Commit graph

889,574 commits

Author SHA1 Message Date
David Howells
e2f904fd79 rxrpc: Fix sendmsg() returning EPIPE due to recvmsg() returning ENODATA
[ Upstream commit 639f181f0ee20d3249dbc55f740f0167267180f0 ]

rxrpc_sendmsg() returns EPIPE if there's an outstanding error, such as if
rxrpc_recvmsg() indicating ENODATA if there's nothing for it to read.

Change rxrpc_recvmsg() to return EAGAIN instead if there's nothing to read
as this particular error doesn't get stored in ->sk_err by the networking
core.

Also change rxrpc_sendmsg() so that it doesn't fail with delayed receive
errors (there's no way for it to report which call, if any, the error was
caused by).

Fixes: 17926a7932 ("[AF_RXRPC]: Provide secure RxRPC sockets for use by userspace and kernel both")
Signed-off-by: David Howells <dhowells@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-07-31 18:39:31 +02:00
Weilong Chen
01c9283506 rtnetlink: Fix memory(net_device) leak when ->newlink fails
[ Upstream commit cebb69754f37d68e1355a5e726fdac317bcda302 ]

When vlan_newlink call register_vlan_dev fails, it might return error
with dev->reg_state = NETREG_UNREGISTERED. The rtnl_newlink should
free the memory. But currently rtnl_newlink only free the memory which
state is NETREG_UNINITIALIZED.

BUG: memory leak
unreferenced object 0xffff8881051de000 (size 4096):
  comm "syz-executor139", pid 560, jiffies 4294745346 (age 32.445s)
  hex dump (first 32 bytes):
    76 6c 61 6e 32 00 00 00 00 00 00 00 00 00 00 00  vlan2...........
    00 45 28 03 81 88 ff ff 00 00 00 00 00 00 00 00  .E(.............
  backtrace:
    [<0000000047527e31>] kmalloc_node include/linux/slab.h:578 [inline]
    [<0000000047527e31>] kvmalloc_node+0x33/0xd0 mm/util.c:574
    [<000000002b59e3bc>] kvmalloc include/linux/mm.h:753 [inline]
    [<000000002b59e3bc>] kvzalloc include/linux/mm.h:761 [inline]
    [<000000002b59e3bc>] alloc_netdev_mqs+0x83/0xd90 net/core/dev.c:9929
    [<000000006076752a>] rtnl_create_link+0x2c0/0xa20 net/core/rtnetlink.c:3067
    [<00000000572b3be5>] __rtnl_newlink+0xc9c/0x1330 net/core/rtnetlink.c:3329
    [<00000000e84ea553>] rtnl_newlink+0x66/0x90 net/core/rtnetlink.c:3397
    [<0000000052c7c0a9>] rtnetlink_rcv_msg+0x540/0x990 net/core/rtnetlink.c:5460
    [<000000004b5cb379>] netlink_rcv_skb+0x12b/0x3a0 net/netlink/af_netlink.c:2469
    [<00000000c71c20d3>] netlink_unicast_kernel net/netlink/af_netlink.c:1303 [inline]
    [<00000000c71c20d3>] netlink_unicast+0x4c6/0x690 net/netlink/af_netlink.c:1329
    [<00000000cca72fa9>] netlink_sendmsg+0x735/0xcc0 net/netlink/af_netlink.c:1918
    [<000000009221ebf7>] sock_sendmsg_nosec net/socket.c:652 [inline]
    [<000000009221ebf7>] sock_sendmsg+0x109/0x140 net/socket.c:672
    [<000000001c30ffe4>] ____sys_sendmsg+0x5f5/0x780 net/socket.c:2352
    [<00000000b71ca6f3>] ___sys_sendmsg+0x11d/0x1a0 net/socket.c:2406
    [<0000000007297384>] __sys_sendmsg+0xeb/0x1b0 net/socket.c:2439
    [<000000000eb29b11>] do_syscall_64+0x56/0xa0 arch/x86/entry/common.c:359
    [<000000006839b4d0>] entry_SYSCALL_64_after_hwframe+0x44/0xa9

Fixes: cb626bf566eb ("net-sysfs: Fix reference count leak")
Reported-by: Hulk Robot <hulkci@huawei.com>
Signed-off-by: Weilong Chen <chenweilong@huawei.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-07-31 18:39:30 +02:00
Cong Wang
b7d3d6df72 qrtr: orphan socket in qrtr_release()
[ Upstream commit af9f691f0f5bdd1ade65a7b84927639882d7c3e5 ]

We have to detach sock from socket in qrtr_release(),
otherwise skb->sk may still reference to this socket
when the skb is released in tun->queue, particularly
sk->sk_wq still points to &sock->wq, which leads to
a UAF.

Reported-and-tested-by: syzbot+6720d64f31c081c2f708@syzkaller.appspotmail.com
Fixes: 28fb4e59a4 ("net: qrtr: Expose tunneling endpoint to user space")
Cc: Bjorn Andersson <bjorn.andersson@linaro.org>
Cc: Eric Dumazet <eric.dumazet@gmail.com>
Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-07-31 18:39:30 +02:00
Miaohe Lin
2bf797a869 net: udp: Fix wrong clean up for IS_UDPLITE macro
[ Upstream commit b0a422772fec29811e293c7c0e6f991c0fd9241d ]

We can't use IS_UDPLITE to replace udp_sk->pcflag when UDPLITE_RECV_CC is
checked.

Fixes: b2bf1e2659 ("[UDP]: Clean up for IS_UDPLITE macro")
Signed-off-by: Miaohe Lin <linmiaohe@huawei.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-07-31 18:39:30 +02:00
Xiongfeng Wang
274b40b6df net-sysfs: add a newline when printing 'tx_timeout' by sysfs
[ Upstream commit 9bb5fbea59f36a589ef886292549ca4052fe676c ]

When I cat 'tx_timeout' by sysfs, it displays as follows. It's better to
add a newline for easy reading.

root@syzkaller:~# cat /sys/devices/virtual/net/lo/queues/tx-0/tx_timeout
0root@syzkaller:~#

Signed-off-by: Xiongfeng Wang <wangxiongfeng2@huawei.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-07-31 18:39:30 +02:00
Wei Yongjun
8d9f13dd40 ip6_gre: fix null-ptr-deref in ip6gre_init_net()
[ Upstream commit 46ef5b89ec0ecf290d74c4aee844f063933c4da4 ]

KASAN report null-ptr-deref error when register_netdev() failed:

KASAN: null-ptr-deref in range [0x00000000000003c0-0x00000000000003c7]
CPU: 2 PID: 422 Comm: ip Not tainted 5.8.0-rc4+ #12
Call Trace:
 ip6gre_init_net+0x4ab/0x580
 ? ip6gre_tunnel_uninit+0x3f0/0x3f0
 ops_init+0xa8/0x3c0
 setup_net+0x2de/0x7e0
 ? rcu_read_lock_bh_held+0xb0/0xb0
 ? ops_init+0x3c0/0x3c0
 ? kasan_unpoison_shadow+0x33/0x40
 ? __kasan_kmalloc.constprop.0+0xc2/0xd0
 copy_net_ns+0x27d/0x530
 create_new_namespaces+0x382/0xa30
 unshare_nsproxy_namespaces+0xa1/0x1d0
 ksys_unshare+0x39c/0x780
 ? walk_process_tree+0x2a0/0x2a0
 ? trace_hardirqs_on+0x4a/0x1b0
 ? _raw_spin_unlock_irq+0x1f/0x30
 ? syscall_trace_enter+0x1a7/0x330
 ? do_syscall_64+0x1c/0xa0
 __x64_sys_unshare+0x2d/0x40
 do_syscall_64+0x56/0xa0
 entry_SYSCALL_64_after_hwframe+0x44/0xa9

ip6gre_tunnel_uninit() has set 'ign->fb_tunnel_dev' to NULL, later
access to ign->fb_tunnel_dev cause null-ptr-deref. Fix it by saving
'ign->fb_tunnel_dev' to local variable ndev.

Fixes: dafabb6590cb ("ip6_gre: fix use-after-free in ip6gre_tunnel_lookup()")
Reported-by: Hulk Robot <hulkci@huawei.com>
Signed-off-by: Wei Yongjun <weiyongjun1@huawei.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-07-31 18:39:30 +02:00
Xie He
fbcd85cd11 drivers/net/wan/x25_asy: Fix to make it work
[ Upstream commit 8fdcabeac39824fe67480fd9508d80161c541854 ]

This driver is not working because of problems of its receiving code.
This patch fixes it to make it work.

When the driver receives an LAPB frame, it should first pass the frame
to the LAPB module to process. After processing, the LAPB module passes
the data (the packet) back to the driver, the driver should then add a
one-byte pseudo header and pass the data to upper layers.

The changes to the "x25_asy_bump" function and the
"x25_asy_data_indication" function are to correctly implement this
procedure.

Also, the "x25_asy_unesc" function ignores any frame that is shorter
than 3 bytes. However the shortest frames are 2-byte long. So we need
to change it to allow 2-byte frames to pass.

Cc: Eric Dumazet <edumazet@google.com>
Cc: Martin Schiller <ms@dev.tdt.de>
Signed-off-by: Xie He <xie.he.0141@gmail.com>
Reviewed-by: Martin Schiller <ms@dev.tdt.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-07-31 18:39:30 +02:00
Subash Abhinov Kasiviswanathan
d109acd580 dev: Defer free of skbs in flush_backlog
[ Upstream commit 7df5cb75cfb8acf96c7f2342530eb41e0c11f4c3 ]

IRQs are disabled when freeing skbs in input queue.
Use the IRQ safe variant to free skbs here.

Fixes: 145dd5f9c8 ("net: flush the softnet backlog in process context")
Signed-off-by: Subash Abhinov Kasiviswanathan <subashab@codeaurora.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-07-31 18:39:30 +02:00
Peilin Ye
52aeeec1a6 AX.25: Prevent out-of-bounds read in ax25_sendmsg()
[ Upstream commit 8885bb0621f01a6c82be60a91e5fc0f6e2f71186 ]

Checks on `addr_len` and `usax->sax25_ndigis` are insufficient.
ax25_sendmsg() can go out of bounds when `usax->sax25_ndigis` equals to 7
or 8. Fix it.

It is safe to remove `usax->sax25_ndigis > AX25_MAX_DIGIS`, since
`addr_len` is guaranteed to be less than or equal to
`sizeof(struct full_sockaddr_ax25)`

Signed-off-by: Peilin Ye <yepeilin.cs@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-07-31 18:39:29 +02:00
Peilin Ye
2f1624faf6 AX.25: Fix out-of-bounds read in ax25_connect()
[ Upstream commit 2f2a7ffad5c6cbf3d438e813cfdc88230e185ba6 ]

Checks on `addr_len` and `fsa->fsa_ax25.sax25_ndigis` are insufficient.
ax25_connect() can go out of bounds when `fsa->fsa_ax25.sax25_ndigis`
equals to 7 or 8. Fix it.

This issue has been reported as a KMSAN uninit-value bug, because in such
a case, ax25_connect() reaches into the uninitialized portion of the
`struct sockaddr_storage` statically allocated in __sys_connect().

It is safe to remove `fsa->fsa_ax25.sax25_ndigis > AX25_MAX_DIGIS` because
`addr_len` is guaranteed to be less than or equal to
`sizeof(struct full_sockaddr_ax25)`.

Reported-by: syzbot+c82752228ed975b0a623@syzkaller.appspotmail.com
Link: https://syzkaller.appspot.com/bug?id=55ef9d629f3b3d7d70b69558015b63b48d01af66
Signed-off-by: Peilin Ye <yepeilin.cs@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-07-31 18:39:29 +02:00
Greg Kroah-Hartman
006f2d92c2 Revert "Revert "ANDROID: ALSA: jack: Update supported jack switch types""
This reverts commit 22082e3e54.

Shouldn't have been reverted from this branch.

Cc: Todd Kjos <tkjos@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Ie71a68da01b80d3d8ff770dcf68135fbeb5c847f
2020-07-31 18:34:21 +02:00
Greg Kroah-Hartman
dc23881999 Revert "Revert "ANDROID: ASoC: compress: fix unsigned integer overflow check""
This reverts commit ea0bb61ded.

Shouldn't have been dropped from this branch.

Cc: Todd Kjos <tkjos@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Id757beae312e21816b923636c812107099279985
2020-07-31 18:34:20 +02:00
George Shen
a4ce94e61a msm: cvp: Add support of mdt loader
Loading EVA firmware will be done through mdt loder instead of
subsystem loader.

Change-Id: I0dea86b49e0e18ef1a4a2d39088c842cf03c29d7
Signed-off-by: George Shen <sqiao@codeaurora.org>
2020-07-31 09:08:29 -07:00
Greg Kroah-Hartman
6d423415ef ANDROID: GKI: enable CONFIG_VIDEO_V4L2_SUBDEV_API
It's needed by drivers that some boards need, so build it into the
kernel core for everyone to use.

Bug: 162449887
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Id486baec2f3c5b5dfbf18352d940dcf4ac701b67
2020-07-31 16:50:56 +02:00
Jeehong Kim
df4e084388 FROMLIST: power: add "Wireless" to power_supply_type and power_supply_type_text
In android platform(BatteryMonitor.cpp), SysfsStringEnumMap<int>
supplyTypeMap[] is declred for communication with kernel(sysfs)
and there is "Wireless". But, no type for "Wireless" in kernel.
So, we suggest to add "Wireless" to power_supply_type and
power_supply_type_text to use "Wireless" on android platform.
This will help ensure that text values are kept in sync with
BatteryMonitor.cpp.

Bug: 160750558

Signed-off-by: Do Hyoung Kim <dh0703.kim@samsung.com>
Signed-off-by: Jeehong Kim <jhez.kim@samsung.com>
Link: https://lore.kernel.org/lkml/20200730000946.15327-1-jhez.kim@samsung.com/T/#u
Change-Id: I486bef98ac785d6352370b8e9c4865ed2351f6d4
2020-07-31 14:22:57 +00:00
Todd Kjos
ea0bb61ded Revert "ANDROID: ASoC: compress: fix unsigned integer overflow check"
Revert submission 144587-1572027951673-b7d38b4

Reason for revert: See b/142489397
Reverted Changes:
Ia6d475540:ANDROID: ASoC: compress: fix unsigned integer over...
If77f8b37b:ANDROID: ALSA: jack: Update supported jack switch ...

Change-Id: I514458a88b3b96bc2da6d1558b41fd3ccf0aafbd
Signed-off-by: Todd Kjos <tkjos@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2020-07-31 14:08:28 +02:00
Todd Kjos
22082e3e54 Revert "ANDROID: ALSA: jack: Update supported jack switch types"
Revert submission 144587-1572027951673-b7d38b4

Reason for revert: See b/142489397
Reverted Changes:
Ia6d475540:ANDROID: ASoC: compress: fix unsigned integer over...
If77f8b37b:ANDROID: ALSA: jack: Update supported jack switch ...

Change-Id: Ifd73cf33379ff4893cf17ea447f1031bde796434
Signed-off-by: Todd Kjos <tkjos@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2020-07-31 14:08:11 +02:00
Naveen Yadav
b398c2138a arm64: defconfig: Enable interconnect driver for sdxlemur
Enable sdxlemur interconnect driver so that consumers are
able to obtain their path handles for voting required bandwidths.

Change-Id: I553fa47819bd1e78f22ac10ab3a6420449bb4925
Signed-off-by: Naveen Yadav <naveenky@codeaurora.org>
2020-07-31 15:41:23 +05:30
qctecmdr
63a58ef9b3 Merge "defconfig: sdxlemur: enable QCOM PCIe drivers" 2020-07-30 19:46:43 -07:00
qctecmdr
1807fa0375 Merge "msm: kgsl: Fix possible use-after-free while adding context to active list" 2020-07-30 19:46:42 -07:00
qctecmdr
7cbd5863ce Merge "arm64: enable internal regdb for holi" 2020-07-30 19:46:42 -07:00
qctecmdr
08de85d630 Merge "soc: qcom: eud: Enable EUD IRQs by default" 2020-07-30 19:46:42 -07:00
qctecmdr
cb45ce8074 Merge "pinctrl: qcom: Update GPIO to PDC wakeirq map for shima" 2020-07-30 19:46:41 -07:00
qctecmdr
0b14e1a09f Merge "usb: dwc3-msm: Add eud to MODULE_SOFTDEP" 2020-07-30 19:46:41 -07:00
Isaac J. Manjarres
778d88fe9b iommu/iommu-logger: Log IOMMU client name in debug structures
Log IOMMU client name in debug structures so that tools can
directly read the IOMMU client name without having to access
other structures outside of the IOMMU debug attachments structure.

Change-Id: I36c13fd63e6ca7260b69d01573126e276eb5835b
Signed-off-by: Isaac J. Manjarres <isaacm@codeaurora.org>
2020-07-30 16:29:11 -07:00
Jordan Crouse
4e3ff7f6ed msm: kgsl: Don't map DDR as strongly ordered
Don't map DDR memory as strongly ordered because it makes the memory
controller sad. All we really care about is the cache characteristics
and write-combine is the same as far as those are concerned.

Change-Id: Ic0dedbad30785c8d7c24ad3249413139593029f0
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
2020-07-30 13:15:19 -06:00
Jordan Crouse
9222a3588a msm: kgsl: Don't print pagefault debugging in global space
Don't print pagefault debugging in global space to avoid giving
away buffer addresses.

Change-Id: Ic0dedbad7a66aca1bd5b678aac0ddae6a8612f1c
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
2020-07-30 13:15:18 -06:00
Jordan Crouse
2460bec971 msm: kgsl: Make sure that IB addresses are dword aligned
All IB GPU addresses should be dword aligned. Enforce that in software
to keep invalid addresses from bothering the CP.

Change-Id: Ic0dedbad2298ebbd20ca1b575b8e36dcbf5a1fbe
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
2020-07-30 13:15:18 -06:00
Jordan Crouse
7b96268e45 msm: kgsl: Add back apriv bit for legacy targets
Commit ef5440e7b8 ("msm: kgsl: Remove nonsense around the a5xx and a6xx
SMMU table update") removed a lot of the cruft around a pagetable update
but unfortunately legacy targets still needed APRIV to write to the
pagetable_desc memory so add that part back in.

Change-Id: Ic0dedbad71544eaaf77efe1d523c9bf533cb4973
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
2020-07-30 13:15:17 -06:00
Jordan Crouse
b2e689c2c7 msm: kgsl: Limit the HFI error log to 16 characters
The HFI error message has a 16 character error string attached. We should
not trust that the error string is properly formatted with a null
character at the end. Set the string precision to ensure that we only
print up to 16 characters of the payload.

Change-Id: Ic0dedbad1b2aebef1feb3f9f7f531869e96599e6
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
2020-07-30 13:15:17 -06:00
Urvashi Agrawal
cd2e264ddf msm: kgsl: Initialize CP engine before loading the zap shader
If CP is not initialized and zap shader loading fails the GMU IFPC state
machine is uninitialized which causes unwanted mess. Reverse the order
of CP_INIT and zap to handle the situation gracefully.

Change-Id: I062e4c7febd8ee11099bae1b58c579851a43e8bd
Signed-off-by: Urvashi Agrawal <urvaagra@codeaurora.org>
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
2020-07-30 13:15:16 -06:00
Jordan Crouse
8e84207644 msm: kgsl: Detect missing per-process pagetable support and fallback
Per-process pagetable support might be disabled in the arm-smmu driver for
any number of reasons but we won't know it until we try to create our
first dynamic domain. If enabling the dynamic domain returns -EOPNOTSUPP
then disable per-process pagetables and fall back to global pagetables.

Also, demote a WARN to a log-once message when the arm-smmu driver doesn't
support the system cache no-write-allocate tag.

Change-Id: Ic0dedbadb66fc862eeb9cd585ade9edc1d178c77
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
2020-07-30 13:15:16 -06:00
qctecmdr
5acb608571 Merge "Bluetooth: Add support for WCN399x series BT SoC" 2020-07-30 11:23:57 -07:00
qctecmdr
668fc75dda Merge "ABI: Add clock API's to GKI qcom whitelist" 2020-07-30 11:23:56 -07:00
qctecmdr
94380d39bc Merge "taskstats: extended taskstats2 with acct fields" 2020-07-30 11:23:56 -07:00
qctecmdr
167507760d Merge "usb: dwc3: gadget: Check controller status with endpoint enable/disable" 2020-07-30 11:23:55 -07:00
Manikandan Mohan
852e8b2ffe cnss2: Add support of runtime Vreg enable for QCA6490
QCA6490 with internal regulator configuration needs additional
voltage regulator to be enabled. Update platform driver to get
the config from BDF using QMI and enable it in TCS accordingly.

Change-Id: Idb93fb95d46696f943f166e31cf50dc5b3b0da97
Signed-off-by: Manikandan Mohan <manikand@codeaurora.org>
2020-07-30 10:41:32 -07:00
Tony Truong
de69ee66f3 msm: msi: add support for Synopsys MSI
Propagate Synopsys MSI support from msm-4.14 for PCIe controller
and PCIe MSI driver. Changes support:

	1) QGIC MSI/MSI-X
	2) Synopsys MSI/MSI-X
	3) PCIe controller low power modes with MSI

Change-Id: If7a2e1980233e032325ffec597284b9164162407
Signed-off-by: Tony Truong <truong@codeaurora.org>
2020-07-30 09:21:41 -07:00
Pratham Pratap
6c7f709360 sound: usb: Fix error handling path
Commit 2733ec307cd5 ("sound: usb: Clear in_use if wait_event
fails while disconnect") added ENODEV check with EINVAL in the
error path if chip is removed while handling uaudio stream request.
Instead, both the error codes should be checked exclusively in the
return path to avoid NULL pointer access.

Change-Id: Iebf12b6f13fc6a22c679ed3482759c9173004bb8
Signed-off-by: Pratham Pratap <prathampratap@codeaurora.org>
2020-07-30 08:54:37 -07:00
Sriharsha Allenki
c49b56e4f7 sound: usb: Fix possible race between release and cleanup
In a case where the physical disconnect of headset
and the disable call from QMI race with each other,
there is a possibility that usb_sec_event_ring_cleanup
is called at the same time from uaudio_dev_cleanup
and uaudio_dev_release leading to kernel panic.
Fix this by seriailizing both these calls using
the dev_lock mutex.

Change-Id: I88abccca704786446e0826fc60994c9580828156
Signed-off-by: Sriharsha Allenki <sallenki@codeaurora.org>
2020-07-30 08:54:22 -07:00
Pratham Pratap
d88ee8d05d sound: usb: Clear in_use if wait_event fails while disconnect
Commit 02ec74e63187 ("sound: usb: Ensure proper cleanup of uaudio_dev
under all scenarios") fixed cyclic dependency between uaudio_dev_release
and uaudio_dev_cleanup by allowing dev_cleanup to happen if wait_event
of in_use to be cleared fails. Instead, clear in_use in disconnect_cb
if wait_event fails and don't rely on dev_release to happen, to maintain
the serialization of these calls.

Change-Id: If779dffd972334e050686a1865ed8f63b8e8655d
Signed-off-by: Pratham Pratap <prathampratap@codeaurora.org>
2020-07-30 08:54:05 -07:00
Pratham Pratap
dbe0a9a0f5 sound: usb: Ensure proper cleanup of uaudio_dev under all scenarios
Consider a case where chip is freed before disabling the audio
channel. This can happen when usb_audio_disconnect is called due
to USB DevFS proc_disconnect_claim ioctl. usb_audio_disconnect
will call uaudio_disconnect_cb which will wait for in_use to be
false to cleanup the uaudio_dev. If in_use never becomes false
and the wait_event is interrupted by some other signal then driver
bails out esrly from here and doesn't cleanup the uaudio_dev. Since
uaudio_dev_release is responsible for clearing the in_use based on
stream disable call, fix the cyclic dependency here on
uaudio_dev_release and uaudio_dev_cleanup by adding timeout in
wait_event and allowing dev_cleanup to happen from uaudio_disconnect_cb.
If disable stream request comes after this, handle_uaudio_stream_req
will still go ahead and try to find substream of the card but will
go to error path since card is already disconnected. This will set
the return value to -ENODEV but in the error path driver is not
checking for the correct return value and trying to access chip again.
Fix this by adding one more check for -ENODEV in the error handling path.

Change-Id: Ie11ad162f02c46878eb2663bf21cbafa54a62b0a
Signed-off-by: Pratham Pratap <prathampratap@codeaurora.org>
2020-07-30 08:53:42 -07:00
qctecmdr
87ff01a781 Merge "msm: kgsl: Unbind adreno from component device for nogmu" 2020-07-30 08:24:43 -07:00
qctecmdr
a63267620c Merge "spi: spi-msm-geni: Add support in SPI driver for Trusted VM" 2020-07-30 08:24:43 -07:00
qctecmdr
df78d1100b Merge "defconfig: Enable TouchScreen for QRD holi target" 2020-07-30 08:24:42 -07:00
Kiran Gunda
fce85e0b42 leds: qpnp-flash-v2: Convert power_supply properties to iio
Convert "main_psy" and "bms" power_supply properties to iio
channels. Also remove the revid support and identify the
pmic type based on the driver match data.

Change-Id: I70910fc502cfb1e4cd7906eca234e3a44d2f9c84
Signed-off-by: Kiran Gunda <kgunda@codeaurora.org>
2020-07-30 04:03:45 -07:00
Kiran Gunda
40ccd6775f leds: qpnp-flash-v2: Add support for qpnp-flash-v2 driver
QPNP Flash v2 LED driver supports the flash LED peripheral on
QTI PMICs like PMI8998, PM8150L and their derivatives to support
camera flash operation.

This is taken as a snapshot from msm-4.19 kernel
'commit 0873aa6e66d4 (" Merge "msm: ADSPRPC: Size check before
allocating memory from DMA")'.

Change-Id: If18cd60ba0e2ca2c463996e65216f02d21e6fd76
Signed-off-by: Kiran Gunda <kgunda@codeaurora.org>
2020-07-30 16:30:47 +05:30
Maulik Shah
45bbc04db8 pinctrl: qcom: Update GPIO to PDC wakeirq map for shima
Update latest GPIO to PDC wakeirq map.

Change-Id: I3cca3fcb9f5e4f58b8846d65858ed36b58d3c732
Signed-off-by: Maulik Shah <mkshah@codeaurora.org>
2020-07-30 15:18:16 +05:30
qctecmdr
9644a106b1 Merge "dma-mapping-fast: Fix sg-list length calculation in fast_smmu_unmap_sg()" 2020-07-30 02:34:56 -07:00
qctecmdr
dc03d0a5f7 Merge "qseecom: Check error when allocating coherent buffer" 2020-07-30 02:34:56 -07:00