From 687f2e3e5da40cc9e9140d9af72c9d2be502810d Mon Sep 17 00:00:00 2001 From: Shivakumar Malke Date: Wed, 23 Nov 2022 15:34:13 +0530 Subject: [PATCH] msm: camera: lrme: BL command length validation This change is to validate BL command length and addresses before submitting to CDM. Also as part of recovery avoids moving wrong packet submit request to pending queue. CRs-Fixed: 3342983 Change-Id: I15f082cdd4d54ad6bf0e446115780829b3b711dd Signed-off-by: Shivakumar Malke --- .../cam_lrme/lrme_hw_mgr/cam_lrme_hw_mgr.c | 49 +++++++++++++------ 1 file changed, 34 insertions(+), 15 deletions(-) diff --git a/drivers/cam_lrme/lrme_hw_mgr/cam_lrme_hw_mgr.c b/drivers/cam_lrme/lrme_hw_mgr/cam_lrme_hw_mgr.c index 53ca5442e03f..38feacabb941 100644 --- a/drivers/cam_lrme/lrme_hw_mgr/cam_lrme_hw_mgr.c +++ b/drivers/cam_lrme/lrme_hw_mgr/cam_lrme_hw_mgr.c @@ -330,7 +330,6 @@ static int cam_lrme_mgr_util_prepare_hw_update_entries( CAM_ERR(CAM_LRME, "Exceed max num of entry"); return -EINVAL; } - hw_entry[num_entry].handle = cmd_desc[i].mem_handle; hw_entry[num_entry].len = cmd_desc[i].length; hw_entry[num_entry].offset = cmd_desc[i].offset; @@ -425,22 +424,27 @@ static int cam_lrme_mgr_util_submit_req(void *priv, void *data) CAM_LRME_HW_CMD_SUBMIT, &submit_args, sizeof(struct cam_lrme_hw_submit_args)); - if (rc == -EBUSY) - CAM_DBG(CAM_LRME, "device busy"); - else if (rc) - CAM_ERR(CAM_LRME, "submit request failed rc %d", rc); if (rc) { - req_prio == 0 ? spin_lock(&hw_device->high_req_lock) : - spin_lock(&hw_device->normal_req_lock); - list_add(&frame_req->frame_list, - (req_prio == 0 ? - &hw_device->frame_pending_list_high : - &hw_device->frame_pending_list_normal)); - req_prio == 0 ? spin_unlock(&hw_device->high_req_lock) : - spin_unlock(&hw_device->normal_req_lock); + if (rc == -EBUSY) { + CAM_DBG(CAM_LRME, "device busy"); + + req_prio == 0 ? + spin_lock(&hw_device->high_req_lock) : + spin_lock(&hw_device->normal_req_lock); + list_add(&frame_req->frame_list, + (req_prio == 0 ? + &hw_device->frame_pending_list_high : + &hw_device->frame_pending_list_normal)); + req_prio == 0 ? + spin_unlock(&hw_device->high_req_lock) : + spin_unlock( + &hw_device->normal_req_lock); + rc = 0; + } else + CAM_ERR(CAM_LRME, + "submit request failed for frame req id: %llu rc %d", + frame_req->req_id, rc); } - if (rc == -EBUSY) - rc = 0; } else { req_prio == 0 ? spin_lock(&hw_device->high_req_lock) : spin_lock(&hw_device->normal_req_lock); @@ -709,6 +713,7 @@ static int cam_lrme_mgr_hw_flush(void *hw_mgr_priv, void *hw_flush_args) struct cam_hw_flush_args *args; struct cam_lrme_device *hw_device; struct cam_lrme_frame_request *frame_req = NULL, *req_to_flush = NULL; + struct cam_lrme_frame_request *frame_req_temp = NULL; struct cam_lrme_frame_request **req_list = NULL; uint32_t device_index; struct cam_lrme_hw_flush_args lrme_flush_args; @@ -733,6 +738,20 @@ static int cam_lrme_mgr_hw_flush(void *hw_mgr_priv, void *hw_flush_args) goto end; } + spin_lock(&hw_device->high_req_lock); + list_for_each_entry_safe(frame_req, frame_req_temp, + &hw_device->frame_pending_list_high, frame_list) { + list_del_init(&frame_req->frame_list); + } + spin_unlock(&hw_device->high_req_lock); + + spin_lock(&hw_device->normal_req_lock); + list_for_each_entry_safe(frame_req, frame_req_temp, + &hw_device->frame_pending_list_normal, frame_list) { + list_del_init(&frame_req->frame_list); + } + spin_unlock(&hw_device->normal_req_lock); + req_list = (struct cam_lrme_frame_request **)args->flush_req_pending; for (i = 0; i < args->num_req_pending; i++) { frame_req = req_list[i];