From: Bhargav Joshi <j.bhargav.u@gmail.com>
To: Thomas Gleixner <tglx@kernel.org>,
Tony Lindgren <tony@atomide.com>,
Jason Cooper <jason@lakedaemon.net>,
Marc Zyngier <maz@kernel.org>
Cc: linux-kernel@vger.kernel.org, goledhruva@gmail.com,
m-chawdhry@ti.com, daniel.baluta@gmail.com,
simona.toaca@nxp.com, j.bhargav.u@gmail.com
Subject: [PATCH v2] irqchip: crossbar: Fix data race in allocate_gic_irq
Date: Wed, 10 Jun 2026 16:44:15 +0530 [thread overview]
Message-ID: <20260610-irq-spinlock-fix-v2-1-a6824a74a8dd@gmail.com> (raw)
In allocate_gic_irq(), if irq_domain_alloc_irqs_parent() fails, the
error path resets cb->irq_map[i] to IRQ_FREE. It modifies cb->irq_map[]
without holding cb->lock. modifying without lock could cause data race.
Fix this by acquiring raw_spin_lock around cb->irq_map[] modification.
Fixes: 783d31863fb8 ("irqchip: crossbar: Convert dra7 crossbar to stacked domains")
Signed-off-by: Bhargav Joshi <j.bhargav.u@gmail.com>
---
This bug was flagged by the Sashiko AI bot during the review process for
the DT schema conversion of ti,irq-crossbar binding.
https://lore.kernel.org/linux-devicetree/20260605210647.CCC881F00893@smtp.kernel.org/
---
Changes in v2:
- Fixed typo in spin_unlock
- Link to v1: https://patch.msgid.link/20260610-irq-spinlock-fix-v1-1-6f227ea9fa34@gmail.com
---
drivers/irqchip/irq-crossbar.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/irqchip/irq-crossbar.c b/drivers/irqchip/irq-crossbar.c
index cd1134101ace..3d8bb37c9141 100644
--- a/drivers/irqchip/irq-crossbar.c
+++ b/drivers/irqchip/irq-crossbar.c
@@ -100,8 +100,11 @@ static int allocate_gic_irq(struct irq_domain *domain, unsigned virq,
fwspec.param[2] = IRQ_TYPE_LEVEL_HIGH;
err = irq_domain_alloc_irqs_parent(domain, virq, 1, &fwspec);
- if (err)
+ if (err) {
+ raw_spin_lock(&cb->lock);
cb->irq_map[i] = IRQ_FREE;
+ raw_spin_unlock(&cb->lock);
+ }
else
cb->write(i, hwirq);
---
base-commit: 2d3090a8aeb596a26935db0955d46c9a5db5c6ce
change-id: 20260610-irq-spinlock-fix-1c90d8bc0f13
Best regards,
--
Bhargav
next reply other threads:[~2026-06-10 11:14 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-10 11:14 Bhargav Joshi [this message]
2026-06-11 14:43 ` Thomas Gleixner
2026-06-11 21:40 ` Bhargav Joshi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260610-irq-spinlock-fix-v2-1-a6824a74a8dd@gmail.com \
--to=j.bhargav.u@gmail.com \
--cc=daniel.baluta@gmail.com \
--cc=goledhruva@gmail.com \
--cc=jason@lakedaemon.net \
--cc=linux-kernel@vger.kernel.org \
--cc=m-chawdhry@ti.com \
--cc=maz@kernel.org \
--cc=simona.toaca@nxp.com \
--cc=tglx@kernel.org \
--cc=tony@atomide.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®