Grab rq->refcount before calling ->fn in blk_mq_tagset_busy_iter(), and
this way will prevent the request from being re-used when ->fn is
running. The approach is same as what we do during handling timeout.
Fix request use-after-free(UAF) related with completion race or queue
releasing:
- If one rq is referred before rq->q is frozen, then queue won't be
frozen before the request is released during iteration.
- If one rq is referred after rq->q is frozen, refcount_inc_not_zero()
will return false, and we won't iterate over this request.
However, still one request UAF not covered: refcount_inc_not_zero() may
read one freed request, and it will be handled in next patch.
Tested-by: John Garry <john.garry@huawei.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Signed-off-by: Ming Lei <ming.lei@redhat.com>.
Bug: 197804811
Change-Id: I0e431a8361d1412aaca3f7c0310780d9a9ad0db8
[Upstream: cherry picked from commit 2e315dc07df009c3e29d6926871f62a30cfae394]
[Pradeep: Resolved conflicts in block/blk-mq-tag.c]
Git-commit: a5d38e7c26
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
The pm8008 regulator is connected over I2C and the I2C device configures
its BW vote in runtime_resume and runtime_suspend. These callbacks are
triggered from the pm8008 driver's regmap calls. This means regulator
framework requests for pm8008 call into the ICC framework which in turn
calls into clock framework.
The qcom rpm smd clock providers calls into RPM message with the
the regulator framework, ICC framework and clock framework locks held.
To prevent these deadlocks, enable the I2C qup clocks required for pm8008
by default during probe and stop requesting for clock enable/rate from the
framework.
Change-Id: Ifd486bec85a46139ccb15f4b5dbd2d43c33f3fda
Signed-off-by: Taniya Das <tdas@codeaurora.org>
This change is a workaround change to fix the PMIC race condition
with the clock enablement. In case of PMIC txfer over i2c, I2C driver
resumes and votes for BW and clocks. The BW vote goes to RPM and that
in turn waiting for the global PMIC mutex causing race condition in
rare cases.
Hence as a workaroun, do not vote for the BW vote only for PMIC used
I2C SE instance.
Change-Id: I94c57427200a71dd2792533b1af249940b0bf03f
Signed-off-by: Mukesh Kumar Savaliya <msavaliy@codeaurora.org>
Enable cnss2 driver as module as requested on sdxlemur.
CRs-Fixed: 3016737
Change-Id: I0d8971c60d765fbfbee55ba1d215a2eb1ebc5659
Signed-off-by: Will Huang <wilhuang@codeaurora.org>
Add CONFIG_IPV6 check to ipv6 specific early eth code
Change-Id: Ib1b266e6da7243e4a1b2d3507b0d19b119e2ebdc
Signed-off-by: Raihan Haider<rhaider@codeaurora.org>
Register notifier to get notification for restart_level
change of WPSS and send SMP2P command to FW to enable
PHY processor SSR.
Change-Id: Id0edb6ab6a44fbca83b2dbe6bad7c86e2540d865
Signed-off-by: Naman Padhiar <npadhiar@codeaurora.org>
/sys/kernel/debug/kgsl/proc/<pid>/mem prints incorrect map size
in some cases. Currently, memdesc size is printed as map size.
Because of this, map size shows non-zero value even for unmapped
buffers. Since kgsl buffers can be mapped multiple times, update
the print to map count instead of map size.
Change-Id: I7970580bc3b1c9a30ca0d72d9caf89af1ce09740
Signed-off-by: Kamal Agrawal <kamaagra@codeaurora.org>
Update the sdcc clock frequency from 200MHz to 171MHz.
Change-Id: Ibada53598071e84ab600aeba9d3418d41d811357
Signed-off-by: Taniya Das <tdas@codeaurora.org>
To help with the debug of interrupt storms and problems during IRQ
handling, log the IRQ number in RTB for each interrupt that fires.
Change-Id: Icea5ded0f7d66ba3c7608793e7c25218e2a64e0c
Signed-off-by: Subbaraman Narayanamurthy <subbaram@codeaurora.org>
[abhimany: resolve trivial merge conflicts]
Signed-off-by: Abhimanyu Kapur <abhimany@codeaurora.org>
[aiquny: resolve trivial merge conflicts]
Signed-off-by: Maria Yu <aiquny@codeaurora.org>
kgsl_system_alloc_pages and kgsl_pool_alloc_pages allocate memory for
pages array. This memory is not freed in kgsl_alloc_secure_pages in
some failure cases. Free the allocated memory in case of failure to
avoid memory leak issues.
Change-Id: Ifed2573506d549f60d01f8d3ba06cbabdc9878e0
Signed-off-by: Puranam V G Tejaswi <pvgtejas@codeaurora.org>
Commit b610aa2d70a3 ("input: qcom-hv-haptics: Ignore checking HBoost status
when SWR is playing") is added to ignore checking hBoost ready status when
triggering a non-FIFO play with SWR playing in the background. This should
be also applicable when triggering a FIFO play, so remove the pattern_src
check as the HBoost should be always ready when triggering the play with
SWR playing in the background.
Change-Id: If3d5ff7138e189c81991775d7814229c4d0e8c0a
Signed-off-by: Fenglin Wu <fenglinw@codeaurora.org>
Currently the kernel implementation disables L1 in HS since
there are target which does not support gadget L1.
However, implementing this leads to Ch9 compliance
failures.
Therefore implementing a debugfs parameter through which
this can be controlled, when testing for compliance it can
be set to true and carry out the tests.
Change-Id: I9cf9c49737b18ca889fcc1dbe8232a7bb999f35c
Signed-off-by: Udipto Goswami <ugoswami@codeaurora.org>
If the device doesn't support LPM, make sure to disable the LPM
capability and don't advertise to the host that it supports it.
Change-Id: I29ceac849220b06d2a01fa14f00483b10d7acfc0
Acked-by: Felipe Balbi <balbi@kernel.org>
Signed-off-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com>
Link: https://lore.kernel.org/r/9e68527ff932b1646f92a7593d4092a903754666.1618366071.git.Thinh.Nguyen@synopsys.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Git-Commit: 475e8be53d0496f9bc6159f4abb3ff5f9b90e8de
Git-Repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Udipto Goswami <ugoswami@codeaurora.org>
This reverts commit c3de8d2179 ("usb: dwc3: Add support
of disable L1 in HS mode") since the patch had implemented
the functionality by changing the bcdUSB to 2.0.
Eventhough it solves the problem, this results in compliance
failures.
Fix this by reverting the implementation. This will allow
the compliance to detect the DUT as L1 supported device.
Change-Id: I30894618584ebedf697dd98e0c94a42c961bc49d
Signed-off-by: Udipto Goswami <ugoswami@codeaurora.org>
sdx targets rely on oom killer to kill the processes as there is
no lmk. so, disable panic_on_oom on sdxlemur.
Change-Id: I4f06a0f4d6e45384d048bb5b9c61bee76d751896
Signed-off-by: Vijayanand Jitta <vjitta@codeaurora.org>
ret variable is meant to store the return value which can be negative.
Change the data type from unsigned int to int.
Change-Id: I6ea46c40d22dfc6474bbfda9b0e7791d39798520
Signed-off-by: Kamal Agrawal <kamaagra@codeaurora.org>
Currently there is a race condition where during the flushing of ereqs
the channel is closed from the client on the EP side, which is causing
the flush function to access null memory. To avoid that call the flush
from dev close which ensures all the pending ereqs are closed before
closing the channel and freeing the memory.
Change-Id: Id81d8cb8b326340d28f6cfe9d48dcd685a8038f9
Signed-off-by: Gauri Joshi <gaurjosh@codeaurora.org>
When ffs_func_disable is called the driver will call set_alt
as part of which if FFS_DEACTIVATED is set then it schedules
reset_work. It further goes and tries to call epfile_destroy
where kfree is done. If within the same time, if ep0_release
is also called, it will also go forward and call epfiles_destroy.
This is because although the driver did kfree, but did't mark NULL,
which is why the if check for epfile equals NULL will fail to prevent
and will still be able to proceed. At this point the epfile instance
is corrupted therefore when in epfile_destroy it goes into the if
check which will trigger the BUG_ON check causing crash.
Following is the illustration:
CPU1 CPU2
ffs_ep0_release
ffs_data_closed
ffs->state = FFS_DEACTIVATED (atomic context)
ffs_func_disable
ffs_func_set_alt
schedule_work(&ffs->reset_work)
ffs_epfiles_destroy(ffs->epfiles)
(running for loop not finished)
ffs_reset_work (preempts)
ffs_data_reset
ffs_data_clear
ffs_epfiles_destroy(ffs->epfiles)
Fix this by protecting the epfile_destroy calls with mutex_lock
and also ensuring to mark epfiles NULL within it.
Change-Id: I452c61ba9f404676e08550d12cb7096b8d449706
Signed-off-by: Udipto Goswami <ugoswami@codeaurora.org>
commit ("USB: configfs: Don't send DISCONNECT uevent during unbind")
removed sending disconnect uevent from unbind path. In normal disconnect
path kernel will notify the disconnect event from dwc3_disconnect_gadget()
function. If their is a race between composition switch and cable
disconnect dwc gadget pointers may become null from composition unbind
rules and then we end up not sending any disconnect notification to
usespace and status remains in usb connected state in
usb preferences screen.
Hence fix this issue by scheduling android work from bind path
which will send disconnect event to userspace.
Change-Id: Ic53d8d9f6e5ae19d28bb1c23722a62a38f80ec08
Signed-off-by: Chandana Kishori Chiluveru <cchiluve@codeaurora.org>
QCN9000 target with device ID 0x1104 does not support L0s and L1
support.
Disable L0s and L1 support for QCN9000 in PCI quirks.
Change-Id: Ibb7b7c6e89e8076e4f7c6e32de651833e7c62c73
Signed-off-by: Vignesh Viswanathan <viswanat@codeaurora.org>
Jan Kara's analysis of the syzbot report (edited):
The reproducer opens a directory on FUSE filesystem, it then attaches
dnotify mark to the open directory. After that a fuse_do_getattr() call
finds that attributes returned by the server are inconsistent, and calls
make_bad_inode() which, among other things does:
inode->i_mode = S_IFREG;
This then confuses dnotify which doesn't tear down its structures
properly and eventually crashes.
Avoid calling make_bad_inode() on a live inode: switch to a private flag on
the fuse inode. Also add the test to ops which the bad_inode_ops would
have caught.
This change goes back to the initial merge of fuse in 2.6.14...
Change-Id: Iec8f3c66e1ee214e641d71cf01e6f0c2755c3cef
Reported-by: syzbot+f427adf9324b92652ccc@syzkaller.appspotmail.com
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Tested-by: Jan Kara <jack@suse.cz>
Cc: <stable@vger.kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Git-commit: 732251cabe
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
The global irqs are being enabled before EP driver has completed
successful link enumeration. This causes a race condition where
the BME IRQ is processed before link up causing the link up to
exit before updating the link status. Any further processing results
in LINK_DISABLED error. Avoid this scenario by enabling the global
interrupts after enumeration has finished.
Change-Id: I983a35f461da5d8966cadc9918b5529d16182b47
Signed-off-by: Gauri Joshi <gaurjosh@codeaurora.org>