DMA Engine development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Sai Sree Kartheek Adivi" <s-adivi@ti.com>
Cc: conor+dt@kernel.org, devicetree@vger.kernel.org, robh@kernel.org,
	vkoul@kernel.org, Frank.Li@kernel.org, dmaengine@vger.kernel.org
Subject: Re: [PATCH v12 18/20] dmaengine: ti: k3-udma-v2: Add support for PKTDMA V2
Date: Wed, 07 Oct 2026 11:12:54 +0000	[thread overview]
Message-ID: <sashiko-outbox-162917@kernel.org> (raw)
In-Reply-To: <20261007102936.2402427-19-s-adivi@ti.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] dmaengine: ti: hardware ring UAF on unstoppable DMA channel error path
- [Medium] dmaengine: ti: udma_v2_ring_irq_handler returns IRQ_NONE for valid RX flush
- [Medium] dmaengine: ti: DMA mapping leaks on probe and setup error paths
--

commit 49c152d7719d193b9ac7700439e03ff1c85f702b
Author: Sai Sree Kartheek Adivi <s-adivi@ti.com>

dmaengine: ti: k3-udma-v2: Add support for PKTDMA V2

The patch adds support for PKTDMA V2 to the k3-udma driver. It introduces
changes such as static channel mapping, direct IRQs to the GIC, unified
channel space, and remote side configuration handled directly by DMA without
needing to write to PEER registers.

> diff --git a/drivers/dma/ti/k3-udma-v2.c b/drivers/dma/ti/k3-udma-v2.c
> index 0bbd7e41a8f9b..feac531a24f47 100644
> --- a/drivers/dma/ti/k3-udma-v2.c
> +++ b/drivers/dma/ti/k3-udma-v2.c
[ ... ]
> @@ -803,6 +803,155 @@ static int bcdma_v2_alloc_chan_resources(struct dma_chan *chan)
>  	return ret;
>  }
>  
> +static int pktdma_v2_alloc_chan_resources(struct dma_chan *chan)
> +{
[ ... ]
> +	if (udma_is_chan_running(uc)) {
> +		dev_warn(ud->dev, "chan%d: is running!\n", uc->id);
> +		ud->reset_chan(uc, false);
> +		if (udma_is_chan_running(uc)) {
> +			dev_err(ud->dev, "chan%d: won't stop!\n", uc->id);
> +			ret = -EBUSY;
> +			goto err_res_free;
> +		}
> +	}
[ ... ]
> +	ret = request_irq(uc->irq_num_ring, udma_v2_ring_irq_handler,
> +			  IRQF_SHARED | IRQF_TRIGGER_HIGH, uc->name, uc);
> +
> +	if (ret) {

[Severity: Medium]
Will returning IRQ_NONE for a valid hardware event (like an RX flush descriptor
successfully popped) break the IRQF_SHARED contract?

In udma_v2_ring_irq_handler(), if udma_pop_from_ring() returns -ENOENT, it
evaluates as true and returns IRQ_NONE:

    if (udma_pop_from_ring(uc, &paddr) || !paddr)
        return IRQ_NONE;

Since accumulating these spurious interrupts during teardown can cause the
spurious IRQ detector to permanently disable the interrupt line, does this
break all other devices sharing the IRQ?

[ ... ]
> +err_irq_free:
> +	uc->irq_num_ring = 0;
> +err_res_free:
> +	udma_free_tx_resources(uc);
> +	udma_free_rx_resources(uc);

[Severity: High]
Does this code free the coherent DMA memory back to the kernel pool without
disabling the hardware ring accelerator?

If the DMA channel is still running (as checked earlier in the function) and
the ring accelerator points to this freed memory, will the hardware perform
arbitrary DMA writes/reads and corrupt kernel memory?


[Severity: Medium]
Does the error path in udma_v2_probe() permanently leak coherent DMA memory?

If of_dma_controller_register() fails, it returns without calling
udma_teardown_rx_flush():

    ret = of_dma_controller_register(dev->of_node, udma_v2_of_xlate, ud);
    if (ret) {
        dev_err(dev, "failed to register of_dma controller\n");
        dma_async_device_unregister(&ud->ddev);
    }
    return ret;

Additionally, if dma_map_single() fails inside udma_setup_rx_flush(), does it
return -ENOMEM without unmapping the already-mapped resources like
rx_flush->buffer_paddr?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261007102936.2402427-1-s-adivi@ti.com?part=18

  reply	other threads:[~2026-10-07 11:12 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-07 10:28 [PATCH v12 00/20] dmaengine: ti: Add support for BCDMA v2 and PKTDMA v2 Sai Sree Kartheek Adivi
2026-10-07 10:28 ` [PATCH v12 01/20] dmaengine: ti: k3-udma: Fix sporadic crash on AM62x Sai Sree Kartheek Adivi
2026-10-07 10:28 ` [PATCH v12 02/20] dmaengine: ti: k3-udma: move macros to header file Sai Sree Kartheek Adivi
2026-10-07 10:28 ` [PATCH v12 03/20] dmaengine: ti: k3-udma: move structs and enums " Sai Sree Kartheek Adivi
2026-10-07 10:28 ` [PATCH v12 04/20] dmaengine: ti: k3-udma: move static inline helper functions " Sai Sree Kartheek Adivi
2026-10-07 10:28 ` [PATCH v12 05/20] dmaengine: ti: k3-udma: move descriptor management to k3-udma-common.c Sai Sree Kartheek Adivi
2026-10-07 10:53   ` sashiko-bot
2026-10-07 10:28 ` [PATCH v12 06/20] dmaengine: ti: k3-udma: move ring management functions " Sai Sree Kartheek Adivi
2026-10-07 10:28 ` [PATCH v12 07/20] dmaengine: ti: k3-udma: Add variant-specific function pointers to udma_dev Sai Sree Kartheek Adivi
2026-10-07 10:28 ` [PATCH v12 08/20] dmaengine: ti: k3-udma: move udma utility functions to k3-udma-common.c Sai Sree Kartheek Adivi
2026-10-07 10:28 ` [PATCH v12 09/20] dmaengine: ti: k3-udma: move resource management " Sai Sree Kartheek Adivi
2026-10-07 10:28 ` [PATCH v12 10/20] dmaengine: ti: k3-udma: refactor resource setup functions Sai Sree Kartheek Adivi
2026-10-07 10:28 ` [PATCH v12 11/20] dmaengine: ti: k3-udma: move inclusion of k3-udma-private.c to k3-udma-common.c Sai Sree Kartheek Adivi
2026-10-07 10:28 ` [PATCH v12 12/20] dmaengine: ti: k3-udma: pin owning module while glue clients hold a udma_dev Sai Sree Kartheek Adivi
2026-10-07 10:55   ` sashiko-bot
2026-10-07 10:28 ` [PATCH v12 13/20] drivers: soc: ti: k3-ringacc: handle absence of tisci Sai Sree Kartheek Adivi
2026-10-07 10:59   ` sashiko-bot
2026-10-07 10:28 ` [PATCH v12 14/20] dt-bindings: dma: ti: Add K3 BCDMA V2 Sai Sree Kartheek Adivi
2026-10-07 10:58   ` sashiko-bot
2026-10-07 10:28 ` [PATCH v12 15/20] dt-bindings: dma: ti: Add K3 PKTDMA V2 Sai Sree Kartheek Adivi
2026-10-07 10:28 ` [PATCH v12 16/20] dmaengine: ti: k3-psil-am62l: Add AM62Lx PSIL and PDMA data Sai Sree Kartheek Adivi
2026-10-07 10:28 ` [PATCH v12 17/20] dmaengine: ti: k3-udma-v2: New driver for K3 BCDMA_V2 Sai Sree Kartheek Adivi
2026-10-07 11:10   ` sashiko-bot
2026-10-07 10:28 ` [PATCH v12 18/20] dmaengine: ti: k3-udma-v2: Add support for PKTDMA V2 Sai Sree Kartheek Adivi
2026-10-07 11:12   ` sashiko-bot [this message]
2026-10-07 10:29 ` [PATCH v12 19/20] dmaengine: ti: k3-udma-v2: Update glue layer to support " Sai Sree Kartheek Adivi
2026-10-07 11:08   ` sashiko-bot
2026-10-07 10:29 ` [PATCH v12 20/20] dmaengine: ti: k3-udma: Validate resource ID and fix logging in reservation Sai Sree Kartheek Adivi
2026-10-07 11:05   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=sashiko-outbox-162917@kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=dmaengine@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=s-adivi@ti.com \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox