This reverts commit 74cc257a62210a7fc69cd095ecd48a364621bb7a.
Instead, enable the SUSPEND event interrupt on enable_irq as part
of gadget start to be inline with USB specification.
Change-Id: I4c2d6e48a2276b480e112ee203a18a6865f15408
Signed-off-by: Pratham Pratap <prathampratap@codeaurora.org>
In bfq_idle_slice_timer func, bfqq = bfqd->in_service_queue is
not in bfqd-lock critical section. The bfqq, which is not
equal to NULL in bfq_idle_slice_timer, may be freed after passing
to bfq_idle_slice_timer_body. So we will access the freed memory.
In addition, considering the bfqq may be in race, we should
firstly check whether bfqq is in service before doing something
on it in bfq_idle_slice_timer_body func. If the bfqq in race is
not in service, it means the bfqq has been expired through
__bfq_bfqq_expire func, and wait_request flags has been cleared in
__bfq_bfqd_reset_in_service func. So we do not need to re-clear the
wait_request of bfqq which is not in service.
KASAN log is given as follows:
[13058.354613] ==============================================================
[13058.354640] BUG: KASAN: use-after-free in bfq_idle_slice_timer+0xac/0x290
[13058.354644] Read of size 8 at addr ffffa02cf3e63f78 by task fork13/19767
[13058.354646]
[13058.354655] CPU: 96 PID: 19767 Comm: fork13
[13058.354661] Call trace:
[13058.354667] dump_backtrace+0x0/0x310
[13058.354672] show_stack+0x28/0x38
[13058.354681] dump_stack+0xd8/0x108
[13058.354687] print_address_description+0x68/0x2d0
[13058.354690] kasan_report+0x124/0x2e0
[13058.354697] __asan_load8+0x88/0xb0
[13058.354702] bfq_idle_slice_timer+0xac/0x290
[13058.354707] __hrtimer_run_queues+0x298/0x8b8
[13058.354710] hrtimer_interrupt+0x1b8/0x678
[13058.354716] arch_timer_handler_phys+0x4c/0x78
[13058.354722] handle_percpu_devid_irq+0xf0/0x558
[13058.354731] generic_handle_irq+0x50/0x70
[13058.354735] __handle_domain_irq+0x94/0x110
[13058.354739] gic_handle_irq+0x8c/0x1b0
[13058.354742] el1_irq+0xb8/0x140
[13058.354748] do_wp_page+0x260/0xe28
[13058.354752] __handle_mm_fault+0x8ec/0x9b0
[13058.354756] handle_mm_fault+0x280/0x460
[13058.354762] do_page_fault+0x3ec/0x890
[13058.354765] do_mem_abort+0xc0/0x1b0
[13058.354768] el0_da+0x24/0x28
[13058.354770]
[13058.354773] Allocated by task 19731:
[13058.354780] kasan_kmalloc+0xe0/0x190
[13058.354784] kasan_slab_alloc+0x14/0x20
[13058.354788] kmem_cache_alloc_node+0x130/0x440
[13058.354793] bfq_get_queue+0x138/0x858
[13058.354797] bfq_get_bfqq_handle_split+0xd4/0x328
[13058.354801] bfq_init_rq+0x1f4/0x1180
[13058.354806] bfq_insert_requests+0x264/0x1c98
[13058.354811] blk_mq_sched_insert_requests+0x1c4/0x488
[13058.354818] blk_mq_flush_plug_list+0x2d4/0x6e0
[13058.354826] blk_flush_plug_list+0x230/0x548
[13058.354830] blk_finish_plug+0x60/0x80
[13058.354838] read_pages+0xec/0x2c0
[13058.354842] __do_page_cache_readahead+0x374/0x438
[13058.354846] ondemand_readahead+0x24c/0x6b0
[13058.354851] page_cache_sync_readahead+0x17c/0x2f8
[13058.354858] generic_file_buffered_read+0x588/0xc58
[13058.354862] generic_file_read_iter+0x1b4/0x278
[13058.354965] ext4_file_read_iter+0xa8/0x1d8 [ext4]
[13058.354972] __vfs_read+0x238/0x320
[13058.354976] vfs_read+0xbc/0x1c0
[13058.354980] ksys_read+0xdc/0x1b8
[13058.354984] __arm64_sys_read+0x50/0x60
[13058.354990] el0_svc_common+0xb4/0x1d8
[13058.354994] el0_svc_handler+0x50/0xa8
[13058.354998] el0_svc+0x8/0xc
[13058.354999]
[13058.355001] Freed by task 19731:
[13058.355007] __kasan_slab_free+0x120/0x228
[13058.355010] kasan_slab_free+0x10/0x18
[13058.355014] kmem_cache_free+0x288/0x3f0
[13058.355018] bfq_put_queue+0x134/0x208
[13058.355022] bfq_exit_icq_bfqq+0x164/0x348
[13058.355026] bfq_exit_icq+0x28/0x40
[13058.355030] ioc_exit_icq+0xa0/0x150
[13058.355035] put_io_context_active+0x250/0x438
[13058.355038] exit_io_context+0xd0/0x138
[13058.355045] do_exit+0x734/0xc58
[13058.355050] do_group_exit+0x78/0x220
[13058.355054] __wake_up_parent+0x0/0x50
[13058.355058] el0_svc_common+0xb4/0x1d8
[13058.355062] el0_svc_handler+0x50/0xa8
[13058.355066] el0_svc+0x8/0xc.
Change-Id: I510c704a6f2324741d70db33f0350e14642fe92f
Acked-by: Paolo Valente <paolo.valente@linaro.org>
Reported-by: Wang Wang <wangwang2@huawei.com>
Signed-off-by: Zhiqiang Liu <liuzhiqiang26@huawei.com>
Signed-off-by: Feilong Lin <linfeilong@huawei.com>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Git-commit: 2f95fa5c955d0a9987ffdc3a095e2f4e62c5f2a9
Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux-block
Signed-off-by: Pradeep P V K <ppvk@codeaurora.org>
When CVP SSR is triggred by debug node, CVP is still working,
such as sending HFI MSG back to kernel driver. While kernel
driver handles HFI MSG, there is dealock in acquiring CVP
core mutex and device mutex. They are also acquired by SSR handler.
Change-Id: I28060312f8f239dfa3ac36c5bb8c7a5b720abdc2
Signed-off-by: George Shen <sqiao@codeaurora.org>
Do I2C frequency related configurations during resume.
Don't make the current message as NULL before the whole
transfer process is complete.
Change-Id: I8c4797fed1cfa0743c98eea3324e4b7b82d7f3cb
Signed-off-by: Vipin Deep Kaur <vkaur@codeaurora.org>
Fix printing stale regval value in case of votable gdsc and if driver
observes error is gdsc polling.
Change-Id: I20c6e28fa8ed9ca5eea9f2a4c57b22c424ee262a
Signed-off-by: Vivek Aknurwar <viveka@codeaurora.org>
GPU_RBBM_GBIF_CLIENT_QOS_CNTL register is getting updated for
every wake up sequence but not retained across IFPC.
Add this register to GPU specific powerup register list so as to
restore its value across IFPC.
Change-Id: I3fe15ad43af1f0f1adc49764e749bb89e4cf8a65
Signed-off-by: Rajesh Kemisetti <rajeshk@codeaurora.org>
Signed-off-by: Raghu Ananya Arabolu <rarabolu@codeaurora.org>
Netmgr requires upstream iface info whenever tethering is
enabled to toggle RSB advanced feature on/off for the
respective upstream iface. Make changes to give provision
to get upstream iface whenever tethering is enabled.
Change-Id: I8f48f327ca55c3c91a978241087e6ffd5f8d4d10
Signed-off-by: Chaitanya Pratapa <cpratapa@codeaurora.org>
The trusted VM reserves 32 MB of memory for CMA usage. Given
that the CMA requirement for the trusted VM is much lower than
32 MB, reduce the default CMA pool size to 8 MB for the trusted
VM, to give the kernel more memory for non-movable allocations.
Change-Id: Ib205767979fdf4655a660556c3546e7d5ffda8fb
Signed-off-by: Isaac J. Manjarres <isaacm@codeaurora.org>
WLAN device may adjust GEN speed and width at run time so save them
accordingly from driver.
Change-Id: I4b20909425c4606b3ee5995946c97542b9849a54
Signed-off-by: Yue Ma <yuem@codeaurora.org>
The mem-buf driver cannot compile when the memory hotplug
configurations are disabled. In certain environments, mem-buf
does not require memory hotplug functionality (i.e. when the mem-buf
driver acts as a supplier), so stub out the memory-hotplug calls
if memory hotplug is not enabled.
Change-Id: Id1305358c84a0c4cd19cb539254bb6c4f8b2fb90
Signed-off-by: Isaac J. Manjarres <isaacm@codeaurora.org>
When offlining memory the system can attempt to migrate a lot of pages,
if there are problems with migration this can flood the logs.
Rate limit the page migration warnings in order to avoid this.
Change-Id: Iaf140cfc2f48cd441a384864c4d0b409db7b89d7
Signed-off-by: Liam Mark <lmark@codeaurora.org>
Tick duration defines the tick duration (in microseconds) for the clock
that PPG uses which is used to program the ramp step duration for the
pattern. If unspecified, the default value is 7800 us.
Change-Id: I7cd96d74a39becffbf9a008610c0092ad2462446
Signed-off-by: Guru Das Srinagesh <gurus@codeaurora.org>
For debug purposes, allow clients to issue SOC reset or read the entire
register dump when they wish to do so. They may not read proper values
or the reset may not take effect if the device is powered down.
Change-Id: I7fb7589a1bdfd5d7c610bdf6aab5edfc814cdceb
Signed-off-by: Bhaumik Bhatt <bbhatt@codeaurora.org>
Add config fragment options to generate target specific defconfig
during compile time from multiple QCOM configuration options.
Change-Id: I5c1818a0658b781d0f0c7fae9378a9c573d5dd69
Signed-off-by: Jeevan Shriram <jshriram@codeaurora.org>
Ion heap pools are refilled by kworker threads when pool
count reaches low mark, these threads are created using
kthread_create, as a result these threads will remain in
TASK_UNINTERRUPTIBLE state until they are woken up i.e; till
low mark is reached. This can result in false hung task reports.
So, fix this by replacing kthread_create with kthread_run so
that these threads get woken up just after they are created.
Change-Id: I3f96387c8a1707e917cbdc2d74b0a64ca6c6cb2f
Signed-off-by: Vijayanand Jitta <vjitta@codeaurora.org>
Add support for L3 bandwidth devices that vote in units
of MBPS. This includes creating OPP tables in units of
MBPS as well as requiring that these devices define a
width in DT which is used to convert the votes to Hz
before submitting them to the L3 provider.
Change-Id: I47a569f76b9e57caac57788592784921c689505b
Signed-off-by: Amir Vajid <avajid@codeaurora.org>
DP driver shall call SS release lane API asynchronously when USB is into
device mode or host mode or not yet started. This is possible as ADSP
firmware notification over UCSI may be delayed and can be running in
parallel with altmode functionality. Hence force maximum speed as USB
high speed if SS release lane API is called until next USB able disconnect.
Change-Id: Iaae8b4e39ec8695e0204b83d9292cd3efa4af310
Signed-off-by: Mayank Rana <mrana@codeaurora.org>
When the new core_reg_number value is the same as previous value,
writing to core_reg_number node cannot exit normally, this
change resolve this issue.
Change-Id: I6cbb301fc77a630aa9f01a68341c9510fdbd5c0f
Signed-off-by: Yuanfang Zhang <zhangyuanfang@codeaurora.org>
Not all registers can be set while dumping debug registers depending
on the state of the device. For example, wake doorbell is not set
until a READY state of the device is reached. Hence, we could access
a NULL pointer while dumping debug registers. Avoid this by adding a
check to skip the addresses which are not yet set.
Change-Id: Iccf275705d87023613ad3ab0c2ab53bad7ab912a
Signed-off-by: Bhaumik Bhatt <bbhatt@codeaurora.org>
regulator_unregister() calls rdev_free_qti_debugfs() with the
regulator_list_mutex held. rdev_free_qti_debugfs() then calls
regulator_put() which attempts to lock regulator_list_mutex again.
This leads to deadlock.
Modify regulator_unregister() and rdev_free_qti_debugfs() so that
mutex deadlock cannot occur.
Change-Id: I12bb4c704f7d9332e790c707aba854e224474bdb
Signed-off-by: David Collins <collinsd@codeaurora.org>
A null pointer dereference in qrtr_ns_data_ready() is seen if a client
opens a qrtr socket before qrtr_ns_init() can bind to the control port.
When the control port is bound, the ENETRESET error will be broadcasted
and clients will close their sockets. This results in DEL_CLIENT
packets being sent to the ns and qrtr_ns_data_ready() being called
without the workqueue being allocated.
Allocate the workqueue before setting sk_data_ready and binding to the
control port. This ensures that the work and workqueue structs are
allocated and initialized before qrtr_ns_data_ready can be called.
Change-Id: Ib20aec56414789905ccd80a91290fca9e3c29ead
Signed-off-by: Chris Lew <clew@codeaurora.org>
PM8350C PWM PPG does away with the need to directly manage the PBS
triggering via the PBS driver APIs by using a single register write to
an SDAM register instead. A PBS sequence thus triggered should be duly
cleared before next use. The existing scheme is also retained for
backward compatibility with targets that use a single-nvmem scheme.
The new PBS triggering scheme also expects a change in the way the high
and low indices pertaining to the pattern are specified.
Change-Id: I7d07dc611f98ce32cf5e8ba7de758fbbc3513f4b
Signed-off-by: Guru Das Srinagesh <gurus@codeaurora.org>
This change add printing of the channel name for each
sequence number print.
Change-Id: I7a5e5ac57eba9d637d48387849f1ba915096215b
Signed-off-by: Konstantin Dorfman <kdorfman@codeaurora.org>
Vote for LDO regulator during probe() if LDO related
properties are present in the device tree otherwise
we will avoid LDO configuration as it's optional.
Configure VEN gpio low and unvote for LDO during driver unloading.
Change-Id: I36ecdc5cef5afb6ddb0ef6ea4db6e745e567ab7b
Signed-off-by: Gaurav Singhal <gsinghal@codeaurora.org>
Due to co-existence of both time synchronization methods on a
platform, it is likely that a doorbell method response can be pending
while another host client requests for time using the MMIO or
synchronous method. Wait for completion of the doorbell method and
return the local and remote times from that request as the device may
not be able to handle both requests or host is likely to end up reading
corrupted time values. Also, ensure the doorbell method request is done
while holding the bus vote so the host stays awake and receives the
response as soon as possible.
Change-Id: If876905eb523fd65f3758f13b75c035de4108d8d
Signed-off-by: Bhaumik Bhatt <bbhatt@codeaurora.org>
Validate event ring accesses before walking special event rings and
update processing time synchronization such that a doorbell is rung and
future requests are queued until a response is received. Also, ensure
events are only processed when they are pending.
Change-Id: Ib8c9385530f822af3e53efb96b82c0f26c3438b7
Signed-off-by: Bhaumik Bhatt <bbhatt@codeaurora.org>
Currently only a pending packets check is used to block fast
suspends. Since it does not exactly reflect what the core
driver intends to do, allow a bus vote to the controller device
to block fast suspends as well.
Change-Id: I31266d296e855027f6b49b2dcfe4606bb48ac221
Signed-off-by: Bhaumik Bhatt <bbhatt@codeaurora.org>