"LA.UM.9.14.1.r1-10900-QCM6490.QSSI14.0"
* tag 'LA.UM.9.14.1.r1-10900-QCM6490.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qca-wifi-host-cmn:
qcacmn: Fix low TPC power for vendor DTPC IE
qcacmn: set pdev id to 0xFF when set country code
qcacmn: Update preauth candidate entry to scan table
qcacmn: Dont add the wmi header size while allocating the wmi buff
qcacmn: Reduce the log level from error to info
qcacmn: add vendor command to configure the parameters for monitor mode
Revert "qcacmn: add vendor command to configure the parameters for monitor mode"
qcacmn: Add cdp api to update the packet capture mode
qcacmn: add vendor command to configure the parameters for monitor mode
qcacmn: Add APIs to get data packets info
qcacmn: Drop non-eapol packets for unauthorized peer
qcacmn: Fix possible OOB in wmi_extract_dbr_buf_release_entry
Revert "qcacmn: add wmi service for tx aggregation support"
qcacmn: add wmi service for tx aggregation support
Change-Id: I1bc6d399f20e906c9366e0a816952cb5dfe865b6
"LA.UM.9.14.1.r1-10900-QCM6490.QSSI14.0"
* tag 'LA.UM.9.14.1.r1-10900-QCM6490.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/fw-api:
Revert "fw-api: update below 4 CLs in fw common interface files".
fw-api: update below 4 CLs in fw common interface files
Change-Id: Ib291ad69feefd8daa92547e9352d9c3889f11aac
"LA.UM.9.14.1.r1-10900-QCM6490.QSSI14.0"
* tag 'LA.UM.9.14.1.r1-10900-QCM6490.QSSI14.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4:
msm: kgsl: Defer drawobj_sync_timeline_fence_work() to a workqueue
BACKPORT: of: base: Skip CPU nodes with "fail"/"fail-..." status
qcom: cpufreq-hw: Use the topology coreid for offset
msm: kgsl: Check user generated timestamp before queuing drawobjs
msm: kgsl: Keep postamble packets in a privileged buffer
net: qrtr: haven: Add bounds check on tx path
pci: msm: Add support to retry for sending rpmsg
cpu-topology: Change the size of allocation for cpu's
devfreq: memlat: Correct the num_cpus in memlat-mon
core_ctl: Add check for available cpus before accessing per_cpus
msm: kgsl: Remove protected GPUCC registers from snapshot
wifi: cfg80211: fix BSS refcounting bugs
wifi: cfg80211: avoid nontransmitted BSS list corruption
wifi: cfg80211: fix u8 overflow in cfg80211_update_notlisted_nontrans()
cnss2: Add code to fallback to non-contiguous FW mem allocation
msm: kgsl: Fix gpuaddr_in_range() to check upper bound
msm: kgsl: Remove 'fd' dependency to get dma_buf handle
msm: kgsl: Zap performance counters across context switches
msm: kgsl: Update the IFPC power up reglist
msm: kgsl: Update register protection config
msm: kgsl: Add support for A643 GPU
Change-Id: Ie958b06794787ef0672bb2cdd0c12911b819f3d5
* 'master' of https://github.com/namjaejeon/linux-exfat-oot:
exfat: add necessary header for vmalloc
exfat: release s_lock before calling dir_emit()
exfat: check if filename entries exceeds max filename length
exfat: github action: make space for running xfstests
exfat: use kvmalloc_array/kvfree instead of kmalloc_array/kfree
exfat: splice: Use filemap_splice_read() instead of generic_file_splice_read()
exfat: fs: build the legacy direct I/O code conditionally
exfat: fs: port ->rename() to pass mnt_idmap
exfat: fs: port ->mkdir() to pass mnt_idmap
exfat: fs: port ->create() to pass mnt_idmap
exfat: fs: port ->getattr() to pass mnt_idmap
exfat: fs: port ->setattr() to pass mnt_idmap
exfat: fix the newly allocated clusters are not freed in error handling
exfat: don't print error log in normal case
exfat: remove unneeded code from exfat_alloc_cluster()
exfat: remove ->writepage
exfat: handle unreconized benign secondary entries
exfat: fix inode->i_blocks for non-512 byte sector size device
exfat: redefine DIR_DELETED as the bad cluster number
exfat: fix reporting fs error when reading dir beyond EOF
exfat: fix unexpected EOF while reading dir
exfat: reuse exfat_find_location() to simplify exfat_get_dentry_set()
exfat: fix overflow in sector and cluster conversion
exfat: remove i_size_write() from __exfat_truncate()
exfat: remove argument 'size' from exfat_truncate()
exfat: remove unnecessary arguments from exfat_find_dir_entry()
exfat: remove unneeded codes from __exfat_rename()
exfat: remove call ilog2() from exfat_readdir()
exfat: remove generic/286
exfat: fix python package installation failure
exfat: github actions: add apt-get update command
exfat: treewide: use get_random_u32() when possible
exfat: replace magic numbers with Macros
exfat: rename exfat_free_dentry_set() to exfat_put_dentry_set()
exfat: move exfat_entry_set_cache from heap to stack
exfat: support dynamic allocate bh for exfat_entry_set_cache
exfat: reduce the size of exfat_entry_set_cache
exfat: add SECTOR_SIZE macro
exfat: hint the empty entry which at the end of cluster chain
exfat: simplify empty entry hint
exfat: add auto-test using github action
exfat: remove travis-CI test
exfat: release 6.0.0 version
exfat: fix overflow for large capacity partition
exfat: add auto build-test and simple stability test using travis-CI
exfat: Drop superfluous new line for error messages
exfat: Downgrade ENAMETOOLONG error message to debug messages
exfat: Expand exfat_err() and co directly to pr_*() macro
exfat: Define NLS_NAME_* as bit flags explicitly
exfat: Return ENAMETOOLONG consistently for oversized paths
exfat: simplified by using round_up()
fs: Convert mpage_readpage to mpage_read_folio
fs: Remove flags parameter from aops->write_begin
fs: Remove aop flags parameter from cont_write_begin()
block: add a bdev_discard_granularity helper
block: remove QUEUE_FLAG_DISCARD
exfat: remove duplicate write inode for extending dir/file
exfat: remove duplicate write inode for truncating file
exfat: reuse __exfat_write_inode() to update directory entry
exfat: use updated exfat_chain directly during renaming
Change-Id: Ib68d90de9ea596296407f446fa611525034db193
"LA.UM.9.14.r1-22200-LAHAINA.QSSI14.0"
* tag 'LA.UM.9.14.r1-22200-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel:
ASoC: msm-pcm-q6-v2: Add dsp buf check
ASoC: Add the judgment for TDM
asoc: swrm: disable bus reset based on swrm verison
dsp: afe: Add check for sidetone iir config copy size
ASoC: msm-pcm-host-voice: Address buffer overflow in hpcm playback copy
ASoC: msm-pcm-voip: Avoid interger underflow
dsp: asm: validate payload size before access
dsp: afe: check for param size before copying
dsp: q6core: validate payload size before access for AVCS
dsp: afe: Add check for num_channels
soc: swr-mstr-ctrl: add new lock to sync runtime_resume and runtime_suspend
soc: reduce the auto suspend timeout when swr event finished
Change-Id: I82d3446a3ecf6cf47f75ab34a292557f24339ebb
"LA.UM.9.14.r1-22200-LAHAINA.QSSI14.0"
* tag 'LA.UM.9.14.r1-22200-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4:
usb: gadget: cdev: Add spinlock to synchronize ports->cbits_updated
msm: ep_pcie: Set clock power management bit for EP
msm: Add config option for R8168 IOSS glue driver
ipa_eth: Header change to pass more info from ETH to GSI
Change-Id: Ib6b27009e9867a605881464b80926daf6e0da25b
drawobj_sync_timeline_fence_work() does a cleanup of fence and syncobj
allocations. Doing this cleanup in irq context requires the irq_work
struct to remain valid after the function executes. Avoid this constraint
by deferring this work to the memory workqueue.
Change-Id: Icf648a61686c1ef3fd84467a2376b11a9a4bb803
Signed-off-by: Lynus Vaz <quic_lvaz@quicinc.com>
The reg in soc_dapm_mux is 32-bit. The BE DAI ID passed
as shift(to be operated on the reg) may be more than 31,
which may cause overflow.
Set reg field to SND_SOC_NOPM to avoid any DAPM operation
while passing BE IDs in shift_l field and hence avoid overflow.
Change-Id: Ibbbca04c61b7c56eb4c5a7485a4e93dc28a09709
Signed-off-by: Soumya Managoli <smanag@codeaurora.org>
[dereference23: Forward port to msm-5.4]
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
Initialize struct cm_roam_values_copy to avoid using uninitialized
parameters in wlan_cm_roam_cfg_set_value().
Initialize struct pdev_params to zero to avoid using uninitialized
parameters in wmi_unified_pdev_param_send().
Change-Id: I820db09840431487f1756695a0562f8a794f549f
CRs-Fixed: 3187194
Based on panel hardware support, display brightness levels can
be very high value. This high value display brightness cooling
device levels can cause exceeding PAGE_SIZE for cooling device stat
buffer. It leads to buffer failure for cooling device stat feature.
Limit display panel mitigation level max to 255. If hardware
supports more than 255, then scale brightness levels fit
into above limit.
Change-Id: Ieeee4ff2aa5cd884819b30b4fd9839e48ac4d804
Signed-off-by: Manaf Meethalavalappu Pallikunhi <manafm@codeaurora.org>
exfat_extract_uni_name copies characters from a given file name entry into
the 'uniname' variable. This variable is actually defined on the stack of
the exfat_readdir() function. According to the definition of
the 'exfat_uni_name' type, the file name should be limited 255 characters
(+ null teminator space), but the exfat_get_uniname_from_ext_entry()
function can write more characters because there is no check if filename
entries exceeds max filename length. This patch add the check not to copy
filename characters when exceeding max filename length.
Cc: stable@vger.kernel.org
Cc: Yuezhang Mo <Yuezhang.Mo@sony.com>
Reported-by: Maxim Suhanov <dfirblog@gmail.com>
Reviewed-by: Sungjong Seo <sj1557.seo@samsung.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
github action seems to decrease disk space of each users. This patch try
to remove file creation test and reset test images in the middle of testing xfstests
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
The call stack shown below is a scenario in the Linux 4.19 kernel.
Allocating memory failed where exfat fs use kmalloc_array due to
system memory fragmentation, while the u-disk was inserted without
recognition.
Devices such as u-disk using the exfat file system are pluggable and
may be insert into the system at any time.
However, long-term running systems cannot guarantee the continuity of
physical memory. Therefore, it's necessary to address this issue.
Binder:2632_6: page allocation failure: order:4,
mode:0x6040c0(GFP_KERNEL|__GFP_COMP), nodemask=(null)
Call trace:
[242178.097582] dump_backtrace+0x0/0x4
[242178.097589] dump_stack+0xf4/0x134
[242178.097598] warn_alloc+0xd8/0x144
[242178.097603] __alloc_pages_nodemask+0x1364/0x1384
[242178.097608] kmalloc_order+0x2c/0x510
[242178.097612] kmalloc_order_trace+0x40/0x16c
[242178.097618] __kmalloc+0x360/0x408
[242178.097624] load_alloc_bitmap+0x160/0x284
[242178.097628] exfat_fill_super+0xa3c/0xe7c
[242178.097635] mount_bdev+0x2e8/0x3a0
[242178.097638] exfat_fs_mount+0x40/0x50
[242178.097643] mount_fs+0x138/0x2e8
[242178.097649] vfs_kern_mount+0x90/0x270
[242178.097655] do_mount+0x798/0x173c
[242178.097659] ksys_mount+0x114/0x1ac
[242178.097665] __arm64_sys_mount+0x24/0x34
[242178.097671] el0_svc_common+0xb8/0x1b8
[242178.097676] el0_svc_handler+0x74/0x90
[242178.097681] el0_svc+0x8/0x340
By analyzing the exfat code,we found that continuous physical memory
is not required here,so kvmalloc_array is used can solve this problem.
Signed-off-by: gaoming <gaoming20@hihonor.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Consider a scenario in which open, write and close of AT port is being
done repeatedly. At some point in time, cbits_updated in f_cdev
structure gets overwritten by the previous close instance causing the AT
port to go unresponsive. This prevents port bridge service from sending
DTR/RTS settings to at_mdm0 from at_usb0.
Fix this by adding spinlock to synchronise the updation of
ports->cbits_updated field in f_cdev structure.
Change-Id: Ibf39aa90f3918cd5f22e32a3b06685db4c4298ae
Signed-off-by: Pratham Pratap <quic_ppratap@quicinc.com>
Add a new LEGACY_DIRECT_IO config symbol that is only selected by the
file systems that still use the legacy blockdev_direct_IO code, so that
kernels without support for those file systems don't need to build the
code.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Jan Kara <jack@suse.cz>
Reviewed-by: Eric Biggers <ebiggers@google.com>
Link: https://lore.kernel.org/r/20230125065839.191256-3-hch@lst.de
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Convert to struct mnt_idmap.
Last cycle we merged the necessary infrastructure in
256c8aed2b42 ("fs: introduce dedicated idmap type for mounts").
This is just the conversion to struct mnt_idmap.
Currently we still pass around the plain namespace that was attached to a
mount. This is in general pretty convenient but it makes it easy to
conflate namespaces that are relevant on the filesystem with namespaces
that are relevent on the mount level. Especially for non-vfs developers
without detailed knowledge in this area this can be a potential source for
bugs.
Once the conversion to struct mnt_idmap is done all helpers down to the
really low-level helpers will take a struct mnt_idmap argument instead of
two namespace arguments. This way it becomes impossible to conflate the two
eliminating the possibility of any bugs. All of the vfs and all filesystems
only operate on struct mnt_idmap.
Acked-by: Dave Chinner <dchinner@redhat.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Christian Brauner (Microsoft) <brauner@kernel.org>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Convert to struct mnt_idmap.
Last cycle we merged the necessary infrastructure in
256c8aed2b42 ("fs: introduce dedicated idmap type for mounts").
This is just the conversion to struct mnt_idmap.
Currently we still pass around the plain namespace that was attached to a
mount. This is in general pretty convenient but it makes it easy to
conflate namespaces that are relevant on the filesystem with namespaces
that are relevent on the mount level. Especially for non-vfs developers
without detailed knowledge in this area this can be a potential source for
bugs.
Once the conversion to struct mnt_idmap is done all helpers down to the
really low-level helpers will take a struct mnt_idmap argument instead of
two namespace arguments. This way it becomes impossible to conflate the two
eliminating the possibility of any bugs. All of the vfs and all filesystems
only operate on struct mnt_idmap.
Acked-by: Dave Chinner <dchinner@redhat.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Christian Brauner (Microsoft) <brauner@kernel.org>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Convert to struct mnt_idmap.
Last cycle we merged the necessary infrastructure in
256c8aed2b42 ("fs: introduce dedicated idmap type for mounts").
This is just the conversion to struct mnt_idmap.
Currently we still pass around the plain namespace that was attached to a
mount. This is in general pretty convenient but it makes it easy to
conflate namespaces that are relevant on the filesystem with namespaces
that are relevent on the mount level. Especially for non-vfs developers
without detailed knowledge in this area this can be a potential source for
bugs.
Once the conversion to struct mnt_idmap is done all helpers down to the
really low-level helpers will take a struct mnt_idmap argument instead of
two namespace arguments. This way it becomes impossible to conflate the two
eliminating the possibility of any bugs. All of the vfs and all filesystems
only operate on struct mnt_idmap.
Acked-by: Dave Chinner <dchinner@redhat.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Christian Brauner (Microsoft) <brauner@kernel.org>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Convert to struct mnt_idmap.
Last cycle we merged the necessary infrastructure in
256c8aed2b42 ("fs: introduce dedicated idmap type for mounts").
This is just the conversion to struct mnt_idmap.
Currently we still pass around the plain namespace that was attached to a
mount. This is in general pretty convenient but it makes it easy to
conflate namespaces that are relevant on the filesystem with namespaces
that are relevent on the mount level. Especially for non-vfs developers
without detailed knowledge in this area this can be a potential source for
bugs.
Once the conversion to struct mnt_idmap is done all helpers down to the
really low-level helpers will take a struct mnt_idmap argument instead of
two namespace arguments. This way it becomes impossible to conflate the two
eliminating the possibility of any bugs. All of the vfs and all filesystems
only operate on struct mnt_idmap.
Acked-by: Dave Chinner <dchinner@redhat.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Christian Brauner (Microsoft) <brauner@kernel.org>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Convert to struct mnt_idmap.
Last cycle we merged the necessary infrastructure in
256c8aed2b42 ("fs: introduce dedicated idmap type for mounts").
This is just the conversion to struct mnt_idmap.
Currently we still pass around the plain namespace that was attached to a
mount. This is in general pretty convenient but it makes it easy to
conflate namespaces that are relevant on the filesystem with namespaces
that are relevent on the mount level. Especially for non-vfs developers
without detailed knowledge in this area this can be a potential source for
bugs.
Once the conversion to struct mnt_idmap is done all helpers down to the
really low-level helpers will take a struct mnt_idmap argument instead of
two namespace arguments. This way it becomes impossible to conflate the two
eliminating the possibility of any bugs. All of the vfs and all filesystems
only operate on struct mnt_idmap.
Acked-by: Dave Chinner <dchinner@redhat.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Christian Brauner (Microsoft) <brauner@kernel.org>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
In error handling 'free_cluster', before num_alloc clusters allocated,
p_chain->size will not updated and always 0, thus the newly allocated
clusters are not freed.
Signed-off-by: Yuezhang Mo <Yuezhang.Mo@sony.com>
Reviewed-by: Andy Wu <Andy.Wu@sony.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
When allocating a new cluster, exFAT first allocates from the
next cluster of the last cluster of the file. If the last cluster
of the file is the last cluster of the volume, allocate from the
first cluster. This is a normal case, but the following error log
will be printed. It makes users confused, so this commit removes
the error log.
[1960905.181545] exFAT-fs (sdb1): hint_cluster is invalid (262130)
Signed-off-by: Yuezhang Mo <Yuezhang.Mo@sony.com>
Reviewed-by: Andy Wu <Andy.Wu@sony.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
In the removed code, num_clusters is 0, nothing is done in
exfat_chain_cont_cluster(), so it is unneeded, remove it.
Signed-off-by: Yuezhang Mo <Yuezhang.Mo@sony.com>
Reviewed-by: Andy Wu <Andy.Wu@sony.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Patch series "start removing writepage instances v2".
The VM doesn't need or want ->writepage for writeback and is fine with
just having ->writepages as long as ->migrate_folio is implemented.
This series removes all ->writepage instances that use
block_write_full_page directly and also have a plain mpage_writepages
based ->writepages.
This patch (of 7):
->writepage is a very inefficient method to write back data, and only used
through write_cache_pages or a a fallback when no ->migrate_folio method
is present.
Set ->migrate_folio to the generic buffer_head based helper, and remove
the ->writepage implementation.
Link: https://lkml.kernel.org/r/20221202102644.770505-1-hch@lst.de
Link: https://lkml.kernel.org/r/20221202102644.770505-2-hch@lst.de
Signed-off-by: Christoph Hellwig <hch@lst.de>
Acked-by: Namjae Jeon <linkinjeon@kernel.org>
Acked-by: Johannes Weiner <hannes@cmpxchg.org>
Cc: Bob Copeland <me@bobcopeland.com>
Cc: Dave Kleikamp <shaggy@kernel.org>
Cc: Jan Kara <jack@suse.com>
Cc: Mikulas Patocka <mikulas@artax.karlin.mff.cuni.cz>
Cc: OGAWA Hirofumi <hirofumi@mail.parknet.co.jp>
Cc: Sungjong Seo <sj1557.seo@samsung.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
"LA.UM.9.14.r1-22000-LAHAINA.QSSI12.0"
* tag 'LA.UM.9.14.r1-22000-LAHAINA.QSSI12.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4:
cpufreq: schedutil: Fix UAF issue
msm: mhi_dev: Support async write in UCI for size greater than 8k
mtd: msm_qpic_nand: Add boot_a and boot_b access to APPS
qcom: cpufreq-hw: Use the topology coreid for offset
soc: qcom: Add Upperbounds check for program header
msm: adsprpc: Handle UAF in fastrpc_buf_free
interconnect: qcom: sm8150: fix UAF under remove function
interconnect: qcom: monaco: fix UAF under remove function
interconnect: qcom: direwolf: fix UAF under remove function
interconnect: qcom: yupik: fix UAF under remove function
interconnect: qcom: sdxnightjar: fix UAF under remove function
interconnect: qcom: sdxlemur: fix UAF under remove function
interconnect: qcom: sm6150: fix UAF under remove function
interconnect: qcom: shima: fix UAF under remove function
interconnect: qcom: scshrike: fix UAF under remove function
interconnect: qcom: lahaina: fix UAF under remove function
interconnect: qcom: holi: fix UAF under remove function
qcedev: vote for crypto clocks during module close
msm: synx: Check for zero before reducing bind handles
msm: adsprpc: Handle UAF in fastrpc internal munmap
mtd: msm_qpic_nand: Add boot_a and boot_b access to APPS
coresight-tmc: increase qdss pcie sw path throughput
net: qrtr: Move service id based filter check before queueing skb
defconfig: sdxlemur: Enable R8168 driver config
virt: haven: rsc_mgr: Allocate right buffer size of requests
Conflicts:
arch/arm64/boot/dts/vendor/bindings/phy/amlogic,g12a-usb3-pcie-phy.yaml
arch/arm64/boot/dts/vendor/bindings/sound/qcom,wcd9335.txt
drivers/edac/qcom_edac.c
drivers/net/ethernet/stmicro/stmmac/dwmac-qcom-ethqos.c
drivers/net/ethernet/stmicro/stmmac/stmmac_hwtstamp.c
drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
mm/khugepaged.c
Change-Id: I5b49e94db45d481ea90ba77800b26c32bd7433ab
https://source.android.com/docs/security/bulletin/2023-07-01
CVE-2022-42703
CVE-2023-21255
CVE-2023-25012
* tag 'ASB-2023-07-05_11-5.4' of https://android.googlesource.com/kernel/common:
UPSTREAM: ipvlan:Fix out-of-bounds caused by unclear skb->cb
UPSTREAM: net/sched: cls_u32: Fix reference counter leak leading to overflow
UPSTREAM: memstick: r592: Fix UAF bug in r592_remove due to race condition
BACKPORT: btrfs: unset reloc control if transaction commit fails in prepare_to_relocate()
ANDROID: HID: Only utilise UHID provided exports if UHID is enabled
UPSTREAM: bluetooth: Perform careful capability checks in hci_sock_ioctl()
ANDROID: HID; Over-ride default maximum buffer size when using UHID
Revert "ANDROID: AVB error handler to invalidate vbmeta partition."
UPSTREAM: mailbox: mailbox-test: fix a locking issue in mbox_test_message_write()
UPSTREAM: mailbox: mailbox-test: Fix potential double-free in mbox_test_message_write()
UPSTREAM: efi: rt-wrapper: Add missing include
BACKPORT: arm64: efi: Execute runtime services from a dedicated stack
Change-Id: I1f90844654d86b0a8507de963cb574813fdbf99b
According to PCIe spec, PCIE_CAP_CLOCK_POWER_MAN bit in
LINK_CAPABILITIES_REG register should be set for EP. But it is seen as
cleared after core reset. In the current driver this bit is being set
but it is not taking effect. Enabling CLK_PM_EN in PCIE_ELBI_SYS_CTRL
register, so that PCIE_CAP_CLOCK_POWER_MAN is set.
Change-Id: I16654d5a477fa8eeaad61d6ec1dd32757627e2f9
Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
Fix is to add check for this ADSP returned buf offset + size,
if it is within the available buf size range
Change-Id: I400cc4f5c07164f0a9b405ebea144ea0ae4b6cf2
Signed-off-by: Shalini Manjunatha <quic_c_shalma@quicinc.com>
[ Upstream commit 04c55383fa5689357bcdd2c8036725a55ed632bc ]
In the event of a failure in tcf_change_indev(), u32_set_parms() will
immediately return without decrementing the recently incremented
reference counter. If this happens enough times, the counter will
rollover and the reference freed, leading to a double free which can be
used to do 'bad things'.
In order to prevent this, move the point of possible failure above the
point where the reference counter is incremented. Also save any
meaningful return values to be applied to the return data at the
appropriate point in time.
This issue was caught with KASAN.
Bug: 273251569
Fixes: 705c709126 ("net: sched: cls_u32: no need to call tcf_exts_change for newly allocated struct")
Suggested-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Lee Jones <lee@kernel.org>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit 07f9cc229b44cbcee6385802d390091d915f38c3)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I95524bfda9a08a40b3d54515e528419dba18dc55