Re: [PATCH] sh: intc: sort the prio and sense lists after filling them

From: John Paul Adrian Glaubitz

Date: Sat Oct 03 2026 - 03:51:56 EST


On Sun, 2026-09-27 at 21:13 +0200, Karl Mehltretter wrote:
> register_intc_controller() sorts d->prio and d->sense right after
> allocating them, with hw->nr_prio_regs and hw->nr_sense_regs as the
> element count. The lists hold hw->nr_vectors entries and are only
> filled later, by intc_register_irq().
>
> On SH7785, sh7785-irq0123 and sh7785-irq4567 have four vectors but the
> SoC's eleven priority registers, so sort() swaps 88 bytes in a 32 byte
> kmalloc object at boot. slub_debug=FZPU reports "Right Redzone
> overwritten" in kmalloc-32, and v6.5 and v6.6 panic in
> __kmem_cache_alloc_node() while registering sh7785-irq0123.
>
> Found with a custom QEMU model of the SH7785LCR. On it, v6.4
> sh7785lcr_defconfig boots with SLAB, the defconfig default before v6.5,
> and hangs before the console is up when built with SLUB.
>
> Sort the lists once all vectors are registered, with the number of
> entries that were added.
>
> Fixes: b59f9f9775e6 ("sh: intc: optimize intc IRQ lookup")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: LLM
> Signed-off-by: Karl Mehltretter <kmehltretter@xxxxxxxxx>
> ---
>
> Notes:
> Testing, all in QEMU on a custom SH7785LCR model, not on hardware:
> - v6.5 and v6.6 sh7785lcr_defconfig hang before the console is up
> (gcc 8 and gcc 14). With slub_debug=FZPU they boot and validating
> kmalloc-32 reports "Right Redzone overwritten" after the object
> holding the entries of sh7785-irq4567. With this patch they boot
> and the report is gone.
> - v6.4 sh7785lcr_defconfig (SLAB) boots. The same v6.4 built with SLUB
> hangs, reports the overflow with slub_debug=FZPU, and boots with
> this patch.
> - Current mainline boots with or without the patch, but reports the
> overflow with slub_debug=FZPU unless patched.
> Testing on real hardware is welcome.
>
> drivers/sh/intc/core.c | 11 +++++------
> 1 file changed, 5 insertions(+), 6 deletions(-)
>
> diff --git a/drivers/sh/intc/core.c b/drivers/sh/intc/core.c
> index aa68fe190865d..ffbe60234eefc 100644
> --- a/drivers/sh/intc/core.c
> +++ b/drivers/sh/intc/core.c
> @@ -275,9 +275,6 @@ int __init register_intc_controller(struct intc_desc *desc)
> k += save_reg(d, k, hw->prio_regs[i].set_reg, smp);
> k += save_reg(d, k, hw->prio_regs[i].clr_reg, smp);
> }
> -
> - sort(d->prio, hw->nr_prio_regs, sizeof(*d->prio),
> - intc_handle_int_cmp, NULL);
> }
>
> if (hw->sense_regs) {
> @@ -287,9 +284,6 @@ int __init register_intc_controller(struct intc_desc *desc)
>
> for (i = 0; i < hw->nr_sense_regs; i++)
> k += save_reg(d, k, hw->sense_regs[i].reg, 0);
> -
> - sort(d->sense, hw->nr_sense_regs, sizeof(*d->sense),
> - intc_handle_int_cmp, NULL);
> }
>
> if (hw->subgroups)
> @@ -357,6 +351,11 @@ int __init register_intc_controller(struct intc_desc *desc)
> }
> }
>
> + sort(d->prio, d->nr_prio, sizeof(*d->prio),
> + intc_handle_int_cmp, NULL);
> + sort(d->sense, d->nr_sense, sizeof(*d->sense),
> + intc_handle_int_cmp, NULL);
> +
> intc_subgroup_init(desc, d);
>
> /* enable bits matching force_enable after registering irqs */

Without the patch, a memory leak is reported when booting with slub_debug=FZPU
triggering a validation manually after boot:

root@tirpitz:~> echo 1 > /sys/kernel/slab/kmalloc-32/validate
[ 181.568000] [Right Redzone overwritten] 0x810245c0-0x810245c3 @offset=1472. First byte 0x0 instead of 0xcc
[ 181.568000] =============================================================================
[ 181.568000] BUG kmalloc-32 (Not tainted): Object corrupt
[ 181.568000] -----------------------------------------------------------------------------
[ 181.568000]
[ 181.568000] Slab 0x9ff20480 objects=32 used=32 fp=0x00000000 flags=0x40000000(section=16|zone=0)
[ 181.568000] Object 0x810245a0 @offset=1440 fp=0x00000000
[ 181.568000]
[ 181.568000] Redzone 81024580: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................
[ 181.568000] Redzone 81024590: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................
[ 181.568000] Object 810245a0: 1a 00 00 00 8c 78 06 06 1c 00 00 00 88 78 06 06 .....x.......x..
[ 181.568000] Object 810245b0: 1e 00 00 00 84 78 06 06 10 00 00 00 80 78 06 06 .....x.......x..
[ 181.568000] Redzone 810245c0: 00 00 00 00 ....
[ 181.568000] Padding 810245f4: 00 00 00 00 5a 5a 5a 5a 5a 5a 5a 5a ....ZZZZZZZZ
[ 181.568000] Disabling lock debugging due to kernel taint
[ 181.568000] ------------[ cut here ]------------
[ 181.568000] WARNING: mm/slub.c:1257 at object_err+0x46/0x158, CPU#0: bash/970
[ 181.568000] Modules linked in:
[ 181.568000]
[ 181.568000] CPU: 0 UID: 0 PID: 970 Comm: bash Tainted: G B 7.3.0-rc5-00341-gf6dfa8891d61 #7 PREEMPT
[ 181.568000] Tainted: [B]=BAD_PAGE
[ 181.568000] PC is at object_err+0x46/0x158
[ 181.568000] PR is at object_err+0x46/0x158
[ 181.568000] PC : 80004e3a SP : 86051dcc SR : 400081f1 TEA : c0000010
[ 181.568000] R0 : 00000020 R1 : 8074959c R2 : 00000000 R3 : 00000020
[ 181.568000] R4 : 806becb0 R5 : fa69f078 R6 : 00000000 R7 : 00000000
[ 181.568000] R8 : 810023e0 R9 : 810245a0 R10 : 00000054 R11 : 80004d48
[ 181.568000] R12 : 0000808f R13 : 80004bd4 R14 : 86051dcc
[ 181.568000] MACH: 00000038 MACL: 0002bfa8 GBR : 2957b860 PR : 80004e3a
[ 181.568000]
[ 181.568000] Call trace:
[ 181.568000] [<800ff726>] check_bytes_and_report+0xa2/0xfc
[ 181.568000] [<800ff7e8>] check_object+0x68/0x204
[ 181.568000] [<800ff684>] check_bytes_and_report+0x0/0xfc
[ 181.568000] [<800ffafe>] validate_slab+0xbe/0xf4
[ 181.568000] [<800ffc12>] validate_slab_cache+0xde/0x114
[ 181.568000] [<800ffa40>] validate_slab+0x0/0xf4
[ 181.568000] [<800ffc7e>] validate_store+0x36/0x48
[ 181.568000] [<800fcd82>] slab_attr_store+0x1a/0x22
[ 181.568000] [<80185fcc>] sysfs_kf_write+0x3c/0x58
[ 181.568000] [<80185670>] kernfs_fop_write_iter+0xe6/0x136
[ 181.568000] [<801188b8>] vfs_write+0xd0/0x138
[ 181.568000] [<80118a56>] ksys_write+0x62/0xbc
[ 181.568000] [<80118aba>] sys_write+0xa/0x18
[ 181.568000] [<80118ab0>] sys_write+0x0/0x18
[ 181.568000] [<8001025a>] syscall_call+0x18/0x1e
[ 181.568000]
[ 181.568000] ---[ end trace 0000000000000000 ]---
[ 181.568000] FIX kmalloc-32: Restoring Right Redzone 0x810245c0-0x810245c3=0xcc
[ 181.568000] [Object padding overwritten] 0x810245f4-0x810245f7 @offset=1524. First byte 0x0 instead of 0x5a
