[PATCH v2 0/3] xen/arm: Fix eSPI IRQ handling

Mykola Kvach posted 3 patches 2 days, 13 hours ago
Patches applied successfully (tree, apply log)
git fetch https://gitlab.com/xen-project/patchew/xen tags/patchew/cover.1786385827.git.mykola._5Fkvach@epam.com
xen/arch/arm/gic-v2.c        |  8 ++++++--
xen/arch/arm/gic-v3.c        |  8 ++++++--
xen/arch/arm/irq.c           | 29 ++++++++++++++++++++++++-----
xen/arch/arm/tee/ffa_notif.c | 11 ++++++++++-
xen/arch/arm/time.c          | 18 ++++++++++++++----
xen/arch/arm/vgic.c          | 25 ++++++++++++++-----------
xen/drivers/char/ns16550.c   |  5 ++++-
xen/drivers/char/pl011.c     |  4 +++-
8 files changed, 81 insertions(+), 27 deletions(-)
[PATCH v2 0/3] xen/arm: Fix eSPI IRQ handling
Posted by Mykola Kvach 2 days, 13 hours ago
This series fixes sparse eSPI INTID handling and checks errors returned by
irq_set_type().

Xen has IRQ descriptors for INTIDs below NR_IRQS and for eSPIs starting at
4096. It has no descriptors for INTIDs 1024 through 4095. Patch 1 checks
INTIDs in setup_irq() and irq_set_spi_type() before these functions look up
a descriptor. irq_set_spi_type() checks descriptor ranges because the GIC
line counts are not known yet. setup_irq() uses the line counts once they
are available.

Patch 2 fixes the vGIC allocation bitmap. Reserving an eSPI used a compact
bitmap index, but freeing it used the raw virtual INTID. This could write
past the bitmap and leave the eSPI reserved.

Patch 3 is new in v2. It checks errors from irq_set_type() in the GTDT,
MADT, SPCR, and FF-A paths. GTDT and MADT could keep a rejected timer or
maintenance INTID and later use it in a direct descriptor lookup. This
patch also fixes MISRA C Rule 17.7 violations.

Tested with:
- Arm64 debug builds with CONFIG_ACPI=y and CONFIG_FFA=y, both with and
  without CONFIG_GICV3_ESPI
- FVP Device Tree boot with 64 eSPIs; Linux dom0 started
- QEMU virt UEFI/ACPI boot to a dom0 initramfs shell; this covered the GTDT,
  GICv3 MADT, and PL011 SPCR paths

Changes in v2:
- Check descriptor ranges in irq_set_spi_type() and implemented GIC lines
  in setup_irq().
- Keep the is_espi() debug check when CONFIG_GICV3_ESPI is disabled.
- Remove a redundant CONFIG_GICV3_ESPI guard from the vGIC code.
- Add patch 3 to check irq_set_type() errors in the GTDT, MADT, SPCR, and
  FF-A paths.
- Target master instead of the 4.22 release.

v1: https://patchew.org/Xen/cover.1783671887.git.mykola._5Fkvach@epam.com/

Mykola Kvach (3):
  xen/arm: validate IRQs before descriptor lookup
  xen/arm: vgic: free eSPIs using the bitmap index
  xen/arm: handle irq_set_type() failures

 xen/arch/arm/gic-v2.c        |  8 ++++++--
 xen/arch/arm/gic-v3.c        |  8 ++++++--
 xen/arch/arm/irq.c           | 29 ++++++++++++++++++++++++-----
 xen/arch/arm/tee/ffa_notif.c | 11 ++++++++++-
 xen/arch/arm/time.c          | 18 ++++++++++++++----
 xen/arch/arm/vgic.c          | 25 ++++++++++++++-----------
 xen/drivers/char/ns16550.c   |  5 ++++-
 xen/drivers/char/pl011.c     |  4 +++-
 8 files changed, 81 insertions(+), 27 deletions(-)

-- 
2.43.0