mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v1 0/3] misc: fastrpc: fix UAF and Oops around SSR teardown
@ 2026-10-07  8:44 Jianping Li
  2026-10-07  8:44 ` [PATCH v1 1/3] misc: fastrpc: initialise channel refcount before exposing the misc device Jianping Li
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Jianping Li @ 2026-10-07  8:44 UTC (permalink / raw)
  To: Srinivas Kandagatla, Ekansh Gupta
  Cc: Jianping Li, Arnd Bergmann, Greg Kroah-Hartman, Thierry Escande,
	linux-arm-msm, dri-devel, linux-kernel, quic_chennak

On Hamoa (X1E80100) IoT EVK the ADSP can restart repeatedly, and every
restart has a chance of taking the kernel down with it:

  Unable to handle kernel paging request at virtual address fffffdffc1ffffc0
  Internal error: Oops: 0000000096000006
  CPU: 5 UID: 0 PID: 2766 Comm: adsprpcd
  pc : ___free_pages+0x24/0xe0
  Call trace:
    ___free_pages
    __free_pages
    __dma_direct_free_pages
    dma_direct_free
    dma_free_attrs
    fastrpc_context_free [fastrpc]
    fastrpc_internal_invoke [fastrpc]
    fastrpc_device_ioctl [fastrpc]

The faulting address decodes to a struct page for a PFN that has no
vmemmap backing. It comes from dma_free_coherent() being called against
a qcom,fastrpc-compute-cb device that of_platform_depopulate() has
already unbound: with the IOMMU torn down, the call falls through to
dma_direct_free(), which takes the buffer's IOVA for a physical address
and hands the resulting page to the page allocator.

fastrpc_rpmsg_remove() wakes every pending invoke with -EPIPE and then
immediately depopulates the context banks, with no synchronisation in
between, so woken threads race the teardown on their way to
fastrpc_context_free().
The series is ordered so each patch stands on its own:

  1/3 is an independent probe-time bug found while debugging this: the
      misc device is exposed before the channel refcount is initialised,
      so an open() racing probe hits "refcount_t: addition on 0".

  2/3 makes fastrpc_notify_users() wake poll-mode waiters, which today
      keep spinning on a buffer the teardown is about to reclaim.

  3/3 counts in-flight invokes and drains them before touching any
      channel resource.


Jianping Li (3):
  misc: fastrpc: initialise channel refcount before exposing the misc
    device
  misc: fastrpc: wake poll-mode waiters on SSR
  misc: fastrpc: drain in-flight invokes before tearing down context
    banks

 drivers/misc/fastrpc.c | 63 ++++++++++++++++++++++++++++++++++++++----
 1 file changed, 58 insertions(+), 5 deletions(-)

-- 
2.43.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-07  8:45 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-07  8:44 [PATCH v1 0/3] misc: fastrpc: fix UAF and Oops around SSR teardown Jianping Li
2026-10-07  8:44 ` [PATCH v1 1/3] misc: fastrpc: initialise channel refcount before exposing the misc device Jianping Li
2026-10-07  8:44 ` [PATCH v1 2/3] misc: fastrpc: wake poll-mode waiters on SSR Jianping Li
2026-10-07  8:44 ` [PATCH v1 3/3] misc: fastrpc: drain in-flight invokes before tearing down context banks Jianping Li

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®