mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 12:25:00 -04:00
918,579 commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
bb8a45801d |
msm: eva: Copy back the validated size to avoid security issue
As we are reading the packet from a shared queue, there is a possibility to corrupt the packet->size data of shared queue by malicious FW after validating it in the kernel driver. Change-Id: I9bff8f2daa64054eada37de54fe3fa837d57b22a Signed-off-by: Aniruddh Sharma <quic_anirshar@quicinc.com> Signed-off-by: Madhu Ananthula <quic_mananthu@quicinc.com> |
||
|
|
6ea403acf3 | Merge "USB: dwc3: gadget: Add stop transfer request for isoc transfers" | ||
|
|
9d163aee48 | Merge "USB: dwc3: gadget: Queue data for 16 micro frames ahead in future" | ||
|
|
6ea1e229e2 | Merge "arm64: defconfig: Enable uvc for QCM6490 IOT target" | ||
|
|
a8ee531704 |
msm: npu: Fix use after free issue
There is possibility that network will be used after free. This change is to fix this issue. Change-Id: I12205b750450bee36f85dff3f620f8f0689a4e46 Signed-off-by: Gao Wang <quic_gaowang@quicinc.com> |
||
|
|
09c3ad5d25 |
USB: dwc3: gadget: Add stop transfer request for isoc transfers
Currently,stop transfer is done based on missed isoc packets which can cause issue when software list is empty with no missed isoc. Issue stop active transfers if started list is empty. Also,Frame_number is set from XferNotReady and may be already out of date. DSTS only provides the lower 14 bit of the current frame number. So add the upper two bits of frame_number and handle a possible rollover. This will provide the correct frame_number unless more than rollover has happened since XferNotReady. Increase TX fifo size for isochronous endpoint in case maxburst is greater than 6 for better performance. Added Endtransfer logic to be called when BUS expiry happens due to frame mismatch. Change-Id: I672529f4a4fa2740b46febbe265cd386e5932017 Signed-off-by: AKASH KUMAR <quic_akakum@quicinc.com> |
||
|
|
944949f22e |
arm64: defconfig: Enable uvc for QCM6490 IOT target
Enable USB UVC peripheral function driver that enables video streaming over USB. Change-Id: I951d93f735a57b382aa5e43f2997880ded89b2f4 Signed-off-by: Akash Kumar <quic_akakum@quicinc.com> |
||
|
|
10dc202835 |
firmware: qcom_scm: do not clear dump mode from shutdown
Do not overwrite download mode to NO dump mode from SCM driver, it is already being done at proper place in qcom-dload-mode driver and writing it here can clean up EDL mode written from qcom-dload-mode. Fix this issue by remove writing no dump mode from SCM driver. Change-Id: Ibfe8b8484dd69ae8386b46c9a53ef42a4a475688 Signed-off-by: Mukesh Ojha <quic_mojha@quicinc.com> |
||
|
|
222ee0825f |
Merge android11-5.4.281 (d62984a) into msm-5.4
* remotes/origin/tmp-d62984a:
ANDROID: delete tool added by mistake
ANDROID: fix ENOMEM check of binder_proc_ext
ANDROID: binder: fix KMI issues due to frozen notification
BACKPORT: FROMGIT: binder: frozen notification binder_features flag
BACKPORT: FROMGIT: binder: frozen notification
BACKPORT: selftests/binderfs: add test for feature files
UPSTREAM: docs: binderfs: add section about feature files
BACKPORT: binderfs: add support for feature files
FROMLIST: binder: fix memory leaks of spam and pending work
FROMGIT: Binder: add TF_UPDATE_TXN to replace outdated txn
BACKPORT: binder: tell userspace to dump current backtrace when detected oneway spamming
UPSTREAM: net: sched: sch_multiq: fix possible OOB write in multiq_tune()
FROMLIST: binder: fix UAF caused by offsets overwrite
Revert "net: mac802154: Fix racy device stats updates by DEV_STATS_INC() and DEV_STATS_ADD()"
Linux 5.4.281
tap: add missing verification for short frame
tun: add missing verification for short frame
filelock: Fix fcntl/close race recovery compat path
ALSA: hda/realtek: Enable headset mic on Positivo SU C1400
jfs: don't walk off the end of ealist
ocfs2: add bounds checking to ocfs2_check_dir_entry()
net: relax socket state check at accept time.
drm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq()
ACPI: processor_idle: Fix invalid comparison with insertion sort for latency
ARM: 9324/1: fix get_user() broken with veneer
hfsplus: fix uninit-value in copy_name
selftests/vDSO: fix clang build errors and warnings
spi: imx: Don't expect DMA for i.MX{25,35,50,51,53} cspi devices
fs: better handle deep ancestor chains in is_subdir()
Bluetooth: hci_core: cancel all works upon hci_unregister_dev()
scsi: libsas: Fix exp-attached device scan after probe failure scanned in again after probe failed
powerpc/eeh: avoid possible crash when edev->pdev changes
powerpc/pseries: Whitelist dtl slub object for copying to userspace
net: mac802154: Fix racy device stats updates by DEV_STATS_INC() and DEV_STATS_ADD()
net: usb: qmi_wwan: add Telit FN912 compositions
ALSA: dmaengine_pcm: terminate dmaengine before synchronize
s390/sclp: Fix sclp_init() cleanup on failure
can: kvaser_usb: fix return value for hif_usb_send_regout
ASoC: ti: omap-hdmi: Fix too long driver name
ASoC: ti: davinci-mcasp: Set min period size using FIFO config
bytcr_rt5640 : inverse jack detect for Archos 101 cesium
Input: elantech - fix touchpad state on resume for Lenovo N24
mips: fix compat_sys_lseek syscall
ALSA: hda/realtek: Add more codec ID to no shutup pins list
KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()
wifi: cfg80211: wext: add extra SIOCSIWSCAN data check
mei: demote client disconnect warning on suspend to debug
fs/file: fix the check in find_next_fd()
kconfig: remove wrong expr_trans_bool()
kconfig: gconf: give a proper initial state to the Save button
ila: block BH in ila_output()
Input: silead - Always support 10 fingers
wifi: mac80211: fix UBSAN noise in ieee80211_prep_hw_scan()
wifi: mac80211: mesh: init nonpeer_pm to active by default in mesh sdata
ACPI: EC: Avoid returning AE_OK on errors in address space handler
ACPI: EC: Abort address space access upon error
scsi: qedf: Set qed_slowpath_params to zero before use
filelock: Remove locks reliably when fcntl/close race is detected
gcc-plugins: Rename last_stmt() for GCC 14+
ANDROID: GKI: refresh ABI to include kimage_vaddr
ANDROID: preserve CRC for struct tcp_sock
Linux 5.4.280
i2c: rcar: bring hardware to known state when probing
nilfs2: fix kernel bug on rename operation of broken directory
tcp: avoid too many retransmit packets
tcp: use signed arithmetic in tcp_rtx_probe0_timed_out()
net: tcp: fix unexcepted socket die when snd_wnd is 0
tcp: refactor tcp_retransmit_timer()
SUNRPC: Fix RPC client cleaned up the freed pipefs dentries
libceph: fix race between delayed_work() and ceph_monc_stop()
ALSA: hda/realtek: Limit mic boost on VAIO PRO PX
nvmem: meson-efuse: Fix return value of nvmem callbacks
hpet: Support 32-bit userspace
USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor
usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()
USB: Add USB_QUIRK_NO_SET_INTF quirk for START BP-850k
USB: serial: option: add Rolling RW350-GL variants
USB: serial: option: add Netprisma LCUK54 series modules
USB: serial: option: add support for Foxconn T99W651
USB: serial: option: add Fibocom FM350-GL
USB: serial: option: add Telit FN912 rmnet compositions
USB: serial: option: add Telit generic core-dump composition
octeontx2-af: fix detection of IP layer
ARM: davinci: Convert comma to semicolon
s390: Mark psw in __load_psw_mask() as __unitialized
udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port().
ppp: reject claimed-as-LCP but actually malformed packets
net: ethernet: lantiq_etop: fix double free in detach
net: lantiq_etop: add blank line after declaration
octeontx2-af: Fix incorrect value output on error path in rvu_check_rsrc_availability()
tcp: fix incorrect undo caused by DSACK of TLP retransmit
tcp: add TCP_INFO status for failed client TFO
vfs: don't mod negative dentry count when on shrinker list
fs/dcache: Re-use value stored to dentry->d_flags instead of re-reading
filelock: fix potential use-after-free in posix_lock_inode
nilfs2: fix incorrect inode allocation from reserved inodes
nvme-multipath: find NUMA path only for online numa-node
ALSA: hda/realtek: Enable headset mic of JP-IK LEAP W502 with ALC897
i2c: pnx: Fix potential deadlock warning from del_timer_sync() call in isr
media: dw2102: fix a potential buffer overflow
bnx2x: Fix multiple UBSAN array-index-out-of-bounds
drm/amdgpu/atomfirmware: silence UBSAN warning
drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes
Revert "mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again"
fsnotify: Do not generate events for O_PATH file descriptors
can: kvaser_usb: Explicitly initialize family in leafimx driver_info struct
mm: optimize the redundant loop of mm_update_owner_next()
nilfs2: add missing check for inode numbers on directory entries
nilfs2: fix inode number range checks
inet_diag: Initialize pad field in struct inet_diag_req_v2
selftests: make order checking verbose in msg_zerocopy selftest
selftests: fix OOM in msg_zerocopy selftest
bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set()
wifi: wilc1000: fix ies_len type in connect path
tcp_metrics: validate source addr length
UPSTREAM: tcp: fix DSACK undo in fast recovery to call tcp_try_to_open()
net: tcp better handling of reordering then loss cases
tcp: add ece_ack flag to reno sack functions
tcp: tcp_mark_head_lost is only valid for sack-tcp
s390/pkey: Wipe sensitive data on failure
jffs2: Fix potential illegal address access in jffs2_free_inode
powerpc/xmon: Check cpu id in commands "c#", "dp#" and "dx#"
orangefs: fix out-of-bounds fsid access
powerpc/64: Set _IO_BASE to POISON_POINTER_DELTA not 0 for CONFIG_PCI=n
i2c: i801: Annotate apanel_addr as __ro_after_init
media: dvb-frontends: tda10048: Fix integer overflow
media: s2255: Use refcount_t instead of atomic_t for num_channels
media: dvb-frontends: tda18271c2dd: Remove casting during div
net: dsa: mv88e6xxx: Correct check for empty list
Input: ff-core - prefer struct_size over open coded arithmetic
firmware: dmi: Stop decoding on broken entry
sctp: prefer struct_size over open coded arithmetic
media: dw2102: Don't translate i2c read into write
drm/amd/display: Skip finding free audio for unknown engine_id
drm/amdgpu: Initialize timestamp for some legacy SOCs
scsi: qedf: Make qedf_execute_tmf() non-preemptible
IB/core: Implement a limit on UMAD receive List
media: dvb-usb: dib0700_devices: Add missing release_firmware()
media: dvb: as102-fe: Fix as10x_register_addr packing
drm/lima: fix shared irq handling on driver remove
Compiler Attributes: Add __uninitialized macro
Linux 5.4.279
arm64: dts: rockchip: Add sound-dai-cells for RK3368
ARM: dts: rockchip: rk3066a: add #sound-dai-cells to hdmi node
tcp: Fix data races around icsk->icsk_af_ops.
ipv6: Fix data races around sk->sk_prot.
ipv6: annotate some data-races around sk->sk_prot
nfs: Leave pages in the pagecache if readpage failed
pwm: stm32: Refuse too small period requests
mtd: spinand: macronix: Add support for serial NAND flash
ftruncate: pass a signed offset
ata: libata-core: Fix double free on error
batman-adv: Don't accept TT entries for out-of-spec VIDs
drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_hd_modes
drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_ld_modes
hexagon: fix fadvise64_64 calling conventions
csky, hexagon: fix broken sys_sync_file_range
net: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rts_session_new
net: can: j1939: recover socket queue on CAN bus error during BAM transmission
net: can: j1939: Initialize unused data in j1939_send_one()
tty: mcf: MCF54418 has 10 UARTS
usb: atm: cxacru: fix endpoint checking in cxacru_bind()
usb: musb: da8xx: fix a resource leak in probe()
usb: gadget: printer: SS+ support
net: usb: ax88179_178a: improve link status logs
iio: chemical: bme680: Fix sensor data read operation
iio: chemical: bme680: Fix overflows in compensate() functions
iio: chemical: bme680: Fix calibration data variable
iio: chemical: bme680: Fix pressure value output
iio: adc: ad7266: Fix variable checking bug
mmc: sdhci: Do not lock spinlock around mmc_gpio_get_ro()
mmc: sdhci: Do not invert write-protect twice
mmc: sdhci-pci: Convert PCIBIOS_* return codes to errnos
x86: stop playing stack games in profile_pc()
gpio: davinci: Validate the obtained number of IRQs
nvme: fixup comment for nvme RDMA Provider Type
soc: ti: wkup_m3_ipc: Send NULL dummy message instead of pointer message
media: dvbdev: Initialize sbuf
ALSA: emux: improve patch ioctl data validation
net/dpaa2: Avoid explicit cpumask var allocation on stack
net/iucv: Avoid explicit cpumask var allocation on stack
mtd: partitions: redboot: Added conversion of operands to a larger type
drm/panel: ilitek-ili9881c: Fix warning with GPIO controllers that sleep
netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers
parisc: use correct compat recv/recvfrom syscalls
sparc: fix old compat_sys_select()
net: phy: micrel: add Microchip KSZ 9477 to the device table
net: phy: mchp: Add support for LAN8814 QUAD PHY
net: dsa: microchip: fix initial port flush problem
ASoC: fsl-asoc-card: set priv->pdev before using it
netfilter: nf_tables: validate family when identifying table via handle
drm/amdgpu: fix UBSAN warning in kv_dpm.c
pinctrl: rockchip: fix pinmux reset in rockchip_pmx_set
pinctrl: rockchip: fix pinmux bits for RK3328 GPIO3-B pins
pinctrl: rockchip: fix pinmux bits for RK3328 GPIO2-B pins
pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER
iio: dac: ad5592r: fix temperature channel scaling value
iio: dac: ad5592r: un-indent code-block for scale read
iio: dac: ad5592r-base: Replace indio_dev->mlock with own device lock
x86/amd_nb: Check for invalid SMN reads
PCI: Add PCI_ERROR_RESPONSE and related definitions
perf/core: Fix missing wakeup when waiting for context reference
kheaders: explicitly define file modes for archived headers
Revert "kheaders: substituting --sort in archive creation"
tracing: Add MODULE_DESCRIPTION() to preemptirq_delay_test
arm64: dts: qcom: qcs404: fix bluetooth device address
ARM: dts: samsung: smdk4412: fix keypad no-autorepeat
ARM: dts: samsung: exynos4412-origen: fix keypad no-autorepeat
ARM: dts: samsung: smdkv310: fix keypad no-autorepeat
i2c: ocores: set IACK bit after core is enabled
gcov: add support for GCC 14
drm/radeon: fix UBSAN warning in kv_dpm.c
ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine."
dmaengine: ioatdma: Fix missing kmem_cache_destroy()
regulator: core: Fix modpost error "regulator_get_regmap" undefined
net: usb: rtl8150 fix unintiatilzed variables in rtl8150_get_link_ksettings
netfilter: ipset: Fix suspicious rcu_dereference_protected()
virtio_net: checksum offloading handling fix
net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc()
net/sched: act_api: rely on rcu in tcf_idr_check_alloc
netns: Make get_net_ns() handle zero refcount net
xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr()
ipv6: prevent possible NULL dereference in rt6_probe()
ipv6: prevent possible NULL deref in fib6_nh_init()
netrom: Fix a memory leak in nr_heartbeat_expiry()
cipso: fix total option length computation
mips: bmips: BCM6358: make sure CBR is correctly set
MIPS: Routerboard 532: Fix vendor retry check code
MIPS: Octeon: Add PCIe link status check
PCI/PM: Avoid D3cold for HP Pavilion 17 PC/1972 PCIe Ports
udf: udftime: prevent overflow in udf_disk_stamp_to_time()
usb: misc: uss720: check for incompatible versions of the Belkin F5U002
powerpc/io: Avoid clang null pointer arithmetic warnings
powerpc/pseries: Enforce hcall result buffer validity and size
Bluetooth: ath3k: Fix multiple issues reported by checkpatch.pl
scsi: qedi: Fix crash while reading debugfs attribute
drop_monitor: replace spin_lock by raw_spin_lock
batman-adv: bypass empty buckets in batadv_purge_orig_ref()
selftests/bpf: Prevent client connect before server bind in test_tc_tunnel.sh
rcutorture: Fix rcu_torture_one_read() pipe_count overflow comment
i2c: at91: Fix the functionality flags of the slave-only interface
usb-storage: alauda: Check whether the media is initialized
greybus: Fix use-after-free bug in gb_interface_release due to race condition.
netfilter: nftables: exthdr: fix 4-byte stack OOB write
hugetlb_encode.h: fix undefined behaviour (34 << 26)
hv_utils: drain the timesync packets on onchannelcallback
tick/nohz_full: Don't abuse smp_call_function_single() in tick_setup_device()
nilfs2: fix potential kernel bug due to lack of writeback flag waiting
intel_th: pci: Add Lunar Lake support
intel_th: pci: Add Meteor Lake-S support
intel_th: pci: Add Sapphire Rapids SOC support
intel_th: pci: Add Granite Rapids SOC support
intel_th: pci: Add Granite Rapids support
dmaengine: axi-dmac: fix possible race in remove()
PCI: rockchip-ep: Remove wrong mask on subsys_vendor_id
ocfs2: fix races between hole punching and AIO+DIO
ocfs2: use coarse time for new created files
fs/proc: fix softlockup in __read_vmcore
vmci: prevent speculation leaks by sanitizing event in event_deliver()
tracing/selftests: Fix kprobe event name test for .isra. functions
drm/exynos: hdmi: report safe 640x480 mode as a fallback when no EDID found
drm/exynos/vidi: fix memory leak in .get_modes()
drivers: core: synchronize really_probe() and dev_uevent()
ionic: fix use after netif_napi_del()
net/ipv6: Fix the RT cache flush via sysctl using a previous delay
netfilter: ipset: Fix race between namespace cleanup and gc in the list:set type
Bluetooth: L2CAP: Fix rejecting L2CAP_CONN_PARAM_UPDATE_REQ
net/mlx5e: Fix features validation check for tunneled UDP (non-VXLAN) packets
tcp: fix race in tcp_v6_syn_recv_sock()
drm/bridge/panel: Fix runtime warning on panel bridge release
drm/komeda: check for error-valued pointer
liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet
HID: logitech-dj: Fix memory leak in logi_dj_recv_switch_to_dj_mode()
iommu: Return right value in iommu_sva_bind_device()
iommu/amd: Fix sysfs leak in iommu init
HID: core: remove unnecessary WARN_ON() in implement()
gpio: tqmx86: fix typo in Kconfig label
SUNRPC: return proper error from gss_wrap_req_priv
Input: try trimming too long modalias strings
scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory
xhci: Apply broken streams quirk to Etron EJ188 xHCI host
xhci: Apply reset resume quirk to Etron EJ188 xHCI host
xhci: Set correct transferred length for cancelled bulk transfers
jfs: xattr: fix buffer overflow for invalid xattr
mei: me: release irq in mei_me_pci_resume error path
USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages
nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors
nilfs2: return the mapped address from nilfs_get_page()
nilfs2: Remove check for PageError
selftests/mm: compaction_test: fix bogus test success on Aarch64
selftests/mm: conform test to TAP format output
selftests/mm: compaction_test: fix incorrect write of zero to nr_hugepages
serial: sc16is7xx: fix bug in sc16is7xx_set_baud() when using prescaler
serial: sc16is7xx: replace hardcoded divisor value with BIT() macro
drm/amd/display: Handle Y carry-over in VCP X.Y calculation
ASoC: ti: davinci-mcasp: Fix race condition during probe
ASoC: ti: davinci-mcasp: Handle missing required DT properties
ASoC: ti: davinci-mcasp: Simplify the configuration parameter handling
ASoC: ti: davinci-mcasp: Remove legacy dma_request parsing
ASoC: ti: davinci-mcasp: Use platform_get_irq_byname_optional
ASoC: ti: davinci-mcasp: remove always zero of davinci_mcasp_get_dt_params
ASoC: ti: davinci-mcasp: remove redundant assignment to variable ret
usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete
ipv6: fix possible race in __fib6_drop_pcpu_from()
af_unix: Annotate data-race of sk->sk_shutdown in sk_diag_fill().
af_unix: Use skb_queue_len_lockless() in sk_diag_show_rqlen().
af_unix: Use unix_recvq_full_lockless() in unix_stream_connect().
af_unix: Annotate data-race of net->unx.sysctl_max_dgram_qlen.
af_unix: Annotate data-races around sk->sk_state in UNIX_DIAG.
af_unix: Annotate data-races around sk->sk_state in sendmsg() and recvmsg().
af_unix: Annotate data-races around sk->sk_state in unix_write_space() and poll().
af_unix: Annotate data-race of sk->sk_state in unix_inq_len().
ptp: Fix error message on failed pin verification
net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP
net/mlx5: Stop waiting for PCI if pci channel is offline
tcp: count CLOSE-WAIT sockets for TCP_MIB_CURRESTAB
vxlan: Fix regression when dropping packets due to invalid src addresses
net: sched: sch_multiq: fix possible OOB write in multiq_tune()
ipv6: sr: block BH in seg6_output_core() and seg6_input_core()
wifi: iwlwifi: mvm: don't read past the mfuart notifcation
wifi: iwlwifi: dbg_ini: move iwl_dbg_tlv_free outside of debugfs ifdef
wifi: iwlwifi: mvm: revert gen2 TX A-MPDU size to 64
wifi: cfg80211: pmsr: use correct nla_get_uX functions
wifi: mac80211: Fix deadlock in ieee80211_sta_ps_deliver_wakeup()
wifi: mac80211: mesh: Fix leak of mesh_preq_queue objects
Conflicts:
kernel/gen_kheaders.sh
Change-Id: I4a0de5504b5e61a23b78a1a8f06aceaac810f3c7
Signed-off-by: kamasali Satyanarayan <quic_kamasali@quicinc.com>
|
||
|
|
7ea86abd86 | Merge "Merge android11-5.4.278(7453ecf) into msm-5.4" | ||
|
|
c2fe5024c0 | Merge "power: reset: Disable support of dynamic download mode (ramdump)" | ||
|
|
113056cafc | Merge "msm: virtio_npu: Fix use-after-free issue in unmap_buf" | ||
|
|
e88bb9b374 |
Merge android11-5.4.278(7453ecf) into msm-5.4
* remotes/origin/tmp-7453ecf:
UPSTREAM: usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()
ANDROID: 16K: Don't set padding vm_flags on 32-bit archs
ANDROID: GKI: refresh ABI to include kimage_vaddr
BACKPORT: arm64: move kimage_vaddr to .rodata
BACKPORT: arm64: kernel: Convert to modern annotations for assembly data
ANDROID: fix kernelci build breaks due to hid/uhid cyclic dependency
UPSTREAM: af_unix: Fix garbage collector racing against connect()
Revert "drm/panel: simple: Add missing Innolux G121X1-L03 format, flags, connector"
Linux 5.4.278
nfs: fix undefined behavior in nfs_block_bits()
s390/ap: Fix crash in AP internal function modify_bitmap()
ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find()
sparc: move struct termio to asm/termios.h
xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING
net: fix __dst_negative_advice() race
kdb: Use format-specifiers rather than memset() for padding in kdb_read()
kdb: Merge identical case statements in kdb_read()
kdb: Fix console handling when editing and tab-completing commands
kdb: Use format-strings rather than '\0' injection in kdb_read()
kdb: Fix buffer overflow during tab-complete
sparc64: Fix number of online CPUs
intel_th: pci: Add Meteor Lake-S CPU support
net/9p: fix uninit-value in p9_client_rpc()
net/ipv6: Fix route deleting failure when metric equals 0
crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak
crypto: ecrdsa - Fix module auto-load on add_key
KVM: arm64: Allow AArch32 PSTATE.M to be restored as System mode
fbdev: savage: Handle err return when savagefb_check_var failed
media: v4l2-core: hold videodev_lock until dev reg, finishes
media: mxl5xx: Move xpt structures off stack
media: mc: mark the media devnode as registered from the, start
arm64: dts: hi3798cv200: fix the size of GICR
wifi: rtl8xxxu: Fix the TX power of RTL8192CU, RTL8723AU
md/raid5: fix deadlock that raid5d() wait for itself to clear MD_SB_CHANGE_PENDING
arm64: tegra: Correct Tegra132 I2C alias
ACPI: resource: Do IRQ override on TongFang GXxHRXx and GMxHGxx
ata: pata_legacy: make legacy_exit() work again
drm/amdgpu: add error handle to avoid out-of-bounds
media: lgdt3306a: Add a check against null-pointer-def
f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode()
x86/mm: Remove broken vsyscall emulation code from the page fault code
vxlan: Fix regression when dropping packets due to invalid src addresses
nilfs2: fix use-after-free of timer for log writer thread
afs: Don't cross .backup mountpoint from backup volume
io_uring: fail NOP if non-zero op flags is passed in
mmc: core: Do not force a retune before RPMB switch
binder: fix max_thread type inconsistency
SUNRPC: Fix loop termination condition in gss_free_in_token_pages()
genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU offline
ALSA: timer: Set lower bound of start tick time
ipvlan: Dont Use skb->sk in ipvlan_process_v{4,6}_outbound
spi: stm32: Don't warn about spurious interrupts
kconfig: fix comparison to constant symbols, 'm', 'n'
netfilter: tproxy: bail out if IP has been disabled on the device
net:fec: Add fec_enet_deinit()
net: usb: smsc95xx: fix changing LED_SEL bit value updated from EEPROM
smsc95xx: use usbnet->driver_priv
smsc95xx: remove redundant function arguments
enic: Validate length of nl attributes in enic_set_vf_port
dma-buf/sw-sync: don't enable IRQ from sync_print_obj()
net/mlx5e: Use rx_missed_errors instead of rx_dropped for reporting buffer exhaustion
nvmet: fix ns enable/disable possible hang
spi: Don't mark message DMA mapped when no transfer in it is
netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu()
nfc: nci: Fix handling of zero-length payload packets in nci_rx_work()
nfc: nci: Fix kcov check in nci_rx_work()
net: fec: avoid lock evasion when reading pps_enable
virtio: delete vq in vp_find_vqs_msix() when request_irq() fails
arm64: asm-bug: Add .align 2 to the end of __BUG_ENTRY
openvswitch: Set the skbuff pkt_type for proper pmtud support.
tcp: Fix shift-out-of-bounds in dctcp_update_alpha().
params: lift param_set_uint_minmax to common code
ipv6: sr: fix memleak in seg6_hmac_init_algo
sunrpc: fix NFSACL RPC retry on soft mount
nfc: nci: Fix uninit-value in nci_rx_work
x86/kconfig: Select ARCH_WANT_FRAME_POINTERS again when UNWINDER_FRAME_POINTER=y
null_blk: Fix the WARNING: modpost: missing MODULE_DESCRIPTION()
media: cec: cec-api: add locking in cec_release()
media: cec: cec-adap: always cancel work in cec_transmit_msg_fh
um: Fix the -Wmissing-prototypes warning for __switch_mm
powerpc/pseries: Add failure related checks for h_get_mpp and h_get_ppp
scsi: qla2xxx: Replace all non-returning strlcpy() with strscpy()
media: stk1160: fix bounds checking in stk1160_copy_video()
um: Add winch to winch_handlers before registering winch IRQ
um: Fix return value in ubd_init()
drm/msm/dpu: Always flush the slave INTF on the CTL
Input: pm8xxx-vibrator - correct VIB_MAX_LEVELS calculation
Input: ims-pcu - fix printf string overflow
libsubcmd: Fix parse-options memory leak
serial: sh-sci: protect invalidating RXDMA on shutdown
f2fs: fix to release node block count in error path of f2fs_new_node_page()
extcon: max8997: select IRQ_DOMAIN instead of depending on it
ppdev: Add an error check in register_device
ppdev: Remove usage of the deprecated ida_simple_xx() API
stm class: Fix a double free in stm_register_device()
usb: gadget: u_audio: Clear uac pointer when freed.
microblaze: Remove early printk call from cpuinfo-static.c
microblaze: Remove gcc flag for non existing early_printk.c file
iio: pressure: dps310: support negative temperature values
greybus: arche-ctrl: move device table to its right location
serial: max3100: Fix bitwise types
serial: max3100: Update uart_driver_registered on driver removal
serial: max3100: Lock port->lock when calling uart_handle_cts_change()
firmware: dmi-id: add a release callback function
dmaengine: idma64: Add check for dma_set_max_seg_size
soundwire: cadence: fix invalid PDI offset
soundwire: cadence_master: improve PDI allocation
soundwire: intel: don't filter out PDI0/1
soundwire: cadence/intel: simplify PDI/port mapping
greybus: lights: check return of get_channel_from_mode
sched/fair: Allow disabling sched_balance_newidle with sched_relax_domain_level
sched/topology: Don't set SD_BALANCE_WAKE on cpuset domain relax
af_packet: do not call packet_read_pending() from tpacket_destruct_skb()
netrom: fix possible dead-lock in nr_rt_ioctl()
RDMA/IPoIB: Fix format truncation compilation errors
selftests/kcmp: remove unused open mode
selftests/kcmp: Make the test output consistent and clear
SUNRPC: Fix gss_free_in_token_pages()
sunrpc: removed redundant procp check
ext4: avoid excessive credit estimate in ext4_tmpfile()
x86/insn: Fix PUSH instruction in x86 instruction decoder opcode map
RDMA/hns: Use complete parentheses in macros
drm/panel: simple: Add missing Innolux G121X1-L03 format, flags, connector
ASoC: tracing: Export SND_SOC_DAPM_DIR_OUT to its value
drm/arm/malidp: fix a possible null pointer dereference
fbdev: sh7760fb: allow modular build
platform/x86: wmi: Make two functions static
media: radio-shark2: Avoid led_names truncations
media: ngene: Add dvb_ca_en50221_init return value check
fbdev: sisfb: hide unused variables
powerpc/fsl-soc: hide unused const variable
drm/mediatek: Add 0 size check to mtk_drm_gem_obj
fbdev: shmobile: fix snprintf truncation
mtd: rawnand: hynix: fixed typo
drm/amd/display: Fix potential index out of bounds in color transformation function
ipv6: sr: fix invalid unregister error path
ipv6: sr: fix incorrect unregister order
ipv6: sr: add missing seg6_local_exit
net: openvswitch: fix overwriting ct original tuple for ICMPv6
net: usb: smsc95xx: stop lying about skb->truesize
af_unix: Fix data races in unix_release_sock/unix_stream_sendmsg
net: ethernet: cortina: Locking fixes
m68k: mac: Fix reboot hang on Mac IIci
m68k: Fix spinlock race in kernel thread creation
net: usb: sr9700: stop lying about skb->truesize
usb: aqc111: stop lying about skb->truesize
wifi: mwl8k: initialize cmd->addr[] properly
scsi: qedf: Ensure the copied buf is NUL terminated
scsi: bfa: Ensure the copied buf is NUL terminated
HID: intel-ish-hid: ipc: Add check for pci_alloc_irq_vectors
Revert "sh: Handle calling csum_partial with misaligned data"
sh: kprobes: Merge arch_copy_kprobe() into arch_prepare_kprobe()
wifi: ar5523: enable proper endpoint verification
wifi: carl9170: add a proper sanity check for endpoints
macintosh/via-macii: Fix "BUG: sleeping function called from invalid context"
tcp: avoid premature drops in tcp_add_backlog()
tcp: fix a signed-integer-overflow bug in tcp_add_backlog()
tcp: minor optimization in tcp_add_backlog()
wifi: ath10k: populate board data for WCN3990
wifi: ath10k: Fix an error code problem in ath10k_dbg_sta_write_peer_debug_trigger()
x86/purgatory: Switch to the position-independent small code model
scsi: hpsa: Fix allocation size for Scsi_Host private data
scsi: libsas: Fix the failure of adding phy with zero-address to port
cpufreq: exit() callback is optional
cpufreq: Rearrange locking in cpufreq_remove_dev()
cpufreq: Split cpufreq_offline()
cpufreq: Reorganize checks in cpufreq_offline()
ACPI: disable -Wstringop-truncation
irqchip/alpine-msi: Fix off-by-one in allocation error path
scsi: ufs: core: Perform read back after disabling UIC_COMMAND_COMPL
scsi: ufs: core: Perform read back after disabling interrupts
scsi: ufs: cdns-pltfrm: Perform read back after writing HCLKDIV
scsi: ufs: qcom: Perform read back after writing reset bit
qed: avoid truncating work queue length
x86/boot: Ignore relocations in .notes sections in walk_relocs() too
wifi: ath10k: poll service ready message before failing
md: fix resync softlockup when bitmap size is less than array size
null_blk: Fix missing mutex_destroy() at module removal
jffs2: prevent xattr node from overflowing the eraseblock
s390/cio: fix tracepoint subchannel type field
crypto: ccp - drop platform ifdef checks
parisc: add missing export of __cmpxchg_u8()
nilfs2: fix out-of-range warning
ecryptfs: Fix buffer size for tag 66 packet
firmware: raspberrypi: Use correct device for DMA mappings
crypto: bcm - Fix pointer arithmetic
openpromfs: finish conversion to the new mount API
nvme: find numa distance only if controller has valid numa id
drm/amdkfd: Flush the process wq before creating a kfd_process
ASoC: da7219-aad: fix usage of device_get_named_child_node()
ASoC: dt-bindings: rt5645: add cbj sleeve gpio property
ASoC: rt5645: Fix the electric noise due to the CBJ contacts floating
drm/amd/display: Set color_mgmt_changed to true on unsuspend
net: usb: qmi_wwan: add Telit FN920C04 compositions
wifi: cfg80211: fix the order of arguments for trace events of the tx_rx_evt class
nilfs2: fix potential hang in nilfs_detach_log_writer()
nilfs2: fix unexpected freezing of nilfs_segctor_sync()
net: smc91x: Fix m68k kernel compilation for ColdFire CPU
ring-buffer: Fix a race between readers and resize checks
speakup: Fix sizeof() vs ARRAY_SIZE() bug
tty: n_gsm: fix possible out-of-bounds in gsm0_receive()
x86/tsc: Trust initial offset in architectural TSC-adjust MSRs
Linux 5.4.277
docs: kernel_include.py: Cope with docutils 0.21
serial: kgdboc: Fix NMI-safety problems from keyboard reset code
usb: typec: ucsi: displayport: Fix potential deadlock
drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper()
btrfs: add missing mutex_unlock in btrfs_relocate_sys_chunks()
arm64: dts: qcom: Fix 'interrupt-map' parent address cells
firmware: arm_scmi: Harden accesses to the reset domains
smb: client: fix potential OOBs in smb2_parse_contexts()
net: bcmgenet: synchronize UMAC_CMD access
net: bcmgenet: synchronize use of bcmgenet_set_rx_mode()
net: bcmgenet: synchronize EXT_RGMII_OOB_CTRL access
net: bcmgenet: keep MAC in reset until PHY is up
Revert "net: bcmgenet: use RGMII loopback for MAC reset"
Revert "selftests: mm: fix map_hugetlb failure on 64K page size systems"
ext4: fix bug_on in __es_tree_search
pinctrl: core: handle radix_tree_insert() errors in pinctrl_register_one_pin()
Linux 5.4.276
pinctrl: mediatek: paris: Fix PIN_CONFIG_INPUT_SCHMITT_ENABLE readback
pinctrl: mediatek: remove set but not used variable 'e'
pinctrl: mediatek: Fix some off by one bugs
pinctrl: mediatek: Fix fallback behavior for bias_set_combo
regulator: core: fix debugfs creation regression
net: fix out-of-bounds access in ops_init
drm/vmwgfx: Fix invalid reads in fence signaled events
dyndbg: fix old BUG_ON in >control parser
tipc: fix UAF in error path
usb: gadget: f_fs: Fix a race condition when processing setup packets.
usb: gadget: composite: fix OS descriptors w_value logic
firewire: nosy: ensure user_length is taken into account when fetching packet contents
net: qede: use return from qede_parse_flow_attr() for flower
net: qede: sanitize 'rc' in qede_add_tc_flower_fltr()
ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action()
net: bridge: fix corrupted ethernet header on multicast-to-unicast
phonet: fix rtm_phonet_notify() skb allocation
rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation
Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout
Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout
tcp: Use refcount_inc_not_zero() in tcp_twsk_unique().
tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets
xfrm: Preserve vlan tags for transport mode software GRO
pinctrl: mediatek: Fix fallback call path
net:usb:qmi_wwan: support Rolling modules
fs/9p: drop inodes immediately on non-.L too
clk: Don't hold prepare_lock when calling kref_put()
gpio: crystalcove: Use -ENOTSUPP consistently
gpio: wcove: Use -ENOTSUPP consistently
9p: explicitly deny setlease attempts
fs/9p: translate O_TRUNC into OTRUNC
fs/9p: only translate RWX permissions for plain 9P2000
selftests: timers: Fix valid-adjtimex signed left-shift undefined behavior
MIPS: scall: Save thread_info.syscall unconditionally on entry
gpu: host1x: Do not setup DMA for virtual devices
scsi: target: Fix SELinux error when systemd-modules loads the target module
btrfs: always clear PERTRANS metadata during commit
btrfs: make btrfs_clear_delalloc_extent() free delalloc reserve
tools/power turbostat: Fix Bzy_MHz documentation typo
tools/power turbostat: Fix added raw MSR output
firewire: ohci: mask bus reset interrupts between ISR and bottom half
ata: sata_gemini: Check clk_enable() result
net: bcmgenet: Reset RBUF on first open
ALSA: line6: Zero-initialize message buffers
scsi: bnx2fc: Remove spin_lock_bh while releasing resources after upload
net: mark racy access on sk->sk_rcvbuf
wifi: cfg80211: fix rdev_dump_mpp() arguments order
wifi: mac80211: fix ieee80211_bss_*_flags kernel-doc
gfs2: Fix invalid metadata access in punch_hole
scsi: lpfc: Update lpfc_ramp_down_queue_handler() logic
clk: sunxi-ng: h6: Reparent CPUX during PLL CPUX rate change
tipc: fix a possible memleak in tipc_buf_append
net: bridge: fix multicast-to-unicast with fraglist GSO
net: dsa: mv88e6xxx: Fix number of databases for 88E6141 / 88E6341
net: dsa: mv88e6xxx: Add number of MACs in the ATU
net: qede: use return from qede_parse_flow_attr() for flow_spec
net l2tp: drop flow hash on forward
nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment().
bna: ensure the copied buf is NUL terminated
s390/mm: Fix clearing storage keys for huge pages
s390/mm: Fix storage key clearing for guest huge pages
pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map()
power: rt9455: hide unused rt9455_boost_voltage_values
nfs: Handle error of rpc_proc_register() in nfs_net_init().
nfs: make the rpc_stat per net namespace
nfs: expose /proc/net/sunrpc/nfs in net namespaces
sunrpc: add a struct rpc_stats arg to rpc_create_args
pinctrl: mediatek: paris: Rework support for PIN_CONFIG_{INPUT,OUTPUT}_ENABLE
pinctrl: mediatek: paris: Rework mtk_pinconf_{get,set} switch/case logic
pinctrl: mediatek: paris: Fix PIN_CONFIG_BIAS_* readback
pinctrl: mediatek: remove shadow variable declaration
pinctrl: mediatek: Backward compatible to previous Mediatek's bias-pull usage
pinctrl: mediatek: Refine mtk_pinconf_get()
pinctrl: mediatek: Refine mtk_pinconf_get() and mtk_pinconf_set()
pinctrl: mediatek: Supporting driving setting without mapping current to register value
pinctrl: mediatek: Check gpio pin number and use binary search in mtk_hw_pin_field_lookup()
pinctrl: core: delete incorrect free in pinctrl_enable()
wifi: nl80211: don't free NULL coalescing rule
dmaengine: Revert "dmaengine: pl330: issue_pending waits until WFP state"
dmaengine: pl330: issue_pending waits until WFP state
Revert "clk: Get runtime PM before walking tree during disable_unused"
Linux 5.4.275
serial: core: fix kernel-doc for uart_port_unlock_irqrestore()
udp: preserve the connected status if only UDP cmsg
dm: limit the number of targets and parameter size area
bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS
HID: i2c-hid: remove I2C_HID_READ_PENDING flag to prevent lock-up
i2c: smbus: fix NULL function pointer dereference
idma64: Don't try to serve interrupts when device is powered off
dmaengine: owl: fix register access functions
tcp: Fix NEW_SYN_RECV handling in inet_twsk_purge()
tcp: Clean up kernel listener's reqsk in inet_twsk_purge()
mtd: diskonchip: work around ubsan link failure
stackdepot: respect __GFP_NOLOCKDEP allocation flag
net: b44: set pause params only when interface is up
ethernet: Add helper for assigning packet type when dest address does not match device address
irqchip/gic-v3-its: Prevent double free on error
drm/amdgpu: Fix leak when GPU memory allocation fails
arm64: dts: rockchip: enable internal pull-up for Q7_THRM# on RK3399 Puma
btrfs: fix information leak in btrfs_ioctl_logical_to_ino()
Bluetooth: btusb: Add Realtek RTL8852BE support ID 0x0bda:0x4853
Bluetooth: Fix type of len in {l2cap,sco}_sock_getsockopt_old()
tracing: Increase PERF_MAX_TRACE_SIZE to handle Sentinel1 and docker together
tracing: Show size of requested perf buffer
net/mlx5e: Fix a race in command alloc flow
Revert "crypto: api - Disallow identical driver names"
drm/amdgpu: validate the parameters of bo mapping operations more clearly
amdgpu: validate offset_in_bo of drm_amdgpu_gem_va
drm/amdgpu: restrict bo mapping within gpu address limits
serial: mxs-auart: add spinlock around changing cts state
serial: core: Provide port lock wrappers
af_unix: Suppress false-positive lockdep splat for spin_lock() in __unix_gc().
iavf: Fix TC config comparison with existing adapter TC config
i40e: Do not use WQ_MEM_RECLAIM flag for workqueue
mlxsw: spectrum_acl_tcam: Fix memory leak when canceling rehash work
mlxsw: spectrum_acl_tcam: Fix incorrect list API usage
mlxsw: spectrum_acl_tcam: Fix warning during rehash
mlxsw: spectrum_acl_tcam: Fix memory leak during rehash
mlxsw: spectrum_acl_tcam: Rate limit error message
mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash
mlxsw: spectrum_acl_tcam: Fix possible use-after-free during activity update
mlxsw: spectrum_acl_tcam: Fix race during rehash delayed work
net: openvswitch: Fix Use-After-Free in ovs_ct_exit
ipvs: Fix checksumming on GSO of SCTP packets
net: gtp: Fix Use-After-Free in gtp_dellink
net: usb: ax88179_178a: stop lying about skb->truesize
NFC: trf7970a: disable all regulators on removal
mlxsw: core: Unregister EMAD trap using FORWARD action
vxlan: drop packets from invalid src-address
ARC: [plat-hsdk]: Remove misplaced interrupt-cells property
arm64: dts: mediatek: mt2712: fix validation errors
arm64: dts: mt2712: add ethernet device node
arm64: dts: mediatek: mt7622: drop "reset-names" from thermal block
arm64: dts: mediatek: mt7622: fix ethernet controller "compatible"
arm64: dts: mediatek: mt7622: fix IR nodename
arm64: dts: rockchip: enable internal pull-up on PCIE_WAKE# for RK3399 Puma
arm64: dts: rockchip: fix alphabetical ordering RK3399 puma
KVM: async_pf: Cleanup kvm_setup_async_pf()
nilfs2: fix OOB in nilfs_set_de_type
nouveau: fix instmem race condition around ptr stores
fs: sysfs: Fix reference leak in sysfs_break_active_protection()
speakup: Avoid crash on very long word
usb: Disable USB3 LPM at shutdown
usb: dwc2: host: Fix dereference issue in DDMA completion flow.
Revert "usb: cdc-wdm: close race between read and workqueue"
USB: serial: option: add Telit FN920C04 rmnet compositions
USB: serial: option: add Rolling RW101-GL and RW135-GL support
USB: serial: option: support Quectel EM060K sub-models
USB: serial: option: add Lonsung U8300/U9300 product
USB: serial: option: add support for Fibocom FM650/FG650
USB: serial: option: add Fibocom FM135-GL variants
serial/pmac_zilog: Remove flawed mitigation for rx irq flood
comedi: vmk80xx: fix incomplete endpoint checking
binder: check offset alignment in binder_get_object()
x86/cpufeatures: Fix dependencies for GFNI, VAES, and VPCLMULQDQ
clk: Get runtime PM before walking tree during disable_unused
clk: Initialize struct clk_core kref earlier
clk: Print an info line before disabling unused clocks
clk: remove extra empty line
clk: Mark 'all_lists' as const
clk: Remove prepare_lock hold assertion in __clk_release()
drm: nv04: Fix out of bounds access
RDMA/mlx5: Fix port number for counter query in multi-port configuration
RDMA/rxe: Fix the problem "mutex_destroy missing"
tun: limit printing rate when illegal packet received by tun dev
netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get()
Revert "tracing/trigger: Fix to return error if failed to alloc snapshot"
kprobes: Fix possible use-after-free issue on kprobe registration
selftests/ftrace: Limit length in subsystem-enable tests
btrfs: record delayed inode root in transaction
x86/apic: Force native_apic_mem_read() to use the MOV instruction
selftests: timers: Fix abs() warning in posix_timers test
vhost: Add smp_rmb() in vhost_vq_avail_empty()
drm/client: Fully protect modes[] with dev->mode_config.mutex
btrfs: qgroup: correctly model root qgroup rsv in convert
net: ena: Fix potential sign extension issue
af_unix: Fix garbage collector racing against connect()
af_unix: Do not use atomic ops for unix_sk(sk)->inflight.
net/mlx5: Properly link new fs rules into the tree
ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr
ipv4/route: avoid unused-but-set-variable warning
ipv6: fib: hide unused 'pn' variable
geneve: fix header validation in geneve[6]_xmit_skb
u64_stats: fix u64_stats_init() for lockdep when used repeatedly in one file
net: openvswitch: fix unwanted error log on timeout policy probing
nouveau: fix function cast warning
Bluetooth: Fix memory leak in hci_req_sync_complete()
batman-adv: Avoid infinite loop trying to resize local TT
Change-Id: I36df890fc0cf15277cf5d6be8f56774233fb4431
Signed-off-by: kamasali Satyanarayan <quic_kamasali@quicinc.com>
|
||
|
|
a721c06f7d |
msm: virtio_npu: Fix use-after-free issue in unmap_buf
address the security CR of virtio_npu driver Change-Id: Ibf656fa76dedb19086b75d8bf519b2f415ac8d22 Signed-off-by: Gao Wang <quic_gaowang@quicinc.com> |
||
|
|
79c14fa641 |
msm: virtio_npu: Fix use-after-free issue in virt_npu_map_buf
address the security CR of virtio_npu driver Change-Id: Ib77014bc12490e7b09367354024baa2754d3e433 Signed-off-by: gaowang <quic_gaowang@quicinc.com> |
||
|
|
c5539fb1c2 |
i2c: i2c-master-msm-geni: add null pointer check in event call back
Currently i2c geni driver doesn't have null pointer check condition in event call back function. If any invalid event is coming from GSI, i2c geni driver accessing null pointer which is causing crash. To solve this added null pointer checks in event call back functions. Change-Id: Ie14a40eee846c0ea29bec512d6320e9548c509b5 Signed-off-by: Anil Veshala Veshala <quic_aveshala@quicinc.com> |
||
|
|
e4c2f15ba5 | Merge "firmware: qcom_scm: handle echo b > /proc/sysrq-trigger" | ||
|
|
4adbc0218a | Merge "msm: ep_pcie: Disable hot reset and ignore linkdown" | ||
|
|
94c4fda252 | Merge "scripts: mod: replace with a safe function" | ||
|
|
b2af2b5f9f |
firmware: qcom_scm: handle echo b > /proc/sysrq-trigger
Introduce restart handler to handle "echo b > /proc/sysrq-trigger". One special thing with 'b' kind of reboot is, it does not call reboot notifiers and call restart handler right a way and that does not seems to work for blair SoC and it goes to dump mode. Keep this restart handler priority to 201 greater than 200 which is the priority for msm-poweroff to make reboot work cleaner. Change-Id: I42f8c0fde29af402096d760c37ec2d8b3a85439a Signed-off-by: Mukesh Ojha <quic_mojha@quicinc.com> Signed-off-by: Sayan Dey <quic_sayand@quicinc.com> |
||
|
|
f1d1549d8e |
scripts: mod: replace with a safe function
Add safe function vsnprintf instead of sprintf by passing size as argument. Change-Id: Ibd21a0c7d9039543dee32c1297035ed9984ed748 Signed-off-by: Vishnu Teja <quic_vteja@quicinc.com> |
||
|
|
32de0804b1 |
msm: ep_pcie: Disable hot reset and ignore linkdown
Intel host tends to retrain the link if device doesn't send PM_Enter_L23 in time, leading to linkdown and hot reset in device side. The hot reset here even results to PERST# timeout and device crash to PBL, which is not expected. Since we are in the entry of shutdown the link when linkdown happen, it makes sense to ignore the linkdown. To avoid device crash because of PERST# timeout, disable hot reset in pm_turnoff irq and reenable it when we do linktrain again. Change-Id: I87961faaae2a14c9a5e7d24543b416914076dd2e Signed-off-by: Qiang Yu <quic_qianyu@quicinc.com> Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com> |
||
|
|
bb76f075ca |
coresight-tmc: Replace deprecated function
Use 'scnprintf' to replace deprecated function 'sprintf'. Change-Id: Ic258e7dfe719f1f871f9c9eb5988609a5f3b6284 Signed-off-by: Yuanfang Zhang <quic_yuanfang@quicinc.com> |
||
|
|
d62984adb1 |
ANDROID: delete tool added by mistake
Remove the gen-hyprel binary added accidentally while backporting a
patch into an older branch. The tool gets generated in newer builds and
wasn't part of the gitignore file here.
Fixes:
|
||
|
|
a03c6437cf |
ANDROID: fix ENOMEM check of binder_proc_ext
The check should be done against 'eproc' before it gets dereferenced.
Fixes: d49297739550 ("BACKPORT: binder: use euid from cred instead of using task")
Change-Id: Ief0c08212c4da8bdfdf628474de9dd30ee5a8db0
Signed-off-by: Carlos Llamas <cmllamas@google.com>
|
||
|
|
be02156857 |
ANDROID: binder: fix KMI issues due to frozen notification
The patches to support binder's frozen notification feature break the
KMI. This change fixes such issues by (1) moving proc->delivered_freeze
into the existing proc_wrapper struction, (2) dropping the frozen stats
support and (3) amending the STG due to a harmless enum binder_work_type
addition.
These are the reported KMI issues fixed by this patch:
function symbol 'int __traceiter_binder_transaction_received(void*, struct binder_transaction*)' changed
CRC changed from 0x74e9c98b to 0xfe0f8640
type 'struct binder_proc' changed
byte size changed from 584 to 632
member 'struct list_head delivered_death' changed
offset changed by 256
member 'struct list_head delivered_freeze' was added
13 members ('u32 max_threads' .. 'u64 android_oem_data1') changed
offset changed by 384
type 'struct binder_thread' changed
byte size changed from 464 to 496
2 members ('atomic_t tmp_ref' .. 'bool is_dead') changed
offset changed by 224
4 members ('struct task_struct* task' .. 'enum binder_prio_state prio_state') changed
offset changed by 256
type 'struct binder_stats' changed
byte size changed from 216 to 244
member changed from 'atomic_t br[21]' to 'atomic_t br[23]'
type changed from 'atomic_t[21]' to 'atomic_t[23]'
number of elements changed from 21 to 23
member changed from 'atomic_t bc[19]' to 'atomic_t bc[22]'
offset changed from 672 to 736
type changed from 'atomic_t[19]' to 'atomic_t[22]'
number of elements changed from 19 to 22
member changed from 'atomic_t obj_created[7]' to 'atomic_t obj_created[8]'
offset changed from 1280 to 1440
type changed from 'atomic_t[7]' to 'atomic_t[8]'
number of elements changed from 7 to 8
member changed from 'atomic_t obj_deleted[7]' to 'atomic_t obj_deleted[8]'
offset changed from 1504 to 1696
type changed from 'atomic_t[7]' to 'atomic_t[8]'
number of elements changed from 7 to 8
type 'enum binder_work_type' changed
enumerator 'BINDER_WORK_FROZEN_BINDER' (10) was added
enumerator 'BINDER_WORK_CLEAR_FREEZE_NOTIFICATION' (11) was added
Bug: 363013421
Change-Id: If9f1f14a2eda215a4c9cb0823c50c8e0e8079ef1
Signed-off-by: Carlos Llamas <cmllamas@google.com>
|
||
|
|
1063c2fa62 |
BACKPORT: FROMGIT: binder: frozen notification binder_features flag
Add a flag to binder_features to indicate that the freeze notification feature is available. Signed-off-by: Yu-Ting Tseng <yutingtseng@google.com> Acked-by: Carlos Llamas <cmllamas@google.com> Link: https://lore.kernel.org/r/20240709070047.4055369-6-yutingtseng@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Bug: 363013421 (cherry picked from commit 30b968b002a92870325a5c9d1ce78eba0ce386e7 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git char-misc-next) Change-Id: Ic26c8ae42d27c6fd8f5daed5eecabd1652e29502 [cmllamas: fix trivial conflicts due to missing extended_error] Signed-off-by: Carlos Llamas <cmllamas@google.com> |
||
|
|
d1e87637cd |
BACKPORT: FROMGIT: binder: frozen notification
Frozen processes present a significant challenge in binder transactions. When a process is frozen, it cannot, by design, accept and/or respond to binder transactions. As a result, the sender needs to adjust its behavior, such as postponing transactions until the peer process unfreezes. However, there is currently no way to subscribe to these state change events, making it impossible to implement frozen-aware behaviors efficiently. Introduce a binder API for subscribing to frozen state change events. This allows programs to react to changes in peer process state, mitigating issues related to binder transactions sent to frozen processes. Implementation details: For a given binder_ref, the state of frozen notification can be one of the followings: 1. Userspace doesn't want a notification. binder_ref->freeze is null. 2. Userspace wants a notification but none is in flight. list_empty(&binder_ref->freeze->work.entry) = true 3. A notification is in flight and waiting to be read by userspace. binder_ref_freeze.sent is false. 4. A notification was read by userspace and kernel is waiting for an ack. binder_ref_freeze.sent is true. When a notification is in flight, new state change events are coalesced into the existing binder_ref_freeze struct. If userspace hasn't picked up the notification yet, the driver simply rewrites the state. Otherwise, the notification is flagged as requiring a resend, which will be performed once userspace acks the original notification that's inflight. See https://r.android.com/3070045 for how userspace is going to use this feature. Signed-off-by: Yu-Ting Tseng <yutingtseng@google.com> Acked-by: Carlos Llamas <cmllamas@google.com> Link: https://lore.kernel.org/r/20240709070047.4055369-4-yutingtseng@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Bug: 363013421 (cherry picked from commit d579b04a52a183db47dfcb7a44304d7747d551e1 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git char-misc-next) Change-Id: I5dd32abba932ca7d03ae58660143e075ed778b81 [cmllamas: fix merge conflicts due to missing 0567461a7a6e] Signed-off-by: Carlos Llamas <cmllamas@google.com> |
||
|
|
8c4165a043 |
BACKPORT: selftests/binderfs: add test for feature files
Verify that feature files are created successfully after mounting a binderfs instance. Note that only "oneway_spam_detection" feature is tested with this patch as it is currently the only feature listed. Acked-by: Christian Brauner <christian.brauner@ubuntu.com> Signed-off-by: Carlos Llamas <cmllamas@google.com> Link: https://lore.kernel.org/r/20210715031805.1725878-3-cmllamas@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> (cherry picked from commit 07e913418ce4ba5eb620dd4668bf91ec94e11136) Bug: 191910201 Signed-off-by: Carlos Llamas <cmllamas@google.com> [cmllamas: fix merge issues due to missing eaa163caa4cc] Change-Id: I86d7ef34b3099c8714c319e48029aaf3dbf87081 |
||
|
|
4d4f8b7a7f |
UPSTREAM: docs: binderfs: add section about feature files
Document how binder feature files can be used to determine whether a feature is supported by the binder driver. "oneway_spam_detection" is used as an example as it is the first available feature file. Acked-by: Christian Brauner <christian.brauner@ubuntu.com> Signed-off-by: Carlos Llamas <cmllamas@google.com> Link: https://lore.kernel.org/r/20210715031805.1725878-2-cmllamas@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> (cherry picked from commit 06e1721d2a265d1247093f5ad5ae2958ef10a604) Bug: 191910201 Signed-off-by: Carlos Llamas <cmllamas@google.com> Change-Id: I9c4542e0ee65dd94a492fe0440ba8f1a48d8b797 |
||
|
|
460de65538 |
BACKPORT: binderfs: add support for feature files
Provide userspace with a mechanism to discover features supported by the binder driver to refrain from using any unsupported ones in the first place. Starting with "oneway_spam_detection" only new features are to be listed under binderfs and all previous ones are assumed to be supported. Assuming an instance of binderfs has been mounted at /dev/binderfs, binder feature files can be found under /dev/binderfs/features/. Usage example: $ mkdir /dev/binderfs $ mount -t binder binder /dev/binderfs $ cat /dev/binderfs/features/oneway_spam_detection 1 Acked-by: Christian Brauner <christian.brauner@ubuntu.com> Signed-off-by: Carlos Llamas <cmllamas@google.com> Link: https://lore.kernel.org/r/20210715031805.1725878-1-cmllamas@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> (cherry picked from commit fc470abf54b2bd6e539065e07905e767b443d719) Bug: 191910201 Signed-off-by: Carlos Llamas <cmllamas@google.com> [cmllamas: fix merge conflicts due to missing 095cf502b31e] Change-Id: Ia5c03aa1881981bee26459e741134b83d5b59693 |
||
|
|
31f1f4b2aa |
FROMLIST: binder: fix memory leaks of spam and pending work
commit 1aa3aaf8953c84bad398adf6c3cabc9d6685bf7d upstream
A transaction complete work is allocated and queued for each
transaction. Under certain conditions the work->type might be marked as
BINDER_WORK_TRANSACTION_ONEWAY_SPAM_SUSPECT to notify userspace about
potential spamming threads or as BINDER_WORK_TRANSACTION_PENDING when
the target is currently frozen.
However, these work types are not being handled in binder_release_work()
so they will leak during a cleanup. This was reported by syzkaller with
the following kmemleak dump:
BUG: memory leak
unreferenced object 0xffff88810e2d6de0 (size 32):
comm "syz-executor338", pid 5046, jiffies 4294968230 (age 13.590s)
hex dump (first 32 bytes):
e0 6d 2d 0e 81 88 ff ff e0 6d 2d 0e 81 88 ff ff .m-......m-.....
04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[<ffffffff81573b75>] kmalloc_trace+0x25/0x90 mm/slab_common.c:1114
[<ffffffff83d41873>] kmalloc include/linux/slab.h:599 [inline]
[<ffffffff83d41873>] kzalloc include/linux/slab.h:720 [inline]
[<ffffffff83d41873>] binder_transaction+0x573/0x4050 drivers/android/binder.c:3152
[<ffffffff83d45a05>] binder_thread_write+0x6b5/0x1860 drivers/android/binder.c:4010
[<ffffffff83d486dc>] binder_ioctl_write_read drivers/android/binder.c:5066 [inline]
[<ffffffff83d486dc>] binder_ioctl+0x1b2c/0x3cf0 drivers/android/binder.c:5352
[<ffffffff816b25f2>] vfs_ioctl fs/ioctl.c:51 [inline]
[<ffffffff816b25f2>] __do_sys_ioctl fs/ioctl.c:871 [inline]
[<ffffffff816b25f2>] __se_sys_ioctl fs/ioctl.c:857 [inline]
[<ffffffff816b25f2>] __x64_sys_ioctl+0xf2/0x140 fs/ioctl.c:857
[<ffffffff84b30008>] do_syscall_x64 arch/x86/entry/common.c:50 [inline]
[<ffffffff84b30008>] do_syscall_64+0x38/0xb0 arch/x86/entry/common.c:80
[<ffffffff84c0008b>] entry_SYSCALL_64_after_hwframe+0x63/0xcd
Fix the leaks by kfreeing these work types in binder_release_work() and
handle them as a BINDER_WORK_TRANSACTION_COMPLETE cleanup.
Cc: stable@vger.kernel.org
Fixes: a7dc1e6f99df ("binder: tell userspace to dump current backtrace when detected oneway spamming")
Reported-by: syzbot+7f10c1653e35933c0f1e@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=7f10c1653e35933c0f1e
Suggested-by: Alice Ryhl <aliceryhl@google.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Acked-by: Todd Kjos <tkjos@google.com>
Link: https://lore.kernel.org/r/20230922175138.230331-1-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[cmllamas: backport to v5.15 by dropping BINDER_WORK_TRANSACTION_PENDING
as commit 0567461a7a6e is not present. Remove fixes tag accordingly.]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Link: https://lore.kernel.org/all/20231208034842.997899-1-cmllamas@google.com/
Change-Id: I8e1ee7af87ef5706544e4f320e9498b8f4855a6b
[cmllamas: also backport to v5.4 to fix OOT 8a09136176f6]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
|
||
|
|
334fe73bdd |
FROMGIT: Binder: add TF_UPDATE_TXN to replace outdated txn
When the target process is busy, incoming oneway transactions are queued in the async_todo list. If the clients continue sending extra oneway transactions while the target process is frozen, this queue can become too large to accommodate new transactions. That's why binder driver introduced ONEWAY_SPAM_DETECTION to detect this situation. It's helpful to debug the async binder buffer exhausting issue, but the issue itself isn't solved directly. In real cases applications are designed to send oneway transactions repeatedly, delivering updated inforamtion to the target process. Typical examples are Wi-Fi signal strength and some real time sensor data. Even if the apps might only care about the lastet information, all outdated oneway transactions are still accumulated there until the frozen process is thawed later. For this kind of situations, there's no existing method to skip those outdated transactions and deliver the latest one only. This patch introduces a new transaction flag TF_UPDATE_TXN. To use it, use apps can set this new flag along with TF_ONE_WAY. When such an oneway transaction is to be queued into the async_todo list of a frozen process, binder driver will check if any previous pending transactions can be superseded by comparing their code, flags and target node. If such an outdated pending transaction is found, the latest transaction will supersede that outdated one. This effectively prevents the async binder buffer running out and saves unnecessary binder read workloads. Acked-by: Todd Kjos <tkjos@google.com> Signed-off-by: Li Li <dualli@google.com> Link: https://lore.kernel.org/r/20220526220018.3334775-2-dualli@chromium.org Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Bug: 231624308 Test: manually check async binder buffer size of frozen apps Test: stress test with kernel 4.14/4.19/5.10/5.15 (cherry picked from commit 9864bb4801331daa48514face9d0f4861e4d485b git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git char-misc-next) Change-Id: I1c4bff1eda1ca15aaaad5bf696c8fc00be743176 |
||
|
|
2bfddf30aa |
BACKPORT: binder: tell userspace to dump current backtrace when detected oneway spamming
When async binder buffer got exhausted, some normal oneway transactions will also be discarded and may cause system or application failures. By that time, the binder debug information we dump may not be relevant to the root cause. And this issue is difficult to debug if without the backtrace of the thread sending spam. This change will send BR_ONEWAY_SPAM_SUSPECT to userspace when oneway spamming is detected, request to dump current backtrace. Oneway spamming will be reported only once when exceeding the threshold (target process dips below 80% of its oneway space, and current process is responsible for either more than 50 transactions, or more than 50% of the oneway space). And the detection will restart when the async buffer has returned to a healthy state. Acked-by: Todd Kjos <tkjos@google.com> Signed-off-by: Hang Lu <hangl@codeaurora.org> Link: https://lore.kernel.org/r/1617961246-4502-3-git-send-email-hangl@codeaurora.org Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Bug: 181190340 Change-Id: Id3d2526099bc89f04d8ad3ad6e48141b2a8f2515 (cherry picked from commit a7dc1e6f99df59799ab0128d9c4e47bbeceb934d) Signed-off-by: Hang Lu <hangl@codeaurora.org> [cmllamas: fix trivial merge issue] Signed-off-by: Carlos Llamas <cmllamas@google.com> |
||
|
|
c3d6993d5c | Merge "msm-5.4.c3: qseecom: Fix possible race condition" | ||
|
|
f0e3f64088 |
msm-5.4.c3: qseecom: Fix possible race condition
Fix possible race condition in data->type value in case of multithreaded listener or app IOCTLs. For example, below could cause inconsistent data->type value while racing belows IOCTLs Thread1 with QSEECOM_IOCTL_REGISTER_LISTENER_REQ Thread2 with QSEECOM_IOCTL_UNREGISTER_LISTENER_REQ. Change-Id: I436b63c044a66c324d94db27566a7be70981bd6b Signed-off-by: Divisha Bisht <quic_divibish@quicinc.com> |
||
|
|
54d3e3ca11 |
USB: storage: Replace the sprintf with scnprintf
'sprintf' has been deprecated, hence replace it with a safer function scnprintf. Change-Id: I9bc8e3dfd2032a0447f38fc98a3ad31d9d609cab Signed-off-by: Rajashekar kuruva <quic_kuruva@quicinc.com> Signed-off-by: Prashanth K <quic_prashk@quicinc.com> |
||
|
|
83ba639ff8 | Merge "adsprpc: Handle UAF scenario in put_args" | ||
|
|
c6e7698c0c |
adsprpc: Handle UAF scenario in put_args
Currently, the DSP updates header buffers with unused DMA handle fds. In the put_args section, if any DMA handle FDs are present in the header buffer, the corresponding map is freed. However, since the header buffer is exposed to users in unsigned PD, users can update invalid FDs. If this invalid FD matches with any FD that is already in use, it could lead to a use-after-free (UAF) vulnerability. As a solution,add DMA handle references for DMA FDs, and the map for the FD will be freed only when a reference is found. Acked-by: Om Deore <quic_odeore@quicinc.com> Change-Id: I19ae21230bf11fe89858b10c9069a5daccabc392 Signed-off-by: Santosh Sakore <quic_ssakore@quicinc.com> |
||
|
|
177e8e0fad | Merge "msm: adsprpc: Avoid taking reference for group_info" | ||
|
|
de9f4fe6f8 |
msm: adsprpc: Avoid taking reference for group_info
Currently, the get_current_groups API accesses group info, which increases the usage refcount. If the IOCTL using the get_current_groups API is called many times, the usage counter overflows. To avoid this, access group info without taking a reference. A reference is not required as group info is not released during the IOCTL call. Change-Id: Ib4de80cac8b36f73d8f5c6dd9824722153189285 Signed-off-by: ANANDU KRISHNAN E <quic_anane@quicinc.com> |
||
|
|
63a32bf361 |
usb: gadget: f_gsi: bail out if opts is null
Currently, functions gsi_inst_clean & gsi_free_inst utilises gsi_opts without any check, however there is a possibility that the opts structure could become NULL. In such case, due to lack of if checks can result in NULL pointer dereference. Change-Id: I548690e2eee377b5292f258972ae7e38417f3085 Signed-off-by: Prashanth K <quic_prashk@quicinc.com> |
||
|
|
df80fcf8cd |
Merge tag 'android11-5.4.281_r00' into android11-5.4
This catches the android11-5.4 branch up to the 5.4.281 LTS release. Included in here are the following commits: * |
||
|
|
ef9a17e64f |
UPSTREAM: net: sched: sch_multiq: fix possible OOB write in multiq_tune()
[ Upstream commit affc18fdc694190ca7575b9a86632a73b9fe043d ]
q->bands will be assigned to qopt->bands to execute subsequent code logic
after kmalloc. So the old q->bands should not be used in kmalloc.
Otherwise, an out-of-bounds write will occur.
Bug: 349777785
Fixes:
|
||
|
|
0fc0638ba8 | Merge "msm: ep_pcie: Avoid setting host wake pending flag for D0" | ||
|
|
f4e5b5151e |
FROMLIST: binder: fix UAF caused by offsets overwrite
Binder objects are processed and copied individually into the target buffer during transactions. Any raw data in-between these objects is copied as well. However, this raw data copy lacks an out-of-bounds check. If the raw data exceeds the data section size then the copy overwrites the offsets section. This eventually triggers an error that attempts to unwind the processed objects. However, at this point the offsets used to index these objects are now corrupted. Unwinding with corrupted offsets can result in decrements of arbitrary nodes and lead to their premature release. Other users of such nodes are left with a dangling pointer triggering a use-after-free. This issue is made evident by the following KASAN report (trimmed): ================================================================== BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x19c Write of size 4 at addr ffff47fc91598f04 by task binder-util/743 CPU: 9 UID: 0 PID: 743 Comm: binder-util Not tainted 6.11.0-rc4 #1 Hardware name: linux,dummy-virt (DT) Call trace: _raw_spin_lock+0xe4/0x19c binder_free_buf+0x128/0x434 binder_thread_write+0x8a4/0x3260 binder_ioctl+0x18f0/0x258c [...] Allocated by task 743: __kmalloc_cache_noprof+0x110/0x270 binder_new_node+0x50/0x700 binder_transaction+0x413c/0x6da8 binder_thread_write+0x978/0x3260 binder_ioctl+0x18f0/0x258c [...] Freed by task 745: kfree+0xbc/0x208 binder_thread_read+0x1c5c/0x37d4 binder_ioctl+0x16d8/0x258c [...] ================================================================== To avoid this issue, let's check that the raw data copy is within the boundaries of the data section. Fixes: 6d98eb95b450 ("binder: avoid potential data leakage when copying txn") Cc: Todd Kjos <tkjos@google.com> Cc: stable@vger.kernel.org Signed-off-by: Carlos Llamas <cmllamas@google.com> Bug: 352520660 Link: https://lore.kernel.org/all/20240822182353.2129600-1-cmllamas@google.com/ Change-Id: I1b2dd8403b63e5eeb58904558b7b542141c83fc2 Signed-off-by: Carlos Llamas <cmllamas@google.com> |
||
|
|
97fd8bd8e6 | Merge "msm: ep_pcie: Prevent repetitive wake operation if wake is in process" | ||
|
|
ccba394a90 |
msm: ep_pcie: Avoid setting host wake pending flag for D0
In current implementation, when host wake request is received in D0 and M3 states, the following sequence of events are happening causing next host wake request from IPA/ client to fail. Sequence of events: 1. Device is in waking up process in D0, M3 states and expecting M0 next. 2. Wake up request received as device in M3. 3. Host wake API is executed setting host_wake_pending flag as well. 4. M0 received as part of wake up from 1. 5. Device in D0, M0 states. 6. Device again went to suspend state as no transfers are happening. 7. Device in D3cold, M3 states 8. Wake up request received from IPA. 9. Host wake API is called again but its returning without any operation as host_wake_pending flag is set. wake toggle is not done. 10. host_wake_pending flag is cleared only on receiving next D0. 11. Host wake requests are failing because of 9. To handle this, avoiding setting of host_wake_pending flag when the host wake request is received in D0 state. Change-Id: I83acde55e6c116653c3ed00e6b4560e3db6390bd Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com> |
||
|
|
d62bca7bf4 |
msm: ep_pcie: Prevent repetitive wake operation if wake is in process
Sometimes, device receives two consecutive wake-up events, added into a
workqueue. Then device assert WAKE# and host deassert PERST# if device
in D3cold state, triggering deassert perst IRQ. In IRQ thread, device
flush the workqueue to make sure previous d3cold process has completed
before enable endpoint. commit 43917f862f7d ("msm: mhi_dev: Flush
workqueue before processing PERST deassert"). However, the second wake
event is also in the workqueue, so ep_pcie_core_wakeup_host_internal
is invoked and seeing dev->perst_deast is true, setted by deassert
PERST# IRQ. Then device goes to access MHI register to issue inband PME,
leading to NOC error because endpoint is still disabled.
So add a check to prevent wake operation if a previous wake has completed.
10567.834470: [0x8219195 mhi_sm_dev_event_manager] Handling
MHI_DEV_EVENT_CORE_WAKEUP event, current states: M3 & D3_COLD_STATE
10567.834498: ep_pcie_core_toggle_wake_gpio: PCIe V1711211: No. 115 to
assert PCIe WAKE#; perst is asserted; D3hot is received, WAKE GPIO
state:0
10567.834507: ep_pcie_core_wakeup_host_internal: PCIe V1711211: Set wake
pending : 1 and return ; perst is not de-asserted; D3hot is set
10567.849704: [0x8219195 mhi_dev_notify_sm_event] received:
MHI_DEV_EVENT_HW_ACC_WAKEUP
10567.849976: ep_pcie_handle_perst_irq: PCIe V1711211: No. 1018 PERST
deassertion
10567.850053: [0x8219195 mhi_sm_dev_event_manager] Handling
MHI_DEV_EVENT_HW_ACC_WAKEUP event, current states: M3 & D3_COLD_STATE
10567.850071: ep_pcie_core_wakeup_host_internal: PCIe V1711211: request to
assert WAKE# when in D3hot
10567.860093: ep_pcie_core_issue_inband_pme: PCIe V1711211: request to
assert inband wake.
Change-Id: I85fb37c4171c5ef4974c573f0abba199cb718a84
Signed-off-by: Qiang Yu <quic_qianyu@quicinc.com>
|
||
|
|
0f0f48e68a | Merge "msm_ipa: Install exception rule for PPPoE-MPLS" |