From b9f3e9838b40a7dbaff64f96137b3b51f42f2db7 Mon Sep 17 00:00:00 2001 From: angelomds42 Date: Mon, 13 Apr 2026 01:23:34 -0300 Subject: [PATCH 1/6] qcacld-3.0: Fix implicit enum-enum-cast warnings This fixes the following warning when building with newer clang: error: implicit conversion from enumeration type 'A_STATUS' to different enumeration type 'QDF_STATUS' [-Werror,-Wimplicit-enum-enum-cast] Change-Id: I84f9f9b0406fad6df74749cbcb2cb176d42525aa Signed-off-by: angelomds42 --- drivers/staging/qcacld-3.0/core/dp/htt/htt_h2t.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/staging/qcacld-3.0/core/dp/htt/htt_h2t.c b/drivers/staging/qcacld-3.0/core/dp/htt/htt_h2t.c index e1bed656e5ec..3038b831a3e5 100644 --- a/drivers/staging/qcacld-3.0/core/dp/htt/htt_h2t.c +++ b/drivers/staging/qcacld-3.0/core/dp/htt/htt_h2t.c @@ -629,7 +629,7 @@ htt_h2t_rx_ring_cfg_msg_hl(struct htt_pdev_t *pdev) pkt = htt_htc_pkt_alloc(pdev); if (!pkt) - return A_ERROR; /* failure */ + return QDF_STATUS_E_FAILURE; /* failure */ /* * show that this is not a tx frame download @@ -645,7 +645,7 @@ htt_h2t_rx_ring_cfg_msg_hl(struct htt_pdev_t *pdev) HTC_HEADER_LEN + HTC_HDR_ALIGNMENT_PADDING, 4, true); if (!msg) { htt_htc_pkt_free(pdev, pkt); - return A_ERROR; /* failure */ + return QDF_STATUS_E_FAILURE; /* failure */ } /* * Set the length of the message. From 925d92bed52d521a8e88b9f241482189882e8667 Mon Sep 17 00:00:00 2001 From: Michael Bestas Date: Sun, 30 Aug 2026 02:43:47 +0300 Subject: [PATCH 2/6] techpack: audio: wcd_cpe: Fix -Wimplicit-enum-enum-cast Change-Id: Ie415813c248c86c162673ea932927ffd1d35755d --- techpack/audio/asoc/codecs/wcd_cpe_services.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/techpack/audio/asoc/codecs/wcd_cpe_services.c b/techpack/audio/asoc/codecs/wcd_cpe_services.c index 96e2bb1945a4..fb6e1de56a21 100644 --- a/techpack/audio/asoc/codecs/wcd_cpe_services.c +++ b/techpack/audio/asoc/codecs/wcd_cpe_services.c @@ -987,7 +987,7 @@ static enum cpe_svc_result broadcast_boot_event( static enum cpe_process_result cpe_boot_initialize(struct cpe_info *t_info, enum cpe_svc_result *cpe_rc) { - enum cpe_process_result rc = CPE_SVC_FAILED; + enum cpe_process_result rc = CPE_PROC_FAILED; struct cpe_svc_notification payload; struct cmi_core_svc_event_system_boot *p = NULL; @@ -1991,7 +1991,7 @@ enum cmi_api_result cmi_send_msg(void *message) GFP_ATOMIC); if (!msg) { CPE_SVC_REL_LOCK(&cpe_d.cpe_api_mutex, "cpe_api"); - return CPE_SVC_NO_MEMORY; + return CMI_API_NO_MEMORY; } if (CMI_HDR_GET_OBM_FLAG(hdr) == CMI_OBM_FLAG_OUT_BAND) @@ -2006,7 +2006,7 @@ enum cmi_api_result cmi_send_msg(void *message) if (!msg->payload) { kfree(msg); CPE_SVC_REL_LOCK(&cpe_d.cpe_api_mutex, "cpe_api"); - return CPE_SVC_NO_MEMORY; + return CMI_API_NO_MEMORY; } msg->address = 0; From aba9e36d0f9fc049fb634505087c37a5fb28a3e9 Mon Sep 17 00:00:00 2001 From: LuK1337 Date: Fri, 28 Aug 2026 11:11:07 +0200 Subject: [PATCH 3/6] input: fingerprint: etxxx: Fix CFI failure on module init [ 2.458802] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010 [ 2.459516] Internal error: Oops: 96000005 [#1] PREEMPT SMP [ 2.459788] Modules linked in: ec617_drv(+) wcd9xxx_dlkm(+) bolero_cdc_dlkm(+) mbhc_dlkm stub_dlkm q6_dlkm adsp_loader_dlkm leds_aw2016 wcd937x_slave_dlkm rdbg focaltech_fts sec_ts_drv(+) p73 btpower apr_dlkm wcd938x_slave_dlkm wsa881x_analog_dlkm bu520x1nvx q6_notifier_dlkm rmnet_shs wcd_core_dlkm rmnet_offload q6_pdr_dlkm haptic snd_event_dlkm rmnet_core swr_dlkm rmnet_ctl snx0 [ 2.460075] CPU: 2 PID: 546 Comm: modprobe Tainted: G S 5.4.302-qgki-g3972ebf038eb #3 [ 2.460221] Hardware name: Sony Mobile Communications. PDX225(BLAIR v4) (DT) [ 2.460285] pstate: 80400005 (Nzcv daif +PAN -UAO) [ 2.460398] pc : __cfi_check_fail+0x4/0x50 [ec617_drv] [ 2.460457] lr : __cfi_check+0x1ac/0x1e0 [ec617_drv] [ 2.460912] x21: 02b3a43e29242445 x20: 0000000000000010 [ 2.462187] Call trace: [ 2.462240] __cfi_check_fail+0x4/0x50 [ec617_drv] [ 2.462332] __cfi_slowpath+0x10c/0x168 [ 2.462383] do_one_initcall+0x1dc/0x384 [ 2.462435] do_init_module+0x4c/0x204 [ 2.462522] load_module+0x1734/0x18c0 [ 2.462569] __arm64_sys_finit_module+0xb4/0xf0 [ 2.462617] el0_svc_common+0xc0/0x1a8 [ 2.462698] el0_svc_handler+0x24/0x70 [ 2.462745] el0_svc+0x8/0x100 [ 2.462877] ---[ end trace 711a96c503b0de92 ]--- [ 2.481911] Kernel panic - not syncing: Fatal exception module_init()/module_exit() define init_module/cleanup_module as aliases of the given functions. With clang r584948 and cross-DSO CFI, such an alias only gets its own jump table entry when the aliasee has internal linkage. Since egisfp_init()/egisfp_exit() were declared non-static, modpost ended up pointing __this_module.init at the raw .init.text address instead of init_module.cfi_jt: R_AARCH64_ABS64 init_module + 0 R_AARCH64_ABS64 cleanup_module + 0 __cfi_check() then compared the initcall pointer (type id 02b3a43e29242445) against egisfp_init.cfi_jt, failed, and jumped to __cfi_check_fail(), which faulted while dereferencing its bogus diag argument. Make both functions static, as they should have been in the first place. The relocations now resolve to the jump table: R_AARCH64_ABS64 init_module.cfi_jt + 0 R_AARCH64_ABS64 cleanup_module.cfi_jt + 0 Assisted-by: ClaudeCode:claude-opus-5 Change-Id: I3bf5a698bc5103e1fe0ae13e4c9c52cad9b41c7e --- drivers/input/misc/ets_bix_mmi/etxxx_fp.c | 4 ++-- drivers/input/misc/rbs_fod_mmi/etxxx_fp.c | 4 ++-- drivers/input/misc/rbs_fps_mmi/etxxx_fp.c | 4 ++-- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/drivers/input/misc/ets_bix_mmi/etxxx_fp.c b/drivers/input/misc/ets_bix_mmi/etxxx_fp.c index 1384c113b690..e5caee6a476d 100755 --- a/drivers/input/misc/ets_bix_mmi/etxxx_fp.c +++ b/drivers/input/misc/ets_bix_mmi/etxxx_fp.c @@ -1543,7 +1543,7 @@ egistec_probe_failed: return status; } -int __init egisfp_init(void) +static int __init egisfp_init(void) { int status; INFO_PRINT(" %s : module init \n", __func__); @@ -1556,7 +1556,7 @@ int __init egisfp_init(void) INFO_PRINT(" %s : module init OK ! \n", __func__); return status; } -void __exit egisfp_exit(void) +static void __exit egisfp_exit(void) { INFO_PRINT("module exit \n"); platform_driver_unregister(&egisfp_driver); diff --git a/drivers/input/misc/rbs_fod_mmi/etxxx_fp.c b/drivers/input/misc/rbs_fod_mmi/etxxx_fp.c index b4e4068acd8b..fdee9e03ebc4 100644 --- a/drivers/input/misc/rbs_fod_mmi/etxxx_fp.c +++ b/drivers/input/misc/rbs_fod_mmi/etxxx_fp.c @@ -1473,7 +1473,7 @@ egistec_probe_failed: return status; } -int __init egisfp_init(void) +static int __init egisfp_init(void) { int status; INFO_PRINT(" %s : module init \n", __func__); @@ -1486,7 +1486,7 @@ int __init egisfp_init(void) INFO_PRINT(" %s : module init OK ! \n", __func__); return status; } -void __exit egisfp_exit(void) +static void __exit egisfp_exit(void) { INFO_PRINT("module exit \n"); platform_driver_unregister(&egisfp_driver); diff --git a/drivers/input/misc/rbs_fps_mmi/etxxx_fp.c b/drivers/input/misc/rbs_fps_mmi/etxxx_fp.c index f75ffeedd2e3..9ca505d7575b 100644 --- a/drivers/input/misc/rbs_fps_mmi/etxxx_fp.c +++ b/drivers/input/misc/rbs_fps_mmi/etxxx_fp.c @@ -1389,7 +1389,7 @@ egistec_probe_failed: return status; } -int __init egisfp_init(void) +static int __init egisfp_init(void) { int status; INFO_PRINT(" %s : module init \n", __func__); @@ -1402,7 +1402,7 @@ int __init egisfp_init(void) INFO_PRINT(" %s : module init OK ! \n", __func__); return status; } -void __exit egisfp_exit(void) +static void __exit egisfp_exit(void) { INFO_PRINT("module exit \n"); platform_driver_unregister(&egisfp_driver); From d3d47118ab058320eff60b555d77bfa9d7ec6f20 Mon Sep 17 00:00:00 2001 From: Junxi Qian Date: Wed, 8 Apr 2026 16:10:06 +0800 Subject: [PATCH 4/6] UPSTREAM: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket state is LLCP_CLOSED, the code correctly calls release_sock() and nfc_llcp_sock_put() but fails to return. Execution falls through to the remainder of the function, which calls release_sock() and nfc_llcp_sock_put() again. This results in a double release_sock() and a refcount underflow via double nfc_llcp_sock_put(), leading to a use-after-free. Add the missing return statements after the LLCP_CLOSED branches in both functions to prevent the fall-through. Bug: 499350302 Fixes: d646960f7986 ("NFC: Initial LLCP support") Signed-off-by: Junxi Qian Reviewed-by: Eric Dumazet Link: https://patch.msgid.link/20260408081006.3723-1-qjx1298677004@gmail.com Signed-off-by: Jakub Kicinski (cherry picked from commit 2b5dd4632966c39da6ba74dbc8689b309065e82c) Signed-off-by: Lee Jones Change-Id: I041f20fc1fea32f715d2646579fab071e58688d8 --- net/nfc/llcp_core.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/net/nfc/llcp_core.c b/net/nfc/llcp_core.c index da3cb0d29b97..cd481490bcfe 100644 --- a/net/nfc/llcp_core.c +++ b/net/nfc/llcp_core.c @@ -1096,6 +1096,7 @@ static void nfc_llcp_recv_hdlc(struct nfc_llcp_local *local, if (sk->sk_state == LLCP_CLOSED) { release_sock(sk); nfc_llcp_sock_put(llcp_sock); + return; } /* Pass the payload upstream */ @@ -1187,6 +1188,7 @@ static void nfc_llcp_recv_disc(struct nfc_llcp_local *local, if (sk->sk_state == LLCP_CLOSED) { release_sock(sk); nfc_llcp_sock_put(llcp_sock); + return; } if (sk->sk_state == LLCP_CONNECTED) { From 1f9e522f945d201268336c2f83ddb75bbcd243fc Mon Sep 17 00:00:00 2001 From: Lee Jones Date: Fri, 27 Feb 2026 10:09:38 +0000 Subject: [PATCH 5/6] FROMGIT: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Presently, if the force feedback initialisation fails when probing the Logitech G920 Driving Force Racing Wheel for Xbox One, an error number will be returned and propagated before the userspace infrastructure (sysfs and /dev/input) has been torn down. If userspace ignores the errors and continues to use its references to these dangling entities, a UAF will promptly follow. We have 2 options; continue to return the error, but ensure that all of the infrastructure is torn down accordingly or continue to treat this condition as a warning by emitting the message but returning success. It is thought that the original author's intention was to emit the warning but keep the device functional, less the force feedback feature, so let's go with that. Bug: 482992246 Signed-off-by: Lee Jones Reviewed-by: Günther Noack Signed-off-by: Benjamin Tissoires (cherry picked from commit f7a4c78bfeb320299c1b641500fe7761eadbd101) # HID Signed-off-by: Lee Jones Change-Id: I2d2148fc1fd977b47e07523ee977070dbfa149b5 --- drivers/hid/hid-logitech-hidpp.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/hid/hid-logitech-hidpp.c b/drivers/hid/hid-logitech-hidpp.c index 477b082aa6a8..ac7dc35b1e89 100644 --- a/drivers/hid/hid-logitech-hidpp.c +++ b/drivers/hid/hid-logitech-hidpp.c @@ -3743,10 +3743,12 @@ static int hidpp_probe(struct hid_device *hdev, const struct hid_device_id *id) if (hidpp->quirks & HIDPP_QUIRK_CLASS_G920) { ret = hidpp_ff_init(hidpp, &data); - if (ret) + if (ret) { hid_warn(hidpp->hid_dev, "Unable to initialize force feedback support, errno %d\n", ret); + ret = 0; + } } return ret; From db44a74f9fae4521ca11134c556d9cff4409f755 Mon Sep 17 00:00:00 2001 From: Lee Jones Date: Tue, 21 Apr 2026 13:45:26 +0100 Subject: [PATCH 6/6] tipc: fix double-free in tipc_buf_append() [ Upstream commit d293ca716e7d5dffdaecaf6b9b2f857a33dc3d3a ] tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been freed, leading to double-free. Fix this by checking if head now points to a newly allocated reassembled skb. If it does, reassign *headbuf for later freeing operations. Bug: 500022799 Fixes: d618d09a68e4 ("tipc: enforce valid ratio between skb truesize and contents") Suggested-by: Tung Nguyen Signed-off-by: Lee Jones Reviewed-by: Tung Nguyen Signed-off-by: Jakub Kicinski Signed-off-by: Sasha Levin [uli: backport to 4.19] Signed-off-by: Ulrich Hecht Reviewed-by: Pavel Machek Reviewed-by: Nobuhiro Iwamatsu Change-Id: I76d957597768652e2f05be3470bf960f6ff29085 --- net/tipc/msg.c | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/net/tipc/msg.c b/net/tipc/msg.c index ff167decbef1..5ba2c8ec8e11 100644 --- a/net/tipc/msg.c +++ b/net/tipc/msg.c @@ -175,8 +175,20 @@ int tipc_buf_append(struct sk_buff **headbuf, struct sk_buff **buf) if (fragid == LAST_FRAGMENT) { TIPC_SKB_CB(head)->validated = false; - if (unlikely(!tipc_msg_validate(&head))) + + /* If the reassembled skb has been freed in + * tipc_msg_validate() because of an invalid truesize, + * then head will point to a newly allocated reassembled + * skb, while *headbuf points to freed reassembled skb. + * In such cases, correct *headbuf for freeing the newly + * allocated reassembled skb later. + */ + if (unlikely(!tipc_msg_validate(&head))) { + if (head != *headbuf) + *headbuf = head; goto err; + } + *buf = head; TIPC_SKB_CB(head)->tail = NULL; *headbuf = NULL;