drivers/spi/spi-rockchip-sfc.c | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-)
With rockchip,sfc-no-dma, probe skips allocating and mapping the transfer
buffer. However, controller registration failure and driver removal still
call dma_unmap_single() for that nonexistent mapping.
Guard the DMA mapping and buffer cleanup with use_dma. Keep the existing
cleanup for allocation and mapping failures on the DMA path.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.
Fixes: ee795e82e101 ("spi: rockchip-sfc: Fix DMA-API usage")
Assisted-by: OpenAI:GPT-5.6
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
---
Changes in v2:
- Guard the cleanup calls directly instead of jumping between error labels,
as suggested by Mark Brown.
drivers/spi/spi-rockchip-sfc.c | 16 ++++++++++------
1 file changed, 10 insertions(+), 6 deletions(-)
diff --git a/drivers/spi/spi-rockchip-sfc.c b/drivers/spi/spi-rockchip-sfc.c
index 662a994da60beca33358dc6af09017e88771d017..bc5537aee449e0c33c2d6ecf9d57205d432ec7b6 100644
--- a/drivers/spi/spi-rockchip-sfc.c
+++ b/drivers/spi/spi-rockchip-sfc.c
@@ -719,10 +719,12 @@ static int rockchip_sfc_probe(struct platform_device *pdev)
return 0;
err_register:
- dma_unmap_single(dev, sfc->dma_buffer, sfc->max_iosize,
- DMA_BIDIRECTIONAL);
+ if (sfc->use_dma)
+ dma_unmap_single(dev, sfc->dma_buffer, sfc->max_iosize,
+ DMA_BIDIRECTIONAL);
err_dma_map:
- free_pages((unsigned long)sfc->buffer, get_order(sfc->max_iosize));
+ if (sfc->use_dma)
+ free_pages((unsigned long)sfc->buffer, get_order(sfc->max_iosize));
err_dma:
pm_runtime_get_sync(dev);
pm_runtime_put_noidle(dev);
@@ -743,9 +745,11 @@ static void rockchip_sfc_remove(struct platform_device *pdev)
struct spi_controller *host = sfc->host;
spi_unregister_controller(host);
- dma_unmap_single(&pdev->dev, sfc->dma_buffer, sfc->max_iosize,
- DMA_BIDIRECTIONAL);
- free_pages((unsigned long)sfc->buffer, get_order(sfc->max_iosize));
+ if (sfc->use_dma) {
+ dma_unmap_single(&pdev->dev, sfc->dma_buffer, sfc->max_iosize,
+ DMA_BIDIRECTIONAL);
+ free_pages((unsigned long)sfc->buffer, get_order(sfc->max_iosize));
+ }
clk_disable_unprepare(sfc->clk);
clk_disable_unprepare(sfc->hclk);
--
2.53.0
On Sat, Sep 12, 2026 at 03:00:56PM -0400, Myeonghun Pak wrote: > With rockchip,sfc-no-dma, probe skips allocating and mapping the transfer > buffer. However, controller registration failure and driver removal still > call dma_unmap_single() for that nonexistent mapping. Please don't send new patches in reply to old patches or serieses, this makes it harder for both people and tools to understand what is going on - it can bury things in mailboxes and make it difficult to keep track of what current patches are, both for the new patches and the old ones.
Sorry about that. I'll send future revisions as new threads. 2026년 9월 13일 (일) 오전 7:34, Mark Brown <broonie@kernel.org>님이 작성: > > On Sat, Sep 12, 2026 at 03:00:56PM -0400, Myeonghun Pak wrote: > > With rockchip,sfc-no-dma, probe skips allocating and mapping the transfer > > buffer. However, controller registration failure and driver removal still > > call dma_unmap_single() for that nonexistent mapping. > > Please don't send new patches in reply to old patches or serieses, this > makes it harder for both people and tools to understand what is going > on - it can bury things in mailboxes and make it difficult to keep track > of what current patches are, both for the new patches and the old ones.
© 2016 - 2026 Red Hat, Inc.