Re: [PATCH v4 10/10] arm_mpam: detect and enable MPAM-Fb PCC support

From: Jonathan Cameron

Date: Mon Jul 27 2026 - 19:38:17 EST


On Mon, 27 Jul 2026 21:57:15 +0530
Srivathsa L Rao <srivathsa.rao@xxxxxxxxxxxxxxxx> wrote:

> On 7/23/2026 9:24 PM, Andre Przywara wrote:
> > The Arm MPAM-Fb specification [1] describes a protocol to access MSC
> > registers through a firmware interface. This requires a shared memory
> > region to hold the message, and a mailbox to trigger the access.
> > For ACPI this is wrapped as a PCC channel, described using existing
> > ACPI abstractions.
> >
> > Add code to parse those PCC table descriptions associated with an MSC,
> > and store the parsed information in the MSC struct.
> > There can be multiple PCC channels, and each channel can serve multiple
> > MSCs, so we need to keep track of the channel usage, using a list and
> > a refcount.

Blank line for consistency

> > This will be used by the MPAM-Fb access wrapper code.
> >
> > [1] https://developer.arm.com/documentation/den0144/latest
> >
> > Signed-off-by: Andre Przywara <andre.przywara@xxxxxxx>

> > diff --git a/drivers/resctrl/mpam_devices.c b/drivers/resctrl/mpam_devices.c
> > index fea3161ffbe9..fc4b5f87fbe9 100644
> > --- a/drivers/resctrl/mpam_devices.c
> > +++ b/drivers/resctrl/mpam_devices.c

> > +static void mpam_pcc_chan_release(struct kref *ref)
> > +{
> > + struct mpam_pcc_chan *cur = container_of(ref, struct mpam_pcc_chan,
> > + refcount);
> > +
> > + pcc_mbox_free_channel(cur->pcc_chan);
> > + list_del(&cur->pcc_chans);
> > + kfree(cur);
> > +}
> > +
> > +static struct mpam_pcc_chan *mpam_pcc_chan_get(struct device *dev,
> > + int subspace_id)
> > +{
> > + struct mpam_pcc_chan *cur;
> > + int ret;
> > +
> > + guard(mutex)(&pcc_chan_list_lock);
> > +
> > + list_for_each_entry(cur, &pcc_chan_list, pcc_chans) {
> > + if (cur->subspace_id == subspace_id) {
> > + kref_get(&cur->refcount);
> > +
> > + return cur;
> > + }
> > + }
> > +
> > + cur = kzalloc_obj(*cur);
> > + if (!cur)
> > + return ERR_PTR(-ENOMEM);
> > +
> > + cur->pcc_cl.dev = dev;
> > + cur->pcc_cl.tx_block = true;
> > +
> > + cur->pcc_chan = pcc_mbox_request_channel(&cur->pcc_cl, subspace_id);
> > + if (IS_ERR(cur->pcc_chan)) {
> > + long err = PTR_ERR(cur->pcc_chan);
> > +
> > + kfree(cur);
> > + return ERR_PTR(err);
> > + }
> > +
> > + /* Timeout based on the "nominal latency" from the PCC ACPI table. */
> > + cur->pcc_cl.tx_tout = cur->pcc_chan->latency * 5;
> > +
> > + ret = devm_mutex_init(dev, &cur->pcc_chan_lock);
> > + if (ret)
> > + return ERR_PTR(ret);
> > +
>
> Here, devm_mutex_init() ties the lifetime of pcc_chan_lock to dev, which
> is &pdev->dev of the first MSC to call mpam_pcc_chan_get(). But
> mpam_pcc_chan is shared across multiple MSCs via kref, so it can
> outlive that first device.
>
> If a second MSC has incremented the refcount and is still active when
> the first MSC's device is removed, the devm cleanup on the first device
> would call mutex_destroy() on pcc_chan_lock while the second MSC may
> still be inside:
>
> guard(mutex)(&pcc_chan->pcc_chan_lock);
>
> I am not 100% sure this is reachable in practice — it may depend on
> the order in which platform devices are unbound, and whether that can
> happen with MSCs sharing a channel. I also note that devm_mutex_init()
> is a no-op on non-debug kernels, so this would only be observable with
> CONFIG_DEBUG_MUTEXES=y. But it felt worth raising in case
> it is a real path.
>
> If my understanding is correct, would it make sense to use a plain
> mutex_init() here instead, and move mutex_destroy() into
> mpam_pcc_chan_release() where the kref guarantees no concurrent users
> remain?

Good spot and fwiw Sashiko shouted about this one as well!
https://sashiko.dev/#/patchset/20260723155454.1760823-1-andre.przywara%40arm.com

It also called out the lack of error handling should this fail, but that
becomes irrelevant if the code is updated as you suggest.


>
> > + cur->subspace_id = subspace_id;
> > + kref_init(&cur->refcount);
> > +
> > + list_add_tail(&cur->pcc_chans, &pcc_chan_list);
> > +
> > + return cur;
> > +}
> > +

Thanks,

Jonathan