Re: [PATCH v3 4/8] irqchip/al-fic: switch to shared parent interrupt

From: Radu Rendec

Date: Wed Oct 07 2026 - 21:06:23 EST


On Mon, 2026-10-05 at 11:24 +0000, Eliav Farber wrote:
> Until now the driver requested its parent interrupt using the chained IRQ
> API (irq_set_chained_handler_and_data()), which only works when each
> parent interrupt is wired to a single FIC instance.
>
> A FIC controller is built from groups, each described by its own DT node,
> and the groups of one controller share that controller's output line
> toward the parent. So a real devicetree has several FIC nodes on one
> parent GIC SPI, and a chained handler can only be installed once per
> parent. Cascading compounds this: an aggregating group collects several
> peripherals' outputs onto the line above it.
>
> To support that, request the parent interrupt as a shared interrupt
> (IRQF_SHARED) instead of installing a chained handler. The handler now has
> the standard irqreturn_t prototype and reports whether this instance had
> anything pending, so the shared-IRQ core can tell which instance on the
> line raised the interrupt. IRQF_NO_THREAD is set because the handler only
> demultiplexes to the child domain and must not be forced-threaded; all
> instances sharing a parent line agree on this flag, as the shared-IRQ core
> requires.
>
> The handler reads the group's cause register and returns IRQ_HANDLED when
> any unmasked cause bit is set, IRQ_NONE otherwise. That is the signal the
> shared-IRQ core needs - "did this instance's hardware raise the line" -
> rather than the result of dispatching to the child domain, which for a
> domain sized exactly to the cause register always succeeds.
>
> request_irq() can fail, unlike irq_set_chained_handler_and_data(), so add
> an error path for it. Set IRQ_DOMAIN_FLAG_DESTROY_GC on the domain after
> creating it, so irq_domain_remove() tears the generic chips down too and
> the single call suffices for both the chip-allocation and request_irq()
> failure paths.
>
> Co-developed-by: Talel Shenhar <talel@xxxxxxxxxx>
> Signed-off-by: Talel Shenhar <talel@xxxxxxxxxx>
> Signed-off-by: Eliav Farber <farbere@xxxxxxxxxx>
> ---
> v3:
>  - al_fic_irq_handler() no longer derives IRQ_HANDLED/IRQ_NONE from
>    generic_handle_domain_irq(), whose return value only reports whether
>    the hwirq to virq mapping succeeded - and since the loop iterates
>    exactly NR_FIC_IRQS bits, which is the domain's own size, that mapping
>    always succeeds. Return IRQ_HANDLED when the masked CAUSE snapshot is
>    non-zero instead, which is the correct signal for a shared interrupt.
>  - Set IRQ_DOMAIN_FLAG_DESTROY_GC on the domain and let
>    irq_domain_remove() free the generic chips, instead of calling
>    irq_domain_remove_generic_chips() by hand. Both error paths now go
>    through one label. The invalid-free fix from v2 is unaffected; only the
>    teardown mechanism changed.
>  - Use of_node_full_name() in the request_irq() call.
>
> v2:
>  - Fix the request_irq() error path: v1 called irq_free_generic_chip(gc),
>    which is kfree(gc) on an interior pointer into the single allocation
>    made by irq_domain_alloc_generic_chips() - an invalid free reachable
>    when request_irq() fails at probe. Replace it with
>    irq_domain_remove_generic_chips() before irq_domain_remove(), and add a
>    commit-message paragraph explaining the teardown ordering.
>  - Add Co-developed-by/Signed-off-by: Talel Shenhar.
>  - Reworded to state the hardware reason for the shared parent (the groups
>    of one controller share that controller's output line).
>
>  drivers/irqchip/irq-al-fic.c | 28 ++++++++++++++++++----------
>  1 file changed, 18 insertions(+), 10 deletions(-)
>
> diff --git a/drivers/irqchip/irq-al-fic.c b/drivers/irqchip/irq-al-fic.c
> index ee06d0123b7a..4c60da8558ed 100644
> --- a/drivers/irqchip/irq-al-fic.c
> +++ b/drivers/irqchip/irq-al-fic.c
> @@ -4,9 +4,9 @@
>   */
>  
>  #include <linux/bitfield.h>
> +#include <linux/interrupt.h>
>  #include <linux/irq.h>
>  #include <linux/irqchip.h>
> -#include <linux/irqchip/chained_irq.h>
>  #include <linux/irqdomain.h>
>  #include <linux/module.h>
>  #include <linux/of.h>
> @@ -95,24 +95,21 @@ static int al_fic_irq_set_type(struct irq_data *data, unsigned int flow_type)
>   return 0;
>  }
>  
> -static void al_fic_irq_handler(struct irq_desc *desc)
> +static irqreturn_t al_fic_irq_handler(int irq, void *data)
>  {
> - struct al_fic *fic = irq_desc_get_handler_data(desc);
> + struct al_fic *fic = data;
>   struct irq_domain *domain = fic->domain;
> - struct irq_chip *irqchip = irq_desc_get_chip(desc);
>   struct irq_chip_generic *gc = irq_get_domain_generic_chip(domain, 0);
>   unsigned long pending;
>   u32 hwirq;
>  
> - chained_irq_enter(irqchip, desc);
> -
>   pending = readl_relaxed(fic->base + AL_FIC_CAUSE);
>   pending &= ~gc->mask_cache;
>  
>   for_each_set_bit(hwirq, &pending, NR_FIC_IRQS)
>   generic_handle_domain_irq(domain, hwirq);
>  
> - chained_irq_exit(irqchip, desc);
> + return pending ? IRQ_HANDLED : IRQ_NONE;
>  }
>  
>  static int al_fic_irq_retrigger(struct irq_data *data)
> @@ -140,6 +137,12 @@ static int al_fic_register(struct device_node *node,
>   return -ENOMEM;
>   }
>  
> + /*
> + * Let irq_domain_remove() free the generic chips on either error path
> + * below, instead of calling irq_domain_remove_generic_chips() by hand.
> + */
> + fic->domain->flags |= IRQ_DOMAIN_FLAG_DESTROY_GC;
> +
>   ret = irq_alloc_domain_generic_chips(fic->domain,
>        NR_FIC_IRQS,
>        1, of_node_full_name(fic->node),
> @@ -162,9 +165,14 @@ static int al_fic_register(struct device_node *node,
>   gc->chip_types->chip.flags = IRQCHIP_SKIP_SET_WAKE;
>   gc->private = fic;
>  
> - irq_set_chained_handler_and_data(fic->parent_irq,
> - al_fic_irq_handler,
> - fic);
> + ret = request_irq(fic->parent_irq, al_fic_irq_handler,
> +   IRQF_NO_THREAD | IRQF_SHARED,
> +   of_node_full_name(fic->node), fic);
> + if (ret) {
> + pr_err("fail to request irq (%d)\n", ret);
> + goto err_domain_remove;
> + }
> +
>   return 0;
>  
>  err_domain_remove:

Reviewed-by: Radu Rendec <radu@xxxxxxxxxx>