All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Koichiro Den" <den@valinux.co.jp>
Cc: vkoul@kernel.org, dmaengine@vger.kernel.org, Frank.Li@kernel.org
Subject: Re: [PATCH v4 04/24] dmaengine: dw-edma: Make DMA link list work as a circular buffer
Date: Wed, 29 Jul 2026 14:51:35 +0000	[thread overview]
Message-ID: <20260729145136.540A51F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260729143036.3087722-5-den@valinux.co.jp>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Hardware abort interrupt silently stalls pending descriptors and sets channel to IDLE, risking use-after-free on subsequent transfers
--

--- Patch [4]: [PATCH v4 04/24] dmaengine: dw-edma: Make DMA link list work as a circular buffer ---
commit e57484a362fa80a92a80a905cb57fb2805286319
Author: Frank Li <Frank.Li@nxp.com>
dmaengine: dw-edma: Make DMA link list work as a circular buffer

This commit modifies the driver to operate the DMA linked list as a
circular ring buffer instead of rebuilding it per transfer. It also adds
ring resets after channel stops to prevent inheriting occupied slots.

> diff --git a/drivers/dma/dw-edma/dw-edma-core.c b/drivers/dma/dw-edma/dw-edma-core.c
> index 6a25a050b89c4..d7a8a43b71d64 100644
> --- a/drivers/dma/dw-edma/dw-edma-core.c
> +++ b/drivers/dma/dw-edma/dw-edma-core.c
[ ... ]
> @@ -685,6 +748,8 @@ static void dw_edma_abort_interrupt(struct dw_edma_chan *chan)
>  		list_del(&vd->node);
>  		vchan_cookie_complete(vd);
>  	}
> +	if (!chan->non_ll)
> +		dw_edma_core_reset_ll(chan);
>  	chan->request = EDMA_REQ_NONE;
>  	chan->status = EDMA_ST_IDLE;
>  	spin_unlock_irqrestore(&chan->vc.lock, flags);

[Severity: High]
This is a pre-existing issue, but does dw_edma_abort_interrupt() leave stale
descriptors in the desc_issued queue?

When a hardware abort interrupt occurs, the active descriptor is aborted
and removed, but the remaining queued descriptors are not flushed. Since
the channel status is set directly to EDMA_ST_IDLE, will a subsequent
dma_async_issue_pending() silently resume executing these stale descriptors?

If a client assumed the batch was canceled and freed the memory, would
the DMA engine accessing these leftover descriptors cause a use-after-free?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260729143036.3087722-1-den@valinux.co.jp?part=4

  reply	other threads:[~2026-07-29 14:51 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-29 14:30 [PATCH v4 00/24] dmaengine: dw-edma: Support dynamic LL appends Koichiro Den
2026-07-29 14:30 ` [PATCH v4 01/24] dmaengine: dw-edma: Add dw_edma_core_ll_cur_idx() to get current LL entry index Koichiro Den
2026-07-29 14:54   ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 02/24] dmaengine: dw-edma: Add dw_edma_core_ll_clear() to clear LL control-word Koichiro Den
2026-07-29 14:30 ` [PATCH v4 03/24] dmaengine: dw-edma: Factor out linked-list transfer start Koichiro Den
2026-07-29 14:30 ` [PATCH v4 04/24] dmaengine: dw-edma: Make DMA link list work as a circular buffer Koichiro Den
2026-07-29 14:51   ` sashiko-bot [this message]
2026-07-29 14:30 ` [PATCH v4 05/24] dmaengine: dw-edma: Move callback result helper before LL helpers Koichiro Den
2026-07-29 14:30 ` [PATCH v4 06/24] dmaengine: dw-edma: Dispatch DONE interrupts by channel request Koichiro Den
2026-07-29 14:30 ` [PATCH v4 07/24] dmaengine: dw-edma: Centralize LL doorbell decisions Koichiro Den
2026-07-29 16:01   ` Frank Li
2026-07-29 14:30 ` [PATCH v4 08/24] dmaengine: dw-edma: Prepare LL progress event handling Koichiro Den
2026-07-29 16:04   ` Frank Li
2026-07-29 16:47   ` Frank Li
2026-07-29 14:30 ` [PATCH v4 09/24] dmaengine: dw-edma: Prepare deferred IRQ reporting for LL events Koichiro Den
2026-07-29 14:30 ` [PATCH v4 10/24] dmaengine: dw-edma: Prepare LL kicks for event serialization Koichiro Den
2026-07-29 16:13   ` Frank Li
2026-07-29 14:30 ` [PATCH v4 11/24] dmaengine: dw-edma: Serialize LL event capture with channel kicks Koichiro Den
2026-07-29 14:51   ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 12/24] dmaengine: dw-edma: Keep channels stopped while ABORT is pending Koichiro Den
2026-07-29 14:30 ` [PATCH v4 13/24] dmaengine: dw-edma: Reclaim issued descriptors from IRQ-paired LL progress Koichiro Den
2026-07-29 14:30 ` [PATCH v4 14/24] dmaengine: dw-edma: Add LL interrupt placement policy Koichiro Den
2026-07-29 14:30 ` [PATCH v4 15/24] dmaengine: dw-edma: Recheck stopped LL channels before restart Koichiro Den
2026-07-29 14:46   ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 16/24] dmaengine: dw-edma: Use HDMA watermarks as progress events Koichiro Den
2026-07-29 14:30 ` [PATCH v4 17/24] dmaengine: dw-edma: Recover stopped channels from tx_status() Koichiro Den
2026-07-29 14:30 ` [PATCH v4 18/24] dmaengine: dw-edma: Make the LL ring reset a full channel resync Koichiro Den
2026-07-29 14:30 ` [PATCH v4 19/24] dmaengine: dw-edma: Drain LL entries for STOP and PAUSE Koichiro Den
2026-07-29 14:56   ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 20/24] dmaengine: dw-edma: Dynamically append requests while running Koichiro Den
2026-07-29 14:30 ` [PATCH v4 21/24] dmaengine: dw-edma: Add engine reset and enable operations Koichiro Den
2026-07-29 14:30 ` [PATCH v4 22/24] dmaengine: dw-edma: Add engine recovery infrastructure Koichiro Den
2026-07-29 15:02   ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 23/24] dmaengine: dw-edma: Detect and recover a stalled eDMA engine Koichiro Den
2026-07-29 14:30 ` [PATCH v4 24/24] dmaengine: dw-edma: Add trace support Koichiro Den
2026-07-29 14:55   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260729145136.540A51F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=den@valinux.co.jp \
    --cc=dmaengine@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.