Skip to content

Commit 44bd0ec

Browse files
Fan Wugregkh
authored andcommitted
serial: amba-pl011: synchronize DMA teardown
[ Upstream commit 4409154 ] dmaengine_terminate_all() does not wait for a running callback, so the TX callback can still touch the TX buffer after it is freed. The RX poll timer reads the RX buffers without the port lock. Switch to dmaengine_terminate_sync() and delete the RX timer before freeing the buffers. Fixes: ead76f3 ("ARM: 6763/1: pl011: add optional RX DMA to PL011 v2") Cc: stable <stable@kernel.org> Assisted-by: Codex:gpt-5.6 Signed-off-by: Fan Wu <fanwu01@zju.edu.cn> Link: https://patch.msgid.link/20260731085915.326775-4-fanwu01@zju.edu.cn Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> [ changed upstream's `timer_delete_sync()` deletion to match this tree's `del_timer_sync()` spelling at the old call site ] Signed-off-by: Sasha Levin <sashal@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 18781cc commit 44bd0ec

1 file changed

Lines changed: 4 additions & 4 deletions

File tree

‎drivers/tty/serial/amba-pl011.c‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1198,7 +1198,7 @@ static void pl011_dma_shutdown(struct uart_amba_port *uap)
11981198

11991199
if (uap->using_tx_dma) {
12001200
/* In theory, this should already be done by pl011_dma_flush_buffer */
1201-
dmaengine_terminate_all(uap->dmatx.chan);
1201+
dmaengine_terminate_sync(uap->dmatx.chan);
12021202
if (uap->dmatx.queued) {
12031203
dma_unmap_single(uap->dmatx.chan->device->dev,
12041204
uap->dmatx.dma, uap->dmatx.len,
@@ -1211,12 +1211,12 @@ static void pl011_dma_shutdown(struct uart_amba_port *uap)
12111211
}
12121212

12131213
if (uap->using_rx_dma) {
1214-
dmaengine_terminate_all(uap->dmarx.chan);
1214+
if (uap->dmarx.poll_rate)
1215+
timer_delete_sync(&uap->dmarx.timer);
1216+
dmaengine_terminate_sync(uap->dmarx.chan);
12151217
/* Clean up the RX DMA */
12161218
pl011_dmabuf_free(uap->dmarx.chan, &uap->dmarx.dbuf_a, DMA_FROM_DEVICE);
12171219
pl011_dmabuf_free(uap->dmarx.chan, &uap->dmarx.dbuf_b, DMA_FROM_DEVICE);
1218-
if (uap->dmarx.poll_rate)
1219-
del_timer_sync(&uap->dmarx.timer);
12201220
uap->using_rx_dma = false;
12211221
}
12221222
}

0 commit comments

Comments
 (0)