A potential use after free can occur in _vm_unmap_aliases where an already
freed vmap_area could be accessed, Consider the following scenario:
Process 1 Process 2
__vm_unmap_aliases __vm_unmap_aliases
purge_fragmented_blocks_allcpus rcu_read_lock()
rcu_read_lock()
list_del_rcu(&vb->free_list)
list_for_each_entry_rcu(vb .. )
__purge_vmap_area_lazy
kmem_cache_free(va)
va_start = vb->va->va_start
Here Process 1 is in purge path and it does list_del_rcu on vmap_block and
later frees the vmap_area, since Process 2 was holding the rcu lock at
this time vmap_block will still be present in and Process 2 accesse it and
thereby it tries to access vmap_area of that vmap_block which was already
freed by Process 1 and this results in use after free.
Fix this by adding a check for vb->dirty before accessing vmap_area
structure since vb->dirty will be set to VMAP_BBMAP_BITS in purge path
checking for this will prevent the use after free.
Change-Id: Ibba0e2ee0d0f049aa0158b78b086aeaad6b70f68
Link: https://lkml.kernel.org/r/1616062105-23263-1-git-send-email-vjitta@codeaurora.org
Signed-off-by: Vijayanand Jitta <vjitta@codeaurora.org>
Git-Commit: ad216c0316ad6391d90f4de0a7f59396b2925a06
Git-Repo: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
Reviewed-by: Uladzislau Rezki (Sony) <urezki@gmail.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Add measure only support for QDSS related GCC clocks for
YUPIK.
Change-Id: Ia27282433a63d21929cad3bd8098cc91df445db8
Signed-off-by: Madhuri Medasani <mmedasan@codeaurora.org>
Add measure only support for QDSS related GCC clocks for
SHIMA.
Change-Id: I8aac50323865f71cc44461abb45a8ae97e75c314
Signed-off-by: Madhuri Medasani <mmedasan@codeaurora.org>
Moving boot KPI to sysnode by using “place_marker".
Change-Id: I0680584b23a63e4f185cf68c118e696ac956dd2e
Signed-off-by: Madhab Sharma <madhshar@codeaurora.org>
Update gcc_qup clocks of pm8008 to measure only
since these are not registered in GCC to avoid
the crash because of parent index in BLAIR.
Change-Id: Ia9d19b95331a43eab3c229405218e5871c073be1
Signed-off-by: Madhuri Medasani <mmedasan@codeaurora.org>
When changing USB speed via sysfs, the device might utilize the
idle time between DISCONNECT and CONNECT events and enter suspend.
As a result the pending CONNECT might get delayed thus pushing USB
enumeration during the next resume. Avoid this by not releasing the
wakeup source when usb restart is in progress.
Change-Id: I754b76eb7b36923a2dcd4d58587101750d1cd83c
Signed-off-by: Elson Roy Serrao <eserrao@codeaurora.org>
Defer mhi resume till M0 ack is notified to host.
This is to ensure no outstanding transfer completion events are
send to host before M0 ack.
Change-Id: Ia10fabc554b1cdef14a0771012b9ffea68851e25
Signed-off-by: Veerabhadrarao Badiganti <vbadigan@codeaurora.org>
When qdss open and close are called back to back at a high rate,
connect_work that gets queued in qdss open can execute after
qdss close. For qdss HW path the connect work that gets scheduled
as part of the next qdss open results in ep config failure as the
ep is already configured during previous connect work. Now before
queuing the request if there is a qdss close it would reset the dbm
ep configuration thus routing this request via software path instead
of dbm path. The subsequent dequeue would lead to a NULL pointer
dereference of completion callback. Fix this by flushing connect_work
as part of qdss close for graceful termination.
Change-Id: I8edf73ea1f87e297297828e6e25c7c14a422ec3a
Signed-off-by: Elson Roy Serrao <eserrao@codeaurora.org>
Use unshifted value to set the clock req override value
and enable fields as the register write function already
shifts the values to the correct position.
Change-Id: I0b5dea0f6f8462363471910ffe93f8f8975e7929
Signed-off-by: Siva Kumar Akkireddi <sivaa@codeaurora.org>
Signed-off-by: Veerabhadrarao Badiganti <vbadigan@codeaurora.org>
During D3hot, we are explicitly blocking L1 state by setting
REQ_EXIT_L1 bit of PM_CTRL register. If we transitioning back to D0
from D3 (without D3cold), REQ_EXIT_L1 bit won't get cleared. And
L1 would get blocked till next D3cold. Clear this explicitly during
D0 to avoid this scenario.
Change-Id: Ib168dee255f29832600ebca14eea1ac2ea393985
Signed-off-by: Veerabhadrarao Badiganti <vbadigan@codeaurora.org>
Change the clk_regmap_div_ro ops to clk_regmap_div ops to
allow dynamic configuration of the cdivs. This is required
for cphy configuration where the byte intf clock need to be
the same frequency as its byte clock.
