Re: [PATCH 3/9] dmaengine: dw-axi-dmac: Use bus width capability helpers

[email protected] Thu, 30 Jul 2026 14:36:51 +0000
Newsgroups org.kernel.vger.dmaengine
Message-ID <[email protected]>
Thank you for your contribution! Sashiko AI review found 1 potential issue(=
s) to consider:

Pre-existing issues:
- [High] This problem wasn't introduced by this patch, but the probe functi=
on contains a high-severity race condition. Early IRQ registration via `dev=
m_request_irq()` with `IRQF_SHARED` before channel registers are initialize=
d and clocks are enabled exposes a fatal race condition.
--

--- Patch [3]: [PATCH 3/9] dmaengine: dw-axi-dmac: Use bus width capability=
 helpers ---
commit b49303c13707fb73ed2de7d6198eee4906bb5793
Author: Nuno S=C3=A1 <[email protected]>

dmaengine: dw-axi-dmac: Use bus width capability helpers

Advertise the supported bus widths through dma_set_src_bus_widths()
and dma_set_dst_bus_widths() instead of assigning the legacy u32 masks
directly. This keeps the driver using the new bitmap representation
while preserving legacy fields during the transition.

> diff --git a/drivers/dma/dw-axi-dmac/dw-axi-dmac-platform.c b/drivers/dma=
/dw-axi-dmac/dw-axi-dmac-platform.c
> index bcefaff03b5c6..69cac7e3625f0 100644
> --- a/drivers/dma/dw-axi-dmac/dw-axi-dmac-platform.c
> +++ b/drivers/dma/dw-axi-dmac/dw-axi-dmac-platform.c
[ ... ]
> @@ -1482,6 +1468,20 @@ static int dw_probe(struct platform_device *pdev)
>  	unsigned int flags;
>  	u32 i;
>  	int ret;
> +	/*
> +	 * The set of bus widths supported by the DMA controller. DW AXI DMAC
> +	 * supports master data bus width up to 512 bits (for both AXI master
> +	 * interfaces), but it depends on IP block configuration.
> +	 */

[Severity: High]
This isn't a bug introduced by this patch, but while reviewing dw_probe()
I noticed a potential race condition involving early IRQ registration.

If a shared interrupt line fires immediately after devm_request_irq() is
called in axi_req_irqs(), the handler dw_axi_dma_interrupt() will execute.

Could this attempt to read from chip->regs before clocks are enabled via
axi_dma_resume(), potentially causing an external abort?

Additionally, the interrupt handler iterates over dw->chan before
chan->chan_regs is initialized in the subsequent channel initialization loop
in dw_probe():

dw_axi_dma_interrupt() {
    ...
    for (i =3D 0; i < dw->hdata->nr_channels; i++) {
        chan =3D &dw->chan[i];
        status =3D axi_chan_irq_read(chan);
        axi_chan_irq_clear(chan, status);
    ...
}

Can this cause axi_chan_irq_read() to dereference a NULL pointer when
accessing chan->chan_regs?

[ ... ]

--=20
Sashiko AI review =C2=B7 https://sashiko.dev/#/patchset/20260730-dmaengine-=
[email protected]?part=3D3