All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Rosen Penev" <rosenp@gmail.com>
Cc: vkoul@kernel.org, Frank.Li@kernel.org, dmaengine@vger.kernel.org
Subject: Re: [PATCHv3] dmaengine: fsldma: convert to platform_get_irq_optional()
Date: Fri, 11 Sep 2026 22:14:06 +0000	[thread overview]
Message-ID: <20260911221407.23ECC1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260911220439.177474-1-rosenp@gmail.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

Pre-existing issues:
- [High] The return value of dma_async_device_register() is completely ignored, leading to silent failures and a potential zombie driver state that corrupts core DMA IDA state on removal.
- [High] Missing tasklet_kill() before freeing the DMA channel structure leads to a potential Use-After-Free if a tasklet is scheduled during teardown.
--

commit d7e04e63631501d249cff16deb847b2b702a2b37
Author: Rosen Penev <rosenp@gmail.com>

dmaengine: fsldma: convert to platform_get_irq_optional()

Replace the per-controller irq_of_parse_and_map() call with
platform_get_irq_optional(). The controller IRQ is optional when absent
and the driver falls back to per-channel IRQs.

> diff --git a/drivers/dma/fsldma.c b/drivers/dma/fsldma.c
> index 22d62d958abd9..dd2937e443673 100644
> --- a/drivers/dma/fsldma.c
> +++ b/drivers/dma/fsldma.c

[ ... ]

> @@ -1300,7 +1307,6 @@ static int fsldma_of_probe(struct platform_device *op)
>  		if (fdev->chan[i])
>  			fsl_dma_chan_remove(fdev->chan[i]);

[Severity: High]
This is a pre-existing issue, but does fsl_dma_chan_remove() fail to
explicitly kill the tasklet before freeing the channel structure?

During device removal or probe error paths, fsldma_free_irqs() calls
free_irq(). If a hardware interrupt executes just before free_irq(), it
schedules chan->tasklet. free_irq() waits for the hardirq handler to finish
but does not wait for pending softirqs.

The driver then calls fsl_dma_chan_remove() which invokes kfree(chan)
without calling tasklet_kill(&chan->tasklet).

When the softirq scheduler subsequently runs the tasklet, could
dma_do_tasklet() dereference the freed chan pointer and cause a
use-after-free?


[Severity: High]
This is another pre-existing issue, but does fsldma_of_probe() ignore the
return value of dma_async_device_register() just before this error path?

fsldma_of_probe() does this right before the out_free_fdev label:

    dma_async_device_register(&fdev->common);
    return 0;

If dma_async_device_register() fails, the driver returns success but the
device is not successfully registered. On driver teardown, fsldma_of_remove()
will call dma_async_device_unregister() with this unregistered device.

Could this lead to a double-free or mis-free in the IDA allocator, freeing
an ID it never successfully acquired and corrupting the DMA engine ID
namespace?

>  	}
> -	irq_dispose_mapping(fdev->irq);
>  	iounmap(fdev->regs);
>  out_free:
>  	kfree(fdev);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260911220439.177474-1-rosenp@gmail.com?part=1

  reply	other threads:[~2026-09-11 22:14 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-11 22:04 [PATCHv3] dmaengine: fsldma: convert to platform_get_irq_optional() Rosen Penev
2026-09-11 22:14 ` sashiko-bot [this message]
2026-09-14 15:49 ` Frank Li
2026-09-15 17:36 ` Vinod Koul

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260911221407.23ECC1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=dmaengine@vger.kernel.org \
    --cc=rosenp@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.