From: sashiko-bot@kernel.org
To: "Koichiro Den" <den@valinux.co.jp>
Cc: Frank.Li@kernel.org, dmaengine@vger.kernel.org, vkoul@kernel.org
Subject: Re: [PATCH v4 15/24] dmaengine: dw-edma: Recheck stopped LL channels before restart
Date: Wed, 29 Jul 2026 14:46:53 +0000 [thread overview]
Message-ID: <20260729144654.2D3831F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260729143036.3087722-16-den@valinux.co.jp>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Double read of volatile `jiffies` variable without a snapshot leads to a race condition where the timer delay can underflow, causing indefinite stalling.
--
--- Patch [15]: [PATCH v4 15/24] dmaengine: dw-edma: Recheck stopped LL channels before restart ---
commit 9769569e17606605660b53b027f9a3d71abb5a3d
Author: Koichiro Den <den@valinux.co.jp>
dmaengine: dw-edma: Recheck stopped LL channels before restart
This commit introduces a delayed recheck mechanism for stopped LL channels.
It samples DMA_LLP again before restarting a stopped channel to reclaim
newly visible progress that might have been missed due to an interrupt race.
> diff --git a/drivers/dma/dw-edma/dw-edma-core.c b/drivers/dma/dw-edma/dw-edma-core.c
> index 16d3d2a8d1c26..0d1e6f48cac1d 100644
> --- a/drivers/dma/dw-edma/dw-edma-core.c
> +++ b/drivers/dma/dw-edma/dw-edma-core.c
[ ... ]
> +static void dw_edma_ll_recheck_work(struct work_struct *work)
> +{
> + struct dw_edma_chan *chan =
> + container_of(to_delayed_work(work), struct dw_edma_chan,
> + ll_recheck_work);
> + unsigned long delay;
> +
> + guard(spinlock_irqsave)(&chan->vc.lock);
> +
> + if (unlikely(READ_ONCE(chan->dw->teardown))) {
> + chan->ll_recheck_at = 0;
> + return;
> + }
> +
> + if (!chan->ll_recheck_at)
> + return;
> +
> + if (time_before(jiffies, chan->ll_recheck_at)) {
> + delay = chan->ll_recheck_at - jiffies;
[Severity: High]
Could this code suffer from a race condition due to reading jiffies twice?
Since jiffies is volatile, the compiler will emit two separate memory loads.
If jiffies advances past chan->ll_recheck_at between the time_before()
check and the subtraction, delay will underflow to an extremely large
unsigned value. This would schedule the recheck work indefinitely far into
the future, potentially hanging the DMA channel.
Should jiffies be cached in a local variable (e.g., unsigned long now =
jiffies;) before the check to avoid this TOCTOU race?
> + mod_delayed_work(chan->dw->wq, &chan->ll_recheck_work, delay);
> + return;
> + }
> +
> + chan->ll_recheck_at = 0;
> + if (chan->request == EDMA_REQ_NONE)
> + dw_edma_core_ch_maybe_doorbell(chan);
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260729143036.3087722-1-den@valinux.co.jp?part=15
next prev parent reply other threads:[~2026-07-29 14:46 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 14:30 [PATCH v4 00/24] dmaengine: dw-edma: Support dynamic LL appends Koichiro Den
2026-07-29 14:30 ` [PATCH v4 01/24] dmaengine: dw-edma: Add dw_edma_core_ll_cur_idx() to get current LL entry index Koichiro Den
2026-07-29 14:54 ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 02/24] dmaengine: dw-edma: Add dw_edma_core_ll_clear() to clear LL control-word Koichiro Den
2026-07-29 14:30 ` [PATCH v4 03/24] dmaengine: dw-edma: Factor out linked-list transfer start Koichiro Den
2026-07-29 14:30 ` [PATCH v4 04/24] dmaengine: dw-edma: Make DMA link list work as a circular buffer Koichiro Den
2026-07-29 14:51 ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 05/24] dmaengine: dw-edma: Move callback result helper before LL helpers Koichiro Den
2026-07-29 14:30 ` [PATCH v4 06/24] dmaengine: dw-edma: Dispatch DONE interrupts by channel request Koichiro Den
2026-07-29 14:30 ` [PATCH v4 07/24] dmaengine: dw-edma: Centralize LL doorbell decisions Koichiro Den
2026-07-29 16:01 ` Frank Li
2026-07-29 14:30 ` [PATCH v4 08/24] dmaengine: dw-edma: Prepare LL progress event handling Koichiro Den
2026-07-29 16:04 ` Frank Li
2026-07-29 16:47 ` Frank Li
2026-07-29 14:30 ` [PATCH v4 09/24] dmaengine: dw-edma: Prepare deferred IRQ reporting for LL events Koichiro Den
2026-07-29 14:30 ` [PATCH v4 10/24] dmaengine: dw-edma: Prepare LL kicks for event serialization Koichiro Den
2026-07-29 16:13 ` Frank Li
2026-07-29 14:30 ` [PATCH v4 11/24] dmaengine: dw-edma: Serialize LL event capture with channel kicks Koichiro Den
2026-07-29 14:51 ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 12/24] dmaengine: dw-edma: Keep channels stopped while ABORT is pending Koichiro Den
2026-07-29 14:30 ` [PATCH v4 13/24] dmaengine: dw-edma: Reclaim issued descriptors from IRQ-paired LL progress Koichiro Den
2026-07-29 14:30 ` [PATCH v4 14/24] dmaengine: dw-edma: Add LL interrupt placement policy Koichiro Den
2026-07-29 14:30 ` [PATCH v4 15/24] dmaengine: dw-edma: Recheck stopped LL channels before restart Koichiro Den
2026-07-29 14:46 ` sashiko-bot [this message]
2026-07-29 14:30 ` [PATCH v4 16/24] dmaengine: dw-edma: Use HDMA watermarks as progress events Koichiro Den
2026-07-29 14:30 ` [PATCH v4 17/24] dmaengine: dw-edma: Recover stopped channels from tx_status() Koichiro Den
2026-07-29 14:30 ` [PATCH v4 18/24] dmaengine: dw-edma: Make the LL ring reset a full channel resync Koichiro Den
2026-07-29 14:30 ` [PATCH v4 19/24] dmaengine: dw-edma: Drain LL entries for STOP and PAUSE Koichiro Den
2026-07-29 14:56 ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 20/24] dmaengine: dw-edma: Dynamically append requests while running Koichiro Den
2026-07-29 14:30 ` [PATCH v4 21/24] dmaengine: dw-edma: Add engine reset and enable operations Koichiro Den
2026-07-29 14:30 ` [PATCH v4 22/24] dmaengine: dw-edma: Add engine recovery infrastructure Koichiro Den
2026-07-29 15:02 ` sashiko-bot
2026-07-29 14:30 ` [PATCH v4 23/24] dmaengine: dw-edma: Detect and recover a stalled eDMA engine Koichiro Den
2026-07-29 14:30 ` [PATCH v4 24/24] dmaengine: dw-edma: Add trace support Koichiro Den
2026-07-29 14:55 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260729144654.2D3831F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=den@valinux.co.jp \
--cc=dmaengine@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox