From nobody Mon Sep 28 23:56:30 2026 Received: from mail-ed1-f42.google.com (mail-ed1-f42.google.com [209.85.208.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2278A3CE4A3 for ; Fri, 14 Aug 2026 14:27:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.42 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786717662; cv=none; b=UhVKdieMqTwn9kjJLklix/nIq/I6jEkcfxBLadj/dr32o0blt0k4QND7rgdHzHAHixBCl2231znXuosLN0HVmBVb8PI380m7IRJz492+CgRtFv/m4HVb2L7xET3VuWNRHhuRTZ+CIcjaYBHQ1mqQU0JRjZrA6BlnIitxrIqd2rc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786717662; c=relaxed/simple; bh=bAEWJXpWzPUhQYzyuDT8PPZLPevp6bNC7oyuUisHQ4M=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Ur6gQeVFXbO8G7gaRAnc2jLYrrbXBsEO/8JZdZL6oYIiCav4OmJ26ezCBKb5qsRKB9uSnW7CJOeHsCfOO/cVHY8GERy1VsUg42N7j8S1zkCyX3ZjKutOMuUZJcXMtOkOjSrQ3QM6umUZG0UzReqMEbKNO3LGchYt8GBRqmM97OE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=soundtrack.io; spf=pass smtp.mailfrom=soundtrack.io; dkim=pass (2048-bit key) header.d=soundtrack.io header.i=@soundtrack.io header.b=BjkR7nZw; arc=none smtp.client-ip=209.85.208.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=soundtrack.io Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=soundtrack.io Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=soundtrack.io header.i=@soundtrack.io header.b="BjkR7nZw" Received: by mail-ed1-f42.google.com with SMTP id 4fb4d7f45d1cf-69a1c7ce59dso159821a12.3 for ; Fri, 14 Aug 2026 07:27:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=soundtrack.io; s=google; t=1786717654; x=1787322454; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=7YukWWHI9wYIN19FTJID+eUyg7sERpWkqr51k3rjwMM=; b=BjkR7nZwLzXESdZi0USnXcTvckh8r9CTK4Sx9G1jf8OQ4+4Hp/UUYtO8Yfn0GEipG/ FvmVtPwWUjvVzyw5tDn83Qq/Qzi1ejt6qmTIvhYZyYMP9Hmx+bYDaQwNn2Bl7jTMNBet qEjAadwlzMISuT6dLh9zHch1/FlLC8n7v9ksRH60b2nbmwAC8qbG4IBoAC4fzlHKf1Vt KTAcpJOd6R/pbwZIOWNGUrONnDNIuiB5zjOSRA8/I/drG2WMQM3te1h1/kCSaBaHtd9x VrqyHDlrRq9Zv5/ULUuiYQ1gT2+QVp9J9UbSKtvzRWGiU86t9/WvaF/J4kcpqZXMAy0j spgw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786717654; x=1787322454; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=7YukWWHI9wYIN19FTJID+eUyg7sERpWkqr51k3rjwMM=; b=ZWxFePGeLCrExl0QkpnuEMIfuG9t+goQVttbldT1YV+o2P8cQdRBnoQHPtN5yohOZa PsLSv0UCe7YyDg5tyZArntbh1IeO3M55fVK2XWS//gjFIdtcJN4ORCDKPKUhBA8GiDRE /t5YLK0wCj3tCv39kp72AYxh9hpCK4sSgKVitii21O7GwhuU/RqYOlYKQ4ppHCMXcL/R Z61k0alxHmEUjzHRHMUQ2NXnMURS8uPlud1p/caCLm2nD+6B+ZkDPdnImOYFtLpnZ3rY vlJLYxQmat+wl2wsNjmBXj7MTtq1tZ4IKhIeEQuz67wqsueX8ZGTf+FCWevWbvhvVrPS 0y4g== X-Forwarded-Encrypted: i=1; AHgh+RrrEAXraRswo4bseff0/N58Qk4xDsH+8KqwGCguwdRjI0hWByaBRURWDQjlLSRQ+7fvY5WDlPSpnu9Wtv8=@vger.kernel.org X-Gm-Message-State: AOJu0YwScwLu3Tzwd3lZPhk1VkjnYIqNim6SVfKRb1+Zi/ipwvBqqHMx pF3ZW/oEuOi1XoWXBgbf99mfJn25hoCPOEPn1kM4acPNIG3vjkwXt10T8JIsACEf+U0= X-Gm-Gg: AR+sD10d2+resiox89TmD48lItFMJ0hFR+UO/KhRB2HnDVy67r421CB0/Fn3gbEthm3 xY233OMOLgyorMrCsFvT6Uu1z6fawrgV2npQ+ntcXtw7PMcbUJmJPB+IDpSM/hHQCXB34PNPaU6 FWViRWjGa5nws5uWP9DaaEdg64lD51+12jGRF/35BW0wbw/4nX0ZrRhypIPWwshQpTUz9+nF3/7 WSc5DIuHhcZoAUin5gTh7lL2Mev53uNJdActfCVLHdXD6jgL7gEuhOnxh7+KkRMTWhlHhQ5FWTS yTcrSkmabcu643t/eD2gRD5Mu+yvzINJLK0+kCjnvYvHE71MjgFiTC/F0nnHUNs7uikJX0XXp// bVTmd/2jEu7WVgOQCT5s5nTG/MpH9/gw8Uf7IwpTxtOEojj8fQyduC5OYV95pYFJoaWVWTIFTUm 1iQ+Zu9D6wW8Vxk/wAaibvs9huZtwARbnxaKOUGadMrIIQdIWDAbIgvr9kN0AYizZGTnxKYPJCG PAk3dINIFottbpoc8onCERC5/ggEBq8f+cn13W4Eyajoa2qaBGqyoG1Qw== X-Received: by 2002:a05:6402:548d:b0:6a0:f1d5:deb8 with SMTP id 4fb4d7f45d1cf-6a38a83c619mr1585118a12.0.1786717653700; Fri, 14 Aug 2026 07:27:33 -0700 (PDT) Received: from Christians-MBP (31-209-40-223.cust.bredband2.com. [31.209.40.223]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c21234c45ffsm106308866b.19.2026.08.14.07.27.32 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Fri, 14 Aug 2026 07:27:33 -0700 (PDT) From: Christian Lugnberg To: vkoul@kernel.org Cc: Frank.Li@kernel.org, wens@kernel.org, jernej.skrabec@gmail.com, samuel@sholland.org, dmaengine@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org, Christian Lugnberg , stable@vger.kernel.org Subject: [PATCH v2 1/2] dmaengine: sun6i: fix non-atomic read of DMA position registers Date: Fri, 14 Aug 2026 16:21:10 +0200 Message-ID: <20260814142708.79120-2-christian.lugnberg@soundtrack.io> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260814142708.79120-1-christian.lugnberg@soundtrack.io> References: <20260814142708.79120-1-christian.lugnberg@soundtrack.io> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable sun6i_get_chan_size() reads DMA_CHAN_LLI_ADDR and DMA_CHAN_CUR_CNT in two separate readl() calls with no synchronisation between them: pos =3D readl(pchan->base + DMA_CHAN_LLI_ADDR); bytes =3D readl(pchan->base + DMA_CHAN_CUR_CNT); DMA_CHAN_LLI_ADDR holds the physical address of the *next* descriptor the engine will load once the current one completes. DMA_CHAN_CUR_CNT holds the remaining byte count for the *current* descriptor. If the DMA engine advances to the next LLI entry between the two reads, pos becomes stale: it still points to what was the next descriptor at the time of the first read, but that descriptor is now the current one and CUR_CNT reflects its initial (full) byte count. The subsequent virtual-chain walk starts one entry too early and accumulates an extra full period's worth of bytes into the residue estimate. For ALSA cyclic buffers the over-counted residue can reach the full buffer size, causing the computed playback position to appear to jump backward to near zero. The ALSA PCM core treats such a backward discontinuity in hw_ptr as evidence that the buffer has underrun and declares an xrun. On the Barix IPAM400 (Allwinner H3, kernel 6.12) this manifests as audible glitches accompanied by spurious xrun log entries, confirmed by two independent observations: First, the ALSA buffer in the affected configuration is 2 seconds deep with a 500 ms refill period (the interval at which the player software wakes up to top up the buffer). For a real underrun to occur the player would have to stall for the full 2 seconds without writing any audio =E2=80=94 effecti= vely impossible under normal scheduling conditions. Yet xruns are observed regularly. Second, the underrun duration reported by the kernel at xrun time is ~30 =C2=B5s, roughly one audio sample at 44100 Hz. A genuine drain of a 2 second buffer cannot resolve in 30 =C2=B5s; only a phantom position jump caused by a register read race can produce such a number. Observed on a 44100 Hz stereo S16_LE stream: $ cat /proc/asound/Codec/pcm0p/sub0/status state: XRUN delay: 0 avail: 88200 avail_max: 22514 The avail_max of 22514 frames (511 ms) matches exactly one ALSA period =E2= =80=94 the amount added by starting the LLI chain walk one entry too early. The race window itself is narrow. Each DMA descriptor covers approximately 88 samples (~2 ms at 44100 Hz), so the engine advances to a new descriptor roughly every 2 ms. The two readl() calls must straddle that exact boundary for the corruption to occur, which explains why the bug is intermittent. The bug is further confirmed by the xrun_debug bit 2 toggle (jiffies position validation). With it enabled xruns cease immediately and do not return; clearing it causes xruns to reappear within minutes. This on/off reproducibility isolates the fault to the hw_ptr position reporting path; the DMA engine itself is functioning correctly, as evidenced by hw_ptr advancing at a steady 44100 frames/sec between events: $ echo 4 > /proc/asound/Codec/pcm0p/xrun_debug # xruns stop $ echo 0 > /proc/asound/Codec/pcm0p/xrun_debug # xruns return Fix this by re-reading DMA_CHAN_LLI_ADDR after DMA_CHAN_CUR_CNT and retrying if the value changed. This double-read pattern guarantees that both registers were sampled during the same descriptor interval. The cost is at most one extra readl() pair per call in the racy case, which occurs only at descriptor boundaries (~every 2 ms) and is negligible. Fixes: a90e173f3faf ("dmaengine: sun6i: Add cyclic capability") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-sonnet-4-6 Signed-off-by: Christian Lugnberg --- drivers/dma/sun6i-dma.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/drivers/dma/sun6i-dma.c b/drivers/dma/sun6i-dma.c index f47a326dd7ff..04fe1f5042e9 100644 --- a/drivers/dma/sun6i-dma.c +++ b/drivers/dma/sun6i-dma.c @@ -354,8 +354,10 @@ static size_t sun6i_get_chan_size(struct sun6i_pchan *= pchan) size_t bytes; dma_addr_t pos; =20 - pos =3D readl(pchan->base + DMA_CHAN_LLI_ADDR); - bytes =3D readl(pchan->base + DMA_CHAN_CUR_CNT); + do { + pos =3D readl(pchan->base + DMA_CHAN_LLI_ADDR); + bytes =3D readl(pchan->base + DMA_CHAN_CUR_CNT); + } while (pos !=3D readl(pchan->base + DMA_CHAN_LLI_ADDR)); =20 if (pos =3D=3D LLI_LAST_ITEM) return bytes; --=20 2.54.0 (Apple Git-156) From nobody Mon Sep 28 23:56:30 2026 Received: from mail-ed1-f47.google.com (mail-ed1-f47.google.com [209.85.208.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 084A43BCD25 for ; Fri, 14 Aug 2026 14:27:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.47 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786717676; cv=none; b=PYyy5asgJlWm55DgZ2GHciwD0jex8fVBrH5HQ7ok/uy92JQceBOu6QhJPQ7SPpMiJJ/11smehZ3Q1bzy3VPi4NIUq6lONwgdNW2t1aFAs9B6yjbjqs1hOlhmN30Bb0tQmPXv5p+LjaW/XlPbH73CRi65OhLnCNBxM0Sd6KFgr2c= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786717676; c=relaxed/simple; bh=k0KzLk/Py5MfNs6v0LG2pawI7nCHX5oUhShrr2VzixE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ILS73LR2h6q+zFP24MNaYrzOw1C84HDOvfp6K71VO/DzGZhyFNIFhKy3ytWX51mxQDk7Cuui+EHCQreyKZvopq/jjnH0q+SLzPB9+jQ7r5Dep85VR8Ofid4TEjuTRvBa95RMPeVkR1cJcXNiA8rlyrPjTPwujT7xwDPaXjP7UQQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=soundtrack.io; spf=pass smtp.mailfrom=soundtrack.io; dkim=pass (2048-bit key) header.d=soundtrack.io header.i=@soundtrack.io header.b=Abk8hbO3; arc=none smtp.client-ip=209.85.208.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=soundtrack.io Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=soundtrack.io Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=soundtrack.io header.i=@soundtrack.io header.b="Abk8hbO3" Received: by mail-ed1-f47.google.com with SMTP id 4fb4d7f45d1cf-6a18af264f9so223233a12.0 for ; Fri, 14 Aug 2026 07:27:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=soundtrack.io; s=google; t=1786717660; x=1787322460; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=t8f5UJCABHvmBw6dzoHdGzw6KbaLnhVEoCCS6jqmRT4=; b=Abk8hbO3uhyHVYxm90lWMY7m0s1iBE3oGJKs2XJgQJ09dUKp5u+hpy8pMULNG3S4N0 e9pukQFGcMYrj866rPOzzYuIRgTQHxq+VgrHhKSqHqIV4NL2KQwI4Z0BD8Mp1sTvz3LM 1Ugb3Rn3Np/3gUXKg/NOKV7OmW7VFrLGUsUcLUxd8plGza8ue3UV3u23tsXSj4kYYawL J7kC1N/xMNaSSysLroGs/baRvrSRAS7FQHZwZLnkac4pqIUoF3KegUu+PaJm01xPISTf vwVFJoGrz90CFCe49XxKrtsGC/cUUE0svJth8QhQWh6/8afjYQ7ikvKEydsyEdCZOV/0 g3Ng== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786717660; x=1787322460; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=t8f5UJCABHvmBw6dzoHdGzw6KbaLnhVEoCCS6jqmRT4=; b=F4JRLflT3OA+EDfuF+pgUEyrGJAGlR0t1KG//b8pC/yi3KsgKDuN9KNFMzBCOxrm3h hC003KulbOuTzleJXeube2A3LFmUIox7qhpXba1YtZoT9M5bCqC1VONTVtOZOq4creOR nwNpY5+qqRSXKA7X3AoxxiGzlYEAs5JhykwslopDdOaPHobQrgzXPOE9zYdId+2b7S9Y JCPe5wVU9o43UfSRv1yzMBqG+L4BdxK4OG+OsqHRq9vnL8MrhVDbpG/LpTcnHTtrLik9 s72PLiwh7tkRFtZtZjus5N1k8wsGhSLDt2kKu9/EpD9l+XCvsgyls9suvSbcs++1g803 hXjA== X-Forwarded-Encrypted: i=1; AHgh+RogL5q76COpxpHHMGnTby1Y48jQRVj8qGCa4hcnq5TcAQX9OGotHQ7Gugqvezg1SmR3rkh27f7U8ceHA40=@vger.kernel.org X-Gm-Message-State: AOJu0Yxr18DL+85nIuYuGNfrbZDfOXN3NO5/AtQw0/dl1kBRElD+q7xe DsYrLun8HJwwxHYpW76vyEBq/FLbhm9cN/ETI2WVkME1cXfxOr37A31VFpsa0lJm4XY= X-Gm-Gg: AR+sD11nv7RX4HdTeilSuc0IgDxenc6hyUfACM16a5moHyWfCkcXknPeBlT7Uniaeru zf03z2V2pQgCyER1RqXb2tQyqx8t/Ez6Wr/jox1Qd6Gh5qDXNgRIZeg8iURk93afeQHtlFHFK/S E0PrjmHqQUfUgUxv/ugcgCRL20TgvB1oojIrg7kU3/Zawv0JrfF4BbPgoMMfb08Nde4Rg0zEt0j 39RwgSrDbHuWarkdWMd6yeKLkNmtr0dtGKpPRupZ+0piDhavziJDZe2Yp0yBKHFLSkP2Gg4QQob EbaOJ6m22pzJbXqD6TPcSSbqSDSE76BM/nJcsXTE3PG8OBpYC9Le9h0Fx4EunV1NpD9xxf3tpkE 7gdiulQEnsUn1mWOwMT2ATQBoHprr0rnjqRkc/dcMp87/EsoKksEQxZND2NH/ll0pk2p87Xd1wN 1HrAK9kbFhkQDgbhgurqWFHcmf5oZUi3XhhQvglFE7Tmi1wMtvZz+GKIgB74CzIYaejuKIMZjpn x9sUGWLsvaxgFJ7Imt/tGGHZoQ+wldY+MvD0sExmHyxPX+TAA6jAZ8HBg== X-Received: by 2002:a17:907:9403:b0:c1c:4ae9:b935 with SMTP id a640c23a62f3a-c212a22e029mr175852366b.3.1786717659858; Fri, 14 Aug 2026 07:27:39 -0700 (PDT) Received: from Christians-MBP (31-209-40-223.cust.bredband2.com. [31.209.40.223]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c21234c45ffsm106308866b.19.2026.08.14.07.27.38 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Fri, 14 Aug 2026 07:27:39 -0700 (PDT) From: Christian Lugnberg To: vkoul@kernel.org Cc: Frank.Li@kernel.org, wens@kernel.org, jernej.skrabec@gmail.com, samuel@sholland.org, dmaengine@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org, Christian Lugnberg , stable@vger.kernel.org Subject: [PATCH v2 2/2] dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status Date: Fri, 14 Aug 2026 16:21:11 +0200 Message-ID: <20260814142708.79120-3-christian.lugnberg@soundtrack.io> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260814142708.79120-1-christian.lugnberg@soundtrack.io> References: <20260814142708.79120-1-christian.lugnberg@soundtrack.io> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" sun6i_dma_tx_status() calls vchan_find_desc() to look up the virtual descriptor for a given cookie, before checking whether the pointer vd is NULL: vd =3D vchan_find_desc(&vchan->vc, cookie); txd =3D to_sun6i_desc(&vd->tx); /* vd may be NULL here */ if (vd) { for (lli =3D txd->v_lli; ...) vchan_find_desc() returns NULL when the descriptor has already been completed or is in-flight on a physical channel and no longer present in the virtual channel's descriptor list. When vd is NULL, to_sun6i_desc() is called unconditionally on &vd->tx before the NULL check, which is undefined behaviour. Move the call inside the if (vd) guard to ensure it is only reached with a valid pointer. vd =3D vchan_find_desc(&vchan->vc, cookie); if (vd) { struct sun6i_desc *txd =3D to_sun6i_desc(&vd->tx); for (lli =3D txd->v_lli; ...) Fixes: 555859308723 ("dmaengine: sun6i: Add driver for the Allwinner A31 DM= A controller") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-sonnet-4-6 Signed-off-by: Christian Lugnberg Reviewed-by: Frank Li --- drivers/dma/sun6i-dma.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/drivers/dma/sun6i-dma.c b/drivers/dma/sun6i-dma.c index 04fe1f5042e9..7704b016aed8 100644 --- a/drivers/dma/sun6i-dma.c +++ b/drivers/dma/sun6i-dma.c @@ -981,7 +981,6 @@ static enum dma_status sun6i_dma_tx_status(struct dma_c= han *chan, struct sun6i_pchan *pchan =3D vchan->phy; struct sun6i_dma_lli *lli; struct virt_dma_desc *vd; - struct sun6i_desc *txd; enum dma_status ret; unsigned long flags; size_t bytes =3D 0; @@ -993,9 +992,9 @@ static enum dma_status sun6i_dma_tx_status(struct dma_c= han *chan, spin_lock_irqsave(&vchan->vc.lock, flags); =20 vd =3D vchan_find_desc(&vchan->vc, cookie); - txd =3D to_sun6i_desc(&vd->tx); =20 if (vd) { + struct sun6i_desc *txd =3D to_sun6i_desc(&vd->tx); for (lli =3D txd->v_lli; lli !=3D NULL; lli =3D lli->v_lli_next) bytes +=3D lli->len; } else if (!pchan || !pchan->desc) { --=20 2.54.0 (Apple Git-156)