From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yx1-f52.google.com (mail-yx1-f52.google.com [74.125.224.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1B959373BE7 for ; Thu, 25 Jun 2026 08:57:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.224.52 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782377850; cv=none; b=M5Fs6LJYCmzXY6ctGQRPuAX4MqQ2Fnk7c57JLnoUoVaBp2Sdw5995NIMsUe/VEXc0tpN0aguDehem4sYiRNHXHpkhdzkDTrDvbsgOt7LS7M1pgbEP7cLNWLsEu5YWY5xksdKcs2qxpbqvWoLGHzB3pVw0fIrkicyFV6RMzi9WJ0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782377850; c=relaxed/simple; bh=7+RpgeFXilV9LBg54j04AxM1dVDg8zK074PE+ydai/M=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=cibPmDLLXLPyv7aG35/YuArBv3dQBKLo8bvL2FuDzeTBItb9FNSRO6+/mtjZyvve8wqPKJh+r89JIkpFZnv4BlroSPDvg725zcp0wY8qZGm6vWWfEpqjqDpK7xus1X9oyCigVvx0k1lJBs/fsfoaJIf9FQTroI3t3L1pEBf70rg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=gXVhpqjw; arc=none smtp.client-ip=74.125.224.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="gXVhpqjw" Received: by mail-yx1-f52.google.com with SMTP id 956f58d0204a3-6611669cd16so2265376d50.0 for ; Thu, 25 Jun 2026 01:57:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782377848; x=1782982648; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=3HXBGWP+mHV9r0WWwErucYsy42UpdRmWv6NJcEbVBLI=; b=gXVhpqjwqJFHcx12EuO8AanvpBdSfaGcTVJWC5Fo8lHUD2jxcTv1hxFan5diXBQQTk M+kzD7QsLvD/cG4DJgvQhbIygvmVjG0cth2v4/OVSmynwfrcxJwREPQwfA+RQ1PS/ve7 bObLzkxD4wJUXafF65NRxLSpjKyGmgCCFQyLIcvAQzr3QQUr+eHENp7MaydZv6UmUFTG gvNbYpY/+iFDIfVJkpDi96F12vKtEDD2kN8DAvuODXUW/Q5DF43mp2brLDdP9rPSuJK2 0Rcrh8GOrZf05oExTn9AngAWY2AlWeR/wpMXV4LRgv12NosRM+ekzpIbIkkmAQ+iiuwE DMWQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782377848; x=1782982648; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=3HXBGWP+mHV9r0WWwErucYsy42UpdRmWv6NJcEbVBLI=; b=bhpQ2WCUBkEBZphfJ9iCMurjTD/K4BhwHb/MLtJ9SHT1W7jewhn+tVDbOJkBo6MOjY dSeZjU0Cmjhyq0KDK+3Hzrxoo7Xi1BcO/Jzbq6MpCTxMWyBMVT4ZSTbJv3FCiyGemsqX RgRuFZflpLRRBFPj2JPT83V1eo1g7DSKnk+Cs1XDt6hGshq3miC/YERndLPwigcVLZxo uQWcys3hwhcKkJqSl03hzr/xAUlKcF38LaxfsEIOzVck+CGcFj07cf5smLIfDHBk2Kpt /mNUYUSojhpX6yD7YWzLuEoNX6PGeMKXU1rxU0VHIhrmGMdQF9RV0Ji1dCmWyWptwkaR rNzA== X-Forwarded-Encrypted: i=1; AHgh+RpwYyu0kksvy/R9lwCFW85Zv51r9w7ORvOTLfNS6yVVAFvV5wtRBaoPQ9hfjOWXiBVjME1e5tlz5ulwqmM=@vger.kernel.org X-Gm-Message-State: AOJu0YzjBLSm/H3X8dY+34UebkbXIBL+U8MTkSwIu/hHVGEaehCpqxHT bVgIXOENfF89I9Gl8rt1WZ60iS3pkHYNb1D4Uxt3pvfbx5tDtGz12euP X-Gm-Gg: AfdE7cn4HFVsJ/yvius309FQ8w2nebxtsTCxo3h8hLivDuz3mXP4WvUDFL/kOadsYpI IDdjJj5TKhR5Ezmdzzl3iauvJuhxCAgsRu+IL3ErAOK5Rib3T5QlkLzR8OZcjPkgF82Qdnh8jji 7tftLyTEWKA14aJU8dWxj5RMlzOzPdWD4JmDGdgMEyE+11A7dQ2pjosVrCtdCPC5wCB3LUGfxqT b0yDil7LY6ImBFgZBdp4GXFt915CRDHn7DeNGy1W5Jtg0N1eH6L/O0M0MIw1MdbudmULAByiv// 9m0ejtJlTFhzFJMn5pxxQpjku46eAef5Kj1x7iPBeoLia6NIu7apSPSF9leZKU68VegPia8JUWN iSXvQ7LqGFnqQjOwLGTmMuuVyK1BRtva2+4598syPGf3+CtHKtz7O+Ov7ijsjy2CUBbS7BBiS3s sFT49eYms8AtX7RD0RXavHv23f1w== X-Received: by 2002:a05:690e:b4a:b0:660:ffe0:2df7 with SMTP id 956f58d0204a3-66487c28ae6mr1186398d50.23.1782377847966; Thu, 25 Jun 2026 01:57:27 -0700 (PDT) Received: from Dev-Null-MSI ([2a0d:3344:52ac:a808:98a4:4381:be45:536f]) by smtp.gmail.com with ESMTPSA id 956f58d0204a3-6647f785f6bsm1105061d50.6.2026.06.25.01.57.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 25 Jun 2026 01:57:27 -0700 (PDT) From: Yousef Alhouseen To: Srinivas Kandagatla , Amol Maheshwari Cc: Konrad Dybcio , Arnd Bergmann , Greg Kroah-Hartman , linux-arm-msm@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Yousef Alhouseen Subject: [PATCH 3/3] misc: fastrpc: protect interrupted mmap cleanup Date: Thu, 25 Jun 2026 10:56:59 +0200 Message-ID: <20260625085659.4469-3-alhouseenyousef@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260625085659.4469-1-alhouseenyousef@gmail.com> References: <20260625085659.4469-1-alhouseenyousef@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The interrupted invoke path walks and moves fl->mmaps without holding fl->lock, racing concurrent mmap and munmap operations that use the same list. Move the buffers while holding the user lock and use list_del_init() so later cleanup can safely identify moved nodes. Buffers moved to the channel interrupted list are also discarded on rpmsg removal without freeing their coherent DMA allocations. Free them during channel removal so interrupted invokes cannot permanently leak DMA buffers. Signed-off-by: Yousef Alhouseen --- drivers/misc/fastrpc.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c index 50f90e17e..608878052 100644 --- a/drivers/misc/fastrpc.c +++ b/drivers/misc/fastrpc.c @@ -1395,10 +1395,12 @@ static int fastrpc_internal_invoke(struct fastrpc_user *fl, u32 kernel, bail: if (err == -ERESTARTSYS) { + spin_lock(&fl->lock); list_for_each_entry_safe(buf, b, &fl->mmaps, node) { - list_del(&buf->node); + list_del_init(&buf->node); list_add_tail(&buf->node, &fl->cctx->invoke_interrupted_mmaps); } + spin_unlock(&fl->lock); } /* We are done with this compute context */ @@ -2628,8 +2630,10 @@ static void fastrpc_rpmsg_remove(struct rpmsg_device *rpdev) if (cctx->secure_fdevice) misc_deregister(&cctx->secure_fdevice->miscdev); - list_for_each_entry_safe(buf, b, &cctx->invoke_interrupted_mmaps, node) - list_del(&buf->node); + list_for_each_entry_safe(buf, b, &cctx->invoke_interrupted_mmaps, node) { + list_del_init(&buf->node); + fastrpc_buf_free(buf); + } if (cctx->remote_heap) fastrpc_buf_free(cctx->remote_heap); -- 2.54.0