From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f176.google.com (mail-pf1-f176.google.com [209.85.210.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 440413033E8 for ; Fri, 1 May 2026 04:12:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.176 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777608741; cv=none; b=e4dKvXSTXBHyg2l62/wnE+VYRiWy4bHh6Er5yh+3Nrh4rzfVBL1l3BgJh5JLiVfNiqa6kxBZlBQUr/Ea4sz5bcutNYUcoAxmeQN+lkhDNHx70mbHwnGqHO9lme2gNXkfW/gdZm+oX1ZeCO4HSwTsjiRgNFhYiT/aCgR8JVUMIZU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777608741; c=relaxed/simple; bh=9NbnFzTEGh6+lE1PwksEW7af7i8jzYb/dCKoYyURmxQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=nRv7cuOxtReXa1cYNqCiDKdwO0pvjh+Vd8IM6c5fSN6wXwTRvqYWuYVZ3LV7sx7xrgGQuV6KstRPNehDgBUqY6ksM0R4hKwjCBLyL9u9F0GjpjM9agvPJUGN7bLvBMLVmKwOzZnSnIiasxhxbQn8VLNtgMb87+rwInoxfc7pyE8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=WflBnlVV; arc=none smtp.client-ip=209.85.210.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="WflBnlVV" Received: by mail-pf1-f176.google.com with SMTP id d2e1a72fcca58-827270d50d4so1556293b3a.3 for ; Thu, 30 Apr 2026 21:12:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1777608740; x=1778213540; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=PYNm6J9AhUQ6HT8V6B6W7Iuh7E+aasxrExqJ2exyz7U=; b=WflBnlVVLpYKdqZ5+gvI7bTslgdtAUNJ8HJNO541GdBxHGlR1YHd8uBzDm1zAf4oZV nkxZRbPocjasqAZWQ94rZg1CKbKbaVGjKdmA23rmemQIekV6OBdXP+W1WjEIl0LR9eHF 2BjVGuLtvP/CuA034+o7zFdRfHFs9PeJBJMyMHjjninSBID1QP6bjOIM9jRO0IHwn7Ix hmnSJlbMcC4Th5v7+BJiy9cgmAvfClMRQ4LtWeTlf8nUyz2DrHM6Cwr+l4BtgOt7epCt SFp5s916/tW9oSYDO3cxIotZFjU+Z9b4yxed38Nz10xDjsGHbup9lwNWrNyXjNe30uL+ ai6w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1777608740; x=1778213540; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=PYNm6J9AhUQ6HT8V6B6W7Iuh7E+aasxrExqJ2exyz7U=; b=EZVonSMLARB2WnhZRgPq5cn+nSg7TDb+pJcIa+RwPcHWjWq/wIxxw/m0Il7bNLLh5u 9nqP7HPem5GjvfRaLukxFLPnEBN94tYl1ub8BflVmwPM6KR1TkU1dnlwNk1b6kPb+OhS AxFJ8R5emV8oW5dd+If7Sc8qSNUNEUkVd7ZYsd20AMVl5Bw2mCqF3q1W4qk4Ueu1ddSL pNZ3lAz/IT1XnRzjnJroXybMqcc6yngXjf+KZMoeoSbDgHFKvgeaBMa9UGwia17Tscz+ Rn3ckHU4WcVMumBjdfKDNY/CulaNE/XIqUOjEGUifqZAYtSc0cHa+fes90wPL6bY3arB kjZA== X-Forwarded-Encrypted: i=1; AFNElJ9sJjXfaN4XqH3uCs7iNZCnJrZf3DmFTuQoUajjCAPz6Qj5C16M/qdPIPGOC/v4G0gBDa0X5lL3zjR0rtk=@vger.kernel.org X-Gm-Message-State: AOJu0Yx4BmHUOQph6cvjHUvyhuk4MR6gCmab0Rd2AK62M/Gn/iNh4GbH LXU/PB/+Q0wq5F3bYU2ZNtNK38O4Nqr6jCnRRMo6iQDyZNiYfH5+z0Nz X-Gm-Gg: AeBDievIkI04+98WzuQNwWeq34Gb/aERzrKmbGGo7DILvXf4pCtqPyPW+CAUaaaplw6 QLC8ZFMe6atT1p+3VXhbNZ+fhuzXRdk2hwG7dxQni7UspLfB0wvoIoIfGtEd5HswarSHo5/sLk/ TFxKf00So7HAAFQrz9z16zxzdOjLSNDCk3em7zRXk1zMfh9xhOLnfZnT5gEmU0nuxslpU3SQp7e yPhw9g/zm8nRnawLRmQzDEFOsXBCxeBSBArDaAI/vJdRp7tSHtu9igffPSnIyU4Si8OVkf3QWAq oThTxYf9SrZnX8Gecdlq8c0bO8M53TvBQzW4cReFvzKUHr1Xi8zpyoTqo4as5A4ULChPDh0xcwM djS97Qb4vufaqt9JIuRx1NQuAun3R7wEfpYbNcTR2Ix0WFLQ2bBr1gbEnlEZmd1R48eLJ5q/q5P ImzxWfNn8+zdHaqO+v2oWP14gLI8JoErT278ty1TnT9gKzaoxpLmh++MOF7P4uF0o= X-Received: by 2002:a05:6a00:1c9e:b0:824:adf4:5a2f with SMTP id d2e1a72fcca58-834fdc5c2admr6357028b3a.43.1777608739583; Thu, 30 Apr 2026 21:12:19 -0700 (PDT) Received: from localhost.localdomain ([49.205.216.49]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-83515b485eesm1159428b3a.48.2026.04.30.21.12.15 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Thu, 30 Apr 2026 21:12:18 -0700 (PDT) From: "Ritesh Harjani (IBM)" To: linuxppc-dev@lists.ozlabs.org, Haren Myneni Cc: Madhavan Srinivasan , Christophe Leroy , Venkat Rao Bagalkote , Nicholas Piggin , linux-kernel@vger.kernel.org, "Ritesh Harjani (IBM)" , stable@vger.kernel.org Subject: [PATCH v3 1/9] pseries/papr-hvpipe: Fix race with interrupt handler Date: Fri, 1 May 2026 09:41:40 +0530 Message-ID: X-Mailer: git-send-email 2.50.1 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit While executing ->ioctl handler or ->release handler, if an interrupt fires on the same cpu, then we can enter into a deadlock. This patch fixes both these handlers to take spin_lock_irq{save|restore} versions of the lock to prevent this deadlock. Cc: stable@vger.kernel.org Fixes: 814ef095f12c9 ("powerpc/pseries: Add papr-hvpipe char driver for HVPIPE interfaces") Signed-off-by: Ritesh Harjani (IBM) --- arch/powerpc/platforms/pseries/papr-hvpipe.c | 20 +++++++++++--------- 1 file changed, 11 insertions(+), 9 deletions(-) diff --git a/arch/powerpc/platforms/pseries/papr-hvpipe.c b/arch/powerpc/platforms/pseries/papr-hvpipe.c index 14ae480d060a..c41d45e1986d 100644 --- a/arch/powerpc/platforms/pseries/papr-hvpipe.c +++ b/arch/powerpc/platforms/pseries/papr-hvpipe.c @@ -444,13 +444,14 @@ static int papr_hvpipe_handle_release(struct inode *inode, struct file *file) { struct hvpipe_source_info *src_info; + unsigned long flags; /* * Hold the lock, remove source from src_list, reset the * hvpipe status and release the lock to prevent any race * with message event IRQ. */ - spin_lock(&hvpipe_src_list_lock); + spin_lock_irqsave(&hvpipe_src_list_lock, flags); src_info = file->private_data; list_del(&src_info->list); file->private_data = NULL; @@ -461,10 +462,10 @@ static int papr_hvpipe_handle_release(struct inode *inode, */ if (src_info->hvpipe_status & HVPIPE_MSG_AVAILABLE) { src_info->hvpipe_status = 0; - spin_unlock(&hvpipe_src_list_lock); + spin_unlock_irqrestore(&hvpipe_src_list_lock, flags); hvpipe_rtas_recv_msg(NULL, 0); } else - spin_unlock(&hvpipe_src_list_lock); + spin_unlock_irqrestore(&hvpipe_src_list_lock, flags); kfree(src_info); return 0; @@ -480,20 +481,21 @@ static const struct file_operations papr_hvpipe_handle_ops = { static int papr_hvpipe_dev_create_handle(u32 srcID) { struct hvpipe_source_info *src_info __free(kfree) = NULL; + unsigned long flags; - spin_lock(&hvpipe_src_list_lock); + spin_lock_irqsave(&hvpipe_src_list_lock, flags); /* * Do not allow more than one process communicates with * each source. */ src_info = hvpipe_find_source(srcID); if (src_info) { - spin_unlock(&hvpipe_src_list_lock); + spin_unlock_irqrestore(&hvpipe_src_list_lock, flags); pr_err("pid(%d) is already using the source(%d)\n", src_info->tsk->pid, srcID); return -EALREADY; } - spin_unlock(&hvpipe_src_list_lock); + spin_unlock_irqrestore(&hvpipe_src_list_lock, flags); src_info = kzalloc_obj(*src_info, GFP_KERNEL_ACCOUNT); if (!src_info) @@ -510,18 +512,18 @@ static int papr_hvpipe_dev_create_handle(u32 srcID) return fdf.err; retain_and_null_ptr(src_info); - spin_lock(&hvpipe_src_list_lock); + spin_lock_irqsave(&hvpipe_src_list_lock, flags); /* * If two processes are executing ioctl() for the same * source ID concurrently, prevent the second process to * acquire FD. */ if (hvpipe_find_source(srcID)) { - spin_unlock(&hvpipe_src_list_lock); + spin_unlock_irqrestore(&hvpipe_src_list_lock, flags); return -EALREADY; } list_add(&src_info->list, &hvpipe_src_list); - spin_unlock(&hvpipe_src_list_lock); + spin_unlock_irqrestore(&hvpipe_src_list_lock, flags); return fd_publish(fdf); } -- 2.39.5