Commit graph

909,960 commits

Author SHA1 Message Date
Vinayaka B M
bf7fb6ca05 msm: ipa: Rmnet CV2X header file changes
Modify code to support additional rmnet_cv2x teth
interface.

Original 2779101.

Change-Id: I5cd9b07036c5c4d1e1df9e6d996b358057c58635
Signed-off-by: Vinayaka B M <quic_vinaybm@quicinc.com>
2023-01-21 20:30:16 -08:00
Jishnu Prakash
a5e6953336 mfd: qcom-spmi-pmic: Add remove API
Add remove API for unloading spmi-pmic module, as the SPMI
framework right now requires drivers under it to have a
remove API defined when removing them.

Change-Id: Iaf5b9f602fb9389c75a68702eaceb847abcf2876
Signed-off-by: Jishnu Prakash <quic_jprakash@quicinc.com>
2023-01-19 22:44:07 -08:00
qctecmdr
41978afa6c Merge "mhi: core: Add the basic sanity to check the irq registration" 2023-01-09 06:41:24 -08:00
qctecmdr
a1531c645a Merge "net: qrtr: haven: Add bounds check in rx path" 2023-01-08 22:39:59 -08:00
Jyothi Kumar Seerapu
b4c9cf2eed mhi: core: Add the basic sanity to check the irq registration
As part of MHI Power On sequence, registering the mhi irq through
request_threaded_irq function. In case of failure in mhi irq
registration, we simply return without printing the error message.
So, added the error message with printing mhi irq number and return
value in failure case of irq registration.

Change-Id: I5d2e1bc6d66abc8b42ca60fbc53b7664d3468db0
Signed-off-by: Jyothi Kumar Seerapu <quic_jseerapu@quicinc.com>
2023-01-09 09:38:13 +05:30
qctecmdr
aa89ee4a2c Merge "net: qrtr: haven: Add bounds check on tx path" 2023-01-05 01:15:29 -08:00
qctecmdr
5cbaa45558 Merge "msm: ipa: Add DSCP PCP mapping info ioctl" 2023-01-03 04:27:34 -08:00
Sarannya S
cf0602ada5 net: qrtr: haven: Add bounds check on tx path
Add bounds check on values read from shared memory in the tx path. In
cases where the VM is misbehaving, the qrtr haven transport should
exit and print a warning when bogus values may cause out of bounds to
be read.

Change-Id: Ic1177ced6f41de66459970eff4537d82de4f614e
Signed-off-by: Sarannya S <quic_sarannya@quicinc.com>
2023-01-02 20:36:33 -08:00
Michael Adisumarta
3434256d68 msm: ipa: Add DSCP PCP mapping info ioctl
Adding DSCP PCP mapping ioctl support for easymesh R3.

Change-Id: I7a7fcc3fdc22cdf1970638e8163bda7ef74dc7b3
Signed-off-by: Michael Adisumarta <quic_madisuma@quicinc.com>
2023-01-02 19:56:08 -08:00
Kishore Kumar Ravi
ab6f0337d4 rpmsg: glink: Remove dev_set_name to avoid KASAN issue
KASAN repots use after free issue for dev_set_name call.

Remove dev_set_name to override KASAN issue.

Change-Id: If59ef4671dbd71692f36ee605c14bea4602f41e5
Signed-off-by: Kishore Kumar Ravi <quic_kiskum@quicinc.com>
2023-01-01 23:13:20 -08:00
qctecmdr
c96e0bdcc4 Merge "iio: qcom-spmi-adc5: remove the remove callback" 2022-12-28 21:30:19 -08:00
Sarannya S
a97331a732 net: qrtr: haven: Add bounds check in rx path
Validate the values read from shared memory in the receive path.
In the case where a VM is misbehaving, the qrtr haven transport
should return immediately and print a warning.

Change-Id: Ieccd3f99ec0cf321f136600760e7f66e125f765a
Signed-off-by: Sarannya S <quic_sarannya@quicinc.com>
2022-12-28 08:27:10 -08:00
qctecmdr
245ad69b23 Merge "icnss2: Add data length validation in cnss_wlfw_qdss_data_send_sync()" 2022-12-27 23:34:36 -08:00
qctecmdr
ab866c2306 Merge "devfreq: memlat: Change number of array elements for holding core_stats" 2022-12-27 20:15:36 -08:00
Alan Chen
9c72c5a227 icnss2: Add data length validation in cnss_wlfw_qdss_data_send_sync()
Add a data length validation check in fw response message in
qdss_data_send_sync().

Change-Id: I750f46549bc914698baaf4e24f1710536ca8e356
CRs-Fixed: 3366343
Signed-off-by: Alan Chen <quic_alache@quicinc.com>
2022-12-27 16:43:40 -08:00
Avaneesh Kumar Dwivedi
3ebdc2df40 devfreq: memlat: Change number of array elements for holding core_stats
Memlat driver allocates as many array elements in core_stats array as 
many possible cpus While when any of core is not available in between
we need to consider what is first and last cpu in possible mask, 
accordingly initialize the core_stats array.

Change-Id: I26420d2b061b712f94c3e496cff12811ea4a678a
Signed-off-by: Avaneesh Kumar Dwivedi <quic_akdwived@quicinc.com>
2022-12-27 04:12:36 -08:00
Avaneesh Kumar Dwivedi
ccce7f7c52 cpu-topology: Change the size of allocation for cpu's raw_capacity
Allocating raw_capacity nodes as per max possible cpus gives issues
when there are cores in between which are not available. Allocate as 
many elements for holding raw_capacity as is last set bit position
in possible mask.

Change-Id: I90055f96c320b15960efac10d8d92c69413eeb6b
Signed-off-by: Avaneesh Kumar Dwivedi <quic_akdwived@quicinc.com>
2022-12-27 04:11:48 -08:00
Jishnu Prakash
06cfd223bf iio: qcom-spmi-adc5: remove the remove callback
Remove the driver remove callback as there is no significant
cleanup action done in it for the ADC driver.

Change-Id: I2a11ac4d15cc94e652c7b238da4cc47f28dbf8a3
Signed-off-by: Jishnu Prakash <quic_jprakash@quicinc.com>
2022-12-27 03:02:38 -08:00
Naman Padhiar
a845583f32 cnss2: Validate maximum number of memory segments
For WIN use case maximum number of memory segments requested
by FW is increased to 52 in QMI layer. Since CNSS2 driver uses
same QMI header files and message structures the same maximum
number of segment is applicable for CNSS2. It means for memory
allocation, FW can request 52 memory segments to CNSS2 via QMI
indication but local CNSS2 variable which get segment info from
indication supports maximum 32 segments.
To fix it, change CNSS2 array variable size to same as number of
maximum segment supported in QMI layer.

Change-Id: I661b55b53cb31327da12f064d0a516884159eb5b
Signed-off-by: Naman Padhiar <quic_npadhiar@quicinc.com>
2022-12-22 03:05:22 -08:00
Alan Chen
533e2889b8 cnss2: Add data length validation in cnss_wlfw_qdss_data_send_sync()
Add a data length validation check in fw response message in
qdss_data_send_sync().

Change-Id: I197b8d52c06e35f5fcf0f8fee94429fdcf500fcb
CRs-Fixed: 3359589
Signed-off-by: Alan Chen <quic_alache@quicinc.com>
2022-12-20 13:35:55 -08:00
qctecmdr
c3cdfb23f5 Merge "memshare: Free QMI handle only if its valid" 2022-12-12 20:45:46 -08:00
Manoj Prabhu B
9dcfdde71f memshare: Free QMI handle only if its valid
Avoid possible use-after-free access for a QMI handle
during driver deinit by ensuring the free happens only for
valid QMI handle and is marked NULL post free.

Change-Id: I4314dff560de2fc3aea30d636f935d7a02067a57
Signed-off-by: Manoj Prabhu B <quic_bmanoj@quicinc.com>
2022-12-12 10:33:37 +05:30
Charan Teja Kalla
484e438642 ANDROID: arm64: mm: perform clean & invalidation in __dma_map_area
commit c50f11c6196f ("arm64: mm: Don't invalidate FROM_DEVICE buffers at
start of DMA transfer") break assumptions of some device drivers about
invalidation that happens as part of __dma_map_area(DMA_FROM_DEVICE). An
example include drivers using dmabuf API dma_buf_begin_cpu_access() and
dma_buf_end_cpu_access() to achieve buffer invalidation. Fix this breakage
by replacing clean with clean and invalidation in __dma_map_area() for
DMA inbound case.

Bug: 260978220
Change-Id: Id1a2750c2036de693cd52e8f7316f1d820b5a262
Fixes: c50f11c6196f ("arm64: mm: Don't invalidate FROM_DEVICE buffers at start of DMA transfer")
Signed-off-by: Charan Teja Kalla <quic_charante@quicinc.com>
Signed-off-by: Shiraz Hashim <quic_shashim@quicinc.com>
Signed-off-by: Prakash Gupta <quic_guptap@quicinc.com>
Signed-off-by: Pavankumar Kondeti <quic_pkondeti@quicinc.com>
Git-commit: cbbd724281
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2022-12-05 14:43:43 +05:30
Will Deacon
1461e36622 arm64: mm: Don't invalidate FROM_DEVICE buffers at start of DMA transfer
commit c50f11c6196f45c92ca48b16a5071615d4ae0572 upstream.

Invalidating the buffer memory in arch_sync_dma_for_device() for
FROM_DEVICE transfers

When using the streaming DMA API to map a buffer prior to inbound
non-coherent DMA (i.e. DMA_FROM_DEVICE), we invalidate any dirty CPU
cachelines so that they will not be written back during the transfer and
corrupt the buffer contents written by the DMA. This, however, poses two
potential problems:

  (1) If the DMA transfer does not write to every byte in the buffer,
      then the unwritten bytes will contain stale data once the transfer
      has completed.

  (2) If the buffer has a virtual alias in userspace, then stale data
      may be visible via this alias during the period between performing
      the cache invalidation and the DMA writes landing in memory.

Address both of these issues by cleaning (aka writing-back) the dirty
lines in arch_sync_dma_for_device(DMA_FROM_DEVICE) instead of discarding
them using invalidation.

Change-Id: Ibfda7d1f68d11d76c7b603f083d8ee773a37cc22
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Christoph Hellwig <hch@lst.de>
Cc: Robin Murphy <robin.murphy@arm.com>
Cc: Russell King <linux@armlinux.org.uk>
Cc: <stable@vger.kernel.org>
Link: https://lore.kernel.org/r/20220606152150.GA31568@willie-the-truck
Signed-off-by: Will Deacon <will@kernel.org>
Reviewed-by: Ard Biesheuvel <ardb@kernel.org>
Link: https://lore.kernel.org/r/20220610151228.4562-2-will@kernel.org
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Git-commit: 7b9c3bfbad
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2022-12-05 14:42:06 +05:30
qctecmdr
9ef9b9d575 Merge "msm: ep_pcie: Sending PME for device initiated D3cold exit" 2022-12-02 04:57:04 -08:00
qctecmdr
a91c0ba8d5 Merge "net: usbnet: Add mechanism to throttle usb0 RX traffic in USB SS" 2022-11-29 07:55:18 -08:00
qctecmdr
fb82ed659b Merge "net: rmnet: add ioctl support for IP route utility" 2022-11-28 20:39:31 -08:00
Sai Chaitanya Kaveti
a13ebeb960 msm: ep_pcie: Sending PME for device initiated D3cold exit
According to the PCIe specification, PME message is to be sent for
device initiated D3cold to D0 transition. To support this sending PME
immediately after link training while transitioning from D3cold to D0.

As retention flops are not available for sdxlemur, sticky bits in the
registers are not retained during low power state. PME enable bit is
being cleared because of this. To handle this added a flag to check the
status of pme_en after D3 event and set pme_en during link training if
the flag is set.

Change-Id: I474a675a35566c2ff051374c9d212c47d08d622d
Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
2022-11-28 19:26:38 +05:30
Sharath Chandra Vurukala
272e244efa net: rmnet: add ioctl support for IP route utility
Add a new define to support rmnet ioctl for IP ROUTE.

Change-Id: I9927ff28dd0a377eef132586ea7794cc01279fc0
Signed-off-by: Sharath Chandra Vurukala <quic_sharathv@quicinc.com>
2022-11-27 22:20:46 -08:00
Krishna Kurapati
6da027eb3a net: usbnet: Add mechanism to throttle usb0 RX traffic in USB SS
ECM traffic is non-aggregated which makes it send huge number of
packets in high throughput usecases. This causes the CPU to
dedicate majority of the cycles to ISR context and the softIRQ
contexts stay suspended.

The rx_complete (hardIRQ) keeps adding SKBs to the 'done' list. The
usbnet_bh (tasklet) is supposed to dequeue SKBs from 'done' list and
provide them to NW stack so that they can be consumed. Because of the
above issue, the 'done' list keeps increasing and the system
eventually runs out of memory. When the WD_pet task also does not get
a chance to run because of hardIRQ storm, WD bite is also observed.

Introduce a mechanism to balance the time between hardIRQ and softIRQ
contexts. Add module parameter 'usb0_rx_skb_threshold' to stop the
submission of URBs to HW from the ISR. This will allow the usbnet_bh
to run and consume SKBs, thereby avoiding the OOM scenario and the
WD_pet task also gets a chance to pet the WD. The default value of
this threshold is 500, which can be changed runtime to suit the
requirements according to CPU load.

Since in the failing case, ASIX AX88179/178A USB 3.0/2.0 to Gigabit
Ethernet adapters are being used, throttle handling has been added in
that driver.

Usage:
echo <threshold> > /sys/module/usbnet/parameters/usb0_rx_skb_threshold

Change-Id: I4667f0ad67d5605b132a0e6062be27e01ef75a08
Signed-off-by: Ajay Agarwal <ajaya@codeaurora.org>
Signed-off-by: Krishna Kurapati <quic_kriskura@quicinc.com>
2022-11-27 21:52:36 -08:00
qctecmdr
2cbfc9cf22 Merge "msm: kgsl: Remove protected GPUCC registers from snapshot" 2022-11-27 19:58:20 -08:00
qctecmdr
9927b09f7f Merge "msm: mhi_dev: Avoiding double free in MHI UCI layer" 2022-11-25 23:44:30 -08:00
Avaneesh Kumar Dwivedi
7bb7779ce4 core_ctl: Add check for available cpus before accessing per_cpus
For qultivate target its trying to call per_cpu() for
cpu's which are fused out and leading to crash So, Add
a check for available cpu's before calling per_cpu.

Change-Id: Idfd97fcfc83baa59afe9010396e7b6314087bf13
Signed-off-by: Avaneesh Kumar Dwivedi <quic_akdwived@quicinc.com>
Signed-off-by: Chetan C R <quic_cchinnad@quicinc.com>
2022-11-24 22:22:42 +05:30
Amit Kushwaha
a56e91363f msm: kgsl: Remove protected GPUCC registers from snapshot
This change is to prevent data abort when HLOS accessing
protected registers used in SoftSKU.

Change-Id: Ia7facc5cf78453f75f829ae7b6626a7f182c8f91
Signed-off-by: Amit Kushwaha <quic_amitkush@quicinc.com>
2022-11-24 17:32:47 +05:30
qctecmdr
1de0be8d9c Merge "msm: ipa3: add new ETH PDU QMI" 2022-11-24 00:26:58 -08:00
qctecmdr
8caaed7837 Merge "msm: ipa3: rmnet: header file update for eth pdu" 2022-11-24 00:26:57 -08:00
qctecmdr
21b2ea7163 Merge "msm: ipa3: add new ETH PDU pipes and ETH PDU event" 2022-11-24 00:26:57 -08:00
Sai Chaitanya Kaveti
4dd23ac1ac msm: mhi_dev: Avoiding double free in MHI UCI layer
In mhi_uci_ctrl_set_tiocm(), the control message is submitted to MHI/IPA
using mhi_uci_send_packet(). Device waits for completion after this. If
the wait is interrupted or is timed out, control message buffer is freed
using kfree(). But as the message is already sent, write completion
callback is invoked after buffer is freed and same pointer is being
freed again.

To avoid this double free issue, removing kfree() in
mhi_uci_ctrl_set_tiocm(). Once sending of the message is completed,
buffer is freed as part of the write completion callback.

Change-Id: I6e33ce46fc5506ac45256102221fafb08050a5b5
Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
2022-11-24 11:18:48 +05:30
Michael Adisumarta
16d47db67b msm: ipa3: add new ETH PDU QMI
Add new QMI messages and struct to support ETH PDU FR.

Change-Id: I2fa969330898e7e08b7ab3dcf0fea6b4239b253a
Signed-off-by: Michael Adisumarta <quic_madisuma@quicinc.com>
2022-11-22 12:14:28 -08:00
Michael Adisumarta
7610cc416f msm: ipa3: add new ETH PDU pipes and ETH PDU event
Define the UL and DL pipe for ETH PDU E2E transfers.
Add new event for ENABLE_ETH_PDU_MODE.

Change-Id: I1ebb943d63cee47c686a857343b1974ead376be0
Signed-off-by: Michael Adisumarta <quic_madisuma@quicinc.com>
2022-11-21 16:29:51 -08:00
Skylar Chang
64ca5a9d31 msm: ipa3: rmnet: header file update for eth pdu
Introduce new ioctls and structures for ETH PDU

Change-Id: I5b6a98f90b8b3816a27aa9e6020b1a863d24aa22
Signed-off-by: Skylar Chang <quic_chiaweic@quicinc.com>
2022-11-21 15:18:12 -08:00
Michael Adisumarta
3b9c44ebff msm: ipa3: add MPLS support to existing IPA GRE struct
Add kernel support to handle IPA offload for MPLS packets
over GRE tunnel. Add new struct that specify tuple parameters
for packets that will take the exception path for MPLS over GRE.

Change-Id: I27a668af59af02dd08dd74f19782e28a7a40c6c2
Signed-off-by: Michael Adisumarta <quic_madisuma@quicinc.com>
2022-11-18 10:03:13 -08:00
qctecmdr
72c459559a Merge "wifi: cfg80211: avoid nontransmitted BSS list corruption" 2022-11-16 17:41:20 -08:00
Balaji Pothunoori
d67ce86e48 wifi: cfg80211: fix BSS refcounting bugs
There are multiple refcounting bugs related to multi-BSSID:
 - In bss_ref_get(), if the BSS has a hidden_beacon_bss, then
   the bss pointer is overwritten before checking for the
   transmitted BSS, which is clearly wrong. Fix this by using
   the bss_from_pub() macro.

 - In cfg80211_bss_update() we copy the transmitted_bss pointer
   from tmp into new, but then if we release new, we'll unref
   it erroneously. We already set the pointer and ref it, but
   need to NULL it since it was copied from the tmp data.

 - In cfg80211_inform_single_bss_data(), if adding to the non-
   transmitted list fails, we unlink the BSS and yet still we
   return it, but this results in returning an entry without
   a reference. We shouldn't return it anyway if it was broken
   enough to not get added there.

This fixes CVE-2022-42720.

Reported-by: Sönke Huster <shuster@seemoo.tu-darmstadt.de>
Tested-by: Sönke Huster <shuster@seemoo.tu-darmstadt.de>
Fixes: a3584f56de ("cfg80211: Properly track transmitting and non-transmitting BSS")
Link: https://lore.kernel.org/lkml/20221013175147.168042993@linuxfoundation.org/
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Change-Id: If6ed330dc65fdf387ee8584b5a69840242edf5cc
Signed-off-by: Balaji Pothunoori <quic_bpothuno@quicinc.com>
2022-11-15 21:48:35 -08:00
qctecmdr
9a078efa80 Merge "wifi: cfg80211: fix u8 overflow in cfg80211_update_notlisted_nontrans()" 2022-11-13 22:15:20 -08:00
qctecmdr
48ca3a82d1 Merge "qcedev: check num_fds during unmap" 2022-11-13 22:15:20 -08:00
Srikanth Marepalli
060227f10d wifi: cfg80211: avoid nontransmitted BSS list corruption
If a non-transmitted BSS shares enough information (both
SSID and BSSID!) with another non-transmitted BSS of a
different AP, then we can find and update it, and then
try to add it to the non-transmitted BSS list. We do a
search for it on the transmitted BSS, but if it's not
there (but belongs to another transmitted BSS), the list
gets corrupted.

Since this is an erroneous situation, simply fail the
list insertion in this case and free the non-transmitted
BSS.

This fixes CVE-2022-42721.

Reported-by: Sönke Huster <shuster@seemoo.tu-darmstadt.de>
Tested-by: Sönke Huster <shuster@seemoo.tu-darmstadt.de>
Fixes: 0b8fb8235b ("cfg80211: Parsing of Multiple BSSID information in scanning")
Link: https://lore.kernel.org/all/20221013175145.382242160@linuxfoundation.org/
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Git-commit: bcca852027e5878aec911a347407ecc88d6fff7f
Git-repo: https://android.googlesource.com/kernel/common

Change-Id: Icb2106b5ac5ff5e3ecb50bd09440bce5560fbb05
Signed-off-by: Srikanth Marepalli <quic_srimarep@quicinc.com>
2022-11-10 05:25:55 -08:00
Johannes Berg
cfac1c3466 wifi: cfg80211: fix u8 overflow in cfg80211_update_notlisted_nontrans()
In the copy code of the elements, we do the following calculation
to reach the end of the MBSSID element:

	/* copy the IEs after MBSSID */
	cpy_len = mbssid[1] + 2;

This looks fine, however, cpy_len is a u8, the same as mbssid[1],
so the addition of two can overflow. In this case the subsequent
memcpy() will overflow the allocated buffer, since it copies 256
bytes too much due to the way the allocation and memcpy() sizes
are calculated.

Fix this by using size_t for the cpy_len variable.

This fixes CVE-2022-41674.

Reported-by: Soenke Huster <shuster@seemoo.tu-darmstadt.de>
Tested-by: Soenke Huster <shuster@seemoo.tu-darmstadt.de>
Fixes: 0b8fb8235b ("cfg80211: Parsing of Multiple BSSID information in scanning")
Link: https://lore.kernel.org/lkml/20221013175147.067414219@linuxfoundation.org/
Reviewed-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Git-commit: aebe9f4639b13a1f4e9a6b42cdd2e38c617b442d
Git-repo: https://android.googlesource.com/kernel/common

Change-Id: If6ed330dc65fdf387ee8584b5a69840242edf5cf
Signed-off-by: Vulupala Shashank Reddy<quic_vulupa@quicinc.com>
2022-11-10 01:58:29 -08:00
qctecmdr
9026bcc916 Merge "cnss2: Add support for handling AFC memory request from FW" 2022-11-09 23:11:58 -08:00
Will Huang
b4ea3e4d0a cnss2: Add support for handling AFC memory request from FW
Add APIs for handling AFC memory request from FW:
cnss_send_buffer_to_afcmem() and cnss_reset_afcmem().

cnss_send_buffer_to_afcmem() will be called if receive valid AFC
response data, cnss_reset_afcmem() will be called if receive
invalid AFC response data. After memory copy done, another WMI
command will indicate FW ready to read.

Add FW memory type QMI_WLFW_AFC_MEM_V01.

Change-Id: I34b9add3d7721d778e5474d9b11ad64adb4f04f0
CRs-Fixed: 3223607
Signed-off-by: Balamurugan Mahalingam <bmahalin@codeaurora.org>
Signed-off-by: Will Huang <quic_wilhuang@quicinc.com>
2022-11-08 18:06:43 +08:00