From: "Roger Pau Monné" <roger.pau@citrix.com>
To: Jason Andryuk <jason.andryuk@amd.com>
Cc: xen-devel@lists.xenproject.org,
Oleksii Kurochko <oleksii.kurochko@gmail.com>,
Jan Beulich <jbeulich@suse.com>,
Andrew Cooper <andrew.cooper3@citrix.com>
Subject: Re: [PATCH v2] x86/apic: Avoid infinite loop in io_apic_level_ack_pending()
Date: Tue, 14 Oct 2025 09:37:09 +0200 [thread overview]
Message-ID: <aO39pb3L42ktBol_@Mac.lan> (raw)
In-Reply-To: <20251013211106.8720-1-jason.andryuk@amd.com>
On Mon, Oct 13, 2025 at 05:11:06PM -0400, Jason Andryuk wrote:
> io_apic_level_ack_pending() will end up in an infinite loop if
> entry->pin == -1. entry does not change, so it will keep reading -1.
Do you know how you end up with an entry with pin == -1 on the
irq_pin_list? Are there systems with gaps in the GSI space between
IO-APICs? So far everything I saw had the IO-APIC in contiguous GSI
space.
> Convert to a proper for loop so that continue works. Add a new helper,
> next_entry(), to handle advancing to the next irq_pin_list entry.
>
> Fixes: f821102450a1 ("x86: IRQ Migration logic enhancement.")
> Signed-off-by: Jason Andryuk <jason.andryuk@amd.com>
> ---
> v2:
> continue (not break) for pin == -1.
>
> I added the next_entry() helper since putting the expression in the for
> loop is a little cluttered. The helper can also be re-used for other
> instances within the file.
> ---
> xen/arch/x86/io_apic.c | 14 +++++++++-----
> 1 file changed, 9 insertions(+), 5 deletions(-)
>
> diff --git a/xen/arch/x86/io_apic.c b/xen/arch/x86/io_apic.c
> index c384f10c1b..7b58345c96 100644
> --- a/xen/arch/x86/io_apic.c
> +++ b/xen/arch/x86/io_apic.c
> @@ -1586,14 +1586,21 @@ static int __init cf_check setup_ioapic_ack(const char *s)
> }
> custom_param("ioapic_ack", setup_ioapic_ack);
>
> +static struct irq_pin_list *next_entry(struct irq_pin_list *entry)
I think you can make the entry parameter const?
> +{
> + if ( !entry->next )
> + return NULL;
> +
> + return irq_2_pin + entry->next;
> +}
> +
> static bool io_apic_level_ack_pending(unsigned int irq)
> {
> struct irq_pin_list *entry;
> unsigned long flags;
>
> spin_lock_irqsave(&ioapic_lock, flags);
> - entry = &irq_2_pin[irq];
> - for (;;) {
> + for ( entry = &irq_2_pin[irq]; entry ; entry = next_entry(entry) ) {
I'm not sure where we stand regarding coding style here, but it looks
you either want to remove the space between parentheses (my
preference), or place the opening for braces on a newline. I would
possibly do:
for (entry = &irq_2_pin[irq]; entry; entry = next_entry(entry)) {
...
As I think it fits better given the small change and the surrounding
coding style.
> unsigned int reg;
> int pin;
Below here you can remove the:
if (!entry)
break;
Chunk, as the for loop already checks for this condition.
Otherwise looks good, I think we should consider for 4.21 inclusion.
Thanks, Roger.
next prev parent reply other threads:[~2025-10-14 7:37 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-10-13 21:11 [PATCH v2] x86/apic: Avoid infinite loop in io_apic_level_ack_pending() Jason Andryuk
2025-10-14 7:37 ` Roger Pau Monné [this message]
2025-10-14 12:24 ` Jason Andryuk
2025-10-15 12:59 ` Jan Beulich
2025-10-15 17:14 ` Jason Andryuk
2025-10-15 17:32 ` Roger Pau Monné
2025-10-16 6:40 ` Jan Beulich
2025-10-14 13:29 ` Oleksii Kurochko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aO39pb3L42ktBol_@Mac.lan \
--to=roger.pau@citrix.com \
--cc=andrew.cooper3@citrix.com \
--cc=jason.andryuk@amd.com \
--cc=jbeulich@suse.com \
--cc=oleksii.kurochko@gmail.com \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.