Re: [PATCH v2 2/7] s390/pci: Fix resource leak in zpci MSI setup
From: Niklas Schnelle
Date: Tue Oct 06 2026 - 05:59:20 EST
On Mon, 2026-10-05 at 14:03 +0200, Tobias Schumacher wrote:
> If airq_iv_create() fails in __alloc_airq(), the zpci_sbv bit allocated
> by airq_iv_alloc_bit() is never freed. This permanently leaks one of the
> ZPCI_NR_DEVICES summary bits, reducing system capacity with each failed
> device hotplug. In systems with repeated device insertion failures or
> under memory pressure, all summary bits can be exhausted, preventing new
> PCI devices from being added until reboot.
>
> Add proper error handling to free the zpci_sbv bit and reset zdev->aisb
> if the AIBV creation fails.
>
> Fixes: f770950a4709 ("s390/pci: Migrate s390 IRQ logic to IRQ domain API")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Tobias Schumacher <ts@xxxxxxxxxxxxx>
> ---
> arch/s390/pci/pci_irq.c | 5 ++++-
> 1 file changed, 4 insertions(+), 1 deletion(-)
>
> diff --git a/arch/s390/pci/pci_irq.c b/arch/s390/pci/pci_irq.c
> index c9520a16ca75..134f8f4a5cfa 100644
> --- a/arch/s390/pci/pci_irq.c
> +++ b/arch/s390/pci/pci_irq.c
> @@ -313,8 +313,11 @@ static int __alloc_airq(struct zpci_dev *zdev, int msi_vecs,
> zdev->aibv = airq_iv_create(msi_vecs,
> AIRQ_IV_PTR | AIRQ_IV_DATA | AIRQ_IV_BITLOCK,
> NULL);
> - if (!zdev->aibv)
> + if (!zdev->aibv) {
> + airq_iv_free_bit(zpci_sbv, *bit);
> + zdev->aisb = -1UL;
> return -ENOMEM;
> + }
>
> /* Wire up shortcut pointer */
> zpci_ibv[*bit] = zdev->aibv;
Thank you for fixing and sorry for not catching it in the review!
Reviewed-by: Niklas Schnelle <schnelle@xxxxxxxxxxxxx>