dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v5 0/3] misc: fastrpc: fix ADSP duplicate session creation
@ 2026-09-23  8:39 Vinayak Katoch
  2026-09-23  8:39 ` [PATCH v5 1/3] misc: fastrpc: iterate CB nodes manually instead of of_platform_populate Vinayak Katoch
                   ` (2 more replies)
  0 siblings, 3 replies; 10+ messages in thread
From: Vinayak Katoch @ 2026-09-23  8:39 UTC (permalink / raw)
  To: Srinivas Kandagatla, Amol Maheshwari, Arnd Bergmann,
	Greg Kroah-Hartman, Rob Herring, Krzysztof Kozlowski,
	Conor Dooley, Ekansh Gupta
  Cc: linux-arm-msm, dri-devel, linux-kernel, Bharath Kumar,
	Chenna Kesava Raju, devicetree, Vinayak Katoch,
	Krzysztof Kozlowski

For ADSP, only a limited number of FastRPC context banks (CBs) are
available. Each CB supports a single session, which means only a few
processes can run on ADSP simultaneously. If all sessions are consumed
by fastrpc daemons, no session remains available when a user application
starts, causing the application to fail.

To work around this, some DT set:
  qcom,nsessions = <5>;
which duplicated sessions inline during context bank initialisation.
Upstream feedback indicated that this policy does not belong in DT and
should be handled at the driver level instead.

This series iterates over CB child nodes directly and synchronously,
replacing of_platform_populate() and of_platform_depopulate(), and moves
the ADSP session duplication to the driver. The qcom,nsessions binding
is deprecated in the same series.

Signed-off-by: Vinayak Katoch <vinayak.katoch@oss.qualcomm.com>
---
Changes in v5:
- Introduce fastrpc_cb_devices_create() and fastrpc_cb_devices_destroy()
  for symmetric CB device lifecycle management in probe and remove.
- Replace module_init/exit pair with module_rpmsg_driver().
- Link to v4: https://lore.kernel.org/r/20260826-dup-sessions-v4-0-35555d2bfed4@oss.qualcomm.com

Changes in v4:
- Rebased on latest linux-next (a8406e6c0b79, 2026-08-25)
- Link to v3: https://lore.kernel.org/r/20260824-dup-sessions-v3-0-4b019def4e0b@oss.qualcomm.com

Changes in v3:
- Add patch to fix async probe race with of_platform_populate().
- Rename fastrpc_cb_probe() to fastrpc_cb_init().
- Reorder series: sync fix, nsessions, binding.
- Collect Reviewed-by tags.
- Link to v2: https://lore.kernel.org/r/20260708-dup-sessions-v2-0-da40f9c98a2b@oss.qualcomm.com

Changes in v2:
- Added patch to deprecate the qcom,nsessions dt-binding.
- Kept the logic unchanged; only split into two patches.
- Link to v1: https://lore.kernel.org/r/20260609-dup-sessions-v1-1-26934abb9fa3@oss.qualcomm.com

---
Vinayak Katoch (3):
      misc: fastrpc: iterate CB nodes manually instead of of_platform_populate
      misc: fastrpc: move ADSP duplicate session creation to the driver
      dt-bindings: misc: qcom,fastrpc: deprecate qcom,nsessions

 .../devicetree/bindings/misc/qcom,fastrpc.yaml     |   2 +
 drivers/misc/fastrpc.c                             | 133 +++++++++++----------
 2 files changed, 71 insertions(+), 64 deletions(-)
---
base-commit: 5c4d4169604b335c38bbc79bc1fc03042981fc6f
change-id: 20260609-dup-sessions-ea2acaac1994

Best regards,
-- 
Vinayak Katoch <vinayak.katoch@oss.qualcomm.com>


^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PATCH v5 1/3] misc: fastrpc: iterate CB nodes manually instead of of_platform_populate
  2026-09-23  8:39 [PATCH v5 0/3] misc: fastrpc: fix ADSP duplicate session creation Vinayak Katoch
@ 2026-09-23  8:39 ` Vinayak Katoch
  2026-09-23  8:50   ` sashiko-bot
  2026-10-09  6:02   ` Ekansh Gupta
  2026-09-23  8:39 ` [PATCH v5 2/3] misc: fastrpc: move ADSP duplicate session creation to the driver Vinayak Katoch
  2026-09-23  8:39 ` [PATCH v5 3/3] dt-bindings: misc: qcom,fastrpc: deprecate qcom,nsessions Vinayak Katoch
  2 siblings, 2 replies; 10+ messages in thread
From: Vinayak Katoch @ 2026-09-23  8:39 UTC (permalink / raw)
  To: Srinivas Kandagatla, Amol Maheshwari, Arnd Bergmann,
	Greg Kroah-Hartman, Rob Herring, Krzysztof Kozlowski,
	Conor Dooley, Ekansh Gupta
  Cc: linux-arm-msm, dri-devel, linux-kernel, Bharath Kumar,
	Chenna Kesava Raju, devicetree, Vinayak Katoch

of_platform_populate() only guarantees that child devices are registered,
not that their probes have completed before it returns. This creates a
window where fastrpc_cb_init() may not have run for all context bank
nodes, leaving the channel context partially initialised.

Introduce fastrpc_cb_devices_create() to iterate over child DT nodes
directly and call fastrpc_cb_init() synchronously for each
qcom,fastrpc-compute-cb node. This ensures all context banks are fully
initialised before fastrpc_rpmsg_probe() returns.

Introduce fastrpc_cb_devices_destroy() as the symmetric counterpart.
Before destroying the CB platform devices, invalidate all sessions under
the channel lock so that any fastrpc_user still holding a reference to
the channel context cannot acquire a new session backed by a destroyed
device.

Since fastrpc_cb_driver is no longer needed as an independent platform
driver, remove it along with its match table and remove callback. Use
module_rpmsg_driver() now that only a single driver registration remains.

Signed-off-by: Vinayak Katoch <vinayak.katoch@oss.qualcomm.com>
---
 drivers/misc/fastrpc.c | 104 ++++++++++++++++++++++++-------------------------
 1 file changed, 52 insertions(+), 52 deletions(-)

diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c
index af18ff1992ee..f20d3e5ecc81 100644
--- a/drivers/misc/fastrpc.c
+++ b/drivers/misc/fastrpc.c
@@ -2333,7 +2333,7 @@ static const struct file_operations fastrpc_fops = {
 	.compat_ioctl = fastrpc_device_ioctl,
 };
 
-static int fastrpc_cb_probe(struct platform_device *pdev)
+static int fastrpc_cb_init(struct platform_device *pdev)
 {
 	struct fastrpc_channel_ctx *cctx;
 	struct fastrpc_session_ctx *sess;
@@ -2355,7 +2355,7 @@ static int fastrpc_cb_probe(struct platform_device *pdev)
 	spin_lock_irqsave(&cctx->lock, flags);
 	if (cctx->sesscount >= FASTRPC_MAX_SESSIONS) {
 		spin_unlock_irqrestore(&cctx->lock, flags);
-		dev_err(&pdev->dev, "too many sessions\n");
+		dev_err(dev, "too many sessions\n");
 		return -ENOSPC;
 	}
 	dma_bits = cctx->soc_data->dma_addr_bits_default;
@@ -2389,37 +2389,63 @@ static int fastrpc_cb_probe(struct platform_device *pdev)
 	return 0;
 }
 
-static void fastrpc_cb_remove(struct platform_device *pdev)
+static void fastrpc_cb_devices_destroy(struct rpmsg_device *rpdev)
 {
-	struct fastrpc_channel_ctx *cctx = dev_get_drvdata(pdev->dev.parent);
-	struct fastrpc_session_ctx *sess = dev_get_drvdata(&pdev->dev);
+	struct fastrpc_channel_ctx *cctx = dev_get_drvdata(&rpdev->dev);
+	struct device *rdev = &rpdev->dev;
+	struct platform_device *pdev;
+	struct device_node *np;
 	unsigned long flags;
 	int i;
 
 	spin_lock_irqsave(&cctx->lock, flags);
-	for (i = 0; i < FASTRPC_MAX_SESSIONS; i++) {
-		if (cctx->session[i].sid == sess->sid) {
-			cctx->session[i].valid = false;
-			cctx->sesscount--;
+	for (i = 0; i < cctx->sesscount; i++)
+		cctx->session[i].valid = false;
+	spin_unlock_irqrestore(&cctx->lock, flags);
+
+	for_each_available_child_of_node(rdev->of_node, np) {
+		if (!of_device_is_compatible(np, "qcom,fastrpc-compute-cb")) {
+			of_node_put(np);
+			continue;
 		}
+
+		pdev = of_find_device_by_node(np);
+		of_node_put(np);
+		if (pdev)
+			of_platform_device_destroy(&pdev->dev, NULL);
 	}
-	spin_unlock_irqrestore(&cctx->lock, flags);
 }
 
-static const struct of_device_id fastrpc_match_table[] = {
-	{ .compatible = "qcom,fastrpc-compute-cb" },
-	{ }
-};
+static int fastrpc_cb_devices_create(struct rpmsg_device *rpdev)
+{
+	struct device *rdev = &rpdev->dev;
+	struct platform_device *pdev;
+	struct device_node *np;
+	int err;
 
-static struct platform_driver fastrpc_cb_driver = {
-	.probe = fastrpc_cb_probe,
-	.remove = fastrpc_cb_remove,
-	.driver = {
-		.name = "qcom,fastrpc-cb",
-		.of_match_table = fastrpc_match_table,
-		.suppress_bind_attrs = true,
-	},
-};
+	for_each_available_child_of_node(rdev->of_node, np) {
+		if (!of_device_is_compatible(np, "qcom,fastrpc-compute-cb")) {
+			of_node_put(np);
+			continue;
+		}
+
+		pdev = of_platform_device_create(np, NULL, rdev);
+		if (!pdev) {
+			of_node_put(np);
+			fastrpc_cb_devices_destroy(rpdev);
+			return -EINVAL;
+		}
+
+		err = fastrpc_cb_init(pdev);
+		if (err) {
+			of_node_put(np);
+			fastrpc_cb_devices_destroy(rpdev);
+			return err;
+		}
+	}
+
+	return 0;
+}
 
 static int fastrpc_device_register(struct device *dev, struct fastrpc_channel_ctx *cctx,
 				   bool is_secured, const char *domain)
@@ -2639,7 +2665,7 @@ static int fastrpc_rpmsg_probe(struct rpmsg_device *rpdev)
 	data->rpdev = rpdev;
 	dev_set_drvdata(&rpdev->dev, data);
 
-	err = of_platform_populate(rdev->of_node, NULL, NULL, rdev);
+	err = fastrpc_cb_devices_create(rpdev);
 	if (err)
 		goto err_deregister_fdev;
 
@@ -2711,7 +2737,7 @@ static void fastrpc_rpmsg_remove(struct rpmsg_device *rpdev)
 				&cctx->remote_heap_addr, cctx->remote_heap_size, err);
 	}
 
-	of_platform_depopulate(&rpdev->dev);
+	fastrpc_cb_devices_destroy(rpdev);
 
 	fastrpc_channel_ctx_put(cctx);
 }
@@ -2798,33 +2824,7 @@ static struct rpmsg_driver fastrpc_driver = {
 	},
 };
 
-static int fastrpc_init(void)
-{
-	int ret;
-
-	ret = platform_driver_register(&fastrpc_cb_driver);
-	if (ret < 0) {
-		pr_err("fastrpc: failed to register cb driver\n");
-		return ret;
-	}
-
-	ret = register_rpmsg_driver(&fastrpc_driver);
-	if (ret < 0) {
-		pr_err("fastrpc: failed to register rpmsg driver\n");
-		platform_driver_unregister(&fastrpc_cb_driver);
-		return ret;
-	}
-
-	return 0;
-}
-module_init(fastrpc_init);
-
-static void fastrpc_exit(void)
-{
-	platform_driver_unregister(&fastrpc_cb_driver);
-	unregister_rpmsg_driver(&fastrpc_driver);
-}
-module_exit(fastrpc_exit);
+module_rpmsg_driver(fastrpc_driver);
 
 MODULE_DESCRIPTION("Qualcomm FastRPC");
 MODULE_LICENSE("GPL v2");

-- 
2.34.1


^ permalink raw reply related	[flat|nested] 10+ messages in thread

* [PATCH v5 2/3] misc: fastrpc: move ADSP duplicate session creation to the driver
  2026-09-23  8:39 [PATCH v5 0/3] misc: fastrpc: fix ADSP duplicate session creation Vinayak Katoch
  2026-09-23  8:39 ` [PATCH v5 1/3] misc: fastrpc: iterate CB nodes manually instead of of_platform_populate Vinayak Katoch
@ 2026-09-23  8:39 ` Vinayak Katoch
  2026-09-23  8:50   ` sashiko-bot
  2026-10-09  6:11   ` Ekansh Gupta
  2026-09-23  8:39 ` [PATCH v5 3/3] dt-bindings: misc: qcom,fastrpc: deprecate qcom,nsessions Vinayak Katoch
  2 siblings, 2 replies; 10+ messages in thread
From: Vinayak Katoch @ 2026-09-23  8:39 UTC (permalink / raw)
  To: Srinivas Kandagatla, Amol Maheshwari, Arnd Bergmann,
	Greg Kroah-Hartman, Rob Herring, Krzysztof Kozlowski,
	Conor Dooley, Ekansh Gupta
  Cc: linux-arm-msm, dri-devel, linux-kernel, Bharath Kumar,
	Chenna Kesava Raju, devicetree, Vinayak Katoch

For ADSP, only a limited number of FastRPC context banks (CBs) are
available. Each CB supports a single session, which means only a few
processes can run on ADSP simultaneously. If all sessions are consumed
by fastrpc daemons, no session remains available when a user application
starts, causing the application to fail.

To work around this, qcom,nsessions = <5> was set in DT to duplicate
sessions inline during fastrpc_cb_init(). This policy does not belong
in DT and should be handled at the driver level instead.

Remove the qcom,nsessions DT property read and the per-CB duplication
logic from fastrpc_cb_init(). After all context banks have been
initialised in fastrpc_rpmsg_probe(), append FASTRPC_DUP_SESSIONS (4)
copies of the last session for the ADSP domain.

Signed-off-by: Vinayak Katoch <vinayak.katoch@oss.qualcomm.com>
---
 drivers/misc/fastrpc.c | 29 +++++++++++++++++------------
 1 file changed, 17 insertions(+), 12 deletions(-)

diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c
index f20d3e5ecc81..b29c1fd00de2 100644
--- a/drivers/misc/fastrpc.c
+++ b/drivers/misc/fastrpc.c
@@ -34,6 +34,7 @@
 #define CDSP_DOMAIN_ID (3)
 #define GDSP_DOMAIN_ID (4)
 #define FASTRPC_MAX_SESSIONS	14
+#define FASTRPC_DUP_SESSIONS	4
 #define FASTRPC_MAX_VMIDS	16
 #define FASTRPC_ALIGN		128
 #define FASTRPC_MAX_FDLIST	16
@@ -2338,7 +2339,6 @@ static int fastrpc_cb_init(struct platform_device *pdev)
 	struct fastrpc_channel_ctx *cctx;
 	struct fastrpc_session_ctx *sess;
 	struct device *dev = &pdev->dev;
-	int i, sessions = 0;
 	unsigned long flags;
 	u32 dma_bits;
 	u32 sid = 0;
@@ -2348,7 +2348,6 @@ static int fastrpc_cb_init(struct platform_device *pdev)
 	if (!cctx)
 		return -EINVAL;
 
-	of_property_read_u32(dev->of_node, "qcom,nsessions", &sessions);
 	if (of_property_read_u32(dev->of_node, "reg", &sid))
 		dev_info(dev, "FastRPC Session ID not specified in DT\n");
 
@@ -2369,16 +2368,6 @@ static int fastrpc_cb_init(struct platform_device *pdev)
 	if (cctx->domain_id == CDSP_DOMAIN_ID)
 		dma_bits = cctx->soc_data->dma_addr_bits_cdsp;
 
-	if (sessions > 0) {
-		struct fastrpc_session_ctx *dup_sess;
-
-		for (i = 1; i < sessions; i++) {
-			if (cctx->sesscount >= FASTRPC_MAX_SESSIONS)
-				break;
-			dup_sess = &cctx->session[cctx->sesscount++];
-			memcpy(dup_sess, sess, sizeof(*dup_sess));
-		}
-	}
 	spin_unlock_irqrestore(&cctx->lock, flags);
 	rc = dma_set_mask(dev, DMA_BIT_MASK(dma_bits));
 	if (rc) {
@@ -2669,6 +2658,22 @@ static int fastrpc_rpmsg_probe(struct rpmsg_device *rpdev)
 	if (err)
 		goto err_deregister_fdev;
 
+	if (data->domain_id == ADSP_DOMAIN_ID && data->sesscount > 0) {
+		struct fastrpc_session_ctx *last_sess;
+		struct fastrpc_session_ctx *dup_sess;
+		unsigned long flags;
+
+		spin_lock_irqsave(&data->lock, flags);
+		last_sess = &data->session[data->sesscount - 1];
+		for (i = 0; i < FASTRPC_DUP_SESSIONS; i++) {
+			if (data->sesscount >= FASTRPC_MAX_SESSIONS)
+				break;
+			dup_sess = &data->session[data->sesscount++];
+			memcpy(dup_sess, last_sess, sizeof(*dup_sess));
+		}
+		spin_unlock_irqrestore(&data->lock, flags);
+	}
+
 	return 0;
 
 err_deregister_fdev:

-- 
2.34.1


^ permalink raw reply related	[flat|nested] 10+ messages in thread

* [PATCH v5 3/3] dt-bindings: misc: qcom,fastrpc: deprecate qcom,nsessions
  2026-09-23  8:39 [PATCH v5 0/3] misc: fastrpc: fix ADSP duplicate session creation Vinayak Katoch
  2026-09-23  8:39 ` [PATCH v5 1/3] misc: fastrpc: iterate CB nodes manually instead of of_platform_populate Vinayak Katoch
  2026-09-23  8:39 ` [PATCH v5 2/3] misc: fastrpc: move ADSP duplicate session creation to the driver Vinayak Katoch
@ 2026-09-23  8:39 ` Vinayak Katoch
  2026-09-23  8:50   ` sashiko-bot
  2026-10-09  6:12   ` Ekansh Gupta
  2 siblings, 2 replies; 10+ messages in thread
From: Vinayak Katoch @ 2026-09-23  8:39 UTC (permalink / raw)
  To: Srinivas Kandagatla, Amol Maheshwari, Arnd Bergmann,
	Greg Kroah-Hartman, Rob Herring, Krzysztof Kozlowski,
	Conor Dooley, Ekansh Gupta
  Cc: linux-arm-msm, dri-devel, linux-kernel, Bharath Kumar,
	Chenna Kesava Raju, devicetree, Vinayak Katoch,
	Krzysztof Kozlowski

The qcom,nsessions property was used to duplicate FastRPC sessions
inline during context bank initialisation. Session duplication is now
handled at the driver level, making this DT property redundant. Mark
it deprecated.

Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Signed-off-by: Vinayak Katoch <vinayak.katoch@oss.qualcomm.com>
---
 Documentation/devicetree/bindings/misc/qcom,fastrpc.yaml | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/Documentation/devicetree/bindings/misc/qcom,fastrpc.yaml b/Documentation/devicetree/bindings/misc/qcom,fastrpc.yaml
index 49d2a5e8ba39..e945c8ba75e3 100644
--- a/Documentation/devicetree/bindings/misc/qcom,fastrpc.yaml
+++ b/Documentation/devicetree/bindings/misc/qcom,fastrpc.yaml
@@ -101,8 +101,10 @@ patternProperties:
       qcom,nsessions:
         $ref: /schemas/types.yaml#/definitions/uint32
         default: 1
+        deprecated: true
         description: >
           A value indicating how many sessions can share this context bank.
+          Session duplication is now handled by the driver.
 
     required:
       - compatible

-- 
2.34.1


^ permalink raw reply related	[flat|nested] 10+ messages in thread

* Re: [PATCH v5 3/3] dt-bindings: misc: qcom,fastrpc: deprecate qcom,nsessions
  2026-09-23  8:39 ` [PATCH v5 3/3] dt-bindings: misc: qcom,fastrpc: deprecate qcom,nsessions Vinayak Katoch
@ 2026-09-23  8:50   ` sashiko-bot
  2026-10-09  6:12   ` Ekansh Gupta
  1 sibling, 0 replies; 10+ messages in thread
From: sashiko-bot @ 2026-09-23  8:50 UTC (permalink / raw)
  To: Vinayak Katoch; +Cc: robh, conor+dt, dri-devel, devicetree

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] of: use-after-free and double put on device tree node during iteration
- [Medium] device: memory leak due to missing put_device() after of_find_device_by_node()
--

commit 0cd61e434e0b0defac9c431333bfa40bb39df800
Author: Vinayak Katoch <vinayak.katoch@oss.qualcomm.com>

misc: fastrpc: iterate CB nodes manually instead of of_platform_populate

This commit replaces of_platform_populate() with manual iteration of device
tree child nodes to ensure context banks are fully initialised before
fastrpc_rpmsg_probe() returns. It introduces fastrpc_cb_devices_create()
and fastrpc_cb_devices_destroy() to handle this synchronous setup and
teardown.

> diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c
> index af18ff1992eed..f20d3e5ecc81f 100644
> --- a/drivers/misc/fastrpc.c
> +++ b/drivers/misc/fastrpc.c
[ ... ]
> @@ -2389,37 +2389,63 @@ static int fastrpc_cb_probe(struct platform_device *pdev)
>  	return 0;
>  }
>  
> -static void fastrpc_cb_remove(struct platform_device *pdev)
> +static void fastrpc_cb_devices_destroy(struct rpmsg_device *rpdev)
>  {
> -	struct fastrpc_channel_ctx *cctx = dev_get_drvdata(pdev->dev.parent);
> -	struct fastrpc_session_ctx *sess = dev_get_drvdata(&pdev->dev);
> +	struct fastrpc_channel_ctx *cctx = dev_get_drvdata(&rpdev->dev);
> +	struct device *rdev = &rpdev->dev;
> +	struct platform_device *pdev;
> +	struct device_node *np;
>  	unsigned long flags;
>  	int i;
>  
>  	spin_lock_irqsave(&cctx->lock, flags);
> -	for (i = 0; i < FASTRPC_MAX_SESSIONS; i++) {
> -		if (cctx->session[i].sid == sess->sid) {
> -			cctx->session[i].valid = false;
> -			cctx->sesscount--;
> +	for (i = 0; i < cctx->sesscount; i++)
> +		cctx->session[i].valid = false;
> +	spin_unlock_irqrestore(&cctx->lock, flags);
> +
> +	for_each_available_child_of_node(rdev->of_node, np) {
> +		if (!of_device_is_compatible(np, "qcom,fastrpc-compute-cb")) {
> +			of_node_put(np);
> +			continue;
>  		}

[Severity: High]
Can this result in a double-put and use-after-free on the device tree node?

The for_each_available_child_of_node() macro automatically handles dropping
the reference on the current child node at the end of each iteration via
of_get_next_available_child(). Calling of_node_put(np) manually before
continue causes the iterator to dereference np->sibling on the already-freed
node, followed by a second of_node_put(np) that underflows the reference
count.

> +
> +		pdev = of_find_device_by_node(np);
> +		of_node_put(np);

[Severity: High]
Will this manual of_node_put() lead to the same use-after-free issue?

Calling of_node_put(np) manually at the end of the loop body causes the same
issue with the loop macro underflowing the reference count and accessing the
freed node during iteration.

> +		if (pdev)
> +			of_platform_device_destroy(&pdev->dev, NULL);

[Severity: Medium]
Could this leak the pdev device reference?

of_find_device_by_node() acquires a device reference by incrementing its
refcount. This reference doesn't appear to be released via put_device(&pdev->dev)
or platform_device_put(pdev) after calling of_platform_device_destroy().

>  	}
> -	spin_unlock_irqrestore(&cctx->lock, flags);
>  }
>  
> -static const struct of_device_id fastrpc_match_table[] = {
> -	{ .compatible = "qcom,fastrpc-compute-cb" },
> -	{ }
> -};
> +static int fastrpc_cb_devices_create(struct rpmsg_device *rpdev)
> +{
> +	struct device *rdev = &rpdev->dev;
> +	struct platform_device *pdev;
> +	struct device_node *np;
> +	int err;
>  
> -static struct platform_driver fastrpc_cb_driver = {
> -	.probe = fastrpc_cb_probe,
> -	.remove = fastrpc_cb_remove,
> -	.driver = {
> -		.name = "qcom,fastrpc-cb",
> -		.of_match_table = fastrpc_match_table,
> -		.suppress_bind_attrs = true,
> -	},
> -};
> +	for_each_available_child_of_node(rdev->of_node, np) {
> +		if (!of_device_is_compatible(np, "qcom,fastrpc-compute-cb")) {
> +			of_node_put(np);
> +			continue;
> +		}

[Severity: High]
Does this early of_node_put() cause a similar double-put and use-after-free
during the loop iteration?

Similar to fastrpc_cb_devices_destroy(), calling of_node_put(np) before
continue will double-put the node and use-after-free np->sibling during
the loop iteration.

> +
> +		pdev = of_platform_device_create(np, NULL, rdev);
[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260923-dup-sessions-v5-0-e953133a1827@oss.qualcomm.com?part=3

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH v5 2/3] misc: fastrpc: move ADSP duplicate session creation to the driver
  2026-09-23  8:39 ` [PATCH v5 2/3] misc: fastrpc: move ADSP duplicate session creation to the driver Vinayak Katoch
@ 2026-09-23  8:50   ` sashiko-bot
  2026-10-09  6:11   ` Ekansh Gupta
  1 sibling, 0 replies; 10+ messages in thread
From: sashiko-bot @ 2026-09-23  8:50 UTC (permalink / raw)
  To: Vinayak Katoch; +Cc: dri-devel, conor+dt, robh, devicetree

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] misc: fastrpc: duplicated ADSP sessions leak due to probe race condition
--

commit 6af4cd918024ca72389e7e81cea29baaabd3588c
Author: Vinayak Katoch <vinayak.katoch@oss.qualcomm.com>

misc: fastrpc: move ADSP duplicate session creation to the driver

This commit removes the qcom,nsessions DT property read from
fastrpc_cb_init() and stops duplicating sessions at the context bank level.
Instead, it adds a fixed loop in fastrpc_rpmsg_probe() that duplicates the
last ADSP session FASTRPC_DUP_SESSIONS times.

> diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c
> index f20d3e5ecc81f..b29c1fd00de28 100644
> --- a/drivers/misc/fastrpc.c
> +++ b/drivers/misc/fastrpc.c

> [ ... ]

> @@ -2669,6 +2658,22 @@ static int fastrpc_rpmsg_probe(struct rpmsg_device *rpdev)
>  	if (err)
>  		goto err_deregister_fdev;
>  
> +	if (data->domain_id == ADSP_DOMAIN_ID && data->sesscount > 0) {
> +		struct fastrpc_session_ctx *last_sess;
> +		struct fastrpc_session_ctx *dup_sess;
> +		unsigned long flags;
> +
> +		spin_lock_irqsave(&data->lock, flags);
> +		last_sess = &data->session[data->sesscount - 1];
> +		for (i = 0; i < FASTRPC_DUP_SESSIONS; i++) {
> +			if (data->sesscount >= FASTRPC_MAX_SESSIONS)
> +				break;
> +			dup_sess = &data->session[data->sesscount++];
> +			memcpy(dup_sess, last_sess, sizeof(*dup_sess));

[Severity: Medium]
Can this sequence result in leaked duplicate sessions?

Looking at fastrpc_rpmsg_probe(), the misc device is registered via
fastrpc_device_register() and exposed to userspace before we reach this loop.

If a concurrent userspace application calls open() and triggers
fastrpc_session_alloc(), it could mark the last session's used flag as true.

Since this loop uses memcpy() to duplicate last_sess, wouldn't it blindly
copy the used = true state into all the newly created duplicate sessions?

If so, these duplicates would be permanently marked as in-use without being
assigned to an active user context, causing them to leak and remain
permanently unavailable.

> +		}
> +		spin_unlock_irqrestore(&data->lock, flags);
> +	}
> +
>  	return 0;
>  
>  err_deregister_fdev:

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260923-dup-sessions-v5-0-e953133a1827@oss.qualcomm.com?part=2

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH v5 1/3] misc: fastrpc: iterate CB nodes manually instead of of_platform_populate
  2026-09-23  8:39 ` [PATCH v5 1/3] misc: fastrpc: iterate CB nodes manually instead of of_platform_populate Vinayak Katoch
@ 2026-09-23  8:50   ` sashiko-bot
  2026-10-09  6:02   ` Ekansh Gupta
  1 sibling, 0 replies; 10+ messages in thread
From: sashiko-bot @ 2026-09-23  8:50 UTC (permalink / raw)
  To: Vinayak Katoch; +Cc: robh, devicetree, dri-devel, conor+dt

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] of: double-free of device_node references in OF iterator loops
- [Medium] driver-core: memory leak of platform_device in fastrpc_cb_devices_destroy
--

commit 0cd61e434e0b0defac9c431333bfa40bb39df800
Author: Vinayak Katoch <vinayak.katoch@oss.qualcomm.com>

misc: fastrpc: iterate CB nodes manually instead of of_platform_populate

This commit replaces of_platform_populate() with direct iteration over child 
context bank nodes to ensure synchronous initialization via fastrpc_cb_init().
It also introduces fastrpc_cb_devices_destroy() to manually clean up platform 
devices during teardown and removes the standalone platform driver.

> diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c
> index af18ff1992eed..f20d3e5ecc81f 100644
> --- a/drivers/misc/fastrpc.c
> +++ b/drivers/misc/fastrpc.c
[ ... ]
> @@ -2389,37 +2389,63 @@ static int fastrpc_cb_probe(struct platform_device *pdev)
> -static void fastrpc_cb_remove(struct platform_device *pdev)
> +static void fastrpc_cb_devices_destroy(struct rpmsg_device *rpdev)
>  {
[ ... ]
> +	for_each_available_child_of_node(rdev->of_node, np) {
> +		if (!of_device_is_compatible(np, "qcom,fastrpc-compute-cb")) {
> +			of_node_put(np);
> +			continue;
>  		}

[Severity: High]
Does explicitly dropping the reference before continue result in a double-free
when the loop macro advances? The for_each_available_child_of_node() iterator
inherently calls of_node_put() on the previous node when advancing. This
occurs here during device destruction in fastrpc_cb_devices_destroy().

> +
> +		pdev = of_find_device_by_node(np);
> +		of_node_put(np);

[Severity: High]
Does explicitly dropping the reference at the end of the loop body result in a
double-free when the loop macro advances to the next iteration?

> +		if (pdev)
> +			of_platform_device_destroy(&pdev->dev, NULL);
>  	}

[Severity: Medium]
Does this leak the platform_device reference acquired by
of_find_device_by_node() in fastrpc_cb_devices_destroy()? The reference
returned by of_find_device_by_node() has an incremented reference count, which
doesn't appear to be released via put_device() or platform_device_put() after
unregistering the device.

> -	spin_unlock_irqrestore(&cctx->lock, flags);
>  }
>  
[ ... ]
> +static int fastrpc_cb_devices_create(struct rpmsg_device *rpdev)
> +{
> +	struct device *rdev = &rpdev->dev;
> +	struct platform_device *pdev;
> +	struct device_node *np;
> +	int err;
>  
> +	for_each_available_child_of_node(rdev->of_node, np) {
> +		if (!of_device_is_compatible(np, "qcom,fastrpc-compute-cb")) {
> +			of_node_put(np);
> +			continue;
> +		}

[Severity: High]
Does explicitly dropping the reference before continue result in a double-free
when the loop macro advances? The for_each_available_child_of_node() iterator
inherently calls of_node_put() on the previous node when advancing. This
occurs during driver initialization in fastrpc_cb_devices_create().

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260923-dup-sessions-v5-0-e953133a1827@oss.qualcomm.com?part=1

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH v5 1/3] misc: fastrpc: iterate CB nodes manually instead of of_platform_populate
  2026-09-23  8:39 ` [PATCH v5 1/3] misc: fastrpc: iterate CB nodes manually instead of of_platform_populate Vinayak Katoch
  2026-09-23  8:50   ` sashiko-bot
@ 2026-10-09  6:02   ` Ekansh Gupta
  1 sibling, 0 replies; 10+ messages in thread
From: Ekansh Gupta @ 2026-10-09  6:02 UTC (permalink / raw)
  To: Vinayak Katoch, Srinivas Kandagatla, Amol Maheshwari,
	Arnd Bergmann, Greg Kroah-Hartman, Rob Herring,
	Krzysztof Kozlowski, Conor Dooley
  Cc: linux-arm-msm, dri-devel, linux-kernel, Bharath Kumar,
	Chenna Kesava Raju, devicetree

On 23-09-2026 14:09, Vinayak Katoch wrote:
> of_platform_populate() only guarantees that child devices are registered,
> not that their probes have completed before it returns. This creates a
> window where fastrpc_cb_init() may not have run for all context bank
> nodes, leaving the channel context partially initialised.
> 
> Introduce fastrpc_cb_devices_create() to iterate over child DT nodes
> directly and call fastrpc_cb_init() synchronously for each
> qcom,fastrpc-compute-cb node. This ensures all context banks are fully
> initialised before fastrpc_rpmsg_probe() returns.
> 
> Introduce fastrpc_cb_devices_destroy() as the symmetric counterpart.
> Before destroying the CB platform devices, invalidate all sessions under
> the channel lock so that any fastrpc_user still holding a reference to
> the channel context cannot acquire a new session backed by a destroyed
> device.
> 
> Since fastrpc_cb_driver is no longer needed as an independent platform
> driver, remove it along with its match table and remove callback. Use
> module_rpmsg_driver() now that only a single driver registration remains.
> 
> Signed-off-by: Vinayak Katoch <vinayak.katoch@oss.qualcomm.com>
> ---
>  drivers/misc/fastrpc.c | 104 ++++++++++++++++++++++++-------------------------
>  1 file changed, 52 insertions(+), 52 deletions(-)
> 
> diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c
> index af18ff1992ee..f20d3e5ecc81 100644
> --- a/drivers/misc/fastrpc.c
> +++ b/drivers/misc/fastrpc.c
> @@ -2333,7 +2333,7 @@ static const struct file_operations fastrpc_fops = {
>  	.compat_ioctl = fastrpc_device_ioctl,
>  };
>  
> -static int fastrpc_cb_probe(struct platform_device *pdev)
> +static int fastrpc_cb_init(struct platform_device *pdev)
>  {
>  	struct fastrpc_channel_ctx *cctx;
>  	struct fastrpc_session_ctx *sess;
> @@ -2355,7 +2355,7 @@ static int fastrpc_cb_probe(struct platform_device *pdev)
>  	spin_lock_irqsave(&cctx->lock, flags);
>  	if (cctx->sesscount >= FASTRPC_MAX_SESSIONS) {
>  		spin_unlock_irqrestore(&cctx->lock, flags);
> -		dev_err(&pdev->dev, "too many sessions\n");
> +		dev_err(dev, "too many sessions\n");
>  		return -ENOSPC;
>  	}
>  	dma_bits = cctx->soc_data->dma_addr_bits_default;
> @@ -2389,37 +2389,63 @@ static int fastrpc_cb_probe(struct platform_device *pdev)
>  	return 0;
>  }
>  
> -static void fastrpc_cb_remove(struct platform_device *pdev)
> +static void fastrpc_cb_devices_destroy(struct rpmsg_device *rpdev)
>  {
> -	struct fastrpc_channel_ctx *cctx = dev_get_drvdata(pdev->dev.parent);
> -	struct fastrpc_session_ctx *sess = dev_get_drvdata(&pdev->dev);
if this dev_get_drvdata() is not used, can you also remove
dev_set_drvdata()?> +	struct fastrpc_channel_ctx *cctx =
dev_get_drvdata(&rpdev->dev);
> +	struct device *rdev = &rpdev->dev;
> +	struct platform_device *pdev;
> +	struct device_node *np;
>  	unsigned long flags;
>  	int i;
>  
>  	spin_lock_irqsave(&cctx->lock, flags);
> -	for (i = 0; i < FASTRPC_MAX_SESSIONS; i++) {
> -		if (cctx->session[i].sid == sess->sid) {
> -			cctx->session[i].valid = false;
> -			cctx->sesscount--;
> +	for (i = 0; i < cctx->sesscount; i++)
> +		cctx->session[i].valid = false;
> +	spin_unlock_irqrestore(&cctx->lock, flags);
> +
> +	for_each_available_child_of_node(rdev->of_node, np) {
> +		if (!of_device_is_compatible(np, "qcom,fastrpc-compute-cb")) {
can there be any such case?> +			of_node_put(np);
> +			continue;
>  		}
> +
> +		pdev = of_find_device_by_node(np);
> +		of_node_put(np);
> +		if (pdev)
> +			of_platform_device_destroy(&pdev->dev, NULL);
>  	}
can you check if this works here instead of above blob:
device_for_each_child_reverse(rdev, NULL, of_platform_device_destroy);>
-	spin_unlock_irqrestore(&cctx->lock, flags);
>  }
>  
> -static const struct of_device_id fastrpc_match_table[] = {
> -	{ .compatible = "qcom,fastrpc-compute-cb" },
> -	{ }
> -};
> +static int fastrpc_cb_devices_create(struct rpmsg_device *rpdev)
> +{
> +	struct device *rdev = &rpdev->dev;
> +	struct platform_device *pdev;
> +	struct device_node *np;
> +	int err;
>  
> -static struct platform_driver fastrpc_cb_driver = {
> -	.probe = fastrpc_cb_probe,
> -	.remove = fastrpc_cb_remove,
> -	.driver = {
> -		.name = "qcom,fastrpc-cb",
> -		.of_match_table = fastrpc_match_table,
> -		.suppress_bind_attrs = true,
> -	},
> -};
> +	for_each_available_child_of_node(rdev->of_node, np) {
> +		if (!of_device_is_compatible(np, "qcom,fastrpc-compute-cb")) {
> +			of_node_put(np);
> +			continue;
> +		}
> +
> +		pdev = of_platform_device_create(np, NULL, rdev);
> +		if (!pdev) {
> +			of_node_put(np);
> +			fastrpc_cb_devices_destroy(rpdev);
> +			return -EINVAL;
-ENODEV?> +		}
> +
> +		err = fastrpc_cb_init(pdev);
> +		if (err) {
> +			of_node_put(np);
> +			fastrpc_cb_devices_destroy(rpdev);
> +			return err;
> +		}
> +	}
> +
> +	return 0;
> +}
>  
>  static int fastrpc_device_register(struct device *dev, struct fastrpc_channel_ctx *cctx,
>  				   bool is_secured, const char *domain)
> @@ -2639,7 +2665,7 @@ static int fastrpc_rpmsg_probe(struct rpmsg_device *rpdev)
>  	data->rpdev = rpdev;
>  	dev_set_drvdata(&rpdev->dev, data);
>  
> -	err = of_platform_populate(rdev->of_node, NULL, NULL, rdev);
> +	err = fastrpc_cb_devices_create(rpdev);
>  	if (err)
>  		goto err_deregister_fdev;
>  
> @@ -2711,7 +2737,7 @@ static void fastrpc_rpmsg_remove(struct rpmsg_device *rpdev)
>  				&cctx->remote_heap_addr, cctx->remote_heap_size, err);
>  	}
>  
> -	of_platform_depopulate(&rpdev->dev);
> +	fastrpc_cb_devices_destroy(rpdev);
>  
>  	fastrpc_channel_ctx_put(cctx);
>  }
> @@ -2798,33 +2824,7 @@ static struct rpmsg_driver fastrpc_driver = {
>  	},
>  };
>  
> -static int fastrpc_init(void)
> -{
> -	int ret;
> -
> -	ret = platform_driver_register(&fastrpc_cb_driver);
> -	if (ret < 0) {
> -		pr_err("fastrpc: failed to register cb driver\n");
> -		return ret;
> -	}
> -
> -	ret = register_rpmsg_driver(&fastrpc_driver);
> -	if (ret < 0) {
> -		pr_err("fastrpc: failed to register rpmsg driver\n");
> -		platform_driver_unregister(&fastrpc_cb_driver);
> -		return ret;
> -	}
> -
> -	return 0;
> -}
> -module_init(fastrpc_init);
> -
> -static void fastrpc_exit(void)
> -{
> -	platform_driver_unregister(&fastrpc_cb_driver);
> -	unregister_rpmsg_driver(&fastrpc_driver);
> -}
> -module_exit(fastrpc_exit);
> +module_rpmsg_driver(fastrpc_driver);
>  
>  MODULE_DESCRIPTION("Qualcomm FastRPC");
>  MODULE_LICENSE("GPL v2");
> 


^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH v5 2/3] misc: fastrpc: move ADSP duplicate session creation to the driver
  2026-09-23  8:39 ` [PATCH v5 2/3] misc: fastrpc: move ADSP duplicate session creation to the driver Vinayak Katoch
  2026-09-23  8:50   ` sashiko-bot
@ 2026-10-09  6:11   ` Ekansh Gupta
  1 sibling, 0 replies; 10+ messages in thread
From: Ekansh Gupta @ 2026-10-09  6:11 UTC (permalink / raw)
  To: Vinayak Katoch, Srinivas Kandagatla, Amol Maheshwari,
	Arnd Bergmann, Greg Kroah-Hartman, Rob Herring,
	Krzysztof Kozlowski, Conor Dooley
  Cc: linux-arm-msm, dri-devel, linux-kernel, Bharath Kumar,
	Chenna Kesava Raju, devicetree

On 23-09-2026 14:09, Vinayak Katoch wrote:
> For ADSP, only a limited number of FastRPC context banks (CBs) are
> available. Each CB supports a single session, which means only a few
> processes can run on ADSP simultaneously. If all sessions are consumed
> by fastrpc daemons, no session remains available when a user application
> starts, causing the application to fail.
> 
> To work around this, qcom,nsessions = <5> was set in DT to duplicate
> sessions inline during fastrpc_cb_init(). This policy does not belong
> in DT and should be handled at the driver level instead.
> 
> Remove the qcom,nsessions DT property read and the per-CB duplication
> logic from fastrpc_cb_init(). After all context banks have been
> initialised in fastrpc_rpmsg_probe(), append FASTRPC_DUP_SESSIONS (4)
> copies of the last session for the ADSP domain.
> 
> Signed-off-by: Vinayak Katoch <vinayak.katoch@oss.qualcomm.com>
> ---
>  drivers/misc/fastrpc.c | 29 +++++++++++++++++------------
>  1 file changed, 17 insertions(+), 12 deletions(-)
> 
> diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c
> index f20d3e5ecc81..b29c1fd00de2 100644
> --- a/drivers/misc/fastrpc.c
> +++ b/drivers/misc/fastrpc.c
> @@ -34,6 +34,7 @@
>  #define CDSP_DOMAIN_ID (3)
>  #define GDSP_DOMAIN_ID (4)
>  #define FASTRPC_MAX_SESSIONS	14
> +#define FASTRPC_DUP_SESSIONS	4
add some comment here>  #define FASTRPC_MAX_VMIDS	16
>  #define FASTRPC_ALIGN		128
>  #define FASTRPC_MAX_FDLIST	16
> @@ -2338,7 +2339,6 @@ static int fastrpc_cb_init(struct platform_device *pdev)
>  	struct fastrpc_channel_ctx *cctx;
>  	struct fastrpc_session_ctx *sess;
>  	struct device *dev = &pdev->dev;
> -	int i, sessions = 0;
>  	unsigned long flags;
>  	u32 dma_bits;
>  	u32 sid = 0;
> @@ -2348,7 +2348,6 @@ static int fastrpc_cb_init(struct platform_device *pdev)
>  	if (!cctx)
>  		return -EINVAL;
>  
> -	of_property_read_u32(dev->of_node, "qcom,nsessions", &sessions);
>  	if (of_property_read_u32(dev->of_node, "reg", &sid))
>  		dev_info(dev, "FastRPC Session ID not specified in DT\n");
>  
> @@ -2369,16 +2368,6 @@ static int fastrpc_cb_init(struct platform_device *pdev)
>  	if (cctx->domain_id == CDSP_DOMAIN_ID)
>  		dma_bits = cctx->soc_data->dma_addr_bits_cdsp;
>  
> -	if (sessions > 0) {
> -		struct fastrpc_session_ctx *dup_sess;
> -
> -		for (i = 1; i < sessions; i++) {
> -			if (cctx->sesscount >= FASTRPC_MAX_SESSIONS)
> -				break;
> -			dup_sess = &cctx->session[cctx->sesscount++];
> -			memcpy(dup_sess, sess, sizeof(*dup_sess));
> -		}
> -	}
>  	spin_unlock_irqrestore(&cctx->lock, flags);
>  	rc = dma_set_mask(dev, DMA_BIT_MASK(dma_bits));
>  	if (rc) {
> @@ -2669,6 +2658,22 @@ static int fastrpc_rpmsg_probe(struct rpmsg_device *rpdev)
>  	if (err)
>  		goto err_deregister_fdev;
>  
> +	if (data->domain_id == ADSP_DOMAIN_ID && data->sesscount > 0) {
> +		struct fastrpc_session_ctx *last_sess;
> +		struct fastrpc_session_ctx *dup_sess;
> +		unsigned long flags;
> +
> +		spin_lock_irqsave(&data->lock, flags);
> +		last_sess = &data->session[data->sesscount - 1];
> +		for (i = 0; i < FASTRPC_DUP_SESSIONS; i++) {
> +			if (data->sesscount >= FASTRPC_MAX_SESSIONS)
> +				break;
> +			dup_sess = &data->session[data->sesscount++];
> +			memcpy(dup_sess, last_sess, sizeof(*dup_sess));
> +		}
> +		spin_unlock_irqrestore(&data->lock, flags);
> +	}
> +
>  	return 0;
>  
>  err_deregister_fdev:
> 


^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH v5 3/3] dt-bindings: misc: qcom,fastrpc: deprecate qcom,nsessions
  2026-09-23  8:39 ` [PATCH v5 3/3] dt-bindings: misc: qcom,fastrpc: deprecate qcom,nsessions Vinayak Katoch
  2026-09-23  8:50   ` sashiko-bot
@ 2026-10-09  6:12   ` Ekansh Gupta
  1 sibling, 0 replies; 10+ messages in thread
From: Ekansh Gupta @ 2026-10-09  6:12 UTC (permalink / raw)
  To: Vinayak Katoch, Srinivas Kandagatla, Amol Maheshwari,
	Arnd Bergmann, Greg Kroah-Hartman, Rob Herring,
	Krzysztof Kozlowski, Conor Dooley
  Cc: linux-arm-msm, dri-devel, linux-kernel, Bharath Kumar,
	Chenna Kesava Raju, devicetree, Krzysztof Kozlowski

On 23-09-2026 14:09, Vinayak Katoch wrote:
> The qcom,nsessions property was used to duplicate FastRPC sessions
> inline during context bank initialisation. Session duplication is now
> handled at the driver level, making this DT property redundant. Mark
> it deprecated.
> 
> Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
> Signed-off-by: Vinayak Katoch <vinayak.katoch@oss.qualcomm.com>

Reviewed-by: Ekansh Gupta <ekansh.gupta@oss.qualcomm.com>

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2026-10-09  6:12 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-23  8:39 [PATCH v5 0/3] misc: fastrpc: fix ADSP duplicate session creation Vinayak Katoch
2026-09-23  8:39 ` [PATCH v5 1/3] misc: fastrpc: iterate CB nodes manually instead of of_platform_populate Vinayak Katoch
2026-09-23  8:50   ` sashiko-bot
2026-10-09  6:02   ` Ekansh Gupta
2026-09-23  8:39 ` [PATCH v5 2/3] misc: fastrpc: move ADSP duplicate session creation to the driver Vinayak Katoch
2026-09-23  8:50   ` sashiko-bot
2026-10-09  6:11   ` Ekansh Gupta
2026-09-23  8:39 ` [PATCH v5 3/3] dt-bindings: misc: qcom,fastrpc: deprecate qcom,nsessions Vinayak Katoch
2026-09-23  8:50   ` sashiko-bot
2026-10-09  6:12   ` Ekansh Gupta

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox