* [PATCH v2] dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO
2026-06-21 8:52 [PATCH] dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO Aditya Chari
@ 2026-06-21 9:19 ` Aditya Chari
2026-06-21 15:34 ` sashiko-bot
2026-06-21 9:43 ` [PATCH v3] " Aditya Chari
2026-06-21 13:43 ` [PATCH] " sashiko-bot
2 siblings, 1 reply; 10+ messages in thread
From: Aditya Chari @ 2026-06-21 9:19 UTC (permalink / raw)
To: robh, krzk+dt, conor+dt, gregkh
Cc: jacobsfeder, devicetree, linux-staging, linux-kernel,
Aditya Chari
The axis-fifo driver's compatible strings were undocumented, flagged
by checkpatch.pl as UNDOCUMENTED_DT_STRING. Add a YAML devicetree
binding document for drivers/staging/axis-fifo, converted from and
replacing the existing free-form text binding (axis-fifo.txt), which
this patch removes.
Signed-off-by: Aditya Chari <adi25charis@gmail.com>
---
Changes since v1:
- Fixed xlnx,rx/tx-fifo-depth: depth is in 32-bit words, not bytes,
matching the driver's overflow check in axis_fifo_write() and the
wording of the original text binding.
- Restored the full set of hardware-generated properties (interrupt-
names, AXI-Stream protocol/width properties, has-axis-t* feature
flags, fifo threshold properties, etc.) so that additionalProperties:
false does not reject valid device trees generated for real hardware.
- Removed the now-superseded axis-fifo.txt text binding.
.../bindings/misc/xlnx,axi-fifo-mm-s.yaml | 221 ++++++++++++++++++
drivers/staging/axis-fifo/axis-fifo.txt | 96 --------
2 files changed, 221 insertions(+), 96 deletions(-)
create mode 100644 Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml
delete mode 100644 drivers/staging/axis-fifo/axis-fifo.txt
diff --git a/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml b/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml
new file mode 100644
index 000000000..f4606b13c
--- /dev/null
+++ b/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml
@@ -0,0 +1,221 @@
+# SPDX-License-Identifier: (GPL-2.0 OR BSD-2-Clause)
+%YAML 1.2
+---
+$id: http://devicetree.org/schemas/misc/xlnx,axi-fifo-mm-s.yaml#
+$schema: http://devicetree.org/meta-schemas/core.yaml#
+
+title: Xilinx AXI-Stream FIFO (axis-fifo)
+
+maintainers:
+ - Jacob Feder <jacobsfeder@gmail.com>
+
+description:
+ The AXI-Stream FIFO (AXIS-FIFO) IP core provides a memory-mapped AXI4-Lite
+ interface for sending and receiving data over an AXI4-Stream interface
+ using FIFO buffers. Currently supports only store-forward mode with a
+ 32-bit AXI4-Lite interface; cut-through mode and full AXI4 are not
+ supported. See Xilinx PG080 for IP details.
+
+properties:
+ compatible:
+ enum:
+ - xlnx,axi-fifo-mm-s-4.1
+ - xlnx,axi-fifo-mm-s-4.2
+ - xlnx,axi-fifo-mm-s-4.3
+
+ reg:
+ maxItems: 1
+
+ interrupts:
+ maxItems: 1
+
+ interrupt-names:
+ items:
+ - const: interrupt
+
+ xlnx,axi-str-rxd-tdata-width:
+ description:
+ Width in bits of the AXI4-Stream receive data interface. Only a
+ width of 32 is currently supported by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 32
+
+ xlnx,axi-str-txd-tdata-width:
+ description:
+ Width in bits of the AXI4-Stream transmit data interface. Only a
+ width of 32 is currently supported by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 32
+
+ xlnx,axi-str-txc-tdata-width:
+ description:
+ Width in bits of the AXI4-Stream transmit control interface.
+ Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,axi-str-rxd-protocol:
+ description: AXI-Stream receive data protocol. Ignored by the driver.
+ enum: [ XIL_AXI_STREAM_ETH_DATA ]
+
+ xlnx,axi-str-txd-protocol:
+ description: AXI-Stream transmit data protocol. Ignored by the driver.
+ enum: [ XIL_AXI_STREAM_ETH_DATA ]
+
+ xlnx,axi-str-txc-protocol:
+ description: AXI-Stream transmit control protocol. Ignored by the driver.
+ enum: [ XIL_AXI_STREAM_ETH_CTRL ]
+
+ xlnx,axis-tdest-width:
+ description: AXI-Stream TDEST width. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,axis-tid-width:
+ description: AXI-Stream TID width. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,axis-tuser-width:
+ description: AXI-Stream TUSER width. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,data-interface-type:
+ description: Data interface type. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,has-axis-tdest:
+ description:
+ Whether the AXI-Stream interface has TDEST. This feature is not
+ supported by the driver and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,has-axis-tid:
+ description:
+ Whether the AXI-Stream interface has TID. This feature is not
+ supported by the driver and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,has-axis-tkeep:
+ description:
+ Whether the AXI-Stream interface has TKEEP. This feature is not
+ supported by the driver and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,has-axis-tstrb:
+ description:
+ Whether the AXI-Stream interface has TSTRB. This feature is not
+ supported by the driver and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,has-axis-tuser:
+ description:
+ Whether the AXI-Stream interface has TUSER. This feature is not
+ supported by the driver and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,rx-fifo-depth:
+ description:
+ Depth in 32-bit words of the receive FIFO, as configured in the
+ IP core.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,rx-fifo-pe-threshold:
+ description: RX programmable empty interrupt threshold. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,rx-fifo-pf-threshold:
+ description: RX programmable full interrupt threshold. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,s-axi-id-width:
+ description: AXI4-Lite ID width. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,s-axi4-data-width:
+ description: AXI4-Lite data width. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,select-xpm:
+ description: Whether XPM macros are used. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,tx-fifo-depth:
+ description:
+ Depth in 32-bit words of the transmit FIFO, as configured in the
+ IP core.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,tx-fifo-pe-threshold:
+ description: TX programmable empty interrupt threshold. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,tx-fifo-pf-threshold:
+ description: TX programmable full interrupt threshold. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,use-rx-cut-through:
+ description:
+ Whether RX cut-through mode is used. Not supported by the driver
+ and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,use-rx-data:
+ description:
+ Indicates whether the receive data path is present, as configured
+ in the IP core. A value of 1 enables the receive path, 0 disables it.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ enum: [ 0, 1 ]
+
+ xlnx,use-tx-ctrl:
+ description:
+ Whether the transmit control interface is used. Not supported by
+ the driver and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,use-tx-cut-through:
+ description:
+ Whether TX cut-through mode is used. Not supported by the driver
+ and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,use-tx-data:
+ description:
+ Indicates whether the transmit data path is present, as configured
+ in the IP core. A value of 1 enables the transmit path, 0 disables it.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ enum: [ 0, 1 ]
+
+required:
+ - compatible
+ - reg
+ - interrupts
+ - xlnx,axi-str-rxd-tdata-width
+ - xlnx,axi-str-txd-tdata-width
+ - xlnx,rx-fifo-depth
+ - xlnx,tx-fifo-depth
+ - xlnx,use-rx-data
+ - xlnx,use-tx-data
+
+additionalProperties: false
+
+examples:
+ - |
+ #include <dt-bindings/interrupt-controller/irq.h>
+
+ axi_fifo_mm_s_0: axi-fifo-mm-s@40000000 {
+ compatible = "xlnx,axi-fifo-mm-s-4.1";
+ reg = <0x40000000 0x10000>;
+ interrupts = <0 29 IRQ_TYPE_LEVEL_HIGH>;
+ xlnx,axi-str-rxd-tdata-width = <32>;
+ xlnx,axi-str-txd-tdata-width = <32>;
+ xlnx,rx-fifo-depth = <512>;
+ xlnx,tx-fifo-depth = <32768>;
+ xlnx,use-rx-data = <1>;
+ xlnx,use-tx-data = <1>;
+ };
diff --git a/drivers/staging/axis-fifo/axis-fifo.txt b/drivers/staging/axis-fifo/axis-fifo.txt
deleted file mode 100644
index 413b81a53..000000000
--- a/drivers/staging/axis-fifo/axis-fifo.txt
+++ /dev/null
@@ -1,96 +0,0 @@
-Xilinx AXI-Stream FIFO v4.1 IP core
-
-This IP core has read and write AXI-Stream FIFOs, the contents of which can
-be accessed from the AXI4 memory-mapped interface. This is useful for
-transferring data from a processor into the FPGA fabric. The driver creates
-a character device that can be read/written to with standard
-open/read/write/close.
-
-See Xilinx PG080 document for IP details.
-
-Currently supports only store-forward mode with a 32-bit
-AXI4-Lite interface. DOES NOT support:
- - cut-through mode
- - AXI4 (non-lite)
-
-Required properties:
-- compatible: Should be one of:
- "xlnx,axi-fifo-mm-s-4.1"
- "xlnx,axi-fifo-mm-s-4.2"
- "xlnx,axi-fifo-mm-s-4.3"
-- interrupt-names: Should be "interrupt"
-- interrupt-parent: Should be <&intc>
-- interrupts: Should contain interrupts lines.
-- reg: Should contain registers location and length.
-- xlnx,axi-str-rxd-protocol: Should be "XIL_AXI_STREAM_ETH_DATA"
-- xlnx,axi-str-rxd-tdata-width: Should be <0x20>
-- xlnx,axi-str-txc-protocol: Should be "XIL_AXI_STREAM_ETH_CTRL"
-- xlnx,axi-str-txc-tdata-width: Should be <0x20>
-- xlnx,axi-str-txd-protocol: Should be "XIL_AXI_STREAM_ETH_DATA"
-- xlnx,axi-str-txd-tdata-width: Should be <0x20>
-- xlnx,axis-tdest-width: AXI-Stream TDEST width (ignored by the driver)
-- xlnx,axis-tid-width: AXI-Stream TID width (ignored by the driver)
-- xlnx,axis-tuser-width: AXI-Stream TUSER width (ignored by the driver)
-- xlnx,data-interface-type: Should be <0x0> (ignored by the driver)
-- xlnx,has-axis-tdest: Should be <0x0> (this feature isn't supported)
-- xlnx,has-axis-tid: Should be <0x0> (this feature isn't supported)
-- xlnx,has-axis-tkeep: Should be <0x0> (this feature isn't supported)
-- xlnx,has-axis-tstrb: Should be <0x0> (this feature isn't supported)
-- xlnx,has-axis-tuser: Should be <0x0> (this feature isn't supported)
-- xlnx,rx-fifo-depth: Depth of RX FIFO in words
-- xlnx,rx-fifo-pe-threshold: RX programmable empty interrupt threshold
- (ignored by the driver)
-- xlnx,rx-fifo-pf-threshold: RX programmable full interrupt threshold
- (ignored by the driver)
-- xlnx,s-axi-id-width: Should be <0x4> (ignored by the driver)
-- xlnx,s-axi4-data-width: Should be <0x20> (ignored by the driver)
-- xlnx,select-xpm: Should be <0x0> (ignored by the driver)
-- xlnx,tx-fifo-depth: Depth of TX FIFO in words
-- xlnx,tx-fifo-pe-threshold: TX programmable empty interrupt threshold
- (ignored by the driver)
-- xlnx,tx-fifo-pf-threshold: TX programmable full interrupt threshold
- (ignored by the driver)
-- xlnx,use-rx-cut-through: Should be <0x0> (this feature isn't supported)
-- xlnx,use-rx-data: <0x1> if RX FIFO is enabled, <0x0> otherwise
-- xlnx,use-tx-ctrl: Should be <0x0> (this feature isn't supported)
-- xlnx,use-tx-cut-through: Should be <0x0> (this feature isn't supported)
-- xlnx,use-tx-data: <0x1> if TX FIFO is enabled, <0x0> otherwise
-
-Example:
-
-axi_fifo_mm_s_0: axi_fifo_mm_s@43c00000 {
- compatible = "xlnx,axi-fifo-mm-s-4.1";
- interrupt-names = "interrupt";
- interrupt-parent = <&intc>;
- interrupts = <0 29 4>;
- reg = <0x43c00000 0x10000>;
- xlnx,axi-str-rxd-protocol = "XIL_AXI_STREAM_ETH_DATA";
- xlnx,axi-str-rxd-tdata-width = <0x20>;
- xlnx,axi-str-txc-protocol = "XIL_AXI_STREAM_ETH_CTRL";
- xlnx,axi-str-txc-tdata-width = <0x20>;
- xlnx,axi-str-txd-protocol = "XIL_AXI_STREAM_ETH_DATA";
- xlnx,axi-str-txd-tdata-width = <0x20>;
- xlnx,axis-tdest-width = <0x4>;
- xlnx,axis-tid-width = <0x4>;
- xlnx,axis-tuser-width = <0x4>;
- xlnx,data-interface-type = <0x0>;
- xlnx,has-axis-tdest = <0x0>;
- xlnx,has-axis-tid = <0x0>;
- xlnx,has-axis-tkeep = <0x0>;
- xlnx,has-axis-tstrb = <0x0>;
- xlnx,has-axis-tuser = <0x0>;
- xlnx,rx-fifo-depth = <0x200>;
- xlnx,rx-fifo-pe-threshold = <0x2>;
- xlnx,rx-fifo-pf-threshold = <0x1fb>;
- xlnx,s-axi-id-width = <0x4>;
- xlnx,s-axi4-data-width = <0x20>;
- xlnx,select-xpm = <0x0>;
- xlnx,tx-fifo-depth = <0x8000>;
- xlnx,tx-fifo-pe-threshold = <0x200>;
- xlnx,tx-fifo-pf-threshold = <0x7ffb>;
- xlnx,use-rx-cut-through = <0x0>;
- xlnx,use-rx-data = <0x0>;
- xlnx,use-tx-ctrl = <0x0>;
- xlnx,use-tx-cut-through = <0x0>;
- xlnx,use-tx-data = <0x1>;
-};
--
2.53.0
^ permalink raw reply related [flat|nested] 10+ messages in thread* Re: [PATCH v2] dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO
2026-06-21 9:19 ` [PATCH v2] " Aditya Chari
@ 2026-06-21 15:34 ` sashiko-bot
0 siblings, 0 replies; 10+ messages in thread
From: sashiko-bot @ 2026-06-21 15:34 UTC (permalink / raw)
To: Aditya Chari; +Cc: robh, devicetree, conor+dt
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
New issues:
- [Low] Missing `$ref` type definition for custom string properties in DT binding.
Pre-existing issues:
- [Critical] Use-After-Free on device unbind due to lack of synchronization with open file descriptors.
- [High] Integer underflow in bounds check allows bypassing transmit packet size restriction.
--
commit 97e86b437f0cf66fc60eec47c4742a54db8053f8
Author: Aditya Chari <adi25charis@gmail.com>
dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO
The axis-fifo driver's compatible strings were undocumented, flagged
by checkpatch.pl as UNDOCUMENTED_DT_STRING. Add a YAML devicetree
binding document for drivers/staging/axis-fifo, converted from and
replacing the existing free-form text binding (axis-fifo.txt), which
this patch removes.
> diff --git a/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml b/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml
> new file mode 100644
> --- /dev/null
> +++ b/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml
> @@ -0,0 +1,221 @@
[ ... ]
> + xlnx,axi-str-rxd-protocol:
> + description: AXI-Stream receive data protocol. Ignored by the driver.
> + enum: [ XIL_AXI_STREAM_ETH_DATA ]
> +
> + xlnx,axi-str-txd-protocol:
> + description: AXI-Stream transmit data protocol. Ignored by the driver.
> + enum: [ XIL_AXI_STREAM_ETH_DATA ]
> +
> + xlnx,axi-str-txc-protocol:
> + description: AXI-Stream transmit control protocol. Ignored by the driver.
> + enum: [ XIL_AXI_STREAM_ETH_CTRL ]
[Severity: Low]
Do these custom string properties need a $ref to types.yaml?
Device tree schema validation (dt_binding_check) requires custom properties
to explicitly specify their type. Providing an enum of strings might not be
sufficient for dt-schema to infer the type, which could cause type missing
or unknown schema validation errors.
Should these properties include a $ref: /schemas/types.yaml#/definitions/string
constraint?
[ ... ]
> + xlnx,tx-fifo-depth:
> + description:
> + Depth in 32-bit words of the transmit FIFO, as configured in the
> + IP core.
> + $ref: /schemas/types.yaml#/definitions/uint32
[Severity: High]
This isn't a bug introduced by this patch, but should we add a minimum: 4
constraint here to protect against an integer underflow in the driver?
In drivers/staging/axis-fifo/axis-fifo.c:axis_fifo_write(), the bounds check
assumes tx_fifo_depth is at least 4:
if (!words_to_write || (len % sizeof(u32)) ||
(words_to_write > (fifo->tx_fifo_depth - 4)))
return -EINVAL;
If the device tree configures xlnx,tx-fifo-depth to a value less than 4, this
subtraction underflows to a massive unsigned integer, bypassing the bounds
check. This could allow an oversized packet to trigger a Transmit Packet
Overrun Error in the hardware.
[ ... ]
[Severity: Critical]
This is a pre-existing issue in the driver documented by this binding, but is
there a use-after-free vulnerability during device unbind?
The driver allocates its core state using devm_kzalloc():
drivers/staging/axis-fifo/axis-fifo.c:axis_fifo_probe() {
...
fifo = devm_kzalloc(dev, sizeof(*fifo), GFP_KERNEL);
...
}
During removal, it deregisters the misc device but doesn't wait for active
VFS file references to be dropped:
drivers/staging/axis-fifo/axis-fifo.c:axis_fifo_remove() {
...
misc_deregister(&fifo->miscdev);
...
}
When axis_fifo_remove() returns, the devres layer automatically frees the
axis_fifo structure. If a user process holds an open file descriptor and
subsequently calls write() or read(), it will dereference the freed pointer:
drivers/staging/axis-fifo/axis-fifo.c:axis_fifo_write() {
struct axis_fifo *fifo = f->private_data;
...
}
Should the driver use a different allocation and reference counting strategy
to ensure the memory remains valid as long as the file descriptor is open?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260621091953.53281-1-adi25charis@gmail.com?part=1
^ permalink raw reply [flat|nested] 10+ messages in thread
* [PATCH v3] dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO
2026-06-21 8:52 [PATCH] dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO Aditya Chari
2026-06-21 9:19 ` [PATCH v2] " Aditya Chari
@ 2026-06-21 9:43 ` Aditya Chari
2026-06-21 15:54 ` sashiko-bot
2026-06-21 18:33 ` Krzysztof Kozlowski
2026-06-21 13:43 ` [PATCH] " sashiko-bot
2 siblings, 2 replies; 10+ messages in thread
From: Aditya Chari @ 2026-06-21 9:43 UTC (permalink / raw)
To: robh, krzk+dt, conor+dt, gregkh
Cc: jacobsfeder, devicetree, linux-staging, linux-kernel,
Aditya Chari
The axis-fifo driver's compatible strings were undocumented, flagged
by checkpatch.pl as UNDOCUMENTED_DT_STRING. Add a YAML devicetree
binding document for drivers/staging/axis-fifo, converted from and
replacing the existing free-form text binding (axis-fifo.txt), which
this patch removes.
Constrain xlnx,tx-fifo-depth to a minimum of 4, since the driver
subtracts 4 from this value in its transmit bounds check and a
smaller value would underflow that check.
Signed-off-by: Aditya Chari <adi25charis@gmail.com>
---
Changes since v2:
- Added $ref: /schemas/types.yaml#/definitions/string to the three
AXI-Stream protocol enum properties (xlnx,axi-str-rxd-protocol,
xlnx,axi-str-txd-protocol, xlnx,axi-str-txc-protocol) for explicit
type consistency with the rest of the schema.
- Added minimum: 4 to xlnx,tx-fifo-depth, since the driver subtracts
4 from this value in its transmit bounds check
(axis_fifo_write()) and a smaller configured value would underflow
that unsigned check, bypassing the oversized-packet guard.
Changes since v1:
- Fixed xlnx,rx/tx-fifo-depth: depth is in 32-bit words, not bytes,
matching the driver's overflow check in axis_fifo_write() and the
wording of the original text binding.
- Restored the full set of hardware-generated properties (interrupt-
names, AXI-Stream protocol/width properties, has-axis-t* feature
flags, fifo threshold properties, etc.) so that additionalProperties:
false does not reject valid device trees generated for real hardware.
- Removed the now-superseded axis-fifo.txt text binding.
.../bindings/misc/xlnx,axi-fifo-mm-s.yaml | 227 ++++++++++++++++++
drivers/staging/axis-fifo/axis-fifo.txt | 96 --------
2 files changed, 227 insertions(+), 96 deletions(-)
create mode 100644 Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml
delete mode 100644 drivers/staging/axis-fifo/axis-fifo.txt
diff --git a/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml b/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml
new file mode 100644
index 000000000..53bf52524
--- /dev/null
+++ b/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml
@@ -0,0 +1,227 @@
+# SPDX-License-Identifier: (GPL-2.0 OR BSD-2-Clause)
+%YAML 1.2
+---
+$id: http://devicetree.org/schemas/misc/xlnx,axi-fifo-mm-s.yaml#
+$schema: http://devicetree.org/meta-schemas/core.yaml#
+
+title: Xilinx AXI-Stream FIFO (axis-fifo)
+
+maintainers:
+ - Jacob Feder <jacobsfeder@gmail.com>
+
+description:
+ The AXI-Stream FIFO (AXIS-FIFO) IP core provides a memory-mapped AXI4-Lite
+ interface for sending and receiving data over an AXI4-Stream interface
+ using FIFO buffers. Currently supports only store-forward mode with a
+ 32-bit AXI4-Lite interface; cut-through mode and full AXI4 are not
+ supported. See Xilinx PG080 for IP details.
+
+properties:
+ compatible:
+ enum:
+ - xlnx,axi-fifo-mm-s-4.1
+ - xlnx,axi-fifo-mm-s-4.2
+ - xlnx,axi-fifo-mm-s-4.3
+
+ reg:
+ maxItems: 1
+
+ interrupts:
+ maxItems: 1
+
+ interrupt-names:
+ items:
+ - const: interrupt
+
+ xlnx,axi-str-rxd-tdata-width:
+ description:
+ Width in bits of the AXI4-Stream receive data interface. Only a
+ width of 32 is currently supported by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 32
+
+ xlnx,axi-str-txd-tdata-width:
+ description:
+ Width in bits of the AXI4-Stream transmit data interface. Only a
+ width of 32 is currently supported by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 32
+
+ xlnx,axi-str-txc-tdata-width:
+ description:
+ Width in bits of the AXI4-Stream transmit control interface.
+ Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,axi-str-rxd-protocol:
+ description: AXI-Stream receive data protocol. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/string
+ enum: [ XIL_AXI_STREAM_ETH_DATA ]
+
+ xlnx,axi-str-txd-protocol:
+ description: AXI-Stream transmit data protocol. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/string
+ enum: [ XIL_AXI_STREAM_ETH_DATA ]
+
+ xlnx,axi-str-txc-protocol:
+ description: AXI-Stream transmit control protocol. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/string
+ enum: [ XIL_AXI_STREAM_ETH_CTRL ]
+
+ xlnx,axis-tdest-width:
+ description: AXI-Stream TDEST width. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,axis-tid-width:
+ description: AXI-Stream TID width. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,axis-tuser-width:
+ description: AXI-Stream TUSER width. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,data-interface-type:
+ description: Data interface type. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,has-axis-tdest:
+ description:
+ Whether the AXI-Stream interface has TDEST. This feature is not
+ supported by the driver and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,has-axis-tid:
+ description:
+ Whether the AXI-Stream interface has TID. This feature is not
+ supported by the driver and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,has-axis-tkeep:
+ description:
+ Whether the AXI-Stream interface has TKEEP. This feature is not
+ supported by the driver and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,has-axis-tstrb:
+ description:
+ Whether the AXI-Stream interface has TSTRB. This feature is not
+ supported by the driver and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,has-axis-tuser:
+ description:
+ Whether the AXI-Stream interface has TUSER. This feature is not
+ supported by the driver and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,rx-fifo-depth:
+ description:
+ Depth in 32-bit words of the receive FIFO, as configured in the
+ IP core.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,rx-fifo-pe-threshold:
+ description: RX programmable empty interrupt threshold. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,rx-fifo-pf-threshold:
+ description: RX programmable full interrupt threshold. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,s-axi-id-width:
+ description: AXI4-Lite ID width. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,s-axi4-data-width:
+ description: AXI4-Lite data width. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,select-xpm:
+ description: Whether XPM macros are used. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,tx-fifo-depth:
+ description:
+ Depth in 32-bit words of the transmit FIFO, as configured in the
+ IP core. Must be at least 4; the driver subtracts 4 from this
+ value when bounds-checking transmit writes, and a smaller value
+ underflows that check.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ minimum: 4
+
+ xlnx,tx-fifo-pe-threshold:
+ description: TX programmable empty interrupt threshold. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,tx-fifo-pf-threshold:
+ description: TX programmable full interrupt threshold. Ignored by the driver.
+ $ref: /schemas/types.yaml#/definitions/uint32
+
+ xlnx,use-rx-cut-through:
+ description:
+ Whether RX cut-through mode is used. Not supported by the driver
+ and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,use-rx-data:
+ description:
+ Indicates whether the receive data path is present, as configured
+ in the IP core. A value of 1 enables the receive path, 0 disables it.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ enum: [ 0, 1 ]
+
+ xlnx,use-tx-ctrl:
+ description:
+ Whether the transmit control interface is used. Not supported by
+ the driver and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,use-tx-cut-through:
+ description:
+ Whether TX cut-through mode is used. Not supported by the driver
+ and must be 0.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ const: 0
+
+ xlnx,use-tx-data:
+ description:
+ Indicates whether the transmit data path is present, as configured
+ in the IP core. A value of 1 enables the transmit path, 0 disables it.
+ $ref: /schemas/types.yaml#/definitions/uint32
+ enum: [ 0, 1 ]
+
+required:
+ - compatible
+ - reg
+ - interrupts
+ - xlnx,axi-str-rxd-tdata-width
+ - xlnx,axi-str-txd-tdata-width
+ - xlnx,rx-fifo-depth
+ - xlnx,tx-fifo-depth
+ - xlnx,use-rx-data
+ - xlnx,use-tx-data
+
+additionalProperties: false
+
+examples:
+ - |
+ #include <dt-bindings/interrupt-controller/irq.h>
+
+ axi_fifo_mm_s_0: axi-fifo-mm-s@40000000 {
+ compatible = "xlnx,axi-fifo-mm-s-4.1";
+ reg = <0x40000000 0x10000>;
+ interrupts = <0 29 IRQ_TYPE_LEVEL_HIGH>;
+ xlnx,axi-str-rxd-tdata-width = <32>;
+ xlnx,axi-str-txd-tdata-width = <32>;
+ xlnx,rx-fifo-depth = <512>;
+ xlnx,tx-fifo-depth = <32768>;
+ xlnx,use-rx-data = <1>;
+ xlnx,use-tx-data = <1>;
+ };
diff --git a/drivers/staging/axis-fifo/axis-fifo.txt b/drivers/staging/axis-fifo/axis-fifo.txt
deleted file mode 100644
index 413b81a53..000000000
--- a/drivers/staging/axis-fifo/axis-fifo.txt
+++ /dev/null
@@ -1,96 +0,0 @@
-Xilinx AXI-Stream FIFO v4.1 IP core
-
-This IP core has read and write AXI-Stream FIFOs, the contents of which can
-be accessed from the AXI4 memory-mapped interface. This is useful for
-transferring data from a processor into the FPGA fabric. The driver creates
-a character device that can be read/written to with standard
-open/read/write/close.
-
-See Xilinx PG080 document for IP details.
-
-Currently supports only store-forward mode with a 32-bit
-AXI4-Lite interface. DOES NOT support:
- - cut-through mode
- - AXI4 (non-lite)
-
-Required properties:
-- compatible: Should be one of:
- "xlnx,axi-fifo-mm-s-4.1"
- "xlnx,axi-fifo-mm-s-4.2"
- "xlnx,axi-fifo-mm-s-4.3"
-- interrupt-names: Should be "interrupt"
-- interrupt-parent: Should be <&intc>
-- interrupts: Should contain interrupts lines.
-- reg: Should contain registers location and length.
-- xlnx,axi-str-rxd-protocol: Should be "XIL_AXI_STREAM_ETH_DATA"
-- xlnx,axi-str-rxd-tdata-width: Should be <0x20>
-- xlnx,axi-str-txc-protocol: Should be "XIL_AXI_STREAM_ETH_CTRL"
-- xlnx,axi-str-txc-tdata-width: Should be <0x20>
-- xlnx,axi-str-txd-protocol: Should be "XIL_AXI_STREAM_ETH_DATA"
-- xlnx,axi-str-txd-tdata-width: Should be <0x20>
-- xlnx,axis-tdest-width: AXI-Stream TDEST width (ignored by the driver)
-- xlnx,axis-tid-width: AXI-Stream TID width (ignored by the driver)
-- xlnx,axis-tuser-width: AXI-Stream TUSER width (ignored by the driver)
-- xlnx,data-interface-type: Should be <0x0> (ignored by the driver)
-- xlnx,has-axis-tdest: Should be <0x0> (this feature isn't supported)
-- xlnx,has-axis-tid: Should be <0x0> (this feature isn't supported)
-- xlnx,has-axis-tkeep: Should be <0x0> (this feature isn't supported)
-- xlnx,has-axis-tstrb: Should be <0x0> (this feature isn't supported)
-- xlnx,has-axis-tuser: Should be <0x0> (this feature isn't supported)
-- xlnx,rx-fifo-depth: Depth of RX FIFO in words
-- xlnx,rx-fifo-pe-threshold: RX programmable empty interrupt threshold
- (ignored by the driver)
-- xlnx,rx-fifo-pf-threshold: RX programmable full interrupt threshold
- (ignored by the driver)
-- xlnx,s-axi-id-width: Should be <0x4> (ignored by the driver)
-- xlnx,s-axi4-data-width: Should be <0x20> (ignored by the driver)
-- xlnx,select-xpm: Should be <0x0> (ignored by the driver)
-- xlnx,tx-fifo-depth: Depth of TX FIFO in words
-- xlnx,tx-fifo-pe-threshold: TX programmable empty interrupt threshold
- (ignored by the driver)
-- xlnx,tx-fifo-pf-threshold: TX programmable full interrupt threshold
- (ignored by the driver)
-- xlnx,use-rx-cut-through: Should be <0x0> (this feature isn't supported)
-- xlnx,use-rx-data: <0x1> if RX FIFO is enabled, <0x0> otherwise
-- xlnx,use-tx-ctrl: Should be <0x0> (this feature isn't supported)
-- xlnx,use-tx-cut-through: Should be <0x0> (this feature isn't supported)
-- xlnx,use-tx-data: <0x1> if TX FIFO is enabled, <0x0> otherwise
-
-Example:
-
-axi_fifo_mm_s_0: axi_fifo_mm_s@43c00000 {
- compatible = "xlnx,axi-fifo-mm-s-4.1";
- interrupt-names = "interrupt";
- interrupt-parent = <&intc>;
- interrupts = <0 29 4>;
- reg = <0x43c00000 0x10000>;
- xlnx,axi-str-rxd-protocol = "XIL_AXI_STREAM_ETH_DATA";
- xlnx,axi-str-rxd-tdata-width = <0x20>;
- xlnx,axi-str-txc-protocol = "XIL_AXI_STREAM_ETH_CTRL";
- xlnx,axi-str-txc-tdata-width = <0x20>;
- xlnx,axi-str-txd-protocol = "XIL_AXI_STREAM_ETH_DATA";
- xlnx,axi-str-txd-tdata-width = <0x20>;
- xlnx,axis-tdest-width = <0x4>;
- xlnx,axis-tid-width = <0x4>;
- xlnx,axis-tuser-width = <0x4>;
- xlnx,data-interface-type = <0x0>;
- xlnx,has-axis-tdest = <0x0>;
- xlnx,has-axis-tid = <0x0>;
- xlnx,has-axis-tkeep = <0x0>;
- xlnx,has-axis-tstrb = <0x0>;
- xlnx,has-axis-tuser = <0x0>;
- xlnx,rx-fifo-depth = <0x200>;
- xlnx,rx-fifo-pe-threshold = <0x2>;
- xlnx,rx-fifo-pf-threshold = <0x1fb>;
- xlnx,s-axi-id-width = <0x4>;
- xlnx,s-axi4-data-width = <0x20>;
- xlnx,select-xpm = <0x0>;
- xlnx,tx-fifo-depth = <0x8000>;
- xlnx,tx-fifo-pe-threshold = <0x200>;
- xlnx,tx-fifo-pf-threshold = <0x7ffb>;
- xlnx,use-rx-cut-through = <0x0>;
- xlnx,use-rx-data = <0x0>;
- xlnx,use-tx-ctrl = <0x0>;
- xlnx,use-tx-cut-through = <0x0>;
- xlnx,use-tx-data = <0x1>;
-};
--
2.53.0
^ permalink raw reply related [flat|nested] 10+ messages in thread* Re: [PATCH v3] dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO
2026-06-21 9:43 ` [PATCH v3] " Aditya Chari
@ 2026-06-21 15:54 ` sashiko-bot
2026-06-21 18:33 ` Krzysztof Kozlowski
1 sibling, 0 replies; 10+ messages in thread
From: sashiko-bot @ 2026-06-21 15:54 UTC (permalink / raw)
To: Aditya Chari; +Cc: conor+dt, robh, devicetree
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
Pre-existing issues:
- [High] Missing runtime bounds check for tx_fifo_depth causes integer underflow and potential DoS
- [High] Unvalidated hardware read can cause massive busy loop and CPU soft lockup
- [High] Hardware interrupts enabled before IRQ handler registration
--
commit cd9dfa74e4b12151a534638f2622f83e05f40fee
Author: Aditya Chari <adi25charis@gmail.com>
dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO
This patch converts the free-form text binding for the Xilinx AXI-Stream
FIFO IP core into a YAML schema. It also enforces a minimum value of 4
for the xlnx,tx-fifo-depth property to match the driver's transmit bounds
check.
> diff --git a/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml b/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml
> new file mode 100644
> index 0000000000000..53bf52524e74d
> --- /dev/null
> +++ b/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml
> @@ -0,0 +1,227 @@
> +# SPDX-License-Identifier: (GPL-2.0 OR BSD-2-Clause)
> +%YAML 1.2
> +---
> +$id: http://devicetree.org/schemas/misc/xlnx,axi-fifo-mm-s.yaml#
> +$schema: http://devicetree.org/meta-schemas/core.yaml#
[ ... ]
> +properties:
> + compatible:
> + enum:
> + - xlnx,axi-fifo-mm-s-4.1
> + - xlnx,axi-fifo-mm-s-4.2
> + - xlnx,axi-fifo-mm-s-4.3
> +
> + reg:
> + maxItems: 1
> +
> + interrupts:
> + maxItems: 1
[Severity: High]
This is a pre-existing issue, but does the driver enable interrupts before
registering the IRQ handler?
Looking at drivers/staging/axis-fifo/axis-fifo.c:axis_fifo_probe():
reset_ip_core(fifo);
irq = platform_get_irq(pdev, 0);
if (irq < 0)
return irq;
rc = devm_request_irq(fifo->dt_device, irq, &axis_fifo_irq, 0,
DRIVER_NAME, fifo);
And in reset_ip_core():
iowrite32(XLLF_INT_TC_MASK | XLLF_INT_RC_MASK | XLLF_INT_RPURE_MASK |
XLLF_INT_RPORE_MASK | XLLF_INT_RPUE_MASK |
XLLF_INT_TPOE_MASK | XLLF_INT_TSE_MASK,
fifo->base_addr + XLLF_IER_OFFSET);
If the hardware immediately asserts an interrupt, could this trigger a spurious
interrupt before devm_request_irq() completes, permanently disabling the IRQ
line?
[ ... ]
> + xlnx,tx-fifo-depth:
> + description:
> + Depth in 32-bit words of the transmit FIFO, as configured in the
> + IP core. Must be at least 4; the driver subtracts 4 from this
> + value when bounds-checking transmit writes, and a smaller value
> + underflows that check.
> + $ref: /schemas/types.yaml#/definitions/uint32
> + minimum: 4
[Severity: High]
This isn't a bug introduced by this patch, but since the binding enforces a
minimum of 4, what happens if a malformed device tree provides a smaller
value?
In drivers/staging/axis-fifo/axis-fifo.c:axis_fifo_parse_dt():
ret = of_property_read_u32(node, "xlnx,tx-fifo-depth",
&fifo->tx_fifo_depth);
if (ret)
return ret;
The value is parsed without enforcing the boundary constraint. Could this
lead to an integer underflow later in axis_fifo_write()?
if (!words_to_write || (len % sizeof(u32)) ||
(words_to_write > (fifo->tx_fifo_depth - 4)))
return -EINVAL;
If fifo->tx_fifo_depth is less than 4, this subtraction underflows, bypassing
the maximum packet size check.
[ ... ]
> + xlnx,use-rx-data:
> + description:
> + Indicates whether the receive data path is present, as configured
> + in the IP core. A value of 1 enables the receive path, 0 disables it.
> + $ref: /schemas/types.yaml#/definitions/uint32
> + enum: [ 0, 1 ]
[Severity: High]
This is a pre-existing issue, but does the driver handle hardware read errors
safely when processing received data?
In drivers/staging/axis-fifo/axis-fifo.c:axis_fifo_read():
bytes_available = ioread32(fifo->base_addr + XLLF_RLR_OFFSET);
words_available = bytes_available / sizeof(u32);
...
if (bytes_available % sizeof(u32)) {
/* this probably can't happen unless IP
* registers were previously mishandled
*/
dev_err(fifo->dt_device, "received a packet that isn't word-aligned\n");
ret = -EIO;
goto err_flush_rx;
}
If the device is in an error state and ioread32() returns 0xFFFFFFFF,
words_available becomes 0x3FFFFFFF. Would this cause the error recovery loop
to stall the CPU?
err_flush_rx:
while (words_available--)
ioread32(fifo->base_addr + XLLF_RDFD_OFFSET);
Executing over a billion memory-mapped reads sequentially could trigger the
kernel's soft lockup watchdog.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260621094312.53655-1-adi25charis@gmail.com?part=1
^ permalink raw reply [flat|nested] 10+ messages in thread* Re: [PATCH v3] dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO
2026-06-21 9:43 ` [PATCH v3] " Aditya Chari
2026-06-21 15:54 ` sashiko-bot
@ 2026-06-21 18:33 ` Krzysztof Kozlowski
2026-06-22 4:21 ` Aditya Chari S
1 sibling, 1 reply; 10+ messages in thread
From: Krzysztof Kozlowski @ 2026-06-21 18:33 UTC (permalink / raw)
To: Aditya Chari, robh, krzk+dt, conor+dt, gregkh
Cc: jacobsfeder, devicetree, linux-staging, linux-kernel
On 21/06/2026 11:43, Aditya Chari wrote:
> The axis-fifo driver's compatible strings were undocumented, flagged
> by checkpatch.pl as UNDOCUMENTED_DT_STRING. Add a YAML devicetree
> binding document for drivers/staging/axis-fifo, converted from and
> replacing the existing free-form text binding (axis-fifo.txt), which
> this patch removes.
>
> Constrain xlnx,tx-fifo-depth to a minimum of 4, since the driver
> subtracts 4 from this value in its transmit bounds check and a
> smaller value would underflow that check.
>
> Signed-off-by: Aditya Chari <adi25charis@gmail.com>
> ---
>
> Changes since v2:
> - Added $ref: /schemas/types.yaml#/definitions/string to the three
> AXI-Stream protocol enum properties (xlnx,axi-str-rxd-protocol,
> xlnx,axi-str-txd-protocol, xlnx,axi-str-txc-protocol) for explicit
> type consistency with the rest of the schema.
> - Added minimum: 4 to xlnx,tx-fifo-depth, since the driver subtracts
> 4 from this value in its transmit bounds check
> (axis_fifo_write()) and a smaller configured value would underflow
> that unsigned check, bypassing the oversized-packet guard.
>
> Changes since v1:
> - Fixed xlnx,rx/tx-fifo-depth: depth is in 32-bit words, not bytes,
> matching the driver's overflow check in axis_fifo_write() and the
> wording of the original text binding.
> - Restored the full set of hardware-generated properties (interrupt-
> names, AXI-Stream protocol/width properties, has-axis-t* feature
> flags, fifo threshold properties, etc.) so that additionalProperties:
> false does not reject valid device trees generated for real hardware.
> - Removed the now-superseded axis-fifo.txt text binding.
Please slow down. Three versions within 1 hour! Why sending something
and immediately sending fixes to it?
>
> .../bindings/misc/xlnx,axi-fifo-mm-s.yaml | 227 ++++++++++++++++++
> drivers/staging/axis-fifo/axis-fifo.txt | 96 --------
Why are you touching staging binding?
https://lore.kernel.org/all/?q=dfn%3Aaxis-fifo.txt
Best regards,
Krzysztof
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH v3] dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO
2026-06-21 18:33 ` Krzysztof Kozlowski
@ 2026-06-22 4:21 ` Aditya Chari S
2026-06-22 5:18 ` Krzysztof Kozlowski
0 siblings, 1 reply; 10+ messages in thread
From: Aditya Chari S @ 2026-06-22 4:21 UTC (permalink / raw)
To: Krzysztof Kozlowski, robh, krzk+dt, conor+dt, gregkh
Cc: jacobsfeder, devicetree, linux-staging, linux-kernel,
michal.simek, lucas.fariamo08
Sorry about the pace - jumped from automated lint feedback straight to
a new version without waiting for an actual reviewer. Won't happen
again.
On the staging binding question - I found the driver-removal thread
from June 2 and read through it. Michal Simek's reply makes clear this
driver isn't going anywhere (their networking team has plans that
depend on it), and that there's already an in-flight binding
conversion from Lucas Faria Mendes that he's actively tracking. I
wasn't aware of that series when I started this.
Given that, I'll withdraw mine rather than duplicate work that's
already further along and already has the relevant maintainer's eyes
on it.
Thanks for pointing me toward the history.
Regards,
Aditya
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH v3] dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO
2026-06-22 4:21 ` Aditya Chari S
@ 2026-06-22 5:18 ` Krzysztof Kozlowski
2026-06-22 6:22 ` Aditya Chari S
0 siblings, 1 reply; 10+ messages in thread
From: Krzysztof Kozlowski @ 2026-06-22 5:18 UTC (permalink / raw)
To: Aditya Chari S, robh, krzk+dt, conor+dt, gregkh
Cc: jacobsfeder, devicetree, linux-staging, linux-kernel,
michal.simek, lucas.fariamo08
On 22/06/2026 06:21, Aditya Chari S wrote:
> Sorry about the pace - jumped from automated lint feedback straight to
> a new version without waiting for an actual reviewer. Won't happen
> again.
>
> On the staging binding question - I found the driver-removal thread
> from June 2 and read through it. Michal Simek's reply makes clear this
> driver isn't going anywhere (their networking team has plans that
> depend on it), and that there's already an in-flight binding
> conversion from Lucas Faria Mendes that he's actively tracking. I
> wasn't aware of that series when I started this.
>
> Given that, I'll withdraw mine rather than duplicate work that's
> already further along and already has the relevant maintainer's eyes
> on it.
>
The main point is that driver is in staging, so we don't take bindings
for it.
Best regards,
Krzysztof
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH v3] dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO
2026-06-22 5:18 ` Krzysztof Kozlowski
@ 2026-06-22 6:22 ` Aditya Chari S
0 siblings, 0 replies; 10+ messages in thread
From: Aditya Chari S @ 2026-06-22 6:22 UTC (permalink / raw)
To: Krzysztof Kozlowski, robh, krzk+dt, conor+dt, gregkh
Cc: jacobsfeder, devicetree, linux-staging, linux-kernel,
michal.simek, lucas.fariamo08
On Mon, Jun 22, 2026, Krzysztof Kozlowski wrote:
> The main point is that driver is in staging, so we don't take bindings
> for it.
Understood, thanks for clarifying.
Regards,
Aditya
On Mon, Jun 22, 2026 at 10:48 AM Krzysztof Kozlowski <krzk@kernel.org> wrote:
>
> On 22/06/2026 06:21, Aditya Chari S wrote:
> > Sorry about the pace - jumped from automated lint feedback straight to
> > a new version without waiting for an actual reviewer. Won't happen
> > again.
> >
> > On the staging binding question - I found the driver-removal thread
> > from June 2 and read through it. Michal Simek's reply makes clear this
> > driver isn't going anywhere (their networking team has plans that
> > depend on it), and that there's already an in-flight binding
> > conversion from Lucas Faria Mendes that he's actively tracking. I
> > wasn't aware of that series when I started this.
> >
> > Given that, I'll withdraw mine rather than duplicate work that's
> > already further along and already has the relevant maintainer's eyes
> > on it.
> >
>
> The main point is that driver is in staging, so we don't take bindings
> for it.
>
> Best regards,
> Krzysztof
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH] dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO
2026-06-21 8:52 [PATCH] dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO Aditya Chari
2026-06-21 9:19 ` [PATCH v2] " Aditya Chari
2026-06-21 9:43 ` [PATCH v3] " Aditya Chari
@ 2026-06-21 13:43 ` sashiko-bot
2 siblings, 0 replies; 10+ messages in thread
From: sashiko-bot @ 2026-06-21 13:43 UTC (permalink / raw)
To: Aditya Chari; +Cc: conor+dt, devicetree, robh
Thank you for your contribution! Sashiko AI review found 5 potential issue(s) to consider:
New issues:
- [High] The YAML binding incorrectly documents the FIFO depth properties as being in 'bytes', while the driver and hardware expect them in 'words'.
- [Medium] The schema omits valid hardware properties while enforcing `additionalProperties: false`, falsely restricting the device tree to only the properties the current driver implementation reads and causing valid hardware device trees to fail schema validation.
- [Medium] Hardware data width properties are artificially constrained to `const: 32` based on driver support rather than hardware capabilities.
- [Low] The previous text-based binding document was not removed.
Pre-existing issues:
- [Critical] A pre-existing use-after-free vulnerability occurs if the device is unbound while userspace holds an open file descriptor.
--
commit 1499d3b34c3ed26799e82ed6630ba1f50a8aec04
Author: Aditya Chari <adi25charis@gmail.com>
dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO
The axis-fifo driver's compatible strings were undocumented, flagged
by checkpatch.pl as UNDOCUMENTED_DT_STRING. Add a devicetree
binding document describing the required properties
for drivers/staging/axis-fifo, derived from the properties
the driver reads via of_property_read_u32()
in axis_fifo_parse_dt().
> dt-bindings: misc: add binding for Xilinx AXI-Stream FIFO
[Severity: Low]
Should the previous text-based binding document be removed in this patch?
It looks like the legacy drivers/staging/axis-fifo/axis-fifo.txt binding
was left in the tree, leaving two conflicting sources of truth for the
same hardware compatible string.
> diff --git a/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml b/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml
> new file mode 100644
> index 0000000000000..8ef0adde32ad8
> --- /dev/null
> +++ b/Documentation/devicetree/bindings/misc/xlnx,axi-fifo-mm-s.yaml
[ ... ]
> + xlnx,axi-str-rxd-tdata-width:
> + description:
> + Width in bits of the AXI4-Stream receive data interface. Only a
> + width of 32 is currently supported by the driver.
> + $ref: /schemas/types.yaml#/definitions/uint32
> + const: 32
> +
> + xlnx,axi-str-txd-tdata-width:
> + description:
> + Width in bits of the AXI4-Stream transmit data interface. Only a
> + width of 32 is currently supported by the driver.
> + $ref: /schemas/types.yaml#/definitions/uint32
> + const: 32
[Severity: Medium]
Should this schema describe the hardware capabilities rather than the software
limitations?
Over-constraining the schema to const: 32 based on current driver support
might cause validation errors for device trees that accurately represent
hardware synthesized with different bus widths.
> + xlnx,rx-fifo-depth:
> + description:
> + Depth in bytes of the receive FIFO, as configured in the IP core.
> + $ref: /schemas/types.yaml#/definitions/uint32
> +
> + xlnx,tx-fifo-depth:
> + description:
> + Depth in bytes of the transmit FIFO, as configured in the IP core.
> + $ref: /schemas/types.yaml#/definitions/uint32
[Severity: High]
Is it correct to document these properties as being in bytes?
Looking at the driver code, it evaluates the depth as word counts when checking
for overflow:
drivers/staging/axis-fifo/axis-fifo.c:axis_fifo_write() {
...
if (words_to_write > (fifo->tx_fifo_depth - 4)) {
...
}
...
}
If a devicetree author specifies the depth in bytes per the new YAML
documentation, could the driver load a value four times too large, allowing
out-of-bounds writes that might trigger a hardware transmit overrun error?
[ ... ]
> +required:
> + - compatible
> + - reg
> + - interrupts
> + - xlnx,axi-str-rxd-tdata-width
> + - xlnx,axi-str-txd-tdata-width
> + - xlnx,rx-fifo-depth
> + - xlnx,tx-fifo-depth
> + - xlnx,use-rx-data
> + - xlnx,use-tx-data
> +
> +additionalProperties: false
[Severity: Medium]
Does this schema artificially restrict the devicetree by omitting valid
hardware properties?
The original text binding allowed properties such as xlnx,has-axis-tkeep
and interrupt-names. Because the schema enforces additionalProperties: false,
will running dt_binding_check on existing, valid device trees generated for
this IP result in false-positive validation errors?
[Severity: Critical]
This is a pre-existing issue, but does the driver have a use-after-free
vulnerability if the device is unbound while a userspace process holds an
open file descriptor?
In the driver, the axis_fifo structure is allocated with devm_kzalloc() and
I/O memory mapped with devm_platform_get_and_ioremap_resource():
drivers/staging/axis-fifo/axis-fifo.c:axis_fifo_probe() {
...
fifo = devm_kzalloc(dev, sizeof(*fifo), GFP_KERNEL);
...
}
However, axis_fifo_remove() unregisters the character device without tracking
or waiting for active file descriptors to close:
drivers/staging/axis-fifo/axis-fifo.c:axis_fifo_remove() {
...
misc_deregister(&fifo->miscdev);
...
}
If the device is unbound via sysfs while a userspace process keeps the char
device open, the driver core's devres cleanup automatically frees the fifo
structure and unmaps base_addr. Would subsequent read(), write(), or poll()
calls via the active file descriptor then access the freed fifo pointer and
unmapped I/O memory?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260621085209.52651-1-adi25charis@gmail.com?part=1
^ permalink raw reply [flat|nested] 10+ messages in thread