From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2AC6C23C503 for ; Mon, 25 May 2026 03:30:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779679856; cv=none; b=HHKyTgalbjMu6i5gB4XGBcVnujQSAzEed9RcRMidhDZZUVPpf3ohQpGjjKE/0owD58LFC3pvDhcbsp55tPq6Pgcy86KlNlUX33AtjvfqkH5n7CtD2MwJlcpdXvFC4jc0Vc08pE8e+6Bai72V96bx9jM4NKJ0d2Q4tw1330etB24= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779679856; c=relaxed/simple; bh=YIsDSV6yvOZUdMHZ75MeNvg1gtcsZuqWcsVCfApJFk4=; h=Message-ID:Date:MIME-Version:Subject:To:References:Cc:From: In-Reply-To:Content-Type; b=IXdrDK2mPuQhN+QvOGzVLvX4lyl+w+N+kgj2kWhzMdg0Vc5z03siZcRtkVGk69OcPv+iCal0pSdGA1LL1ADmOkeoT8u4BsRKcb+4YqP7BNxQzrB2NYyptiNEHBbOfkS9A7bGijBhG2pSVQ6H+2pFLrrdhYvcHuyjXN9rb+kEkzw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=BR+YA7ex; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=HWmaXGKX; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="BR+YA7ex"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="HWmaXGKX" Received: from pps.filterd (m0279865.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 64OLprMh2904634 for ; Mon, 25 May 2026 03:30:54 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= 9ttDcIawSn5wHGMPcjxnIGUJLNBlKWRE6XzhIGYw9xo=; b=BR+YA7exBKoqJfyf IwhZWGrr7MBmRhR6IS2jPPb6DPtFRw5dIpxJ2IDCDzts1VBmK/mBbFIPeztpYkK/ /qNQRmYiLV5Jt8RdvMMRf3vgq6+BZWjF8lR7mn39lf7BVA88oVBg199rBHmB25PV OH3wWIniaymv2qPCP31bfSNCBygBxwcMZ0wG+H/G+xQ2XCVxdDfN0V9KAPa6rm2E T96WgZKmn1oM1hs78DjJy1cHj6YMId3NBaTNtjo1eBG8vVXJLEAXMZPsxNu4+Pm0 emrTDaeRF94MMRhcCT86VYwquaaknBhxGHg9NyIbkyfzKPytkxI9MLyuXrThJoZG BaKGEw== Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4eb36t4w4n-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Mon, 25 May 2026 03:30:54 +0000 (GMT) Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-36642d2f4deso18433813a91.3 for ; Sun, 24 May 2026 20:30:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1779679854; x=1780284654; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:cc:content-language :references:to:subject:user-agent:mime-version:date:message-id:from :to:cc:subject:date:message-id:reply-to; bh=9ttDcIawSn5wHGMPcjxnIGUJLNBlKWRE6XzhIGYw9xo=; b=HWmaXGKXAgdIOgWBHWy0xmXx8hJcxTcGZGvnJtAdU9pyatBCgcE0h1utyV3TAJMegX bjApyhqVsTJc6cvexU54jRtccrV9q4+JfNbvXy01fLDR3CRga6Xw8Rb3rmX5TvikDEsB qvKYCYwjbajT5vH7JzAJTgCBcB444am2ll0xQvR+NBwfnYI+U4P1a0uTppwvDKvaU/+e 4FN6x9yi0x+IVKGHWnILoIlUi+M5elDbWuDgjbAIr50C2RS5ZcR62ARoqYnO/NDwdbuv g8rSTqqax8VISYfGoNcsANtXi8HzSYA6CuqR396uZG1dPWUKZv8tZTq0e4N/n+Q/KkPM 73Eg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779679854; x=1780284654; h=content-transfer-encoding:in-reply-to:from:cc:content-language :references:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=9ttDcIawSn5wHGMPcjxnIGUJLNBlKWRE6XzhIGYw9xo=; b=hlwTfMh/sPVKQfbVlL4FqswBNm7II5Ywkjxqm3aHoFtZj7Hkeb6GT113zrRxj1kwKe mjIX5ono94IFz0AZuYzHrSIzvorO7hGGOJt/3ONeLdzwzN65FqUtuc+0L8noIoLMgglt ks24ls9VHj39x900y8cfoxb1E8wSoXnAjWcfy6jWN6YuDfxYptIiZuVX9QM3pJrVD5rh 7xdaIUc/6eaUzOdS5/GtjNaoD0sJd1fARkgQ3LAYAqBnyTwN/QZN76EB2loeN6ILQWQv co9n2kpOABh60IrgZCfpBHUgGE1fRz2kyf7/kBaoYaKYxAk5Qho/mKJI0s5vQmHbyBB0 KGaQ== X-Forwarded-Encrypted: i=1; AFNElJ9N0TP+7kV6ep49+4ZPW2bcd8YAS/1u7pHJvsewlIOkYGX+ToDEbinZCVDp4+QJ1ydCO6ZM+LU3CVdbFpU=@vger.kernel.org X-Gm-Message-State: AOJu0YwPQf57HDiWxxpqGyns7XhX8NaSHyMmeamVa+M0qWqR/NTYlUsB V3Qww8E0R2+XDevruSLhN+2LGROHEj07jBy8/pC6UC0H6Zkug4vqLcf9kLAYzAENoN+/H2pV/Bd e9iNT8APYT6nHkEtE1hjnVagk3sjg86g22v8ikHjTWSRMjNgtsbLAoJBfoe1mg6HRXHc= X-Gm-Gg: Acq92OEaFZAasn1RJpr8EW6U9IwmHCoIGTcO0wETuMUae8JMTthzWgpYtitqxcX0n4k EmIqmrAi7C1gtHlDFsuzc/f1y8GY0jtOpGPzmmT5zsM4tzeWkXJeYSJo0KBQC2FtfG4cbinl2t1 JET/pc5pbIo5M3Z3u7zzq7k0cHg0tVA0+RzMPtHIfhAp8fSiRt+0Bnjca00xNxtrSaoDx3rvO29 e0OD3i2iOvwHDvB51+M5nNd4vdvzWIa9ZVeCpMHnkSTq5rNEwGqUlv4ifB8gNIULGbzdzi9nFie W4IZNL3WvKDLeISM+OgyZfBwIU/+6lscltqGl2YZGPt7U/NXp3Kd0Ub07M63HIE8dgYr02cHob6 +7yX+Qns48vg558Z+qun6tmt/SmR2tAP5f3C9XQkeu5grDPo18s+4P0x/oJN7P9MAKy0QRvTItw qwp05+LKdNMv9HAvFf X-Received: by 2002:a05:6a21:164a:b0:3a2:bd1d:d679 with SMTP id adf61e73a8af0-3b328fd02e8mr13103525637.48.1779679853478; Sun, 24 May 2026 20:30:53 -0700 (PDT) X-Received: by 2002:a05:6a21:164a:b0:3a2:bd1d:d679 with SMTP id adf61e73a8af0-3b328fd02e8mr13103484637.48.1779679852995; Sun, 24 May 2026 20:30:52 -0700 (PDT) Received: from [10.133.33.205] (tpe-colo-wan-fw-bordernet.qualcomm.com. [103.229.16.4]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-c85202903absm6598010a12.7.2026.05.24.20.30.48 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sun, 24 May 2026 20:30:52 -0700 (PDT) Message-ID: Date: Mon, 25 May 2026 11:30:43 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v5 2/5] misc: fastrpc: Remove buffer from list prior to unmap operation To: Greg KH References: <20260515124217.20723-1-jianping.li@oss.qualcomm.com> <20260515124217.20723-3-jianping.li@oss.qualcomm.com> <37146a3a-b18f-40f1-b95b-0ac19bf6c07a@oss.qualcomm.com> <2026052211-pavilion-compost-5fcd@gregkh> Content-Language: en-US Cc: Dmitry Baryshkov , amahesh@qti.qualcomm.com, arnd@arndb.de, abelvesa@kernel.org, jorge.ramirez-ortiz@linaro.org, Ekansh Gupta , linux-arm-msm@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, quic_chennak@quicinc.com, stable@kernel.org From: Jianping Li In-Reply-To: <2026052211-pavilion-compost-5fcd@gregkh> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Proofpoint-GUID: 8B-rBUqW1eI8A-sbtgtzSmokuC-OCDjC X-Authority-Analysis: v=2.4 cv=Fto1OWrq c=1 sm=1 tr=0 ts=6a13c26e cx=c_pps a=vVfyC5vLCtgYJKYeQD43oA==:117 a=nuhDOHQX5FNHPW3J6Bj6AA==:17 a=IkcTkHD0fZMA:10 a=NGcC8JguVDcA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=Um2Pa8k9VHT-vaBCBUpS:22 a=EUspDBNiAAAA:8 a=nYJ9tK4vUQEl1fWjGX8A:9 a=QEXdDO2ut3YA:10 a=rl5im9kqc5Lf4LNbBjHf:22 X-Proofpoint-ORIG-GUID: 8B-rBUqW1eI8A-sbtgtzSmokuC-OCDjC X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNTI1MDAzMCBTYWx0ZWRfXyUlqahRq43lH 8Gk9gfRCwjz0rivt1DeMrme2oeDhv5lBvEKjD0KlKfOZLV0Kn6kuIcYqdg5bbqh0T6vsQPsxzB2 mHQ2OsGDeRIZou8KU1K03RXFgnNJvEQc55o2SMxzBMSEBJ+LDw1DnX3V3OJ6CkYWvwQYGV1h8V8 xz8Nxh/4RVSeb2mpQh713QrqjtziesHGR9K64Rd3ozKAwNfTEdKwOASchIeDVx3kex3kS+Hb8uI BSCAbR+4ydeFgoM9//PBojyTt/p9s53SkHTANuj4uEdzLd77UYhCD7IYiec82LDldaRFwvN8zhW LmU3cYabn8jO6GTR2yYTu/VfIR5NlV7xuga9jC/hjDBlOQALKFYr/csVvWqE+GPf7Vjxpk3LtWu KfnrP8T5WfT4kuPc8fQkpCTRfPum80h4/scruw4NAZBppabr4eHySAuFQAil0MZU/OimzW2C3oO TpU3M/8I3mYEvlXg3OQ== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-05-25_01,2026-05-18_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 bulkscore=0 malwarescore=0 priorityscore=1501 impostorscore=0 lowpriorityscore=0 spamscore=0 clxscore=1015 adultscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2605130000 definitions=main-2605250030 On 5/22/2026 3:03 PM, Greg KH wrote: > On Fri, May 22, 2026 at 02:55:29PM +0800, Jianping Li wrote: >> On 5/15/2026 9:36 PM, Dmitry Baryshkov wrote: >>> On Fri, May 15, 2026 at 08:42:14PM +0800, Jianping Li wrote: >>>> From: Ekansh Gupta >>>> >>>> fastrpc_req_munmap_impl() is called to unmap any buffer. The buffer is >>>> getting removed from the list after it is unmapped from DSP. This can >>>> create potential race conditions if any other thread removes the entry >>>> from list while unmap operation is ongoing. Remove the entry before >>> How can it remove the entry from the list? >> Multiple threads sharing the same file descriptor may invoke unmap concurrently. > multiple threads sharing the same file descriptor is a horrible > userspace bug. If you do that, you get what you deserve :) > > thanks, > > greg k-h I agree that concurrent unmap on the same buffer from multiple threads is a userspace bug. However, the fastrpc driver is exposed via ioctl, and any userspace (including any random apk) can map directly and then call multiple unmap. This patch is not intended to support incorrect userspace usage, but to ensure that the driver remains robust against invalid or racy inputs. Thanks, Jianping.