As Lasse pointed out, "EROFS uses LZ4_decompress_safe_partial
for both partial and full blocks. Thus when it is decoding a
full block, it doesn't know if the LZ4 decoder actually decoded
all the input. The real uncompressed size could be bigger than
the value stored in the file system metadata.
Using LZ4_decompress_safe instead of _safe_partial when
decompressing a full block would help to detect errors."
So it's reasonable to use _safe in case of potential corrupted
images and it might have some speed gain as well although
I didn't observe much difference.
Note that legacy compressor (< 5.3, no LZ4_0PADDING) could
encode extra data in a pcluster, which is excluded as well.
Cc: Lasse Collin <lasse.collin@tukaani.org>
Fixes: 0ffd71bcc3 ("staging: erofs: introduce LZ4 decompression inplace")
[ Gao Xiang: v5.3+, I will manually backport this to stable later. ]
Link: https://lore.kernel.org/r/20200226081008.86348-2-gaoxiang25@huawei.com
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Change-Id: Ic8f01ed11c94983fdd1c5b6252b8d15bc8d70c3f
Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
XArray has friendly APIs and it will replace the old radix
tree in the near future.
This convert makes use of __xa_cmpxchg when inserting on
a just inserted item by other thread. In detail, instead
of totally looking up again as what we did for the old
radix tree, it will try to legitimize the current in-tree
item in the XArray therefore more effective.
In addition, naming is rather a challenge for non-English
speaker like me. The basic idea of workstn is to provide
a runtime sparse array with items arranged in the physical
block number order. Such items (was called workgroup) can be
used to record compress clusters or for later new features.
However, both workgroup and workstn seem not good names from
whatever point of view, so I'd like to rename them as pslot
and managed_pslots to stand for physical slots. This patch
handles the second as a part of the radix tree convert.
Cc: Matthew Wilcox <willy@infradead.org>
Link: https://lore.kernel.org/r/20200220024642.91529-1-gaoxiang25@huawei.com
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Change-Id: I38011a74040ea8d7cfe9669c2736aae8ad2f92ab
Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
A label and extra variables will be eliminated,
which is more cleaner.
Link: https://lore.kernel.org/r/20200121064819.139469-1-gaoxiang25@huawei.com
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Change-Id: Ie2695bb8cb46b4e2aa4b979b7558b02c52079af9
Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
No need to introduce such separated helper since
cache strategy compile configs were changed into
runtime options instead in v5.4. No logic changes.
Link: https://lore.kernel.org/r/20200121064747.138987-1-gaoxiang25@huawei.com
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Change-Id: I2653ee9a7d8de2d84c36c7a7f736d79814b6f113
Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
Because workgroup pointers inserted to a radix tree are always tagged with
a single value of 0, it is possible to remove tagging and untagging of the
pointers completely.
Change-Id: I148904fa4ad13d0de593a5cf5b308638253da446
Signed-off-by: Vladimir Zapolskiy <vladimir@tuxera.com>
Link: https://lore.kernel.org/r/20200102120118.14979-4-vladimir@tuxera.com
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
All workgroups are registered with tag value set to 0, to simplify
erofs_register_workgroup() interface the tag argument can be removed,
if its only value is sent down to the function body.
Change-Id: I109b88af9f753f5dc0db8973e62a9056c36dc5ee
Signed-off-by: Vladimir Zapolskiy <vladimir@tuxera.com>
Link: https://lore.kernel.org/r/20200102120118.14979-3-vladimir@tuxera.com
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
It is feasible to simplify erofs_find_workgroup() interface by removing
an unused function argument. While formally the argument is used in the
function itself, its assigned value is ignored on the caller side.
Change-Id: I9b10d39aef877d42ddbd3f864afbe05b273d258c
Signed-off-by: Vladimir Zapolskiy <vladimir@tuxera.com>
Link: https://lore.kernel.org/r/20200102120118.14979-2-vladimir@tuxera.com
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
VLE was an old informal name of fixed-sized output
compression which came from published ATC'19 paper [1].
Drop those old annotations since erofs can handle
all encoded clusters in block-aligned basis, which
is wider than fixed-sized output compression after
larger clustersize feature is fully implemented.
Unaligned encoding won't be considered in EROFS
since it's not friendly to inplace I/O and perhaps
decompression inplace.
a) Fixed-sized output compression with 16KB pcluster:
___________________________________
|xxxxxxxx|xxxxxxxx|xxxxxxxx|xxxxxxxx|
|___ 0___|___ 1___|___ 2___|___ 3___| physical blocks
b) Block-aligned fixed-sized input compression with
16KB pcluster:
___________________________________
|xxxxxxxx|xxxxxxxx|xxxxxxxx|xxx00000|
|___ 0___|___ 1___|___ 2___|___ 3___| physical blocks
c) Block-unaligned fixed-sized input compression with
16KB compression unit:
____________________________________________
|..xxxxxx|xxxxxxxx|xxxxxxxx|xxxxxxxx|x.......|
|___ 0___|___ 1___|___ 2___|___ 3___|___ 4___| physical blocks
Refine better names for those as well.
[1] https://www.usenix.org/conference/atc19/presentation/gao
Link: https://lore.kernel.org/r/20191108033733.63919-1-gaoxiang25@huawei.com
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Change-Id: I398224bf5a0690ed0d388bdf32bf9c77dc720d3e
Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
Introduce superblock checksum feature in order to
check at mounting time.
Note that the first 1024 bytes are ignore for x86
boot sectors and other oddities.
Link: https://lore.kernel.org/r/20191104024937.113939-1-gaoxiang25@huawei.com
Change-Id: Ibd3a0d0ec04edd990f54da1d1ed5d1228534a5dd
Signed-off-by: Pratik Shinde <pratikshinde320@gmail.com>
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Cc: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
For those tasks waiting I/O for sync decompression,
they should be better marked as IO wait state.
Link: https://lore.kernel.org/r/20191008125616.183715-5-gaoxiang25@huawei.com
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Change-Id: I6922f7e3201b5d69642167c882f5580fb4d11a03
Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
Previously, both z_erofs_unzip_io and z_erofs_unzip_io_sb
record decompress queues for backend to use.
The only difference is that z_erofs_unzip_io is used for
on-stack sync decompression so that it doesn't have a super
block field (since the caller can pass it in its context),
but it increases complexity with only a pointer saving.
Rename z_erofs_unzip_io to z_erofs_decompressqueue with
a fixed super_block member and kill the other entirely,
and it can fallback to sync decompression if memory
allocation failure.
Link: https://lore.kernel.org/r/20191008125616.183715-4-gaoxiang25@huawei.com
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Change-Id: I7cbe96d40baaa224984c9f959f89af742a203abc
Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
Now open code is much cleaner due to iterative development.
Link: https://lore.kernel.org/r/20191124025217.12345-1-hsiangkao@aol.com
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Change-Id: I450d0405c8a6f747c9b32a6d97631452ba7b9ee4
Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
After commit 4279f3f988 ("staging: erofs: turn cache
strategies into mount options"), cache strategies are
changed into mount options rather than old build configs.
Let's kill useless code for obsoleted build options.
Link: https://lore.kernel.org/r/20191008125616.183715-2-gaoxiang25@huawei.com
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Change-Id: I62652b33f227a8ddbd6e51750f5fb5493940fd0a
Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
- change return value to int since collection is
already returned within the collector.
- better function naming.
Link: https://lore.kernel.org/r/20191008125616.183715-1-gaoxiang25@huawei.com
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Change-Id: Ic3ef48384778efc6fb04acf041b918dbc16acd72
Signed-off-by: Gao Xiang <gaoxiang25@huawei.com>
This patch replaces all memcpy() calls with LZ4_memcpy() which calls
__builtin_memcpy() so the compiler can inline it.
LZ4 relies heavily on memcpy() with a constant size being inlined. In x86
and i386 pre-boot environments memcpy() cannot be inlined because memcpy()
doesn't get defined as __builtin_memcpy().
An equivalent patch has been applied upstream so that the next import
won't lose this change [1].
I've measured the kernel decompression speed using QEMU before and after
this patch for the x86_64 and i386 architectures. The speed-up is about
10x as shown below.
Code Arch Kernel Size Time Speed
v5.8 x86_64 11504832 B 148 ms 79 MB/s
patch x86_64 11503872 B 13 ms 885 MB/s
v5.8 i386 9621216 B 91 ms 106 MB/s
patch i386 9620224 B 10 ms 962 MB/s
I also measured the time to decompress the initramfs on x86_64, i386, and
arm. All three show the same decompression speed before and after, as
expected.
[1] https://github.com/lz4/lz4/pull/890
Signed-off-by: Nick Terrell <terrelln@fb.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Cc: Yann Collet <yann.collet.73@gmail.com>
Cc: Gao Xiang <gaoxiang25@huawei.com>
Cc: Sven Schmidt <4sschmid@informatik.uni-hamburg.de>
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: Ingo Molnar <mingo@kernel.org>
Cc: Arvind Sankar <nivedita@alum.mit.edu>
Link: http://lkml.kernel.org/r/20200803194022.2966806-1-nickrterrell@gmail.com
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Change-Id: I3e725b70595227145a8c8b42a6626cb0629fdddf
* 'for-kernel-version-from-4.1.0' of https://github.com/namjaejeon/linux-exfat-oot:
exfat: github action: run buiuld and tests on for-kernel-version-from-4.1.0 branch
exfat: fix ALIGN_DOWN undefined error
exfat: using ffs instead of internal logic
exfat: using hweight instead of internal logic
exfat: fix ctime is not updated
exfat: fix setting uninitialized time to ctime/atime
exfat: convert to new timestamp accessors
exfat: convert to ctime accessor functions
exfat: fs: pass the request_mask to generic_fillattr
exfat: convert to simple_rename_timestamp
exfat: ensure that ctime is updated whenever the mtime is
exfat: fs: add CONFIG_BUFFER_HEAD
exfat: use fat ioctls definitions from include/uapi/linux/msdos_fs.h
exfat: github action: remove liunx-4.1 source to get more disk space
exfat: support create zero-size directory
exfat: support handle zero-size directory
exfat: add ioctls for accessing attributes
exfat: vfs: get rid of old '->iterate' directory operation
Change-Id: I7e8add708697faf95952cacdb24bf5f504190fe4
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"
* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/dataipa:
msm: ipa3: reduce rx-wan pool and cmn page, temp pool sizes
msm: ipa: allocate page recycling buffers only once
msm: ipa: avoid OOM Killer for temp allocations
msm: ipa3: Flush free page WQ only for page recyle replenish handler
msm: ipa3: Fix to flush to workqueue during teardown pipe
msm: ipa3: Fix to destory workqueue only if created
msm: ipa3: Changes to enhance find free pages from list
msm: ipa: page pool recycling enhancements
msm: ipa: page pool recycling enhancements
Change-Id: I21c0f5974f08fc032605d2710858eb28e592d1f0
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"
* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/camera-kernel:
msm: camera: sensor: Proper handling of race condition in util api
msm: camera: sensor: Proper handling of race condition in util api
msm: camera: memmgr: Add missing calls of put buf to avoid leak
Change-Id: I0aff5a21e16f44c2e13ed99b463f326eb57b1653
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"
* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0:
Release 2.0.8.34M
qcacld-3.0: Add a sanity check to prevent integer overflow
Release 2.0.8.34L
qcacld-3.0: Fix possible spinlock acquire after destroy
Release 2.0.8.34K
qcacld-3.0: Find 6 GHz power type for connection channel
qcacld-3.0: Find best 6 GHz power type for connection
Release 2.0.8.34J
qcacld-3.0: Add vendor attribute for high RSSI roam trigger threshold
Change-Id: I740cd45f715d6609b53b19a9d42b0bf9df8983bc
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"
* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qca-wifi-host-cmn:
qcacmn: Fix out of bound read issue in ESP ie parse
qcacmn: Update no. of DWORDs for htt_tx_msdu_desc_ext2_t
qcacmn: Change minimum mbssid ie length value to 1
qcacmn: Find 6 GHz power type for connection channel
qcacmn: Add an API to translate the 6 GHz channel enum
qcacmn: Find best 6 GHz power type for connection
qcacmn: Support 5 GHz high RSSI roam
qcacmn: Define QCA vendor attribute for high RSSI roam trigger threshold
Change-Id: Ie73b137390339317e5f3f4a72577b04d34c2f0c2
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"
* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4:
bus: mhi: Fix potential out-of-bound access
rpmsg: slatecom: maintain rx_size to read
rpmsg: slatecom: out of bound read from process_cmd
soc: qcom: add out of bound check for AON fifo
soc: qcom: smem: Add boundary checks for partitions
msm: kgsl: Do not release dma and anon buffers if unmap fails
msm: kgsl: Do not release dma and anon buffers if unmap fails
memshare: Prevent possible integer overflow
msm: kgsl: Keep the timeline fence valid for logging
msm: ipa: Add support for Private IP Forwarding
msm: ipa3: add support to identify wifi attach
soc: qcom: minidump_log: Protect md_dump_slabinfo under SLUB_DEBUG
mm: slub: Declare slab_owner_ops only when SLUB DEBUG is enabled
soc: qcom: Add BLAIR-LITE SoC information to socinfo
soc: qcom: socinfo: Add soc information for BLAIR LTE
msm_serial_hs: Fix race between mod_timer and del_timer calls
Change-Id: I5ab9a7732af0be4754b506f2c815ab29b236fb91
https://source.android.com/docs/security/bulletin/2024-03-01
* tag 'ASB-2024-03-05_11-5.4' of https://android.googlesource.com/kernel/common:
ANDROID: GKI: Update symbol list for Zebra
UPSTREAM: usb: raw-gadget: properly handle interrupted requests
UPSTREAM: net: prevent skb corruption on frag list segmentation
UPSTREAM: netfilter: nft_set_rbtree: skip end interval element from gc
UPSTREAM: net: tls, update curr on splice as well
Change-Id: I7a6117e861e8c35bb66bcc3a9a21cc6db49946b2
In mhi_sat_isvalid_header function if the length is less than
the size of header then there can be out-of-bound access.
So fix the len check in the function.
Change-Id: I80f1556557b1bf2f30c07f6377bd6e3db48712b3
Signed-off-by: Krishna chaitanya chundru <quic_krichai@quicinc.com>
(cherry picked from commit d7601393dc)
For cmd close_ack or open request where rx_size is being
incrementing with respect to offset might lead to out of
bound read from rx_data.
Decrease rx_size as we process commands.
Change-Id: I492eadcbebb78386fc20f744eb9ad8db4a2914fc
Signed-off-by: Kaushal Hooda <quic_khooda@quicinc.com>
(cherry picked from commit ab0f86134f)
When dereferencing "rx_data" as type "glink_slatecom_msg" ,
we didn't check if "rx_data" has enough room to hold that type.
The "rx_size" is read from slate to master fifo and if received
rx_size is less then "glink_slatecom_msg" then it could lead to
heap out of bounds read.
If received rx_size is less then the expected glink_slatecom_msg
then return back as a bad message.
Change-Id: Idde757ee70c7c88c22e4f036e6da0280e3b385d0
Signed-off-by: Kaushal Hooda <quic_khooda@quicinc.com>
(cherry picked from commit 7ddb61a6ac)
Add out of bound check while parsing the SPI
slave-to-master fifo.
Change-Id: I14f707307fa277b2f8a7b543d3cc5e9ebac885db
Signed-off-by: Ajit Kumar <quic_kajit@quicinc.com>
(cherry picked from commit 0950011ce6)
While parsing ESP IE from beacon/probe response frame,
the condition in loop to copy ESP_INFO from the ESP IE is
incorrect which will iterate for 5 times rather than 4 times,
this may cause OOB access.
data < ((uint8_t *)esp_ie + esp_ie->esp_len + 3)
Here adding 3 for esp_ie->esp_len, actually esp_len itself is
1 byte extra (esp_ len = ESP_ID_EXTN + ESP_INFO * 4),
but by adding 3 again will loop for one more iteration
this will cause OOB access.
Remove 3 in loop condition to avoid one more extra iteration
and ignore ESP_ID_EXTN element for total elements, in function
util_scan_update_esp_data.
Change-Id: Ia9226e483672369af36c6914e3ac914fe9de45e5
CRs-Fixed: 3710081
(cherry picked from commit 799a747940)
Currently, if a USB request that was queued by Raw Gadget is interrupted
(via a signal), wait_for_completion_interruptible returns -ERESTARTSYS.
Raw Gadget then attempts to propagate this value to userspace as a return
value from its ioctls. However, when -ERESTARTSYS is returned by a syscall
handler, the kernel internally restarts the syscall.
This doesn't allow userspace applications to interrupt requests queued by
Raw Gadget (which is required when the emulated device is asked to switch
altsettings). It also violates the implied interface of Raw Gadget that a
single ioctl must only queue a single USB request.
Instead, make Raw Gadget do what GadgetFS does: check whether the request
was interrupted (dequeued with status == -ECONNRESET) and report -EINTR to
userspace.
Bug: 254441685
Fixes: f2c2e717642c ("usb: gadget: add raw-gadget interface")
Cc: stable <stable@kernel.org>
Signed-off-by: Andrey Konovalov <andreyknvl@gmail.com>
Link: https://lore.kernel.org/r/0db45b1d7cc466e3d4d1ab353f61d63c977fbbc5.1698350424.git.andreyknvl@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit e8033bde451eddfb9b1bbd6e2d848c1b5c277222)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I1509b30c9962d6e695b268c183e41bdd551f1780
commit 60c0c230c6f046da536d3df8b39a20b9a9fd6af0 upstream.
rbtree lazy gc on insert might collect an end interval element that has
been just added in this transactions, skip end interval elements that
are not yet active.
Bug: 325477234
Fixes: f718863aca46 ("netfilter: nft_set_rbtree: fix overlap expiration walk")
Cc: stable@vger.kernel.org
Reported-by: lonial con <kongln9170@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 10e9cb3931)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I42f7bca418d47948292b15ace9f371b81ccd7fe8
Add condition check to make sure that the end address
of private entry does not go out of partition.
Change-Id: I88b3c69d86d90905b214c13a8c632b134b487a49
Signed-off-by: Sarannya S <quic_sarannya@quicinc.com>
Signed-off-by: Pranav Mahesh Phansalkar <quic_pphansal@quicinc.com>
Power count is coming from user space which can be modified due to
access to shared memory. This change scopes the data locally so
as to avoid vulnerability of count being modified by external
means while executing due to being in shared memory.
CRs-Fixed: 3691744.
Change-Id: I57d13435453195f8aab0c9aad4414d290274ff81
Signed-off-by: Shivi Mangal <quic_smangal@quicinc.com>
(cherry picked from commit c9cd58783e)
If iommu unmap fails and leaves dma or anon buffers still mapped in the
iommu, do not free them.
Change-Id: Ice0e1a59c1ac0ee7a9d62d8899966b84fa63d5ca
Signed-off-by: Lynus Vaz <quic_lvaz@quicinc.com>
Signed-off-by: Deepak Kumar <quic_dkumar@quicinc.com>
(cherry picked from commit e7c4bb239b)