Linux s390 Architecture development
 help / color / mirror / Atom feed
* [PATCH v3 0/8] s390/pci: Fix bugs in IRQ domain migration and resource cleanup
@ 2026-10-09  6:15 Tobias Schumacher
  2026-10-09  6:15 ` [PATCH v3 1/8] s390/pci: Fix double-free and NULL deref in zpci MSI domain cleanup Tobias Schumacher
                   ` (7 more replies)
  0 siblings, 8 replies; 19+ messages in thread
From: Tobias Schumacher @ 2026-10-09  6:15 UTC (permalink / raw)
  To: Niklas Schnelle, Gerd Bayer, Julian Ruess, Farhan Ali,
	Christian Borntraeger, Halil Pasic, Matthew Rosato
  Cc: Heiko Carstens, Vasily Gorbik, Alexander Gordeev, Sven Schnelle,
	linux-s390, linux-kernel, Tobias Schumacher

Commit f770950a4709 ("s390/pci: Migrate s390 IRQ logic to IRQ
domain API") introduced several bugs in error handling and cleanup
paths. This series fixes these issues:

1. Double-free and NULL dereference in the parent MSI domain cleanup
2. Leak of a zpci_sbv summary bit when AIBV creation fails
3. Directed-mode teardown freeing zdev->max_msi bits instead of the
   zdev->msi_nr_irqs bits that were allocated
4. Use-after-free race between floating IRQ delivery and teardown

Patch 5 is unrelated to the migration. zpci_directed_irq_init() has
leaked its allocations on the -ENOMEM paths since it was added in
e979ce7bced2 ("s390/pci: provide support for CPU directed interrupts").

Patch 6 is a cleanup that removes an unnecessary update of
zpci_msi_parent_ops from the per-bus domain creation path.

Patch 7 is a cleanup that drops the unused index argument of
zpci_msi_clear_airq(). The doubled index it removes never selected a
wrong entry, so it is not a fix.

Patch 8 is a cleanup that unregisters the adapter interrupt first in
zpci_irq_exit().

Patches 1 to 5 carry Cc: stable. Patches 6 to 8 do not; none of them
changes behaviour.

Signed-off-by: Tobias Schumacher <ts@linux.ibm.com>
---
Changes in v3:
- Reverted ordering change in zpci_msi_teardown_floating() (patch 4)
- Patch 5: move zpci_set_irq_ctrl() after allocations in
  zpci_directed_irq_init()
- Patch 5: add Cc: stable
- Added patch 8 which changes teardown ordering in zpci_irq_exit()
- Link to v2: https://lore.kernel.org/r/20261005-s390_irq_domain_fixes-v2-0-d45b824874c0@linux.ibm.com

Changes in v2:
- Capitalize the word after the "s390/pci:" prefix on all subjects
- Replace the "add NULL check in zpci_msi_clear_airq()" patch with a
  cleanup that drops the unused index argument, and move it to the end
  of the series
- Patch 4: clear zpci_ibv[] before the grace period, free the summary
  bit after it, publish with rcu_assign_pointer()
- Patch 5: correct the Fixes: tag, drop Cc: stable
- Link to v1: https://lore.kernel.org/r/20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com

---
Tobias Schumacher (8):
      s390/pci: Fix double-free and NULL deref in zpci MSI domain cleanup
      s390/pci: Fix resource leak in zpci MSI setup
      s390/pci: Fix MSI directed-mode teardown IRQ bit count
      s390/pci: Fix use-after-free race in zpci floating interrupt cleanup
      s390/pci: Add error cleanup in zpci_directed_irq_init()
      s390/pci: Set MSI_FLAG_NO_AFFINITY at IRQ init time
      s390/pci: Drop the unused index argument of zpci_msi_clear_airq()
      s390/pci: Unregister the adapter interrupt first in zpci_irq_exit()

 arch/s390/pci/pci_irq.c | 109 +++++++++++++++++++++++++++++-------------------
 1 file changed, 67 insertions(+), 42 deletions(-)
---
base-commit: a90ee4305c4a5df72c11b31dacfdc76e00fcf78a
change-id: 20260818-s390_irq_domain_fixes-ad74b3134c51

Best regards,
-- 
Tobias Schumacher <ts@linux.ibm.com>


^ permalink raw reply	[flat|nested] 19+ messages in thread

end of thread, other threads:[~2026-10-09  8:22 UTC | newest]

Thread overview: 19+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-09  6:15 [PATCH v3 0/8] s390/pci: Fix bugs in IRQ domain migration and resource cleanup Tobias Schumacher
2026-10-09  6:15 ` [PATCH v3 1/8] s390/pci: Fix double-free and NULL deref in zpci MSI domain cleanup Tobias Schumacher
2026-10-09  6:28   ` sashiko-bot
2026-10-09  6:15 ` [PATCH v3 2/8] s390/pci: Fix resource leak in zpci MSI setup Tobias Schumacher
2026-10-09  6:28   ` sashiko-bot
2026-10-09  6:15 ` [PATCH v3 3/8] s390/pci: Fix MSI directed-mode teardown IRQ bit count Tobias Schumacher
2026-10-09  6:33   ` sashiko-bot
2026-10-09  6:15 ` [PATCH v3 4/8] s390/pci: Fix use-after-free race in zpci floating interrupt cleanup Tobias Schumacher
2026-10-09  6:32   ` sashiko-bot
2026-10-09  8:22     ` Tobias Schumacher
2026-10-09  6:15 ` [PATCH v3 5/8] s390/pci: Add error cleanup in zpci_directed_irq_init() Tobias Schumacher
2026-10-09  6:25   ` sashiko-bot
2026-10-09  6:15 ` [PATCH v3 6/8] s390/pci: Set MSI_FLAG_NO_AFFINITY at IRQ init time Tobias Schumacher
2026-10-09  6:26   ` sashiko-bot
2026-10-09  6:15 ` [PATCH v3 7/8] s390/pci: Drop the unused index argument of zpci_msi_clear_airq() Tobias Schumacher
2026-10-09  6:23   ` sashiko-bot
2026-10-09  6:15 ` [PATCH v3 8/8] s390/pci: Unregister the adapter interrupt first in zpci_irq_exit() Tobias Schumacher
2026-10-09  6:29   ` sashiko-bot
2026-10-09  7:10     ` Tobias Schumacher

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox