DMA Engine development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Allen Pais" <allen.lkml@gmail.com>
Cc: vkoul@kernel.org, dmaengine@vger.kernel.org, Frank.Li@kernel.org
Subject: Re: [PATCH v3 17/34] dmaengine: ste_dma40: convert per-channel tasklet to dmaengine BH
Date: Mon, 10 Aug 2026 18:34:27 +0000	[thread overview]
Message-ID: <20260810183427.BD29A1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <72495a21d3eb7ef735400e1a52deb24f3e70c944.1786384168.git.allen.lkml@gmail.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:

Pre-existing issues:
- [High] Missing IRQ free on probe error path leads to Use-After-Free
- [High] Missing `device_synchronize` callback causes UAF race condition with client callbacks
- [High] Integer underflow and out-of-bounds array access on zero-length scatterlist
--

--- Patch [17]: [PATCH v3 17/34] dmaengine: ste_dma40: convert per-channel tasklet to dmaengine BH ---
commit fc9cce1bc39ef7ff38acb71e0dd932c23517c6a1
Author: Allen Pais <allen.lkml@gmail.com>

dmaengine: ste_dma40: convert per-channel tasklet to dmaengine BH
    
Replace the per-channel tasklet with the shared dmaengine BH helper.
The handler continues to run in softirq context while dmaengine owns
the common scheduling and teardown mechanism.

> diff --git a/drivers/dma/ste_dma40.c b/drivers/dma/ste_dma40.c
> index 0d9ffa3e26639..e6dfa1fc5e5ab 100644
> --- a/drivers/dma/ste_dma40.c
> +++ b/drivers/dma/ste_dma40.c
[ ... ]
> @@ -1641,7 +1638,7 @@ static void dma_tasklet(struct tasklet_struct *t)
>  	d40c->pending_tx--;
>  
>  	if (d40c->pending_tx)
> -		tasklet_schedule(&d40c->tasklet);
> +		dmaengine_schedule_bh(&d40c->chan);
>  
>  	spin_unlock_irqrestore(&d40c->lock, flags);

[Severity: High]
This is a pre-existing issue, but I noticed the callback is executed
without the channel lock held here.

Is it possible for a concurrent client termination to return early and free
resources?

The ste_dma40 driver does not implement the device_synchronize callback.
When a client calls dmaengine_terminate_sync(), the core
dmaengine_synchronize() fallback acts as a no-op.

If dmaengine_terminate_sync() is called while this background handler has
dropped the lock to execute dmaengine_desc_callback_invoke(), could the
termination return immediately instead of waiting for the callback to finish?

This might allow the client to proceed and free buffers or structures that
the background callback is actively accessing.


Also, I noticed another pre-existing issue in the probe error path:

drivers/dma/ste_dma40.c:d40_probe() {
    ...
		dev_err(dev,
			"could not register of_dma_controller\n");
		goto destroy_cache;
	}

	dev_info(base->dev, "initialized\n");
	return 0;

 destroy_cache:
	if (base->lcla_pool.dma_addr)
		dma_unmap_single(base->dev, base->lcla_pool.dma_addr,
				 SZ_1K * base->num_phy_chans,
				 DMA_TO_DEVICE);
    ...
}

[Severity: High]
This is a pre-existing issue, but does this error path need a free_irq()?

If a subsequent initialization step fails (e.g., 
of_dma_controller_register()), the code jumps to destroy_cache and returns
an error without freeing the IRQ.

Then devres automatically frees the memory allocated for the d40_base
structure.

If an interrupt fires after a probe failure, could d40_handle_interrupt()
execute using the freed base pointer?


Finally, I saw a potential out-of-bounds access in the scatterlist preparation:

drivers/dma/ste_dma40.c:d40_prep_sg() {
    ...
	desc = d40_prep_desc(chan, sg_src, sg_len, dma_flags);
	if (desc == NULL)
		goto unlock;

	if (sg_next(&sg_src[sg_len - 1]) == sg_src)
		desc->cyclic = true;
    ...
}

[Severity: High]
This is a pre-existing issue, but does this code correctly handle an empty
scatterlist?

If a client provides an empty scatterlist where sg_len is 0, does the
subtraction sg_len - 1 underflow to UINT_MAX?

Could this lead to d40_prep_desc() successfully returning a zero-length
allocation, and then the condition sg_next(&sg_src[UINT_MAX]) triggering
a massive out-of-bounds memory read?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1786384168.git.allen.lkml@gmail.com?part=17

  reply	other threads:[~2026-08-10 18:34 UTC|newest]

Thread overview: 213+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-01-08  8:03 [RFC PATCH 0/1] dmaengine: introduce dmaengine_bh_wq and bh helpers Allen Pais
2026-01-08  8:03 ` [RFC PATCH 1/1] " Allen Pais
2026-01-08 10:26   ` Arnd Bergmann
2026-01-08 19:22     ` Allen
2026-01-09 16:42       ` Arnd Bergmann
2026-01-12 22:20         ` Allen
2026-01-13  7:33           ` Arnd Bergmann
2026-01-13 19:31             ` Allen
2026-07-27 20:28 ` [PATCH v2 00/64] dmaengine: migrate channel tasklets to WQ_BH Allen Pais
2026-07-27 20:28   ` [PATCH v2 01/64] dmaengine: add tasklet-backed channel BH helpers Allen Pais
2026-07-27 20:56     ` sashiko-bot
2026-07-29 12:46       ` Vinod Koul
2026-07-29 12:48     ` Vinod Koul
2026-08-04  3:32       ` Allen
2026-07-27 20:28   ` [PATCH v2 02/64] dmaengine: back channel BH helpers with WQ_BH Allen Pais
2026-07-27 20:28   ` [PATCH v2 03/64] dmaengine: apple-admac: use dma_chan BH callback Allen Pais
2026-07-27 20:28   ` [PATCH v2 04/64] dmaengine: at_xdmac: move irq bottom half to dma_chan BH Allen Pais
2026-07-27 20:56     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 05/64] dmaengine: ep93xx: hook callbacks via " Allen Pais
2026-07-27 20:59     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 06/64] dmaengine: fsldma: migrate tasklet to " Allen Pais
2026-07-27 20:56     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 07/64] dmaengine: fsl_raid: run completions via " Allen Pais
2026-07-27 20:55     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 08/64] dmaengine: imx-dma: flip per-chan tasklet to " Allen Pais
2026-07-27 20:57     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 09/64] dmaengine: ioat: convert cleanup " Allen Pais
2026-07-27 20:38     ` Dave Jiang
2026-07-27 21:02     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 10/64] dmaengine: mmp_pdma: replace per-chan tasklet with " Allen Pais
2026-07-27 20:54     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 11/64] dmaengine: mmp_tdma: hook completions to " Allen Pais
2026-07-27 20:55     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 12/64] dmaengine: mv_xor: convert irq tasklet " Allen Pais
2026-07-27 20:57     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 13/64] dmaengine: mxs-dma: use dma_chan BH scheduling Allen Pais
2026-07-27 20:59     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 14/64] dmaengine: nbpfaxi: switch callbacks to dma_chan BH Allen Pais
2026-07-27 20:28   ` [PATCH v2 15/64] dmaengine: pch_dma: convert tasklet " Allen Pais
2026-07-27 20:57     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 16/64] dmaengine: ppc4xx: replace irq tasklet with " Allen Pais
2026-07-27 20:54     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 17/64] dmaengine: ste_dma40: convert per-channel tasklet to " Allen Pais
2026-07-27 21:00     ` sashiko-bot
2026-07-28 19:33     ` Linus Walleij
2026-07-27 20:28   ` [PATCH v2 18/64] dmaengine: xgene-dma: wire descriptor cleanup " Allen Pais
2026-07-27 20:59     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 19/64] dmaengine: xilinx-dma: use dma_chan BH instead of tasklets Allen Pais
2026-07-27 20:59     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 20/64] dmaengine: xilinx-dpdma: kill vchan BH on remove Allen Pais
2026-07-27 20:59     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 21/64] dmaengine: zynqmp-dma: switch completion tasklet to dma_chan BH Allen Pais
2026-07-27 20:54     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 22/64] dmaengine: tegra20-apb: use channel BH helpers Allen Pais
2026-07-27 20:28   ` [PATCH v2 23/64] dmaengine: timb_dma: route callbacks via channel BH Allen Pais
2026-07-27 21:09     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 24/64] dmaengine: txx9dmac: " Allen Pais
2026-07-27 21:00     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 25/64] dmaengine: mv_xor_v2: use channel BH helpers Allen Pais
2026-07-27 21:02     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 26/64] dmaengine: mpc512x: route callbacks via channel BH Allen Pais
2026-07-27 21:07     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 27/64] dmaengine: k3dma: kill vchan BH on remove Allen Pais
2026-07-27 21:02     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 28/64] dmaengine: plx_dma: use channel BH helpers Allen Pais
2026-07-27 20:38     ` Logan Gunthorpe
2026-07-27 21:09     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 29/64] dmaengine: sf-pdma: route error callbacks through channel BH Allen Pais
2026-07-27 21:06     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 30/64] dmaengine: sa11x0-dma: kill vchan BH on remove Allen Pais
2026-07-27 21:07     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 31/64] dmaengine: pl330: route callbacks via channel BH Allen Pais
2026-07-27 20:34     ` Allen Pais
2026-07-27 21:07     ` sashiko-bot
2026-07-27 20:34   ` [PATCH v2 32/64] dmaengine: k3-udma: use channel BH for vchan completions Allen Pais
2026-07-27 21:10     ` sashiko-bot
2026-07-27 20:36   ` [PATCH v2 33/64] dmaengine: sun6i: kill vchan BH on teardown Allen Pais
2026-07-27 21:08     ` sashiko-bot
2026-07-27 20:37   ` [PATCH v2 34/64] dmaengine: mtk-cqdma: " Allen Pais
2026-07-27 21:09     ` sashiko-bot
2026-07-27 20:38   ` [PATCH v2 35/64] dmaengine: altera-msgdma: use channel BH helpers Allen Pais
2026-07-27 21:06     ` sashiko-bot
2026-07-27 20:38   ` [PATCH v2 36/64] dmaengine: sprd-dma: kill vchan BH on teardown Allen Pais
2026-07-27 21:07     ` sashiko-bot
2026-07-27 20:38   ` [PATCH v2 37/64] dmaengine: idma64: " Allen Pais
2026-07-27 21:07     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 38/64] dmaengine: img-mdc-dma: " Allen Pais
2026-07-27 21:09     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 39/64] dmaengine: fsl-edma-common: " Allen Pais
2026-07-27 21:14     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 40/64] dmaengine: dw-axi-dmac: " Allen Pais
2026-07-27 21:11     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 41/64] dmaengine: hsu: " Allen Pais
2026-07-27 21:10     ` sashiko-bot
2026-07-28  8:47     ` Andy Shevchenko
2026-07-27 20:39   ` [PATCH v2 42/64] dmaengine: jz4780: " Allen Pais
2026-07-27 21:09     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 43/64] dmaengine: pxa_dma: " Allen Pais
2026-07-27 21:10     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 44/64] dmaengine: mtk-hsdma: " Allen Pais
2026-07-27 21:09     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 45/64] dmaengine: mtk-uart-apdma: " Allen Pais
2026-07-27 21:14     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 46/64] dmaengine: imx-sdma: " Allen Pais
2026-07-27 21:17     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 47/64] dmaengine: loongson1-apb: " Allen Pais
2026-07-27 21:17     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 48/64] dmaengine: owl-dma: " Allen Pais
2026-07-27 21:17     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 49/64] dmaengine: hisi: " Allen Pais
2026-07-27 21:20     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 50/64] dmaengine: dw-edma: " Allen Pais
2026-07-27 21:18     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 51/64] dmaengine: bcm2835: " Allen Pais
2026-07-27 21:20     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 52/64] dmaengine: tegra210-adma: " Allen Pais
2026-07-27 21:17     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 53/64] dmaengine: fsl-qdma: use dma_chan_kill_bh Allen Pais
2026-07-27 21:17     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 54/64] dmaengine: st_fdma: " Allen Pais
2026-07-27 21:18     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 55/64] dmaengine: dma-axi-dmac: " Allen Pais
2026-07-27 21:18     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 56/64] dmaengine: omap-dma: " Allen Pais
2026-07-27 21:25     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 57/64] dmaengine: edma: " Allen Pais
2026-07-27 21:20     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 58/64] dmaengine: qcom-adm: " Allen Pais
2026-07-27 21:17     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 59/64] dmaengine: tegra186-gpc: " Allen Pais
2026-07-27 21:23     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 60/64] dmaengine: bam-dma: " Allen Pais
2026-07-27 21:19     ` sashiko-bot
2026-07-28  8:38     ` Bartosz Golaszewski
2026-07-27 20:39   ` [PATCH v2 61/64] dmaengine: dw: defer callbacks via channel BH Allen Pais
2026-07-27 21:31     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 62/64] dmaengine: hidma: " Allen Pais
2026-07-27 21:25     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 63/64] dmaengine: qcom-gpi: defer callbacks via vchan Allen Pais
2026-07-27 21:24     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 64/64] dmaengine: switchtec: use channel BH helpers Allen Pais
2026-07-27 21:08     ` Logan Gunthorpe
2026-07-27 21:22     ` sashiko-bot
2026-07-28 20:39   ` [PATCH v2 00/64] dmaengine: migrate channel tasklets to WQ_BH Arnd Bergmann
2026-08-04  3:29     ` Allen
2026-08-10 18:09   ` [PATCH v3 00/34] " Allen Pais
2026-08-10 18:09     ` [PATCH v3 01/34] dmaengine: add tasklet-backed channel BH helpers Allen Pais
2026-08-10 18:30       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 02/34] dmaengine: back channel BH helpers with WQ_BH Allen Pais
2026-08-10 18:09     ` [PATCH v3 03/34] dmaengine: apple-admac: use dmaengine BH callback Allen Pais
2026-08-10 18:29       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 04/34] dmaengine: at_xdmac: move irq bottom half to dmaengine BH Allen Pais
2026-08-10 18:35       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 05/34] dmaengine: ep93xx: hook callbacks via " Allen Pais
2026-08-10 18:31       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 06/34] dmaengine: fsldma: migrate tasklet to " Allen Pais
2026-08-10 18:29       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 07/34] dmaengine: fsl_raid: run completions via " Allen Pais
2026-08-10 18:27       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 08/34] dmaengine: imx-dma: flip per-chan tasklet to " Allen Pais
2026-08-10 18:34       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 09/34] dmaengine: ioat: convert cleanup " Allen Pais
2026-08-10 18:27       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 10/34] dmaengine: mmp_pdma: replace per-chan tasklet with " Allen Pais
2026-08-10 18:28       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 11/34] dmaengine: mmp_tdma: hook completions to " Allen Pais
2026-08-10 18:28       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 12/34] dmaengine: mv_xor: convert irq tasklet " Allen Pais
2026-08-10 18:27       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 13/34] dmaengine: mxs-dma: use dmaengine BH scheduling Allen Pais
2026-08-10 18:27       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 14/34] dmaengine: nbpfaxi: switch callbacks to dmaengine BH Allen Pais
2026-08-10 18:23       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 15/34] dmaengine: pch_dma: convert tasklet " Allen Pais
2026-08-10 18:34       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 16/34] dmaengine: ppc4xx: replace irq tasklet with " Allen Pais
2026-08-10 18:36       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 17/34] dmaengine: ste_dma40: convert per-channel tasklet to " Allen Pais
2026-08-10 18:34       ` sashiko-bot [this message]
2026-08-10 18:09     ` [PATCH v3 18/34] dmaengine: xgene-dma: wire descriptor cleanup " Allen Pais
2026-08-10 18:35       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 19/34] dmaengine: xilinx-dma: use dmaengine BH instead of tasklets Allen Pais
2026-08-10 18:28       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 20/34] dmaengine: xilinx-dpdma: kill vchan BH on remove Allen Pais
2026-08-10 18:31       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 21/34] dmaengine: zynqmp-dma: switch completion tasklet to dmaengine BH Allen Pais
2026-08-10 18:35       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 22/34] dmaengine: tegra20-apb: use channel BH helpers Allen Pais
2026-08-10 18:40       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 23/34] dmaengine: timb_dma: route callbacks via channel BH Allen Pais
2026-08-10 18:45       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 24/34] dmaengine: txx9dmac: " Allen Pais
2026-08-10 18:34       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 25/34] dmaengine: mv_xor_v2: use channel BH helpers Allen Pais
2026-08-10 18:46       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 26/34] dmaengine: mpc512x: route callbacks via channel BH Allen Pais
2026-08-10 18:50       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 27/34] dmaengine: plx_dma: use channel BH helpers Allen Pais
2026-08-10 18:39       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 28/34] dmaengine: sf-pdma: route error callbacks through channel BH Allen Pais
2026-08-10 18:41       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 29/34] dmaengine: pl330: route callbacks via " Allen Pais
2026-08-10 18:39       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 30/34] dmaengine: altera-msgdma: use channel BH helpers Allen Pais
2026-08-10 18:49       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 31/34] dmaengine: dw: defer callbacks via channel BH Allen Pais
2026-08-10 18:44       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 32/34] dmaengine: hidma: " Allen Pais
2026-08-10 18:45       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 33/34] dmaengine: qcom-gpi: defer callbacks via vchan Allen Pais
2026-08-10 18:50       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 34/34] dmaengine: switchtec: use channel BH helpers Allen Pais
2026-08-10 18:43       ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260810183427.BD29A1F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=allen.lkml@gmail.com \
    --cc=dmaengine@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox