Re: [PATCH] dmaengine: fsl_raid: don't invoke client callback under desc_lock

From: Frank Li

Date: Sat Jul 18 2026 - 10:15:35 EST


On Fri, Jul 17, 2026 at 10:30:10PM -0700, Rosen Penev wrote:
> fsl_re_dequeue() holds re_chan->desc_lock while calling
> fsl_re_desc_done(), which synchronously invokes the DMA client completion
> callback via dmaengine_desc_get_callback_invoke(). If that callback
> submits new work (e.g. fsl_re_tx_submit()), it tries to reacquire the
> same desc_lock and deadlocks on the spinlock.
>
> Collect completed descriptors into a local list under the lock, then
> release the lock and invoke the callbacks before moving the descriptors
> to the ack queue.
>
> Fixes: ad80da658bbc ("dmaengine: Driver support for FSL RaidEngine device.")
> Assisted-by: opencode:hy3-free
> Signed-off-by: Rosen Penev <rosenp@xxxxxxxxx>
> ---

Reviewed-by: Frank Li <Frank.Li@xxxxxxx>

> drivers/dma/fsl_raid.c | 15 +++++++++++++--
> 1 file changed, 13 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/dma/fsl_raid.c b/drivers/dma/fsl_raid.c
> index 2d86f61105e5..bfaef6245695 100644
> --- a/drivers/dma/fsl_raid.c
> +++ b/drivers/dma/fsl_raid.c
> @@ -162,6 +162,7 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
> struct fsl_re_hw_desc *hwdesc;
> unsigned long flags;
> unsigned int count, oub_count;
> + LIST_HEAD(completed);
> int found;
>
> fsl_re_cleanup_descs(re_chan);
> @@ -182,8 +183,7 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
> }
>
> if (found) {
> - fsl_re_desc_done(desc);
> - list_move_tail(&desc->node, &re_chan->ack_q);
> + list_move_tail(&desc->node, &completed);
> } else {
> dev_err(re_chan->dev,
> "found hwdesc not in sw queue, discard it\n");
> @@ -196,6 +196,17 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
> FSL_RE_RMVD_JOB(1));
> }
> spin_unlock_irqrestore(&re_chan->desc_lock, flags);
> +
> + /* Invoke the client callbacks outside the channel lock. The callback
> + * may submit new work which re-acquires desc_lock, so holding it here
> + * would deadlock.
> + */
> + list_for_each_entry_safe(desc, _desc, &completed, node) {
> + fsl_re_desc_done(desc);
> + spin_lock_irqsave(&re_chan->desc_lock, flags);
> + list_move_tail(&desc->node, &re_chan->ack_q);
> + spin_unlock_irqrestore(&re_chan->desc_lock, flags);
> + }
> }
>
> /* Per Job Ring interrupt handler */
> --
> 2.55.0
>