[REGRESSION] PCI: Dynamic OF node creation hangs on invalid bridge configuration

Angel J <[email protected]>
Newsgroups org.kernel.vger.linux-pci,dev.linux.lists.regressions,org.kernel.vger.linux-devicetree,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <GXe6anuewkS4bLNwca3cYOmUxN9csc0TxLYGSBc1qNRmfrmvFlcmD62wEM23TxfzfuXAv4P3yvUv7pyraleARrL1Na-aN8w-t9uc1Igu8DA=@httpd.dev>
Hello,

This regression was introduced in v6.17-rc1 and remains in the dynamic
PCI OF node code. Linux 6.18 fails very early during boot on my Dell XPS
8940 when CONFIG_PCI_DYNAMIC_OF_NODES=y. The display goes black before
any useful console or pstore output appears, and the machine remains
hung.

Disabling CONFIG_PCI_DYNAMIC_OF_NODES makes the same kernel boot normally.
Linux v6.19-rc5 also boots because the RP1 driver stopped selecting that
option, not because the dynamic PCI OF node code changed.

Hardware:

  System: Dell XPS 8940, board 0K3CM7, BIOS 2.27.1 (2025-04-03)
  CPU: Intel Core i7-11700 (Rocket Lake)
  Triggering device: 0000:00:00.0, Intel 8086:4c43
  Firmware boot: UEFI, ACPI-based x86_64

Test results:

  Linux 6.12.103: good
  Linux v6.17-rc1: bad
  Linux 6.18.44, CONFIG_PCI_DYNAMIC_OF_NODES=y: bad
  Linux 6.18.44, CONFIG_PCI_DYNAMIC_OF_NODES=n: good
  Linux 6.18.44, CONFIG_PCI_DYNAMIC_OF_NODES=y, skip invalid bridge: good
  Linux v6.19-rc4: bad
  Linux v6.19-rc5: good
  Linux 4621c338d33f: bad
  Linux e55feea3a03a: good

The first-parent boundary between the last two tests is:

  e55feea3a03a ("Merge tag 'soc-fixes-6.19' ...")

That merge contains ce26f588c831 ("misc: rp1: drop overlay support"), which
removes:

  select PCI_DYNAMIC_OF_NODES

from MISC_RP1. The generated configurations differed only by:

  -CONFIG_PCI_DYNAMIC_OF_NODES=y
  +# CONFIG_PCI_DYNAMIC_OF_NODES is not set

CONFIG_MISC_RP1=m in both. The known-bad 4621c338d33f and Linux 6.18.44
both boot after disabling PCI_DYNAMIC_OF_NODES (and MISC_RP1, whose Kconfig
select otherwise forces it on).

There is no RP1 device in this machine, and its driver does not probe.
MISC_RP1 affects this x86 system only because its Kconfig select enables
PCI_DYNAMIC_OF_NODES globally.

I narrowed the hang to dynamic OF node creation for 0000:00:00.0
(8086:4c43), the Intel Rocket Lake-S integrated memory controller. On
this machine it reports PCI class 0604 and header type 1, but it is bound
to icl_uncore and is not a usable forwarding bridge:

  Bus: primary=ff, secondary=ff, subordinate=ff
  I/O and memory bridge windows: invalid/all ones
  kernel: bridge configuration invalid ([bus ff-ff]), reconfiguring

A minimal dynamic node for this device boots. Adding only
device_type="pci" makes it hang. Full PCI dynamic OF node generation also
boots when only 0000:00:00.0 is skipped.

I also tested a generic guard in of_pci_make_dev_node(). It reads
PCI_PRIMARY_BUS and skips node creation if the primary bus does not match
pdev->bus->number, the secondary bus is not greater than the primary bus,
or the secondary bus is greater than the subordinate bus. Linux 6.18.44
boots with CONFIG_PCI_DYNAMIC_OF_NODES=y and logs:

  pci 0000:00:00.0: skipping dynamic OF node for invalid bridge

The regression was introduced by 49d63971f963 in v6.17-rc1. Commit
ce26f588c831 made v6.19-rc5 boot by removing MISC_RP1's select of
PCI_DYNAMIC_OF_NODES. That avoids the failing path in the tested
configuration but does not change of_pci_make_dev_node().

I do not have a log from the failed boots. No output appeared with
earlyprintk=efi,keep, keep_bootcon, ignore_loglevel, loglevel=8,
initcall_debug, and EFI pstore enabled. Blacklisting both GPU drivers and
disabling the Intel IOMMU did not make the bad kernel boot.

Should of_pci_make_dev_node() reject devices with invalid bridge bus
configuration, or should 8086:4c43 use a device-specific quirk? I can
prepare and test a patch for either approach. For Linux 6.18 stable,
would that fix be preferable to backporting ce26f588c831 and its
dependencies?

#regzbot introduced: 49d63971f963
#regzbot title: PCI_DYNAMIC_OF_NODES early boot hang on ACPI x86

Thanks,
Angel J
signature.asc (application/pgp-signature, 343 B)
-----BEGIN PGP SIGNATURE-----
Version: ProtonMail

wrsEARYKAG0FgmqKV28JEBoBbwppzUxnRRQAAAAAABwAIHNhbHRAbm90YXRp
b25zLm9wZW5wZ3Bqcy5vcmdLuaAoGKL92QTzbI2Uy7jw4k6tIc99AdBp6S6r
YQoA3BYhBEAFf9htFyVnqZzmVhoBbwppzUxnAADIqQD/fnLk8GJzel74P3PZ
NqUm7u5JPB8p1goB/ebqiGCVVakA/jt6U8pQNghHs/SsdfY/fVJqNl9WXIEV
5zaRuPsjk5cK
=Lb99
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.