Commit graph

907,392 commits

Author SHA1 Message Date
Vamsi Krishna Gattupalli
ccb839ea48 msm: ADSPRPC: Restrict untrusted applications from attaching to GuestOS
Untrusted application can attach to guestOS and staticPD if it can
somehow make INIT IOCTL call with ATTACH flag. This is a potential
security issue as the untrusted application can crash guestOS or
staticPD. Restrict attach to guestOS or staticPD request if request
is being made using non-secure device node.

Change-Id: I322c7b242fd0baaf1c1bce2d83b992fecb0ca593
Acked-by: Ekansh Gupta <ekangupt@qti.qualcomm.com>
Signed-off-by: Vamsi Krishna Gattupalli <quic_vgattupa@quicinc.com>
2022-06-26 22:33:35 -07:00
qctecmdr
50e706ca69 Merge "msm: kgsl: Enable BCL only after first boot is done" 2022-06-24 06:14:37 -07:00
qctecmdr
582043ac51 Merge "msm: mhi_dev: Avoiding null pointer dereference in uci layer" 2022-06-24 06:14:36 -07:00
Sai Chaitanya Kaveti
1bcfee37cb msm: mhi_dev: Avoiding null pointer dereference in uci layer
Avoiding null pointer dereference in mhi_uci_client_open API in uci layer
by changing the location of the condition check for uci_handle.

Change-Id: If2cc99f47f4c5d05d0df4a5b4900894683f7c8d1
Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
2022-06-23 23:21:50 -07:00
qctecmdr
8a6ca28bfc Merge "interconnect: qcom: Enable BCMs needed for QoS configuration for Shima" 2022-06-23 21:42:30 -07:00
qctecmdr
37eeb35df8 Merge "dt-bindings: thermal: Add new sdr sensor placeholders" 2022-06-23 21:42:29 -07:00
qctecmdr
6b5b8c5949 Merge "drivers: thermal: qmi_sensor: Add new sdr thermistors" 2022-06-23 21:42:28 -07:00
Taniya Das
a7cdb778e4 clk: qcom: gpucc: Update the frequency for GPU core clock for blair
Add support for 700MHz for GPUCC core clock.

Change-Id: Ieb1e5514df0c00f3c6d0eb3cf8d9baccd214ba07
Signed-off-by: Taniya Das <quic_tdas@quicinc.com>
2022-06-23 05:33:03 -07:00
Odelu Kukatla
d813843cc0 interconnect: qcom: Enable BCMs needed for QoS configuration for Shima
Some QoS blocks require voting for BCMs before their registers can be
accessed, since they require clocks and regulators controlled by BCM.
Vote for these BCMs before configuring QoS during probe.

Change-Id: I6aaf8a963f4ace12eb639b61ae0ae45ac045d849
Signed-off-by: Odelu Kukatla <okukatla@codeaurora.org>
2022-06-23 00:38:37 -07:00
Mike Tipton
937337ff1b interconnect: qcom: Add support for enabling BCMs needed for QoS
Some QoS blocks require voting for BCMs before their registers can be
accessed, since they require clocks and regulators controlled by BCM.

Change-Id: Ic93d224c7dc56c8e56d527179a0c2d1e888e3822
Signed-off-by: Mike Tipton <mdtipton@codeaurora.org>
Signed-off-by: Odelu Kukatla <okukatla@codeaurora.org>
2022-06-23 00:37:29 -07:00
Pranav Patel
cb0163949d msm: kgsl: Enable BCL only after first boot is done
BCL requires that respective Central Broadcast register
be programed from TZ. This programing happens only
when zap shader firmware load is successful. Zap firmware
load can fail in boot up path, but we are setting
bcl_enabled to true before firmware load is successful.
This is not correct. BCL should be enabled only after
respective register programing is done from TZ side.
Otherwise gmu goes to error state when ACK from BCL is
expected during boot. Enable BCL only after we
successfully complete first boot to ensure that Central
Broadcast register is programed before enabling BCL.

Change-Id: I6267c943262cc0448fa77d29d5ae6e8f5cae7e9f
Signed-off-by: Pranav Patel <quic_pranavp@quicinc.com>
2022-06-21 17:47:00 +05:30
Priyansh Jain
5ce222095f dt-bindings: thermal: Add new sdr sensor placeholders
Add additional placeholder for sdr sensors to make common TS list
compatible with all the targets.

Change-Id: I566cf7b212b64e52ed788f73ff097b9327e6874e
Signed-off-by: Priyansh Jain <quic_priyjain@quicinc.com>
2022-06-21 02:24:22 -07:00
Priyansh Jain
4bd50933ca drivers: thermal: qmi_sensor: Add new sdr thermistors
Add new sdr thermistors support.

Change-Id: Ie23752dc1275a5e36d5f4bebbde80052b2c8242b
Signed-off-by: Priyansh Jain <quic_priyjain@quicinc.com>
2022-06-21 14:48:46 +05:30
qctecmdr
38d03da9dd Merge "msm: ipa3: Add support for External Router Mode FR" 2022-06-13 14:32:36 -07:00
qctecmdr
b64fdf367a Merge "smcinvoke : file private data validation which is sent by userspace" 2022-06-10 00:20:58 -07:00
qctecmdr
8a2c8ccf67 Merge "icnss2: Do not start recovery timer on gracefull shutdown" 2022-06-09 20:36:48 -07:00
Michael Adisumarta
ab6b79b7aa msm: ipa3: Add support for External Router Mode FR
Add new IOCTL to get external router mode and ipv6 prefix
addr and mask. Define new structs and enum to hold this
ext route info.

Change-Id: I3ef9ebdb0c33c5deeda27b340c1261e08a032b7c
Signed-off-by: Michael Adisumarta <quic_madisuma@quicinc.com>
2022-06-09 10:37:49 -07:00
qctecmdr
86029e5e8d Merge "i2c: i2c-msm-geni: add rtl based changes" 2022-06-09 04:37:31 -07:00
qctecmdr
51b9a1958f Merge "perf: arm: Implement perf counter for 32bit arm" 2022-06-09 04:37:29 -07:00
Naman Padhiar
f64e093709 icnss2: Do not start recovery timer on gracefull shutdown
Recovery timer is used to detect FW_READY timeout during
SSR/PDR recovery and assert when expires. In case of
gracefull shutdown avoid starting recovery timer.

Change-Id: Ieae2ae1d52db6648c1639ff5fca8fa9f004a6d7f
Signed-off-by: Naman Padhiar <quic_npadhiar@quicinc.com>
2022-06-08 22:55:14 -07:00
Sandeepkumar Yenugula
14d7d37185 perf: arm: Implement perf counter for 32bit arm
Implement perf trace counter for arm 32bit.

Change-Id: I9d783ded2a6a9d815fcf611b1529786d1971a2b6
Signed-off-by: Sandeepkumar Yenugula<quic_syenugul@quicinc.com>
Signed-off-by: Ishank Rawat <quic_irawat@quicinc.com>
2022-06-08 22:21:05 -07:00
Chetan Chinnadagudihundi Ravindranath
26985a67c5 soc: qcom: socinfo: Add the soc-id for KATMAI/KATMAIP
Add soc-id entry for KATMAI/KATMAIP (msm-id: 575/576) to the list
of soc-ids supported.

Change-Id: Iabc5c65f3020d1d12f73ed80b220a06ac6466553
Signed-off-by: Chetan Chinnadagudihundi Ravindranath <quic_cchinnad@quicinc.com>
2022-06-08 06:53:16 -07:00
Harrison Meng
04108b8378 pci: msm: Extend sleep time when reset i2c client
For HSP link down issue on CPE platform, because CPE NTN3 pcie switch
separates pcie link between RC and EP into two pcie buses,
RC0<->USP and DSP<->EP, so we should take care of this case on pcie
link training, make code change as following:
1. do link training RC0<->USP first and then do link training for
   DSP<->EP
2. link training of DSP<->EP need more time to complete.
From test result, 100ms is not enough, 200ms is ok.

Change-Id: I0f36fc19ab1c6b90132596359c7b158fde7d3e22
Signed-off-by: Harrison Meng <quic_hmeng@quicinc.com>
2022-06-07 07:03:17 -07:00
Anil Veshala Veshala
4f676b6913 i2c: i2c-msm-geni: add rtl based changes
When IO lines not in good state we are not doing cancel
and abort for non-rtl SE's, due to this we are seeing
unexpected errors from QUP. To solve this added changes
like rtl based flag, to proceed further sequence for non-rtl
based SE's.

Change-Id: I4dac0bf97ff0077bf18b806446de95eab40a2e1f
Signed-off-by: Anil Veshala Veshala <quic_aveshala@quicinc.com>
2022-06-06 23:19:04 -07:00
Pavan Bobba
2fa26c84e7 smcinvoke : file private data validation which is sent by userspace
a validation added to check  whether retrieved struct smcinvoke_file_data
inside the function get_server_id belongs to g_smcinvoke_fops or not.

Change-Id: If949889a764775200650a8d0b744359c0611b576
Signed-off-by: Pavan Bobba <quic_pav@quicinc.com>
2022-06-06 04:24:07 -07:00
qctecmdr
f094cbc663 Merge "Merge android11-5.4.180+ (e7792e2) into msm-5.4" 2022-06-03 06:42:43 -07:00
qctecmdr
26e6ab84e1 Merge "usb: gadget: u_serial: Don't dequeue requests in gserial_disconnect" 2022-06-02 05:43:09 -07:00
qctecmdr
2e1743bcba Merge "haven: hh_rm_core: fix ID leaking" 2022-06-01 05:08:31 -07:00
Guru Das Srinagesh
2387accd22 haven: gh_msgq: Disallow multiple registrations with same label
Multiple clients racing with each other to register with the same label
could possibly succeed in doing so, contrary to design, which mandates
that only one client should be able to register with a given label, and
others should receive an -EBUSY. This is due to the below two reasons:
  1. Checking for a label's cap_table_entry in the global
     gh_msgq_cap_list and then allocating one if none is found is
     not an atomic operation all under one spinlock.
  2. The cap_entry_lock spinlock protecting the cap_table_entry is
     relinquished prematurely, before the client_desc can be set in
     cap_table_entry.
Two clients attempting to register by passing in the same label could
potentially each find no corresponding cap_table_entry and then each
proceed to allocate a new entry (adding it to the global
gh_msgq_cap_list). Continuing with this scenario, both freshly-allocated
cap_table_entry's will have their client_desc set to NULL and so will
have a client_desc allocated and return successfully.
Fix this by:
1. Bringing the cap_table_entry existence check and allocation steps
   under the same spinlock, thereby preventing further allocations if
   the cap_table_entry already exists.
2. Removing the spinlock from within gh_mgsq_alloc_entry() because it is
   now being called with the same spinlock held.
3. Extending cap_entry_lock's critical section to cover the allocation
   of client_desc as well. This will prevent the overwriting of
   client_desc in the case of a race condition where two clients obtain
   the same cap_table_entry and both of them find their client_desc's to
   be NULL and then each proceed to allocate one and assign it to the
   same cap_table_entry one after the other.
4. Changing the allocation flags to GFP_ATOMIC to avoid sleeping within
   a critical section.

Change-Id: I99072d466e91151302a50e5f35f2b2a8d5ee5c48
Signed-off-by: Guru Das Srinagesh <gurus@codeaurora.org>
Signed-off-by: Kishor Krishna Bhat <quic_kishkris@quicinc.com>
2022-05-31 04:03:34 -07:00
Srinivasarao Pathipati
eb03a71570 Merge android11-5.4.180+ (e7792e2) into msm-5.4
* refs/heads/tmp-e7792e2:
  BACKPORT: scsi: ufs: Resume ufs host before accessing ufs device
  BACKPORT: can: ems_usb: ems_usb_start_xmit(): fix double dev_kfree_skb() in error path
  ANDROID: ABI: Added symbols for allwinner
  BACKPORT: can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path
  BACKPORT: esp: Fix possible buffer overflow in ESP transformation
  ANDROID: ABI: Update allowed list for QCOM
  ANDROID: dm-bow: Protect Ranges fetched and erased from the RB tree
  BACKPORT: staging: ion: Prevent incorrect reference counting behavour
  FROMGIT: net: fix wrong network header length
  ANDROID: fix KCFLAGS override by __ANDROID_COMMON_KERNEL__
  ANDROID: Add flag to indicate compiling against ACK
  BACKPORT: net/packet: fix slab-out-of-bounds access in packet_recvmsg()
  BACKPORT: block: Add a helper to validate the block size
  BACKPORT: virtio-blk: Use blk_validate_block_size() to validate block size
  BACKPORT: fuse: fix pipe buffer lifetime for direct_io
  ANDROID: ABI: Update allowed list for galaxy

 Conflicts:
	build.config.common
	drivers/scsi/ufs/ufs-sysfs.c

Change-Id: I7dc73e85ca1412a1d00422fd4a62724f65581aec
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2022-05-30 12:43:51 +05:30
qctecmdr
b6845fdd76 Merge "msm: kgsl: use kvmalloc for ringbuffer submission" 2022-05-29 23:00:24 -07:00
qctecmdr
1a00719a8e Merge "defconfig: sdxlemur: Enable IPv6 NAT" 2022-05-26 16:05:38 -07:00
Uttkarsh Aggarwal
e48ead6773 usb: gadget: u_serial: Don't dequeue requests in gserial_disconnect
The following patches are reverted since dequeuing all requests
in gserial_disconnect() with interrupts disabled is resulting
in stability issues. The original problem of end transfer timeout
in DWC3 driver is not completely solved with dequeuing the requests,
so this patch does not introduce any regressions.

f331451 usb: gadget: u_serial: Remove extra list operation from
gs_start_tx.

fb8bcea usb: gadget: u_serial: Rectify the list operations is
rx/tx path.

83626bc usb: gadget: u_serial: Dequeue request on gserial_disconnect.

Change-Id: Ic8a8cbaf295d1cb335b463743814a289c89069b8
Signed-off-by: Uttkarsh Aggarwal <quic_uaggarwa@quicinc.com>
2022-05-26 22:49:58 +05:30
Jack Pham
0a91646856 platform: msm: usb_bam: Fix potential use-after-free in connect_pipe
In the connect_pipe() failure path, the allocated pipe is freed but
the pointer variable is not reset creating a dangling pointer and
potential UaF if it is later accessed.  Fix it by assigning it to NULL.

Change-Id: Iae9fb05ce819fc94839180762393fa18aaecdd60
Signed-off-by: Jack Pham <quic_jackp@quicinc.com>
2022-05-25 23:34:12 -07:00
Pranav Patel
93f6fdbe31 msm: kgsl: use kvmalloc for ringbuffer submission
kmalloc returns out of memory in low memory conditions even if memory
is available in non-contiguous manner. This results in failure to
submit commands to ringbuffer. Use kvmalloc in place of kmalloc so
that when kmalloc fails in low memory conditions, commands can be
submitted if vmalloc can provide enough memory.

Change-Id: If6a20e35983982b5c0888e5f7dabecfa8c026bcb
Signed-off-by: Pranav Patel <quic_pranavp@quicinc.com>
2022-05-25 04:37:07 -07:00
qctecmdr
26872d7115 Merge "mmc: sdhci-msm: configure sdcc clocks core memory" 2022-05-24 22:24:51 -07:00
James Wyatt Guidry
644e9d88eb defconfig: sdxlemur: Enable IPv6 NAT
- Enabled IPv6 NAT for sdxlemur

Change-Id: Iabb6340343f00e7a8d4870148f84b74250632626
Signed-off-by: James Wyatt Guidry <quic_jguidry@quicinc.com>
2022-05-24 13:41:21 -07:00
Srinivasarao Pathipati
d0a7eee654 haven: hh_rm_core: fix ID leaking
Remove IDs from hh_rm_call_idr in failure paths of hh_rm_call().

Change-Id: I2e2817bdd22f570ebb299ceebed0677817815194
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2022-05-24 16:53:49 +05:30
qctecmdr
3497dfc249 Merge "i2c:i2c-msm-geni: Updating last mark busy failure case" 2022-05-23 23:30:15 -07:00
qctecmdr
77caecb902 Merge "msm: kgsl: Fix gpuaddr_in_range() to check upper bound" 2022-05-18 21:50:08 -07:00
Rohan Sethi
ac7349dd70 msm: kgsl: Fix gpuaddr_in_range() to check upper bound
Currently gpuaddr_in_range() accepts only the gpuaddr & returns
true if it lies in valid range. But this does not mean that the
entire buffer is within range.
Modify the function to accept size as a parameter and check that
both starting & ending points of buffer lie within mmu range.

Change-Id: I1d722295b9a27e746bfdb6d3bf409ffe722193cb
Signed-off-by: Rohan Sethi <rohsethi@codeaurora.org>
2022-05-18 17:58:41 +05:30
qctecmdr
9f84500259 Merge "i2c-msm-genic: To remove unsupported %: in format string" 2022-05-18 00:56:04 -07:00
qctecmdr
215122559e Merge "smcinvoke: Add explicit cache flush during CB req from TZ" 2022-05-18 00:56:04 -07:00
qctecmdr
c6c2cbd621 Merge "scsi: ufs: fix deadlock between resume and eh_work" 2022-05-18 00:56:03 -07:00
qctecmdr
778d5c01eb Merge "i2c: i2c-msm-geni: Reset i2c GPIOs using FORCE_DEFAULT" 2022-05-18 00:56:02 -07:00
qctecmdr
5177e06269 Merge "i2c: i2c-msm-geni: Handle NACK interrupt as an error condition" 2022-05-18 00:56:01 -07:00
qctecmdr
b6998ed934 Merge "msm: ADSPRPC: Update unsigned pd support on cDSP from kernel" 2022-05-18 00:56:01 -07:00
qctecmdr
422c9d10eb Merge "clk: qcom: gdsc-regulator: Add debug logs for gdsc set mode" 2022-05-18 00:56:00 -07:00
qctecmdr
2eefb7690f Merge "cnss2: Add change to update 128KB prealloc reserve pool size to 5" 2022-05-17 17:07:47 -07:00
qctecmdr
c000754ee2 Merge "msm: ep_pcie: Avoid releasing resources if pcie-perst-enum is set" 2022-05-17 17:07:46 -07:00