All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Koichiro Den" <den@valinux.co.jp>
Cc: Frank.Li@kernel.org, vkoul@kernel.org, dmaengine@vger.kernel.org
Subject: Re: [PATCH v2 12/19] dmaengine: dw-edma: Recover stopped channels from tx_status()
Date: Thu, 23 Jul 2026 08:59:41 +0000	[thread overview]
Message-ID: <20260723085942.134281F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260723084150.521366-13-den@valinux.co.jp>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] Polling and restarting a stopped channel in tx_status races with the hardware STOP interrupt handler, causing the newly running transfer to be misinterpreted as stopped, leading to premature completion and data corruption.
--

--- Patch [12]: [PATCH v2 12/19] dmaengine: dw-edma: Recover stopped channels from tx_status() ---
commit b34ccd5c57949fabf1e4daf7d4e7cfdaa0576cc4
Author: Koichiro Den <den@valinux.co.jp>

    dmaengine: dw-edma: Recover stopped channels from tx_status()

This commit allows tx_status() to consume IRQ-recorded progress under
vc.lock. If a channel is stopped with pending entries, it reconciles a
fresh LLP boundary and restarts the channel.

> diff --git a/drivers/dma/dw-edma/dw-edma-core.c b/drivers/dma/dw-edma/dw-edma-core.c
> index 9489ca7e70fda..3fc929a6bcf52 100644
> --- a/drivers/dma/dw-edma/dw-edma-core.c
> +++ b/drivers/dma/dw-edma/dw-edma-core.c

[ ... ]

> @@ -654,6 +662,36 @@ dw_edma_device_tx_status(struct dma_chan *dchan, dma_cookie_t cookie,
>  	if (ret == DMA_COMPLETE)
>  		return ret;
>  
> +	if (!chan->non_ll) {
> +		scoped_guard(spinlock_irqsave, &chan->vc.lock) {
> +			enum dma_status ch_status;
> +
> +			ch_status = dw_edma_core_ch_status(chan);
> +
> +			/*
> +			 * Do not treat raw DMA_LLP polling as normal progress here. Only
> +			 * recycle progress recorded by the IRQ pass that consumed the
> +			 * status event.
> +			 */
> +			if (chan->request == EDMA_REQ_NONE &&
> +			    chan->status != EDMA_ST_PAUSE &&
> +			    ch_status == DMA_COMPLETE &&
> +			    dw_edma_ll_consume_progress(chan)) {
> +				dw_edma_start_transfer(chan);
> +				chan->status = dw_edma_ll_pending(chan) ?
> +					       EDMA_ST_BUSY : EDMA_ST_IDLE;
> +			}
> +
> +			if (dw_edma_ll_recoverable_pending(chan, ch_status))
> +				chan->status = EDMA_ST_BUSY;
> +			dw_edma_core_ch_maybe_doorbell(chan);

[Severity: Critical]
Can this race with the hard IRQ handler and cause data corruption?

If a transfer completes and the hardware stops, the hard IRQ handler 
(e.g., dw_hdma_v0_core_handle_int()) will read and clear the STOP status,
then call done(chan, true) which queues the deferred handler with stopped=true.

Before the deferred handler acquires chan->vc.lock, could a client polling
dw_edma_device_tx_status() acquire the lock, observe DMA_COMPLETE, and restart
the channel by hitting the doorbell here?

If so, when the deferred handler finally acquires the lock in
dw_edma_record_irq_idx(), it samples the LLP which is now moving since the
channel has been restarted. Because it uses the stale stopped=true flag,
dw_edma_ll_recycle_idx() returns the exact moving LLP index without applying
the idx - 1 safety margin. 

Could this cause descriptors to be completed prematurely while the hardware is
still actively transferring data?

> +		}
> +
> +		/* dw_edma_ll_clean_pending() may have completed this cookie. */
> +		ret = dma_cookie_status(dchan, cookie, txstate);
> +		if (ret == DMA_COMPLETE)
> +			return ret;
> +	}
>  	if (ret == DMA_IN_PROGRESS && chan->status == EDMA_ST_PAUSE)
>  		ret = DMA_PAUSED;
>

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260723084150.521366-1-den@valinux.co.jp?part=12

  reply	other threads:[~2026-07-23  8:59 UTC|newest]

Thread overview: 39+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-23  8:41 [PATCH v2 00/19] dmaengine: dw-edma: Support dynamic LL appends Koichiro Den
2026-07-23  8:41 ` [PATCH v2 01/19] dmaengine: dw-edma: Add dw_edma_core_ll_cur_idx() to get current LL entry index Koichiro Den
2026-07-23 16:25   ` Frank Li
2026-07-23  8:41 ` [PATCH v2 02/19] dmaengine: dw-edma: Add dw_edma_core_ll_clear() to clear LL control-word Koichiro Den
2026-07-23 18:53   ` Frank Li
2026-07-23  8:41 ` [PATCH v2 03/19] dmaengine: dw-edma: Factor out linked-list transfer start Koichiro Den
2026-07-23 16:31   ` Frank Li
2026-07-23  8:41 ` [PATCH v2 04/19] dmaengine: dw-edma: Make DMA link list work as a circular buffer Koichiro Den
2026-07-23  9:07   ` sashiko-bot
2026-07-23 16:43     ` Frank Li
2026-07-23  8:41 ` [PATCH v2 05/19] dmaengine: dw-edma: Add LL interrupt placement policy Koichiro Den
2026-07-23 19:58   ` Frank Li
2026-07-23  8:41 ` [PATCH v2 06/19] dmaengine: dw-edma: Move callback result helper before LL helpers Koichiro Den
2026-07-23 16:51   ` Frank Li
2026-07-23  8:41 ` [PATCH v2 07/19] dmaengine: dw-edma: Dispatch DONE interrupts by channel request Koichiro Den
2026-07-23  8:55   ` sashiko-bot
2026-07-23 16:57   ` Frank Li
2026-07-23  8:41 ` [PATCH v2 08/19] dmaengine: dw-edma: Centralize LL doorbell decisions Koichiro Den
2026-07-23  9:09   ` sashiko-bot
2026-07-23 17:02   ` Frank Li
2026-07-23  8:41 ` [PATCH v2 09/19] dmaengine: dw-edma: Reclaim issued descriptors from IRQ-paired LL progress Koichiro Den
2026-07-23  9:01   ` sashiko-bot
2026-07-23  8:41 ` [PATCH v2 10/19] dmaengine: dw-edma: Use HDMA watermarks as progress events Koichiro Den
2026-07-23  8:41 ` [PATCH v2 11/19] dmaengine: dw-edma: Reconcile lost completions from a stopped LLP re-sample Koichiro Den
2026-07-23  8:41 ` [PATCH v2 12/19] dmaengine: dw-edma: Recover stopped channels from tx_status() Koichiro Den
2026-07-23  8:59   ` sashiko-bot [this message]
2026-07-23  8:41 ` [PATCH v2 13/19] dmaengine: dw-edma: Make the LL ring reset a full channel resync Koichiro Den
2026-07-23  9:10   ` sashiko-bot
2026-07-23  8:41 ` [PATCH v2 14/19] dmaengine: dw-edma: Reset LL state after terminate and abort Koichiro Den
2026-07-23  9:14   ` sashiko-bot
2026-07-23  8:41 ` [PATCH v2 15/19] dmaengine: dw-edma: Add engine reset and enable operations Koichiro Den
2026-07-23  9:11   ` sashiko-bot
2026-07-23  8:41 ` [PATCH v2 16/19] dmaengine: dw-edma: Add engine recovery infrastructure Koichiro Den
2026-07-23  9:14   ` sashiko-bot
2026-07-23  8:41 ` [PATCH v2 17/19] dmaengine: dw-edma: Detect and recover a stalled eDMA engine Koichiro Den
2026-07-23  9:12   ` sashiko-bot
2026-07-23  8:41 ` [PATCH v2 18/19] dmaengine: dw-edma: Dynamically append requests while running Koichiro Den
2026-07-23  8:41 ` [PATCH v2 19/19] dmaengine: dw-edma: Add trace support Koichiro Den
2026-07-23  9:11   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260723085942.134281F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=den@valinux.co.jp \
    --cc=dmaengine@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.