Commit graph

1,371 commits

Author SHA1 Message Date
Linux Build Service Account
1b8e9355a2 Merge 336163ddec on remote branch
Change-Id: I92270af5cb1f133bb17b4888fd2c43cde713e4c2
2022-08-15 23:23:43 -07:00
Yash Upadhyay
336163ddec msm: camera: memmgr: Avoid TOCTOU buffer access on multiple use of same fd
Fd is a user-accessible value, referring it multiple times
leads to TOCTOU issues. Dma_buf can be freed after the 1st
use of fd and userspace can create another dma_buf but with
same fd. In such scenario, during 2nd use of fd, we may get
a different dma_buf with different length. To avoid this, we
can use same dma_buf instead of retrieving it twice using same
fd. In this change FD is accessed only once in syscall.

CRs-Fixed: 3159446
Change-Id: I00eb6dd3d798165f5c6c0bd59feabe80a68592b1
Signed-off-by: Yash Upadhyay <quic_yupadhya@quicinc.com>
2022-08-03 10:04:47 +05:30
Linux Build Service Account
35a56acb33 Merge d35e7e899b on remote branch
Change-Id: Ide4cb97fa564ec984b297ea505c70bee1561f64a
2022-07-12 15:18:29 -07:00
Camera Software Integration
d35e7e899b Merge "msm: camera: utils: modify debug function logic" into camera-kernel.lnx.4.0 2022-06-29 21:13:09 -07:00
Linux Build Service Account
eeac0cb806 Merge 21017701fa on remote branch
Change-Id: I87eba0b2244645858fbc0ac22d9fdbbaf435ebc0
2022-06-17 05:10:52 -07:00
daopingl
cfb8c413c9 msm: camera: utils: modify debug function logic
there are only 8k stack in 32 bit system, this change used to make
the temp variables be contorl by the parameters, which can decrase
the stack resource cost under default debug settings and finally
improve the stability of multi camera cases.

CRs-fixed: 3193708
Change-Id: If0f33cc310d64c83c0e4781a5de61483ebc35769
Signed-off-by: daopingl <quic_daopingl@quicinc.com>
2022-05-27 17:58:36 +08:00
Camera Software Integration
21017701fa Merge "msm: camera: reqmgr: Reset the slot if it is applied" into camera-kernel.lnx.4.0 2022-05-25 11:38:34 -07:00
Kai Xing
028478e7df msm: camera: fd: fix compile error for kernel 5.4
Function definition error: delete static keyword.

CRs-Fixed: 3191744
Change-Id: Ifea089f47de02233b31695146b1ddacfbaec35a8
Signed-off-by: Kai Xing <quic_kxing@quicinc.com>
2022-05-11 16:59:10 +05:30
Linux Build Service Account
17853d328d Merge 40348c542e on remote branch
Change-Id: I5646f879736b95c842506161a9b74e23bfb78dcc
2022-05-10 06:39:00 -07:00
Camera Software Integration
40348c542e Merge "msm: camera: jpeg: By default disable Camnoc MISR configuration" into camera-kernel.lnx.4.0 2022-05-01 08:33:39 -07:00
Depeng Shao
f4a952f180 msm: camera: reqmgr: Reset the slot if it is applied
This change reset the slot when the next req is applied, it
should be caused by some exception before, we need to reset
this slot in case we applied wrong req to sub devices.

CRs-Fixed: 2949657
Change-Id: I0b5f7b1d8450ed355701090b185812fb7a6b6e06
Signed-off-by: Depeng Shao <quic_depengs@quicinc.com>
2022-04-28 09:48:17 +05:30
Linux Build Service Account
dabd749a6b Merge 355f51b649 on remote branch
Change-Id: Ibaa7e88a2d874f25d4df75ff47c3eed0d91d56b3
2022-04-14 02:11:55 -07:00
Shravan Nevatia
6c445cfb01 msm: camera: eeprom: Add OOB read check for eeprom memory map
Add check to prevent OOB read of eeprom memory map.

Change-Id: Ifeeeffdc2a50536edbde5b5d755a052ace86d596
CRs-Fixed: 3003049
Signed-off-by: Shravan Nevatia <quic_snevatia@quicinc.com>
2022-04-11 23:23:41 +05:30
Camera Software Integration
355f51b649 Merge "msm: camera: ife: dump data at overlflow for rdi only use case" into camera-kernel.lnx.4.0 2022-04-06 02:13:15 -07:00
Camera Software Integration
d8227145a5 Merge "msm: camera: memmgr: update correct length in bufq" into camera-kernel.lnx.4.0 2022-04-06 02:13:04 -07:00
Tejas Prajapati
dd87df520d msm: camera: ife: dump data at overlflow for rdi only use case
Below information is dumped at the overflow
1. Dump SOF, EPOCH, EOF and Error time.
2. Dump IRQ status.
3. Cpas AB, IB votes.
4. Dump width and height of all the acquired ports.
5. CSID clock.

CRs-Fixed: 3159425
Change-Id: I580d8f4d50c49568a6bc9ae8d06fc4b93f11891c
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
2022-03-31 10:10:01 +05:30
Camera Software Integration
6d548aa9b5 Merge "msm: camera: reqmgr: Validate the link handle" into camera-kernel.lnx.4.0 2022-03-22 06:26:28 -07:00
Camera Software Integration
a9d8ab272a Merge "msm: camera: reqmgr: Avoid freeing subdev twice" into camera-kernel.lnx.4.0 2022-03-22 06:21:19 -07:00
Tejas Prajapati
a4b0246d27 msm: camera: memmgr: update correct length in bufq
In a corner case, race condition to free the original
ion buf allocated and new ion buffer with same fd but
different size after freeing the origianl ion buf might
result into mismatches in the real ion buf size assigned
in bufq. To avoid this update length in bufq with
local variable.

CRs-Fixed: 3142221
Change-Id: I23d91445bd088bbde19ffa191e158256166f2053
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
2022-03-17 14:49:58 +05:30
Linux Build Service Account
14568cb248 Merge f33380f182 on remote branch
Change-Id: I2fea743726b96556867189b281f72e860ad6dc55
2022-03-16 06:28:01 -07:00
Yash Upadhyay
e5cbfaf0af msm: camera: reqmgr: Validate the link handle
Instead of correct link handle, if some other handle like
dev handle is passed then it may access some other data space.
To avoid such scenario, need to check whether link handle
passed by ioctl is same as retrieved link handle.

CRs-Fixed: 3120454
Change-Id: Idff2e3c25b60563788ffb426c7cabc367c3c97f8
Signed-off-by: Yash Upadhyay <quic_yupadhya@quicinc.com>
2022-03-15 09:22:45 +05:30
Dharmender Sharma
24a4646c76 msm: camera: jpeg: By default disable Camnoc MISR configuration
By default driver is configuring jpeg misr and also dumping misr values.
So added a check if camnoc_misr_support is enabled then only configure
and dump the misr value.

CRs-Fixed: 3168072
Change-Id: I4090b1a43b55a0f7643c352689aa04b56d31df8d
Signed-off-by: Dharmender Sharma <quic_dharshar@quicinc.com>
2022-03-15 08:07:38 +05:30
zhuo
f33380f182 msm: camera: cdm: Fix workqueue timing issue
Due to workqueue does not process the work in order,
so sometimes the later work will be processed earlier.
Such as, when submit request order: 1/2/3, cdm interrupt
come order: 1/2/3, workqueue process order: 2/1/3,
when process 2 request, which currently will notify 1/2
CDM clients and remove 1/2 from submit list. After that,
when process 1 request, will notify 3, actually 3 is not
done at the moment, which maybe cause smmu page fault issue.
And sometimes, when there is a delay in handling interrupts,
then HLOS handles two interrupts as one only. This change only
notify the request less than and equal to the interrupt request.

CRs-Fixed: 3130447
Change-Id: I0fd0e8adee48767e5ab7db1921a8284d107c2f40
Signed-off-by: zhuo <quic_zhuo@quicinc.com>
2022-02-28 13:24:40 +08:00
Linux Build Service Account
ff868a2d19 Merge 6639a3b50f on remote branch
Change-Id: I04409d42a5a0099394b2931c566136ea4af28cae
2022-02-14 22:01:52 -08:00
Camera Software Integration
6639a3b50f Merge "msm: camera: tfe: dump csid clock and path data at overflow" into camera-kernel.lnx.4.0 2022-02-09 22:58:05 -08:00
Nirmal Abraham
583fb300c8 msm: camera: reqmgr: Avoid freeing subdev twice
The 'l_device' pointer in __cam_req_mgr_destroy_subdev is
set to NULL after freeing but this is done on a
local copy of the variable in stack. This results in
double-free when this function is called again. To avoid
this, pass 'l_device' pointer by reference and assign it
to NULL after freeing.

CRs-Fixed: 3120468
Change-Id: If2dde6f1c702bee26a3c8a68c2f45bafbf0f7cd6
Signed-off-by: Nirmal Abraham <quic_c_nabrah@quicinc.com>
2022-02-08 10:14:49 +05:30
Camera Software Integration
b3fd39f822 Merge "msm: camera: reqmgr: reader writer locks to avoid memory faults" into camera-kernel.lnx.4.0 2022-01-27 11:47:04 -08:00
Tejas Prajapati
a35c7c2f10 msm: camera: tfe: dump csid clock and path data at overflow
On overflow dump the AB and IB votes, tfe clock,
CSID clock and respective bus path data for acquire
time and addr_status registers.

CRs-Fixed: 3118430
Change-Id: Ia38eb4350e8e38562b6d22769b38637480da0b9d
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
2022-01-19 10:32:57 +05:30
Linux Build Service Account
1d988caf4a Merge eac3f0b664 on remote branch
Change-Id: I65eaf0c1ca7d8dac9ecd52d9ce1f8c7c01c99375
2022-01-18 00:05:46 -08:00
Camera Software Integration
eac3f0b664 Merge "msm: camera: ope: Fix for 32-bit kernel" into camera-kernel.lnx.4.0 2022-01-11 03:35:41 -08:00
Tejas Prajapati
691ddd437f msm: camera: reqmgr: reader writer locks to avoid memory faults
Shared memory is initialized by CRM and used by
other drivers; with CRM not active other drivers
would fail to access the shared memory if
memory manager is deinit. Reader Writer locks can
prevent the open/close/ioctl calls from other drivers
if CRM open/close is already being processed.

Issue observed with the below sequence if drivers
are opened from UMD directly without this change.
CRM Open successful,ICP open successful,
CRM close in progress, ICP open successful,
mem mgr deinit and CRM close successful,
ICP tries to access HFI memory and result in crash.

This change helps to serialze the calls and prevents
issue.

CRs-Fixed: 3019488
Change-Id: I464411576a5a04f5d0b402c403ce8a1d4df7dad0
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
2022-01-07 17:22:12 +05:30
Camera Software Integration
c450d2e419 Merge "msm: camera: reqmgr: check if link handle is correctly passed" into camera-kernel.lnx.4.0 2022-01-03 10:53:03 -08:00
Alok Chauhan
deb0914ed4 msm: camera: ope: Fix for 32-bit kernel
Use div_u64 to do 64-bit division.

CRs-Fixed: 3099898
Change-Id: I405461ea02d0ec668cb7be764543a9a16bd1c3e6
Signed-off-by: Alok Chauhan <quic_alokc@quicinc.com>
Signed-off-by: Nirmal Abraham <quic_c_nabrah@quicinc.com>
2022-01-03 17:42:21 +05:30
Camera Software Integration
89103da2f8 Merge "msm: camera: isp: Add eof notification for rdi only context" into camera-kernel.lnx.4.0 2021-12-21 20:58:00 -08:00
Tejas Prajapati
4856f7a40a msm: camera: reqmgr: check if link handle is correctly passed
Instead of the link handle if the dev handle is
passed for dumping the request information, this
can lead to accessing invalid data structure.
To avodi accessing invalid data structure based on
the dev handle, first check if the link handle passed
in IOCTL is matchting with looked up link handle.

CRs-Fixed: 3097336
Change-Id: I815457ff96e3b26fe9fa886bd984d53d209e4edb
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
2021-12-20 14:44:36 +05:30
Linux Build Service Account
f1afeb29d6 Merge ce9b4b3f12 on remote branch
Change-Id: Iac93b676c0af9002e5e02402043e823ce92b3fc6
2021-12-14 05:52:43 -08:00
Camera Software Integration
be0697dec4 Merge "msm: camera: ope: Increase max bl limit and max stripe to process" into camera-kernel.lnx.4.0 2021-12-13 11:01:00 -08:00
Camera Software Integration
7ad290b351 Merge "msm: camera: ope: Update request timeout for NRT/RT context" into camera-kernel.lnx.4.0 2021-12-13 10:59:30 -08:00
Tejas Prajapati
c6de9ec432 msm: camera: isp: Add eof notification for rdi only context
For RDI only context EOF is not notified; it should be
notified, for the corner case if the flash is
configured to apply at EOF then it will block apply for
ISP on SOF as well until the EOF is notified, this
change adds EOF notification.

CRs-Fixed: 3091241
Change-Id: If6d974d092d640d9def89bbcf7a88fba0d85579b
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
2021-12-13 01:08:06 -08:00
Zhenlin Lian
ce9b4b3f12 msm: camera: config: Enable camera drivers for qcs610
Add camera config files for target qcs610.

Change-Id: I4fefaa0254aa8267b4375bb4270f286f46ec7997
Signed-off-by: Zhenlin Lian <quic_zlian@quicinc.com>
2021-12-03 01:58:20 -08:00
Camera Software Integration
c9f9bce593 Merge "msm: camera: reqmgr: Prevent session deadlock" into camera-kernel.lnx.4.0 2021-12-02 04:27:09 -08:00
Camera Software Integration
f9bcd25377 Merge "msm: camera: isp: handle buf_done at apply failure from deferred list" into camera-kernel.lnx.4.0 2021-12-02 04:26:15 -08:00
Alok Chauhan
8eeacc770c msm: camera: ope: Update request timeout for NRT/RT context
Currently the ope request timeout value for RT and NRT context
are same. In some usecases, NRT request processing takes more time.

Hence, initialize the RT and NRT request timeout value separately.

CRs-Fixed: 3082993
Change-Id: I17e86d26403fb21cdff518a81dee7a19c865144e
Signed-off-by: Alok Chauhan <quic_alokc@quicinc.com>
2021-11-26 18:07:31 +05:30
Vikram Sharma
4fbb1700ef msm: camera: ope: Increase max bl limit and max stripe to process
Increase “OPE_MAX_CDM_BLS” to 32 from 24 and MAX_STRIPES to 64 from 48
to process 108M frame.

CRs-Fixed: 3082993
Change-Id: I9e3631cc86c5e10e4e2020d4a9b2264ea282e437
Signed-off-by: Vikram Sharma <vikramsa@codeaurora.org>
2021-11-26 12:12:16 +05:30
sokchetra eung
1f76cca6da msm: camera: reqmgr: Prevent session deadlock
Releasing session lock before unlink and acquiring
it immediately after to allow workq to be done. Check
link state after acquiring session lock in process_
req to return if link is IDLE.

CRs-Fixed: 3003287
Change-Id: Ie7a8ffc4edcb123db290d6da047d748b3e99d68b
Signed-off-by: sokchetra eung <eung@codeaurora.org>
2021-11-24 20:36:01 -08:00
Tejas Prajapati
572462dbf6 msm: camera: isp: handle buf_done at apply failure from deferred list
For RDI only context where the buf_done is handled from wait list,
if the buf_done is moved to deferred list then the bubble
recovery might fail. To make sure the bubble is processed the request
needs to be moved pending list. This change helps moving the request
from active list to pending list.

CRs-Fixed: 3079621
Change-Id: Ibb271e68ca2312cbd3d71bd64e2ed7963bf60b55
Signed-off-by: Tejas Prajapati <tpraja@codeaurora.org>
2021-11-18 09:30:49 +05:30
Wyes Karny
f49b4dd0b9 msm: camera: cdm: Fix deadlock issue in CDM handle error
Fix deadlock issue in CDM handle error.

CRs-Fixed: 3073203
Change-Id: Ia63e1841fc00e74e4c03a1d6b28e94814748aa8f
Signed-off-by: Wyes Karny <wkarny@codeaurora.org>
2021-11-15 17:08:25 +05:30
Linux Build Service Account
f525e54864 Merge b819b10757 on remote branch
Change-Id: I8752563448ea9e79c0e95d0cb6b1ccfaaab0024b
2021-11-10 22:23:49 -08:00
Vikram Sharma
8a251d8af1 msm: camera: isp: Fix PPI index based on the phy selection
1) There is one to one mapping for ppi index with phy index
but phy select is not always equal to phy number,for some
targets "phy_sel = phy_idx + 1", and for some targets it is
"phy_sel = phy_idx", ppi_index should be updated accordingly.
2) Updated to configure ppi cfg register as.
 for cphy, disable dphy in config register.
 for dphy, do nothing (both cphy and dphy will be selected).
 then enable all lanes.

CRs-Fixed: 3057665
Change-Id: I1d5d66034a5563b5adcb8163acf9a668d10d4a19
Signed-off-by: Vikram Sharma <vikramsa@codeaurora.org>
2021-10-29 13:42:55 +05:30
Camera Software Integration
b819b10757 Merge "msm: camera: ife: Add ife num outport bound checks" into camera-kernel.lnx.4.0 2021-10-28 11:23:16 -07:00