From: sashiko-bot@kernel.org
To: Frank.Li@oss.nxp.com
Cc: wsa+renesas@sang-engineering.com, imx@lists.linux.dev,
Frank.Li@kernel.org
Subject: Re: [PATCH v3 1/1] mmc: use dmaengine_get_dma_device() instead of chan->device->dev
Date: Mon, 21 Sep 2026 14:54:41 +0000 [thread overview]
Message-ID: <20260921145441.E47831F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260921144426.1083196-1-Frank.Li@oss.nxp.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] mmc: mxs-mmc: mismatched DMA device on dmaengine_prep_slave_sg() error path
- [High] mmc: mxcmmc: NULL pointer dereference in mxcmci_setup_data() on PIO fallback
--
commit 76329da80aaedf4e7a72d175c67b41a9f5e8706a
Author: Frank Li <Frank.Li@nxp.com>
mmc: use dmaengine_get_dma_device() instead of chan->device->dev
This patch replaces direct dma_chan::device::dev access with the proper
dmaengine_get_dma_device() for the consumer API. It ensures the correct
device is used for DMA mapping, preparing for making the DMA engine
provider data structures private.
> diff --git a/drivers/mmc/host/mxcmmc.c b/drivers/mmc/host/mxcmmc.c
> --- a/drivers/mmc/host/mxcmmc.c
> +++ b/drivers/mmc/host/mxcmmc.c
> @@ -290,6 +290,7 @@ static int mxcmci_setup_data(struct mxcmci_host *host, struct mmc_data *data)
> unsigned int datasize = nob * blksz;
> struct scatterlist *sg;
> enum dma_transfer_direction slave_dirn;
> + struct device *dma_dev = dmaengine_get_dma_device(host->dma);
[Severity: High]
Does this code dereference a NULL pointer when host->dma is NULL?
If the driver falls back to PIO mode during probe because requesting the DMA
channel failed, host->dma is set to NULL. This variable initialization appears
to evaluate dmaengine_get_dma_device(host->dma) before the check for PIO mode
(!mxcmci_use_dma(host)) can execute, which could cause a panic.
> int i, nents;
>
> host->data = data;
[ ... ]
> diff --git a/drivers/mmc/host/mxs-mmc.c b/drivers/mmc/host/mxs-mmc.c
> --- a/drivers/mmc/host/mxs-mmc.c
> +++ b/drivers/mmc/host/mxs-mmc.c
> @@ -221,7 +221,7 @@ static struct dma_async_tx_descriptor *mxs_mmc_prep_dma(
>
> if (data) {
> /* data */
> - dma_map_sg(mmc_dev(host->mmc), data->sg,
> + dma_map_sg(dmaengine_get_dma_device(ssp->dmach), data->sg,
> data->sg_len, ssp->dma_dir);
> sgl = data->sg;
> sg_len = data->sg_len;
[Severity: High]
Will this lead to a mismatched DMA device during the error path in
mxs_mmc_prep_dma()?
The error path in mxs_mmc_prep_dma() still uses the old mmc_dev(host->mmc)
call to unmap the scatterlist:
if (desc) {
...
} else {
if (data)
dma_unmap_sg(mmc_dev(host->mmc), data->sg,
data->sg_len, ssp->dma_dir);
}
Can this leak the IOMMU mapping on the correct device and erroneously unmap
mappings on the wrong device if dmaengine_prep_slave_sg() fails?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260921144426.1083196-1-Frank.Li@oss.nxp.com?part=1
next prev parent reply other threads:[~2026-09-21 14:54 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-21 14:44 [PATCH v3 1/1] mmc: use dmaengine_get_dma_device() instead of chan->device->dev Frank.Li
2026-09-21 14:54 ` sashiko-bot [this message]
2026-09-21 15:02 ` Wolfram Sang
2026-09-21 16:08 ` Frank Li
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260921145441.E47831F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=Frank.Li@oss.nxp.com \
--cc=imx@lists.linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
--cc=wsa+renesas@sang-engineering.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox