DMA Engine development
 help / color / mirror / Atom feed
* [PATCHv3] dmaengine: fsldma: convert to platform_get_irq_optional()
@ 2026-09-11 22:04 Rosen Penev
  2026-09-11 22:14 ` sashiko-bot
  0 siblings, 1 reply; 2+ messages in thread
From: Rosen Penev @ 2026-09-11 22:04 UTC (permalink / raw)
  To: dmaengine
  Cc: Zhang Wei, Vinod Koul, Frank Li, open list:FREESCALE DMA DRIVER,
	open list

Replace the per-controller irq_of_parse_and_map() call with
platform_get_irq_optional(). The controller IRQ is optional when absent
and the driver falls back to per-channel IRQs. The corresponding
irq_dispose_mapping() calls in the probe error path and remove function
are removed.

Moved before anything else in order to handle -EPROBE_DEFER and to avoid
doing extra work. Simplifies the if statements as well.

Assisted-by: LLM
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
 v3: fix build error from the move
 v2: move to the front of probe.
 drivers/dma/fsldma.c | 11 ++++++++---
 1 file changed, 8 insertions(+), 3 deletions(-)

diff --git a/drivers/dma/fsldma.c b/drivers/dma/fsldma.c
index fb19c60540be..6db2c4d284c9 100644
--- a/drivers/dma/fsldma.c
+++ b/drivers/dma/fsldma.c
@@ -1224,8 +1224,13 @@ static int fsldma_of_probe(struct platform_device *op)
 	struct fsldma_device *fdev;
 	struct device_node *child;
 	unsigned int i;
+	int irq;
 	int err;
 
+	irq = platform_get_irq_optional(op, 0);
+	if (irq == -EPROBE_DEFER)
+		return irq;
+
 	fdev = kzalloc_obj(*fdev);
 	if (!fdev) {
 		err = -ENOMEM;
@@ -1246,7 +1251,9 @@ static int fsldma_of_probe(struct platform_device *op)
 	}
 
 	/* map the channel IRQ if it exists, but don't hookup the handler yet */
-	fdev->irq = irq_of_parse_and_map(op->dev.of_node, 0);
+	fdev->irq = irq;
+	if (fdev->irq < 0)
+		fdev->irq = 0;
 
 	dma_cap_set(DMA_MEMCPY, fdev->common.cap_mask);
 	dma_cap_set(DMA_SLAVE, fdev->common.cap_mask);
@@ -1308,7 +1315,6 @@ static int fsldma_of_probe(struct platform_device *op)
 		if (fdev->chan[i])
 			fsl_dma_chan_remove(fdev->chan[i]);
 	}
-	irq_dispose_mapping(fdev->irq);
 	iounmap(fdev->regs);
 out_free:
 	kfree(fdev);
@@ -1330,7 +1336,6 @@ static void fsldma_of_remove(struct platform_device *op)
 		if (fdev->chan[i])
 			fsl_dma_chan_remove(fdev->chan[i]);
 	}
-	irq_dispose_mapping(fdev->irq);
 
 	iounmap(fdev->regs);
 	kfree(fdev);
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCHv3] dmaengine: fsldma: convert to platform_get_irq_optional()
  2026-09-11 22:04 [PATCHv3] dmaengine: fsldma: convert to platform_get_irq_optional() Rosen Penev
@ 2026-09-11 22:14 ` sashiko-bot
  0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-09-11 22:14 UTC (permalink / raw)
  To: Rosen Penev; +Cc: vkoul, Frank.Li, dmaengine

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

Pre-existing issues:
- [High] The return value of dma_async_device_register() is completely ignored, leading to silent failures and a potential zombie driver state that corrupts core DMA IDA state on removal.
- [High] Missing tasklet_kill() before freeing the DMA channel structure leads to a potential Use-After-Free if a tasklet is scheduled during teardown.
--

commit d7e04e63631501d249cff16deb847b2b702a2b37
Author: Rosen Penev <rosenp@gmail.com>

dmaengine: fsldma: convert to platform_get_irq_optional()

Replace the per-controller irq_of_parse_and_map() call with
platform_get_irq_optional(). The controller IRQ is optional when absent
and the driver falls back to per-channel IRQs.

> diff --git a/drivers/dma/fsldma.c b/drivers/dma/fsldma.c
> index 22d62d958abd9..dd2937e443673 100644
> --- a/drivers/dma/fsldma.c
> +++ b/drivers/dma/fsldma.c

[ ... ]

> @@ -1300,7 +1307,6 @@ static int fsldma_of_probe(struct platform_device *op)
>  		if (fdev->chan[i])
>  			fsl_dma_chan_remove(fdev->chan[i]);

[Severity: High]
This is a pre-existing issue, but does fsl_dma_chan_remove() fail to
explicitly kill the tasklet before freeing the channel structure?

During device removal or probe error paths, fsldma_free_irqs() calls
free_irq(). If a hardware interrupt executes just before free_irq(), it
schedules chan->tasklet. free_irq() waits for the hardirq handler to finish
but does not wait for pending softirqs.

The driver then calls fsl_dma_chan_remove() which invokes kfree(chan)
without calling tasklet_kill(&chan->tasklet).

When the softirq scheduler subsequently runs the tasklet, could
dma_do_tasklet() dereference the freed chan pointer and cause a
use-after-free?


[Severity: High]
This is another pre-existing issue, but does fsldma_of_probe() ignore the
return value of dma_async_device_register() just before this error path?

fsldma_of_probe() does this right before the out_free_fdev label:

    dma_async_device_register(&fdev->common);
    return 0;

If dma_async_device_register() fails, the driver returns success but the
device is not successfully registered. On driver teardown, fsldma_of_remove()
will call dma_async_device_unregister() with this unregistered device.

Could this lead to a double-free or mis-free in the IDA allocator, freeing
an ID it never successfully acquired and corrupting the DMA engine ID
namespace?

>  	}
> -	irq_dispose_mapping(fdev->irq);
>  	iounmap(fdev->regs);
>  out_free:
>  	kfree(fdev);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260911220439.177474-1-rosenp@gmail.com?part=1

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-11 22:14 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 22:04 [PATCHv3] dmaengine: fsldma: convert to platform_get_irq_optional() Rosen Penev
2026-09-11 22:14 ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox