From nobody Mon Sep 28 17:50:05 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D5197244692; Wed, 19 Aug 2026 08:51:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787129475; cv=none; b=rYYfuiRILXAOgQgZmRCqRmXv8a1p98ddchAwFovbKpbPWJWhD9lhhdcWW52AExf6nLu3/4ptV4R/xSuxMbZwPucmO4qDuqjGbgjDg8fLP5hZojdysEynzafqa63n3QZcSvvaEpM1SOMXNagElfaMOhVsECs2lqSDQaVwRH0lniE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787129475; c=relaxed/simple; bh=WctqrLEAZWzKfYg+EOvKS8CdQ0/iuFD9GoYTN73wdhM=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=lU57Vjt+SN6IvjnTEg/VHjZbPZfic9WYSHLlmwYMD+qK5GK/qm/7/DwQFlrubGJT0xT8dUVi1itmn4JSYwtmhNyKPb3/1nLNKK5RE9W7ye8O+c15+0t7zis8ImQ0vO5eHu1v9pgVRjepOgviPFGSmR5CTcpFy/lwJLXd6IEOk64= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=irGyLVmK; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="irGyLVmK" Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67J6VlEn2666835; Wed, 19 Aug 2026 08:51:13 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=IGeXpM 2K+U9rHRxIh7xZlp7tfxxYPblF6nobaKUiKfY=; b=irGyLVmKNIgGsGg1wvI9X9 NTplPLw9ZCliMZvGi1C32qNy8IeegIgQcu2Ps6QHE3mA/CejoBYY+pM8HBXEkSie 27u4AqHVh0cfxHq+9v1ZJBkqIL691Swej24HReEMWoztdryk6EUr8RJSuaET7JJz oDcZcMvH+cxTcO+DFq6joWsglweYwify8f5ovbgOgLsD7+h9yDNwxG8yIpjLMDjd KJM+Z0YLKOyqhXFDqWRCw4nWCqzBl4nnD/HEcHeIFlv8DLsFqhsOda9cr37ehMf1 MtVTFAjePhtUoSaNTtB0ETsW0rrmVFN0n0C2J9B6EubOYprV6JeoONcuXScnhhBg == Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g4yu0amgy-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2026 08:51:12 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67J8fHVb028355; Wed, 19 Aug 2026 08:51:12 GMT Received: from smtprelay06.fra02v.mail.ibm.com ([9.218.2.230]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4g354yfruc-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2026 08:51:12 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (smtpav05.fra02v.mail.ibm.com [10.20.54.104]) by smtprelay06.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67J8p8rl46006574 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 19 Aug 2026 08:51:08 GMT Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 564B220043; Wed, 19 Aug 2026 08:51:08 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 2095D2004D; Wed, 19 Aug 2026 08:51:08 +0000 (GMT) Received: from [127.0.1.1] (unknown [9.87.85.9]) by smtpav05.fra02v.mail.ibm.com (Postfix) with ESMTP; Wed, 19 Aug 2026 08:51:08 +0000 (GMT) From: Tobias Schumacher Date: Wed, 19 Aug 2026 10:50:54 +0200 Subject: [PATCH 1/7] s390/pci: fix double-free in zpci MSI cleanup Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260819-s390_irq_domain_fixes-v1-1-826ff27b6e97@linux.ibm.com> References: <20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com> In-Reply-To: <20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com> To: Niklas Schnelle , Gerd Bayer , Julian Ruess , Farhan Ali , Christian Borntraeger , Halil Pasic Cc: Heiko Carstens , Vasily Gorbik , Alexander Gordeev , Sven Schnelle , linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, Tobias Schumacher , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=MthiLWae c=1 sm=1 tr=0 ts=6a856e81 cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=n6EUqp7IjLKcVj1b1CMA:9 a=QEXdDO2ut3YA:10 X-Proofpoint-ORIG-GUID: Cr771B-kUzzUDyObvkj0LSHAeylhJgtP X-Proofpoint-GUID: Cr771B-kUzzUDyObvkj0LSHAeylhJgtP X-Proofpoint-Spam-Info: AW1haW4tMjYwODE5MDA2MyBTYWx0ZWRfX3Cs2rIBtsCLS lIk5VqFhVqdoZ/BVzz3ioVEC/pGRZuH6pAx73f60WIt8arOQAOE5iJCENh35sBd+/fbPO6Zns+e pAiE/SR7DrurLAU3cDomAS8ZTY8Q0Z4= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODE5MDA2MyBTYWx0ZWRfX1oLkeaDZvPlv 2uTy634QSQ0xIkps5jeu2ut4q3NkGZ9kSeq+wcWVmTtN7SHMY1XfyagoAuI+h03EF+iimrhs1k6 O4JUsd6/PkxhspRMlyvUL5XEupcrUheXquGSUuNTl47t/Kosp3rHJyNO7kQ3DmAFhqYpXBRFCqH 33JMogn7n94F4pr2Z3Vm1q1JxHHWVbH//dLVo3Gu5Lw1FVOz/Evuy6ktXWkevRdlm/VGUFJYit6 QBLHSodhG6tEjR3QAJG7H5KwQG39U5w0ft+guFj/kxZC+vjZM5WwuscWhC7DtQBH4JRwiCIKNSD XtmNX4zHWKqp1TrzBStQC7re/P5r7475jYiPa2uMwcB03TqE9J50jF22p8GDktlvCufQkz8WGR4 xjDR0ROoduNDE1QGvDQYbHybLt3NQyFYnwQf4HYobBrIVm5OP/D2jt1qOBHbfOoz3WdBsSSmBdG a26pLfYrr9h5h7jg4XQ== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-19_02,2026-08-18_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 impostorscore=0 bulkscore=0 phishscore=0 clxscore=1011 spamscore=0 adultscore=0 lowpriorityscore=0 priorityscore=1501 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608190063 zpci_remove_parent_msi_domain() can be called multiple times on the same zbus, causing a double-free. This occurs when pci_create_root_bus() fails after successful MSI domain creation in zpci_bus_create_pci_bus(): the error path calls zpci_remove_parent_msi_domain() to clean up, but doesn't NULL the pointer. Later, when zpci_bus_release() is called via kref_put(), it calls zpci_remove_parent_msi_domain() again, attempting to free the already-freed domain and fwnode. Add NULL check at function entry and NULL the pointer after cleanup to make the function idempotent and safe for multiple calls. Fixes: f770950a4709 ("s390/pci: Migrate s390 IRQ logic to IRQ domain API") Cc: stable@vger.kernel.org Signed-off-by: Tobias Schumacher --- arch/s390/pci/pci_irq.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/arch/s390/pci/pci_irq.c b/arch/s390/pci/pci_irq.c index 9c9ed3d8d959..c9520a16ca75 100644 --- a/arch/s390/pci/pci_irq.c +++ b/arch/s390/pci/pci_irq.c @@ -533,9 +533,13 @@ void zpci_remove_parent_msi_domain(struct zpci_bus *zb= us) { struct fwnode_handle *fn; =20 + if (!zbus->msi_parent_domain) + return; + fn =3D zbus->msi_parent_domain->fwnode; irq_domain_remove(zbus->msi_parent_domain); irq_domain_free_fwnode(fn); + zbus->msi_parent_domain =3D NULL; } =20 static void __init cpu_enable_directed_irq(void *unused) --=20 2.53.0 From nobody Mon Sep 28 17:50:05 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 41A13364EAB; Wed, 19 Aug 2026 08:51:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787129475; cv=none; b=FzhuGrA+nb4xwbio/fS/NRv+wsLdIKvevXzg97KrRoc9ThJkid/UO3wY2n53mv2Jsn71JEUsQ+K1e2CbaMPk1NULpbkA3ONQjdh87LP5xSH0cphMO4PJPQdRukFVqAMY9n41IdL+pg4xa/vc7wzstaHArzA57qR2TNJFnjh0NSY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787129475; c=relaxed/simple; bh=YF241Iafk6NhMcqEAINFG6wX1J+3sOVRO8wcvi3ARnI=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=sNSVy+Kkcw+CM3cTAJhLvVAiy123vp5YwDbJXo3mvQCXRW/tV2EALWA+PA7xwztyM03PmNh+RmRq9JYqnDXKkWRLWMD9jOTcbDsP18n8OBqxUF/xlMWC0nk8wwY8MheJe7bn//RJC77ruXhWtGi1hsVdkjL2O5eilm6p0KLMMlk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=CW9XQ1Rg; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="CW9XQ1Rg" Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67J6WHC42700038; Wed, 19 Aug 2026 08:51:13 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=H+qUVP v54PjVY8PcBT7IstjPN3xmgNg0sD/7+TA8etA=; b=CW9XQ1RgPIlDQ+lrDHEvHj b6az1wbyxzgMWqA06db6zz2HYpyqKT1ExERDleOFcbk15iz5QxmoITTssFEgI6F6 3W62L4c/t+Udtqr2hjfgUYIVhzrjZLXIdRmZHR0pONwXYXaltGO1wfykDm6mykGH uNUcZEGMSWqIayp4o25VF1ePdFlemODOu5f0zfy0ko6jn+QEr5g1q4SEUYkhwjzo r7DKsHKzZFAbhllP2ohxuI7aTAy7WubjlMtu7zS6t+CJenH7QcV8xiTKk9qMtoaU 5Vd3Nf+ljEnzh0CVtLBdh1GejCgafp48oO3tiQIummsAVs5De1W75hYfwoLWqKLQ == Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g4yu42jjy-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2026 08:51:13 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67J8fOWh007716; Wed, 19 Aug 2026 08:51:12 GMT Received: from smtprelay06.fra02v.mail.ibm.com ([9.218.2.230]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4g32eq868h-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2026 08:51:12 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (smtpav05.fra02v.mail.ibm.com [10.20.54.104]) by smtprelay06.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67J8p85F47448374 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 19 Aug 2026 08:51:08 GMT Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 8ED532004D; Wed, 19 Aug 2026 08:51:08 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 592CB2004B; Wed, 19 Aug 2026 08:51:08 +0000 (GMT) Received: from [127.0.1.1] (unknown [9.87.85.9]) by smtpav05.fra02v.mail.ibm.com (Postfix) with ESMTP; Wed, 19 Aug 2026 08:51:08 +0000 (GMT) From: Tobias Schumacher Date: Wed, 19 Aug 2026 10:50:55 +0200 Subject: [PATCH 2/7] s390/pci: fix use-after-free race in zpci floating interrupt cleanup Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260819-s390_irq_domain_fixes-v1-2-826ff27b6e97@linux.ibm.com> References: <20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com> In-Reply-To: <20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com> To: Niklas Schnelle , Gerd Bayer , Julian Ruess , Farhan Ali , Christian Borntraeger , Halil Pasic Cc: Heiko Carstens , Vasily Gorbik , Alexander Gordeev , Sven Schnelle , linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, Tobias Schumacher , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=CpuPtH4D c=1 sm=1 tr=0 ts=6a856e81 cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=u7Un7ibZpohKse0PRmsA:9 a=QEXdDO2ut3YA:10 X-Proofpoint-ORIG-GUID: trZ20OCLFhIDlnVLASgd964B5cg4G4sB X-Proofpoint-GUID: trZ20OCLFhIDlnVLASgd964B5cg4G4sB X-Proofpoint-Spam-Info: AW1haW4tMjYwODE5MDA2MyBTYWx0ZWRfXykX0js7xL1tr PlkKiNlcjI9VpiMDpRGh370p/DQkzGLnGlTSZHGtLlvRTnne1dAy+opwJCUZ5yubUX2M/9JeKJF Qt6zC9E7/bteXi3u5FjmSgKn+CpNG+Q= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODE5MDA2MyBTYWx0ZWRfX3JOV13L27HZJ Xbjc+fnTSLkTLcMCC8wcuvEaaE8wh6tbOkTnfLgqefimDsHTzsrr+u7Jq7Q9ytbGvKKrixTv+xl Mx8oIXpaLhMD38iV0KrMp4rqe29hHFbYYZAn4pvU32aH7f/xVjPRv2wZI59p6l6fYSUy9r3rPp3 PskVQHFYxfX2Gv9hZzgur8tJ6Z0HkzejgS7n8/zcv2SY3wtOrMBEB8ocJYdhg5I0Tre2R/pfl8V Y8UmKL/LiTvfOZ0BpEkaKnJGbS6oFvKr5dE9AC6I87CnTEuA/UjMoHtYu3WjI7ebQnBFNKsvDEG eRBbQdTFb1H7VC+5jrP4kmA0XGdgD0q+PXqdvZq1N99SizGxmSrSzt9FEO/hdB+vHkFF93X1kxY 0G7S3p9ILJVJt+ASzDvgryKBPgGl1APBtfU74sZkgwrZPUPVYH0Ki8y1t5nbsDfOxw9+rtHTeJv xeDOhl9ys7BufxSxA5A== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-19_02,2026-08-18_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 adultscore=0 bulkscore=0 malwarescore=0 phishscore=0 lowpriorityscore=0 spamscore=0 clxscore=1011 priorityscore=1501 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608190063 The interrupt handler reads zpci_ibv[si] without synchronization while concurrent teardown can release this memory, creating a race: - handler reads the pointer, - then teardown frees memory, - then handler uses the freed pointer. Fix by protecting array access with RCU synchronization. Fixes: f770950a4709 ("s390/pci: Migrate s390 IRQ logic to IRQ domain API") Cc: stable@vger.kernel.org Signed-off-by: Tobias Schumacher --- arch/s390/pci/pci_irq.c | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/arch/s390/pci/pci_irq.c b/arch/s390/pci/pci_irq.c index c9520a16ca75..94b03d16006b 100644 --- a/arch/s390/pci/pci_irq.c +++ b/arch/s390/pci/pci_irq.c @@ -278,8 +278,14 @@ static void zpci_floating_irq_handler(struct airq_stru= ct *airq, continue; } =20 + rcu_read_lock(); + /* Scan the adapter interrupt vector for this device. */ - aibv =3D zpci_ibv[si]; + aibv =3D rcu_dereference(zpci_ibv[si]); + if (!aibv) { + rcu_read_unlock(); + continue; + } for (ai =3D 0;;) { ai =3D airq_iv_scan(aibv, ai, airq_iv_end(aibv)); if (ai =3D=3D -1UL) @@ -291,6 +297,7 @@ static void zpci_floating_irq_handler(struct airq_struc= t *airq, generic_handle_domain_irq(msi_domain, hwirq); airq_iv_unlock(aibv, ai); } + rcu_read_unlock(); } } =20 @@ -346,9 +353,12 @@ static void zpci_msi_teardown_directed(struct zpci_dev= *zdev) =20 static void zpci_msi_teardown_floating(struct zpci_dev *zdev) { + airq_iv_free_bit(zpci_sbv, zdev->aisb); + zpci_ibv[zdev->aisb] =3D NULL; + synchronize_rcu(); + airq_iv_release(zdev->aibv); zdev->aibv =3D NULL; - airq_iv_free_bit(zpci_sbv, zdev->aisb); zdev->aisb =3D -1UL; zdev->msi_first_bit =3D -1U; zdev->msi_nr_irqs =3D 0; --=20 2.53.0 From nobody Mon Sep 28 17:50:05 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BF20F415F07; Wed, 19 Aug 2026 08:51:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787129476; cv=none; b=N1g5/Oyt3zV6zLSDfT1N6hAAZmpmld/BiAcgwzECm1n9gFkCbosJXyDT2JPva4TcmUgx8Wfgj/MTf4eLuc78Fj7nIdvAI3wJUYAVyYaVipHAcUklV0CLkVSsshUfp6FQnW465cgd6LhImT5U0AWrDGvZupNRNWlA7iyAtmp2oIE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787129476; c=relaxed/simple; bh=Y38cVCTo9HfTxe9w3USJ3JnCx84wfBdyYn5Fbl8Gdmg=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=QEOMQHU1PssTuD3jfroklIk2I8/RJCyX9OUZuiv41sqiqwolidjbaN4sIRjS0rldy1sZ9KRT3tohUGtVfrCSos5DmgfVE1ZzvjafDByTqDza8bknTZVm2e3d25tm7Q1+9EkOdpyIpYFH+7RJdVn0ZRwE/o3zJn0bCY4tUAd69jU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=sVLr6KmD; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="sVLr6KmD" Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67J6VjDS2621733; Wed, 19 Aug 2026 08:51:14 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=r2BdWx oh8mgVXdbRQoThpiDQbegCOwnf7Z5RlaRMD1c=; b=sVLr6KmDJLoOygr5EFfzbZ z47PDCCRhkISqCXGRgj48neLvYSLnWb2kH/krHV1pVoMNvNb4S7LXn8LIWRgX31h N6M5l+pCxwwnQN0bBW0GensqKj8F9Lo6qhbQhKl0WZbKhicdjOpUJ1IxSjFokiVx JxTaYK0uvTkDbnFWjFyPxTg7eKHG8B8OhUAsP29Yr01Emj94HlBg7Gu9H3CUfF7Z MfHGHlCT+wndBTRQRe9ap7dU/HdIQQ0Hj5Yun8t/2pu/6mH7I6F2j2s7iuAgKiIG x7PQLVoUjBuh1nBeRyA9SNAyu/+FQx9yDZ1RKVo67CH9rh80K46mE5GAoIeGlkZQ == Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g4yu1amfs-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2026 08:51:13 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67J8fJP6028842; Wed, 19 Aug 2026 08:51:12 GMT Received: from smtprelay06.fra02v.mail.ibm.com ([9.218.2.230]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4g32tw84uy-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2026 08:51:12 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (smtpav05.fra02v.mail.ibm.com [10.20.54.104]) by smtprelay06.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67J8p8oD35586410 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 19 Aug 2026 08:51:08 GMT Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id BF41920040; Wed, 19 Aug 2026 08:51:08 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 8F5D62004E; Wed, 19 Aug 2026 08:51:08 +0000 (GMT) Received: from [127.0.1.1] (unknown [9.87.85.9]) by smtpav05.fra02v.mail.ibm.com (Postfix) with ESMTP; Wed, 19 Aug 2026 08:51:08 +0000 (GMT) From: Tobias Schumacher Date: Wed, 19 Aug 2026 10:50:56 +0200 Subject: [PATCH 3/7] s390/pci: fix resource leak in zpci MSI setup Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260819-s390_irq_domain_fixes-v1-3-826ff27b6e97@linux.ibm.com> References: <20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com> In-Reply-To: <20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com> To: Niklas Schnelle , Gerd Bayer , Julian Ruess , Farhan Ali , Christian Borntraeger , Halil Pasic Cc: Heiko Carstens , Vasily Gorbik , Alexander Gordeev , Sven Schnelle , linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, Tobias Schumacher , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=LsCiDHdc c=1 sm=1 tr=0 ts=6a856e82 cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=fzb7yXF3lHBN6XHo5OoA:9 a=QEXdDO2ut3YA:10 X-Proofpoint-GUID: d1UHDiz7EFVAo2TqZctM_qQoSv4kv7XV X-Proofpoint-Spam-Info: AW1haW4tMjYwODE5MDA2MyBTYWx0ZWRfXzRbdCMZqAD9b LRfNMlGXkDx4rAE+s8ybywHlXCMmfgjftkO+ScteO+Wg6Ky6PBf8QIFrwXZ+aBsGkvy2x5MVzio JTjXy7kFuPCWlgJVivmjPU2jS1MI184= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODE5MDA2MyBTYWx0ZWRfX/xvf/YWKAuz6 YpXT9WUtba8lj6igh2TaKBOWQmM7X1Guho6Wrnu4onOs/xjvQiwm2tyUluBQtakIlUuD9FCXzdy QlT7lri+EQSINxXlFRmH7A4X+y8HDLD1pFZ+wqTo8n6H/Z2iquDGWWJrzL2Oq7x9zf+vECGJUNr usNWSO/uIYfmmyhyoDL7GvwDuBH/dOqlC3hz2ngmCgdg++zc0b1z71DRZL6qz1fxsWkY9JbPc9P fErWFa+EmZwgZeGB/CK1thuN0j+akoyfZ6DqeTvBt+AGC2kR9KaswWhQODV3+nspebYBI7oS9zc 8aMMfX0pw9IqCRlOsjpLiKyLdfxpKY1SGUaf8Dka35fDFRllb82TUV0jcHVAoru/qThrHgkGwo8 9/j+DLhZjSgetFEaMmlV4qlc4zF5RFO/apRZSUKb8cAAJ6eM1kYXpOGmAk1nyT8DTs2RqrdGRMt hJ2KDYpcU3IqmBaH6Og== X-Proofpoint-ORIG-GUID: d1UHDiz7EFVAo2TqZctM_qQoSv4kv7XV X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-19_02,2026-08-18_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 spamscore=0 priorityscore=1501 lowpriorityscore=0 bulkscore=0 adultscore=0 suspectscore=0 impostorscore=0 clxscore=1015 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608190063 If airq_iv_create() fails in __alloc_airq(), the zpci_sbv bit allocated by airq_iv_alloc_bit() is never freed. This permanently leaks one of the ZPCI_NR_DEVICES summary bits (~128 total), reducing system capacity with each failed device hotplug. In systems with repeated device insertion failures or under memory pressure, all summary bits can be exhausted, preventing new PCI devices from being added until reboot. Add proper error handling to free the zpci_sbv bit and reset zdev->aisb if the AIBV creation fails. Fixes: f770950a4709 ("s390/pci: Migrate s390 IRQ logic to IRQ domain API") Cc: stable@vger.kernel.org Signed-off-by: Tobias Schumacher --- arch/s390/pci/pci_irq.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/arch/s390/pci/pci_irq.c b/arch/s390/pci/pci_irq.c index 94b03d16006b..5e934ac990ac 100644 --- a/arch/s390/pci/pci_irq.c +++ b/arch/s390/pci/pci_irq.c @@ -320,8 +320,11 @@ static int __alloc_airq(struct zpci_dev *zdev, int msi= _vecs, zdev->aibv =3D airq_iv_create(msi_vecs, AIRQ_IV_PTR | AIRQ_IV_DATA | AIRQ_IV_BITLOCK, NULL); - if (!zdev->aibv) + if (!zdev->aibv) { + airq_iv_free_bit(zpci_sbv, *bit); + zdev->aisb =3D -1UL; return -ENOMEM; + } =20 /* Wire up shortcut pointer */ zpci_ibv[*bit] =3D zdev->aibv; --=20 2.53.0 From nobody Mon Sep 28 17:50:05 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7D4A94252AE; Wed, 19 Aug 2026 08:51:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787129477; cv=none; b=Y4XpUVtM6mmGDSGnhS0b3tdCy8QvkCwR0o8tWc3BF6vx6dVCEH77OPsl3uKFX2OBL50WVi2/MBa9tM7qm4uV/8+6iXNuqIEyxreWW8EqKsOYNRY/xJvdjS0wPV4aDv994vzSKnhMFG6uoLyIqxGK+g07q2DSna3W33bda9faXGk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787129477; c=relaxed/simple; bh=TUEkS8610yFZ5NGf0Xl4UBB7A3BrCqBlaqaQ5SiVQM4=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=OZNMQEbQI24EfP9bsdjx/3gPc0kqDB2QUYD7OGhuuG5yqviuWH9Drm10XcMTcLCAgnXQWIDXxK/HOyUv90S8fj22g6YtSrspy0Gku8ZxLvNgophvZf3ppJjpAocDT5Pa2wtxCqcBHye9Enc0XghLKIgZnAykXJa9PZO/SE4CaHc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=o4Slmqs2; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="o4Slmqs2" Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67J6W7sV1544811; Wed, 19 Aug 2026 08:51:14 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=X2tJql l+Fi4HNShPax6UVCV1yJsPcFkMEGIW0WeqA9Q=; b=o4Slmqs2Y2OsEJyWuCGeuB 6Q1jCk2gvwGXIbIL480gzvU3yeIIWICRFnKigb7MOepRUCjtAXUAum0QD6GBu5Qg s1xFeH+hkf+XhEJtJ76km0GTVZmgO0XHoLMBtITjiAw2oVLNFclDEAemiha3c84I mlAeTMip3PKlFCeGpuiwsY4gZj6u6f2DjqAJX0nVQA5xJOeT/NkUqjf+dizDCuGH vbZUV5kQLk3Mdkqglw24SfBQaCOhbCi4mA49VcOxsByIeuOEZQR0NGSS9OhHmjW+ 02oEs190/4urnyU2mjxU3eOa8pg0DFO2MW9eXSX1xYlv0JsMETn8XD5WGEYrjDvg == Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g4yu22jvf-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2026 08:51:13 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67J8fMg7018364; Wed, 19 Aug 2026 08:51:13 GMT Received: from smtprelay07.fra02v.mail.ibm.com ([9.218.2.229]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4g33ek8169-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2026 08:51:13 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (smtpav05.fra02v.mail.ibm.com [10.20.54.104]) by smtprelay07.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67J8p9f643450734 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 19 Aug 2026 08:51:09 GMT Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 0151820040; Wed, 19 Aug 2026 08:51:09 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id C479E20043; Wed, 19 Aug 2026 08:51:08 +0000 (GMT) Received: from [127.0.1.1] (unknown [9.87.85.9]) by smtpav05.fra02v.mail.ibm.com (Postfix) with ESMTP; Wed, 19 Aug 2026 08:51:08 +0000 (GMT) From: Tobias Schumacher Date: Wed, 19 Aug 2026 10:50:57 +0200 Subject: [PATCH 4/7] s390/pci: fix MSI directed-mode teardown IRQ bit count Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260819-s390_irq_domain_fixes-v1-4-826ff27b6e97@linux.ibm.com> References: <20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com> In-Reply-To: <20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com> To: Niklas Schnelle , Gerd Bayer , Julian Ruess , Farhan Ali , Christian Borntraeger , Halil Pasic Cc: Heiko Carstens , Vasily Gorbik , Alexander Gordeev , Sven Schnelle , linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, Tobias Schumacher , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=AdqB2XXG c=1 sm=1 tr=0 ts=6a856e81 cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=V8glGbnc2Ofi9Qvn3v5h:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=HZfvwOHSaoXKuVtsHEEA:9 a=QEXdDO2ut3YA:10 X-Proofpoint-GUID: GjJ6vVpTghGTrR3g2iY6JDSunex6PZwZ X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODE5MDA2MyBTYWx0ZWRfX2UZRO+yDlHG5 PQo5VLaulvPLyXOQoFNsFZDL7MCQBvHYlqNuR19cFXDvW71ZIHWF3+csOnzkE6R3QkVRQEgp3ic rRRxUuV1sQxeATemOvbSRfuTCc0YNZw9ca8qPrdFx48LuPoa1ghzdOE+XtekYfuO+eBd4G1hfE0 pla/eGRgCGSKNBWg91ehofzv8C+N5fbr8Tca3BktZrSNkCTnvnw+PnJct2JDEwivzlspJov/Tbl szATi6KMn7vrUcsjjgQDILbV41oQm6VGJieFaf50jeni7DB9iAhQT62ZeoIHegIs/6rP8/J2bHN m/I4Lap164ZRH6MMt5ost0yVtz/cRzYVN1ahSH0udvh3ltDw+HACI+Mh79NvG0EJ1Pj+Y/3XLKT kJRZ8UXwjxUQ4FxmTNE6TEN0wMYFsokQ9LP1WWZbDaWKGFzixAc+vbhFSbJwGce/y0yNCZ4oz8A 01GgkakgyHTujwZ/4jw== X-Proofpoint-Spam-Info: AW1haW4tMjYwODE5MDA2MyBTYWx0ZWRfX5qaOCQhsIXnf XHvZ1JL2l1S63Xn0fKwYo/z4BrBNywd3shZSykv0K0fkwPvJWHObmoxRC1K7RKTEo0JFpsZkr81 nHM//AqjZOuEc/MR8wrPA6tNbmGqsEA= X-Proofpoint-ORIG-GUID: GjJ6vVpTghGTrR3g2iY6JDSunex6PZwZ X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-19_02,2026-08-18_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 priorityscore=1501 suspectscore=0 malwarescore=0 impostorscore=0 adultscore=0 bulkscore=0 lowpriorityscore=0 phishscore=0 spamscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608190063 On s390 with directed interrupts enabled, zpci_msi_teardown_directed() frees the platform's maximum number of MSI bits (zdev->max_msi) instead of the actual allocated count (zdev->msi_nr_irqs). This corrupts the shared IRQ bitmap used by all PCI functions, causing lost interrupts and heap corruption. Fix zpci_msi_teardown_directed() to only free the actual allocated IRQ bit count. Fixes: f770950a4709 ("s390/pci: Migrate s390 IRQ logic to IRQ domain API") Cc: stable@vger.kernel.org Signed-off-by: Tobias Schumacher --- arch/s390/pci/pci_irq.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/s390/pci/pci_irq.c b/arch/s390/pci/pci_irq.c index 5e934ac990ac..e9eda846cb2d 100644 --- a/arch/s390/pci/pci_irq.c +++ b/arch/s390/pci/pci_irq.c @@ -349,7 +349,7 @@ static struct airq_struct zpci_airq =3D { =20 static void zpci_msi_teardown_directed(struct zpci_dev *zdev) { - airq_iv_free(zpci_ibv[0], zdev->msi_first_bit, zdev->max_msi); + airq_iv_free(zpci_ibv[0], zdev->msi_first_bit, zdev->msi_nr_irqs); zdev->msi_first_bit =3D -1U; zdev->msi_nr_irqs =3D 0; } --=20 2.53.0 From nobody Mon Sep 28 17:50:05 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B06B33F1AD3; Wed, 19 Aug 2026 08:51:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787129475; cv=none; b=QyRaglQ6qcFaAbHBQuhvXkc6iIhvZUG4q0/RUf+vXqkMuzYaFp0kGfD46OKp/XLeeoD8siuP0qhZhxDZDL/OzEVZ0evvy+Dks0Oz1StHeVGmR3LXR0fe33fCXMRL54GiEbq4xqLgUFr/wRzUh5qjRH82rt36Io1j124kvP1niqM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787129475; c=relaxed/simple; bh=iiGSw3MAEDhhYKpP3QXTIIkI70MydeBZkCvYSd6fNBU=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=uCqTV0l6Ph/fF0rd+Pojf66Jdd3girGqKFKv8AvMtwjJRSArM3u4K2JFVKRc4+5XyOcX6kN+QX/zPYihAFgFnI5/atQDxbU+Yg9RSbok/TOSxSXhAAW3lMvWTPW0WJXmWntQwtmSDwZzzK0EcmK+WiaF/pKmHlDYSxsUbwoxH0I= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=p4Xw30LW; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="p4Xw30LW" Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67J6Wupq799764; Wed, 19 Aug 2026 08:51:14 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=iYxY3F wJ0N+w/bPo/HDIS3Nx0fLFnUy3i0c1+BKecvg=; b=p4Xw30LWjGM62zdmHpaQ6T XYsTuc3vwzAa5KmBalynxqyNYU93pGQldn7NJLYzDjTwSoRqa0Xsz3PAzYPqR4yK 7c7DlgNzdL29mTndg9Iaf1g1dvu9U4dM2D9/UnxRAksLUn1sRVeN06HA5kAgcunf 8wMwdRaN8fe5GRoSTw/Glw6oXZRPm1zS/WlEa26itYp9KLj7Rir5dNe85pBIlzVi 3VE6X2qlYA211o6FGOEIBwvvB2gGjP+7pYfpGeI9fe6qgdDNt4qf23C5UEv1eXNc qT/o/DLDDR3A0vjf/r3ZC5zxS6QNQJ+MyAWId0msDeNi7H8GxV6Tryur7dlgY7Tg == Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g4yu02mcv-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2026 08:51:13 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67J8fH6Y028348; Wed, 19 Aug 2026 08:51:12 GMT Received: from smtprelay07.fra02v.mail.ibm.com ([9.218.2.229]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4g354yfrud-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2026 08:51:12 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (smtpav05.fra02v.mail.ibm.com [10.20.54.104]) by smtprelay07.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67J8p9hK49676760 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 19 Aug 2026 08:51:09 GMT Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 3633D20040; Wed, 19 Aug 2026 08:51:09 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 060D32004B; Wed, 19 Aug 2026 08:51:09 +0000 (GMT) Received: from [127.0.1.1] (unknown [9.87.85.9]) by smtpav05.fra02v.mail.ibm.com (Postfix) with ESMTP; Wed, 19 Aug 2026 08:51:08 +0000 (GMT) From: Tobias Schumacher Date: Wed, 19 Aug 2026 10:50:58 +0200 Subject: [PATCH 5/7] s390/pci: add NULL check in zpci_msi_clear_airq() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260819-s390_irq_domain_fixes-v1-5-826ff27b6e97@linux.ibm.com> References: <20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com> In-Reply-To: <20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com> To: Niklas Schnelle , Gerd Bayer , Julian Ruess , Farhan Ali , Christian Borntraeger , Halil Pasic Cc: Heiko Carstens , Vasily Gorbik , Alexander Gordeev , Sven Schnelle , linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, Tobias Schumacher , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-TM-AS-GCONF: 00 X-Proofpoint-ORIG-GUID: Kso1fGyYDa3arVyF_osRN5QMLioZu8SB X-Proofpoint-GUID: Kso1fGyYDa3arVyF_osRN5QMLioZu8SB X-Authority-Analysis: v=2.4 cv=RoX16imK c=1 sm=1 tr=0 ts=6a856e81 cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=ZfaGzbHgtsswHcod-aMA:9 a=QEXdDO2ut3YA:10 X-Proofpoint-Spam-Info: AW1haW4tMjYwODE5MDA2MyBTYWx0ZWRfXzxp59iM3tS2z 0jSo6IqLeq9j2W/tLODMiJvLI7D0gUS//EHfeDQe41KmLVftjJVQcOjDndkVMlHTPv5mSfeNQPZ e2SfQ2eUr67xh+jSAewdYXZZ2WZdINw= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODE5MDA2MyBTYWx0ZWRfXzZRHS2OVgzud 92JsLFqNqUoFZadhK3no+5SaHn/QdfqGVP+93/D7qV62osg6dZCu6P4uPCyZRALeQxsiSpRnU8s JrG3qGXU/5bNpuzhvg3p1u/CGmhHLwC7l7kkeAMGzDDvW6S/FjNmDzrQJUmes20nQj5kTh5yOQX kNGnFxMDf3ZuGcRx6/1Dcm+TJCocHs1mbI0+vtfGIvHB2d5PCyA7po7AAnwMhtEzT2oqPU5m0gv FKuP8EX3lOL9X/jI/T8By4paiCZ80uBHDs3WBosaxF6IKCNYiOVmR5prKpVYPqc2/HaQDK0ZU/K 7twS77XM54QB7zK7mA54T5tf95orsJxsPAAhhadpRq+2egNah66DdzwT1z5uwVP6t+M/7OE1nZz hRLOGfGZH86P5qhdrwsHNqbxkoxPJKsMJPy5uuVdX4/7y7ioNn/pMyyoBwXHP2FfGpLr3tKVdmk TrCMRV21Sn2nBq+en6Q== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-19_02,2026-08-18_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 impostorscore=0 suspectscore=0 malwarescore=0 adultscore=0 clxscore=1015 phishscore=0 spamscore=0 bulkscore=0 lowpriorityscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608190063 zpci_msi_clear_airq() clears IRQ data in both DIRECTED and FLOATING modes but does not check if the interrupt vector pointers are NULL before dereferencing them. In DIRECTED mode, zpci_ibv[cpu] can be NULL if: - zpci_directed_irq_init() fails during boot after allocating some but not all per-CPU vectors, and cleanup is attempted - The system is shutting down and zpci_irq_exit() has already released some vectors In FLOATING mode, zdev->aibv can be NULL if: - zpci_msi_prepare() fails after __alloc_airq() but before setting up the device's AIBV, and zpci_msi_domain_free() is called during error cleanup - The device is being torn down and zpci_msi_teardown_floating() has already released the AIBV Add NULL checks for zpci_ibv[cpu] in DIRECTED mode and zdev->aibv in FLOATING mode to prevent crashes during these error and shutdown paths. Fixes: f770950a4709 ("s390/pci: Migrate s390 IRQ logic to IRQ domain API") Cc: stable@vger.kernel.org Signed-off-by: Tobias Schumacher --- arch/s390/pci/pci_irq.c | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/arch/s390/pci/pci_irq.c b/arch/s390/pci/pci_irq.c index e9eda846cb2d..1515d8d7460e 100644 --- a/arch/s390/pci/pci_irq.c +++ b/arch/s390/pci/pci_irq.c @@ -465,12 +465,16 @@ static void zpci_msi_clear_airq(struct irq_data *d, i= nt i) =20 if (irq_delivery =3D=3D DIRECTED) { for_each_possible_cpu(cpu) { - airq_iv_set_ptr(zpci_ibv[cpu], bit + i, 0); - airq_iv_set_data(zpci_ibv[cpu], bit + i, 0); + if (zpci_ibv[cpu]) { + airq_iv_set_ptr(zpci_ibv[cpu], bit + i, 0); + airq_iv_set_data(zpci_ibv[cpu], bit + i, 0); + } } } else { - airq_iv_set_ptr(zdev->aibv, bit + i, 0); - airq_iv_set_data(zdev->aibv, bit + i, 0); + if (zdev->aibv) { + airq_iv_set_ptr(zdev->aibv, bit + i, 0); + airq_iv_set_data(zdev->aibv, bit + i, 0); + } } } =20 --=20 2.53.0 From nobody Mon Sep 28 17:50:05 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 854CE424D64; Wed, 19 Aug 2026 08:51:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787129477; cv=none; b=le/QiPw9e3a13pDHC4q2FoGPWm6aD11rbaY9mj2rAlPs8biBFW0lVFxyiN7WHzC4hOKawCfSWEenieDphKJGPQwYMPnY/akMPd9LvGeGaJgfI42ZnWWNWCZ/lADQ9uvonS//74/SIP4dp9xxS1D0JKFgYvI2Yl4WwpY91sd0MWs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787129477; c=relaxed/simple; bh=lrb+OrxV8ahIGAoh56p1bDqAKZpF+iq6sJcJkP85Tnk=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=fepkYUFLkPReCXk5gaZlf10/nQIas+2GLfLo0aiF9AGPkFVnDXGKAEdeDNSPin0MCDJrcfmN/3pbGmC0Qj9AU3NDPFkQXbP8V/V35u6R4Gs5KrqraoCZ7jNLzC054yBZ1yICIffgrrqsglgTIc9ifIn8ptpX/4M9+61U+BQjFHU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=Nflerk8x; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="Nflerk8x" Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67J6VkdI2621747; Wed, 19 Aug 2026 08:51:14 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=dVlfP1 aKWDc1w4MU8JTuxultFGKrT+Ma/XA7z29gKRE=; b=Nflerk8xvIdnMq8iNKrrFT nVgR/Xp748XrV6+4GhChnDIk91lqKBxiaILe+kIJjjRhOvFcOKhKhkE0GMOH5lUi CysX2j1UGpAeP2RwJlEhR8gdBzFsNc4dWjWbMpjAKBh8Aq6OTFB+YUevT5pNUWeJ 4O66gshLUGKj4cs1rqxV91/1fD74bJZPw75XarBEW9udDNcVqUPMnYnBiD+At1Le At6at09coG/k4WP3i1N9iKdIiDbHq3PW3YSSihQ0wyWOTds0PcBWvXr566gpPyPf 651VlUGMbs/LMWqMIfTnzy6GucUe2XMOIIV+deVpKUZCpnHVVWk+bKTKgGtPQxOQ == Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g4yu1amfv-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2026 08:51:14 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67J8fM2r028855; Wed, 19 Aug 2026 08:51:13 GMT Received: from smtprelay07.fra02v.mail.ibm.com ([9.218.2.229]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4g32tw84v1-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2026 08:51:13 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (smtpav05.fra02v.mail.ibm.com [10.20.54.104]) by smtprelay07.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67J8p9oQ43450740 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 19 Aug 2026 08:51:09 GMT Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 6AF6D20040; Wed, 19 Aug 2026 08:51:09 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 3AE6C2004E; Wed, 19 Aug 2026 08:51:09 +0000 (GMT) Received: from [127.0.1.1] (unknown [9.87.85.9]) by smtpav05.fra02v.mail.ibm.com (Postfix) with ESMTP; Wed, 19 Aug 2026 08:51:09 +0000 (GMT) From: Tobias Schumacher Date: Wed, 19 Aug 2026 10:50:59 +0200 Subject: [PATCH 6/7] s390/pci: add error cleanup in zpci_directed_irq_init Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260819-s390_irq_domain_fixes-v1-6-826ff27b6e97@linux.ibm.com> References: <20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com> In-Reply-To: <20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com> To: Niklas Schnelle , Gerd Bayer , Julian Ruess , Farhan Ali , Christian Borntraeger , Halil Pasic Cc: Heiko Carstens , Vasily Gorbik , Alexander Gordeev , Sven Schnelle , linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, Tobias Schumacher , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=LsCiDHdc c=1 sm=1 tr=0 ts=6a856e82 cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=bp1g5Iz1D7c7guLF1_8A:9 a=QEXdDO2ut3YA:10 X-Proofpoint-GUID: truLiIf-91VheaJFWK3F7nB2USbP94Lq X-Proofpoint-Spam-Info: AW1haW4tMjYwODE5MDA2MyBTYWx0ZWRfX3EyZ8VmSD9uM Ey3aYwOpJpRasO9MVw44e/rEYF+wU5eo1nMP8NtL1gmzYy309E8YTZM0y+FtJU+C3FFSAFWzyX0 IAhG18jn5WSA9e7AaisaDYfoncTqWWY= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODE5MDA2MyBTYWx0ZWRfX1k2tBKE+wjXg v4hAQtJLUXFQ+V3rv0EwLaueDT1Vt9a4ZVz22gauNPwHB5tOMqzw+48Zp+OoZv1JRJmrYAWL8Jd Ww2NSRbRLYKDmOwMVVLtC8o4EBNcRqgtTQmwLEKt0skmMj8OjwSY+QIprUXOTmwt8Wp537AotwY G8xb4TEk1MnjhGSjEXgKhcJRxwt6Y4OyAp8RolnDgum808dP60VL1QUSd+1XNVobF1nVQmro9Qr 2LdNALMUAWQNYi23c5K8dloU/GjAm9IZVwSW0AsU1A3Vqpq3hwmz3mrovygAnJ2Qg+yF+WgrS4k 1a06KlNk1X9KqoSPbBqhl+4ly1fdJijbQEgzvQjdqgsZ5mHN62scVuE/JoDJcOJwFhdEx7fYIgI MLGw0fkQ7jfUJx47jDUK+SBIgmrfx6NNVcQJhf+vzy7fpWZu515kxwF6t53qZGGs0E3uYxI7qMo /3fEdf9RzlZYVx+pEfg== X-Proofpoint-ORIG-GUID: truLiIf-91VheaJFWK3F7nB2USbP94Lq X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-19_02,2026-08-18_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 spamscore=0 priorityscore=1501 lowpriorityscore=0 bulkscore=0 adultscore=0 suspectscore=0 impostorscore=0 clxscore=1015 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608190063 If per-CPU airq_iv allocation fails in the loop, previously allocated vectors and arrays leak. Add proper error path to release all resources on failure. Fixes: f770950a4709 ("s390/pci: Migrate s390 IRQ logic to IRQ domain API") Cc: stable@vger.kernel.org Signed-off-by: Tobias Schumacher --- arch/s390/pci/pci_irq.c | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/arch/s390/pci/pci_irq.c b/arch/s390/pci/pci_irq.c index 1515d8d7460e..1ddf6b3625a2 100644 --- a/arch/s390/pci/pci_irq.c +++ b/arch/s390/pci/pci_irq.c @@ -586,7 +586,7 @@ static int __init zpci_directed_irq_init(void) =20 zpci_ibv =3D kzalloc_objs(*zpci_ibv, num_possible_cpus()); if (!zpci_ibv) - return -ENOMEM; + goto out_free_sbv; =20 for_each_possible_cpu(cpu) { /* @@ -599,13 +599,25 @@ static int __init zpci_directed_irq_init(void) AIRQ_IV_CACHELINE | (!cpu ? AIRQ_IV_ALLOC : 0), NULL); if (!zpci_ibv[cpu]) - return -ENOMEM; + goto out_free_ibv; } on_each_cpu(cpu_enable_directed_irq, NULL, 1); =20 zpci_irq_chip.irq_set_affinity =3D zpci_set_irq_affinity; =20 return 0; + +out_free_ibv: + for_each_possible_cpu(cpu) { + if (zpci_ibv[cpu]) + airq_iv_release(zpci_ibv[cpu]); + } + kfree(zpci_ibv); + zpci_ibv =3D NULL; +out_free_sbv: + airq_iv_release(zpci_sbv); + zpci_sbv =3D NULL; + return -ENOMEM; } =20 static int __init zpci_floating_irq_init(void) --=20 2.53.0 From nobody Mon Sep 28 17:50:05 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7D3FF424D6D; Wed, 19 Aug 2026 08:51:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787129477; cv=none; b=a4n6SnvUlspG2RfMwTFGcE4PnvnHD7UrVjolQpC+Jd/EtxRM/Bi9mCmVb2Pg6n4NTJ89WivL6rgEC4YKjHXgwmCafYMh6FLZqHFIwE3wysNG4zFjZISXANMCyGiHPHTUQdL4IRaNNB6tAROyS61YqnfzMndgYUojm6ueys5Xf6g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787129477; c=relaxed/simple; bh=n+zdyWWYmMNNFu8LL3tJxKU4bHapgAI4vHnbe7Vh4Hk=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=nLyDuW4UBGkuysVY+BTa5i1CMTXAo1JDat/DRjcysIAeUL3D0e1C1wIjtRAarpv6lfR+A6QmpehANr9p9Ril9R9E/Ek8kxSZtJBt4c5h0jorxsJf0+5nWIBAjQ7IFMAr6oQ6nHcIduiyTtuHWONX1w5PgZdkMbTUIkOJGVNQECA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=ixzMxj30; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="ixzMxj30" Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67J6WIvI2700051; Wed, 19 Aug 2026 08:51:14 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=+c9hkR /UvnFv1X+twEJIzP9975oBrBOHa03KPUs8p4I=; b=ixzMxj30XKSfhc+b7DPckN Z7sz8tkB1OGUiBYYsO7p7sibCSQ9GhSALxeFqudWkwXasZU14TbptpanTtR6AMAY wDwLcSdAMRNC2jN+abVWbj6cYhisTjGyV4zJCYfSkLprHrW5BAuwF+EYpkvYDPQ6 +37jP6u/xF7L/5II9AW8upTMtpUk4DqvmjBzdPKb9ct0XGP09R3QZyUf27S7OwPS i+5Oo1yQ8nyLRQkfhqreYgDDsz73jXPD3HqWMJEEZAJbv9lIlsvIXbdWuyEZLTzH SVIb+yh65RNLiHlUrpyoV/zwbCqnWzFtmzT/2n27wMtewVaEBI/BlXwAB3EB5EoQ == Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g4yu42jk3-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2026 08:51:14 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67J8oZfj006773; Wed, 19 Aug 2026 08:51:13 GMT Received: from smtprelay07.fra02v.mail.ibm.com ([9.218.2.229]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4g34ngftmx-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2026 08:51:13 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (smtpav05.fra02v.mail.ibm.com [10.20.54.104]) by smtprelay07.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67J8p9Hc43450742 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 19 Aug 2026 08:51:09 GMT Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 9CAF92004E; Wed, 19 Aug 2026 08:51:09 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 6F6382004B; Wed, 19 Aug 2026 08:51:09 +0000 (GMT) Received: from [127.0.1.1] (unknown [9.87.85.9]) by smtpav05.fra02v.mail.ibm.com (Postfix) with ESMTP; Wed, 19 Aug 2026 08:51:09 +0000 (GMT) From: Tobias Schumacher Date: Wed, 19 Aug 2026 10:51:00 +0200 Subject: [PATCH 7/7] s390/pci: move MSI affinity flag initialization to boot time Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260819-s390_irq_domain_fixes-v1-7-826ff27b6e97@linux.ibm.com> References: <20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com> In-Reply-To: <20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@linux.ibm.com> To: Niklas Schnelle , Gerd Bayer , Julian Ruess , Farhan Ali , Christian Borntraeger , Halil Pasic Cc: Heiko Carstens , Vasily Gorbik , Alexander Gordeev , Sven Schnelle , linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, Tobias Schumacher X-Mailer: b4 0.14.3 X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=CpuPtH4D c=1 sm=1 tr=0 ts=6a856e82 cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VnNF1IyMAAAA:8 a=ZS0GaVJMuydn_FCVLc4A:9 a=QEXdDO2ut3YA:10 X-Proofpoint-ORIG-GUID: UihizuyWQUkHQOyZ82EzVgei7QeALog4 X-Proofpoint-GUID: UihizuyWQUkHQOyZ82EzVgei7QeALog4 X-Proofpoint-Spam-Info: AW1haW4tMjYwODE5MDA2MyBTYWx0ZWRfX1twRYAuB5CR3 k3HzMpApIimOeUlQ3kCsrzFdNb5SbLMBzNmPqR8srUYfTLtkigKpVhGilSrVOi9e4muFRp8T74p /29cseWvKCB4HyZOatWNbhvRQo2jL9Y= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODE5MDA2MyBTYWx0ZWRfX1wi38Xdf9E7W cB9Tg+rwPyTpkmHj4+SnVdI+9ZJs5aRGo3k2JHKqp5BstEizszrJwWsEF7bgNfHYR6ccVTAvhiG YqNuz9pjcvrEEhBHhzGexnvdUNVxkeU8+kWkjnpmH+cKmiPsEF/z+Qv4cN8C7tTXAzaWWdwHxss //TiQsUJpHB+xZmfpFZlikTf/gZmaPbVEVhXMxKxWM/XDZH1qF/96fPRmkJD40YmVAEBN+rVLxo 6GSs6y3Y3yydO9yIfj+qVXbrCG68xZTOHcaIdFdF5x02X/y/x4u6bB66PO5UYUYTT1TryKoDETj 69D53LyP+bEqyeFt2Rv98jlsYZdfVLBT590ZTecQYWqKcgE/UQRcrWLXR5Yd8YjIFAIx4lwO/K2 FtvMJFkT0ffVQw4dBDWZ2C74L+9IFozaLggdAnQdBartS4e1J3OedEckx4Uh7VqVdWryvs8NiVG vDW60tfBd5YJ8TXgFOQ== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-19_02,2026-08-18_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 adultscore=0 bulkscore=0 malwarescore=0 phishscore=0 lowpriorityscore=0 spamscore=0 clxscore=1015 priorityscore=1501 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608190063 The MSI_FLAG_NO_AFFINITY flag for FLOATING mode is currently set lazily in zpci_create_parent_msi_domain(), which may be called multiple times when discovering PCI buses. While setting the flag multiple times is a no-op due to its idempotent nature, this is inefficient and unclear. Since irq_delivery mode is determined once at boot time and never changes, move the flag initialization to zpci_irq_init() where it belongs. This clarifies intent and avoids redundant repeated operations on the shared structure. Signed-off-by: Tobias Schumacher --- arch/s390/pci/pci_irq.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/arch/s390/pci/pci_irq.c b/arch/s390/pci/pci_irq.c index 1ddf6b3625a2..ed19f7cce9eb 100644 --- a/arch/s390/pci/pci_irq.c +++ b/arch/s390/pci/pci_irq.c @@ -533,9 +533,6 @@ int zpci_create_parent_msi_domain(struct zpci_bus *zbus) return -ENOMEM; } =20 - if (irq_delivery =3D=3D FLOATING) - zpci_msi_parent_ops.required_flags |=3D MSI_FLAG_NO_AFFINITY; - zbus->msi_parent_domain =3D msi_create_parent_irq_domain(&info, &zpci_msi= _parent_ops); if (!zbus->msi_parent_domain) { irq_domain_free_fwnode(info.fwnode); @@ -646,6 +643,9 @@ int __init zpci_irq_init(void) if (s390_pci_force_floating) irq_delivery =3D FLOATING; =20 + if (irq_delivery =3D=3D FLOATING) + zpci_msi_parent_ops.required_flags |=3D MSI_FLAG_NO_AFFINITY; + if (irq_delivery =3D=3D DIRECTED) zpci_airq.handler =3D zpci_directed_irq_handler; =20 --=20 2.53.0