From: sashiko-bot@kernel.org
To: "Koichiro Den" <den@valinux.co.jp>
Cc: robh@kernel.org, wsa+renesas@sang-engineering.com,
devicetree@vger.kernel.org, linux-pci@vger.kernel.org,
conor+dt@kernel.org
Subject: Re: [PATCH v2 11/15] PCI: rcar-gen4: Recover the Root Port on link down
Date: Mon, 28 Sep 2026 17:07:57 +0000 [thread overview]
Message-ID: <20260928170757.C71FC1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260928165230.3397664-12-den@valinux.co.jp>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] pci: use-after-free of MSI IRQ domain during host teardown
- [Medium] pci: controller permanently wedged if Root Port removed during link down
--
commit 82b6de1b742f3cf8c20cc9550ebcd54c8a744889
Author: Koichiro Den <den@valinux.co.jp>
Subject: PCI: rcar-gen4: Recover the Root Port on link down
This patch adds handling for link down events on the R-Car PCIe controller.
It introduces a mechanism to defer Root Port recovery to a workqueue to
avoid host hangs from DBI accesses while the link is down. It also arms
this detection post-enumeration and disarms it during driver removal.
> diff --git a/drivers/pci/controller/dwc/pcie-rcar-gen4.c b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
> index 256410fb4b1cd..aa80232afabad 100644
> --- a/drivers/pci/controller/dwc/pcie-rcar-gen4.c
> +++ b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
[ ... ]
> @@ -559,15 +575,35 @@ static int rcar_gen4_pcie_host_msi_addr(struct dw_pcie_rp *pp, u32 *msi_addr)
> static void rcar_gen4_pcie_app_irq_sync_locked(struct rcar_gen4_pcie *rcar)
> {
[ ... ]
> + /*
> + * Note that rcar->rp_events_armed is not checked here because device
> + * removal may still need iMSI-RX interrupts after Root Port events have
> + * been disarmed.
> + */
> if (!rcar->reinit_pending && pp->use_imsi_rx && pci_msi_enabled())
> val |= MSI_CTRL_INT;
> writel(val, rcar->base + PCIEINTSTS0EN);
[ ... ]
> @@ -630,6 +666,44 @@ static int rcar_gen4_pcie_host_msi_init(struct dw_pcie_rp *pp)
[ ... ]
> +static void rcar_gen4_pcie_link_down_work(struct work_struct *work)
> +{
> + struct rcar_gen4_pcie *rcar =
> + container_of(work, struct rcar_gen4_pcie, link_down_work);
> + struct pci_dev *port;
> +
> + /* Hold a reference: the Root Port can be removed through sysfs. */
> + port = pci_get_slot(rcar->dw.pp.bridge->bus, PCI_DEVFN(0, 0));
> + if (!port)
> + return;
[Severity: Medium]
If the Root Port has been removed via sysfs and pci_get_slot() returns NULL,
does this early return leave reinit_pending set to true?
Since rcar_gen4_pcie_handle_link_down() sets reinit_pending to true before
scheduling this work, bypassing the reset sequence here would fail to clear
reinit_pending. Could this result in MSI interrupts being permanently masked?
> +
> + pci_host_handle_link_down(port);
> + pci_dev_put(port);
> +}
[ ... ]
> @@ -640,6 +714,10 @@ static irqreturn_t rcar_gen4_pcie_msi_irq_handler(int irq, void *data)
[ ... ]
> + /* Check reset requests before MSI handling, which accesses DBI. */
> + if (rcar_gen4_pcie_handle_link_down(rcar))
> + return IRQ_HANDLED;
> +
> status = readl(rcar->base + PCIEINTSTS0) &
> readl(rcar->base + PCIEINTSTS0EN);
> if (!(status & MSI_CTRL_INT))
> return IRQ_NONE;
>
> dw_handle_msi_irq(&rcar->dw.pp);
>
> return IRQ_HANDLED;
> }
[ ... ]
> @@ -918,6 +1023,8 @@ static int rcar_gen4_add_dw_pcie_rp(struct rcar_gen4_pcie *rcar)
[ ... ]
> static void rcar_gen4_remove_dw_pcie_rp(struct rcar_gen4_pcie *rcar)
> {
> + /* Cancel recovery work before removing the PCI bus */
> + rcar_gen4_pcie_rp_events_disarm(rcar);
> dw_pcie_host_deinit(&rcar->dw.pp);
> }
[Severity: High]
During host teardown, rcar_gen4_pcie_rp_events_disarm() is called which leaves
MSI interrupts enabled via rcar_gen4_pcie_app_irq_sync_locked().
The teardown then continues into the core:
drivers/pci/controller/dwc/pcie-designware-host.c:dw_pcie_host_deinit() {
...
if (pp->use_imsi_rx)
dw_pcie_free_msi(pp);
if (pp->ops->deinit)
pp->ops->deinit(pp);
...
}
Because dw_pcie_free_msi() frees the irq_domain before the driver's .deinit
callback has a chance to call free_irq(), what happens if a hardware
interrupt fires in this window?
Would rcar_gen4_pcie_msi_irq_handler() execute and call dw_handle_msi_irq(),
leading to a use-after-free when it dereferences the freed pp->irq_domain?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260928165230.3397664-1-den@valinux.co.jp?part=11
next prev parent reply other threads:[~2026-09-28 17:07 UTC|newest]
Thread overview: 58+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 16:52 [PATCH v2 00/15] PCI: rcar-gen4: Recover from link down and route Root Port interrupts Koichiro Den
2026-09-28 16:52 ` [PATCH v2 01/15] PCI: dwc: Add Renesas to the RAS DES VSEC list Koichiro Den
2026-09-28 16:56 ` sashiko-bot
2026-09-28 16:52 ` [PATCH v2 02/15] PCI: rcar-gen4: Check live link status in link_up() Koichiro Den
2026-09-28 16:57 ` sashiko-bot
2026-10-03 18:29 ` Marek Vasut
2026-10-03 18:51 ` Marek Vasut
2026-10-05 4:22 ` Koichiro Den
2026-10-05 5:59 ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 03/15] dt-bindings: PCI: rcar-gen4: Add optional "aer" interrupt Koichiro Den
2026-09-28 16:58 ` sashiko-bot
2026-09-30 10:31 ` Krzysztof Kozlowski
2026-10-03 20:00 ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 04/15] PCI: dwc: Export dw_handle_msi_irq() Koichiro Den
2026-09-28 16:58 ` sashiko-bot
2026-10-03 20:02 ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 05/15] PCI: rcar-gen4: Move deinitialization helpers before SoC initialization Koichiro Den
2026-09-28 16:57 ` sashiko-bot
2026-10-03 20:23 ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 06/15] PCI: rcar-gen4: Assert resets when Gen5 PHY initialization fails Koichiro Den
2026-09-28 16:59 ` sashiko-bot
2026-10-03 21:34 ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 07/15] PCI: rcar-gen4: Separate hardware setup from resource acquisition Koichiro Den
2026-09-28 16:56 ` sashiko-bot
2026-10-03 23:41 ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 08/15] PCI: rcar-gen4: Add a controller reinitialization callback Koichiro Den
2026-09-28 17:02 ` sashiko-bot
2026-10-03 23:54 ` Marek Vasut
2026-10-05 4:31 ` Koichiro Den
2026-09-28 16:52 ` [PATCH v2 09/15] PCI: rcar-gen4: Add Root Port reset support Koichiro Den
2026-09-28 17:03 ` sashiko-bot
2026-10-04 0:11 ` Marek Vasut
2026-10-05 6:14 ` Koichiro Den
2026-09-28 16:52 ` [PATCH v2 10/15] PCI: rcar-gen4: Take over the iMSI-RX interrupt Koichiro Den
2026-09-28 17:04 ` sashiko-bot
2026-09-29 17:43 ` Geert Uytterhoeven
2026-09-30 6:38 ` Koichiro Den
2026-10-04 1:17 ` Marek Vasut
2026-10-04 0:53 ` Marek Vasut
2026-10-05 17:05 ` Koichiro Den
2026-09-28 16:52 ` [PATCH v2 11/15] PCI: rcar-gen4: Recover the Root Port on link down Koichiro Den
2026-09-28 17:07 ` sashiko-bot [this message]
2026-10-04 1:38 ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 12/15] PCI: dwc: Let glue drivers hide the Root Port MSI capabilities Koichiro Den
2026-09-28 16:59 ` sashiko-bot
2026-09-28 16:52 ` [PATCH v2 13/15] PCI: rcar-gen4: Route Root Port AER to a virtual Root Port IRQ Koichiro Den
2026-09-28 17:06 ` sashiko-bot
2026-10-04 2:52 ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 14/15] PCI: rcar-gen4: Route Root Port PME and bandwidth notifications Koichiro Den
2026-09-28 17:08 ` sashiko-bot
2026-10-04 4:40 ` Marek Vasut
2026-10-05 17:09 ` Koichiro Den
2026-09-28 16:52 ` [PATCH v2 15/15] arm64: dts: renesas: r8a779f0: Describe the PCIe AER interrupts Koichiro Den
2026-09-28 16:59 ` sashiko-bot
2026-10-03 20:00 ` Marek Vasut
2026-10-05 17:11 ` Koichiro Den
2026-10-06 5:20 ` Marek Vasut
2026-10-03 17:46 ` [PATCH v2 00/15] PCI: rcar-gen4: Recover from link down and route Root Port interrupts Marek Vasut
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928170757.C71FC1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=den@valinux.co.jp \
--cc=devicetree@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=wsa+renesas@sang-engineering.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox