Currently, ucsi_qti_notify() is checking the received data from
charger firmware (PPM) to see if there is any connector status
response with partner accessory information (e.g. analog audio).
It does this based on setting a flag (cmd_requested_flags) when
UCSI_GET_CONNECTOR_STATUS command is sent from UCSI framework to
PPM so that the response for that command can be read and clients
registered for getting notification on partner accessory can get
notified. However, in a certain scenario, multiple response for
different commands can be received from PPM. See a possible
example below.
1. UCSI framework sends UCSI_GET_CONNECTOR_STATUS command
2. ucsi_glink driver sets cmd_requested_flags, waits for response
3. UCSI framework sends UCSI_GET_CURRENT_CAM command
4. ucsi_glink driver gets a response for UCSI_GET_CONNECTOR_STATUS
and schedules notify_work since ucsi_qti_notify() is called
with cmd_requested_flags set.
5. ucsi_glink driver gets a response for UCSI_GET_CURRENT_CAM and
this can end up reading "flags" because cmd_requested_flags is
not cleared yet. However, this causes a buffer overflow because
ucsi_qti_read() passes "val" pointer passed from UCSI framework
which is of 1 byte length and ucsi_qti_notify() ends up reading
"flags" which is at an offset 2 of length 9 bytes.
6. ucsi_qti_notify_work() clears cmd_requested_flags.
Fix this by checking the message length in ucsi_qti_notify()
to ensure that status->flags is read only when a response is
received for UCSI_GET_CONNECTOR_STATUS. Also, relocate the
clearing of "cmd_requested_flags" flag.
CRs-Fixed: 2678391
Change-Id: Iac1d5c58e1ed2fd0f3bc153da23cddf0700cc097
Signed-off-by: Subbaraman Narayanamurthy <subbaram@codeaurora.org>
Register driver work handler will only power up device, resume PCIe
link and start MHI to download firmware. It may only block there
for a timeout, so there is no need to post it as killable event.
Change-Id: Ib82050358dc8df4a8163ecb43702aa86ed34f23d
Signed-off-by: Yue Ma <yuem@codeaurora.org>
For uniprocessor systems, add a NULL definition of tick_broadcast to
add support for tick broadcast.
Change-Id: I7dc47984cb6b60c9814171888f6adbc480a1e990
Signed-off-by: Mahesh Sivasubramanian <msivasub@codeaurora.org>
This change is for general scheduler improvement.
Change-Id: I15daf3a5837f8147f1fbb179e0fba7e1547cb499
Signed-off-by: Shaleen Agrawal <shalagra@codeaurora.org>
Currently gdsc_disable() can return a value of 1 upon
successfully disabling a GDSC if it has a parent supply.
Correct this so that 0 is always returned on success.
Change-Id: I37ade1bf62b4e8b2f3446b9072674935579d75dd
Signed-off-by: David Collins <collinsd@codeaurora.org>
Add SW USB mode support for TMC to use software interface
to send data from TMC to USB.
Change-Id: I8e4dee6cfd037d8bb81ea27ad2ed996e9980720c
Signed-off-by: Shaoqing Liu <shaoqingliu@codeaurora.org>
Signed-off-by: Tingwei Zhang <tingwei@codeaurora.org>
Signed-off-by: Mao Jinlong <jinlmao@codeaurora.org>
Fix uapi header to work with KERNEL_HEADER_TEST and UAPI_HEADER_TEST.
Change-Id: I1ad9ded45b95f9abf3a5543f5aa21cfe7541a9cd
Signed-off-by: Vignesh Kulothungan <vigneshk@codeaurora.org>
When SMMU works in bypass mode, set has_iommu to false. ETR
can use SG mode.
Change-Id: Ic7a6814cace92098473e4b5302408034e662058d
Signed-off-by: Tingwei Zhang <tingwei@codeaurora.org>
Signed-off-by: Mao Jinlong <jinlmao@codeaurora.org>
Will aid debugging lockups in perf_event_read_value()
track the cpu being ipi'd.
Change-Id: Ia948f31bb2d91bca6144c0c50f8f66bd9c1459fe
Signed-off-by: Stephen Dickey <dickey@codeaurora.org>