commit bce1305c0ece3dc549663605e567655dd701752c upstream.
It appears that a ReportSize value of zero is legal, even if a bit
non-sensical. Most of the HID code seems to handle that gracefully,
except when computing the total size in bytes. When fed as input to
memset, this leads to some funky outcomes.
Detect the corner case and correctly compute the size.
Cc: stable@vger.kernel.org
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Benjamin Tissoires <benjamin.tissoires@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit bce1305c0ece3dc549663605e567655dd701752c)
Change-Id: I5ab5febc22b8d5d8c5d398c3ff93f73cb3c90e05
Signed-off-by: Todd Kjos <tkjos@google.com>
commit 35556bed836f8dc07ac55f69c8d17dce3e7f0e25 upstream.
When calling into hid_map_usage(), the passed event code is
blindly stored as is, even if it doesn't fit in the associated bitmap.
This event code can come from a variety of sources, including devices
masquerading as input devices, only a bit more "programmable".
Instead of taking the event code at face value, check that it actually
fits the corresponding bitmap, and if it doesn't:
- spit out a warning so that we know which device is acting up
- NULLify the bitmap pointer so that we catch unexpected uses
Code paths that can make use of untrusted inputs can now check
that the mapping was indeed correct and bail out if not.
Cc: stable@vger.kernel.org
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Benjamin Tissoires <benjamin.tissoires@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 35556bed836f8dc07ac55f69c8d17dce3e7f0e25)
Change-Id: Ie4dc11f43ed1eae2d09feaf9cff17d6d16cf9987
Signed-off-by: Todd Kjos <tkjos@google.com>
Correct the parameters passed to GENMASK macro
for H8_ENTER_COND_MASK.
Change-Id: If9997c7fb18d28aacce58697666c1c36a56b9a68
Signed-off-by: Bao D. Nguyen <nguyenb@codeaurora.org>
Correct start_rx sequence to keep the dma buffers available
before starting rx engine.
This is needed to handle rx data which might come between
starting of rx engine and having dma buffer available.
Change-Id: I194890ba8f51d6a917d6b1682f6b21ca443ca38b
Signed-off-by: Prudhvi Yarlagadda <pyarlaga@codeaurora.org>
The inclusion of draw object flag for msm_perf_events_update.
Since user-space thread is triggered based on kgsl events
this will be vital to distinguish the events based on frame
states and prevent undesirable user-space thread wake-ups.
Change-Id: I28040808d6c114b718aad0e0ab63554683e77460
Signed-off-by: Aman Mehta <amanmeht@codeaurora.org>
Hyp uart is default disabled from ABL now. There is no need of
CONFIG_HH_DISABLE_UART option anymore. Hyp uart now can be controlled
using DEBUG_FS interface.
Change-Id: Ie1a0986399d30b89bf62468a23633994c8d6b11b
Signed-off-by: Murali Nalajala <mnalajal@codeaurora.org>
By default, the system firmware enables the mpm wakeup functionality
of all the supported GPIOs. However, certain usecases demand that
this capability be disabled on certain gpios. Hence, provide a
generic interface to disable the GPIOs as needed.
Change-Id: I3b051bf676a157410880a3c596b784212a927a36
Signed-off-by: Raghavendra Rao Ananta <rananta@codeaurora.org>
Hyp uart is disabled default today in ABL. Provide debugfs
interface to users when they want to enable hyp uart to
debug hypervisor and VM issues.
Change-Id: I5e2c0501ed309a65c9dff1304b2e88e0d58917ae
Signed-off-by: Murali Nalajala <mnalajal@codeaurora.org>
Snapshot of PCIe MHI device driver as of msm-4.14.
'commit <adeff59> (""drivers: clk: msm:
fix compilation for non DEBUG_FS build"")'.
Fix several warnings as part of propagation to 5.4.
Change-Id: I48b88d8e8900cb6e166c24ad2322a6fa2ec6fb8a
Signed-off-by: Siddartha Mohanadoss <smohanad@codeaurora.org>
Enabled ram dump collection for CMA memory
that is used for remote heap and dynamic loading memory.
Change-Id: I07fe071ee90b39204822aee368b52b7e63b5600d
Acked-by: Krishnaiah Tadakamalla <ktadakam@qti.qualcomm.com>
Signed-off-by: Jeya R <jeyr@codeaurora.org>
Signed-off-by: Vamsi krishna Gattupalli <vgattupa@codeaurora.org>
Commit 09854ba94c6a ("mm: do_wp_page() simplification") reorganized all
the code around the page re-use vs copy, but in the process also moved
the final unlock_page() around to after the wp_page_reuse() call.
That normally doesn't matter - but it means that the unlock_page() is
now done after releasing the page table lock. Again, not a big deal,
you'd think.
But it turns out that it's very wrong indeed, because once we've
released the page table lock, we've basically lost our only reference to
the page - the page tables - and it could now be free'd at any time. We
do hold the mmap_sem, so no actual unmap() can happen, but madvise can
come in and a MADV_DONTNEED will zap the page range - and free the page.
So now the page may be free'd just as we're unlocking it, which in turn
will usually trigger a "Bad page state" error in the freeing path. To
make matters more confusing, by the time the debug code prints out the
page state, the unlock has typically completed and everything looks fine
again.
This all doesn't happen in any normal situations, but it does trigger
with the dirtyc0w_child LTP test. And it seems to trigger much more
easily (but not expclusively) on s390 than elsewhere, probably because
s390 doesn't do the "batch pages up for freeing after the TLB flush"
that gives the unlock_page() more time to complete and makes the race
harder to hit.
Fixes: 09854ba94c6a ("mm: do_wp_page() simplification")
Link: https://lore.kernel.org/lkml/a46e9bbef2ed4e17778f5615e818526ef848d791.camel@redhat.com/
Link: https://lore.kernel.org/linux-mm/c41149a8-211e-390b-af1d-d5eee690fecb@linux.alibaba.com/
Reported-by: Qian Cai <cai@redhat.com>
Reported-by: Alex Shi <alex.shi@linux.alibaba.com>
Bisected-and-analyzed-by: Gerald Schaefer <gerald.schaefer@linux.ibm.com>
Tested-by: Gerald Schaefer <gerald.schaefer@linux.ibm.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Git-commit: be068f29034fb00530a053d18b8cf140c32b12b3
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
[zhenhuah@codeaurora.org: resolved conflict]
Change-Id: I775e3706aa5d6be6b8352e8f59cb10e8d9326c5c
Signed-off-by: Zhenhua Huang <zhenhuah@codeaurora.org>
With the more strict (but greatly simplified) page reuse logic in
do_wp_page(), we can safely go back to the world where cow is not
enforced with writes.
This essentially reverts commit 17839856fd58 ("gup: document and work
around 'COW can break either way' issue"). There are some context
differences due to some changes later on around it:
2170ecfa7688 ("drm/i915: convert get_user_pages() --> pin_user_pages()", 2020-06-03)
376a34efa4ee ("mm/gup: refactor and de-duplicate gup_fast() code", 2020-06-03)
Some lines moved back and forth with those, but this revert patch should
have striped out and covered all the enforced cow bits anyways.
Suggested-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Peter Xu <peterx@redhat.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Git-commit: a308c71bf1e6e19cc2e4ced31853ee0fc7cb439a
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
[zhenhuah@codeaurora.org: resolve trivial merge conflict]
Change-Id: I1e72c780c74b324efe6dbeed17ab131657254f16
Signed-off-by: Zhenhua Huang <zhenhuah@codeaurora.org>
When memory block is logically offlined, it is still part of System RAM but
is inactive, and can be made active or Onlined anytime.
Take totalram snapshot to include offlined memory in Memtotal.
This method avoids taking device_hotplug lock to meminfo.
Fixes: dc00b6d99a ("proc/meminfo: include offlined region for mem total")
Change-Id: I2b69444e6f066e1c1928278707616840308b00d0
Signed-off-by: Prakash Gupta <guptap@codeaurora.org>
With QCOM quirks, the invalidations are agrregated to reduce map/unmap
time. In absenence of CONFIG_QCOM_IOMMU_TLBI_QUIRKS enabled, the map/unmap
latency impact time critical usecases. Hence defer TLB invalidation when
CONFIG_QCOM_IOMMU_TLBI_QUIRKS is not enabled.
Change-Id: I866b4211901f71fe054bbd9f465b4df5c7dac82c
Signed-off-by: Prakash Gupta <guptap@codeaurora.org>
In ssr handling of remote subsystem down, all rpmsg devices are removed
for that edge. If at the same time ssr down is received for other remote
subsystem, it may try to notify already down remote and end up using
invalid rpmsg device which causes use after free.
Store device state in ssr context and update this with holding a lock.
SSR notification function should also use the same lock and perform
check for validity of rpmsg device.
CRs-Fixed: 2580433
Change-Id: I339e228a527f7b6a737944d8e9e53caa31992914
Signed-off-by: Deepak Kumar Singh <deesin@codeaurora.org>
During ssr rpmsg ssr device will unregister, which can result
in use of stale device pointer in ssr callback function.
Now incrementing refcount inside ssr callback function to
prevent release of rpmsg device.
CRs-Fixed: 2551255
Change-Id: If3fc57c4635378dc6fdcb7df120c83dca0e83758
Signed-off-by: Deepak Kumar Singh <deesin@codeaurora.org>
Allocation of memory to user_ctxt_record is done based on adreno_device
flag. If a context is created when preemption is disabled, the memory
to user_ctxt_record is not allocated. Now if we enable preemption,
through the sysfs knob, the device flag is again set. We may try to
access user_ctxt_record in preemption_pre_ibsubmit(). So allocate memory
to user_ctxt_record based on the preemption feature flag instead
of preemption device flag.
Change-Id: I947ef5a1bfbd8bff471427fae60d7fcd507b85a2
Signed-off-by: Puranam V G Tejaswi <pvgtejas@codeaurora.org>
Signed-off-by: Harshitha Sai Neelati <hsaine@codeaurora.org>
This change propagates the missing fixes in novatek tcm touch
driver from msm-4.19 to msm-5.4.
Change-Id: Ie404c8412f7efa847b8e14965bcaf45568225502
Signed-off-by: Ravikanth Tuniki <rtunik@codeaurora.org>
When merging configuration fragments, it might be of interest to
identify mismatches (redefinitions) programmatically. Hence add the
option -s (strict mode) to instruct merge_config.sh to bail out in
case any redefinition has been detected.
With strict mode, warnings are emitted as before, but the script
terminates with rc=1. If -y is set to define "builtin having
precedence over modules", fragments are still allowed to set =m (while
the base config has =y). Strict mode will tolerate that as demotions
from =y to =m are ignored when setting -y.
Bug: 174454795
Link: https://lore.kernel.org/linux-kbuild/20201202151238.3776616-1-maennich@google.com/
Cc: Masahiro Yamada <masahiroy@kernel.org>
Signed-off-by: Matthias Maennich <maennich@google.com>
Change-Id: Ib982a87811956e48b718a15680f06474a39dc19d
(cherry picked from commit 32164038495558fbc6d47f36033bac3014f53b8e)
Add the header file changes for socksv5
info passed from other modules.
Change-Id: I24c0bbb3344fd97d0468a78b9d5fa95f05fbe198
Signed-off-by: Armaan Siddiqui <asiddiqu@codeaurora.org>
Reject the session when third party applications
try to spawn signed PD and channel configured as secure.
Change-Id: Iab18ad364985372f8007b6dda933ef4e5adf0213
Acked-by: Nishant Chaubey <chaubey@qti.qualcomm.com>
Signed-off-by: Vamsi krishna Gattupalli <vgattupa@codeaurora.org>
Add scaling function required to read PMIC5 current ADC channels
so that channel 0xA5 (ADC5_PARALLEL_ISENSE) can use that.
Change-Id: I55ede0c736c6f350df8ac92ea8661db4129da13c
Signed-off-by: Jishnu Prakash <jprakash@codeaurora.org>