[PATCH v9 2/6] firmware: meson: sm: Add video firmware loading SMC call

sashiko-bot at kernel.org sashiko-bot at kernel.org
Mon Sep 14 01:22:08 PDT 2026


Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [Critical] Missing synchronization around shared memory accesses for SMC calls.
--

commit e3c062e69752dda5c782cbb1944c0acc0d0866c2
Author: Zhentao Guo <zhentao.guo at amlogic.com>

firmware: meson: sm: Add video firmware loading SMC call

Add SM_LOAD_VIDEO_FW at SMC ID 0xb200000f in the command
table to load video firmware.

> diff --git a/drivers/firmware/meson/meson_sm.c b/drivers/firmware/meson/meson_sm.c
> index ab9751a59b552..887caa5c625db 100644
> --- a/drivers/firmware/meson/meson_sm.c
> +++ b/drivers/firmware/meson/meson_sm.c
> @@ -48,6 +48,7 @@ static const struct meson_sm_chip gxbb_chip = {
>  		CMD(SM_THERMAL_CALIB_READ,	0x82000047),
>  		CMD(SM_A1_PWRC_SET,		0x82000093),
>  		CMD(SM_A1_PWRC_GET,		0x82000095),
> +		CMD(SM_LOAD_VIDEO_FW,		0xb200000f),

[Severity: Critical]
This is a pre-existing issue, but is there missing synchronization around
shared memory accesses for SMC calls when handling these commands?

Looking at meson_sm_call_write() and meson_sm_call_read(), data is copied to
and from shared, unprotected memory regions (sm_shmem_in_base and
sm_shmem_out_base) during the SMC calls:

meson_sm_call_write() {
	...
	memcpy(fw->sm_shmem_in_base, buffer, size);

	if (meson_sm_call(fw, cmd_index, &written, arg0, arg1, arg2, arg3, arg4) < 0)
		return -EINVAL;
	...
}

meson_sm_call_read() {
	...
	if (meson_sm_call(fw, cmd_index, &size, arg0, arg1, arg2, arg3, arg4) < 0)
		return -EINVAL;

	if (buffer)
		memcpy(buffer, fw->sm_shmem_out_base, size);
	...
}

Since there are no mutexes in meson_sm.c or the upstream nvmem core's
read/write handlers (nvmem_reg_read/nvmem_reg_write), concurrent access to
the SMC functions is unsynchronized. 

For example, two root processes could concurrently write to nvmem, or
concurrently read the world-readable sysfs files.

One thread could overwrite sm_shmem_in_base while another thread is
mid-sequence (after its memcpy but before its SMC call executes), leading to
the SM receiving corrupted data. 

Similarly, SMC execution and the subsequent read from sm_shmem_out_base can
be interleaved by another thread's SMC call, causing a thread to read the
other thread's returned data.

Could this concurrent access cause data corruption during one-time hardware
operations like EFUSE writes, or corrupt thermal calibration data reads and
lead to system instability?

>  		{ /* sentinel */ },
>  	},
>  };

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260914-b4-s4-vdec-upstream-v9-0-72fdb0d71b02@amlogic.com?part=2



More information about the linux-amlogic mailing list