Skip to content

Commit e66ed13

Browse files
shroffnigregkh
authored andcommitted
powerpc/xive: fix kmemleak caused by incorrect chip_data lookup
commit 6771c54 upstream. The kmemleak reports the following memory leak: Unreferenced object 0xc0000002a7fbc640 (size 64): comm "kworker/8:1", pid 540, jiffies 4294937872 hex dump (first 32 bytes): 01 00 00 00 00 00 00 00 00 00 09 04 00 04 00 00 ................ 00 00 a7 81 00 00 0a c0 00 00 08 04 00 04 00 00 ................ backtrace (crc 177d48f6): __kmalloc_cache_noprof+0x520/0x730 xive_irq_alloc_data.constprop.0+0x40/0xe0 xive_irq_domain_alloc+0xd0/0x1b0 irq_domain_alloc_irqs_parent+0x44/0x6c pseries_irq_domain_alloc+0x1cc/0x354 irq_domain_alloc_irqs_parent+0x44/0x6c msi_domain_alloc+0xb0/0x220 irq_domain_alloc_irqs_locked+0x138/0x4d0 __irq_domain_alloc_irqs+0x8c/0xfc __msi_domain_alloc_irqs+0x214/0x4d8 msi_domain_alloc_irqs_all_locked+0x70/0xf8 pci_msi_setup_msi_irqs+0x60/0x78 __pci_enable_msix_range+0x54c/0x98c pci_alloc_irq_vectors_affinity+0x16c/0x1d4 nvme_pci_enable+0xac/0x9c0 [nvme] nvme_probe+0x340/0x764 [nvme] This occurs when allocating MSI-X vectors for an NVMe device. During allocation the XIVE code creates a struct xive_irq_data and stores it in irq_data->chip_data. When the MSI-X irqdomain is later freed, xive_irq_free_data() is responsible for retrieving this structure and freeing it. However, after commit cc0cc23 ("powerpc/xive: Untangle xive from child interrupt controller drivers"), xive_irq_free_data() retrieves the chip_data using irq_get_chip_data(), which looks up the data through the child domain. This is incorrect because the XIVE-specific irq data is associated with the XIVE (parent) domain. As a result the lookup fails and the allocated struct xive_irq_data is never freed, leading to the kmemleak report shown above. Fix this by retrieving the irq_data from the correct domain using irq_domain_get_irq_data() and then accessing the chip_data via irq_data_get_irq_chip_data(). Cc: stable@vger.kernel.org Fixes: cc0cc23 ("powerpc/xive: Untangle xive from child interrupt controller drivers") Signed-off-by: Nilay Shroff <nilay@linux.ibm.com> Tested-by: Venkat Rao Bagalkote <venkat88@linux.ibm.com> Reviewed-by: Nam Cao <namcao@linutronix.de> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260311134336.326996-1-nilay@linux.ibm.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 315f0dc commit e66ed13

1 file changed

Lines changed: 11 additions & 5 deletions

File tree

arch/powerpc/sysdev/xive/common.c

Lines changed: 11 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1038,13 +1038,19 @@ static struct xive_irq_data *xive_irq_alloc_data(unsigned int virq, irq_hw_numbe
10381038
return xd;
10391039
}
10401040

1041-
static void xive_irq_free_data(unsigned int virq)
1041+
static void xive_irq_free_data(struct irq_domain *domain, unsigned int virq)
10421042
{
1043-
struct xive_irq_data *xd = irq_get_chip_data(virq);
1043+
struct xive_irq_data *xd;
1044+
struct irq_data *data = irq_domain_get_irq_data(domain, virq);
1045+
1046+
if (!data)
1047+
return;
10441048

1049+
xd = irq_data_get_irq_chip_data(data);
10451050
if (!xd)
10461051
return;
1047-
irq_set_chip_data(virq, NULL);
1052+
1053+
irq_domain_reset_irq_data(data);
10481054
xive_cleanup_irq_data(xd);
10491055
kfree(xd);
10501056
}
@@ -1305,7 +1311,7 @@ static int xive_irq_domain_map(struct irq_domain *h, unsigned int virq,
13051311

13061312
static void xive_irq_domain_unmap(struct irq_domain *d, unsigned int virq)
13071313
{
1308-
xive_irq_free_data(virq);
1314+
xive_irq_free_data(d, virq);
13091315
}
13101316

13111317
static int xive_irq_domain_xlate(struct irq_domain *h, struct device_node *ct,
@@ -1443,7 +1449,7 @@ static void xive_irq_domain_free(struct irq_domain *domain,
14431449
pr_debug("%s %d #%d\n", __func__, virq, nr_irqs);
14441450

14451451
for (i = 0; i < nr_irqs; i++)
1446-
xive_irq_free_data(virq + i);
1452+
xive_irq_free_data(domain, virq + i);
14471453
}
14481454
#endif
14491455

0 commit comments

Comments
 (0)