From: sashiko-bot@kernel.org
To: "Sai Sree Kartheek Adivi" <s-adivi@ti.com>
Cc: robh@kernel.org, vkoul@kernel.org, devicetree@vger.kernel.org,
Frank.Li@kernel.org, dmaengine@vger.kernel.org,
conor+dt@kernel.org
Subject: Re: [PATCH v8 11/19] dmaengine: ti: k3-udma: move inclusion of k3-udma-private.c to k3-udma-common.c
Date: Mon, 10 Aug 2026 16:27:33 +0000 [thread overview]
Message-ID: <20260810162733.A335D1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260810151423.1948224-12-s-adivi@ti.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
New issues:
- [High] Moving `xudma_*` exports to `k3-udma-common.c` severs the module dependency between the glue layer and the `k3-udma` driver, allowing trivial module unload and subsequent use-after-free.
Pre-existing issues:
- [High] `of_xudma_dev_get` returns a pointer to devres-managed memory without establishing a device link, allowing use-after-free via sysfs unbind.
--
--- Patch [11]: [PATCH v8 11/19] dmaengine: ti: k3-udma: move inclusion of k3-udma-private.c to k3-udma-common.c ---
commit d7f9cc34a06f8d7304b5d1021da68dd8f487667c
Author: Sai Sree Kartheek Adivi <s-adivi@ti.com>
dmaengine: ti: k3-udma: move inclusion of k3-udma-private.c to k3-udma-common.c
This commit relocates the inclusion of k3-udma-private.c from k3-udma.c to
k3-udma-common.c to allow sharing the code with other udma variants.
> diff --git a/drivers/dma/ti/k3-udma-common.c b/drivers/dma/ti/k3-udma-common.c
> index b9d3cac5eb9d0..01b66e9f026b4 100644
> --- a/drivers/dma/ti/k3-udma-common.c
> +++ b/drivers/dma/ti/k3-udma-common.c
[ ... ]
> @@ -2535,3 +2535,6 @@ EXPORT_SYMBOL_GPL(k3_udma_setup_resources);
>
> MODULE_DESCRIPTION("Texas Instruments K3 UDMA Common Library");
> MODULE_LICENSE("GPL v2");
> +
> +/* Private interfaces to UDMA */
> +#include "k3-udma-private.c"
[Severity: High]
Does moving this include introduce a regression by shifting the xudma_*
exports from the k3-udma module to the k3-udma-common module?
The k3-udma-glue.ko module bypasses the standard dma engine framework and
relies on these xudma_* functions. Previously, these functions were exported
by the k3-udma.ko driver, establishing a module dependency that prevented
k3-udma.ko from being unloaded while active.
By moving the exports to k3-udma-common.ko, k3-udma-glue.ko no longer holds
a reference to k3-udma.ko. If an administrator runs rmmod k3-udma, could it
successfully unbind the driver and free the devm-allocated struct udma_dev,
causing a use-after-free in the networking drivers on their next operation?
[Severity: High]
This is a pre-existing issue in k3-udma-private.c, but looking at how
of_xudma_dev_get() is implemented:
drivers/dma/ti/k3-udma-private.c:of_xudma_dev_get() {
...
ud = platform_get_drvdata(pdev);
put_device(&pdev->dev);
if (!ud) {
...
}
Since of_xudma_dev_get() drops the device reference before returning the
pointer to the devres-managed struct udma_dev, and does not establish a
supplier-consumer relationship via device_link_add(), can this lead to a
use-after-free if a privileged user unbinds the driver via sysfs?
The driver core would be unaware of the glue layer's dependency, allowing the
unbind to succeed and free udma_dev while consumers hold a dangling pointer.
> diff --git a/drivers/dma/ti/k3-udma.c b/drivers/dma/ti/k3-udma.c
> index 9a261747c8709..ddedd51ab26d9 100644
> --- a/drivers/dma/ti/k3-udma.c
> +++ b/drivers/dma/ti/k3-udma.c
[ ... ]
> @@ -2857,5 +2857,3 @@ module_platform_driver(udma_driver);
> MODULE_DESCRIPTION("Texas Instruments UDMA support");
> MODULE_LICENSE("GPL v2");
>
> -/* Private interfaces to UDMA */
> -#include "k3-udma-private.c"
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260810151423.1948224-1-s-adivi@ti.com?part=11
next prev parent reply other threads:[~2026-08-10 16:27 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-10 15:13 [PATCH v8 00/19] dmaengine: ti: Add support for BCDMA v2 and PKTDMA v2 Sai Sree Kartheek Adivi
2026-08-10 15:13 ` [PATCH v8 01/19] dmaengine: ti: k3-udma: Fix sporadic crash on AM62x Sai Sree Kartheek Adivi
2026-08-10 15:36 ` sashiko-bot
2026-08-10 15:13 ` [PATCH v8 02/19] dmaengine: ti: k3-udma: move macros to header file Sai Sree Kartheek Adivi
2026-08-10 15:25 ` sashiko-bot
2026-08-10 15:13 ` [PATCH v8 03/19] dmaengine: ti: k3-udma: move structs and enums " Sai Sree Kartheek Adivi
2026-08-10 15:13 ` [PATCH v8 04/19] dmaengine: ti: k3-udma: move static inline helper functions " Sai Sree Kartheek Adivi
2026-08-10 15:13 ` [PATCH v8 05/19] dmaengine: ti: k3-udma: move descriptor management to k3-udma-common.c Sai Sree Kartheek Adivi
2026-08-10 15:56 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 06/19] dmaengine: ti: k3-udma: move ring management functions " Sai Sree Kartheek Adivi
2026-08-10 15:52 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 07/19] dmaengine: ti: k3-udma: Add variant-specific function pointers to udma_dev Sai Sree Kartheek Adivi
2026-08-10 16:06 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 08/19] dmaengine: ti: k3-udma: move udma utility functions to k3-udma-common.c Sai Sree Kartheek Adivi
2026-08-10 16:09 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 09/19] dmaengine: ti: k3-udma: move resource management " Sai Sree Kartheek Adivi
2026-08-10 16:26 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 10/19] dmaengine: ti: k3-udma: refactor resource setup functions Sai Sree Kartheek Adivi
2026-08-10 15:14 ` [PATCH v8 11/19] dmaengine: ti: k3-udma: move inclusion of k3-udma-private.c to k3-udma-common.c Sai Sree Kartheek Adivi
2026-08-10 16:27 ` sashiko-bot [this message]
2026-08-10 15:14 ` [PATCH v8 12/19] drivers: soc: ti: k3-ringacc: handle absence of tisci Sai Sree Kartheek Adivi
2026-08-10 16:38 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 13/19] dt-bindings: dma: ti: Add K3 BCDMA V2 Sai Sree Kartheek Adivi
2026-08-11 6:32 ` Krzysztof Kozlowski
2026-08-10 15:14 ` [PATCH v8 14/19] dt-bindings: dma: ti: Add K3 PKTDMA V2 Sai Sree Kartheek Adivi
2026-08-10 15:14 ` [PATCH v8 15/19] dmaengine: ti: k3-psil-am62l: Add AM62Lx PSIL and PDMA data Sai Sree Kartheek Adivi
2026-08-10 16:45 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 16/19] dmaengine: ti: k3-udma-v2: New driver for K3 BCDMA_V2 Sai Sree Kartheek Adivi
2026-08-10 17:04 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 17/19] dmaengine: ti: k3-udma-v2: Add support for PKTDMA V2 Sai Sree Kartheek Adivi
2026-08-10 17:09 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 18/19] dmaengine: ti: k3-udma-v2: Update glue layer to support " Sai Sree Kartheek Adivi
2026-08-10 17:20 ` sashiko-bot
2026-08-10 15:14 ` [PATCH v8 19/19] dmaengine: ti: k3-udma: Validate resource ID and fix logging in reservation Sai Sree Kartheek Adivi
2026-08-10 17:35 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260810162733.A335D1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=dmaengine@vger.kernel.org \
--cc=robh@kernel.org \
--cc=s-adivi@ti.com \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.