From aac3ca927c96791c39b7ba0c07c3c635b451d621 Mon Sep 17 00:00:00 2001 From: Peter Ujfalusi Date: Tue, 6 Oct 2026 18:22:01 +0300 Subject: [PATCH] module: generic: allocate module IPC messages from coherent memory mod_ipc_msg_w_ext_init() allocates the ipc_msg and its tx_data with mod_zalloc(), which uses SOF_MEM_FLAG_USER only and thus returns cached memory. Before the conversion the message was allocated with SOF_MEM_FLAG_COHERENT. msg->list is linked into the uncached ipc->msg_list by the module (possibly on a secondary core or DP thread) and unlinked by the IPC send worker on the primary core. With a cached msg the worker operates on stale list pointers, list_item_del() fails to unlink the message and the same notification is sent to the host over and over again. Allocate the message and its payload with SOF_MEM_FLAG_COHERENT, as it was done before. Fixes: 97dd71011f7e ("ipc: make IPC message allocation userspace-safe") Signed-off-by: Peter Ujfalusi --- src/include/sof/audio/module_adapter/module/generic.h | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/src/include/sof/audio/module_adapter/module/generic.h b/src/include/sof/audio/module_adapter/module/generic.h index 26a02b6f2c99..6801dd338e17 100644 --- a/src/include/sof/audio/module_adapter/module/generic.h +++ b/src/include/sof/audio/module_adapter/module/generic.h @@ -263,16 +263,21 @@ static inline struct ipc_msg *mod_ipc_msg_w_ext_init(struct processing_module *m { struct ipc_msg *msg; - msg = mod_zalloc(mod, sizeof(*msg)); + /* msg->list is linked into ipc->msg_list and handled cross-core: must be uncached */ + msg = mod_alloc_ext(mod, SOF_MEM_FLAG_USER | SOF_MEM_FLAG_COHERENT, sizeof(*msg), 0); if (!msg) return NULL; + memset(msg, 0, sizeof(*msg)); + if (size) { - msg->tx_data = mod_zalloc(mod, size); + msg->tx_data = mod_alloc_ext(mod, SOF_MEM_FLAG_USER | SOF_MEM_FLAG_COHERENT, + size, 0); if (!msg->tx_data) { mod_free(mod, msg); return NULL; } + memset(msg->tx_data, 0, size); } msg->header = header;