From: sashiko-bot@kernel.org
To: "Devendra K Verma" <devverma@amd.com>
Cc: vkoul@kernel.org, dmaengine@vger.kernel.org, Frank.Li@kernel.org,
linux-pci@vger.kernel.org
Subject: Re: [PATCH v1 3/3] dmaengine: dw-edma: Add changes to support Channel Separation
Date: Wed, 22 Jul 2026 11:32:16 +0000 [thread overview]
Message-ID: <20260722113216.C1E351F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260722111640.1146212-4-devverma@amd.com>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
New issues:
- [High] The newly introduced `ch_sep_sz` field in `struct dw_edma_chip` is uninitialized (defaults to 0) for platform drivers outside of `dw-edma-pcie` that use HDMA natively, causing all channel register accesses to map to identical offset 0.
- [High] The driver trusts the device-provided VSEC configuration to calculate DMA channel register offsets but never verifies if these offsets remain within the mapped PCI BAR region.
Pre-existing issues:
- [High] Pre-existing double free of IRQ vectors in `dw_edma_pcie_remove()` due to devres interference.
--
--- Patch [3]: [PATCH v1 3/3] dmaengine: dw-edma: Add changes to support Channel Separation ---
commit 2ad7c860cd4c4a1bef961b814db689f718e1407c
Author: Devendra K Verma <devverma@amd.com>
dmaengine: dw-edma: Add changes to support Channel Separation
This patch modifies the dw-edma driver to support configurable channel
separation sizes. It updates the register offset calculations to use a
dynamic size provided by the hardware IP instead of assuming a default
256-byte separation.
> diff --git a/drivers/dma/dw-edma/dw-edma-pcie.c b/drivers/dma/dw-edma/dw-edma-pcie.c
> index 6295d01ba2f71..ca2a4be2f3a50 100644
> --- a/drivers/dma/dw-edma/dw-edma-pcie.c
> +++ b/drivers/dma/dw-edma/dw-edma-pcie.c
[ ... ]
> @@ -443,6 +446,7 @@ static int dw_edma_pcie_probe(struct pci_dev *pdev,
> chip->nr_irqs = nr_irqs;
> chip->ops = &dw_edma_pcie_plat_ops;
> chip->cfg_non_ll = non_ll;
> + chip->ch_sep_sz = vsec_data->ch_sep_sz;
>
> chip->ll_wr_cnt = vsec_data->wr_ch_cnt;
> chip->ll_rd_cnt = vsec_data->rd_ch_cnt;
[Severity: High]
This is a pre-existing issue, but does dw_edma_pcie_remove() explicitly call
pci_free_irq_vectors(pdev)?
Since pcim_enable_device(pdev) is called during dw_edma_pcie_probe(), it
automatically manages subsequent IRQ vectors via devres. When the driver is
unbound, the devres cleanup routine will attempt to free the already-freed
vectors, which could cause a double-free kernel panic on the device unbind
or module unload path.
> diff --git a/drivers/dma/dw-edma/dw-hdma-v0-core.c b/drivers/dma/dw-edma/dw-hdma-v0-core.c
> index 632abb8b481cf..3f27a93c4d8c8 100644
> --- a/drivers/dma/dw-edma/dw-hdma-v0-core.c
> +++ b/drivers/dma/dw-edma/dw-hdma-v0-core.c
[ ... ]
> @@ -23,18 +23,23 @@ enum dw_hdma_control {
> DW_HDMA_V0_LLE = BIT(9),
> };
>
> -static inline struct dw_hdma_v0_regs __iomem *__dw_regs(struct dw_edma *dw)
> -{
> - return dw->chip->reg_base;
> -}
> -
> static inline struct dw_hdma_v0_ch_regs __iomem *
> __dw_ch_regs(struct dw_edma *dw, enum dw_edma_dir dir, u16 ch)
> {
> - if (dir == EDMA_DIR_WRITE)
> - return &(__dw_regs(dw)->ch[ch].wr);
> - else
> - return &(__dw_regs(dw)->ch[ch].rd);
> + u32 ch_base;
> +
> + /*
> + * For Write, the channel register index starts at
> + * wr_base(ch_idx) = (2 * ch_idx) * ch_sep_sz
> + *
> + * For Read channel,
> + * rd_base(ch_idx) = (2 * ch_idx + 1) * ch_sep_sz
> + */
> + ch_base = 2 * ch;
> + if (dir == EDMA_DIR_READ)
> + ch_base += 1;
> +
> + return dw->chip->reg_base + (ch_base * dw->chip->ch_sep_sz);
[Severity: High]
Does this code verify that the computed channel register offset remains within
the mapped PCI BAR region?
If a malicious or misconfigured PCIe endpoint provides a large channel
separation size, could this calculation result in out-of-bounds MMIO accesses?
[Severity: High]
If platform drivers outside of dw-edma-pcie use HDMA natively and allocate
struct dw_edma_chip via devm_kzalloc without explicitly initializing
ch_sep_sz, does ch_sep_sz default to 0?
Could this cause all channel register accesses to map to offset 0, leading to
data corruption by incorrectly targeting Write Channel 0's registers?
> }
>
> diff --git a/drivers/dma/dw-edma/dw-hdma-v0-debugfs.c b/drivers/dma/dw-edma/dw-hdma-v0-debugfs.c
> index dcdc57fe976c1..33128685bbd90 100644
> --- a/drivers/dma/dw-edma/dw-hdma-v0-debugfs.c
> +++ b/drivers/dma/dw-edma/dw-hdma-v0-debugfs.c
[ ... ]
> @@ -13,22 +13,17 @@
> #include "dw-hdma-v0-regs.h"
> #include "dw-edma-core.h"
>
> -#define REGS_ADDR(dw, name) \
> - ({ \
> - struct dw_hdma_v0_regs __iomem *__regs = (dw)->chip->reg_base; \
> - \
> - (void __iomem *)&__regs->name; \
> - })
> -
> #define REGS_CH_ADDR(dw, name, _dir, _ch) \
> ({ \
> - struct dw_hdma_v0_ch_regs __iomem *__ch_regs; \
> + struct dw_hdma_v0_ch_regs __iomem *__ch_regs; \
> + off_t __off = (dw)->chip->ch_sep_sz; \
> \
> - if (_dir == EDMA_DIR_READ) \
> - __ch_regs = REGS_ADDR(dw, ch[_ch].rd); \
> + if ((_dir) == EDMA_DIR_READ) \
> + __off *= (2 * (_ch) + 1); \
> else \
> - __ch_regs = REGS_ADDR(dw, ch[_ch].wr); \
> + __off *= (2 * (_ch)); \
> \
> + __ch_regs = ((dw)->chip->reg_base + __off); \
[Severity: High]
Could this also lead to out-of-bounds MMIO accesses during debugfs reads?
If the untrusted channel separation size is used to compute the offset, and
userspace triggers a debugfs read, it seems this could be exploited if not
validated against the BAR size.
> (void __iomem *)&__ch_regs->name; \
> })
>
> diff --git a/include/linux/dma/edma.h b/include/linux/dma/edma.h
> index 1fafd5b0e3153..a6c5728f03d38 100644
> --- a/include/linux/dma/edma.h
> +++ b/include/linux/dma/edma.h
> @@ -104,6 +104,7 @@ struct dw_edma_chip {
>
> struct dw_edma *dw;
> bool cfg_non_ll;
> + u32 ch_sep_sz;
[Severity: High]
Does this new field need a fallback default for non-PCIe drivers?
Other core drivers that instantiate struct dw_edma_chip for HDMA might not
explicitly set this, leaving it uninitialized.
> };
>
> /* Export to the platform drivers */
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260722111640.1146212-1-devverma@amd.com?part=3
next prev parent reply other threads:[~2026-07-22 11:32 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-22 11:16 [PATCH v1 0/3] CPM6 Channel Separation Support Devendra K Verma
2026-07-22 11:16 ` [PATCH v1 1/3] dmaengine: dw-edma: Make Xilinx Macros Dev Name Agnostic Devendra K Verma
2026-07-22 11:24 ` sashiko-bot
2026-07-22 14:51 ` Frank Li
2026-07-22 11:16 ` [PATCH v1 2/3] dmaengine: dw-edma: Enable Chan Separation via VSEC Devendra K Verma
2026-07-22 11:33 ` sashiko-bot
2026-07-22 15:00 ` Frank Li
2026-07-22 11:16 ` [PATCH v1 3/3] dmaengine: dw-edma: Add changes to support Channel Separation Devendra K Verma
2026-07-22 11:32 ` sashiko-bot [this message]
2026-07-22 15:22 ` Frank Li
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260722113216.C1E351F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=devverma@amd.com \
--cc=dmaengine@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox