Commit graph

975,910 commits

Author SHA1 Message Date
Sheenam Monga
9944a4c53c
BACKPORT: qcacmn: Fix potential OOB read in util_scan_parse_rnr_ie
Currently, while parsing scan RNR Ie data is moved to
next neighbor_ap_info_field after parsing the current
neighbor_ap_info_field. But in last iteration pointer may
try to access invalid data if (uint8_t *)ie + rnr_ie_len + 2)
bytes are less than sizeof neighbor_ap_info_field and same
is the case with tbtt_length access.

Fix is to add a length check of data + next data size to be parsed
< (uint8_t *)ie + rnr_ie_len + 2) instead of adding a validation
of data length only.

CRs-Fixed: 3710080
Change-Id: I05e5a9a02f0f4f9bc468db894588e676f0a248c0
2024-08-16 00:48:57 +03:00
Harshdeep Dhatt
e7fe0e2788
BACKPORT: kgsl: hwsched: Don't cross dereference kgsl_mem_entry pointer
The passed in pointer in kgsl_count_hw_fences() can be a
kgsl_mem_entry pointer. This gets cross dereferenced to
a kgsl_drawobj_sync_event pointer and causes a NULL pointer
dereference. To avoid this cross dereference, decouple the two
paths and call kgsl_count_hw_fences() only in the appropriate
path.

Change-Id: I1088a0b67f1f82a20ddc94c94cbdd31a44b18da6
Signed-off-by: Harshdeep Dhatt <quic_hdhatt@quicinc.com>
2024-08-16 00:33:07 +03:00
Siddharth Gupta
5777b2cd18 soc: qcom: mdt_loader: Read hash from firmware blob
Since the split elf blobs will always contain the hash segment, we rely on
the blob file to get the hash rather than assume that it will be present in
the mdt file. This change uses the hash index to read the appropriate elf
blob to get the hash segment.

Change-Id: Iaf37a15f7794d417d01d9eda4a9df772623ae19c
Signed-off-by: Siddharth Gupta <sidgup@codeaurora.org>
2024-08-08 16:32:23 -05:00
Siddharth Gupta
a748d0a179 soc: qcom: mdt_loader: Handle split bins correctly
It may be that the offset of the first program header lies inside the mdt's
filesize, in this case the loader would incorrectly assume that the bins
were not split. The loading would then continue on to fail for split bins.
This change updates the logic used by the mdt loader to understand whether
the firmware images are split or not. It figures this out by checking if
each programs header's segment lies within the file or not.

Change-Id: I18ce4922eadceb96193584d829829878048ea045
Signed-off-by: Siddharth Gupta <sidgup@codeaurora.org>
2024-08-08 16:32:22 -05:00
Siddharth Gupta
94ab28d633 soc: qcom: mdt_loader: Allow hash at any phdr
The assumption that the elf program header will always have the hash
segment program header at index 1 may not hold true in all cases. This
change updates the read metadata function to find the hash program header
dynamically.

Change-Id: Ic5aa0d290b24ec3273003d980fec070b9e058c4f
Signed-off-by: Siddharth Gupta <sidgup@codeaurora.org>
2024-08-08 16:32:17 -05:00
Bruno Martins
616d4d19a3 Merge tag 'ASB-2024-08-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2024-08-01
CVE-2024-36971

* tag 'ASB-2024-08-05_11-5.4' of https://android.googlesource.com/kernel/common:
  UPSTREAM: usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()

Change-Id: Iff42948cbc36e52c49fe2dccc51e5173f4ed5a39
2024-08-08 16:44:56 +01:00
Michael Bestas
cf9c5fb631
Merge tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/dataipa into android13-5.4-lahaina
"LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0"

* tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/dataipa:
  msm: ipa: Add additional cleanup in finish rt rule addition
  msm: ipa: Add additional cleanup in finish rt rule addition

Change-Id: Ic51c62ff63dc875fb537329316d09c52aee89197
2024-08-05 23:58:26 +03:00
Michael Bestas
6f41a7e92b
Merge tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/camera-kernel into android13-5.4-lahaina
"LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0"

* tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/camera-kernel:
  msm: camera: sensor: TOCTOU error handling in eeprom
  msm: camera: sensor: TOCTOU error handling in eeprom
  msm: camera: sensor: TOCTOU error handling in eeprom
  msm: camera: sensor: TOCTOU error handling in eeprom

Change-Id: I185fde58c627ce0efc41855773e3b7d52075fd39
2024-08-05 22:15:53 +03:00
Michael Bestas
7262b988ea
Merge tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel into android13-5.4-lahaina
"LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0"

* tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel:
  dsp: q6lsm: Check size of payload before access

Change-Id: I782131a810aaecf254b92d94e2db252c3741784e
2024-08-05 22:14:56 +03:00
Michael Bestas
97911c9236
Revert "dsp: q6lsm: Handle payload_size = sizeof(uint32_t) gracefully"
Reason for revert: Conflicts with upstream change.

This reverts commit 2ade12f6b1.

Change-Id: I189a7d9854d26ef14e5ba04ae94cea42bc4ede55
2024-08-05 22:14:15 +03:00
Michael Bestas
10af39f19d
Merge tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0 into android13-5.4-lahaina
"LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0"

* tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0:
  Release 2.0.8.34S
  qcacld-3.0: Fix the AKM precedence order for RSN IE

Change-Id: Ibef7673ebcb1f012a552f63568ccfc28c2fac4e3
2024-08-05 22:05:51 +03:00
Michael Bestas
f52fc9f2ff
Merge tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qca-wifi-host-cmn into android13-5.4-lahaina
"LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0"

* tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qca-wifi-host-cmn:
  qcacmn: Copy the AKM into scan filter during STA connection

Change-Id: I2c33c966c92a8e4d238e7691ce24284726b31890
2024-08-05 22:04:58 +03:00
Michael Bestas
0e7cee495a
Merge tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/fw-api into android13-5.4-lahaina
"LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0"

* tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/fw-api:
  fw-api: Add marina E3 hal header files to fw-api project
  fw-api: CL 27039913 - update fw common interface files
  fw-api: CL 27020660 - update fw common interface files
  fw-api: CL 27007360 - update fw common interface files
  fw-api: CL 26997210 - update fw common interface files
  fw-api: CL 26979953 - update fw common interface files
  fw-api: CL 26967399 - update fw common interface files
  fw-api: CL 26957438 - update fw common interface files
  fw-api: CL 26944074 - update fw common interface files
  fw-api: CL 26941589 - update fw common interface files
  fw-api: CL 26938915 - update fw common interface files
  fw-api: CL 26931520 - update fw common interface files
  fw-api: CL 26931515 - update fw common interface files
  fw-api: Add hardware header files for QCC2072 Cologne
  fw-api: CL 26908485 - update fw common interface files
  fw-api: CL 26901300 - update fw common interface files
  fw-api: CL 26870782 - update fw common interface files
  fw-api: CL 26859968 - update fw common interface files
  fw-api: CL 26859965 - update fw common interface files
  fw-api: CL 26851668 - update fw common interface files
  fw-api: CL 26851667 - update fw common interface files
  fw-api: CL 26849729 - update fw common interface files
  fw-api: CL 26832690 - update fw common interface files
  fw-api: CL 26800691 - update fw common interface files
  fw-api: CL 26790062 - update fw common interface files
  fw-api: CL 26789113 - update fw common interface files
  fw-api: CL 26775343 - update fw common interface files
  fw-api: CL 26772591 - update fw common interface files
  fw-api: CL 26716443 - update fw common interface files
  fw-api: CL 26705428 - update fw common interface files
  fw-api: CL 26692963 - update fw common interface files
  fw-api: CL 26690604 - update fw common interface files
  fw-api: CL 26684651 - update fw common interface files
  fw-api: CL 26682404 - update fw common interface files

Change-Id: Idabe67e55bed5db7601764699d90148cd3c5ae6d
2024-08-05 22:04:01 +03:00
Michael Bestas
ea1c711e8f
Merge tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4 into android13-5.4-lahaina
"LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0"

* tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4:
  qcedev: fix UAF in qcedev_smmu
  msm: cvp: OOB write fix due to integer underflow
  msm: eva: Adding kref count for cvp_get_inst_from_id
  msm: kgsl: Fix error handling during drawctxt switch
  msm_ipa: EoGRE Multi tunnel support
  usb: dwc3: Fix dwc3 version and revisions in remote wakeup path
  usb: gadget: f_cdev: Add remote wakeup capability from notify_serial_state
  power: reset: qcom-dload-mode: nodump mode error handling
  firmware: qcom_scm: Add a call for getting dload mode
  msm: kgsl: Fix error handling during drawctxt switch
  power: reset: qcom-dload-mode: support for nodump mode
  defconfig: sdxlemur: Enable nodump support for sdxlemur
  PCI: Disable L0s support for SDX65 with QPS615 on CPE platform
  msm: adsprpc: use-after-free (UAF) in global maps
  UPSTREAM: xhci: prepare for operation without shared HCD
  rpmsg: glink: Get reference of channel objects in rx path
  msm_ipa: Tunnel Config structure changes
  soc: qcom: mdt_loader: add bound checks for headers
  BACKPORT: media: venus: hfi: add checks in capabilities from firmware

Change-Id: Idae516c9223cb306b362ad22f031735cd856d59f
2024-08-05 21:53:23 +03:00
Michael Bestas
df44b16b4f
Merge branch 'android11-5.4-lts' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
* 'android11-5.4-lts' of https://android.googlesource.com/kernel/common: (482 commits)
  ANDROID: GKI: refresh ABI to include kimage_vaddr
  ANDROID: preserve CRC for struct tcp_sock
  ANDROID: 16K: Don't set padding vm_flags on 32-bit archs
  Linux 5.4.280
  i2c: rcar: bring hardware to known state when probing
  nilfs2: fix kernel bug on rename operation of broken directory
  tcp: avoid too many retransmit packets
  tcp: use signed arithmetic in tcp_rtx_probe0_timed_out()
  net: tcp: fix unexcepted socket die when snd_wnd is 0
  tcp: refactor tcp_retransmit_timer()
  SUNRPC: Fix RPC client cleaned up the freed pipefs dentries
  libceph: fix race between delayed_work() and ceph_monc_stop()
  ALSA: hda/realtek: Limit mic boost on VAIO PRO PX
  nvmem: meson-efuse: Fix return value of nvmem callbacks
  hpet: Support 32-bit userspace
  USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor
  usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()
  USB: Add USB_QUIRK_NO_SET_INTF quirk for START BP-850k
  USB: serial: option: add Rolling RW350-GL variants
  USB: serial: option: add Netprisma LCUK54 series modules
  ...

 Conflicts:
	kernel/gen_kheaders.sh

Change-Id: Ib57235b05d1bd369b3852565eabea8e658b59aed
2024-08-05 21:50:23 +03:00
Michael Bestas
58d1d8f5ba
Merge tag 'ASB-2024-07-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2024-07-01
CVE-2024-26923

* tag 'ASB-2024-07-05_11-5.4' of https://android.googlesource.com/kernel/common: (193 commits)
  ANDROID: fix kernelci build breaks due to hid/uhid cyclic dependency
  UPSTREAM: af_unix: Fix garbage collector racing against connect()
  ANDROID: 16K: Only check basename of linker context
  UPSTREAM: af_unix: Do not use atomic ops for unix_sk(sk)->inflight.
  Linux 5.4.276
  pinctrl: mediatek: paris: Fix PIN_CONFIG_INPUT_SCHMITT_ENABLE readback
  pinctrl: mediatek: remove set but not used variable 'e'
  pinctrl: mediatek: Fix some off by one bugs
  pinctrl: mediatek: Fix fallback behavior for bias_set_combo
  regulator: core: fix debugfs creation regression
  net: fix out-of-bounds access in ops_init
  drm/vmwgfx: Fix invalid reads in fence signaled events
  dyndbg: fix old BUG_ON in >control parser
  tipc: fix UAF in error path
  usb: gadget: f_fs: Fix a race condition when processing setup packets.
  usb: gadget: composite: fix OS descriptors w_value logic
  firewire: nosy: ensure user_length is taken into account when fetching packet contents
  net: qede: use return from qede_parse_flow_attr() for flower
  net: qede: sanitize 'rc' in qede_add_tc_flower_fltr()
  ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action()
  ...

 Conflicts:
	net/unix/garbage.c

Change-Id: I9d928b110c82362cd82e7e9cc3bb19c664cdd53d
2024-08-05 21:38:21 +03:00
Linux Build Service Account
cfe860ee5e Merge "msm: eva: Adding kref count for cvp_get_inst_from_id" into kernel.lnx.5.4.r1-rel 2024-07-24 23:39:49 -07:00
Linux Build Service Account
37f6b279b7 Merge "qcedev: fix UAF in qcedev_smmu" into kernel.lnx.5.4.r1-rel 2024-07-24 23:39:48 -07:00
Daniel Perez-Zoghbi
928f6c0c07 qcedev: fix UAF in qcedev_smmu
External researcher found UAF in qcedev_smmu.c on an error condition in
qcedev_check_and_map_buffer. When an error occurs, we free binfo, but it
is still kept in the registeredbufs list. The fix removes it from the
list before freeing binfo.

Change-Id: I0327e456bd46106b12c36a5a21305407aae428dd
Signed-off-by: Daniel Perez-Zoghbi <quic_dperezzo@quicinc.com>
(cherry picked from commit ed97e9cf1d)
2024-07-24 02:40:35 -07:00
ptak
d17869edb9 msm: cvp: OOB write fix due to integer underflow
If FW send a pkt->size which is less than the sizeof packet structure
then pkt->size - sizeof() would result into an integer underflow.
Due to this the subsequent check would be bypassed and we will
start write to an OOB memory.

Change-Id: Icb3e4e6d64275592ceb6f747de653dcc1c65fec7
Signed-off-by: ptak <quic_ptak@quicinc.com>
(cherry picked from commit 143f500168)
2024-07-23 02:30:27 -07:00
Pranay Varma Kopanati
010a93190a msm: eva: Adding kref count for cvp_get_inst_from_id
Adding count for instance

Change-Id: I4505feb478c1c682ecf6a790d7cb804f70e50a1c
Signed-off-by: Pranay Varma Kopanati <quic_pkopanat@quicinc.com>
(cherry picked from commit b651124b92)
2024-07-23 02:27:30 -07:00
Lee Jones
7453ecf4d1 UPSTREAM: usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()
commit 6d3c721e686ea6c59e18289b400cc95c76e927e0 upstream.

Userspace provided string 's' could trivially have the length zero. Left
unchecked this will firstly result in an OOB read in the form
`if (str[0 - 1] == '\n') followed closely by an OOB write in the form
`str[0 - 1] = '\0'`.

There is already a validating check to catch strings that are too long.
Let's supply an additional check for invalid strings that are too short.

Bug: 346754046
Signed-off-by: Lee Jones <lee@kernel.org>
Cc: stable <stable@kernel.org>
Link: https://lore.kernel.org/r/20240705074339.633717-1-lee@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit d1205033e912f9332c1dbefa812e6ceb0575ce0a)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Id9a34f3e5495aef0d2a800a1386210f4d9fa8116
2024-07-22 16:28:44 +01:00
Giuliano Procida
b61187c891 ANDROID: GKI: refresh ABI to include kimage_vaddr
This symbol is now recognised by ABI tooling.

Bug: 352610488
Change-Id: I8bc6702c41239cd0a190b2128865faf673d97930
Signed-off-by: Giuliano Procida <gprocida@google.com>
2024-07-22 12:26:41 +01:00
Greg Kroah-Hartman
b2e024e390 Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
Do a backmerge to catch up with the recent changes in the android11-5.4
branch.  Included in here are the following commits:

56e07d95b5 Merge tag 'android11-5.4.278_r00' into android11-5.4
adc9210e7e ANDROID: 16K: Don't set padding vm_flags on 32-bit archs
dc1385281a ANDROID: GKI: refresh ABI to include kimage_vaddr
9ace17ce18 BACKPORT: arm64: move kimage_vaddr to .rodata
db0d3aeed9 BACKPORT: arm64: kernel: Convert to modern annotations for assembly data
7f5fa80716 ANDROID: fix kernelci build breaks due to hid/uhid cyclic dependency
6aff87f48c Merge tag 'android11-5.4.276_r00' into android11-5.4
5727972f15 UPSTREAM: af_unix: Fix garbage collector racing against connect()

Change-Id: I14b743bf150b90425e7c5a96d8aa8e26408ef2a2
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-07-22 09:38:37 +00:00
Linux Build Service Account
5fb258cd32 Merge 197d813903 on remote branch
Change-Id: I15656a805320859e7c8362e013b7b10d5b11ff61
2024-07-22 01:05:04 -07:00
Linux Build Service Account
7798d6e33c Merge 02194073f2 on remote branch
Change-Id: I39bd5105b6cfd91dfa812dc2ba1bd77a2a5dffd5
2024-07-22 01:04:58 -07:00
Linux Build Service Account
7a35c80109 Merge d6e961825a on remote branch
Change-Id: Ida2c8a56ee06eb0a125e91c5c4c4fab341e15530
2024-07-22 01:02:34 -07:00
Linux Build Service Account
649e95b962 Merge 9a7006bc63 on remote branch
Change-Id: I7e4edb7d6d32718de96953670f8665fc3c1d2343
2024-07-22 01:02:03 -07:00
Linux Build Service Account
12f9385b56 Merge 790d2cd6c9 on remote branch
Change-Id: I34336876ce6d531ec41f2b9fe2b79e5fe63e9bcc
2024-07-22 00:58:30 -07:00
Linux Build Service Account
c9ef58f2a6 Merge 872c22a405 on remote branch
Change-Id: I8b01e33e05d3aa2223ca44e97fbb12dd2f78e17f
2024-07-22 00:58:07 -07:00
Linux Build Service Account
5f4c6f9118 Merge 14c551f6ab on remote branch
Change-Id: I79493575f272fa5eea21b6a5b0b629468ec09a3b
2024-07-22 00:57:23 -07:00
Greg Kroah-Hartman
56e07d95b5 Merge tag 'android11-5.4.278_r00' into android11-5.4
This catches android11-5.4 up to the 5.4.278 LTS release.  Included in
here are the following commits:

* 06b018ca42 Revert "drm/panel: simple: Add missing Innolux G121X1-L03 format, flags, connector"
*   eb1a0358d1 Merge 5.4.278 into android11-5.4-lts
|\
| * 189ee9735a Linux 5.4.278
| * 2997e2fb1c nfs: fix undefined behavior in nfs_block_bits()
| * 7c72af16ab s390/ap: Fix crash in AP internal function modify_bitmap()
| * 896a7e7d0d ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find()
| * 95572c6b8e sparc: move struct termio to asm/termios.h
| * 0b45c25d60 xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING
| * db00828250 net: fix __dst_negative_advice() race
| * 6b84387afe kdb: Use format-specifiers rather than memset() for padding in kdb_read()
| * 147bac05f2 kdb: Merge identical case statements in kdb_read()
| * 084e84ede9 kdb: Fix console handling when editing and tab-completing commands
| * 6a3836f29b kdb: Use format-strings rather than '\0' injection in kdb_read()
| * ddd2972d8e kdb: Fix buffer overflow during tab-complete
| * 2098b237ba sparc64: Fix number of online CPUs
| * 68682329fc intel_th: pci: Add Meteor Lake-S CPU support
| * 2101901dd5 net/9p: fix uninit-value in p9_client_rpc()
| * 636438dd9d net/ipv6: Fix route deleting failure when metric equals 0
| * 6396b33e98 crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak
| * 95abba5168 crypto: ecrdsa - Fix module auto-load on add_key
| * a2579c802c KVM: arm64: Allow AArch32 PSTATE.M to be restored as System mode
| * 86435f39c1 fbdev: savage: Handle err return when savagefb_check_var failed
| * bec5fe171f media: v4l2-core: hold videodev_lock until dev reg, finishes
| * 0dcb04014f media: mxl5xx: Move xpt structures off stack
| * 6ac608af7b media: mc: mark the media devnode as registered from the, start
| * c125ebaf03 arm64: dts: hi3798cv200: fix the size of GICR
| * 6649fea036 wifi: rtl8xxxu: Fix the TX power of RTL8192CU, RTL8723AU
| * 634ba3c97e md/raid5: fix deadlock that raid5d() wait for itself to clear MD_SB_CHANGE_PENDING
| * fe60a7bc34 arm64: tegra: Correct Tegra132 I2C alias
| * 68edebd1ff ACPI: resource: Do IRQ override on TongFang GXxHRXx and GMxHGxx
| * 3b472ad39c ata: pata_legacy: make legacy_exit() work again
| * 5594971e02 drm/amdgpu: add error handle to avoid out-of-bounds
| * 8915dcd29a media: lgdt3306a: Add a check against null-pointer-def
| * c559a8d840 f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode()
| * 27fba38ddd x86/mm: Remove broken vsyscall emulation code from the page fault code
| * 9a7f481f3e vxlan: Fix regression when dropping packets due to invalid src addresses
| * 82933c84f1 nilfs2: fix use-after-free of timer for log writer thread
| * ffbda400b2 afs: Don't cross .backup mountpoint from backup volume
| * 6e23457791 io_uring: fail NOP if non-zero op flags is passed in
| * 63664389b6 mmc: core: Do not force a retune before RPMB switch
| * e4daa1a1ff binder: fix max_thread type inconsistency
| * 6ed45d20d3 SUNRPC: Fix loop termination condition in gss_free_in_token_pages()
| * f5f4675960 genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU offline
| * 74bfb8d90f ALSA: timer: Set lower bound of start tick time
| * 54768bacfd ipvlan: Dont Use skb->sk in ipvlan_process_v{4,6}_outbound
| * ce05d4a3b0 spi: stm32: Don't warn about spurious interrupts
| * f13fc5113d kconfig: fix comparison to constant symbols, 'm', 'n'
| * 10f0af5234 netfilter: tproxy: bail out if IP has been disabled on the device
| * 582233516a net:fec: Add fec_enet_deinit()
| * 00a762ee6b net: usb: smsc95xx: fix changing LED_SEL bit value updated from EEPROM
| * 2be4ac3d99 smsc95xx: use usbnet->driver_priv
| * a4ecfe6a98 smsc95xx: remove redundant function arguments
| * ca63fb7af9 enic: Validate length of nl attributes in enic_set_vf_port
| * 165b25e3ee dma-buf/sw-sync: don't enable IRQ from sync_print_obj()
| * a921cd1f0c net/mlx5e: Use rx_missed_errors instead of rx_dropped for reporting buffer exhaustion
| * 5f4278f151 nvmet: fix ns enable/disable possible hang
| * 27a6986af2 spi: Don't mark message DMA mapped when no transfer in it is
| * 3989b81785 netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu()
| * 2271803d9f nfc: nci: Fix handling of zero-length payload packets in nci_rx_work()
| * db58c41b51 nfc: nci: Fix kcov check in nci_rx_work()
| * 4b179b0cfc net: fec: avoid lock evasion when reading pps_enable
| * 43a9aaf632 virtio: delete vq in vp_find_vqs_msix() when request_irq() fails
| * 22469a0335 arm64: asm-bug: Add .align 2 to the end of __BUG_ENTRY
| * 09ef5c5e36 openvswitch: Set the skbuff pkt_type for proper pmtud support.
| * 6aacaa80d9 tcp: Fix shift-out-of-bounds in dctcp_update_alpha().
| * 07b002723c params: lift param_set_uint_minmax to common code
| * 4a3fcf5372 ipv6: sr: fix memleak in seg6_hmac_init_algo
| * b1589a6eef sunrpc: fix NFSACL RPC retry on soft mount
| * 485ded868e nfc: nci: Fix uninit-value in nci_rx_work
| * eae8e2dcb0 x86/kconfig: Select ARCH_WANT_FRAME_POINTERS again when UNWINDER_FRAME_POINTER=y
| * f5acbae737 null_blk: Fix the WARNING: modpost: missing MODULE_DESCRIPTION()
| * 2990b6c0a6 media: cec: cec-api: add locking in cec_release()
| * 8890dd70fa media: cec: cec-adap: always cancel work in cec_transmit_msg_fh
| * 3f5c5d869e um: Fix the -Wmissing-prototypes warning for __switch_mm
| * 5b1796345d powerpc/pseries: Add failure related checks for h_get_mpp and h_get_ppp
| * b648756eb9 scsi: qla2xxx: Replace all non-returning strlcpy() with strscpy()
| * ecf4ddc3ae media: stk1160: fix bounds checking in stk1160_copy_video()
| * dc1ff95602 um: Add winch to winch_handlers before registering winch IRQ
| * 94bf61b291 um: Fix return value in ubd_init()
| * 0a5ad8dc33 drm/msm/dpu: Always flush the slave INTF on the CTL
| * 2b486d2306 Input: pm8xxx-vibrator - correct VIB_MAX_LEVELS calculation
| * 33d148cdb1 Input: ims-pcu - fix printf string overflow
| * b01d29acc8 libsubcmd: Fix parse-options memory leak
| * d9754fc9c0 serial: sh-sci: protect invalidating RXDMA on shutdown
| * cd97dcd412 f2fs: fix to release node block count in error path of f2fs_new_node_page()
| * 7420402619 extcon: max8997: select IRQ_DOMAIN instead of depending on it
| * b8c6b83cc3 ppdev: Add an error check in register_device
| * 5f3c34b719 ppdev: Remove usage of the deprecated ida_simple_xx() API
| * a0450d3f38 stm class: Fix a double free in stm_register_device()
| * 4591a1764a usb: gadget: u_audio: Clear uac pointer when freed.
| * eba6b40877 microblaze: Remove early printk call from cpuinfo-static.c
| * 0df1153511 microblaze: Remove gcc flag for non existing early_printk.c file
| * 463d714a58 iio: pressure: dps310: support negative temperature values
| * c0e9a72845 greybus: arche-ctrl: move device table to its right location
| * e728f8dfff serial: max3100: Fix bitwise types
| * 9db4222ed8 serial: max3100: Update uart_driver_registered on driver removal
| * ea9b35372b serial: max3100: Lock port->lock when calling uart_handle_cts_change()
| * 4ba0e40fdd firmware: dmi-id: add a release callback function
| * 7481337ab7 dmaengine: idma64: Add check for dma_set_max_seg_size
| * 002364b2d5 soundwire: cadence: fix invalid PDI offset
| * 98a649463a soundwire: cadence_master: improve PDI allocation
| * 6584388c03 soundwire: intel: don't filter out PDI0/1
| * 10568e442c soundwire: cadence/intel: simplify PDI/port mapping
| * e2c64246e5 greybus: lights: check return of get_channel_from_mode
| * 5c05727363 sched/fair: Allow disabling sched_balance_newidle with sched_relax_domain_level
| * 2137d07adb sched/topology: Don't set SD_BALANCE_WAKE on cpuset domain relax
| * b5b2d42bb3 af_packet: do not call packet_read_pending() from tpacket_destruct_skb()
| * 1fbfb483c1 netrom: fix possible dead-lock in nr_rt_ioctl()
| * fdee55c429 RDMA/IPoIB: Fix format truncation compilation errors
| * a7d9afa3dd selftests/kcmp: remove unused open mode
| * e7af24598d selftests/kcmp: Make the test output consistent and clear
| * 4420b73c7f SUNRPC: Fix gss_free_in_token_pages()
| * ff15f1100c sunrpc: removed redundant procp check
| * 9462d82504 ext4: avoid excessive credit estimate in ext4_tmpfile()
| * ce366a2c94 x86/insn: Fix PUSH instruction in x86 instruction decoder opcode map
| * 2679ddbf08 RDMA/hns: Use complete parentheses in macros
| * f5734138fb drm/panel: simple: Add missing Innolux G121X1-L03 format, flags, connector
| * bab3a580ee ASoC: tracing: Export SND_SOC_DAPM_DIR_OUT to its value
| * 565d9ad7e5 drm/arm/malidp: fix a possible null pointer dereference
| * a790c8a742 fbdev: sh7760fb: allow modular build
| * a8c15b9f30 platform/x86: wmi: Make two functions static
| * 51184b721d media: radio-shark2: Avoid led_names truncations
| * 166e0d4d79 media: ngene: Add dvb_ca_en50221_init return value check
| * 472e95f220 fbdev: sisfb: hide unused variables
| * e8d37421d4 powerpc/fsl-soc: hide unused const variable
| * be34a1b351 drm/mediatek: Add 0 size check to mtk_drm_gem_obj
| * 9b8deba36a fbdev: shmobile: fix snprintf truncation
| * 6658e44858 mtd: rawnand: hynix: fixed typo
| * e280ab978c drm/amd/display: Fix potential index out of bounds in color transformation function
| * 646cd236c5 ipv6: sr: fix invalid unregister error path
| * 6d7723bdc7 ipv6: sr: fix incorrect unregister order
| * 08094420c6 ipv6: sr: add missing seg6_local_exit
| * 0b532f5943 net: openvswitch: fix overwriting ct original tuple for ICMPv6
| * 90fa1b38c3 net: usb: smsc95xx: stop lying about skb->truesize
| * de6641d213 af_unix: Fix data races in unix_release_sock/unix_stream_sendmsg
| * 3cd46d51a4 net: ethernet: cortina: Locking fixes
| * c03effc478 m68k: mac: Fix reboot hang on Mac IIci
| * 5213cc01d0 m68k: Fix spinlock race in kernel thread creation
| * 85f70f8aeb net: usb: sr9700: stop lying about skb->truesize
| * 43b78d06e7 usb: aqc111: stop lying about skb->truesize
| * d0209bbac2 wifi: mwl8k: initialize cmd->addr[] properly
| * a75001678e scsi: qedf: Ensure the copied buf is NUL terminated
| * 595a6b98de scsi: bfa: Ensure the copied buf is NUL terminated
| * c5d19837cc HID: intel-ish-hid: ipc: Add check for pci_alloc_irq_vectors
| * 2bdad9da45 Revert "sh: Handle calling csum_partial with misaligned data"
| * deb3c6e64b sh: kprobes: Merge arch_copy_kprobe() into arch_prepare_kprobe()
| * 68a5a00c5d wifi: ar5523: enable proper endpoint verification
| * ac3ed46a87 wifi: carl9170: add a proper sanity check for endpoints
| * 1e9c3f2cae macintosh/via-macii: Fix "BUG: sleeping function called from invalid context"
| * 31e1da773a tcp: avoid premature drops in tcp_add_backlog()
| * 9d04b4d0fe tcp: fix a signed-integer-overflow bug in tcp_add_backlog()
| * 527eaa5aa6 tcp: minor optimization in tcp_add_backlog()
| * 539c4bf754 wifi: ath10k: populate board data for WCN3990
| * 9e16d735c6 wifi: ath10k: Fix an error code problem in ath10k_dbg_sta_write_peer_debug_trigger()
| * 15650ffd47 x86/purgatory: Switch to the position-independent small code model
| * e3a45d8134 scsi: hpsa: Fix allocation size for Scsi_Host private data
| * e999155c60 scsi: libsas: Fix the failure of adding phy with zero-address to port
| * 2d730b465e cpufreq: exit() callback is optional
| * e660a2e670 cpufreq: Rearrange locking in cpufreq_remove_dev()
| * 14bef1ad61 cpufreq: Split cpufreq_offline()
| * 458965e83c cpufreq: Reorganize checks in cpufreq_offline()
| * a65066c520 ACPI: disable -Wstringop-truncation
| * 8e44605294 irqchip/alpine-msi: Fix off-by-one in allocation error path
| * 0dba8fd01a scsi: ufs: core: Perform read back after disabling UIC_COMMAND_COMPL
| * 14baa35711 scsi: ufs: core: Perform read back after disabling interrupts
| * db5e443d5a scsi: ufs: cdns-pltfrm: Perform read back after writing HCLKDIV
| * 50b2cebe33 scsi: ufs: qcom: Perform read back after writing reset bit
| * 8cff599e2f qed: avoid truncating work queue length
| * 6dde0c15c5 x86/boot: Ignore relocations in .notes sections in walk_relocs() too
| * a50b7aae18 wifi: ath10k: poll service ready message before failing
| * 43771597fe md: fix resync softlockup when bitmap size is less than array size
| * 0f306d16ff null_blk: Fix missing mutex_destroy() at module removal
| * 526235dffc jffs2: prevent xattr node from overflowing the eraseblock
| * f84dd50f91 s390/cio: fix tracepoint subchannel type field
| * 2246880d90 crypto: ccp - drop platform ifdef checks
| * 3a7c49e101 parisc: add missing export of __cmpxchg_u8()
| * 354bc3231f nilfs2: fix out-of-range warning
| * 235b859810 ecryptfs: Fix buffer size for tag 66 packet
| * 94ac93159b firmware: raspberrypi: Use correct device for DMA mappings
| * e719c8991c crypto: bcm - Fix pointer arithmetic
| * 281ccb2a54 openpromfs: finish conversion to the new mount API
| * fce3de55e8 nvme: find numa distance only if controller has valid numa id
| * 74d98cccea drm/amdkfd: Flush the process wq before creating a kfd_process
| * 7e44593de9 ASoC: da7219-aad: fix usage of device_get_named_child_node()
| * b159bd7fa8 ASoC: dt-bindings: rt5645: add cbj sleeve gpio property
| * 63175250af ASoC: rt5645: Fix the electric noise due to the CBJ contacts floating
| * 07191510c3 drm/amd/display: Set color_mgmt_changed to true on unsuspend
| * 47bce5529c net: usb: qmi_wwan: add Telit FN920C04 compositions
| * 917c553186 wifi: cfg80211: fix the order of arguments for trace events of the tx_rx_evt class
| * bc9cee50a4 nilfs2: fix potential hang in nilfs_detach_log_writer()
| * bcb5016559 nilfs2: fix unexpected freezing of nilfs_segctor_sync()
| * 8cd4b29283 net: smc91x: Fix m68k kernel compilation for ColdFire CPU
| * c68b7a442e ring-buffer: Fix a race between readers and resize checks
| * cd7f3978c2 speakup: Fix sizeof() vs ARRAY_SIZE() bug
| * b229bc6c6e tty: n_gsm: fix possible out-of-bounds in gsm0_receive()
| * 491bd4d7aa x86/tsc: Trust initial offset in architectural TSC-adjust MSRs
* | 5c67c52b0d Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
* | 4b533a5511 Merge 5.4.277 into android11-5.4-lts
|\|
| * 4a548b29cd Linux 5.4.277
| * 2b21f3095b docs: kernel_include.py: Cope with docutils 0.21
| * ecef5df796 serial: kgdboc: Fix NMI-safety problems from keyboard reset code
| * 6b40d4c262 usb: typec: ucsi: displayport: Fix potential deadlock
| * 467139546f drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper()
| * 791d236a68 btrfs: add missing mutex_unlock in btrfs_relocate_sys_chunks()
| * ea4105d991 arm64: dts: qcom: Fix 'interrupt-map' parent address cells
| * 7184491fc5 firmware: arm_scmi: Harden accesses to the reset domains
| * 6726429c18 smb: client: fix potential OOBs in smb2_parse_contexts()
| * db389e74d3 net: bcmgenet: synchronize UMAC_CMD access
| * ae59f1f444 net: bcmgenet: synchronize use of bcmgenet_set_rx_mode()
| * 40fc58f86b net: bcmgenet: synchronize EXT_RGMII_OOB_CTRL access
| * 4f470a80ce net: bcmgenet: keep MAC in reset until PHY is up
| * bf3ace5c10 Revert "net: bcmgenet: use RGMII loopback for MAC reset"
| * 44f0418482 Revert "selftests: mm: fix map_hugetlb failure on 64K page size systems"
| * d0083459e2 ext4: fix bug_on in __es_tree_search
| * c9e7f98f55 pinctrl: core: handle radix_tree_insert() errors in pinctrl_register_one_pin()
* 18ae7bded0 Merge branch 'android11-5.4' into branch 'android11-5.4-lts'

Change-Id: I77842e63e44ae93d7f0cdc0022f1f43edc1dc89e
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-07-20 13:35:08 +00:00
Greg Kroah-Hartman
33437b2981 ANDROID: preserve CRC for struct tcp_sock
In commit fe7a7b8942 ("tcp: add TCP_INFO status for failed client
TFO"), 2 unused bits in struct tcp_sock were renamed and used.  This
does not change the binary abi, but the checking tools do notice this,
so mark it as such so that the CRC generation remains the same.

Fixes: fe7a7b8942 ("tcp: add TCP_INFO status for failed client TFO")
Change-Id: I160605fb220d393c77ed4972957cbf823980694c
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-07-20 12:53:22 +00:00
Greg Kroah-Hartman
f90cc3d8c1 This is the 5.4.280 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmaY400ACgkQONu9yGCS
 aT4SOxAAsnnWA4GPcspY03fxcSwl+CdgDj22VVgxDW/va/rk7fcxo000snNgo2M+
 K1x9qL3SPAXVEZNIUdSU001+/pnaaVdskXRNanwIvIuZMeh2cn8qmP+MFUPHLKWH
 aki1FPsh3lvI3x7JVioSWNvSuiaHgeXFBPKUB4wP5J51QYiuSWGb1gIrGCsCNiHI
 kboMmDEo1cxSLE+0wWzhBXn921FA1Vot10SqtYwQJnAICq2TsE2YPgshiMkrYZ4e
 0KbTLizk390pDT+n+Nrnoi7wNoRX/KoHz7A/94l3zwp3/xv9glqeudt+Cy9esQjo
 yZQDkq6LtSW8ABWjcCXPMEg2r7p8HPmiOuCP8oHBo9kHNgyePbArEPWQP+xC3vzq
 zeMH09m+arw8njBYdKv3c+5VVY7ABHQK3Vfo2Z3MMf5ZZgTg7f+e7uBT4RcFBriq
 Eyne4CLPzuuzn/BEgcoPWxwaDs8mDThbxRlfSmnDbfE7IcuDGRH7EsvFuViSKE13
 ncpLJu03bs/AhZe3eiLk+AWwb4gHJD1oBNWu1CkQ5XY2S0MxYxyYdlhNpGA5yvyO
 RqIhrTm+ye/NlD8X1jj2WAPTR3l94TTQoBsJAhsfceusC3OeS5537hKJNL4c8O1f
 GZM+vbAudy529iFVru84ZZLM31RwwOqRP3LRt1sOiSZs50FZ9HE=
 =Q9dw
 -----END PGP SIGNATURE-----

Merge 5.4.280 into android11-5.4-lts

Changes in 5.4.280
	Compiler Attributes: Add __uninitialized macro
	drm/lima: fix shared irq handling on driver remove
	media: dvb: as102-fe: Fix as10x_register_addr packing
	media: dvb-usb: dib0700_devices: Add missing release_firmware()
	IB/core: Implement a limit on UMAD receive List
	scsi: qedf: Make qedf_execute_tmf() non-preemptible
	drm/amdgpu: Initialize timestamp for some legacy SOCs
	drm/amd/display: Skip finding free audio for unknown engine_id
	media: dw2102: Don't translate i2c read into write
	sctp: prefer struct_size over open coded arithmetic
	firmware: dmi: Stop decoding on broken entry
	Input: ff-core - prefer struct_size over open coded arithmetic
	net: dsa: mv88e6xxx: Correct check for empty list
	media: dvb-frontends: tda18271c2dd: Remove casting during div
	media: s2255: Use refcount_t instead of atomic_t for num_channels
	media: dvb-frontends: tda10048: Fix integer overflow
	i2c: i801: Annotate apanel_addr as __ro_after_init
	powerpc/64: Set _IO_BASE to POISON_POINTER_DELTA not 0 for CONFIG_PCI=n
	orangefs: fix out-of-bounds fsid access
	powerpc/xmon: Check cpu id in commands "c#", "dp#" and "dx#"
	jffs2: Fix potential illegal address access in jffs2_free_inode
	s390/pkey: Wipe sensitive data on failure
	tcp: tcp_mark_head_lost is only valid for sack-tcp
	tcp: add ece_ack flag to reno sack functions
	net: tcp better handling of reordering then loss cases
	UPSTREAM: tcp: fix DSACK undo in fast recovery to call tcp_try_to_open()
	tcp_metrics: validate source addr length
	wifi: wilc1000: fix ies_len type in connect path
	bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set()
	selftests: fix OOM in msg_zerocopy selftest
	selftests: make order checking verbose in msg_zerocopy selftest
	inet_diag: Initialize pad field in struct inet_diag_req_v2
	nilfs2: fix inode number range checks
	nilfs2: add missing check for inode numbers on directory entries
	mm: optimize the redundant loop of mm_update_owner_next()
	can: kvaser_usb: Explicitly initialize family in leafimx driver_info struct
	fsnotify: Do not generate events for O_PATH file descriptors
	Revert "mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again"
	drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes
	drm/amdgpu/atomfirmware: silence UBSAN warning
	bnx2x: Fix multiple UBSAN array-index-out-of-bounds
	media: dw2102: fix a potential buffer overflow
	i2c: pnx: Fix potential deadlock warning from del_timer_sync() call in isr
	ALSA: hda/realtek: Enable headset mic of JP-IK LEAP W502 with ALC897
	nvme-multipath: find NUMA path only for online numa-node
	nilfs2: fix incorrect inode allocation from reserved inodes
	filelock: fix potential use-after-free in posix_lock_inode
	fs/dcache: Re-use value stored to dentry->d_flags instead of re-reading
	vfs: don't mod negative dentry count when on shrinker list
	tcp: add TCP_INFO status for failed client TFO
	tcp: fix incorrect undo caused by DSACK of TLP retransmit
	octeontx2-af: Fix incorrect value output on error path in rvu_check_rsrc_availability()
	net: lantiq_etop: add blank line after declaration
	net: ethernet: lantiq_etop: fix double free in detach
	ppp: reject claimed-as-LCP but actually malformed packets
	udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port().
	s390: Mark psw in __load_psw_mask() as __unitialized
	ARM: davinci: Convert comma to semicolon
	octeontx2-af: fix detection of IP layer
	USB: serial: option: add Telit generic core-dump composition
	USB: serial: option: add Telit FN912 rmnet compositions
	USB: serial: option: add Fibocom FM350-GL
	USB: serial: option: add support for Foxconn T99W651
	USB: serial: option: add Netprisma LCUK54 series modules
	USB: serial: option: add Rolling RW350-GL variants
	USB: Add USB_QUIRK_NO_SET_INTF quirk for START BP-850k
	usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()
	USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor
	hpet: Support 32-bit userspace
	nvmem: meson-efuse: Fix return value of nvmem callbacks
	ALSA: hda/realtek: Limit mic boost on VAIO PRO PX
	libceph: fix race between delayed_work() and ceph_monc_stop()
	SUNRPC: Fix RPC client cleaned up the freed pipefs dentries
	tcp: refactor tcp_retransmit_timer()
	net: tcp: fix unexcepted socket die when snd_wnd is 0
	tcp: use signed arithmetic in tcp_rtx_probe0_timed_out()
	tcp: avoid too many retransmit packets
	nilfs2: fix kernel bug on rename operation of broken directory
	i2c: rcar: bring hardware to known state when probing
	Linux 5.4.280

Change-Id: Ic487769acece8eedb10cc2a310d97f453abba2f0
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-07-19 13:19:29 +00:00
Kalesh Singh
adc9210e7e ANDROID: 16K: Don't set padding vm_flags on 32-bit archs
vma_pad_fixup_flags() and is_mergable_pad_vma() were inadvertently
affecting the vm_flags on 32-bit arch, making some VMAs not mergable.

This causes zygote to crash as the Art GC's heap compaction fails.

The compaction depends on mremap() which will fail when operating on
a range that spans multiple VMAs [1]. This can happen now due to the
incorrect is_mergable_pad_vma() check.

Make all the pgsize_migration APIs no-ops in 32-bit architectures,
since Android only performs ELF segment extension in 64-bit archs.

[1] https://github.com/torvalds/linux/blob/v6.9/mm/mremap.c#L841-L843

Bug: 353667356
Change-Id: Id9b0076ef173d75a4afc85577355d340fce03e65
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
(cherry picked from commit f3437db87063f624f189e1cd38347a971fdd3fa0)
2024-07-18 20:00:41 +00:00
Greg Kroah-Hartman
88d2aa8774 Linux 5.4.280
Link: https://lore.kernel.org/r/20240716152740.626160410@linuxfoundation.org
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Link: https://lore.kernel.org/r/20240717063752.619384275@linuxfoundation.org
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-07-18 11:40:56 +02:00
Wolfram Sang
392b4f1149 i2c: rcar: bring hardware to known state when probing
[ Upstream commit 4e36c0f20cb1c74c7bd7ea31ba432c1c4a989031 ]

When probing, the hardware is not brought into a known state. This may
be a problem when a hypervisor restarts Linux without resetting the
hardware, leaving an old state running. Make sure the hardware gets
initialized, especially interrupts should be cleared and disabled.

Reported-by: Dirk Behme <dirk.behme@de.bosch.com>
Reported-by: Geert Uytterhoeven <geert+renesas@glider.be>
Closes: https://lore.kernel.org/r/20240702045535.2000393-1-dirk.behme@de.bosch.com
Fixes: 6ccbe60713 ("i2c: add Renesas R-Car I2C driver")
Signed-off-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-07-18 11:40:56 +02:00
Ryusuke Konishi
24c1c8566a nilfs2: fix kernel bug on rename operation of broken directory
commit a9e1ddc09ca55746079cc479aa3eb6411f0d99d4 upstream.

Syzbot reported that in rename directory operation on broken directory on
nilfs2, __block_write_begin_int() called to prepare block write may fail
BUG_ON check for access exceeding the folio/page size.

This is because nilfs_dotdot(), which gets parent directory reference
entry ("..") of the directory to be moved or renamed, does not check
consistency enough, and may return location exceeding folio/page size for
broken directories.

Fix this issue by checking required directory entries ("." and "..") in
the first chunk of the directory in nilfs_dotdot().

Link: https://lkml.kernel.org/r/20240628165107.9006-1-konishi.ryusuke@gmail.com
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Reported-by: syzbot+d3abed1ad3d367fa2627@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=d3abed1ad3d367fa2627
Fixes: 2ba466d74e ("nilfs2: directory entry operations")
Tested-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-07-18 11:40:56 +02:00
Eric Dumazet
d2346fca5b tcp: avoid too many retransmit packets
commit 97a9063518f198ec0adb2ecb89789de342bb8283 upstream.

If a TCP socket is using TCP_USER_TIMEOUT, and the other peer
retracted its window to zero, tcp_retransmit_timer() can
retransmit a packet every two jiffies (2 ms for HZ=1000),
for about 4 minutes after TCP_USER_TIMEOUT has 'expired'.

The fix is to make sure tcp_rtx_probe0_timed_out() takes
icsk->icsk_user_timeout into account.

Before blamed commit, the socket would not timeout after
icsk->icsk_user_timeout, but would use standard exponential
backoff for the retransmits.

Also worth noting that before commit e89688e3e978 ("net: tcp:
fix unexcepted socket die when snd_wnd is 0"), the issue
would last 2 minutes instead of 4.

Fixes: b701a99e43 ("tcp: Add tcp_clamp_rto_to_user_timeout() helper to improve accuracy")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Neal Cardwell <ncardwell@google.com>
Reviewed-by: Jason Xing <kerneljasonxing@gmail.com>
Reviewed-by: Jon Maxwell <jmaxwell37@gmail.com>
Reviewed-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Link: https://patch.msgid.link/20240710001402.2758273-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-07-18 11:40:56 +02:00
Eric Dumazet
2ff6dd600c tcp: use signed arithmetic in tcp_rtx_probe0_timed_out()
commit 36534d3c54537bf098224a32dc31397793d4594d upstream.

Due to timer wheel implementation, a timer will usually fire
after its schedule.

For instance, for HZ=1000, a timeout between 512ms and 4s
has a granularity of 64ms.
For this range of values, the extra delay could be up to 63ms.

For TCP, this means that tp->rcv_tstamp may be after
inet_csk(sk)->icsk_timeout whenever the timer interrupt
finally triggers, if one packet came during the extra delay.

We need to make sure tcp_rtx_probe0_timed_out() handles this case.

Fixes: e89688e3e978 ("net: tcp: fix unexcepted socket die when snd_wnd is 0")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Menglong Dong <imagedong@tencent.com>
Acked-by: Neal Cardwell <ncardwell@google.com>
Reviewed-by: Jason Xing <kerneljasonxing@gmail.com>
Link: https://lore.kernel.org/r/20240607125652.1472540-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-07-18 11:40:56 +02:00
Menglong Dong
8cc1b4d81a net: tcp: fix unexcepted socket die when snd_wnd is 0
commit e89688e3e97868451a5d05b38a9d2633d6785cd4 upstream.

In tcp_retransmit_timer(), a window shrunk connection will be regarded
as timeout if 'tcp_jiffies32 - tp->rcv_tstamp > TCP_RTO_MAX'. This is not
right all the time.

The retransmits will become zero-window probes in tcp_retransmit_timer()
if the 'snd_wnd==0'. Therefore, the icsk->icsk_rto will come up to
TCP_RTO_MAX sooner or later.

However, the timer can be delayed and be triggered after 122877ms, not
TCP_RTO_MAX, as I tested.

Therefore, 'tcp_jiffies32 - tp->rcv_tstamp > TCP_RTO_MAX' is always true
once the RTO come up to TCP_RTO_MAX, and the socket will die.

Fix this by replacing the 'tcp_jiffies32' with '(u32)icsk->icsk_timeout',
which is exact the timestamp of the timeout.

However, "tp->rcv_tstamp" can restart from idle, then tp->rcv_tstamp
could already be a long time (minutes or hours) in the past even on the
first RTO. So we double check the timeout with the duration of the
retransmission.

Meanwhile, making "2 * TCP_RTO_MAX" as the timeout to avoid the socket
dying too soon.

Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Link: https://lore.kernel.org/netdev/CADxym3YyMiO+zMD4zj03YPM3FBi-1LHi6gSD2XT8pyAMM096pg@mail.gmail.com/
Signed-off-by: Menglong Dong <imagedong@tencent.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-07-18 11:40:56 +02:00
Eric Dumazet
39dc2b8d55 tcp: refactor tcp_retransmit_timer()
commit 0d580fbd2db084a5c96ee9c00492236a279d5e0f upstream.

It appears linux-4.14 stable needs a backport of commit
88f8598d0a ("tcp: exit if nothing to retransmit on RTO timeout")

Since tcp_rtx_queue_empty() is not in pre 4.15 kernels,
let's refactor tcp_retransmit_timer() to only use tcp_rtx_queue_head()

I will provide to stable teams the squashed patches.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Willem de Bruijn <willemb@google.com>
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Acked-by: Soheil Hassas Yeganeh <soheil@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-07-18 11:40:56 +02:00
felix
7d61d1da2e SUNRPC: Fix RPC client cleaned up the freed pipefs dentries
commit bfca5fb4e97c46503ddfc582335917b0cc228264 upstream.

RPC client pipefs dentries cleanup is in separated rpc_remove_pipedir()
workqueue,which takes care about pipefs superblock locking.
In some special scenarios, when kernel frees the pipefs sb of the
current client and immediately alloctes a new pipefs sb,
rpc_remove_pipedir function would misjudge the existence of pipefs
sb which is not the one it used to hold. As a result,
the rpc_remove_pipedir would clean the released freed pipefs dentries.

To fix this issue, rpc_remove_pipedir should check whether the
current pipefs sb is consistent with the original pipefs sb.

This error can be catched by KASAN:
=========================================================
[  250.497700] BUG: KASAN: slab-use-after-free in dget_parent+0x195/0x200
[  250.498315] Read of size 4 at addr ffff88800a2ab804 by task kworker/0:18/106503
[  250.500549] Workqueue: events rpc_free_client_work
[  250.501001] Call Trace:
[  250.502880]  kasan_report+0xb6/0xf0
[  250.503209]  ? dget_parent+0x195/0x200
[  250.503561]  dget_parent+0x195/0x200
[  250.503897]  ? __pfx_rpc_clntdir_depopulate+0x10/0x10
[  250.504384]  rpc_rmdir_depopulate+0x1b/0x90
[  250.504781]  rpc_remove_client_dir+0xf5/0x150
[  250.505195]  rpc_free_client_work+0xe4/0x230
[  250.505598]  process_one_work+0x8ee/0x13b0
...
[   22.039056] Allocated by task 244:
[   22.039390]  kasan_save_stack+0x22/0x50
[   22.039758]  kasan_set_track+0x25/0x30
[   22.040109]  __kasan_slab_alloc+0x59/0x70
[   22.040487]  kmem_cache_alloc_lru+0xf0/0x240
[   22.040889]  __d_alloc+0x31/0x8e0
[   22.041207]  d_alloc+0x44/0x1f0
[   22.041514]  __rpc_lookup_create_exclusive+0x11c/0x140
[   22.041987]  rpc_mkdir_populate.constprop.0+0x5f/0x110
[   22.042459]  rpc_create_client_dir+0x34/0x150
[   22.042874]  rpc_setup_pipedir_sb+0x102/0x1c0
[   22.043284]  rpc_client_register+0x136/0x4e0
[   22.043689]  rpc_new_client+0x911/0x1020
[   22.044057]  rpc_create_xprt+0xcb/0x370
[   22.044417]  rpc_create+0x36b/0x6c0
...
[   22.049524] Freed by task 0:
[   22.049803]  kasan_save_stack+0x22/0x50
[   22.050165]  kasan_set_track+0x25/0x30
[   22.050520]  kasan_save_free_info+0x2b/0x50
[   22.050921]  __kasan_slab_free+0x10e/0x1a0
[   22.051306]  kmem_cache_free+0xa5/0x390
[   22.051667]  rcu_core+0x62c/0x1930
[   22.051995]  __do_softirq+0x165/0x52a
[   22.052347]
[   22.052503] Last potentially related work creation:
[   22.052952]  kasan_save_stack+0x22/0x50
[   22.053313]  __kasan_record_aux_stack+0x8e/0xa0
[   22.053739]  __call_rcu_common.constprop.0+0x6b/0x8b0
[   22.054209]  dentry_free+0xb2/0x140
[   22.054540]  __dentry_kill+0x3be/0x540
[   22.054900]  shrink_dentry_list+0x199/0x510
[   22.055293]  shrink_dcache_parent+0x190/0x240
[   22.055703]  do_one_tree+0x11/0x40
[   22.056028]  shrink_dcache_for_umount+0x61/0x140
[   22.056461]  generic_shutdown_super+0x70/0x590
[   22.056879]  kill_anon_super+0x3a/0x60
[   22.057234]  rpc_kill_sb+0x121/0x200

Fixes: 0157d021d2 ("SUNRPC: handle RPC client pipefs dentries by network namespace aware routines")
Signed-off-by: felix <fuzhen5@huawei.com>
Signed-off-by: Trond Myklebust <trond.myklebust@hammerspace.com>
Signed-off-by: Hagar Hemdan <hagarhem@amazon.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-07-18 11:40:56 +02:00
Ilya Dryomov
63e5d035e3 libceph: fix race between delayed_work() and ceph_monc_stop()
commit 69c7b2fe4c9cc1d3b1186d1c5606627ecf0de883 upstream.

