Commit graph

1,327 commits

Author SHA1 Message Date
Tejas Prajapati
691ddd437f msm: camera: reqmgr: reader writer locks to avoid memory faults
Shared memory is initialized by CRM and used by
other drivers; with CRM not active other drivers
would fail to access the shared memory if
memory manager is deinit. Reader Writer locks can
prevent the open/close/ioctl calls from other drivers
if CRM open/close is already being processed.

Issue observed with the below sequence if drivers
are opened from UMD directly without this change.
CRM Open successful,ICP open successful,
CRM close in progress, ICP open successful,
mem mgr deinit and CRM close successful,
ICP tries to access HFI memory and result in crash.

This change helps to serialze the calls and prevents
issue.

CRs-Fixed: 3019488
Change-Id: I464411576a5a04f5d0b402c403ce8a1d4df7dad0
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
2022-01-07 17:22:12 +05:30
Camera Software Integration
c450d2e419 Merge "msm: camera: reqmgr: check if link handle is correctly passed" into camera-kernel.lnx.4.0 2022-01-03 10:53:03 -08:00
Camera Software Integration
89103da2f8 Merge "msm: camera: isp: Add eof notification for rdi only context" into camera-kernel.lnx.4.0 2021-12-21 20:58:00 -08:00
Tejas Prajapati
4856f7a40a msm: camera: reqmgr: check if link handle is correctly passed
Instead of the link handle if the dev handle is
passed for dumping the request information, this
can lead to accessing invalid data structure.
To avodi accessing invalid data structure based on
the dev handle, first check if the link handle passed
in IOCTL is matchting with looked up link handle.

CRs-Fixed: 3097336
Change-Id: I815457ff96e3b26fe9fa886bd984d53d209e4edb
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
2021-12-20 14:44:36 +05:30
Camera Software Integration
be0697dec4 Merge "msm: camera: ope: Increase max bl limit and max stripe to process" into camera-kernel.lnx.4.0 2021-12-13 11:01:00 -08:00
Camera Software Integration
7ad290b351 Merge "msm: camera: ope: Update request timeout for NRT/RT context" into camera-kernel.lnx.4.0 2021-12-13 10:59:30 -08:00
Tejas Prajapati
c6de9ec432 msm: camera: isp: Add eof notification for rdi only context
For RDI only context EOF is not notified; it should be
notified, for the corner case if the flash is
configured to apply at EOF then it will block apply for
ISP on SOF as well until the EOF is notified, this
change adds EOF notification.

CRs-Fixed: 3091241
Change-Id: If6d974d092d640d9def89bbcf7a88fba0d85579b
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
2021-12-13 01:08:06 -08:00
Zhenlin Lian
ce9b4b3f12 msm: camera: config: Enable camera drivers for qcs610
Add camera config files for target qcs610.

Change-Id: I4fefaa0254aa8267b4375bb4270f286f46ec7997
Signed-off-by: Zhenlin Lian <quic_zlian@quicinc.com>
2021-12-03 01:58:20 -08:00
Camera Software Integration
c9f9bce593 Merge "msm: camera: reqmgr: Prevent session deadlock" into camera-kernel.lnx.4.0 2021-12-02 04:27:09 -08:00
Camera Software Integration
f9bcd25377 Merge "msm: camera: isp: handle buf_done at apply failure from deferred list" into camera-kernel.lnx.4.0 2021-12-02 04:26:15 -08:00
Alok Chauhan
8eeacc770c msm: camera: ope: Update request timeout for NRT/RT context
Currently the ope request timeout value for RT and NRT context
are same. In some usecases, NRT request processing takes more time.

Hence, initialize the RT and NRT request timeout value separately.

CRs-Fixed: 3082993
Change-Id: I17e86d26403fb21cdff518a81dee7a19c865144e
Signed-off-by: Alok Chauhan <quic_alokc@quicinc.com>
2021-11-26 18:07:31 +05:30
Vikram Sharma
4fbb1700ef msm: camera: ope: Increase max bl limit and max stripe to process
Increase “OPE_MAX_CDM_BLS” to 32 from 24 and MAX_STRIPES to 64 from 48
to process 108M frame.

CRs-Fixed: 3082993
Change-Id: I9e3631cc86c5e10e4e2020d4a9b2264ea282e437
Signed-off-by: Vikram Sharma <vikramsa@codeaurora.org>
2021-11-26 12:12:16 +05:30
sokchetra eung
1f76cca6da msm: camera: reqmgr: Prevent session deadlock
Releasing session lock before unlink and acquiring
it immediately after to allow workq to be done. Check
link state after acquiring session lock in process_
req to return if link is IDLE.

CRs-Fixed: 3003287
Change-Id: Ie7a8ffc4edcb123db290d6da047d748b3e99d68b
Signed-off-by: sokchetra eung <eung@codeaurora.org>
2021-11-24 20:36:01 -08:00
Tejas Prajapati
572462dbf6 msm: camera: isp: handle buf_done at apply failure from deferred list
For RDI only context where the buf_done is handled from wait list,
if the buf_done is moved to deferred list then the bubble
recovery might fail. To make sure the bubble is processed the request
needs to be moved pending list. This change helps moving the request
from active list to pending list.

CRs-Fixed: 3079621
Change-Id: Ibb271e68ca2312cbd3d71bd64e2ed7963bf60b55
Signed-off-by: Tejas Prajapati <tpraja@codeaurora.org>
2021-11-18 09:30:49 +05:30
Wyes Karny
f49b4dd0b9 msm: camera: cdm: Fix deadlock issue in CDM handle error
Fix deadlock issue in CDM handle error.

CRs-Fixed: 3073203
Change-Id: Ia63e1841fc00e74e4c03a1d6b28e94814748aa8f
Signed-off-by: Wyes Karny <wkarny@codeaurora.org>
2021-11-15 17:08:25 +05:30
Vikram Sharma
8a251d8af1 msm: camera: isp: Fix PPI index based on the phy selection
1) There is one to one mapping for ppi index with phy index
but phy select is not always equal to phy number,for some
targets "phy_sel = phy_idx + 1", and for some targets it is
"phy_sel = phy_idx", ppi_index should be updated accordingly.
2) Updated to configure ppi cfg register as.
 for cphy, disable dphy in config register.
 for dphy, do nothing (both cphy and dphy will be selected).
 then enable all lanes.

CRs-Fixed: 3057665
Change-Id: I1d5d66034a5563b5adcb8163acf9a668d10d4a19
Signed-off-by: Vikram Sharma <vikramsa@codeaurora.org>
2021-10-29 13:42:55 +05:30
Camera Software Integration
b819b10757 Merge "msm: camera: ife: Add ife num outport bound checks" into camera-kernel.lnx.4.0 2021-10-28 11:23:16 -07:00
Trishansh Bhardwaj
45dbb6c0cd msm: camera: ife: Add ife num outport bound checks
Variable num_ports is provided by userspace, it it used to index
res_list_isp_out. Big num_ports value can cause out of bound read.

Bound check num_ports, to prevent OOB read.

CRs-Fixed: 3056360
Change-Id: I86b6cf0419c68af1f510ce166e4964e177367eaf
Signed-off-by: Trishansh Bhardwaj <tbhardwa@codeaurora.org>
2021-10-18 07:09:27 +00:00
Vikram Sharma
7f25abfda5 msm: camera: cdm: handle dead lock scenario
This change handles a race condition in which cdm workqueue is
scheduled on one of the cores and cdm flush is executing on
another core. We come across a dead lock between fifo_lock and
hw_mutex lock.

CRs-Fixed: 3049531
Change-Id: Ie0b8982a7e55218fc5655f8e3d08a952fd852ed7
Signed-off-by: Vikram Sharma <vikramsa@codeaurora.org>
2021-10-14 02:43:56 -07:00
Camera Software Integration
981b2405f2 Merge "msm: camera: isp: Add handling for flush in flushed state" into camera-kernel.lnx.4.0 2021-10-11 11:34:30 -07:00
Camera Software Integration
d1207eb24c Merge "msm: camera: core: Delete request from pending list in case of error" into camera-kernel.lnx.4.0 2021-10-11 11:33:06 -07:00
Vikram Sharma
abee20f08a msm: camera: isp: Add handling for flush in flushed state
This change handles race condition in which flush is handled in
flushed state.

CRs-Fixed: 3038297
Change-Id: I8be1f8c70431c77366f8846d8ccab3414f3ede3e
Signed-off-by: Vikram Sharma <vikramsa@codeaurora.org>
2021-10-05 01:09:47 -07:00
Camera Software Integration
1894a410ed Merge "msm: camera: req_mgr: Table info dump removed" into camera-kernel.lnx.4.0 2021-10-04 11:23:19 -07:00
Camera Software Integration
30da00d21b Merge "msm: camera: flash: Add support for qup i2c flash" into camera-kernel.lnx.4.0 2021-10-04 11:22:47 -07:00
Gaurav Jindal
6e882932bd msm: camera: core: Delete request from pending list in case of error
While preparing hw for request, there is a possiblity of receiving
invalid sync object. In this case, we need to return error. By this
time, the request is already in pending list. While returning error,
request is moved back to free list. But deleting from the pending list
was missed.
This commit deleted the request from the pending list if the sync object
received is invalid.

