[PATCH 00/16] irqchip: harden initialization error paths

Haofeng Li lihaofeng at kylinos.cn
Tue Jul 14 05:23:35 PDT 2026


An audit of irqchip initialization and allocation error paths found a
collection of resource leaks and lifetime issues across several drivers.

The most serious cases leave interrupt handlers or other globally visible
state pointing at memory that is subsequently freed or unmapped.  Other
cases leak IRQ domains, parent mappings, MMIO mappings, allocation bitmap
regions, or allocated objects when initialization fails part-way through.
The series also fixes an unbounded IMSIC MMIO lookup, a possible NULL MMIO
access in the NVIDIA T241 workaround, and two cases where useful error
information is lost or reported incorrectly.

The changes are confined to failure handling; successful initialization
paths are left unchanged.  The MIPS GIC fixes in patches 7 and 8 build on
each other, as do the Realtek RTL fixes in patches 12 and 13.  The remaining
patches are independent.

The issues addressed are:

  - bound MMIO lookup and make allocation cleanup NULL-safe;
  - roll back partially allocated IRQs, domains and bitmap regions;
  - do not free or unmap state after it has been published to live users;
  - distinguish managed from unmanaged MMIO mappings during cleanup;
  - release parent IRQ mappings, per-CPU mappings and OF node references;
  - preserve deferred-probe errors and report the correct reset error.

Haofeng Li (16):
  irqchip/riscv-imsic: fix MMIO lookup OOB and NULL cleanup
  irqchip/loongarch-ir: fix redirect free and alloc leaks
  irqchip/sifive-plic: do not iounmap devm mappings
  irqchip/crossbar: fix allocation and init cleanup
  irqchip/bcm7038-l1: clean up init failure paths
  irqchip/loongson-liointc: unmap per-core iomaps on error
  irqchip/mips-gic: clean up IRQ domain creation failure
  irqchip/mips-gic: clean up if IPI domain registration fails
  irqchip/econet: clean up VEIC initialization
  irqchip/aspeed-vic: publish handler only after domain creation
  irqchip/loongson-eiointc: preserve live state on cascade failure
  irqchip/realtek-rtl: unmap per-CPU bases on init failure
  irqchip/realtek-rtl: dispose parent mapping on domain failure
  irqchip/renesas-rzg2l: fix wrong errno in reset error log
  irqchip/gic-v3: fail T241 quirk if alias ioremap fails
  irqchip/bcm7120-l2: fix parent IRQ count error handling

 drivers/irqchip/irq-aspeed-vic.c        | 23 ++++++++++++++----
 drivers/irqchip/irq-bcm7038-l1.c        | 24 +++++++++++++++----
 drivers/irqchip/irq-bcm7120-l2.c        |  8 +++++--
 drivers/irqchip/irq-crossbar.c          | 23 ++++++++++++++++--
 drivers/irqchip/irq-econet-en751221.c   |  5 +++-
 drivers/irqchip/irq-gic-v3.c            | 11 ++++++++-
 drivers/irqchip/irq-loongarch-ir.c      | 21 +++++++++++++++--
 drivers/irqchip/irq-loongson-eiointc.c  | 13 ++++++-----
 drivers/irqchip/irq-loongson-liointc.c  |  8 +++++++
 drivers/irqchip/irq-mips-gic.c          | 31 +++++++++++++++----------
 drivers/irqchip/irq-realtek-rtl.c       | 28 ++++++++++++++++++----
 drivers/irqchip/irq-renesas-rzg2l.c     |  2 +-
 drivers/irqchip/irq-riscv-imsic-state.c | 12 ++++++----
 drivers/irqchip/irq-sifive-plic.c       |  4 +++-
 14 files changed, 168 insertions(+), 45 deletions(-)


base-commit: a13c140cc289c0b7b3770bce5b3ad42ab35074aa
-- 
2.25.1



More information about the linux-riscv mailing list