mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] dmaengine: sh: rz-dmac: Fix off-by-one in residue lmdesc lookup
@ 2026-09-22  9:20 Claudiu Beznea
  2026-09-24 21:17 ` Frank Li
  2026-10-05 15:43 ` Vinod Koul
  0 siblings, 2 replies; 3+ messages in thread
From: Claudiu Beznea @ 2026-09-22  9:20 UTC (permalink / raw)
  To: vkoul, Frank.Li, biju.das.jz, geert+renesas
  Cc: claudiu.beznea, dmaengine, linux-kernel, linux-renesas-soc,
	Tommaso Merciai, stable, Claudiu Beznea

From: Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>

lmdesc->nxla is the address of the next descriptor, so comparing it
against CRLA, which is the address of the current descriptor,
finds the descriptor before the active one, not the active one.
The residue loops below then summed one lmdesc too many on top of
that.

Compare each descriptor's own address to CRLA instead, and add tb
after advancing to the next lmdesc.

Fixes: 21323b118c16 ("dmaengine: sh: rz-dmac: Add device_tx_status() callback")
Fixes: 172bfb57481c ("dmaengine: sh: rz-dmac: Add cyclic DMA support")
Cc: stable@vger.kernel.org
Suggested-by: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
Signed-off-by: Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>
Signed-off-by: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
---
 drivers/dma/sh/rz-dmac.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/dma/sh/rz-dmac.c b/drivers/dma/sh/rz-dmac.c
index ca76f1bb45c4..fdd7131e890a 100644
--- a/drivers/dma/sh/rz-dmac.c
+++ b/drivers/dma/sh/rz-dmac.c
@@ -937,7 +937,7 @@ static u32 rz_dmac_calculate_residue_bytes_in_vd(struct rz_dmac_chan *channel,
 	struct rz_dmac *dmac = to_rz_dmac(chan->device);
 	u32 residue = 0, i = 0;
 
-	while (lmdesc->nxla != crla) {
+	while (rz_dmac_lmdesc_addr(channel, lmdesc) != crla) {
 		lmdesc = rz_dmac_get_next_lmdesc(channel->lmdesc.base, lmdesc);
 		if (++i >= DMAC_NR_LMDESC)
 			return 0;
@@ -948,13 +948,13 @@ static u32 rz_dmac_calculate_residue_bytes_in_vd(struct rz_dmac_chan *channel,
 		u32 start_lmdesc_addr = rz_dmac_lmdesc_addr(channel, desc->start_lmdesc);
 
 		while (lmdesc->nxla != start_lmdesc_addr) {
-			residue += lmdesc->tb;
 			lmdesc = rz_dmac_get_next_lmdesc(channel->lmdesc.base, lmdesc);
+			residue += lmdesc->tb;
 		}
 	} else {
 		while (lmdesc->chcfg & CHCFG_DEM) {
-			residue += lmdesc->tb;
 			lmdesc = rz_dmac_get_next_lmdesc(channel->lmdesc.base, lmdesc);
+			residue += lmdesc->tb;
 		}
 	}
 
-- 
2.43.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] dmaengine: sh: rz-dmac: Fix off-by-one in residue lmdesc lookup
  2026-09-22  9:20 [PATCH] dmaengine: sh: rz-dmac: Fix off-by-one in residue lmdesc lookup Claudiu Beznea
@ 2026-09-24 21:17 ` Frank Li
  2026-10-05 15:43 ` Vinod Koul
  1 sibling, 0 replies; 3+ messages in thread
From: Frank Li @ 2026-09-24 21:17 UTC (permalink / raw)
  To: Claudiu Beznea
  Cc: vkoul, Frank.Li, biju.das.jz, geert+renesas, claudiu.beznea,
	dmaengine, linux-kernel, linux-renesas-soc, Tommaso Merciai,
	stable, Claudiu Beznea

On Tue, Sep 22, 2026 at 12:20:37PM +0300, Claudiu Beznea wrote:
> From: Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>
>
> lmdesc->nxla is the address of the next descriptor, so comparing it
> against CRLA, which is the address of the current descriptor,
> finds the descriptor before the active one, not the active one.
> The residue loops below then summed one lmdesc too many on top of
> that.
>
> Compare each descriptor's own address to CRLA instead, and add tb
> after advancing to the next lmdesc.
>
> Fixes: 21323b118c16 ("dmaengine: sh: rz-dmac: Add device_tx_status() callback")
> Fixes: 172bfb57481c ("dmaengine: sh: rz-dmac: Add cyclic DMA support")
> Cc: stable@vger.kernel.org
> Suggested-by: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
> Signed-off-by: Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>
> Signed-off-by: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
> ---

Reviewed-by: Frank Li <Frank.Li@nxp.com>

>  drivers/dma/sh/rz-dmac.c | 6 +++---
>  1 file changed, 3 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/dma/sh/rz-dmac.c b/drivers/dma/sh/rz-dmac.c
> index ca76f1bb45c4..fdd7131e890a 100644
> --- a/drivers/dma/sh/rz-dmac.c
> +++ b/drivers/dma/sh/rz-dmac.c
> @@ -937,7 +937,7 @@ static u32 rz_dmac_calculate_residue_bytes_in_vd(struct rz_dmac_chan *channel,
>  	struct rz_dmac *dmac = to_rz_dmac(chan->device);
>  	u32 residue = 0, i = 0;
>
> -	while (lmdesc->nxla != crla) {
> +	while (rz_dmac_lmdesc_addr(channel, lmdesc) != crla) {
>  		lmdesc = rz_dmac_get_next_lmdesc(channel->lmdesc.base, lmdesc);
>  		if (++i >= DMAC_NR_LMDESC)
>  			return 0;
> @@ -948,13 +948,13 @@ static u32 rz_dmac_calculate_residue_bytes_in_vd(struct rz_dmac_chan *channel,
>  		u32 start_lmdesc_addr = rz_dmac_lmdesc_addr(channel, desc->start_lmdesc);
>
>  		while (lmdesc->nxla != start_lmdesc_addr) {
> -			residue += lmdesc->tb;
>  			lmdesc = rz_dmac_get_next_lmdesc(channel->lmdesc.base, lmdesc);
> +			residue += lmdesc->tb;
>  		}
>  	} else {
>  		while (lmdesc->chcfg & CHCFG_DEM) {
> -			residue += lmdesc->tb;
>  			lmdesc = rz_dmac_get_next_lmdesc(channel->lmdesc.base, lmdesc);
> +			residue += lmdesc->tb;
>  		}
>  	}
>
> --
> 2.43.0
>

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] dmaengine: sh: rz-dmac: Fix off-by-one in residue lmdesc lookup
  2026-09-22  9:20 [PATCH] dmaengine: sh: rz-dmac: Fix off-by-one in residue lmdesc lookup Claudiu Beznea
  2026-09-24 21:17 ` Frank Li
@ 2026-10-05 15:43 ` Vinod Koul
  1 sibling, 0 replies; 3+ messages in thread
From: Vinod Koul @ 2026-10-05 15:43 UTC (permalink / raw)
  To: Frank.Li, biju.das.jz, geert+renesas, Claudiu Beznea
  Cc: claudiu.beznea, dmaengine, linux-kernel, linux-renesas-soc,
	Tommaso Merciai, stable, Claudiu Beznea


On Tue, 22 Sep 2026 12:20:37 +0300, Claudiu Beznea wrote:
> lmdesc->nxla is the address of the next descriptor, so comparing it
> against CRLA, which is the address of the current descriptor,
> finds the descriptor before the active one, not the active one.
> The residue loops below then summed one lmdesc too many on top of
> that.
> 
> Compare each descriptor's own address to CRLA instead, and add tb
> after advancing to the next lmdesc.
> 
> [...]

Applied, thanks!

[1/1] dmaengine: sh: rz-dmac: Fix off-by-one in residue lmdesc lookup
      commit: 9db8e502b34bc1df8078abd0169a4fa0624de3bb

Best regards,
-- 
~Vinod



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-05 15:43 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-22  9:20 [PATCH] dmaengine: sh: rz-dmac: Fix off-by-one in residue lmdesc lookup Claudiu Beznea
2026-09-24 21:17 ` Frank Li
2026-10-05 15:43 ` Vinod Koul

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®