DMA Engine development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Wolfram Sang" <wsa+renesas@sang-engineering.com>
Cc: Frank.Li@kernel.org, dmaengine@vger.kernel.org,
	wsa+renesas@sang-engineering.com, vkoul@kernel.org
Subject: Re: [PATCH 2/3] dmaengine: rcar-dmac: Add missing dma_descriptor_unmap()
Date: Thu, 17 Sep 2026 07:25:06 +0000	[thread overview]
Message-ID: <20260917072507.5BDB61F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260917071208.36888-3-wsa+renesas@sang-engineering.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] dmaengine: data corruption due to premature dma_cookie_complete() before unmap
--

commit 1e9a738c62158e887202df32a8267f4bc4bfe4cd
Author: Koichiro Den <den@valinux.co.jp>

dmaengine: rcar-dmac: Add missing dma_descriptor_unmap()

This commit adds missing calls to dma_descriptor_unmap() in the threaded IRQ
completion path and the channel reinit path. This prevents streaming DMA 
mappings from exhausting mapping resources.

> diff --git a/drivers/dma/sh/rcar-dmac.c b/drivers/dma/sh/rcar-dmac.c
> index 2d2baa36feeae..016024858fe5a 100644
> --- a/drivers/dma/sh/rcar-dmac.c
> +++ b/drivers/dma/sh/rcar-dmac.c

[ ... ]

> @@ -1652,6 +1653,7 @@ static irqreturn_t rcar_dmac_isr_channel_thread(int irq, void *dev)
>  		desc = list_first_entry(&chan->desc.done, struct rcar_dmac_desc,
>  					node);
>  		dma_cookie_complete(&desc->async_tx);
> +		dma_descriptor_unmap(&desc->async_tx);

[Severity: High]
Could this specific ordering lead to data corruption? 

By calling dma_cookie_complete() before dma_descriptor_unmap() in
rcar_dmac_isr_channel_thread(), polling clients (via dma_async_is_tx_complete()
or rcar_dmac_tx_status()) checking for completion locklessly might observe
the completion too early.

If they access the destination buffer before the unmap operation finishes
cache invalidations or SWIOTLB bounce buffer copies, it could result in
reading stale data.

Would it be safer to place dma_descriptor_unmap() strictly before
dma_cookie_complete() to prevent clients from seeing stale memory?

>  		list_del(&desc->node);
>  
>  		dmaengine_desc_get_callback(&desc->async_tx, &cb);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260917071208.36888-1-wsa+renesas@sang-engineering.com?part=2

  reply	other threads:[~2026-09-17  7:25 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17  7:12 [PATCH 0/3] dmaengine: rcar-dmac: collection of small missed fixes Wolfram Sang
2026-09-17  7:12 ` [PATCH 1/3] dmaengine: rcar-dmac: Fix PM usage counter imbalance Wolfram Sang
2026-09-17  7:17   ` Laurent Pinchart
2026-09-17  7:12 ` [PATCH 2/3] dmaengine: rcar-dmac: Add missing dma_descriptor_unmap() Wolfram Sang
2026-09-17  7:25   ` sashiko-bot [this message]
2026-09-17  7:38   ` Laurent Pinchart
2026-09-17  8:23     ` Wolfram Sang
2026-09-17 16:39   ` Frank Li
2026-09-18 13:07     ` Koichiro Den
2026-09-27 12:43       ` Wolfram Sang
2026-09-27 13:11         ` Wolfram Sang
2026-09-29  4:13           ` Koichiro Den
2026-09-27 12:38     ` Wolfram Sang
2026-09-17  7:12 ` [PATCH 3/3] dmaengine: rcar-dmac: Remove redundant dev_err()/dev_err_probe() Wolfram Sang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260917072507.5BDB61F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=dmaengine@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vkoul@kernel.org \
    --cc=wsa+renesas@sang-engineering.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox