On Mon, Sep 28, 2026 at 09:41:10PM +0800, Hongyan Xu wrote:
> The XSL fault interrupt takes an mm reference and queues fault_work
> embedded in the SPA. free_irq() stops new interrupt handlers but does
> not drain an already queued worker, allowing free_spa() to release its
> container first.
> 
> Cancel the work after freeing the interrupt. When cancellation removes a
> pending instance, also drop the mm reference that the worker would have
> released.
> 
> Fixes: 5ef3166e8a32 ("ocxl: Driver code for 'generic' opencapi devices")
> Signed-off-by: Hongyan Xu <[email protected]>
> ---
>  drivers/misc/ocxl/link.c | 2 ++
>  1 file changed, 2 insertions(+)
> 
> diff --git a/drivers/misc/ocxl/link.c b/drivers/misc/ocxl/link.c
> index 7749dcd16117..8146e98e77e7 100644
> --- a/drivers/misc/ocxl/link.c
> +++ b/drivers/misc/ocxl/link.c
> @@ -335,6 +335,8 @@ static void release_xsl_irq(struct ocxl_link *link)
>  
>       if (spa->virq) {
>               free_irq(spa->virq, link);
> +             if (cancel_work_sync(&spa->xsl_fault.fault_work))
> +                     mmput(spa->xsl_fault.pe_data.mm);
>               irq_dispose_mapping(spa->virq);
>       }
>       kfree(spa->irq_name);
> -- 
> 2.50.1.windows.1
> 

How was this found and tested?

thanks,

greg k-h

Reply via email to