Re: [PATCH v8] wifi: ath11k: fix resource leak on error in ext IRQ setup
Rameshkumar Sundaram <[email protected]> Thu, 30 Jul 2026 15:03:37 +0530
| Newsgroups | org.infradead.lists.ath11k,org.kernel.vger.linux-kernel,org.kernel.vger.linux-wireless |
|---|---|
| Message-ID | <[email protected]> |
On 7/29/2026 7:30 AM, ZhaoJinming wrote: > In ath11k_ahb_config_irq(), when a CE request_irq() fails, the function > returns the error immediately without freeing the CE IRQs that were > successfully registered in previous loop iterations. The probe error > path does not call ath11k_ahb_free_irq() either, so the previously > registered CE IRQ handlers remain attached to the interrupt lines and > are never released. > > In ath11k_ahb_config_ext_irq(), when an external request_irq() fails, > the error is only logged and the loop continues. The function then > returns 0 indicating success, leaving the device in a partially > configured state where some external IRQs are not registered. This > causes enable_irq()/disable_irq()/free_irq() to be called on > unregistered IRQs during runtime and remove/shutdown, triggering > WARN_ON(!desc->action), and missing interrupt handlers lead to data > loss. > > Additionally, if alloc_netdev_dummy() fails for a later IRQ group, the > function returns -ENOMEM without freeing the ext IRQs and napi_ndev > that were successfully set up for earlier groups. > > Fix all three issues: propagate the error up to the caller and unwind > all successfully registered IRQs and allocated resources on failure. > Also move ab->irq_num[irq_idx] assignment after request_irq() succeeds > in the ext IRQ path to match the CE IRQ path and avoid storing a stale > IRQ number on failure. > > Signed-off-by: ZhaoJinming <[email protected]> Reviewed-by: Rameshkumar Sundaram <[email protected]>