Commit graph

911,795 commits

Author SHA1 Message Date
Sai Chaitanya Kaveti
5e4dbce2b7 msm: mhi_dev: Support async write in UCI for size greater than 8k
In the current implementation of MHI UCI layer, write operation from
device to host fails if the size requested by client is more than 8k.
Removing this condition in this change as MHI supports buffer size of
upto 64k in async path. Continuing to fail write in sync case, as MHI
layer uses pre allocated buffers of size 8k. Also, added debug logs to
check if buffer size of Diag is more than 16k. With this change async
writes of size greater than 8k are supported in UCI layer.

Change-Id: I084da6a49a00095e806872f591365eabb9edc1de
Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
2023-06-01 19:55:42 +05:30
qctecmdr
17edd981ce Merge "mtd: msm_qpic_nand: Add boot_a and boot_b access to APPS" 2023-05-30 08:08:27 -07:00
Pradeep P V K
eba92f48be mtd: msm_qpic_nand: Add boot_a and boot_b access to APPS
The existing code logic, checks for partitions that have
access to apps by name "boot". This logic may not work
if the boot partition name changes, let's say as boot_a/b.

So, get the active boot partition details by reading the
new kernel command line parameter "part.activeboot=" and
use this partition page offset address to read the ONFI
parameter page. If active boot partition details are
not found, fallback to legacy code.

Change-Id: I7c7071ccfc687f2e03bd9209a3c7260fb131ff10
Signed-off-by: Pradeep P V K <quic_pragalla@quicinc.com>
2023-05-30 11:24:41 +05:30
Prerna Singh
c62a901eab qcom: cpufreq-hw: Use the topology coreid for offset
Use the topology_core_id() API to calculate the offset
of the CPU cores. This will help to correctly calculate the
offset in case of CPU with fused cores.

Change-Id: I78992edc3a646b8062e8bdd80f4c72e8c97387ec
Signed-off-by: Prerna Singh <quic_prersing@quicinc.com>
2023-05-19 07:34:44 -07:00
Auditya Bhattaram
06426824a2 soc: qcom: Add Upperbounds check for program header
e_phnum represent the number of entries in the program header table.
So add Upperbounds check for program header and return invalid if the
number of program headers is greater than PN_XNUM (0xffff).

Change-Id: I63927e2e88a57a567a52b4eb377abe94ad3713b8
Signed-off-by: Auditya Bhattaram <quic_audityab@quicinc.com>
2023-05-17 22:29:07 -07:00
qctecmdr
60fe648361 Merge "msm: adsprpc: Handle UAF in fastrpc_buf_free" 2023-05-16 21:39:58 -07:00
Tapas Dey
7cf8efc166 msm: adsprpc: Handle UAF in fastrpc_buf_free
Thread T1 add buffer to fl->cached_bufs and release fl->hlock and holding
buffer reference. Now thread T2 will aquire fl->hlock and free buffer in
fastrpc_cached_buf_list_free(). T1 will dereference the freed buffer.
Moving reference buffer uses for T1 inside fl->hlock to avoid UAF.

Change-Id: I5f08d5497099133f87d55f5879cfe50c2ba23ae6
Signed-off-by: Tapas Dey <quic_tapadey@quicinc.com>
2023-05-15 04:49:16 -07:00
qctecmdr
811eb4ca7f Merge "interconnect: qcom: direwolf: fix UAF under remove function" 2023-05-15 04:24:40 -07:00
qctecmdr
f807b6d9c6 Merge "interconnect: qcom: sm6150: fix UAF under remove function" 2023-05-15 04:24:40 -07:00
qctecmdr
527aabe6b0 Merge "interconnect: qcom: sdxnightjar: fix UAF under remove function" 2023-05-15 04:24:40 -07:00
qctecmdr
8b7e1ec0b4 Merge "interconnect: qcom: yupik: fix UAF under remove function" 2023-05-15 04:24:39 -07:00
qctecmdr
ec56e31d27 Merge "interconnect: qcom: sdxlemur: fix UAF under remove function" 2023-05-15 04:24:39 -07:00
qctecmdr
daed7cb962 Merge "interconnect: qcom: scshrike: fix UAF under remove function" 2023-05-15 04:24:39 -07:00
qctecmdr
3c7f2a8364 Merge "interconnect: qcom: sm8150: fix UAF under remove function" 2023-05-15 04:24:36 -07:00
qctecmdr
bb70967678 Merge "qcedev: vote for crypto clocks during module close" 2023-05-14 21:30:14 -07:00
qctecmdr
096643eb48 Merge "interconnect: qcom: monaco: fix UAF under remove function" 2023-05-12 21:02:30 -07:00
Raviteja Laggyshetty
ae2d0077d6 interconnect: qcom: sm8150: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: I0c8cfd628483cd44408b987e4765dc7237ef7ad5
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-12 19:20:57 +05:30
Raviteja Laggyshetty
a5e1d0fedf interconnect: qcom: monaco: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: I249472490349c227d9f30f276439fd1d0de0bdb9
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-12 19:16:16 +05:30
qctecmdr
72b1398669 Merge "interconnect: qcom: shima: fix UAF under remove function" 2023-05-12 05:37:11 -07:00
qctecmdr
ed38cbcc29 Merge "interconnect: qcom: lahaina: fix UAF under remove function" 2023-05-12 02:04:17 -07:00
Raviteja Laggyshetty
b4c93ec98e interconnect: qcom: direwolf: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: I7bd39e3269409527cc55e5a7ceaddedb70324612
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-04 18:57:22 -07:00
Raviteja Laggyshetty
9904cf1df1 interconnect: qcom: yupik: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: I608e85bc66028878b9dbfeff1c0a4caf683d03fb
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-04 18:56:48 -07:00
Raviteja Laggyshetty
adf5e4ca9d interconnect: qcom: sdxnightjar: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: I761c047c722cebe3b2c721adab3fbed9dc1d7e47
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-04 18:56:17 -07:00
Raviteja Laggyshetty
ee142e497d interconnect: qcom: sdxlemur: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: Ic75d04bf95dc21d5453c6e5e3a0a4864304fc8b5
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-04 18:54:47 -07:00
Raviteja Laggyshetty
194c56a921 interconnect: qcom: sm6150: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: Ib1335860da25147ca87715a1935d2e8feee3fde4
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-04 18:54:04 -07:00
Raviteja Laggyshetty
153bf8409a interconnect: qcom: shima: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: I296b40141d3d844f3011cd704e8c593c8bc0f5e0
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-04 18:53:24 -07:00
Raviteja Laggyshetty
bb0e2f4acf interconnect: qcom: scshrike: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: Ib420005ad94507db927a3014a39bd0d06b4d416f
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-04 18:52:49 -07:00
Raviteja Laggyshetty
c36b875972 interconnect: qcom: lahaina: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: I7a840812752b34248ec3dcb241b069cf4bf77608
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-04 18:52:11 -07:00
Raviteja Laggyshetty
e57b2b062e interconnect: qcom: holi: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: If4ddebec67f008e5412c1bf03bed0693fcaaffe0
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-02 21:06:47 -07:00
Gaurav Kashyap
0a7a6f1501 qcedev: vote for crypto clocks during module close
When qcedev module is exiting, it disconnects SPS.
At this times, crypto clocks need to be turned on
or it will cause a synchronous abort.

Tests: rmmod on the qcedev module.

Change-Id: I1721fe408392ef81b07a6c08d2196b2413ba2b2f
Signed-off-by: Gaurav Kashyap <quic_gaurkash@quicinc.com>
Signed-off-by: Nageswara reddy Karnati <quic_nkarnati@quicinc.com>
2023-05-02 01:38:31 -07:00
qctecmdr
0c085f1ad1 Merge "virt: haven: rsc_mgr: Allocate right buffer size of requests" 2023-05-01 23:24:23 -07:00
qctecmdr
489c7f8c5a Merge "msm: adsprpc: Handle UAF in fastrpc internal munmap" 2023-04-23 09:47:13 -07:00
Ram Nagesh
f20dfe7d99 msm: synx: Check for zero before reducing bind handles
Suppose user has sent invalid external fence to bind API. Now, while
binding, if synx signal comes in parallel, it will set number of bound
synxs as 0 after signal. Further reduction on that number(num_bound_synxs)
(in case of callback registration failure) would make it wrap
around. So, now num_bound_synxs is large value and abrupt close on synx
fd will lead to synx_util_object_destroy. Here, the for loop on
num_bound_synxs would lead to invalid memory access.

This change decrements num_bound_synxs only if not zero.

Change-Id: I0cfffc90d4164b149c87545818ae4dcf57fc4c46
Signed-off-by: Ram Nagesh <quic_ramnages@quicinc.com>
2023-04-20 23:12:43 -07:00
Santosh Sakore
96507bd863 msm: adsprpc: Handle UAF in fastrpc internal munmap
Added reference count for contex map indicate memory under used
in remote call. And, this memory would not removed in internal
unmap to avoid UAF.

