From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8F2C03793CE for ; Tue, 2 Jun 2026 07:18:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780384692; cv=none; b=P8OAXIfQZUN2GTq4HV40gjTjuALBuzHEDf6AlF4WP7+gBcKujeWUR93PlN8luP9ai9Ep0sq0+o6EtuyA5iQjqAjq8gbBkRY8Y1PpLs7eT7dZff5RuJaISG0dbxRrfRYrYJ8NjdclSxiPvEcIrNbZjDcakxS2f4rKUlFwjJm09U0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780384692; c=relaxed/simple; bh=uwUosZaTRLvg70pMj5LLo47klKvzExFmHdJcqWxZT4Q=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=vCdmU8tsK+QZdK7LVTRAn3h6JaO8UQwZRjwR+x9cFMGUMMk66JBPIMjpLi6HCL7JisNH0PZtbcXwqp49Cym345Oe2+jBeyuD0LRb4VcMkR3JuvomvqaBl7ncejQ/Yfj71AcuZqxkzkZNPlWqdNPkdWUbIj+qWdhx3WLyZXqcFSU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=BuP1B37t; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=MMF3+cD4; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="BuP1B37t"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="MMF3+cD4" Received: from pps.filterd (m0279868.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6523j66p599787 for ; Tue, 2 Jun 2026 07:18:10 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=qcppdkim1; bh=h2rbBUksZJT YcjdAJliGesa3QsJPl7wEGaGM4JyELQc=; b=BuP1B37tHS7VbrwU9/VUo/TUYKT oAul/jxN2jFUzdSURUIKGp7AdxAaCZlWpjYlpJ4nY8mjli7ovWe777Ehxp54ElP8 pQlvNLGlKDYZpQrWAaXFI5qYGvb7wNBelhJaoAlG6G/Yk/KL/KvLXU0NP0MUcEGD IPxURgaiTerzEemUfalIlgl/BHdWzbmeIb8w1/mSlEDVx1RpnUjhpsWWIXht5ine G6V5TC5aovy90kPxlOpL2VkcVqNRtA+2DhU62KSAdKfy+6J11D/885T5vM4qOzt6 EETyxofzjM69kl3Xn3hEcWihbLSVS/oe1Q5TwkmJ5Vfp40SDZXpaK1NaQnA== Received: from mail-pj1-f71.google.com (mail-pj1-f71.google.com [209.85.216.71]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4eha8rca4w-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Tue, 02 Jun 2026 07:18:10 +0000 (GMT) Received: by mail-pj1-f71.google.com with SMTP id 98e67ed59e1d1-36d99181eaaso3119106a91.3 for ; Tue, 02 Jun 2026 00:18:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1780384689; x=1780989489; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=h2rbBUksZJTYcjdAJliGesa3QsJPl7wEGaGM4JyELQc=; b=MMF3+cD4DdP6/lXqY4B+iqR58odm3yOrFu9UjPZU0bG9QIC2nNdu9X4EPvAv4eb3Qh yWIlBPahzcNddibHzcKXJrTToYtJBiB/JsxQ/Sexbr3bW7KTp+0VuSs3qkf5CUdiQkBB eE2KJhy6W5b25bcxrt4FQSwGbV+C0wVG/6TCEh0zInDiR2fR6RVcdFBaRZitPJ2KfyRR V1Eo4Aps6lfQ4iRsX3Ds7ffrPjm4jS3v49+EDHf1oXDP7PwYJfxBTKyg9vBVljhAcDRd VN2SnoI1o7+v6F523IsQT+JHozJCGEDhDgZYHHG+Y1uI1sODIrLx/MWEfgbeorZCTRTC /kAw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780384689; x=1780989489; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=h2rbBUksZJTYcjdAJliGesa3QsJPl7wEGaGM4JyELQc=; b=EOJyck5Y7bsVcsysp1pLFwLDPVimDSbrhXV38AO38uOxr6qawK5jX2G9ok69nfmsHS zHaulhkrZjssKJY7jKWHgmJJISIK8NWVJFxfhRxF3A52x+NYPP7eU/WgNvgPlnyn8N+r FmYNxvtCUtw+fPj/HScF/A3qy/oHTB9PPysP3fLkbeRAbyeM6oet3tIhOtQYr2M6pYTx rl5r1S1lh9McdeOeJb5cbVSUzuPzYY5+D7u8vm0pXxXLc7GbWVIIXpscfi68iyCewsVf VR/SQs3fZlKTsNmcfGi7n42xg98AYk/+uWwdxrpxnKuBSYUaPzlYPwZmfWCseRFfihhZ kkBA== X-Forwarded-Encrypted: i=1; AFNElJ9HKF20jEMGMAz8AjCUKLjO2cEuyF5FLTw8DOD9s6QLlkypNNrJ4WtSsFo7/4Hr71RhcIgzTVcPeOBSSrA=@vger.kernel.org X-Gm-Message-State: AOJu0YzYCr8LQ7U6nsNQw1R5yaHRt9x0fgL3C/uxO2DgAIFT9oGzb6RW 6rrc9b1HuQO6rMTW+6nJQjmXXvCr4Brb1IGXT0SCbJXo/DpTtJG7vk2d04lFf5O4ClIVRutFSWn tna1Dz3nNz0B9RD5LLhqTMHt+AsbUXVkp5gd5Bgp60FigTwMVgZn8xBqV/mqCe2zLtGQ= X-Gm-Gg: Acq92OGz/9twXITsB5Dz6RBa0T0qakY5eIgmhS6X7PT9RLc7g6R6SA+O85trHYD0siw aHtVDtyTl2TxRTbhkVcpa+NGwWh00Ab9byeZtgB4Q1B/C+qLKs02m6drg+Ao7yX/d+I0uKtaXHV PkMJxI1vPbfNBGQkE37UgncFy/mh2a1OhUoEc47/GOFrqaRXtuMcUNiABpAJvKrL9uObxLe+ZH8 ez5DmxrsZKxAoXlOhIto6NdibnTZWzzg1KfUwm75Fb6Ia1PCsMBnE/e51UQYrSZsKu7pc7IHAaY kOeah+dn+LFMGvHOwOkjb5f0IjEmKxCPbBtanJ9uIwZXz0X5lEUetksaL1CzjNX0bnPAQXNG0WB RVgmhzCMb9j3ZsaCptbvmRCgwMmrZmN6D4fpV7qg/cHDxYuA7yXdofbrtQcI5bnqYMl7C0PQ2u2 vb3NM3g9GUg7+WDJNGr8msIRiK/M7bvA== X-Received: by 2002:a17:90b:5184:b0:36b:8824:d7cc with SMTP id 98e67ed59e1d1-36c501efef2mr13151231a91.20.1780384689410; Tue, 02 Jun 2026 00:18:09 -0700 (PDT) X-Received: by 2002:a17:90b:5184:b0:36b:8824:d7cc with SMTP id 98e67ed59e1d1-36c501efef2mr13151203a91.20.1780384688932; Tue, 02 Jun 2026 00:18:08 -0700 (PDT) Received: from QCOM-SocCW5bzXR.qualcomm.com (tpe-colo-wan-fw-bordernet.qualcomm.com. [103.229.16.4]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-36dd91c9991sm1766279a91.7.2026.06.02.00.18.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 02 Jun 2026 00:18:08 -0700 (PDT) From: Jianping Li To: srini@kernel.org, amahesh@qti.qualcomm.com, arnd@arndb.de, gregkh@linuxfoundation.org, abelvesa@kernel.org, jorge.ramirez@oss.qualcomm.com Cc: Ekansh Gupta , linux-arm-msm@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, quic_chennak@quicinc.com, stable@kernel.org, Jianping Li Subject: [PATCH v7 2/5] misc: fastrpc: Remove buffer from list prior to unmap operation Date: Tue, 2 Jun 2026 15:17:47 +0800 Message-Id: <20260602071750.526-3-jianping.li@oss.qualcomm.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260602071750.526-1-jianping.li@oss.qualcomm.com> References: <20260602071750.526-1-jianping.li@oss.qualcomm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Authority-Analysis: v=2.4 cv=aKnAb79m c=1 sm=1 tr=0 ts=6a1e83b2 cx=c_pps a=UNFcQwm+pnOIJct1K4W+Mw==:117 a=nuhDOHQX5FNHPW3J6Bj6AA==:17 a=FelO9ux0wxsA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=ZpdpYltYx_vBUK5n70dp:22 a=EUspDBNiAAAA:8 a=VwQbUJbxAAAA:8 a=8ZZxLbFAX5vHFMKIXQAA:9 a=uKXjsCUrEbL0IQVhDsJ9:22 X-Proofpoint-GUID: upGHocaBJp0td9HOFaJpAnAlXdMV7UG7 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNjAyMDA2NiBTYWx0ZWRfX2J9/6Y+F6amd 416aQ+McIdn7nhl3DPLuuPGrpl6R8xILtBxRH79XYDYQ6T4UtGI6GKtKQA+cTXvimzjY3YHryNp YyTd0zPaoq3eT0zGP0G4hc7jgpciXkaKQQQwEO0eGJ5uqBcR9938fPdXUdW9IU+uuRC/VQtkbCb VB4jtZ6B8AVxqFfzw8MSJ80ak1B0RdoWV0j7PU9JDm27mIVWed+2gNI+YnXI1q6GZ1w3G0+dRIM TZJbz/mssk5bbbNj+9+gfy8+D0Uzrb1ZJOj25G26jTPD8yQXwJ2BNgiwHze2p/Zv75zs97/zH2W T/lvrt5HJ+xV6Dmu0W86uR4HhfffQTtPq8tlHFpVa6RG8a45LtOp0KBGb9sT0iORuNR3uF/rnMB VWF77iDMlHpFMprcIf9PUYjq7zSYiWnN9c5zK7fiDstXytrizBNFNDa8aY87SNARBMRPCfSjuQ4 6Bs1/IULzIMKXtq1A8Q== X-Proofpoint-ORIG-GUID: upGHocaBJp0td9HOFaJpAnAlXdMV7UG7 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-06-01_07,2026-05-28_03,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 bulkscore=0 malwarescore=0 priorityscore=1501 adultscore=0 lowpriorityscore=0 clxscore=1015 impostorscore=0 phishscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2605210000 definitions=main-2606020066 From: Ekansh Gupta fastrpc_req_munmap_impl() is called to unmap any buffer. The buffer is getting removed from the list after it is unmapped from DSP. This can create potential race conditions if multiple threads invoke unmap concurrently, where one thread may remove the entry from the list while another thread's unmap operation is still ongoing. Fix this by removing the buffer entry from the list before calling the unmap operation. If the unmap fails, the entry is re-added to the list so that userspace can retry the unmap, or alternatively, the buffer will be cleaned up during device release when the DSP process is torn down and all DSP-side mappings are freed along with remaining buffers in the list. Fixes: 2419e55e532de ("misc: fastrpc: add mmap/unmap support") Cc: stable@kernel.org Signed-off-by: Ekansh Gupta Signed-off-by: Jianping Li --- drivers/misc/fastrpc.c | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c index 80a636962357..a8a58f889d07 100644 --- a/drivers/misc/fastrpc.c +++ b/drivers/misc/fastrpc.c @@ -1892,9 +1892,6 @@ static int fastrpc_req_munmap_impl(struct fastrpc_user *fl, struct fastrpc_buf * &args[0]); if (!err) { dev_dbg(dev, "unmmap\tpt 0x%09lx OK\n", buf->raddr); - spin_lock(&fl->lock); - list_del(&buf->node); - spin_unlock(&fl->lock); fastrpc_buf_free(buf); } else { dev_err(dev, "unmmap\tpt 0x%09lx ERROR\n", buf->raddr); @@ -1908,6 +1905,7 @@ static int fastrpc_req_munmap(struct fastrpc_user *fl, char __user *argp) struct fastrpc_buf *buf = NULL, *iter, *b; struct fastrpc_req_munmap req; struct device *dev = fl->sctx->dev; + int err; if (copy_from_user(&req, argp, sizeof(req))) return -EFAULT; @@ -1915,6 +1913,7 @@ static int fastrpc_req_munmap(struct fastrpc_user *fl, char __user *argp) spin_lock(&fl->lock); list_for_each_entry_safe(iter, b, &fl->mmaps, node) { if ((iter->raddr == req.vaddrout) && (iter->size == req.size)) { + list_del(&iter->node); buf = iter; break; } @@ -1927,7 +1926,14 @@ static int fastrpc_req_munmap(struct fastrpc_user *fl, char __user *argp) return -EINVAL; } - return fastrpc_req_munmap_impl(fl, buf); + err = fastrpc_req_munmap_impl(fl, buf); + if (err) { + spin_lock(&fl->lock); + list_add_tail(&buf->node, &fl->mmaps); + spin_unlock(&fl->lock); + } + + return err; } static int fastrpc_req_mmap(struct fastrpc_user *fl, char __user *argp) -- 2.43.0