Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Harendra Gautam" <harendra.gautam@oss.qualcomm.com>
Cc: devicetree@vger.kernel.org, conor+dt@kernel.org, robh@kernel.org
Subject: Re: [PATCH v8 03/10] ASoC: qcom: Add QAIF hardware register map
Date: Mon, 28 Sep 2026 13:03:48 +0000	[thread overview]
Message-ID: <20260928130348.A9F8B1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260928-b4-qaif-shikra-audio-v8-3-ac618057fe85@oss.qualcomm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] qaif: hardware register offset typo in EE map definitions
--

commit 87884b7c293c2733efcb7eb006da31f9ab34c5a8
Author: Harendra Gautam <harendra.gautam@oss.qualcomm.com>

ASoC: qcom: Add QAIF hardware register map

Add qaif-reg.h to define the MMIO register offsets for the Qualcomm Audio
Interface (QAIF) hardware block. The QAIF driver needs a common register map
to program the core registers, audio interfaces, and other components.

> diff --git a/sound/soc/qcom/qaif-reg.h b/sound/soc/qcom/qaif-reg.h
> new file mode 100644
> index 0000000000000..84a9c0285289e
> --- /dev/null
> +++ b/sound/soc/qcom/qaif-reg.h
> @@ -82,21 +82,21 @@

> [ ... ]

> +/*
> + * EE (Execution Engine) assignment and map registers.
> + *
> + * The EE offset (v->ee) is an address/index offset relative to the
> + * platform-defined QAIF/EE base and lets the hardware route the AIF
> + * operation to the correct EE context. It is hardware/platform-specific and
> + * must match the mapping defined for the selected QAIF AIF/lane in the
> + * hardware programming guide. It is not a runtime data offset and must not
> + * be changed based on the stream configuration.
> + */
> +#define QAIF_EE_RDDMA_ASSIGNMENT_REG(v)			(0x19148 + (0x1000 * ((v)->ee)))
> +#define QAIF_EE_WRDMA_ASSIGNMENT_REG(v)			(0x19150 + (0x1000 * ((v)->ee)))
> +#define QAIF_EE_INTF_ASSIGNMENT_REG(v)			(0x19158 + (0x1000 * ((v)->ee)))
> +#define QAIF_EE_CODEC_RDDMA_ASSIGN_REG(v)		(0x19308 + (0x1000 * ((v)->ee)))
> +#define QAIF_EE_CODEC_WRDMA_ASSIGN_REG(v)		(0x19318 + (0x1000 * ((v)->ee)))
> +#define QAIF_EE_RDDMA_MAP_REG(v)			(0x1920 + (0x1000 * ((v)->ee)))
> +#define QAIF_EE_WRDMA_MAP_REG(v)			(0x1940 + (0x1000 * ((v)->ee)))
> +#define QAIF_EE_INTF_MAP_REG(v)				(0x1960 + (0x1000 * ((v)->ee)))
> +#define QAIF_EE_CODEC_RDDMA_MAP_REG(v)			(0x1980 + (0x1000 * ((v)->ee)))
> +#define QAIF_EE_CODEC_WRDMA_MAP_REG(v)			(0x1A00 + (0x1000 * ((v)->ee)))

[Severity: High]
Are there missing hex digits in these register offsets?

These QAIF_EE_*_MAP_REG definitions appear to contain a typo (e.g. 0x1920
instead of 0x19020). When written to by regmap during
qaif_map_ee_resource(), this could cause writes to target unmapped MMIO
memory or clobber unrelated QAIF_AUD_INTF hardware registers when
v->ee >= 1.

Could this lead to a bus fault or silent hardware malfunction when
snd_pcm_hw_params() is called by an unprivileged user?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260928-b4-qaif-shikra-audio-v8-0-ac618057fe85@oss.qualcomm.com?part=3

  reply	other threads:[~2026-09-28 13:03 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 12:52 [PATCH v8 00/10] ASoC: qcom: Add QAIF driver for Shikra audio platform Harendra Gautam
2026-09-28 12:52 ` [PATCH v8 01/10] ASoC: dt-bindings: qcom,shikra-qaif-cpu: Add binding Harendra Gautam
2026-09-28 13:01   ` sashiko-bot
2026-10-06 14:16   ` Rob Herring
2026-09-28 12:52 ` [PATCH v8 02/10] ASoC: qcom: Add QAIF shared data structures and variant interface Harendra Gautam
2026-09-28 12:52 ` [PATCH v8 03/10] ASoC: qcom: Add QAIF hardware register map Harendra Gautam
2026-09-28 13:03   ` sashiko-bot [this message]
2026-09-28 12:52 ` [PATCH v8 04/10] ASoC: qcom: Add QAIF CPU DAI ops, regmap, DT parsing and platform init Harendra Gautam
2026-09-28 13:04   ` sashiko-bot
2026-09-28 12:52 ` [PATCH v8 05/10] ASoC: soc-core: Add snd_soc_of_xlate_dai_name() generic helper Harendra Gautam
2026-09-28 12:52 ` [PATCH v8 06/10] ASoC: qcom: Switch lpass-cpu and qaif-cpu to snd_soc_of_xlate_dai_name() Harendra Gautam
2026-09-28 12:52 ` [PATCH v8 07/10] ASoC: qcom: Add QAIF PCM operations Harendra Gautam
2026-09-28 13:07   ` sashiko-bot
2026-09-28 12:52 ` [PATCH v8 08/10] ASoC: qcom: Add QAIF IRQ handling and platform register Harendra Gautam
2026-09-28 13:04   ` sashiko-bot
2026-09-29 11:36   ` Ajay Kumar Nandam
2026-09-30  5:28     ` Harendra Gautam
2026-09-28 12:52 ` [PATCH v8 09/10] ASoC: qcom: Add Shikra QAIF support Harendra Gautam
2026-09-28 12:53 ` [PATCH v8 10/10] MAINTAINERS: Add Qualcomm QAIF driver entry Harendra Gautam

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928130348.A9F8B1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=harendra.gautam@oss.qualcomm.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox