mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Piyush Raj Chouhan <pc1598@mainlining.org>
To: Srinivas Kandagatla <srini@kernel.org>,
	Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: Ekansh Gupta <ekansh.gupta@oss.qualcomm.com>,
	linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org,
	Piyush Raj Chouhan <pc1598@mainlining.org>
Subject: [PATCH 0/1] misc: fastrpc: Fix SMMU context fault on sensors PD
Date: Sat,  3 Oct 2026 01:31:17 +0530	[thread overview]
Message-ID: <20261002200118.138837-1-pc1598@mainlining.org> (raw)

Hi Srinivas, Greg,

While bringing up the sensors DSP (SLPI) on Qualcomm SM8150 devices, I ran
into an SMMU context fault whenever userspace (hexagonrpcd) tries to attach
to the sensors protection domain (/dev/fastrpc-sdsp).

The issue comes down to fastrpc_get_args(): if the device tree defines a
stream ID (sid) for the context bank, FastRPC allocates the message buffer
through the SMMU using fastrpc_buf_alloc(). However, the sensors PD on SLPI
firmware expects this buffer in physical shared memory from the remote heap,
bypassing the context bank. Handing it an SMMU-mapped IOVA triggers an
immediate fault:

  arm-smmu 15000000.iommu: Unhandled context fault: fsr=0x402, iova=0x1fffff000, fsynr=0x330001, cbfrsynra=0x5a1, cb=11
  qcom_q6v5_pas 2400000.remoteproc: fatal error received: PDM: service 'sensor_process' crash
  remoteproc remoteproc0: crash detected in slpi: type fatal error

This patch checks for SENSORS_PD and ensures its message buffer is always
allocated from the remote heap, even when an SMMU sid is configured. Other
workloads (compute, camera, audio) remain unaffected.

After applying this fix:
- hexagonrpcd attaches cleanly without crashing SLPI or dropping pipes.
- SLPI remains up with zero SMMU faults.
- Sensor queries over QRTR/SEE (service 400) succeed and stream live
  accelerometer, gyro, and magnetometer data to userspace.

Tested on Xiaomi Redmi K20 Pro running 7.3-rc5.

Thanks,
Piyush Raj Chouhan

Piyush Raj Chouhan (1):
  misc: fastrpc: Allocate message buffer from remote heap for sensors PD

 drivers/misc/fastrpc.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

-- 
2.55.0

             reply	other threads:[~2026-10-02 20:01 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 20:01 Piyush Raj Chouhan [this message]
2026-10-02 20:01 ` [PATCH] misc: fastrpc: Allocate message buffer from remote heap for " Piyush Raj Chouhan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002200118.138837-1-pc1598@mainlining.org \
    --to=pc1598@mainlining.org \
    --cc=ekansh.gupta@oss.qualcomm.com \
    --cc=gregkh@linuxfoundation.org \
    --cc=linux-arm-msm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=srini@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®