Check if the handle data type received from userspace is valid
for app loaded query request to avoid the offset boundary check
for qseecom_send_modfd_resp is bypassed.
Bug: 143972932
Change-Id: I5f3611a8f830d6904213781c5ba70cfc0ba3e2e0
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
CVE-2019-14041
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
When unloading the app, reset all client members to NULL
to protect from accessing the memory after being freed.
Bug: 143973884
Change-Id: I573b9c6fde03539522d2b04724a2246660c62518
Signed-off-by: jitendra thakare <jitendrathakare@codeaurora.org>
CVE-2019-14040
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
To avoid access of variable after being freed, using
list_first_entry_safe function to iterate over list
of given type, safe against removal of list entry.
Change-Id: I70611fddf3e9b80b1affa3e5235be24eac0d0a58
Signed-off-by: Monika Singh <monising@codeaurora.org>
CVE-2018-11988
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
* Guards of sec_debug.h include removed in those files that call
functions declared in that header. The header defines empty
functions when CONFIG_SEC_DEBUG is not defined.
* Expose extern declaration of sec_class in qpnp-power-on.c when
CONFIG_SEC_DEBUG is not defined.
* Guard debug level sysfs tuneables.
Change-Id: I4e8b1ae7dd1dce0dec5434da64832165b2659aff
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Make change in __qseecom_load_fw() and qseecom_load_commonlib_image()
to check buffer size before copying img to buffer.
CRs-fixed: 1080290
CAF-Change-Id: I0f48666ac948a9571e249598ae7cc19df9036b1d
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
CVE-2017-0614
Change-Id: Ib75dfe5ece9959e6fbbd571ef0d49485a0c8d947
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Make change to improve input validation on request and response
buffers' address and length for qseecom_send_service_cmd.
CAF-Change-Id: I047e3264333d767541e43b7dadd1727232fd48ef
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
[haggertk]: Backport to 3.4/msm8974
CVE-2017-0613
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: Ida2babcd9d0ad6308f39b1b8389352b45d179664
Check if there is no integer overflow before using req_len and
resp_len (received from user space). If an overflow is detected
then exit the operation.
Change-Id: I0459a6992bb3b280db42be63a275c55fa6105b1c
Signed-off-by: Hariprasad Dhalinarasimha <hnamgund@codeaurora.org>
CVE-2014-9787
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Modify the request_module to prefix the file system type with "fs-"
and add aliases to all of the filesystems that can be built as modules
to match.
A common practice is to build all of the kernel code and leave code
that is not commonly needed as modules, with the result that many
users are exposed to any bug anywhere in the kernel.
Looking for filesystems with a fs- prefix limits the pool of possible
modules that can be loaded by mount to just filesystems trivially
making things safer with no real cost.
Using aliases means user space can control the policy of which
filesystem modules are auto-loaded by editing /etc/modprobe.d/*.conf
with blacklist and alias directives. Allowing simple, safe,
well understood work-arounds to known problematic software.
This also addresses a rare but unfortunate problem where the filesystem
name is not the same as it's module name and module auto-loading
would not work. While writing this patch I saw a handful of such
cases. The most significant being autofs that lives in the module
autofs4.
This is relevant to user namespaces because we can reach the request
module in get_fs_type() without having any special permissions, and
people get uncomfortable when a user specified string (in this case
the filesystem type) goes all of the way to request_module.
After having looked at this issue I don't think there is any
particular reason to perform any filtering or permission checks beyond
making it clear in the module request that we want a filesystem
module. The common pattern in the kernel is to call request_module()
without regards to the users permissions. In general all a filesystem
module does once loaded is call register_filesystem() and go to sleep.
Which means there is not much attack surface exposed by loading a
filesytem module unless the filesystem is mounted. In a user
namespace filesystems are not mounted unless .fs_flags = FS_USERNS_MOUNT,
which most filesystems do not set today.
Change-Id: I623b13dbdb44bb9ba7481f29575e1ca4ad8102f4
Acked-by: Serge Hallyn <serge.hallyn@canonical.com>
Acked-by: Kees Cook <keescook@chromium.org>
Reported-by: Kees Cook <keescook@google.com>
Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
When I use several fast SSD to do swap, swapper_space.tree_lock is
heavily contended. This makes each swap partition have one
address_space to reduce the lock contention. There is an array of
address_space for swap. The swap entry type is the index to the array.
In my test with 3 SSD, this increases the swapout throughput 20%.
[akpm@linux-foundation.org: revert unneeded change to __add_to_swap_cache]
Signed-off-by: Shaohua Li <shli@fusionio.com>
Cc: Hugh Dickins <hughd@google.com>
Acked-by: Rik van Riel <riel@redhat.com>
Acked-by: Minchan Kim <minchan@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Change-Id: I8ad2d301866b2873562a46df2952cf562b2b5aab
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Register the app in qseecom driver if it has been already loaded
by appsbl before
Change-Id: Iec39137a7e18dc703c731e55955ab84d1b9c97f3
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
Signed-off-by: Shreyas Narayan <shrena@codeaurora.org>
Converting cputime_t to usec caused overflow when the value is greater
than 1 hour. Use msec and convert to unsigned long long to support bigger
range.
Bug: 22461683
Change-Id: I853fe3e8e7dbf0d3e2cc5c6f9688a5a6e1f1fb3e
Signed-off-by: Jin Qian <jinqian@google.com>
Git-commit: 73f7982c2bc8590fa63b9f5e308b9dda27701bf9
Git-repo: https://android.googlesource.com/kernel/msm/
Signed-off-by: Srinivasarao P <spathi@codeaurora.org>
This avoids the race where a particular process is terminating and we
read the show_uid_stats. At this time since the task_struct still exists
and we will account for the terminating process as one of the active
task, where as the stats would have been added in the task exit
callback.
Bug: 22064385
Change-Id: Id2ae04b33fcd230eda9683a41b6019d4dd8f5d85
Signed-off-by: Jin Qian <jinqian@google.com>
Signed-off-by: Ruchi Kandoi <kandoiruchi@google.com>
Git-commit: 42ec52850c400aca1c67da166c11a7ea256c7884
Git-repo: https://android.googlesource.com/kernel/msm/
Signed-off-by: Srinivasarao P <spathi@codeaurora.org>
/proc/uid_cputime/show_uid_stats shows a third field power for each of
the uids. It represents the power in the units (uAusec)
Bug: 21498425
Change-Id: I52fdc5e59647e9dc97561a26d56f462a2689ba9c
Signed-off-by: Ruchi Kandoi <kandoiruchi@google.com>
Git-commit: d17e7e2771a3998c2514de082be588522625618e
Git-repo: https://android.googlesource.com/kernel/msm/
Signed-off-by: Srinivasarao P <spathi@codeaurora.org>
Do not send app regin notification if qseecom in appsbl has
already done it
Change-Id: I81ae9a991a5d8ec582d9320e18be1b6f8e8ee7fd
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
While back-porting commit 3aaf46626af5875372d625644759c570a1515c3f
from upstream to 3.4 kernel, argument mismatch is seen for hash
functions. Fixed this by sending correct number of arguments.
And also added equivalent functionality for undefined functions
and macros like task_cputime_adjusted()
Change-Id: I862cfb9b5212cc960571a8e072bda3c034cf0873
Signed-off-by: Srinivasarao P <spathi@codeaurora.org>
Adds proc files /proc/uid_cputime/show_uid_stat and
/proc/uid_cputime/remove_uid_range.
show_uid_stat lists the total utime and stime for the active as well as
terminated processes for each of the uids.
Writing a range of uids to remove_uid_range will delete the accounting
for all the uids within that range.
Change-Id: Ibaf562c66fef82c3a4d793c67e52e100d5f803a4
Signed-off-by: Jin Qian <jinqian@google.com>
Git-commit: 3aaf46626af5875372d625644759c570a1515c3f
Git-repo: https://android.googlesource.com/kernel/common/
[nabrah@codeaurora.org: Resolved trivial merge conflicts]
Signed-off-by: Nirmal Abraham <nabrah@codeaurora.org>
Signed-off-by: Srinivasarao P <spathi@codeaurora.org>
When multiple processes called qseecom_release() to close /dev/qseecom
at almost the same time, and one process succeeded to unload app and
released resource, null pointer exception would occurr on another process.
So make change to add mutex_lock/mutex_unlock for qseecom_unload_app
in qseecom_release.
Change-Id: Ie7cf61b1d3ea5339ea79e0f7637ca610969e3d6c
CRs-fixed: 849916
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
Prints been added to the driver to understand the call flow
while executing the applications, which is required only for
debugging not in normal execution flow. This patch change
the pr_info messages to pr_debug messages to remove the
excessive logging during normal work flow.
Change-Id: Ic2223c1d570dcd2d74d26fa09f9b68362bebef23
Signed-off-by: AnilKumar Chimata <anilc@codeaurora.org>
Change memcpy to strlcpy to only copy the string for app_name.
Change-Id: I46cf34c2d2fdbf24e9e65008555f762761c81dd7
Signed-off-by: William Clark <wclark@codeaurora.org>
We've made changes on app session managements to save app name in
qseecom when loading app by userspace client. This change is to save
app name when loading app by kernel client, then qseecom can compare
the app name correctly when sending commands to TZ.
CRs-Fixed: 748491
Change-Id: I341a1a89f0e8a45056be7a5ce0a6a540842bc5dd
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
Improve user input validation across send cmd APIs. Add new
API __validate_send_cmd_inputs() to validate all user provided
inputs.
Change-Id: Ibbb0c0e7e5483f653bd59b927562b63c1e43c365
Signed-off-by: Mona Hossain <mhossain@codeaurora.org>
Qseecom driver does not have boundary checks for offset within the
message. So this patch add checks to validate the offsets sent by
client to modify data within the command request message and it
should not exceed the memory allocated for that message.
Change-Id: I29bfbdc154eebb4f3f4bfbb31789562e37fa5886
Signed-off-by: Mona Hossain <mhossain@codeaurora.org>
Signed-off-by: Mallikarjuna Reddy Amireddy <mamire@codeaurora.org>
Make a change to free the ion memory allocated for keymaster client
even if keymaster app doesn't need to be unloaded from TZ, so as to
avoid memory leak.
CRs-Fixed: 724638
Change-Id: I3ddb68c8a3f96b0a44afc3efc63e93f0a8be51bb
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
In current qseecom_suspend function, qseecom will scale down bus
bandwidth if both of accumultive mode and current mode are not
INACTIVE. But if device goes into suspend before bus scaling timeout
happens, the accumulative mode may be zero but current mode is
still not INACTIVE. This may prevent the device going to suspend,
thus, make a change to just check current bus scaling mode in
qseecom_suspend.
CRs-Fixed: 740287
Change-Id: I60e90000aa9efe428b144fb766e19e81312af66f
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
Make a change to fix secure app loading failure due to premature
kzfree() from __qseecom_load_fw(), when kernel mode qseecom client
tries to load app.
CRs-fixed: 694541
Change-Id: I1ac39ee885c12e08e863d976321dda2380ace852
Signed-off-by: William Clark <wclark@codeaurora.org>
To avoid the service failure on a target where bus scaling flag is not
enabled in target device tree file by mistake, make a change to enable/
disable crypto clocks when the client calls to scale up bus bandwidth
and send command even if bus scaling feature is not enabled.
CRs-Fixed: 726840
Change-Id: Ib33a535051b68561bde5ab6a23ad0f02dc27ab13
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
Make change to check if ce clock is enabled before sending command
to TZ, then to prevent data aborting if clock is not enabled for
TZ crypto operation.
CRs-Fixed: 726840
Change-Id: I55b5b10ad80e741c39f8cf411f67e6b83887f3bb
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
keymaster app has two names with different length: "keymaster" and
"keymaste". To compare the app names correctly, the shorter name
length is choosen for memcmp in __qseecom_send_cmd.
Change-Id: I5f0dff7f9756362be40cc64985b65bc2268d734f
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
Signed-off-by: William Clark <wclark@codeaurora.org>
Media server is associated with multiple apps on TZ-side.
Unloading a single app for clean up is not enought. QSEECOM
needs to handle the app load & unload of multiple apps
associated with the client. During app_load & app_unload
along with app_id, app_name should also be checked. Besides,
keymaster will not be unloaded and app search execution
during app unload is optimized.
Change-Id: Ie92e97b9154851b713a8c3394b8ed10fdbdebd2f
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
Signed-off-by: William Clark <wclark@codeaurora.org>
Currently qseecom will return the app_id (>0) instead of 0 if the
app id already exists when loading app. Then the userspace client
will release qseecom handle if an non-zero return value is obtained.
Make a change to let qseecom return 0 when app id exist so as to
avoid the incorrect qseecom release.
Change-Id: I03b0b0ae95b2e043fda972aa3b613e7df585154a
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
Registering and resetting BAM device upon initialization of tspp
driver requests bam irq resource, which prevents entering sleep.
Instead, BAM device is now initialized only when first needed which
is when the first channel is opened. BAM device is uninitialized
when channel is closed.
Change-Id: I056acea721fae164b91a2a5e3946028b4c2b6df2
Signed-off-by: Gilad Broner <gbroner@codeaurora.org>
The qseecom_wipe_key() api allows both FDE and PFE usage,
It is calling __qseecom_delete_saved_key() api
that should also allow both.
Change-Id: I2ae583977e7e4958e6dd8a939af74ac62a147895
Signed-off-by: Amir Samuelov <amirs@codeaurora.org>
The tspp driver keeps a list of all the buffers and their current
state. When interrupt occurs to signal new data is available some
buffers state is updated. tspp_get_buffer and tspp_release_buffer
also change the state of buffers. This change adds locking in these
functions to protect against concurrent update which may lead to
an invalid state.
Change-Id: I6331a49bcd0a57e6b9ef8c3860bf8ca9d0e0190b
Signed-off-by: Gilad Broner <gbroner@codeaurora.org>
qseecom.cumulative_mode is used to track the cummulative bus request
mode from all concurrent running clients. It is registered before
send_cmd operation, but is not un-registered after it is complete.
This may cause the bus bandwidth is restored to a wrong mode after
resuming from sleep. Thus, we make change to update it accordingly.
qseecom.current_mode is also updated in suspend/resume function to
ensure timer can scale down bus bw after resume when cumulative_mode
is non-zero. Besides, timer operation is optimized in case there are
multiple unserialized concurrent users of the same timer.
Change-Id: I06043d2b88a47e24da03460fe1ae26a94cb6a608
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
When there are multiple running qseecom clients, ce clock may be disabled
by one client while TZ is still loading another client's app, which will
lead to load app failure. So, we make a change to register bus bandwidth
mode before loading app and avoid to disable clock when current bandwidth
mode is not INACTIVE.
Change-Id: I1727f6fc038baf95da39089e1f0faefe42f3d40c
Signed-off-by: Zhen Kong <zkong@codeaurora.org>