* [PATCH v3] arm64: dts: qcom: agatti: Add memory-region for audio PD
@ 2026-08-20 5:51 Vinayak Katoch
2026-08-20 6:03 ` sashiko-bot
0 siblings, 1 reply; 2+ messages in thread
From: Vinayak Katoch @ 2026-08-20 5:51 UTC (permalink / raw)
To: Bjorn Andersson, Konrad Dybcio, Rob Herring, Krzysztof Kozlowski,
Conor Dooley
Cc: Bharath Kumar, Chenna Kesava Raju, Ekansh Gupta, linux-arm-msm,
devicetree, linux-kernel, Christopher Obbard, Dmitry Baryshkov,
Vinayak Katoch
Reserve memory region for audio PD dynamic loading and remote heap
requirements. Add the required VMID list for memory ownership
transfers.
Tested-by: Christopher Obbard <chris.obbard@oss.qualcomm.com>
Reviewed-by: Ekansh Gupta <ekansh.gupta@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Vinayak Katoch <vinayak.katoch@oss.qualcomm.com>
---
Changes in v3:
- Changed alloc-ranges to <0x0 0x0 0x1 0x0> to cover the full 32-bit address space.
- Collected Reviewed-by/Tested-by tags.
- Link to v2: https://lore.kernel.org/r/20260807-agatti-audio-v2-1-3959b1ab8059@oss.qualcomm.com
Changes in v2:
- Fixed VMID list alignment.
- Link to v1: https://lore.kernel.org/r/20260806-agatti-audio-v1-1-cd6766cc9ccb@oss.qualcomm.com
---
arch/arm64/boot/dts/qcom/agatti.dtsi | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/arch/arm64/boot/dts/qcom/agatti.dtsi b/arch/arm64/boot/dts/qcom/agatti.dtsi
index 590bd2432d85..d010ef7fdf8c 100644
--- a/arch/arm64/boot/dts/qcom/agatti.dtsi
+++ b/arch/arm64/boot/dts/qcom/agatti.dtsi
@@ -381,6 +381,14 @@ rmtfs_mem: memory@89b01000 {
qcom,client-id = <1>;
qcom,vmid = <QCOM_SCM_VMID_MSS_MSA QCOM_SCM_VMID_NAV>;
};
+
+ adsp_rpc_remote_heap_mem: adsp-rpc-remote-heap {
+ compatible = "shared-dma-pool";
+ alloc-ranges = <0x0 0x0 0x1 0x0>;
+ reusable;
+ alignment = <0x0 0x400000>;
+ size = <0x0 0x800000>;
+ };
};
smp2p-adsp {
@@ -2348,6 +2356,9 @@ fastrpc {
compatible = "qcom,fastrpc";
qcom,glink-channels = "fastrpcglink-apps-dsp";
label = "adsp";
+ memory-region = <&adsp_rpc_remote_heap_mem>;
+ qcom,vmids = <QCOM_SCM_VMID_LPASS
+ QCOM_SCM_VMID_ADSP_HEAP>;
qcom,non-secure-domain;
---
base-commit: 1701fda2f58e345c050f4309971bdc07cd6146ba
change-id: 20260806-agatti-audio-357bcd74ae9c
Best regards,
--
Vinayak Katoch <vinayak.katoch@oss.qualcomm.com>
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH v3] arm64: dts: qcom: agatti: Add memory-region for audio PD
2026-08-20 5:51 [PATCH v3] arm64: dts: qcom: agatti: Add memory-region for audio PD Vinayak Katoch
@ 2026-08-20 6:03 ` sashiko-bot
0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-08-20 6:03 UTC (permalink / raw)
To: Vinayak Katoch; +Cc: devicetree, conor+dt, robh
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] The `adsp-rpc-remote-heap` region is configured as a `reusable` CMA pool without retaining HLOS (Host OS) access, leaving it mapped in the kernel's linear mapping and causing fatal stage-2 permission faults (XPU violations) upon speculative CPU access after ownership is transferred to the DSP.
--
--- Patch [1]: [PATCH v3] arm64: dts: qcom: agatti: Add memory-region for audio PD ---
commit 775c3c4fb571c7287ee665932e31677e111e34c6
Author: Vinayak Katoch <vinayak.katoch@oss.qualcomm.com>
arm64: dts: qcom: agatti: Add memory-region for audio PD
This commit reserves a memory region for audio PD dynamic loading and remote
heap requirements. It also adds the required VMID list for memory ownership
transfers.
Link: https://lore.kernel.org/r/20260807-agatti-audio-v2-1-3959b1ab8059@oss.qualcomm.com
> diff --git a/arch/arm64/boot/dts/qcom/agatti.dtsi b/arch/arm64/boot/dts/qcom/agatti.dtsi
> --- a/arch/arm64/boot/dts/qcom/agatti.dtsi
> +++ b/arch/arm64/boot/dts/qcom/agatti.dtsi
> @@ -381,6 +381,14 @@ rmtfs_mem: memory@89b01000 {
> qcom,client-id = <1>;
> qcom,vmid = <QCOM_SCM_VMID_MSS_MSA QCOM_SCM_VMID_NAV>;
> };
> +
> + adsp_rpc_remote_heap_mem: adsp-rpc-remote-heap {
> + compatible = "shared-dma-pool";
> + alloc-ranges = <0x0 0x0 0x1 0x0>;
> + reusable;
[Severity: High]
Since this reserved-memory node is defined with reusable rather than no-map,
it forces the region to be managed by CMA and mapped in the kernel's linear
mapping.
Could this expose the region to speculative CPU accesses, which might lead to
fatal stage-2 permission faults (XPU violations) after ownership is transferred
to the DSP?
> + alignment = <0x0 0x400000>;
> + size = <0x0 0x800000>;
> + };
> };
[ ... ]
> @@ -2347,6 +2355,9 @@ fastrpc {
> compatible = "qcom,fastrpc";
> qcom,glink-channels = "fastrpcglink-apps-dsp";
> label = "adsp";
> + memory-region = <&adsp_rpc_remote_heap_mem>;
> + qcom,vmids = <QCOM_SCM_VMID_LPASS
> + QCOM_SCM_VMID_ADSP_HEAP>;
[Severity: High]
The qcom,vmids array explicitly omits QCOM_SCM_VMID_HLOS here.
This directs the fastrpc driver to completely revoke CPU access during the SCM
assignment. If the memory remains in the linear mapping (due to the reusable
property above), doesn't this create a fatal mismatch with the active stage-1
linear mapping, resulting in kernel panics upon speculative CPU data or
instruction fetches?
>
> qcom,non-secure-domain;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260820-agatti-audio-v3-1-47337097ee53@oss.qualcomm.com?part=1
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-08-20 6:03 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-20 5:51 [PATCH v3] arm64: dts: qcom: agatti: Add memory-region for audio PD Vinayak Katoch
2026-08-20 6:03 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox