Re: [PATCH v4 09/13] arm64: dts: qcom: sm8550: Add Iris context bank subnodes
From: sashiko-bot@kernel.org
Date: 2026-09-13 19:05:48
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: Pre-existing issues: - [High] Failure to skip address and size cells for non-matching nodes when parsing `iommu-addresses`. -- commit a702abacb77d093fbe2f72280c242fce5e476787 Author: Vikash Garodia [off-list ref] arm64: dts: qcom: sm8550: Add Iris context bank subnodes The VPU issues DMA through several SMMU streams, and the hardware does not give every stream the same addressable range. The non-pixel stream cannot address the low 600MB of IOVA space, while the pixel stream can address the full range. This patch moves the address range restriction to specific VPU streams represented as subnodes.
quoted hunk ↗ jump to hunk
diff --git a/arch/arm64/boot/dts/qcom/sm8550.dtsi b/arch/arm64/boot/dts/qcom/sm8550.dtsi index 23604436add30..60164b853ae07 100644 --- a/arch/arm64/boot/dts/qcom/sm8550.dtsi +++ b/arch/arm64/boot/dts/qcom/sm8550.dtsi
[ ... ]
quoted hunk ↗ jump to hunk
@@ -3701,6 +3699,19 @@ &config_noc SLAVE_VENUS_CFG QCOM_ICC_TAG_ACTIVE_ONLY>, */ status = "disabled"; + #address-cells = <1>; + #size-cells = <1>; + dma-ranges = <0x0 0x0 0x0 0xe0000000>; + + non-pixel { + iommus = <&apps_smmu 0x1940 0x0>; + iommu-ranges = <0x25800000 0xba800000>; + }; + + pixel { + iommus = <&apps_smmu 0x1947 0x0>; + }; +
[Severity: High]
This isn't a bug introduced by this patch, but it is a pre-existing High
severity issue that requires fixing.
Will this device tree layout expose a parser desynchronization in the IOMMU
code when handling nodes?
If an iommu-addresses property contains entries for multiple devices, the
parser fails to skip address and size cells for non-matching nodes:
drivers/iommu/of_iommu.c:of_iommu_get_resv_regions() {
if (np == dev->of_node) {
int prot = IOMMU_READ | IOMMU_WRITE;
...
maps = of_translate_dma_region(np, maps, &iova, &length);
...
}
}
Because there is no else branch to advance the maps pointer past the
address and size cells for non-matching nodes, if the parser encounters a
phandle for a different device first, it evaluates np == dev->of_node as
false.
In the next loop iteration, the parser then misinterprets the first address
cell of the skipped entry as the next phandle.
Could this desynchronization cause the parser to miss IOMMU reserved regions,
allowing the IOMMU allocator to allocate IOVA addresses that overlap with
reserved physical memory regions and resulting in SMMU faults or memory
corruption?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260914-vpu_iommu_iova_handling-v4-0-9b9074a73c41@oss.qualcomm.com?part=9