Commit graph

976,010 commits

Author SHA1 Message Date
Michael Bestas
defbd8dccd
Merge tag 'LA.UM.9.14.r1-25000.02-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4 into android13-5.4-lahaina
"LA.UM.9.14.r1-25000.02-LAHAINA.QSSI14.0"

* tag 'LA.UM.9.14.r1-25000.02-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4:
  msm-5.4.c3: qseecom: Fix possible race condition
  msm: adsprpc: Avoid taking reference for group_info
  adsprpc: Handle UAF scenario in put_args
  msm-5.4.c3: qseecom: Fix possible race condition
  USB: storage: Replace the sprintf with scnprintf
  adsprpc: Handle UAF scenario in put_args
  msm: adsprpc: Avoid taking reference for group_info
  usb: gadget: f_gsi: bail out if opts is null
  msm: ep_pcie: Avoid setting host wake pending flag for D0
  msm: ep_pcie: Prevent repetitive wake operation if wake is in process
  msm_ipa: Install exception rule for PPPoE-MPLS
  securemsm-kernel: Decrement the server object ref count in mutex context
  qcedev: fix UAF in qcedev_smmu
  thermal: qcom: Add support to update tsens trip based on nvmem data
  msm: eva: Fix UAF issue when remove module
  msm: cvp: OOB write fix due to integer underflow
  msm: ep_pcie: Avoid writing req_L1_exit during dstate change
  msm: eva: Adding kref count for cvp_get_inst_from_id

Change-Id: I3dad70dec062688b50554d7676a4b85bcb42fad9
2024-10-09 18:08:09 +00:00
Michael Bestas
123d88374f
Merge tag 'ASB-2024-09-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2024-09-01
CVE-2024-36972

* tag 'ASB-2024-09-05_11-5.4' of https://android.googlesource.com/kernel/common: (59 commits)
  ANDROID: delete tool added by mistake
  ANDROID: fix ENOMEM check of binder_proc_ext
  ANDROID: binder: fix KMI issues due to frozen notification
  BACKPORT: FROMGIT: binder: frozen notification binder_features flag
  BACKPORT: FROMGIT: binder: frozen notification
  BACKPORT: selftests/binderfs: add test for feature files
  UPSTREAM: docs: binderfs: add section about feature files
  BACKPORT: binderfs: add support for feature files
  FROMLIST: binder: fix memory leaks of spam and pending work
  FROMGIT: Binder: add TF_UPDATE_TXN to replace outdated txn
  BACKPORT: binder: tell userspace to dump current backtrace when detected oneway spamming
  UPSTREAM: net: sched: sch_multiq: fix possible OOB write in multiq_tune()
  FROMLIST: binder: fix UAF caused by offsets overwrite
  Revert "net: mac802154: Fix racy device stats updates by DEV_STATS_INC() and DEV_STATS_ADD()"
  Linux 5.4.281
  tap: add missing verification for short frame
  tun: add missing verification for short frame
  filelock: Fix fcntl/close race recovery compat path
  ALSA: hda/realtek: Enable headset mic on Positivo SU C1400
  jfs: don't walk off the end of ealist
  ...

 Conflicts:
	drivers/android/binder.c
	include/uapi/linux/android/binder.h

Change-Id: I0cdb84a8241c0abaf6e5fad140ed19480655d53c
2024-10-09 18:08:04 +00:00
Linux Build Service Account
d2648db3ba Merge c3d6993d5c on remote branch
Change-Id: Ic2f0d626a18077e9fc47e067669813bdc1b644f4
2024-09-18 04:13:49 -07:00
Carlos Llamas
d62984adb1 ANDROID: delete tool added by mistake
Remove the gen-hyprel binary added accidentally while backporting a
patch into an older branch. The tool gets generated in newer builds and
wasn't part of the gitignore file here.

Fixes: d1e87637cd ("BACKPORT: FROMGIT: binder: frozen notification")
Change-Id: I103358cb2ca9c5fb934f047033e44c04fe85298d
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-09-09 22:59:15 +00:00
Carlos Llamas
a03c6437cf ANDROID: fix ENOMEM check of binder_proc_ext
The check should be done against 'eproc' before it gets dereferenced.

Fixes: d49297739550 ("BACKPORT: binder: use euid from cred instead of using task")
Change-Id: Ief0c08212c4da8bdfdf628474de9dd30ee5a8db0
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-09-07 22:04:18 +00:00
Carlos Llamas
be02156857 ANDROID: binder: fix KMI issues due to frozen notification
The patches to support binder's frozen notification feature break the
KMI. This change fixes such issues by (1) moving proc->delivered_freeze
into the existing proc_wrapper struction, (2) dropping the frozen stats
support and (3) amending the STG due to a harmless enum binder_work_type
addition.

These are the reported KMI issues fixed by this patch:

  function symbol 'int __traceiter_binder_transaction_received(void*, struct binder_transaction*)' changed
    CRC changed from 0x74e9c98b to 0xfe0f8640

  type 'struct binder_proc' changed
    byte size changed from 584 to 632
    member 'struct list_head delivered_death' changed
      offset changed by 256
    member 'struct list_head delivered_freeze' was added
    13 members ('u32 max_threads' .. 'u64 android_oem_data1') changed
      offset changed by 384

  type 'struct binder_thread' changed
    byte size changed from 464 to 496
    2 members ('atomic_t tmp_ref' .. 'bool is_dead') changed
      offset changed by 224
    4 members ('struct task_struct* task' .. 'enum binder_prio_state prio_state') changed
      offset changed by 256

  type 'struct binder_stats' changed
    byte size changed from 216 to 244
    member changed from 'atomic_t br[21]' to 'atomic_t br[23]'
      type changed from 'atomic_t[21]' to 'atomic_t[23]'
        number of elements changed from 21 to 23
    member changed from 'atomic_t bc[19]' to 'atomic_t bc[22]'
      offset changed from 672 to 736
      type changed from 'atomic_t[19]' to 'atomic_t[22]'
        number of elements changed from 19 to 22
    member changed from 'atomic_t obj_created[7]' to 'atomic_t obj_created[8]'
      offset changed from 1280 to 1440
      type changed from 'atomic_t[7]' to 'atomic_t[8]'
        number of elements changed from 7 to 8
    member changed from 'atomic_t obj_deleted[7]' to 'atomic_t obj_deleted[8]'
      offset changed from 1504 to 1696
      type changed from 'atomic_t[7]' to 'atomic_t[8]'
        number of elements changed from 7 to 8

  type 'enum binder_work_type' changed
    enumerator 'BINDER_WORK_FROZEN_BINDER' (10) was added
    enumerator 'BINDER_WORK_CLEAR_FREEZE_NOTIFICATION' (11) was added

Bug: 363013421
Change-Id: If9f1f14a2eda215a4c9cb0823c50c8e0e8079ef1
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-09-07 22:04:18 +00:00
Yu-Ting Tseng
1063c2fa62 BACKPORT: FROMGIT: binder: frozen notification binder_features flag
Add a flag to binder_features to indicate that the freeze notification
feature is available.

Signed-off-by: Yu-Ting Tseng <yutingtseng@google.com>
Acked-by: Carlos Llamas <cmllamas@google.com>
Link: https://lore.kernel.org/r/20240709070047.4055369-6-yutingtseng@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 363013421
(cherry picked from commit 30b968b002a92870325a5c9d1ce78eba0ce386e7
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
 char-misc-next)
Change-Id: Ic26c8ae42d27c6fd8f5daed5eecabd1652e29502
[cmllamas: fix trivial conflicts due to missing extended_error]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-09-07 22:04:18 +00:00
Yu-Ting Tseng
d1e87637cd BACKPORT: FROMGIT: binder: frozen notification
Frozen processes present a significant challenge in binder transactions.
When a process is frozen, it cannot, by design, accept and/or respond to
binder transactions. As a result, the sender needs to adjust its
behavior, such as postponing transactions until the peer process
unfreezes. However, there is currently no way to subscribe to these
state change events, making it impossible to implement frozen-aware
behaviors efficiently.

Introduce a binder API for subscribing to frozen state change events.
This allows programs to react to changes in peer process state,
mitigating issues related to binder transactions sent to frozen
processes.

Implementation details:
For a given binder_ref, the state of frozen notification can be one of
the followings:
1. Userspace doesn't want a notification. binder_ref->freeze is null.
2. Userspace wants a notification but none is in flight.
   list_empty(&binder_ref->freeze->work.entry) = true
3. A notification is in flight and waiting to be read by userspace.
   binder_ref_freeze.sent is false.
4. A notification was read by userspace and kernel is waiting for an ack.
   binder_ref_freeze.sent is true.

When a notification is in flight, new state change events are coalesced into
the existing binder_ref_freeze struct. If userspace hasn't picked up the
notification yet, the driver simply rewrites the state. Otherwise, the
notification is flagged as requiring a resend, which will be performed
once userspace acks the original notification that's inflight.

See https://r.android.com/3070045 for how userspace is going to use this
feature.

Signed-off-by: Yu-Ting Tseng <yutingtseng@google.com>
Acked-by: Carlos Llamas <cmllamas@google.com>
Link: https://lore.kernel.org/r/20240709070047.4055369-4-yutingtseng@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 363013421
(cherry picked from commit d579b04a52a183db47dfcb7a44304d7747d551e1
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
 char-misc-next)
Change-Id: I5dd32abba932ca7d03ae58660143e075ed778b81
[cmllamas: fix merge conflicts due to missing 0567461a7a6e]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-09-07 22:04:18 +00:00
Carlos Llamas
8c4165a043 BACKPORT: selftests/binderfs: add test for feature files
Verify that feature files are created successfully after mounting a
binderfs instance. Note that only "oneway_spam_detection" feature is
tested with this patch as it is currently the only feature listed.

Acked-by: Christian Brauner <christian.brauner@ubuntu.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Link: https://lore.kernel.org/r/20210715031805.1725878-3-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 07e913418ce4ba5eb620dd4668bf91ec94e11136)
Bug: 191910201
Signed-off-by: Carlos Llamas <cmllamas@google.com>
[cmllamas: fix merge issues due to missing eaa163caa4cc]
Change-Id: I86d7ef34b3099c8714c319e48029aaf3dbf87081
2024-09-07 22:04:18 +00:00
Carlos Llamas
4d4f8b7a7f UPSTREAM: docs: binderfs: add section about feature files
Document how binder feature files can be used to determine whether a
feature is supported by the binder driver. "oneway_spam_detection" is
used as an example as it is the first available feature file.

Acked-by: Christian Brauner <christian.brauner@ubuntu.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Link: https://lore.kernel.org/r/20210715031805.1725878-2-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 06e1721d2a265d1247093f5ad5ae2958ef10a604)
Bug: 191910201
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Change-Id: I9c4542e0ee65dd94a492fe0440ba8f1a48d8b797
2024-09-07 22:04:18 +00:00
Carlos Llamas
460de65538 BACKPORT: binderfs: add support for feature files
Provide userspace with a mechanism to discover features supported by
the binder driver to refrain from using any unsupported ones in the
first place. Starting with "oneway_spam_detection" only new features
are to be listed under binderfs and all previous ones are assumed to
be supported.

Assuming an instance of binderfs has been mounted at /dev/binderfs,
binder feature files can be found under /dev/binderfs/features/.
Usage example:

  $ mkdir /dev/binderfs
  $ mount -t binder binder /dev/binderfs
  $ cat /dev/binderfs/features/oneway_spam_detection
  1

Acked-by: Christian Brauner <christian.brauner@ubuntu.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Link: https://lore.kernel.org/r/20210715031805.1725878-1-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit fc470abf54b2bd6e539065e07905e767b443d719)
Bug: 191910201
Signed-off-by: Carlos Llamas <cmllamas@google.com>
[cmllamas: fix merge conflicts due to missing 095cf502b31e]
Change-Id: Ia5c03aa1881981bee26459e741134b83d5b59693
2024-09-07 22:04:17 +00:00
Carlos Llamas
31f1f4b2aa FROMLIST: binder: fix memory leaks of spam and pending work
commit 1aa3aaf8953c84bad398adf6c3cabc9d6685bf7d upstream

A transaction complete work is allocated and queued for each
transaction. Under certain conditions the work->type might be marked as
BINDER_WORK_TRANSACTION_ONEWAY_SPAM_SUSPECT to notify userspace about
potential spamming threads or as BINDER_WORK_TRANSACTION_PENDING when
the target is currently frozen.

However, these work types are not being handled in binder_release_work()
so they will leak during a cleanup. This was reported by syzkaller with
the following kmemleak dump:

BUG: memory leak
unreferenced object 0xffff88810e2d6de0 (size 32):
  comm "syz-executor338", pid 5046, jiffies 4294968230 (age 13.590s)
  hex dump (first 32 bytes):
    e0 6d 2d 0e 81 88 ff ff e0 6d 2d 0e 81 88 ff ff  .m-......m-.....
    04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
  backtrace:
    [<ffffffff81573b75>] kmalloc_trace+0x25/0x90 mm/slab_common.c:1114
    [<ffffffff83d41873>] kmalloc include/linux/slab.h:599 [inline]
    [<ffffffff83d41873>] kzalloc include/linux/slab.h:720 [inline]
    [<ffffffff83d41873>] binder_transaction+0x573/0x4050 drivers/android/binder.c:3152
    [<ffffffff83d45a05>] binder_thread_write+0x6b5/0x1860 drivers/android/binder.c:4010
    [<ffffffff83d486dc>] binder_ioctl_write_read drivers/android/binder.c:5066 [inline]
    [<ffffffff83d486dc>] binder_ioctl+0x1b2c/0x3cf0 drivers/android/binder.c:5352
    [<ffffffff816b25f2>] vfs_ioctl fs/ioctl.c:51 [inline]
    [<ffffffff816b25f2>] __do_sys_ioctl fs/ioctl.c:871 [inline]
    [<ffffffff816b25f2>] __se_sys_ioctl fs/ioctl.c:857 [inline]
    [<ffffffff816b25f2>] __x64_sys_ioctl+0xf2/0x140 fs/ioctl.c:857
    [<ffffffff84b30008>] do_syscall_x64 arch/x86/entry/common.c:50 [inline]
    [<ffffffff84b30008>] do_syscall_64+0x38/0xb0 arch/x86/entry/common.c:80
    [<ffffffff84c0008b>] entry_SYSCALL_64_after_hwframe+0x63/0xcd

Fix the leaks by kfreeing these work types in binder_release_work() and
handle them as a BINDER_WORK_TRANSACTION_COMPLETE cleanup.

Cc: stable@vger.kernel.org
Fixes: a7dc1e6f99df ("binder: tell userspace to dump current backtrace when detected oneway spamming")
Reported-by: syzbot+7f10c1653e35933c0f1e@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=7f10c1653e35933c0f1e
Suggested-by: Alice Ryhl <aliceryhl@google.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Acked-by: Todd Kjos <tkjos@google.com>
Link: https://lore.kernel.org/r/20230922175138.230331-1-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[cmllamas: backport to v5.15 by dropping BINDER_WORK_TRANSACTION_PENDING
 as commit 0567461a7a6e is not present. Remove fixes tag accordingly.]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>

Link: https://lore.kernel.org/all/20231208034842.997899-1-cmllamas@google.com/
Change-Id: I8e1ee7af87ef5706544e4f320e9498b8f4855a6b
[cmllamas: also backport to v5.4 to fix OOT 8a09136176f6]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-09-07 22:03:49 +00:00
Li Li
334fe73bdd FROMGIT: Binder: add TF_UPDATE_TXN to replace outdated txn
When the target process is busy, incoming oneway transactions are
queued in the async_todo list. If the clients continue sending extra
oneway transactions while the target process is frozen, this queue can
become too large to accommodate new transactions. That's why binder
driver introduced ONEWAY_SPAM_DETECTION to detect this situation. It's
helpful to debug the async binder buffer exhausting issue, but the
issue itself isn't solved directly.

In real cases applications are designed to send oneway transactions
repeatedly, delivering updated inforamtion to the target process.
Typical examples are Wi-Fi signal strength and some real time sensor
data. Even if the apps might only care about the lastet information,
all outdated oneway transactions are still accumulated there until the
frozen process is thawed later. For this kind of situations, there's
no existing method to skip those outdated transactions and deliver the
latest one only.

This patch introduces a new transaction flag TF_UPDATE_TXN. To use it,
use apps can set this new flag along with TF_ONE_WAY. When such an
oneway transaction is to be queued into the async_todo list of a frozen
process, binder driver will check if any previous pending transactions
can be superseded by comparing their code, flags and target node. If
such an outdated pending transaction is found, the latest transaction
will supersede that outdated one. This effectively prevents the async
binder buffer running out and saves unnecessary binder read workloads.

Acked-by: Todd Kjos <tkjos@google.com>
Signed-off-by: Li Li <dualli@google.com>
Link: https://lore.kernel.org/r/20220526220018.3334775-2-dualli@chromium.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bug: 231624308
Test: manually check async binder buffer size of frozen apps
Test: stress test with kernel 4.14/4.19/5.10/5.15
(cherry picked from commit 9864bb4801331daa48514face9d0f4861e4d485b
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
  char-misc-next)
Change-Id: I1c4bff1eda1ca15aaaad5bf696c8fc00be743176
2024-09-07 22:03:08 +00:00
Hang Lu
2bfddf30aa BACKPORT: binder: tell userspace to dump current backtrace when detected oneway spamming
When async binder buffer got exhausted, some normal oneway transactions
will also be discarded and may cause system or application failures. By
that time, the binder debug information we dump may not be relevant to
the root cause. And this issue is difficult to debug if without the
backtrace of the thread sending spam.

This change will send BR_ONEWAY_SPAM_SUSPECT to userspace when oneway
spamming is detected, request to dump current backtrace. Oneway spamming
will be reported only once when exceeding the threshold (target process
dips below 80% of its oneway space, and current process is responsible
for either more than 50 transactions, or more than 50% of the oneway
space). And the detection will restart when the async buffer has
returned to a healthy state.

Acked-by: Todd Kjos <tkjos@google.com>
Signed-off-by: Hang Lu <hangl@codeaurora.org>
Link: https://lore.kernel.org/r/1617961246-4502-3-git-send-email-hangl@codeaurora.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 181190340
Change-Id: Id3d2526099bc89f04d8ad3ad6e48141b2a8f2515
(cherry picked from commit a7dc1e6f99df59799ab0128d9c4e47bbeceb934d)
Signed-off-by: Hang Lu <hangl@codeaurora.org>
[cmllamas: fix trivial merge issue]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-09-07 22:02:42 +00:00
Linux Build Service Account
9bdc77e622 Merge "msm-5.4.c3: qseecom: Fix possible race condition" into kernel.lnx.5.4.r1-rel 2024-09-03 03:33:24 -07:00
Linux Build Service Account
2913fc224e Merge "adsprpc: Handle UAF scenario in put_args" into kernel.lnx.5.4.r1-rel 2024-09-03 03:33:22 -07:00
Linux Build Service Account
b28cf76a9a Merge "msm: adsprpc: Avoid taking reference for group_info" into kernel.lnx.5.4.r1-rel 2024-09-03 03:33:20 -07:00
Divisha Bisht
3a617351ae msm-5.4.c3: qseecom: Fix possible race condition
Fix possible race condition in data->type value in case of multithreaded
listener or app IOCTLs.

For example, below could cause inconsistent data->type value while
racing belows IOCTLs

Thread1 with QSEECOM_IOCTL_REGISTER_LISTENER_REQ
Thread2 with QSEECOM_IOCTL_UNREGISTER_LISTENER_REQ.

Change-Id: I436b63c044a66c324d94db27566a7be70981bd6b
Signed-off-by: Divisha Bisht <quic_divibish@quicinc.com>
(cherry picked from commit f0e3f64088)
2024-09-03 00:13:12 -07:00
Linux Build Service Account
119c1bcc29 Merge 0fc0638ba8 on remote branch
Change-Id: I0ac91223cf762a6543e048c9fb59e52ea1098265
2024-08-30 04:52:01 -07:00
QCTECMDR Service
c3d6993d5c Merge "msm-5.4.c3: qseecom: Fix possible race condition" 2024-08-30 04:08:23 -07:00
ANANDU KRISHNAN E
20018f6ad2 msm: adsprpc: Avoid taking reference for group_info
Currently, the get_current_groups API accesses group info, which
increases the usage refcount. If the IOCTL using the
get_current_groups API is called many times, the usage counter
overflows. To avoid this, access group info without taking a
reference. A reference is not required as group info is not
released during the IOCTL call.

Change-Id: Ib4de80cac8b36f73d8f5c6dd9824722153189285
Signed-off-by: ANANDU KRISHNAN E <quic_anane@quicinc.com>
(cherry picked from commit de9f4fe6f8)
2024-08-30 01:59:00 -07:00
Santosh Sakore
8e0a90efc0 adsprpc: Handle UAF scenario in put_args
Currently, the DSP updates header buffers with unused DMA handle fds.
In the put_args section, if any DMA handle FDs are present in the
header buffer, the corresponding map is freed. However, since the
header buffer is exposed to users in unsigned PD, users can update
invalid FDs. If this invalid FD matches with any FD that is already
in use, it could lead to a use-after-free (UAF) vulnerability.
As a solution,add DMA handle references for DMA FDs, and the map for
the FD will be freed only when a reference is found.

Acked-by: Om Deore <quic_odeore@quicinc.com>
Change-Id: I19ae21230bf11fe89858b10c9069a5daccabc392
Signed-off-by: Santosh Sakore <quic_ssakore@quicinc.com>
(cherry picked from commit c6e7698c0c)
2024-08-30 01:52:15 -07:00
Divisha Bisht
f0e3f64088 msm-5.4.c3: qseecom: Fix possible race condition
Fix possible race condition in data->type value in case of multithreaded
listener or app IOCTLs.

For example, below could cause inconsistent data->type value while
racing belows IOCTLs

Thread1 with QSEECOM_IOCTL_REGISTER_LISTENER_REQ
Thread2 with QSEECOM_IOCTL_UNREGISTER_LISTENER_REQ.

Change-Id: I436b63c044a66c324d94db27566a7be70981bd6b
Signed-off-by: Divisha Bisht <quic_divibish@quicinc.com>
2024-08-29 22:14:16 -07:00
Rajashekar kuruva
54d3e3ca11 USB: storage: Replace the sprintf with scnprintf
'sprintf' has been deprecated, hence replace it with
a safer function scnprintf.

Change-Id: I9bc8e3dfd2032a0447f38fc98a3ad31d9d609cab
Signed-off-by: Rajashekar kuruva <quic_kuruva@quicinc.com>
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
2024-08-29 21:16:16 -07:00
QCTECMDR Service
83ba639ff8 Merge "adsprpc: Handle UAF scenario in put_args" 2024-08-29 17:29:58 -07:00
Santosh Sakore
c6e7698c0c adsprpc: Handle UAF scenario in put_args
Currently, the DSP updates header buffers with unused DMA handle fds.
In the put_args section, if any DMA handle FDs are present in the
header buffer, the corresponding map is freed. However, since the
header buffer is exposed to users in unsigned PD, users can update
invalid FDs. If this invalid FD matches with any FD that is already
in use, it could lead to a use-after-free (UAF) vulnerability.
As a solution,add DMA handle references for DMA FDs, and the map for
the FD will be freed only when a reference is found.

Acked-by: Om Deore <quic_odeore@quicinc.com>
Change-Id: I19ae21230bf11fe89858b10c9069a5daccabc392
Signed-off-by: Santosh Sakore <quic_ssakore@quicinc.com>
2024-08-29 09:15:22 -07:00
QCTECMDR Service
177e8e0fad Merge "msm: adsprpc: Avoid taking reference for group_info" 2024-08-29 07:38:37 -07:00
ANANDU KRISHNAN E
de9f4fe6f8 msm: adsprpc: Avoid taking reference for group_info
Currently, the get_current_groups API accesses group info, which
increases the usage refcount. If the IOCTL using the
get_current_groups API is called many times, the usage counter
overflows. To avoid this, access group info without taking a
reference. A reference is not required as group info is not
released during the IOCTL call.

Change-Id: Ib4de80cac8b36f73d8f5c6dd9824722153189285
Signed-off-by: ANANDU KRISHNAN E <quic_anane@quicinc.com>
2024-08-29 02:16:09 -07:00
Prashanth K
63a32bf361 usb: gadget: f_gsi: bail out if opts is null
Currently, functions gsi_inst_clean & gsi_free_inst utilises
gsi_opts without any check, however there is a possibility
that the opts structure could become NULL. In such case, due
to lack of if checks can result in NULL pointer dereference.

Change-Id: I548690e2eee377b5292f258972ae7e38417f3085
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
2024-08-28 22:14:17 -07:00
Greg Kroah-Hartman
df80fcf8cd Merge tag 'android11-5.4.281_r00' into android11-5.4
This catches the android11-5.4 branch up to the 5.4.281 LTS release.
Included in here are the following commits:

* a0347a4c8d Revert "net: mac802154: Fix racy device stats updates by DEV_STATS_INC() and DEV_STATS_ADD()"
*   c043beb2bd Merge 5.4.281 into android11-5.4-lts
|\
| * 84d75fd864 Linux 5.4.281
| * 8be915fc5f tap: add missing verification for short frame
| * 32b0aaba5d tun: add missing verification for short frame
| * 4c43ad4ab4 filelock: Fix fcntl/close race recovery compat path
| * d2c0c43dc4 ALSA: hda/realtek: Enable headset mic on Positivo SU C1400
| * fc16776a82 jfs: don't walk off the end of ealist
| * 564d23cc5b ocfs2: add bounds checking to ocfs2_check_dir_entry()
| * 59801e88c9 net: relax socket state check at accept time.
| * 3dd9734878 drm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq()
| * cfcdc6f6b2 ACPI: processor_idle: Fix invalid comparison with insertion sort for latency
| * 281e90e346 ARM: 9324/1: fix get_user() broken with veneer
| * c733e24a61 hfsplus: fix uninit-value in copy_name
| * 1d405de980 selftests/vDSO: fix clang build errors and warnings
| * 5a2e4cca14 spi: imx: Don't expect DMA for i.MX{25,35,50,51,53} cspi devices
| * 18ea1e471e fs: better handle deep ancestor chains in is_subdir()
| * 9cfc84b1d4 Bluetooth: hci_core: cancel all works upon hci_unregister_dev()
| * adc305fd60 scsi: libsas: Fix exp-attached device scan after probe failure scanned in again after probe failed
| * 8836e1bf58 powerpc/eeh: avoid possible crash when edev->pdev changes
| * a7b952941c powerpc/pseries: Whitelist dtl slub object for copying to userspace
| * e011febff8 net: mac802154: Fix racy device stats updates by DEV_STATS_INC() and DEV_STATS_ADD()
| * c48d9c1e38 net: usb: qmi_wwan: add Telit FN912 compositions
| * 58f03c322b ALSA: dmaengine_pcm: terminate dmaengine before synchronize
| * 455a6653d8 s390/sclp: Fix sclp_init() cleanup on failure
| * 15f5c60fe3 can: kvaser_usb: fix return value for hif_usb_send_regout
| * 45a6b888bc ASoC: ti: omap-hdmi: Fix too long driver name
| * 56c1ce1fa8 ASoC: ti: davinci-mcasp: Set min period size using FIFO config
| * 4b7c9f6501 bytcr_rt5640 : inverse jack detect for Archos 101 cesium
| * 2842f49427 Input: elantech - fix touchpad state on resume for Lenovo N24
| * 409299623a mips: fix compat_sys_lseek syscall
| * 922371a064 ALSA: hda/realtek: Add more codec ID to no shutup pins list
| * be847bb20c KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()
| * de5fcf757e wifi: cfg80211: wext: add extra SIOCSIWSCAN data check
| * 0feb07d339 mei: demote client disconnect warning on suspend to debug
| * 9f631c8ed0 fs/file: fix the check in find_next_fd()
| * 59fc8ffb54 kconfig: remove wrong expr_trans_bool()
| * a236ded9a3 kconfig: gconf: give a proper initial state to the Save button
| * 9610337109 ila: block BH in ila_output()
| * 47ad139d07 Input: silead - Always support 10 fingers
| * d46afb7c54 wifi: mac80211: fix UBSAN noise in ieee80211_prep_hw_scan()
| * e4bc8d4e49 wifi: mac80211: mesh: init nonpeer_pm to active by default in mesh sdata
| * 275590f2e9 ACPI: EC: Avoid returning AE_OK on errors in address space handler
| * 838d9c0f6b ACPI: EC: Abort address space access upon error
| * 49fba721ae scsi: qedf: Set qed_slowpath_params to zero before use
| * dc2ce1dfce filelock: Remove locks reliably when fcntl/close race is detected
| * 69df3bdb27 gcc-plugins: Rename last_stmt() for GCC 14+
* | b61187c891 ANDROID: GKI: refresh ABI to include kimage_vaddr
* | b2e024e390 Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
* | 33437b2981 ANDROID: preserve CRC for struct tcp_sock
* | f90cc3d8c1 Merge 5.4.280 into android11-5.4-lts
|\|
| * 88d2aa8774 Linux 5.4.280
| * 392b4f1149 i2c: rcar: bring hardware to known state when probing
| * 24c1c8566a nilfs2: fix kernel bug on rename operation of broken directory
| * d2346fca5b tcp: avoid too many retransmit packets
| * 2ff6dd600c tcp: use signed arithmetic in tcp_rtx_probe0_timed_out()
| * 8cc1b4d81a net: tcp: fix unexcepted socket die when snd_wnd is 0
| * 39dc2b8d55 tcp: refactor tcp_retransmit_timer()
| * 7d61d1da2e SUNRPC: Fix RPC client cleaned up the freed pipefs dentries
| * 63e5d035e3 libceph: fix race between delayed_work() and ceph_monc_stop()
| * 2b59187cf0 ALSA: hda/realtek: Limit mic boost on VAIO PRO PX
| * 427524ff30 nvmem: meson-efuse: Fix return value of nvmem callbacks
| * db18df897d hpet: Support 32-bit userspace
| * 60abea505b USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor
| * c95fbdde87 usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()
| * 4fdf8c1442 USB: Add USB_QUIRK_NO_SET_INTF quirk for START BP-850k
| * 421fcde004 USB: serial: option: add Rolling RW350-GL variants
| * c16c577cc6 USB: serial: option: add Netprisma LCUK54 series modules
| * 97fc18b2af USB: serial: option: add support for Foxconn T99W651
| * a647d795ef USB: serial: option: add Fibocom FM350-GL
| * 6877a78894 USB: serial: option: add Telit FN912 rmnet compositions
| * 895b666846 USB: serial: option: add Telit generic core-dump composition
| * b7ea5bea1e octeontx2-af: fix detection of IP layer
| * 833a64978a ARM: davinci: Convert comma to semicolon
| * 834681e42a s390: Mark psw in __load_psw_mask() as __unitialized
| * 7a67c4e476 udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port().
| * 6e8f1c2117 ppp: reject claimed-as-LCP but actually malformed packets
| * 907443174e net: ethernet: lantiq_etop: fix double free in detach
| * b1f3921335 net: lantiq_etop: add blank line after declaration
| * 73c2119833 octeontx2-af: Fix incorrect value output on error path in rvu_check_rsrc_availability()
| * 47d4a1f8fc tcp: fix incorrect undo caused by DSACK of TLP retransmit
| * fe7a7b8942 tcp: add TCP_INFO status for failed client TFO
| * ec48e8e343 vfs: don't mod negative dentry count when on shrinker list
| * c0d80ea39a fs/dcache: Re-use value stored to dentry->d_flags instead of re-reading
| * 1cbbb3d947 filelock: fix potential use-after-free in posix_lock_inode
| * 4380b1af28 nilfs2: fix incorrect inode allocation from reserved inodes
| * 262f126ebb nvme-multipath: find NUMA path only for online numa-node
| * 88f5c27988 ALSA: hda/realtek: Enable headset mic of JP-IK LEAP W502 with ALC897
| * effe0500af i2c: pnx: Fix potential deadlock warning from del_timer_sync() call in isr
| * 40945660b4 media: dw2102: fix a potential buffer overflow
| * cbe5308702 bnx2x: Fix multiple UBSAN array-index-out-of-bounds
| * 917c0e2f15 drm/amdgpu/atomfirmware: silence UBSAN warning
| * e36364f5f3 drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes
| * 23a28f5f3f Revert "mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again"
| * 7cfcb65054 fsnotify: Do not generate events for O_PATH file descriptors
| * 6ac691872e can: kvaser_usb: Explicitly initialize family in leafimx driver_info struct
| * 25ab2411cb mm: optimize the redundant loop of mm_update_owner_next()
| * 07c176e7ac nilfs2: add missing check for inode numbers on directory entries
| * 08cab183a6 nilfs2: fix inode number range checks
| * 0184bf0a34 inet_diag: Initialize pad field in struct inet_diag_req_v2
| * 5b627a4082 selftests: make order checking verbose in msg_zerocopy selftest
| * 0d1ad62524 selftests: fix OOM in msg_zerocopy selftest
| * 6b21346b39 bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set()
| * de046fe83c wifi: wilc1000: fix ies_len type in connect path
| * 2a2e79dbe2 tcp_metrics: validate source addr length
| * d8aef6be52 UPSTREAM: tcp: fix DSACK undo in fast recovery to call tcp_try_to_open()
| * 5d17bcc30d net: tcp better handling of reordering then loss cases
| * ddb97a331d tcp: add ece_ack flag to reno sack functions
| * fe36035207 tcp: tcp_mark_head_lost is only valid for sack-tcp
| * b5eb9176eb s390/pkey: Wipe sensitive data on failure
| * 0b3246052e jffs2: Fix potential illegal address access in jffs2_free_inode
| * bf3336ff11 powerpc/xmon: Check cpu id in commands "c#", "dp#" and "dx#"
| * 556edaa27c orangefs: fix out-of-bounds fsid access
| * 048703bb5c powerpc/64: Set _IO_BASE to POISON_POINTER_DELTA not 0 for CONFIG_PCI=n
| * aa5653209c i2c: i801: Annotate apanel_addr as __ro_after_init
| * 5c72587d02 media: dvb-frontends: tda10048: Fix integer overflow
| * e65ebfaabb media: s2255: Use refcount_t instead of atomic_t for num_channels
| * d84e51c272 media: dvb-frontends: tda18271c2dd: Remove casting during div
| * 3bf8d70e14 net: dsa: mv88e6xxx: Correct check for empty list
| * 13528e1d8f Input: ff-core - prefer struct_size over open coded arithmetic
| * 69fa4c636e firmware: dmi: Stop decoding on broken entry
| * a69aac931f sctp: prefer struct_size over open coded arithmetic
| * e3a23c3aa1 media: dw2102: Don't translate i2c read into write
| * eacca028a6 drm/amd/display: Skip finding free audio for unknown engine_id
| * 0046d87ed6 drm/amdgpu: Initialize timestamp for some legacy SOCs
| * 4f314aadee scsi: qedf: Make qedf_execute_tmf() non-preemptible
| * b491370241 IB/core: Implement a limit on UMAD receive List
| * f273ea5eb8 media: dvb-usb: dib0700_devices: Add missing release_firmware()
| * 4777123f8b media: dvb: as102-fe: Fix as10x_register_addr packing
| * 0d60c43df5 drm/lima: fix shared irq handling on driver remove
| * 34b0536965 Compiler Attributes: Add __uninitialized macro
* | a54d566214 Merge 5.4.279 into android11-5.4-lts
|/
* 5096731948 Linux 5.4.279
* 73f0f07b59 arm64: dts: rockchip: Add sound-dai-cells for RK3368
* 8023cf6edd ARM: dts: rockchip: rk3066a: add #sound-dai-cells to hdmi node
* d529193eae tcp: Fix data races around icsk->icsk_af_ops.
* f194e63054 ipv6: Fix data races around sk->sk_prot.
* 18560b76c7 ipv6: annotate some data-races around sk->sk_prot
* 6a91d8eb5a nfs: Leave pages in the pagecache if readpage failed
* d59bb70350 pwm: stm32: Refuse too small period requests
* 82982175be mtd: spinand: macronix: Add support for serial NAND flash
* f531d4bc6c ftruncate: pass a signed offset
* 56f1c7e290 ata: libata-core: Fix double free on error
* fb59ed1a15 batman-adv: Don't accept TT entries for out-of-spec VIDs
* 1c9f2e6015 drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_hd_modes
* dbd75f3225 drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_ld_modes
* c176f429f1 hexagon: fix fadvise64_64 calling conventions
* 672d065b23 csky, hexagon: fix broken sys_sync_file_range
* ed581989d7 net: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rts_session_new
* b00d49003b net: can: j1939: recover socket queue on CAN bus error during BAM transmission
* 5e4ed38eb1 net: can: j1939: Initialize unused data in j1939_send_one()
* 9e0e2aa362 tty: mcf: MCF54418 has 10 UARTS
* 23926d316d usb: atm: cxacru: fix endpoint checking in cxacru_bind()
* adf6ff216a usb: musb: da8xx: fix a resource leak in probe()
* be9ab6bc9b usb: gadget: printer: SS+ support
* cbefac615f net: usb: ax88179_178a: improve link status logs
* 00dd15aa87 iio: chemical: bme680: Fix sensor data read operation
* b0af334616 iio: chemical: bme680: Fix overflows in compensate() functions
* 0e3d3ca499 iio: chemical: bme680: Fix calibration data variable
* e2d03080ed iio: chemical: bme680: Fix pressure value output
* 9423fc2d02 iio: adc: ad7266: Fix variable checking bug
* 605466fcf4 mmc: sdhci: Do not lock spinlock around mmc_gpio_get_ro()
* d9e8b0f56b mmc: sdhci: Do not invert write-protect twice
* f24f76f59f mmc: sdhci-pci: Convert PCIBIOS_* return codes to errnos
* 27c3be8409 x86: stop playing stack games in profile_pc()
* cd75721984 gpio: davinci: Validate the obtained number of IRQs
* 5b289f24bb nvme: fixup comment for nvme RDMA Provider Type
* 49c0f6f119 soc: ti: wkup_m3_ipc: Send NULL dummy message instead of pointer message
* dc307b9eb6 media: dvbdev: Initialize sbuf
* 79d9a000f0 ALSA: emux: improve patch ioctl data validation
* b2262b3be2 net/dpaa2: Avoid explicit cpumask var allocation on stack
* 842afb47d8 net/iucv: Avoid explicit cpumask var allocation on stack
* 143ec47f4f mtd: partitions: redboot: Added conversion of operands to a larger type
* 98686ec182 drm/panel: ilitek-ili9881c: Fix warning with GPIO controllers that sleep
* 23752737c6 netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers
* 7122df1a13 parisc: use correct compat recv/recvfrom syscalls
* be8ee8032f sparc: fix old compat_sys_select()
* cb9285617e net: phy: micrel: add Microchip KSZ 9477 to the device table
* 3f5e8191a1 net: phy: mchp: Add support for LAN8814 QUAD PHY
* d5b0053b93 net: dsa: microchip: fix initial port flush problem
* 8896e18b7c ASoC: fsl-asoc-card: set priv->pdev before using it
* 7d589b7d23 netfilter: nf_tables: validate family when identifying table via handle
* 1c44f7759a drm/amdgpu: fix UBSAN warning in kv_dpm.c
* df9409bb0e pinctrl: rockchip: fix pinmux reset in rockchip_pmx_set
* 18acf67d3c pinctrl: rockchip: fix pinmux bits for RK3328 GPIO3-B pins
* 95848c3596 pinctrl: rockchip: fix pinmux bits for RK3328 GPIO2-B pins
* 420ce12619 pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER
* 6290b2cc56 iio: dac: ad5592r: fix temperature channel scaling value
* c1cd6d0591 iio: dac: ad5592r: un-indent code-block for scale read
* 3bd4e475ce iio: dac: ad5592r-base: Replace indio_dev->mlock with own device lock
* 3f0e0be5f8 x86/amd_nb: Check for invalid SMN reads
* 91870a211a PCI: Add PCI_ERROR_RESPONSE and related definitions
* 5bbf6ad532 perf/core: Fix missing wakeup when waiting for context reference
* c1fedc15e6 kheaders: explicitly define file modes for archived headers
* beace929a2 Revert "kheaders: substituting --sort in archive creation"
* 7abb6dcf4d tracing: Add MODULE_DESCRIPTION() to preemptirq_delay_test
* 2a200310e3 arm64: dts: qcom: qcs404: fix bluetooth device address
* f22e9e675e ARM: dts: samsung: smdk4412: fix keypad no-autorepeat
* c4ece19fe5 ARM: dts: samsung: exynos4412-origen: fix keypad no-autorepeat
* 3642af0a2c ARM: dts: samsung: smdkv310: fix keypad no-autorepeat
* 6e55cf4943 i2c: ocores: set IACK bit after core is enabled
* 89059eddac gcov: add support for GCC 14
* a8c6df9fe5 drm/radeon: fix UBSAN warning in kv_dpm.c
* ae465109d8 ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine."
* 7c3d43723a dmaengine: ioatdma: Fix missing kmem_cache_destroy()
* 70a527b606 regulator: core: Fix modpost error "regulator_get_regmap" undefined
* 6fd8e8e7b0 net: usb: rtl8150 fix unintiatilzed variables in rtl8150_get_link_ksettings
* 3799d02ae4 netfilter: ipset: Fix suspicious rcu_dereference_protected()
* 5b7d611fb8 virtio_net: checksum offloading handling fix
* 0d8a2d287c net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc()
* 6b02df925e net/sched: act_api: rely on rcu in tcf_idr_check_alloc
* 3a6cd326ea netns: Make get_net_ns() handle zero refcount net
* caf0bec84c xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr()
* d66fc48261 ipv6: prevent possible NULL dereference in rt6_probe()
* 3200ffeec4 ipv6: prevent possible NULL deref in fib6_nh_init()
* e07a9c2a85 netrom: Fix a memory leak in nr_heartbeat_expiry()
* 11b09f4015 cipso: fix total option length computation
* 10afe5f7d3 mips: bmips: BCM6358: make sure CBR is correctly set
* 31a77b23ae MIPS: Routerboard 532: Fix vendor retry check code
* 64845ac648 MIPS: Octeon: Add PCIe link status check
* 993401b52f PCI/PM: Avoid D3cold for HP Pavilion 17 PC/1972 PCIe Ports
* 060868e6ab udf: udftime: prevent overflow in udf_disk_stamp_to_time()
* dff3b01e91 usb: misc: uss720: check for incompatible versions of the Belkin F5U002
* be601edecf powerpc/io: Avoid clang null pointer arithmetic warnings
* 19c166ee42 powerpc/pseries: Enforce hcall result buffer validity and size
* 6eaaa1e440 Bluetooth: ath3k: Fix multiple issues reported by checkpatch.pl
* 21c963de2e scsi: qedi: Fix crash while reading debugfs attribute
* 594e47957f drop_monitor: replace spin_lock by raw_spin_lock
* 154e3f862b batman-adv: bypass empty buckets in batadv_purge_orig_ref()
* 1d01d0f498 selftests/bpf: Prevent client connect before server bind in test_tc_tunnel.sh
* 075fc5d20c rcutorture: Fix rcu_torture_one_read() pipe_count overflow comment
* f51f449e7d i2c: at91: Fix the functionality flags of the slave-only interface
* 51fe16c058 usb-storage: alauda: Check whether the media is initialized
* 74cd0a4218 greybus: Fix use-after-free bug in gb_interface_release due to race condition.
* cf39c4f77a netfilter: nftables: exthdr: fix 4-byte stack OOB write
* 6302bdfeb4 hugetlb_encode.h: fix undefined behaviour (34 << 26)
* b3f5d4e767 hv_utils: drain the timesync packets on onchannelcallback
* fd093ae0d3 tick/nohz_full: Don't abuse smp_call_function_single() in tick_setup_device()
* a75b8f493d nilfs2: fix potential kernel bug due to lack of writeback flag waiting
* 59f9bea4ef intel_th: pci: Add Lunar Lake support
* b51a4d3310 intel_th: pci: Add Meteor Lake-S support
* 41982a9191 intel_th: pci: Add Sapphire Rapids SOC support
* 3e9c81086e intel_th: pci: Add Granite Rapids SOC support
* 0deb268526 intel_th: pci: Add Granite Rapids support
* 4d35028fb0 dmaengine: axi-dmac: fix possible race in remove()
* 5edb09d66c PCI: rockchip-ep: Remove wrong mask on subsys_vendor_id
* e8e2db1ada ocfs2: fix races between hole punching and AIO+DIO
* 292665c1e7 ocfs2: use coarse time for new created files
* 803d5a33d5 fs/proc: fix softlockup in __read_vmcore
* 681967c4ff vmci: prevent speculation leaks by sanitizing event in event_deliver()
* 4c2df1874b tracing/selftests: Fix kprobe event name test for .isra. functions
* e23f2eaf51 drm/exynos: hdmi: report safe 640x480 mode as a fallback when no EDID found
* ebcf81504f drm/exynos/vidi: fix memory leak in .get_modes()
* 13d25e82b6 drivers: core: synchronize really_probe() and dev_uevent()
* 0d19267cb1 ionic: fix use after netif_napi_del()
* b3e5f33fbe net/ipv6: Fix the RT cache flush via sysctl using a previous delay
* c0761d1f1c netfilter: ipset: Fix race between namespace cleanup and gc in the list:set type
* cd41a24ab4 Bluetooth: L2CAP: Fix rejecting L2CAP_CONN_PARAM_UPDATE_REQ
* 860abda358 net/mlx5e: Fix features validation check for tunneled UDP (non-VXLAN) packets
* 030df5c422 tcp: fix race in tcp_v6_syn_recv_sock()
* 59217c5722 drm/bridge/panel: Fix runtime warning on panel bridge release
* 0674ed1e58 drm/komeda: check for error-valued pointer
* dcc7440f32 liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet
* 15122dc140 HID: logitech-dj: Fix memory leak in logi_dj_recv_switch_to_dj_mode()
* 700f564758 iommu: Return right value in iommu_sva_bind_device()
* 61bbbc665f iommu/amd: Fix sysfs leak in iommu init
* f9db5fbeff HID: core: remove unnecessary WARN_ON() in implement()
* e817bff375 gpio: tqmx86: fix typo in Kconfig label
* 7ef55e6b95 SUNRPC: return proper error from gss_wrap_req_priv
* 08637180f7 Input: try trimming too long modalias strings
* 19649e49a6 scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory
* 707d153ec4 xhci: Apply broken streams quirk to Etron EJ188 xHCI host
* 5a9e518b8b xhci: Apply reset resume quirk to Etron EJ188 xHCI host
* 4cacb44810 xhci: Set correct transferred length for cancelled bulk transfers
* 1e84c9b183 jfs: xattr: fix buffer overflow for invalid xattr
* a1e6e2a221 mei: me: release irq in mei_me_pci_resume error path
* 05b2cd6d33 USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages
* 405b71f125 nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors
* d1194314f4 nilfs2: return the mapped address from nilfs_get_page()
* 93ac3da63a nilfs2: Remove check for PageError
* 2c9456e0a5 selftests/mm: compaction_test: fix bogus test success on Aarch64
* 29cfada209 selftests/mm: conform test to TAP format output
* 8767e3ec55 selftests/mm: compaction_test: fix incorrect write of zero to nr_hugepages
* f1ebd2c8de serial: sc16is7xx: fix bug in sc16is7xx_set_baud() when using prescaler
* 0876b726c8 serial: sc16is7xx: replace hardcoded divisor value with BIT() macro
* 63127374c8 drm/amd/display: Handle Y carry-over in VCP X.Y calculation
* 71a0cb1ba6 ASoC: ti: davinci-mcasp: Fix race condition during probe
* 808d885740 ASoC: ti: davinci-mcasp: Handle missing required DT properties
* 84d923099e ASoC: ti: davinci-mcasp: Simplify the configuration parameter handling
* 6405101177 ASoC: ti: davinci-mcasp: Remove legacy dma_request parsing
* 1e2fbb5e1a ASoC: ti: davinci-mcasp: Use platform_get_irq_byname_optional
* 6daaf36291 ASoC: ti: davinci-mcasp: remove always zero of davinci_mcasp_get_dt_params
* da5ff71c65 ASoC: ti: davinci-mcasp: remove redundant assignment to variable ret
* 9e72ef59cb usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete
* c90af1cced ipv6: fix possible race in __fib6_drop_pcpu_from()
* ba387948b7 af_unix: Annotate data-race of sk->sk_shutdown in sk_diag_fill().
* 5968c834b4 af_unix: Use skb_queue_len_lockless() in sk_diag_show_rqlen().
* 682fe47168 af_unix: Use unix_recvq_full_lockless() in unix_stream_connect().
* 7e1fd47ccd af_unix: Annotate data-race of net->unx.sysctl_max_dgram_qlen.
* 45ad9f9a5f af_unix: Annotate data-races around sk->sk_state in UNIX_DIAG.
* 54d5a52bd8 af_unix: Annotate data-races around sk->sk_state in sendmsg() and recvmsg().
* f69e57925e af_unix: Annotate data-races around sk->sk_state in unix_write_space() and poll().
* 863250c01b af_unix: Annotate data-race of sk->sk_state in unix_inq_len().
* f1a03799d8 ptp: Fix error message on failed pin verification
* c6041e7124 net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP
* a0a0a84d9a net/mlx5: Stop waiting for PCI if pci channel is offline
* b2ca635b82 tcp: count CLOSE-WAIT sockets for TCP_MIB_CURRESTAB
* 29e49cc655 vxlan: Fix regression when dropping packets due to invalid src addresses
* d5d9d24178 net: sched: sch_multiq: fix possible OOB write in multiq_tune()
* 80021fe0c7 ipv6: sr: block BH in seg6_output_core() and seg6_input_core()
* 6532f18e66 wifi: iwlwifi: mvm: don't read past the mfuart notifcation
* 2f2809e4c4 wifi: iwlwifi: dbg_ini: move iwl_dbg_tlv_free outside of debugfs ifdef
* d22cfa12ee wifi: iwlwifi: mvm: revert gen2 TX A-MPDU size to 64
* 9c0c2940dc wifi: cfg80211: pmsr: use correct nla_get_uX functions
* 28ba44d680 wifi: mac80211: Fix deadlock in ieee80211_sta_ps_deliver_wakeup()
* ec79670eae wifi: mac80211: mesh: Fix leak of mesh_preq_queue objects

Change-Id: I615ba6af1d77feff21f5d5b89bfa766f9b1e5e3f
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-08-27 18:52:38 +00:00
Hangyu Hua
ef9a17e64f UPSTREAM: net: sched: sch_multiq: fix possible OOB write in multiq_tune()
[ Upstream commit affc18fdc694190ca7575b9a86632a73b9fe043d ]

q->bands will be assigned to qopt->bands to execute subsequent code logic
after kmalloc. So the old q->bands should not be used in kmalloc.
Otherwise, an out-of-bounds write will occur.

Bug: 349777785
Fixes: c2999f7fb0 ("net: sched: multiq: don't call qdisc_put() while holding tree lock")
Signed-off-by: Hangyu Hua <hbh25y@gmail.com>
Acked-by: Cong Wang <cong.wang@bytedance.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit 0f208fad86631e005754606c3ec80c0d44a11882)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Iec8413c39878596795420ae58bbe6974890cf2de
2024-08-27 09:59:25 +01:00
QCTECMDR Service
0fc0638ba8 Merge "msm: ep_pcie: Avoid setting host wake pending flag for D0" 2024-08-27 00:24:32 -07:00
Carlos Llamas
f4e5b5151e FROMLIST: binder: fix UAF caused by offsets overwrite
Binder objects are processed and copied individually into the target
buffer during transactions. Any raw data in-between these objects is
copied as well. However, this raw data copy lacks an out-of-bounds
check. If the raw data exceeds the data section size then the copy
overwrites the offsets section. This eventually triggers an error that
attempts to unwind the processed objects. However, at this point the
offsets used to index these objects are now corrupted.

Unwinding with corrupted offsets can result in decrements of arbitrary
nodes and lead to their premature release. Other users of such nodes are
left with a dangling pointer triggering a use-after-free. This issue is
made evident by the following KASAN report (trimmed):

  ==================================================================
  BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x19c
  Write of size 4 at addr ffff47fc91598f04 by task binder-util/743

  CPU: 9 UID: 0 PID: 743 Comm: binder-util Not tainted 6.11.0-rc4 #1
  Hardware name: linux,dummy-virt (DT)
  Call trace:
   _raw_spin_lock+0xe4/0x19c
   binder_free_buf+0x128/0x434
   binder_thread_write+0x8a4/0x3260
   binder_ioctl+0x18f0/0x258c
  [...]

  Allocated by task 743:
   __kmalloc_cache_noprof+0x110/0x270
   binder_new_node+0x50/0x700
   binder_transaction+0x413c/0x6da8
   binder_thread_write+0x978/0x3260
   binder_ioctl+0x18f0/0x258c
  [...]

  Freed by task 745:
   kfree+0xbc/0x208
   binder_thread_read+0x1c5c/0x37d4
   binder_ioctl+0x16d8/0x258c
  [...]
  ==================================================================

To avoid this issue, let's check that the raw data copy is within the
boundaries of the data section.

Fixes: 6d98eb95b450 ("binder: avoid potential data leakage when copying txn")
Cc: Todd Kjos <tkjos@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: Carlos Llamas <cmllamas@google.com>

Bug: 352520660
Link: https://lore.kernel.org/all/20240822182353.2129600-1-cmllamas@google.com/
Change-Id: I1b2dd8403b63e5eeb58904558b7b542141c83fc2
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-08-23 16:47:50 +00:00
QCTECMDR Service
97fd8bd8e6 Merge "msm: ep_pcie: Prevent repetitive wake operation if wake is in process" 2024-08-23 07:47:48 -07:00
Sai Chaitanya Kaveti
ccba394a90 msm: ep_pcie: Avoid setting host wake pending flag for D0
In current implementation, when host wake request is received in D0 and
M3 states, the following sequence of events are happening causing next
host wake request from IPA/ client to fail.

Sequence of events:
1. Device is in waking up process in D0, M3 states and expecting M0
next.
2. Wake up request received as device in M3.
3. Host wake API is executed setting host_wake_pending flag as well.
4. M0 received as part of wake up from 1.
5. Device in D0, M0 states.
6. Device again went to suspend state as no transfers are happening.
7. Device in D3cold, M3 states
8. Wake up request received from IPA.
9. Host wake API is called again but its returning without any operation
as host_wake_pending flag is set. wake toggle is not done.
10. host_wake_pending flag is cleared only on receiving next D0.
11. Host wake requests are failing because of 9.

To handle this, avoiding setting of host_wake_pending flag when the host
wake request is received in D0 state.

Change-Id: I83acde55e6c116653c3ed00e6b4560e3db6390bd
Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
2024-08-23 14:46:48 +05:30
Qiang Yu
d62bca7bf4 msm: ep_pcie: Prevent repetitive wake operation if wake is in process
Sometimes, device receives two consecutive wake-up events, added into a
workqueue. Then device assert WAKE# and host deassert PERST# if device
in D3cold state, triggering deassert perst IRQ. In IRQ thread, device
flush the workqueue to make sure previous d3cold process has completed
before enable endpoint. commit 43917f862f7d ("msm: mhi_dev: Flush
workqueue before processing PERST deassert"). However, the second wake
event is also in the workqueue, so ep_pcie_core_wakeup_host_internal
is invoked and seeing dev->perst_deast is true, setted by deassert
PERST# IRQ. Then device goes to access MHI register to issue inband PME,
leading to NOC error because endpoint is still disabled.

So add a check to prevent wake operation if a previous wake has completed.

10567.834470: [0x8219195 mhi_sm_dev_event_manager] Handling
MHI_DEV_EVENT_CORE_WAKEUP event, current states: M3 & D3_COLD_STATE
10567.834498: ep_pcie_core_toggle_wake_gpio: PCIe V1711211: No. 115 to
assert PCIe WAKE#; perst is asserted; D3hot is  received, WAKE GPIO
state:0
10567.834507: ep_pcie_core_wakeup_host_internal: PCIe V1711211: Set wake
pending : 1 and return ; perst is not de-asserted; D3hot is set
10567.849704: [0x8219195 mhi_dev_notify_sm_event] received:
MHI_DEV_EVENT_HW_ACC_WAKEUP
10567.849976: ep_pcie_handle_perst_irq: PCIe V1711211: No. 1018 PERST
deassertion
10567.850053: [0x8219195 mhi_sm_dev_event_manager] Handling
MHI_DEV_EVENT_HW_ACC_WAKEUP event, current states: M3 & D3_COLD_STATE
10567.850071: ep_pcie_core_wakeup_host_internal: PCIe V1711211: request to
assert WAKE# when in D3hot
10567.860093: ep_pcie_core_issue_inband_pme: PCIe V1711211: request to
assert inband wake.

Change-Id: I85fb37c4171c5ef4974c573f0abba199cb718a84
Signed-off-by: Qiang Yu <quic_qianyu@quicinc.com>
2024-08-23 14:36:50 +05:30
Qihang Hu
a6f230d5d5 usb: gadget: composite: Show warning if function driver's descriptors are incomplete.
In the config_ep_by_speed_and_alt function, select the corresponding
descriptor through g->speed. But some legacy or not well designed
function drivers may not support the corresponding speed. So, we can
directly display warnings instead of causing kernel panic. At the
same time, it indicates the reasons in warning message.

Change-Id: Ib8c979663d9f04212bcc3ef4e1c0dc5be26c6958
Reviewed-by: Peter Chen <peter.chen@kernel.org>
Signed-off-by: Qihang Hu <huqihang@oppo.com>
Link: https://lore.kernel.org/r/20211110101129.462357-1-huqihang@oppo.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Mot-CRs-Fixed: (CR)
Reviewed-on: https://gerrit.mot.com/2264211
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Tested-by: Jira Key
Reviewed-by: Igor Kovalenko <igork@motorola.com>
Submit-Approved: Jira Key
2024-08-19 07:17:56 +00:00
Alexander Winkowski
02b9f89f58
Revert "BACKPORT: kgsl: hwsched: Don't cross dereference kgsl_mem_entry pointer"
This reverts commit e7fe0e2788.

According to Qualcomm, this platform is not affected [1]. It causes NULL
pointer dereference on older kernels due to the lack of 976b6d97c6.

[1] https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2024-bulletin.html#_cve-2024-21478
Change-Id: Ic50a8c89ec9f0b4f56ac90125be646147bae5f20
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
2024-08-18 18:08:16 +00:00
Sheenam Monga
9944a4c53c
BACKPORT: qcacmn: Fix potential OOB read in util_scan_parse_rnr_ie
Currently, while parsing scan RNR Ie data is moved to
next neighbor_ap_info_field after parsing the current
neighbor_ap_info_field. But in last iteration pointer may
try to access invalid data if (uint8_t *)ie + rnr_ie_len + 2)
bytes are less than sizeof neighbor_ap_info_field and same
is the case with tbtt_length access.

Fix is to add a length check of data + next data size to be parsed
< (uint8_t *)ie + rnr_ie_len + 2) instead of adding a validation
of data length only.

CRs-Fixed: 3710080
Change-Id: I05e5a9a02f0f4f9bc468db894588e676f0a248c0
2024-08-16 00:48:57 +03:00
Harshdeep Dhatt
e7fe0e2788
BACKPORT: kgsl: hwsched: Don't cross dereference kgsl_mem_entry pointer
The passed in pointer in kgsl_count_hw_fences() can be a
kgsl_mem_entry pointer. This gets cross dereferenced to
a kgsl_drawobj_sync_event pointer and causes a NULL pointer
dereference. To avoid this cross dereference, decouple the two
paths and call kgsl_count_hw_fences() only in the appropriate
path.

Change-Id: I1088a0b67f1f82a20ddc94c94cbdd31a44b18da6
Signed-off-by: Harshdeep Dhatt <quic_hdhatt@quicinc.com>
2024-08-16 00:33:07 +03:00
QCTECMDR Service
0f0f48e68a Merge "msm_ipa: Install exception rule for PPPoE-MPLS" 2024-08-13 00:40:16 -07:00
Himansu Nayak
752e583b65 msm_ipa: Install exception rule for PPPoE-MPLS
Add code to install exception rule for icmp
and dhcp packet in DL direction for v4 and v6.

Change-Id: I27a2c3cb9cb342a5e4d22246e350bf721d784a15
Signed-off-by: Himansu Nayak <quic_himansu@quicinc.com>
2024-08-13 00:15:43 +05:30
Greg Kroah-Hartman
a0347a4c8d Revert "net: mac802154: Fix racy device stats updates by DEV_STATS_INC() and DEV_STATS_ADD()"
This reverts commit e011febff8 which is
commit b8ec0dc3845f6c9089573cb5c2c4b05f7fc10728 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I08cf60f05f5db95e255ce111e9556b0671b0cc09
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-08-11 14:29:33 +00:00
Siddharth Gupta
5777b2cd18 soc: qcom: mdt_loader: Read hash from firmware blob
Since the split elf blobs will always contain the hash segment, we rely on
the blob file to get the hash rather than assume that it will be present in
the mdt file. This change uses the hash index to read the appropriate elf
blob to get the hash segment.

Change-Id: Iaf37a15f7794d417d01d9eda4a9df772623ae19c
Signed-off-by: Siddharth Gupta <sidgup@codeaurora.org>
2024-08-08 16:32:23 -05:00
Siddharth Gupta
a748d0a179 soc: qcom: mdt_loader: Handle split bins correctly
It may be that the offset of the first program header lies inside the mdt's
filesize, in this case the loader would incorrectly assume that the bins
were not split. The loading would then continue on to fail for split bins.
This change updates the logic used by the mdt loader to understand whether
the firmware images are split or not. It figures this out by checking if
each programs header's segment lies within the file or not.

Change-Id: I18ce4922eadceb96193584d829829878048ea045
Signed-off-by: Siddharth Gupta <sidgup@codeaurora.org>
2024-08-08 16:32:22 -05:00
Siddharth Gupta
94ab28d633 soc: qcom: mdt_loader: Allow hash at any phdr
The assumption that the elf program header will always have the hash
segment program header at index 1 may not hold true in all cases. This
change updates the read metadata function to find the hash program header
dynamically.

Change-Id: Ic5aa0d290b24ec3273003d980fec070b9e058c4f
Signed-off-by: Siddharth Gupta <sidgup@codeaurora.org>
2024-08-08 16:32:17 -05:00
Bruno Martins
616d4d19a3 Merge tag 'ASB-2024-08-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2024-08-01
CVE-2024-36971

* tag 'ASB-2024-08-05_11-5.4' of https://android.googlesource.com/kernel/common:
  UPSTREAM: usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()

Change-Id: Iff42948cbc36e52c49fe2dccc51e5173f4ed5a39
2024-08-08 16:44:56 +01:00
Michael Bestas
cf9c5fb631
Merge tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/dataipa into android13-5.4-lahaina
"LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0"

* tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/dataipa:
  msm: ipa: Add additional cleanup in finish rt rule addition
  msm: ipa: Add additional cleanup in finish rt rule addition

Change-Id: Ic51c62ff63dc875fb537329316d09c52aee89197
2024-08-05 23:58:26 +03:00
Michael Bestas
6f41a7e92b
Merge tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/camera-kernel into android13-5.4-lahaina
"LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0"

* tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/camera-kernel:
  msm: camera: sensor: TOCTOU error handling in eeprom
  msm: camera: sensor: TOCTOU error handling in eeprom
  msm: camera: sensor: TOCTOU error handling in eeprom
  msm: camera: sensor: TOCTOU error handling in eeprom

Change-Id: I185fde58c627ce0efc41855773e3b7d52075fd39
2024-08-05 22:15:53 +03:00
Michael Bestas
7262b988ea
Merge tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel into android13-5.4-lahaina
"LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0"

* tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel:
  dsp: q6lsm: Check size of payload before access

Change-Id: I782131a810aaecf254b92d94e2db252c3741784e
2024-08-05 22:14:56 +03:00