Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Long Zhao" <longzhao@ambarella.com>
Cc: devicetree@vger.kernel.org, robh@kernel.org, conor+dt@kernel.org,
	linux-gpio@vger.kernel.org
Subject: Re: [PATCH 6/7] gpio: pl061: switch data path to gpio-regmap
Date: Fri, 09 Oct 2026 11:50:11 +0000	[thread overview]
Message-ID: <sashiko-outbox-165431@kernel.org> (raw)
In-Reply-To: <20261009-cv75-gpio-v1-6-5836bd438423@ambarella.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] gpio: UAF of irq_domain during devm teardown due to LIFO ordering
- [High] gpio: Missing GPIOCHIP_IRQ_RESOURCE_HELPERS allows GPIO/IRQ conflicts
- [High] gpio: Missing synchronize_irq() causes UAF on chained handler removal
--

commit b485edbbc0d9055aa12255ec0a09e3fe648808bb
Author: Long Zhao <longzhao@ambarella.com>

    gpio: pl061: switch data path to gpio-regmap
    
    Move get, set and direction onto gpio-regmap. ARM PL061 sets
    GPIO_REGMAP_QUIRK_SET_AFTER_DIR so the output value is written
    after the direction change.

> diff --git a/drivers/gpio/gpio-pl061.c b/drivers/gpio/gpio-pl061.c
> index b7632b30a9098..ba3350a8971c8 100644
> --- a/drivers/gpio/gpio-pl061.c
> +++ b/drivers/gpio/gpio-pl061.c
[ ... ]
> @@ -293,29 +227,28 @@ static void pl061_irq_unmask(struct irq_data *d)
[ ... ]
> -static const struct irq_chip pl061_irq_chip = {
> +static const struct irq_chip pl061_irqchip = {
> +	.name			= "pl061",
>  	.irq_ack		= pl061_irq_ack,
>  	.irq_mask		= pl061_irq_mask,
>  	.irq_unmask		= pl061_irq_unmask,
> @@ -323,67 +256,187 @@ static const struct irq_chip pl061_irq_chip = {
>  	.irq_set_wake		= pl061_irq_set_wake,
>  	.irq_print_chip		= pl061_irq_print_chip,
>  	.flags			= IRQCHIP_IMMUTABLE,
> -	GPIOCHIP_IRQ_RESOURCE_HELPERS,
> -};

[Severity: High]
Does this code omit the GPIOCHIP_IRQ_RESOURCE_HELPERS macro? 

Without the .irq_request_resources and .irq_release_resources callbacks it
provides, gpiolib won't be notified when an IRQ is requested, and
gpiochip_lock_as_irq() is skipped.

Could this allow the GPIO line to be concurrently configured as an output
while it is actively firing interrupts?

[ ... ]
> +static void pl061_remove_irq(void *data)
> +{
> +	struct pl061 *pl061 = data;
> +
> +	irq_set_chained_handler_and_data(pl061->parent_irq, NULL, NULL);

[Severity: High]
Can a concurrent interrupt handler still be executing here?

This replaces the flow handler but doesn't wait for currently executing
handlers to finish like synchronize_irq() would.

> +
> +	for (unsigned int i = 0; i < pl061->data->ngpio; i++) {
> +		unsigned int virq;
> +
> +		virq = irq_find_mapping(pl061->irq_domain, i);
> +		if (virq)
> +			irq_dispose_mapping(virq);
> +	}
> +
> +	irq_domain_remove(pl061->irq_domain);

[Severity: High]
Could the lack of synchronization against concurrent interrupts lead to a
use-after-free here?

If pl061_irq_handler() is concurrently executing on another CPU, it might call
generic_handle_domain_irq(pl061->irq_domain, ...) and dereference the
domain after it has been freed.

> +}
[ ... ]
> +	gpio_regmap = devm_gpio_regmap_register(dev, &config);
> +	if (IS_ERR(gpio_regmap)) {
> +		if (pl061->irq_domain)
> +			irq_domain_remove(pl061->irq_domain);
> +		return PTR_ERR(gpio_regmap);
> +	}
> +
> +	if (irq) {
> +		ret = devm_add_action_or_reset(dev, pl061_remove_irq, pl061);

[Severity: High]
Because devm executes actions in reverse (LIFO) order, pl061_remove_irq() will
execute before the gpio_regmap is unregistered.

Will this destroy the irq_domain while the gpio_chip is still active?

If so, when the gpio_chip is later unregistered, gpiochip_remove() might
dereference the freed domain pointer when attempting to tear down requested
IRQs.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261009-cv75-gpio-v1-0-5836bd438423@ambarella.com?part=6

  reply	other threads:[~2026-10-09 11:50 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-09 10:57 [PATCH 0/7] gpio: add Ambarella CV75 PL061 support Long Zhao via B4 Relay
2026-10-09 10:57 ` [PATCH 1/7] dt-bindings: gpio: pl061: add Ambarella CV75 variant Long Zhao via B4 Relay
2026-10-09 11:32   ` Krzysztof Kozlowski
2026-10-09 10:57 ` [PATCH 2/7] gpiolib: regmap: add GPIO_REGMAP_QUIRK_SET_AFTER_DIR Long Zhao via B4 Relay
2026-10-09 11:17   ` Michael Walle
2026-10-09 11:27   ` sashiko-bot
2026-10-09 10:57 ` [PATCH 3/7] gpio: pl061: convert register access to regmap Long Zhao via B4 Relay
2026-10-09 10:57 ` [PATCH 4/7] gpio: pl061: use IRQ_TYPE_LEVEL_MASK and IRQ_TYPE_EDGE_BOTH Long Zhao via B4 Relay
2026-10-09 10:57 ` [PATCH 5/7] gpio: pl061: use cleanup helpers for locks Long Zhao via B4 Relay
2026-10-09 10:57 ` [PATCH 6/7] gpio: pl061: switch data path to gpio-regmap Long Zhao via B4 Relay
2026-10-09 11:50   ` sashiko-bot [this message]
2026-10-09 10:58 ` [PATCH 7/7] gpio: pl061: add Ambarella register-layout variant Long Zhao via B4 Relay
2026-10-09 12:03   ` sashiko-bot
2026-10-09 11:32 ` [PATCH 0/7] gpio: add Ambarella CV75 PL061 support Krzysztof Kozlowski

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=sashiko-outbox-165431@kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=linux-gpio@vger.kernel.org \
    --cc=longzhao@ambarella.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox