mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] remoteproc: qcom: pas: pass no resource table when the firmware has none
@ 2026-10-05 12:54 Jorge Ramirez-Ortiz
  2026-10-05 16:12 ` Mukesh Ojha
  0 siblings, 1 reply; 3+ messages in thread
From: Jorge Ramirez-Ortiz @ 2026-10-05 12:54 UTC (permalink / raw)
  To: jorge.ramirez, andersson, mathieu.poirier, konrad.dybcio,
	mukesh.ojha, sumit.garg
  Cc: linux-arm-msm, linux-remoteproc, linux-kernel

The firmware resource table is passed to the PAS backend even when the
firmware carries none. This only works on the first boot, while the
cached pointer and its size are both zero.

Stopping the remote processor, or failing to start it, frees the cached
table and clears the pointer but leaves the size set. The next start
then pairs a NULL table with a non-zero size.

The SCM backend substitutes an empty table and hides the problem. The
TEE backend copies from the NULL pointer:

  remoteproc remoteproc2: powering up cdsp
  pc : __pi_memcpy_generic+0x110/0x22c
  lr : qcom_pas_tee_get_rsc_table+0xf4/0x25c
  Call trace:
   __pi_memcpy_generic+0x110/0x22c (P)
   qcom_pas_get_rsc_table+0x38/0x60
   qcom_pas_parse_firmware+0xa0/0x100
   rproc_boot+0x2d4/0x380
   state_store+0x40/0x100

Fixes: a4584bff63c8 ("remoteproc: pas: Extend parse_fw callback to fetch resources via SMC call")
Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
---
 drivers/remoteproc/qcom_q6v5_pas.c | 11 ++++++-----
 1 file changed, 6 insertions(+), 5 deletions(-)

diff --git a/drivers/remoteproc/qcom_q6v5_pas.c b/drivers/remoteproc/qcom_q6v5_pas.c
index a005546c265d..e871e03ba794 100644
--- a/drivers/remoteproc/qcom_q6v5_pas.c
+++ b/drivers/remoteproc/qcom_q6v5_pas.c
@@ -463,7 +463,7 @@ static int qcom_pas_parse_firmware(struct rproc *rproc, const struct firmware *f
 	struct resource_table *table = NULL;
 	size_t output_rt_size;
 	void *output_rt;
-	size_t table_sz;
+	size_t table_sz = 0;
 	int ret;
 
 	ret = qcom_register_dump_segments(rproc, fw);
@@ -476,11 +476,12 @@ static int qcom_pas_parse_firmware(struct rproc *rproc, const struct firmware *f
 		return 0;
 
 	ret = rproc_elf_load_rsc_table(rproc, fw);
-	if (ret)
+	if (ret) {
 		dev_dbg(&rproc->dev, "Failed to load resource table from firmware\n");
-
-	table = rproc->table_ptr;
-	table_sz = rproc->table_sz;
+	} else {
+		table = rproc->table_ptr;
+		table_sz = rproc->table_sz;
+	}
 
 	/*
 	 * The resources consumed by Qualcomm remote processors fall into two categories:
-- 
2.54.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] remoteproc: qcom: pas: pass no resource table when the firmware has none
  2026-10-05 12:54 [PATCH] remoteproc: qcom: pas: pass no resource table when the firmware has none Jorge Ramirez-Ortiz
@ 2026-10-05 16:12 ` Mukesh Ojha
  2026-10-05 21:01   ` Jorge Ramirez
  0 siblings, 1 reply; 3+ messages in thread
From: Mukesh Ojha @ 2026-10-05 16:12 UTC (permalink / raw)
  To: Jorge Ramirez-Ortiz
  Cc: andersson, mathieu.poirier, konrad.dybcio, sumit.garg,
	linux-arm-msm, linux-remoteproc, linux-kernel

On Mon, Oct 05, 2026 at 02:54:00PM +0200, Jorge Ramirez-Ortiz wrote:
> The firmware resource table is passed to the PAS backend even when the
> firmware carries none. This only works on the first boot, while the
> cached pointer and its size are both zero.
> 
> Stopping the remote processor, or failing to start it, frees the cached
> table and clears the pointer but leaves the size set. The next start
> then pairs a NULL table with a non-zero size.
> 
> The SCM backend substitutes an empty table and hides the problem. The
> TEE backend copies from the NULL pointer:
> 
>   remoteproc remoteproc2: powering up cdsp
>   pc : __pi_memcpy_generic+0x110/0x22c
>   lr : qcom_pas_tee_get_rsc_table+0xf4/0x25c
>   Call trace:
>    __pi_memcpy_generic+0x110/0x22c (P)
>    qcom_pas_get_rsc_table+0x38/0x60
>    qcom_pas_parse_firmware+0xa0/0x100
>    rproc_boot+0x2d4/0x380
>    state_store+0x40/0x100
> 
> Fixes: a4584bff63c8 ("remoteproc: pas: Extend parse_fw callback to fetch resources via SMC call")
> Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
> ---
>  drivers/remoteproc/qcom_q6v5_pas.c | 11 ++++++-----
>  1 file changed, 6 insertions(+), 5 deletions(-)
> 
> diff --git a/drivers/remoteproc/qcom_q6v5_pas.c b/drivers/remoteproc/qcom_q6v5_pas.c
> index a005546c265d..e871e03ba794 100644
> --- a/drivers/remoteproc/qcom_q6v5_pas.c
> +++ b/drivers/remoteproc/qcom_q6v5_pas.c
> @@ -463,7 +463,7 @@ static int qcom_pas_parse_firmware(struct rproc *rproc, const struct firmware *f
>  	struct resource_table *table = NULL;
>  	size_t output_rt_size;
>  	void *output_rt;
> -	size_t table_sz;
> +	size_t table_sz = 0;
>  	int ret;
>  
>  	ret = qcom_register_dump_segments(rproc, fw);
> @@ -476,11 +476,12 @@ static int qcom_pas_parse_firmware(struct rproc *rproc, const struct firmware *f
>  		return 0;
>  
>  	ret = rproc_elf_load_rsc_table(rproc, fw);
> -	if (ret)
> +	if (ret) {
>  		dev_dbg(&rproc->dev, "Failed to load resource table from firmware\n");
> -
> -	table = rproc->table_ptr;
> -	table_sz = rproc->table_sz;
> +	} else {
> +		table = rproc->table_ptr;
> +		table_sz = rproc->table_sz;
> +	}


Earlier code was intentional please read the comment below.. /**...*/

diff --git a/drivers/remoteproc/qcom_q6v5_pas.c b/drivers/remoteproc/qcom_q6v5_pas.c
index 2e1e39826ffa..5edb39ad5277 100644
--- a/drivers/remoteproc/qcom_q6v5_pas.c
+++ b/drivers/remoteproc/qcom_q6v5_pas.c
@@ -504,8 +504,11 @@ static int qcom_pas_parse_firmware(struct rproc *rproc, const struct firmware *f
                return 0;

        ret = rproc_elf_load_rsc_table(rproc, fw);
-       if (ret)
+       if (ret) {
                dev_dbg(&rproc->dev, "Failed to load resource table from firmware\n");
+               rproc->table_ptr =  NULL;
+               rproc->table_sz = 0;
+       }


>  
>  	/*
>  	 * The resources consumed by Qualcomm remote processors fall into two categories:
> -- 
> 2.54.0
> 

-- 
-Mukesh Ojha

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] remoteproc: qcom: pas: pass no resource table when the firmware has none
  2026-10-05 16:12 ` Mukesh Ojha
@ 2026-10-05 21:01   ` Jorge Ramirez
  0 siblings, 0 replies; 3+ messages in thread
From: Jorge Ramirez @ 2026-10-05 21:01 UTC (permalink / raw)
  To: Mukesh Ojha
  Cc: Jorge Ramirez-Ortiz, andersson, mathieu.poirier, konrad.dybcio,
	sumit.garg, linux-arm-msm, linux-remoteproc, linux-kernel

On 05/10/26 21:42:24, Mukesh Ojha wrote:
> On Mon, Oct 05, 2026 at 02:54:00PM +0200, Jorge Ramirez-Ortiz wrote:
> > The firmware resource table is passed to the PAS backend even when the
> > firmware carries none. This only works on the first boot, while the
> > cached pointer and its size are both zero.
> > 
> > Stopping the remote processor, or failing to start it, frees the cached
> > table and clears the pointer but leaves the size set. The next start
> > then pairs a NULL table with a non-zero size.
> > 
> > The SCM backend substitutes an empty table and hides the problem. The
> > TEE backend copies from the NULL pointer:
> > 
> >   remoteproc remoteproc2: powering up cdsp
> >   pc : __pi_memcpy_generic+0x110/0x22c
> >   lr : qcom_pas_tee_get_rsc_table+0xf4/0x25c
> >   Call trace:
> >    __pi_memcpy_generic+0x110/0x22c (P)
> >    qcom_pas_get_rsc_table+0x38/0x60
> >    qcom_pas_parse_firmware+0xa0/0x100
> >    rproc_boot+0x2d4/0x380
> >    state_store+0x40/0x100
> > 
> > Fixes: a4584bff63c8 ("remoteproc: pas: Extend parse_fw callback to fetch resources via SMC call")
> > Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
> > ---
> >  drivers/remoteproc/qcom_q6v5_pas.c | 11 ++++++-----
> >  1 file changed, 6 insertions(+), 5 deletions(-)
> > 
> > diff --git a/drivers/remoteproc/qcom_q6v5_pas.c b/drivers/remoteproc/qcom_q6v5_pas.c
> > index a005546c265d..e871e03ba794 100644
> > --- a/drivers/remoteproc/qcom_q6v5_pas.c
> > +++ b/drivers/remoteproc/qcom_q6v5_pas.c
> > @@ -463,7 +463,7 @@ static int qcom_pas_parse_firmware(struct rproc *rproc, const struct firmware *f
> >  	struct resource_table *table = NULL;
> >  	size_t output_rt_size;
> >  	void *output_rt;
> > -	size_t table_sz;
> > +	size_t table_sz = 0;
> >  	int ret;
> >  
> >  	ret = qcom_register_dump_segments(rproc, fw);
> > @@ -476,11 +476,12 @@ static int qcom_pas_parse_firmware(struct rproc *rproc, const struct firmware *f
> >  		return 0;
> >  
> >  	ret = rproc_elf_load_rsc_table(rproc, fw);
> > -	if (ret)
> > +	if (ret) {
> >  		dev_dbg(&rproc->dev, "Failed to load resource table from firmware\n");
> > -
> > -	table = rproc->table_ptr;
> > -	table_sz = rproc->table_sz;
> > +	} else {
> > +		table = rproc->table_ptr;
> > +		table_sz = rproc->table_sz;
> > +	}
> 
> 
> Earlier code was intentional please read the comment below.. /**...*/
> 

AFAICS the comments say that the call might pass NULL and zero as input
resources. And this patch does exactly that - it doesnt allow NULL and
non-zero.

did I miss something?








^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-05 21:01 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05 12:54 [PATCH] remoteproc: qcom: pas: pass no resource table when the firmware has none Jorge Ramirez-Ortiz
2026-10-05 16:12 ` Mukesh Ojha
2026-10-05 21:01   ` Jorge Ramirez

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®