From: sashiko-bot@kernel.org
To: "Linus Walleij" <linusw@kernel.org>
Cc: dmaengine@vger.kernel.org, Frank.Li@kernel.org, vkoul@kernel.org
Subject: Re: [PATCH v6 20/23] dmaengine: ste_dma40: Fix event group bounds
Date: Thu, 24 Sep 2026 09:28:27 +0000 [thread overview]
Message-ID: <20260924092827.AC3E71F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924-dma40-fixes-v6-20-fdb6755020a2@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] dmaengine: ste_dma40: channel aliasing for event group 4 on V4B
--
commit 48ff5fdacb29b6847b9d51f8ce427281645c1c9b
Author: Linus Walleij <linusw@kernel.org>
dmaengine: ste_dma40: Fix event group bounds
This commit fixes event group bounds validation by properly restricting
device type values to the hardware event-group range and removing incorrect
physical channel limits. It also stops physical channel searches before they
can index past the allocated channel array.
Closes: https://lore.kernel.org/dmaengine/20260819225008.5F9651F000E9@smtp.kernel.org/
> diff --git a/drivers/dma/ste_dma40.c b/drivers/dma/ste_dma40.c
> index 8b13f1360edbe..d3d79e394d028 100644
> --- a/drivers/dma/ste_dma40.c
> +++ b/drivers/dma/ste_dma40.c
[ ... ]
> @@ -2068,8 +2078,12 @@ static int d40_allocate_channel(struct d40_chan *d40c, bool *first_phy_user)
> }
> }
> } else
> - for (j = 0; j < d40c->base->num_phy_chans; j += 8) {
> + for (j = 0; j < d40c->base->num_phy_chans;
> + j += D40_GROUP_SIZE) {
> int phy_num = j + event_group * 2;
> + if (phy_num + 1 >= num_phy_chans)
> + break;
> +
[Severity: High]
Does this cause channel aliasing for event group 4 on V4B hardware?
Since D40_GROUP_SIZE is hardcoded to 8, if event_group is 4 (allowed for V4B)
and j is 0, phy_num evaluates to 8. But if event_group is 0 and j is 8,
phy_num also evaluates to 8.
Could this collision map two different groups to the same physical channel?
Additionally, since D40_PHYS_TO_GROUP is hardcoded as ((phys & 7) / 2),
channel 8 evaluates to group 0. Might this incorrectly configure the GCC clock
and hardware registers for group 0 instead of 4, breaking DMA operations for
event group 4 and channels >= 8?
[ ... ]
> @@ -2089,8 +2103,10 @@ static int d40_allocate_channel(struct d40_chan *d40c, bool *first_phy_user)
> return -EINVAL;
>
> /* Find logical channel */
> - for (j = 0; j < d40c->base->num_phy_chans; j += 8) {
> + for (j = 0; j < d40c->base->num_phy_chans; j += D40_GROUP_SIZE) {
> int phy_num = j + event_group * 2;
> + if (phy_num + 1 >= num_phy_chans)
> + break;
[Severity: High]
Will this mathematical collision also occur here for logical channel allocation
when event_group is 4?
[ ... ]
> @@ -3470,6 +3486,7 @@ static int __init d40_hw_detect_init(struct platform_device *pdev,
> base->log_chans = &base->phy_chans[num_phy_chans];
>
> if (base->plat_data->num_of_phy_chans == 14) {
> + base->gen_dmac.num_event_groups = D40_EVENT_GROUPS_V4B;
[Severity: High]
Does setting the max event groups to 5 allow event_group = 4, which
ultimately exposes the aliasing bug against the hardcoded block size of 8
in d40_allocate_channel()?
> base->gen_dmac.backup = d40_backup_regs_v4b;
> base->gen_dmac.backup_size = BACKUP_REGS_SZ_V4B;
> base->gen_dmac.interrupt_en = D40_DREG_CPCMIS;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260924-dma40-fixes-v6-0-fdb6755020a2@kernel.org?part=20
next prev parent reply other threads:[~2026-09-24 9:28 UTC|newest]
Thread overview: 45+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 8:35 [PATCH v6 00/23] dmaengine: ste_dma40: Fix numerous accumulated bugs Linus Walleij
2026-09-24 8:35 ` [PATCH v6 01/23] dmaengine: ste_dma40: Fix physical cyclic capability Linus Walleij
2026-09-24 8:35 ` [PATCH v6 02/23] dmaengine: ste_dma40: Fix cyclic transfer residue Linus Walleij
2026-09-24 14:37 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 03/23] dmaengine: ste_dma40: Recover coalesced cyclic callbacks Linus Walleij
2026-09-24 14:48 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 04/23] dmaengine: ste_dma40: Fix failed start cleanup Linus Walleij
2026-09-24 8:35 ` [PATCH v6 05/23] dmaengine: ste_dma40: Fix probe runtime PM disable Linus Walleij
2026-09-24 14:50 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 06/23] dmaengine: ste_dma40: Check runtime PM in IRQ Linus Walleij
2026-09-24 8:35 ` [PATCH v6 07/23] dmaengine: ste_dma40: Handle runtime PM resume errors Linus Walleij
2026-09-24 14:54 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 08/23] dmaengine: ste_dma40: Return IRQ_NONE when no interrupt is pending Linus Walleij
2026-09-24 14:55 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 09/23] dmaengine: ste_dma40: Init hardware before registration Linus Walleij
2026-09-24 14:58 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 10/23] dmaengine: ste_dma40: Fix probe IRQ leak Linus Walleij
2026-09-24 15:02 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 11/23] dmaengine: ste_dma40: Fix DMA registration unwind Linus Walleij
2026-09-24 9:10 ` sashiko-bot
2026-09-24 15:11 ` Frank Li
2026-09-27 8:41 ` Linus Walleij
2026-09-24 8:35 ` [PATCH v6 12/23] dmaengine: ste_dma40: Fix LCLA allocation order Linus Walleij
2026-09-24 15:16 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 13/23] dmaengine: ste_dma40: Fix probe LCLA free Linus Walleij
2026-09-24 15:34 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 14/23] dmaengine: ste_dma40: Put the LCPA SRAM node Linus Walleij
2026-09-24 15:43 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 15/23] dmaengine: ste_dma40: Fix memcpy channel parsing Linus Walleij
2026-09-24 15:49 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 16/23] dmaengine: ste_dma40: Validate disabled channel indexes Linus Walleij
2026-09-24 15:53 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 17/23] dmaengine: ste_dma40: Validate DMA specifier length Linus Walleij
2026-09-24 15:54 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 18/23] dmaengine: ste_dma40: Reject direction changes after allocation Linus Walleij
2026-09-24 15:57 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 19/23] dmaengine: ste_dma40: Fix logical channel bounds check Linus Walleij
2026-09-24 8:35 ` [PATCH v6 20/23] dmaengine: ste_dma40: Fix event group bounds Linus Walleij
2026-09-24 9:28 ` sashiko-bot [this message]
2026-09-24 8:35 ` [PATCH v6 21/23] dmaengine: ste_dma40: Search all blocks for fixed logical channels Linus Walleij
2026-09-24 16:08 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 22/23] dmaengine: ste_dma40: Validate fixed physical channel indexes Linus Walleij
2026-09-24 16:09 ` Frank Li
2026-09-24 8:35 ` [PATCH v6 23/23] dmaengine: ste_dma40: Validate memcpy configuration Linus Walleij
2026-09-24 16:11 ` Frank Li
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924092827.AC3E71F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=dmaengine@vger.kernel.org \
--cc=linusw@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.