[PATCH 0/2] ACPI/CPPC: make policy-limit updates safe

Christian Loehle posted 2 patches 2 days, 13 hours ago
drivers/acpi/cppc_acpi.c       | 22 +++++++++++++++++-----
drivers/cpufreq/cppc_cpufreq.c | 33 +++++++++++++++++++++++----------
include/acpi/cppc_acpi.h       |  5 +++--
3 files changed, 43 insertions(+), 17 deletions(-)
[PATCH 0/2] ACPI/CPPC: make policy-limit updates safe
Posted by Christian Loehle 2 days, 13 hours ago
Commit ea3db45ae476 ("cpufreq: cppc: Update MIN_PERF/MAX_PERF in target
callbacks") made cppc-cpufreq submit policy bounds from both target
callbacks. Two correctness issues remain in that path.

ACPI permits the CPPC controls to use different address spaces. Fast
switching can consequently enter the sleeping PCC path when DESIRED_PERF
is directly accessible but MIN_PERF or MAX_PERF is PCC-backed. Fix it by
doing the simple thing and only allowing fast-switch when all controls
are directly accessible.

The policy bounds are also read without the policy lock. Because the core
updates policy->min and policy->max separately, a lockless reader can form
an inverted pair. Patch 2 sanitizes that snapshot before converting it to
CPPC performance values.

Christian Loehle (2):
  ACPI: CPPC: Check all controls for fast switching
  cpufreq: cppc: Sanitize lockless policy limit snapshots

 drivers/acpi/cppc_acpi.c       | 22 +++++++++++++++++-----
 drivers/cpufreq/cppc_cpufreq.c | 33 +++++++++++++++++++++++----------
 include/acpi/cppc_acpi.h       |  5 +++--
 3 files changed, 43 insertions(+), 17 deletions(-)

-- 
2.34.1
Re: [PATCH 0/2] ACPI/CPPC: make policy-limit updates safe
Posted by Rafael J. Wysocki (Intel) 2 days, 9 hours ago
On Wed, Jul 22, 2026 at 11:38 AM Christian Loehle
<christian.loehle@arm.com> wrote:
>
> Commit ea3db45ae476 ("cpufreq: cppc: Update MIN_PERF/MAX_PERF in target
> callbacks") made cppc-cpufreq submit policy bounds from both target
> callbacks. Two correctness issues remain in that path.
>
> ACPI permits the CPPC controls to use different address spaces. Fast
> switching can consequently enter the sleeping PCC path when DESIRED_PERF
> is directly accessible but MIN_PERF or MAX_PERF is PCC-backed. Fix it by
> doing the simple thing and only allowing fast-switch when all controls
> are directly accessible.
>
> The policy bounds are also read without the policy lock. Because the core
> updates policy->min and policy->max separately, a lockless reader can form
> an inverted pair. Patch 2 sanitizes that snapshot before converting it to
> CPPC performance values.
>
> Christian Loehle (2):
>   ACPI: CPPC: Check all controls for fast switching
>   cpufreq: cppc: Sanitize lockless policy limit snapshots
>
>  drivers/acpi/cppc_acpi.c       | 22 +++++++++++++++++-----
>  drivers/cpufreq/cppc_cpufreq.c | 33 +++++++++++++++++++++++----------
>  include/acpi/cppc_acpi.h       |  5 +++--
>  3 files changed, 43 insertions(+), 17 deletions(-)
>
> --

Applied as 7.2-rc material, thanks!