Commit graph

1,417 commits

Author SHA1 Message Date
Parag Singhal
542be35e0e msm: camera: common: Fix OOB access in bandwidth path handling
Invalid input from user can lead to an index going below the valid
range after offset calculation. Existing validation only checked
the upper bound, allowing negative values to pass and cause
out-of-bounds memory access.
Add complete bounds validation to ensure safe access.

CRs-Fixed: 4544133
Change-Id: Ib37b25ab84e9004eaeb216302857d65df18a2516
Signed-off-by: Parag Singhal <parsin@qti.qualcomm.com>
(cherry picked from commit d6cee3f552be8126f0c8b29ea833228bf3357fa8)
2026-07-06 22:42:47 -07:00
Linux Build Service Account
68c6536164 Merge 6aa2110d4f on remote branch
Change-Id: I10e6d2ee1d9caafd47892a8a8897e67766f420aa
2026-04-29 05:43:29 -07:00
Linux Build Service Account
6aa2110d4f Merge changes I52459823,I88d1c764 into camera-kernel-iot.lnx.4.1
* changes:
  msm: camera: isp: Fix potential illegal access in Acquire HW. Fix for above
  msm: camera: isp: Fix potential illegal access in Acquire HW
2026-03-03 21:50:19 -08:00
Linux Build Service Account
bd44a374ed Merge changes I185381f8,I26ee4c58 into camera-kernel-iot.lnx.4.1
* changes:
  msm: camera: ois: Copy packet header in kernel
  msm: camera: common: Add missing put_cpu_buf calls
2026-03-03 21:50:18 -08:00
Linux Build Service Account
eb61b222e5 Merge changes I2a81410f,I69163a42,I39494b0a into camera-kernel-iot.lnx.4.1
* changes:
  msm: camera: sensor: handling condition for random read
  msm: camera: icp: io buf config num validation
  msm: camera: ope: check cpu buffer offset and cmd buf idx
2026-03-03 21:50:15 -08:00
Ajith Rajana
7e0e214538 msm: camera: isp: Fix potential illegal access in Acquire HW.
Fix for above

Change-Id: I524598236aec47f3e80ef0325326ee75a809b197
Signed-off-by: Ajith Rajana <rajana@qti.qualcomm.com>
2026-02-09 16:53:24 +05:30
Vivek Yadav
bca82b3563 msm: camera: isp: Fix potential illegal access in Acquire HW
Fix potential illegal acquire_hw memory access due to following
scenario. Even though ioctl is synchronous, the kernel performs
1. copy_from_user(&api_version, ...) — reads just the version.
2. Allocates buffer based on version.
3. copy_from_user(acquire_ptr, ...) — reads the full structure.

If another thread modifies the user-space buffer (cmd->handle)
between steps 1 and 3, the kernel will
* Allocate a buffer for version 1.
* But read data formatted for version 1, by modifying api version v2.
* Call the  isp_ctx: acquire_hw_in_acquired.
* Now even though the allocated strructure version is v1, in
  acquire_hw_in_acquired call to api of version v2 would get invoked.
* Leading to OOB reads/writes.

CRs-Fixed: 4216838
Change-Id: I88d1c76438b56d6ccfa014aa440a536ac5bdd27a
Signed-off-by: Vivek Yadav <viveyada@qti.qualcomm.com>
(cherry picked from commit 55273537c3c23152bba518402a96a86918e3f56c)
2026-02-09 16:53:04 +05:30
chengxue
3b061e5b70 msm: camera: ois: Copy packet header in kernel
After getting the mapped buffer through cam_mem_get_cpu_buf()
in kernel, userspace is still able to access those buffers.
This change copy ois packet header in kernel to avoid TOCTOU
issue.

CRs-Fixed: 3885381
Change-Id: I185381f81a6a736a029b516dc7f99cce1cac7129
Signed-off-by: chengxue <quic_chengxue@quicinc.com>
2026-02-09 16:52:46 +05:30
Nirmal Abraham
ba6bfdd6ee msm: camera: common: Add missing put_cpu_buf calls
Add cam_mem_put_cpu_buf calls in error scenarios to avoid
memory leak.

CRs-Fixed: 3866880
Change-Id: I26ee4c58ab88458d109b13a04cfcaea3502b31a3
Signed-off-by: Nirmal Abraham <quic_c_nabrah@quicinc.com>
2026-02-09 16:52:18 +05:30
jinguiw
4bc8ff3984 msm: camera: sensor: handling condition for random read
Get i2c setting count twice in different location for i2c setting,
may lead to out of bound for reg settings. Record i2c setting count
in the first fetch to avoid this risk.

CRs-Fixed: 3885312
Change-Id: I2a81410fecdf41910d7d2eb0daf233621fe0b452
Signed-off-by: jinguiw <quic_jinguiw@quicinc.com>
2026-02-09 16:48:08 +05:30
jinguiw
c74ff3c92d msm: camera: icp: io buf config num validation
There are only limitations for CAM_BUF_IN and CAM_BUF_OUT in
config validation, but there will be CAM_BUF_IN_OUT type also.
In process io config, both CAM_BUF_OUT and CAM_BUF_IN_OUT types
are in out_map_entries. No limitation for CAM_BUF_IN_OUT will
lead to out of bound for out_map_entries. This change adds check
for num of io config need in out_map_entries to avoid
out of bound risk.

CRs-Fixed: 3857308
Change-Id: I69163a4264d226d617cbe4f37ba1deb4e6434e31
Signed-off-by: jinguiw <quic_jinguiw@quicinc.com>
2026-02-09 16:47:47 +05:30
jinguiw
08d0784e99 msm: camera: ope: check cpu buffer offset and cmd buf idx
No check for cpu buffer offset, which may lead to out of cpu buffer
map. No check for cmd buffer index, which may lead to out of bound
or negative index. Adding check for cpu buffer map offset and
adding check for cmd buffer index.

CRs-Fixed: 3864084
Change-Id: I39494b0a9f323cb5569d37a0c033b2eaf8fbd32c
Signed-off-by: jinguiw <quic_jinguiw@quicinc.com>
2026-02-09 16:47:23 +05:30
Swami Reddy Reddy
2bb93e9329 msm: camera: sensor: TOCTOU error handling
- Proper Handling in case of invalid pinctrl index
- Removing dead code and unused variables
- Change to dereference s_ctrl only after proper
  NULL Dereference Check.

CRs-Fixed: 3875406
Change-Id: I8e2c717b22efff2a7d6503d38c048e30eff230da
Signed-off-by: Swami Reddy Reddy <quic_swamired@quicinc.com>
(cherry picked from commit 79d77de659ef7ae0727af4165c5894804ab72d60)
2025-04-21 09:10:05 -07:00
Swami Reddy Reddy
d1e31dec5a msm: camera: sensor: TOCTOU error handling
- Proper Handling in case of invalid pinctrl index
- Removing dead code and unused variables
- Change to dereference s_ctrl only after proper
  NULL Dereference Check.

CRs-Fixed: 3875406
Change-Id: I8e2c717b22efff2a7d6503d38c048e30eff230da
Signed-off-by: Swami Reddy Reddy <quic_swamired@quicinc.com>
2024-10-15 00:47:48 -07:00
Linux Build Service Account
288bd09c34 Merge 010154959c on remote branch
Change-Id: Ib0107a286d9d281f57dff217ff8de2458e778521
2024-05-13 08:31:20 -07:00
Linux Build Service Account
81dea19b73 Merge 27597eb95b on remote branch
Change-Id: I385e6bd541b34edd86c0afbf6be4a0c86be398c5
2024-04-10 12:51:47 -07:00
zhuo
010154959c msm: camera: memmgr: Add refcount to track umd in use buffers
Currently krefcount is using by umd and kmd. Due to sometimes
there is issue in umd, such as release twice. That maybe causes
buffer release before kmd access the buffer. This commit add
a new refcount to track umd in use buffers and use current krefcount
to track kmd in use buffers. For the same buffer use in kmd and umd
only when all refcount become zero, the buffer start to release.

CRs-Fixed: 3692103
Change-Id: I5a58d9bab4c82bdb192d6a6a3d2b3d254dc04c9e
Signed-off-by: zhuo <quic_zhuo@quicinc.com>
2024-04-07 17:12:24 +08:00
Shivi Mangal
27597eb95b msm: camera: sensor: Handling race condition in util api
I2C cmd is coming from user space which can be modified due to
access to shared memory. This change scopes the data locally so
as to avoid vulnerability of count being modified by external
means while executing due to being in shared memory.

CRs-Fixed: 3707472
Change-Id: I8a89e23e99b80b089ed4c4cf3098feead752356e
Signed-off-by: Shivi Mangal <quic_smangal@quicinc.com>
(cherry picked from commit 4e00cc5f9f81bf471d58ee5d6beb210a5326fcff)
(cherry picked from commit 6245be68a914dd9984c259ab3c6bc1647c1593be)
2024-04-02 10:34:01 -07:00
Linux Build Service Account
de18458094 Merge 06f5366d58 on remote branch
Change-Id: Ie538b96e3bb73fd3946aed31a1d1f16711d4edaf
2024-03-10 22:57:57 -07:00
Camera Software Integration
06f5366d58 Merge "msm: camera: memmgr: Add missing calls of put buf to avoid leak" into camera-kernel.lnx.4.0 2024-02-23 22:37:34 -08:00
Shivi Mangal
c9cd58783e msm: camera: sensor: Proper handling of race condition in util api
Power count is coming from user space which can be modified due to
access to shared memory. This change scopes the data locally so
as to avoid vulnerability of count being modified by external
means while executing due to being in shared memory.

CRs-Fixed: 3691744.

Change-Id: I57d13435453195f8aab0c9aad4414d290274ff81
Signed-off-by: Shivi Mangal <quic_smangal@quicinc.com>
2024-02-11 09:09:40 -08:00
Shivakumar Malke
47fb597026 msm: camera: memmgr: Add missing calls of put buf to avoid leak
This change add calls to put cpu buf in few scenarios.

CRs-Fixed: 3578162
Change-Id: Iab6aa0324b5072390b38df296c7acee00f5102a1
Signed-off-by: Vikram Sharma <quic_vikramsa@quicinc.com>
Signed-off-by: Nirmal Abraham <quic_c_nabrah@quicinc.com>
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
Signed-off-by: Pranav Sanwal <quic_psanwal@quicinc.com>
2024-02-06 00:26:28 -08:00
Linux Build Service Account
1096f8864c Merge 45e9dd3937 on remote branch
Change-Id: I0274a44043fe17796cc4d3d55104210a2a569075
2024-01-11 03:05:42 -08:00
Yash Upadhyay
45e9dd3937 msm: camera: common: Fix possible OOB reads and writes operation
We need to check if the packet is valid before using it.

CRs-Fixed: 3605421
Change-Id: Ide4e005ba46690c1cac02cb77a2d9aaa497b15df
Signed-off-by: Yash Upadhyay <quic_yupadhya@quicinc.com>
(cherry picked from commit 2a55b109db91e8302f023f25295b564df9ef400c)
2023-12-11 23:28:39 +05:30
Linux Build Service Account
da4eec4658 Merge 82ce65cbeb on remote branch
Change-Id: I2b1995623ed5db3e53c485cdfae3b2deada62073
2023-09-18 05:31:25 -07:00
Nirmal Abraham
82ce65cbeb msm: camera: memmgr: release buffers after usage
Call cam_mem_put_cpu_buf corresponding to
cam_mem_get_cpu_buf calls to make sure ref_cnt
is balanced and buffer is freed when all
clients are done with the buffer usage.

CRs-Fixed: 3547081
Change-Id: I9414829d6f17c368f2718fe05dbe25c71b31e674
Signed-off-by: Nirmal Abraham <quic_c_nabrah@quicinc.com>
2023-07-13 21:06:48 -07:00
Linux Build Service Account
b0f4412db3 Merge f81db81382 on remote branch
Change-Id: Ib7eaa74a7665a4508797d38da7127c79d6a2a901
2023-07-13 06:17:01 -07:00
Gaurav Jindal
f81db81382 msm: camera: fd: Fix compilation issue
This commit fixes compilation issue.

CRs-Fixed: 3549085
Change-Id: Ia98fbbf67736c372fea4788b8e445c534126da21
Signed-off-by: Gaurag Jindal <quic_gjindal@quicinc.com>
2023-07-04 04:50:49 -07:00
illa lakshmi soujanya
0724e68848 msm: camera: sensor: Add changes to prevent unmap buffers
The function cam_mem_mgr_release can unmap buffers when in use.
This change with cam_mem_put_cpu_buf prevents unmaping the buffers in use.

CRs-Fixed: 3489559
Change-Id: I9c4e284c5961a2eb4ff0df362c93d6cea7d77cab
Signed-off-by: illa lakshmi soujanya <quic_illa@quicinc.com>
2023-06-23 18:58:29 +05:30
Shivakumar Malke
575f20ea96 msm: camera: mem_mgr: Add refcount to track in use buffers
The function cam_mem_mgr_release can unmap the buffers when in use.

This change prevents unmapping the buffers when in use.

CRs-Fixed: 3489559
Change-Id: I2e72e795d39ac15abfa56c19043c419a03686966
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
Signed-off-by: Gaurav Jindal <quic_gjindal@quicinc.com>
2023-06-23 18:52:01 +05:30
Karthik Dillibabu
217ebc5e61 msm: camera: core: validation of session/device/link handle
This change is to validate session, device and link handle.
Also, checks whether the device handle belongs to
correct session handle or not.

CRs-Fixed: 3496553
Change-Id: I6b86bf7d0908a280e90e085a3b3e1727facdf8c6
Signed-off-by: Karthik Dillibabu <quic_kard@quicinc.com>
2023-06-13 11:38:28 +05:30
Linux Build Service Account
ff5ca45c7d Merge 68373c0331 on remote branch
Change-Id: I85ad05a7a99c540d7f9c8d6ffe27553f0850d3d2
2023-05-16 02:06:43 -07:00
Linux Build Service Account
117bda2bee Merge 9b3f91ecab on remote branch
Change-Id: I098e7146b8853a4ce50df412ee006de56b1c1ac0
2023-04-19 01:28:02 -07:00
zhuo
68373c0331 msm: camera: cdm: Making WQ to have inflight works to be one
For requests with multiple BL tags,in a corner case,
cdm work notifies out of order requests to client as
difference in bl_tags is greater than boundary check.

This commit avoids out of order request processing by
making number of inflight work to be 1 and increasing
the priority of workqueue. And therefore removed all
checks that are not required.

CRs-Fixed: 3453131
Change-Id: I6db3e9379b2474347cff1618ea6ad705ca3561fb
Signed-off-by: zhuo <quic_zhuo@quicinc.com>
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
2023-04-05 21:13:27 -07:00
Yash Upadhyay
9b3f91ecab msm: camera: cdm: check irq status on hang detection
Problem:
Check IRQ status on hang detection if the inline IRQ
is set then the cdm has triggered IRQ but there is a
workqueue scheduling delay which is causing the cdm's
config timeout.

Solution:
To prevent the timeout due to
scheduling delay check the work record and irq status
and return true if its delay.

CRs-Fixed: 3433175
Change-Id: Iaa34f8ff9b57e7da9f80677a7da9b4f9a53dad14
Signed-off-by: Yash Upadhyay <quic_yupadhya@quicinc.com>
2023-03-15 09:06:44 +05:30
Camera Software Integration
bfe3e9d726 Merge "msm: camera: ope: Avoid deadlock in OPE PF handling" into camera-kernel.lnx.4.0 2023-03-13 04:50:34 -07:00
Shivakumar Malke
53152ba8cd msm: camera: ope: Avoid deadlock in OPE PF handling
In OPE fault handler, while dumping pf info ctx_mutex is
acquired and corresponding page fault ops is called. In
pagefault ops same mutex is getting acquired again causing
a dead lock.

This commit avoids locking the same mutex again.

CRs-Fixed: 3419490
Change-Id: I2e37f725865d091f2cb682fc62f5d21278b93959
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
2023-03-02 15:22:10 +05:30
Shivakumar Malke
d7eae61ec4 msm: camera: smmu: Use get_file to increase ref count
Due to race condition, fd pointing to a particular dma buf
is released by userspace  before incrementing ref count and
hence freed that dma buf. When the call returns it still uses
the freed dma buf causing use-after-free.

This fix includes get_file API to increment ref count
before dma_buf_fd.

CRs-Fixed: 3341070
Change-Id: I8ebc37b4ceb5f8691bbbb3d26b8b64878d832fbe
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
2023-02-21 12:19:00 +05:30
Linux Build Service Account
717ed6c0c7 Merge 687f2e3e5d on remote branch
Change-Id: I28ff8056f19a5f268fcbe4220494c90ca5d8a63c
2023-01-17 01:41:59 -08:00
Linux Build Service Account
7be199b817 Merge 9831108abf on remote branch
Change-Id: I7f73bde6ba7e1e7ba9b8d72cd24dc50018d883c7
2022-12-15 09:02:15 -08:00
Shivakumar Malke
687f2e3e5d msm: camera: lrme: BL command length validation
This change is to validate BL command length and
addresses before submitting to CDM. Also as part
of recovery avoids moving wrong packet submit request
to pending queue.

CRs-Fixed: 3342983
Change-Id: I15f082cdd4d54ad6bf0e446115780829b3b711dd
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
2022-12-13 10:39:35 +05:30
Shivakumar Malke
9831108abf msm: camera: isp: Handle early bufdones
In case of early bufones, signalling fence for few
ports are missed for target which do not support
last consumed address which result in a unsignalled fence

Issue is fixed by handling early bufdones and signalling
success for resource which got early bufdone.

CRs-Fixed: 3333269
Change-Id: I0a56f770806d48034bcc45d2ca68d8f9adcc8eee
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
2022-11-16 18:59:51 +05:30
Linux Build Service Account
0b53631edf Merge 5685ecf200 on remote branch
Change-Id: Id30175596e589fdef485c1f8b51f9b2321dc9397
2022-11-14 04:08:02 -08:00
Linux Build Service Account
742ed9f15d Merge a2b2dfab21 on remote branch
Change-Id: I5162c2cf87d26995bdd362531d53047d3928c513
2022-10-18 02:42:49 -07:00
Ashish Bhimanpalliwar
5685ecf200 msm: camera: common: Add conditions to catch invalid packet data
Add conditions to catch invalid cmd_desc, io buffers, and kmd buffers in
the packet payload.

CRs-Fixed: 3250331
Change-Id: I2db474572a8c5391ba9b9821de2da0db8f10eb4d
Signed-off-by: Ashish Bhimanpalliwar <quic_abhiman@quicinc.com>
2022-10-10 20:49:53 -07:00
Shivakumar Malke
a2b2dfab21 msm: camera: isp: Handle RUP in applied substate
In TFE top-half handler, TOP register status is read first and
then based on top register status, bus register status is read.
There could be a corner case where bufdone irq top-half handling
is ongoing, top status registers are read, and while reading bus
register status we might have got SOF and RUP irqs. Since RUP and
Bufdone both come from bus side, RUP bit is set during this bus
register read. Hence, RUP is handled first along with bufdone and
then SOF irq is handled. There is no handling in statemachine for
such RUP's in RDI only context statemachine. Hence leading to
bubble condition resulting in frame drop

To overcome such scenario, handling for RUP in applied substate
is introduced in RDI only statemachine.

CRs-Fixed: 3298719
Change-Id: I5cc8a0c122aa09c22da6536303f849344454c480
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
2022-09-28 16:38:19 +05:30
Linux Build Service Account
1b8e9355a2 Merge 336163ddec on remote branch
Change-Id: I92270af5cb1f133bb17b4888fd2c43cde713e4c2
2022-08-15 23:23:43 -07:00
Yash Upadhyay
336163ddec msm: camera: memmgr: Avoid TOCTOU buffer access on multiple use of same fd
Fd is a user-accessible value, referring it multiple times
leads to TOCTOU issues. Dma_buf can be freed after the 1st
use of fd and userspace can create another dma_buf but with
same fd. In such scenario, during 2nd use of fd, we may get
a different dma_buf with different length. To avoid this, we
can use same dma_buf instead of retrieving it twice using same
fd. In this change FD is accessed only once in syscall.

CRs-Fixed: 3159446
Change-Id: I00eb6dd3d798165f5c6c0bd59feabe80a68592b1
Signed-off-by: Yash Upadhyay <quic_yupadhya@quicinc.com>
2022-08-03 10:04:47 +05:30
Linux Build Service Account
35a56acb33 Merge d35e7e899b on remote branch
Change-Id: Ide4cb97fa564ec984b297ea505c70bee1561f64a
2022-07-12 15:18:29 -07:00
Camera Software Integration
d35e7e899b Merge "msm: camera: utils: modify debug function logic" into camera-kernel.lnx.4.0 2022-06-29 21:13:09 -07:00