[PATCH v5 1/3] gpu: nova-core: move the debugfs root into the module data

From: Vladislav Zaharov

Date: Wed Sep 23 2026 - 00:56:48 EST


The debugfs root lives in a static that init() fills in and a guard
field of the module data clears again. That costs a `static mut`, an
unsafe write on each side and a guard type whose only job is to undo
the write.

It also leaks. try_pin_init! drops only the fields it has already
built, and the guard is written after the Registration, so a
registration that fails leaves the guard unbuilt and the static set.
Statics are never dropped, and the module is unloaded right away, so
the directory outlives everything that could remove it. The next load
then finds the name taken: debugfs_create_dir() returns -EEXIST, which
Entry keeps as it would any other pointer, and the driver comes up with
no debugfs at all until the machine is rebooted.

Have the module data own a DebugfsData instead, built before the
registration and dropped after it, and keep only a pointer to it in the
static, for devices that have no other way to reach the data of their
module. What is left is one unsafe read for the users and a single write
when the data is built, with no guard type. A registration that fails
now drops the data that was built before it, and the directory goes with
it.

Assisted-by: LLM
Signed-off-by: Vladislav Zaharov <vladazaharova2018@xxxxxxxxx>
---
drivers/gpu/nova-core/gsp.rs | 10 +---
drivers/gpu/nova-core/nova_core.rs | 73 ++++++++++++++++++++++--------
2 files changed, 55 insertions(+), 28 deletions(-)

diff --git a/drivers/gpu/nova-core/gsp.rs b/drivers/gpu/nova-core/gsp.rs
index dda58095f40b..01ed4adffe93 100644
--- a/drivers/gpu/nova-core/gsp.rs
+++ b/drivers/gpu/nova-core/gsp.rs
@@ -199,15 +199,7 @@ pub(crate) fn new(
logrm,
};

- #[allow(static_mut_refs)]
- // SAFETY: `DEBUGFS_ROOT` is created before driver registration and cleared
- // after driver unregistration, so no probe() can race with its modification.
- //
- // PANIC: `DEBUGFS_ROOT` cannot be `None` here. It is set before driver
- // registration and cleared after driver unregistration, so it is always
- // `Some` for the entire lifetime that probe() can be called.
- let log_parent: &debugfs::Dir = unsafe { crate::DEBUGFS_ROOT.as_ref() }
- .expect("DEBUGFS_ROOT not initialized");
+ let log_parent: &debugfs::Dir = crate::debugfs_data(dev).root();

log_parent.scope(log_buffers, dev.name(), |logs, dir| {
dir.read_binary_file(c"loginit", &logs.loginit.0);
diff --git a/drivers/gpu/nova-core/nova_core.rs b/drivers/gpu/nova-core/nova_core.rs
index 1133c6ce5c55..08509f64770e 100644
--- a/drivers/gpu/nova-core/nova_core.rs
+++ b/drivers/gpu/nova-core/nova_core.rs
@@ -4,6 +4,7 @@

use kernel::{
debugfs,
+ device,
driver::Registration,
pci,
prelude::*,
@@ -30,40 +31,74 @@

pub(crate) const MODULE_NAME: &core::ffi::CStr = <LocalModule as kernel::ModuleMetadata>::NAME;

-// TODO: Move this into per-module data once that exists.
-static mut DEBUGFS_ROOT: Option<debugfs::Dir> = None;
+/// Pointer to the [`DebugfsData`] the module owns.
+///
+/// A device has no way to reach the data of its module, so code running on behalf of a bound
+/// device goes through here instead.
+/// Written once, while the module data is built, and never again: what it points at is dropped
+/// only after the driver is unregistered, so it is good for as long as any device is bound, and
+/// is not read outside of that.
+// TODO: Drop this once devices can reach the data of their module.
+static mut DEBUGFS_DATA: *const DebugfsData = core::ptr::null();

-/// Guard that clears `DEBUGFS_ROOT` when dropped.
-struct DebugfsRootGuard;
+/// Data the module shares with every GPU it drives.
+///
+/// Reached from a device through [`debugfs_data()`].
+#[pin_data]
+pub(crate) struct DebugfsData {
+ /// Root directory of the driver in debugfs.
+ root: debugfs::Dir,
+}
+
+impl DebugfsData {
+ /// Creates the shared data.
+ fn new() -> impl PinInit<Self> {
+ pin_init!(Self {
+ root: debugfs::Dir::new(c"nova-core"),
+ })
+ }

-impl Drop for DebugfsRootGuard {
- fn drop(&mut self) {
- // SAFETY: This guard is dropped after `_driver` (due to field order),
- // so the driver is unregistered and no probe() can be running.
- unsafe { DEBUGFS_ROOT = None };
+ /// Returns the root directory of the driver in debugfs.
+ pub(crate) fn root(&self) -> &debugfs::Dir {
+ &self.root
}
}

+/// Returns the data the module shares with its devices.
+///
+/// The bound device is what makes this sound: the data is built before the driver is registered
+/// and dropped after it is unregistered, so it outlives every device that is bound, and the
+/// returned reference cannot be held past the one it is taken for.
+pub(crate) fn debugfs_data<'a>(_dev: &'a device::Device<device::Bound>) -> &'a DebugfsData {
+ // SAFETY: A device can only be bound once the driver is registered, which happens after
+ // `DEBUGFS_DATA` is written, so it points at the data of this module, which lives at least
+ // as long as the caller's device is bound.
+ unsafe { &*DEBUGFS_DATA }
+}
+
#[pin_data]
struct NovaCoreModule {
- // Fields are dropped in declaration order, so `_driver` is dropped first,
- // then `_debugfs_guard` clears `DEBUGFS_ROOT`.
+ // Fields are dropped in declaration order, so the registration goes first and no probe() can
+ // still be running once the shared data is torn down. `init()` builds them the other way
+ // round, as the data has to be there before the first probe() reaches for it.
#[pin]
_driver: Registration<pci::Adapter<driver::NovaCoreDriver>>,
- _debugfs_guard: DebugfsRootGuard,
+ #[pin]
+ _debugfs: DebugfsData,
}

impl InPlaceModule for NovaCoreModule {
fn init(module: &'static kernel::ThisModule) -> impl PinInit<Self, Error> {
- let dir = debugfs::Dir::new(c"nova-core");
-
- // SAFETY: We are the only driver code running during init, so there
- // cannot be any concurrent access to `DEBUGFS_ROOT`.
- unsafe { DEBUGFS_ROOT = Some(dir) };
-
try_pin_init!(Self {
+ _debugfs <- DebugfsData::new(),
+ _: {
+ // SAFETY: Nothing reads `DEBUGFS_DATA` before a device is bound, which cannot
+ // happen until the driver is registered below. What it points at is dropped only
+ // once the driver is unregistered, so it is valid for as long as any device is
+ // bound, and nothing reads it outside of that.
+ unsafe { DEBUGFS_DATA = &*_debugfs };
+ },
_driver <- Registration::new(MODULE_NAME, module),
- _debugfs_guard: DebugfsRootGuard,
})
}
}
--
2.55.0