The hangcheck timer can rearm itself or queue reset_work, while the V3D
interrupt queues job_done_work. vc4_gem_destroy() releases state
embedded in vc4_dev without first draining those asynchronous callbacks.

Shut down the timer so it cannot be rearmed, then cancel both work items
before GEM state is destroyed.

Fixes: d5b1a78a772f ("drm/vc4: Add support for drawing 3D frames.")
Signed-off-by: Hongyan Xu <[email protected]>
---
 drivers/gpu/drm/vc4/vc4_gem.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/gpu/drm/vc4/vc4_gem.c b/drivers/gpu/drm/vc4/vc4_gem.c
index e231c906709c..2443b62df89c 100644
--- a/drivers/gpu/drm/vc4/vc4_gem.c
+++ b/drivers/gpu/drm/vc4/vc4_gem.c
@@ -1194,6 +1194,10 @@ static void vc4_gem_destroy(struct drm_device *dev, void 
*unused)
 {
        struct vc4_dev *vc4 = to_vc4_dev(dev);
 
+       timer_shutdown_sync(&vc4->hangcheck.timer);
+       cancel_work_sync(&vc4->hangcheck.reset_work);
+       cancel_work_sync(&vc4->job_done_work);
+
        /* Waiting for exec to finish would need to be done before
         * unregistering V3D.
         */
-- 
2.50.1.windows.1

Reply via email to