From: sashiko-bot@kernel.org
To: "Koichiro Den" <den@valinux.co.jp>
Cc: Frank.Li@kernel.org, dmaengine@vger.kernel.org, vkoul@kernel.org
Subject: Re: [PATCH v3 01/24] dmaengine: dw-edma: Add dw_edma_core_ll_cur_idx() to get current LL entry index
Date: Mon, 27 Jul 2026 17:17:22 +0000 [thread overview]
Message-ID: <20260727171722.CF8431F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260727170323.2321369-2-den@valinux.co.jp>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] Torn read of 64-bit hardware register 'llp' leads to false -EINVAL when the DMA is running.
--
--- Patch [1]: [PATCH v3 01/24] dmaengine: dw-edma: Add dw_edma_core_ll_cur_idx() to get current LL entry index ---
commit 8302239cbe55e73285af81992cde8e677977d567
Author: Frank Li <Frank.Li@nxp.com>
dmaengine: dw-edma: Add dw_edma_core_ll_cur_idx() to get current LL entry index
Add dw_edma_core_ll_cur_idx() to get the current LL entry index. This
prepares the driver for dynamically adding DMA requests while the engine
is running.
> diff --git a/drivers/dma/dw-edma/dw-edma-v0-core.c b/drivers/dma/dw-edma/dw-edma-v0-core.c
> --- a/drivers/dma/dw-edma/dw-edma-v0-core.c
> +++ b/drivers/dma/dw-edma/dw-edma-v0-core.c
> @@ -616,6 +616,24 @@ static void dw_edma_v0_core_ch_doorbell(struct dw_edma_chan *chan)
[ ... ]
> +static int dw_edma_v0_core_ll_cur_idx(struct dw_edma_chan *chan)
> +{
> + u32 base, val;
> +
> + val = GET_CH_32(chan->dw, chan->dir, chan->id, llp.lsb);
> + base = lower_32_bits(dw_edma_core_get_ll_paddr(chan));
> +
> + /*
> + * An all-zero pointer means that the channel context is unavailable,
> + * so an LL region starting at DMA address zero is not supported.
> + */
> + if (!val && !GET_CH_32(chan->dw, chan->dir, chan->id, llp.msb))
[Severity: Medium]
Does this conditional read of llp.msb risk a torn read if the DMA engine
is actively running?
If the linked list ring crosses a 4 GiB boundary, a valid descriptor can reside
at a physical address with a zero LSB (e.g., 0x00000001_00000000).
Could the following sequence occur:
CPU reads llp.lsb as 0.
CPU is interrupted.
DMA engine advances the ring to an address below 4 GiB (e.g. 0x00000000_FFFFD000).
CPU resumes and reads llp.msb as 0.
Will this cause the function to falsely evaluate the pointer as all-zeros
and incorrectly return -EINVAL?
> + return -EINVAL;
> +
> + /* u32 subtraction handles a low-word wrap at a 4 GiB boundary. */
> + return (val - base) / EDMA_LL_SZ;
> +}
[ ... ]
> diff --git a/drivers/dma/dw-edma/dw-hdma-v0-core.c b/drivers/dma/dw-edma/dw-hdma-v0-core.c
> --- a/drivers/dma/dw-edma/dw-hdma-v0-core.c
> +++ b/drivers/dma/dw-edma/dw-hdma-v0-core.c
> @@ -384,6 +384,24 @@ static void dw_hdma_v0_core_ch_doorbell(struct dw_edma_chan *chan)
[ ... ]
> +static int dw_hdma_v0_core_ll_cur_idx(struct dw_edma_chan *chan)
> +{
> + u32 base, val;
> +
> + val = GET_CH_32(chan->dw, chan->dir, chan->id, llp.lsb);
> + base = lower_32_bits(dw_edma_core_get_ll_paddr(chan));
> +
> + /*
> + * An all-zero pointer means that the channel context is unavailable,
> + * so an LL region starting at DMA address zero is not supported.
> + */
> + if (!val && !GET_CH_32(chan->dw, chan->dir, chan->id, llp.msb))
[Severity: Medium]
This shares the same logic as dw_edma_v0_core_ll_cur_idx(). Can this also
suffer from the identical torn read scenario described above, leading to a
false -EINVAL?
> + return -EINVAL;
> +
> + /* u32 subtraction handles a low-word wrap at a 4 GiB boundary. */
> + return (val - base) / EDMA_LL_SZ;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260727170323.2321369-1-den@valinux.co.jp?part=1
next prev parent reply other threads:[~2026-07-27 17:17 UTC|newest]
Thread overview: 43+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-27 17:02 [PATCH v3 00/24] dmaengine: dw-edma: Support dynamic LL appends Koichiro Den
2026-07-27 17:03 ` [PATCH v3 01/24] dmaengine: dw-edma: Add dw_edma_core_ll_cur_idx() to get current LL entry index Koichiro Den
2026-07-27 17:17 ` sashiko-bot [this message]
2026-07-27 17:03 ` [PATCH v3 02/24] dmaengine: dw-edma: Add dw_edma_core_ll_clear() to clear LL control-word Koichiro Den
2026-07-27 17:03 ` [PATCH v3 03/24] dmaengine: dw-edma: Factor out linked-list transfer start Koichiro Den
2026-07-27 17:03 ` [PATCH v3 04/24] dmaengine: dw-edma: Make DMA link list work as a circular buffer Koichiro Den
2026-07-27 17:24 ` sashiko-bot
2026-07-27 19:09 ` Frank Li
2026-07-27 17:03 ` [PATCH v3 05/24] dmaengine: dw-edma: Move callback result helper before LL helpers Koichiro Den
2026-07-27 17:03 ` [PATCH v3 06/24] dmaengine: dw-edma: Dispatch DONE interrupts by channel request Koichiro Den
2026-07-27 17:13 ` sashiko-bot
2026-07-27 19:11 ` Frank Li
2026-07-27 17:03 ` [PATCH v3 07/24] dmaengine: dw-edma: Centralize LL doorbell decisions Koichiro Den
2026-07-27 17:23 ` sashiko-bot
2026-07-27 19:14 ` Frank Li
2026-07-27 17:03 ` [PATCH v3 08/24] dmaengine: dw-edma: Prepare LL progress event handling Koichiro Den
2026-07-27 19:47 ` Frank Li
2026-07-27 20:09 ` Frank Li
2026-07-27 17:03 ` [PATCH v3 09/24] dmaengine: dw-edma: Prepare deferred IRQ reporting for LL events Koichiro Den
2026-07-27 20:12 ` Frank Li
2026-07-27 17:03 ` [PATCH v3 10/24] dmaengine: dw-edma: Prepare LL kicks for event serialization Koichiro Den
2026-07-27 20:18 ` Frank Li
2026-07-27 17:03 ` [PATCH v3 11/24] dmaengine: dw-edma: Serialize LL event capture with channel kicks Koichiro Den
2026-07-27 20:35 ` Frank Li
2026-07-27 17:03 ` [PATCH v3 12/24] dmaengine: dw-edma: Keep channels stopped while ABORT is pending Koichiro Den
2026-07-27 17:19 ` sashiko-bot
2026-07-27 17:03 ` [PATCH v3 13/24] dmaengine: dw-edma: Reclaim issued descriptors from IRQ-paired LL progress Koichiro Den
2026-07-27 17:03 ` [PATCH v3 14/24] dmaengine: dw-edma: Add LL interrupt placement policy Koichiro Den
2026-07-27 17:21 ` sashiko-bot
2026-07-27 17:03 ` [PATCH v3 15/24] dmaengine: dw-edma: Recheck stopped LL channels before restart Koichiro Den
2026-07-27 17:21 ` sashiko-bot
2026-07-27 17:03 ` [PATCH v3 16/24] dmaengine: dw-edma: Use HDMA watermarks as progress events Koichiro Den
2026-07-27 17:03 ` [PATCH v3 17/24] dmaengine: dw-edma: Recover stopped channels from tx_status() Koichiro Den
2026-07-27 17:03 ` [PATCH v3 18/24] dmaengine: dw-edma: Make the LL ring reset a full channel resync Koichiro Den
2026-07-27 17:24 ` sashiko-bot
2026-07-27 17:03 ` [PATCH v3 19/24] dmaengine: dw-edma: Drain LL entries for STOP and PAUSE Koichiro Den
2026-07-27 17:30 ` sashiko-bot
2026-07-27 17:03 ` [PATCH v3 20/24] dmaengine: dw-edma: Dynamically append requests while running Koichiro Den
2026-07-27 17:03 ` [PATCH v3 21/24] dmaengine: dw-edma: Add engine reset and enable operations Koichiro Den
2026-07-27 17:03 ` [PATCH v3 22/24] dmaengine: dw-edma: Add engine recovery infrastructure Koichiro Den
2026-07-27 17:03 ` [PATCH v3 23/24] dmaengine: dw-edma: Detect and recover a stalled eDMA engine Koichiro Den
2026-07-27 17:37 ` sashiko-bot
2026-07-27 17:03 ` [PATCH v3 24/24] dmaengine: dw-edma: Add trace support Koichiro Den
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260727171722.CF8431F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=den@valinux.co.jp \
--cc=dmaengine@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.