[PATCH v2 00/11] dmaengine: miscellaneous fixes for ioat, switchtec_dma and plx_dma
From: Logan Gunthorpe
Date: Tue Jul 21 2026 - 12:24:25 EST
When reviewing the recent switchtec patchset[1], the Sashiko bot noticed
a handful of pre-existing problems in the ioat and switchtec drivers.
I attempted to fix those plus an unrelated issue reported in plxdma but
when I submitted those patches, Sashiko found even more issues[2]. (It is
relentless!).
I've fixed the issues reported with v1 of this series and the ones for the
switchtec driver. But the pre-existing issues in ioat, plxdma and the
dmaengine itself I've punted until I can find some time to dig into them.
Hopefully, this is good enough for Sashiko this time and we can get
it reviewed by real humans.
The series is based off of v7.2-rc4.
Thanks,
Logan
[1] https://lore.kernel.org/all/20260707162045.23910-1-logang@xxxxxxxxxxxx
[2] https://sashiko.dev/#/patchset/20260717221001.361421-1-logang@xxxxxxxxxxxx
Changes since v1:
* Added a fix for switchtec_dma_alloc_chan_resources()'s error path
calling disable_channel() instead of properly halting the channel
before freeing the descriptor rings. (Per Sashiko)
* Added a fix for switchtec-dma channel structs being freed without
being removed from dma_dev->channels on a registration failure,
while the channel status IRQ is still live. (Per Sashiko)
* Added a fix for switchtec_dma_remove() using swdma_dev after it may
already have been freed by dma_async_device_unregister(). (Per
Sashiko)
* Added a fix for chan_status_irq being freed with the wrong API, and
a valid vector index of 0 being incorrectly treated as unset.
(Per Sashiko)
* Made switchtec_dma_chans_release() void, since nothing checked its
return value. (Noticed while reviewing the code for these changes).
Logan Gunthorpe (11):
dmaengine: switchtec-dma: fix double-free in switchtec_dma_free_desc()
dmaengine: switchtec-dma: fix resource leak in alloc_chan_resources
dmaengine: switchtec-dma: halt channel on alloc_chan_resources error
dmaengine: switchtec-dma: fix channel leak on registration failure
dmaengine: switchtec-dma: make switchtec_dma_chans_release() void
dmaengine: switchtec-dma: unlink channels before freeing on
registration failure
dmaengine: switchtec-dma: fix use-after-free of swdma_dev in remove()
dmaengine: switchtec-dma: fix chan_status_irq cleanup on create()
error
dmaengine: ioat: disable relaxed ordering before registering the
device
dmaengine: ioat: use sysfs_emit() in per-channel sysfs show()
dmaengine: plx_dma: fix NULL pointer deref in plx_dma_isr()
drivers/dma/ioat/init.c | 18 ++++-----
drivers/dma/ioat/sysfs.c | 22 +++++------
drivers/dma/plx_dma.c | 10 ++---
drivers/dma/switchtec_dma.c | 78 +++++++++++++++++++++++++++----------
4 files changed, 82 insertions(+), 46 deletions(-)
base-commit: 1590cf0329716306e948a8fc29f1d3ee87d3989f
--
2.47.3