DMA Engine development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Allen Pais" <allen.lkml@gmail.com>
Cc: vkoul@kernel.org, Frank.Li@kernel.org, dmaengine@vger.kernel.org
Subject: Re: [PATCH v3 30/34] dmaengine: altera-msgdma: use channel BH helpers
Date: Mon, 10 Aug 2026 18:49:24 +0000	[thread overview]
Message-ID: <20260810184924.DDC241F000E9@smtp.kernel.org> (raw)
In-Reply-To: <21c92aefc28557597024ee450f1690761ba6d452.1786384169.git.allen.lkml@gmail.com>

Thank you for your contribution! Sashiko AI review found 7 potential issue(s) to consider:

Pre-existing issues:
- [High] The failure path in `msgdma_probe()` does not call `dma_async_device_unregister()` if `of_dma_controller_register()` fails, leading to a Use-After-Free.
- [High] The IRQ handler is requested before crucial data structures, lists, spinlocks, and the bottom-half worker are initialized, which can cause a kernel panic on an early interrupt.
- [High] Batching multiple DMA transactions causes dropped transfers due to incorrect list splicing in `msgdma_start_transfer()`.
- [High] Dropping the spinlock while iterating a list via `list_for_each_entry_safe` enables arbitrary concurrent list destruction, leading to a Use-After-Free.
- [High] Zero-length transfers bypass descriptor limit checking, breaking accounting metrics and eventually leading to a NULL pointer dereference.
- [High] A hardware-induced soft lockup where the driver spins infinitely with interrupts disabled if the hardware descriptor FIFO remains full.
- [High] Missing bitmask application when reading the response fill-level register allows undefined upper bits to impose massive computational loops, freezing the kernel.
--

--- Patch [30]: [PATCH v3 30/34] dmaengine: altera-msgdma: use channel BH helpers ---
commit 728ca1a7dab7d5ba74ab85afa0d21836b794d564
Author: Allen Pais <allen.lkml@gmail.com>

dmaengine: altera-msgdma: use channel BH helpers

Replace the device tasklet with the per-channel BH helper so completion
handling runs via dmaengine_*_bh.

> diff --git a/drivers/dma/altera-msgdma.c b/drivers/dma/altera-msgdma.c
> index e23e5b441a24e..c8e145cea6d25 100644
> --- a/drivers/dma/altera-msgdma.c
> +++ b/drivers/dma/altera-msgdma.c
[ ... ]
> @@ -684,11 +683,12 @@ static int msgdma_alloc_chan_resources(struct dma_chan *dchan)
>  
>  /**
>   * msgdma_tasklet - Schedule completion tasklet
> - * @t: Pointer to the Altera sSGDMA channel structure
> + * @chan: Pointer to the Altera sSGDMA channel structure
>   */
> -static void msgdma_tasklet(struct tasklet_struct *t)
> +static void msgdma_tasklet(struct dma_chan *chan)
>  {
> -	struct msgdma_device *mdev = from_tasklet(mdev, t, irq_tasklet);
> +	struct msgdma_device *mdev = container_of(chan, struct msgdma_device,
> +						  dmachan);
>  	u32 count;
>  	u32 __maybe_unused size;
>  	u32 __maybe_unused status;

[Severity: High]
This isn't a bug introduced by this patch, but there appears to be a missing
bitmask on the response fill-level read further down in this function:

	if (mdev->resp) {
		/* Read number of responses that are available */
		count = ioread32(mdev->csr + MSGDMA_CSR_RESP_FILL_LEVEL);

The macro MSGDMA_CSR_RESP_FILL_LEVEL_GET() exists but isn't used here. If the
upper 16 bits contain non-zero data, count will be massively inflated. Could
this cause the subsequent while (count--) loop to iterate excessively and
cause a CPU stall?

[ ... ]
> @@ -766,7 +766,7 @@ static void msgdma_dev_remove(struct msgdma_device *mdev)
>  		return;
>  
>  	devm_free_irq(mdev->dev, mdev->irq, mdev);
> -	tasklet_kill(&mdev->irq_tasklet);
> +	dmaengine_kill_bh(&mdev->dmachan);
>  	list_del(&mdev->dmachan.device_node);
>  }

[Severity: High]
This is a pre-existing issue, but I have a question about the cleanup path.

If dma_async_device_register() succeeds in msgdma_probe(), but
of_dma_controller_register() fails, the code jumps to the fail label and calls
msgdma_dev_remove().

However, msgdma_dev_remove() lacks a dma_async_device_unregister() call. Since
mdev was allocated with devm_kzalloc(), it is automatically freed on probe
failure. Does this leave the dmaengine core with dangling pointers and cause
a Use-After-Free?

[ ... ]
> @@ -852,7 +852,7 @@ static int msgdma_probe(struct platform_device *pdev)
>  	if (ret)
>  		return ret;
>  
> -	tasklet_setup(&mdev->irq_tasklet, msgdma_tasklet);
> +	dmaengine_init_bh(&mdev->dmachan, msgdma_tasklet);
>  
>  	dma_cookie_init(&mdev->dmachan);

[Severity: High]
This isn't a bug introduced by this patch, but I have a question about the
initialization order here.

Higher up in msgdma_probe(), devm_request_irq() is called before the BH worker,
spinlocks, and lists are initialized.

If an interrupt fires immediately upon registration, could msgdma_irq_handler()
attempt to lock the uninitialized spinlock, access uninitialized lists in
msgdma_start_transfer(), and schedule an uninitialized BH worker?

I also noticed several other pre-existing issues in this file:

[Severity: High]
This is a pre-existing issue, but I noticed something concerning in how batched
transfers are handled.

In msgdma_start_transfer():

	desc = list_first_entry_or_null(&mdev->pending_list,
					struct msgdma_sw_desc, node);
	if (!desc)
		return;

	list_splice_tail_init(&mdev->pending_list, &mdev->active_list);
	msgdma_copy_desc_to_fifo(mdev, desc);

When multiple transactions are queued, this takes the first descriptor but moves
the entire pending_list to active_list using list_splice_tail_init(). However,
it only copies the first descriptor to the hardware FIFO.

When this transfer completes, subsequent transactions remain trapped in
active_list because msgdma_start_transfer() only checks pending_list. Does this
result in dropped transfers when a client driver batches multiple requests?

[Severity: High]
This is a pre-existing issue, but the lock dropping pattern seems dangerous.

In msgdma_chan_desc_cleanup(), the code iterates over mdev->done_list using
list_for_each_entry_safe and temporarily drops mdev->lock:

		if (dmaengine_desc_callback_valid(&cb)) {
			spin_unlock_irqrestore(&mdev->lock, irqflags);
			dmaengine_desc_callback_invoke(&cb, NULL);
			spin_lock_irqsave(&mdev->lock, irqflags);
		}

If dma_release_channel() is called concurrently, msgdma_free_chan_resources()
can acquire the lock, reset all lists, and free the backing array with
kfree(mdev->sw_desq). When msgdma_chan_desc_cleanup() reacquires the lock, its
next pointer will reference freed memory. Can this race lead to a
Use-After-Free?

[Severity: High]
This isn't a bug introduced by this patch, but there seems to be an accounting
flaw for zero-length transfers.

In msgdma_prep_memcpy():

	desc_cnt = DIV_ROUND_UP(len, MSGDMA_MAX_TRANS_LEN);
	...
	mdev->desc_free_cnt -= desc_cnt;
	...
	do {
		/* Allocate and populate the descriptor */
		new = msgdma_get_descriptor(mdev);
		...
	} while (len);

If len is 0, desc_cnt is 0. The free count check passes, and desc_free_cnt is
decremented by 0.

However, the do-while loop executes exactly once, withdrawing a physical
descriptor from mdev->free_list via msgdma_get_descriptor(). If multiple
zero-length requests are submitted, won't this drain free_list entirely without
decrementing desc_free_cnt, eventually causing a NULL pointer dereference in
msgdma_get_descriptor()?

[Severity: High]
This is a pre-existing issue, but I am worried about the polling loop in
msgdma_copy_one():

	while (ioread32(mdev->csr + MSGDMA_CSR_STATUS) &
	       MSGDMA_CSR_STAT_DESC_BUF_FULL)
		mdelay(1);

Since this function is invoked under a spinlock with local interrupts disabled,
could a malfunctioning hardware device permanently stall the CPU core and trigger
the NMI watchdog?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1786384168.git.allen.lkml@gmail.com?part=30

  reply	other threads:[~2026-08-10 18:49 UTC|newest]

Thread overview: 213+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-01-08  8:03 [RFC PATCH 0/1] dmaengine: introduce dmaengine_bh_wq and bh helpers Allen Pais
2026-01-08  8:03 ` [RFC PATCH 1/1] " Allen Pais
2026-01-08 10:26   ` Arnd Bergmann
2026-01-08 19:22     ` Allen
2026-01-09 16:42       ` Arnd Bergmann
2026-01-12 22:20         ` Allen
2026-01-13  7:33           ` Arnd Bergmann
2026-01-13 19:31             ` Allen
2026-07-27 20:28 ` [PATCH v2 00/64] dmaengine: migrate channel tasklets to WQ_BH Allen Pais
2026-07-27 20:28   ` [PATCH v2 01/64] dmaengine: add tasklet-backed channel BH helpers Allen Pais
2026-07-27 20:56     ` sashiko-bot
2026-07-29 12:46       ` Vinod Koul
2026-07-29 12:48     ` Vinod Koul
2026-08-04  3:32       ` Allen
2026-07-27 20:28   ` [PATCH v2 02/64] dmaengine: back channel BH helpers with WQ_BH Allen Pais
2026-07-27 20:28   ` [PATCH v2 03/64] dmaengine: apple-admac: use dma_chan BH callback Allen Pais
2026-07-27 20:28   ` [PATCH v2 04/64] dmaengine: at_xdmac: move irq bottom half to dma_chan BH Allen Pais
2026-07-27 20:56     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 05/64] dmaengine: ep93xx: hook callbacks via " Allen Pais
2026-07-27 20:59     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 06/64] dmaengine: fsldma: migrate tasklet to " Allen Pais
2026-07-27 20:56     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 07/64] dmaengine: fsl_raid: run completions via " Allen Pais
2026-07-27 20:55     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 08/64] dmaengine: imx-dma: flip per-chan tasklet to " Allen Pais
2026-07-27 20:57     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 09/64] dmaengine: ioat: convert cleanup " Allen Pais
2026-07-27 20:38     ` Dave Jiang
2026-07-27 21:02     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 10/64] dmaengine: mmp_pdma: replace per-chan tasklet with " Allen Pais
2026-07-27 20:54     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 11/64] dmaengine: mmp_tdma: hook completions to " Allen Pais
2026-07-27 20:55     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 12/64] dmaengine: mv_xor: convert irq tasklet " Allen Pais
2026-07-27 20:57     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 13/64] dmaengine: mxs-dma: use dma_chan BH scheduling Allen Pais
2026-07-27 20:59     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 14/64] dmaengine: nbpfaxi: switch callbacks to dma_chan BH Allen Pais
2026-07-27 20:28   ` [PATCH v2 15/64] dmaengine: pch_dma: convert tasklet " Allen Pais
2026-07-27 20:57     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 16/64] dmaengine: ppc4xx: replace irq tasklet with " Allen Pais
2026-07-27 20:54     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 17/64] dmaengine: ste_dma40: convert per-channel tasklet to " Allen Pais
2026-07-27 21:00     ` sashiko-bot
2026-07-28 19:33     ` Linus Walleij
2026-07-27 20:28   ` [PATCH v2 18/64] dmaengine: xgene-dma: wire descriptor cleanup " Allen Pais
2026-07-27 20:59     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 19/64] dmaengine: xilinx-dma: use dma_chan BH instead of tasklets Allen Pais
2026-07-27 20:59     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 20/64] dmaengine: xilinx-dpdma: kill vchan BH on remove Allen Pais
2026-07-27 20:59     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 21/64] dmaengine: zynqmp-dma: switch completion tasklet to dma_chan BH Allen Pais
2026-07-27 20:54     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 22/64] dmaengine: tegra20-apb: use channel BH helpers Allen Pais
2026-07-27 20:28   ` [PATCH v2 23/64] dmaengine: timb_dma: route callbacks via channel BH Allen Pais
2026-07-27 21:09     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 24/64] dmaengine: txx9dmac: " Allen Pais
2026-07-27 21:00     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 25/64] dmaengine: mv_xor_v2: use channel BH helpers Allen Pais
2026-07-27 21:02     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 26/64] dmaengine: mpc512x: route callbacks via channel BH Allen Pais
2026-07-27 21:07     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 27/64] dmaengine: k3dma: kill vchan BH on remove Allen Pais
2026-07-27 21:02     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 28/64] dmaengine: plx_dma: use channel BH helpers Allen Pais
2026-07-27 20:38     ` Logan Gunthorpe
2026-07-27 21:09     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 29/64] dmaengine: sf-pdma: route error callbacks through channel BH Allen Pais
2026-07-27 21:06     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 30/64] dmaengine: sa11x0-dma: kill vchan BH on remove Allen Pais
2026-07-27 21:07     ` sashiko-bot
2026-07-27 20:28   ` [PATCH v2 31/64] dmaengine: pl330: route callbacks via channel BH Allen Pais
2026-07-27 20:34     ` Allen Pais
2026-07-27 21:07     ` sashiko-bot
2026-07-27 20:34   ` [PATCH v2 32/64] dmaengine: k3-udma: use channel BH for vchan completions Allen Pais
2026-07-27 21:10     ` sashiko-bot
2026-07-27 20:36   ` [PATCH v2 33/64] dmaengine: sun6i: kill vchan BH on teardown Allen Pais
2026-07-27 21:08     ` sashiko-bot
2026-07-27 20:37   ` [PATCH v2 34/64] dmaengine: mtk-cqdma: " Allen Pais
2026-07-27 21:09     ` sashiko-bot
2026-07-27 20:38   ` [PATCH v2 35/64] dmaengine: altera-msgdma: use channel BH helpers Allen Pais
2026-07-27 21:06     ` sashiko-bot
2026-07-27 20:38   ` [PATCH v2 36/64] dmaengine: sprd-dma: kill vchan BH on teardown Allen Pais
2026-07-27 21:07     ` sashiko-bot
2026-07-27 20:38   ` [PATCH v2 37/64] dmaengine: idma64: " Allen Pais
2026-07-27 21:07     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 38/64] dmaengine: img-mdc-dma: " Allen Pais
2026-07-27 21:09     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 39/64] dmaengine: fsl-edma-common: " Allen Pais
2026-07-27 21:14     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 40/64] dmaengine: dw-axi-dmac: " Allen Pais
2026-07-27 21:11     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 41/64] dmaengine: hsu: " Allen Pais
2026-07-27 21:10     ` sashiko-bot
2026-07-28  8:47     ` Andy Shevchenko
2026-07-27 20:39   ` [PATCH v2 42/64] dmaengine: jz4780: " Allen Pais
2026-07-27 21:09     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 43/64] dmaengine: pxa_dma: " Allen Pais
2026-07-27 21:10     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 44/64] dmaengine: mtk-hsdma: " Allen Pais
2026-07-27 21:09     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 45/64] dmaengine: mtk-uart-apdma: " Allen Pais
2026-07-27 21:14     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 46/64] dmaengine: imx-sdma: " Allen Pais
2026-07-27 21:17     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 47/64] dmaengine: loongson1-apb: " Allen Pais
2026-07-27 21:17     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 48/64] dmaengine: owl-dma: " Allen Pais
2026-07-27 21:17     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 49/64] dmaengine: hisi: " Allen Pais
2026-07-27 21:20     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 50/64] dmaengine: dw-edma: " Allen Pais
2026-07-27 21:18     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 51/64] dmaengine: bcm2835: " Allen Pais
2026-07-27 21:20     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 52/64] dmaengine: tegra210-adma: " Allen Pais
2026-07-27 21:17     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 53/64] dmaengine: fsl-qdma: use dma_chan_kill_bh Allen Pais
2026-07-27 21:17     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 54/64] dmaengine: st_fdma: " Allen Pais
2026-07-27 21:18     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 55/64] dmaengine: dma-axi-dmac: " Allen Pais
2026-07-27 21:18     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 56/64] dmaengine: omap-dma: " Allen Pais
2026-07-27 21:25     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 57/64] dmaengine: edma: " Allen Pais
2026-07-27 21:20     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 58/64] dmaengine: qcom-adm: " Allen Pais
2026-07-27 21:17     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 59/64] dmaengine: tegra186-gpc: " Allen Pais
2026-07-27 21:23     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 60/64] dmaengine: bam-dma: " Allen Pais
2026-07-27 21:19     ` sashiko-bot
2026-07-28  8:38     ` Bartosz Golaszewski
2026-07-27 20:39   ` [PATCH v2 61/64] dmaengine: dw: defer callbacks via channel BH Allen Pais
2026-07-27 21:31     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 62/64] dmaengine: hidma: " Allen Pais
2026-07-27 21:25     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 63/64] dmaengine: qcom-gpi: defer callbacks via vchan Allen Pais
2026-07-27 21:24     ` sashiko-bot
2026-07-27 20:39   ` [PATCH v2 64/64] dmaengine: switchtec: use channel BH helpers Allen Pais
2026-07-27 21:08     ` Logan Gunthorpe
2026-07-27 21:22     ` sashiko-bot
2026-07-28 20:39   ` [PATCH v2 00/64] dmaengine: migrate channel tasklets to WQ_BH Arnd Bergmann
2026-08-04  3:29     ` Allen
2026-08-10 18:09   ` [PATCH v3 00/34] " Allen Pais
2026-08-10 18:09     ` [PATCH v3 01/34] dmaengine: add tasklet-backed channel BH helpers Allen Pais
2026-08-10 18:30       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 02/34] dmaengine: back channel BH helpers with WQ_BH Allen Pais
2026-08-10 18:09     ` [PATCH v3 03/34] dmaengine: apple-admac: use dmaengine BH callback Allen Pais
2026-08-10 18:29       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 04/34] dmaengine: at_xdmac: move irq bottom half to dmaengine BH Allen Pais
2026-08-10 18:35       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 05/34] dmaengine: ep93xx: hook callbacks via " Allen Pais
2026-08-10 18:31       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 06/34] dmaengine: fsldma: migrate tasklet to " Allen Pais
2026-08-10 18:29       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 07/34] dmaengine: fsl_raid: run completions via " Allen Pais
2026-08-10 18:27       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 08/34] dmaengine: imx-dma: flip per-chan tasklet to " Allen Pais
2026-08-10 18:34       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 09/34] dmaengine: ioat: convert cleanup " Allen Pais
2026-08-10 18:27       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 10/34] dmaengine: mmp_pdma: replace per-chan tasklet with " Allen Pais
2026-08-10 18:28       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 11/34] dmaengine: mmp_tdma: hook completions to " Allen Pais
2026-08-10 18:28       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 12/34] dmaengine: mv_xor: convert irq tasklet " Allen Pais
2026-08-10 18:27       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 13/34] dmaengine: mxs-dma: use dmaengine BH scheduling Allen Pais
2026-08-10 18:27       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 14/34] dmaengine: nbpfaxi: switch callbacks to dmaengine BH Allen Pais
2026-08-10 18:23       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 15/34] dmaengine: pch_dma: convert tasklet " Allen Pais
2026-08-10 18:34       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 16/34] dmaengine: ppc4xx: replace irq tasklet with " Allen Pais
2026-08-10 18:36       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 17/34] dmaengine: ste_dma40: convert per-channel tasklet to " Allen Pais
2026-08-10 18:34       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 18/34] dmaengine: xgene-dma: wire descriptor cleanup " Allen Pais
2026-08-10 18:35       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 19/34] dmaengine: xilinx-dma: use dmaengine BH instead of tasklets Allen Pais
2026-08-10 18:28       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 20/34] dmaengine: xilinx-dpdma: kill vchan BH on remove Allen Pais
2026-08-10 18:31       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 21/34] dmaengine: zynqmp-dma: switch completion tasklet to dmaengine BH Allen Pais
2026-08-10 18:35       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 22/34] dmaengine: tegra20-apb: use channel BH helpers Allen Pais
2026-08-10 18:40       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 23/34] dmaengine: timb_dma: route callbacks via channel BH Allen Pais
2026-08-10 18:45       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 24/34] dmaengine: txx9dmac: " Allen Pais
2026-08-10 18:34       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 25/34] dmaengine: mv_xor_v2: use channel BH helpers Allen Pais
2026-08-10 18:46       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 26/34] dmaengine: mpc512x: route callbacks via channel BH Allen Pais
2026-08-10 18:50       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 27/34] dmaengine: plx_dma: use channel BH helpers Allen Pais
2026-08-10 18:39       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 28/34] dmaengine: sf-pdma: route error callbacks through channel BH Allen Pais
2026-08-10 18:41       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 29/34] dmaengine: pl330: route callbacks via " Allen Pais
2026-08-10 18:39       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 30/34] dmaengine: altera-msgdma: use channel BH helpers Allen Pais
2026-08-10 18:49       ` sashiko-bot [this message]
2026-08-10 18:09     ` [PATCH v3 31/34] dmaengine: dw: defer callbacks via channel BH Allen Pais
2026-08-10 18:44       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 32/34] dmaengine: hidma: " Allen Pais
2026-08-10 18:45       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 33/34] dmaengine: qcom-gpi: defer callbacks via vchan Allen Pais
2026-08-10 18:50       ` sashiko-bot
2026-08-10 18:09     ` [PATCH v3 34/34] dmaengine: switchtec: use channel BH helpers Allen Pais
2026-08-10 18:43       ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260810184924.DDC241F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=allen.lkml@gmail.com \
    --cc=dmaengine@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox