All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Vikash Garodia" <vikash.garodia@oss.qualcomm.com>
Cc: media-ci@linuxtv.org, devicetree@vger.kernel.org,
	robh@kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH 10/22] arm64: dts: qcom: sm8650: Reserve low IOVA range for Iris
Date: Fri, 07 Aug 2026 08:42:55 +0000	[thread overview]
Message-ID: <20260807084255.DE04A1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260807-iris_iova_600mb_fix-v1-10-3996f67e33f9@oss.qualcomm.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

Pre-existing issues:
- [High] Pre-existing parsing bug in `of_iommu_get_resv_regions()` causing misalignment and incorrect parsing when encountering non-matching shared reservations.
- [High] Missing NULL check for the return value of `of_translate_dma_region()` causes a kernel panic if address translation fails.
--

--- Patch [10]: [PATCH 10/22] arm64: dts: qcom: sm8650: Reserve low IOVA range for Iris ---
commit 0235003bbbcd1eb35cb1bdeb1f805b1bd98ddfd1
Author: Vikash Garodia <vikash.garodia@oss.qualcomm.com>

arm64: dts: qcom: sm8650: Reserve low IOVA range for Iris

Iris VPU reserves IOVA addresses below 0x25800000, primarily for secure
non-pixel buffers. This commit adds a reserved-memory IOVA reservation
node covering [0, 0x25800000] and references it from the Iris node to keep
DMA allocations above that boundary.

> diff --git a/arch/arm64/boot/dts/qcom/sm8650.dtsi b/arch/arm64/boot/dts/qcom/sm8650.dtsi
> --- a/arch/arm64/boot/dts/qcom/sm8650.dtsi
> +++ b/arch/arm64/boot/dts/qcom/sm8650.dtsi
[ ... ]
> @@ -5266,7 +5277,7 @@ &config_noc SLAVE_VENUS_CFG QCOM_ICC_TAG_ACTIVE_ONLY>,
>  			interconnect-names = "cpu-cfg",
>  					     "video-mem";
>  
> -			memory-region = <&video_mem>;
> +			memory-region = <&video_mem>, <&iris_iova>;

[Severity: High]
This isn't a bug introduced by this patch, but does adding multiple entries
to a memory-region expose a parsing bug in of_iommu_get_resv_regions()?

When processing a node with multiple entries, if an earlier phandle in the
list does not match dev->of_node, the loop in drivers/iommu/of_iommu.c
fails to advance the maps pointer over the address and size cells:

drivers/iommu/of_iommu.c:of_iommu_get_resv_regions() {
    phandle = be32_to_cpup(maps++);
    np = of_find_node_by_phandle(phandle);

    if (np == dev->of_node) {
        ...
        maps = of_translate_dma_region(np, maps, &iova, &length);
        ...
    }
    /* Missing advancement of maps if np != dev->of_node */
}

Will the next iteration erroneously read the unparsed address or size cells
as the next phandle, corrupting the device tree parsing?

[Severity: High]
This is another pre-existing issue in the same parsing area, but could
address translation failures lead to a kernel panic here?

If of_translate_dma_region() fails (for example, if the device lacks a DMA
parent), it returns NULL. The return value is assigned directly to maps
without checking:

drivers/iommu/of_iommu.c:of_iommu_get_resv_regions() {
    ...
    maps = of_translate_dma_region(np, maps, &iova, &length);
    if (length == 0) {
    ...
}

On the next loop iteration, the condition maps < end will be evaluated
where NULL is less than the valid kernel pointer end, and
be32_to_cpup(maps++) will dereference the NULL pointer.

Could this trigger a crash on boot if an untranslatable DMA region is
encountered?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260807-iris_iova_600mb_fix-v1-0-3996f67e33f9@oss.qualcomm.com?part=10

  reply	other threads:[~2026-08-07  8:42 UTC|newest]

Thread overview: 59+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <5BXSXMNl656WiJPJAMmHvb3I2NzYMshRZuGuub3CxEXvdCUlIDKYbnv5jUq-pa6P1NibBLkO3njnKGxi7Al3jQ==@protonmail.internalid>
2026-08-07  8:24 ` [PATCH 00/22] media: iris: Restrict lower IOVA range for Venus and Iris VPUs Vikash Garodia
2026-08-07  8:24   ` [PATCH 01/22] dt-bindings: media: qcom,venus-common: Allow IOVA reservation memory-region Vikash Garodia
2026-08-07  8:49     ` sashiko-bot
2026-08-07  8:51       ` Vikash Garodia
2026-08-07  8:24   ` [PATCH 02/22] dt-bindings: media: qcom,sm8550-iris: " Vikash Garodia
2026-08-07  8:40     ` sashiko-bot
2026-08-07  9:01     ` Dmitry Baryshkov
2026-08-07  8:24   ` [PATCH 03/22] dt-bindings: media: qcom,sc7180-venus: " Vikash Garodia
2026-08-07  8:24   ` [PATCH 04/22] arm64: dts: qcom: hamoa: Reserve low IOVA range for Iris Vikash Garodia
2026-08-07  8:45     ` sashiko-bot
2026-08-07  9:03     ` Dmitry Baryshkov
2026-08-07  9:26       ` Vikash Garodia
2026-08-07 10:00         ` Dmitry Baryshkov
2026-08-07 10:22           ` Vikash Garodia
2026-08-07 13:18             ` Bryan O'Donoghue
2026-08-08 15:48               ` Vikash Garodia
2026-08-10 12:10                 ` Dmitry Baryshkov
2026-08-10 16:57                   ` Vikash Garodia
2026-08-11  0:17                     ` Dmitry Baryshkov
2026-08-07 16:24       ` Rob Herring
2026-08-08  4:37         ` Vishnu Reddy
2026-08-08  9:55           ` Bryan O'Donoghue
2026-08-10 13:47             ` Rob Herring
2026-08-07  8:24   ` [PATCH 05/22] arm64: dts: qcom: lemans: " Vikash Garodia
2026-08-07  8:44     ` sashiko-bot
2026-08-07  8:24   ` [PATCH 06/22] arm64: dts: qcom: monaco: " Vikash Garodia
2026-08-07  8:47     ` sashiko-bot
2026-08-07  8:24   ` [PATCH 07/22] arm64: dts: qcom: sc8280xp: " Vikash Garodia
2026-08-07  8:44     ` sashiko-bot
2026-08-07  8:24   ` [PATCH 08/22] arm64: dts: qcom: sm8350: " Vikash Garodia
2026-08-07  8:50     ` sashiko-bot
2026-08-07  8:24   ` [PATCH 09/22] arm64: dts: qcom: sm8550: " Vikash Garodia
2026-08-07  8:46     ` sashiko-bot
2026-08-07  8:24   ` [PATCH 10/22] arm64: dts: qcom: sm8650: " Vikash Garodia
2026-08-07  8:42     ` sashiko-bot [this message]
2026-08-07  8:24   ` [PATCH 11/22] arm64: dts: qcom: sm8750: " Vikash Garodia
2026-08-07  8:54     ` sashiko-bot
2026-08-07  8:24   ` [PATCH 12/22] arm64: dts: qcom: agatti: Reserve low IOVA range for Venus Vikash Garodia
2026-08-07  8:57     ` sashiko-bot
2026-08-07  8:24   ` [PATCH 13/22] arm64: dts: qcom: kodiak: " Vikash Garodia
2026-08-07  8:54     ` sashiko-bot
2026-08-07  8:24   ` [PATCH 14/22] arm64: dts: qcom: msm8916: " Vikash Garodia
2026-08-07  8:58     ` sashiko-bot
2026-08-07  8:24   ` [PATCH 15/22] arm64: dts: qcom: msm8996: " Vikash Garodia
2026-08-07  8:25   ` [PATCH 16/22] arm64: dts: qcom: msm8998: " Vikash Garodia
2026-08-07  8:25   ` [PATCH 17/22] arm64: dts: qcom: sc7180: " Vikash Garodia
2026-08-07  8:59     ` sashiko-bot
2026-08-07  8:25   ` [PATCH 18/22] arm64: dts: qcom: sdm630: " Vikash Garodia
2026-08-07  9:00     ` sashiko-bot
2026-08-07  8:25   ` [PATCH 19/22] arm64: dts: qcom: sdm845: " Vikash Garodia
2026-08-07  8:25   ` [PATCH 20/22] arm64: dts: qcom: sm6115: " Vikash Garodia
2026-08-07  9:05     ` sashiko-bot
2026-08-07  8:25   ` [PATCH 21/22] arm64: dts: qcom: sm8250: " Vikash Garodia
2026-08-07  8:25   ` [PATCH 22/22] arm64: dts: qcom: talos: " Vikash Garodia
2026-08-07  9:08     ` sashiko-bot
2026-08-07  8:51   ` [PATCH 00/22] media: iris: Restrict lower IOVA range for Venus and Iris VPUs Bryan O'Donoghue
2026-08-07  8:59   ` Dmitry Baryshkov
2026-08-07  9:05     ` Vikash Garodia
2026-08-07 10:01       ` Dmitry Baryshkov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260807084255.DE04A1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=media-ci@linuxtv.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vikash.garodia@oss.qualcomm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.