Linux PCI subsystem development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Abhin Parekadan Jose" <abhinjoses@gmail.com>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH RFC v3 5/5] misc: Add edu_srpoc surprise removal POC driver
Date: Sun, 27 Sep 2026 17:59:37 +0000	[thread overview]
Message-ID: <20260927175937.E006F1F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260927175203.928270-6-abhinjoses@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] misc: missing reinit_completion() in edu_remove() causes unhandled IRQ storm
--

commit f9ed797f2f520a59d9e2c04ca2421e2d89d85acb
Author: Abhin Parekadan Jose <abhinjoses@gmail.com>

misc: Add edu_srpoc surprise removal POC driver

This commit adds a test driver for the QEMU edu device to reproduce
a surprise removal hang. The driver's remove callback schedules a
delayed interrupt and blocks until it fires or a disconnect work runs.

Link: https://lore.kernel.org/all/20260905183905.997833-4-abhinjoses@gmail.com/
Link: https://lore.kernel.org/all/20260905185027.291191F00A3A@smtp.kernel.org/

> diff --git a/drivers/misc/edu_srpoc.c b/drivers/misc/edu_srpoc.c
> new file mode 100644
> index 0000000000000..b74a95109dba9
> --- /dev/null
> +++ b/drivers/misc/edu_srpoc.c
[ ... ]
> +static void edu_remove(struct pci_dev *pdev)
> +{
> +	struct edu_dev *edu = pci_get_drvdata(pdev);
> +
> +	iowrite32(EDU_STATUS_IRQFACT, edu->regs + EDU_REG_STATUS);
> +	iowrite32(600000, edu->regs + EDU_REG_DELAYED_IRQ);
> +
> +	dev_info(&pdev->dev, "Waiting for IRQ in remove()\n");
> +	wait_for_completion(&edu->irq_done);

[Severity: Medium]
Could this leave an unhandled interrupt pending if the completion count was
already incremented?

If a prior interrupt (for example, from a previous test run or device state
before the driver loaded) has already called complete(&edu->irq_done),
wait_for_completion() will return immediately instead of waiting for the
600-second delayed interrupt requested just above.

This would allow edu_remove() to finish and the driver to unload while the
delayed hardware interrupt remains pending. When this interrupt fires later
with no handler registered, it could trigger an unhandled IRQ storm that
permanently disables the shared PCI INTx line, potentially affecting other
devices.

Should there be a call to reinit_completion(&edu->irq_done) before
requesting the delayed interrupt here?

> +	dev_info(&pdev->dev, "Unblocked, cleaning up\n");
> +
> +	pci_clear_disconnect_work(pdev);
> +	free_irq(pci_irq_vector(pdev, 0), edu);
> +	pci_free_irq_vectors(pdev);
> +	pci_clear_master(pdev);
> +	pci_iounmap(pdev, edu->regs);
> +	pci_release_regions(pdev);
> +	pci_disable_device(pdev);
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260927175203.928270-1-abhinjoses@gmail.com?part=5

      reply	other threads:[~2026-09-27 17:59 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-27 17:51 [PATCH RFC v3 0/5] PCI: pciehp: Report surprise removal during safe removal Abhin Parekadan Jose
2026-09-27 17:51 ` [PATCH RFC v3 1/5] PCI: Report surprise removal event Abhin Parekadan Jose
2026-09-27 18:02   ` sashiko-bot
2026-09-27 17:51 ` [PATCH RFC v3 2/5] PCI: pciehp: Add pci_hp_wait_link_change() Abhin Parekadan Jose
2026-09-27 17:56   ` sashiko-bot
2026-09-27 17:52 ` [PATCH RFC v3 3/5] PCI/DPC: Add pci_dpc_wait_recovery() Abhin Parekadan Jose
2026-09-27 17:55   ` sashiko-bot
2026-09-27 17:52 ` [PATCH RFC v3 4/5] PCI: pciehp: Report surprise removal from pciehp_isr() Abhin Parekadan Jose
2026-09-27 17:59   ` sashiko-bot
2026-09-27 17:52 ` [PATCH RFC v3 5/5] misc: Add edu_srpoc surprise removal POC driver Abhin Parekadan Jose
2026-09-27 17:59   ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260927175937.E006F1F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=abhinjoses@gmail.com \
    --cc=linux-pci@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox