Merge "drivers: mailbox: fix race resulting in multiple message submission"

This commit is contained in:
qctecmdr 2019-08-16 18:44:15 -07:00 • committed by Gerrit - the friendly Code Review server
commit 2d6d5ac694
4 changed files with 143 additions and 1 deletions

View file

@ -50,7 +50,7 @@ static int add_to_rbuf(struct mbox_chan *chan, void *mssg)
return idx;
}
static void msg_submit(struct mbox_chan *chan)
static int __msg_submit(struct mbox_chan *chan)
{
unsigned count, idx;
unsigned long flags;
@ -82,6 +82,24 @@ static void msg_submit(struct mbox_chan *chan)
exit:
spin_unlock_irqrestore(&chan->lock, flags);
return err;
}
static void msg_submit(struct mbox_chan *chan)
{
int err = 0;
/*
* If the controller returns -EAGAIN, then it means, our spinlock
* here is preventing the controller from receiving its interrupt,
* that would help clear the controller channels that are currently
* blocked waiting on the interrupt response.
* Retry again.
*/
do {
err = __msg_submit(chan);
} while (err == -EAGAIN);
if (!err && (chan->txdone_method & TXDONE_BY_POLL))
/* kick start the timer immediately to avoid delays */
hrtimer_start(&chan->mbox->poll_hrt, 0, HRTIMER_MODE_REL);

View file

@ -229,4 +229,13 @@ config QCOM_SECURE_BUFFER
memory buffers. This ensures that only the correct clients can
use this memory and no unauthorized access is made to the
buffer.
config QMP_DEBUGFS_CLIENT
bool "Debugfs Client to communicate with AOP using QMP protocol"
depends on DEBUG_FS
help
This options enables a driver which allows clients to send messages
to Alway On processor using QMP transport. Users can echo a message
into an exposed debugfs node to send to AOP. The driver expects the
passed in string argument to be formatted correctly for AOP to read.
endmenu

View file

@ -29,3 +29,4 @@ obj-$(CONFIG_QCOM_LAHAINA_LLCC) += llcc-lahaina.o
obj-$(CONFIG_QCOM_SDM845_LLCC) += llcc-sdm845.o
obj-$(CONFIG_QCOM_RPMHPD) += rpmhpd.o
obj-$(CONFIG_QCOM_RPMPD) += rpmpd.o
obj-$(CONFIG_QMP_DEBUGFS_CLIENT) += qmp-debugfs-client.o

View file

@ -0,0 +1,114 @@
// SPDX-License-Identifier: GPL-2.0-only
/* Copyright (c) 2017-2019, The Linux Foundation. All rights reserved. */
#include <linux/module.h>
#include <linux/kernel.h>
#include <linux/init.h>
#include <linux/mailbox_client.h>
#include <linux/seq_file.h>
#include <linux/debugfs.h>
#include <linux/platform_device.h>
#include <linux/mailbox/qmp.h>
#include <linux/uaccess.h>
#include <linux/mailbox_controller.h>
#define MAX_MSG_SIZE 96 /* Imposed by the remote*/
struct qmp_debugfs_data {
struct qmp_pkt pkt;
char buf[MAX_MSG_SIZE + 1];
};
static struct qmp_debugfs_data data_pkt[MBOX_TX_QUEUE_LEN];
static struct mbox_chan *chan;
static struct mbox_client *cl;
static DEFINE_MUTEX(qmp_debugfs_mutex);
static ssize_t aop_msg_write(struct file *file, const char __user *userstr,
size_t len, loff_t *pos)
{
static int count;
int rc;
if (!len || (len > MAX_MSG_SIZE))
return len;
mutex_lock(&qmp_debugfs_mutex);
if (count >= MBOX_TX_QUEUE_LEN)
count = 0;
memset(&(data_pkt[count]), 0, sizeof(data_pkt[count]));
rc = copy_from_user(data_pkt[count].buf, userstr, len);
if (rc) {
pr_err("%s copy from user failed, rc=%d\n", __func__, rc);
mutex_unlock(&qmp_debugfs_mutex);
return len;
}
/*
* Controller expects a 4 byte aligned buffer
*/
data_pkt[count].pkt.size = (len + 0x3) & ~0x3;
data_pkt[count].pkt.data = data_pkt[count].buf;
if (mbox_send_message(chan, &(data_pkt[count].pkt)) < 0)
pr_err("Failed to send qmp request\n");
else
count++;
mutex_unlock(&qmp_debugfs_mutex);
return len;
}
static const struct file_operations aop_msg_fops = {
.write = aop_msg_write,
};
static int qmp_msg_probe(struct platform_device *pdev)
{
struct dentry *file;
cl = devm_kzalloc(&pdev->dev, sizeof(*cl), GFP_KERNEL);
if (!cl)
return -ENOMEM;
cl->dev = &pdev->dev;
cl->tx_block = true;
cl->tx_tout = 1000;
cl->knows_txdone = false;
chan = mbox_request_channel(cl, 0);
if (IS_ERR(chan)) {
dev_err(&pdev->dev, "Failed to mbox channel\n");
return PTR_ERR(chan);
}
file = debugfs_create_file("aop_send_message", 0220, NULL, NULL,
&aop_msg_fops);
if (!file)
goto err;
return 0;
err:
mbox_free_channel(chan);
chan = NULL;
return -ENOMEM;
}
static const struct of_device_id aop_qmp_match_tbl[] = {
{.compatible = "qcom,debugfs-qmp-client"},
{},
};
static struct platform_driver aop_qmp_msg_driver = {
.probe = qmp_msg_probe,
.driver = {
.name = "debugfs-qmp-client",
.owner = THIS_MODULE,
.suppress_bind_attrs = true,
.of_match_table = aop_qmp_match_tbl,
},
};
builtin_platform_driver(aop_qmp_msg_driver);