Linux PCI subsystem development
 help / color / mirror / Atom feed
From: Bjorn Helgaas <helgaas@kernel.org>
To: Runyu Xiao <runyu.xiao@seu.edu.cn>
Cc: Bjorn Helgaas <bhelgaas@google.com>,
	Kristen Carlson Accardi <kristen.c.accardi@intel.com>,
	Kenji Kaneshige <kaneshige.kenji@jp.fujitsu.com>,
	Jesse Barnes <jbarnes@virtuousgeek.org>,
	linux-pci@vger.kernel.org, linux-kernel@vger.kernel.org,
	stable@vger.kernel.org, Jianhao Xu <jianhao.xu@seu.edu.cn>
Subject: Re: [PATCH] PCI: pciehp: Make poll mode parameter read-only
Date: Mon, 21 Sep 2026 12:51:54 -0500	[thread overview]
Message-ID: <20260921175154.GA1332331@bhelgaas> (raw)
In-Reply-To: <20260921142608.270312-1-runyu.xiao@seu.edu.cn>

On Mon, Sep 21, 2026 at 10:26:08PM +0800, Runyu Xiao wrote:
> pciehp_request_irq() and pciehp_free_irq() select different resources
> based on the global pciehp_poll_mode parameter. The parameter is
> currently writable through sysfs, so changing it while a controller is
> active can make teardown stop a nonexistent polling thread or call
> free_irq() for an IRQ that was not requested.
> 
> Keep the parameter available for boot and module configuration, but
> prevent runtime changes to the registration mode.
> 
> Reproducer:
> Boot an x86_64 guest in QEMU with a native PCIe hotplug root port and an
> e1000 device, using these device options:
> 
>     -device pcie-root-port,id=rp1,chassis=1,slot=1
>     -device e1000,bus=rp1
> 
> Pass pcie_ports=native pciehp.pciehp_poll_mode=1 to the guest kernel.
> As root in the guest, replace the device name below with a bound pciehp
> service device and run:
> 
>     dev=0000:00:1c.0:pcie004
>     driver=/sys/bus/pci_express/drivers/pciehp
>     echo 0 > /sys/module/pciehp/parameters/poll_mode
>     echo "$dev" > "$driver/unbind"
>     dmesg | grep 'Trying to free already-free IRQ'
> 
> The unfixed kernel accepts the runtime mode change and reports the warning
> when the service device is removed. The fixed kernel rejects the write and
> removes the device without the warning. The mode change is a deliberate
> privileged test action and is not expected during ordinary operation.
> 
> Fixes: 2aeeef119995 ("pciehp: Clean up pcie_init()")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM Codex
> Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>

Applied to pci/hotplug for v7.4, thanks!

> ---
>  drivers/pci/hotplug/pciehp_core.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/pci/hotplug/pciehp_core.c b/drivers/pci/hotplug/pciehp_core.c
> index 2cafd3b26f344..5ce32dc7e178f 100644
> --- a/drivers/pci/hotplug/pciehp_core.c
> +++ b/drivers/pci/hotplug/pciehp_core.c
> @@ -38,7 +38,7 @@ int pciehp_poll_time;
>   * not really modular, but the easiest way to keep compat with existing
>   * bootargs behaviour is to continue using module_param here.
>   */
> -module_param(pciehp_poll_mode, bool, 0644);
> +module_param(pciehp_poll_mode, bool, 0444);
>  module_param(pciehp_poll_time, int, 0644);
>  MODULE_PARM_DESC(pciehp_poll_mode, "Using polling mechanism for hot-plug events or not");
>  MODULE_PARM_DESC(pciehp_poll_time, "Polling mechanism frequency, in seconds");
> -- 
> 2.34.1
> 

      parent reply	other threads:[~2026-09-21 17:51 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21 14:26 [PATCH] PCI: pciehp: Make poll mode parameter read-only Runyu Xiao
2026-09-21 14:34 ` sashiko-bot
2026-09-21 15:41 ` Lukas Wunner
2026-09-21 17:51 ` Bjorn Helgaas [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260921175154.GA1332331@bhelgaas \
    --to=helgaas@kernel.org \
    --cc=bhelgaas@google.com \
    --cc=jbarnes@virtuousgeek.org \
    --cc=jianhao.xu@seu.edu.cn \
    --cc=kaneshige.kenji@jp.fujitsu.com \
    --cc=kristen.c.accardi@intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=runyu.xiao@seu.edu.cn \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox