UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.
Change-Id: I0c8cfd628483cd44408b987e4765dc7237ef7ad5
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.
Change-Id: I249472490349c227d9f30f276439fd1d0de0bdb9
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.
Change-Id: I608e85bc66028878b9dbfeff1c0a4caf683d03fb
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.
Change-Id: I761c047c722cebe3b2c721adab3fbed9dc1d7e47
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.
Change-Id: Ic75d04bf95dc21d5453c6e5e3a0a4864304fc8b5
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.
Change-Id: Ib1335860da25147ca87715a1935d2e8feee3fde4
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.
Change-Id: I296b40141d3d844f3011cd704e8c593c8bc0f5e0
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.
Change-Id: Ib420005ad94507db927a3014a39bd0d06b4d416f
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.
Change-Id: I7a840812752b34248ec3dcb241b069cf4bf77608
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
UAF is observed while unloading the interconnect driver.
Interconnect is core to the system and should not
be unloaded once it is probed. Marking the driver as
permanent by removing the module_exit function.
Change-Id: If4ddebec67f008e5412c1bf03bed0693fcaaffe0
Signed-off-by: Raviteja Laggyshetty <quic_rlaggysh@quicinc.com>
When qcedev module is exiting, it disconnects SPS.
At this times, crypto clocks need to be turned on
or it will cause a synchronous abort.
Tests: rmmod on the qcedev module.
Change-Id: I1721fe408392ef81b07a6c08d2196b2413ba2b2f
Signed-off-by: Gaurav Kashyap <quic_gaurkash@quicinc.com>
Signed-off-by: Nageswara reddy Karnati <quic_nkarnati@quicinc.com>
Suppose user has sent invalid external fence to bind API. Now, while
binding, if synx signal comes in parallel, it will set number of bound
synxs as 0 after signal. Further reduction on that number(num_bound_synxs)
(in case of callback registration failure) would make it wrap
around. So, now num_bound_synxs is large value and abrupt close on synx
fd will lead to synx_util_object_destroy. Here, the for loop on
num_bound_synxs would lead to invalid memory access.
This change decrements num_bound_synxs only if not zero.
Change-Id: I0cfffc90d4164b149c87545818ae4dcf57fc4c46
Signed-off-by: Ram Nagesh <quic_ramnages@quicinc.com>
Added reference count for contex map indicate memory under used
in remote call. And, this memory would not removed in internal
unmap to avoid UAF.
Change-Id: Ieb4ff6b298ff9c48953bc5b3539fdfe19a14b442
Acked-by: Santosh Sakore <ssakore@qti.qualcomm.com>
Signed-off-by: Santosh Sakore <quic_ssakore@quicinc.com>
As part of FR53657, make changes to support for boot_a and
boot_b partition access to HLOS APPS.
Change-Id: Ic173bd54df11e42b1811c198314719c4c34338db
Signed-off-by: Pradeep P V K <quic_pragalla@quicinc.com>
Postamble packets are executed in privileged mode by gpu. So we should keep
them in a privileged scratch buffer to block userspace access. For
targets with APRIV feature support, we can mark the preemption scratch
buffer as privileged too to avoid similar issues in future.
Change-Id: Ifda360dda251083f38dfde80ce1b5dc83daae902
Signed-off-by: Akhil P Oommen <quic_akhilpo@quicinc.com>
Signed-off-by: Kaushal Sanadhya <quic_ksanadhy@quicinc.com>
Move service id based filter check before queueing skb to avoid
possible use after free issue since skb might get released once
rx thread completed the processing of skb.
Change-Id: Iff93e32abd3d55f78bf4ce80675fc3bb312b0841
Signed-off-by: Arun Prakash <quic_app@quicinc.com>
In ioctls like kgsl_ioctl_submit_commands(), if both syncobj
type and cmd/marker/sparseobj type are submitted, the syncobj
is queued first followed by the other obj type. After syncobj
is successfully queued, in case of failure in get_timestamp
while queuing the other obj, both the command objs are
destroyed. As sync obj is already queued, accessing this
later would cause a crash.
Compare the user generated timestamp with the drawctxt
timestamp and return early in case of error. This avoids
unnecessary queuing of drawobjs.
Change-Id: Iedebd480bc18cd74d2f69d24a9dc1032fab01cdb
Signed-off-by: Kamal Agrawal <quic_kamaagra@quicinc.com>
If we're in the middle of series of chained TRBs, DWC3 will
avoid clearing HWO and SW has to do it manually.
We are doing it while reclaiming trbs for sg transfers.
Add check for sg queued trb and reclaim it as DWC3 skips
clearing HWO bit during sg transfers.
Change-Id: I200254728c0549da6534aea51daad94be6b6295e
Signed-off-by: AKASH KUMAR <quic_akakum@quicinc.com>
This change blocks access to channel name string,
in case channel name string length is more than permissible limits.
Change-Id: I2fe0b32498bc74011b1d42bb3c056c7e174494ca
Signed-off-by: rakegand <quic_rakegand@quicinc.com>
EDP reference clock for Yupik is required by EDP consumer.
Change-Id: I981bbaa789cdce86a140d17b81d46d590cc7d980
Signed-off-by: Taniya Das <quic_tdas@quicinc.com>