From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 139FA4B1D0E; Fri, 18 Sep 2026 16:24:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789748699; cv=none; b=bGJtOCoIG/M6oupxBGcn28aZzxXiR3WQ53QWoc2V8H/gakgmrl+cQxRTCw0J6Pk/EtgHHNFQklm+j7igb4bQZQjSGeQ7DKsGTXvr12V2M5f0AYXSFCf+k7diKwOcwlNupoqf4ecfHrS8KGAvFOJ41Z1A6RQytvlq2lIZV16R+/g= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789748699; c=relaxed/simple; bh=8/1lqUoq/K34HgUabWvqpRwRpvmHca+eFx1A2VKBgjo=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=hJnRZ4alAvMJZ/HtELMsTeROm3WOjVy6gOQtUE48a2z3YKu7wF98HJWJhqKAjTfJzTHSbCpyY1VTgWgD3MdHGvWIGUbAW3iiKqJ3zHVkEx76qZS/cNtZRxrpDk+rOG6Q9yU0pkk33MNxtUEJXZFg617Hu30yaEAM4OWKXL6WgNg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=K5/N6cjZ; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="K5/N6cjZ" Received: by smtp.kernel.org (Postfix) with ESMTPSA id B55B61F00898; Fri, 18 Sep 2026 16:24:55 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1789748697; bh=yEeeeTHiqjPr/SFqeWUWU6XXka8YYzy+3bYgm7RasZg=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=K5/N6cjZnBIMeVryLlQTa8YTFh5+elPnWNPYGRWHGS0j4LDTX8tRTJU62KhSebE71 JaHP1HBG/MBzPQEI5q6U2SFThWiPAkYxBA2SKrrEiBlFD9vHKr1E0wJk4uhQe5ChhS 5Gyet1c5CiAE1ZGWCnwPdtR7LAusI7s6laCO2SKlkfbiGNGCsFvn0bbXHLyQ+zhZ6z 8vI5/YqhXd4ueXOtS5hXtH1wcVZI8MtcPHrW4KlwV4RuWYIsDgVHqVCcEV7z2iWP5N A39E6AJNjGoA3TjozVYAl8jWtzV0Lp+8W1bJwW1ZK+BMtFRyYhAeqVxSBXMWoGT4bI f3fHpv9caLWug== From: Linus Walleij Date: Fri, 18 Sep 2026 18:24:36 +0200 Subject: [PATCH v3 17/22] dmaengine: ste_dma40: Reject direction changes after allocation Precedence: bulk X-Mailing-List: dmaengine@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20260918-dma40-fixes-v3-17-8dd8450669e8@kernel.org> References: <20260918-dma40-fixes-v3-0-8dd8450669e8@kernel.org> In-Reply-To: <20260918-dma40-fixes-v3-0-8dd8450669e8@kernel.org> To: Vinod Koul , Frank Li Cc: dmaengine@vger.kernel.org, phone-devel@vger.kernel.org, Linus Walleij , sashiko-bot@kernel.org X-Mailer: b4 0.14.3 Logical channel allocation uses the configured direction to select the source or destination allocation mask, derive the logical channel number, and choose the LCPA location. d40_set_runtime_config_write() nevertheless overwrites the configured direction when a transfer is prepared for the opposite direction. d40_free_dma() then clears the wrong allocation mask, leaking the original resource and potentially releasing one used by another client. Reject directions that differ from the direction used during allocation and propagate runtime configuration errors to callers. Skip slave runtime configuration for memcpy transfers, which also use d40_prep_sg() but do not require it. Fixes: 95e1400fa131 ("DMAENGINE: add runtime slave config to DMA40 v3") Reported-by: sashiko-bot@kernel.org Closes: https://lore.kernel.org/dmaengine/20260618051539.15E201F000E9@smtp.kernel.org/ Assisted-by: LLM Signed-off-by: Linus Walleij --- drivers/dma/ste_dma40.c | 29 ++++++++++++++--------------- 1 file changed, 14 insertions(+), 15 deletions(-) diff --git a/drivers/dma/ste_dma40.c b/drivers/dma/ste_dma40.c index abb3ca015417..07a940a26074 100644 --- a/drivers/dma/ste_dma40.c +++ b/drivers/dma/ste_dma40.c @@ -2281,7 +2281,13 @@ d40_prep_sg(struct dma_chan *dchan, struct scatterlist *sg_src, return NULL; } - d40_set_runtime_config_write(dchan, &chan->slave_config, direction); + if (direction != DMA_MEM_TO_MEM) { + ret = d40_set_runtime_config_write(dchan, + &chan->slave_config, + direction); + if (ret) + return NULL; + } spin_lock_irqsave(&chan->lock, flags); @@ -2745,6 +2751,13 @@ static int d40_set_runtime_config_write(struct dma_chan *chan, return -EINVAL; } + if (direction != cfg->dir) { + chan_err(d40c, + "transfer direction %d differs from allocated direction %d\n", + direction, cfg->dir); + return -EINVAL; + } + src_addr_width = config->src_addr_width; src_maxburst = config->src_maxburst; dst_addr_width = config->dst_addr_width; @@ -2753,13 +2766,6 @@ static int d40_set_runtime_config_write(struct dma_chan *chan, if (direction == DMA_DEV_TO_MEM) { config_addr = config->src_addr; - if (cfg->dir != DMA_DEV_TO_MEM) - dev_dbg(d40c->base->dev, - "channel was not configured for peripheral " - "to memory transfer (%d) overriding\n", - cfg->dir); - cfg->dir = DMA_DEV_TO_MEM; - /* Configure the memory side */ if (dst_addr_width == DMA_SLAVE_BUSWIDTH_UNDEFINED) dst_addr_width = src_addr_width; @@ -2769,13 +2775,6 @@ static int d40_set_runtime_config_write(struct dma_chan *chan, } else if (direction == DMA_MEM_TO_DEV) { config_addr = config->dst_addr; - if (cfg->dir != DMA_MEM_TO_DEV) - dev_dbg(d40c->base->dev, - "channel was not configured for memory " - "to peripheral transfer (%d) overriding\n", - cfg->dir); - cfg->dir = DMA_MEM_TO_DEV; - /* Configure the memory side */ if (src_addr_width == DMA_SLAVE_BUSWIDTH_UNDEFINED) src_addr_width = dst_addr_width; -- 2.55.0