From nobody Sun Sep 27 02:54:49 2026 Received: from mail-wr1-f53.google.com (mail-wr1-f53.google.com [209.85.221.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 98AFB4F0549 for ; Sat, 5 Sep 2026 18:39:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788633566; cv=none; b=RSnAgwFrpqNRTG9XIe0EdHb4hG8DwPdjVnPHY5EUBCAPQUXyJCU34uo8SJon5GizTL/xGMkoPr8mHkop51TKyYjvMz09eYILl802SlpuTEM9Bj8EcP64XjGGWcfF+fhsIaJaCU7WK+pZIz9Gi9BvOXK5BFxNLDO+BAY0p31a6VI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788633566; c=relaxed/simple; bh=2YluIy60Jfzmukqkh5yOQvfMAun1hVRGK+XOEjZhVsY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=OWpAUB4rzEDB4jWUuYhnhZTwowjZgQVytco36zNfMUHrdwYfZTHdVa32ti+rnVa/hpJ3hwGXmj0ntGM0pHEtamI8kY9tMQwf+iefEvcy3X9IFGla5WD92FdlgtRyYJA3F9pI+tCHdcvNnBmmgYpX1cWoxk5rcgO0kU7mHD4waGs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=KLz6LIxb; arc=none smtp.client-ip=209.85.221.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="KLz6LIxb" Received: by mail-wr1-f53.google.com with SMTP id ffacd0b85a97d-4843e9c5960so2157087f8f.0 for ; Sat, 05 Sep 2026 11:39:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788633563; x=1789238363; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=x0q/PhqzpPPYuw5I7NOI37oNV5qDMBKzDX3eeEPIj9k=; b=KLz6LIxbRakntqO5V2uMN+MjCp/PT0SkGjrF/WegNNP+dwIlC5SrSc7eWmgc0ZSJ+f UaLOSXLpT21iEwTw/HQcnXotfnTfIUmu4q3Bu4LhhfBqzSL3D5nGxceYn6Aw14nWlPab 3YdtPPdBj0VSEv5gTLuJyB+wq+xQUGWGIQk4IoQBH6HX2Gxe67zytz5WOSRg9qlZMNAE q5TLzZDK9v3+XLEtfI29n/+bVHl7D+4aoOy7NYy4FrlE9y3pd+9admpi/H97DpqpyamP 45dAtFa/Qd6IqCRcIZP7HcB38R5nt3U7tNIMO6qDpcCMtMZfvuirIDNXV6PAP7kG6Dzx u1cQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788633563; x=1789238363; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=x0q/PhqzpPPYuw5I7NOI37oNV5qDMBKzDX3eeEPIj9k=; b=aI8EMFoSTo+IpfEIcFMbiGse6bnUBBCTNLQ4o1xVER8ZCkWYCuDw0GbT1RT6/MyPR6 u6kI4niEbYAubJNPPVM9gNhjhJFYGlD3GN07RXc5E25jlJp8xW909RFGg2YWL5cQxVKG U7wGavbV42FYtsgGc3rHlHwG0k73o4/NukXV+B423n6SjxwBydEC31sFG2CoB7S1kGUl QptADkrertfZBJYleMzMP8JdOaxnjaF1tmsKDvlLpm7CbiMBRsAkHyPDmMQGRbRrf7vk bqYigWXRPrLDHF+Lj71Fj3a/+rindutyLYg2jMLxZI0gVAOprGv7qcN1hHdN97GaDWj/ yIdQ== X-Forwarded-Encrypted: i=1; AKwUvByPtK49btuf1R4ezUV3NLHX3t0ldzkws0KTCYaeJmYr7Mf9/NflhCNbLzALLNIjSv8K+EFMO/wBlfk79aE=@vger.kernel.org X-Gm-Message-State: AFuF++lD2/J99eC7uAKg0iZSF4bJUvd2P3LMF8o0dkQ6DQ8CnCyq42IL GZAeqbcCK9MC5R8iOY+/y0J5JOpkkBoKbx2SR438u0uHd08wKEf4I7hj X-Gm-Gg: AYBFou0ZbeoklsR3I8kLT9K/kqHGGu8/PU2VAMlXOv+8IyeFKai9aqeaSRcN1LGk2Yj f7I5IAVhZoi0jTLu3kZ00P4LMwca0c/duO2Q2q0lxOZcp4WXopLZJG29RG2SfBmv5KqITQ0jkY0 6rDF11zCR4mns7Z/pd/Ojoy+PXH8RntuP3BMB6EteMJEjI3IeDdQoZIgJG67C1y0yLNdioiSzKw y2SMmrf5GHtuPXkF/bH7HLgzxY4H+cxaxXqrlcLwqRj2moJWUZVOyHINWKsw1EvQyGRhcTgmk8b 5v5z1KIB/GoC0YgFIu3pBoA6SSlAMIg6ndUaN7oPzcXguwhPCTaxtaCQeDjGbyj0qot1Hek9iRI +NLaV6UhyrSd2w+G0Ong9OJl3kMrn14IX4ELLPYGDU4b0hX3kK1dr4Wj9p3xcJX48hEJDn+92JM h8Z2sszcG6XJ5Np00Gxc5U5klfesqgxHOKim0oeRTlINBeXUWmVTEG35KA9Y6LKolc82rINHNB0 w== X-Received: by 2002:adf:e19e:0:b0:485:8c16:5eef with SMTP id ffacd0b85a97d-4858c166088mr10620207f8f.41.1788633562541; Sat, 05 Sep 2026 11:39:22 -0700 (PDT) Received: from 1c44f78ca37e.fritz.box ([2.210.128.137]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm16333603f8f.34.2026.09.05.11.39.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 11:39:21 -0700 (PDT) From: Abhin Parekadan Jose To: bhelgaas@google.com, lukas@wunner.de, mst@redhat.com Cc: linux-pci@vger.kernel.org, linux-kernel@vger.kernel.org, ilpo.jarvinen@linux.intel.com, kees@kernel.org, xueshuai@linux.alibaba.com, Abhin Parekadan Jose Subject: [PATCH RFC 1/3] PCI: Report surprise removal event Date: Sat, 5 Sep 2026 18:38:58 +0000 Message-ID: <20260905183905.997833-2-abhinjoses@gmail.com> X-Mailer: git-send-email 2.51.1 In-Reply-To: <20260905183905.997833-1-abhinjoses@gmail.com> References: <20260905183905.997833-1-abhinjoses@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: "Michael S. Tsirkin" At the moment, in case of a surprise removal, the regular remove callback is invoked, exclusively. This works well, because mostly, the cleanup would be the same. However, there's a race: imagine device removal was initiated by a user action, such as driver unbind, and it in turn initiated some cleanup and is now waiting for an interrupt from the device. If the device is now surprise-removed, that never arrives and the remove callback hangs forever. For example, this was reported for virtio-blk: 1. the graceful removal is ongoing in the remove() callback, where disk deletion del_gendisk() is ongoing, which waits for the requests to complete, 2. Now few requests are yet to complete, and surprise removal started. At this point, virtio block driver will not get notified by the driver core layer, because it is likely serializing remove() happening by +user/driver unload and PCI hotplug driver-initiated device removal. So vblk driver doesn't know that device is removed, block layer is waiting for requests completions to arrive which it never gets. So del_gendisk() gets stuck. Drivers can artificially add timeouts to handle that, but it can be flaky. Instead, let's add a way for the driver to be notified about the disconnect. It can then do any necessary cleanup, knowing that the device is inactive. Since cleanups can take a long time, this takes an approach of a work struct that the driver initiates and enables on probe, and tears down on remove. Signed-off-by: Michael S. Tsirkin Link: https://lore.kernel.org/all/fba3d235e38c1c6fcef2a30ed083ad9e25b20fa3.= 1752094439.git.mst@redhat.com/ [Abhin: adapted commit message subject] Signed-off-by: Abhin Parekadan Jose --- drivers/pci/pci.h | 6 ++++++ include/linux/pci.h | 45 +++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 51 insertions(+) diff --git a/drivers/pci/pci.h b/drivers/pci/pci.h index ba3c3fddddc2..23b1605e783a 100644 --- a/drivers/pci/pci.h +++ b/drivers/pci/pci.h @@ -805,6 +805,12 @@ static inline int pci_dev_set_disconnected(struct pci_= dev *dev, void *unused) pci_dev_set_io_state(dev, pci_channel_io_perm_failure); pci_doe_disconnected(dev); =20 + if (READ_ONCE(dev->disconnect_work_enable)) { + /* Make sure work is up to date. */ + smp_rmb(); + schedule_work(&dev->disconnect_work); + } + return 0; } =20 diff --git a/include/linux/pci.h b/include/linux/pci.h index d31a8d107b1e..06d43f57f509 100644 --- a/include/linux/pci.h +++ b/include/linux/pci.h @@ -592,6 +592,9 @@ struct pci_dev { u8 reset_methods[PCI_NUM_RESET_METHODS]; /* In priority order */ =20 struct gpio_desc *wake; /* WAKE# GPIO */ + /* Report disconnect events. 0x0 - disable, 0x1 - enable */ + u8 disconnect_work_enable; + struct work_struct disconnect_work; =20 #ifdef CONFIG_PCIE_TPH u16 tph_cap; /* TPH capability offset */ @@ -2123,6 +2126,48 @@ pci_release_mem_regions(struct pci_dev *pdev) pci_select_bars(pdev, IORESOURCE_MEM)); } =20 +/* + * Run this first thing after getting a disconnect work, to prevent it from + * running multiple times. + * Returns: true if disconnect was enabled, proceed. false if disabled, ab= ort. + */ +static inline bool pci_test_and_clear_disconnect_enable(struct pci_dev *pd= ev) +{ + u8 enable =3D 0x1; + u8 disable =3D 0x0; + + return try_cmpxchg(&pdev->disconnect_work_enable, &enable, disable); +} + +/* + * Caller must initialize @pdev->disconnect_work before invoking this. + * The work function must run and check pci_test_and_clear_disconnect_enab= le. + * Note that device can go away right after this call. + */ +static inline void pci_set_disconnect_work(struct pci_dev *pdev) +{ + /* Make sure WQ has been initialized already */ + smp_wmb(); + + WRITE_ONCE(pdev->disconnect_work_enable, 0x1); + + /* check the device did not go away meanwhile. */ + mb(); + + if (!pci_device_is_present(pdev)) + schedule_work(&pdev->disconnect_work); +} + +static inline void pci_clear_disconnect_work(struct pci_dev *pdev) +{ + WRITE_ONCE(pdev->disconnect_work_enable, 0x0); + + /* Make sure to stop using work from now on. */ + smp_wmb(); + + cancel_work_sync(&pdev->disconnect_work); +} + bool pci_suspend_retains_context(struct pci_dev *pdev); =20 #else /* CONFIG_PCI is not enabled */ --=20 2.51.1 From nobody Sun Sep 27 02:54:49 2026 Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C06304F0526 for ; Sat, 5 Sep 2026 18:39:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.51 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788633570; cv=none; b=k/TaXWlCI8GgBChX7Jljv9EET94pg+GoUiqEo+v+B/s62yyxxJNhLTMzsrQdiukfXLmoGiwvw3J7IJ815sjxJdVCNimQh56qqGYgdwNp6xYcP0hIQlolS85neNlaZHSx15bhMIQvCOn3Y53kE5py+x98PXHi3uxHCV54AeoLTQw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788633570; c=relaxed/simple; bh=zqM1Egd1H5DgF8rBBGGCJB+/hNj9dNxjE7s90jsaat0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=h60J3VQTDs74kAt/S/VlZEbE4+/sBftTesAM8crk1iOXk5soOy/6mrVUDr8s5It23VPfNFA8mIpHBogWhQmqHbbJ1wnkjpRrAyF7a7buDHS/3O61y+ukerl9irEOxMH+U6Qw9oPlj/HkBNA8PfD/L1WCtHwsQWmJdy9jZxMSnwo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=V/ZZps0P; arc=none smtp.client-ip=209.85.221.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="V/ZZps0P" Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-48436251906so2390378f8f.0 for ; Sat, 05 Sep 2026 11:39:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788633567; x=1789238367; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=JTWignQfEmN2SpuJ74uFQJg2JrONtVT7vSQ7KAxjdQM=; b=V/ZZps0Pldu+bLFyEb8oKRl2mt/+9o9n3n8oqTUR1rJPSwodQmyg9/s1Zfb4xtjMoW dyW+FaMx5IZhqw00gwgNQhGo8rpM3LlCg2yB0YWxMm/XOteq2csIuNn+WHH8QQy+1adG uD0O6reEPQOdCsnPZclnEiXRlvbWmgLUCWtbN29KlAqCazDBjoUWC1A4wjyXN54c+jJd osF+1uQXv7plGnrUwA6dDpkud4tBU4xit7o6UPd08D/WwKdM80BNiiNWb6V3JEGVeQwP q4ZkzCdLSDo3hgTq3Ktc8cR+ShBT2Y+eCf+2hj4N/rE2QhE+8dbkI6t8i+gWxsXpxT4R fHLA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788633567; x=1789238367; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=JTWignQfEmN2SpuJ74uFQJg2JrONtVT7vSQ7KAxjdQM=; b=fEgfZfEjfLwAZ0NVFUkUSG75AQVTmDaNhlDVGnU7AmbTrMMX1RKzWZirFT1BVA/GdI Eji2TYC9vMjXcuwEGEipBLVTdjXnQ8hytW8eQYqtLhUZoEwiiF8u4Yrzr69IcCxss5Iq QkmN4FQ128+xKpctpJ98Pg9sRAKGyPpL1fFZ5gxLbJ/SVekdNLfTfioFO9QcwqVbLwaB CipEMc4PexlA/wrQ+PDROZB/2usNmKNUnBRA6hvjhA3cCIY/F6vMu6IRRHeedGQpjYjy VCV6v4GOY9myNifcnhRhVFK/0WbrU2ca87rt6tEgrB//Sca3XFcWAAlRxUr7ts4WKDGb 3uFA== X-Forwarded-Encrypted: i=1; AKwUvBxMfmC/DkbmzhsWky1qWF6DhSJYe8FkDUafL8nsuE2BXem/fNmvAcf3V701bfnQ4I3zWiXtOZG6dSGxcZ8=@vger.kernel.org X-Gm-Message-State: AFuF++nUyQDJvJDY3flTh7FcCaaFKKmyvXn7Re2ZsFEqmTZRa7RXn2Si JkpdnszK4D4yuz7vMrQdTSO1IbXrfMV8L7Tv+QXuzcytMFS2jSMBxUuodJo3R2msZtw= X-Gm-Gg: AYBFou26EfqSe3Mq8BJbl+RBhZ7HcodV5zJ/BKai1+khpAPBp/BD7ho4w64Q6KCUIvu bHb7JF3V6G+Odkgs0aOis++W9UzTf4tFqLpjHnd8t5Mwd5if3GNnnBjZBWxzCTHAuvJu6eqOq1y Xwk4+I4TFu98g3LsZYfiYVVlx1iexM8+kry6OAUzmhIPGPs1LB33CVaB/ygclbeqHdC/wtWYKHw te0kXZavvj2i4EAEVsEDm+hcZ9gaKp340vJizdPJxYboa3J0bQqyUG+9P7aXgE3Ffsf/WCh8UT7 N3fb2KPpBHvH9TuvbI1/QUPLh6RN4m2r3u3PtUnNxFc9WB5nC/UY/pfofgvWKR1vnxJLIjOF3jr /8nO4RUadKqtorQL14oKp5z84BE8ZESDRy99Qq8+2XZSJ8ZLzM/guaATSsQbY0XbmUYl60vQqL0 AOlrm8pSrfTrqLnSDQalgAALbHykAGN/IhLoLRLD5lQK+jSQj14wQOTCPGyVYBVLp7/HfwMOvuv Q== X-Received: by 2002:a05:6000:18a8:b0:482:ea08:8c8a with SMTP id ffacd0b85a97d-48587090294mr25391012f8f.20.1788633566813; Sat, 05 Sep 2026 11:39:26 -0700 (PDT) Received: from 1c44f78ca37e.fritz.box ([2.210.128.137]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm16333603f8f.34.2026.09.05.11.39.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 11:39:25 -0700 (PDT) From: Abhin Parekadan Jose To: bhelgaas@google.com, lukas@wunner.de, mst@redhat.com Cc: linux-pci@vger.kernel.org, linux-kernel@vger.kernel.org, ilpo.jarvinen@linux.intel.com, kees@kernel.org, xueshuai@linux.alibaba.com, Abhin Parekadan Jose Subject: [PATCH RFC 2/3] PCI: pciehp: Report surprise removal from pciehp_isr() Date: Sat, 5 Sep 2026 18:38:59 +0000 Message-ID: <20260905183905.997833-3-abhinjoses@gmail.com> X-Mailer: git-send-email 2.51.1 In-Reply-To: <20260905183905.997833-1-abhinjoses@gmail.com> References: <20260905183905.997833-1-abhinjoses@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" A surprise removal during a safe removal cannot be reported: the removal blocks waiting on a device interrupt or status read, and the single-threaded IRQ thread is itself executing that removal, so it cannot report that the device is gone. The removal hangs. The hardirq handler pciehp_isr() still runs while the IRQ thread is blocked, so it can report the disconnect. However, pciehp_ist() deliberately ignores link and presence changes caused by a Secondary Bus Reset or Downstream Port Containment, where the device is only temporarily inaccessible. Distinguishing those normally requires waiting for the SBR or DPC to conclude, which takes seconds and is not possible in hardirq context. Schedule a work item from pciehp_isr() when a PDC or DLLSC event arrives and PDS indicates if the device is connected/disconnected. This provides us a pathway to wait/block/sleep as we will not be in pciehp_isr(). Move the scheduling of the driver's disconnect notification out of pci_dev_set_disconnected() into schedule_notification_work() so it can be invoked from the new work item. Factor the spurious link change test out of pciehp_ist() into pciehp_is_spurious_link_change() so both pciehp_ist() and pciehp_disconnect_work() can use it. Link: https://lore.kernel.org/all/aHlZE18kPuHuDtTT@wunner.de/ Signed-off-by: Abhin Parekadan Jose --- drivers/pci/hotplug/pciehp.h | 1 + drivers/pci/hotplug/pciehp_hpc.c | 56 +++++++++++++++++++++++++++----- drivers/pci/pci.h | 6 ++++ 3 files changed, 55 insertions(+), 8 deletions(-) diff --git a/drivers/pci/hotplug/pciehp.h b/drivers/pci/hotplug/pciehp.h index debc79b0adfb..c8ceb9320e2e 100644 --- a/drivers/pci/hotplug/pciehp.h +++ b/drivers/pci/hotplug/pciehp.h @@ -116,6 +116,7 @@ struct controller { unsigned int ist_running; int request_result; wait_queue_head_t requester; + struct work_struct disconnect_work; }; =20 /** diff --git a/drivers/pci/hotplug/pciehp_hpc.c b/drivers/pci/hotplug/pciehp_= hpc.c index 4c62140a3cb4..235ca8a176f1 100644 --- a/drivers/pci/hotplug/pciehp_hpc.c +++ b/drivers/pci/hotplug/pciehp_hpc.c @@ -620,6 +620,45 @@ static void pciehp_ignore_link_change(struct controlle= r *ctrl, up_read(&ctrl->reset_lock); } =20 +/* + * Link Down/Up events caused by Downstream Port Containment if recovery + * succeeded, or caused by Secondary Bus Reset, suspend to D3cold, firmware + * update, FPGA reconfiguration, etc. are spurious and should be ignored. + */ +static bool pciehp_is_spurious_link_change(struct controller *ctrl, + struct pci_dev *pdev, + u32 events) +{ + return (events & (PCI_EXP_SLTSTA_PDC | PCI_EXP_SLTSTA_DLLSC)) && + (pci_dpc_recovered(pdev) || pci_hp_spurious_link_change(pdev)) && + ctrl->state =3D=3D ON_STATE; +} + +/* + * Workaround to not wait in the isr. + */ +static void pciehp_disconnect_work(struct work_struct *work) +{ + struct pci_bus *bus; + struct controller *ctrl =3D container_of(work, struct controller, + disconnect_work); + struct pci_dev *pdev =3D ctrl_dev(ctrl); + u32 events; + + events =3D atomic_read(&ctrl->pending_events); + + if (pciehp_is_spurious_link_change(ctrl, pdev, events)) + return; + + bus =3D ctrl->pcie->port->subordinate; + + /* The card may have returned */ + if (!bus || pciehp_card_present(ctrl) !=3D 0) + return; + + pci_walk_bus(bus, schedule_notification_work, NULL); +} + static irqreturn_t pciehp_isr(int irq, void *dev_id) { struct controller *ctrl =3D (struct controller *)dev_id; @@ -722,6 +761,12 @@ static irqreturn_t pciehp_isr(int irq, void *dev_id) =20 /* Save pending events for consumption by IRQ thread. */ atomic_or(events, &ctrl->pending_events); + + /* presence change events */ + if ((events & (PCI_EXP_SLTSTA_PDC | PCI_EXP_SLTSTA_DLLSC)) && + !pciehp_card_present(ctrl)) + schedule_work(&ctrl->disconnect_work); + return IRQ_WAKE_THREAD; } =20 @@ -761,14 +806,7 @@ static irqreturn_t pciehp_ist(int irq, void *dev_id) PCI_EXP_SLTCTL_ATTN_IND_ON); } =20 - /* - * Ignore Link Down/Up events caused by Downstream Port Containment - * if recovery succeeded, or caused by Secondary Bus Reset, - * suspend to D3cold, firmware update, FPGA reconfiguration, etc. - */ - if ((events & (PCI_EXP_SLTSTA_PDC | PCI_EXP_SLTSTA_DLLSC)) && - (pci_dpc_recovered(pdev) || pci_hp_spurious_link_change(pdev)) && - ctrl->state =3D=3D ON_STATE) { + if (pciehp_is_spurious_link_change(ctrl, pdev, events)) { u16 ignored_events =3D PCI_EXP_SLTSTA_DLLSC; =20 if (!ctrl->inband_presence_disabled) @@ -1036,6 +1074,7 @@ struct controller *pcie_init(struct pcie_device *dev) init_waitqueue_head(&ctrl->requester); init_waitqueue_head(&ctrl->queue); INIT_DELAYED_WORK(&ctrl->button_work, pciehp_queue_pushbutton_work); + INIT_WORK(&ctrl->disconnect_work, pciehp_disconnect_work); dbg_ctrl(ctrl); =20 down_read(&pci_bus_sem); @@ -1096,6 +1135,7 @@ struct controller *pcie_init(struct pcie_device *dev) void pciehp_release_ctrl(struct controller *ctrl) { cancel_delayed_work_sync(&ctrl->button_work); + cancel_work_sync(&ctrl->disconnect_work); kfree(ctrl); } =20 diff --git a/drivers/pci/pci.h b/drivers/pci/pci.h index 23b1605e783a..4e17878edeab 100644 --- a/drivers/pci/pci.h +++ b/drivers/pci/pci.h @@ -805,6 +805,12 @@ static inline int pci_dev_set_disconnected(struct pci_= dev *dev, void *unused) pci_dev_set_io_state(dev, pci_channel_io_perm_failure); pci_doe_disconnected(dev); =20 + return 0; +} + +static inline int schedule_notification_work(struct pci_dev *dev, void *un= used) +{ + pci_dev_set_disconnected(dev, NULL); if (READ_ONCE(dev->disconnect_work_enable)) { /* Make sure work is up to date. */ smp_rmb(); --=20 2.51.1 From nobody Sun Sep 27 02:54:49 2026 Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 83C854EE858 for ; Sat, 5 Sep 2026 18:39:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.47 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788633573; cv=none; b=ezkw6nBDNfkpFCrQGRdvp8rGGHZHSNJScD4mn1EuxqZks127DZtQodrstLLLqoiyCgPoDXzkpccn2vNZhCtevEiOGsOmFbIYOoQDX9i8E8ExTw+Orlo1ZMTPAZJbwr+8hjVk6RXBX1iF+hUBcqzsH2g6QvlvFJkM3HTb4gbtSWk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788633573; c=relaxed/simple; bh=4p0t4kxqdtq0p2YlJ6VyfHFrgxr8bBrSXVIfvZ+IBtg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=HB24lAOHF8BOJifJ0oHKKzVyxRTse761GpDTwEcu2imQl70G4VrVxV9nTixO7zdi23vO9wjivDiFtZWW2aN2ldJmeRCU+E7JnrtH8S5Pn4Agh8THlOAEjd6zbAJqVfxCivkd8Uv1FKWqmYtROIY7bFqKmeMtRw2lJdoi2IZ9iHM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=jxvoPhZw; arc=none smtp.client-ip=209.85.221.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="jxvoPhZw" Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-48589798dbbso1706315f8f.3 for ; Sat, 05 Sep 2026 11:39:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788633569; x=1789238369; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=rlmalfwKU2dFS/LTehgVnk0Im0uZNUUABZEx/k40zk4=; b=jxvoPhZwtSGgT8QDyqU7Zj0JE2o5we5PiPxJrP3EO1ueGLZCgbbCxspTgr2aLqnToN NlvUsfMf4dzdZb115hfVLu+zSitgRcoKPyuEudcrbSVOL6A6AVR+tNn1bI8+vAW95Bsj vTr8yNxomkxngy46ykISeiNSnJ+3xWajc7kegT+7VJKUVHxTZSAXaF5QnSZbGGqM9yI2 7Rxuq1KEBmYIuQHsD02gZ56o6i2Pzxx043UrMKOmM6wwMw7QMpHscAbgD2Jd+mj+0Ld/ hrzzYOFuygiKaitTp1/gZhbtBPNpcDWQ7LyWjVG410gBH3ATsbCPukoxsoyhK/wY/Zfg vLdQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788633569; x=1789238369; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=rlmalfwKU2dFS/LTehgVnk0Im0uZNUUABZEx/k40zk4=; b=shc0EeZHYHzYWpMweZ88g8eXBfPGZ8TWtDshSMp4BZea8HI9Ahk3gxsvc1zRLqa2L0 oFyLiZ37Y/0J25YTmA05gvEXpPBqOoCx7XIx0bP9ev1mRJT2RwU1/BQcgVlX0MNchlth q6s6nNe7Uw0LSmp+rdUJVoLIDbgMTQKWKwLQfM0gH25Ei7ulclFnrZPPl74AQn19o284 SyeypSDR0zdveLdi1lBcvZI6zxj0LIE9jxh/Oc3XbnNa0HM0vsAJq5lkplSRKlMxbXGh vrkNg3c5iYNoZ1+C3D3MF55Nn0om0J5j93lUIy6RG5H92WfHA1jiBK69gwqLotUx/5oz 5l2A== X-Forwarded-Encrypted: i=1; AKwUvBxIehSfJN90AU5ta4Ut5PaJKIuzZ6uBKW+gR2tI8+hWRRRDl7H/MSs1b6sK8meVjo2gcNhORU749umbVow=@vger.kernel.org X-Gm-Message-State: AFuF++nA6E1UYP1E7MueknTgyoVoKCp5nJsvyHMUXwaX3pw1n5SNgbLj RA58KdRaJLanPb2loS41IreqjJWd3zlwpN1cqbI0KaSb+YsQLV9DRqLK X-Gm-Gg: AYBFou2babg8dUSfFqcahqzOxdMLYXnm/1vLmMJjyCQvL3QQX51jNKJntydIVNx04WK 4FKMzIyA11zQutKJg3Gnr6fDKBRx3jFKzzg0QSKHAjysjidUC+5usGA7m77+n9BWuUqesOcX+iC FHMcgsIAmsT9DSVYZ6k0YGWoDBixdJF+nnq8w2YWeJPzpr36Gr2qNMNzM1ZOTJ0qwllfuWg1qaD oXMQHu0mvLZkAsK8xuqUBGFbX3Hpd3S3X/4k0I2xb69IeoOyUREo5VpjcxoZPiHv7RbJW0edAV9 gFCXPHEwwQvhIghPNWIvFzkHbK+V2AlMBWKYElY9gUC8hRnylWbZ3iAhERSO4pUlOkaKK7Tz7oT 5zqrgPP88PvZCWCgM09SBgvu56EcrCWj0UnKeW4/G0ygopLhJNNSM4iU7J1BiElyCVCWXg/VeEw 9543Qt071xsBO7qz8+DZZHvhwzBEL0wDNHm2BHx/enUOeOtGu/doTPClfgB04PprizH/dTvxYcH A== X-Received: by 2002:a5d:64e1:0:b0:485:8f42:e8cd with SMTP id ffacd0b85a97d-4858f42ec28mr6981886f8f.3.1788633569252; Sat, 05 Sep 2026 11:39:29 -0700 (PDT) Received: from 1c44f78ca37e.fritz.box ([2.210.128.137]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm16333603f8f.34.2026.09.05.11.39.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 11:39:28 -0700 (PDT) From: Abhin Parekadan Jose To: bhelgaas@google.com, lukas@wunner.de, mst@redhat.com Cc: linux-pci@vger.kernel.org, linux-kernel@vger.kernel.org, ilpo.jarvinen@linux.intel.com, kees@kernel.org, xueshuai@linux.alibaba.com, Abhin Parekadan Jose Subject: [PATCH RFC 3/3] misc: Add edu_srpoc surprise removal POC driver Date: Sat, 5 Sep 2026 18:39:00 +0000 Message-ID: <20260905183905.997833-4-abhinjoses@gmail.com> X-Mailer: git-send-email 2.51.1 In-Reply-To: <20260905183905.997833-1-abhinjoses@gmail.com> References: <20260905183905.997833-1-abhinjoses@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable A test driver for the QEMU edu device that reproduces the surprise removal hang described in MST's RFC v5 thread. - hacked in a reg to the edu device on qemu to raise a delayed irq - This driver writes to that reg in remove and waits for the irq to be handled. This simulates del_gendisk() blocked in blk_mq_freeze_queue_wait() Assisted-by: LLM Signed-off-by: Abhin Parekadan Jose --- drivers/misc/Makefile | 1 + drivers/misc/edu_srpoc.c | 169 +++++++++++++++++++++++++++++++++++++++ 2 files changed, 170 insertions(+) create mode 100644 drivers/misc/edu_srpoc.c diff --git a/drivers/misc/Makefile b/drivers/misc/Makefile index e8d8d5d88c0d..1479bf19c646 100644 --- a/drivers/misc/Makefile +++ b/drivers/misc/Makefile @@ -9,6 +9,7 @@ obj-$(CONFIG_AD525X_DPOT_I2C) +=3D ad525x_dpot-i2c.o obj-$(CONFIG_AD525X_DPOT_SPI) +=3D ad525x_dpot-spi.o obj-$(CONFIG_ATMEL_SSC) +=3D atmel-ssc.o obj-$(CONFIG_DUMMY_IRQ) +=3D dummy-irq.o +obj-y +=3D edu_srpoc.o obj-$(CONFIG_ICS932S401) +=3D ics932s401.o obj-$(CONFIG_LKDTM) +=3D lkdtm/ obj-$(CONFIG_TI_FPC202) +=3D ti_fpc202.o diff --git a/drivers/misc/edu_srpoc.c b/drivers/misc/edu_srpoc.c new file mode 100644 index 000000000000..f536bc4aa253 --- /dev/null +++ b/drivers/misc/edu_srpoc.c @@ -0,0 +1,169 @@ +// SPDX-License-Identifier: GPL-2.0 +/* + * edu_srpoc.c Surprise Removal POC driver for the QEMU edu device + * + * In remove(), schedules a delayed interrupt on the edu device and + * blocks waiting for it to complete. This simulates del_gendisk() + * blocked in blk_mq_freeze_queue_wait() on slow in-flight I/O. + * + * Surprise-remove the device during this window to reproduce the hang. + * + * edu BAR 0 registers used: + * 0x08 Factorial: write N to compute N! asynchronously + * 0x20 Status: write EDU_STATUS_IRQFACT to enable IRQ on completion + * 0x24 IRQ status: bit 0 =3D FACT_IRQ, bit 9 =3D DELAY_IRQ + * 0x30 Delayed IRQ: write N (ms). Hacked in this functionality(not ups= tream). + * 0x64 IRQ lower: write bitmask to ack + */ + +#include +#include +#include +#include +#include + +#define PCI_VENDOR_ID_EDU 0x1234 +#define PCI_DEVICE_ID_EDU 0x11e8 + +#define EDU_REG_FACT 0x08 +#define EDU_REG_STATUS 0x20 +#define EDU_REG_DELAYED_IRQ 0x30 +#define EDU_REG_IRQ_STATUS 0x24 +#define EDU_REG_IRQ_LOWER 0x64 + +#define EDU_STATUS_IRQFACT 0x80 +#define EDU_FACT_IRQ BIT(0) +#define EDU_DELAY_IRQ BIT(9) + +struct edu_dev { + struct pci_dev *pdev; + void __iomem *regs; + struct completion irq_done; +}; + +static irqreturn_t edu_irq_handler(int irq, void *data) +{ + struct edu_dev *edu =3D data; + u32 status; + + status =3D ioread32(edu->regs + EDU_REG_IRQ_STATUS); + if (!status) + return IRQ_NONE; + + iowrite32(status, edu->regs + EDU_REG_IRQ_LOWER); + + if (status & (EDU_FACT_IRQ | EDU_DELAY_IRQ)) { + complete(&edu->irq_done); + } + + return IRQ_HANDLED; +} + +static void edu_disconnect(struct work_struct *work) +{ + struct pci_dev *pdev =3D container_of(work, struct pci_dev, + disconnect_work); + struct edu_dev *edu =3D pci_get_drvdata(pdev); + + if (!pci_test_and_clear_disconnect_enable(pdev)) + return; + + if (!edu) + return; + + dev_info(&pdev->dev, "disconnect_work fired =E2=80=94 unblocking remove()= \n"); + complete(&edu->irq_done); +} + +static int edu_probe(struct pci_dev *pdev, const struct pci_device_id *id) +{ + struct edu_dev *edu; + int err; + + edu =3D devm_kzalloc(&pdev->dev, sizeof(*edu), GFP_KERNEL); + if (!edu) + return -ENOMEM; + + edu->pdev =3D pdev; + init_completion(&edu->irq_done); + + err =3D pci_enable_device(pdev); + if (err) + return err; + + err =3D pci_request_regions(pdev, "edu_srpoc"); + if (err) + goto err_disable; + + edu->regs =3D pci_iomap(pdev, 0, 0); + if (!edu->regs) { + err =3D -ENOMEM; + goto err_release; + } + + pci_set_master(pdev); + + err =3D pci_alloc_irq_vectors(pdev, 1, 1, PCI_IRQ_MSI | PCI_IRQ_INTX); + if (err < 0) + goto err_iounmap; + + err =3D request_irq(pci_irq_vector(pdev, 0), edu_irq_handler, + IRQF_SHARED, "edu_srpoc", edu); + if (err) + goto err_free_vectors; + + pci_set_drvdata(pdev, edu); + + INIT_WORK(&pdev->disconnect_work, edu_disconnect); + pci_set_disconnect_work(pdev); + + dev_info(&pdev->dev, "edu_srpoc probed\n"); + return 0; + +err_free_vectors: + pci_free_irq_vectors(pdev); +err_iounmap: + pci_iounmap(pdev, edu->regs); +err_release: + pci_release_regions(pdev); +err_disable: + pci_disable_device(pdev); + return err; +} + +static void edu_remove(struct pci_dev *pdev) +{ + struct edu_dev *edu =3D pci_get_drvdata(pdev); + + iowrite32(EDU_STATUS_IRQFACT, edu->regs + EDU_REG_STATUS); + iowrite32(600000, edu->regs + EDU_REG_DELAYED_IRQ); + + dev_info(&pdev->dev, "Waiting for IRQ in remove()\n"); + wait_for_completion(&edu->irq_done); + dev_info(&pdev->dev, "Unblocked, cleaning up\n"); + + pci_clear_disconnect_work(pdev); + free_irq(pci_irq_vector(pdev, 0), edu); + pci_free_irq_vectors(pdev); + pci_iounmap(pdev, edu->regs); + pci_release_regions(pdev); + pci_disable_device(pdev); +} + +static const struct pci_device_id edu_ids[] =3D { + { PCI_DEVICE(PCI_VENDOR_ID_EDU, PCI_DEVICE_ID_EDU) }, + { 0 } +}; +MODULE_DEVICE_TABLE(pci, edu_ids); + +static struct pci_driver edu_driver =3D { + .name =3D "edu_srpoc", + .id_table =3D edu_ids, + .probe =3D edu_probe, + .remove =3D edu_remove, +}; + +module_pci_driver(edu_driver); +MODULE_AUTHOR("Abhin Parekadan Jose"); +MODULE_DESCRIPTION("edu surprise removal POC driver"); +MODULE_LICENSE("GPL"); --=20 2.51.1