Skip to content

Commit b10e064

Browse files
abelvesagregkh
authored andcommitted
misc: fastrpc: Rework fastrpc_req_munmap
[ Upstream commit 72fa6f7 ] Move the lookup of the munmap request to the fastrpc_req_munmap and pass on only the buf to the lower level fastrpc_req_munmap_impl. That way we can use the lower level fastrpc_req_munmap_impl on error path in fastrpc_req_mmap to free the buf without searching for the munmap request it belongs to. Co-developed-by: Srinivas Kandagatla <srinivas.kandagatla@linaro.org> Signed-off-by: Abel Vesa <abel.vesa@linaro.org> Signed-off-by: Srinivas Kandagatla <srinivas.kandagatla@linaro.org> Link: https://lore.kernel.org/r/20221125071405.148786-7-srinivas.kandagatla@linaro.org Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Stable-dep-of: 6102ceb ("misc: fastrpc: Remove buffer from list prior to unmap operation") Signed-off-by: Sasha Levin <sashal@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 75d593f commit b10e064

1 file changed

Lines changed: 25 additions & 27 deletions

File tree

‎drivers/misc/fastrpc.c‎

Lines changed: 25 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -1389,30 +1389,14 @@ static int fastrpc_invoke(struct fastrpc_user *fl, char __user *argp)
13891389
return err;
13901390
}
13911391

1392-
static int fastrpc_req_munmap_impl(struct fastrpc_user *fl,
1393-
struct fastrpc_req_munmap *req)
1392+
static int fastrpc_req_munmap_impl(struct fastrpc_user *fl, struct fastrpc_buf *buf)
13941393
{
13951394
struct fastrpc_invoke_args args[1] = { [0] = { 0 } };
1396-
struct fastrpc_buf *buf = NULL, *iter, *b;
13971395
struct fastrpc_munmap_req_msg req_msg;
13981396
struct device *dev = fl->sctx->dev;
13991397
int err;
14001398
u32 sc;
14011399

1402-
spin_lock(&fl->lock);
1403-
list_for_each_entry_safe(iter, b, &fl->mmaps, node) {
1404-
if ((iter->raddr == req->vaddrout) && (iter->size == req->size)) {
1405-
buf = iter;
1406-
break;
1407-
}
1408-
}
1409-
spin_unlock(&fl->lock);
1410-
1411-
if (!buf) {
1412-
dev_err(dev, "mmap not in list\n");
1413-
return -EINVAL;
1414-
}
1415-
14161400
req_msg.pgid = fl->tgid;
14171401
req_msg.size = buf->size;
14181402
req_msg.vaddr = buf->raddr;
@@ -1438,12 +1422,29 @@ static int fastrpc_req_munmap_impl(struct fastrpc_user *fl,
14381422

14391423
static int fastrpc_req_munmap(struct fastrpc_user *fl, char __user *argp)
14401424
{
1425+
struct fastrpc_buf *buf = NULL, *iter, *b;
14411426
struct fastrpc_req_munmap req;
1427+
struct device *dev = fl->sctx->dev;
14421428

14431429
if (copy_from_user(&req, argp, sizeof(req)))
14441430
return -EFAULT;
14451431

1446-
return fastrpc_req_munmap_impl(fl, &req);
1432+
spin_lock(&fl->lock);
1433+
list_for_each_entry_safe(iter, b, &fl->mmaps, node) {
1434+
if ((iter->raddr == req.vaddrout) && (iter->size == req.size)) {
1435+
buf = iter;
1436+
break;
1437+
}
1438+
}
1439+
spin_unlock(&fl->lock);
1440+
1441+
if (!buf) {
1442+
dev_err(dev, "mmap\t\tpt 0x%09llx [len 0x%08llx] not in list\n",
1443+
req.vaddrout, req.size);
1444+
return -EINVAL;
1445+
}
1446+
1447+
return fastrpc_req_munmap_impl(fl, buf);
14471448
}
14481449

14491450
static int fastrpc_req_mmap(struct fastrpc_user *fl, char __user *argp)
@@ -1452,7 +1453,6 @@ static int fastrpc_req_mmap(struct fastrpc_user *fl, char __user *argp)
14521453
struct fastrpc_buf *buf = NULL;
14531454
struct fastrpc_mmap_req_msg req_msg;
14541455
struct fastrpc_mmap_rsp_msg rsp_msg;
1455-
struct fastrpc_req_munmap req_unmap;
14561456
struct fastrpc_phy_page pages;
14571457
struct fastrpc_req_mmap req;
14581458
struct device *dev = fl->sctx->dev;
@@ -1500,7 +1500,8 @@ static int fastrpc_req_mmap(struct fastrpc_user *fl, char __user *argp)
15001500
&args[0]);
15011501
if (err) {
15021502
dev_err(dev, "mmap error (len 0x%08llx)\n", buf->size);
1503-
goto err_invoke;
1503+
fastrpc_buf_free(buf);
1504+
return err;
15041505
}
15051506

15061507
/* update the buffer to be able to deallocate the memory on the DSP */
@@ -1514,20 +1515,17 @@ static int fastrpc_req_mmap(struct fastrpc_user *fl, char __user *argp)
15141515
spin_unlock(&fl->lock);
15151516

15161517
if (copy_to_user((void __user *)argp, &req, sizeof(req))) {
1517-
/* unmap the memory and release the buffer */
1518-
req_unmap.vaddrout = buf->raddr;
1519-
req_unmap.size = buf->size;
1520-
fastrpc_req_munmap_impl(fl, &req_unmap);
1521-
return -EFAULT;
1518+
err = -EFAULT;
1519+
goto err_assign;
15221520
}
15231521

15241522
dev_dbg(dev, "mmap\t\tpt 0x%09lx OK [len 0x%08llx]\n",
15251523
buf->raddr, buf->size);
15261524

15271525
return 0;
15281526

1529-
err_invoke:
1530-
fastrpc_buf_free(buf);
1527+
err_assign:
1528+
fastrpc_req_munmap_impl(fl, buf);
15311529

15321530
return err;
15331531
}

0 commit comments

Comments
 (0)