Commit graph

916,302 commits

Author SHA1 Message Date
mahj8
667b71ea21 usb: pd: Add PDO Selection
The PDO selection should be done by either the Kernel or User Space.
Setup a callback that selects the PDO based on what the Voltage Max
is set to when the function is called.

refer to https://gerrit.mot.com/1403781
Based on Gerrit https://gerrit.mot.com/#/c/1301690/

Change-Id: I54a14b47e79637c681cc24c78a75a1206ecd903e
Signed-off-by: mahj8 <mahj8@lenovo.com>
Reviewed-on: https://gerrit.mot.com/1770248
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Tested-by: Jira Key
Reviewed-by: Huosheng Liao <liaohs@motorola.com>
Submit-Approved: Jira Key
2024-04-18 14:44:55 +08:00
mahj8
a0ecbc9a1b power: supply/qcom: smb5-lib: Select PDO
The charger driver should directly call into the policy
engine and select the proper PDO.  Otherwise the first PDO
is selected.

refer to https://gerrit.mot.com/1403773
Based on Gerrit https://gerrit.mot.com/#/c/1301691/

Change-Id: I73a2ef923393977e202aebc142d09c4301de4fbe
Signed-off-by: mahj8 <mahj8@lenovo.com>
Reviewed-on: https://gerrit.mot.com/1770246
SLTApproved: Slta Waiver
SME-Granted: SME Approvals Granted
Tested-by: Jira Key
Reviewed-by: Huosheng Liao <liaohs@motorola.com>
Submit-Approved: Jira Key
2024-04-18 14:44:55 +08:00
Kenny Kessler
0637aeab60 power: pmic-voter: Export Interfaces
Export some pmic-voter interfaces for dlkm usage as well
as create access functions that are exported for dlkm to
manipulate the struct.

Change-Id: I306c65c9890bd69dc49fcd722ac0981ddb908dc6
Signed-off-by: Kenny Kessler <kenny.kessler@motorola.com>
Reviewed-on: https://gerrit.mot.com/1200744
SLTApproved: Slta Waiver
SME-Granted: SME Approvals Granted
Tested-by: Jira Key
Reviewed-by: Ryan Lattrel <ryanl@motorola.com>
Reviewed-by: Ling Jin <lingjin@motorola.com>
Reviewed-by: Kenneth Kessler <kennykessler@motorola.com>
Submit-Approved: Jira Key
Reviewed-on: https://gerrit.mot.com/1770243
Reviewed-by: Huosheng Liao <liaohs@motorola.com>
2024-04-18 14:44:55 +08:00
jixj
c5cf78e9ba enable ibiza dts
- add IBIZA_DT for ibiza
- enable CONFIG_IBIZA_DTB

Change-Id: I93c2db316131c85195731016116fe0df66fc5695
Reviewed-on: https://gerrit.mot.com/1771104
SLTApproved: Slta Waiver
SME-Granted: SME Approvals Granted
Tested-by: Jira Key
Reviewed-by: Huosheng Liao <liaohs@motorola.com>
Submit-Approved: Jira Key
2024-04-18 14:44:55 +08:00
weimh1
d4fb0ad41c kernel/config: add product specific config files
1.add debug-holi-ibiza.config for product debug config
  2.add moto-holi-ibiza.config for product specific config
  3.add factory-holi-ibiza.config for product factory config

Change-Id: I6b6eb65e9e19ed455447e609987438cd6b554b0c
Signed-off-by: weimh1 <weimh1@lenovo.com>
Reviewed-on: https://gerrit.mot.com/1771042
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Tested-by: Jira Key
Reviewed-by: Hujun Liao <liaohj@motorola.com>
Submit-Approved: Jira Key
2024-04-18 14:44:55 +08:00
jixj
ddf492709b arm64/confgs: Enable denver dts
Enable CONFIG_DENVER_DTB to only build denver dts,
reduce the dtb image size.

Change-Id: I512ec05ae8e45b14d26a3bc9dde91ce84e5c72cc
Reviewed-on: https://gerrit.mot.com/1770156
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Tested-by: Jira Key
Reviewed-by: Huosheng Liao <liaohs@motorola.com>
Submit-Approved: Jira Key
2024-04-18 14:44:55 +08:00
weimh1
dee1ae4006 kernel/config: merge moto fragment configs
Kernel configs compose of several parts.These parts will be merged into
	one final file such as "holi-qgki-debug_defconfig".
    The rule of Moto-product-config files from high order is:
      product debug config
      platform debug config,
      product config
      platform config

    Here is an example of product "denver" based on 4350
    platform (holi):

    1. factory build config list with order:
    factory-holi-denver.config
    factory-holi.config
    moto-holi-denver.config
    moto-holi.config

    2. userdebug build config list with order:
    debug-holi-denver.config
    debug-holi.config
    moto-holi-denver.config
    moto-holi.config

    3. user version config list with order:
    moto-holi-denver.config
    moto-holi.config

Change-Id: Ie7512300581337ae6768bdfa618613a797f3c10f
Signed-off-by: weimh1 <weimh1@lenovo.com>
Reviewed-on: https://gerrit.mot.com/1769363
SLTApproved: Slta Waiver
SME-Granted: SME Approvals Granted
Tested-by: Jira Key
Reviewed-by: Huosheng Liao <liaohs@motorola.com>
Submit-Approved: Jira Key
2024-04-18 14:44:55 +08:00
jixj
0f89da7576 soc: qcom: kconfig opt to build denver dtbs
Introduce a new configuration DENVER_DTB that will allow the
target to only build denver devices.

Change-Id: I766404bb7792c217d37eecd3a543d866fc018fae
Reviewed-on: https://gerrit.mot.com/1762925
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Submit-Approved: Jira Key
Tested-by: Jira Key
Reviewed-by: Huosheng Liao <liaohs@motorola.com>
2024-04-18 14:44:54 +08:00
jixj
d3e7540280 soc: qcom: kconfig opt to build moto dtbs
Introduce a new configuration MMI_DEVICE_DTBS that will allow the
target to only build Motorola devices.

Change-Id: I8eb2d1586dd2d99c696a3e198e5809a12cab6ad9
Reviewed-on: https://gerrit.mot.com/1762924
SLTApproved: Slta Waiver
SME-Granted: SME Approvals Granted
Submit-Approved: Jira Key
Tested-by: Jira Key
Reviewed-by: Huosheng Liao <liaohs@motorola.com>
2024-04-18 14:44:54 +08:00
Bang Nguyen
4e61dd033c Add new macro MIPI_DSI_MSG_READ
Add a new macro MIPI_DSI_MSG_READ (bit 4) in drm_mipi_dsi.h for
MIPI DSI READ Message

Change-Id: I8d6ed4aa10b915f7ff74339c8bdabe061c09ecd5
Signed-off-by: Bang Nguyen <bangnguyen@motorola.com>
Reviewed-on: https://gerrit.mot.com/1697680
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Tested-by: Jira Key
Reviewed-by: Shuo Yan <shuoyan@motorola.com>
Reviewed-by: Guobin Zhang <zhanggb@motorola.com>
Submit-Approved: Jira Key
2024-04-18 14:44:54 +08:00
litong
2e75049063 workaround for the error of "__symbol_put " undefined
ERROR: "__symbol_put" [../../motorola/kernel/modules/drivers/input/
	touchscreen/touchscreen_mmi/touchscreen_mmi.ko] undefined!
ERROR: "__symbol_get" [../../motorola/kernel/modules/drivers/input/
	touchscreen/touchscreen_mmi/touchscreen_mmi.ko] undefined!

Change-Id: I5ae7f9e395c61a1cd7f4b7ee7e914880ad767448
Reviewed-on: https://gerrit.mot.com/1745785
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Submit-Approved: Jira Key
Tested-by: Jira Key
Reviewed-by: Zhenxin Xi <xizx@motorola.com>
Reviewed-on: https://gerrit.mot.com/1755124
Reviewed-by: Lianlu Chen <chenll4@lenovo.com>
2024-04-18 14:44:54 +08:00
Sudheer Papothi
1188d4ea63 ASoC: msm: qdsp6v2: Handles additional flac metadata
Currently, metadata such as min/max block size is sent only for first
stream in FLAC gapless playback. This causes incorrect configuration
and, subsequently, framedrops in decoding of second stream and onwards
by sending these additional flac metadata, dsp receives stream-wise
metadata and decodes without dropping

Change-Id: Ibd4a9b24180622422ed719b075fd47bcd4ad0c9b
Signed-off-by: Amit Shekhar <ashekhar@codeaurora.org>
Signed-off-by: Banajit Goswami <bgoswami@codeaurora.org>
Signed-off-by: Sudheer Papothi <spapothi@codeaurora.org>
Signed-off-by: Meng Wang <mwang@codeaurora.org>
(cherry picked from commit feb23f7f5d63d7b890ba481d0b466b6e9a5eed15)
Reviewed-on: https://gerrit.mot.com/1752137
SLTApproved: Slta Waiver
SME-Granted: SME Approvals Granted
Submit-Approved: Jira Key
Tested-by: Jira Key
Reviewed-by: Lianlu Chen <chenll4@lenovo.com>
2024-04-18 14:44:54 +08:00
yangqh5
b9ebcb8b43 Init denver kernel config
Change-Id: I72e78a9919b7f42b3b7f7624e7e40e25255b669e
Reviewed-on: https://gerrit.mot.com/1752050
SLTApproved: Slta Waiver
SME-Granted: SME Approvals Granted
Submit-Approved: Jira Key
Tested-by: Jira Key
Reviewed-by: Lianlu Chen <chenll4@lenovo.com>
2024-04-18 14:44:54 +08:00
huangzq2
94d568a93d Revert "mm: fix unexpected zeroed page mapping with zram swap"
This reverts commit f098f8b982.

Change-Id: I02afb5f962700b250c870eaf347ec425ea72e514
2024-04-18 14:44:54 +08:00
Linux Build Service Account
eb52301813 Merge 920dbdcff7 on remote branch
Change-Id: I2a9ae48f966a5cc28de8aa25ec173763a3a876b4
2024-03-08 19:08:39 -08:00
Vivek Kumar
920dbdcff7 defconfig: arm64: Disable trimming non-whitelisted symbols
Disable trimming of non-whitelisted symbols for all defconfigs.

Change-Id: I11f8c5a2835b79cad31ff36e04f618f22c22e84b
Signed-off-by: Vivek Kumar <quic_vivekuma@quicinc.com>
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2024-03-05 13:38:03 +05:30
qctecmdr
89f4076c51 Merge "soc: qcom: add out of bound check for AON fifo" 2024-03-04 12:13:25 -08:00
qctecmdr
5028cb01e9 Merge "rpmsg: slatecom: maintain rx_size to read" 2024-03-04 09:00:19 -08:00
qctecmdr
89ebcc83ba Merge "bus: mhi: Fix potential out-of-bound access" 2024-03-04 02:03:00 -08:00
Ajit Kumar
0950011ce6 soc: qcom: add out of bound check for AON fifo
Add out of bound check while parsing the SPI
slave-to-master fifo.

Change-Id: I14f707307fa277b2f8a7b543d3cc5e9ebac885db
Signed-off-by: Ajit Kumar <quic_kajit@quicinc.com>
2024-03-04 01:58:55 -08:00
Kaushal Hooda
ab0f86134f rpmsg: slatecom: maintain rx_size to read
For cmd close_ack or open request where rx_size is being
incrementing with respect to offset might lead to out of
bound read from rx_data.

Decrease rx_size as we process commands.

Change-Id: I492eadcbebb78386fc20f744eb9ad8db4a2914fc
Signed-off-by: Kaushal Hooda <quic_khooda@quicinc.com>
2024-03-04 01:13:25 -08:00
Linux Build Service Account
99691fcf0f Merge "msm: kgsl: Do not release dma and anon buffers if unmap fails" into kernel.lnx.5.4.r3-rel 2024-02-27 16:47:52 -08:00
Lynus Vaz
267c47fd45 msm: kgsl: Do not release dma and anon buffers if unmap fails
If iommu unmap fails and leaves dma or anon buffers still mapped in the
iommu, do not free them.

Change-Id: Ice0e1a59c1ac0ee7a9d62d8899966b84fa63d5ca
Signed-off-by: Lynus Vaz <quic_lvaz@quicinc.com>
Signed-off-by: Deepak Kumar <quic_dkumar@quicinc.com>
(cherry picked from commit e7c4bb239b)
2024-02-26 22:31:47 -08:00
Sarannya S
9d501ea882 soc: qcom: smem: Add boundary checks for partitions
Add condition check to make sure that the end address
of private entry does not go out of partition.

Change-Id: I88b3c69d86d90905b214c13a8c632b134b487a49
Signed-off-by: Sarannya S <quic_sarannya@quicinc.com>
Signed-off-by: Pranav Mahesh Phansalkar <quic_pphansal@quicinc.com>
(cherry picked from commit 58e401790a)
2024-02-26 22:31:17 -08:00
Sarannya S
58e401790a soc: qcom: smem: Add boundary checks for partitions
Add condition check to make sure that the end address
of private entry does not go out of partition.

Change-Id: I88b3c69d86d90905b214c13a8c632b134b487a49
Signed-off-by: Sarannya S <quic_sarannya@quicinc.com>
Signed-off-by: Pranav Mahesh Phansalkar <quic_pphansal@quicinc.com>
2024-02-20 14:31:26 +05:30
Linux Build Service Account
926d1a7b7f Merge 301c6b0cba on remote branch
Change-Id: I20154d13474efe83afb9bf5324fa428f122942b1
2024-02-18 01:46:45 -08:00
qctecmdr
2cf7f335fc Merge "msm: kgsl: Do not release dma and anon buffers if unmap fails" 2024-02-13 10:14:25 -08:00
Lynus Vaz
e7c4bb239b msm: kgsl: Do not release dma and anon buffers if unmap fails
If iommu unmap fails and leaves dma or anon buffers still mapped in the
iommu, do not free them.

Change-Id: Ice0e1a59c1ac0ee7a9d62d8899966b84fa63d5ca
Signed-off-by: Lynus Vaz <quic_lvaz@quicinc.com>
Signed-off-by: Deepak Kumar <quic_dkumar@quicinc.com>
2024-02-13 15:05:15 +05:30
Manoj Prabhu B
f555e9e4ad memshare: Prevent possible integer overflow
Prevent possible integer overflow by sanitizing the alloc request
size coming from the client against allottable amount of memory.

Change-Id: I74cb0f7b0808f20299586969fd5c810d44c3e576
Signed-off-by: Manoj Prabhu B <quic_bmanoj@quicinc.com>
Signed-off-by: Madhab Sharma <quic_madhshar@quicinc.com>
2024-02-09 14:52:41 +05:30
qctecmdr
301c6b0cba Merge "Merge android11-5.4.259+ (70db018) into msm-5.4" 2024-02-05 00:10:49 -08:00
qctecmdr
995eaab1e4 Merge "msm: kgsl: Keep the timeline fence valid for logging" 2024-01-31 21:04:15 -08:00
qctecmdr
1e787ce267 Merge "msm: ipa: Add support for Private IP Forwarding" 2024-01-31 12:02:50 -08:00
Lynus Vaz
c2eae40b63 msm: kgsl: Keep the timeline fence valid for logging
The timeline fence needs to remain valid for logging purposes. Take an
extra refcount on the timeline dma_fence to make sure it doesn't go
away till we're done with it.

Change-Id: I6670ef7add099a72684c1fe20ed009dff85d1f27
Signed-off-by: Lynus Vaz <quic_lvaz@quicinc.com>
Signed-off-by: Deepak Kumar <quic_dkumar@quicinc.com>
2024-01-31 20:24:16 +05:30
Krishna Nagaraja
fd3f99504d msm: ipa: Add support for Private IP Forwarding
Changes for new uCP commands, and IOCTL to support this feature

Change-Id: Idd7de3f18fc557b54b3c2d965802065b3f6dd982
Signed-off-by: Krishna Nagaraja <quic_krisnag@quicinc.com>
2024-01-31 15:08:32 +05:30
kamasali Satyanarayan
079b43b825 Merge android11-5.4.259+ (70db018) into msm-5.4
* remotes/origin/tmp-70db018:
  UPSTREAM: ipv4: igmp: fix refcnt uaf issue when receiving igmp query packet
  ANDROID: Snapshot Mainline's version of checkpatch.pl
  UPSTREAM: nvmet-tcp: Fix a possible UAF in queue intialization setup
  UPSTREAM: nvmet-tcp: move send/recv error handling in the send/recv methods instead of call-sites

Conflicts:
	scripts/checkpatch.pl

Change-Id: I28aaacd0fb6478ade935672027760efce65a7911
Signed-off-by: kamasali Satyanarayan <quic_kamasali@quicinc.com>
2024-01-31 01:01:26 -08:00
Linux Build Service Account
08a359c69f Merge c7fecf0481 on remote branch
Change-Id: I82c23d4259365c57552bc9f98ef4398b0a80eb36
2024-01-30 21:09:31 -08:00
Fakruddin Vohra
fc5843f99a msm: ipa3: add support to identify wifi attach
add change to identify the wifi attach as communicated
by wlan at wdi init.

Change-Id: Iea73ce1037bdbe1064570173c0792f0fe139ac4f
Signed-off-by: Fakruddin Vohra <quic_fakruddi@quicinc.com>
2024-01-29 21:12:46 -08:00
qctecmdr
bcb96a65a1 Merge "msm_serial_hs: Fix race between mod_timer and del_timer calls" 2024-01-29 06:10:16 -08:00
qctecmdr
4bf33cb3ab Merge "soc: qcom: minidump_log: Protect md_dump_slabinfo under SLUB_DEBUG" 2024-01-21 20:36:18 -08:00
qctecmdr
4d067a9dad Merge "mm: slub: Declare slab_owner_ops only when SLUB DEBUG is enabled" 2024-01-21 20:36:17 -08:00
Rohit Agarwal
ae146b9a20 soc: qcom: minidump_log: Protect md_dump_slabinfo under SLUB_DEBUG
Protect md_dump_slabinfo call only if SLUB_DEBUG is enabled.

Change-Id: I1f703e039517dd24fad303f830a6a30a3f32c3f7
Signed-off-by: Rohit Agarwal <quic_rohiagar@quicinc.com>
2024-01-19 14:06:33 +05:30
Rohit Agarwal
40d396eb36 mm: slub: Declare slab_owner_ops only when SLUB DEBUG is enabled
Declare the ops struct and corresponding callbacks only when
SLUB_DEBUG is enabled.
Currently, the ops is defined only under
MINIDUMP_PANIC_DUMP config but the variables it uses are protected
under SLUB_DEBUG as well.

Change-Id: I11f29564e1d65edc506a50e2c12aac374dbca6d5
Signed-off-by: Rohit Agarwal <quic_rohiagar@quicinc.com>
2024-01-18 01:32:07 -08:00
Saranya R
c7fecf0481 soc: qcom: Add BLAIR-LITE SoC information to socinfo
Add BLAIR-LITE SoC information to socinfo.

Change-Id: I334a80508434ea3aaa972ecb0e2b72586e81dfca
Signed-off-by: Saranya R <quic_sarar@quicinc.com>
2024-01-10 17:38:02 +05:30
Swetha Chikkaboraiah
40d06eb6f1 soc: qcom: socinfo: Add soc information for BLAIR LTE
Add SOC ID to support socinfo for BLAIR LTE platform.

Change-Id: I5223272ef20eac2396e52fa910628ec8236eb1ed
Signed-off-by: Swetha Chikkaboraiah <quic_schikk@quicinc.com>
2024-01-08 06:36:36 -08:00
qctecmdr
bd73268ecf Merge "qcom-dload-mode: Convert reboot notifier to restart notifier" 2024-01-04 03:54:14 -08:00
Mukesh Ojha
52c3eb6f12 qcom-dload-mode: Convert reboot notifier to restart notifier
There could be chance of edl download mode written by qcom-dload-mode
driver overwritten by Scm device shutdown call as the reboot notifiers
gets called prior to device_shutdown in reboot path.

To fix this convert the reboot notifiers to restart notifiers and keep
its priority higher than scm restart handler so that warm reboot_mode
set here should be seen by SCM restart handler (priority 130).

Change-Id: I2daa41d04788e525f274323e9c815bf10cb79ed2
Signed-off-by: Mukesh Ojha <quic_mojha@quicinc.com>
Signed-off-by: Rohit Agarwal <quic_rohiagar@quicinc.com>
2024-01-03 15:44:34 +05:30
qctecmdr
f758f24d4d Merge "net: qrtr: smd: kfree svc_arr after use" 2023-12-26 03:12:21 -08:00
Marco Zhang
04c0665b7a Merge commit 'b67a45b62a' into HEAD
Change-Id: I9dc77c149470a0d2dd45ac092eae602f5625f1f3
2023-12-26 14:22:54 +08:00
qctecmdr
b67a45b62a Merge "defconfig: sdxlemur: Enable minidump for sdxlemur" 2023-12-22 10:22:13 -08:00
Zhengchao Shao
70db018a10 UPSTREAM: ipv4: igmp: fix refcnt uaf issue when receiving igmp query packet
[ Upstream commit e2b706c691905fe78468c361aaabc719d0a496f1 ]

When I perform the following test operations:
1.ip link add br0 type bridge
2.brctl addif br0 eth0
3.ip addr add 239.0.0.1/32 dev eth0
4.ip addr add 239.0.0.1/32 dev br0
5.ip addr add 224.0.0.1/32 dev br0
6.while ((1))
    do
        ifconfig br0 up
        ifconfig br0 down
    done
7.send IGMPv2 query packets to port eth0 continuously. For example,
./mausezahn ethX -c 0 "01 00 5e 00 00 01 00 72 19 88 aa 02 08 00 45 00 00
1c 00 01 00 00 01 02 0e 7f c0 a8 0a b7 e0 00 00 01 11 64 ee 9b 00 00 00 00"

The preceding tests may trigger the refcnt uaf issue of the mc list. The
stack is as follows:
	refcount_t: addition on 0; use-after-free.
	WARNING: CPU: 21 PID: 144 at lib/refcount.c:25 refcount_warn_saturate (lib/refcount.c:25)
	CPU: 21 PID: 144 Comm: ksoftirqd/21 Kdump: loaded Not tainted 6.7.0-rc1-next-20231117-dirty #80
	Hardware name: Red Hat KVM, BIOS 0.5.1 01/01/2011
	RIP: 0010:refcount_warn_saturate (lib/refcount.c:25)
	RSP: 0018:ffffb68f00657910 EFLAGS: 00010286
	RAX: 0000000000000000 RBX: ffff8a00c3bf96c0 RCX: ffff8a07b6160908
	RDX: 00000000ffffffd8 RSI: 0000000000000027 RDI: ffff8a07b6160900
	RBP: ffff8a00cba36862 R08: 0000000000000000 R09: 00000000ffff7fff
	R10: ffffb68f006577c0 R11: ffffffffb0fdcdc8 R12: ffff8a00c3bf9680
	R13: ffff8a00c3bf96f0 R14: 0000000000000000 R15: ffff8a00d8766e00
	FS:  0000000000000000(0000) GS:ffff8a07b6140000(0000) knlGS:0000000000000000
	CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
	CR2: 000055f10b520b28 CR3: 000000039741a000 CR4: 00000000000006f0
	Call Trace:
	<TASK>
	igmp_heard_query (net/ipv4/igmp.c:1068)
	igmp_rcv (net/ipv4/igmp.c:1132)
	ip_protocol_deliver_rcu (net/ipv4/ip_input.c:205)
	ip_local_deliver_finish (net/ipv4/ip_input.c:234)
	__netif_receive_skb_one_core (net/core/dev.c:5529)
	netif_receive_skb_internal (net/core/dev.c:5729)
	netif_receive_skb (net/core/dev.c:5788)
	br_handle_frame_finish (net/bridge/br_input.c:216)
	nf_hook_bridge_pre (net/bridge/br_input.c:294)
	__netif_receive_skb_core (net/core/dev.c:5423)
	__netif_receive_skb_list_core (net/core/dev.c:5606)
	__netif_receive_skb_list (net/core/dev.c:5674)
	netif_receive_skb_list_internal (net/core/dev.c:5764)
	napi_gro_receive (net/core/gro.c:609)
	e1000_clean_rx_irq (drivers/net/ethernet/intel/e1000/e1000_main.c:4467)
	e1000_clean (drivers/net/ethernet/intel/e1000/e1000_main.c:3805)
	__napi_poll (net/core/dev.c:6533)
	net_rx_action (net/core/dev.c:6735)
	__do_softirq (kernel/softirq.c:554)
	run_ksoftirqd (kernel/softirq.c:913)
	smpboot_thread_fn (kernel/smpboot.c:164)
	kthread (kernel/kthread.c:388)
	ret_from_fork (arch/x86/kernel/process.c:153)
	ret_from_fork_asm (arch/x86/entry/entry_64.S:250)
	</TASK>

The root causes are as follows:
Thread A					Thread B
...						netif_receive_skb
br_dev_stop					...
    br_multicast_leave_snoopers			...
        __ip_mc_dec_group			...
            __igmp_group_dropped		igmp_rcv
                igmp_stop_timer			    igmp_heard_query         //ref = 1
                ip_ma_put			        igmp_mod_timer
                    refcount_dec_and_test	            igmp_start_timer //ref = 0
			...                                     refcount_inc //ref increases from 0
When the device receives an IGMPv2 Query message, it starts the timer
immediately, regardless of whether the device is running. If the device is
down and has left the multicast group, it will cause the mc list refcount
uaf issue.

Bug: 316932391
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Signed-off-by: Zhengchao Shao <shaozhengchao@huawei.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Hangbin Liu <liuhangbin@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit 94445d9583079e0ccc5dde1370076ff24800d86e)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I277be2304e564994e05b981ccd6cd8cbb9dc85be
2023-12-21 11:28:11 +00:00