Hi Hongyan,

This issue was already addressed in [1].

[1] https://gitlab.freedesktop.org/drm/misc/kernel/-/commit/94cf5971b1d04c6382437387c4dc3836cc7a1437

Best regards,
- Maíra

On 28/09/26 10:41, Hongyan Xu wrote:
The hangcheck timer can rearm itself or queue reset_work, while the V3D
interrupt queues job_done_work. vc4_gem_destroy() releases state
embedded in vc4_dev without first draining those asynchronous callbacks.

Shut down the timer so it cannot be rearmed, then cancel both work items
before GEM state is destroyed.

Fixes: d5b1a78a772f ("drm/vc4: Add support for drawing 3D frames.")
Signed-off-by: Hongyan Xu <[email protected]>
---
  drivers/gpu/drm/vc4/vc4_gem.c | 4 ++++
  1 file changed, 4 insertions(+)

diff --git a/drivers/gpu/drm/vc4/vc4_gem.c b/drivers/gpu/drm/vc4/vc4_gem.c
index e231c906709c..2443b62df89c 100644
--- a/drivers/gpu/drm/vc4/vc4_gem.c
+++ b/drivers/gpu/drm/vc4/vc4_gem.c
@@ -1194,6 +1194,10 @@ static void vc4_gem_destroy(struct drm_device *dev, void 
*unused)
  {
        struct vc4_dev *vc4 = to_vc4_dev(dev);
+ timer_shutdown_sync(&vc4->hangcheck.timer);
+       cancel_work_sync(&vc4->hangcheck.reset_work);
+       cancel_work_sync(&vc4->job_done_work);
+
        /* Waiting for exec to finish would need to be done before
         * unregistering V3D.
         */

Reply via email to