"LA.UM.9.14.1.r1-14100-QCM6490.QSSI14.0"
* tag 'LA.UM.9.14.1.r1-14100-QCM6490.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0:
Release 2.0.8.34R
qcacld-3.0: Do not aggregate checksum failure packets in FISA
Release 2.0.8.34Q
qcacld-3.0: Handle assoc request frm in ROAM sync crypto update
Release 2.0.8.34P
qcacld-3.0: Send the user configured MFP state in RSO command
qcacld-3.0: Update key management after bss create response
qcacld-3.0: Add support for max 5 number of AKMs in connect req
qcacld-3.0: Add support for allowed_authmode
qcacld-3.0: Add support for security scoring
Release 2.0.8.34O
qcacld-3.0: Return vendor abort status to userspace
Change-Id: I5e0e2cfca7fad7129262440fd46a2aabba659598
"LA.UM.9.14.1.r1-14100-QCM6490.QSSI14.0"
* tag 'LA.UM.9.14.1.r1-14100-QCM6490.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qca-wifi-host-cmn:
qcacmn: Add length checks for noninheritance_ie
qcacmn: Fix OOB reads in util_gen_new_ie
qcacmn: Fix OOB reads in util_gen_new_ie
qcacmn: Add length checks for noninheritance_ie
qcacmn: Send the user configured MFP state in RSO command
qcacmn: Add support for handling the NL crypto params
qcacmn: Update key management after bss create response
qcacmn: Update BSS score calculation based on Security Profile
qcacmn: Add check to avoid NULL pointer deference in parse MBSSID
qcacmn: Fix use-after-free issue in util_scan_parse_mbssid
qcacmn: Fix memleak in MBSSIE handler
qcacmn: Fix potential OOB read in util_scan_is_split_prof_found()
qcacmn: Fix potential OOB read in util_scan_parse_mbssid()
qcacmn: Fix potential OOB read in util_scan_is_split_prof_found()
qcacmn: Fix potential OOB read in util_scan_parse_mbssid()
Change-Id: Iad0fb4d1bbcc122af81f9fed96436d246798a6dc
"LA.UM.9.14.1.r1-14100-QCM6490.QSSI14.0"
* tag 'LA.UM.9.14.1.r1-14100-QCM6490.QSSI14.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4:
msm: adsprpc: use-after-free (UAF) in global maps
sdxnightJar.config: kernel changes for TRIGGER target
msm: mhi_dev: Add UCI support if client req > TRE length
usb: gadget: f_cdev: Call function wakeup if func_wakeup_pending is set
usb: gadget: f_cdev: Bail out from cer_resume if func_suspended
msm: kgsl: Do not release dma and anon buffers if unmap fails
ALSA: compress: Remove redefinition
BACKPORT: media: venus: hfi: fix the check in session buffer requirement
msm: kgsl: Do not free sharedmem if it cannot be unmapped
ALSA: compress: allow pause and resume during draining
securemsm-kernel: Fix multiple listener registration on same fd
Configured process_madvise with upstream syscall number
msm: kgsl: Limit the syncpoint count for AUX commands
msm: kgsl: Prevent wrap around during user address mapping
iommu: Fix missing return check of arm_lpae_init_pte
Change-Id: I59256059b3d15fed896a7ce58d09f0950829dabb
* tag 'LA.UM.9.16.r1-14900-MANNAR.QSSI14.0':
ARM: dts: msm: Set refclock base address for sdxnightjar
ARM: dts: qcom: Add qcom minidump id for sdxlemur
ARM: dts: msm: Add non-wake-svc node
ARM: dts: msm: Add APQ-XR support for Blair
ARM: dts: qcom: Set number of descriptors to 1024
ARM: dts: qcom: Add property for multiple rx queues
ARM: dts: qcom: Add pcie node for Realtek r8168 driver
ARM: dts: msm: add backlight properties for eDP
Change-Id: I1321fe0f79f87f670fe20de4d1635103964638af
In the event when msm_gem_delayed_import returns an error, reset
the obj_dirty property to true to allow the buffer to detach and
attach again.
Change-Id: Ib8da8f237c5a4ab696675cbcf66f1a3dfae02639
Signed-off-by: Samantha Tran <samtran@codeaurora.org>
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
When we import an ION buffer, we call the dma_buf_map_attachment().
The intent is to not map it to the dma device(which in this case is the
KGSl device), but to only get the sg_table. Once we have the sg_table
we later map the physical pages to the GPU SMMU manually and not by using
the dma device ops.
The ION driver as part of the partial cache maintenance requires that
all the sg_tables of the attached devices to the buffer have a single
segment. This creates a problem for KGSL since in this case the kgsl is
a dummy device, so the buffer for KGSL always has multiple segments.
This patch calls the dma_buf_unmap_attachment() as soon we get a hold of
the sg_table as doing so a) we don't need the buffer to be mapped to a
dummy device, b) removes the buffer from the cache maintenance constraints
of the ION driver.
Change-Id: I0675e62c4a27b4e368d53ea6310c9244b687baa6
Signed-off-by: Sharat Masetty <smasetty@codeaurora.org>
Signed-off-by: Puranam V G Tejaswi <pvgtejas@codeaurora.org>
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
Currently, remote heap maps get added to the global list before the
fastrpc_internal_mmap function completes the mapping. Meanwhile, the
fastrpc_internal_munmap function accesses the map, starts unmapping, and
frees the map before the fastrpc_internal_mmap function completes,
resulting in a use-after-free (UAF) issue. Add the map to the list after
the fastrpc_internal_mmap function completes the mapping.
Change-Id: Ia524f142edba57a1f389dd0e5c83a1967c7f5a59
Acked-by: Abhishek Singh <abhishes@qti.qualcomm.com>
Signed-off-by: Santosh Sakore <quic_ssakore@quicinc.com>
(cherry picked from commit 6f9f631c90)
"LA.UM.9.14.r1-24700-LAHAINA.QSSI15.0"
* tag 'LA.UM.9.14.r1-24700-LAHAINA.QSSI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/camera-kernel:
msm: camera: memmgr: Add refcount to track umd in use buffers
msm: camera: memmgr: Add refcount to track umd in use buffers
msm: camera: sensor: Handling race condition in util api
Change-Id: I4708288ccf2096b70148fbeb2bb543991ac8df4d
"LA.UM.9.14.r1-24700-LAHAINA.QSSI15.0"
* tag 'LA.UM.9.14.r1-24700-LAHAINA.QSSI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel:
Asoc: dsp: Fix to check the list is empty or not
dsp: q6lsm: Check size of payload before access
Fix for OOB access issue
dsp: q6asm increase the locking range
ASoC: msm-pcm-q6-v2: Add size check
ASoC : Add proper copyright marking.
dsp: afe: Add check for num_spks
soc: pinctrl-lpi: remove pm ops
asoc: msm-compress: Fix compress_pause failure on gki
Audio legacy: Integer overflow in msm_lsm_ioctl_compat during audio playback usecase. size = sizeof(p_info_32) + p_info_32.param_size; This overflow issue may result heap overflow during copying the data: memcpy(param_info_rsp, &p_info_32, sizeof(p_info_32));
ASoC : Add macro to differentiate auto code
ASoC: msm: get CoPP index based on FE id
asoc: codecs: add array bound check
soc: Address SWR rate mismatch interrupt
asoc : add configuration about SLIMBUS_7_TX
asoc: lahaina: add support for aud_ref_clk_sel mux
dsp: afe: add support for aud_ref_clk_sel mux
ASoC: dsp: Release lock before return
ASoC: wcd937x: Add flag to decide RX_MUTE for HPHL and EAR
ASoC: bolero: Add check for CMPDR switch
ASoC : add support of HDMI controller for rb3gen2 platform
asoc: lahaina: fractional sample rate support for TDM
asoc: support for fractional sample rate over tdm
Revert "asoc: msm-compress : Fix for CTS-on-gsi with gki"
audio-kernel:swr: Add dynamic SWRM clk support
asoc: codec: make mclk freq configurable in Bolero
asoc: lahaina: Add ext clk source support
asoc: ext-clk: Add support for configuring ext clk
dsp: afe: Enhance and expose API for configuring ext clk
dsp: q6voice: Handle mutex lock-unlock
asoc: msm-compress : Fix for CTS-on-gsi with gki
Change-Id: I21b8e5f5ef608bf298230419123e4ee37c9b0797
"LA.UM.9.14.r1-24700-LAHAINA.QSSI15.0"
* tag 'LA.UM.9.14.r1-24700-LAHAINA.QSSI15.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4:
msm: npu v1: Fix OOB issue in IPC between driver and firmware
mmc: sdhci-msm: Disable partial_init and clk-scaling to avoid RED error
slimbus: qcom-ngd-ctrl: Avoid accessing deallocated stack
msm_ipa: new structure for tunnel design for uC
msm: ipa3: change variable name for indication of rx tlv format
soc: qcom: llcc: Handle a second device without data corruption
msm: eva: User after free fix in msm_cvp_mark_user_persist
rpmsg: slatecom: out of bound read from process_cmd
soc: qcom: msm_minidump: Configurable Encryption support
defconfig: arm64: Disable trimming non-whitelisted symbols
soc: qcom: add out of bound check for AON fifo
rpmsg: slatecom: maintain rx_size to read
Revert LLCC changes
bus: mhi: Fix potential out-of-bound access
Conflicts:
arch/arm64/boot/dts/vendor/bindings/interrupt-controller/ti,sci-intr.txt
drivers/soc/qcom/llcc-slice.c
drivers/usb/dwc3/core.c
kernel/events/core.c
mm/memory-failure.c
Change-Id: Ie4d89454f0766d0a48ebd4f2e6facb6deca9ea57
When MSDU fails for checksum validation, do not aggregate those
packets and make sure current flow is flushed. Since checksum
failure packet data is not trust worthy it is not advisable to
build aggregated skb on top of checksum failure packets.
Change-Id: I09d8c4aeb656e6b0b5d268a60d72147534f2a2ab
CRs-Fixed: 3805053
Currently struct ipa_wdi_conn_in_params occupies 1588 bytes and putting
it on the stack is rather expensive, which could potentially lead to
stack corruption.
Fix is to reduce stack usage in dp_ipa_setup by dynamically allocating
struct ipa_wdi_conn_in_params on the heap.
Change-Id: I8f71f44906a5c95f37627f7573b57b7825daaa7e
CRs-Fixed: 2852027
In qrtr_get_service_id, use xa_load instead of node_get to check
if the node exists or not. Calling node_get from interrupt context
can cause potential deadlock since it calls into xa_store to
allocate the node if it does not exist.
Change-Id: Ida9f7a113417f0d184c0903004d94dd2eca6c472
Signed-off-by: Sarannya S <quic_sarannya@quicinc.com>
The return value for of_property_count_u32_elems can be negative in the
case of an error or the property is not found. It is incorrect to use
size_t, unsigned type, as this can cause an overflow. Switch size from
type size_t to int.
Change-Id: Ica0425abd034b82994ab32087f04d602ce3dd9e9
Signed-off-by: Tony Truong <quic_truong@quicinc.com>
Fix a compilation error seen when casting void pointer to
int by casting it to uintptr_t instead.
Change-Id: I679da04f21041c386fa7ad8905ede94e12ea160c
Signed-off-by: Jishnu Prakash <quic_jprakash@quicinc.com>
../drivers/thermal/qcom/max31760_fan.c:331:3: error: ignoring return
value of function declared with 'warn_unused_result' attribute
[-Werror,-Wunused-result]
(pdata->vdd_reg);
^~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~
Change-Id: I06fb07da60cb765e4daf98c38afdb97690491c6f
Fixes:
../drivers/input/touchscreen/focaltech_touch/focaltech_core.c:979:3:
error: ignoring return value of function declared with
'warn_unused_result' attribute [-Werror,-Wunused-result]
PTR_ERR(acl_desc);
^~~~~~~ ~~~~~~~~
../drivers/input/touchscreen/focaltech_touch/focaltech_core.c:986:3:
error: ignoring return value of function declared with
'warn_unused_result' attribute [-Werror,-Wunused-result]
PTR_ERR(sgl_desc);
^~~~~~~ ~~~~~~~~
Change-Id: I941c32696a52a84a0a9272d4f969755932925aaa
../net/ipv4/tcp_timer.c:202:27: warning: implicit truncation from 'int' to a one-bit wide bit-field changes value from 1 to -1 [-Wsingle-bit-bitfield-constant-conversion]
icsk->icsk_mtup.enabled = 1;
Change-Id: I7e1b4013ba6a67fad27a611d30f98939ceaa5109
../techpack/dataipa/drivers/platform/msm/ipa/ipa_v3/rmnet_ipa.c:510:41: warning: implicit conversion from enumeration type 'enum ipa_ip_type_enum_v01' to different enumeration type 'enum ipa_ip_type' [-Wenum-conversion]
q6_ul_flt_rule_ptr->ip = flt_spec_ptr->ip_type;
~ ~~~~~~~~~~~~~~^~~~~~~
../techpack/dataipa/drivers/platform/msm/ipa/ipa_v3/rmnet_ipa.c:511:45: warning: implicit conversion from enumeration type 'enum ipa_filter_action_enum_v01' to different enumeration type 'enum ipa_flt_action' [-Wenum-conversion]
q6_ul_flt_rule_ptr->action = flt_spec_ptr->filter_action;
~ ~~~~~~~~~~~~~~^~~~~~~~~~~~~
Change-Id: I0eb68d707151cd103676a30659ab81bf6fced131
Ensures that no new warnings are introduced to the build.
Bug: 141372918
Change-Id: I4107af91f5c1ddd655037823350e005e8362d588
Signed-off-by: Chenglu Lin <chenglulin@google.com>
Add configuration option CONFIG_CC_WERROR to prevent warnings
from creeping in.
Bug: 141372918
Change-Id: Ie2d067c0177d8f13e9aaa9a78867998e390f89ee
Signed-off-by: Chenglu Lin <chenglulin@google.com>
When CONFIG_CFI_CLANG and CONFIG_DYNAMIC_FTRACE are enabled, LLVM will
generate a jump function named ftrace_call.cfi_jt for ftrace_call, which
makes "&ftrace_call" in ftrace_update_ftrace_func() actually the address
of ftrace_call.cfi_jt. As a result, the tracer can't be really enabled
through runtime modification. Use __va_function() to get the actual address
of ftrace_call to fix the issue.
Bug: 184105181
Signed-off-by: Ben Dai <ben.dai@unisoc.com>
Change-Id: Ic9272cd4ab447b3b145d8e397e5c9010c49f7a12
After the switch to non-canonical CFI jump tables, the jump table
sections were placed after the .text section. Merge these sections
into .text to fix issues with error injection and kallsyms.
Bug: 225079388
Bug: 190422440
Change-Id: I6c81b3e4dbba62739f7fc5f6b45271c54f278c8f
Signed-off-by: Sami Tolvanen <samitolvanen@google.com>
Handle error return value from copy_to_user() in ioctls to avoid
following compilation failure.
"error: ignoring return value of function declared with 'warn_unused_result'
attribute".
Change-Id: I92944ade7fb88e0543ca4254fab226da5777def7
Signed-off-by: Jeevan Shriram <quic_jshriram@quicinc.com>
It never hurts to know if drivers have some flaws.
Change-Id: Iba3acda0eeec9448fc907def5b3d25f117bc818b
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
This flag is specific to clang, where it is only used by the 32-bit and
64-bit ARM backends. In certain situations, the presence of this flag
will cause a warning, as shown by commit 6580c5c18fb3 ("um: clang: Strip
out -mno-global-merge from USER_CFLAGS").
Since commit 61163efae0 ("kbuild: LLVMLinux: Add Kbuild support for
building kernel with Clang") that added this flag back in 2014, there
have been quite a few changes to the GlobalMerge pass in LLVM. Building
several different ARCH=arm and ARCH=arm64 configurations with LLVM 11
(minimum) and 15 (current main version) with this flag removed (i.e.,
with the default of '-mglobal-merge') reveals no modpost warnings, so it
is likely that the issue noted in the comment is no longer relevant due
to changes in LLVM or modpost, meaning this flag can be removed.
If any new warnings show up that are a result of the removal of this
flag, it can be added back under arch/arm{,64}/Makefile to avoid
warnings on other architectures.
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Tested-by: David Gow <davidgow@google.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Tested-by: Sedat Dilek <sedat.dilek@gmail.com>
Reviewed-by: Sedat Dilek <sedat.dilek@gmail.com>
Signed-off-by: Masahiro Yamada <masahiroy@kernel.org>
(cherry picked from commit cf300b83c793c25c6b485fdaf7a4447d8ea4c655)
Change-Id: Ice39a960619319828b83c8091798fe383395a2b0
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
strlen(swr_dmic_name_prefix_of) + 1 bytes are allocated for prefix_name just above
techpack/audio/asoc/codecs/swr-dmic.c:685:11: error: size argument in 'strlcpy' call appears to be size of the source; expected the size of the destination [-Werror,-Wstrlcpy-strlcat-size]
strlen(swr_dmic_name_prefix_of) + 1);
~~~~~~~^~~~~~~~~~~~~~~~~~~~~~~~~~~~
1 error generated.
Change-Id: I808b4f135d42fc50587eeb9348848f7e0a3561cc
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
The size is checked just above.
../drivers/hwtracing/coresight/coresight-tmc.c:423:26: warning: 'sscanf' may overflow; destination buffer in argument 3 has size 10, but the corresponding specifier may require size 11 [-Wfortify-source]
423 | if (sscanf(buf, "%10s", str) != 1)
| ^
../drivers/hwtracing/coresight/coresight-tmc.c:464:26: warning: 'sscanf' may overflow; destination buffer in argument 3 has size 10, but the corresponding specifier may require size 11 [-Wfortify-source]
464 | if (sscanf(buf, "%10s", str) != 1)
| ^
2 warnings generated.
Change-Id: I5db199a85ba0c7dfc15fae5d62c9c4d8c550d3e7
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
Extracted from I54b58226e3d6de0b674ac4ca1407138d1c9707e8
../drivers/soc/qcom/msm_minidump.c:521:39: warning: size argument in 'strlcpy' call appears to be size of the source; expected the size of the destination [-Wstrlcpy-strlcat-size]
521 | strlcpy(banner, linux_banner, strlen(linux_banner) + 1);
| ~~~~~~~^~~~~~~~~~~~~~~~~
1 warning generated.
Change-Id: I43fa5006150dd402405f8c942571f08da0eb714a
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
Only 19 characters out of total 20 can be used due to the '\0' terminator.
Change-Id: I34883be26f97a16fdcb5ff97ff326d98f4d93c18
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
CAF cherry-picked an obsolete LLVMLinux patch from 2014 in commit
a2a31f1ddc that introduced this
unnecessary flag. Now that the functions used by Clang's libcall
optimizations have been implemented, we can allow Clang to perform said
optimizations for a minor performance bump in certain code paths.
Change-Id: Ifa6b731c9702973be2c656d341e33a6186ed7cf2
Signed-off-by: Danny Lin <danny@kdrag0n.dev>
This reverts commit 1210d2329b.
Unnecessary with Clang 6.0+.
Change-Id: I6f29ca050566e9027e51605e64bf6893602344ef
Signed-off-by: Danny Lin <danny@kdrag0n.dev>