Commit graph

907,368 commits

Author SHA1 Message Date
Pavan Bobba
2fa26c84e7 smcinvoke : file private data validation which is sent by userspace
a validation added to check  whether retrieved struct smcinvoke_file_data
inside the function get_server_id belongs to g_smcinvoke_fops or not.

Change-Id: If949889a764775200650a8d0b744359c0611b576
Signed-off-by: Pavan Bobba <quic_pav@quicinc.com>
2022-06-06 04:24:07 -07:00
qctecmdr
f094cbc663 Merge "Merge android11-5.4.180+ (e7792e2) into msm-5.4" 2022-06-03 06:42:43 -07:00
qctecmdr
26e6ab84e1 Merge "usb: gadget: u_serial: Don't dequeue requests in gserial_disconnect" 2022-06-02 05:43:09 -07:00
qctecmdr
2e1743bcba Merge "haven: hh_rm_core: fix ID leaking" 2022-06-01 05:08:31 -07:00
Guru Das Srinagesh
2387accd22 haven: gh_msgq: Disallow multiple registrations with same label
Multiple clients racing with each other to register with the same label
could possibly succeed in doing so, contrary to design, which mandates
that only one client should be able to register with a given label, and
others should receive an -EBUSY. This is due to the below two reasons:
  1. Checking for a label's cap_table_entry in the global
     gh_msgq_cap_list and then allocating one if none is found is
     not an atomic operation all under one spinlock.
  2. The cap_entry_lock spinlock protecting the cap_table_entry is
     relinquished prematurely, before the client_desc can be set in
     cap_table_entry.
Two clients attempting to register by passing in the same label could
potentially each find no corresponding cap_table_entry and then each
proceed to allocate a new entry (adding it to the global
gh_msgq_cap_list). Continuing with this scenario, both freshly-allocated
cap_table_entry's will have their client_desc set to NULL and so will
have a client_desc allocated and return successfully.
Fix this by:
1. Bringing the cap_table_entry existence check and allocation steps
   under the same spinlock, thereby preventing further allocations if
   the cap_table_entry already exists.
2. Removing the spinlock from within gh_mgsq_alloc_entry() because it is
   now being called with the same spinlock held.
3. Extending cap_entry_lock's critical section to cover the allocation
   of client_desc as well. This will prevent the overwriting of
   client_desc in the case of a race condition where two clients obtain
   the same cap_table_entry and both of them find their client_desc's to
   be NULL and then each proceed to allocate one and assign it to the
   same cap_table_entry one after the other.
4. Changing the allocation flags to GFP_ATOMIC to avoid sleeping within
   a critical section.

Change-Id: I99072d466e91151302a50e5f35f2b2a8d5ee5c48
Signed-off-by: Guru Das Srinagesh <gurus@codeaurora.org>
Signed-off-by: Kishor Krishna Bhat <quic_kishkris@quicinc.com>
2022-05-31 04:03:34 -07:00
Srinivasarao Pathipati
eb03a71570 Merge android11-5.4.180+ (e7792e2) into msm-5.4
* refs/heads/tmp-e7792e2:
  BACKPORT: scsi: ufs: Resume ufs host before accessing ufs device
  BACKPORT: can: ems_usb: ems_usb_start_xmit(): fix double dev_kfree_skb() in error path
  ANDROID: ABI: Added symbols for allwinner
  BACKPORT: can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path
  BACKPORT: esp: Fix possible buffer overflow in ESP transformation
  ANDROID: ABI: Update allowed list for QCOM
  ANDROID: dm-bow: Protect Ranges fetched and erased from the RB tree
  BACKPORT: staging: ion: Prevent incorrect reference counting behavour
  FROMGIT: net: fix wrong network header length
  ANDROID: fix KCFLAGS override by __ANDROID_COMMON_KERNEL__
  ANDROID: Add flag to indicate compiling against ACK
  BACKPORT: net/packet: fix slab-out-of-bounds access in packet_recvmsg()
  BACKPORT: block: Add a helper to validate the block size
  BACKPORT: virtio-blk: Use blk_validate_block_size() to validate block size
  BACKPORT: fuse: fix pipe buffer lifetime for direct_io
  ANDROID: ABI: Update allowed list for galaxy

 Conflicts:
	build.config.common
	drivers/scsi/ufs/ufs-sysfs.c

Change-Id: I7dc73e85ca1412a1d00422fd4a62724f65581aec
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2022-05-30 12:43:51 +05:30
qctecmdr
b6845fdd76 Merge "msm: kgsl: use kvmalloc for ringbuffer submission" 2022-05-29 23:00:24 -07:00
qctecmdr
1a00719a8e Merge "defconfig: sdxlemur: Enable IPv6 NAT" 2022-05-26 16:05:38 -07:00
Uttkarsh Aggarwal
e48ead6773 usb: gadget: u_serial: Don't dequeue requests in gserial_disconnect
The following patches are reverted since dequeuing all requests
in gserial_disconnect() with interrupts disabled is resulting
in stability issues. The original problem of end transfer timeout
in DWC3 driver is not completely solved with dequeuing the requests,
so this patch does not introduce any regressions.

f331451 usb: gadget: u_serial: Remove extra list operation from
gs_start_tx.

fb8bcea usb: gadget: u_serial: Rectify the list operations is
rx/tx path.

83626bc usb: gadget: u_serial: Dequeue request on gserial_disconnect.

Change-Id: Ic8a8cbaf295d1cb335b463743814a289c89069b8
Signed-off-by: Uttkarsh Aggarwal <quic_uaggarwa@quicinc.com>
2022-05-26 22:49:58 +05:30
Jack Pham
0a91646856 platform: msm: usb_bam: Fix potential use-after-free in connect_pipe
In the connect_pipe() failure path, the allocated pipe is freed but
the pointer variable is not reset creating a dangling pointer and
potential UaF if it is later accessed.  Fix it by assigning it to NULL.

Change-Id: Iae9fb05ce819fc94839180762393fa18aaecdd60
Signed-off-by: Jack Pham <quic_jackp@quicinc.com>
2022-05-25 23:34:12 -07:00
Pranav Patel
93f6fdbe31 msm: kgsl: use kvmalloc for ringbuffer submission
kmalloc returns out of memory in low memory conditions even if memory
is available in non-contiguous manner. This results in failure to
submit commands to ringbuffer. Use kvmalloc in place of kmalloc so
that when kmalloc fails in low memory conditions, commands can be
submitted if vmalloc can provide enough memory.

Change-Id: If6a20e35983982b5c0888e5f7dabecfa8c026bcb
Signed-off-by: Pranav Patel <quic_pranavp@quicinc.com>
2022-05-25 04:37:07 -07:00
qctecmdr
26872d7115 Merge "mmc: sdhci-msm: configure sdcc clocks core memory" 2022-05-24 22:24:51 -07:00
James Wyatt Guidry
644e9d88eb defconfig: sdxlemur: Enable IPv6 NAT
- Enabled IPv6 NAT for sdxlemur

Change-Id: Iabb6340343f00e7a8d4870148f84b74250632626
Signed-off-by: James Wyatt Guidry <quic_jguidry@quicinc.com>
2022-05-24 13:41:21 -07:00
Srinivasarao Pathipati
d0a7eee654 haven: hh_rm_core: fix ID leaking
Remove IDs from hh_rm_call_idr in failure paths of hh_rm_call().

Change-Id: I2e2817bdd22f570ebb299ceebed0677817815194
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2022-05-24 16:53:49 +05:30
qctecmdr
3497dfc249 Merge "i2c:i2c-msm-geni: Updating last mark busy failure case" 2022-05-23 23:30:15 -07:00
qctecmdr
77caecb902 Merge "msm: kgsl: Fix gpuaddr_in_range() to check upper bound" 2022-05-18 21:50:08 -07:00
Rohan Sethi
ac7349dd70 msm: kgsl: Fix gpuaddr_in_range() to check upper bound
Currently gpuaddr_in_range() accepts only the gpuaddr & returns
true if it lies in valid range. But this does not mean that the
entire buffer is within range.
Modify the function to accept size as a parameter and check that
both starting & ending points of buffer lie within mmu range.

Change-Id: I1d722295b9a27e746bfdb6d3bf409ffe722193cb
Signed-off-by: Rohan Sethi <rohsethi@codeaurora.org>
2022-05-18 17:58:41 +05:30
qctecmdr
9f84500259 Merge "i2c-msm-genic: To remove unsupported %: in format string" 2022-05-18 00:56:04 -07:00
qctecmdr
215122559e Merge "smcinvoke: Add explicit cache flush during CB req from TZ" 2022-05-18 00:56:04 -07:00
qctecmdr
c6c2cbd621 Merge "scsi: ufs: fix deadlock between resume and eh_work" 2022-05-18 00:56:03 -07:00
qctecmdr
778d5c01eb Merge "i2c: i2c-msm-geni: Reset i2c GPIOs using FORCE_DEFAULT" 2022-05-18 00:56:02 -07:00
qctecmdr
5177e06269 Merge "i2c: i2c-msm-geni: Handle NACK interrupt as an error condition" 2022-05-18 00:56:01 -07:00
qctecmdr
b6998ed934 Merge "msm: ADSPRPC: Update unsigned pd support on cDSP from kernel" 2022-05-18 00:56:01 -07:00
qctecmdr
422c9d10eb Merge "clk: qcom: gdsc-regulator: Add debug logs for gdsc set mode" 2022-05-18 00:56:00 -07:00
qctecmdr
2eefb7690f Merge "cnss2: Add change to update 128KB prealloc reserve pool size to 5" 2022-05-17 17:07:47 -07:00
qctecmdr
c000754ee2 Merge "msm: ep_pcie: Avoid releasing resources if pcie-perst-enum is set" 2022-05-17 17:07:46 -07:00
qctecmdr
e47bb16672 Merge "msm: ipa: Add if_index in ipa_wlan_msg struct" 2022-05-17 17:07:46 -07:00
qctecmdr
ffd8017cb2 Merge "icnss: Add ASSERT if fw ready got timed out" 2022-05-17 17:07:46 -07:00
qctecmdr
84ca266039 Merge "msm: kgsl: Remove 'fd' dependency to get dma_buf handle" 2022-05-17 17:07:42 -07:00
Sachin Gupta
e7792e2790 BACKPORT: scsi: ufs: Resume ufs host before accessing ufs device
As a part of sysfs reading of descriptors/attributes/flags,
query commands should only be executed when hba's
power runtime status is active.
To guarantee this, add pm_runtime_get/put_sync()
to those paths where query commands are sent.

Bug: 232878917
Link: https://lore.kernel.org/r/f712a4f7bdb0ae32e0d83634731e7aaa1b3a6cdd.1585009663.git.asutoshd@codeaurora.org
Change-Id: I56b89be3ac850794b874a7b46295a8d12ef4ea02
(cherry picked from commit 0c2039dc1591bb9a3b887753b37946f09f4bf208)
[sachgupt: Resolved minor conflict in drivers/scsi/ufs/ufs-sysfs.c]
Signed-off-by: Nitin Rawat <quic_nitirawa@quicinc.com>
Signed-off-by: Sachin Gupta <quic_sachgupt@quicinc.com>
2022-05-17 20:45:20 +00:00
Hangyu Hua
12bf063cb9 BACKPORT: can: ems_usb: ems_usb_start_xmit(): fix double dev_kfree_skb() in error path
commit c70222752228a62135cee3409dccefd494a24646 upstream.

There is no need to call dev_kfree_skb() when usb_submit_urb() fails
beacause can_put_echo_skb() deletes the original skb and
can_free_echo_skb() deletes the cloned skb.

Bug: 228694391
Link: https://lore.kernel.org/all/20220228083639.38183-1-hbh25y@gmail.com
Fixes: 702171adee ("ems_usb: Added support for EMS CPC-USB/ARM7 CAN/USB interface")
Cc: stable@vger.kernel.org
Cc: Sebastian Haas <haas@ems-wuensche.com>
Signed-off-by: Hangyu Hua <hbh25y@gmail.com>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: Ia678a0b249eae6e80823461f18eb315ec5385eab
2022-05-17 16:04:38 +00:00
Aran Dalton
1ae6fd7e6f ANDROID: ABI: Added symbols for allwinner
Leaf changes summary: 1 artifact changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

1 Added function:

  [A] 'function void devm_extcon_dev_free(device*, extcon_dev*)'

Bug: 231769124
Change-Id: I962814563554a960d45adb18def5987aaff25c65
Signed-off-by: Aran Dalton <arda@allwinnertech.com>
2022-05-17 09:46:27 +08:00
Hangyu Hua
7d33bb909e BACKPORT: can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path
commit 3d3925ff6433f98992685a9679613a2cc97f3ce2 upstream.

There is no need to call dev_kfree_skb() when usb_submit_urb() fails
because can_put_echo_skb() deletes original skb and
can_free_echo_skb() deletes the cloned skb.

Bug: 228694483
Fixes: 0024d8ad16 ("can: usb_8dev: Add support for USB2CAN interface from 8 devices")
Link: https://lore.kernel.org/all/20220311080614.45229-1-hbh25y@gmail.com
Cc: stable@vger.kernel.org
Signed-off-by: Hangyu Hua <hbh25y@gmail.com>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: I3c9191dd936d82e7c692fad33919b766e69ed7b5
2022-05-16 12:16:54 +01:00
Anil Veshala Veshala
2578117ac1 i2c:i2c-msm-geni: Updating last mark busy failure case
We are seeing xfer timeout due to IO lines not in proper state,
if IO lines recovered we do cancel command, if IO lines not
recovered we are returning without doing cancel operation and not
updating last mark busy, due to this we are not receiving SUSPEND call.
After sometime unexpected event is coming from GSI, due to this
we are seeing the crash. To resolve this we have updated last mark
busy for pending_cancel failure case as well. If we update last mark
busy, runtime_suspend will invoke here we are doing gpi pause operation,
unexpected event won't expected if we do gpi pause.

Also,added RTL based SE flag, doing pending cancel only for RTL based SE's.

Change-Id: Ia1af93fc9dadf4a11fa2e3f614878de550ab4c0e
Signed-off-by: Anil Veshala Veshala <quic_aveshala@quicinc.com>
2022-05-16 16:03:05 +05:30
Naman Padhiar
766debf6bb icnss: Add ASSERT if fw ready got timed out
Add ASSERT when FW READY got timed out to debug why
FW READY indication is not come.

Change-Id: I0def3d0bd945f1cfe25c8c5fa48b593bb0556b03
Signed-off-by: Naman Padhiar <quic_npadhiar@quicinc.com>
2022-05-16 15:46:08 +05:30
Srinivasarao Pathipati
7d71c1b289 Merge android11-5.4.180+ (459ed28) into msm-5.4
* refs/heads/tmp-459ed28:
  ANDROID: ABI: Update allowed list for QCOM
  BACKPORT: ext4: don't BUG if someone dirty pages without asking ext4 first
  ANDROID: incremental-fs: limit mount stack depth
  Revert "ANDROID: dm-bow: Protect Ranges fetched and erased from the RB tree"
  ANDROID: usb: gadget: f_accessory: add compat_ioctl support
  UPSTREAM: sr9700: sanity check for packet length
  ANDROID: ABI: update allowed list for galaxy
  ANDROID: GKI: Add symbol list for Zebra
  UPSTREAM: Revert "xfrm: state and policy should fail if XFRMA_IF_ID 0"

Change-Id: I78177b9bbdd140bc1c44351b3b59eeaee087726a
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2022-05-13 23:10:00 +05:30
Steffen Klassert
09c810c77d BACKPORT: esp: Fix possible buffer overflow in ESP transformation
commit ebe48d368e97d007bfeb76fcb065d6cfc4c96645 upstream.

The maximum message size that can be send is bigger than
the  maximum site that skb_page_frag_refill can allocate.
So it is possible to write beyond the allocated buffer.

Fix this by doing a fallback to COW in that case.

v2:

Avoid get get_order() costs as suggested by Linus Torvalds.

Bug: 227452856
Fixes: cac2661c53 ("esp4: Avoid skb_cow_data whenever possible")
Fixes: 03e2a30f6a ("esp6: Avoid skb_cow_data whenever possible")
Reported-by: valis <sec@valis.email>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Tadeusz Struk <tadeusz.struk@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Change-Id: I2c7f97914138271e7788adfcebbd0b2b8b43cdcb
Signed-off-by: Lee Jones <lee.jones@linaro.org>
2022-05-13 09:52:20 +01:00
Sai Chaitanya Kaveti
1175e4cdbf msm: ep_pcie: Avoid releasing resources if pcie-perst-enum is set
When link is not up during the enumeration, enumeration fails
and the driver releases resources, disables Perst IRQ. If the
ep_pcie gets a Perst de assertion after this it is not handled,
as Perst IRQ is disabled.

Here, avoiding disabling of Perst IRQ, De-initializing of GPIOs
and making the base addresses of various resources as NULL, if
pcie-perst-enum is set in device tree. This ensures that the
enumeration is done as part of the subsequent Perst de assertion
events.

Change-Id: If5d8ce08031d089b1477d93a2125e3fe0fc97942
Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
2022-05-13 00:11:32 -07:00
Srinivasarao Pathipati
92c489b86d ANDROID: ABI: Update allowed list for QCOM
Update the android/abi_gki_aarch64_qcom with API kill_anon_super.

Bug: 230828747
Change-Id: I5abe6a5a27f343997ef8a83beb3b0adee796a23c
Signed-off-by: Srinivasarao Pathipati <quic_spathi@quicinc.com>
2022-05-13 12:15:05 +05:30
Piyush Dhyani
5b45cf1ede msm: ipa: Add if_index in ipa_wlan_msg struct
Add if_index in ipa_wlan_msg struct to receive
the interface index from wlan driver.

Change-Id: I50a43ff4529b29a41753298e87fd84a0dfc9a969
Signed-off-by: Piyush Dhyani <quic_pdhyani@quicinc.com>
2022-05-12 12:10:30 -07:00
Steven Rostedt (VMware)
04ede4c080 tracing: Check return value of __create_val_fields() before using its result
After having a typo for writing a histogram trigger.

Wrote:
  echo 'hist:key=pid:ts=common_timestamp.usec' > events/sched/sched_waking/trigger

Instead of:
  echo 'hist:key=pid:ts=common_timestamp.usecs' > events/sched/sched_waking/trigger

and the following crash happened:

 BUG: kernel NULL pointer dereference, address: 0000000000000008
 #PF: supervisor read access in kernel mode
 #PF: error_code(0x0000) - not-present page
 PGD 0 P4D 0
 Oops: 0000 [#1] PREEMPT SMP PTI
 CPU: 4 PID: 1641 Comm: sh Not tainted 5.9.0-rc5-test+ #549
 Hardware name: Hewlett-Packard HP Compaq Pro 6300 SFF/339A, BIOS K01 v03.03 07/14/2016
 RIP: 0010:event_hist_trigger_func+0x70b/0x1ee0
 Code: 24 08 89 d5 49 89 cc e9 8c 00 00 00 4c 89 f2 41 b9 00 10 00 00 4c 89 e1 44 89 ee 4c 89 ff e8 dc d3 ff ff 45 89 ea 4b 8b 14 d7 <f6> 42 08 04 74 17 41 8b 8f c0 00 00 00 8d 71 01 41 89 b7 c0 00 00
 RSP: 0018:ffff959213d53db0 EFLAGS: 00010202
 RAX: ffffffffffffffea RBX: 0000000000000000 RCX: 0000000000084c04
 RDX: 0000000000000000 RSI: df7326aefebd174c RDI: 0000000000031080
 RBP: 0000000000000002 R08: 0000000000000001 R09: 0000000000000001
 R10: 0000000000000001 R11: 0000000000000046 R12: ffff959211dcf690
 R13: 0000000000000001 R14: ffff95925a36e370 R15: ffff959251c89800
 FS:  00007fb9ea934740(0000) GS:ffff95925ab00000(0000) knlGS:0000000000000000
 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
 CR2: 0000000000000008 CR3: 00000000c976c005 CR4: 00000000001706e0
 Call Trace:
  ? trigger_process_regex+0x78/0x110
  trigger_process_regex+0xc5/0x110
  event_trigger_write+0x71/0xd0
  vfs_write+0xca/0x210
  ksys_write+0x70/0xf0
  do_syscall_64+0x33/0x40
  entry_SYSCALL_64_after_hwframe+0x44/0xa9
 RIP: 0033:0x7fb9eaa29487
 Code: 64 89 02 48 c7 c0 ff ff ff ff eb bb 0f 1f 80 00 00 00 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 48 89 54 24 18 48 89 74 24

This was caused by accessing the hlist_data fields after the call to
__create_val_fields() without checking if the creation succeed.

Link: https://lkml.kernel.org/r/20201013154852.3abd8702@gandalf.local.home

Change-Id: I5c9f3561f724aceea24a7ef43dcc50c7e79bf8ff
Fixes: 63a1e5de3006 ("tracing: Save normal string variables")
Reviewed-by: Masami Hiramatsu <mhiramat@kernel.org>
Reviewed-by: Tom Zanussi <zanussi@kernel.org>
Signed-off-by: Steven Rostedt (VMware) <rostedt@goodmis.org>
Git-commit: 6d9bd139455d9d40fec8c242985996468b34180c
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2022-05-12 13:47:35 +05:30
Sachin Gupta
ee158d065f mmc: sdhci-msm: configure sdcc clocks core memory
This change configures sdcc core and ice clock memory
state when clock is turned off. For ice clock, core mem
needs to be retained to allow retaining crypto configuration
(including keys) when ice clock is turned off.

Change-Id: Id67c887ce5d5f6b6242b3267aeceebaa574c587b
Signed-off-by: Sayali Lokhande <quic_sayalil@quicinc.com>
Signed-off-by: Sachin Gupta <quic_sachgupt@quicinc.com>
2022-05-11 04:34:45 -07:00
Srinivasarao Pathipati
f896faff41 ANDROID: ABI: Update allowed list for QCOM
Update the android/abi_gki_aarch64_qcom with API kill_anon_super.

Bug: 230828747
Change-Id: I5abe6a5a27f343997ef8a83beb3b0adee796a23c
Signed-off-by: Srinivasarao Pathipati <quic_spathi@quicinc.com>
2022-05-11 15:39:17 +05:30
Lee Jones
0840b18507 ANDROID: dm-bow: Protect Ranges fetched and erased from the RB tree
Bug: 195565510
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: Ic8134eb902aa7d929e3121b2f69b1d258f570652
(cherry picked from commit 98c15b2bad1a277da43c65c642f8c3c3ee07bacc)
2022-05-10 11:42:43 +00:00
Lee Jones
7f04e0c309 BACKPORT: staging: ion: Prevent incorrect reference counting behavour
Supply additional check in order to prevent unexpected results.

Bug: 205573273
Fixes: b892bf75b2 ("ion: Switch ion to use dma-buf")
Suggested-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[Lee: Patch now applies to ion_buffer.c instead of ion.c]
Change-Id: Ia6afdd9ca502caa9cad6619d438fc6c8e8457679
(cherry picked from commit 27da8d16e4)
2022-05-10 10:33:28 +00:00
Lina Wang
9adbfa635e FROMGIT: net: fix wrong network header length
When clatd starts with ebpf offloaing, and NETIF_F_GRO_FRAGLIST is enable,
several skbs are gathered in skb_shinfo(skb)->frag_list. The first skb's
ipv6 header will be changed to ipv4 after bpf_skb_proto_6_to_4,
network_header\transport_header\mac_header have been updated as ipv4 acts,
but other skbs in frag_list didnot update anything, just ipv6 packets.

udp_queue_rcv_skb will call skb_segment_list to traverse other skbs in
frag_list and make sure right udp payload is delivered to user space.
Unfortunately, other skbs in frag_list who are still ipv6 packets are
updated like the first skb and will have wrong transport header length.

e.g.before bpf_skb_proto_6_to_4,the first skb and other skbs in frag_list
has the same network_header(24)& transport_header(64), after
bpf_skb_proto_6_to_4, ipv6 protocol has been changed to ipv4, the first
skb's network_header is 44,transport_header is 64, other skbs in frag_list
didnot change.After skb_segment_list, the other skbs in frag_list has
different network_header(24) and transport_header(44), so there will be 20
bytes different from original,that is difference between ipv6 header and
ipv4 header. Just change transport_header to be the same with original.

Actually, there are two solutions to fix it, one is traversing all skbs
and changing every skb header in bpf_skb_proto_6_to_4, the other is
modifying frag_list skb's header in skb_segment_list. Considering
efficiency, adopt the second one--- when the first skb and other skbs in
frag_list has different network_header length, restore them to make sure
right udp payload is delivered to user space.

Signed-off-by: Lina Wang <lina.wang@mediatek.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit cf3ab8d4a797960b4be20565abb3bcd227b18a68 https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git master)
Bug: 218157620
Test: TreeHugger
Signed-off-by: Maciej Żenczykowski <maze@google.com>
Change-Id: I36f2f329ec1a56bb0742141a7fa482cafa183ad3
2022-05-09 16:01:57 +00:00
Mahesh Reddy Kodidi
c034bb96ec i2c-msm-genic: To remove unsupported %: in format string
Currently the format string passed to vsnprintf() from
the I2C driver in the audio codec code flow is not
correct. Fix this issue by removing the extra % character
in the GENI_SE_DBG().

Change-Id: Icef5aa7499e6b3433d82324735bc784309a6610d
Signed-off-by: Mahesh Reddy Kodidi <quic_mahreddy@quicinc.com>
2022-05-07 00:20:37 +05:30
Mohammed Siddiq
90a16e2ae5 cnss2: Add change to update 128KB prealloc reserve pool size to 5
WLAN host driver has a new memory requirement and it expects
5 128KB prealloc buffers. Add change to update 128KB prealloc
reserve pool size to 5.

Change-Id: Iaf3162a76e73605a06e22e8547b6aa4b48768d91
Signed-off-by: Mohammed Siddiq <quic_msiddiq@quicinc.com>
2022-05-04 19:52:49 +05:30
Nitesh Gupta
5b4fd8b686 smcinvoke: Add explicit cache flush during CB req from TZ
Change: During Callback request from TZ, out and in buffers
needed explicit cache coherency to be performed.

Change-Id: I2b2aee7dce3d75dc07576079f4b0d268488c5951
Signed-off-by: Nitesh Gupta <quic_nitegupt@quicinc.com>
2022-05-04 00:30:26 -07:00
ravnar
3b62ca041c msm: kgsl: Remove 'fd' dependency to get dma_buf handle
Get the dma_buf handle directly from 'vm_file' after
doing necessary checks on the file.

Change-Id: Id5eec16588d64e4e28483b32bb52d4d3d9b86b99
Signed-off-by: ravnar <quic_ravnar@quicinc.com>
Signed-off-by: Sanjay Yadav <quic_sanjyada@quicinc.com>
2022-05-04 12:27:46 +05:30