[ Upstream commit a04224da1f3424b2c607b12a3bd1f0e302fb8231 ]
Previously, gadget assignment to the net device occurred exclusively
during the initial binding attempt.
Nevertheless, the gadget pointer could change during bind/unbind
cycles due to various conditions, including the unloading/loading
of the UDC device driver or the detachment/reconnection of an
OTG-capable USB hub device.
This patch relocates the gether_set_gadget() function out from
ncm_opts->bound condition check, ensuring that the correct gadget
is assigned during each bind request.
The provided logs demonstrate the consistency of ncm_opts throughout
the power cycle, while the gadget may change.
* OTG hub connected during boot up and assignment of gadget and
ncm_opts pointer
[ 2.366301] usb 2-1.5: New USB device found, idVendor=2996, idProduct=0105
[ 2.366304] usb 2-1.5: New USB device strings: Mfr=1, Product=2, SerialNumber=3
[ 2.366306] usb 2-1.5: Product: H2H Bridge
[ 2.366308] usb 2-1.5: Manufacturer: Aptiv
[ 2.366309] usb 2-1.5: SerialNumber: 13FEB2021
[ 2.427989] usb 2-1.5: New USB device found, VID=2996, PID=0105
[ 2.428959] dabridge 2-1.5:1.0: dabridge 2-4 total endpoints=5, 0000000093a8d681
[ 2.429710] dabridge 2-1.5:1.0: P(0105) D(22.06.22) F(17.3.16) H(1.1) high-speed
[ 2.429714] dabridge 2-1.5:1.0: Hub 2-2 P(0151) V(06.87)
[ 2.429956] dabridge 2-1.5:1.0: All downstream ports in host mode
[ 2.430093] gadget 000000003c414d59 ------> gadget pointer
* NCM opts and associated gadget pointer during First ncm_bind
[ 34.763929] NCM opts 00000000aa304ac9
[ 34.763930] NCM gadget 000000003c414d59
* OTG capable hub disconnecte or assume driver unload.
[ 97.203114] usb 2-1: USB disconnect, device number 2
[ 97.203118] usb 2-1.1: USB disconnect, device number 3
[ 97.209217] usb 2-1.5: USB disconnect, device number 4
[ 97.230990] dabr_udc deleted
* Reconnect the OTG hub or load driver assaign new gadget pointer.
[ 111.534035] usb 2-1.1: New USB device found, idVendor=2996, idProduct=0120, bcdDevice= 6.87
[ 111.534038] usb 2-1.1: New USB device strings: Mfr=1, Product=2, SerialNumber=3
[ 111.534040] usb 2-1.1: Product: Vendor
[ 111.534041] usb 2-1.1: Manufacturer: Aptiv
[ 111.534042] usb 2-1.1: SerialNumber: Superior
[ 111.535175] usb 2-1.1: New USB device found, VID=2996, PID=0120
[ 111.610995] usb 2-1.5: new high-speed USB device number 8 using xhci-hcd
[ 111.630052] usb 2-1.5: New USB device found, idVendor=2996, idProduct=0105, bcdDevice=21.02
[ 111.630055] usb 2-1.5: New USB device strings: Mfr=1, Product=2, SerialNumber=3
[ 111.630057] usb 2-1.5: Product: H2H Bridge
[ 111.630058] usb 2-1.5: Manufacturer: Aptiv
[ 111.630059] usb 2-1.5: SerialNumber: 13FEB2021
[ 111.687464] usb 2-1.5: New USB device found, VID=2996, PID=0105
[ 111.690375] dabridge 2-1.5:1.0: dabridge 2-8 total endpoints=5, 000000000d87c961
[ 111.691172] dabridge 2-1.5:1.0: P(0105) D(22.06.22) F(17.3.16) H(1.1) high-speed
[ 111.691176] dabridge 2-1.5:1.0: Hub 2-6 P(0151) V(06.87)
[ 111.691646] dabridge 2-1.5:1.0: All downstream ports in host mode
[ 111.692298] gadget 00000000dc72f7a9 --------> new gadget ptr on connect
* NCM opts and associated gadget pointer during second ncm_bind
[ 113.271786] NCM opts 00000000aa304ac9 -----> same opts ptr used during first bind
[ 113.271788] NCM gadget 00000000dc72f7a9 ----> however new gaget ptr, that will not set
in net_device due to ncm_opts->bound = true
Change-Id: I803f892ccd2a0f9558d4f32d8a3104aba78353ff
Signed-off-by: Hardik Gajjar <hgajjar@de.adit-jv.com>
Link: https://lore.kernel.org/r/20231020153324.82794-1-hgajjar@de.adit-jv.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
This patch allows the administrator to configure the interface
name of a function using u_ether (e.g., eem, ncm, rndis).
Currently, all such interfaces, regardless of function type, are
always called usb0, usb1, etc. This makes it very cumbersome to
use more than one such type at a time, because userspace cannnot
easily tell the interfaces apart and apply the right
configuration to each one. Interface renaming in userspace based
on driver doesn't help, because the interfaces all have the same
driver. Without this patch, doing this require hacks/workarounds
such as setting fixed MAC addresses on the functions, and then
renaming by MAC address, or scraping configfs after each
interface is created to find out what it is.
Setting the interface name is done by writing to the same
"ifname" configfs attribute that reports the interface name after
the function is bound. The write must contain an interface
pattern such as "usb%d" (which will cause the net core to pick
the next available interface name starting with "usb").
This patch does not allow writing an exact interface name (as
opposed to a pattern) because if the interface already exists at
bind time, the bind will fail and the whole gadget will fail to
activate. This could be allowed in a future patch.
For compatibility with current userspace, when reading an ifname
that has not currently been set, the result is still "(unnamed
net_device)". Once a write to ifname happens, then reading ifname
will return whatever was last written.
Tested by configuring an rndis function and an ncm function on
the same gadget, and writing "rndis%d" to ifname on the rndis
function and "ncm%d" to ifname on the ncm function. When the
gadget was bound, the rndis interface was rndis0 and the ncm
interface was ncm0.
Signed-off-by: Lorenzo Colitti <lorenzo@google.com>
(cherry picked from commit 63d152149b2d0860ccf8c4e6596b6175b2b7ace6
https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb.git usb-next)
Link: https://lore.kernel.org/r/20210113234222.3272933-1-lorenzo@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lorenzo Colitti <lorenzo@google.com>
Change-Id: I04deb6cc1d8a5b8ee82404940de2a79c06fbafe7
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
mm/page_owner.c:944:39: error:
size argument in 'strlcpy' call appears to be size of the source;
expected the size of the destination [-Werror,-Wstrlcpy-strlcat-size]
944 | strlcpy(call_site->name, buf, strlen(buf));
| ~~~~~~~^~~~
mm/page_owner.c:944:32: note:
change size argument to be the size of the destination
944 | strlcpy(call_site->name, buf, strlen(buf));
| ^~~~~~~~~~~
| sizeof(call_site->name)
https://github.com/LineageOS/android_kernel_qcom_sm8450/blob/lineage-20/drivers/soc/qcom/minidump_memory.c#L692
contains the same code.
Change-Id: Id06f67fe18f2e00dd180afaf99c7577787198cc3
Signed-off-by: Sevenrock <sevenrock@hotmail.de>
Revert the following changes to restore to upstream version:
commit 006d8adf55 ("usb: gadget: f_ncm: allocate/free net device upon driver bind/unbind")
commit ad2d551ece ("usb: gadget: Add check gadget function bind or not")
Reason for revert: Causes gether_set_ifname() support to kernel panic.
Change-Id: I51064467cad63e47a4a9734f18f1a5b95fa8db86
* sm8350/lineage-20:
UPSTREAM: net: sched: Disallow replacing of child qdisc from one parent to another
FROMGIT: media: venus: hfi: add a check to handle OOB in sfr region
FROMGIT: media: venus: hfi: add check to handle incorrect queue size
FROMGIT: media: venus: hfi_parser: refactor hfi packet parsing logic
FROMGIT: media: venus: hfi_parser: add check to avoid out of bound access
UPSTREAM: pfifo_tail_enqueue: Drop new packet when sch->limit == 0
UPSTREAM: f2fs: compress: don't allow unaligned truncation on released compress inode
UPSTREAM: net: core: reject skb_copy(_expand) for fraglist GSO skbs
UPSTREAM: udp: prevent local UDP tunnel packets from being GROed
UPSTREAM: udp: do not transition UDP GRO fraglist partial checksums to unnecessary
UPSTREAM: udp: do not accept non-tunnel GSO skbs landing in a tunnel
UPSTREAM: binder: Return EFAULT if we fail BINDER_ENABLE_ONEWAY_SPAM_DETECTION
UPSTREAM: usb: dwc3: host: Set XHCI_SG_TRB_CACHE_SIZE_QUIRK
UPSTREAM: usb: host: xhci-plat: Add support for XHCI_SG_TRB_CACHE_SIZE_QUIRK
UPSTREAM: usb: xhci: Add error handling in xhci_map_urb_for_dma
UPSTREAM: usb: xhci: Use temporary buffer to consolidate SG
UPSTREAM: usb: xhci: Set quirk for XHCI_SG_TRB_CACHE_SIZE_QUIRK
defconfig: Enable RTL8152 ETH-USB driver
ANDROID: ABI: Cuttlefish Symbol update
fw-api: CL 28563606 - update fw common interface files
...
Change-Id: I39d8fa1352de578a5a6c15be2b4b9911bf1c154c
https://source.android.com/docs/security/bulletin/2025-04-01
CVE-2024-50264
CVE-2024-53197
CVE-2024-56556
CVE-2024-53150
* tag 'ASB-2025-04-05_11-5.4' of https://android.googlesource.com/kernel/common:
UPSTREAM: net: sched: Disallow replacing of child qdisc from one parent to another
UPSTREAM: pfifo_tail_enqueue: Drop new packet when sch->limit == 0
UPSTREAM: f2fs: compress: don't allow unaligned truncation on released compress inode
UPSTREAM: net: core: reject skb_copy(_expand) for fraglist GSO skbs
UPSTREAM: udp: prevent local UDP tunnel packets from being GROed
UPSTREAM: udp: do not transition UDP GRO fraglist partial checksums to unnecessary
UPSTREAM: udp: do not accept non-tunnel GSO skbs landing in a tunnel
UPSTREAM: binder: Return EFAULT if we fail BINDER_ENABLE_ONEWAY_SPAM_DETECTION
Change-Id: If91ea6f68126e13b4dfc08471e94ced6d2d68ae9
LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0
# By Jayasri Sampath Kumaran
# Via Karthik Veeranki (1) and Linux Build Service Account (1)
* tag 'clo/display-drivers/LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0':
disp: msm: sde: fix kms NULL pointer access in encoder IRQ control
Change-Id: I52a1f3a27d8eed895e1db8a48f15c225d1c1c3ea
LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0
# Via Linux Build Service Account
* tag 'clo/datarmnet/LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0':
Change-Id: I5a76d0990d5bc7655a0c66fc2f39a02f900cdd43
LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0
# By Ratna Deepthi Kudaravalli
# Via Linux Build Service Account (1) and Ratna Deepthi Kudaravalli (1)
* tag 'clo/audio-kernel/LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0':
audio-kernel: avoid out of bound read while checking a bit
Change-Id: I70a5aa2eb95361d9181d5e93a2bbbcce590ce7db
LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0
# By Krupali Dhanvijay (1) and Ravindra Konda (1)
# Via Linux Build Service Account (1) and Ravindra Konda (1)
* tag 'clo/qcacld-3.0/LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0':
Release 2.0.8.34Z
qcacld-3.0: Update key management in original auth mode for WAPI
Change-Id: Idc372a690bf0f5d77ce26e64c7d5fbc5d6aa95c2
LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0
# By Prashanth K (6) and others
# Via Gerrit - the friendly Code Review server (5) and others
* tag 'clo/msm-5.4/LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0':
FROMGIT: media: venus: hfi: add a check to handle OOB in sfr region
FROMGIT: media: venus: hfi: add check to handle incorrect queue size
FROMGIT: media: venus: hfi_parser: refactor hfi packet parsing logic
FROMGIT: media: venus: hfi_parser: add check to avoid out of bound access
UPSTREAM: usb: dwc3: host: Set XHCI_SG_TRB_CACHE_SIZE_QUIRK
UPSTREAM: usb: host: xhci-plat: Add support for XHCI_SG_TRB_CACHE_SIZE_QUIRK
UPSTREAM: usb: xhci: Add error handling in xhci_map_urb_for_dma
UPSTREAM: usb: xhci: Use temporary buffer to consolidate SG
UPSTREAM: usb: xhci: Set quirk for XHCI_SG_TRB_CACHE_SIZE_QUIRK
defconfig: Enable RTL8152 ETH-USB driver
msm: mhi_dev: Breaking memory for event request in smaller chunks
msm: eva: Validating the SFR buffer size before accessing
msm: eva: Copy back the validated size to avoid security issue
Change-Id: Ibd883e18a8a410fb23eb3cda97e88b77c34cdbd7
https://source.android.com/docs/security/bulletin/2025-03-01
CVE-2024-46852
CVE-2024-50302
CVE-2025-22413
# By Greg Kroah-Hartman (7) and others
# Via Greg Kroah-Hartman (3) and Terence Tritton (xWF) (1)
* tag 'ASB-2025-03-05_11-5.4':
ANDROID: ABI: Cuttlefish Symbol update
Revert "net: net_namespace: Optimize the code"
Revert "net: add exit_batch_rtnl() method"
Revert "gtp: use exit_batch_rtnl() method"
Revert "gtp: Use for_each_netdev_rcu() in gtp_genl_dump_pdp()."
Revert "gtp: Destroy device along with udp socket's netns dismantle."
Linux 5.4.290
Partial revert of xhci: use pm_ptr() instead #ifdef for CONFIG_PM conditionals
xhci: use pm_ptr() instead of #ifdef for CONFIG_PM conditionals
drm/v3d: Assign job pointer to NULL before signaling the fence
Input: xpad - add support for wooting two he (arm)
Input: xpad - add unofficial Xbox 360 wireless receiver clone
Input: atkbd - map F23 key to support default copilot shortcut
Revert "usb: gadget: u_serial: Disable ep before setting port to null to fix the crash caused by port being null"
USB: serial: quatech2: fix null-ptr-deref in qt2_process_read_urb()
ext4: fix slab-use-after-free in ext4_split_extent_at()
ext4: avoid ext4_error()'s caused by ENOMEM in the truncate path
vfio/platform: check the bounds of read/write syscalls
net/xen-netback: prevent UAF in xenvif_flush_hash()
net: xen-netback: hash.c: Use built-in RCU list checking
signal/m68k: Use force_sigsegv(SIGSEGV) in fpsp040_die
m68k: Add missing mmap_read_lock() to sys_cacheflush()
m68k: Update ->thread.esp0 before calling syscall_trace() in ret_from_signal
gfs2: Truncate address space when flipping GFS2_DIF_JDATA flag
irqchip/sunxi-nmi: Add missing SKIP_WAKE flag
scsi: iscsi: Fix redundant response for ISCSI_UEVENT_GET_HOST_STATS request
ASoC: wm8994: Add depends on MFD core
net: fix data-races around sk->sk_forward_alloc
scsi: sg: Fix slab-use-after-free read in sg_release()
ipv6: avoid possible NULL deref in rt6_uncached_list_flush_dev()
hrtimers: Handle CPU state correctly on hotplug
irqchip/gic-v3: Handle CPU_PM_ENTER_FAILED correctly
fs/proc: fix softlockup in __read_vmcore (part 2)
net: ethernet: xgbe: re-add aneg to supported features in PHY quirks
nvmet: propagate npwg topology
poll_wait: add mb() to fix theoretical race between waitqueue_active() and .poll()
kheaders: Ignore silly-rename files
hfs: Sanity check the root record
mac802154: check local interfaces before deleting sdata list
i2c: mux: demux-pinctrl: check initial mux selection, too
drm/v3d: Ensure job pointer is set to NULL after job completion
nfp: bpf: prevent integer overflow in nfp_bpf_event_output()
gtp: Destroy device along with udp socket's netns dismantle.
gtp: Use for_each_netdev_rcu() in gtp_genl_dump_pdp().
gtp: use exit_batch_rtnl() method
net: add exit_batch_rtnl() method
net: net_namespace: Optimize the code
net: ethernet: ti: cpsw_ale: Fix cpsw_ale_get_field()
sctp: sysctl: rto_min/max: avoid using current->nsproxy
ocfs2: fix slab-use-after-free due to dangling pointer dqi_priv
ocfs2: correct return value of ocfs2_local_free_info()
phy: core: Fix that API devm_of_phy_provider_unregister() fails to unregister the phy provider
phy: core: fix code style in devm_of_phy_provider_unregister
arm64: dts: rockchip: add hevc power domain clock to rk3328
arm64: dts: rockchip: add #power-domain-cells to power domain nodes
arm64: dts: rockchip: fix pd_tcpc0 and pd_tcpc1 node position on rk3399
arm64: dts: rockchip: fix defines in pd_vio node for rk3399
iio: inkern: call iio_device_put() only on mapped devices
iio: adc: at91: call input_free_device() on allocated iio_dev
iio: adc: ti-ads124s08: Use gpiod_set_value_cansleep()
iio: gyro: fxas21002c: Fix missing data update in trigger handler
iio: adc: ti-ads8688: fix information leak in triggered buffer
iio: imu: kmx61: fix information leak in triggered buffer
iio: light: vcnl4035: fix information leak in triggered buffer
iio: dummy: iio_simply_dummy_buffer: fix information leak in triggered buffer
iio: pressure: zpa2326: fix information leak in triggered buffer
usb: gadget: f_fs: Remove WARN_ON in functionfs_bind
usb: fix reference leak in usb_new_device()
USB: core: Disable LPM only for non-suspended ports
USB: usblp: return error when setting unsupported protocol
usb: gadget: u_serial: Disable ep before setting port to null to fix the crash caused by port being null
USB: serial: cp210x: add Phoenix Contact UPS Device
usb-storage: Add max sectors quirk for Nokia 208
staging: iio: ad9832: Correct phase range check
staging: iio: ad9834: Correct phase range check
USB: serial: option: add Neoway N723-EA support
USB: serial: option: add MeiG Smart SRM815
drm/amd/display: increase MAX_SURFACES to the value supported by hw
ACPI: resource: Add Asus Vivobook X1504VAP to irq1_level_low_skip_override[]
ACPI: resource: Add TongFang GM5HG0A to irq1_edge_low_force_override[]
drm/amd/display: Add check for granularity in dml ceil/floor helpers
sctp: sysctl: auth_enable: avoid using current->nsproxy
sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy
dm thin: make get_first_thin use rcu-safe list first function
tls: Fix tls_sw_sendmsg error handling
net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute
tcp/dccp: allow a connection when sk_max_ack_backlog is zero
tcp/dccp: complete lockless accesses to sk->sk_max_ack_backlog
net: 802: LLC+SNAP OID:PID lookup on start of skb data
ieee802154: ca8210: Add missing check for kfifo_alloc() in ca8210_probe()
dm array: fix cursor index when skipping across block boundaries
dm array: fix unreleased btree blocks on closing a faulty array cursor
dm array: fix releasing a faulty array block twice in dm_array_cursor_end
jbd2: flush filesystem device before updating tail sequence
Change-Id: I83cf20e29c63126cd17dfa393dca0ce7dfa47a76
* sm8350/lineage-20:
qcacmn: Fix OOB Read in util_gen_new_ie
BACKPORT: dsp-kernel: Add attribute and flag checks during map creation
Change-Id: I1257311e97442a66141ce387ab8c718d50ae0058
In util_gen_new_ie, there is a possible out-of-bound read due to a missing
length check for extended IEs in the final pass over the copied
subelements.
Fix is to check tmp_new[1] is not zero.
Change-Id: Ic393d699a208bb54ff645bd8d2424b84becf5543
CRs-Fixed: 3924648
A persistence map is expected to hold refs=2 during its creation.
However, the Fuzzy test can create a persistence map by configuring
a mismatch between attributes and flags using the KEEP MAP attribute
and FD NOMAP flags. This sets the map reference count to 1. The user
then calls fastrpc_internal_munmap_fd to free the map since it
doesn't check flags, which can cause a use-after-free (UAF) for the
file map and shared buffer. Add a check to restrict DMA handle
maps with invalid attributes.
Change-Id: I2f024ef99cc2a0487010504166e3af3433d5302d
Acked-by: Santosh <quic_ssakore@quicinc.com>
Signed-off-by: Abhinav Parihar <quic_parihar@quicinc.com>
mm/page_owner.c:944:39: error:
size argument in 'strlcpy' call appears to be size of the source;
expected the size of the destination [-Werror,-Wstrlcpy-strlcat-size]
944 | strlcpy(call_site->name, buf, strlen(buf));
| ~~~~~~~^~~~
mm/page_owner.c:944:32: note:
change size argument to be the size of the destination
944 | strlcpy(call_site->name, buf, strlen(buf));
| ^~~~~~~~~~~
| sizeof(call_site->name)
https://github.com/LineageOS/android_kernel_qcom_sm8450/blob/lineage-20/drivers/soc/qcom/minidump_memory.c#L692
contains the same code.
Change-Id: Id06f67fe18f2e00dd180afaf99c7577787198cc3
Signed-off-by: Sevenrock <sevenrock@hotmail.de>
drivers/backlight/aw99703/leds_aw99703.c:705:27:
error: variable 'bl_dev' set but not used [-Werror,-Wunused-but-set-variable]
705 | struct backlight_device *bl_dev;
Change-Id: Ic54933366a36805939160423188595c81e2711e6
Signed-off-by: Sevenrock <sevenrock@hotmail.de>
I am pretty sure prod builds don't need this to be enabled and was
meant originally to be used in the development phase.
Further, dmesg shows that it fails to open the file:
aw_cali_get_read_cali_re:channel:1 open /mnt/vendor/persist/factory/audio/aw_cali.bin failed!
Change-Id: I61c5151ba23a1d117b54dd2eb0c0f482da7d941a
Signed-off-by: Forenche <prahul2003@gmail.com>