DMA Engine development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Linus Walleij" <linusw@kernel.org>
Cc: vkoul@kernel.org, dmaengine@vger.kernel.org, Frank.Li@kernel.org
Subject: Re: [PATCH v4 03/23] dmaengine: ste_dma40: Recover coalesced cyclic callbacks
Date: Sat, 19 Sep 2026 22:37:37 +0000	[thread overview]
Message-ID: <20260919223738.5E7381F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260920-dma40-fixes-v4-3-d751b2d9c23f@kernel.org>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] dmaengine: ste_dma40: double-interrupt race causes full buffer spurious callbacks
- [High] dmaengine: ste_dma40: duplicate cyclic callbacks on fallback pointer sampling failure
--

commit a2aa4dd1ba30133f07fa06190999eebead74c31d
Author: Linus Walleij <linusw@kernel.org>

dmaengine: ste_dma40: Recover coalesced cyclic callbacks

This commit addresses lost period notifications in the DMA40 driver caused
by coalesced cyclic callbacks. It calculates elapsed periods by comparing
the current memory-side pointer against the last queued callback position,
accounting for elapsed periods and potential full buffer laps.

> diff --git a/drivers/dma/ste_dma40.c b/drivers/dma/ste_dma40.c
> index c9983e600dafc..b992471e05f29 100644
> --- a/drivers/dma/ste_dma40.c
> +++ b/drivers/dma/ste_dma40.c

[ ... ]

> @@ -1484,6 +1488,40 @@ static bool d40_cyclic_offset(struct d40_chan *d40c, struct d40_desc *d40d,
>  	return false;
>  }
>  
> +static unsigned int d40_cyclic_periods_elapsed(struct d40_chan *d40c,
> +					       struct d40_desc *d40d)
> +{
> +	size_t current_pos;
> +	size_t offset;
> +	unsigned int periods;
> +
> +	if (!d40d->cyclic_period_len ||
> +	    !d40_cyclic_offset(d40c, d40d, &offset))
> +		return 1;

[Severity: High]
Could this fallback path lead to duplicate callbacks on the next interrupt?

If d40_cyclic_offset fails to reliably read the hardware pointer (for
example, returning false after retry failures due to concurrent register
updates), this returns 1 to legitimately report a single period completion.

However, since d40d->cyclic_callback_pos is left unmodified here, won't the
next successful interrupt recalculate the elapsed periods using the stale
cyclic_callback_pos, effectively recounting the period that was already
reported by this fallback path?

> +
> +	current_pos = rounddown(offset, d40d->cyclic_period_len);
> +	if (!d40_residue(d40c) && current_pos != offset)
> +		current_pos += d40d->cyclic_period_len;
> +	if (current_pos == d40d->cyclic_buf_len)
> +		current_pos = 0;
> +
> +	if (current_pos > d40d->cyclic_callback_pos) {
> +		periods = (current_pos - d40d->cyclic_callback_pos) /
> +			d40d->cyclic_period_len;
> +	} else if (current_pos < d40d->cyclic_callback_pos) {
> +		periods = (d40d->cyclic_buf_len -
> +			d40d->cyclic_callback_pos + current_pos) /
> +			d40d->cyclic_period_len;
> +	} else {
> +		/* At least one interrupt occurred, so assume one buffer lap. */
> +		periods = d40d->cyclic_buf_len / d40d->cyclic_period_len;
> +	}

[Severity: High]
Is it possible for this else branch to be triggered by a double-interrupt
race rather than a full buffer lap?

If a second or ghost interrupt fires immediately after the first, before the
hardware pointer has advanced to the next boundary, current_pos will exactly
equal cyclic_callback_pos. This branch appears to interpret that condition
strictly as a full buffer lap caused by CPU starvation.

Could this extremely common double-interrupt race cause a massive burst of
spurious callbacks (a full buffer's worth) to be queued to the cyclic DMA
client, potentially leading to severe state desynchronization like ALSA
audio underruns or pointer jumps?

> +
> +	d40d->cyclic_callback_pos = current_pos;
> +
> +	return periods;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260920-dma40-fixes-v4-0-d751b2d9c23f@kernel.org?part=3

  reply	other threads:[~2026-09-19 22:37 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-19 22:22 [PATCH v4 00/23] dmaengine: ste_dma40: Fix numerous accumulated bugs Linus Walleij
2026-09-19 22:22 ` [PATCH v4 01/23] dmaengine: ste_dma40: Fix physical cyclic capability Linus Walleij
2026-09-19 22:22 ` [PATCH v4 02/23] dmaengine: ste_dma40: Fix cyclic transfer residue Linus Walleij
2026-09-19 22:22 ` [PATCH v4 03/23] dmaengine: ste_dma40: Recover coalesced cyclic callbacks Linus Walleij
2026-09-19 22:37   ` sashiko-bot [this message]
2026-09-19 22:22 ` [PATCH v4 04/23] dmaengine: ste_dma40: Fix failed start cleanup Linus Walleij
2026-09-19 22:22 ` [PATCH v4 05/23] dmaengine: ste_dma40: Fix probe runtime PM disable Linus Walleij
2026-09-19 22:22 ` [PATCH v4 06/23] dmaengine: ste_dma40: Check runtime PM in IRQ Linus Walleij
2026-09-19 22:22 ` [PATCH v4 07/23] dmaengine: ste_dma40: Handle runtime PM resume errors Linus Walleij
2026-09-19 22:22 ` [PATCH v4 08/23] dmaengine: ste_dma40: Return IRQ_NONE without interrupt status Linus Walleij
2026-09-19 22:36   ` sashiko-bot
2026-09-19 22:22 ` [PATCH v4 09/23] dmaengine: ste_dma40: Init hardware before registration Linus Walleij
2026-09-19 22:22 ` [PATCH v4 10/23] dmaengine: ste_dma40: Fix probe IRQ leak Linus Walleij
2026-09-19 22:22 ` [PATCH v4 11/23] dmaengine: ste_dma40: Fix DMA registration unwind Linus Walleij
2026-09-19 22:22 ` [PATCH v4 12/23] dmaengine: ste_dma40: Fix LCLA allocation order Linus Walleij
2026-09-19 22:22 ` [PATCH v4 13/23] dmaengine: ste_dma40: Fix probe LCLA free Linus Walleij
2026-09-19 22:22 ` [PATCH v4 14/23] dmaengine: ste_dma40: Put the LCPA SRAM node Linus Walleij
2026-09-19 22:22 ` [PATCH v4 15/23] dmaengine: ste_dma40: Fix memcpy channel parsing Linus Walleij
2026-09-19 22:22 ` [PATCH v4 16/23] dmaengine: ste_dma40: Validate disabled channel indexes Linus Walleij
2026-09-19 22:22 ` [PATCH v4 17/23] dmaengine: ste_dma40: Validate DMA specifier length Linus Walleij
2026-09-19 22:22 ` [PATCH v4 18/23] dmaengine: ste_dma40: Reject direction changes after allocation Linus Walleij
2026-09-19 22:22 ` [PATCH v4 19/23] dmaengine: ste_dma40: Fix logical channel bounds check Linus Walleij
2026-09-19 22:22 ` [PATCH v4 20/23] dmaengine: ste_dma40: Fix event group bounds Linus Walleij
2026-09-19 22:22 ` [PATCH v4 21/23] dmaengine: ste_dma40: Search all blocks for fixed logical channels Linus Walleij
2026-09-19 22:22 ` [PATCH v4 22/23] dmaengine: ste_dma40: Validate fixed physical channel indexes Linus Walleij
2026-09-19 22:22 ` [PATCH v4 23/23] dmaengine: ste_dma40: Validate memcpy configuration Linus Walleij

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260919223738.5E7381F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=dmaengine@vger.kernel.org \
    --cc=linusw@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox