Linux PCI subsystem development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Pranjal Shrivastava" <praan@google.com>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH v11 07/16] genirq/msi: Cache MSI message in irq_chip_write_msi_msg()
Date: Tue, 29 Sep 2026 05:07:43 +0000	[thread overview]
Message-ID: <20260929050743.9D5981F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260929034510.2023173-8-praan@google.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] irq: NULL pointer dereference in irq_chip_write_msi_msg()
--

commit 98ab4cb46e40acf3e5ccb95b4213b5490ae2ff8a
Author: Pranjal Shrivastava <praan@google.com>

genirq/msi: Cache MSI message in irq_chip_write_msi_msg()

Currently, PCI MSI caches the composed MSI message into the MSI descriptor
inside __pci_write_msi_msg(). This patch caches the message directly in
irq_chip_write_msi_msg() so that all hierarchical MSI domains automatically
record the latest message.

> diff --git a/kernel/irq/msi.c b/kernel/irq/msi.c
> index fb5f372215bf2..df460a574d800 100644
> --- a/kernel/irq/msi.c
> +++ b/kernel/irq/msi.c
> @@ -634,6 +634,15 @@ static unsigned int msi_domain_get_hwsize(struct device *dev, unsigned int domid
>  static inline void irq_chip_write_msi_msg(struct irq_data *data,
>  					  struct msi_msg *msg)
>  {
> +	struct msi_desc *desc = irq_data_get_msi_desc(data);
> +
> +	/*
> +	 * PCI Multi-MSI shares a single descriptor across all vectors and
> +	 * the device stores only the base message. Cache the message of the
> +	 * first interrupt only, so that sub-vectors cannot overwrite it.
> +	 */
> +	if (desc->irq == data->irq)

[Severity: Critical]
Does this code cause a NULL pointer dereference for domains without an
msi_desc object?

Looking at irq_chip_write_msi_msg() in kernel/irq/msi.c,
architecture-specific domains like the x86 HPET (hpet_msi_domain_info) and
DMAR (dmar_msi_domain_info) utilize generic MSI domain operations but do not
allocate an msi_desc object for their interrupts.

When an interrupt from these domains is activated or its affinity is updated,
calls like msi_domain_activate() or msi_domain_set_affinity() invoke
irq_chip_write_msi_msg().

Because irq_data_get_msi_desc(data) returns NULL for these interrupts,
checking desc->irq unconditionally could lead to a fatal dereference during
boot.

I checked the follow-up patches in the series and it appears a check for
desc is not introduced in any subsequent patch, so this regression remains
present in the final series state.

Should this be updated to check if desc is valid first?

> +		desc->msg = *msg;
>  	data->chip->irq_write_msi_msg(data, msg);
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260929034510.2023173-1-praan@google.com?part=7

  reply	other threads:[~2026-09-29  5:07 UTC|newest]

Thread overview: 55+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29  3:44 [PATCH v11 00/16] iommu/arm-smmu-v3: Implement Runtime/System Sleep ops Pranjal Shrivastava
2026-09-29  3:44 ` [PATCH v11 01/16] iommu/arm-smmu-v3: Refactor arm_smmu_setup_irqs Pranjal Shrivastava
2026-09-29  3:59   ` sashiko-bot
2026-10-07 14:06   ` Will Deacon
2026-09-29  3:44 ` [PATCH v11 02/16] iommu/arm-smmu-v3: Add Q_POS() macro Pranjal Shrivastava
2026-09-29  4:01   ` sashiko-bot
2026-09-29  3:44 ` [PATCH v11 03/16] iommu/arm-smmu-v3: Add arm_smmu_drain_queue() helper Pranjal Shrivastava
2026-09-29  4:11   ` sashiko-bot
2026-09-30 18:24   ` Nicolin Chen
2026-09-30 20:17     ` Pranjal Shrivastava
2026-09-29  3:44 ` [PATCH v11 04/16] iommu/tegra241-cmdqv: Add a helper to drain VCMDQs Pranjal Shrivastava
2026-09-29  4:24   ` sashiko-bot
2026-09-29  3:44 ` [PATCH v11 05/16] iommu/arm-smmu-v3: Add a helper to drain cmd queues Pranjal Shrivastava
2026-09-29  4:31   ` sashiko-bot
2026-09-29  3:45 ` [PATCH v11 06/16] iommu/tegra241-cmdqv: Restore PROD and CONS after resume Pranjal Shrivastava
2026-09-29  4:42   ` sashiko-bot
2026-09-29  3:45 ` [PATCH v11 07/16] genirq/msi: Cache MSI message in irq_chip_write_msi_msg() Pranjal Shrivastava
2026-09-29  5:07   ` sashiko-bot [this message]
2026-09-29  3:45 ` [PATCH v11 08/16] genirq/msi: Provide msi_device_domain_restore_msi_msgs() Pranjal Shrivastava
2026-09-29  5:22   ` sashiko-bot
2026-09-29  3:45 ` [PATCH v11 09/16] iommu/arm-smmu-v3: Restore MSI config on resume Pranjal Shrivastava
2026-09-29  5:31   ` sashiko-bot
2026-10-07 14:07   ` Will Deacon
2026-09-29  3:45 ` [PATCH v11 10/16] iommu/arm-smmu-v3: Factor out arm_smmu_handle_gerror() Pranjal Shrivastava
2026-09-29  5:37   ` sashiko-bot
2026-09-30 18:34   ` Nicolin Chen
2026-09-30 20:00     ` Pranjal Shrivastava
2026-09-30 20:12       ` Nicolin Chen
2026-09-30 20:03     ` Pranjal Shrivastava
2026-10-07 14:07   ` Will Deacon
2026-09-29  3:45 ` [PATCH v11 11/16] iommu/arm-smmu-v3: Add CMDQ_PROD_STOP_FLAG to gate CMDQ submissions Pranjal Shrivastava
2026-09-29  5:55   ` sashiko-bot
2026-09-30 20:33   ` Nicolin Chen
2026-10-01  5:40     ` Pranjal Shrivastava
2026-10-01 18:03       ` Nicolin Chen
2026-10-02 16:47         ` Jason Gunthorpe
2026-10-02 21:11           ` Pranjal Shrivastava
2026-10-06 17:26             ` Nicolin Chen
2026-10-07 14:08   ` Will Deacon
2026-09-29  3:45 ` [PATCH v11 12/16] iommu/tegra241-cmdqv: Add a helper to quiesce VCMDQs Pranjal Shrivastava
2026-09-29  6:05   ` sashiko-bot
2026-09-30 19:02   ` Nicolin Chen
2026-09-30 19:57     ` Pranjal Shrivastava
2026-09-30 20:03       ` Nicolin Chen
2026-09-29  3:45 ` [PATCH v11 13/16] iommu/arm-smmu-v3: Implement pm_runtime & system sleep ops Pranjal Shrivastava
2026-09-29  6:17   ` sashiko-bot
2026-10-01 20:22   ` Nicolin Chen
2026-10-07 14:08   ` Will Deacon
2026-09-29  3:45 ` [PATCH v11 14/16] iommu/arm-smmu-v3: Enable pm_runtime and setup devlinks Pranjal Shrivastava
2026-09-29  6:32   ` sashiko-bot
2026-09-29  3:45 ` [PATCH v11 15/16] iommu/arm-smmu-v3: Invoke pm_runtime before hw access Pranjal Shrivastava
2026-09-29  6:41   ` sashiko-bot
2026-09-29  3:45 ` [PATCH v11 16/16] iommu/arm-smmu-v3: Add KUnit unit tests for Runtime PM Pranjal Shrivastava
2026-09-29  6:48   ` sashiko-bot
2026-10-01 19:12   ` Nicolin Chen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929050743.9D5981F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=praan@google.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox