From: sashiko-bot@kernel.org
To: "Long Zhao" <longzhao@ambarella.com>
Cc: devicetree@vger.kernel.org, robh@kernel.org, conor+dt@kernel.org,
linux-gpio@vger.kernel.org
Subject: Re: [PATCH 6/7] gpio: pl061: switch data path to gpio-regmap
Date: Fri, 09 Oct 2026 11:50:11 +0000 [thread overview]
Message-ID: <sashiko-outbox-165431@kernel.org> (raw)
In-Reply-To: <20261009-cv75-gpio-v1-6-5836bd438423@ambarella.com>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] gpio: UAF of irq_domain during devm teardown due to LIFO ordering
- [High] gpio: Missing GPIOCHIP_IRQ_RESOURCE_HELPERS allows GPIO/IRQ conflicts
- [High] gpio: Missing synchronize_irq() causes UAF on chained handler removal
--
commit b485edbbc0d9055aa12255ec0a09e3fe648808bb
Author: Long Zhao <longzhao@ambarella.com>
gpio: pl061: switch data path to gpio-regmap
Move get, set and direction onto gpio-regmap. ARM PL061 sets
GPIO_REGMAP_QUIRK_SET_AFTER_DIR so the output value is written
after the direction change.
> diff --git a/drivers/gpio/gpio-pl061.c b/drivers/gpio/gpio-pl061.c
> index b7632b30a9098..ba3350a8971c8 100644
> --- a/drivers/gpio/gpio-pl061.c
> +++ b/drivers/gpio/gpio-pl061.c
[ ... ]
> @@ -293,29 +227,28 @@ static void pl061_irq_unmask(struct irq_data *d)
[ ... ]
> -static const struct irq_chip pl061_irq_chip = {
> +static const struct irq_chip pl061_irqchip = {
> + .name = "pl061",
> .irq_ack = pl061_irq_ack,
> .irq_mask = pl061_irq_mask,
> .irq_unmask = pl061_irq_unmask,
> @@ -323,67 +256,187 @@ static const struct irq_chip pl061_irq_chip = {
> .irq_set_wake = pl061_irq_set_wake,
> .irq_print_chip = pl061_irq_print_chip,
> .flags = IRQCHIP_IMMUTABLE,
> - GPIOCHIP_IRQ_RESOURCE_HELPERS,
> -};
[Severity: High]
Does this code omit the GPIOCHIP_IRQ_RESOURCE_HELPERS macro?
Without the .irq_request_resources and .irq_release_resources callbacks it
provides, gpiolib won't be notified when an IRQ is requested, and
gpiochip_lock_as_irq() is skipped.
Could this allow the GPIO line to be concurrently configured as an output
while it is actively firing interrupts?
[ ... ]
> +static void pl061_remove_irq(void *data)
> +{
> + struct pl061 *pl061 = data;
> +
> + irq_set_chained_handler_and_data(pl061->parent_irq, NULL, NULL);
[Severity: High]
Can a concurrent interrupt handler still be executing here?
This replaces the flow handler but doesn't wait for currently executing
handlers to finish like synchronize_irq() would.
> +
> + for (unsigned int i = 0; i < pl061->data->ngpio; i++) {
> + unsigned int virq;
> +
> + virq = irq_find_mapping(pl061->irq_domain, i);
> + if (virq)
> + irq_dispose_mapping(virq);
> + }
> +
> + irq_domain_remove(pl061->irq_domain);
[Severity: High]
Could the lack of synchronization against concurrent interrupts lead to a
use-after-free here?
If pl061_irq_handler() is concurrently executing on another CPU, it might call
generic_handle_domain_irq(pl061->irq_domain, ...) and dereference the
domain after it has been freed.
> +}
[ ... ]
> + gpio_regmap = devm_gpio_regmap_register(dev, &config);
> + if (IS_ERR(gpio_regmap)) {
> + if (pl061->irq_domain)
> + irq_domain_remove(pl061->irq_domain);
> + return PTR_ERR(gpio_regmap);
> + }
> +
> + if (irq) {
> + ret = devm_add_action_or_reset(dev, pl061_remove_irq, pl061);
[Severity: High]
Because devm executes actions in reverse (LIFO) order, pl061_remove_irq() will
execute before the gpio_regmap is unregistered.
Will this destroy the irq_domain while the gpio_chip is still active?
If so, when the gpio_chip is later unregistered, gpiochip_remove() might
dereference the freed domain pointer when attempting to tear down requested
IRQs.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261009-cv75-gpio-v1-0-5836bd438423@ambarella.com?part=6
next prev parent reply other threads:[~2026-10-09 11:50 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-09 10:57 [PATCH 0/7] gpio: add Ambarella CV75 PL061 support Long Zhao via B4 Relay
2026-10-09 10:57 ` [PATCH 1/7] dt-bindings: gpio: pl061: add Ambarella CV75 variant Long Zhao via B4 Relay
2026-10-09 11:32 ` Krzysztof Kozlowski
2026-10-09 10:57 ` [PATCH 2/7] gpiolib: regmap: add GPIO_REGMAP_QUIRK_SET_AFTER_DIR Long Zhao via B4 Relay
2026-10-09 11:17 ` Michael Walle
2026-10-09 11:27 ` sashiko-bot
2026-10-09 10:57 ` [PATCH 3/7] gpio: pl061: convert register access to regmap Long Zhao via B4 Relay
2026-10-09 10:57 ` [PATCH 4/7] gpio: pl061: use IRQ_TYPE_LEVEL_MASK and IRQ_TYPE_EDGE_BOTH Long Zhao via B4 Relay
2026-10-09 10:57 ` [PATCH 5/7] gpio: pl061: use cleanup helpers for locks Long Zhao via B4 Relay
2026-10-09 10:57 ` [PATCH 6/7] gpio: pl061: switch data path to gpio-regmap Long Zhao via B4 Relay
2026-10-09 11:50 ` sashiko-bot [this message]
2026-10-09 10:58 ` [PATCH 7/7] gpio: pl061: add Ambarella register-layout variant Long Zhao via B4 Relay
2026-10-09 12:03 ` sashiko-bot
2026-10-09 11:32 ` [PATCH 0/7] gpio: add Ambarella CV75 PL061 support Krzysztof Kozlowski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=sashiko-outbox-165431@kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=linux-gpio@vger.kernel.org \
--cc=longzhao@ambarella.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox