Commit graph

919,075 commits

Author SHA1 Message Date
Pulkit Singh Tak
d7c484822f msm: eva: Validating the SFR buffer size before accessing
To avoid any OOB write or other security issues, it's good to
validate the buffer size before accessing it.

Change-Id: Ibfdef21293c9385119cfb6338ef36e20c0fc1f2f
Signed-off-by: Pulkit Singh Tak <quic_ptak@quicinc.com>
(cherry picked from commit 8ee6cd6bef)
2025-01-23 23:42:16 -08:00
Linux Build Service Account
59b19eff23 Merge 6ea403acf3 on remote branch
Change-Id: I56b796bf0bc3983711d547ef0bbf64b90dcd2c6b
2025-01-14 12:04:43 -08:00
QCTECMDR Service
6ea403acf3 Merge "USB: dwc3: gadget: Add stop transfer request for isoc transfers" 2025-01-03 02:06:40 -08:00
QCTECMDR Service
9d163aee48 Merge "USB: dwc3: gadget: Queue data for 16 micro frames ahead in future" 2025-01-02 00:40:24 -08:00
QCTECMDR Service
6ea1e229e2 Merge "arm64: defconfig: Enable uvc for QCM6490 IOT target" 2024-12-31 02:31:07 -08:00
Gao Wang
a8ee531704 msm: npu: Fix use after free issue
There is possibility that network will be used after free.
This change is to fix this issue.

Change-Id: I12205b750450bee36f85dff3f620f8f0689a4e46
Signed-off-by: Gao Wang <quic_gaowang@quicinc.com>
2024-12-26 18:13:11 -08:00
AKASH KUMAR
09c3ad5d25 USB: dwc3: gadget: Add stop transfer request for isoc transfers
Currently,stop transfer is done based on missed isoc packets
which can cause issue when software list is empty with no missed
isoc.

Issue stop active transfers if started list is empty.

Also,Frame_number is set from XferNotReady and may be already
out of date. DSTS only provides the lower 14 bit of the
current frame number. So add the upper two bits of
frame_number and handle a possible rollover.
This will provide the correct frame_number unless more than
rollover has happened since XferNotReady.

Increase TX fifo size for isochronous endpoint in case maxburst
is greater than 6 for better performance.

Added Endtransfer logic to be called when BUS expiry happens due
to frame mismatch.

Change-Id: I672529f4a4fa2740b46febbe265cd386e5932017
Signed-off-by: AKASH KUMAR <quic_akakum@quicinc.com>
2024-12-25 22:16:16 -08:00
Akash Kumar
944949f22e arm64: defconfig: Enable uvc for QCM6490 IOT target
Enable USB UVC peripheral function driver that
enables video streaming over USB.

Change-Id: I951d93f735a57b382aa5e43f2997880ded89b2f4
Signed-off-by: Akash Kumar <quic_akakum@quicinc.com>
2024-12-13 13:37:57 +05:30
Mukesh Ojha
10dc202835 firmware: qcom_scm: do not clear dump mode from shutdown
Do not overwrite download mode to NO dump mode from SCM driver, it is
already being done at proper place in qcom-dload-mode driver and
writing it here can clean up EDL mode written from qcom-dload-mode.

Fix this issue by remove writing no dump mode from SCM driver.

Change-Id: Ibfe8b8484dd69ae8386b46c9a53ef42a4a475688
Signed-off-by: Mukesh Ojha <quic_mojha@quicinc.com>
2024-12-03 22:34:55 -08:00
Linux Build Service Account
88069c58c3 Merge 7ea86abd86 on remote branch
Change-Id: Ifbdb535d8cf5d84b2c6545b1aa2937349dba30ff
2024-11-08 01:35:14 -08:00
kamasali Satyanarayan
222ee0825f Merge android11-5.4.281 (d62984a) into msm-5.4
* remotes/origin/tmp-d62984a:
  ANDROID: delete tool added by mistake
  ANDROID: fix ENOMEM check of binder_proc_ext
  ANDROID: binder: fix KMI issues due to frozen notification
  BACKPORT: FROMGIT: binder: frozen notification binder_features flag
  BACKPORT: FROMGIT: binder: frozen notification
  BACKPORT: selftests/binderfs: add test for feature files
  UPSTREAM: docs: binderfs: add section about feature files
  BACKPORT: binderfs: add support for feature files
  FROMLIST: binder: fix memory leaks of spam and pending work
  FROMGIT: Binder: add TF_UPDATE_TXN to replace outdated txn
  BACKPORT: binder: tell userspace to dump current backtrace when detected oneway spamming
  UPSTREAM: net: sched: sch_multiq: fix possible OOB write in multiq_tune()
  FROMLIST: binder: fix UAF caused by offsets overwrite
  Revert "net: mac802154: Fix racy device stats updates by DEV_STATS_INC() and DEV_STATS_ADD()"
  Linux 5.4.281
  tap: add missing verification for short frame
  tun: add missing verification for short frame
  filelock: Fix fcntl/close race recovery compat path
  ALSA: hda/realtek: Enable headset mic on Positivo SU C1400
  jfs: don't walk off the end of ealist
  ocfs2: add bounds checking to ocfs2_check_dir_entry()
  net: relax socket state check at accept time.
  drm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq()
  ACPI: processor_idle: Fix invalid comparison with insertion sort for latency
  ARM: 9324/1: fix get_user() broken with veneer
  hfsplus: fix uninit-value in copy_name
  selftests/vDSO: fix clang build errors and warnings
  spi: imx: Don't expect DMA for i.MX{25,35,50,51,53} cspi devices
  fs: better handle deep ancestor chains in is_subdir()
  Bluetooth: hci_core: cancel all works upon hci_unregister_dev()
  scsi: libsas: Fix exp-attached device scan after probe failure scanned in again after probe failed
  powerpc/eeh: avoid possible crash when edev->pdev changes
  powerpc/pseries: Whitelist dtl slub object for copying to userspace
  net: mac802154: Fix racy device stats updates by DEV_STATS_INC() and DEV_STATS_ADD()
  net: usb: qmi_wwan: add Telit FN912 compositions
  ALSA: dmaengine_pcm: terminate dmaengine before synchronize
  s390/sclp: Fix sclp_init() cleanup on failure
  can: kvaser_usb: fix return value for hif_usb_send_regout
  ASoC: ti: omap-hdmi: Fix too long driver name
  ASoC: ti: davinci-mcasp: Set min period size using FIFO config
  bytcr_rt5640 : inverse jack detect for Archos 101 cesium
  Input: elantech - fix touchpad state on resume for Lenovo N24
  mips: fix compat_sys_lseek syscall
  ALSA: hda/realtek: Add more codec ID to no shutup pins list
  KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()
  wifi: cfg80211: wext: add extra SIOCSIWSCAN data check
  mei: demote client disconnect warning on suspend to debug
  fs/file: fix the check in find_next_fd()
  kconfig: remove wrong expr_trans_bool()
  kconfig: gconf: give a proper initial state to the Save button
  ila: block BH in ila_output()
  Input: silead - Always support 10 fingers
  wifi: mac80211: fix UBSAN noise in ieee80211_prep_hw_scan()
  wifi: mac80211: mesh: init nonpeer_pm to active by default in mesh sdata
  ACPI: EC: Avoid returning AE_OK on errors in address space handler
  ACPI: EC: Abort address space access upon error
  scsi: qedf: Set qed_slowpath_params to zero before use
  filelock: Remove locks reliably when fcntl/close race is detected
  gcc-plugins: Rename last_stmt() for GCC 14+
  ANDROID: GKI: refresh ABI to include kimage_vaddr
  ANDROID: preserve CRC for struct tcp_sock
  Linux 5.4.280
  i2c: rcar: bring hardware to known state when probing
  nilfs2: fix kernel bug on rename operation of broken directory
  tcp: avoid too many retransmit packets
  tcp: use signed arithmetic in tcp_rtx_probe0_timed_out()
  net: tcp: fix unexcepted socket die when snd_wnd is 0
  tcp: refactor tcp_retransmit_timer()
  SUNRPC: Fix RPC client cleaned up the freed pipefs dentries
  libceph: fix race between delayed_work() and ceph_monc_stop()
  ALSA: hda/realtek: Limit mic boost on VAIO PRO PX
  nvmem: meson-efuse: Fix return value of nvmem callbacks
  hpet: Support 32-bit userspace
  USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor
  usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()
  USB: Add USB_QUIRK_NO_SET_INTF quirk for START BP-850k
  USB: serial: option: add Rolling RW350-GL variants
  USB: serial: option: add Netprisma LCUK54 series modules
  USB: serial: option: add support for Foxconn T99W651
  USB: serial: option: add Fibocom FM350-GL
  USB: serial: option: add Telit FN912 rmnet compositions
  USB: serial: option: add Telit generic core-dump composition
  octeontx2-af: fix detection of IP layer
  ARM: davinci: Convert comma to semicolon
  s390: Mark psw in __load_psw_mask() as __unitialized
  udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port().
  ppp: reject claimed-as-LCP but actually malformed packets
  net: ethernet: lantiq_etop: fix double free in detach
  net: lantiq_etop: add blank line after declaration
  octeontx2-af: Fix incorrect value output on error path in rvu_check_rsrc_availability()
  tcp: fix incorrect undo caused by DSACK of TLP retransmit
  tcp: add TCP_INFO status for failed client TFO
  vfs: don't mod negative dentry count when on shrinker list
  fs/dcache: Re-use value stored to dentry->d_flags instead of re-reading
  filelock: fix potential use-after-free in posix_lock_inode
  nilfs2: fix incorrect inode allocation from reserved inodes
  nvme-multipath: find NUMA path only for online numa-node
  ALSA: hda/realtek: Enable headset mic of JP-IK LEAP W502 with ALC897
  i2c: pnx: Fix potential deadlock warning from del_timer_sync() call in isr
  media: dw2102: fix a potential buffer overflow
  bnx2x: Fix multiple UBSAN array-index-out-of-bounds
  drm/amdgpu/atomfirmware: silence UBSAN warning
  drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes
  Revert "mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again"
  fsnotify: Do not generate events for O_PATH file descriptors
  can: kvaser_usb: Explicitly initialize family in leafimx driver_info struct
  mm: optimize the redundant loop of mm_update_owner_next()
  nilfs2: add missing check for inode numbers on directory entries
  nilfs2: fix inode number range checks
  inet_diag: Initialize pad field in struct inet_diag_req_v2
  selftests: make order checking verbose in msg_zerocopy selftest
  selftests: fix OOM in msg_zerocopy selftest
  bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set()
  wifi: wilc1000: fix ies_len type in connect path
  tcp_metrics: validate source addr length
  UPSTREAM: tcp: fix DSACK undo in fast recovery to call tcp_try_to_open()
  net: tcp better handling of reordering then loss cases
  tcp: add ece_ack flag to reno sack functions
  tcp: tcp_mark_head_lost is only valid for sack-tcp
  s390/pkey: Wipe sensitive data on failure
  jffs2: Fix potential illegal address access in jffs2_free_inode
  powerpc/xmon: Check cpu id in commands "c#", "dp#" and "dx#"
  orangefs: fix out-of-bounds fsid access
  powerpc/64: Set _IO_BASE to POISON_POINTER_DELTA not 0 for CONFIG_PCI=n
  i2c: i801: Annotate apanel_addr as __ro_after_init
  media: dvb-frontends: tda10048: Fix integer overflow
  media: s2255: Use refcount_t instead of atomic_t for num_channels
  media: dvb-frontends: tda18271c2dd: Remove casting during div
  net: dsa: mv88e6xxx: Correct check for empty list
  Input: ff-core - prefer struct_size over open coded arithmetic
  firmware: dmi: Stop decoding on broken entry
  sctp: prefer struct_size over open coded arithmetic
  media: dw2102: Don't translate i2c read into write
  drm/amd/display: Skip finding free audio for unknown engine_id
  drm/amdgpu: Initialize timestamp for some legacy SOCs
  scsi: qedf: Make qedf_execute_tmf() non-preemptible
  IB/core: Implement a limit on UMAD receive List
  media: dvb-usb: dib0700_devices: Add missing release_firmware()
  media: dvb: as102-fe: Fix as10x_register_addr packing
  drm/lima: fix shared irq handling on driver remove
  Compiler Attributes: Add __uninitialized macro
  Linux 5.4.279
  arm64: dts: rockchip: Add sound-dai-cells for RK3368
  ARM: dts: rockchip: rk3066a: add #sound-dai-cells to hdmi node
  tcp: Fix data races around icsk->icsk_af_ops.
  ipv6: Fix data races around sk->sk_prot.
  ipv6: annotate some data-races around sk->sk_prot
  nfs: Leave pages in the pagecache if readpage failed
  pwm: stm32: Refuse too small period requests
  mtd: spinand: macronix: Add support for serial NAND flash
  ftruncate: pass a signed offset
  ata: libata-core: Fix double free on error
  batman-adv: Don't accept TT entries for out-of-spec VIDs
  drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_hd_modes
  drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_ld_modes
  hexagon: fix fadvise64_64 calling conventions
  csky, hexagon: fix broken sys_sync_file_range
  net: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rts_session_new
  net: can: j1939: recover socket queue on CAN bus error during BAM transmission
  net: can: j1939: Initialize unused data in j1939_send_one()
  tty: mcf: MCF54418 has 10 UARTS
  usb: atm: cxacru: fix endpoint checking in cxacru_bind()
  usb: musb: da8xx: fix a resource leak in probe()
  usb: gadget: printer: SS+ support
  net: usb: ax88179_178a: improve link status logs
  iio: chemical: bme680: Fix sensor data read operation
  iio: chemical: bme680: Fix overflows in compensate() functions
  iio: chemical: bme680: Fix calibration data variable
  iio: chemical: bme680: Fix pressure value output
  iio: adc: ad7266: Fix variable checking bug
  mmc: sdhci: Do not lock spinlock around mmc_gpio_get_ro()
  mmc: sdhci: Do not invert write-protect twice
  mmc: sdhci-pci: Convert PCIBIOS_* return codes to errnos
  x86: stop playing stack games in profile_pc()
  gpio: davinci: Validate the obtained number of IRQs
  nvme: fixup comment for nvme RDMA Provider Type
  soc: ti: wkup_m3_ipc: Send NULL dummy message instead of pointer message
  media: dvbdev: Initialize sbuf
  ALSA: emux: improve patch ioctl data validation
  net/dpaa2: Avoid explicit cpumask var allocation on stack
  net/iucv: Avoid explicit cpumask var allocation on stack
  mtd: partitions: redboot: Added conversion of operands to a larger type
  drm/panel: ilitek-ili9881c: Fix warning with GPIO controllers that sleep
  netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers
  parisc: use correct compat recv/recvfrom syscalls
  sparc: fix old compat_sys_select()
  net: phy: micrel: add Microchip KSZ 9477 to the device table
  net: phy: mchp: Add support for LAN8814 QUAD PHY
  net: dsa: microchip: fix initial port flush problem
  ASoC: fsl-asoc-card: set priv->pdev before using it
  netfilter: nf_tables: validate family when identifying table via handle
  drm/amdgpu: fix UBSAN warning in kv_dpm.c
  pinctrl: rockchip: fix pinmux reset in rockchip_pmx_set
  pinctrl: rockchip: fix pinmux bits for RK3328 GPIO3-B pins
  pinctrl: rockchip: fix pinmux bits for RK3328 GPIO2-B pins
  pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER
  iio: dac: ad5592r: fix temperature channel scaling value
  iio: dac: ad5592r: un-indent code-block for scale read
  iio: dac: ad5592r-base: Replace indio_dev->mlock with own device lock
  x86/amd_nb: Check for invalid SMN reads
  PCI: Add PCI_ERROR_RESPONSE and related definitions
  perf/core: Fix missing wakeup when waiting for context reference
  kheaders: explicitly define file modes for archived headers
  Revert "kheaders: substituting --sort in archive creation"
  tracing: Add MODULE_DESCRIPTION() to preemptirq_delay_test
  arm64: dts: qcom: qcs404: fix bluetooth device address
  ARM: dts: samsung: smdk4412: fix keypad no-autorepeat
  ARM: dts: samsung: exynos4412-origen: fix keypad no-autorepeat
  ARM: dts: samsung: smdkv310: fix keypad no-autorepeat
  i2c: ocores: set IACK bit after core is enabled
  gcov: add support for GCC 14
  drm/radeon: fix UBSAN warning in kv_dpm.c
  ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine."
  dmaengine: ioatdma: Fix missing kmem_cache_destroy()
  regulator: core: Fix modpost error "regulator_get_regmap" undefined
  net: usb: rtl8150 fix unintiatilzed variables in rtl8150_get_link_ksettings
  netfilter: ipset: Fix suspicious rcu_dereference_protected()
  virtio_net: checksum offloading handling fix
  net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc()
  net/sched: act_api: rely on rcu in tcf_idr_check_alloc
  netns: Make get_net_ns() handle zero refcount net
  xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr()
  ipv6: prevent possible NULL dereference in rt6_probe()
  ipv6: prevent possible NULL deref in fib6_nh_init()
  netrom: Fix a memory leak in nr_heartbeat_expiry()
  cipso: fix total option length computation
  mips: bmips: BCM6358: make sure CBR is correctly set
  MIPS: Routerboard 532: Fix vendor retry check code
  MIPS: Octeon: Add PCIe link status check
  PCI/PM: Avoid D3cold for HP Pavilion 17 PC/1972 PCIe Ports
  udf: udftime: prevent overflow in udf_disk_stamp_to_time()
  usb: misc: uss720: check for incompatible versions of the Belkin F5U002
  powerpc/io: Avoid clang null pointer arithmetic warnings
  powerpc/pseries: Enforce hcall result buffer validity and size
  Bluetooth: ath3k: Fix multiple issues reported by checkpatch.pl
  scsi: qedi: Fix crash while reading debugfs attribute
  drop_monitor: replace spin_lock by raw_spin_lock
  batman-adv: bypass empty buckets in batadv_purge_orig_ref()
  selftests/bpf: Prevent client connect before server bind in test_tc_tunnel.sh
  rcutorture: Fix rcu_torture_one_read() pipe_count overflow comment
  i2c: at91: Fix the functionality flags of the slave-only interface
  usb-storage: alauda: Check whether the media is initialized
  greybus: Fix use-after-free bug in gb_interface_release due to race condition.
  netfilter: nftables: exthdr: fix 4-byte stack OOB write
  hugetlb_encode.h: fix undefined behaviour (34 << 26)
  hv_utils: drain the timesync packets on onchannelcallback
  tick/nohz_full: Don't abuse smp_call_function_single() in tick_setup_device()
  nilfs2: fix potential kernel bug due to lack of writeback flag waiting
  intel_th: pci: Add Lunar Lake support
  intel_th: pci: Add Meteor Lake-S support
  intel_th: pci: Add Sapphire Rapids SOC support
  intel_th: pci: Add Granite Rapids SOC support
  intel_th: pci: Add Granite Rapids support
  dmaengine: axi-dmac: fix possible race in remove()
  PCI: rockchip-ep: Remove wrong mask on subsys_vendor_id
  ocfs2: fix races between hole punching and AIO+DIO
  ocfs2: use coarse time for new created files
  fs/proc: fix softlockup in __read_vmcore
  vmci: prevent speculation leaks by sanitizing event in event_deliver()
  tracing/selftests: Fix kprobe event name test for .isra. functions
  drm/exynos: hdmi: report safe 640x480 mode as a fallback when no EDID found
  drm/exynos/vidi: fix memory leak in .get_modes()
  drivers: core: synchronize really_probe() and dev_uevent()
  ionic: fix use after netif_napi_del()
  net/ipv6: Fix the RT cache flush via sysctl using a previous delay
  netfilter: ipset: Fix race between namespace cleanup and gc in the list:set type
  Bluetooth: L2CAP: Fix rejecting L2CAP_CONN_PARAM_UPDATE_REQ
  net/mlx5e: Fix features validation check for tunneled UDP (non-VXLAN) packets
  tcp: fix race in tcp_v6_syn_recv_sock()
  drm/bridge/panel: Fix runtime warning on panel bridge release
  drm/komeda: check for error-valued pointer
  liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet
  HID: logitech-dj: Fix memory leak in logi_dj_recv_switch_to_dj_mode()
  iommu: Return right value in iommu_sva_bind_device()
  iommu/amd: Fix sysfs leak in iommu init
  HID: core: remove unnecessary WARN_ON() in implement()
  gpio: tqmx86: fix typo in Kconfig label
  SUNRPC: return proper error from gss_wrap_req_priv
  Input: try trimming too long modalias strings
  scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory
  xhci: Apply broken streams quirk to Etron EJ188 xHCI host
  xhci: Apply reset resume quirk to Etron EJ188 xHCI host
  xhci: Set correct transferred length for cancelled bulk transfers
  jfs: xattr: fix buffer overflow for invalid xattr
  mei: me: release irq in mei_me_pci_resume error path
  USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages
  nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors
  nilfs2: return the mapped address from nilfs_get_page()
  nilfs2: Remove check for PageError
  selftests/mm: compaction_test: fix bogus test success on Aarch64
  selftests/mm: conform test to TAP format output
  selftests/mm: compaction_test: fix incorrect write of zero to nr_hugepages
  serial: sc16is7xx: fix bug in sc16is7xx_set_baud() when using prescaler
  serial: sc16is7xx: replace hardcoded divisor value with BIT() macro
  drm/amd/display: Handle Y carry-over in VCP X.Y calculation
  ASoC: ti: davinci-mcasp: Fix race condition during probe
  ASoC: ti: davinci-mcasp: Handle missing required DT properties
  ASoC: ti: davinci-mcasp: Simplify the configuration parameter handling
  ASoC: ti: davinci-mcasp: Remove legacy dma_request parsing
  ASoC: ti: davinci-mcasp: Use platform_get_irq_byname_optional
  ASoC: ti: davinci-mcasp: remove always zero of davinci_mcasp_get_dt_params
  ASoC: ti: davinci-mcasp: remove redundant assignment to variable ret
  usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete
  ipv6: fix possible race in __fib6_drop_pcpu_from()
  af_unix: Annotate data-race of sk->sk_shutdown in sk_diag_fill().
  af_unix: Use skb_queue_len_lockless() in sk_diag_show_rqlen().
  af_unix: Use unix_recvq_full_lockless() in unix_stream_connect().
  af_unix: Annotate data-race of net->unx.sysctl_max_dgram_qlen.
  af_unix: Annotate data-races around sk->sk_state in UNIX_DIAG.
  af_unix: Annotate data-races around sk->sk_state in sendmsg() and recvmsg().
  af_unix: Annotate data-races around sk->sk_state in unix_write_space() and poll().
  af_unix: Annotate data-race of sk->sk_state in unix_inq_len().
  ptp: Fix error message on failed pin verification
  net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP
  net/mlx5: Stop waiting for PCI if pci channel is offline
  tcp: count CLOSE-WAIT sockets for TCP_MIB_CURRESTAB
  vxlan: Fix regression when dropping packets due to invalid src addresses
  net: sched: sch_multiq: fix possible OOB write in multiq_tune()
  ipv6: sr: block BH in seg6_output_core() and seg6_input_core()
  wifi: iwlwifi: mvm: don't read past the mfuart notifcation
  wifi: iwlwifi: dbg_ini: move iwl_dbg_tlv_free outside of debugfs ifdef
  wifi: iwlwifi: mvm: revert gen2 TX A-MPDU size to 64
  wifi: cfg80211: pmsr: use correct nla_get_uX functions
  wifi: mac80211: Fix deadlock in ieee80211_sta_ps_deliver_wakeup()
  wifi: mac80211: mesh: Fix leak of mesh_preq_queue objects

 Conflicts:
	kernel/gen_kheaders.sh

Change-Id: I4a0de5504b5e61a23b78a1a8f06aceaac810f3c7
Signed-off-by: kamasali Satyanarayan <quic_kamasali@quicinc.com>
2024-10-29 01:43:17 -07:00
QCTECMDR Service
7ea86abd86 Merge "Merge android11-5.4.278(7453ecf) into msm-5.4" 2024-10-28 01:05:28 -07:00
QCTECMDR Service
c2fe5024c0 Merge "power: reset: Disable support of dynamic download mode (ramdump)" 2024-10-27 22:13:42 -07:00
QCTECMDR Service
113056cafc Merge "msm: virtio_npu: Fix use-after-free issue in unmap_buf" 2024-10-27 22:13:41 -07:00
kamasali Satyanarayan
e88bb9b374 Merge android11-5.4.278(7453ecf) into msm-5.4
* remotes/origin/tmp-7453ecf:
  UPSTREAM: usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()
  ANDROID: 16K: Don't set padding vm_flags on 32-bit archs
  ANDROID: GKI: refresh ABI to include kimage_vaddr
  BACKPORT: arm64: move kimage_vaddr to .rodata
  BACKPORT: arm64: kernel: Convert to modern annotations for assembly data
  ANDROID: fix kernelci build breaks due to hid/uhid cyclic dependency
  UPSTREAM: af_unix: Fix garbage collector racing against connect()
  Revert "drm/panel: simple: Add missing Innolux G121X1-L03 format, flags, connector"
  Linux 5.4.278
  nfs: fix undefined behavior in nfs_block_bits()
  s390/ap: Fix crash in AP internal function modify_bitmap()
  ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find()
  sparc: move struct termio to asm/termios.h
  xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING
  net: fix __dst_negative_advice() race
  kdb: Use format-specifiers rather than memset() for padding in kdb_read()
  kdb: Merge identical case statements in kdb_read()
  kdb: Fix console handling when editing and tab-completing commands
  kdb: Use format-strings rather than '\0' injection in kdb_read()
  kdb: Fix buffer overflow during tab-complete
  sparc64: Fix number of online CPUs
  intel_th: pci: Add Meteor Lake-S CPU support
  net/9p: fix uninit-value in p9_client_rpc()
  net/ipv6: Fix route deleting failure when metric equals 0
  crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak
  crypto: ecrdsa - Fix module auto-load on add_key
  KVM: arm64: Allow AArch32 PSTATE.M to be restored as System mode
  fbdev: savage: Handle err return when savagefb_check_var failed
  media: v4l2-core: hold videodev_lock until dev reg, finishes
  media: mxl5xx: Move xpt structures off stack
  media: mc: mark the media devnode as registered from the, start
  arm64: dts: hi3798cv200: fix the size of GICR
  wifi: rtl8xxxu: Fix the TX power of RTL8192CU, RTL8723AU
  md/raid5: fix deadlock that raid5d() wait for itself to clear MD_SB_CHANGE_PENDING
  arm64: tegra: Correct Tegra132 I2C alias
  ACPI: resource: Do IRQ override on TongFang GXxHRXx and GMxHGxx
  ata: pata_legacy: make legacy_exit() work again
  drm/amdgpu: add error handle to avoid out-of-bounds
  media: lgdt3306a: Add a check against null-pointer-def
  f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode()
  x86/mm: Remove broken vsyscall emulation code from the page fault code
  vxlan: Fix regression when dropping packets due to invalid src addresses
  nilfs2: fix use-after-free of timer for log writer thread
  afs: Don't cross .backup mountpoint from backup volume
  io_uring: fail NOP if non-zero op flags is passed in
  mmc: core: Do not force a retune before RPMB switch
  binder: fix max_thread type inconsistency
  SUNRPC: Fix loop termination condition in gss_free_in_token_pages()
  genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU offline
  ALSA: timer: Set lower bound of start tick time
  ipvlan: Dont Use skb->sk in ipvlan_process_v{4,6}_outbound
  spi: stm32: Don't warn about spurious interrupts
  kconfig: fix comparison to constant symbols, 'm', 'n'
  netfilter: tproxy: bail out if IP has been disabled on the device
  net:fec: Add fec_enet_deinit()
  net: usb: smsc95xx: fix changing LED_SEL bit value updated from EEPROM
  smsc95xx: use usbnet->driver_priv
  smsc95xx: remove redundant function arguments
  enic: Validate length of nl attributes in enic_set_vf_port
  dma-buf/sw-sync: don't enable IRQ from sync_print_obj()
  net/mlx5e: Use rx_missed_errors instead of rx_dropped for reporting buffer exhaustion
  nvmet: fix ns enable/disable possible hang
  spi: Don't mark message DMA mapped when no transfer in it is
  netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu()
  nfc: nci: Fix handling of zero-length payload packets in nci_rx_work()
  nfc: nci: Fix kcov check in nci_rx_work()
  net: fec: avoid lock evasion when reading pps_enable
  virtio: delete vq in vp_find_vqs_msix() when request_irq() fails
  arm64: asm-bug: Add .align 2 to the end of __BUG_ENTRY
  openvswitch: Set the skbuff pkt_type for proper pmtud support.
  tcp: Fix shift-out-of-bounds in dctcp_update_alpha().
  params: lift param_set_uint_minmax to common code
  ipv6: sr: fix memleak in seg6_hmac_init_algo
  sunrpc: fix NFSACL RPC retry on soft mount
  nfc: nci: Fix uninit-value in nci_rx_work
  x86/kconfig: Select ARCH_WANT_FRAME_POINTERS again when UNWINDER_FRAME_POINTER=y
  null_blk: Fix the WARNING: modpost: missing MODULE_DESCRIPTION()
  media: cec: cec-api: add locking in cec_release()
  media: cec: cec-adap: always cancel work in cec_transmit_msg_fh
  um: Fix the -Wmissing-prototypes warning for __switch_mm
  powerpc/pseries: Add failure related checks for h_get_mpp and h_get_ppp
  scsi: qla2xxx: Replace all non-returning strlcpy() with strscpy()
  media: stk1160: fix bounds checking in stk1160_copy_video()
  um: Add winch to winch_handlers before registering winch IRQ
  um: Fix return value in ubd_init()
  drm/msm/dpu: Always flush the slave INTF on the CTL
  Input: pm8xxx-vibrator - correct VIB_MAX_LEVELS calculation
  Input: ims-pcu - fix printf string overflow
  libsubcmd: Fix parse-options memory leak
  serial: sh-sci: protect invalidating RXDMA on shutdown
  f2fs: fix to release node block count in error path of f2fs_new_node_page()
  extcon: max8997: select IRQ_DOMAIN instead of depending on it
  ppdev: Add an error check in register_device
  ppdev: Remove usage of the deprecated ida_simple_xx() API
  stm class: Fix a double free in stm_register_device()
  usb: gadget: u_audio: Clear uac pointer when freed.
  microblaze: Remove early printk call from cpuinfo-static.c
  microblaze: Remove gcc flag for non existing early_printk.c file
  iio: pressure: dps310: support negative temperature values
  greybus: arche-ctrl: move device table to its right location
  serial: max3100: Fix bitwise types
  serial: max3100: Update uart_driver_registered on driver removal
  serial: max3100: Lock port->lock when calling uart_handle_cts_change()
  firmware: dmi-id: add a release callback function
  dmaengine: idma64: Add check for dma_set_max_seg_size
  soundwire: cadence: fix invalid PDI offset
  soundwire: cadence_master: improve PDI allocation
  soundwire: intel: don't filter out PDI0/1
  soundwire: cadence/intel: simplify PDI/port mapping
  greybus: lights: check return of get_channel_from_mode
  sched/fair: Allow disabling sched_balance_newidle with sched_relax_domain_level
  sched/topology: Don't set SD_BALANCE_WAKE on cpuset domain relax
  af_packet: do not call packet_read_pending() from tpacket_destruct_skb()
  netrom: fix possible dead-lock in nr_rt_ioctl()
  RDMA/IPoIB: Fix format truncation compilation errors
  selftests/kcmp: remove unused open mode
  selftests/kcmp: Make the test output consistent and clear
  SUNRPC: Fix gss_free_in_token_pages()
  sunrpc: removed redundant procp check
  ext4: avoid excessive credit estimate in ext4_tmpfile()
  x86/insn: Fix PUSH instruction in x86 instruction decoder opcode map
  RDMA/hns: Use complete parentheses in macros
  drm/panel: simple: Add missing Innolux G121X1-L03 format, flags, connector
  ASoC: tracing: Export SND_SOC_DAPM_DIR_OUT to its value
  drm/arm/malidp: fix a possible null pointer dereference
  fbdev: sh7760fb: allow modular build
  platform/x86: wmi: Make two functions static
  media: radio-shark2: Avoid led_names truncations
  media: ngene: Add dvb_ca_en50221_init return value check
  fbdev: sisfb: hide unused variables
  powerpc/fsl-soc: hide unused const variable
  drm/mediatek: Add 0 size check to mtk_drm_gem_obj
  fbdev: shmobile: fix snprintf truncation
  mtd: rawnand: hynix: fixed typo
  drm/amd/display: Fix potential index out of bounds in color transformation function
  ipv6: sr: fix invalid unregister error path
  ipv6: sr: fix incorrect unregister order
  ipv6: sr: add missing seg6_local_exit
  net: openvswitch: fix overwriting ct original tuple for ICMPv6
  net: usb: smsc95xx: stop lying about skb->truesize
  af_unix: Fix data races in unix_release_sock/unix_stream_sendmsg
  net: ethernet: cortina: Locking fixes
  m68k: mac: Fix reboot hang on Mac IIci
  m68k: Fix spinlock race in kernel thread creation
  net: usb: sr9700: stop lying about skb->truesize
  usb: aqc111: stop lying about skb->truesize
  wifi: mwl8k: initialize cmd->addr[] properly
  scsi: qedf: Ensure the copied buf is NUL terminated
  scsi: bfa: Ensure the copied buf is NUL terminated
  HID: intel-ish-hid: ipc: Add check for pci_alloc_irq_vectors
  Revert "sh: Handle calling csum_partial with misaligned data"
  sh: kprobes: Merge arch_copy_kprobe() into arch_prepare_kprobe()
  wifi: ar5523: enable proper endpoint verification
  wifi: carl9170: add a proper sanity check for endpoints
  macintosh/via-macii: Fix "BUG: sleeping function called from invalid context"
  tcp: avoid premature drops in tcp_add_backlog()
  tcp: fix a signed-integer-overflow bug in tcp_add_backlog()
  tcp: minor optimization in tcp_add_backlog()
  wifi: ath10k: populate board data for WCN3990
  wifi: ath10k: Fix an error code problem in ath10k_dbg_sta_write_peer_debug_trigger()
  x86/purgatory: Switch to the position-independent small code model
  scsi: hpsa: Fix allocation size for Scsi_Host private data
  scsi: libsas: Fix the failure of adding phy with zero-address to port
  cpufreq: exit() callback is optional
  cpufreq: Rearrange locking in cpufreq_remove_dev()
  cpufreq: Split cpufreq_offline()
  cpufreq: Reorganize checks in cpufreq_offline()
  ACPI: disable -Wstringop-truncation
  irqchip/alpine-msi: Fix off-by-one in allocation error path
  scsi: ufs: core: Perform read back after disabling UIC_COMMAND_COMPL
  scsi: ufs: core: Perform read back after disabling interrupts
  scsi: ufs: cdns-pltfrm: Perform read back after writing HCLKDIV
  scsi: ufs: qcom: Perform read back after writing reset bit
  qed: avoid truncating work queue length
  x86/boot: Ignore relocations in .notes sections in walk_relocs() too
  wifi: ath10k: poll service ready message before failing
  md: fix resync softlockup when bitmap size is less than array size
  null_blk: Fix missing mutex_destroy() at module removal
  jffs2: prevent xattr node from overflowing the eraseblock
  s390/cio: fix tracepoint subchannel type field
  crypto: ccp - drop platform ifdef checks
  parisc: add missing export of __cmpxchg_u8()
  nilfs2: fix out-of-range warning
  ecryptfs: Fix buffer size for tag 66 packet
  firmware: raspberrypi: Use correct device for DMA mappings
  crypto: bcm - Fix pointer arithmetic
  openpromfs: finish conversion to the new mount API
  nvme: find numa distance only if controller has valid numa id
  drm/amdkfd: Flush the process wq before creating a kfd_process
  ASoC: da7219-aad: fix usage of device_get_named_child_node()
  ASoC: dt-bindings: rt5645: add cbj sleeve gpio property
  ASoC: rt5645: Fix the electric noise due to the CBJ contacts floating
  drm/amd/display: Set color_mgmt_changed to true on unsuspend
  net: usb: qmi_wwan: add Telit FN920C04 compositions
  wifi: cfg80211: fix the order of arguments for trace events of the tx_rx_evt class
  nilfs2: fix potential hang in nilfs_detach_log_writer()
  nilfs2: fix unexpected freezing of nilfs_segctor_sync()
  net: smc91x: Fix m68k kernel compilation for ColdFire CPU
  ring-buffer: Fix a race between readers and resize checks
  speakup: Fix sizeof() vs ARRAY_SIZE() bug
  tty: n_gsm: fix possible out-of-bounds in gsm0_receive()
  x86/tsc: Trust initial offset in architectural TSC-adjust MSRs
  Linux 5.4.277
  docs: kernel_include.py: Cope with docutils 0.21
  serial: kgdboc: Fix NMI-safety problems from keyboard reset code
  usb: typec: ucsi: displayport: Fix potential deadlock
  drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper()
  btrfs: add missing mutex_unlock in btrfs_relocate_sys_chunks()
  arm64: dts: qcom: Fix 'interrupt-map' parent address cells
  firmware: arm_scmi: Harden accesses to the reset domains
  smb: client: fix potential OOBs in smb2_parse_contexts()
  net: bcmgenet: synchronize UMAC_CMD access
  net: bcmgenet: synchronize use of bcmgenet_set_rx_mode()
  net: bcmgenet: synchronize EXT_RGMII_OOB_CTRL access
  net: bcmgenet: keep MAC in reset until PHY is up
  Revert "net: bcmgenet: use RGMII loopback for MAC reset"
  Revert "selftests: mm: fix map_hugetlb failure on 64K page size systems"
  ext4: fix bug_on in __es_tree_search
  pinctrl: core: handle radix_tree_insert() errors in pinctrl_register_one_pin()
  Linux 5.4.276
  pinctrl: mediatek: paris: Fix PIN_CONFIG_INPUT_SCHMITT_ENABLE readback
  pinctrl: mediatek: remove set but not used variable 'e'
  pinctrl: mediatek: Fix some off by one bugs
  pinctrl: mediatek: Fix fallback behavior for bias_set_combo
  regulator: core: fix debugfs creation regression
  net: fix out-of-bounds access in ops_init
  drm/vmwgfx: Fix invalid reads in fence signaled events
  dyndbg: fix old BUG_ON in >control parser
  tipc: fix UAF in error path
  usb: gadget: f_fs: Fix a race condition when processing setup packets.
  usb: gadget: composite: fix OS descriptors w_value logic
  firewire: nosy: ensure user_length is taken into account when fetching packet contents
  net: qede: use return from qede_parse_flow_attr() for flower
  net: qede: sanitize 'rc' in qede_add_tc_flower_fltr()
  ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action()
  net: bridge: fix corrupted ethernet header on multicast-to-unicast
  phonet: fix rtm_phonet_notify() skb allocation
  rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation
  Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout
  Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout
  tcp: Use refcount_inc_not_zero() in tcp_twsk_unique().
  tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets
  xfrm: Preserve vlan tags for transport mode software GRO
  pinctrl: mediatek: Fix fallback call path
  net:usb:qmi_wwan: support Rolling modules
  fs/9p: drop inodes immediately on non-.L too
  clk: Don't hold prepare_lock when calling kref_put()
  gpio: crystalcove: Use -ENOTSUPP consistently
  gpio: wcove: Use -ENOTSUPP consistently
  9p: explicitly deny setlease attempts
  fs/9p: translate O_TRUNC into OTRUNC
  fs/9p: only translate RWX permissions for plain 9P2000
  selftests: timers: Fix valid-adjtimex signed left-shift undefined behavior
  MIPS: scall: Save thread_info.syscall unconditionally on entry
  gpu: host1x: Do not setup DMA for virtual devices
  scsi: target: Fix SELinux error when systemd-modules loads the target module
  btrfs: always clear PERTRANS metadata during commit
  btrfs: make btrfs_clear_delalloc_extent() free delalloc reserve
  tools/power turbostat: Fix Bzy_MHz documentation typo
  tools/power turbostat: Fix added raw MSR output
  firewire: ohci: mask bus reset interrupts between ISR and bottom half
  ata: sata_gemini: Check clk_enable() result
  net: bcmgenet: Reset RBUF on first open
  ALSA: line6: Zero-initialize message buffers
  scsi: bnx2fc: Remove spin_lock_bh while releasing resources after upload
  net: mark racy access on sk->sk_rcvbuf
  wifi: cfg80211: fix rdev_dump_mpp() arguments order
  wifi: mac80211: fix ieee80211_bss_*_flags kernel-doc
  gfs2: Fix invalid metadata access in punch_hole
  scsi: lpfc: Update lpfc_ramp_down_queue_handler() logic
  clk: sunxi-ng: h6: Reparent CPUX during PLL CPUX rate change
  tipc: fix a possible memleak in tipc_buf_append
  net: bridge: fix multicast-to-unicast with fraglist GSO
  net: dsa: mv88e6xxx: Fix number of databases for 88E6141 / 88E6341
  net: dsa: mv88e6xxx: Add number of MACs in the ATU
  net: qede: use return from qede_parse_flow_attr() for flow_spec
  net l2tp: drop flow hash on forward
  nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment().
  bna: ensure the copied buf is NUL terminated
  s390/mm: Fix clearing storage keys for huge pages
  s390/mm: Fix storage key clearing for guest huge pages
  pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map()
  power: rt9455: hide unused rt9455_boost_voltage_values
  nfs: Handle error of rpc_proc_register() in nfs_net_init().
  nfs: make the rpc_stat per net namespace
  nfs: expose /proc/net/sunrpc/nfs in net namespaces
  sunrpc: add a struct rpc_stats arg to rpc_create_args
  pinctrl: mediatek: paris: Rework support for PIN_CONFIG_{INPUT,OUTPUT}_ENABLE
  pinctrl: mediatek: paris: Rework mtk_pinconf_{get,set} switch/case logic
  pinctrl: mediatek: paris: Fix PIN_CONFIG_BIAS_* readback
  pinctrl: mediatek: remove shadow variable declaration
  pinctrl: mediatek: Backward compatible to previous Mediatek's bias-pull usage
  pinctrl: mediatek: Refine mtk_pinconf_get()
  pinctrl: mediatek: Refine mtk_pinconf_get() and mtk_pinconf_set()
  pinctrl: mediatek: Supporting driving setting without mapping current to register value
  pinctrl: mediatek: Check gpio pin number and use binary search in mtk_hw_pin_field_lookup()
  pinctrl: core: delete incorrect free in pinctrl_enable()
  wifi: nl80211: don't free NULL coalescing rule
  dmaengine: Revert "dmaengine: pl330: issue_pending waits until WFP state"
  dmaengine: pl330: issue_pending waits until WFP state
  Revert "clk: Get runtime PM before walking tree during disable_unused"
  Linux 5.4.275
  serial: core: fix kernel-doc for uart_port_unlock_irqrestore()
  udp: preserve the connected status if only UDP cmsg
  dm: limit the number of targets and parameter size area
  bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS
  HID: i2c-hid: remove I2C_HID_READ_PENDING flag to prevent lock-up
  i2c: smbus: fix NULL function pointer dereference
  idma64: Don't try to serve interrupts when device is powered off
  dmaengine: owl: fix register access functions
  tcp: Fix NEW_SYN_RECV handling in inet_twsk_purge()
  tcp: Clean up kernel listener's reqsk in inet_twsk_purge()
  mtd: diskonchip: work around ubsan link failure
  stackdepot: respect __GFP_NOLOCKDEP allocation flag
  net: b44: set pause params only when interface is up
  ethernet: Add helper for assigning packet type when dest address does not match device address
  irqchip/gic-v3-its: Prevent double free on error
  drm/amdgpu: Fix leak when GPU memory allocation fails
  arm64: dts: rockchip: enable internal pull-up for Q7_THRM# on RK3399 Puma
  btrfs: fix information leak in btrfs_ioctl_logical_to_ino()
  Bluetooth: btusb: Add Realtek RTL8852BE support ID 0x0bda:0x4853
  Bluetooth: Fix type of len in {l2cap,sco}_sock_getsockopt_old()
  tracing: Increase PERF_MAX_TRACE_SIZE to handle Sentinel1 and docker together
  tracing: Show size of requested perf buffer
  net/mlx5e: Fix a race in command alloc flow
  Revert "crypto: api - Disallow identical driver names"
  drm/amdgpu: validate the parameters of bo mapping operations more clearly
  amdgpu: validate offset_in_bo of drm_amdgpu_gem_va
  drm/amdgpu: restrict bo mapping within gpu address limits
  serial: mxs-auart: add spinlock around changing cts state
  serial: core: Provide port lock wrappers
  af_unix: Suppress false-positive lockdep splat for spin_lock() in __unix_gc().
  iavf: Fix TC config comparison with existing adapter TC config
  i40e: Do not use WQ_MEM_RECLAIM flag for workqueue
  mlxsw: spectrum_acl_tcam: Fix memory leak when canceling rehash work
  mlxsw: spectrum_acl_tcam: Fix incorrect list API usage
  mlxsw: spectrum_acl_tcam: Fix warning during rehash
  mlxsw: spectrum_acl_tcam: Fix memory leak during rehash
  mlxsw: spectrum_acl_tcam: Rate limit error message
  mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash
  mlxsw: spectrum_acl_tcam: Fix possible use-after-free during activity update
  mlxsw: spectrum_acl_tcam: Fix race during rehash delayed work
  net: openvswitch: Fix Use-After-Free in ovs_ct_exit
  ipvs: Fix checksumming on GSO of SCTP packets
  net: gtp: Fix Use-After-Free in gtp_dellink
  net: usb: ax88179_178a: stop lying about skb->truesize
  NFC: trf7970a: disable all regulators on removal
  mlxsw: core: Unregister EMAD trap using FORWARD action
  vxlan: drop packets from invalid src-address
  ARC: [plat-hsdk]: Remove misplaced interrupt-cells property
  arm64: dts: mediatek: mt2712: fix validation errors
  arm64: dts: mt2712: add ethernet device node
  arm64: dts: mediatek: mt7622: drop "reset-names" from thermal block
  arm64: dts: mediatek: mt7622: fix ethernet controller "compatible"
  arm64: dts: mediatek: mt7622: fix IR nodename
  arm64: dts: rockchip: enable internal pull-up on PCIE_WAKE# for RK3399 Puma
  arm64: dts: rockchip: fix alphabetical ordering RK3399 puma
  KVM: async_pf: Cleanup kvm_setup_async_pf()
  nilfs2: fix OOB in nilfs_set_de_type
  nouveau: fix instmem race condition around ptr stores
  fs: sysfs: Fix reference leak in sysfs_break_active_protection()
  speakup: Avoid crash on very long word
  usb: Disable USB3 LPM at shutdown
  usb: dwc2: host: Fix dereference issue in DDMA completion flow.
  Revert "usb: cdc-wdm: close race between read and workqueue"
  USB: serial: option: add Telit FN920C04 rmnet compositions
  USB: serial: option: add Rolling RW101-GL and RW135-GL support
  USB: serial: option: support Quectel EM060K sub-models
  USB: serial: option: add Lonsung U8300/U9300 product
  USB: serial: option: add support for Fibocom FM650/FG650
  USB: serial: option: add Fibocom FM135-GL variants
  serial/pmac_zilog: Remove flawed mitigation for rx irq flood
  comedi: vmk80xx: fix incomplete endpoint checking
  binder: check offset alignment in binder_get_object()
  x86/cpufeatures: Fix dependencies for GFNI, VAES, and VPCLMULQDQ
  clk: Get runtime PM before walking tree during disable_unused
  clk: Initialize struct clk_core kref earlier
  clk: Print an info line before disabling unused clocks
  clk: remove extra empty line
  clk: Mark 'all_lists' as const
  clk: Remove prepare_lock hold assertion in __clk_release()
  drm: nv04: Fix out of bounds access
  RDMA/mlx5: Fix port number for counter query in multi-port configuration
  RDMA/rxe: Fix the problem "mutex_destroy missing"
  tun: limit printing rate when illegal packet received by tun dev
  netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get()
  Revert "tracing/trigger: Fix to return error if failed to alloc snapshot"
  kprobes: Fix possible use-after-free issue on kprobe registration
  selftests/ftrace: Limit length in subsystem-enable tests
  btrfs: record delayed inode root in transaction
  x86/apic: Force native_apic_mem_read() to use the MOV instruction
  selftests: timers: Fix abs() warning in posix_timers test
  vhost: Add smp_rmb() in vhost_vq_avail_empty()
  drm/client: Fully protect modes[] with dev->mode_config.mutex
  btrfs: qgroup: correctly model root qgroup rsv in convert
  net: ena: Fix potential sign extension issue
  af_unix: Fix garbage collector racing against connect()
  af_unix: Do not use atomic ops for unix_sk(sk)->inflight.
  net/mlx5: Properly link new fs rules into the tree
  ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr
  ipv4/route: avoid unused-but-set-variable warning
  ipv6: fib: hide unused 'pn' variable
  geneve: fix header validation in geneve[6]_xmit_skb
  u64_stats: fix u64_stats_init() for lockdep when used repeatedly in one file
  net: openvswitch: fix unwanted error log on timeout policy probing
  nouveau: fix function cast warning
  Bluetooth: Fix memory leak in hci_req_sync_complete()
  batman-adv: Avoid infinite loop trying to resize local TT

Change-Id: I36df890fc0cf15277cf5d6be8f56774233fb4431
Signed-off-by: kamasali Satyanarayan <quic_kamasali@quicinc.com>
2024-10-15 16:13:40 +05:30
Gao Wang
a721c06f7d msm: virtio_npu: Fix use-after-free issue in unmap_buf
address the security CR of virtio_npu driver

Change-Id: Ibf656fa76dedb19086b75d8bf519b2f415ac8d22
Signed-off-by: Gao Wang <quic_gaowang@quicinc.com>
2024-10-14 00:51:57 -07:00
gaowang
79c14fa641 msm: virtio_npu: Fix use-after-free issue in virt_npu_map_buf
address the security CR of virtio_npu driver

Change-Id: Ib77014bc12490e7b09367354024baa2754d3e433
Signed-off-by: gaowang <quic_gaowang@quicinc.com>
2024-10-13 19:53:36 -07:00
Linux Build Service Account
d2648db3ba Merge c3d6993d5c on remote branch
Change-Id: Ic2f0d626a18077e9fc47e067669813bdc1b644f4
2024-09-18 04:13:49 -07:00
Anil Veshala Veshala
c5539fb1c2 i2c: i2c-master-msm-geni: add null pointer check in event call back
Currently i2c geni driver doesn't have null pointer check condition
in event call back function. If any invalid event is coming from GSI,
i2c geni driver accessing null pointer which is causing crash.
To solve this added null pointer checks in event call back functions.

Change-Id: Ie14a40eee846c0ea29bec512d6320e9548c509b5
Signed-off-by: Anil Veshala Veshala <quic_aveshala@quicinc.com>
2024-09-18 02:50:52 -07:00
QCTECMDR Service
e4c2f15ba5 Merge "firmware: qcom_scm: handle echo b > /proc/sysrq-trigger" 2024-09-17 03:35:03 -07:00
QCTECMDR Service
4adbc0218a Merge "msm: ep_pcie: Disable hot reset and ignore linkdown" 2024-09-16 07:20:29 -07:00
QCTECMDR Service
94c4fda252 Merge "scripts: mod: replace with a safe function" 2024-09-16 03:42:38 -07:00
Mukesh Ojha
b2af2b5f9f firmware: qcom_scm: handle echo b > /proc/sysrq-trigger
Introduce restart handler to handle "echo b > /proc/sysrq-trigger".
One special thing with 'b' kind of reboot is, it does not call reboot
notifiers and call restart handler right a way and that does not seems
to work for blair SoC and it goes to dump mode.

Keep this restart handler priority to 201 greater than 200 which is the
priority for msm-poweroff to make reboot work cleaner.

Change-Id: I42f8c0fde29af402096d760c37ec2d8b3a85439a
Signed-off-by: Mukesh Ojha <quic_mojha@quicinc.com>
Signed-off-by: Sayan Dey <quic_sayand@quicinc.com>
2024-09-16 12:49:11 +05:30
Vishnu Teja
f1d1549d8e scripts: mod: replace with a safe function
Add safe function vsnprintf instead of sprintf
by passing size as argument.

Change-Id: Ibd21a0c7d9039543dee32c1297035ed9984ed748
Signed-off-by: Vishnu Teja <quic_vteja@quicinc.com>
2024-09-14 01:04:36 -07:00
Qiang Yu
32de0804b1 msm: ep_pcie: Disable hot reset and ignore linkdown
Intel host tends to retrain the link if device doesn't send PM_Enter_L23
in time, leading to linkdown and hot reset in device side. The hot reset
here even results to PERST# timeout and device crash to PBL, which is
not expected.

Since we are in the entry of shutdown the link when linkdown happen, it
makes sense to ignore the linkdown. To avoid device crash because of
PERST# timeout, disable hot reset in pm_turnoff irq and reenable it when
we do linktrain again.

Change-Id: I87961faaae2a14c9a5e7d24543b416914076dd2e
Signed-off-by: Qiang Yu <quic_qianyu@quicinc.com>
Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
2024-09-13 17:38:37 +05:30
Yuanfang Zhang
bb76f075ca coresight-tmc: Replace deprecated function
Use 'scnprintf' to replace deprecated function 'sprintf'.

Change-Id: Ic258e7dfe719f1f871f9c9eb5988609a5f3b6284
Signed-off-by: Yuanfang Zhang <quic_yuanfang@quicinc.com>
2024-09-11 18:53:09 +08:00
Carlos Llamas
d62984adb1 ANDROID: delete tool added by mistake
Remove the gen-hyprel binary added accidentally while backporting a
patch into an older branch. The tool gets generated in newer builds and
wasn't part of the gitignore file here.

Fixes: d1e87637cd ("BACKPORT: FROMGIT: binder: frozen notification")
Change-Id: I103358cb2ca9c5fb934f047033e44c04fe85298d
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-09-09 22:59:15 +00:00
Carlos Llamas
a03c6437cf ANDROID: fix ENOMEM check of binder_proc_ext
The check should be done against 'eproc' before it gets dereferenced.

Fixes: d49297739550 ("BACKPORT: binder: use euid from cred instead of using task")
Change-Id: Ief0c08212c4da8bdfdf628474de9dd30ee5a8db0
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-09-07 22:04:18 +00:00
Carlos Llamas
be02156857 ANDROID: binder: fix KMI issues due to frozen notification
The patches to support binder's frozen notification feature break the
KMI. This change fixes such issues by (1) moving proc->delivered_freeze
into the existing proc_wrapper struction, (2) dropping the frozen stats
support and (3) amending the STG due to a harmless enum binder_work_type
addition.

These are the reported KMI issues fixed by this patch:

  function symbol 'int __traceiter_binder_transaction_received(void*, struct binder_transaction*)' changed
    CRC changed from 0x74e9c98b to 0xfe0f8640

  type 'struct binder_proc' changed
    byte size changed from 584 to 632
    member 'struct list_head delivered_death' changed
      offset changed by 256
    member 'struct list_head delivered_freeze' was added
    13 members ('u32 max_threads' .. 'u64 android_oem_data1') changed
      offset changed by 384

  type 'struct binder_thread' changed
    byte size changed from 464 to 496
    2 members ('atomic_t tmp_ref' .. 'bool is_dead') changed
      offset changed by 224
    4 members ('struct task_struct* task' .. 'enum binder_prio_state prio_state') changed
      offset changed by 256

  type 'struct binder_stats' changed
    byte size changed from 216 to 244
    member changed from 'atomic_t br[21]' to 'atomic_t br[23]'
      type changed from 'atomic_t[21]' to 'atomic_t[23]'
        number of elements changed from 21 to 23
    member changed from 'atomic_t bc[19]' to 'atomic_t bc[22]'
      offset changed from 672 to 736
      type changed from 'atomic_t[19]' to 'atomic_t[22]'
        number of elements changed from 19 to 22
    member changed from 'atomic_t obj_created[7]' to 'atomic_t obj_created[8]'
      offset changed from 1280 to 1440
      type changed from 'atomic_t[7]' to 'atomic_t[8]'
        number of elements changed from 7 to 8
    member changed from 'atomic_t obj_deleted[7]' to 'atomic_t obj_deleted[8]'
      offset changed from 1504 to 1696
      type changed from 'atomic_t[7]' to 'atomic_t[8]'
        number of elements changed from 7 to 8

  type 'enum binder_work_type' changed
    enumerator 'BINDER_WORK_FROZEN_BINDER' (10) was added
    enumerator 'BINDER_WORK_CLEAR_FREEZE_NOTIFICATION' (11) was added

Bug: 363013421
Change-Id: If9f1f14a2eda215a4c9cb0823c50c8e0e8079ef1
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-09-07 22:04:18 +00:00
Yu-Ting Tseng
1063c2fa62 BACKPORT: FROMGIT: binder: frozen notification binder_features flag
Add a flag to binder_features to indicate that the freeze notification
feature is available.

Signed-off-by: Yu-Ting Tseng <yutingtseng@google.com>
Acked-by: Carlos Llamas <cmllamas@google.com>
Link: https://lore.kernel.org/r/20240709070047.4055369-6-yutingtseng@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 363013421
(cherry picked from commit 30b968b002a92870325a5c9d1ce78eba0ce386e7
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
 char-misc-next)
Change-Id: Ic26c8ae42d27c6fd8f5daed5eecabd1652e29502
[cmllamas: fix trivial conflicts due to missing extended_error]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-09-07 22:04:18 +00:00
Yu-Ting Tseng
d1e87637cd BACKPORT: FROMGIT: binder: frozen notification
Frozen processes present a significant challenge in binder transactions.
When a process is frozen, it cannot, by design, accept and/or respond to
binder transactions. As a result, the sender needs to adjust its
behavior, such as postponing transactions until the peer process
unfreezes. However, there is currently no way to subscribe to these
state change events, making it impossible to implement frozen-aware
behaviors efficiently.

Introduce a binder API for subscribing to frozen state change events.
This allows programs to react to changes in peer process state,
mitigating issues related to binder transactions sent to frozen
processes.

Implementation details:
For a given binder_ref, the state of frozen notification can be one of
the followings:
1. Userspace doesn't want a notification. binder_ref->freeze is null.
2. Userspace wants a notification but none is in flight.
   list_empty(&binder_ref->freeze->work.entry) = true
3. A notification is in flight and waiting to be read by userspace.
   binder_ref_freeze.sent is false.
4. A notification was read by userspace and kernel is waiting for an ack.
   binder_ref_freeze.sent is true.

When a notification is in flight, new state change events are coalesced into
the existing binder_ref_freeze struct. If userspace hasn't picked up the
notification yet, the driver simply rewrites the state. Otherwise, the
notification is flagged as requiring a resend, which will be performed
once userspace acks the original notification that's inflight.

See https://r.android.com/3070045 for how userspace is going to use this
feature.

Signed-off-by: Yu-Ting Tseng <yutingtseng@google.com>
Acked-by: Carlos Llamas <cmllamas@google.com>
Link: https://lore.kernel.org/r/20240709070047.4055369-4-yutingtseng@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 363013421
(cherry picked from commit d579b04a52a183db47dfcb7a44304d7747d551e1
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
 char-misc-next)
Change-Id: I5dd32abba932ca7d03ae58660143e075ed778b81
[cmllamas: fix merge conflicts due to missing 0567461a7a6e]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-09-07 22:04:18 +00:00
Carlos Llamas
8c4165a043 BACKPORT: selftests/binderfs: add test for feature files
Verify that feature files are created successfully after mounting a
binderfs instance. Note that only "oneway_spam_detection" feature is
tested with this patch as it is currently the only feature listed.

Acked-by: Christian Brauner <christian.brauner@ubuntu.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Link: https://lore.kernel.org/r/20210715031805.1725878-3-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 07e913418ce4ba5eb620dd4668bf91ec94e11136)
Bug: 191910201
Signed-off-by: Carlos Llamas <cmllamas@google.com>
[cmllamas: fix merge issues due to missing eaa163caa4cc]
Change-Id: I86d7ef34b3099c8714c319e48029aaf3dbf87081
2024-09-07 22:04:18 +00:00
Carlos Llamas
4d4f8b7a7f UPSTREAM: docs: binderfs: add section about feature files
Document how binder feature files can be used to determine whether a
feature is supported by the binder driver. "oneway_spam_detection" is
used as an example as it is the first available feature file.

Acked-by: Christian Brauner <christian.brauner@ubuntu.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Link: https://lore.kernel.org/r/20210715031805.1725878-2-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 06e1721d2a265d1247093f5ad5ae2958ef10a604)
Bug: 191910201
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Change-Id: I9c4542e0ee65dd94a492fe0440ba8f1a48d8b797
2024-09-07 22:04:18 +00:00
Carlos Llamas
460de65538 BACKPORT: binderfs: add support for feature files
Provide userspace with a mechanism to discover features supported by
the binder driver to refrain from using any unsupported ones in the
first place. Starting with "oneway_spam_detection" only new features
are to be listed under binderfs and all previous ones are assumed to
be supported.

Assuming an instance of binderfs has been mounted at /dev/binderfs,
binder feature files can be found under /dev/binderfs/features/.
Usage example:

  $ mkdir /dev/binderfs
  $ mount -t binder binder /dev/binderfs
  $ cat /dev/binderfs/features/oneway_spam_detection
  1

Acked-by: Christian Brauner <christian.brauner@ubuntu.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Link: https://lore.kernel.org/r/20210715031805.1725878-1-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit fc470abf54b2bd6e539065e07905e767b443d719)
Bug: 191910201
Signed-off-by: Carlos Llamas <cmllamas@google.com>
[cmllamas: fix merge conflicts due to missing 095cf502b31e]
Change-Id: Ia5c03aa1881981bee26459e741134b83d5b59693
2024-09-07 22:04:17 +00:00
Carlos Llamas
31f1f4b2aa FROMLIST: binder: fix memory leaks of spam and pending work
commit 1aa3aaf8953c84bad398adf6c3cabc9d6685bf7d upstream

A transaction complete work is allocated and queued for each
transaction. Under certain conditions the work->type might be marked as
BINDER_WORK_TRANSACTION_ONEWAY_SPAM_SUSPECT to notify userspace about
potential spamming threads or as BINDER_WORK_TRANSACTION_PENDING when
the target is currently frozen.

However, these work types are not being handled in binder_release_work()
so they will leak during a cleanup. This was reported by syzkaller with
the following kmemleak dump:

BUG: memory leak
unreferenced object 0xffff88810e2d6de0 (size 32):
  comm "syz-executor338", pid 5046, jiffies 4294968230 (age 13.590s)
  hex dump (first 32 bytes):
    e0 6d 2d 0e 81 88 ff ff e0 6d 2d 0e 81 88 ff ff  .m-......m-.....
    04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
  backtrace:
    [<ffffffff81573b75>] kmalloc_trace+0x25/0x90 mm/slab_common.c:1114
    [<ffffffff83d41873>] kmalloc include/linux/slab.h:599 [inline]
    [<ffffffff83d41873>] kzalloc include/linux/slab.h:720 [inline]
    [<ffffffff83d41873>] binder_transaction+0x573/0x4050 drivers/android/binder.c:3152
    [<ffffffff83d45a05>] binder_thread_write+0x6b5/0x1860 drivers/android/binder.c:4010
    [<ffffffff83d486dc>] binder_ioctl_write_read drivers/android/binder.c:5066 [inline]
    [<ffffffff83d486dc>] binder_ioctl+0x1b2c/0x3cf0 drivers/android/binder.c:5352
    [<ffffffff816b25f2>] vfs_ioctl fs/ioctl.c:51 [inline]
    [<ffffffff816b25f2>] __do_sys_ioctl fs/ioctl.c:871 [inline]
    [<ffffffff816b25f2>] __se_sys_ioctl fs/ioctl.c:857 [inline]
    [<ffffffff816b25f2>] __x64_sys_ioctl+0xf2/0x140 fs/ioctl.c:857
    [<ffffffff84b30008>] do_syscall_x64 arch/x86/entry/common.c:50 [inline]
    [<ffffffff84b30008>] do_syscall_64+0x38/0xb0 arch/x86/entry/common.c:80
    [<ffffffff84c0008b>] entry_SYSCALL_64_after_hwframe+0x63/0xcd

Fix the leaks by kfreeing these work types in binder_release_work() and
handle them as a BINDER_WORK_TRANSACTION_COMPLETE cleanup.

Cc: stable@vger.kernel.org
Fixes: a7dc1e6f99df ("binder: tell userspace to dump current backtrace when detected oneway spamming")
Reported-by: syzbot+7f10c1653e35933c0f1e@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=7f10c1653e35933c0f1e
Suggested-by: Alice Ryhl <aliceryhl@google.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Acked-by: Todd Kjos <tkjos@google.com>
Link: https://lore.kernel.org/r/20230922175138.230331-1-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[cmllamas: backport to v5.15 by dropping BINDER_WORK_TRANSACTION_PENDING
 as commit 0567461a7a6e is not present. Remove fixes tag accordingly.]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>

Link: https://lore.kernel.org/all/20231208034842.997899-1-cmllamas@google.com/
Change-Id: I8e1ee7af87ef5706544e4f320e9498b8f4855a6b
[cmllamas: also backport to v5.4 to fix OOT 8a09136176f6]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-09-07 22:03:49 +00:00
Li Li
334fe73bdd FROMGIT: Binder: add TF_UPDATE_TXN to replace outdated txn
When the target process is busy, incoming oneway transactions are
queued in the async_todo list. If the clients continue sending extra
oneway transactions while the target process is frozen, this queue can
become too large to accommodate new transactions. That's why binder
driver introduced ONEWAY_SPAM_DETECTION to detect this situation. It's
helpful to debug the async binder buffer exhausting issue, but the
issue itself isn't solved directly.

In real cases applications are designed to send oneway transactions
repeatedly, delivering updated inforamtion to the target process.
Typical examples are Wi-Fi signal strength and some real time sensor
data. Even if the apps might only care about the lastet information,
all outdated oneway transactions are still accumulated there until the
frozen process is thawed later. For this kind of situations, there's
no existing method to skip those outdated transactions and deliver the
latest one only.

This patch introduces a new transaction flag TF_UPDATE_TXN. To use it,
use apps can set this new flag along with TF_ONE_WAY. When such an
oneway transaction is to be queued into the async_todo list of a frozen
process, binder driver will check if any previous pending transactions
can be superseded by comparing their code, flags and target node. If
such an outdated pending transaction is found, the latest transaction
will supersede that outdated one. This effectively prevents the async
binder buffer running out and saves unnecessary binder read workloads.

Acked-by: Todd Kjos <tkjos@google.com>
Signed-off-by: Li Li <dualli@google.com>
Link: https://lore.kernel.org/r/20220526220018.3334775-2-dualli@chromium.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bug: 231624308
Test: manually check async binder buffer size of frozen apps
Test: stress test with kernel 4.14/4.19/5.10/5.15
(cherry picked from commit 9864bb4801331daa48514face9d0f4861e4d485b
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
  char-misc-next)
Change-Id: I1c4bff1eda1ca15aaaad5bf696c8fc00be743176
2024-09-07 22:03:08 +00:00
Hang Lu
2bfddf30aa BACKPORT: binder: tell userspace to dump current backtrace when detected oneway spamming
When async binder buffer got exhausted, some normal oneway transactions
will also be discarded and may cause system or application failures. By
that time, the binder debug information we dump may not be relevant to
the root cause. And this issue is difficult to debug if without the
backtrace of the thread sending spam.

This change will send BR_ONEWAY_SPAM_SUSPECT to userspace when oneway
spamming is detected, request to dump current backtrace. Oneway spamming
will be reported only once when exceeding the threshold (target process
dips below 80% of its oneway space, and current process is responsible
for either more than 50 transactions, or more than 50% of the oneway
space). And the detection will restart when the async buffer has
returned to a healthy state.

Acked-by: Todd Kjos <tkjos@google.com>
Signed-off-by: Hang Lu <hangl@codeaurora.org>
Link: https://lore.kernel.org/r/1617961246-4502-3-git-send-email-hangl@codeaurora.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 181190340
Change-Id: Id3d2526099bc89f04d8ad3ad6e48141b2a8f2515
(cherry picked from commit a7dc1e6f99df59799ab0128d9c4e47bbeceb934d)
Signed-off-by: Hang Lu <hangl@codeaurora.org>
[cmllamas: fix trivial merge issue]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-09-07 22:02:42 +00:00
Linux Build Service Account
9bdc77e622 Merge "msm-5.4.c3: qseecom: Fix possible race condition" into kernel.lnx.5.4.r1-rel 2024-09-03 03:33:24 -07:00
Linux Build Service Account
2913fc224e Merge "adsprpc: Handle UAF scenario in put_args" into kernel.lnx.5.4.r1-rel 2024-09-03 03:33:22 -07:00
Linux Build Service Account
b28cf76a9a Merge "msm: adsprpc: Avoid taking reference for group_info" into kernel.lnx.5.4.r1-rel 2024-09-03 03:33:20 -07:00
Divisha Bisht
3a617351ae msm-5.4.c3: qseecom: Fix possible race condition
Fix possible race condition in data->type value in case of multithreaded
listener or app IOCTLs.

For example, below could cause inconsistent data->type value while
racing belows IOCTLs

Thread1 with QSEECOM_IOCTL_REGISTER_LISTENER_REQ
Thread2 with QSEECOM_IOCTL_UNREGISTER_LISTENER_REQ.

Change-Id: I436b63c044a66c324d94db27566a7be70981bd6b
Signed-off-by: Divisha Bisht <quic_divibish@quicinc.com>
(cherry picked from commit f0e3f64088)
2024-09-03 00:13:12 -07:00
Linux Build Service Account
119c1bcc29 Merge 0fc0638ba8 on remote branch
Change-Id: I0ac91223cf762a6543e048c9fb59e52ea1098265
2024-08-30 04:52:01 -07:00
QCTECMDR Service
c3d6993d5c Merge "msm-5.4.c3: qseecom: Fix possible race condition" 2024-08-30 04:08:23 -07:00
ANANDU KRISHNAN E
20018f6ad2 msm: adsprpc: Avoid taking reference for group_info
Currently, the get_current_groups API accesses group info, which
increases the usage refcount. If the IOCTL using the
get_current_groups API is called many times, the usage counter
overflows. To avoid this, access group info without taking a
reference. A reference is not required as group info is not
released during the IOCTL call.

Change-Id: Ib4de80cac8b36f73d8f5c6dd9824722153189285
Signed-off-by: ANANDU KRISHNAN E <quic_anane@quicinc.com>
(cherry picked from commit de9f4fe6f8)
2024-08-30 01:59:00 -07:00
Santosh Sakore
8e0a90efc0 adsprpc: Handle UAF scenario in put_args
Currently, the DSP updates header buffers with unused DMA handle fds.
In the put_args section, if any DMA handle FDs are present in the
header buffer, the corresponding map is freed. However, since the
header buffer is exposed to users in unsigned PD, users can update
invalid FDs. If this invalid FD matches with any FD that is already
in use, it could lead to a use-after-free (UAF) vulnerability.
As a solution,add DMA handle references for DMA FDs, and the map for
the FD will be freed only when a reference is found.

Acked-by: Om Deore <quic_odeore@quicinc.com>
Change-Id: I19ae21230bf11fe89858b10c9069a5daccabc392
Signed-off-by: Santosh Sakore <quic_ssakore@quicinc.com>
(cherry picked from commit c6e7698c0c)
2024-08-30 01:52:15 -07:00
Divisha Bisht
f0e3f64088 msm-5.4.c3: qseecom: Fix possible race condition
Fix possible race condition in data->type value in case of multithreaded
listener or app IOCTLs.

For example, below could cause inconsistent data->type value while
racing belows IOCTLs

Thread1 with QSEECOM_IOCTL_REGISTER_LISTENER_REQ
Thread2 with QSEECOM_IOCTL_UNREGISTER_LISTENER_REQ.

Change-Id: I436b63c044a66c324d94db27566a7be70981bd6b
Signed-off-by: Divisha Bisht <quic_divibish@quicinc.com>
2024-08-29 22:14:16 -07:00
Rajashekar kuruva
54d3e3ca11 USB: storage: Replace the sprintf with scnprintf
'sprintf' has been deprecated, hence replace it with
a safer function scnprintf.

Change-Id: I9bc8e3dfd2032a0447f38fc98a3ad31d9d609cab
Signed-off-by: Rajashekar kuruva <quic_kuruva@quicinc.com>
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
2024-08-29 21:16:16 -07:00
QCTECMDR Service
83ba639ff8 Merge "adsprpc: Handle UAF scenario in put_args" 2024-08-29 17:29:58 -07:00
Santosh Sakore
c6e7698c0c adsprpc: Handle UAF scenario in put_args
Currently, the DSP updates header buffers with unused DMA handle fds.
In the put_args section, if any DMA handle FDs are present in the
header buffer, the corresponding map is freed. However, since the
header buffer is exposed to users in unsigned PD, users can update
invalid FDs. If this invalid FD matches with any FD that is already
in use, it could lead to a use-after-free (UAF) vulnerability.
As a solution,add DMA handle references for DMA FDs, and the map for
the FD will be freed only when a reference is found.

Acked-by: Om Deore <quic_odeore@quicinc.com>
Change-Id: I19ae21230bf11fe89858b10c9069a5daccabc392
Signed-off-by: Santosh Sakore <quic_ssakore@quicinc.com>
2024-08-29 09:15:22 -07:00
QCTECMDR Service
177e8e0fad Merge "msm: adsprpc: Avoid taking reference for group_info" 2024-08-29 07:38:37 -07:00