[PATCH v3 00/11] dmaengine: miscellaneous fixes for ioat, switchtec_dma and plx_dma
Logan Gunthorpe <[email protected]> Mon, 27 Jul 2026 12:15:15 -0600
| Newsgroups | org.kernel.vger.dmaengine,org.kernel.vger.linux-kernel,org.kernel.vger.linux-pci |
|---|---|
| Message-ID | <[email protected]> |
When reviewing the recent switchtec patchset[1], the Sashiko bot noticed a handful of pre-existing problems in the ioat and switchtec drivers. I attempted to fix those plus an unrelated issue reported in plxdma but when I submitted those patches, Sashiko found even more issues[2][3] (it is relentless!). I've fixed the issues reported with v1 and v2 of this series and many of the ones for the switchtec driver. But the pre-existing issues in ioat, plxdma and the dmaengine itself I've punted until I can find some time to dig into them. The series is based off of v7.2-rc4. Thanks, Logan [1] https://lore.kernel.org/all/[email protected] [2] https://sashiko.dev/#/patchset/[email protected] [3] https://sashiko.dev/#/patchset/[email protected] Changes since v2: * Fixed a race when unlisting the channels in the error path. The interrupt needed to be disabled before hand. (Per Sashiko) * Picked up Acked-by from Dave Jiang on the two ioat patches. Changes since v1: * Added a fix for switchtec_dma_alloc_chan_resources()'s error path calling disable_channel() instead of properly halting the channel before freeing the descriptor rings. (Per Sashiko) * Added a fix for switchtec-dma channel structs being freed without being removed from dma_dev->channels on a registration failure, while the channel status IRQ is still live. (Per Sashiko) * Added a fix for switchtec_dma_remove() using swdma_dev after it may already have been freed by dma_async_device_unregister(). (Per Sashiko) * Added a fix for chan_status_irq being freed with the wrong API, and a valid vector index of 0 being incorrectly treated as unset. (Per Sashiko) * Made switchtec_dma_chans_release() void, since nothing checked its return value. (Noticed while reviewing the code for these changes). Logan Gunthorpe (11): dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc() dmaengine: switchtec-dma: fix resource leak in alloc_chan_resources dmaengine: switchtec-dma: halt channel on alloc_chan_resources error dmaengine: switchtec-dma: fix channel leak on registration failure dmaengine: switchtec-dma: make switchtec_dma_chans_release() void dmaengine: switchtec-dma: fix chan_status_irq cleanup on create() error dmaengine: switchtec-dma: disable channels before freeing on registration failure dmaengine: switchtec-dma: fix use-after-free of swdma_dev in remove() dmaengine: ioat: disable relaxed ordering before registering the device dmaengine: ioat: use sysfs_emit() in per-channel sysfs show() dmaengine: plx_dma: fix NULL pointer deref in plx_dma_isr() drivers/dma/ioat/init.c | 18 ++++---- drivers/dma/ioat/sysfs.c | 22 +++++----- drivers/dma/plx_dma.c | 10 ++--- drivers/dma/switchtec_dma.c | 84 +++++++++++++++++++++++++++---------- 4 files changed, 88 insertions(+), 46 deletions(-) base-commit: 1590cf0329716306e948a8fc29f1d3ee87d3989f -- 2.47.3