From: sashiko-bot@kernel.org
To: "Aaradhana Sahu" <aaradhana.sahu@oss.qualcomm.com>
Cc: conor+dt@kernel.org, robh@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH ath-next 11/17] wifi: ath12k: Add platform MSI support for CE
Date: Thu, 08 Oct 2026 10:41:32 +0000 [thread overview]
Message-ID: <sashiko-outbox-164035@kernel.org> (raw)
In-Reply-To: <20261008-mpp_bringup-v1-11-2c5797b5e4ac@oss.qualcomm.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Resource leak of non-devm MSIs and IRQs on ath12k_ahb_probe() error paths
--
commit ad41050e8b81bf8d1dd6e4fe6253604d235fd347
Author: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
wifi: ath12k: Add platform MSI support for CE
This commit adds support for configuring Copy Engine (CE) interrupts
through platform MSI on hybrid AHB devices like the QCN6432. It introduces
an IPCI MSI configuration, allocates MSI vectors from the platform MSI
domain, and registers CE interrupt handlers using the allocated vectors.
> diff --git a/drivers/net/wireless/ath/ath12k/pcic.c b/drivers/net/wireless/ath/ath12k/pcic.c
> --- a/drivers/net/wireless/ath/ath12k/pcic.c
> +++ b/drivers/net/wireless/ath/ath12k/pcic.c
[ ... ]
> @@ -154,3 +155,157 @@ void ath12k_pcic_write32(struct ath12k_base *ab, u32 offset, u32 value)
[ ... ]
> +static int ath12k_pcic_ce_irq_config(struct ath12k_base *ab,
> + struct msi_desc **msi_desc, int num_msi)
> +{
[ ... ]
> + scnprintf(ce_pipe->irq_name, sizeof(ce_pipe->irq_name),
> + "pcic%u_wlan_ce_%u", userpd_id, i);
> + ret = request_irq(desc->irq, ath12k_pcic_ce_interrupt_handler,
> + IRQF_SHARED, ce_pipe->irq_name, ce_pipe);
[Severity: High]
Does this leak the requested IRQ on the probe error path?
Since request_irq() is used here instead of devm_request_irq(), it requires
explicit cleanup. This function is called by ath12k_ahb_config_irq() during
ath12k_ahb_probe(). If a subsequent initialization step in probe fails
(such as arch_init or core_init), the error path jumps to labels like
err_deinit_arch or err_core_free.
However, the error path in ath12k_ahb_probe() does not appear to call
ath12k_ahb_disable_irq() or ath12k_pcic_free_irq() to free these IRQs.
If the device context (ab) is subsequently freed by ath12k_core_free()
while the interrupt handlers remain registered, could this lead to a
use-after-free panic if an interrupt fires?
> + if (ret) {
> + ath12k_warn(ab, "failed to request irq %d: %d\n", irq_idx, ret);
> + ath12k_pci_free_ce_irq(ab, i);
> + return ret;
> + }
[ ... ]
> +int ath12k_pcic_config_irq(struct ath12k_base *ab)
> +{
> + int user_base_data, base_vector, num_vectors;
> + struct platform_device *pdev = ab->pdev;
> + int ret;
> +
> + ab->msi.config = &ath12k_msi_config[ATH12K_MSI_CONFIG_IPCI];
> +
> + ret = platform_device_msi_init_and_alloc_irqs(&pdev->dev,
> + ab->msi.config->total_vectors,
> + ath12k_msi_msg_handler);
[Severity: High]
Similarly, does this platform MSI domain allocation get leaked on the
ath12k_ahb_probe() error path?
platform_device_msi_init_and_alloc_irqs() is not devres managed, so the
domain must be explicitly destroyed via platform_device_msi_free_irqs_all().
Because ath12k_ahb_probe() does not call the corresponding free routine when
it encounters an error after this point, are these MSI vectors leaked?
> + if (ret)
> + return ret;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261008-mpp_bringup-v1-0-2c5797b5e4ac@oss.qualcomm.com?part=11
next prev parent reply other threads:[~2026-10-08 10:41 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 10:23 [PATCH ath-next 00/17] wifi: ath12k: Add support for QCN6432 Aaradhana Sahu
2026-10-08 10:23 ` [PATCH ath-next 01/17] dt-bindings: net: wireless: Add QCN6432 device tree binding documentation Aaradhana Sahu
2026-10-09 10:30 ` Krzysztof Kozlowski
2026-10-08 10:23 ` [PATCH ath-next 02/17] wifi: ath12k: Refactor PCI operations and MSI config structure Aaradhana Sahu
2026-10-08 10:23 ` [PATCH ath-next 03/17] wifi: ath12k: Add hardware parameter for QCN6432 Aaradhana Sahu
2026-10-08 10:24 ` [PATCH ath-next 04/17] wifi: ath12k: Add hardware ring mask " Aaradhana Sahu
2026-10-08 10:24 ` [PATCH ath-next 05/17] wifi: ath12k: add hardware registers " Aaradhana Sahu
2026-10-08 10:24 ` [PATCH ath-next 06/17] wifi: ath12k: move multi MSI vector flag to ath12k_dev_flags Aaradhana Sahu
2026-10-08 10:24 ` [PATCH ath-next 07/17] wifi: ath12k: Add hybrid_bus_type in ath12k_hw_params Aaradhana Sahu
2026-10-08 10:24 ` [PATCH ath-next 08/17] wifi: ath12k: Add hif operation support for QCN6432 Aaradhana Sahu
2026-10-08 10:24 ` [PATCH ath-next 09/17] wifi: ath12k: add support for unified data-region memory allocation Aaradhana Sahu
2026-10-08 10:35 ` sashiko-bot
2026-10-08 10:24 ` [PATCH ath-next 10/17] wifi: ath12k: move MSI config to pci.c Aaradhana Sahu
2026-10-08 10:24 ` [PATCH ath-next 11/17] wifi: ath12k: Add platform MSI support for CE Aaradhana Sahu
2026-10-08 10:41 ` sashiko-bot [this message]
2026-10-08 10:24 ` [PATCH ath-next 12/17] wifi: ath12k: Enable MSI interrupt support for DP interrupt Aaradhana Sahu
2026-10-08 10:45 ` sashiko-bot
2026-10-08 10:24 ` [PATCH ath-next 13/17] wifi: ath12k: use CMEM write for PPT on hybrid bus devices Aaradhana Sahu
2026-10-08 10:24 ` [PATCH ath-next 14/17] wifi: ath12k: store and use MSI data per CE and DP interrupt group for QCN6432 Aaradhana Sahu
2026-10-08 10:24 ` [PATCH ath-next 15/17] wifi: ath12k: Derive QMI service instance ID per protection domain Aaradhana Sahu
2026-10-08 10:24 ` [PATCH ath-next 16/17] wifi: ath12k: Resolve userPD ID per device Aaradhana Sahu
2026-10-08 10:43 ` sashiko-bot
2026-10-08 10:24 ` [PATCH ath-next 17/17] wifi: ath12k: Add QCN6432 AHB support Aaradhana Sahu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=sashiko-outbox-164035@kernel.org \
--to=sashiko-bot@kernel.org \
--cc=aaradhana.sahu@oss.qualcomm.com \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox