Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Koichiro Den" <den@valinux.co.jp>
Cc: conor+dt@kernel.org, devicetree@vger.kernel.org,
	linux-pci@vger.kernel.org, wsa+renesas@sang-engineering.com,
	robh@kernel.org
Subject: Re: [PATCH 04/11] PCI: dwc: Add a host op to run before iMSI-RX status is read
Date: Fri, 18 Sep 2026 03:32:41 +0000	[thread overview]
Message-ID: <20260918033242.55BE61F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260918032038.2216471-5-den@valinux.co.jp>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] PCI: dwc: NULL pointer dereference in dw_chained_msi_isr()
--

commit 3a93530b14d46331da98ba1bc4fa4fde8fc72e4b
Author: Koichiro Den <den@valinux.co.jp>

PCI: dwc: Add a host op to run before iMSI-RX status is read

This commit adds a pre_msi_irq host callback invoked from the generic chained
handler before the MSI status is read. Returning true skips the MSI handling,
which prevents stalls when DBI accesses are issued right after an unexpected
link down.

> diff --git a/drivers/pci/controller/dwc/pcie-designware-host.c b/drivers/pci/controller/dwc/pcie-designware-host.c
> index f5a38e6fd8d79..ad013dd0a1662 100644
> --- a/drivers/pci/controller/dwc/pcie-designware-host.c
> +++ b/drivers/pci/controller/dwc/pcie-designware-host.c
> @@ -95,7 +95,8 @@ static void dw_chained_msi_isr(struct irq_desc *desc)
>  	chained_irq_enter(chip, desc);
>  
>  	pp = irq_desc_get_handler_data(desc);
> -	dw_handle_msi_irq(pp);
> +	if (!pp->ops->pre_msi_irq || !pp->ops->pre_msi_irq(pp))

[Severity: High]
Does this introduce a NULL pointer dereference when pp->ops is NULL?

Some glue drivers (like qcom_pcie_ecam_host_init) explicitly bypass
dw_pcie_host_init() and do not provide a pp->ops structure. On these platforms,
pp->ops is left NULL since the structure is zero-initialized via devm_kzalloc().

When the chained MSI interrupt handler fires during normal system operation,
evaluating pp->ops->pre_msi_irq would unconditionally dereference the NULL
pointer and crash the kernel. 

Would it be possible to add a safety check for pp->ops before checking for
the pre_msi_irq callback?

> +		dw_handle_msi_irq(pp);
>  
>  	chained_irq_exit(chip, desc);
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260918032038.2216471-1-den@valinux.co.jp?part=4

  reply	other threads:[~2026-09-18  3:32 UTC|newest]

Thread overview: 45+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-18  3:20 [PATCH 00/11] PCI: rcar-gen4: Recover from link down and route Root Port interrupts Koichiro Den
2026-09-18  3:20 ` [PATCH 01/11] PCI: dwc: Add Renesas to the RAS DES VSEC list Koichiro Den
2026-09-18  3:24   ` sashiko-bot
2026-09-22 19:40   ` Marek Vasut
2026-09-18  3:20 ` [PATCH 02/11] PCI: rcar-gen4: Drop the APP-based link_up check Koichiro Den
2026-09-18  3:25   ` sashiko-bot
2026-09-22 20:56   ` Marek Vasut
2026-09-23 14:56     ` Koichiro Den
2026-09-27 19:59       ` Marek Vasut
2026-09-28  4:20         ` Koichiro Den
2026-09-28 15:07           ` Marek Vasut
2026-09-18  3:20 ` [PATCH 03/11] dt-bindings: PCI: rcar-gen4: Add optional "aer" interrupt Koichiro Den
2026-09-18  3:25   ` sashiko-bot
2026-09-22 20:59   ` Marek Vasut
2026-09-28 18:32   ` Rob Herring (Arm)
2026-09-18  3:20 ` [PATCH 04/11] PCI: dwc: Add a host op to run before iMSI-RX status is read Koichiro Den
2026-09-18  3:32   ` sashiko-bot [this message]
2026-09-18  3:20 ` [PATCH 05/11] PCI: rcar-gen4: Split reusable hardware initialization Koichiro Den
2026-09-18  3:27   ` sashiko-bot
2026-09-22 21:15   ` Marek Vasut
2026-09-23 15:24     ` Koichiro Den
2026-09-27 20:43       ` Marek Vasut
2026-09-18  3:20 ` [PATCH 06/11] PCI: rcar-gen4: Add Root Port reset support Koichiro Den
2026-09-18  3:29   ` sashiko-bot
2026-09-22 21:22   ` Marek Vasut
2026-09-23 16:12     ` Koichiro Den
2026-09-27 22:25       ` Marek Vasut
2026-09-28  3:50         ` Koichiro Den
2026-09-28 17:47           ` Marek Vasut
2026-09-18  3:20 ` [PATCH 07/11] PCI: rcar-gen4: Recover the Root Port on link down Koichiro Den
2026-09-18  3:33   ` sashiko-bot
2026-09-22 21:44   ` Marek Vasut
2026-09-24 16:15     ` Koichiro Den
2026-09-27 22:37       ` Marek Vasut
2026-09-28  4:06         ` Koichiro Den
2026-09-28 17:36           ` Marek Vasut
2026-09-18  3:20 ` [PATCH 08/11] PCI: dwc: Let glue drivers hide the Root Port MSI capabilities Koichiro Den
2026-09-18  3:24   ` sashiko-bot
2026-09-18  3:20 ` [PATCH 09/11] PCI: rcar-gen4: Route Root Port AER to a virtual Root Port IRQ Koichiro Den
2026-09-18  3:32   ` sashiko-bot
2026-09-18  3:20 ` [PATCH 10/11] PCI: rcar-gen4: Route Root Port PME and bandwidth notifications Koichiro Den
2026-09-18  3:30   ` sashiko-bot
2026-09-18  3:20 ` [PATCH 11/11] arm64: dts: renesas: r8a779f0: Describe the PCIe AER interrupts Koichiro Den
2026-09-18  3:27   ` sashiko-bot
2026-09-22 21:31   ` Marek Vasut

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260918033242.55BE61F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=den@valinux.co.jp \
    --cc=devicetree@vger.kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=wsa+renesas@sang-engineering.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox