Re: [PATCH v9 1/5] PCI: dwc: ep: Clear MSI iATU mapping in dw_pcie_ep_cleanup()

Niklas Cassel <[email protected]>
Newsgroups org.kernel.vger.linux-pci,dev.linux.lists.sashiko-reviews
Message-ID <ampyhZmYPQl3U8HT@ryzen>
On Wed, Jul 29, 2026 at 05:15:42AM +0000, [email protected] wrote:
> [Severity: High]
> This is a pre-existing issue, but does the persistent MSI iATU mapping
> conflict with dynamic MSI-X iATU mapping?
> 
> Both MSI and MSI-X use the same physical address (ep->msi_mem_phys). If
> dw_pcie_ep_raise_msi_irq() caches the ATU mapping, and then
> dw_pcie_ep_raise_msix_irq() is called, it maps the same address to a new
> window:
> 
> drivers/pci/controller/dwc/pcie-designware-ep.c:dw_pcie_ep_raise_msix_irq() {
>     ...
>     ret = dw_pcie_ep_map_addr(epc, func_no, 0, ep->msi_mem_phys, msg_addr,
>                               map_size);
>     ...
> }
> 
> When dw_pcie_ep_raise_msix_irq() later calls dw_pcie_ep_unmap_addr(), the
> lookup function returns the first matching address:
> 
> drivers/pci/controller/dwc/pcie-designware-ep.c:dw_pcie_find_index() {
>     ...
>     if (ep->outbound_addr[index] != addr)
>         continue;
>     *atu_index = index;
>     return 0;
> }
> 
> Could this unmap the cached MSI window instead of the newly allocated MSI-X
> window, permanently leaking the MSI-X window?

This pre-existing bug sounds a bit nasty.

I sent a proposed fix, please review:
https://lore.kernel.org/linux-pci/[email protected]/T/#u


Kind regards,
Niklas
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.