From: sashiko-bot@kernel.org
To: "Pranjal Shrivastava" <praan@google.com>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH v11 08/16] genirq/msi: Provide msi_device_domain_restore_msi_msgs()
Date: Tue, 29 Sep 2026 05:22:23 +0000 [thread overview]
Message-ID: <20260929052223.C3A411F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929034510.2023173-9-praan@google.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] irq/msi: NULL pointer dereference in msi_device_domain_restore_msi_msgs
--
commit 095b22d878464bc6c7b357c12fc988c69e1487d7
Author: Thomas Gleixner <tglx@kernel.org>
genirq/msi: Provide msi_device_domain_restore_msi_msgs()
This commit provides msi_device_domain_restore_msi_msgs() to iterate over MSI
descriptors and rewrite cached MSI messages for devices that lose register
state during power transitions. It iterates over the associated MSI descriptors
in the device's MSI domain and rewrites the messages via the irq_chip hierarchy.
> diff --git a/kernel/irq/msi.c b/kernel/irq/msi.c
> index df460a574d800..8fb855b5e09f3 100644
> --- a/kernel/irq/msi.c
> +++ b/kernel/irq/msi.c
[ ... ]
> + xa_for_each_range(xa, idx, msi_desc, 0, info->hwsize - 1) {
> + /* Only handle MSI entries which have an interrupt associated */
> + if (!msi_desc_match(msi_desc, MSI_DESC_ASSOCIATED))
> + continue;
> +
> + scoped_irqdesc_get_and_buslock(msi_desc->irq, 0) {
> + struct irq_data *data = irq_desc_get_irq_data(scoped_irqdesc);
> + struct msi_msg msg = msi_desc->msg;
> +
> + if (data->chip)
> + irq_chip_write_msi_msg(data, &msg);
[Severity: Critical]
Will this result in a NULL pointer dereference in hierarchical IRQ domains?
Since irq_desc_get_irq_data() retrieves the top-level irq_data, data->chip
points to the top-level irq_chip. In hierarchical IRQ domains, the top-level
irq_chip typically does not implement the irq_write_msi_msg callback.
When this top-level irq_data is passed to irq_chip_write_msi_msg(), it will
dereference a NULL function pointer:
kernel/irq/msi.c:irq_chip_write_msi_msg() {
...
data->chip->irq_write_msi_msg(data, msg);
}
Should this code retrieve the specific irq_data for the MSI domain that
actually implements the write_msi_msg callback, rather than using the
top-level irq_data?
> + }
> + }
> +}
> +EXPORT_SYMBOL_GPL(msi_device_domain_restore_msi_msgs);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260929034510.2023173-1-praan@google.com?part=8
next prev parent reply other threads:[~2026-09-29 5:22 UTC|newest]
Thread overview: 55+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 3:44 [PATCH v11 00/16] iommu/arm-smmu-v3: Implement Runtime/System Sleep ops Pranjal Shrivastava
2026-09-29 3:44 ` [PATCH v11 01/16] iommu/arm-smmu-v3: Refactor arm_smmu_setup_irqs Pranjal Shrivastava
2026-09-29 3:59 ` sashiko-bot
2026-10-07 14:06 ` Will Deacon
2026-09-29 3:44 ` [PATCH v11 02/16] iommu/arm-smmu-v3: Add Q_POS() macro Pranjal Shrivastava
2026-09-29 4:01 ` sashiko-bot
2026-09-29 3:44 ` [PATCH v11 03/16] iommu/arm-smmu-v3: Add arm_smmu_drain_queue() helper Pranjal Shrivastava
2026-09-29 4:11 ` sashiko-bot
2026-09-30 18:24 ` Nicolin Chen
2026-09-30 20:17 ` Pranjal Shrivastava
2026-09-29 3:44 ` [PATCH v11 04/16] iommu/tegra241-cmdqv: Add a helper to drain VCMDQs Pranjal Shrivastava
2026-09-29 4:24 ` sashiko-bot
2026-09-29 3:44 ` [PATCH v11 05/16] iommu/arm-smmu-v3: Add a helper to drain cmd queues Pranjal Shrivastava
2026-09-29 4:31 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 06/16] iommu/tegra241-cmdqv: Restore PROD and CONS after resume Pranjal Shrivastava
2026-09-29 4:42 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 07/16] genirq/msi: Cache MSI message in irq_chip_write_msi_msg() Pranjal Shrivastava
2026-09-29 5:07 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 08/16] genirq/msi: Provide msi_device_domain_restore_msi_msgs() Pranjal Shrivastava
2026-09-29 5:22 ` sashiko-bot [this message]
2026-09-29 3:45 ` [PATCH v11 09/16] iommu/arm-smmu-v3: Restore MSI config on resume Pranjal Shrivastava
2026-09-29 5:31 ` sashiko-bot
2026-10-07 14:07 ` Will Deacon
2026-09-29 3:45 ` [PATCH v11 10/16] iommu/arm-smmu-v3: Factor out arm_smmu_handle_gerror() Pranjal Shrivastava
2026-09-29 5:37 ` sashiko-bot
2026-09-30 18:34 ` Nicolin Chen
2026-09-30 20:00 ` Pranjal Shrivastava
2026-09-30 20:12 ` Nicolin Chen
2026-09-30 20:03 ` Pranjal Shrivastava
2026-10-07 14:07 ` Will Deacon
2026-09-29 3:45 ` [PATCH v11 11/16] iommu/arm-smmu-v3: Add CMDQ_PROD_STOP_FLAG to gate CMDQ submissions Pranjal Shrivastava
2026-09-29 5:55 ` sashiko-bot
2026-09-30 20:33 ` Nicolin Chen
2026-10-01 5:40 ` Pranjal Shrivastava
2026-10-01 18:03 ` Nicolin Chen
2026-10-02 16:47 ` Jason Gunthorpe
2026-10-02 21:11 ` Pranjal Shrivastava
2026-10-06 17:26 ` Nicolin Chen
2026-10-07 14:08 ` Will Deacon
2026-09-29 3:45 ` [PATCH v11 12/16] iommu/tegra241-cmdqv: Add a helper to quiesce VCMDQs Pranjal Shrivastava
2026-09-29 6:05 ` sashiko-bot
2026-09-30 19:02 ` Nicolin Chen
2026-09-30 19:57 ` Pranjal Shrivastava
2026-09-30 20:03 ` Nicolin Chen
2026-09-29 3:45 ` [PATCH v11 13/16] iommu/arm-smmu-v3: Implement pm_runtime & system sleep ops Pranjal Shrivastava
2026-09-29 6:17 ` sashiko-bot
2026-10-01 20:22 ` Nicolin Chen
2026-10-07 14:08 ` Will Deacon
2026-09-29 3:45 ` [PATCH v11 14/16] iommu/arm-smmu-v3: Enable pm_runtime and setup devlinks Pranjal Shrivastava
2026-09-29 6:32 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 15/16] iommu/arm-smmu-v3: Invoke pm_runtime before hw access Pranjal Shrivastava
2026-09-29 6:41 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 16/16] iommu/arm-smmu-v3: Add KUnit unit tests for Runtime PM Pranjal Shrivastava
2026-09-29 6:48 ` sashiko-bot
2026-10-01 19:12 ` Nicolin Chen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929052223.C3A411F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=praan@google.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox