Linux PCI subsystem development
 help / color / mirror / Atom feed
* [PATCH v6 00/10] dmaengine: miscellaneous fixes for ioat, switchtec_dma and plx_dma
@ 2026-09-02  6:21 Logan Gunthorpe
  2026-09-02  6:21 ` [PATCH v6 01/10] dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc() Logan Gunthorpe
                   ` (9 more replies)
  0 siblings, 10 replies; 21+ messages in thread
From: Logan Gunthorpe @ 2026-09-02  6:21 UTC (permalink / raw)
  To: linux-kernel, linux-pci, dmaengine, Vinod Koul
  Cc: Frank Li, Kelvin Cao, Thomas Weißschuh, Dave Jiang,
	George Ge, Jaeyoung Chung, Logan Gunthorpe

This is the latest series of fixes that has been rebased onto v7.3-rc1.

After getting more Sashiko feedback on the two problematic patches I
have to eat crow and appologize. Frank was correct about them and I
was a bit too stubborn. Sorry about that. I have dropped those two
patches in this series so hopefully it can go in quickly.

Please note: I'm going to be on vacation starting Friday the 4th until
the 15th so if there is any feedback in that window I'll respond when
I get back.

Thanks,

Logan

Changes since v5:
 * Dropped the two patches that skipped freeing the descriptor rings
   when the channel could not be confirmed halted ("always clear DMA
   base registers on chan_stop()" and "halt channel on
   alloc_chan_resources error"), per Frank's recommendation. All
   remaining patches are unchanged.

Changes since v4:
 * Rebased onto v7.3-rc1.
 * Added paragraph to patches 3 and 4 to make clear that they are
   leaking memory in favour of preventing theoretically buggy hardware
   from trashing re-used memory. I think this is the best thing to do.

Changes since v3:
 * Add a patch (3) making switchtec_dma_chan_stop() clear the DMA base
   registers even when halt_channel() times out, and return the halt
   result. switchtec_dma_free_chan_resources() (patch 3) and the
   alloc_chan_resources() error path (patch 4) now skip freeing the
   descriptor rings when the halt wasn't confirmed. This will leak some
   memory on tear down but that avoids broken hardware from scribbling
   on memory that may have been freed and reallocated. (Per Sashiko)
 * Remove each channel's list entry in switchtec_dma_chans_free()
   (patch 5), immediately before the memory is freed, instead of in
   switchtec_dma_chans_disable() (patch 8), which now only frees the
   channel status IRQ. (Per Sashiko)
 * Collected Reviewed-by tags from Frank and applied one of his
   commit message suggestions.

Changes since v2:

 * Fixed a race when unlisting the channels in the error path.
   The interrupt needed to be disabled before hand. (Per Sashiko)
 * Picked up Acked-by from Dave Jiang on the two ioat patches.

Changes since v1:

 * Added a fix for switchtec_dma_alloc_chan_resources()'s error path
   calling disable_channel() instead of properly halting the channel
   before freeing the descriptor rings. (Per Sashiko)
 * Added a fix for switchtec-dma channel structs being freed without
   being removed from dma_dev->channels on a registration failure,
   while the channel status IRQ is still live. (Per Sashiko)
 * Added a fix for switchtec_dma_remove() using swdma_dev after it may
   already have been freed by dma_async_device_unregister(). (Per
   Sashiko)
 * Added a fix for chan_status_irq being freed with the wrong API, and
   a valid vector index of 0 being incorrectly treated as unset.
   (Per Sashiko)
 * Made switchtec_dma_chans_release() void, since nothing checked its
   return value. (Noticed while reviewing the code for these changes).

Logan Gunthorpe (10):
  dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc()
  dmaengine: switchtec-dma: fix resource leak in alloc_chan_resources
  dmaengine: switchtec-dma: fix channel leak on registration failure
  dmaengine: switchtec-dma: make switchtec_dma_chans_release() void
  dmaengine: switchtec-dma: fix chan_status_irq cleanup on create()
    error
  dmaengine: switchtec-dma: disable channels before freeing on
    registration failure
  dmaengine: switchtec-dma: fix use-after-free of swdma_dev in remove()
  dmaengine: ioat: disable relaxed ordering before registering the
    device
  dmaengine: ioat: use sysfs_emit() in per-channel sysfs show()
  dmaengine: plx_dma: fix NULL pointer deref in plx_dma_isr()

 drivers/dma/ioat/init.c     | 18 ++++-----
 drivers/dma/ioat/sysfs.c    | 22 +++++-----
 drivers/dma/plx_dma.c       | 10 ++---
 drivers/dma/switchtec_dma.c | 80 +++++++++++++++++++++++++++----------
 4 files changed, 84 insertions(+), 46 deletions(-)


base-commit: cee9395acd8043be0644b25c34bfa86623f2b935
--
2.47.3

^ permalink raw reply	[flat|nested] 21+ messages in thread

end of thread, other threads:[~2026-09-02  6:40 UTC | newest]

Thread overview: 21+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02  6:21 [PATCH v6 00/10] dmaengine: miscellaneous fixes for ioat, switchtec_dma and plx_dma Logan Gunthorpe
2026-09-02  6:21 ` [PATCH v6 01/10] dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc() Logan Gunthorpe
2026-09-02  6:36   ` sashiko-bot
2026-09-02  6:21 ` [PATCH v6 02/10] dmaengine: switchtec-dma: fix resource leak in alloc_chan_resources Logan Gunthorpe
2026-09-02  6:36   ` sashiko-bot
2026-09-02  6:21 ` [PATCH v6 03/10] dmaengine: switchtec-dma: fix channel leak on registration failure Logan Gunthorpe
2026-09-02  6:39   ` sashiko-bot
2026-09-02  6:21 ` [PATCH v6 04/10] dmaengine: switchtec-dma: make switchtec_dma_chans_release() void Logan Gunthorpe
2026-09-02  6:28   ` sashiko-bot
2026-09-02  6:21 ` [PATCH v6 05/10] dmaengine: switchtec-dma: fix chan_status_irq cleanup on create() error Logan Gunthorpe
2026-09-02  6:34   ` sashiko-bot
2026-09-02  6:21 ` [PATCH v6 06/10] dmaengine: switchtec-dma: disable channels before freeing on registration failure Logan Gunthorpe
2026-09-02  6:38   ` sashiko-bot
2026-09-02  6:21 ` [PATCH v6 07/10] dmaengine: switchtec-dma: fix use-after-free of swdma_dev in remove() Logan Gunthorpe
2026-09-02  6:37   ` sashiko-bot
2026-09-02  6:21 ` [PATCH v6 08/10] dmaengine: ioat: disable relaxed ordering before registering the device Logan Gunthorpe
2026-09-02  6:33   ` sashiko-bot
2026-09-02  6:21 ` [PATCH v6 09/10] dmaengine: ioat: use sysfs_emit() in per-channel sysfs show() Logan Gunthorpe
2026-09-02  6:28   ` sashiko-bot
2026-09-02  6:21 ` [PATCH v6 10/10] dmaengine: plx_dma: fix NULL pointer deref in plx_dma_isr() Logan Gunthorpe
2026-09-02  6:40   ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox