Xenomai real-time core development
 help / color / mirror / Atom feed
* [PATCH 1/2] genirq: irq_pipeline: Don't run handlers of disabled lines on replay
@ 2026-07-21  8:15 Richard Weinberger
  2026-07-21  8:15 ` [PATCH 2/2] mailbox: qcom-ipcc: Mark it as irq pipeline safe Richard Weinberger
  2026-07-23 14:23 ` [PATCH 1/2] genirq: irq_pipeline: Don't run handlers of disabled lines on replay Philippe Gerum
  0 siblings, 2 replies; 4+ messages in thread
From: Richard Weinberger @ 2026-07-21  8:15 UTC (permalink / raw)
  To: xenomai; +Cc: upstream+xenomai, Richard Weinberger

The pipelined handle_level_irq() function only checks unsing irq_can_handle()
on the IRQ_FLOW_START path, assuming that an event which reaches
the in-band replay path already passed this check when it was deferred
at pipeline entry.
This assumption does not hold for interrupts demultiplexed by an
in-band parent action handler.

This was observed on qcom hardware, the qcom-ipcc summary interrupt is
an in-band line, hence its demux handler runs from the replay path.
qcom_glink_smem requests its child IPCC interrupt with IRQF_NO_AUTOEN
and only enables it once smem->glink has been assigned, but the demux
delivered the interrupt early, dereferencing the still-NULL pointer:

Unable to handle kernel NULL pointer dereference at 00000000000000a0
Call trace:
_raw_spin_lock_irqsave+0x40/0x9c
__wake_up+0x28/0x70
qcom_glink_native_rx+0x58/0x6a4
qcom_glink_smem_intr+0x14/0x24
__handle_irq_event_percpu+0x4c/0x1c8
handle_irq_event+0x54/0x11c
handle_level_irq+0x150/0x24c
generic_handle_irq+0x24/0x30
qcom_ipcc_irq_fn+0x5c/0xb4
__handle_irq_event_percpu+0x4c/0x1c8
handle_irq_event+0x54/0x11c
handle_fasteoi_irq+0x164/0x278
arch_do_IRQ_pipelined+0x44/0x6c
sync_current_irq_stage+0x150/0x1e0

Signed-off-by: Richard Weinberger <richard@nod.at>
---
 kernel/irq/chip.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/kernel/irq/chip.c b/kernel/irq/chip.c
index 562cc856a3871..1b33a9599c46d 100644
--- a/kernel/irq/chip.c
+++ b/kernel/irq/chip.c
@@ -948,6 +948,11 @@ void handle_level_irq(struct irq_desc *desc)
 		return;
 	}
 
+	if (!irq_can_handle_actions(desc)) {
+		mask_irq(desc);
+		return;
+	}
+
 	kstat_incr_irqs_this_cpu(desc);
 	handle_irq_event(desc);
 
-- 
2.51.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* [PATCH 2/2] mailbox: qcom-ipcc: Mark it as irq pipeline safe
  2026-07-21  8:15 [PATCH 1/2] genirq: irq_pipeline: Don't run handlers of disabled lines on replay Richard Weinberger
@ 2026-07-21  8:15 ` Richard Weinberger
  2026-07-23 14:28   ` Philippe Gerum
  2026-07-23 14:23 ` [PATCH 1/2] genirq: irq_pipeline: Don't run handlers of disabled lines on replay Philippe Gerum
  1 sibling, 1 reply; 4+ messages in thread
From: Richard Weinberger @ 2026-07-21  8:15 UTC (permalink / raw)
  To: xenomai; +Cc: upstream+xenomai, Richard Weinberger

With the summary IRQ OOB capable, child IRQs can also
run OOB and the driver is irq  pipeline safe.

Signed-off-by: Richard Weinberger <richard@nod.at>
---
 drivers/mailbox/qcom-ipcc.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/mailbox/qcom-ipcc.c b/drivers/mailbox/qcom-ipcc.c
index d957d989c0cee..c316d8b4c03c4 100644
--- a/drivers/mailbox/qcom-ipcc.c
+++ b/drivers/mailbox/qcom-ipcc.c
@@ -110,7 +110,7 @@ static struct irq_chip qcom_ipcc_irq_chip = {
 	.name = "ipcc",
 	.irq_mask = qcom_ipcc_mask_irq,
 	.irq_unmask = qcom_ipcc_unmask_irq,
-	.flags = IRQCHIP_SKIP_SET_WAKE,
+	.flags = IRQCHIP_SKIP_SET_WAKE | IRQCHIP_PIPELINE_SAFE,
 };
 
 static int qcom_ipcc_domain_map(struct irq_domain *d, unsigned int irq,
@@ -322,7 +322,7 @@ static int qcom_ipcc_probe(struct platform_device *pdev)
 
 	ret = devm_request_irq(&pdev->dev, ipcc->irq, qcom_ipcc_irq_fn,
 			       IRQF_TRIGGER_HIGH | IRQF_NO_SUSPEND |
-			       IRQF_NO_THREAD, name, ipcc);
+			       IRQF_NO_THREAD | IRQF_OOB, name, ipcc);
 	if (ret < 0) {
 		dev_err(&pdev->dev, "Failed to register the irq: %d\n", ret);
 		goto err_req_irq;
-- 
2.51.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH 1/2] genirq: irq_pipeline: Don't run handlers of disabled lines on replay
  2026-07-21  8:15 [PATCH 1/2] genirq: irq_pipeline: Don't run handlers of disabled lines on replay Richard Weinberger
  2026-07-21  8:15 ` [PATCH 2/2] mailbox: qcom-ipcc: Mark it as irq pipeline safe Richard Weinberger
@ 2026-07-23 14:23 ` Philippe Gerum
  1 sibling, 0 replies; 4+ messages in thread
From: Philippe Gerum @ 2026-07-23 14:23 UTC (permalink / raw)
  To: Richard Weinberger; +Cc: xenomai, upstream+xenomai


Hi Richard,

Richard Weinberger <richard@nod.at> writes:

> The pipelined handle_level_irq() function only checks unsing irq_can_handle()
> on the IRQ_FLOW_START path, assuming that an event which reaches
> the in-band replay path already passed this check when it was deferred
> at pipeline entry.
> This assumption does not hold for interrupts demultiplexed by an
> in-band parent action handler.
>
> This was observed on qcom hardware, the qcom-ipcc summary interrupt is
> an in-band line, hence its demux handler runs from the replay path.
> qcom_glink_smem requests its child IPCC interrupt with IRQF_NO_AUTOEN
> and only enables it once smem->glink has been assigned, but the demux
> delivered the interrupt early, dereferencing the still-NULL pointer:
>

Nice catch, merged, thanks.

-- 
Philippe.

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH 2/2] mailbox: qcom-ipcc: Mark it as irq pipeline safe
  2026-07-21  8:15 ` [PATCH 2/2] mailbox: qcom-ipcc: Mark it as irq pipeline safe Richard Weinberger
@ 2026-07-23 14:28   ` Philippe Gerum
  0 siblings, 0 replies; 4+ messages in thread
From: Philippe Gerum @ 2026-07-23 14:28 UTC (permalink / raw)
  To: Richard Weinberger; +Cc: xenomai, upstream+xenomai

Richard Weinberger <richard@nod.at> writes:

> With the summary IRQ OOB capable, child IRQs can also
> run OOB and the driver is irq  pipeline safe.
>
> Signed-off-by: Richard Weinberger <richard@nod.at>
> ---
>  drivers/mailbox/qcom-ipcc.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/mailbox/qcom-ipcc.c b/drivers/mailbox/qcom-ipcc.c
> index d957d989c0cee..c316d8b4c03c4 100644
> --- a/drivers/mailbox/qcom-ipcc.c
> +++ b/drivers/mailbox/qcom-ipcc.c
> @@ -110,7 +110,7 @@ static struct irq_chip qcom_ipcc_irq_chip = {
>  	.name = "ipcc",
>  	.irq_mask = qcom_ipcc_mask_irq,
>  	.irq_unmask = qcom_ipcc_unmask_irq,
> -	.flags = IRQCHIP_SKIP_SET_WAKE,
> +	.flags = IRQCHIP_SKIP_SET_WAKE | IRQCHIP_PIPELINE_SAFE,
>  };
>  
>  static int qcom_ipcc_domain_map(struct irq_domain *d, unsigned int irq,
> @@ -322,7 +322,7 @@ static int qcom_ipcc_probe(struct platform_device *pdev)
>  
>  	ret = devm_request_irq(&pdev->dev, ipcc->irq, qcom_ipcc_irq_fn,
>  			       IRQF_TRIGGER_HIGH | IRQF_NO_SUSPEND |
> -			       IRQF_NO_THREAD, name, ipcc);
> +			       IRQF_NO_THREAD | IRQF_OOB, name, ipcc);
>  	if (ret < 0) {
>  		dev_err(&pdev->dev, "Failed to register the irq: %d\n", ret);
>  		goto err_req_irq;

Merged, thanks.

-- 
Philippe.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-07-23 14:28 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-21  8:15 [PATCH 1/2] genirq: irq_pipeline: Don't run handlers of disabled lines on replay Richard Weinberger
2026-07-21  8:15 ` [PATCH 2/2] mailbox: qcom-ipcc: Mark it as irq pipeline safe Richard Weinberger
2026-07-23 14:28   ` Philippe Gerum
2026-07-23 14:23 ` [PATCH 1/2] genirq: irq_pipeline: Don't run handlers of disabled lines on replay Philippe Gerum

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox