drivers/dma/fsl_raid.c | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-)
fsl_re_dequeue() holds re_chan->desc_lock while calling
fsl_re_desc_done(), which synchronously invokes the DMA client completion
callback via dmaengine_desc_get_callback_invoke(). If that callback
submits new work (e.g. fsl_re_tx_submit()), it tries to reacquire the
same desc_lock and deadlocks on the spinlock.
Collect completed descriptors into a local list under the lock, then
release the lock and invoke the callbacks before moving the descriptors
to the ack queue.
Fixes: ad80da658bbc ("dmaengine: Driver support for FSL RaidEngine device.")
Assisted-by: opencode:hy3-free
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
drivers/dma/fsl_raid.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
diff --git a/drivers/dma/fsl_raid.c b/drivers/dma/fsl_raid.c
index 2d86f61105e5..bfaef6245695 100644
--- a/drivers/dma/fsl_raid.c
+++ b/drivers/dma/fsl_raid.c
@@ -162,6 +162,7 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
struct fsl_re_hw_desc *hwdesc;
unsigned long flags;
unsigned int count, oub_count;
+ LIST_HEAD(completed);
int found;
fsl_re_cleanup_descs(re_chan);
@@ -182,8 +183,7 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
}
if (found) {
- fsl_re_desc_done(desc);
- list_move_tail(&desc->node, &re_chan->ack_q);
+ list_move_tail(&desc->node, &completed);
} else {
dev_err(re_chan->dev,
"found hwdesc not in sw queue, discard it\n");
@@ -196,6 +196,17 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
FSL_RE_RMVD_JOB(1));
}
spin_unlock_irqrestore(&re_chan->desc_lock, flags);
+
+ /* Invoke the client callbacks outside the channel lock. The callback
+ * may submit new work which re-acquires desc_lock, so holding it here
+ * would deadlock.
+ */
+ list_for_each_entry_safe(desc, _desc, &completed, node) {
+ fsl_re_desc_done(desc);
+ spin_lock_irqsave(&re_chan->desc_lock, flags);
+ list_move_tail(&desc->node, &re_chan->ack_q);
+ spin_unlock_irqrestore(&re_chan->desc_lock, flags);
+ }
}
/* Per Job Ring interrupt handler */
--
2.55.0
On Fri, Jul 17, 2026 at 10:30:10PM -0700, Rosen Penev wrote:
> fsl_re_dequeue() holds re_chan->desc_lock while calling
> fsl_re_desc_done(), which synchronously invokes the DMA client completion
> callback via dmaengine_desc_get_callback_invoke(). If that callback
> submits new work (e.g. fsl_re_tx_submit()), it tries to reacquire the
> same desc_lock and deadlocks on the spinlock.
>
> Collect completed descriptors into a local list under the lock, then
> release the lock and invoke the callbacks before moving the descriptors
> to the ack queue.
>
> Fixes: ad80da658bbc ("dmaengine: Driver support for FSL RaidEngine device.")
> Assisted-by: opencode:hy3-free
> Signed-off-by: Rosen Penev <rosenp@gmail.com>
> ---
Reviewed-by: Frank Li <Frank.Li@nxp.com>
> drivers/dma/fsl_raid.c | 15 +++++++++++++--
> 1 file changed, 13 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/dma/fsl_raid.c b/drivers/dma/fsl_raid.c
> index 2d86f61105e5..bfaef6245695 100644
> --- a/drivers/dma/fsl_raid.c
> +++ b/drivers/dma/fsl_raid.c
> @@ -162,6 +162,7 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
> struct fsl_re_hw_desc *hwdesc;
> unsigned long flags;
> unsigned int count, oub_count;
> + LIST_HEAD(completed);
> int found;
>
> fsl_re_cleanup_descs(re_chan);
> @@ -182,8 +183,7 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
> }
>
> if (found) {
> - fsl_re_desc_done(desc);
> - list_move_tail(&desc->node, &re_chan->ack_q);
> + list_move_tail(&desc->node, &completed);
> } else {
> dev_err(re_chan->dev,
> "found hwdesc not in sw queue, discard it\n");
> @@ -196,6 +196,17 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
> FSL_RE_RMVD_JOB(1));
> }
> spin_unlock_irqrestore(&re_chan->desc_lock, flags);
> +
> + /* Invoke the client callbacks outside the channel lock. The callback
> + * may submit new work which re-acquires desc_lock, so holding it here
> + * would deadlock.
> + */
> + list_for_each_entry_safe(desc, _desc, &completed, node) {
> + fsl_re_desc_done(desc);
> + spin_lock_irqsave(&re_chan->desc_lock, flags);
> + list_move_tail(&desc->node, &re_chan->ack_q);
> + spin_unlock_irqrestore(&re_chan->desc_lock, flags);
> + }
> }
>
> /* Per Job Ring interrupt handler */
> --
> 2.55.0
>
© 2016 - 2026 Red Hat, Inc.