The way the delayed work is handled in ceph_monc_stop() is prone to
races with mon_fault() and possibly also finish_hunting().  Both of
these can requeue the delayed work which wouldn't be canceled by any of
the following code in case that happens after cancel_delayed_work_sync()
runs -- __close_session() doesn't mess with the delayed work in order
to avoid interfering with the hunting interval logic.  This part was
missed in commit b5d91704f5 ("libceph: behave in mon_fault() if
cur_mon < 0") and use-after-free can still ensue on monc and objects
that hang off of it, with monc->auth and monc->monmap being
particularly susceptible to quickly being reused.

To fix this:

- clear monc->cur_mon and monc->hunting as part of closing the session
  in ceph_monc_stop()
- bail from delayed_work() if monc->cur_mon is cleared, similar to how
  it's done in mon_fault() and finish_hunting() (based on monc->hunting)
- call cancel_delayed_work_sync() after the session is closed

Cc: stable@vger.kernel.org
Link: https://tracker.ceph.com/issues/66857
Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
Reviewed-by: Xiubo Li <xiubli@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-07-18 11:40:55 +02:00
Edson Juliano Drosdeck
2b59187cf0 ALSA: hda/realtek: Limit mic boost on VAIO PRO PX
commit 6db03b1929e207d2c6e84e75a9cd78124b3d6c6d upstream.

The internal mic boost on the VAIO models VJFE-CL and VJFE-IL is too high.
Fix this by applying the ALC269_FIXUP_LIMIT_INT_MIC_BOOST fixup to the machine
to limit the gain.

Signed-off-by: Edson Juliano Drosdeck <edson.drosdeck@gmail.com>
Cc: <stable@vger.kernel.org>
Link: https://patch.msgid.link/20240705141012.5368-1-edson.drosdeck@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-07-18 11:40:55 +02:00
Joy Chakraborty
427524ff30 nvmem: meson-efuse: Fix return value of nvmem callbacks
commit 7a0a6d0a7c805f9380381f4deedffdf87b93f408 upstream.

Read/write callbacks registered with nvmem core expect 0 to be returned
on success and a negative value to be returned on failure.

meson_efuse_read() and meson_efuse_write() call into
meson_sm_call_read() and meson_sm_call_write() respectively which return
the number of bytes read or written on success as per their api
description.

Fix to return error if meson_sm_call_read()/meson_sm_call_write()
returns an error else return 0.

Fixes: a29a63bdaf ("nvmem: meson-efuse: simplify read callback")
Cc: stable@vger.kernel.org
Signed-off-by: Joy Chakraborty <joychakr@google.com>
Reviewed-by: Dan Carpenter <dan.carpenter@linaro.org>
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Srinivas Kandagatla <srinivas.kandagatla@linaro.org>
Link: https://lore.kernel.org/r/20240628113704.13742-3-srinivas.kandagatla@linaro.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-07-18 11:40:55 +02:00
He Zhe
db18df897d hpet: Support 32-bit userspace
commit 4e60131d0d36af65ab9c9144f4f163fe97ae36e8 upstream.

hpet_compat_ioctl and read file operations failed to handle parameters from
32-bit userspace and thus samples/timers/hpet_example.c fails as below.

root@intel-x86-64:~# ./hpet_example-32.out poll /dev/hpet 1 2
-hpet: executing poll
hpet_poll: HPET_IRQFREQ failed

This patch fixes cmd and arg handling in hpet_compat_ioctl and adds compat
handling for 32-bit userspace in hpet_read.

hpet_example now shows that it works for both 64-bit and 32-bit.

root@intel-x86-64:~# ./hpet_example-32.out poll /dev/hpet 1 2
-hpet: executing poll
hpet_poll: info.hi_flags 0x0
hpet_poll: expired time = 0xf4298
hpet_poll: revents = 0x1
hpet_poll: data 0x1
hpet_poll: expired time = 0xf4235
hpet_poll: revents = 0x1
hpet_poll: data 0x1
root@intel-x86-64:~# ./hpet_example-64.out poll /dev/hpet 1 2
-hpet: executing poll
hpet_poll: info.hi_flags 0x0
hpet_poll: expired time = 0xf42a1
hpet_poll: revents = 0x1
hpet_poll: data 0x1
hpet_poll: expired time = 0xf4232
hpet_poll: revents = 0x1
hpet_poll: data 0x1

Cc: stable@vger.kernel.org
Signed-off-by: He Zhe <zhe.he@windriver.com>
Fixes: 54066a57c5 ("hpet: kill BKL, add compat_ioctl")
Reviewed-by: Arnd Bergmann <arnd@arndb.de>
Link: https://lore.kernel.org/r/20240606123908.738733-1-zhe.he@windriver.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-07-18 11:40:55 +02:00
Alan Stern
60abea505b USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor
commit a368ecde8a5055b627749b09c6218ef793043e47 upstream.

Syzbot has identified a bug in usbcore (see the Closes: tag below)
caused by our assumption that the reserved bits in an endpoint
descriptor's bEndpointAddress field will always be 0.  As a result of
the bug, the endpoint_is_duplicate() routine in config.c (and possibly
other routines as well) may believe that two descriptors are for
distinct endpoints, even though they have the same direction and
endpoint number.  This can lead to confusion, including the bug
identified by syzbot (two descriptors with matching endpoint numbers
and directions, where one was interrupt and the other was bulk).

To fix the bug, we will clear the reserved bits in bEndpointAddress
when we parse the descriptor.  (Note that both the USB-2.0 and USB-3.1
specs say these bits are "Reserved, reset to zero".)  This requires us
to make a copy of the descriptor earlier in usb_parse_endpoint() and
use the copy instead of the original when checking for duplicates.

Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Reported-and-tested-by: syzbot+8693a0bb9c10b554272a@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/linux-usb/0000000000003d868e061bc0f554@google.com/
Fixes: 0a8fd13462 ("USB: fix problems with duplicate endpoint addresses")
CC: Oliver Neukum <oneukum@suse.com>
CC: stable@vger.kernel.org
Link: https://lore.kernel.org/r/205a5edc-7fef-4159-b64a-80374b6b101a@rowland.harvard.edu
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-07-18 11:40:55 +02:00
Lee Jones
c95fbdde87 usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()
commit 6d3c721e686ea6c59e18289b400cc95c76e927e0 upstream.

Userspace provided string 's' could trivially have the length zero. Left
unchecked this will firstly result in an OOB read in the form
`if (str[0 - 1] == '\n') followed closely by an OOB write in the form
`str[0 - 1] = '\0'`.

There is already a validating check to catch strings that are too long.
Let's supply an additional check for invalid strings that are too short.

Signed-off-by: Lee Jones <lee@kernel.org>
Cc: stable <stable@kernel.org>
Link: https://lore.kernel.org/r/20240705074339.633717-1-lee@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-07-18 11:40:55 +02:00
WangYuli
4fdf8c1442 USB: Add USB_QUIRK_NO_SET_INTF quirk for START BP-850k
commit 3859e85de30815a20bce7db712ce3d94d40a682d upstream.

START BP-850K is a dot matrix printer that crashes when
it receives a Set-Interface request and needs USB_QUIRK_NO_SET_INTF
to work properly.

Cc: stable <stable@kernel.org>
Signed-off-by: jinxiaobo <jinxiaobo@uniontech.com>
Signed-off-by: WangYuli <wangyuli@uniontech.com>
Link: https://lore.kernel.org/r/202E4B2BD0F0FEA4+20240702154408.631201-1-wangyuli@uniontech.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-07-18 11:40:55 +02:00