From: sashiko-bot@kernel.org
To: "Sai Sree Kartheek Adivi" <s-adivi@ti.com>
Cc: dmaengine@vger.kernel.org, conor+dt@kernel.org, robh@kernel.org,
devicetree@vger.kernel.org, Frank.Li@kernel.org,
vkoul@kernel.org
Subject: Re: [PATCH v8 07/19] dmaengine: ti: k3-udma: Add variant-specific function pointers to udma_dev
Date: Mon, 10 Aug 2026 16:06:45 +0000 [thread overview]
Message-ID: <20260810160646.48DAF1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260810151423.1948224-8-s-adivi@ti.com>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
New issues:
- [Medium] Unconditional invocation of optional psil_pair and psil_unpair function pointers leads to potential NULL pointer dereferences.
Pre-existing issues:
- [High] Debug objects leak due to misuse of INIT_DELAYED_WORK_ONSTACK for heap-allocated work items.
- [High] Unconditional destruction of hdesc_pool in the error path of pktdma_alloc_chan_resources causes a double-free.
--
--- Patch [7]: [PATCH v8 07/19] dmaengine: ti: k3-udma: Add variant-specific function pointers to udma_dev ---
commit e169d39794002b63060719c1aeef8f8eb77d45c6
Author: Sai Sree Kartheek Adivi <s-adivi@ti.com>
dmaengine: ti: k3-udma: Add variant-specific function pointers to udma_dev
Introduce function pointers in the udma_dev structure to allow
variant-specific implementations for certain operations.
This prepares the driver for supporting multiple K3 UDMA variants,
such as UDMA v2, with minimal code duplication.
> diff --git a/drivers/dma/ti/k3-udma.c b/drivers/dma/ti/k3-udma.c
> index 40ba114ac81dd..c44a12157e65f 100644
> --- a/drivers/dma/ti/k3-udma.c
> +++ b/drivers/dma/ti/k3-udma.c
[ ... ]
> @@ -1663,7 +1663,7 @@ static int udma_alloc_chan_resources(struct dma_chan *chan)
> }
>
> /* PSI-L pairing */
> - ret = navss_psil_pair(ud, uc->config.src_thread, uc->config.dst_thread);
> + ret = ud->psil_pair(ud, uc->config.src_thread, uc->config.dst_thread);
[Severity: Medium]
Will this crash if a future variant does not support PSI-L pairing?
The wrapper function xudma_navss_psil_pair() checks if ud->psil_pair is set
before calling it, but this direct call does not. If a future variant leaves
this pointer unassigned, couldn't this result in a NULL pointer dereference?
[ ... ]
> @@ -1849,8 +1849,8 @@ static int bcdma_alloc_chan_resources(struct dma_chan *chan)
> uc->use_dma_pool = true;
> } else if (uc->config.dir != DMA_MEM_TO_MEM) {
> /* PSI-L pairing */
> - ret = navss_psil_pair(ud, uc->config.src_thread,
> - uc->config.dst_thread);
> + ret = ud->psil_pair(ud, uc->config.src_thread,
> + uc->config.dst_thread);
[Severity: High]
This isn't a bug introduced by this patch, but I noticed a pre-existing issue
in bcdma_alloc_chan_resources() and pktdma_alloc_chan_resources(). It looks
like the work item is initialized as a stack object but it's embedded within
the heap-allocated struct udma_chan:
INIT_DELAYED_WORK_ONSTACK(&uc->tx_drain.work,
udma_check_tx_completion);
Since destroy_delayed_work_on_stack() is never called when the channel is
freed, wouldn't every allocation/free cycle leak a debug object, eventually
leading to ODEBUG OOM warnings?
[ ... ]
> @@ -2083,7 +2083,7 @@ static int pktdma_alloc_chan_resources(struct dma_chan *chan)
> err_irq_free:
> uc->irq_num_ring = 0;
> err_psi_free:
> - navss_psil_unpair(ud, uc->config.src_thread, uc->config.dst_thread);
> + ud->psil_unpair(ud, uc->config.src_thread, uc->config.dst_thread);
> uc->psil_paired = false;
> err_res_free:
> udma_free_tx_resources(uc);
[Severity: High]
This is a pre-existing issue, but the error path in
pktdma_alloc_chan_resources() unconditionally destroys the dma pool:
err_res_free:
udma_free_tx_resources(uc);
udma_free_rx_resources(uc);
udma_reset_uchan(uc);
dma_pool_destroy(uc->hdesc_pool);
If a channel is freed (leaving uc->hdesc_pool as a dangling pointer), and
later re-requested but fails early in the allocation process, wouldn't this
jump to err_res_free and cause a double-free of the pool?
Unlike other paths, there's no check for uc->use_dma_pool here.
[ ... ]
> @@ -2374,8 +2374,8 @@ static void udma_free_chan_resources(struct dma_chan *chan)
>
> /* Release PSI-L pairing */
> if (uc->psil_paired) {
> - navss_psil_unpair(ud, uc->config.src_thread,
> - uc->config.dst_thread);
> + ud->psil_unpair(ud, uc->config.src_thread,
> + uc->config.dst_thread);
[Severity: Medium]
As mentioned earlier, does this need a check for ud->psil_unpair being
non-NULL to avoid a potential panic if a future variant lacks PSI-L pairing
support?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260810151423.1948224-1-s-adivi@ti.com?part=7
next prev parent reply other threads:[~2026-08-10 16:06 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-10 15:13 [PATCH v8 00/19] dmaengine: ti: Add support for BCDMA v2 and PKTDMA v2 Sai Sree Kartheek Adivi
2026-08-10 15:13 ` [PATCH v8 01/19] dmaengine: ti: k3-udma: Fix sporadic crash on AM62x Sai Sree Kartheek Adivi
2026-08-10 15:36 ` sashiko-bot
2026-08-10 15:13 ` [PATCH v8 02/19] dmaengine: ti: k3-udma: move macros to header file Sai Sree Kartheek Adivi
2026-08-10 15:25 ` sashiko-bot
2026-08-10 15:13 ` [PATCH v8 03/19] dmaengine: ti: k3-udma: move structs and enums " Sai Sree Kartheek Adivi
2026-08-10 15:13 ` [PATCH v8 04/19] dmaengine: ti: k3-udma: move static inline helper functions " Sai Sree Kartheek Adivi
2026-08-10 15:13 ` [PATCH v8 05/19] dmaengine: ti: k3-udma: move descriptor management to k3-udma-common.c Sai Sree Kartheek Adivi
2026-08-10 15:56 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 06/19] dmaengine: ti: k3-udma: move ring management functions " Sai Sree Kartheek Adivi
2026-08-10 15:52 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 07/19] dmaengine: ti: k3-udma: Add variant-specific function pointers to udma_dev Sai Sree Kartheek Adivi
2026-08-10 16:06 ` sashiko-bot [this message]
2026-08-10 15:14 ` [PATCH v8 08/19] dmaengine: ti: k3-udma: move udma utility functions to k3-udma-common.c Sai Sree Kartheek Adivi
2026-08-10 16:09 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 09/19] dmaengine: ti: k3-udma: move resource management " Sai Sree Kartheek Adivi
2026-08-10 16:26 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 10/19] dmaengine: ti: k3-udma: refactor resource setup functions Sai Sree Kartheek Adivi
2026-08-10 15:14 ` [PATCH v8 11/19] dmaengine: ti: k3-udma: move inclusion of k3-udma-private.c to k3-udma-common.c Sai Sree Kartheek Adivi
2026-08-10 16:27 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 12/19] drivers: soc: ti: k3-ringacc: handle absence of tisci Sai Sree Kartheek Adivi
2026-08-10 16:38 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 13/19] dt-bindings: dma: ti: Add K3 BCDMA V2 Sai Sree Kartheek Adivi
2026-08-11 6:32 ` Krzysztof Kozlowski
2026-08-10 15:14 ` [PATCH v8 14/19] dt-bindings: dma: ti: Add K3 PKTDMA V2 Sai Sree Kartheek Adivi
2026-08-10 15:14 ` [PATCH v8 15/19] dmaengine: ti: k3-psil-am62l: Add AM62Lx PSIL and PDMA data Sai Sree Kartheek Adivi
2026-08-10 16:45 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 16/19] dmaengine: ti: k3-udma-v2: New driver for K3 BCDMA_V2 Sai Sree Kartheek Adivi
2026-08-10 17:04 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 17/19] dmaengine: ti: k3-udma-v2: Add support for PKTDMA V2 Sai Sree Kartheek Adivi
2026-08-10 17:09 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 18/19] dmaengine: ti: k3-udma-v2: Update glue layer to support " Sai Sree Kartheek Adivi
2026-08-10 17:20 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 19/19] dmaengine: ti: k3-udma: Validate resource ID and fix logging in reservation Sai Sree Kartheek Adivi
2026-08-10 17:35 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260810160646.48DAF1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=dmaengine@vger.kernel.org \
--cc=robh@kernel.org \
--cc=s-adivi@ti.com \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.