]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
thunderbolt: stream: Unmap buffers with mapped size
authorXu Rao <raoxu@uniontech.com>
Thu, 11 Jun 2026 06:45:30 +0000 (14:45 +0800)
committerMika Westerberg <mika.westerberg@linux.intel.com>
Mon, 27 Jul 2026 09:58:54 +0000 (11:58 +0200)
The size passed to dma_unmap_page() must match the size used for the
corresponding dma_map_page() call.

Stream RX and TX buffers are mapped with TB_MAX_FRAME_SIZE when the
buffer pools are allocated. However, tbstream_ring_free() currently uses
tb_ring_frame_size() as the unmap size.

That helper returns the current frame payload size, not the DMA mapping
size. On the TX path, tbstream_dev_alloc_tx() stores a shorter payload
length in frame.size when the payload is smaller than TB_MAX_FRAME_SIZE.
This happens for a short final DATA frame, and also for the CLOSE frame,
which is allocated with SZ_256.

In those cases the buffer was mapped with TB_MAX_FRAME_SIZE, but
tb_ring_frame_size() returns the shorter frame payload length. This makes
the dma_unmap_page() size differ from the original dma_map_page() size.

Use TB_MAX_FRAME_SIZE when unmapping stream buffers so the unmap size
matches the DMA mapping size used by the buffer allocation paths.

Signed-off-by: Xu Rao <raoxu@uniontech.com>
Fixes: 6db21d817b43 ("thunderbolt: Add support for USB4STREAM")
Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
drivers/thunderbolt/stream.c

index c1f5c55583d069c811d25df95f4e90136255d585..4cc86d8d6491839dc5c057b4cfaee63472d7c1ab 100644 (file)
@@ -257,7 +257,7 @@ static void tbstream_ring_free(struct tbstream_ring *ring)
 
                if (sf->frame.buffer_phy)
                        dma_unmap_page(dma_dev, sf->frame.buffer_phy,
-                                      tb_ring_frame_size(&sf->frame), dir);
+                                      TB_MAX_FRAME_SIZE, dir);
                sf->frame.buffer_phy = 0;
                if (sf->page)
                        __free_page(sf->page);