[PATCH v4 3/6] platform/x86/amd/hsmp: Serialize per-socket metric table reads with a mutex
From: Muralidhara M K
Date: Wed Jul 08 2026 - 00:24:50 EST
HSMP_GET_METRIC_TABLE makes the firmware refill a shared per-socket metric
DRAM region, which hsmp_metric_tbl_read() then copies out with
memcpy_fromio(). Two concurrent readers of the metrics_bin sysfs attribute
on the same socket can race: one can trigger a fresh fill while the other
is mid-copy and return a torn snapshot. (The hwmon path does not touch
this region; it only issues power messages via hsmp_send_message().)
Embed a struct mutex metric_read_lock in each hsmp_socket and hold it
across the fill-and-copy in hsmp_metric_tbl_read(). Add
hsmp_init_metric_read_locks() and hsmp_destroy_metric_read_locks(), which
take only struct hsmp_plat_device and iterate pdev->sock[] over
pdev->num_sockets so the caller cannot pass a count that disagrees with the
array.
Wire them into both front-ends' probe and teardown paths so the mutex is
always initialized before metrics_bin is exposed: the platform driver and
the ACPI driver both drive hsmp_metric_tbl_read() through the same 0444
metrics_bin attribute. Doing this in one patch avoids a bisection point
where an ACPI read would lock an uninitialized mutex.
Signed-off-by: Muralidhara M K <muralidhara.mk@xxxxxxx>
---
drivers/platform/x86/amd/hsmp/acpi.c | 3 +++
drivers/platform/x86/amd/hsmp/hsmp.c | 29 ++++++++++++++++++++++++++++
drivers/platform/x86/amd/hsmp/hsmp.h | 5 +++++
drivers/platform/x86/amd/hsmp/plat.c | 10 +++++++---
4 files changed, 44 insertions(+), 3 deletions(-)
diff --git a/drivers/platform/x86/amd/hsmp/acpi.c b/drivers/platform/x86/amd/hsmp/acpi.c
index eef799ce1fb8..095289ddb7e7 100644
--- a/drivers/platform/x86/amd/hsmp/acpi.c
+++ b/drivers/platform/x86/amd/hsmp/acpi.c
@@ -636,6 +636,8 @@ static int hsmp_acpi_probe(struct platform_device *pdev)
GFP_KERNEL);
if (!hsmp_pdev->sock)
return -ENOMEM;
+
+ hsmp_init_metric_read_locks(hsmp_pdev);
}
ret = init_acpi(&pdev->dev);
@@ -667,6 +669,7 @@ static void hsmp_acpi_remove(struct platform_device *pdev)
*/
if (hsmp_pdev->is_probed) {
hsmp_misc_deregister();
+ hsmp_destroy_metric_read_locks(hsmp_pdev);
hsmp_pdev->is_probed = false;
}
}
diff --git a/drivers/platform/x86/amd/hsmp/hsmp.c b/drivers/platform/x86/amd/hsmp/hsmp.c
index 4586d86f72a3..10fc21887308 100644
--- a/drivers/platform/x86/amd/hsmp/hsmp.c
+++ b/drivers/platform/x86/amd/hsmp/hsmp.c
@@ -10,9 +10,11 @@
#include <asm/amd/hsmp.h>
#include <linux/acpi.h>
+#include <linux/cleanup.h>
#include <linux/delay.h>
#include <linux/device.h>
#include <linux/io.h>
+#include <linux/mutex.h>
#include <linux/semaphore.h>
#include <linux/sysfs.h>
@@ -406,6 +408,15 @@ ssize_t hsmp_metric_tbl_read(struct hsmp_socket *sock, char *buf, size_t size)
msg.msg_id = HSMP_GET_METRIC_TABLE;
msg.sock_ind = sock->sock_ind;
+ /*
+ * HSMP_GET_METRIC_TABLE makes the firmware refill the shared metric
+ * DRAM region, then the snapshot is copied out of it. Serialize the
+ * fill-and-copy per socket so two concurrent readers cannot have one
+ * trigger a fresh fill while the other is mid-copy and return a torn
+ * snapshot.
+ */
+ guard(mutex)(&sock->metric_read_lock);
+
ret = hsmp_send_message(&msg);
if (ret)
return ret;
@@ -415,6 +426,24 @@ ssize_t hsmp_metric_tbl_read(struct hsmp_socket *sock, char *buf, size_t size)
}
EXPORT_SYMBOL_NS_GPL(hsmp_metric_tbl_read, "AMD_HSMP");
+void hsmp_init_metric_read_locks(struct hsmp_plat_device *pdev)
+{
+ u16 i;
+
+ for (i = 0; i < pdev->num_sockets; i++)
+ mutex_init(&pdev->sock[i].metric_read_lock);
+}
+EXPORT_SYMBOL_NS_GPL(hsmp_init_metric_read_locks, "AMD_HSMP");
+
+void hsmp_destroy_metric_read_locks(struct hsmp_plat_device *pdev)
+{
+ u16 i;
+
+ for (i = 0; i < pdev->num_sockets; i++)
+ mutex_destroy(&pdev->sock[i].metric_read_lock);
+}
+EXPORT_SYMBOL_NS_GPL(hsmp_destroy_metric_read_locks, "AMD_HSMP");
+
void hsmp_unmap_metric_tbls(struct hsmp_plat_device *pdev)
{
u16 i;
diff --git a/drivers/platform/x86/amd/hsmp/hsmp.h b/drivers/platform/x86/amd/hsmp/hsmp.h
index 98c82a4c0cc3..a43a8043a6cb 100644
--- a/drivers/platform/x86/amd/hsmp/hsmp.h
+++ b/drivers/platform/x86/amd/hsmp/hsmp.h
@@ -15,6 +15,7 @@
#include <linux/hwmon.h>
#include <linux/kconfig.h>
#include <linux/miscdevice.h>
+#include <linux/mutex.h>
#include <linux/pci.h>
#include <linux/semaphore.h>
#include <linux/sysfs.h>
@@ -43,6 +44,8 @@ struct hsmp_socket {
void __iomem *metric_tbl_addr;
void __iomem *virt_base_addr;
struct semaphore hsmp_sem;
+ /* Serializes HSMP_GET_METRIC_TABLE fill-and-copy for this socket */
+ struct mutex metric_read_lock;
char name[HSMP_ATTR_GRP_NAME_SIZE];
struct device *dev;
u16 sock_ind;
@@ -64,6 +67,8 @@ void hsmp_misc_deregister(void);
int hsmp_misc_register(struct device *dev);
int hsmp_get_tbl_dram_base(u16 sock_ind);
ssize_t hsmp_metric_tbl_read(struct hsmp_socket *sock, char *buf, size_t size);
+void hsmp_init_metric_read_locks(struct hsmp_plat_device *pdev);
+void hsmp_destroy_metric_read_locks(struct hsmp_plat_device *pdev);
void hsmp_unmap_metric_tbls(struct hsmp_plat_device *pdev);
struct hsmp_plat_device *get_hsmp_pdev(void);
#if IS_ENABLED(CONFIG_HWMON)
diff --git a/drivers/platform/x86/amd/hsmp/plat.c b/drivers/platform/x86/amd/hsmp/plat.c
index e7ee6e701e5a..d46dcb8c7f03 100644
--- a/drivers/platform/x86/amd/hsmp/plat.c
+++ b/drivers/platform/x86/amd/hsmp/plat.c
@@ -202,13 +202,15 @@ static int init_platform_device(struct device *dev)
}
/*
- * The metric tables are mapped with ioremap() rather than devm, so release
- * them explicitly. Registered as a devres action so it also runs on a probe
- * failure after init_platform_device() has mapped some of them.
+ * The metric tables are mapped with ioremap() rather than devm and the
+ * per-socket mutexes need an explicit mutex_destroy(), so tear both down
+ * here. Registered as a devres action so it also runs on a probe failure
+ * after init_platform_device() has mapped some tables.
*/
static void hsmp_pltdrv_release(void *data)
{
hsmp_unmap_metric_tbls(hsmp_pdev);
+ hsmp_destroy_metric_read_locks(hsmp_pdev);
}
static int hsmp_pltdrv_probe(struct platform_device *pdev)
@@ -221,6 +223,8 @@ static int hsmp_pltdrv_probe(struct platform_device *pdev)
if (!hsmp_pdev->sock)
return -ENOMEM;
+ hsmp_init_metric_read_locks(hsmp_pdev);
+
ret = devm_add_action_or_reset(&pdev->dev, hsmp_pltdrv_release, NULL);
if (ret)
return ret;
--
2.34.1