Re: [PATCH v2 4/7] s390/pci: Fix use-after-free race in zpci floating interrupt cleanup

From: Tobias Schumacher

Date: Wed Oct 07 2026 - 02:03:11 EST


On Tue Oct 6, 2026 at 9:23 PM CEST, Niklas Schnelle wrote:
> On Mon, 2026-10-05 at 14:03 +0200, Tobias Schumacher wrote:

> --- snip ---

>> @@ -660,10 +664,12 @@ void __init zpci_irq_exit(void)
>>
>> if (irq_delivery == DIRECTED) {
>> for_each_possible_cpu(cpu) {
>> - airq_iv_release(zpci_ibv[cpu]);
>> + airq_iv_release(zpci_dibv[cpu]);
>> }
>> + kfree(zpci_dibv);
>> + } else {
>> + kfree(zpci_ibv);
>> }
>> - kfree(zpci_ibv);
>> if (zpci_sbv)
>> airq_iv_release(zpci_sbv);
>> unregister_adapter_interrupt(&zpci_airq);
>
> This is pre-existing but my additional LLM review noticed it. It
> seems like a theoretical race and against the reverse cleanup vs setup
> rule, that kfree(zpci_ibv) is done before
> unregister_adapter_interrupt().

Good point. Since this goes back to the original adapter interrput code,
I'll probably add a separate patch in v3.

Thanks,
Tobias