From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A8CE82C11C4 for ; Tue, 28 Jul 2026 03:47:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785210463; cv=none; b=TPBWheCyVEQmD+fgpE/3SU3MKO3juCUK8txGHtL4DrLuIiVztduEYbbIqhduLQ5VQVXJwGlMMrAJK2eFds2q1h+oiZjN0NmHm5jBD+qNiNmIytyc2eV4HnFu8+73KwUEtK3Ieu0vVzGgqMmqgaMuq7W99W8pCh3k4gXhHhw6FDo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785210463; c=relaxed/simple; bh=SUgNNO3nfk4ebdfPQSmFw62HaPVuLhWhQQOFUBQiqfU=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=XqpcwVjTYPXBFjAq7+ehqsyZwjrV8dAvtM2uSxr2HW5/vpxPagBX1vAQVvT2vniUT/hbBrh+tr/1PorSs+xsOII6gex5CPpCosACrPXu+UUzi5075EbcLAX2wn0lFiBXFhOhYiMKC/Pkkw5/KxnVBzdfTjpBUTBp+HFi79Y6+qI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=RoxL19td; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=M9GKcl3r; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="RoxL19td"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="M9GKcl3r" Received: from pps.filterd (m0279868.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66S3b9b61540543 for ; Tue, 28 Jul 2026 03:47:40 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= yo/lWxHJw9yNZPh3KLPiwdIL7Wsz2tn7HHED+a/H1h4=; b=RoxL19tdNYhKSsSr ivep5JCeOPtMK9paYkEeGCn2c8PH3H6DYpB5QybV5YW6aaAXRKmzqHqpFQHN0swb wUhEsoDsx7C+4QIeU8osOvGyk34/YL3cPBwyBgx6lhFk3V/vXIVz7BagSQo3F5WB 2/P4fndKqM/zv8i5EFQHj6L02N3BJMJeOVac3/AIwmYrCC+R3HzfYMbtEnTzBDb7 ido4KdQG5JOVRnnIrEgvSnLp+qbln+LDGpPCZx+scYLm0J2hNkDe0otvO+ZARIl2 eXSwQi0RLsY7FQin4OAgjeI3vu5Hc9pPCQWk0eRVSUijibPIwoqGado8Fav/G4wJ go0haQ== Received: from mail-pg1-f197.google.com (mail-pg1-f197.google.com [209.85.215.197]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fp4ukv5tt-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Tue, 28 Jul 2026 03:47:40 +0000 (GMT) Received: by mail-pg1-f197.google.com with SMTP id 41be03b00d2f7-cab041eced3so4530659a12.1 for ; Mon, 27 Jul 2026 20:47:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1785210459; x=1785815259; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=yo/lWxHJw9yNZPh3KLPiwdIL7Wsz2tn7HHED+a/H1h4=; b=M9GKcl3rec59qWrMp1i1ntFudeJbpQeD/VxgJo+mAWyupwKZkFaDADxdskcFYTQry7 8Eiochd2fJV+xC90mZdlHMdI0/UHbDHU9mm/Xf23y3BYE2XYFV1sCkynchCDPJ1UnKA3 2KBMNTI7eLQPPWCYlwrHnz4DI/jB2/C/9OCOYF/k6Tnr/TaGZjOndVhWxm/G5hK9clZZ vHrApzkkko9p2c7wGTGrsjVtffBqUIpRxX9619KEo+TxW5JirZxh9N5dmxj3DzS7CCqp Pa1UEsDKEppoGtrdK4q/YbYfqdxZtOKfjvUMQRt2QQ49grV06Fkw7CZo5DSJNTEffy2p Mscw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785210459; x=1785815259; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=yo/lWxHJw9yNZPh3KLPiwdIL7Wsz2tn7HHED+a/H1h4=; b=QRCs/VvXo0afR6tlg0eQ+ehx+6KaTzZgPJzWSQ5SVqCYGU/yDCQQqfbHXnE4bliJrz vY0Z7wmDqpEdTcawfSDvh63E3ozT178e9r3j/aWOELLs+N7LaH7OsuN2gka3rSJUwmRv FwrdFgwO5JnkYEEzmrZ3DmoyrkeYkyYFPRKouA/zCNAxIcXGBJkz9dxRdGhue9jicP25 u3eyKUvb1PTX1AYbIqvx/EVa12n/R9CGqsDgrCCAAw3AVe+sg0wdmE1hbQ5VgOl2pQRr uKl0jQHuj3yQqj9YG5CDoIMZCHGpYZ1vSXXj5ms39ne9A3mUGl9aGE0r13+OAOJcuinP ZnGQ== X-Forwarded-Encrypted: i=1; AHgh+RoKaE4uGrMPgo45OMxIwkJKfCT69JsfQmGJtTgXlCmMQDLmNdugsx4AgelR9UWzQ4B/4+21EvM7obJgKAw=@vger.kernel.org X-Gm-Message-State: AOJu0YzniS1kdsmP5nIjgdmbjlcL3QqyidSRXPfnqK9+DaedcYQybdFS kUIBCP59BrwJmWiLCIRSpVgPmB1U3oKO92YtWQlupvIwQPzgu+ZWeYs3x+YWNpZ+Mn80SXJEl4X Zs5lcHi5gGGNgEMe3If+biIwkLPdCIkKtHep4879zsN+ab21//+Ads5JuIDQ3LumohzZ98s9QCl U= X-Gm-Gg: AR+sD116zieYNoG3aMCB5Rjs797KgYdefMhVlagHI8fPqgwtm8PsoLfbV2G1OyT9/18 rI77CraKn8K/55Cj6ljhSq0Lt8cOtwWJdhqdwL/kE/EPpIt5Ao/VgfaouVGZG+DBk9m0vKv8f6Z IH/Xa8zvuy8g+mNXthwoBuGmL0zqnrwrUjJJUxiOZKfefEZPDnv9QJ4f5JWFRvBMjFP7Co4O9oM pZkR+WhlOEMjYnkTIKWxODayNy9zrHSTgaEkw/ZYKl4iUCW6Ol/Pbu1Q3gkk1qSYvLr6bjrOjer +NtOpJ3iXzycd2DUwN1Gjsq8fq++VN1tz8n0+IaGROmndOebKCRVJhyKSqzKeWErrkZig1mXQr5 8H0ZwqgNZDJAT0mMqX2UvzYeb9MB6Qw== X-Received: by 2002:a05:6a20:6f93:b0:3c3:bbe6:95c9 with SMTP id adf61e73a8af0-3c8aaf877a9mr932517637.16.1785210459485; Mon, 27 Jul 2026 20:47:39 -0700 (PDT) X-Received: by 2002:a05:6a20:6f93:b0:3c3:bbe6:95c9 with SMTP id adf61e73a8af0-3c8aaf877a9mr932490637.16.1785210459089; Mon, 27 Jul 2026 20:47:39 -0700 (PDT) Received: from [10.204.78.209] ([202.46.23.25]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-314bc59cfb4sm37084511eec.26.2026.07.27.20.47.35 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 27 Jul 2026 20:47:38 -0700 (PDT) Message-ID: <3a83e00a-9e4c-4411-b554-1edb9d02c799@oss.qualcomm.com> Date: Tue, 28 Jul 2026 09:17:34 +0530 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] misc: fastrpc: Ignore unsolicited DSP response sentinel To: Shawn Guo , Srinivas Kandagatla Cc: Arnd Bergmann , Greg Kroah-Hartman , linux-arm-msm@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org References: <20260727130940.577721-1-shengchao.guo@oss.qualcomm.com> Content-Language: en-US From: Ekansh Gupta In-Reply-To: <20260727130940.577721-1-shengchao.guo@oss.qualcomm.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Proofpoint-GUID: v1jI5JdGmOn0if51Muf7RsdhwhvvNTXS X-Proofpoint-ORIG-GUID: v1jI5JdGmOn0if51Muf7RsdhwhvvNTXS X-Proofpoint-Spam-Info: AW1haW4tMjYwNzI4MDAzMSBTYWx0ZWRfXy/E5sZEFPhR9 +0xmbcsz7AYXvjGBd4GRsE1ZYuy/ps1GDkGHvQ61n2J5e38nWx7paoK7elJuk+69Rnpz7wqgHNh TNvqufq6E2qSV01f1bkx7FSaBRTR30c= X-Authority-Analysis: v=2.4 cv=PeHPQChd c=1 sm=1 tr=0 ts=6a68265c cx=c_pps a=rz3CxIlbcmazkYymdCej/Q==:117 a=ZePRamnt/+rB5gQjfz0u9A==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=ZpdpYltYx_vBUK5n70dp:22 a=EUspDBNiAAAA:8 a=RR3Qzd7dXdH_FvX10yoA:9 a=QEXdDO2ut3YA:10 a=bFCP_H2QrGi7Okbo017w:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzI4MDAzMSBTYWx0ZWRfXx6fiayCTNzAm w8xe0Yx34DEOK44f71uckYRwYCbtSIafQSK1JEHu9d+hL0hG1u4qAWv/SYAdFSEETd+lWJ90xcT YusJO3mALMsJUFbWkM4vln5k/C8Occ4WOHmmsv9OZeHQZT3pYR++I1k4wb+Us5GBGK/35q/NU99 AHhYPl4L05b/zEpYVxa/ZWjEtpb3y2aCGk5GLhQi2a4GhYu0gvDR6xciQYixh9//+OVuPt1Nth+ hexiqC/F0OLcQx4uUS/IuXSg/zyzMiPGSrrQ69MMMfbPIXHcDSDaG+Hf0thGXMoRFGVX/aEoE+1 wlBDCWuk6jI8f67kGP71gQompVd1H5it4+qwMaIOkYvdftZG2C5d7xeMrDq6a4+8Haw1GRgXaUS 9am08jXc0+EX/sdAbfn8MpYzjXJ8lnU0qaBWiSCoCDxnKoCQOCfiEcZCMYVh5gIwXtZhGelxg/L R+AVeSlu6RSs90MKuyA== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-28_01,2026-07-27_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 malwarescore=0 clxscore=1015 adultscore=0 spamscore=0 phishscore=0 lowpriorityscore=0 bulkscore=0 priorityscore=1501 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607280031 On 27-07-2026 18:39, Shawn Guo wrote: > The DSP firmware on Nord targets emits an unsolicited glink message > during process teardown whose context field holds a fixed sentinel > (0xABCDABCD) rather than the context of an outstanding invocation. > fastrpc_rpmsg_callback() treats every inbound message as an invoke > response, so the sentinel is masked and shifted like any real response > ((0xABCDABCD & 0xFF0) >> 4 == 188) and looked up in the channel's > context idr. > > This is not merely cosmetic. In the common case idr slot 188 is empty, > the lookup fails, and the driver only logs a spurious "No context ID > matches response" error on every teardown. But the context idr is shared > by every protection domain and the listener thread on the channel and is > filled cyclically over [1, FASTRPC_CTX_MAX]. If slot 188 holds a live > context when the sentinel arrives, the sentinel's return value is written > into that unrelated in-flight invocation and it is completed early. That > is a latent, timing-dependent bug that just does not happen to trigger in > current test runs. > > Drop the sentinel before it is ever turned into a context lookup. > This removes both the log spam and the mis-completion race. A genuine > response can never be masked: a real context is (idr_index << 4) | pd > (at most 0xFF3) and can never equal the sentinel. > > Lemans and other targets are unaffected: their DSP firmware does not send > this message, so the new check never fires. > Sharing more details for this context: On newer firmware, there is a support for DSP PD notification where DSP sends PD state notifications on certain states as per user request. PD exit notification is always sent by DSP which is with context id 0xABCDABCD. As of today, DSP notification framework is not supported by fastrpc lib or driver and it's safe to ignore this callback. With this, Reviewed-by: Ekansh Gupta > Assisted-by: Claude:claude-opus-4-8 > Signed-off-by: Shawn Guo > --- > drivers/misc/fastrpc.c | 17 +++++++++++++++++ > 1 file changed, 17 insertions(+) > > diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c > index d86e79134c68..be9f102690f6 100644 > --- a/drivers/misc/fastrpc.c > +++ b/drivers/misc/fastrpc.c > @@ -38,6 +38,15 @@ > #define FASTRPC_INIT_HANDLE 1 > #define FASTRPC_DSP_UTILITIES_HANDLE 2 > #define FASTRPC_CTXID_MASK (0xFF0) > + > +/* > + * DSP firmware on some targets (e.g. the Nord remoteproc) sends an unsolicited > + * message during process teardown that carries this sentinel in the context > + * field instead of the context of an outstanding invocation. It is not a > + * response, so it must be dropped rather than matched against the context idr. > + */ > +#define FASTRPC_RSP_CTX_SENTINEL 0xABCDABCD > + > #define INIT_FILELEN_MAX (2 * 1024 * 1024) > #define INIT_FILE_NAMELEN_MAX (128) > #define FASTRPC_DEVICE_NAME "fastrpc" > @@ -2552,6 +2561,14 @@ static int fastrpc_rpmsg_callback(struct rpmsg_device *rpdev, void *data, > if (!cctx) > return -ENODEV; > > + /* > + * A sentinel context marks an unsolicited message from the DSP rather > + * than a response to an outstanding invocation. Drop it: a real context > + * is (idr_index << 4) | pd and can never collide with this value. > + */ > + if (rsp->ctx == FASTRPC_RSP_CTX_SENTINEL) > + return 0; > + > ctxid = ((rsp->ctx & FASTRPC_CTXID_MASK) >> 4); > > spin_lock_irqsave(&cctx->lock, flags);