All of lore.kernel.org
 help / color / mirror / Atom feed
From: Frank Li <Frank.li@oss.nxp.com>
To: Slavin Liu <bolin.liu@seu.edu.cn>, Joy Zou <joy.zou@nxp.com>
Cc: frank.li@nxp.com, vkoul@kernel.org, imx@lists.linux.dev,
	dmaengine@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH RFC] dmaengine: fsl-edma: check channel acquisition before use
Date: Fri, 11 Sep 2026 09:56:38 -0500	[thread overview]
Message-ID: <aqQWpnGmv1NxUGcr@SMW015318> (raw)
In-Reply-To: <20260911060902.94153-1-bolin.liu@seu.edu.cn>

On Fri, Sep 11, 2026 at 02:09:02PM +0800, Slavin Liu wrote:

Remove RFC

dmaengine: fsl-edma: check channel acquisition before mark it used.

>
> dma_get_slave_channel() can return NULL when acquiring a channel fails,
> for example if fsl_edma_alloc_chan_resources() cannot request an IRQ.
> fsl_edma3_xlate() dereferences that return value to update privatecnt.
>
> Acquire and check the channel before publishing its source ID and
> request parameters. A NULL-only check after the existing source-ID
> assignment would leave the failed request marked as in use, causing
> fsl_edma_srcid_in_use() to reject a subsequent request for that source.
> The channel resource-allocation callback does not consume these request
> parameters, so set them only after acquisition succeeds. The existing
> scoped mutex release and successful-channel return are preserved.
>
> Detected by static analysis and reviewed with AI-assisted source auditing.

Add Joy Zou, who change this logic recently

Frank

>
> Fixes: 72f5801a4e2b ("dmaengine: fsl-edma: integrate v3 support")
> Assisted-by: LLM
> Signed-off-by: Slavin Liu <bolin.liu@seu.edu.cn>
> ---
>  drivers/dma/fsl-edma-main.c | 5 ++++-
>  1 file changed, 4 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/dma/fsl-edma-main.c b/drivers/dma/fsl-edma-main.c
> index d9fb717b5b53..6934ac882697 100644
> --- a/drivers/dma/fsl-edma-main.c
> +++ b/drivers/dma/fsl-edma-main.c
> @@ -326,13 +326,16 @@ static struct dma_chan *fsl_edma3_xlate(struct of_phandle_args *dma_spec,
>                 if ((dma_spec->args[2] & FSL_EDMA_ODD_CH) && !(i & 0x1))
>                         continue;
>
> +               chan = dma_get_slave_channel(chan);
> +               if (!chan)
> +                       return NULL;
> +
>                 fsl_chan->srcid = dma_spec->args[0];
>                 fsl_chan->priority = dma_spec->args[1];
>                 fsl_chan->is_rxchan = dma_spec->args[2] & FSL_EDMA_RX;
>                 fsl_chan->is_remote = dma_spec->args[2] & FSL_EDMA_REMOTE;
>                 fsl_chan->is_multi_fifo = dma_spec->args[2] & FSL_EDMA_MULTI_FIFO;
>
> -               chan = dma_get_slave_channel(chan);
>                 chan->device->privatecnt++;
>                 return chan;
>         }
>

      parent reply	other threads:[~2026-09-11 14:56 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-11  6:09 [PATCH RFC] dmaengine: fsl-edma: check channel acquisition before use Slavin Liu
2026-09-11  6:26 ` sashiko-bot
2026-09-11 14:56 ` Frank Li [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aqQWpnGmv1NxUGcr@SMW015318 \
    --to=frank.li@oss.nxp.com \
    --cc=bolin.liu@seu.edu.cn \
    --cc=dmaengine@vger.kernel.org \
    --cc=frank.li@nxp.com \
    --cc=imx@lists.linux.dev \
    --cc=joy.zou@nxp.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.