All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Rosen Penev" <rosenp@gmail.com>
Cc: vkoul@kernel.org, Frank.Li@kernel.org, dmaengine@vger.kernel.org
Subject: Re: [PATCHv2] dmaengine: bestcomm: ioremap early
Date: Wed, 02 Sep 2026 21:54:51 +0000	[thread overview]
Message-ID: <20260902215452.2079E1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260902214612.311207-1-rosenp@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] The globally exported `bcom_eng` pointer is freed but not nullified on the probe error path, leaving a dangling pointer.
--

commit c9ef17db56df7b3bc923fc0c2ee2b7acf55e223b
Author: Rosen Penev <rosenp@gmail.com>

dmaengine: bestcomm: ioremap early

This commit replaces the open-coded resource lookup and cleanup in the
bestcomm driver probe and remove paths with the managed
devm_platform_get_and_ioremap_resource() helper, simplifying error handling.

> diff --git a/drivers/dma/bestcomm/bestcomm.c b/drivers/dma/bestcomm/bestcomm.c
> index 432b43520ddc9..44ff4a42376b1 100644
> --- a/drivers/dma/bestcomm/bestcomm.c
> +++ b/drivers/dma/bestcomm/bestcomm.c
[ ... ]
> @@ -439,10 +422,6 @@ static int mpc52xx_bcom_probe(struct platform_device *op)
>  	return 0;
>  
>  	/* Error path */
> -error_unmap:
> -	iounmap(bcom_eng->regs);
> -error_release:
> -	release_mem_region(res_bcom.start, sizeof(struct mpc52xx_sdma));
>  error_sramclean:
>  	kfree(bcom_eng);

[Severity: High]
This isn't a bug introduced by this patch, but is it possible for the global
bcom_eng pointer to be left dangling here?

On the error path when mpc52xx_bcom_probe() fails (e.g., if
bcom_engine_init() returns an error), kfree(bcom_eng) is called but bcom_eng
is not explicitly reset to NULL.

Could local system drivers (like those in drivers/net/ethernet/freescale/)
calling exported functions such as bcom_task_alloc() bypass safety checks
since bcom_eng is not NULL, and proceed to dereference freed memory
(for instance, when attempting to acquire bcom_eng->lock)?

>  	bcom_sram_cleanup();

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260902214612.311207-1-rosenp@gmail.com?part=1

  reply	other threads:[~2026-09-02 21:54 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-02 21:46 [PATCHv2] dmaengine: bestcomm: ioremap early Rosen Penev
2026-09-02 21:54 ` sashiko-bot [this message]
2026-09-04 15:50 ` Frank Li

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260902215452.2079E1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=dmaengine@vger.kernel.org \
    --cc=rosenp@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.