Validity of ioremap pointer within the kernel module

From: Eduard Fuchs <hidden>
Date: 2020-08-19 13:53:26

Hello,

I am working on a driver for the McASP controller (on BeagleBone Black
device) that works outside the sound subsystem.
The following steps are performed correctly as far as I understand:
 * init() function of the module registers the "platform_driver"
 * Kernel finds the correct device in device-tree and performs the
probe() function
* in the probe() function, a "miscdevice" is created and the ressouce is
mapped with devm_platform_ioremap_resource_byname() (address and size
provided from dts).
* in the probe() function, access to the McASP registers works without
any problems.
* the probe() function is left with "return 0".

If at a later time, triggered by userspace, the open() function of
"miscdevice" is called, then a kernel fault occurs:

[ 1138.192489] DRV1: [drv_mdev_open():169]: misc device open called ...
[ 1138.192517] misc testdrv: [drv_mdev_open():170]: memory for driver
data found at 0xda9fca40
[ 1138.192526] misc testdrv: [drv_mdev_open():171]: virtual address for
McASP registers base mapped at 0xFA038000.
[ 1138.192532] DRV1: [mcasp_dump_registers():107]: Dump McASP register
information:
[ 1138.192538] 8<--- cut here ---
[ 1138.195612] Unhandled fault: external abort on non-linefetch (0x1028)
at 0xfa038000
[ 1138.203302] pgd = 13c9a0d5
[ 1138.206016] [fa038000] *pgd=48011452(bad)
[ 1138.210048] Internal error: : 1028 [#1] PREEMPT THUMB2
[ 1138.215209] Modules linked in: testdrv1(O) ti_eqep counter spidev
8021q garp stp mrp llc evdev usb_f_acm u_serial usb_f_ecm usb_f_rndis
u_ether libcomposite iptable_nat nf_nat nf_conntrack nf_defrag_ipv6
nf_defrag_ipv4 iptable_mangle iptable_filter ip_tables x_tables [last
unloaded: testdrv1]
[ 1138.241265] CPU: 0 PID: 827 Comm: tesdrv_test Tainted: G           O
    5.7.6-tmc02 #1
[ 1138.249386] Hardware name: Generic AM33XX (Flattened Device Tree)
[ 1138.255518] PC is at mcasp_dump_registers+0x1a/0x338 [testdrv1]
[ 1138.261463] LR is at mcasp_dump_registers+0x1b/0x338 [testdrv1]
[ 1138.267404] pc : [<bf8a5086>]    lr : [<bf8a5087>]    psr: 60070033
[ 1138.273694] sp : dc133d60  ip : 00000000  fp : dc133e68
[ 1138.278936] r10: bf8a608c  r9 : c0fb4c20  r8 : daee6030
[ 1138.284179] r7 : daeba000  r6 : 0000003d  r5 : bf8a610c  r4 : fa038000
[ 1138.290731] r3 : c0f05288  r2 : 00000000  r1 : 40070093  r0 : 00000044
[ 1138.297286] Flags: nZCv  IRQs on  FIQs on  Mode SVC_32  ISA Thumb
Segment none
[ 1138.304622] Control: 50c5387d  Table: 98af4019  DAC: 00000051
[ 1138.310390] Process tesdrv_test (pid: 827, stack limit = 0xcf218d31)
[ 1138.316769] Stack: (0xdc133d60 to 0xdc134000)
[ 1138.321145] 3d60: c0f05288 da9fca44 bf8a610c 0000003d daeba000
bf8a553b fa038000 da9fca44
[ 1138.329359] 3d80: c0fb4c2c bf8a54e5 c0fb4c2c c0645d41 c0a7869c
daee6030 dc351b80 daeba000
[ 1138.337572] 3da0: 00000000 dc0f3f00 dc351bac c0274d35 0000003d
c0f05288 daeba000 daee6030
[ 1138.345786] 3dc0: 00000000 c0274ca9 daeba008 daeba000 dc133f18
c026d975 da2685d8 00000000
[ 1138.353999] 3de0: 00000000 00000002 00000000 00000000 daeba000
c027c815 00000002 dfdc34b4
[ 1138.362212] 3e00: dab8c800 00000000 00000000 c010ef31 8813a18f
dc132000 8813a18f d8a35c00
[ 1138.370426] 3e20: 63c00000 00000041 8813a18f 00000002 daee6030
c0110e1f dc133edc c0f05288
[ 1138.378639] 3e40: 8813a18f daafc000 dc133f18 00000001 00000000
dc133f50 ffffff9c 00000005
[ 1138.386852] 3e60: 00000000 c027df4b db2279d0 da2685d8 7271e2e6
00000007 dc14a015 c0260183
[ 1138.395066] 3e80: 00000000 dbf154c8 daee6030 00000101 00000002
00000550 0000094c 00000000
[ 1138.403279] 3ea0: 00000000 00000000 dc133eac c026cb15 00000040
c0289997 dc0e6500 00000ff0
[ 1138.411493] 3ec0: ffffe000 004fe6ec 00000ff0 c0f05288 00000000
00000003 00000100 dc14a000
[ 1138.419706] 3ee0: 00000000 00000002 ffffff9c 00000000 dc1441ed
00000000 00000000 c0f05288
[ 1138.427919] 3f00: dc14a000 00000003 00000000 c026e1a1 00000000
c0f05288 00000000 dc130000
[ 1138.436132] 3f20: 00000004 00000100 00000001 c0f05288 d8a0f03c
dc133f60 dc133f78 00000000
[ 1138.444346] 3f40: 00000000 00000000 00000000 c026f0bb 00000000
00000000 00000000 00000000
[ 1138.452559] 3f60: 00000000 00000000 00000000 00000000 00000000
00000000 00000000 00000000
[ 1138.460772] 3f80: 00000000 c0f05288 b6fdd000 bed70c38 00000000
00000000 00000005 c0100284
[ 1138.468986] 3fa0: dc132000 c0100061 bed70c38 00000000 004fe6ec
00000000 bed70d7c 004fe6ec
[ 1138.477199] 3fc0: bed70c38 00000000 00000000 00000005 00000000
00000000 0050f000 00000000
[ 1138.485412] 3fe0: 00000000 bed70c04 004fe66b b6f59936 00070030
004fe6ec 00000000 00000000
[ 1138.493653] [<bf8a5086>] (mcasp_dump_registers [testdrv1]) from
[<bf8a5087>] (mcasp_dump_registers+0x1b/0x338 [testdrv1])
[ 1138.504660] Code: f6cb 708a f0bc da0f (6822) 2100
[ 1138.509473] ---[ end trace bb0b2efe6c81b12a ]---

Does anyone have an idea that I forgot or do wrong.

Thanks,
Eduard Fuchs

Attachments

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help