From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C895D3DDDDF for ; Tue, 26 May 2026 11:12:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779793922; cv=none; b=tLKrqnaO7++VykzP6gbasJVj2gYJGYJwNXkzBQhgSZjacgqDEh1WX05eOn9DANmRPPcDHAE9UGuFAxPXY+1ZDwC/ZtcpQS3cSBYvcdjwJ7FwxWSNjlZfIORnqbIHNdD798eetmk2yo11FteqnJylN8k4LYxjRG0/4avBdzE9qaQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779793922; c=relaxed/simple; bh=SpYFOdNS7gnBf/9Kq+Ug6hzz85x84LyutbiS5RMAVCU=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=IA5+67JEz7EI04qeLcrV5rEVTEI1TzsKVCxRL67zHXTtLb+uct+9v0AKLRuTicbZXfly8SleYHInRF1LEfQ5Vrfjns7vUJAjHMkBccyutAymr37Ng3Br0In8FElN/Fik4dJ2+QaG9wp7YQ4cqS0sE+odCwJ9KlbK1UVccyKCxXo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=EJBbWzLW; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=JusWcy0t; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="EJBbWzLW"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="JusWcy0t" Received: from pps.filterd (m0279868.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 64Q60cUx1763299 for ; Tue, 26 May 2026 11:11:59 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=qcppdkim1; bh=VhYbVLEP74Y 0H1uCZ5BG5cAHB/9WIR0BIz6pt5j6WzM=; b=EJBbWzLWaqxe+JQct1UrsjZIufP 6JZkeWQVxdln6F+30j60S7EZHsQPJZ3kbl2Xzk4LVVmQuoYttqvPdcghmlgmKHJf DiuUPNY0RUycuMhMPfrJDhXEu6DP9LB9S6mElzGRWXnG+tBSVpfnZB1JT+tY9fex zR1GRhC4oIg0vKh+gZugmJdK+JouGdM4U5WCnegAPQ7tq1xPq+lYlE2BzbEoF3pt KtTRgJkAajEM1qP3L9ofkZlIyVWb58TNXkeF/S/mQytD0RmDkmkye442jDUgSomF HxZu95BaVoJf6vC1G2aoWctKZeQsyXikQe/wT3Ow2Sg1w5dv/cdpwXLicNw== Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4ed5vgh6yx-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Tue, 26 May 2026 11:11:59 +0000 (GMT) Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-366ded3bed0so7413693a91.0 for ; Tue, 26 May 2026 04:11:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1779793919; x=1780398719; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=VhYbVLEP74Y0H1uCZ5BG5cAHB/9WIR0BIz6pt5j6WzM=; b=JusWcy0tvUOnWRWmXTqanrn15eH5xdJoe+UF46sKi1v420kZRtq0grPPu2En7i1UXQ 551TOTIFSfj4R8SCPxemB2XSBUAl4Gom7xWPMVfN6y1o0n5Mg8c/iQ9k/r1yAMhXNsyp otAc3xUlV2VsgCQEJt1gIoPBCicQM5LERY6+J7c2y6IAtyG3X3HcKsAlIZlbPEiYM/ea VkDuane4NbnMk4MB5P5XgxKQVNZM1c6osWnBwHTxodQbbGlOrzel/2GsIOUjjcxsDl40 qpcwuYwAVyKL+Dv8mhCGtbw9yAUsCkZJgUJyQ+RpvZPrDzEa6gAuHMSmvs0sAHZjPQ80 MB9g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779793919; x=1780398719; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=VhYbVLEP74Y0H1uCZ5BG5cAHB/9WIR0BIz6pt5j6WzM=; b=rosoCOWZqQ/5vg3RvgihawGvAhKV41wHNyd6v5Qm23KZeWw4coGRgiykTAe7wxGUvc URV0pmWeLoxkfU5CEtAOIK0ODhBjDH+odqnWrpbNDIfY1BBl1TQjtv1PgvPcbB+90zNS FrQ51k78JAHcKzjKceQoPHJpA0JGofGkwLA7iESEVcYlzOWVjD9ZOEwWHE7xfUK3n3Sw QT7u/inW5YVInXMI6y+z/Fzn+6VONgmUhUyGK2G0azYewW/EkonhFLo1ok+qDtkqBCTE sGzPJreiQGWLjyIon1xbLk7h/BOcMAioacGUWiUcl9+jIlUGP2zVJ6sst68v1h8Z2bhy cDNg== X-Forwarded-Encrypted: i=1; AFNElJ+RbmGD5yYcAnaoc3qduejPaYgnJ2hR6Sq3YL02yOZ4u5zbM7j0E6msxM7Zeka36aafz0Q8C3qKcioUJ1M=@vger.kernel.org X-Gm-Message-State: AOJu0YydUVUvplCB1nfqm4QfTRNIcAaYojsPILyF2VW+MzzZjyF+K3mL YQ3ItgvZbpz5ZtnEA+eYnWEyQ4JpNYm81Ym69yO5MhEfNbtS5wu3WIRRpXFHqH5ExTZyk097WEC JkvdhFs0RHwVz+lYmAcIsGiaBrz0YeA4Q6wxyTzfIfgjz3wHLZImaFu8nSggu1VMsUdU= X-Gm-Gg: Acq92OEReRWOyRcOAs/2nXG11EV79qYnUpr2qqsHO6a/DxiMQJP2aG0TLURibfU8TzX xwgC0RweW+unkwDy6NjAZd24I7wsWQROT16EdcOoqoFbOS5Ypo72ndp2pNOx2x8tdVpdVm/ObcL i370aZVviTiao09aasBQGGCQYkQXnrnXRBEC+d5EZ1eBaY86qapMenntRLG9b/BnTSJtfXaJe0I S7lwq+WaMuy6EXi61WZTwSN2+274SHjn0E8+I9dtQmwLGLzd/YVF/O02XNPwzgkVk0tz6HqN/6I QtBZEj6kpogv355yCsZOLJxT8ZlaJSEMbndAJlZXAA1pRxauYtjLFf4LwDShN+STsAlOq0pfI9R gTaEOd9wW6TI5LJgqy+c91E2spyMeYz1zmo7s41x4hQKFRe1veYlcQkSJ8fbEUzRauGpWQnybCM wB5f1BCHhBqIl/swoVLQ== X-Received: by 2002:a17:90b:2712:b0:35f:b9f1:fded with SMTP id 98e67ed59e1d1-36a6c79dd38mr13454552a91.12.1779793918506; Tue, 26 May 2026 04:11:58 -0700 (PDT) X-Received: by 2002:a17:90b:2712:b0:35f:b9f1:fded with SMTP id 98e67ed59e1d1-36a6c79dd38mr13454520a91.12.1779793917996; Tue, 26 May 2026 04:11:57 -0700 (PDT) Received: from QCOM-SocCW5bzXR.qualcomm.com (tpe-colo-wan-fw-bordernet.qualcomm.com. [103.229.16.4]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-36a72c4ce6bsm12104253a91.11.2026.05.26.04.11.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 26 May 2026 04:11:57 -0700 (PDT) From: Jianping Li To: srini@kernel.org, amahesh@qti.qualcomm.com, arnd@arndb.de, gregkh@linuxfoundation.org, abelvesa@kernel.org, jorge.ramirez@oss.qualcomm.com Cc: Jianping Li , linux-arm-msm@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, ekansh.gupta@oss.qualcomm.com, quic_chennak@quicinc.com, stable@kernel.org Subject: [PATCH v6 4/5] imisc: fastrpc: Allocate entire reserved memory for Audio PD in probe Date: Tue, 26 May 2026 19:11:23 +0800 Message-Id: <20260526111124.515-5-jianping.li@oss.qualcomm.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260526111124.515-1-jianping.li@oss.qualcomm.com> References: <20260526111124.515-1-jianping.li@oss.qualcomm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Authority-Analysis: v=2.4 cv=IrYutr/g c=1 sm=1 tr=0 ts=6a157fff cx=c_pps a=vVfyC5vLCtgYJKYeQD43oA==:117 a=nuhDOHQX5FNHPW3J6Bj6AA==:17 a=NGcC8JguVDcA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=ZpdpYltYx_vBUK5n70dp:22 a=VwQbUJbxAAAA:8 a=EUspDBNiAAAA:8 a=vXPY0jRleWu_0xqwLycA:9 a=rl5im9kqc5Lf4LNbBjHf:22 X-Proofpoint-ORIG-GUID: ZZw6fbhWw9_75m3rGtwF37ZTBh7HPleI X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNTI2MDA5NyBTYWx0ZWRfX4aZf+HymbwDb bQEiVuC2Incey5rgjEE6Yx4vrYTvKCXznkqmHK24+THMW2/GqZZWzVG++q97qDuIhsgsMv49BPs PGK7l3L53zD3l1EB4WzFMCCPbuJ2i6SROTeTMHrIWOJlBn6UOHWqykM32kw44+or39gsa5gX8mc VEXgGaYlN3LuzUaLLpen5ptySOC9NgADokIaG8R+lb1uf0rMXMXcsL9aHoWyJIjbwHNdeWmrK0q X+ASx9KJi6E+MhrVDJJYQFB/qhNz2c4knypxDr2mstoOoVudNky9i0bg7AUGCLFfaCKNNGzawKN +kZLantk+l6qOIU3i2BhVMMfvz69mfZvJrL3a3AjrJu7PpQ3Q7ucwJAgM3r5S3H2O+k6Qlj4t6f 4JrkaWm9jK/1E8YJ5KW1UhmzIj24JY2KO0C24b3o6oY9hL3K/zc5ZiiCEst3vvaJwpOXLZjip9S B+T1ArkmBGT78y8aG0w== X-Proofpoint-GUID: ZZw6fbhWw9_75m3rGtwF37ZTBh7HPleI X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-05-26_02,2026-05-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 malwarescore=0 spamscore=0 phishscore=0 priorityscore=1501 clxscore=1015 suspectscore=0 lowpriorityscore=0 impostorscore=0 adultscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2605130000 definitions=main-2605260097 Allocating and freeing Audio PD memory from userspace is unsafe because the kernel cannot reliably determine when the DSP has finished using the memory. Userspace may free buffers while they are still in use by the DSP, and remote free requests cannot be safely trusted. Additionally, the current implementation allows userspace to repeatedly grow the Audio PD heap, but does not support shrinking it. This can lead to unbounded memory usage over time, effectively causing a memory leak. Fix this by allocating the entire Audio PD reserved-memory region during rpmsg probe and tying its lifetime to the rpmsg channel. This removes userspace-controlled alloc/free and ensures that memory is reclaimed only when the DSP process is torn down. Fixes: 0871561055e66 ("misc: fastrpc: Add support for audiopd") Cc: stable@kernel.org Signed-off-by: Jianping Li --- drivers/misc/fastrpc.c | 103 ++++++++++++++++++++--------------------- 1 file changed, 50 insertions(+), 53 deletions(-) diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c index f46a8f53970d..0208208c2d27 100644 --- a/drivers/misc/fastrpc.c +++ b/drivers/misc/fastrpc.c @@ -276,6 +276,8 @@ struct fastrpc_channel_ctx { struct kref refcount; /* Flag if dsp attributes are cached */ bool valid_attributes; + /* Flag if audio PD init mem was allocated */ + bool audio_init_mem; u32 dsp_attributes[FASTRPC_MAX_DSP_ATTRIBUTES]; struct fastrpc_device *secure_fdevice; struct fastrpc_device *fdevice; @@ -1344,15 +1346,16 @@ static int fastrpc_init_create_static_process(struct fastrpc_user *fl, struct fastrpc_init_create_static init; struct fastrpc_invoke_args *args; struct fastrpc_phy_page pages[1]; + struct fastrpc_channel_ctx *cctx = fl->cctx; char *name; int err; - bool scm_done = false; struct { int client_id; u32 namelen; u32 pageslen; } inbuf; u32 sc; + unsigned long flags; if (!fl->cctx->remote_heap || !fl->cctx->remote_heap->dma_addr || @@ -1383,31 +1386,6 @@ static int fastrpc_init_create_static_process(struct fastrpc_user *fl, inbuf.client_id = fl->client_id; inbuf.namelen = init.namelen; inbuf.pageslen = 0; - if (!fl->cctx->remote_heap) { - err = fastrpc_remote_heap_alloc(fl, fl->sctx->dev, init.memlen, - &fl->cctx->remote_heap); - if (err) - goto err_name; - - /* Map if we have any heap VMIDs associated with this ADSP Static Process. */ - if (fl->cctx->vmcount) { - u64 src_perms = BIT(QCOM_SCM_VMID_HLOS); - - err = qcom_scm_assign_mem(fl->cctx->remote_heap->dma_addr, - (u64)fl->cctx->remote_heap->size, - &src_perms, - fl->cctx->vmperms, fl->cctx->vmcount); - if (err) { - dev_err(fl->sctx->dev, - "Failed to assign memory with dma_addr %pad size 0x%llx err %d\n", - &fl->cctx->remote_heap->dma_addr, - fl->cctx->remote_heap->size, err); - goto err_map; - } - scm_done = true; - inbuf.pageslen = 1; - } - } fl->pd = USER_PD; @@ -1419,8 +1397,24 @@ static int fastrpc_init_create_static_process(struct fastrpc_user *fl, args[1].length = inbuf.namelen; args[1].fd = -1; - pages[0].addr = fl->cctx->remote_heap->dma_addr; - pages[0].size = fl->cctx->remote_heap->size; + spin_lock_irqsave(&cctx->lock, flags); + if (!fl->cctx->audio_init_mem) { + if (!fl->cctx->remote_heap || + !fl->cctx->remote_heap->dma_addr || + !fl->cctx->remote_heap->size) { + spin_unlock_irqrestore(&cctx->lock, flags); + err = -ENOMEM; + goto err; + } + pages[0].addr = fl->cctx->remote_heap->dma_addr; + pages[0].size = fl->cctx->remote_heap->size; + fl->cctx->audio_init_mem = true; + inbuf.pageslen = 1; + } else { + pages[0].addr = 0; + pages[0].size = 0; + } + spin_unlock_irqrestore(&cctx->lock, flags); args[2].ptr = (u64)(uintptr_t) pages; args[2].length = sizeof(*pages); @@ -1438,27 +1432,7 @@ static int fastrpc_init_create_static_process(struct fastrpc_user *fl, return 0; err_invoke: - if (fl->cctx->vmcount && scm_done) { - u64 src_perms = 0; - struct qcom_scm_vmperm dst_perms; - u32 i; - - for (i = 0; i < fl->cctx->vmcount; i++) - src_perms |= BIT(fl->cctx->vmperms[i].vmid); - - dst_perms.vmid = QCOM_SCM_VMID_HLOS; - dst_perms.perm = QCOM_SCM_PERM_RWX; - err = qcom_scm_assign_mem(fl->cctx->remote_heap->dma_addr, - (u64)fl->cctx->remote_heap->size, - &src_perms, &dst_perms, 1); - if (err) - dev_err(fl->sctx->dev, "Failed to assign memory dma_addr %pad size 0x%llx err %d\n", - &fl->cctx->remote_heap->dma_addr, fl->cctx->remote_heap->size, err); - } -err_map: - fastrpc_buf_free(fl->cctx->remote_heap); - fl->cctx->remote_heap = NULL; -err_name: + fl->cctx->audio_init_mem = false; kfree(name); err: kfree(args); @@ -2425,12 +2399,21 @@ static int fastrpc_rpmsg_probe(struct rpmsg_device *rpdev) } } - if (domain_id == SDSP_DOMAIN_ID) { + if (domain_id == SDSP_DOMAIN_ID || domain_id == ADSP_DOMAIN_ID) { struct resource res; u64 src_perms; err = of_reserved_mem_region_to_resource(rdev->of_node, 0, &res); if (!err) { + if (domain_id == ADSP_DOMAIN_ID) { + data->remote_heap = + kzalloc_obj(*data->remote_heap, GFP_KERNEL); + if (!data->remote_heap) + return -ENOMEM; + + data->remote_heap->dma_addr = res.start; + data->remote_heap->size = resource_size(&res); + } src_perms = BIT(QCOM_SCM_VMID_HLOS); err = qcom_scm_assign_mem(res.start, resource_size(&res), &src_perms, @@ -2438,7 +2421,6 @@ static int fastrpc_rpmsg_probe(struct rpmsg_device *rpdev) if (err) goto err_free_data; } - } secure_dsp = !(of_property_read_bool(rdev->of_node, "qcom,non-secure-domain")); @@ -2519,6 +2501,7 @@ static void fastrpc_rpmsg_remove(struct rpmsg_device *rpdev) struct fastrpc_buf *buf, *b; struct fastrpc_user *user; unsigned long flags; + int err; /* No invocations past this point */ spin_lock_irqsave(&cctx->lock, flags); @@ -2536,8 +2519,22 @@ static void fastrpc_rpmsg_remove(struct rpmsg_device *rpdev) list_for_each_entry_safe(buf, b, &cctx->invoke_interrupted_mmaps, node) list_del(&buf->node); - if (cctx->remote_heap) - fastrpc_buf_free(cctx->remote_heap); + if (cctx->remote_heap && cctx->vmcount) { + u64 src_perms = 0; + struct qcom_scm_vmperm dst_perms; + + for (u32 i = 0; i < cctx->vmcount; i++) + src_perms |= BIT(cctx->vmperms[i].vmid); + + dst_perms.vmid = QCOM_SCM_VMID_HLOS; + dst_perms.perm = QCOM_SCM_PERM_RWX; + + err = qcom_scm_assign_mem(cctx->remote_heap->dma_addr, + cctx->remote_heap->size, &src_perms, + &dst_perms, 1); + if (!err) + kfree(cctx->remote_heap); + } of_platform_depopulate(&rpdev->dev); -- 2.43.0