Observes below crash while accessing (use-after-free) lock member
of bfq data.
context#1 context#2
process_one_work()
kthread() blk_mq_run_work_fn()
worker_thread() ->__blk_mq_run_hw_queue()
process_one_work() ->blk_mq_sched_dispatch_requests()
__blk_release_queue() ->blk_mq_do_dispatch_sched()
->__elevator_exit()
->blk_mq_exit_sched()
->exit_sched()
->kfree()
->bfq_dispatch_request()
->spin_unlock_irq(&bfqd->lock)
This is because of the kblockd delayed work that might got scheduled
around blk_release_queue() and accessed use-after-free member of
bfq_data.
240.212359: <2> Unable to handle kernel paging request at
virtual address ffffffee2e33ad70
...
240.212637: <2> Workqueue: kblockd blk_mq_run_work_fn
240.212649: <2> pstate: 00c00085 (nzcv daIf +PAN +UAO)
240.212666: <2> pc : queued_spin_lock_slowpath+0x10c/0x2e0
240.212677: <2> lr : queued_spin_lock_slowpath+0x84/0x2e0
...
Call trace:
240.212865: <2> queued_spin_lock_slowpath+0x10c/0x2e0
240.212876: <2> do_raw_spin_lock+0xf0/0xf4
240.212890: <2> _raw_spin_lock_irq+0x74/0x94
240.212906: <2> bfq_dispatch_request+0x4c/0xd60
240.212918: <2> blk_mq_do_dispatch_sched+0xe0/0x1f0
240.212927: <2> blk_mq_sched_dispatch_requests+0x130/0x194
240.212940: <2> __blk_mq_run_hw_queue+0x100/0x158
240.212950: <2> blk_mq_run_work_fn+0x1c/0x28
240.212963: <2> process_one_work+0x280/0x460
240.212973: <2> worker_thread+0x27c/0x4dc
240.212986: <2> kthread+0x160/0x170
Fix this by cancelling the delayed work if any before elevator exits.
Change-Id: If015576983e328aa726bac90a7a8de824d6532f0
Signed-off-by: Pradeep P V K <ppvk@codeaurora.org>
Enable the qti-fixed-regulator driver so that proxy consumer
voting may be used for fixed regulator devices.
Change-Id: Ibdbe3129de0a11f71d2c0adbae12659e6332f5fd
Signed-off-by: David Collins <collinsd@codeaurora.org>
Add a new QTI fixed voltage regulator driver that is derived from
the fixed voltage regulator driver. Use this to provide support
for proxy consumer voting and debug features required on Qualcomm
Technologies, Inc. boards. Implement this driver as a wrapper
around fixed.c with #ifdef directives so that future updates to
fixed.c are applied automatically to qti-fixed-regulator.c.
Change-Id: If4cf664b3f6a8214256a4b2de753f7ff27aa864e
Signed-off-by: David Collins <collinsd@codeaurora.org>
DDR interface is (2x16), so update the number of channels to "2"
and bus width to "4".
Change-Id: I2e6c8f3ebe8cce38412dbcb5fe9032353d28b597
Signed-off-by: Odelu Kukatla <okukatla@codeaurora.org>
Check for accessible pages, before capturing the
page context, while dumping pointer data, for
CPU registers.
Change-Id: If7f38f0e3cb12e5c0ad85f8ed3140ce098108f62
Signed-off-by: Neeraj Upadhyay <neeraju@codeaurora.org>
In order to make devlink happy we need to bind an IOMMU device on the
primary GMU platform device. Since we don't need GMU user yet the
decision is easy. Move GMU kernel to the platform device instead
of a child.
Change-Id: Ic0dedbad082c57b2aeb6a35573ead8535f3b8ab9
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
While executing suspend_noirq callbacks non-wakeup interrupts are
disabled, wake-up interrupts are enabled but their handling is
deferred till the completion of suspend_noirq stage.
UART console vote/unvote the resources in suspend_noirq/resume_noirq
stages. There is no issue wrt managing clk and pinctrl resources at
noirq stage however ICC BW voting can't be done at noirq stage.
ICC requests are converted to ack based requested for RPM driver, the
ack here is nothing but interrupt from IPCC driver and it can't be
processed at noirq stage, hence flow is indefinitely stuck in UART
suspend_noirq callback.
Change-Id: Ie279580795d3c85db4dc42766b0b2d9a8adb3f00
Signed-off-by: Akash Asthana <akashast@codeaurora.org>
Sometimes due to late initialization glink callback may not be
initialized and incoming will be dropped.
Print error message if receive callback is not ready.
Change-Id: I3eae1717d4e1c14b319e288078d122762fd476e7
Signed-off-by: Sarannya S <sarannya@codeaurora.org>
Some of the fs allocations like those for journalling
are critical and can cause a fatal error if allocation
fails. Avoid bailing out early in those cases, even if
a fatal signal is pending on the caller task.
Change-Id: Ib2803d763313b196123a4c1e2c66227b5d6e6e14
Signed-off-by: Vinayak Menon <vinmenon@codeaurora.org>
Receive callback can be registered even before rpmsg driver probe is
complete. Assuming callback register as channel ready and allowing
remote host to send data is incorrect. In such case for any rx packet
callback may return prematurely thereby dropping the rx packet.
Adding a flag to store channel state when it is ready. Check this flag
before allocating rx intent and allowing data communication to proceed.
It will ensure that client driver is able to receive data correctly,
without any rx packet getting dropped.
CRs-Fixed: 2747216
Change-Id: Ib153cfe5689f31d7417622bf6177e9535fda628a
Signed-off-by: Deepak Kumar Singh <deesin@codeaurora.org>
Added support for notifying hints from userspace
Change-Id: I3af1951614e4cd20826a595c6fca23b18c5a749b
Signed-off-by: richagar <richagar@codeaurora.org>