From nobody Fri Oct 2 13:04:16 2026 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E1EC33B14D0 for ; Fri, 31 Jul 2026 09:32:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785490350; cv=none; b=JxO+tLy6/JpTO0pf3a/fExsJHGlfDYY2HVHWUtI0xYmsqBnpwr3DHKKw0kS5EvSi8BcHzuoa09PZBWI/ZbHe/l02UigTBNXcvGtoP7NzJPgohqosj8j3Aiwc9NIOmjX/1XWGQCWsByWYUBCbZpG1onkNcrY+I4VXoHqF4+A5Q7A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785490350; c=relaxed/simple; bh=kOAz2k/oJSKynmJYRQ2cCzpmWDdbhzZJA4UBO3BVAd0=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=p65y427KEVDTgkYYsK0CUiu6WuWFBBMnUf7pTahMI6RPN3Mx7N4d2dwlbvZ+IH7bQlNvbcPrORXc1wzOd6QL60NO9bjJvEjb3PShTp1xPIPWMyL7ElTC7C1aN1+HIeRBeYoWm9cWK8JWitQY38hcVMpQOubPlPpnKFqE7Q5JgeI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=CMmx1NUm; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=KjBXnyBE; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="CMmx1NUm"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="KjBXnyBE" Received: from pps.filterd (m0279870.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66V8dmdr3645890 for ; Fri, 31 Jul 2026 09:32:19 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:date:from:message-id:mime-version :subject:to; s=qcppdkim1; bh=wUbHtxRx1UaykzKn9/78x3dxb6CH/2YkVI6 E2YLTXV8=; b=CMmx1NUmKE6qtZuHyowodg4iRF/Hn5XtQkvpX00+wLiVNeg32iU avNscTpkK+JrWKVzEHzshg9VqQwnsxbO1a4h9njJQuVrmA2iVJr6jZQs9dwAHji/ 3P5e3h9uCtlIs2SOZ0z2o3tUAfF/yecsKbAo1maMGkRN2b2F413WY7uE+SNDbQHz i31GrOcGU5XVtM0lm7DntI6yNdodMCdmRSSKJwUOe/7qPcy/frFfdLSD/pvCUKfr 0adlja/wIYtGR65Wbi/PrSmbukwQmtwjWFUqPdQbNa3ay8R/O/6/e0lS5QZGqckY Eabp0Fngrol2ynUFhtVs6gDKrrbYtmWLjcA== Received: from mail-pf1-f198.google.com (mail-pf1-f198.google.com [209.85.210.198]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4frrd3r78j-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Fri, 31 Jul 2026 09:32:19 +0000 (GMT) Received: by mail-pf1-f198.google.com with SMTP id d2e1a72fcca58-84a251c2e3eso2393017b3a.1 for ; Fri, 31 Jul 2026 02:32:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1785490338; x=1786095138; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=wUbHtxRx1UaykzKn9/78x3dxb6CH/2YkVI6E2YLTXV8=; b=KjBXnyBEATHoHUlSe9b8JGTXMAEd/iZ4Xd/XZmdtgEksA1duoPX1JJLFMwD0h/d6mE wQuBmD7K9ad1McXZlJ/lrVVQTLBqKo0N0SopTr7UHYb0EQYq7VSnFjrroxuV0TeNPDxN Di9/WAncrVaKBDvCMh1iOk+Aq8kUyra918huCn6H9k/PjvqEdSpvdnBwP6/113JOUo9E EfnLPxBiz/Eczpg5bgCQmbJxiwaHr19yVw1zkGbzl9lNRVSGiLKZl2WIN7c6yCN8Me7H DVQ9K8WjN1uThZUW+fYerTP6IcjxDohJuMOTKTcmW61xPN9XtJq2+sElamYQmybmXloa fEvQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785490338; x=1786095138; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=wUbHtxRx1UaykzKn9/78x3dxb6CH/2YkVI6E2YLTXV8=; b=BH1EGKFPvy3neddoGbYIPNXOqjktq9YelHW+6ZZGEXzDm3TzlAK+yxjYOh6hFe/O/A Ri8g/oM+GOPL8NIV+BUsjF5R0Zdsz0PXl37yjkoQCrdc0aIFHAVV3ck7GuM57+IFEZAV Ocx/dNLxuG9IhmDVwkGWYr29AGAjcVIP24ZsCdsKGoFPyAZkZ+e+Ic83tRlDXHaHI2Af 90HwtysRJkOurjcZbhBtQO+u9D0kz93wBZQQZWfgSc7qQRjwm+/ldGD2/XjSL48ymylX i5T027JYZV/ULfw+k+UzVQ2fguvI16cCM4dlcnL9RegTso9iADcru8gB3zfM1zOnmCEW 1b1A== X-Forwarded-Encrypted: i=1; AHgh+RpSGQUQ+qa00Kzmh5Ze4YFC2JkHjJsxnRIl5HWvMTFeJgWGQbTwAAvA9ciPkks5qgrnRAQCQIXItbjWkIs=@vger.kernel.org X-Gm-Message-State: AOJu0YxN7a4QGTHqfctRGxlmsuiox7/SHMrtR278AeBVeND8yJ6Epj9l ZDB7OJA095G7AfL5FCZPJe09wMX/4Y3QUm6q5PDli2vrDBRpBldd6bjt7WQDDRYek9o2/GC7zcG /03bw5UdH3Zr7Hzi7lAAjCX3BRhJ3H/EWGdN0Jnnmcf8Q1bKni/INeK1CDBtQZXWOHsY= X-Gm-Gg: AR+sD10nDNDx42MBTsKT/0AJR6X5fPMIwILcPLpeYgMVNMsjsTxoidwqsGuuHRz6wjF GZwrNxpUZ9vvxEGzG3iLUtZdbLYJmPAMjBeAcSTniyhYE+2aQJSX2pa75IIB8hjB8OcAnS3EEJd dpDunfY6BmgcIH/9ArK5MVb4PoaxYdUKBhHX/jQ1oEsIBLt7OTOBHQGT6CY+7aFMtrkulXsnI3Z p92NKRjPy80GaFk963lcSdHaFujLe1+oMkI6CGxeBaEUGQdraQv+Mfp/rbXkNOnP6/3JnBJVEwd +fCMNl765if7Rcm0ZrjovBLGLNTDWLG1o86jrLqrcHDCC3AgAdWr/PHkdTdF3q0t98m/EDIKQGX V/iNSb5TO7tz1SgLddHDI4Uw1mFFDLeozR/pUlYxyCrEIC3SPACHfRcLhRAp9pjhdChQHItatxw == X-Received: by 2002:a05:6a00:35cd:b0:82f:51e8:b38e with SMTP id d2e1a72fcca58-84ed7483bc7mr1020527b3a.24.1785490338088; Fri, 31 Jul 2026 02:32:18 -0700 (PDT) X-Received: by 2002:a05:6a00:35cd:b0:82f:51e8:b38e with SMTP id d2e1a72fcca58-84ed7483bc7mr1020497b3a.24.1785490337392; Fri, 31 Jul 2026 02:32:17 -0700 (PDT) Received: from QCOM-SocCW5bzXR.qualcomm.com (tpe-colo-wan-fw-bordernet.qualcomm.com. [103.229.16.4]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cbe3963ddc3sm340155a12.7.2026.07.31.02.32.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Jul 2026 02:32:16 -0700 (PDT) From: Jianping Li To: Srinivas Kandagatla , Ekansh Gupta Cc: Jianping Li , Arnd Bergmann , Greg Kroah-Hartman , Abel Vesa , linux-arm-msm@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, quic_chennak@quicinc.com, stable@kernel.org Subject: [PATCH v11] misc: fastrpc: Allocate entire reserved memory for Audio PD in probe Date: Fri, 31 Jul 2026 17:32:10 +0800 Message-Id: <20260731093210.473-1-jianping.li@oss.qualcomm.com> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Proofpoint-GUID: e_FFvd8P-v1PaJ9chgrrT8IDZ5cbjWXY X-Proofpoint-Spam-Info: AW1haW4tMjYwNzMxMDA3MCBTYWx0ZWRfX5x4t7a25vEnx of4agazVUyEyrYiId88gFfxluQU/R6fS6a9Yfm48j/gGWbM4S0Ph5rl785WgO44MZ42aqjWIVGr NPbFy70Ww/XIwq7WqrkEodnF4HUMORs= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzMxMDA3MCBTYWx0ZWRfX8CczNBP/HNnN +12lxQ8VfgHT/CpleGwQByXycBIivQaM0gtA4Zt0jR690d7IGbkjWoo0AzM9k8k6jY1XBJpdNRM JkxQnFomrXGRjIHHv/vrdn7sX0hQkCxlKYpx+m3bFdUPFOgf+a8yttDiHEbl4NrnQiSNHjsrKnD y0MIf9kFmZpjw3BP3P0I/y1zZC7KnnBqikkVBX7iMBjhgQQN5P9mzjetCUs/xVjhY8NyKWW2SvE Mn4WKMUbGe8RtIMqCh18Zg7GTm0p2XONGW/F8CuyGCb0NlsC3scws6ZQEKBI85L8xmXMUlS9zwr ksYMLRtzozXJtkIFLc9ZkTTNNC2hUdSn5Z/A0KcRyFIK1ZVjBrzfklI5AQQgOEu7bOfdyeK1/pn KJbD/92iouQ8TSx98dqrtX1IK3X2EV9BPGzToO2rWsl/pm6rrtEBouOCk2QYZRwDQcdvj9w6r1b 33MqHh9LVbyi96vdFGw== X-Proofpoint-ORIG-GUID: e_FFvd8P-v1PaJ9chgrrT8IDZ5cbjWXY X-Authority-Analysis: v=2.4 cv=fPIJG5ae c=1 sm=1 tr=0 ts=6a6c6ba3 cx=c_pps a=m5Vt/hrsBiPMCU0y4gIsQw==:117 a=nuhDOHQX5FNHPW3J6Bj6AA==:17 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=gowsoOTTUOVcmtlkKump:22 a=VwQbUJbxAAAA:8 a=EUspDBNiAAAA:8 a=yegpaEAI8PfkSgOXudcA:9 a=IoOABgeZipijB_acs4fv:22 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-31_03,2026-07-30_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 malwarescore=0 priorityscore=1501 suspectscore=0 spamscore=0 lowpriorityscore=0 bulkscore=0 clxscore=1015 impostorscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607310070 Content-Type: text/plain; charset="utf-8" Allocating and freeing Audio PD memory from userspace is unsafe because the kernel cannot reliably determine when the DSP has finished using the memory. Userspace may free buffers while they are still in use by the DSP, and remote free requests cannot be safely trusted. Additionally, the current implementation allows userspace to repeatedly grow the Audio PD heap, but does not support shrinking it. This can lead to unbounded memory usage over time, effectively causing a memory leak. Fix this by allocating the entire Audio PD reserved-memory region during rpmsg probe and tying its lifetime to the rpmsg channel. This removes userspace-controlled alloc/free and ensures that memory is reclaimed only when the DSP process is torn down. Validate the presence of the Audio PD reserved-memory region during rpmsg probe and fail early if it is missing, so that a misconfigured device tree is caught at probe time instead of at process creation. Fixes: 0871561055e66 ("misc: fastrpc: Add support for audiopd") Cc: stable@kernel.org Signed-off-by: Jianping Li Patch [v10]: https://lore.kernel.org/all/20260716095847.479-1-jianping.li@o= ss.qualcomm.com/ Changes in v11: - Replace the remote_heap fastrpc_buf pointer with dedicated remote_heap_addr and remote_heap_size fields in fastrpc_channel_ctx to avoid leaving a partially initialized fastrpc_buf. - Drop ADSP_MMAP_REMOTE_HEAP_ADDR support from fastrpc_req_mmap() since the user process should no longer grow or shrink the Audio PD remote heap. Changes in v10: - Move Audio PD remote heap validation into fastrpc_rpmsg_probe(). - Treat Audio PD remote heap as a mandatory resource and fail probe if the reserved memory region is missing. Changes in v9: - Make sure fastrpc_init_create_static_process() only sets audio_init_mem to false when the sent address is actually invalid. --- drivers/misc/fastrpc.c | 137 +++++++++++++++++++---------------------- 1 file changed, 63 insertions(+), 74 deletions(-) diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c index dd51d475a74e..e054e80584a2 100644 --- a/drivers/misc/fastrpc.c +++ b/drivers/misc/fastrpc.c @@ -70,8 +70,6 @@ #define ADSP_MMAP_HEAP_ADDR 4 /* MAP static DMA buffer on DSP User PD */ #define ADSP_MMAP_DMA_BUFFER 6 -/* Add memory to static PD pool protection thru hypervisor */ -#define ADSP_MMAP_REMOTE_HEAP_ADDR 8 /* Add memory to userPD pool, for user heap */ #define ADSP_MMAP_ADD_PAGES 0x1000 /* Add memory to userPD pool, for LLC heap */ @@ -314,10 +312,14 @@ struct fastrpc_channel_ctx { struct kref refcount; /* Flag if dsp attributes are cached */ bool valid_attributes; + /* Flag if audio PD init mem was allocated */ + bool audio_init_mem; + /* Audio PD reserved remote heap region */ + phys_addr_t remote_heap_addr; + u64 remote_heap_size; u32 dsp_attributes[FASTRPC_MAX_DSP_ATTRIBUTES]; struct fastrpc_device *secure_fdevice; struct fastrpc_device *fdevice; - struct fastrpc_buf *remote_heap; struct list_head invoke_interrupted_mmaps; bool secure; bool unsigned_support; @@ -1454,15 +1456,17 @@ static int fastrpc_init_create_static_process(struc= t fastrpc_user *fl, struct fastrpc_init_create_static init; struct fastrpc_invoke_args *args; struct fastrpc_phy_page pages[1]; + struct fastrpc_channel_ctx *cctx =3D fl->cctx; char *name; int err; - bool scm_done =3D false; struct { int client_id; u32 namelen; u32 pageslen; } inbuf; u32 sc; + unsigned long flags; + bool sent_heap =3D false; =20 args =3D kzalloc_objs(*args, FASTRPC_CREATE_STATIC_PROCESS_NARGS); if (!args) @@ -1486,31 +1490,6 @@ static int fastrpc_init_create_static_process(struct= fastrpc_user *fl, inbuf.client_id =3D fl->client_id; inbuf.namelen =3D init.namelen; inbuf.pageslen =3D 0; - if (!fl->cctx->remote_heap) { - err =3D fastrpc_remote_heap_alloc(fl, fl->sctx->dev, init.memlen, - &fl->cctx->remote_heap); - if (err) - goto err_name; - - /* Map if we have any heap VMIDs associated with this ADSP Static Proces= s. */ - if (fl->cctx->vmcount) { - u64 src_perms =3D BIT(QCOM_SCM_VMID_HLOS); - - err =3D qcom_scm_assign_mem(fl->cctx->remote_heap->dma_addr, - (u64)fl->cctx->remote_heap->size, - &src_perms, - fl->cctx->vmperms, fl->cctx->vmcount); - if (err) { - dev_err(fl->sctx->dev, - "Failed to assign memory with dma_addr %pad size 0x%llx err %d\n", - &fl->cctx->remote_heap->dma_addr, - fl->cctx->remote_heap->size, err); - goto err_map; - } - scm_done =3D true; - inbuf.pageslen =3D 1; - } - } =20 fl->pd =3D USER_PD; =20 @@ -1522,8 +1501,25 @@ static int fastrpc_init_create_static_process(struct= fastrpc_user *fl, args[1].length =3D inbuf.namelen; args[1].fd =3D -1; =20 - pages[0].addr =3D fl->cctx->remote_heap->dma_addr; - pages[0].size =3D fl->cctx->remote_heap->size; + /* + * Audio PD is a static PD and retains the remote heap + * information across daemon restarts. Therefore only + * the first attach should provide heap information to + * DSP. Subsequent attaches reuse the previously + * initialized memory pool. + */ + spin_lock_irqsave(&cctx->lock, flags); + if (!cctx->audio_init_mem) { + pages[0].addr =3D cctx->remote_heap_addr; + pages[0].size =3D cctx->remote_heap_size; + cctx->audio_init_mem =3D true; + inbuf.pageslen =3D 1; + sent_heap =3D true; + } else { + pages[0].addr =3D 0; + pages[0].size =3D 0; + } + spin_unlock_irqrestore(&cctx->lock, flags); =20 args[2].ptr =3D (u64)(uintptr_t) pages; args[2].length =3D sizeof(*pages); @@ -1541,27 +1537,11 @@ static int fastrpc_init_create_static_process(struc= t fastrpc_user *fl, =20 return 0; err_invoke: - if (fl->cctx->vmcount && scm_done) { - u64 src_perms =3D 0; - struct qcom_scm_vmperm dst_perms; - u32 i; - - for (i =3D 0; i < fl->cctx->vmcount; i++) - src_perms |=3D BIT(fl->cctx->vmperms[i].vmid); - - dst_perms.vmid =3D QCOM_SCM_VMID_HLOS; - dst_perms.perm =3D QCOM_SCM_PERM_RWX; - err =3D qcom_scm_assign_mem(fl->cctx->remote_heap->dma_addr, - (u64)fl->cctx->remote_heap->size, - &src_perms, &dst_perms, 1); - if (err) - dev_err(fl->sctx->dev, "Failed to assign memory dma_addr %pad size 0x%l= lx err %d\n", - &fl->cctx->remote_heap->dma_addr, fl->cctx->remote_heap->size, err); + if (sent_heap) { + spin_lock_irqsave(&cctx->lock, flags); + cctx->audio_init_mem =3D false; + spin_unlock_irqrestore(&cctx->lock, flags); } -err_map: - fastrpc_buf_free(fl->cctx->remote_heap); - fl->cctx->remote_heap =3D NULL; -err_name: kfree(name); err: kfree(args); @@ -2090,7 +2070,7 @@ static int fastrpc_req_mmap(struct fastrpc_user *fl, = char __user *argp) if (copy_from_user(&req, argp, sizeof(req))) return -EFAULT; =20 - if (req.flags !=3D ADSP_MMAP_ADD_PAGES && req.flags !=3D ADSP_MMAP_REMOTE= _HEAP_ADDR) { + if (req.flags !=3D ADSP_MMAP_ADD_PAGES) { dev_err(dev, "flag not supported 0x%x\n", req.flags); =20 return -EINVAL; @@ -2101,10 +2081,7 @@ static int fastrpc_req_mmap(struct fastrpc_user *fl,= char __user *argp) return -EINVAL; } =20 - if (req.flags =3D=3D ADSP_MMAP_REMOTE_HEAP_ADDR) - err =3D fastrpc_remote_heap_alloc(fl, dev, req.size, &buf); - else - err =3D fastrpc_buf_alloc(fl, dev, req.size, &buf); + err =3D fastrpc_buf_alloc(fl, dev, req.size, &buf); =20 if (err) { dev_err(dev, "failed to allocate buffer\n"); @@ -2143,20 +2120,6 @@ static int fastrpc_req_mmap(struct fastrpc_user *fl,= char __user *argp) /* let the client know the address to use */ req.vaddrout =3D rsp_msg.vaddr; =20 - /* Add memory to static PD pool, protection thru hypervisor */ - if (req.flags =3D=3D ADSP_MMAP_REMOTE_HEAP_ADDR && fl->cctx->vmcount) { - u64 src_perms =3D BIT(QCOM_SCM_VMID_HLOS); - - err =3D qcom_scm_assign_mem(buf->dma_addr, (u64)buf->size, - &src_perms, fl->cctx->vmperms, fl->cctx->vmcount); - if (err) { - dev_err(fl->sctx->dev, - "Failed to assign memory dma_addr %pad size 0x%llx err %d", - &buf->dma_addr, buf->size, err); - goto err_assign; - } - } - spin_lock(&fl->lock); list_add_tail(&buf->node, &fl->mmaps); spin_unlock(&fl->lock); @@ -2584,12 +2547,22 @@ static int fastrpc_rpmsg_probe(struct rpmsg_device = *rpdev) } } =20 - if (domain_id =3D=3D SDSP_DOMAIN_ID) { + if (domain_id =3D=3D SDSP_DOMAIN_ID || domain_id =3D=3D ADSP_DOMAIN_ID) { struct resource res; u64 src_perms; =20 err =3D of_reserved_mem_region_to_resource(rdev->of_node, 0, &res); + + if (err && domain_id =3D=3D ADSP_DOMAIN_ID) { + dev_err(rdev, "missing mandatory remote heap memory-region\n"); + goto err_free_data; + } + if (!err) { + if (domain_id =3D=3D ADSP_DOMAIN_ID) { + data->remote_heap_addr =3D res.start; + data->remote_heap_size =3D resource_size(&res); + } src_perms =3D BIT(QCOM_SCM_VMID_HLOS); =20 err =3D qcom_scm_assign_mem(res.start, resource_size(&res), &src_perms, @@ -2597,7 +2570,6 @@ static int fastrpc_rpmsg_probe(struct rpmsg_device *r= pdev) if (err) goto err_free_data; } - } =20 secure_dsp =3D !(of_property_read_bool(rdev->of_node, "qcom,non-secure-do= main")); @@ -2681,6 +2653,7 @@ static void fastrpc_rpmsg_remove(struct rpmsg_device = *rpdev) struct fastrpc_buf *buf, *b; struct fastrpc_user *user; unsigned long flags; + int err, i; =20 /* No invocations past this point */ spin_lock_irqsave(&cctx->lock, flags); @@ -2698,8 +2671,24 @@ static void fastrpc_rpmsg_remove(struct rpmsg_device= *rpdev) list_for_each_entry_safe(buf, b, &cctx->invoke_interrupted_mmaps, node) list_del(&buf->node); =20 - if (cctx->remote_heap) - fastrpc_buf_free(cctx->remote_heap); + if (cctx->remote_heap_size && cctx->vmcount) { + u64 src_perms =3D 0; + struct qcom_scm_vmperm dst_perms; + + for (i =3D 0; i < cctx->vmcount; i++) + src_perms |=3D BIT(cctx->vmperms[i].vmid); + + dst_perms.vmid =3D QCOM_SCM_VMID_HLOS; + dst_perms.perm =3D QCOM_SCM_PERM_RWX; + + err =3D qcom_scm_assign_mem(cctx->remote_heap_addr, + cctx->remote_heap_size, &src_perms, + &dst_perms, 1); + if (err) + dev_err(&rpdev->dev, + "Failed to assign memory back to HLOS: addr %pa size %#llx err %d\n", + &cctx->remote_heap_addr, cctx->remote_heap_size, err); + } =20 of_platform_depopulate(&rpdev->dev); =20 --=20 2.43.0