Re: [PATCH] arm64: dts: qcom: sm6125-xiaomi-laurel-sprout: reserve firmware-owned DRAM
From: Konrad Dybcio
Date: Mon Aug 24 2026 - 09:23:36 EST
On 8/21/26 5:25 AM, Roman Linev wrote:
> sm6125.dtsi sizes reserved_mem1@46200000 at 0x2d00000 (45 MiB), so it ends
> at 0x48f00000. On laurel-sprout the firmware owns 0x4900000 (73 MiB) at
> that base: the downstream device tree overrides the SoC region with
>
> removed_region@46200000 { reg = <0 0x46200000 0 0x4900000>; };
>
> which ends exactly at 0x4ab00000, where mainline places camera_mem. The
> 28 MiB between 0x48f00000 and 0x4ab00000 is therefore firmware-owned on
> this board while mainline leaves it as free System RAM and hands it to the
> page allocator.
>
> On Qualcomm a "removed_region" is XPU-protected, so this is not a matter of
> reading stale data: the region is not the kernel's to allocate.
Not necessarily, XPU protection is a specialized mechanism, there may be
other owners that don't like tampering with their memory (hyp, tz..)
> The observed symptom is hard lockups under sustained buffered reads, where
> page-cache pressure eventually reaches the disputed range. Before this
> change the device wedged at a rate of roughly one lockup per 59 MiB of
> buffered reads from the SD card, reproducibly enough to fire on demand.
> With the region reserved, the same workload has run 691 GiB of buffered
> reads with zero lockups.
CONFIG_MEMTEST=y and `memtest=1` in cmdline is good to run to confirm
your memory map checks out
[...]
> + /*
> + * The SoC dtsi sizes reserved_mem1 at 0x2d00000 (45 MiB), ending
> + * at 0x48f00000. This device's firmware owns 0x4900000 (73 MiB)
> + * there -- downstream laurel_sprout carves out
> + * removed_region@46200000 with that size, ending exactly at
> + * camera_mem's 0x4ab00000. The 28 MiB in between is XPU-owned
> + * on this board and mainline currently hands it to the buddy
> + * allocator.
> + */
> + reserved_mem1_laurel: memory@48f00000 {
The label is unused, you can drop it. I think you should just do something
like this:
/* This carveout is larger than on other devices */
&reserved_mem1 {
reg = <0x0 0x46200000 0x0 foo>;
};
Konrad