https://source.android.com/docs/security/bulletin/2022-12-01 CVE-2022-23960 * tag 'ASB-2022-12-05_11-5.4' of https://android.googlesource.com/kernel/common: UPSTREAM: bpf: Ensure correct locking around vulnerable function find_vpid() UPSTREAM: HID: roccat: Fix use-after-free in roccat_read() ANDROID: arm64: mm: perform clean & invalidation in __dma_map_area UPSTREAM: mmc: hsq: Fix data stomping during mmc recovery UPSTREAM: pinctrl: sunxi: Fix name for A100 R_PIO BACKPORT: mmc: core: Fix UHS-I SD 1.8V workaround branch UPSTREAM: Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm regression UPSTREAM: wifi: mac80211_hwsim: set virtio device ready in probe() BACKPORT: f2fs: don't use casefolded comparison for "." and ".." UPSTREAM: Revert "mm/cma.c: remove redundant cma_mutex lock" UPSTREAM: usb: dwc3: Try usb-role-switch first in dwc3_drd_init BACKPORT: usb: typec: ucsi: Fix reuse of completion structure BACKPORT: tipc: fix incorrect order of state message data sanity check UPSTREAM: net: fix up skbs delta_truesize in UDP GRO frag_list UPSTREAM: cgroup-v1: Correct privileges check in release_agent writes UPSTREAM: mm: don't try to NUMA-migrate COW pages that have other uses UPSTREAM: usb: raw-gadget: fix handling of dual-direction-capable endpoints UPSTREAM: selinux: check return value of sel_make_avc_files UPSTREAM: usb: musb: select GENERIC_PHY instead of depending on it BACKPORT: driver core: Fix error return code in really_probe() UPSTREAM: fscrypt: fix derivation of SipHash keys on big endian CPUs BACKPORT: fscrypt: rename FS_KEY_DERIVATION_NONCE_SIZE UPSTREAM: socionext: account for napi_gro_receive never returning GRO_DROP UPSTREAM: net: socionext: netsec: fix xdp stats accounting BACKPORT: fs: align IOCB_* flags with RWF_* flags UPSTREAM: efi: capsule-loader: Fix use-after-free in efi_capsule_write BACKPORT: ARM: 9039/1: assembler: generalize byte swapping macro into rev_l BACKPORT: ARM: 9035/1: uncompress: Add be32tocpu macro UPSTREAM: drm/meson: Fix overflow implicit truncation warnings UPSTREAM: irqchip/tegra: Fix overflow implicit truncation warnings UPSTREAM: video: fbdev: pxa3xx-gcu: Fix integer overflow in pxa3xx_gcu_write ANDROID: GKI: db845c: Update symbols list and ABI Linux 5.4.219 wifi: mac80211: fix MBSSID parsing use-after-free wifi: mac80211: don't parse mbssid in assoc response mac80211: mlme: find auth challenge directly Revert "fs: check FMODE_LSEEK to control internal pipe splicing" Linux 5.4.218 Input: xpad - fix wireless 360 controller breaking after suspend Input: xpad - add supported devices as contributed on github wifi: cfg80211: update hidden BSSes to avoid WARN_ON wifi: mac80211_hwsim: avoid mac80211 warning on bad rate wifi: cfg80211: avoid nontransmitted BSS list corruption wifi: cfg80211: fix BSS refcounting bugs wifi: cfg80211: ensure length byte is present before access wifi: cfg80211/mac80211: reject bad MBSSID elements wifi: cfg80211: fix u8 overflow in cfg80211_update_notlisted_nontrans() random: use expired timer rather than wq for mixing fast pool random: avoid reading two cache lines on irq randomness random: restore O_NONBLOCK support USB: serial: qcserial: add new usb-id for Dell branded EM7455 scsi: stex: Properly zero out the passthrough command structure efi: Correct Macmini DMI match in uefi cert quirk ALSA: hda: Fix position reporting on Poulsbo random: clamp credited irq bits to maximum mixed ceph: don't truncate file in atomic_open nilfs2: replace WARN_ONs by nilfs_error for checkpoint acquisition failure nilfs2: fix leak of nilfs_root in case of writer thread creation failure nilfs2: fix NULL pointer dereference at nilfs_bmap_lookup_at_level() rpmsg: qcom: glink: replace strncpy() with strscpy_pad() mmc: core: Terminate infinite loop in SD-UHS voltage switch mmc: core: Replace with already defined values for readability USB: serial: ftdi_sio: fix 300 bps rate for SIO usb: mon: make mmapped memory read only arch: um: Mark the stack non-executable to fix a binutils warning um: Cleanup compiler warning in arch/x86/um/tls_32.c um: Cleanup syscall_handler_t cast in syscalls_32.h net/ieee802154: fix uninit value bug in dgram_sendmsg scsi: qedf: Fix a UAF bug in __qedf_probe() ARM: dts: fix Moxa SDIO 'compatible', remove 'sdhci' misnomer dmaengine: xilinx_dma: Report error in case of dma_set_mask_and_coherent API failure dmaengine: xilinx_dma: cleanup for fetching xlnx,num-fstores property firmware: arm_scmi: Add SCMI PM driver remove routine fs: fix UAF/GPF bug in nilfs_mdt_destroy perf tools: Fixup get_current_dir_name() compilation mm: pagewalk: Fix race between unmap and page walker Linux 5.4.217 docs: update mediator information in CoC docs Makefile.extrawarn: Move -Wcast-function-type-strict to W=1 Revert "drm/amdgpu: use dirty framebuffer helper" xfs: remove unused variable 'done' xfs: fix uninitialized variable in xfs_attr3_leaf_inactive xfs: streamline xfs_attr3_leaf_inactive xfs: move incore structures out of xfs_da_format.h xfs: fix memory corruption during remote attr value buffer invalidation xfs: refactor remote attr value buffer invalidation xfs: fix IOCB_NOWAIT handling in xfs_file_dio_aio_read xfs: fix s_maxbytes computation on 32-bit kernels xfs: truncate should remove all blocks, not just to the end of the page cache xfs: introduce XFS_MAX_FILEOFF xfs: fix misuse of the XFS_ATTR_INCOMPLETE flag x86/speculation: Add RSB VM Exit protections x86/bugs: Warn when "ibrs" mitigation is selected on Enhanced IBRS parts x86/speculation: Use DECLARE_PER_CPU for x86_spec_ctrl_current x86/speculation: Disable RRSBA behavior x86/bugs: Add Cannon lake to RETBleed affected CPU list x86/cpu/amd: Enumerate BTC_NO x86/common: Stamp out the stepping madness x86/speculation: Fill RSB on vmexit for IBRS KVM: VMX: Fix IBRS handling after vmexit KVM: VMX: Prevent guest RSB poisoning attacks with eIBRS KVM: VMX: Convert launched argument to flags KVM: VMX: Flatten __vmx_vcpu_run() KVM/nVMX: Use __vmx_vcpu_run in nested_vmx_check_vmentry_hw KVM/VMX: Use TEST %REG,%REG instead of CMP $0,%REG in vmenter.S x86/speculation: Remove x86_spec_ctrl_mask x86/speculation: Use cached host SPEC_CTRL value for guest entry/exit x86/speculation: Fix SPEC_CTRL write on SMT state change x86/speculation: Fix firmware entry SPEC_CTRL handling x86/speculation: Fix RSB filling with CONFIG_RETPOLINE=n x86/speculation: Change FILL_RETURN_BUFFER to work with objtool intel_idle: Disable IBRS during long idle x86/bugs: Report Intel retbleed vulnerability x86/bugs: Split spectre_v2_select_mitigation() and spectre_v2_user_select_mitigation() x86/speculation: Add spectre_v2=ibrs option to support Kernel IBRS x86/bugs: Optimize SPEC_CTRL MSR writes x86/entry: Add kernel IBRS implementation x86/entry: Remove skip_r11rcx x86/bugs: Keep a per-CPU IA32_SPEC_CTRL value x86/bugs: Add AMD retbleed= boot parameter x86/bugs: Report AMD retbleed vulnerability x86/cpufeatures: Move RETPOLINE flags to word 11 x86/kvm/vmx: Make noinstr clean x86/cpu: Add a steppings field to struct x86_cpu_id x86/cpu: Add consistent CPU match macros x86/devicetable: Move x86 specific macro out of generic code Revert "x86/cpu: Add a steppings field to struct x86_cpu_id" Revert "x86/speculation: Add RSB VM Exit protections" Linux 5.4.216 clk: iproc: Do not rely on node name for correct PLL setup clk: imx: imx6sx: remove the SET_RATE_PARENT flag for QSPI clocks selftests: Fix the if conditions of in test_extra_filter() nvme: Fix IOC_PR_CLEAR and IOC_PR_RELEASE ioctls for nvme devices nvme: add new line after variable declatation usbnet: Fix memory leak in usbnet_disconnect() Input: melfas_mip4 - fix return value check in mip4_probe() Revert "drm: bridge: analogix/dp: add panel prepare/unprepare in suspend/resume time" soc: sunxi: sram: Fix debugfs info for A64 SRAM C soc: sunxi: sram: Fix probe function ordering issues soc: sunxi_sram: Make use of the helper function devm_platform_ioremap_resource() soc: sunxi: sram: Prevent the driver from being unbound soc: sunxi: sram: Actually claim SRAM regions ARM: dts: am33xx: Fix MMCHS0 dma properties ARM: dts: Move am33xx and am43xx mmc nodes to sdhci-omap driver media: dvb_vb2: fix possible out of bound access mm: fix madivse_pageout mishandling on non-LRU page mm/migrate_device.c: flush TLB while holding PTL mm: prevent page_frag_alloc() from corrupting the memory mm/page_alloc: fix race condition between build_all_zonelists and page allocation mmc: moxart: fix 4-bit bus width and remove 8-bit bus width libata: add ATA_HORKAGE_NOLPM for Pioneer BDR-207M and BDR-205 Revert "net: mvpp2: debugfs: fix memory leak when using debugfs_lookup()" ntfs: fix BUG_ON in ntfs_lookup_inode_by_name() ARM: dts: integrator: Tag PCI host with device_type clk: ingenic-tcu: Properly enable registers before accessing timers net: usb: qmi_wwan: Add new usb-id for Dell branded EM7455 uas: ignore UAS for Thinkplus chips usb-storage: Add Hiksemi USB3-FW to IGNORE_UAS uas: add no-uas quirk for Hiksemi usb_disk Linux 5.4.215 ext4: make directory inode spreading reflect flexbg size xfs: fix use-after-free when aborting corrupt attr inactivation xfs: fix an ABBA deadlock in xfs_rename xfs: don't commit sunit/swidth updates to disk if that would cause repair failures xfs: split the sunit parameter update into two parts xfs: refactor agfl length computation function xfs: use bitops interface for buf log item AIL flag check xfs: stabilize insert range start boundary to avoid COW writeback race xfs: fix some memory leaks in log recovery xfs: always log corruption errors xfs: constify the buffer pointer arguments to error functions xfs: convert EIO to EFSCORRUPTED when log contents are invalid xfs: Fix deadlock between AGI and AGF when target_ip exists in xfs_rename() xfs: attach dquots and reserve quota blocks during unwritten conversion xfs: range check ri_cnt when recovering log items xfs: add missing assert in xfs_fsmap_owner_from_rmap xfs: slightly tweak an assert in xfs_fs_map_blocks xfs: replace -EIO with -EFSCORRUPTED for corrupt metadata ext4: fix bug in extents parsing when eh_entries == 0 and eh_depth > 0 workqueue: don't skip lockdep work dependency in cancel_work_sync() drm/rockchip: Fix return type of cdn_dp_connector_mode_valid drm/amd/display: Limit user regamma to a valid value drm/amdgpu: use dirty framebuffer helper Drivers: hv: Never allocate anything besides framebuffer from framebuffer memory region cifs: always initialize struct msghdr smb_msg completely usb: xhci-mtk: fix issue of out-of-bounds array access s390/dasd: fix Oops in dasd_alias_get_start_dev due to missing pavgroup serial: tegra-tcu: Use uart_xmit_advance(), fixes icount.tx accounting serial: tegra: Use uart_xmit_advance(), fixes icount.tx accounting serial: Create uart_xmit_advance() net: sched: fix possible refcount leak in tc_new_tfilter() net: sunhme: Fix packet reception for len < RX_COPY_THRESHOLD perf kcore_copy: Do not check /proc/modules is unchanged perf jit: Include program header in ELF files can: gs_usb: gs_can_open(): fix race dev->can.state condition netfilter: ebtables: fix memory leak when blob is malformed net/sched: taprio: make qdisc_leaf() see the per-netdev-queue pfifo child qdiscs net/sched: taprio: avoid disabling offload when it was never enabled of: mdio: Add of_node_put() when breaking out of for_each_xx i40e: Fix set max_tx_rate when it is lower than 1 Mbps i40e: Fix VF set max MTU size iavf: Fix set max MTU size with port VLAN and jumbo frames iavf: Fix bad page state MIPS: Loongson32: Fix PHY-mode being left unspecified MIPS: lantiq: export clk_get_io() for lantiq_wdt.ko net: team: Unsync device addresses on ndo_stop ipvlan: Fix out-of-bound bugs caused by unset skb->mac_header iavf: Fix cached head and tail value for iavf_get_tx_pending netfilter: nfnetlink_osf: fix possible bogus match in nf_osf_find() netfilter: nf_conntrack_irc: Tighten matching on DCC message netfilter: nf_conntrack_sip: fix ct_sip_walk_headers arm64: dts: rockchip: Remove 'enable-active-low' from rk3399-puma arm64: dts: rockchip: Set RK3399-Gru PCLK_EDP to 24 MHz arm64: dts: rockchip: Pull up wlan wake# on Gru-Bob mm/slub: fix to return errno if kmalloc() fails efi: libstub: check Shim mode using MokSBStateRT ALSA: hda/realtek: Enable 4-speaker output Dell Precision 5530 laptop ALSA: hda/realtek: Add quirk for ASUS GA503R laptop ALSA: hda/realtek: Add pincfg for ASUS G533Z HP jack ALSA: hda/realtek: Add pincfg for ASUS G513 HP jack ALSA: hda/realtek: Re-arrange quirk table entries ALSA: hda/realtek: Add quirk for Huawei WRT-WX9 ALSA: hda: add Intel 5 Series / 3400 PCI DID ALSA: hda/tegra: set depop delay for tegra USB: serial: option: add Quectel RM520N USB: serial: option: add Quectel BG95 0x0203 composition USB: core: Fix RST error in hub.c Revert "usb: gadget: udc-xilinx: replace memcpy with memcpy_toio" Revert "usb: add quirks for Lenovo OneLink+ Dock" usb: cdns3: fix issue with rearming ISO OUT endpoint usb: gadget: udc-xilinx: replace memcpy with memcpy_toio usb: add quirks for Lenovo OneLink+ Dock tty: serial: atmel: Preserve previous USART mode if RS485 disabled serial: atmel: remove redundant