Commit graph

911,778 commits

Author SHA1 Message Date
qctecmdr
daed7cb962 Merge "interconnect: qcom: scshrike: fix UAF under remove function" 2023-05-15 04:24:39 -07:00
qctecmdr
3c7f2a8364 Merge "interconnect: qcom: sm8150: fix UAF under remove function" 2023-05-15 04:24:36 -07:00
qctecmdr
bb70967678 Merge "qcedev: vote for crypto clocks during module close" 2023-05-14 21:30:14 -07:00
qctecmdr
096643eb48 Merge "interconnect: qcom: monaco: fix UAF under remove function" 2023-05-12 21:02:30 -07:00
Raviteja Laggyshetty
ae2d0077d6 interconnect: qcom: sm8150: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: I0c8cfd628483cd44408b987e4765dc7237ef7ad5
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-12 19:20:57 +05:30
Raviteja Laggyshetty
a5e1d0fedf interconnect: qcom: monaco: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: I249472490349c227d9f30f276439fd1d0de0bdb9
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-12 19:16:16 +05:30
qctecmdr
72b1398669 Merge "interconnect: qcom: shima: fix UAF under remove function" 2023-05-12 05:37:11 -07:00
qctecmdr
ed38cbcc29 Merge "interconnect: qcom: lahaina: fix UAF under remove function" 2023-05-12 02:04:17 -07:00
Raviteja Laggyshetty
153bf8409a interconnect: qcom: shima: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: I296b40141d3d844f3011cd704e8c593c8bc0f5e0
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-04 18:53:24 -07:00
Raviteja Laggyshetty
bb0e2f4acf interconnect: qcom: scshrike: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: Ib420005ad94507db927a3014a39bd0d06b4d416f
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-04 18:52:49 -07:00
Raviteja Laggyshetty
c36b875972 interconnect: qcom: lahaina: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: I7a840812752b34248ec3dcb241b069cf4bf77608
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-04 18:52:11 -07:00
Raviteja Laggyshetty
e57b2b062e interconnect: qcom: holi: fix UAF under remove function
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.

Change-Id: If4ddebec67f008e5412c1bf03bed0693fcaaffe0
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
2023-05-02 21:06:47 -07:00
Gaurav Kashyap
0a7a6f1501 qcedev: vote for crypto clocks during module close
When qcedev module is exiting, it disconnects SPS.
At this times, crypto clocks need to be turned on
or it will cause a synchronous abort.

Tests: rmmod on the qcedev module.

Change-Id: I1721fe408392ef81b07a6c08d2196b2413ba2b2f
Signed-off-by: Gaurav Kashyap <quic_gaurkash@quicinc.com>
Signed-off-by: Nageswara reddy Karnati <quic_nkarnati@quicinc.com>
2023-05-02 01:38:31 -07:00
qctecmdr
0c085f1ad1 Merge "virt: haven: rsc_mgr: Allocate right buffer size of requests" 2023-05-01 23:24:23 -07:00
qctecmdr
489c7f8c5a Merge "msm: adsprpc: Handle UAF in fastrpc internal munmap" 2023-04-23 09:47:13 -07:00
Ram Nagesh
f20dfe7d99 msm: synx: Check for zero before reducing bind handles
Suppose user has sent invalid external fence to bind API. Now, while
binding, if synx signal comes in parallel, it will set number of bound
synxs as 0 after signal. Further reduction on that number(num_bound_synxs)
(in case of callback registration failure) would make it wrap
around. So, now num_bound_synxs is large value and abrupt close on synx
fd will lead to synx_util_object_destroy. Here, the for loop on
num_bound_synxs would lead to invalid memory access.

This change decrements num_bound_synxs only if not zero.

Change-Id: I0cfffc90d4164b149c87545818ae4dcf57fc4c46
Signed-off-by: Ram Nagesh <quic_ramnages@quicinc.com>
2023-04-20 23:12:43 -07:00
Santosh Sakore
96507bd863 msm: adsprpc: Handle UAF in fastrpc internal munmap
Added reference count for contex map indicate memory under used
in remote call. And, this memory would not removed in internal
unmap to avoid UAF.

Change-Id: Ieb4ff6b298ff9c48953bc5b3539fdfe19a14b442
Acked-by: Santosh Sakore <ssakore@qti.qualcomm.com>
Signed-off-by: Santosh Sakore <quic_ssakore@quicinc.com>
2023-04-21 11:35:43 +05:30
qctecmdr
460f325dcb Merge "coresight-tmc: increase qdss pcie sw path throughput" 2023-04-20 04:34:07 -07:00
qctecmdr
32365ca0ad Merge "mtd: msm_qpic_nand: Add boot_a and boot_b access to APPS" 2023-04-20 04:34:06 -07:00
qctecmdr
da3aa8fcd8 Merge "defconfig: sdxlemur: Enable R8168 driver config" 2023-04-20 04:34:06 -07:00
qctecmdr
3699f69fa5 Merge "net: qrtr: Move service id based filter check before queueing skb" 2023-04-20 04:34:04 -07:00
qctecmdr
019027da9d Merge "Merge android11-5.4.226+ (2af3bdf) into msm-5.4" 2023-04-20 01:16:41 -07:00
qctecmdr
0569ed8c36 Merge "msm: kgsl: Keep postamble packets in a privileged buffer" 2023-04-18 10:00:07 -07:00
qctecmdr
b4f4305f32 Merge "msm: kgsl: Check user generated timestamp before queuing drawobjs" 2023-04-18 10:00:06 -07:00
Pradeep P V K
b4b121f38d mtd: msm_qpic_nand: Add boot_a and boot_b access to APPS
As part of FR53657, make changes to support for boot_a and
boot_b partition access to HLOS APPS.

Change-Id: Ic173bd54df11e42b1811c198314719c4c34338db
Signed-off-by: Pradeep P V K <quic_pragalla@quicinc.com>
2023-04-11 21:24:02 +05:30
Yuanfang Zhang
931dbd1b07 coresight-tmc: increase qdss pcie sw path throughput
Increase throughput for qdss pcie sw path.

Change-Id: I4bb52e81d2617d8e83d0dcfe525cad2f6f5ca93a
Signed-off-by: Yuanfang Zhang <quic_yuanfang@quicinc.com>
2023-04-06 23:10:27 -07:00
Akhil P Oommen
128731bb62 msm: kgsl: Keep postamble packets in a privileged buffer
Postamble packets are executed in privileged mode by gpu. So we should keep
them in a privileged scratch buffer to block userspace access. For
targets with APRIV feature support, we can mark the preemption scratch
buffer as privileged too to avoid similar issues in future.

Change-Id: Ifda360dda251083f38dfde80ce1b5dc83daae902
Signed-off-by: Akhil P Oommen <quic_akhilpo@quicinc.com>
Signed-off-by: Kaushal Sanadhya <quic_ksanadhy@quicinc.com>
2023-03-31 16:21:55 +05:30
Arun Prakash
87acdd7036 net: qrtr: Move service id based filter check before queueing skb
Move service id based filter check before queueing skb to avoid
possible use after free issue since skb might get released once
rx thread completed the processing of skb.

Change-Id: Iff93e32abd3d55f78bf4ce80675fc3bb312b0841
Signed-off-by: Arun Prakash <quic_app@quicinc.com>
2023-03-29 17:44:19 +05:30
Kamal Agrawal
046f27cfe2 msm: kgsl: Check user generated timestamp before queuing drawobjs
In ioctls like kgsl_ioctl_submit_commands(), if both syncobj
type and cmd/marker/sparseobj type are submitted, the syncobj
is queued first followed by the other obj type. After syncobj
is successfully queued, in case of failure in get_timestamp
while queuing the other obj, both the command objs are
destroyed. As sync obj is already queued, accessing this
later would cause a crash.

Compare the user generated timestamp with the drawctxt
timestamp and return early in case of error. This avoids
unnecessary queuing of drawobjs.

Change-Id: Iedebd480bc18cd74d2f69d24a9dc1032fab01cdb
Signed-off-by: Kamal Agrawal <quic_kamaagra@quicinc.com>
2023-03-28 17:56:20 +05:30
qctecmdr
29910cbf29 Merge "dwc3: Add check for sg queued trbs while reclaiming" 2023-03-21 11:00:43 -07:00
Krishna Nagaraja
1f7f937648 msm: ipa3: add ioctl interface for dual backhaul
Add the ioctl interface to indicate Dual backhaul info,
using QMI message.

Change-Id: I5fa944c61e1745fe71c7ddc8bf48e0001c19e520
Signed-off-by: Krishna Nagaraja <quic_krisnag@quicinc.com>
2023-03-19 21:30:32 -07:00
AKASH KUMAR
f3dae06c15 dwc3: Add check for sg queued trbs while reclaiming
If we're in the middle of series of chained TRBs, DWC3 will
avoid clearing HWO and SW has to do it manually.
We are doing it while reclaiming trbs for sg transfers.

Add check for sg queued trb and reclaim it as DWC3 skips
clearing HWO bit during sg transfers.

Change-Id: I200254728c0549da6534aea51daad94be6b6295e
Signed-off-by: AKASH KUMAR <quic_akakum@quicinc.com>
2023-03-17 10:42:08 +05:30
qctecmdr
e531d35984 Merge "i2c-msm-geni: KASAN: use-after-free in __list_add_valid+0x2c/0xc4" 2023-03-16 11:57:12 -07:00
qctecmdr
8be449ff0c Merge "soc: spcom: Addressing KASAN issue slab-out-of-bounds" 2023-03-15 14:57:44 -07:00
qctecmdr
74e7790a2b Merge "clk: qcom: gcc: Add support for edp ref clock for Yupik" 2023-03-15 10:23:58 -07:00
qctecmdr
f7bb312e24 Merge "msm: Add config option for Realtek R8168 driver" 2023-03-15 07:20:38 -07:00
qctecmdr
b29b126fed Merge "BACKPORT: FROMGIT: cgroup: Use separate src/dst nodes when preloading css_sets for migration" 2023-03-15 07:20:36 -07:00
rakegand
6380631f28 soc: spcom: Addressing KASAN issue slab-out-of-bounds
This change blocks access to channel name string,
in case channel name string length is more than permissible limits.

Change-Id: I2fe0b32498bc74011b1d42bb3c056c7e174494ca
Signed-off-by: rakegand <quic_rakegand@quicinc.com>
2023-03-15 02:37:29 -07:00
Raihan Haider
4b3ce87e47 defconfig: sdxlemur: Enable R8168 driver config
Set R8168 driver config to y.

Change-Id: I31cfdf90592db9da3e5e02be2f23c2d625863055
Signed-off-by: Raihan Haider <quic_rhaider@quicinc.com>
2023-03-14 22:52:51 -07:00
Taniya Das
f73dcc175f clk: qcom: gcc: Add support for edp ref clock for Yupik
EDP clock is required for edp consumer.

Change-Id: I06a537f06dd95af67db2679f5d16620eef624a60
Signed-off-by: Taniya Das <quic_tdas@quicinc.com>
2023-03-14 22:19:11 -07:00
Taniya Das
930876955f clk: qcom: gcc: Add support for EDP Ref clock Yupik
EDP reference clock for Yupik is required by EDP consumer.

Change-Id: I981bbaa789cdce86a140d17b81d46d590cc7d980
Signed-off-by: Taniya Das <quic_tdas@quicinc.com>
2023-03-14 22:08:30 -07:00
Raihan Haider
e80691d824 msm: Add config option for Realtek R8168 driver
Add kernel config option for Realtek R8168 driver

Change-Id: I81a7b1f3585d69d550109d00d09944242c921728
Signed-off-by: Raihan Haider <quic_rhaider@quicinc.com>
2023-03-14 06:28:28 -07:00
qctecmdr
6e5a826add Merge "ANDROID: mm/filemap: Fix missing put_page() for speculative page fault" 2023-03-13 00:25:11 -07:00
Patrick Daly
290d702383 ANDROID: mm/filemap: Fix missing put_page() for speculative page fault
find_get_page() returns a page with increased refcount, assuming a page
exists at the given index. Ensure this refcount is dropped on error.

Bug: 271079833
Fixes: 59d4d125 ("BACKPORT: FROMLIST: mm: implement speculative handling in filemap_fault()")
Change-Id: Idc7b9e3f11f32a02bed4c6f4e11cec9200a5c790
Signed-off-by: Patrick Daly <quic_pdaly@quicinc.com>
(cherry picked from commit 6232eecfa7ca0d8d0ca088da6d0edb2c3a879ff9)
Signed-off-by: Zhenhua Huang <quic_zhenhuah@quicinc.com>
Git-commit: 1d05213028b6dbdb8801e20f29b6a6f91c216033
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2023-03-10 11:08:16 +05:30
Tejun Heo
064252c4f2 BACKPORT: FROMGIT: cgroup: Use separate src/dst nodes when preloading css_sets for migration
Each cset (css_set) is pinned by its tasks. When we're moving tasks around
across csets for a migration, we need to hold the source and destination
csets to ensure that they don't go away while we're moving tasks about. This
is done by linking cset->mg_preload_node on either the
mgctx->preloaded_dst_csets or mgctx->preloaded_dst_csets list. Using the
same cset->mg_preload_node for both the src and dst lists was deemed okay as
a cset can't be both the source and destination at the same time.

Unfortunately, this overloading becomes problematic when multiple tasks are
involved in a migration and some of them are identity noop migrations while
others are actually moving across cgroups. For example, this can happen with
the following sequence on cgroup1:

 #1> mkdir -p /sys/fs/cgroup/misc/a/b
 #2> echo $$ > /sys/fs/cgroup/misc/a/cgroup.procs
 #3> RUN_A_COMMAND_WHICH_CREATES_MULTIPLE_THREADS &
 #4> PID=$!
 #5> echo $PID > /sys/fs/cgroup/misc/a/b/tasks
 #6> echo $PID > /sys/fs/cgroup/misc/a/cgroup.procs

the process including the group leader back into a. In this final migration,
non-leader threads would be doing identity migration while the group leader
is doing an actual one.

After #3, let's say the whole process was in cset A, and that after #4, the
leader moves to cset B. Then, during #6, the following happens:

 1. cgroup_migrate_add_src() is called on B for the leader.

 2. cgroup_migrate_add_src() is called on A for the other threads.

 3. cgroup_migrate_prepare_dst() is called. It scans the src list.

 3. It notices that B wants to migrate to A, so it tries to A to the dst
    list but realizes that its ->mg_preload_node is already busy.

 4. and then it notices A wants to migrate to A as it's an identity
    migration, it culls it by list_del_init()'ing its ->mg_preload_node and
    putting references accordingly.

 5. The rest of migration takes place with B on the src list but nothing on
    the dst list.

This means that A isn't held while migration is in progress. If all tasks
leave A before the migration finishes and the incoming task pins it, the
cset will be destroyed leading to use-after-free.

This is caused by overloading cset->mg_preload_node for both src and dst
preload lists. We wanted to exclude the cset from the src list but ended up
inadvertently excluding it from the dst list too.

This patch fixes the issue by separating out cset->mg_preload_node into
->mg_src_preload_node and ->mg_dst_preload_node, so that the src and dst
preloadings don't interfere with each other.

Bug: 236582926
Change-Id: Ieaf1c0c8fc23753570897fd6e48a54335ab939ce
Signed-off-by: Tejun Heo <tj@kernel.org>
Reported-by: Mukesh Ojha <quic_mojha@quicinc.com>
Reported-by: shisiyuan <shisiyuan19870131@gmail.com>
Link: http://lkml.kernel.org/r/1654187688-27411-1-git-send-email-shisiyuan@xiaomi.com
Link: https://lore.kernel.org/lkml/Yh+RGIJ0f3nrqIiN@slm.duckdns.org/#t
Fixes: f817de9851 ("cgroup: prepare migration path for unified hierarchy")
Cc: stable@vger.kernel.org # v3.16+
(cherry picked from commit 07fd5b6cdf3cc30bfde8fe0f644771688be04447
 https://git.kernel.org/pub/scm/linux/kernel/git/tj/cgroup.git for-5.19-fixes)
Signed-off-by: Elliot Berman <quic_eberman@quicinc.com>
Signed-off-by: Mukesh Ojha <quic_mojha@quicinc.com>
[mojha: Move the two new list heads into a wrapper ext_css_set struct to ensure
 ABI doesn't break and also defined a macro init_css_set which will be replaced
 with init_ext_css_set.cset to avoid too much code changes]
Git-commit: e8fce594347a77af0481c18b6b56509b954fa771
Git-repo: https://android.googlesource.com/kernel/common/
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2023-03-06 16:58:34 +05:30
Krishna Kurapati
fd63157b5e usb: pd: Send extcon notification as soon as APSD detection is done
In some targets, it is observed that the time difference between vbus
being provided by exerciser and the terminations being applied is
more than 1 second causing failures of Type-C compliance testcases
4.10.2 and 4.10.3

When policy engine's psy changed work gets kicked in first time from
vbus present interrupt callback of charger driver, we kick in usb pd
sm work and it keeps running. Since apsd is not yet done, we don't
queue peripheral work. When apsd is done and charger driver invokes
power supply changed work, policy engine bails out as sm work is
already running although the charger type is detected as SDP/CDP and
were supposed to send an extcon notification. As a result the extcon
is sent when the sm work hits enter snk startup call and it
recognises that apsd is done and charger type is SDP or CDP and sends
extcon. This is results in a delay of roughly 1.3 seconds from the
moment vbus got detected to the moment we provide extcon notification
to dwc3-msm.

To avoid this, check for charger type and provide extcon if haven't
done already in the psy_changed_notifier_work. This reduces the time
delay to around 0.5 seconds helping resolve compliance issue.

Change-Id: I02c9a4a6b21ca75d43fd68f2447a7388210a4856
Signed-off-by: Krishna Kurapati <quic_kriskura@quicinc.com>
2023-03-06 15:14:29 +05:30
kamasali Satyanarayan
f8d95e3d28 Merge android11-5.4.226+ (2af3bdf) into msm-5.4
* refs/heads/tmp-2af3bdf:
  UPSTREAM: ext4: add inode table check in __ext4_get_inode_loc to aovid possible infinite loop
  UPSTREAM: net_sched: reject TCF_EM_SIMPLE case for complex ematch module
  UPSTREAM: ipv6: ensure sane device mtu in tunnels
  BACKPORT: iommu: Avoid races around device probe
  BACKPORT: mac80211_hwsim: notify wmediumd of used MAC addresses
  FROMGIT: mac80211_hwsim: add concurrent channels scanning support over virtio
  ANDROID: ABI: Cuttlefish Symbol update
  UPSTREAM: media: dvb-core: Fix UAF due to refcount races at releasing

Change-Id: I92cded046f502ab95484e44ecc3d01337a065d87
Signed-off-by: kamasali Satyanarayan <quic_kamasali@quicinc.com>
2023-03-06 10:41:59 +05:30
qctecmdr
660959f7c2 Merge "msm: mhi_dev: Update msi_disable on fetching MSI config" 2023-03-01 15:07:30 -08:00
qctecmdr
dc28e64e51 Merge "pci: msm: Flush workqueue and destroy it in mhi controller unregister" 2023-02-28 21:37:13 -08:00
Jyothi Kumar Seerapu
d37fe0868c pci: msm: Flush workqueue and destroy it in mhi controller unregister
In mhi_unregister_mhi_controller function, flush the work queue and then
destroy it for releasing the memory of unused workqueues.
When multiple mhi-based WLAN endpoints are attached directly or
over switch, then there can be multiple mhi controllers and
so CNSS driver calls for mhi controller registration multiple times.
Each time invoking mhi controller register creates another set of
workqueues and previous workqueues become stale.
By doing so, it will consume the system memory.

So, better to release the memory assigned to workqueue by destroying
the work queue in mhi_unregister_mhi_controller function.

Change-Id: I838371e9c00969a64e658e6175115363ccb916bf
Signed-off-by: Jyothi Kumar Seerapu <quic_jseerapu@quicinc.com>
2023-02-27 14:08:02 +05:30