mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Bhargav Joshi <j.bhargav.u@gmail.com>
To: Thomas Gleixner <tglx@kernel.org>,
	Tony Lindgren <tony@atomide.com>,
	 Jason Cooper <jason@lakedaemon.net>,
	Marc Zyngier <maz@kernel.org>
Cc: linux-kernel@vger.kernel.org, goledhruva@gmail.com,
	m-chawdhry@ti.com,  daniel.baluta@gmail.com,
	simona.toaca@nxp.com, j.bhargav.u@gmail.com
Subject: [PATCH v2] irqchip: crossbar: Fix data race in allocate_gic_irq
Date: Wed, 10 Jun 2026 16:44:15 +0530	[thread overview]
Message-ID: <20260610-irq-spinlock-fix-v2-1-a6824a74a8dd@gmail.com> (raw)

In allocate_gic_irq(), if irq_domain_alloc_irqs_parent() fails, the
error path resets cb->irq_map[i] to IRQ_FREE. It modifies cb->irq_map[]
without holding cb->lock. modifying without lock could cause data race.

Fix this by acquiring raw_spin_lock around cb->irq_map[] modification.

Fixes: 783d31863fb8 ("irqchip: crossbar: Convert dra7 crossbar to stacked domains")

Signed-off-by: Bhargav Joshi <j.bhargav.u@gmail.com>
---
This bug was flagged by the Sashiko AI bot during the review process for
the DT schema conversion of ti,irq-crossbar binding.
https://lore.kernel.org/linux-devicetree/20260605210647.CCC881F00893@smtp.kernel.org/
---
Changes in v2:
- Fixed typo in spin_unlock
- Link to v1: https://patch.msgid.link/20260610-irq-spinlock-fix-v1-1-6f227ea9fa34@gmail.com
---
 drivers/irqchip/irq-crossbar.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/drivers/irqchip/irq-crossbar.c b/drivers/irqchip/irq-crossbar.c
index cd1134101ace..3d8bb37c9141 100644
--- a/drivers/irqchip/irq-crossbar.c
+++ b/drivers/irqchip/irq-crossbar.c
@@ -100,8 +100,11 @@ static int allocate_gic_irq(struct irq_domain *domain, unsigned virq,
 	fwspec.param[2] = IRQ_TYPE_LEVEL_HIGH;
 
 	err = irq_domain_alloc_irqs_parent(domain, virq, 1, &fwspec);
-	if (err)
+	if (err) {
+		raw_spin_lock(&cb->lock);
 		cb->irq_map[i] = IRQ_FREE;
+		raw_spin_unlock(&cb->lock);
+	}
 	else
 		cb->write(i, hwirq);
 

---
base-commit: 2d3090a8aeb596a26935db0955d46c9a5db5c6ce
change-id: 20260610-irq-spinlock-fix-1c90d8bc0f13

Best regards,
-- 
Bhargav


             reply	other threads:[~2026-06-10 11:14 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-10 11:14 Bhargav Joshi [this message]
2026-06-11 14:43 ` Thomas Gleixner
2026-06-11 21:40   ` Bhargav Joshi

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260610-irq-spinlock-fix-v2-1-a6824a74a8dd@gmail.com \
    --to=j.bhargav.u@gmail.com \
    --cc=daniel.baluta@gmail.com \
    --cc=goledhruva@gmail.com \
    --cc=jason@lakedaemon.net \
    --cc=linux-kernel@vger.kernel.org \
    --cc=m-chawdhry@ti.com \
    --cc=maz@kernel.org \
    --cc=simona.toaca@nxp.com \
    --cc=tglx@kernel.org \
    --cc=tony@atomide.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®