From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1AC614746CF; Fri, 18 Sep 2026 16:25:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789748705; cv=none; b=K0tpH59HgmEmEqtmlCxGqx7hdfg+Q2IwPQafP1YrIDfZDJpMYh8/DE0QU/wdJPZYfK1Y34OUHQ9brqFUapBxqsHL+vEvabPw5y9J32Sor+moqoM0NRwoKscgPHQG5+x+INFc3uOmVX5qhDZ2GxIEjkO3DDAJPGMcfeUFL56l2KM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789748705; c=relaxed/simple; bh=E4eqolHbKENxgiQIdKqhAtEAqK8UYDXjKOEDUAr2ppw=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Z1vXcKMIzyjM39wkCs0xEO6MKslOklOFLRH3hFS33nyyxsRN0lTI4emn9qnxkD+gUVrE5rqgZJnhV4h11i5eNNP2TT5OQ+qGYCYa3vtB1LRuMXoVySku+N6v+CJvkLKxH34JN5sARHm2bkpqd3QLIw+qfhIYU06eCftlhEKUyTg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=QMAWidFK; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="QMAWidFK" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 40E941F000FF; Fri, 18 Sep 2026 16:24:59 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1789748700; bh=z56kpCym5C1Q1FBflM/aiThi6ifQGOGUwyGgBXhLwtU=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=QMAWidFKjlF5fbn7zKxdQQ+Dl+7vh+bT7XJ/fN1RCsQ10cX+lX1IilZFMzpH2amom JcBBkTIf16Xp4vKOK3ax4mHZNBbzYRponRfZQx6kcm+wLpnHbdZWhdwBnFdkuz2ebP 0rezIhgLzX7ro5lpdRIzlfuGmpuI7sy1p+dK6w+pIm63elBhMTmZvIIuNQ5qVMztGy g1slgDRmy8HYpf4Z9czwdqxJT9go9XDJuzJC64uXd1m50HWYfM5/3ayUuOnW3l1OtD 7jgACkF+TkFJvwikm5iT7gPQVpO66wj46VSZvh7RxCYb8s+8logi8+0zyeiTyhkQ9H zVzDijA4eGjbg== From: Linus Walleij Date: Fri, 18 Sep 2026 18:24:38 +0200 Subject: [PATCH v3 19/22] dmaengine: ste_dma40: Fix event group bounds Precedence: bulk X-Mailing-List: dmaengine@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20260918-dma40-fixes-v3-19-8dd8450669e8@kernel.org> References: <20260918-dma40-fixes-v3-0-8dd8450669e8@kernel.org> In-Reply-To: <20260918-dma40-fixes-v3-0-8dd8450669e8@kernel.org> To: Vinod Koul , Frank Li Cc: dmaengine@vger.kernel.org, phone-devel@vger.kernel.org, Linus Walleij , sashiko-bot@kernel.org X-Mailer: b4 0.14.3 The dev_type validation can allow values whose derived event group has no matching physical channel pair. d40_allocate_channel() then indexes phy_res with j + event_group * 2, and __d40_set_prio_rt() uses the same group to select priority and realtime registers. Reject dev_type values outside the hardware event-group range, and stop the physical-channel search before a partial final channel group can index past phy_res. Fixes: 26955c07dcf3 ("dmaengine: ste_dma40: Amalgamate DMA source and destination channel numbers") Reported-by: sashiko-bot@kernel.org Closes: https://lore.kernel.org/dmaengine/20260819225008.5F9651F000E9@smtp.kernel.org/ Assisted-by: LLM Signed-off-by: Linus Walleij --- drivers/dma/ste_dma40.c | 23 +++++++++++++++++++++-- 1 file changed, 21 insertions(+), 2 deletions(-) diff --git a/drivers/dma/ste_dma40.c b/drivers/dma/ste_dma40.c index 26dbef630eef..5dbe11fceb4c 100644 --- a/drivers/dma/ste_dma40.c +++ b/drivers/dma/ste_dma40.c @@ -79,6 +79,10 @@ struct stedma40_platform_data { #define D40_LCLA_LINK_PER_EVENT_GRP 128 #define D40_LCLA_END D40_LCLA_LINK_PER_EVENT_GRP +/* Number of event groups per hardware register layout */ +#define D40_EVENT_GROUPS_V4A 4 +#define D40_EVENT_GROUPS_V4B 5 + /* Max number of logical channels per physical channel */ #define D40_MAX_LOG_CHAN_PER_PHY 32 @@ -513,6 +517,7 @@ struct d40_chan { * @high_prio_clear: the high priority clear register * @interrupt_en: the interrupt enable register * @interrupt_clear: the interrupt clear register + * @num_event_groups: number of supported event groups * @il: the pointer to struct d40_interrupt_lookup * @il_size: the size of d40_interrupt_lookup array * @init_reg: the pointer to the struct d40_reg_val @@ -527,6 +532,7 @@ struct d40_gen_dmac { u32 high_prio_clear; u32 interrupt_en; u32 interrupt_clear; + u32 num_event_groups; struct d40_interrupt_lookup *il; u32 il_size; struct d40_reg_val *init_reg; @@ -1752,6 +1758,11 @@ static int d40_validate_conf(struct d40_chan *d40c, bool is_log = conf->mode == STEDMA40_MODE_LOGICAL; bool invalid_dev_type = conf->dev_type < 0; + if (!invalid_dev_type && + D40_TYPE_TO_GROUP(conf->dev_type) >= + d40c->base->gen_dmac.num_event_groups) + invalid_dev_type = true; + if (!conf->dir) { chan_err(d40c, "Invalid direction.\n"); res = -EINVAL; @@ -1934,8 +1945,12 @@ static int d40_allocate_channel(struct d40_chan *d40c, bool *first_phy_user) } } } else - for (j = 0; j < d40c->base->num_phy_chans; j += 8) { + for (j = 0; j < d40c->base->num_phy_chans; + j += D40_GROUP_SIZE) { int phy_num = j + event_group * 2; + if (phy_num + 1 >= num_phy_chans) + break; + for (i = phy_num; i < phy_num + 2; i++) { if (d40_alloc_mask_set(&phys[i], is_src, @@ -1955,8 +1970,10 @@ static int d40_allocate_channel(struct d40_chan *d40c, bool *first_phy_user) return -EINVAL; /* Find logical channel */ - for (j = 0; j < d40c->base->num_phy_chans; j += 8) { + for (j = 0; j < d40c->base->num_phy_chans; j += D40_GROUP_SIZE) { int phy_num = j + event_group * 2; + if (phy_num + 1 >= num_phy_chans) + break; if (d40c->dma_cfg.use_fixed_channel) { i = d40c->dma_cfg.phy_channel; @@ -3326,6 +3343,7 @@ static int __init d40_hw_detect_init(struct platform_device *pdev, base->log_chans = &base->phy_chans[num_phy_chans]; if (base->plat_data->num_of_phy_chans == 14) { + base->gen_dmac.num_event_groups = D40_EVENT_GROUPS_V4B; base->gen_dmac.backup = d40_backup_regs_v4b; base->gen_dmac.backup_size = BACKUP_REGS_SZ_V4B; base->gen_dmac.interrupt_en = D40_DREG_CPCMIS; @@ -3339,6 +3357,7 @@ static int __init d40_hw_detect_init(struct platform_device *pdev, base->gen_dmac.init_reg = dma_init_reg_v4b; base->gen_dmac.init_reg_size = ARRAY_SIZE(dma_init_reg_v4b); } else { + base->gen_dmac.num_event_groups = D40_EVENT_GROUPS_V4A; if (base->rev >= 3) { base->gen_dmac.backup = d40_backup_regs_v4a; base->gen_dmac.backup_size = BACKUP_REGS_SZ_V4A; -- 2.55.0