Suppose if the userspace using ffs failed to open
ep0, it will issue a ep0_release and continuously try to do
ep0_open until it gets through.
The general operation of ep0_release is the it will destroy
the epfile and free the structures. Whole thing follows this
path:
ffs_ep0_release
ffs_data_reset
ffs_data_clear
kfree(epfiles) mark NULL
kfree(raw_desc)
raw_desc =NULL
Now the last few steps of the release process is done without
any mutex. In one functions we do kfree and another we mark
NULL.
This created a potential double free scenario, if a ep0_release
process got preempted before kfree, meanwhile another ep0_release
gets through and freed up the structures but didn't mark NULL
and within that time the preempted process wakes up and tried
to kfree again, due to structure not marked NULL will lead to
double free/invalid free.
Following is the illustration:
CPU2 CPU3
ffs_ep0_release
ffs_data_reset
ffs_data_clear
kfree(epfiles)
epfiles = NULL
--preempted--
ffs_ep0_release
ffs_data_reset
ffs_data_clear
kfree(epfiles)
epfiles = NULL
kfree(ffs->raw_descs_data)
kfree(ffs->raw_strings)
kfree(ffs->stringtabs)
--woke-up--
kfree(ffs->raw_descs_data)
<use-after-free>
raw_desc =NULL
Fix this by performing kfree and NULL operations under
ffs_data_clear within a mutex lock.
Change-Id: I1c8d92ff99c30165b06bafdd00bc9eb610f3bb76
Signed-off-by: Udipto Goswami <quic_ugoswami@quicinc.com>
Add support for pin connectivity test for BT/FM slimbus
Change-Id: Ia913bcb204f6cccc59790b9a4cef20cbd346f05c
Signed-off-by: Satish Kumar Kodishala <quic_skodisha@quicinc.com>
Due to pcie link down, wlan tried to recover from the
failure, it checked for the current context to see if
some memory has to be allocated in atomic context, but
seems it failed to take into account one condition.
To maintain wlan driver code as OS independent, code changes
are done to allocate memory always with GFP_ATOMIC flag inside
cnss_schedule_recovery() function. This avoids adding gfp flags
inside wlan driver code.
Change-Id: I255d22a46288eccc2056d870b5f3ee7575ee71eb
Signed-off-by: Gangadhar Kavalastramath <quic_gkavalas@quicinc.com>
Due to changes in Kconfig default options, genericarmv8 is out of sync.
Sync genericarmv8 defconfig to the latest code.
Change-Id: I15d753b9d9429ac623fd7b7e7eaa936b5ed2a8b1
Signed-off-by: Pavankumar Kondeti <quic_pkondeti@quicinc.com>
The function drivers have no business accessing usb_request::num_mapped_sgs
field. The UDC will use this field to cache the sgs mapped for a given
request.
Change-Id: I6a8c8c2e52a36caedfe977f517b4c04b1ad0045c
Signed-off-by: Pavankumar Kondeti <quic_pkondeti@quicinc.com>
Dump registers in case of Data CRC/timeout errors and print other
useful information.
This contains below patches as well:
4c196de7e0fd mmc: sdhci: rate limit sdhci_dumpregs() prints
16dabee056d4 mmc: sdhci: Add timestamp debug info for data timeout error
e00d878df07e mmc: sdhci: Avoid dumping registers when SD card removed.
Change-Id: I5efe8ff4bacc5da3a05829be7cac4ce40f9fc584
Signed-off-by: Sarthak Garg <quic_sartgarg@quicinc.com>
This patch adds new netlink attribute to allow a user to (optionally)
specify the desired offload mode immediately upon MACSec link creation.
Separate iproute patch will be required to support this from user space.
Change-Id: I3aa8c9c2eb65763707487267a23ea2e645d1afde
Signed-off-by: Mark Starovoytov <mstarovoitov@marvell.com>
Signed-off-by: Igor Russkikh <irusskikh@marvell.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Git-commit: 791bb3fcafcedd11f9066da9fee9342ecb6904d0
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
Signed-off-by: Karthik Rudrapatna <quic_krudrapa@quicinc.com>
Extend hBoost PBS control to all play modes, so hBoost disabling
will be always handled in the driver by triggering the PBS. Also,
delay hBoost turning off 2 seconds after the stop command to
prevent hBoost being enabled/disabled too frequently in repeated
short vibration case, this help to avoid hBoost lockup when it's
enabled and disabled very quickly.
Change-Id: I76263e51ad00a01d95ff7fd7b08c1655031516e6
Signed-off-by: Fenglin Wu <fenglinw@codeaurora.org>
* refs/heads/tmp-983a7e7:
FROMGIT: USB: gadget: bRequestType is a bitfield, not a enum
UPSTREAM: aio: fix use-after-free due to missing POLLFREE handling
UPSTREAM: aio: keep poll requests on waitqueue until completed
UPSTREAM: signalfd: use wake_up_pollfree()
UPSTREAM: binder: use wake_up_pollfree()
UPSTREAM: wait: add wake_up_pollfree()
UPSTREAM: USB: gadget: zero allocate endpoint 0 buffers
UPSTREAM: USB: gadget: detect too-big endpoint 0 requests
UPSTREAM: HID: check for valid USB device for many HID drivers
UPSTREAM: HID: wacom: fix problems when device is not a valid USB device
UPSTREAM: HID: bigbenff: prevent null pointer dereference
UPSTREAM: HID: add USB_HID dependancy on some USB HID drivers
UPSTREAM: HID: add USB_HID dependancy to hid-chicony
UPSTREAM: HID: add USB_HID dependancy to hid-prodikeys
UPSTREAM: HID: add hid_is_usb() function to make it simpler for USB detection
BACKPORT: f2fs: relocate inline conversion from mmap() to mkwrite()
BACKPORT: f2fs: support RO feature
BACKPORT: f2fs: fix wrong total_sections check and fsmeta check
BACKPORT: FROMGIT: binder: fix freeze race
FROMGIT: binder: BINDER_GET_FROZEN_INFO ioctl
FROMGIT: binder: use EINTR for interrupted wait for work
BACKPORT: FROMGIT: binder: BINDER_FREEZE ioctl
ANDROID: usb: gadget: f_accessory: Mitgate handling of non-existent USB request
FROMGIT: binder: fix test regression due to sender_euid change
BACKPORT: binder: use cred instead of task for getsecid
BACKPORT: binder: use cred instead of task for selinux checks
BACKPORT: binder: use euid from cred instead of using task
ANDROID: setlocalversion: make KMI_GENERATION optional
Change-Id: I00cf067e7b2e31eb3ad074ede720c087a7647959
Signed-off-by: Srinivasarao Pathipati <quic_spathi@quicinc.com>
When bridge0 is in Primiscous mode, passed the packets to macsec
Change-Id: Ib325e0bb19cee792a8dd3759a4e752581e48827b
Signed-off-by: Karthik Rudrapatna <quic_krudrapa@quicinc.com>
Remove asynchronous network execution related code since it's
not used.
Change-Id: I9e9b54fddbbe9a0a1c0721983ae65e464fd49c0f
Signed-off-by: Jilai Wang <quic_jilaiw@quicinc.com>
Commit 980a25b5c2 ("usb: dwc3: Dont release wakeup source
during usb restart") introduced a check in dwc3_msm_suspend
for in_restart before releasing the wakeup source to ensure
that driver doesn't release the wakeup source if suspend is
kicked while restart session was executing. Now consider a
case where, due to some reason, erratic event is seen on the
controller and restart session is kicked. While restart work
was running, physical cable disconnect happened which will
call suspend routine eventually but due to in_restart flag
being set driver will not release the wakeup source and will
end up consuming power even though cable got disconnected.
Fix this by adding one more level of judgement of vbus_active
to ensure that wakeup source is released when cable gets
disconnected during restart usb work.
Change-Id: Ie54618640d08c4f2e3f0dc1d38260e0aa2d309c2
Signed-off-by: Pratham Pratap <quic_ppratap@quicinc.com>
This tries to fix priority inversion in the below condition resulting in
long checkpoint delay.
f2fs_get_node_info()
- nat_tree_lock
-> sleep to grab journal_rwsem by contention
checkpoint
- waiting for nat_tree_lock
In order to let checkpoint go, let's release nat_tree_lock, if there's a
journal_rwsem contention.
Change-Id: I72ca6cf52908a08976c200be32a09fb3105e726e
Signed-off-by: Daeho Jeong <daehojeong@google.com>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Git-commit: 2eeb0dce728a7eac3e4dfe355d98af40d61f7a26
Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/jaegeuk/f2fs.git
Signed-off-by: Sayali Lokhande <sayalil@codeaurora.org>
This change is to fix warnings generated when running sparse check.
Change-Id: I67bc66d1fc6d3fe39cd3d566e00b67e14e61bb7d
Signed-off-by: Jilai Wang <jilaiw@codeaurora.org>
Validate SMEM state handler before using it.
Change-Id: I762cef00daa267ff7e411a5c740556d7f235d383
Signed-off-by: Naman Padhiar <quic_npadhiar@quicinc.com>
A NOC was seen while dumping BAM registers information. To avoid this,
always enable qpic clocks before accessing BAM registers.
Change-Id: I7a8799d742dc1fcc066512aba1537d7d48797a73
Signed-off-by: Pradeep P V K <quic_pragalla@quicinc.com>
Szymon rightly pointed out that the previous check for the endpoint
direction in bRequestType was not looking at only the bit involved, but
rather the whole value. Normally this is ok, but for some request
types, bits other than bit 8 could be set and the check for the endpoint
length could not stall correctly.
Fix that up by only checking the single bit.
Fixes: 153a2d7e3350 ("USB: gadget: detect too-big endpoint 0 requests")
Cc: Felipe Balbi <balbi@kernel.org>
Reported-by: Szymon Heidrich <szymon.heidrich@gmail.com>
Link: https://lore.kernel.org/r/20211214184621.385828-1-gregkh@linuxfoundation.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit f08adf5add9a071160c68bb2a61d697f39ab0758
https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb.git usb-linus)
Bug: 210292376
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I7e708b2b94433009c87f697346e0515d93454f48
misc command doesn't do npu_init before sending to firmware, so
it's possible that npu will be turned off while npu firmware is
handling misc commands which causes times out in host driver.
To fix this issue, npu_init/npu_deinit need to be called before
and after misc commands are handled. In addition, only one misc
command should be handled at any moment. The misc command should
be failed right away while the other one is being handled.
Change-Id: I523255da15fa4e3b8b21d74b28f90d3458ebeb3c
Signed-off-by: Jilai Wang <jilaiw@codeaurora.org>
Client initiated close channel is happening and transfer completion
callback is not received within the timeout period. When completion
callback is received it is becoming invalid as the memory is cleared
as part of close channel previously. Here, keeping event req memory
without clearing in close channel API and marking the elements in
flush event request buffer as stale.
Change-Id: I1e15cf51f0819252f79493d8f806352a12801ef6
Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
Change is to reutrn -EDEFER error when i2c is not probed and delay
PCIE probe. I2C probe is gettting called post pcie enumeration
and this results in i2c de-emphasis settings not being applied.
Pine doesn't enumerate as these settings are not applied.
Change-Id: I1ac966b26c65f44afb32987927558209bf8787a7
Signed-off-by: Subramanian Ananthanarayanan <quic_skananth@quicinc.com>
When HW offloading is enabled, offloaded stats should be used, because
s/w stats are wrong and out of sync with the HW in this case.
Change-Id: I83ed6f427ae03d6624602e8763a8799f03cd5246
Signed-off-by: Dmitry Bogdanov <dbogdanov@marvell.com>
Signed-off-by: Mark Starovoytov <mstarovoitov@marvell.com>
Signed-off-by: Igor Russkikh <irusskikh@marvell.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Git-commit: b62c3624500a7e1cc081e75973299c1f7901a438
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
Signed-off-by: Karthik Rudrapatna <quic_krudrapa@quicinc.com>
The idea is simple. If the frame is an exact match for the controlled port
(based on DA comparison), then we simply divert this skb to matching port.
Multicast/broadcast messages are delivered to all ports.
Change-Id: Iaa716e14c1a178a99b51b1104e7c68eb2f8e592e
Signed-off-by: Mark Starovoytov <mstarovoitov@marvell.com>
Signed-off-by: Igor Russkikh <irusskikh@marvell.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Git-commit: f428011b90ec0de7429886f753b7c3293392761c
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
Signed-off-by: Karthik Rudrapatna <quic_krudrapa@quicinc.com>
Offload engine can setup several SecY. Each macsec interface shall have
its own mac address. It will filter a traffic by dest mac address.
Change-Id: Ic0e971c8061eb7ce74e1ddab4b76374571da5a8c
Signed-off-by: Dmitry Bogdanov <dbogdanov@marvell.com>
Signed-off-by: Mark Starovoytov <mstarovoitov@marvell.com>
Signed-off-by: Igor Russkikh <irusskikh@marvell.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Git-commit: A249f8050624f92f844605274de3367e2c8ac706
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
Signed-off-by: Karthik Rudrapatna <quic_krudrapa@quicinc.com>
This patch adds secy pointer initialization in the macsec_context.
It will be used by MAC drivers in offloading operations.
Change-Id: I59c0d751f2b026096dcbe57355b47d7f940b0a94
Signed-off-by: Dmitry Bogdanov <dbogdanov@marvell.com>
Signed-off-by: Mark Starovoytov <mstarovoitov@marvell.com>
Signed-off-by: Igor Russkikh <irusskikh@marvell.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Git-commit: 182879f89b858fede98136ea3ad45fe9c7178387
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
Signed-off-by: Karthik Rudrapatna <quic_krudrapa@quicinc.com>