[PATCH v2 0/7] s390/pci: Fix bugs in IRQ domain migration and resource cleanup

From: Tobias Schumacher

Date: Mon Oct 05 2026 - 08:06:26 EST


Commit f770950a4709 ("s390/pci: Migrate s390 IRQ logic to IRQ
domain API") introduced several bugs in error handling and cleanup
paths. This series fixes these issues:

1. Double-free and NULL dereference in the parent MSI domain cleanup
2. Leak of a zpci_sbv summary bit when AIBV creation fails
3. Directed-mode teardown freeing zdev->max_msi bits instead of the
zdev->msi_nr_irqs bits that were allocated
4. Use-after-free race between floating IRQ delivery and teardown

Patch 5 is unrelated to the migration. zpci_directed_irq_init() has
leaked its allocations on the -ENOMEM paths since it was added in
e979ce7bced2 ("s390/pci: provide support for CPU directed interrupts").

Patch 6 is a cleanup that removes an unnecessary update of
zpci_msi_parent_ops from the per-bus domain creation path.

Patch 7 is a cleanup that drops the unused index argument of
zpci_msi_clear_airq(). The doubled index it removes never selected a
wrong entry, so it is not a fix.

Patches 1 to 4 carry Cc: stable. Patches 5 to 7 do not: patch 5 only
affects a boot-time allocation failure, and patches 6 and 7 change no
behaviour.

Signed-off-by: Tobias Schumacher <ts@xxxxxxxxxxxxx>
---
Changes in v2:
- Capitalize the word after the "s390/pci:" prefix on all subjects
- Replace the "add NULL check in zpci_msi_clear_airq()" patch with a
cleanup that drops the unused index argument, and move it to the end
of the series
- Patch 4: clear zpci_ibv[] before the grace period, free the summary
bit after it, publish with rcu_assign_pointer()
- Patch 5: correct the Fixes: tag, drop Cc: stable
- Link to v1: https://lore.kernel.org/r/20260819-s390_irq_domain_fixes-v1-0-826ff27b6e97@xxxxxxxxxxxxx

---
Tobias Schumacher (7):
s390/pci: Fix double-free and NULL deref in zpci MSI domain cleanup
s390/pci: Fix resource leak in zpci MSI setup
s390/pci: Fix MSI directed-mode teardown IRQ bit count
s390/pci: Fix use-after-free race in zpci floating interrupt cleanup
s390/pci: Add error cleanup in zpci_directed_irq_init
s390/pci: Set MSI_FLAG_NO_AFFINITY at IRQ init time
s390/pci: Drop the unused index argument of zpci_msi_clear_airq()

arch/s390/pci/pci_irq.c | 99 +++++++++++++++++++++++++++++++------------------
1 file changed, 62 insertions(+), 37 deletions(-)
---
base-commit: a90ee4305c4a5df72c11b31dacfdc76e00fcf78a
change-id: 20260818-s390_irq_domain_fixes-ad74b3134c51

Best regards,
--
Tobias Schumacher <ts@xxxxxxxxxxxxx>