From: sashiko-bot@kernel.org
To: "Ciprian Costea" <ciprianmarian.costea@oss.nxp.com>
Cc: conor+dt@kernel.org, "Marc Kleine-Budde" <mkl@pengutronix.de>,
linux-can@vger.kernel.org, Frank.Li@kernel.org,
devicetree@vger.kernel.org,
"Vincent Mailhol" <mailhol@kernel.org>,
robh@kernel.org, "Oliver Hartkopp" <socketcan@hartkopp.net>,
imx@lists.linux.dev, "Oleksij Rempel" <o.rempel@pengutronix.de>
Subject: Re: [RESEND PATCH v6 3/6] can: flexcan: split rx/tx masks per mailbox IRQ line
Date: Fri, 14 Aug 2026 09:18:28 +0000 [thread overview]
Message-ID: <20260814091828.C9B3B1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260814090324.647898-4-ciprianmarian.costea@oss.nxp.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [Critical] Concurrent execution of split mailbox IRQ handlers corrupts the lockless `skb_irq_queue`, leading to list corruption and kernel panics.
--
--- Patch [3]: [RESEND PATCH v6 3/6] can: flexcan: split rx/tx masks per mailbox IRQ line ---
commit c6ddbabd84c6f2c763ef4c2438243c9db72c6384
Author: Ciprian Marian Costea <ciprianmarian.costea@oss.nxp.com>
can: flexcan: split rx/tx masks per mailbox IRQ line
This patch introduces FLEXCAN_SECONDARY_MB_IRQ_MB0_MASK and
FLEXCAN_SECONDARY_MB_IRQ_MB1_MASK to split the RX/TX masks between the two
mailbox IRQ lines on S32G2 platforms. It updates flexcan_do_mb() to accept
a mb_mask parameter so each IRQ handler only processes its corresponding
mailboxes.
> diff --git a/drivers/net/can/flexcan/flexcan-core.c b/drivers/net/can/flexcan/flexcan-core.c
> index 7dde2e623defe..8b70952f7f05d 100644
> --- a/drivers/net/can/flexcan/flexcan-core.c
> +++ b/drivers/net/can/flexcan/flexcan-core.c
[ ... ]
> @@ -1244,8 +1255,14 @@ static irqreturn_t flexcan_irq_mb(int irq, void *dev_id)
> struct net_device *dev = dev_id;
> struct flexcan_priv *priv = netdev_priv(dev);
> irqreturn_t handled;
> + u64 mb_mask = ~0ULL;
> +
> + if (priv->devtype_data.quirks & FLEXCAN_QUIRK_SECONDARY_MB_IRQ)
> + mb_mask = (irq == priv->irq_secondary_mb) ?
> + FLEXCAN_SECONDARY_MB_IRQ_MB1_MASK :
> + FLEXCAN_SECONDARY_MB_IRQ_MB0_MASK;
>
> - handled = flexcan_do_mb(dev);
> + handled = flexcan_do_mb(dev, mb_mask);
[Severity: Critical]
This is a pre-existing issue and was not introduced by this patch, but is
this safe from concurrent execution? If both primary and secondary MB IRQ
lines assert simultaneously on SMP systems, different CPUs could execute
flexcan_irq_mb() concurrently.
Both handlers would call flexcan_do_mb(), which eventually calls
can_rx_offload_irq_offload_timestamp(). That offload function modifies the
shared lockless queue without synchronization:
can_rx_offload_irq_offload_timestamp() {
...
__skb_queue_add_sort(&offload->skb_irq_queue, skb,
can_rx_offload_compare);
...
}
Could this concurrent lockless mutation of the doubly-linked list result
in list corruption or kernel panics when traffic arrives simultaneously for
mailboxes in both the mb-0 and mb-1 ranges?
>
> if (handled)
> can_rx_offload_irq_finish(&priv->offload);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260814090324.647898-1-ciprianmarian.costea@oss.nxp.com?part=3
next prev parent reply other threads:[~2026-08-14 9:18 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-14 9:03 [RESEND PATCH v6 0/6] can: flexcan: Add NXP S32N79 SoC support Ciprian Costea
2026-08-14 9:03 ` [RESEND PATCH v6 1/6] can: flexcan: use dedicated IRQ handlers for multi-IRQ platforms Ciprian Costea
2026-08-14 9:20 ` sashiko-bot
2026-08-14 9:03 ` [RESEND PATCH v6 2/6] can: flexcan: disable all IRQ lines in flexcan_chip_interrupts_enable() Ciprian Costea
2026-08-14 9:14 ` sashiko-bot
2026-08-14 9:03 ` [RESEND PATCH v6 3/6] can: flexcan: split rx/tx masks per mailbox IRQ line Ciprian Costea
2026-08-14 9:18 ` sashiko-bot [this message]
2026-08-14 9:03 ` [RESEND PATCH v6 4/6] dt-bindings: can: fsl,flexcan: add NXP S32N79 SoC support Ciprian Costea
2026-08-14 9:03 ` [RESEND PATCH v6 5/6] can: flexcan: add FLEXCAN_QUIRK_IRQ_BERR quirk Ciprian Costea
2026-08-14 9:17 ` sashiko-bot
2026-08-14 9:03 ` [RESEND PATCH v6 6/6] can: flexcan: add NXP S32N79 SoC support Ciprian Costea
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260814091828.C9B3B1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=ciprianmarian.costea@oss.nxp.com \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=imx@lists.linux.dev \
--cc=linux-can@vger.kernel.org \
--cc=mailhol@kernel.org \
--cc=mkl@pengutronix.de \
--cc=o.rempel@pengutronix.de \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=socketcan@hartkopp.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox