diff mbox

[v2] arm: davinci: fix edma dmaengine induced null pointer dereference on da830

Message ID 1362499102-16468-1-git-send-email-mporter@ti.com (mailing list archive)
State Accepted
Headers show

Commit Message

Matt Porter March 5, 2013, 3:58 p.m. UTC
This adds additional error checking to the private edma api implementation
to catch the case where the edma_alloc_slot() has an invalid controller
parameter. The edma dmaengine wrapper driver relies on this condition
being handled in order to avoid setting up a second edma dmaengine
instance on DA830.

Verfied using a DA850 with the second EDMA controller platform instance
removed to simulate a DA830 which only has a single EDMA controller.

Reported-by: Tomas Novotny <tomas@novotny.cz>
Signed-off-by: Matt Porter <mporter@ti.com>
Cc: stable@vger.kernel.org # v3.7.x+
---
v2: Move error check out of conditional to catch all cases

 arch/arm/mach-davinci/dma.c |    3 +++
 1 file changed, 3 insertions(+)

Comments

Tomas Novotny March 6, 2013, 4:57 p.m. UTC | #1
On Tue,  5 Mar 2013 10:58:22 -0500
Matt Porter <mporter@ti.com> wrote:

> This adds additional error checking to the private edma api implementation
> to catch the case where the edma_alloc_slot() has an invalid controller
> parameter. The edma dmaengine wrapper driver relies on this condition
> being handled in order to avoid setting up a second edma dmaengine
> instance on DA830.
> 
> Verfied using a DA850 with the second EDMA controller platform instance
> removed to simulate a DA830 which only has a single EDMA controller.
> 
> Reported-by: Tomas Novotny <tomas@novotny.cz>
> Signed-off-by: Matt Porter <mporter@ti.com>
> Cc: stable@vger.kernel.org # v3.7.x+
> ---
> v2: Move error check out of conditional to catch all cases
> 
>  arch/arm/mach-davinci/dma.c |    3 +++
>  1 file changed, 3 insertions(+)
> 
> diff --git a/arch/arm/mach-davinci/dma.c b/arch/arm/mach-davinci/dma.c
> index a685e97..45b7c71 100644
> --- a/arch/arm/mach-davinci/dma.c
> +++ b/arch/arm/mach-davinci/dma.c
> @@ -743,6 +743,9 @@ EXPORT_SYMBOL(edma_free_channel);
>   */
>  int edma_alloc_slot(unsigned ctlr, int slot)
>  {
> +	if (!edma_cc[ctlr])
> +		return -EINVAL;
> +
>  	if (slot >= 0)
>  		slot = EDMA_CHAN_SLOT(slot);
>  

On the TI AM1707 based custom board:

Tested-by: Tomas Novotny <tomas@novotny.cz>
Sekhar Nori March 12, 2013, 10:15 a.m. UTC | #2
On 3/6/2013 10:27 PM, Tomas Novotny wrote:
> On Tue,  5 Mar 2013 10:58:22 -0500
> Matt Porter <mporter@ti.com> wrote:
> 
>> This adds additional error checking to the private edma api implementation
>> to catch the case where the edma_alloc_slot() has an invalid controller
>> parameter. The edma dmaengine wrapper driver relies on this condition
>> being handled in order to avoid setting up a second edma dmaengine
>> instance on DA830.
>>
>> Verfied using a DA850 with the second EDMA controller platform instance
>> removed to simulate a DA830 which only has a single EDMA controller.
>>
>> Reported-by: Tomas Novotny <tomas@novotny.cz>
>> Signed-off-by: Matt Porter <mporter@ti.com>
>> Cc: stable@vger.kernel.org # v3.7.x+
>> ---
>> v2: Move error check out of conditional to catch all cases
>>
>>  arch/arm/mach-davinci/dma.c |    3 +++
>>  1 file changed, 3 insertions(+)
>>
>> diff --git a/arch/arm/mach-davinci/dma.c b/arch/arm/mach-davinci/dma.c
>> index a685e97..45b7c71 100644
>> --- a/arch/arm/mach-davinci/dma.c
>> +++ b/arch/arm/mach-davinci/dma.c
>> @@ -743,6 +743,9 @@ EXPORT_SYMBOL(edma_free_channel);
>>   */
>>  int edma_alloc_slot(unsigned ctlr, int slot)
>>  {
>> +	if (!edma_cc[ctlr])
>> +		return -EINVAL;
>> +
>>  	if (slot >= 0)
>>  		slot = EDMA_CHAN_SLOT(slot);
>>  
> 
> On the TI AM1707 based custom board:
> 
> Tested-by: Tomas Novotny <tomas@novotny.cz>

I tested it on DA830 EVM. Queuing this for v3.9-rc

Thanks,
Sekhar
diff mbox

Patch

diff --git a/arch/arm/mach-davinci/dma.c b/arch/arm/mach-davinci/dma.c
index a685e97..45b7c71 100644
--- a/arch/arm/mach-davinci/dma.c
+++ b/arch/arm/mach-davinci/dma.c
@@ -743,6 +743,9 @@  EXPORT_SYMBOL(edma_free_channel);
  */
 int edma_alloc_slot(unsigned ctlr, int slot)
 {
+	if (!edma_cc[ctlr])
+		return -EINVAL;
+
 	if (slot >= 0)
 		slot = EDMA_CHAN_SLOT(slot);