The DMA address allocated may be in 64-bit address
range if dma mask is set to 64-bit, the MSB register
value is required.
Signed-off-by: Cheng Zeng <quic_chenzeng@quicinc.com>
Remove Initializing rx_pkt link if dma mapping fails.
Change-Id: I49d08555c875fc9039805ef8775be3b676f51d08
Signed-off-by: Michael Adisumarta <madisuma@codeaurora.org>
Updated change to retry attaching smmu nodes if it fails, in a
deffered work queue with 500msec delay.
Change-Id: Ia54d801543224caf81085fedfd16305eca99995e
Signed-off-by: Raghavendar rao l <rlomte@codequrora.org>
Adding changes to support the deep sleep mode on monaco
target.
Change-Id: I50016848fde9533a856203bc2ad89bf851179a7b
Signed-off-by: Ashok Vuyyuru <quic_avuyyuru@quicinc.com>
While resetting the header rules if it find invalid header ID it
will return before freeting proc header table it was leading to use
after free when accessing the header pointer from proc header table.
Adding changes to NULL terminating header pointer in proc header table
after header table deleted from the list.
Change-Id: If270d855d3907e61368336316161a250053e1e62
Signed-off-by: Ashok Vuyyuru <avuyyuru@codeaurora.org>
During header deletion, if there is a HPC referencing to a header,
and the header is deleted, the later commit will cause
writing garbage values to the HW during commit.
Change-Id: Ib8bb490e38c57d975c21e5848850cd79263c95fe
Signed-off-by: Jagadeesh Ponduru <jponduru@codeaurora.org>
Currently during nop desc send, we are setting
nop pending flag to false before queing desc,
due to which we are not able to queue nop desc
again if it fails for first time. Now setting
nop pending flag to false only if we successfully
queued nop desc.
Change-Id: Ice0b3726f2ff0e81c0e5b041346e0ba06619ef62
Signed-off-by: Piyush Dhyani <pdhyani@codeaurora.org>
Increased the timeout value of ipa3_uc_send_cmd
from 10 to 20 in ipa3_uc_debug_stats_alloc function.
Change-Id: I5be5839c60b84226872a22e8a05bb712e395e62d
Signed-off-by: Jagadeesh Ponduru <jponduru@codeaurora.org>
For Q6 endpoints add change to not reset the HOLB timer
value to zero instead of default value. Add change to
enable HOLB twice for IPA 4.x targets.
Change-Id: Ic9596e711b037d24ae25835cb6dd193ec040d723
Signed-off-by: Praveen Kurapati <pkurapat@codeaurora.org>
Signed-off-by: Jagadeesh Ponduru <jponduru@codeaurora.org>
Make changes to free up all pending EOB pages when SKB allocation
used to handle EOT is failed as we could end up in a frag
overflow.
Change-Id: I80ae84d00d1bbf2cf89e97261d2fe8c3742eda04
Signed-off-by: Chaitanya Pratapa <cpratapa@codeaurora.org>
Signed-off-by: Jagadeesh Ponduru <jponduru@codeaurora.org>
If smmu is not enabled, smmu context device check
was missing before accessing it which was resulting
in null pointer dereference. Now adding check
before accessing it.
Change-Id: I94393524c79847a165ba605d34906525640b359a
Signed-off-by: Cheng Zeng <chenzeng@codeaurora.org>
Due to excessive logs from ipa it blocks other tasks execution.
Ratelimit added inorder to reduce the logs.
Change-Id: I00ae9b1e62dd14d82e22d3c788b68d0474a8de87
Signed-off-by: Praveen Kurapati <pkurapat@codeaurora.org>
To avoid temporary stall on WLAN client enabling the HOLB on
WLAN2 consumer pipe.
Change-Id: I3920205f7f62dbdd240da162fab4158ab8e070b4
Signed-off-by: Jagadeeesh Ponduru <jponduru@codeaurora.org>
Assign NULL to pointers that may be used later
after calling kfree on them.
Change-Id: I3298eb484c92ee2373f0bc41aae8ae45fb373cf0
Signed-off-by: Ilia Lin <ilialin@codeaurora.org>
Changed the spin_lock in ipa3_release_gsi_channel
to spin_lock_irqsave to avoid getting interrupted
while stop channel is command is executed.
Signed-off-by: Sivakanth Vaka <svaka@codeaurora.org>
This Issue is seen by Enabling CONFIG_DEBUG_ATOMIC_SLEEP=y and boot the
device.To avoid going into kernel panic state,changed the function
calls order of spin_lock() and idr_preload() after calling
kmem_cache_zalloc().Originally, these two functions were called
before calling kmem_cache_zalloc().
Change-Id: I2738548abd4148828e7d9436415c5c4d769680b9
Signed-off-by: Jagadeesh Ponduru <jponduru@codeaurora.org>
Changes done to copy num of rules from user space to
kernel side as earlier only payload was being copied.
Change-Id: I14e15fe0c6746226cc44d224d33c00e809cd69ca
Signed-off-by: Armaan Siddiqui <asiddiqu@codeaurora.org>
There are potential race condition ioctls in
the IPA driver when it copies the actual
arguments from the user-space memory to the
IPA-driver. The fix is to add check on the
2nd copy to make sure the same payload size
is copied to the pre-allocated kernel memory
as during the 1st copy.
Change-Id: I3d31cb11a24e969db4fd1728cf6ab1ce983a75e9
Signed-off-by: Armaan Siddiqui <asiddiqu@codeaurora.org>
The value of `req->filter_spec_ex2_list_len`
is user input via ioctl and it's type is uint32,
so an integer overflow may occur. Which can result
in out of bound access in the following loop. Now
add changes to prevent Integer overflow.
Change-Id: Ia29b9ddc674e5dd3d5baf6623cf0a464c156d8f7
Signed-off-by: Piyush Dhyani <pdhyani@codeaurora.org>
Make changes to populate qmap_id when disabling coalescing.
Change-Id: Iaf0981bd22948b87bb8f9c548fe74e789eaf689c
Signed-off-by: Chaitanya Pratapa <cpratapa@codeaurora.org>
Adding changes to retry with GFP_KENREL flag when memory allocation
fails with GFP_ATOMIC flag. Panic the device if after max retries
also memory allocation fails.
Change-Id: Ic9ad827757de92715be5acc5645b7e860b4bd0e4
Signed-off-by: Praveen Kurapati <pkurapat@codeaurora.org>
Fix use-after-free of rt_tbl in __ipa_del_flt_rule
by checking if the rt_tbl is already freed.
Change-Id: I09541f65f474dc42f262c603d99f6bbcbb0ce8ec
Signed-off-by: Goutam Bose <gbose@codeaurora.org>