From 65b7a17e0f1b6408ae406779af539f07bb804de0 Mon Sep 17 00:00:00 2001 From: Vignesh Kulothungan Date: Tue, 12 Dec 2017 17:33:24 -0800 Subject: [PATCH 1/2] dsp: Update ADSP status to reflect failure Update the adsp status to log failures during AVCS_CMDRSP_GET_FWK_VERSION callback. Set q6core_avcs_ver_info status to VER_QUERY_SUPPORTED only when there is a valid ADSP response for framework version. Change-Id: Ie2c6db2842c0b89c9d1a3807bcb49d413a639988 Signed-off-by: Vignesh Kulothungan --- dsp/q6core.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/dsp/q6core.c b/dsp/q6core.c index 5e09faa7d7e8..e7c41bb9c2c9 100644 --- a/dsp/q6core.c +++ b/dsp/q6core.c @@ -1,4 +1,4 @@ -/* Copyright (c) 2012-2017, The Linux Foundation. All rights reserved. +/* Copyright (c) 2012-2018, The Linux Foundation. All rights reserved. * * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License version 2 and @@ -236,12 +236,16 @@ static int32_t aprv2_core_fn_q(struct apr_client_data *data, void *priv) pr_debug("%s: Received AVCS_CMDRSP_GET_FWK_VERSION\n", __func__); payload1 = data->payload; - q6core_lcl.q6core_avcs_ver_info.status = VER_QUERY_SUPPORTED; q6core_lcl.avcs_fwk_ver_resp_received = 1; ret = parse_fwk_version_info(payload1); - if (ret < 0) + if (ret < 0) { + q6core_lcl.adsp_status = ret; pr_err("%s: Failed to parse payload:%d\n", __func__, ret); + } else { + q6core_lcl.q6core_avcs_ver_info.status = + VER_QUERY_SUPPORTED; + } wake_up(&q6core_lcl.avcs_fwk_ver_req_wait); break; default: From 9ae2ddedeee49c7b81475aa1339c35a86e5983d1 Mon Sep 17 00:00:00 2001 From: Aditya Bavanari Date: Tue, 9 Jan 2018 11:35:29 +0530 Subject: [PATCH 2/2] dsp: fix NULL pointer exception in core driver NULL pointer dereference occurs while getting version size when version info memory allocation fails. Add NULL check to avoid this NULL pointer exception. CRs-Fixed: 2142971 Change-Id: I47a905a9b4e767d54b406a279626369f18a861d9 Signed-off-by: Aditya Bavanari --- dsp/q6core.c | 15 ++++++++++----- 1 file changed, 10 insertions(+), 5 deletions(-) diff --git a/dsp/q6core.c b/dsp/q6core.c index e7c41bb9c2c9..c5b64096a234 100644 --- a/dsp/q6core.c +++ b/dsp/q6core.c @@ -108,8 +108,7 @@ static int parse_fwk_version_info(uint32_t *payload) */ ver_size = sizeof(struct avcs_get_fwk_version) + num_services * sizeof(struct avs_svc_api_info); - if (q6core_lcl.q6core_avcs_ver_info.ver_info != NULL) - pr_warn("%s: Version info is not NULL\n", __func__); + q6core_lcl.q6core_avcs_ver_info.ver_info = kzalloc(ver_size, GFP_ATOMIC); if (q6core_lcl.q6core_avcs_ver_info.ver_info == NULL) @@ -236,7 +235,6 @@ static int32_t aprv2_core_fn_q(struct apr_client_data *data, void *priv) pr_debug("%s: Received AVCS_CMDRSP_GET_FWK_VERSION\n", __func__); payload1 = data->payload; - q6core_lcl.avcs_fwk_ver_resp_received = 1; ret = parse_fwk_version_info(payload1); if (ret < 0) { q6core_lcl.adsp_status = ret; @@ -246,6 +244,7 @@ static int32_t aprv2_core_fn_q(struct apr_client_data *data, void *priv) q6core_lcl.q6core_avcs_ver_info.status = VER_QUERY_SUPPORTED; } + q6core_lcl.avcs_fwk_ver_resp_received = 1; wake_up(&q6core_lcl.avcs_fwk_ver_req_wait); break; default: @@ -445,8 +444,14 @@ size_t q6core_get_fwk_version_size(uint32_t service_id) if (ret) goto done; - num_services = q6core_lcl.q6core_avcs_ver_info.ver_info - ->avcs_fwk_version.num_services; + if (q6core_lcl.q6core_avcs_ver_info.ver_info != NULL) { + num_services = q6core_lcl.q6core_avcs_ver_info.ver_info + ->avcs_fwk_version.num_services; + } else { + pr_err("%s: ver_info is NULL\n", __func__); + ret = -EINVAL; + goto done; + } ret = sizeof(struct avcs_get_fwk_version); if (service_id == AVCS_SERVICE_ID_ALL)