Random sequence cache is precomputed during slab object creation
based up on the object size and no of objects per slab. These could
be changed when flags like SLAB_STORE_USER, SLAB_POISON are updated
from sysfs. So when shuffle_freelist is called during slab_alloc it
uses updated object count to access the precomputed random sequence
cache. This could result in incorrect access of the random sequence
cache which could further result in slab corruption. Fix this by
reinitializing the random sequence cache up on slab object update.
A sample panic trace when write to slab_store_user was attempted.
Call trace0:
exception
set_freepointer(inline)
shuffle_freelist(inline)
new_slab+0x688/0x690
___slab_alloc+0x548/0x6f8
kmem_cache_alloc+0x3dc/0x418
zs_malloc+0x60/0x578
zram_bvec_rw+0x66c/0xaa0
zram_make_request+0x190/0x2c8
generic_make_request+0x1f8/0x420
submit_bio+0x140/0x1d8
submit_bh_wbc+0x1a0/0x1e0
__block_write_full_page+0x3a0/0x5e8
block_write_full_page+0xec/0x108
blkdev_writepage+0x2c/0x38
__writepage+0x34/0x98
write_cache_pages+0x33c/0x598
generic_writepages+0x54/0x98
blkdev_writepages+0x24/0x30
do_writepages+0x90/0x138
__filemap_fdatawrite_range+0xc0/0x128
file_write_and_wait_range+0x44/0xa0
blkdev_fsync+0x38/0x68
__arm64_sys_fsync+0x6c/0xb8.
Change-Id: Ia87ff808d23ff8dbb721d3cc3e3b29771200ec5a
Signed-off-by: Vijayanand Jitta <vjitta@codeaurora.org>
Clients store their private data in user within event structure
and not in notify structure. Thus update the callback to point
to the correct user info.
Change-Id: I938b135443d66b9451cead35d508bad9a4f685f8
Signed-off-by: Tony Truong <truong@codeaurora.org>
Retain 2019 as the copyright year of memory_dump.h.
Change-Id: I6c9053e64c8ee7a416a2f9af028b288ef577c5d8
Signed-off-by: Mao Jinlong <jinlmao@codeaurora.org>
Fix other headers to work when KERNEL_HEADER_TEST is enabled by adding
dependencies and advance struct prototypes where appropriate.
Change-Id: Ic0dedbad6804e5dca75b33b3d0ae9e3b89a51669
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Enable the fastrpc QGKI config option that the driver can use to
detect that it is being compiled in a QGKI kernel.
Change-Id: I6bd44bfd61e79ebe70689f326d5616b6d856c146
Acked-by: Thyagarajan Venkatanarayanan <venkatan@qti.qualcomm.com>
Signed-off-by: Himateja Reddy <hmreddy@codeaurora.org>
The logic for calculating the request buffer sizes for the
MEM_SHARE and MEM_LEND resource manager calls is not present,
so add it.
Change-Id: I804ee108565733b0e4b376b5fd31abdb3d359c1f
Signed-off-by: Isaac J. Manjarres <isaacm@codeaurora.org>
Use the locally calculated value of memory attribute entries when
populating the memory attribute descriptor, instead of always
dereferencing the client provided memory attribute descriptor,
as clients may not always provide one.
Change-Id: Ifbe586336e69e439ed404067616cce7515fd7953
Signed-off-by: Isaac J. Manjarres <isaacm@codeaurora.org>
Add subsystem restart (SSR) support to altmode glink driver so
that when subsystem goes down and comes up again, it can send
PAN_EN to charger firmware to receive notifications about altmode
interface.
Change-Id: Ie011d5110b6c26790fe1dd6149115019f8bc261c
Signed-off-by: Subbaraman Narayanamurthy <subbaram@codeaurora.org>
Add subsystem restart (SSR) support to battery charger driver so
that it can stop read/write properties when subsystem goes down.
Also, send message to enable notification again once subsystem
comes up.
Change-Id: I64f3abfa1d12c4e6a65fd01d7f66155c8741e68a
Signed-off-by: Subbaraman Narayanamurthy <subbaram@codeaurora.org>
Add subsystem restart (SSR) support to UCSI Glink driver so that
it can unregister from UCSI framework when subsystem goes down
and register with UCSI framework when it comes up again. When
subsystem goes down, it is not possible for UCSI stack to send
or receive data to and from PPM (i.e. remote subsystem) over
PMIC Glink. Hence, return immediately in ucsi_qti_{read,write}()
to avoid error logs and handle cleanup easily.
Change-Id: I711920222bd531af27b87337cad7db8aabbaa466
Signed-off-by: Subbaraman Narayanamurthy <subbaram@codeaurora.org>
Add support for PMIC Glink clients to receive notification when
the subsystem goes down and comes up again. PMIC Glink client
can pass a function pointer state_cb via which they would like
to receive when PMIC Glink state transitions so that they can
unregister from the framework (e.g. UCSI) and clean up their
state as needed.
PMIC Glink device supports SSR for the subsystem specified under
"qcom,subsys-name" property.
Change-Id: I0f32f638d72a13e231e6813fb3d782c8fa7a4af0
Signed-off-by: Subbaraman Narayanamurthy <subbaram@codeaurora.org>
In preparation for subsystem restart (SSR) and protection domain
restart (PDR) where subsystem state transitions would be sent to
PMIC Glink clients via another callback function, change the client
callback function pointer name to msg_cb. This would convey that
this callback is for delivering the messages to a client upon its
registration.
Change-Id: I584d6c5d3898fe54e6928b25502d6382ce6ccbc4
Signed-off-by: Subbaraman Narayanamurthy <subbaram@codeaurora.org>
The ION trusted VM flag may map to a VMID that was dynamically
assigned, instead of statically allocated. Thus, use the RM driver
APIs to determine the VMID for the trusted VM.
Change-Id: Ide4dd77a4cedbdf7e32f3c834fef9a0dfc6ba9d5
Signed-off-by: Isaac J. Manjarres <isaacm@codeaurora.org>
Currently, the clients of the hh_msgq driver would allocate buffers,
fill with data and call hh_msgq_send(). Upon success, hh_msgq_send()
would be freeing the buffer, while in the case of failure, the clients
are responsible for it. However, this approach of buffer management is
not symmetric and could be confusing for the clients. Hence, let the
clients take full ownership of the buffers- allocating and freeing.
Also make changes to the affected client drivers.
Change-Id: I73101d823f9d3de16414e444fde494222f584e53
Signed-off-by: Raghavendra Rao Ananta <rananta@codeaurora.org>
It's a highly likely situation that the clients call hh_msgq_recv()
from a thread in a polling fashion, and these threads are spawned
during client driver's initialization. Hence, it's possible that
the cap-ids for the message queues will not be ready so early and
the clients would end up continuously spinning on hh_msgq_recv(),
receiving the error -EAGAIN. To avoid this situation, put the
client process onto a wait-queue until the cap-ids are ready.
Although a little unlikely, to satisfy the symmetry, add the same
provision for the callers of hh_msgq_send() as well.
Change-Id: I4e042215c5e43271d566340ce1ef9c52ecafeb5c
Signed-off-by: Raghavendra Rao Ananta <rananta@codeaurora.org>
Signed-off-by: Murali Nalajala <mnalajal@codeaurora.org>
hh_msgq_register() can now return -EPROBE_DEFER as an error code.
Since this is not a fatal error, and will end up in having the
probe function called again at a later point in time, do not
print an error when -EPROBE_DEFER is returned.
Change-Id: I7646788719bdbaac309bc1fbd840de754398e23b
Signed-off-by: Isaac J. Manjarres <isaacm@codeaurora.org>