From nobody Mon Sep 28 21:11:15 2026 Received: from mail-ed1-f51.google.com (mail-ed1-f51.google.com [209.85.208.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C337544236A for ; Mon, 17 Aug 2026 13:57:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.51 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786975058; cv=none; b=hLUj16fj3Xjz3pMSpYudqAmzil7d5iNie6SNm97AOjX+hOCXPYQ2VWgLLZGv0OxRADbzhEq9D8hszLPGLKUQJ1ATXdJKm8/1wgRhbo6LlClj39hTpeFsIrEfPOBiykoWNfVOVuB0Rdwj8UiZygH+2HpIsO1C0/gQ65rRjcGCeMI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786975058; c=relaxed/simple; bh=PZI7MMxmJVNzbmV5bnrz48F2Q3n5UxIGaRjcpiHxuHk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=d6JX0Rp3eB63xRNaIFbVS8YKV0CvIaxuFU24SPM9X4uEiWMDe/vK0bOG0LyQcp2tPhDQiWOgfG5FESw8Qd2CbfysxJIr2ml63BcE7zKDaXW5mUGjDzpmGWWKcOtc8rDNEE+DVgPgXz3gvhDTPXYg6WPpEpthvqap5AseWpRPIc8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=soundtrack.io; spf=pass smtp.mailfrom=soundtrack.io; dkim=pass (2048-bit key) header.d=soundtrack.io header.i=@soundtrack.io header.b=tEpTIBqH; arc=none smtp.client-ip=209.85.208.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=soundtrack.io Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=soundtrack.io Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=soundtrack.io header.i=@soundtrack.io header.b="tEpTIBqH" Received: by mail-ed1-f51.google.com with SMTP id 4fb4d7f45d1cf-698aece3d7eso631577a12.1 for ; Mon, 17 Aug 2026 06:57:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=soundtrack.io; s=google; t=1786975054; x=1787579854; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=WLmqosVfHRUnCpTXG/vmgJdRPIFeEEdEr21ji49UgUg=; b=tEpTIBqHOBDANpCGB3UUeUWv7fsWbUyEVdhtcDtwO4ow2BV1/qXXoNsn4KpTBZceNS +epRX8gxHhp3p7jD8atP/eTILwMrLYloFOlBsRqnmQK7pK8S/VQaeg1hwZtNyAKdqKbW XhxA33Er+1OhNraUijNWjhKECGmKgR5Hjaqsz8TDqZOlZ/WmWKjpS8eZ/SpVAHXR2DvK qtSS0NCcAyYCwKi4zaQT5w9kZc7bvntfyunBiIIckGK5/3/Zp1t3s+aL18avXya01HuK nXvhhAvdM5DohQnoyNoi3atR92f7m0KTP0MOgmIMF/GfDw/Mzo2K3xoYdI4PjEkG0hqN V/JQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786975054; x=1787579854; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=WLmqosVfHRUnCpTXG/vmgJdRPIFeEEdEr21ji49UgUg=; b=gSf6WSNSJnvLrPoPTBwVJjOZ9EjUZXjG3NNjuFVL/8QgINxljSN7Oj0zYiK1qml+PP oQ48t3hQcJ8vszVO2KQaOqPG/jfz5+TyMRCQ5QH5cSIdNvjnHdwCiuID5ZnHa8ajGKq6 sEC73RenzppKVzXYTNN3A4JNph6nxtfKnIYr3hdicCDEpedDAjZGeHEQ7TDq5ZjLUkOU g5MKUG19G2VpdSWztJJ4WN2M2+Y+TVmpIMsJlNxOeJGRZEJleArrpMbYfBdezfAeNJMU MbGXqsJIv8nesaZwSuSUfMtENLH+pr/dynig/3q7zqZ+y3dD2Q6cqLB3X1CDqG3s4qWu i9jg== X-Forwarded-Encrypted: i=1; AHgh+Rrjsyv4we9VS8jD3gwXLYMop+nT1G7tneeo+D31g4jVcG+EXoFouS7JAEO3uluXJnZXBDMwNpkvy1LoUCU=@vger.kernel.org X-Gm-Message-State: AOJu0YyFuZvChy0k1J19FxE0cIORF5Os3SG0W06PEvgDaXeo5zOpKjvQ Za37zXXMiGCDZ5jERlYv7kqri8DzIGnuNwP55hv9r/Z2dGKQTOptu/Zx0LKdRfskZSg= X-Gm-Gg: AR+sD13lF12oJIe+PproMYv7EUx1/HMFBGMjn+BsJ7nO5nRLR5jOQAaDrvxhzyIKLIU m/vafYOEPRyy7V2DNFOekF59n9WkGy3989mPAbXMSE8WJiRRgxu5rWxa8RKkL3VLLpnFTUgCPxX qaBncoAX8H4koqGzuM9IxIqHpxPnmdvaarJHIrHhErEUYy+luV3jmfb1glANRK22CekVapW9DQ9 5I/NiqLFzrWpS8hENmjGSzmp/pKz62rPvrGSslHA2z2vHVSUn7WIn6S48UXlH79unx9L96K+tFD eru53MNXu8JrL0SfNSimS9Jjprbpb2Fs4uDOdr5+j8dEJA9cPsCB9IekWnEJ+ocQyFdPiCDhJ9q 3lLxc8D7pC3e+JUo1XLJmM/PjU+MRDhSp5reRXDvDCaK/8wUpLOdBN1wHOPTUeoEqYd5Dh2HFUB ONBcN8MIU5368eGKlczx9ABTD03XF3ysEEzurquo0BSfY+9vIJZWcrM2R/tdCee66mJ0ib6PD6q E6yNJzQEpBh1kMP25kpKH6pydWqCqHRUTCIjcAwM7GLfBbeQeIw/ORaYwA= X-Received: by 2002:a05:6402:234b:b0:6a3:68c2:9a9e with SMTP id 4fb4d7f45d1cf-6a38a845a42mr7135042a12.0.1786975054047; Mon, 17 Aug 2026 06:57:34 -0700 (PDT) Received: from Mac.localdomain (31-209-40-223.cust.bredband2.com. [31.209.40.223]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a3d85319b1sm810238a12.13.2026.08.17.06.57.32 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Mon, 17 Aug 2026 06:57:33 -0700 (PDT) From: Christian Lugnberg To: vkoul@kernel.org Cc: Frank.Li@kernel.org, wens@kernel.org, jernej.skrabec@gmail.com, samuel@sholland.org, dmaengine@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org, Christian Lugnberg , stable@vger.kernel.org Subject: [PATCH v3 1/2] dmaengine: sun6i: fix non-atomic read of DMA position registers Date: Mon, 17 Aug 2026 15:51:22 +0200 Message-ID: <20260817135723.12807-2-christian.lugnberg@soundtrack.io> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260817135723.12807-1-christian.lugnberg@soundtrack.io> References: <20260817135723.12807-1-christian.lugnberg@soundtrack.io> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" sun6i_get_chan_size() reads DMA_CHAN_LLI_ADDR and DMA_CHAN_CUR_CNT in two separate readl() calls with no synchronisation between them: pos =3D readl(pchan->base + DMA_CHAN_LLI_ADDR); bytes =3D readl(pchan->base + DMA_CHAN_CUR_CNT); DMA_CHAN_LLI_ADDR holds the physical address of the *next* descriptor the engine will load once the current one completes. DMA_CHAN_CUR_CNT holds the remaining byte count for the *current* descriptor. If the DMA engine advances to the next LLI entry between the two reads, pos becomes stale: it still points to what was the next descriptor at the time of the first read, but that descriptor is now the current one and CUR_CNT reflects its initial (full) byte count. The subsequent virtual-chain walk starts one entry too early and accumulates an extra full period's worth of bytes into the residue estimate. Fix this by re-reading DMA_CHAN_LLI_ADDR after DMA_CHAN_CUR_CNT and retrying if the value changed. This double-read pattern guarantees that both registers were sampled during the same descriptor interval. The cost is at most one extra readl() pair per call in the racy case, which occurs only at descriptor boundaries (~every 2 ms) and is negligible. Fixes: a90e173f3faf ("dmaengine: sun6i: Add cyclic capability") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-sonnet-4-6 Signed-off-by: Christian Lugnberg Reviewed-by: Frank Li --- drivers/dma/sun6i-dma.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/drivers/dma/sun6i-dma.c b/drivers/dma/sun6i-dma.c index f47a326dd7ff..04fe1f5042e9 100644 --- a/drivers/dma/sun6i-dma.c +++ b/drivers/dma/sun6i-dma.c @@ -354,8 +354,10 @@ static size_t sun6i_get_chan_size(struct sun6i_pchan *= pchan) size_t bytes; dma_addr_t pos; =20 - pos =3D readl(pchan->base + DMA_CHAN_LLI_ADDR); - bytes =3D readl(pchan->base + DMA_CHAN_CUR_CNT); + do { + pos =3D readl(pchan->base + DMA_CHAN_LLI_ADDR); + bytes =3D readl(pchan->base + DMA_CHAN_CUR_CNT); + } while (pos !=3D readl(pchan->base + DMA_CHAN_LLI_ADDR)); =20 if (pos =3D=3D LLI_LAST_ITEM) return bytes; --=20 2.54.0 (Apple Git-156) From nobody Mon Sep 28 21:11:15 2026 Received: from mail-ed1-f45.google.com (mail-ed1-f45.google.com [209.85.208.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4FC98442387 for ; Mon, 17 Aug 2026 13:57:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.45 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786975061; cv=none; b=FN8jrwvK1rITwp9sizjNNYqpzGxv1ffh4BkkU+1Ife872A2BKHe9gdfhltDJJoScAAcrDbjv77i1M9PleGOoGPclVKh+sYcBS+S9yhWXodWkkegWEl2M6tRPXFyqZLyY8y61m9PQ595PYNf/P8okXm7pmtFfnobD8F73ENZn9sk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786975061; c=relaxed/simple; bh=k0KzLk/Py5MfNs6v0LG2pawI7nCHX5oUhShrr2VzixE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=OE/nAMh9CjjFY80jRI3jUax5INmafpKHlk5kCQZd0ocSpcb2ADxQa+1f7jyMTOLwT6O+9FHgx2eSK+ChVKwE3kP/gQZuigzNREAmwLXeuNQyTYTQTZExrg/Vg0JveKdXo4uiFvc4bV4sVncez1tLilml7csBGzrnJYcvlGGlUwA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=soundtrack.io; spf=pass smtp.mailfrom=soundtrack.io; dkim=pass (2048-bit key) header.d=soundtrack.io header.i=@soundtrack.io header.b=hdJx5niR; arc=none smtp.client-ip=209.85.208.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=soundtrack.io Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=soundtrack.io Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=soundtrack.io header.i=@soundtrack.io header.b="hdJx5niR" Received: by mail-ed1-f45.google.com with SMTP id 4fb4d7f45d1cf-69a1c7ce59dso589363a12.3 for ; Mon, 17 Aug 2026 06:57:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=soundtrack.io; s=google; t=1786975057; x=1787579857; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=t8f5UJCABHvmBw6dzoHdGzw6KbaLnhVEoCCS6jqmRT4=; b=hdJx5niR0E94H+nb8qraeXqUsnG1zW9Iefn8aVEaWVoNUVi73xHl4faMuaxtHbGUVv 1+iCpJGw85dX1UB/Utz6R5p81h0HWeAgBnKulOzx46iLMMVclrPROTxuCJjwVZbQlJEj BsFKfCFzXNP15fGR7XUuOv2fbOj2V83Mb3824LpUbW5w/4wBhAdlzeSMKPDZ1Xtd4clT ggRJT6JrvD+zzX0n9vfH26bOkZZ1GSbFewlYrx6QCgvgjWK1K5vrVFE7fV99XilpOOK1 NJU4h+agtuSxVBcROd5IQ7P/hSI8GGLF5sAQs1lXVHhcS7XZHv+aldPuC9d162N8hFq8 fXuA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786975057; x=1787579857; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=t8f5UJCABHvmBw6dzoHdGzw6KbaLnhVEoCCS6jqmRT4=; b=NgbWuPB5PTKrWrhIiIU3YRF2eF/shRV874tK0WdcS7Dyi9JI90OT3d8bGosOCVLYX6 PKEMmMetF58uaodKgX4Y8zQmZEbltdhKSZsQhVT0Z8gdHnRi0/2OO3eNTjrgjQeHvTIZ RYZQrhqQ5EsN9HkVaRXajn3a+PSOnOZvwhC3gmGNBHtltId4JcyTIX4HLX6G5jJpXErJ pyX/RViKkk1+KjB5n7dji3J3mdJDQwljm5KVdttvyDx+/ers1dlLGPqZMZ/coYcjALTH wa43/klHN/8WlasNIHxysebSysNpqbFRWlW0s94oRYNg6cbBPc1/Zv6yt7KbAP7G5F2C 3HlA== X-Forwarded-Encrypted: i=1; AHgh+Rpnzq5pY1kotuphCsu4YYMCBB2iPi0/82291Xq/aQqBbXKSSnAoTa83HU4lm4BrdN1+8Zg+DuIbf63LrwI=@vger.kernel.org X-Gm-Message-State: AOJu0YwdWxpcdiDt7NfYRz9sLeaZqNFUHRJjjk9dXvfYMn7HPBAqhLdd igxWGluGxuXy5ZvAMjMi/FH+ljvZVq1sK8hX++DDtW9BBCWicMmx+8zSHR449m+XI2A= X-Gm-Gg: AR+sD12HHstx+hXIrdYALkfcVSCTmNZnbEccIVeP1WDTD4GD7ysPjrdHr21ZIv/tisO mwmkSG3y+0VMXklnecymC7AqIGOo0Jz1eZ+G6FyoJTthOMKX1yLWNtro9hJ8ShKMWozV6kqNh9s GXLkszAD6swtgGIUXXUCuEfpiucbGF1yn4cEikiyhcAKiZAGV0nDpCsTJsL+7w2/POw4SsDg9Wn CRh7YpLF995M3ku5tHW0796qcGjOXQMQJ3Rn3OMpbVgPkuoaPVu2PsI2STwQK0KipANZcsfPyrA aIEe8XTwTiDAc9XILv0nesmR+wcTMwx/o0nOjgJPVkFZU7UFlIF0iYibPiW6hE8mWsgvrvfGQmh Pe8FISzfKjYqTuUVOSJiqUiHarCenNpYUxPBTvZmXfoUBLjxXjriCfXepk8tW6U7sNmXFaZNHLT d6aOGHh+n+32wD2YHs8dtJja+o2n7Up2z3EaogeMBek4t6BDhn37wZSTqcvX6moOKEZ/I+Hd85t tBLjDER1fRJK8pD5cTfvzFd7St6quRWRa2icBZyNIYuJMKelRDwg5pqHow= X-Received: by 2002:a05:6402:2812:b0:6a3:8446:c56b with SMTP id 4fb4d7f45d1cf-6a38a8bf430mr6474052a12.1.1786975056608; Mon, 17 Aug 2026 06:57:36 -0700 (PDT) Received: from Mac.localdomain (31-209-40-223.cust.bredband2.com. [31.209.40.223]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a3d85319b1sm810238a12.13.2026.08.17.06.57.35 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Mon, 17 Aug 2026 06:57:36 -0700 (PDT) From: Christian Lugnberg To: vkoul@kernel.org Cc: Frank.Li@kernel.org, wens@kernel.org, jernej.skrabec@gmail.com, samuel@sholland.org, dmaengine@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org, Christian Lugnberg , stable@vger.kernel.org Subject: [PATCH v3 2/2] dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status Date: Mon, 17 Aug 2026 15:51:23 +0200 Message-ID: <20260817135723.12807-3-christian.lugnberg@soundtrack.io> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260817135723.12807-1-christian.lugnberg@soundtrack.io> References: <20260817135723.12807-1-christian.lugnberg@soundtrack.io> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" sun6i_dma_tx_status() calls vchan_find_desc() to look up the virtual descriptor for a given cookie, before checking whether the pointer vd is NULL: vd =3D vchan_find_desc(&vchan->vc, cookie); txd =3D to_sun6i_desc(&vd->tx); /* vd may be NULL here */ if (vd) { for (lli =3D txd->v_lli; ...) vchan_find_desc() returns NULL when the descriptor has already been completed or is in-flight on a physical channel and no longer present in the virtual channel's descriptor list. When vd is NULL, to_sun6i_desc() is called unconditionally on &vd->tx before the NULL check, which is undefined behaviour. Move the call inside the if (vd) guard to ensure it is only reached with a valid pointer. vd =3D vchan_find_desc(&vchan->vc, cookie); if (vd) { struct sun6i_desc *txd =3D to_sun6i_desc(&vd->tx); for (lli =3D txd->v_lli; ...) Fixes: 555859308723 ("dmaengine: sun6i: Add driver for the Allwinner A31 DM= A controller") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-sonnet-4-6 Signed-off-by: Christian Lugnberg Reviewed-by: Frank Li --- drivers/dma/sun6i-dma.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/drivers/dma/sun6i-dma.c b/drivers/dma/sun6i-dma.c index 04fe1f5042e9..7704b016aed8 100644 --- a/drivers/dma/sun6i-dma.c +++ b/drivers/dma/sun6i-dma.c @@ -981,7 +981,6 @@ static enum dma_status sun6i_dma_tx_status(struct dma_c= han *chan, struct sun6i_pchan *pchan =3D vchan->phy; struct sun6i_dma_lli *lli; struct virt_dma_desc *vd; - struct sun6i_desc *txd; enum dma_status ret; unsigned long flags; size_t bytes =3D 0; @@ -993,9 +992,9 @@ static enum dma_status sun6i_dma_tx_status(struct dma_c= han *chan, spin_lock_irqsave(&vchan->vc.lock, flags); =20 vd =3D vchan_find_desc(&vchan->vc, cookie); - txd =3D to_sun6i_desc(&vd->tx); =20 if (vd) { + struct sun6i_desc *txd =3D to_sun6i_desc(&vd->tx); for (lli =3D txd->v_lli; lli !=3D NULL; lli =3D lli->v_lli_next) bytes +=3D lli->len; } else if (!pchan || !pchan->desc) { --=20 2.54.0 (Apple Git-156)