From nobody Sat Jul 25 04:54:06 2026 Received: from ale.deltatee.com (ale.deltatee.com [204.191.154.188]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8490B3D9680; Fri, 17 Jul 2026 22:10:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=204.191.154.188 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784326219; cv=none; b=dB1fMiTcaXvHLtnq7bd/xpGY2yjtgCwu6LI/rNG4wks8tbylqAfKcQKrv9UM+mWwwGgz+arUBu8obpUtSuYSJx2ndxvOTsbMturQyqk6PuEfUezkDk2Yd6yfqhMo6PHTqlDzpLZ0B3DLJ+e3+VD74kVeO9QkKYFRG4E0/4vjtFM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784326219; c=relaxed/simple; bh=/bHx1KqUQ5FZegJF2+0lqfCDtUh0LCnmdvxhqwVny8s=; h=From:To:Cc:Date:Message-ID:In-Reply-To:References:MIME-Version: Subject; b=maclhUBDpohMWczsai/mXIMsOsvvigiewWP+bG6QXAkcEpWQct8WDm424mkuG6QFNre3mLj8D+jOP9i8sizNnk4qfE38Y7v2hBiMaVSs8qrOWXhc4r79PGh40nYQdk4VKh4F7tSsCxrlR2Jd+iiKmgRSTZ9Cag8UxuBi06ewqX8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=deltatee.com; spf=pass smtp.mailfrom=deltatee.com; dkim=pass (2048-bit key) header.d=deltatee.com header.i=@deltatee.com header.b=flMyrU2C; arc=none smtp.client-ip=204.191.154.188 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=deltatee.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=deltatee.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=deltatee.com header.i=@deltatee.com header.b="flMyrU2C" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=deltatee.com; s=20200525; h=Subject:MIME-Version:References:In-Reply-To: Message-ID:Date:Cc:To:From:content-disposition; bh=1Sc00LLbJ3B9EzEYCBr4PK/7bI/kLf3dvLcEogNQeHU=; b=flMyrU2C4Uf59Oq+PlTez+YnOV fWqAhzSAWWrdhVO/DOgSsH0jVZV3/SdO9kBWHpGDBcZP2qxXqF/GfIyH48TRilP1ld5gln/KLscM1 tcXfDFL9Q9nNtYTDJL34JE+3YNJtqWqwwgxaDBRylQGsuYwqj6TWZq8cY0RV4UYWe9Z49yJIIUPrD vTYsMpHaVf9CvrwKnYuIv5FWMK/PGQlJg2wU74dRmPX2eTWSgcO3s+HOigvAX8l/1g9sRlGlPww/G OQi+T4V01eJ8aW9NgJtrhWQaJkMVIeL5AbA5sx+h0Lt4e0erQk4qqbXTXnT9Eujprr3N4EE728AEz 27sO1L1g==; Received: from cgy1-donard.priv.deltatee.com ([172.16.1.31]) by ale.deltatee.com with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1wkqkz-00000008wEm-3fqA; Fri, 17 Jul 2026 16:10:10 -0600 Received: from gunthorp by cgy1-donard.priv.deltatee.com with local (Exim 4.98.2) (envelope-from ) id 1wkqku-00000001W1r-2nGQ; Fri, 17 Jul 2026 16:10:04 -0600 From: Logan Gunthorpe To: linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, dmaengine@vger.kernel.org, Vinod Koul Cc: Frank Li , Kelvin Cao , =?UTF-8?q?Thomas=20Wei=C3=9Fschuh?= , Dave Jiang , George Ge , Jaeyoung Chung , Logan Gunthorpe Date: Fri, 17 Jul 2026 16:09:56 -0600 Message-ID: <20260717221001.361421-2-logang@deltatee.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260717221001.361421-1-logang@deltatee.com> References: <20260717221001.361421-1-logang@deltatee.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-SA-Exim-Connect-IP: 172.16.1.31 X-SA-Exim-Rcpt-To: linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, dmaengine@vger.kernel.org, vkoul@kernel.org, Frank.li@nxp.com, linux@weissschuh.net, dave.jiang@intel.com, kelvin.cao@microchip.com, george.ge@microchip.com, jjy600901@snu.ac.kr, logang@deltatee.com X-SA-Exim-Mail-From: gunthorp@deltatee.com X-Spam-Level: Subject: [PATCH v1 1/6] dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc() X-SA-Exim-Version: 4.2.1 (built Sun, 23 Feb 2025 07:57:16 +0000) X-SA-Exim-Scanned: Yes (on ale.deltatee.com) Content-Type: text/plain; charset="utf-8" switchtec_dma_free_desc() frees swdma_chan->hw_sq, hw_cq, and every desc_ring[] entry without clearing the pointers afterward. If switchtec_dma_alloc_chan_resources() fails partway through and calls it during unwind, then a later retry of alloc_chan_resources() fails in switchtec_dma_alloc_desc() before reallocating one of those pointers, its own failure path calls switchtec_dma_free_desc() again and frees the same, already-freed pointers a second time. NULL out each pointer as it's freed so a subsequent call is a no-op for anything already released. Fixes: 30eba9df76ad ("dmaengine: switchtec-dma: Implement hardware initiali= zation and cleanup") Signed-off-by: Logan Gunthorpe --- drivers/dma/switchtec_dma.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/drivers/dma/switchtec_dma.c b/drivers/dma/switchtec_dma.c index 3ef928640615..a4a7d66d042d 100644 --- a/drivers/dma/switchtec_dma.c +++ b/drivers/dma/switchtec_dma.c @@ -886,14 +886,18 @@ static void switchtec_dma_free_desc(struct switchtec_= dma_chan *swdma_chan) if (swdma_chan->hw_sq) dma_free_coherent(swdma_dev->dma_dev.dev, size, swdma_chan->hw_sq, swdma_chan->dma_addr_sq); + swdma_chan->hw_sq =3D NULL; =20 size =3D SWITCHTEC_DMA_CQ_SIZE * sizeof(*swdma_chan->hw_cq); if (swdma_chan->hw_cq) dma_free_coherent(swdma_dev->dma_dev.dev, size, swdma_chan->hw_cq, swdma_chan->dma_addr_cq); + swdma_chan->hw_cq =3D NULL; =20 - for (i =3D 0; i < SWITCHTEC_DMA_RING_SIZE; i++) + for (i =3D 0; i < SWITCHTEC_DMA_RING_SIZE; i++) { kfree(swdma_chan->desc_ring[i]); + swdma_chan->desc_ring[i] =3D NULL; + } } =20 static int switchtec_dma_alloc_desc(struct switchtec_dma_chan *swdma_chan) --=20 2.47.3 From nobody Sat Jul 25 04:54:06 2026 Received: from ale.deltatee.com (ale.deltatee.com [204.191.154.188]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AEACD3DB634; Fri, 17 Jul 2026 22:10:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=204.191.154.188 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784326220; cv=none; b=JuPZTlvx525CrGyCuvkpx3CTo1fJTUmx3tVPUr7XjvZ61V6ZOt/Gxq9VMQHdohR6wolXp4X6CYlDS1KWzYuhjp4f1NpKQ/acHLAwXNsKGj6y/d8UoZNDmVAqpC0KlqYnzSimMlCQoW84hAcxDMWtvE82k20VHYiACdESutBvwN0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784326220; c=relaxed/simple; bh=3apJniTrAz3OCQNT/k1t2ilm3Dew3xvjc75QyxNB1oo=; h=From:To:Cc:Date:Message-ID:In-Reply-To:References:MIME-Version: Subject; b=BL3+V7l/Jwr9BhiIZNfIJ1Nm13Xff+E3MXE1UTKqYUIGQm8bLHFZhI+J9FqqEP7fZu2ceuZJzc+YHFyLTmLncSJNTwHyTcXDNaxX7W2L9tN18uSyH5QVsywCDT05F3Agw/lUCHvjwlFrqYsDGlmka4bLgcxEaV+ezqRFItdNggA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=deltatee.com; spf=pass smtp.mailfrom=deltatee.com; dkim=pass (2048-bit key) header.d=deltatee.com header.i=@deltatee.com header.b=RBpOFYaz; arc=none smtp.client-ip=204.191.154.188 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=deltatee.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=deltatee.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=deltatee.com header.i=@deltatee.com header.b="RBpOFYaz" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=deltatee.com; s=20200525; h=Subject:MIME-Version:References:In-Reply-To: Message-ID:Date:Cc:To:From:content-disposition; bh=9NFh33ZHenlHQ/BzhUGRfrC+RQcL3SZXA7WYZysgfj8=; b=RBpOFYazJXgqc4vvIiUW5sI5h6 r0DXKdIsV7zHZVeYiswR555S4JWHTGJOr6x8/KmqXh1DkaUkFcI3g6ZWDZHQ2RiAwIjtbA84/un21 4Kcznbx8IPeqJ4+JE0mzM78yiWm0v2UDVAyYo28MT1RkWYnMB8xCO2VyDvBopnuSdZH/oUIxibPwB p8hwTT0oEWXvm++Mxega7mcGPbg2kjsq9PtgHu9Sd/KwkzjJh6YUnydI2bp64VjSU6Gg7DvfhcvNT IMPdggpkkzELgVs2H8sFfJdpeXwR8nXuByFTy1/E34xET8qdt9qR9gHYFh6xNn1U0Vy9sIlgxx3YY BZ284LpA==; Received: from cgy1-donard.priv.deltatee.com ([172.16.1.31]) by ale.deltatee.com with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1wkqkz-00000008wEn-3hL4; Fri, 17 Jul 2026 16:10:11 -0600 Received: from gunthorp by cgy1-donard.priv.deltatee.com with local (Exim 4.98.2) (envelope-from ) id 1wkqku-00000001W1v-3Qk7; Fri, 17 Jul 2026 16:10:04 -0600 From: Logan Gunthorpe To: linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, dmaengine@vger.kernel.org, Vinod Koul Cc: Frank Li , Kelvin Cao , =?UTF-8?q?Thomas=20Wei=C3=9Fschuh?= , Dave Jiang , George Ge , Jaeyoung Chung , Logan Gunthorpe , Sashiko Date: Fri, 17 Jul 2026 16:09:57 -0600 Message-ID: <20260717221001.361421-3-logang@deltatee.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260717221001.361421-1-logang@deltatee.com> References: <20260717221001.361421-1-logang@deltatee.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-SA-Exim-Connect-IP: 172.16.1.31 X-SA-Exim-Rcpt-To: linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, dmaengine@vger.kernel.org, Frank.li@nxp.com, linux@weissschuh.net, dave.jiang@intel.com, kelvin.cao@microchip.com, george.ge@microchip.com, jjy600901@snu.ac.kr, logang@deltatee.com, vkoul@kernel.org, sashiko-bot@kernel.org X-SA-Exim-Mail-From: gunthorp@deltatee.com X-Spam-Level: Subject: [PATCH v1 2/6] dmaengine: switchtec-dma: fix resource leak in alloc_chan_resources X-SA-Exim-Version: 4.2.1 (built Sun, 23 Feb 2025 07:57:16 +0000) X-SA-Exim-Scanned: Yes (on ale.deltatee.com) Content-Type: text/plain; charset="utf-8" switchtec_dma_alloc_chan_resources() returns directly on any later failure, without ever freeing the descriptor rings and coherent DMA memory it just allocated. The dmaengine core does not call device_free_chan_resources() when device_alloc_chan_resources() fails, so the driver has to unwind its own partial state. The device-removed check also runs after ring_active and comp_ring_active have already been set true, so a failure there left the channel marked active despite alloc_chan_resources() reporting failure. Add an error-unwind path that disables the channel and frees the descriptor rings on every failure after allocation. ring_active and comp_ring_active are cleared under the same locks switchtec_dma_free_chan_resources() already uses, since the completion tasklet checks comp_ring_active under complete_lock before touching the completion ring, and a stale IRQ can still be in flight when this unwind path runs. Reported-by: Sashiko Link: https://lore.kernel.org/dmaengine/20260707165555.350951F000E9@smtp.ke= rnel.org/T/#u Fixes: 30eba9df76ad ("dmaengine: switchtec-dma: Implement hardware initiali= zation and cleanup") Signed-off-by: Logan Gunthorpe --- drivers/dma/switchtec_dma.c | 23 +++++++++++++++++++---- 1 file changed, 19 insertions(+), 4 deletions(-) diff --git a/drivers/dma/switchtec_dma.c b/drivers/dma/switchtec_dma.c index a4a7d66d042d..f77da31aeb65 100644 --- a/drivers/dma/switchtec_dma.c +++ b/drivers/dma/switchtec_dma.c @@ -988,15 +988,15 @@ static int switchtec_dma_alloc_chan_resources(struct = dma_chan *chan) =20 rc =3D enable_channel(swdma_chan); if (rc) - return rc; + goto err_free_desc; =20 rc =3D reset_channel(swdma_chan); if (rc) - return rc; + goto err_disable_channel; =20 rc =3D unhalt_channel(swdma_chan); if (rc) - return rc; + goto err_disable_channel; =20 swdma_chan->ring_active =3D true; swdma_chan->comp_ring_active =3D true; @@ -1007,7 +1007,8 @@ static int switchtec_dma_alloc_chan_resources(struct = dma_chan *chan) rcu_read_lock(); if (!rcu_dereference(swdma_dev->pdev)) { rcu_read_unlock(); - return -ENODEV; + rc =3D -ENODEV; + goto err_ring_inactive; } =20 perf_cfg =3D readl(&swdma_chan->mmio_chan_fw->perf_cfg); @@ -1029,6 +1030,20 @@ static int switchtec_dma_alloc_chan_resources(struct= dma_chan *chan) FIELD_GET(PERF_MRRS_MASK, perf_cfg)); =20 return SWITCHTEC_DMA_SQ_SIZE; + +err_ring_inactive: + spin_lock_bh(&swdma_chan->submit_lock); + swdma_chan->ring_active =3D false; + spin_unlock_bh(&swdma_chan->submit_lock); + + spin_lock_bh(&swdma_chan->complete_lock); + swdma_chan->comp_ring_active =3D false; + spin_unlock_bh(&swdma_chan->complete_lock); +err_disable_channel: + disable_channel(swdma_chan); +err_free_desc: + switchtec_dma_free_desc(swdma_chan); + return rc; } =20 static void switchtec_dma_free_chan_resources(struct dma_chan *chan) --=20 2.47.3 From nobody Sat Jul 25 04:54:06 2026 Received: from ale.deltatee.com (ale.deltatee.com [204.191.154.188]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 847703BBFBA; Fri, 17 Jul 2026 22:10:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=204.191.154.188 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784326219; cv=none; b=gS/h9W54Zm5wQ0Lne1jJZ94UToDrREZyR1dadDm1wXI55C/OdpVzm2XjH6RVhLulPsqBm7amA+Pn8AOHvHA3Ml0Whd3XRi0FBuwVjFzPvFLX4xhdm16LG6o2Iyphbpn1xB9amJirPNrySzL5YbJcnMFlS6g4bA1kDjDavpwHCjU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784326219; c=relaxed/simple; bh=shjGsBUS+JLAjTMUaOepuPgDDRUJp/DJN1g833a5LTY=; h=From:To:Cc:Date:Message-ID:In-Reply-To:References:MIME-Version: Subject; b=dqx5aXrfx3W61QtBR5AXN+I+n3Z4Gd6Ne1jjRsoW0L6YeXsk3YNpffR0Or3ozjSymJwlChZUPIeGELsQ/pn2J8xVTxX5o4g8ooHWpq/Ji6IHu2WpLWea8lxzDGtCpOavbQu1nS7KNjRw6YC9KtA4sQHNl2vSZi4+X2cbZm0YQks= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=deltatee.com; spf=pass smtp.mailfrom=deltatee.com; dkim=pass (2048-bit key) header.d=deltatee.com header.i=@deltatee.com header.b=AG0Gjgzf; arc=none smtp.client-ip=204.191.154.188 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=deltatee.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=deltatee.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=deltatee.com header.i=@deltatee.com header.b="AG0Gjgzf" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=deltatee.com; s=20200525; h=Subject:MIME-Version:References:In-Reply-To: Message-ID:Date:Cc:To:From:content-disposition; bh=7my9hZJD79zYvl1v8NjTQ00eaM0/EhxbMZNG7EfBQps=; b=AG0Gjgzf4MjzJUrA/G/fRPDgQ1 ag5wE4bhkldQBeucs3xkXYEF2rC+SA15H7cHkYpaAbTQ7rE7UGiyag529dTlLg9Ff5s5G2q7hg8OM hpABCQK2Mp+hOYGQG/0Q6K96pyaC+yp2S0kItI/GZm2WUO/Vbrh92puXc0PSEAwFghFAg2zxyNa6e luoI/YDr3fbfjsqbeWCsyHVEtt1qyJQb7KdYxPFxeurlz0Sz9epkesPnJYXy/06kXB3S0ZXEL/GnK T8Wktb/DqH7Hpq5xV7XxPwquwIof4ELVk2ZZOY2gO+188gqud+TZmWkW2HcV3vxwNYxQvj4v4nY6X G+BIkiRg==; Received: from cgy1-donard.priv.deltatee.com ([172.16.1.31]) by ale.deltatee.com with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1wkqkz-00000008wEo-3hZp; Fri, 17 Jul 2026 16:10:11 -0600 Received: from gunthorp by cgy1-donard.priv.deltatee.com with local (Exim 4.98.2) (envelope-from ) id 1wkqku-00000001W1z-48gX; Fri, 17 Jul 2026 16:10:05 -0600 From: Logan Gunthorpe To: linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, dmaengine@vger.kernel.org, Vinod Koul Cc: Frank Li , Kelvin Cao , =?UTF-8?q?Thomas=20Wei=C3=9Fschuh?= , Dave Jiang , George Ge , Jaeyoung Chung , Logan Gunthorpe , Sashiko Date: Fri, 17 Jul 2026 16:09:58 -0600 Message-ID: <20260717221001.361421-4-logang@deltatee.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260717221001.361421-1-logang@deltatee.com> References: <20260717221001.361421-1-logang@deltatee.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-SA-Exim-Connect-IP: 172.16.1.31 X-SA-Exim-Rcpt-To: linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, dmaengine@vger.kernel.org, Frank.li@nxp.com, linux@weissschuh.net, dave.jiang@intel.com, kelvin.cao@microchip.com, george.ge@microchip.com, jjy600901@snu.ac.kr, logang@deltatee.com, vkoul@kernel.org, sashiko-bot@kernel.org X-SA-Exim-Mail-From: gunthorp@deltatee.com X-Spam-Level: Subject: [PATCH v1 3/6] dmaengine: switchtec-dma: fix channel leak on registration failure X-SA-Exim-Version: 4.2.1 (built Sun, 23 Feb 2025 07:57:16 +0000) X-SA-Exim-Scanned: Yes (on ale.deltatee.com) Content-Type: text/plain; charset="utf-8" If dma_async_device_register() fails during probe, switchtec_dma_chans_release() only stops hardware and frees IRQs and tasklets; it never frees the per-channel swdma_chan structures or the swdma_chans array itself. switchtec_dma_chans_release() is also called from switchtec_dma_remove() before dma_async_device_unregister() has torn down the channels, so it can't free that memory itself. Free the channels and the array directly in the registration-failure path instead, where nothing else will ever free them. Reported-by: Sashiko Link: https://lore.kernel.org/dmaengine/20260707165555.350951F000E9@smtp.ke= rnel.org/T/#u Fixes: 30eba9df76ad ("dmaengine: switchtec-dma: Implement hardware initiali= zation and cleanup") Signed-off-by: Logan Gunthorpe --- drivers/dma/switchtec_dma.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/drivers/dma/switchtec_dma.c b/drivers/dma/switchtec_dma.c index f77da31aeb65..5768948ef466 100644 --- a/drivers/dma/switchtec_dma.c +++ b/drivers/dma/switchtec_dma.c @@ -1234,7 +1234,7 @@ static void switchtec_dma_release(struct dma_device *= dma_dev) static int switchtec_dma_create(struct pci_dev *pdev) { struct switchtec_dma_dev *swdma_dev; - int chan_cnt, nr_vecs, irq, rc; + int chan_cnt, nr_vecs, irq, rc, i; struct dma_device *dma; struct dma_chan *chan; =20 @@ -1317,6 +1317,11 @@ static int switchtec_dma_create(struct pci_dev *pdev) err_chans_release_exit: switchtec_dma_chans_release(pdev, swdma_dev); =20 + for (i =3D 0; i < swdma_dev->chan_cnt; i++) + kfree(swdma_dev->swdma_chans[i]); + + kfree(swdma_dev->swdma_chans); + err_exit: if (swdma_dev->chan_status_irq) free_irq(swdma_dev->chan_status_irq, swdma_dev); --=20 2.47.3 From nobody Sat Jul 25 04:54:06 2026 Received: from ale.deltatee.com (ale.deltatee.com [204.191.154.188]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8480A3D955B; Fri, 17 Jul 2026 22:10:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=204.191.154.188 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784326219; cv=none; b=KAE9DTHzIaVkf2DTojuQSPlcIyCg9CVHFkPesg+W2/RY+bH1zh04604sz7YE7+qXa5bVTdUkPBBuOO7FsGbZHpVTGHJ4cZqrn+DDmQcqBtoEpAfQ1sna6bBDk0AxMGRZZWPIG16Vj5dyqMxM8rF8RQyxsuDj2VR8I2N1E7P4DQI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784326219; c=relaxed/simple; bh=boazSQKaoz1Y5heBQp7szsJqCij2Wr04g3mlrBLNMks=; h=From:To:Cc:Date:Message-ID:In-Reply-To:References:MIME-Version: Subject; b=aDmAHwPpi3jwd2A/ZCTtvIHzBDpS1syTfXIh2ClAJtpzD0vA+XYNWsRpSGwGNRrTvJ17wMFqnGqFwJUb57QYeK/LCypoR+u7QI/eU4sKZoR2UgH0qgBLbyqt8cQi2jgNFahPSroJhVy5E/muJfOyKbjZxjgESBFcfSqKkHT1MAQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=deltatee.com; spf=pass smtp.mailfrom=deltatee.com; dkim=pass (2048-bit key) header.d=deltatee.com header.i=@deltatee.com header.b=LO7yGZms; arc=none smtp.client-ip=204.191.154.188 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=deltatee.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=deltatee.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=deltatee.com header.i=@deltatee.com header.b="LO7yGZms" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=deltatee.com; s=20200525; h=Subject:MIME-Version:References:In-Reply-To: Message-ID:Date:Cc:To:From:content-disposition; bh=koyBdE/JNh7nnWKhy5pv5nbe/haHHnakVIxzfBN56ag=; b=LO7yGZmshPgE9l9KIEu+jtOR45 K9c0IECUhzATJtcj+vXuQRPI1wV1NikExjNhUqhSckQvMnw5yGU6E7c9DLKgaze8Klx3i/TMP335i 7U13l9+v4DtnRX+jUfTvEL/cKuo4wQWRggLvngEbZzk5eMwv2NNcfFZRYQJhoUaIajbDLGR/kX9D1 uRmvp3Jr2LiXs88AbCmr4c47xZZYf1pe8fxYGi/Osv7fFsvXXa2KR29Xwg0pMJEzmer6Iw+Q6we1W WefVyYPNwXoqgqApy89fV9mtzIWsK7TUCS4iJ/5c11O5hVkSozh0O1U8JVQSXW/QALKiwgbbrUCmO hAa36WgQ==; Received: from cgy1-donard.priv.deltatee.com ([172.16.1.31]) by ale.deltatee.com with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1wkqkz-00000008wEp-3hEw; Fri, 17 Jul 2026 16:10:10 -0600 Received: from gunthorp by cgy1-donard.priv.deltatee.com with local (Exim 4.98.2) (envelope-from ) id 1wkqkv-00000001W23-0WA3; Fri, 17 Jul 2026 16:10:05 -0600 From: Logan Gunthorpe To: linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, dmaengine@vger.kernel.org, Vinod Koul Cc: Frank Li , Kelvin Cao , =?UTF-8?q?Thomas=20Wei=C3=9Fschuh?= , Dave Jiang , George Ge , Jaeyoung Chung , Logan Gunthorpe , Sashiko Date: Fri, 17 Jul 2026 16:09:59 -0600 Message-ID: <20260717221001.361421-5-logang@deltatee.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260717221001.361421-1-logang@deltatee.com> References: <20260717221001.361421-1-logang@deltatee.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-SA-Exim-Connect-IP: 172.16.1.31 X-SA-Exim-Rcpt-To: linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, dmaengine@vger.kernel.org, Frank.li@nxp.com, linux@weissschuh.net, dave.jiang@intel.com, kelvin.cao@microchip.com, george.ge@microchip.com, jjy600901@snu.ac.kr, logang@deltatee.com, vkoul@kernel.org, sashiko-bot@kernel.org X-SA-Exim-Mail-From: gunthorp@deltatee.com X-Spam-Level: Subject: [PATCH v1 4/6] dmaengine: ioat: disable relaxed ordering before registering the device X-SA-Exim-Version: 4.2.1 (built Sun, 23 Feb 2025 07:57:16 +0000) X-SA-Exim-Scanned: Yes (on ale.deltatee.com) Content-Type: text/plain; charset="utf-8" ioat3_dma_probe() disabled PCIe relaxed ordering after calling dma_async_device_register(), so if an error occurs and the code jumps to err_disable_interrupts, the function returns with the device still registered in the core's dma_device_list while the caller frees the ioatdma_device struct, leaving a dangling registration that anything walking the device list can dereference after it's been freed. Move the capability read/write ahead of dma_async_device_register() instead. Nothing after registration depends on relaxed ordering already being disabled, and nothing before it depends on the device being registered, so this is a plain reordering. It also means every remaining step after registration can't fail, so there's no need to ever have to unregister the device once registered. Fixes: 511deae0261c ("dmaengine: ioatdma: disable relaxed ordering for ioat= dma") Reported-by: Sashiko Link: https://lore.kernel.org/dmaengine/20260707165906.249F41F000E9@smtp.ke= rnel.org/T/#u Signed-off-by: Logan Gunthorpe --- drivers/dma/ioat/init.c | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/drivers/dma/ioat/init.c b/drivers/dma/ioat/init.c index 737496391109..a57024c4b066 100644 --- a/drivers/dma/ioat/init.c +++ b/drivers/dma/ioat/init.c @@ -1170,15 +1170,6 @@ static int ioat3_dma_probe(struct ioatdma_device *io= at_dma, int dca) ioat_chan->reg_base + IOAT_DCACTRL_OFFSET); } =20 - err =3D dma_async_device_register(&ioat_dma->dma_dev); - if (err) - goto err_disable_interrupts; - - ioat_kobject_add(ioat_dma, &ioat_ktype); - - if (dca) - ioat_dma->dca =3D ioat_dca_init(pdev, ioat_dma->reg_base); - /* disable relaxed ordering */ err =3D pcie_capability_read_word(pdev, PCI_EXP_DEVCTL, &val16); if (err) { @@ -1194,6 +1185,15 @@ static int ioat3_dma_probe(struct ioatdma_device *io= at_dma, int dca) goto err_disable_interrupts; } =20 + err =3D dma_async_device_register(&ioat_dma->dma_dev); + if (err) + goto err_disable_interrupts; + + ioat_kobject_add(ioat_dma, &ioat_ktype); + + if (dca) + ioat_dma->dca =3D ioat_dca_init(pdev, ioat_dma->reg_base); + if (ioat_dma->cap & IOAT_CAP_DPS) writeb(ioat_pending_level + 1, ioat_dma->reg_base + IOAT_PREFETCH_LIMIT_OFFSET); --=20 2.47.3 From nobody Sat Jul 25 04:54:06 2026 Received: from ale.deltatee.com (ale.deltatee.com [204.191.154.188]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id ABD9A3955CD; Fri, 17 Jul 2026 22:20:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=204.191.154.188 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784326808; cv=none; b=C4VVuGZZNaGGo0pkE6XQN8bncRYn5gdMGSeCCh3UcCGlQeDKYtF7G7/bpU3p8OYqu7YiyR8HYfhzIl07LeihEb+Vyy+7/5Tfo4iCYnU0UDrOLSTEWCg4q9cTTKaB0opSWMMCV5Y1ifcNzB8lnH5UJaeQuyPA6OaunhCHY8vCW40= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784326808; c=relaxed/simple; bh=CoUiwWrHYlbdSivViJap2VPMr1u4C1g594WmORgtiq4=; h=From:To:Cc:Date:Message-ID:In-Reply-To:References:MIME-Version: Subject; b=DFcLB23yK4/YMIvJHT41YMvFyMLlEALda0heBF/WFbQs4AO5og5ks6gzLYqCFo2J28r9gXS6q7iz3k3xROk3hfbGqIkNLfU3jG6Uj1uC8mlf7y6sK7zpKCL8tkLOKWO5T7jvbruK974wq1qYEQf9G/9lGE2ehnitIhGGC9+f4q0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=deltatee.com; spf=pass smtp.mailfrom=deltatee.com; dkim=pass (2048-bit key) header.d=deltatee.com header.i=@deltatee.com header.b=rPy1fTP5; arc=none smtp.client-ip=204.191.154.188 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=deltatee.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=deltatee.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=deltatee.com header.i=@deltatee.com header.b="rPy1fTP5" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=deltatee.com; s=20200525; h=Subject:MIME-Version:References:In-Reply-To: Message-ID:Date:Cc:To:From:content-disposition; bh=ipTAymtpVpnfbcTyjH7O8f3+s0e/pKqBLscUDcJLr7E=; b=rPy1fTP5ZFgxxcdoXqHAohq6M0 qAADV3OXdf3SS5w+r1VJysoVnVU18W6qIquGHuD/uY26gYNtb6y8Gxk7btD6gbB9FbqNau+SJJFV5 E/YTDKg1Ho8TwmAfEzzBC9wRNpHD93C/4s/k+NtWFQ0C0Y3w7ePiGTgOlZin7W4dY0tZ1EJ7Zdrm1 mhdHDKidgGwlTR8ZbuGQFfj0CpQv//8TSaGIckTmha3VKqXsYniZgzJiftewD5lESFa3NJqGj261r HANg/7rJZ5mXMgOhmtdCYn0RyBkLY6iwAQwU2zDjinbKl252moL50u580NcDVsTJzz9qGA+R3Hbud hy9pxK2Q==; Received: from cgy1-donard.priv.deltatee.com ([172.16.1.31]) by ale.deltatee.com with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1wkquc-00000008wLZ-2uoh; Fri, 17 Jul 2026 16:20:07 -0600 Received: from gunthorp by cgy1-donard.priv.deltatee.com with local (Exim 4.98.2) (envelope-from ) id 1wkqkv-00000001W27-17oo; Fri, 17 Jul 2026 16:10:05 -0600 From: Logan Gunthorpe To: linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, dmaengine@vger.kernel.org, Vinod Koul Cc: Frank Li , Kelvin Cao , =?UTF-8?q?Thomas=20Wei=C3=9Fschuh?= , Dave Jiang , George Ge , Jaeyoung Chung , Logan Gunthorpe Date: Fri, 17 Jul 2026 16:10:00 -0600 Message-ID: <20260717221001.361421-6-logang@deltatee.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260717221001.361421-1-logang@deltatee.com> References: <20260717221001.361421-1-logang@deltatee.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-SA-Exim-Connect-IP: 172.16.1.31 X-SA-Exim-Rcpt-To: linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, dmaengine@vger.kernel.org, vkoul@kernel.org, Frank.li@nxp.com, linux@weissschuh.net, dave.jiang@intel.com, kelvin.cao@microchip.com, george.ge@microchip.com, jjy600901@snu.ac.kr, logang@deltatee.com X-SA-Exim-Mail-From: gunthorp@deltatee.com X-Spam-Level: Subject: [PATCH v1 5/6] dmaengine: ioat: use sysfs_emit() in per-channel sysfs show() X-SA-Exim-Version: 4.2.1 (built Sun, 23 Feb 2025 07:57:16 +0000) X-SA-Exim-Scanned: Yes (on ale.deltatee.com) Content-Type: text/plain; charset="utf-8" Convert the sprintf() calls in the per-channel sysfs attribute show() functions to sysfs_emit(). Signed-off-by: Logan Gunthorpe --- drivers/dma/ioat/sysfs.c | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/drivers/dma/ioat/sysfs.c b/drivers/dma/ioat/sysfs.c index e796ddb5383f..976134df8108 100644 --- a/drivers/dma/ioat/sysfs.c +++ b/drivers/dma/ioat/sysfs.c @@ -24,12 +24,12 @@ static ssize_t cap_show(struct dma_chan *c, char *page) { struct dma_device *dma =3D c->device; =20 - return sprintf(page, "copy%s%s%s%s%s\n", - dma_has_cap(DMA_PQ, dma->cap_mask) ? " pq" : "", - dma_has_cap(DMA_PQ_VAL, dma->cap_mask) ? " pq_val" : "", - dma_has_cap(DMA_XOR, dma->cap_mask) ? " xor" : "", - dma_has_cap(DMA_XOR_VAL, dma->cap_mask) ? " xor_val" : "", - dma_has_cap(DMA_INTERRUPT, dma->cap_mask) ? " intr" : ""); + return sysfs_emit(page, "copy%s%s%s%s%s\n", + dma_has_cap(DMA_PQ, dma->cap_mask) ? " pq" : "", + dma_has_cap(DMA_PQ_VAL, dma->cap_mask) ? " pq_val" : "", + dma_has_cap(DMA_XOR, dma->cap_mask) ? " xor" : "", + dma_has_cap(DMA_XOR_VAL, dma->cap_mask) ? " xor_val" : "", + dma_has_cap(DMA_INTERRUPT, dma->cap_mask) ? " intr" : ""); =20 } static const struct ioat_sysfs_entry ioat_cap_attr =3D __ATTR_RO(cap); @@ -39,8 +39,8 @@ static ssize_t version_show(struct dma_chan *c, char *pag= e) struct dma_device *dma =3D c->device; struct ioatdma_device *ioat_dma =3D to_ioatdma_device(dma); =20 - return sprintf(page, "%d.%d\n", - ioat_dma->version >> 4, ioat_dma->version & 0xf); + return sysfs_emit(page, "%d.%d\n", + ioat_dma->version >> 4, ioat_dma->version & 0xf); } static const struct ioat_sysfs_entry ioat_version_attr =3D __ATTR_RO(versi= on); =20 @@ -118,7 +118,7 @@ static ssize_t ring_size_show(struct dma_chan *c, char = *page) { struct ioatdma_chan *ioat_chan =3D to_ioat_chan(c); =20 - return sprintf(page, "%d\n", (1 << ioat_chan->alloc_order) & ~1); + return sysfs_emit(page, "%d\n", (1 << ioat_chan->alloc_order) & ~1); } static const struct ioat_sysfs_entry ring_size_attr =3D __ATTR_RO(ring_siz= e); =20 @@ -127,7 +127,7 @@ static ssize_t ring_active_show(struct dma_chan *c, cha= r *page) struct ioatdma_chan *ioat_chan =3D to_ioat_chan(c); =20 /* ...taken outside the lock, no need to be precise */ - return sprintf(page, "%d\n", ioat_ring_active(ioat_chan)); + return sysfs_emit(page, "%d\n", ioat_ring_active(ioat_chan)); } static const struct ioat_sysfs_entry ring_active_attr =3D __ATTR_RO(ring_a= ctive); =20 @@ -135,7 +135,7 @@ static ssize_t intr_coalesce_show(struct dma_chan *c, c= har *page) { struct ioatdma_chan *ioat_chan =3D to_ioat_chan(c); =20 - return sprintf(page, "%d\n", ioat_chan->intr_coalesce); + return sysfs_emit(page, "%d\n", ioat_chan->intr_coalesce); } =20 static ssize_t intr_coalesce_store(struct dma_chan *c, const char *page, --=20 2.47.3 From nobody Sat Jul 25 04:54:06 2026 Received: from ale.deltatee.com (ale.deltatee.com [204.191.154.188]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 455E7233723; Fri, 17 Jul 2026 22:20:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=204.191.154.188 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784326808; cv=none; b=G+ScAwYTmQEqbaEohCWalf99sa8v44WbsVawWQ+ihzwUqP6VZUTCaQDcgJDDmA+j2Rm8OiaLxG0Pucp2D+N4BxwAru6rvpVI5azYjh5cMp/ieLuJzGqHff8A/WONiCJdNmiAVYEYk+6HUFTQRPwUA0DkS7mSo+6snqEIrpmkZS8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784326808; c=relaxed/simple; bh=c1RDThDu/yg04bQSvgQI5zZi0YfbwuOZe497uObnO8I=; h=From:To:Cc:Date:Message-ID:In-Reply-To:References:MIME-Version: Subject; b=RXei89N+aYPqGAJRlUJB9WHXqu2p4lRJBGSyAYb50mGSsE3br/+Ci3SfLRH9iEgTLuzKpMhWAdXS9fjRJFzDXse2hZtxkXWN1lL0mg/cSo8dwEwANSz2zyzTYUYDZ2mqoPKHMYotHicX5ZBGnvnWG+jd3h0AjAJK84r+f1Xm5QM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=deltatee.com; spf=pass smtp.mailfrom=deltatee.com; dkim=pass (2048-bit key) header.d=deltatee.com header.i=@deltatee.com header.b=rGIV4bzx; arc=none smtp.client-ip=204.191.154.188 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=deltatee.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=deltatee.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=deltatee.com header.i=@deltatee.com header.b="rGIV4bzx" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=deltatee.com; s=20200525; h=Subject:MIME-Version:References:In-Reply-To: Message-ID:Date:Cc:To:From:content-disposition; bh=yNCvsxX1ZdcmE8oOIwPo/bMfv+7yuyYsTjy6+dHYoIo=; b=rGIV4bzx9lDwujKYKttEurfTZr mi8Y8815kp4uDPWO3YMN8KyeQ2oVdBWlxtSYvkVn1xTJ995F4RLJcNlYSiFpqlCt0ws+VEjYwCeXW aiuHlluCEVOWltpYPuhkuMqwDmBP+xKnnPiYzy114eFtUy8cDEEyFpIqLd+kjyWPmldwuV0OVSruJ bci+NJQIXBiWjOTiL03UAhM6ncf5S/3OCROMNski3AAS/nhl9lyymKUwUiuczlle1jzgiiVlAzNNd bV4shB0FyK7xraojl7frL6RfAI24sXCs6fY/dcI3vbwGUKmopgfYu4uxA39DcdLRUDBUpEhVCbRcP i3iviLuA==; Received: from cgy1-donard.priv.deltatee.com ([172.16.1.31]) by ale.deltatee.com with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1wkqub-00000008wLZ-3jhi; Fri, 17 Jul 2026 16:20:06 -0600 Received: from gunthorp by cgy1-donard.priv.deltatee.com with local (Exim 4.98.2) (envelope-from ) id 1wkqkv-00000001W2B-1lXz; Fri, 17 Jul 2026 16:10:05 -0600 From: Logan Gunthorpe To: linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, dmaengine@vger.kernel.org, Vinod Koul Cc: Frank Li , Kelvin Cao , =?UTF-8?q?Thomas=20Wei=C3=9Fschuh?= , Dave Jiang , George Ge , Jaeyoung Chung , Logan Gunthorpe , Sangyun Kim , Kyungwook Boo Date: Fri, 17 Jul 2026 16:10:01 -0600 Message-ID: <20260717221001.361421-7-logang@deltatee.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260717221001.361421-1-logang@deltatee.com> References: <20260717221001.361421-1-logang@deltatee.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-SA-Exim-Connect-IP: 172.16.1.31 X-SA-Exim-Rcpt-To: linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, dmaengine@vger.kernel.org, vkoul@kernel.org, Frank.li@nxp.com, linux@weissschuh.net, dave.jiang@intel.com, kelvin.cao@microchip.com, george.ge@microchip.com, logang@deltatee.com, jjy600901@snu.ac.kr, sangyun.kim@snu.ac.kr, bookyungwook@gmail.com X-SA-Exim-Mail-From: gunthorp@deltatee.com X-Spam-Level: Subject: [PATCH v1 6/6] dmaengine: plx_dma: fix NULL pointer deref in plx_dma_isr() X-SA-Exim-Version: 4.2.1 (built Sun, 23 Feb 2025 07:57:16 +0000) X-SA-Exim-Scanned: Yes (on ale.deltatee.com) Content-Type: text/plain; charset="utf-8" plx_dma_create() registered the interrupt handler with request_irq() before initializing plxdev->bar. If the device raised an interrupt in that window, plx_dma_isr() would dereference the still-NULL bar. Move the bar assignment ahead of request_irq() so everything the handler can touch is initialized before it can run. Reported-by: Sangyun Kim Reported-by: Kyungwook Boo Link: https://lore.kernel.org/all/20260610112121.676561-1-jjy600901@snu.ac.= kr/T/#u Fixes: c2dbcaa8c672 ("dmaengine: plx-dma: Implement hardware initialization= and cleanup") Signed-off-by: Logan Gunthorpe --- drivers/dma/plx_dma.c | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/drivers/dma/plx_dma.c b/drivers/dma/plx_dma.c index 84941a918b01..409898e92c32 100644 --- a/drivers/dma/plx_dma.c +++ b/drivers/dma/plx_dma.c @@ -504,17 +504,17 @@ static int plx_dma_create(struct pci_dev *pdev) if (!plxdev) return -ENOMEM; =20 - rc =3D request_irq(pci_irq_vector(pdev, 0), plx_dma_isr, 0, - KBUILD_MODNAME, plxdev); - if (rc) - goto free_plx; - spin_lock_init(&plxdev->ring_lock); tasklet_setup(&plxdev->desc_task, plx_dma_desc_task); =20 RCU_INIT_POINTER(plxdev->pdev, pdev); plxdev->bar =3D pcim_iomap_table(pdev)[0]; =20 + rc =3D request_irq(pci_irq_vector(pdev, 0), plx_dma_isr, 0, + KBUILD_MODNAME, plxdev); + if (rc) + goto free_plx; + dma =3D &plxdev->dma_dev; INIT_LIST_HEAD(&dma->channels); dma_cap_set(DMA_MEMCPY, dma->cap_mask); --=20 2.47.3