From: Srinivas Kandagatla <srini@kernel.org>
Hi Greg,
This series collects a handful of fastrpc fixes that have accumulated on
the list. All patches are small, target long-standing issues, and are
tagged for stable.
The fixes fall into two buckets:
Memory leaks:
- Audio PD memory pool never registered its initial buffer because
pageslen was left at zero, so the pool was always empty and every
allocation fell back to the remote heap (patch 1).
- fastrpc_device_open() takes a channel ctx reference before allocating
a session; the -EBUSY path on session-alloc failure never dropped it
(patch 4).
- fastrpc_channel_ctx_free() never destroyed ctx_idr, leaking the IDR
backing storage on channel teardown (patch 5).
Locking / list corruption:
- fastrpc_req_munmap() removed the buffer from fl->mmaps only after the
DSP unmap returned, allowing two concurrent unmaps to race on the
same entry. Detach the buffer under fl->lock first and re-add it if
the DSP call fails (patch 2).
- The -ERESTARTSYS path in fastrpc_internal_invoke() walked fl->mmaps
and spliced it onto cctx->invoke_interrupted_mmaps without holding
fl->lock, racing with every other mmaps accessor (patch 3).
Please queue for 7.2.
Thanks,
Srini
Anandu Krishnan E (1):
misc: fastrpc: fix channel ctx ref leak when session alloc fails
Eddie Lin (1):
misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free
Ekansh Gupta (2):
misc: fastrpc: Fix initial memory allocation for Audio PD memory pool
misc: fastrpc: Remove buffer from list prior to unmap operation
Junrui Luo (1):
misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke
drivers/misc/fastrpc.c | 27 ++++++++++++++++++---------
1 file changed, 18 insertions(+), 9 deletions(-)
--
2.53.0