From c797384edc967d42ee00e3cafaf2f20a826cbe45 Mon Sep 17 00:00:00 2001 From: Suren Baghdasaryan Date: Tue, 8 Dec 2020 11:44:29 -0800 Subject: [PATCH 1/6] ANDROID: kthread: break dependency between worker->lock and task_struct->pi_lock A number of kthread-related functions indirectly take task_struct->pi_lock while holding worker->lock in the call chain like this: spin_lock(&worker->lock) kthread_insert_work wake_up_process try_to_wake_up raw_spin_lock_irqsave(&p->pi_lock, flags) This lock dependency exists whenever kthread_insert_work is called either directly or indirectly via __kthread_queue_delayed_work in the following functions: kthread_queue_work kthread_delayed_work_timer_fn kthread_queue_delayed_work kthread_flush_work kthread_mod_delayed_work This creates possibilities for circular dependencies like the one reported at [1]. Break this lock dependency by moving task wakeup after worker->lock has been released. [1]: https://lore.kernel.org/lkml/CAJuCfpG4NkhpQvZjgXZ_3gm6Hf1QgN_eUOQ8iX9Cv1k9whLwSQ@mail.gmail.com Reported-by: Ke Wang Reported-by: Shakeel Butt Suggested-by: Peter Zijlstra Tested-by: Shakeel Butt Signed-off-by: Suren Baghdasaryan Link: https://lkml.org/lkml/2020/5/4/1148 Cherry picked instead of commit 461daba06bdcb9c7a3f92b9bbd110e1f7d093ffc as an alternative solution for the lockdep error that does not break KMI. Bug: 174875976 Signed-off-by: Suren Baghdasaryan Change-Id: I2478847f66c85dca953846cd77955928d690c97c --- kernel/kthread.c | 44 +++++++++++++++++++++++++++++++++----------- 1 file changed, 33 insertions(+), 11 deletions(-) diff --git a/kernel/kthread.c b/kernel/kthread.c index 1e9bf63a30de..ec0bdcc79ef9 100644 --- a/kernel/kthread.c +++ b/kernel/kthread.c @@ -9,6 +9,7 @@ #include #include #include +#include #include #include #include @@ -806,14 +807,15 @@ static void kthread_insert_work_sanity_check(struct kthread_worker *worker, /* insert @work before @pos in @worker */ static void kthread_insert_work(struct kthread_worker *worker, struct kthread_work *work, - struct list_head *pos) + struct list_head *pos, + struct wake_q_head *wake_q) { kthread_insert_work_sanity_check(worker, work); list_add_tail(&work->node, pos); work->worker = worker; if (!worker->current_work && likely(worker->task)) - wake_up_process(worker->task); + wake_q_add(wake_q, worker->task); } /** @@ -831,15 +833,19 @@ static void kthread_insert_work(struct kthread_worker *worker, bool kthread_queue_work(struct kthread_worker *worker, struct kthread_work *work) { - bool ret = false; + DEFINE_WAKE_Q(wake_q); unsigned long flags; + bool ret = false; raw_spin_lock_irqsave(&worker->lock, flags); if (!queuing_blocked(worker, work)) { - kthread_insert_work(worker, work, &worker->work_list); + kthread_insert_work(worker, work, &worker->work_list, &wake_q); ret = true; } raw_spin_unlock_irqrestore(&worker->lock, flags); + + wake_up_q(&wake_q); + return ret; } EXPORT_SYMBOL_GPL(kthread_queue_work); @@ -857,6 +863,7 @@ void kthread_delayed_work_timer_fn(struct timer_list *t) struct kthread_delayed_work *dwork = from_timer(dwork, t, timer); struct kthread_work *work = &dwork->work; struct kthread_worker *worker = work->worker; + DEFINE_WAKE_Q(wake_q); unsigned long flags; /* @@ -873,15 +880,18 @@ void kthread_delayed_work_timer_fn(struct timer_list *t) /* Move the work from worker->delayed_work_list. */ WARN_ON_ONCE(list_empty(&work->node)); list_del_init(&work->node); - kthread_insert_work(worker, work, &worker->work_list); + kthread_insert_work(worker, work, &worker->work_list, &wake_q); raw_spin_unlock_irqrestore(&worker->lock, flags); + + wake_up_q(&wake_q); } EXPORT_SYMBOL(kthread_delayed_work_timer_fn); static void __kthread_queue_delayed_work(struct kthread_worker *worker, struct kthread_delayed_work *dwork, - unsigned long delay) + unsigned long delay, + struct wake_q_head *wake_q) { struct timer_list *timer = &dwork->timer; struct kthread_work *work = &dwork->work; @@ -897,7 +907,7 @@ static void __kthread_queue_delayed_work(struct kthread_worker *worker, * on that there's no such delay when @delay is 0. */ if (!delay) { - kthread_insert_work(worker, work, &worker->work_list); + kthread_insert_work(worker, work, &worker->work_list, wake_q); return; } @@ -930,17 +940,21 @@ bool kthread_queue_delayed_work(struct kthread_worker *worker, unsigned long delay) { struct kthread_work *work = &dwork->work; + DEFINE_WAKE_Q(wake_q); unsigned long flags; bool ret = false; raw_spin_lock_irqsave(&worker->lock, flags); if (!queuing_blocked(worker, work)) { - __kthread_queue_delayed_work(worker, dwork, delay); + __kthread_queue_delayed_work(worker, dwork, delay, &wake_q); ret = true; } raw_spin_unlock_irqrestore(&worker->lock, flags); + + wake_up_q(&wake_q); + return ret; } EXPORT_SYMBOL_GPL(kthread_queue_delayed_work); @@ -969,6 +983,7 @@ void kthread_flush_work(struct kthread_work *work) KTHREAD_WORK_INIT(fwork.work, kthread_flush_work_fn), COMPLETION_INITIALIZER_ONSTACK(fwork.done), }; + DEFINE_WAKE_Q(wake_q); struct kthread_worker *worker; bool noop = false; @@ -981,15 +996,18 @@ void kthread_flush_work(struct kthread_work *work) WARN_ON_ONCE(work->worker != worker); if (!list_empty(&work->node)) - kthread_insert_work(worker, &fwork.work, work->node.next); + kthread_insert_work(worker, &fwork.work, + work->node.next, &wake_q); else if (worker->current_work == work) kthread_insert_work(worker, &fwork.work, - worker->work_list.next); + worker->work_list.next, &wake_q); else noop = true; raw_spin_unlock_irq(&worker->lock); + wake_up_q(&wake_q); + if (!noop) wait_for_completion(&fwork.done); } @@ -1067,6 +1085,7 @@ bool kthread_mod_delayed_work(struct kthread_worker *worker, unsigned long delay) { struct kthread_work *work = &dwork->work; + DEFINE_WAKE_Q(wake_q); unsigned long flags; int ret = false; @@ -1085,9 +1104,12 @@ bool kthread_mod_delayed_work(struct kthread_worker *worker, ret = __kthread_cancel_work(work, true, &flags); fast_queue: - __kthread_queue_delayed_work(worker, dwork, delay); + __kthread_queue_delayed_work(worker, dwork, delay, &wake_q); out: raw_spin_unlock_irqrestore(&worker->lock, flags); + + wake_up_q(&wake_q); + return ret; } EXPORT_SYMBOL_GPL(kthread_mod_delayed_work); From 9c7d617b7c21b357e0bb29d1c284f11d5f6bdb7a Mon Sep 17 00:00:00 2001 From: Zhiqiang Tu Date: Fri, 11 Dec 2020 08:34:43 +0800 Subject: [PATCH 2/6] ANDROID: ABI: Update allowed list for QCOM Leaf changes summary: 0 artifact changed Changed leaf types summary: 0 leaf type changed Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 0 Added function Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable Bug: 175333697 Change-Id: I03fa6c2d6f71d266ee2352728bf7858b673d2215 Signed-off-by: Zhiqiang Tu --- android/abi_gki_aarch64_qcom | 1 + 1 file changed, 1 insertion(+) diff --git a/android/abi_gki_aarch64_qcom b/android/abi_gki_aarch64_qcom index e0f01ecc7aeb..2d4aee796cb1 100644 --- a/android/abi_gki_aarch64_qcom +++ b/android/abi_gki_aarch64_qcom @@ -1467,6 +1467,7 @@ netlink_unicast net_ratelimit new_inode + nf_conntrack_destroy nla_memcpy __nla_parse nla_put_64bit From bf9fcff8a893bc2f97c0d41e844bc34aea4527c2 Mon Sep 17 00:00:00 2001 From: Wei Wang Date: Thu, 10 Dec 2020 11:03:43 -0800 Subject: [PATCH 3/6] ANDROID: x86: configs: gki: add missing CONFIG_BLK_CGROUP Bug: 175265928 Test: Build Signed-off-by: Wei Wang Change-Id: I4902ceee5b533f918e70d37073cb4eb47d35a544 --- arch/x86/configs/gki_defconfig | 1 + 1 file changed, 1 insertion(+) diff --git a/arch/x86/configs/gki_defconfig b/arch/x86/configs/gki_defconfig index 1eb71a655cc3..8d50179d79c6 100644 --- a/arch/x86/configs/gki_defconfig +++ b/arch/x86/configs/gki_defconfig @@ -20,6 +20,7 @@ CONFIG_UCLAMP_TASK=y CONFIG_CGROUPS=y CONFIG_MEMCG=y CONFIG_MEMCG_SWAP=y +CONFIG_BLK_CGROUP=y CONFIG_CGROUP_SCHED=y # CONFIG_FAIR_GROUP_SCHED is not set CONFIG_UCLAMP_TASK_GROUP=y From 35042a2a919e017ef1c69f4fd15e07d54ab4f05a Mon Sep 17 00:00:00 2001 From: kaliu Date: Wed, 9 Dec 2020 22:00:05 -0800 Subject: [PATCH 4/6] ANDROID: ABI: Update allowed list for QCOM Leaf changes summary: 1 artifact changed Changed leaf types summary: 0 leaf type changed Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable 1 Added function: [A] 'function int pci_dev_present(const pci_device_id*)' Bug: 175266632 Change-Id: I9dc7e1c258ccdc907e5584bf66ed9d2c39038941 Signed-off-by: Kai Liu Signed-off-by: kaliu --- android/abi_gki_aarch64.xml | 876 ++++++++++++++++++----------------- android/abi_gki_aarch64_qcom | 1 + 2 files changed, 446 insertions(+), 431 deletions(-) diff --git a/android/abi_gki_aarch64.xml b/android/abi_gki_aarch64.xml index 41eb6b5ddfae..77fd73d8c10c 100644 --- a/android/abi_gki_aarch64.xml +++ b/android/abi_gki_aarch64.xml @@ -2682,6 +2682,7 @@ + @@ -11459,6 +11460,23 @@ + + + + + + + + + + + + + + + + + @@ -14468,23 +14486,6 @@ - - - - - - - - - - - - - - - - - @@ -16008,7 +16009,7 @@ - + @@ -16078,18 +16079,18 @@ - + - + - + @@ -16097,7 +16098,7 @@ - + @@ -37764,7 +37765,6 @@ - @@ -54745,25 +54745,6 @@ - - - - - - - - - - - - - - - - - - - @@ -56042,7 +56023,7 @@ - + @@ -56067,8 +56048,8 @@ - - + + @@ -56096,20 +56077,6 @@ - - - - - - - - - - - - - - @@ -63854,7 +63821,7 @@ - + @@ -63863,7 +63830,7 @@ - + @@ -67901,6 +67868,10 @@ + + + + @@ -72944,6 +72915,22 @@ + + + + + + + + + + + + + + + + @@ -73522,22 +73509,6 @@ - - - - - - - - - - - - - - - - @@ -89134,23 +89105,6 @@ - - - - - - - - - - - - - - - - - @@ -89497,14 +89451,6 @@ - - - - - - - - @@ -89953,7 +89899,7 @@ - + @@ -91372,7 +91318,7 @@ - + @@ -91571,7 +91517,7 @@ - + @@ -91717,17 +91663,6 @@ - - - - - - - - - - - @@ -93397,14 +93332,14 @@ - + - - + + - + @@ -93413,69 +93348,69 @@ - - - + + + - - - - + + + + - - + + - - - + + + - - - + + + - - + + - - - - + + + + - - + + - - - - + + + + - - + + - - + + - - + + - - + + @@ -108981,240 +108916,9 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - @@ -109367,18 +109071,7 @@ - - - - - - - - - - - @@ -109567,13 +109260,6 @@ - - - - - - - @@ -109581,10 +109267,6 @@ - - - - @@ -109799,7 +109481,7 @@ - + @@ -110505,6 +110187,17 @@ + + + + + + + + + + + @@ -113848,25 +113541,6 @@ - - - - - - - - - - - - - - - - - - - @@ -115836,6 +115510,25 @@ + + + + + + + + + + + + + + + + + + + @@ -118561,7 +118254,268 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -118645,6 +118599,17 @@ + + + + + + + + + + + @@ -118708,7 +118673,6 @@ - @@ -123290,6 +123254,14 @@ + + + + + + + + @@ -124597,6 +124569,47 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -125347,9 +125360,10 @@ + - + @@ -130921,6 +130935,6 @@ diff --git a/android/abi_gki_aarch64_qcom b/android/abi_gki_aarch64_qcom index 2d4aee796cb1..a09d7f31e4f1 100644 --- a/android/abi_gki_aarch64_qcom +++ b/android/abi_gki_aarch64_qcom @@ -1665,6 +1665,7 @@ pci_walk_bus pci_write_config_dword pci_write_config_word + pci_dev_present PDE_DATA __per_cpu_offset perf_trace_buf_alloc From 5d835560a3344d8fea2194d63930583f7cb916e9 Mon Sep 17 00:00:00 2001 From: Sudarshan Rajagopalan Date: Wed, 28 Oct 2020 14:31:09 -0700 Subject: [PATCH 5/6] ANDROID: mm/memblock: export memblock_end_of_DRAM Export memblock_end_of_DRAM() so that module drivers can know the physical end address of memory blocks that system booted with. Bug: 174547201 Change-Id: Ib0c90b736f16d1abbf47d4f3288443c35f9e17b4 Signed-off-by: Sudarshan Rajagopalan Signed-off-by: Stanley Chu --- mm/memblock.c | 1 + 1 file changed, 1 insertion(+) diff --git a/mm/memblock.c b/mm/memblock.c index 1256c0c3a997..ce64a6b6f2c0 100644 --- a/mm/memblock.c +++ b/mm/memblock.c @@ -1626,6 +1626,7 @@ phys_addr_t __init_memblock memblock_end_of_DRAM(void) return (memblock.memory.regions[idx].base + memblock.memory.regions[idx].size); } +EXPORT_SYMBOL_GPL(memblock_end_of_DRAM); static phys_addr_t __init_memblock __find_max_addr(phys_addr_t limit) { From e0b1644a472e806b7b8c0110de81913bb2dbc918 Mon Sep 17 00:00:00 2001 From: Charan Teja Reddy Date: Mon, 14 Dec 2020 11:18:09 +0800 Subject: [PATCH 6/6] BACKPORT: dmabuf: fix NULL pointer dereference in dma_buf_release() MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit NULL pointer dereference is observed while exporting the dmabuf but failed to allocate the 'struct file' which results into the dropping of the allocated dentry corresponding to this file in the dmabuf fs, which is ending up in dma_buf_release() and accessing the uninitialzed dentry->d_fsdata. Call stack on 5.4 is below: dma_buf_release+0x2c/0x254 drivers/dma-buf/dma-buf.c:88 __dentry_kill+0x294/0x31c fs/dcache.c:584 dentry_kill fs/dcache.c:673 [inline] dput+0x250/0x380 fs/dcache.c:859 path_put+0x24/0x40 fs/namei.c:485 alloc_file_pseudo+0x1a4/0x200 fs/file_table.c:235 dma_buf_getfile drivers/dma-buf/dma-buf.c:473 [inline] dma_buf_export+0x25c/0x3ec drivers/dma-buf/dma-buf.c:585 Fix this by checking for the valid pointer in the dentry->d_fsdata. cherry picked from commit 19a508bd1ad8e444de86873bf2f2b2ab8edd6552 Bug: 175512919 Link: https://patchwork.freedesktop.org/patch/391319/ Change-Id: I3856a387d1902fd2b39b016e81283f082089131c Cc: [5.7+] Signed-off-by: Charan Teja Reddy Signed-off-by: Christian König Reviewed-by: Christian König Signed-off-by: Chao Hao Signed-off-by: Chun-Hung Wu --- drivers/dma-buf/dma-buf.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/dma-buf/dma-buf.c b/drivers/dma-buf/dma-buf.c index 92f04a31c326..8e820bb0ec85 100644 --- a/drivers/dma-buf/dma-buf.c +++ b/drivers/dma-buf/dma-buf.c @@ -59,6 +59,8 @@ static void dma_buf_release(struct dentry *dentry) struct dma_buf *dmabuf; dmabuf = dentry->d_fsdata; + if (unlikely(!dmabuf)) + return; BUG_ON(dmabuf->vmapping_counter);