CRs-Fixed: 2660625
Change-Id: Id619452889476b0c2811c8560361205b0d89bcb9
Signed-off-by: Gaurav Jindal <gjindal@codeaurora.org>
2021-09-30 00:42:57 -07:00
sokchetra eung
1f20f5bc62 msm: camera: req_mgr: Table info dump removed
Remove dump_tbl_info function and all of its
invocations in CRM to prevent dumping all the
handle info when holding the spin lock.

CRs-Fixed: 3014074, 3014073
Change-Id: Ie98bafb489fc0d1f2d75cf0f3f08efb48d9b4062
Signed-off-by: sokchetra eung <eung@codeaurora.org>
2021-09-29 11:23:29 -07:00
Vishal Verma
77cf2e394f msm: camera: flash: Add support for qup i2c flash
Add Support for qup i2c based flash. Update i2c
driver probe function and added regulator init at
power up and init for gpio pin control table. Since
positive return values are not errors for qup i2c rx
and tx data transfer, fix the return type for the APIs.
Added check for null pointer in get flash dt data for
device node. Correct the logging group in sensor util
for regulator power up function.

CRs-Fixed: 3047031
Change-Id: I70558fbb489b622da25278283015139b6d4fe2a6
Signed-off-by: Vishal Verma <vishverm@codeaurora.org>
2021-09-29 10:14:59 +05:30
Camera Software Integration
0695f8edc8 Merge "msm: camera: memmgr: ref count for init and deinit" into camera-kernel.lnx.4.0 2021-09-25 23:17:50 -07:00
Camera Software Integration
ff6c9be4dd Merge "msm: camera: jpeg: Ensure in/out map entries are within allowed range" into camera-kernel.lnx.4.0 2021-09-21 10:48:51 -07:00
Shravya Samala
ed7d45ddc5 msm: camera: jpeg: Ensure in/out map entries are within allowed range
Added checks to make sure in_map /out_map entries of packet
io configs are within expected maximum value.

CRs-Fixed: 3007258
Change-Id: I7e5a652cd8f9ae104a10a2af551fe49930849b2d
Signed-off-by: Shravya Samala <shravyas@codeaurora.org>
2021-09-13 13:42:48 +05:30
Tejas Prajapati
b8429f0813 msm: camera: memmgr: ref count for init and deinit
Shared memory is initialized by CRM and used by
ICP; with CRM not active the ICP would fail to
access the shared memory if memory manager is
deinit. Tracking open and close calls will help
ICP driver to access the shared memory if CRM
is not active.

CRs-Fixed: 3019488
Change-Id: Ifdf198c2e3593050573c66aeba69d50d131435b9
Signed-off-by: Tejas Prajapati <tpraja@codeaurora.org>
2021-09-07 15:11:20 +05:30
Dharmender Sharma
1510d5b82f msm: camera: jpeg: JPEG HW and Camnoc MISR
Support for Camnoc MISR for JPEG DMA and Encoder.
Also added support for seprate target files.

CRs-Fixed: 3012752
Change-Id: I5e066d5d871f58073f669c01270d5b64ce16088e
Signed-off-by: Dharmender Sharma <dharshar@codeaurora.org>
Signed-off-by: Shravya Samala <shravyas@codeaurora.org>
2021-09-07 00:40:18 -07:00
Camera Software Integration
8ef61574d0 Merge "msm: camera: isp: Support all patterns for TOP TPG" into camera-kernel.lnx.4.0 2021-09-06 20:38:59 -07:00
Camera Software Integration
12c02d3c4a Merge "msm: camera: reqmgr: Delay to do slot reset for finished req" into camera-kernel.lnx.4.0 2021-09-06 20:38:47 -07:00
Camera Software Integration
71d33047c2 Merge "msm: camera: cdm: Acquire mutex lock before accessing client data" into camera-kernel.lnx.4.0 2021-09-06 05:04:56 -07:00
Camera Software Integration
e12864cddd Merge "msm: camera: smmu: Unmap secure buffers in secure camera use case" into camera-kernel.lnx.4.0 2021-09-01 10:26:21 -07:00
Dharmender Sharma
6e68552105 msm: camera: isp: Support all patterns for TOP TPG
It provide support for differeent TPG patterns
like color bar, incrementing and user defined.

CRs-Fixed: 3026095
Change-Id: If18c99fb759f9cdb5bf8950c54f719d188a5e4ae
Signed-off-by: Dharmender Sharma <dharshar@codeaurora.org>
2021-08-31 13:26:10 +05:30
Camera Software Integration
3e949eb2c0 Merge "msm: camera: ope: Fix uninitialized variable access" into camera-kernel.lnx.4.0 2021-08-30 05:31:17 -07:00
Camera Software Integration
322225df0d Merge "msm: camera: sync: Prevent OOB access of sync name" into camera-kernel.lnx.4.0 2021-08-30 05:31:10 -07:00
Camera Software Integration
f2b30f3448 Merge "msm: camera: reqmgr: Fix trigger count out of bound issue" into camera-kernel.lnx.4.0 2021-08-25 04:10:10 -07:00
Camera Software Integration
40fa38ccab Merge "msm: camera: flash: Add support for flash stream off" into camera-kernel.lnx.4.0 2021-08-25 04:09:20 -07:00
Camera Software Integration
774b550caf Merge "msm: camera: tfe: Fix dereference of pointer before NULL check" into camera-kernel.lnx.4.0 2021-08-25 04:08:53 -07:00
Camera Software Integration
b8070c343c Merge "msm: camera: isp: CSID Tasklet stop sequence" into camera-kernel.lnx.4.0 2021-08-25 04:08:36 -07:00
Alok Chauhan
dfa85a1638 msm: camera: ope: Fix uninitialized variable access
Update ope pf dump function for uninitialized variables
access.

CRs-Fixed: 3020020
Change-Id: I7a996b15c8fe48297bcd160be3dbf4c7b65dc41d
Signed-off-by: Alok Chauhan <alokc@codeaurora.org>
2021-08-23 19:17:12 +05:30
chengxue
1c39013311 msm: camera: reqmgr: Delay to do slot reset for finished req
For boken mode with hw sync enable, a link and its synclink
streaming with sync. if a bubble condition happens on a link,
and can not wait all buf done to clear the isp ctx
process_bubble flag in time, there may apply fails on isp
during the bubble recovery flow. current crm reset in_q slot
after req's report has finished. this may lead to a synclink
slot not found while do ready check.

So delay to do slot reset by referring the link delay.

CRs-Fixed: 2996710
Change-Id: Ice8c340a9f478a69d97e3a7c77e0d0a263be66fa
Signed-off-by: chengxue <chengxue@codeaurora.org>
2021-08-23 14:22:33 +08:00
Trishansh Bhardwaj
8839726f67 msm: camera: sync: Prevent OOB access of sync name
Issue:
strlcpy calls strlen on src ptr. If src is not NULL terminated then OOB
access will occur in below stack.
  strlen
  strlcpy
  cam_sync_init_row
  cam_sync_handle_create
  cam_sync_dev_ioctl

Fix:
Pad user-space supplied name with NULL.

CRs-Fixed: 3010262
Change-Id: Ib5c2fbfe395025ec05e0bb2980f86111e95ff54c
Signed-off-by: Trishansh Bhardwaj <tbhardwa@codeaurora.org>
2021-08-20 07:35:58 +00:00
Shravya Samala
9d68bffd2a msm: camera: cdm: Acquire mutex lock before accessing client data
There is a chance of use after release of client data in
cdm internal operation calls. Hence acquire mutex lock whenever
accessing client data to avoid use after release scenario.

CRs-Fixed: 3010261
Change-Id: Iaf7f41d56301299a6f63a5dc1090334063019881
Signed-off-by: Shravya Samala <shravyas@codeaurora.org>
2021-08-17 01:37:52 -07:00
shiwgupt
e41ff174c1 msm: camera: flash: Add support for flash stream off
- Apply flash off register settings at the time of stream off.
- Add support to send fire command in initial config command.

CRs-Fixed: 2998772
Change-Id: I8897a68e637d283afd98e386b6a7b1fbaaf63c61
Signed-off-by: shiwgupt <shiwgupt@codeaurora.org>
2021-08-17 08:33:29 +05:30
Shravya Samala
e3c0176a11 msm: camera: tfe: Fix dereference of pointer before NULL check
This commit fixes derefering NULL pointer before accessing
it.

CRs-Fixed: 3011823
Change-Id: Id9ba556103310d9bb13a0b1029e942a2541a272f
Signed-off-by: Shravya Samala <shravyas@codeaurora.org>
2021-08-16 14:40:03 +05:30
Camera Software Integration
8d5da81f5d Merge "msm: camera: flash: Handle I2C flash request deletion" into camera-kernel.lnx.4.0 2021-08-13 10:07:32 -07:00