"LA.UM.9.14.r1-24700-LAHAINA.QSSI15.0"
* tag 'LA.UM.9.14.r1-24700-LAHAINA.QSSI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel:
Asoc: dsp: Fix to check the list is empty or not
dsp: q6lsm: Check size of payload before access
Fix for OOB access issue
dsp: q6asm increase the locking range
ASoC: msm-pcm-q6-v2: Add size check
ASoC : Add proper copyright marking.
dsp: afe: Add check for num_spks
soc: pinctrl-lpi: remove pm ops
asoc: msm-compress: Fix compress_pause failure on gki
Audio legacy: Integer overflow in msm_lsm_ioctl_compat during audio playback usecase. size = sizeof(p_info_32) + p_info_32.param_size; This overflow issue may result heap overflow during copying the data: memcpy(param_info_rsp, &p_info_32, sizeof(p_info_32));
ASoC : Add macro to differentiate auto code
ASoC: msm: get CoPP index based on FE id
asoc: codecs: add array bound check
soc: Address SWR rate mismatch interrupt
asoc : add configuration about SLIMBUS_7_TX
asoc: lahaina: add support for aud_ref_clk_sel mux
dsp: afe: add support for aud_ref_clk_sel mux
ASoC: dsp: Release lock before return
ASoC: wcd937x: Add flag to decide RX_MUTE for HPHL and EAR
ASoC: bolero: Add check for CMPDR switch
ASoC : add support of HDMI controller for rb3gen2 platform
asoc: lahaina: fractional sample rate support for TDM
asoc: support for fractional sample rate over tdm
Revert "asoc: msm-compress : Fix for CTS-on-gsi with gki"
audio-kernel:swr: Add dynamic SWRM clk support
asoc: codec: make mclk freq configurable in Bolero
asoc: lahaina: Add ext clk source support
asoc: ext-clk: Add support for configuring ext clk
dsp: afe: Enhance and expose API for configuring ext clk
dsp: q6voice: Handle mutex lock-unlock
asoc: msm-compress : Fix for CTS-on-gsi with gki
Change-Id: I21b8e5f5ef608bf298230419123e4ee37c9b0797
"LA.UM.9.14.r1-24700-LAHAINA.QSSI15.0"
* tag 'LA.UM.9.14.r1-24700-LAHAINA.QSSI15.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4:
msm: npu v1: Fix OOB issue in IPC between driver and firmware
mmc: sdhci-msm: Disable partial_init and clk-scaling to avoid RED error
slimbus: qcom-ngd-ctrl: Avoid accessing deallocated stack
msm_ipa: new structure for tunnel design for uC
msm: ipa3: change variable name for indication of rx tlv format
soc: qcom: llcc: Handle a second device without data corruption
msm: eva: User after free fix in msm_cvp_mark_user_persist
rpmsg: slatecom: out of bound read from process_cmd
soc: qcom: msm_minidump: Configurable Encryption support
defconfig: arm64: Disable trimming non-whitelisted symbols
soc: qcom: add out of bound check for AON fifo
rpmsg: slatecom: maintain rx_size to read
Revert LLCC changes
bus: mhi: Fix potential out-of-bound access
Conflicts:
arch/arm64/boot/dts/vendor/bindings/interrupt-controller/ti,sci-intr.txt
drivers/soc/qcom/llcc-slice.c
drivers/usb/dwc3/core.c
kernel/events/core.c
mm/memory-failure.c
Change-Id: Ie4d89454f0766d0a48ebd4f2e6facb6deca9ea57
Currently struct ipa_wdi_conn_in_params occupies 1588 bytes and putting
it on the stack is rather expensive, which could potentially lead to
stack corruption.
Fix is to reduce stack usage in dp_ipa_setup by dynamically allocating
struct ipa_wdi_conn_in_params on the heap.
Change-Id: I8f71f44906a5c95f37627f7573b57b7825daaa7e
CRs-Fixed: 2852027
In qrtr_get_service_id, use xa_load instead of node_get to check
if the node exists or not. Calling node_get from interrupt context
can cause potential deadlock since it calls into xa_store to
allocate the node if it does not exist.
Change-Id: Ida9f7a113417f0d184c0903004d94dd2eca6c472
Signed-off-by: Sarannya S <quic_sarannya@quicinc.com>
The return value for of_property_count_u32_elems can be negative in the
case of an error or the property is not found. It is incorrect to use
size_t, unsigned type, as this can cause an overflow. Switch size from
type size_t to int.
Change-Id: Ica0425abd034b82994ab32087f04d602ce3dd9e9
Signed-off-by: Tony Truong <quic_truong@quicinc.com>
Fix a compilation error seen when casting void pointer to
int by casting it to uintptr_t instead.
Change-Id: I679da04f21041c386fa7ad8905ede94e12ea160c
Signed-off-by: Jishnu Prakash <quic_jprakash@quicinc.com>
../drivers/thermal/qcom/max31760_fan.c:331:3: error: ignoring return
value of function declared with 'warn_unused_result' attribute
[-Werror,-Wunused-result]
(pdata->vdd_reg);
^~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~
Change-Id: I06fb07da60cb765e4daf98c38afdb97690491c6f
Fixes:
../drivers/input/touchscreen/focaltech_touch/focaltech_core.c:979:3:
error: ignoring return value of function declared with
'warn_unused_result' attribute [-Werror,-Wunused-result]
PTR_ERR(acl_desc);
^~~~~~~ ~~~~~~~~
../drivers/input/touchscreen/focaltech_touch/focaltech_core.c:986:3:
error: ignoring return value of function declared with
'warn_unused_result' attribute [-Werror,-Wunused-result]
PTR_ERR(sgl_desc);
^~~~~~~ ~~~~~~~~
Change-Id: I941c32696a52a84a0a9272d4f969755932925aaa
../net/ipv4/tcp_timer.c:202:27: warning: implicit truncation from 'int' to a one-bit wide bit-field changes value from 1 to -1 [-Wsingle-bit-bitfield-constant-conversion]
icsk->icsk_mtup.enabled = 1;
Change-Id: I7e1b4013ba6a67fad27a611d30f98939ceaa5109
../techpack/dataipa/drivers/platform/msm/ipa/ipa_v3/rmnet_ipa.c:510:41: warning: implicit conversion from enumeration type 'enum ipa_ip_type_enum_v01' to different enumeration type 'enum ipa_ip_type' [-Wenum-conversion]
q6_ul_flt_rule_ptr->ip = flt_spec_ptr->ip_type;
~ ~~~~~~~~~~~~~~^~~~~~~
../techpack/dataipa/drivers/platform/msm/ipa/ipa_v3/rmnet_ipa.c:511:45: warning: implicit conversion from enumeration type 'enum ipa_filter_action_enum_v01' to different enumeration type 'enum ipa_flt_action' [-Wenum-conversion]
q6_ul_flt_rule_ptr->action = flt_spec_ptr->filter_action;
~ ~~~~~~~~~~~~~~^~~~~~~~~~~~~
Change-Id: I0eb68d707151cd103676a30659ab81bf6fced131
Ensures that no new warnings are introduced to the build.
Bug: 141372918
Change-Id: I4107af91f5c1ddd655037823350e005e8362d588
Signed-off-by: Chenglu Lin <chenglulin@google.com>
Add configuration option CONFIG_CC_WERROR to prevent warnings
from creeping in.
Bug: 141372918
Change-Id: Ie2d067c0177d8f13e9aaa9a78867998e390f89ee
Signed-off-by: Chenglu Lin <chenglulin@google.com>
When CONFIG_CFI_CLANG and CONFIG_DYNAMIC_FTRACE are enabled, LLVM will
generate a jump function named ftrace_call.cfi_jt for ftrace_call, which
makes "&ftrace_call" in ftrace_update_ftrace_func() actually the address
of ftrace_call.cfi_jt. As a result, the tracer can't be really enabled
through runtime modification. Use __va_function() to get the actual address
of ftrace_call to fix the issue.
Bug: 184105181
Signed-off-by: Ben Dai <ben.dai@unisoc.com>
Change-Id: Ic9272cd4ab447b3b145d8e397e5c9010c49f7a12
After the switch to non-canonical CFI jump tables, the jump table
sections were placed after the .text section. Merge these sections
into .text to fix issues with error injection and kallsyms.
Bug: 225079388
Bug: 190422440
Change-Id: I6c81b3e4dbba62739f7fc5f6b45271c54f278c8f
Signed-off-by: Sami Tolvanen <samitolvanen@google.com>
Handle error return value from copy_to_user() in ioctls to avoid
following compilation failure.
"error: ignoring return value of function declared with 'warn_unused_result'
attribute".
Change-Id: I92944ade7fb88e0543ca4254fab226da5777def7
Signed-off-by: Jeevan Shriram <quic_jshriram@quicinc.com>
It never hurts to know if drivers have some flaws.
Change-Id: Iba3acda0eeec9448fc907def5b3d25f117bc818b
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
This flag is specific to clang, where it is only used by the 32-bit and
64-bit ARM backends. In certain situations, the presence of this flag
will cause a warning, as shown by commit 6580c5c18fb3 ("um: clang: Strip
out -mno-global-merge from USER_CFLAGS").
Since commit 61163efae0 ("kbuild: LLVMLinux: Add Kbuild support for
building kernel with Clang") that added this flag back in 2014, there
have been quite a few changes to the GlobalMerge pass in LLVM. Building
several different ARCH=arm and ARCH=arm64 configurations with LLVM 11
(minimum) and 15 (current main version) with this flag removed (i.e.,
with the default of '-mglobal-merge') reveals no modpost warnings, so it
is likely that the issue noted in the comment is no longer relevant due
to changes in LLVM or modpost, meaning this flag can be removed.
If any new warnings show up that are a result of the removal of this
flag, it can be added back under arch/arm{,64}/Makefile to avoid
warnings on other architectures.
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Tested-by: David Gow <davidgow@google.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Tested-by: Sedat Dilek <sedat.dilek@gmail.com>
Reviewed-by: Sedat Dilek <sedat.dilek@gmail.com>
Signed-off-by: Masahiro Yamada <masahiroy@kernel.org>
(cherry picked from commit cf300b83c793c25c6b485fdaf7a4447d8ea4c655)
Change-Id: Ice39a960619319828b83c8091798fe383395a2b0
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
strlen(swr_dmic_name_prefix_of) + 1 bytes are allocated for prefix_name just above
techpack/audio/asoc/codecs/swr-dmic.c:685:11: error: size argument in 'strlcpy' call appears to be size of the source; expected the size of the destination [-Werror,-Wstrlcpy-strlcat-size]
strlen(swr_dmic_name_prefix_of) + 1);
~~~~~~~^~~~~~~~~~~~~~~~~~~~~~~~~~~~
1 error generated.
Change-Id: I808b4f135d42fc50587eeb9348848f7e0a3561cc
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
The size is checked just above.
../drivers/hwtracing/coresight/coresight-tmc.c:423:26: warning: 'sscanf' may overflow; destination buffer in argument 3 has size 10, but the corresponding specifier may require size 11 [-Wfortify-source]
423 | if (sscanf(buf, "%10s", str) != 1)
| ^
../drivers/hwtracing/coresight/coresight-tmc.c:464:26: warning: 'sscanf' may overflow; destination buffer in argument 3 has size 10, but the corresponding specifier may require size 11 [-Wfortify-source]
464 | if (sscanf(buf, "%10s", str) != 1)
| ^
2 warnings generated.
Change-Id: I5db199a85ba0c7dfc15fae5d62c9c4d8c550d3e7
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
Extracted from I54b58226e3d6de0b674ac4ca1407138d1c9707e8
../drivers/soc/qcom/msm_minidump.c:521:39: warning: size argument in 'strlcpy' call appears to be size of the source; expected the size of the destination [-Wstrlcpy-strlcat-size]
521 | strlcpy(banner, linux_banner, strlen(linux_banner) + 1);
| ~~~~~~~^~~~~~~~~~~~~~~~~
1 warning generated.
Change-Id: I43fa5006150dd402405f8c942571f08da0eb714a
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
Only 19 characters out of total 20 can be used due to the '\0' terminator.
Change-Id: I34883be26f97a16fdcb5ff97ff326d98f4d93c18
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
CAF cherry-picked an obsolete LLVMLinux patch from 2014 in commit
a2a31f1ddc that introduced this
unnecessary flag. Now that the functions used by Clang's libcall
optimizations have been implemented, we can allow Clang to perform said
optimizations for a minor performance bump in certain code paths.
Change-Id: Ifa6b731c9702973be2c656d341e33a6186ed7cf2
Signed-off-by: Danny Lin <danny@kdrag0n.dev>
This reverts commit 1210d2329b.
Unnecessary with Clang 6.0+.
Change-Id: I6f29ca050566e9027e51605e64bf6893602344ef
Signed-off-by: Danny Lin <danny@kdrag0n.dev>
We don't need to know that PM notifiers are working. Silence the entry/exit
log spam in ipa_pm_notify().
Change-Id: I9bae89fa5e27b8835683ec1423ecc751491ea13c
Signed-off-by: Sultan Alsawaf <sultan@osomprivacy.com>
After commit 1248f43abe ("arm64: Move the LSE gas support detection to Kconfig")
CONFIG_ARM64_USE_LSE_ATOMICS should be used to disable LSE atomics usage.
Change-Id: Ibb1abef274883b74b3d6151cc0fbe1647d5b9076
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
The conditional was mistakenly removed in e4e5585516.
Change-Id: If8fdb03cbda21a75b2c6ad00cee268f1a1c3ebe1
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
Do not mark MPM as wake irq. Break s2idle suspend when MPM irq
is pending.
Change-Id: Ia455c589fdadcaa3be6084a68990887a2d4c3517
Signed-off-by: Maulik Shah <quic_mkshah@quicinc.com>
Add IRQCHIP_SET_TYPE_MASKED flag for gpio and gic irqchips.
Change-Id: Ie6bf76ab2c98e4bc40ad4adfb13da9c9b69734c9
Signed-off-by: Maulik Shah <quic_mkshah@quicinc.com>
As mpm irq is not expected to fire during the suspend phase,
so irq set with IRQF_NO_SUSPEND is not required.
This patch removes the IRQF_NO_SUSPEND flag from mpm irq
request.
Change-Id: I546968efa093e14f056c245648c2409e88a1bc45
Signed-off-by: Raghavendra Kakarla <quic_rkakarla@quicinc.com>
https://source.android.com/docs/security/bulletin/2024-05-01
CVE-2023-4622
* tag 'ASB-2024-05-05_11-5.4' of https://android.googlesource.com/kernel/common:
ANDROID: 16K: Fix show maps CFI failure
ANDROID: 16K: Handle pad VMA splits and merges
ANDROID: 16K: madvise_vma_pad_pages: Remove filemap_fault check
ANDROID: 16K: Only madvise padding from dynamic linker context
ANDROID: 16K: Separate padding from ELF LOAD segment mappings
ANDROID: 16K: Exclude ELF padding for fault around range
ANDROID: 16K: Use MADV_DONTNEED to save VMA padding pages.
ANDROID: 16K: Introduce ELF padding representation for VMAs
ANDROID: 16K: Introduce /sys/kernel/mm/pgsize_miration/enabled
ANDROID: GKI: add snd_compr_stop_error to Xiaomi_abi
UPSTREAM: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path
UPSTREAM: netfilter: nf_tables: release batch on table validation from abort path
UPSTREAM: netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout
Conflicts:
mm/Makefile
mm/mlock.c
mm/mprotect.c
Change-Id: I559d13f0370fd2ede446df61fd1ce0550fa45155
In util_gen_new_ie, there are several possible out-of-bound reads
with invalid information elements such as improper/missing check when
updating tmp_old, missing check prior to starting while loop and missing
length check.
To fix these OOB issues add and improve length checks in util_gen_new_ie.
Change-Id: I39b9cd82ab6a7bd1a4c8d7cd5039a998a290b85f
CRs-Fixed: 3717568
(cherry picked from commit 9a7916c74a)
In util_scan_find_noninheritance_ie API,
ies[ELEM_ID_EXTN_POS] may lead to OOB access if
len==MIN_IE_LEN.
util_parse_noninheritance_list may lead to OOB
read access extn_elem[ELEM_ID_LIST_LEN_POS]
Fix is to add length checks and add sub_copy and length
subie_len checks before accessing extn_elem to avoid any
OOB read.
Change-Id: I7758c6e4d8d568a5050011603b48a23e0b11da94
CRs-Fixed: 3717569
(cherry picked from commit aab3fa668d)
If the kernel is built CONFIG_CFI_CLANG=y, reading smaps
may cause a panic. This is due to a failed CFI check; which
is triggered becuase the signature of the function pointer for
printing smaps padding VMAs does not match exactly with that
for show_smap().
Fix this by casting the function pointer to the expected type
based on whether printing maps or smaps padding.
Bug: 330117029
Bug: 327600007
Bug: 330767927
Bug: 328266487
Bug: 329803029
Change-Id: I65564a547dacbc4131f8557344c8c96e51f90cd5
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
In some cases a VMA with padding representation may be split, and
therefore the padding flags must be updated accordingly.
There are 3 cases to handle:
Given:
| DDDDPPPP |
where:
- D represents 1 page of data;
- P represents 1 page of padding;
- | represents the boundaries (start/end) of the VMA
1) Split exactly at the padding boundary
| DDDDPPPP | --> | DDDD | PPPP |
- Remove padding flags from the first VMA.
- The second VMA is all padding
2) Split within the padding area
| DDDDPPPP | --> | DDDDPP | PP |
- Subtract the length of the second VMA from the first VMA's
padding.
- The second VMA is all padding, adjust its padding length (flags)
3) Split within the data area
| DDDDPPPP | --> | DD | DDPPPP |
- Remove padding flags from the first VMA.
- The second VMA is has the same padding as from before the split.
To simplify the semantics merging of padding VMAs is not allowed.
If a split produces a VMA that is entirely padding, show_[s]maps()
only outputs the padding VMA entry (as the data entry is of length 0).
Bug: 330117029
Bug: 327600007
Bug: 330767927
Bug: 328266487
Bug: 329803029
Change-Id: Ie2628ced5512e2c7f8af25fabae1f38730c8bb1a
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Some file systems like F2FS use a custom filemap_fault ops. Remove this
check, as checking vm_file is sufficient.
Bug: 330117029
Bug: 327600007
Bug: 330767927
Bug: 328266487
Bug: 329803029
Change-Id: Id6a584d934f06650c0a95afd1823669fc77ba2c2
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Only preform padding advise from the execution context on bionic's
dynamic linker. This ensures that madvise() doesn't have unwanted
side effects.
Also rearrange the order of fail checks in madvise_vma_pad_pages()
in order of ascending cost.
Bug: 330117029
Bug: 327600007
Bug: 330767927
Bug: 328266487
Bug: 329803029
Change-Id: I3e05b8780c6eda78007f86b613f8c11dd18ac28f
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>