All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v5.10 0/2] x86/irq: Plug vector setup race
@ 2025-08-21 13:07 Jinjie Ruan
  2025-08-21 13:07 ` [PATCH v5.10 1/2] x86/irq: Factor out handler invocation from common_interrupt() Jinjie Ruan
  2025-08-21 13:07 ` [PATCH v5.10 2/2] x86/irq: Plug vector setup race Jinjie Ruan
  0 siblings, 2 replies; 4+ messages in thread
From: Jinjie Ruan @ 2025-08-21 13:07 UTC (permalink / raw)
  To: tglx, mingo, bp, dave.hansen, hpa, prarit, rui.y.wang, gregkh,
	x86, stable, linux-kernel
  Cc: ruanjinjie

There is a vector setup race, which overwrites the interrupt
descriptor in the per CPU vector array resulting in a disfunctional device.

CPU0				CPU1
				interrupt is raised in APIC IRR
				but not handled
  free_irq()
    per_cpu(vector_irq, CPU1)[vector] = VECTOR_SHUTDOWN;

  request_irq()			common_interrupt()
  				  d = this_cpu_read(vector_irq[vector]);

    per_cpu(vector_irq, CPU1)[vector] = desc;

    				  if (d == VECTOR_SHUTDOWN)
				    this_cpu_write(vector_irq[vector], VECTOR_UNUSED);

free_irq() cannot observe the pending vector in the CPU1 APIC as there is
no way to query the remote CPUs APIC IRR.

This requires that request_irq() uses the same vector/CPU as the one which
was freed, but this also can be triggered by a spurious interrupt.

Interestingly enough this problem managed to be hidden for more than a
decade.

Prevent this by reevaluating vector_irq under the vector lock, which is
held by the interrupt activation code when vector_irq is updated.

Fixes: 9345005f4eed ("x86/irq: Fix do_IRQ() interrupt warning for cpu hotplug retriggered irqs")
Cc: stable@vger.kernel.org#5.10.x
Cc: gregkh@linuxfoundation.org

Jacob Pan (1):
  x86/irq: Factor out handler invocation from common_interrupt()

Thomas Gleixner (1):
  x86/irq: Plug vector setup race

 arch/x86/kernel/irq.c | 70 ++++++++++++++++++++++++++++++++++---------
 1 file changed, 56 insertions(+), 14 deletions(-)

-- 
2.34.1


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2025-08-21 13:14 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-08-21 13:07 [PATCH v5.10 0/2] x86/irq: Plug vector setup race Jinjie Ruan
2025-08-21 13:07 ` [PATCH v5.10 1/2] x86/irq: Factor out handler invocation from common_interrupt() Jinjie Ruan
2025-08-21 13:13   ` kernel test robot
2025-08-21 13:07 ` [PATCH v5.10 2/2] x86/irq: Plug vector setup race Jinjie Ruan

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.