From 8038bc2bb90a14027e85669553263cfc6468ac9d Mon Sep 17 00:00:00 2001 From: "jian.gong" Date: Thu, 24 Dec 2020 19:36:54 +0800 Subject: [PATCH 01/18] ANDROID: ABI: add symbols of __dynamic_netdev_dbg to unisoc Add symbols of __dynamic_netdev_dbg to unisoc, and updates the ABI representation accordingly. Leaf changes summary: 1 artifact changed Changed leaf types summary: 0 leaf type changed Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable 1 Added function: [A] 'function void __dynamic_netdev_dbg(_ddebug*, const net_device*, const char*, ...)' Bug: 160255258 Change-Id: I357d2f430fbe76f061fbc85919eaba9f95ce7e2e Signed-off-by: jian.gong --- android/abi_gki_aarch64.xml | 946 ++++++++++++++++----------------- android/abi_gki_aarch64_unisoc | 2 + 2 files changed, 450 insertions(+), 498 deletions(-) diff --git a/android/abi_gki_aarch64.xml b/android/abi_gki_aarch64.xml index 541fa1afd553..fd29c947a4cb 100644 --- a/android/abi_gki_aarch64.xml +++ b/android/abi_gki_aarch64.xml @@ -88,6 +88,7 @@ + @@ -4701,7 +4702,7 @@ - + @@ -4737,6 +4738,7 @@ + @@ -11463,23 +11465,6 @@ - - - - - - - - - - - - - - - - - @@ -14489,6 +14474,23 @@ + + + + + + + + + + + + + + + + + @@ -15486,20 +15488,6 @@ - - - - - - - - - - - - - - @@ -27306,6 +27294,7 @@ + @@ -27345,7 +27334,7 @@ - + @@ -27402,7 +27391,6 @@ - @@ -33111,7 +33099,7 @@ - + @@ -34495,7 +34483,7 @@ - + @@ -34756,7 +34744,7 @@ - + @@ -35767,7 +35755,7 @@ - + @@ -37331,8 +37319,6 @@ - - @@ -37842,6 +37828,8 @@ + + @@ -54289,7 +54277,6 @@ - @@ -54377,6 +54364,8 @@ + + @@ -54559,7 +54548,6 @@ - @@ -54783,6 +54771,17 @@ + + + + + + + + + + + @@ -56061,6 +56060,14 @@ + + + + + + + + @@ -72214,30 +72221,6 @@ - - - - - - - - - - - - - - - - - - - - - - - - @@ -82114,17 +82097,6 @@ - - - - - - - - - - - @@ -82418,6 +82390,17 @@ + + + + + + + + + + + @@ -88359,7 +88342,7 @@ - + @@ -88585,7 +88568,6 @@ - @@ -88605,7 +88587,7 @@ - + @@ -88784,27 +88766,27 @@ - - + + - + - + - + - + @@ -89454,14 +89436,6 @@ - - - - - - - - @@ -89517,6 +89491,14 @@ + + + + + + + + @@ -89528,6 +89510,20 @@ + + + + + + + + + + + + + + @@ -89553,6 +89549,14 @@ + + + + + + + + @@ -89591,14 +89595,6 @@ - - - - - - - - @@ -89965,23 +89961,6 @@ - - - - - - - - - - - - - - - - - @@ -90856,6 +90835,23 @@ + + + + + + + + + + + + + + + + + @@ -91583,7 +91579,7 @@ - + @@ -91729,64 +91725,6 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - @@ -100786,13 +100724,13 @@ - + - + - + @@ -100834,7 +100772,7 @@ - + @@ -103730,6 +103668,23 @@ + + + + + + + + + + + + + + + + + @@ -104997,7 +104952,7 @@ - + @@ -105013,7 +104968,7 @@ - + @@ -105021,7 +104976,7 @@ - + @@ -105035,7 +104990,7 @@ - + @@ -107156,6 +107111,13 @@ + + + + + + + @@ -108982,9 +108944,240 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -109137,7 +109330,18 @@ + + + + + + + + + + + @@ -109326,6 +109530,13 @@ + + + + + + + @@ -109333,6 +109544,10 @@ + + + + @@ -109759,18 +109974,15 @@ - + - + - + - - - - + @@ -109778,7 +109990,7 @@ - + @@ -115495,7 +115707,7 @@ - + @@ -117898,17 +118110,6 @@ - - - - - - - - - - - @@ -118320,268 +118521,7 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - @@ -118665,17 +118605,6 @@ - - - - - - - - - - - @@ -123320,25 +123249,6 @@ - - - - - - - - - - - - - - - - - - - @@ -124814,6 +124724,44 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -126871,6 +126819,8 @@ + + @@ -130980,6 +130930,6 @@ diff --git a/android/abi_gki_aarch64_unisoc b/android/abi_gki_aarch64_unisoc index 0f3c2df59e3b..4266cbe0bcea 100644 --- a/android/abi_gki_aarch64_unisoc +++ b/android/abi_gki_aarch64_unisoc @@ -64,6 +64,7 @@ complete complete_all config_ep_by_speed + config_group_init_type_name console_lock console_unlock __const_udelay @@ -186,6 +187,7 @@ dst_release dump_stack __dynamic_dev_dbg + __dynamic_netdev_dbg __dynamic_pr_debug enable_irq ether_setup From 032e643834def0159c90a0a3612a278cf6d33163 Mon Sep 17 00:00:00 2001 From: Zhiqiang Tu Date: Fri, 25 Dec 2020 13:05:31 +0800 Subject: [PATCH 02/18] ANDROID: ABI: Update allowed list for QCOM Leaf changes summary: 0 artifact changed Changed leaf types summary: 0 leaf type changed Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 0 Added function Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable Bug: 176306856 Change-Id: I52e0bbea0f41d97ca4241f6309babfad7dac82f8 Signed-off-by: Zhiqiang Tu --- android/abi_gki_aarch64_qcom | 1 + 1 file changed, 1 insertion(+) diff --git a/android/abi_gki_aarch64_qcom b/android/abi_gki_aarch64_qcom index a09d7f31e4f1..b4744eb24073 100644 --- a/android/abi_gki_aarch64_qcom +++ b/android/abi_gki_aarch64_qcom @@ -1041,6 +1041,7 @@ __hwspin_unlock hypervisor_kobj i2c_add_adapter + i2c_add_numbered_adapter i2c_del_adapter i2c_del_driver i2c_get_dma_safe_msg_buf From a9911f2a9a231c0dff14d3a5a0c98cf35bb279dc Mon Sep 17 00:00:00 2001 From: Will Deacon Date: Fri, 20 Nov 2020 13:28:01 +0000 Subject: [PATCH 03/18] UPSTREAM: arm64: pgtable: Fix pte_accessible() pte_accessible() is used by ptep_clear_flush() to figure out whether TLB invalidation is necessary when unmapping pages for reclaim. Although our implementation is correct according to the architecture, returning true only for valid, young ptes in the absence of racing page-table modifications, this is in fact flawed due to lazy invalidation of old ptes in ptep_clear_flush_young() where we elide the expensive DSB instruction for completing the TLB invalidation. Rather than penalise the aging path, adjust pte_accessible() to return true for any valid pte, even if the access flag is cleared. Bug: 176475096 Change-Id: Ifd7919b4e9b790a94802b0115f93a9a260757036 Cc: Fixes: 76c714be0e5e ("arm64: pgtable: implement pte_accessible()") Reported-by: Yu Zhao Acked-by: Yu Zhao Reviewed-by: Minchan Kim Reviewed-by: Catalin Marinas Link: https://lore.kernel.org/r/20201120143557.6715-2-will@kernel.org Signed-off-by: Will Deacon (cherry picked from commit 07509e10dcc77627f8b6a57381e878fe269958d3) Signed-off-by: Isaac J. Manjarres --- arch/arm64/include/asm/pgtable.h | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/arch/arm64/include/asm/pgtable.h b/arch/arm64/include/asm/pgtable.h index 41dd4b1f0ccb..ac6bd56e970d 100644 --- a/arch/arm64/include/asm/pgtable.h +++ b/arch/arm64/include/asm/pgtable.h @@ -98,8 +98,6 @@ extern unsigned long empty_zero_page[PAGE_SIZE / sizeof(unsigned long)]; #define pte_valid(pte) (!!(pte_val(pte) & PTE_VALID)) #define pte_valid_not_user(pte) \ ((pte_val(pte) & (PTE_VALID | PTE_USER)) == PTE_VALID) -#define pte_valid_young(pte) \ - ((pte_val(pte) & (PTE_VALID | PTE_AF)) == (PTE_VALID | PTE_AF)) #define pte_valid_user(pte) \ ((pte_val(pte) & (PTE_VALID | PTE_USER)) == (PTE_VALID | PTE_USER)) @@ -107,9 +105,12 @@ extern unsigned long empty_zero_page[PAGE_SIZE / sizeof(unsigned long)]; * Could the pte be present in the TLB? We must check mm_tlb_flush_pending * so that we don't erroneously return false for pages that have been * remapped as PROT_NONE but are yet to be flushed from the TLB. + * Note that we can't make any assumptions based on the state of the access + * flag, since ptep_clear_flush_young() elides a DSB when invalidating the + * TLB. */ #define pte_accessible(mm, pte) \ - (mm_tlb_flush_pending(mm) ? pte_present(pte) : pte_valid_young(pte)) + (mm_tlb_flush_pending(mm) ? pte_present(pte) : pte_valid(pte)) /* * p??_access_permitted() is true for valid user mappings (subject to the From f85485b30163db172b81a5b85f8beeeb505e4b73 Mon Sep 17 00:00:00 2001 From: Jeehong Kim Date: Tue, 15 Dec 2020 14:51:07 +0900 Subject: [PATCH 04/18] ANDROID: ABI: update allowed list for galaxy Leaf changes summary: 3 artifacts changed Changed leaf types summary: 0 leaf type changed Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 2 Added variables 1 Added function: [A] 'function int tracepoint_probe_unregister(tracepoint*, void*, void*)' 2 Added variables: [A] 'tracepoint __tracepoint_android_vh_wq_lockup_pool' [A] 'rq runqueues' Bug: 175649831 Signed-off-by: Jeehong Kim Change-Id: I2e0c8591188e68f82bfbe97acba02aee875f9621 --- android/abi_gki_aarch64.xml | 282 +++++++++++++++++++-------------- android/abi_gki_aarch64_galaxy | 3 + 2 files changed, 169 insertions(+), 116 deletions(-) diff --git a/android/abi_gki_aarch64.xml b/android/abi_gki_aarch64.xml index fd29c947a4cb..5c4b2abf4767 100644 --- a/android/abi_gki_aarch64.xml +++ b/android/abi_gki_aarch64.xml @@ -3820,6 +3820,7 @@ + @@ -4457,6 +4458,7 @@ + @@ -4559,6 +4561,7 @@ + @@ -4702,7 +4705,7 @@ - + @@ -11465,6 +11468,23 @@ + + + + + + + + + + + + + + + + + @@ -14474,23 +14494,6 @@ - - - - - - - - - - - - - - - - - @@ -14968,7 +14971,7 @@ - + @@ -15468,7 +15471,6 @@ - @@ -16272,6 +16274,8 @@ + + @@ -17090,7 +17094,7 @@ - + @@ -17207,7 +17211,7 @@ - + @@ -17267,8 +17271,8 @@ - - + + @@ -22657,6 +22661,7 @@ + @@ -37319,6 +37324,8 @@ + + @@ -37786,6 +37793,14 @@ + + + + + + + + @@ -37828,8 +37843,6 @@ - - @@ -52953,7 +52966,7 @@ - + @@ -52961,7 +52974,7 @@ - + @@ -53403,7 +53416,7 @@ - + @@ -53454,7 +53467,7 @@ - + @@ -53680,7 +53693,7 @@ - + @@ -59704,7 +59717,6 @@ - @@ -65360,7 +65372,7 @@ - + @@ -65406,8 +65418,6 @@ - - @@ -72057,6 +72067,7 @@ + @@ -81041,7 +81052,7 @@ - + @@ -81465,7 +81476,6 @@ - @@ -81536,7 +81546,7 @@ - + @@ -81626,12 +81636,12 @@ - + - + - + @@ -81724,7 +81734,7 @@ - + @@ -82840,12 +82850,12 @@ - + - + @@ -88342,7 +88352,7 @@ - + @@ -88568,6 +88578,7 @@ + @@ -88587,7 +88598,7 @@ - + @@ -88766,27 +88777,27 @@ - - + + - + - + - + - + @@ -89114,7 +89125,7 @@ - + @@ -89961,6 +89972,23 @@ + + + + + + + + + + + + + + + + + @@ -90835,23 +90863,6 @@ - - - - - - - - - - - - - - - - - @@ -91579,7 +91590,7 @@ - + @@ -91725,6 +91736,64 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -93816,14 +93885,6 @@ - - - - - - - - @@ -94277,6 +94338,7 @@ + @@ -103668,23 +103730,6 @@ - - - - - - - - - - - - - - - - - @@ -106498,6 +106543,12 @@ + + + + + + @@ -108054,7 +108105,7 @@ - + @@ -108081,7 +108132,7 @@ - + @@ -109974,23 +110025,12 @@ - - - - - - - - - - - - + @@ -110283,7 +110323,7 @@ - + @@ -117446,7 +117486,7 @@ - + @@ -117542,7 +117582,7 @@ - + @@ -117557,7 +117597,6 @@ - @@ -117716,7 +117755,7 @@ - + @@ -117814,7 +117853,7 @@ - + @@ -118110,6 +118149,17 @@ + + + + + + + + + + + diff --git a/android/abi_gki_aarch64_galaxy b/android/abi_gki_aarch64_galaxy index cbe1f884a220..e460d3ff7965 100644 --- a/android/abi_gki_aarch64_galaxy +++ b/android/abi_gki_aarch64_galaxy @@ -161,6 +161,7 @@ __tracepoint_android_vh_is_fpsimd_save __tracepoint_android_vh_kfree_skb __tracepoint_android_vh_ptype_head + __tracepoint_android_vh_wq_lockup_pool __tracepoint_device_pm_callback_end __tracepoint_device_pm_callback_start __tracepoint_gpu_mem_total @@ -2007,6 +2008,7 @@ rtnl_unlock rt_mutex_lock rt_mutex_unlock + runqueues save_stack_trace save_stack_trace_tsk sched_clock @@ -2400,6 +2402,7 @@ trace_raw_output_prep trace_seq_printf tracepoint_probe_register + tracepoint_probe_unregister tracing_off truncate_inode_pages try_module_get From c29fbd7cd7287699e3a8f6fdb13f71870214d9bb Mon Sep 17 00:00:00 2001 From: Saravana Kannan Date: Wed, 4 Nov 2020 12:54:30 -0800 Subject: [PATCH 05/18] UPSTREAM: driver core: Fix lockdep warning on wfs_lock There's a potential deadlock with the following cycle: wfs_lock --> device_links_lock --> kn->count Fix this by simply dropping the lock around a list_empty() check that's just exported to a sysfs file. The sysfs file output is an instantaneous check anyway and the lock doesn't really add any protection. Lockdep log: [ 48.808132] [ 48.808132] the existing dependency chain (in reverse order) is: [ 48.809069] [ 48.809069] -> #2 (kn->count){++++}: [ 48.809707] __kernfs_remove.llvm.7860393000964815146+0x2d4/0x460 [ 48.810537] kernfs_remove_by_name_ns+0x54/0x9c [ 48.811171] sysfs_remove_file_ns+0x18/0x24 [ 48.811762] device_del+0x2b8/0x5a8 [ 48.812269] __device_link_del+0x98/0xb8 [ 48.812829] device_links_driver_bound+0x210/0x2d8 [ 48.813496] driver_bound+0x44/0xf8 [ 48.814000] really_probe+0x340/0x6e0 [ 48.814526] driver_probe_device+0xb8/0x100 [ 48.815117] device_driver_attach+0x78/0xb8 [ 48.815708] __driver_attach+0xe0/0x194 [ 48.816255] bus_for_each_dev+0xa8/0x11c [ 48.816816] driver_attach+0x24/0x30 [ 48.817331] bus_add_driver+0x100/0x1e0 [ 48.817880] driver_register+0x78/0x114 [ 48.818427] __platform_driver_register+0x44/0x50 [ 48.819089] 0xffffffdbb3227038 [ 48.819551] do_one_initcall+0xd8/0x1e0 [ 48.820099] do_init_module+0xd8/0x298 [ 48.820636] load_module+0x3afc/0x44c8 [ 48.821173] __arm64_sys_finit_module+0xbc/0xf0 [ 48.821807] el0_svc_common+0xbc/0x1d0 [ 48.822344] el0_svc_handler+0x74/0x98 [ 48.822882] el0_svc+0x8/0xc [ 48.823310] [ 48.823310] -> #1 (device_links_lock){+.+.}: [ 48.824036] __mutex_lock_common+0xe0/0xe44 [ 48.824626] mutex_lock_nested+0x28/0x34 [ 48.825185] device_link_add+0xd4/0x4ec [ 48.825734] of_link_to_suppliers+0x158/0x204 [ 48.826347] of_fwnode_add_links+0x50/0x64 [ 48.826928] device_link_add_missing_supplier_links+0x90/0x11c [ 48.827725] fw_devlink_resume+0x58/0x130 [ 48.828296] of_platform_default_populate_init+0xb4/0xd0 [ 48.829030] do_one_initcall+0xd8/0x1e0 [ 48.829578] do_initcall_level+0xb8/0xcc [ 48.830137] do_basic_setup+0x60/0x7c [ 48.830662] kernel_init_freeable+0x128/0x1ac [ 48.831275] kernel_init+0x18/0x29c [ 48.831781] ret_from_fork+0x10/0x18 [ 48.832297] [ 48.832297] -> #0 (wfs_lock){+.+.}: [ 48.832922] __lock_acquire+0xe04/0x2e20 [ 48.833480] lock_acquire+0xbc/0xec [ 48.833984] __mutex_lock_common+0xe0/0xe44 [ 48.834577] mutex_lock_nested+0x28/0x34 [ 48.835136] waiting_for_supplier_show+0x3c/0x98 [ 48.835781] dev_attr_show+0x48/0xb4 [ 48.836295] sysfs_kf_seq_show+0xe8/0x184 [ 48.836864] kernfs_seq_show+0x48/0x8c [ 48.837401] seq_read+0x1c8/0x600 [ 48.837884] kernfs_fop_read+0x68/0x204 [ 48.838431] __vfs_read+0x60/0x214 [ 48.838925] vfs_read+0xbc/0x15c [ 48.839397] ksys_read+0x78/0xe4 [ 48.839869] __arm64_sys_read+0x1c/0x28 [ 48.840416] el0_svc_common+0xbc/0x1d0 [ 48.840953] el0_svc_handler+0x74/0x98 [ 48.841490] el0_svc+0x8/0xc [ 48.841917] [ 48.841917] other info that might help us debug this: [ 48.841917] [ 48.842920] Chain exists of: [ 48.842920] wfs_lock --> device_links_lock --> kn->count [ 48.842920] [ 48.844152] Possible unsafe locking scenario: [ 48.844152] [ 48.844895] CPU0 CPU1 [ 48.845463] ---- ---- [ 48.846032] lock(kn->count); [ 48.846417] lock(device_links_lock); [ 48.847203] lock(kn->count); [ 48.847902] lock(wfs_lock); [ 48.848276] [ 48.848276] *** DEADLOCK *** Reported-by: Cheng-Jui.Wang@mediatek.com Signed-off-by: Saravana Kannan Link: https://lore.kernel.org/r/20201104205431.3795207-1-saravanak@google.com Signed-off-by: Greg Kroah-Hartman Bug: 171536500 (cherry picked from commit 7008e58c63bc8468e8d16154e25d780198b3ecfc) Change-Id: Icb98a270d6ff07bcc81a2162ac00493fae6fafe6 --- drivers/base/core.c | 2 -- 1 file changed, 2 deletions(-) diff --git a/drivers/base/core.c b/drivers/base/core.c index 60721e05dba0..2e31233e4666 100644 --- a/drivers/base/core.c +++ b/drivers/base/core.c @@ -1053,10 +1053,8 @@ static ssize_t waiting_for_supplier_show(struct device *dev, bool val; device_lock(dev); - mutex_lock(&wfs_lock); val = !list_empty(&dev->links.needs_suppliers) && dev->links.need_for_probe; - mutex_unlock(&wfs_lock); device_unlock(dev); return sprintf(buf, "%u\n", val); } From d61ede24cbb2ac0d774b70d3ec56939983b331de Mon Sep 17 00:00:00 2001 From: Roman Kiryanov Date: Tue, 5 Jan 2021 14:29:27 -0800 Subject: [PATCH 06/18] ANDROID: Update abi_gki_aarch64_goldfish Fixes `virtio_wifi: Unknown symbol ieee80211_tx_status_ext (err -2)` build/abi/extract_symbols out/android11-5.4/dist/ --whitelist common/android/abi_gki_aarch64_goldfish Bug: 176831960 Test: none Signed-off-by: Roman Kiryanov Change-Id: I07671dd29079588cad5e3984427a8ca0ad389e9a --- android/abi_gki_aarch64.xml | 1840 +++++++++++++++++++++++------- android/abi_gki_aarch64_goldfish | 138 ++- 2 files changed, 1563 insertions(+), 415 deletions(-) diff --git a/android/abi_gki_aarch64.xml b/android/abi_gki_aarch64.xml index 5c4b2abf4767..6d10969a1278 100644 --- a/android/abi_gki_aarch64.xml +++ b/android/abi_gki_aarch64.xml @@ -98,6 +98,8 @@ + + @@ -372,6 +374,7 @@ + @@ -497,6 +500,11 @@ + + + + + @@ -1744,6 +1752,13 @@ + + + + + + + @@ -1874,6 +1889,7 @@ + @@ -2660,6 +2676,7 @@ + @@ -4367,6 +4384,7 @@ + @@ -15471,6 +15489,7 @@ + @@ -16274,8 +16293,6 @@ - - @@ -17094,7 +17111,7 @@ - + @@ -17211,7 +17228,7 @@ - + @@ -17271,8 +17288,8 @@ - - + + @@ -25714,7 +25731,44 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -25728,6 +25782,9 @@ + + + @@ -26888,6 +26945,728 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -26896,6 +27675,11 @@ + + + + + @@ -26912,11 +27696,16 @@ + + + + + @@ -26929,6 +27718,21 @@ + + + + + + + + + + + + + + + @@ -26990,10 +27794,34 @@ + + + + + + + + + + + + + + + + + + + + + + + + @@ -27043,6 +27871,20 @@ + + + + + + + + + + + + + + @@ -27106,6 +27948,18 @@ + + + + + + + + + + + + @@ -37147,6 +38001,7 @@ + @@ -37325,6 +38180,14 @@ + + + + + + + + @@ -37530,10 +38393,10 @@ - + - + @@ -37545,35 +38408,18 @@ - + - + - + - - - - + + - - - - - - - - - - - - - - - - - + + @@ -37617,18 +38463,27 @@ - + - + - + - - + + - - + + + + + + + + + + + @@ -37694,28 +38549,25 @@ - - - - + - + @@ -37724,20 +38576,20 @@ - + - - + + - + - + @@ -37754,7 +38606,7 @@ - + @@ -37793,14 +38645,6 @@ - - - - - - - - @@ -39274,13 +40118,13 @@ - + - + @@ -39363,7 +40207,7 @@ - + @@ -39761,7 +40605,7 @@ - + @@ -52113,9 +52957,6 @@ - - - @@ -52966,7 +53807,7 @@ - + @@ -52974,7 +53815,7 @@ - + @@ -53416,7 +54257,7 @@ - + @@ -53467,7 +54308,7 @@ - + @@ -53693,7 +54534,7 @@ - + @@ -54784,15 +55625,12 @@ - + - + - - - - + @@ -55903,7 +56741,7 @@ - + @@ -55927,7 +56765,7 @@ - + @@ -59717,6 +60555,7 @@ + @@ -61926,8 +62765,8 @@ - - + + @@ -65372,7 +66211,7 @@ - + @@ -65418,6 +66257,8 @@ + + @@ -72067,7 +72908,6 @@ - @@ -81052,7 +81892,7 @@ - + @@ -81476,6 +82316,7 @@ + @@ -81546,7 +82387,7 @@ - + @@ -81636,12 +82477,12 @@ - + - + - + @@ -81734,7 +82575,7 @@ - + @@ -82850,12 +83691,12 @@ - + - + @@ -89125,7 +89966,7 @@ - + @@ -89502,14 +90343,6 @@ - - - - - - - - @@ -93885,6 +94718,14 @@ + + + + + + + + @@ -105115,8 +105956,47 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -108105,7 +108985,7 @@ - + @@ -108132,7 +109012,7 @@ - + @@ -108946,7 +109826,6 @@ - @@ -108972,6 +109851,14 @@ + + + + + + + + @@ -108983,6 +109870,31 @@ + + + + + + + + + + + + + + + + + + + + + + + + + @@ -108995,240 +109907,9 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - @@ -109381,18 +110062,7 @@ - - - - - - - - - - - @@ -109581,13 +110251,6 @@ - - - - - - - @@ -109595,10 +110258,6 @@ - - - - @@ -110030,7 +110689,7 @@ - + @@ -110323,7 +110982,7 @@ - + @@ -115725,17 +116384,6 @@ - - - - - - - - - - - @@ -115795,6 +116443,164 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -115810,6 +116616,11 @@ + + + + + @@ -117486,7 +118297,7 @@ - + @@ -117582,7 +118393,7 @@ - + @@ -117597,6 +118408,7 @@ + @@ -117755,7 +118567,7 @@ - + @@ -117853,7 +118665,7 @@ - + @@ -118571,7 +119383,268 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -118655,6 +119728,17 @@ + + + + + + + + + + + @@ -123299,14 +124383,6 @@ - - - - - - - - @@ -124619,7 +125695,7 @@ - + @@ -124640,7 +125716,7 @@ - + diff --git a/android/abi_gki_aarch64_goldfish b/android/abi_gki_aarch64_goldfish index 93efcaf60f8a..3901c3ff26ee 100644 --- a/android/abi_gki_aarch64_goldfish +++ b/android/abi_gki_aarch64_goldfish @@ -15,6 +15,9 @@ blk_queue_write_cache bpf_trace_run2 bpf_trace_run3 + bt_err + bt_info + build_skb cancel_delayed_work_sync cancel_work_sync __cfi_slowpath @@ -37,6 +40,7 @@ _dev_err device_add_disk device_create + device_init_wakeup device_unregister _dev_info __dev_kfree_skb_any @@ -70,8 +74,23 @@ __get_free_pages get_random_bytes get_unused_fd_flags + __hci_cmd_sync + hrtimer_cancel + hrtimer_init + hrtimer_start_range_ns ida_alloc_range ida_free + ieee80211_alloc_hw_nm + ieee80211_beacon_get_tim + ieee80211_csa_finish + ieee80211_csa_is_complete + ieee80211_free_hw + ieee80211_free_txskb + ieee80211_get_tx_rates + ieee80211_iterate_active_interfaces_atomic + ieee80211_register_hw + ieee80211_start_tx_ba_cb_irqsafe + ieee80211_stop_tx_ba_cb_irqsafe init_timer_key init_wait_entry __init_waitqueue_head @@ -84,6 +103,7 @@ jiffies jiffies_to_msecs kfree + kfree_skb kimage_voffset __kmalloc kmalloc_caches @@ -100,6 +120,7 @@ kobject_put kobject_uevent kstrdup + ktime_get ktime_get_mono_fast_ns ktime_get_raw_ts64 ktime_get_real_seconds @@ -123,11 +144,18 @@ mutex_lock_interruptible mutex_trylock mutex_unlock + napi_complete_done + napi_disable + __napi_schedule + napi_schedule_prep netdev_err netdev_info netif_carrier_off netif_carrier_on netif_device_detach + netif_napi_add + netif_set_real_num_rx_queues + netif_set_real_num_tx_queues netif_tx_stop_all_queues netif_tx_wake_queue nf_conntrack_destroy @@ -153,7 +181,6 @@ platform_driver_unregister platform_get_irq platform_get_resource - pm_runtime_allow __pm_runtime_suspend __pm_runtime_use_autosuspend preempt_schedule @@ -184,7 +211,10 @@ register_netdev register_virtio_device register_virtio_driver + __regmap_init + release_firmware remap_pfn_range + request_firmware __request_module request_threaded_irq revalidate_disk @@ -198,7 +228,9 @@ sg_init_one sg_init_table skb_add_rx_frag + skb_page_frag_refill skb_put + skb_to_sgvec snd_card_register snd_ctl_enum_info snd_ctl_sync_vmaster @@ -207,6 +239,7 @@ snd_pcm_add_chmap_ctls snd_pcm_period_elapsed snprintf + softnet_data sort sprintf __stack_chk_fail @@ -248,6 +281,7 @@ virtqueue_detach_unused_buf virtqueue_disable_cb virtqueue_enable_cb + virtqueue_enable_cb_prepare virtqueue_get_avail_addr virtqueue_get_buf virtqueue_get_desc_addr @@ -257,6 +291,7 @@ virtqueue_kick virtqueue_kick_prepare virtqueue_notify + virtqueue_poll vmemmap vring_create_virtqueue vring_del_virtqueue @@ -266,6 +301,63 @@ __wake_up __warn_printk +# required by btintel.ko + bt_to_errno + hci_cmd_sync + request_firmware_direct + +# required by btrtl.ko + bt_warn + +# required by btusb.ko + bit_wait_timeout + btbcm_set_bdaddr + btbcm_setup_apple + btbcm_setup_patchram + device_wakeup_disable + disable_irq + disable_irq_nosync + enable_irq + gpiod_get_optional + gpiod_put + gpiod_set_value_cansleep + hci_alloc_dev + __hci_cmd_sync_ev + hci_free_dev + hci_recv_diag + hci_recv_frame + hci_register_dev + hci_unregister_dev + irq_modify_status + irq_set_irq_wake + of_irq_get_byname + of_match_device + of_property_read_variable_u16_array + out_of_line_wait_on_bit_timeout + pm_system_wakeup + pm_wakeup_dev_event + usb_alloc_urb + usb_anchor_urb + usb_autopm_get_interface + usb_autopm_put_interface + usb_bulk_msg + usb_control_msg + usb_deregister + usb_driver_claim_interface + usb_driver_release_interface + usb_enable_autosuspend + usb_free_urb + usb_get_from_anchor + usb_ifnum_to_if + usb_kill_anchored_urbs + usb_match_id + usb_register_driver + usb_scuttle_anchored_urbs + usb_set_interface + usb_submit_urb + usb_unanchor_urb + wake_up_bit + # required by dummy-cpufreq.ko cpufreq_generic_attr cpufreq_register_driver @@ -283,7 +375,6 @@ # required by goldfish_address_space.ko __ioremap kimage_vaddr - kzfree memremap memunmap @@ -341,7 +432,6 @@ kernel_read kernel_write kern_path - ktime_get lockref_get lock_rename lookup_one_len @@ -398,31 +488,16 @@ genl_notify genl_register_family genl_unregister_family - hrtimer_cancel hrtimer_forward - hrtimer_init - hrtimer_start_range_ns - ieee80211_alloc_hw_nm - ieee80211_beacon_get_tim - ieee80211_csa_finish - ieee80211_csa_is_complete - ieee80211_free_hw - ieee80211_free_txskb - ieee80211_get_tx_rates - ieee80211_iterate_active_interfaces_atomic ieee80211_probereq_get ieee80211_queue_delayed_work ieee80211_ready_on_channel - ieee80211_register_hw ieee80211_remain_on_channel_expired ieee80211_rx_irqsafe ieee80211_scan_completed - ieee80211_start_tx_ba_cb_irqsafe - ieee80211_stop_tx_ba_cb_irqsafe ieee80211_tx_status_irqsafe ieee80211_unregister_hw init_net - kfree_skb kstrndup __netdev_alloc_skb netif_rx @@ -580,7 +655,6 @@ # required by rtc-test.ko add_timer del_timer - device_init_wakeup devm_rtc_allocate_device platform_device_add platform_device_alloc @@ -606,6 +680,7 @@ get_device_system_crosststamp kvasprintf ns_to_timespec + pm_runtime_allow __pm_runtime_disable pm_runtime_enable pm_runtime_forbid @@ -664,7 +739,6 @@ regcache_cache_only regcache_sync regmap_exit - __regmap_init regmap_read regmap_update_bits_base regmap_write @@ -708,6 +782,7 @@ vmalloc # required by virtio-gpu.ko + dma_buf_get_uuid dma_direct_map_sg dma_direct_sync_sg_for_device dma_direct_unmap_sg @@ -769,6 +844,7 @@ drm_gem_object_lookup drm_gem_object_put_unlocked drm_gem_object_release + drm_gem_prime_export drm_gem_prime_fd_to_handle drm_gem_prime_handle_to_fd drm_gem_prime_mmap @@ -809,6 +885,7 @@ ttm_bo_init_mm ttm_bo_kmap ttm_bo_kunmap + ttm_bo_manager_func ttm_bo_mmap ttm_bo_move_to_lru_tail ttm_bo_put @@ -819,6 +896,7 @@ ttm_eu_backoff_reservation ttm_eu_fence_buffer_objects ttm_eu_reserve_buffers + ttm_tt_init ww_mutex_lock_interruptible ww_mutex_unlock @@ -907,7 +985,6 @@ bpf_prog_sub bpf_stats_enabled_key bpf_warn_invalid_xdp_action - build_skb __cpuhp_remove_state __cpuhp_setup_state __cpuhp_state_add_instance @@ -922,21 +999,14 @@ find_next_bit flow_keys_basic_dissector __napi_alloc_skb - napi_complete_done napi_consume_skb - napi_disable napi_gro_receive napi_hash_del - __napi_schedule - napi_schedule_prep netdev_notify_peers netdev_warn netif_device_attach - netif_napi_add netif_napi_del netif_schedule_queue - netif_set_real_num_rx_queues - netif_set_real_num_tx_queues __netif_set_xps_queue net_ratelimit __num_online_cpus @@ -944,18 +1014,13 @@ sched_clock skb_coalesce_rx_frag __skb_flow_dissect - skb_page_frag_refill skb_partial_csum_set - skb_to_sgvec skb_tstamp_tx - softnet_data synchronize_net __tracepoint_xdp_exception virtqueue_add_inbuf_ctx virtqueue_enable_cb_delayed - virtqueue_enable_cb_prepare virtqueue_get_buf_ctx - virtqueue_poll xdp_convert_zc_to_xdp_frame xdp_do_flush_map xdp_do_redirect @@ -985,3 +1050,10 @@ nvdimm_bus_register nvdimm_bus_unregister nvdimm_pmem_region_create + +# required by virtio_wifi.ko + ieee80211_rx_napi + ieee80211_stop_queues + ieee80211_tx_status_ext + ieee80211_wake_queues + init_dummy_netdev From a91758267286f358788a5a9c25b2a15e2fbc4bfa Mon Sep 17 00:00:00 2001 From: Vijayavardhan Vennapusa Date: Wed, 4 Apr 2018 11:02:28 +0530 Subject: [PATCH 07/18] ANDROID: USB: f_accessory: Check dev pointer before decoding ctrl request In case of poweroff charging mode, accessory function instance is not created and due to this, _acc_dev will be NULL. If target is connected to Accessory dock in poweroff charging mode, there is a chance dev pointer is accessed, which is NULL. Hence add a check before processing control request and return error if it is NULL. Bug: 141002587 Change-Id: I4f1deb9d764b8c0bd1d7837cbc43a2933167f568 Signed-off-by: Vijayavardhan Vennapusa Signed-off-by: Jack Pham Signed-off-by: Giuliano Procida --- drivers/usb/gadget/function/f_accessory.