From: sashiko-bot@kernel.org
To: Zhipeng.wang_1@oss.nxp.com
Cc: Frank.Li@kernel.org, imx@lists.linux.dev
Subject: Re: [PATCH v6 5/9] irqchip/imx-irqsteer: Mask all interrupts in probe()
Date: Thu, 08 Oct 2026 09:18:11 +0000 [thread overview]
Message-ID: <sashiko-outbox-163917@kernel.org> (raw)
In-Reply-To: <20261008090231.796511-6-Zhipeng.wang_1@oss.nxp.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] irqchip/imx-irqsteer: missing wmb() allows interrupt storm race
--
commit e530007174d6dce33c6ec542e006f51e4a17dc73
Author: Zhipeng Wang <zhipeng.wang_1@nxp.com>
irqchip/imx-irqsteer: Mask all interrupts in probe()
This commit masks all input interrupts in probe() before setting up
chained handlers. This prevents an interrupt storm if a child interrupt
was left unmasked during driver unload, as the hardware would otherwise
assert it immediately upon re-mapping in the new domain.
> diff --git a/drivers/irqchip/irq-imx-irqsteer.c b/drivers/irqchip/irq-imx-irqsteer.c
> index 5acc04504e520..fa233de9bc2b2 100644
> --- a/drivers/irqchip/irq-imx-irqsteer.c
> +++ b/drivers/irqchip/irq-imx-irqsteer.c
[ ... ]
> @@ -239,6 +239,14 @@ static int imx_irqsteer_probe(struct platform_device *pdev)
> if (irqsteer_has_chanctrl(data->devtype_data))
> writel_relaxed(BIT(data->channel), data->regs + CHANCTRL);
>
> + /*
> + * Mask all interrupts before wiring up the chained handlers. CHANMASK
> + * has inverted polarity (a set bit enables the interrupt), so writing
> + * zero masks the source.
> + */
> + for (i = 0; i < data->reg_num; i++)
> + writel_relaxed(0, data->regs + CHANMASK(i, data->reg_num));
> +
[Severity: Medium]
Is an explicit memory barrier needed here to ensure the masks are applied
before the parent interrupt is unmasked?
Since writel_relaxed() does not provide a barrier, these writes to the IRQ
Steer hardware could be reordered. The parent GIC interrupt may be unmasked
before the IRQ Steer actually processes the interrupt masks, leaving a window
for the interrupt storm this patch is designed to prevent.
The parent GIC driver uses writel_relaxed() to unmask (for example,
gic_unmask_irq() in GICv2 or gic_poke_irq() in GICv3). Furthermore,
intervening locks like desc->lock in the IRQ core or irq_domain_mutex
provide only ACQUIRE and RELEASE semantics. On ARM64, an intervening RELEASE
followed by an ACQUIRE to different lock addresses can be reordered by the
CPU.
Could this allow the subsequent GIC relaxed write to cross the prior IRQ
Steer relaxed write, meaning a full wmb() is strictly required to order
writes to different I/O peripherals?
> ret = devm_pm_runtime_set_active_enabled(&pdev->dev);
> if (ret)
> goto out;
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261008090231.796511-1-Zhipeng.wang_1@oss.nxp.com?part=5
next prev parent reply other threads:[~2026-10-08 9:18 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 9:02 [PATCH v6 0/9] irqchip/imx-irqsteer: Allow building as module Zhipeng.wang_1
2026-10-08 9:02 ` [PATCH v6 1/9] irqchip/imx-irqsteer: Call chained_irq_exit() on the handler error path Zhipeng.wang_1
2026-10-08 9:02 ` [PATCH v6 2/9] irqchip/imx-irqsteer: Validate IRQ count before creating domain Zhipeng.wang_1
2026-10-08 20:36 ` Frank Li
2026-10-08 9:02 ` [PATCH v6 3/9] irqchip/imx-irqsteer: Dispose of parent IRQ mappings in remove() Zhipeng.wang_1
2026-10-08 9:02 ` [PATCH v6 4/9] irqchip/imx-irqsteer: Convert to devm_pm_runtime_set_active_enabled() Zhipeng.wang_1
2026-10-08 9:21 ` sashiko-bot
2026-10-08 20:46 ` Frank Li
2026-10-10 8:38 ` Zhipeng Wang (OSS)
2026-10-08 20:41 ` Frank Li
2026-10-10 8:26 ` Zhipeng Wang (OSS)
2026-10-08 9:02 ` [PATCH v6 5/9] irqchip/imx-irqsteer: Mask all interrupts in probe() Zhipeng.wang_1
2026-10-08 9:18 ` sashiko-bot [this message]
2026-10-08 20:59 ` Frank Li
2026-10-08 9:02 ` [PATCH v6 6/9] irqchip/imx-irqsteer: Let devres own the clock Zhipeng.wang_1
2026-10-08 9:13 ` sashiko-bot
2026-10-08 20:54 ` Frank Li
2026-10-08 9:02 ` [PATCH v6 7/9] irqchip/imx-irqsteer: Allow building as module Zhipeng.wang_1
2026-10-08 9:19 ` sashiko-bot
2026-10-08 9:02 ` [PATCH v6 8/9] genirq/irqdomain: Add devm_irq_domain_create_linear() Zhipeng.wang_1
2026-10-08 9:02 ` [PATCH v6 9/9] irqchip/imx-irqsteer: Use devm_irq_domain_create_linear() Zhipeng.wang_1
2026-10-08 9:15 ` sashiko-bot
2026-10-08 21:01 ` Frank Li
2026-10-10 9:06 ` Zhipeng Wang (OSS)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=sashiko-outbox-163917@kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=Zhipeng.wang_1@oss.nxp.com \
--cc=imx@lists.linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox