Commit graph

973,840 commits

Author SHA1 Message Date
Michael Bestas
edd5792efd
Merge tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/dataipa into android13-5.4-lahaina
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"

* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/dataipa:
  msm: ipa3: reduce rx-wan pool and cmn page, temp pool sizes
  msm: ipa: allocate page recycling buffers only once
  msm: ipa: avoid OOM Killer for temp allocations
  msm: ipa3: Flush free page WQ only for page recyle replenish handler
  msm: ipa3: Fix to flush to workqueue during teardown pipe
  msm: ipa3: Fix to destory workqueue only if created
  msm: ipa3: Changes to enhance find free pages from list
  msm: ipa: page pool recycling enhancements
  msm: ipa: page pool recycling enhancements

Change-Id: I21c0f5974f08fc032605d2710858eb28e592d1f0
2024-03-23 17:41:41 +02:00
Michael Bestas
c609876f88
Merge tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/camera-kernel into android13-5.4-lahaina
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"

* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/camera-kernel:
  msm: camera: sensor: Proper handling of race condition in util api
  msm: camera: sensor: Proper handling of race condition in util api
  msm: camera: memmgr: Add missing calls of put buf to avoid leak

Change-Id: I0aff5a21e16f44c2e13ed99b463f326eb57b1653
2024-03-23 17:40:57 +02:00
Michael Bestas
1971b36bd2
Merge tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0 into android13-5.4-lahaina
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"

* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0:
  Release 2.0.8.34M
  qcacld-3.0: Add a sanity check to prevent integer overflow
  Release 2.0.8.34L
  qcacld-3.0: Fix possible spinlock acquire after destroy
  Release 2.0.8.34K
  qcacld-3.0: Find 6 GHz power type for connection channel
  qcacld-3.0: Find best 6 GHz power type for connection
  Release 2.0.8.34J
  qcacld-3.0: Add vendor attribute for high RSSI roam trigger threshold

Change-Id: I740cd45f715d6609b53b19a9d42b0bf9df8983bc
2024-03-23 17:40:16 +02:00
Michael Bestas
386451381a
Merge tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qca-wifi-host-cmn into android13-5.4-lahaina
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"

* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qca-wifi-host-cmn:
  qcacmn: Fix out of bound read issue in ESP ie parse
  qcacmn: Update no. of DWORDs for htt_tx_msdu_desc_ext2_t
  qcacmn: Change minimum mbssid ie length value to 1
  qcacmn: Find 6 GHz power type for connection channel
  qcacmn: Add an API to translate the 6 GHz channel enum
  qcacmn: Find best 6 GHz power type for connection
  qcacmn: Support 5 GHz high RSSI roam
  qcacmn: Define QCA vendor attribute for high RSSI roam trigger threshold

Change-Id: Ie73b137390339317e5f3f4a72577b04d34c2f0c2
2024-03-23 17:39:34 +02:00
Michael Bestas
f4b7330ae8
Merge tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/fw-api into android13-5.4-lahaina
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"

* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/fw-api:
  fw-api: CL 25995600 - update fw common interface files
  fw-api: CL 25993098 - update fw common interface files
  fw-api: CL 25976261 - update fw common interface files
  fw-api: CL 25939563 - update fw common interface files
  fw-api: CL 25939560 - update fw common interface files
  fw-api: CL 25930751 - update fw common interface files
  fw-api: CL 25920610 - update fw common interface files
  fw-api: CL 25914677 - update fw common interface files
  fw-api: CL 25907622 - update fw common interface files
  fw-api: CL 25904384 - update fw common interface files
  fw-api: CL 25886772 - update fw common interface files
  fw-api: CL 25886388 - update fw common interface files
  fw-api: CL 25873461 - update fw common interface files
  fw-api: Add hardware header files for WCN7750
  fw-api: CL 25873460 - update fw common interface files
  fw-api: CL 25869885 - update fw common interface files
  fw-api: CL 25866433 - update fw common interface files
  fw-api: CL 25840790 - update fw common interface files
  fw-api: CL 25839627 - update fw common interface files
  fw-api: Fix compilation warnings
  fw-api: peach: v2: Fix compilation errors
  fw-api: CL 25798927 - update fw common interface files
  fw-api: CL 25795907 - update fw common interface files
  fw-api: CL 25779296 - update fw common interface files
  fw-api: CL 25777035 - update fw common interface files
  fw-api: CL 25775134 - update fw common interface files
  fw-api: CL 25746138 - update fw common interface files
  fw-api: CL 25739385 - update fw common interface files
  fw-api: CL 25734378 - update fw common interface files
  fw-api: CL 25734374 - update fw common interface files
  fw-api: CL 25722609 - update fw common interface files
  fw-api: CL 25706940 - update fw common interface files
  fw-api: CL 25706687 - update fw common interface files
  fw-api: CL 25682638 - update fw common interface files
  fw-api: CL 25672910 - update fw common interface files
  fw-api: CL 25663374 - update fw common interface files
  fw-api: CL 25652231 - update fw common interface files
  fw-api: Get V2 HW header files for peach
  fw-api: CL 25639871 - update fw common interface files
  fw-api: CL 25638846 - update fw common interface files
  fw-api: CL 25637760 - update fw common interface files
  fw-api: CL 25636238 - update fw common interface files
  fw-api: CL 25618622 - update fw common interface files
  fw-api: CL 25612024 - update fw common interface files
  fw-api: CL 25601210 - update fw common interface files
  fw-api: CL 25598308 - update fw common interface files
  fw-api: CL 25585821 - update fw common interface files
  fw-api: CL 25582070 - update fw common interface files
  fw-api: CL 25582068 - update fw common interface files
  fw-api: CL 25560130 - update fw common interface files
  fw-api: CL 25538998 - update fw common interface files
  fw-api: CL 25538692 - update fw common interface files
  fw-api: CL 25526295 - update fw common interface files
  fw-api: CL 25522189 - update fw common interface files
  fw-api: CL 25493022 - update fw common interface files
  fw-api: CL 25473754 - update fw common interface files

Change-Id: I1b11683c2661051d4847480e6c2173e7c31fe5d1
2024-03-23 17:38:34 +02:00
Michael Bestas
58d91073d9
Merge tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4 into android13-5.4-lahaina
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"

* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4:
  bus: mhi: Fix potential out-of-bound access
  rpmsg: slatecom: maintain rx_size to read
  rpmsg: slatecom: out of bound read from process_cmd
  soc: qcom: add out of bound check for AON fifo
  soc: qcom: smem: Add boundary checks for partitions
  msm: kgsl: Do not release dma and anon buffers if unmap fails
  msm: kgsl: Do not release dma and anon buffers if unmap fails
  memshare: Prevent possible integer overflow
  msm: kgsl: Keep the timeline fence valid for logging
  msm: ipa: Add support for Private IP Forwarding
  msm: ipa3: add support to identify wifi attach
  soc: qcom: minidump_log: Protect md_dump_slabinfo under SLUB_DEBUG
  mm: slub: Declare slab_owner_ops only when SLUB DEBUG is enabled
  soc: qcom: Add BLAIR-LITE SoC information to socinfo
  soc: qcom: socinfo: Add soc information for BLAIR LTE
  msm_serial_hs: Fix race between mod_timer and del_timer calls

Change-Id: I5ab9a7732af0be4754b506f2c815ab29b236fb91
2024-03-23 17:36:59 +02:00
Bruno Martins
f32a592779 Merge tag 'ASB-2024-03-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2024-03-01

* tag 'ASB-2024-03-05_11-5.4' of https://android.googlesource.com/kernel/common:
  ANDROID: GKI: Update symbol list for Zebra
  UPSTREAM: usb: raw-gadget: properly handle interrupted requests
  UPSTREAM: net: prevent skb corruption on frag list segmentation
  UPSTREAM: netfilter: nft_set_rbtree: skip end interval element from gc
  UPSTREAM: net: tls, update curr on splice as well

Change-Id: I7a6117e861e8c35bb66bcc3a9a21cc6db49946b2
2024-03-12 10:53:13 +00:00
Linux Build Service Account
0cb96a3ce3 Merge "bus: mhi: Fix potential out-of-bound access" into kernel.lnx.5.4.r1-rel 2024-03-11 03:51:17 -07:00
Linux Build Service Account
1130afed29 Merge "rpmsg: slatecom: out of bound read from process_cmd" into kernel.lnx.5.4.r1-rel 2024-03-11 03:51:15 -07:00
Linux Build Service Account
95730a4611 Merge "soc: qcom: add out of bound check for AON fifo" into kernel.lnx.5.4.r1-rel 2024-03-11 03:51:13 -07:00
Krishna chaitanya chundru
6df00291cb bus: mhi: Fix potential out-of-bound access
In mhi_sat_isvalid_header function if the length is less than
the size of header then there can be out-of-bound access.

So fix the len check in the function.

Change-Id: I80f1556557b1bf2f30c07f6377bd6e3db48712b3
Signed-off-by: Krishna chaitanya chundru <quic_krichai@quicinc.com>
(cherry picked from commit d7601393dc)
2024-03-11 03:17:56 -07:00
Kaushal Hooda
bff9163e23 rpmsg: slatecom: maintain rx_size to read
For cmd close_ack or open request where rx_size is being
incrementing with respect to offset might lead to out of
bound read from rx_data.

Decrease rx_size as we process commands.

Change-Id: I492eadcbebb78386fc20f744eb9ad8db4a2914fc
Signed-off-by: Kaushal Hooda <quic_khooda@quicinc.com>
(cherry picked from commit ab0f86134f)
2024-03-11 03:15:25 -07:00
Kaushal Hooda
0106549bb9 rpmsg: slatecom: out of bound read from process_cmd
When dereferencing "rx_data" as type "glink_slatecom_msg" ,
we didn't check if "rx_data" has enough room to hold that type.
The "rx_size" is read from slate to master fifo and if received
rx_size is less then "glink_slatecom_msg" then it could lead to
heap out of bounds read.

If received rx_size is less then the expected glink_slatecom_msg
then return back as a bad message.

Change-Id: Idde757ee70c7c88c22e4f036e6da0280e3b385d0
Signed-off-by: Kaushal Hooda <quic_khooda@quicinc.com>
(cherry picked from commit 7ddb61a6ac)
2024-03-11 03:13:41 -07:00
Ajit Kumar
d830cc50b9 soc: qcom: add out of bound check for AON fifo
Add out of bound check while parsing the SPI
slave-to-master fifo.

Change-Id: I14f707307fa277b2f8a7b543d3cc5e9ebac885db
Signed-off-by: Ajit Kumar <quic_kajit@quicinc.com>
(cherry picked from commit 0950011ce6)
2024-03-11 03:12:06 -07:00
Krupali Dhanvijay
b36b22d2c7 qcacmn: Fix out of bound read issue in ESP ie parse
While parsing ESP IE from beacon/probe response frame,
the condition in loop to copy ESP_INFO from the ESP IE is
incorrect which will iterate for 5 times rather than 4 times,
this may cause OOB access.

data < ((uint8_t *)esp_ie + esp_ie->esp_len + 3)
Here adding 3 for esp_ie->esp_len, actually esp_len itself is
1 byte extra (esp_ len = ESP_ID_EXTN + ESP_INFO * 4),
but by adding 3 again will loop for one more iteration
this will cause OOB access.

Remove 3 in loop condition to avoid one more extra iteration
and ignore ESP_ID_EXTN element for total elements, in function
util_scan_update_esp_data.

Change-Id: Ia9226e483672369af36c6914e3ac914fe9de45e5
CRs-Fixed: 3710081
(cherry picked from commit 799a747940)
2024-03-11 03:01:42 -07:00
Linux Build Service Account
fad511703f Merge 58e401790a on remote branch
Change-Id: I9790077c57d1e497dcf92c7224360105baf23e30
2024-03-07 11:38:47 -08:00
Linux Build Service Account
02b5fbf230 Merge 06f5366d58 on remote branch
Change-Id: I26cafc24b3e17bb30da3d6df2b693ab4b75fe4ff
2024-03-07 11:35:26 -08:00
Linux Build Service Account
b3c6b2d02d Merge 1f86f4ddfa on remote branch
Change-Id: Ib6ffa685310baf7d0e9f29a9fa0d3a8a9bb2d8de
2024-03-07 11:34:37 -08:00
Linux Build Service Account
5b72541f69 Merge d32175f446 on remote branch
Change-Id: I83d4bb2919ffa864eea600b4df277012c93735ff
2024-03-07 11:29:07 -08:00
Linux Build Service Account
b8c81a5b03 Merge 9f87938ec2 on remote branch
Change-Id: I98ae892a48a07039048b15bc7684b970e68c2aab
2024-03-07 11:28:30 -08:00
xuguangyang
d24801ee88 ANDROID: GKI: Update symbol list for Zebra
Update the android/abi_gki_aarch64_zebra

Leaf changes summary: 2 artifacts changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 2 Added functions
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

2 Added functions:

  [A] 'function int dev_change_flags(net_device*, unsigned int, netlink_ext_ack*)'
  [A] 'function net_device* netdev_master_upper_dev_get(net_device*)'

Bug: 328360926

Change-Id: Ica1469e5793dc5fb2627aa20b431e42d590eea37
Signed-off-by: xuguangyang <xuguangyang91@gmail.com>
2024-03-06 10:55:54 +00:00
Andrey Konovalov
26423f6f2f UPSTREAM: usb: raw-gadget: properly handle interrupted requests
Currently, if a USB request that was queued by Raw Gadget is interrupted
(via a signal), wait_for_completion_interruptible returns -ERESTARTSYS.
Raw Gadget then attempts to propagate this value to userspace as a return
value from its ioctls. However, when -ERESTARTSYS is returned by a syscall
handler, the kernel internally restarts the syscall.

This doesn't allow userspace applications to interrupt requests queued by
Raw Gadget (which is required when the emulated device is asked to switch
altsettings). It also violates the implied interface of Raw Gadget that a
single ioctl must only queue a single USB request.

Instead, make Raw Gadget do what GadgetFS does: check whether the request
was interrupted (dequeued with status == -ECONNRESET) and report -EINTR to
userspace.

Bug: 254441685
Fixes: f2c2e717642c ("usb: gadget: add raw-gadget interface")
Cc: stable <stable@kernel.org>
Signed-off-by: Andrey Konovalov <andreyknvl@gmail.com>
Link: https://lore.kernel.org/r/0db45b1d7cc466e3d4d1ab353f61d63c977fbbc5.1698350424.git.andreyknvl@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit e8033bde451eddfb9b1bbd6e2d848c1b5c277222)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I1509b30c9962d6e695b268c183e41bdd551f1780
2024-02-28 12:51:50 +00:00
Paolo Abeni
1306a39bd6 UPSTREAM: net: prevent skb corruption on frag list segmentation
Ian reported several skb corruptions triggered by rx-gro-list,
collecting different oops alike:

