mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: srini@kernel.org
To: gregkh@linuxfoundation.org
Cc: linux-kernel@vger.kernel.org, Srinivas Kandagatla <srini@kernel.org>
Subject: [PATCH 0/5] fastrpc: fixes for 7.2
Date: Fri, 24 Jul 2026 23:33:36 +0100	[thread overview]
Message-ID: <20260724223342.629168-1-srini@kernel.org> (raw)

From: Srinivas Kandagatla <srini@kernel.org>

Hi Greg,

This series collects a handful of fastrpc fixes that have accumulated on
the list. All patches are small, target long-standing issues, and are
tagged for stable.

The fixes fall into two buckets:

Memory leaks:
 - Audio PD memory pool never registered its initial buffer because
   pageslen was left at zero, so the pool was always empty and every
   allocation fell back to the remote heap (patch 1).
 - fastrpc_device_open() takes a channel ctx reference before allocating
   a session; the -EBUSY path on session-alloc failure never dropped it
   (patch 4).
 - fastrpc_channel_ctx_free() never destroyed ctx_idr, leaking the IDR
   backing storage on channel teardown (patch 5).

Locking / list corruption:
 - fastrpc_req_munmap() removed the buffer from fl->mmaps only after the
   DSP unmap returned, allowing two concurrent unmaps to race on the
   same entry. Detach the buffer under fl->lock first and re-add it if
   the DSP call fails (patch 2).
 - The -ERESTARTSYS path in fastrpc_internal_invoke() walked fl->mmaps
   and spliced it onto cctx->invoke_interrupted_mmaps without holding
   fl->lock, racing with every other mmaps accessor (patch 3).

Please queue for 7.2.

Thanks,
Srini

Anandu Krishnan E (1):
  misc: fastrpc: fix channel ctx ref leak when session alloc fails

Eddie Lin (1):
  misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free

Ekansh Gupta (2):
  misc: fastrpc: Fix initial memory allocation for Audio PD memory pool
  misc: fastrpc: Remove buffer from list prior to unmap operation

Junrui Luo (1):
  misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke

 drivers/misc/fastrpc.c | 27 ++++++++++++++++++---------
 1 file changed, 18 insertions(+), 9 deletions(-)

--
2.53.0


             reply	other threads:[~2026-07-24 22:33 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-24 22:33 srini [this message]
2026-07-24 22:33 ` [PATCH 1/5] misc: fastrpc: Fix initial memory allocation for Audio PD memory pool srini
2026-07-24 22:33 ` [PATCH 2/5] misc: fastrpc: Remove buffer from list prior to unmap operation srini
2026-07-24 22:33 ` [PATCH 3/5] misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke srini
2026-07-24 22:33 ` [PATCH 4/5] misc: fastrpc: fix channel ctx ref leak when session alloc fails srini
2026-07-24 22:33 ` [PATCH 5/5] misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free srini

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260724223342.629168-1-srini@kernel.org \
    --to=srini@kernel.org \
    --cc=gregkh@linuxfoundation.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®