From 2bcdc156d9da3955c8b180d8f66a07df21c34414 Mon Sep 17 00:00:00 2001 From: Raghavendra Rao Ananta Date: Fri, 4 Sep 2020 15:46:20 -0700 Subject: [PATCH 1/6] ANDROID: ABI: Update allowed list for QCOM Leaf changes summary: 2 artifacts changed Changed leaf types summary: 0 leaf type changed Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 1 Added variable 1 Added function: [A] 'function void regmap_mmio_detach_clk(regmap*)' 1 Added variable: [A] 'const vb2_mem_ops vb2_vmalloc_memops' Bug: 167839566 Change-Id: I503d09516e077a354ee7380597a4015baf80d75f Signed-off-by: Raghavendra Rao Ananta --- android/abi_gki_aarch64.xml | 1294 +++++++++++++++++----------------- android/abi_gki_aarch64_qcom | 8 + 2 files changed, 667 insertions(+), 635 deletions(-) diff --git a/android/abi_gki_aarch64.xml b/android/abi_gki_aarch64.xml index 0650271f360a..a263c39a0a40 100644 --- a/android/abi_gki_aarch64.xml +++ b/android/abi_gki_aarch64.xml @@ -2912,6 +2912,7 @@ + @@ -4388,6 +4389,7 @@ + @@ -15230,6 +15232,14 @@ + + + + + + + + @@ -15249,20 +15259,6 @@ - - - - - - - - - - - - - - @@ -16038,6 +16034,22 @@ + + + + + + + + + + + + + + + + @@ -16391,7 +16403,7 @@ - + @@ -16493,7 +16505,7 @@ - + @@ -16962,7 +16974,7 @@ - + @@ -16975,10 +16987,10 @@ - + - + @@ -16986,7 +16998,7 @@ - + @@ -17356,7 +17368,7 @@ - + @@ -17727,7 +17739,7 @@ - + @@ -18046,10 +18058,10 @@ - + - + @@ -22071,24 +22083,6 @@ - - - - - - - - - - - - - - - - - - @@ -22340,17 +22334,23 @@ - - - + + + - - + + - - + + - + + + + + + + @@ -22359,6 +22359,7 @@ + @@ -22561,7 +22562,7 @@ - + @@ -22784,7 +22785,7 @@ - + @@ -22842,15 +22843,15 @@ - + - + - + @@ -23075,26 +23076,6 @@ - - - - - - - - - - - - - - - - - - - - @@ -23243,12 +23224,12 @@ - + - + @@ -23587,6 +23568,10 @@ + + + + @@ -24045,7 +24030,7 @@ - + @@ -24234,7 +24219,7 @@ - + @@ -24848,12 +24833,12 @@ - + - + @@ -29650,13 +29635,13 @@ - + - + @@ -32178,7 +32163,7 @@ - + @@ -32199,7 +32184,7 @@ - + @@ -32599,7 +32584,7 @@ - + @@ -33583,7 +33568,7 @@ - + @@ -33841,10 +33826,10 @@ - + - + @@ -34850,7 +34835,7 @@ - + @@ -36517,7 +36502,7 @@ - + @@ -36527,7 +36512,6 @@ - @@ -37123,7 +37107,7 @@ - + @@ -37384,10 +37368,10 @@ - + - + @@ -37506,13 +37490,13 @@ - + - + @@ -37809,7 +37793,7 @@ - + @@ -39606,7 +39590,7 @@ - + @@ -39698,7 +39682,7 @@ - + @@ -40687,7 +40671,7 @@ - + @@ -40706,7 +40690,7 @@ - + @@ -41994,7 +41978,7 @@ - + @@ -42019,9 +42003,9 @@ - + - + @@ -42033,7 +42017,7 @@ - + @@ -42162,7 +42146,7 @@ - + @@ -42628,9 +42612,9 @@ - + - + @@ -42642,7 +42626,7 @@ - + @@ -42650,7 +42634,7 @@ - + @@ -42679,7 +42663,7 @@ - + @@ -44278,7 +44262,7 @@ - + @@ -44291,7 +44275,7 @@ - + @@ -44307,7 +44291,7 @@ - + @@ -44315,13 +44299,13 @@ - + - + @@ -44585,7 +44569,7 @@ - + @@ -44593,7 +44577,7 @@ - + @@ -45512,10 +45496,10 @@ - + - + @@ -45798,7 +45782,7 @@ - + @@ -46013,8 +45997,11 @@ + + + - + @@ -46160,7 +46147,7 @@ - + @@ -46278,10 +46265,10 @@ - + - + @@ -46293,7 +46280,7 @@ - + @@ -46318,7 +46305,7 @@ - + @@ -46529,7 +46516,7 @@ - + @@ -47494,10 +47481,10 @@ - + - + @@ -48118,7 +48105,7 @@ - + @@ -48134,7 +48121,7 @@ - + @@ -48142,13 +48129,13 @@ - + - + @@ -48640,10 +48627,10 @@ - + - + @@ -48868,7 +48855,7 @@ - + @@ -48903,7 +48890,7 @@ - + @@ -49220,10 +49207,10 @@ - + - + @@ -50929,7 +50916,7 @@ - + @@ -50944,7 +50931,7 @@ - + @@ -51592,7 +51579,7 @@ - + @@ -51608,7 +51595,7 @@ - + @@ -51906,7 +51893,7 @@ - + @@ -52293,7 +52280,7 @@ - + @@ -53293,7 +53280,7 @@ - + @@ -54011,7 +53998,7 @@ - + @@ -54036,15 +54023,15 @@ - + - + - + @@ -54053,7 +54040,7 @@ - + @@ -54661,7 +54648,7 @@ - + @@ -55470,17 +55457,6 @@ - - - - - - - - - - - @@ -56000,9 +55976,9 @@ - + - + @@ -56011,7 +55987,7 @@ - + @@ -56019,7 +55995,7 @@ - + @@ -58717,10 +58693,10 @@ - + - + @@ -58747,7 +58723,7 @@ - + @@ -63472,7 +63448,7 @@ - + @@ -63523,7 +63499,7 @@ - + @@ -63607,7 +63583,7 @@ - + @@ -65632,7 +65608,7 @@ - + @@ -66329,7 +66305,7 @@ - + @@ -66340,7 +66316,7 @@ - + @@ -68711,18 +68687,18 @@ - + - + - + - + @@ -69109,7 +69085,7 @@ - + @@ -69938,14 +69914,6 @@ - - - - - - - - @@ -70099,6 +70067,14 @@ + + + + + + + + @@ -70110,28 +70086,18 @@ - + - + - - - - - - + - - - - - - + - + @@ -71775,10 +71741,10 @@ - + - + @@ -71831,10 +71797,10 @@ - + - + @@ -73273,7 +73239,7 @@ - + @@ -73282,7 +73248,7 @@ - + @@ -73888,7 +73854,7 @@ - + @@ -73935,7 +73901,7 @@ - + @@ -74195,7 +74161,7 @@ - + @@ -75555,7 +75521,7 @@ - + @@ -75576,7 +75542,7 @@ - + @@ -78931,7 +78897,7 @@ - + @@ -82732,7 +82698,7 @@ - + @@ -82740,7 +82706,7 @@ - + @@ -85426,7 +85392,7 @@ - + @@ -85445,7 +85411,7 @@ - + @@ -85952,7 +85918,7 @@ - + @@ -86526,7 +86492,7 @@ - + @@ -86819,7 +86785,7 @@ - + @@ -86841,7 +86807,7 @@ - + @@ -87026,10 +86992,10 @@ - + - + @@ -87303,7 +87269,7 @@ - + @@ -87332,7 +87298,7 @@ - + @@ -87410,7 +87376,7 @@ - + @@ -87565,7 +87531,7 @@ - + @@ -87613,7 +87579,7 @@ - + @@ -87798,7 +87764,7 @@ - + @@ -87810,12 +87776,12 @@ - + - + @@ -87835,7 +87801,7 @@ - + @@ -87966,7 +87932,7 @@ - + @@ -88080,7 +88046,7 @@ - + @@ -88095,7 +88061,7 @@ - + @@ -88154,7 +88120,7 @@ - + @@ -88871,7 +88837,7 @@ - + @@ -89536,7 +89502,7 @@ - + @@ -89584,7 +89550,7 @@ - + @@ -89730,7 +89696,7 @@ - + @@ -90294,7 +90260,7 @@ - + @@ -90716,6 +90682,17 @@ + + + + + + + + + + + @@ -91448,7 +91425,7 @@ - + @@ -92335,7 +92312,7 @@ - + @@ -92358,7 +92335,7 @@ - + @@ -92584,7 +92561,7 @@ - + @@ -92602,7 +92579,7 @@ - + @@ -93916,7 +93893,7 @@ - + @@ -93937,7 +93914,7 @@ - + @@ -95980,10 +95957,10 @@ - + - + @@ -100391,7 +100368,7 @@ - + @@ -101540,7 +101517,7 @@ - + @@ -101634,7 +101611,7 @@ - + @@ -101648,24 +101625,7 @@ - - - - - - - - - - - - - - - - - - + @@ -101791,22 +101751,6 @@ - - - - - - - - - - - - - - - - @@ -101872,7 +101816,7 @@ - + @@ -101941,7 +101885,7 @@ - + @@ -102741,7 +102685,7 @@ - + @@ -102979,7 +102923,7 @@ - + @@ -103024,7 +102968,7 @@ - + @@ -103374,10 +103318,10 @@ - + - + @@ -104107,16 +104051,16 @@ - + - + - + @@ -104124,7 +104068,7 @@ - + @@ -104202,7 +104146,7 @@ - + @@ -104219,7 +104163,7 @@ - + @@ -104458,7 +104402,7 @@ - + @@ -104579,7 +104523,7 @@ - + @@ -104668,7 +104612,7 @@ - + @@ -104686,10 +104630,10 @@ - + - + @@ -104708,7 +104652,7 @@ - + @@ -104738,7 +104682,7 @@ - + @@ -105058,10 +105002,210 @@ + + + + - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -105069,7 +105213,7 @@ - + @@ -105215,7 +105359,18 @@ + + + + + + + + + + + @@ -105388,6 +105543,13 @@ + + + + + + + @@ -105395,6 +105557,10 @@ + + + + @@ -105459,7 +105625,7 @@ - + @@ -105467,7 +105633,7 @@ - + @@ -106790,7 +106956,7 @@ - + @@ -106799,7 +106965,7 @@ - + @@ -108050,10 +108216,10 @@ - + - + @@ -108126,7 +108292,7 @@ - + @@ -108381,7 +108547,7 @@ - + @@ -109066,7 +109232,7 @@ - + @@ -109074,7 +109240,7 @@ - + @@ -109088,7 +109254,7 @@ - + @@ -109096,7 +109262,7 @@ - + @@ -109112,7 +109278,7 @@ - + @@ -110857,7 +111023,7 @@ - + @@ -110865,7 +111031,7 @@ - + @@ -110881,7 +111047,7 @@ - + @@ -110889,7 +111055,7 @@ - + @@ -110897,7 +111063,7 @@ - + @@ -110943,7 +111109,7 @@ - + @@ -110951,7 +111117,7 @@ - + @@ -110967,7 +111133,7 @@ - + @@ -110975,7 +111141,7 @@ - + @@ -111013,7 +111179,7 @@ - + @@ -111043,7 +111209,7 @@ - + @@ -111345,7 +111511,7 @@ - + @@ -111354,7 +111520,7 @@ - + @@ -112257,10 +112423,10 @@ - + - + @@ -112282,10 +112448,10 @@ - + - + @@ -112624,6 +112790,17 @@ + + + + + + + + + + + @@ -112830,10 +113007,10 @@ - + - + @@ -112841,7 +113018,7 @@ - + @@ -113019,7 +113196,7 @@ - + @@ -113132,7 +113309,7 @@ - + @@ -113240,17 +113417,6 @@ - - - - - - - - - - - @@ -113366,7 +113532,7 @@ - + @@ -113784,207 +113950,12 @@ - - - - - - - - - - - - - + - - - - + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + @@ -114003,10 +113974,10 @@ - + - + @@ -114022,7 +113993,7 @@ - + @@ -114033,7 +114004,7 @@ - + @@ -114041,11 +114012,11 @@ - + - + - + @@ -114054,12 +114025,12 @@ - + - + @@ -114070,7 +114041,7 @@ - + @@ -114098,7 +114069,7 @@ - + @@ -114117,7 +114088,7 @@ - + @@ -114128,7 +114099,7 @@ - + @@ -114136,7 +114107,7 @@ - + @@ -114150,7 +114121,7 @@ - + @@ -114158,18 +114129,8 @@ - - - - - - - - - - + - @@ -114241,17 +114202,6 @@ - - - - - - - - - - - @@ -117355,7 +117305,7 @@ - + @@ -117367,7 +117317,7 @@ - + @@ -118883,7 +118833,7 @@ - + @@ -118899,7 +118849,7 @@ - + @@ -119634,7 +119584,7 @@ - + @@ -119738,12 +119688,12 @@ - + - + - + @@ -119776,7 +119726,7 @@ - + @@ -119877,10 +119827,10 @@ - + - + @@ -120374,6 +120324,61 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -120465,7 +120470,7 @@ - + @@ -120617,6 +120622,25 @@ + + + + + + + + + + + + + + + + + + + @@ -120631,13 +120655,13 @@ - + - + @@ -120761,7 +120785,7 @@ - + @@ -120862,7 +120886,7 @@ - + @@ -121563,7 +121587,7 @@ - + @@ -121573,9 +121597,9 @@ - + - + @@ -121587,7 +121611,7 @@ - + @@ -121654,13 +121678,13 @@ - + - + - + @@ -121669,7 +121693,7 @@ - + @@ -121677,7 +121701,7 @@ - + @@ -121685,7 +121709,7 @@ - + @@ -121716,7 +121740,7 @@ - + @@ -121794,13 +121818,13 @@ - + - + @@ -122674,7 +122698,7 @@ - + @@ -122842,7 +122866,7 @@ - + @@ -123526,7 +123550,7 @@ - + @@ -123643,10 +123667,10 @@ - + - + @@ -124603,7 +124627,7 @@ - + @@ -125817,7 +125841,7 @@ - + @@ -126185,7 +126209,7 @@ - + @@ -126405,7 +126429,7 @@ - + @@ -126513,7 +126537,7 @@ - + diff --git a/android/abi_gki_aarch64_qcom b/android/abi_gki_aarch64_qcom index 5e7a276eac5e..4937eec64a99 100644 --- a/android/abi_gki_aarch64_qcom +++ b/android/abi_gki_aarch64_qcom @@ -1342,6 +1342,12 @@ memmove memory_read_from_buffer memparse + mempool_alloc + mempool_alloc_slab + mempool_create + mempool_destroy + mempool_free + mempool_free_slab memremap memset __memset_io @@ -1850,6 +1856,7 @@ regmap_field_update_bits_base __regmap_init regmap_irq_get_virq + regmap_mmio_detach_clk regmap_raw_read regmap_read regmap_update_bits_base @@ -2673,6 +2680,7 @@ vb2_reqbufs vb2_streamoff vb2_streamon + vb2_vmalloc_memops vchan_dma_desc_free_list vchan_init vchan_tx_desc_free From 6d9aec4bc59f6edb291ed4319f26fbeb57fc8271 Mon Sep 17 00:00:00 2001 From: Johannes Berg Date: Wed, 5 Aug 2020 15:35:18 +0200 Subject: [PATCH 2/6] UPSTREAM: nl80211: fix NL80211_ATTR_HE_6GHZ_CAPABILITY usage commit fce2ff728f95b8894db14f51c9274dc56c37616f upstream. In nl80211_set_station(), we check NL80211_ATTR_HE_6GHZ_CAPABILITY and then use NL80211_ATTR_HE_CAPABILITY, which is clearly wrong. Fix this to use NL80211_ATTR_HE_6GHZ_CAPABILITY as well. Cc: stable@vger.kernel.org Fixes: 43e64bf301fd ("cfg80211: handle 6 GHz capability of new station") Link: https://lore.kernel.org/r/20200805153516.310cef625955.I0abc04dc8abb2c7c005c88ef8fa2d0e3c9fb95c4@changeid Signed-off-by: Johannes Berg Signed-off-by: Greg Kroah-Hartman (cherry picked from commit fce2ff728f95b8894db14f51c9274dc56c37616f) Signed-off-by: Greg Kroah-Hartman Change-Id: Ib3951a485537514e26a9ac70ad9773580ecc4f53 --- net/wireless/nl80211.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c index 3f7dcbc753a4..2b01f92388ac 100644 --- a/net/wireless/nl80211.c +++ b/net/wireless/nl80211.c @@ -5980,7 +5980,7 @@ static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info) if (info->attrs[NL80211_ATTR_HE_6GHZ_CAPABILITY]) params.he_6ghz_capa = - nla_data(info->attrs[NL80211_ATTR_HE_CAPABILITY]); + nla_data(info->attrs[NL80211_ATTR_HE_6GHZ_CAPABILITY]); if (info->attrs[NL80211_ATTR_AIRTIME_WEIGHT]) params.airtime_weight = From 987c7b940b5d94cb2a0ccad6f27979991441996b Mon Sep 17 00:00:00 2001 From: Luhua Xu Date: Wed, 30 Oct 2019 17:03:54 +0800 Subject: [PATCH 3/6] UPSTREAM: spi: add power control when set_cs As to set_cs takes effect immediately, power spi is needed when setup spi. Bug: 167938264 Cc: Mark Brown Signed-off-by: Luhua Xu Link: https://lore.kernel.org/r/1572426234-30019-1-git-send-email-luhua.xu@mediatek.com Signed-off-by: Mark Brown (cherry picked from commit d948e6ca189985495a21cd622c31e30e72b6b688) Signed-off-by: Greg Kroah-Hartman Change-Id: I4ed7f854419901f9537916096b941135796956d1 --- drivers/spi/spi.c | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/drivers/spi/spi.c b/drivers/spi/spi.c index 6a81b2a33cb4..bb3066cedb7e 100644 --- a/drivers/spi/spi.c +++ b/drivers/spi/spi.c @@ -3111,7 +3111,20 @@ int spi_setup(struct spi_device *spi) if (spi->controller->setup) status = spi->controller->setup(spi); - spi_set_cs(spi, false); + if (spi->controller->auto_runtime_pm && spi->controller->set_cs) { + status = pm_runtime_get_sync(spi->controller->dev.parent); + if (status < 0) { + pm_runtime_put_noidle(spi->controller->dev.parent); + dev_err(&spi->controller->dev, "Failed to power device: %d\n", + status); + return status; + } + spi_set_cs(spi, false); + pm_runtime_mark_last_busy(spi->controller->dev.parent); + pm_runtime_put_autosuspend(spi->controller->dev.parent); + } else { + spi_set_cs(spi, false); + } if (spi->rt && !spi->controller->rt) { spi->controller->rt = true; From 2d5d56df7f19e37483209decf17a43213592e084 Mon Sep 17 00:00:00 2001 From: Alexander Lobakin Date: Mon, 14 Oct 2019 11:00:33 +0300 Subject: [PATCH 4/6] BACKPORT: net: core: use listified Rx for GRO_NORMAL in napi_gro_receive() Commit 323ebb61e32b4 ("net: use listified RX for handling GRO_NORMAL skbs") made use of listified skb processing for the users of napi_gro_frags(). The same technique can be used in a way more common napi_gro_receive() to speed up non-merged (GRO_NORMAL) skbs for a wide range of drivers including gro_cells and mac80211 users. This slightly changes the return value in cases where skb is being dropped by the core stack, but it seems to have no impact on related drivers' functionality. gro_normal_batch is left untouched as it's very individual for every single system configuration and might be tuned in manual order to achieve an optimal performance. Signed-off-by: Alexander Lobakin Acked-by: Edward Cree Signed-off-by: David S. Miller Bug: 167477898 Change-Id: Ie9e079cf9a5799ca2c4924848ca6b3caeef056d7 (cherry picked from commit 6570bc79c0dfff0f228b7afd2de720fb4e84d61d) [hyunsoon: fix conflicts in net/core/dev.c] Signed-off-by: Hyunsoon Kim --- net/core/dev.c | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/net/core/dev.c b/net/core/dev.c index 724ae5d84fe3..782c28482b2a 100644 --- a/net/core/dev.c +++ b/net/core/dev.c @@ -5609,12 +5609,13 @@ static void napi_skb_free_stolen_head(struct sk_buff *skb) kmem_cache_free(skbuff_head_cache, skb); } -static gro_result_t napi_skb_finish(gro_result_t ret, struct sk_buff *skb) +static gro_result_t napi_skb_finish(struct napi_struct *napi, + struct sk_buff *skb, + gro_result_t ret) { switch (ret) { case GRO_NORMAL: - if (netif_receive_skb_internal(skb)) - ret = GRO_DROP; + gro_normal_one(napi, skb); break; case GRO_DROP: @@ -5646,7 +5647,7 @@ gro_result_t napi_gro_receive(struct napi_struct *napi, struct sk_buff *skb) skb_gro_reset_offset(skb); - ret = napi_skb_finish(dev_gro_receive(napi, skb), skb); + ret = napi_skb_finish(napi, skb, dev_gro_receive(napi, skb)); trace_napi_gro_receive_exit(ret); return ret; From 1b6a6a2efea171a48551b52db7f21fabf03c6d19 Mon Sep 17 00:00:00 2001 From: "glider@google.com" Date: Tue, 16 Jun 2020 10:34:35 +0200 Subject: [PATCH 5/6] UPSTREAM: security: allow using Clang's zero initialization for stack variables MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Upstream commit f0fe00d4972a8cd4b98cc2c29758615e4d51cdfe. In addition to -ftrivial-auto-var-init=pattern (used by CONFIG_INIT_STACK_ALL now) Clang also supports zero initialization for locals enabled by -ftrivial-auto-var-init=zero. The future of this flag is still being debated (see https://bugs.llvm.org/show_bug.cgi?id=45497). Right now it is guarded by another flag, -enable-trivial-auto-var-init-zero-knowing-it-will-be-removed-from-clang, which means it may not be supported by future Clang releases. Another possible resolution is that -ftrivial-auto-var-init=zero will persist (as certain users have already started depending on it), but the name of the guard flag will change. In the meantime, zero initialization has proven itself as a good production mitigation measure against uninitialized locals. Unlike pattern initialization, which has a higher chance of triggering existing bugs, zero initialization provides safe defaults for strings, pointers, indexes, and sizes. On the other hand, pattern initialization remains safer for return values. Chrome OS and Android are moving to using zero initialization for production builds. Performance-wise, the difference between pattern and zero initialization is usually negligible, although the generated code for zero initialization is more compact. This patch renames CONFIG_INIT_STACK_ALL to CONFIG_INIT_STACK_ALL_PATTERN and introduces another config option, CONFIG_INIT_STACK_ALL_ZERO, that enables zero initialization for locals if the corresponding flags are supported by Clang. Cc: Kees Cook Cc: Nick Desaulniers Cc: Greg Kroah-Hartman Signed-off-by: Alexander Potapenko Link: https://lore.kernel.org/r/20200616083435.223038-1-glider@google.com Reviewed-by: Maciej Żenczykowski Signed-off-by: Kees Cook Change-Id: I3c69570e7e3d3bbb666709de6feb531000bce2bf --- Makefile | 13 +++++++++++-- init/main.c | 12 +++++++----- security/Kconfig.hardening | 29 +++++++++++++++++++++++++---- 3 files changed, 43 insertions(+), 11 deletions(-) diff --git a/Makefile b/Makefile index 3059e1900e96..a57932c031ec 100644 --- a/Makefile +++ b/Makefile @@ -796,11 +796,20 @@ KBUILD_CFLAGS += -fomit-frame-pointer endif endif -# Initialize all stack variables with a pattern, if desired. -ifdef CONFIG_INIT_STACK_ALL +# Initialize all stack variables with a 0xAA pattern. +ifdef CONFIG_INIT_STACK_ALL_PATTERN KBUILD_CFLAGS += -ftrivial-auto-var-init=pattern endif +# Initialize all stack variables with a zero value. +ifdef CONFIG_INIT_STACK_ALL_ZERO +# Future support for zero initialization is still being debated, see +# https://bugs.llvm.org/show_bug.cgi?id=45497. These flags are subject to being +# renamed or dropped. +KBUILD_CFLAGS += -ftrivial-auto-var-init=zero +KBUILD_CFLAGS += -enable-trivial-auto-var-init-zero-knowing-it-will-be-removed-from-clang +endif + DEBUG_CFLAGS := $(call cc-option, -fno-var-tracking-assignments) ifdef CONFIG_DEBUG_INFO diff --git a/init/main.c b/init/main.c index 8c7d6b8ee6bd..9e0e160bbe24 100644 --- a/init/main.c +++ b/init/main.c @@ -525,14 +525,16 @@ static void __init report_meminit(void) { const char *stack; - if (IS_ENABLED(CONFIG_INIT_STACK_ALL)) - stack = "all"; + if (IS_ENABLED(CONFIG_INIT_STACK_ALL_PATTERN)) + stack = "all(pattern)"; + else if (IS_ENABLED(CONFIG_INIT_STACK_ALL_ZERO)) + stack = "all(zero)"; else if (IS_ENABLED(CONFIG_GCC_PLUGIN_STRUCTLEAK_BYREF_ALL)) - stack = "byref_all"; + stack = "byref_all(zero)"; else if (IS_ENABLED(CONFIG_GCC_PLUGIN_STRUCTLEAK_BYREF)) - stack = "byref"; + stack = "byref(zero)"; else if (IS_ENABLED(CONFIG_GCC_PLUGIN_STRUCTLEAK_USER)) - stack = "__user"; + stack = "__user(zero)"; else stack = "off"; diff --git a/security/Kconfig.hardening b/security/Kconfig.hardening index af4c979b38ee..269967c4fc1b 100644 --- a/security/Kconfig.hardening +++ b/security/Kconfig.hardening @@ -19,13 +19,16 @@ config GCC_PLUGIN_STRUCTLEAK menu "Memory initialization" -config CC_HAS_AUTO_VAR_INIT +config CC_HAS_AUTO_VAR_INIT_PATTERN def_bool $(cc-option,-ftrivial-auto-var-init=pattern) +config CC_HAS_AUTO_VAR_INIT_ZERO + def_bool $(cc-option,-ftrivial-auto-var-init=zero -enable-trivial-auto-var-init-zero-knowing-it-will-be-removed-from-clang) + choice prompt "Initialize kernel stack variables at function entry" default GCC_PLUGIN_STRUCTLEAK_BYREF_ALL if COMPILE_TEST && GCC_PLUGINS - default INIT_STACK_ALL if COMPILE_TEST && CC_HAS_AUTO_VAR_INIT + default INIT_STACK_ALL_PATTERN if COMPILE_TEST && CC_HAS_AUTO_VAR_INIT_PATTERN default INIT_STACK_NONE help This option enables initialization of stack variables at @@ -88,9 +91,9 @@ choice of uninitialized stack variable exploits and information exposures. - config INIT_STACK_ALL + config INIT_STACK_ALL_PATTERN bool "0xAA-init everything on the stack (strongest)" - depends on CC_HAS_AUTO_VAR_INIT + depends on CC_HAS_AUTO_VAR_INIT_PATTERN help Initializes everything on the stack with a 0xAA pattern. This is intended to eliminate all classes @@ -98,6 +101,24 @@ choice exposures, even variables that were warned to have been left uninitialized. + Pattern initialization is known to provoke many existing bugs + related to uninitialized locals, e.g. pointers receive + non-NULL values, buffer sizes and indices are very big. + + config INIT_STACK_ALL_ZERO + bool "zero-init everything on the stack (strongest and safest)" + depends on CC_HAS_AUTO_VAR_INIT_ZERO + help + Initializes everything on the stack with a zero + value. This is intended to eliminate all classes + of uninitialized stack variable exploits and information + exposures, even variables that were warned to have been + left uninitialized. + + Zero initialization provides safe defaults for strings, + pointers, indices and sizes, and is therefore + more suitable as a security mitigation measure. + endchoice config GCC_PLUGIN_STRUCTLEAK_VERBOSE From a56472627739e5ea2f842bcbe5ac2ca0ab4e9ea9 Mon Sep 17 00:00:00 2001 From: Alexander Potapenko Date: Thu, 3 Sep 2020 09:16:26 +0200 Subject: [PATCH 6/6] ANDROID: gki_defconfig: initialize locals with zeroes This patch switches compiler-based stack initialization from 0xAA to zero pattern, resulting in much more efficient code and saner defaults for uninitialized local variables. Bug: 154198143 Test: run cuttlefish and observe the following lines in dmesg: test_stackinit: all tests passed! test_meminit: all 130 tests passed! Signed-off-by: Alexander Potapenko Change-Id: If9f2047fcbee58b90dbd8ad45707c5b40a654e2d --- arch/arm64/configs/gki_defconfig | 2 +- arch/x86/configs/gki_defconfig | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/arch/arm64/configs/gki_defconfig b/arch/arm64/configs/gki_defconfig index cb7c9a5cb859..9f2bdcdae163 100644 --- a/arch/arm64/configs/gki_defconfig +++ b/arch/arm64/configs/gki_defconfig @@ -543,7 +543,7 @@ CONFIG_FORTIFY_SOURCE=y CONFIG_STATIC_USERMODEHELPER=y CONFIG_STATIC_USERMODEHELPER_PATH="" CONFIG_SECURITY_SELINUX=y -CONFIG_INIT_STACK_ALL=y +CONFIG_INIT_STACK_ALL_ZERO=y CONFIG_INIT_ON_ALLOC_DEFAULT_ON=y CONFIG_CRYPTO_ADIANTUM=y CONFIG_CRYPTO_LZ4=y diff --git a/arch/x86/configs/gki_defconfig b/arch/x86/configs/gki_defconfig index edca2f2a24e5..96140818bf38 100644 --- a/arch/x86/configs/gki_defconfig +++ b/arch/x86/configs/gki_defconfig @@ -469,7 +469,7 @@ CONFIG_FORTIFY_SOURCE=y CONFIG_STATIC_USERMODEHELPER=y CONFIG_STATIC_USERMODEHELPER_PATH="" CONFIG_SECURITY_SELINUX=y -CONFIG_INIT_STACK_ALL=y +CONFIG_INIT_STACK_ALL_ZERO=y CONFIG_INIT_ON_ALLOC_DEFAULT_ON=y CONFIG_CRYPTO_ADIANTUM=y CONFIG_CRYPTO_SHA256_SSSE3=y