Skip to content

Commit 60e8b71

Browse files
author
Jyri Sarha
committed
ipc: make IPC message allocation userspace-safe
Add an optional heap parameter to ipc_msg_w_ext_init() and ipc_msg_init() so callers can direct allocations to a specific heap. When the heap argument is NULL the existing rzalloc() path is used; when non-NULL, sof_heap_alloc()/sof_heap_free() are used instead. This allows IPC messages to be allocated from userspace-accessible heaps. For audio module contexts, introduce mod_ipc_msg_w_ext_init() and mod_ipc_msg_init() in generic.h. These use mod_zalloc()/ mod_free() for allocations that are automatically tracked and freed with the module lifecycle. ipc_msg_w_ext_init() is moved from a static inline in msg.h to a non-inline function in ipc-common.c due to the additional sof_heap_alloc dependency. Update all existing callers: - Module context callers (cadence, sound_dose, tdfb, mfcc) use the new mod_ipc_msg_*() variants and mod_ipc_msg_free(). - host-zephyr.c uses hd->heap, pipeline-graph.c uses the heap parameter from pipeline_new(). - Remaining kernel-context callers pass NULL for the default heap. Signed-off-by: Jyri Sarha <jyri.sarha@linux.intel.com>
1 parent 94e21d3 commit 60e8b71

18 files changed

Lines changed: 126 additions & 53 deletions

File tree

‎src/audio/google/google_hotword_detect.c‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -111,7 +111,7 @@ static struct comp_dev *ghd_create(const struct comp_driver *drv,
111111
cd->event.event_type = SOF_CTRL_EVENT_KD;
112112
cd->event.num_elems = 0;
113113

114-
cd->msg = ipc_msg_init(cd->event.rhdr.hdr.cmd, cd->event.rhdr.hdr.size);
114+
cd->msg = ipc_msg_init(NULL, cd->event.rhdr.hdr.cmd, cd->event.rhdr.hdr.size);
115115
if (!cd->msg) {
116116
comp_err(dev, "ipc_msg_init failed");
117117
goto cd_fail;

‎src/audio/host-legacy.c‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -559,7 +559,7 @@ int host_common_new(struct host_data *hd, struct comp_dev *dev,
559559
ipc_build_stream_posn(&hd->posn, SOF_IPC_STREAM_POSITION, config_id);
560560

561561
#if CONFIG_HOST_DMA_IPC_POSITION_UPDATES
562-
hd->msg = ipc_msg_init(hd->posn.rhdr.hdr.cmd, hd->posn.rhdr.hdr.size);
562+
hd->msg = ipc_msg_init(NULL, hd->posn.rhdr.hdr.cmd, hd->posn.rhdr.hdr.size);
563563
if (!hd->msg) {
564564
comp_err(dev, "ipc_msg_init failed");
565565
dma_put(hd->dma);

‎src/audio/host-zephyr.c‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -727,7 +727,7 @@ __cold int host_common_new(struct host_data *hd, struct comp_dev *dev,
727727
ipc_build_stream_posn(&hd->posn, SOF_IPC_STREAM_POSITION, config_id);
728728

729729
#if CONFIG_HOST_DMA_IPC_POSITION_UPDATES
730-
hd->msg = ipc_msg_init(hd->posn.rhdr.hdr.cmd, sizeof(hd->posn));
730+
hd->msg = ipc_msg_init(hd->heap, hd->posn.rhdr.hdr.cmd, sizeof(hd->posn));
731731
if (!hd->msg) {
732732
comp_err(dev, "ipc_msg_init failed");
733733
sof_dma_put(hd->dma);

‎src/audio/mfcc/mfcc.c‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -129,7 +129,7 @@ static int mfcc_free(struct processing_module *mod)
129129
struct mfcc_comp_data *cd = module_get_private_data(mod);
130130

131131
comp_info(mod->dev, "entry");
132-
ipc_msg_free(cd->msg);
132+
mod_ipc_msg_free(mod, cd->msg);
133133
cd->msg = NULL;
134134
mod_data_blob_handler_free(mod, cd->model_handler);
135135
mfcc_free_buffers(mod);

‎src/audio/mfcc/mfcc_ipc4.c‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -49,10 +49,10 @@ int mfcc_ipc_notification_init(struct processing_module *mod)
4949
primary->r.type = SOF_IPC4_GLB_NOTIFICATION;
5050
primary->r.rsp = SOF_IPC4_MESSAGE_DIR_MSG_REQUEST;
5151
primary->r.msg_tgt = SOF_IPC4_MESSAGE_TARGET_FW_GEN_MSG;
52-
cd->msg = ipc_msg_w_ext_init(msg_proto.header, msg_proto.extension,
53-
sizeof(struct sof_ipc4_notify_module_data) +
54-
sizeof(struct sof_ipc4_control_msg_payload) +
55-
sizeof(struct sof_ipc4_ctrl_value_chan));
52+
cd->msg = mod_ipc_msg_w_ext_init(mod, msg_proto.header, msg_proto.extension,
53+
sizeof(struct sof_ipc4_notify_module_data) +
54+
sizeof(struct sof_ipc4_control_msg_payload) +
55+
sizeof(struct sof_ipc4_ctrl_value_chan));
5656
if (!cd->msg) {
5757
comp_err(dev, "Failed to initialize VAD notification");
5858
return -ENOMEM;

‎src/audio/module_adapter/module/cadence_ipc4.c‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -233,7 +233,7 @@ static struct ipc_msg *cadence_codec_notification_init(struct processing_module
233233
primary.r.type = SOF_IPC4_GLB_NOTIFICATION;
234234
primary.r.rsp = SOF_IPC4_MESSAGE_DIR_MSG_REQUEST;
235235
primary.r.msg_tgt = SOF_IPC4_MESSAGE_TARGET_FW_GEN_MSG;
236-
msg = ipc_msg_w_ext_init(primary.dat, 0, sizeof(*msg_module_data));
236+
msg = mod_ipc_msg_w_ext_init(mod, primary.dat, 0, sizeof(*msg_module_data));
237237
if (!msg)
238238
return NULL;
239239

@@ -366,7 +366,7 @@ static int cadence_codec_init(struct processing_module *mod)
366366
if (setup_cfg)
367367
mod_free(mod, setup_cfg->data);
368368
free_notification:
369-
ipc_msg_free(cd->msg);
369+
mod_ipc_msg_free(mod, cd->msg);
370370
free_cd:
371371
mod_free(mod, cd);
372372

@@ -568,7 +568,7 @@ static int ipc4_cadence_codec_free(struct processing_module *mod)
568568
{
569569
struct cadence_codec_data *cd = module_get_private_data(mod);
570570

571-
ipc_msg_free(cd->msg);
571+
mod_ipc_msg_free(mod, cd->msg);
572572

573573
return cadence_codec_free(mod);
574574
}

‎src/audio/pipeline/pipeline-graph.c‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -227,7 +227,7 @@ struct pipeline *pipeline_new(struct k_heap *heap, uint32_t pipeline_id, uint32_
227227
ipc_build_stream_posn(&posn, SOF_IPC_STREAM_TRIG_XRUN, p->comp_id);
228228

229229
if (posn.rhdr.hdr.size) {
230-
p->msg = ipc_msg_init(posn.rhdr.hdr.cmd, posn.rhdr.hdr.size);
230+
p->msg = ipc_msg_init(heap, posn.rhdr.hdr.cmd, posn.rhdr.hdr.size);
231231
if (!p->msg) {
232232
pipe_err(p, "ipc_msg_init failed");
233233
goto free;

‎src/audio/sound_dose/sound_dose-ipc4.c‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -32,9 +32,9 @@ static struct ipc_msg *sound_dose_notification_init(struct processing_module *mo
3232
primary->r.type = SOF_IPC4_GLB_NOTIFICATION;
3333
primary->r.rsp = SOF_IPC4_MESSAGE_DIR_MSG_REQUEST;
3434
primary->r.msg_tgt = SOF_IPC4_MESSAGE_TARGET_FW_GEN_MSG;
35-
msg = ipc_msg_w_ext_init(msg_proto.header, msg_proto.extension,
36-
sizeof(struct sof_ipc4_notify_module_data) +
37-
sizeof(struct sof_ipc4_control_msg_payload));
35+
msg = mod_ipc_msg_w_ext_init(mod, msg_proto.header, msg_proto.extension,
36+
sizeof(struct sof_ipc4_notify_module_data) +
37+
sizeof(struct sof_ipc4_control_msg_payload));
3838
if (!msg)
3939
return NULL;
4040

‎src/audio/sound_dose/sound_dose.c‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -327,7 +327,7 @@ __cold static int sound_dose_free(struct processing_module *mod)
327327
comp_dbg(mod->dev, "entry");
328328

329329
sound_dose_filters_free(cd);
330-
ipc_msg_free(cd->msg);
330+
mod_ipc_msg_free(mod, cd->msg);
331331
rfree(cd->abi);
332332
rfree(cd);
333333
return 0;

‎src/audio/tdfb/tdfb.c‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -676,7 +676,7 @@ static int tdfb_init(struct processing_module *mod)
676676
err:
677677
/* These are null if not used for IPC version */
678678
mod_free(mod, cd->ctrl_data);
679-
ipc_msg_free(cd->msg);
679+
mod_ipc_msg_free(mod, cd->msg);
680680
mod_data_blob_handler_free(mod, cd->model_handler);
681681

682682
err_free_cd:
@@ -691,7 +691,7 @@ static int tdfb_free(struct processing_module *mod)
691691

692692
comp_dbg(mod->dev, "entry");
693693

694-
ipc_msg_free(cd->msg);
694+
mod_ipc_msg_free(mod, cd->msg);
695695
tdfb_free_delaylines(mod);
696696
mod_data_blob_handler_free(mod, cd->model_handler);
697697
tdfb_direction_free(mod);

0 commit comments

Comments
 (0)