Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: - [High] dma-buf: udmabuf CPU mapping fails on arches with PAGE_SIZE > 64KB --
commit 8fabdc29555a534a611bda125124d9a796d8f300 Author: Karl Mehltretter <[email protected]> udmabuf: respect the device's maximum segment size The commit fixes how get_sg_table() allocates scatterlists by passing the device's maximum segment size to the scatterlist allocator. It returns -EINVAL if the limit is smaller than PAGE_SIZE. > diff --git a/drivers/dma-buf/udmabuf.c b/drivers/dma-buf/udmabuf.c > index df6dd00462423..018937435356e 100644 > --- a/drivers/dma-buf/udmabuf.c > +++ b/drivers/dma-buf/udmabuf.c > @@ -133,15 +133,22 @@ static struct sg_table *get_sg_table(struct device > *dev, struct dma_buf *buf, > { > struct udmabuf *ubuf = buf->priv; > struct sg_table *sg; > + unsigned int max_segment; > int ret; > > + max_segment = dma_get_max_seg_size(dev); > + /* The SG allocator requires a segment limit of at least PAGE_SIZE. */ > + if (max_segment < PAGE_SIZE) > + return ERR_PTR(-EINVAL); [Severity: High] Does this unintentionally cause CPU mappings to unconditionally fail on architectures with a PAGE_SIZE larger than 64KB? When dma_buf_begin_cpu_access() is called for a udmabuf, it invokes get_sg_table() using udmabuf_misc.this_device. Because this misc device is initialized without setting up dma_parms or max_segment_size: drivers/dma-buf/udmabuf.c:udmabuf_dev_init() { ... ret = dma_coerce_mask_and_coherent(udmabuf_misc.this_device, DMA_BIT_MASK(64)); ... } dma_get_max_seg_size() blindly returns the fallback default of SZ_64K. On architectures with a 256KB PAGE_SIZE (such as Hexagon or PowerPC), this new validation evaluates to 65536 < 262144, unconditionally returning -EINVAL and breaking all CPU mappings. > + > sg = kzalloc_obj(*sg); > if (!sg) > return ERR_PTR(-ENOMEM); > > - ret = sg_alloc_table_from_pages(sg, ubuf->pages, ubuf->pagecount, 0, > - ubuf->pagecount << PAGE_SHIFT, > - GFP_KERNEL); > + ret = sg_alloc_table_from_pages_segment(sg, ubuf->pages, > ubuf->pagecount, > + 0, ubuf->pagecount << > PAGE_SHIFT, > + max_segment, > + GFP_KERNEL); > if (ret < 0) > goto err_alloc; > -- Sashiko AI review · https://sashiko.dev/#/patchset/[email protected]?part=1
