[PATCH v3 6/9] perf/cxl: Don't share the overflow interrupt, and keep it pinned
Dave Jiang <[email protected]> Fri, 31 Jul 2026 16:28:24 -0700
| Newsgroups | org.kernel.vger.linux-cxl,org.kernel.vger.linux-perf-users |
|---|---|
| Message-ID | <[email protected]> |
The PMU pins its overflow interrupt to info->on_cpu in the hotplug
callbacks, but requests it with only IRQF_SHARED | IRQF_NO_THREAD. Without
IRQF_NOBALANCING, irqbalance or a userspace smp_affinity write can move the
interrupt to another CPU. cxl_pmu_irq() then runs local64_cmpxchg() and
local64_add() on hwc->prev_count and event->count there, at the same time
as the managing CPU. local64_t is only atomic against same-CPU access, so
the counts get corrupted.
IRQF_NOBALANCING on its own does not fix that while the line is shared.
__setup_irq() only acts on the flag for the first action on a line, and a
co-owner has no reason to want our affinity. It would keep taking the
interrupt wherever its own affinity points, running our handler on the
wrong CPU.
Drop IRQF_SHARED and add IRQF_NOBALANCING. The spec only recommends that a
component give each CPMU instance a distinct Interrupt Message Number (CXL
r4.0 8.2.7.1.1), so a device may put several on one vector. Such a device
now fails to add the second CPMU instead of silently miscounting both.
Fixes: 5d7107c72796 ("perf: CXL Performance Monitoring Unit driver")
Reported-by: [email protected]
Closes: https://sashiko.dev/#/patchset/[email protected]?part=1
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Dave Jiang <[email protected]>
---
v3:
- Drop IRQF_SHARED as well, and retitle (Jonathan, Robin).
---
drivers/perf/cxl_pmu.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/drivers/perf/cxl_pmu.c b/drivers/perf/cxl_pmu.c
index c9e30cb149df..6fdc66a01fb6 100644
--- a/drivers/perf/cxl_pmu.c
+++ b/drivers/perf/cxl_pmu.c
@@ -784,7 +784,7 @@ static irqreturn_t cxl_pmu_irq(int irq, void *data)
overflowed = readq(base + CXL_PMU_OVERFLOW_REG);
- /* Interrupt may be shared, so maybe it isn't ours */
+ /* Nothing overflowed, so the device did not raise this */
if (!overflowed)
return IRQ_NONE;
@@ -887,7 +887,14 @@ static int cxl_pmu_probe(struct device *dev)
if (!irq_name)
return -ENOMEM;
- rc = devm_request_irq(dev, irq, cxl_pmu_irq, IRQF_SHARED | IRQF_NO_THREAD,
+ /*
+ * The handler must run on info->on_cpu, so the interrupt cannot be
+ * shared - IRQF_NOBALANCING is only honoured for the first action on a
+ * line, and a co-owner would keep taking the interrupt wherever its own
+ * affinity points.
+ */
+ rc = devm_request_irq(dev, irq, cxl_pmu_irq,
+ IRQF_NO_THREAD | IRQF_NOBALANCING,
irq_name, info);
if (rc)
return rc;
--
2.55.0