Commit graph

899,669 commits

Author SHA1 Message Date
Kiran Gunda
d0bd65b0a8 uapi: Add UAPI headers for slatecom_interface driver
Add slatecom_interface header file in gen_headers to make it
accessible from userspace modules who uses Android.bp files
for compilation.

Change-Id: Ie298ec28983c16999d941ee8667e2dd7b5c3db22
Signed-off-by: Kiran Gunda <kgunda@codeaurora.org>
2021-09-07 23:57:54 -07:00
qctecmdr
3b06ec126c Merge "dma-buf: WARN on dmabuf release with pending attachments" 2021-09-06 06:07:41 -07:00
qctecmdr
92972b0281 Merge "net: qrtr: mhi_dev: unblock any tx on mhi disconnect" 2021-09-05 22:42:26 -07:00
Charan Teja Reddy
a453bdb6a8 dma-buf: WARN on dmabuf release with pending attachments
It is expected from the clients to follow the below steps on an imported
dmabuf fd:
a) dmabuf = dma_buf_get(fd) // Get the dmabuf from fd
b) dma_buf_attach(dmabuf); // Clients attach to the dmabuf
   o Here the kernel does some slab allocations, say for
dma_buf_attachment and may be some other slab allocation in the
dmabuf->ops->attach().
c) Client may need to do dma_buf_map_attachment().
d) Accordingly dma_buf_unmap_attachment() should be called.
e) dma_buf_detach () // Clients detach to the dmabuf.
   o Here the slab allocations made in b) are freed.
f) dma_buf_put(dmabuf) // Can free the dmabuf if it is the last
reference.

Now say an erroneous client failed at step c) above thus it directly
called dma_buf_put(), step f) above. Considering that it may be the last
reference to the dmabuf, buffer will be freed with pending attachments
left to the dmabuf which can show up as the 'memory leak'. This should
at least be reported as the WARN().

Change-Id: Ia58b41500be943fe3c2da3eb0f5480ae99715de2
Signed-off-by: Charan Teja Reddy <charante@codeaurora.org>
Reviewed-by: Christian König <christian.koenig@amd.com>
Link: https://patchwork.freedesktop.org/patch/msgid/1627043468-16381-1-git-send-email-charante@codeaurora.org
Signed-off-by: Christian König <christian.koenig@amd.com>
2021-09-05 22:11:56 -07:00
qctecmdr
2116ac0ac7 Merge "drivers: pinctrl: qcom: Update GPIO to PDC mapping for shima" 2021-09-04 15:05:49 -07:00
qctecmdr
566940b7dd Merge "drivers: pinctrl: qcom: Update GPIO to PDC mapping for lahaina" 2021-09-04 15:05:49 -07:00
qctecmdr
1c5a6f6f48 Merge "defconfig: Enable host mode compliance config on sdxlemur" 2021-09-04 08:49:29 -07:00
qctecmdr
680693843c Merge "BACKPORT: blk-mq: fix is_flush_rq" 2021-09-04 08:49:28 -07:00
Elson Roy Serrao
08912906b1 defconfig: Enable host mode compliance config on sdxlemur
This change enables the host mode compliance config on sdxlemur.

Change-Id: Ied9e01d73fec84918ece143b8c54b4b30f9045bc
Signed-off-by: Elson Roy Serrao <eserrao@codeaurora.org>
2021-09-03 11:36:12 -07:00
Tushar Nimkar
92234af10e drivers: pinctrl: qcom: Update GPIO to PDC mapping for shima
This change update GPIO to PDC mapping.

Change-Id: Ic6a5208984e5139558dcf7e8a8445e8013878ba6
Signed-off-by: Tushar Nimkar <tnimkar@codeaurora.org>
2021-09-03 08:18:11 -07:00
Tushar Nimkar
4138cd8006 drivers: pinctrl: qcom: Update GPIO to PDC mapping for lahaina
This patch updates gpio to pdc mapping.

Change-Id: I41f788d2c5a207820299375f871d28fd1ee6de18
Signed-off-by: Tushar Nimkar <tnimkar@codeaurora.org>
2021-09-03 05:34:28 -07:00
Ming Lei
db5e1fbf5e BACKPORT: blk-mq: fix is_flush_rq
is_flush_rq() is called from bt_iter()/bt_tags_iter(), and runs the
following check:

	hctx->fq->flush_rq == req

but the passed hctx from bt_iter()/bt_tags_iter() may be NULL because:

1) memory re-order in blk_mq_rq_ctx_init():

	rq->mq_hctx = data->hctx;
	...
	refcount_set(&rq->ref, 1);

OR

2) tag re-use and ->rqs[] isn't updated with new request.

Fix the issue by re-writing is_flush_rq() as:

	return rq->end_io == flush_end_io;

which turns out simpler to follow and immune to data race since we have
ordered WRITE rq->end_io and refcount_set(&rq->ref, 1).

Fixes: 2e315dc07df0 ("blk-mq: grab rq->refcount before calling ->fn in
    blk_mq_tagset_busy_iter")
Cc: "Blank-Burian, Markus, Dr." <blankburian@uni-muenster.de>
Cc: Yufen Yu <yuyufen@huawei.com>
Signed-off-by: Ming Lei <ming.lei@redhat.com>.

Bug: 197804811
Change-Id: I4c19fc2c7d39235b0e95a622f26646a353a19ee9
[Upstream: cherry picked from commit a9ed27a764156929efe714033edb3e9023c5f321]
[Pradeep: Resolved conflicts in block/blk.h]
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
Git-commit: ec1b6ab9fe
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
2021-09-03 05:21:21 -07:00
Ming Lei
45f431f698 BACKPORT: blk-mq: clearing flush request reference in tags->rqs[]
Before we free request queue, clearing flush request reference in
tags->rqs[], so that potential UAF can be avoided.

Based on one patch written by David Jeffery.

Tested-by: John Garry <john.garry@huawei.com>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Reviewed-by: David Jeffery <djeffery@redhat.com>
Signed-off-by: Ming Lei <ming.lei@redhat.com>.

Bug: 197804811
Change-Id: I9600626e807a4eed546c21be808fabed2a9db9b1
[Upstream: cherry picked from commit 364b61818f65045479e42e76ed8dd6f051778280]
[Todd: refactored to avoid breaking KMI ]
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
Signed-off-by: Todd Kjos <tkjos@google.com>
Git-commit: c9a3b51b07
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
2021-09-03 05:20:30 -07:00
Ming Lei
585cb1a5da BACKPORT: blk-mq: clear stale request in tags->rq[] before freeing one request pool
refcount_inc_not_zero() in bt_tags_iter() still may read one freed
request.

Fix the issue by the following approach:

1) hold a per-tags spinlock when reading ->rqs[tag] and calling
refcount_inc_not_zero in bt_tags_iter()

2) clearing stale request referred via ->rqs[tag] before freeing
request pool, the per-tags spinlock is held for clearing stale
->rq[tag]

So after we cleared stale requests, bt_tags_iter() won't observe
freed request any more, also the clearing will wait for pending
request reference.

The idea of clearing ->rqs[] is borrowed from John Garry's previous
patch and one recent David's patch.

Tested-by: John Garry <john.garry@huawei.com>
Reviewed-by: David Jeffery <djeffery@redhat.com>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Signed-off-by: Ming Lei <ming.lei@redhat.com>.

Bug: 197804811
Change-Id: If49478d7b05d3f5b0a26966ddf9ae764cf2fb6b0
[Upstream: cherry picked from commit bd63141d585bef14f4caf111f6d0e27fe2300ec6]
[Todd: refactored to avoid breaking KMI ]
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
Signed-off-by: Todd Kjos <tkjos@google.com>
Git-commit: bb96e7f45d
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
2021-09-03 05:19:17 -07:00
Ming Lei
7fe0d300ab BACKPORT: blk-mq: grab rq->refcount before calling ->fn in blk_mq_tagset_busy_iter
Grab rq->refcount before calling ->fn in blk_mq_tagset_busy_iter(), and
this way will prevent the request from being re-used when ->fn is
running. The approach is same as what we do during handling timeout.

Fix request use-after-free(UAF) related with completion race or queue
releasing:

- If one rq is referred before rq->q is frozen, then queue won't be
frozen before the request is released during iteration.

- If one rq is referred after rq->q is frozen, refcount_inc_not_zero()
will return false, and we won't iterate over this request.

However, still one request UAF not covered: refcount_inc_not_zero() may
read one freed request, and it will be handled in next patch.

Tested-by: John Garry <john.garry@huawei.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Signed-off-by: Ming Lei <ming.lei@redhat.com>.

Bug: 197804811
Change-Id: I0e431a8361d1412aaca3f7c0310780d9a9ad0db8
[Upstream: cherry picked from commit 2e315dc07df009c3e29d6926871f62a30cfae394]
[Pradeep: Resolved conflicts in block/blk-mq-tag.c]
Git-commit: a5d38e7c26
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
2021-09-03 05:17:29 -07:00
qctecmdr
c4dae24acf Merge "iommu/arm-smmu: Remove 'qcom,power-always-on' property for SMMU" 2021-09-03 04:59:02 -07:00
qctecmdr
6edc453eb7 Merge "mhi: core: Release write lock in mhi fast resume on failure" 2021-09-03 04:59:01 -07:00
qctecmdr
15dc7a3b1e Merge "mhi: core: Avoid race condition mhi channel prepare and M0 event" 2021-09-03 04:59:01 -07:00
qctecmdr
20e78130d6 Merge "serial: msm_geni_serial: Fix deadlock scenario with rx_lock" 2021-09-03 04:59:00 -07:00
qctecmdr
6860a12e0a Merge "dmaengine: gpi: Add support to dump GPI registers by clients" 2021-09-03 04:59:00 -07:00
qctecmdr
52d4b09f35 Merge "msm: kgsl: Fix list corruption in worker initialization of mem_entry" 2021-09-03 04:59:00 -07:00
qctecmdr
a129649871 Merge "soc: qcom: sdx_ext_ipc: Change GPIO configuration" 2021-09-03 04:58:59 -07:00
qctecmdr
41a30cb9e4 Merge "serial: msm_geni_serial: Avoid manual RFR flow control for OBS" 2021-09-03 04:58:59 -07:00
qctecmdr
3ab0300a3d Merge "defconfig: Disable RTL8152 config on sdxlemur" 2021-09-03 04:58:57 -07:00
qctecmdr
21c7ca2b0a Merge "i2c: i2c-msm-geni: Skip BW vote for PMIC used I2C SE node" 2021-09-03 01:09:54 -07:00
qctecmdr
bb4838a3dc Merge "defconfig: sdxlemur: Enable cnss2 driver as module" 2021-09-03 01:09:53 -07:00
Deepak Kumar Singh
ffa9b7ab83 net: qrtr: mhi_dev: unblock any tx on mhi disconnect
If host is not using qrtr channel, Tx on device may block for
availabilty of tre. If we try to unregister qrtr endpoint at
the same time it will block for endpoint lock held in Tx path.

Unblock any Tx before calling qrtr endpoint unregister.

Change-Id: I59b1a68fd2279ba6bc472a3a532102e82f094175
Signed-off-by: Deepak Kumar Singh <deesin@codeaurora.org>
2021-09-03 12:48:46 +05:30
Taniya Das
6d39fb3bdc clk: smd: rpm: Add a qup active only vote for HOLI
The pm8008 regulator is connected over I2C and the I2C device configures
its BW vote in runtime_resume and runtime_suspend. These callbacks are
triggered from the pm8008 driver's regmap calls. This means regulator
framework requests for pm8008 call into the ICC framework which in turn
calls into clock framework.
The qcom rpm smd clock providers calls into RPM message with the
the regulator framework, ICC framework and  clock framework locks held.

To prevent these deadlocks, enable the I2C qup clocks required for pm8008
by default during probe and stop requesting for clock enable/rate from the
framework.

Change-Id: Ifd486bec85a46139ccb15f4b5dbd2d43c33f3fda
Signed-off-by: Taniya Das <tdas@codeaurora.org>
2021-09-02 18:16:10 -07:00
Charan Teja Reddy
eed034c55c iommu/arm-smmu: Remove 'qcom,power-always-on' property for SMMU
The commit 8ffa6450ba ("iommu/arm-smmu: Add support for not removing
SMMU power votes") add the support for not removing the power votes of
smmu. It requires 'qcom,power-always-on' in smmu dt property to enable
this support which is currently enabled only for gpu smmu. And this
makes the clients of the SMMU to know If this dt property is enabled to
make decissions in their drivers which is not directly available.

Since there exists a device with atomic domain attached to apps smmu
which will make power resources always on, this separate dt property to
enable power resources for specific SMMU is not required. Thus remove
the 'qcom,power-always-on' property which makes power resources of
SMMU's as always ON when CONFIG_ARM_SMMU_POWER_ALWAYS_ON is enabled.

Change-Id: I2ee1d330f5c1c65474fea7d6b2a9389ae3cf085d
Signed-off-by: Charan Teja Reddy <charante@codeaurora.org>
2021-09-02 10:13:18 -07:00
Vivek Pernamitta
f793818297 mhi: core: Release write lock in mhi fast resume on failure
Release write lock when EP config space is not accessible
while mhi fast resume.

Change-Id: I7d92bca2685058db81312820471609409ddfdbbf
Signed-off-by: Vivek Pernamitta <vpernami@codeaurora.org>
2021-09-02 06:08:18 -07:00
Vivek Pernamitta
afdefc05f7 mhi: core: Avoid race condition mhi channel prepare and M0 event
There is one race condition where mhi_prepare_channel is called
in which read pointer and write pointer is set to base address
and in parallel there could be an MHI M0 transaction which
checks any pending event rings on all channels (tre_ring)
with RP != WP and rings channel DB which causes Null pointer
access. Check for MHI channel is enabled before ringing channel
doorbell. Reset mhi channel chan_ctxt, tre_ring and buf_ring
wp and rp to NULL in mhi_deinit_chan_ctxt.

Change-Id: If30908fc7fcc26f6987bd0da886bb75468a29b9e
Signed-off-by: Vivek Pernamitta <vpernami@codeaurora.org>
2021-09-02 05:18:10 -07:00
Mukesh Kumar Savaliya
90e0b5fd60 dmaengine: gpi: Add support to dump GPI registers by clients
This is to add gpi register dump support where clients can directly
call the API to dump GSI registers. This helps debug when GSI transfer
has any issue like timeout, no callback etc at the client driver and
want to dump register directly based on the need.

Change-Id: I1d9fadd51ccea166f2a486e84a8de47c134e435b
Signed-off-by: Mukesh Kumar Savaliya <msavaliy@codeaurora.org>
2021-09-02 03:33:28 -07:00
Chandana Kishori Chiluveru
ae7aa712f4 serial: msm_geni_serial: Fix deadlock scenario with rx_lock
In one core msm_geni_serial driver acquiring port->rx_lock in
stop_rx_sequencer function in process context by calling handle_rx_dma_xfer
and this process is preempted becz of core interrupt is
fired on same core and then same lock is trying to acquire
from interrupt context. This is resulting in deadlock issue.

Below are the core call stack of deadlock.

Core 0 LR: _raw_spin_lock[jt]+40 <ffffffe973336e14>
[<ffffffe971f1df5c>] handle_rx_dma_xfer+0x44
[<ffffffe971f1ec70>] msm_geni_serial_handle_isr+0x6fc
[<ffffffe971f1f6ec>] msm_geni_serial_isr+0x40
[<ffffffe9721634a8>] __handle_irq_event_percpu+0x158
[<ffffffe9721637d8>] handle_irq_event+0x60
[<ffffffe972169548>] handle_fasteoi_irq+0x128
[<ffffffe972162364>] __handle_domain_irq+0xa0
[<ffffffe971e81b64>] gic_handle_irq$7f58c51dd0f0d487d89dbb027abc57c5+0xb8
[<ffffffe971e83f84>] el1_irq+0x104
[<ffffffe971f1df68>] handle_rx_dma_xfer+0x50
[<ffffffe971f1d9ac>] stop_rx_sequencer+0x118
[<ffffffe971f20f94>] msm_geni_serial_set_termios+0x114
[<ffffffe9726dbd30>] uart_change_speed+0x58
[<ffffffe9726ddf40>] uart_set_termios$ecf561cdccc9a487f79dc2d4825d91c7+0xd4
[<ffffffe9726d033c>] tty_set_termios[jt]+0x1c0
[<ffffffe9726d0c2c>] set_termios+0x124
[<ffffffe9726d0894>] tty_mode_ioctl+0x468
[<ffffffe9726d117c>] n_tty_ioctl_helper+0xac
[<ffffffe9726cc498>] n_tty_ioctl$31461d4e731178606d28313f43c714a4[jt]+0x318
[<ffffffe9726c80cc>] tty_ioctl+0x37c
[<ffffffe9723185fc>] do_vfs_ioctl+0x384
[<ffffffe97231923c>] __arm64_sys_ioctl+0x78
[<ffffffe9720be588>] el0_svc_common[jt]+0xd8
[<ffffffe9720be4c8>] el0_svc_handler+0x68
[<ffffffe971e84e88>] ret_to_user[jt]+0x0.

Change-Id: I7e1392cd82a93b1da6b19f05dbe67b66d46193f1
Signed-off-by: Chandana Kishori Chiluveru <cchiluve@codeaurora.org>
2021-09-02 01:41:45 -07:00
Mukesh Kumar Savaliya
417537107c i2c: i2c-msm-geni: Skip BW vote for PMIC used I2C SE node
This change is a workaround change to fix the PMIC race condition
with the clock enablement. In case of PMIC txfer over i2c, I2C driver
resumes and votes for BW and clocks. The BW vote goes to RPM and that
in turn waiting for the global PMIC mutex causing race condition in
rare cases.

Hence as a workaroun, do not vote for the BW vote only for PMIC used
I2C SE instance.

Change-Id: I94c57427200a71dd2792533b1af249940b0bf03f
Signed-off-by: Mukesh Kumar Savaliya <msavaliy@codeaurora.org>
2021-09-01 02:20:28 -07:00
Will Huang
62b58f4ac2 defconfig: sdxlemur: Enable cnss2 driver as module
Enable cnss2 driver as module as requested on sdxlemur.

CRs-Fixed: 3016737
Change-Id: I0d8971c60d765fbfbee55ba1d215a2eb1ebc5659
Signed-off-by: Will Huang <wilhuang@codeaurora.org>
2021-09-01 15:19:05 +08:00
Prasanna Kumar Thoorvas Samyrao Muralidharan
0106d8287c soc: qcom: sdx_ext_ipc: Change GPIO configuration
Changing GPIO output value is not reflecting. Change GPIO pull up
configuration from pull up to no pull to reflect state change.

Change-Id: Iac636b9b601b9819ee7aac2118c1af3b0f864e86
Signed-off-by: Prasanna Kumar Thoorvas Samyrao Muralidharan <ptsm@codeaurora.org>
2021-09-01 11:43:11 +05:30
Prateek Raj Singh
528dad421a FM: mutex changes modified
Removed unrequired mutexes, and conditions.

CRs-Fixed: 3026494
Change-Id: Ib216567e80c8bf29257d11f4565865eebb8d2585
Signed-off-by: Prateek Raj Singh <pratsing@codeaurora.org>
2021-08-31 20:19:54 +05:30
qctecmdr
af0f012029 Merge "icnss2: Enable PHY processor SSR along with WPSS SSR" 2021-08-30 16:30:45 -07:00
Raihan Haider
24557c6da1 net: stmmac: Add CONFIG_IPV6 check
Add CONFIG_IPV6 check to ipv6 specific early eth code

Change-Id: Ib1b266e6da7243e4a1b2d3507b0d19b119e2ebdc
Signed-off-by: Raihan Haider<rhaider@codeaurora.org>
2021-08-30 03:46:07 -07:00
Naman Padhiar
047f485e92 icnss2: Enable PHY processor SSR along with WPSS SSR
Register notifier to get notification for restart_level
change of WPSS and send SMP2P command to FW to enable
PHY processor SSR.

Change-Id: Id0edb6ab6a44fbca83b2dbe6bad7c86e2540d865
Signed-off-by: Naman Padhiar <npadhiar@codeaurora.org>
2021-08-30 02:25:51 -07:00
Pankaj Gupta
ff332e83f2 msm: kgsl: Fix list corruption in worker initialization of mem_entry
While deferring mem_entry_put, we are doing INIT_WORK for entry.
When mem_entry_put get called again for the same entry before
execution of previous work finishes, there is a chance of corruption
in the list and cause a crash. Update kgsl_mem_entry_put_deferred
to put refcount on mem entry and trigger deferred mem entry destroy
only when refcount on entry is the last refcount.

Change-Id: I2a8533fd26e776d49ab128bdb484053ce3bc82dc
Signed-off-by: Pankaj Gupta <gpankaj@codeaurora.org>
2021-08-30 12:51:32 +05:30
Yogesh Lal
a72d52e9ec arm: defconfig: Enable SDX_EXT_IPC external ipc driver
This enables the module to help modem communicate
with external Application processor.

Change-Id: I839f00a28f668fac062157bf24437cf7605a9482
Signed-off-by: Yogesh Lal <ylal@codeaurora.org>
Signed-off-by: Rohit Agarwal <rohiagar@codeaurora.org>
2021-08-30 08:50:38 +05:30
Pavankumar Vijapur
445f77d01d drivers: qcom: sdx_ext_ipc: keep wakeup irq always on
When suspend is in progress on local processor, if
remote processor toggles GPIO to indicate a resume
event to local processor, this event may get lost.
This commit addresses this situation.

1. Add IRQF_NO_SUSPEND flag so that wakeup_irq is
not disabled during suspend on local processor.

2. Install primary handler that inform pm core
that a system wakeup event has happened. The pm
core can then abort a suspend in progress.

Change-Id: I8d84f15a118c4630bde7b9db35ffadddeb937cb9
Signed-off-by: Pavankumar Vijapur <pvijapur@codeaurora.org>
Signed-off-by: Yogesh Lal <ylal@codeaurora.org>
2021-08-30 08:49:58 +05:30
Rishi Gupta
15614d336d drivers: qcom: sdx_ext_ipc: notify remote processor wokeup
When the remote processor wants to wake up local processor
it toggles one of the GPIO. The IRQ handler at local
end will notify registered listeners about it.

Change-Id: Iccbfb7c86538c1e111c97bbe438ef5846182405e
Signed-off-by: Rishi Gupta <rishgupt@codeaurora.org>
Signed-off-by: Yogesh Lal <ylal@codeaurora.org>
2021-08-30 08:48:39 +05:30
qctecmdr
8e9243189d Merge "clk: qcom: gcc: Lower the frequency for sdxlemur from 200 to 171MHz" 2021-08-27 09:16:15 -07:00
qctecmdr
187e9a162b Merge "ARM: gic: Add support for logging interrupts in RTB" 2021-08-27 09:16:15 -07:00
qctecmdr
5581c905ea Merge "drivers: thermal: Update Ibat scaling factor for Mando" 2021-08-27 09:16:14 -07:00
qctecmdr
fb84cc3a1e Merge "usb: dwc3: debugfs: Add suppot for Enabling L1 in HS through debugfs" 2021-08-27 09:16:14 -07:00
qctecmdr
8b8860e43d Merge "icnss2: Properly handle SOC_WAKE req stuck in QMI" 2021-08-27 09:16:13 -07:00
Kamal Agrawal
097e7abad2 msm: kgsl: Print map count instead of map size
/sys/kernel/debug/kgsl/proc/<pid>/mem prints incorrect map size
in some cases. Currently, memdesc size is printed as map size.
Because of this, map size shows non-zero value even for unmapped
buffers. Since kgsl buffers can be mapped multiple times, update
the print to map count instead of map size.

Change-Id: I7970580bc3b1c9a30ca0d72d9caf89af1ce09740
Signed-off-by: Kamal Agrawal <kamaagra@codeaurora.org>
2021-08-27 05:13:36 -07:00