From nobody Fri Jul 24 23:30:48 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4AEC02D738F; Wed, 22 Jul 2026 05:54:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784699697; cv=none; b=Asrq4Bd1CvoXx4wKQbJtuRwM6cMcGSgGIsU0M1P1qk2cb/dHCTmV4P2LpwgAYTFR/rA1fL/nNlAyCKtpN+EWv3gR+BFdItYbKP5VtApCUlYIZwgvKOQ87Ed9VwtP3cavu145UKWBmzHcDvV64LfjXdQXh0Xunc6BBTLnE4z6bHE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784699697; c=relaxed/simple; bh=voOOBd9HvX3UPrrJxTYmzX8Mpvp98H8H/fh0sHin1iw=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=UPPqQpUPbf/37+qhkfRehWkFHq690i8Hdvwkv24OoAe6pMs+3jq2aotTEIV2SZEW4vcVg1rclCwU9arUq2702cFzIV7fKHEXzgwUUjvAzHMRJbLf3FJkXTh3v8erjYEikoXzFWUGeM8DgD8EyqvWRxKAurxCozJ6CMas0cB0Tj8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=MLFu/Ksy; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="MLFu/Ksy" Received: by smtp.kernel.org (Postfix) with ESMTPS id EBDA5C19425; Wed, 22 Jul 2026 05:54:56 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1784699697; bh=voOOBd9HvX3UPrrJxTYmzX8Mpvp98H8H/fh0sHin1iw=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=MLFu/KsydcTzhmIkxtCL35BHF9f+EsOZwluu2/QWQm0SzT+BcpDL4eRJ50aF1j2Z9 FKYKxze6HqnJs5TqoaOk4EAlnLx9W6Kgo7WerBf9XeUbKOFQxKaT7ajqi6G6K8O1vH ikbnXYnks5zVB7cVm9I46jkEichtsr7eszOx3Wo/JCe9HVuw05v+ruWmuc63WZck4/ pd3XDwqvtYMNsWozNHozt4jSYtng6tCUfkYIePNHglzfzTntqB2SfkkU4FHKltg/Ic rvYDT5vZSILmHoTaQ0Plh10ePOBKtGOlZ9o7EU5/E0OyK6+JbBVy3ktWW4vb/1yLw+ 0Z79RFD8mi/UQ== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CAD68C4452D; Wed, 22 Jul 2026 05:54:56 +0000 (UTC) From: Manivannan Sadhasivam via B4 Relay Date: Wed, 22 Jul 2026 07:54:44 +0200 Subject: [PATCH v3 1/3] bus: mhi: ep: Add mhi_cntrl->flush_async() callback to flush the async read/write Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-mhi-ep-flush-v3-1-d855e715264e@oss.qualcomm.com> References: <20260722-mhi-ep-flush-v3-0-d855e715264e@oss.qualcomm.com> In-Reply-To: <20260722-mhi-ep-flush-v3-0-d855e715264e@oss.qualcomm.com> To: Manivannan Sadhasivam , Frank Li , =?utf-8?q?Krzysztof_Wilczy=C5=84ski?= , Kishon Vijay Abraham I , Bjorn Helgaas Cc: linux-kernel@vger.kernel.org, mhi@lists.linux.dev, linux-arm-msm@vger.kernel.org, linux-pci@vger.kernel.org, Manivannan Sadhasivam , stable+noautosel@kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=4161; i=manivannan.sadhasivam@oss.qualcomm.com; h=from:subject:message-id; bh=IkrbWGlEQbOAWg2OT7ZSXhgox1wLJ33VB3lenmrtVfU=; b=owEBbQGS/pANAwAKAVWfEeb+kc71AcsmYgBqYFstS4YEGfK7bEHRXulskXth3Z0HuQ9M++/yg k7gJDJJu/mJATMEAAEKAB0WIQRnpUMqgUjL2KRYJ5dVnxHm/pHO9QUCamBbLQAKCRBVnxHm/pHO 9awgB/9qYahMC116DbL/9d4r9BuLADg1kry3tQmQ2yh5aCX4fcJ8TScMN7HJtNeUH+eCmKgws6D Oef3i+V2BSP3ZKEjcFkHLm1h2E3EHhxZtSzT2JSyI9hRUJgn4pmMnneoiGsJPUakDoB2pyCmwn8 mAzPVfk8qj8CghMJ+0n8CUQxJYhULuJPqwd6LoL1SS6qQ0y1BYbFG2EszaVj5ZKikzvvmkHsFdw S+AsXQxrul5BFUrqTr7BOW65acuAniJPv7/ZfuE7czX0Aob4PgGMsub4auNg3edLeq72ijcDrsW uhgJM4wd/QMi3BAxgGRi2UZKaZ1/rDJK7E8e0IJYH812gfRp X-Developer-Key: i=manivannan.sadhasivam@oss.qualcomm.com; a=openpgp; fpr=C668AEC3C3188E4C611465E7488550E901166008 X-Endpoint-Received: by B4 Relay for manivannan.sadhasivam@oss.qualcomm.com/default with auth_id=461 X-Original-From: Manivannan Sadhasivam Reply-To: manivannan.sadhasivam@oss.qualcomm.com From: Manivannan Sadhasivam MHI EP stack makes use of the MHI controller drivers like MHI EPF to do read/write to the host memory. And that driver is free to use mechanisms like DMA to offload the read/write operations. So if DMA is used for offload, then there is no guarantee that those DMA operations would be completed by the time mhi_ep_remove() gets called. This can lead to UAF (Use-After-Free) issues as the DMA callback can trigger xfer_cb() even after mhi_ep_remove() has returned. So to fix this issue, introduce the mhi_cntrl->flush_async() callback and call it in mhi_ep_remove() to drain all the in-flight async transfers before disconnecting the channels. The completion handlers keep triggering xfer_cb() as long as it is set. So flushing the transfers after notifying the client about the disconnect (-ENOTCONN) would still let a success callback slip through afterwards and lead to the same UAF. So disable the channels first to prevent new transfers, then flush the in-flight transfers so that their completions are delivered while xfer_cb() is still valid and only then notify the disconnect and clear xfer_cb(). Cc: # Needs dmaengine driver fix as well Fixes: 2547beb00ddb ("bus: mhi: ep: Add support for async DMA read operatio= n") Fixes: ee08acb58fe4 ("bus: mhi: ep: Add support for async DMA write operati= on") Signed-off-by: Manivannan Sadhasivam Reviewed-by: Frank Li --- drivers/bus/mhi/ep/main.c | 18 +++++++++++++++++- include/linux/mhi_ep.h | 2 ++ 2 files changed, 19 insertions(+), 1 deletion(-) diff --git a/drivers/bus/mhi/ep/main.c b/drivers/bus/mhi/ep/main.c index 0277e1ab1198..b94c571f01d8 100644 --- a/drivers/bus/mhi/ep/main.c +++ b/drivers/bus/mhi/ep/main.c @@ -1612,6 +1612,7 @@ static void mhi_ep_remove(struct device *dev) { struct mhi_ep_device *mhi_dev =3D to_mhi_ep_device(dev); struct mhi_ep_driver *mhi_drv =3D to_mhi_ep_driver(dev->driver); + struct mhi_ep_cntrl *mhi_cntrl =3D mhi_dev->mhi_cntrl; struct mhi_result result =3D {}; struct mhi_ep_chan *mhi_chan; int dir; @@ -1620,6 +1621,22 @@ static void mhi_ep_remove(struct device *dev) if (mhi_dev->dev_type =3D=3D MHI_DEVICE_CONTROLLER) return; =20 + /* Disable the channels to prevent new transfers */ + for (dir =3D 0; dir < 2; dir++) { + mhi_chan =3D dir ? mhi_dev->ul_chan : mhi_dev->dl_chan; + + if (!mhi_chan) + continue; + + mutex_lock(&mhi_chan->lock); + mhi_chan->state =3D MHI_CH_STATE_DISABLED; + mutex_unlock(&mhi_chan->lock); + } + + /* Flush in-flight transfers before notifying disconnect */ + if (mhi_cntrl->flush_async) + mhi_cntrl->flush_async(mhi_cntrl); + /* Disconnect the channels associated with the driver */ for (dir =3D 0; dir < 2; dir++) { mhi_chan =3D dir ? mhi_dev->ul_chan : mhi_dev->dl_chan; @@ -1635,7 +1652,6 @@ static void mhi_ep_remove(struct device *dev) mhi_chan->xfer_cb(mhi_chan->mhi_dev, &result); } =20 - mhi_chan->state =3D MHI_CH_STATE_DISABLED; mhi_chan->xfer_cb =3D NULL; mutex_unlock(&mhi_chan->lock); } diff --git a/include/linux/mhi_ep.h b/include/linux/mhi_ep.h index 7b40fc8cbe77..f6383a57a872 100644 --- a/include/linux/mhi_ep.h +++ b/include/linux/mhi_ep.h @@ -107,6 +107,7 @@ struct mhi_ep_buf_info { * @write_sync: CB function for writing to host memory synchronously * @read_async: CB function for reading from host memory asynchronously * @write_async: CB function for writing to host memory asynchronously + * @flush_async: CB function for flushing asynchronous read/writes * @mhi_state: MHI Endpoint state * @max_chan: Maximum channels supported by the endpoint controller * @mru: MRU (Maximum Receive Unit) value of the endpoint controller @@ -164,6 +165,7 @@ struct mhi_ep_cntrl { int (*write_sync)(struct mhi_ep_cntrl *mhi_cntrl, struct mhi_ep_buf_info = *buf_info); int (*read_async)(struct mhi_ep_cntrl *mhi_cntrl, struct mhi_ep_buf_info = *buf_info); int (*write_async)(struct mhi_ep_cntrl *mhi_cntrl, struct mhi_ep_buf_info= *buf_info); + void (*flush_async)(struct mhi_ep_cntrl *mhi_cntrl); =20 enum mhi_state mhi_state; =20 --=20 2.43.0 From nobody Fri Jul 24 23:30:48 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4AF812D876F; Wed, 22 Jul 2026 05:54:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784699697; cv=none; b=Au9b2xJkGOmUY+HFkAbVn0ggKnY/EFENm3K+wULL2VcXLPbuyQwoKymcI8+Po+EMCLfVNq6HIRrPfyPh4CStVJ8pF9WWWhOVEfI34aLaU1oE5WY1bLuMLfTjgMhpMcNUbx7ZGOm8anD2pN5tyYEexpVsMlvu/2ahbs0iHV30kh4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784699697; c=relaxed/simple; bh=8ISXVHhswyDJiLXbd9bq0w0gVpCRGbYE2cLAKgLPSUs=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Hpge0HU67F/DuE2WbGiv/zZmTBGFW7yGsMh50xJd2PWyt7LoOAycQwvZTtlppWIkb+25txL9hpbhbRYL3Ck0iv7s4geKYzsJYNaFsUjU1/Yg7dvET4hQ6ZY0doK14QjT/D7uxXSmx+6MKiafA62hECkVoaIxVvvGahtxMymKYuI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=IXobRvag; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="IXobRvag" Received: by smtp.kernel.org (Postfix) with ESMTPS id 0B729C2BCF7; Wed, 22 Jul 2026 05:54:57 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1784699697; bh=8ISXVHhswyDJiLXbd9bq0w0gVpCRGbYE2cLAKgLPSUs=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=IXobRvagSWXHg8OgG9asw/rKXt/J2+uIP9N++yjhwLuoQVQjbykDSYZd4bMtjI72L nwUuR/7sG1eLYzCg2aPxlYUzimIy5tXA8+Uoj8z/7ejrp37N/G2fFLCgaZXboodK0q h58TG5FkXQW8dKEb4GkG6BJ5raUZgQEWY5XavbogcrUOg+eldinlnSrBe3EjIKOv7y vcGWy9Xoml/XtDcubW8Iuvm1s+5auvg8tMSx29AcE3XXG2+IVyTb+Ge+tJOVOpVXnZ YC5yToZwqi0Fmr3eWcnbN3ctnHfDOjbUyPiOF+0p3mN/+X1a4s+Rfc6QPmY4iYCDVi CrVVcVToa5DGQ== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E4960C44512; Wed, 22 Jul 2026 05:54:56 +0000 (UTC) From: Manivannan Sadhasivam via B4 Relay Date: Wed, 22 Jul 2026 07:54:45 +0200 Subject: [PATCH v3 2/3] bus: mhi: ep: Flush async transfers before notifying disconnect in mhi_ep_abort_transfer() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-mhi-ep-flush-v3-2-d855e715264e@oss.qualcomm.com> References: <20260722-mhi-ep-flush-v3-0-d855e715264e@oss.qualcomm.com> In-Reply-To: <20260722-mhi-ep-flush-v3-0-d855e715264e@oss.qualcomm.com> To: Manivannan Sadhasivam , Frank Li , =?utf-8?q?Krzysztof_Wilczy=C5=84ski?= , Kishon Vijay Abraham I , Bjorn Helgaas Cc: linux-kernel@vger.kernel.org, mhi@lists.linux.dev, linux-arm-msm@vger.kernel.org, linux-pci@vger.kernel.org, Manivannan Sadhasivam X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=2946; i=manivannan.sadhasivam@oss.qualcomm.com; h=from:subject:message-id; bh=yYP+ssCeYGN8h3YxfGvLUNdFi6kTstff2HKocV8IchA=; b=owEBbQGS/pANAwAKAVWfEeb+kc71AcsmYgBqYFsuWs6hV/EA0gNZPq6G7FLIVAjdbHcNC87kr 1+V7QAfQg6JATMEAAEKAB0WIQRnpUMqgUjL2KRYJ5dVnxHm/pHO9QUCamBbLgAKCRBVnxHm/pHO 9ep4B/9Z9JoR7B95Sl+cR/qb1BirNG2gugm/gIFZDehEC2drABtPwmU0hgh+/i/fl5mTF4Babmn 00ljcznoLYLuKnRx+q0RBg4W7wxavypisjsdWVsZMm3OTRl37wDPrMset2twIWKXu2+tA7AUj/a zz0B7eJxVFgQt80Mc4p+4YN8I6b2rIqJG/p960ehVIGKPErfa77VqJfG+gFHn5qH1E4+imDcmuc VmG+Cn8RN5X9qsOJ0NNXAr3U6J4sYTzfSpqEG7YM3x8x87iPD/veYqRSgXLO7uRV1/5dA8JKkbt G9dUFWbs29pAoHd+uvHNCwd5V1BLADIcblyOrFTyJejD2Ew2 X-Developer-Key: i=manivannan.sadhasivam@oss.qualcomm.com; a=openpgp; fpr=C668AEC3C3188E4C611465E7488550E901166008 X-Endpoint-Received: by B4 Relay for manivannan.sadhasivam@oss.qualcomm.com/default with auth_id=461 X-Original-From: Manivannan Sadhasivam Reply-To: manivannan.sadhasivam@oss.qualcomm.com From: Manivannan Sadhasivam mhi_ep_abort_transfer() notifies the client drivers about the channel disconnect using -ENOTCONN and only then flushes the ring workqueue to drain the in-flight transfers. But the async DMA transfers issued by the ring workers can still complete after the notification. And the completion handlers trigger the client xfer_cb() as long as it is set. So a transfer completing during the flush can deliver a success callback to the client even after it has been notified about the disconnect. This can lead to UAF (Use-After-Free) issues as the client can free its per-transfer resources in response to the -ENOTCONN notification and the trailing success callback would then reference the freed resources. So to fix this issue, disable all the channels first to prevent new transfers and then drain both the ring workqueue and the in-flight async transfers before notifying the disconnect. The completion and queue paths bail out once the channel state is not MHI_CH_STATE_RUNNING, so disabling the channels upfront makes sure that no new transfer sneaks in during the drain and all the pending completions are delivered while xfer_cb() is still valid. Signed-off-by: Manivannan Sadhasivam Reviewed-by: Frank Li --- drivers/bus/mhi/ep/main.c | 23 +++++++++++++++++------ 1 file changed, 17 insertions(+), 6 deletions(-) diff --git a/drivers/bus/mhi/ep/main.c b/drivers/bus/mhi/ep/main.c index b94c571f01d8..51735f87017f 100644 --- a/drivers/bus/mhi/ep/main.c +++ b/drivers/bus/mhi/ep/main.c @@ -1025,26 +1025,37 @@ static void mhi_ep_abort_transfer(struct mhi_ep_cnt= rl *mhi_cntrl) struct mhi_ep_chan *mhi_chan; int i; =20 - /* Stop all the channels */ + /* Disable all the channels to prevent new transfers */ + for (i =3D 0; i < mhi_cntrl->max_chan; i++) { + mhi_chan =3D &mhi_cntrl->mhi_chan[i]; + if (!mhi_chan->ring.started) + continue; + + mutex_lock(&mhi_chan->lock); + mhi_chan->state =3D MHI_CH_STATE_DISABLED; + mutex_unlock(&mhi_chan->lock); + } + + /* Drain ring workers and in-flight transfers before notifying disconnect= */ + flush_workqueue(mhi_cntrl->wq); + if (mhi_cntrl->flush_async) + mhi_cntrl->flush_async(mhi_cntrl); + + /* Send channel disconnect status to client drivers */ for (i =3D 0; i < mhi_cntrl->max_chan; i++) { mhi_chan =3D &mhi_cntrl->mhi_chan[i]; if (!mhi_chan->ring.started) continue; =20 mutex_lock(&mhi_chan->lock); - /* Send channel disconnect status to client drivers */ if (mhi_chan->xfer_cb) { result.transaction_status =3D -ENOTCONN; result.bytes_xferd =3D 0; mhi_chan->xfer_cb(mhi_chan->mhi_dev, &result); } - - mhi_chan->state =3D MHI_CH_STATE_DISABLED; mutex_unlock(&mhi_chan->lock); } =20 - flush_workqueue(mhi_cntrl->wq); - /* Destroy devices associated with all channels */ device_for_each_child(&mhi_cntrl->mhi_dev->dev, NULL, mhi_ep_destroy_devi= ce); =20 --=20 2.43.0 From nobody Fri Jul 24 23:30:48 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4BFDC2DF12F; Wed, 22 Jul 2026 05:54:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784699697; cv=none; b=WHf/ZPwlgEsnoKz322b2dUWRD1jwHpI+UwqAl282r24xhh4hIUafipFcc/Wvpa2hCferA7Bc7HyXx766EJOvITHrUV4NmsD45LL8KyfE8cxl3LihuI7qlq5QRNTlXpgztY0r0rG8uT32RanNLwk35W4D0rekxXLH31QXSZE1G3g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784699697; c=relaxed/simple; bh=9dEPT3RpH+LXlUxgzUAD8P8587PjPqNLki2jIn6r14s=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Ke512UTPTmz8lpWhV5YhEq1lJULdueIKU3DwPPUkokismhwlXqhhMHaWT+rk11NUThvyZaRFXqB9MuKQ3qXowIqvl2mFNZWV7W9ium9K1faVDCkRdVBYVxZtoywMbLog138o9Z2S0jYZwcztqlUVV/44XvNztZ4elmMhBcLa0Dk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=DA4V31y9; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="DA4V31y9" Received: by smtp.kernel.org (Postfix) with ESMTPS id 1DBAEC2BD01; Wed, 22 Jul 2026 05:54:57 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1784699697; bh=9dEPT3RpH+LXlUxgzUAD8P8587PjPqNLki2jIn6r14s=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=DA4V31y9Jni+rIc7pqc6bkpWwKvbGNXfrL5oPqvrT0u269k0m9QvXO8bl0lEXI2i7 /1Hn/o+XucLjAH5QKohPmzfMdiInj6untyiAwAgDztKPslT/2tAB6J4pViLhJ8Av7D MjKrFpuQ2hezg/veAVG475HhmBubarQ9Wgq8LtiKR2+Wo5Cb4lN9gtZMAyHTXDKwHT 3pVhFFki0FHB2aS/fHBdMnNsXbhNKYSGPPLjhUfDt7u56hPjmW3kD21Jmk/HrIDrbm vHKbVT2pK7cgzMk84WR8C8f1GdVf9onnGoR8fBghcVdZf3Agb6tAU3jVpfKa8r0BVV mewt+yXeFY/kw== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 047F9C44538; Wed, 22 Jul 2026 05:54:57 +0000 (UTC) From: Manivannan Sadhasivam via B4 Relay Date: Wed, 22 Jul 2026 07:54:46 +0200 Subject: [PATCH v3 3/3] PCI: epf-mhi: Implement mhi_cntrl->flush_async() to flush DMA read/write Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-mhi-ep-flush-v3-3-d855e715264e@oss.qualcomm.com> References: <20260722-mhi-ep-flush-v3-0-d855e715264e@oss.qualcomm.com> In-Reply-To: <20260722-mhi-ep-flush-v3-0-d855e715264e@oss.qualcomm.com> To: Manivannan Sadhasivam , Frank Li , =?utf-8?q?Krzysztof_Wilczy=C5=84ski?= , Kishon Vijay Abraham I , Bjorn Helgaas Cc: linux-kernel@vger.kernel.org, mhi@lists.linux.dev, linux-arm-msm@vger.kernel.org, linux-pci@vger.kernel.org, Manivannan Sadhasivam X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=1534; i=manivannan.sadhasivam@oss.qualcomm.com; h=from:subject:message-id; bh=qLqfbvmjnz3X26mpqAuThVFaSvP9MX15HVPTE+SgzCA=; b=owEBbQGS/pANAwAKAVWfEeb+kc71AcsmYgBqYFsuC5PTByf4wCyyQefH6+dH7fRf88dhESowk g8bnZx4gV2JATMEAAEKAB0WIQRnpUMqgUjL2KRYJ5dVnxHm/pHO9QUCamBbLgAKCRBVnxHm/pHO 9fPIB/4tKg/A7Sh52QXah2k7JDw+eLTsYikqwlLXwhDPptp7RQX/qFLQ0DgVysZpfZcZckmyA5S 6nk5qorgHBaBKqaxK11czAOEyCLCce/g3WU8L509g6PdgKAol0YiwIMHH9zzJ7b2f7RhDD8w/UE M3RxgU+XEGTL1eQ5t6BCrVQwHYFcHI3OBxVtWVCgmr/OveC5cBafP/aMBEJm/fWBLgE0X/8RX8m 1HyCQqzKl5hMoqMOendaQvux0lpehBvwm3EJDuXfSKtuUqQ7wmTnKyqxKXYaReRxSChlkFfV3xu lcOSlcIn4g9ayftzxSN8PAH5hgasKJR+jImIlazUaMicwUJk X-Developer-Key: i=manivannan.sadhasivam@oss.qualcomm.com; a=openpgp; fpr=C668AEC3C3188E4C611465E7488550E901166008 X-Endpoint-Received: by B4 Relay for manivannan.sadhasivam@oss.qualcomm.com/default with auth_id=461 X-Original-From: Manivannan Sadhasivam Reply-To: manivannan.sadhasivam@oss.qualcomm.com From: Manivannan Sadhasivam The MHI core needs to make sure that all the current DMA transactions are completed before removing the channels. So implement the mhi_cntrl->flush_async() callback by first making sure all the in-flight DMA operations are completed and then flushing the DMA workqueue. Signed-off-by: Manivannan Sadhasivam Reviewed-by: Frank Li --- drivers/pci/endpoint/functions/pci-epf-mhi.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/drivers/pci/endpoint/functions/pci-epf-mhi.c b/drivers/pci/end= point/functions/pci-epf-mhi.c index 7f5326925ed5..8d2d9d01cfd2 100644 --- a/drivers/pci/endpoint/functions/pci-epf-mhi.c +++ b/drivers/pci/endpoint/functions/pci-epf-mhi.c @@ -644,6 +644,15 @@ static int pci_epf_mhi_edma_write_async(struct mhi_ep_= cntrl *mhi_cntrl, return ret; } =20 +static void pci_epf_mhi_edma_flush_async(struct mhi_ep_cntrl *mhi_cntrl) +{ + struct pci_epf_mhi *epf_mhi =3D to_epf_mhi(mhi_cntrl); + + dmaengine_synchronize(epf_mhi->dma_chan_rx); + dmaengine_synchronize(epf_mhi->dma_chan_tx); + flush_workqueue(epf_mhi->dma_wq); +} + struct epf_dma_filter { struct device *dev; u32 dma_mask; @@ -812,6 +821,7 @@ static int pci_epf_mhi_link_up(struct pci_epf *epf) mhi_cntrl->write_sync =3D pci_epf_mhi_edma_write; mhi_cntrl->read_async =3D pci_epf_mhi_edma_read_async; mhi_cntrl->write_async =3D pci_epf_mhi_edma_write_async; + mhi_cntrl->flush_async =3D pci_epf_mhi_edma_flush_async; } =20 /* Register the MHI EP controller */ --=20 2.43.0