Protect against memory faults while accessing userspace addresses.
Change-Id: I1433bac73d24d428749558e530e6869c2e5ee98f
Signed-off-by: Patrick Daly <pdaly@codeaurora.org>
A slave timer instance might be still accessible in a racy way while
operating the master instance as it lacks of locking. Since the
master operation is mostly protected with timer->lock, we should cope
with it while changing the slave instance, too. Also, some linked
lists (active_list and ack_list) of slave instances aren't unlinked
immediately at stopping or closing, and this may lead to unexpected
accesses.
This patch tries to address these issues. It adds spin lock of
timer->lock (either from master or slave, which is equivalent) in a
few places. For avoiding a deadlock, we ensure that the global
slave_active_lock is always locked at first before each timer lock.
Also, ack and active_list of slave instances are properly unlinked at
snd_timer_stop() and snd_timer_close().
Last but not least, remove the superfluous call of _snd_timer_stop()
at removing slave links. This is a noop, and calling it may confuse
readers wrt locking. Further cleanup will follow in a later patch.
Actually we've got reports of use-after-free by syzkaller fuzzer, and
this hopefully fixes these issues.
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
(cherry picked from commit b5a663aa426f4884c71cd8580adae73f33570f0d)
Change-Id: I7e7e4e1ab476f93131111d60d8f4e6a1add43193
Signed-off-by: Dennis Cagle <d-cagle@codeaurora.org>
For VOIP case, hardware pointer is always getting incremented
by fixed pcm count. Because of this, hw_ptr is incrementing much
faster than the actual data consumed by DSP. This leads to
pcm_write failure. Fix is to increment hardware pointer by packet
length of frames consumed by DSP for PCM mode
CRs-Fixed: 811744
Change-Id: I1284bdfbf1e74abd126bcb83b8c3dc80e2efc082
Signed-off-by: Shreyas Nagasandra Chandrasekhar <snagas@codeaurora.org>
For Headphone and lineout concurrency scenario,call to enable
buck is made twice.First,while transitioning from IDLE to HPH
and next while moving from HPH to HPH+LO state.But,while disabling
it is called only once while changing state from HPH to IDLE.
This leads to buck_users being non-zero and buck not being
disabled after concurrency usecase.
Specs dont require enabling buck for transition from Headphone
to Headphone+Lineout case.Change made to not enable buck during
this scenario.
Change-Id: I07c51838928c1e177c5b6d2469fe5c527cd78969
Signed-off-by: Shreyas Nagasandra Chandrasekhar <snagas@codeaurora.org>
Handle fake mechanical interrupt during slow insertion of
headset usecase when the plug type is detected as lineout.
CRs-Fixed: 754305
Change-Id: I559309915771b633c6f1677f020459b8afc1f574
Signed-off-by: Sudheer Papothi <spapothi@codeaurora.org>
Signed-off-by: Shreyas Nagasandra Chandrasekhar <snagas@codeaurora.org>
EQ index is copied over from userspace. There's potential risk that
this value can exceed the array boundary. A sanity check for the index
is required.
Change-Id: Ic57a00521119c9fa77dfe0971d58da701092f850
CRs-Fixed: 791363
Signed-off-by: Weiyin Jiang <wjiang@codeaurora.org>
During fast switching of audio playback, we need to wait
for 5ms for the LINE PAs to get settled down before enabling
them again for playback. Same delay is also required after PA
is enabled. Add the required delays after LINE PAs are enabled
or disabled.
Change-Id: Ia4200e0c4bfee3bcd00f0c2f5d1267ea23463f51
Signed-off-by: Shreyas Nagasandra Chandrasekhar <snagas@codeaurora.org>
Re-enable soft pause feature to smooth drastic gain change as to
remove pop noise for offload playback.
Change-Id: Idf5e1044f11a37e1ebcb00e7df5eea2d80552d45
CRs-Fixed: 745564
Signed-off-by: Weiyin Jiang <wjiang@codeaurora.org>
While enabling ANC headset,there is a wrong call to
release firmware in the case of hwdep being used for
codec calibration. The change releases firmware only
in the case of hwdep is not used.
CRs-Fixed: 785739
Change-Id: Ie06dd1e626d24e34d24100054ed413d32e65fe3f
Signed-off-by: Shreyas Nagasandra Chandrasekhar <snagas@codeaurora.org>
Signed-off-by: Rajshekar Eashwarappa <reashw@codeaurora.org>
Due to the difference in usage , this mixer control would
always set the default value of BT SCO Sample Rate as
there is no matching case .
Added change to ensure that the userspace sends the enum
and not the value.
Change-Id: I097b20a4983e7c4eae29e97803e36fcfc14fb8b2
Signed-off-by: Shreyas Nagasandra Chandrasekhar <snagas@codeaurora.org>
Gain controller requires an active clock in order
to programme the gain value.
Register a post power up callback handler with
IIR1 clock and re-apply the IIR1 gain register
value in the callback handler.
Change-Id: Idb0640c411b577662cb56fd5e175f6d08c717920
Signed-off-by: SoumyaManagoli <smanag@codeaurora.org>
The asm loopback driver during close does not check
for NULL before closing the playback and capture
instances.
The change ensures only the valid playback/capture
instances are closed.
CRs-Fixed: 643724
Change-Id: I698d8fb75ce838635ed6dd70eedb6b509b9fcec6
Signed-off-by: Aravind Kumar <akumark@codeaurora.org>
Signed-off-by: Pradosh Das <c_prados@qti.qualcomm.com>
The overflow check is required to ensure that user space data
in kernel may not go beyond buffer boundary.
CRs-Fixed: 563086
Signed-off-by: Asish Bhattacharya <asishb@codeaurora.org>
Signed-off-by: Mohammad Johny Shaik <mjshai@codeaurora.org>
(cherry picked from commit 7e09949355b2dac9aac8bb414037ccaca3c68d86)
Signed-off-by: Pavan Chikkala <pavanc@codeaurora.org>
Change-Id: I4da774740c71b97dc2e4fd16c78bf065ad457690
Signed-off-by: Pavan Chikkala <pavanc@codeaurora.org>
Signed-off-by: Divya Narayanan Poojary <dnaray@codeaurora.org>
If headset is inserted during voice call, the micbias
count is updated. Now on removal of headset, the dapm
widget for force disable of micbias is not called. Due
to this when the headset is inserted again, the count
not updated for headset as force enable dapm widget
will not be called. Make sure to update the count only
in the micbias widget callback function.
CRs-Fixed: 735818
Change-Id: I9e666b19c48a942704471d3fec2d5a4939c973ea
Signed-off-by: Simmi Pateriya <simmip@codeaurora.org>
Issue: When SSR command is issued in the end of stream of
compress offload playback, ANR is seen in music app. Because
EOS is waiting indefinitely and will not return since ADSP is
dead in this case.
Fix is to unblock EOS on reset event callback from DSP.
Change-Id: Ifc379360b0ba7c589c3e2dddb7b2a3c712af7fb0
CRs-Fixed: 731606
Signed-off-by: Divya Narayanan Poojary <dnaray@codeaurora.org>
Start voice command timeout is exceeding 300ms
on ADSP.BF.2.2. Increase it to 500ms to avoid
timeout errors.
CRs-fixed: 681025
Change-Id: I940a55a6cd8444ea3ff6fdba0576d7a1f7e8d98c
Signed-off-by: Karthik Reddy Katta <a_katta@codeaurora.org>
Unblock drain on reset event callback from DSP as drain is
aborted in this case and it should be considered completed
with error.
CRs-Fixed: 731606
Change-Id: Iafc68eb6b75c21635d7ada4c56dd5af0b4b2c233
Signed-off-by: Dhananjay Kumar <dhakumar@codeaurora.org>
Update boundary check in ADM_GET_PARAM response,
the param_size returned from DSP is in number
of bytes, update the same in GET_PARAM_CDM_RSP.
Change-Id: Iac0f0c070a021618499bf8545c455885f2346d6a
Signed-off-by: Ashish Jain <ashishj@codeaurora.org>
Digital mute is enabled as part of the DAPM sequence but unmute
is done through digital mute interface on TX path added in the
codec driver which facilitate soc framework to ensure the
decimator path is unmuted when the stream is started. but this
will not holds good for the ADIE loopback usecases.
Add mixer control to update the loopback status and during
the DAPM sequence based on this status unmute the DEC path as part
of DAPM sequence.
Change-Id: Ia2f83841d0c4fde41627e3ec0bce1eeeee1ebe40
Signed-off-by: Aravind Kumar <akumark@codeaurora.org>
Sending speaker protection calibration for wrong afe port
causes crash in ADSP. This is wrong and kernel should
send the parameters only when mixer controls is explicitly
issued.
Change-Id: I5213a99d989b79feede92b3b50eebf84da41cca8
Signed-off-by: Anish Kumar <kanish@codeaurora.org>
During cases of OCMEM GROW/SHRINK , there is a scope for
map()/unmap() to be called continously.Added a check to avoid
this error condition
Change-Id: If13c9216d0c9daa1cddb22924708dd11f23e54e3
Signed-off-by: Pavan Chikkala <pavanc@codeaurora.org>
Alsa ASoC framework provides mute function to avoid click
and pop in pcm prepare function. Change adds op for
digital mute function in codec driver which will be called
by the asoc frame work when audio usecase is enabled.
Change-Id: I067eec9abd1551281ddb92ded614492d115e3a6e
Signed-off-by: Aravind Kumar <akumark@codeaurora.org>
The tx path currently has the digital hpf switch to
reduce the pop. Add the analog hpf switch as well to reduce
the turn on tx pop level further.
Change-Id: I2eaaea6b25f8781b9e6f2bc70011bbfd2a7796a2
Signed-off-by: Aravind Kumar <akumark@codeaurora.org>
Add Slimbus 3 TX port to the list of valid ports.
Otherwise opening of this port will fail.
CRs-fixed: 682168
Change-Id: I53bdde37afb4c5b0773eff86bfcc45541532e4e7
Signed-off-by: Damir Didjusto <damird@codeaurora.org>
Signed-off-by: Banajit Goswami <bgoswami@codeaurora.org>