Re: [PATCH 1/9] gpio: mxc: fix race between chained IRQ handler install and probe completion

From: Andy Shevchenko

Date: Sat Oct 03 2026 - 13:36:57 EST


On Sat, Oct 3, 2026 at 3:09 PM Peng Fan (OSS) <peng.fan@xxxxxxxxxxx> wrote:

> mxc_update_irq_chained_handler() is called before the IRQ domain, the
> generic IRQ chip, and the port list entry are set up. If an interrupt
> arrives in that window:
>
> - mx3_gpio_irq_handler() calls generic_handle_domain_irq() with
> port->domain still NULL.
> - mx2_gpio_irq_handler() walks mxc_gpio_ports, but the port has not
> been added to the list yet.
>
> Additionally, if any of the subsequent probe steps (gpio_generic_chip_init,
> devm_gpiochip_add_data, irq_domain_create_legacy, or mxc_gpio_init_gc)

We refer to the functions as func(), like you have done above, but here...
(No need to resend just for this.)

> fail, the error paths never unregister the chained handler, leaving a
> dangling handler that points at freed memory.
>
> Move the handler installation after all its dependencies are ready and
> after list_add_tail(), so the handler is never live while the data
> structures it touches are incomplete, and is never installed if probe
> fails.

--
With Best Regards,
Andy Shevchenko