a validation added to check whether retrieved struct smcinvoke_file_data
inside the function get_server_id belongs to g_smcinvoke_fops or not.
Change-Id: If949889a764775200650a8d0b744359c0611b576
Signed-off-by: Pavan Bobba <quic_pav@quicinc.com>
Multiple clients racing with each other to register with the same label
could possibly succeed in doing so, contrary to design, which mandates
that only one client should be able to register with a given label, and
others should receive an -EBUSY. This is due to the below two reasons:
1. Checking for a label's cap_table_entry in the global
gh_msgq_cap_list and then allocating one if none is found is
not an atomic operation all under one spinlock.
2. The cap_entry_lock spinlock protecting the cap_table_entry is
relinquished prematurely, before the client_desc can be set in
cap_table_entry.
Two clients attempting to register by passing in the same label could
potentially each find no corresponding cap_table_entry and then each
proceed to allocate a new entry (adding it to the global
gh_msgq_cap_list). Continuing with this scenario, both freshly-allocated
cap_table_entry's will have their client_desc set to NULL and so will
have a client_desc allocated and return successfully.
Fix this by:
1. Bringing the cap_table_entry existence check and allocation steps
under the same spinlock, thereby preventing further allocations if
the cap_table_entry already exists.
2. Removing the spinlock from within gh_mgsq_alloc_entry() because it is
now being called with the same spinlock held.
3. Extending cap_entry_lock's critical section to cover the allocation
of client_desc as well. This will prevent the overwriting of
client_desc in the case of a race condition where two clients obtain
the same cap_table_entry and both of them find their client_desc's to
be NULL and then each proceed to allocate one and assign it to the
same cap_table_entry one after the other.
4. Changing the allocation flags to GFP_ATOMIC to avoid sleeping within
a critical section.
Change-Id: I99072d466e91151302a50e5f35f2b2a8d5ee5c48
Signed-off-by: Guru Das Srinagesh <gurus@codeaurora.org>
Signed-off-by: Kishor Krishna Bhat <quic_kishkris@quicinc.com>
The following patches are reverted since dequeuing all requests
in gserial_disconnect() with interrupts disabled is resulting
in stability issues. The original problem of end transfer timeout
in DWC3 driver is not completely solved with dequeuing the requests,
so this patch does not introduce any regressions.
f331451 usb: gadget: u_serial: Remove extra list operation from
gs_start_tx.
fb8bcea usb: gadget: u_serial: Rectify the list operations is
rx/tx path.
83626bc usb: gadget: u_serial: Dequeue request on gserial_disconnect.
Change-Id: Ic8a8cbaf295d1cb335b463743814a289c89069b8
Signed-off-by: Uttkarsh Aggarwal <quic_uaggarwa@quicinc.com>
In the connect_pipe() failure path, the allocated pipe is freed but
the pointer variable is not reset creating a dangling pointer and
potential UaF if it is later accessed. Fix it by assigning it to NULL.
Change-Id: Iae9fb05ce819fc94839180762393fa18aaecdd60
Signed-off-by: Jack Pham <quic_jackp@quicinc.com>
kmalloc returns out of memory in low memory conditions even if memory
is available in non-contiguous manner. This results in failure to
submit commands to ringbuffer. Use kvmalloc in place of kmalloc so
that when kmalloc fails in low memory conditions, commands can be
submitted if vmalloc can provide enough memory.
Change-Id: If6a20e35983982b5c0888e5f7dabecfa8c026bcb
Signed-off-by: Pranav Patel <quic_pranavp@quicinc.com>
Remove IDs from hh_rm_call_idr in failure paths of hh_rm_call().
Change-Id: I2e2817bdd22f570ebb299ceebed0677817815194
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
Currently gpuaddr_in_range() accepts only the gpuaddr & returns
true if it lies in valid range. But this does not mean that the
entire buffer is within range.
Modify the function to accept size as a parameter and check that
both starting & ending points of buffer lie within mmu range.
Change-Id: I1d722295b9a27e746bfdb6d3bf409ffe722193cb
Signed-off-by: Rohan Sethi <rohsethi@codeaurora.org>
As a part of sysfs reading of descriptors/attributes/flags,
query commands should only be executed when hba's
power runtime status is active.
To guarantee this, add pm_runtime_get/put_sync()
to those paths where query commands are sent.
Bug: 232878917
Link: https://lore.kernel.org/r/f712a4f7bdb0ae32e0d83634731e7aaa1b3a6cdd.1585009663.git.asutoshd@codeaurora.org
Change-Id: I56b89be3ac850794b874a7b46295a8d12ef4ea02
(cherry picked from commit 0c2039dc1591bb9a3b887753b37946f09f4bf208)
[sachgupt: Resolved minor conflict in drivers/scsi/ufs/ufs-sysfs.c]
Signed-off-by: Nitin Rawat <quic_nitirawa@quicinc.com>
Signed-off-by: Sachin Gupta <quic_sachgupt@quicinc.com>
commit c70222752228a62135cee3409dccefd494a24646 upstream.
There is no need to call dev_kfree_skb() when usb_submit_urb() fails
beacause can_put_echo_skb() deletes the original skb and
can_free_echo_skb() deletes the cloned skb.
Bug: 228694391
Link: https://lore.kernel.org/all/20220228083639.38183-1-hbh25y@gmail.com
Fixes: 702171adee ("ems_usb: Added support for EMS CPC-USB/ARM7 CAN/USB interface")
Cc: stable@vger.kernel.org
Cc: Sebastian Haas <haas@ems-wuensche.com>
Signed-off-by: Hangyu Hua <hbh25y@gmail.com>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: Ia678a0b249eae6e80823461f18eb315ec5385eab
commit 3d3925ff6433f98992685a9679613a2cc97f3ce2 upstream.
There is no need to call dev_kfree_skb() when usb_submit_urb() fails
because can_put_echo_skb() deletes original skb and
can_free_echo_skb() deletes the cloned skb.
Bug: 228694483
Fixes: 0024d8ad16 ("can: usb_8dev: Add support for USB2CAN interface from 8 devices")
Link: https://lore.kernel.org/all/20220311080614.45229-1-hbh25y@gmail.com
Cc: stable@vger.kernel.org
Signed-off-by: Hangyu Hua <hbh25y@gmail.com>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: I3c9191dd936d82e7c692fad33919b766e69ed7b5
We are seeing xfer timeout due to IO lines not in proper state,
if IO lines recovered we do cancel command, if IO lines not
recovered we are returning without doing cancel operation and not
updating last mark busy, due to this we are not receiving SUSPEND call.
After sometime unexpected event is coming from GSI, due to this
we are seeing the crash. To resolve this we have updated last mark
busy for pending_cancel failure case as well. If we update last mark
busy, runtime_suspend will invoke here we are doing gpi pause operation,
unexpected event won't expected if we do gpi pause.
Also,added RTL based SE flag, doing pending cancel only for RTL based SE's.
Change-Id: Ia1af93fc9dadf4a11fa2e3f614878de550ab4c0e
Signed-off-by: Anil Veshala Veshala <quic_aveshala@quicinc.com>
Add ASSERT when FW READY got timed out to debug why
FW READY indication is not come.
Change-Id: I0def3d0bd945f1cfe25c8c5fa48b593bb0556b03
Signed-off-by: Naman Padhiar <quic_npadhiar@quicinc.com>
* refs/heads/tmp-459ed28:
ANDROID: ABI: Update allowed list for QCOM
BACKPORT: ext4: don't BUG if someone dirty pages without asking ext4 first
ANDROID: incremental-fs: limit mount stack depth
Revert "ANDROID: dm-bow: Protect Ranges fetched and erased from the RB tree"
ANDROID: usb: gadget: f_accessory: add compat_ioctl support
UPSTREAM: sr9700: sanity check for packet length
ANDROID: ABI: update allowed list for galaxy
ANDROID: GKI: Add symbol list for Zebra
UPSTREAM: Revert "xfrm: state and policy should fail if XFRMA_IF_ID 0"
Change-Id: I78177b9bbdd140bc1c44351b3b59eeaee087726a
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
commit ebe48d368e97d007bfeb76fcb065d6cfc4c96645 upstream.
The maximum message size that can be send is bigger than
the maximum site that skb_page_frag_refill can allocate.
So it is possible to write beyond the allocated buffer.
Fix this by doing a fallback to COW in that case.
v2:
Avoid get get_order() costs as suggested by Linus Torvalds.
Bug: 227452856
Fixes: cac2661c53 ("esp4: Avoid skb_cow_data whenever possible")
Fixes: 03e2a30f6a ("esp6: Avoid skb_cow_data whenever possible")
Reported-by: valis <sec@valis.email>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Tadeusz Struk <tadeusz.struk@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Change-Id: I2c7f97914138271e7788adfcebbd0b2b8b43cdcb
Signed-off-by: Lee Jones <lee.jones@linaro.org>
When link is not up during the enumeration, enumeration fails
and the driver releases resources, disables Perst IRQ. If the
ep_pcie gets a Perst de assertion after this it is not handled,
as Perst IRQ is disabled.
Here, avoiding disabling of Perst IRQ, De-initializing of GPIOs
and making the base addresses of various resources as NULL, if
pcie-perst-enum is set in device tree. This ensures that the
enumeration is done as part of the subsequent Perst de assertion
events.
Change-Id: If5d8ce08031d089b1477d93a2125e3fe0fc97942
Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
Update the android/abi_gki_aarch64_qcom with API kill_anon_super.
Bug: 230828747
Change-Id: I5abe6a5a27f343997ef8a83beb3b0adee796a23c
Signed-off-by: Srinivasarao Pathipati <quic_spathi@quicinc.com>
Add if_index in ipa_wlan_msg struct to receive
the interface index from wlan driver.
Change-Id: I50a43ff4529b29a41753298e87fd84a0dfc9a969
Signed-off-by: Piyush Dhyani <quic_pdhyani@quicinc.com>
This change configures sdcc core and ice clock memory
state when clock is turned off. For ice clock, core mem
needs to be retained to allow retaining crypto configuration
(including keys) when ice clock is turned off.
Change-Id: Id67c887ce5d5f6b6242b3267aeceebaa574c587b
Signed-off-by: Sayali Lokhande <quic_sayalil@quicinc.com>
Signed-off-by: Sachin Gupta <quic_sachgupt@quicinc.com>
Update the android/abi_gki_aarch64_qcom with API kill_anon_super.
Bug: 230828747
Change-Id: I5abe6a5a27f343997ef8a83beb3b0adee796a23c
Signed-off-by: Srinivasarao Pathipati <quic_spathi@quicinc.com>
Bug: 195565510
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: Ic8134eb902aa7d929e3121b2f69b1d258f570652
(cherry picked from commit 98c15b2bad1a277da43c65c642f8c3c3ee07bacc)
Supply additional check in order to prevent unexpected results.
Bug: 205573273
Fixes: b892bf75b2 ("ion: Switch ion to use dma-buf")
Suggested-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[Lee: Patch now applies to ion_buffer.c instead of ion.c]
Change-Id: Ia6afdd9ca502caa9cad6619d438fc6c8e8457679
(cherry picked from commit 27da8d16e4)
When clatd starts with ebpf offloaing, and NETIF_F_GRO_FRAGLIST is enable,
several skbs are gathered in skb_shinfo(skb)->frag_list. The first skb's
ipv6 header will be changed to ipv4 after bpf_skb_proto_6_to_4,
network_header\transport_header\mac_header have been updated as ipv4 acts,
but other skbs in frag_list didnot update anything, just ipv6 packets.
udp_queue_rcv_skb will call skb_segment_list to traverse other skbs in
frag_list and make sure right udp payload is delivered to user space.
Unfortunately, other skbs in frag_list who are still ipv6 packets are
updated like the first skb and will have wrong transport header length.
e.g.before bpf_skb_proto_6_to_4,the first skb and other skbs in frag_list
has the same network_header(24)& transport_header(64), after
bpf_skb_proto_6_to_4, ipv6 protocol has been changed to ipv4, the first
skb's network_header is 44,transport_header is 64, other skbs in frag_list
didnot change.After skb_segment_list, the other skbs in frag_list has
different network_header(24) and transport_header(44), so there will be 20
bytes different from original,that is difference between ipv6 header and
ipv4 header. Just change transport_header to be the same with original.
Actually, there are two solutions to fix it, one is traversing all skbs
and changing every skb header in bpf_skb_proto_6_to_4, the other is
modifying frag_list skb's header in skb_segment_list. Considering
efficiency, adopt the second one--- when the first skb and other skbs in
frag_list has different network_header length, restore them to make sure
right udp payload is delivered to user space.
Signed-off-by: Lina Wang <lina.wang@mediatek.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit cf3ab8d4a797960b4be20565abb3bcd227b18a68 https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git master)
Bug: 218157620
Test: TreeHugger
Signed-off-by: Maciej Żenczykowski <maze@google.com>
Change-Id: I36f2f329ec1a56bb0742141a7fa482cafa183ad3
Currently the format string passed to vsnprintf() from
the I2C driver in the audio codec code flow is not
correct. Fix this issue by removing the extra % character
in the GENI_SE_DBG().
Change-Id: Icef5aa7499e6b3433d82324735bc784309a6610d
Signed-off-by: Mahesh Reddy Kodidi <quic_mahreddy@quicinc.com>
WLAN host driver has a new memory requirement and it expects
5 128KB prealloc buffers. Add change to update 128KB prealloc
reserve pool size to 5.
Change-Id: Iaf3162a76e73605a06e22e8547b6aa4b48768d91
Signed-off-by: Mohammed Siddiq <quic_msiddiq@quicinc.com>
Change: During Callback request from TZ, out and in buffers
needed explicit cache coherency to be performed.
Change-Id: I2b2aee7dce3d75dc07576079f4b0d268488c5951
Signed-off-by: Nitesh Gupta <quic_nitegupt@quicinc.com>
Get the dma_buf handle directly from 'vm_file' after
doing necessary checks on the file.
Change-Id: Id5eec16588d64e4e28483b32bb52d4d3d9b86b99
Signed-off-by: ravnar <quic_ravnar@quicinc.com>
Signed-off-by: Sanjay Yadav <quic_sanjyada@quicinc.com>