Re: [PATCH v2 3/7] s390/pci: Fix MSI directed-mode teardown IRQ bit count
From: Niklas Schnelle
Date: Tue Oct 06 2026 - 07:14:59 EST
On Mon, 2026-10-05 at 14:03 +0200, Tobias Schumacher wrote:
> On s390 with directed interrupts enabled, zpci_msi_teardown_directed()
> frees the platform's maximum number of MSI bits (zdev->max_msi) instead
> of the actual allocated count (zdev->msi_nr_irqs). This corrupts the
> shared IRQ bitmap used by all PCI functions, causing lost interrupts and
> heap corruption. Fix zpci_msi_teardown_directed() to only free the
> actual allocated IRQ bit count.
>
> Fixes: f770950a4709 ("s390/pci: Migrate s390 IRQ logic to IRQ domain API")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Tobias Schumacher <ts@xxxxxxxxxxxxx>
> ---
> arch/s390/pci/pci_irq.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/arch/s390/pci/pci_irq.c b/arch/s390/pci/pci_irq.c
> index 134f8f4a5cfa..d5763c5feb09 100644
> --- a/arch/s390/pci/pci_irq.c
> +++ b/arch/s390/pci/pci_irq.c
> @@ -342,7 +342,7 @@ static struct airq_struct zpci_airq = {
>
> static void zpci_msi_teardown_directed(struct zpci_dev *zdev)
> {
> - airq_iv_free(zpci_ibv[0], zdev->msi_first_bit, zdev->max_msi);
> + airq_iv_free(zpci_ibv[0], zdev->msi_first_bit, zdev->msi_nr_irqs);
> zdev->msi_first_bit = -1U;
> zdev->msi_nr_irqs = 0;
> }
Good catch and fix looks good to me.
Reviewed-by: Niklas Schnelle <schnelle@xxxxxxxxxxxxx>