Commit graph

1,393 commits

Author SHA1 Message Date
Linux Build Service Account
da4eec4658 Merge 82ce65cbeb on remote branch
Change-Id: I2b1995623ed5db3e53c485cdfae3b2deada62073
2023-09-18 05:31:25 -07:00
Nirmal Abraham
82ce65cbeb msm: camera: memmgr: release buffers after usage
Call cam_mem_put_cpu_buf corresponding to
cam_mem_get_cpu_buf calls to make sure ref_cnt
is balanced and buffer is freed when all
clients are done with the buffer usage.

CRs-Fixed: 3547081
Change-Id: I9414829d6f17c368f2718fe05dbe25c71b31e674
Signed-off-by: Nirmal Abraham <quic_c_nabrah@quicinc.com>
2023-07-13 21:06:48 -07:00
Linux Build Service Account
b0f4412db3 Merge f81db81382 on remote branch
Change-Id: Ib7eaa74a7665a4508797d38da7127c79d6a2a901
2023-07-13 06:17:01 -07:00
Gaurav Jindal
f81db81382 msm: camera: fd: Fix compilation issue
This commit fixes compilation issue.

CRs-Fixed: 3549085
Change-Id: Ia98fbbf67736c372fea4788b8e445c534126da21
Signed-off-by: Gaurag Jindal <quic_gjindal@quicinc.com>
2023-07-04 04:50:49 -07:00
illa lakshmi soujanya
0724e68848 msm: camera: sensor: Add changes to prevent unmap buffers
The function cam_mem_mgr_release can unmap buffers when in use.
This change with cam_mem_put_cpu_buf prevents unmaping the buffers in use.

CRs-Fixed: 3489559
Change-Id: I9c4e284c5961a2eb4ff0df362c93d6cea7d77cab
Signed-off-by: illa lakshmi soujanya <quic_illa@quicinc.com>
2023-06-23 18:58:29 +05:30
Shivakumar Malke
575f20ea96 msm: camera: mem_mgr: Add refcount to track in use buffers
The function cam_mem_mgr_release can unmap the buffers when in use.

This change prevents unmapping the buffers when in use.

CRs-Fixed: 3489559
Change-Id: I2e72e795d39ac15abfa56c19043c419a03686966
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
Signed-off-by: Gaurav Jindal <quic_gjindal@quicinc.com>
2023-06-23 18:52:01 +05:30
Karthik Dillibabu
217ebc5e61 msm: camera: core: validation of session/device/link handle
This change is to validate session, device and link handle.
Also, checks whether the device handle belongs to
correct session handle or not.

CRs-Fixed: 3496553
Change-Id: I6b86bf7d0908a280e90e085a3b3e1727facdf8c6
Signed-off-by: Karthik Dillibabu <quic_kard@quicinc.com>
2023-06-13 11:38:28 +05:30
Linux Build Service Account
ff5ca45c7d Merge 68373c0331 on remote branch
Change-Id: I85ad05a7a99c540d7f9c8d6ffe27553f0850d3d2
2023-05-16 02:06:43 -07:00
Linux Build Service Account
117bda2bee Merge 9b3f91ecab on remote branch
Change-Id: I098e7146b8853a4ce50df412ee006de56b1c1ac0
2023-04-19 01:28:02 -07:00
zhuo
68373c0331 msm: camera: cdm: Making WQ to have inflight works to be one
For requests with multiple BL tags,in a corner case,
cdm work notifies out of order requests to client as
difference in bl_tags is greater than boundary check.

This commit avoids out of order request processing by
making number of inflight work to be 1 and increasing
the priority of workqueue. And therefore removed all
checks that are not required.

CRs-Fixed: 3453131
Change-Id: I6db3e9379b2474347cff1618ea6ad705ca3561fb
Signed-off-by: zhuo <quic_zhuo@quicinc.com>
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
2023-04-05 21:13:27 -07:00
Yash Upadhyay
9b3f91ecab msm: camera: cdm: check irq status on hang detection
Problem:
Check IRQ status on hang detection if the inline IRQ
is set then the cdm has triggered IRQ but there is a
workqueue scheduling delay which is causing the cdm's
config timeout.

Solution:
To prevent the timeout due to
scheduling delay check the work record and irq status
and return true if its delay.

CRs-Fixed: 3433175
Change-Id: Iaa34f8ff9b57e7da9f80677a7da9b4f9a53dad14
Signed-off-by: Yash Upadhyay <quic_yupadhya@quicinc.com>
2023-03-15 09:06:44 +05:30
Camera Software Integration
bfe3e9d726 Merge "msm: camera: ope: Avoid deadlock in OPE PF handling" into camera-kernel.lnx.4.0 2023-03-13 04:50:34 -07:00
Shivakumar Malke
53152ba8cd msm: camera: ope: Avoid deadlock in OPE PF handling
In OPE fault handler, while dumping pf info ctx_mutex is
acquired and corresponding page fault ops is called. In
pagefault ops same mutex is getting acquired again causing
a dead lock.

This commit avoids locking the same mutex again.

CRs-Fixed: 3419490
Change-Id: I2e37f725865d091f2cb682fc62f5d21278b93959
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
2023-03-02 15:22:10 +05:30
Shivakumar Malke
d7eae61ec4 msm: camera: smmu: Use get_file to increase ref count
Due to race condition, fd pointing to a particular dma buf
is released by userspace  before incrementing ref count and
hence freed that dma buf. When the call returns it still uses
the freed dma buf causing use-after-free.

This fix includes get_file API to increment ref count
before dma_buf_fd.

CRs-Fixed: 3341070
Change-Id: I8ebc37b4ceb5f8691bbbb3d26b8b64878d832fbe
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
2023-02-21 12:19:00 +05:30
Linux Build Service Account
717ed6c0c7 Merge 687f2e3e5d on remote branch
Change-Id: I28ff8056f19a5f268fcbe4220494c90ca5d8a63c
2023-01-17 01:41:59 -08:00
Linux Build Service Account
7be199b817 Merge 9831108abf on remote branch
Change-Id: I7f73bde6ba7e1e7ba9b8d72cd24dc50018d883c7
2022-12-15 09:02:15 -08:00
Shivakumar Malke
687f2e3e5d msm: camera: lrme: BL command length validation
This change is to validate BL command length and
addresses before submitting to CDM. Also as part
of recovery avoids moving wrong packet submit request
to pending queue.

CRs-Fixed: 3342983
Change-Id: I15f082cdd4d54ad6bf0e446115780829b3b711dd
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
2022-12-13 10:39:35 +05:30
Shivakumar Malke
9831108abf msm: camera: isp: Handle early bufdones
In case of early bufones, signalling fence for few
ports are missed for target which do not support
last consumed address which result in a unsignalled fence

Issue is fixed by handling early bufdones and signalling
success for resource which got early bufdone.

CRs-Fixed: 3333269
Change-Id: I0a56f770806d48034bcc45d2ca68d8f9adcc8eee
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
2022-11-16 18:59:51 +05:30
Linux Build Service Account
0b53631edf Merge 5685ecf200 on remote branch
Change-Id: Id30175596e589fdef485c1f8b51f9b2321dc9397
2022-11-14 04:08:02 -08:00
Linux Build Service Account
742ed9f15d Merge a2b2dfab21 on remote branch
Change-Id: I5162c2cf87d26995bdd362531d53047d3928c513
2022-10-18 02:42:49 -07:00
Ashish Bhimanpalliwar
5685ecf200 msm: camera: common: Add conditions to catch invalid packet data
Add conditions to catch invalid cmd_desc, io buffers, and kmd buffers in
the packet payload.

CRs-Fixed: 3250331
Change-Id: I2db474572a8c5391ba9b9821de2da0db8f10eb4d
Signed-off-by: Ashish Bhimanpalliwar <quic_abhiman@quicinc.com>
2022-10-10 20:49:53 -07:00
Shivakumar Malke
a2b2dfab21 msm: camera: isp: Handle RUP in applied substate
In TFE top-half handler, TOP register status is read first and
then based on top register status, bus register status is read.
There could be a corner case where bufdone irq top-half handling
is ongoing, top status registers are read, and while reading bus
register status we might have got SOF and RUP irqs. Since RUP and
Bufdone both come from bus side, RUP bit is set during this bus
register read. Hence, RUP is handled first along with bufdone and
then SOF irq is handled. There is no handling in statemachine for
such RUP's in RDI only context statemachine. Hence leading to
bubble condition resulting in frame drop

To overcome such scenario, handling for RUP in applied substate
is introduced in RDI only statemachine.

CRs-Fixed: 3298719
Change-Id: I5cc8a0c122aa09c22da6536303f849344454c480
Signed-off-by: Shivakumar Malke <quic_smalke@quicinc.com>
2022-09-28 16:38:19 +05:30
Linux Build Service Account
1b8e9355a2 Merge 336163ddec on remote branch
Change-Id: I92270af5cb1f133bb17b4888fd2c43cde713e4c2
2022-08-15 23:23:43 -07:00
Yash Upadhyay
336163ddec msm: camera: memmgr: Avoid TOCTOU buffer access on multiple use of same fd
Fd is a user-accessible value, referring it multiple times
leads to TOCTOU issues. Dma_buf can be freed after the 1st
use of fd and userspace can create another dma_buf but with
same fd. In such scenario, during 2nd use of fd, we may get
a different dma_buf with different length. To avoid this, we
can use same dma_buf instead of retrieving it twice using same
fd. In this change FD is accessed only once in syscall.

CRs-Fixed: 3159446
Change-Id: I00eb6dd3d798165f5c6c0bd59feabe80a68592b1
Signed-off-by: Yash Upadhyay <quic_yupadhya@quicinc.com>
2022-08-03 10:04:47 +05:30
Linux Build Service Account
35a56acb33 Merge d35e7e899b on remote branch
Change-Id: Ide4cb97fa564ec984b297ea505c70bee1561f64a
2022-07-12 15:18:29 -07:00
Camera Software Integration
d35e7e899b Merge "msm: camera: utils: modify debug function logic" into camera-kernel.lnx.4.0 2022-06-29 21:13:09 -07:00
Linux Build Service Account
eeac0cb806 Merge 21017701fa on remote branch
Change-Id: I87eba0b2244645858fbc0ac22d9fdbbaf435ebc0
2022-06-17 05:10:52 -07:00
daopingl
cfb8c413c9 msm: camera: utils: modify debug function logic
there are only 8k stack in 32 bit system, this change used to make
the temp variables be contorl by the parameters, which can decrase
the stack resource cost under default debug settings and finally
improve the stability of multi camera cases.

CRs-fixed: 3193708
Change-Id: If0f33cc310d64c83c0e4781a5de61483ebc35769
Signed-off-by: daopingl <quic_daopingl@quicinc.com>
2022-05-27 17:58:36 +08:00
Camera Software Integration
21017701fa Merge "msm: camera: reqmgr: Reset the slot if it is applied" into camera-kernel.lnx.4.0 2022-05-25 11:38:34 -07:00
Kai Xing
028478e7df msm: camera: fd: fix compile error for kernel 5.4
Function definition error: delete static keyword.

CRs-Fixed: 3191744
Change-Id: Ifea089f47de02233b31695146b1ddacfbaec35a8
Signed-off-by: Kai Xing <quic_kxing@quicinc.com>
2022-05-11 16:59:10 +05:30
Linux Build Service Account
17853d328d Merge 40348c542e on remote branch
Change-Id: I5646f879736b95c842506161a9b74e23bfb78dcc
2022-05-10 06:39:00 -07:00
Camera Software Integration
40348c542e Merge "msm: camera: jpeg: By default disable Camnoc MISR configuration" into camera-kernel.lnx.4.0 2022-05-01 08:33:39 -07:00
Depeng Shao
f4a952f180 msm: camera: reqmgr: Reset the slot if it is applied
This change reset the slot when the next req is applied, it
should be caused by some exception before, we need to reset
this slot in case we applied wrong req to sub devices.

CRs-Fixed: 2949657
Change-Id: I0b5f7b1d8450ed355701090b185812fb7a6b6e06
Signed-off-by: Depeng Shao <quic_depengs@quicinc.com>
2022-04-28 09:48:17 +05:30
Linux Build Service Account
dabd749a6b Merge 355f51b649 on remote branch
Change-Id: Ibaa7e88a2d874f25d4df75ff47c3eed0d91d56b3
2022-04-14 02:11:55 -07:00
Shravan Nevatia
6c445cfb01 msm: camera: eeprom: Add OOB read check for eeprom memory map
Add check to prevent OOB read of eeprom memory map.

Change-Id: Ifeeeffdc2a50536edbde5b5d755a052ace86d596
CRs-Fixed: 3003049
Signed-off-by: Shravan Nevatia <quic_snevatia@quicinc.com>
2022-04-11 23:23:41 +05:30
Camera Software Integration
355f51b649 Merge "msm: camera: ife: dump data at overlflow for rdi only use case" into camera-kernel.lnx.4.0 2022-04-06 02:13:15 -07:00
Camera Software Integration
d8227145a5 Merge "msm: camera: memmgr: update correct length in bufq" into camera-kernel.lnx.4.0 2022-04-06 02:13:04 -07:00
Tejas Prajapati
dd87df520d msm: camera: ife: dump data at overlflow for rdi only use case
Below information is dumped at the overflow
1. Dump SOF, EPOCH, EOF and Error time.
2. Dump IRQ status.
3. Cpas AB, IB votes.
4. Dump width and height of all the acquired ports.
5. CSID clock.

CRs-Fixed: 3159425
Change-Id: I580d8f4d50c49568a6bc9ae8d06fc4b93f11891c
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
2022-03-31 10:10:01 +05:30
Camera Software Integration
6d548aa9b5 Merge "msm: camera: reqmgr: Validate the link handle" into camera-kernel.lnx.4.0 2022-03-22 06:26:28 -07:00
Camera Software Integration
a9d8ab272a Merge "msm: camera: reqmgr: Avoid freeing subdev twice" into camera-kernel.lnx.4.0 2022-03-22 06:21:19 -07:00
Tejas Prajapati
a4b0246d27 msm: camera: memmgr: update correct length in bufq
In a corner case, race condition to free the original
ion buf allocated and new ion buffer with same fd but
different size after freeing the origianl ion buf might
result into mismatches in the real ion buf size assigned
in bufq. To avoid this update length in bufq with
local variable.

CRs-Fixed: 3142221
Change-Id: I23d91445bd088bbde19ffa191e158256166f2053
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
2022-03-17 14:49:58 +05:30
Linux Build Service Account
14568cb248 Merge f33380f182 on remote branch
Change-Id: I2fea743726b96556867189b281f72e860ad6dc55
2022-03-16 06:28:01 -07:00
Yash Upadhyay
e5cbfaf0af msm: camera: reqmgr: Validate the link handle
Instead of correct link handle, if some other handle like
dev handle is passed then it may access some other data space.
To avoid such scenario, need to check whether link handle
passed by ioctl is same as retrieved link handle.

CRs-Fixed: 3120454
Change-Id: Idff2e3c25b60563788ffb426c7cabc367c3c97f8
Signed-off-by: Yash Upadhyay <quic_yupadhya@quicinc.com>
2022-03-15 09:22:45 +05:30
Dharmender Sharma
24a4646c76 msm: camera: jpeg: By default disable Camnoc MISR configuration
By default driver is configuring jpeg misr and also dumping misr values.
So added a check if camnoc_misr_support is enabled then only configure
and dump the misr value.

CRs-Fixed: 3168072
Change-Id: I4090b1a43b55a0f7643c352689aa04b56d31df8d
Signed-off-by: Dharmender Sharma <quic_dharshar@quicinc.com>
2022-03-15 08:07:38 +05:30
zhuo
f33380f182 msm: camera: cdm: Fix workqueue timing issue
Due to workqueue does not process the work in order,
so sometimes the later work will be processed earlier.
Such as, when submit request order: 1/2/3, cdm interrupt
come order: 1/2/3, workqueue process order: 2/1/3,
when process 2 request, which currently will notify 1/2
CDM clients and remove 1/2 from submit list. After that,
when process 1 request, will notify 3, actually 3 is not
done at the moment, which maybe cause smmu page fault issue.
And sometimes, when there is a delay in handling interrupts,
then HLOS handles two interrupts as one only. This change only
notify the request less than and equal to the interrupt request.

CRs-Fixed: 3130447
Change-Id: I0fd0e8adee48767e5ab7db1921a8284d107c2f40
Signed-off-by: zhuo <quic_zhuo@quicinc.com>
2022-02-28 13:24:40 +08:00
Linux Build Service Account
ff868a2d19 Merge 6639a3b50f on remote branch
Change-Id: I04409d42a5a0099394b2931c566136ea4af28cae
2022-02-14 22:01:52 -08:00
Camera Software Integration
6639a3b50f Merge "msm: camera: tfe: dump csid clock and path data at overflow" into camera-kernel.lnx.4.0 2022-02-09 22:58:05 -08:00
Nirmal Abraham
583fb300c8 msm: camera: reqmgr: Avoid freeing subdev twice
The 'l_device' pointer in __cam_req_mgr_destroy_subdev is
set to NULL after freeing but this is done on a
local copy of the variable in stack. This results in
double-free when this function is called again. To avoid
this, pass 'l_device' pointer by reference and assign it
to NULL after freeing.

CRs-Fixed: 3120468
Change-Id: If2dde6f1c702bee26a3c8a68c2f45bafbf0f7cd6
Signed-off-by: Nirmal Abraham <quic_c_nabrah@quicinc.com>
2022-02-08 10:14:49 +05:30
Camera Software Integration
b3fd39f822 Merge "msm: camera: reqmgr: reader writer locks to avoid memory faults" into camera-kernel.lnx.4.0 2022-01-27 11:47:04 -08:00
Tejas Prajapati
a35c7c2f10 msm: camera: tfe: dump csid clock and path data at overflow
On overflow dump the AB and IB votes, tfe clock,
CSID clock and respective bus path data for acquire
time and addr_status registers.

CRs-Fixed: 3118430
Change-Id: Ia38eb4350e8e38562b6d22769b38637480da0b9d
Signed-off-by: Tejas Prajapati <quic_tpraja@quicinc.com>
2022-01-19 10:32:57 +05:30