From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 743CF3F7882 for ; Mon, 24 Aug 2026 10:39:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787567986; cv=none; b=DwRLPF/mmVfd0+rBTDfKupgd0zKtEKzD66BG6igNIb+6DJbF4ihvschsE4EbISzGYUmN77ZVopkGE2UIxuEGpRK2rqaD2ZmwmtZzrUXzGjqx4ibNO9LaS0HLk2c8lgxZXnV98dQDVdW/OCHaze9erqZEwFhY7OZo/rig4lKynH4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787567986; c=relaxed/simple; bh=sXw6xPg2OdGU6bdMxWP/T6PiD8CO7PA4AG9N6e99RLM=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=TfHZc4xmw5AgSWuiEVSoKl/IZg+rVNDvcNfpBMdDJ59tlOjz9umsIJ92SPR1A+7xrnt8zK0A/lilRGYm4AKO7cU36ySS9A+bHrN0AwSywxABh36jN+Jrutkec7ixNopgilgCMGmfoQ9iBgxP12PAlmLeQIegn9rkGhktZgwOGEo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=a+ujSlq+; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=GytYZ2cH; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="a+ujSlq+"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="GytYZ2cH" Received: from pps.filterd (m0279873.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67O994WC2448667 for ; Mon, 24 Aug 2026 10:39:43 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= EH+CuZjP4cDRfKOg/gisXTBEt3tpjz6voXrCTk5GOxo=; b=a+ujSlq+jQ5yxo4p zQ+RyLbY/Qw7RhEzmxJ2ItxbfABdgVGf9KwB/g5xTdsuyQedXSs1wq30zzLEDnPN wGpR1j2fHGf5KW4tWUHQH4ZXt7hi5175DAduB61DDwnB7eZQ3lTs3MXUd9BkBBb3 55svgnXiJmER7LWUShXr3KO5CI/nZJxPMXFFS3URDSAPN9o8+iotNoYgL0r921sk 0F03EIFkAeBITk8/LYXk9OTo5ufHFN84w/lW8OsJzw7ofN/f4vqTWho48zrnE4Sc DPyJe6ET+fNhkYaHLac4WyJyJvA8c3Dae8jWMJ6uedkQjNrOzm3jRnWlXkjsYZHZ I2uoqg== Received: from mail-oa1-f70.google.com (mail-oa1-f70.google.com [209.85.160.70]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4g8j7r0nuh-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Mon, 24 Aug 2026 10:39:43 +0000 (GMT) Received: by mail-oa1-f70.google.com with SMTP id 586e51a60fabf-4488f192768so5427635fac.0 for ; Mon, 24 Aug 2026 03:39:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1787567982; x=1788172782; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=EH+CuZjP4cDRfKOg/gisXTBEt3tpjz6voXrCTk5GOxo=; b=GytYZ2cHVlJo9F9BCDkAEiKSXBsIUTSbT0jRWsNxas/QuX3keaChT7mLP+uUp1aM/E icyarOJOhSVmsR3kIRrkzc2GoY7m+K89Ak1qGaHnJUPkXANwBjkelv+aOWI2ofB5hn31 rHndCqOuruDJmbtlqRaaqBV0QJcM0oUSikeBt0x9GRCx3dRC632TRn6CTYub6ApgFOxT ++mROZq4Y5TTHR1S4axnvoPTDxrn5yERESc0eARmlmvQMdL1xlNVbPe0fQ78J5gwmLSw DTaNgxVcKWp4YTcYU7qX9PtHKUKcMQ1LSksyXM5WVjnbZ2x6Mb251luQi+zKbchnEQRA r+qw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787567982; x=1788172782; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=EH+CuZjP4cDRfKOg/gisXTBEt3tpjz6voXrCTk5GOxo=; b=NPyrl6lcGD/bTE5zr/M0ZhxJ2M9Og/dLqqxTZmwv6sEcCIfFiPhzPEblQQFR2seFxW MOMOkdgNCaVZhxD04iCvlqxP7B+7F5bcm1LJOjrOFl813UGIzqzEzLSNB0j0hMSVDQTs yOIU0xpRtUVs5f1J4/uofYy+1wZ5BsonWS8tq2PsjQHxRhwASGcxVMFDhhogoFSpZn3X mTOHZ4besdGNyT8X2U4UeEaAvNH0q+8MaAJCk4HAgifJrkfqvQt1d1eSuYbFgQDlIMJ5 gWSnJ9uivKt9jA6lBtSKaM2AZBDU3s9Z/Ndp9twRpE22T1Oqk4SDqM+mAUNmoFfo7HUM fgHg== X-Forwarded-Encrypted: i=1; AHgh+RrnB3NEAkrqwDL8xyH7jzpoP4PWq7iGgJKhp3k1h3UdpScfO5LL4+7rOhFGntDkXO19hEZurBeW4YCvAfY=@vger.kernel.org X-Gm-Message-State: AFuF++lEkHGuMC2DWakvxOc25slDukNBRvfKsNdF/D1kmuAWpH6TDnQo u6xY2yiX6ZOqCBIHiJMUS/4vkZHfKS519HrpiW2AwS11r8cR89+mn/cgOXl52I64/7NMX9jdWwU PDJjRdRMuBoKTGK/CEgtA1taqxz+Ljze2c775hbA9hRQlsafDekjlRcHyeMGQdrFAt9Y= X-Gm-Gg: AR+sD11GOEm/hwwO/beNkexva7/bdmuhnEi9POvS3H4jO7A/V/ZxyRyobqM3ynjLmqR 5OYQ0qfg7Fz5DKnb/4oHlOTY96QQUjjp35h9m7L77pHHrX6Tg2LUhpXUJ2RPGD90SDKKN3b32Dt UBj+mKUY+39F44HBbIDhV+g3r5lYnr0MmsCC/rqrE7/fdZWo0/9qNKAsPfqde0fukx3wwzYKVQZ 2p+y2Z7XGSd6jb0y/wXwY3SEHR6h3CnYduieFedWOdxJ8BO6uxGkZfmmQ4w4AYh2pJXEkErTTtg NwLr02HZ8RKSoZ6jds4f6017mWXQSlZpsA7hCZ2gVN4FAPEmP7WMpSg4i2hL2fPHRa32iLAdreM 9MPsmkziBIUx4JzLlFJnJJ3mBMBtAmw== X-Received: by 2002:a05:6820:205:b0:6b1:4fe1:9464 with SMTP id 006d021491bc7-6b1593ad824mr24135570eaf.22.1787567982437; Mon, 24 Aug 2026 03:39:42 -0700 (PDT) X-Received: by 2002:a05:6820:205:b0:6b1:4fe1:9464 with SMTP id 006d021491bc7-6b1593ad824mr24135534eaf.22.1787567981917; Mon, 24 Aug 2026 03:39:41 -0700 (PDT) Received: from [10.219.56.151] ([202.46.23.19]) by smtp.gmail.com with ESMTPSA id 586e51a60fabf-46383499862sm5295493fac.9.2026.08.24.03.39.37 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 24 Aug 2026 03:39:41 -0700 (PDT) Message-ID: <75858cb3-5490-4e11-81fd-d6b73cbc28eb@oss.qualcomm.com> Date: Mon, 24 Aug 2026 16:09:35 +0530 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v12] misc: fastrpc: Allocate entire reserved memory for Audio PD in probe To: Jianping Li , Srinivas Kandagatla Cc: arnd@arndb.de, Greg KH , abelvesa@kernel.org, linux-arm-msm@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, quic_chennak@quicinc.com, stable@kernel.org References: <20260814101955.234238-1-jianping.li@oss.qualcomm.com> <57185025-de92-43c4-a300-fa2682993d15@oss.qualcomm.com> <9176dda0-ba46-47aa-a642-390dc0b01228@oss.qualcomm.com> Content-Language: en-US From: Ekansh Gupta In-Reply-To: <9176dda0-ba46-47aa-a642-390dc0b01228@oss.qualcomm.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODI0MDA4OCBTYWx0ZWRfX063inteVmZRK Ap7jbRxLdL+4/ZLcr9k2T02WlJBN7Kc89KHtLEKn+XHpFMGb3KXNoRo49f78V9exa30dy2fE9bN iRVWuE+fm++H2RhPzZAdLf5SGgXwSa6nTsE3HZfd4bfTE/gVHntgtsL549YlaKqP2ie8ZXIBp06 CEqZNoA5sdkeMRoG8hQhJEYp1ssnmz+Tr9Pkh7E9zDo/EhfuOfMG3S/WT4fyOUf3gjYDD5GaR+E 5qCa/UgQEgCD53Xz2RAekKZJyJ+510zNAeFWBhAg1Xi0k46W0YbV9hZcUH8T4YAlm1njLDere2t n9c2k2p8xNxWHQf7ZL4mcxazpEPQ7TUIcQBi15qXLxUJ17bqjNBzcArO3K+wIKfqcQPgRB7xqiq 9Js0n8daN5FIV7di+Ks45c4VEbIi79246s5tI/CYeDxmDDOrYf7ErhyUgJu/u3ndjzLgfAVoimL /TNR0fNpAFgtcgmbfdA== X-Proofpoint-Spam-Info: AW1haW4tMjYwODI0MDA4OCBTYWx0ZWRfX6enxdVpi6HVo u9cY/HOciQnT4k/px/mAUVlgm+2isJd2fTlgB6SgpFy2Gx5UkZ9dA6WotPDu6an3rplQKm11Wfs V1PG2/JpQbbumOmECyCkVVkJvw8E9Ts= X-Proofpoint-GUID: sygxoFA7XNgKNBmFVmkq5RmlwN3hcC4h X-Authority-Analysis: v=2.4 cv=IL8yzAvG c=1 sm=1 tr=0 ts=6a8c1f6f cx=c_pps a=nSjmGuzVYOmhOUYzIAhsAg==:117 a=j4ogTh8yFefVWWEFDRgCtg==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=rJkE3RaqiGZ5pbrm-msn:22 a=VwQbUJbxAAAA:8 a=EUspDBNiAAAA:8 a=Tn-M0EgaeUShJGCi6KMA:9 a=QEXdDO2ut3YA:10 a=1zu1i0D7hVQfj8NKfPKu:22 X-Proofpoint-ORIG-GUID: sygxoFA7XNgKNBmFVmkq5RmlwN3hcC4h X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-24_03,2026-08-21_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 malwarescore=0 phishscore=0 priorityscore=1501 suspectscore=0 spamscore=0 bulkscore=0 lowpriorityscore=0 clxscore=1015 impostorscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608240088 On 24-08-2026 14:19, Jianping Li wrote: > > On 8/20/2026 1:10 PM, Ekansh Gupta wrote: >> On 14-08-2026 15:49, Jianping Li wrote: >>> Allocating and freeing Audio PD memory from userspace is unsafe because >>> the kernel cannot reliably determine when the DSP has finished using the >>> memory. Userspace may free buffers while they are still in use by the DSP, >>> and remote free requests cannot be safely trusted. >>> >>> Additionally, the current implementation allows userspace to repeatedly >>> grow the Audio PD heap, but does not support shrinking it. This can lead >>> to unbounded memory usage over time, effectively causing a memory leak. >>> >>> Fix this by allocating the entire Audio PD reserved-memory region during >>> rpmsg probe and tying its lifetime to the rpmsg channel. This removes >>> userspace-controlled alloc/free and ensures that memory is reclaimed only >>> when the DSP process is torn down. >>> >>> The reserved-memory region is now mandatory for the Audio PD domain. >>> Rather than failing rpmsg probe when it is missing, validate it in >>> fastrpc_init_create_static_process() and reject only the static-process >>> creation. This keeps the fastrpc device probing for all other domains >>> even on a misconfigured device tree. >>> >>> Fixes: 0871561055e66 ("misc: fastrpc: Add support for audiopd") >>> Cc: stable@kernel.org >>> Signed-off-by: Jianping Li >>> --- >>> Patch [v11]: https://lore.kernel.org/all/20260731093210.473-1- >>> jianping.li@oss.qualcomm.com/ >>> >>> Changes in v12: >>> - Do not fail rpmsg probe when the reserved-memory region is missing, >>> validate the region in fastrpc_init_create_static_process() instead, >>> so probe keeps working for all domains. >>> - Add fastrpc_domain_has_reserved_heap() / fastrpc_domain_uses_static_heap() >>> helpers to replace the open-coded ADSP/SDSP domain checks. >>> >>> Changes in v11: >>> - Replace the remote_heap fastrpc_buf pointer with dedicated >>> remote_heap_addr and remote_heap_size fields in >>> fastrpc_channel_ctx to avoid leaving a partially >>> initialized fastrpc_buf. >>> >>> - Drop ADSP_MMAP_REMOTE_HEAP_ADDR support from >>> fastrpc_req_mmap() since the user process should no longer >>> grow or shrink the Audio PD remote heap. >>> >>> Changes in v10: >>> - Move Audio PD remote heap validation into >>> fastrpc_rpmsg_probe(). >>> >>> - Treat Audio PD remote heap as a mandatory >>> resource and fail probe if the reserved >>> memory region is missing. >>> >>> Changes in v9: >>> - Make sure fastrpc_init_create_static_process() >>> only sets audio_init_mem to false when the sent >>> address is actually invalid. >>> --- >>> drivers/misc/fastrpc.c | 150 +++++++++++++++++++++-------------------- >>> 1 file changed, 76 insertions(+), 74 deletions(-) >>> >>> diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c >>> index 90fd669636ec..3f14a4673698 100644 >>> --- a/drivers/misc/fastrpc.c >>> +++ b/drivers/misc/fastrpc.c >>> @@ -70,8 +70,6 @@ >>> #define ADSP_MMAP_HEAP_ADDR 4 >>> /* MAP static DMA buffer on DSP User PD */ >>> #define ADSP_MMAP_DMA_BUFFER 6 >>> -/* Add memory to static PD pool protection thru hypervisor */ >>> -#define ADSP_MMAP_REMOTE_HEAP_ADDR 8 >>> /* Add memory to userPD pool, for user heap */ >>> #define ADSP_MMAP_ADD_PAGES 0x1000 >>> /* Add memory to userPD pool, for LLC heap */ >>> @@ -314,10 +312,14 @@ struct fastrpc_channel_ctx { >>> struct kref refcount; >>> /* Flag if dsp attributes are cached */ >>> bool valid_attributes; >>> + /* Flag if audio PD init mem was allocated */ >>> + bool audio_init_mem; >>> + /* Audio PD reserved remote heap region */ >>> + phys_addr_t remote_heap_addr; >>> + u64 remote_heap_size; >>> u32 dsp_attributes[FASTRPC_MAX_DSP_ATTRIBUTES]; >>> struct fastrpc_device *secure_fdevice; >>> struct fastrpc_device *fdevice; >>> - struct fastrpc_buf *remote_heap; >>> struct list_head invoke_interrupted_mmaps; >>> bool secure; >>> bool unsigned_support; >>> @@ -1454,15 +1456,24 @@ static int fastrpc_init_create_static_process(struct fastrpc_user *fl, >>> struct fastrpc_init_create_static init; >>> struct fastrpc_invoke_args *args; >>> struct fastrpc_phy_page pages[1]; >>> + struct fastrpc_channel_ctx *cctx = fl->cctx; >>> char *name; >>> int err; >>> - bool scm_done = false; >>> struct { >>> int client_id; >>> u32 namelen; >>> u32 pageslen; >>> } inbuf; >>> u32 sc; >>> + unsigned long flags; >>> + bool sent_heap = false; >>> + >>> + if (!cctx->remote_heap_addr || !cctx->remote_heap_size) { >>> + err = -ENOMEM; >>> + dev_err(fl->sctx->dev, >>> + "remote heap memory region is not added\n"); >>> + return err; >>> + } >>> >>> args = kzalloc_objs(*args, FASTRPC_CREATE_STATIC_PROCESS_NARGS); >>> if (!args) >>> @@ -1486,31 +1497,6 @@ static int fastrpc_init_create_static_process(struct fastrpc_user *fl, >>> inbuf.client_id = fl->client_id; >>> inbuf.namelen = init.namelen; >>> inbuf.pageslen = 0; >>> - if (!fl->cctx->remote_heap) { >>> - err = fastrpc_remote_heap_alloc(fl, fl->sctx->dev, init.memlen, >>> - &fl->cctx->remote_heap); >>> - if (err) >>> - goto err_name; >>> - >>> - /* Map if we have any heap VMIDs associated with this ADSP Static Process. */ >>> - if (fl->cctx->vmcount) { >>> - u64 src_perms = BIT(QCOM_SCM_VMID_HLOS); >>> - >>> - err = qcom_scm_assign_mem(fl->cctx->remote_heap->dma_addr, >>> - (u64)fl->cctx->remote_heap->size, >>> - &src_perms, >>> - fl->cctx->vmperms, fl->cctx->vmcount); >>> - if (err) { >>> - dev_err(fl->sctx->dev, >>> - "Failed to assign memory with dma_addr %pad size 0x%llx err %d\n", >>> - &fl->cctx->remote_heap->dma_addr, >>> - fl->cctx->remote_heap->size, err); >>> - goto err_map; >>> - } >>> - scm_done = true; >>> - inbuf.pageslen = 1; >>> - } >>> - } >>> >>> fl->pd = USER_PD; >>> >>> @@ -1522,8 +1508,25 @@ static int fastrpc_init_create_static_process(struct fastrpc_user *fl, >>> args[1].length = inbuf.namelen; >>> args[1].fd = -1; >>> >>> - pages[0].addr = fl->cctx->remote_heap->dma_addr; >>> - pages[0].size = fl->cctx->remote_heap->size; >>> + /* >>> + * Audio PD is a static PD and retains the remote heap >>> + * information across daemon restarts. Therefore only >>> + * the first attach should provide heap information to >>> + * DSP. Subsequent attaches reuse the previously >>> + * initialized memory pool. >>> + */ >>> + spin_lock_irqsave(&cctx->lock, flags); >>> + if (!cctx->audio_init_mem) { >>> + pages[0].addr = cctx->remote_heap_addr; >>> + pages[0].size = cctx->remote_heap_size; >>> + cctx->audio_init_mem = true; >>> + inbuf.pageslen = 1; >>> + sent_heap = true; >>> + } else { >>> + pages[0].addr = 0; >>> + pages[0].size = 0; >>> + } >>> + spin_unlock_irqrestore(&cctx->lock, flags); >>> >>> args[2].ptr = (u64)(uintptr_t) pages; >>> args[2].length = sizeof(*pages); >>> @@ -1541,27 +1544,11 @@ static int fastrpc_init_create_static_process(struct fastrpc_user *fl, >>> >>> return 0; >>> err_invoke: >>> - if (fl->cctx->vmcount && scm_done) { >>> - u64 src_perms = 0; >>> - struct qcom_scm_vmperm dst_perms; >>> - u32 i; >>> - >>> - for (i = 0; i < fl->cctx->vmcount; i++) >>> - src_perms |= BIT(fl->cctx->vmperms[i].vmid); >>> - >>> - dst_perms.vmid = QCOM_SCM_VMID_HLOS; >>> - dst_perms.perm = QCOM_SCM_PERM_RWX; >>> - err = qcom_scm_assign_mem(fl->cctx->remote_heap->dma_addr, >>> - (u64)fl->cctx->remote_heap->size, >>> - &src_perms, &dst_perms, 1); >>> - if (err) >>> - dev_err(fl->sctx->dev, "Failed to assign memory dma_addr %pad size 0x%llx err %d\n", >>> - &fl->cctx->remote_heap->dma_addr, fl->cctx->remote_heap->size, err); >>> + if (sent_heap) { >>> + spin_lock_irqsave(&cctx->lock, flags); >>> + cctx->audio_init_mem = false; >>> + spin_unlock_irqrestore(&cctx->lock, flags); >>> } >>> -err_map: >>> - fastrpc_buf_free(fl->cctx->remote_heap); >>> - fl->cctx->remote_heap = NULL; >>> -err_name: >>> kfree(name); >>> err: >>> kfree(args); >>> @@ -2090,7 +2077,7 @@ static int fastrpc_req_mmap(struct fastrpc_user *fl, char __user *argp) >>> if (copy_from_user(&req, argp, sizeof(req))) >>> return -EFAULT; >>> >>> - if (req.flags != ADSP_MMAP_ADD_PAGES && req.flags != ADSP_MMAP_REMOTE_HEAP_ADDR) { >>> + if (req.flags != ADSP_MMAP_ADD_PAGES) { >>> dev_err(dev, "flag not supported 0x%x\n", req.flags); return -EINVAL; @@ -2101,10 +2088,7 @@ static int >>> fastrpc_req_mmap(struct fastrpc_user *fl, char __user *argp) return - >>> EINVAL; } - if (req.flags == ADSP_MMAP_REMOTE_HEAP_ADDR) - err = >>> fastrpc_remote_heap_alloc(fl, dev, req.size, &buf); - else - err = >>> fastrpc_buf_alloc(fl, dev, req.size, &buf); + err = >>> fastrpc_buf_alloc(fl, dev, req.size, &buf); if (err) { dev_err(dev, "failed to allocate buffer\n"); >>> @@ -2143,20 +2127,6 @@ static int fastrpc_req_mmap(struct fastrpc_user *fl, char __user *argp) >>> /* let the client know the address to use */ >>> req.vaddrout = rsp_msg.vaddr; >>> >>> - /* Add memory to static PD pool, protection thru hypervisor */ >>> - if (req.flags == ADSP_MMAP_REMOTE_HEAP_ADDR && fl->cctx->vmcount) { >>> - u64 src_perms = BIT(QCOM_SCM_VMID_HLOS); >>> - >>> - err = qcom_scm_assign_mem(buf->dma_addr, (u64)buf->size, >>> - &src_perms, fl->cctx->vmperms, fl->cctx->vmcount); >>> - if (err) { >>> - dev_err(fl->sctx->dev, >>> - "Failed to assign memory dma_addr %pad size 0x%llx err %d", >>> - &buf->dma_addr, buf->size, err); >>> - goto err_assign; >>> - } >>> - } >>> - >>> spin_lock(&fl->lock); >>> list_add_tail(&buf->node, &fl->mmaps); >>> spin_unlock(&fl->lock); >>> @@ -2537,6 +2507,16 @@ static const struct of_device_id fastrpc_poll_supported_machines[] __maybe_unuse >>> {}, >>> }; >>> >>> +static bool fastrpc_domain_has_reserved_heap(u32 domain_id) >>> +{ >>> + return domain_id == SDSP_DOMAIN_ID || domain_id == ADSP_DOMAIN_ID; >>> +} >>> + >>> +static bool fastrpc_domain_uses_static_heap(u32 domain_id) >>> +{ >>> + return domain_id == ADSP_DOMAIN_ID; >>> +} >> any reason to have functions for one time used checks?> + > > Just to give some context: I added these helpers based on the v11 > review, which requested replacing the open-coded ADSP/SDSP checks > with functions describing the per-domain capabilities. > > In this patch, they currently have a single caller each. > Therefore, if you feel it's unnecessary, I can revert > to the version without helpers. move the reserved memory initialization block to a new helper function, something like fastrpc_init_reserved_mem()> >>> static int fastrpc_rpmsg_probe(struct rpmsg_device *rpdev) >>> { >>> struct device *rdev = &rpdev->dev; >>> @@ -2584,20 +2564,25 @@ static int fastrpc_rpmsg_probe(struct rpmsg_device *rpdev) >>> } >>> } >>> >>> - if (domain_id == SDSP_DOMAIN_ID) { >>> + if (fastrpc_domain_has_reserved_heap(domain_id)) { >>> struct resource res; >>> u64 src_perms; >>> >>> err = of_reserved_mem_region_to_resource(rdev->of_node, 0, &res); >>> if (!err) { >>> + if (fastrpc_domain_uses_static_heap(domain_id)) { >>> + data->remote_heap_addr = res.start; >>> + data->remote_heap_size = resource_size(&res); >>> + } >>> src_perms = BIT(QCOM_SCM_VMID_HLOS); >>> >>> err = qcom_scm_assign_mem(res.start, resource_size(&res), &src_perms, >>> data->vmperms, data->vmcount); >> better to check vmcount before calling this> if (err) > > Agreed. I'll wrap the qcom_scm_assign_mem() call in if (data->vmcount) in v13. > >>> goto err_free_data; >>> + } else { >>> + err = 0; >>> } >>> - >>> } >>> >>> secure_dsp = !(of_property_read_bool(rdev->of_node, "qcom,non-secure-domain")); >>> @@ -2681,6 +2666,7 @@ static void fastrpc_rpmsg_remove(struct rpmsg_device *rpdev) >>> struct fastrpc_buf *buf, *b; >>> struct fastrpc_user *user; >>> unsigned long flags; >>> + int err, i; >>> >>> /* No invocations past this point */ >>> spin_lock_irqsave(&cctx->lock, flags); >>> @@ -2698,8 +2684,24 @@ static void fastrpc_rpmsg_remove(struct rpmsg_device *rpdev) >>> list_for_each_entry_safe(buf, b, &cctx->invoke_interrupted_mmaps, node) >>> list_del(&buf->node); >>> >>> - if (cctx->remote_heap) >>> - fastrpc_buf_free(cctx->remote_heap); >>> + if (cctx->remote_heap_size && cctx->vmcount) { >>> + u64 src_perms = 0; >>> + struct qcom_scm_vmperm dst_perms; >>> + >>> + for (i = 0; i < cctx->vmcount; i++) >>> + src_perms |= BIT(cctx->vmperms[i].vmid); >>> + >>> + dst_perms.vmid = QCOM_SCM_VMID_HLOS; >>> + dst_perms.perm = QCOM_SCM_PERM_RWX; >>> + >>> + err = qcom_scm_assign_mem(cctx->remote_heap_addr, >>> + cctx->remote_heap_size, &src_perms, >>> + &dst_perms, 1); >>> + if (err) >>> + dev_err(&rpdev->dev, >>> + "Failed to assign memory back to HLOS: addr %pa size %#llx err %d\n", >>> + &cctx->remote_heap_addr, cctx->remote_heap_size, err); >>> + } >>> >>> of_platform_depopulate(&rpdev->dev); >>>