DMA Engine development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Linus Walleij" <linusw@kernel.org>
Cc: dmaengine@vger.kernel.org, Frank.Li@kernel.org, vkoul@kernel.org
Subject: Re: [PATCH v6 20/23] dmaengine: ste_dma40: Fix event group bounds
Date: Thu, 24 Sep 2026 09:28:27 +0000	[thread overview]
Message-ID: <20260924092827.AC3E71F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924-dma40-fixes-v6-20-fdb6755020a2@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] dmaengine: ste_dma40: channel aliasing for event group 4 on V4B
--

commit 48ff5fdacb29b6847b9d51f8ce427281645c1c9b
Author: Linus Walleij <linusw@kernel.org>
dmaengine: ste_dma40: Fix event group bounds

This commit fixes event group bounds validation by properly restricting
device type values to the hardware event-group range and removing incorrect
physical channel limits. It also stops physical channel searches before they
can index past the allocated channel array.

Closes: https://lore.kernel.org/dmaengine/20260819225008.5F9651F000E9@smtp.kernel.org/

> diff --git a/drivers/dma/ste_dma40.c b/drivers/dma/ste_dma40.c
> index 8b13f1360edbe..d3d79e394d028 100644
> --- a/drivers/dma/ste_dma40.c
> +++ b/drivers/dma/ste_dma40.c
[ ... ]
> @@ -2068,8 +2078,12 @@ static int d40_allocate_channel(struct d40_chan *d40c, bool *first_phy_user)
>  				}
>  			}
>  		} else
> -			for (j = 0; j < d40c->base->num_phy_chans; j += 8) {
> +			for (j = 0; j < d40c->base->num_phy_chans;
> +			     j += D40_GROUP_SIZE) {
>  				int phy_num = j  + event_group * 2;
> +				if (phy_num + 1 >= num_phy_chans)
> +					break;
> +

[Severity: High]
Does this cause channel aliasing for event group 4 on V4B hardware?

Since D40_GROUP_SIZE is hardcoded to 8, if event_group is 4 (allowed for V4B)
and j is 0, phy_num evaluates to 8. But if event_group is 0 and j is 8,
phy_num also evaluates to 8.

Could this collision map two different groups to the same physical channel?

Additionally, since D40_PHYS_TO_GROUP is hardcoded as ((phys & 7) / 2),
channel 8 evaluates to group 0. Might this incorrectly configure the GCC clock
and hardware registers for group 0 instead of 4, breaking DMA operations for
event group 4 and channels >= 8?

[ ... ]
> @@ -2089,8 +2103,10 @@ static int d40_allocate_channel(struct d40_chan *d40c, bool *first_phy_user)
>  		return -EINVAL;
>  
>  	/* Find logical channel */
> -	for (j = 0; j < d40c->base->num_phy_chans; j += 8) {
> +	for (j = 0; j < d40c->base->num_phy_chans; j += D40_GROUP_SIZE) {
>  		int phy_num = j + event_group * 2;
> +		if (phy_num + 1 >= num_phy_chans)
> +			break;

[Severity: High]
Will this mathematical collision also occur here for logical channel allocation
when event_group is 4?

[ ... ]
> @@ -3470,6 +3486,7 @@ static int __init d40_hw_detect_init(struct platform_device *pdev,
>  	base->log_chans = &base->phy_chans[num_phy_chans];
>  
>  	if (base->plat_data->num_of_phy_chans == 14) {
> +		base->gen_dmac.num_event_groups = D40_EVENT_GROUPS_V4B;

[Severity: High]
Does setting the max event groups to 5 allow event_group = 4, which
ultimately exposes the aliasing bug against the hardcoded block size of 8
in d40_allocate_channel()?

>  		base->gen_dmac.backup = d40_backup_regs_v4b;
>  		base->gen_dmac.backup_size = BACKUP_REGS_SZ_V4B;
>  		base->gen_dmac.interrupt_en = D40_DREG_CPCMIS;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260924-dma40-fixes-v6-0-fdb6755020a2@kernel.org?part=20

  reply	other threads:[~2026-09-24  9:28 UTC|newest]

Thread overview: 45+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24  8:35 [PATCH v6 00/23] dmaengine: ste_dma40: Fix numerous accumulated bugs Linus Walleij
2026-09-24  8:35 ` [PATCH v6 01/23] dmaengine: ste_dma40: Fix physical cyclic capability Linus Walleij
2026-09-24  8:35 ` [PATCH v6 02/23] dmaengine: ste_dma40: Fix cyclic transfer residue Linus Walleij
2026-09-24 14:37   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 03/23] dmaengine: ste_dma40: Recover coalesced cyclic callbacks Linus Walleij
2026-09-24 14:48   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 04/23] dmaengine: ste_dma40: Fix failed start cleanup Linus Walleij
2026-09-24  8:35 ` [PATCH v6 05/23] dmaengine: ste_dma40: Fix probe runtime PM disable Linus Walleij
2026-09-24 14:50   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 06/23] dmaengine: ste_dma40: Check runtime PM in IRQ Linus Walleij
2026-09-24  8:35 ` [PATCH v6 07/23] dmaengine: ste_dma40: Handle runtime PM resume errors Linus Walleij
2026-09-24 14:54   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 08/23] dmaengine: ste_dma40: Return IRQ_NONE when no interrupt is pending Linus Walleij
2026-09-24 14:55   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 09/23] dmaengine: ste_dma40: Init hardware before registration Linus Walleij
2026-09-24 14:58   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 10/23] dmaengine: ste_dma40: Fix probe IRQ leak Linus Walleij
2026-09-24 15:02   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 11/23] dmaengine: ste_dma40: Fix DMA registration unwind Linus Walleij
2026-09-24  9:10   ` sashiko-bot
2026-09-24 15:11   ` Frank Li
2026-09-27  8:41     ` Linus Walleij
2026-09-24  8:35 ` [PATCH v6 12/23] dmaengine: ste_dma40: Fix LCLA allocation order Linus Walleij
2026-09-24 15:16   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 13/23] dmaengine: ste_dma40: Fix probe LCLA free Linus Walleij
2026-09-24 15:34   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 14/23] dmaengine: ste_dma40: Put the LCPA SRAM node Linus Walleij
2026-09-24 15:43   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 15/23] dmaengine: ste_dma40: Fix memcpy channel parsing Linus Walleij
2026-09-24 15:49   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 16/23] dmaengine: ste_dma40: Validate disabled channel indexes Linus Walleij
2026-09-24 15:53   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 17/23] dmaengine: ste_dma40: Validate DMA specifier length Linus Walleij
2026-09-24 15:54   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 18/23] dmaengine: ste_dma40: Reject direction changes after allocation Linus Walleij
2026-09-24 15:57   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 19/23] dmaengine: ste_dma40: Fix logical channel bounds check Linus Walleij
2026-09-24  8:35 ` [PATCH v6 20/23] dmaengine: ste_dma40: Fix event group bounds Linus Walleij
2026-09-24  9:28   ` sashiko-bot [this message]
2026-09-24  8:35 ` [PATCH v6 21/23] dmaengine: ste_dma40: Search all blocks for fixed logical channels Linus Walleij
2026-09-24 16:08   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 22/23] dmaengine: ste_dma40: Validate fixed physical channel indexes Linus Walleij
2026-09-24 16:09   ` Frank Li
2026-09-24  8:35 ` [PATCH v6 23/23] dmaengine: ste_dma40: Validate memcpy configuration Linus Walleij
2026-09-24 16:11   ` Frank Li

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924092827.AC3E71F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=dmaengine@vger.kernel.org \
    --cc=linusw@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox