Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Koichiro Den" <den@valinux.co.jp>
Cc: linux-pci@vger.kernel.org, robh@kernel.org,
	wsa+renesas@sang-engineering.com, devicetree@vger.kernel.org,
	conor+dt@kernel.org
Subject: Re: [PATCH v2 10/15] PCI: rcar-gen4: Take over the iMSI-RX interrupt
Date: Mon, 28 Sep 2026 17:04:54 +0000	[thread overview]
Message-ID: <20260928170455.1555D1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260928165230.3397664-11-den@valinux.co.jp>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] PCI: rcar-gen4: UAF in MSI IRQ domain due to early freeing in teardown
--

commit af654bd32d2cbf225a560670eb31511987c35382
Author: Koichiro Den <den@valinux.co.jp>

PCI: rcar-gen4: Take over the iMSI-RX interrupt

This patch requests the "msi" interrupt in the driver and demultiplexes
the MSIs to handle controller reset requests and Root Port notifications
on the same line. The driver takes ownership of the interrupt instead of
the DesignWare core.

> diff --git a/drivers/pci/controller/dwc/pcie-rcar-gen4.c b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
> index d3f04358bbe31..256410fb4b1cd 100644
> --- a/drivers/pci/controller/dwc/pcie-rcar-gen4.c
> +++ b/drivers/pci/controller/dwc/pcie-rcar-gen4.c

[ ... ]

> @@ -818,6 +878,9 @@ static void rcar_gen4_pcie_host_deinit(struct dw_pcie_rp *pp)
>  	struct dw_pcie *dw = to_dw_pcie_from_pp(pp);
>  	struct rcar_gen4_pcie *rcar = to_rcar_gen4_pcie(dw);
>  
> +	/* Stop the handler before asserting reset and disabling the clocks. */
> +	free_irq(rcar->msi_irq, rcar);
> +

[Severity: High]
Does this setup introduce a use-after-free risk during teardown?

During driver removal or probe failure, dw_pcie_host_deinit() calls
dw_pcie_free_msi() to free the MSI IRQ domain before it calls the driver's
.deinit callback:

drivers/pci/controller/dwc/pcie-designware-host.c:dw_pcie_host_deinit() {
	...
	if (pp->use_imsi_rx)
		dw_pcie_free_msi(pp);

	if (pp->ops->deinit)
		pp->ops->deinit(pp);
	...
}

Because pp->msi_irq[0] is set to -ENODEV, the DWC core does not unhook any
handler. This means rcar_gen4_pcie_msi_irq_handler() remains active and
could execute before free_irq() is called in rcar_gen4_pcie_host_deinit().

If an MSI is latched just before the link is stopped, the active handler
will dispatch to the DWC core via dw_handle_msi_irq(&rcar->dw.pp) and
dereference the freed pp->irq_domain.

While the commit message acknowledges this as a gap that might require a
common DWC core fix, this patch actively introduces a crash path for this
driver that could be triggered reliably on driver unbind or probe error
with pending MSIs.

Could we synchronize or stop the handler earlier to prevent this dereference?

>  	rcar_gen4_pcie_host_perst_assert(pp, true);
>  	rcar->drvdata->deinit(rcar);
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260928165230.3397664-1-den@valinux.co.jp?part=10

  reply	other threads:[~2026-09-28 17:04 UTC|newest]

Thread overview: 58+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 16:52 [PATCH v2 00/15] PCI: rcar-gen4: Recover from link down and route Root Port interrupts Koichiro Den
2026-09-28 16:52 ` [PATCH v2 01/15] PCI: dwc: Add Renesas to the RAS DES VSEC list Koichiro Den
2026-09-28 16:56   ` sashiko-bot
2026-09-28 16:52 ` [PATCH v2 02/15] PCI: rcar-gen4: Check live link status in link_up() Koichiro Den
2026-09-28 16:57   ` sashiko-bot
2026-10-03 18:29   ` Marek Vasut
2026-10-03 18:51     ` Marek Vasut
2026-10-05  4:22       ` Koichiro Den
2026-10-05  5:59         ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 03/15] dt-bindings: PCI: rcar-gen4: Add optional "aer" interrupt Koichiro Den
2026-09-28 16:58   ` sashiko-bot
2026-09-30 10:31   ` Krzysztof Kozlowski
2026-10-03 20:00   ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 04/15] PCI: dwc: Export dw_handle_msi_irq() Koichiro Den
2026-09-28 16:58   ` sashiko-bot
2026-10-03 20:02   ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 05/15] PCI: rcar-gen4: Move deinitialization helpers before SoC initialization Koichiro Den
2026-09-28 16:57   ` sashiko-bot
2026-10-03 20:23   ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 06/15] PCI: rcar-gen4: Assert resets when Gen5 PHY initialization fails Koichiro Den
2026-09-28 16:59   ` sashiko-bot
2026-10-03 21:34   ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 07/15] PCI: rcar-gen4: Separate hardware setup from resource acquisition Koichiro Den
2026-09-28 16:56   ` sashiko-bot
2026-10-03 23:41   ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 08/15] PCI: rcar-gen4: Add a controller reinitialization callback Koichiro Den
2026-09-28 17:02   ` sashiko-bot
2026-10-03 23:54   ` Marek Vasut
2026-10-05  4:31     ` Koichiro Den
2026-09-28 16:52 ` [PATCH v2 09/15] PCI: rcar-gen4: Add Root Port reset support Koichiro Den
2026-09-28 17:03   ` sashiko-bot
2026-10-04  0:11   ` Marek Vasut
2026-10-05  6:14     ` Koichiro Den
2026-09-28 16:52 ` [PATCH v2 10/15] PCI: rcar-gen4: Take over the iMSI-RX interrupt Koichiro Den
2026-09-28 17:04   ` sashiko-bot [this message]
2026-09-29 17:43   ` Geert Uytterhoeven
2026-09-30  6:38     ` Koichiro Den
2026-10-04  1:17       ` Marek Vasut
2026-10-04  0:53   ` Marek Vasut
2026-10-05 17:05     ` Koichiro Den
2026-09-28 16:52 ` [PATCH v2 11/15] PCI: rcar-gen4: Recover the Root Port on link down Koichiro Den
2026-09-28 17:07   ` sashiko-bot
2026-10-04  1:38   ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 12/15] PCI: dwc: Let glue drivers hide the Root Port MSI capabilities Koichiro Den
2026-09-28 16:59   ` sashiko-bot
2026-09-28 16:52 ` [PATCH v2 13/15] PCI: rcar-gen4: Route Root Port AER to a virtual Root Port IRQ Koichiro Den
2026-09-28 17:06   ` sashiko-bot
2026-10-04  2:52   ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 14/15] PCI: rcar-gen4: Route Root Port PME and bandwidth notifications Koichiro Den
2026-09-28 17:08   ` sashiko-bot
2026-10-04  4:40   ` Marek Vasut
2026-10-05 17:09     ` Koichiro Den
2026-09-28 16:52 ` [PATCH v2 15/15] arm64: dts: renesas: r8a779f0: Describe the PCIe AER interrupts Koichiro Den
2026-09-28 16:59   ` sashiko-bot
2026-10-03 20:00   ` Marek Vasut
2026-10-05 17:11     ` Koichiro Den
2026-10-06  5:20       ` Marek Vasut
2026-10-03 17:46 ` [PATCH v2 00/15] PCI: rcar-gen4: Recover from link down and route Root Port interrupts Marek Vasut

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928170455.1555D1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=den@valinux.co.jp \
    --cc=devicetree@vger.kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=wsa+renesas@sang-engineering.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox