From nobody Thu Sep 24 13:38:57 2026 Received: from mail-dl2-f12.google.com (mail-dl2-f12.google.com [74.125.229.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 743D240EB81 for ; Wed, 23 Sep 2026 23:42:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.229.140 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790206970; cv=none; b=EYeCVKp2vVqjLBjcMAKbWaDb4iPjyIF3bV/xNuiBADyBWNYLaNTM65DXzzq91KMn1y+zIKinIdAc+PAqZLtft1q/htyCKGML+EBWJyGuyQWMa2KbRwRJdhtakOwlolMS9diKz4MI+uvpiKHsaNiE/dfwRrPb+Lb8Pwb64MffMl4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790206970; c=relaxed/simple; bh=uflvYHIp0CZCGULSPkFw++aiEt8uJY1nRxYvfR7lPmg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=oGLLOT0IY+RuFTjX4QZCsPUYSvqEz9UbpZkhZNegYccAxonFTz+5SaxTIEEIFe6zt5e2yyi+qHNJJTdL8zIbFqQ2q4StLzNiyUfM775HkiGvcClFM0OnqoBjGWVSQeUVcy/RZphYYDPCyd+o8llV8V1PpTG5jdCOBWkjg3oegIw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=om50hVJe; arc=none smtp.client-ip=74.125.229.140 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="om50hVJe" Received: by mail-dl2-f12.google.com with SMTP id a92af1059eb24-142dd025d06so1277159c88.1 for ; Wed, 23 Sep 2026 16:42:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790206967; x=1790811767; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=XLfwo4y4R0vmCrnrfTBSoXmDYXNUSOGgS3Hjd3uog28=; b=om50hVJeCm9+19MkiovuzAVDv4aOhmZ2b2hPEepnA6GJjfR6E6Nn1BPsjocfFM2TFB 29TclM/Qr+UvmirH6vYJBpXVZohIQAHteOQZEHrpUveyzf50Bf/IydrCih8b/chaft4h a+m7mZyoGBa9AsylWToQoFpaaPvHzur7KRTphr2Rqcs1QB7nJSzmYLX1NkCRxtDkHboo k27Sk59lFwKsp9iBUcP8jObLo8v0/28L8bY2umHUqvrBKliiQ7y28iaUBVjZDhZMYSnp a5k7KW0H5yJ9wgh+SNrVaBI3HvVSPpZ9aUobnekBNYh/ZuG1P+3U4F0LB+weVelaoaDJ nQhw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790206967; x=1790811767; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=XLfwo4y4R0vmCrnrfTBSoXmDYXNUSOGgS3Hjd3uog28=; b=2L5K5bkzydAKsw9dWxwKBjTdOBn/mmql+GWyN2Io1vxMzfcKYj2PDYMoKuj9pEY8QD AvZwTeeGPJPBZjVmubTWgVn0+OwrpuoGxjgvCj+c2snyJC1vPC7jaBVF9gvXCxjKvgaM gxCww5xIkip2yJOrLwz+6u3tKOt3K3ID6IL4vr9amRkmKeknIaMhV0XhGcDXJTgZUKkE QXpZyEVT28f+oGrXsJqENHQRtMQ6VhsW5HgLK5VzZDz0BTFE5prF+47N1zNivuc0Svoi DjItItYPHY+0C5E9ngmBvZ0Wkc94SVO+/IIE+5SDXNgYg1dTRJcsGASsf2aNM1r/USQY tZFA== X-Forwarded-Encrypted: i=1; AKwUvByI6duKFwLN80ibhD1xg5OiJ2YwvNLuQrv7Pn+nUZx4FCOu8KIWEyrw1Bpfbey03IfPrXfq3zwr6QmRP+c=@vger.kernel.org X-Gm-Message-State: AFuF++m1acxfXWAp4jWGXnwqEMWmfiuzIW9JY7XbyUjTmXdrayOOXeim GN9IJ8jVUYY9+Uc+9OpfeuS7Q2JW8OgvuhAeSeahkfVQWGH/G0si4ldG1zq89eNf X-Gm-Gg: AYBFou2cHvYdZC6E/4HK0UjY6/vD9uZB4k+ygq9Qxs8P+bwmqy/xfOpjzbxv4VNL75u zKXDahBuUBSnqowtFgYhcooAiLAR3yTDMMHja/+Vw5rhr8GNW31p4EPwMyOACxmSkKFbVr6Honl 5ZaKLQJYrMmNqsxa1NUehGBhfS6nr5QpwLFOGV0jqA5CKJt4ydZy4vvZc2bS3P6zMUecAOAiB+u Z8zvzk2k/PZ2BdM9iW9POxqZUBiODsnuCtG5fe9OL1nunLaXiZOt92/5h1smJ5XZkVhgWQfElbh //wIENngkk+LOMVz8J0pPz5sB63L+dxnWQG2oGjWwpcs2QiBH6QHXnEbX9e9JLHueEawnQoiLJC yrLwfpxjmKdHUflg4ntBGRzOcj/zpbggiwRSu3VX3SP4MAtO5rCcjhMVA66VVXF04yUsR68RBnS pnB3x3wI4Rjag5rm3MvkAlcuQRlks4NWDCbj8SfQKqfh7/dImhBjMw0/fcK5Wdf/Sp0cFSQ1z5u SqxzYU08CcH08L3WJW0V8Ub9pbJC7xUm+Lh X-Received: by 2002:a05:7301:6199:20b0:33b:e74c:e43e with SMTP id 5a478bee46e88-34004b8cd97mr452859eec.19.1790206967392; Wed, 23 Sep 2026 16:42:47 -0700 (PDT) Received: from archsung (186-244-17-112.user3p.vtal.net.br. [186.244.17.112]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33e90ec54d8sm9088502eec.0.2026.09.23.16.42.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 16:42:46 -0700 (PDT) From: Felipe Calliari To: linux-media@vger.kernel.org Cc: Sakari Ailus , Antti Laakso , "Sapre, Sarang" , Mauro Carvalho Chehab , Tomas Moro , linux-kernel@vger.kernel.org, Felipe Calliari , stable@vger.kernel.org Subject: [PATCH 1/2] media: ipu6: Clear the isys ISR hooks when the isys driver goes away Date: Wed, 23 Sep 2026 20:42:23 -0300 Message-ID: <20260923234224.325504-2-calliarifelipe@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260923234224.325504-1-calliarifelipe@gmail.com> References: <20260923234224.325504-1-calliarifelipe@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" isys_probe() points adev->auxdrv and adev->auxdrv_data at data in the isys module, and the buttress interrupt handler calls the isys ISR through them. Neither isys_remove() nor the probe error path clears them. Once intel_ipu6_isys is unloaded, any buttress interrupt dereferences memory of the unloaded module. One way to hit this: the IRQ is shared, so with CONFIG_DEBUG_SHIRQ free_irq() runs the handler once more. If a buttress interrupt status bit is pending at that point, "rmmod intel_ipu6" after "rmmod intel_ipu6_isys" oopses: BUG: unable to handle page fault for address: ffffffffc8a00560 RIP: 0010:ipu6_buttress_isr+0x19b/0x370 [intel_ipu6] Call Trace: free_irq+0x16b/0x360 devres_release+0x37/0x80 devm_free_irq+0x42/0x70 ipu6_pci_remove+0x52/0xd0 [intel_ipu6] This happened on a Samsung Galaxy Book3 Ultra. A module notifier added for testing confirmed that after "rmmod intel_ipu6_isys" the hook still points into the unloaded module, and that it is NULL with this change. Set the hooks only after the last early return of isys_probe(). Clear them on the probe error path and at the end of isys_remove(), then synchronize_irq(). In the buttress handlers, read auxdrv_data once, so that a hook cleared concurrently is seen as NULL rather than dereferenced. Fixes: f50c4ca0a820 ("media: intel/ipu6: add the main input system driver") Cc: stable@vger.kernel.org Signed-off-by: Felipe Calliari --- drivers/media/pci/intel/ipu6/ipu6-buttress.c | 15 ++++++++----- drivers/media/pci/intel/ipu6/ipu6-isys.c | 23 +++++++++++++++++--- 2 files changed, 30 insertions(+), 8 deletions(-) diff --git a/drivers/media/pci/intel/ipu6/ipu6-buttress.c b/drivers/media/p= ci/intel/ipu6/ipu6-buttress.c index 105de1744..63197f746 100644 --- a/drivers/media/pci/intel/ipu6/ipu6-buttress.c +++ b/drivers/media/pci/intel/ipu6/ipu6-buttress.c @@ -315,15 +315,20 @@ ipu6_buttress_ipc_send(struct ipu6_device *isp, =20 static irqreturn_t ipu6_buttress_call_isr(struct ipu6_bus_device *adev) { + const struct ipu6_auxdrv_data *drv_data; irqreturn_t ret =3D IRQ_WAKE_THREAD; =20 - if (!adev || !adev->auxdrv || !adev->auxdrv_data) + if (!adev || !READ_ONCE(adev->auxdrv)) return IRQ_NONE; =20 - if (adev->auxdrv_data->isr) - ret =3D adev->auxdrv_data->isr(adev); + drv_data =3D READ_ONCE(adev->auxdrv_data); + if (!drv_data) + return IRQ_NONE; + + if (drv_data->isr) + ret =3D drv_data->isr(adev); =20 - if (ret =3D=3D IRQ_WAKE_THREAD && !adev->auxdrv_data->isr_threaded) + if (ret =3D=3D IRQ_WAKE_THREAD && !drv_data->isr_threaded) ret =3D IRQ_NONE; =20 return ret; @@ -436,7 +441,7 @@ irqreturn_t ipu6_buttress_isr_threaded(int irq, void *i= sp_ptr) unsigned int i; =20 for (i =3D 0; i < ARRAY_SIZE(adev) && adev[i]; i++) { - drv_data =3D adev[i]->auxdrv_data; + drv_data =3D READ_ONCE(adev[i]->auxdrv_data); if (!drv_data) continue; =20 diff --git a/drivers/media/pci/intel/ipu6/ipu6-isys.c b/drivers/media/pci/i= ntel/ipu6/ipu6-isys.c index 08f29b678..15254e3e3 100644 --- a/drivers/media/pci/intel/ipu6/ipu6-isys.c +++ b/drivers/media/pci/intel/ipu6/ipu6-isys.c @@ -13,6 +13,7 @@ #include #include #include +#include #include #include #include @@ -989,6 +990,18 @@ void ipu6_put_fw_msg_buf(struct ipu6_isys *isys, struc= t isys_fw_msgs *msg) static const struct ipu6_auxdrv_data ipu6_isys_auxdrv_data; static const struct ipu6_auxdrv_data ipu7_isys_auxdrv_data; =20 +/* + * The buttress interrupt handler calls into this driver through + * adev->auxdrv_data, which points into this module. Clear it once the + * device is torn down, and wait for a running handler to finish. + */ +static void isys_unset_auxdrv(struct ipu6_bus_device *adev) +{ + WRITE_ONCE(adev->auxdrv, NULL); + WRITE_ONCE(adev->auxdrv_data, NULL); + synchronize_irq(adev->isp->pdev->irq); +} + static int isys_probe(struct auxiliary_device *auxdev, const struct auxiliary_device_id *auxdev_id) { @@ -1006,9 +1019,6 @@ static int isys_probe(struct auxiliary_device *auxdev, if (!isys) return -ENOMEM; =20 - adev->auxdrv_data =3D IS_IPU7(isp) ? &ipu7_isys_auxdrv_data : - &ipu6_isys_auxdrv_data; - adev->auxdrv =3D to_auxiliary_drv(auxdev->dev.driver); isys->adev =3D adev; isys->pdata =3D adev->pdata; csi2_pdata =3D &isys->pdata->ipdata->csi2; @@ -1037,6 +1047,10 @@ static int isys_probe(struct auxiliary_device *auxde= v, =20 dev_set_drvdata(&auxdev->dev, isys); =20 + adev->auxdrv_data =3D IS_IPU7(isp) ? &ipu7_isys_auxdrv_data : + &ipu6_isys_auxdrv_data; + adev->auxdrv =3D to_auxiliary_drv(auxdev->dev.driver); + isys_stream_init(isys); =20 cpu_latency_qos_add_request(&isys->pm_qos, PM_QOS_DEFAULT_VALUE); @@ -1065,6 +1079,7 @@ static int isys_probe(struct auxiliary_device *auxdev, free_fw_msg_bufs: free_fw_msg_bufs(isys); out_remove_pkg_dir_shared_buffer: + isys_unset_auxdrv(adev); cpu_latency_qos_remove_request(&isys->pm_qos); =20 for (i =3D 0; i < IPU6_ISYS_MAX_STREAMS; i++) @@ -1094,6 +1109,8 @@ static void isys_remove(struct auxiliary_device *auxd= ev) isys_iwake_watermark_cleanup(isys); mutex_destroy(&isys->stream_mutex); mutex_destroy(&isys->mutex); + + isys_unset_auxdrv(auxdev_to_adev(auxdev)); } =20 static const struct ipu6_auxdrv_data ipu6_isys_auxdrv_data =3D { --=20 2.55.0 From nobody Thu Sep 24 13:38:57 2026 Received: from mail-dy2-f26.google.com (mail-dy2-f26.google.com [74.125.229.26]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0BD3B3E7621 for ; Wed, 23 Sep 2026 23:42:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.229.26 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790206973; cv=none; b=eFTLI4S9666EGgFkpdpBZ7sRxoir6UiR2XRrvLq4hF4CDEFL2iIGaP5d7ww0UV0bS9Lg9SQOyhhInGUiV2cgU+eBLlXkqEujHt55flKzZpImy3MX1gYULmVucJIU8tQR5B1qshW4s3FAc6ENg/oN0qKxHEYzzjGKM6tPMUheh3M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790206973; c=relaxed/simple; bh=scApZ48JKByYXRUZuoAY4Adnb7ZBllREjmuuQPO8t9Q=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=stpRPjdt1JKwoxuAh7F96JKpewzA1tHsyeUEZNEDxppBpQ6q23j5HgJgGMpeCH+Br6kqvPExTvfi5l3TQ85VfZDLH1Yki+Rl738mUZKlUTfZo2q2MLOA8y/E2t+33+mV0qFrJtFF8fqmhNgUyqAMxDByVTpBYDQFavco1CPYWJI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=NKPc4Dzk; arc=none smtp.client-ip=74.125.229.26 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="NKPc4Dzk" Received: by mail-dy2-f26.google.com with SMTP id 5a478bee46e88-33175556ebbso883001eec.2 for ; Wed, 23 Sep 2026 16:42:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790206971; x=1790811771; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=slUIx4ec0Cimq2PSOCuDVhE9ZpRT6hWAlORZbx5Y+H0=; b=NKPc4DzkaKK5W5YSGERvMczCWxYJTcu7/b1Yvy9assFL9J4XysT7WqfXnuVUhBr5FC 6Ij/i4QxDqRzqG8GjnaTmZQqZm9L0h0hRlJifr2ANXcNto4Apvh4ucp7aSkCZVfuUc4a ch5laCCNqHWCiRUt93jErBDCJ1NIalHRG55PnBqRtoUAqa+obcCMcf/yJlvLddL/HfWJ 9kcLAcPlk3tnq2C+UtemLYI1dcfPIM/NShkEMxmKonQLcLmStMaiw/c16AiRatP22bLG sY5fnTE+MNkRYv7prKHSb5t0mfNoFrC4L54TLg7b4Cnh1mlpvYgZetQH0wppiUZLtHlc SPWQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790206971; x=1790811771; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=slUIx4ec0Cimq2PSOCuDVhE9ZpRT6hWAlORZbx5Y+H0=; b=Ei3Y/6HB87E67zjF/Ie0PdQsgM5ogyR5AqDisRd76CGbrIGceVXE2kobgfUKH/ZBNQ P37/obuH/V30yCJ8ZKWtpYSlV9sQVS6G8lSZvqdSDzjCWzkt3fQwCau2uMGMUZE0lHAH OgNsHpAv/VqC7HkFsqEP+S+UYTIGTcWsinb2HSCTFm9TRPtsDV5xHWqizcRZOqHMOjyz z4ARt/obXwKZy0XZYCleILBmsf0U+e67JZBhGy3jYqDaMXf14txRsByx52Z7QfPq3Ngt mG/g3lCOuuUGRgBf+XMBo3XU0fcSYzHpRHFI4BzT5UxPryMjbKfm3/rj1l2mnXlz7TPB YD6w== X-Forwarded-Encrypted: i=1; AKwUvBxPbBVsvPfba6atVqrusRWDXK2uBUgAgJSECH6SBk+uP+Fo2SfzrFUZ8EVNnF9Vef11+ANrp2ycA1pAh/M=@vger.kernel.org X-Gm-Message-State: AFuF++kkRB4ZL3oV0m+4Ivfca7p/zyKKSsBi5sajHth0kn/KbcX3UL+7 J8QAtC3Q9rNa1cZ38t1QK/Rgv0B5kfXzxAmdNjm7uE2xKlJV7DB/5rOu5IyF6N4w X-Gm-Gg: AYBFou3CbjDGmLv3JXwEd9m3IzJ6A6ffvr5YTxXYR2IH6mvZ3+pAdXMwmvYIFkF6rLg vKuL5usYfvke00v2EHrbK2m4gtIWnuMWPdZhYtPcfKKp4+8Rn5pTn5W6X8pUcyjK0VyHqRO7zrc DadlTzCRo0tv3sou7M6xwA9m8+MtaibBDTtfcXxm4x1/oJiCunAJWvds63dm0y3k5hrP4/qtUbi YDg6lbyvO7fNQOKI9D/jVeGca32H2VkWg5UzA1O8sQtTuhuWCaIMXV63GiX5Dj5G/ponMsbJdNH gf8b82ECkkLJnYSJOT1fLuaxVD+WBcX/DSdbv8ipLnG+StSMugtmRUaZmhiBFk2wrpCGzA725oh iFgf3+CJxXtabbrvDXbQz19LlGU3kA7hsLgRhhQoqzCPzyiZZ7yKSo1oqAvdZaCEMAAdec45dNX 3YbhY3/Za7veD24Z5A7xSe6whMxXulie7EWX2FCjaHTx7mhHk6bMeo/+9aU1AtlUK5ixMcEuO/7 QvKDPOvmFChktzXoksKtqGJJBpU/UT+u+wz X-Received: by 2002:a05:693c:621a:b0:33b:c69b:7074 with SMTP id 5a478bee46e88-34002be16ccmr527382eec.4.1790206970986; Wed, 23 Sep 2026 16:42:50 -0700 (PDT) Received: from archsung (186-244-17-112.user3p.vtal.net.br. [186.244.17.112]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33e90ec54d8sm9088502eec.0.2026.09.23.16.42.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 16:42:49 -0700 (PDT) From: Felipe Calliari To: linux-media@vger.kernel.org Cc: Sakari Ailus , Antti Laakso , "Sapre, Sarang" , Mauro Carvalho Chehab , Tomas Moro , linux-kernel@vger.kernel.org, Felipe Calliari , stable@vger.kernel.org Subject: [PATCH 2/2] media: ipu6: Only call the isys and psys ISRs for their own interrupts Date: Wed, 23 Sep 2026 20:42:24 -0300 Message-ID: <20260923234224.325504-3-calliarifelipe@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260923234224.325504-1-calliarifelipe@gmail.com> References: <20260923234224.325504-1-calliarifelipe@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" ipu6_buttress_isr() calls the isys and psys ISRs on every buttress interrupt, and only afterwards checks whether the interrupt was theirs. So each isys interrupt also runs the psys ISR, and each psys interrupt runs the isys ISR, only to have the result discarded. Beyond the wasted work, this makes an interrupt for one device dereference the other device's hooks. After intel_ipu6_psys is unloaded, its adev->auxdrv_data still points into the unloaded module, and every isys interrupt, e.g. on the next stream, calls through it. This matches a hard lockup without a trace reported on the first stream after unloading the psys driver. On a Samsung Galaxy Book3 Ultra, instrumenting the ISR showed that a 60-frame capture after "rmmod intel_ipu6_psys" would have made at least ten calls through the stale psys hooks. The same capture made none with this change, and captured all 60 frames. Check the interrupt status bit before calling the ISR. Reported-by: Mars-Wave Closes: https://lore.kernel.org/linux-media/20260922063507.690-1-tmorolias@= gmail.com/ Fixes: ab29a2478e70 ("media: intel/ipu6: add IPU6 buttress interface driver= ") Cc: stable@vger.kernel.org Signed-off-by: Felipe Calliari --- drivers/media/pci/intel/ipu6/ipu6-buttress.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/media/pci/intel/ipu6/ipu6-buttress.c b/drivers/media/p= ci/intel/ipu6/ipu6-buttress.c index 63197f746..74c191d72 100644 --- a/drivers/media/pci/intel/ipu6/ipu6-buttress.c +++ b/drivers/media/pci/intel/ipu6/ipu6-buttress.c @@ -369,11 +369,13 @@ irqreturn_t ipu6_buttress_isr(int irq, void *isp_ptr) writel(irq_status, isp->base + regs->irq_clear); =20 for (i =3D 0; i < ARRAY_SIZE(adev_irq_mask); i++) { - irqreturn_t r =3D ipu6_buttress_call_isr(adev[i]); + irqreturn_t r; =20 if (!(irq_status & adev_irq_mask[i])) continue; =20 + r =3D ipu6_buttress_call_isr(adev[i]); + if (r =3D=3D IRQ_WAKE_THREAD) { ret =3D IRQ_WAKE_THREAD; disable_irqs |=3D adev_irq_mask[i]; --=20 2.55.0