Re: [PATCH v2 4/7] s390/pci: Fix use-after-free race in zpci floating interrupt cleanup
From: Tobias Schumacher
Date: Wed Oct 07 2026 - 01:51:19 EST
On Tue Oct 6, 2026 at 5:18 PM CEST, Niklas Schnelle wrote:
> On Mon, 2026-10-05 at 14:03 +0200, Tobias Schumacher wrote:
-- snip --
>> zpci_ibv served both delivery modes, indexed by summary bit under
>
> Nit: Maybe more precisely and matching the comment: "…, indexed by
> function under FLOATING and …"?
Agreed, will change that for v3.
> --- snip ---
>> static void zpci_msi_teardown_floating(struct zpci_dev *zdev)
>> {
>> + rcu_assign_pointer(zpci_ibv[zdev->aisb], NULL);
>> + synchronize_rcu();
>> + airq_iv_free_bit(zpci_sbv, zdev->aisb);
>> +
>> airq_iv_release(zdev->aibv);
>> zdev->aibv = NULL;
>> - airq_iv_free_bit(zpci_sbv, zdev->aisb);
>
> Not sure why the aisb free moved to before the aibv release? The commit
> message only explains why it is after the synchronize_rcu(). This way
> it's also not in the opposite order of the allocation.
No reason, this ordering change is a leftover of a previous fix attempt.
I'll move it back so the teardown mirrors the allocation again for v3.
Thanks,
Tobias