q6v5_wcss_remove() omits the cleanup for the sysmon, glink, and ssr
subdevices that are registered in q6v5_wcss_probe(). This leaves these
subdevices registered in the rproc subdev list after driver unbind,
which can cause use-after-free if the rproc framework subsequently
accesses them.
Additionally, rproc_del() is currently called after the subdev cleanup,
but it must be called first. rproc_del() internally calls rproc_stop(),
which invokes rproc_stop_subdevices() and rproc_unprepare_subdevices()
to run each subdev's stop/unprepare callbacks. If subdevices are removed
from the list before rproc_del(), those callbacks are never invoked.
The correct order, as used in sibling drivers such as adsp_remove() and
wcnss_remove(), is to call rproc_del() first, then remove the subdevices.
Fix both issues by calling rproc_del() first, then removing all
registered subdevices. qcom_remove_sysmon_subdev() already handles a
NULL argument gracefully, so it can be called unconditionally for
platforms where the sysmon subdev is not registered.
Fixes: 8a226e2c71bb ("remoteproc: wcss: add support for rpmsg communication")
Signed-off-by: Anup Vishwakarma <[email protected]>
---
drivers/remoteproc/qcom_q6v5_wcss.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/remoteproc/qcom_q6v5_wcss.c
b/drivers/remoteproc/qcom_q6v5_wcss.c
index b391724cfd08..7980c1ac55f6 100644
--- a/drivers/remoteproc/qcom_q6v5_wcss.c
+++ b/drivers/remoteproc/qcom_q6v5_wcss.c
@@ -1042,9 +1042,12 @@ static void q6v5_wcss_remove(struct platform_device
*pdev)
struct rproc *rproc = platform_get_drvdata(pdev);
struct q6v5_wcss *wcss = rproc->priv;
+ rproc_del(rproc);
+ qcom_remove_sysmon_subdev(wcss->sysmon);
qcom_q6v5_deinit(&wcss->q6v5);
+ qcom_remove_glink_subdev(rproc, &wcss->glink_subdev);
qcom_remove_pdm_subdev(rproc, &wcss->pdm_subdev);
- rproc_del(rproc);
+ qcom_remove_ssr_subdev(rproc, &wcss->ssr_subdev);
}
static const struct wcss_data wcss_ipq8074_res_init = {
---
base-commit: f0406245cb9855e6318335a8a223551354291a46
change-id: 20261005-b4-q6v5_wcss_remove_subdev_cleanup-028c6690618a
Best regards,
--
Anup Vishwakarma <[email protected]>