From nobody Fri Jul 24 23:30:19 2026 Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 128D73DDAED for ; Wed, 22 Jul 2026 04:31:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.47 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784694672; cv=none; b=g4YwEFB7wjAopiuo79eO20kNfulLzE5v5VvoU5Y5ANpPkfYr8YWBlaWu/PSfJXFvZc/AUr6cfFjQu84u6nUGK4xZLHDmFjW4tw/3aYl5bAO/V5Yu0aZaQcc4XwGwR7uW2XmFtTkaiw4Amwt/nCf/sQhweNJIobHu/MRFxDkXgS0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784694672; c=relaxed/simple; bh=MoFBOqjbdPllrAOMjyA3z1unmWUiWpJoQ6Sdq8yEmIU=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=Z35NbOX0RL2xNylvQkEL2uDaJPlJK2KomSd10eOy6Zmr9xKnhMIJIBqZo0Sw8+0VLKzGC3UQquQxYkJgeLpToP4DwgfJQrcqaXKfAbnpO+GYahPQjgqvPysBgB5ZCN/YFZb4fX++QBpBjTfCRmdncH9q2Li23esF26tJlZv+2jQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=OCwy/eGy; arc=none smtp.client-ip=209.85.128.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="OCwy/eGy" Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-4955aa106b1so27192195e9.0 for ; Tue, 21 Jul 2026 21:31:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784694669; x=1785299469; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=cw+g8044aLFqtXGEWXTOBm0DvocPh9k56AtCHyZmPRw=; b=OCwy/eGydkRhUTGIX4cs0/ps0avEisVo8rljAWJi0A1OZDeRXm2RaRcuYCRlWS1fdb Sy3fV/b81pFAxRWMeq6EFpdCmlhPqrRnVXPsuDQLzA+Z+cK+yexStdydo4hf6PIlYYtY DCVeioyPPUmnNpUTQnb+MUr5mISks1biss1y1HqXmBRaSYb9u6L94w9FaKRr57Tlb9yU PxvMvtv2cIuf7YZKSP4AOhhT3cUVfyEj+l7hUd8ex9YlGGZJEFtqSJjAG73Gy3wDoFbH E33Ew26EWLLmAS7BdFHDWEHFC+pDo1Rd4fu4LW/PPbfCvY3sGUrqPdm/pk/WMiVM43PI TD5g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784694669; x=1785299469; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=cw+g8044aLFqtXGEWXTOBm0DvocPh9k56AtCHyZmPRw=; b=KkNdcCQWxWOIQx0WFedCNe2l0G37lu72MZfzjrVlmyT3Yw4giXEU9aRH6pOygfKhWX A16RIMatwv9N8BGRhddigWznVaKAY9YXI0+B9QwN2awyx7w6N8gozwXxZCR2o74gNjQ3 gTaqEwvCryOeVws1wBFxuJHpDy4o4nwJcNuMjbd8f0PJOq4SUNPu20c/INOvNH2ue41J GYvZtBA+V+W4CjIkUj5CaCIOxnbYfIGcxV7EJM6RdFEeKAKwCUQqKdDv4rb8ErM8kiHy l/kEYQpcm3iP6kKpmiViFUKnrmkq/4lstxK4Isd/XAL8bcMEZNIIePPf4Mrz9B6TCek3 LvFA== X-Forwarded-Encrypted: i=1; AHgh+RpfQYHYLqWgwGo+Blzm5JkgvZGY2EV1+fLBb7TFVm3YdtgAYNv6UjHdziBYSIaHM3MQYxfw90MJYH9adLI=@vger.kernel.org X-Gm-Message-State: AOJu0Yw5LXbgNBxH/ZBh3xJCGyYvQ5geKKxfMNbdUTFR2OqA8luXMiIv MPHBbz2X1nNvRfLN5lpszaBwYsZaW2Mdo1PEXygHaSWtcoO2U3v9hDSw X-Gm-Gg: AR+sD13PRVWZLkcX206wqF98RgvlJ+3ZpYhpF427diim7F9jwL+ViqHRfapfZqrxK9V LqHvKgYE9/Yk/UkVl/1QJxpsGti7Qjc5Iyxn9MM/8w4JTr0k2wV4Q1jIoBwucyhYp6SCCLAOCVM uMonbIcO7vtNk1ScSfBTGN7D4S8BuppiMXu5JWN/FAf+0ipSoAwlAWGXPg6F5ZJrCPik1JuXWR8 6N4SzxXfgMQZDKQFEXTjFhTLn2QuB8VMsBh6JkRQPBGYEE9II767pimZphB0C1Z9Cq3FNCeAaLN LItkX66L2S9ID6XB3gERjLCoMs38bhy4X34wnD0/KA9LMqiU++Ex9I/bzSAvW6estCTxKlkFE3n 3sB4OKU8TvL5XAIrhebwlkJ4VXP5+uTcZ3+/PcXQLHOCjkl5jrlhMN4P9N7KbflaU1Y8AXPUxcq yyhI//TelLEBFbUJmHZaAuW+xxER5yazWXbBN5ZQ0XO06YvO6gkXEZDxEI8qaO3Hs= X-Received: by 2002:a05:600c:8b16:b0:495:69eb:27fe with SMTP id 5b1f17b1804b1-49569eb28a0mr35742605e9.11.1784694669049; Tue, 21 Jul 2026 21:31:09 -0700 (PDT) Received: from localhost.localdomain ([102.187.228.150]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4956537c7desm161495895e9.7.2026.07.21.21.31.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Jul 2026 21:31:08 -0700 (PDT) From: Mohamed Ayman To: Suzuki K Poulose , Mike Leach , James Clark , Leo Yan , Alexander Shishkin , Sebastian Andrzej Siewior , Clark Williams , Steven Rostedt , coresight@lists.linaro.org (moderated list:ARM/CORESIGHT FRAMEWORK AND DRIVERS), linux-arm-kernel@lists.infradead.org (moderated list:ARM/CORESIGHT FRAMEWORK AND DRIVERS), linux-kernel@vger.kernel.org (open list), linux-rt-devel@lists.linux.dev (open list:Real-time Linux (PREEMPT_RT):Keyword:PREEMPT_RT) Cc: Mohamed Ayman , coresight@lists.linaro.org (moderated list:ARM/CORESIGHT FRAMEWORK AND DRIVERS), linux-arm-kernel@lists.infradead.org (moderated list:ARM/CORESIGHT FRAMEWORK AND DRIVERS), linux-kernel@vger.kernel.org (open list), linux-rt-devel@lists.linux.dev (open list:Real-time Linux (PREEMPT_RT):Keyword:PREEMPT_RT) Subject: [PATCH v4] coresight: Fix scheduling while atomic in coresight_cpu_pm_notify() Date: Wed, 22 Jul 2026 07:30:23 +0300 Message-Id: <20260722043023.6978-1-mohamedaymanworkspace@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260712210446.14290-1-mohamedaymanworkspace@gmail.com> References: <20260712210446.14290-1-mohamedaymanworkspace@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Dropping the last reference to a coresight_device can trigger a kernel panic on PREEMPT_RT builds due to a "scheduling while atomic" violation. When the CPU enters an idle state, coresight_cpu_pm_notify() is invoked with local interrupts disabled. It calls coresight_cpu_get_active_path(), which currently uses coresight_get_percpu_source_ref() to get a kobject reference, and then immediately drops it with coresight_put_percpu_source_r= ef(). If this put_device() call drops the very last reference (e.g., due to a concurrent device unregistration), it synchronously triggers the release cascade. On PREEMPT_RT, free_percpu() takes a sleeping spinlock_t. Furthermore, any parent device in the release chain might also acquire sleeping locks, causing a system crash in the atomic PM context. Fix this by eliminating the get/put dance entirely in the PM notifier path. Since coresight_cpu_pm_notify() runs with IRQs disabled, it is safe to read the per-cpu source pointer directly under the coresight_dev_lock, check the mode, and return the path without unnecessarily manipulating the kobject refcount. Suggested-by: Sebastian Andrzej Siewior Reviewed-by: Sebastian Andrzej Siewior Reviewed-by: Leo Yan Signed-off-by: Mohamed Ayman --- drivers/hwtracing/coresight/coresight-core.c | 15 ++++++--------- 1 file changed, 6 insertions(+), 9 deletions(-) diff --git a/drivers/hwtracing/coresight/coresight-core.c b/drivers/hwtraci= ng/coresight/coresight-core.c index 6d65c43d5..9461fac9f 100644 --- a/drivers/hwtracing/coresight/coresight-core.c +++ b/drivers/hwtracing/coresight/coresight-core.c @@ -1850,16 +1850,13 @@ static void coresight_release_device_list(void) static struct coresight_path *coresight_cpu_get_active_path(enum cs_mode m= ode) { struct coresight_device *source; - bool is_active =3D false; + struct coresight_path *path =3D NULL; =20 - source =3D coresight_get_percpu_source_ref(smp_processor_id()); - if (!source) - return NULL; - - if (coresight_get_mode(source) & mode) - is_active =3D true; + guard(raw_spinlock_irqsave)(&coresight_dev_lock); =20 - coresight_put_percpu_source_ref(source); + source =3D per_cpu(csdev_source, smp_processor_id()); + if (source && (coresight_get_mode(source) & mode)) + path =3D source->path; =20 /* * It is expected to run in atomic context or with the CPU lock held for @@ -1868,7 +1865,7 @@ static struct coresight_path *coresight_cpu_get_activ= e_path(enum cs_mode mode) * change. Since the build path has taken a reference on the component, * the path can be safely used by the caller. */ - return is_active ? source->path : NULL; + return path; } =20 /* Return: 1 if PM is required, 0 if skip, or a negative error */ --=20 2.34.1