assignment in rs485_config tty/serial: atmel: RS485 & ISO7816: wait for TXRDY before sending data wifi: mac80211: Fix UAF in ieee80211_scan_rx() usb: xhci-mtk: relax TT periodic bandwidth allocation usb: xhci-mtk: allow multiple Start-Split in a microframe usb: xhci-mtk: add some schedule error number usb: xhci-mtk: add a function to (un)load bandwidth info usb: xhci-mtk: use @sch_tt to check whether need do TT schedule usb: xhci-mtk: add only one extra CS for FS/LS INTR usb: xhci-mtk: get the microframe boundary for ESIT usb: dwc3: gadget: Avoid duplicate requests to enable Run/Stop usb: dwc3: gadget: Don't modify GEVNTCOUNT in pullup() usb: dwc3: gadget: Refactor pullup() usb: dwc3: gadget: Prevent repeat pullup() usb: dwc3: Issue core soft reset before enabling run/stop usb: dwc3: gadget: Avoid starting DWC3 gadget during UDC unbind ALSA: hda/sigmatel: Fix unused variable warning for beep power change cgroup: Add missing cpus_read_lock() to cgroup_attach_task_all() video: fbdev: pxa3xx-gcu: Fix integer overflow in pxa3xx_gcu_write mksysmap: Fix the mismatch of 'L0' symbols in System.map MIPS: OCTEON: irq: Fix octeon_irq_force_ciu_mapping() afs: Return -EAGAIN, not -EREMOTEIO, when a file already locked net: usb: qmi_wwan: add Quectel RM520N ALSA: hda/tegra: Align BDL entry to 4KB boundary ALSA: hda/sigmatel: Keep power up while beep is enabled rxrpc: Fix calc of resend age rxrpc: Fix local destruction being repeated regulator: pfuze100: Fix the global-out-of-bounds access in pfuze100_regulator_probe() ASoC: nau8824: Fix semaphore unbalance at error paths iomap: iomap that extends beyond EOF should be marked dirty MAINTAINERS: add Chandan as xfs maintainer for 5.4.y cifs: don't send down the destination address to sendmsg for a SOCK_STREAM cifs: revalidate mapping when doing direct writes tracing: hold caller_addr to hardirq_{enable,disable}_ip task_stack, x86/cea: Force-inline stack helpers ALSA: pcm: oss: Fix race at SNDCTL_DSP_SYNC parisc: ccio-dma: Add missing iounmap in error path in ccio_probe() drm/meson: Fix OSD1 RGB to YCbCr coefficient drm/meson: Correct OSD1 global alpha value gpio: mpc8xxx: Fix support for IRQ_TYPE_LEVEL_LOW flow_type in mpc85xx NFSv4: Turn off open-by-filehandle and NFS re-export for NFSv4.0 of: fdt: fix off-by-one error in unflatten_dt_nodes() Revert "USB: core: Prevent nested device-reset calls" Revert "io_uring: disable polling pollfree files" Revert "netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to y" Revert "sched/deadline: Fix priority inheritance with multiple scheduling classes" Revert "kernel/sched: Remove dl_boosted flag comment" Revert "mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse" Revert "fs: check FMODE_LSEEK to control internal pipe splicing" Linux 5.4.214 tracefs: Only clobber mode/uid/gid on remount if asked soc: fsl: select FSL_GUTS driver for DPIO net: dp83822: disable rx error interrupt mm: Fix TLB flush for not-first PFNMAP mappings in unmap_region() usb: storage: Add ASUS <0x0b05:0x1932> to IGNORE_UAS platform/x86: acer-wmi: Acer Aspire One AOD270/Packard Bell Dot keymap fixes perf/arm_pmu_platform: fix tests for platform_get_irq() failure nvmet-tcp: fix unhandled tcp states in nvmet_tcp_state_change() Input: iforce - add support for Boeder Force Feedback Wheel ieee802154: cc2520: add rc code in cc2520_tx() tg3: Disable tg3 device on system reboot to avoid triggering AER hid: intel-ish-hid: ishtp: Fix ishtp client sending disordered message HID: ishtp-hid-clientHID: ishtp-hid-client: Fix comment typo drm/msm/rd: Fix FIFO-full deadlock Linux 5.4.213 MIPS: loongson32: ls1c: Fix hang during startup x86/nospec: Fix i386 RSB stuffing sch_sfb: Also store skb len before calling child enqueue tcp: fix early ETIMEDOUT after spurious non-SACK RTO nvme-tcp: fix UAF when detecting digest errors RDMA/mlx5: Set local port to one when accessing counters ipv6: sr: fix out-of-bounds read when setting HMAC data. RDMA/siw: Pass a pointer to virt_to_page() i40e: Fix kernel crash during module removal tipc: fix shift wrapping bug in map_get() sch_sfb: Don't assume the skb is still around after enqueueing to child afs: Use the operation issue time instead of the reply time for callbacks rxrpc: Fix an insufficiently large sglist in rxkad_verify_packet_2() netfilter: nf_conntrack_irc: Fix forged IP logic netfilter: br_netfilter: Drop dst references before setting. RDMA/hns: Fix supported page size soc: brcmstb: pm-arm: Fix refcount leak and __iomem leak bugs RDMA/cma: Fix arguments order in net device validation regulator: core: Clean up on enable failure ARM: dts: imx6qdl-kontron-samx6i: remove duplicated node smb3: missing inode locks in punch hole cgroup: Fix threadgroup_rwsem <-> cpus_read_lock() deadlock cgroup: Elide write-locking threadgroup_rwsem when updating csses on an empty subtree cgroup: Optimize single thread migration scsi: lpfc: Add missing destroy_workqueue() in error path scsi: mpt3sas: Fix use-after-free warning nvmet: fix a use-after-free debugfs: add debugfs_lookup_and_remove() kprobes: Prohibit probes in gate area ALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface() ALSA: aloop: Fix random zeros in capture data when using jiffies timer ALSA: emu10k1: Fix out of bounds access in snd_emu10k1_pcm_channel_alloc() drm/amdgpu: mmVM_L2_CNTL3 register not initialized correctly fbdev: chipsfb: Add missing pci_disable_device() in chipsfb_pci_init() arm64: cacheinfo: Fix incorrect assignment of signed error value to unsigned fw_level parisc: Add runtime check to prevent PA2.0 kernels on PA1.x machines parisc: ccio-dma: Handle kmalloc failure in ccio_init_resources() drm/radeon: add a force flush to delay work when radeon drm/amdgpu: Check num_gfx_rings for gfx v9_0 rb setup. drm/gem: Fix GEM handle release errors scsi: megaraid_sas: Fix double kfree() USB: serial: ch341: fix disabled rx timer on older devices USB: serial: ch341: fix lost character on LCR updates usb: dwc3: disable USB core PHY management usb: dwc3: fix PHY disable sequence btrfs: harden identification of a stale device drm/i915/glk: ECS Liva Q2 needs GLK HDMI port timing quirk ALSA: seq: Fix data-race at module auto-loading ALSA: seq: oss: Fix data-race for max_midi_devs access net: mac802154: Fix a condition in the receive path ip: fix triggering of 'icmp redirect' wifi: mac80211: Don't finalize CSA in IBSS mode if state is disconnected driver core: Don't probe devices after bus_type.match() probe deferral usb: gadget: mass_storage: Fix cdrom data transfers on MAC-OS USB: core: Prevent nested device-reset calls s390: fix nospec table alignments s390/hugetlb: fix prepare_hugepage_range() check for 2 GB hugepages usb-storage: Add ignore-residue quirk for NXP PN7462AU USB: cdc-acm: Add Icom PMR F3400 support (0c26:0020) usb: dwc2: fix wrong order of phy_power_on and phy_init usb: typec: altmodes/displayport: correct pin assignment for UFP receptacles USB: serial: option: add support for Cinterion MV32-WA/WB RmNet mode USB: serial: option: add Quectel EM060K modem USB: serial: option: add support for OPPO R11 diag port USB: serial: cp210x: add Decagon UCA device id xhci: Add grace period after xHC start to prevent premature runtime suspend. thunderbolt: Use the actual buffer in tb_async_error() gpio: pca953x: Add mutex_lock for regcache sync in PM hwmon: (gpio-fan) Fix array out of bounds access clk: bcm: rpi: Fix error handling of raspberrypi_fw_get_rate Input: rk805-pwrkey - fix module autoloading clk: core: Fix runtime PM sequence in clk_core_unprepare() Revert "clk: core: Honor CLK_OPS_PARENT_ENABLE for clk gate ops" clk: core: Honor CLK_OPS_PARENT_ENABLE for clk gate ops drm/i915/reg: Fix spelling mistake "Unsupport" -> "Unsupported" usb: dwc3: qcom: fix use-after-free on runtime-PM wakeup binder: fix UAF of ref->proc caused by race condition USB: serial: ftdi_sio: add Omron CS1W-CIF31 device id misc: fastrpc: fix memory corruption on open misc: fastrpc: fix memory corruption on probe iio: adc: mcp3911: use correct formula for AD conversion Input: iforce - wake up after clearing IFORCE_XMIT_RUNNING flag tty: serial: lpuart: disable flow control while waiting for the transmit engine to complete vt: Clear selection before changing the font powerpc: align syscall table for ppc32 staging: rtl8712: fix use after free bugs serial: fsl_lpuart: RS485 RTS polariy is inverse net/smc: Remove redundant refcount increase Revert "sch_cake: Return __NET_XMIT_STOLEN when consuming enqueued skb" tcp: annotate data-race around challenge_timestamp sch_cake: Return __NET_XMIT_STOLEN when consuming enqueued skb kcm: fix strp_init() order and cleanup ethernet: rocker: fix sleep in atomic context bug in neigh_timer_handler net: sched: tbf: don't call qdisc_put() while holding tree lock Revert "xhci: turn off port power in shutdown" wifi: cfg80211: debugfs: fix return type in ht40allow_map_read() ieee802154/adf7242: defer destroy_workqueue call iio: adc: mcp3911: make use of the sign bit platform/x86: pmc_atom: Fix SLP_TYPx bitfield mask drm/msm/dsi: Fix number of regulators for msm8996_dsi_cfg drm/msm/dsi: fix the inconsistent indenting net: dp83822: disable false carrier interrupt Revert "mm: kmemleak: take a full lowmem check in kmemleak_*_phys()" fs: only do a memory barrier for the first set_buffer_uptodate() net: mvpp2: debugfs: fix memory leak when using debugfs_lookup() wifi: iwlegacy: 4965: corrected fix for potential off-by-one overflow in il4965_rs_fill_link_cmd() efi: capsule-loader: Fix use-after-free in efi_capsule_write Linux 5.4.212 net: neigh: don't call kfree_skb() under spin_lock_irqsave() net/af_packet: check len when min_header_len equals to 0 io_uring: disable polling pollfree files kprobes: don't call disarm_kprobe() for disabled kprobes lib/vdso: Mark do_hres() and do_coarse() as __always_inline lib/vdso: Let do_coarse() return 0 to simplify the callsite btrfs: tree-checker: check for overlapping extent items netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to y drm/amd/display: Fix pixel clock programming s390/hypfs: avoid error message under KVM neigh: fix possible DoS due to net iface start/stop loop drm/amd/display: clear optc underflow before turn off odm clock drm/amd/display: Avoid MPC infinite loop btrfs: unify lookup return value when dir entry is missing btrfs: do not pin logs too early during renames btrfs: introduce btrfs_lookup_match_dir mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse bpf: Don't redirect packets with invalid pkt_len ftrace: Fix NULL pointer dereference in is_ftrace_trampoline when ftrace is dead fbdev: fb_pm2fb: Avoid potential divide by zero error HID: hidraw: fix memory leak in hidraw_release() media: pvrusb2: fix memory leak in pvr_probe udmabuf: Set the DMA mask for the udmabuf device (v2) HID: steam: Prevent NULL pointer dereference in steam_{recv,send}_report Bluetooth: L2CAP: Fix build errors in some archs kbuild: Fix include path in scripts/Makefile.modpost x86/bugs: Add "unknown" reporting for MMIO Stale Data s390/mm: do not trigger write fault when vma does not allow VM_WRITE mm: Force TLB flush for PFNMAP mappings before unlink_file_vma() scsi: storvsc: Remove WQ_MEM_RECLAIM from storvsc_error_wq perf/x86/intel/uncore: Fix broken read_counter() for SNB IMC PMU md: call __md_stop_writes in md_stop mm/hugetlb: fix hugetlb not supporting softdirty tracking ACPI: processor: Remove freq Qos request for all CPUs s390: fix double free of GS and RI CBs on fork() failure asm-generic: sections: refactor memory_intersects loop: Check for overflow while configuring loop x86/unwind/orc: Unwind ftrace trampolines with correct ORC entry btrfs: check if root is readonly while setting security xattr btrfs: add info when mount fails due to stale replace target btrfs: replace: drop assert for suspended replace btrfs: fix silent failure when deleting root reference ixgbe: stop resetting SYSTIME in ixgbe_ptp_start_cyclecounter net: Fix a data-race around sysctl_somaxconn. net: Fix a data-race around netdev_budget_usecs. net: Fix a data-race around netdev_budget. net: Fix a data-race around sysctl_net_busy_read. net: Fix a data-race around sysctl_net_busy_poll. net: Fix a data-race around sysctl_tstamp_allow_data. ratelimit: Fix data-races in ___ratelimit(). net: Fix data-races around netdev_tstamp_prequeue. net: Fix data-races around weight_p and dev_weight_[rt]x_bias. netfilter: nft_tunnel: restrict it to netdev family netfilter: nft_osf: restrict osf to ipv4, ipv6 and inet families netfilter: nft_payload: do not truncate csum_offset and csum_type netfilter: nft_payload: report ERANGE for too long offset and length bnxt_en: fix NQ resource accounting during vf creation on 57500 chips netfilter: ebtables: reject blobs that don't provide all entry points net: ipvtap - add __init/__exit annotations to module init/exit funcs bonding: 802.3ad: fix no transmission of LACPDUs net: moxa: get rid of asymmetry in DMA mapping/unmapping net/mlx5e: Properly disable vlan strip on non-UL reps rose: check NULL rose_loopback_neigh->loopback SUNRPC: RPC level errors should set task->tk_rpc_status af_key: Do not call xfrm_probe_algs in parallel xfrm: fix refcount leak in __xfrm_policy_check() kernel/sched: Remove dl_boosted flag comment sched/deadline: Fix priority inheritance with multiple scheduling classes sched/deadline: Fix stale throttling on de-/boosted tasks sched/deadline: Unthrottle PI boosted threads while enqueuing pinctrl: amd: Don't save/restore interrupt status and wake status bits Revert "selftests/bpf: Fix test_align verifier log patterns" Revert "selftests/bpf: Fix "dubious pointer arithmetic" test" usb: cdns3: Fix issue for clear halt endpoint kernel/sys_ni: add compat entry for fadvise64_64 parisc: Fix exception handler for fldw and fstw instructions audit: fix potential double free on error path from fsnotify_add_inode_mark Revert "USB: HCD: Fix URB giveback issue in tasklet function" Linux 5.4.211 btrfs: raid56: don't trust any cached sector in __raid56_parity_recover() btrfs: only write the sectors in the vertical stripe which has data stripes can: j1939: j1939_session_destroy(): fix memory leak of skbs can: j1939: j1939_sk_queue_activate_next_locked(): replace WARN_ON_ONCE with netdev_warn_once() tracing/probes: Have kprobes and uprobes use $COMM too MIPS: tlbex: Explicitly compare _PAGE_NO_EXEC against 0 video: fbdev: i740fb: Check the argument of i740_calc_vclk() powerpc/64: Init jump labels before parse_early_param() smb3: check xattr value length earlier f2fs: fix to avoid use f2fs_bug_on() in f2fs_new_node_page() ALSA: timer: Use deferred fasync helper ALSA: core: Add async signal helpers powerpc/32: Don't always pass -mcpu=powerpc to the compiler watchdog: export lockup_detector_reconfigure RISC-V: Add fast call path of crash_kexec() riscv: mmap with PROT_WRITE but no PROT_READ is invalid mips: cavium-octeon: Fix missing of_node_put() in octeon2_usb_clocks_start vfio: Clear the caps->buf to NULL after free tty: serial: Fix refcount leak bug in ucc_uart.c lib/list_debug.c: Detect uninitialized lists ext4: avoid resizing to a partial cluster size ext4: avoid remove directory when directory is corrupted drivers:md:fix a potential use-after-free bug nvmet-tcp: fix lockdep complaint on nvmet_tcp_wq flush during queue teardown dmaengine: sprd: Cleanup in .remove() after pm_runtime_get_sync() failed selftests/kprobe: Do not test for GRP/ without event failures um: add "noreboot" command line option for PANIC_TIMEOUT=-1 setups PCI/ACPI: Guard ARM64-specific mcfg_quirks cxl: Fix a memory leak in an error handling path gadgetfs: ep_io - wait until IRQ finishes scsi: lpfc: Prevent buffer overflow crashes in debugfs with malformed user input clk: qcom: ipq8074: dont disable gcc_sleep_clk_src vboxguest: Do not use devm for irq usb: renesas: Fix refcount leak bug usb: host: ohci-ppc-of: Fix refcount leak bug drm/meson: Fix overflow implicit truncation warnings irqchip/tegra: Fix overflow implicit truncation warnings usb: gadget: uvc: call uvc uvcg_warn on completed status instead of uvcg_info usb: cdns3 fix use-after-free at workaround 2 PCI: Add ACS quirk for Broadcom BCM5750x NICs drm/meson: Fix refcount bugs in meson_vpu_has_available_connectors() locking/atomic: Make test_and_*_bit() ordered on failure gcc-plugins: Undefine LATENT_ENTROPY_PLUGIN when plugin disabled for a file igb: Add lock to avoid data race fec: Fix timer capture timing in `fec_ptp_enable_pps()` i40e: Fix to stop tx_timeout recovery if GLOBR fails ice: Ignore EEXIST when setting promisc mode net: dsa: microchip: ksz9477: fix fdb_dump last invalid entry net: moxa: pass pdev instead of ndev to DMA functions net: dsa: mv88e6060: prevent crash on an unused port powerpc/pci: Fix get_phb_number() locking netfilter: nf_tables: really skip inactive sets when allocating name clk: rockchip: add sclk_mac_lbtest to rk3188_critical_clocks iavf: Fix adminq error handling nios2: add force_successful_syscall_return() nios2: restarts apply only to the first sigframe we build... nios2: fix syscall restart checks nios2: traced syscall does need to check the syscall number nios2: don't leave NULLs in sys_call_table[] nios2: page fault et.al. are *not* restartable syscalls... tee: add overflow check in register_shm_helper() dpaa2-eth: trace the allocated address instead of page struct atm: idt77252: fix use-after-free bugs caused by tst_timer xen/xenbus: fix return type in xenbus_file_read() nfp: ethtool: fix the display error of `ethtool -m DEVNAME` NTB: ntb_tool: uninitialized heap data in tool_fn_write() tools build: Switch to new openssl API for test-libcrypto tools/vm/slabinfo: use alphabetic order when two values are equal dt-bindings: arm: qcom: fix MSM8916 MTP compatibles vsock: Set socket state back to SS_UNCONNECTED in vsock_connect_timeout() vsock: Fix memory leak in vsock_connect() plip: avoid rcu debug splat geneve: do not use RT_TOS for IPv6 flowlabel ACPI: property: Return type of acpi_add_nondev_subnodes() should be bool pinctrl: sunxi: Add I/O bias setting for H6 R-PIO pinctrl: qcom: msm8916: Allow CAMSS GP clocks to be muxed pinctrl: nomadik: Fix refcount leak in nmk_pinctrl_dt_subnode_to_map net: bgmac: Fix a BUG triggered by wrong bytes_compl devlink: Fix use-after-free after a failed reload SUNRPC: Reinitialise the backchannel request buffers before reuse sunrpc: fix expiry of auth creds can: mcp251x: Fix race condition on receive interrupt NFSv4/pnfs: Fix a use-after-free bug in open NFSv4.1: RECLAIM_COMPLETE must handle EACCES NFSv4: Fix races in the legacy idmapper upcall NFSv4.1: Handle NFS4ERR_DELAY replies to OP_SEQUENCE correctly NFSv4.1: Don't decrease the value of seq_nr_highest_sent Documentation: ACPI: EINJ: Fix obsolete example apparmor: Fix memleak in aa_simple_write_to_buffer() apparmor: fix reference count leak in aa_pivotroot() apparmor: fix overlapping attachment computation apparmor: fix aa_label_asxprint return check apparmor: Fix failed mount permission check error message apparmor: fix absroot causing audited secids to begin with = apparmor: fix quiet_denied for file rules can: ems_usb: fix clang's -Wunaligned-access warning tracing: Have filter accept "common_cpu" to be consistent btrfs: fix lost error handling when looking up extended ref on log replay mmc: pxamci: Fix an error handling path in pxamci_probe() mmc: pxamci: Fix another error handling path in pxamci_probe() ata: libata-eh: Add missing command name rds: add missing barrier to release_refill ALSA: info: Fix llseek return value when using callback net_sched: cls_route: disallow handle of 0 net/9p: Initialize the iounit field during fid creation Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm regression Revert "net: usb: ax88179_178a needs FLAG_SEND_ZLP" scsi: sg: Allow waiting for commands to complete on removed device tcp: fix over estimation in sk_forced_mem_schedule() KVM: x86: Avoid theoretical NULL pointer dereference in kvm_irq_delivery_to_apic_fast() KVM: x86: Check lapic_in_kernel() before attempting to set a SynIC irq KVM: Add infrastructure and macro to mark VM as bugged btrfs: reject log replay if there is unsupported RO compat flag net_sched: cls_route: remove from list when handle is 0 iommu/vt-d: avoid invalid memory access via node_online(NUMA_NO_NODE) firmware: arm_scpi: Ensure scpi_info is not assigned if the probe fails timekeeping: contribute wall clock to rng on time change ACPI: CPPC: Do not prevent CPPC from working in the future dm writecache: set a default MAX_WRITEBACK_JOBS dm thin: fix use-after-free crash in dm_sm_register_threshold_callback dm raid: fix address sanitizer warning in raid_status dm raid: fix address sanitizer warning in raid_resume intel_th: pci: Add Meteor Lake-P support intel_th: pci: Add Raptor Lake-S PCH support intel_th: pci: Add Raptor Lake-S CPU support ext4: correct the misjudgment in ext4_iget_extra_inode ext4: correct max_inline_xattr_value_size computing ext4: fix extent status tree race in writeback error recovery path ext4: update s_overhead_clusters in the superblock during an on-line resize ext4: fix use-after-free in ext4_xattr_set_entry ext4: make sure ext4_append() always allocates new block ext4: add EXT4_INODE_HAS_XATTR_SPACE macro in xattr.h btrfs: reset block group chunk force if we have to wait tpm: eventlog: Fix section mismatch for DEBUG_SECTION_MISMATCH kexec, KEYS, s390: Make use of built-in and secondary keyring for signature verification spmi: trace: fix stack-out-of-bound access in SPMI tracing functions x86/olpc: fix 'logical not is only applied to the left hand side' scsi: qla2xxx: Fix erroneous mailbox timeout after PCI error injection scsi: qla2xxx: Turn off multi-queue for 8G adapters scsi: qla2xxx: Fix discovery issues in FC-AL topology scsi: zfcp: Fix missing auto port scan and thus missing target ports video: fbdev: s3fb: Check the size of screen before memset_io() video: fbdev: arkfb: Check the size of screen before memset_io() video: fbdev: vt8623fb: Check the size of screen before memset_io() tools/thermal: Fix possible path truncations video: fbdev: arkfb: Fix a divide-by-zero bug in ark_set_pixclock() x86/numa: Use cpumask_available instead of hardcoded NULL check scripts/faddr2line: Fix vmlinux detection on arm64 genelf: Use HAVE_LIBCRYPTO_SUPPORT, not the never defined HAVE_LIBCRYPTO powerpc/pci: Fix PHB numbering when using opal-phbid kprobes: Forbid probing on trampoline and BPF code areas perf symbol: Fail to read phdr workaround powerpc/cell/axon_msi: Fix refcount leak in setup_msi_msg_address powerpc/xive: Fix refcount leak in xive_get_max_prio powerpc/spufs: Fix refcount leak in spufs_init_isolated_loader powerpc/pci: Prefer PCI domain assignment via DT 'linux,pci-domain' and alias powerpc/32: Do not allow selection of e5500 or e6500 CPUs on PPC32 video: fbdev: sis: fix typos in SiS_GetModeID() video: fbdev: amba-clcd: Fix refcount leak bugs watchdog: armada_37xx_wdt: check the return value of devm_ioremap() in armada_37xx_wdt_probe() ASoC: audio-graph-card: Add of_node_put() in fail path fuse: Remove the control interface for virtio-fs ASoC: qcom: q6dsp: Fix an off-by-one in q6adm_alloc_copp() s390/zcore: fix race when reading from hardware system area iommu/arm-smmu: qcom_iommu: Add of_node_put() when breaking out of loop mfd: max77620: Fix refcount leak in max77620_initialise_fps mfd: t7l66xb: Drop platform disable callback kfifo: fix kfifo_to_user() return type rpmsg: qcom_smd: Fix refcount leak in qcom_smd_parse_edge iommu/exynos: Handle failed IOMMU device registration properly tty: n_gsm: fix missing corner cases in gsmld_poll() tty: n_gsm: fix DM command tty: n_gsm: fix wrong T1 retry count handling vfio/ccw: Do not change FSM state in subchannel event remoteproc: qcom: wcnss: Fix handling of IRQs tty: n_gsm: fix race condition in gsmld_write() tty: n_gsm: fix packet re-transmission without open control channel tty: n_gsm: fix non flow control frames during mux flow off profiling: fix shift too large makes kernel panic ASoC: codecs: wcd9335: move gains from SX_TLV to S8_TLV ASoC: codecs: msm8916-wcd-digital: move gains from SX_TLV to S8_TLV serial: 8250_dw: Store LSR into lsr_saved_flags in dw8250_tx_wait_empty() ASoC: mediatek: mt8173-rt5650: Fix refcount leak in mt8173_rt5650_dev_probe ASoC: codecs: da7210: add check for i2c_add_driver ASoC: mt6797-mt6351: Fix refcount leak in mt6797_mt6351_dev_probe ASoC: mediatek: mt8173: Fix refcount leak in mt8173_rt5650_rt5676_dev_probe opp: Fix error check in dev_pm_opp_attach_genpd() jbd2: fix assertion 'jh->b_frozen_data == NULL' failure when journal aborted ext4: recover csum seed of tmp_inode after migrating to extents jbd2: fix outstanding credits assert in jbd2_journal_commit_transaction() null_blk: fix ida error handling in null_add_dev() RDMA/rxe: Fix error unwind in rxe_create_qp() mm/mmap.c: fix missing call to vm_unacct_memory in mmap_region platform/olpc: Fix uninitialized data in debugfs write USB: serial: fix tty-port initialized comments PCI: tegra194: Fix link up retry sequence PCI: tegra194: Fix Root Port interrupt handling HID: alps: Declare U1_UNICORN_LEGACY support mmc: cavium-thunderx: Add of_node_put() when breaking out of loop mmc: cavium-octeon: Add of_node_put() when breaking out of loop gpio: gpiolib-of: Fix refcount bugs in of_mm_gpiochip_add_data() RDMA/hfi1: fix potential memory leak in setup_base_ctxt() RDMA/siw: Fix duplicated reported IW_CM_EVENT_CONNECT_REPLY event RDMA/hns: Fix incorrect clearing of interrupt status register usb: gadget: udc: amd5536 depends on HAS_DMA scsi: smartpqi: Fix DMA direction for RAID requests mmc: sdhci-of-at91: fix set_uhs_signaling rewriting of MC1R memstick/ms_block: Fix a memory leak memstick/ms_block: Fix some incorrect memory allocation mmc: sdhci-of-esdhc: Fix refcount leak in esdhc_signal_voltage_switch staging: rtl8192u: Fix sleep in atomic context bug in dm_fsync_timer_callback intel_th: msu: Fix vmalloced buffers intel_th: msu-sink: Potential dereference of null pointer intel_th: Fix a resource leak in an error handling path soundwire: bus_type: fix remove and shutdown support clk: qcom: camcc-sdm845: Fix topology around titan_top power domain clk: qcom: ipq8074: set BRANCH_HALT_DELAY flag for UBI clocks clk: qcom: ipq8074: fix NSS port frequency tables usb: host: xhci: use snprintf() in xhci_decode_trb() clk: qcom: clk-krait: unlock spin after mux completion driver core: fix potential deadlock in __driver_attach misc: rtsx: Fix an error handling path in rtsx_pci_probe() clk: mediatek: reset: Fix written reset bit offset usb: xhci: tegra: Fix error check usb: ohci-nxp: Fix refcount leak in ohci_hcd_nxp_probe usb: host: Fix refcount leak in ehci_hcd_ppc_of_probe fpga: altera-pr-ip: fix unsigned comparison with less than zero mtd: st_spi_fsm: Add a clk_disable_unprepare() in .probe()'s error path mtd: partitions: Fix refcount leak in parse_redboot_of mtd: sm_ftl: Fix deadlock caused by cancel_work_sync in sm_release HID: cp2112: prevent a buffer overflow in cp2112_xfer() mtd: rawnand: meson: Fix a potential double free issue mtd: maps: Fix refcount leak in ap_flash_init mtd: maps: Fix refcount leak in of_flash_probe_versatile clk: renesas: r9a06g032: Fix UART clkgrp bitsel dccp: put dccp_qpolicy_full() and dccp_qpolicy_push() in the same lock net: rose: fix netdev reference changes netdevsim: Avoid allocation warnings triggered from user space iavf: Fix max_rate limiting crypto: inside-secure - Add missing MODULE_DEVICE_TABLE for of net/mlx5e: Fix the value of MLX5E_MAX_RQ_NUM_MTTS wifi: libertas: Fix possible refcount leak in if_usb_probe() wifi: iwlwifi: mvm: fix double list_add at iwl_mvm_mac_wake_tx_queue wifi: wil6210: debugfs: fix uninitialized variable use in `wil_write_file_wmi()` i2c: mux-gpmux: Add of_node_put() when breaking out of loop i2c: cadence: Support PEC for SMBus block read Bluetooth: hci_intel: Add check for platform_driver_register can: pch_can: pch_can_error(): initialize errc before using it can: error: specify the values of data[5..7] of CAN error frames can: usb_8dev: do not report txerr and rxerr during bus-off can: kvaser_usb_leaf: do not report txerr and rxerr during bus-off can: kvaser_usb_hydra: do not report txerr and rxerr during bus-off can: sun4i_can: do not report txerr and rxerr during bus-off can: hi311x: do not report txerr and rxerr during bus-off can: sja1000: do not report txerr and rxerr during bus-off can: rcar_can: do not report txerr and rxerr during bus-off can: pch_can: do not report txerr and rxerr during bus-off selftests/bpf: fix a test for snprintf() overflow wifi: p54: add missing parentheses in p54_flush() wifi: p54: Fix an error handling path in p54spi_probe() wifi: wil6210: debugfs: fix info leak in wil_write_file_wmi() fs: check FMODE_LSEEK to control internal pipe splicing selftests: timers: clocksource-switch: fix passing errors from child selftests: timers: valid-adjtimex: build fix for newer toolchains libbpf: Fix the name of a reused map tcp: make retransmitted SKB fit into the send window drm/exynos/exynos7_drm_decon: free resources when clk_set_parent() failed. mediatek: mt76: mac80211: Fix missing of_node_put() in mt76_led_init() media: platform: mtk-mdp: Fix mdp_ipi_comm structure alignment crypto: hisilicon - Kunpeng916 crypto driver don't sleep when in softirq drm/msm/mdp5: Fix global state lock backoff drm: bridge: sii8620: fix possible off-by-one drm/mediatek: dpi: Only enable dpi after the bridge is enabled drm/mediatek: dpi: Remove output format of YUV drm/rockchip: Fix an error handling path rockchip_dp_probe() drm/rockchip: vop: Don't crash for invalid duplicate_state() crypto: arm64/gcm - Select AEAD for GHASH_ARM64_CE drm/vc4: dsi: Correct DSI divider calculations drm/vc4: plane: Fix margin calculations for the right/bottom edges drm/vc4: plane: Remove subpixel positioning check media: hdpvr: fix error value returns in hdpvr_read drm/mcde: Fix refcount leak in mcde_dsi_bind drm: bridge: adv7511: Add check for mipi_dsi_driver_register wifi: iwlegacy: 4965: fix potential off-by-one overflow in il4965_rs_fill_link_cmd() ath9k: fix use-after-free in ath9k_hif_usb_rx_cb media: tw686x: Register the irq at the end of probe i2c: Fix a potential use after free drm: adv7511: override i2c address of cec before accessing it drm/mediatek: Add pull-down MIPI operation in mtk_dsi_poweroff function drm/radeon: fix potential buffer overflow in ni_set_mc_special_registers() drm/mipi-dbi: align max_chunk to 2 in spi_transfer wifi: rtlwifi: fix error codes in rtl_debugfs_set_write_h2c() ath10k: do not enforce interrupt trigger type dm: return early from dm_pr_call() if DM device is suspended thermal/tools/tmon: Include pthread and time headers in tmon.h nohz/full, sched/rt: Fix missed tick-reenabling bug in dequeue_task_rt() regulator: of: Fix refcount leak bug in of_get_regulation_constraints() blk-mq: don't create hctx debugfs dir until q->debugfs_dir is created erofs: avoid consecutive detection for Highmem memory arm64: dts: mt7622: fix BPI-R64 WPS button bus: hisi_lpc: fix missing platform_device_put() in hisi_lpc_acpi_probe() ARM: dts: qcom: pm8841: add required thermal-sensor-cells soc: qcom: aoss: Fix refcount leak in qmp_cooling_devices_register cpufreq: zynq: Fix refcount leak in zynq_get_revision ARM: OMAP2+: Fix refcount leak in omap3xxx_prm_late_init ARM: OMAP2+: Fix refcount leak in omapdss_init_of ARM: dts: qcom: mdm9615: add missing PMIC GPIO reg soc: fsl: guts: machine variable might be unset ARM: dts: ast2600-evb: fix board compatible ARM: dts: ast2500-evb: fix board compatible x86/pmem: Fix platform-device leak in error path ARM: bcm: Fix refcount leak in bcm_kona_smc_init meson-mx-socinfo: Fix refcount leak in meson_mx_socinfo_init ARM: findbit: fix overflowing offset spi: spi-rspi: Fix PIO fallback on RZ platforms selinux: Add boundary check in put_entry() PM: hibernate: defer device probing when resuming from hibernation ARM: shmobile: rcar-gen2: Increase refcount for new reference arm64: dts: allwinner: a64: orangepi-win: Fix LED node name arm64: dts: qcom: ipq8074: fix NAND node name ACPI: LPSS: Fix missing check in register_device_clock() ACPI: PM: save NVS memory for Lenovo G40-45 ACPI: EC: Remove duplicate ThinkPad X1 Carbon 6th entry from DMI quirks ARM: OMAP2+: display: Fix refcount leak bug spi: synquacer: Add missing clk_disable_unprepare() ARM: dts: imx6ul: fix qspi node compatible ARM: dts: imx6ul: fix lcdif node compatible ARM: dts: imx6ul: fix csi node compatible ARM: dts: imx6ul: change operating-points to uint32-matrix ARM: dts: imx6ul: add missing properties for sram wait: Fix __wait_event_hrtimeout for RT/DL tasks genirq: Don't return error on missing optional irq_request_resources() ext2: Add more validity checks for inode counts arm64: fix oops in concurrently setting insn_emulation sysctls arm64: Do not forget syscall when starting a new thread. x86: Handle idle=nomwait cmdline properly for x86_idle epoll: autoremove wakers even more aggressively netfilter: nf_tables: fix null deref due to zeroed list head netfilter: nf_tables: do not allow RULE_ID to refer to another chain netfilter: nf_tables: do not allow SET_ID to refer to another table arm64: dts: uniphier: Fix USB interrupts for PXs3 SoC ARM: dts: uniphier: Fix USB interrupts for PXs2 SoC USB: HCD: Fix URB giveback issue in tasklet function coresight: Clear the connection field properly MIPS: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK powerpc/powernv: Avoid crashing if rng is NULL powerpc/ptdump: Fix display of RW pages on FSL_BOOK3E powerpc/fsl-pci: Fix Class Code of PCIe Root Port PCI: Add defines for normal and subtractive PCI bridges ia64, processor: fix -Wincompatible-pointer-types in ia64_get_irr() md-raid10: fix KASAN warning serial: mvebu-uart: uart2 error bits clearing fuse: limit nsec iio: light: isl29028: Fix the warning in isl29028_remove() drm/amdgpu: Check BO's requested pinning domains against its preferred_domains drm/nouveau: fix another off-by-one in nvbios_addr drm/gem: Properly annotate WW context on drm_gem_lock_reservations() error parisc: io_pgetevents_time64() needs compat syscall in 32-bit compat mode parisc: Fix device names in /proc/iomem ovl: drop WARN_ON() dentry is NULL in ovl_encode_fh() usbnet: Fix linkwatch use-after-free on disconnect fbcon: Fix boundary checks for fbcon=vc:n1-n2 parameters thermal: sysfs: Fix cooling_device_stats_setup() error code path fs: Add missing umask strip in vfs_tmpfile vfs: Check the truncate maximum size in inode_newsize_ok() tty: vt: initialize unicode screen buffer ALSA: hda/realtek: Add quirk for another Asus K42JZ model ALSA: hda/cirrus - support for iMac 12,1 model ALSA: hda/conexant: Add quirk for LENOVO 20149 Notebook model mm/mremap: hold the rmap lock in write mode when moving page table entries. KVM: x86: Set error code to segment selector on LLDT/LTR non-canonical #GP KVM: x86: Mark TSS busy during LTR emulation _after_ all fault checks KVM: nVMX: Let userspace set nVMX MSR to any _host_ supported value KVM: SVM: Don't BUG if userspace injects an interrupt with GIF=0 KVM: nVMX: Snapshot pre-VM-Enter DEBUGCTL for !nested_run_pending case KVM: nVMX: Snapshot pre-VM-Enter BNDCFGS for !nested_run_pending case HID: wacom: Don't register pad_input for touch switch HID: wacom: Only report rotation for art pen add barriers to buffer_uptodate and set_buffer_uptodate wifi: mac80211_hwsim: use 32-bit skb cookie wifi: mac80211_hwsim: add back erroneously removed cast wifi: mac80211_hwsim: fix race condition in pending packet igc: Remove _I_PHY_ID checking ALSA: bcd2000: Fix a UAF bug on the error path of probing scsi: Revert "scsi: qla2xxx: Fix disk failure to rediscover" x86: link vdso and boot with -z noexecstack --no-warn-rwx-segments Makefile: link with -z noexecstack --no-warn-rwx-segments Conflicts: Documentation/devicetree/bindings/arm/qcom.yaml Documentation/devicetree/bindings~HEAD arch/x86/boot/compressed/Makefile drivers/mmc/core/sd.c drivers/rpmsg/qcom_glink_native.c drivers/usb/dwc3/core.c drivers/usb/dwc3/gadget.c drivers/usb/typec/ucsi/ucsi.c net/core/dev.c net/netfilter/nf_conntrack_irc.c Change-Id: I796398110bc61fa6a8bb94f7ef41b9209683dbf7
1606 lines
40 KiB
C
1606 lines
40 KiB
C
// SPDX-License-Identifier: GPL-2.0
|
|
/*
|
|
* Copyright (c) 2015, Sony Mobile Communications AB.
|
|
* Copyright (c) 2012-2013, 2020 The Linux Foundation. All rights reserved.
|
|
*/
|
|
|
|
#include <linux/interrupt.h>
|
|
#include <linux/io.h>
|
|
#include <linux/mailbox_client.h>
|
|
#include <linux/mfd/syscon.h>
|
|
#include <linux/module.h>
|
|
#include <linux/of_irq.h>
|
|
#include <linux/of_platform.h>
|
|
#include <linux/platform_device.h>
|
|
#include <linux/regmap.h>
|
|
#include <linux/sched.h>
|
|
#include <linux/sizes.h>
|
|
#include <linux/slab.h>
|
|
#include <linux/soc/qcom/smem.h>
|
|
#include <linux/wait.h>
|
|
#include <linux/rpmsg.h>
|
|
#include <linux/rpmsg/qcom_smd.h>
|
|
|
|
#include "rpmsg_internal.h"
|
|
|
|
/*
|
|
* The Qualcomm Shared Memory communication solution provides point-to-point
|
|
* channels for clients to send and receive streaming or packet based data.
|
|
*
|
|
* Each channel consists of a control item (channel info) and a ring buffer
|
|
* pair. The channel info carry information related to channel state, flow
|
|
* control and the offsets within the ring buffer.
|
|
*
|
|
* All allocated channels are listed in an allocation table, identifying the
|
|
* pair of items by name, type and remote processor.
|
|
*
|
|
* Upon creating a new channel the remote processor allocates channel info and
|
|
* ring buffer items from the smem heap and populate the allocation table. An
|
|
* interrupt is sent to the other end of the channel and a scan for new
|
|
* channels should be done. A channel never goes away, it will only change
|
|
* state.
|
|
*
|
|
* The remote processor signals it intent for bring up the communication
|
|
* channel by setting the state of its end of the channel to "opening" and
|
|
* sends out an interrupt. We detect this change and register a smd device to
|
|
* consume the channel. Upon finding a consumer we finish the handshake and the
|
|
* channel is up.
|
|
*
|
|
* Upon closing a channel, the remote processor will update the state of its
|
|
* end of the channel and signal us, we will then unregister any attached
|
|
* device and close our end of the channel.
|
|
*
|
|
* Devices attached to a channel can use the qcom_smd_send function to push
|
|
* data to the channel, this is done by copying the data into the tx ring
|
|
* buffer, updating the pointers in the channel info and signaling the remote
|
|
* processor.
|
|
*
|
|
* The remote processor does the equivalent when it transfer data and upon
|
|
* receiving the interrupt we check the channel info for new data and delivers
|
|
* this to the attached device. If the device is not ready to receive the data
|
|
* we leave it in the ring buffer for now.
|
|
*/
|
|
|
|
struct smd_channel_info;
|
|
struct smd_channel_info_pair;
|
|
struct smd_channel_info_word;
|
|
struct smd_channel_info_word_pair;
|
|
|
|
static const struct rpmsg_endpoint_ops qcom_smd_endpoint_ops;
|
|
|
|
#define SMD_ALLOC_TBL_COUNT 2
|
|
#define SMD_ALLOC_TBL_SIZE 64
|
|
|
|
/*
|
|
* This lists the various smem heap items relevant for the allocation table and
|
|
* smd channel entries.
|
|
*/
|
|
static const struct {
|
|
unsigned alloc_tbl_id;
|
|
unsigned info_base_id;
|
|
unsigned fifo_base_id;
|
|
} smem_items[SMD_ALLOC_TBL_COUNT] = {
|
|
{
|
|
.alloc_tbl_id = 13,
|
|
.info_base_id = 14,
|
|
.fifo_base_id = 338
|
|
},
|
|
{
|
|
.alloc_tbl_id = 266,
|
|
.info_base_id = 138,
|
|
.fifo_base_id = 202,
|
|
},
|
|
};
|
|
|
|
/**
|
|
* struct qcom_smd_edge - representing a remote processor
|
|
* @dev: device associated with this edge
|
|
* @name: name of this edge
|
|
* @of_node: of_node handle for information related to this edge
|
|
* @edge_id: identifier of this edge
|
|
* @remote_pid: identifier of remote processor
|
|
* @irq: interrupt for signals on this edge
|
|
* @ipc_regmap: regmap handle holding the outgoing ipc register
|
|
* @ipc_offset: offset within @ipc_regmap of the register for ipc
|
|
* @ipc_bit: bit in the register at @ipc_offset of @ipc_regmap
|
|
* @mbox_client: mailbox client handle
|
|
* @mbox_chan: apcs ipc mailbox channel handle
|
|
* @channels: list of all channels detected on this edge
|
|
* @channels_lock: guard for modifications of @channels
|
|
* @allocated: array of bitmaps representing already allocated channels
|
|
* @smem_available: last available amount of smem triggering a channel scan
|
|
* @new_channel_event: wait queue for new channel events
|
|
* @scan_work: work item for discovering new channels
|
|
* @state_work: work item for edge state changes
|
|
*/
|
|
struct qcom_smd_edge {
|
|
struct device dev;
|
|
|
|
const char *name;
|
|
|
|
struct device_node *of_node;
|
|
unsigned edge_id;
|
|
unsigned remote_pid;
|
|
|
|
int irq;
|
|
|
|
struct regmap *ipc_regmap;
|
|
int ipc_offset;
|
|
int ipc_bit;
|
|
|
|
struct mbox_client mbox_client;
|
|
struct mbox_chan *mbox_chan;
|
|
|
|
struct list_head channels;
|
|
spinlock_t channels_lock;
|
|
|
|
DECLARE_BITMAP(allocated[SMD_ALLOC_TBL_COUNT], SMD_ALLOC_TBL_SIZE);
|
|
|
|
unsigned smem_available;
|
|
|
|
wait_queue_head_t new_channel_event;
|
|
|
|
struct work_struct scan_work;
|
|
struct work_struct state_work;
|
|
};
|
|
|
|
/*
|
|
* SMD channel states.
|
|
*/
|
|
enum smd_channel_state {
|
|
SMD_CHANNEL_CLOSED,
|
|
SMD_CHANNEL_OPENING,
|
|
SMD_CHANNEL_OPENED,
|
|
SMD_CHANNEL_FLUSHING,
|
|
SMD_CHANNEL_CLOSING,
|
|
SMD_CHANNEL_RESET,
|
|
SMD_CHANNEL_RESET_OPENING
|
|
};
|
|
|
|
struct qcom_smd_device {
|
|
struct rpmsg_device rpdev;
|
|
|
|
struct qcom_smd_edge *edge;
|
|
};
|
|
|
|
struct qcom_smd_endpoint {
|
|
struct rpmsg_endpoint ept;
|
|
|
|
struct qcom_smd_channel *qsch;
|
|
};
|
|
|
|
#define to_smd_device(r) container_of(r, struct qcom_smd_device, rpdev)
|
|
#define to_smd_edge(d) container_of(d, struct qcom_smd_edge, dev)
|
|
#define to_smd_endpoint(e) container_of(e, struct qcom_smd_endpoint, ept)
|
|
|
|
/**
|
|
* struct qcom_smd_channel - smd channel struct
|
|
* @edge: qcom_smd_edge this channel is living on
|
|
* @qsept: reference to a associated smd endpoint
|
|
* @registered: flag to indicate if the channel is registered
|
|
* @name: name of the channel
|
|
* @state: local state of the channel
|
|
* @remote_state: remote state of the channel
|
|
* @state_change_event: state change event
|
|
* @info: byte aligned outgoing/incoming channel info
|
|
* @info_word: word aligned outgoing/incoming channel info
|
|
* @tx_lock: lock to make writes to the channel mutually exclusive
|
|
* @fblockread_event: wakeup event tied to tx fBLOCKREADINTR
|
|
* @tx_fifo: pointer to the outgoing ring buffer
|
|
* @rx_fifo: pointer to the incoming ring buffer
|
|
* @fifo_size: size of each ring buffer
|
|
* @bounce_buffer: bounce buffer for reading wrapped packets
|
|
* @cb: callback function registered for this channel
|
|
* @recv_lock: guard for rx info modifications and cb pointer
|
|
* @pkt_size: size of the currently handled packet
|
|
* @drvdata: driver private data
|
|
* @list: lite entry for @channels in qcom_smd_edge
|
|
*/
|
|
struct qcom_smd_channel {
|
|
struct qcom_smd_edge *edge;
|
|
|
|
struct qcom_smd_endpoint *qsept;
|
|
bool registered;
|
|
|
|
char *name;
|
|
enum smd_channel_state state;
|
|
enum smd_channel_state remote_state;
|
|
wait_queue_head_t state_change_event;
|
|
|
|
struct smd_channel_info_pair *info;
|
|
struct smd_channel_info_word_pair *info_word;
|
|
|
|
spinlock_t tx_lock;
|
|
wait_queue_head_t fblockread_event;
|
|
|
|
void *tx_fifo;
|
|
void *rx_fifo;
|
|
int fifo_size;
|
|
|
|
void *bounce_buffer;
|
|
|
|
spinlock_t recv_lock;
|
|
|
|
int pkt_size;
|
|
|
|
void *drvdata;
|
|
|
|
struct list_head list;
|
|
};
|
|
|
|
/*
|
|
* Format of the smd_info smem items, for byte aligned channels.
|
|
*/
|
|
struct smd_channel_info {
|
|
__le32 state;
|
|
u8 fDSR;
|
|
u8 fCTS;
|
|
u8 fCD;
|
|
u8 fRI;
|
|
u8 fHEAD;
|
|
u8 fTAIL;
|
|
u8 fSTATE;
|
|
u8 fBLOCKREADINTR;
|
|
__le32 tail;
|
|
__le32 head;
|
|
};
|
|
|
|
struct smd_channel_info_pair {
|
|
struct smd_channel_info tx;
|
|
struct smd_channel_info rx;
|
|
};
|
|
|
|
/*
|
|
* Format of the smd_info smem items, for word aligned channels.
|
|
*/
|
|
struct smd_channel_info_word {
|
|
__le32 state;
|
|
__le32 fDSR;
|
|
__le32 fCTS;
|
|
__le32 fCD;
|
|
__le32 fRI;
|
|
__le32 fHEAD;
|
|
__le32 fTAIL;
|
|
__le32 fSTATE;
|
|
__le32 fBLOCKREADINTR;
|
|
__le32 tail;
|
|
__le32 head;
|
|
};
|
|
|
|
struct smd_channel_info_word_pair {
|
|
struct smd_channel_info_word tx;
|
|
struct smd_channel_info_word rx;
|
|
};
|
|
|
|
#define GET_RX_CHANNEL_FLAG(channel, param) \
|
|
({ \
|
|
BUILD_BUG_ON(sizeof(channel->info->rx.param) != sizeof(u8)); \
|
|
channel->info_word ? \
|
|
le32_to_cpu(channel->info_word->rx.param) : \
|
|
channel->info->rx.param; \
|
|
})
|
|
|
|
#define GET_RX_CHANNEL_INFO(channel, param) \
|
|
({ \
|
|
BUILD_BUG_ON(sizeof(channel->info->rx.param) != sizeof(u32)); \
|
|
le32_to_cpu(channel->info_word ? \
|
|
channel->info_word->rx.param : \
|
|
channel->info->rx.param); \
|
|
})
|
|
|
|
#define SET_RX_CHANNEL_FLAG(channel, param, value) \
|
|
({ \
|
|
BUILD_BUG_ON(sizeof(channel->info->rx.param) != sizeof(u8)); \
|
|
if (channel->info_word) \
|
|
channel->info_word->rx.param = cpu_to_le32(value); \
|
|
else \
|
|
channel->info->rx.param = value; \
|
|
})
|
|
|
|
#define SET_RX_CHANNEL_INFO(channel, param, value) \
|
|
({ \
|
|
BUILD_BUG_ON(sizeof(channel->info->rx.param) != sizeof(u32)); \
|
|
if (channel->info_word) \
|
|
channel->info_word->rx.param = cpu_to_le32(value); \
|
|
else \
|
|
channel->info->rx.param = cpu_to_le32(value); \
|
|
})
|
|
|
|
#define GET_TX_CHANNEL_FLAG(channel, param) \
|
|
({ \
|
|
BUILD_BUG_ON(sizeof(channel->info->tx.param) != sizeof(u8)); \
|
|
channel->info_word ? \
|
|
le32_to_cpu(channel->info_word->tx.param) : \
|
|
channel->info->tx.param; \
|
|
})
|
|
|
|
#define GET_TX_CHANNEL_INFO(channel, param) \
|
|
({ \
|
|
BUILD_BUG_ON(sizeof(channel->info->tx.param) != sizeof(u32)); \
|
|
le32_to_cpu(channel->info_word ? \
|
|
channel->info_word->tx.param : \
|
|
channel->info->tx.param); \
|
|
})
|
|
|
|
#define SET_TX_CHANNEL_FLAG(channel, param, value) \
|
|
({ \
|
|
BUILD_BUG_ON(sizeof(channel->info->tx.param) != sizeof(u8)); \
|
|
if (channel->info_word) \
|
|
channel->info_word->tx.param = cpu_to_le32(value); \
|
|
else \
|
|
channel->info->tx.param = value; \
|
|
})
|
|
|
|
#define SET_TX_CHANNEL_INFO(channel, param, value) \
|
|
({ \
|
|
BUILD_BUG_ON(sizeof(channel->info->tx.param) != sizeof(u32)); \
|
|
if (channel->info_word) \
|
|
channel->info_word->tx.param = cpu_to_le32(value); \
|
|
else \
|
|
channel->info->tx.param = cpu_to_le32(value); \
|
|
})
|
|
|
|
/**
|
|
* struct qcom_smd_alloc_entry - channel allocation entry
|
|
* @name: channel name
|
|
* @cid: channel index
|
|
* @flags: channel flags and edge id
|
|
* @ref_count: reference count of the channel
|
|
*/
|
|
struct qcom_smd_alloc_entry {
|
|
u8 name[20];
|
|
__le32 cid;
|
|
__le32 flags;
|
|
__le32 ref_count;
|
|
} __packed;
|
|
|
|
#define SMD_CHANNEL_FLAGS_EDGE_MASK 0xff
|
|
#define SMD_CHANNEL_FLAGS_STREAM BIT(8)
|
|
#define SMD_CHANNEL_FLAGS_PACKET BIT(9)
|
|
|
|
/*
|
|
* Each smd packet contains a 20 byte header, with the first 4 being the length
|
|
* of the packet.
|
|
*/
|
|
#define SMD_PACKET_HEADER_LEN 20
|
|
|
|
/*
|
|
* Signal the remote processor associated with 'channel'.
|
|
*/
|
|
static void qcom_smd_signal_channel(struct qcom_smd_channel *channel)
|
|
{
|
|
struct qcom_smd_edge *edge = channel->edge;
|
|
|
|
if (edge->mbox_chan) {
|
|
/*
|
|
* We can ignore a failing mbox_send_message() as the only
|
|
* possible cause is that the FIFO in the framework is full of
|
|
* other writes to the same bit.
|
|
*/
|
|
mbox_send_message(edge->mbox_chan, NULL);
|
|
mbox_client_txdone(edge->mbox_chan, 0);
|
|
} else {
|
|
regmap_write(edge->ipc_regmap, edge->ipc_offset, BIT(edge->ipc_bit));
|
|
}
|
|
}
|
|
|
|
/*
|
|
* Initialize the tx channel info
|
|
*/
|
|
static void qcom_smd_channel_reset(struct qcom_smd_channel *channel)
|
|
{
|
|
SET_TX_CHANNEL_INFO(channel, state, SMD_CHANNEL_CLOSED);
|
|
SET_TX_CHANNEL_FLAG(channel, fDSR, 0);
|
|
SET_TX_CHANNEL_FLAG(channel, fCTS, 0);
|
|
SET_TX_CHANNEL_FLAG(channel, fCD, 0);
|
|
SET_TX_CHANNEL_FLAG(channel, fRI, 0);
|
|
SET_TX_CHANNEL_FLAG(channel, fHEAD, 0);
|
|
SET_TX_CHANNEL_FLAG(channel, fTAIL, 0);
|
|
SET_TX_CHANNEL_FLAG(channel, fSTATE, 1);
|
|
SET_TX_CHANNEL_FLAG(channel, fBLOCKREADINTR, 1);
|
|
SET_TX_CHANNEL_INFO(channel, head, 0);
|
|
SET_RX_CHANNEL_INFO(channel, tail, 0);
|
|
|
|
qcom_smd_signal_channel(channel);
|
|
|
|
channel->state = SMD_CHANNEL_CLOSED;
|
|
channel->pkt_size = 0;
|
|
}
|
|
|
|
/*
|
|
* Set the callback for a channel, with appropriate locking
|
|
*/
|
|
static void qcom_smd_channel_set_callback(struct qcom_smd_channel *channel,
|
|
rpmsg_rx_cb_t cb)
|
|
{
|
|
struct rpmsg_endpoint *ept = &channel->qsept->ept;
|
|
unsigned long flags;
|
|
|
|
spin_lock_irqsave(&channel->recv_lock, flags);
|
|
ept->cb = cb;
|
|
spin_unlock_irqrestore(&channel->recv_lock, flags);
|
|
};
|
|
|
|
/*
|
|
* Calculate the amount of data available in the rx fifo
|
|
*/
|
|
static size_t qcom_smd_channel_get_rx_avail(struct qcom_smd_channel *channel)
|
|
{
|
|
unsigned head;
|
|
unsigned tail;
|
|
|
|
head = GET_RX_CHANNEL_INFO(channel, head);
|
|
tail = GET_RX_CHANNEL_INFO(channel, tail);
|
|
|
|
return (head - tail) & (channel->fifo_size - 1);
|
|
}
|
|
|
|
/*
|
|
* Set tx channel state and inform the remote processor
|
|
*/
|
|
static void qcom_smd_channel_set_state(struct qcom_smd_channel *channel,
|
|
int state)
|
|
{
|
|
struct qcom_smd_edge *edge = channel->edge;
|
|
bool is_open = state == SMD_CHANNEL_OPENED;
|
|
|
|
if (channel->state == state)
|
|
return;
|
|
|
|
dev_dbg(&edge->dev, "set_state(%s, %d)\n", channel->name, state);
|
|
|
|
SET_TX_CHANNEL_FLAG(channel, fDSR, is_open);
|
|
SET_TX_CHANNEL_FLAG(channel, fCTS, is_open);
|
|
SET_TX_CHANNEL_FLAG(channel, fCD, is_open);
|
|
|
|
SET_TX_CHANNEL_INFO(channel, state, state);
|
|
SET_TX_CHANNEL_FLAG(channel, fSTATE, 1);
|
|
|
|
channel->state = state;
|
|
qcom_smd_signal_channel(channel);
|
|
}
|
|
|
|
/*
|
|
* Copy count bytes of data using 32bit accesses, if that's required.
