From: sashiko-bot@kernel.org
To: "Koichiro Den" <den@valinux.co.jp>
Cc: Frank.Li@kernel.org, vkoul@kernel.org, dmaengine@vger.kernel.org
Subject: Re: [PATCH v4 01/24] dmaengine: dw-edma: Add dw_edma_core_ll_cur_idx() to get current LL entry index
Date: Wed, 29 Jul 2026 14:54:47 +0000 [thread overview]
Message-ID: <20260729145448.36D751F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260729143036.3087722-2-den@valinux.co.jp>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] The linked-list index computation lacks bounds checking and underflows on PCIe link loss, returning a massive positive integer that bypasses negative error checks.
--
--- Patch [1]: [PATCH v4 01/24] dmaengine: dw-edma: Add dw_edma_core_ll_cur_idx() to get current LL entry index ---
commit 97ea1bc0d0cff65116038aa18e1ba530b5bbe7c9
Author: Frank Li <Frank.Li@nxp.com>
dmaengine: dw-edma: Add dw_edma_core_ll_cur_idx() to get current LL entry index
This commit adds dw_edma_core_ll_cur_idx() to retrieve the current LL entry
index, preparing for dynamic addition of DMA requests while the DMA engine
is running.
> diff --git a/drivers/dma/dw-edma/dw-edma-v0-core.c b/drivers/dma/dw-edma/dw-edma-v0-core.c
> index abc1bd4c0be2e..7b9a95ecedbb6 100644
> --- a/drivers/dma/dw-edma/dw-edma-v0-core.c
> +++ b/drivers/dma/dw-edma/dw-edma-v0-core.c
[ ... ]
> @@ -616,6 +616,24 @@ static void dw_edma_v0_core_ch_doorbell(struct dw_edma_chan *chan)
> FIELD_PREP(EDMA_V0_DOORBELL_CH_MASK, chan->id));
> }
>
> +static int dw_edma_v0_core_ll_cur_idx(struct dw_edma_chan *chan)
> +{
> + u32 base, val;
> +
> + val = GET_CH_32(chan->dw, chan->dir, chan->id, llp.lsb);
> + base = lower_32_bits(dw_edma_core_get_ll_paddr(chan));
> +
> + /*
> + * LL regions stay within one 4 GiB address window. If the low word is
> + * zero, use the high word to distinguish a nonzero boundary address
> + * from an unprogrammed all-zero context.
> + */
> + if (!val && !GET_CH_32(chan->dw, chan->dir, chan->id, llp.msb))
> + return -EINVAL;
> +
> + return (val - base) / EDMA_LL_SZ;
[Severity: High]
If a PCIe link loss or hardware error occurs, the MMIO read for llp.lsb could
return all-Fs (0xFFFFFFFF). Could this cause the unsigned subtraction of
(val - base) to underflow into a massive positive integer?
If val is 0xFFFFFFFF, the !val check is bypassed. After division by EDMA_LL_SZ
(24), this yields a very large positive index that fits comfortably within a
signed 32-bit int. Will this bypass negative error checks in callers and lead
to an out-of-bounds memory access when the index is used?
> +}
[ ... ]
> diff --git a/drivers/dma/dw-edma/dw-hdma-v0-core.c b/drivers/dma/dw-edma/dw-hdma-v0-core.c
> index 36ee72efcd317..d849220f3b5d3 100644
> --- a/drivers/dma/dw-edma/dw-hdma-v0-core.c
> +++ b/drivers/dma/dw-edma/dw-hdma-v0-core.c
[ ... ]
> @@ -384,6 +384,24 @@ static void dw_hdma_v0_core_ch_doorbell(struct dw_edma_chan *chan)
> SET_CH_32(dw, chan->dir, chan->id, doorbell, HDMA_V0_DOORBELL_START);
> }
>
> +static int dw_hdma_v0_core_ll_cur_idx(struct dw_edma_chan *chan)
> +{
> + u32 base, val;
> +
> + val = GET_CH_32(chan->dw, chan->dir, chan->id, llp.lsb);
> + base = lower_32_bits(dw_edma_core_get_ll_paddr(chan));
> +
> + /*
> + * LL regions stay within one 4 GiB address window. If the low word is
> + * zero, use the high word to distinguish a nonzero boundary address
> + * from an unprogrammed all-zero context.
> + */
> + if (!val && !GET_CH_32(chan->dw, chan->dir, chan->id, llp.msb))
> + return -EINVAL;
> +
> + return (val - base) / EDMA_LL_SZ;
[Severity: High]
Like the v0 core implementation, does this HDMA arithmetic need bounds checking
to prevent a stale hardware pointer where val < base, or a PCIe link loss,
from returning a large positive integer instead of a negative error code?
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260729143036.3087722-1-den@valinux.co.jp?part=1
next prev parent reply other threads:[~2026-07-29 14:54 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 14:30 [PATCH v4 00/24] dmaengine: dw-edma: Support dynamic LL appends Koichiro Den
2026-07-29 14:30 ` [PATCH v4 01/24] dmaengine: dw-edma: Add dw_edma_core_ll_cur_idx() to get current LL entry index Koichiro Den
2026-07-29 14:54 ` sashiko-bot [this message]
2026-07-29 14:30 ` [PATCH v4 02/24] dmaengine: dw-edma: Add dw_edma_core_ll_clear() to clear LL control-word Koichiro Den
2026-07-29 14:30 ` [PATCH v4 03/24] dmaengine: dw-edma: Factor out linked-list transfer start Koichiro Den
2026-07-29 14:30 ` [PATCH v4 04/24] dmaengine: dw-edma: Make DMA link list work as a circular buffer Koichiro Den
2026-07-29 14:51 ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 05/24] dmaengine: dw-edma: Move callback result helper before LL helpers Koichiro Den
2026-07-29 14:30 ` [PATCH v4 06/24] dmaengine: dw-edma: Dispatch DONE interrupts by channel request Koichiro Den
2026-07-29 14:30 ` [PATCH v4 07/24] dmaengine: dw-edma: Centralize LL doorbell decisions Koichiro Den
2026-07-29 16:01 ` Frank Li
2026-07-29 14:30 ` [PATCH v4 08/24] dmaengine: dw-edma: Prepare LL progress event handling Koichiro Den
2026-07-29 16:04 ` Frank Li
2026-07-29 16:47 ` Frank Li
2026-07-29 14:30 ` [PATCH v4 09/24] dmaengine: dw-edma: Prepare deferred IRQ reporting for LL events Koichiro Den
2026-07-29 14:30 ` [PATCH v4 10/24] dmaengine: dw-edma: Prepare LL kicks for event serialization Koichiro Den
2026-07-29 16:13 ` Frank Li
2026-07-29 14:30 ` [PATCH v4 11/24] dmaengine: dw-edma: Serialize LL event capture with channel kicks Koichiro Den
2026-07-29 14:51 ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 12/24] dmaengine: dw-edma: Keep channels stopped while ABORT is pending Koichiro Den
2026-07-29 14:30 ` [PATCH v4 13/24] dmaengine: dw-edma: Reclaim issued descriptors from IRQ-paired LL progress Koichiro Den
2026-07-29 14:30 ` [PATCH v4 14/24] dmaengine: dw-edma: Add LL interrupt placement policy Koichiro Den
2026-07-29 14:30 ` [PATCH v4 15/24] dmaengine: dw-edma: Recheck stopped LL channels before restart Koichiro Den
2026-07-29 14:46 ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 16/24] dmaengine: dw-edma: Use HDMA watermarks as progress events Koichiro Den
2026-07-29 14:30 ` [PATCH v4 17/24] dmaengine: dw-edma: Recover stopped channels from tx_status() Koichiro Den
2026-07-29 14:30 ` [PATCH v4 18/24] dmaengine: dw-edma: Make the LL ring reset a full channel resync Koichiro Den
2026-07-29 14:30 ` [PATCH v4 19/24] dmaengine: dw-edma: Drain LL entries for STOP and PAUSE Koichiro Den
2026-07-29 14:56 ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 20/24] dmaengine: dw-edma: Dynamically append requests while running Koichiro Den
2026-07-29 14:30 ` [PATCH v4 21/24] dmaengine: dw-edma: Add engine reset and enable operations Koichiro Den
2026-07-29 14:30 ` [PATCH v4 22/24] dmaengine: dw-edma: Add engine recovery infrastructure Koichiro Den
2026-07-29 15:02 ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 23/24] dmaengine: dw-edma: Detect and recover a stalled eDMA engine Koichiro Den
2026-07-29 14:30 ` [PATCH v4 24/24] dmaengine: dw-edma: Add trace support Koichiro Den
2026-07-29 14:55 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260729145448.36D751F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=den@valinux.co.jp \
--cc=dmaengine@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.