[PATCH v2] coresight: Fix scheduling while atomic in coresight_put_percpu_source_ref()

From: Mohamed Ayman

Date: Mon Jul 13 2026 - 19:00:55 EST


Dropping the last reference to a coresight_device triggers a kernel panic
on PREEMPT_RT builds due to a "scheduling while atomic" violation.

During CPU idle transitions, coresight_cpu_pm_notify() runs with
interrupts disabled. It eventually calls put_device(), which can
synchronously trigger the device's release callback and drop the parent
device's reference. On PREEMPT_RT, free_percpu() takes a sleeping lock
(rt-mutex), and the parent's release callback might also sleep. Sleeping
in this atomic PM context crashes the system.

A previous patch tried deferring just the coresight_device_release() body,
but this still left the synchronous put_device() call dangerously exposed
to sleeping parent release functions.

Fix this by entirely deferring the put_device() call to process context.
We add a pending counter (put_pending) and a work_struct to the coresight
device. When releasing a reference, we increment the counter and queue
the work. A worker thread then safely drains the counter and calls
put_device(). The counter prevents leaking references if multiple puts
are queued before the worker even has a chance to run.

To prevent a use-after-free race condition during module unload, the work
is queued on a dedicated coresight_wq which is safely drained and
destroyed in coresight_exit().

Finally, remove the unnecessary raw_spinlock_irqsave in the put path,
as dropping a reference doesn't require protecting the per-CPU table.

Signed-off-by: Mohamed Ayman <mohamedaymanworkspace@xxxxxxxxx>
---
drivers/hwtracing/coresight/coresight-core.c | 37 ++++++++++++++------
include/linux/coresight.h | 3 ++
2 files changed, 30 insertions(+), 10 deletions(-)

diff --git a/drivers/hwtracing/coresight/coresight-core.c b/drivers/hwtracing/coresight/coresight-core.c
index 6d65c43d5..e931e6bdc 100644
--- a/drivers/hwtracing/coresight/coresight-core.c
+++ b/drivers/hwtracing/coresight/coresight-core.c
@@ -63,6 +63,8 @@ static LIST_HEAD(coresight_dev_idx_list);

static const struct cti_assoc_op *cti_assoc_ops;

+static struct workqueue_struct *coresight_wq;
+
static struct coresight_node *
coresight_path_first_node(struct coresight_path *path)
{
@@ -132,6 +134,16 @@ static void coresight_clear_percpu_source(struct coresight_device *csdev)
per_cpu(csdev_source, csdev->cpu) = NULL;
}

+static void coresight_put_device_work(struct work_struct *work)
+{
+ struct coresight_device *csdev =
+ container_of(work, struct coresight_device, put_work);
+ int n = atomic_xchg(&csdev->put_pending, 0);
+
+ while (n--)
+ put_device(&csdev->dev);
+}
+
struct coresight_device *coresight_get_percpu_source_ref(int cpu)
{
struct coresight_device *csdev;
@@ -163,16 +175,9 @@ void coresight_put_percpu_source_ref(struct coresight_device *csdev)
if (!csdev || !coresight_is_percpu_source(csdev))
return;

- guard(raw_spinlock_irqsave)(&coresight_dev_lock);
+ atomic_inc(&csdev->put_pending);

- /*
- * TODO: coresight_device_release() is invoked to release resources when
- * the device's refcount reaches zero. It then calls free_percpu(),
- * which acquires pcpu_lock — a sleepable lock when PREEMPT_RT is
- * enabled. Since the raw spinlock coresight_dev_lock is held, this can
- * lead to a potential "scheduling while atomic" issue.
- */
- put_device(&csdev->dev);
+ queue_work(coresight_wq, &csdev->put_work);
}

struct coresight_device *coresight_get_source(struct coresight_path *path)
@@ -1563,6 +1568,9 @@ coresight_init_device(struct coresight_desc *desc)
csdev->dev.release = coresight_device_release;
csdev->dev.bus = &coresight_bustype;

+ INIT_WORK(&csdev->put_work, coresight_put_device_work);
+ atomic_set(&csdev->put_pending, 0);
+
return csdev;
}

@@ -2090,9 +2098,13 @@ static int __init coresight_init(void)
{
int ret;

+ coresight_wq = alloc_workqueue("coresight_wq", 0, 0);
+ if (!coresight_wq)
+ return -ENOMEM;
+
ret = bus_register(&coresight_bustype);
if (ret)
- return ret;
+ goto exit_wq;

ret = etm_perf_init();
if (ret)
@@ -2121,6 +2133,8 @@ static int __init coresight_init(void)
etm_perf_exit();
exit_bus_unregister:
bus_unregister(&coresight_bustype);
+exit_wq:
+ destroy_workqueue(coresight_wq);
return ret;
}

@@ -2133,6 +2147,9 @@ static void __exit coresight_exit(void)
etm_perf_exit();
bus_unregister(&coresight_bustype);
coresight_release_device_list();
+
+ if (coresight_wq)
+ destroy_workqueue(coresight_wq);
}

module_init(coresight_init);
diff --git a/include/linux/coresight.h b/include/linux/coresight.h
index ddf18c970..589a6c20d 100644
--- a/include/linux/coresight.h
+++ b/include/linux/coresight.h
@@ -13,6 +13,7 @@
#include <linux/perf_event.h>
#include <linux/sched.h>
#include <linux/platform_device.h>
+#include <linux/workqueue.h>

/* Peripheral id registers (0xFD0-0xFEC) */
#define CORESIGHT_PERIPHIDR4 0xfd0
@@ -293,6 +294,8 @@ struct coresight_device {
struct csdev_access access;
struct device dev;
struct coresight_path *path;
+ struct work_struct put_work;
+ atomic_t put_pending;
atomic_t mode;
int refcnt;
int cpu;
--
2.34.1