From: Linus Walleij <linusw@kernel.org>
To: Vinod Koul <vkoul@kernel.org>, Frank Li <Frank.Li@kernel.org>
Cc: dmaengine@vger.kernel.org, phone-devel@vger.kernel.org,
Linus Walleij <linusw@kernel.org>,
sashiko-bot@kernel.org, Frank Li <Frank.Li@nxp.com>
Subject: [PATCH v7 15/24] dmaengine: ste_dma40: Fix memcpy channel parsing
Date: Sun, 27 Sep 2026 11:03:28 +0200 [thread overview]
Message-ID: <20260927-dma40-fixes-v7-15-89f595e8851d@kernel.org> (raw)
In-Reply-To: <20260927-dma40-fixes-v7-0-89f595e8851d@kernel.org>
d40_of_probe() validates the memcpy-channels property against
D40_MEMCPY_MAX_CHANS, but reads the property directly into a smaller global
array. A long property can therefore overwrite adjacent data. The mutable
global also lets a later DMA40 instance replace the memcpy channel mapping
used for future allocations on an earlier instance.
Store the mapping in the per-device platform data, validate the property
against that storage, and check the property read result. The property is
required and d40_probe() always populates the platform data, so remove the
obsolete global mapping and fallback.
Fixes: a7dacb68b35a ("dmaengine: ste_dma40: Allow memcpy channels to be configured from DT")
Reported-by: sashiko-bot@kernel.org
Closes: https://lore.kernel.org/dmaengine/20260819225215.5EA2F1F000E9@smtp.kernel.org/
Assisted-by: LLM
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
---
drivers/dma/ste_dma40.c | 45 ++++++++++++++-------------------------------
1 file changed, 14 insertions(+), 31 deletions(-)
diff --git a/drivers/dma/ste_dma40.c b/drivers/dma/ste_dma40.c
index 70f2a6594945..43a6ded6aa09 100644
--- a/drivers/dma/ste_dma40.c
+++ b/drivers/dma/ste_dma40.c
@@ -28,6 +28,8 @@
#include "ste_dma40.h"
#include "ste_dma40_ll.h"
+#define D40_MEMCPY_MAX_CHANS 8
+
/**
* struct stedma40_platform_data - Configuration struct for the dma device.
*
@@ -41,6 +43,7 @@
* to use SoftLLI.
* @use_esram_lcla: flag for mapping the lcla into esram region
* @num_of_memcpy_chans: The number of channels reserved for memcpy.
+ * @memcpy_channels: The event lines used for memcpy.
* @num_of_phy_chans: The number of physical channels implemented in HW.
* 0 means reading the number of channels from DMA HW but this is only valid
* for 'multiple of 4' channels, like 8.
@@ -51,6 +54,7 @@ struct stedma40_platform_data {
int num_of_soft_lli_chans;
bool use_esram_lcla;
int num_of_memcpy_chans;
+ u32 memcpy_channels[D40_MEMCPY_MAX_CHANS];
int num_of_phy_chans;
};
@@ -89,25 +93,6 @@ struct stedma40_platform_data {
#define D40_ALLOC_PHY BIT(30)
#define D40_ALLOC_LOG_FREE 0
-#define D40_MEMCPY_MAX_CHANS 8
-
-/* Reserved event lines for memcpy only. */
-#define DB8500_DMA_MEMCPY_EV_0 51
-#define DB8500_DMA_MEMCPY_EV_1 56
-#define DB8500_DMA_MEMCPY_EV_2 57
-#define DB8500_DMA_MEMCPY_EV_3 58
-#define DB8500_DMA_MEMCPY_EV_4 59
-#define DB8500_DMA_MEMCPY_EV_5 60
-
-static int dma40_memcpy_channels[] = {
- DB8500_DMA_MEMCPY_EV_0,
- DB8500_DMA_MEMCPY_EV_1,
- DB8500_DMA_MEMCPY_EV_2,
- DB8500_DMA_MEMCPY_EV_3,
- DB8500_DMA_MEMCPY_EV_4,
- DB8500_DMA_MEMCPY_EV_5,
-};
-
/* Default configuration for physical memcpy */
static const struct stedma40_chan_cfg dma40_memcpy_conf_phy = {
.mode = STEDMA40_MODE_PHYSICAL,
@@ -2154,7 +2139,8 @@ static int d40_config_memcpy(struct d40_chan *d40c)
if (dma_has_cap(DMA_MEMCPY, cap) && !dma_has_cap(DMA_SLAVE, cap)) {
d40c->dma_cfg = dma40_memcpy_conf_log;
- d40c->dma_cfg.dev_type = dma40_memcpy_channels[d40c->chan.chan_id];
+ d40c->dma_cfg.dev_type =
+ d40c->base->plat_data->memcpy_channels[d40c->chan.chan_id];
d40_log_cfg(&d40c->dma_cfg,
&d40c->log_def.lcsp1, &d40c->log_def.lcsp3);
@@ -3434,12 +3420,7 @@ static int __init d40_hw_detect_init(struct platform_device *pdev,
num_phy_chans = min(num_phy_chans, STEDMA40_MAX_PHYS);
/* The number of channels used for memcpy */
- if (plat_data->num_of_memcpy_chans)
- num_memcpy_chans = plat_data->num_of_memcpy_chans;
- else
- num_memcpy_chans = ARRAY_SIZE(dma40_memcpy_channels);
-
- num_memcpy_chans = min(num_memcpy_chans, D40_MEMCPY_MAX_CHANS);
+ num_memcpy_chans = plat_data->num_of_memcpy_chans;
num_log_chans = num_phy_chans * D40_MAX_LOG_CHAN_PER_PHY;
dev_info(dev,
@@ -3688,6 +3669,7 @@ static int __init d40_of_probe(struct device *dev,
struct stedma40_platform_data *pdata;
int num_phy = 0, num_memcpy = 0, num_disabled = 0;
const __be32 *list;
+ int ret;
pdata = devm_kzalloc(dev, sizeof(*pdata), GFP_KERNEL);
if (!pdata)
@@ -3701,18 +3683,19 @@ static int __init d40_of_probe(struct device *dev,
list = of_get_property(np, "memcpy-channels", &num_memcpy);
num_memcpy /= sizeof(*list);
- if (num_memcpy > D40_MEMCPY_MAX_CHANS || num_memcpy <= 0) {
+ if (num_memcpy > ARRAY_SIZE(pdata->memcpy_channels) ||
+ num_memcpy <= 0) {
d40_err(dev,
"Invalid number of memcpy channels specified (%d)\n",
num_memcpy);
return -EINVAL;
}
+ ret = of_property_read_u32_array(np, "memcpy-channels",
+ pdata->memcpy_channels, num_memcpy);
+ if (ret)
+ return ret;
pdata->num_of_memcpy_chans = num_memcpy;
- of_property_read_u32_array(np, "memcpy-channels",
- dma40_memcpy_channels,
- num_memcpy);
-
list = of_get_property(np, "disabled-channels", &num_disabled);
num_disabled /= sizeof(*list);
--
2.55.0
next prev parent reply other threads:[~2026-09-27 9:03 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-27 9:03 [PATCH v7 00/24] dmaengine: ste_dma40: Fix numerous accumulated bugs Linus Walleij
2026-09-27 9:03 ` [PATCH v7 01/24] dmaengine: ste_dma40: Fix physical cyclic capability Linus Walleij
2026-09-27 9:03 ` [PATCH v7 02/24] dmaengine: ste_dma40: Fix cyclic transfer residue Linus Walleij
2026-09-27 9:03 ` [PATCH v7 03/24] dmaengine: ste_dma40: Recover coalesced cyclic callbacks Linus Walleij
2026-09-28 16:48 ` Frank Li
2026-09-27 9:03 ` [PATCH v7 04/24] dmaengine: ste_dma40: Fix failed start cleanup Linus Walleij
2026-09-27 9:03 ` [PATCH v7 05/24] dmaengine: ste_dma40: Fix probe runtime PM disable Linus Walleij
2026-09-27 9:03 ` [PATCH v7 06/24] dmaengine: ste_dma40: Check runtime PM in IRQ Linus Walleij
2026-09-27 9:24 ` sashiko-bot
2026-09-27 17:48 ` Linus Walleij
2026-09-27 9:03 ` [PATCH v7 07/24] dmaengine: ste_dma40: Handle runtime PM resume errors Linus Walleij
2026-09-27 9:03 ` [PATCH v7 08/24] dmaengine: ste_dma40: Return IRQ_NONE when no interrupt is pending Linus Walleij
2026-09-27 9:03 ` [PATCH v7 09/24] dmaengine: ste_dma40: Init hardware before registration Linus Walleij
2026-09-28 16:49 ` Frank Li
2026-09-27 9:03 ` [PATCH v7 10/24] dmaengine: ste_dma40: Fix probe IRQ leak Linus Walleij
2026-09-28 16:50 ` Frank Li
2026-09-27 9:03 ` [PATCH v7 11/24] dmaengine: ste_dma40: Fix DMA registration unwind Linus Walleij
2026-09-28 16:57 ` Frank Li
2026-09-27 9:03 ` [PATCH v7 12/24] dmaengine: ste_dma40: Fix LCLA allocation order Linus Walleij
2026-09-27 9:03 ` [PATCH v7 13/24] dmaengine: ste_dma40: Fix probe LCLA free Linus Walleij
2026-09-27 9:03 ` [PATCH v7 14/24] dmaengine: ste_dma40: Put the LCPA SRAM node Linus Walleij
2026-09-27 9:03 ` Linus Walleij [this message]
2026-09-27 9:03 ` [PATCH v7 16/24] dmaengine: ste_dma40: Validate disabled channel indexes Linus Walleij
2026-09-27 9:03 ` [PATCH v7 17/24] dmaengine: ste_dma40: Validate DMA specifier length Linus Walleij
2026-09-27 9:03 ` [PATCH v7 18/24] dmaengine: ste_dma40: Reject direction changes after allocation Linus Walleij
2026-09-27 9:03 ` [PATCH v7 19/24] dmaengine: ste_dma40: Fix logical channel bounds check Linus Walleij
2026-09-28 16:58 ` Frank Li
2026-09-27 9:03 ` [PATCH v7 20/24] dmaengine: ste_dma40: Fix event group bounds Linus Walleij
2026-09-28 17:00 ` Frank Li
2026-09-27 9:03 ` [PATCH v7 21/24] dmaengine: ste_dma40: Fix V4B event group mapping Linus Walleij
2026-09-30 19:36 ` Frank Li
2026-09-27 9:03 ` [PATCH v7 22/24] dmaengine: ste_dma40: Search all blocks for fixed logical channels Linus Walleij
2026-10-05 15:39 ` Vinod Koul
2026-10-05 22:26 ` Linus Walleij
2026-09-27 9:03 ` [PATCH v7 23/24] dmaengine: ste_dma40: Validate fixed physical channel indexes Linus Walleij
2026-09-27 9:03 ` [PATCH v7 24/24] dmaengine: ste_dma40: Validate memcpy configuration Linus Walleij
2026-10-05 15:43 ` [PATCH v7 00/24] dmaengine: ste_dma40: Fix numerous accumulated bugs Vinod Koul
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260927-dma40-fixes-v7-15-89f595e8851d@kernel.org \
--to=linusw@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=Frank.Li@nxp.com \
--cc=dmaengine@vger.kernel.org \
--cc=phone-devel@vger.kernel.org \
--cc=sashiko-bot@kernel.org \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox