From: Logan Gunthorpe <logang@deltatee.com>
To: linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org,
dmaengine@vger.kernel.org, Vinod Koul <vkoul@kernel.org>
Cc: "Frank Li" <Frank.li@nxp.com>,
"Kelvin Cao" <kelvin.cao@microchip.com>,
"Thomas Weißschuh" <linux@weissschuh.net>,
"Dave Jiang" <dave.jiang@intel.com>,
"George Ge" <george.ge@microchip.com>,
"Jaeyoung Chung" <jjy600901@snu.ac.kr>,
"Logan Gunthorpe" <logang@deltatee.com>
Subject: [PATCH v5 00/12] dmaengine: miscellaneous fixes for ioat, switchtec_dma and plx_dma
Date: Mon, 31 Aug 2026 13:13:50 -0600 [thread overview]
Message-ID: <20260831191403.207631-1-logang@deltatee.com> (raw)
This is the latest series of fixes that has been rebased onto v7.3-rc1.
There is an unresolved disagreement between me and Frank who does not
think patches 3 and 4 are worth taking. I think they fix unlikely but
theoretically possible issues with hardware failing to tear down
correctly. I think these patches are correct, the best we can do and worth
doing. And I especially want to have them merged if only to not have
Sashiko bringing up the same issues every time we send a patch set.
Please note: I'm going to be on vacation starting Friday the 4th until
the 15th so if there is any feedback in that window I'll respond when
I get back.
Thanks,
Logan
Changes since v4:
* Rebased onto v7.3-rc1.
* Added paragraph to patches 3 and 4 to make clear that they are
leaking memory in favour of preventing theoretically buggy hardware
from trashing re-used memory. I think this is the best thing to do.
Changes since v3:
* Add a patch (3) making switchtec_dma_chan_stop() clear the DMA base
registers even when halt_channel() times out, and return the halt
result. switchtec_dma_free_chan_resources() (patch 3) and the
alloc_chan_resources() error path (patch 4) now skip freeing the
descriptor rings when the halt wasn't confirmed. This will leak some
memory on tear down but that avoids broken hardware from scribbling
on memory that may have been freed and reallocated. (Per Sashiko)
* Remove each channel's list entry in switchtec_dma_chans_free()
(patch 5), immediately before the memory is freed, instead of in
switchtec_dma_chans_disable() (patch 8), which now only frees the
channel status IRQ. (Per Sashiko)
* Collected Reviewed-by tags from Frank and applied one of his
commit message suggestions.
Changes since v2:
* Fixed a race when unlisting the channels in the error path.
The interrupt needed to be disabled before hand. (Per Sashiko)
* Picked up Acked-by from Dave Jiang on the two ioat patches.
Changes since v1:
* Added a fix for switchtec_dma_alloc_chan_resources()'s error path
calling disable_channel() instead of properly halting the channel
before freeing the descriptor rings. (Per Sashiko)
* Added a fix for switchtec-dma channel structs being freed without
being removed from dma_dev->channels on a registration failure,
while the channel status IRQ is still live. (Per Sashiko)
* Added a fix for switchtec_dma_remove() using swdma_dev after it may
already have been freed by dma_async_device_unregister(). (Per
Sashiko)
* Added a fix for chan_status_irq being freed with the wrong API, and
a valid vector index of 0 being incorrectly treated as unset.
(Per Sashiko)
* Made switchtec_dma_chans_release() void, since nothing checked its
return value. (Noticed while reviewing the code for these changes).
Logan Gunthorpe (12):
dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc()
dmaengine: switchtec-dma: fix resource leak in alloc_chan_resources
dmaengine: switchtec-dma: always clear DMA base registers on
chan_stop()
dmaengine: switchtec-dma: halt channel on alloc_chan_resources error
dmaengine: switchtec-dma: fix channel leak on registration failure
dmaengine: switchtec-dma: make switchtec_dma_chans_release() void
dmaengine: switchtec-dma: fix chan_status_irq cleanup on create()
error
dmaengine: switchtec-dma: disable channels before freeing on
registration failure
dmaengine: switchtec-dma: fix use-after-free of swdma_dev in remove()
dmaengine: ioat: disable relaxed ordering before registering the
device
dmaengine: ioat: use sysfs_emit() in per-channel sysfs show()
dmaengine: plx_dma: fix NULL pointer deref in plx_dma_isr()
drivers/dma/ioat/init.c | 18 +++---
drivers/dma/ioat/sysfs.c | 22 ++++----
drivers/dma/plx_dma.c | 10 ++--
drivers/dma/switchtec_dma.c | 107 ++++++++++++++++++++++++++----------
4 files changed, 104 insertions(+), 53 deletions(-)
base-commit: cee9395acd8043be0644b25c34bfa86623f2b935
--
2.47.3
next reply other threads:[~2026-08-31 19:14 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 19:13 Logan Gunthorpe [this message]
2026-08-31 19:13 ` [PATCH v5 01/12] dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc() Logan Gunthorpe
2026-08-31 21:28 ` sashiko-bot
2026-08-31 19:13 ` [PATCH v5 02/12] dmaengine: switchtec-dma: fix resource leak in alloc_chan_resources Logan Gunthorpe
2026-08-31 21:38 ` sashiko-bot
2026-08-31 19:13 ` [PATCH v5 03/12] dmaengine: switchtec-dma: always clear DMA base registers on chan_stop() Logan Gunthorpe
2026-08-31 21:51 ` sashiko-bot
2026-08-31 22:43 ` Logan Gunthorpe
2026-08-31 19:13 ` [PATCH v5 04/12] dmaengine: switchtec-dma: halt channel on alloc_chan_resources error Logan Gunthorpe
2026-08-31 22:04 ` sashiko-bot
2026-08-31 19:13 ` [PATCH v5 05/12] dmaengine: switchtec-dma: fix channel leak on registration failure Logan Gunthorpe
2026-08-31 22:18 ` sashiko-bot
2026-08-31 19:13 ` [PATCH v5 06/12] dmaengine: switchtec-dma: make switchtec_dma_chans_release() void Logan Gunthorpe
2026-08-31 22:24 ` sashiko-bot
2026-08-31 19:13 ` [PATCH v5 07/12] dmaengine: switchtec-dma: fix chan_status_irq cleanup on create() error Logan Gunthorpe
2026-08-31 22:35 ` sashiko-bot
2026-08-31 19:13 ` [PATCH v5 08/12] dmaengine: switchtec-dma: disable channels before freeing on registration failure Logan Gunthorpe
2026-08-31 22:50 ` sashiko-bot
2026-08-31 19:13 ` [PATCH v5 09/12] dmaengine: switchtec-dma: fix use-after-free of swdma_dev in remove() Logan Gunthorpe
2026-08-31 23:04 ` sashiko-bot
2026-08-31 19:14 ` [PATCH v5 10/12] dmaengine: ioat: disable relaxed ordering before registering the device Logan Gunthorpe
2026-08-31 23:13 ` sashiko-bot
2026-08-31 19:14 ` [PATCH v5 11/12] dmaengine: ioat: use sysfs_emit() in per-channel sysfs show() Logan Gunthorpe
2026-08-31 23:19 ` sashiko-bot
2026-08-31 19:14 ` [PATCH v5 12/12] dmaengine: plx_dma: fix NULL pointer deref in plx_dma_isr() Logan Gunthorpe
2026-08-31 23:30 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831191403.207631-1-logang@deltatee.com \
--to=logang@deltatee.com \
--cc=Frank.li@nxp.com \
--cc=dave.jiang@intel.com \
--cc=dmaengine@vger.kernel.org \
--cc=george.ge@microchip.com \
--cc=jjy600901@snu.ac.kr \
--cc=kelvin.cao@microchip.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=linux@weissschuh.net \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox