Re: [PATCH iwl-net 02/10] ice: fix IRQ freeing in ice_vsi_req_irq_msix() error path

From: Ivan Vecera

Date: Sat Oct 03 2026 - 05:54:33 EST


On October 2, 2026 3:07:44 PM GMT+02:00, Petr Oros <poros@xxxxxxxxxx> wrote:
>The vectors are requested with the q_vector as dev_id, but the error
>path frees them with &vsi->q_vectors[vector], which is the address of
>the array slot. devm_free_irq() finds no matching devres entry, warns
>and leaves the IRQ requested. The unwind also tries to free vectors that
>the request loop skipped because they have no rings.
>
>Forcing request_irq to fail on the fourth vector during ndo_open gives:
>
> ice 0000:04:00.2 enp4s0f2np2: MSIX request_irq failed, error: -16
> WARNING: kernel/irq/devres.c:191 at devm_free_irq+0x30/0x40
> WARNING: kernel/irq/devres.c:191 at devm_free_irq+0x30/0x40
> WARNING: kernel/irq/devres.c:191 at devm_free_irq+0x30/0x40
>
>and the three IRQs stay registered in /proc/interrupts while the
>interface is down.
>
>Pass the q_vector as dev_id and skip the vectors without rings, which
>the request loop never requested.
>
>i40e fixed the same mistake in commit 915470e1b44e ("i40e: fix IRQ
>freeing in i40e_vsi_request_irq_msix error path").
>
>Fixes: cdedef59deb0 ("ice: Configure VSIs for Tx/Rx")
>Assisted-by: LLM
>Signed-off-by: Petr Oros <poros@xxxxxxxxxx>
>---
> drivers/net/ethernet/intel/ice/ice_main.c | 8 ++++++--
> 1 file changed, 6 insertions(+), 2 deletions(-)
>
>diff --git a/drivers/net/ethernet/intel/ice/ice_main.c b/drivers/net/ethernet/intel/ice/ice_main.c
>index f2121e79fca993..d246cde36ae726 100644
>--- a/drivers/net/ethernet/intel/ice/ice_main.c
>+++ b/drivers/net/ethernet/intel/ice/ice_main.c
>@@ -2582,8 +2582,12 @@ static int ice_vsi_req_irq_msix(struct ice_vsi *vsi, char *basename)
>
> free_q_irqs:
> while (vector--) {
>- irq_num = vsi->q_vectors[vector]->irq.virq;
>- devm_free_irq(dev, irq_num, &vsi->q_vectors[vector]);
>+ struct ice_q_vector *q_vector = vsi->q_vectors[vector];
>+
>+ if (!q_vector->tx.tx_ring && !q_vector->rx.rx_ring)
>+ continue;
>+
>+ devm_free_irq(dev, q_vector->irq.virq, q_vector);
> }
> return err;
> }

Reviewed-by: Ivan Vecera <ivecera@xxxxxxxxxx>