From: sashiko-bot@kernel.org
To: "Long Zhao" <longzhao@ambarella.com>
Cc: linux-serial@vger.kernel.org, robh@kernel.org,
linux-clk@vger.kernel.org, lee@kernel.org, conor+dt@kernel.org,
mfd@lists.linux.dev, devicetree@vger.kernel.org
Subject: Re: [PATCH v9 11/15] gpio: pl061: switch data path to gpio-regmap
Date: Thu, 01 Oct 2026 12:56:06 +0000 [thread overview]
Message-ID: <20261001125606.D99071F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261001-cv75-v5-v9-11-486cc289a4b8@ambarella.com>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] gpio: pl061: UAF due to LIFO devres cleanup ordering
- [High] gpio: pl061: Missing GPIOCHIP_IRQ_RESOURCE_HELPERS allows HW conflict
- [Medium] gpio: pl061: Missing synchronize_irq() causes UAF on module unload
--
commit 0dd970f78f76a57be040a10722f95f7c065440ed
Author: Long Zhao <longzhao@ambarella.com>
gpio: pl061: switch data path to gpio-regmap
This commit migrates the PL061 driver to use gpio-regmap for its data path,
handling the PL061 quirk where output values must be written after a direction
change. It sets up a custom irqchip and domain attached via gpio-regmap, and
modifies the interrupt handler to appropriately check regmap reads.
> diff --git a/drivers/gpio/gpio-pl061.c b/drivers/gpio/gpio-pl061.c
> index c821a5117eede..08d45f8923c2a 100644
> --- a/drivers/gpio/gpio-pl061.c
> +++ b/drivers/gpio/gpio-pl061.c
[ ... ]
> -static const struct irq_chip pl061_irq_chip = {
> +static const struct irq_chip pl061_irqchip = {
> + .name = "pl061",
> .irq_ack = pl061_irq_ack,
> .irq_mask = pl061_irq_mask,
> .irq_unmask = pl061_irq_unmask,
> @@ -322,67 +256,187 @@ static const struct irq_chip pl061_irq_chip = {
> .irq_set_wake = pl061_irq_set_wake,
> .irq_print_chip = pl061_irq_print_chip,
> .flags = IRQCHIP_IMMUTABLE,
> - GPIOCHIP_IRQ_RESOURCE_HELPERS,
> -};
> +};
[Severity: High]
Does the omission of GPIOCHIP_IRQ_RESOURCE_HELPERS from this irq_chip
definition detach it from gpiolib's resource locking?
Without these helpers, gpiochip_lock_as_irq() is never called when a pin
is requested as an IRQ, so GPIOD_FLAG_USED_AS_IRQ is not set. Could this
allow userspace to accidentally reconfigure an active IRQ pin as an output,
causing hardware conflicts?
> +
> +static int pl061_irq_domain_map(struct irq_domain *d, unsigned int virq,
[ ... ]
> +static void pl061_remove_irq(void *data)
> +{
> + struct pl061 *pl061 = data;
> +
> + irq_set_chained_handler_and_data(pl061->parent_irq, NULL, NULL);
[Severity: Medium]
Is a call to synchronize_irq() needed here before proceeding?
While the chained handler is cleared, there appears to be no synchronization
with in-flight handlers. If pl061_irq_handler() is running concurrently
on another CPU, it might still be executing when we proceed.
> +
> + for (unsigned int i = 0; i < pl061->data->ngpio; i++) {
> + unsigned int virq;
> +
> + virq = irq_find_mapping(pl061->irq_domain, i);
> + if (virq)
> + irq_dispose_mapping(virq);
> + }
> +
> + irq_domain_remove(pl061->irq_domain);
[Severity: Medium]
If pl061_irq_handler() is still running, could it access this freed domain
when it calls generic_handle_domain_irq(pl061->irq_domain, offset)?
> +}
[ ... ]
> +static int pl061_probe(struct amba_device *adev, const struct amba_id *id)
> +{
[ ... ]
> + config.parent = dev;
> + config.regmap = pl061->regmap;
> + config.ngpio = data->ngpio;
> + config.reg_dat_base = GPIO_REGMAP_ADDR(regs->dat);
> + config.reg_set_base = GPIO_REGMAP_ADDR(regs->dat);
> + config.reg_dir_out_base = GPIO_REGMAP_ADDR(regs->dir);
> + config.reg_mask_xlate = data->reg_mask_xlate;
> + config.quirks = data->quirks;
> + config.irq_domain = pl061->irq_domain;
> + config.drvdata = pl061;
> +
> + gpio_regmap = devm_gpio_regmap_register(dev, &config);
> + if (IS_ERR(gpio_regmap)) {
> + if (pl061->irq_domain)
> + irq_domain_remove(pl061->irq_domain);
> + return PTR_ERR(gpio_regmap);
> + }
> +
> + if (irq) {
> + ret = devm_add_action_or_reset(dev, pl061_remove_irq, pl061);
[Severity: High]
Can this devres action registration order cause a use-after-free during
driver unbind?
Since devm_add_action_or_reset() is called after devm_gpio_regmap_register(),
devres will execute pl061_remove_irq() first during teardown because it uses
LIFO ordering.
This means pl061_remove_irq() will run and free pl061->irq_domain, but
the gpiochip is still registered. When gpio_regmap subsequently unregisters
the gpiochip, gpiochip_remove() will eventually call
gpiochip_free_remaining_irqs(), which will attempt to use the already-freed
irq.domain pointer.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261001-cv75-v5-v9-0-486cc289a4b8@ambarella.com?part=11
next prev parent reply other threads:[~2026-10-01 12:56 UTC|newest]
Thread overview: 41+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 12:40 [PATCH v9 00/15] Ambarella CV75 SoC minimal bring-up Long Zhao via B4 Relay
2026-10-01 12:40 ` [PATCH v9 01/15] dt-bindings: arm: add Ambarella CV75 platforms Long Zhao via B4 Relay
2026-10-01 12:43 ` sashiko-bot
2026-10-01 12:40 ` [PATCH v9 02/15] dt-bindings: mfd: syscon: add Ambarella CV75 secure scratchpad Long Zhao via B4 Relay
2026-10-01 12:43 ` sashiko-bot
2026-10-01 12:40 ` [PATCH v9 03/15] dt-bindings: clock: add Ambarella CV75 RCT Long Zhao via B4 Relay
2026-10-01 12:45 ` sashiko-bot
2026-10-01 12:40 ` [PATCH v9 04/15] dt-bindings: gpio: pl061: add Ambarella CV75 variant Long Zhao via B4 Relay
2026-10-01 12:50 ` sashiko-bot
2026-10-01 19:23 ` Conor Dooley
2026-10-01 19:36 ` Linus Walleij
2026-10-01 21:16 ` Conor Dooley
2026-10-01 12:40 ` [PATCH v9 05/15] dt-bindings: serial: snps-dw-apb-uart: add ambarella,cv75-uart Long Zhao via B4 Relay
2026-10-01 12:43 ` sashiko-bot
2026-10-01 12:40 ` [PATCH v9 06/15] clk: ambarella: add CV75 RCT clock controller Long Zhao via B4 Relay
2026-10-01 12:47 ` sashiko-bot
2026-10-02 8:10 ` Andy Shevchenko
2026-10-01 12:40 ` [PATCH v9 07/15] gpiolib: regmap: add GPIO_REGMAP_QUIRK_SET_AFTER_DIR Long Zhao via B4 Relay
2026-10-01 12:45 ` sashiko-bot
2026-10-02 7:41 ` Andy Shevchenko
2026-10-01 12:40 ` [PATCH v9 08/15] gpio: pl061: convert register access to regmap Long Zhao via B4 Relay
2026-10-01 12:47 ` sashiko-bot
2026-10-02 8:26 ` Andy Shevchenko
2026-10-01 12:40 ` [PATCH v9 09/15] gpio: pl061: use IRQ_TYPE_LEVEL_MASK and IRQ_TYPE_EDGE_BOTH Long Zhao via B4 Relay
2026-10-01 12:45 ` sashiko-bot
2026-10-02 9:22 ` Andy Shevchenko
2026-10-01 12:40 ` [PATCH v9 10/15] gpio: pl061: use cleanup helpers for locks Long Zhao via B4 Relay
2026-10-01 12:46 ` sashiko-bot
2026-10-01 12:41 ` [PATCH v9 11/15] gpio: pl061: switch data path to gpio-regmap Long Zhao via B4 Relay
2026-10-01 12:56 ` sashiko-bot [this message]
2026-10-01 12:41 ` [PATCH v9 12/15] gpio: pl061: add Ambarella register-layout variant Long Zhao via B4 Relay
2026-10-01 12:55 ` sashiko-bot
2026-10-01 12:41 ` [PATCH v9 13/15] serial: 8250_dw: add Ambarella CV75 quirks Long Zhao via B4 Relay
2026-10-01 12:49 ` sashiko-bot
2026-10-01 12:52 ` Greg Kroah-Hartman
2026-10-01 19:20 ` Linus Walleij
2026-10-02 2:17 ` zl020895
2026-10-02 8:09 ` Jerome Brunet
2026-10-01 12:41 ` [PATCH v9 14/15] arm64: ambarella: add ARCH_AMBARELLA and CV75 EVK DT Long Zhao via B4 Relay
2026-10-01 12:54 ` sashiko-bot
2026-10-01 12:41 ` [PATCH v9 15/15] MAINTAINERS: add ARM/AMBARELLA SoC support Long Zhao via B4 Relay
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001125606.D99071F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=lee@kernel.org \
--cc=linux-clk@vger.kernel.org \
--cc=linux-serial@vger.kernel.org \
--cc=longzhao@ambarella.com \
--cc=mfd@lists.linux.dev \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox