Re: [PATCH] mmc: sdhci: unmap the bounce buffer before device release
From: Ulf Hansson
Date: Tue Aug 04 2026 - 09:55:32 EST
On Mon, Jul 27, 2026 at 4:11 PM Myeonghun Pak <mhun512@xxxxxxxxx> wrote:
>
> sdhci_allocate_bounce_buffer() allocates its buffer with devm_kmalloc()
> but maps it with dma_map_single(). The buffer is therefore released by
> devres without the streaming DMA mapping being unmapped.
>
> Register a managed action after dma_map_single() succeeds so the mapping
> is removed before devres releases the buffer. The action is registered
> only for buffers allocated and mapped by the SDHCI core, leaving buffers
> provided by host drivers under their existing ownership.
>
> Fixes: bd9b902798ab ("mmc: sdhci: Implement an SDHCI-specific bounce buffer")
> Cc: stable@xxxxxxxxxxxxxxx
> Co-developed-by: Ijae Kim <ae878000@xxxxxxxxx>
> Signed-off-by: Ijae Kim <ae878000@xxxxxxxxx>
> Signed-off-by: Myeonghun Pak <mhun512@xxxxxxxxx>
Applied for fixes, thanks!
Kind regards
Uffe
> ---
> drivers/mmc/host/sdhci.c | 16 ++++++++++++++++
> 1 file changed, 16 insertions(+)
>
> diff --git a/drivers/mmc/host/sdhci.c b/drivers/mmc/host/sdhci.c
> index e3bf901b10aa..efb4c7742fe2 100644
> --- a/drivers/mmc/host/sdhci.c
> +++ b/drivers/mmc/host/sdhci.c
> @@ -4187,6 +4187,14 @@ void __sdhci_read_caps(struct sdhci_host *host, const u16 *ver,
> }
> EXPORT_SYMBOL_GPL(__sdhci_read_caps);
>
> +static void sdhci_unmap_bounce_buffer(void *data)
> +{
> + struct sdhci_host *host = data;
> +
> + dma_unmap_single(mmc_dev(host->mmc), host->bounce_addr,
> + host->bounce_buffer_size, DMA_BIDIRECTIONAL);
> +}
> +
> static void sdhci_allocate_bounce_buffer(struct sdhci_host *host)
> {
> struct mmc_host *mmc = host->mmc;
> @@ -4247,6 +4255,14 @@ static void sdhci_allocate_bounce_buffer(struct sdhci_host *host)
> }
>
> host->bounce_buffer_size = bounce_size;
> + ret = devm_add_action_or_reset(mmc_dev(mmc),
> + sdhci_unmap_bounce_buffer, host);
> + if (ret) {
> + devm_kfree(mmc_dev(mmc), host->bounce_buffer);
> + host->bounce_buffer = NULL;
> + host->bounce_buffer_size = 0;
> + return;
> + }
>
> out:
> /* Lie about this since we're bouncing */
> --
> 2.47.1
>