Commit graph

602750 commits

Author SHA1 Message Date
Rajesh Kemisetti
8774e7b998 msm: kgsl: Add missing check for snapshot IB dump
During ringbuffer parsing, same IB can exist multiple times
but size validation happens only for the first time.
This leads to out of bound access if the subsequent sizes are
greater than the allocated size.

Add a check to make sure that requested size is within the
allocated range.

Change-Id: Ie5d3c02c1669de2e6188821399e985f0991aa57c
Signed-off-by: Rajesh Kemisetti <rajeshk@codeaurora.org>
2019-08-30 09:21:10 +02:00
Srinivas Dasari
350a145574 cfg80211: indicate support for external authentication
Define macro to indicate backport support for
external authentication where authentication can be
offloaded to userspace in specific cases such as SAE.

Change-Id: Ib253b303e82f583f61bc13d14c8d491d5ea2af15
CRs-Fixed: 2468738
Signed-off-by: Srinivas Dasari <dasaris@codeaurora.org>
Signed-off-by: Jiachao Wu <jiacwu@codeaurora.org>
Signed-off-by: Min Liu <minliu@codeaurora.org>
Signed-off-by: stonez <stonez@codeaurora.org>
2019-08-30 09:21:10 +02:00
Pavankumar Kondeti
97fe3984e9 sched/walt: Fix the memory leak of idle task load pointers
The memory for task load pointers are allocated twice for each
idle thread except for the boot CPU. This happens during boot
from idle_threads_init()->idle_init() in the following 2 paths.

1. idle_init()->fork_idle()->copy_process()->
		sched_fork()->init_new_task_load()

2. idle_init()->fork_idle()-> init_idle()->init_new_task_load()

The memory allocation for all tasks happens through the 1st path,
so use the same for idle tasks and kill the 2nd path. Since
the idle thread of boot CPU does not go through fork_idle(),
allocate the memory for it separately.

Change-Id: I4696a414ffe07d4114b56d326463026019e278f1
Signed-off-by: Pavankumar Kondeti <pkondeti@codeaurora.org>
[schikk@codeaurora.org: resolved merge conflicts]
Signed-off-by: Swetha Chikkaboraiah <schikk@codeaurora.org>
2019-08-30 09:21:10 +02:00
Srinivas Dasari
18716efa40 nl80211: Allow SAE Authentication for NL80211_CMD_CONNECT
This commit allows SAE Authentication for NL80211_CMD_CONNECT
interface, provided host driver advertises the support.

Host drivers may offload the SAE authentication to user space
through NL80211_CMD_EXTERNAL_AUTH interface and thus expect
the user space to advertise support to handle offload through
NL80211_ATTR_EXTERNAL_AUTH_SUPPORT in NL80211_CMD_CONNECT
request. Such drivers should reject the connect request on no
offload support from user space.

Signed-off-by: Srinivas Dasari <dasaris@qti.qualcomm.com>
Signed-off-by: Jouni Malinen <jouni@qca.qualcomm.com>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Git-commit: 10773a7c09b327d02144c7d181e6544b7015ffc7
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
CRs-Fixed: 2468738
Change-Id: I41b49228e88b32a35323c4dc8fa98e507a8a971d
Signed-off-by: Srinivas Dasari <dasaris@codeaurora.org>
Signed-off-by: Jiachao Wu <jiacwu@codeaurora.org>
Signed-off-by: Min Liu <minliu@codeaurora.org>
Signed-off-by: stonez <stonez@codeaurora.org>
2019-08-30 09:21:10 +02:00
Srinivas Dasari
3edd7e38cf cfg80211/nl80211: Optional authentication offload to userspace
This interface allows the host driver to offload the authentication to
user space. This is exclusively defined for host drivers that do not
define separate commands for authentication and association, but rely on
userspace SME (e.g., in wpa_supplicant for the ~WPA_DRIVER_FLAGS_SME
case) for the authentication to happen. This can be used to implement
SAE without full implementation in the kernel/firmware while still being
able to use NL80211_CMD_CONNECT with driver-based BSS selection.

Host driver sends NL80211_CMD_EXTERNAL_AUTH event to start/abort
authentication to the port on which connect is triggered and status
of authentication is further indicated by user space to host
driver through the same command response interface.

User space entities advertise this capability through the
NL80211_ATTR_EXTERNAL_AUTH_SUPP flag in the NL80211_CMD_CONNECT request.
Host drivers shall look at this capability to offload the authentication.

Signed-off-by: Srinivas Dasari <dasaris@qti.qualcomm.com>
Signed-off-by: Jouni Malinen <jouni@qca.qualcomm.com>
[add socket connection ownership check]
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Git-commit: 40cbfa90218bc570a7959b436b9d48a18c361041
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
CRs-Fixed: 2468738
Change-Id: Id925dd82d9a9c719b32aac2de75b6ad001f1a958
[dasaris@codeaurora.org: merging with msm-specific changes]
Signed-off-by: Srinivas Dasari <dasaris@codeaurora.org>
Signed-off-by: Jiachao Wu <jiacwu@codeaurora.org>
Signed-off-by: Min Liu <minliu@codeaurora.org>
Signed-off-by: stonez <stonez@codeaurora.org>
2019-08-30 09:21:10 +02:00
Srinivas Dasari
8cb175043f cfg80211: Updated nl80211_commands to be in sync with upstream
Update nl80211_commands to be in sync with upstream.
This is needed to add new commands.

Change-Id: Ib6b71e3f66560b035377c7bc0c115490b04f5c4f
CRs-Fixed: 2468738
Signed-off-by: Srinivas Dasari <dasaris@codeaurora.org>
Signed-off-by: stonez <stonez@codeaurora.org>
2019-08-30 09:21:10 +02:00
Pranav Vashi
7f0b81a71f usb: dwc3-msm: adapt enum otg_state to drd_state
Signed-off-by: Pranav Vashi <neobuddy89@gmail.com>
2019-08-10 14:29:01 +02:00
codeworkx
4b5255f5eb Revert "msm: camera: isp: Fix frame drop pattern"
This reverts commit cc4d1a6cb1.
2019-08-10 14:20:12 +02:00
codeworkx
f6334e63fa Merge tag 'LA.UM.7.4.r1-05400-8x98.0' into lineage-16.0
"LA.UM.7.4.r1-05400-8x98.0"

Change-Id: Iaa6db184c519b1a6f8de9b989ba402f156bec25c
2019-08-10 14:13:49 +02:00
Alistair Strachan
88950d5914 media: uvcvideo: Fix 'type' check leading to overflow
commit 47bb117911b051bbc90764a8bff96543cbd2005f upstream.

When initially testing the Camera Terminal Descriptor wTerminalType
field (buffer[4]), no mask is used. Later in the function, the MSB is
overloaded to store the descriptor subtype, and so a mask of 0x7fff
is used to check the type.

If a descriptor is specially crafted to set this overloaded bit in the
original wTerminalType field, the initial type check will fail (falling
through, without adjusting the buffer size), but the later type checks
will pass, assuming the buffer has been made suitably large, causing an
overflow.

Avoid this problem by checking for the MSB in the wTerminalType field.
If the bit is set, assume the descriptor is bad, and abort parsing it.

Originally reported here:
https://groups.google.com/forum/#!topic/syzkaller/Ot1fOE6v1d8
A similar (non-compiling) patch was provided at that time.

Change-Id: Icedffeb8d406351675f5195fdd9000a644d07b95
Reported-by: syzbot <syzkaller@googlegroups.com>
Signed-off-by: Alistair Strachan <astrachan@google.com>
Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab+samsung@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2019-08-09 17:59:09 +02:00
codeworkx
2b6f677357 Update wifi stack from LA.UM.7.4.r1-05400-8x98.0
Change-Id: I7e46d6e7c3c73ead5c66d10ee2955c8a8f3f5292
2019-07-20 07:14:53 +02:00
Tyler Nijmeh
a84f38de6b qcacld-3.0: Do not allow any wakelocks to be held
These contribute to a great amount of idle drain.

Tests: 30 minutes of playing Spotify with the screen off, unplugged.

Change-Id: Ibe62c631fd93de99d71d56ee6cb2387571f71d34
Signed-off-by: Tyler Nijmeh <tylernij@gmail.com>
2019-07-09 15:13:32 -07:00
Sultan Alsawaf
c9d0aae63a qcacld-3.0: Fix null pointer dereference in htt_rx_amsdu_rx_in_order_pop_ll()
Change-Id: Idde12e970e4915f038ed6bccf3a8d7012d7cff11
2019-07-09 15:12:08 -07:00
Linux Build Service Account
5ef8738b63 Merge commit '7b96ca1e7fcd95dbd20d460d19b52675edbe906f' into HEAD
Change-Id: I7a812ced03187bac71f367c9da461676237c5aa8
2019-07-05 17:03:31 +05:30
Linux Build Service Account
7b96ca1e7f Merge "msm: ais: handle the error value returned during get clock" 2019-06-29 05:13:25 -07:00
E V Ravi
12fa518175 msm: ais: handle the error value returned during get clock
currently only NULL pointer check is used to validate the return
value from clkget this change to handle all the failures.

Change-Id: I275cb4717c675baf528e05c50058f2c6b0025011
Signed-off-by: E V Ravi <evenka@codeaurora.org>
Signed-off-by: Sumalatha Malothu <smalot@codeaurora.org>
2019-06-29 15:11:24 +05:30
Linux Build Service Account
b061f9ea06 Merge "soc: qcom: smem: validate fields of shared structures" 2019-06-27 11:34:45 -07:00
Linux Build Service Account
e42eed967e Merge "msm: ipa: fix to validate the ioctl WAN_IOC_SEND_LAN_CLIENT_MSG params" 2019-06-27 04:38:42 -07:00
Linux Build Service Account
5100cbd1b3 Merge "diag: Prevent out-of-bound access while processing userspace data" 2019-06-27 04:38:40 -07:00
Deepak Kumar Singh
f94667b92e soc: qcom: smem: validate fields of shared structures
Structures in shared memory that can be modified by remote
processors may have untrusted values, they should be validated
before use.

Adding proper validation before using fields of shared
structures.

CRs-Fixed: 2421611
Change-Id: Ifed71c506a26105eac3db9ee35f086d7dbf5a3a3
Signed-off-by: Deepak Kumar Singh <deesin@codeaurora.org>
2019-06-27 04:12:57 -07:00
Chaitanya Pratapa
7123fa1089 msm: ipa: fix to validate the ioctl WAN_IOC_SEND_LAN_CLIENT_MSG params
When processing WAN_IOC_SEND_LAN_CLIENT_MSG ioctl there is a possibility
of message_type being invalid and this can lead to out of buffer error.
Make a change to validate the ioctl params before processing.

Change-Id: If7955f77863b772ae1c8feda5ca0145c822403b9
Signed-off-by: Chaitanya Pratapa <cpratapa@codeaurora.org>
2019-06-26 23:35:12 -07:00
Hardik Arya
25e6769daa diag: Prevent out-of-bound access while processing userspace data
Proper buffer length checks are missing in diagchar_write
handlers for userspace data while processing the same buffer.

Change-Id: I5b8095766e09c22f164398089505fe827fee8b54
Signed-off-by: Hardik Arya <harya@codeaurora.org>
2019-06-27 10:34:44 +05:30
Andrew Zaborowski
dea74cf7d5 cfg80211: NL80211_ATTR_SOCKET_OWNER support for CMD_CONNECT
Disconnect or deauthenticate when the owning socket is closed if this
flag is supplied to CMD_CONNECT or CMD_ASSOCIATE.  This may be used
to ensure userspace daemon doesn't leave an unmanaged connection behind.

In some situations it would be possible to account for that, to some
degree, in the deamon restart code or in the up/down scripts without
the use of this attribute.  But there will be systems where the daemon
can go away for varying periods without a warning due to local resource
management.

Signed-off-by: Andrew Zaborowski <andrew.zaborowski@intel.com>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>

Git-commit: 36a554cec119bbd20c4ec0cb96bd4712d124bfea
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/jberg/mac80211-next.git
Change-Id: Ic09ee323fc6215059d5c2572ba3e77c56addad32
CRs-Fixed: 2468738
Signed-off-by: Srinivas Dasari <dasaris@codeaurora.org>
Signed-off-by: Jiachao Wu <jiacwu@codeaurora.org>
Signed-off-by: Min Liu <minliu@codeaurora.org>
Signed-off-by: stonez <stonez@codeaurora.org>
2019-06-26 12:40:38 +08:00
Linux Build Service Account
2692bfe650 Merge "dsp: q6core: validate payload size before memory copy" 2019-06-24 20:00:53 -07:00
codeworkx
419feecce6 oneplus5: enable support for RTL8152 and LAN78XX usb network adapters
Change-Id: Ief3401f912f68c48f07261f912535e88d5d3b9be
2019-06-23 18:58:35 +02:00
Pranav Vashi
5ba935e545 oneplus5: qcacld: Enable packet capture feature
Signed-off-by: Pranav Vashi <neobuddy89@gmail.com>
Change-Id: Id70942df031d09d3728991b2831237728ea29d0f
2019-06-19 21:49:51 +02:00
codeworkx
d14a32cb6d oneplus5: qcacld: enable FILS_SK feature
Change-Id: I916f7558f9e38a62710ae29c2e57e17b6b1c916f
2019-06-19 21:47:32 +02:00
codeworkx
0ea04765eb oneplus5: regenerate defconfig
Change-Id: Ifc54c1ca0cc643afd755ec0744cb9bd240560375
2019-06-19 21:43:08 +02:00
Linux Build Service Account
ca05390f0c Merge "msm: sensor: actuator: fix out of bound read for bivcm region params" 2019-06-18 09:48:14 -07:00
Linux Build Service Account
6240792cda Merge "diag: Prevent out of bound access while getting build mask" 2019-06-18 00:25:17 -07:00
Haibin Liu
94835ff2d3 msm: sensor: actuator: fix out of bound read for bivcm region params
The region index for bivcm is not validated against the region size.
This causes out-of-bound read on the KASAN kernel.
Add restriction that region index smaller than region size.

CRs-Fixed: 2379514
Change-Id: I72c4a41a4b41c8fa70c174ffd3215a81eaa14355
Signed-off-by: Haibin Liu <haibinl@codeaurora.org>
2019-06-17 23:50:38 -07:00
Manoj Prabhu B
82caeda139 diag: Prevent out of bound access while getting build mask
Add check for minimum length before typecasting to build mask
structure to prevent out of bound access.

CRs-Fixed: 2431005
Change-Id: I97b439ead62c8a67869c9209442ef771308f2d3f
Signed-off-by: Manoj Prabhu B <bmanoj@codeaurora.org>
2019-06-17 23:24:16 -07:00
Deepak Kumar Singh
166ba6a45b soc: qcom: smem: validate fields of shared structures
Structures in shared memory that can be modified by remote
processors may have untrusted values, they should be validated
before use.

Adding proper validation before using fields of shared
structures.

CRs-Fixed: 2421602
Change-Id: I947ed5b0fe5705e5223d75b0ea8aafb36113ca5a
Signed-off-by: Deepak Kumar Singh <deesin@codeaurora.org>
2019-06-17 23:14:53 -07:00
Tharun Kumar Merugu
b9a42b4ce5 msm: adsprpc: maintain local copy of rpra offloaded to DSP
Since DSP is not supposed to modify the base pointer rpra of the
input/output arguments offloaded to DSP, maintain a local copy of
the pointer and use it after receiving interrupt from DSP.

Change-Id: I4afade7184cb2aca148060fb0cda06c6174f3b55
Acked-by: Maitreyi Gupta <maitreyi@qti.qualcomm.com>
Signed-off-by: Tharun Kumar Merugu <mtharu@codeaurora.org>
Signed-off-by: Mohammed Nayeem Ur Rahman <mohara@codeaurora.org>
2019-06-17 06:52:56 -07:00
LuK1337
c62e49afc1 Revert "qcacld-3.0: Fix OOB in wma_stats_event_handler"
* This change makes WiFi report invalid signal strength.

This reverts commit be468730d315e973e9936da275b06600d0ce276c.

Change-Id: I01094049520ea706c27e00f316539f9d9d53bbc7
2019-06-16 08:32:43 +02:00
Albert I
93e8af2c9d qcacld-3.0: Add packet capture feature option into Kconfig
* Needed after LA.UM.7.4.r1-05300-8x98.0 merge.

Signed-off-by: Albert I <kras@raphielgang.org>
Change-Id: I7af8ef790db303c8cb0d338479b85b12b4f86019
2019-06-16 08:26:34 +02:00
Luca Stefani
91261f4801 staging: qcacld-3.0: make debug functions configurable
Change-Id: If0643fc66aac1846fc5e1466d047ff31a5b175c3
2019-06-16 08:26:15 +02:00
Ethan Chen
96b2738d6b staging: qcacld-3.0: Fix Kconfig
* Correct badly named options
* Add missing options

Change-Id: I4a5cc2216fe36a07520827cdb9577a75ec09450a
2019-06-16 08:25:42 +02:00
Park Ju Hyung
a492739e39 staging: qcacld-3.0: fix an inconsistency between userspace and kernel options
Signed-off-by: Park Ju Hyung <qkrwngud825@gmail.com>
2019-06-16 08:22:12 +02:00
codeworkx
b2bfc56a41 Update wifi stack from LA.UM.7.4.r1-05300-8x98.0
Change-Id: I57425c2e97765519cb7c6b37c9ccbe351563fe9b
2019-06-16 08:19:06 +02:00
Max Weffers
ac0bcfe881 Revert "msm: mdss: hdmi: skip pan_display during handoff"
* Makes the device get stuck on splash screen
  when booting in offline charging mode.

This reverts commit b03b261cfc.

Change-Id: I79fc04a43a7995c1015464b2d3c481200ddcaf8d
2019-06-16 08:16:12 +02:00
codeworkx
15f81a19b5 Merge tag 'LA.UM.7.4.r1-05300-8x98.0' into lineage-16.0
"LA.UM.7.4.r1-05300-8x98.0"

Change-Id: I8e27939efccb7d0bda0ac7c4e32afdf3c6d62507
2019-06-16 08:15:21 +02:00
Linux Build Service Account
26b963c83a Merge "msm: ipa3: Fix to validate check for IP type" 2019-06-11 12:23:55 -07:00
Praveen Kurapati
53f933ef2d msm: ipa3: Fix to validate check for IP type
Add proper check for validating the IP type while
sending request for ul-filter-rule install.

Change-Id: I170230310884f176cf41d5ae20287f6d74a4bc29
Signed-off-by: Praveen Kurapati <pkurapat@codeaurora.org>
2019-06-11 05:08:24 -07:00
Linux Build Service Account
9c3d573678 Merge "dwc3-msm: Fix dwc3_drd_state_string for undefined state" 2019-06-11 04:12:19 -07:00
Linux Build Service Account
ebbd0af9c7 Merge "msm: camera: isp: Fix frame drop pattern" 2019-06-09 18:48:02 -07:00
Linux Build Service Account
84253b6fc6 Merge "asoc: Ratelimit error logs to avoid excessive logging" 2019-06-09 08:03:25 -07:00
Linux Build Service Account
220c735ef4 Merge "msm: ipa: fix to validate input parameters" 2019-06-09 08:03:24 -07:00
Linux Build Service Account
bb646b5795 Merge "msm: mdss: hdmi: fix 4 block EDID read failure" 2019-06-09 08:03:22 -07:00
Linux Build Service Account
1569dc4f6c Merge "msm: mdss: hdmi: parse extended EDID block map" 2019-06-09 00:24:38 -07:00