Commit graph

916,933 commits

Author SHA1 Message Date
QCTECMDR Service
8375c081bb Merge "msm: eva: Adding kref count for cvp_get_inst_from_id" 2024-07-22 04:48:15 -07:00
QCTECMDR Service
c2a6a9ca1a Merge "msm: eva: Fix UAF issue when remove module" 2024-07-21 23:56:22 -07:00
QCTECMDR Service
b7e3d54e1b Merge "msm: cvp: OOB write fix due to integer underflow" 2024-07-15 21:50:14 -07:00
QCTECMDR Service
d3b92de37c Merge "msm: ep_pcie: Avoid writing req_L1_exit during dstate change" 2024-07-14 23:37:26 -07:00
Manaf Meethalavalappu Pallikunhi
c360f7cb0c thermal: qcom: Add support to update tsens trip based on nvmem data
Add support to detect higher thermal profile parts and update thermal
zone trips dynamically based on nvmem cell data for tsens.

Change-Id: I792c4f2736d10d68b45cc9b64c0ec08d185cf007
Signed-off-by: Manaf Meethalavalappu Pallikunhi <quic_manafm@quicinc.com>
2024-07-12 13:01:01 +05:30
ptak
12a570651b msm: eva: Fix UAF issue when remove module
Should use different way to get the core info for
different device.

Change-Id: I8231d08afa75a1f47781f54ec2e5fa264820cc9e
Signed-off-by: ptak <quic_ptak@quicinc.com>
2024-07-11 17:07:46 +05:30
ptak
143f500168 msm: cvp: OOB write fix due to integer underflow
If FW send a pkt->size which is less than the sizeof packet structure
then pkt->size - sizeof() would result into an integer underflow.
Due to this the subsequent check would be bypassed and we will
start write to an OOB memory.

Change-Id: Icb3e4e6d64275592ceb6f747de653dcc1c65fec7
Signed-off-by: ptak <quic_ptak@quicinc.com>
2024-07-11 12:25:08 +05:30
Pallavi Singh
bbf350b175 msm: ep_pcie: Avoid writing req_L1_exit during dstate change
Avoid setting this bit to make sure device stays in L1SS when D-state is
changes to D3 Hot.

Because of device not staying in L1SS the PCIe link was going through
recovery all the time power consumption was higher than expected value.

Change-Id: Id06996745171e62d3a9dbc499c693f8a9870b2ea
Signed-off-by: Pallavi Singh <quic_pallsing@quicinc.com>
2024-07-10 23:27:28 -07:00
QCTECMDR Service
02194073f2 Merge "msm_ipa: EoGRE Multi tunnel support" 2024-07-01 17:58:07 -07:00
Himansu Nayak
503c564d87 msm_ipa: EoGRE Multi tunnel support
Updated the existing pad variable to
support multi tunnel in SINGLE_TAG
feature.

Change-Id: I9be926250308e1b4375b677834e0e83eaa9aad41
Signed-off-by: Himansu Nayak <quic_himansu@quicinc.com>
2024-07-01 11:08:46 +05:30
QCTECMDR Service
6d33a677e4 Merge "usb: dwc3: Fix dwc3 version and revisions in remote wakeup path" 2024-06-30 20:59:58 -07:00
QCTECMDR Service
8c7c30afc0 Merge "usb: gadget: f_cdev: Add remote wakeup capability from notify_serial_state" 2024-06-28 10:32:27 -07:00
QCTECMDR Service
cc7ab6ffb6 Merge "BACKPORT: media: venus: hfi: add checks in capabilities from firmware" 2024-06-26 23:18:15 -07:00
QCTECMDR Service
75c5b60dcd Merge "msm: kgsl: Fix error handling during drawctxt switch" 2024-06-25 02:38:15 -07:00
Prashanth K
00d7d1195d usb: dwc3: Fix dwc3 version and revisions in remote wakeup path
Currently inorder to issue remote wakup to host, we perform some
register operations which are needed only for DWC3_IP versions
>= 194A, but we do perform operations for DWC31_IP controllers as
well, which is not expected. Hence cleanup the IP and revisions
of DWC3 in remote wakup path.

Change-Id: Idede7b05b1fb53fe582c6e2d7483784d578a9738
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
2024-06-25 12:15:45 +05:30
Prashanth K
8837f6669e usb: gadget: f_cdev: Add remote wakeup capability from notify_serial_state
Currently if the Modem sends notifications like Rind Indicator
or Carrier Detect, we just bail out if USB is already suspended.
Add remote wakeup capability in this path.

Change-Id: I62321d67e54390f167776af563c0b666b0d9e789
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
2024-06-25 10:51:47 +05:30
QCTECMDR Service
956d8e87a1 Merge "power: reset: qcom-dload-mode: nodump mode error handling" 2024-06-24 04:20:28 -07:00
Khaja Hussain Shaik Khaji
cef0450861 power: reset: qcom-dload-mode: nodump mode error handling
In case nodump mode is already set, do not allow user to
change dump mode to other modes now.

Change-Id: I25b9e0d20b4dca2fb19d22f225a3dd9f0ea66cc5
Signed-off-by: Khaja Hussain Shaik Khaji <quic_kshaikkh@quicinc.com>
2024-06-21 13:45:19 +05:30
Khaja Hussain Shaik Khaji
446a7be36f firmware: qcom_scm: Add a call for getting dload mode
Add an SCM call to read the dload mode cookie, which can
be used in various drivers to make decisions based on the
dload mode. Earlier, this support was not there and HLOS
was not aware of changes in this cookie, outside of its
domain.

Change-Id: I3bb82b65bc411354090b34b98f7e651dd1888e5b
Signed-off-by: Khaja Hussain Shaik Khaji <quic_kshaikkh@quicinc.com>
2024-06-21 10:36:14 +05:30
QCTECMDR Service
9c3cd8528c Merge "defconfig: sdxlemur: Enable nodump support for sdxlemur" 2024-06-20 08:06:25 -07:00
QCTECMDR Service
99edd1401d Merge "power: reset: qcom-dload-mode: support for nodump mode" 2024-06-20 02:54:52 -07:00
Rakesh Naidu Bhaviripudi
db749ede68 msm: kgsl: Fix error handling during drawctxt switch
Currently, separate submissions are made for page table
switch and context switch to the ring buffer. However, if
the page table switch succeeds but the context switch fails,
it can lead to use of wrong page table for drawctxt.

To address this issue, submit page table switch and context
switch commands as a single submission to ring buffer.

Also, remove the unnecessary ADRENO_DEVICE_FAULT check and
correctly put the refcount of adreno context during error
cleanup.

Change-Id: I1bb4ee3ebb0ce6ea32f0b6799cfb7fa89c0d09c7
Signed-off-by: Rakesh Naidu Bhaviripudi <quic_rakeshb@quicinc.com>
2024-06-20 12:18:17 +05:30
Pranay Varma Kopanati
b651124b92 msm: eva: Adding kref count for cvp_get_inst_from_id
Adding count for instance

Change-Id: I4505feb478c1c682ecf6a790d7cb804f70e50a1c
Signed-off-by: Pranay Varma Kopanati <quic_pkopanat@quicinc.com>
2024-06-17 13:29:28 +05:30
Khaja Hussain Shaik Khaji
c7cfe23876 power: reset: qcom-dload-mode: support for nodump mode
In case of unexpected warm-restart, device will go into special
download modes. Add support to not go into download modes
i.e., nodump mode.

Change-Id: Ica5f1b22a648458b151a8ae696e97aad83b7fc6c
Signed-off-by: Khaja Hussain Shaik Khaji <quic_kshaikkh@quicinc.com>
2024-06-13 00:56:01 +05:30
Khaja Hussain Shaik Khaji
2142fdbde8 defconfig: sdxlemur: Enable nodump support for sdxlemur
Enable POWER_RESET_QCOM_DOWNLOAD_MODE_NODUMP for sdxlemur so that
on a warm-restart, user can choose to set nodump as download mode.

Change-Id: Icc600c2c45a266a56df890c16f1d32fd7a7eb98c
Signed-off-by: Khaja Hussain Shaik Khaji <quic_kshaikkh@quicinc.com>
2024-06-13 00:45:57 +05:30
qctecmdr
3733cab2bf Merge "msm: adsprpc: use-after-free (UAF) in global maps" 2024-06-09 22:04:33 -07:00
qctecmdr
b0184b0120 Merge "PCI: Disable L0s support for SDX65 with QPS615 on CPE platform" 2024-06-03 08:03:09 -07:00
qctecmdr
b3b348f9af Merge "rpmsg: glink: Get reference of channel objects in rx path" 2024-06-03 05:36:18 -07:00
Paras Sharma
62e6a8f4bb PCI: Disable L0s support for SDX65 with QPS615 on CPE platform
NoC timeout issues are seen with HSP attach over QPS615 switch while
IPA is accessing HSP specific registers.

At the time of issue link state from PARF register dump showed that
link is in L0s.

So, disable the L0s state as a work-around
(vetted by hardware verification team) and this change should have
minimum power impact.

Change-Id: I21ddffdc69d83ece01ac8546c22b50b450cc6ed5
Signed-off-by: Paras Sharma <quic_parass@quicinc.com>
2024-06-03 01:39:58 -07:00
Santosh Sakore
6f9f631c90 msm: adsprpc: use-after-free (UAF) in global maps
Currently, remote heap maps get added to the global list before the
fastrpc_internal_mmap function completes the mapping. Meanwhile, the
fastrpc_internal_munmap function accesses the map, starts unmapping, and
frees the map before the fastrpc_internal_mmap function completes,
resulting in a use-after-free (UAF) issue. Add the map to the list after
the fastrpc_internal_mmap function completes the mapping.

Change-Id: Ia524f142edba57a1f389dd0e5c83a1967c7f5a59
Acked-by: Abhishek Singh <abhishes@qti.qualcomm.com>
Signed-off-by: Santosh Sakore <quic_ssakore@quicinc.com>
2024-06-02 22:15:45 -07:00
Akash Kumar
8ab07001b2 UPSTREAM: xhci: prepare for operation without shared HCD
This patch is reworked as multiple patches went to support target
with only one roothub.
This patch prepares xhci for the following scenario:
- If either of the root hubs has no ports, then omit shared HCD.
- The main HCD can be USB3 if there are no USB2 ports.

(cherry picked from commit
57f23cd0bf2f ("xhci: factor out parts of xhci_gen_setup().")
4a593a62a9e3a (BACKPORT: xhci: Fix null pointer dereference in removal
 if xHC has only one roothub.")
669bc5a188b40 ("UPSTREAM: xhci: Add bus number to some debug messages.")
873f323618c20 ("UPSTREAM: xhci: prepare for operation without shared HCD.)"
0cf1ea040a7e2 ("BACKPORT: usb: host: xhci-plat: create shared HCD
 after having added the main HCD.")
e0fe986972f5b ("BACKPORT: usb: host: xhci-plat: prepare operation without
 shared HCD.")
4736ebd7fcaff ("UPSTREAM: usb: host: xhci-plat: omit shared HCD if
 either root hub has no ports.")
1bd8bb7d2dfc4 ("xhci: Don't defer primary roothub registration if
 there is only one roothub.")
https: //git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
master).

Change-Id: I2ebdb15ebc2125db6ee18f14291f5590139adbdf
Signed-off-by: Akash Kumar <quic_akakum@quicinc.com>
2024-05-27 22:30:45 -07:00
Pranav Mahesh Phansalkar
4a348646df rpmsg: glink: Get reference of channel objects in rx path
Get channel references in data receive path as channel might get freed
while processing commands received from remote processor.

This ensures channel context is not freed before its usage is complete.

Change-Id: I7d9a98e34c21ae0d277456853a755dab8d105d5f
Signed-off-by: Pranav Mahesh Phansalkar <quic_pphansal@quicinc.com>
2024-05-27 14:17:44 +05:30
Vaibhav Vashisht
1ddb375967 msm_ipa: Tunnel Config structure changes
Added feature mode in the tunnel config structure.

Change-Id: I8f52e0aee00d631aca3593ec45f8f47b6dfcf464
Signed-off-by: Vaibhav Vashisht <quic_vvashish@quicinc.com>
2024-05-22 23:52:41 +05:30
Srinivasarao Pathipati
3de9978f70 soc: qcom: mdt_loader: add bound checks for headers
Add checks to ensure that ehdr's size not more than fw->size.

Change-Id: Ia17558dfff783dc900ac67475019929ac95fe53b
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2024-05-20 13:15:34 +05:30
qctecmdr
4421fcf024 Merge "msm: mhi_dev: Add UCI support if client req > TRE length" 2024-05-09 22:18:18 -07:00
Dheeraj Kumar
4dcf58f7b4 sdxnightJar.config: kernel changes for TRIGGER target
As a part of port trigger FR, the iptables rule needs to be added,
and the target TRIGGER should be enabled.

Change-Id: I32cf6bf3fd5fc6dcc7844992b026648f908495ba
Signed-off-by: Dheeraj Kumar <quic_dhekum@quicinc.com>
2024-05-06 10:56:39 +05:30
Sai Chaitanya Kaveti
52f01d5092 msm: mhi_dev: Add UCI support if client req > TRE length
Consider the following issue scenario:
1. Received client write request with size greater than single TRE
element length.
2. mhi_dev_write() is called from UCI layer to handle the request.
3. In mhi_dev_write(), packet is split into multiple packets of TRE
length and is expected to send as multiple packets of TRE length in
loop.
4. The first transfer with TRE length is initiated and MHI received a
completion call back as well.
5. As part of call back, UCI completion callback is called and the
client buffer is cleared.
6. As remaining transfers are not completed, seeing NULL pointer
dereference error while trying to process next transfers in the same
write request.

To handle this scenario from UCI layer, added the support to split the
packets into TRE length if the request size is greater than TRE length.
For this, saving and passing the minimum TRE size to UCI layer as part
of channel doorbell processing.

Change-Id: Id7468967e59effab690dacab6eca02d0f3f8ca2c
Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
2024-05-06 09:58:55 +05:30
Prashanth K
d44f01f447 usb: gadget: f_cdev: Call function wakeup if func_wakeup_pending is set
Perform function wakeup from cser_resume if func_wakup_pending
flag is true. Set it again if the func_wakeup returns -EAGAIN.

Change-Id: If056327126e932911e3d832421b6171a50757e55
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
2024-04-27 11:34:34 +05:30
Prashanth K
5caba72586 usb: gadget: f_cdev: Bail out from cer_resume if func_suspended
Currently when the device exits from U3, all the interfaces will
be resumed. In f_cdev driver, cser_resume will be called, which
will clear is_suspended flag and process pending requests.

Consider a situation where DUN interface is function suspended,
and gadget resume happens eventually clearing is_suspended flag.
Now if userspace writes something into at_usb node, f_cdev_write
will queue the request without calling func_wakeup. And since the
DUN interface is function suspended, host expects func_wakeup to
be called before queueing the data.

Fix this by bailing out from cser_resume() if function is already
suspended, and wait for the userspace to issue remote-wakeup by
writing something into at_usb node.

Change-Id: Iba9c1dfd8a5deeb6c73af3ff370d51af193ff0e9
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
2024-04-26 15:17:50 +05:30
qctecmdr
9ed4117589 Merge "msm: npu v1: Fix OOB issue in IPC between driver and firmware" 2024-04-22 15:08:06 -07:00
Jilai Wang
3396e5da36 msm: npu v1: Fix OOB issue in IPC between driver and firmware
We shoudn't trust the data from firmware, and need to validate
all content before using them.

Change-Id: I39b58f3d482931a932dab7ca4b8cc3e4d9086b36
Signed-off-by: Jilai Wang <quic_jilaiw@quicinc.com>
2024-04-22 05:35:47 -07:00
qctecmdr
aed0dc4b9e Merge "Merge android11-5.4.268+ (66f4b04) into msm-5.4" 2024-04-22 04:08:22 -07:00
Sarthak Garg
e46fa24948 mmc: sdhci-msm: Disable partial_init and clk-scaling to avoid RED error
As part of partial_init, after tuning when we're enabling CQE (Command
Queue Engine) mode, driver sends CMD44 (QUEUED_TASK_PARAM), and the
response received for this is illegal command error.

This is a temporary fix to avoid RED (Response Error Detected) error
until power and performance impact is analyzed with disabling partial_init
and clk-scaling.

Change-Id: I97833e60399d43a611342ef17a82639c9b7ea5be
Signed-off-by: Sachin Gupta <quic_sachgupt@quicinc.com>
Signed-off-by: Sarthak Garg <quic_sartgarg@quicinc.com>
Signed-off-by: Ram Prakash Gupta <quic_rampraka@quicinc.com>
2024-04-18 10:46:06 +05:30
kamasali Satyanarayan
73c5cc5b57 Merge android11-5.4.268+ (66f4b04) into msm-5.4
* remotes/origin/tmp-66f4b04:
  FROMLIST: binder: check offset alignment in binder_get_object()
  BACKPORT: f2fs: expose # of overprivision segments
  ANDROID: GKI: Update symbol list for Zebra
  ANDROID: GKI: Update symbol list for Zebra
  UPSTREAM: usb: raw-gadget: properly handle interrupted requests
  UPSTREAM: net: prevent skb corruption on frag list segmentation
  UPSTREAM: netfilter: nft_set_rbtree: skip end interval element from gc
  ANDROID: GKI: db845c: Update symbols list and ABI
  UPSTREAM: drm/msm/dsi: Enable runtime PM
  UPSTREAM: PM: runtime: Have devm_pm_runtime_enable() handle pm_runtime_dont_use_autosuspend()
  UPSTREAM: PM: runtime: add devm_pm_runtime_enable helper
  UPSTREAM: net: tls, update curr on splice as well
  Reapply "perf: Fix perf_event_validate_size()"
  UPSTREAM: ida: Fix crash in ida_free when the bitmap is empty
  UPSTREAM: netfilter: nf_tables: Reject tables of unsupported family
  FROMGIT: clk: qcom: gcc-sdm845: Add soft dependency on rpmhpd
  Linux 5.4.268
  arm64: dts: armada-3720-turris-mox: set irq type for RTC
  perf top: Skip side-band event setup if HAVE_LIBBPF_SUPPORT is not set
  i2c: s3c24xx: fix transferring more than one message in polling mode
  i2c: s3c24xx: fix read transfers in polling mode
  mlxsw: spectrum_acl_erp: Fix error flow of pool allocation failure
  kdb: Fix a potential buffer overflow in kdb_local()
  kdb: Censor attempts to set PROMPT without ENABLE_MEM_READ
  ipvs: avoid stat macros calls from preemptible context
  netfilter: nf_tables: skip dead set elements in netlink dump
  net: dsa: vsc73xx: Add null pointer check to vsc73xx_gpio_probe
  net: ravb: Fix dma_addr_t truncation in error case
  net: phy: micrel: populate .soft_reset for KSZ9131
  net: qualcomm: rmnet: fix global oob in rmnet_policy
  s390/pci: fix max size calculation in zpci_memcpy_toio()
  PCI: keystone: Fix race condition when initializing PHYs
  nvmet-tcp: Fix the H2C expected PDU len calculation
  serial: imx: Correct clock error message in function probe()
  apparmor: avoid crash when parsed profile name is empty
  perf env: Avoid recursively taking env->bpf_progs.lock
  perf bpf: Decouple creating the evlist from adding the SB event
  perf top: Move sb_evlist to 'struct perf_top'
  perf record: Move sb_evlist to 'struct record'
  perf env: Add perf_env__numa_node()
  nvmet-tcp: fix a crash in nvmet_req_complete()
  nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length
  perf genelf: Set ELF program header addresses properly
  software node: Let args be NULL in software_node_get_reference_args
  acpi: property: Let args be NULL in __acpi_node_get_property_reference
  serial: 8250: omap: Don't skip resource freeing if pm_runtime_resume_and_get() failed
  MIPS: Alchemy: Fix an out-of-bound access in db1550_dev_setup()
  MIPS: Alchemy: Fix an out-of-bound access in db1200_dev_setup()
  mips: Fix incorrect max_low_pfn adjustment
  HID: wacom: Correct behavior when processing some confidence == false touches
  x86/kvm: Do not try to disable kvmclock if it was not enabled
  wifi: mwifiex: configure BSSID consistently when starting AP
  wifi: rtlwifi: Convert LNKCTL change to PCIe cap RMW accessors
  wifi: rtlwifi: Remove bogus and dangerous ASPM disable/enable code
  rootfs: Fix support for rootfstype= when root= is given
  fbdev: flush deferred work in fb_deferred_io_fsync()
  ALSA: oxygen: Fix right channel of capture volume mixer
  usb: mon: Fix atomicity violation in mon_bin_vma_fault
  usb: typec: class: fix typec_altmode_put_partner to put plugs
  Revert "usb: typec: class: fix typec_altmode_put_partner to put plugs"
  usb: chipidea: wait controller resume finished for wakeup irq
  Revert "usb: dwc3: don't reset device side if dwc3 was configured as host-only"
  Revert "usb: dwc3: Soft reset phy on probe for host"
  usb: dwc: ep0: Update request status in dwc3_ep0_stall_restart
  usb: phy: mxs: remove CONFIG_USB_OTG condition for mxs_phy_is_otg_host()
  tick-sched: Fix idle and iowait sleeptime accounting vs CPU hotplug
  binder: fix unused alloc->free_async_space
  binder: fix race between mmput() and do_exit()
  xen-netback: don't produce zero-size SKB frags
  Revert "ASoC: atmel: Remove system clock tree configuration for at91sam9g20ek"
  Input: atkbd - use ab83 as id when skipping the getid command
  binder: fix use-after-free in shinker's callback
  binder: fix async space check for 0-sized buffers
  of: unittest: Fix of_count_phandle_with_args() expected value message
  of: Fix double free in of_parse_phandle_with_args_map
  mmc: sdhci_omap: Fix TI SoC dependencies
  clk: si5341: fix an error code problem in si5341_output_clk_set_rate
  watchdog: bcm2835_wdt: Fix WDIOC_SETTIMEOUT handling
  watchdog/hpwdt: Only claim UNKNOWN NMI if from iLO
  watchdog: set cdev owner before adding
  drivers: clk: zynqmp: calculate closest mux rate
  gpu/drm/radeon: fix two memleaks in radeon_vm_init
  drivers/amd/pm: fix a use-after-free in kv_parse_power_table
  drm/amd/pm: fix a double-free in si_dpm_init
  drm/amdgpu/debugfs: fix error code when smc register accessors are NULL
  media: dvbdev: drop refcount on error path in dvb_device_open()
  media: cx231xx: fix a memleak in cx231xx_init_isoc
  drm/bridge: tc358767: Fix return value on error case
  drm/radeon/trinity_dpm: fix a memleak in trinity_parse_power_table
  drm/radeon/dpm: fix a memleak in sumo_parse_power_table
  drm/radeon: check the alloc_workqueue return value in radeon_crtc_init()
  drm/drv: propagate errors from drm_modeset_register_all()
  drm/msm/dsi: Use pm_runtime_resume_and_get to prevent refcnt leaks
  drm/msm/mdp4: flush vblank event on disable
  ASoC: cs35l34: Fix GPIO name and drop legacy include
  ASoC: cs35l33: Fix GPIO name and drop legacy include
  drm/radeon: check return value of radeon_ring_lock()
  drm/radeon/r100: Fix integer overflow issues in r100_cs_track_check()
  drm/radeon/r600_cs: Fix possible int overflows in r600_cs_check_reg()
  f2fs: fix to avoid dirent corruption
  drm/bridge: Fix typo in post_disable() description
  media: pvrusb2: fix use after free on context disconnection
  RDMA/usnic: Silence uninitialized symbol smatch warnings
  ARM: davinci: always select CONFIG_CPU_ARM926T
  ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim()
  Bluetooth: btmtkuart: fix recv_buf() return value
  Bluetooth: Fix bogus check for re-auth no supported with non-ssp
  netfilter: nf_tables: mark newset as dead on transaction abort
  wifi: rtlwifi: rtl8192se: using calculate_bit_shift()
  wifi: rtlwifi: rtl8192ee: using calculate_bit_shift()
  wifi: rtlwifi: rtl8192de: using calculate_bit_shift()
  rtlwifi: rtl8192de: make arrays static const, makes object smaller
  wifi: rtlwifi: rtl8192ce: using calculate_bit_shift()
  wifi: rtlwifi: rtl8192cu: using calculate_bit_shift()
  wifi: rtlwifi: rtl8192c: using calculate_bit_shift()
  wifi: rtlwifi: rtl8188ee: phy: using calculate_bit_shift()
  wifi: rtlwifi: add calculate_bit_shift()
  dma-mapping: clear dev->dma_mem to NULL after freeing it
  virtio/vsock: fix logic which reduces credit update messages
  selftests/net: fix grep checking for fib_nexthop_multiprefix
  scsi: hisi_sas: Replace with standard error code return value
  arm64: dts: qcom: sdm845-db845c: correct LED panic indicator
  scsi: fnic: Return error if vmalloc() failed
  wifi: rtlwifi: rtl8821ae: phy: fix an undefined bitwise shift behavior
  rtlwifi: Use ffs in <foo>_phy_calculate_bit_shift
  firmware: ti_sci: Fix an off-by-one in ti_sci_debugfs_create()
  net/ncsi: Fix netlink major/minor version numbers
  ncsi: internal.h: Fix a spello
  ARM: dts: qcom: apq8064: correct XOADC register address
  wifi: libertas: stop selecting wext
  bpf, lpm: Fix check prefixlen before walking trie
  wifi: rtw88: fix RX filter in FIF_ALLMULTI flag
  NFSv4.1/pnfs: Ensure we handle the error NFS4ERR_RETURNCONFLICT
  blocklayoutdriver: Fix reference leak of pnfs_device_node
  crypto: scomp - fix req->dst buffer overflow
  crypto: sahara - do not resize req->src when doing hash operations
  crypto: sahara - fix processing hash requests with req->nbytes < sg->length
  crypto: sahara - improve error handling in sahara_sha_process()
  crypto: sahara - fix wait_for_completion_timeout() error handling
  crypto: sahara - fix ahash reqsize
  crypto: virtio - Wait for tasklet to complete on device remove
  gfs2: Fix kernel NULL pointer dereference in gfs2_rgrp_dump
  pstore: ram_core: fix possible overflow in persistent_ram_init_ecc()
  crypto: sahara - fix error handling in sahara_hw_descriptor_create()
  crypto: sahara - fix processing requests with cryptlen < sg->length
  crypto: sahara - fix ahash selftest failure
  crypto: sahara - remove FLAGS_NEW_KEY logic
  crypto: af_alg - Disallow multiple in-flight AIO requests
  crypto: ccp - fix memleak in ccp_init_dm_workarea
  virtio_crypto: Introduce VIRTIO_CRYPTO_NOSPC
  crypto: virtio - don't use 'default m'
  crypto: virtio - Handle dataq logic with tasklet
  selinux: Fix error priority for bind with AF_UNSPEC on PF_INET6 socket
  mtd: Fix gluebi NULL pointer dereference caused by ftl notifier
  spi: sh-msiof: Enforce fixed DTDL for R-Car H3
  calipso: fix memory leak in netlbl_calipso_add_pass()
  netlabel: remove unused parameter in netlbl_netlink_auditinfo()
  net: netlabel: Fix kerneldoc warnings
  ACPI: LPIT: Avoid u32 multiplication overflow
  ACPI: video: check for error while searching for backlight device parent
  mtd: rawnand: Increment IFC_TIMEOUT_MSECS for nand controller response
  powerpc/imc-pmu: Add a null pointer check in update_events_in_group()
  powerpc/powernv: Add a null pointer check in opal_powercap_init()
  powerpc/powernv: Add a null pointer check in opal_event_init()
  powerpc/powernv: Add a null pointer check to scom_debug_init_one()
  selftests/powerpc: Fix error handling in FPU/VMX preemption tests
  powerpc/pseries/memhp: Fix access beyond end of drmem array
  powerpc/pseries/memhotplug: Quieten some DLPAR operations
  powerpc/44x: select I2C for CURRITUCK
  powerpc: add crtsavres.o to always-y instead of extra-y
  EDAC/thunderx: Fix possible out-of-bounds string access
  x86/lib: Fix overflow when counting digits
  coresight: etm4x: Fix width of CCITMIN field
  parport: parport_serial: Add Brainboxes device IDs and geometry
  parport: parport_serial: Add Brainboxes BAR details
  uio: Fix use-after-free in uio_open
  binder: fix comment on binder_alloc_new_buf() return value
  binder: fix trivial typo of binder_free_buf_locked()
  binder: use EPOLLERR from eventpoll.h
  ACPI: resource: Add another DMI match for the TongFang GMxXGxx
  drm/crtc: fix uninitialized variable use
  ARM: sun9i: smp: fix return code check of of_property_match_string
  ida: Fix crash in ida_free when the bitmap is empty
  Input: xpad - add Razer Wolverine V2 support
  ARC: fix spare error
  s390/scm: fix virtual vs physical address confusion
  Input: i8042 - add nomux quirk for Acer P459-G2-M
  Input: atkbd - skip ATKBD_CMD_GETID in translated mode
  reset: hisilicon: hi6220: fix Wvoid-pointer-to-enum-cast warning
  ring-buffer: Do not record in NMI if the arch does not support cmpxchg in NMI
  tracing: Add size check when printing trace_marker output
  tracing: Have large events show up as '[LINE TOO BIG]' instead of nothing
  neighbour: Don't let neigh_forced_gc() disable preemption for long
  drm/crtc: Fix uninit-value bug in drm_mode_setcrtc
  jbd2: correct the printing of write_flags in jbd2_write_superblock()
  clk: rockchip: rk3128: Fix HCLK_OTG gate register
  drm/exynos: fix a wrong error checking
  drm/exynos: fix a potential error pointer dereference
  nvme: introduce helper function to get ctrl state
  ASoC: da7219: Support low DC impedance headset
  net/tg3: fix race condition in tg3_reset_task()
  nouveau/tu102: flush all pdbs on vmm flush
  ASoC: rt5650: add mutex to avoid the jack detection failure
  ASoC: cs43130: Fix incorrect frame delay configuration
  ASoC: cs43130: Fix the position of const qualifier
  ASoC: Intel: Skylake: mem leak in skl register function
  ASoC: nau8822: Fix incorrect type in assignment and cast to restricted __be16
  ASoC: Intel: Skylake: Fix mem leak in few functions
  ALSA: hda - Fix speaker and headset mic pin config for CHUWI CoreBook XPro
  pinctrl: lochnagar: Don't build on MIPS
  f2fs: explicitly null-terminate the xattr list
  Revert "ipv6: make ip6_rt_gc_expire an atomic_t"
  Revert "ipv6: remove max_size check inline with ipv4"
  Linux 5.4.267
  ASoC: meson: codec-glue: fix pcm format cast warning
  ipv6: remove max_size check inline with ipv4
  ipv6: make ip6_rt_gc_expire an atomic_t
  net/dst: use a smaller percpu_counter batch for dst entries accounting
  PCI: Disable ATS for specific Intel IPU E2000 devices
  PCI: Extract ATS disabling to a helper function
  netfilter: nf_tables: Reject tables of unsupported family
  net: tls, update curr on splice as well
  ath10k: Get rid of "per_ce_irq" hw param
  ath10k: Keep track of which interrupts fired, don't poll them
  ath10k: Add interrupt summary based CE processing
  ath10k: Wait until copy complete is actually done before completing
  mmc: sdhci-sprd: Fix eMMC init failure after hw reset
  mmc: core: Cancel delayed work before releasing host
  mmc: rpmb: fixes pause retune on all RPMB partitions.
  mm: fix unmap_mapping_range high bits shift bug
  i2c: core: Fix atomic xfer check for non-preempt config
  firewire: ohci: suppress unexpected system reboot in AMD Ryzen machines and ASM108x/VT630x PCIe cards
  mm/memory-failure: check the mapcount of the precise page
  net: Implement missing SO_TIMESTAMPING_NEW cmsg support
  bnxt_en: Remove mis-applied code from bnxt_cfg_ntp_filters()
  asix: Add check for usbnet_get_endpoints
  net/qla3xxx: fix potential memleak in ql_alloc_buffer_queues
  net/qla3xxx: switch from 'pci_' to 'dma_' API
  i40e: Restore VF MSI-X state during PCI reset
  ASoC: meson: g12a-tohdmitx: Fix event generation for S/PDIF mux
  ASoC: meson: g12a-tohdmitx: Validate written enum values
  ASoC: meson: g12a: extract codec-to-codec utils
  i40e: fix use-after-free in i40e_aqc_add_filters()
  net: Save and restore msg_namelen in sock_sendmsg
  net: bcmgenet: Fix FCS generation for fragmented skbuffs
  ARM: sun9i: smp: Fix array-index-out-of-bounds read in sunxi_mc_smp_init
  net-timestamp: extend SOF_TIMESTAMPING_OPT_ID to HW timestamps
  can: raw: add support for SO_MARK
  can: raw: add support for SO_TXTIME/SCM_TXTIME
  net: sched: em_text: fix possible memory leak in em_text_destroy()
  i40e: Fix filter input checks to prevent config with invalid values
  nfc: llcp_core: Hold a ref to llcp_local->dev when holding a ref to llcp_local
  ANDROID: db845c: Enable device tree overlay support
  Linux 5.4.266
  block: Don't invalidate pagecache for invalid falloc modes
  ring-buffer: Fix wake ups when buffer_percent is set to 100
  smb: client: fix OOB in smbCalcSize()
  usb: fotg210-hcd: delete an incorrect bounds test
  x86/alternatives: Sync core before enabling interrupts
  net: rfkill: gpio: set GPIO direction
  net: 9p: avoid freeing uninit memory in p9pdu_vreadf
  Bluetooth: hci_event: Fix not checking if HCI_OP_INQUIRY has been sent
  USB: serial: option: add Quectel RM500Q R13 firmware support
  USB: serial: option: add Foxconn T99W265 with new baseline
  USB: serial: option: add Quectel EG912Y module support
  USB: serial: ftdi_sio: update Actisense PIDs constant names
  wifi: cfg80211: fix certs build to not depend on file order
  wifi: cfg80211: Add my certificate
  iio: adc: ti_am335x_adc: Fix return value check of tiadc_request_dma()
  iio: common: ms_sensors: ms_sensors_i2c: fix humidity conversion time table
  scsi: bnx2fc: Fix skb double free in bnx2fc_rcv()
  Input: ipaq-micro-keys - add error handling for devm_kmemdup
  iio: imu: inv_mpu6050: fix an error code problem in inv_mpu6050_read_raw
  interconnect: Treat xlate() returning NULL node as an error
  btrfs: do not allow non subvolume root targets for snapshot
  smb: client: fix NULL deref in asn1_ber_decoder()
  ALSA: hda/hdmi: add force-connect quirk for NUC5CPYB
  ALSA: hda/hdmi: Add quirk to force pin connectivity on NUC10
  pinctrl: at91-pio4: use dedicated lock class for IRQ
  i2c: aspeed: Handle the coalesced stop conditions with the start conditions.
  afs: Fix overwriting of result of DNS query
  net: check dev->gso_max_size in gso_features_check()
  net: warn if gso_type isn't set for a GSO SKB
  afs: Fix dynamic root lookup DNS check
  afs: Fix the dynamic root's d_delete to always delete unused dentries
  net: check vlan filter feature in vlan_vids_add_by_dev() and vlan_vids_del_by_dev()
  net/rose: fix races in rose_kill_by_device()
  ethernet: atheros: fix a memleak in atl1e_setup_ring_resources
  net: sched: ife: fix potential use-after-free
  net/mlx5e: Correct snprintf truncation handling for fw_version buffer used by representors
  net/mlx5: Fix fw tracer first block check
  net/mlx5: improve some comments
  Revert "net/mlx5e: fix double free of encap_header"
  wifi: mac80211: mesh_plink: fix matches_local logic
  s390/vx: fix save/restore of fpu kernel context
  reset: Fix crash when freeing non-existent optional resets
  ARM: OMAP2+: Fix null pointer dereference and memory leak in omap_soc_device_init
  ksmbd: fix wrong name of SMB2_CREATE_ALLOCATION_SIZE
  ALSA: hda/realtek: Enable headset on Lenovo M90 Gen5

Conflicts:
     both modified:   mm/memory-failure.c

Change-Id: Ifeefc7da79e516a9e27c3046430c00ec67ec8c1a
Signed-off-by: kamasali Satyanarayan <quic_kamasali@quicinc.com>
2024-04-10 23:53:13 -07:00
Carlos Llamas
66f4b04cb0 FROMLIST: binder: check offset alignment in binder_get_object()
Commit 6d98eb95b450 ("binder: avoid potential data leakage when copying
txn") introduced changes to how binder objects are copied. In doing so,
it unintentionally removed an offset alignment check done through calls
to binder_alloc_copy_from_buffer() -> check_buffer().

These calls were replaced in binder_get_object() with copy_from_user(),
so now an explicit offset alignment check is needed here. This avoids
later complications when unwinding the objects gets harder.

It is worth noting this check existed prior to commit 7a67a39320
("binder: add function to copy binder object from buffer"), likely
removed due to redundancy at the time.

Fixes: 6d98eb95b450 ("binder: avoid potential data leakage when copying txn")
Cc:  <stable@vger.kernel.org>
Acked-by: Todd Kjos <tkjos@google.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>

Bug: 320661088
Link: https://lore.kernel.org/all/20240330190115.1877819-1-cmllamas@google.com/
Change-Id: Iaddabaa28de7ba7b7d35dbb639d38ca79dbc5077
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-04-01 16:16:30 +00:00
Greg Kroah-Hartman
7570ec5696 Merge tag 'android11-5.4.268_r00' into android11-5.4
This merges up to the 5.4.268 LTS release into the android11-5.4 branch.
included in here are the following commits:

* 8eb6062606 ANDROID: GKI: db845c: Update symbols list and ABI
*   5400c339e0 Merge "Merge branch 'android11-5.4' into branch 'android11-5.4-lts'" into android11-5.4-lts
|\
| * 16a567b6c7 Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
* | c980fbd6a6 UPSTREAM: drm/msm/dsi: Enable runtime PM
* | 7c607fec96 UPSTREAM: PM: runtime: Have devm_pm_runtime_enable() handle pm_runtime_dont_use_autosuspend()
* | f9f96d9da7 UPSTREAM: PM: runtime: add devm_pm_runtime_enable helper
|/
* b70f9975af FROMGIT: clk: qcom: gcc-sdm845: Add soft dependency on rpmhpd
*   74299cb130 Merge 5.4.268 into android11-5.4-lts
|\
| * f0602893f4 Linux 5.4.268
| * 5ff9836ab0 arm64: dts: armada-3720-turris-mox: set irq type for RTC
| * 300a55a3a6 perf top: Skip side-band event setup if HAVE_LIBBPF_SUPPORT is not set
| * ea5587946a i2c: s3c24xx: fix transferring more than one message in polling mode
| * 90734f1cde i2c: s3c24xx: fix read transfers in polling mode
| * 05b6d0234a mlxsw: spectrum_acl_erp: Fix error flow of pool allocation failure
| * d5661f46c1 kdb: Fix a potential buffer overflow in kdb_local()
| * cf6260a34d kdb: Censor attempts to set PROMPT without ENABLE_MEM_READ
| * 36b6db699c ipvs: avoid stat macros calls from preemptible context
| * 4c8a827d68 netfilter: nf_tables: skip dead set elements in netlink dump
| * db9fda526c net: dsa: vsc73xx: Add null pointer check to vsc73xx_gpio_probe
| * 8efe3e8a6c net: ravb: Fix dma_addr_t truncation in error case
| * f7a153e3ac net: phy: micrel: populate .soft_reset for KSZ9131
| * 02467ab8b4 net: qualcomm: rmnet: fix global oob in rmnet_policy
| * 5b58cfcd4c s390/pci: fix max size calculation in zpci_memcpy_toio()
| * 14a7e3a0d0 PCI: keystone: Fix race condition when initializing PHYs
| * 40d171ef23 nvmet-tcp: Fix the H2C expected PDU len calculation
| * 258dccd67b serial: imx: Correct clock error message in function probe()
| * 1d8e62b556 apparmor: avoid crash when parsed profile name is empty
| * 4cd5db4fc4 perf env: Avoid recursively taking env->bpf_progs.lock
| * f19a1cb1f9 perf bpf: Decouple creating the evlist from adding the SB event
| * 739b800279 perf top: Move sb_evlist to 'struct perf_top'
| * 2d59b6ed99 perf record: Move sb_evlist to 'struct record'
| * 14a9769a76 perf env: Add perf_env__numa_node()
| * 9638beb4e1 nvmet-tcp: fix a crash in nvmet_req_complete()
| * ee5e7632e9 nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length
| * 887ab0a444 perf genelf: Set ELF program header addresses properly
| * ed903eeb4e software node: Let args be NULL in software_node_get_reference_args
| * dbb71ba531 acpi: property: Let args be NULL in __acpi_node_get_property_reference
| * b502fb43f7 serial: 8250: omap: Don't skip resource freeing if pm_runtime_resume_and_get() failed
| * d8003fdcc6 MIPS: Alchemy: Fix an out-of-bound access in db1550_dev_setup()
| * 93a7b8d433 MIPS: Alchemy: Fix an out-of-bound access in db1200_dev_setup()
| * fa873e9030 mips: Fix incorrect max_low_pfn adjustment
| * b419fe1180 HID: wacom: Correct behavior when processing some confidence == false touches
| * f7a92bec8e x86/kvm: Do not try to disable kvmclock if it was not enabled
| * 1d6d95aaa6 wifi: mwifiex: configure BSSID consistently when starting AP
| * 249b78dbb1 wifi: rtlwifi: Convert LNKCTL change to PCIe cap RMW accessors
| * c22b4f159b wifi: rtlwifi: Remove bogus and dangerous ASPM disable/enable code
| * b33a303588 rootfs: Fix support for rootfstype= when root= is given
| * 02bd78673b fbdev: flush deferred work in fb_deferred_io_fsync()
| * 7cfc97d1ec ALSA: oxygen: Fix right channel of capture volume mixer
| * 85f6a6590d usb: mon: Fix atomicity violation in mon_bin_vma_fault
| * 14e60d584a usb: typec: class: fix typec_altmode_put_partner to put plugs
| * 94f2aa8145 Revert "usb: typec: class: fix typec_altmode_put_partner to put plugs"
| * a05ebd5779 usb: chipidea: wait controller resume finished for wakeup irq
| * d9c8275c59 Revert "usb: dwc3: don't reset device side if dwc3 was configured as host-only"
| * 548a00780d Revert "usb: dwc3: Soft reset phy on probe for host"
| * c145217af8 usb: dwc: ep0: Update request status in dwc3_ep0_stall_restart
| * 5d5d982701 usb: phy: mxs: remove CONFIG_USB_OTG condition for mxs_phy_is_otg_host()
| * 29032c8e3e tick-sched: Fix idle and iowait sleeptime accounting vs CPU hotplug
| * 5c3d4930c7 binder: fix unused alloc->free_async_space
| * 252a2a5569 binder: fix race between mmput() and do_exit()
| * 4404c2b832 xen-netback: don't produce zero-size SKB frags
| * ee4e9c5fff Revert "ASoC: atmel: Remove system clock tree configuration for at91sam9g20ek"
| * 01fe1b7bb0 Input: atkbd - use ab83 as id when skipping the getid command
| * a53e15e592 binder: fix use-after-free in shinker's callback
| * fc1119a3c6 binder: fix async space check for 0-sized buffers
| * 1b7c039260 of: unittest: Fix of_count_phandle_with_args() expected value message
| * a0a061151a of: Fix double free in of_parse_phandle_with_args_map
| * a9de8a4f52 mmc: sdhci_omap: Fix TI SoC dependencies
| * b8bbe33544 clk: si5341: fix an error code problem in si5341_output_clk_set_rate
| * 4810cce029 watchdog: bcm2835_wdt: Fix WDIOC_SETTIMEOUT handling
| * 11a64041d9 watchdog/hpwdt: Only claim UNKNOWN NMI if from iLO
| * 0d5685c13d watchdog: set cdev owner before adding
| * 777aa44f63 drivers: clk: zynqmp: calculate closest mux rate
| * 5a572eb32f gpu/drm/radeon: fix two memleaks in radeon_vm_init
| * 8b55b06e73 drivers/amd/pm: fix a use-after-free in kv_parse_power_table
| * 06d95c99d5 drm/amd/pm: fix a double-free in si_dpm_init
| * 8ee1fb4c51 drm/amdgpu/debugfs: fix error code when smc register accessors are NULL
| * 68ec0a0211 media: dvbdev: drop refcount on error path in dvb_device_open()
| * 06a9263ac9 media: cx231xx: fix a memleak in cx231xx_init_isoc
| * 6a421928f7 drm/bridge: tc358767: Fix return value on error case
| * d46fe2e93e drm/radeon/trinity_dpm: fix a memleak in trinity_parse_power_table
| * c0769f091f drm/radeon/dpm: fix a memleak in sumo_parse_power_table
| * 5d12c5d75f drm/radeon: check the alloc_workqueue return value in radeon_crtc_init()
| * 09d59f73f4 drm/drv: propagate errors from drm_modeset_register_all()
| * 31b169a8be drm/msm/dsi: Use pm_runtime_resume_and_get to prevent refcnt leaks
| * 9170aa07cb drm/msm/mdp4: flush vblank event on disable
| * 136f919816 ASoC: cs35l34: Fix GPIO name and drop legacy include
| * 86af5d7acf ASoC: cs35l33: Fix GPIO name and drop legacy include
| * 94aa82723a drm/radeon: check return value of radeon_ring_lock()
| * bf48d89123 drm/radeon/r100: Fix integer overflow issues in r100_cs_track_check()
| * 8e5bcb781f drm/radeon/r600_cs: Fix possible int overflows in r600_cs_check_reg()
| * 5624a3c1b1 f2fs: fix to avoid dirent corruption
| * b083ec00f3 drm/bridge: Fix typo in post_disable() description
| * 47aa8fcd5e media: pvrusb2: fix use after free on context disconnection
| * f6a35c21cd RDMA/usnic: Silence uninitialized symbol smatch warnings
| * 9bb9775217 ARM: davinci: always select CONFIG_CPU_ARM926T
| * 3f15ba3dc1 ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim()
| * dcc9cd5ddb Bluetooth: btmtkuart: fix recv_buf() return value
| * efcfcd5f2b Bluetooth: Fix bogus check for re-auth no supported with non-ssp
| * 598c902649 netfilter: nf_tables: mark newset as dead on transaction abort
| * 8dbaaf71ff wifi: rtlwifi: rtl8192se: using calculate_bit_shift()
| * 8fa54f7532 wifi: rtlwifi: rtl8192ee: using calculate_bit_shift()
| * 4838d16666 wifi: rtlwifi: rtl8192de: using calculate_bit_shift()
| * e15fcb1945 rtlwifi: rtl8192de: make arrays static const, makes object smaller
| * ae1df4cc0a wifi: rtlwifi: rtl8192ce: using calculate_bit_shift()
| * a3a25b5d01 wifi: rtlwifi: rtl8192cu: using calculate_bit_shift()
| * 6f84a338ed wifi: rtlwifi: rtl8192c: using calculate_bit_shift()
| * ee0a81cf7e wifi: rtlwifi: rtl8188ee: phy: using calculate_bit_shift()
| * 7cbcf5fe01 wifi: rtlwifi: add calculate_bit_shift()
| * 4985e507e0 dma-mapping: clear dev->dma_mem to NULL after freeing it
| * 48614d528b virtio/vsock: fix logic which reduces credit update messages
| * 332cd73a92 selftests/net: fix grep checking for fib_nexthop_multiprefix
| * 12b91f3636 scsi: hisi_sas: Replace with standard error code return value
| * 14470da02d arm64: dts: qcom: sdm845-db845c: correct LED panic indicator
| * c23c4984ce scsi: fnic: Return error if vmalloc() failed
| * 16d21bfcb3 wifi: rtlwifi: rtl8821ae: phy: fix an undefined bitwise shift behavior
| * 4a20fa7322 rtlwifi: Use ffs in <foo>_phy_calculate_bit_shift
| * 0226926ba3 firmware: ti_sci: Fix an off-by-one in ti_sci_debugfs_create()
| * ef75f3c56b net/ncsi: Fix netlink major/minor version numbers
| * 7276fac0a6 ncsi: internal.h: Fix a spello
| * f6154d4983 ARM: dts: qcom: apq8064: correct XOADC register address
| * bd1bf5e805 wifi: libertas: stop selecting wext
| * dc843ed97d bpf, lpm: Fix check prefixlen before walking trie
| * 93c71706a1 wifi: rtw88: fix RX filter in FIF_ALLMULTI flag
| * aebe7e47c2 NFSv4.1/pnfs: Ensure we handle the error NFS4ERR_RETURNCONFLICT
| * db55dbbba5 blocklayoutdriver: Fix reference leak of pnfs_device_node
| * e0e3f4a187 crypto: scomp - fix req->dst buffer overflow
| * 77d2b18336 crypto: sahara - do not resize req->src when doing hash operations
| * 53ba86f765 crypto: sahara - fix processing hash requests with req->nbytes < sg->length
| * ba1ef4276e crypto: sahara - improve error handling in sahara_sha_process()
| * 0274697075 crypto: sahara - fix wait_for_completion_timeout() error handling
| * b588ed190b crypto: sahara - fix ahash reqsize
| * aea92cca43 crypto: virtio - Wait for tasklet to complete on device remove
| * efc8ef87ab gfs2: Fix kernel NULL pointer dereference in gfs2_rgrp_dump
| * d1fe1aede6 pstore: ram_core: fix possible overflow in persistent_ram_init_ecc()
| * 6e907574ef crypto: sahara - fix error handling in sahara_hw_descriptor_create()
| * e82d07d5c7 crypto: sahara - fix processing requests with cryptlen < sg->length
| * da43c26203 crypto: sahara - fix ahash selftest failure
| * beb815a000 crypto: sahara - remove FLAGS_NEW_KEY logic
| * 4c10928e31 crypto: af_alg - Disallow multiple in-flight AIO requests
| * ca3484d5ca crypto: ccp - fix memleak in ccp_init_dm_workarea
| * 9fffae6cc4 virtio_crypto: Introduce VIRTIO_CRYPTO_NOSPC
| * 01081d76cc crypto: virtio - don't use 'default m'
| * 830a4f073f crypto: virtio - Handle dataq logic with tasklet
| * 86a7c9ba83 selinux: Fix error priority for bind with AF_UNSPEC on PF_INET6 socket
