Re: [PATCH v5 01/13] gpio: mxc: fix race between chained IRQ handler install and probe completion

From: Frank Li

Date: Fri Oct 09 2026 - 14:48:02 EST


On Sat, Oct 10, 2026 at 02:05:22AM +0800, Peng Fan (OSS) wrote:
> From: Peng Fan <peng.fan@xxxxxxx>
>
> mxc_update_irq_chained_handler() is called before the IRQ domain, the
> generic IRQ chip, and the port list entry are set up. If an interrupt
> arrives in that window:
>
> - mx3_gpio_irq_handler() calls generic_handle_domain_irq() with
> port->domain still NULL.
> - mx2_gpio_irq_handler() walks mxc_gpio_ports, but the port has not
> been added to the list yet.
>
> Additionally, if any of the subsequent probe steps
> (gpio_generic_chip_init(), devm_gpiochip_add_data(),
> irq_domain_create_legacy(), or mxc_gpio_init_gc()) fail, the error
> paths never unregister the chained handler, leaving a dangling handler
> that points at freed memory.
>
> Move the handler installation after all its dependencies are ready and
> after list_add_tail(), so the handler is never live while the data
> structures it touches are incomplete, and is never installed if probe
> fails.
>
> Fixes: 5f6d1998adeb ("gpio: mxc: release the parent IRQ in runtime suspend")
> Assisted-by: LLM
> Signed-off-by: Peng Fan <peng.fan@xxxxxxx>
> ---

Reviewed-by: Frank Li <Frank.Li@xxxxxxx>


> drivers/gpio/gpio-mxc.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/gpio/gpio-mxc.c b/drivers/gpio/gpio-mxc.c
> index 7e2690d92df6..e05f276a50e8 100644
> --- a/drivers/gpio/gpio-mxc.c
> +++ b/drivers/gpio/gpio-mxc.c
> @@ -474,8 +474,6 @@ static int mxc_gpio_probe(struct platform_device *pdev)
> } else
> port->mx_irq_handler = mx3_gpio_irq_handler;
>
> - mxc_update_irq_chained_handler(port, true);
> -
> config.dev = &pdev->dev;
> config.sz = 4;
> config.dat = port->base + GPIO_PSR;
> @@ -525,6 +523,8 @@ static int mxc_gpio_probe(struct platform_device *pdev)
>
> list_add_tail(&port->node, &mxc_gpio_ports);
>
> + mxc_update_irq_chained_handler(port, true);
> +
> platform_set_drvdata(pdev, port);
> pm_runtime_put_autosuspend(&pdev->dev);
>
>
> --
> 2.51.0
>
>