[ Upstream commit 639f181f0ee20d3249dbc55f740f0167267180f0 ]
rxrpc_sendmsg() returns EPIPE if there's an outstanding error, such as if
rxrpc_recvmsg() indicating ENODATA if there's nothing for it to read.
Change rxrpc_recvmsg() to return EAGAIN instead if there's nothing to read
as this particular error doesn't get stored in ->sk_err by the networking
core.
Also change rxrpc_sendmsg() so that it doesn't fail with delayed receive
errors (there's no way for it to report which call, if any, the error was
caused by).
Fixes: 17926a7932 ("[AF_RXRPC]: Provide secure RxRPC sockets for use by userspace and kernel both")
Signed-off-by: David Howells <dhowells@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ Upstream commit af9f691f0f5bdd1ade65a7b84927639882d7c3e5 ]
We have to detach sock from socket in qrtr_release(),
otherwise skb->sk may still reference to this socket
when the skb is released in tun->queue, particularly
sk->sk_wq still points to &sock->wq, which leads to
a UAF.
Reported-and-tested-by: syzbot+6720d64f31c081c2f708@syzkaller.appspotmail.com
Fixes: 28fb4e59a4 ("net: qrtr: Expose tunneling endpoint to user space")
Cc: Bjorn Andersson <bjorn.andersson@linaro.org>
Cc: Eric Dumazet <eric.dumazet@gmail.com>
Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ Upstream commit b0a422772fec29811e293c7c0e6f991c0fd9241d ]
We can't use IS_UDPLITE to replace udp_sk->pcflag when UDPLITE_RECV_CC is
checked.
Fixes: b2bf1e2659 ("[UDP]: Clean up for IS_UDPLITE macro")
Signed-off-by: Miaohe Lin <linmiaohe@huawei.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ Upstream commit 9bb5fbea59f36a589ef886292549ca4052fe676c ]
When I cat 'tx_timeout' by sysfs, it displays as follows. It's better to
add a newline for easy reading.
root@syzkaller:~# cat /sys/devices/virtual/net/lo/queues/tx-0/tx_timeout
0root@syzkaller:~#
Signed-off-by: Xiongfeng Wang <wangxiongfeng2@huawei.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ Upstream commit 8fdcabeac39824fe67480fd9508d80161c541854 ]
This driver is not working because of problems of its receiving code.
This patch fixes it to make it work.
When the driver receives an LAPB frame, it should first pass the frame
to the LAPB module to process. After processing, the LAPB module passes
the data (the packet) back to the driver, the driver should then add a
one-byte pseudo header and pass the data to upper layers.
The changes to the "x25_asy_bump" function and the
"x25_asy_data_indication" function are to correctly implement this
procedure.
Also, the "x25_asy_unesc" function ignores any frame that is shorter
than 3 bytes. However the shortest frames are 2-byte long. So we need
to change it to allow 2-byte frames to pass.
Cc: Eric Dumazet <edumazet@google.com>
Cc: Martin Schiller <ms@dev.tdt.de>
Signed-off-by: Xie He <xie.he.0141@gmail.com>
Reviewed-by: Martin Schiller <ms@dev.tdt.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ Upstream commit 7df5cb75cfb8acf96c7f2342530eb41e0c11f4c3 ]
IRQs are disabled when freeing skbs in input queue.
Use the IRQ safe variant to free skbs here.
Fixes: 145dd5f9c8 ("net: flush the softnet backlog in process context")
Signed-off-by: Subash Abhinov Kasiviswanathan <subashab@codeaurora.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ Upstream commit 8885bb0621f01a6c82be60a91e5fc0f6e2f71186 ]
Checks on `addr_len` and `usax->sax25_ndigis` are insufficient.
ax25_sendmsg() can go out of bounds when `usax->sax25_ndigis` equals to 7
or 8. Fix it.
It is safe to remove `usax->sax25_ndigis > AX25_MAX_DIGIS`, since
`addr_len` is guaranteed to be less than or equal to
`sizeof(struct full_sockaddr_ax25)`
Signed-off-by: Peilin Ye <yepeilin.cs@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ Upstream commit 2f2a7ffad5c6cbf3d438e813cfdc88230e185ba6 ]
Checks on `addr_len` and `fsa->fsa_ax25.sax25_ndigis` are insufficient.
ax25_connect() can go out of bounds when `fsa->fsa_ax25.sax25_ndigis`
equals to 7 or 8. Fix it.
This issue has been reported as a KMSAN uninit-value bug, because in such
a case, ax25_connect() reaches into the uninitialized portion of the
`struct sockaddr_storage` statically allocated in __sys_connect().
It is safe to remove `fsa->fsa_ax25.sax25_ndigis > AX25_MAX_DIGIS` because
`addr_len` is guaranteed to be less than or equal to
`sizeof(struct full_sockaddr_ax25)`.
Reported-by: syzbot+c82752228ed975b0a623@syzkaller.appspotmail.com
Link: https://syzkaller.appspot.com/bug?id=55ef9d629f3b3d7d70b69558015b63b48d01af66
Signed-off-by: Peilin Ye <yepeilin.cs@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This reverts commit 22082e3e54.
Shouldn't have been reverted from this branch.
Cc: Todd Kjos <tkjos@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Ie71a68da01b80d3d8ff770dcf68135fbeb5c847f
This reverts commit ea0bb61ded.
Shouldn't have been dropped from this branch.
Cc: Todd Kjos <tkjos@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Id757beae312e21816b923636c812107099279985
Loading EVA firmware will be done through mdt loder instead of
subsystem loader.
Change-Id: I0dea86b49e0e18ef1a4a2d39088c842cf03c29d7
Signed-off-by: George Shen <sqiao@codeaurora.org>
It's needed by drivers that some boards need, so build it into the
kernel core for everyone to use.
Bug: 162449887
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Id486baec2f3c5b5dfbf18352d940dcf4ac701b67
In android platform(BatteryMonitor.cpp), SysfsStringEnumMap<int>
supplyTypeMap[] is declred for communication with kernel(sysfs)
and there is "Wireless". But, no type for "Wireless" in kernel.
So, we suggest to add "Wireless" to power_supply_type and
power_supply_type_text to use "Wireless" on android platform.
This will help ensure that text values are kept in sync with
BatteryMonitor.cpp.
Bug: 160750558
Signed-off-by: Do Hyoung Kim <dh0703.kim@samsung.com>
Signed-off-by: Jeehong Kim <jhez.kim@samsung.com>
Link: https://lore.kernel.org/lkml/20200730000946.15327-1-jhez.kim@samsung.com/T/#u
Change-Id: I486bef98ac785d6352370b8e9c4865ed2351f6d4
Enable sdxlemur interconnect driver so that consumers are
able to obtain their path handles for voting required bandwidths.
Change-Id: I553fa47819bd1e78f22ac10ab3a6420449bb4925
Signed-off-by: Naveen Yadav <naveenky@codeaurora.org>
Log IOMMU client name in debug structures so that tools can
directly read the IOMMU client name without having to access
other structures outside of the IOMMU debug attachments structure.
Change-Id: I36c13fd63e6ca7260b69d01573126e276eb5835b
Signed-off-by: Isaac J. Manjarres <isaacm@codeaurora.org>
Don't map DDR memory as strongly ordered because it makes the memory
controller sad. All we really care about is the cache characteristics
and write-combine is the same as far as those are concerned.
Change-Id: Ic0dedbad30785c8d7c24ad3249413139593029f0
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Don't print pagefault debugging in global space to avoid giving
away buffer addresses.
Change-Id: Ic0dedbad7a66aca1bd5b678aac0ddae6a8612f1c
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
All IB GPU addresses should be dword aligned. Enforce that in software
to keep invalid addresses from bothering the CP.
Change-Id: Ic0dedbad2298ebbd20ca1b575b8e36dcbf5a1fbe
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Commit ef5440e7b8 ("msm: kgsl: Remove nonsense around the a5xx and a6xx
SMMU table update") removed a lot of the cruft around a pagetable update
but unfortunately legacy targets still needed APRIV to write to the
pagetable_desc memory so add that part back in.
Change-Id: Ic0dedbad71544eaaf77efe1d523c9bf533cb4973
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
The HFI error message has a 16 character error string attached. We should
not trust that the error string is properly formatted with a null
character at the end. Set the string precision to ensure that we only
print up to 16 characters of the payload.
Change-Id: Ic0dedbad1b2aebef1feb3f9f7f531869e96599e6
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
If CP is not initialized and zap shader loading fails the GMU IFPC state
machine is uninitialized which causes unwanted mess. Reverse the order
of CP_INIT and zap to handle the situation gracefully.
Change-Id: I062e4c7febd8ee11099bae1b58c579851a43e8bd
Signed-off-by: Urvashi Agrawal <urvaagra@codeaurora.org>
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Per-process pagetable support might be disabled in the arm-smmu driver for
any number of reasons but we won't know it until we try to create our
first dynamic domain. If enabling the dynamic domain returns -EOPNOTSUPP
then disable per-process pagetables and fall back to global pagetables.
Also, demote a WARN to a log-once message when the arm-smmu driver doesn't
support the system cache no-write-allocate tag.
Change-Id: Ic0dedbadb66fc862eeb9cd585ade9edc1d178c77
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
QCA6490 with internal regulator configuration needs additional
voltage regulator to be enabled. Update platform driver to get
the config from BDF using QMI and enable it in TCS accordingly.
Change-Id: Idb93fb95d46696f943f166e31cf50dc5b3b0da97
Signed-off-by: Manikandan Mohan <manikand@codeaurora.org>
Propagate Synopsys MSI support from msm-4.14 for PCIe controller
and PCIe MSI driver. Changes support:
1) QGIC MSI/MSI-X
2) Synopsys MSI/MSI-X
3) PCIe controller low power modes with MSI
Change-Id: If7a2e1980233e032325ffec597284b9164162407
Signed-off-by: Tony Truong <truong@codeaurora.org>
Commit 2733ec307cd5 ("sound: usb: Clear in_use if wait_event
fails while disconnect") added ENODEV check with EINVAL in the
error path if chip is removed while handling uaudio stream request.
Instead, both the error codes should be checked exclusively in the
return path to avoid NULL pointer access.
Change-Id: Iebf12b6f13fc6a22c679ed3482759c9173004bb8
Signed-off-by: Pratham Pratap <prathampratap@codeaurora.org>
In a case where the physical disconnect of headset
and the disable call from QMI race with each other,
there is a possibility that usb_sec_event_ring_cleanup
is called at the same time from uaudio_dev_cleanup
and uaudio_dev_release leading to kernel panic.
Fix this by seriailizing both these calls using
the dev_lock mutex.
Change-Id: I88abccca704786446e0826fc60994c9580828156
Signed-off-by: Sriharsha Allenki <sallenki@codeaurora.org>
Commit 02ec74e63187 ("sound: usb: Ensure proper cleanup of uaudio_dev
under all scenarios") fixed cyclic dependency between uaudio_dev_release
and uaudio_dev_cleanup by allowing dev_cleanup to happen if wait_event
of in_use to be cleared fails. Instead, clear in_use in disconnect_cb
if wait_event fails and don't rely on dev_release to happen, to maintain
the serialization of these calls.
Change-Id: If779dffd972334e050686a1865ed8f63b8e8655d
Signed-off-by: Pratham Pratap <prathampratap@codeaurora.org>
Consider a case where chip is freed before disabling the audio
channel. This can happen when usb_audio_disconnect is called due
to USB DevFS proc_disconnect_claim ioctl. usb_audio_disconnect
will call uaudio_disconnect_cb which will wait for in_use to be
false to cleanup the uaudio_dev. If in_use never becomes false
and the wait_event is interrupted by some other signal then driver
bails out esrly from here and doesn't cleanup the uaudio_dev. Since
uaudio_dev_release is responsible for clearing the in_use based on
stream disable call, fix the cyclic dependency here on
uaudio_dev_release and uaudio_dev_cleanup by adding timeout in
wait_event and allowing dev_cleanup to happen from uaudio_disconnect_cb.
If disable stream request comes after this, handle_uaudio_stream_req
will still go ahead and try to find substream of the card but will
go to error path since card is already disconnected. This will set
the return value to -ENODEV but in the error path driver is not
checking for the correct return value and trying to access chip again.
Fix this by adding one more check for -ENODEV in the error handling path.
Change-Id: Ie11ad162f02c46878eb2663bf21cbafa54a62b0a
Signed-off-by: Pratham Pratap <prathampratap@codeaurora.org>
Convert "main_psy" and "bms" power_supply properties to iio
channels. Also remove the revid support and identify the
pmic type based on the driver match data.
Change-Id: I70910fc502cfb1e4cd7906eca234e3a44d2f9c84
Signed-off-by: Kiran Gunda <kgunda@codeaurora.org>
QPNP Flash v2 LED driver supports the flash LED peripheral on
QTI PMICs like PMI8998, PM8150L and their derivatives to support
camera flash operation.
This is taken as a snapshot from msm-4.19 kernel
'commit 0873aa6e66d4 (" Merge "msm: ADSPRPC: Size check before
allocating memory from DMA")'.
Change-Id: If18cd60ba0e2ca2c463996e65216f02d21e6fd76
Signed-off-by: Kiran Gunda <kgunda@codeaurora.org>