Commit graph

916,577 commits

Author SHA1 Message Date
qctecmdr
edf462cdf1 Merge "msm: ipa3: change variable name for indication of rx tlv format" 2024-03-14 04:21:18 -07:00
qctecmdr
c5745130f9 Merge "soc: qcom: llcc: Handle a second device without data corruption" 2024-03-13 22:19:26 -07:00
Fakruddin Vohra
8c44843e9f msm: ipa3: change variable name for indication of
rx tlv format

wlan cannot have hsp in there traces so need to
change variable name.

Change-Id: I49ff72b3e446600b42064b02d33b409f55e327d0
Signed-off-by: Fakruddin Vohra <quic_fakruddi@quicinc.com>
2024-03-13 08:33:14 -07:00
qctecmdr
edd54a3236 Merge "msm: eva: User after free fix in msm_cvp_mark_user_persist" 2024-03-12 04:26:12 -07:00
Uwe Kleine-König
7ba19e773b soc: qcom: llcc: Handle a second device without data corruption
[ Upstream commit f1a1bc8775b26345aba2be278118999e7f661d3d ]

Usually there is only one llcc device. But if there were a second, even
a failed probe call would modify the global drv_data pointer. So check
if drv_data is valid before overwriting it.

Change-Id: Ie9bcc0686959b0c3bfb740963eed3ba399ed735e
Signed-off-by: Uwe Kleine-König <u.kleine-koenig@pengutronix.de>
Fixes: a3134fb09e ("drivers: soc: Add LLCC driver")
Git-commit: cc1a1dcb41
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
Link: https://lore.kernel.org/r/20230926083229.2073890-1-u.kleine-koenig@pengutronix.de
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: kamasali Satyanarayan <quic_kamasali@quicinc.com>
2024-03-12 16:40:17 +05:30
Gopireddy Arunteja Reddy
1babb91a34 msm: eva: User after free fix in msm_cvp_mark_user_persist
Update buffer ktid inside mutex protetion.

Change-Id: I86767eb60e1f78e373233c0f64c3b5a2249cba0e
Signed-off-by: Gopireddy Arunteja Reddy <quic_garuntej@quicinc.com>
2024-03-11 07:39:10 -07:00
qctecmdr
9c9c087a1b Merge "Merge android11-5.4.265+ (a34cc1d) into msm-5.4" 2024-03-07 22:36:58 -08:00
qctecmdr
ef7ec434b5 Merge "rpmsg: slatecom: out of bound read from process_cmd" 2024-03-07 03:35:40 -08:00
Kaushal Hooda
7ddb61a6ac rpmsg: slatecom: out of bound read from process_cmd
When dereferencing "rx_data" as type "glink_slatecom_msg" ,
we didn't check if "rx_data" has enough room to hold that type.
The "rx_size" is read from slate to master fifo and if received
rx_size is less then "glink_slatecom_msg" then it could lead to
heap out of bounds read.

If received rx_size is less then the expected glink_slatecom_msg
then return back as a bad message.

Change-Id: Idde757ee70c7c88c22e4f036e6da0280e3b385d0
Signed-off-by: Kaushal Hooda <quic_khooda@quicinc.com>
2024-03-06 22:27:00 -08:00
Vivek Kumar
920dbdcff7 defconfig: arm64: Disable trimming non-whitelisted symbols
Disable trimming of non-whitelisted symbols for all defconfigs.

Change-Id: I11f8c5a2835b79cad31ff36e04f618f22c22e84b
Signed-off-by: Vivek Kumar <quic_vivekuma@quicinc.com>
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2024-03-05 13:38:03 +05:30
qctecmdr
89f4076c51 Merge "soc: qcom: add out of bound check for AON fifo" 2024-03-04 12:13:25 -08:00
qctecmdr
5028cb01e9 Merge "rpmsg: slatecom: maintain rx_size to read" 2024-03-04 09:00:19 -08:00
qctecmdr
89ebcc83ba Merge "bus: mhi: Fix potential out-of-bound access" 2024-03-04 02:03:00 -08:00
Ajit Kumar
0950011ce6 soc: qcom: add out of bound check for AON fifo
Add out of bound check while parsing the SPI
slave-to-master fifo.

Change-Id: I14f707307fa277b2f8a7b543d3cc5e9ebac885db
Signed-off-by: Ajit Kumar <quic_kajit@quicinc.com>
2024-03-04 01:58:55 -08:00
Kaushal Hooda
ab0f86134f rpmsg: slatecom: maintain rx_size to read
For cmd close_ack or open request where rx_size is being
incrementing with respect to offset might lead to out of
bound read from rx_data.

Decrease rx_size as we process commands.

Change-Id: I492eadcbebb78386fc20f744eb9ad8db4a2914fc
Signed-off-by: Kaushal Hooda <quic_khooda@quicinc.com>
2024-03-04 01:13:25 -08:00
kamasali Satyanarayan
478988c2b4 Merge android11-5.4.265+ (a34cc1d) into msm-5.4
* remotes/origin/tmp-a34cc1d:
  Revert LLCC changes
  Reapply "perf: Disallow mis-matched inherited group reads"
  UPSTREAM: ath10k: Get rid of "per_ce_irq" hw param
  UPSTREAM: ath10k: Keep track of which interrupts fired, don't poll them
  UPSTREAM: ath10k: Add interrupt summary based CE processing
  UPSTREAM: ath10k: Wait until copy complete is actually done before completing
  FROMGIT: clk: qcom: gcc-sdm845: Add soft dependency on rpmhpd
  ANDROID: GKI: fix crc issue in include/net/addrconf.h
  Revert "cred: switch to using atomic_long_t"
  Linux 5.4.265
  powerpc/ftrace: Fix stack teardown in ftrace_no_trace
  powerpc/ftrace: Create a dummy stackframe to fix stack unwind
  mmc: block: Be sure to wait while busy in CQE error recovery
  ring-buffer: Fix memory leak of free page
  team: Fix use-after-free when an option instance allocation fails
  arm64: mm: Always make sw-dirty PTEs hw-dirty in pte_modify
  ext4: prevent the normalized size from exceeding EXT_MAX_BLOCKS
  soundwire: stream: fix NULL pointer dereference for multi_link
  perf: Fix perf_event_validate_size() lockdep splat
  HID: hid-asus: add const to read-only outgoing usb buffer
  net: usb: qmi_wwan: claim interface 4 for ZTE MF290
  asm-generic: qspinlock: fix queued_spin_value_unlocked() implementation
  HID: multitouch: Add quirk for HONOR GLO-GXXX touchpad
  HID: hid-asus: reset the backlight brightness level on resume
  HID: add ALWAYS_POLL quirk for Apple kb
  platform/x86: intel_telemetry: Fix kernel doc descriptions
  bcache: avoid NULL checking to c->root in run_cache_set()
  bcache: add code comments for bch_btree_node_get() and __bch_btree_node_alloc()
  bcache: avoid oversize memory allocation by small stripe_size
  blk-throttle: fix lockdep warning of "cgroup_mutex or RCU read lock required!"
  usb: aqc111: check packet for fixup for true limit
  Revert "PCI: acpiphp: Reassign resources on bridge if necessary"
  ALSA: hda/hdmi: add force-connect quirks for ASUSTeK Z170 variants
  cred: switch to using atomic_long_t
  appletalk: Fix Use-After-Free in atalk_ioctl
  net: stmmac: Handle disabled MDIO busses from devicetree
  net: stmmac: use dev_err_probe() for reporting mdio bus registration failure
  vsock/virtio: Fix unsigned integer wrap around in virtio_transport_has_space()
  sign-file: Fix incorrect return values check
  net: Remove acked SYN flag from packet in the transmit queue correctly
  qed: Fix a potential use-after-free in qed_cxt_tables_alloc
  net/rose: Fix Use-After-Free in rose_ioctl
  atm: Fix Use-After-Free in do_vcc_ioctl
  atm: solos-pci: Fix potential deadlock on &tx_queue_lock
  atm: solos-pci: Fix potential deadlock on &cli_queue_lock
  qca_spi: Fix reset behavior
  qca_debug: Fix ethtool -G iface tx behavior
  qca_debug: Prevent crash on TX ring changes
  net: ipv6: support reporting otherwise unknown prefix flags in RTM_NEWPREFIX
  afs: Fix refcount underflow from error handling race
  Revert "psample: Require 'CAP_NET_ADMIN' when joining "packets" group"
  Revert "mmc: core: add helpers mmc_regulator_enable/disable_vqmmc"
  Revert "mmc: sdhci-sprd: Fix vqmmc not shutting down after the card was pulled"
  Revert "genetlink: add CAP_NET_ADMIN test for multicast bind"
  Revert "drop_monitor: Require 'CAP_SYS_ADMIN' when joining "events" group"
  Revert "perf/core: Add a new read format to get a number of lost samples"
  Revert "perf: Fix perf_event_validate_size()"
  Revert "hrtimers: Push pending hrtimers away from outgoing CPU earlier"
  Linux 5.4.264
  devcoredump: Send uevent once devcd is ready
  devcoredump : Serialize devcd_del work
  smb: client: fix potential NULL deref in parse_dfs_referrals()
  cifs: Fix non-availability of dedup breaking generic/304
  Revert "btrfs: add dmesg output for first mount and last unmount of a filesystem"
  tools headers UAPI: Sync linux/perf_event.h with the kernel sources
  drop_monitor: Require 'CAP_SYS_ADMIN' when joining "events" group
  psample: Require 'CAP_NET_ADMIN' when joining "packets" group
  genetlink: add CAP_NET_ADMIN test for multicast bind
  netlink: don't call ->netlink_bind with table lock held
  io_uring/af_unix: disable sending io_uring over sockets
  nilfs2: fix missing error check for sb_set_blocksize call
  KVM: s390/mm: Properly reset no-dat
  x86/CPU/AMD: Check vendor in the AMD microcode callback
  serial: 8250_omap: Add earlycon support for the AM654 UART controller
  serial: sc16is7xx: address RX timeout interrupt errata
  ARM: PL011: Fix DMA support
  usb: typec: class: fix typec_altmode_put_partner to put plugs
  parport: Add support for Brainboxes IX/UC/PX parallel cards
  usb: gadget: f_hid: fix report descriptor allocation
  mmc: sdhci-sprd: Fix vqmmc not shutting down after the card was pulled
  mmc: core: add helpers mmc_regulator_enable/disable_vqmmc
  gpiolib: sysfs: Fix error handling on failed export
  perf: Fix perf_event_validate_size()
  perf/core: Add a new read format to get a number of lost samples
  arm64: dts: mediatek: mt8173-evb: Fix regulator-fixed node names
  arm64: dts: mediatek: mt7622: fix memory node warning check
  packet: Move reference count in packet_sock to atomic_long_t
  tracing: Fix a possible race when disabling buffered events
  tracing: Fix incomplete locking when disabling buffered events
  tracing: Always update snapshot buffer size
  nilfs2: prevent WARNING in nilfs_sufile_set_segment_usage()
  ALSA: pcm: fix out-of-bounds in snd_pcm_state_names
  ARM: dts: imx7: Declare timers compatible with fsl,imx6dl-gpt
  ARM: dts: imx: make gpt node name generic
  ARM: imx: Check return value of devm_kasprintf in imx_mmdc_perf_init
  scsi: be2iscsi: Fix a memleak in beiscsi_init_wrb_handle()
  tracing: Fix a warning when allocating buffered events fails
  ASoC: wm_adsp: fix memleak in wm_adsp_buffer_populate
  hwmon: (acpi_power_meter) Fix 4.29 MW bug
  RDMA/bnxt_re: Correct module description string
  bpf: sockmap, updating the sg structure should also update curr
  tcp: do not accept ACK of bytes we never sent
  netfilter: xt_owner: Fix for unsafe access of sk->sk_socket
  net: hns: fix fake link up on xge port
  ipv4: ip_gre: Avoid skb_pull() failure in ipgre_xmit()
  arcnet: restoring support for multiple Sohard Arcnet cards
  net: arcnet: com20020 fix error handling
  net: arcnet: Fix RESET flag handling
  hv_netvsc: rndis_filter needs to select NLS
  ipv6: fix potential NULL deref in fib6_add()
  of: dynamic: Fix of_reconfig_get_state_change() return value documentation
  of: Add missing 'Return' section in kerneldoc comments
  of: Fix kerneldoc output formatting
  of: base: Fix some formatting issues and provide missing descriptions
  of/irq: Make of_msi_map_rid() PCI bus agnostic
  of/irq: make of_msi_map_get_device_domain() bus agnostic
  of/iommu: Make of_map_rid() PCI agnostic
  ACPI/IORT: Make iort_msi_map_rid() PCI agnostic
  ACPI/IORT: Make iort_get_device_domain IRQ domain agnostic
  of: base: Add of_get_cpu_state_node() to get idle states for a CPU node
  drm/amdgpu: correct chunk_ptr to a pointer to chunk.
  kconfig: fix memory leak from range properties
  tg3: Increment tx_dropped in tg3_tso_bug()
  tg3: Move the [rt]x_dropped counters to tg3_napi
  netfilter: ipset: fix race condition between swap/destroy and kernel side add/del/test
  hrtimers: Push pending hrtimers away from outgoing CPU earlier
  Revert "HID: core: store the unique system identifier in hid_device"
  Revert "HID: fix HID device resource race between HID core and debugging support"
  Linux 5.4.263
  mmc: block: Retry commands in CQE error recovery
  mmc: core: convert comma to semicolon
  mmc: cqhci: Fix task clearing in CQE error recovery
  mmc: cqhci: Warn of halt or task clear failure
  mmc: cqhci: Increase recovery halt timeout
  cpufreq: imx6q: Don't disable 792 Mhz OPP unnecessarily
  cpufreq: imx6q: don't warn for disabling a non-existing frequency
  scsi: qla2xxx: Fix system crash due to bad pointer access
  scsi: qla2xxx: Use scsi_cmd_to_rq() instead of scsi_cmnd.request
  scsi: core: Introduce the scsi_cmd_to_rq() function
  scsi: qla2xxx: Simplify the code for aborting SCSI commands
  ima: detect changes to the backing overlay file
  ovl: skip overlayfs superblocks at global sync
  ima: annotate iint mutex to avoid lockdep false positive warnings
  fbdev: stifb: Make the STI next font pointer a 32-bit signed offset
  mtd: cfi_cmdset_0001: Byte swap OTP info
  mtd: cfi_cmdset_0001: Support the absence of protection registers
  s390/cmma: fix detection of DAT pages
  s390/mm: fix phys vs virt confusion in mark_kernel_pXd() functions family
  smb3: fix touch -h of symlink
  net: ravb: Start TX queues after HW initialization succeeded
  net: ravb: Use pm_runtime_resume_and_get()
  ravb: Fix races between ravb_tx_timeout_work() and net related ops
  net: stmmac: xgmac: Disable FPE MMC interrupts
  ipv4: igmp: fix refcnt uaf issue when receiving igmp query packet
  Input: xpad - add HyperX Clutch Gladiate Support
  btrfs: make error messages more clear when getting a chunk map
  btrfs: send: ensure send_fd is writable
  btrfs: fix off-by-one when checking chunk map includes logical address
  btrfs: add dmesg output for first mount and last unmount of a filesystem
  powerpc: Don't clobber f0/vs0 during fp|altivec register save
  bcache: revert replacing IS_ERR_OR_NULL with IS_ERR
  dm verity: don't perform FEC for failed readahead IO
  dm-verity: align struct dm_verity_fec_io properly
  ALSA: hda/realtek: Add supported ALC257 for ChromeOS
  ALSA: hda/realtek: Headset Mic VREF to 100%
  ALSA: hda: Disable power-save on KONTRON SinglePC
  mmc: block: Do not lose cache flush during CQE error recovery
  firewire: core: fix possible memory leak in create_units()
  pinctrl: avoid reload of p state in list iteration
  io_uring: fix off-by one bvec index
  USB: dwc3: qcom: fix wakeup after probe deferral
  USB: dwc3: qcom: fix resource leaks on probe deferral
  usb: dwc3: set the dma max_seg_size
  USB: dwc2: write HCINT with INTMASK applied
  USB: serial: option: don't claim interface 4 for ZTE MF290
  USB: serial: option: fix FM101R-GL defines
  USB: serial: option: add Fibocom L7xx modules
  bcache: prevent potential division by zero error
  bcache: check return value from btree_node_alloc_replacement()
  dm-delay: fix a race between delay_presuspend and delay_bio
  hv_netvsc: Mark VF as slave before exposing it to user-mode
  hv_netvsc: Fix race of register_netdevice_notifier and VF register
  USB: serial: option: add Luat Air72*U series products
  s390/dasd: protect device queue against concurrent access
  bcache: replace a mistaken IS_ERR() by IS_ERR_OR_NULL() in btree_gc_coalesce()
  ACPI: resource: Skip IRQ override on ASUS ExpertBook B1402CVA
  KVM: arm64: limit PMU version to PMUv3 for ARMv8.1
  arm64: cpufeature: Extract capped perfmon fields
  ext4: make sure allocate pending entry not fail
  ext4: fix slab-use-after-free in ext4_es_insert_extent()
  ext4: using nofail preallocation in ext4_es_insert_extent()
  ext4: using nofail preallocation in ext4_es_insert_delayed_block()
  ext4: using nofail preallocation in ext4_es_remove_extent()
  ext4: use pre-allocated es in __es_remove_extent()
  ext4: use pre-allocated es in __es_insert_extent()
  ext4: factor out __es_alloc_extent() and __es_free_extent()
  ext4: add a new helper to check if es must be kept
  MIPS: KVM: Fix a build warning about variable set but not used
  nvmet: nul-terminate the NQNs passed in the connect command
  nvmet: remove unnecessary ctrl parameter
  afs: Fix file locking on R/O volumes to operate in local mode
  afs: Return ENOENT if no cell DNS record can be found
  net: axienet: Fix check for partial TX checksum
  amd-xgbe: propagate the correct speed and duplex status
  amd-xgbe: handle the corner-case during tx completion
  amd-xgbe: handle corner-case during sfp hotplug
  arm/xen: fix xen_vcpu_info allocation alignment
  net: usb: ax88179_178a: fix failed operations during ax88179_reset
  ipv4: Correct/silence an endian warning in __ip_do_redirect
  HID: fix HID device resource race between HID core and debugging support
  HID: core: store the unique system identifier in hid_device
  drm/rockchip: vop: Fix color for RGB888/BGR888 format on VOP full
  ata: pata_isapnp: Add missing error check for devm_ioport_map()
  drm/panel: simple: Fix Innolux G101ICE-L01 timings
  drm/panel: simple: Fix Innolux G101ICE-L01 bus flags
  afs: Make error on cell lookup failure consistent with OpenAFS
  PCI: keystone: Drop __init from ks_pcie_add_pcie_{ep,port}()
  RDMA/irdma: Prevent zero-length STAG registration
  driver core: Release all resources during unbind before updating device links
  ANDROID: GKI: db845c: Update symbols list and ABI on rpmsg_register_device_override
  Revert "tracing: Have trace_event_file have ref counters"
  Linux 5.4.262
  netfilter: nf_tables: bogus EBUSY when deleting flowtable after flush (for 5.4)
  netfilter: nf_tables: disable toggling dormant table state more than once
  netfilter: nf_tables: fix table flag updates
  netfilter: nftables: update table flags from the commit phase
  netfilter: nf_tables: double hook unregistration in netns path
  netfilter: nf_tables: unregister flowtable hooks on netns exit
  netfilter: nf_tables: fix memleak when more than 255 elements expired
  netfilter: nft_set_hash: try later when GC hits EAGAIN on iteration
  netfilter: nft_set_rbtree: use read spinlock to avoid datapath contention
  netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction
  netfilter: nf_tables: defer gc run if previous batch is still pending
  netfilter: nf_tables: use correct lock to protect gc_list
  netfilter: nf_tables: GC transaction race with abort path
  netfilter: nf_tables: GC transaction race with netns dismantle
  netfilter: nf_tables: fix GC transaction races with netns and netlink event exit path
  netfilter: nf_tables: remove busy mark and gc batch API
  netfilter: nft_set_hash: mark set element as dead when deleting from packet path
  netfilter: nf_tables: adapt set backend to use GC transaction API
  netfilter: nf_tables: GC transaction API to avoid race with control plane
  netfilter: nf_tables: don't skip expired elements during walk
  netfilter: nft_set_rbtree: fix overlap expiration walk
  netfilter: nft_set_rbtree: fix null deref on element insertion
  netfilter: nft_set_rbtree: Switch to node list walk for overlap detection
  netfilter: nf_tables: drop map element references from preparation phase
  netfilter: nftables: rename set element data activation/deactivation functions
  netfilter: nf_tables: pass context to nft_set_destroy()
  tracing: Have trace_event_file have ref counters
  drm/amdgpu: fix error handling in amdgpu_bo_list_get()
  ext4: remove gdb backup copy for meta bg in setup_new_flex_group_blocks
  ext4: correct the start block of counting reserved clusters
  ext4: correct return value of ext4_convert_meta_bg
  ext4: correct offset of gdb backup in non meta_bg group to update_backups
  ext4: apply umask if ACL support is disabled
  Revert "net: r8169: Disable multicast filter for RTL8168H and RTL8107E"
  nfsd: fix file memleak on client_opens_release
  media: venus: hfi: add checks to handle capabilities from firmware
  media: venus: hfi: fix the check to handle session buffer requirement
  media: venus: hfi_parser: Add check to keep the number of codecs within range
  media: sharp: fix sharp encoding
  media: lirc: drop trailing space from scancode transmit
  i2c: i801: fix potential race in i801_block_transaction_byte_by_byte
  net: dsa: lan9303: consequently nested-lock physical MDIO
  Revert ncsi: Propagate carrier gain/loss events to the NCSI controller
  Bluetooth: btusb: Add 0bda:b85b for Fn-Link RTL8852BE
  Bluetooth: btusb: Add RTW8852BE device 13d3:3570 to device tables
  bluetooth: Add device 13d3:3571 to device tables
  bluetooth: Add device 0bda:887b to device tables
  Bluetooth: btusb: Add Realtek RTL8852BE support ID 0x0cb8:0xc559
  Bluetooth: btusb: add Realtek 8822CE to usb_device_id table
  Bluetooth: btusb: Add flag to define wideband speech capability
  tty: serial: meson: fix hard LOCKUP on crtscts mode
  serial: meson: Use platform_get_irq() to get the interrupt
  tty: serial: meson: retrieve port FIFO size from DT
  serial: meson: remove redundant initialization of variable id
  ALSA: hda/realtek - Enable internal speaker of ASUS K6500ZC
  ALSA: info: Fix potential deadlock at disconnection
  parisc/pgtable: Do not drop upper 5 address bits of physical address
  parisc: Prevent booting 64-bit kernels on PA1.x machines
  i3c: master: cdns: Fix reading status register
  mm/cma: use nth_page() in place of direct struct page manipulation
  dmaengine: stm32-mdma: correct desc prep when channel running
  mcb: fix error handling for different scenarios when parsing
  i2c: core: Run atomic i2c xfer when !preemptible
  kernel/reboot: emergency_restart: Set correct system_state
  quota: explicitly forbid quota files from being encrypted
  jbd2: fix potential data lost in recovering journal raced with synchronizing fs bdev
  btrfs: don't arbitrarily slow down delalloc if we're committing
  PM: hibernate: Clean up sync_read handling in snapshot_write_next()
  PM: hibernate: Use __get_safe_page() rather than touching the list
  mmc: vub300: fix an error code
  clk: qcom: ipq8074: drop the CLK_SET_RATE_PARENT flag from PLL clocks
  parisc/pdc: Add width field to struct pdc_model
  PCI: keystone: Don't discard .probe() callback
  PCI: keystone: Don't discard .remove() callback
  genirq/generic_chip: Make irq_remove_generic_chip() irqdomain aware
  mmc: meson-gx: Remove setting of CMD_CFG_ERROR
  ACPI: resource: Do IRQ override on TongFang GMxXGxx
  PCI/sysfs: Protect driver's D3cold preference from user space
  hvc/xen: fix error path in xen_hvc_init() to always register frontend driver
  audit: don't WARN_ON_ONCE(!current->mm) in audit_exe_compare()
  audit: don't take task_lock() in audit_exe_compare() code path
  KVM: x86: Ignore MSR_AMD64_TW_CFG access
  KVM: x86: hyper-v: Don't auto-enable stimer on write from user-space
  x86/cpu/hygon: Fix the CPU topology evaluation for real
  scsi: megaraid_sas: Increase register read retry rount from 3 to 30 for selected registers
  bpf: Fix precision tracking for BPF_ALU | BPF_TO_BE | BPF_END
  randstruct: Fix gcc-plugin performance mode to stay in group
  media: venus: hfi: add checks to perform sanity on queue pointers
  cifs: spnego: add ';' in HOST_KEY_LEN
  tools/power/turbostat: Fix a knl bug
  macvlan: Don't propagate promisc change to lower dev in passthru
  net/mlx5e: Check return value of snprintf writing to fw_version buffer for representors
  net/mlx5_core: Clean driver version and name
  net/mlx5e: fix double free of encap_header
  net: stmmac: fix rx budget limit check
  net: stmmac: Rework stmmac_rx()
  netfilter: nf_conntrack_bridge: initialize err to 0
  net: ethernet: cortina: Fix MTU max setting
  net: ethernet: cortina: Handle large frames
  net: ethernet: cortina: Fix max RX frame define
  bonding: stop the device in bond_setup_by_slave()
  ptp: annotate data-race around q->head and q->tail
  xen/events: fix delayed eoi list handling
  ppp: limit MRU to 64K
  tipc: Fix kernel-infoleak due to uninitialized TLV value
  net: hns3: fix variable may not initialized problem in hns3_init_mac_addr()
  tty: Fix uninit-value access in ppp_sync_receive()
  ipvlan: add ipvlan_route_v6_outbound() helper
  NFSv4.1: fix SP4_MACH_CRED protection for pnfs IO
  wifi: iwlwifi: Use FW rate for non-data frames
  pwm: Fix double shift bug
  ASoC: ti: omap-mcbsp: Fix runtime PM underflow warnings
  kgdb: Flush console before entering kgdb on panic
  drm/amd/display: Avoid NULL dereference of timing generator
  media: cobalt: Use FIELD_GET() to extract Link Width
  gfs2: ignore negated quota changes
  media: vivid: avoid integer overflow
  media: gspca: cpia1: shift-out-of-bounds in set_flicker
  i2c: sun6i-p2wi: Prevent potential division by zero
  usb: gadget: f_ncm: Always set current gadget in ncm_bind()
  tty: vcc: Add check for kstrdup() in vcc_probe()
  HID: Add quirk for Dell Pro Wireless Keyboard and Mouse KM5221W
  scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup()
  atm: iphase: Do PCI error checks on own line
  PCI: tegra194: Use FIELD_GET()/FIELD_PREP() with Link Width fields
  ALSA: hda: Fix possible null-ptr-deref when assigning a stream
  ARM: 9320/1: fix stack depot IRQ stack filter
  jfs: fix array-index-out-of-bounds in diAlloc
  jfs: fix array-index-out-of-bounds in dbFindLeaf
  fs/jfs: Add validity check for db_maxag and db_agpref
  fs/jfs: Add check for negative db_l2nbperpage
  RDMA/hfi1: Use FIELD_GET() to extract Link Width
  crypto: pcrypt - Fix hungtask for PADATA_RESET
  selftests/efivarfs: create-read: fix a resource leak
  drm/amdgpu: Fix a null pointer access when the smc_rreg pointer is NULL
  drm/amd: Fix UBSAN array-index-out-of-bounds for Polaris and Tonga
  drm/amd: Fix UBSAN array-index-out-of-bounds for SMU7
  drm/komeda: drop all currently held locks if deadlock happens
  platform/x86: thinkpad_acpi: Add battery quirk for Thinkpad X120e
  Bluetooth: Fix double free in hci_conn_cleanup
  wifi: ath10k: Don't touch the CE interrupt registers after power up
  net: annotate data-races around sk->sk_dst_pending_confirm
  net: annotate data-races around sk->sk_tx_queue_mapping
  wifi: ath10k: fix clang-specific fortify warning
  wifi: ath9k: fix clang-specific fortify warnings
  wifi: mac80211: don't return unset power in ieee80211_get_tx_power()
  wifi: mac80211_hwsim: fix clang-specific fortify warning
  x86/mm: Drop the 4 MB restriction on minimal NUMA node memory size
  clocksource/drivers/timer-atmel-tcb: Fix initialization on SAM9 hardware
  clocksource/drivers/timer-imx-gpt: Fix potential memory leak
  perf/core: Bail out early if the request AUX area is out of bound
  locking/ww_mutex/test: Fix potential workqueue corruption
  Revert "inet: shrink struct flowi_common"
  Revert "ipvlan: properly track tx_errors"
  ANDROID: fix up rpmsg_device ABI break
  ANDROID: fix up platform_device ABI break
  Linux 5.4.261
  btrfs: use u64 for buffer sizes in the tree search ioctls
  Revert "mmc: core: Capture correct oemid-bits for eMMC cards"
  fbdev: fsl-diu-fb: mark wr_reg_wa() static
  fbdev: imsttfb: fix a resource leak in probe
  fbdev: imsttfb: Fix error path of imsttfb_probe()
  spi: spi-zynq-qspi: add spi-mem to driver kconfig dependencies
  drm/syncobj: fix DRM_SYNCOBJ_WAIT_FLAGS_WAIT_AVAILABLE
  netfilter: nat: fix ipv6 nat redirect with mapped and scoped addresses
  netfilter: nft_redir: use `struct nf_nat_range2` throughout and deduplicate eval call-backs
  netfilter: xt_recent: fix (increase) ipv6 literal buffer length
  r8169: respect userspace disabling IFF_MULTICAST
  tg3: power down device only on SYSTEM_POWER_OFF
  net/smc: fix dangling sock under state SMC_APPFINCLOSEWAIT
  net: stmmac: xgmac: Enable support for multiple Flexible PPS outputs
  Fix termination state for idr_for_each_entry_ul()
  net: r8169: Disable multicast filter for RTL8168H and RTL8107E
  dccp/tcp: Call security_inet_conn_request() after setting IPv6 addresses.
  dccp: Call security_inet_conn_request() after setting IPv4 addresses.
  inet: shrink struct flowi_common
  tipc: Change nla_policy for bearer-related names to NLA_NUL_STRING
  llc: verify mac len before reading mac header
  Input: synaptics-rmi4 - fix use after free in rmi_unregister_function()
  pwm: brcmstb: Utilize appropriate clock APIs in suspend/resume
  pwm: sti: Reduce number of allocations and drop usage of chip_data
  pwm: sti: Avoid conditional gotos
  regmap: prevent noinc writes from clobbering cache
  media: dvb-usb-v2: af9035: fix missing unlock
  media: s3c-camif: Avoid inappropriate kfree()
  media: bttv: fix use after free error due to btv->timeout timer
  pcmcia: ds: fix possible name leak in error path in pcmcia_device_add()
  pcmcia: ds: fix refcount leak in pcmcia_device_add()
  pcmcia: cs: fix possible hung task and memory leak pccardd()
  rtc: pcf85363: fix wrong mask/val parameters in regmap_update_bits call
  i3c: Fix potential refcount leak in i3c_master_register_new_i3c_devs
  powerpc/pseries: fix potential memory leak in init_cpu_associativity()
  powerpc/imc-pmu: Use the correct spinlock initializer.
  powerpc/xive: Fix endian conversion size
  modpost: fix tee MODULE_DEVICE_TABLE built on big-endian host
  f2fs: fix to initialize map.m_pblk in f2fs_precache_extents()
  dmaengine: pxa_dma: Remove an erroneous BUG_ON() in pxad_free_desc()
  USB: usbip: fix stub_dev hub disconnect
  tools: iio: iio_generic_buffer ensure alignment
  tools: iio: iio_generic_buffer: Fix some integer type and calculation
  tools: iio: privatize globals and functions in iio_generic_buffer.c file
  misc: st_core: Do not call kfree_skb() under spin_lock_irqsave()
  dmaengine: ti: edma: handle irq_of_parse_and_map() errors
  usb: dwc2: fix possible NULL pointer dereference caused by driver concurrency
  tty: tty_jobctrl: fix pid memleak in disassociate_ctty()
  leds: trigger: ledtrig-cpu:: Fix 'output may be truncated' issue for 'cpu'
  ledtrig-cpu: Limit to 8 CPUs
  leds: pwm: Don't disable the PWM when the LED should be off
  leds: pwm: convert to atomic PWM API
  leds: pwm: simplify if condition
  mfd: dln2: Fix double put in dln2_probe
  ASoC: ams-delta.c: use component after check
  ASoC: Intel: Skylake: Fix mem leak when parsing UUIDs fails
  sh: bios: Revive earlyprintk support
  RDMA/hfi1: Workaround truncation compilation error
  scsi: ufs: core: Leave space for '\0' in utf8 desc string
  ext4: move 'ix' sanity check to corrent position
  ARM: 9321/1: memset: cast the constant byte to unsigned char
  hid: cp2112: Fix duplicate workqueue initialization
  HID: cp2112: Use irqchip template
  crypto: caam/jr - fix Chacha20 + Poly1305 self test failure
  crypto: caam/qi2 - fix Chacha20 + Poly1305 self test failure
  nd_btt: Make BTT lanes preemptible
  sched/rt: Provide migrate_disable/enable() inlines
  libnvdimm/of_pmem: Use devm_kstrdup instead of kstrdup and check its return value
  hwrng: geode - fix accessing registers
  clk: scmi: Free scmi_clk allocated when the clocks with invalid info are skipped
  firmware: ti_sci: Mark driver as non removable
  firmware: ti_sci: Replace HTTP links with HTTPS ones
  soc: qcom: llcc: Handle a second device without data corruption
  soc: qcom: Rename llcc-slice to llcc-qcom
  soc: qcom: llcc cleanup to get rid of sdm845 specific driver file
  ARM: dts: qcom: mdm9615: populate vsdcc fixed regulator
  arm64: dts: qcom: sdm845-mtp: fix WiFi configuration
  drm/rockchip: cdn-dp: Fix some error handling paths in cdn_dp_probe()
  drm/radeon: possible buffer overflow
  drm/rockchip: vop: Fix call to crtc reset helper
  drm/rockchip: vop: Fix reset of state in duplicate state crtc funcs
  hwmon: (coretemp) Fix potentially truncated sysfs attribute name
  platform/x86: wmi: Fix opening of char device
  platform/x86: wmi: remove unnecessary initializations
  platform/x86: wmi: Fix probe failure when failing to register WMI devices
  clk: mediatek: clk-mt2701: Add check for mtk_alloc_clk_data
  clk: mediatek: clk-mt7629: Add check for mtk_alloc_clk_data
  clk: mediatek: clk-mt7629-eth: Add check for mtk_alloc_clk_data
  clk: mediatek: clk-mt6797: Add check for mtk_alloc_clk_data
  clk: mediatek: clk-mt6779: Add check for mtk_alloc_clk_data
  clk: npcm7xx: Fix incorrect kfree
  clk: keystone: pll: fix a couple NULL vs IS_ERR() checks
  clk: imx: Select MXC_CLK for CLK_IMX8QXP
  clk: qcom: gcc-sm8150: Fix gcc_sdcc2_apps_clk_src
  clk: qcom: gcc-sm8150: use ARRAY_SIZE instead of specifying num_parents
  clk: qcom: clk-rcg2: Fix clock rate overflow for high parent frequencies
  regmap: debugfs: Fix a erroneous check after snprintf()
  ipvlan: properly track tx_errors
  net: add DEV_STATS_READ() helper
  ipv6: avoid atomic fragment on GSO packets
  ACPI: sysfs: Fix create_pnp_modalias() and create_of_modalias()
  tcp: fix cookie_init_timestamp() overflows
  tcp: Remove one extra ktime_get_ns() from cookie_init_timestamp
  chtls: fix tp->rcv_tstamp initialization
  r8169: fix rare issue with broken rx after link-down on RTL8125
  r8169: use tp_to_dev instead of open code
  thermal: core: prevent potential string overflow
  can: dev: can_restart(): fix race condition between controller restart and netif_carrier_on()
  can: dev: can_restart(): don't crash kernel if carrier is OK
  wifi: rtlwifi: fix EDCA limit set by BT coexistence
  tcp_metrics: do not create an entry from tcp_init_metrics()
  tcp_metrics: properly set tp->snd_ssthresh in tcp_init_metrics()
  tcp_metrics: add missing barriers on delete
  wifi: mt76: mt7603: rework/fix rx pse hang check
  wifi: rtw88: debug: Fix the NULL vs IS_ERR() bug for debugfs_create_file()
  tcp: call tcp_try_undo_recovery when an RTOd TFO SYNACK is ACKed
  i40e: fix potential memory leaks in i40e_remove()
  genirq/matrix: Exclude managed interrupts in irq_matrix_allocated()
  vfs: fix readahead(2) on block devices
  Linux 5.4.260
  tty: 8250: Add support for Intashield IS-100
  tty: 8250: Add support for Brainboxes UP cards
  tty: 8250: Add support for additional Brainboxes UC cards
  tty: 8250: Remove UC-257 and UC-431
  usb: storage: set 1.50 as the lower bcdDevice for older "Super Top" compatibility
  PCI: Prevent xHCI driver from claiming AMD VanGogh USB3 DRD device
  Revert "ARM: dts: Move am33xx and am43xx mmc nodes to sdhci-omap driver"
  nvmet-tcp: Fix a possible UAF in queue intialization setup
  nvmet-tcp: move send/recv error handling in the send/recv methods instead of call-sites
  remove the sx8 block driver
  ata: ahci: fix enum constants for gcc-13
  net: chelsio: cxgb4: add an error code check in t4_load_phy_fw
  platform/mellanox: mlxbf-tmfifo: Fix a warning message
  platform/x86: asus-wmi: Change ASUS_WMI_BRN_DOWN code from 0x20 to 0x2e
  scsi: mpt3sas: Fix in error path
  fbdev: uvesafb: Call cn_del_callback() at the end of uvesafb_exit()
  ASoC: rt5650: fix the wrong result of key button
  netfilter: nfnetlink_log: silence bogus compiler warning
  spi: npcm-fiu: Fix UMA reads when dummy.nbytes == 0
  fbdev: atyfb: only use ioremap_uc() on i386 and ia64
  Input: synaptics-rmi4 - handle reset delay when using SMBus trsnsport
  dmaengine: ste_dma40: Fix PM disable depth imbalance in d40_probe
  irqchip/stm32-exti: add missing DT IRQ flag translation
  Input: i8042 - add Fujitsu Lifebook E5411 to i8042 quirk table
  x86: Fix .brk attribute in linker script
  rpmsg: Fix possible refcount leak in rpmsg_register_device_override()
  rpmsg: glink: Release driver_override
  rpmsg: Fix calling device_lock() on non-initialized device
  rpmsg: Fix kfree() of static memory on setting driver_override
  rpmsg: Constify local variable in field store macro
  driver: platform: Add helper for safer setting of driver_override
  ext4: fix BUG in ext4_mb_new_inode_pa() due to overflow
  ext4: avoid overlapping preallocations due to overflow
  ext4: add two helper functions extent_logical_end() and pa_logical_end()
  x86/mm: Fix RESERVE_BRK() for older binutils
  x86/mm: Simplify RESERVE_BRK()
  nfsd: lock_rename() needs both directories to live on the same fs
  f2fs: fix to do sanity check on inode type during garbage collection
  smbdirect: missing rc checks while waiting for rdma events
  kobject: Fix slab-out-of-bounds in fill_kobj_path()
  arm64: fix a concurrency issue in emulation_proc_handler()
  drm/dp_mst: Fix NULL deref in get_mst_branch_device_by_guid_helper()
  x86/i8259: Skip probing when ACPI/MADT advertises PCAT compatibility
  i40e: Fix wrong check for I40E_TXR_FLAGS_WB_ON_ITR
  clk: Sanitize possible_parent_show to Handle Return Value of of_clk_get_parent_name
  perf/core: Fix potential NULL deref
  nvmem: imx: correct nregs for i.MX6UL
  nvmem: imx: correct nregs for i.MX6SLL
  nvmem: imx: correct nregs for i.MX6ULL
  i2c: aspeed: Fix i2c bus hang in slave read
  i2c: stm32f7: Fix PEC handling in case of SMBUS transfers
  i2c: muxes: i2c-demux-pinctrl: Use of_get_i2c_adapter_by_node()
  i2c: muxes: i2c-mux-gpmux: Use of_get_i2c_adapter_by_node()
  i2c: muxes: i2c-mux-pinctrl: Use of_get_i2c_adapter_by_node()
  iio: exynos-adc: request second interupt only when touchscreen mode is used
  gtp: fix fragmentation needed check with gso
  gtp: uapi: fix GTPA_MAX
  tcp: fix wrong RTO timeout when received SACK reneging
  r8152: Cancel hw_phy_work if we have an error in probe
  r8152: Run the unload routine if we have errors during probe
  r8152: Increase USB control msg timeout to 5000ms as per spec
  net: ieee802154: adf7242: Fix some potential buffer overflow in adf7242_stats_show()
  igc: Fix ambiguity in the ethtool advertising
  neighbour: fix various data-races
  igb: Fix potential memory leak in igb_add_ethtool_nfc_entry
  treewide: Spelling fix in comment
  r8169: fix the KCSAN reported data race in rtl_rx while reading desc->opts1
  r8169: fix the KCSAN reported data-race in rtl_tx while reading TxDescArray[entry].opts1
  virtio-mmio: fix memory leak of vm_dev
  virtio_balloon: Fix endless deflation and inflation on arm64
  mcb-lpc: Reallocate memory region to avoid memory overlapping
  mcb: Return actual parsed size when reading chameleon table
  selftests/ftrace: Add new test case which checks non unique symbol
  mtd: rawnand: marvell: Ensure program page operations are successful

Conflicts:
     both modified:   drivers/clk/qcom/gcc-sm8150.c
     both modified:   drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
     both modified:   drivers/usb/dwc3/core.c
     both modified:   drivers/usb/gadget/function/f_ncm.c
     both modified:   kernel/events/core.c

Change-Id: I29a93811ddcabe88b7912a6593801505e9fd233c
Signed-off-by: kamasali Satyanarayan <quic_kamasali@quicinc.com>
2024-02-29 15:10:56 +05:30
Srinivasarao Pathipati
1ffd957fcf Revert LLCC changes
reverting below llcc changes
cc1a1dcb41 soc: qcom: llcc: Handle a second device without data corruption
813fdddde2 soc: qcom: Rename llcc-slice to llcc-qcom
077010717b soc: qcom: llcc cleanup to get rid of sdm845 specific driver file

Change-Id: Ia3588add7e8884d2b05fd770253c98afad41adf5
Signed-off-by: kamasali Satyanarayan <quic_kamasali@quicinc.com>
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2024-02-28 12:57:06 +05:30
Sarannya S
58e401790a soc: qcom: smem: Add boundary checks for partitions
Add condition check to make sure that the end address
of private entry does not go out of partition.

Change-Id: I88b3c69d86d90905b214c13a8c632b134b487a49
Signed-off-by: Sarannya S <quic_sarannya@quicinc.com>
Signed-off-by: Pranav Mahesh Phansalkar <quic_pphansal@quicinc.com>
2024-02-20 14:31:26 +05:30
qctecmdr
2cf7f335fc Merge "msm: kgsl: Do not release dma and anon buffers if unmap fails" 2024-02-13 10:14:25 -08:00
Lynus Vaz
e7c4bb239b msm: kgsl: Do not release dma and anon buffers if unmap fails
If iommu unmap fails and leaves dma or anon buffers still mapped in the
iommu, do not free them.

Change-Id: Ice0e1a59c1ac0ee7a9d62d8899966b84fa63d5ca
Signed-off-by: Lynus Vaz <quic_lvaz@quicinc.com>
Signed-off-by: Deepak Kumar <quic_dkumar@quicinc.com>
2024-02-13 15:05:15 +05:30
Manoj Prabhu B
f555e9e4ad memshare: Prevent possible integer overflow
Prevent possible integer overflow by sanitizing the alloc request
size coming from the client against allottable amount of memory.

Change-Id: I74cb0f7b0808f20299586969fd5c810d44c3e576
Signed-off-by: Manoj Prabhu B <quic_bmanoj@quicinc.com>
Signed-off-by: Madhab Sharma <quic_madhshar@quicinc.com>
2024-02-09 14:52:41 +05:30
qctecmdr
301c6b0cba Merge "Merge android11-5.4.259+ (70db018) into msm-5.4" 2024-02-05 00:10:49 -08:00
qctecmdr
995eaab1e4 Merge "msm: kgsl: Keep the timeline fence valid for logging" 2024-01-31 21:04:15 -08:00
qctecmdr
1e787ce267 Merge "msm: ipa: Add support for Private IP Forwarding" 2024-01-31 12:02:50 -08:00
Greg Kroah-Hartman
a34cc1dcf7 Reapply "perf: Disallow mis-matched inherited group reads"
This reverts commit 4934e8f7a8.

Keeps the ABI stable by taking advantage of a hole in the structure!

Bug: 307236803
Change-Id: Ic5f7ebeb3a9b13afdb3bfff7e54c4a93b863dab6
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-01-31 15:17:06 +00:00
Lynus Vaz
c2eae40b63 msm: kgsl: Keep the timeline fence valid for logging
The timeline fence needs to remain valid for logging purposes. Take an
extra refcount on the timeline dma_fence to make sure it doesn't go
away till we're done with it.

Change-Id: I6670ef7add099a72684c1fe20ed009dff85d1f27
Signed-off-by: Lynus Vaz <quic_lvaz@quicinc.com>
Signed-off-by: Deepak Kumar <quic_dkumar@quicinc.com>
2024-01-31 20:24:16 +05:30
Krishna Nagaraja
fd3f99504d msm: ipa: Add support for Private IP Forwarding
Changes for new uCP commands, and IOCTL to support this feature

Change-Id: Idd7de3f18fc557b54b3c2d965802065b3f6dd982
Signed-off-by: Krishna Nagaraja <quic_krisnag@quicinc.com>
2024-01-31 15:08:32 +05:30
kamasali Satyanarayan
079b43b825 Merge android11-5.4.259+ (70db018) into msm-5.4
* remotes/origin/tmp-70db018:
  UPSTREAM: ipv4: igmp: fix refcnt uaf issue when receiving igmp query packet
  ANDROID: Snapshot Mainline's version of checkpatch.pl
  UPSTREAM: nvmet-tcp: Fix a possible UAF in queue intialization setup
  UPSTREAM: nvmet-tcp: move send/recv error handling in the send/recv methods instead of call-sites

Conflicts:
	scripts/checkpatch.pl

Change-Id: I28aaacd0fb6478ade935672027760efce65a7911
Signed-off-by: kamasali Satyanarayan <quic_kamasali@quicinc.com>
2024-01-31 01:01:26 -08:00
Douglas Anderson
aea710204a UPSTREAM: ath10k: Get rid of "per_ce_irq" hw param
[ Upstream commit 7f86551665121931ecd6d327e019e7a69782bfcd ]

As of the patch ("ath10k: Keep track of which interrupts fired, don't
poll them") we now have no users of this hardware parameter.  Remove
it.

Suggested-by: Brian Norris <briannorris@chromium.org>
Signed-off-by: Douglas Anderson <dianders@chromium.org>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Link: https://lore.kernel.org/r/20200709082024.v2.2.I083faa4e62e69f863311c89ae5eb28ec5a229b70@changeid
Stable-dep-of: 170c75d43a77 ("ath10k: Don't touch the CE interrupt registers after power up")
Signed-off-by: Amit Pundir <amit.pundir@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 146449535
Change-Id: I221d9cc30d009c3bc87a7943f8e3da1931984e1e
Signed-off-by: Amit Pundir <amit.pundir@linaro.org>
(cherry picked from android11-5.4-lts commit c2d9b43855)
2024-01-30 21:34:08 +05:30
Douglas Anderson
89945968f1 UPSTREAM: ath10k: Keep track of which interrupts fired, don't poll them
[ Upstream commit d66d24ac300cf41c6b88367fc9b4b6348679273d ]

If we have a per CE (Copy Engine) IRQ then we have no summary
register.  Right now the code generates a summary register by
iterating over all copy engines and seeing if they have an interrupt
pending.

This has a problem.  Specifically if _none_ if the Copy Engines have
an interrupt pending then they might go into low power mode and
reading from their address space will cause a full system crash.  This
was seen to happen when two interrupts went off at nearly the same
time.  Both were handled by a single call of ath10k_snoc_napi_poll()
but, because there were two interrupts handled and thus two calls to
napi_schedule() there was still a second call to
ath10k_snoc_napi_poll() which ran with no interrupts pending.

Instead of iterating over all the copy engines, let's just keep track
of the IRQs that fire.  Then we can effectively generate our own
summary without ever needing to read the Copy Engines.

Tested-on: WCN3990 SNOC WLAN.HL.3.2.2-00490-QCAHLSWMTPL-1

Signed-off-by: Douglas Anderson <dianders@chromium.org>
Reviewed-by: Rakesh Pillai <pillair@codeaurora.org>
Reviewed-by: Brian Norris <briannorris@chromium.org>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Link: https://lore.kernel.org/r/20200709082024.v2.1.I4d2f85ffa06f38532631e864a3125691ef5ffe06@changeid
Stable-dep-of: 170c75d43a77 ("ath10k: Don't touch the CE interrupt registers after power up")
Signed-off-by: Amit Pundir <amit.pundir@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 146449535
Change-Id: I3dbc75664ccbf4e8a1da60e42e84056551b10524
Signed-off-by: Amit Pundir <amit.pundir@linaro.org>
(cherry picked from android11-5.4-lts commit d15f869cb3)
2024-01-30 21:33:52 +05:30
Rakesh Pillai
d9f1b99f4c UPSTREAM: ath10k: Add interrupt summary based CE processing
[ Upstream commit b92aba35d39d10d8a6bdf2495172fd490c598b4a ]

Currently the NAPI processing loops through all
the copy engines and processes a particular copy
engine is the copy completion is set for that copy
engine. The host driver is not supposed to access
any copy engine register after clearing the interrupt
status register.

This might result in kernel crash like the one below
[ 1159.220143] Call trace:
[ 1159.220170]  ath10k_snoc_read32+0x20/0x40 [ath10k_snoc]
[ 1159.220193]  ath10k_ce_per_engine_service_any+0x78/0x130 [ath10k_core]
[ 1159.220203]  ath10k_snoc_napi_poll+0x38/0x8c [ath10k_snoc]
[ 1159.220270]  net_rx_action+0x100/0x3b0
[ 1159.220312]  __do_softirq+0x164/0x30c
[ 1159.220345]  run_ksoftirqd+0x2c/0x64
[ 1159.220380]  smpboot_thread_fn+0x1b0/0x288
[ 1159.220405]  kthread+0x11c/0x12c
[ 1159.220423]  ret_from_fork+0x10/0x18

To avoid such a scenario, we generate an interrupt
summary by reading the copy completion for all the
copy engine before actually processing any of them.
This will avoid reading the interrupt status register
for any CE after the interrupt status is cleared.

Tested-on: WCN3990 hw1.0 SNOC WLAN.HL.3.1-01040-QCAHLSWMTPLZ-1

Signed-off-by: Rakesh Pillai <pillair@codeaurora.org>
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Tested-by: Douglas Anderson <dianders@chromium.org>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Link: https://lore.kernel.org/r/1593193967-29897-1-git-send-email-pillair@codeaurora.org
Stable-dep-of: 170c75d43a77 ("ath10k: Don't touch the CE interrupt registers after power up")
Signed-off-by: Amit Pundir <amit.pundir@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 146449535
Change-Id: I3d85ff89b889eac117c6f14c77b8aae1d5b3d236
Signed-off-by: Amit Pundir <amit.pundir@linaro.org>
(cherry picked from android11-5.4-lts commit 696b992edc)
2024-01-30 21:33:36 +05:30
Douglas Anderson
0226ac138f UPSTREAM: ath10k: Wait until copy complete is actually done before completing
[ Upstream commit 8f9ed93d09a97444733d492a3bbf66bcb786a777 ]

On wcn3990 we have "per_ce_irq = true".  That makes the
ath10k_ce_interrupt_summary() function always return 0xfff. The
ath10k_ce_per_engine_service_any() function will see this and think
that _all_ copy engines have an interrupt.  Without checking, the
ath10k_ce_per_engine_service() assumes that if it's called that the
"copy complete" (cc) interrupt fired.  This combination seems bad.

Let's add a check to make sure that the "copy complete" interrupt
actually fired in ath10k_ce_per_engine_service().

This might fix a hard-to-reproduce failure where it appears that the
copy complete handlers run before the copy is really complete.
Specifically a symptom was that we were seeing this on a Qualcomm
sc7180 board:
  arm-smmu 15000000.iommu: Unhandled context fault:
  fsr=0x402, iova=0x7fdd45780, fsynr=0x30003, cbfrsynra=0xc1, cb=10

Even on platforms that don't have wcn3990 this still seems like it
would be a sane thing to do.  Specifically the current IRQ handler
comments indicate that there might be other misc interrupt sources
firing that need to be cleared.  If one of those sources was the one
that caused the IRQ handler to be called it would also be important to
double-check that the interrupt we cared about actually fired.

Tested-on: WCN3990 SNOC WLAN.HL.3.2.2-00490-QCAHLSWMTPL-1

Signed-off-by: Douglas Anderson <dianders@chromium.org>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Link: https://lore.kernel.org/r/20200609082015.1.Ife398994e5a0a6830e4d4a16306ef36e0144e7ba@changeid
Stable-dep-of: 170c75d43a77 ("ath10k: Don't touch the CE interrupt registers after power up")
Signed-off-by: Amit Pundir <amit.pundir@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 146449535
Change-Id: I2ed2f1f7b97a27c741341bc6044450b68234114e
Signed-off-by: Amit Pundir <amit.pundir@linaro.org>
(cherry picked from android11-5.4-lts commit 366df9ecbc)
2024-01-30 21:33:20 +05:30
Amit Pundir
a7a2a20fff FROMGIT: clk: qcom: gcc-sdm845: Add soft dependency on rpmhpd
With the addition of RPMh power domain to the GCC node in
device tree, we noticed a significant delay in getting the
UFS driver probed on AOSP which futher led to mount failures
because Android do not support rootwait. So adding a soft
dependency on RPMh power domain which informs modprobe to
load rpmhpd module before gcc-sdm845.

Cc: <stable@vger.kernel.org> # v5.4+
Fixes: 4b6ea15c0a11 ("arm64: dts: qcom: sdm845: Add missing RPMh power domain to GCC")
Suggested-by: Manivannan Sadhasivam <manivannan.sadhasivam@linaro.org>
Signed-off-by: Amit Pundir <amit.pundir@linaro.org>
Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@linaro.org>
Link: https://lore.kernel.org/r/20240123062814.2555649-1-amit.pundir@linaro.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>

Bug: 146449535
(cherry picked from commit 1d9054e3a4fd36e2949e616f7360bdb81bcc1921
https://git.kernel.org/pub/scm/linux/kernel/git/qcom/linux.git/commit/?h=for-next)
Signed-off-by: Amit Pundir <amit.pundir@linaro.org>
Change-Id: I93c875d3d6acc8c2c2bf9f238a72733861f87869
(cherry picked from android11-5.4-lts commit b70f9975af)
2024-01-30 21:33:05 +05:30
Fakruddin Vohra
fc5843f99a msm: ipa3: add support to identify wifi attach
add change to identify the wifi attach as communicated
by wlan at wdi init.

Change-Id: Iea73ce1037bdbe1064570173c0792f0fe139ac4f
Signed-off-by: Fakruddin Vohra <quic_fakruddi@quicinc.com>
2024-01-29 21:12:46 -08:00
qctecmdr
bcb96a65a1 Merge "msm_serial_hs: Fix race between mod_timer and del_timer calls" 2024-01-29 06:10:16 -08:00
qctecmdr
4bf33cb3ab Merge "soc: qcom: minidump_log: Protect md_dump_slabinfo under SLUB_DEBUG" 2024-01-21 20:36:18 -08:00
qctecmdr
4d067a9dad Merge "mm: slub: Declare slab_owner_ops only when SLUB DEBUG is enabled" 2024-01-21 20:36:17 -08:00
Rohit Agarwal
ae146b9a20 soc: qcom: minidump_log: Protect md_dump_slabinfo under SLUB_DEBUG
Protect md_dump_slabinfo call only if SLUB_DEBUG is enabled.

Change-Id: I1f703e039517dd24fad303f830a6a30a3f32c3f7
Signed-off-by: Rohit Agarwal <quic_rohiagar@quicinc.com>
2024-01-19 14:06:33 +05:30
Rohit Agarwal
40d396eb36 mm: slub: Declare slab_owner_ops only when SLUB DEBUG is enabled
Declare the ops struct and corresponding callbacks only when
SLUB_DEBUG is enabled.
Currently, the ops is defined only under
MINIDUMP_PANIC_DUMP config but the variables it uses are protected
under SLUB_DEBUG as well.

Change-Id: I11f29564e1d65edc506a50e2c12aac374dbca6d5
Signed-off-by: Rohit Agarwal <quic_rohiagar@quicinc.com>
2024-01-18 01:32:07 -08:00
Saranya R
c7fecf0481 soc: qcom: Add BLAIR-LITE SoC information to socinfo
Add BLAIR-LITE SoC information to socinfo.

Change-Id: I334a80508434ea3aaa972ecb0e2b72586e81dfca
Signed-off-by: Saranya R <quic_sarar@quicinc.com>
2024-01-10 17:38:02 +05:30
Greg Kroah-Hartman
80118b745c Merge tag 'android11-5.4.265_r00' into branch 'android11-5.4'
This merges the changes up to the 5.4.265 LTS release into the
android11-5.4 branch.  It contains the following individual commits:

* e2be513380 ANDROID: GKI: fix crc issue in include/net/addrconf.h
* 3c4b111a71 Revert "cred: switch to using atomic_long_t"
*   5158e9afed Merge 5.4.265 into android11-5.4-lts
|\
| * 2d21f73b2f Linux 5.4.265
| * 5c70542f32 powerpc/ftrace: Fix stack teardown in ftrace_no_trace
| * 0e1867b482 powerpc/ftrace: Create a dummy stackframe to fix stack unwind
| * 9395c04666 mmc: block: Be sure to wait while busy in CQE error recovery
| * 3b8b2c5d76 ring-buffer: Fix memory leak of free page
| * 3459c9aa64 team: Fix use-after-free when an option instance allocation fails
| * 363a67ef3a arm64: mm: Always make sw-dirty PTEs hw-dirty in pte_modify
| * de8ada0236 ext4: prevent the normalized size from exceeding EXT_MAX_BLOCKS
| * f451d6784b soundwire: stream: fix NULL pointer dereference for multi_link
| * 404902216b perf: Fix perf_event_validate_size() lockdep splat
| * 4109d9a855 HID: hid-asus: add const to read-only outgoing usb buffer
| * 1fc4091991 net: usb: qmi_wwan: claim interface 4 for ZTE MF290
| * 88ceaf8e2c asm-generic: qspinlock: fix queued_spin_value_unlocked() implementation
| * 91175d6fe5 HID: multitouch: Add quirk for HONOR GLO-GXXX touchpad
| * 1f94c0d60d HID: hid-asus: reset the backlight brightness level on resume
| * e9a3cd3dcf HID: add ALWAYS_POLL quirk for Apple kb
| * 395ad0baa4 platform/x86: intel_telemetry: Fix kernel doc descriptions
| * af509912cd bcache: avoid NULL checking to c->root in run_cache_set()
| * 356ae9de79 bcache: add code comments for bch_btree_node_get() and __bch_btree_node_alloc()
| * ca4b00c6cb bcache: avoid oversize memory allocation by small stripe_size
| * e1d811cbc3 blk-throttle: fix lockdep warning of "cgroup_mutex or RCU read lock required!"
| * 84f2e5b3e7 usb: aqc111: check packet for fixup for true limit
| * 619a340666 Revert "PCI: acpiphp: Reassign resources on bridge if necessary"
| * 371dbce60a ALSA: hda/hdmi: add force-connect quirks for ASUSTeK Z170 variants
| * be7676b03a cred: switch to using atomic_long_t
| * 9112bd1072 appletalk: Fix Use-After-Free in atalk_ioctl
| * 23ee06762c net: stmmac: Handle disabled MDIO busses from devicetree
| * 538b7b8f21 net: stmmac: use dev_err_probe() for reporting mdio bus registration failure
| * 067e6ec9f5 vsock/virtio: Fix unsigned integer wrap around in virtio_transport_has_space()
| * cc7cf0b2ee sign-file: Fix incorrect return values check
| * 510d45207a net: Remove acked SYN flag from packet in the transmit queue correctly
| * 5d9d500a28 qed: Fix a potential use-after-free in qed_cxt_tables_alloc
| * 3df812627e net/rose: Fix Use-After-Free in rose_ioctl
| * b099c28847 atm: Fix Use-After-Free in do_vcc_ioctl
| * e3430b870e atm: solos-pci: Fix potential deadlock on &tx_queue_lock
| * 8cff60fb73 atm: solos-pci: Fix potential deadlock on &cli_queue_lock
| * fcf17666ef qca_spi: Fix reset behavior
| * 51ad9c19bb qca_debug: Fix ethtool -G iface tx behavior
| * b7f5868664 qca_debug: Prevent crash on TX ring changes
| * 9354e0acdb net: ipv6: support reporting otherwise unknown prefix flags in RTM_NEWPREFIX
| * 053220aaed afs: Fix refcount underflow from error handling race
* | bc99f18e84 Revert "psample: Require 'CAP_NET_ADMIN' when joining "packets" group"
* | 000b611ebf Revert "mmc: core: add helpers mmc_regulator_enable/disable_vqmmc"
* | ee67cef1d3 Revert "mmc: sdhci-sprd: Fix vqmmc not shutting down after the card was pulled"
* | ee9bfb84c7 Revert "genetlink: add CAP_NET_ADMIN test for multicast bind"
* | 4684391cef Revert "drop_monitor: Require 'CAP_SYS_ADMIN' when joining "events" group"
* | 50aa4f43a9 Revert "perf/core: Add a new read format to get a number of lost samples"
* | 8eb4011508 Revert "perf: Fix perf_event_validate_size()"
* | 5c9845d8c6 Revert "hrtimers: Push pending hrtimers away from outgoing CPU earlier"
* | af6deae771 Merge 5.4.264 into android11-5.4-lts
|\|
| * 16e6e107a6 Linux 5.4.264
| * 06bcac5c51 devcoredump: Send uevent once devcd is ready
| * c6a1282e53 devcoredump : Serialize devcd_del work
| * d99376b702 smb: client: fix potential NULL deref in parse_dfs_referrals()
| * ab5813bb20 cifs: Fix non-availability of dedup breaking generic/304
| * bdee8b2805 Revert "btrfs: add dmesg output for first mount and last unmount of a filesystem"
| * dd9e851944 tools headers UAPI: Sync linux/perf_event.h with the kernel sources
| * 4a341627a1 drop_monitor: Require 'CAP_SYS_ADMIN' when joining "events" group
| * fe8402511e psample: Require 'CAP_NET_ADMIN' when joining "packets" group
| * 263bffd2b6 genetlink: add CAP_NET_ADMIN test for multicast bind
| * a149fbadb9 netlink: don't call ->netlink_bind with table lock held
| * 18824f592a io_uring/af_unix: disable sending io_uring over sockets
| * 32f4536c10 nilfs2: fix missing error check for sb_set_blocksize call
| * 77a353924d KVM: s390/mm: Properly reset no-dat
| * 1aee33d43d x86/CPU/AMD: Check vendor in the AMD microcode callback
| * 3371eac211 serial: 8250_omap: Add earlycon support for the AM654 UART controller
| * ce79cf407c serial: sc16is7xx: address RX timeout interrupt errata
| * d896c47f8c ARM: PL011: Fix DMA support
| * 880b035bc6 usb: typec: class: fix typec_altmode_put_partner to put plugs
| * a9022cbdd0 parport: Add support for Brainboxes IX/UC/PX parallel cards
| * fefc0559c5 usb: gadget: f_hid: fix report descriptor allocation
| * 1796ae6a7a mmc: sdhci-sprd: Fix vqmmc not shutting down after the card was pulled
| * a1f29e995f mmc: core: add helpers mmc_regulator_enable/disable_vqmmc
| * 05918dec9a gpiolib: sysfs: Fix error handling on failed export
| * 152f51d159 perf: Fix perf_event_validate_size()
| * 84ca356ec8 perf/core: Add a new read format to get a number of lost samples
| * 07bdb1bd24 arm64: dts: mediatek: mt8173-evb: Fix regulator-fixed node names
| * 6109859f69 arm64: dts: mediatek: mt7622: fix memory node warning check
| * 148d8f0707 packet: Move reference count in packet_sock to atomic_long_t
| * 965cbc6b62 tracing: Fix a possible race when disabling buffered events
| * 6f2e50961f tracing: Fix incomplete locking when disabling buffered events
| * 84302391d1 tracing: Always update snapshot buffer size
| * cb74e8fd6b nilfs2: prevent WARNING in nilfs_sufile_set_segment_usage()
| * 610ebc2895 ALSA: pcm: fix out-of-bounds in snd_pcm_state_names
| * 439166b1b2 ARM: dts: imx7: Declare timers compatible with fsl,imx6dl-gpt
| * 4fe36f83f8 ARM: dts: imx: make gpt node name generic
| * 69b669cc63 ARM: imx: Check return value of devm_kasprintf in imx_mmdc_perf_init
| * 59348f1482 scsi: be2iscsi: Fix a memleak in beiscsi_init_wrb_handle()
| * 8244ea916b tracing: Fix a warning when allocating buffered events fails
| * 4713be8445 ASoC: wm_adsp: fix memleak in wm_adsp_buffer_populate
| * febb7bbe29 hwmon: (acpi_power_meter) Fix 4.29 MW bug
| * ad4cf77667 RDMA/bnxt_re: Correct module description string
| * b4b89b7b2d bpf: sockmap, updating the sg structure should also update curr
| * 7ffff0cc92 tcp: do not accept ACK of bytes we never sent
| * 69431f609b netfilter: xt_owner: Fix for unsafe access of sk->sk_socket
| * c61c61d7e7 net: hns: fix fake link up on xge port
| * 1ec21fde58 ipv4: ip_gre: Avoid skb_pull() failure in ipgre_xmit()
| * e38cd53421 arcnet: restoring support for multiple Sohard Arcnet cards
| * f265467319 net: arcnet: com20020 fix error handling
| * d124c18267 net: arcnet: Fix RESET flag handling
| * 9f5a25aa1b hv_netvsc: rndis_filter needs to select NLS
| * be1ab8bf05 ipv6: fix potential NULL deref in fib6_add()
| * 5cd05bbaae of: dynamic: Fix of_reconfig_get_state_change() return value documentation
| * 5cadae629e of: Add missing 'Return' section in kerneldoc comments
| * b31cb14cac of: Fix kerneldoc output formatting
| * 36ce931a80 of: base: Fix some formatting issues and provide missing descriptions
| * 8c4fcbe27a of/irq: Make of_msi_map_rid() PCI bus agnostic
| * ae374c57af of/irq: make of_msi_map_get_device_domain() bus agnostic
| * e5cfaab662 of/iommu: Make of_map_rid() PCI agnostic
| * f7a8552008 ACPI/IORT: Make iort_msi_map_rid() PCI agnostic
| * da36a3ef32 ACPI/IORT: Make iort_get_device_domain IRQ domain agnostic
| * d786067be2 of: base: Add of_get_cpu_state_node() to get idle states for a CPU node
| * 13f27a0537 drm/amdgpu: correct chunk_ptr to a pointer to chunk.
| * d162a5e6a5 kconfig: fix memory leak from range properties
| * d346441530 tg3: Increment tx_dropped in tg3_tso_bug()
| * cd49b8e07d tg3: Move the [rt]x_dropped counters to tg3_napi
| * 427deb5ba5 netfilter: ipset: fix race condition between swap/destroy and kernel side add/del/test
| * 54d0d83a53 hrtimers: Push pending hrtimers away from outgoing CPU earlier
* | 096ff6ecb4 Revert "HID: core: store the unique system identifier in hid_device"
* | 68c9c64f02 Revert "HID: fix HID device resource race between HID core and debugging support"
* | 0780b1ab09 Merge 5.4.263 into android11-5.4-lts
|\|
| * 34244ed621 Linux 5.4.263
| * afa7b11ea8 mmc: block: Retry commands in CQE error recovery
| * c8008304db mmc: core: convert comma to semicolon
| * 33cc97d249 mmc: cqhci: Fix task clearing in CQE error recovery
| * 3e78540d98 mmc: cqhci: Warn of halt or task clear failure
| * 5b87f35546 mmc: cqhci: Increase recovery halt timeout
| * 1a051c6d15 cpufreq: imx6q: Don't disable 792 Mhz OPP unnecessarily
| * d497e1b2f5 cpufreq: imx6q: don't warn for disabling a non-existing frequency
| * b1a66a050f scsi: qla2xxx: Fix system crash due to bad pointer access
| * c1f97cc21e scsi: qla2xxx: Use scsi_cmd_to_rq() instead of scsi_cmnd.request
| * df0110425f scsi: core: Introduce the scsi_cmd_to_rq() function
| * 66cd605530 scsi: qla2xxx: Simplify the code for aborting SCSI commands
| * 30511f37c9 ima: detect changes to the backing overlay file
| * 8c85e455f7 ovl: skip overlayfs superblocks at global sync
| * 157c8056ab ima: annotate iint mutex to avoid lockdep false positive warnings
| * a8038ae581 fbdev: stifb: Make the STI next font pointer a 32-bit signed offset
| * 939012ee31 mtd: cfi_cmdset_0001: Byte swap OTP info
| * 416dad018e mtd: cfi_cmdset_0001: Support the absence of protection registers
| * 21ad8c1c4f s390/cmma: fix detection of DAT pages
| * c11027d333 s390/mm: fix phys vs virt confusion in mark_kernel_pXd() functions family
| * f1db39b154 smb3: fix touch -h of symlink
| * 97d54b8005 net: ravb: Start TX queues after HW initialization succeeded
| * 7023a293e9 net: ravb: Use pm_runtime_resume_and_get()
| * 05aa8f3e3b ravb: Fix races between ravb_tx_timeout_work() and net related ops
| * d37609b529 net: stmmac: xgmac: Disable FPE MMC interrupts
| * 7ccf772a8b ipv4: igmp: fix refcnt uaf issue when receiving igmp query packet
| * f8b5b5d236 Input: xpad - add HyperX Clutch Gladiate Support
| * 6536698eea btrfs: make error messages more clear when getting a chunk map
| * 4c6274cfd6 btrfs: send: ensure send_fd is writable
| * 79ffc04aba btrfs: fix off-by-one when checking chunk map includes logical address
| * dd94ffab1b btrfs: add dmesg output for first mount and last unmount of a filesystem
| * 30b807d736 powerpc: Don't clobber f0/vs0 during fp|altivec register save
| * bb55decee2 bcache: revert replacing IS_ERR_OR_NULL with IS_ERR
| * 729da56e01 dm verity: don't perform FEC for failed readahead IO
| * b515ed6284 dm-verity: align struct dm_verity_fec_io properly
| * d377e593d1 ALSA: hda/realtek: Add supported ALC257 for ChromeOS
| * 47dd3917c4 ALSA: hda/realtek: Headset Mic VREF to 100%
| * 88ce27f0a3 ALSA: hda: Disable power-save on KONTRON SinglePC
| * 4a2d1399f8 mmc: block: Do not lose cache flush during CQE error recovery
| * 4d7d14c696 firewire: core: fix possible memory leak in create_units()
| * 1eaa188f7f pinctrl: avoid reload of p state in list iteration
| * 40532b2913 io_uring: fix off-by one bvec index
| * 9e7f410f6a USB: dwc3: qcom: fix wakeup after probe deferral
| * db62d193e6 USB: dwc3: qcom: fix resource leaks on probe deferral
| * ca44455362 usb: dwc3: set the dma max_seg_size
| * 7a0b6fc6c3 USB: dwc2: write HCINT with INTMASK applied
| * d1c866356d USB: serial: option: don't claim interface 4 for ZTE MF290
| * 38233a62d3 USB: serial: option: fix FM101R-GL defines
| * 83be9405b3 USB: serial: option: add Fibocom L7xx modules
| * 406fae6c79 bcache: prevent potential division by zero error
| * c00163256a bcache: check return value from btree_node_alloc_replacement()
| * a658ee7930 dm-delay: fix a race between delay_presuspend and delay_bio
| * ef918a1ba4 hv_netvsc: Mark VF as slave before exposing it to user-mode
| * 997d895fa4 hv_netvsc: Fix race of register_netdevice_notifier and VF register
| * f2a0c988d7 USB: serial: option: add Luat Air72*U series products
| * f1ac778940 s390/dasd: protect device queue against concurrent access
| * 300e96e171 bcache: replace a mistaken IS_ERR() by IS_ERR_OR_NULL() in btree_gc_coalesce()
| * 76f791b78d ACPI: resource: Skip IRQ override on ASUS ExpertBook B1402CVA
| * 78c1e3aa69 KVM: arm64: limit PMU version to PMUv3 for ARMv8.1
| * 5d4f6d809e arm64: cpufeature: Extract capped perfmon fields
| * 32cfd5c3b8 ext4: make sure allocate pending entry not fail
| * 70edeedd79 ext4: fix slab-use-after-free in ext4_es_insert_extent()
| * 15a84cf4c7 ext4: using nofail preallocation in ext4_es_insert_extent()
| * 80c8dcb09f ext4: using nofail preallocation in ext4_es_insert_delayed_block()
| * be4684ee83 ext4: using nofail preallocation in ext4_es_remove_extent()
| * d809d1d2ed ext4: use pre-allocated es in __es_remove_extent()
| * 059722ec64 ext4: use pre-allocated es in __es_insert_extent()
| * 53df96011a ext4: factor out __es_alloc_extent() and __es_free_extent()
| * c48b5fdd46 ext4: add a new helper to check if es must be kept
| * b9cd5c3afc MIPS: KVM: Fix a build warning about variable set but not used
| * afbedd6136 nvmet: nul-terminate the NQNs passed in the connect command
| * 84ac94bed0 nvmet: remove unnecessary ctrl parameter
| * 07009245d3 afs: Fix file locking on R/O volumes to operate in local mode
| * 54ffe881d7 afs: Return ENOENT if no cell DNS record can be found
| * 3680d10b41 net: axienet: Fix check for partial TX checksum
| * a7e7b92804 amd-xgbe: propagate the correct speed and duplex status
| * c3a77c754e amd-xgbe: handle the corner-case during tx completion
| * 895f1903ea amd-xgbe: handle corner-case during sfp hotplug
| * 7fabd97a05 arm/xen: fix xen_vcpu_info allocation alignment
| * 9beba93f8c net: usb: ax88179_178a: fix failed operations during ax88179_reset
| * fc23517c87 ipv4: Correct/silence an endian warning in __ip_do_redirect
| * 6fd145351d HID: fix HID device resource race between HID core and debugging support
| * 2c8f796104 HID: core: store the unique system identifier in hid_device
| * 90b3df8b5b drm/rockchip: vop: Fix color for RGB888/BGR888 format on VOP full
| * bfdda8c9c5 ata: pata_isapnp: Add missing error check for devm_ioport_map()
| * 9d980808f9 drm/panel: simple: Fix Innolux G101ICE-L01 timings
| * cc543bad78 drm/panel: simple: Fix Innolux G101ICE-L01 bus flags
| * c2eadc1586 afs: Make error on cell lookup failure consistent with OpenAFS
| * 7369371bb8 PCI: keystone: Drop __init from ks_pcie_add_pcie_{ep,port}()
| * 518b7f7d87 RDMA/irdma: Prevent zero-length STAG registration
| * d359886a7a driver core: Release all resources during unbind before updating device links
* | a0f28e56bc ANDROID: GKI: db845c: Update symbols list and ABI on rpmsg_register_device_override
* | 69365d1ade Revert "tracing: Have trace_event_file have ref counters"
* |   288ce21693 Merge "Merge 5.4.262 into android11-5.4-lts" into android11-5.4-lts
|\ \
| * | a3aeec7ab8 Merge 5.4.262 into android11-5.4-lts
| |\|
| | * 8e221b4717 Linux 5.4.262
| | * b053223b7c netfilter: nf_tables: bogus EBUSY when deleting flowtable after flush (for 5.4)
| | * c35df8b8c5 netfilter: nf_tables: disable toggling dormant table state more than once
| | * e10f661adc netfilter: nf_tables: fix table flag updates
| | * 46c2947fcd netfilter: nftables: update table flags from the commit phase
| | * b09e6ccf0d netfilter: nf_tables: double hook unregistration in netns path
| | * b05a24cc45 netfilter: nf_tables: unregister flowtable hooks on netns exit
| | * a995a68e8a netfilter: nf_tables: fix memleak when more than 255 elements expired
| | * b95d7af657 netfilter: nft_set_hash: try later when GC hits EAGAIN on iteration
| | * 61a7b3de20 netfilter: nft_set_rbtree: use read spinlock to avoid datapath contention
| | * 03caf75da1 netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction
| | * 021d734c7e netfilter: nf_tables: defer gc run if previous batch is still pending
| | * 38ed6a5f83 netfilter: nf_tables: use correct lock to protect gc_list
| | * 4b6346dc1e netfilter: nf_tables: GC transaction race with abort path
| | * b76dcf4662 netfilter: nf_tables: GC transaction race with netns dismantle
| | * 29ff9b8efb netfilter: nf_tables: fix GC transaction races with netns and netlink event exit path
| | * 1398a0eee2 netfilter: nf_tables: remove busy mark and gc batch API
| | * 85520a1f1d netfilter: nft_set_hash: mark set element as dead when deleting from packet path
| | * c357648929 netfilter: nf_tables: adapt set backend to use GC transaction API
| | * bbdb3b65aa netfilter: nf_tables: GC transaction API to avoid race with control plane
| | * 1da4874d05 netfilter: nf_tables: don't skip expired elements during walk
| | * acaee227cf netfilter: nft_set_rbtree: fix overlap expiration walk
| | * 899aa56385 netfilter: nft_set_rbtree: fix null deref on element insertion
| | * 181859bdfb netfilter: nft_set_rbtree: Switch to node list walk for overlap detection
| | * 3c7ec098e3 netfilter: nf_tables: drop map element references from preparation phase
| | * 6b880f3b2c netfilter: nftables: rename set element data activation/deactivation functions
| | * e1eed9e0b5 netfilter: nf_tables: pass context to nft_set_destroy()
| | * 961c4511c7 tracing: Have trace_event_file have ref counters
| | * 7676a41d90 drm/amdgpu: fix error handling in amdgpu_bo_list_get()
| | * 36383005f1 ext4: remove gdb backup copy for meta bg in setup_new_flex_group_blocks
| | * e95f74653d ext4: correct the start block of counting reserved clusters
| | * 1fbfdcc3d6 ext4: correct return value of ext4_convert_meta_bg
| | * dfdfd3f218 ext4: correct offset of gdb backup in non meta_bg group to update_backups
| | * 85c12e80c4 ext4: apply umask if ACL support is disabled
| | * d2aed8814f Revert "net: r8169: Disable multicast filter for RTL8168H and RTL8107E"
| | * b9e5f633b3 nfsd: fix file memleak on client_opens_release
| | * 339d7d40d3 media: venus: hfi: add checks to handle capabilities from firmware
| | * cab97cdd40 media: venus: hfi: fix the check to handle session buffer requirement
| | * 5d39d0c1f4 media: venus: hfi_parser: Add check to keep the number of codecs within range
| | * 497b12d47c media: sharp: fix sharp encoding
| | * 92d8a0478f media: lirc: drop trailing space from scancode transmit
| | * cac054d103 i2c: i801: fix potential race in i801_block_transaction_byte_by_byte
| | * b132e46236 net: dsa: lan9303: consequently nested-lock physical MDIO
| | * 229738d717 Revert ncsi: Propagate carrier gain/loss events to the NCSI controller
| | * 4074957ec6 Bluetooth: btusb: Add 0bda:b85b for Fn-Link RTL8852BE
| | * 356a2ee5fc Bluetooth: btusb: Add RTW8852BE device 13d3:3570 to device tables
| | * afe92b66a5 bluetooth: Add device 13d3:3571 to device tables
| | * dc073a2626 bluetooth: Add device 0bda:887b to device tables
| | * 75d26f7f61 Bluetooth: btusb: Add Realtek RTL8852BE support ID 0x0cb8:0xc559
| | * 323710a6b4 Bluetooth: btusb: add Realtek 8822CE to usb_device_id table
| | * 981ee23b8d Bluetooth: btusb: Add flag to define wideband speech capability
| | * 0fe69c99cc tty: serial: meson: fix hard LOCKUP on crtscts mode
| | * 8f40bbf7dc serial: meson: Use platform_get_irq() to get the interrupt
| | * a1113f2c9b tty: serial: meson: retrieve port FIFO size from DT
| | * 13391526d8 serial: meson: remove redundant initialization of variable id
| | * 6245d0d70f ALSA: hda/realtek - Enable internal speaker of ASUS K6500ZC
| | * 4ef452297d ALSA: info: Fix potential deadlock at disconnection
| | * c7df9523fe parisc/pgtable: Do not drop upper 5 address bits of physical address
| | * c32dfec867 parisc: Prevent booting 64-bit kernels on PA1.x machines
| | * d570d139cb i3c: master: cdns: Fix reading status register
| | * ad6941b192 mm/cma: use nth_page() in place of direct struct page manipulation
| | * 3651286660 dmaengine: stm32-mdma: correct desc prep when channel running
| | * 4a5c267d57 mcb: fix error handling for different scenarios when parsing
| | * 25eb381a73 i2c: core: Run atomic i2c xfer when !preemptible
| | * 975b5ff33f kernel/reboot: emergency_restart: Set correct system_state
| | * 421f9ccc75 quota: explicitly forbid quota files from being encrypted
| | * 7d0c36cd2e jbd2: fix potential data lost in recovering journal raced with synchronizing fs bdev
| | * 665c2f186b btrfs: don't arbitrarily slow down delalloc if we're committing
| | * b5a8382cf8 PM: hibernate: Clean up sync_read handling in snapshot_write_next()
| | * 2b3cfdaa88 PM: hibernate: Use __get_safe_page() rather than touching the list
| | * 612c17a90f mmc: vub300: fix an error code
| | * 398940412e clk: qcom: ipq8074: drop the CLK_SET_RATE_PARENT flag from PLL clocks
| | * 0b2b22b706 parisc/pdc: Add width field to struct pdc_model
| | * 012dba0ab8 PCI: keystone: Don't discard .probe() callback
| | * 9988c9dc3c PCI: keystone: Don't discard .remove() callback
| | * a438322e00 genirq/generic_chip: Make irq_remove_generic_chip() irqdomain aware
| | * 683c562c43 mmc: meson-gx: Remove setting of CMD_CFG_ERROR
| | * d894f9288c ACPI: resource: Do IRQ override on TongFang GMxXGxx
| | * 7b15bc9b75 PCI/sysfs: Protect driver's D3cold preference from user space
| | * 78d3487b5b hvc/xen: fix error path in xen_hvc_init() to always register frontend driver
| | * 6b21ae025b audit: don't WARN_ON_ONCE(!current->mm) in audit_exe_compare()
| | * c0d01f03aa audit: don't take task_lock() in audit_exe_compare() code path
| | * 4d0a828775 KVM: x86: Ignore MSR_AMD64_TW_CFG access
| | * 5066faedd2 KVM: x86: hyper-v: Don't auto-enable stimer on write from user-space
| | * 268d17ab63 x86/cpu/hygon: Fix the CPU topology evaluation for real
| | * acbc12b0b3 scsi: megaraid_sas: Increase register read retry rount from 3 to 30 for selected registers
| | * bae6905103 bpf: Fix precision tracking for BPF_ALU | BPF_TO_BE | BPF_END
| | * 6933bc9a5f randstruct: Fix gcc-plugin performance mode to stay in group
| | * c94d05ac69 media: venus: hfi: add checks to perform sanity on queue pointers
| | * 6d028ade9d cifs: spnego: add ';' in HOST_KEY_LEN
| | * 26415e35f6 tools/power/turbostat: Fix a knl bug
| | * a49786297b macvlan: Don't propagate promisc change to lower dev in passthru
| | * 04cb9ab8eb net/mlx5e: Check return value of snprintf writing to fw_version buffer for representors
| | * c740f4716a net/mlx5_core: Clean driver version and name
| | * e4bdbcce8e net/mlx5e: fix double free of encap_header
| | * 5cc1f24f73 net: stmmac: fix rx budget limit check
| | * c4b712d1a8 net: stmmac: Rework stmmac_rx()
| | * b2762d13df netfilter: nf_conntrack_bridge: initialize err to 0
| | * fd51e7541f net: ethernet: cortina: Fix MTU max setting
| | * 823bffdaac net: ethernet: cortina: Handle large frames
| | * f5055d7345 net: ethernet: cortina: Fix max RX frame define
| | * b4f0e605a5 bonding: stop the device in bond_setup_by_slave()
| | * 7ea0a719e5 ptp: annotate data-race around q->head and q->tail
| | * 89af55e0fa xen/events: fix delayed eoi list handling
| | * db957a2f54 ppp: limit MRU to 64K
| | * f3b250d919 tipc: Fix kernel-infoleak due to uninitialized TLV value
| | * 77236275d4 net: hns3: fix variable may not initialized problem in hns3_init_mac_addr()
| | * 14c6cd41c8 tty: Fix uninit-value access in ppp_sync_receive()
| | * 4d2d30f079 ipvlan: add ipvlan_route_v6_outbound() helper
| | * ed53c15188 NFSv4.1: fix SP4_MACH_CRED protection for pnfs IO
| | * fe449f8b97 wifi: iwlwifi: Use FW rate for non-data frames
| | * eca19db60f pwm: Fix double shift bug
| | * d996530ba9 ASoC: ti: omap-mcbsp: Fix runtime PM underflow warnings
| | * 6d703922bc kgdb: Flush console before entering kgdb on panic
| | * eac3e4760a drm/amd/display: Avoid NULL dereference of timing generator
| | * 514565ff7f media: cobalt: Use FIELD_GET() to extract Link Width
| | * 2bb42a27a9 gfs2: ignore negated quota changes
| | * a251e20a2c media: vivid: avoid integer overflow
| | * 8f83c85ee8 media: gspca: cpia1: shift-out-of-bounds in set_flicker
| | * a8f829886d i2c: sun6i-p2wi: Prevent potential division by zero
| | * 80876a07ca usb: gadget: f_ncm: Always set current gadget in ncm_bind()
| | * 460284dfb1 tty: vcc: Add check for kstrdup() in vcc_probe()
| | * 35b9435123 HID: Add quirk for Dell Pro Wireless Keyboard and Mouse KM5221W
| | * b549acf999 scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup()
| | * 33906b36b1 atm: iphase: Do PCI error checks on own line
| | * 54f4dde8fa PCI: tegra194: Use FIELD_GET()/FIELD_PREP() with Link Width fields
| | * 2527775616 ALSA: hda: Fix possible null-ptr-deref when assigning a stream
| | * 953ed26a77 ARM: 9320/1: fix stack depot IRQ stack filter
| | * 7467ca10a5 jfs: fix array-index-out-of-bounds in diAlloc
| | * ecfb47f13b jfs: fix array-index-out-of-bounds in dbFindLeaf
| | * 32bd8f1cbc fs/jfs: Add validity check for db_maxag and db_agpref
| | * a81a56b4cb fs/jfs: Add check for negative db_l2nbperpage
| | * e18d266fb3 RDMA/hfi1: Use FIELD_GET() to extract Link Width
| | * c9c1334697 crypto: pcrypt - Fix hungtask for PADATA_RESET
| | * ddd6e52663 selftests/efivarfs: create-read: fix a resource leak
| | * 437e0fa907 drm/amdgpu: Fix a null pointer access when the smc_rreg pointer is NULL
| | * d50a56749e drm/amd: Fix UBSAN array-index-out-of-bounds for Polaris and Tonga
| | * c847379a5d drm/amd: Fix UBSAN array-index-out-of-bounds for SMU7
| | * 1f24c286f4 drm/komeda: drop all currently held locks if deadlock happens
| | * 5305ae0d4a platform/x86: thinkpad_acpi: Add battery quirk for Thinkpad X120e
| | * 3c4236f1b2 Bluetooth: Fix double free in hci_conn_cleanup
| | * 3cf391e417 wifi: ath10k: Don't touch the CE interrupt registers after power up
| | * 252bde6b17 net: annotate data-races around sk->sk_dst_pending_confirm
| | * 73909810ac net: annotate data-races around sk->sk_tx_queue_mapping
| | * bd653b0709 wifi: ath10k: fix clang-specific fortify warning
| | * 32cc96dc5f wifi: ath9k: fix clang-specific fortify warnings
| | * efeae5f497 wifi: mac80211: don't return unset power in ieee80211_get_tx_power()
| | * 770da15be3 wifi: mac80211_hwsim: fix clang-specific fortify warning
| | * cfe13e1486 x86/mm: Drop the 4 MB restriction on minimal NUMA node memory size
| | * 91f7467ac9 clocksource/drivers/timer-atmel-tcb: Fix initialization on SAM9 hardware
| | * da667a3f8e clocksource/drivers/timer-imx-gpt: Fix potential memory leak
| | * 788c0b3442 perf/core: Bail out early if the request AUX area is out of bound
| | * dcd85e3c92 locking/ww_mutex/test: Fix potential workqueue corruption
* | | 4e4cce8b5a Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
|/ /
* | 12bc15efbc Revert "inet: shrink struct flowi_common"
* | 8d8014e4a1 Revert "ipvlan: properly track tx_errors"
* | 0e07b7bd3c Merge 5.4.261 into android11-5.4-lts
|\|
| * ef379773e2 Linux 5.4.261
| * 3542ef5c37 btrfs: use u64 for buffer sizes in the tree search ioctls
| * 7868e6151a Revert "mmc: core: Capture correct oemid-bits for eMMC cards"
| * 7be3aca8d7 fbdev: fsl-diu-fb: mark wr_reg_wa() static
| * 6c66d737b2 fbdev: imsttfb: fix a resource leak in probe
| * b90c8dfd71 fbdev: imsttfb: Fix error path of imsttfb_probe()
| * 4a6a3f1b38 spi: spi-zynq-qspi: add spi-mem to driver kconfig dependencies
| * 157333513d drm/syncobj: fix DRM_SYNCOBJ_WAIT_FLAGS_WAIT_AVAILABLE
| * 21858a75dc netfilter: nat: fix ipv6 nat redirect with mapped and scoped addresses
| * ae99c5e16a netfilter: nft_redir: use `struct nf_nat_range2` throughout and deduplicate eval call-backs
| * 11380557c2 netfilter: xt_recent: fix (increase) ipv6 literal buffer length
| * cce1d46681 r8169: respect userspace disabling IFF_MULTICAST
| * e820e23338 tg3: power down device only on SYSTEM_POWER_OFF
| * f8065cde49 net/smc: fix dangling sock under state SMC_APPFINCLOSEWAIT
| * 592f934b7a net: stmmac: xgmac: Enable support for multiple Flexible PPS outputs
| * 85513df59a Fix termination state for idr_for_each_entry_ul()
| * 56cddb5e65 net: r8169: Disable multicast filter for RTL8168H and RTL8107E
| * e5a664ef49 dccp/tcp: Call security_inet_conn_request() after setting IPv6 addresses.
| * 3af0af2f98 dccp: Call security_inet_conn_request() after setting IPv4 addresses.
| * afa49774d8 inet: shrink struct flowi_common
| * 2199260c42 tipc: Change nla_policy for bearer-related names to NLA_NUL_STRING
| * cbdcdf42d1 llc: verify mac len before reading mac header
| * 50d1225366 Input: synaptics-rmi4 - fix use after free in rmi_unregister_function()
| * e3677bfcbb pwm: brcmstb: Utilize appropriate clock APIs in suspend/resume
| * 6e9b529589 pwm: sti: Reduce number of allocations and drop usage of chip_data
| * 19e45307f7 pwm: sti: Avoid conditional gotos
| * c4d5179e42 regmap: prevent noinc writes from clobbering cache
| * d62d868b30 media: dvb-usb-v2: af9035: fix missing unlock
| * 7843a9bfbe media: s3c-camif: Avoid inappropriate kfree()
| * b35fdade92 media: bttv: fix use after free error due to btv->timeout timer
| * 0bc0e36fcc pcmcia: ds: fix possible name leak in error path in pcmcia_device_add()
| * 1502edd4a0 pcmcia: ds: fix refcount leak in pcmcia_device_add()
| * 58d6fb6a93 pcmcia: cs: fix possible hung task and memory leak pccardd()
| * 37212eede6 rtc: pcf85363: fix wrong mask/val parameters in regmap_update_bits call
| * 204beeb509 i3c: Fix potential refcount leak in i3c_master_register_new_i3c_devs
| * 247ed618f5 powerpc/pseries: fix potential memory leak in init_cpu_associativity()
| * cee681d4b2 powerpc/imc-pmu: Use the correct spinlock initializer.
| * dc5804b47b powerpc/xive: Fix endian conversion size
| * b6cffe8dd7 modpost: fix tee MODULE_DEVICE_TABLE built on big-endian host
| * 90ab33735e f2fs: fix to initialize map.m_pblk in f2fs_precache_extents()
| * 9f20b06214 dmaengine: pxa_dma: Remove an erroneous BUG_ON() in pxad_free_desc()
| * 688326e2cf USB: usbip: fix stub_dev hub disconnect
| * b003b7a7d4 tools: iio: iio_generic_buffer ensure alignment
| * 7a64d15db7 tools: iio: iio_generic_buffer: Fix some integer type and calculation
| * db6d5b9ff6 tools: iio: privatize globals and functions in iio_generic_buffer.c file
| * 55b90e4c40 misc: st_core: Do not call kfree_skb() under spin_lock_irqsave()
| * ed9b2ad3b9 dmaengine: ti: edma: handle irq_of_parse_and_map() errors
| * 64c47749fc usb: dwc2: fix possible NULL pointer dereference caused by driver concurrency
| * 4050f13f71 tty: tty_jobctrl: fix pid memleak in disassociate_ctty()
| * ba46faaa49 leds: trigger: ledtrig-cpu:: Fix 'output may be truncated' issue for 'cpu'
| * abfd682fc5 ledtrig-cpu: Limit to 8 CPUs
| * f6c3b7a4ce leds: pwm: Don't disable the PWM when the LED should be off
| * cd6f50115f leds: pwm: convert to atomic PWM API
| * 9686f771c0 leds: pwm: simplify if condition
| * 87b1ee831d mfd: dln2: Fix double put in dln2_probe
| * b843d2cd13 ASoC: ams-delta.c: use component after check
| * 4634c9cc72 ASoC: Intel: Skylake: Fix mem leak when parsing UUIDs fails
| * 66888e6953 sh: bios: Revive earlyprintk support
| * fdcbe9ce7b RDMA/hfi1: Workaround truncation compilation error
| * 01698922f5 scsi: ufs: core: Leave space for '\0' in utf8 desc string
| * 3c61391a31 ext4: move 'ix' sanity check to corrent position
| * 454e6493bb ARM: 9321/1: memset: cast the constant byte to unsigned char
| * 727203e6e7 hid: cp2112: Fix duplicate workqueue initialization
| * 48bb2931f2 HID: cp2112: Use irqchip template
| * 7b62cf90d0 crypto: caam/jr - fix Chacha20 + Poly1305 self test failure
| * 090e89c716 crypto: caam/qi2 - fix Chacha20 + Poly1305 self test failure
| * 40ba3fa212 nd_btt: Make BTT lanes preemptible
| * 68655462f8 sched/rt: Provide migrate_disable/enable() inlines
| * d14a373fe5 libnvdimm/of_pmem: Use devm_kstrdup instead of kstrdup and check its return value
| * f5d95a3968 hwrng: geode - fix accessing registers
| * e4e4d4abb8 clk: scmi: Free scmi_clk allocated when the clocks with invalid info are skipped
| * ce11e445d0 firmware: ti_sci: Mark driver as non removable
| * 5d97cc0b49 firmware: ti_sci: Replace HTTP links with HTTPS ones
| * cc1a1dcb41 soc: qcom: llcc: Handle a second device without data corruption
| * 813fdddde2 soc: qcom: Rename llcc-slice to llcc-qcom
| * 077010717b soc: qcom: llcc cleanup to get rid of sdm845 specific driver file
| * 3da50ee512 ARM: dts: qcom: mdm9615: populate vsdcc fixed regulator
| * 6b464d9414 arm64: dts: qcom: sdm845-mtp: fix WiFi configuration
| * 64d9900860 drm/rockchip: cdn-dp: Fix some error handling paths in cdn_dp_probe()
| * ddc42881f1 drm/radeon: possible buffer overflow
| * 4a29f0f7a1 drm/rockchip: vop: Fix call to crtc reset helper
| * 824f0f4f93 drm/rockchip: vop: Fix reset of state in duplicate state crtc funcs
| * eaf62ea650 hwmon: (coretemp) Fix potentially truncated sysfs attribute name
| * 9fb0eed09e platform/x86: wmi: Fix opening of char device
| * 22117b77ee platform/x86: wmi: remove unnecessary initializations
| * 1607ea8a81 platform/x86: wmi: Fix probe failure when failing to register WMI devices
| * d1461f0c9c clk: mediatek: clk-mt2701: Add check for mtk_alloc_clk_data
| * e8ae4b49dd clk: mediatek: clk-mt7629: Add check for mtk_alloc_clk_data
| * cfa68e0ac5 clk: mediatek: clk-mt7629-eth: Add check for mtk_alloc_clk_data
| * 2705c5b97f clk: mediatek: clk-mt6797: Add check for mtk_alloc_clk_data
| * fbe466f06d clk: mediatek: clk-mt6779: Add check for mtk_alloc_clk_data
| * 8ae911637b clk: npcm7xx: Fix incorrect kfree
| * cbcf67b0bc clk: keystone: pll: fix a couple NULL vs IS_ERR() checks
| * 3d38bc4bab clk: imx: Select MXC_CLK for CLK_IMX8QXP
| * ae98b5ef99 clk: qcom: gcc-sm8150: Fix gcc_sdcc2_apps_clk_src
| * 15f335494b clk: qcom: gcc-sm8150: use ARRAY_SIZE instead of specifying num_parents
| * 141ccc1272 clk: qcom: clk-rcg2: Fix clock rate overflow for high parent frequencies
| * dbf13624b2 regmap: debugfs: Fix a erroneous check after snprintf()
| * af50165c12 ipvlan: properly track tx_errors
| * 76304c749e net: add DEV_STATS_READ() helper
| * 4482b250c8 ipv6: avoid atomic fragment on GSO packets
| * 19d5273378 ACPI: sysfs: Fix create_pnp_modalias() and create_of_modalias()
| * 5105d46146 tcp: fix cookie_init_timestamp() overflows
| * e4e819bdc8 tcp: Remove one extra ktime_get_ns() from cookie_init_timestamp
| * 7ab8aa7300 chtls: fix tp->rcv_tstamp initialization
| * 75bbf6e934 r8169: fix rare issue with broken rx after link-down on RTL8125
| * 282342bc47 r8169: use tp_to_dev instead of open code
| * 3091ab943d thermal: core: prevent potential string overflow
| * 35854733ae can: dev: can_restart(): fix race condition between controller restart and netif_carrier_on()
| * b53be254d3 can: dev: can_restart(): don't crash kernel if carrier is OK
| * a29f012a27 wifi: rtlwifi: fix EDCA limit set by BT coexistence
| * bed72a332f tcp_metrics: do not create an entry from tcp_init_metrics()
| * f3902c0e6f tcp_metrics: properly set tp->snd_ssthresh in tcp_init_metrics()
| * b78f2b7774 tcp_metrics: add missing barriers on delete
| * af0fe2c2ff wifi: mt76: mt7603: rework/fix rx pse hang check
| * a2e99dbdc1 wifi: rtw88: debug: Fix the NULL vs IS_ERR() bug for debugfs_create_file()
| * c9b929f793 tcp: call tcp_try_undo_recovery when an RTOd TFO SYNACK is ACKed
| * 25eaef1d0d i40e: fix potential memory leaks in i40e_remove()
| * 09ce728c9e genirq/matrix: Exclude managed interrupts in irq_matrix_allocated()
| * 3718a48ef4 vfs: fix readahead(2) on block devices
* | 0443350950 ANDROID: fix up rpmsg_device ABI break
* | 398b357f13 ANDROID: fix up platform_device ABI break
* | 7b96d6414a Merge 5.4.260 into android11-5.4-lts
|/
* 87e8e7a7aa Linux 5.4.260
* 8b0ecf2167 tty: 8250: Add support for Intashield IS-100
* 6dd5561b23 tty: 8250: Add support for Brainboxes UP cards
* 03145e0ff8 tty: 8250: Add support for additional Brainboxes UC cards
* 5a6471372f tty: 8250: Remove UC-257 and UC-431
* 72f236b57f usb: storage: set 1.50 as the lower bcdDevice for older "Super Top" compatibility
* 792a91fcd2 PCI: Prevent xHCI driver from claiming AMD VanGogh USB3 DRD device
* 4b865e0d78 Revert "ARM: dts: Move am33xx and am43xx mmc nodes to sdhci-omap driver"
* 4e53bab11f nvmet-tcp: Fix a possible UAF in queue intialization setup
* 2c9415ec8e nvmet-tcp: move send/recv error handling in the send/recv methods instead of call-sites
* 784ef618b2 remove the sx8 block driver
* a31f8222a7 ata: ahci: fix enum constants for gcc-13
* cc1afa62e2 net: chelsio: cxgb4: add an error code check in t4_load_phy_fw
* 7e429d1f39 platform/mellanox: mlxbf-tmfifo: Fix a warning message
* 5f4f58eac3 platform/x86: asus-wmi: Change ASUS_WMI_BRN_DOWN code from 0x20 to 0x2e
* 88d1aa03eb scsi: mpt3sas: Fix in error path
* b1f62e3ef9 fbdev: uvesafb: Call cn_del_callback() at the end of uvesafb_exit()
* fb02de6479 ASoC: rt5650: fix the wrong result of key button
* b6c09ff5ea netfilter: nfnetlink_log: silence bogus compiler warning
* 6c23b6d308 spi: npcm-fiu: Fix UMA reads when dummy.nbytes == 0
* 788b308340 fbdev: atyfb: only use ioremap_uc() on i386 and ia64
* 848b9c6888 Input: synaptics-rmi4 - handle reset delay when using SMBus trsnsport
* a0bf183db4 dmaengine: ste_dma40: Fix PM disable depth imbalance in d40_probe
* 39ae053abb irqchip/stm32-exti: add missing DT IRQ flag translation
* fbcd05a0db Input: i8042 - add Fujitsu Lifebook E5411 to i8042 quirk table
* cda248f169 x86: Fix .brk attribute in linker script
* 01e6885b75 rpmsg: Fix possible refcount leak in rpmsg_register_device_override()
* cff56d7a92 rpmsg: glink: Release driver_override
* 3d14785980 rpmsg: Fix calling device_lock() on non-initialized device
* e70898ae1a rpmsg: Fix kfree() of static memory on setting driver_override
* 0df5d80135 rpmsg: Constify local variable in field store macro
* 063444d66f driver: platform: Add helper for safer setting of driver_override
* 83ecffd40c ext4: fix BUG in ext4_mb_new_inode_pa() due to overflow
* 66cfd4cf6a ext4: avoid overlapping preallocations due to overflow
* 1e0a5dec26 ext4: add two helper functions extent_logical_end() and pa_logical_end()
* c2102ac103 x86/mm: Fix RESERVE_BRK() for older binutils
* ced79d864b x86/mm: Simplify RESERVE_BRK()
* 5fc242c118 nfsd: lock_rename() needs both directories to live on the same fs
* e9a988cd4c f2fs: fix to do sanity check on inode type during garbage collection
* 750de03de7 smbdirect: missing rc checks while waiting for rdma events
* 5776aeee2a kobject: Fix slab-out-of-bounds in fill_kobj_path()
* 0a45e0e5dd arm64: fix a concurrency issue in emulation_proc_handler()
* 6ba2ffe3cb drm/dp_mst: Fix NULL deref in get_mst_branch_device_by_guid_helper()
* 9d29933f36 x86/i8259: Skip probing when ACPI/MADT advertises PCAT compatibility
* 1ed21b207e i40e: Fix wrong check for I40E_TXR_FLAGS_WB_ON_ITR
* f48670c3b0 clk: Sanitize possible_parent_show to Handle Return Value of of_clk_get_parent_name
* 511f3e9bbb perf/core: Fix potential NULL deref
* 8de78231cb nvmem: imx: correct nregs for i.MX6UL
* 0b2c3a8601 nvmem: imx: correct nregs for i.MX6SLL
* 6063678df7 nvmem: imx: correct nregs for i.MX6ULL
* 12337d3e88 i2c: aspeed: Fix i2c bus hang in slave read
* e3d8ef87a9 i2c: stm32f7: Fix PEC handling in case of SMBUS transfers
* 5764f6e546 i2c: muxes: i2c-demux-pinctrl: Use of_get_i2c_adapter_by_node()
* a3b9bcedd7 i2c: muxes: i2c-mux-gpmux: Use of_get_i2c_adapter_by_node()
* 07ec3d952a i2c: muxes: i2c-mux-pinctrl: Use of_get_i2c_adapter_by_node()
* 519ff2d9fe iio: exynos-adc: request second interupt only when touchscreen mode is used
* 2bf9fbd136 gtp: fix fragmentation needed check with gso
* 2ab1b7ad50 gtp: uapi: fix GTPA_MAX
* 54ba3b8267 tcp: fix wrong RTO timeout when received SACK reneging
* 29cb3f81bc r8152: Cancel hw_phy_work if we have an error in probe
* 6124d0b100 r8152: Run the unload routine if we have errors during probe
* 1d3cb4aa93 r8152: Increase USB control msg timeout to 5000ms as per spec
* 2f8da95116 net: ieee802154: adf7242: Fix some potential buffer overflow in adf7242_stats_show()
* ec885679fa igc: Fix ambiguity in the ethtool advertising
* 3b098edafe neighbour: fix various data-races
* 418ca6e63e igb: Fix potential memory leak in igb_add_ethtool_nfc_entry
* 00ef4a7de6 treewide: Spelling fix in comment
* e44e78ff44 r8169: fix the KCSAN reported data race in rtl_rx while reading desc->opts1
* b9ba50fc18 r8169: fix the KCSAN reported data-race in rtl_tx while reading TxDescArray[entry].opts1
* a27c6bfc52 virtio-mmio: fix memory leak of vm_dev
* 8d394fcb03 virtio_balloon: Fix endless deflation and inflation on arm64
* be84e96426 mcb-lpc: Reallocate memory region to avoid memory overlapping
* 3235094d55 mcb: Return actual parsed size when reading chameleon table
* fbe17a8be1 selftests/ftrace: Add new test case which checks non unique symbol
* 4d057ca86e mtd: rawnand: marvell: Ensure program page operations are successful

Change-Id: I58a8cd7194465f27b5fde3af6e27010d4d4c543c
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-01-09 13:26:54 +00:00
Swetha Chikkaboraiah
40d06eb6f1 soc: qcom: socinfo: Add soc information for BLAIR LTE
Add SOC ID to support socinfo for BLAIR LTE platform.

Change-Id: I5223272ef20eac2396e52fa910628ec8236eb1ed
Signed-off-by: Swetha Chikkaboraiah <quic_schikk@quicinc.com>
2024-01-08 06:36:36 -08:00
Greg Kroah-Hartman
e2be513380 ANDROID: GKI: fix crc issue in include/net/addrconf.h
In commit 9354e0acdb ("net: ipv6: support reporting otherwise unknown
prefix flags in RTM_NEWPREFIX") a union is added to fix some issues, but
that messes with the crc of a number of networking symbols for obvious
reasons.  As this does not actually change the abi at all, use some
GENKSYMS magic #define logic to preserve the crc so that all is well.

Bug: 161946584
Fixes: 9354e0acdb ("net: ipv6: support reporting otherwise unknown prefix flags in RTM_NEWPREFIX")
Change-Id: I9d2df74e8f3ae60425534f1b33d50b2bc444f7f5
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-01-05 11:28:46 +00:00
qctecmdr
bd73268ecf Merge "qcom-dload-mode: Convert reboot notifier to restart notifier" 2024-01-04 03:54:14 -08:00
Greg Kroah-Hartman
3c4b111a71 Revert "cred: switch to using atomic_long_t"
This reverts commit be7676b03a which is
commit f8fa5d76925991976b3e7076f9d1052515ec1fca upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way.

Bug: 161946584
Bug: 317347552
Change-Id: I9eb52866bc3b2a9f02e3f7fbee0bacbcc06b0849
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-01-03 17:00:08 +00:00
Mukesh Ojha
52c3eb6f12 qcom-dload-mode: Convert reboot notifier to restart notifier
There could be chance of edl download mode written by qcom-dload-mode
driver overwritten by Scm device shutdown call as the reboot notifiers
gets called prior to device_shutdown in reboot path.

To fix this convert the reboot notifiers to restart notifiers and keep
its priority higher than scm restart handler so that warm reboot_mode
set here should be seen by SCM restart handler (priority 130).

Change-Id: I2daa41d04788e525f274323e9c815bf10cb79ed2
Signed-off-by: Mukesh Ojha <quic_mojha@quicinc.com>
Signed-off-by: Rohit Agarwal <quic_rohiagar@quicinc.com>
2024-01-03 15:44:34 +05:30
qctecmdr
f758f24d4d Merge "net: qrtr: smd: kfree svc_arr after use" 2023-12-26 03:12:21 -08:00
qctecmdr
b67a45b62a Merge "defconfig: sdxlemur: Enable minidump for sdxlemur" 2023-12-22 10:22:13 -08:00
Greg Kroah-Hartman
5158e9afed This is the 5.4.265 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmWC/R4ACgkQONu9yGCS
 aT6XRw/+OE/DwEAaRGgM/gGLayr/n6zJoL7DUhLxkS+wG3beQXFsdigCHRRhTh58
 OCQP6pL6UlbJ8Yge3FtpYqqkR+UyY7c/wsjJI05v7dKUJ742rpFNML9w0Dg9Au8w
 k4TsVU01nnr9HC7rY8k8zYZ/DZdULvIX8RNhSOi0CMO2gkdMUFrh/IC0q5JIWKmL
 xFmMieGtsr4kl4sP2oUbYihf1Li4oblouBV+70kPViC6XA0YhOSCT0+PfDxp5CuD
 sux1srZGY/782zI0O6+ObsYascwgL+wk0oEJRj1vO02tJKKbtEGMJvGO9Mcpto6B
 2YBq40PAhyeKFdt4YzOWCSO7WjvWP7h15U68EY+E6ruy9La+P/dTyhAqsBBTVDEs
 PGFIjxc5pnHn72JQ/U3yJoHFM7yW26VEmEGItsd81VermNgqe2scSPSPHIfM0qFU
 z2l0PcQkm+SLK2cFDSCBUBaXfx4R2UuWe/QY07K2eN5YCC4mqROajVh4Vqyj1Q8j
 PLw/yrt8lOJcDEDMtFq7hcXKMzcb/dYfCZcSfxl6YJeaR4X4ViOkDGVhLEkVeOn5
 K3kyIvPd268rmoy/9jTuDYu6axMhg2eE2dTQqBg8pFwIOgetUwtYcBhyxDtmGZm1
 lNUYmY84BSHZwXuKjNXGgZ5DI0U7nAWis+odR0scHpVKwaC8ta8=
 =d0Ht
 -----END PGP SIGNATURE-----

Merge 5.4.265 into android11-5.4-lts

Changes in 5.4.265
	afs: Fix refcount underflow from error handling race
	net: ipv6: support reporting otherwise unknown prefix flags in RTM_NEWPREFIX
	qca_debug: Prevent crash on TX ring changes
	qca_debug: Fix ethtool -G iface tx behavior
	qca_spi: Fix reset behavior
	atm: solos-pci: Fix potential deadlock on &cli_queue_lock
	atm: solos-pci: Fix potential deadlock on &tx_queue_lock
	atm: Fix Use-After-Free in do_vcc_ioctl
	net/rose: Fix Use-After-Free in rose_ioctl
	qed: Fix a potential use-after-free in qed_cxt_tables_alloc
	net: Remove acked SYN flag from packet in the transmit queue correctly
	sign-file: Fix incorrect return values check
	vsock/virtio: Fix unsigned integer wrap around in virtio_transport_has_space()
	net: stmmac: use dev_err_probe() for reporting mdio bus registration failure
	net: stmmac: Handle disabled MDIO busses from devicetree
	appletalk: Fix Use-After-Free in atalk_ioctl
	cred: switch to using atomic_long_t
	ALSA: hda/hdmi: add force-connect quirks for ASUSTeK Z170 variants
	Revert "PCI: acpiphp: Reassign resources on bridge if necessary"
	usb: aqc111: check packet for fixup for true limit
	blk-throttle: fix lockdep warning of "cgroup_mutex or RCU read lock required!"
	bcache: avoid oversize memory allocation by small stripe_size
	bcache: add code comments for bch_btree_node_get() and __bch_btree_node_alloc()
	bcache: avoid NULL checking to c->root in run_cache_set()
	platform/x86: intel_telemetry: Fix kernel doc descriptions
	HID: add ALWAYS_POLL quirk for Apple kb
	HID: hid-asus: reset the backlight brightness level on resume
	HID: multitouch: Add quirk for HONOR GLO-GXXX touchpad
	asm-generic: qspinlock: fix queued_spin_value_unlocked() implementation
	net: usb: qmi_wwan: claim interface 4 for ZTE MF290
	HID: hid-asus: add const to read-only outgoing usb buffer
	perf: Fix perf_event_validate_size() lockdep splat
	soundwire: stream: fix NULL pointer dereference for multi_link
	ext4: prevent the normalized size from exceeding EXT_MAX_BLOCKS
	arm64: mm: Always make sw-dirty PTEs hw-dirty in pte_modify
	team: Fix use-after-free when an option instance allocation fails
	ring-buffer: Fix memory leak of free page
	mmc: block: Be sure to wait while busy in CQE error recovery
	powerpc/ftrace: Create a dummy stackframe to fix stack unwind
	powerpc/ftrace: Fix stack teardown in ftrace_no_trace
	Linux 5.4.265

Change-Id: I762a9cd127dfce014141a135e818a170c99e3fd1
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2023-12-21 12:17:30 +00:00
Zhengchao Shao
70db018a10 UPSTREAM: ipv4: igmp: fix refcnt uaf issue when receiving igmp query packet
[ Upstream commit e2b706c691905fe78468c361aaabc719d0a496f1 ]

When I perform the following test operations:
1.ip link add br0 type bridge
2.brctl addif br0 eth0
3.ip addr add 239.0.0.1/32 dev eth0
4.ip addr add 239.0.0.1/32 dev br0
5.ip addr add 224.0.0.1/32 dev br0
6.while ((1))
    do
        ifconfig br0 up
        ifconfig br0 down
    done
7.send IGMPv2 query packets to port eth0 continuously. For example,
./mausezahn ethX -c 0 "01 00 5e 00 00 01 00 72 19 88 aa 02 08 00 45 00 00
1c 00 01 00 00 01 02 0e 7f c0 a8 0a b7 e0 00 00 01 11 64 ee 9b 00 00 00 00"

The preceding tests may trigger the refcnt uaf issue of the mc list. The
stack is as follows:
	refcount_t: addition on 0; use-after-free.
	WARNING: CPU: 21 PID: 144 at lib/refcount.c:25 refcount_warn_saturate (lib/refcount.c:25)
	CPU: 21 PID: 144 Comm: ksoftirqd/21 Kdump: loaded Not tainted 6.7.0-rc1-next-20231117-dirty #80
	Hardware name: Red Hat KVM, BIOS 0.5.1 01/01/2011
	RIP: 0010:refcount_warn_saturate (lib/refcount.c:25)
	RSP: 0018:ffffb68f00657910 EFLAGS: 00010286
	RAX: 0000000000000000 RBX: ffff8a00c3bf96c0 RCX: ffff8a07b6160908
	RDX: 00000000ffffffd8 RSI: 0000000000000027 RDI: ffff8a07b6160900
	RBP: ffff8a00cba36862 R08: 0000000000000000 R09: 00000000ffff7fff
	R10: ffffb68f006577c0 R11: ffffffffb0fdcdc8 R12: ffff8a00c3bf9680
	R13: ffff8a00c3bf96f0 R14: 0000000000000000 R15: ffff8a00d8766e00
	FS:  0000000000000000(0000) GS:ffff8a07b6140000(0000) knlGS:0000000000000000
	CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
	CR2: 000055f10b520b28 CR3: 000000039741a000 CR4: 00000000000006f0
	Call Trace:
	<TASK>
	igmp_heard_query (net/ipv4/igmp.c:1068)
	igmp_rcv (net/ipv4/igmp.c:1132)
	ip_protocol_deliver_rcu (net/ipv4/ip_input.c:205)
	ip_local_deliver_finish (net/ipv4/ip_input.c:234)
	__netif_receive_skb_one_core (net/core/dev.c:5529)
	netif_receive_skb_internal (net/core/dev.c:5729)
	netif_receive_skb (net/core/dev.c:5788)
	br_handle_frame_finish (net/bridge/br_input.c:216)
	nf_hook_bridge_pre (net/bridge/br_input.c:294)
	__netif_receive_skb_core (net/core/dev.c:5423)
	__netif_receive_skb_list_core (net/core/dev.c:5606)
	__netif_receive_skb_list (net/core/dev.c:5674)
	netif_receive_skb_list_internal (net/core/dev.c:5764)
	napi_gro_receive (net/core/gro.c:609)
	e1000_clean_rx_irq (drivers/net/ethernet/intel/e1000/e1000_main.c:4467)
	e1000_clean (drivers/net/ethernet/intel/e1000/e1000_main.c:3805)
	__napi_poll (net/core/dev.c:6533)
	net_rx_action (net/core/dev.c:6735)
	__do_softirq (kernel/softirq.c:554)
	run_ksoftirqd (kernel/softirq.c:913)
	smpboot_thread_fn (kernel/smpboot.c:164)
	kthread (kernel/kthread.c:388)
	ret_from_fork (arch/x86/kernel/process.c:153)
	ret_from_fork_asm (arch/x86/entry/entry_64.S:250)
	</TASK>

The root causes are as follows:
Thread A					Thread B
...						netif_receive_skb
br_dev_stop					...
    br_multicast_leave_snoopers			...
        __ip_mc_dec_group			...
            __igmp_group_dropped		igmp_rcv
                igmp_stop_timer			    igmp_heard_query         //ref = 1
                ip_ma_put			        igmp_mod_timer
                    refcount_dec_and_test	            igmp_start_timer //ref = 0
			...                                     refcount_inc //ref increases from 0
When the device receives an IGMPv2 Query message, it starts the timer
immediately, regardless of whether the device is running. If the device is
down and has left the multicast group, it will cause the mc list refcount
uaf issue.

Bug: 316932391
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Signed-off-by: Zhengchao Shao <shaozhengchao@huawei.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Hangbin Liu <liuhangbin@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit 94445d9583079e0ccc5dde1370076ff24800d86e)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I277be2304e564994e05b981ccd6cd8cbb9dc85be
2023-12-21 11:28:11 +00:00