* [PATCH 1/4] dmaengine: ti: omap-dma: fix missing return in probe error path
2026-05-31 2:05 [PATCH 0/4] dmaengine: ti: omap-dma: various bug fixes Rosen Penev
@ 2026-05-31 2:05 ` Rosen Penev
2026-05-31 2:05 ` [PATCH 2/4] dmaengine: ti: omap-dma: fix notifier leak in remove Rosen Penev
` (2 subsequent siblings)
3 siblings, 0 replies; 5+ messages in thread
From: Rosen Penev @ 2026-05-31 2:05 UTC (permalink / raw)
To: dmaengine; +Cc: Peter Ujfalusi, Vinod Koul, Frank Li, Haotian Zhang, open list
If of_dma_controller_register() fails, the error path omits the return
statement, causing probe to continue (and eventually succeed) despite
the DMA controller not being registered. Add the missing return rc;.
Fixes: 2e1136acf8a8 ("dmaengine: omap-dma: fix dma_pool resource leak in error paths")
Cc: stable@vger.kernel.org
Assisted-by: Opencode:BigPickle
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
drivers/dma/ti/omap-dma.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/dma/ti/omap-dma.c b/drivers/dma/ti/omap-dma.c
index 55ece7fd0d99..0f6dd6b0a301 100644
--- a/drivers/dma/ti/omap-dma.c
+++ b/drivers/dma/ti/omap-dma.c
@@ -1828,6 +1828,7 @@ static int omap_dma_probe(struct platform_device *pdev)
if (od->ll123_supported)
dma_pool_destroy(od->desc_pool);
omap_dma_free(od);
+ return rc;
}
}
--
2.54.0
^ permalink raw reply [flat|nested] 5+ messages in thread* [PATCH 2/4] dmaengine: ti: omap-dma: fix notifier leak in remove
2026-05-31 2:05 [PATCH 0/4] dmaengine: ti: omap-dma: various bug fixes Rosen Penev
2026-05-31 2:05 ` [PATCH 1/4] dmaengine: ti: omap-dma: fix missing return in probe error path Rosen Penev
@ 2026-05-31 2:05 ` Rosen Penev
2026-05-31 2:05 ` [PATCH 3/4] dmaengine: ti: omap-dma: fix dma_pool_destroy before omap_dma_free in error paths Rosen Penev
2026-05-31 2:05 ` [PATCH 4/4] dmaengine: ti: omap-dma: fix interrupt handling in remove Rosen Penev
3 siblings, 0 replies; 5+ messages in thread
From: Rosen Penev @ 2026-05-31 2:05 UTC (permalink / raw)
To: dmaengine; +Cc: Peter Ujfalusi, Vinod Koul, Frank Li, Haotian Zhang, open list
The notifier may be registered for needs_busy_check (omap2420) rather than
may_lose_context (omap3). The remove path only checks may_lose_context,
leaving the notifier registered during driver removal. Check both flags.
Fixes: 2e1136acf8a8 ("dmaengine: omap-dma: fix dma_pool resource leak in error paths")
Cc: stable@vger.kernel.org
Assisted-by: Opencode:BigPickle
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
drivers/dma/ti/omap-dma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma/ti/omap-dma.c b/drivers/dma/ti/omap-dma.c
index 0f6dd6b0a301..839e04f53fc2 100644
--- a/drivers/dma/ti/omap-dma.c
+++ b/drivers/dma/ti/omap-dma.c
@@ -1853,7 +1853,7 @@ static void omap_dma_remove(struct platform_device *pdev)
struct omap_dmadev *od = platform_get_drvdata(pdev);
int irq;
- if (od->cfg->may_lose_context)
+ if (od->cfg->needs_busy_check || od->cfg->may_lose_context)
cpu_pm_unregister_notifier(&od->nb);
if (pdev->dev.of_node)
--
2.54.0
^ permalink raw reply [flat|nested] 5+ messages in thread* [PATCH 3/4] dmaengine: ti: omap-dma: fix dma_pool_destroy before omap_dma_free in error paths
2026-05-31 2:05 [PATCH 0/4] dmaengine: ti: omap-dma: various bug fixes Rosen Penev
2026-05-31 2:05 ` [PATCH 1/4] dmaengine: ti: omap-dma: fix missing return in probe error path Rosen Penev
2026-05-31 2:05 ` [PATCH 2/4] dmaengine: ti: omap-dma: fix notifier leak in remove Rosen Penev
@ 2026-05-31 2:05 ` Rosen Penev
2026-05-31 2:05 ` [PATCH 4/4] dmaengine: ti: omap-dma: fix interrupt handling in remove Rosen Penev
3 siblings, 0 replies; 5+ messages in thread
From: Rosen Penev @ 2026-05-31 2:05 UTC (permalink / raw)
To: dmaengine; +Cc: Peter Ujfalusi, Vinod Koul, Frank Li, Haotian Zhang, open list
omap_dma_free() tears down channels and may free t2_desc entries from
the descriptor pool via tasklet cleanup. Destroying the pool before
omap_dma_free() is a use-after-free. Move omap_dma_free() ahead of
dma_pool_destroy() in both probe error paths and the remove path.
Fixes: 2e1136acf8a8 ("dmaengine: omap-dma: fix dma_pool resource leak in error paths")
Cc: stable@vger.kernel.org
Assisted-by: Opencode:BigPickle
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
drivers/dma/ti/omap-dma.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/dma/ti/omap-dma.c b/drivers/dma/ti/omap-dma.c
index 839e04f53fc2..fd1ad3b4268c 100644
--- a/drivers/dma/ti/omap-dma.c
+++ b/drivers/dma/ti/omap-dma.c
@@ -1808,9 +1808,9 @@ static int omap_dma_probe(struct platform_device *pdev)
if (rc) {
pr_warn("OMAP-DMA: failed to register slave DMA engine device: %d\n",
rc);
+ omap_dma_free(od);
if (od->ll123_supported)
dma_pool_destroy(od->desc_pool);
- omap_dma_free(od);
return rc;
}
@@ -1825,9 +1825,9 @@ static int omap_dma_probe(struct platform_device *pdev)
if (rc) {
pr_warn("OMAP-DMA: failed to register DMA controller\n");
dma_async_device_unregister(&od->ddev);
+ omap_dma_free(od);
if (od->ll123_supported)
dma_pool_destroy(od->desc_pool);
- omap_dma_free(od);
return rc;
}
}
@@ -1869,10 +1869,10 @@ static void omap_dma_remove(struct platform_device *pdev)
omap_dma_glbl_write(od, IRQENABLE_L0, 0);
}
+ omap_dma_free(od);
+
if (od->ll123_supported)
dma_pool_destroy(od->desc_pool);
-
- omap_dma_free(od);
}
static const struct omap_dma_config omap2420_data = {
--
2.54.0
^ permalink raw reply [flat|nested] 5+ messages in thread* [PATCH 4/4] dmaengine: ti: omap-dma: fix interrupt handling in remove
2026-05-31 2:05 [PATCH 0/4] dmaengine: ti: omap-dma: various bug fixes Rosen Penev
` (2 preceding siblings ...)
2026-05-31 2:05 ` [PATCH 3/4] dmaengine: ti: omap-dma: fix dma_pool_destroy before omap_dma_free in error paths Rosen Penev
@ 2026-05-31 2:05 ` Rosen Penev
3 siblings, 0 replies; 5+ messages in thread
From: Rosen Penev @ 2026-05-31 2:05 UTC (permalink / raw)
To: dmaengine; +Cc: Peter Ujfalusi, Vinod Koul, Frank Li, Haotian Zhang, open list
The remove path had three pre-existing bugs:
1. Interrupts are enabled via IRQENABLE_L1 in probe and alloc_chan_resources,
but the remove path writes to IRQENABLE_L0, which has no effect on the L1
interrupt line. The DMA engine can continue asserting its IRQ during
removal. Write to IRQENABLE_L1 instead.
2. devm_free_irq() was called before disabling hardware interrupts. With
IRQF_SHARED, the hardware may still assert the IRQ line after the handler
is freed, causing unhandled interrupts that can lead to the kernel
permanently disabling the shared IRQ line. Disable interrupts first.
3. platform_get_irq() return value was not checked before devm_free_irq().
If it returns an error code (<= 0), passing it to devm_free_irq() is
incorrect. Add a guard.
Fixes: 2e1136acf8a8 ("dmaengine: omap-dma: fix dma_pool resource leak in error paths")
Cc: stable@vger.kernel.org
Assisted-by: Opencode:BigPickle
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
drivers/dma/ti/omap-dma.c | 11 ++++++-----
1 file changed, 6 insertions(+), 5 deletions(-)
diff --git a/drivers/dma/ti/omap-dma.c b/drivers/dma/ti/omap-dma.c
index fd1ad3b4268c..ad90ca226db3 100644
--- a/drivers/dma/ti/omap-dma.c
+++ b/drivers/dma/ti/omap-dma.c
@@ -1859,16 +1859,17 @@ static void omap_dma_remove(struct platform_device *pdev)
if (pdev->dev.of_node)
of_dma_controller_free(pdev->dev.of_node);
- irq = platform_get_irq(pdev, 1);
- devm_free_irq(&pdev->dev, irq, od);
-
dma_async_device_unregister(&od->ddev);
if (!omap_dma_legacy(od)) {
- /* Disable all interrupts */
- omap_dma_glbl_write(od, IRQENABLE_L0, 0);
+ od->irq_enable_mask = 0;
+ omap_dma_glbl_write(od, IRQENABLE_L1, 0);
}
+ irq = platform_get_irq(pdev, 1);
+ if (irq > 0)
+ devm_free_irq(&pdev->dev, irq, od);
+
omap_dma_free(od);
if (od->ll123_supported)
--
2.54.0
^ permalink raw reply [flat|nested] 5+ messages in thread