Change-Id: Iddf733697b7287577f690bd5535a60f406b7129a
Signed-off-by: BIVASH KUMAR SINGH <bkumarsi@codeaurora.org>
This mem_lock will cause deadlock when usb close router call back to
usb_notifier. so remove it.
Change-Id: I9530c843702ca605f6935cc0ac6d9649bf204594
Signed-off-by: Yuanfang Zhang <zhangyuanfang@codeaurora.org>
Allow IOSS Shim layer to be dynamically loaded as a kernel module.
Change-Id: Iac293adfb29954b12253b1ee08f64077606091cc
Signed-off-by: Manuel Gomez <gomez@codeaurora.org>
Disable access to PCIE config space registers and notify client
driver to recover link on reading PCIE endpoint config registers
as FF's.
Change-Id: Iea6b25036bc6d967d6598d08348bb41fc18ef304
Signed-off-by: Vivek Pernamitta <vpernami@codeaurora.org>
Currently we are not initializing cb_num for secure context.
This is causing problems in the kgsl fault handler path when
there is a pagefault for secure context. Hence initialize cb_num
for secure context.
Change-Id: I35a37193f512f315f443e9f0d92fdae11411bbd2
Signed-off-by: Harshitha Sai Neelati <hsaineel@codeaurora.org>
rpmh_rsc_debug() can race with tcs_tx_done() interrupt handler and
may not see any tcs busy and hence won't do bug_on(). Later it may
go ahead and free() the request which interrupt handler is processing.
Lets always bug_on() upon timeout.
Change-Id: I238a6a3639077850df158cb1f0190656e014bb57
Signed-off-by: Maulik Shah <mkshah@codeaurora.org>
Add check for maximum thermal state while setting
current state.
Change-Id: I4ade853d0cda1d8754486dc6dd8f53596fae7a9a
Signed-off-by: Naman Padhiar <npadhiar@codeaurora.org>
There is possibility of failure in getting large memory
during panic notifier callback. Hence try atomic snapshot
with 1MB in case default memory allocation fails.
Change-Id: I8f5ff29139d272dc35094c230e1868623585b476
Signed-off-by: Rohan Sethi <rohsethi@codeaurora.org>
This change is to avoid potential race btw stop rx and incoming
SOC RX data in parallel. During suspend path wait_for_transfers_inflight()
logic will check for TX/RX data pending for completion. Check for RX_LEN_IN
status in wait_for_transfers_inflight() and return -EBUSY to avoid race
between stop_rx and SOC RX data.
Change-Id: I28702d3dc11ee4b6d3fe5b4bad9a19099d8cf725
Signed-off-by: Chandana Kishori Chiluveru <cchiluve@codeaurora.org>
L23_READY bit in the PARF_PM_CTRL register is set coming
out of PBL. Clear it once PCIe enumerates. This will avoid
the corner case where L23_READY is sent to the host causing
the link to be disable before the EP PCIe driver has had a
chance to disable the endpoint cleanly.
Change-Id: I2159cf88c4ec5f2b38b7134e42c6a069a9738d6c
Signed-off-by: Gauri Joshi <gaurjosh@codeaurora.org>
Update the TZ version to include the latest diag version
when choosing to use enlarged buffers.
Change-Id: Icd285c171957d0ddf6d4e9980bae33fa7b5eb9ec
Signed-off-by: Gaurav Kashyap <gaurkash@codeaurora.org>
After BCR reset while reconfiguring the SDHC registers
Interrupt Signal Enable Register does not reflect the value
and so it fails initialization of eMMC. As per design constraint
it requires 200us delay after BCR reset.
Change-Id: I99eca34e02a1b2557dca3b3da5a0cbeb32b7aff5
Signed-off-by: Maramaina Naresh <mnaresh@codeaurora.org>
This change updates gpio to pdc mapping for sdxlemur.
Change-Id: I0149b3cc798815693a7999335444419b1d896444
Signed-off-by: Tushar Nimkar <tnimkar@codeaurora.org>
Currently as part of mmc suspend and resume, we are using
different api's to check support for cmd5 (sleep/awake),
which results in suspend sending cmd5 for sleep, while
in resume it's always going for full init instead of sending
cmd5 for awake. Fix this by using same api in both suspend
and resume paths so that partial init functionality is
actually utilized.
Change-Id: Ia84b7790fe00f1f24a63d6dc509646ebcbd4d3ef
Signed-off-by: Sayali Lokhande <sayalil@codeaurora.org>
Avoid calling ASSERT from select_window API when it called
from panic handler. As device is already crashed, calling
ASSERT will just add unwanted prints and dump stacks.
Change-Id: If38be6d8e452c49cabfa059b4bf12b2f8a3c60a2
Signed-off-by: Naman Padhiar <npadhiar@codeaurora.org>