In qcom_pas_stop function, return value of qcom_pas_shutdown for pas_id
is overwritten by the return value of qcom_pas_shutdown for dtb_pas_id.
This causes errors seen on qcom_pas_shutdown failures for pas_id to be
masked to the caller. This might lead to issues where the memory regions
locked by PAS, as part of qcom_pas_auth_and_reset, are not released for
access by linux and rproc_coredump flow will end up accessing the locked
memory, leading to an access violation.

Fix this by using a separate variable for the dtb_pas_id shutdown call
and only overriding the main return value if the pas_id shutdown succeeded
but dtb_pas_id shutdown failed.

Fixes: 29814986b82e ("remoteproc: qcom_q6v5_pas: add support for dtb 
co-firmware loading")
Signed-off-by: Vignesh Viswanathan <[email protected]>
---
 drivers/remoteproc/qcom_q6v5_pas.c | 10 +++++++---
 1 file changed, 7 insertions(+), 3 deletions(-)

diff --git a/drivers/remoteproc/qcom_q6v5_pas.c 
b/drivers/remoteproc/qcom_q6v5_pas.c
index ca8e61254c44..40e8f3e32aa9 100644
--- a/drivers/remoteproc/qcom_q6v5_pas.c
+++ b/drivers/remoteproc/qcom_q6v5_pas.c
@@ -405,6 +405,7 @@ static int qcom_pas_stop(struct rproc *rproc)
 {
        struct qcom_pas *pas = rproc->priv;
        int handover;
+       int dtb_ret;
        int ret;
 
        ret = qcom_q6v5_request_stop(&pas->q6v5, pas->sysmon);
@@ -419,9 +420,12 @@ static int qcom_pas_stop(struct rproc *rproc)
                dev_err(pas->dev, "failed to shutdown: %d\n", ret);
 
        if (pas->dtb_pas_id) {
-               ret = qcom_pas_shutdown(pas->dtb_pas_id);
-               if (ret)
-                       dev_err(pas->dev, "failed to shutdown dtb: %d\n", ret);
+               dtb_ret = qcom_pas_shutdown(pas->dtb_pas_id);
+               if (dtb_ret)
+                       dev_err(pas->dev, "failed to shutdown dtb: %d\n", 
dtb_ret);
+
+               if (!ret && dtb_ret)
+                       ret = dtb_ret;
 
                qcom_pas_unmap_carveout(rproc, pas->dtb_mem_phys, 
pas->dtb_mem_size);
        }

---
base-commit: e6664f2b33db9b6811eb4cec109f06cb2b4f458d
change-id: 20260818-rproc_dtb_fix-60f5064b0631

Best regards,
--  
Vignesh Viswanathan <[email protected]>


Reply via email to