Skip to content

Two minor rp1-pio fixes - #7664

Merged
pelwell merged 2 commits into
raspberrypi:rpi-6.18.yfrom
pelwell:rp1pio
Sep 30, 2026
Merged

pelwell merged 2 commits into
raspberrypi:rpi-6.18.yfrom
pelwell:rp1pio

Conversation

@pelwell

@pelwell pelwell commented Sep 29, 2026

Copy link
Copy Markdown
Contributor
  1. Use the correct DMA device pointer in the DMA free calls.
  2. Set dma->cyclic earlier so it is available to rp1_pio_sm_dma_free in the error path.
  3. Set an error code in the case that the cyclic preparation fails.

Although it hasn't been an issue due to the specifics of the Pi 5
platform, DMA buffers should be allocated and freed with the same "dev"
parameter. Guarantee that by deriving the dev pointer from the given
dma_info pointer.

Signed-off-by: Phil Elwell <phil@raspberrypi.com>
@popcornmix

Copy link
Copy Markdown
Collaborator

misc: rp1-pio: Use the correct dev in dma_free

Looks good. dma_dev is read before dma_release_channel(), and dma->chan is valid on every path that reaches the free.

misc: rp1-pio: Minor cyclic DMA error path fixes

  • Failing the cyclic allocation still takes the wrong path. dma->cyclic = cyclic now comes after the dma_alloc_coherent() has succeeded. But dma->buf_count = buf_count is set before it. If that allocation fails, rp1_pio_sm_dma_free() sees cyclic == false and buf_count == N, and runs the non-cyclic loop over bufs[0..N-1]. bufs[0].buf is NULL (dma_free_coherent() ignores that). bufs[1..] still hold pointers from an earlier non-cyclic configuration of that SM, which have already been freed, because rp1_pio_sm_dma_free() never clears them. So this is a double free. User space can trigger it easily: close after a non-cyclic configuration of an SM, then ask for a cyclic buf_size * buf_count too large to allocate. The simplest fix is to set dma->cyclic = cyclic before the allocation: the cyclic branch of the free then passes a NULL bufs[0].buf, which is harmless. Clearing buf/dma_addr after freeing would also stop stale pointers doing damage later.
  • Nit: the other "DMA preparation failed" paths return -EIO. -ENOMEM here is defensible, but -EIO would match them.

1. Set dma->cyclic earlier so it is available to rp1_pio_sm_dma_free in
   the error path.

2. Set an error code in the case that the cyclic preparation fails.

Signed-off-by: Phil Elwell <phil@raspberrypi.com>
@pelwell
pelwell merged commit ccae069 into raspberrypi:rpi-6.18.y Sep 30, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants