[PATCH] spi: meson-spicc: fix invalid DMA unmap on mapping failure
From: Hongjian Dai
Date: Thu Oct 08 2026 - 08:49:01 EST
meson_spicc_dma_unmap() decided whether a buffer had to be unmapped by
testing its DMA address for non-zero. On a mapping failure
dma_map_single() returns DMA_MAPPING_ERROR (typically non-zero), so the
error path in meson_spicc_transfer_one() passed that error value to
dma_unmap_single(), unmapping an address which was never mapped. The
same happened for t->rx_dma on TX mapping failure, which is not written
at all.
Initialize both addresses to DMA_MAPPING_ERROR before mapping and use
dma_mapping_error() to decide, so only buffers which were actually
mapped are unmapped.
Fixes: 18197e98353d ("spi: meson-spicc: add DMA support")
Signed-off-by: Hongjian Dai <daihongjian@xxxxxxxxxxxxxxx>
---
drivers/spi/spi-meson-spicc.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/drivers/spi/spi-meson-spicc.c b/drivers/spi/spi-meson-spicc.c
index fa2d2db2d6e7..b1f8c823d5d0 100644
--- a/drivers/spi/spi-meson-spicc.c
+++ b/drivers/spi/spi-meson-spicc.c
@@ -235,6 +235,13 @@ static int meson_spicc_dma_map(struct meson_spicc_device *spicc,
{
struct device *dev = spicc->host->dev.parent;
+ /*
+ * Mark the DMA addresses as invalid so that meson_spicc_dma_unmap()
+ * will not try to unmap a buffer which was not (successfully) mapped.
+ */
+ t->tx_dma = DMA_MAPPING_ERROR;
+ t->rx_dma = DMA_MAPPING_ERROR;
+
if (!(t->tx_buf && t->rx_buf))
return -EINVAL;
@@ -257,9 +264,9 @@ static void meson_spicc_dma_unmap(struct meson_spicc_device *spicc,
{
struct device *dev = spicc->host->dev.parent;
- if (t->tx_dma)
+ if (!dma_mapping_error(dev, t->tx_dma))
dma_unmap_single(dev, t->tx_dma, t->len, DMA_TO_DEVICE);
- if (t->rx_dma)
+ if (!dma_mapping_error(dev, t->rx_dma))
dma_unmap_single(dev, t->rx_dma, t->len, DMA_FROM_DEVICE);
}
--
2.43.0