* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-09-27 19:13 [PATCH] sh: intc: sort the prio and sense lists after filling them Karl Mehltretter
@ 2026-09-27 19:30 ` Karl Mehltretter
2026-09-28 15:01 ` John Paul Adrian Glaubitz
` (2 subsequent siblings)
3 siblings, 0 replies; 17+ messages in thread
From: Karl Mehltretter @ 2026-09-27 19:30 UTC (permalink / raw)
To: Yoshinori Sato
Cc: Karl Mehltretter, John Paul Adrian Glaubitz, Rich Felker,
linux-sh, linux-kernel
Adding Yoshinori at yoshinori.sato@nifty.com. The users.sourceforge.jp
address in MAINTAINERS no longer receives mail. The patch is at
https://lore.kernel.org/r/20260927191359.6144-1-kmehltretter@gmail.com
and quoted in full below.
On Sun, 27 Sep 2026 21:13:59 +0200, Karl Mehltretter wrote:
> register_intc_controller() sorts d->prio and d->sense right after
> allocating them, with hw->nr_prio_regs and hw->nr_sense_regs as the
> element count. The lists hold hw->nr_vectors entries and are only
> filled later, by intc_register_irq().
>
> On SH7785, sh7785-irq0123 and sh7785-irq4567 have four vectors but the
> SoC's eleven priority registers, so sort() swaps 88 bytes in a 32 byte
> kmalloc object at boot. slub_debug=FZPU reports "Right Redzone
> overwritten" in kmalloc-32, and v6.5 and v6.6 panic in
> __kmem_cache_alloc_node() while registering sh7785-irq0123.
>
> Found with a custom QEMU model of the SH7785LCR. On it, v6.4
> sh7785lcr_defconfig boots with SLAB, the defconfig default before v6.5,
> and hangs before the console is up when built with SLUB.
>
> Sort the lists once all vectors are registered, with the number of
> entries that were added.
>
> Fixes: b59f9f9775e6 ("sh: intc: optimize intc IRQ lookup")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
> ---
>
> Notes:
> Testing, all in QEMU on a custom SH7785LCR model, not on hardware:
> - v6.5 and v6.6 sh7785lcr_defconfig hang before the console is up
> (gcc 8 and gcc 14). With slub_debug=FZPU they boot and validating
> kmalloc-32 reports "Right Redzone overwritten" after the object
> holding the entries of sh7785-irq4567. With this patch they boot
> and the report is gone.
> - v6.4 sh7785lcr_defconfig (SLAB) boots. The same v6.4 built with SLUB
> hangs, reports the overflow with slub_debug=FZPU, and boots with
> this patch.
> - Current mainline boots with or without the patch, but reports the
> overflow with slub_debug=FZPU unless patched.
> Testing on real hardware is welcome.
>
> drivers/sh/intc/core.c | 11 +++++------
> 1 file changed, 5 insertions(+), 6 deletions(-)
>
> diff --git a/drivers/sh/intc/core.c b/drivers/sh/intc/core.c
> index aa68fe190865d..ffbe60234eefc 100644
> --- a/drivers/sh/intc/core.c
> +++ b/drivers/sh/intc/core.c
> @@ -275,9 +275,6 @@ int __init register_intc_controller(struct intc_desc *desc)
> k += save_reg(d, k, hw->prio_regs[i].set_reg, smp);
> k += save_reg(d, k, hw->prio_regs[i].clr_reg, smp);
> }
> -
> - sort(d->prio, hw->nr_prio_regs, sizeof(*d->prio),
> - intc_handle_int_cmp, NULL);
> }
>
> if (hw->sense_regs) {
> @@ -287,9 +284,6 @@ int __init register_intc_controller(struct intc_desc *desc)
>
> for (i = 0; i < hw->nr_sense_regs; i++)
> k += save_reg(d, k, hw->sense_regs[i].reg, 0);
> -
> - sort(d->sense, hw->nr_sense_regs, sizeof(*d->sense),
> - intc_handle_int_cmp, NULL);
> }
>
> if (hw->subgroups)
> @@ -357,6 +351,11 @@ int __init register_intc_controller(struct intc_desc *desc)
> }
> }
>
> + sort(d->prio, d->nr_prio, sizeof(*d->prio),
> + intc_handle_int_cmp, NULL);
> + sort(d->sense, d->nr_sense, sizeof(*d->sense),
> + intc_handle_int_cmp, NULL);
> +
> intc_subgroup_init(desc, d);
>
> /* enable bits matching force_enable after registering irqs */
> --
> 2.53.0
>
>
^ permalink raw reply [flat|nested] 17+ messages in thread* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-09-27 19:13 [PATCH] sh: intc: sort the prio and sense lists after filling them Karl Mehltretter
2026-09-27 19:30 ` Karl Mehltretter
@ 2026-09-28 15:01 ` John Paul Adrian Glaubitz
2026-09-28 16:03 ` Geert Uytterhoeven
2026-10-02 4:57 ` John Paul Adrian Glaubitz
2026-10-03 7:51 ` John Paul Adrian Glaubitz
3 siblings, 1 reply; 17+ messages in thread
From: John Paul Adrian Glaubitz @ 2026-09-28 15:01 UTC (permalink / raw)
To: Karl Mehltretter, Yoshinori Sato, Rich Felker; +Cc: linux-sh, linux-kernel
Hi Karl,
On Sun, 2026-09-27 at 21:13 +0200, Karl Mehltretter wrote:
> register_intc_controller() sorts d->prio and d->sense right after
> allocating them, with hw->nr_prio_regs and hw->nr_sense_regs as the
> element count. The lists hold hw->nr_vectors entries and are only
> filled later, by intc_register_irq().
>
> On SH7785, sh7785-irq0123 and sh7785-irq4567 have four vectors but the
> SoC's eleven priority registers, so sort() swaps 88 bytes in a 32 byte
> kmalloc object at boot. slub_debug=FZPU reports "Right Redzone
> overwritten" in kmalloc-32, and v6.5 and v6.6 panic in
> __kmem_cache_alloc_node() while registering sh7785-irq0123.
>
> Found with a custom QEMU model of the SH7785LCR. On it, v6.4
> sh7785lcr_defconfig boots with SLAB, the defconfig default before v6.5,
> and hangs before the console is up when built with SLUB.
>
> Sort the lists once all vectors are registered, with the number of
> entries that were added.
>
> Fixes: b59f9f9775e6 ("sh: intc: optimize intc IRQ lookup")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
> ---
>
> Notes:
> Testing, all in QEMU on a custom SH7785LCR model, not on hardware:
> - v6.5 and v6.6 sh7785lcr_defconfig hang before the console is up
> (gcc 8 and gcc 14). With slub_debug=FZPU they boot and validating
> kmalloc-32 reports "Right Redzone overwritten" after the object
> holding the entries of sh7785-irq4567. With this patch they boot
> and the report is gone.
> - v6.4 sh7785lcr_defconfig (SLAB) boots. The same v6.4 built with SLUB
> hangs, reports the overflow with slub_debug=FZPU, and boots with
> this patch.
> - Current mainline boots with or without the patch, but reports the
> overflow with slub_debug=FZPU unless patched.
> Testing on real hardware is welcome.
>
> drivers/sh/intc/core.c | 11 +++++------
> 1 file changed, 5 insertions(+), 6 deletions(-)
>
> diff --git a/drivers/sh/intc/core.c b/drivers/sh/intc/core.c
> index aa68fe190865d..ffbe60234eefc 100644
> --- a/drivers/sh/intc/core.c
> +++ b/drivers/sh/intc/core.c
> @@ -275,9 +275,6 @@ int __init register_intc_controller(struct intc_desc *desc)
> k += save_reg(d, k, hw->prio_regs[i].set_reg, smp);
> k += save_reg(d, k, hw->prio_regs[i].clr_reg, smp);
> }
> -
> - sort(d->prio, hw->nr_prio_regs, sizeof(*d->prio),
> - intc_handle_int_cmp, NULL);
> }
>
> if (hw->sense_regs) {
> @@ -287,9 +284,6 @@ int __init register_intc_controller(struct intc_desc *desc)
>
> for (i = 0; i < hw->nr_sense_regs; i++)
> k += save_reg(d, k, hw->sense_regs[i].reg, 0);
> -
> - sort(d->sense, hw->nr_sense_regs, sizeof(*d->sense),
> - intc_handle_int_cmp, NULL);
> }
>
> if (hw->subgroups)
> @@ -357,6 +351,11 @@ int __init register_intc_controller(struct intc_desc *desc)
> }
> }
>
> + sort(d->prio, d->nr_prio, sizeof(*d->prio),
> + intc_handle_int_cmp, NULL);
> + sort(d->sense, d->nr_sense, sizeof(*d->sense),
> + intc_handle_int_cmp, NULL);
> +
> intc_subgroup_init(desc, d);
>
> /* enable bits matching force_enable after registering irqs */
I tried this patch and the kernel still gets stuck for me after loading it
with u-boot, the problem that I have been seeing since 6.5.0 and haven't
been able to resolve.
=> usb reset; fatload usb 0:1 0x89000000 uImage-7.3.0.gz ; pmb ; bootm
(Re)start USB...
USB0: scanning bus 0 for devices... 2 USB Device(s) found
scanning usb for storage devices... 1 Storage Device(s) found
reading uImage-7.3.0.gz
3649306 bytes read in 2074 ms (1.7 MiB/s)
## Booting kernel from Legacy Image at 89000000 ...
Image Name: Linux-7.3.0-rc5-00001-g8cd915e93
Image Type: SuperH Linux Kernel Image (gzip compressed)
Data Size: 3649242 Bytes = 3.5 MiB
Load Address: 8c010000
Entry Point: 8c011000
Verifying Checksum ... OK
Uncompressing Kernel Image ... OK
I also never understood why the load address I used at the u-boot prompt
differed from the one that the uImage build process showed at the end of
the kernel build:
GZIP arch/sh/boot/vmlinux.bin.gz
UIMAGE arch/sh/boot/uImage.gz
Image Name: Linux-7.3.0-rc5-00002-g02d53450e
Created: Mon Sep 28 14:56:15 2026
Image Type: SuperH Linux Kernel Image (gzip compressed)
Data Size: 3649249 Bytes = 3563.72 KiB = 3.48 MiB
Load Address: 8c010000
Entry Point: 8c011000
Image arch/sh/boot/uImage is ready
Any idea?
Adrian
--
.''`. John Paul Adrian Glaubitz
: :' : Debian Developer
`. `' Physicist
`- GPG: 62FF 8A75 84E0 2956 9546 0006 7426 3B37 F5B5 F913
^ permalink raw reply [flat|nested] 17+ messages in thread* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-09-28 15:01 ` John Paul Adrian Glaubitz
@ 2026-09-28 16:03 ` Geert Uytterhoeven
2026-09-28 16:46 ` John Paul Adrian Glaubitz
0 siblings, 1 reply; 17+ messages in thread
From: Geert Uytterhoeven @ 2026-09-28 16:03 UTC (permalink / raw)
To: John Paul Adrian Glaubitz
Cc: Karl Mehltretter, Yoshinori Sato, Rich Felker, linux-sh, linux-kernel
Hi Adrian,
On Mon, 28 Sept 2026 at 17:10, John Paul Adrian Glaubitz
<glaubitz@physik.fu-berlin.de> wrote:
> => usb reset; fatload usb 0:1 0x89000000 uImage-7.3.0.gz ; pmb ; bootm
> (Re)start USB...
> USB0: scanning bus 0 for devices... 2 USB Device(s) found
> scanning usb for storage devices... 1 Storage Device(s) found
> reading uImage-7.3.0.gz
> 3649306 bytes read in 2074 ms (1.7 MiB/s)
> ## Booting kernel from Legacy Image at 89000000 ...
> Image Name: Linux-7.3.0-rc5-00001-g8cd915e93
> Image Type: SuperH Linux Kernel Image (gzip compressed)
> Data Size: 3649242 Bytes = 3.5 MiB
> Load Address: 8c010000
> Entry Point: 8c011000
> Verifying Checksum ... OK
> Uncompressing Kernel Image ... OK
>
> I also never understood why the load address I used at the u-boot prompt
> differed from the one that the uImage build process showed at the end of
> the kernel build:
>
> GZIP arch/sh/boot/vmlinux.bin.gz
> UIMAGE arch/sh/boot/uImage.gz
> Image Name: Linux-7.3.0-rc5-00002-g02d53450e
> Created: Mon Sep 28 14:56:15 2026
> Image Type: SuperH Linux Kernel Image (gzip compressed)
> Data Size: 3649249 Bytes = 3563.72 KiB = 3.48 MiB
> Load Address: 8c010000
> Entry Point: 8c011000
> Image arch/sh/boot/uImage is ready
>
> Any idea?
0x89000000 is the address where you load the uImage.
0x8c010000 is the address where the unpacked kernel image will be
stored.
The latter comes from your kernel config:
arch/sh/boot/Makefile:UIMAGE_LOADADDR = $(KERNEL_LOAD)
arch/sh/boot/Makefile:UIMAGE_ENTRYADDR = $(KERNEL_ENTRY)
It's similar on ARM platforms that (still) use uImage.
Gr{oetje,eeting}s,
Geert
--
Geert Uytterhoeven -- There's lots of Linux beyond ia32 -- geert@linux-m68k.org
In personal conversations with technical people, I call myself a hacker. But
when I'm talking to journalists I just say "programmer" or something like that.
-- Linus Torvalds
^ permalink raw reply [flat|nested] 17+ messages in thread* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-09-28 16:03 ` Geert Uytterhoeven
@ 2026-09-28 16:46 ` John Paul Adrian Glaubitz
2026-09-28 17:00 ` Geert Uytterhoeven
0 siblings, 1 reply; 17+ messages in thread
From: John Paul Adrian Glaubitz @ 2026-09-28 16:46 UTC (permalink / raw)
To: Geert Uytterhoeven
Cc: Karl Mehltretter, Yoshinori Sato, Rich Felker, linux-sh, linux-kernel
Hi Geert,
On Mon, 2026-09-28 at 18:03 +0200, Geert Uytterhoeven wrote:
> On Mon, 28 Sept 2026 at 17:10, John Paul Adrian Glaubitz
> <glaubitz@physik.fu-berlin.de> wrote:
> > => usb reset; fatload usb 0:1 0x89000000 uImage-7.3.0.gz ; pmb ; bootm
> > (Re)start USB...
> > USB0: scanning bus 0 for devices... 2 USB Device(s) found
> > scanning usb for storage devices... 1 Storage Device(s) found
> > reading uImage-7.3.0.gz
> > 3649306 bytes read in 2074 ms (1.7 MiB/s)
> > ## Booting kernel from Legacy Image at 89000000 ...
> > Image Name: Linux-7.3.0-rc5-00001-g8cd915e93
> > Image Type: SuperH Linux Kernel Image (gzip compressed)
> > Data Size: 3649242 Bytes = 3.5 MiB
> > Load Address: 8c010000
> > Entry Point: 8c011000
> > Verifying Checksum ... OK
> > Uncompressing Kernel Image ... OK
> >
> > I also never understood why the load address I used at the u-boot prompt
> > differed from the one that the uImage build process showed at the end of
> > the kernel build:
> >
> > GZIP arch/sh/boot/vmlinux.bin.gz
> > UIMAGE arch/sh/boot/uImage.gz
> > Image Name: Linux-7.3.0-rc5-00002-g02d53450e
> > Created: Mon Sep 28 14:56:15 2026
> > Image Type: SuperH Linux Kernel Image (gzip compressed)
> > Data Size: 3649249 Bytes = 3563.72 KiB = 3.48 MiB
> > Load Address: 8c010000
> > Entry Point: 8c011000
> > Image arch/sh/boot/uImage is ready
> >
> > Any idea?
>
> 0x89000000 is the address where you load the uImage.
> 0x8c010000 is the address where the unpacked kernel image will be
> stored.
>
> The latter comes from your kernel config:
>
> arch/sh/boot/Makefile:UIMAGE_LOADADDR = $(KERNEL_LOAD)
> arch/sh/boot/Makefile:UIMAGE_ENTRYADDR = $(KERNEL_ENTRY)
>
> It's similar on ARM platforms that (still) use uImage.
The thing is that it stopped working after 6.5.0 and I never figured
out why. I did test all kinds of changes and it just never worked
again while pre 6.5.0 kernels work just fine.
Adrian
--
.''`. John Paul Adrian Glaubitz
: :' : Debian Developer
`. `' Physicist
`- GPG: 62FF 8A75 84E0 2956 9546 0006 7426 3B37 F5B5 F913
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-09-28 16:46 ` John Paul Adrian Glaubitz
@ 2026-09-28 17:00 ` Geert Uytterhoeven
2026-09-28 17:21 ` John Paul Adrian Glaubitz
0 siblings, 1 reply; 17+ messages in thread
From: Geert Uytterhoeven @ 2026-09-28 17:00 UTC (permalink / raw)
To: John Paul Adrian Glaubitz
Cc: Karl Mehltretter, Yoshinori Sato, Rich Felker, linux-sh, linux-kernel
Hi Adrian,
On Mon, 28 Sept 2026 at 18:46, John Paul Adrian Glaubitz
<glaubitz@physik.fu-berlin.de> wrote:
> On Mon, 2026-09-28 at 18:03 +0200, Geert Uytterhoeven wrote:
> > On Mon, 28 Sept 2026 at 17:10, John Paul Adrian Glaubitz
> > <glaubitz@physik.fu-berlin.de> wrote:
> > > => usb reset; fatload usb 0:1 0x89000000 uImage-7.3.0.gz ; pmb ; bootm
> > > (Re)start USB...
> > > USB0: scanning bus 0 for devices... 2 USB Device(s) found
> > > scanning usb for storage devices... 1 Storage Device(s) found
> > > reading uImage-7.3.0.gz
> > > 3649306 bytes read in 2074 ms (1.7 MiB/s)
> > > ## Booting kernel from Legacy Image at 89000000 ...
> > > Image Name: Linux-7.3.0-rc5-00001-g8cd915e93
> > > Image Type: SuperH Linux Kernel Image (gzip compressed)
> > > Data Size: 3649242 Bytes = 3.5 MiB
> > > Load Address: 8c010000
> > > Entry Point: 8c011000
> > > Verifying Checksum ... OK
> > > Uncompressing Kernel Image ... OK
> > >
> > > I also never understood why the load address I used at the u-boot prompt
> > > differed from the one that the uImage build process showed at the end of
> > > the kernel build:
> > >
> > > GZIP arch/sh/boot/vmlinux.bin.gz
> > > UIMAGE arch/sh/boot/uImage.gz
> > > Image Name: Linux-7.3.0-rc5-00002-g02d53450e
> > > Created: Mon Sep 28 14:56:15 2026
> > > Image Type: SuperH Linux Kernel Image (gzip compressed)
> > > Data Size: 3649249 Bytes = 3563.72 KiB = 3.48 MiB
> > > Load Address: 8c010000
> > > Entry Point: 8c011000
> > > Image arch/sh/boot/uImage is ready
> > >
> > > Any idea?
> >
> > 0x89000000 is the address where you load the uImage.
> > 0x8c010000 is the address where the unpacked kernel image will be
> > stored.
> >
> > The latter comes from your kernel config:
> >
> > arch/sh/boot/Makefile:UIMAGE_LOADADDR = $(KERNEL_LOAD)
> > arch/sh/boot/Makefile:UIMAGE_ENTRYADDR = $(KERNEL_ENTRY)
> >
> > It's similar on ARM platforms that (still) use uImage.
>
> The thing is that it stopped working after 6.5.0 and I never figured
> out why. I did test all kinds of changes and it just never worked
> again while pre 6.5.0 kernels work just fine.
Have you tried to bisect it?
Gr{oetje,eeting}s,
Geert
--
Geert Uytterhoeven -- There's lots of Linux beyond ia32 -- geert@linux-m68k.org
In personal conversations with technical people, I call myself a hacker. But
when I'm talking to journalists I just say "programmer" or something like that.
-- Linus Torvalds
^ permalink raw reply [flat|nested] 17+ messages in thread* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-09-28 17:00 ` Geert Uytterhoeven
@ 2026-09-28 17:21 ` John Paul Adrian Glaubitz
2026-09-28 18:34 ` Geert Uytterhoeven
0 siblings, 1 reply; 17+ messages in thread
From: John Paul Adrian Glaubitz @ 2026-09-28 17:21 UTC (permalink / raw)
To: Geert Uytterhoeven
Cc: Karl Mehltretter, Yoshinori Sato, Rich Felker, linux-sh, linux-kernel
Hi Geert,
On Mon, 2026-09-28 at 19:00 +0200, Geert Uytterhoeven wrote:
> Hi Adrian,
>
> On Mon, 28 Sept 2026 at 18:46, John Paul Adrian Glaubitz
> <glaubitz@physik.fu-berlin.de> wrote:
> > On Mon, 2026-09-28 at 18:03 +0200, Geert Uytterhoeven wrote:
> > > On Mon, 28 Sept 2026 at 17:10, John Paul Adrian Glaubitz
> > > <glaubitz@physik.fu-berlin.de> wrote:
> > > > => usb reset; fatload usb 0:1 0x89000000 uImage-7.3.0.gz ; pmb ; bootm
> > > > (Re)start USB...
> > > > USB0: scanning bus 0 for devices... 2 USB Device(s) found
> > > > scanning usb for storage devices... 1 Storage Device(s) found
> > > > reading uImage-7.3.0.gz
> > > > 3649306 bytes read in 2074 ms (1.7 MiB/s)
> > > > ## Booting kernel from Legacy Image at 89000000 ...
> > > > Image Name: Linux-7.3.0-rc5-00001-g8cd915e93
> > > > Image Type: SuperH Linux Kernel Image (gzip compressed)
> > > > Data Size: 3649242 Bytes = 3.5 MiB
> > > > Load Address: 8c010000
> > > > Entry Point: 8c011000
> > > > Verifying Checksum ... OK
> > > > Uncompressing Kernel Image ... OK
> > > >
> > > > I also never understood why the load address I used at the u-boot prompt
> > > > differed from the one that the uImage build process showed at the end of
> > > > the kernel build:
> > > >
> > > > GZIP arch/sh/boot/vmlinux.bin.gz
> > > > UIMAGE arch/sh/boot/uImage.gz
> > > > Image Name: Linux-7.3.0-rc5-00002-g02d53450e
> > > > Created: Mon Sep 28 14:56:15 2026
> > > > Image Type: SuperH Linux Kernel Image (gzip compressed)
> > > > Data Size: 3649249 Bytes = 3563.72 KiB = 3.48 MiB
> > > > Load Address: 8c010000
> > > > Entry Point: 8c011000
> > > > Image arch/sh/boot/uImage is ready
> > > >
> > > > Any idea?
> > >
> > > 0x89000000 is the address where you load the uImage.
> > > 0x8c010000 is the address where the unpacked kernel image will be
> > > stored.
> > >
> > > The latter comes from your kernel config:
> > >
> > > arch/sh/boot/Makefile:UIMAGE_LOADADDR = $(KERNEL_LOAD)
> > > arch/sh/boot/Makefile:UIMAGE_ENTRYADDR = $(KERNEL_ENTRY)
> > >
> > > It's similar on ARM platforms that (still) use uImage.
> >
> > The thing is that it stopped working after 6.5.0 and I never figured
> > out why. I did test all kinds of changes and it just never worked
> > again while pre 6.5.0 kernels work just fine.
>
> Have you tried to bisect it?
Yes, I did. I did not manage to find the commit that caused it.
Maybe Karl has an idea. This image is known to work [1]:
glaubitz@suse-laptop:~> file uImage-git.gz
uImage-git.gz: u-boot legacy uImage, Linux-6.5.0-rc2, Linux/SuperH, OS Kernel Image (gzip), 4416616 bytes, Mon Jul 17 14:17:35 2023, Load Address: 0X80001000, Entry Point: 0X80002000, Header CRC:
0XBA69203A, Data CRC: 0XD097D603
glaubitz@suse-laptop:~>
It boots fine with:
usb reset ; fatload usb 0:1 0x89000000 uImage-git.gz ; pmb ; bootm
Adrian
> [1] https://people.debian.org/~glaubitz/sh7785lcr/uImage-git.gz
--
.''`. John Paul Adrian Glaubitz
: :' : Debian Developer
`. `' Physicist
`- GPG: 62FF 8A75 84E0 2956 9546 0006 7426 3B37 F5B5 F913
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-09-28 17:21 ` John Paul Adrian Glaubitz
@ 2026-09-28 18:34 ` Geert Uytterhoeven
2026-09-28 19:02 ` John Paul Adrian Glaubitz
0 siblings, 1 reply; 17+ messages in thread
From: Geert Uytterhoeven @ 2026-09-28 18:34 UTC (permalink / raw)
To: John Paul Adrian Glaubitz
Cc: Karl Mehltretter, Yoshinori Sato, Rich Felker, linux-sh, linux-kernel
Hi Adrian,
On Mon, 28 Sept 2026 at 19:21, John Paul Adrian Glaubitz
<glaubitz@physik.fu-berlin.de> wrote:
> On Mon, 2026-09-28 at 19:00 +0200, Geert Uytterhoeven wrote:
> > On Mon, 28 Sept 2026 at 18:46, John Paul Adrian Glaubitz
> > <glaubitz@physik.fu-berlin.de> wrote:
> > > On Mon, 2026-09-28 at 18:03 +0200, Geert Uytterhoeven wrote:
> > > > On Mon, 28 Sept 2026 at 17:10, John Paul Adrian Glaubitz
> > > > <glaubitz@physik.fu-berlin.de> wrote:
> > > > > => usb reset; fatload usb 0:1 0x89000000 uImage-7.3.0.gz ; pmb ; bootm
> > > > > (Re)start USB...
> > > > > USB0: scanning bus 0 for devices... 2 USB Device(s) found
> > > > > scanning usb for storage devices... 1 Storage Device(s) found
> > > > > reading uImage-7.3.0.gz
> > > > > 3649306 bytes read in 2074 ms (1.7 MiB/s)
> > > > > ## Booting kernel from Legacy Image at 89000000 ...
> > > > > Image Name: Linux-7.3.0-rc5-00001-g8cd915e93
> > > > > Image Type: SuperH Linux Kernel Image (gzip compressed)
> > > > > Data Size: 3649242 Bytes = 3.5 MiB
> > > > > Load Address: 8c010000
> > > > > Entry Point: 8c011000
> > > > > Verifying Checksum ... OK
> > > > > Uncompressing Kernel Image ... OK
> > > > >
> > > > > I also never understood why the load address I used at the u-boot prompt
> > > > > differed from the one that the uImage build process showed at the end of
> > > > > the kernel build:
> > > > >
> > > > > GZIP arch/sh/boot/vmlinux.bin.gz
> > > > > UIMAGE arch/sh/boot/uImage.gz
> > > > > Image Name: Linux-7.3.0-rc5-00002-g02d53450e
> > > > > Created: Mon Sep 28 14:56:15 2026
> > > > > Image Type: SuperH Linux Kernel Image (gzip compressed)
> > > > > Data Size: 3649249 Bytes = 3563.72 KiB = 3.48 MiB
> > > > > Load Address: 8c010000
> > > > > Entry Point: 8c011000
> > > > > Image arch/sh/boot/uImage is ready
> > > > >
> > > > > Any idea?
> > > >
> > > > 0x89000000 is the address where you load the uImage.
> > > > 0x8c010000 is the address where the unpacked kernel image will be
> > > > stored.
> > > >
> > > > The latter comes from your kernel config:
> > > >
> > > > arch/sh/boot/Makefile:UIMAGE_LOADADDR = $(KERNEL_LOAD)
> > > > arch/sh/boot/Makefile:UIMAGE_ENTRYADDR = $(KERNEL_ENTRY)
> > > >
> > > > It's similar on ARM platforms that (still) use uImage.
> > >
> > > The thing is that it stopped working after 6.5.0 and I never figured
> > > out why. I did test all kinds of changes and it just never worked
> > > again while pre 6.5.0 kernels work just fine.
> >
> > Have you tried to bisect it?
>
> Yes, I did. I did not manage to find the commit that caused it.
Perhaps a size limitation? Your kernel image is flirting with 4 MiB.
Perhaps a config issue? The safest way to preserve your config for
bisection is:
cp .config arch/sh/configs/bisect_defconfig
and to run "make bisect_defconfig" in each bisection step.
> Maybe Karl has an idea. This image is known to work [1]:
>
> glaubitz@suse-laptop:~> file uImage-git.gz
> uImage-git.gz: u-boot legacy uImage, Linux-6.5.0-rc2, Linux/SuperH, OS Kernel Image (gzip), 4416616 bytes, Mon Jul 17 14:17:35 2023, Load Address: 0X80001000, Entry Point: 0X80002000, Header CRC:
> 0XBA69203A, Data CRC: 0XD097D603
> glaubitz@suse-laptop:~>
>
> It boots fine with:
>
> usb reset ; fatload usb 0:1 0x89000000 uImage-git.gz ; pmb ; bootm
Do you have a config for that kernel?
Gr{oetje,eeting}s,
Geert
--
Geert Uytterhoeven -- There's lots of Linux beyond ia32 -- geert@linux-m68k.org
In personal conversations with technical people, I call myself a hacker. But
when I'm talking to journalists I just say "programmer" or something like that.
-- Linus Torvalds
^ permalink raw reply [flat|nested] 17+ messages in thread* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-09-28 18:34 ` Geert Uytterhoeven
@ 2026-09-28 19:02 ` John Paul Adrian Glaubitz
2026-09-28 21:22 ` Karl Mehltretter
0 siblings, 1 reply; 17+ messages in thread
From: John Paul Adrian Glaubitz @ 2026-09-28 19:02 UTC (permalink / raw)
To: Geert Uytterhoeven
Cc: Karl Mehltretter, Yoshinori Sato, Rich Felker, linux-sh, linux-kernel
Hi Geert,
On Mon, 2026-09-28 at 20:34 +0200, Geert Uytterhoeven wrote:
> Perhaps a size limitation? Your kernel image is flirting with 4 MiB.
> Perhaps a config issue? The safest way to preserve your config for
> bisection is:
>
> cp .config arch/sh/configs/bisect_defconfig
>
> and to run "make bisect_defconfig" in each bisection step.
>
> > Maybe Karl has an idea. This image is known to work [1]:
> >
> > glaubitz@suse-laptop:~> file uImage-git.gz
> > uImage-git.gz: u-boot legacy uImage, Linux-6.5.0-rc2, Linux/SuperH, OS Kernel Image (gzip), 4416616 bytes, Mon Jul 17 14:17:35 2023, Load Address: 0X80001000, Entry Point: 0X80002000, Header CRC:
> > 0XBA69203A, Data CRC: 0XD097D603
> > glaubitz@suse-laptop:~>
> >
> > It boots fine with:
> >
> > usb reset ; fatload usb 0:1 0x89000000 uImage-git.gz ; pmb ; bootm
>
> Do you have a config for that kernel?
Here are some known configs:
https://people.debian.org/~glaubitz/sh7785lcr/configs/
Adrian
--
.''`. John Paul Adrian Glaubitz
: :' : Debian Developer
`. `' Physicist
`- GPG: 62FF 8A75 84E0 2956 9546 0006 7426 3B37 F5B5 F913
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-09-28 19:02 ` John Paul Adrian Glaubitz
@ 2026-09-28 21:22 ` Karl Mehltretter
2026-09-28 21:29 ` John Paul Adrian Glaubitz
2026-09-29 9:20 ` John Paul Adrian Glaubitz
0 siblings, 2 replies; 17+ messages in thread
From: Karl Mehltretter @ 2026-09-28 21:22 UTC (permalink / raw)
To: John Paul Adrian Glaubitz
Cc: Geert Uytterhoeven, Yoshinori Sato, Rich Felker, linux-sh, linux-kernel
On Mon, Sep 28, 2026 at 09:02:55PM +0100, John Paul Adrian Glaubitz wrote:
> On Mon, 2026-09-28 at 20:34 +0200, Geert Uytterhoeven wrote:
> > > usb reset ; fatload usb 0:1 0x89000000 uImage-git.gz ; pmb ; bootm
> >
> > Do you have a config for that kernel?
>
> Here are some known configs:
>
> https://people.debian.org/~glaubitz/sh7785lcr/configs/
I think it's the config. Your new image loads at 0x8c010000, the working
one at 0x80001000.
0x8c010000 is what an R2D config gives, and config-SH7785LCR-6.5 is one:
CPU_SUBTYPE_SH7751R and SH_RTS7751R2D, 29BIT, MEMORY_START 0x0c000000.
config-SH7785LCR-2024 still has SH7785LCR, 32BIT/PMB and MEMORY_START
0x40000000, which gives 0x80001000.
I tried both on my QEMU model of the SH7785LCR with 7.3: the 2024 config
boots up to the root mount, the 6.5 one prints nothing at all.
So I'd start from config-SH7785LCR-2024 (or sh7785lcr_32bit_defconfig):
cp config-SH7785LCR-2024 .config make ARCH=sh olddefconfig
and check for "Load Address: 80001000". Keep the intc patch applied, the
overflow crashed v6.5 and v6.6 with SLUB on my QEMU model.
With the right config the kernel may then really be too large: 7.3-rc5
with config-SH7785LCR-2024 uncompresses to 8.2 MiB, and U-Boot's default
CONFIG_SYS_BOOTM_LEN is 8 MiB. U-Boot then prints "Image too large:
increase CONFIG_SYS_BOOTM_LEN". With CONFIG_CC_OPTIMIZE_FOR_SIZE=y it is
7.3 MiB and boots through U-Boot on the model.
On the model I use U-Boot 2019.04 (sh7785lcr_32bit_defconfig, the last
release with the board), with a few local fixes it needs to start at
all.
Which U-Boot version does your board run ("version" at the
prompt)? Its limit may differ from the 8 MiB default.
Karl
^ permalink raw reply [flat|nested] 17+ messages in thread* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-09-28 21:22 ` Karl Mehltretter
@ 2026-09-28 21:29 ` John Paul Adrian Glaubitz
2026-09-29 9:20 ` John Paul Adrian Glaubitz
1 sibling, 0 replies; 17+ messages in thread
From: John Paul Adrian Glaubitz @ 2026-09-28 21:29 UTC (permalink / raw)
To: Karl Mehltretter
Cc: Geert Uytterhoeven, Yoshinori Sato, Rich Felker, linux-sh, linux-kernel
Hi Karl,
On Mon, 2026-09-28 at 23:22 +0200, Karl Mehltretter wrote:
> Which U-Boot version does your board run ("version" at the
> prompt)? Its limit may differ from the 8 MiB default.
I'll answer the remaining questions later, but here is the version:
U-Boot 2014.01 (Jan 30 2015 - 11:01:14)
CPU: SH4
BOARD: Renesas Technology Corp. R0P7785LC0011RL
DRAM: 384MB
Flash: 64MB
PCI: SH7780 PCI host bridge found.
PCI: Bus Dev VenId DevId Class Int
00:00.0 - 10ec:8169 - Network controller
00:01.0 - 1095:3512 - Mass storage controller
In: serial
Out: serial
Err: serial
Net: RTL8169#0
Hit any key to stop autoboot: 0
=>
Adrian
--
.''`. John Paul Adrian Glaubitz
: :' : Debian Developer
`. `' Physicist
`- GPG: 62FF 8A75 84E0 2956 9546 0006 7426 3B37 F5B5 F913
^ permalink raw reply [flat|nested] 17+ messages in thread* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-09-28 21:22 ` Karl Mehltretter
2026-09-28 21:29 ` John Paul Adrian Glaubitz
@ 2026-09-29 9:20 ` John Paul Adrian Glaubitz
2026-09-29 9:39 ` John Paul Adrian Glaubitz
1 sibling, 1 reply; 17+ messages in thread
From: John Paul Adrian Glaubitz @ 2026-09-29 9:20 UTC (permalink / raw)
To: Karl Mehltretter
Cc: Geert Uytterhoeven, Yoshinori Sato, Rich Felker, linux-sh, linux-kernel
Hi Karl,
On Mon, 2026-09-28 at 23:22 +0200, Karl Mehltretter wrote:
> On Mon, Sep 28, 2026 at 09:02:55PM +0100, John Paul Adrian Glaubitz wrote:
> > On Mon, 2026-09-28 at 20:34 +0200, Geert Uytterhoeven wrote:
> > > > usb reset ; fatload usb 0:1 0x89000000 uImage-git.gz ; pmb ; bootm
> > >
> > > Do you have a config for that kernel?
> >
> > Here are some known configs:
> >
> > https://people.debian.org/~glaubitz/sh7785lcr/configs/
>
> I think it's the config. Your new image loads at 0x8c010000, the working
> one at 0x80001000.
>
> 0x8c010000 is what an R2D config gives, and config-SH7785LCR-6.5 is one:
> CPU_SUBTYPE_SH7751R and SH_RTS7751R2D, 29BIT, MEMORY_START 0x0c000000.
> config-SH7785LCR-2024 still has SH7785LCR, 32BIT/PMB and MEMORY_START
> 0x40000000, which gives 0x80001000.
>
> I tried both on my QEMU model of the SH7785LCR with 7.3: the 2024 config
> boots up to the root mount, the 6.5 one prints nothing at all.
>
> So I'd start from config-SH7785LCR-2024 (or sh7785lcr_32bit_defconfig):
>
> cp config-SH7785LCR-2024 .config make ARCH=sh olddefconfig
>
> and check for "Load Address: 80001000". Keep the intc patch applied, the
> overflow crashed v6.5 and v6.6 with SLUB on my QEMU model.
>
> With the right config the kernel may then really be too large: 7.3-rc5
> with config-SH7785LCR-2024 uncompresses to 8.2 MiB, and U-Boot's default
> CONFIG_SYS_BOOTM_LEN is 8 MiB. U-Boot then prints "Image too large:
> increase CONFIG_SYS_BOOTM_LEN". With CONFIG_CC_OPTIMIZE_FOR_SIZE=y it is
> 7.3 MiB and boots through U-Boot on the model.
Yes, that did the trick! Just need to figure out now why it didn't parse the
bootargs from u-boot to set the proper root device:
=> usb reset; fatload usb 0:1 0x89000000 uImage-7.3.0.gz ; pmb ; bootm
(Re)start USB...
USB0: scanning bus 0 for devices... 2 USB Device(s) found
scanning usb for storage devices... 1 Storage Device(s) found
reading uImage-7.3.0.gz
4319551 bytes read in 2457 ms (1.7 MiB/s)
## Booting kernel from Legacy Image at 89000000 ...
Image Name: Linux-7.3.0-rc5-00002-g02d53450e
Image Type: SuperH Linux Kernel Image (gzip compressed)
Data Size: 4319487 Bytes = 4.1 MiB
Load Address: 80001000
Entry Point: 80002000
Verifying Checksum ... OK
Uncompressing Kernel Image ... OK
[ 0.000000] Linux version 7.3.0-rc5-00002-g02d53450ebff (glaubitz@node54.cloud.suse.de) (sh4-linux-gcc (GCC) 11.1.0, GNU ld (GNU Binutils) 2.36.1) #2 PREEMPT Tue Sep 29 09:12:51 UTC 2026
[ 0.000000] Boot params:
[ 0.000000] ... MOUNT_ROOT_RDONLY - 00000000
[ 0.000000] ... RAMDISK_FLAGS - 00000000
[ 0.000000] ... ORIG_ROOT_DEV - 00000000
[ 0.000000] ... LOADER_TYPE - 00000000
[ 0.000000] ... INITRD_START - 00000000
[ 0.000000] ... INITRD_SIZE - 00000000
[ 0.000000] Booting machvec: SH7785LCR
[ 0.000000] PMB: boot mappings:
[ 0.000000] 0x00080000 -> 0x00040000 [ 512MB cached ]
[ 0.000000] 0x000a0000 -> 0x00040000 [ 16MB uncached ]
[ 0.000000] Renesas Technology Corp. R0P7785LC0011RL support.
[ 0.000000] Zone ranges:
[ 0.000000] Normal [mem 0x0000000040000000-0x000000005fffffff]
[ 0.000000] Movable zone start for each node
[ 0.000000] Early memory node ranges
[ 0.000000] node 0: [mem 0x0000000040000000-0x000000005fffffff]
[ 0.000000] Initmem setup node 0 [mem 0x0000000040000000-0x000000005fffffff]
[ 0.000000] Kernel command line: console=ttySC1,115200
[ 0.000000] printk: log buffer data + meta data: 65536 + 204800 = 270336 bytes
[ 0.000000] Dentry cache hash table entries: 65536 (order: 6, 262144 bytes, linear)
[ 0.000000] Inode-cache hash table entries: 32768 (order: 5, 131072 bytes, linear)
[ 0.000000] Sorting __ex_table...
[ 0.000000] Built 1 zonelists, mobility grouping on. Total pages: 131072
[ 0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off
[ 0.000000] stackdepot: allocating hash table via alloc_large_system_hash
[ 0.000000] stackdepot hash table entries: 32768 (order: 6, 262144 bytes, linear)
[ 0.000000] stackdepot: allocating space for 8192 stack pools via memblock
[ 0.000000] PVR=10300700 CVR=71440211 PRR=00000250
[ 0.000000] I-cache : n_ways=4 n_sets=256 way_incr=8192
[ 0.000000] I-cache : entry_mask=0x00001fe0 alias_mask=0x00001000 n_aliases=2
[ 0.000000] D-cache : n_ways=4 n_sets=256 way_incr=8192
[ 0.000000] D-cache : entry_mask=0x00001fe0 alias_mask=0x00001000 n_aliases=2
[ 0.000000] virtual kernel memory layout:
[ 0.000000] fixmap : 0xdffd7000 - 0xdffff000 ( 160 kB)
[ 0.000000] vmalloc : 0xc0000000 - 0xdffd5000 ( 511 MB)
[ 0.000000] lowmem : 0x80000000 - 0xa0000000 ( 512 MB) (cached)
[ 0.000000] : 0xa0000000 - 0xa1000000 ( 16 MB) (uncached)
[ 0.000000] .init : 0x8071c000 - 0x80749000 ( 180 kB)
[ 0.000000] .data : 0x80495280 - 0x8071b5f0 (2584 kB)
[ 0.000000] .text : 0x80001000 - 0x80495280 (4688 kB)
[ 0.000000] SLUB: HWalign=32, Order=0-3, MinObjects=0, CPUs=1, Nodes=1
[ 0.000000] rcu: Preemptible hierarchical RCU implementation.
[ 0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 25 jiffies.
[ 0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0
[ 0.000000] intc: Registered controller 'sh7785' with 67 IRQs
[ 0.000000] intc: Registered controller 'sh7785-irq4567' with 4 IRQs
[ 0.000000] intc: Registered controller 'sh7785-irq0123' with 4 IRQs
[ 0.000000] rcu: srcu_init: Setting srcu_struct sizes based on contention.
[ 0.000000] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 7645041785100000 ns
[ 0.000000] Console: colour dummy device 80x25
[ 0.000000] sh-tmu.0: ch0: used for clock events
[ 0.000000] sh-tmu.0: ch0: used for periodic clock events
[ 0.000000] sh-tmu.0: ch1: used as clock source
[ 0.000000] clocksource: sh-tmu.0: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 152900847964 ns
[ 0.000000] sh-tmu.1: ch0: used for clock events
[ 0.000000] sh-tmu.1: ch1: used as clock source
[ 0.000000] clocksource: sh-tmu.1: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 152900847964 ns
[ 0.000000] sched_clock: 32 bits at 250 Hz, resolution 4000000ns, wraps every 8589934590000000ns
[ 0.000000] Calibrating delay loop (skipped)... 599.99 BogoMIPS PRESET (lpj=1199999)
[ 0.000000] CPU: SH7785
[ 0.000000] pid_max: default: 32768 minimum: 301
[ 0.004000] Mount-cache hash table entries: 1024 (order: 0, 4096 bytes, linear)
[ 0.004000] Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes, linear)
[ 0.012000] VFS: Finished mounting rootfs on nullfs
[ 0.040000] Performance Events: sh4a support registered
[ 0.044000] rcu: Hierarchical SRCU implementation.
[ 0.044000] rcu: Max phase no-delay instances is 1000.
[ 0.052000] Memory: 508924K/524288K available (4684K kernel code, 452K rwdata, 2128K rodata, 180K init, 2149K bss, 14428K reserved, 0K cma-reserved)
[ 0.056000] devtmpfs: initialized
[ 0.084000] posixtimers hash table entries: 512 (order: 2, 10240 bytes, linear)
[ 0.084000] futex hash table entries: 256 (7168 bytes on 1 NUMA nodes, total 7 KiB, linear).
[ 0.104000] NET: Registered PF_NETLINK/PF_ROUTE protocol family
[ 0.196000] DMA: preallocated 128 KiB GFP_KERNEL pool for atomic allocations
[ 0.196000] audit: initializing netlink subsys (disabled)
[ 0.204000] audit: type=2000 audit(0.200:1): state=initialized audit_enabled=0 res=1
[ 0.212000] cpuidle: using governor ladder
[ 0.212000] cpuidle: using governor menu
[ 0.252000] gpio gpiochip0: Static allocation of GPIO base is deprecated, use dynamic allocation.
[ 0.260000] sh-pfc pfc-sh7785: sh7785_pfc handling gpio 0 -> 110
[ 0.264000] gpio gpiochip1: Static allocation of GPIO base is deprecated, use dynamic allocation.
[ 0.268000] sh-pfc pfc-sh7785: sh7785_pfc handling gpio 111 -> 275
[ 0.268000] sh-pfc pfc-sh7785: sh7785_pfc support registered
[ 0.268000] HW Breakpoints: SH-4A UBC support registered
[ 0.272000] PCI: Starting initialization.
[ 0.524000] PCI: Found a Renesas SH7785 host controller, revision 1.
[ 0.524000] PCI: Checking 66MHz capabilities...
[ 0.524000] PCI: Running at 66MHz.
[ 0.536000] HugeTLB: registered 1.00 MiB page size, pre-allocated 0 pages
[ 0.536000] HugeTLB: 0 KiB vmemmap can be freed for a 1.00 MiB page
[ 0.568000] SCSI subsystem initialized
[ 0.580000] usbcore: registered new interface driver usbfs
[ 0.580000] usbcore: registered new interface driver hub
[ 0.584000] usbcore: registered new device driver usb
[ 0.588000] sh_tmu sh-tmu.0: kept as earlytimer
[ 0.588000] sh_tmu sh-tmu.1: kept as earlytimer
[ 0.612000] DMA: Registering sh_dmac handler (12 channels).
[ 0.640000] DMA: Registering DMA API.
[ 0.644000] PCI host bridge to bus 0000:00
[ 0.644000] pci_bus 0000:00: root bus resource [io 0x1000-0x3fffff]
[ 0.644000] pci_bus 0000:00: root bus resource [mem 0xfd000000-0xfdffffff]
[ 0.644000] pci_bus 0000:00: root bus resource [mem 0x10000000-0x13ffffff]
[ 0.644000] pci_bus 0000:00: root bus resource [mem 0xc0000000-0xdfffffff]
[ 0.644000] pci_bus 0000:00: No busn resource found for root bus, will use [bus 00-ff]
[ 0.644000] pci 0000:00:00.0: [10ec:8169] type 00 class 0x020000 conventional PCI endpoint
[ 0.644000] pci 0000:00:00.0: BAR 0 [io 0x0000-0x00ff]
[ 0.644000] pci 0000:00:00.0: BAR 1 [mem 0x00000000-0x000000ff]
[ 0.644000] pci 0000:00:00.0: ROM [mem 0x00000000-0x0001ffff pref]
[ 0.644000] pci 0000:00:00.0: supports D1 D2
[ 0.644000] pci 0000:00:00.0: PME# supported from D1 D2 D3hot
[ 0.652000] pci 0000:00:01.0: [1095:3512] type 00 class 0x018000 conventional PCI endpoint
[ 0.652000] pci 0000:00:01.0: BAR 0 [io 0x0000-0x0007]
[ 0.652000] pci 0000:00:01.0: BAR 1 [io 0x0000-0x0003]
[ 0.652000] pci 0000:00:01.0: BAR 2 [io 0x0000-0x0007]
[ 0.652000] pci 0000:00:01.0: BAR 3 [io 0x0000-0x0003]
[ 0.652000] pci 0000:00:01.0: BAR 4 [io 0x0000-0x000f]
[ 0.652000] pci 0000:00:01.0: BAR 5 [mem 0x00000000-0x000001ff]
[ 0.652000] pci 0000:00:01.0: ROM [mem 0x00000000-0x0007ffff pref]
[ 0.652000] pci 0000:00:01.0: supports D1 D2
[ 0.660000] pci_bus 0000:00: busn_res: [bus 00-ff] end is updated to 00
[ 0.660000] pci 0000:00:01.0: ROM [mem 0xfd000000-0xfd07ffff pref]: assigned
[ 0.660000] pci 0000:00:00.0: ROM [mem 0xfd080000-0xfd09ffff pref]: assigned
[ 0.660000] pci 0000:00:01.0: BAR 5 [mem 0xfd0a0000-0xfd0a01ff]: assigned
[ 0.660000] pci 0000:00:00.0: BAR 0 [io 0x1000-0x10ff]: assigned
[ 0.660000] pci 0000:00:00.0: BAR 1 [mem 0xfd0a0200-0xfd0a02ff]: assigned
[ 0.660000] pci 0000:00:01.0: BAR 4 [io 0x1400-0x140f]: assigned
[ 0.660000] pci 0000:00:01.0: BAR 0 [io 0x1410-0x1417]: assigned
[ 0.660000] pci 0000:00:01.0: BAR 2 [io 0x1418-0x141f]: assigned
[ 0.660000] pci 0000:00:01.0: BAR 1 [io 0x1420-0x1423]: assigned
[ 0.660000] pci 0000:00:01.0: BAR 3 [io 0x1424-0x1427]: assigned
[ 0.664000] clocksource: Switched to clocksource sh-tmu.0
[ 0.668000] sh_tmu sh-tmu.0: ch0: used for oneshot clock events
[ 0.916000] NET: Registered PF_INET protocol family
[ 0.920000] IP idents hash table entries: 8192 (order: 4, 65536 bytes, linear)
[ 0.928000] tcp_listen_portaddr_hash hash table entries: 256 (order: 1, 5120 bytes, linear)
[ 0.928000] Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, linear)
[ 0.928000] TCP established hash table entries: 4096 (order: 2, 16384 bytes, linear)
[ 0.928000] TCP bind hash table entries: 4096 (order: 6, 163840 bytes, linear)
[ 0.928000] TCP: Hash tables configured (established 4096 bind 4096)
[ 0.932000] UDP hash table entries: 256 (order: 3, 20480 bytes, linear)
[ 0.932000] NET: Registered PF_UNIX/PF_LOCAL protocol family
[ 0.932000] PCI: CLS 0 bytes, default 32
[ 0.936000] sq: Registering store queue API.
[ 0.988000] workingset: timestamp_bits=30 (anon: 25) max_order=17 bucket_order=0 (anon: 0)
[ 1.012000] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 251)
[ 1.012000] io scheduler mq-deadline registered
[ 1.020000] SuperH (H)SCI(F) driver initialized
[ 1.044000] sh-sci.0: ttySC0 MMIO:0xffea0000 (irq = 56, base_baud = 0) is a scif
[ 1.072000] sh-sci.1: ttySC1 MMIO:0xffeb0000 (irq = 60, base_baud = 0) is a scif
[ 1.072000] printk: legacy console [ttySC1] enabled
[ 2.044000] sh-sci.2: ttySC2 MMIO:0xffec0000 (irq = 76, base_baud = 0) is a scif
[ 2.080000] sh-sci.3: ttySC3 MMIO:0xffed0000 (irq = 77, base_baud = 0) is a scif
[ 2.112000] sh-sci.4: ttySC4 MMIO:0xffee0000 (irq = 78, base_baud = 0) is a scif
[ 2.156000] sh-sci.5: ttySC5 MMIO:0xffef0000 (irq = 79, base_baud = 0) is a scif
[ 2.624000] brd: module loaded
[ 2.872000] loop: module loaded
[ 2.876000] sm501 sm501: SM501 At (ptrval): Version 050100c0, 4 Mb, IRQ 26
[ 2.884000] sm501 sm501: setting M1XCLK to 112000000
[ 2.912000] sm501 sm501: setting MCLK to 84000000
[ 2.960000] sata_sil 0000:00:01.0: enabling device (0000 -> 0003)
[ 2.968000] sata_sil 0000:00:01.0: cache line size not set. Driver may not function
[ 2.976000] sata_sil 0000:00:01.0: Applying R_ERR on DMA activate FIS errata fix
[ 3.040000] scsi host0: sata_sil
[ 3.064000] scsi host1: sata_sil
[ 3.084000] ata1: SATA max UDMA/100 mmio m512@0xfd0a0000 tf 0xfd0a0080 irq 82 lpm-pol 0
[ 3.092000] ata2: SATA max UDMA/100 mmio m512@0xfd0a0000 tf 0xfd0a00c0 irq 82 lpm-pol 0
[ 3.120000] physmap-flash physmap-flash.0: physmap platform flash device: [mem 0x00000000-0x03ffffff]
[ 3.132000] physmap-flash.0: Found 2 x16 devices at 0x0 in 32-bit bank. Manufacturer ID 0x000001 Chip ID 0x002201
[ 3.144000] Amd/Fujitsu Extended Query Table at 0x0040
[ 3.148000] Amd/Fujitsu Extended Query version 1.3.
[ 3.152000] number of CFI chips: 1
[ 3.164000] Creating 4 MTD partitions on "physmap-flash.0":
[ 3.172000] 0x000000000000-0x000000080000 : "loader"
[ 3.244000] 0x000000080000-0x000000100000 : "bootenv"
[ 3.320000] 0x000000100000-0x000000500000 : "kernel"
[ 3.396000] 0x000000500000-0x000004000000 : "data"
[ 3.412000] ata1: SATA link up 1.5 Gbps (SStatus 113 SControl 310)
[ 3.420000] ata1.00: ATA-9: TOSHIBA THNSNJ128GCSU, JURA0101, max UDMA/100
[ 3.436000] ata1.00: 250069680 sectors, multi 16: LBA48 NCQ (depth 0/32)
[ 3.444000] ata1.00: Features: Dev-Sleep HIPM DIPM
[ 3.460000] ata1.00: configured for UDMA/100
[ 3.484000] scsi 0:0:0:0: Direct-Access ATA TOSHIBA THNSNJ12 0101 PQ: 0 ANSI: 5
[ 3.620000] sd 0:0:0:0: [sda] 250069680 512-byte logical blocks: (128 GB/119 GiB)
[ 3.656000] sd 0:0:0:0: [sda] Write Protect is off
[ 3.668000] sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn't support DPO or FUA
[ 3.680000] r8169 0000:00:00.0: enabling device (0000 -> 0003)
[ 3.696000] sd 0:0:0:0: [sda] Preferred minimum I/O size 512 bytes
[ 3.780000] sda: sda1 sda2 sda3
[ 3.812000] sd 0:0:0:0: [sda] Attached SCSI disk
[ 3.836000] r8169 0000:00:00.0 eth0: RTL8169sc/8110sc, 00:00:87:6b:bd:69, XID 180, IRQ 81
[ 3.844000] r8169 0000:00:00.0 eth0: jumbo features [frames: 7146 bytes, tx checksumming: ok]
[ 3.868000] r8a66597_hcd r8a66597_hcd: USB Host Controller
[ 3.876000] r8a66597_hcd r8a66597_hcd: new USB bus registered, assigned bus number 1
[ 3.884000] r8a66597_hcd r8a66597_hcd: irq 18, io port 0x08000000
[ 3.924000] hub 1-0:1.0: USB hub found
[ 3.932000] hub 1-0:1.0: 2 ports detected
[ 3.960000] ata2: SATA link down (SStatus 0 SControl 310)
[ 3.980000] usbcore: registered new interface driver usb-storage
[ 3.992000] PCA9564/PCA9665 at 0x06000000: PCA9564 detected.
[ 3.996000] PCA9564/PCA9665 at 0x06000000: Choosing the clock frequency based on index is deprecated. Use the nominal frequency.
[ 4.008000] PCA9564/PCA9665 at 0x06000000: Clock frequency is 330kHz
[ 4.016000] (null): No reset-pin found. Chip may get stuck!
[ 4.028000] i2c-pca-platform i2c-pca-platform: registered.
[ 4.044000] cpufreq: SuperH CPU frequency driver.
[ 4.052000] cpufreq: cpufreq_policy_online: ->get() failed
[ 4.080000] usbcore: registered new interface driver usbhid
[ 4.088000] usbhid: USB HID core driver
[ 4.100000] NET: Registered PF_INET6 protocol family
[ 4.124000] Segment Routing with IPv6
[ 4.128000] In-situ OAM (IOAM) with IPv6
[ 4.132000] sit: IPv6, IPv4 and MPLS over IPv4 tunneling driver
[ 4.160000] NET: Registered PF_PACKET protocol family
[ 4.168000] Key type dns_resolver registered
[ 4.172000] heartbeat: version 0.1.2 loaded
[ 4.252000] usb 1-1: new high-speed USB device number 2 using r8a66597_hcd
[ 5.164000] kmemleak: Automatic memory scanning thread started
[ 5.172000] kmemleak: Kernel memory leak detector initialized (mem pool available: 15862)
[ 5.188000] /dev/root: Can't lookup blockdev
[ 5.192000] VFS: Cannot open root device "" or unknown-block(0,0): error -19
[ 5.200000] Please append a correct "root=" boot option; here are the available partitions:
[ 5.208000] 0100 4096 ram0
[ 5.208000] (driver?)
[ 5.216000] 0101 4096 ram1
[ 5.216000] (driver?)
[ 5.220000] 0102 4096 ram2
[ 5.220000] (driver?)
[ 5.228000] 0103 4096 ram3
[ 5.228000] (driver?)
[ 5.232000] 0104 4096 ram4
[ 5.232000] (driver?)
[ 5.240000] 0105 4096 ram5
[ 5.240000] (driver?)
[ 5.248000] 0106 4096 ram6
[ 5.248000] (driver?)
[ 5.252000] 0107 4096 ram7
[ 5.252000] (driver?)
[ 5.260000] 0108 4096 ram8
[ 5.260000] (driver?)
[ 5.264000] 0109 4096 ram9
[ 5.268000] (driver?)
[ 5.272000] 010a 4096 ram10
[ 5.272000] (driver?)
[ 5.280000] 010b 4096 ram11
[ 5.280000] (driver?)
[ 5.284000] 010c 4096 ram12
[ 5.284000] (driver?)
[ 5.292000] 010d 4096 ram13
[ 5.292000] (driver?)
[ 5.300000] 010e 4096 ram14
[ 5.300000] (driver?)
[ 5.304000] 010f 4096 ram15
[ 5.304000] (driver?)
[ 5.312000] 1f00 512 mtdblock0
[ 5.312000] (driver?)
[ 5.320000] 1f01 512 mtdblock1
[ 5.320000] (driver?)
[ 5.324000] 1f02 4096 mtdblock2
[ 5.324000] (driver?)
[ 5.332000] 1f03 60416 mtdblock3
[ 5.332000] (driver?)
[ 5.340000] 0800 125034840 sda
[ 5.340000] driver: sd
[ 5.344000] 0801 51200000 sda1 e6077cf7-01
[ 5.344000]
[ 5.352000] 0802 65011712 sda2 e6077cf7-02
[ 5.352000]
[ 5.360000] 0803 8822104 sda3 e6077cf7-03
[ 5.360000]
[ 5.368000] List of all bdev filesystems:
[ 5.372000] ext3
[ 5.372000] ext4
[ 5.372000] ext2
[ 5.376000] vfat
[ 5.376000] msdos
[ 5.380000]
[ 5.384000] Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0)
[ 5.384000] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 7.3.0-rc5-00002-g02d53450ebff #2 PREEMPT
[ 5.384000] Stack: (0x8108be4c to 0x8108c000)
[ 5.384000] be40: 8000bd2a 8108be60 80608484 806164e0 00000001
[ 5.384000] be60: 8000bd64 8108be74 80608484 807495ac 00000000 800026d6 8108be7c 00000005
[ 5.384000] be80: 80003260 800028cc 8108bea4 80608478 80474760 00000005 80003260 00000005
[ 5.384000] bea0: 8105a01a 8108beb4 a4cfc1f8 8071d252 8108bec0 8108becc 00000000 00000000
[ 5.384000] bec0: 00000000 ffffff9c 80608518 6e6b6e75 2d6e776f 636f6c62 2c30286b 80002930
[ 5.384000] bee0: 807406c4 00000000 00000000 a4cfc1f8 8071d382 8108bf10 000000c0 80749024
[ 5.384000] bf00: 807406c4 8074902c 00000000 807406c4 8074028c 8108bf44 8071d578 8108bf38
[ 5.384000] bf20: 000000c0 80749000 807406c4 8074902c 807406b8 80003260 8074026c a4cfc1f8
[ 5.384000] bf40: 8071cd1e 8108bf60 000000c0 80749000 8074028c 8074026c 810898e0 806b37bc
[ 5.384000] bf60: 00000007 00000007 00000000 8071c0a0 80746b74 8048c7a8 8108bf94 81098740
[ 5.384000] bf80: 806be21c 00000000 806b3d7c 806b1164 80003260 80010200 806aded8 806bdbe0
[ 5.384000] bfa0: 8003f0c4 00000000 00000000 00000000 00000000 00000000 8048c788 00000000
[ 5.384000] bfc0: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000
[ 5.384000] bfe0: 00000000 00000000 00000000 40008000 00000000 00000000 00000000 00000000
[ 5.384000]
[ 5.384000] Call trace:
[ 5.384000] [<8000bd2a>] dump_stack_lvl+0x36/0x64
[ 5.384000] [<8000bd64>] dump_stack+0xc/0x1c
[ 5.384000] [<800026d6>] vpanic+0xae/0x280
[ 5.384000] [<80003260>] _printk+0x0/0x50
[ 5.384000] [<800028cc>] panic+0x24/0x2c
[ 5.384000] [<80474760>] strlen+0x0/0x58
[ 5.384000] [<80003260>] _printk+0x0/0x50
[ 5.384000] [<8071d252>] mount_root_generic+0x12e/0x224
[ 5.384000] [<80002930>] pr_cont_pool_info+0x5c/0x80
[ 5.384000] [<8071d382>] mount_root+0x3a/0x168
[ 5.384000] [<8071d578>] prepare_namespace+0xc8/0x208
[ 5.384000] [<80003260>] _printk+0x0/0x50
[ 5.384000] [<8071cd1e>] kernel_init_freeable+0x16e/0x240
[ 5.384000] [<8071c0a0>] ignore_unknown_bootoption+0x0/0xc
[ 5.384000] [<8048c7a8>] kernel_init+0x20/0x120
[ 5.384000] [<80003260>] _printk+0x0/0x50
[ 5.384000] [<80010200>] ret_from_kernel_thread+0xc/0x14
[ 5.384000] [<8003f0c4>] schedule_tail+0x0/0x78
[ 5.384000] [<8048c788>] kernel_init+0x0/0x120
[ 5.384000]
[ 5.384000] ---[ end Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0) ]---
Adrian
--
.''`. John Paul Adrian Glaubitz
: :' : Debian Developer
`. `' Physicist
`- GPG: 62FF 8A75 84E0 2956 9546 0006 7426 3B37 F5B5 F913
^ permalink raw reply [flat|nested] 17+ messages in thread* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-09-29 9:20 ` John Paul Adrian Glaubitz
@ 2026-09-29 9:39 ` John Paul Adrian Glaubitz
0 siblings, 0 replies; 17+ messages in thread
From: John Paul Adrian Glaubitz @ 2026-09-29 9:39 UTC (permalink / raw)
To: Karl Mehltretter
Cc: Geert Uytterhoeven, Yoshinori Sato, Rich Felker, linux-sh, linux-kernel
Hi Karl,
On Tue, 2026-09-29 at 11:20 +0200, John Paul Adrian Glaubitz wrote:
> Hi Karl,
>
> On Mon, 2026-09-28 at 23:22 +0200, Karl Mehltretter wrote:
> > On Mon, Sep 28, 2026 at 09:02:55PM +0100, John Paul Adrian Glaubitz wrote:
> > > On Mon, 2026-09-28 at 20:34 +0200, Geert Uytterhoeven wrote:
> > > > > usb reset ; fatload usb 0:1 0x89000000 uImage-git.gz ; pmb ; bootm
> > > >
> > > > Do you have a config for that kernel?
> > >
> > > Here are some known configs:
> > >
> > > https://people.debian.org/~glaubitz/sh7785lcr/configs/
> >
> > I think it's the config. Your new image loads at 0x8c010000, the working
> > one at 0x80001000.
> >
> > 0x8c010000 is what an R2D config gives, and config-SH7785LCR-6.5 is one:
> > CPU_SUBTYPE_SH7751R and SH_RTS7751R2D, 29BIT, MEMORY_START 0x0c000000.
> > config-SH7785LCR-2024 still has SH7785LCR, 32BIT/PMB and MEMORY_START
> > 0x40000000, which gives 0x80001000.
> >
> > I tried both on my QEMU model of the SH7785LCR with 7.3: the 2024 config
> > boots up to the root mount, the 6.5 one prints nothing at all.
> >
> > So I'd start from config-SH7785LCR-2024 (or sh7785lcr_32bit_defconfig):
> >
> > cp config-SH7785LCR-2024 .config make ARCH=sh olddefconfig
> >
> > and check for "Load Address: 80001000". Keep the intc patch applied, the
> > overflow crashed v6.5 and v6.6 with SLUB on my QEMU model.
> >
> > With the right config the kernel may then really be too large: 7.3-rc5
> > with config-SH7785LCR-2024 uncompresses to 8.2 MiB, and U-Boot's default
> > CONFIG_SYS_BOOTM_LEN is 8 MiB. U-Boot then prints "Image too large:
> > increase CONFIG_SYS_BOOTM_LEN". With CONFIG_CC_OPTIMIZE_FOR_SIZE=y it is
> > 7.3 MiB and boots through U-Boot on the model.
>
> Yes, that did the trick! Just need to figure out now why it didn't parse the
> bootargs from u-boot to set the proper root device:
>
> => usb reset; fatload usb 0:1 0x89000000 uImage-7.3.0.gz ; pmb ; bootm
> (Re)start USB...
> USB0: scanning bus 0 for devices... 2 USB Device(s) found
> scanning usb for storage devices... 1 Storage Device(s) found
> reading uImage-7.3.0.gz
> 4319551 bytes read in 2457 ms (1.7 MiB/s)
> ## Booting kernel from Legacy Image at 89000000 ...
> Image Name: Linux-7.3.0-rc5-00002-g02d53450e
> Image Type: SuperH Linux Kernel Image (gzip compressed)
> Data Size: 4319487 Bytes = 4.1 MiB
> Load Address: 80001000
> Entry Point: 80002000
> Verifying Checksum ... OK
> Uncompressing Kernel Image ... OK
> [ 0.000000] Linux version 7.3.0-rc5-00002-g02d53450ebff (glaubitz@node54.cloud.suse.de) (sh4-linux-gcc (GCC) 11.1.0, GNU ld (GNU Binutils) 2.36.1) #2 PREEMPT Tue Sep 29 09:12:51 UTC 2026
> [ 0.000000] Boot params:
> [ 0.000000] ... MOUNT_ROOT_RDONLY - 00000000
> [ 0.000000] ... RAMDISK_FLAGS - 00000000
> [ 0.000000] ... ORIG_ROOT_DEV - 00000000
> [ 0.000000] ... LOADER_TYPE - 00000000
> [ 0.000000] ... INITRD_START - 00000000
> [ 0.000000] ... INITRD_SIZE - 00000000
> [ 0.000000] Booting machvec: SH7785LCR
> [ 0.000000] PMB: boot mappings:
> [ 0.000000] 0x00080000 -> 0x00040000 [ 512MB cached ]
> [ 0.000000] 0x000a0000 -> 0x00040000 [ 16MB uncached ]
> [ 0.000000] Renesas Technology Corp. R0P7785LC0011RL support.
> [ 0.000000] Zone ranges:
> [ 0.000000] Normal [mem 0x0000000040000000-0x000000005fffffff]
> [ 0.000000] Movable zone start for each node
> [ 0.000000] Early memory node ranges
> [ 0.000000] node 0: [mem 0x0000000040000000-0x000000005fffffff]
> [ 0.000000] Initmem setup node 0 [mem 0x0000000040000000-0x000000005fffffff]
> [ 0.000000] Kernel command line: console=ttySC1,115200
> [ 0.000000] printk: log buffer data + meta data: 65536 + 204800 = 270336 bytes
> [ 0.000000] Dentry cache hash table entries: 65536 (order: 6, 262144 bytes, linear)
> [ 0.000000] Inode-cache hash table entries: 32768 (order: 5, 131072 bytes, linear)
> [ 0.000000] Sorting __ex_table...
> [ 0.000000] Built 1 zonelists, mobility grouping on. Total pages: 131072
> [ 0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off
> [ 0.000000] stackdepot: allocating hash table via alloc_large_system_hash
> [ 0.000000] stackdepot hash table entries: 32768 (order: 6, 262144 bytes, linear)
> [ 0.000000] stackdepot: allocating space for 8192 stack pools via memblock
> [ 0.000000] PVR=10300700 CVR=71440211 PRR=00000250
> [ 0.000000] I-cache : n_ways=4 n_sets=256 way_incr=8192
> [ 0.000000] I-cache : entry_mask=0x00001fe0 alias_mask=0x00001000 n_aliases=2
> [ 0.000000] D-cache : n_ways=4 n_sets=256 way_incr=8192
> [ 0.000000] D-cache : entry_mask=0x00001fe0 alias_mask=0x00001000 n_aliases=2
> [ 0.000000] virtual kernel memory layout:
> [ 0.000000] fixmap : 0xdffd7000 - 0xdffff000 ( 160 kB)
> [ 0.000000] vmalloc : 0xc0000000 - 0xdffd5000 ( 511 MB)
> [ 0.000000] lowmem : 0x80000000 - 0xa0000000 ( 512 MB) (cached)
> [ 0.000000] : 0xa0000000 - 0xa1000000 ( 16 MB) (uncached)
> [ 0.000000] .init : 0x8071c000 - 0x80749000 ( 180 kB)
> [ 0.000000] .data : 0x80495280 - 0x8071b5f0 (2584 kB)
> [ 0.000000] .text : 0x80001000 - 0x80495280 (4688 kB)
> [ 0.000000] SLUB: HWalign=32, Order=0-3, MinObjects=0, CPUs=1, Nodes=1
> [ 0.000000] rcu: Preemptible hierarchical RCU implementation.
> [ 0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 25 jiffies.
> [ 0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0
> [ 0.000000] intc: Registered controller 'sh7785' with 67 IRQs
> [ 0.000000] intc: Registered controller 'sh7785-irq4567' with 4 IRQs
> [ 0.000000] intc: Registered controller 'sh7785-irq0123' with 4 IRQs
> [ 0.000000] rcu: srcu_init: Setting srcu_struct sizes based on contention.
> [ 0.000000] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 7645041785100000 ns
> [ 0.000000] Console: colour dummy device 80x25
> [ 0.000000] sh-tmu.0: ch0: used for clock events
> [ 0.000000] sh-tmu.0: ch0: used for periodic clock events
> [ 0.000000] sh-tmu.0: ch1: used as clock source
> [ 0.000000] clocksource: sh-tmu.0: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 152900847964 ns
> [ 0.000000] sh-tmu.1: ch0: used for clock events
> [ 0.000000] sh-tmu.1: ch1: used as clock source
> [ 0.000000] clocksource: sh-tmu.1: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 152900847964 ns
> [ 0.000000] sched_clock: 32 bits at 250 Hz, resolution 4000000ns, wraps every 8589934590000000ns
> [ 0.000000] Calibrating delay loop (skipped)... 599.99 BogoMIPS PRESET (lpj=1199999)
> [ 0.000000] CPU: SH7785
> [ 0.000000] pid_max: default: 32768 minimum: 301
> [ 0.004000] Mount-cache hash table entries: 1024 (order: 0, 4096 bytes, linear)
> [ 0.004000] Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes, linear)
> [ 0.012000] VFS: Finished mounting rootfs on nullfs
> [ 0.040000] Performance Events: sh4a support registered
> [ 0.044000] rcu: Hierarchical SRCU implementation.
> [ 0.044000] rcu: Max phase no-delay instances is 1000.
> [ 0.052000] Memory: 508924K/524288K available (4684K kernel code, 452K rwdata, 2128K rodata, 180K init, 2149K bss, 14428K reserved, 0K cma-reserved)
> [ 0.056000] devtmpfs: initialized
> [ 0.084000] posixtimers hash table entries: 512 (order: 2, 10240 bytes, linear)
> [ 0.084000] futex hash table entries: 256 (7168 bytes on 1 NUMA nodes, total 7 KiB, linear).
> [ 0.104000] NET: Registered PF_NETLINK/PF_ROUTE protocol family
> [ 0.196000] DMA: preallocated 128 KiB GFP_KERNEL pool for atomic allocations
> [ 0.196000] audit: initializing netlink subsys (disabled)
> [ 0.204000] audit: type=2000 audit(0.200:1): state=initialized audit_enabled=0 res=1
> [ 0.212000] cpuidle: using governor ladder
> [ 0.212000] cpuidle: using governor menu
> [ 0.252000] gpio gpiochip0: Static allocation of GPIO base is deprecated, use dynamic allocation.
> [ 0.260000] sh-pfc pfc-sh7785: sh7785_pfc handling gpio 0 -> 110
> [ 0.264000] gpio gpiochip1: Static allocation of GPIO base is deprecated, use dynamic allocation.
> [ 0.268000] sh-pfc pfc-sh7785: sh7785_pfc handling gpio 111 -> 275
> [ 0.268000] sh-pfc pfc-sh7785: sh7785_pfc support registered
> [ 0.268000] HW Breakpoints: SH-4A UBC support registered
> [ 0.272000] PCI: Starting initialization.
> [ 0.524000] PCI: Found a Renesas SH7785 host controller, revision 1.
> [ 0.524000] PCI: Checking 66MHz capabilities...
> [ 0.524000] PCI: Running at 66MHz.
> [ 0.536000] HugeTLB: registered 1.00 MiB page size, pre-allocated 0 pages
> [ 0.536000] HugeTLB: 0 KiB vmemmap can be freed for a 1.00 MiB page
> [ 0.568000] SCSI subsystem initialized
> [ 0.580000] usbcore: registered new interface driver usbfs
> [ 0.580000] usbcore: registered new interface driver hub
> [ 0.584000] usbcore: registered new device driver usb
> [ 0.588000] sh_tmu sh-tmu.0: kept as earlytimer
> [ 0.588000] sh_tmu sh-tmu.1: kept as earlytimer
> [ 0.612000] DMA: Registering sh_dmac handler (12 channels).
> [ 0.640000] DMA: Registering DMA API.
> [ 0.644000] PCI host bridge to bus 0000:00
> [ 0.644000] pci_bus 0000:00: root bus resource [io 0x1000-0x3fffff]
> [ 0.644000] pci_bus 0000:00: root bus resource [mem 0xfd000000-0xfdffffff]
> [ 0.644000] pci_bus 0000:00: root bus resource [mem 0x10000000-0x13ffffff]
> [ 0.644000] pci_bus 0000:00: root bus resource [mem 0xc0000000-0xdfffffff]
> [ 0.644000] pci_bus 0000:00: No busn resource found for root bus, will use [bus 00-ff]
> [ 0.644000] pci 0000:00:00.0: [10ec:8169] type 00 class 0x020000 conventional PCI endpoint
> [ 0.644000] pci 0000:00:00.0: BAR 0 [io 0x0000-0x00ff]
> [ 0.644000] pci 0000:00:00.0: BAR 1 [mem 0x00000000-0x000000ff]
> [ 0.644000] pci 0000:00:00.0: ROM [mem 0x00000000-0x0001ffff pref]
> [ 0.644000] pci 0000:00:00.0: supports D1 D2
> [ 0.644000] pci 0000:00:00.0: PME# supported from D1 D2 D3hot
> [ 0.652000] pci 0000:00:01.0: [1095:3512] type 00 class 0x018000 conventional PCI endpoint
> [ 0.652000] pci 0000:00:01.0: BAR 0 [io 0x0000-0x0007]
> [ 0.652000] pci 0000:00:01.0: BAR 1 [io 0x0000-0x0003]
> [ 0.652000] pci 0000:00:01.0: BAR 2 [io 0x0000-0x0007]
> [ 0.652000] pci 0000:00:01.0: BAR 3 [io 0x0000-0x0003]
> [ 0.652000] pci 0000:00:01.0: BAR 4 [io 0x0000-0x000f]
> [ 0.652000] pci 0000:00:01.0: BAR 5 [mem 0x00000000-0x000001ff]
> [ 0.652000] pci 0000:00:01.0: ROM [mem 0x00000000-0x0007ffff pref]
> [ 0.652000] pci 0000:00:01.0: supports D1 D2
> [ 0.660000] pci_bus 0000:00: busn_res: [bus 00-ff] end is updated to 00
> [ 0.660000] pci 0000:00:01.0: ROM [mem 0xfd000000-0xfd07ffff pref]: assigned
> [ 0.660000] pci 0000:00:00.0: ROM [mem 0xfd080000-0xfd09ffff pref]: assigned
> [ 0.660000] pci 0000:00:01.0: BAR 5 [mem 0xfd0a0000-0xfd0a01ff]: assigned
> [ 0.660000] pci 0000:00:00.0: BAR 0 [io 0x1000-0x10ff]: assigned
> [ 0.660000] pci 0000:00:00.0: BAR 1 [mem 0xfd0a0200-0xfd0a02ff]: assigned
> [ 0.660000] pci 0000:00:01.0: BAR 4 [io 0x1400-0x140f]: assigned
> [ 0.660000] pci 0000:00:01.0: BAR 0 [io 0x1410-0x1417]: assigned
> [ 0.660000] pci 0000:00:01.0: BAR 2 [io 0x1418-0x141f]: assigned
> [ 0.660000] pci 0000:00:01.0: BAR 1 [io 0x1420-0x1423]: assigned
> [ 0.660000] pci 0000:00:01.0: BAR 3 [io 0x1424-0x1427]: assigned
> [ 0.664000] clocksource: Switched to clocksource sh-tmu.0
> [ 0.668000] sh_tmu sh-tmu.0: ch0: used for oneshot clock events
> [ 0.916000] NET: Registered PF_INET protocol family
> [ 0.920000] IP idents hash table entries: 8192 (order: 4, 65536 bytes, linear)
> [ 0.928000] tcp_listen_portaddr_hash hash table entries: 256 (order: 1, 5120 bytes, linear)
> [ 0.928000] Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, linear)
> [ 0.928000] TCP established hash table entries: 4096 (order: 2, 16384 bytes, linear)
> [ 0.928000] TCP bind hash table entries: 4096 (order: 6, 163840 bytes, linear)
> [ 0.928000] TCP: Hash tables configured (established 4096 bind 4096)
> [ 0.932000] UDP hash table entries: 256 (order: 3, 20480 bytes, linear)
> [ 0.932000] NET: Registered PF_UNIX/PF_LOCAL protocol family
> [ 0.932000] PCI: CLS 0 bytes, default 32
> [ 0.936000] sq: Registering store queue API.
> [ 0.988000] workingset: timestamp_bits=30 (anon: 25) max_order=17 bucket_order=0 (anon: 0)
> [ 1.012000] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 251)
> [ 1.012000] io scheduler mq-deadline registered
> [ 1.020000] SuperH (H)SCI(F) driver initialized
> [ 1.044000] sh-sci.0: ttySC0 MMIO:0xffea0000 (irq = 56, base_baud = 0) is a scif
> [ 1.072000] sh-sci.1: ttySC1 MMIO:0xffeb0000 (irq = 60, base_baud = 0) is a scif
> [ 1.072000] printk: legacy console [ttySC1] enabled
> [ 2.044000] sh-sci.2: ttySC2 MMIO:0xffec0000 (irq = 76, base_baud = 0) is a scif
> [ 2.080000] sh-sci.3: ttySC3 MMIO:0xffed0000 (irq = 77, base_baud = 0) is a scif
> [ 2.112000] sh-sci.4: ttySC4 MMIO:0xffee0000 (irq = 78, base_baud = 0) is a scif
> [ 2.156000] sh-sci.5: ttySC5 MMIO:0xffef0000 (irq = 79, base_baud = 0) is a scif
> [ 2.624000] brd: module loaded
> [ 2.872000] loop: module loaded
> [ 2.876000] sm501 sm501: SM501 At (ptrval): Version 050100c0, 4 Mb, IRQ 26
> [ 2.884000] sm501 sm501: setting M1XCLK to 112000000
> [ 2.912000] sm501 sm501: setting MCLK to 84000000
> [ 2.960000] sata_sil 0000:00:01.0: enabling device (0000 -> 0003)
> [ 2.968000] sata_sil 0000:00:01.0: cache line size not set. Driver may not function
> [ 2.976000] sata_sil 0000:00:01.0: Applying R_ERR on DMA activate FIS errata fix
> [ 3.040000] scsi host0: sata_sil
> [ 3.064000] scsi host1: sata_sil
> [ 3.084000] ata1: SATA max UDMA/100 mmio m512@0xfd0a0000 tf 0xfd0a0080 irq 82 lpm-pol 0
> [ 3.092000] ata2: SATA max UDMA/100 mmio m512@0xfd0a0000 tf 0xfd0a00c0 irq 82 lpm-pol 0
> [ 3.120000] physmap-flash physmap-flash.0: physmap platform flash device: [mem 0x00000000-0x03ffffff]
> [ 3.132000] physmap-flash.0: Found 2 x16 devices at 0x0 in 32-bit bank. Manufacturer ID 0x000001 Chip ID 0x002201
> [ 3.144000] Amd/Fujitsu Extended Query Table at 0x0040
> [ 3.148000] Amd/Fujitsu Extended Query version 1.3.
> [ 3.152000] number of CFI chips: 1
> [ 3.164000] Creating 4 MTD partitions on "physmap-flash.0":
> [ 3.172000] 0x000000000000-0x000000080000 : "loader"
> [ 3.244000] 0x000000080000-0x000000100000 : "bootenv"
> [ 3.320000] 0x000000100000-0x000000500000 : "kernel"
> [ 3.396000] 0x000000500000-0x000004000000 : "data"
> [ 3.412000] ata1: SATA link up 1.5 Gbps (SStatus 113 SControl 310)
> [ 3.420000] ata1.00: ATA-9: TOSHIBA THNSNJ128GCSU, JURA0101, max UDMA/100
> [ 3.436000] ata1.00: 250069680 sectors, multi 16: LBA48 NCQ (depth 0/32)
> [ 3.444000] ata1.00: Features: Dev-Sleep HIPM DIPM
> [ 3.460000] ata1.00: configured for UDMA/100
> [ 3.484000] scsi 0:0:0:0: Direct-Access ATA TOSHIBA THNSNJ12 0101 PQ: 0 ANSI: 5
> [ 3.620000] sd 0:0:0:0: [sda] 250069680 512-byte logical blocks: (128 GB/119 GiB)
> [ 3.656000] sd 0:0:0:0: [sda] Write Protect is off
> [ 3.668000] sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn't support DPO or FUA
> [ 3.680000] r8169 0000:00:00.0: enabling device (0000 -> 0003)
> [ 3.696000] sd 0:0:0:0: [sda] Preferred minimum I/O size 512 bytes
> [ 3.780000] sda: sda1 sda2 sda3
> [ 3.812000] sd 0:0:0:0: [sda] Attached SCSI disk
> [ 3.836000] r8169 0000:00:00.0 eth0: RTL8169sc/8110sc, 00:00:87:6b:bd:69, XID 180, IRQ 81
> [ 3.844000] r8169 0000:00:00.0 eth0: jumbo features [frames: 7146 bytes, tx checksumming: ok]
> [ 3.868000] r8a66597_hcd r8a66597_hcd: USB Host Controller
> [ 3.876000] r8a66597_hcd r8a66597_hcd: new USB bus registered, assigned bus number 1
> [ 3.884000] r8a66597_hcd r8a66597_hcd: irq 18, io port 0x08000000
> [ 3.924000] hub 1-0:1.0: USB hub found
> [ 3.932000] hub 1-0:1.0: 2 ports detected
> [ 3.960000] ata2: SATA link down (SStatus 0 SControl 310)
> [ 3.980000] usbcore: registered new interface driver usb-storage
> [ 3.992000] PCA9564/PCA9665 at 0x06000000: PCA9564 detected.
> [ 3.996000] PCA9564/PCA9665 at 0x06000000: Choosing the clock frequency based on index is deprecated. Use the nominal frequency.
> [ 4.008000] PCA9564/PCA9665 at 0x06000000: Clock frequency is 330kHz
> [ 4.016000] (null): No reset-pin found. Chip may get stuck!
> [ 4.028000] i2c-pca-platform i2c-pca-platform: registered.
> [ 4.044000] cpufreq: SuperH CPU frequency driver.
> [ 4.052000] cpufreq: cpufreq_policy_online: ->get() failed
> [ 4.080000] usbcore: registered new interface driver usbhid
> [ 4.088000] usbhid: USB HID core driver
> [ 4.100000] NET: Registered PF_INET6 protocol family
> [ 4.124000] Segment Routing with IPv6
> [ 4.128000] In-situ OAM (IOAM) with IPv6
> [ 4.132000] sit: IPv6, IPv4 and MPLS over IPv4 tunneling driver
> [ 4.160000] NET: Registered PF_PACKET protocol family
> [ 4.168000] Key type dns_resolver registered
> [ 4.172000] heartbeat: version 0.1.2 loaded
> [ 4.252000] usb 1-1: new high-speed USB device number 2 using r8a66597_hcd
> [ 5.164000] kmemleak: Automatic memory scanning thread started
> [ 5.172000] kmemleak: Kernel memory leak detector initialized (mem pool available: 15862)
> [ 5.188000] /dev/root: Can't lookup blockdev
> [ 5.192000] VFS: Cannot open root device "" or unknown-block(0,0): error -19
> [ 5.200000] Please append a correct "root=" boot option; here are the available partitions:
> [ 5.208000] 0100 4096 ram0
> [ 5.208000] (driver?)
> [ 5.216000] 0101 4096 ram1
> [ 5.216000] (driver?)
> [ 5.220000] 0102 4096 ram2
> [ 5.220000] (driver?)
> [ 5.228000] 0103 4096 ram3
> [ 5.228000] (driver?)
> [ 5.232000] 0104 4096 ram4
> [ 5.232000] (driver?)
> [ 5.240000] 0105 4096 ram5
> [ 5.240000] (driver?)
> [ 5.248000] 0106 4096 ram6
> [ 5.248000] (driver?)
> [ 5.252000] 0107 4096 ram7
> [ 5.252000] (driver?)
> [ 5.260000] 0108 4096 ram8
> [ 5.260000] (driver?)
> [ 5.264000] 0109 4096 ram9
> [ 5.268000] (driver?)
> [ 5.272000] 010a 4096 ram10
> [ 5.272000] (driver?)
> [ 5.280000] 010b 4096 ram11
> [ 5.280000] (driver?)
> [ 5.284000] 010c 4096 ram12
> [ 5.284000] (driver?)
> [ 5.292000] 010d 4096 ram13
> [ 5.292000] (driver?)
> [ 5.300000] 010e 4096 ram14
> [ 5.300000] (driver?)
> [ 5.304000] 010f 4096 ram15
> [ 5.304000] (driver?)
> [ 5.312000] 1f00 512 mtdblock0
> [ 5.312000] (driver?)
> [ 5.320000] 1f01 512 mtdblock1
> [ 5.320000] (driver?)
> [ 5.324000] 1f02 4096 mtdblock2
> [ 5.324000] (driver?)
> [ 5.332000] 1f03 60416 mtdblock3
> [ 5.332000] (driver?)
> [ 5.340000] 0800 125034840 sda
> [ 5.340000] driver: sd
> [ 5.344000] 0801 51200000 sda1 e6077cf7-01
> [ 5.344000]
> [ 5.352000] 0802 65011712 sda2 e6077cf7-02
> [ 5.352000]
> [ 5.360000] 0803 8822104 sda3 e6077cf7-03
> [ 5.360000]
> [ 5.368000] List of all bdev filesystems:
> [ 5.372000] ext3
> [ 5.372000] ext4
> [ 5.372000] ext2
> [ 5.376000] vfat
> [ 5.376000] msdos
> [ 5.380000]
> [ 5.384000] Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0)
> [ 5.384000] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 7.3.0-rc5-00002-g02d53450ebff #2 PREEMPT
> [ 5.384000] Stack: (0x8108be4c to 0x8108c000)
> [ 5.384000] be40: 8000bd2a 8108be60 80608484 806164e0 00000001
> [ 5.384000] be60: 8000bd64 8108be74 80608484 807495ac 00000000 800026d6 8108be7c 00000005
> [ 5.384000] be80: 80003260 800028cc 8108bea4 80608478 80474760 00000005 80003260 00000005
> [ 5.384000] bea0: 8105a01a 8108beb4 a4cfc1f8 8071d252 8108bec0 8108becc 00000000 00000000
> [ 5.384000] bec0: 00000000 ffffff9c 80608518 6e6b6e75 2d6e776f 636f6c62 2c30286b 80002930
> [ 5.384000] bee0: 807406c4 00000000 00000000 a4cfc1f8 8071d382 8108bf10 000000c0 80749024
> [ 5.384000] bf00: 807406c4 8074902c 00000000 807406c4 8074028c 8108bf44 8071d578 8108bf38
> [ 5.384000] bf20: 000000c0 80749000 807406c4 8074902c 807406b8 80003260 8074026c a4cfc1f8
> [ 5.384000] bf40: 8071cd1e 8108bf60 000000c0 80749000 8074028c 8074026c 810898e0 806b37bc
> [ 5.384000] bf60: 00000007 00000007 00000000 8071c0a0 80746b74 8048c7a8 8108bf94 81098740
> [ 5.384000] bf80: 806be21c 00000000 806b3d7c 806b1164 80003260 80010200 806aded8 806bdbe0
> [ 5.384000] bfa0: 8003f0c4 00000000 00000000 00000000 00000000 00000000 8048c788 00000000
> [ 5.384000] bfc0: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000
> [ 5.384000] bfe0: 00000000 00000000 00000000 40008000 00000000 00000000 00000000 00000000
> [ 5.384000]
> [ 5.384000] Call trace:
> [ 5.384000] [<8000bd2a>] dump_stack_lvl+0x36/0x64
> [ 5.384000] [<8000bd64>] dump_stack+0xc/0x1c
> [ 5.384000] [<800026d6>] vpanic+0xae/0x280
> [ 5.384000] [<80003260>] _printk+0x0/0x50
> [ 5.384000] [<800028cc>] panic+0x24/0x2c
> [ 5.384000] [<80474760>] strlen+0x0/0x58
> [ 5.384000] [<80003260>] _printk+0x0/0x50
> [ 5.384000] [<8071d252>] mount_root_generic+0x12e/0x224
> [ 5.384000] [<80002930>] pr_cont_pool_info+0x5c/0x80
> [ 5.384000] [<8071d382>] mount_root+0x3a/0x168
> [ 5.384000] [<8071d578>] prepare_namespace+0xc8/0x208
> [ 5.384000] [<80003260>] _printk+0x0/0x50
> [ 5.384000] [<8071cd1e>] kernel_init_freeable+0x16e/0x240
> [ 5.384000] [<8071c0a0>] ignore_unknown_bootoption+0x0/0xc
> [ 5.384000] [<8048c7a8>] kernel_init+0x20/0x120
> [ 5.384000] [<80003260>] _printk+0x0/0x50
> [ 5.384000] [<80010200>] ret_from_kernel_thread+0xc/0x14
> [ 5.384000] [<8003f0c4>] schedule_tail+0x0/0x78
> [ 5.384000] [<8048c788>] kernel_init+0x0/0x120
> [ 5.384000]
> [ 5.384000] ---[ end Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0) ]---
OK, CONFIG_CMDLINE_FROM_BOOTLOADER=y was missing.
root@tirpitz:~> uname -a
Linux tirpitz.buildd.org 7.3.0-rc5-00002-g02d53450ebff #3 PREEMPT Tue Sep 29 09:33:13 UTC 2026 sh4a GNU/Linux
root@tirpitz:~>
Now I can go ahead and test your patch or, better said, check how the kernel
behaves without it as my SH-7785LCR is currently with your patch applied.
Adrian
--
.''`. John Paul Adrian Glaubitz
: :' : Debian Developer
`. `' Physicist
`- GPG: 62FF 8A75 84E0 2956 9546 0006 7426 3B37 F5B5 F913
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-09-27 19:13 [PATCH] sh: intc: sort the prio and sense lists after filling them Karl Mehltretter
2026-09-27 19:30 ` Karl Mehltretter
2026-09-28 15:01 ` John Paul Adrian Glaubitz
@ 2026-10-02 4:57 ` John Paul Adrian Glaubitz
2026-10-02 21:58 ` Karl Mehltretter
2026-10-03 7:51 ` John Paul Adrian Glaubitz
3 siblings, 1 reply; 17+ messages in thread
From: John Paul Adrian Glaubitz @ 2026-10-02 4:57 UTC (permalink / raw)
To: Karl Mehltretter, Yoshinori Sato, Rich Felker; +Cc: linux-sh, linux-kernel
Hi Karl,
On Sun, 2026-09-27 at 21:13 +0200, Karl Mehltretter wrote:
> register_intc_controller() sorts d->prio and d->sense right after
> allocating them, with hw->nr_prio_regs and hw->nr_sense_regs as the
> element count. The lists hold hw->nr_vectors entries and are only
> filled later, by intc_register_irq().
>
> On SH7785, sh7785-irq0123 and sh7785-irq4567 have four vectors but the
> SoC's eleven priority registers, so sort() swaps 88 bytes in a 32 byte
> kmalloc object at boot. slub_debug=FZPU reports "Right Redzone
> overwritten" in kmalloc-32, and v6.5 and v6.6 panic in
> __kmem_cache_alloc_node() while registering sh7785-irq0123.
>
> Found with a custom QEMU model of the SH7785LCR. On it, v6.4
> sh7785lcr_defconfig boots with SLAB, the defconfig default before v6.5,
> and hangs before the console is up when built with SLUB.
>
> Sort the lists once all vectors are registered, with the number of
> entries that were added.
>
> Fixes: b59f9f9775e6 ("sh: intc: optimize intc IRQ lookup")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
> ---
>
> Notes:
> Testing, all in QEMU on a custom SH7785LCR model, not on hardware:
> - v6.5 and v6.6 sh7785lcr_defconfig hang before the console is up
> (gcc 8 and gcc 14). With slub_debug=FZPU they boot and validating
> kmalloc-32 reports "Right Redzone overwritten" after the object
> holding the entries of sh7785-irq4567. With this patch they boot
> and the report is gone.
> - v6.4 sh7785lcr_defconfig (SLAB) boots. The same v6.4 built with SLUB
> hangs, reports the overflow with slub_debug=FZPU, and boots with
> this patch.
> - Current mainline boots with or without the patch, but reports the
> overflow with slub_debug=FZPU unless patched.
> Testing on real hardware is welcome.
>
> drivers/sh/intc/core.c | 11 +++++------
> 1 file changed, 5 insertions(+), 6 deletions(-)
>
> diff --git a/drivers/sh/intc/core.c b/drivers/sh/intc/core.c
> index aa68fe190865d..ffbe60234eefc 100644
> --- a/drivers/sh/intc/core.c
> +++ b/drivers/sh/intc/core.c
> @@ -275,9 +275,6 @@ int __init register_intc_controller(struct intc_desc *desc)
> k += save_reg(d, k, hw->prio_regs[i].set_reg, smp);
> k += save_reg(d, k, hw->prio_regs[i].clr_reg, smp);
> }
> -
> - sort(d->prio, hw->nr_prio_regs, sizeof(*d->prio),
> - intc_handle_int_cmp, NULL);
> }
>
> if (hw->sense_regs) {
> @@ -287,9 +284,6 @@ int __init register_intc_controller(struct intc_desc *desc)
>
> for (i = 0; i < hw->nr_sense_regs; i++)
> k += save_reg(d, k, hw->sense_regs[i].reg, 0);
> -
> - sort(d->sense, hw->nr_sense_regs, sizeof(*d->sense),
> - intc_handle_int_cmp, NULL);
> }
>
> if (hw->subgroups)
> @@ -357,6 +351,11 @@ int __init register_intc_controller(struct intc_desc *desc)
> }
> }
>
> + sort(d->prio, d->nr_prio, sizeof(*d->prio),
> + intc_handle_int_cmp, NULL);
> + sort(d->sense, d->nr_sense, sizeof(*d->sense),
> + intc_handle_int_cmp, NULL);
> +
> intc_subgroup_init(desc, d);
>
> /* enable bits matching force_enable after registering irqs */
I just booted the kernel with slub_debug=FZPU on my SH-7785LCR EVB and
I'm getting the following "kmalloc Redzone overwritten" warning in both
cases.
Without your patch:
[ 9.580000] [kmalloc Redzone overwritten] 0x820d32a9-0x820d32a9 @offset=681. First byte 0x9 instead of 0xcc
[ 9.580000] =============================================================================
[ 9.580000] BUG kmalloc-32 (Not tainted): Object corrupt
[ 9.580000] -----------------------------------------------------------------------------
[ 9.580000]
[ 9.580000] Allocated in usb_get_configuration+0x12c/0x11d8 age=51 cpu=0 pid=10
[ 9.580000] _raw_spin_lock_irqsave+0x20/0x38
[ 9.580000] ___slab_alloc+0x21e/0x44c
[ 9.580000] _raw_spin_unlock_irqrestore+0xe/0x44
[ 9.580000] __alloc_object+0xaa/0x19c
[ 9.580000] memset+0x0/0x8c
[ 9.580000] __kmalloc_noprof+0xb0/0x1c0
[ 9.580000] memset+0x0/0x8c
[ 9.580000] _kzalloc_noprof.constprop.0+0xc/0x1c
[ 9.580000] usb_get_configuration+0x12c/0x11d8
[ 9.580000] usb_get_configuration+0x12c/0x11d8
[ 9.580000] _kzalloc_noprof.constprop.0+0x0/0x1c
[ 9.580000] set_next_task_fair+0x190/0x350
[ 9.580000] __schedule+0x5aa/0x6bc
[ 9.580000] _raw_spin_lock_irqsave+0x20/0x38
[ 9.580000] _raw_spin_unlock_irqrestore+0xe/0x44
[ 9.580000] __try_to_del_timer_sync+0x4a/0x88
[ 9.580000] Slab 0x9ff41a60 objects=32 used=7 fp=0x820d33a0 flags=0x40000200(workingset|section=16|zone=0)
[ 9.580000] Object 0x820d32a0 @offset=672 fp=0x820d3320
[ 9.580000]
[ 9.580000] Redzone 820d3280: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................
[ 9.580000] Redzone 820d3290: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................
[ 9.580000] Object 820d32a0: 09 02 20 00 01 01 00 80 fa 09 cc cc cc cc cc cc .. .............
[ 9.580000] Object 820d32b0: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................
[ 9.580000] Redzone 820d32c0: cc cc cc cc ....
[ 9.580000] Padding 820d32f4: 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a ZZZZZZZZZZZZ
[ 9.580000] Disabling lock debugging due to kernel taint
[ 9.580000] ------------[ cut here ]------------
[ 9.580000] WARNING: mm/slub.c:1257 at object_err+0x46/0x158, CPU#0: kworker/0:1/10
[ 9.580000] Modules linked in:
[ 9.580000]
[ 9.580000] CPU: 0 UID: 0 PID: 10 Comm: kworker/0:1 Tainted: G B 7.3.0-rc5-00001-g8cd915e933c5 #4 PREEMPT
[ 9.580000] Tainted: [B]=BAD_PAGE
[ 9.580000] Workqueue: usb_hub_wq hub_event
[ 9.580000] PC is at object_err+0x46/0x158
[ 9.580000] PR is at object_err+0x46/0x158
[ 9.580000] PC : 80004e3a SP : 810cdc20 SR : 400081f1 TEA : c00d0008
[ 9.580000] R0 : 00000020 R1 : 8074959c R2 : 00000000 R3 : 00000020
[ 9.580000] R4 : 00000001 R5 : ff623224 R6 : 00000000 R7 : 00000000
[ 9.580000] R8 : 810023e0 R9 : 820d32a0 R10 : 00000054 R11 : 80004d48
[ 9.580000] R12 : 0000808f R13 : 80004bd4 R14 : 810cdc20
[ 9.580000] MACH: 0000003a MACL: 0002bfa8 GBR : 2958a4c0 PR : 80004e3a
[ 9.580000]
[ 9.580000] Call trace:
[ 9.580000] [<800ff6d2>] check_bytes_and_report+0xa2/0xfc
[ 9.580000] [<800ff7d2>] check_object+0xa6/0x204
[ 9.580000] [<800ff630>] check_bytes_and_report+0x0/0xfc
[ 9.580000] [<80100222>] free_to_partial_list+0x9a/0x2b8
[ 9.580000] [<800788da>] __timer_delete_sync+0x2a/0x50
[ 9.580000] [<80078810>] __try_to_del_timer_sync+0x0/0x88
[ 9.580000] [<8007890c>] timer_delete_sync+0xc/0x18
[ 9.580000] [<8010048a>] __slab_free+0x4a/0x19c
[ 9.580000] [<80009264>] _dev_notice+0x0/0x5c
[ 9.580000] [<8032b516>] usb_get_configuration+0x1a2/0x11d8
[ 9.580000] [<80112d28>] delete_object_full+0x40/0x68
[ 9.580000] [<80101bf6>] kfree+0x112/0x1a4
[ 9.580000] [<80009264>] _dev_notice+0x0/0x5c
[ 9.580000] [<8032b516>] usb_get_configuration+0x1a2/0x11d8
[ 9.580000] [<8032b516>] usb_get_configuration+0x1a2/0x11d8
[ 9.580000] [<8032b516>] usb_get_configuration+0x1a2/0x11d8
[ 9.580000] [<80009264>] _dev_notice+0x0/0x5c
[ 9.580000] [<80044ec0>] set_next_task_fair+0x190/0x350
[ 9.580000] [<800788da>] __timer_delete_sync+0x2a/0x50
[ 9.580000] [<80078810>] __try_to_del_timer_sync+0x0/0x88
[ 9.580000] [<8007890c>] timer_delete_sync+0xc/0x18
[ 9.580000] [<80492f70>] schedule_timeout+0x98/0xe4
[ 9.580000] [<80323842>] usb_new_device+0x46/0x2ac
[ 9.580000] [<80493014>] schedule_timeout_uninterruptible+0x14/0x20
[ 9.580000] [<803248c0>] hub_event+0xbf0/0xdf4
[ 9.580000] [<8025657c>] _find_next_zero_bit+0x0/0x6c
[ 9.580000] [<80493756>] _raw_spin_unlock_bh+0x16/0x2c
[ 9.580000] [<80323360>] hub_init_func3+0x10/0x20
[ 9.580000] [<8002f084>] process_scheduled_works+0x148/0x25c
[ 9.580000] [<80030638>] wq_worker_sleeping+0x14/0x88
[ 9.580000] [<8002ccca>] assign_work+0x6c/0x82
[ 9.580000] [<8002f358>] worker_thread+0xe4/0x1a8
[ 9.580000] [<80493b98>] _raw_spin_lock_irq+0x0/0x34
[ 9.580000] [<8002cc5e>] assign_work+0x0/0x82
[ 9.580000] [<80036168>] kthread+0xdc/0x114
[ 9.580000] [<8002f274>] worker_thread+0x0/0x1a8
[ 9.580000] [<8001d45c>] do_exit+0x0/0x798
[ 9.580000] [<80010200>] ret_from_kernel_thread+0xc/0x14
[ 9.580000] [<8003f0c4>] schedule_tail+0x0/0x78
[ 9.580000] [<8003608c>] kthread+0x0/0x114
[ 9.580000]
[ 9.580000] ---[ end trace 0000000000000000 ]---
[ 9.580000] FIX kmalloc-32: Restoring kmalloc Redzone 0x820d32a9-0x820d32a9=0xcc
[ 9.580000] FIX kmalloc-32: Object at 0x820d32a0 not freed
[ 10.536000] kmemleak: Kernel memory leak detector initialized (mem pool available: 15907)
[ 10.544000] kmemleak: Automatic memory scanning thread started
With your patch:
[ 9.612000] [kmalloc Redzone overwritten] 0x820cc229-0x820cc229 @offset=553. First byte 0x9 instead of 0xcc
[ 9.612000] =============================================================================
[ 9.612000] BUG kmalloc-32 (Not tainted): Object corrupt
[ 9.612000] -----------------------------------------------------------------------------
[ 9.612000]
[ 9.612000] Allocated in usb_get_configuration+0x12c/0x11d8 age=51 cpu=0 pid=10
[ 9.612000] _raw_spin_lock_irqsave+0x20/0x38
[ 9.612000] ___slab_alloc+0x21e/0x44c
[ 9.612000] _raw_spin_unlock_irqrestore+0xe/0x44
[ 9.612000] __alloc_object+0xaa/0x19c
[ 9.612000] memset+0x0/0x8c
[ 9.612000] __kmalloc_noprof+0xb0/0x1c0
[ 9.612000] memset+0x0/0x8c
[ 9.612000] _kzalloc_noprof.constprop.0+0xc/0x1c
[ 9.612000] usb_get_configuration+0x12c/0x11d8
[ 9.612000] usb_get_configuration+0x12c/0x11d8
[ 9.612000] _kzalloc_noprof.constprop.0+0x0/0x1c
[ 9.612000] set_next_task_fair+0x190/0x350
[ 9.612000] __schedule+0x5aa/0x6bc
[ 9.612000] _raw_spin_lock_irqsave+0x20/0x38
[ 9.612000] _raw_spin_unlock_irqrestore+0xe/0x44
[ 9.612000] __try_to_del_timer_sync+0x4a/0x88
[ 9.612000] Slab 0x9ff41980 objects=32 used=6 fp=0x820cc320 flags=0x40000200(workingset|section=16|zone=0)
[ 9.612000] Object 0x820cc220 @offset=544 fp=0x820cc2a0
[ 9.612000]
[ 9.612000] Redzone 820cc200: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................
[ 9.612000] Redzone 820cc210: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................
[ 9.612000] Object 820cc220: 09 02 20 00 01 01 00 80 fa 09 cc cc cc cc cc cc .. .............
[ 9.612000] Object 820cc230: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................
[ 9.612000] Redzone 820cc240: cc cc cc cc ....
[ 9.612000] Padding 820cc274: 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a ZZZZZZZZZZZZ
[ 9.612000] Disabling lock debugging due to kernel taint
[ 9.612000] ------------[ cut here ]------------
[ 9.612000] WARNING: mm/slub.c:1257 at object_err+0x46/0x158, CPU#0: kworker/0:1/10
[ 9.612000] Modules linked in:
[ 9.612000]
[ 9.612000] CPU: 0 UID: 0 PID: 10 Comm: kworker/0:1 Tainted: G B 7.3.0-rc5-00002-g02d53450ebff #3 PREEMPT
[ 9.612000] Tainted: [B]=BAD_PAGE
[ 9.612000] Workqueue: usb_hub_wq hub_event
[ 9.612000] PC is at object_err+0x46/0x158
[ 9.612000] PR is at object_err+0x46/0x158
[ 9.612000] PC : 80004e3a SP : 810cdc20 SR : 400081f1 TEA : c00d0008
[ 9.612000] R0 : 00000020 R1 : 8074959c R2 : 00000000 R3 : 00000020
[ 9.612000] R4 : 00000001 R5 : ff623224 R6 : 00000000 R7 : 00000000
[ 9.612000] R8 : 810023e0 R9 : 820cc220 R10 : 00000054 R11 : 80004d48
[ 9.612000] R12 : 0000808f R13 : 80004bd4 R14 : 810cdc20
[ 9.612000] MACH: 0000003d MACL: 0002bfa8 GBR : 2958a4c0 PR : 80004e3a
[ 9.612000]
[ 9.612000] Call trace:
[ 9.612000] [<800ff6d2>] check_bytes_and_report+0xa2/0xfc
[ 9.612000] [<800ff7d2>] check_object+0xa6/0x204
[ 9.612000] [<800ff630>] check_bytes_and_report+0x0/0xfc
[ 9.612000] [<80100222>] free_to_partial_list+0x9a/0x2b8
[ 9.612000] [<800788da>] __timer_delete_sync+0x2a/0x50
[ 9.612000] [<80078810>] __try_to_del_timer_sync+0x0/0x88
[ 9.612000] [<8007890c>] timer_delete_sync+0xc/0x18
[ 9.612000] [<8010048a>] __slab_free+0x4a/0x19c
[ 9.612000] [<80009264>] _dev_notice+0x0/0x5c
[ 9.612000] [<8032b516>] usb_get_configuration+0x1a2/0x11d8
[ 9.612000] [<80112d28>] delete_object_full+0x40/0x68
[ 9.612000] [<80101bf6>] kfree+0x112/0x1a4
[ 9.612000] [<80009264>] _dev_notice+0x0/0x5c
[ 9.612000] [<8032b516>] usb_get_configuration+0x1a2/0x11d8
[ 9.612000] [<8032b516>] usb_get_configuration+0x1a2/0x11d8
[ 9.612000] [<8032b516>] usb_get_configuration+0x1a2/0x11d8
[ 9.612000] [<80009264>] _dev_notice+0x0/0x5c
[ 9.612000] [<80044ec0>] set_next_task_fair+0x190/0x350
[ 9.612000] [<800788da>] __timer_delete_sync+0x2a/0x50
[ 9.612000] [<80078810>] __try_to_del_timer_sync+0x0/0x88
[ 9.612000] [<8007890c>] timer_delete_sync+0xc/0x18
[ 9.612000] [<80492f70>] schedule_timeout+0x98/0xe4
[ 9.612000] [<80323842>] usb_new_device+0x46/0x2ac
[ 9.612000] [<80493014>] schedule_timeout_uninterruptible+0x14/0x20
[ 9.612000] [<803248c0>] hub_event+0xbf0/0xdf4
[ 9.612000] [<8025657c>] _find_next_zero_bit+0x0/0x6c
[ 9.612000] [<80493756>] _raw_spin_unlock_bh+0x16/0x2c
[ 9.612000] [<80323360>] hub_init_func3+0x10/0x20
[ 9.612000] [<8002f084>] process_scheduled_works+0x148/0x25c
[ 9.612000] [<80030638>] wq_worker_sleeping+0x14/0x88
[ 9.612000] [<8002ccca>] assign_work+0x6c/0x82
[ 9.612000] [<8002f358>] worker_thread+0xe4/0x1a8
[ 9.612000] [<80493b98>] _raw_spin_lock_irq+0x0/0x34
[ 9.612000] [<8002cc5e>] assign_work+0x0/0x82
[ 9.612000] [<80036168>] kthread+0xdc/0x114
[ 9.612000] [<8002f274>] worker_thread+0x0/0x1a8
[ 9.612000] [<8001d45c>] do_exit+0x0/0x798
[ 9.612000] [<80010200>] ret_from_kernel_thread+0xc/0x14
[ 9.612000] [<8003f0c4>] schedule_tail+0x0/0x78
[ 9.612000] [<8003608c>] kthread+0x0/0x114
[ 9.612000]
[ 9.612000] ---[ end trace 0000000000000000 ]---
[ 9.612000] FIX kmalloc-32: Restoring kmalloc Redzone 0x820cc229-0x820cc229=0xcc
[ 9.612000] FIX kmalloc-32: Object at 0x820cc220 not freed
[ 10.528000] kmemleak: Kernel memory leak detector initialized (mem pool available: 15907)
[ 10.536000] kmemleak: Automatic memory scanning thread started
Are you sure your patch actually fixes this problem?
Or do I maybe need a cold reboot?
Adrian
--
.''`. John Paul Adrian Glaubitz
: :' : Debian Developer
`. `' Physicist
`- GPG: 62FF 8A75 84E0 2956 9546 0006 7426 3B37 F5B5 F913
^ permalink raw reply [flat|nested] 17+ messages in thread* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-10-02 4:57 ` John Paul Adrian Glaubitz
@ 2026-10-02 21:58 ` Karl Mehltretter
2026-10-03 6:53 ` John Paul Adrian Glaubitz
0 siblings, 1 reply; 17+ messages in thread
From: Karl Mehltretter @ 2026-10-02 21:58 UTC (permalink / raw)
To: John Paul Adrian Glaubitz
Cc: Yoshinori Sato, Rich Felker, linux-sh, linux-kernel
On Fri, Oct 02, 2026 at 06:57:19AM +0100, John Paul Adrian Glaubitz wrote:
> I just booted the kernel with slub_debug=FZPU on my SH-7785LCR EVB and
> I'm getting the following "kmalloc Redzone overwritten" warning in both
> cases.
>
Hi Adrian,
thanks for testing. A cold reboot is not needed. The reported object was
allocated by usb_get_configuration(), so this warning is unrelated to the
INTC patch.
I sent a fix for the USB R8A66597 bug and copied you:
https://lore.kernel.org/r/20261002213225.27834-1-kmehltretter@gmail.com/
> Are you sure your patch actually fixes this problem?
>
> Or do I maybe need a cold reboot?
A cold reboot is not needed.
The INTC allocation remains live after boot, so SLUB does not necessarily
check its redzone automatically. To check it explicitly after boot, run:
echo 1 > /sys/kernel/slab/kmalloc-32/validate
Could you please test once with only the USB patch and once with both
patches, using slub_debug=FZPU and running that command after each boot?
Thanks,
Karl
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-10-02 21:58 ` Karl Mehltretter
@ 2026-10-03 6:53 ` John Paul Adrian Glaubitz
0 siblings, 0 replies; 17+ messages in thread
From: John Paul Adrian Glaubitz @ 2026-10-03 6:53 UTC (permalink / raw)
To: Karl Mehltretter; +Cc: Yoshinori Sato, Rich Felker, linux-sh, linux-kernel
Hi,
On Fri, 2026-10-02 at 23:58 +0200, Karl Mehltretter wrote:
> thanks for testing. A cold reboot is not needed. The reported object was
> allocated by usb_get_configuration(), so this warning is unrelated to the
> INTC patch.
OK, so how do I reproduce the INTC issue?
> I sent a fix for the USB R8A66597 bug and copied you:
>
> https://lore.kernel.org/r/20261002213225.27834-1-kmehltretter@gmail.com/
Let me check.
> > Are you sure your patch actually fixes this problem?
> >
> > Or do I maybe need a cold reboot?
>
> A cold reboot is not needed.
>
> The INTC allocation remains live after boot, so SLUB does not necessarily
> check its redzone automatically. To check it explicitly after boot, run:
>
> echo 1 > /sys/kernel/slab/kmalloc-32/validate
So, running the validation should trigger the INTC issue on an unpatched kernel?
> Could you please test once with only the USB patch and once with both
> patches, using slub_debug=FZPU and running that command after each boot?
I'll test the USB patch first and see if that fixes the issue when booting
with slub_debug=FZPU. Then test the INTC issue with the command above.
Adrian
--
.''`. John Paul Adrian Glaubitz
: :' : Debian Developer
`. `' Physicist
`- GPG: 62FF 8A75 84E0 2956 9546 0006 7426 3B37 F5B5 F913
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH] sh: intc: sort the prio and sense lists after filling them
2026-09-27 19:13 [PATCH] sh: intc: sort the prio and sense lists after filling them Karl Mehltretter
` (2 preceding siblings ...)
2026-10-02 4:57 ` John Paul Adrian Glaubitz
@ 2026-10-03 7:51 ` John Paul Adrian Glaubitz
3 siblings, 0 replies; 17+ messages in thread
From: John Paul Adrian Glaubitz @ 2026-10-03 7:51 UTC (permalink / raw)
To: Karl Mehltretter, Yoshinori Sato, Rich Felker; +Cc: linux-sh, linux-kernel
On Sun, 2026-09-27 at 21:13 +0200, Karl Mehltretter wrote:
> register_intc_controller() sorts d->prio and d->sense right after
> allocating them, with hw->nr_prio_regs and hw->nr_sense_regs as the
> element count. The lists hold hw->nr_vectors entries and are only
> filled later, by intc_register_irq().
>
> On SH7785, sh7785-irq0123 and sh7785-irq4567 have four vectors but the
> SoC's eleven priority registers, so sort() swaps 88 bytes in a 32 byte
> kmalloc object at boot. slub_debug=FZPU reports "Right Redzone
> overwritten" in kmalloc-32, and v6.5 and v6.6 panic in
> __kmem_cache_alloc_node() while registering sh7785-irq0123.
>
> Found with a custom QEMU model of the SH7785LCR. On it, v6.4
> sh7785lcr_defconfig boots with SLAB, the defconfig default before v6.5,
> and hangs before the console is up when built with SLUB.
>
> Sort the lists once all vectors are registered, with the number of
> entries that were added.
>
> Fixes: b59f9f9775e6 ("sh: intc: optimize intc IRQ lookup")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
> ---
>
> Notes:
> Testing, all in QEMU on a custom SH7785LCR model, not on hardware:
> - v6.5 and v6.6 sh7785lcr_defconfig hang before the console is up
> (gcc 8 and gcc 14). With slub_debug=FZPU they boot and validating
> kmalloc-32 reports "Right Redzone overwritten" after the object
> holding the entries of sh7785-irq4567. With this patch they boot
> and the report is gone.
> - v6.4 sh7785lcr_defconfig (SLAB) boots. The same v6.4 built with SLUB
> hangs, reports the overflow with slub_debug=FZPU, and boots with
> this patch.
> - Current mainline boots with or without the patch, but reports the
> overflow with slub_debug=FZPU unless patched.
> Testing on real hardware is welcome.
>
> drivers/sh/intc/core.c | 11 +++++------
> 1 file changed, 5 insertions(+), 6 deletions(-)
>
> diff --git a/drivers/sh/intc/core.c b/drivers/sh/intc/core.c
> index aa68fe190865d..ffbe60234eefc 100644
> --- a/drivers/sh/intc/core.c
> +++ b/drivers/sh/intc/core.c
> @@ -275,9 +275,6 @@ int __init register_intc_controller(struct intc_desc *desc)
> k += save_reg(d, k, hw->prio_regs[i].set_reg, smp);
> k += save_reg(d, k, hw->prio_regs[i].clr_reg, smp);
> }
> -
> - sort(d->prio, hw->nr_prio_regs, sizeof(*d->prio),
> - intc_handle_int_cmp, NULL);
> }
>
> if (hw->sense_regs) {
> @@ -287,9 +284,6 @@ int __init register_intc_controller(struct intc_desc *desc)
>
> for (i = 0; i < hw->nr_sense_regs; i++)
> k += save_reg(d, k, hw->sense_regs[i].reg, 0);
> -
> - sort(d->sense, hw->nr_sense_regs, sizeof(*d->sense),
> - intc_handle_int_cmp, NULL);
> }
>
> if (hw->subgroups)
> @@ -357,6 +351,11 @@ int __init register_intc_controller(struct intc_desc *desc)
> }
> }
>
> + sort(d->prio, d->nr_prio, sizeof(*d->prio),
> + intc_handle_int_cmp, NULL);
> + sort(d->sense, d->nr_sense, sizeof(*d->sense),
> + intc_handle_int_cmp, NULL);
> +
> intc_subgroup_init(desc, d);
>
> /* enable bits matching force_enable after registering irqs */
Without the patch, a memory leak is reported when booting with slub_debug=FZPU
triggering a validation manually after boot:
root@tirpitz:~> echo 1 > /sys/kernel/slab/kmalloc-32/validate
[ 181.568000] [Right Redzone overwritten] 0x810245c0-0x810245c3 @offset=1472. First byte 0x0 instead of 0xcc
[ 181.568000] =============================================================================
[ 181.568000] BUG kmalloc-32 (Not tainted): Object corrupt
[ 181.568000] -----------------------------------------------------------------------------
[ 181.568000]
[ 181.568000] Slab 0x9ff20480 objects=32 used=32 fp=0x00000000 flags=0x40000000(section=16|zone=0)
[ 181.568000] Object 0x810245a0 @offset=1440 fp=0x00000000
[ 181.568000]
[ 181.568000] Redzone 81024580: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................
[ 181.568000] Redzone 81024590: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................
[ 181.568000] Object 810245a0: 1a 00 00 00 8c 78 06 06 1c 00 00 00 88 78 06 06 .....x.......x..
[ 181.568000] Object 810245b0: 1e 00 00 00 84 78 06 06 10 00 00 00 80 78 06 06 .....x.......x..
[ 181.568000] Redzone 810245c0: 00 00 00 00 ....
[ 181.568000] Padding 810245f4: 00 00 00 00 5a 5a 5a 5a 5a 5a 5a 5a ....ZZZZZZZZ
[ 181.568000] Disabling lock debugging due to kernel taint
[ 181.568000] ------------[ cut here ]------------
[ 181.568000] WARNING: mm/slub.c:1257 at object_err+0x46/0x158, CPU#0: bash/970
[ 181.568000] Modules linked in:
[ 181.568000]
[ 181.568000] CPU: 0 UID: 0 PID: 970 Comm: bash Tainted: G B 7.3.0-rc5-00341-gf6dfa8891d61 #7 PREEMPT
[ 181.568000] Tainted: [B]=BAD_PAGE
[ 181.568000] PC is at object_err+0x46/0x158
[ 181.568000] PR is at object_err+0x46/0x158
[ 181.568000] PC : 80004e3a SP : 86051dcc SR : 400081f1 TEA : c0000010
[ 181.568000] R0 : 00000020 R1 : 8074959c R2 : 00000000 R3 : 00000020
[ 181.568000] R4 : 806becb0 R5 : fa69f078 R6 : 00000000 R7 : 00000000
[ 181.568000] R8 : 810023e0 R9 : 810245a0 R10 : 00000054 R11 : 80004d48
[ 181.568000] R12 : 0000808f R13 : 80004bd4 R14 : 86051dcc
[ 181.568000] MACH: 00000038 MACL: 0002bfa8 GBR : 2957b860 PR : 80004e3a
[ 181.568000]
[ 181.568000] Call trace:
[ 181.568000] [<800ff726>] check_bytes_and_report+0xa2/0xfc
[ 181.568000] [<800ff7e8>] check_object+0x68/0x204
[ 181.568000] [<800ff684>] check_bytes_and_report+0x0/0xfc
[ 181.568000] [<800ffafe>] validate_slab+0xbe/0xf4
[ 181.568000] [<800ffc12>] validate_slab_cache+0xde/0x114
[ 181.568000] [<800ffa40>] validate_slab+0x0/0xf4
[ 181.568000] [<800ffc7e>] validate_store+0x36/0x48
[ 181.568000] [<800fcd82>] slab_attr_store+0x1a/0x22
[ 181.568000] [<80185fcc>] sysfs_kf_write+0x3c/0x58
[ 181.568000] [<80185670>] kernfs_fop_write_iter+0xe6/0x136
[ 181.568000] [<801188b8>] vfs_write+0xd0/0x138
[ 181.568000] [<80118a56>] ksys_write+0x62/0xbc
[ 181.568000] [<80118aba>] sys_write+0xa/0x18
[ 181.568000] [<80118ab0>] sys_write+0x0/0x18
[ 181.568000] [<8001025a>] syscall_call+0x18/0x1e
[ 181.568000]
[ 181.568000] ---[ end trace 0000000000000000 ]---
[ 181.568000] FIX kmalloc-32: Restoring Right Redzone 0x810245c0-0x810245c3=0xcc
[ 181.568000] [Object padding overwritten] 0x810245f4-0x810245f7 @offset=1524. First byte 0x0 instead of 0x5a
[ 181.568000] =============================================================================
[ 181.568000] BUG kmalloc-32 (Tainted: G B W ): Object corrupt
[ 181.568000] -----------------------------------------------------------------------------
[ 181.568000]
[ 181.568000] Slab 0x9ff20480 objects=32 used=32 fp=0x00000000 flags=0x40000000(section=16|zone=0)
[ 181.568000] Object 0x810245a0 @offset=1440 fp=0x00000000
[ 181.568000]
[ 181.568000] Redzone 81024580: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................
[ 181.568000] Redzone 81024590: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................
[ 181.568000] Object 810245a0: 1a 00 00 00 8c 78 06 06 1c 00 00 00 88 78 06 06 .....x.......x..
[ 181.568000] Object 810245b0: 1e 00 00 00 84 78 06 06 10 00 00 00 80 78 06 06 .....x.......x..
[ 181.568000] Redzone 810245c0: cc cc cc cc ....
[ 181.568000] Padding 810245f4: 00 00 00 00 5a 5a 5a 5a 5a 5a 5a 5a ....ZZZZZZZZ
[ 181.568000] ------------[ cut here ]------------
[ 181.568000] WARNING: mm/slub.c:1257 at object_err+0x46/0x158, CPU#0: bash/970
[ 181.568000] Modules linked in:
[ 181.568000]
[ 181.568000] CPU: 0 UID: 0 PID: 970 Comm: bash Tainted: G B W 7.3.0-rc5-00341-gf6dfa8891d61 #7 PREEMPT
[ 181.568000] Tainted: [B]=BAD_PAGE, [W]=WARN
[ 181.568000] PC is at object_err+0x46/0x158
[ 181.568000] PR is at object_err+0x46/0x158
[ 181.568000] PC : 80004e3a SP : 86051dcc SR : 400081f1 TEA : c0000010
[ 181.568000] R0 : 00000220 R1 : 8074959c R2 : 00000000 R3 : 00000220
[ 181.568000] R4 : 00000005 R5 : 00000001 R6 : 00000000 R7 : 00000000
[ 181.568000] R8 : 810023e0 R9 : 810245a0 R10 : 00000054 R11 : 80004d48
[ 181.568000] R12 : 0000808f R13 : 80004bd4 R14 : 86051dcc
[ 181.568000] MACH: 00000038 MACL: 0002bfa8 GBR : 2957b860 PR : 80004e3a
[ 181.568000]
[ 181.568000] Call trace:
[ 181.568000] [<800ff726>] check_bytes_and_report+0xa2/0xfc
[ 181.568000] [<800ff8ce>] check_object+0x14e/0x204
[ 181.568000] [<800ff684>] check_bytes_and_report+0x0/0xfc
[ 181.568000] [<800ffafe>] validate_slab+0xbe/0xf4
[ 181.568000] [<800ffc12>] validate_slab_cache+0xde/0x114
[ 181.568000] [<800ffa40>] validate_slab+0x0/0xf4
[ 181.568000] [<800ffc7e>] validate_store+0x36/0x48
[ 181.568000] [<800fcd82>] slab_attr_store+0x1a/0x22
[ 181.568000] [<80185fcc>] sysfs_kf_write+0x3c/0x58
[ 181.568000] [<80185670>] kernfs_fop_write_iter+0xe6/0x136
[ 181.568000] [<801188b8>] vfs_write+0xd0/0x138
[ 181.568000] [<80118a56>] ksys_write+0x62/0xbc
[ 181.568000] [<80118aba>] sys_write+0xa/0x18
[ 181.568000] [<80118ab0>] sys_write+0x0/0x18
[ 181.568000] [<8001025a>] syscall_call+0x18/0x1e
[ 181.568000]
[ 181.568000] ---[ end trace 0000000000000000 ]---
[ 181.568000] FIX kmalloc-32: Restoring Object padding 0x810245f4-0x810245f7=0x5a
root@tirpitz:~>
With the patch applied, no leak is reported after validation:
root@tirpitz:~> echo 1 > /sys/kernel/slab/kmalloc-32/validate
root@tirpitz:~>
Tested-by: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
Adrian
--
.''`. John Paul Adrian Glaubitz
: :' : Debian Developer
`. `' Physicist
`- GPG: 62FF 8A75 84E0 2956 9546 0006 7426 3B37 F5B5 F913
^ permalink raw reply [flat|nested] 17+ messages in thread