[PATCH iwl-net 02/10] ice: fix IRQ freeing in ice_vsi_req_irq_msix() error path

From: Petr Oros

Date: Fri Oct 02 2026 - 09:09:21 EST


The vectors are requested with the q_vector as dev_id, but the error
path frees them with &vsi->q_vectors[vector], which is the address of
the array slot. devm_free_irq() finds no matching devres entry, warns
and leaves the IRQ requested. The unwind also tries to free vectors that
the request loop skipped because they have no rings.

Forcing request_irq to fail on the fourth vector during ndo_open gives:

ice 0000:04:00.2 enp4s0f2np2: MSIX request_irq failed, error: -16
WARNING: kernel/irq/devres.c:191 at devm_free_irq+0x30/0x40
WARNING: kernel/irq/devres.c:191 at devm_free_irq+0x30/0x40
WARNING: kernel/irq/devres.c:191 at devm_free_irq+0x30/0x40

and the three IRQs stay registered in /proc/interrupts while the
interface is down.

Pass the q_vector as dev_id and skip the vectors without rings, which
the request loop never requested.

i40e fixed the same mistake in commit 915470e1b44e ("i40e: fix IRQ
freeing in i40e_vsi_request_irq_msix error path").

Fixes: cdedef59deb0 ("ice: Configure VSIs for Tx/Rx")
Assisted-by: LLM
Signed-off-by: Petr Oros <poros@xxxxxxxxxx>
---
drivers/net/ethernet/intel/ice/ice_main.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/drivers/net/ethernet/intel/ice/ice_main.c b/drivers/net/ethernet/intel/ice/ice_main.c
index f2121e79fca993..d246cde36ae726 100644
--- a/drivers/net/ethernet/intel/ice/ice_main.c
+++ b/drivers/net/ethernet/intel/ice/ice_main.c
@@ -2582,8 +2582,12 @@ static int ice_vsi_req_irq_msix(struct ice_vsi *vsi, char *basename)

free_q_irqs:
while (vector--) {
- irq_num = vsi->q_vectors[vector]->irq.virq;
- devm_free_irq(dev, irq_num, &vsi->q_vectors[vector]);
+ struct ice_q_vector *q_vector = vsi->q_vectors[vector];
+
+ if (!q_vector->tx.tx_ring && !q_vector->rx.rx_ring)
+ continue;
+
+ devm_free_irq(dev, q_vector->irq.virq, q_vector);
}
return err;
}
--
2.55.0