From: Logan Gunthorpe <logang@deltatee.com>
To: linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org,
dmaengine@vger.kernel.org, Vinod Koul <vkoul@kernel.org>
Cc: "Frank Li" <Frank.li@nxp.com>,
"Kelvin Cao" <kelvin.cao@microchip.com>,
"Thomas Weißschuh" <linux@weissschuh.net>,
"Dave Jiang" <dave.jiang@intel.com>,
"George Ge" <george.ge@microchip.com>,
"Jaeyoung Chung" <jjy600901@snu.ac.kr>,
"Logan Gunthorpe" <logang@deltatee.com>,
Sashiko <sashiko-bot@kernel.org>
Subject: [PATCH v5 03/12] dmaengine: switchtec-dma: always clear DMA base registers on chan_stop()
Date: Mon, 31 Aug 2026 13:13:53 -0600 [thread overview]
Message-ID: <20260831191403.207631-4-logang@deltatee.com> (raw)
In-Reply-To: <20260831191403.207631-1-logang@deltatee.com>
switchtec_dma_chan_stop() returned early if halt_channel() timed out,
skipping the writes that clear sq_base/cq_base on the channel, and
gave its caller no way to tell the halt hadn't been confirmed.
switchtec_dma_free_chan_resources() unconditionally frees the
descriptor rings right after calling this function, so if the
hardware failed to halt, it could keep writing into memory that had
already been freed.
Attempt the register clear regardless of whether the halt was successful
and have switchtec_dma_chan_stop() return the halt result so callers can
tell when it wasn't confirmed. switchtec_dma_free_chan_resources() now
skips freeing the descriptor rings (leaking them instead) in case the
hardware continues to write into that memory.
All this is hardening that is pretty unlikely to be hit in the real
world. However, it is correct and the best thing to do against buggy
hardware that doesn't tear down correctly and could still write to
memory. In this unlikely situation it is better to leak the memory
than have hardware randomly trash memory that has already been used
for something else.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://lore.kernel.org/dmaengine/20260721162531.BA01A1F01560@smtp.kernel.org
Signed-off-by: Logan Gunthorpe <logang@deltatee.com>
---
drivers/dma/switchtec_dma.c | 23 ++++++++++++++++-------
1 file changed, 16 insertions(+), 7 deletions(-)
diff --git a/drivers/dma/switchtec_dma.c b/drivers/dma/switchtec_dma.c
index e55fe9ff7e2c..e2bb65237d2c 100644
--- a/drivers/dma/switchtec_dma.c
+++ b/drivers/dma/switchtec_dma.c
@@ -543,26 +543,33 @@ switchtec_dma_abort_desc(struct switchtec_dma_chan *swdma_chan, int force)
spin_unlock_bh(&swdma_chan->complete_lock);
}
-static void switchtec_dma_chan_stop(struct switchtec_dma_chan *swdma_chan)
+static int switchtec_dma_chan_stop(struct switchtec_dma_chan *swdma_chan)
{
+ struct pci_dev *pdev;
int rc;
rc = halt_channel(swdma_chan);
- if (rc)
- return;
rcu_read_lock();
- if (!rcu_dereference(swdma_chan->swdma_dev->pdev)) {
+ pdev = rcu_dereference(swdma_chan->swdma_dev->pdev);
+ if (!pdev) {
rcu_read_unlock();
- return;
+ return rc;
}
+ if (rc)
+ pci_err(pdev,
+ "Channel %d halt timed out, clearing DMA base registers anyway\n",
+ swdma_chan->index);
+
writel(0, &swdma_chan->mmio_chan_fw->sq_base_lo);
writel(0, &swdma_chan->mmio_chan_fw->sq_base_hi);
writel(0, &swdma_chan->mmio_chan_fw->cq_base_lo);
writel(0, &swdma_chan->mmio_chan_fw->cq_base_hi);
rcu_read_unlock();
+
+ return rc;
}
static int switchtec_dma_terminate_all(struct dma_chan *chan)
@@ -1050,6 +1057,7 @@ static void switchtec_dma_free_chan_resources(struct dma_chan *chan)
{
struct switchtec_dma_chan *swdma_chan =
container_of(chan, struct switchtec_dma_chan, dma_chan);
+ int rc;
spin_lock_bh(&swdma_chan->submit_lock);
swdma_chan->ring_active = false;
@@ -1059,9 +1067,10 @@ static void switchtec_dma_free_chan_resources(struct dma_chan *chan)
swdma_chan->comp_ring_active = false;
spin_unlock_bh(&swdma_chan->complete_lock);
- switchtec_dma_chan_stop(swdma_chan);
+ rc = switchtec_dma_chan_stop(swdma_chan);
switchtec_dma_abort_desc(swdma_chan, 0);
- switchtec_dma_free_desc(swdma_chan);
+ if (!rc)
+ switchtec_dma_free_desc(swdma_chan);
disable_channel(swdma_chan);
}
--
2.47.3
next prev parent reply other threads:[~2026-08-31 19:14 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 19:13 [PATCH v5 00/12] dmaengine: miscellaneous fixes for ioat, switchtec_dma and plx_dma Logan Gunthorpe
2026-08-31 19:13 ` [PATCH v5 01/12] dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc() Logan Gunthorpe
2026-08-31 21:28 ` sashiko-bot
2026-08-31 19:13 ` [PATCH v5 02/12] dmaengine: switchtec-dma: fix resource leak in alloc_chan_resources Logan Gunthorpe
2026-08-31 21:38 ` sashiko-bot
2026-08-31 19:13 ` Logan Gunthorpe [this message]
2026-08-31 21:51 ` [PATCH v5 03/12] dmaengine: switchtec-dma: always clear DMA base registers on chan_stop() sashiko-bot
2026-08-31 22:43 ` Logan Gunthorpe
2026-08-31 19:13 ` [PATCH v5 04/12] dmaengine: switchtec-dma: halt channel on alloc_chan_resources error Logan Gunthorpe
2026-08-31 22:04 ` sashiko-bot
2026-08-31 19:13 ` [PATCH v5 05/12] dmaengine: switchtec-dma: fix channel leak on registration failure Logan Gunthorpe
2026-08-31 22:18 ` sashiko-bot
2026-08-31 19:13 ` [PATCH v5 06/12] dmaengine: switchtec-dma: make switchtec_dma_chans_release() void Logan Gunthorpe
2026-08-31 22:24 ` sashiko-bot
2026-08-31 19:13 ` [PATCH v5 07/12] dmaengine: switchtec-dma: fix chan_status_irq cleanup on create() error Logan Gunthorpe
2026-08-31 22:35 ` sashiko-bot
2026-08-31 19:13 ` [PATCH v5 08/12] dmaengine: switchtec-dma: disable channels before freeing on registration failure Logan Gunthorpe
2026-08-31 22:50 ` sashiko-bot
2026-08-31 19:13 ` [PATCH v5 09/12] dmaengine: switchtec-dma: fix use-after-free of swdma_dev in remove() Logan Gunthorpe
2026-08-31 23:04 ` sashiko-bot
2026-08-31 19:14 ` [PATCH v5 10/12] dmaengine: ioat: disable relaxed ordering before registering the device Logan Gunthorpe
2026-08-31 23:13 ` sashiko-bot
2026-08-31 19:14 ` [PATCH v5 11/12] dmaengine: ioat: use sysfs_emit() in per-channel sysfs show() Logan Gunthorpe
2026-08-31 23:19 ` sashiko-bot
2026-08-31 19:14 ` [PATCH v5 12/12] dmaengine: plx_dma: fix NULL pointer deref in plx_dma_isr() Logan Gunthorpe
2026-08-31 23:30 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831191403.207631-4-logang@deltatee.com \
--to=logang@deltatee.com \
--cc=Frank.li@nxp.com \
--cc=dave.jiang@intel.com \
--cc=dmaengine@vger.kernel.org \
--cc=george.ge@microchip.com \
--cc=jjy600901@snu.ac.kr \
--cc=kelvin.cao@microchip.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=linux@weissschuh.net \
--cc=sashiko-bot@kernel.org \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox