Re: [PATCH v6 18/23] xen/riscv: implement IRQ routing for device passthrough

Oleksii Kurochko <[email protected]> Thu, 30 Jul 2026 13:31:44 +0200
Newsgroups gmane.comp.emulators.xen.devel
Message-ID <[email protected]>

On 7/30/26 9:18 AM, Jan Beulich wrote:
> On 29.07.2026 17:23, Oleksii Kurochko wrote:
>>
>>
>> On 7/29/26 5:02 PM, Oleksii Kurochko wrote:
>>>
>>>
>>> On 7/29/26 4:15 PM, Jan Beulich wrote:
>>>> On 29.07.2026 13:59, Oleksii Kurochko wrote:
>>>>> On 7/23/26 3:30 PM, Jan Beulich wrote:
>>>>>> On 20.07.2026 17:59, Oleksii Kurochko wrote:
>>>>>>> +/* Route an IRQ to a specific guest */
>>>>>>> +int route_irq_to_guest(struct domain *d, unsigned int virq,
>>>>>>> +                       unsigned int irq, const char *devname)
>>>>>>> +{
>>>>>>> +    struct irqaction *action;
>>>>>>> +    struct irq_guest *info;
>>>>>>> +    struct irq_desc *desc;
>>>>>>> +    unsigned long flags;
>>>>>>> +    int retval = 0;
>>>>>>> +
>>>>>>> +    if ( d->is_dying )
>>>>>>> +        return -EINVAL;
>>>>>>> +
>>>>>>> +    desc = irq_to_desc(irq);
>>>>>>> +
>>>>>>> +    /*
>>>>>>> +     * release_irq() frees this action via xvfree(), relying on
>>>>>>> action
>>>>>>> +     * being the first member of struct irq_guest so that &info-
>>>>>>>> action
>>>>>>> +     * coincides with info itself. Guard the layout so a future field
>>>>>>> +     * reorder can't silently turn that into a free() of a mid-
>>>>>>> allocation
>>>>>>> +     * pointer.
>>>>>>> +     */
>>>>>>> +    BUILD_BUG_ON(offsetof(struct irq_guest, action) != 0);
>>>>>>
>>>>>> Can't release_irq() simply use container_of()? One way or another it
>>>>>> feels
>>>>>> like you're painting yourself into a particular corner ...
>>>>>
>>>>> If it isn't the best option then it is needed to follow they way we had
>>>>> before:
>>>>
>>>> I don't understand why you think you need to go back.
>>>
>>> Because, based on your reply—specifically, "One way or another it feels
>>> like you're painting yourself into a particular corner..." — it seems
>>> that even if I replaced BUILD_BUG_ON() with container_of() in
>>> release_irq(), you would still consider it a bad solution. Did I
>>> misunderstand your point?
>>
>> One more thing: I'm not really sure it's safe to do the following in
>> release_irq():
>>
>> if ( action->free_on_release )
>>       xvfree(container_of(action, struct irq_guest, action));
>>
>> release_irq() is a generic API, but this kind of allocation is only
>> needed for guest IRQs. Wouldn't it be better to set:
>>
>> action->free_on_release = false;
>>
>> for guest IRQs, and then free the memory in release_guest_irq() after
>> the call to release_irq()?
> 
> Perhaps.
> 
>> Wouldn't that be a better approach than calling
>> `xvfree(container_of(...))` from within the generic release_irq()?
> 
> Perhaps.
> 
> What I'd really like to see you do is come up with an approach that is
> both self-consistent and future-proof. With the latter aspect meaning that
> it should be (reasonably) easy to identify places that need changing if
> e.g. the "->free_on_release is only ever one value" property goes away.
> 

An approach with action->free_on_release = false; together with 
vfree(info) in release_guest_irq() seems to be the best option. Since 
action is no longer allocated dynamically, it should not be freed 
through free_on_release, so setting it to false makes that explicit. 
Additionally, guest IRQs have extra state (struct irq_guest), and it is 
the responsibility of release_guest_irq() to clean it up.

This also keeps the semantics of ->free_on_release consistent for Xen 
IRQs. If it is set to true, release_irq() is responsible for freeing 
struct irq_action; if it is false, release_irq() should not free it.

For guest interrupts, release_irq() should not free anything because 
struct irq_action is embedded in struct irq_guest, which is freed by 
release_guest_irq(). If, in the future, guest interrupts need 
->free_on_release = true, the only required change would be to allocate 
struct irq_action dynamically and set ->free_on_release = true. All 
other is already covered. That makes the design, in my opinion, 
self-consistent and future-proof.

~ Oleksii