From: Adrian Hunter <adrian.hunter@intel.com>
To: alexandre.belloni@bootlin.com
Cc: Frank.Li@nxp.com, billy_tsai@aspeedtech.com,
linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org
Subject: [PATCH V2 02/17] i3c: mipi-i3c-hci: Bounce short reads irrespective of the IOMMU
Date: Thu, 17 Sep 2026 22:13:41 +0300 [thread overview]
Message-ID: <20260917191356.133242-3-adrian.hunter@intel.com> (raw)
In-Reply-To: <20260917191356.133242-1-adrian.hunter@intel.com>
The controller writes whole DWORDs, so a read whose length is not a
multiple of 4 overwrites up to 3 bytes past the end of the destination
buffer. That is a property of the controller, not of the IOMMU, but the
bounce buffer that works around it was used only when the device was
IOMMU mapped. Everywhere else the buffer is left unprotected.
Drop the device_iommu_mapped() condition.
The overrun is easily seen with CONFIG_SLUB_DEBUG=y and kernel command
line options intel_iommu=off slub_debug=FZPU, which reports it as a
kmalloc redzone overwrite, like:
[kmalloc Redzone overwritten] 0xffff8a354561570e-0xffff8a354561570f @offset=1806. First byte 0x15 instead of 0xcc
=============================================================================
BUG kmalloc-8 (Not tainted): Object corrupt
Allocated in i3c_master_retrieve_dev_info+0xc1/0x760 age=40 cpu=6 pid=1
...
Freed in i3c_master_enec_disec_locked+0xeb/0x140 age=40 cpu=6 pid=1
...
WARNING: mm/slub.c:1233 at object_err+0x1c1/0x1cf, CPU#6: swapper/0/1
...
Fixes: 9e23897bca62 ("i3c: mipi-i3c-hci: Use physical device pointer with DMA API")
Cc: stable@vger.kernel.org
Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
---
Changes in V2:
Added the slub_debug report to the commit message.
drivers/i3c/master/mipi-i3c-hci/dma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/i3c/master/mipi-i3c-hci/dma.c b/drivers/i3c/master/mipi-i3c-hci/dma.c
index 7c2b20474130..5b195978f376 100644
--- a/drivers/i3c/master/mipi-i3c-hci/dma.c
+++ b/drivers/i3c/master/mipi-i3c-hci/dma.c
@@ -428,7 +428,7 @@ static void hci_dma_unmap_xfer(struct i3c_hci *hci,
static struct i3c_dma *hci_dma_map_xfer(struct device *dev, struct hci_xfer *xfer)
{
enum dma_data_direction dir = xfer->rnw ? DMA_FROM_DEVICE : DMA_TO_DEVICE;
- bool need_bounce = device_iommu_mapped(dev) && xfer->rnw && (xfer->data_len & 3);
+ bool need_bounce = xfer->rnw && (xfer->data_len & 3);
return i3c_master_dma_map_single(dev, xfer->data, xfer->data_len, need_bounce, dir);
}
--
2.53.0
next prev parent reply other threads:[~2026-09-17 19:14 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 19:13 [PATCH V2 00/17] i3c: Fixes, cleanups and HDR-DDR support Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 01/17] i3c: master: Fix out-of-bounds read in DMA bounce buffer setup Adrian Hunter
2026-09-17 19:13 ` Adrian Hunter [this message]
2026-09-17 21:21 ` [PATCH V2 02/17] i3c: mipi-i3c-hci: Bounce short reads irrespective of the IOMMU Frank Li
2026-09-17 19:13 ` [PATCH V2 03/17] i3c: mipi-i3c-hci-pci: Set drvdata before creating LTR sysfs attribute Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 04/17] i3c: master: Match ACPI targets to the correct bus controller instance Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 05/17] i3c: master: Remove stale GETSTATUS length check Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 06/17] i3c: mipi-i3c-hci: Restore controller state if i3c_hci_enable_ibi() returns an error Adrian Hunter
2026-09-17 21:23 ` Frank Li
2026-09-17 19:13 ` [PATCH V2 07/17] i3c: mipi-i3c-hci: Send DISEC before disabling IBIs in hardware Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 08/17] i3c: mipi-i3c-hci: Fix runtime PM violation in i3c_hci_free_ibi() Adrian Hunter
2026-09-17 21:32 ` Frank Li
2026-09-17 19:13 ` [PATCH V2 09/17] i3c: mipi-i3c-hci: Process multiple IBIs per interrupt Adrian Hunter
2026-09-17 21:37 ` Frank Li
2026-09-17 19:13 ` [PATCH V2 10/17] i3c: mipi-i3c-hci: Move DMA suspend/resume callbacks Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 11/17] i3c: mipi-i3c-hci: Stop rings gracefully when suspending Adrian Hunter
2026-09-17 21:40 ` Frank Li
2026-09-17 19:13 ` [PATCH V2 12/17] i3c: mipi-i3c-hci: Correct RESP_DATA_LENGTH to bits 15:0 Adrian Hunter
2026-09-17 21:42 ` Frank Li
2026-09-17 19:13 ` [PATCH V2 13/17] i3c: mipi-i3c-hci: Remove invalid transfer size limit Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 14/17] i3c: mipi-i3c-hci: Remove invalid HDR-BT and Fm/Fm+ definitions Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 15/17] i3c: mipi-i3c-hci: Support configurable device NACK retries Adrian Hunter
2026-09-18 13:44 ` Frank Li
2026-09-17 19:13 ` [PATCH V2 16/17] i3c: Restrict HDR modes to those supported by the bus and target Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 17/17] i3c: mipi-i3c-hci: Add HDR-DDR support Adrian Hunter
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260917191356.133242-3-adrian.hunter@intel.com \
--to=adrian.hunter@intel.com \
--cc=Frank.Li@nxp.com \
--cc=alexandre.belloni@bootlin.com \
--cc=billy_tsai@aspeedtech.com \
--cc=linux-i3c@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®