Change-Id: Ieb4ff6b298ff9c48953bc5b3539fdfe19a14b442
Acked-by: Santosh Sakore <ssakore@qti.qualcomm.com>
Signed-off-by: Santosh Sakore <quic_ssakore@quicinc.com>
2023-04-21 11:35:43 +05:30
qctecmdr
460f325dcb Merge "coresight-tmc: increase qdss pcie sw path throughput" 2023-04-20 04:34:07 -07:00
qctecmdr
32365ca0ad Merge "mtd: msm_qpic_nand: Add boot_a and boot_b access to APPS" 2023-04-20 04:34:06 -07:00
qctecmdr
da3aa8fcd8 Merge "defconfig: sdxlemur: Enable R8168 driver config" 2023-04-20 04:34:06 -07:00
qctecmdr
3699f69fa5 Merge "net: qrtr: Move service id based filter check before queueing skb" 2023-04-20 04:34:04 -07:00
qctecmdr
019027da9d Merge "Merge android11-5.4.226+ (2af3bdf) into msm-5.4" 2023-04-20 01:16:41 -07:00
qctecmdr
0569ed8c36 Merge "msm: kgsl: Keep postamble packets in a privileged buffer" 2023-04-18 10:00:07 -07:00
qctecmdr
b4f4305f32 Merge "msm: kgsl: Check user generated timestamp before queuing drawobjs" 2023-04-18 10:00:06 -07:00
Pradeep P V K
b4b121f38d mtd: msm_qpic_nand: Add boot_a and boot_b access to APPS
As part of FR53657, make changes to support for boot_a and
boot_b partition access to HLOS APPS.

Change-Id: Ic173bd54df11e42b1811c198314719c4c34338db
Signed-off-by: Pradeep P V K <quic_pragalla@quicinc.com>
2023-04-11 21:24:02 +05:30
Yuanfang Zhang
931dbd1b07 coresight-tmc: increase qdss pcie sw path throughput
Increase throughput for qdss pcie sw path.

Change-Id: I4bb52e81d2617d8e83d0dcfe525cad2f6f5ca93a
Signed-off-by: Yuanfang Zhang <quic_yuanfang@quicinc.com>
2023-04-06 23:10:27 -07:00
Akhil P Oommen
128731bb62 msm: kgsl: Keep postamble packets in a privileged buffer
Postamble packets are executed in privileged mode by gpu. So we should keep
them in a privileged scratch buffer to block userspace access. For
targets with APRIV feature support, we can mark the preemption scratch
buffer as privileged too to avoid similar issues in future.

Change-Id: Ifda360dda251083f38dfde80ce1b5dc83daae902
Signed-off-by: Akhil P Oommen <quic_akhilpo@quicinc.com>
Signed-off-by: Kaushal Sanadhya <quic_ksanadhy@quicinc.com>
2023-03-31 16:21:55 +05:30
Arun Prakash
87acdd7036 net: qrtr: Move service id based filter check before queueing skb
Move service id based filter check before queueing skb to avoid
possible use after free issue since skb might get released once
rx thread completed the processing of skb.

Change-Id: Iff93e32abd3d55f78bf4ce80675fc3bb312b0841
Signed-off-by: Arun Prakash <quic_app@quicinc.com>
2023-03-29 17:44:19 +05:30
Kamal Agrawal
046f27cfe2 msm: kgsl: Check user generated timestamp before queuing drawobjs
In ioctls like kgsl_ioctl_submit_commands(), if both syncobj
type and cmd/marker/sparseobj type are submitted, the syncobj
is queued first followed by the other obj type. After syncobj
is successfully queued, in case of failure in get_timestamp
while queuing the other obj, both the command objs are
destroyed. As sync obj is already queued, accessing this
later would cause a crash.

Compare the user generated timestamp with the drawctxt
timestamp and return early in case of error. This avoids
unnecessary queuing of drawobjs.

Change-Id: Iedebd480bc18cd74d2f69d24a9dc1032fab01cdb
Signed-off-by: Kamal Agrawal <quic_kamaagra@quicinc.com>
2023-03-28 17:56:20 +05:30
qctecmdr
29910cbf29 Merge "dwc3: Add check for sg queued trbs while reclaiming" 2023-03-21 11:00:43 -07:00
Krishna Nagaraja
1f7f937648 msm: ipa3: add ioctl interface for dual backhaul
Add the ioctl interface to indicate Dual backhaul info,
using QMI message.

Change-Id: I5fa944c61e1745fe71c7ddc8bf48e0001c19e520
Signed-off-by: Krishna Nagaraja <quic_krisnag@quicinc.com>
2023-03-19 21:30:32 -07:00
AKASH KUMAR
f3dae06c15 dwc3: Add check for sg queued trbs while reclaiming
If we're in the middle of series of chained TRBs, DWC3 will
avoid clearing HWO and SW has to do it manually.
We are doing it while reclaiming trbs for sg transfers.

Add check for sg queued trb and reclaim it as DWC3 skips
clearing HWO bit during sg transfers.

Change-Id: I200254728c0549da6534aea51daad94be6b6295e
Signed-off-by: AKASH KUMAR <quic_akakum@quicinc.com>
2023-03-17 10:42:08 +05:30
qctecmdr
e531d35984 Merge "i2c-msm-geni: KASAN: use-after-free in __list_add_valid+0x2c/0xc4" 2023-03-16 11:57:12 -07:00