From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 38AE0513575; Fri, 18 Sep 2026 16:24:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789748694; cv=none; b=DoPkrBlw4nc+pelHZYVP+Km0lhhWW8aSms/T0fmoDY4Sgh/C/28x//8DMk0pyuz2zcdrSGUVYQUAgouqCQ7nEbkt1cob4v9p4pG0XSxDrd/aHPq06fIPH6QSt5fqv/tm0MZsG+rkFPJHWCgPGfrN4EKdPfFAzEQaNkknbRz50Y4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789748694; c=relaxed/simple; bh=JCn+trBeo+2kLzalZrAOBBv6TU2oF8VA4qr1+HGk+dU=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=lSfGk1/0FIqH9LbO2brW3WZtYuraOCpJYsiYtoO/aliBRKbd6KE7+Num7pf5Y85DfIXH5UJXp2OlSxfWMafaRNyRn15C/Hj2thpzd1cjscXqCQgG4O1TKEUXXI3ArNHUF5UcjhvwQLPQ7foix2dQnNFawX9inFNuwZVMiiNw7pc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=ozKywrh0; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="ozKywrh0" Received: by smtp.kernel.org (Postfix) with ESMTPSA id CD7F01F00898; Fri, 18 Sep 2026 16:24:50 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1789748692; bh=7FLGNlwGQzM6ZVdG64nz31cUdiPaUyhbzRHqr3ALMAs=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=ozKywrh0Y/3TuwAAZbUfoK+DXLCR0qUXtyh4XyU8y+Od63kJsrEcH7xTa7ulkeMa+ PSxfFlBgexGdTIE9TRgvW0YeDAOexGmoZiMiJHXh3bvEVSRXfGDFbSBPFTNKdoTE2z Pf+u9nAUF0Wym9kuyy0BJXXm9MV0I4sSJEDJvjAGSfWQcDUcUjeBKThXYOr0TIrOSb eUH/sZ+b4TIPMdUlxbCtI7Lb96ZOXeVv0tqotWyMBxqqLvtbIbWKjkOnKyp4jKsfyj CpaTi+c71az8auSj6bZpA+hOCwc3p1PrpF4/PPuymiyWjfCxU8AjyWDmxj1M/Zm5Nn qSt9+6Psyj/2A== From: Linus Walleij Date: Fri, 18 Sep 2026 18:24:33 +0200 Subject: [PATCH v3 14/22] dmaengine: ste_dma40: Fix memcpy channel parsing Precedence: bulk X-Mailing-List: dmaengine@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20260918-dma40-fixes-v3-14-8dd8450669e8@kernel.org> References: <20260918-dma40-fixes-v3-0-8dd8450669e8@kernel.org> In-Reply-To: <20260918-dma40-fixes-v3-0-8dd8450669e8@kernel.org> To: Vinod Koul , Frank Li Cc: dmaengine@vger.kernel.org, phone-devel@vger.kernel.org, Linus Walleij , sashiko-bot@kernel.org X-Mailer: b4 0.14.3 d40_of_probe() validates the memcpy-channels property against D40_MEMCPY_MAX_CHANS, but reads the property directly into a smaller global array. A long property can therefore overwrite adjacent data. The mutable global also lets a later DMA40 instance replace the memcpy channel mapping used for future allocations on an earlier instance. Store the mapping in the per-device platform data, validate the property against that storage, and check the property read result. The property is required and d40_probe() always populates the platform data, so remove the obsolete global mapping and fallback. Fixes: a7dacb68b35a ("dmaengine: ste_dma40: Allow memcpy channels to be configured from DT") Reported-by: sashiko-bot@kernel.org Closes: https://lore.kernel.org/dmaengine/20260819225215.5EA2F1F000E9@smtp.kernel.org/ Assisted-by: LLM Signed-off-by: Linus Walleij --- drivers/dma/ste_dma40.c | 45 ++++++++++++++------------------------------- 1 file changed, 14 insertions(+), 31 deletions(-) diff --git a/drivers/dma/ste_dma40.c b/drivers/dma/ste_dma40.c index 557b9620c488..a53155b1fe1f 100644 --- a/drivers/dma/ste_dma40.c +++ b/drivers/dma/ste_dma40.c @@ -28,6 +28,8 @@ #include "ste_dma40.h" #include "ste_dma40_ll.h" +#define D40_MEMCPY_MAX_CHANS 8 + /** * struct stedma40_platform_data - Configuration struct for the dma device. * @@ -41,6 +43,7 @@ * to use SoftLLI. * @use_esram_lcla: flag for mapping the lcla into esram region * @num_of_memcpy_chans: The number of channels reserved for memcpy. + * @memcpy_channels: The event lines used for memcpy. * @num_of_phy_chans: The number of physical channels implemented in HW. * 0 means reading the number of channels from DMA HW but this is only valid * for 'multiple of 4' channels, like 8. @@ -51,6 +54,7 @@ struct stedma40_platform_data { int num_of_soft_lli_chans; bool use_esram_lcla; int num_of_memcpy_chans; + u32 memcpy_channels[D40_MEMCPY_MAX_CHANS]; int num_of_phy_chans; }; @@ -86,25 +90,6 @@ struct stedma40_platform_data { #define D40_ALLOC_PHY BIT(30) #define D40_ALLOC_LOG_FREE 0 -#define D40_MEMCPY_MAX_CHANS 8 - -/* Reserved event lines for memcpy only. */ -#define DB8500_DMA_MEMCPY_EV_0 51 -#define DB8500_DMA_MEMCPY_EV_1 56 -#define DB8500_DMA_MEMCPY_EV_2 57 -#define DB8500_DMA_MEMCPY_EV_3 58 -#define DB8500_DMA_MEMCPY_EV_4 59 -#define DB8500_DMA_MEMCPY_EV_5 60 - -static int dma40_memcpy_channels[] = { - DB8500_DMA_MEMCPY_EV_0, - DB8500_DMA_MEMCPY_EV_1, - DB8500_DMA_MEMCPY_EV_2, - DB8500_DMA_MEMCPY_EV_3, - DB8500_DMA_MEMCPY_EV_4, - DB8500_DMA_MEMCPY_EV_5, -}; - /* Default configuration for physical memcpy */ static const struct stedma40_chan_cfg dma40_memcpy_conf_phy = { .mode = STEDMA40_MODE_PHYSICAL, @@ -2023,7 +2008,8 @@ static int d40_config_memcpy(struct d40_chan *d40c) if (dma_has_cap(DMA_MEMCPY, cap) && !dma_has_cap(DMA_SLAVE, cap)) { d40c->dma_cfg = dma40_memcpy_conf_log; - d40c->dma_cfg.dev_type = dma40_memcpy_channels[d40c->chan.chan_id]; + d40c->dma_cfg.dev_type = + d40c->base->plat_data->memcpy_channels[d40c->chan.chan_id]; d40_log_cfg(&d40c->dma_cfg, &d40c->log_def.lcsp1, &d40c->log_def.lcsp3); @@ -3293,12 +3279,7 @@ static int __init d40_hw_detect_init(struct platform_device *pdev, num_phy_chans = min(num_phy_chans, STEDMA40_MAX_PHYS); /* The number of channels used for memcpy */ - if (plat_data->num_of_memcpy_chans) - num_memcpy_chans = plat_data->num_of_memcpy_chans; - else - num_memcpy_chans = ARRAY_SIZE(dma40_memcpy_channels); - - num_memcpy_chans = min(num_memcpy_chans, D40_MEMCPY_MAX_CHANS); + num_memcpy_chans = plat_data->num_of_memcpy_chans; num_log_chans = num_phy_chans * D40_MAX_LOG_CHAN_PER_PHY; dev_info(dev, @@ -3547,6 +3528,7 @@ static int __init d40_of_probe(struct device *dev, struct stedma40_platform_data *pdata; int num_phy = 0, num_memcpy = 0, num_disabled = 0; const __be32 *list; + int ret; pdata = devm_kzalloc(dev, sizeof(*pdata), GFP_KERNEL); if (!pdata) @@ -3560,18 +3542,19 @@ static int __init d40_of_probe(struct device *dev, list = of_get_property(np, "memcpy-channels", &num_memcpy); num_memcpy /= sizeof(*list); - if (num_memcpy > D40_MEMCPY_MAX_CHANS || num_memcpy <= 0) { + if (num_memcpy > ARRAY_SIZE(pdata->memcpy_channels) || + num_memcpy <= 0) { d40_err(dev, "Invalid number of memcpy channels specified (%d)\n", num_memcpy); return -EINVAL; } + ret = of_property_read_u32_array(np, "memcpy-channels", + pdata->memcpy_channels, num_memcpy); + if (ret) + return ret; pdata->num_of_memcpy_chans = num_memcpy; - of_property_read_u32_array(np, "memcpy-channels", - dma40_memcpy_channels, - num_memcpy); - list = of_get_property(np, "disabled-channels", &num_disabled); num_disabled /= sizeof(*list); -- 2.55.0