Commit Graph
345899 Commits
Author SHA1 Message Date
Vamsi krishna Gattupalli 2c6e06a790 msm:ADSPRPC :Fix to avoid Use after free in fastrpc_internal_munmap
Added a check to validate map before freeing it to avoid Use after
free scenario.

Change-Id: I484391ff7c55c0689530a928a2821ee5a1a0e10c
Signed-off-by: Vamsi krishna Gattupalli <vgattupa@codeaurora.org>
Issue: SEC-2916
(cherry picked from commit 14d4bb80a2adba18b0c4d125dd330fec9f9d4162)
2021-10-10 23:46:48 +02:00
prakash d5edb9b824 msm: vidc: Add support for VUI_DISPLAY_INFO
This is needed to get color primaries, transfer and matrix values from
avc devoder.

Issue: FP2P-432
Issue: FP2P-435
Change-Id: Id1d375c9f6e1c05fc9b8336162bb11cc12d6dea2
2021-10-10 23:46:47 +02:00
Kalesh Singh 3ebffa120f ANDROID: xt_qtaguid: Remove tag_entry from process list on untag
A sock_tag_entry can only be part of one process's
pqd_entry->sock_tag_list. Retagging the socket only updates
sock_tag_entry->tag, and does not add the tag entry to the current
process's pqd_entry list, nor update sock_tag_entry->pid.
So the sock_tag_entry is only ever present in the
pqd_entry list of the process that initially tagged the socket.

A sock_tag_entry can also get created and not be added to any process's
pqd_entry list. This happens if the process that initially tags the
socket has not opened /dev/xt_qtaguid.

ctrl_cmd_untag() supports untagging from a context other than the
process that initially tagged the socket. Currently, the sock_tag_entry is
only removed from its containing pqd_entry->sock_tag_list if the
process that does the untagging has opened /dev/xt_qtaguid. However, the
tag entry should always be deleted from its pqd entry list (if present).

Issue: SEC-2842
Bug: 176919394
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I5b6f0c36c0ebefd98cc6873a4057104c7d885ccc
(cherry picked from commit 8f9138d6c464a60f37f1b293bc61ccbcce6210f6)
2021-10-10 23:46:47 +02:00
Bharath d6fedc0d07 Backport: ANDROID: Add untag hacks to inet_release function
To prevent protential risk of memory leak caused by closing socket with
out untag it from qtaguid module, the qtaguid module now do not hold any
socket file reference count. Instead, it will increase the sk_refcnt of
the sk struct to prevent a reuse of the socket pointer.  And when a socket
is released. It will delete the tag if the socket is previously tagged so
no more resources is held by xt_qtaguid moudle. A flag is added to the untag
process to prevent possible kernel crash caused by fail to delete
corresponding socket_tag_entry list.

Issue: FP2P-307
Test: run cts -m CtsNativeNetTestCases
Change-Id: I163bb06bdbf6aa63503f1f14ec1dd177a72b9df3
(cherry picked from commit b5428181f94bd0d1ff5d321bd58413bdb61f8df4)
2021-10-10 23:46:47 +02:00
bings 155f6cd98d wlan: fix buffer overflow in psessionEntry->pSchBeaconFrameBegin
psessionEntry->pSchBeaconFrameBegin is allocated with fix length
SCH_MAX_BEACON_SIZE. Do not copy the value to the buffer exceeding
psessionEntry->pSchBeaconFrameBegin.

Change-Id: I539692c01753b991a963b0416177cf5b474cfdf8
CRs-Fixed: 2579375
2021-10-10 23:46:47 +02:00
Dundi Raviteja e3b0411e00 wlan: Drop broadcast AMSDU frames
Drop AMSDU subframes if AMSDU subframe header's DA
is equal to broadcast address.

Change-Id: I21f2b95b45fb150a857d23ba158a0f9df15d5c46
CRs-Fixed: 2897293
2021-10-10 23:46:47 +02:00
Dundi Raviteja 460e39033c wlan: Drop invalid AMSDU subframe
Drop AMSDU subframes if AMSDU subframe header's DA
is equal to LLC header.

Change-Id: Ieeb680cd395f275fe2b3bd98afdf4a2e57609b10
CRs-Fixed: 2867994
2021-10-10 23:46:47 +02:00
Dundi Raviteja 43317a0a96 wlan: Drop invalid EAPOL packets in SAP mode
Drop inalid EAPOL packets in SAP mode which are not
destined to self mac address.

Change-Id: I9754dddf580e60bd88ddc6e28355162499a8d125
CRs-Fixed: 2868054
2021-10-10 23:46:47 +02:00
Srinivas Dasari 0feadfa2a1 prima: Send assoc reject upon failing to post ASSOC_IND
Currently, lim silently drops the association if it fails to
post ASSOC_IND due to some reason(e.g. invalid contents of
assoc request) and the MLM state is stuck in
eLIM_MLM_WT_ASSOC_CNF_STATE. Station context is not cleaned up
till the next association. Gracefully cleanup the association
in such failure cases.

Change-Id: I348a7d3ffc537cf89dc311da7bb9846e27635efe
CRs-Fixed: 2857049
2021-10-10 23:46:47 +02:00
Dundi Raviteja e92fee434d wlan: check count variable while removing from list
list_empty() can still return false even if list is not initialized.
so, while removing from list use count variable to check whether
the list is empty or not.

Change-Id: I436ec6df3ef41227563d1efdb528e0444f199390
CRs-Fixed: 2679126
2021-10-10 23:46:47 +02:00
Sourav Mohapatra 4ecd853b71 wlan: Add sanity check for data in ptt_sock_rx_nlink_msg
Currently in the driver, while typecasting the skb data to local
structure in function ptt_sock_proc_reg_req, there can occur a potential
OOB read. The length of the data to be typecasted is not verified
properly.

Add a sanity check to verify that the data being typecasted is of proper
size.

Change-Id: Ib88477a2817649e092e25e21f948c33160dfa09b
CRs-Fixed: 2559499
2021-10-10 23:46:47 +02:00
Gururaj Patil 62e33cb8bb wlan: Avoid int overflow in csr_scan_save_preferred_network_found()
Add validation check on frameLength to avoid int overflow in
csr_scan_save_preferred_network_found function.

Change-Id: I6bcdfb757610152bc801d5134e62dd58629d1e81
CRs-Fixed: 2232358
Signed-off-by: Gururaj Patil <gururaj.patil3@harman.com>
2021-10-10 23:46:47 +02:00
Vignesh Viswanathan 3edcf16d05 wlan: Fix out-of-bounds access in limProcessActionFrameNoSession
Currently in the function limProcessActionFrameNoSession, mem_cmp
is done on the received frame pointer without validating the frame_len
which could lead to out-of-bounds memory access if the frame_len is
not matching the size of action_hdr.

Add check to validate the frame_len with action_hdr size before doing
mem_cmp for the p2p oui.

Change-Id: I39329d1a9ef45614d3c617db11a7a7f5ec2aaaec
CRs-Fixed: 2110756
(cherry picked from commit bc13a475626dbbc7d3bac85f1b020d4ac1724cb6)
2021-10-10 23:46:47 +02:00
sheenam monga 90a589efa3 wlan: Check for minimum frameLen for action frames
Propagation to pronoto from cld2.0.
In limProcessActionFrame and limProcessActionFrameNoSession,
The Rx frame pointer is directly casted to the action frame header
to find the Action frame category and action ID without validating
the minimum length of the frame. If the frame len is less than the
action frame header len, then OOB read would occur.

Check if frame_len is less than the size of action frame header len
and return if true.

Change-Id: Idf8ca7eeacdf57171d2850fe6317784911830aac
CRs-Fixed: 2598901
(cherry picked from commit 382cabdaa5b3d7423600679248e771d285643aae)
2021-10-10 23:46:47 +02:00
Edhar, Mahesh Kumar 0d545e358e MAC: synchronize PE and HDD initiated disconnects
PE generated disassoc request is not serialized in SME queue. This
results in corrupting 'lim.limDisassocDeauthCnfReq.pMlmDisassocReq'
which is a global context to save disassoc request.
Address the above by indicating all the PE generated disassoc requests
to SME and process disconnection request only after receiving
eWNI_SME_DISASSOC_CNF from SME(similar to that of processing disassoc
request from peer).

Change-Id: I2b93925ba64c4d9ff22b071dd2e5c7681be59e15
CRs-Fixed: 934183
(cherry picked from commit 03cf7ff1db9f7ec73b1b0dff42d05e943113f64f)
[FP2: re-apply https://github.com/LineageOS/android_kernel_huawei_msm8916/commit/71b1c1ed51d3d9b79773e7027ff8fb8e0e406e9d]
2021-10-10 23:46:47 +02:00
Abhishek Ambure c623a40841 wlan: Remove off-by-one write condition in sch_beacon_process
In the API, the driver inserts 0 after the SSID name, to mark the
end of the ssid, but if the SSID name is 32 characters which is
the max SSID length possible, the driver puts 0 at the 33rd
place of memory which is not the part of the SSID name, which
results in OOB write, or off-by-one write condition.

Fix is to remove the addition of 0 after ssid, as in every
case the driver prints the ssid, taking the ssid length
as the input, and in that case insertion of 0 will not serve
any purpose.

Change-Id: I1d58026ec9f48fe9d00bd2f50783c65899588978
CRs-Fixed: 2598900
(cherry picked from commit ad65dc9f8a5731d4138ba61f2731f0db3b68bc82)
2021-10-10 23:46:47 +02:00
Karsten Tausche 52500e056f wlan: Hide support for incomplete link layer stats
Link layer stats are not supported as required by CTS, so don't report
support for them.

Undefining WLAN_FEATURE_LINK_LAYER_STATS at build level causes various
build errors, because the flag is not checked properly in all cases or
fall-back implementations are missing. Therefore, instead of disabling
the feature, just hide it from the system instead.

Test: run cts -m CtsStatsdHostTestCases -t android.cts.statsd.atom.HostAtomTests#testWifiActivityInfo
Change-Id: I9d053ff8bdee1352645c3b8f75bfb284f4f0ca05
2021-10-10 23:46:47 +02:00
Stefan Assmann 56ad2ded99 qcacld-2.0: disable link layer stats
Link layer stats triggers firmware timeout.
02-17 21:28:32.793   390   390 E WifiHAL : wifi_get_link_stats: requestResponse Error:-7
02-17 21:28:32.805   567  1525 E WifiVendorHal: getWifiLinkLayerStats(l.937) failed {.code = ERROR_UNKNOWN, .description = , timed out}
They weren't queried before pie, so deal without them.

Unfortunately I didn't find a way to teach wifi HAL not to query this so
the log still gets spammed with
02-19 11:31:10.316   393   393 E WifiHAL : wifi_get_link_stats: requestResponse Error:-3
02-19 11:31:10.320   568  1615 E WifiVendorHal: getWifiLinkLayerStats(l.937) failed {.code = ERROR_NOT_SUPPORTED, .description = }
every few seconds. But at least it doesn't hang the device anymore.

Change-Id: Ia00d19b7384605c6ee6b7b68d441a4616e9816a6
(cherry picked from commit
  LineageOS/android_kernel_cyanogen_msm8974@7b01570045)
2021-10-10 23:46:47 +02:00
Ashish Kumar Dhanotiya 5e0789d479 wlan: Validate assoc response IE len before copy
When host sends assoc response to supplicant, it
allocates a buffer of fixed size and copies a variable
length of assoc response IEs to this fixed sized buffer.
There is a possibility of OOB write to the allocated buffer
if the assoc response IEs length is greater than the
allocated buffer size.
To avoid above issue validate the assoc response IEs length
with the allocated buffer size before data copy to the buffer.

Change-Id: Ib12385e9ff04e5172ae8b505faf959e426fda439
CRs-Fixed: 2616226
(cherry picked from commit 9bb1a72f6ebdf5d2b1a466aec732aa9c5bc37c4d)
2021-10-10 23:46:47 +02:00
Pragaspathi Thilagaraj 714434efb8 wlan: Fix integer overflow in rrm_fill_beacon_ies()
In function rrm_fill_beacon_ies, the total IE length is
calculated as sum of length field of the IE and 2 (element id 1
byte and IE length field 1 byte). The total IE length is defined
of type uint16_t and will overflow if the *(pBcnIes + 1)=0xfe.
Validate the len against total IE length to avoid overflow.

Change-Id: If8f86952ce43c5923906fc6ef18705f1785c5d88
CRs-Fixed: 2617004
(cherry picked from commit 949b1745b9e1ddd8f81960723643cdf10e5f1963)
2021-10-10 23:46:47 +02:00
sheenam monga cbd27d9917 wlan: check BcnNumIes against size of header instead of 0
Currently, for while loop BcnNumIes is checked against 0
which may cause OOB read for len = *(pBcnIes + 1).

Fix is to check BcnNumIes against size of header i.e 2 instead
of 0 to avoid 00B read.

Change-Id: Id167410da790e449d36853d8505142e1b218e9b8
CRs-Fixed: 2635666
(cherry picked from commit 7957db59a545ac43b260401546f4bc72470783df)
2021-10-10 23:46:47 +02:00
Ashish Kumar Dhanotiya 4ca08288d1 wlan: Validate assoc response IE len before copy
When host sends ft assoc response to supplicant, it
allocates a buffer of fixed size and copies a variable
length of assoc response IEs to this fixed sized buffer.
There is a possibility of OOB write to the allocated buffer
if the assoc response IEs length is greater than the
allocated buffer size.
To avoid above issue validate the assoc response IEs length
with the allocated buffer size before data copy to the buffer.

Change-Id: Ife9c2071a8cc4a2918b9f349f4024478f94b2d78
CRs-Fixed: 2616225
(cherry picked from commit c7ea2364eb458e2706b7bae3ed3e70fba7fa56e6)
2021-10-10 23:46:47 +02:00
sheenam monga 92846ca4b6 prima: Protect pHashTable with lock
lim_is_assoc_req_for_drop() uses pHashTable which can be accessed
by peDeleteSession simulataneously. This can lead to crash as
memory for pHashTable can be deleted.

Fix this by protecting usage of pHashTable with a lock.

Change-Id: Iaef7a26d9f3e1ccb76807c9dcf140a6f3de34d8e
CRs-Fixed: 2771345
(cherry picked from commit 0c398c2bd44fd1370eca2b1aa01a80f4675fea13)
2021-10-10 23:46:46 +02:00
Gautam Kumar Shukla 73f11d4d96 cfg80211: add extensible feature flag attribute
*ported from kernel 3.18

With the wiphy::features flag being used up this patch adds a
new field wiphy::ext_features. Considering extensibility this
new field is declared as a byte array. This extensible flag is
exposed to user-space by NL80211_ATTR_EXT_FEATURES.

Cc: Avinash Patil <patila@marvell.com>
Signed-off-by: Gautam (Gautam Kumar) Shukla <gautams@broadcom.com>
Signed-off-by: Arend van Spriel <arend@broadcom.com>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Git-commit: d75bb06b61cb69ee6223d791d3bb230e68623b20
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/jberg/mac80211-next.git
CRs-Fixed: 1098230
Change-Id: Ice288928b17340a571c1acca719325fbf1020072
2021-10-10 23:46:46 +02:00
prototype74 124fa8b668 leds_qpnp: revert to stock
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: Ib4abc82489e14144fdef726df087e41697b2226c
2021-10-10 23:46:31 +02:00
prototype74 d34195fc15 battery: reworked temp table (s3ve3g)
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: I511868ad2d2bc9c55387db7f233a0fd1f6f700e9
2021-10-10 23:46:21 +02:00
prototype74 4582c23f66 dts: reduced full check current 2nd to 100mA
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: I8186c92a3e0e778d2745b394e8e51d4abfa3ddbc
2021-10-10 23:46:10 +02:00
prototype74 5c8a935a11 dts: reworked battery data again (s3ve3g)
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: I08c37023abfa068f337da7531a428ac184c2d428
2021-10-10 23:46:01 +02:00
prototype74 a09bfa321b dts: removed space in s6e8aa0a panel
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: I723ad606124eaf9daa279ba947cf715d399b7b66
2021-10-10 23:45:32 +02:00
prototype74 81ee867ea2 dts: moved mdss stuff to s6e8aa0a display panel
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: Ie774042c61fee9df7d78d5d09fffa10a0ba11970
2021-10-10 23:45:23 +02:00
prototype74 f6fcf56a12 dts: removed rpm-regulator-ldoa27
rpm-regulator-ldoa27 is defined in msm8226-regulator already

Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: I64b33b9e0d38da45a5989b5fc36ec4c12dc8fc2b
2021-10-10 23:45:14 +02:00
prototype74 494b436580 dts: enable channel 27 in vadc
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: I6839d9439211260d7d24fdb9952230fa0052c9d2
2021-10-10 23:44:52 +02:00
prototype74 3f5248db2a dts: changed 3rd seq to 0x7A
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: I8a9aeca2cfaf024940af168d8dc8cb844f6acb8a
2021-10-10 23:44:44 +02:00
prototype74 ee12c7f9e7 dts: cool-bat-decidegc to -10°C
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: I31d60654be6d37ca79dbc50fea7f471650e21d1b
2021-10-10 23:44:35 +02:00
prototype74 c86fdbadc9 dts: reworked battery data (s3ve3g)
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: I97e07395f791b86bf43bf3f2443188c95afc5693
2021-10-10 23:44:27 +02:00
prototype74 29f7257928 defconfig: s3ve3g*: limit MMAP readaround to 32
Change-Id: I30e53bdbd075a0de9a606a7f80c2e4fdfa2e95b2
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
2021-10-10 23:44:19 +02:00
prototype74 9f58f4721b defconfig: s3ve3g*: enable CONFIG_MUIC_SUPPORT_RUSTPROOF
Change-Id: Ia70c5ecdf2d02f4e18e4f71910eb7a3c9b4c5931
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
2021-10-10 23:44:06 +02:00
prototype74 d573257e05 defconfig: s3ve3g*: enable CONFIG_MUIC_SUPPORT_CHARGING_CABLE
Change-Id: I2ab09443659bab5966db06107c2fea8e8776407a
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
2021-10-10 23:43:58 +02:00
prototype74 66e32f3c10 qpnp-bms: updated Battery Monitoring System (BMS)
Note: from official MSM8916 sources
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: I6a0da3dda95ec1db93a99f61871cb243df729864
2021-10-10 23:43:37 +02:00
prototype74 2bab1f3e44 sec_battery: revert to stock
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: I943c727dcb2c47c1c5222903876a569cac3b1fee
2021-10-10 23:43:29 +02:00
prototype74 6c9c01a095 qpnp-charger: enable vddmax adjuster (s3ve3g)
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: I5183986c4e4c2799d13ef2270a30ff178683e12e
2021-10-10 23:43:21 +02:00
Todd Kjos 7d7f1430e4 UPSTREAM: binder: check for overflow when alloc for security context
commit 0b0509508beff65c1d50541861bc0d4973487dc5 upstream.

When allocating space in the target buffer for the security context,
make sure the extra_buffers_size doesn't overflow. This can only
happen if the given size is invalid, but an overflow can turn it
into a valid size. Fail the transaction if an overflow is detected.

Bug: 130571081
Change-Id: Ibaec652d2073491cc426a4a24004a848348316bf
Signed-off-by: Todd Kjos <tkjos@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[haggertk: Backport to 3.4. Omitted return_error_{line,param}]
CVE-2019-2181
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2021-06-27 15:48:11 +02:00
Martijn Coenen 5df7ea671c BACKPORT: binder: Set end of SG buffer area properly.
In case the target node requests a security context, the
extra_buffers_size is increased with the size of the security context.
But, that size is not available for use by regular scatter-gather
buffers; make sure the ending of that buffer is marked correctly.

Bug: 136210786
Acked-by: Todd Kjos <tkjos@google.com>
Fixes: ec74136ded79 ("binder: create node flag to request sender's security context")
Signed-off-by: Martijn Coenen <maco@android.com>
Cc: stable@vger.kernel.org # 5.1+
Link: https://lore.kernel.org/r/20190709110923.220736-1-maco@android.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit a56587065094fd96eb4c2b5ad65571daad32156d)
Change-Id: Icb499a8843814532631de6c12d9709e7540967bf
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2021-06-27 15:48:11 +02:00
Todd Kjos 6f98f7c433 BACKPORT: binder: create node flag to request sender's security context
To allow servers to verify client identity, allow a node
flag to be set that causes the sender's security context
to be delivered with the transaction. The BR_TRANSACTION
command is extended in BR_TRANSACTION_SEC_CTX to
contain a pointer to the security context string.

Bug: 25646100
Change-Id: I0ec053072d6337576680067e07f90dd054b1ecfb
Signed-off-by: Todd Kjos <tkjos@google.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2021-06-27 15:48:11 +02:00
Martijn Coenen 85e80cf26f defconfig: Set CONFIG_BLK_DEV_LOOP_MIN_COUNT to 16.
To have the kernel pre-create 16 loop devices, which will save boot time
as soon as we start having more than 8 APEXes.

Bug: 119022885
Change-Id: I81fcd421fa3ce69c3f1ae150f7aca3cb64320385
Signed-off-by: Martijn Coenen <maco@android.com>
2021-06-27 15:48:11 +02:00
Greg Hackmann e14dccb7c0 alarmtimer: don't rate limit one-shot timers
Commit ff86bf0c65f1 ("alarmtimer: Rate limit periodic intervals") sets a
minimum bound on the alarm timer interval.  This minimum bound shouldn't
be applied if the interval is 0.  Otherwise, one-shot timers will be
converted into periodic ones.

Fixes: ff86bf0c65f1 ("alarmtimer: Rate limit periodic intervals")
Change-Id: I3dd6cb7b5caec3d39b956489448c19d3cda41e5c
Reported-by: Ben Fennema <fennema@google.com>
Signed-off-by: Greg Hackmann <ghackmann@google.com>
Cc: stable@vger.kernel.org
Cc: John Stultz <john.stultz@linaro.org>
Reviewed-by: Thomas Gleixner <tglx@linutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2021-06-19 16:26:29 +02:00
Thomas Gleixner 72843fac81 alarmtimer: Rate limit periodic intervals
commit ff86bf0c65f14346bf2440534f9ba5ac232c39a0 upstream.

The alarmtimer code has another source of potentially rearming itself too
fast. Interval timers with a very samll interval have a similar CPU hog
effect as the previously fixed overflow issue.

The reason is that alarmtimers do not implement the normal protection
against this kind of problem which the other posix timer use:

  timer expires -> queue signal -> deliver signal -> rearm timer

This scheme brings the rearming under scheduler control and prevents
permanently firing timers which hog the CPU.

Bringing this scheme to the alarm timer code is a major overhaul because it
lacks all the necessary mechanisms completely.

So for a quick fix limit the interval to one jiffie. This is not
problematic in practice as alarmtimers are usually backed by an RTC for
suspend which have 1 second resolution. It could be therefor argued that
the resolution of this clock should be set to 1 second in general, but
that's outside the scope of this fix.

Change-Id: Iad8d71a3136cf397b75a541720ebbfbc4152dd31
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Kostya Serebryany <kcc@google.com>
Cc: syzkaller <syzkaller@googlegroups.com>
Cc: John Stultz <john.stultz@linaro.org>
Cc: Dmitry Vyukov <dvyukov@google.com>
Link: http://lkml.kernel.org/r/20170530211655.896767100@linutronix.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2021-06-19 16:26:21 +02:00
Guenter Roeck c002055e92 UPSTREAM: timer: Export destroy_hrtimer_on_stack()
hrtimer_init_on_stack() needs a matching call to
destroy_hrtimer_on_stack(), so both need to be exported.

Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit c08376ac97cb202ec65320f3d90d5c4c5e2adb0b)
[astrachan: Fixes i386-allmodconfig build failure in vsoc.ko noticed
 by 01.org kbuild-all project building kernel/msm]
Bug: 70214720
Change-Id: If4d5c466255019322ea21ef38ee5b1b382cce969
Signed-off-by: Alistair Strachan <astrachan@google.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2021-06-19 16:26:11 +02:00
Anna-Maria Gleixner ead1cb2215 hrtimer: Ensure POSIX compliance (relative CLOCK_REALTIME hrtimers)
commit 48d0c9becc7f3c66874c100c126459a9da0fdced upstream.

The POSIX specification defines that relative CLOCK_REALTIME timers are not
affected by clock modifications. Those timers have to use CLOCK_MONOTONIC
to ensure POSIX compliance.

The introduction of the additional HRTIMER_MODE_PINNED mode broke this
requirement for pinned timers.

There is no user space visible impact because user space timers are not
using pinned mode, but for consistency reasons this needs to be fixed.

Check whether the mode has the HRTIMER_MODE_REL bit set instead of
comparing with HRTIMER_MODE_ABS.

Change-Id: Ib186c3983c6f66fb4000d85fd5ec09b702a033ab
Signed-off-by: Anna-Maria Gleixner <anna-maria@linutronix.de>
Cc: Christoph Hellwig <hch@lst.de>
Cc: John Stultz <john.stultz@linaro.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: keescook@chromium.org
Fixes: 597d027573 ("timers: Framework for identifying pinned timers")
Link: http://lkml.kernel.org/r/20171221104205.7269-7-anna-maria@linutronix.de
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: Mike Galbraith <efault@gmx.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2021-06-19 16:26:01 +02:00
Thomas Gleixner a6e5b4f946 hrtimer: Reset hrtimer cpu base proper on CPU hotplug
commit d5421ea43d30701e03cadc56a38854c36a8b4433 upstream.

The hrtimer interrupt code contains a hang detection and mitigation
mechanism, which prevents that a long delayed hrtimer interrupt causes a
continous retriggering of interrupts which prevent the system from making
progress. If a hang is detected then the timer hardware is programmed with
a certain delay into the future and a flag is set in the hrtimer cpu base
which prevents newly enqueued timers from reprogramming the timer hardware
prior to the chosen delay. The subsequent hrtimer interrupt after the delay
clears the flag and resumes normal operation.

If such a hang happens in the last hrtimer interrupt before a CPU is
unplugged then the hang_detected flag is set and stays that way when the
CPU is plugged in again. At that point the timer hardware is not armed and
it cannot be armed because the hang_detected flag is still active, so
nothing clears that flag. As a consequence the CPU does not receive hrtimer
interrupts and no timers expire on that CPU which results in RCU stalls and
other malfunctions.

Clear the flag along with some other less critical members of the hrtimer
cpu base to ensure starting from a clean state when a CPU is plugged in.

Thanks to Paul, Sebastian and Anna-Maria for their help to get down to the
root cause of that hard to reproduce heisenbug. Once understood it's
trivial and certainly justifies a brown paperbag.

Fixes: 41d2e49493 ("hrtimer: Tune hrtimer_interrupt hang logic")
Change-Id: I707de358bcc70a980dc4bd581c159a30e01cce41
Reported-by: Paul E. McKenney <paulmck@linux.vnet.ibm.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Sebastian Sewior <bigeasy@linutronix.de>
Cc: Anna-Maria Gleixner <anna-maria@linutronix.de>
Cc: stable@vger.kernel.org
Link: https://lkml.kernel.org/r/alpine.DEB.2.20.1801261447590.2067@nanos
[bigeasy: backport to v3.18, drop ->next_timer it was introduced later]
Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2021-06-19 16:25:51 +02:00