Re: [PATCH v4] irqchip/renesas-irqc: fix generic interrupt chip leak on remove
Geert Uytterhoeven <[email protected]>
| Newsgroups | org.kernel.vger.linux-renesas-soc,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <CAMuHMdUxEnBx-2dvjSUPMjEb__0c-44y00OH9oftkPqoW18YyA@mail.gmail.com> |
Hi Qingshuang, On Wed, 8 Jul 2026 at 11:39, Qingshuang Fu <[email protected]> wrote: > From: Qingshuang Fu <[email protected]> > > The driver allocates domain generic chips using > irq_alloc_domain_generic_chips() during probe. However, on driver > remove, the generic chips are not automatically freed when the interrupt > domain is removed because the domain flags do not include > IRQ_DOMAIN_FLAG_DESTROY_GC. > > This causes both the domain generic chips structure and the associated > generic chips to be leaked. Additionally, the generic chips remain on > the global gc_list and may later be visited by generic interrupt chip > suspend, resume, or shutdown callbacks after the driver has been removed, > potentially resulting in a use-after-free and kernel crash. > > Fix the resource leak by setting IRQ_DOMAIN_FLAG_DESTROY_GC on the > interrupt domain; this lets the interrupt domain core automatically > release all generic chips when irq_domain_remove() is called, removing > the need for manual cleanup calls in error paths and remove callback. > > Fixes: 99c221df33fbfa1b ("irqchip/renesas-irqc: Move over to nested generic chip") Thanks for the update! No changelog? > Signed-off-by: Qingshuang Fu <[email protected]> > Reviewed-by: Geert Uytterhoeven <[email protected]> Please do not retain Rb-tags when completely changing a patch. > --- a/drivers/irqchip/irq-renesas-irqc.c > +++ b/drivers/irqchip/irq-renesas-irqc.c > @@ -194,6 +194,9 @@ static int irqc_probe(struct platform_device *pdev) > p->gc->chip_types[0].chip.irq_set_wake = irqc_irq_set_wake; > p->gc->chip_types[0].chip.flags = IRQCHIP_MASK_ON_SUSPEND; > > + /* Automatically free generic chips when interrupt domain is destroyed */ I am not sure you need the comment. > + p->irq_domain->flags |= IRQ_DOMAIN_FLAG_DESTROY_GC; > + LGTM, but you may want to do this right after creating p->irq_domain, like is done in pdc_intc_probe(). > irq_domain_set_pm_device(p->irq_domain, dev); > > /* request interrupts one by one */ > Gr{oetje,eeting}s, Geert -- Geert Uytterhoeven -- There's lots of Linux beyond ia32 -- [email protected] In personal conversations with technical people, I call myself a hacker. But when I'm talking to journalists I just say "programmer" or something like that. -- Linus Torvalds