[ 181.568000] =============================================================================
[ 181.568000] BUG kmalloc-32 (Tainted: G B W ): Object corrupt
[ 181.568000] -----------------------------------------------------------------------------
[ 181.568000]
[ 181.568000] Slab 0x9ff20480 objects=32 used=32 fp=0x00000000 flags=0x40000000(section=16|zone=0)
[ 181.568000] Object 0x810245a0 @offset=1440 fp=0x00000000
[ 181.568000]
[ 181.568000] Redzone 81024580: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................
[ 181.568000] Redzone 81024590: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc ................
[ 181.568000] Object 810245a0: 1a 00 00 00 8c 78 06 06 1c 00 00 00 88 78 06 06 .....x.......x..
[ 181.568000] Object 810245b0: 1e 00 00 00 84 78 06 06 10 00 00 00 80 78 06 06 .....x.......x..
[ 181.568000] Redzone 810245c0: cc cc cc cc ....
[ 181.568000] Padding 810245f4: 00 00 00 00 5a 5a 5a 5a 5a 5a 5a 5a ....ZZZZZZZZ
[ 181.568000] ------------[ cut here ]------------
[ 181.568000] WARNING: mm/slub.c:1257 at object_err+0x46/0x158, CPU#0: bash/970
[ 181.568000] Modules linked in:
[ 181.568000]
[ 181.568000] CPU: 0 UID: 0 PID: 970 Comm: bash Tainted: G B W 7.3.0-rc5-00341-gf6dfa8891d61 #7 PREEMPT
[ 181.568000] Tainted: [B]=BAD_PAGE, [W]=WARN
[ 181.568000] PC is at object_err+0x46/0x158
[ 181.568000] PR is at object_err+0x46/0x158
[ 181.568000] PC : 80004e3a SP : 86051dcc SR : 400081f1 TEA : c0000010
[ 181.568000] R0 : 00000220 R1 : 8074959c R2 : 00000000 R3 : 00000220
[ 181.568000] R4 : 00000005 R5 : 00000001 R6 : 00000000 R7 : 00000000
[ 181.568000] R8 : 810023e0 R9 : 810245a0 R10 : 00000054 R11 : 80004d48
[ 181.568000] R12 : 0000808f R13 : 80004bd4 R14 : 86051dcc
[ 181.568000] MACH: 00000038 MACL: 0002bfa8 GBR : 2957b860 PR : 80004e3a
[ 181.568000]
[ 181.568000] Call trace:
[ 181.568000] [<800ff726>] check_bytes_and_report+0xa2/0xfc
[ 181.568000] [<800ff8ce>] check_object+0x14e/0x204
[ 181.568000] [<800ff684>] check_bytes_and_report+0x0/0xfc
[ 181.568000] [<800ffafe>] validate_slab+0xbe/0xf4
[ 181.568000] [<800ffc12>] validate_slab_cache+0xde/0x114
[ 181.568000] [<800ffa40>] validate_slab+0x0/0xf4
[ 181.568000] [<800ffc7e>] validate_store+0x36/0x48
[ 181.568000] [<800fcd82>] slab_attr_store+0x1a/0x22
[ 181.568000] [<80185fcc>] sysfs_kf_write+0x3c/0x58
[ 181.568000] [<80185670>] kernfs_fop_write_iter+0xe6/0x136
[ 181.568000] [<801188b8>] vfs_write+0xd0/0x138
[ 181.568000] [<80118a56>] ksys_write+0x62/0xbc
[ 181.568000] [<80118aba>] sys_write+0xa/0x18
[ 181.568000] [<80118ab0>] sys_write+0x0/0x18
[ 181.568000] [<8001025a>] syscall_call+0x18/0x1e
[ 181.568000]
[ 181.568000] ---[ end trace 0000000000000000 ]---
[ 181.568000] FIX kmalloc-32: Restoring Object padding 0x810245f4-0x810245f7=0x5a
root@tirpitz:~>

With the patch applied, no leak is reported after validation:

root@tirpitz:~> echo 1 > /sys/kernel/slab/kmalloc-32/validate
root@tirpitz:~>

Tested-by: John Paul Adrian Glaubitz <glaubitz@xxxxxxxxxxxxxxxxxxx>

Adrian

--
.''`. John Paul Adrian Glaubitz
: :' : Debian Developer
`. `' Physicist
`- GPG: 62FF 8A75 84E0 2956 9546 0006 7426 3B37 F5B5 F913