From: sashiko-bot@kernel.org
To: "Vikash Garodia" <vikash.garodia@oss.qualcomm.com>
Cc: media-ci@linuxtv.org, conor+dt@kernel.org, robh@kernel.org,
devicetree@vger.kernel.org
Subject: Re: [PATCH 04/22] arm64: dts: qcom: hamoa: Reserve low IOVA range for Iris
Date: Fri, 07 Aug 2026 08:45:15 +0000 [thread overview]
Message-ID: <20260807084516.2BCDA1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260807-iris_iova_600mb_fix-v1-4-3996f67e33f9@oss.qualcomm.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Missing bounds check, incorrect pointer advancement, and potential NULL pointer dereference when parsing the `iommu-addresses` property.
--
--- Patch [4]: [PATCH 04/22] arm64: dts: qcom: hamoa: Reserve low IOVA range for Iris ---
commit 0d7d545a5dddd31b4e0cc75f7a486bdd8ebe240d
Author: Daniel J Blueman <daniel@quora.org>
arm64: dts: qcom: hamoa: Reserve low IOVA range for Iris
This commit adds a reserved iova region below 0x25800000 for the Iris vpu on
hamoa platforms to prevent smmu faults. It references this reserved memory
using the iommu-addresses property to keep dma allocations above the boundary.
Link: https://github.com/qualcomm-linux/kernel-topics/issues/1157#issuecomment-4458933574
> diff --git a/arch/arm64/boot/dts/qcom/hamoa.dtsi b/arch/arm64/boot/dts/qcom/hamoa.dtsi
> index 8a96ea1bdb9c4..87f424765d513 100644
> --- a/arch/arm64/boot/dts/qcom/hamoa.dtsi
> +++ b/arch/arm64/boot/dts/qcom/hamoa.dtsi
> @@ -666,6 +666,17 @@ smem_mem: smem@ffe00000 {
> hwlocks = <&tcsr_mutex 3>;
> no-map;
> };
> +
> + /*
> + * The Iris VPU reserves IOVA below 0x25800000 (600MB),
> + * primarily for non-pixel buffers using different Stream IDs.
> + * DMA into that range triggers unhandled SMMU faults and
> + * spontaneous reboots, so reserve it to keep IOMMU
> + * allocations above this boundary.
> + */
> + iris_iova: iris-iova {
> + iommu-addresses = <&iris 0x0 0x0 0x0 0x25800000>;
[Severity: High]
This isn't a bug introduced by this patch, but adding this iommu-addresses
property could trigger a pre-existing issue in the device tree parsing logic.
Looking at of_iommu_get_resv_regions() in drivers/iommu/of_iommu.c, when
parsing the iommu-addresses property, if a parsed phandle does not match
dev->of_node, the loop fails to skip the parent's na + ns cells:
drivers/iommu/of_iommu.c:of_iommu_get_resv_regions() {
...
while (maps < end) {
struct device_node *np;
u32 phandle;
phandle = be32_to_cpup(maps++);
np = of_find_node_by_phandle(phandle);
if (np == dev->of_node) {
// ...
maps = of_translate_dma_region(np, maps, &iova, &length);
...
}
Because maps is only incremented by 1 cell (the phandle) instead of
1 + na + ns, the parser becomes misaligned. Subsequent iterations will
interpret address and size cells as phandles.
Additionally, if of_translate_dma_region() fails, it returns null. The loop
then assigns null to maps. Since end is a valid kernel pointer, the maps < end
check passes on the next iteration, and be32_to_cpup(maps++) dereferences the
null pointer.
Furthermore, in of_translate_dma_region(), there is no bounds checking against
the property's allocation size:
drivers/of/address.c:of_translate_dma_region() {
...
address = of_translate_dma_address(dev, prop);
if (address == OF_BAD_ADDR)
return NULL;
size = of_read_number(prop + na, ns);
...
}
If the parser is misaligned and a false match occurs near the end of the
buffer, this can read out-of-bounds heap memory.
Does this new device tree property risk exposing these parsing issues if
multiple entries or malformed data are present in the device tree?
> + };
> };
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260807-iris_iova_600mb_fix-v1-0-3996f67e33f9@oss.qualcomm.com?part=4
next prev parent reply other threads:[~2026-08-07 8:45 UTC|newest]
Thread overview: 59+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <5BXSXMNl656WiJPJAMmHvb3I2NzYMshRZuGuub3CxEXvdCUlIDKYbnv5jUq-pa6P1NibBLkO3njnKGxi7Al3jQ==@protonmail.internalid>
2026-08-07 8:24 ` [PATCH 00/22] media: iris: Restrict lower IOVA range for Venus and Iris VPUs Vikash Garodia
2026-08-07 8:24 ` [PATCH 01/22] dt-bindings: media: qcom,venus-common: Allow IOVA reservation memory-region Vikash Garodia
2026-08-07 8:49 ` sashiko-bot
2026-08-07 8:51 ` Vikash Garodia
2026-08-07 8:24 ` [PATCH 02/22] dt-bindings: media: qcom,sm8550-iris: " Vikash Garodia
2026-08-07 8:40 ` sashiko-bot
2026-08-07 9:01 ` Dmitry Baryshkov
2026-08-07 8:24 ` [PATCH 03/22] dt-bindings: media: qcom,sc7180-venus: " Vikash Garodia
2026-08-07 8:24 ` [PATCH 04/22] arm64: dts: qcom: hamoa: Reserve low IOVA range for Iris Vikash Garodia
2026-08-07 8:45 ` sashiko-bot [this message]
2026-08-07 9:03 ` Dmitry Baryshkov
2026-08-07 9:26 ` Vikash Garodia
2026-08-07 10:00 ` Dmitry Baryshkov
2026-08-07 10:22 ` Vikash Garodia
2026-08-07 13:18 ` Bryan O'Donoghue
2026-08-08 15:48 ` Vikash Garodia
2026-08-10 12:10 ` Dmitry Baryshkov
2026-08-10 16:57 ` Vikash Garodia
2026-08-11 0:17 ` Dmitry Baryshkov
2026-08-07 16:24 ` Rob Herring
2026-08-08 4:37 ` Vishnu Reddy
2026-08-08 9:55 ` Bryan O'Donoghue
2026-08-10 13:47 ` Rob Herring
2026-08-07 8:24 ` [PATCH 05/22] arm64: dts: qcom: lemans: " Vikash Garodia
2026-08-07 8:44 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 06/22] arm64: dts: qcom: monaco: " Vikash Garodia
2026-08-07 8:47 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 07/22] arm64: dts: qcom: sc8280xp: " Vikash Garodia
2026-08-07 8:44 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 08/22] arm64: dts: qcom: sm8350: " Vikash Garodia
2026-08-07 8:50 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 09/22] arm64: dts: qcom: sm8550: " Vikash Garodia
2026-08-07 8:46 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 10/22] arm64: dts: qcom: sm8650: " Vikash Garodia
2026-08-07 8:42 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 11/22] arm64: dts: qcom: sm8750: " Vikash Garodia
2026-08-07 8:54 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 12/22] arm64: dts: qcom: agatti: Reserve low IOVA range for Venus Vikash Garodia
2026-08-07 8:57 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 13/22] arm64: dts: qcom: kodiak: " Vikash Garodia
2026-08-07 8:54 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 14/22] arm64: dts: qcom: msm8916: " Vikash Garodia
2026-08-07 8:58 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 15/22] arm64: dts: qcom: msm8996: " Vikash Garodia
2026-08-07 8:25 ` [PATCH 16/22] arm64: dts: qcom: msm8998: " Vikash Garodia
2026-08-07 8:25 ` [PATCH 17/22] arm64: dts: qcom: sc7180: " Vikash Garodia
2026-08-07 8:59 ` sashiko-bot
2026-08-07 8:25 ` [PATCH 18/22] arm64: dts: qcom: sdm630: " Vikash Garodia
2026-08-07 9:00 ` sashiko-bot
2026-08-07 8:25 ` [PATCH 19/22] arm64: dts: qcom: sdm845: " Vikash Garodia
2026-08-07 8:25 ` [PATCH 20/22] arm64: dts: qcom: sm6115: " Vikash Garodia
2026-08-07 9:05 ` sashiko-bot
2026-08-07 8:25 ` [PATCH 21/22] arm64: dts: qcom: sm8250: " Vikash Garodia
2026-08-07 8:25 ` [PATCH 22/22] arm64: dts: qcom: talos: " Vikash Garodia
2026-08-07 9:08 ` sashiko-bot
2026-08-07 8:51 ` [PATCH 00/22] media: iris: Restrict lower IOVA range for Venus and Iris VPUs Bryan O'Donoghue
2026-08-07 8:59 ` Dmitry Baryshkov
2026-08-07 9:05 ` Vikash Garodia
2026-08-07 10:01 ` Dmitry Baryshkov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260807084516.2BCDA1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=media-ci@linuxtv.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vikash.garodia@oss.qualcomm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.