From: Jiang Liu <jiang.liu@linux.intel.com>
To: Suravee Suthikulpanit <Suravee.Suthikulpanit@amd.com>,
Thomas Gleixner <tglx@linutronix.de>
Cc: marc.zyngier@arm.com, linux-arm-kernel@lists.infradead.org,
linux-pci@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] irqdomain: Fix NULL pointer dererence in irq_domain_free_irqs_parent
Date: Fri, 21 Nov 2014 10:49:07 +0800 [thread overview]
Message-ID: <546EA823.8030401@linux.intel.com> (raw)
In-Reply-To: <546E9E8E.5000303@amd.com>
On 2014/11/21 10:08, Suravee Suthikulpanit wrote:
> On 11/20/2014 07:32 PM, Thomas Gleixner wrote:
>> On Thu, 20 Nov 2014, suravee.suthikulpanit@amd.com wrote:
>>> This patch checks if the parent domain is NULL before recursively
>>> freeing
>>> irqs in the parent domains.
>>
>> Which is nonsense, because if the thing has not been allocated in the
>> first place, then it cannot explode in the free path magically, except
>> there is a missing check in the allocation path error handling.
>>
>> And that's obviously not the case simply because this originates from:
>>> [<fffffe0000449278>] pci_disable_msix+0x40/0x50
>>
>
> Thomas,
>
> In this case, I have the following irq domain hierarchy:
>
> [GIC] -- [GICv2m] -- [MSI]
>
> which recursively calling the freeing function:
>
> In GIC domain, it currently defines the struct irq_domain_ops.free() with :
> --> irq_domain_free_irqs_top()
> |--> irq_domain_free_irqs_common()
> |--> irq_domain_free_irq_parent()
> |--> irq_domain_free_irqs_recursive()
>
> and there is no check before passing the NULL domain->parent into the
> irq_domain_free_irqs_recursive(), which causes the error.
>
> Since the GIC is the top most domain, it does not have parent domain.
> So, I'm not sure what is missing from the allocation path error
> handling, as you mentioned.
Hi Thomas,
We have had a discussion about this issue in another thread.
Originally irq_domain_free_irqs_common() is designed to be used by
irqdomains with parent. But there are desires to reuse it to support
irqdomains without parent too for code reduction.
So I suggest to change irq_domain_free_irqs_common() instead of
irq_domain_free_irqs_parent() because caller of
irq_domain_free_irqs_parent() should guarantee current domain do have
a parent.
I'm preparing a patch for this:)
Regards!
Gerry
>
> Thanks,
>
> Suravee
WARNING: multiple messages have this Message-ID (diff)
From: jiang.liu@linux.intel.com (Jiang Liu)
To: linux-arm-kernel@lists.infradead.org
Subject: [PATCH] irqdomain: Fix NULL pointer dererence in irq_domain_free_irqs_parent
Date: Fri, 21 Nov 2014 10:49:07 +0800 [thread overview]
Message-ID: <546EA823.8030401@linux.intel.com> (raw)
In-Reply-To: <546E9E8E.5000303@amd.com>
On 2014/11/21 10:08, Suravee Suthikulpanit wrote:
> On 11/20/2014 07:32 PM, Thomas Gleixner wrote:
>> On Thu, 20 Nov 2014, suravee.suthikulpanit at amd.com wrote:
>>> This patch checks if the parent domain is NULL before recursively
>>> freeing
>>> irqs in the parent domains.
>>
>> Which is nonsense, because if the thing has not been allocated in the
>> first place, then it cannot explode in the free path magically, except
>> there is a missing check in the allocation path error handling.
>>
>> And that's obviously not the case simply because this originates from:
>>> [<fffffe0000449278>] pci_disable_msix+0x40/0x50
>>
>
> Thomas,
>
> In this case, I have the following irq domain hierarchy:
>
> [GIC] -- [GICv2m] -- [MSI]
>
> which recursively calling the freeing function:
>
> In GIC domain, it currently defines the struct irq_domain_ops.free() with :
> --> irq_domain_free_irqs_top()
> |--> irq_domain_free_irqs_common()
> |--> irq_domain_free_irq_parent()
> |--> irq_domain_free_irqs_recursive()
>
> and there is no check before passing the NULL domain->parent into the
> irq_domain_free_irqs_recursive(), which causes the error.
>
> Since the GIC is the top most domain, it does not have parent domain.
> So, I'm not sure what is missing from the allocation path error
> handling, as you mentioned.
Hi Thomas,
We have had a discussion about this issue in another thread.
Originally irq_domain_free_irqs_common() is designed to be used by
irqdomains with parent. But there are desires to reuse it to support
irqdomains without parent too for code reduction.
So I suggest to change irq_domain_free_irqs_common() instead of
irq_domain_free_irqs_parent() because caller of
irq_domain_free_irqs_parent() should guarantee current domain do have
a parent.
I'm preparing a patch for this:)
Regards!
Gerry
>
> Thanks,
>
> Suravee
next prev parent reply other threads:[~2014-11-21 2:49 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-11-21 1:02 [PATCH] irqdomain: Fix NULL pointer dererence in irq_domain_free_irqs_parent suravee.suthikulpanit
2014-11-21 1:02 ` suravee.suthikulpanit at amd.com
2014-11-21 1:32 ` Thomas Gleixner
2014-11-21 1:32 ` Thomas Gleixner
2014-11-21 2:08 ` Suravee Suthikulpanit
2014-11-21 2:08 ` Suravee Suthikulpanit
2014-11-21 2:49 ` Jiang Liu [this message]
2014-11-21 2:49 ` Jiang Liu
2014-11-21 3:06 ` Suravee Suthikulpanit
2014-11-21 3:06 ` Suravee Suthikulpanit
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=546EA823.8030401@linux.intel.com \
--to=jiang.liu@linux.intel.com \
--cc=Suravee.Suthikulpanit@amd.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=marc.zyngier@arm.com \
--cc=tglx@linutronix.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.