From 8d3d29f0729af71df257e2a90f6b612bb57f6078 Mon Sep 17 00:00:00 2001 From: Todd Kjos Date: Fri, 9 Oct 2020 16:24:55 -0700 Subject: [PATCH 01/14] UPSTREAM: binder: fix UAF when releasing todo list When releasing a thread todo list when tearing down a binder_proc, the following race was possible which could result in a use-after-free: 1. Thread 1: enter binder_release_work from binder_thread_release 2. Thread 2: binder_update_ref_for_handle() -> binder_dec_node_ilocked() 3. Thread 2: dec nodeA --> 0 (will free node) 4. Thread 1: ACQ inner_proc_lock 5. Thread 2: block on inner_proc_lock 6. Thread 1: dequeue work (BINDER_WORK_NODE, part of nodeA) 7. Thread 1: REL inner_proc_lock 8. Thread 2: ACQ inner_proc_lock 9. Thread 2: todo list cleanup, but work was already dequeued 10. Thread 2: free node 11. Thread 2: REL inner_proc_lock 12. Thread 1: deref w->type (UAF) The problem was that for a BINDER_WORK_NODE, the binder_work element must not be accessed after releasing the inner_proc_lock while processing the todo list elements since another thread might be handling a deref on the node containing the binder_work element leading to the node being freed. Signed-off-by: Todd Kjos Link: https://lore.kernel.org/r/20201009232455.4054810-1-tkjos@google.com Cc: # 4.14, 4.19, 5.4, 5.8 Signed-off-by: Greg Kroah-Hartman (cherry picked from commit f3277cbfba763cd2826396521b9296de67cf1bbc) Signed-off-by: Greg Kroah-Hartman Change-Id: I7c1bf0b74824f272664e76206c5dc3b66b9eeaff --- drivers/android/binder.c | 35 ++++++++++------------------------- 1 file changed, 10 insertions(+), 25 deletions(-) diff --git a/drivers/android/binder.c b/drivers/android/binder.c index 02df51ede095..85a6a7cb3cd1 100644 --- a/drivers/android/binder.c +++ b/drivers/android/binder.c @@ -230,7 +230,7 @@ static struct binder_transaction_log_entry *binder_transaction_log_add( struct binder_work { struct list_head entry; - enum { + enum binder_work_type { BINDER_WORK_TRANSACTION = 1, BINDER_WORK_TRANSACTION_COMPLETE, BINDER_WORK_RETURN_ERROR, @@ -917,27 +917,6 @@ static struct binder_work *binder_dequeue_work_head_ilocked( return w; } -/** - * binder_dequeue_work_head() - Dequeues the item at head of list - * @proc: binder_proc associated with list - * @list: list to dequeue head - * - * Removes the head of the list if there are items on the list - * - * Return: pointer dequeued binder_work, NULL if list was empty - */ -static struct binder_work *binder_dequeue_work_head( - struct binder_proc *proc, - struct list_head *list) -{ - struct binder_work *w; - - binder_inner_proc_lock(proc); - w = binder_dequeue_work_head_ilocked(list); - binder_inner_proc_unlock(proc); - return w; -} - static void binder_defer_work(struct binder_proc *proc, enum binder_deferred_state defer); static void binder_free_thread(struct binder_thread *thread); @@ -4753,13 +4732,17 @@ static void binder_release_work(struct binder_proc *proc, struct list_head *list) { struct binder_work *w; + enum binder_work_type wtype; while (1) { - w = binder_dequeue_work_head(proc, list); + binder_inner_proc_lock(proc); + w = binder_dequeue_work_head_ilocked(list); + wtype = w ? w->type : 0; + binder_inner_proc_unlock(proc); if (!w) return; - switch (w->type) { + switch (wtype) { case BINDER_WORK_TRANSACTION: { struct binder_transaction *t; @@ -4793,9 +4776,11 @@ static void binder_release_work(struct binder_proc *proc, kfree(death); binder_stats_deleted(BINDER_STAT_DEATH); } break; + case BINDER_WORK_NODE: + break; default: pr_err("unexpected work type, %d, not freed\n", - w->type); + wtype); break; } } From 205650744e175d581a549181b0345d8b0f0b2cfa Mon Sep 17 00:00:00 2001 From: Ravikanth Tuniki Date: Fri, 16 Oct 2020 15:48:51 +0530 Subject: [PATCH 02/14] ANDROID: ABI: update allowed list for QCOM Update the android/abi_gki_aarch64_qcom with recent symbol additions. Simple change and no need to update the .xml file, as no new symbol addition. Bug: 171100523 Change-Id: I5083548f18633b66b76d525209c52b4c44eded75 Signed-off-by: Ravikanth Tuniki --- android/abi_gki_aarch64_qcom | 3 +++ 1 file changed, 3 insertions(+) diff --git a/android/abi_gki_aarch64_qcom b/android/abi_gki_aarch64_qcom index 6c2539bdd013..ec52822cc991 100644 --- a/android/abi_gki_aarch64_qcom +++ b/android/abi_gki_aarch64_qcom @@ -870,6 +870,7 @@ find_next_zero_bit find_snd_usb_substream find_vma + find_vpid finish_wait firmware_request_nowarn flow_keys_basic_dissector @@ -1665,6 +1666,7 @@ phy_start phy_stop physvirt_offset + pid_task pinconf_generic_dt_node_to_map pinctrl_dev_get_drvdata pinctrl_force_default @@ -1975,6 +1977,7 @@ sched_clock sched_setattr sched_setscheduler + sched_setscheduler_nocheck schedule schedule_timeout schedule_timeout_interruptible From cbd55f8de66b64054669601d75184ae011a1523c Mon Sep 17 00:00:00 2001 From: Jaehyoung Choi Date: Mon, 19 Oct 2020 11:38:38 +0900 Subject: [PATCH 03/14] ANDROID: GKI: Update abi_gki_aarch64_exynos Leaf changes summary: 19 artifacts changed Changed leaf types summary: 0 leaf type changed Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 19 Added functions Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable 19 Added functions: [A] 'function void __sock_recv_timestamp(msghdr*, sock*, sk_buff*)' [A] 'function void __sock_recv_wifi_status(msghdr*, sock*, sk_buff*)' [A] 'function void __wake_up_locked_key(wait_queue_head*, unsigned int, void*)' [A] 'function void __wake_up_sync(wait_queue_head*, unsigned int, int)' [A] 'function void add_wait_queue_exclusive(wait_queue_head*, wait_queue_entry*)' [A] 'function bool cfg80211_chandef_valid(const cfg80211_chan_def*)' [A] 'function void cfg80211_conn_failed(net_device*, const u8*, nl80211_connect_failed_reason, gfp_t)' [A] 'function void cfg80211_ref_bss(wiphy*, cfg80211_bss*)' [A] 'function int dev_vprintk_emit(int, const device*, const char*, va_list)' [A] 'function nlattr** genl_family_attrbuf(const genl_family*)' [A] 'function int genlmsg_multicast_allns(const genl_family*, sk_buff*, u32, unsigned int, gfp_t)' [A] 'function i2c_client* i2c_new_device(i2c_adapter*, const i2c_board_info*)' [A] 'function int iio_convert_raw_to_processed(iio_channel*, int, int*, unsigned int)' [A] 'function int iio_get_channel_type(iio_channel*, iio_chan_type*)' [A] 'function bool rfkill_blocked(rfkill*)' [A] 'function int rtc_add_group(rtc_device*, const attribute_group*)' [A] 'function int rtc_set_time(rtc_device*, rtc_time*)' [A] 'function int snd_soc_dai_set_tristate(snd_soc_dai*, int)' [A] 'function int vprintk_emit(int, int, const char*, size_t, const char*, va_list)' Bug: 171029675 Signed-off-by: Jaehyoung Choi Change-Id: Ib4cc16e6ba55e4ba135ace7784aaaaf0eac4c00f --- android/abi_gki_aarch64.xml | 489 ++++++++++++++++++++++----------- android/abi_gki_aarch64_exynos | 87 ++++++ 2 files changed, 410 insertions(+), 166 deletions(-) diff --git a/android/abi_gki_aarch64.xml b/android/abi_gki_aarch64.xml index 88042d5b20bc..18c8c69aeec7 100644 --- a/android/abi_gki_aarch64.xml +++ b/android/abi_gki_aarch64.xml @@ -215,7 +215,9 @@ + + @@ -250,6 +252,8 @@ + + @@ -299,6 +303,7 @@ + @@ -522,7 +527,9 @@ + + @@ -544,6 +551,7 @@ + @@ -857,6 +865,7 @@ + @@ -1569,9 +1578,11 @@ + + @@ -1717,6 +1728,7 @@ + @@ -1821,11 +1833,13 @@ + + @@ -3025,6 +3039,7 @@ + @@ -3065,10 +3080,12 @@ + + @@ -3427,6 +3444,7 @@ + @@ -4206,6 +4224,7 @@ + @@ -15298,7 +15317,6 @@ - @@ -15318,6 +15336,20 @@ + + + + + + + + + + + + + + @@ -16102,6 +16134,8 @@ + + @@ -16915,7 +16949,7 @@ - + @@ -17032,7 +17066,7 @@ - + @@ -17092,8 +17126,8 @@ - - + + @@ -22722,6 +22756,13 @@ + + + + + + + @@ -31299,7 +31340,6 @@ - @@ -32094,7 +32134,6 @@ - @@ -39744,6 +39783,8 @@ + + @@ -39760,6 +39801,11 @@ + + + + + @@ -40797,6 +40843,7 @@ + @@ -40827,11 +40874,23 @@ + + + + + + + + + + + + @@ -53967,6 +54026,14 @@ + + + + + + + + @@ -55229,14 +55296,6 @@ - - - - - - - - @@ -55987,6 +56046,17 @@ + + + + + + + + + + + @@ -59320,7 +59390,7 @@ - + @@ -59645,17 +59715,6 @@ - - - - - - - - - - - @@ -64203,6 +64262,17 @@ + + + + + + + + + + + @@ -64365,7 +64435,7 @@ - + @@ -64411,8 +64481,6 @@ - - @@ -70760,6 +70828,20 @@ + + + + + + + + + + + + + + @@ -70902,6 +70984,7 @@ + @@ -71066,6 +71149,30 @@ + + + + + + + + + + + + + + + + + + + + + + + + @@ -88232,14 +88339,6 @@ - - - - - - - - @@ -88251,6 +88350,20 @@ + + + + + + + + + + + + + + @@ -92758,6 +92871,8 @@ + + @@ -92803,6 +92918,15 @@ + + + + + + + + + @@ -93072,7 +93196,7 @@ - + @@ -93298,6 +93422,7 @@ + @@ -99520,13 +99645,13 @@ - + - + - + @@ -99568,7 +99693,7 @@ - + @@ -103731,7 +103856,7 @@ - + @@ -103747,7 +103872,7 @@ - + @@ -103755,7 +103880,7 @@ - + @@ -103769,7 +103894,7 @@ - + @@ -103800,6 +103925,11 @@ + + + + + @@ -103813,6 +103943,18 @@ + + + + + + + + + + + + @@ -107618,6 +107760,10 @@ + + + + @@ -108670,29 +108816,7 @@ - - - - - - - - - - - - - - - - - - - - - - - + @@ -108985,7 +109109,7 @@ - + @@ -109029,18 +109153,18 @@ - + - + - + @@ -109167,32 +109291,6 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - @@ -111460,6 +111558,31 @@ + + + + + + + + + + + + + + + + + + + + + + + + + @@ -111484,6 +111607,7 @@ + @@ -114128,7 +114252,7 @@ - + @@ -116334,6 +116458,25 @@ + + + + + + + + + + + + + + + + + + + @@ -116383,11 +116526,11 @@ - + - + @@ -116399,29 +116542,41 @@ - + - + - - + + - + + + + + + + + + + + + + @@ -116510,17 +116665,6 @@ - - - - - - - - - - - @@ -116932,6 +117076,25 @@ + + + + + + + + + + + + + + + + + + + @@ -116947,6 +117110,18 @@ + + + + + + + + + + + + @@ -121642,14 +121817,6 @@ - - - - - - - - @@ -122094,6 +122261,11 @@ + + + + + @@ -122180,6 +122352,13 @@ + + + + + + + @@ -122367,6 +122546,8 @@ + + @@ -122390,6 +122571,10 @@ + + + + @@ -122922,6 +123107,11 @@ + + + + + @@ -123089,44 +123279,6 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - @@ -128225,6 +128377,11 @@ + + + + + @@ -129380,6 +129537,6 @@ diff --git a/android/abi_gki_aarch64_exynos b/android/abi_gki_aarch64_exynos index 0b41a3f16cad..3e86b71f22cd 100644 --- a/android/abi_gki_aarch64_exynos +++ b/android/abi_gki_aarch64_exynos @@ -3,6 +3,7 @@ add_timer_on add_uevent_var add_wait_queue + add_wait_queue_exclusive adjust_managed_page_count alarm_cancel alarm_init @@ -34,6 +35,7 @@ _bcd2bin bcmp _bin2bcd + bin2hex bio_crypt_should_process __bitmap_clear __bitmap_parse @@ -56,6 +58,7 @@ bpf_trace_run6 bpf_trace_run7 bpf_trace_run9 + __break_lease build_skb bus_find_device bus_for_each_dev @@ -78,9 +81,11 @@ __cfg80211_alloc_event_skb __cfg80211_alloc_reply_skb cfg80211_chandef_create + cfg80211_chandef_valid cfg80211_ch_switch_notify cfg80211_classify8021d cfg80211_connect_done + cfg80211_conn_failed cfg80211_del_sta_sinfo cfg80211_disconnected cfg80211_external_auth_request @@ -93,6 +98,7 @@ cfg80211_new_sta cfg80211_put_bss cfg80211_ready_on_channel + cfg80211_ref_bss cfg80211_remain_on_channel_expired cfg80211_roamed cfg80211_rx_mgmt @@ -106,9 +112,13 @@ __class_create class_create_file_ns class_destroy + class_dev_iter_exit + class_dev_iter_init + class_dev_iter_next class_find_device __class_register class_unregister + clear_inode clear_page clk_bulk_disable clk_bulk_enable @@ -206,14 +216,18 @@ csum_partial csum_tcpudp_nofold _ctype + d_add dapm_pinctrl_event dapm_regulator_event datagram_poll + d_drop + deactivate_locked_super default_llseek default_wake_function delayed_work_timer_fn del_timer del_timer_sync + dentry_open destroy_workqueue dev_alloc_name _dev_crit @@ -311,6 +325,7 @@ devm_request_threaded_irq devm_reset_control_array_get __devm_reset_control_get + devm_rtc_allocate_device devm_rtc_device_register devm_snd_dmaengine_pcm_register devm_snd_soc_register_card @@ -341,7 +356,10 @@ devres_release dev_set_mac_address dev_set_name + dev_vprintk_emit _dev_warn + dget_parent + d_instantiate disable_irq disable_irq_nosync disable_percpu_irq @@ -394,6 +412,7 @@ dma_free_attrs dma_get_slave_caps dma_get_slave_channel + d_make_root dmam_alloc_attrs dma_mmap_attrs dma_pool_alloc @@ -414,6 +433,7 @@ down_trylock down_write d_path + dput driver_find driver_find_device driver_register @@ -465,10 +485,19 @@ freq_qos_add_request freq_qos_remove_request freq_qos_update_request + fs_kobj + fsstack_copy_attr_all fwnode_property_present fwnode_property_read_u16_array generic_file_llseek + generic_file_mmap + generic_file_read_iter + generic_file_splice_read generic_handle_irq + generic_read_dir + generic_shutdown_super + genl_family_attrbuf + genlmsg_multicast_allns genlmsg_put genl_register_family genl_unregister_family @@ -542,6 +571,7 @@ i2c_del_driver i2c_for_each_dev i2c_get_adapter + i2c_new_device i2c_new_dummy i2c_put_adapter i2c_register_driver @@ -564,13 +594,17 @@ ieee80211_channel_to_freq_khz ieee80211_freq_khz_to_channel ieee80211_get_channel_khz + iget5_locked ignore_console_lock_warning + ihold iio_channel_get iio_channel_release + iio_convert_raw_to_processed iio_device_alloc iio_device_free __iio_device_register iio_device_unregister + iio_get_channel_type iio_read_channel_processed iio_read_channel_raw in4_pton @@ -582,6 +616,8 @@ init_timer_key init_wait_entry __init_waitqueue_head + inode_init_once + inode_init_owner input_allocate_device input_event input_free_device @@ -639,6 +675,7 @@ iounmap __iowrite32_copy ip_send_check + iput __irq_alloc_descs irq_create_mapping __irq_domain_add @@ -664,6 +701,7 @@ irq_to_desc irq_work_queue is_console_locked + iterate_dir jiffies jiffies_64 jiffies_64_to_clock_t @@ -673,7 +711,9 @@ kasprintf kernel_kobj kernel_read + kernel_restart kernel_write + kern_path keyslot_manager_create_passthrough keyslot_manager_private __kfifo_alloc @@ -752,10 +792,16 @@ llist_add_batch __local_bh_enable_ip __lock_buffer + lockref_get + lock_rename lock_sock_nested + lookup_one_len loops_per_jiffy + LZ4_decompress_safe map_vm_area + match_int match_string + match_token media_create_intf_link media_create_pad_link media_device_register_entity @@ -841,6 +887,7 @@ no_llseek nonseekable_open noop_llseek + notify_change nr_cpu_ids nr_irqs nsecs_to_jiffies @@ -916,6 +963,7 @@ of_usb_get_phy_mode of_usb_host_tpl_support oops_in_progress + pagecache_get_page panic panic_notifier_list param_array_ops @@ -929,6 +977,8 @@ param_ops_ullong param_ops_ulong param_set_uint + path_get + path_put pci_alloc_irq_vectors_affinity pci_bus_type pci_d3cold_disable @@ -1121,6 +1171,7 @@ register_chrdev_region register_console register_die_notifier + register_filesystem register_inet6addr_notifier register_inetaddr_notifier register_netdev @@ -1177,13 +1228,17 @@ reset_control_reset return_address rfkill_alloc + rfkill_blocked rfkill_destroy rfkill_register rfkill_unregister rps_needed + rtc_add_group rtc_class_close rtc_class_open rtc_read_time + __rtc_register_device + rtc_set_time rtc_time64_to_tm rtc_tm_to_time64 rtc_update_irq @@ -1211,6 +1266,7 @@ seq_printf seq_puts seq_read + set_anon_super set_cpus_allowed_ptr set_normalized_timespec64 set_page_dirty_lock @@ -1218,6 +1274,7 @@ sg_alloc_table sg_alloc_table_from_pages sg_copy_to_buffer + sget sg_free_table sg_init_one sg_init_table @@ -1230,8 +1287,11 @@ __sg_page_iter_start sg_pcopy_from_buffer sg_pcopy_to_buffer + simple_getattr simple_open simple_read_from_buffer + simple_setattr + simple_statfs simple_strtol simple_strtoul simple_write_to_buffer @@ -1301,6 +1361,7 @@ snd_soc_dai_set_fmt snd_soc_dai_set_sysclk snd_soc_dai_set_tdm_slot + snd_soc_dai_set_tristate snd_soc_dapm_add_routes snd_soc_dapm_disable_pin snd_soc_dapm_enable_pin @@ -1369,6 +1430,8 @@ sock_no_shutdown sock_no_socketpair sock_queue_rcv_skb + __sock_recv_timestamp + __sock_recv_wifi_status sock_register sock_unregister softnet_data @@ -1412,11 +1475,13 @@ strncat strncmp strncpy + strndup_user strnlen strnstr strpbrk strrchr strsep + strspn strstr submit_bh subsys_system_register @@ -1425,6 +1490,7 @@ __sync_dirty_buffer sync_file_create sync_file_get_fence + sync_filesystem synchronize_irq synchronize_rcu syscon_regmap_lookup_by_phandle @@ -1490,6 +1556,7 @@ __trace_puts trace_raw_output_prep trace_seq_printf + truncate_inode_pages try_module_get __tty_alloc_driver tty_flip_buffer_push @@ -1534,9 +1601,13 @@ ufshcd_system_resume ufshcd_system_suspend ufshcd_wb_ctrl + unlock_new_inode + unlock_page + unlock_rename unmap_mapping_range __unregister_chrdev unregister_chrdev_region + unregister_filesystem unregister_inet6addr_notifier unregister_inetaddr_notifier unregister_netdev @@ -1642,6 +1713,7 @@ usb_unregister_notify usb_wakeup_notification __usecs_to_jiffies + user_path_at_empty usleep_range v4l2_ctrl_handler_free v4l2_ctrl_handler_init_class @@ -1692,9 +1764,20 @@ vb2_streamon vb2_wait_for_all_buffers vfree + vfs_create + vfs_fallocate vfs_fsync + vfs_getattr + vfs_getxattr + vfs_link + vfs_listxattr vfs_llseek + vfs_mkdir + vfs_rename + vfs_rmdir + vfs_setxattr vfs_statx + vfs_unlink video_devdata video_device_alloc video_device_release @@ -1703,6 +1786,7 @@ video_unregister_device vmalloc vmalloc_to_page + vmalloc_to_pfn vmalloc_user vmap vmemmap @@ -1712,6 +1796,7 @@ vm_map_pages vm_map_ram vm_unmap_ram + vprintk_emit vscnprintf vsnprintf vsprintf @@ -1724,12 +1809,14 @@ wait_for_completion_timeout __wait_on_buffer __wake_up + __wake_up_locked_key wake_up_process wakeup_source_add wakeup_source_create wakeup_source_destroy wakeup_source_register wakeup_source_unregister + __wake_up_sync __warn_printk watchdog_init_timeout watchdog_register_device From ec46411eb4efb3366f1614663566a67bf2231c5b Mon Sep 17 00:00:00 2001 From: Christoph Hellwig Date: Thu, 30 Jul 2020 08:10:20 +0200 Subject: [PATCH 04/14] UPSTREAM: modules: mark ref_module static ref_module isn't used anywhere outside of module.c. Bug: 157965270 Bug: 171277690 Signed-off-by: Christoph Hellwig Signed-off-by: Jessica Yu (cherry picked from commit 7ef5264de773279b9f23b6cc8afb5addb30e970b) Signed-off-by: Greg Kroah-Hartman Change-Id: I68f39675f53b745664c833ac150d838563c78aae Signed-off-by: Greg Kroah-Hartman --- include/linux/module.h | 1 - kernel/module.c | 6 ++---- 2 files changed, 2 insertions(+), 5 deletions(-) diff --git a/include/linux/module.h b/include/linux/module.h index 996e81a51fbf..7b3500539cae 100644 --- a/include/linux/module.h +++ b/include/linux/module.h @@ -648,7 +648,6 @@ static inline void __module_get(struct module *module) #define symbol_put_addr(p) do { } while (0) #endif /* CONFIG_MODULE_UNLOAD */ -int ref_module(struct module *a, struct module *b); /* This is a #define so the string doesn't get put in every .o file */ #define module_name(mod) \ diff --git a/kernel/module.c b/kernel/module.c index 63c0a2d1db66..9a319c9447f7 100644 --- a/kernel/module.c +++ b/kernel/module.c @@ -866,7 +866,7 @@ static int add_module_usage(struct module *a, struct module *b) } /* Module a uses b: caller needs module_mutex() */ -int ref_module(struct module *a, struct module *b) +static int ref_module(struct module *a, struct module *b) { int err; @@ -885,7 +885,6 @@ int ref_module(struct module *a, struct module *b) } return 0; } -EXPORT_SYMBOL_GPL(ref_module); /* Clear the unload stuff of the module. */ static void module_unload_free(struct module *mod) @@ -1165,11 +1164,10 @@ static inline void module_unload_free(struct module *mod) { } -int ref_module(struct module *a, struct module *b) +static int ref_module(struct module *a, struct module *b) { return strong_try_module_get(b); } -EXPORT_SYMBOL_GPL(ref_module); static inline int module_unload_init(struct module *mod) { From 2951ba186e1705e8455a2c98df69e2d2ce2a90c7 Mon Sep 17 00:00:00 2001 From: Christoph Hellwig Date: Thu, 30 Jul 2020 08:10:21 +0200 Subject: [PATCH 05/14] UPSTREAM: modules: mark find_symbol static find_symbol is only used in module.c. Bug: 157965270 Bug: 171277690 Signed-off-by: Christoph Hellwig Signed-off-by: Jessica Yu (cherry picked from commit 773110470e2fa3839523384ae014f8a723c4d178) Signed-off-by: Greg Kroah-Hartman Change-Id: Ifd34f7a477be9ed1b7715ce966473f2898c5a975 Signed-off-by: Greg Kroah-Hartman --- include/linux/module.h | 11 ----------- kernel/module.c | 3 +-- 2 files changed, 1 insertion(+), 13 deletions(-) diff --git a/include/linux/module.h b/include/linux/module.h index 7b3500539cae..05215b486c1c 100644 --- a/include/linux/module.h +++ b/include/linux/module.h @@ -581,17 +581,6 @@ struct symsearch { bool unused; }; -/* - * Search for an exported symbol by name. - * - * Must be called with module_mutex held or preemption disabled. - */ -const struct kernel_symbol *find_symbol(const char *name, - struct module **owner, - const s32 **crc, - bool gplok, - bool warn); - /* * Walk the exported symbol table * diff --git a/kernel/module.c b/kernel/module.c index 9a319c9447f7..436ec9f6478e 100644 --- a/kernel/module.c +++ b/kernel/module.c @@ -582,7 +582,7 @@ static bool find_exported_symbol_in_section(const struct symsearch *syms, /* Find an exported symbol and return it, along with, (optional) crc and * (optional) module which owns it. Needs preempt disabled or module_mutex. */ -const struct kernel_symbol *find_symbol(const char *name, +static const struct kernel_symbol *find_symbol(const char *name, struct module **owner, const s32 **crc, bool gplok, @@ -605,7 +605,6 @@ const struct kernel_symbol *find_symbol(const char *name, pr_debug("Failed to find symbol %s\n", name); return NULL; } -EXPORT_SYMBOL_GPL(find_symbol); /* * Search for module by name: must hold module_mutex (or preempt disabled From 6cd6da665d3fcb4d456b44f669ca1daf7539cbaf Mon Sep 17 00:00:00 2001 From: Christoph Hellwig Date: Thu, 30 Jul 2020 08:10:22 +0200 Subject: [PATCH 06/14] UPSTREAM: modules: mark each_symbol_section static each_symbol_section is only used inside of module.c. Bug: 157965270 Bug: 171277690 Signed-off-by: Christoph Hellwig Signed-off-by: Jessica Yu (cherry picked from commit a54e04914c211b5678602a46b3ede5d82ec1327d) Signed-off-by: Greg Kroah-Hartman Change-Id: I5debe30f150847281874d9b2c47952f9036d37d2 --- include/linux/module.h | 9 --------- kernel/module.c | 3 +-- 2 files changed, 1 insertion(+), 11 deletions(-) diff --git a/include/linux/module.h b/include/linux/module.h index 05215b486c1c..70750f8856e1 100644 --- a/include/linux/module.h +++ b/include/linux/module.h @@ -581,15 +581,6 @@ struct symsearch { bool unused; }; -/* - * Walk the exported symbol table - * - * Must be called with module_mutex held or preemption disabled. - */ -bool each_symbol_section(bool (*fn)(const struct symsearch *arr, - struct module *owner, - void *data), void *data); - /* Returns 0 and fills in value, defined and namebuf, or -ERANGE if symnum out of range. */ int module_get_kallsym(unsigned int symnum, unsigned long *value, char *type, diff --git a/kernel/module.c b/kernel/module.c index 436ec9f6478e..b3f4a62f2ae8 100644 --- a/kernel/module.c +++ b/kernel/module.c @@ -419,7 +419,7 @@ static bool each_symbol_in_section(const struct symsearch *arr, } /* Returns true as soon as fn returns true, otherwise false. */ -bool each_symbol_section(bool (*fn)(const struct symsearch *arr, +static bool each_symbol_section(bool (*fn)(const struct symsearch *arr, struct module *owner, void *data), void *data) @@ -481,7 +481,6 @@ bool each_symbol_section(bool (*fn)(const struct symsearch *arr, } return false; } -EXPORT_SYMBOL_GPL(each_symbol_section); struct find_symbol_arg { /* Input */ From 68d5cd1dcb65d2fc15b87975278122827ed9cdf5 Mon Sep 17 00:00:00 2001 From: Christoph Hellwig Date: Thu, 30 Jul 2020 08:10:23 +0200 Subject: [PATCH 07/14] UPSTREAM: modules: unexport __module_text_address __module_text_address is only used by built-in code. Bug: 157965270 Bug: 171277690 Signed-off-by: Christoph Hellwig Signed-off-by: Jessica Yu (cherry picked from commit 3fe1e56d0e68b623dd62d8d38265d2a052e7e185) Signed-off-by: Greg Kroah-Hartman Change-Id: I1a9081c6fa3d2a6e27ede24a4fa2b6a220cd521d Signed-off-by: Greg Kroah-Hartman --- kernel/module.c | 1 - 1 file changed, 1 deletion(-) diff --git a/kernel/module.c b/kernel/module.c index b3f4a62f2ae8..8b40f32d8c3f 100644 --- a/kernel/module.c +++ b/kernel/module.c @@ -4561,7 +4561,6 @@ struct module *__module_text_address(unsigned long addr) } return mod; } -EXPORT_SYMBOL_GPL(__module_text_address); /* Don't grab lock, we're oopsing. */ void print_modules(void) From 684d5eaf063f5b0a8231acfb58990025348af894 Mon Sep 17 00:00:00 2001 From: Christoph Hellwig Date: Thu, 30 Jul 2020 08:10:24 +0200 Subject: [PATCH 08/14] UPSTREAM: modules: unexport __module_address __module_address is only used by built-in code. Bug: 157965270 Bug: 171277690 Signed-off-by: Christoph Hellwig Signed-off-by: Jessica Yu (cherry picked from commit 34e64705ad415ed7a816e60ef62b42fe6d1729d9) Signed-off-by: Greg Kroah-Hartman Change-Id: I9fb9339e17a7bac54afee8d301f33298a702fcb9 Signed-off-by: Greg Kroah-Hartman --- kernel/module.c | 1 - 1 file changed, 1 deletion(-) diff --git a/kernel/module.c b/kernel/module.c index 8b40f32d8c3f..9ca9fe6c4307 100644 --- a/kernel/module.c +++ b/kernel/module.c @@ -4522,7 +4522,6 @@ struct module *__module_address(unsigned long addr) } return mod; } -EXPORT_SYMBOL_GPL(__module_address); /* * is_module_text_address - is this address inside module code? From 35601d50151b2cd29a357ab85f9ff0222af9877e Mon Sep 17 00:00:00 2001 From: Christoph Hellwig Date: Thu, 30 Jul 2020 08:10:25 +0200 Subject: [PATCH 09/14] UPSTREAM: modules: rename the licence field in struct symsearch to license Use the same spelling variant as the rest of the file. Bug: 157965270 Bug: 171277690 Signed-off-by: Christoph Hellwig Signed-off-by: Jessica Yu (cherry picked from commit cd8732cdcc37d7077c4fa2c966b748c0662b607e) Signed-off-by: Greg Kroah-Hartman Change-Id: I0ad6d1dcbe39053566bb922b9a71359f753df85c --- include/linux/module.h | 2 +- kernel/module.c | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/include/linux/module.h b/include/linux/module.h index 70750f8856e1..3926d5ae1ff1 100644 --- a/include/linux/module.h +++ b/include/linux/module.h @@ -577,7 +577,7 @@ struct symsearch { NOT_GPL_ONLY, GPL_ONLY, WILL_BE_GPL_ONLY, - } licence; + } license; bool unused; }; diff --git a/kernel/module.c b/kernel/module.c index 9ca9fe6c4307..077aec753bb7 100644 --- a/kernel/module.c +++ b/kernel/module.c @@ -501,9 +501,9 @@ static bool check_exported_symbol(const struct symsearch *syms, struct find_symbol_arg *fsa = data; if (!fsa->gplok) { - if (syms->licence == GPL_ONLY) + if (syms->license == GPL_ONLY) return false; - if (syms->licence == WILL_BE_GPL_ONLY && fsa->warn) { + if (syms->license == WILL_BE_GPL_ONLY && fsa->warn) { pr_warn("Symbol %s is being used by a non-GPL module, " "which will not be allowed in the future\n", fsa->name); From f39710f356204024cd0428c9b9e0ad336f875efa Mon Sep 17 00:00:00 2001 From: Christoph Hellwig Date: Thu, 30 Jul 2020 08:10:26 +0200 Subject: [PATCH 10/14] UPSTREAM: modules: return licensing information from find_symbol Report the GPLONLY status through a new argument. Bug: 157965270 Bug: 171277690 Signed-off-by: Christoph Hellwig Signed-off-by: Jessica Yu (cherry picked from commit ef1dac6021cc8ec5de02ce31722bf26ac4ed5523) Signed-off-by: Greg Kroah-Hartman Change-Id: I93285e06e380509b11356256da4d3d5a8738e252 --- include/linux/module.h | 2 +- kernel/module.c | 16 +++++++++++----- 2 files changed, 12 insertions(+), 6 deletions(-) diff --git a/include/linux/module.h b/include/linux/module.h index 3926d5ae1ff1..0f5b9c3ce047 100644 --- a/include/linux/module.h +++ b/include/linux/module.h @@ -573,7 +573,7 @@ struct module *find_module(const char *name); struct symsearch { const struct kernel_symbol *start, *stop; const s32 *crcs; - enum { + enum mod_license { NOT_GPL_ONLY, GPL_ONLY, WILL_BE_GPL_ONLY, diff --git a/kernel/module.c b/kernel/module.c index 077aec753bb7..a1a9997833ef 100644 --- a/kernel/module.c +++ b/kernel/module.c @@ -492,6 +492,7 @@ struct find_symbol_arg { struct module *owner; const s32 *crc; const struct kernel_symbol *sym; + enum mod_license license; }; static bool check_exported_symbol(const struct symsearch *syms, @@ -525,6 +526,7 @@ static bool check_exported_symbol(const struct symsearch *syms, fsa->owner = owner; fsa->crc = symversion(syms->crcs, symnum); fsa->sym = &syms->start[symnum]; + fsa->license = syms->license; return true; } @@ -584,6 +586,7 @@ static bool find_exported_symbol_in_section(const struct symsearch *syms, static const struct kernel_symbol *find_symbol(const char *name, struct module **owner, const s32 **crc, + enum mod_license *license, bool gplok, bool warn) { @@ -598,6 +601,8 @@ static const struct kernel_symbol *find_symbol(const char *name, *owner = fsa.owner; if (crc) *crc = fsa.crc; + if (license) + *license = fsa.license; return fsa.sym; } @@ -1071,7 +1076,7 @@ void __symbol_put(const char *symbol) struct module *owner; preempt_disable(); - if (!find_symbol(symbol, &owner, NULL, true, false)) + if (!find_symbol(symbol, &owner, NULL, NULL, true, false)) BUG(); module_put(owner); preempt_enable(); @@ -1348,7 +1353,7 @@ static inline int check_modstruct_version(const struct load_info *info, * locking is necessary -- use preempt_disable() to placate lockdep. */ preempt_disable(); - if (!find_symbol("module_layout", NULL, &crc, true, false)) { + if (!find_symbol("module_layout", NULL, &crc, NULL, true, false)) { preempt_enable(); BUG(); } @@ -1432,6 +1437,7 @@ static const struct kernel_symbol *resolve_symbol(struct module *mod, struct module *owner; const struct kernel_symbol *sym; const s32 *crc; + enum mod_license license; int err; /* @@ -1441,7 +1447,7 @@ static const struct kernel_symbol *resolve_symbol(struct module *mod, */ sched_annotate_sleep(); mutex_lock(&module_mutex); - sym = find_symbol(name, &owner, &crc, + sym = find_symbol(name, &owner, &crc, &license, !(mod->taints & (1 << TAINT_PROPRIETARY_MODULE)), true); if (!sym) goto unlock; @@ -2263,7 +2269,7 @@ void *__symbol_get(const char *symbol) const struct kernel_symbol *sym; preempt_disable(); - sym = find_symbol(symbol, &owner, NULL, true, true); + sym = find_symbol(symbol, &owner, NULL, NULL, true, true); if (sym && strong_try_module_get(owner)) sym = NULL; preempt_enable(); @@ -2298,7 +2304,7 @@ static int verify_exported_symbols(struct module *mod) for (i = 0; i < ARRAY_SIZE(arr); i++) { for (s = arr[i].sym; s < arr[i].sym + arr[i].num; s++) { if (find_symbol(kernel_symbol_name(s), &owner, NULL, - true, false)) { + NULL, true, false)) { pr_err("%s: exports duplicate symbol %s" " (owned by %s)\n", mod->name, kernel_symbol_name(s), From 35b560985bf9890e62a5f58c3ec79a9966da2fba Mon Sep 17 00:00:00 2001 From: Christoph Hellwig Date: Tue, 28 Jul 2020 23:33:33 +0200 Subject: [PATCH 11/14] UPSTREAM: modules: inherit TAINT_PROPRIETARY_MODULE If a TAINT_PROPRIETARY_MODULE exports symbol, inherit the taint flag for all modules importing these symbols, and don't allow loading symbols from TAINT_PROPRIETARY_MODULE modules if the module previously imported gplonly symbols. Add a anti-circumvention devices so people don't accidentally get themselves into trouble this way. Comment from Greg: "Ah, the proven-to-be-illegal "GPL Condom" defense :)" Bug: 171277690 [jeyu: pr_info -> pr_err and pr_warn as per discussion] Link: http://lore.kernel.org/r/20200730162957.GA22469@lst.de Acked-by: Daniel Vetter Reviewed-by: Greg Kroah-Hartman Signed-off-by: Christoph Hellwig Signed-off-by: Jessica Yu (cherry picked from commit 262e6ae7081df304fc625cf368d5c2cbba2bb991) Signed-off-by: Greg Kroah-Hartman Change-Id: Id7c1af6bb8523bc39bda1efc661929d9ea0ccb20 --- include/linux/module.h | 1 + kernel/module.c | 26 ++++++++++++++++++++++++++ 2 files changed, 27 insertions(+) diff --git a/include/linux/module.h b/include/linux/module.h index 0f5b9c3ce047..4f71785d6bbd 100644 --- a/include/linux/module.h +++ b/include/linux/module.h @@ -382,6 +382,7 @@ struct module { unsigned int num_gpl_syms; const struct kernel_symbol *gpl_syms; const s32 *gpl_crcs; + bool using_gplonly_symbols; #ifdef CONFIG_UNUSED_SYMBOLS /* unused exported symbols. */ diff --git a/kernel/module.c b/kernel/module.c index a1a9997833ef..aca3a6355165 100644 --- a/kernel/module.c +++ b/kernel/module.c @@ -1427,6 +1427,24 @@ static int verify_namespace_is_imported(const struct load_info *info, return 0; } +static bool inherit_taint(struct module *mod, struct module *owner) +{ + if (!owner || !test_bit(TAINT_PROPRIETARY_MODULE, &owner->taints)) + return true; + + if (mod->using_gplonly_symbols) { + pr_err("%s: module using GPL-only symbols uses symbols from proprietary module %s.\n", + mod->name, owner->name); + return false; + } + + if (!test_bit(TAINT_PROPRIETARY_MODULE, &mod->taints)) { + pr_warn("%s: module uses symbols from proprietary module %s, inheriting taint.\n", + mod->name, owner->name); + set_bit(TAINT_PROPRIETARY_MODULE, &mod->taints); + } + return true; +} /* Resolve a symbol for this module. I.e. if we find one, record usage. */ static const struct kernel_symbol *resolve_symbol(struct module *mod, @@ -1452,6 +1470,14 @@ static const struct kernel_symbol *resolve_symbol(struct module *mod, if (!sym) goto unlock; + if (license == GPL_ONLY) + mod->using_gplonly_symbols = true; + + if (!inherit_taint(mod, owner)) { + sym = NULL; + goto getname; + } + if (!check_version(info, name, mod, crc)) { sym = ERR_PTR(-EINVAL); goto getname; From db96212bdede8915d9769eddcd378f70a8e4d279 Mon Sep 17 00:00:00 2001 From: Greg Kroah-Hartman Date: Tue, 20 Oct 2020 16:49:28 +0200 Subject: [PATCH 12/14] ANDROID: GKI: fix ABI breakage in module.h commit 262e6ae7081d ("modules: inherit TAINT_PROPRIETARY_MODULE") changes the size of 'struct module' a bit by adding a single boolean value to the middle. Move things around a bit and take up a space to preserve the abi so that nothing changes with the abi before that commit was merged. This might be able to be dropped at the next Android KABI "Break", if one happens. Bug: 171277690 Fixes: 262e6ae7081d ("modules: inherit TAINT_PROPRIETARY_MODULE") Signed-off-by: Greg Kroah-Hartman Change-Id: Ie31a6fcea384ad665248c87f7abfde4d214da70a --- include/linux/module.h | 8 ++++++-- kernel/module.c | 4 ++-- 2 files changed, 8 insertions(+), 4 deletions(-) diff --git a/include/linux/module.h b/include/linux/module.h index 4f71785d6bbd..5246cbce5881 100644 --- a/include/linux/module.h +++ b/include/linux/module.h @@ -346,6 +346,11 @@ struct klp_modinfo { }; #endif +struct module_kabi_preserve_1 { + u64 using_gplonly_symbols:1; + u64 free:63; +}; + struct module { enum module_state state; @@ -382,7 +387,6 @@ struct module { unsigned int num_gpl_syms; const struct kernel_symbol *gpl_syms; const s32 *gpl_crcs; - bool using_gplonly_symbols; #ifdef CONFIG_UNUSED_SYMBOLS /* unused exported symbols. */ @@ -516,7 +520,7 @@ struct module { struct error_injection_entry *ei_funcs; unsigned int num_ei_funcs; #endif - ANDROID_KABI_RESERVE(1); + ANDROID_KABI_USE(1, struct module_kabi_preserve_1 m1); ANDROID_KABI_RESERVE(2); ANDROID_KABI_RESERVE(3); ANDROID_KABI_RESERVE(4); diff --git a/kernel/module.c b/kernel/module.c index aca3a6355165..60f6a995265c 100644 --- a/kernel/module.c +++ b/kernel/module.c @@ -1432,7 +1432,7 @@ static bool inherit_taint(struct module *mod, struct module *owner) if (!owner || !test_bit(TAINT_PROPRIETARY_MODULE, &owner->taints)) return true; - if (mod->using_gplonly_symbols) { + if (mod->m1.using_gplonly_symbols) { pr_err("%s: module using GPL-only symbols uses symbols from proprietary module %s.\n", mod->name, owner->name); return false; @@ -1471,7 +1471,7 @@ static const struct kernel_symbol *resolve_symbol(struct module *mod, goto unlock; if (license == GPL_ONLY) - mod->using_gplonly_symbols = true; + mod->m1.using_gplonly_symbols = true; if (!inherit_taint(mod, owner)) { sym = NULL; From f1ff4a467862cf04052e30f56c0ae1c1a575f410 Mon Sep 17 00:00:00 2001 From: wangzun1 Date: Tue, 20 Oct 2020 19:51:43 +0800 Subject: [PATCH 13/14] ANDROID: GKI: update xiaomi symbol list Leaf changes summary: 0 artifact changed Changed leaf types summary: 0 leaf type changed Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 0 Added function Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable Bug: 171162194 Signed-off-by: Zun Wang Change-Id: I169bcdd14878392ef57aec9c303a421800278610 Signed-off-by: Greg Kroah-Hartman --- android/abi_gki_aarch64_xiaomi | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/android/abi_gki_aarch64_xiaomi b/android/abi_gki_aarch64_xiaomi index 7b58413581e8..95acdab2fb70 100644 --- a/android/abi_gki_aarch64_xiaomi +++ b/android/abi_gki_aarch64_xiaomi @@ -16,6 +16,10 @@ regcache_drop_region snd_soc_dapm_del_routes +# required by tfa98xx_dlkm.ko + device_remove_bin_file + snd_pcm_hw_constraint_mask64 + # required by q6_dlkm.ko down_interruptible __kfifo_alloc From e17d9fc5315f6e4cfa93a99ccacdeb61d343e770 Mon Sep 17 00:00:00 2001 From: Abdulla Kamar Date: Tue, 20 Oct 2020 21:36:20 +1100 Subject: [PATCH 14/14] ANDROID: GKI: Enable CONFIG_X86_X2APIC Enable support for CONFIG_X86_X2APIC, if available. This speeds up operation in a hypervisor, as APIC is handled via MSRs. Bug: 171287650 Change-Id: Ie3cf57d07b8dde08ec609dfb031cfb0029218501 Signed-off-by: Abdulla Kamar --- arch/x86/configs/gki_defconfig | 1 + 1 file changed, 1 insertion(+) diff --git a/arch/x86/configs/gki_defconfig b/arch/x86/configs/gki_defconfig index 5f6b1e4dd7f3..066dac7dfa88 100644 --- a/arch/x86/configs/gki_defconfig +++ b/arch/x86/configs/gki_defconfig @@ -48,6 +48,7 @@ CONFIG_SLAB_FREELIST_HARDENED=y CONFIG_SHUFFLE_PAGE_ALLOCATOR=y CONFIG_PROFILING=y CONFIG_SMP=y +CONFIG_X86_X2APIC=y CONFIG_HYPERVISOR_GUEST=y CONFIG_PARAVIRT=y CONFIG_NR_CPUS=32