Skip to content

Commit 98bf7e5

Browse files
Qingshuang FuThomas Gleixner
authored andcommitted
irqchip/ts4800: Fix missing chained handler cleanup on remove
The driver installs a chained handler for the parent interrupt during probe using irq_set_chained_handler_and_data(), but the remove function does not clear this handler. This leaves a dangling handler that may be called when the parent interrupt fires after the driver has been removed, potentially accessing freed memory and causing a kernel crash. Additionally, the parent_irq obtained via irq_of_parse_and_map() is not stored, making it inaccessible in the remove function. Moreover, interrupt mappings created during probe are not properly disposed. Fix this by: - Saving parent_irq in probe - Clearing the chained handler with NULL in ts4800_ic_remove() - Disposing all IRQ mappings before domain removal to prevent resource leaks Fixes: d01f863 ("irqchip/ts4800: Add TS-4800 interrupt controller") Signed-off-by: Qingshuang Fu <fuqingshuang@kylinos.cn> Signed-off-by: Thomas Gleixner <tglx@kernel.org> Link: https://patch.msgid.link/20260623015211.109382-1-fffsqian@163.com
1 parent 2e1368a commit 98bf7e5

1 file changed

Lines changed: 10 additions & 0 deletions

File tree

drivers/irqchip/irq-ts4800.c

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,7 @@ struct ts4800_irq_data {
2828
void __iomem *base;
2929
struct platform_device *pdev;
3030
struct irq_domain *domain;
31+
unsigned int parent_irq;
3132
};
3233

3334
static void ts4800_irq_mask(struct irq_data *d)
@@ -134,6 +135,7 @@ static int ts4800_ic_probe(struct platform_device *pdev)
134135
irq_set_chained_handler_and_data(parent_irq,
135136
ts4800_ic_chained_handle_irq, data);
136137

138+
data->parent_irq = parent_irq;
137139
platform_set_drvdata(pdev, data);
138140

139141
return 0;
@@ -142,6 +144,14 @@ static int ts4800_ic_probe(struct platform_device *pdev)
142144
static void ts4800_ic_remove(struct platform_device *pdev)
143145
{
144146
struct ts4800_irq_data *data = platform_get_drvdata(pdev);
147+
unsigned int hwirq;
148+
149+
irq_set_chained_handler_and_data(data->parent_irq, NULL, NULL);
150+
151+
for (hwirq = 0; hwirq < 8; hwirq++)
152+
irq_dispose_mapping(irq_find_mapping(data->domain, hwirq));
153+
154+
irq_dispose_mapping(data->parent_irq);
145155

146156
irq_domain_remove(data->domain);
147157
}

0 commit comments

Comments
 (0)