From: Thomas Gleixner <tglx@kernel.org>
To: "Han / 한상우Sangwoo" <sangwoo.han@nearthlab.com>,
"Bjorn Helgaas" <helgaas@kernel.org>
Cc: jim2101024@gmail.com, florian.fainelli@broadcom.com,
lpieralisi@kernel.org, kwilczynski@kernel.org, mani@kernel.org,
bhelgaas@google.com, bcm-kernel-feedback-list@broadcom.com,
robh@kernel.org, linux-pci@vger.kernel.org,
linux-rpi-kernel@lists.infradead.org,
linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org, Inochi Amaoto <inochiama@gmail.com>
Subject: Re: [PATCH] PCI: brcmstb: Reserve only the MSI vectors that are handed out
Date: Thu, 01 Oct 2026 21:29:27 +0200 [thread overview]
Message-ID: <871pa9gqy0.ffs@fw13> (raw)
In-Reply-To: <CAFg7d9bJJjR7JEMXanttGVcGisa4x3uLYPR43Te4+JKMzHBkfQ@mail.gmail.com>
On Mon, Sep 21 2026 at 18:05, Han / 한상우Sangwoo wrote:
> I tested Thomas's patch on the same hardware setup with the 5-vector
> MSI endpoint. The patch was applied as posted on top of 6.12.93
> (rpi-6.12.y).
>
> With the patch applied:
>
> - The MSI base hwirq remained at 0x8 across 200 driver reload cycles.
> - The driver got all 5 requested vectors on every cycle, with no
> single-MSI fallback. Multiple Message Enable remained at 8.
> - The brcmstb inner-domain mapping returned to baseline after each
> unload/reload, with 12 mapped while the driver was loaded and 4 after
> unload.
> - A kprobe showed one allocation of 8 vectors followed by eight
> single-vector frees, with nothing left over.
8 single vector frees?
Seems I got something wrong there verus the bulk free. Updated patch
below.
> The MSI vector exhaustion issue I originally observed no longer
> reproduces with the patch.
Good. Can you please retest with the updated patch?
> I also observed a KASAN report with managed affinity. Using a small
> out-of-tree test module bound to the same endpoint and requesting 1..3
> vectors with PCI_IRQ_MSI | PCI_IRQ_AFFINITY, a request for 3 vectors
> resulted in:
>
> BUG: KASAN: slab-out-of-bounds in __irq_alloc_descs+0x158/0x460
>
> Requests for 5 and 7 vectors were capped to 4 on this 4-CPU system and
> did not trigger the report. I have not checked this against the
> unpatched kernel yet, so I cannot tell whether it is related to the
> patch.
Any updates on that? Also please provide the source for that test.
Thanks,
tglx
---
--- a/kernel/irq/irqdomain.c
+++ b/kernel/irq/irqdomain.c
@@ -1610,6 +1610,17 @@ static void irq_domain_free_irqs_hierarc
if (!domain->ops->free)
return;
+ /*
+ * MSI device domains are capable of bulk free.
+ *
+ * CHECKME: Are all MSI parent domains capable?
+ */
+ if (domain->flags & (IRQ_DOMAIN_FLAG_MSI_DEVICE | IRQ_DOMAIN_FLAG_MSI_PARENT)) {
+ if (irq_domain_get_irq_data(domain, irq_base))
+ domain->ops->free(domain, irq_base, nr_irqs);
+ return;
+ }
+
for (i = 0; i < nr_irqs; i++) {
if (irq_domain_get_irq_data(domain, irq_base + i))
domain->ops->free(domain, irq_base + i, 1);
--- a/kernel/irq/msi.c
+++ b/kernel/irq/msi.c
@@ -1333,20 +1333,28 @@ static int __msi_domain_alloc_irqs(struc
ops->set_desc(&arg, desc);
- virq = __irq_domain_alloc_irqs(domain, -1, desc->nvec_used,
+ /* Make sure a MULTI-MSI allocation is power of two */
+ unsigned int nvec_aligned = roundup_pow_of_two(desc->nvec_used);
+
+ virq = __irq_domain_alloc_irqs(domain, -1, nvec_aligned,
dev_to_node(dev), &arg, false,
desc->affinity);
if (virq < 0)
return msi_handle_pci_fail(domain, desc, allocated);
- for (i = 0; i < desc->nvec_used; i++) {
+ for (i = 0; i < nvec_aligned; i++) {
irq_set_msi_desc_off(virq, i, desc);
irq_debugfs_copy_devname(virq + i, dev);
ret = msi_init_virq(domain, virq + i, vflags);
if (ret)
return ret;
}
+
if (info->flags & MSI_FLAG_DEV_SYSFS) {
+ /*
+ * This only exposes desc->nvec_used and ignores the
+ * overallocated MULTI-MSI ones.
+ */
ret = msi_sysfs_populate_desc(dev, desc);
if (ret)
return ret;
@@ -1610,13 +1618,15 @@ static void __msi_domain_free_irqs(struc
continue;
/* Make sure all interrupts are deactivated */
- for (i = 0; i < desc->nvec_used; i++) {
+ unsigned int nvec_aligned = roundup_pow_of_two(desc->nvec_used);
+
+ for (i = 0; i < nvec_aligned; i++) {
irqd = irq_domain_get_irq_data(domain, desc->irq + i);
if (irqd && irqd_is_activated(irqd))
irq_domain_deactivate_irq(irqd);
}
- irq_domain_free_irqs(desc->irq, desc->nvec_used);
+ irq_domain_free_irqs(desc->irq, nvec_aligned);
if (info->flags & MSI_FLAG_DEV_SYSFS)
msi_sysfs_remove_desc(dev, desc);
desc->irq = 0;
prev parent reply other threads:[~2026-10-01 19:29 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-30 7:22 Sangwoo Han
2026-08-03 16:11 ` Manivannan Sadhasivam
2026-08-03 22:22 ` Bjorn Helgaas
2026-08-04 11:31 ` Han / 한상우Sangwoo
2026-08-04 12:50 ` Bjorn Helgaas
2026-08-10 23:30 ` Bjorn Helgaas
2026-09-07 16:34 ` Bjorn Helgaas
2026-09-07 21:40 ` Thomas Gleixner
2026-09-16 23:10 ` Bjorn Helgaas
2026-09-21 9:05 ` Han / 한상우Sangwoo
2026-10-01 19:29 ` Thomas Gleixner [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=871pa9gqy0.ffs@fw13 \
--to=tglx@kernel.org \
--cc=bcm-kernel-feedback-list@broadcom.com \
--cc=bhelgaas@google.com \
--cc=florian.fainelli@broadcom.com \
--cc=helgaas@kernel.org \
--cc=inochiama@gmail.com \
--cc=jim2101024@gmail.com \
--cc=kwilczynski@kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=linux-rpi-kernel@lists.infradead.org \
--cc=lpieralisi@kernel.org \
--cc=mani@kernel.org \
--cc=robh@kernel.org \
--cc=sangwoo.han@nearthlab.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®