From 498eb6780a30d5cbb9bdb0e80bcdef206d305a42 Mon Sep 17 00:00:00 2001 From: Biao Li Date: Wed, 4 Aug 2021 17:29:31 +0800 Subject: [PATCH 1/4] ANDROID: fuse: Allocate zeroed memory for canonical path MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The page used to contain the fuse_dentry_canonical_path to be handled in fuse_dev_do_write is allocated using __get_free_pages(GFP_KERNEL). The returned page may contain undefined data, that by chance may be considered as a valid path name that is not in the cache. In that case, if the FUSE daemon mistakenly doesn't fill the canonical path buffer, the FUSE driver may fall into two blocking request_wait_answer(fuse_dev_write->kern_path->fuse_lookup_name) causing a deadlock condition. The stack is as follows: find S 0 20511 20117 0x00000000 Call trace: [] __switch_to+0xb8/0xd4 [] __schedule+0x458/0x714 [] schedule+0x8c/0xa8 [] request_wait_answer+0x74/0x220 [] __fuse_request_send+0x8c/0xa0 [] fuse_request_send+0x60/0x6c [] fuse_dentry_canonical_path+0xb8/0x104 [] do_sys_open+0x1b4/0x260 [] SyS_openat+0x3c/0x4c [] el0_svc_naked+0x34/0x38 mount.ntfs-3g S 0 5845 1 0x00000000 Call trace: [] __switch_to+0xb8/0xd4 [] __schedule+0x458/0x714 [] schedule+0x8c/0xa8 [] request_wait_answer+0x74/0x220 [] __fuse_request_send+0x8c/0xa0 [] fuse_request_send+0x60/0x6c [] fuse_simple_request+0x128/0x16c [] fuse_lookup_name+0x104/0x1b0 [] fuse_lookup+0x5c/0x11c [] lookup_slow+0xfc/0x174 [] walk_component+0xf0/0x290 [] path_lookupat+0xa0/0x128 [] filename_lookup+0x84/0x124 [] kern_path+0x44/0x54 [] fuse_dev_do_write+0x828/0xa0c [] fuse_dev_write+0x90/0xb4 [] do_iter_readv_writev+0xf4/0x13c [] do_readv_writev+0xec/0x220 [] vfs_writev+0x60/0x74 [] do_writev+0x7c/0x100 [] SyS_writev+0x38/0x48 [] el0_svc_naked+0x34/0x38 Fix by ensuring that the page allocated for the canonical path is zeroed. Bug: 194856119 Fixes: 24ab59f6bb42 ("ANDROID: fuse: Add support for d_canonical_path") Signed-off-by: Biao Li Signed-off-by: Shuosheng Huang Signed-off-by: Alessio Balsini Change-Id: I400815dc1049d90c308f5cf87ce60de97ff82131 --- fs/fuse/dir.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/fs/fuse/dir.c b/fs/fuse/dir.c index ebd1927b2f61..be2e7c359490 100644 --- a/fs/fuse/dir.c +++ b/fs/fuse/dir.c @@ -311,7 +311,7 @@ static void fuse_dentry_canonical_path(const struct path *path, struct path *can char *path_name; int err; - path_name = (char*)__get_free_page(GFP_KERNEL); + path_name = (char *)get_zeroed_page(GFP_KERNEL); if (!path_name) goto default_path; From aa64559e554fabb969a069d59ca7bc7ea2c43e3d Mon Sep 17 00:00:00 2001 From: Nobutaka Matsuo Date: Thu, 29 Jul 2021 12:53:01 -0700 Subject: [PATCH 2/4] ANDROID: GKI: Add FCNT KMI symbol list No new symbols added that are not already in the .xml file. Bug: 194979426 Change-Id: I5fad2df65c189bf0afbefeff2aeab19c500552dd Signed-off-by: Nobutaka Matsuo Signed-off-by: Greg Kroah-Hartman --- android/abi_gki_aarch64_fcnt | 71 ++++++++++++++++++++++++++++++++++++ build.config.gki.aarch64 | 1 + 2 files changed, 72 insertions(+) create mode 100644 android/abi_gki_aarch64_fcnt diff --git a/android/abi_gki_aarch64_fcnt b/android/abi_gki_aarch64_fcnt new file mode 100644 index 000000000000..67e6f4284fb1 --- /dev/null +++ b/android/abi_gki_aarch64_fcnt @@ -0,0 +1,71 @@ +[abi_symbol_list] +# required by appnv.ko + __lock_page + sync_blockdev + read_cache_page + blkdev_put + blkdev_get_by_dev + +# required by pt.ko + input_mt_sync_frame + mod_timer_pending + +# required by pt_device_access.ko + device_remove_bin_file + request_firmware_direct + +# required by msm_drm.ko + mipi_dsi_dcs_write_buffer + +# required by earphonedrv.ko + gpiod_put + iio_read_channel_raw + +# required by drv260x.ko + devm_led_classdev_unregister + regmap_multi_reg_write + +# required by leds-gpio.ko + gpiod_set_consumer_name + +# required by qpnp-smb5-main.ko + param_get_uint + round_jiffies_relative + emergency_restart + +# required by fj_watchdog.ko + del_timer + panic + param_get_uint + param_set_int + platform_device_register + +# required by sleep_time_log.ko + register_pm_notifier + rtc_time64_to_tm + unregister_pm_notifier + +# required by aw_haptic.ko + devm_gpio_free + +# required by fs18xx_dlkm.ko + snd_pcm_format_physical_width + snd_pcm_hw_constraint_mask64 + +# required by camera.ko + i2c_unregister_device + i2c_smbus_write_byte_data + i2c_smbus_read_byte_data + +# required by semi_touch_driver.ko + vfs_llseek + +# required by cdfingerfp.ko + wakeup_source_remove + wakeup_source_add + +# required by drv2624-ram.ko + devm_led_classdev_unregister + +# required by chipone-ts.ko + input_mt_sync_frame diff --git a/build.config.gki.aarch64 b/build.config.gki.aarch64 index 6ce620fe85bf..754a6be5c1aa 100644 --- a/build.config.gki.aarch64 +++ b/build.config.gki.aarch64 @@ -9,6 +9,7 @@ android/abi_gki_aarch64_cuttlefish android/abi_gki_aarch64_db845c android/abi_gki_aarch64_exynos android/abi_gki_aarch64_exynosauto +android/abi_gki_aarch64_fcnt android/abi_gki_aarch64_galaxy android/abi_gki_aarch64_goldfish android/abi_gki_aarch64_hikey960 From d09f0a4e233f08c3b9bd3e165fd5e5b26a8d7f6a Mon Sep 17 00:00:00 2001 From: Alistair Delva Date: Fri, 6 Aug 2021 11:16:02 -0700 Subject: [PATCH 3/4] ANDROID: GKI: Disable X86_MCE drivers Android does not use these drivers and enabling them causes additional and unwanted epoll wakeups due to uevents at suspend/resume time. Bug: 195607946 Signed-off-by: Alistair Delva Change-Id: Id3d58dc695c0cd6d2a65503a421de1afebd83784 --- arch/x86/configs/gki_defconfig | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/x86/configs/gki_defconfig b/arch/x86/configs/gki_defconfig index 1fb1554bd5dc..869128096c38 100644 --- a/arch/x86/configs/gki_defconfig +++ b/arch/x86/configs/gki_defconfig @@ -53,6 +53,7 @@ CONFIG_X86_X2APIC=y CONFIG_HYPERVISOR_GUEST=y CONFIG_PARAVIRT=y CONFIG_NR_CPUS=32 +# CONFIG_X86_MCE is not set CONFIG_EFI=y CONFIG_PM_WAKELOCKS=y CONFIG_PM_WAKELOCKS_LIMIT=0 @@ -304,7 +305,6 @@ CONFIG_THERMAL_GOV_POWER_ALLOCATOR=y CONFIG_CPU_THERMAL=y CONFIG_DEVFREQ_THERMAL=y CONFIG_THERMAL_EMULATION=y -# CONFIG_X86_PKG_TEMP_THERMAL is not set CONFIG_WATCHDOG=y CONFIG_WATCHDOG_CORE=y CONFIG_MFD_SYSCON=y From 4417145c4f3880a118c035f8f6228dca5ee0aa3a Mon Sep 17 00:00:00 2001 From: Will Deacon Date: Thu, 18 Mar 2021 17:07:37 +0000 Subject: [PATCH 4/4] UPSTREAM: arm64: vdso: Avoid ISB after reading from cntvct_el0 commit 77ec462536a13d4b428a1eead725c4818a49f0b1 upstream. (The upstream patch was not marked as fixed but this can fix Fixes: 28b1a824a4f4 ("arm64: vdso: Substitute gettimeofday() with C implementation") sysbench memory comparison: - Before: 3072.00 MB transferred (2601.11 MB/sec) - After: 3072.00 MB transferred (3217.86 MB/sec) ) We can avoid the expensive ISB instruction after reading the counter in the vDSO gettime functions by creating a fake address hazard against a dummy stack read, just like we do inside the kernel. Bug: 195968646 Fixes: 28b1a824a4f4 ("arm64: vdso: Substitute gettimeofday() with C implementation") Signed-off-by: Will Deacon Reviewed-by: Vincenzo Frascino Link: https://lore.kernel.org/r/20210318170738.7756-5-will@kernel.org Signed-off-by: Catalin Marinas CC: stable@vger.kernel.org (cherry picked from commit 77ec462536a13d4b428a1eead725c4818a49f0b1) Signed-off-by: Chanho Park Change-Id: I891873626c27060e7ead724754096a7c5f59e4e6 --- arch/arm64/include/asm/arch_timer.h | 21 --------------------- arch/arm64/include/asm/barrier.h | 19 +++++++++++++++++++ arch/arm64/include/asm/vdso/gettimeofday.h | 6 +----- 3 files changed, 20 insertions(+), 26 deletions(-) diff --git a/arch/arm64/include/asm/arch_timer.h b/arch/arm64/include/asm/arch_timer.h index 9f0ec21d6327..88d20f04c64a 100644 --- a/arch/arm64/include/asm/arch_timer.h +++ b/arch/arm64/include/asm/arch_timer.h @@ -165,25 +165,6 @@ static inline void arch_timer_set_cntkctl(u32 cntkctl) isb(); } -/* - * Ensure that reads of the counter are treated the same as memory reads - * for the purposes of ordering by subsequent memory barriers. - * - * This insanity brought to you by speculative system register reads, - * out-of-order memory accesses, sequence locks and Thomas Gleixner. - * - * http://lists.infradead.org/pipermail/linux-arm-kernel/2019-February/631195.html - */ -#define arch_counter_enforce_ordering(val) do { \ - u64 tmp, _val = (val); \ - \ - asm volatile( \ - " eor %0, %1, %1\n" \ - " add %0, sp, %0\n" \ - " ldr xzr, [%0]" \ - : "=r" (tmp) : "r" (_val)); \ -} while (0) - static __always_inline u64 __arch_counter_get_cntpct_stable(void) { u64 cnt; @@ -224,8 +205,6 @@ static __always_inline u64 __arch_counter_get_cntvct(void) return cnt; } -#undef arch_counter_enforce_ordering - static inline int arch_timer_arch_init(void) { return 0; diff --git a/arch/arm64/include/asm/barrier.h b/arch/arm64/include/asm/barrier.h index e0e2b1946f42..0fcd854fc95f 100644 --- a/arch/arm64/include/asm/barrier.h +++ b/arch/arm64/include/asm/barrier.h @@ -57,6 +57,25 @@ static inline unsigned long array_index_mask_nospec(unsigned long idx, return mask; } +/* + * Ensure that reads of the counter are treated the same as memory reads + * for the purposes of ordering by subsequent memory barriers. + * + * This insanity brought to you by speculative system register reads, + * out-of-order memory accesses, sequence locks and Thomas Gleixner. + * + * http://lists.infradead.org/pipermail/linux-arm-kernel/2019-February/631195.html + */ +#define arch_counter_enforce_ordering(val) do { \ + u64 tmp, _val = (val); \ + \ + asm volatile( \ + " eor %0, %1, %1\n" \ + " add %0, sp, %0\n" \ + " ldr xzr, [%0]" \ + : "=r" (tmp) : "r" (_val)); \ +} while (0) + #define __smp_mb() dmb(ish) #define __smp_rmb() dmb(ishld) #define __smp_wmb() dmb(ishst) diff --git a/arch/arm64/include/asm/vdso/gettimeofday.h b/arch/arm64/include/asm/vdso/gettimeofday.h index 65d0331a8ac8..917519d6316c 100644 --- a/arch/arm64/include/asm/vdso/gettimeofday.h +++ b/arch/arm64/include/asm/vdso/gettimeofday.h @@ -86,11 +86,7 @@ static __always_inline u64 __arch_get_hw_counter(s32 clock_mode) */ isb(); asm volatile("mrs %0, cntvct_el0" : "=r" (res) :: "memory"); - /* - * This isb() is required to prevent that the seq lock is - * speculated.# - */ - isb(); + arch_counter_enforce_ordering(res); return res; }