[   62.624003] BUG: kernel NULL pointer dereference, address: 00000000000000c0
[   62.631083] #PF: supervisor read access in kernel mode
[   62.636312] #PF: error_code(0x0000) - not-present page
[   62.641541] PGD 0 P4D 0
[   62.644174] Oops: 0000 [#1] PREEMPT SMP NOPTI
[   62.648629] CPU: 1 PID: 913 Comm: napi/eno2-79 Not tainted 6.4.0 #364
[   62.655162] Hardware name: Supermicro Super Server/A2SDi-12C-HLN4F, BIOS 1.7a 10/13/2022
[   62.663344] RIP: 0010:__udp_gso_segment (./include/linux/skbuff.h:2858
./include/linux/udp.h:23 net/ipv4/udp_offload.c:228 net/ipv4/udp_offload.c:261
net/ipv4/udp_offload.c:277)
[   62.687193] RSP: 0018:ffffbd3a83b4f868 EFLAGS: 00010246
[   62.692515] RAX: 00000000000000ce RBX: 0000000000000000 RCX: 0000000000000000
[   62.699743] RDX: ffffa124def8a000 RSI: 0000000000000079 RDI: ffffa125952a14d4
[   62.706970] RBP: ffffa124def8a000 R08: 0000000000000022 R09: 00002000001558c9
[   62.714199] R10: 0000000000000000 R11: 00000000be554639 R12: 00000000000000e2
[   62.721426] R13: ffffa125952a1400 R14: ffffa125952a1400 R15: 00002000001558c9
[   62.728654] FS:  0000000000000000(0000) GS:ffffa127efa40000(0000)
knlGS:0000000000000000
[   62.736852] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   62.742702] CR2: 00000000000000c0 CR3: 00000001034b0000 CR4: 00000000003526e0
[   62.749948] Call Trace:
[   62.752498]  <TASK>
[   62.779267] inet_gso_segment (net/ipv4/af_inet.c:1398)
[   62.787605] skb_mac_gso_segment (net/core/gro.c:141)
[   62.791906] __skb_gso_segment (net/core/dev.c:3403 (discriminator 2))
[   62.800492] validate_xmit_skb (./include/linux/netdevice.h:4862
net/core/dev.c:3659)
[   62.804695] validate_xmit_skb_list (net/core/dev.c:3710)
[   62.809158] sch_direct_xmit (net/sched/sch_generic.c:330)
[   62.813198] __dev_queue_xmit (net/core/dev.c:3805 net/core/dev.c:4210)
net/netfilter/core.c:626)
[   62.821093] br_dev_queue_push_xmit (net/bridge/br_forward.c:55)
[   62.825652] maybe_deliver (net/bridge/br_forward.c:193)
[   62.829420] br_flood (net/bridge/br_forward.c:233)
[   62.832758] br_handle_frame_finish (net/bridge/br_input.c:215)
[   62.837403] br_handle_frame (net/bridge/br_input.c:298
net/bridge/br_input.c:416)
[   62.851417] __netif_receive_skb_core.constprop.0 (net/core/dev.c:5387)
[   62.866114] __netif_receive_skb_list_core (net/core/dev.c:5570)
[   62.871367] netif_receive_skb_list_internal (net/core/dev.c:5638
net/core/dev.c:5727)
[   62.876795] napi_complete_done (./include/linux/list.h:37
./include/net/gro.h:434 ./include/net/gro.h:429 net/core/dev.c:6067)
[   62.881004] ixgbe_poll (drivers/net/ethernet/intel/ixgbe/ixgbe_main.c:3191)
[   62.893534] __napi_poll (net/core/dev.c:6498)
[   62.897133] napi_threaded_poll (./include/linux/netpoll.h:89
net/core/dev.c:6640)
[   62.905276] kthread (kernel/kthread.c:379)
[   62.913435] ret_from_fork (arch/x86/entry/entry_64.S:314)
[   62.917119]  </TASK>

In the critical scenario, rx-gro-list GRO-ed packets are fed, via a
bridge, both to the local input path and to an egress device (tun).

The segmentation of such packets unsafely writes to the cloned skbs
with shared heads.

This change addresses the issue by uncloning as needed the
to-be-segmented skbs.

Bug: 254441685
Reported-by: Ian Kumlien <ian.kumlien@gmail.com>
Tested-by: Ian Kumlien <ian.kumlien@gmail.com>
Fixes: 3a1296a38d0c ("net: Support GRO/GSO fraglist chaining.")
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit c329b261afe71197d9da83c1f18eb45a7e97e089)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I781f218d67b94d0cc43166b0ed5cc5240b7a2b20
2024-02-28 12:47:09 +00:00
Pablo Neira Ayuso
502693befb UPSTREAM: netfilter: nft_set_rbtree: skip end interval element from gc
commit 60c0c230c6f046da536d3df8b39a20b9a9fd6af0 upstream.

rbtree lazy gc on insert might collect an end interval element that has
been just added in this transactions, skip end interval elements that
are not yet active.

Bug: 325477234
Fixes: f718863aca46 ("netfilter: nft_set_rbtree: fix overlap expiration walk")
Cc: stable@vger.kernel.org
Reported-by: lonial con <kongln9170@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 10e9cb3931)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I42f7bca418d47948292b15ace9f371b81ccd7fe8
2024-02-27 16:38:00 +00:00
Camera Software Integration
06f5366d58 Merge "msm: camera: memmgr: Add missing calls of put buf to avoid leak" into camera-kernel.lnx.4.0 2024-02-23 22:37:34 -08:00
Sarannya S
58e401790a soc: qcom: smem: Add boundary checks for partitions
Add condition check to make sure that the end address
of private entry does not go out of partition.

Change-Id: I88b3c69d86d90905b214c13a8c632b134b487a49
Signed-off-by: Sarannya S <quic_sarannya@quicinc.com>
Signed-off-by: Pranav Mahesh Phansalkar <quic_pphansal@quicinc.com>
2024-02-20 14:31:26 +05:30
Shivi Mangal
7440c110a4 msm: camera: sensor: Proper handling of race condition in util api
Power count is coming from user space which can be modified due to
access to shared memory. This change scopes the data locally so
as to avoid vulnerability of count being modified by external
means while executing due to being in shared memory.

CRs-Fixed: 3691744.

Change-Id: I57d13435453195f8aab0c9aad4414d290274ff81
Signed-off-by: Shivi Mangal <quic_smangal@quicinc.com>
(cherry picked from commit c9cd58783e)
2024-02-15 19:16:01 -08:00
Linux Build Service Account
d4eac70ee3 Merge "Merge 301c6b0cba on remote branch" into kernel.lnx.5.4.r1-rel 2024-02-14 02:19:13 -08:00
Lynus Vaz
26a82ee466 msm: kgsl: Do not release dma and anon buffers if unmap fails
If iommu unmap fails and leaves dma or anon buffers still mapped in the
iommu, do not free them.

Change-Id: Ice0e1a59c1ac0ee7a9d62d8899966b84fa63d5ca
Signed-off-by: Lynus Vaz <quic_lvaz@quicinc.com>
Signed-off-by: Deepak Kumar <quic_dkumar@quicinc.com>
(cherry picked from commit e7c4bb239b)
2024-02-13 22:16:47 -08:00
qctecmdr
2cf7f335fc Merge "msm: kgsl: Do not release dma and anon buffers if unmap fails" 2024-02-13 10:14:25 -08:00
Linux Build Service Account
6283378ce9 Merge 4579b40320 on remote branch
Change-Id: Icd836fabce6535be8b0e6e8c3e6a7b2c67ab1fe8
2024-02-13 02:27:19 -08:00
Linux Build Service Account
83707ca098 Merge 301c6b0cba on remote branch
Change-Id: Id51ccd051d71d65e65f22f9b46cccd848e4d5266
2024-02-13 02:27:10 -08:00
Linux Build Service Account
e19fbb22e4 Merge dc1e1b33ec on remote branch
Change-Id: I5661315f1fd2de4645e938f4211106c5e98eeaa3
2024-02-13 02:24:00 -08:00
Linux Build Service Account
12b4378369 Merge dc2a8a0860 on remote branch
Change-Id: Ie79fe99edeb380604cb069af377ef8212cc4ca99
2024-02-13 02:20:24 -08:00
Lynus Vaz
e7c4bb239b msm: kgsl: Do not release dma and anon buffers if unmap fails
If iommu unmap fails and leaves dma or anon buffers still mapped in the
iommu, do not free them.

Change-Id: Ice0e1a59c1ac0ee7a9d62d8899966b84fa63d5ca
Signed-off-by: Lynus Vaz <quic_lvaz@quicinc.com>
Signed-off-by: Deepak Kumar <quic_dkumar@quicinc.com>
2024-02-13 15:05:15 +05:30
spuligil
9f87938ec2 fw-api: CL 25995600 - update fw common interface files
Change-Id: I7cc1fda861a84c1f42c44b6f7f3f8bb7dce741fb
CRs-Fixed: 2262693
2024-02-12 07:28:40 -08:00
spuligil
29ebb1e83c fw-api: CL 25993098 - update fw common interface files
Change-Id: I71389caec8dba8bb2f35aa518b165a9e5f5460cc
CRs-Fixed: 2262693
2024-02-12 07:28:38 -08:00
spuligil
f1f142ff47 fw-api: CL 25976261 - update fw common interface files
Change-Id: Idd176144330b387bbc4dc46ed0d45132d1d13167
CRs-Fixed: 2262693
2024-02-12 07:28:36 -08:00
spuligil
d10f89582b fw-api: CL 25939563 - update fw common interface files
Change-Id: I7b6d9c36043a7f090dad6821fe7341103762f142
CRs-Fixed: 2262693
2024-02-12 07:28:34 -08:00
spuligil
a07d3dfc56 fw-api: CL 25939560 - update fw common interface files
Change-Id: I131b97ecc1c6c5431d4b98ebd85ee9d55a03a32d
CRs-Fixed: 2262693
2024-02-12 07:28:32 -08:00
spuligil
873ca3466e fw-api: CL 25930751 - update fw common interface files
WMI: add ML_MONITOR_MODE target cap + ML_FULL_MONITOR_MODE rsrc cfg flags
Change-Id: Ibfedd4af0e63ac0d6247b315244d7c431de3baba
CRs-Fixed: 2262693
2024-02-12 07:28:30 -08:00
spuligil
cc4247b9a9 fw-api: CL 25920610 - update fw common interface files
HTT: add H2T TX_SUPER_RULE_SETUP msg def
Change-Id: If338c1a95723cce04d9607918c0162cdc261e7f5
CRs-Fixed: 2262693
2024-02-12 07:28:28 -08:00
spuligil
0bb05e0306 fw-api: CL 25914677 - update fw common interface files
WMI: change QMS_DLKM to SMEM_MAILBOX
Change-Id: Ia377773337031334e3b678db28b148b291246f69
CRs-Fixed: 2262693
2024-02-12 07:28:26 -08:00
spuligil
b09d9c5097 fw-api: CL 25907622 - update fw common interface files
WMI: add PDEV_SET_CUSTOM_TX_POWER_PER_MCS cmd msg def
Change-Id: I5c6d418cd4a3675d7a42a72bc6b228b32828d0b0
CRs-Fixed: 2262693
2024-02-12 07:28:24 -08:00
spuligil
1bff3b1aa0 fw-api: CL 25904384 - update fw common interface files
WMI: add assoc_flags field in peer_assoc_complete cmd msg
Change-Id: I502028a498ab2cd97931adaed95061995235338d
CRs-Fixed: 2262693
2024-02-12 07:28:22 -08:00
spuligil
d6db73dabd fw-api: CL 25886772 - update fw common interface files
WMI: add WMI_REG_CHAN_LIST_CC_EXT2_EVENTID msg def
Change-Id: I5e7c452d699a46b243238c5cb182ea3c7e215ff9
CRs-Fixed: 2262693
2024-02-12 07:28:20 -08:00
spuligil
d3e1c40ec1 fw-api: CL 25886388 - update fw common interface files
HTT stats: add max_reg_only_allowed_power[] field in phy_tpc_stats TLV
Change-Id: Ie3ef2d8f215eb4b778d54016b3c4c562e4a036e4
CRs-Fixed: 2262693
2024-02-12 07:28:18 -08:00
spuligil
b619c235aa fw-api: CL 25873461 - update fw common interface files
WMI: add PDEV_ENABLE_XLNA_[CMD,EVENT] msg defs
Change-Id: Iafb97078155a89efeb40b5f258e4f7e14c4c36cf
CRs-Fixed: 2262693
2024-02-12 07:28:17 -08:00
Manikanta Pubbisetty
6e7d08d9ee fw-api: Add hardware header files for WCN7750
Add E1.0 E1R24 hardware header files to bring-in support for
WCN7750 WiFi.

Change-Id: I1bf2283711cd32390e4e3478d07f7e1efb9d12ea
CRs-Fixed: 3713582
2024-02-12 07:28:15 -08:00
Shivi Mangal
c9cd58783e msm: camera: sensor: Proper handling of race condition in util api
Power count is coming from user space which can be modified due to
access to shared memory. This change scopes the data locally so
as to avoid vulnerability of count being modified by external
means while executing due to being in shared memory.

CRs-Fixed: 3691744.

Change-Id: I57d13435453195f8aab0c9aad4414d290274ff81
Signed-off-by: Shivi Mangal <quic_smangal@quicinc.com>
2024-02-11 09:09:40 -08:00