Below information is dumped at the overflow
1. Dump SOF, EPOCH, EOF and Error time.
2. Dump IRQ status.
3. Cpas AB, IB votes.
4. Dump width and height of all the acquired ports.
5. CSID clock.
CRs-Fixed: 3159425
Change-Id: I580d8f4d50c49568a6bc9ae8d06fc4b93f11891c
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
In a corner case, race condition to free the original
ion buf allocated and new ion buffer with same fd but
different size after freeing the origianl ion buf might
result into mismatches in the real ion buf size assigned
in bufq. To avoid this update length in bufq with
local variable.
CRs-Fixed: 3142221
Change-Id: I23d91445bd088bbde19ffa191e158256166f2053
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
Instead of correct link handle, if some other handle like
dev handle is passed then it may access some other data space.
To avoid such scenario, need to check whether link handle
passed by ioctl is same as retrieved link handle.
CRs-Fixed: 3120454
Change-Id: Idff2e3c25b60563788ffb426c7cabc367c3c97f8
Signed-off-by: Yash Upadhyay <quic_yupadhya@quicinc.com>
Due to workqueue does not process the work in order,
so sometimes the later work will be processed earlier.
Such as, when submit request order: 1/2/3, cdm interrupt
come order: 1/2/3, workqueue process order: 2/1/3,
when process 2 request, which currently will notify 1/2
CDM clients and remove 1/2 from submit list. After that,
when process 1 request, will notify 3, actually 3 is not
done at the moment, which maybe cause smmu page fault issue.
And sometimes, when there is a delay in handling interrupts,
then HLOS handles two interrupts as one only. This change only
notify the request less than and equal to the interrupt request.
CRs-Fixed: 3130447
Change-Id: I0fd0e8adee48767e5ab7db1921a8284d107c2f40
Signed-off-by: zhuo <quic_zhuo@quicinc.com>
The 'l_device' pointer in __cam_req_mgr_destroy_subdev is
set to NULL after freeing but this is done on a
local copy of the variable in stack. This results in
double-free when this function is called again. To avoid
this, pass 'l_device' pointer by reference and assign it
to NULL after freeing.
CRs-Fixed: 3120468
Change-Id: If2dde6f1c702bee26a3c8a68c2f45bafbf0f7cd6
Signed-off-by: Nirmal Abraham <quic_c_nabrah@quicinc.com>
On overflow dump the AB and IB votes, tfe clock,
CSID clock and respective bus path data for acquire
time and addr_status registers.
CRs-Fixed: 3118430
Change-Id: Ia38eb4350e8e38562b6d22769b38637480da0b9d
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
Shared memory is initialized by CRM and used by
other drivers; with CRM not active other drivers
would fail to access the shared memory if
memory manager is deinit. Reader Writer locks can
prevent the open/close/ioctl calls from other drivers
if CRM open/close is already being processed.
Issue observed with the below sequence if drivers
are opened from UMD directly without this change.
CRM Open successful,ICP open successful,
CRM close in progress, ICP open successful,
mem mgr deinit and CRM close successful,
ICP tries to access HFI memory and result in crash.
This change helps to serialze the calls and prevents
issue.
CRs-Fixed: 3019488
Change-Id: I464411576a5a04f5d0b402c403ce8a1d4df7dad0
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
Use div_u64 to do 64-bit division.
CRs-Fixed: 3099898
Change-Id: I405461ea02d0ec668cb7be764543a9a16bd1c3e6
Signed-off-by: Alok Chauhan <quic_alokc@quicinc.com>
Signed-off-by: Nirmal Abraham <quic_c_nabrah@quicinc.com>
Instead of the link handle if the dev handle is
passed for dumping the request information, this
can lead to accessing invalid data structure.
To avodi accessing invalid data structure based on
the dev handle, first check if the link handle passed
in IOCTL is matchting with looked up link handle.
CRs-Fixed: 3097336
Change-Id: I815457ff96e3b26fe9fa886bd984d53d209e4edb
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
For RDI only context EOF is not notified; it should be
notified, for the corner case if the flash is
configured to apply at EOF then it will block apply for
ISP on SOF as well until the EOF is notified, this
change adds EOF notification.
CRs-Fixed: 3091241
Change-Id: If6d974d092d640d9def89bbcf7a88fba0d85579b
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
Currently the ope request timeout value for RT and NRT context
are same. In some usecases, NRT request processing takes more time.
Hence, initialize the RT and NRT request timeout value separately.
CRs-Fixed: 3082993
Change-Id: I17e86d26403fb21cdff518a81dee7a19c865144e
Signed-off-by: Alok Chauhan <quic_alokc@quicinc.com>
Increase “OPE_MAX_CDM_BLS” to 32 from 24 and MAX_STRIPES to 64 from 48
to process 108M frame.
CRs-Fixed: 3082993
Change-Id: I9e3631cc86c5e10e4e2020d4a9b2264ea282e437
Signed-off-by: Vikram Sharma <vikramsa@codeaurora.org>
Releasing session lock before unlink and acquiring
it immediately after to allow workq to be done. Check
link state after acquiring session lock in process_
req to return if link is IDLE.
CRs-Fixed: 3003287
Change-Id: Ie7a8ffc4edcb123db290d6da047d748b3e99d68b
Signed-off-by: sokchetra eung <eung@codeaurora.org>
For RDI only context where the buf_done is handled from wait list,
if the buf_done is moved to deferred list then the bubble
recovery might fail. To make sure the bubble is processed the request
needs to be moved pending list. This change helps moving the request
from active list to pending list.
CRs-Fixed: 3079621
Change-Id: Ibb271e68ca2312cbd3d71bd64e2ed7963bf60b55
Signed-off-by: Tejas Prajapati <tpraja@codeaurora.org>
1) There is one to one mapping for ppi index with phy index
but phy select is not always equal to phy number,for some
targets "phy_sel = phy_idx + 1", and for some targets it is
"phy_sel = phy_idx", ppi_index should be updated accordingly.
2) Updated to configure ppi cfg register as.
for cphy, disable dphy in config register.
for dphy, do nothing (both cphy and dphy will be selected).
then enable all lanes.
CRs-Fixed: 3057665
Change-Id: I1d5d66034a5563b5adcb8163acf9a668d10d4a19
Signed-off-by: Vikram Sharma <vikramsa@codeaurora.org>
Variable num_ports is provided by userspace, it it used to index
res_list_isp_out. Big num_ports value can cause out of bound read.
Bound check num_ports, to prevent OOB read.
CRs-Fixed: 3056360
Change-Id: I86b6cf0419c68af1f510ce166e4964e177367eaf
Signed-off-by: Trishansh Bhardwaj <tbhardwa@codeaurora.org>
This change handles a race condition in which cdm workqueue is
scheduled on one of the cores and cdm flush is executing on
another core. We come across a dead lock between fifo_lock and
hw_mutex lock.
CRs-Fixed: 3049531
Change-Id: Ie0b8982a7e55218fc5655f8e3d08a952fd852ed7
Signed-off-by: Vikram Sharma <vikramsa@codeaurora.org>
This change handles race condition in which flush is handled in
flushed state.
CRs-Fixed: 3038297
Change-Id: I8be1f8c70431c77366f8846d8ccab3414f3ede3e
Signed-off-by: Vikram Sharma <vikramsa@codeaurora.org>
While preparing hw for request, there is a possiblity of receiving
invalid sync object. In this case, we need to return error. By this
time, the request is already in pending list. While returning error,
request is moved back to free list. But deleting from the pending list
was missed.
This commit deleted the request from the pending list if the sync object
received is invalid.
CRs-Fixed: 2660625
Change-Id: Id619452889476b0c2811c8560361205b0d89bcb9
Signed-off-by: Gaurav Jindal <gjindal@codeaurora.org>
Remove dump_tbl_info function and all of its
invocations in CRM to prevent dumping all the
handle info when holding the spin lock.
CRs-Fixed: 3014074, 3014073
Change-Id: Ie98bafb489fc0d1f2d75cf0f3f08efb48d9b4062
Signed-off-by: sokchetra eung <eung@codeaurora.org>
Add Support for qup i2c based flash. Update i2c
driver probe function and added regulator init at
power up and init for gpio pin control table. Since
positive return values are not errors for qup i2c rx
and tx data transfer, fix the return type for the APIs.
Added check for null pointer in get flash dt data for
device node. Correct the logging group in sensor util
for regulator power up function.
CRs-Fixed: 3047031
Change-Id: I70558fbb489b622da25278283015139b6d4fe2a6
Signed-off-by: Vishal Verma <vishverm@codeaurora.org>
Added checks to make sure in_map /out_map entries of packet
io configs are within expected maximum value.
CRs-Fixed: 3007258
Change-Id: I7e5a652cd8f9ae104a10a2af551fe49930849b2d
Signed-off-by: Shravya Samala <shravyas@codeaurora.org>
Shared memory is initialized by CRM and used by
ICP; with CRM not active the ICP would fail to
access the shared memory if memory manager is
deinit. Tracking open and close calls will help
ICP driver to access the shared memory if CRM
is not active.
CRs-Fixed: 3019488
Change-Id: Ifdf198c2e3593050573c66aeba69d50d131435b9
Signed-off-by: Tejas Prajapati <tpraja@codeaurora.org>
Support for Camnoc MISR for JPEG DMA and Encoder.
Also added support for seprate target files.
CRs-Fixed: 3012752
Change-Id: I5e066d5d871f58073f669c01270d5b64ce16088e
Signed-off-by: Dharmender Sharma <dharshar@codeaurora.org>
Signed-off-by: Shravya Samala <shravyas@codeaurora.org>