Commit graph

904,794 commits

Author SHA1 Message Date
Swathi K
da2bdbc797 msm: adsprpc: Handle UAF in fastrpc debugfs read
Use lock to protect maps amongst multiple
threads to avoid race condition.

Change-Id: Ib0c83dd38ea8e5acb54a1478d10b02385c27ba31
Signed-off-by: Swathi K <quic_c_kataka@quicinc.com>
2022-01-25 02:07:18 -08:00
qctecmdr
d6a2023cd2 Merge "atlantic forwarding driver v1.1.23" 2022-01-23 02:52:10 -08:00
qctecmdr
53d55f6a17 Merge "msm: mhi_dev: Keeping event req memory without clearing in close channel" 2022-01-22 22:25:45 -08:00
qctecmdr
1d97d4833c Merge "msm: mhi: Check ERRDBG registers for device status" 2022-01-22 22:25:45 -08:00
qctecmdr
3035689d90 Merge "atlantic forwarding driver v1.1.22" 2022-01-22 22:25:45 -08:00
qctecmdr
9172e2d415 Merge "defconfig: Enable usb peripheral audio on sdxnightjar" 2022-01-22 22:25:44 -08:00
qctecmdr
ab1815a767 Merge "msm: ipa: match QMI request message length as per IDL" 2022-01-22 22:25:43 -08:00
Sameer Saurabh
2993024f71 atlantic forwarding driver v1.1.23
- Add License headers to atl_dump parser files.
- Fixed cpus_read lock/unlock apis for latest kernel
- Fixed the coalescing APIs for the latest kernel.

Change-Id: Ic01e197195e715eca6388759298d54c4c51b0fe8
Signed-off-by: Sameer Saurabh <ssaurabh@marvell.com>
Git-commit: 5721b086beed3aa34fd8b2c503b169b19b302664
Git-repo: https://github.com/aquantia/linux-4.14-atlantic-forwarding
Signed-off-by: Raihan Haider <quic_rhaider@quicinc.com>
2022-01-18 03:18:01 -08:00
Sameer Saurabh
1298adebf7 atlantic forwarding driver v1.1.22
- Fixed header file and warning complain
- Atl-fwd: Fix name string for mac_phy stats in ethtool-dump
- Atl-fwd: Minor additions to ethtool dump implementation
- Atl-fwd: Add ethtool-dump parser
- ATLDRV-1776: Fix for link flip during IPA ring reconfig
- Atl-fwd: Update crash-dump structure to fixed size structure
- Atl-fwd: Correct driver README file and export couple of APIs
- Atl-fwd: Populate Action resolve table and Ring data in the ethtool-dump
- ATLDRV-1766: Fix to update HWTS ring tail value to HW
- Fix error in populating the extended stats
- AQC113 register dump support
- stats+crashdump implementation draft
- Statistics and crash dump API proposal
- factor out fwd stuff to drop headers dependencies
- ATLDRV-1744] - Add FW version check in Atl-fwd driver
- Move check for PTP UDP packets to separate function, Enable TX pad insert and Handle all FFs in ptp tx TS
- ATLDRV-1582] - Link not Up after FLR reset
- ATLDRV-1653] - Packet with vlan id 1 doesn't get received when rx vlan filter is disabled
- ATLDRV-1659] - Failed to compile with CONFIG_ATLFWD_FWD=y flag on RHEL 8.3 kernel.

Change-Id: Ie1c4a42f9938b0b4dfb26418a755010baadad011
Signed-off-by: Sameer Saurabh <ssaurabh@marvell.com>
Git-commit: d86086216c6d511576d63dd216ab2cc1a8d46309
Git-repo: https://github.com/aquantia/linux-4.14-atlantic-forwarding
Signed-off-by: Raihan Haider <quic_rhaider@quicinc.com>
2022-01-18 03:17:29 -08:00
Rohith Kollalsi
bc6f276779 defconfig: Enable usb peripheral audio on sdxnightjar
This change enables UAC1 and UAC2 protocol for USB peripheral
audio on sdxnightjar.

Change-Id: Icb804ab221a79ed2c581cebd7107a3a3055f40fd
Signed-off-by: Rohith Kollalsi <quic_rkollals@quicinc.com>
2022-01-17 20:36:55 -08:00
Vivek Pernamitta
66a25bec60 msm: mhi: Check ERRDBG registers for device status
Add support to check RDDM cookie in ERRDBG1,ERRDBG2 and ERRDBG3
registers to debug the the bootup failure when device
failed to enter MISSION mode.

Change-Id: Idaf00c082ffda97805e958ae083a331d9f0909e9
Signed-off-by: Vivek Pernamitta <vpernami@codeaurora.org>
Signed-off-by: Ramya SR <rsr@codeaurora.org>
2022-01-17 20:26:58 -08:00
qctecmdr
f89c40b130 Merge "msm: ep_pcie: Adding log for PHY version 7" 2022-01-12 02:39:38 -08:00
qctecmdr
74d8eab695 Merge "msm: ipa: New APIs for PINE+PINE dual wifi support" 2022-01-11 22:19:47 -08:00
Shivali M S
701425a048 msm: ep_pcie: Adding log for PHY version 7
Adding log as 5nm QMP for PHY version 7.

Change-Id: Ia109d971e80d919b29dac5cd3bcbd02019bdfb18
Signed-off-by: Shivali M S <quic_shivms@quicinc.com>
2022-01-11 18:06:38 +05:30
Michael Adisumarta
59ba0d8951 msm: ipa: match QMI request message length as per IDL
Match the QMI request message max length as per IDL changes.

Change-Id: I960c3f07cd738b6324fa4cd13ffe696870f33b4e
Signed-off-by: Michael Adisumarta <quic_madisuma@quicinc.com>
2022-01-10 17:35:05 -08:00
qctecmdr
d70a1a1959 Merge "ubi: Add scrub_all support to UBI" 2022-01-10 09:43:08 -08:00
Sivakanth Vaka
62bdfdbbd5 msm: ipa: New APIs for PINE+PINE dual wifi support
Add per instance APIs to support dual wifi attach.

Change-Id: I9330382fde5e5c727dd5a619b863adbed9f0c661
Signed-off-by: Sivakanth Vaka <svaka@codeaurora.org>
Signed-off-by: Piyush Dhyani <<quic_pdhyani@quicinc.com>
2022-01-10 19:50:18 +05:30
qctecmdr
ab3960446c Merge "msm: mhi_dev: Added mutex lock in mhi_dev_write_channel" 2022-01-10 04:12:07 -08:00
Maulik Shah
36d60ecc86 cpuidle: lpm-levels: Log sched bias reason in trace
Update the reason for cpuidle state selection as scheduler
bias in case bias timer is set. Make use of unused next_event_us
parameter to replace with cpu bias status.

Change-Id: I42950b3d9d85da0ec5245c9cdbc7bcc5d609be3d
Signed-off-by: Maulik Shah <quic_mkshah@quicinc.com>
2022-01-09 23:44:01 -08:00
Sai Chaitanya Kaveti
24ebbc28a2 msm: mhi_dev: Added mutex lock in mhi_dev_write_channel
mhi_dev_write_channel is called by diag channel. While processing it,
reset interrupt is received from host. During the reset sequence the
work queue mhi_sm_wq is getting destroyed in mhi_dev_sm_exit API. When
the mhi_dev_write_channel is resumed, queuing of work is done as part of
mhi_dev_notify_sm_event. Here, as the work queue is destroyed, crash
occurred with a kernel null pointer deference error. This is a race
condition between reset sequence and mhi_dev_notify_sm_event.

To avoid this race condition added a mutex lock mhi_lock in
mhi_dev_write_channel before calling mhi_dev_notify_sm_event.

Change-Id: Idaf1c33c462b6d659f3e5ddb333afe9c6a967fac
Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
2022-01-09 21:19:16 -08:00
Pradeep P V K
ec242d217d ubi: Add scrub_all support to UBI
The data on NAND parts degrades overtime. This is known as data decay.
This decay is accelarated by extreme temperatures.

When data on nand is read over and over again this can also cause decay
of data. This is known as read disturb and can degrade the data in
the page/block that is read and the adjacent cells as well.

This data degrade can be corrected to a certain degree by the nand
driver/controller using the ECC but this is not sufficient specially
in products designed to last years.

The only way to combat the decay is to "refresh" the data by moving it
to a new location.

Add scrub_all support to UBI to facilitate the data refresh.

Change-Id: Ifafb82fe4ddb7120277dcfbbff79b3e087ca344d
Signed-off-by: Nikhilesh Reddy <reddyn@codeaurora.org>
Signed-off-by: Pradeep P V K <quic_pragalla@quicinc.com>
2022-01-09 20:36:47 -08:00
qctecmdr
9ac5330952 Merge "cnss2: Add code to address boot timer debug corner case" 2022-01-07 17:28:16 -08:00
Abhishek Chauhan
39ae50f6ad arch: arm: defconfig: sdxlemur: Enable MACSEC config
This config enables the MACSEC feature.

Change-Id: Ida828ccac6e5bd4ba003bae87157bede10d793ca
Signed-off-by: Abhishek Chauhan <quic_abchauha@quicinc.com>
2022-01-07 11:02:37 -08:00
Mohammed Siddiq
a3bfceb5af cnss2: Add code to address boot timer debug corner case
To handle corner case where mhi power on success and the boot
debug timer handler execution(i.e dumping register) runs parellel.
Even-though the timer is deleted as soon as mhi is powered on,
as this handler is still running it is armed again. Use
del_timer_sync which makes sure the timer is not queued and
the handler is not running upon its exit.

Change-Id: Ie428f3e8af8870018dfed99a5472afca14116bb3
Signed-off-by: Mohammed Siddiq <quic_msiddiq@quicinc.com>
2022-01-07 06:30:14 -08:00
qctecmdr
ced73a7604 Merge "usb: f_fs: Fix Double free from ffs_data_clear" 2022-01-06 20:30:36 -08:00
qctecmdr
48ad9e8cc1 Merge "BTFM SLIM:Add support for pin connectivity test" 2022-01-06 09:56:45 -08:00
Udipto Goswami
4925b858ac usb: f_fs: Fix Double free from ffs_data_clear
Suppose if the userspace using ffs failed to open
ep0, it will issue a ep0_release and continuously try to do
ep0_open until it gets through.
The general operation of ep0_release is the it will destroy
the epfile and free the structures. Whole thing follows this
path:

ffs_ep0_release
	ffs_data_reset
		ffs_data_clear
		kfree(epfiles) mark NULL
		kfree(raw_desc)
	raw_desc =NULL

Now the last few steps of the release process is done without
any mutex. In one functions we do kfree and another we mark
NULL.
This created a potential double free scenario, if a ep0_release
process got preempted before kfree, meanwhile another ep0_release
gets through and freed up the structures but didn't mark NULL
and within that time the preempted process wakes up and tried
to kfree again, due to structure not marked NULL will lead to
double free/invalid free.

Following is the illustration:

     CPU2                                   CPU3

ffs_ep0_release
ffs_data_reset
ffs_data_clear
  kfree(epfiles)
  epfiles = NULL

--preempted--
					ffs_ep0_release
					ffs_data_reset
					ffs_data_clear
					 kfree(epfiles)
					 epfiles = NULL
					 kfree(ffs->raw_descs_data)
					 kfree(ffs->raw_strings)
					 kfree(ffs->stringtabs)
--woke-up--
  kfree(ffs->raw_descs_data)
<use-after-free>
raw_desc =NULL

Fix this by performing kfree and NULL operations under
ffs_data_clear within a mutex lock.

Change-Id: I1c8d92ff99c30165b06bafdd00bc9eb610f3bb76
Signed-off-by: Udipto Goswami <quic_ugoswami@quicinc.com>
2022-01-05 20:27:27 -08:00
Satish Kumar Kodishala
5582182dad BTFM SLIM:Add support for pin connectivity test
Add support for pin connectivity test for BT/FM slimbus

Change-Id: Ia913bcb204f6cccc59790b9a4cef20cbd346f05c
Signed-off-by: Satish Kumar Kodishala <quic_skodisha@quicinc.com>
2022-01-05 04:40:57 -08:00
qctecmdr
a0072c96a9 Merge "usb: f_qdss: Remove usb_request::num_mapped_sgs access" 2022-01-05 00:43:54 -08:00
Pavankumar Kondeti
cb6bfc80a2 arm64: defconfig: Default updates for genericarmv8
Due to changes in Kconfig default options, genericarmv8 is out of sync.
Sync genericarmv8 defconfig to the latest code.

Change-Id: I15d753b9d9429ac623fd7b7e7eaa936b5ed2a8b1
Signed-off-by: Pavankumar Kondeti <quic_pkondeti@quicinc.com>
2022-01-04 13:33:48 +05:30
Pavankumar Kondeti
ea6dfe28c6 usb: f_qdss: Remove usb_request::num_mapped_sgs access
The function drivers have no business accessing usb_request::num_mapped_sgs
field. The UDC will use this field to cache the sgs mapped for a given
request.

Change-Id: I6a8c8c2e52a36caedfe977f517b4c04b1ad0045c
Signed-off-by: Pavankumar Kondeti <quic_pkondeti@quicinc.com>
2022-01-03 19:54:31 -08:00
qctecmdr
6c2909cd85 Merge "mmc: sdhci: Dump registers in case of DATA CRC/timeout errors" 2022-01-02 20:11:32 -08:00
qctecmdr
cace14e427 Merge "input: qcom-hv-haptics: delay hBoost turning off" 2022-01-02 20:11:30 -08:00
qctecmdr
1ebc5a867d Merge "net: macsec: add support for specifying offload upon link creation" 2022-01-02 09:00:23 -08:00
qctecmdr
f885eea1d5 Merge "Merge android11-5.4.147+ (983a7e7) into msm-5.4" 2021-12-31 03:14:52 -08:00
Sarthak Garg
e9a8ea4493 mmc: sdhci: Dump registers in case of DATA CRC/timeout errors
Dump registers in case of Data CRC/timeout errors and print other
useful information.

This contains below patches as well:

4c196de7e0fd mmc: sdhci: rate limit sdhci_dumpregs() prints
16dabee056d4 mmc: sdhci: Add timestamp debug info for data timeout error
e00d878df07e mmc: sdhci: Avoid dumping registers when SD card removed.

Change-Id: I5efe8ff4bacc5da3a05829be7cac4ce40f9fc584
Signed-off-by: Sarthak Garg <quic_sartgarg@quicinc.com>
2021-12-31 13:09:15 +05:30
Mark Starovoytov
a00bf2b8d6 net: macsec: add support for specifying offload upon link creation
This patch adds new netlink attribute to allow a user to (optionally)
specify the desired offload mode immediately upon MACSec link creation.

Separate iproute patch will be required to support this from user space.

Change-Id: I3aa8c9c2eb65763707487267a23ea2e645d1afde
Signed-off-by: Mark Starovoytov <mstarovoitov@marvell.com>
Signed-off-by: Igor Russkikh <irusskikh@marvell.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Git-commit: 791bb3fcafcedd11f9066da9fee9342ecb6904d0
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
Signed-off-by: Karthik Rudrapatna <quic_krudrapa@quicinc.com>
2021-12-28 09:52:18 -08:00
qctecmdr
8cd841af1b Merge "defconfig: sdxlemur: Enable SHA512 crypto in kernel" 2021-12-28 00:41:19 -08:00
Fenglin Wu
8c194abb0e input: qcom-hv-haptics: delay hBoost turning off
Extend hBoost PBS control to all play modes, so hBoost disabling
will be always handled in the driver by triggering the PBS. Also,
delay hBoost turning off 2 seconds after the stop command to
prevent hBoost being enabled/disabled too frequently in repeated
short vibration case, this help to avoid hBoost lockup when it's
enabled and disabled very quickly.

Change-Id: I76263e51ad00a01d95ff7fd7b08c1655031516e6
Signed-off-by: Fenglin Wu <fenglinw@codeaurora.org>
2021-12-28 09:19:53 +08:00
qctecmdr
cfad8c4755 Merge "haven: hh_msgq: Use GFP_ATOMIC allocations in hh_msgq_alloc_entry()" 2021-12-27 16:41:35 -08:00
qctecmdr
b9da8780f6 Merge "icnss: Add check for valid SMEM handler" 2021-12-27 16:41:35 -08:00
qctecmdr
adc0cdd599 Merge "msm: npu: remove asynchronous network execution support" 2021-12-27 16:41:34 -08:00
Ashok Gummadidala
c22e096303 haven: hh_msgq: Use GFP_ATOMIC allocations in hh_msgq_alloc_entry()
Commit 81d6b86bd96e ("haven: hh_msgq: Disallow multiple
registrations with same label") makes the entire gh_msgq_alloc_entry()
function a critical section by calling it with the gh_msgq_cap_list_lock
spinlock held. It also changed the allocation flags of one of the three
memory allocation operations from GFP_KERNEL to GFP_ATOMIC for this
reason, leaving the other two intact. This sometimes leads to the
following:
[    0.052850][    T1] BUG: sleeping function called from invalid context at mm/slab.h:557
[    0.052852][    T1] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 1, name: swapper/0
[    0.052854][    T1] Preemption disabled at:
[    0.052861][    T1] [<ffffffc010578698>] gh_msgq_populate_cap_info+0x3c/0x26c
[    0.052864][    T1] CPU: 0 PID: 1 Comm: swapper/0 Not tainted 5.10.43-debug-04611-g00783572e88c-dirty #1
[    0.052866][    T1] Hardware name: Qualcomm Technologies, Inc. Waipio SVM MTP (DT)
[    0.052868][    T1] Call trace:
[    0.052873][    T1]  dump_backtrace+0x0/0x20c
[    0.052875][    T1]  show_stack+0x18/0x24
[    0.052880][    T1]  dump_stack_lvl+0xbc/0x134
[    0.052883][    T1]  ___might_sleep+0x16c/0x1c0
[    0.052884][    T1]  __might_sleep+0x50/0x88
[    0.052887][    T1]  __kmalloc_track_caller+0x6c/0x388
[    0.052891][    T1]  kvasprintf+0xa8/0x134
[    0.052892][    T1]  kasprintf+0x54/0x7c
[    0.052894][    T1]  hh_msgq_alloc_entry+0x98/0x128
[    0.052896][    T1]  hh_msgq_populate_cap_info+0x74/0x26c
[    0.052897][    T1]  hh_msgq_probe_direction+0x78/0xf0
[    0.052899][    T1]  hh_msgq_probe+0x4c/0xdc
[    0.052901][    T1]  hh_rm_drv_probe+0x34/0x310
[    0.052904][    T1]  platform_drv_probe+0x3c/0x9c
[    0.052906][    T1]  really_probe+0x11c/0x4c8
[    0.052909][    T1]  driver_probe_device+0x84/0xec
[    0.052911][    T1]  device_driver_attach+0x4c/0x70
[    0.052913][    T1] __driver_attach.llvm.3781602661191075997+0x40/0x154
[    0.052915][    T1]  bus_for_each_dev+0x7c/0xc8
[    0.052917][    T1]  bus_add_driver+0x110/0x20c
[    0.052919][    T1]  driver_register+0x64/0x104
[    0.052921][    T1]  __platform_driver_register+0x44/0x50
[    0.052926][    T1] __initstub__kmod_gh_rm_drv__334_1315_gh_rm_driver_init6+0x1c/0x28
[    0.052928][    T1]  do_one_initcall+0x50/0x29c
[    0.052931][    T1]  do_initcall_level+0xa4/0x16c
[    0.052933][    T1]  do_initcalls+0x60/0xa0
[    0.052934][    T1]  do_basic_setup+0x20/0x2c
[    0.052936][    T1]  kernel_init_freeable+0x8c/0xdc
[    0.052939][    T1]  kernel_init+0x14/0x110
[    0.052941][    T1]  ret_from_fork+0x10/0x30
Even though the error signature says "BUG:" it isn't really a kernel
panic. It only dumps the stack and then carries on, courtesy
CONFIG_DEBUG_ATOMIC_SLEEP.
Change the remaining two memory allocation operations to use GFP_ATOMIC
as well and thereby fix the appearance of this error message.

Change-Id: If7f91e67541b1e925313eeb96f58cc4e2280dba2
Signed-off-by: Ashok Gummadidala <agumma@codeaurora.org>
2021-12-27 02:54:20 -08:00
Srinivasarao Pathipati
8a6924048b Merge android11-5.4.147+ (983a7e7) into msm-5.4
* refs/heads/tmp-983a7e7:
  FROMGIT: USB: gadget: bRequestType is a bitfield, not a enum
  UPSTREAM: aio: fix use-after-free due to missing POLLFREE handling
  UPSTREAM: aio: keep poll requests on waitqueue until completed
  UPSTREAM: signalfd: use wake_up_pollfree()
  UPSTREAM: binder: use wake_up_pollfree()
  UPSTREAM: wait: add wake_up_pollfree()
  UPSTREAM: USB: gadget: zero allocate endpoint 0 buffers
  UPSTREAM: USB: gadget: detect too-big endpoint 0 requests
  UPSTREAM: HID: check for valid USB device for many HID drivers
  UPSTREAM: HID: wacom: fix problems when device is not a valid USB device
  UPSTREAM: HID: bigbenff: prevent null pointer dereference
  UPSTREAM: HID: add USB_HID dependancy on some USB HID drivers
  UPSTREAM: HID: add USB_HID dependancy to hid-chicony
  UPSTREAM: HID: add USB_HID dependancy to hid-prodikeys
  UPSTREAM: HID: add hid_is_usb() function to make it simpler for USB detection
  BACKPORT: f2fs: relocate inline conversion from mmap() to mkwrite()
  BACKPORT: f2fs: support RO feature
  BACKPORT: f2fs: fix wrong total_sections check and fsmeta check
  BACKPORT: FROMGIT: binder: fix freeze race
  FROMGIT: binder: BINDER_GET_FROZEN_INFO ioctl
  FROMGIT: binder: use EINTR for interrupted wait for work
  BACKPORT: FROMGIT: binder: BINDER_FREEZE ioctl
  ANDROID: usb: gadget: f_accessory: Mitgate handling of non-existent USB request
  FROMGIT: binder: fix test regression due to sender_euid change
  BACKPORT: binder: use cred instead of task for getsecid
  BACKPORT: binder: use cred instead of task for selinux checks
  BACKPORT: binder: use euid from cred instead of using task
  ANDROID: setlocalversion: make KMI_GENERATION optional

Change-Id: I00cf067e7b2e31eb3ad074ede720c087a7647959
Signed-off-by: Srinivasarao Pathipati <quic_spathi@quicinc.com>
2021-12-27 12:53:30 +05:30
Karthik Rudrapatna
7657f700dc net: macsec: Clones skb when netdev is in Primiscous mode
When bridge0 is in Primiscous mode, passed the packets to macsec

Change-Id: Ib325e0bb19cee792a8dd3759a4e752581e48827b
Signed-off-by: Karthik Rudrapatna <quic_krudrapa@quicinc.com>
2021-12-23 15:03:10 -08:00
Jilai Wang
77f9dec046 msm: npu: remove asynchronous network execution support
Remove asynchronous network execution related code since it's
not used.

Change-Id: I9e9b54fddbbe9a0a1c0721983ae65e464fd49c0f
Signed-off-by: Jilai Wang <quic_jilaiw@quicinc.com>
2021-12-23 10:18:06 -08:00
qctecmdr
6cd9ac9ba6 Merge "usb: dwc: Release wakeup source if vbus_active is cleared" 2021-12-23 02:30:45 -08:00
qctecmdr
b0035a4a04 Merge "msm: ipa: Includes QMI structure changes for IPA Peripheral stats" 2021-12-23 02:30:45 -08:00
qctecmdr
f0d0122ca7 Merge "net: macsec: add support for getting offloaded stats" 2021-12-23 02:30:44 -08:00
qctecmdr
8a7cea516a Merge "msm: npu: fix driver warnings" 2021-12-23 02:30:42 -08:00