Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1301820

[PATCH 3.12 52/91] Btrfs: fix race leading to incorrect item deletion when dropping extents

From Jiri Slaby <jslaby@suse.cz>
Newsgroups linux.kernel
Subject [PATCH 3.12 52/91] Btrfs: fix race leading to incorrect item deletion when dropping extents
Date 2016-01-05 19:10 +0100
Message-ID <qNEdv-6sw-69@gated-at.bofh.it> (permalink)
References <qNDU6-65D-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


From: Filipe Manana <fdmanana@suse.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit aeafbf8486c9e2bd53f5cc3c10c0b7fd7149d69c upstream.

While running a stress test I got the following warning triggered:

  [191627.672810] ------------[ cut here ]------------
  [191627.673949] WARNING: CPU: 8 PID: 8447 at fs/btrfs/file.c:779 __btrfs_drop_extents+0x391/0xa50 [btrfs]()
  (...)
  [191627.701485] Call Trace:
  [191627.702037]  [<ffffffff8145f077>] dump_stack+0x4f/0x7b
  [191627.702992]  [<ffffffff81095de5>] ? console_unlock+0x356/0x3a2
  [191627.704091]  [<ffffffff8104b3b0>] warn_slowpath_common+0xa1/0xbb
  [191627.705380]  [<ffffffffa0664499>] ? __btrfs_drop_extents+0x391/0xa50 [btrfs]
  [191627.706637]  [<ffffffff8104b46d>] warn_slowpath_null+0x1a/0x1c
  [191627.707789]  [<ffffffffa0664499>] __btrfs_drop_extents+0x391/0xa50 [btrfs]
  [191627.709155]  [<ffffffff8115663c>] ? cache_alloc_debugcheck_after.isra.32+0x171/0x1d0
  [191627.712444]  [<ffffffff81155007>] ? kmemleak_alloc_recursive.constprop.40+0x16/0x18
  [191627.714162]  [<ffffffffa06570c9>] insert_reserved_file_extent.constprop.40+0x83/0x24e [btrfs]
  [191627.715887]  [<ffffffffa065422b>] ? start_transaction+0x3bb/0x610 [btrfs]
  [191627.717287]  [<ffffffffa065b604>] btrfs_finish_ordered_io+0x273/0x4e2 [btrfs]
  [191627.728865]  [<ffffffffa065b888>] finish_ordered_fn+0x15/0x17 [btrfs]
  [191627.730045]  [<ffffffffa067d688>] normal_work_helper+0x14c/0x32c [btrfs]
  [191627.731256]  [<ffffffffa067d96a>] btrfs_endio_write_helper+0x12/0x14 [btrfs]
  [191627.732661]  [<ffffffff81061119>] process_one_work+0x24c/0x4ae
  [191627.733822]  [<ffffffff810615b0>] worker_thread+0x206/0x2c2
  [191627.734857]  [<ffffffff810613aa>] ? process_scheduled_works+0x2f/0x2f
  [191627.736052]  [<ffffffff810613aa>] ? process_scheduled_works+0x2f/0x2f
  [191627.737349]  [<ffffffff810669a6>] kthread+0xef/0xf7
  [191627.738267]  [<ffffffff810f3b3a>] ? time_hardirqs_on+0x15/0x28
  [191627.739330]  [<ffffffff810668b7>] ? __kthread_parkme+0xad/0xad
  [191627.741976]  [<ffffffff81465592>] ret_from_fork+0x42/0x70
  [191627.743080]  [<ffffffff810668b7>] ? __kthread_parkme+0xad/0xad
  [191627.744206] ---[ end trace bbfddacb7aaada8d ]---

  $ cat -n fs/btrfs/file.c
  691  int __btrfs_drop_extents(struct btrfs_trans_handle *trans,
  (...)
  758                  btrfs_item_key_to_cpu(leaf, &key, path->slots[0]);
  759                  if (key.objectid > ino ||
  760                      key.type > BTRFS_EXTENT_DATA_KEY || key.offset >= end)
  761                          break;
  762
  763                  fi = btrfs_item_ptr(leaf, path->slots[0],
  764                                      struct btrfs_file_extent_item);
  765                  extent_type = btrfs_file_extent_type(leaf, fi);
  766
  767                  if (extent_type == BTRFS_FILE_EXTENT_REG ||
  768                      extent_type == BTRFS_FILE_EXTENT_PREALLOC) {
  (...)
  774                  } else if (extent_type == BTRFS_FILE_EXTENT_INLINE) {
  (...)
  778                  } else {
  779                          WARN_ON(1);
  780                          extent_end = search_start;
  781                  }
  (...)

This happened because the item we were processing did not match a file
extent item (its key type != BTRFS_EXTENT_DATA_KEY), and even on this
case we cast the item to a struct btrfs_file_extent_item pointer and
then find a type field value that does not match any of the expected
values (BTRFS_FILE_EXTENT_[REG|PREALLOC|INLINE]). This scenario happens
due to a tiny time window where a race can happen as exemplified below.
For example, consider the following scenario where we're using the
NO_HOLES feature and we have the following two neighbour leafs:

               Leaf X (has N items)                    Leaf Y

[ ... (257 INODE_ITEM 0) (257 INODE_REF 256) ]  [ (257 EXTENT_DATA 8192), ... ]
          slot N - 2         slot N - 1              slot 0

Our inode 257 has an implicit hole in the range [0, 8K[ (implicit rather
than explicit because NO_HOLES is enabled). Now if our inode has an
ordered extent for the range [4K, 8K[ that is finishing, the following
can happen:

          CPU 1                                       CPU 2

  btrfs_finish_ordered_io()
    insert_reserved_file_extent()
      __btrfs_drop_extents()
         Searches for the key
          (257 EXTENT_DATA 4096) through
          btrfs_lookup_file_extent()

         Key not found and we get a path where
         path->nodes[0] == leaf X and
         path->slots[0] == N

         Because path->slots[0] is >=
         btrfs_header_nritems(leaf X), we call
         btrfs_next_leaf()

         btrfs_next_leaf() releases the path

                                                  inserts key
                                                  (257 INODE_REF 4096)
                                                  at the end of leaf X,
                                                  leaf X now has N + 1 keys,
                                                  and the new key is at
                                                  slot N

         btrfs_next_leaf() searches for
         key (257 INODE_REF 256), with
         path->keep_locks set to 1,
         because it was the last key it
         saw in leaf X

           finds it in leaf X again and
           notices it's no longer the last
           key of the leaf, so it returns 0
           with path->nodes[0] == leaf X and
           path->slots[0] == N (which is now
           < btrfs_header_nritems(leaf X)),
           pointing to the new key
           (257 INODE_REF 4096)

         __btrfs_drop_extents() casts the
         item at path->nodes[0], slot
         path->slots[0], to a struct
         btrfs_file_extent_item - it does
         not skip keys for the target
         inode with a type less than
         BTRFS_EXTENT_DATA_KEY
         (BTRFS_INODE_REF_KEY < BTRFS_EXTENT_DATA_KEY)

         sees a bogus value for the type
         field triggering the WARN_ON in
         the trace shown above, and sets
         extent_end = search_start (4096)

         does the if-then-else logic to
         fixup 0 length extent items created
         by a past bug from hole punching:

           if (extent_end == key.offset &&
               extent_end >= search_start)
               goto delete_extent_item;

         that evaluates to true and it ends
         up deleting the key pointed to by
         path->slots[0], (257 INODE_REF 4096),
         from leaf X

The same could happen for example for a xattr that ends up having a key
with an offset value that matches search_start (very unlikely but not
impossible).

So fix this by ensuring that keys smaller than BTRFS_EXTENT_DATA_KEY are
skipped, never casted to struct btrfs_file_extent_item and never deleted
by accident. Also protect against the unexpected case of getting a key
for a lower inode number by skipping that key and issuing a warning.

Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 fs/btrfs/file.c | 16 ++++++++++++----
 1 file changed, 12 insertions(+), 4 deletions(-)

diff --git a/fs/btrfs/file.c b/fs/btrfs/file.c
index 9663f6600973..f0cd2f2fe0af 100644
--- a/fs/btrfs/file.c
+++ b/fs/btrfs/file.c
@@ -746,8 +746,16 @@ next_slot:
 		}
 
 		btrfs_item_key_to_cpu(leaf, &key, path->slots[0]);
-		if (key.objectid > ino ||
-		    key.type > BTRFS_EXTENT_DATA_KEY || key.offset >= end)
+
+		if (key.objectid > ino)
+			break;
+		if (WARN_ON_ONCE(key.objectid < ino) ||
+		    key.type < BTRFS_EXTENT_DATA_KEY) {
+			ASSERT(del_nr == 0);
+			path->slots[0]++;
+			goto next_slot;
+		}
+		if (key.type > BTRFS_EXTENT_DATA_KEY || key.offset >= end)
 			break;
 
 		fi = btrfs_item_ptr(leaf, path->slots[0],
@@ -765,8 +773,8 @@ next_slot:
 			extent_end = key.offset +
 				btrfs_file_extent_inline_len(leaf, fi);
 		} else {
-			WARN_ON(1);
-			extent_end = search_start;
+			/* can't happen */
+			BUG();
 		}
 
 		if (extent_end <= search_start) {
-- 
2.6.4

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 3.12 00/91] 3.12.52-stable review Jiri Slaby <jslaby@suse.cz> - 2016-01-05 18:50 +0100
  [PATCH 3.12 01/91] ipv6: fix tunnel error handling Jiri Slaby <jslaby@suse.cz> - 2016-01-05 18:50 +0100
    [PATCH 3.12 68/91] sctp: use the same clock as if sock source timestamps were on Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 73/91] net: fix IP early demux races Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 62/91] USB: cp210x: Remove CP2110 ID from compatibility list Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 81/91] ahci: add new Intel device IDs Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 75/91] skbuff: Fix offset error in skb_reorder_vlan_header Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 71/91] net: add validation for the socket syscall protocol argument Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 63/91] USB: add quirk for devices with broken LPM Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 57/91] nfs4: start callback_ident at idr 1 Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 58/91] nfs: if we have no valid attrs, then don't declare the attribute cache valid Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 74/91] vlan: Fix untag operations of stacked vlans with REORDER_HEADER off Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 48/91] netfilter: ipt_rpfilter: remove the nh_scope test in rpfilter_lookup_reverse Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 86/91] i2c: i801: add Intel Lewisburg device IDs Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 61/91] USB: serial: Another Infineon flash loader USB ID Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 51/91] ip6mr: call del_timer_sync() in ip6mr_free_table() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 60/91] USB: cdc_acm: Ignore Infineon Flash Loader utility Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 77/91] bluetooth: Validate socket address length in sco_sock_bind(). Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 65/91] usb: Use the USB_SS_MULT() macro to decode burst multiplier for log message Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 69/91] sctp: update the netstamp_needed counter when copying sockets Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 72/91] sh_eth: fix kernel oops in skb_put() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 64/91] USB: whci-hcd: add check for dma mapping error Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 76/91] pptp: verify sockaddr_len in pptp_bind() and pptp_connect() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 91/91] HID: dragonrise: fix HID Descriptor for 0x0006 PID Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 87/91] cdrom: Random writing support for BD-RE media Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 70/91] ipv6: sctp: clone options to avoid use after free Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 59/91] ocfs2: fix umask ignored issue Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 67/91] atl1c: Improve driver not to do order 4 GFP_ATOMIC allocation Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 85/91] i2c: i801: Add support for Intel Broxton Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 82/91] target/stat: print full t10_wwn.model buffer Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 90/91] gpio/omap: raw read and write endian fix Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 36/91] can: sja1000: clear interrupts on start Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 29/91] mac80211: fix driver RSSI event calculations Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 38/91] usblp: do not set TASK_INTERRUPTIBLE before lock Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 47/91] module: Call module notifier on failure after complete_formation() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 27/91] x86/cpu: Call verify_cpu() after having entered long mode too Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 32/91] staging: rtl8712: Add device ID for Sitecom WLA2100 Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 41/91] USB: serial: option: add support for Novatel MiFi USB620L Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 56/91] firewire: ohci: fix JMicron JMB38x IT context discovery Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 46/91] tty: fix stall caused by missing memory barrier in drivers/tty/n_tty.c Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 37/91] arm64: Fix compat register mappings Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 30/91] net: mvneta: Fix CPU_MAP registers initialisation Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 26/91] x86/setup: Fix low identity map for >= 2GB kernel range Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 53/91] Btrfs: fix race leading to BUG_ON when running delalloc for nodatacow Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 55/91] ext4, jbd2: ensure entering into panic after recording an error in superblock Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 66/91] gre6: allow to update all parameters via rtnl Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 43/91] ALSA: usb-audio: add packet size quirk for the Medeli DD305 Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 54/91] ext4: fix potential use after free in __ext4_journal_stop Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 24/91] ARM: common: edma: Fix channel parameter for irq callbacks Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 14/91] net: ipmr: fix static mfc/dev leaks on table destruction Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 39/91] usb: musb: core: fix order of arguments to ulpi write callback Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 45/91] ALSA: usb-audio: work around CH345 input SysEx corruption Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 40/91] USB: ti_usb_3410_5052: Add Honeywell HGI80 ID Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 31/91] mwifiex: fix mwifiex_rdeeprom_read() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 52/91] Btrfs: fix race leading to incorrect item deletion when dropping extents Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 33/91] Bluetooth: hidp: fix device disconnect on idle timeout Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover whole kernel range Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
      Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Paolo Bonzini <pbonzini@redhat.com> - 2016-01-06 11:50 +0100
        Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Matt Fleming <matt@codeblueprint.co.uk> - 2016-01-06 12:10 +0100
          Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Luis Henriques <luis.henriques@canonical.com> - 2016-01-06 12:30 +0100
            Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Matt Fleming <matt@codeblueprint.co.uk> - 2016-01-06 14:40 +0100
              Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Luis Henriques <luis.henriques@canonical.com> - 2016-01-06 15:30 +0100
                Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Matt Fleming <matt@codeblueprint.co.uk> - 2016-01-08 13:00 +0100
                Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Luis Henriques <luis.henriques@canonical.com> - 2016-01-08 14:40 +0100
                Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Jiri Slaby <jslaby@suse.cz> - 2016-01-09 08:10 +0100
                Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Kamal Mostafa <kamal@canonical.com> - 2016-01-14 22:00 +0100
    [PATCH 3.12 34/91] Bluetooth: ath3k: Add new AR3012 0930:021c id Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 44/91] ALSA: usb-audio: prevent CH345 multiport output SysEx corruption Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 35/91] Bluetooth: ath3k: Add support of AR3012 0cf3:817b device Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 28/91] x86/cpu: Fix SMAP check in PVOPS environments Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 49/91] netfilter: ip6t_SYNPROXY: fix NULL pointer dereference Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 42/91] USB: option: add XS Stick W100-2 from 4G Systems Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 10/91] net: qmi_wwan: add XS Stick W100-2 from 4G Systems Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 11/91] tcp: md5: fix lockdep annotation Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 19/91] net/neighbour: fix crash at dumping device-agnostic proxy entries Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 23/91] ARM: 8427/1: dma-mapping: add support for offset parameter in dma_mmap() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 07/91] packet: infer protocol from ethernet header if unset Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 21/91] Bluetooth: ath3k: Add support of 04ca:300d AR3012 device Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 08/91] sctp: translate host order to network order when setting a hmacid Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 22/91] ARM: 8426/1: dma-mapping: add missing range check in dma_mmap() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 05/91] unix: avoid use-after-free in ep_remove_wait_queue Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 02/91] MIPS: KVM: Fix ASID restoration logic Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 20/91] ipv6: sctp: implement sctp_v6_destroy_sock() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 13/91] net, scm: fix PaX detected msg_controllen overflow in scm_detach_fds Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 18/91] ipv6: add complete rcu protection around np->opt Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 12/91] tcp: initialize tp->copied_seq in case of cross SYN connection Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 04/91] MIPS: KVM: Uninit VCPU in vcpu_create error path Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 06/91] packet: do skb_probe_transport_header when we actually have data Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
  Re: [PATCH 3.12 00/91] 3.12.52-stable review Guenter Roeck <linux@roeck-us.net> - 2016-01-05 21:50 +0100
    Re: [PATCH 3.12 00/91] 3.12.52-stable review Jiri Slaby <jslaby@suse.cz> - 2016-01-09 09:50 +0100
  Re: [PATCH 3.12 00/91] 3.12.52-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-01-05 22:20 +0100
  Re: [PATCH 3.12 00/91] 3.12.52-stable review Nikolay Borisov <kernel@kyup.com> - 2016-01-06 08:40 +0100
    Re: [PATCH 3.12 00/91] 3.12.52-stable review Greg KH <gregkh@linuxfoundation.org> - 2016-01-06 09:20 +0100

csiph-web