Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Harendra Gautam" <harendra.gautam@oss.qualcomm.com>
Cc: robh@kernel.org, conor+dt@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH v7 08/10] ASoC: qcom: Add QAIF IRQ handling and platform register
Date: Wed, 23 Sep 2026 07:04:27 +0000	[thread overview]
Message-ID: <20260923070428.5C0771F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260923-b4-qaif-shikra-audio-v7-8-d5b6f056568e@oss.qualcomm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] Uninitialized memory access when reading IOMMU Stream ID
--

commit 033356d64f07f9a066675a08dfb513468fd441a1
Author: Harendra Gautam <harendra.gautam@oss.qualcomm.com>

ASoC: qcom: Add QAIF IRQ handling and platform register

This commit finishes the QAIF PCM platform support so streams can be
registered, started, stopped, and serviced by DMA interrupts. It registers
the ASoC component, requests the QAIF interrupt, and adds trigger handling
to enable or disable DMA and its interrupt sources.

> diff --git a/sound/soc/qcom/qaif-platform.c b/sound/soc/qcom/qaif-platform.c
> --- a/sound/soc/qcom/qaif-platform.c
> +++ b/sound/soc/qcom/qaif-platform.c

[ ... ]

> +int asoc_qcom_qaif_platform_register(struct platform_device *pdev)
> +{
> +	struct qaif_drv_data *drvdata = platform_get_drvdata(pdev);
> +	struct of_phandle_args iommu_spec;
> +	u32 sid;
> +	int ret;
> +
> +	if (!drvdata->variant->alloc_stream_dma_idx ||
> +	    !drvdata->variant->free_stream_dma_idx)
> +		return dev_err_probe(&pdev->dev, -EINVAL,
> +				     "Variant missing mandatory callbacks\n");
> +
> +	ret = of_parse_phandle_with_args(pdev->dev.of_node,
> +					 "iommus", "#iommu-cells", 0,
> +					 &iommu_spec);
> +	if (ret)
> +		return dev_err_probe(&pdev->dev, ret,
> +				     "failed to parse iommus property\n");
> +	sid = iommu_spec.args[0];

[Severity: Medium]
Could this read uninitialized stack memory if the device tree specifies an
IOMMU node with a zero argument count?

If of_parse_phandle_with_args() succeeds but finds zero arguments, it will
set iommu_spec.args_count to 0 without writing to the iommu_spec.args array.
Reading iommu_spec.args[0] unconditionally would then configure the hardware
with a garbage stream ID from the uninitialized stack, potentially causing
IOMMU context faults and breaking audio DMA.

Does this code need to validate that iommu_spec.args_count is greater than 0
before accessing the arguments array?

> +	of_node_put(iommu_spec.np);
> +	drvdata->smmu_csid_bits = sid & QAIF_CSID_MASK;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260923-b4-qaif-shikra-audio-v7-0-d5b6f056568e@oss.qualcomm.com?part=8

  reply	other threads:[~2026-09-23  7:04 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23  6:48 [PATCH v7 00/10] ASoC: qcom: Add QAIF driver for Shikra audio platform Harendra Gautam
2026-09-23  6:48 ` [PATCH v7 01/10] ASoC: dt-bindings: qcom,shikra-qaif-cpu: Add binding Harendra Gautam
2026-09-23  6:59   ` sashiko-bot
2026-09-23  6:48 ` [PATCH v7 02/10] ASoC: qcom: Add QAIF shared data structures and variant interface Harendra Gautam
2026-09-23  6:59   ` sashiko-bot
2026-09-23  9:29   ` Mark Brown
2026-09-28  9:11     ` Harendra Gautam
2026-09-23  6:48 ` [PATCH v7 03/10] ASoC: qcom: Add QAIF hardware register map Harendra Gautam
2026-09-23  7:00   ` sashiko-bot
2026-09-23  6:48 ` [PATCH v7 04/10] ASoC: qcom: Add QAIF CPU DAI ops, regmap, DT parsing and platform init Harendra Gautam
2026-09-23  7:02   ` sashiko-bot
2026-09-23  9:41   ` Mark Brown
2026-09-28  9:38     ` Harendra Gautam
2026-09-28 12:17       ` Harendra Gautam
2026-09-23  6:48 ` [PATCH v7 05/10] ASoC: soc-core: Add snd_soc_of_xlate_dai_name() generic helper Harendra Gautam
2026-09-23  7:00   ` sashiko-bot
2026-09-23  6:48 ` [PATCH v7 06/10] ASoC: qcom: Switch lpass-cpu and qaif-cpu to snd_soc_of_xlate_dai_name() Harendra Gautam
2026-09-24 10:32   ` Ajay Kumar Nandam
2026-09-23  6:48 ` [PATCH v7 07/10] ASoC: qcom: Add QAIF PCM operations Harendra Gautam
2026-09-23  7:03   ` sashiko-bot
2026-09-23  9:45   ` Mark Brown
2026-09-28  9:06     ` Harendra Gautam
2026-09-23  6:48 ` [PATCH v7 08/10] ASoC: qcom: Add QAIF IRQ handling and platform register Harendra Gautam
2026-09-23  7:04   ` sashiko-bot [this message]
2026-09-23  6:48 ` [PATCH v7 09/10] ASoC: qcom: Add Shikra QAIF support Harendra Gautam
2026-09-23  7:09   ` sashiko-bot
2026-09-23  6:48 ` [PATCH v7 10/10] MAINTAINERS: Add Qualcomm QAIF driver entry Harendra Gautam
2026-09-23  9:27 ` [PATCH v7 00/10] ASoC: qcom: Add QAIF driver for Shikra audio platform Mark Brown
2026-09-28  5:44   ` Harendra Gautam

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923070428.5C0771F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=harendra.gautam@oss.qualcomm.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox