Changes in 4.9.238 af_key: pfkey_dump needs parameter validation KVM: fix memory leak in kvm_io_bus_unregister_dev() kprobes: fix kill kprobe which has been marked as gone RDMA/ucma: ucma_context reference leak in error path mtd: Fix comparison in map_word_andequal() hdlc_ppp: add range checks in ppp_cp_parse_cr() ip: fix tos reflection in ack and reset packets tipc: use skb_unshare() instead in tipc_buf_append() bnxt_en: Protect bnxt_set_eee() and bnxt_set_pauseparam() with mutex. net: phy: Avoid NPD upon phy_detach() when driver is unbound net/hsr: Check skb_put_padto() return value net: add __must_check to skb_put_padto() serial: 8250: Avoid error message on reprobe scsi: aacraid: fix illegal IO beyond last LBA m68k: q40: Fix info-leak in rtc_ioctl gma/gma500: fix a memory disclosure bug due to uninitialized bytes ASoC: kirkwood: fix IRQ error handling ALSA: usb-audio: Add delay quirk for H570e USB headsets PM / devfreq: tegra30: Fix integer overflow on CPU's freq max out clk/ti/adpll: allocate room for terminating null mtd: cfi_cmdset_0002: don't free cfi->cfiq in error path of cfi_amdstd_setup() mfd: mfd-core: Protect against NULL call-back function pointer tracing: Adding NULL checks for trace_array descriptor pointer bcache: fix a lost wake-up problem caused by mca_cannibalize_lock RDMA/i40iw: Fix potential use after free xfs: fix attr leaf header freemap.size underflow RDMA/iw_cgxb4: Fix an error handling path in 'c4iw_connect()' debugfs: Fix !DEBUG_FS debugfs_create_automount CIFS: Properly process SMB3 lease breaks kernel/sys.c: avoid copying possible padding bytes in copy_to_user neigh_stat_seq_next() should increase position index rt_cpu_seq_next should increase position index seqlock: Require WRITE_ONCE surrounding raw_seqcount_barrier media: ti-vpe: cal: Restrict DMA to avoid memory corruption ACPI: EC: Reference count query handlers under lock dmaengine: zynqmp_dma: fix burst length configuration tracing: Set kernel_stack's caller size properly ar5523: Add USB ID of SMCWUSBT-G2 wireless adapter Bluetooth: Fix refcount use-after-free issue mm: pagewalk: fix termination condition in walk_pte_range() Bluetooth: prefetch channel before killing sock KVM: fix overflow of zero page refcount with ksm running ALSA: hda: Clear RIRB status before reading WP skbuff: fix a data race in skb_queue_len() audit: CONFIG_CHANGE don't log internal bookkeeping as an event selinux: sel_avc_get_stat_idx should increase position index scsi: lpfc: Fix RQ buffer leakage when no IOCBs available scsi: lpfc: Fix coverity errors in fmdi attribute handling drm/omap: fix possible object reference leak RDMA/rxe: Fix configuration of atomic queue pair attributes KVM: x86: fix incorrect comparison in trace event x86/pkeys: Add check for pkey "overflow" bpf: Remove recursion prevention from rcu free callback dmaengine: tegra-apb: Prevent race conditions on channel's freeing media: go7007: Fix URB type for interrupt handling Bluetooth: guard against controllers sending zero'd events timekeeping: Prevent 32bit truncation in scale64_check_overflow() drm/amdgpu: increase atombios cmd timeout Bluetooth: L2CAP: handle l2cap config request during open state media: tda10071: fix unsigned sign extension overflow xfs: don't ever return a stale pointer from __xfs_dir3_free_read tpm: ibmvtpm: Wait for buffer to be set before proceeding tracing: Use address-of operator on section symbols serial: 8250_port: Don't service RX FIFO if throttled serial: 8250_omap: Fix sleeping function called from invalid context during probe serial: 8250: 8250_omap: Terminate DMA before pushing data on RX timeout cpufreq: powernv: Fix frame-size-overflow in powernv_cpufreq_work_fn tools: gpio-hammer: Avoid potential overflow in main SUNRPC: Fix a potential buffer overflow in 'svc_print_xprts()' svcrdma: Fix leak of transport addresses ubifs: Fix out-of-bounds memory access caused by abnormal value of node_len ALSA: usb-audio: Fix case when USB MIDI interface has more than one extra endpoint descriptor mm/filemap.c: clear page error before actual read mm/mmap.c: initialize align_offset explicitly for vm_unmapped_area KVM: Remove CREATE_IRQCHIP/SET_PIT2 race bdev: Reduce time holding bd_mutex in sync in blkdev_close() drivers: char: tlclk.c: Avoid data race between init and interrupt handler dt-bindings: sound: wm8994: Correct required supplies based on actual implementaion atm: fix a memory leak of vcc->user_back phy: samsung: s5pv210-usb2: Add delay after reset Bluetooth: Handle Inquiry Cancel error after Inquiry Complete USB: EHCI: ehci-mv: fix error handling in mv_ehci_probe() tty: serial: samsung: Correct clock selection logic ALSA: hda: Fix potential race in unsol event handler fuse: don't check refcount after stealing page USB: EHCI: ehci-mv: fix less than zero comparison of an unsigned int e1000: Do not perform reset in reset_task if we are already down printk: handle blank console arguments passed in. btrfs: don't force read-only after error in drop snapshot vfio/pci: fix memory leaks of eventfd ctx perf util: Fix memory leak of prefix_if_not_in perf kcore_copy: Fix module map when there are no modules loaded mtd: rawnand: omap_elm: Fix runtime PM imbalance on error ceph: fix potential race in ceph_check_caps mtd: parser: cmdline: Support MTD names containing one or more colons x86/speculation/mds: Mark mds_user_clear_cpu_buffers() __always_inline vfio/pci: Clear error and request eventfd ctx after releasing cifs: Fix double add page to memcg when cifs_readpages selftests/x86/syscall_nt: Clear weird flags after each test vfio/pci: fix racy on error and request eventfd ctx s390/init: add missing __init annotations i2c: core: Call i2c_acpi_install_space_handler() before i2c_acpi_register_devices() objtool: Fix noreturn detection for ignored functions ieee802154/adf7242: check status of adf7242_read_reg clocksource/drivers/h8300_timer8: Fix wrong return value in h8300_8timer_init() mwifiex: Increase AES key storage size to 256 bits batman-adv: bla: fix type misuse for backbone_gw hash indexing atm: eni: fix the missed pci_disable_device() for eni_init_one() batman-adv: mcast/TT: fix wrongly dropped or rerouted packets mac802154: tx: fix use-after-free batman-adv: Add missing include for in_interrupt() batman-adv: mcast: fix duplicate mcast packets in BLA backbone from mesh ALSA: asihpi: fix iounmap in error handler MIPS: Add the missing 'CPU_1074K' into __get_cpu_type() kprobes: Fix to check probe enabled before disarm_kprobe_ftrace() lib/string.c: implement stpcpy ata: define AC_ERR_OK ata: make qc_prep return ata_completion_errors ata: sata_mv, avoid trigerrable BUG_ON Linux 4.9.238 Signed-off-by: Greg Kroah-Hartman <gregkh@google.com> Change-Id: I799877db3bc49e473bbc023ab948cd241755beff
		
			
				
	
	
		
			221 lines
		
	
	
		
			5.6 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
			
		
		
	
	
			221 lines
		
	
	
		
			5.6 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
| /*
 | |
|  * HD-audio core bus driver
 | |
|  */
 | |
| 
 | |
| #include <linux/init.h>
 | |
| #include <linux/device.h>
 | |
| #include <linux/module.h>
 | |
| #include <linux/export.h>
 | |
| #include <sound/hdaudio.h>
 | |
| #include "trace.h"
 | |
| 
 | |
| static void process_unsol_events(struct work_struct *work);
 | |
| 
 | |
| static const struct hdac_bus_ops default_ops = {
 | |
| 	.command = snd_hdac_bus_send_cmd,
 | |
| 	.get_response = snd_hdac_bus_get_response,
 | |
| };
 | |
| 
 | |
| /**
 | |
|  * snd_hdac_bus_init - initialize a HD-audio bas bus
 | |
|  * @bus: the pointer to bus object
 | |
|  * @ops: bus verb operators
 | |
|  * @io_ops: lowlevel I/O operators
 | |
|  *
 | |
|  * Returns 0 if successful, or a negative error code.
 | |
|  */
 | |
| int snd_hdac_bus_init(struct hdac_bus *bus, struct device *dev,
 | |
| 		      const struct hdac_bus_ops *ops,
 | |
| 		      const struct hdac_io_ops *io_ops)
 | |
| {
 | |
| 	memset(bus, 0, sizeof(*bus));
 | |
| 	bus->dev = dev;
 | |
| 	if (ops)
 | |
| 		bus->ops = ops;
 | |
| 	else
 | |
| 		bus->ops = &default_ops;
 | |
| 	bus->io_ops = io_ops;
 | |
| 	INIT_LIST_HEAD(&bus->stream_list);
 | |
| 	INIT_LIST_HEAD(&bus->codec_list);
 | |
| 	INIT_WORK(&bus->unsol_work, process_unsol_events);
 | |
| 	spin_lock_init(&bus->reg_lock);
 | |
| 	mutex_init(&bus->cmd_mutex);
 | |
| 	bus->irq = -1;
 | |
| 	return 0;
 | |
| }
 | |
| EXPORT_SYMBOL_GPL(snd_hdac_bus_init);
 | |
| 
 | |
| /**
 | |
|  * snd_hdac_bus_exit - clean up a HD-audio bas bus
 | |
|  * @bus: the pointer to bus object
 | |
|  */
 | |
| void snd_hdac_bus_exit(struct hdac_bus *bus)
 | |
| {
 | |
| 	WARN_ON(!list_empty(&bus->stream_list));
 | |
| 	WARN_ON(!list_empty(&bus->codec_list));
 | |
| 	cancel_work_sync(&bus->unsol_work);
 | |
| }
 | |
| EXPORT_SYMBOL_GPL(snd_hdac_bus_exit);
 | |
| 
 | |
| /**
 | |
|  * snd_hdac_bus_exec_verb - execute a HD-audio verb on the given bus
 | |
|  * @bus: bus object
 | |
|  * @cmd: HD-audio encoded verb
 | |
|  * @res: pointer to store the response, NULL if performing asynchronously
 | |
|  *
 | |
|  * Returns 0 if successful, or a negative error code.
 | |
|  */
 | |
| int snd_hdac_bus_exec_verb(struct hdac_bus *bus, unsigned int addr,
 | |
| 			   unsigned int cmd, unsigned int *res)
 | |
| {
 | |
| 	int err;
 | |
| 
 | |
| 	mutex_lock(&bus->cmd_mutex);
 | |
| 	err = snd_hdac_bus_exec_verb_unlocked(bus, addr, cmd, res);
 | |
| 	mutex_unlock(&bus->cmd_mutex);
 | |
| 	return err;
 | |
| }
 | |
| EXPORT_SYMBOL_GPL(snd_hdac_bus_exec_verb);
 | |
| 
 | |
| /**
 | |
|  * snd_hdac_bus_exec_verb_unlocked - unlocked version
 | |
|  * @bus: bus object
 | |
|  * @cmd: HD-audio encoded verb
 | |
|  * @res: pointer to store the response, NULL if performing asynchronously
 | |
|  *
 | |
|  * Returns 0 if successful, or a negative error code.
 | |
|  */
 | |
| int snd_hdac_bus_exec_verb_unlocked(struct hdac_bus *bus, unsigned int addr,
 | |
| 				    unsigned int cmd, unsigned int *res)
 | |
| {
 | |
| 	unsigned int tmp;
 | |
| 	int err;
 | |
| 
 | |
| 	if (cmd == ~0)
 | |
| 		return -EINVAL;
 | |
| 
 | |
| 	if (res)
 | |
| 		*res = -1;
 | |
| 	else if (bus->sync_write)
 | |
| 		res = &tmp;
 | |
| 	for (;;) {
 | |
| 		trace_hda_send_cmd(bus, cmd);
 | |
| 		err = bus->ops->command(bus, cmd);
 | |
| 		if (err != -EAGAIN)
 | |
| 			break;
 | |
| 		/* process pending verbs */
 | |
| 		err = bus->ops->get_response(bus, addr, &tmp);
 | |
| 		if (err)
 | |
| 			break;
 | |
| 	}
 | |
| 	if (!err && res) {
 | |
| 		err = bus->ops->get_response(bus, addr, res);
 | |
| 		trace_hda_get_response(bus, addr, *res);
 | |
| 	}
 | |
| 	return err;
 | |
| }
 | |
| EXPORT_SYMBOL_GPL(snd_hdac_bus_exec_verb_unlocked);
 | |
| 
 | |
| /**
 | |
|  * snd_hdac_bus_queue_event - add an unsolicited event to queue
 | |
|  * @bus: the BUS
 | |
|  * @res: unsolicited event (lower 32bit of RIRB entry)
 | |
|  * @res_ex: codec addr and flags (upper 32bit or RIRB entry)
 | |
|  *
 | |
|  * Adds the given event to the queue.  The events are processed in
 | |
|  * the workqueue asynchronously.  Call this function in the interrupt
 | |
|  * hanlder when RIRB receives an unsolicited event.
 | |
|  */
 | |
| void snd_hdac_bus_queue_event(struct hdac_bus *bus, u32 res, u32 res_ex)
 | |
| {
 | |
| 	unsigned int wp;
 | |
| 
 | |
| 	if (!bus)
 | |
| 		return;
 | |
| 
 | |
| 	trace_hda_unsol_event(bus, res, res_ex);
 | |
| 	wp = (bus->unsol_wp + 1) % HDA_UNSOL_QUEUE_SIZE;
 | |
| 	bus->unsol_wp = wp;
 | |
| 
 | |
| 	wp <<= 1;
 | |
| 	bus->unsol_queue[wp] = res;
 | |
| 	bus->unsol_queue[wp + 1] = res_ex;
 | |
| 
 | |
| 	schedule_work(&bus->unsol_work);
 | |
| }
 | |
| EXPORT_SYMBOL_GPL(snd_hdac_bus_queue_event);
 | |
| 
 | |
| /*
 | |
|  * process queued unsolicited events
 | |
|  */
 | |
| static void process_unsol_events(struct work_struct *work)
 | |
| {
 | |
| 	struct hdac_bus *bus = container_of(work, struct hdac_bus, unsol_work);
 | |
| 	struct hdac_device *codec;
 | |
| 	struct hdac_driver *drv;
 | |
| 	unsigned int rp, caddr, res;
 | |
| 
 | |
| 	spin_lock_irq(&bus->reg_lock);
 | |
| 	while (bus->unsol_rp != bus->unsol_wp) {
 | |
| 		rp = (bus->unsol_rp + 1) % HDA_UNSOL_QUEUE_SIZE;
 | |
| 		bus->unsol_rp = rp;
 | |
| 		rp <<= 1;
 | |
| 		res = bus->unsol_queue[rp];
 | |
| 		caddr = bus->unsol_queue[rp + 1];
 | |
| 		if (!(caddr & (1 << 4))) /* no unsolicited event? */
 | |
| 			continue;
 | |
| 		codec = bus->caddr_tbl[caddr & 0x0f];
 | |
| 		if (!codec || !codec->dev.driver)
 | |
| 			continue;
 | |
| 		spin_unlock_irq(&bus->reg_lock);
 | |
| 		drv = drv_to_hdac_driver(codec->dev.driver);
 | |
| 		if (drv->unsol_event)
 | |
| 			drv->unsol_event(codec, res);
 | |
| 		spin_lock_irq(&bus->reg_lock);
 | |
| 	}
 | |
| 	spin_unlock_irq(&bus->reg_lock);
 | |
| }
 | |
| 
 | |
| /**
 | |
|  * snd_hdac_bus_add_device - Add a codec to bus
 | |
|  * @bus: HDA core bus
 | |
|  * @codec: HDA core device to add
 | |
|  *
 | |
|  * Adds the given codec to the list in the bus.  The caddr_tbl array
 | |
|  * and codec_powered bits are updated, as well.
 | |
|  * Returns zero if success, or a negative error code.
 | |
|  */
 | |
| int snd_hdac_bus_add_device(struct hdac_bus *bus, struct hdac_device *codec)
 | |
| {
 | |
| 	if (bus->caddr_tbl[codec->addr]) {
 | |
| 		dev_err(bus->dev, "address 0x%x is already occupied\n",
 | |
| 			codec->addr);
 | |
| 		return -EBUSY;
 | |
| 	}
 | |
| 
 | |
| 	list_add_tail(&codec->list, &bus->codec_list);
 | |
| 	bus->caddr_tbl[codec->addr] = codec;
 | |
| 	set_bit(codec->addr, &bus->codec_powered);
 | |
| 	bus->num_codecs++;
 | |
| 	return 0;
 | |
| }
 | |
| EXPORT_SYMBOL_GPL(snd_hdac_bus_add_device);
 | |
| 
 | |
| /**
 | |
|  * snd_hdac_bus_remove_device - Remove a codec from bus
 | |
|  * @bus: HDA core bus
 | |
|  * @codec: HDA core device to remove
 | |
|  */
 | |
| void snd_hdac_bus_remove_device(struct hdac_bus *bus,
 | |
| 				struct hdac_device *codec)
 | |
| {
 | |
| 	WARN_ON(bus != codec->bus);
 | |
| 	if (list_empty(&codec->list))
 | |
| 		return;
 | |
| 	list_del_init(&codec->list);
 | |
| 	bus->caddr_tbl[codec->addr] = NULL;
 | |
| 	clear_bit(codec->addr, &bus->codec_powered);
 | |
| 	bus->num_codecs--;
 | |
| }
 | |
| EXPORT_SYMBOL_GPL(snd_hdac_bus_remove_device);
 |