DPDK-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Prashant Gupta <prashant.gupta_3@nxp.com>
To: stephen@networkplumber.org, dev@dpdk.org
Cc: Gagandeep Singh <g.singh@nxp.com>
Subject: [PATCH v3-S1 4/5] dma/dpaa2: validate IOVA in pre-populate helpers
Date: Tue, 15 Sep 2026 17:04:21 +0530	[thread overview]
Message-ID: <20260915113422.4166287-5-prashant.gupta_3@nxp.com> (raw)
In-Reply-To: <20260915113422.4166287-1-prashant.gupta_3@nxp.com>

From: Gagandeep Singh <g.singh@nxp.com>

fle_sdd_pre_populate() and fle_sdd_sg_pre_populate() converted the SDD
and SG entry virtual addresses to IOVA with DPAA2_VADDR_TO_IOVA(), which
does not verify that the range is actually mapped in the IOMMU/SMMU. An
unmapped buffer was silently programmed into the hardware descriptor,
leading to an SMMU translation fault at transfer time that is hard to
trace back to the missing mapping.

Use DPAA2_VADDR_TO_IOVA_AND_CHECK() for the SDD, source SG and
destination SG buffers and report the offending address and size when
the translation is missing, so the misconfiguration is caught early and
clearly. Both helpers now return an error code which is propagated to
the caller instead of continuing with an invalid descriptor.

Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 drivers/dma/dpaa2/dpaa2_qdma.c | 58 ++++++++++++++++++++++++++++------
 1 file changed, 49 insertions(+), 9 deletions(-)

diff --git a/drivers/dma/dpaa2/dpaa2_qdma.c b/drivers/dma/dpaa2/dpaa2_qdma.c
index 6881ab1420..401ab56f39 100644
--- a/drivers/dma/dpaa2/dpaa2_qdma.c
+++ b/drivers/dma/dpaa2/dpaa2_qdma.c
@@ -183,14 +183,23 @@ dpaa2_qdma_multi_eq(struct qdma_virt_queue *qdma_vq)
 	return num_tx;
 }
 
-static void
+static int
 fle_sdd_pre_populate(struct qdma_cntx_fle_sdd *fle_sdd,
 	struct dpaa2_qdma_rbp *rbp, uint64_t src, uint64_t dest,
 	uint32_t fmt)
 {
 	struct qbman_fle *fle = fle_sdd->fle;
 	struct qdma_sdd *sdd = fle_sdd->sdd;
-	uint64_t sdd_iova = DPAA2_VADDR_TO_IOVA(sdd);
+	uint64_t sdd_iova, iova_size;
+
+	iova_size = sizeof(struct qdma_sdd) * DPAA2_QDMA_MAX_SDD;
+	sdd_iova = DPAA2_VADDR_TO_IOVA_AND_CHECK(sdd, iova_size);
+	if (sdd_iova == RTE_BAD_IOVA) {
+		DPAA2_QDMA_ERR("No IOMMU map for sdd(%p)(size=%" PRIx64 ")",
+			sdd, iova_size);
+
+		return -ENOMEM;
+	}
 
 	/* first frame list to source descriptor */
 	DPAA2_SET_FLE_ADDR(&fle[DPAA2_QDMA_SDD_FLE], sdd_iova);
@@ -259,6 +268,8 @@ fle_sdd_pre_populate(struct qdma_cntx_fle_sdd *fle_sdd,
 
 	/* Final bit: 1, for last frame list */
 	DPAA2_SET_FLE_FIN(&fle[DPAA2_QDMA_DST_FLE]);
+
+	return 0;
 }
 
 static void
@@ -286,22 +297,39 @@ sg_entry_pre_populate(struct qdma_cntx_sg *sg_cntx)
 	}
 }
 
-static void
+static int
 fle_sdd_sg_pre_populate(struct qdma_cntx_sg *sg_cntx,
 	struct qdma_virt_queue *qdma_vq)
 {
 	struct qdma_sg_entry *src_sge = sg_cntx->sg_src_entry;
 	struct qdma_sg_entry *dst_sge = sg_cntx->sg_dst_entry;
-	rte_iova_t src_sge_iova, dst_sge_iova;
+	rte_iova_t src_sge_iova, dst_sge_iova, iova_size;
 	struct dpaa2_qdma_rbp *rbp = &qdma_vq->rbp;
 
 	memset(sg_cntx, 0, sizeof(struct qdma_cntx_sg));
 
-	src_sge_iova = DPAA2_VADDR_TO_IOVA(src_sge);
-	dst_sge_iova = DPAA2_VADDR_TO_IOVA(dst_sge);
+	iova_size = RTE_DPAAX_QDMA_JOB_SUBMIT_MAX *
+		sizeof(struct qdma_sg_entry);
+
+	src_sge_iova = DPAA2_VADDR_TO_IOVA_AND_CHECK(src_sge, iova_size);
+	if (src_sge_iova == RTE_BAD_IOVA) {
+		DPAA2_QDMA_ERR("No IOMMU map for src_sge(%p)(size=%" PRIx64 ")",
+			src_sge, iova_size);
+
+		return -ENOMEM;
+	}
+
+	dst_sge_iova = DPAA2_VADDR_TO_IOVA_AND_CHECK(dst_sge, iova_size);
+	if (dst_sge_iova == RTE_BAD_IOVA) {
+		DPAA2_QDMA_ERR("No IOMMU map for dst_sge(%p)(size=%" PRIx64 ")",
+			dst_sge, iova_size);
+
+		return -ENOMEM;
+	}
 
 	sg_entry_pre_populate(sg_cntx);
-	fle_sdd_pre_populate(&sg_cntx->fle_sdd,
+
+	return fle_sdd_pre_populate(&sg_cntx->fle_sdd,
 		rbp, src_sge_iova, dst_sge_iova,
 		QBMAN_FLE_WORD4_FMT_SGE);
 }
@@ -672,7 +700,13 @@ dpaa2_qdma_copy_sg(void *dev_private,
 
 	if (qdma_vq->fle_pre_populate) {
 		if (unlikely(!fle[DPAA2_QDMA_SRC_FLE].length)) {
-			fle_sdd_sg_pre_populate(cntx_sg, qdma_vq);
+			ret = fle_sdd_sg_pre_populate(cntx_sg, qdma_vq);
+			if (ret) {
+				if (!qdma_dev->is_silent)
+					rte_mempool_put(qdma_vq->fle_pool,
+						cntx_sg);
+				return ret;
+			}
 			if (!qdma_dev->is_silent && cntx_sg && idx_addr) {
 				for (i = 0; i < nb_src; i++)
 					cntx_sg->cntx_idx[i] = idx_addr[i];
@@ -874,9 +908,15 @@ dpaa2_qdma_long_copy(struct qdma_virt_queue *qdma_vq,
 
 	if (qdma_vq->fle_pre_populate) {
 		if (unlikely(!fle[DPAA2_QDMA_SRC_FLE].length)) {
-			fle_sdd_pre_populate(fle_sdd,
+			ret = fle_sdd_pre_populate(fle_sdd,
 				&qdma_vq->rbp,
 				0, 0, QBMAN_FLE_WORD4_FMT_SBF);
+			if (ret) {
+				if (!is_silent)
+					rte_mempool_put(qdma_vq->fle_pool,
+						fle_sdd);
+				return ret;
+			}
 		}
 
 		fle_post_populate(fle, src, dst, length);
-- 
2.43.0


  parent reply	other threads:[~2026-09-15 11:34 UTC|newest]

Thread overview: 31+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-15 11:34 [PATCH v3-S1 0/5] dpaa2: bus, DMA and mempool base fixes Prashant Gupta
2026-09-15 11:34 ` [PATCH v3-S1 1/5] bus/fslmc: defer bus initialization to probe Prashant Gupta
2026-09-15 11:34 ` [PATCH v3-S1 2/5] bus/fslmc: reduce probe-time logging and MC traffic Prashant Gupta
2026-09-15 11:34 ` [PATCH v3-S1 3/5] dma/dpaa2: fix array-bounds warning in dequeue path Prashant Gupta
2026-09-15 11:34 ` Prashant Gupta [this message]
2026-09-15 11:34 ` [PATCH v3-S1 5/5] mempool/dpaa2: support ops index from primary in secondary Prashant Gupta
2026-09-15 15:24 ` [PATCH v3-S1 0/5] dpaa2: bus, DMA and mempool base fixes Stephen Hemminger
2026-09-22  9:21 ` [PATCH v4-S1 " Prashant Gupta
2026-09-22  9:21   ` [PATCH v4-S1 1/5] bus/fslmc: defer bus initialization to probe Prashant Gupta
2026-09-22  9:21   ` [PATCH v4-S1 2/5] bus/fslmc: reduce probe-time logging and MC traffic Prashant Gupta
2026-09-22  9:21   ` [PATCH v4-S1 3/5] dma/dpaa2: fix array-bounds warning in dequeue path Prashant Gupta
2026-09-22  9:21   ` [PATCH v4-S1 4/5] dma/dpaa2: validate IOVA in pre-populate helpers Prashant Gupta
2026-09-22  9:21   ` [PATCH v4-S1 5/5] mempool/dpaa2: support ops index from primary in secondary Prashant Gupta
2026-09-22 13:59   ` [PATCH v4-S1 0/5] dpaa2: bus, DMA and mempool base fixes Stephen Hemminger
2026-09-29 14:21   ` [PATCH v5-S1 " Prashant Gupta
2026-09-29 14:21     ` [PATCH v5-S1 1/5] bus/fslmc: defer bus initialization to probe Prashant Gupta
2026-09-29 14:21     ` [PATCH v5-S1 2/5] bus/fslmc: reduce probe-time logging and skip ignored devices Prashant Gupta
2026-09-29 14:21     ` [PATCH v5-S1 3/5] dma/dpaa2: fix array-bounds warning and SG FD double-put Prashant Gupta
2026-09-29 14:21     ` [PATCH v5-S1 4/5] dma/dpaa2: validate FLE pool IOVA mapping at vchan setup Prashant Gupta
2026-09-29 14:21     ` [PATCH v5-S1 5/5] mempool/dpaa2: look up ops index locally in secondary Prashant Gupta
2026-09-29 15:45     ` [PATCH v5-S1 0/5] dpaa2: bus, DMA and mempool base fixes Stephen Hemminger
2026-10-06 14:57       ` [EXT] " Prashant Gupta
2026-10-06 15:07     ` [PATCH v6-S1 0/6] " Prashant Gupta
2026-10-06 15:07       ` [PATCH v6-S1 1/6] bus/fslmc: defer bus initialization to probe Prashant Gupta
2026-10-06 15:07       ` [PATCH v6-S1 2/6] bus/fslmc: reduce probe logging and skip ignored devices Prashant Gupta
2026-10-06 15:07       ` [PATCH v6-S1 3/6] dma/dpaa2: use memcpy to fill completion index ring Prashant Gupta
2026-10-06 15:07       ` [PATCH v6-S1 4/6] dma/dpaa2: release SG FLE on completion ring overflow Prashant Gupta
2026-10-06 15:07       ` [PATCH v6-S1 5/6] dma/dpaa2: validate FLE pool IOVA mapping at vchan setup Prashant Gupta
2026-10-08 22:41         ` Stephen Hemminger
2026-10-06 15:07       ` [PATCH v6-S1 6/6] mempool/dpaa2: look up ops index locally in secondary Prashant Gupta
2026-10-07 15:51       ` [PATCH v6-S1 0/6] dpaa2: bus, DMA and mempool base fixes Stephen Hemminger

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260915113422.4166287-5-prashant.gupta_3@nxp.com \
    --to=prashant.gupta_3@nxp.com \
    --cc=dev@dpdk.org \
    --cc=g.singh@nxp.com \
    --cc=stephen@networkplumber.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox