There is no return statement in case of invalid sequence length in
__wlan_hdd_cfg80211_add_key api.
Return an error code in case of invalid seq_len.
Issue: SEC-1245
Change-Id: Ib240f6cf91d9d563dd87148c15e06ae8b48919d5
CRs-Fixed: 2153553
(adapted from commit https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/prima
5a0eeb72c3cde7dcb8096967561a88a678ad9aec)
propagation from qcacld-3.0 to prima
Currently the key sequence counter received from userspace is not
propagated to SME, so add logic to propagate it.
Issue: SEC-1245
Change-Id: I5371700003744eb967c578c44e4d130628efcdc8
CRs-Fixed: 2134583
(adapted from commit https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/prima
6a2b6756bad53d057cd3cb7856b9184d0011e1e0)
During initializing ibss security settings there is a possibility
of integer underflow while extracting wpa ie because of ie length
check miss.
Add wpa ie length boundary check before extracting wpa ie.
Issue: SEC-1249
Change-Id: I37d8ee5ea1e1ba12277128a1407783f5647251b6
CRs-Fixed: 2151241
(adapted from commit https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0
27381e9d253629180dcdaa698d3fd01bec28d351)
propagation from qcacld-3.0 to prima.
Currently sizeof(struct ieee80211_mgmt) + IE len is used to calculate
the total frame length to send the beacon/probe to kernel.
struct ieee80211_mgmt contains union to define different frames and
thus the sizeof(struct ieee80211_mgmt) may give extra length for
beacon/probe if any of the union size is greater than the probe/beacon
union size. This result in trail of zeroes at the end of the frame.
To fix this use sizeof(mgmt_mac_header) + SIR_MAC_B_PR_SSID_OFFSET +
ie len to determine the exact size of the frame.
Change-Id: I71e94b111f36fcd4060befcae282f1fcce5e17f1
CRs-Fixed: 2251716
Currently there are multiple cfg80211 vendor commands where MAC
address attributes are defined in a nla_policy table with a type of
NLA_UNSPEC but without a minimum length. Add the proper minimum length
to avoid buffer overread.
Change-Id: I11e1205943147102a536ca462fbdba7c826dd195
CRs-Fixed: 2061251
[GabrieleM: Partially applied with 3617aa44129c503af51f4f0537b9c6866]
Add changes to expose dump stack functionality which can be used
by driver to dump stack information when it requires
CR Fixed: 943322
Change-Id: I0fde7142dea2c18daf6b1fb0c5ee4bb8a31a6be0
Signed-off-by: Padma, Santhosh Kumar <skpadma@codeaurora.org>
Signed-off-by: Pradosh Das <prados@codeaurora.org>
Several build configurations had already disabled this warning because
it generates a lot of false positives. But some had not, and it was
still enabled for "allmodconfig" builds, for example.
Looking at the warnings produced, every single one I looked at was a
false positive, and the warnings are frequent enough (and big enough)
that they can easily hide real problems that you don't notice in the
noise generated by -Wmaybe-uninitialized.
The warning is good in theory, but this is a classic case of a warning
that causes more problems than the warning can solve.
If gcc gets better at avoiding false positives, we may be able to
re-enable this warning. But as is, we're better off without it, and I
want to be able to see the *real* warnings.
Change-Id: Ie810d255be8911c413c9abe6965a9a66639a1dce
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
* The function prototype for this function has become :
int mdss_panel_dt_get_dst_fmt(u32 bpp, char mipi_mode, u32 pixel_packing,char *dst_format);
in the latest source drop
In this API, we were using sizeof operator for an array
given as function argument, which is invalid.
However this API is not used anywhere.
Change-Id: I80a43472b35f0f6c117624de2b2907b37eefb786
Signed-off-by: Syam Sidhardhan <s.syam@samsung.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
The pagetable.entries statistics should be incremented by 1
and not the size of the entire mapping.
CRs-Fixed: 911514
Change-Id: Ic9acb6a43a76ee0c429c439e60cbd2a6846647db
Signed-off-by: Harshdeep Dhatt <hdhatt@codeaurora.org>
While back-porting commit 3aaf46626af5875372d625644759c570a1515c3f
from upstream to 3.4 kernel, argument mismatch is seen for hash
functions. Fixed this by sending correct number of arguments.
And also added equivalent functionality for undefined functions
and macros like task_cputime_adjusted()
Change-Id: I862cfb9b5212cc960571a8e072bda3c034cf0873
Signed-off-by: Srinivasarao P <spathi@codeaurora.org>
Adds proc files /proc/uid_cputime/show_uid_stat and
/proc/uid_cputime/remove_uid_range.
show_uid_stat lists the total utime and stime for the active as well as
terminated processes for each of the uids.
Writing a range of uids to remove_uid_range will delete the accounting
for all the uids within that range.
Change-Id: Ibaf562c66fef82c3a4d793c67e52e100d5f803a4
Signed-off-by: Jin Qian <jinqian@google.com>
Git-commit: 3aaf46626af5875372d625644759c570a1515c3f
Git-repo: https://android.googlesource.com/kernel/common/
[nabrah@codeaurora.org: Resolved trivial merge conflicts]
Signed-off-by: Nirmal Abraham <nabrah@codeaurora.org>
Signed-off-by: Srinivasarao P <spathi@codeaurora.org>
This hashtable implementation is using hlist buckets to provide a simple
hashtable to prevent it from getting reimplemented all over the kernel.
Signed-off-by: Sasha Levin <levinsasha928@gmail.com>
[ Merging this now, so that subsystems can start applying Sasha's
patches that use this - Linus ]
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Change-Id: Id3aa808a5096eb4ed0e73b5db8252819cc7eb666
Git-commit: d9b482c8ba1973a189f2d4c8175d405b87fbf2d7
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
Signed-off-by: Srinivasarao P <spathi@codeaurora.org>
Enables uid_cputime functionality which provides
the total time a UID's processes spend in userspace
and kernel space.
Change-Id: Ibba4502dacaf211b6c955b9d0bfc7f6370b2a9fe
Signed-off-by: Nirmal Abraham <nabrah@codeaurora.org>
Signed-off-by: Srinivasarao P <spathi@codeaurora.org>
Security server omits the type field when writing out the contents of the
avtab from /sys/fs/selinux/policy. This leads to a corrupt output. No impact
on the running kernel or its loaded policy. Impacts CTS neverallow tests.
Bug: 20665861
Change-Id: I657e18013dd5a1f40052bc2b02dd8e0afee9bcfb
Signed-off-by: Jeff Vander Stoep <jeffv@google.com>
Git-commit: 8cdfb356b51e29494ca0b9e4e86727d6f841a52d
Git-repo: https://bitbucket.org/seandroid/kernel-common.git
Signed-off-by: Ravi Kumar Siddojigari <rsiddoji@codeaurora.org>
- This reverts commit 1e3bae22f3.
- Changing gcc toolchain to 4.9 version.
- Fix linker error of unknown CPU architecture by
adding CONFIG_MSM_CORTEX_A7 in the arch options
for the GCC. The issue is seen after bump up to
gcc-4.9.
- Fix section mismatch errors after upgrading gcc to 4.9
version. To fix these errors variables are moved to
appropriate sections.
Change-Id: I7b5c9212e63826a0cb5b7e4ab161737ae87a2157
Signed-off-by: Samir Mehta <samirn@codeaurora.org>
Removing copyright and license information from
rmnet_ipa_fd_ioctl.h and ipa_qmi_service_v01.h header files
since these can be exported to user space.
Change-Id: I3535f81c29b888e8ebcbcb32dcba9f0f08b64485
Signed-off-by: Ravinder Konka <rkonka@codeaurora.org>
Include IPA headers required for compilation on
8974/8226
Change-Id: Iba7a211adafe4616327fa00b9b727be1281501a5
Signed-off-by: Ravinder Konka <rkonka@codeaurora.org>
Assign a unique proc inode to each namespace, and use that
inode number to ensure we only allocate at most one proc
inode for every namespace in proc.
A single proc inode per namespace allows userspace to test
to see if two processes are in the same namespace.
This has been a long requested feature and only blocked because
a naive implementation would put the id in a global space and
would ultimately require having a namespace for the names of
namespaces, making migration and certain virtualization tricks
impossible.
We still don't have per superblock inode numbers for proc, which
appears necessary for application unaware checkpoint/restart and
migrations (if the application is using namespace file descriptors)
but that is now allowd by the design if it becomes important.
I have preallocated the ipc and uts initial proc inode numbers so
their structures can be statically initialized.
Change-Id: I01d42c2f051fd74b1474d9d8378ccc78174cf3cf
Signed-off-by: Eric W. Biederman <ebiederm@xmission.com>
Git-commit: f80cd4676998eb352d1a8b9df0f3663537a9ce93
Git-repo: https://android.googlesource.com/kernel/common/
[schikk@codeaurora.org: Resolved merge conflicts ]
CRs-Fixed: 901628
Signed-off-by: Swetha Chikkaboraiah <schikk@codeaurora.org>
Change the proc namespace files into symlinks so that
we won't cache the dentries for the namespace files
which can bypass the ptrace_may_access checks.
To support the symlinks create an additional namespace
inode with it's own set of operations distinct from the
proc pid inode and dentry methods as those no longer
make sense.
Change-Id: Id7d7e0155ef5961778ad339b34f859bc39f4a5aa
Signed-off-by: Eric W. Biederman <ebiederm@xmission.com>
Git-commit: 98c3155c5e3639ca968f948112cb4a50edc86341
Git-repo: https://android.googlesource.com/kernel/common/
CRs-Fixed: 901628
Signed-off-by: Swetha Chikkaboraiah <schikk@codeaurora.org>
Generalize the proc inode allocation so that it can be
used without having to having to create a proc_dir_entry.
This will allow namespace file descriptors to remain light
weight entitities but still have the same inode number
when the backing namespace is the same.
Change-Id: I647fe594d3cd25735d4cfcee62a89ad5991b1304
Acked-by: Serge E. Hallyn <serge.hallyn@ubuntu.com>
Signed-off-by: Eric W. Biederman <ebiederm@xmission.com>
Git-commit: d25167f07ae914bb824da2e5a661d1848afb19d1
Git-repo: https://android.googlesource.com/kernel/common/
CRs-Fixed: 901628
Signed-off-by: Swetha Chikkaboraiah <schikk@codeaurora.org>