Linux PCI subsystem development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Koichiro Den" <den@valinux.co.jp>
Cc: robh@kernel.org, wsa+renesas@sang-engineering.com,
	devicetree@vger.kernel.org, linux-pci@vger.kernel.org,
	conor+dt@kernel.org
Subject: Re: [PATCH v2 11/15] PCI: rcar-gen4: Recover the Root Port on link down
Date: Mon, 28 Sep 2026 17:07:57 +0000	[thread overview]
Message-ID: <20260928170757.C71FC1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260928165230.3397664-12-den@valinux.co.jp>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] pci: use-after-free of MSI IRQ domain during host teardown
- [Medium] pci: controller permanently wedged if Root Port removed during link down
--

commit 82b6de1b742f3cf8c20cc9550ebcd54c8a744889
Author: Koichiro Den <den@valinux.co.jp>
Subject: PCI: rcar-gen4: Recover the Root Port on link down

This patch adds handling for link down events on the R-Car PCIe controller.
It introduces a mechanism to defer Root Port recovery to a workqueue to
avoid host hangs from DBI accesses while the link is down. It also arms
this detection post-enumeration and disarms it during driver removal.

> diff --git a/drivers/pci/controller/dwc/pcie-rcar-gen4.c b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
> index 256410fb4b1cd..aa80232afabad 100644
> --- a/drivers/pci/controller/dwc/pcie-rcar-gen4.c
> +++ b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
[ ... ]
> @@ -559,15 +575,35 @@ static int rcar_gen4_pcie_host_msi_addr(struct dw_pcie_rp *pp, u32 *msi_addr)
>  static void rcar_gen4_pcie_app_irq_sync_locked(struct rcar_gen4_pcie *rcar)
>  {
[ ... ]
> +	/*
> +	 * Note that rcar->rp_events_armed is not checked here because device
> +	 * removal may still need iMSI-RX interrupts after Root Port events have
> +	 * been disarmed.
> +	 */
>  	if (!rcar->reinit_pending && pp->use_imsi_rx && pci_msi_enabled())
>  		val |= MSI_CTRL_INT;
>  	writel(val, rcar->base + PCIEINTSTS0EN);
[ ... ]
> @@ -630,6 +666,44 @@ static int rcar_gen4_pcie_host_msi_init(struct dw_pcie_rp *pp)
[ ... ]
> +static void rcar_gen4_pcie_link_down_work(struct work_struct *work)
> +{
> +	struct rcar_gen4_pcie *rcar =
> +		container_of(work, struct rcar_gen4_pcie, link_down_work);
> +	struct pci_dev *port;
> +
> +	/* Hold a reference: the Root Port can be removed through sysfs. */
> +	port = pci_get_slot(rcar->dw.pp.bridge->bus, PCI_DEVFN(0, 0));
> +	if (!port)
> +		return;

[Severity: Medium]
If the Root Port has been removed via sysfs and pci_get_slot() returns NULL,
does this early return leave reinit_pending set to true?

Since rcar_gen4_pcie_handle_link_down() sets reinit_pending to true before
scheduling this work, bypassing the reset sequence here would fail to clear
reinit_pending. Could this result in MSI interrupts being permanently masked?

> +
> +	pci_host_handle_link_down(port);
> +	pci_dev_put(port);
> +}
[ ... ]
> @@ -640,6 +714,10 @@ static irqreturn_t rcar_gen4_pcie_msi_irq_handler(int irq, void *data)
[ ... ]
> +	/* Check reset requests before MSI handling, which accesses DBI. */
> +	if (rcar_gen4_pcie_handle_link_down(rcar))
> +		return IRQ_HANDLED;
> +
>  	status = readl(rcar->base + PCIEINTSTS0) &
>  		 readl(rcar->base + PCIEINTSTS0EN);
>  	if (!(status & MSI_CTRL_INT))
>  		return IRQ_NONE;
>  
>  	dw_handle_msi_irq(&rcar->dw.pp);
>  
>  	return IRQ_HANDLED;
>  }
[ ... ]
> @@ -918,6 +1023,8 @@ static int rcar_gen4_add_dw_pcie_rp(struct rcar_gen4_pcie *rcar)
[ ... ]
>  static void rcar_gen4_remove_dw_pcie_rp(struct rcar_gen4_pcie *rcar)
>  {
> +	/* Cancel recovery work before removing the PCI bus */
> +	rcar_gen4_pcie_rp_events_disarm(rcar);
>  	dw_pcie_host_deinit(&rcar->dw.pp);
>  }

[Severity: High]
During host teardown, rcar_gen4_pcie_rp_events_disarm() is called which leaves
MSI interrupts enabled via rcar_gen4_pcie_app_irq_sync_locked().

The teardown then continues into the core:

drivers/pci/controller/dwc/pcie-designware-host.c:dw_pcie_host_deinit() {
    ...
    if (pp->use_imsi_rx)
        dw_pcie_free_msi(pp);

    if (pp->ops->deinit)
        pp->ops->deinit(pp);
    ...
}

Because dw_pcie_free_msi() frees the irq_domain before the driver's .deinit
callback has a chance to call free_irq(), what happens if a hardware
interrupt fires in this window?

Would rcar_gen4_pcie_msi_irq_handler() execute and call dw_handle_msi_irq(),
leading to a use-after-free when it dereferences the freed pp->irq_domain?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260928165230.3397664-1-den@valinux.co.jp?part=11

  reply	other threads:[~2026-09-28 17:07 UTC|newest]

Thread overview: 58+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 16:52 [PATCH v2 00/15] PCI: rcar-gen4: Recover from link down and route Root Port interrupts Koichiro Den
2026-09-28 16:52 ` [PATCH v2 01/15] PCI: dwc: Add Renesas to the RAS DES VSEC list Koichiro Den
2026-09-28 16:56   ` sashiko-bot
2026-09-28 16:52 ` [PATCH v2 02/15] PCI: rcar-gen4: Check live link status in link_up() Koichiro Den
2026-09-28 16:57   ` sashiko-bot
2026-10-03 18:29   ` Marek Vasut
2026-10-03 18:51     ` Marek Vasut
2026-10-05  4:22       ` Koichiro Den
2026-10-05  5:59         ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 03/15] dt-bindings: PCI: rcar-gen4: Add optional "aer" interrupt Koichiro Den
2026-09-28 16:58   ` sashiko-bot
2026-09-30 10:31   ` Krzysztof Kozlowski
2026-10-03 20:00   ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 04/15] PCI: dwc: Export dw_handle_msi_irq() Koichiro Den
2026-09-28 16:58   ` sashiko-bot
2026-10-03 20:02   ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 05/15] PCI: rcar-gen4: Move deinitialization helpers before SoC initialization Koichiro Den
2026-09-28 16:57   ` sashiko-bot
2026-10-03 20:23   ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 06/15] PCI: rcar-gen4: Assert resets when Gen5 PHY initialization fails Koichiro Den
2026-09-28 16:59   ` sashiko-bot
2026-10-03 21:34   ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 07/15] PCI: rcar-gen4: Separate hardware setup from resource acquisition Koichiro Den
2026-09-28 16:56   ` sashiko-bot
2026-10-03 23:41   ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 08/15] PCI: rcar-gen4: Add a controller reinitialization callback Koichiro Den
2026-09-28 17:02   ` sashiko-bot
2026-10-03 23:54   ` Marek Vasut
2026-10-05  4:31     ` Koichiro Den
2026-09-28 16:52 ` [PATCH v2 09/15] PCI: rcar-gen4: Add Root Port reset support Koichiro Den
2026-09-28 17:03   ` sashiko-bot
2026-10-04  0:11   ` Marek Vasut
2026-10-05  6:14     ` Koichiro Den
2026-09-28 16:52 ` [PATCH v2 10/15] PCI: rcar-gen4: Take over the iMSI-RX interrupt Koichiro Den
2026-09-28 17:04   ` sashiko-bot
2026-09-29 17:43   ` Geert Uytterhoeven
2026-09-30  6:38     ` Koichiro Den
2026-10-04  1:17       ` Marek Vasut
2026-10-04  0:53   ` Marek Vasut
2026-10-05 17:05     ` Koichiro Den
2026-09-28 16:52 ` [PATCH v2 11/15] PCI: rcar-gen4: Recover the Root Port on link down Koichiro Den
2026-09-28 17:07   ` sashiko-bot [this message]
2026-10-04  1:38   ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 12/15] PCI: dwc: Let glue drivers hide the Root Port MSI capabilities Koichiro Den
2026-09-28 16:59   ` sashiko-bot
2026-09-28 16:52 ` [PATCH v2 13/15] PCI: rcar-gen4: Route Root Port AER to a virtual Root Port IRQ Koichiro Den
2026-09-28 17:06   ` sashiko-bot
2026-10-04  2:52   ` Marek Vasut
2026-09-28 16:52 ` [PATCH v2 14/15] PCI: rcar-gen4: Route Root Port PME and bandwidth notifications Koichiro Den
2026-09-28 17:08   ` sashiko-bot
2026-10-04  4:40   ` Marek Vasut
2026-10-05 17:09     ` Koichiro Den
2026-09-28 16:52 ` [PATCH v2 15/15] arm64: dts: renesas: r8a779f0: Describe the PCIe AER interrupts Koichiro Den
2026-09-28 16:59   ` sashiko-bot
2026-10-03 20:00   ` Marek Vasut
2026-10-05 17:11     ` Koichiro Den
2026-10-06  5:20       ` Marek Vasut
2026-10-03 17:46 ` [PATCH v2 00/15] PCI: rcar-gen4: Recover from link down and route Root Port interrupts Marek Vasut

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928170757.C71FC1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=den@valinux.co.jp \
    --cc=devicetree@vger.kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=wsa+renesas@sang-engineering.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox