Re: [PATCH] misc: ocxl: cancel XSL fault work before freeing SPA

From: Greg KH

Date: Thu Oct 01 2026 - 08:09:50 EST


On Mon, Sep 28, 2026 at 09:41:10PM +0800, Hongyan Xu wrote:
> The XSL fault interrupt takes an mm reference and queues fault_work
> embedded in the SPA. free_irq() stops new interrupt handlers but does
> not drain an already queued worker, allowing free_spa() to release its
> container first.
>
> Cancel the work after freeing the interrupt. When cancellation removes a
> pending instance, also drop the mm reference that the worker would have
> released.
>
> Fixes: 5ef3166e8a32 ("ocxl: Driver code for 'generic' opencapi devices")
> Signed-off-by: Hongyan Xu <getshell@xxxxxxxxxx>
> ---
> drivers/misc/ocxl/link.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/drivers/misc/ocxl/link.c b/drivers/misc/ocxl/link.c
> index 7749dcd16117..8146e98e77e7 100644
> --- a/drivers/misc/ocxl/link.c
> +++ b/drivers/misc/ocxl/link.c
> @@ -335,6 +335,8 @@ static void release_xsl_irq(struct ocxl_link *link)
>
> if (spa->virq) {
> free_irq(spa->virq, link);
> + if (cancel_work_sync(&spa->xsl_fault.fault_work))
> + mmput(spa->xsl_fault.pe_data.mm);
> irq_dispose_mapping(spa->virq);
> }
> kfree(spa->irq_name);
> --
> 2.50.1.windows.1
>

How was this found and tested?

thanks,

greg k-h