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/usb/gadget/function/f_accessory.c b/drivers/usb/gadget/function/f_accessory.c index 3e0b8b5d7d14..de1c7cec7ff0 100644 --- a/drivers/usb/gadget/function/f_accessory.c +++ b/drivers/usb/gadget/function/f_accessory.c @@ -843,6 +843,12 @@ int acc_ctrlrequest(struct usb_composite_dev *cdev, u16 w_length = le16_to_cpu(ctrl->wLength); unsigned long flags; + /* + * If instance is not created which is the case in power off charging + * mode, dev will be NULL. Hence return error if it is the case. + */ + if (!dev) + return -ENODEV; /* printk(KERN_INFO "acc_ctrlrequest " "%02x.%02x v%04x i%04x l%u\n", From 4df304a4df0db816147aef0d16ff510a12a5cffc Mon Sep 17 00:00:00 2001 From: Will Deacon Date: Tue, 15 Dec 2020 13:39:54 +0000 Subject: [PATCH 08/18] ANDROID: usb: f_accessory: Remove stale comments Neither acc_gadget_bind() nor acc_gadget_register_driver() exist, so remove the stale comments that refer to them. Bug: 173789633 Signed-off-by: Will Deacon Change-Id: If396ba3bcac3ca59c48e5a5faa0a8520534ed625 Signed-off-by: Giuliano Procida --- drivers/usb/gadget/function/f_accessory.c | 2 -- 1 file changed, 2 deletions(-) diff --git a/drivers/usb/gadget/function/f_accessory.c b/drivers/usb/gadget/function/f_accessory.c index de1c7cec7ff0..5509ea41fd00 100644 --- a/drivers/usb/gadget/function/f_accessory.c +++ b/drivers/usb/gadget/function/f_accessory.c @@ -199,7 +199,6 @@ static struct usb_gadget_strings *acc_strings[] = { NULL, }; -/* temporary variable used between acc_open() and acc_gadget_bind() */ static struct acc_dev *_acc_dev; struct acc_instance { @@ -1224,7 +1223,6 @@ static int acc_setup(void) INIT_DELAYED_WORK(&dev->start_work, acc_start_work); INIT_WORK(&dev->hid_work, acc_hid_work); - /* _acc_dev must be set before calling usb_gadget_register_driver */ _acc_dev = dev; ret = misc_register(&acc_device); From 82262d09f1ff5160f282ddf32cb325fc56ecffdc Mon Sep 17 00:00:00 2001 From: Will Deacon Date: Tue, 15 Dec 2020 13:43:01 +0000 Subject: [PATCH 09/18] ANDROID: usb: f_accessory: Remove useless non-debug prints Remove some useless print statements, as they can trivially be used to spam the console and don't report anything meaningful. Bug: 173789633 Signed-off-by: Will Deacon Change-Id: I28052010fc3ec033a2c99efeb3f6c919d54d75c2 Signed-off-by: Giuliano Procida --- drivers/usb/gadget/function/f_accessory.c | 12 ------------ 1 file changed, 12 deletions(-) diff --git a/drivers/usb/gadget/function/f_accessory.c b/drivers/usb/gadget/function/f_accessory.c index 5509ea41fd00..f83064dd808f 100644 --- a/drivers/usb/gadget/function/f_accessory.c +++ b/drivers/usb/gadget/function/f_accessory.c @@ -761,7 +761,6 @@ static long acc_ioctl(struct file *fp, unsigned code, unsigned long value) static int acc_open(struct inode *ip, struct file *fp) { - printk(KERN_INFO "acc_open\n"); if (atomic_xchg(&_acc_dev->open_excl, 1)) return -EBUSY; @@ -772,8 +771,6 @@ static int acc_open(struct inode *ip, struct file *fp) static int acc_release(struct inode *ip, struct file *fp) { - printk(KERN_INFO "acc_release\n"); - WARN_ON(!atomic_xchg(&_acc_dev->open_excl, 0)); /* indicate that we are disconnected * still could be online so don't touch online flag @@ -848,12 +845,6 @@ int acc_ctrlrequest(struct usb_composite_dev *cdev, */ if (!dev) return -ENODEV; -/* - printk(KERN_INFO "acc_ctrlrequest " - "%02x.%02x v%04x i%04x l%u\n", - b_requestType, b_request, - w_value, w_index, w_length); -*/ if (b_requestType == (USB_DIR_OUT | USB_TYPE_VENDOR)) { if (b_request == ACCESSORY_START) { @@ -1320,7 +1311,6 @@ static struct usb_function_instance *acc_alloc_inst(void) err = acc_setup(); if (err) { kfree(fi_acc); - pr_err("Error setting ACCESSORY\n"); return ERR_PTR(err); } @@ -1347,8 +1337,6 @@ static struct usb_function *acc_alloc(struct usb_function_instance *fi) { struct acc_dev *dev = _acc_dev; - pr_info("acc_alloc\n"); - dev->function.name = "accessory"; dev->function.strings = acc_strings, dev->function.fs_descriptors = fs_acc_descs; From 21d2a9d7c7006f7f6cb18a6788df8b8e244e5fd7 Mon Sep 17 00:00:00 2001 From: Will Deacon Date: Tue, 15 Dec 2020 13:47:00 +0000 Subject: [PATCH 10/18] ANDROID: usb: f_accessory: Remove useless assignment acc_alloc_inst() assigns to a local 'dev' variable, but then never uses it. Remove the redundant assignment, and the local variable along with it. Bug: 173789633 Signed-off-by: Will Deacon Change-Id: Ide9c2e89fb12b846eb8739b302d1b742fc7eb6b5 Signed-off-by: Giuliano Procida --- drivers/usb/gadget/function/f_accessory.c | 2 -- 1 file changed, 2 deletions(-) diff --git a/drivers/usb/gadget/function/f_accessory.c b/drivers/usb/gadget/function/f_accessory.c index f83064dd808f..59831d709e08 100644 --- a/drivers/usb/gadget/function/f_accessory.c +++ b/drivers/usb/gadget/function/f_accessory.c @@ -1299,7 +1299,6 @@ static void acc_free_inst(struct usb_function_instance *fi) static struct usb_function_instance *acc_alloc_inst(void) { struct acc_instance *fi_acc; - struct acc_dev *dev; int err; fi_acc = kzalloc(sizeof(*fi_acc), GFP_KERNEL); @@ -1316,7 +1315,6 @@ static struct usb_function_instance *acc_alloc_inst(void) config_group_init_type_name(&fi_acc->func_inst.group, "", &acc_func_type); - dev = _acc_dev; return &fi_acc->func_inst; } From 62adf8c60560ca4b8524d0cddff943fff2d00d96 Mon Sep 17 00:00:00 2001 From: Will Deacon Date: Tue, 15 Dec 2020 14:24:17 +0000 Subject: [PATCH 11/18] ANDROID: usb: f_accessory: Wrap '_acc_dev' in get()/put() accessors The '_acc_dev' global variable is a fancy use-after-free factory. Wrap it in some get()/put() functions in preparation for introducing some refcounting. Bug: 173789633 Signed-off-by: Will Deacon Change-Id: I4c839627648c209341a81efa0c001c8d71b878d4 Signed-off-by: Giuliano Procida --- drivers/usb/gadget/function/f_accessory.c | 80 ++++++++++++++++++----- 1 file changed, 62 insertions(+), 18 deletions(-) diff --git a/drivers/usb/gadget/function/f_accessory.c b/drivers/usb/gadget/function/f_accessory.c index 59831d709e08..b91cd38a99c4 100644 --- a/drivers/usb/gadget/function/f_accessory.c +++ b/drivers/usb/gadget/function/f_accessory.c @@ -206,6 +206,15 @@ struct acc_instance { const char *name; }; +static struct acc_dev *get_acc_dev(void) +{ + return _acc_dev; +} + +static void put_acc_dev(struct acc_dev *dev) +{ +} + static inline struct acc_dev *func_to_dev(struct usb_function *f) { return container_of(f, struct acc_dev, function); @@ -271,7 +280,10 @@ static void acc_set_disconnected(struct acc_dev *dev) static void acc_complete_in(struct usb_ep *ep, struct usb_request *req) { - struct acc_dev *dev = _acc_dev; + struct acc_dev *dev = get_acc_dev(); + + if (!dev) + return; if (req->status == -ESHUTDOWN) { pr_debug("acc_complete_in set disconnected"); @@ -281,11 +293,15 @@ static void acc_complete_in(struct usb_ep *ep, struct usb_request *req) req_put(dev, &dev->tx_idle, req); wake_up(&dev->write_wq); + put_acc_dev(dev); } static void acc_complete_out(struct usb_ep *ep, struct usb_request *req) { - struct acc_dev *dev = _acc_dev; + struct acc_dev *dev = get_acc_dev(); + + if (!dev) + return; dev->rx_done = 1; if (req->status == -ESHUTDOWN) { @@ -294,6 +310,7 @@ static void acc_complete_out(struct usb_ep *ep, struct usb_request *req) } wake_up(&dev->read_wq); + put_acc_dev(dev); } static void acc_complete_set_string(struct usb_ep *ep, struct usb_request *req) @@ -761,21 +778,36 @@ static long acc_ioctl(struct file *fp, unsigned code, unsigned long value) static int acc_open(struct inode *ip, struct file *fp) { - if (atomic_xchg(&_acc_dev->open_excl, 1)) - return -EBUSY; + struct acc_dev *dev = get_acc_dev(); - _acc_dev->disconnected = 0; - fp->private_data = _acc_dev; + if (!dev) + return -ENODEV; + + if (atomic_xchg(&dev->open_excl, 1)) { + put_acc_dev(dev); + return -EBUSY; + } + + dev->disconnected = 0; + fp->private_data = dev; return 0; } static int acc_release(struct inode *ip, struct file *fp) { - WARN_ON(!atomic_xchg(&_acc_dev->open_excl, 0)); + struct acc_dev *dev = fp->private_data; + + if (!dev) + return -ENOENT; + + WARN_ON(!atomic_xchg(&dev->open_excl, 0)); /* indicate that we are disconnected * still could be online so don't touch online flag */ - _acc_dev->disconnected = 1; + dev->disconnected = 1; + + fp->private_data = NULL; + put_acc_dev(dev); return 0; } @@ -828,7 +860,7 @@ static void acc_complete_setup_noop(struct usb_ep *ep, struct usb_request *req) int acc_ctrlrequest(struct usb_composite_dev *cdev, const struct usb_ctrlrequest *ctrl) { - struct acc_dev *dev = _acc_dev; + struct acc_dev *dev = get_acc_dev(); int value = -EOPNOTSUPP; struct acc_hid_dev *hid; int offset; @@ -931,6 +963,7 @@ err: "%02x.%02x v%04x i%04x l%u\n", ctrl->bRequestType, ctrl->bRequest, w_value, w_index, w_length); + put_acc_dev(dev); return value; } EXPORT_SYMBOL_GPL(acc_ctrlrequest); @@ -1001,10 +1034,6 @@ kill_all_hid_devices(struct acc_dev *dev) struct list_head *entry, *temp; unsigned long flags; - /* do nothing if usb accessory device doesn't exist */ - if (!dev) - return; - spin_lock_irqsave(&dev->lock, flags); list_for_each_safe(entry, temp, &dev->hid_list) { hid = list_entry(entry, struct acc_hid_dev, list); @@ -1089,12 +1118,15 @@ static void acc_hid_delete(struct acc_hid_dev *hid) static void acc_hid_work(struct work_struct *data) { - struct acc_dev *dev = _acc_dev; + struct acc_dev *dev = get_acc_dev(); struct list_head *entry, *temp; struct acc_hid_dev *hid; struct list_head new_list, dead_list; unsigned long flags; + if (!dev) + return; + INIT_LIST_HEAD(&new_list); spin_lock_irqsave(&dev->lock, flags); @@ -1140,6 +1172,8 @@ static void acc_hid_work(struct work_struct *data) hid_destroy_device(hid->hid); acc_hid_delete(hid); } + + put_acc_dev(dev); } static int acc_function_set_alt(struct usb_function *f, @@ -1230,15 +1264,23 @@ err: void acc_disconnect(void) { + struct acc_dev *dev = get_acc_dev(); + /* unregister all HID devices if USB is disconnected */ - kill_all_hid_devices(_acc_dev); + if (dev) + kill_all_hid_devices(dev); + + put_acc_dev(dev); } EXPORT_SYMBOL_GPL(acc_disconnect); static void acc_cleanup(void) { + struct acc_dev *dev = _acc_dev; + misc_deregister(&acc_device); - kfree(_acc_dev); + put_acc_dev(dev); + kfree(dev); _acc_dev = NULL; } static struct acc_instance *to_acc_instance(struct config_item *item) @@ -1320,7 +1362,9 @@ static struct usb_function_instance *acc_alloc_inst(void) static void acc_free(struct usb_function *f) { -/*NO-OP: no function specific resource allocation in mtp_alloc*/ + struct acc_dev *dev = func_to_dev(f); + + put_acc_dev(dev); } int acc_ctrlrequest_configfs(struct usb_function *f, @@ -1333,7 +1377,7 @@ int acc_ctrlrequest_configfs(struct usb_function *f, static struct usb_function *acc_alloc(struct usb_function_instance *fi) { - struct acc_dev *dev = _acc_dev; + struct acc_dev *dev = get_acc_dev(); dev->function.name = "accessory"; dev->function.strings = acc_strings, From cfe67611673bb8a26805b17611f3262174476e73 Mon Sep 17 00:00:00 2001 From: Will Deacon Date: Tue, 15 Dec 2020 15:18:07 +0000 Subject: [PATCH 12/18] ANDROID: usb: f_accessory: Add refcounting to global 'acc_dev' Add refcounting to track the lifetime of the global 'acc_dev' structure, as the underlying function directories can be removed while references still exist to the dev node. Bug: 173789633 Signed-off-by: Will Deacon Change-Id: I248408e890d01167706c329146d63b64a6456df6 Signed-off-by: Giuliano Procida --- drivers/usb/gadget/function/f_accessory.c | 38 +++++++++++++++++++---- 1 file changed, 32 insertions(+), 6 deletions(-) diff --git a/drivers/usb/gadget/function/f_accessory.c b/drivers/usb/gadget/function/f_accessory.c index b91cd38a99c4..97a6bd8bac90 100644 --- a/drivers/usb/gadget/function/f_accessory.c +++ b/drivers/usb/gadget/function/f_accessory.c @@ -27,6 +27,7 @@ #include #include #include +#include #include #include @@ -73,6 +74,7 @@ struct acc_dev { struct usb_function function; struct usb_composite_dev *cdev; spinlock_t lock; + struct acc_dev_ref *ref; struct usb_ep *ep_in; struct usb_ep *ep_out; @@ -199,7 +201,14 @@ static struct usb_gadget_strings *acc_strings[] = { NULL, }; -static struct acc_dev *_acc_dev; +struct acc_dev_ref { + struct kref kref; + struct acc_dev *acc_dev; +}; + +static struct acc_dev_ref _acc_dev_ref = { + .kref = KREF_INIT(0), +}; struct acc_instance { struct usb_function_instance func_inst; @@ -208,11 +217,26 @@ struct acc_instance { static struct acc_dev *get_acc_dev(void) { - return _acc_dev; + struct acc_dev_ref *ref = &_acc_dev_ref; + + return kref_get_unless_zero(&ref->kref) ? ref->acc_dev : NULL; +} + +static void __put_acc_dev(struct kref *kref) +{ + struct acc_dev_ref *ref = container_of(kref, struct acc_dev_ref, kref); + struct acc_dev *dev = ref->acc_dev; + + ref->acc_dev = NULL; + kfree(dev); } static void put_acc_dev(struct acc_dev *dev) { + struct acc_dev_ref *ref = dev->ref; + + WARN_ON(ref->acc_dev != dev); + kref_put(&ref->kref, __put_acc_dev); } static inline struct acc_dev *func_to_dev(struct usb_function *f) @@ -1230,6 +1254,7 @@ static void acc_function_disable(struct usb_function *f) static int acc_setup(void) { + struct acc_dev_ref *ref = &_acc_dev_ref; struct acc_dev *dev; int ret; @@ -1248,7 +1273,9 @@ static int acc_setup(void) INIT_DELAYED_WORK(&dev->start_work, acc_start_work); INIT_WORK(&dev->hid_work, acc_hid_work); - _acc_dev = dev; + dev->ref = ref; + kref_init(&ref->kref); + ref->acc_dev = dev; ret = misc_register(&acc_device); if (ret) @@ -1276,12 +1303,11 @@ EXPORT_SYMBOL_GPL(acc_disconnect); static void acc_cleanup(void) { - struct acc_dev *dev = _acc_dev; + struct acc_dev *dev = get_acc_dev(); misc_deregister(&acc_device); put_acc_dev(dev); - kfree(dev); - _acc_dev = NULL; + put_acc_dev(dev); /* Pairs with kref_init() in acc_setup() */ } static struct acc_instance *to_acc_instance(struct config_item *item) { From 7f7a5de5ec045109db11e77260a847ce2ece632c Mon Sep 17 00:00:00 2001 From: Will Deacon Date: Tue, 15 Dec 2020 15:48:22 +0000 Subject: [PATCH 13/18] ANDROID: usb: f_accessory: Fix teardown ordering in acc_release() acc_release() attempts to synchronise with acc_open() using an atomic 'open_excl' member in 'struct acc_dev'. Unfortunately, acc_release() prematurely resets this atomic variable to zero, meaning there is a potential race on 'dev->disconnected': acc_open() acc_release() atomic_xchg(open_excl), 0) atomic_xchg(open_excl, 1) dev->disconnected = 0; dev->disconnected = 1; Fix the race by ensuring that the 'disconnected' field is written before clearing 'open_excl' in acc_release(). Bug: 173789633 Signed-off-by: Will Deacon Change-Id: Ib9a21f2305f6d70de3e760da62dbfdd66889200a Signed-off-by: Giuliano Procida --- drivers/usb/gadget/function/f_accessory.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/usb/gadget/function/f_accessory.c b/drivers/usb/gadget/function/f_accessory.c index 97a6bd8bac90..592d59c94222 100644 --- a/drivers/usb/gadget/function/f_accessory.c +++ b/drivers/usb/gadget/function/f_accessory.c @@ -824,13 +824,13 @@ static int acc_release(struct inode *ip, struct file *fp) if (!dev) return -ENOENT; - WARN_ON(!atomic_xchg(&dev->open_excl, 0)); /* indicate that we are disconnected * still could be online so don't touch online flag */ dev->disconnected = 1; fp->private_data = NULL; + WARN_ON(!atomic_xchg(&dev->open_excl, 0)); put_acc_dev(dev); return 0; } From f0e78b6595855cf80e8f0304bd470fefccc9d9ec Mon Sep 17 00:00:00 2001 From: Will Deacon Date: Tue, 15 Dec 2020 16:24:55 +0000 Subject: [PATCH 14/18] ANDROID: usb: f_accessory: Don't corrupt global state on double registration If acc_setup() is called when there is already an allocated instance, misc_register() will fail but the error path leaves a dangling pointer to freed memory in the global 'acc_dev' state. Fix this by ensuring that the refcount is zero before we start, and then using a cmpxchg() from NULL to serialise any concurrent initialisers. Bug: 173789633 Signed-off-by: Will Deacon Change-Id: I2c26289dcce7dbc493964516c49b05d04aaa6839 Signed-off-by: Giuliano Procida --- drivers/usb/gadget/function/f_accessory.c | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/drivers/usb/gadget/function/f_accessory.c b/drivers/usb/gadget/function/f_accessory.c index 592d59c94222..e04b9d7a19de 100644 --- a/drivers/usb/gadget/function/f_accessory.c +++ b/drivers/usb/gadget/function/f_accessory.c @@ -1258,6 +1258,9 @@ static int acc_setup(void) struct acc_dev *dev; int ret; + if (kref_read(&ref->kref)) + return -EBUSY; + dev = kzalloc(sizeof(*dev), GFP_KERNEL); if (!dev) return -ENOMEM; @@ -1274,16 +1277,21 @@ static int acc_setup(void) INIT_WORK(&dev->hid_work, acc_hid_work); dev->ref = ref; - kref_init(&ref->kref); - ref->acc_dev = dev; + if (cmpxchg_relaxed(&ref->acc_dev, NULL, dev)) { + ret = -EBUSY; + goto err_free_dev; + } ret = misc_register(&acc_device); if (ret) - goto err; + goto err_zap_ptr; + kref_init(&ref->kref); return 0; -err: +err_zap_ptr: + ref->acc_dev = NULL; +err_free_dev: kfree(dev); pr_err("USB accessory gadget driver failed to initialize\n"); return ret; From 13dd1a33bc1dc88e6221d8cfc46156ba0ac3c2ca Mon Sep 17 00:00:00 2001 From: Will Deacon Date: Tue, 15 Dec 2020 17:11:11 +0000 Subject: [PATCH 15/18] ANDROID: usb: f_accessory: Cancel any pending work before teardown Tearing down and freeing the 'acc_dev' structure when there is potentially asynchronous work queued involving its member fields is likely to lead to use-after-free issues. Cancel any pending work before freeing the structure. Bug: 173789633 Signed-off-by: Will Deacon Change-Id: I68a91274aea18034637b738d558d043ac74fadf4 Signed-off-by: Giuliano Procida --- drivers/usb/gadget/function/f_accessory.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/usb/gadget/function/f_accessory.c b/drivers/usb/gadget/function/f_accessory.c index e04b9d7a19de..6360b6632f63 100644 --- a/drivers/usb/gadget/function/f_accessory.c +++ b/drivers/usb/gadget/function/f_accessory.c @@ -227,6 +227,10 @@ static void __put_acc_dev(struct kref *kref) struct acc_dev_ref *ref = container_of(kref, struct acc_dev_ref, kref); struct acc_dev *dev = ref->acc_dev; + /* Cancel any async work */ + cancel_delayed_work_sync(&dev->start_work); + cancel_work_sync(&dev->hid_work); + ref->acc_dev = NULL; kfree(dev); } From e0ea2cf7660ddd619bfecf3cd81127a5ae27b971 Mon Sep 17 00:00:00 2001 From: Will Deacon Date: Tue, 15 Dec 2020 17:15:38 +0000 Subject: [PATCH 16/18] ANDROID: usb: f_accessory: Avoid bitfields for shared variables Using bitfields for shared variables is a "bad idea", as they require a non-atomic read-modify-write to be generated by the compiler, which can cause updates to unrelated bits in the same word to disappear. Ensure the 'online' and 'disconnected' members of 'struct acc_dev' are placed in separate variables by declaring them each as 'int'. Bug: 173789633 Signed-off-by: Will Deacon Change-Id: Ia6031d82a764e83b2cc3502fbe5fb273511da752 Signed-off-by: Giuliano Procida --- drivers/usb/gadget/function/f_accessory.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/usb/gadget/function/f_accessory.c b/drivers/usb/gadget/function/f_accessory.c index 6360b6632f63..6126ad551872 100644 --- a/drivers/usb/gadget/function/f_accessory.c +++ b/drivers/usb/gadget/function/f_accessory.c @@ -82,13 +82,13 @@ struct acc_dev { /* online indicates state of function_set_alt & function_unbind * set to 1 when we connect */ - int online:1; + int online; /* disconnected indicates state of open & release * Set to 1 when we disconnect. * Not cleared until our file is closed. */ - int disconnected:1; + int disconnected; /* strings sent by the host */ char manufacturer[ACC_STRING_SIZE]; From 39327dc3065b722976812c995fa9ebd747d81016 Mon Sep 17 00:00:00 2001 From: Will Deacon Date: Tue, 15 Dec 2020 17:15:38 +0000 Subject: [PATCH 17/18] ANDROID: usb: f_accessory: Don't drop NULL reference in acc_disconnect() If get_acc_dev() fails to obtain a reference to the current device, acc_disconnect() will attempt to put_acc_dev() with the resulting NULL pointer, leading to a crash: | Unable to handle kernel NULL pointer dereference at virtual address 00000074 | [...] | [] (acc_disconnect) from [] (android_disconnect+0x1c/0x7c) | [] (android_disconnect) from [] (usb_gadget_udc_reset+0x10/0x34) | [] (usb_gadget_udc_reset) from [] (dwc3_gadget_reset_interrupt+0x88/0x4fc) | [] (dwc3_gadget_reset_interrupt) from [] (dwc3_process_event_buf+0x60/0x3e4) | [] (dwc3_process_event_buf) from [] (dwc3_thread_interrupt+0x24/0x3c) | [] (dwc3_thread_interrupt) from [] (irq_thread_fn+0x1c/0x58) | [] (irq_thread_fn) from [] (irq_thread+0x1ec/0x2f4) | [] (irq_thread) from [] (kthread+0x1a8/0x1ac) | [] (kthread) from [] (ret_from_fork+0x14/0x3c) Follow the pattern used elsewhere, and return early if we fail to obtain a reference. Bug: 173789633 Reported-by: YongQin Liu Signed-off-by: Will Deacon Change-Id: I37a2bff5bc1b6b8269788d08191181763bf0e896 Signed-off-by: Giuliano Procida --- drivers/usb/gadget/function/f_accessory.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/drivers/usb/gadget/function/f_accessory.c b/drivers/usb/gadget/function/f_accessory.c index 6126ad551872..718e01e3190f 100644 --- a/drivers/usb/gadget/function/f_accessory.c +++ b/drivers/usb/gadget/function/f_accessory.c @@ -1305,10 +1305,11 @@ void acc_disconnect(void) { struct acc_dev *dev = get_acc_dev(); - /* unregister all HID devices if USB is disconnected */ - if (dev) - kill_all_hid_devices(dev); + if (!dev) + return; + /* unregister all HID devices if USB is disconnected */ + kill_all_hid_devices(dev); put_acc_dev(dev); } EXPORT_SYMBOL_GPL(acc_disconnect); From 158eae71734679b43e8731c48eec269746118385 Mon Sep 17 00:00:00 2001 From: "jian.gong" Date: Wed, 6 Jan 2021 13:26:13 +0800 Subject: [PATCH 18/18] ANDROID: ABI: update symbols of unisoc whitelist Update whitelist for the symbols used by the unisoc device and updates the ABI representation accordingly Leaf changes summary: 11 artifacts changed Changed leaf types summary: 0 leaf type changed Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 10 Added functions Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 1 Added variable 10 Added functions: [A] 'function void clocks_calc_mult_shift(unsigned int*, unsigned int*, unsigned int, unsigned int, unsigned int)' [A] 'function void cpufreq_add_update_util_hook(int, update_util_data*, void (update_util_data*, typedef u64, unsigned int)*)' [A] 'function void cpufreq_remove_update_util_hook(int)' [A] 'function kobject* get_governor_parent_kobj(cpufreq_policy*)' [A] 'function void gov_attr_set_get(gov_attr_set*, list_head*)' [A] 'function void gov_attr_set_init(gov_attr_set*, list_head*)' [A] 'function unsigned int gov_attr_set_put(gov_attr_set*, list_head*)' [A] 'function bool have_governor_per_policy()' [A] 'function void irq_work_sync(irq_work*)' [A] 'function mbox_chan* mbox_request_channel_byname(mbox_client*, const char*)' 1 Added variable: [A] 'const sysfs_ops governor_sysfs_ops' Bug: 175337500 Change-Id: Ibca2d9ef71b8f91e0ea62de4509f75ee902d30a4 Signed-off-by: jian.gong --- android/abi_gki_aarch64.xml | 1472 +++++++++++++++----------------- android/abi_gki_aarch64_unisoc | 23 + 2 files changed, 688 insertions(+), 807 deletions(-) diff --git a/android/abi_gki_aarch64.xml b/android/abi_gki_aarch64.xml index 6d10969a1278..1f89d3ac2614 100644 --- a/android/abi_gki_aarch64.xml +++ b/android/abi_gki_aarch64.xml @@ -651,6 +651,7 @@ + @@ -686,6 +687,7 @@ + @@ -709,6 +711,7 @@ + @@ -1650,6 +1653,7 @@ + @@ -1691,6 +1695,9 @@ + + + @@ -1752,6 +1759,7 @@ + @@ -2112,6 +2120,7 @@ + @@ -2301,6 +2310,7 @@ + @@ -4524,6 +4534,7 @@ + @@ -14742,6 +14753,16 @@ + + + + + + + + + + @@ -17761,6 +17782,7 @@ + @@ -23002,102 +23024,102 @@ - - + + - - - - - + + + + + - - - - + + + + - - - - - + + + + + - - - - + + + + - - - + + + - - - + + + - - - + + + - - - + + + - - - + + + - - - + + + - - - - + + + + - - - - - + + + + + - - - + + + - - - + + + - - - + + + - - - + + + @@ -23895,14 +23917,6 @@ - - - - - - - - @@ -23935,6 +23949,14 @@ + + + + + + + + @@ -29362,7 +29384,6 @@ - @@ -29390,6 +29411,9 @@ + + + @@ -38001,7 +38025,6 @@ - @@ -38180,14 +38203,6 @@ - - - - - - - - @@ -38393,10 +38408,10 @@ - + - + @@ -38408,18 +38423,35 @@ - + - + - + - - + + + + - - + + + + + + + + + + + + + + + + + @@ -38463,27 +38495,18 @@ - + - + - + - - + + - - - - - - - - - - - + + @@ -38549,25 +38572,28 @@ + + + - + - + @@ -38576,20 +38602,20 @@ - + - - + + - + - + @@ -38606,7 +38632,7 @@ - + @@ -38645,6 +38671,14 @@ + + + + + + + + @@ -47014,6 +47048,11 @@ + + + + + @@ -55625,12 +55664,15 @@ - + - + - + + + + @@ -90343,6 +90385,14 @@ + + + + + + + + @@ -90354,20 +90404,6 @@ - - - - - - - - - - - - - - @@ -92423,7 +92459,7 @@ - + @@ -94718,14 +94754,6 @@ - - - - - - - - @@ -95238,7 +95266,59 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -109907,9 +109987,240 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -110062,7 +110373,18 @@ + + + + + + + + + + + @@ -110251,6 +110573,13 @@ + + + + + + + @@ -110258,6 +110587,10 @@ + + + + @@ -110684,12 +111017,26 @@ + + + + + + + + + + + + + + - + @@ -113002,249 +113349,24 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + - + - + + + + - - - - - - - + - - - - - - - - @@ -114469,28 +114591,6 @@ - - - - - - - - - - - - - - - - - - - - - - @@ -116220,92 +116320,6 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - @@ -116384,6 +116398,149 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -116628,23 +116785,42 @@ - + - + - + - + - + - + - + + + + + + + + + + + + + + + + + + + + @@ -119383,268 +119559,7 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - @@ -119728,17 +119643,6 @@ - - - - - - - - - - - @@ -124365,7 +124269,7 @@ - + @@ -124375,14 +124279,6 @@ - - - - - - - - @@ -124858,7 +124754,7 @@ - + @@ -124890,7 +124786,7 @@ - + @@ -124898,7 +124794,7 @@ - + @@ -124926,7 +124822,7 @@ - + @@ -125850,44 +125746,6 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - diff --git a/android/abi_gki_aarch64_unisoc b/android/abi_gki_aarch64_unisoc index 4266cbe0bcea..e71275e592dd 100644 --- a/android/abi_gki_aarch64_unisoc +++ b/android/abi_gki_aarch64_unisoc @@ -58,6 +58,7 @@ clk_set_parent clk_set_rate clk_unprepare + clocks_calc_mult_shift clockevents_config_and_register __clocksource_register_scale compat_alloc_user_space @@ -72,6 +73,8 @@ cpu_hwcap_keys cpu_hwcaps cpumask_next + cpufreq_add_update_util_hook + cpufreq_remove_update_util_hook cpu_number __cpu_online_mask __cpu_possible_mask @@ -222,7 +225,12 @@ gen_pool_free_owner get_cpu_device __get_free_pages + get_governor_parent_kobj get_random_bytes + gov_attr_set_get + gov_attr_set_init + gov_attr_set_put + governor_sysfs_ops gpiochip_get_data gpiochip_line_is_irq gpiod_direction_input @@ -239,6 +247,7 @@ handle_bad_irq handle_edge_irq handle_level_irq + have_governor_per_policy i2c_del_driver i2c_register_driver i2c_smbus_read_byte_data @@ -311,6 +320,7 @@ irq_of_parse_and_map irq_set_irq_type irq_set_irq_wake + irq_work_sync is_console_locked jiffies jiffies_to_msecs @@ -1419,6 +1429,7 @@ mbox_controller_unregister mbox_free_channel mbox_request_channel + mbox_request_channel_byname mbox_send_message register_syscore_ops @@ -2526,3 +2537,15 @@ snd_pcm_rate_bit_to_rate snd_soc_bytes_info_ext snd_soc_new_compress + +# cpufreq_interactive.ko + add_timer_on + cpufreq_register_notifier + cpufreq_table_index_unsorted + cpufreq_unregister_notifier + down_read_trylock + get_cpu_idle_time + irq_work_queue + kobject_init_and_add + sched_setscheduler_nocheck + strpbrk