[PATCH v3] dmaengine: nbpfaxi: Fix setting channel irqs in probe()

From: Christian Taedcke via B4 Relay

Date: Fri Jul 03 2026 - 04:10:41 EST


From: Christian Taedcke <christian.taedcke@xxxxxxxxxxxxxxx>

When one irq is used for errors and each channel gets a dedicated irq,
the total number of irqs is num_channels + 1. If the error irq is not
the last entry in irqbuf[] but an earlier one, the loop assigning
per-channel irqs terminates one iteration too early and the last
channel is left without an irq.

Iterate over all collected irqs instead of num_channels so the
error-irq skip does not shorten the effective channel count.

Fixes: 188c6ba1dd92 ("dmaengine: nbpfaxi: Fix memory corruption in probe()")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Christian Taedcke <christian.taedcke@xxxxxxxxxxxxxxx>
---
Changes in v3:
- Guard against out-of-bound writes to chan in case of an invalid eirq.
- Link to v2: https://patch.msgid.link/20260702-upstreaming-nbpfaxi-v1-v2-1-e6d6b178a278@xxxxxxxxxxxxxxx

Changes in v2:
- Advance chan only when assigning a real irq to fix out-of-bounds
memory access.
- Remove now redundant ARRAY_SIZE(irqbuf) check.
- Link to v1: https://patch.msgid.link/20260702-upstreaming-nbpfaxi-v1-v1-1-fd8ea8830cea@xxxxxxxxxxxxxxx

To: christian.taedcke-oss@xxxxxxxxxxxxxxx
To: Vinod Koul <vkoul@xxxxxxxxxx>
To: Frank Li <Frank.Li@xxxxxxxxxx>
To: Dan Carpenter <error27@xxxxxxxxx>
Cc: dmaengine@xxxxxxxxxxxxxxx
Cc: linux-kernel@xxxxxxxxxxxxxxx
---
drivers/dma/nbpfaxi.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/dma/nbpfaxi.c b/drivers/dma/nbpfaxi.c
index 05d7321629cc..b1f06f0bd0d5 100644
--- a/drivers/dma/nbpfaxi.c
+++ b/drivers/dma/nbpfaxi.c
@@ -1374,14 +1374,14 @@ static int nbpf_probe(struct platform_device *pdev)
if (irqs == num_channels + 1) {
struct nbpf_channel *chan;

- for (i = 0, chan = nbpf->chan; i < num_channels;
- i++, chan++) {
+ for (i = 0, chan = nbpf->chan; i < irqs; i++) {
/* Skip the error IRQ */
if (irqbuf[i] == eirq)
- i++;
- if (i >= ARRAY_SIZE(irqbuf))
+ continue;
+ if (chan >= nbpf->chan + num_channels)
return -EINVAL;
chan->irq = irqbuf[i];
+ chan++;
}
} else {
/* 2 IRQs and more than one channel */

---
base-commit: dc59e4fea9d83f03bad6bddf3fa2e52491777482
change-id: 20260702-upstreaming-nbpfaxi-v1-0364e355af85

Best regards,
--
Christian Taedcke <christian.taedcke@xxxxxxxxxxxxxxx>