From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 254E73C3C02 for ; Tue, 26 May 2026 06:59:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779778780; cv=none; b=Y24zTCagR/RePubY9PvhbHFkgHzmKWOaFLGGMAsTTFCtIOPBhsB0EqS2s+wGGgt5/Y0o3F2OItIMVe/RsgFWn27VrgJ85qMDNYsmirp8ExmfUdZh4TQMDAbkC8f2+mUGLTpRj5RaCSjhXd6p4+viB5HtX+uFZ8kVVTw1l5WPqXM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779778780; c=relaxed/simple; bh=VCpJwz59z00/2pf1W5HQ5EcorcdEfDt7JDMuLDgIWhU=; h=Message-ID:Date:MIME-Version:Subject:To:References:From:Cc: In-Reply-To:Content-Type; b=Kjubb6A6QPgM5zyFXTs1XGr3Jsz8LjPv6YUpTbh+rhIciXkGQ+W0Opxp16C/mGoqJapp9wO/VXQ85dndWD+1i9k2ZrOFlf0Oc/dJZyRYvghwVV0xiSLS8m4EZ71VU9hsT6bArwN9Z1pKXVEC3EYwYPRLKXWpBvbaC9c2Q2h5KCM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=nj9xsrCm; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=hdTr6YC6; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="nj9xsrCm"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="hdTr6YC6" Received: from pps.filterd (m0279862.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 64Q51AI5079191 for ; Tue, 26 May 2026 06:59:38 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= 3LVvCV+OUMP+eKOrIZZaZLZwCkJ9amVnJmT5FmWau3s=; b=nj9xsrCm/lOT11kn ZnRRjHjYdlK1r6DvR7j8lL0xfTKmOeoGT0ZCNpAhzRDrODPhARMSlJJSJYe7kBnO Ue4e0NBmlMMjO+f+Vd2xkdIXeViCcf8+VuheB7CZUrd6f9WrwZUx0Yzp5nwtjTsC uqOU/UqrQ5+RxR1JfJ4xFv8R5aCwSro4k7DnJh+1fkMqOsrebnwyIvak55V0FzoI XgT+UoPsvDibYhb2t4wMX4rGyZU4OpBOvn9whM5z9xMOHNHcp8ZspTHOfbtMzRK4 +66r68Gv7TQ3WG1K7/PGg7+zM1oEv4vaYmfR0x0Gz0Vb3JnbS2zk6Ko4r40lX35r hgMp4A== Received: from mail-pj1-f70.google.com (mail-pj1-f70.google.com [209.85.216.70]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4eckmabcwf-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Tue, 26 May 2026 06:59:38 +0000 (GMT) Received: by mail-pj1-f70.google.com with SMTP id 98e67ed59e1d1-368b15eeb3bso19571163a91.2 for ; Mon, 25 May 2026 23:59:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1779778778; x=1780383578; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:cc:from:content-language :references:to:subject:user-agent:mime-version:date:message-id:from :to:cc:subject:date:message-id:reply-to; bh=3LVvCV+OUMP+eKOrIZZaZLZwCkJ9amVnJmT5FmWau3s=; b=hdTr6YC6SEW33oaFIZVBSZ+h32WyYlhOWztWhTXeYlyXZi9xbTL54SjxYVL9loEZWq J2ihE/SGlEwikm3W7crVPp3ktMSO/EqF8Waj5ROgBr32JgXFIF/Zxx0vLeVFarB63LUP L+lF/vjhOsAI079c46mJqRngGGnv/+9deQ5m774PEsxtxoXwlAWGQObvQLxpoowFFi9Z aFXkE/KoRZeHmHA5XqriJaH/z3lftvfTA1VeB73ucIC3VSaaw3knlBJkBcZCYxA7v6Dr lXge9+is2sNUH46/384NuuNHDQ2djXqhpKIQtOuiGPYl38WAcMQepx/Yr6jFiqn3TJmb m82Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779778778; x=1780383578; h=content-transfer-encoding:in-reply-to:cc:from:content-language :references:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=3LVvCV+OUMP+eKOrIZZaZLZwCkJ9amVnJmT5FmWau3s=; b=AP60Btr0M1Sv3Tcor3ximoWS0J6u7H61Bx3LYwDXWSURRJydn3iJfP9gAL0e+3hOKH o2tx7swq3/+JK7hhx4Ftyiu6YaST+MEzDWVk8tEXWrMwXmutVehE9TkfABV9Qe1YM3PP Hv4IzrC+zQN9YSbkgrMMToJ1f2tauFhJNjNtrXAxwWNCYMbosjUFCc/vbuI1Uex7NDgs NlRnprc1cvuRFGP476M3tIlNlQbkl2AVhLdBkZg/eS1dxVIbgcpiUj7n5ynOEEKZ2Fp5 ACWtwBonJRRvnD4p6dw5IuD+cv7BnPrJYIRAI71N5mIL3CPiI2K//uEQtINnW224RDgE eqrA== X-Forwarded-Encrypted: i=1; AFNElJ/40hHkglzwj8PzuYRMpfJ8qveccn8qZ5mAAORizF3TlKRew6tp9/A4T+jrr+hhYkx5F2/MTC3hp5z+Wq8=@vger.kernel.org X-Gm-Message-State: AOJu0Yws6/xcKSJtTxUwehEkSHJjXrOs/6r3x/BCzQ/AU5+YbfAgCvFO E0hT7s8xr11uTQYBMQ/zqLdCdNWkkse79DtsJJdLAvGSJSMmdRtlKF5QoupBbApwPXw17Vw7eId PcIqtOzF7/1w0wYzIFyDijvdOxywlddIcUpzpzS4nnuQHwHuueUjUYAJqXsuQobqfGdA= X-Gm-Gg: Acq92OEOAylw8mbNLU3LzjZnH3FtWzXndPwOi2kWZSMyaUVbUahJ9ofVktdptjwvszQ 1iH6I8U61H/xbv91VYRDOvn1QZVbpeRzeEtc9803OF60KCPe0pHmtLP9yEY8Qng3LwgkgVi8Yzd eNQss/B5A3CaEIwnxqQ2XL4U4zQiDA3V444a80HTzpR79Os7pmTu7Elpam9nvoC0tBzTcBi3F9Q Z62FM2ahhsvFZln3+AtUI257ZDdcYK5+iaj1XoMhT1ULHNcVjXkz2FXar759DaM8vRKN1p3jYyB 8eO0p6dgYDx/0e6XlMLTeHRSE/Bqr+VTV0y7PlKQRtRYQ6k+2HlXDpDk/3H9HLpTuTJxHg6i/Lm bzN3z0vgRvoiETkSy7Mki+aEDkIlVs12+7RO+oAAadlVnlAGHL+6LMyJ7jYHOzetvbgraPXmjVW QNWZw/5oHiilcrwpCa X-Received: by 2002:a17:90b:5746:b0:364:78a5:8d40 with SMTP id 98e67ed59e1d1-36a67639d6dmr17650200a91.20.1779778777722; Mon, 25 May 2026 23:59:37 -0700 (PDT) X-Received: by 2002:a17:90b:5746:b0:364:78a5:8d40 with SMTP id 98e67ed59e1d1-36a67639d6dmr17650176a91.20.1779778777240; Mon, 25 May 2026 23:59:37 -0700 (PDT) Received: from [10.133.33.225] (tpe-colo-wan-fw-bordernet.qualcomm.com. [103.229.16.4]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-36a72674492sm10892004a91.8.2026.05.25.23.59.33 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 25 May 2026 23:59:36 -0700 (PDT) Message-ID: <4dc05557-ab95-468f-b972-84fe9fa3cc51@oss.qualcomm.com> Date: Tue, 26 May 2026 14:59:31 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v5 2/5] misc: fastrpc: Remove buffer from list prior to unmap operation To: Dmitry Baryshkov References: <20260515124217.20723-1-jianping.li@oss.qualcomm.com> <20260515124217.20723-3-jianping.li@oss.qualcomm.com> <37146a3a-b18f-40f1-b95b-0ac19bf6c07a@oss.qualcomm.com> <85c2bfd1-8e69-47e4-a360-10a2655bd43f@oss.qualcomm.com> Content-Language: en-US From: Jianping Li Cc: amahesh@qti.qualcomm.com, arnd@arndb.de, Greg KH , abelvesa@kernel.org, jorge.ramirez-ortiz@linaro.org, Ekansh Gupta , linux-arm-msm@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, quic_chennak@quicinc.com, stable@kernel.org In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Authority-Analysis: v=2.4 cv=cL3QdFeN c=1 sm=1 tr=0 ts=6a1544da cx=c_pps a=0uOsjrqzRL749jD1oC5vDA==:117 a=nuhDOHQX5FNHPW3J6Bj6AA==:17 a=IkcTkHD0fZMA:10 a=NGcC8JguVDcA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=_K5XuSEh1TEqbUxoQ0s3:22 a=EUspDBNiAAAA:8 a=HEe4avgjgsDiN2dfqW4A:9 a=QEXdDO2ut3YA:10 a=mQ_c8vxmzFEMiUWkPHU9:22 X-Proofpoint-ORIG-GUID: QveONJ-Uc4BtfB1_7t8M2zZ76jM4a3f1 X-Proofpoint-GUID: QveONJ-Uc4BtfB1_7t8M2zZ76jM4a3f1 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNTI2MDA1OSBTYWx0ZWRfX5iBjcr1kFYQQ RTQvSKHsZzT8y25ppo+e2n/hzb1xBABGGe4SsO34ofqFp4ugBrhMDtpN9zIvFHlutXGuXHXP5jk WbuVMNp9d0vG65vBdfjRQMGdnwDpvgTru3P6eyj0Mxkue4Xs7axXEUQ+7EzSMt1jDDNc1bcJANB FT9BmF2PG9bDGIDbxxj9bDKGZO4FearcRweoeJzhXA9BtnqFT+3cNp2MdwkwdrRx/VV70+idIE0 e0hcq1T2el0dhCBIjMJ6xKedOY8UBpB+HPcxnMibPP4ZrctHWF8enqYpKzTFDTGdhedy9aFyCHj MQHedmLh9wymihhsAGNCA1cl1L/G8lPn2j0SnBoxMe0+PkYXWDOGK6J94r84n3rBiqUY5/qXfMD WiQmfsfVPWz58qy70Xo4Vk/g4C8S6SJtbXshynIJ6RUp5GcZdUQMjbNUziDuF62Ko0VJeRe+ldU w+p7TIwk1ywlanljU6Q== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-05-26_01,2026-05-18_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 bulkscore=0 priorityscore=1501 phishscore=0 adultscore=0 lowpriorityscore=0 spamscore=0 suspectscore=0 clxscore=1015 impostorscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2605130000 definitions=main-2605260059 On 5/25/2026 5:35 PM, Dmitry Baryshkov wrote: > On Mon, 25 May 2026 at 11:34, Jianping Li wrote: >> >> On 5/25/2026 4:30 PM, Dmitry Baryshkov wrote: >>> On Fri, May 22, 2026 at 02:55:29PM +0800, Jianping Li wrote: >>>> On 5/15/2026 9:36 PM, Dmitry Baryshkov wrote: >>>>> On Fri, May 15, 2026 at 08:42:14PM +0800, Jianping Li wrote: >>>>>> From: Ekansh Gupta >>>>>> >>>>>> fastrpc_req_munmap_impl() is called to unmap any buffer. The buffer is >>>>>> getting removed from the list after it is unmapped from DSP. This can >>>>>> create potential race conditions if any other thread removes the entry >>>>>> from list while unmap operation is ongoing. Remove the entry before >>>>> How can it remove the entry from the list? >>>> Multiple threads sharing the same file descriptor may invoke unmap concurrently. >>> => commit message >>> >>>>>> @@ -1898,7 +1897,14 @@ static int fastrpc_req_munmap(struct fastrpc_user *fl, char __user *argp) >>>>>> return -EINVAL; >>>>>> } >>>>>> - return fastrpc_req_munmap_impl(fl, buf); >>>>>> + err = fastrpc_req_munmap_impl(fl, buf); >>>>>> + if (err) { >>>>>> + spin_lock(&fl->lock); >>>>>> + list_add_tail(&buf->node, &fl->mmaps); >>>>>> + spin_unlock(&fl->lock); >>>>>> + } >>>>> Is it expected that userspace tries to unmap it again? Or why is it >>>>> being added to the list? >>>> User process can call unmap and fastrpc library won't call the unmap again. >>> In the other email you wrote that the driver can be used by random apps. >>> So... what happens if userspace unmaps it again? What if the userspace >>> _doesn't_ unmap it (although you've just readded it back)? >> If the same buf is unmapped again, because it has already been added back to the list, the unmap logic will be executed again. >> If userspace no longer performs unmap, the driver will not unmap it proactively. >> The Fastrpc driver will free up this list during fastrpc user-free. > It will free the list. But what happens with the memory mapping? When device release is called, DSP side PD is also cleaned up, which includes cleaning up of DSP side mappings Before kref_put of fl, we call DSP process release, where DSP PD is cleaned up. After calling this, we go ahead and do buf_free of the list Thanks, Jianping. > >>>> Fastrpc driver will free up this list during fastrpc user-free. > >