Untrusted application can attach to guestOS and staticPD if it can
somehow make INIT IOCTL call with ATTACH flag. This is a potential
security issue as the untrusted application can crash guestOS or
staticPD. Restrict attach to guestOS or staticPD request if request
is being made using non-secure device node.
Change-Id: I322c7b242fd0baaf1c1bce2d83b992fecb0ca593
Acked-by: Ekansh Gupta <ekangupt@qti.qualcomm.com>
Signed-off-by: Vamsi Krishna Gattupalli <quic_vgattupa@quicinc.com>
Avoiding null pointer dereference in mhi_uci_client_open API in uci layer
by changing the location of the condition check for uci_handle.
Change-Id: If2cc99f47f4c5d05d0df4a5b4900894683f7c8d1
Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
Some QoS blocks require voting for BCMs before their registers can be
accessed, since they require clocks and regulators controlled by BCM.
Vote for these BCMs before configuring QoS during probe.
Change-Id: I6aaf8a963f4ace12eb639b61ae0ae45ac045d849
Signed-off-by: Odelu Kukatla <okukatla@codeaurora.org>
Some QoS blocks require voting for BCMs before their registers can be
accessed, since they require clocks and regulators controlled by BCM.
Change-Id: Ic93d224c7dc56c8e56d527179a0c2d1e888e3822
Signed-off-by: Mike Tipton <mdtipton@codeaurora.org>
Signed-off-by: Odelu Kukatla <okukatla@codeaurora.org>
BCL requires that respective Central Broadcast register
be programed from TZ. This programing happens only
when zap shader firmware load is successful. Zap firmware
load can fail in boot up path, but we are setting
bcl_enabled to true before firmware load is successful.
This is not correct. BCL should be enabled only after
respective register programing is done from TZ side.
Otherwise gmu goes to error state when ACK from BCL is
expected during boot. Enable BCL only after we
successfully complete first boot to ensure that Central
Broadcast register is programed before enabling BCL.
Change-Id: I6267c943262cc0448fa77d29d5ae6e8f5cae7e9f
Signed-off-by: Pranav Patel <quic_pranavp@quicinc.com>
Add additional placeholder for sdr sensors to make common TS list
compatible with all the targets.
Change-Id: I566cf7b212b64e52ed788f73ff097b9327e6874e
Signed-off-by: Priyansh Jain <quic_priyjain@quicinc.com>
Add new IOCTL to get external router mode and ipv6 prefix
addr and mask. Define new structs and enum to hold this
ext route info.
Change-Id: I3ef9ebdb0c33c5deeda27b340c1261e08a032b7c
Signed-off-by: Michael Adisumarta <quic_madisuma@quicinc.com>
Recovery timer is used to detect FW_READY timeout during
SSR/PDR recovery and assert when expires. In case of
gracefull shutdown avoid starting recovery timer.
Change-Id: Ieae2ae1d52db6648c1639ff5fca8fa9f004a6d7f
Signed-off-by: Naman Padhiar <quic_npadhiar@quicinc.com>
Add soc-id entry for KATMAI/KATMAIP (msm-id: 575/576) to the list
of soc-ids supported.
Change-Id: Iabc5c65f3020d1d12f73ed80b220a06ac6466553
Signed-off-by: Chetan Chinnadagudihundi Ravindranath <quic_cchinnad@quicinc.com>
For HSP link down issue on CPE platform, because CPE NTN3 pcie switch
separates pcie link between RC and EP into two pcie buses,
RC0<->USP and DSP<->EP, so we should take care of this case on pcie
link training, make code change as following:
1. do link training RC0<->USP first and then do link training for
DSP<->EP
2. link training of DSP<->EP need more time to complete.
From test result, 100ms is not enough, 200ms is ok.
Change-Id: I0f36fc19ab1c6b90132596359c7b158fde7d3e22
Signed-off-by: Harrison Meng <quic_hmeng@quicinc.com>
When IO lines not in good state we are not doing cancel
and abort for non-rtl SE's, due to this we are seeing
unexpected errors from QUP. To solve this added changes
like rtl based flag, to proceed further sequence for non-rtl
based SE's.
Change-Id: I4dac0bf97ff0077bf18b806446de95eab40a2e1f
Signed-off-by: Anil Veshala Veshala <quic_aveshala@quicinc.com>
a validation added to check whether retrieved struct smcinvoke_file_data
inside the function get_server_id belongs to g_smcinvoke_fops or not.
Change-Id: If949889a764775200650a8d0b744359c0611b576
Signed-off-by: Pavan Bobba <quic_pav@quicinc.com>
Multiple clients racing with each other to register with the same label
could possibly succeed in doing so, contrary to design, which mandates
that only one client should be able to register with a given label, and
others should receive an -EBUSY. This is due to the below two reasons:
1. Checking for a label's cap_table_entry in the global
gh_msgq_cap_list and then allocating one if none is found is
not an atomic operation all under one spinlock.
2. The cap_entry_lock spinlock protecting the cap_table_entry is
relinquished prematurely, before the client_desc can be set in
cap_table_entry.
Two clients attempting to register by passing in the same label could
potentially each find no corresponding cap_table_entry and then each
proceed to allocate a new entry (adding it to the global
gh_msgq_cap_list). Continuing with this scenario, both freshly-allocated
cap_table_entry's will have their client_desc set to NULL and so will
have a client_desc allocated and return successfully.
Fix this by:
1. Bringing the cap_table_entry existence check and allocation steps
under the same spinlock, thereby preventing further allocations if
the cap_table_entry already exists.
2. Removing the spinlock from within gh_mgsq_alloc_entry() because it is
now being called with the same spinlock held.
3. Extending cap_entry_lock's critical section to cover the allocation
of client_desc as well. This will prevent the overwriting of
client_desc in the case of a race condition where two clients obtain
the same cap_table_entry and both of them find their client_desc's to
be NULL and then each proceed to allocate one and assign it to the
same cap_table_entry one after the other.
4. Changing the allocation flags to GFP_ATOMIC to avoid sleeping within
a critical section.
Change-Id: I99072d466e91151302a50e5f35f2b2a8d5ee5c48
Signed-off-by: Guru Das Srinagesh <gurus@codeaurora.org>
Signed-off-by: Kishor Krishna Bhat <quic_kishkris@quicinc.com>
The following patches are reverted since dequeuing all requests
in gserial_disconnect() with interrupts disabled is resulting
in stability issues. The original problem of end transfer timeout
in DWC3 driver is not completely solved with dequeuing the requests,
so this patch does not introduce any regressions.
f331451 usb: gadget: u_serial: Remove extra list operation from
gs_start_tx.
fb8bcea usb: gadget: u_serial: Rectify the list operations is
rx/tx path.
83626bc usb: gadget: u_serial: Dequeue request on gserial_disconnect.
Change-Id: Ic8a8cbaf295d1cb335b463743814a289c89069b8
Signed-off-by: Uttkarsh Aggarwal <quic_uaggarwa@quicinc.com>
In the connect_pipe() failure path, the allocated pipe is freed but
the pointer variable is not reset creating a dangling pointer and
potential UaF if it is later accessed. Fix it by assigning it to NULL.
Change-Id: Iae9fb05ce819fc94839180762393fa18aaecdd60
Signed-off-by: Jack Pham <quic_jackp@quicinc.com>
kmalloc returns out of memory in low memory conditions even if memory
is available in non-contiguous manner. This results in failure to
submit commands to ringbuffer. Use kvmalloc in place of kmalloc so
that when kmalloc fails in low memory conditions, commands can be
submitted if vmalloc can provide enough memory.
Change-Id: If6a20e35983982b5c0888e5f7dabecfa8c026bcb
Signed-off-by: Pranav Patel <quic_pranavp@quicinc.com>
Remove IDs from hh_rm_call_idr in failure paths of hh_rm_call().
Change-Id: I2e2817bdd22f570ebb299ceebed0677817815194
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
Currently gpuaddr_in_range() accepts only the gpuaddr & returns
true if it lies in valid range. But this does not mean that the
entire buffer is within range.
Modify the function to accept size as a parameter and check that
both starting & ending points of buffer lie within mmu range.
Change-Id: I1d722295b9a27e746bfdb6d3bf409ffe722193cb
Signed-off-by: Rohan Sethi <rohsethi@codeaurora.org>