* sm8350/lineage-20: (306 commits)
ANDROID: gki_defconfig: reduce KFENCE pool size
ANDROID: GKI: enable KFENCE by setting the sample interval to 500ms
ANDROID: GKI: Enable KFENCE
UPSTREAM: random: split initialization into early step and later step
UPSTREAM: kfence: avoid passing -g for test
UPSTREAM: net: add and use skb_unclone_keeptruesize() helper
UPSTREAM: kfence: fix memory leak when cat kfence objects
UPSTREAM: kfence: unconditionally use unbound work queue
UPSTREAM: kfence: use TASK_IDLE when awaiting allocation
UPSTREAM: kfence: fix is_kfence_address() for addresses below KFENCE_POOL_SIZE
FROMLIST: kfence: skip all GFP_ZONEMASK allocations
FROMLIST: kfence: move the size check to the beginning of __kfence_alloc()
ANDROID: kasan: fix interoperability with KFENCE
UPSTREAM: arm64: mm: don't use CON and BLK mapping if KFENCE is enabled
ANDROID: kfence: clean up unused variables
FROMGIT: kfence: use power-efficient work queue to run delayed work
FROMGIT: kfence: maximize allocation wait timeout duration
FROMGIT: kfence: await for allocation using wait_event
FROMGIT: kfence: zero guard page after out-of-bounds access
UPSTREAM: kfence: make compatible with kmemleak
...
Change-Id: Id1436b77692839dc2394f500bba42487fac1b2b4
LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0
* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/video-driver:
msm: vidc: Fix use after free in driver
msm: vidc: Enable hybrid mode only for HFR usecase
Change-Id: Ic2a5c64a04bcd2bed2c853f541255b7563d9b65c
LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0
* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/dataipa:
ipa: Added changes to move the hdr entry to free list
msm: ipa: Avoid use-after-free scenario
Change-Id: I53d9b6e5cd83948d5a7cd67b8b7ffa58af13efef
LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0
* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel:
asoc: lsm: thread safety issue in hw params management
asoc: lsm: Race condition protection in confidence levels handling
asoc: lsm: thread safety issue while accessing substream data
asoc: compress: race condition handling in stream cmd put function
asoc: handle heap overflow in effect driver
asoc: Update dai link for ACM8625S AMP.
asoc: Modification for 8ch capture
audio-kernel: Fix wcd938x DMIC unable to record
audio-kernel: Enable hdmi in audio function for AIO bar
dsp: q6adm: Checking array sizeof channel_type
asoc: codec: avoid out of bound write to map array
dsp: q6lsm: Check size of payload before access
Change-Id: I9eebb44e5b838891dc094853e28535930dee6b83
This reverts commit 7d3114211e.
Reason for revert: Causing display to turn off automatically on moderate and high temperature
Change-Id: I501ae17414f6b4e0c34b7dec2921a90603cbb44a
Signed-off-by: dodyirawan85 <dev.irawans@gmail.com>
Bangkk push for Android 15
* tag 'MMI-V1TC35H.88-16' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-display:
disp: msm: dsi: add null pointer check in dsi_display_dev_remove
msm/dsi_display: resend new roi to panel, fix pu dup issue
disp: msm: sde: clear cached rectangles when PU ROI is set
Change-Id: I2eed4c78f491b527ed088576e799dfb4488e5e97
Dynamic mode switch (DMS) is not supported for video mode panels
before cont-splash handoff handled for first frame. so avoid
dynamic mode-switch during cont-splash handoff for any DRM mode change.
WA is given by QC for GSI issue, as of observation there are no
side effects
QC SR:05515278
QC CR:NA
QC Change ID:Icd5881af99afb3e398d3bba3746b7a35bcda4491
Change-Id: I97f5712ce5bb8448f1c600ccf306d0dac7fa6eae
Signed-off-by: maheshmk <maheshmk@motorola.com>
Reviewed-on: https://gerrit.mot.com/2113033
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Tested-by: Jira Key
Reviewed-by: Ashwin Kumar Pathmudi <jfxr63@motorola.com>
Reviewed-by: Shuo Yan <shuoyan@motorola.com>
Reviewed-by: Guobin Zhang <zhanggb@motorola.com>
Submit-Approved: Jira Key
* We don't build the Camera HAL from source
so userspace does not need access to
cam_sensor.h, move it and implement guarding
for breaking changes for devices with older
Camera Blobs.
Change-Id: I5a45b83e01ad85752e99035805ee2a6d1f8dfa93
Signed-off-by: electimon <electimon@gmail.com>
Direct access to filesystem is insane and hits a neverallow, load it
through the firmware class instead.
Co-authored-by: Michael Bestas <mkbestas@lineageos.org>
Change-Id: Ic522644c73d63a36430526736257d635deb08f6a
Direct access to filesystem is insane and hits a neverallow, load it
through the firmware class instead.
Change-Id: I72149f8674c6211fab57a025b47cf84e505a256a
* sm8350/lineage-20:
UPSTREAM: net: sched: Disallow replacing of child qdisc from one parent to another
FROMGIT: media: venus: hfi: add a check to handle OOB in sfr region
FROMGIT: media: venus: hfi: add check to handle incorrect queue size
FROMGIT: media: venus: hfi_parser: refactor hfi packet parsing logic
FROMGIT: media: venus: hfi_parser: add check to avoid out of bound access
UPSTREAM: pfifo_tail_enqueue: Drop new packet when sch->limit == 0
UPSTREAM: f2fs: compress: don't allow unaligned truncation on released compress inode
UPSTREAM: net: core: reject skb_copy(_expand) for fraglist GSO skbs
UPSTREAM: udp: prevent local UDP tunnel packets from being GROed
UPSTREAM: udp: do not transition UDP GRO fraglist partial checksums to unnecessary
UPSTREAM: udp: do not accept non-tunnel GSO skbs landing in a tunnel
UPSTREAM: binder: Return EFAULT if we fail BINDER_ENABLE_ONEWAY_SPAM_DETECTION
UPSTREAM: usb: dwc3: host: Set XHCI_SG_TRB_CACHE_SIZE_QUIRK
UPSTREAM: usb: host: xhci-plat: Add support for XHCI_SG_TRB_CACHE_SIZE_QUIRK
UPSTREAM: usb: xhci: Add error handling in xhci_map_urb_for_dma
UPSTREAM: usb: xhci: Use temporary buffer to consolidate SG
UPSTREAM: usb: xhci: Set quirk for XHCI_SG_TRB_CACHE_SIZE_QUIRK
defconfig: Enable RTL8152 ETH-USB driver
ANDROID: ABI: Cuttlefish Symbol update
fw-api: CL 28563606 - update fw common interface files
...
Change-Id: I39d8fa1352de578a5a6c15be2b4b9911bf1c154c
LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0
# By Jayasri Sampath Kumaran
# Via Karthik Veeranki (1) and Linux Build Service Account (1)
* tag 'clo/display-drivers/LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0':
disp: msm: sde: fix kms NULL pointer access in encoder IRQ control
Change-Id: I52a1f3a27d8eed895e1db8a48f15c225d1c1c3ea
LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0
# By Ratna Deepthi Kudaravalli
# Via Linux Build Service Account (1) and Ratna Deepthi Kudaravalli (1)
* tag 'clo/audio-kernel/LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0':
audio-kernel: avoid out of bound read while checking a bit
Change-Id: I70a5aa2eb95361d9181d5e93a2bbbcce590ce7db
I am pretty sure prod builds don't need this to be enabled and was
meant originally to be used in the development phase.
Further, dmesg shows that it fails to open the file:
aw_cali_get_read_cali_re:channel:1 open /mnt/vendor/persist/factory/audio/aw_cali.bin failed!
Change-Id: I61c5151ba23a1d117b54dd2eb0c0f482da7d941a
Signed-off-by: Forenche <prahul2003@gmail.com>
techpack/display/msm/dsi/dsi_panel.c:1326:3: error: misleading indentation; sta
tement is not part of the previous 'if' [-Werror,-Wmisleading-indentation]
1326 | rc = dsi_panel_send_param_cmd(panel, param_info);
| ^
techpack/display/msm/dsi/dsi_panel.c:1323:2: note: previous statement is here
1323 | if (panel->lhbm_config.lhbm_wait_for_fps_valid && param_info->value == HBM_FOD_ON_STATE)
| ^
Broken code was added by Motorola:
d67e46e138
Change-Id: If122cbae26b5e8a23f9766cf685d3a3599adc8f5
Signed-off-by: Sevenrock <sevenrock@hotmail.de>
Fogos push for Android 14
* tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-display: (116 commits)
dsi_panel: panel_feature: corret the code mistake
dsi_panel: fix the bug of local HBM
gpu/msm: check fps value before enable lhbm
msm/display-drivers: release lhbm resource
dsi/dfps: update the dfps code to support "OLED+vid mode"
dsi/dfps: set the right fps when panel resume
Support 120Hz command sending
dts/display: [bangkok] update the dsc configure for tianma panel
display-drivers: local hbm: add suport for dc_hybird_threshold
optimze lcd log
kernel:pnangn:update 2nd panel brightness settings to 11bits
kernel/panel:power on/off reset sequence
display/backlight: support hbm dcs only with 51 cmd
display/dsi:add new lcd backlight align type for bit11_4
display: The lcd backlight shift mode update
drm_ioctl: add return value for set_param
drm/dsi_panel: resend hbm off commands
msm/drm:compatible with different hbm table in panel
drm/msm:add delay between mipi0 to reset0 when power off
drm/panel: check panel status before send custom commands
...
Conflicts:
techpack/display/msm/sde/sde_connector.c
techpack/display/msm/sde/sde_kms.c
Change-Id: I13ede04c21415717cd009ae73871894f1be74927
Fogos push for Android 14
* tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-camera: (86 commits)
fogo: fix tombstone when use secure camera
fogo: Fix secure mode switch error (2/2)
Bangkk: reset ois when read standby_flag fail
fogos: Actuator noise reduction[2/2]
fogor: Actuator noise reduction[2/2]
bangkk: Powerup and initialize sensor early [3/4]
bangkk: Fix flash request GPIO-24 failed
bangkk: support dw9784 af drift
bangkk: Open Camera preview will be black then camera error
bangkk: open Camera preview may be black sometimes
bangkk: dw9784 ois bring up
bangkk: Secondary supply flash driver ic compatible
Tundra: restore ois delete submit
Tundra: add delay at check ois data_ready
Revert "(CR): milanf: modify ois vsync irq processing flow"
penang: Adjust actuator noise reduction
penang: Adjust actuator noise reduction
penang: Actuator noise reduction
milanf: modify ois vsync irq processing flow
camera: ois: avoid ois power down twice when download firmware failed
...
Conflicts:
techpack/camera/drivers/cam_sensor_module/cam_ois/cam_ois_core.c
Change-Id: I9aa733fcd4412059a267c7cb9408b05e91eba111
Fogos push for Android 14
* tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-audio: (79 commits)
Revert "asoc: msm-compress : Fix for CTS-on-gsi with gki"
soc: swr-mstr-ctrl: allow runtime suspend first before system suspend
audio:add lock for aw dynamics set dailink
Revert "(CR):audio:add lock for aw dynamics set dailink"
dsp: q6lsm: Address use after free for mmap handle
dsp: q6lsm: Add check for payload buffer
ASoC: msm-pcm-host-voice: Check validity of session idx
audio:add lock for aw dynamics set dailink
q6fsm:add protect for fs1815 algo
fs1815:correct rotation code
aw882xxacf: add hac scene algo ctrl
audio-kernel: fix build fail caused by aw8838
techpack:add aw8838 driver
fsm:correct fsm vbat monitor logic
audio/dsp:reduce fsm vbat monitor retry times
audio/asoc:add PRI_MI2S_TX_HOSTLESS
machie_driver:add aw pri I2S dailink
audio:add fs1815 bypass algo code and logic.
Awinic: update communicate with adsp logic
codecs:add fs1815 PA driver
...
Conflicts:
techpack/audio/dsp/q6lsm.c
Change-Id: I6ec23f0d578fd2494e5e29577ce470dc2cb90f5c
Based on tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-msm
"Fogos push for Android 14"
* staging/kernel-msm/MMI-U1UGS34.23-110-23-2: (698 commits)
mmc: sdhci-msm: Move MMC_CAP2_MAX_DISCARD_SIZE to prevent merge conflict
Reapply "UPSTREAM: binder: fix the missing BR_FROZEN_REPLY in binder_return_strings"
Revert "qseecom: Suppress suspend warning if without bus scaling."
Revert "Penang: fix for device suspend tests fail. [1/2]"
Revert "Penang: resolve kasan panic"
Revert "Penang: kasan panic"
Revert "penang: device suspend tests fail"
Revert "net: qrtr: get svc_id before queueing sk_buff"
Revert "af_unix: Do not use atomic ops for unix_sk(sk)->inflight."
Revert "af_unix: Fix garbage collector racing against connect()"
Revert "BACKPORT: net: fix __dst_negative_advice() race"
Revert "ANDROID: ABI fixup for abi break in struct dst_ops"
Revert "BACKPORT:sched: Provide sched_set_fifo()"
Revert "msm: npu: Fix use after free issue"
Revert "fs:EROFS:Porting 5.10 erofs to 5.4"
Revert "BACKPORT:erofs: add per-cpu threads for decompression as an option"
Revert "UPSTREAM: erofs: fix an error code in z_erofs_init_zip_subsystem()"
msm: adsprpc: Avoid taking reference for group_info
adsprpc: Handle UAF scenario in put_args
msm: adsprpc: use-after-free (UAF) in global maps
...
Change-Id: Ia48438f247670d77560472205994632fa62062dd
This partially reverts commit 2e77a46f0d.
Reason for revert: ipa3_mdt_load_ipa_fws is not present in this kernel,
this is a bad cherrypick resolution by qcom.
Change-Id: I218978168a6c3fe9f6139a6688be1cb4c0f96b94
"LA.UM.9.14.r1-25800-LAHAINA.QSSI15.0"
* tag 'LA.UM.9.14.r1-25800-LAHAINA.QSSI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel:
asoc: codec: avoid out of bound write to map array
asoc: codec: avoid out of bound write to map array
asoc: Fixed OOB issue in qcs405
asoc: codec: wcd934x: enable auto recovery when port overflows
Change-Id: I51a30fe905251b6f66e733bae43fdcd3b0a7e787
- Proper Handling in case of invalid pinctrl index
- Removing dead code and unused variables
- Change to dereference s_ctrl only after proper
NULL Dereference Check.
CRs-Fixed: 3875406
Change-Id: I8e2c717b22efff2a7d6503d38c048e30eff230da
Signed-off-by: Swami Reddy Reddy <quic_swamired@quicinc.com>
"LA.UM.9.14.r1-25000.02-LAHAINA.QSSI14.0"
* tag 'LA.UM.9.14.r1-25000.02-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/camera-kernel:
msm: camera: sensor: handling condition for random read
msm: camera: icp: io buf config num validation
msm: camera: ope: check cpu buffer offset and cmd buf idx
Change-Id: Id26854dd09597215befc5aaff1e5f6731a0fb3e0
"LA.UM.9.14.r1-25000.02-LAHAINA.QSSI14.0"
* tag 'LA.UM.9.14.r1-25000.02-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel:
dsp: q6voice: Add buf size check for cvp cal data
asoc: msm-lsm-client: check for param size before copying
Change-Id: Ia786a33ae66c307d1af54b84796178928cf6ca01