| * 1bf4fe14e9 mtd: Fix gluebi NULL pointer dereference caused by ftl notifier
| * 6b84cb9e38 spi: sh-msiof: Enforce fixed DTDL for R-Car H3
| * 36e19f8463 calipso: fix memory leak in netlbl_calipso_add_pass()
| * 0396c1e211 netlabel: remove unused parameter in netlbl_netlink_auditinfo()
| * 7b99eafea0 net: netlabel: Fix kerneldoc warnings
| * 6c38e791bd ACPI: LPIT: Avoid u32 multiplication overflow
| * 1e3a2b9b40 ACPI: video: check for error while searching for backlight device parent
| * f5ea2cf3bb mtd: rawnand: Increment IFC_TIMEOUT_MSECS for nand controller response
| * 1e80aa25d1 powerpc/imc-pmu: Add a null pointer check in update_events_in_group()
| * 9da4a56dd3 powerpc/powernv: Add a null pointer check in opal_powercap_init()
| * e93d7cf4c1 powerpc/powernv: Add a null pointer check in opal_event_init()
| * f84c1446da powerpc/powernv: Add a null pointer check to scom_debug_init_one()
| * b0200560b6 selftests/powerpc: Fix error handling in FPU/VMX preemption tests
| * 9b5f03500b powerpc/pseries/memhp: Fix access beyond end of drmem array
| * 69c0b92f78 powerpc/pseries/memhotplug: Quieten some DLPAR operations
| * 5401b689ad powerpc/44x: select I2C for CURRITUCK
| * 245da9eebb powerpc: add crtsavres.o to always-y instead of extra-y
| * 5da3b6e719 EDAC/thunderx: Fix possible out-of-bounds string access
| * 555a2f09a6 x86/lib: Fix overflow when counting digits
| * 6ee48d7102 coresight: etm4x: Fix width of CCITMIN field
| * b00d5f7152 parport: parport_serial: Add Brainboxes device IDs and geometry
| * 760a5ab4d8 parport: parport_serial: Add Brainboxes BAR details
| * e93da893d5 uio: Fix use-after-free in uio_open
| * da488e1aad binder: fix comment on binder_alloc_new_buf() return value
| * a92b2797ca binder: fix trivial typo of binder_free_buf_locked()
| * 9774dabad7 binder: use EPOLLERR from eventpoll.h
| * 5e1eb0dfc9 ACPI: resource: Add another DMI match for the TongFang GMxXGxx
| * c5b0517500 drm/crtc: fix uninitialized variable use
| * cfc6afe930 ARM: sun9i: smp: fix return code check of of_property_match_string
| * ef7152f870 ida: Fix crash in ida_free when the bitmap is empty
| * c97996451f Input: xpad - add Razer Wolverine V2 support
| * 510a7bc368 ARC: fix spare error
| * 0fe6431622 s390/scm: fix virtual vs physical address confusion
| * 8fb5795bcf Input: i8042 - add nomux quirk for Acer P459-G2-M
| * 2c70bf9978 Input: atkbd - skip ATKBD_CMD_GETID in translated mode
| * 3d9a9c0881 reset: hisilicon: hi6220: fix Wvoid-pointer-to-enum-cast warning
| * 4f7512e779 ring-buffer: Do not record in NMI if the arch does not support cmpxchg in NMI
| * e405c22ee5 tracing: Add size check when printing trace_marker output
| * f787481af4 tracing: Have large events show up as '[LINE TOO BIG]' instead of nothing
| * d4408ffeb8 neighbour: Don't let neigh_forced_gc() disable preemption for long
| * 9cc9683aec drm/crtc: Fix uninit-value bug in drm_mode_setcrtc
| * 2f601e8696 jbd2: correct the printing of write_flags in jbd2_write_superblock()
| * 1c187cb210 clk: rockchip: rk3128: Fix HCLK_OTG gate register
| * 3f50a73fd9 drm/exynos: fix a wrong error checking
| * 8bc21ac17d drm/exynos: fix a potential error pointer dereference
| * 6eb9759328 nvme: introduce helper function to get ctrl state
| * 971c0b10c9 ASoC: da7219: Support low DC impedance headset
| * ec76b9e057 net/tg3: fix race condition in tg3_reset_task()
| * ef9fefca3f nouveau/tu102: flush all pdbs on vmm flush
| * b67005b284 ASoC: rt5650: add mutex to avoid the jack detection failure
| * 4fece6617b ASoC: cs43130: Fix incorrect frame delay configuration
| * 1bf33a67a9 ASoC: cs43130: Fix the position of const qualifier
| * 61c1e46fb8 ASoC: Intel: Skylake: mem leak in skl register function
| * 81610106fd ASoC: nau8822: Fix incorrect type in assignment and cast to restricted __be16
| * ad5a06e163 ASoC: Intel: Skylake: Fix mem leak in few functions
| * 57a95d06da ALSA: hda - Fix speaker and headset mic pin config for CHUWI CoreBook XPro
| * ebc3c8e090 pinctrl: lochnagar: Don't build on MIPS
| * 12cf91e23b f2fs: explicitly null-terminate the xattr list
* | 5826ec2af1 Revert "ipv6: make ip6_rt_gc_expire an atomic_t"
* | fa82780056 Revert "ipv6: remove max_size check inline with ipv4"
* |   bc9b1af36e Merge "Merge 5.4.267 into android11-5.4-lts" into android11-5.4-lts
|\ \
| * | ac7d08f396 Merge 5.4.267 into android11-5.4-lts
| |\|
| | * 9153fc9664 Linux 5.4.267
| | * 69ef165176 ASoC: meson: codec-glue: fix pcm format cast warning
| | * 584756c3d7 ipv6: remove max_size check inline with ipv4
| | * 66b3025202 ipv6: make ip6_rt_gc_expire an atomic_t
| | * ae424c848d net/dst: use a smaller percpu_counter batch for dst entries accounting
| | * 7b3a9c2bf3 PCI: Disable ATS for specific Intel IPU E2000 devices
| | * c6141c49bc PCI: Extract ATS disabling to a helper function
| | * 8711fa0c06 netfilter: nf_tables: Reject tables of unsupported family
| | * c67bf30baf net: tls, update curr on splice as well
| | * c2d9b43855 ath10k: Get rid of "per_ce_irq" hw param
| | * d15f869cb3 ath10k: Keep track of which interrupts fired, don't poll them
| | * 696b992edc ath10k: Add interrupt summary based CE processing
| | * 366df9ecbc ath10k: Wait until copy complete is actually done before completing
| | * c4541e3980 mmc: sdhci-sprd: Fix eMMC init failure after hw reset
| | * a9c9ffcd21 mmc: core: Cancel delayed work before releasing host
| | * bfc3720ca8 mmc: rpmb: fixes pause retune on all RPMB partitions.
| | * 77359c4973 mm: fix unmap_mapping_range high bits shift bug
| | * 5af5e946c4 i2c: core: Fix atomic xfer check for non-preempt config
| | * d8ec24d79d firewire: ohci: suppress unexpected system reboot in AMD Ryzen machines and ASM108x/VT630x PCIe cards
| | * 85015a96bc mm/memory-failure: check the mapcount of the precise page
| | * 3d8fab93ca net: Implement missing SO_TIMESTAMPING_NEW cmsg support
| | * f7084217d9 bnxt_en: Remove mis-applied code from bnxt_cfg_ntp_filters()
| | * acfeb9039b asix: Add check for usbnet_get_endpoints
| | * 6c00721ad7 net/qla3xxx: fix potential memleak in ql_alloc_buffer_queues
| | * a4ea54c528 net/qla3xxx: switch from 'pci_' to 'dma_' API
| | * 863ca421b4 i40e: Restore VF MSI-X state during PCI reset
| | * 01c2d73ae2 ASoC: meson: g12a-tohdmitx: Fix event generation for S/PDIF mux
| | * bdc00b8c3a ASoC: meson: g12a-tohdmitx: Validate written enum values
| | * fe2d1dda1d ASoC: meson: g12a: extract codec-to-codec utils
| | * 93d80aadc0 i40e: fix use-after-free in i40e_aqc_add_filters()
| | * b40828a2ab net: Save and restore msg_namelen in sock_sendmsg
| | * 68c8fdb9f9 net: bcmgenet: Fix FCS generation for fragmented skbuffs
| | * 4c0fa624a6 ARM: sun9i: smp: Fix array-index-out-of-bounds read in sunxi_mc_smp_init
| | * c1556217ff net-timestamp: extend SOF_TIMESTAMPING_OPT_ID to HW timestamps
| | * 2cdb650848 can: raw: add support for SO_MARK
| | * 96a6d1bb28 can: raw: add support for SO_TXTIME/SCM_TXTIME
| | * b1719cbb73 net: sched: em_text: fix possible memory leak in em_text_destroy()
| | * ef4fd7518c i40e: Fix filter input checks to prevent config with invalid values
| | * 65c6ef02ff nfc: llcp_core: Hold a ref to llcp_local->dev when holding a ref to llcp_local
* | | 6ba3eed4fa ANDROID: db845c: Enable device tree overlay support
|/ /
* / 0d5ac7fe30 Merge 5.4.266 into android11-5.4-lts
|/
* 4410df7011 Linux 5.4.266
* 7d0f1fd80a block: Don't invalidate pagecache for invalid falloc modes
* a0678f5047 ring-buffer: Fix wake ups when buffer_percent is set to 100
* 508e2fdd97 smb: client: fix OOB in smbCalcSize()
* 644b956c94 usb: fotg210-hcd: delete an incorrect bounds test
* a56a19e44b x86/alternatives: Sync core before enabling interrupts
* 4111986fb9 net: rfkill: gpio: set GPIO direction
* 5c375a83d1 net: 9p: avoid freeing uninit memory in p9pdu_vreadf
* 4e7f3899fb Bluetooth: hci_event: Fix not checking if HCI_OP_INQUIRY has been sent
* a83debb523 USB: serial: option: add Quectel RM500Q R13 firmware support
* c82ba4cb44 USB: serial: option: add Foxconn T99W265 with new baseline
* 1f87ba56c4 USB: serial: option: add Quectel EG912Y module support
* a59cb26bc1 USB: serial: ftdi_sio: update Actisense PIDs constant names
* a70b1933fa wifi: cfg80211: fix certs build to not depend on file order
* e8fb002051 wifi: cfg80211: Add my certificate
* 8717fd6d0c iio: adc: ti_am335x_adc: Fix return value check of tiadc_request_dma()
* 45af72f149 iio: common: ms_sensors: ms_sensors_i2c: fix humidity conversion time table
* 4257c16c14 scsi: bnx2fc: Fix skb double free in bnx2fc_rcv()
* e1b31edfe7 Input: ipaq-micro-keys - add error handling for devm_kmemdup
* a85d6aa2b5 iio: imu: inv_mpu6050: fix an error code problem in inv_mpu6050_read_raw
* 388c90c577 interconnect: Treat xlate() returning NULL node as an error
* 04c2223344 btrfs: do not allow non subvolume root targets for snapshot
* 3230a69e66 smb: client: fix NULL deref in asn1_ber_decoder()
* 0ccb39511a ALSA: hda/hdmi: add force-connect quirk for NUC5CPYB
* 6bcf819198 ALSA: hda/hdmi: Add quirk to force pin connectivity on NUC10
* 34e6c4c6a9 pinctrl: at91-pio4: use dedicated lock class for IRQ
* 624659563e i2c: aspeed: Handle the coalesced stop conditions with the start conditions.
* 47ae524229 afs: Fix overwriting of result of DNS query
* c04b7b28c9 net: check dev->gso_max_size in gso_features_check()
* 761ee09e9f net: warn if gso_type isn't set for a GSO SKB
* eec7ef60d2 afs: Fix dynamic root lookup DNS check
* 82d64cbe48 afs: Fix the dynamic root's d_delete to always delete unused dentries
* 2b4600fb69 net: check vlan filter feature in vlan_vids_add_by_dev() and vlan_vids_del_by_dev()
* b10265532d net/rose: fix races in rose_kill_by_device()
* ed4cb8a42c ethernet: atheros: fix a memleak in atl1e_setup_ring_resources
* 3f82a6a6d7 net: sched: ife: fix potential use-after-free
* f48e3337ab net/mlx5e: Correct snprintf truncation handling for fw_version buffer used by representors
* d07ef3a870 net/mlx5: Fix fw tracer first block check
* a46bb28fdb net/mlx5: improve some comments
* 333fd10955 Revert "net/mlx5e: fix double free of encap_header"
* 7bd305f5f2 wifi: mac80211: mesh_plink: fix matches_local logic
* 76366b399a s390/vx: fix save/restore of fpu kernel context
* f40d484e16 reset: Fix crash when freeing non-existent optional resets
* 14d915ca5a ARM: OMAP2+: Fix null pointer dereference and memory leak in omap_soc_device_init
* 62ef5887dd ksmbd: fix wrong name of SMB2_CREATE_ALLOCATION_SIZE
* 35e12efde0 ALSA: hda/realtek: Enable headset on Lenovo M90 Gen5

Updates the .xml file to add the new needed symbol:

Leaf changes summary: 1 artifact changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

1 Added function:

  [A] 'function int devm_pm_runtime_enable(device*)'

Change-Id: I1e68409087f3f833dbfcdbfc56546d982d22d10c
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-03-27 18:12:26 +00:00
Jaegeuk Kim
b558f0cc4d BACKPORT: f2fs: expose # of overprivision segments
This is useful when checking conditions during checkpoint=disable in Android.

Bug: 330501081
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
(cherry picked from commit ed5309ad137e1f467ca1e1b61be3dc39d144316c)
[hakan: Resolved minor conflict in Documentation/ABI/testing/sysfs-fs-f2fs]
Signed-off-by: Håkan Kvist <hakan.kvist@sony.com>
Change-Id: I0bd59501836fbe8fe361da2872ae660f3ac1f541
2024-03-21 22:07:44 +00:00
xuguangyang
ffb0cc5261 ANDROID: GKI: Update symbol list for Zebra
Update the android/abi_gki_aarch64_zebra

Leaf changes summary: 1 artifact changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

1 Added function:

  [A] 'function void prandom_bytes(void*, unsigned long int)'

Bug: 330656237

Change-Id: I703f92b9f2ee27cf5280cc56ba94e8f2242c248f
Signed-off-by: xuguangyang <xuguangyang91@gmail.com>
2024-03-21 07:46:19 +00:00
Mehul Raninga
65757a25d1 slimbus: qcom-ngd-ctrl: Avoid accessing deallocated stack
The functions qcom_slim_ngd_xfer_msg and
qcom_slim_ngd_xfer_msg_sync declare a local completion
variable called done. However, this variable is accessed
beyond the scope of these functions.

To address this issue:
1. Instead of keeping done as a local variable,
move it to qcom_slim_ngd_ctrl.
2. Initialize done during the probe phase.
3. Use this variable for handling transfer and
synchronization messages.

Change-Id: If97b71e2db730ab21bfd07479d2737b0546e1f8e
Signed-off-by: Mehul Raninga <quic_mraninga@quicinc.com>
2024-03-15 10:35:47 +05:30
qctecmdr
4e18d32a35 Merge "msm_ipa: new structure for tunnel design for uC" 2024-03-14 10:59:03 -07:00