All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Logan Gunthorpe" <logang@deltatee.com>
Cc: vkoul@kernel.org, Frank.Li@kernel.org, linux-pci@vger.kernel.org,
	dmaengine@vger.kernel.org
Subject: Re: [PATCH v3 01/11] dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc()
Date: Mon, 27 Jul 2026 18:28:31 +0000	[thread overview]
Message-ID: <20260727182831.9D26F1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260727181526.9672-2-logang@deltatee.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:

Pre-existing issues:
- [High] Memory leak of DMA channel resources on error paths in switchtec_dma_alloc_chan_resources()
- [High] Memory leak of channel structures (swdma_chan) and pointer array on driver probe error
- [High] Incorrect IRQ teardown using free_irq() with a raw MSI-X vector index instead of pci_free_irq()
--

--- Patch [1]: [PATCH v3 01/11] dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc() ---
commit e34f78c4f91061f06369e0d37a6d5d75685edb26
Author: Logan Gunthorpe <logang@deltatee.com>

dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc()

switchtec_dma_free_desc() frees swdma_chan->hw_sq, hw_cq, and every
desc_ring[] entry without clearing the pointers afterward. This patch
NULLs out each pointer as it's freed so a subsequent call is a no-op
for anything already released.

> diff --git a/drivers/dma/switchtec_dma.c b/drivers/dma/switchtec_dma.c
> index 3ef9286406159..a4a7d66d042de 100644
> --- a/drivers/dma/switchtec_dma.c
> +++ b/drivers/dma/switchtec_dma.c
> @@ -886,14 +886,18 @@ static void switchtec_dma_free_desc(struct switchtec_dma_chan *swdma_chan)
>  	if (swdma_chan->hw_sq)
>  		dma_free_coherent(swdma_dev->dma_dev.dev, size,
>  				  swdma_chan->hw_sq, swdma_chan->dma_addr_sq);
> +	swdma_chan->hw_sq = NULL;
>  
>  	size = SWITCHTEC_DMA_CQ_SIZE * sizeof(*swdma_chan->hw_cq);
>  	if (swdma_chan->hw_cq)
>  		dma_free_coherent(swdma_dev->dma_dev.dev, size,
>  				  swdma_chan->hw_cq, swdma_chan->dma_addr_cq);
> +	swdma_chan->hw_cq = NULL;
>  
> -	for (i = 0; i < SWITCHTEC_DMA_RING_SIZE; i++)
> +	for (i = 0; i < SWITCHTEC_DMA_RING_SIZE; i++) {
>  		kfree(swdma_chan->desc_ring[i]);
> +		swdma_chan->desc_ring[i] = NULL;
> +	}
>  }
>  
>  static int switchtec_dma_alloc_desc(struct switchtec_dma_chan *swdma_chan)

[Severity: High]
This isn't a bug introduced by this patch, but does
switchtec_dma_alloc_chan_resources() leak DMA channel resources on error
paths?

If switchtec_dma_alloc_desc() succeeds but a subsequent step like
enable_channel() fails, the driver returns the error code immediately:

switchtec_dma_alloc_chan_resources() {
	...
	rc = enable_channel(swdma_chan);
	if (rc)
		return rc;
	...
}

Does this fail to call switchtec_dma_free_desc() to free the resources
successfully allocated earlier in the function? Since the dmaengine core
does not automatically invoke the cleanup routine for partial failures,
could these resources be permanently leaked?

[Severity: High]
This is a pre-existing issue, but I noticed a potential memory leak of
channel structures on driver probe error.

If switchtec_dma_chans_enumerate() fails partway through, the error path
iterates over initialized channels and calls switchtec_dma_chan_free(),
but it doesn't seem to free the individual channel elements:

switchtec_dma_chans_enumerate() {
	...
err_exit:
	for (i = 0; i < chan_cnt; i++)
		switchtec_dma_chan_free(pdev, swdma_dev->swdma_chans[i]);

	kfree(swdma_dev->swdma_chans);
	...
}

Furthermore, if dma_async_device_register() fails in switchtec_dma_create(),
does the error path forget to free the channel pointer array or the
structures it points to?

switchtec_dma_create() {
	...
err_chans_release_exit:
	switchtec_dma_chans_release(pdev, swdma_dev);
	...
}

[Severity: High]
This is a pre-existing issue, but is the driver using free_irq() incorrectly
with a raw vector index instead of pci_free_irq() during teardown?

If switchtec_dma_create() encounters an error after successfully requesting
the channel status IRQ, it branches to err_exit and calls free_irq():

switchtec_dma_create() {
	...
err_exit:
	if (swdma_dev->chan_status_irq)
		free_irq(swdma_dev->chan_status_irq, swdma_dev);
	...
}

Is swdma_dev->chan_status_irq holding the raw hardware index rather than
the Linux IRQ number? Could this incorrectly free an unrelated system
interrupt and leak the originally requested IRQ?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260727181526.9672-1-logang@deltatee.com?part=1

  reply	other threads:[~2026-07-27 18:28 UTC|newest]

Thread overview: 37+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-27 18:15 [PATCH v3 00/11] dmaengine: miscellaneous fixes for ioat, switchtec_dma and plx_dma Logan Gunthorpe
2026-07-27 18:15 ` [PATCH v3 01/11] dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc() Logan Gunthorpe
2026-07-27 18:28   ` sashiko-bot [this message]
2026-07-27 20:42   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 02/11] dmaengine: switchtec-dma: fix resource leak in alloc_chan_resources Logan Gunthorpe
2026-07-27 18:40   ` sashiko-bot
2026-07-27 18:56     ` Logan Gunthorpe
2026-07-27 20:44   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 03/11] dmaengine: switchtec-dma: halt channel on alloc_chan_resources error Logan Gunthorpe
2026-07-27 18:51   ` sashiko-bot
2026-07-27 20:47     ` Frank Li
2026-07-27 21:28       ` Logan Gunthorpe
2026-07-27 18:15 ` [PATCH v3 04/11] dmaengine: switchtec-dma: fix channel leak on registration failure Logan Gunthorpe
2026-07-27 19:06   ` sashiko-bot
2026-07-27 20:52   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 05/11] dmaengine: switchtec-dma: make switchtec_dma_chans_release() void Logan Gunthorpe
2026-07-27 19:15   ` sashiko-bot
2026-07-27 20:54   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 06/11] dmaengine: switchtec-dma: fix chan_status_irq cleanup on create() error Logan Gunthorpe
2026-07-27 19:28   ` sashiko-bot
2026-07-27 20:55   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 07/11] dmaengine: switchtec-dma: disable channels before freeing on registration failure Logan Gunthorpe
2026-07-27 19:39   ` sashiko-bot
2026-07-27 21:21   ` Frank Li
2026-07-27 21:51     ` Logan Gunthorpe
2026-07-27 18:15 ` [PATCH v3 08/11] dmaengine: switchtec-dma: fix use-after-free of swdma_dev in remove() Logan Gunthorpe
2026-07-27 19:52   ` sashiko-bot
2026-07-27 21:23   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 09/11] dmaengine: ioat: disable relaxed ordering before registering the device Logan Gunthorpe
2026-07-27 20:06   ` sashiko-bot
2026-07-27 21:27   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 10/11] dmaengine: ioat: use sysfs_emit() in per-channel sysfs show() Logan Gunthorpe
2026-07-27 20:13   ` sashiko-bot
2026-07-27 21:28   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 11/11] dmaengine: plx_dma: fix NULL pointer deref in plx_dma_isr() Logan Gunthorpe
2026-07-27 20:23   ` sashiko-bot
2026-07-27 21:29   ` Frank Li

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260727182831.9D26F1F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=dmaengine@vger.kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=logang@deltatee.com \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.