Add slatecom_interface header file in gen_headers to make it
accessible from userspace modules who uses Android.bp files
for compilation.
Change-Id: Ie298ec28983c16999d941ee8667e2dd7b5c3db22
Signed-off-by: Kiran Gunda <kgunda@codeaurora.org>
It is expected from the clients to follow the below steps on an imported
dmabuf fd:
a) dmabuf = dma_buf_get(fd) // Get the dmabuf from fd
b) dma_buf_attach(dmabuf); // Clients attach to the dmabuf
o Here the kernel does some slab allocations, say for
dma_buf_attachment and may be some other slab allocation in the
dmabuf->ops->attach().
c) Client may need to do dma_buf_map_attachment().
d) Accordingly dma_buf_unmap_attachment() should be called.
e) dma_buf_detach () // Clients detach to the dmabuf.
o Here the slab allocations made in b) are freed.
f) dma_buf_put(dmabuf) // Can free the dmabuf if it is the last
reference.
Now say an erroneous client failed at step c) above thus it directly
called dma_buf_put(), step f) above. Considering that it may be the last
reference to the dmabuf, buffer will be freed with pending attachments
left to the dmabuf which can show up as the 'memory leak'. This should
at least be reported as the WARN().
Change-Id: Ia58b41500be943fe3c2da3eb0f5480ae99715de2
Signed-off-by: Charan Teja Reddy <charante@codeaurora.org>
Reviewed-by: Christian König <christian.koenig@amd.com>
Link: https://patchwork.freedesktop.org/patch/msgid/1627043468-16381-1-git-send-email-charante@codeaurora.org
Signed-off-by: Christian König <christian.koenig@amd.com>
This change enables the host mode compliance config on sdxlemur.
Change-Id: Ied9e01d73fec84918ece143b8c54b4b30f9045bc
Signed-off-by: Elson Roy Serrao <eserrao@codeaurora.org>
is_flush_rq() is called from bt_iter()/bt_tags_iter(), and runs the
following check:
hctx->fq->flush_rq == req
but the passed hctx from bt_iter()/bt_tags_iter() may be NULL because:
1) memory re-order in blk_mq_rq_ctx_init():
rq->mq_hctx = data->hctx;
...
refcount_set(&rq->ref, 1);
OR
2) tag re-use and ->rqs[] isn't updated with new request.
Fix the issue by re-writing is_flush_rq() as:
return rq->end_io == flush_end_io;
which turns out simpler to follow and immune to data race since we have
ordered WRITE rq->end_io and refcount_set(&rq->ref, 1).
Fixes: 2e315dc07df0 ("blk-mq: grab rq->refcount before calling ->fn in
blk_mq_tagset_busy_iter")
Cc: "Blank-Burian, Markus, Dr." <blankburian@uni-muenster.de>
Cc: Yufen Yu <yuyufen@huawei.com>
Signed-off-by: Ming Lei <ming.lei@redhat.com>.
Bug: 197804811
Change-Id: I4c19fc2c7d39235b0e95a622f26646a353a19ee9
[Upstream: cherry picked from commit a9ed27a764156929efe714033edb3e9023c5f321]
[Pradeep: Resolved conflicts in block/blk.h]
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
Git-commit: ec1b6ab9fe
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
Before we free request queue, clearing flush request reference in
tags->rqs[], so that potential UAF can be avoided.
Based on one patch written by David Jeffery.
Tested-by: John Garry <john.garry@huawei.com>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Reviewed-by: David Jeffery <djeffery@redhat.com>
Signed-off-by: Ming Lei <ming.lei@redhat.com>.
Bug: 197804811
Change-Id: I9600626e807a4eed546c21be808fabed2a9db9b1
[Upstream: cherry picked from commit 364b61818f65045479e42e76ed8dd6f051778280]
[Todd: refactored to avoid breaking KMI ]
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
Signed-off-by: Todd Kjos <tkjos@google.com>
Git-commit: c9a3b51b07
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
refcount_inc_not_zero() in bt_tags_iter() still may read one freed
request.
Fix the issue by the following approach:
1) hold a per-tags spinlock when reading ->rqs[tag] and calling
refcount_inc_not_zero in bt_tags_iter()
2) clearing stale request referred via ->rqs[tag] before freeing
request pool, the per-tags spinlock is held for clearing stale
->rq[tag]
So after we cleared stale requests, bt_tags_iter() won't observe
freed request any more, also the clearing will wait for pending
request reference.
The idea of clearing ->rqs[] is borrowed from John Garry's previous
patch and one recent David's patch.
Tested-by: John Garry <john.garry@huawei.com>
Reviewed-by: David Jeffery <djeffery@redhat.com>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Signed-off-by: Ming Lei <ming.lei@redhat.com>.
Bug: 197804811
Change-Id: If49478d7b05d3f5b0a26966ddf9ae764cf2fb6b0
[Upstream: cherry picked from commit bd63141d585bef14f4caf111f6d0e27fe2300ec6]
[Todd: refactored to avoid breaking KMI ]
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
Signed-off-by: Todd Kjos <tkjos@google.com>
Git-commit: bb96e7f45d
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
Grab rq->refcount before calling ->fn in blk_mq_tagset_busy_iter(), and
this way will prevent the request from being re-used when ->fn is
running. The approach is same as what we do during handling timeout.
Fix request use-after-free(UAF) related with completion race or queue
releasing:
- If one rq is referred before rq->q is frozen, then queue won't be
frozen before the request is released during iteration.
- If one rq is referred after rq->q is frozen, refcount_inc_not_zero()
will return false, and we won't iterate over this request.
However, still one request UAF not covered: refcount_inc_not_zero() may
read one freed request, and it will be handled in next patch.
Tested-by: John Garry <john.garry@huawei.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Signed-off-by: Ming Lei <ming.lei@redhat.com>.
Bug: 197804811
Change-Id: I0e431a8361d1412aaca3f7c0310780d9a9ad0db8
[Upstream: cherry picked from commit 2e315dc07df009c3e29d6926871f62a30cfae394]
[Pradeep: Resolved conflicts in block/blk-mq-tag.c]
Git-commit: a5d38e7c26
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Pradeep P V K <pragalla@codeaurora.org>
If host is not using qrtr channel, Tx on device may block for
availabilty of tre. If we try to unregister qrtr endpoint at
the same time it will block for endpoint lock held in Tx path.
Unblock any Tx before calling qrtr endpoint unregister.
Change-Id: I59b1a68fd2279ba6bc472a3a532102e82f094175
Signed-off-by: Deepak Kumar Singh <deesin@codeaurora.org>
The pm8008 regulator is connected over I2C and the I2C device configures
its BW vote in runtime_resume and runtime_suspend. These callbacks are
triggered from the pm8008 driver's regmap calls. This means regulator
framework requests for pm8008 call into the ICC framework which in turn
calls into clock framework.
The qcom rpm smd clock providers calls into RPM message with the
the regulator framework, ICC framework and clock framework locks held.
To prevent these deadlocks, enable the I2C qup clocks required for pm8008
by default during probe and stop requesting for clock enable/rate from the
framework.
Change-Id: Ifd486bec85a46139ccb15f4b5dbd2d43c33f3fda
Signed-off-by: Taniya Das <tdas@codeaurora.org>
The commit 8ffa6450ba ("iommu/arm-smmu: Add support for not removing
SMMU power votes") add the support for not removing the power votes of
smmu. It requires 'qcom,power-always-on' in smmu dt property to enable
this support which is currently enabled only for gpu smmu. And this
makes the clients of the SMMU to know If this dt property is enabled to
make decissions in their drivers which is not directly available.
Since there exists a device with atomic domain attached to apps smmu
which will make power resources always on, this separate dt property to
enable power resources for specific SMMU is not required. Thus remove
the 'qcom,power-always-on' property which makes power resources of
SMMU's as always ON when CONFIG_ARM_SMMU_POWER_ALWAYS_ON is enabled.
Change-Id: I2ee1d330f5c1c65474fea7d6b2a9389ae3cf085d
Signed-off-by: Charan Teja Reddy <charante@codeaurora.org>
Release write lock when EP config space is not accessible
while mhi fast resume.
Change-Id: I7d92bca2685058db81312820471609409ddfdbbf
Signed-off-by: Vivek Pernamitta <vpernami@codeaurora.org>
There is one race condition where mhi_prepare_channel is called
in which read pointer and write pointer is set to base address
and in parallel there could be an MHI M0 transaction which
checks any pending event rings on all channels (tre_ring)
with RP != WP and rings channel DB which causes Null pointer
access. Check for MHI channel is enabled before ringing channel
doorbell. Reset mhi channel chan_ctxt, tre_ring and buf_ring
wp and rp to NULL in mhi_deinit_chan_ctxt.
Change-Id: If30908fc7fcc26f6987bd0da886bb75468a29b9e
Signed-off-by: Vivek Pernamitta <vpernami@codeaurora.org>
This is to add gpi register dump support where clients can directly
call the API to dump GSI registers. This helps debug when GSI transfer
has any issue like timeout, no callback etc at the client driver and
want to dump register directly based on the need.
Change-Id: I1d9fadd51ccea166f2a486e84a8de47c134e435b
Signed-off-by: Mukesh Kumar Savaliya <msavaliy@codeaurora.org>
In one core msm_geni_serial driver acquiring port->rx_lock in
stop_rx_sequencer function in process context by calling handle_rx_dma_xfer
and this process is preempted becz of core interrupt is
fired on same core and then same lock is trying to acquire
from interrupt context. This is resulting in deadlock issue.
Below are the core call stack of deadlock.
Core 0 LR: _raw_spin_lock[jt]+40 <ffffffe973336e14>
[<ffffffe971f1df5c>] handle_rx_dma_xfer+0x44
[<ffffffe971f1ec70>] msm_geni_serial_handle_isr+0x6fc
[<ffffffe971f1f6ec>] msm_geni_serial_isr+0x40
[<ffffffe9721634a8>] __handle_irq_event_percpu+0x158
[<ffffffe9721637d8>] handle_irq_event+0x60
[<ffffffe972169548>] handle_fasteoi_irq+0x128
[<ffffffe972162364>] __handle_domain_irq+0xa0
[<ffffffe971e81b64>] gic_handle_irq$7f58c51dd0f0d487d89dbb027abc57c5+0xb8
[<ffffffe971e83f84>] el1_irq+0x104
[<ffffffe971f1df68>] handle_rx_dma_xfer+0x50
[<ffffffe971f1d9ac>] stop_rx_sequencer+0x118
[<ffffffe971f20f94>] msm_geni_serial_set_termios+0x114
[<ffffffe9726dbd30>] uart_change_speed+0x58
[<ffffffe9726ddf40>] uart_set_termios$ecf561cdccc9a487f79dc2d4825d91c7+0xd4
[<ffffffe9726d033c>] tty_set_termios[jt]+0x1c0
[<ffffffe9726d0c2c>] set_termios+0x124
[<ffffffe9726d0894>] tty_mode_ioctl+0x468
[<ffffffe9726d117c>] n_tty_ioctl_helper+0xac
[<ffffffe9726cc498>] n_tty_ioctl$31461d4e731178606d28313f43c714a4[jt]+0x318
[<ffffffe9726c80cc>] tty_ioctl+0x37c
[<ffffffe9723185fc>] do_vfs_ioctl+0x384
[<ffffffe97231923c>] __arm64_sys_ioctl+0x78
[<ffffffe9720be588>] el0_svc_common[jt]+0xd8
[<ffffffe9720be4c8>] el0_svc_handler+0x68
[<ffffffe971e84e88>] ret_to_user[jt]+0x0.
Change-Id: I7e1392cd82a93b1da6b19f05dbe67b66d46193f1
Signed-off-by: Chandana Kishori Chiluveru <cchiluve@codeaurora.org>
This change is a workaround change to fix the PMIC race condition
with the clock enablement. In case of PMIC txfer over i2c, I2C driver
resumes and votes for BW and clocks. The BW vote goes to RPM and that
in turn waiting for the global PMIC mutex causing race condition in
rare cases.
Hence as a workaroun, do not vote for the BW vote only for PMIC used
I2C SE instance.
Change-Id: I94c57427200a71dd2792533b1af249940b0bf03f
Signed-off-by: Mukesh Kumar Savaliya <msavaliy@codeaurora.org>
Enable cnss2 driver as module as requested on sdxlemur.
CRs-Fixed: 3016737
Change-Id: I0d8971c60d765fbfbee55ba1d215a2eb1ebc5659
Signed-off-by: Will Huang <wilhuang@codeaurora.org>
Changing GPIO output value is not reflecting. Change GPIO pull up
configuration from pull up to no pull to reflect state change.
Change-Id: Iac636b9b601b9819ee7aac2118c1af3b0f864e86
Signed-off-by: Prasanna Kumar Thoorvas Samyrao Muralidharan <ptsm@codeaurora.org>
Add CONFIG_IPV6 check to ipv6 specific early eth code
Change-Id: Ib1b266e6da7243e4a1b2d3507b0d19b119e2ebdc
Signed-off-by: Raihan Haider<rhaider@codeaurora.org>
Register notifier to get notification for restart_level
change of WPSS and send SMP2P command to FW to enable
PHY processor SSR.
Change-Id: Id0edb6ab6a44fbca83b2dbe6bad7c86e2540d865
Signed-off-by: Naman Padhiar <npadhiar@codeaurora.org>
While deferring mem_entry_put, we are doing INIT_WORK for entry.
When mem_entry_put get called again for the same entry before
execution of previous work finishes, there is a chance of corruption
in the list and cause a crash. Update kgsl_mem_entry_put_deferred
to put refcount on mem entry and trigger deferred mem entry destroy
only when refcount on entry is the last refcount.
Change-Id: I2a8533fd26e776d49ab128bdb484053ce3bc82dc
Signed-off-by: Pankaj Gupta <gpankaj@codeaurora.org>
This enables the module to help modem communicate
with external Application processor.
Change-Id: I839f00a28f668fac062157bf24437cf7605a9482
Signed-off-by: Yogesh Lal <ylal@codeaurora.org>
Signed-off-by: Rohit Agarwal <rohiagar@codeaurora.org>
When suspend is in progress on local processor, if
remote processor toggles GPIO to indicate a resume
event to local processor, this event may get lost.
This commit addresses this situation.
1. Add IRQF_NO_SUSPEND flag so that wakeup_irq is
not disabled during suspend on local processor.
2. Install primary handler that inform pm core
that a system wakeup event has happened. The pm
core can then abort a suspend in progress.
Change-Id: I8d84f15a118c4630bde7b9db35ffadddeb937cb9
Signed-off-by: Pavankumar Vijapur <pvijapur@codeaurora.org>
Signed-off-by: Yogesh Lal <ylal@codeaurora.org>
When the remote processor wants to wake up local processor
it toggles one of the GPIO. The IRQ handler at local
end will notify registered listeners about it.
Change-Id: Iccbfb7c86538c1e111c97bbe438ef5846182405e
Signed-off-by: Rishi Gupta <rishgupt@codeaurora.org>
Signed-off-by: Yogesh Lal <ylal@codeaurora.org>
/sys/kernel/debug/kgsl/proc/<pid>/mem prints incorrect map size
in some cases. Currently, memdesc size is printed as map size.
Because of this, map size shows non-zero value even for unmapped
buffers. Since kgsl buffers can be mapped multiple times, update
the print to map count instead of map size.
Change-Id: I7970580bc3b1c9a30ca0d72d9caf89af1ce09740
Signed-off-by: Kamal Agrawal <kamaagra@codeaurora.org>