|
|
*/
|
|
static void smd_copy_to_fifo(void __iomem *dst,
|
|
const void *src,
|
|
size_t count,
|
|
bool word_aligned)
|
|
{
|
|
if (word_aligned) {
|
|
__iowrite32_copy(dst, src, count / sizeof(u32));
|
|
} else {
|
|
memcpy_toio(dst, src, count);
|
|
}
|
|
}
|
|
|
|
/*
|
|
* Copy count bytes of data using 32bit accesses, if that is required.
|
|
*/
|
|
static void smd_copy_from_fifo(void *dst,
|
|
const void __iomem *src,
|
|
size_t count,
|
|
bool word_aligned)
|
|
{
|
|
if (word_aligned) {
|
|
__ioread32_copy(dst, src, count / sizeof(u32));
|
|
} else {
|
|
memcpy_fromio(dst, src, count);
|
|
}
|
|
}
|
|
|
|
/*
|
|
* Read count bytes of data from the rx fifo into buf, but don't advance the
|
|
* tail.
|
|
*/
|
|
static size_t qcom_smd_channel_peek(struct qcom_smd_channel *channel,
|
|
void *buf, size_t count)
|
|
{
|
|
bool word_aligned;
|
|
unsigned tail;
|
|
size_t len;
|
|
|
|
word_aligned = channel->info_word;
|
|
tail = GET_RX_CHANNEL_INFO(channel, tail);
|
|
|
|
len = min_t(size_t, count, channel->fifo_size - tail);
|
|
if (len) {
|
|
smd_copy_from_fifo(buf,
|
|
channel->rx_fifo + tail,
|
|
len,
|
|
word_aligned);
|
|
}
|
|
|
|
if (len != count) {
|
|
smd_copy_from_fifo(buf + len,
|
|
channel->rx_fifo,
|
|
count - len,
|
|
word_aligned);
|
|
}
|
|
|
|
return count;
|
|
}
|
|
|
|
/*
|
|
* Advance the rx tail by count bytes.
|
|
*/
|
|
static void qcom_smd_channel_advance(struct qcom_smd_channel *channel,
|
|
size_t count)
|
|
{
|
|
unsigned tail;
|
|
|
|
tail = GET_RX_CHANNEL_INFO(channel, tail);
|
|
tail += count;
|
|
tail &= (channel->fifo_size - 1);
|
|
SET_RX_CHANNEL_INFO(channel, tail, tail);
|
|
}
|
|
|
|
/*
|
|
* Read out a single packet from the rx fifo and deliver it to the device
|
|
*/
|
|
static int qcom_smd_channel_recv_single(struct qcom_smd_channel *channel)
|
|
{
|
|
struct rpmsg_endpoint *ept = &channel->qsept->ept;
|
|
unsigned tail;
|
|
size_t len;
|
|
void *ptr;
|
|
int ret;
|
|
|
|
tail = GET_RX_CHANNEL_INFO(channel, tail);
|
|
|
|
/* Use bounce buffer if the data wraps */
|
|
if (tail + channel->pkt_size >= channel->fifo_size) {
|
|
ptr = channel->bounce_buffer;
|
|
len = qcom_smd_channel_peek(channel, ptr, channel->pkt_size);
|
|
} else {
|
|
ptr = channel->rx_fifo + tail;
|
|
len = channel->pkt_size;
|
|
}
|
|
|
|
ret = ept->cb(ept->rpdev, ptr, len, ept->priv, RPMSG_ADDR_ANY);
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
/* Only forward the tail if the client consumed the data */
|
|
qcom_smd_channel_advance(channel, len);
|
|
|
|
channel->pkt_size = 0;
|
|
|
|
return 0;
|
|
}
|
|
|
|
/*
|
|
* Per channel interrupt handling
|
|
*/
|
|
static bool qcom_smd_channel_intr(struct qcom_smd_channel *channel)
|
|
{
|
|
bool need_state_scan = false;
|
|
int remote_state;
|
|
__le32 pktlen;
|
|
int avail;
|
|
int ret;
|
|
|
|
/* Handle state changes */
|
|
remote_state = GET_RX_CHANNEL_INFO(channel, state);
|
|
if (remote_state != channel->remote_state) {
|
|
channel->remote_state = remote_state;
|
|
need_state_scan = true;
|
|
|
|
wake_up_interruptible_all(&channel->state_change_event);
|
|
}
|
|
/* Indicate that we have seen any state change */
|
|
SET_RX_CHANNEL_FLAG(channel, fSTATE, 0);
|
|
|
|
/* Signal waiting qcom_smd_send() about the interrupt */
|
|
if (!GET_TX_CHANNEL_FLAG(channel, fBLOCKREADINTR))
|
|
wake_up_interruptible_all(&channel->fblockread_event);
|
|
|
|
/* Don't consume any data until we've opened the channel */
|
|
if (channel->state != SMD_CHANNEL_OPENED)
|
|
goto out;
|
|
|
|
/* Indicate that we've seen the new data */
|
|
SET_RX_CHANNEL_FLAG(channel, fHEAD, 0);
|
|
|
|
/* Consume data */
|
|
for (;;) {
|
|
avail = qcom_smd_channel_get_rx_avail(channel);
|
|
|
|
if (!channel->pkt_size && avail >= SMD_PACKET_HEADER_LEN) {
|
|
qcom_smd_channel_peek(channel, &pktlen, sizeof(pktlen));
|
|
qcom_smd_channel_advance(channel, SMD_PACKET_HEADER_LEN);
|
|
channel->pkt_size = le32_to_cpu(pktlen);
|
|
} else if (channel->pkt_size && avail >= channel->pkt_size) {
|
|
ret = qcom_smd_channel_recv_single(channel);
|
|
if (ret)
|
|
break;
|
|
} else {
|
|
break;
|
|
}
|
|
}
|
|
|
|
/* Indicate that we have seen and updated tail */
|
|
SET_RX_CHANNEL_FLAG(channel, fTAIL, 1);
|
|
|
|
/* Signal the remote that we've consumed the data (if requested) */
|
|
if (!GET_RX_CHANNEL_FLAG(channel, fBLOCKREADINTR)) {
|
|
/* Ensure ordering of channel info updates */
|
|
wmb();
|
|
|
|
qcom_smd_signal_channel(channel);
|
|
}
|
|
|
|
out:
|
|
return need_state_scan;
|
|
}
|
|
|
|
/*
|
|
* The edge interrupts are triggered by the remote processor on state changes,
|
|
* channel info updates or when new channels are created.
|
|
*/
|
|
static irqreturn_t qcom_smd_edge_intr(int irq, void *data)
|
|
{
|
|
struct qcom_smd_edge *edge = data;
|
|
struct qcom_smd_channel *channel;
|
|
unsigned available;
|
|
bool kick_scanner = false;
|
|
bool kick_state = false;
|
|
|
|
/*
|
|
* Handle state changes or data on each of the channels on this edge
|
|
*/
|
|
spin_lock(&edge->channels_lock);
|
|
list_for_each_entry(channel, &edge->channels, list) {
|
|
spin_lock(&channel->recv_lock);
|
|
kick_state |= qcom_smd_channel_intr(channel);
|
|
spin_unlock(&channel->recv_lock);
|
|
}
|
|
spin_unlock(&edge->channels_lock);
|
|
|
|
/*
|
|
* Creating a new channel requires allocating an smem entry, so we only
|
|
* have to scan if the amount of available space in smem have changed
|
|
* since last scan.
|
|
*/
|
|
available = qcom_smem_get_free_space(edge->remote_pid);
|
|
if (available != edge->smem_available) {
|
|
edge->smem_available = available;
|
|
kick_scanner = true;
|
|
}
|
|
|
|
if (kick_scanner)
|
|
schedule_work(&edge->scan_work);
|
|
if (kick_state)
|
|
schedule_work(&edge->state_work);
|
|
|
|
return IRQ_HANDLED;
|
|
}
|
|
|
|
/*
|
|
* Calculate how much space is available in the tx fifo.
|
|
*/
|
|
static size_t qcom_smd_get_tx_avail(struct qcom_smd_channel *channel)
|
|
{
|
|
unsigned head;
|
|
unsigned tail;
|
|
unsigned mask = channel->fifo_size - 1;
|
|
|
|
head = GET_TX_CHANNEL_INFO(channel, head);
|
|
tail = GET_TX_CHANNEL_INFO(channel, tail);
|
|
|
|
return mask - ((head - tail) & mask);
|
|
}
|
|
|
|
/*
|
|
* Write count bytes of data into channel, possibly wrapping in the ring buffer
|
|
*/
|
|
static int qcom_smd_write_fifo(struct qcom_smd_channel *channel,
|
|
const void *data,
|
|
size_t count)
|
|
{
|
|
bool word_aligned;
|
|
unsigned head;
|
|
size_t len;
|
|
|
|
word_aligned = channel->info_word;
|
|
head = GET_TX_CHANNEL_INFO(channel, head);
|
|
|
|
len = min_t(size_t, count, channel->fifo_size - head);
|
|
if (len) {
|
|
smd_copy_to_fifo(channel->tx_fifo + head,
|
|
data,
|
|
len,
|
|
word_aligned);
|
|
}
|
|
|
|
if (len != count) {
|
|
smd_copy_to_fifo(channel->tx_fifo,
|
|
data + len,
|
|
count - len,
|
|
word_aligned);
|
|
}
|
|
|
|
head += count;
|
|
head &= (channel->fifo_size - 1);
|
|
SET_TX_CHANNEL_INFO(channel, head, head);
|
|
|
|
return count;
|
|
}
|
|
|
|
/**
|
|
* qcom_smd_send - write data to smd channel
|
|
* @channel: channel handle
|
|
* @data: buffer of data to write
|
|
* @len: number of bytes to write
|
|
* @wait: flag to indicate if write has ca wait
|
|
*
|
|
* This is a blocking write of len bytes into the channel's tx ring buffer and
|
|
* signal the remote end. It will sleep until there is enough space available
|
|
* in the tx buffer, utilizing the fBLOCKREADINTR signaling mechanism to avoid
|
|
* polling.
|
|
*/
|
|
static int __qcom_smd_send(struct qcom_smd_channel *channel, const void *data,
|
|
int len, bool wait)
|
|
{
|
|
__le32 hdr[5] = { cpu_to_le32(len), };
|
|
int tlen = sizeof(hdr) + len;
|
|
unsigned long flags;
|
|
int ret;
|
|
|
|
/* Word aligned channels only accept word size aligned data */
|
|
if (channel->info_word && len % 4)
|
|
return -EINVAL;
|
|
|
|
/* Reject packets that are too big */
|
|
if (tlen >= channel->fifo_size)
|
|
return -EINVAL;
|
|
|
|
/* Highlight the fact that if we enter the loop below we might sleep */
|
|
if (wait)
|
|
might_sleep();
|
|
|
|
spin_lock_irqsave(&channel->tx_lock, flags);
|
|
|
|
while (qcom_smd_get_tx_avail(channel) < tlen &&
|
|
channel->state == SMD_CHANNEL_OPENED) {
|
|
if (!wait) {
|
|
ret = -EAGAIN;
|
|
goto out_unlock;
|
|
}
|
|
|
|
SET_TX_CHANNEL_FLAG(channel, fBLOCKREADINTR, 0);
|
|
|
|
/* Wait without holding the tx_lock */
|
|
spin_unlock_irqrestore(&channel->tx_lock, flags);
|
|
|
|
ret = wait_event_interruptible(channel->fblockread_event,
|
|
qcom_smd_get_tx_avail(channel) >= tlen ||
|
|
channel->state != SMD_CHANNEL_OPENED);
|
|
if (ret)
|
|
return ret;
|
|
|
|
spin_lock_irqsave(&channel->tx_lock, flags);
|
|
|
|
SET_TX_CHANNEL_FLAG(channel, fBLOCKREADINTR, 1);
|
|
}
|
|
|
|
/* Fail if the channel was closed */
|
|
if (channel->state != SMD_CHANNEL_OPENED) {
|
|
ret = -EPIPE;
|
|
goto out_unlock;
|
|
}
|
|
|
|
SET_TX_CHANNEL_FLAG(channel, fTAIL, 0);
|
|
|
|
qcom_smd_write_fifo(channel, hdr, sizeof(hdr));
|
|
qcom_smd_write_fifo(channel, data, len);
|
|
|
|
SET_TX_CHANNEL_FLAG(channel, fHEAD, 1);
|
|
|
|
/* Ensure ordering of channel info updates */
|
|
wmb();
|
|
|
|
qcom_smd_signal_channel(channel);
|
|
|
|
out_unlock:
|
|
spin_unlock_irqrestore(&channel->tx_lock, flags);
|
|
|
|
return ret;
|
|
}
|
|
|
|
/*
|
|
* Helper for opening a channel
|
|
*/
|
|
static int qcom_smd_channel_open(struct qcom_smd_channel *channel,
|
|
rpmsg_rx_cb_t cb)
|
|
{
|
|
struct qcom_smd_edge *edge = channel->edge;
|
|
size_t bb_size;
|
|
int ret;
|
|
|
|
/*
|
|
* Packets are maximum 4k, but reduce if the fifo is smaller
|
|
*/
|
|
bb_size = min(channel->fifo_size, SZ_4K);
|
|
channel->bounce_buffer = kmalloc(bb_size, GFP_KERNEL);
|
|
if (!channel->bounce_buffer)
|
|
return -ENOMEM;
|
|
|
|
qcom_smd_channel_set_callback(channel, cb);
|
|
qcom_smd_channel_set_state(channel, SMD_CHANNEL_OPENING);
|
|
|
|
/* Wait for remote to enter opening or opened */
|
|
ret = wait_event_interruptible_timeout(channel->state_change_event,
|
|
channel->remote_state == SMD_CHANNEL_OPENING ||
|
|
channel->remote_state == SMD_CHANNEL_OPENED,
|
|
HZ);
|
|
if (!ret) {
|
|
dev_err(&edge->dev, "remote side did not enter opening state\n");
|
|
goto out_close_timeout;
|
|
}
|
|
|
|
qcom_smd_channel_set_state(channel, SMD_CHANNEL_OPENED);
|
|
|
|
/* Wait for remote to enter opened */
|
|
ret = wait_event_interruptible_timeout(channel->state_change_event,
|
|
channel->remote_state == SMD_CHANNEL_OPENED,
|
|
HZ);
|
|
if (!ret) {
|
|
dev_err(&edge->dev, "remote side did not enter open state\n");
|
|
goto out_close_timeout;
|
|
}
|
|
|
|
return 0;
|
|
|
|
out_close_timeout:
|
|
qcom_smd_channel_set_state(channel, SMD_CHANNEL_CLOSED);
|
|
return -ETIMEDOUT;
|
|
}
|
|
|
|
/*
|
|
* Helper for closing and resetting a channel
|
|
*/
|
|
static void qcom_smd_channel_close(struct qcom_smd_channel *channel)
|
|
{
|
|
qcom_smd_channel_set_callback(channel, NULL);
|
|
|
|
kfree(channel->bounce_buffer);
|
|
channel->bounce_buffer = NULL;
|
|
|
|
qcom_smd_channel_set_state(channel, SMD_CHANNEL_CLOSED);
|
|
qcom_smd_channel_reset(channel);
|
|
}
|
|
|
|
static struct qcom_smd_channel *
|
|
qcom_smd_find_channel(struct qcom_smd_edge *edge, const char *name)
|
|
{
|
|
struct qcom_smd_channel *channel;
|
|
struct qcom_smd_channel *ret = NULL;
|
|
unsigned long flags;
|
|
|
|
spin_lock_irqsave(&edge->channels_lock, flags);
|
|
list_for_each_entry(channel, &edge->channels, list) {
|
|
if (!strcmp(channel->name, name)) {
|
|
ret = channel;
|
|
break;
|
|
}
|
|
}
|
|
spin_unlock_irqrestore(&edge->channels_lock, flags);
|
|
|
|
return ret;
|
|
}
|
|
|
|
static void __ept_release(struct kref *kref)
|
|
{
|
|
struct rpmsg_endpoint *ept = container_of(kref, struct rpmsg_endpoint,
|
|
refcount);
|
|
kfree(to_smd_endpoint(ept));
|
|
}
|
|
|
|
static struct rpmsg_endpoint *qcom_smd_create_ept(struct rpmsg_device *rpdev,
|
|
rpmsg_rx_cb_t cb, void *priv,
|
|
struct rpmsg_channel_info chinfo)
|
|
{
|
|
struct qcom_smd_endpoint *qsept;
|
|
struct qcom_smd_channel *channel;
|
|
struct qcom_smd_device *qsdev = to_smd_device(rpdev);
|
|
struct qcom_smd_edge *edge = qsdev->edge;
|
|
struct rpmsg_endpoint *ept;
|
|
const char *name = chinfo.name;
|
|
int ret;
|
|
|
|
/* Wait up to HZ for the channel to appear */
|
|
ret = wait_event_interruptible_timeout(edge->new_channel_event,
|
|
(channel = qcom_smd_find_channel(edge, name)) != NULL,
|
|
HZ);
|
|
if (!ret)
|
|
return NULL;
|
|
|
|
if (channel->state != SMD_CHANNEL_CLOSED) {
|
|
dev_err(&rpdev->dev, "channel %s is busy\n", channel->name);
|
|
return NULL;
|
|
}
|
|
|
|
qsept = kzalloc(sizeof(*qsept), GFP_KERNEL);
|
|
if (!qsept)
|
|
return NULL;
|
|
|
|
ept = &qsept->ept;
|
|
|
|
kref_init(&ept->refcount);
|
|
|
|
ept->rpdev = rpdev;
|
|
ept->cb = cb;
|
|
ept->priv = priv;
|
|
ept->ops = &qcom_smd_endpoint_ops;
|
|
|
|
channel->qsept = qsept;
|
|
qsept->qsch = channel;
|
|
|
|
ret = qcom_smd_channel_open(channel, cb);
|
|
if (ret)
|
|
goto free_ept;
|
|
|
|
return ept;
|
|
|
|
free_ept:
|
|
channel->qsept = NULL;
|
|
kref_put(&ept->refcount, __ept_release);
|
|
return NULL;
|
|
}
|
|
|
|
static void qcom_smd_destroy_ept(struct rpmsg_endpoint *ept)
|
|
{
|
|
struct qcom_smd_endpoint *qsept = to_smd_endpoint(ept);
|
|
struct qcom_smd_channel *ch = qsept->qsch;
|
|
|
|
qcom_smd_channel_close(ch);
|
|
ch->qsept = NULL;
|
|
kref_put(&ept->refcount, __ept_release);
|
|
}
|
|
|
|
static int qcom_smd_send(struct rpmsg_endpoint *ept, void *data, int len)
|
|
{
|
|
struct qcom_smd_endpoint *qsept = to_smd_endpoint(ept);
|
|
|
|
return __qcom_smd_send(qsept->qsch, data, len, true);
|
|
}
|
|
|
|
static int qcom_smd_trysend(struct rpmsg_endpoint *ept, void *data, int len)
|
|
{
|
|
struct qcom_smd_endpoint *qsept = to_smd_endpoint(ept);
|
|
|
|
return __qcom_smd_send(qsept->qsch, data, len, false);
|
|
}
|
|
|
|
static __poll_t qcom_smd_poll(struct rpmsg_endpoint *ept,
|
|
struct file *filp, poll_table *wait)
|
|
{
|
|
struct qcom_smd_endpoint *qsept = to_smd_endpoint(ept);
|
|
struct qcom_smd_channel *channel = qsept->qsch;
|
|
__poll_t mask = 0;
|
|
|
|
poll_wait(filp, &channel->fblockread_event, wait);
|
|
|
|
if (qcom_smd_get_tx_avail(channel) > 20)
|
|
mask |= EPOLLOUT | EPOLLWRNORM;
|
|
|
|
return mask;
|
|
}
|
|
|
|
/*
|
|
* Finds the device_node for the smd child interested in this channel.
|
|
*/
|
|
static struct device_node *qcom_smd_match_channel(struct device_node *edge_node,
|
|
const char *channel)
|
|
{
|
|
struct device_node *child;
|
|
const char *name;
|
|
const char *key;
|
|
int ret;
|
|
|
|
for_each_available_child_of_node(edge_node, child) {
|
|
key = "qcom,smd-channels";
|
|
ret = of_property_read_string(child, key, &name);
|
|
if (ret)
|
|
continue;
|
|
|
|
if (strcmp(name, channel) == 0)
|
|
return child;
|
|
}
|
|
|
|
return NULL;
|
|
}
|
|
|
|
static int qcom_smd_announce_create(struct rpmsg_device *rpdev)
|
|
{
|
|
struct qcom_smd_endpoint *qept = to_smd_endpoint(rpdev->ept);
|
|
struct qcom_smd_channel *channel = qept->qsch;
|
|
unsigned long flags;
|
|
bool kick_state;
|
|
|
|
spin_lock_irqsave(&channel->recv_lock, flags);
|
|
kick_state = qcom_smd_channel_intr(channel);
|
|
spin_unlock_irqrestore(&channel->recv_lock, flags);
|
|
|
|
if (kick_state)
|
|
schedule_work(&channel->edge->state_work);
|
|
|
|
return 0;
|
|
}
|
|
|
|
static const struct rpmsg_device_ops qcom_smd_device_ops = {
|
|
.create_ept = qcom_smd_create_ept,
|
|
.announce_create = qcom_smd_announce_create,
|
|
};
|
|
|
|
static const struct rpmsg_endpoint_ops qcom_smd_endpoint_ops = {
|
|
.destroy_ept = qcom_smd_destroy_ept,
|
|
.send = qcom_smd_send,
|
|
.trysend = qcom_smd_trysend,
|
|
.poll = qcom_smd_poll,
|
|
};
|
|
|
|
static void qcom_smd_release_device(struct device *dev)
|
|
{
|
|
struct rpmsg_device *rpdev = to_rpmsg_device(dev);
|
|
struct qcom_smd_device *qsdev = to_smd_device(rpdev);
|
|
|
|
kfree(qsdev);
|
|
}
|
|
|
|
/*
|
|
* Create a smd client device for channel that is being opened.
|
|
*/
|
|
static int qcom_smd_create_device(struct qcom_smd_channel *channel)
|
|
{
|
|
struct qcom_smd_device *qsdev;
|
|
struct rpmsg_device *rpdev;
|
|
struct qcom_smd_edge *edge = channel->edge;
|
|
|
|
dev_dbg(&edge->dev, "registering '%s'\n", channel->name);
|
|
|
|
qsdev = kzalloc(sizeof(*qsdev), GFP_KERNEL);
|
|
if (!qsdev)
|
|
return -ENOMEM;
|
|
|
|
/* Link qsdev to our SMD edge */
|
|
qsdev->edge = edge;
|
|
|
|
/* Assign callbacks for rpmsg_device */
|
|
qsdev->rpdev.ops = &qcom_smd_device_ops;
|
|
|
|
/* Assign public information to the rpmsg_device */
|
|
rpdev = &qsdev->rpdev;
|
|
strscpy_pad(rpdev->id.name, channel->name, RPMSG_NAME_SIZE);
|
|
rpdev->src = RPMSG_ADDR_ANY;
|
|
rpdev->dst = RPMSG_ADDR_ANY;
|
|
|
|
rpdev->dev.of_node = qcom_smd_match_channel(edge->of_node, channel->name);
|
|
rpdev->dev.parent = &edge->dev;
|
|
rpdev->dev.release = qcom_smd_release_device;
|
|
|
|
return rpmsg_register_device(rpdev);
|
|
}
|
|
|
|
static int qcom_smd_create_chrdev(struct qcom_smd_edge *edge)
|
|
{
|
|
struct qcom_smd_device *qsdev;
|
|
|
|
qsdev = kzalloc(sizeof(*qsdev), GFP_KERNEL);
|
|
if (!qsdev)
|
|
return -ENOMEM;
|
|
|
|
qsdev->edge = edge;
|
|
qsdev->rpdev.ops = &qcom_smd_device_ops;
|
|
qsdev->rpdev.dev.parent = &edge->dev;
|
|
qsdev->rpdev.dev.release = qcom_smd_release_device;
|
|
|
|
return rpmsg_chrdev_register_device(&qsdev->rpdev);
|
|
}
|
|
|
|
/*
|
|
* Allocate the qcom_smd_channel object for a newly found smd channel,
|
|
* retrieving and validating the smem items involved.
|
|
*/
|
|
static struct qcom_smd_channel *qcom_smd_create_channel(struct qcom_smd_edge *edge,
|
|
unsigned smem_info_item,
|
|
unsigned smem_fifo_item,
|
|
char *name)
|
|
{
|
|
struct qcom_smd_channel *channel;
|
|
size_t fifo_size;
|
|
size_t info_size;
|
|
void *fifo_base;
|
|
void *info;
|
|
int ret;
|
|
|
|
channel = kzalloc(sizeof(*channel), GFP_KERNEL);
|
|
if (!channel)
|
|
return ERR_PTR(-ENOMEM);
|
|
|
|
channel->edge = edge;
|
|
channel->name = kstrdup(name, GFP_KERNEL);
|
|
if (!channel->name) {
|
|
ret = -ENOMEM;
|
|
goto free_channel;
|
|
}
|
|
|
|
spin_lock_init(&channel->tx_lock);
|
|
spin_lock_init(&channel->recv_lock);
|
|
init_waitqueue_head(&channel->fblockread_event);
|
|
init_waitqueue_head(&channel->state_change_event);
|
|
|
|
info = qcom_smem_get(edge->remote_pid, smem_info_item, &info_size);
|
|
if (IS_ERR(info)) {
|
|
ret = PTR_ERR(info);
|
|
goto free_name_and_channel;
|
|
}
|
|
|
|
/*
|
|
* Use the size of the item to figure out which channel info struct to
|
|
* use.
|
|
*/
|
|
if (info_size == 2 * sizeof(struct smd_channel_info_word)) {
|
|
channel->info_word = info;
|
|
} else if (info_size == 2 * sizeof(struct smd_channel_info)) {
|
|
channel->info = info;
|
|
} else {
|
|
dev_err(&edge->dev,
|
|
"channel info of size %zu not supported\n", info_size);
|
|
ret = -EINVAL;
|
|
goto free_name_and_channel;
|
|
}
|
|
|
|
fifo_base = qcom_smem_get(edge->remote_pid, smem_fifo_item, &fifo_size);
|
|
if (IS_ERR(fifo_base)) {
|
|
ret = PTR_ERR(fifo_base);
|
|
goto free_name_and_channel;
|
|
}
|
|
|
|
/* The channel consist of a rx and tx fifo of equal size */
|
|
fifo_size /= 2;
|
|
|
|
dev_dbg(&edge->dev, "new channel '%s' info-size: %zu fifo-size: %zu\n",
|
|
name, info_size, fifo_size);
|
|
|
|
channel->tx_fifo = fifo_base;
|
|
channel->rx_fifo = fifo_base + fifo_size;
|
|
channel->fifo_size = fifo_size;
|
|
|
|
qcom_smd_channel_reset(channel);
|
|
|
|
return channel;
|
|
|
|
free_name_and_channel:
|
|
kfree(channel->name);
|
|
free_channel:
|
|
kfree(channel);
|
|
|
|
return ERR_PTR(ret);
|
|
}
|
|
|
|
/*
|
|
* Scans the allocation table for any newly allocated channels, calls
|
|
* qcom_smd_create_channel() to create representations of these and add
|
|
* them to the edge's list of channels.
|
|
*/
|
|
static void qcom_channel_scan_worker(struct work_struct *work)
|
|
{
|
|
struct qcom_smd_edge *edge = container_of(work, struct qcom_smd_edge, scan_work);
|
|
struct qcom_smd_alloc_entry *alloc_tbl;
|
|
struct qcom_smd_alloc_entry *entry;
|
|
struct qcom_smd_channel *channel;
|
|
unsigned long flags;
|
|
unsigned fifo_id;
|
|
unsigned info_id;
|
|
int tbl;
|
|
int i;
|
|
u32 eflags, cid;
|
|
|
|
for (tbl = 0; tbl < SMD_ALLOC_TBL_COUNT; tbl++) {
|
|
alloc_tbl = qcom_smem_get(edge->remote_pid,
|
|
smem_items[tbl].alloc_tbl_id, NULL);
|
|
if (IS_ERR(alloc_tbl))
|
|
continue;
|
|
|
|
for (i = 0; i < SMD_ALLOC_TBL_SIZE; i++) {
|
|
entry = &alloc_tbl[i];
|
|
eflags = le32_to_cpu(entry->flags);
|
|
if (test_bit(i, edge->allocated[tbl]))
|
|
continue;
|
|
|
|
if (entry->ref_count == 0)
|
|
continue;
|
|
|
|
if (!entry->name[0])
|
|
continue;
|
|
|
|
if (!(eflags & SMD_CHANNEL_FLAGS_PACKET))
|
|
continue;
|
|
|
|
if ((eflags & SMD_CHANNEL_FLAGS_EDGE_MASK) != edge->edge_id)
|
|
continue;
|
|
|
|
cid = le32_to_cpu(entry->cid);
|
|
info_id = smem_items[tbl].info_base_id + cid;
|
|
fifo_id = smem_items[tbl].fifo_base_id + cid;
|
|
|
|
channel = qcom_smd_create_channel(edge, info_id, fifo_id, entry->name);
|
|
if (IS_ERR(channel))
|
|
continue;
|
|
|
|
spin_lock_irqsave(&edge->channels_lock, flags);
|
|
list_add(&channel->list, &edge->channels);
|
|
spin_unlock_irqrestore(&edge->channels_lock, flags);
|
|
|
|
dev_dbg(&edge->dev, "new channel found: '%s'\n", channel->name);
|
|
set_bit(i, edge->allocated[tbl]);
|
|
|
|
wake_up_interruptible_all(&edge->new_channel_event);
|
|
}
|
|
}
|
|
|
|
schedule_work(&edge->state_work);
|
|
}
|
|
|
|
/*
|
|
* This per edge worker scans smem for any new channels and register these. It
|
|
* then scans all registered channels for state changes that should be handled
|
|
* by creating or destroying smd client devices for the registered channels.
|
|
*
|
|
* LOCKING: edge->channels_lock only needs to cover the list operations, as the
|
|
* worker is killed before any channels are deallocated
|
|
*/
|
|
static void qcom_channel_state_worker(struct work_struct *work)
|
|
{
|
|
struct qcom_smd_channel *channel;
|
|
struct qcom_smd_edge *edge = container_of(work,
|
|
struct qcom_smd_edge,
|
|
state_work);
|
|
struct rpmsg_channel_info chinfo;
|
|
unsigned remote_state;
|
|
unsigned long flags;
|
|
|
|
/*
|
|
* Register a device for any closed channel where the remote processor
|
|
* is showing interest in opening the channel.
|
|
*/
|
|
spin_lock_irqsave(&edge->channels_lock, flags);
|
|
list_for_each_entry(channel, &edge->channels, list) {
|
|
if (channel->state != SMD_CHANNEL_CLOSED)
|
|
continue;
|
|
|
|
remote_state = GET_RX_CHANNEL_INFO(channel, state);
|
|
if (remote_state != SMD_CHANNEL_OPENING &&
|
|
remote_state != SMD_CHANNEL_OPENED &&
|
|
remote_state != SMD_CHANNEL_CLOSING)
|
|
continue;
|
|
|
|
if (channel->registered)
|
|
continue;
|
|
|
|
spin_unlock_irqrestore(&edge->channels_lock, flags);
|
|
qcom_smd_create_device(channel);
|
|
channel->registered = true;
|
|
spin_lock_irqsave(&edge->channels_lock, flags);
|
|
|
|
channel->registered = true;
|
|
}
|
|
|
|
/*
|
|
* Unregister the device for any channel that is opened where the
|
|
* remote processor is closing the channel.
|
|
*/
|
|
list_for_each_entry(channel, &edge->channels, list) {
|
|
if (channel->state != SMD_CHANNEL_OPENING &&
|
|
channel->state != SMD_CHANNEL_OPENED)
|
|
continue;
|
|
|
|
remote_state = GET_RX_CHANNEL_INFO(channel, state);
|
|
if (remote_state == SMD_CHANNEL_OPENING ||
|
|
remote_state == SMD_CHANNEL_OPENED)
|
|
continue;
|
|
|
|
spin_unlock_irqrestore(&edge->channels_lock, flags);
|
|
|
|
strscpy_pad(chinfo.name, channel->name, sizeof(chinfo.name));
|
|
chinfo.src = RPMSG_ADDR_ANY;
|
|
chinfo.dst = RPMSG_ADDR_ANY;
|
|
rpmsg_unregister_device(&edge->dev, &chinfo);
|
|
channel->registered = false;
|
|
spin_lock_irqsave(&edge->channels_lock, flags);
|
|
}
|
|
spin_unlock_irqrestore(&edge->channels_lock, flags);
|
|
}
|
|
|
|
/*
|
|
* Parses an of_node describing an edge.
|
|
*/
|
|
static int qcom_smd_parse_edge(struct device *dev,
|
|
struct device_node *node,
|
|
struct qcom_smd_edge *edge)
|
|
{
|
|
struct device_node *syscon_np;
|
|
const char *key;
|
|
int irq;
|
|
int ret;
|
|
|
|
INIT_LIST_HEAD(&edge->channels);
|
|
spin_lock_init(&edge->channels_lock);
|
|
|
|
INIT_WORK(&edge->scan_work, qcom_channel_scan_worker);
|
|
INIT_WORK(&edge->state_work, qcom_channel_state_worker);
|
|
|
|
edge->of_node = of_node_get(node);
|
|
|
|
key = "qcom,smd-edge";
|
|
ret = of_property_read_u32(node, key, &edge->edge_id);
|
|
if (ret) {
|
|
dev_err(dev, "edge missing %s property\n", key);
|
|
goto put_node;
|
|
}
|
|
|
|
edge->remote_pid = QCOM_SMEM_HOST_ANY;
|
|
key = "qcom,remote-pid";
|
|
of_property_read_u32(node, key, &edge->remote_pid);
|
|
|
|
edge->mbox_client.dev = dev;
|
|
edge->mbox_client.knows_txdone = true;
|
|
edge->mbox_chan = mbox_request_channel(&edge->mbox_client, 0);
|
|
if (IS_ERR(edge->mbox_chan)) {
|
|
if (PTR_ERR(edge->mbox_chan) != -ENODEV) {
|
|
ret = PTR_ERR(edge->mbox_chan);
|
|
goto put_node;
|
|
}
|
|
|
|
edge->mbox_chan = NULL;
|
|
|
|
syscon_np = of_parse_phandle(node, "qcom,ipc", 0);
|
|
if (!syscon_np) {
|
|
dev_err(dev, "no qcom,ipc node\n");
|
|
ret = -ENODEV;
|
|
goto put_node;
|
|
}
|
|
|
|
edge->ipc_regmap = syscon_node_to_regmap(syscon_np);
|
|
of_node_put(syscon_np);
|
|
if (IS_ERR(edge->ipc_regmap)) {
|
|
ret = PTR_ERR(edge->ipc_regmap);
|
|
goto put_node;
|
|
}
|
|
|
|
key = "qcom,ipc";
|
|
ret = of_property_read_u32_index(node, key, 1, &edge->ipc_offset);
|
|
if (ret < 0) {
|
|
dev_err(dev, "no offset in %s\n", key);
|
|
goto put_node;
|
|
}
|
|
|
|
ret = of_property_read_u32_index(node, key, 2, &edge->ipc_bit);
|
|
if (ret < 0) {
|
|
dev_err(dev, "no bit in %s\n", key);
|
|
goto put_node;
|
|
}
|
|
}
|
|
|
|
ret = of_property_read_string(node, "label", &edge->name);
|
|
if (ret < 0)
|
|
edge->name = node->name;
|
|
|
|
irq = irq_of_parse_and_map(node, 0);
|
|
if (!irq) {
|
|
dev_err(dev, "required smd interrupt missing\n");
|
|
ret = -EINVAL;
|
|
goto put_node;
|
|
}
|
|
|
|
ret = devm_request_irq(dev, irq,
|
|
qcom_smd_edge_intr, IRQF_TRIGGER_RISING
|
|
| IRQF_NO_SUSPEND, node->name, edge);
|
|
|
|
if (ret) {
|
|
dev_err(dev, "failed to request smd irq\n");
|
|
goto put_node;
|
|
}
|
|
|
|
edge->irq = irq;
|
|
|
|
return 0;
|
|
|
|
put_node:
|
|
of_node_put(node);
|
|
edge->of_node = NULL;
|
|
|
|
return ret;
|
|
}
|
|
|
|
/*
|
|
* Release function for an edge.
|
|
* Reset the state of each associated channel and free the edge context.
|
|
*/
|
|
static void qcom_smd_edge_release(struct device *dev)
|
|
{
|
|
struct qcom_smd_channel *channel, *tmp;
|
|
struct qcom_smd_edge *edge = to_smd_edge(dev);
|
|
|
|
list_for_each_entry_safe(channel, tmp, &edge->channels, list) {
|
|
list_del(&channel->list);
|
|
kfree(channel->name);
|
|
kfree(channel);
|
|
}
|
|
|
|
kfree(edge);
|
|
}
|
|
|
|
static ssize_t rpmsg_name_show(struct device *dev,
|
|
struct device_attribute *attr, char *buf)
|
|
{
|
|
struct qcom_smd_edge *edge = to_smd_edge(dev);
|
|
|
|
return sprintf(buf, "%s\n", edge->name);
|
|
}
|
|
static DEVICE_ATTR_RO(rpmsg_name);
|
|
|
|
static struct attribute *qcom_smd_edge_attrs[] = {
|
|
&dev_attr_rpmsg_name.attr,
|
|
NULL
|
|
};
|
|
ATTRIBUTE_GROUPS(qcom_smd_edge);
|
|
|
|
/**
|
|
* qcom_smd_register_edge() - register an edge based on an device_node
|
|
* @parent: parent device for the edge
|
|
* @node: device_node describing the edge
|
|
*
|
|
* Returns an edge reference, or negative ERR_PTR() on failure.
|
|
*/
|
|
struct qcom_smd_edge *qcom_smd_register_edge(struct device *parent,
|
|
struct device_node *node)
|
|
{
|
|
struct qcom_smd_edge *edge;
|
|
int ret;
|
|
|
|
edge = kzalloc(sizeof(*edge), GFP_KERNEL);
|
|
if (!edge)
|
|
return ERR_PTR(-ENOMEM);
|
|
|
|
init_waitqueue_head(&edge->new_channel_event);
|
|
|
|
edge->dev.parent = parent;
|
|
edge->dev.release = qcom_smd_edge_release;
|
|
edge->dev.of_node = node;
|
|
edge->dev.groups = qcom_smd_edge_groups;
|
|
dev_set_name(&edge->dev, "%s:%pOFn", dev_name(parent), node);
|
|
ret = device_register(&edge->dev);
|
|
if (ret) {
|
|
pr_err("failed to register smd edge\n");
|
|
put_device(&edge->dev);
|
|
return ERR_PTR(ret);
|
|
}
|
|
|
|
ret = qcom_smd_parse_edge(&edge->dev, node, edge);
|
|
if (ret) {
|
|
dev_err(&edge->dev, "failed to parse smd edge\n");
|
|
goto unregister_dev;
|
|
}
|
|
|
|
ret = qcom_smd_create_chrdev(edge);
|
|
if (ret) {
|
|
dev_err(&edge->dev, "failed to register chrdev for edge\n");
|
|
goto unregister_dev;
|
|
}
|
|
|
|
schedule_work(&edge->scan_work);
|
|
|
|
return edge;
|
|
|
|
unregister_dev:
|
|
if (!IS_ERR_OR_NULL(edge->mbox_chan))
|
|
mbox_free_channel(edge->mbox_chan);
|
|
|
|
device_unregister(&edge->dev);
|
|
return ERR_PTR(ret);
|
|
}
|
|
EXPORT_SYMBOL(qcom_smd_register_edge);
|
|
|
|
static int qcom_smd_remove_device(struct device *dev, void *data)
|
|
{
|
|
device_unregister(dev);
|
|
|
|
return 0;
|
|
}
|
|
|
|
/**
|
|
* qcom_smd_unregister_edge() - release an edge and its children
|
|
* @edge: edge reference acquired from qcom_smd_register_edge
|
|
*/
|
|
int qcom_smd_unregister_edge(struct qcom_smd_edge *edge)
|
|
{
|
|
int ret;
|
|
|
|
disable_irq(edge->irq);
|
|
cancel_work_sync(&edge->scan_work);
|
|
cancel_work_sync(&edge->state_work);
|
|
|
|
ret = device_for_each_child(&edge->dev, NULL, qcom_smd_remove_device);
|
|
if (ret)
|
|
dev_warn(&edge->dev, "can't remove smd device: %d\n", ret);
|
|
|
|
mbox_free_channel(edge->mbox_chan);
|
|
device_unregister(&edge->dev);
|
|
|
|
return 0;
|
|
}
|
|
EXPORT_SYMBOL(qcom_smd_unregister_edge);
|
|
|
|
static int qcom_smd_probe(struct platform_device *pdev)
|
|
{
|
|
struct device_node *node;
|
|
void *p;
|
|
|
|
/* Wait for smem */
|
|
p = qcom_smem_get(QCOM_SMEM_HOST_ANY, smem_items[0].alloc_tbl_id, NULL);
|
|
if (PTR_ERR(p) == -EPROBE_DEFER)
|
|
return PTR_ERR(p);
|
|
|
|
for_each_available_child_of_node(pdev->dev.of_node, node)
|
|
qcom_smd_register_edge(&pdev->dev, node);
|
|
|
|
return 0;
|
|
}
|
|
|
|
static int qcom_smd_remove_edge(struct device *dev, void *data)
|
|
{
|
|
struct qcom_smd_edge *edge = to_smd_edge(dev);
|
|
|
|
return qcom_smd_unregister_edge(edge);
|
|
}
|
|
|
|
/*
|
|
* Shut down all smd clients by making sure that each edge stops processing
|
|
* events and scanning for new channels, then call destroy on the devices.
|
|
*/
|
|
static int qcom_smd_remove(struct platform_device *pdev)
|
|
{
|
|
int ret;
|
|
|
|
ret = device_for_each_child(&pdev->dev, NULL, qcom_smd_remove_edge);
|
|
if (ret)
|
|
dev_warn(&pdev->dev, "can't remove smd device: %d\n", ret);
|
|
|
|
return ret;
|
|
}
|
|
|
|
static const struct of_device_id qcom_smd_of_match[] = {
|
|
{ .compatible = "qcom,smd" },
|
|
{}
|
|
};
|
|
MODULE_DEVICE_TABLE(of, qcom_smd_of_match);
|
|
|
|
static struct platform_driver qcom_smd_driver = {
|
|
.probe = qcom_smd_probe,
|
|
.remove = qcom_smd_remove,
|
|
.driver = {
|
|
.name = "qcom-smd",
|
|
.of_match_table = qcom_smd_of_match,
|
|
},
|
|
};
|
|
|
|
static int __init qcom_smd_init(void)
|
|
{
|
|
return platform_driver_register(&qcom_smd_driver);
|
|
}
|
|
subsys_initcall(qcom_smd_init);
|
|
|
|
static void __exit qcom_smd_exit(void)
|
|
{
|
|
platform_driver_unregister(&qcom_smd_driver);
|
|
}
|
|
module_exit(qcom_smd_exit);
|
|
|
|
MODULE_AUTHOR("Bjorn Andersson <bjorn.andersson@sonymobile.com>");
|
|
MODULE_DESCRIPTION("Qualcomm Shared Memory Driver");
|
|
MODULE_LICENSE("GPL v2");
|