* [PATCH 0/1] misc: fastrpc: Fix SMMU context fault on sensors PD
@ 2026-10-02 20:01 Piyush Raj Chouhan
2026-10-02 20:01 ` [PATCH] misc: fastrpc: Allocate message buffer from remote heap for " Piyush Raj Chouhan
0 siblings, 1 reply; 2+ messages in thread
From: Piyush Raj Chouhan @ 2026-10-02 20:01 UTC (permalink / raw)
To: Srinivas Kandagatla, Greg Kroah-Hartman
Cc: Ekansh Gupta, linux-arm-msm, linux-kernel, Piyush Raj Chouhan
Hi Srinivas, Greg,
While bringing up the sensors DSP (SLPI) on Qualcomm SM8150 devices, I ran
into an SMMU context fault whenever userspace (hexagonrpcd) tries to attach
to the sensors protection domain (/dev/fastrpc-sdsp).
The issue comes down to fastrpc_get_args(): if the device tree defines a
stream ID (sid) for the context bank, FastRPC allocates the message buffer
through the SMMU using fastrpc_buf_alloc(). However, the sensors PD on SLPI
firmware expects this buffer in physical shared memory from the remote heap,
bypassing the context bank. Handing it an SMMU-mapped IOVA triggers an
immediate fault:
arm-smmu 15000000.iommu: Unhandled context fault: fsr=0x402, iova=0x1fffff000, fsynr=0x330001, cbfrsynra=0x5a1, cb=11
qcom_q6v5_pas 2400000.remoteproc: fatal error received: PDM: service 'sensor_process' crash
remoteproc remoteproc0: crash detected in slpi: type fatal error
This patch checks for SENSORS_PD and ensures its message buffer is always
allocated from the remote heap, even when an SMMU sid is configured. Other
workloads (compute, camera, audio) remain unaffected.
After applying this fix:
- hexagonrpcd attaches cleanly without crashing SLPI or dropping pipes.
- SLPI remains up with zero SMMU faults.
- Sensor queries over QRTR/SEE (service 400) succeed and stream live
accelerometer, gyro, and magnetometer data to userspace.
Tested on Xiaomi Redmi K20 Pro running 7.3-rc5.
Thanks,
Piyush Raj Chouhan
Piyush Raj Chouhan (1):
misc: fastrpc: Allocate message buffer from remote heap for sensors PD
drivers/misc/fastrpc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--
2.55.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* [PATCH] misc: fastrpc: Allocate message buffer from remote heap for sensors PD
2026-10-02 20:01 [PATCH 0/1] misc: fastrpc: Fix SMMU context fault on sensors PD Piyush Raj Chouhan
@ 2026-10-02 20:01 ` Piyush Raj Chouhan
0 siblings, 0 replies; 2+ messages in thread
From: Piyush Raj Chouhan @ 2026-10-02 20:01 UTC (permalink / raw)
To: Srinivas Kandagatla, Greg Kroah-Hartman
Cc: Ekansh Gupta, linux-arm-msm, linux-kernel, Piyush Raj Chouhan,
Robin Snyders
The sensors protection domain reaches the message buffer directly rather
than through its context bank, so it requires an allocation from the
reserved remote heap memory pool. Using a context-bank buffer allocation
leaves the DSP addressing memory that is not mapped in its address space,
triggering an SMMU context fault (e.g. 0x1fffff000) or bus stall.
Ensure the remote heap is used for SENSORS_PD invocations even when
a stream ID (sid) is present.
Suggested-by: Robin Snyders <robin@snyders.xyz>
Signed-off-by: Piyush Raj Chouhan <pc1598@mainlining.org>
---
drivers/misc/fastrpc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c
index d4fac2caca86..8f39f4bed20e 100644
--- a/drivers/misc/fastrpc.c
+++ b/drivers/misc/fastrpc.c
@@ -1099,7 +1099,7 @@ static int fastrpc_get_args(u32 kernel, struct fastrpc_invoke_ctx *ctx)
ctx->msg_sz = pkt_size;
- if (ctx->fl->sctx->sid)
+ if (ctx->fl->sctx->sid && ctx->fl->pd != SENSORS_PD)
err = fastrpc_buf_alloc(ctx->fl, dev, pkt_size, &ctx->buf);
else
err = fastrpc_remote_heap_alloc(ctx->fl, dev, pkt_size, &ctx->buf);
--
2.55.0
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-02 20:02 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-02 20:01 [PATCH 0/1] misc: fastrpc: Fix SMMU context fault on sensors PD Piyush Raj Chouhan
2026-10-02 20:01 ` [PATCH] misc: fastrpc: Allocate message buffer from remote heap for " Piyush Raj Chouhan
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®