DMA Engine development
 help / color / mirror / Atom feed
* [PATCH v3 00/11] dmaengine: miscellaneous fixes for ioat, switchtec_dma and plx_dma
@ 2026-07-27 18:15 Logan Gunthorpe
  2026-07-27 18:15 ` [PATCH v3 01/11] dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc() Logan Gunthorpe
                   ` (10 more replies)
  0 siblings, 11 replies; 37+ messages in thread
From: Logan Gunthorpe @ 2026-07-27 18:15 UTC (permalink / raw)
  To: linux-kernel, linux-pci, dmaengine, Vinod Koul
  Cc: Frank Li, Kelvin Cao, Thomas Weißschuh, Dave Jiang,
	George Ge, Jaeyoung Chung, Logan Gunthorpe

When reviewing the recent switchtec patchset[1], the Sashiko bot noticed
a handful of pre-existing problems in the ioat and switchtec drivers.
I attempted to fix those plus an unrelated issue reported in plxdma but
when I submitted those patches, Sashiko found even more issues[2][3] (it is
relentless!).

I've fixed the issues reported with v1 and v2 of this series and many
of the ones for the switchtec driver. But the pre-existing issues in ioat,
plxdma and the dmaengine itself I've punted until I can find some time
to dig into them.

The series is based off of v7.2-rc4.

Thanks,

Logan

[1] https://lore.kernel.org/all/20260707162045.23910-1-logang@deltatee.com
[2] https://sashiko.dev/#/patchset/20260717221001.361421-1-logang@deltatee.com
[3] https://sashiko.dev/#/patchset/20260721155739.62120-1-logang@deltatee.com

Changes since v2:

 * Fixed a race when unlisting the channels in the error path.
   The interrupt needed to be disabled before hand. (Per Sashiko)
 * Picked up Acked-by from Dave Jiang on the two ioat patches.

Changes since v1:

 * Added a fix for switchtec_dma_alloc_chan_resources()'s error path
   calling disable_channel() instead of properly halting the channel
   before freeing the descriptor rings. (Per Sashiko)
 * Added a fix for switchtec-dma channel structs being freed without
   being removed from dma_dev->channels on a registration failure,
   while the channel status IRQ is still live. (Per Sashiko)
 * Added a fix for switchtec_dma_remove() using swdma_dev after it may
   already have been freed by dma_async_device_unregister(). (Per
   Sashiko)
 * Added a fix for chan_status_irq being freed with the wrong API, and
   a valid vector index of 0 being incorrectly treated as unset.
   (Per Sashiko)
 * Made switchtec_dma_chans_release() void, since nothing checked its
   return value. (Noticed while reviewing the code for these changes).

Logan Gunthorpe (11):
  dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc()
  dmaengine: switchtec-dma: fix resource leak in alloc_chan_resources
  dmaengine: switchtec-dma: halt channel on alloc_chan_resources error
  dmaengine: switchtec-dma: fix channel leak on registration failure
  dmaengine: switchtec-dma: make switchtec_dma_chans_release() void
  dmaengine: switchtec-dma: fix chan_status_irq cleanup on create()
    error
  dmaengine: switchtec-dma: disable channels before freeing on
    registration failure
  dmaengine: switchtec-dma: fix use-after-free of swdma_dev in remove()
  dmaengine: ioat: disable relaxed ordering before registering the
    device
  dmaengine: ioat: use sysfs_emit() in per-channel sysfs show()
  dmaengine: plx_dma: fix NULL pointer deref in plx_dma_isr()

 drivers/dma/ioat/init.c     | 18 ++++----
 drivers/dma/ioat/sysfs.c    | 22 +++++-----
 drivers/dma/plx_dma.c       | 10 ++---
 drivers/dma/switchtec_dma.c | 84 +++++++++++++++++++++++++++----------
 4 files changed, 88 insertions(+), 46 deletions(-)


base-commit: 1590cf0329716306e948a8fc29f1d3ee87d3989f
-- 
2.47.3


^ permalink raw reply	[flat|nested] 37+ messages in thread

end of thread, other threads:[~2026-07-27 21:51 UTC | newest]

Thread overview: 37+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-27 18:15 [PATCH v3 00/11] dmaengine: miscellaneous fixes for ioat, switchtec_dma and plx_dma Logan Gunthorpe
2026-07-27 18:15 ` [PATCH v3 01/11] dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc() Logan Gunthorpe
2026-07-27 18:28   ` sashiko-bot
2026-07-27 20:42   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 02/11] dmaengine: switchtec-dma: fix resource leak in alloc_chan_resources Logan Gunthorpe
2026-07-27 18:40   ` sashiko-bot
2026-07-27 18:56     ` Logan Gunthorpe
2026-07-27 20:44   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 03/11] dmaengine: switchtec-dma: halt channel on alloc_chan_resources error Logan Gunthorpe
2026-07-27 18:51   ` sashiko-bot
2026-07-27 20:47     ` Frank Li
2026-07-27 21:28       ` Logan Gunthorpe
2026-07-27 18:15 ` [PATCH v3 04/11] dmaengine: switchtec-dma: fix channel leak on registration failure Logan Gunthorpe
2026-07-27 19:06   ` sashiko-bot
2026-07-27 20:52   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 05/11] dmaengine: switchtec-dma: make switchtec_dma_chans_release() void Logan Gunthorpe
2026-07-27 19:15   ` sashiko-bot
2026-07-27 20:54   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 06/11] dmaengine: switchtec-dma: fix chan_status_irq cleanup on create() error Logan Gunthorpe
2026-07-27 19:28   ` sashiko-bot
2026-07-27 20:55   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 07/11] dmaengine: switchtec-dma: disable channels before freeing on registration failure Logan Gunthorpe
2026-07-27 19:39   ` sashiko-bot
2026-07-27 21:21   ` Frank Li
2026-07-27 21:51     ` Logan Gunthorpe
2026-07-27 18:15 ` [PATCH v3 08/11] dmaengine: switchtec-dma: fix use-after-free of swdma_dev in remove() Logan Gunthorpe
2026-07-27 19:52   ` sashiko-bot
2026-07-27 21:23   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 09/11] dmaengine: ioat: disable relaxed ordering before registering the device Logan Gunthorpe
2026-07-27 20:06   ` sashiko-bot
2026-07-27 21:27   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 10/11] dmaengine: ioat: use sysfs_emit() in per-channel sysfs show() Logan Gunthorpe
2026-07-27 20:13   ` sashiko-bot
2026-07-27 21:28   ` Frank Li
2026-07-27 18:15 ` [PATCH v3 11/11] dmaengine: plx_dma: fix NULL pointer deref in plx_dma_isr() Logan Gunthorpe
2026-07-27 20:23   ` sashiko-bot
2026-07-27 21:29   ` Frank Li

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox