Skip to content

Remove excessive kernel log of amvideocap driver - #112

Merged
mdrjr merged 1 commit into
hardkernel:odroidc-3.10.yfrom
ricardona:odroidc-3.10.y
Jul 25, 2015
Merged

mdrjr merged 1 commit into
hardkernel:odroidc-3.10.yfrom
ricardona:odroidc-3.10.y

Conversation

@ricardona

Copy link
Copy Markdown

When the amvideocap driver is running it registers every video capture (10 per second) to kernel log, in 1 hour the kernel.log file can increase 45 MB.

mdrjr added a commit that referenced this pull request Jul 25, 2015
Remove excessive kernel log of amvideocap driver
@mdrjr
mdrjr merged commit 73b1b60 into hardkernel:odroidc-3.10.y Jul 25, 2015
@mdrjr

mdrjr commented Jul 25, 2015

Copy link
Copy Markdown
Collaborator

Thanks for that Ricardo!

Dmole pushed a commit to Dmole/linux that referenced this pull request Jun 8, 2017
[ Upstream commit d8b5411 ]

Shubham was recently asking on netdev why in arm64 JIT we don't multiply
the index for accessing the tail call map by 8. That led me into testing
out arm64 JIT wrt tail calls and it turned out I got a NULL pointer
dereference on the tail call.

The buggy access is at:

  prog = array->ptrs[index];
  if (prog == NULL)
      goto out;

  [...]
  00000060:  d2800e0a  mov x10, #0x70 // hardkernel#112
  00000064:  f86a682a  ldr x10, [x1,x10]
  00000068:  f862694b  ldr x11, [x10,x2]
  0000006c:  b40000ab  cbz x11, 0x00000080
  [...]

The code triggering the crash is f862694b. x1 at the time contains the
address of the bpf array, x10 offsetof(struct bpf_array, ptrs). Meaning,
above we load the pointer to the program at map slot 0 into x10. x10
can then be NULL if the slot is not occupied, which we later on try to
access with a user given offset in x2 that is the map index.

Fix this by emitting the following instead:

  [...]
  00000060:  d2800e0a  mov x10, #0x70 // hardkernel#112
  00000064:  8b0a002a  add x10, x1, x10
  00000068:  d37df04b  lsl x11, x2, hardkernel#3
  0000006c:  f86b694b  ldr x11, [x10,x11]
  00000070:  b40000ab  cbz x11, 0x00000084
  [...]

This basically adds the offset to ptrs to the base address of the bpf
array we got and we later on access the map with an index * 8 offset
relative to that. The tail call map itself is basically one large area
with meta data at the head followed by the array of prog pointers.
This makes tail calls working again, tested on Cavium ThunderX ARMv8.

Fixes: ddb5599 ("arm64: bpf: implement bpf_tail_call() helper")
Reported-by: Shubham Bansal <illusionist.neo@gmail.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
ardje pushed a commit to ardje/linux that referenced this pull request Aug 6, 2018
[ Upstream commit 74174fe ]

On fast hosts or malicious bots, we trigger a DCCP_BUG() which
seems excessive.

syzbot reported :

BUG: delta (-6195) <= 0 at net/dccp/ccids/ccid3.c:628/ccid3_hc_rx_send_feedback()
CPU: 1 PID: 18 Comm: ksoftirqd/1 Not tainted 4.18.0-rc1+ hardkernel#112
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
 __dump_stack lib/dump_stack.c:77 [inline]
 dump_stack+0x1c9/0x2b4 lib/dump_stack.c:113
 ccid3_hc_rx_send_feedback net/dccp/ccids/ccid3.c:628 [inline]
 ccid3_hc_rx_packet_recv.cold.16+0x38/0x71 net/dccp/ccids/ccid3.c:793
 ccid_hc_rx_packet_recv net/dccp/ccid.h:185 [inline]
 dccp_deliver_input_to_ccids+0xf0/0x280 net/dccp/input.c:180
 dccp_rcv_established+0x87/0xb0 net/dccp/input.c:378
 dccp_v4_do_rcv+0x153/0x180 net/dccp/ipv4.c:654
 sk_backlog_rcv include/net/sock.h:914 [inline]
 __sk_receive_skb+0x3ba/0xd80 net/core/sock.c:517
 dccp_v4_rcv+0x10f9/0x1f58 net/dccp/ipv4.c:875
 ip_local_deliver_finish+0x2eb/0xda0 net/ipv4/ip_input.c:215
 NF_HOOK include/linux/netfilter.h:287 [inline]
 ip_local_deliver+0x1e9/0x750 net/ipv4/ip_input.c:256
 dst_input include/net/dst.h:450 [inline]
 ip_rcv_finish+0x823/0x2220 net/ipv4/ip_input.c:396
 NF_HOOK include/linux/netfilter.h:287 [inline]
 ip_rcv+0xa18/0x1284 net/ipv4/ip_input.c:492
 __netif_receive_skb_core+0x2488/0x3680 net/core/dev.c:4628
 __netif_receive_skb+0x2c/0x1e0 net/core/dev.c:4693
 process_backlog+0x219/0x760 net/core/dev.c:5373
 napi_poll net/core/dev.c:5771 [inline]
 net_rx_action+0x7da/0x1980 net/core/dev.c:5837
 __do_softirq+0x2e8/0xb17 kernel/softirq.c:284
 run_ksoftirqd+0x86/0x100 kernel/softirq.c:645
 smpboot_thread_fn+0x417/0x870 kernel/smpboot.c:164
 kthread+0x345/0x410 kernel/kthread.c:240
 ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:412

Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: syzbot <syzkaller@googlegroups.com>
Cc: Gerrit Renker <gerrit@erg.abdn.ac.uk>
Cc: dccp@vger.kernel.org
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
codewalkerster pushed a commit that referenced this pull request Sep 16, 2026
…pend

VO_GRF is belong to PD_VO and VOP is belong to PD_VOP. During
suspend, VOP accessing the emp-related registers in VO_GRF across
power domains may lead to an unpredictable sequence of power domain
turn off, potentially causing a system crash. Since HDMI and
VO_GRF share the same power domain, access to the EMP-related
registers in VO_GRF must be performed exclusively within HDMI
driver.

The crash stack is as follows:

[   31.751607][    C3] SError Interrupt on CPU3, code 0x00000000bf000000
-- SError
[   31.751621][    C3] CPU: 3 UID: 1000 PID: 1332 Comm: binder:368_4
Tainted: G   M       O       6.12.58+ #112
[   31.751633][    C3] Tainted: [M]=MACHINE_CHECK, [O]=OOT_MODULE
[   31.751637][    C3] Hardware name: Rockchip RK3572 EVB1 V10 Board
(DT)
[   31.751641][    C3] pstate: 804000c5 (Nzcv daIF +PAN -UAO -TCO -DIT
-SSBS BTYPE=--)
[   31.751649][    C3] pc : clk_core_disable+0x4/0x1d8
[   31.751664][    C3] lr : clk_disable+0x30/0x98
[   31.751672][    C3] sp : ffffffc085d3b810
[   31.751675][    C3] x29: ffffffc085d3b810 x28: ffffffe8d235c000 x27:
ffffff80c4c70080
[   31.751687][    C3] x26: 0000000000000000 x25: ffffff80c4c7641b x24:
0000000000000000
[   31.751696][    C3] x23: ffffffe8d14c49c0 x22: ffffff80c4321800 x21:
0000000000000000
[   31.751704][    C3] x20: ffffff80c01a4c00 x19: 00000000000000c0 x18:
ffffffc0842150a0
[   31.751712][    C3] x17: 00000000803ccd4d x16: 00000000803ccd4d x15:
0000000000000095
[   31.751720][    C3] x14: ffffffe8d1f1a780 x13: 0000000000000040 x12:
0000000000000000
[   31.751728][    C3] x11: 0000000000000001 x10: 0000000000000000 x9 :
ffffff801b22ca00
[   31.751736][    C3] x8 : 0000000000000001 x7 : 0000000000000000 x6 :
0000000000000000
[   31.751744][    C3] x5 : 0000000000000001 x4 : 0000000000000000 x3 :
ffffff801b22ca00
[   31.751751][    C3] x2 : 0000000040000000 x1 : 0000000000000000 x0 :
ffffff80c01a4c00
[   31.751762][    C3] Kernel panic - not syncing: Asynchronous SError
Interrupt
[   31.751767][    C3] CPU: 3 UID: 1000 PID: 1332 Comm: binder:368_4
Tainted: G   M       O       6.12.58+ #112
[   31.751775][    C3] Tainted: [M]=MACHINE_CHECK, [O]=OOT_MODULE
[   31.751778][    C3] Hardware name: Rockchip RK3572 EVB1 V10 Board
(DT)
[   31.751782][    C3] Call trace:
[   31.751784][    C3]  dump_backtrace+0xe8/0x108
[   31.751795][    C3]  show_stack+0x18/0x28
[   31.751801][    C3]  dump_stack_lvl+0x40/0xbc
[   31.751810][    C3]  dump_stack+0x18/0x30
[   31.751816][    C3]  panic+0x128/0x370
[   31.751822][    C3]  nmi_panic+0x3c/0x88
[   31.751829][    C3]  arm64_serror_panic+0x6c/0x7c
[   31.751836][    C3]  do_serror+0xdc/0xf8
[   31.751842][    C3]  el1h_64_error_handler+0x34/0x48
[   31.751852][    C3]  el1h_64_error+0x7c/0x80
[   31.751857][    C3]  clk_core_disable+0x4/0x1d8
[   31.751866][    C3]  regmap_mmio_write+0x70/0x8c
[   31.751876][    C3]  _regmap_bus_reg_write+0x114/0x14c
[   31.751886][    C3]  _regmap_write+0x16c/0x264
[   31.751891][    C3]  regmap_write+0x6c/0xac
[   31.751896][    C3]  vop2_crtc_atomic_disable+0x50c/0x20e0
[   31.751904][    C3]
drm_atomic_helper_commit_modeset_disables+0x334/0x664
[   31.751916][    C3]
rockchip_drm_atomic_helper_commit_tail_rpm+0x4c/0x3a4
[   31.751926][    C3]  commit_tail+0xbc/0x170
[   31.751932][    C3]  drm_atomic_helper_commit+0x2ac/0x2d0
[   31.751938][    C3]  drm_atomic_commit+0xc4/0xf4
[   31.751946][    C3]  drm_mode_atomic_ioctl+0x638/0xb28
[   31.751953][    C3]  drm_ioctl+0x320/0x5d0
[   31.751962][    C3]  __arm64_sys_ioctl+0xa8/0xe4
[   31.751972][    C3]  invoke_syscall+0x58/0x10c
[   31.751978][    C3]  el0_svc_common+0xac/0xe0
[   31.751984][    C3]  do_el0_svc+0x1c/0x28
[   31.751989][    C3]  el0_svc+0x2c/0x7c
[   31.751995][    C3]  el0t_64_sync_handler+0x68/0xbc
[   31.752001][    C3]  el0t_64_sync+0x16c/0x170

Change-Id: I867f44e8711cebb804338c559ae836ef34809b37
Signed-off-by: Algea Cao <algea.cao@rock-chips.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants