* [PATCH 1/8] remoteproc: qcom_wcnss: migrate to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
2026-09-25 15:57 [PATCH 0/8] Migrate PAS clients to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset() Mukesh Ojha
@ 2026-09-25 15:57 ` Mukesh Ojha
2026-09-26 15:59 ` sashiko-bot
2026-09-25 15:57 ` [PATCH 2/8] drm/msm/adreno: migrate zap shader loading " Mukesh Ojha
` (6 subsequent siblings)
7 siblings, 1 reply; 16+ messages in thread
From: Mukesh Ojha @ 2026-09-25 15:57 UTC (permalink / raw)
To: Sumit Garg, Bjorn Andersson, Konrad Dybcio, Rob Clark,
Dmitry Baryshkov, David Airlie, Simona Vetter, Vikash Garodia,
Dikshita Agarwal, Bryan O'Donoghue, Mauro Carvalho Chehab,
Alex Elder, Andrew Lunn, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Jeff Johnson, Mathieu Poirier
Cc: Abel Vesa, Sean Paul, Akhil P Oommen, Abhinav Kumar,
Jessica Zhang, Marijn Suijten, linux-arm-msm, linux-kernel,
dri-devel, freedreno, linux-media, netdev, linux-wireless, ath12k,
linux-remoteproc, Mukesh Ojha
wcnss_load() calls qcom_mdt_load() which bundles metadata init, memory
setup, and segment loading into a single API that does not expose a PAS
context, and wcnss_start() calls qcom_pas_auth_and_reset() which skips
the shmbridge prepare step required before TrustZone authentication.
Allocate a qcom_pas_context in wcnss_probe() via
devm_qcom_pas_context_alloc() and store it in struct qcom_wcnss.
Replace qcom_mdt_load() with qcom_mdt_pas_load() in wcnss_load() and
replace qcom_pas_auth_and_reset() with qcom_pas_prepare_and_auth_reset()
in wcnss_start(). The existing devm_ioremap_wc() mapping is retained
for wcnss_da_to_va() address translation.
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
---
drivers/remoteproc/qcom_wcnss.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/remoteproc/qcom_wcnss.c b/drivers/remoteproc/qcom_wcnss.c
index c856a92af43c..01f9076aa0b1 100644
--- a/drivers/remoteproc/qcom_wcnss.c
+++ b/drivers/remoteproc/qcom_wcnss.c
@@ -96,6 +96,7 @@ struct qcom_wcnss {
phys_addr_t mem_reloc;
void __iomem *mem_region;
size_t mem_size;
+ struct qcom_pas_context *pas_ctx;
struct qcom_rproc_subdev smd_subdev;
struct qcom_sysmon *sysmon;
@@ -157,9 +158,7 @@ static int wcnss_load(struct rproc *rproc, const struct firmware *fw)
struct qcom_wcnss *wcnss = rproc->priv;
int ret;
- ret = qcom_mdt_load(wcnss->dev, fw, rproc->firmware, WCNSS_PAS_ID,
- (__force void *)wcnss->mem_region, wcnss->mem_phys,
- wcnss->mem_size, &wcnss->mem_reloc);
+ ret = qcom_mdt_pas_load(wcnss->pas_ctx, fw, rproc->firmware, &wcnss->mem_reloc);
if (ret)
return ret;
@@ -257,7 +256,7 @@ static int wcnss_start(struct rproc *rproc)
wcnss_indicate_nv_download(wcnss);
wcnss_configure_iris(wcnss);
- ret = qcom_pas_auth_and_reset(WCNSS_PAS_ID);
+ ret = qcom_pas_prepare_and_auth_reset(wcnss->pas_ctx);
if (ret) {
dev_err(wcnss->dev,
"failed to authenticate image and release reset\n");
@@ -600,6 +599,11 @@ static int wcnss_probe(struct platform_device *pdev)
if (ret)
return ret;
+ wcnss->pas_ctx = devm_qcom_pas_context_alloc(wcnss->dev, WCNSS_PAS_ID,
+ wcnss->mem_phys, wcnss->mem_size);
+ if (IS_ERR(wcnss->pas_ctx))
+ return PTR_ERR(wcnss->pas_ctx);
+
wcnss->pmu_cfg = mmio + data->pmu_offset;
wcnss->spare_out = mmio + data->spare_offset;
--
2.55.0
^ permalink raw reply related [flat|nested] 16+ messages in thread* Re: [PATCH 1/8] remoteproc: qcom_wcnss: migrate to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
2026-09-25 15:57 ` [PATCH 1/8] remoteproc: qcom_wcnss: migrate " Mukesh Ojha
@ 2026-09-26 15:59 ` sashiko-bot
0 siblings, 0 replies; 16+ messages in thread
From: sashiko-bot @ 2026-09-26 15:59 UTC (permalink / raw)
To: Mukesh Ojha; +Cc: dri-devel, media-ci
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] remoteproc: qcom_wcnss: DMA memory leak of metadata in wcnss_load()
- [High] remoteproc: qcom_wcnss: missing pas_ctx->use_tzmem = true prevents required shmbridge creation
--
commit 77b1a378f038e55ff2a11032d9b6f243214fbb7f
Author: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Date: Fri Sep 25 15:57:30 2026 +0000
remoteproc: qcom_wcnss: migrate to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
This commit migrates the Qualcomm WCNSS remoteproc driver to use
qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset(). It allocates a
PAS context during probe to support TrustZone authentication with shmbridge
preparation.
> diff --git a/drivers/remoteproc/qcom_wcnss.c b/drivers/remoteproc/qcom_wcnss.c
> index c856a92af43ce..01f9076aa0b17 100644
> --- a/drivers/remoteproc/qcom_wcnss.c
> +++ b/drivers/remoteproc/qcom_wcnss.c
[ ... ]
> @@ -157,9 +158,7 @@ static int wcnss_load(struct rproc *rproc, const struct firmware *fw)
> struct qcom_wcnss *wcnss = rproc->priv;
> int ret;
>
> - ret = qcom_mdt_load(wcnss->dev, fw, rproc->firmware, WCNSS_PAS_ID,
> - (__force void *)wcnss->mem_region, wcnss->mem_phys,
> - wcnss->mem_size, &wcnss->mem_reloc);
> + ret = qcom_mdt_pas_load(wcnss->pas_ctx, fw, rproc->firmware, &wcnss->mem_reloc);
[Severity: High]
Does this introduce a DMA memory leak of the metadata buffer?
By passing wcnss->pas_ctx to qcom_mdt_pas_load(), the allocated metadata
buffer is retained in wcnss->pas_ctx->ptr. In the previous qcom_mdt_load()
implementation, passing a NULL context signaled the backend to free the
buffer immediately.
Since the remoteproc operations structure (wcnss_ops) lacks an .unprepare
hook, there doesn't seem to be a corresponding call to
qcom_pas_metadata_release(wcnss->pas_ctx) when the device is shut down.
Will this persistently leak DMA memory each time the remoteproc is started
and stopped via sysfs?
> if (ret)
> return ret;
[ ... ]
> @@ -600,6 +599,11 @@ static int wcnss_probe(struct platform_device *pdev)
> if (ret)
> return ret;
>
> + wcnss->pas_ctx = devm_qcom_pas_context_alloc(wcnss->dev, WCNSS_PAS_ID,
> + wcnss->mem_phys, wcnss->mem_size);
[Severity: High]
The commit message explicitly states the goal is to include the shmbridge
prepare step required before TrustZone authentication. However, does this
actually enable the shmbridge?
The newly allocated wcnss->pas_ctx is zero-initialized by
devm_qcom_pas_context_alloc(), so pas_ctx->use_tzmem defaults to false. When
use_tzmem is false, qcom_scm_pas_prepare_and_auth_reset() explicitly skips
creating the shmbridge and falls back to the legacy behavior.
Should wcnss->pas_ctx->use_tzmem be set to true here to fulfill the stated
security objective?
> + if (IS_ERR(wcnss->pas_ctx))
> + return PTR_ERR(wcnss->pas_ctx);
> +
> wcnss->pmu_cfg = mmio + data->pmu_offset;
> wcnss->spare_out = mmio + data->spare_offset;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260925155737.4161358-1-mukesh.ojha@oss.qualcomm.com?part=1
^ permalink raw reply [flat|nested] 16+ messages in thread
* [PATCH 2/8] drm/msm/adreno: migrate zap shader loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
2026-09-25 15:57 [PATCH 0/8] Migrate PAS clients to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset() Mukesh Ojha
2026-09-25 15:57 ` [PATCH 1/8] remoteproc: qcom_wcnss: migrate " Mukesh Ojha
@ 2026-09-25 15:57 ` Mukesh Ojha
2026-09-26 15:59 ` sashiko-bot
2026-09-25 15:57 ` [PATCH 3/8] media: iris: migrate firmware " Mukesh Ojha
` (5 subsequent siblings)
7 siblings, 1 reply; 16+ messages in thread
From: Mukesh Ojha @ 2026-09-25 15:57 UTC (permalink / raw)
To: Sumit Garg, Bjorn Andersson, Konrad Dybcio, Rob Clark,
Dmitry Baryshkov, David Airlie, Simona Vetter, Vikash Garodia,
Dikshita Agarwal, Bryan O'Donoghue, Mauro Carvalho Chehab,
Alex Elder, Andrew Lunn, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Jeff Johnson, Mathieu Poirier
Cc: Abel Vesa, Sean Paul, Akhil P Oommen, Abhinav Kumar,
Jessica Zhang, Marijn Suijten, linux-arm-msm, linux-kernel,
dri-devel, freedreno, linux-media, netdev, linux-wireless, ath12k,
linux-remoteproc, Mukesh Ojha
zap_shader_load_mdt() uses qcom_mdt_load() which bundles metadata init,
memory setup, and segment loading but exposes no PAS context, and then
calls qcom_pas_auth_and_reset() which skips the shmbridge prepare step
required before TrustZone authentication.
Replace the open-coded memremap()/qcom_mdt_load()/memunmap() sequence
with devm_qcom_pas_context_alloc() and qcom_mdt_pas_load(), then pass
the same context to qcom_pas_prepare_and_auth_reset(). The -EOPNOTSUPP
handling for targets without zap shader support is preserved.
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
---
drivers/gpu/drm/msm/adreno/adreno_gpu.c | 21 ++++++++-------------
1 file changed, 8 insertions(+), 13 deletions(-)
diff --git a/drivers/gpu/drm/msm/adreno/adreno_gpu.c b/drivers/gpu/drm/msm/adreno/adreno_gpu.c
index 5832dc25d6bf..d3e843220b73 100644
--- a/drivers/gpu/drm/msm/adreno/adreno_gpu.c
+++ b/drivers/gpu/drm/msm/adreno/adreno_gpu.c
@@ -34,11 +34,11 @@ static int zap_shader_load_mdt(struct msm_gpu *gpu, const char *fwname,
struct device *dev = &gpu->pdev->dev;
const struct firmware *fw;
const char *signed_fwname = NULL;
+ struct qcom_pas_context *ctx;
struct device_node *np;
struct resource r;
phys_addr_t mem_phys;
ssize_t mem_size;
- void *mem_region = NULL;
int ret;
if (!IS_ENABLED(CONFIG_ARCH_QCOM)) {
@@ -122,9 +122,9 @@ static int zap_shader_load_mdt(struct msm_gpu *gpu, const char *fwname,
}
/* Allocate memory for the firmware image */
- mem_region = memremap(mem_phys, mem_size, MEMREMAP_WC);
- if (!mem_region) {
- ret = -ENOMEM;
+ ctx = devm_qcom_pas_context_alloc(dev, pasid, mem_phys, resource_size(&r));
+ if (IS_ERR(ctx)) {
+ ret = PTR_ERR(ctx);
goto out;
}
@@ -133,27 +133,25 @@ static int zap_shader_load_mdt(struct msm_gpu *gpu, const char *fwname,
*
* Note that we could be dealing with two different paths, since
* with upstream linux-firmware it would be in a qcom/ subdir..
- * adreno_request_fw() handles this, but qcom_mdt_load() does
+ * adreno_request_fw() handles this, but qcom_mdt_pas_load() does
* not. But since we've already gotten through adreno_request_fw()
* we know which of the two cases it is:
*/
if (signed_fwname || (to_adreno_gpu(gpu)->fwloc == FW_LOCATION_LEGACY)) {
- ret = qcom_mdt_load(dev, fw, fwname, pasid,
- mem_region, mem_phys, mem_size, NULL);
+ ret = qcom_mdt_pas_load(ctx, fw, fwname, NULL);
} else {
char *newname;
newname = kasprintf(GFP_KERNEL, "qcom/%s", fwname);
- ret = qcom_mdt_load(dev, fw, newname, pasid,
- mem_region, mem_phys, mem_size, NULL);
+ ret = qcom_mdt_pas_load(ctx, fw, newname, NULL);
kfree(newname);
}
if (ret)
goto out;
/* Send the image to the secure world */
- ret = qcom_pas_auth_and_reset(pasid);
+ ret = qcom_pas_prepare_and_auth_reset(ctx);
/*
* If the pas call returns -EOPNOTSUPP we assume that this target
@@ -165,9 +163,6 @@ static int zap_shader_load_mdt(struct msm_gpu *gpu, const char *fwname,
DRM_DEV_ERROR(dev, "Unable to authorize the image\n");
out:
- if (mem_region)
- memunmap(mem_region);
-
release_firmware(fw);
return ret;
--
2.55.0
^ permalink raw reply related [flat|nested] 16+ messages in thread* Re: [PATCH 2/8] drm/msm/adreno: migrate zap shader loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
2026-09-25 15:57 ` [PATCH 2/8] drm/msm/adreno: migrate zap shader loading " Mukesh Ojha
@ 2026-09-26 15:59 ` sashiko-bot
0 siblings, 0 replies; 16+ messages in thread
From: sashiko-bot @ 2026-09-26 15:59 UTC (permalink / raw)
To: Mukesh Ojha; +Cc: dri-devel, media-ci
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] drm/msm/adreno: memory leak of PAS metadata buffer
- [High] drm/msm/adreno: shmbridge preparation step silently skipped
- [Medium] drm/msm/adreno: struct qcom_pas_context leaked via devres on post-probe retries
--
commit 4d137953382eb8839541fc9229948a9472d95133
Author: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
drm/msm/adreno: migrate zap shader loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
This commit replaces the open-coded memremap/mdt_load sequence for zap shader
loading with devm_qcom_pas_context_alloc and qcom_mdt_pas_load. It then passes
the context to qcom_pas_prepare_and_auth_reset to ensure the shmbridge
preparation step is executed before TrustZone authentication.
> diff --git a/drivers/gpu/drm/msm/adreno/adreno_gpu.c b/drivers/gpu/drm/msm/adreno/adreno_gpu.c
> --- a/drivers/gpu/drm/msm/adreno/adreno_gpu.c
> +++ b/drivers/gpu/drm/msm/adreno/adreno_gpu.c
[ ... ]
> @@ -122,9 +122,9 @@ static int zap_shader_load_mdt(struct msm_gpu *gpu, const char *fwname,
> }
>
> /* Allocate memory for the firmware image */
> - mem_region = memremap(mem_phys, mem_size, MEMREMAP_WC);
> - if (!mem_region) {
> - ret = -ENOMEM;
> + ctx = devm_qcom_pas_context_alloc(dev, pasid, mem_phys, resource_size(&r));
> + if (IS_ERR(ctx)) {
> + ret = PTR_ERR(ctx);
[Severity: High]
Is the shmbridge preparation step actually skipped here?
The commit message mentions fixing the omission of the shmbridge prepare step.
However, devm_qcom_pas_context_alloc() uses devm_kzalloc() which zeroes the
context, and ctx->use_tzmem is never explicitly set to true in
zap_shader_load_mdt().
Because of this, it looks like qcom_pas_prepare_and_auth_reset() will hit
the early return (if (!ctx->use_tzmem)) downstream and bypass the shmbridge
creation entirely, leaving the behaviour unchanged.
[Severity: Medium]
Can this devm allocation cause an accumulating memory leak during post-probe
retries?
Since devm_qcom_pas_context_alloc() ties the allocation to the device
lifetime, if zap_shader_load_mdt() fails and is called multiple times during
runtime PM resume or GPU recovery sequences, the context allocations might
accumulate without being freed since the device remains bound.
> goto out;
> }
>
[ ... ]
> @@ -165,9 +163,6 @@ static int zap_shader_load_mdt(struct msm_gpu *gpu, const char *fwname,
> DRM_DEV_ERROR(dev, "Unable to authorize the image\n");
>
> out:
> - if (mem_region)
> - memunmap(mem_region);
> -
> release_firmware(fw);
>
> return ret;
[Severity: High]
Does this exit path leak the PAS metadata buffer?
When qcom_mdt_pas_load() executes, it internally calls qcom_pas_init_image(),
which allocates a metadata buffer and stores it in ctx->ptr. Unlike the
previous flow with a NULL context where the buffer was immediately freed
internally, a valid context tracks it so the caller can free it.
Should there be a call to qcom_pas_metadata_release(ctx) in this exit path
to prevent leaking this physical memory on every execution?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260925155737.4161358-1-mukesh.ojha@oss.qualcomm.com?part=2
^ permalink raw reply [flat|nested] 16+ messages in thread
* [PATCH 3/8] media: iris: migrate firmware loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
2026-09-25 15:57 [PATCH 0/8] Migrate PAS clients to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset() Mukesh Ojha
2026-09-25 15:57 ` [PATCH 1/8] remoteproc: qcom_wcnss: migrate " Mukesh Ojha
2026-09-25 15:57 ` [PATCH 2/8] drm/msm/adreno: migrate zap shader loading " Mukesh Ojha
@ 2026-09-25 15:57 ` Mukesh Ojha
2026-09-26 15:59 ` sashiko-bot
2026-09-25 15:57 ` [PATCH 4/8] media: venus: " Mukesh Ojha
` (4 subsequent siblings)
7 siblings, 1 reply; 16+ messages in thread
From: Mukesh Ojha @ 2026-09-25 15:57 UTC (permalink / raw)
To: Sumit Garg, Bjorn Andersson, Konrad Dybcio, Rob Clark,
Dmitry Baryshkov, David Airlie, Simona Vetter, Vikash Garodia,
Dikshita Agarwal, Bryan O'Donoghue, Mauro Carvalho Chehab,
Alex Elder, Andrew Lunn, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Jeff Johnson, Mathieu Poirier
Cc: Abel Vesa, Sean Paul, Akhil P Oommen, Abhinav Kumar,
Jessica Zhang, Marijn Suijten, linux-arm-msm, linux-kernel,
dri-devel, freedreno, linux-media, netdev, linux-wireless, ath12k,
linux-remoteproc, Mukesh Ojha
iris_load_fw_to_memory() calls qcom_mdt_load() which bundles metadata
init, memory setup, and segment loading with no PAS context, and
iris_fw_load() calls qcom_pas_auth_and_reset() which skips the shmbridge
prepare step required before TrustZone authentication.
Since the auth call is in a different function from where the PAS context
is allocated, add a pas_ctx pointer to struct iris_core so it can be
threaded between the two call sites. Replace qcom_mdt_load() with
devm_qcom_pas_context_alloc() and qcom_mdt_pas_load() in
iris_load_fw_to_memory(), storing the context in core->pas_ctx, then
pass it to qcom_pas_prepare_and_auth_reset() in iris_fw_load().
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
---
drivers/media/platform/qcom/iris/iris_core.h | 2 ++
.../media/platform/qcom/iris/iris_firmware.c | 20 ++++++++-----------
2 files changed, 10 insertions(+), 12 deletions(-)
diff --git a/drivers/media/platform/qcom/iris/iris_core.h b/drivers/media/platform/qcom/iris/iris_core.h
index 24da60448cf2..68e6adcc1dfd 100644
--- a/drivers/media/platform/qcom/iris/iris_core.h
+++ b/drivers/media/platform/qcom/iris/iris_core.h
@@ -8,6 +8,7 @@
#include <linux/types.h>
#include <linux/pm_domain.h>
+#include <linux/firmware/qcom/qcom_pas.h>
#include <media/v4l2-device.h>
#include "iris_hfi_common.h"
@@ -123,6 +124,7 @@ struct iris_core {
/* encoder and decoder have overlapping caps, so two different arrays are required */
struct platform_inst_fw_cap inst_fw_caps_dec[INST_FW_CAP_MAX];
struct platform_inst_fw_cap inst_fw_caps_enc[INST_FW_CAP_MAX];
+ struct qcom_pas_context *pas_ctx;
};
int iris_core_init(struct iris_core *core);
diff --git a/drivers/media/platform/qcom/iris/iris_firmware.c b/drivers/media/platform/qcom/iris/iris_firmware.c
index 21cdf1c39835..e73a5dd98b88 100644
--- a/drivers/media/platform/qcom/iris/iris_firmware.c
+++ b/drivers/media/platform/qcom/iris/iris_firmware.c
@@ -115,9 +115,7 @@ static int iris_load_fw_to_memory(struct iris_core *core)
struct resource res;
phys_addr_t mem_phys;
const char *fw_name;
- size_t res_size;
ssize_t fw_size;
- void *mem_virt;
int ret;
ret = of_reserved_mem_region_to_resource(dev->of_node, 0, &res);
@@ -125,7 +123,6 @@ static int iris_load_fw_to_memory(struct iris_core *core)
return ret;
mem_phys = res.start;
- res_size = resource_size(&res);
firmware = iris_detect_firmware(core, &fw_name);
if (IS_ERR(firmware))
@@ -134,21 +131,20 @@ static int iris_load_fw_to_memory(struct iris_core *core)
core->iris_firmware_data = core->iris_firmware_desc->firmware_data;
fw_size = qcom_mdt_get_size(firmware);
- if (fw_size < 0 || res_size < (size_t)fw_size) {
+ if (fw_size < 0 || resource_size(&res) < (size_t)fw_size) {
ret = -EINVAL;
goto err_release_fw;
}
- mem_virt = memremap(mem_phys, res_size, MEMREMAP_WC);
- if (!mem_virt) {
- ret = -ENOMEM;
+ core->pas_ctx = devm_qcom_pas_context_alloc(dev, IRIS_PAS_ID, mem_phys,
+ resource_size(&res));
+ if (IS_ERR(core->pas_ctx)) {
+ ret = PTR_ERR(core->pas_ctx);
+ core->pas_ctx = NULL;
goto err_release_fw;
}
- ret = qcom_mdt_load(dev, firmware, fw_name,
- IRIS_PAS_ID, mem_virt, mem_phys, res_size, NULL);
-
- memunmap(mem_virt);
+ ret = qcom_mdt_pas_load(core->pas_ctx, firmware, fw_name, NULL);
err_release_fw:
release_firmware(firmware);
@@ -166,7 +162,7 @@ int iris_fw_load(struct iris_core *core)
return ret;
}
- ret = qcom_pas_auth_and_reset(IRIS_PAS_ID);
+ ret = qcom_pas_prepare_and_auth_reset(core->pas_ctx);
if (ret) {
dev_err(core->dev, "auth and reset failed: %d\n", ret);
return ret;
--
2.55.0
^ permalink raw reply related [flat|nested] 16+ messages in thread* Re: [PATCH 3/8] media: iris: migrate firmware loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
2026-09-25 15:57 ` [PATCH 3/8] media: iris: migrate firmware " Mukesh Ojha
@ 2026-09-26 15:59 ` sashiko-bot
0 siblings, 0 replies; 16+ messages in thread
From: sashiko-bot @ 2026-09-26 15:59 UTC (permalink / raw)
To: Mukesh Ojha; +Cc: dri-devel, media-ci
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] firmware: qcom: pas: missing qcom_pas_metadata_release() leaks TZ/DMA memory
- [Medium] devres: memory leak due to repeated devm_qcom_pas_context_alloc() on fw reload
--
commit bb3acb8beaa539b1cfa0975914c1f8fd75747e36
Author: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
media: iris: migrate firmware loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
iris_load_fw_to_memory() calls qcom_mdt_load() which bundles metadata
init, memory setup, and segment loading with no PAS context, and
iris_fw_load() calls qcom_pas_auth_and_reset() which skips the shmbridge
prepare step required before TrustZone authentication.
> diff --git a/drivers/media/platform/qcom/iris/iris_firmware.c b/drivers/media/platform/qcom/iris/iris_firmware.c
> index 21cdf1c398357..e73a5dd98b88c 100644
> --- a/drivers/media/platform/qcom/iris/iris_firmware.c
> +++ b/drivers/media/platform/qcom/iris/iris_firmware.c
[ ... ]
> @@ -134,21 +131,20 @@ static int iris_load_fw_to_memory(struct iris_core *core)
> core->iris_firmware_data = core->iris_firmware_desc->firmware_data;
>
> fw_size = qcom_mdt_get_size(firmware);
> - if (fw_size < 0 || res_size < (size_t)fw_size) {
> + if (fw_size < 0 || resource_size(&res) < (size_t)fw_size) {
> ret = -EINVAL;
> goto err_release_fw;
> }
>
> - mem_virt = memremap(mem_phys, res_size, MEMREMAP_WC);
> - if (!mem_virt) {
> - ret = -ENOMEM;
> + core->pas_ctx = devm_qcom_pas_context_alloc(dev, IRIS_PAS_ID, mem_phys,
> + resource_size(&res));
[Severity: Medium]
Will this leak device-managed memory when firmware is reloaded?
If the hardware system error recovery path is triggered (for example,
iris_sys_error_handler() calls iris_core_deinit() followed by
iris_core_init() and iris_fw_load()), devm_qcom_pas_context_alloc() is called
again unconditionally. This overwrites core->pas_ctx without freeing the old
devres allocation.
> + if (IS_ERR(core->pas_ctx)) {
> + ret = PTR_ERR(core->pas_ctx);
> + core->pas_ctx = NULL;
> goto err_release_fw;
> }
>
> - ret = qcom_mdt_load(dev, firmware, fw_name,
> - IRIS_PAS_ID, mem_virt, mem_phys, res_size, NULL);
> -
> - memunmap(mem_virt);
> + ret = qcom_mdt_pas_load(core->pas_ctx, firmware, fw_name, NULL);
[Severity: High]
Does this sequence leak DMA or TrustZone memory buffers allocated for firmware
metadata?
When qcom_mdt_pas_load() is called, the underlying PAS subsystem allocates a
DMA buffer for the metadata and stores it in the PAS context. The PAS API
contract dictates that callers must subsequently call
qcom_pas_metadata_release(core->pas_ctx) to free this memory.
Looking at iris_fw_load(), this step appears to be completely omitted on both
success and error paths before the function returns. Because the DMA
allocation is tied to the SCM device (not devres-managed for the iris
driver), repeated firmware loads due to probe/unbind cycles or hardware
errors could permanently exhaust restricted DMA or secure memory pools.
> err_release_fw:
> release_firmware(firmware);
>
> @@ -166,7 +162,7 @@ int iris_fw_load(struct iris_core *core)
> return ret;
> }
>
> - ret = qcom_pas_auth_and_reset(IRIS_PAS_ID);
> + ret = qcom_pas_prepare_and_auth_reset(core->pas_ctx);
> if (ret) {
> dev_err(core->dev, "auth and reset failed: %d\n", ret);
> return ret;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260925155737.4161358-1-mukesh.ojha@oss.qualcomm.com?part=3
^ permalink raw reply [flat|nested] 16+ messages in thread
* [PATCH 4/8] media: venus: migrate firmware loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
2026-09-25 15:57 [PATCH 0/8] Migrate PAS clients to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset() Mukesh Ojha
` (2 preceding siblings ...)
2026-09-25 15:57 ` [PATCH 3/8] media: iris: migrate firmware " Mukesh Ojha
@ 2026-09-25 15:57 ` Mukesh Ojha
2026-09-26 15:59 ` sashiko-bot
2026-09-25 15:57 ` [PATCH 5/8] net: ipa: " Mukesh Ojha
` (3 subsequent siblings)
7 siblings, 1 reply; 16+ messages in thread
From: Mukesh Ojha @ 2026-09-25 15:57 UTC (permalink / raw)
To: Sumit Garg, Bjorn Andersson, Konrad Dybcio, Rob Clark,
Dmitry Baryshkov, David Airlie, Simona Vetter, Vikash Garodia,
Dikshita Agarwal, Bryan O'Donoghue, Mauro Carvalho Chehab,
Alex Elder, Andrew Lunn, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Jeff Johnson, Mathieu Poirier
Cc: Abel Vesa, Sean Paul, Akhil P Oommen, Abhinav Kumar,
Jessica Zhang, Marijn Suijten, linux-arm-msm, linux-kernel,
dri-devel, freedreno, linux-media, netdev, linux-wireless, ath12k,
linux-remoteproc, Mukesh Ojha
venus_load_fw() uses qcom_mdt_load() for the TZ path and a bare
memremap()/qcom_mdt_load_no_init()/memunmap() sequence for the non-TZ
path. venus_boot() then calls qcom_pas_auth_and_reset() which skips the
shmbridge prepare step required before TrustZone authentication.
For the TZ path, add a pas_ctx pointer to struct video_firmware so the
context can be threaded from venus_load_fw() where it is allocated to
venus_boot() where authentication happens. Replace qcom_mdt_load() with
devm_qcom_pas_context_alloc() and qcom_mdt_pas_load(), storing the
context in core->fw.pas_ctx, then pass it to
qcom_pas_prepare_and_auth_reset() in venus_boot().
For the non-TZ path, pass NULL to qcom_mdt_load_no_init() directly,
removing the explicit memremap()/memunmap() since qcom_mdt_load_no_init()
handles the mapping internally when mem_region is NULL.
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
---
drivers/media/platform/qcom/venus/core.h | 2 ++
drivers/media/platform/qcom/venus/firmware.c | 29 +++++++++-----------
2 files changed, 15 insertions(+), 16 deletions(-)
diff --git a/drivers/media/platform/qcom/venus/core.h b/drivers/media/platform/qcom/venus/core.h
index 46705a666776..adcf67043bf6 100644
--- a/drivers/media/platform/qcom/venus/core.h
+++ b/drivers/media/platform/qcom/venus/core.h
@@ -9,6 +9,7 @@
#include <linux/bitops.h>
#include <linux/list.h>
+#include <linux/firmware/qcom/qcom_pas.h>
#include <media/videobuf2-v4l2.h>
#include <media/v4l2-ctrls.h>
#include <media/v4l2-device.h>
@@ -223,6 +224,7 @@ struct venus_core {
size_t mapped_mem_size;
phys_addr_t mem_phys;
size_t mem_size;
+ struct qcom_pas_context *pas_ctx;
} fw;
struct mutex lock;
struct list_head instances;
diff --git a/drivers/media/platform/qcom/venus/firmware.c b/drivers/media/platform/qcom/venus/firmware.c
index 3a38ff985822..4ea4c7769ac3 100644
--- a/drivers/media/platform/qcom/venus/firmware.c
+++ b/drivers/media/platform/qcom/venus/firmware.c
@@ -86,7 +86,6 @@ static int venus_load_fw(struct venus_core *core, const char *fwname,
struct resource res;
struct device *dev;
ssize_t fw_size;
- void *mem_va;
int ret;
*mem_phys = 0;
@@ -117,21 +116,19 @@ static int venus_load_fw(struct venus_core *core, const char *fwname,
goto err_release_fw;
}
- mem_va = memremap(*mem_phys, *mem_size, MEMREMAP_WC);
- if (!mem_va) {
- dev_err(dev, "unable to map memory region %pa size %#zx\n", mem_phys, *mem_size);
- ret = -ENOMEM;
- goto err_release_fw;
- }
-
- if (core->use_tz)
- ret = qcom_mdt_load(dev, mdt, fwname, VENUS_PAS_ID,
- mem_va, *mem_phys, *mem_size, NULL);
- else
- ret = qcom_mdt_load_no_init(dev, mdt, fwname, mem_va,
+ if (core->use_tz) {
+ core->fw.pas_ctx = devm_qcom_pas_context_alloc(dev, VENUS_PAS_ID,
+ *mem_phys, *mem_size);
+ if (IS_ERR(core->fw.pas_ctx)) {
+ ret = PTR_ERR(core->fw.pas_ctx);
+ core->fw.pas_ctx = NULL;
+ goto err_release_fw;
+ }
+ ret = qcom_mdt_pas_load(core->fw.pas_ctx, mdt, fwname, NULL);
+ } else {
+ ret = qcom_mdt_load_no_init(dev, mdt, fwname, NULL,
*mem_phys, *mem_size, NULL);
-
- memunmap(mem_va);
+ }
err_release_fw:
release_firmware(mdt);
return ret;
@@ -237,7 +234,7 @@ int venus_boot(struct venus_core *core)
core->fw.mem_phys = mem_phys;
if (core->use_tz)
- ret = qcom_pas_auth_and_reset(VENUS_PAS_ID);
+ ret = qcom_pas_prepare_and_auth_reset(core->fw.pas_ctx);
else
ret = venus_boot_no_tz(core, mem_phys, mem_size);
--
2.55.0
^ permalink raw reply related [flat|nested] 16+ messages in thread* Re: [PATCH 4/8] media: venus: migrate firmware loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
2026-09-25 15:57 ` [PATCH 4/8] media: venus: " Mukesh Ojha
@ 2026-09-26 15:59 ` sashiko-bot
0 siblings, 0 replies; 16+ messages in thread
From: sashiko-bot @ 2026-09-26 15:59 UTC (permalink / raw)
To: Mukesh Ojha; +Cc: media-ci, dri-devel
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] media: venus: devm_ allocation in venus_load_fw() causes leak on error recovery
--
commit 8d4223f26ac66cddad9e1923272c5c9297949631
Author: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
media: venus: migrate firmware loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
This commit migrates the firmware loading for the TrustZone path to use the
new PAS context allocation and loading functions. It threads the PAS context
from venus_load_fw() through to venus_boot() where authentication occurs.
> diff --git a/drivers/media/platform/qcom/venus/firmware.c b/drivers/media/platform/qcom/venus/firmware.c
> index 3a38ff985822f..4ea4c7769ac3d 100644
> --- a/drivers/media/platform/qcom/venus/firmware.c
> +++ b/drivers/media/platform/qcom/venus/firmware.c
[ ... ]
> @@ -117,21 +116,19 @@ static int venus_load_fw(struct venus_core *core, const char *fwname,
> goto err_release_fw;
> }
>
> - mem_va = memremap(*mem_phys, *mem_size, MEMREMAP_WC);
> - if (!mem_va) {
> - dev_err(dev, "unable to map memory region %pa size %#zx\n", mem_phys, *mem_size);
> - ret = -ENOMEM;
> - goto err_release_fw;
> - }
> -
> - if (core->use_tz)
> - ret = qcom_mdt_load(dev, mdt, fwname, VENUS_PAS_ID,
> - mem_va, *mem_phys, *mem_size, NULL);
> - else
> - ret = qcom_mdt_load_no_init(dev, mdt, fwname, mem_va,
> + if (core->use_tz) {
> + core->fw.pas_ctx = devm_qcom_pas_context_alloc(dev, VENUS_PAS_ID,
> + *mem_phys, *mem_size);
[Severity: High]
Does this devm allocation leak memory during firmware error recovery?
Looking at the firmware recovery path, when a firmware crash occurs,
venus_sys_error_handler() repeatedly invokes venus_boot(), which then calls
venus_load_fw().
Because devm_qcom_pas_context_alloc() attaches the allocation to the device's
lifecycle, it is only freed when the device is unbound. Each recovery cycle
will allocate a new PAS context and overwrite core->fw.pas_ctx without freeing
the previous one. This could lead to unbounded memory consumption and an OOM
crash if an attacker or stream continuously triggers firmware crashes.
> + if (IS_ERR(core->fw.pas_ctx)) {
> + ret = PTR_ERR(core->fw.pas_ctx);
> + core->fw.pas_ctx = NULL;
> + goto err_release_fw;
> + }
> + ret = qcom_mdt_pas_load(core->fw.pas_ctx, mdt, fwname, NULL);
> + } else {
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260925155737.4161358-1-mukesh.ojha@oss.qualcomm.com?part=4
^ permalink raw reply [flat|nested] 16+ messages in thread
* [PATCH 5/8] net: ipa: migrate firmware loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
2026-09-25 15:57 [PATCH 0/8] Migrate PAS clients to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset() Mukesh Ojha
` (3 preceding siblings ...)
2026-09-25 15:57 ` [PATCH 4/8] media: venus: " Mukesh Ojha
@ 2026-09-25 15:57 ` Mukesh Ojha
2026-09-26 15:59 ` sashiko-bot
2026-09-25 15:57 ` [PATCH 6/8] wifi: ath12k: " Mukesh Ojha
` (2 subsequent siblings)
7 siblings, 1 reply; 16+ messages in thread
From: Mukesh Ojha @ 2026-09-25 15:57 UTC (permalink / raw)
To: Sumit Garg, Bjorn Andersson, Konrad Dybcio, Rob Clark,
Dmitry Baryshkov, David Airlie, Simona Vetter, Vikash Garodia,
Dikshita Agarwal, Bryan O'Donoghue, Mauro Carvalho Chehab,
Alex Elder, Andrew Lunn, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Jeff Johnson, Mathieu Poirier
Cc: Abel Vesa, Sean Paul, Akhil P Oommen, Abhinav Kumar,
Jessica Zhang, Marijn Suijten, linux-arm-msm, linux-kernel,
dri-devel, freedreno, linux-media, netdev, linux-wireless, ath12k,
linux-remoteproc, Mukesh Ojha
ipa_firmware_load() calls qcom_mdt_load() which bundles metadata init,
memory setup, and segment loading with no PAS context, then calls
qcom_pas_auth_and_reset() which skips the shmbridge prepare step required
before TrustZone authentication.
Replace the open-coded memremap()/qcom_mdt_load()/memunmap() sequence
with devm_qcom_pas_context_alloc() and qcom_mdt_pas_load(), then pass
the same context to qcom_pas_prepare_and_auth_reset().
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
---
drivers/net/ipa/ipa_main.c | 24 +++++++++++-------------
1 file changed, 11 insertions(+), 13 deletions(-)
diff --git a/drivers/net/ipa/ipa_main.c b/drivers/net/ipa/ipa_main.c
index 14ac2d2faf7c..6964395caedd 100644
--- a/drivers/net/ipa/ipa_main.c
+++ b/drivers/net/ipa/ipa_main.c
@@ -585,12 +585,11 @@ static void ipa_deconfig(struct ipa *ipa)
static int ipa_firmware_load(struct device *dev)
{
+ struct qcom_pas_context *ctx;
const struct firmware *fw;
struct resource res;
phys_addr_t phys;
const char *path;
- ssize_t size;
- void *virt;
int ret;
ret = of_reserved_mem_region_to_resource(dev->of_node, 0, &res);
@@ -615,24 +614,23 @@ static int ipa_firmware_load(struct device *dev)
}
phys = res.start;
- size = (size_t)resource_size(&res);
- virt = memremap(phys, size, MEMREMAP_WC);
- if (!virt) {
- dev_err(dev, "unable to remap firmware memory\n");
- ret = -ENOMEM;
+ ctx = devm_qcom_pas_context_alloc(dev, IPA_PAS_ID, phys,
+ resource_size(&res));
+ if (IS_ERR(ctx)) {
+ ret = PTR_ERR(ctx);
goto out_release_firmware;
}
- ret = qcom_mdt_load(dev, fw, path, IPA_PAS_ID, virt, phys, size, NULL);
+ ret = qcom_mdt_pas_load(ctx, fw, path, NULL);
if (ret) {
dev_err(dev, "error %d loading \"%s\"\n", ret, path);
- } else {
- ret = qcom_pas_auth_and_reset(IPA_PAS_ID);
- if (ret)
- dev_err(dev, "error %d authenticating \"%s\"\n", ret, path);
+ goto out_release_firmware;
}
- memunmap(virt);
+ ret = qcom_pas_prepare_and_auth_reset(ctx);
+ if (ret)
+ dev_err(dev, "error %d authenticating \"%s\"\n", ret, path);
+
out_release_firmware:
release_firmware(fw);
--
2.55.0
^ permalink raw reply related [flat|nested] 16+ messages in thread* Re: [PATCH 5/8] net: ipa: migrate firmware loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
2026-09-25 15:57 ` [PATCH 5/8] net: ipa: " Mukesh Ojha
@ 2026-09-26 15:59 ` sashiko-bot
0 siblings, 0 replies; 16+ messages in thread
From: sashiko-bot @ 2026-09-26 15:59 UTC (permalink / raw)
To: Mukesh Ojha; +Cc: media-ci, dri-devel
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] net: ipa: shmbridge setup bypassed due to uninitialized ctx->use_tzmem flag
- [Medium] net: ipa: memory leak of PAS metadata DMA buffer due to missing qcom_pas_metadata_release()
--
commit 5216b43b65b5b9e8f76798ae9a011c6d5ce85515
Author: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
net: ipa: migrate firmware loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
This commit replaces open-coded memory mapping and firmware loading
sequences with devm_qcom_pas_context_alloc() and qcom_mdt_pas_load().
It then uses qcom_pas_prepare_and_auth_reset() with the goal of
performing the shmbridge prepare step required before TrustZone
authentication.
> diff --git a/drivers/net/ipa/ipa_main.c b/drivers/net/ipa/ipa_main.c
> index 14ac2d2faf7c2..6964395caedd9 100644
> --- a/drivers/net/ipa/ipa_main.c
> +++ b/drivers/net/ipa/ipa_main.c
[ ... ]
> @@ -615,24 +614,23 @@ static int ipa_firmware_load(struct device *dev)
> }
>
> phys = res.start;
> - size = (size_t)resource_size(&res);
> - virt = memremap(phys, size, MEMREMAP_WC);
> - if (!virt) {
> - dev_err(dev, "unable to remap firmware memory\n");
> - ret = -ENOMEM;
> + ctx = devm_qcom_pas_context_alloc(dev, IPA_PAS_ID, phys,
> + resource_size(&res));
> + if (IS_ERR(ctx)) {
> + ret = PTR_ERR(ctx);
> goto out_release_firmware;
> }
[Severity: High]
Does allocating the context here leave the use_tzmem flag implicitly
initialized to false?
The commit message states the goal is to execute the shmbridge prepare
step. However, since devm_qcom_pas_context_alloc() allocates the context
using devm_kzalloc(), the ctx->use_tzmem boolean defaults to false.
When qcom_pas_prepare_and_auth_reset(ctx) is called later, the backend
evaluates this flag. If it is false, it falls back to the legacy
authentication path and completely bypasses the intended
qcom_tzmem_shm_bridge_create() logic.
Should ctx->use_tzmem be explicitly set to true after allocation?
>
> - ret = qcom_mdt_load(dev, fw, path, IPA_PAS_ID, virt, phys, size, NULL);
> + ret = qcom_mdt_pas_load(ctx, fw, path, NULL);
> if (ret) {
> dev_err(dev, "error %d loading \"%s\"\n", ret, path);
> - } else {
> - ret = qcom_pas_auth_and_reset(IPA_PAS_ID);
> - if (ret)
> - dev_err(dev, "error %d authenticating \"%s\"\n", ret, path);
> + goto out_release_firmware;
> }
>
> - memunmap(virt);
> + ret = qcom_pas_prepare_and_auth_reset(ctx);
> + if (ret)
> + dev_err(dev, "error %d authenticating \"%s\"\n", ret, path);
> +
> out_release_firmware:
> release_firmware(fw);
>
[Severity: Medium]
Will returning from this path leak the DMA buffer containing the firmware
metadata?
When qcom_mdt_pas_load() is called, it triggers the allocation and mapping
of a DMA buffer for the metadata, storing its address in ctx->ptr. While
the context structure itself is devres-managed, the underlying PAS backend
requires callers to explicitly free the metadata buffer.
If the function returns without calling qcom_pas_metadata_release(ctx),
does this result in a permanent memory leak of the metadata buffer on
every probe attempt?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260925155737.4161358-1-mukesh.ojha@oss.qualcomm.com?part=5
^ permalink raw reply [flat|nested] 16+ messages in thread
* [PATCH 6/8] wifi: ath12k: migrate firmware loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
2026-09-25 15:57 [PATCH 0/8] Migrate PAS clients to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset() Mukesh Ojha
` (4 preceding siblings ...)
2026-09-25 15:57 ` [PATCH 5/8] net: ipa: " Mukesh Ojha
@ 2026-09-25 15:57 ` Mukesh Ojha
2026-09-26 15:59 ` sashiko-bot
2026-09-25 15:57 ` [PATCH 7/8] soc: qcom: mdt_loader: remove qcom_mdt_load() Mukesh Ojha
2026-09-25 15:57 ` [PATCH 8/8] firmware: qcom: pas: remove qcom_pas_auth_and_reset() Mukesh Ojha
7 siblings, 1 reply; 16+ messages in thread
From: Mukesh Ojha @ 2026-09-25 15:57 UTC (permalink / raw)
To: Sumit Garg, Bjorn Andersson, Konrad Dybcio, Rob Clark,
Dmitry Baryshkov, David Airlie, Simona Vetter, Vikash Garodia,
Dikshita Agarwal, Bryan O'Donoghue, Mauro Carvalho Chehab,
Alex Elder, Andrew Lunn, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Jeff Johnson, Mathieu Poirier
Cc: Abel Vesa, Sean Paul, Akhil P Oommen, Abhinav Kumar,
Jessica Zhang, Marijn Suijten, linux-arm-msm, linux-kernel,
dri-devel, freedreno, linux-media, netdev, linux-wireless, ath12k,
linux-remoteproc, Mukesh Ojha
ath12k_ahb_power_up() and ath12k_ahb_load_auth_shared_fw() call
qcom_mdt_load() for SCM-authenticated paths and then
qcom_pas_auth_and_reset() which skips the shmbridge prepare step
required before TrustZone authentication.
Replace `qcom_mdt_load()` with `devm_qcom_pas_context_alloc()` and
`qcom_mdt_pas_load()` in both call sites. In `ath12k_ahb_power_up()` the
PAS context was allocated inside the first `scm_auth_enabled` block; hoist
it to function scope so it remains visible at the authentication step in
the second `scm_auth_enabled` block, then replace
`qcom_pas_auth_and_reset()` with `qcom_pas_prepare_and_auth_reset()`.
The non-SCM-authenticated fw2 path and no-auth path retain their existing
qcom_mdt_load_no_init() calls with the persistent mem_region mapping.
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
---
drivers/net/wireless/ath/ath12k/ahb.c | 31 +++++++++++++++++++--------
1 file changed, 22 insertions(+), 9 deletions(-)
diff --git a/drivers/net/wireless/ath/ath12k/ahb.c b/drivers/net/wireless/ath/ath12k/ahb.c
index 85360365aa4b..6f0ad29a83f8 100644
--- a/drivers/net/wireless/ath/ath12k/ahb.c
+++ b/drivers/net/wireless/ath/ath12k/ahb.c
@@ -391,6 +391,7 @@ static int ath12k_ahb_power_up(struct ath12k_base *ab)
struct ath12k_ahb_rproc_info *rproc_info = ab_ahb->rproc_info;
char fw_name[ATH12K_USERPD_FW_NAME_LEN];
char fw2_name[ATH12K_USERPD_FW_NAME_LEN];
+ struct qcom_pas_context *ctx = NULL;
struct device *dev = ab->dev;
const struct firmware *fw, *fw2;
unsigned long time_left;
@@ -424,14 +425,20 @@ static int ath12k_ahb_power_up(struct ath12k_base *ab)
ATH12K_AHB_UPD_SWID;
/* Load FW image to a reserved memory location */
- if (ab_ahb->scm_auth_enabled)
- ret = qcom_mdt_load(dev, fw, fw_name, pasid, rproc_info->mem_region,
- rproc_info->mem_phys, rproc_info->mem_size,
- NULL);
- else
+ if (ab_ahb->scm_auth_enabled) {
+ ctx = devm_qcom_pas_context_alloc(dev, pasid,
+ rproc_info->mem_phys,
+ rproc_info->mem_size);
+ if (IS_ERR(ctx)) {
+ ret = PTR_ERR(ctx);
+ goto err_fw;
+ }
+ ret = qcom_mdt_pas_load(ctx, fw, fw_name, NULL);
+ } else {
ret = qcom_mdt_load_no_init(dev, fw, fw_name, rproc_info->mem_region,
rproc_info->mem_phys, rproc_info->mem_size,
NULL);
+ }
if (ret) {
ath12k_err(ab, "Failed to load MDT segments: %d\n", ret);
goto err_fw;
@@ -465,7 +472,7 @@ static int ath12k_ahb_power_up(struct ath12k_base *ab)
if (ab_ahb->scm_auth_enabled) {
/* Authenticate FW image using peripheral ID */
- ret = qcom_pas_auth_and_reset(pasid);
+ ret = qcom_pas_prepare_and_auth_reset(ctx);
if (ret) {
ath12k_err(ab, "failed to boot the remote processor %d\n", ret);
goto err_fw2;
@@ -994,6 +1001,7 @@ static int ath12k_ahb_load_auth_shared_fw(struct ath12k_base *ab,
struct ath12k_ahb_rproc_info *rproc_info,
const char *fw_name, u32 pasid)
{
+ struct qcom_pas_context *ctx;
int ret;
const struct firmware *fw __free(firmware) = NULL;
@@ -1012,14 +1020,19 @@ static int ath12k_ahb_load_auth_shared_fw(struct ath12k_base *ab,
ath12k_dbg(ab, ATH12K_DBG_AHB, "loading firmware %s, size %zd\n", fw_name,
fw->size);
- ret = qcom_mdt_load(ab->dev, fw, fw_name, pasid, rproc_info->mem_region,
- rproc_info->mem_phys, rproc_info->mem_size, NULL);
+ ctx = devm_qcom_pas_context_alloc(ab->dev, pasid,
+ rproc_info->mem_phys,
+ rproc_info->mem_size);
+ if (IS_ERR(ctx))
+ return PTR_ERR(ctx);
+
+ ret = qcom_mdt_pas_load(ctx, fw, fw_name, NULL);
if (ret) {
ath12k_err(ab, "failed to load RO firmware %s: %d\n", fw_name, ret);
return ret;
}
- ret = qcom_pas_auth_and_reset(pasid);
+ ret = qcom_pas_prepare_and_auth_reset(ctx);
if (ret)
ath12k_err(ab, "failed to authenticate and boot shared firmware: %d\n",
ret);
--
2.55.0
^ permalink raw reply related [flat|nested] 16+ messages in thread* Re: [PATCH 6/8] wifi: ath12k: migrate firmware loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
2026-09-25 15:57 ` [PATCH 6/8] wifi: ath12k: " Mukesh Ojha
@ 2026-09-26 15:59 ` sashiko-bot
0 siblings, 0 replies; 16+ messages in thread
From: sashiko-bot @ 2026-09-26 15:59 UTC (permalink / raw)
To: Mukesh Ojha; +Cc: media-ci, dri-devel
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] leak: devm_qcom_pas_context_alloc memory leak in recovery loop
- [High] leak: TrustZone memory leak via missing qcom_pas_metadata_release
--
commit 8e4c5b119cfde717dbade4e353783f865e47fb32
Author: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
wifi: ath12k: migrate firmware loading to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset()
ath12k_ahb_power_up() and ath12k_ahb_load_auth_shared_fw() call
qcom_mdt_load() for SCM-authenticated paths and then
qcom_pas_auth_and_reset() which skips the shmbridge prepare step
required before TrustZone authentication.
> diff --git a/drivers/net/wireless/ath/ath12k/ahb.c b/drivers/net/wireless/ath/ath12k/ahb.c
> index 85360365aa4b2..6f0ad29a83f85 100644
> --- a/drivers/net/wireless/ath/ath12k/ahb.c
> +++ b/drivers/net/wireless/ath/ath12k/ahb.c
[ ... ]
> @@ -424,14 +425,20 @@ static int ath12k_ahb_power_up(struct ath12k_base *ab)
> ATH12K_AHB_UPD_SWID;
>
> /* Load FW image to a reserved memory location */
> - if (ab_ahb->scm_auth_enabled)
> - ret = qcom_mdt_load(dev, fw, fw_name, pasid, rproc_info->mem_region,
> - rproc_info->mem_phys, rproc_info->mem_size,
> - NULL);
> - else
> + if (ab_ahb->scm_auth_enabled) {
> + ctx = devm_qcom_pas_context_alloc(dev, pasid,
> + rproc_info->mem_phys,
> + rproc_info->mem_size);
[Severity: High]
Is it safe to use a devm-managed allocation here?
Since ath12k_ahb_power_up() is called dynamically during normal device
operation, such as in firmware crash recovery loops, and the platform device
does not unbind during this process, does this permanently leak a
struct qcom_pas_context on every power-up cycle?
> + if (IS_ERR(ctx)) {
> + ret = PTR_ERR(ctx);
> + goto err_fw;
> + }
> + ret = qcom_mdt_pas_load(ctx, fw, fw_name, NULL);
[Severity: High]
Does this code leak TrustZone memory?
qcom_mdt_pas_load() allocates firmware metadata inside TrustZone. The
caller is typically required to invoke qcom_pas_metadata_release() to
free this secure memory after authentication is complete or on error.
Without a call to qcom_pas_metadata_release() here or later in the
function, is this secure memory permanently lost on every firmware load?
> + } else {
> ret = qcom_mdt_load_no_init(dev, fw, fw_name, rproc_info->mem_region,
> rproc_info->mem_phys, rproc_info->mem_size,
> NULL);
> + }
[ ... ]
> @@ -1012,14 +1020,19 @@ static int ath12k_ahb_load_auth_shared_fw(struct ath12k_base *ab,
> ath12k_dbg(ab, ATH12K_DBG_AHB, "loading firmware %s, size %zd\n", fw_name,
> fw->size);
>
> - ret = qcom_mdt_load(ab->dev, fw, fw_name, pasid, rproc_info->mem_region,
> - rproc_info->mem_phys, rproc_info->mem_size, NULL);
> + ctx = devm_qcom_pas_context_alloc(ab->dev, pasid,
> + rproc_info->mem_phys,
> + rproc_info->mem_size);
> + if (IS_ERR(ctx))
> + return PTR_ERR(ctx);
> +
> + ret = qcom_mdt_pas_load(ctx, fw, fw_name, NULL);
[Severity: High]
Similar to the question above, is a call to qcom_pas_metadata_release()
needed here to prevent leaking TrustZone memory after the shared
firmware is loaded and authenticated?
> if (ret) {
> ath12k_err(ab, "failed to load RO firmware %s: %d\n", fw_name, ret);
> return ret;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260925155737.4161358-1-mukesh.ojha@oss.qualcomm.com?part=6
^ permalink raw reply [flat|nested] 16+ messages in thread
* [PATCH 7/8] soc: qcom: mdt_loader: remove qcom_mdt_load()
2026-09-25 15:57 [PATCH 0/8] Migrate PAS clients to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset() Mukesh Ojha
` (5 preceding siblings ...)
2026-09-25 15:57 ` [PATCH 6/8] wifi: ath12k: " Mukesh Ojha
@ 2026-09-25 15:57 ` Mukesh Ojha
2026-09-26 15:59 ` sashiko-bot
2026-09-25 15:57 ` [PATCH 8/8] firmware: qcom: pas: remove qcom_pas_auth_and_reset() Mukesh Ojha
7 siblings, 1 reply; 16+ messages in thread
From: Mukesh Ojha @ 2026-09-25 15:57 UTC (permalink / raw)
To: Sumit Garg, Bjorn Andersson, Konrad Dybcio, Rob Clark,
Dmitry Baryshkov, David Airlie, Simona Vetter, Vikash Garodia,
Dikshita Agarwal, Bryan O'Donoghue, Mauro Carvalho Chehab,
Alex Elder, Andrew Lunn, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Jeff Johnson, Mathieu Poirier
Cc: Abel Vesa, Sean Paul, Akhil P Oommen, Abhinav Kumar,
Jessica Zhang, Marijn Suijten, linux-arm-msm, linux-kernel,
dri-devel, freedreno, linux-media, netdev, linux-wireless, ath12k,
linux-remoteproc, Mukesh Ojha
All callers have been migrated to qcom_mdt_pas_load(), which takes an
explicit qcom_pas_context instead of a raw pas_id and delegates memory
setup to the context. Remove the now-unused qcom_mdt_load() wrapper
along with its EXPORT_SYMBOL_GPL and header declaration.
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
---
drivers/soc/qcom/mdt_loader.c | 59 ++++++++++-------------------
include/linux/soc/qcom/mdt_loader.h | 12 ------
2 files changed, 19 insertions(+), 52 deletions(-)
diff --git a/drivers/soc/qcom/mdt_loader.c b/drivers/soc/qcom/mdt_loader.c
index 002100fe2d32..1c7b5906f6ae 100644
--- a/drivers/soc/qcom/mdt_loader.c
+++ b/drivers/soc/qcom/mdt_loader.c
@@ -326,7 +326,8 @@ static bool qcom_mdt_bins_are_split(const struct firmware *fw)
* @dev: device handle to associate resources with
* @fw: firmware object for the mdt file
* @fw_name: name of the firmware, for construction of segment file names
- * @mem_region: allocated memory region to load firmware into
+ * @mem_region: virtual address of the memory region to load firmware into,
+ * or NULL to have the region mapped internally with ioremap_wc()
* @mem_phys: physical address of allocated memory region
* @mem_size: size of the allocated memory region
* @reloc_base: adjusted physical address after relocation
@@ -341,6 +342,7 @@ int qcom_mdt_load_no_init(struct device *dev, const struct firmware *fw,
const struct elf32_phdr *phdrs;
const struct elf32_phdr *phdr;
const struct elf32_hdr *ehdr;
+ void __iomem *mapped = NULL;
phys_addr_t mem_reloc;
phys_addr_t min_addr = PHYS_ADDR_MAX;
ssize_t offset;
@@ -350,12 +352,22 @@ int qcom_mdt_load_no_init(struct device *dev, const struct firmware *fw,
int ret = 0;
int i;
- if (!fw || !mem_region || !mem_phys || !mem_size)
+ if (!fw || !mem_phys || !mem_size)
return -EINVAL;
if (!mdt_header_valid(fw))
return -EINVAL;
+ if (!mem_region) {
+ mapped = ioremap_wc(mem_phys, mem_size);
+ if (!mapped) {
+ dev_err(dev, "unable to map memory region: %pa+%zx\n",
+ &mem_phys, mem_size);
+ return -ENOMEM;
+ }
+ mem_region = (__force void *)mapped;
+ }
+
is_split = qcom_mdt_bins_are_split(fw);
ehdr = (struct elf32_hdr *)fw->data;
phdrs = (struct elf32_phdr *)(fw->data + ehdr->e_phoff);
@@ -434,39 +446,13 @@ int qcom_mdt_load_no_init(struct device *dev, const struct firmware *fw,
if (reloc_base)
*reloc_base = mem_reloc;
+ if (mapped)
+ iounmap(mapped);
+
return ret;
}
EXPORT_SYMBOL_GPL(qcom_mdt_load_no_init);
-/**
- * qcom_mdt_load() - load the firmware which header is loaded as fw
- * @dev: device handle to associate resources with
- * @fw: firmware object for the mdt file
- * @fw_name: name of the firmware, for construction of segment file names
- * @pas_id: PAS identifier
- * @mem_region: allocated memory region to load firmware into
- * @mem_phys: physical address of allocated memory region
- * @mem_size: size of the allocated memory region
- * @reloc_base: adjusted physical address after relocation
- *
- * Returns 0 on success, negative errno otherwise.
- */
-int qcom_mdt_load(struct device *dev, const struct firmware *fw,
- const char *fw_name, int pas_id, void *mem_region,
- phys_addr_t mem_phys, size_t mem_size,
- phys_addr_t *reloc_base)
-{
- int ret;
-
- ret = __qcom_mdt_pas_init(dev, fw, fw_name, pas_id, mem_phys, NULL);
- if (ret)
- return ret;
-
- return qcom_mdt_load_no_init(dev, fw, fw_name, mem_region, mem_phys,
- mem_size, reloc_base);
-}
-EXPORT_SYMBOL_GPL(qcom_mdt_load);
-
/**
* qcom_mdt_pas_load - Loads and authenticates the metadata of the firmware
* (typically contained in the .mdt file), followed by loading the actual
@@ -486,21 +472,14 @@ EXPORT_SYMBOL_GPL(qcom_mdt_load);
int qcom_mdt_pas_load(struct qcom_pas_context *ctx, const struct firmware *fw,
const char *firmware, phys_addr_t *reloc_base)
{
- void __iomem *mem_region;
int ret;
ret = __qcom_mdt_pas_init(ctx->dev, fw, firmware, ctx->pas_id, ctx->mem_phys, ctx);
if (ret)
return ret;
- mem_region = qcom_pas_ctx_map(ctx);
- if (!mem_region)
- return -ENOMEM;
-
- ret = qcom_mdt_load_no_init(ctx->dev, fw, firmware, (__force void *)mem_region,
- ctx->mem_phys, ctx->mem_size, reloc_base);
- iounmap(mem_region);
- return ret;
+ return qcom_mdt_load_no_init(ctx->dev, fw, firmware, NULL,
+ ctx->mem_phys, ctx->mem_size, reloc_base);
}
EXPORT_SYMBOL_GPL(qcom_mdt_pas_load);
diff --git a/include/linux/soc/qcom/mdt_loader.h b/include/linux/soc/qcom/mdt_loader.h
index 74886f772d46..f49de7b388bc 100644
--- a/include/linux/soc/qcom/mdt_loader.h
+++ b/include/linux/soc/qcom/mdt_loader.h
@@ -15,10 +15,6 @@ struct qcom_pas_context;
#if IS_ENABLED(CONFIG_QCOM_MDT_LOADER)
ssize_t qcom_mdt_get_size(const struct firmware *fw);
-int qcom_mdt_load(struct device *dev, const struct firmware *fw,
- const char *fw_name, int pas_id, void *mem_region,
- phys_addr_t mem_phys, size_t mem_size,
- phys_addr_t *reloc_base);
int qcom_mdt_pas_load(struct qcom_pas_context *ctx, const struct firmware *fw,
const char *firmware, phys_addr_t *reloc_base);
@@ -37,14 +33,6 @@ static inline ssize_t qcom_mdt_get_size(const struct firmware *fw)
return -ENODEV;
}
-static inline int qcom_mdt_load(struct device *dev, const struct firmware *fw,
- const char *fw_name, int pas_id,
- void *mem_region, phys_addr_t mem_phys,
- size_t mem_size, phys_addr_t *reloc_base)
-{
- return -ENODEV;
-}
-
static inline int qcom_mdt_pas_load(struct qcom_pas_context *ctx,
const struct firmware *fw, const char *firmware,
phys_addr_t *reloc_base)
--
2.55.0
^ permalink raw reply related [flat|nested] 16+ messages in thread* Re: [PATCH 7/8] soc: qcom: mdt_loader: remove qcom_mdt_load()
2026-09-25 15:57 ` [PATCH 7/8] soc: qcom: mdt_loader: remove qcom_mdt_load() Mukesh Ojha
@ 2026-09-26 15:59 ` sashiko-bot
0 siblings, 0 replies; 16+ messages in thread
From: sashiko-bot @ 2026-09-26 15:59 UTC (permalink / raw)
To: Mukesh Ojha; +Cc: dri-devel, media-ci
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] mm: devres memory leak in device lifecycle functions due to devm_qcom_pas_context_alloc()
--
commit 7aed1d3e9c7b0aae366ecbadb5ead9994e82f517
Author: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
soc: qcom: mdt_loader: remove qcom_mdt_load()
This commit removes the qcom_mdt_load() wrapper since all callers have been
migrated to qcom_mdt_pas_load(). The new function takes an explicit
qcom_pas_context and delegates memory setup to it.
> All callers have been migrated to qcom_mdt_pas_load(), which takes an
> explicit qcom_pas_context instead of a raw pas_id and delegates memory
> setup to the context.
[Severity: Medium]
Does this migration introduce a memory leak of struct qcom_pas_context?
The migration to qcom_mdt_pas_load() requires an explicit context allocated
via devm_qcom_pas_context_alloc(). This allocation is now placed inside
functions like ath12k_ahb_power_up(), venus_load_fw(), and
iris_load_fw_to_memory():
drivers/net/wireless/ath/ath12k/ahb.c:ath12k_ahb_power_up() {
...
ctx = devm_qcom_pas_context_alloc(dev, pasid, rproc_info->mem_phys,
rproc_info->mem_size);
...
}
drivers/media/platform/qcom/venus/firmware.c:venus_load_fw() {
...
core->fw.pas_ctx = devm_qcom_pas_context_alloc(dev, VENUS_PAS_ID,
*mem_phys, *mem_size);
...
}
drivers/media/platform/qcom/iris/iris_firmware.c:iris_load_fw_to_memory() {
...
core->pas_ctx = devm_qcom_pas_context_alloc(dev, IRIS_PAS_ID, mem_phys,
resource_size(&res));
...
}
These functions are executed repeatedly during normal system operations such as
system suspend/resume (e.g., ath12k_core_resume_early() ->
ath12k_hif_power_up() -> ath12k_ahb_power_up()) and system error recovery
(venus_sys_error_handler, iris_sys_error_handler).
Since devm_* resources are only freed when the driver is unbound, does every
invocation append a new allocation to the devres list without freeing the
previous one?
This would leak memory and degrade devres traversal performance with each
suspend/resume cycle or error recovery.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260925155737.4161358-1-mukesh.ojha@oss.qualcomm.com?part=7
^ permalink raw reply [flat|nested] 16+ messages in thread
* [PATCH 8/8] firmware: qcom: pas: remove qcom_pas_auth_and_reset()
2026-09-25 15:57 [PATCH 0/8] Migrate PAS clients to qcom_mdt_pas_load() and qcom_pas_prepare_and_auth_reset() Mukesh Ojha
` (6 preceding siblings ...)
2026-09-25 15:57 ` [PATCH 7/8] soc: qcom: mdt_loader: remove qcom_mdt_load() Mukesh Ojha
@ 2026-09-25 15:57 ` Mukesh Ojha
7 siblings, 0 replies; 16+ messages in thread
From: Mukesh Ojha @ 2026-09-25 15:57 UTC (permalink / raw)
To: Sumit Garg, Bjorn Andersson, Konrad Dybcio, Rob Clark,
Dmitry Baryshkov, David Airlie, Simona Vetter, Vikash Garodia,
Dikshita Agarwal, Bryan O'Donoghue, Mauro Carvalho Chehab,
Alex Elder, Andrew Lunn, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Jeff Johnson, Mathieu Poirier
Cc: Abel Vesa, Sean Paul, Akhil P Oommen, Abhinav Kumar,
Jessica Zhang, Marijn Suijten, linux-arm-msm, linux-kernel,
dri-devel, freedreno, linux-media, netdev, linux-wireless, ath12k,
linux-remoteproc, Mukesh Ojha
All callers have been migrated to qcom_pas_prepare_and_auth_reset(),
which additionally sets up a shmbridge over firmware memory before
TrustZone authentication. Remove the bare pas_id-only wrapper, its
EXPORT_SYMBOL_GPL, the header declaration, the auth_and_reset ops slot
from struct qcom_pas_ops and both backend implementations.
The internal helper functions (__qcom_scm_pas_auth_and_reset,
__qcom_pas_tee_auth_and_reset) remain as they are called directly by
their respective prepare_and_auth_reset implementations.
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
---
drivers/firmware/qcom/qcom_pas.c | 16 ----------------
drivers/firmware/qcom/qcom_pas.h | 3 ---
drivers/firmware/qcom/qcom_pas_tee.c | 6 ------
drivers/firmware/qcom/qcom_scm.c | 7 +++----
include/linux/firmware/qcom/qcom_pas.h | 1 -
5 files changed, 3 insertions(+), 30 deletions(-)
diff --git a/drivers/firmware/qcom/qcom_pas.c b/drivers/firmware/qcom/qcom_pas.c
index 93d78a5c1201..6de6d62adfde 100644
--- a/drivers/firmware/qcom/qcom_pas.c
+++ b/drivers/firmware/qcom/qcom_pas.c
@@ -166,22 +166,6 @@ struct resource_table *qcom_pas_get_rsc_table(struct qcom_pas_context *ctx,
}
EXPORT_SYMBOL_GPL(qcom_pas_get_rsc_table);
-/**
- * qcom_pas_auth_and_reset() - Authenticate the given peripheral firmware
- * and reset the remote processor
- * @pas_id: peripheral authentication service id
- *
- * Return: 0 on success.
- */
-int qcom_pas_auth_and_reset(u32 pas_id)
-{
- if (!ops_ptr)
- return -ENODEV;
-
- return ops_ptr->auth_and_reset(ops_ptr->dev, pas_id);
-}
-EXPORT_SYMBOL_GPL(qcom_pas_auth_and_reset);
-
/**
* qcom_pas_prepare_and_auth_reset() - Prepare, authenticate, and reset the
* remote processor
diff --git a/drivers/firmware/qcom/qcom_pas.h b/drivers/firmware/qcom/qcom_pas.h
index 8643e2760602..a296be2be8c0 100644
--- a/drivers/firmware/qcom/qcom_pas.h
+++ b/drivers/firmware/qcom/qcom_pas.h
@@ -18,8 +18,6 @@ struct device;
* @get_rsc_table: Peripheral get resource table callback.
* @prepare_and_auth_reset: Peripheral prepare firmware authentication and
* reset callback.
- * @auth_and_reset: Peripheral firmware authentication and reset
- * callback.
* @set_remote_state: Peripheral set remote state callback.
* @shutdown: Peripheral shutdown callback.
* @metadata_release: Image metadata release callback.
@@ -37,7 +35,6 @@ struct qcom_pas_ops {
size_t *output_rt_size);
int (*prepare_and_auth_reset)(struct device *dev,
struct qcom_pas_context *ctx);
- int (*auth_and_reset)(struct device *dev, u32 pas_id);
int (*set_remote_state)(struct device *dev, u32 state, u32 pas_id);
int (*shutdown)(struct device *dev, u32 pas_id);
void (*metadata_release)(struct device *dev,
diff --git a/drivers/firmware/qcom/qcom_pas_tee.c b/drivers/firmware/qcom/qcom_pas_tee.c
index ac33a00687aa..dbab9a43e6ca 100644
--- a/drivers/firmware/qcom/qcom_pas_tee.c
+++ b/drivers/firmware/qcom/qcom_pas_tee.c
@@ -320,11 +320,6 @@ static int __qcom_pas_tee_auth_and_reset(struct device *dev, u32 pas_id,
return ret;
}
-static int qcom_pas_tee_auth_and_reset(struct device *dev, u32 pas_id)
-{
- return __qcom_pas_tee_auth_and_reset(dev, pas_id, 0, 0);
-}
-
static int qcom_pas_tee_prepare_and_auth_reset(struct device *dev,
struct qcom_pas_context *ctx)
{
@@ -401,7 +396,6 @@ static struct qcom_pas_ops qcom_pas_ops_tee = {
.init_image = qcom_pas_tee_init_image,
.mem_setup = qcom_pas_tee_mem_setup,
.get_rsc_table = qcom_pas_tee_get_rsc_table,
- .auth_and_reset = qcom_pas_tee_auth_and_reset,
.prepare_and_auth_reset = qcom_pas_tee_prepare_and_auth_reset,
.set_remote_state = qcom_pas_tee_set_remote_state,
.shutdown = qcom_pas_tee_shutdown,
diff --git a/drivers/firmware/qcom/qcom_scm.c b/drivers/firmware/qcom/qcom_scm.c
index dc57c87870cf..08b9c5049dd9 100644
--- a/drivers/firmware/qcom/qcom_scm.c
+++ b/drivers/firmware/qcom/qcom_scm.c
@@ -845,7 +845,7 @@ static void *qcom_scm_pas_get_rsc_table(struct device *dev,
return ret ? ERR_PTR(ret) : tbl_ptr;
}
-static int qcom_scm_pas_auth_and_reset(struct device *dev, u32 pas_id)
+static int __qcom_scm_pas_auth_and_reset(struct device *dev, u32 pas_id)
{
int ret;
struct qcom_scm_desc desc = {
@@ -886,7 +886,7 @@ static int qcom_scm_pas_prepare_and_auth_reset(struct device *dev,
* memory region and then invokes a call to TrustZone to authenticate.
*/
if (!ctx->use_tzmem)
- return qcom_scm_pas_auth_and_reset(dev, ctx->pas_id);
+ return __qcom_scm_pas_auth_and_reset(dev, ctx->pas_id);
/*
* When Linux runs @ EL2 Linux must create the shmbridge itself and then
@@ -896,7 +896,7 @@ static int qcom_scm_pas_prepare_and_auth_reset(struct device *dev,
if (ret)
return ret;
- ret = qcom_scm_pas_auth_and_reset(dev, ctx->pas_id);
+ ret = __qcom_scm_pas_auth_and_reset(dev, ctx->pas_id);
qcom_tzmem_shm_bridge_delete(handle);
return ret;
@@ -977,7 +977,6 @@ static struct qcom_pas_ops qcom_pas_ops_scm = {
.init_image = qcom_scm_pas_init_image,
.mem_setup = qcom_scm_pas_mem_setup,
.get_rsc_table = qcom_scm_pas_get_rsc_table,
- .auth_and_reset = qcom_scm_pas_auth_and_reset,
.prepare_and_auth_reset = qcom_scm_pas_prepare_and_auth_reset,
.set_remote_state = qcom_scm_pas_set_remote_state,
.shutdown = qcom_scm_pas_shutdown,
diff --git a/include/linux/firmware/qcom/qcom_pas.h b/include/linux/firmware/qcom/qcom_pas.h
index 1d132e89536e..07d0f1fad85f 100644
--- a/include/linux/firmware/qcom/qcom_pas.h
+++ b/include/linux/firmware/qcom/qcom_pas.h
@@ -46,7 +46,6 @@ struct resource_table *qcom_pas_get_rsc_table(struct qcom_pas_context *ctx,
void *input_rt, size_t input_rt_size,
size_t *output_rt_size);
int qcom_pas_mem_setup(u32 pas_id, phys_addr_t addr, phys_addr_t size);
-int qcom_pas_auth_and_reset(u32 pas_id);
int qcom_pas_prepare_and_auth_reset(struct qcom_pas_context *ctx);
int qcom_pas_set_remote_state(u32 state, u32 pas_id);
int qcom_pas_shutdown(u32 pas_id);
--
2.55.0
^ permalink raw reply related [flat|nested] 16+ messages in thread