]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
genirq: Unlock irq descriptor after errors
authorGuenter Roeck <linux@roeck-us.net>
Tue, 11 Aug 2020 18:00:12 +0000 (11:00 -0700)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 21 Aug 2020 11:14:46 +0000 (13:14 +0200)
commit f107cee94ba4d2c7357fde59a1d84346c73d4958 upstream.

In irq_set_irqchip_state(), the irq descriptor is not unlocked after an
error is encountered. While that should never happen in practice, a buggy
driver may trigger it. This would result in a lockup, so fix it.

Fixes: 1d0326f352bb ("genirq: Check irq_data_get_irq_chip() return value before use")
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/r/20200811180012.80269-1-linux@roeck-us.net
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
kernel/irq/manage.c

index 48c38e09c6733614e3a9d0ae19d77b9d685a36a3..e68a8f993106507385fdcf0fd97e7c3a416014c2 100644 (file)
@@ -2735,8 +2735,10 @@ int irq_set_irqchip_state(unsigned int irq, enum irqchip_irq_state which,
 
        do {
                chip = irq_data_get_irq_chip(data);
-               if (WARN_ON_ONCE(!chip))
-                       return -ENODEV;
+               if (WARN_ON_ONCE(!chip)) {
+                       err = -ENODEV;
+                       goto out_unlock;
+               }
                if (chip->irq_set_irqchip_state)
                        break;
 #ifdef CONFIG_IRQ_DOMAIN_HIERARCHY
@@ -2749,6 +2751,7 @@ int irq_set_irqchip_state(unsigned int irq, enum irqchip_irq_state which,
        if (data)
                err = chip->irq_set_irqchip_state(data, which, val);
 
+out_unlock:
        irq_put_desc_busunlock(desc, flags);
        return err;
 }