* [PATCHv3] dmaengine: fsldma: convert to platform_get_irq_optional()
@ 2026-09-11 22:04 Rosen Penev
2026-09-11 22:14 ` sashiko-bot
0 siblings, 1 reply; 2+ messages in thread
From: Rosen Penev @ 2026-09-11 22:04 UTC (permalink / raw)
To: dmaengine
Cc: Zhang Wei, Vinod Koul, Frank Li, open list:FREESCALE DMA DRIVER,
open list
Replace the per-controller irq_of_parse_and_map() call with
platform_get_irq_optional(). The controller IRQ is optional when absent
and the driver falls back to per-channel IRQs. The corresponding
irq_dispose_mapping() calls in the probe error path and remove function
are removed.
Moved before anything else in order to handle -EPROBE_DEFER and to avoid
doing extra work. Simplifies the if statements as well.
Assisted-by: LLM
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
v3: fix build error from the move
v2: move to the front of probe.
drivers/dma/fsldma.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/drivers/dma/fsldma.c b/drivers/dma/fsldma.c
index fb19c60540be..6db2c4d284c9 100644
--- a/drivers/dma/fsldma.c
+++ b/drivers/dma/fsldma.c
@@ -1224,8 +1224,13 @@ static int fsldma_of_probe(struct platform_device *op)
struct fsldma_device *fdev;
struct device_node *child;
unsigned int i;
+ int irq;
int err;
+ irq = platform_get_irq_optional(op, 0);
+ if (irq == -EPROBE_DEFER)
+ return irq;
+
fdev = kzalloc_obj(*fdev);
if (!fdev) {
err = -ENOMEM;
@@ -1246,7 +1251,9 @@ static int fsldma_of_probe(struct platform_device *op)
}
/* map the channel IRQ if it exists, but don't hookup the handler yet */
- fdev->irq = irq_of_parse_and_map(op->dev.of_node, 0);
+ fdev->irq = irq;
+ if (fdev->irq < 0)
+ fdev->irq = 0;
dma_cap_set(DMA_MEMCPY, fdev->common.cap_mask);
dma_cap_set(DMA_SLAVE, fdev->common.cap_mask);
@@ -1308,7 +1315,6 @@ static int fsldma_of_probe(struct platform_device *op)
if (fdev->chan[i])
fsl_dma_chan_remove(fdev->chan[i]);
}
- irq_dispose_mapping(fdev->irq);
iounmap(fdev->regs);
out_free:
kfree(fdev);
@@ -1330,7 +1336,6 @@ static void fsldma_of_remove(struct platform_device *op)
if (fdev->chan[i])
fsl_dma_chan_remove(fdev->chan[i]);
}
- irq_dispose_mapping(fdev->irq);
iounmap(fdev->regs);
kfree(fdev);
--
2.55.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCHv3] dmaengine: fsldma: convert to platform_get_irq_optional()
2026-09-11 22:04 [PATCHv3] dmaengine: fsldma: convert to platform_get_irq_optional() Rosen Penev
@ 2026-09-11 22:14 ` sashiko-bot
0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-09-11 22:14 UTC (permalink / raw)
To: Rosen Penev; +Cc: vkoul, Frank.Li, dmaengine
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
Pre-existing issues:
- [High] The return value of dma_async_device_register() is completely ignored, leading to silent failures and a potential zombie driver state that corrupts core DMA IDA state on removal.
- [High] Missing tasklet_kill() before freeing the DMA channel structure leads to a potential Use-After-Free if a tasklet is scheduled during teardown.
--
commit d7e04e63631501d249cff16deb847b2b702a2b37
Author: Rosen Penev <rosenp@gmail.com>
dmaengine: fsldma: convert to platform_get_irq_optional()
Replace the per-controller irq_of_parse_and_map() call with
platform_get_irq_optional(). The controller IRQ is optional when absent
and the driver falls back to per-channel IRQs.
> diff --git a/drivers/dma/fsldma.c b/drivers/dma/fsldma.c
> index 22d62d958abd9..dd2937e443673 100644
> --- a/drivers/dma/fsldma.c
> +++ b/drivers/dma/fsldma.c
[ ... ]
> @@ -1300,7 +1307,6 @@ static int fsldma_of_probe(struct platform_device *op)
> if (fdev->chan[i])
> fsl_dma_chan_remove(fdev->chan[i]);
[Severity: High]
This is a pre-existing issue, but does fsl_dma_chan_remove() fail to
explicitly kill the tasklet before freeing the channel structure?
During device removal or probe error paths, fsldma_free_irqs() calls
free_irq(). If a hardware interrupt executes just before free_irq(), it
schedules chan->tasklet. free_irq() waits for the hardirq handler to finish
but does not wait for pending softirqs.
The driver then calls fsl_dma_chan_remove() which invokes kfree(chan)
without calling tasklet_kill(&chan->tasklet).
When the softirq scheduler subsequently runs the tasklet, could
dma_do_tasklet() dereference the freed chan pointer and cause a
use-after-free?
[Severity: High]
This is another pre-existing issue, but does fsldma_of_probe() ignore the
return value of dma_async_device_register() just before this error path?
fsldma_of_probe() does this right before the out_free_fdev label:
dma_async_device_register(&fdev->common);
return 0;
If dma_async_device_register() fails, the driver returns success but the
device is not successfully registered. On driver teardown, fsldma_of_remove()
will call dma_async_device_unregister() with this unregistered device.
Could this lead to a double-free or mis-free in the IDA allocator, freeing
an ID it never successfully acquired and corrupting the DMA engine ID
namespace?
> }
> - irq_dispose_mapping(fdev->irq);
> iounmap(fdev->regs);
> out_free:
> kfree(fdev);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260911220439.177474-1-rosenp@gmail.com?part=1
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-11 22:14 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 22:04 [PATCHv3] dmaengine: fsldma: convert to platform_get_irq_optional() Rosen Penev
2026-09-11 22:14 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox