Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1184435 > unrolled thread

[3.16.y-ckt stable] Linux 3.16.7-ckt15 stable review

Started byLuis Henriques <luis.henriques@canonical.com>
First post2015-07-15 11:20 +0200
Last post2015-07-15 12:20 +0200
Articles 20 on this page of 186 — 1 participant

Back to article view | Back to linux.kernel


Contents

  [3.16.y-ckt stable] Linux 3.16.7-ckt15 stable review Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 060/185] x86/PCI: Use host bridge _CRS info on Foxconn K8M890-8237A Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 111/185] mm: kmemleak: allow safe memory scanning during kmemleak disabling Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 031/185] scsi_transport_srp: Fix a race condition Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 173/185] perf: Fix ring_buffer_attach() RCU sync, again Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 008/185] packet: read num_members once in packet_rcv_fanout() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 067/185] pinctrl: mvebu: armada-375: remove incorrect space in pin description Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 138/185] vfs: Remove incorrect debugging WARN in prepend_path Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 178/185] __bitmap_parselist: fix bug in empty string handling Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 104/185] fs: Fix S_NOSEC handling Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 180/185] kvm: x86: fix kvm_apic_has_events to check for NULL pointer Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 056/185] b43: fix support for 14e4:4321 PCI dev with BCM4321 chipset Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 184/185] LZ4 : fix the data abort issue Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 145/185] KVM: s390: virtio-ccw: don't overwrite config space values Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 113/185] ALSA: hda - Fix Dock Headphone on Thinkpad X250 seen as a Line Out Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 091/185] ACPI / PNP: Avoid conflicting resource reservations Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 082/185] ima: fix ima_show_template_data_ascii() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 177/185] security_syslog() should be called once only Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 170/185] ACPI / init: Switch over platform to the ACPI mode later Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 020/185] mtd: fix: avoid race condition when accessing mtd->usecount Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 179/185] x86/iosf: Add Kconfig prompt for IOSF_MBI selection Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 120/185] drm/i915: fix backlight after resume on 855gm Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 027/185] ASoC: wm8903: Fix define for WM8903_VMID_RES_250K Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 183/185] ACPI / PNP: Reserve ACPI resources at the fs_initcall_sync stage Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 168/185] sched/fair: Prevent throttling in early pick_next_task_fair() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 185/185] lz4: fix system halt at boot kernel on x86_64 Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:20 +0200
    [PATCH 3.16.y-ckt 150/185] clk: ti: dra7-atl-clock: Fix possible ERR_PTR dereference Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 149/185] powerpc/pseries: Fix possible leaked device node reference Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 162/185] mac80211: prevent possible crypto tx tailroom corruption Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 146/185] 9p: forgetting to cancel request on interrupted zero-copy RPC Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 159/185] ath9k_htc: memory corruption calling set_bit() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 164/185] phy: twl4030-usb: remove incorrect pm_runtime_get_sync() in probe function. Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 156/185] tty: remove platform_sysrq_reset_seq Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 171/185] drm/tegra: dpaux: Fix transfers larger than 4 bytes Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 152/185] HID: rmi: fix some harmless BIT() mistakes Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 163/185] cfg80211: ignore netif running state when changing iftype Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 176/185] mm/hugetlb: introduce minimum hugepage order Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 160/185] rndis_wlan: harmless issue calling set_bit() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 174/185] watchdog: omap: assert the counter being stopped before reprogramming Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 158/185] IB/mlx4: Convert slave port before building address-handle Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 166/185] Btrfs: lock superblock before remounting for rw subvol Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 169/185] ASoC: imx-wm8962: Add a missing error check Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 175/185] bridge: multicast: restore router configuration on port link down/up Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 154/185] pktgen: adjust spacing in proc file interface output Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 167/185] of: return NUMA_NO_NODE from fallback of_node_to_nid() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 155/185] USB: devio: fix a condition in async_completed() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 161/185] mtd: dc21285: use raw spinlock functions for nw_gpio_lock Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 165/185] NFS: Fix size of NFSACL SETACL operations Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 182/185] fs/ufs: restore s_lock mutex_init() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 181/185] sparc: Use GFP_ATOMIC in ldc_alloc_exp_dring() as it can be called in softirq context Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 172/185] mmc: card: Fixup request missing in mmc_blk_issue_rw_rq Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 157/185] net/mlx4_core: Enhance the MAD_IFC wrapper to convert VF port to physical Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:30 +0200
    [PATCH 3.16.y-ckt 133/185] sysctl: Allow creating permanently empty directories that serve as mountpoints. Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 140/185] ACPICA: Tables: Enable both 32-bit and 64-bit FACS Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 129/185] fuse: initialize fc->release before calling it Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 151/185] ipip: fix one sparse error Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 144/185] KVM: x86: properly restore LVT0 Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 148/185] e1000e: Cleanup handling of VLAN_HLEN as a part of max frame size Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 128/185] arm64: Don't report clear pmds and puds as huge Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 141/185] ACPICA: Tables: Fix an issue that FACS initialization is performed twice Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 142/185] ACPICA: Tables: Enable default 64-bit FADT addresses favor Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 124/185] ARM: mvebu: update Ethernet compatible string for Armada XP Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 134/185] proc: Allow creating permanently empty directories that serve as mount points Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 127/185] rbd: use GFP_NOIO in rbd_obj_request_create() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 137/185] mnt: Update fs_fully_visible to test for permanently empty directories Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 153/185] HID: i2c-hid: fix harmless test_bit() issue Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 130/185] vfs: Ignore unlocked mounts in fs_fully_visible Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 126/185] crush: fix a bug in tree bucket decode Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 132/185] fs: Add helper functions for permanently empty directories. Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 143/185] KVM: x86: make vapics_in_nmi_mode atomic Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 135/185] kernfs: Add support for always empty directories. Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 122/185] drm/radeon: SDMA fix hibernation (CI GPU family). Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 139/185] hwmon: (mcp3021) Fix broken output scaling Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 147/185] clk: Fix JSON output in debugfs Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 125/185] net: mvneta: disable IP checksum with jumbo frames for Armada 370 Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 136/185] sysfs: Add support for permanently empty directories to serve as mount points. Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 131/185] VFS: Introduce inode-getting helpers for layered/unioned fs environments Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:40 +0200
    [PATCH 3.16.y-ckt 095/185] arm64: vdso: work-around broken ELF toolchains in Makefile Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 117/185] ALSA: hda - Add headset support to Acer Aspire V5 Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 121/185] drm/radeon: compute ring fix hibernation (CI GPU family) v2. Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 115/185] tracing/filter: Do not allow infix to exceed end of string Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 108/185] ARC: add compiler barrier to LLSC based cmpxchg Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 092/185] Bluetooth: ath3k: add support of 04ca:300f AR3012 device Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 107/185] PM / sleep: Increase default DPM watchdog timeout to 60 Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 098/185] MIPS: Fix KVM guest fixmap address Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 096/185] iommu/amd: Handle large pages correctly in free_pagetable Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 080/185] fs/ufs: restore s_lock mutex Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 105/185] stmmac: troubleshoot unexpected bits in des0 & des1 Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 114/185] tracing/filter: Do not WARN on operand count going below zero Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 123/185] net: mvneta: introduce compatible string "marvell, armada-xp-neta" Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 112/185] dell-laptop: Fix allocating & freeing SMI buffer page Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 094/185] libata: Do not blacklist Micron M500DC Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 099/185] xfs: fix remote symlinks on V5/CRC filesystems Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 103/185] netfilter: nf_qeueue: Drop queue entries on nf_unregister_hook Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 116/185] clocksource: exynos_mct: Avoid blocking calls in the cpu hotplug notifier Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 100/185] ext4: don't retry file block mapping on bigalloc fs with non-extent file Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 109/185] locking,arch,arc: Fold atomic_ops Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 110/185] ARC: add smp barriers around atomics per Documentation/atomic_ops.txt Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 097/185] ext4: call sync_blockdev() before invalidate_bdev() in put_super() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 102/185] NET: ROSE: Don't dereference NULL neighbour pointer. Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 101/185] xfs: don't truncate attribute extents if no extents exist Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 106/185] ACPI / resources: free memory on error in add_region_before() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 118/185] ALSA: hda - Fix the dock headphone output on Fujitsu Lifebook E780 Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 119/185] agp/intel: Fix typo in needs_ilk_vtd_wa() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 11:50 +0200
    [PATCH 3.16.y-ckt 078/185] jbd2: fix ocfs2 corrupt when updating journal superblock fails Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 065/185] pinctrl: mvebu: armada-xp: remove non-existing VDD cpu_pd functions Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 069/185] i2c: at91: fix a race condition when using the DMA controller Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 062/185] pinctrl: mvebu: armada-370: fix spi0 pin description Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 072/185] arm64: Do not attempt to use init_mm in reset_context() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 076/185] jbd2: use GFP_NOFS in jbd2_cleanup_journal_tail() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 081/185] regmap: Fix possible shift overflow in regmap_field_init() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 089/185] x86/PCI: Use host bridge _CRS info on systems with >32 bit addressing Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 088/185] dm stats: fix divide by zero if 'number_of_areas' arg is zero Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 066/185] pinctrl: mvebu: armada-xp: fix functions of MPP48 Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 063/185] pinctrl: mvebu: armada-375: remove non-existing NAND re/we pins Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 087/185] dm space map metadata: fix occasional leak of a metadata block on resize Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 074/185] Disable write buffering on Toshiba ToPIC95 Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 073/185] ext4: fix race between truncate and __ext4_journalled_writepage() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 075/185] fs/ufs: revert "ufs: fix deadlocks introduced by sb mutex merge" Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 070/185] dmaengine: mv_xor: bug fix for racing condition in descriptors cleanup Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 085/185] arm: KVM: force execution of HCPTR access on VM exit Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 079/185] ideapad: fix software rfkill setting Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 071/185] ASoC: wm8960: the enum of "DAC Polarity" should be wm8960_enum[1] Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 064/185] pinctrl: mvebu: armada-xp: remove non-existing NAND pins Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 061/185] pinctrl: mvebu: armada-38x: fix PCIe functions Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 068/185] pinctrl: mvebu: armada-38x: fix incorrect total number of GPIOs Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 077/185] regmap: Fix regmap_bulk_read in BE mode Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 086/185] arm64: mm: Fix freeing of the wrong memmap entries with !SPARSEMEM_VMEMMAP Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 090/185] pNFS: Fix a memory leak when attempted pnfs fails Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 093/185] Bluetooth: ath3k: Add support of 04ca:300d AR3012 device Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 084/185] vTPM: set virtual device before passing to ibmvtpm_reset_crq Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 083/185] nfs: increase size of EXCHANGE_ID name string buffer Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:00 +0200
    [PATCH 3.16.y-ckt 058/185] regulator: core: fix constraints output buffer Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 048/185] mnt: Modify fs_fully_visible to deal with locked ro nodev and atime Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 042/185] fixing infinite OPEN loop in 4.0 stateid recovery Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 040/185] usb: core: Fix USB 3.0 devices lost in NOTATTACHED state after a hub port reset Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 044/185] powerpc/perf: Fix book3s kernel to userspace backtraces Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 043/185] ideapad_laptop: Lenovo G50-30 fix rfkill reports wireless blocked Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 041/185] staging: vt6655: device_rx_srv check sk_buff is NULL Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 057/185] cdc-acm: Add support of ATOL FPrint fiscal printers Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 054/185] Bluetooth: btusb: Fix memory leak in Intel setup routine Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 051/185] selinux: fix setting of security labels on NFS Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 047/185] ieee802154: Fix sockaddr_ieee802154 implicit padding information leak. Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 037/185] ASoC: arizona: Fix noise generator gain TLV Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 049/185] drm/qxl: Do not cause spice-server to clean our objects Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 038/185] usb: dwc3: gadget: don't clear EP_BUSY too early Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 033/185] w1_therm reference count family data Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 055/185] ath9k: fix DMA stop sequence for AR9003+ Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 059/185] ACPI / PM: Add missing pm_generic_complete() invocation Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 039/185] staging: rtl8712: prevent buffer overrun in recvbuf2recvframe Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 050/185] drm/qxl: Do not leak memory if qxl_release_list_add fails Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 035/185] usb: dwc3: gadget: return error if command sent to DGCMD register fails Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 045/185] SUNRPC: Fix a memory leak in the backchannel code Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 046/185] ipr: Increase default adapter init stage change timeout Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 036/185] rcu: Correctly handle non-empty Tiny RCU callback list with none ready Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 053/185] ath3k: add support of 13d3:3474 AR3012 device Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 014/185] x86/mce: Fix MCE severity messages Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 052/185] ath3k: Add support of 0489:e076 AR3012 device Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 030/185] scsi_transport_srp: Introduce srp_wait_for_queuecommand() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:10 +0200
    [PATCH 3.16.y-ckt 025/185] genirq: devres: Fix testing return value of request_any_context_irq() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 002/185] KVM: nSVM: Check for NRIPS support before updating control field Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 021/185] intel_pstate: set BYT MSR with wrmsrl_on_cpu() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 009/185] packet: avoid out of bounds read in round robin fanout Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 003/185] nfs: take extra reference to fl->fl_file when running a setlk Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 015/185] [media] s5h1420: fix a buffer overflow when checking userspace params Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 005/185] net: don't wait for order-3 page allocation Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 010/185] neigh: do not modify unlinked entries Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 028/185] mnt: Refactor the logic for mounting sysfs and proc in a user namespace Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 016/185] [media] cx24116: fix a buffer overflow when checking userspace params Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 024/185] Revert "crypto: talitos - convert to use be16_add_cpu()" Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 034/185] drm/radeon: take the mode_config mutex when dealing with hpds (v2) Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 017/185] [media] af9013: Don't accept invalid bandwidth Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 022/185] leds / PM: fix hibernation on arm when gpio-led used with CPU led trigger Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 006/185] sctp: fix ASCONF list handling Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 019/185] spi: fix race freeing dummy_tx/rx before it is unmapped Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 013/185] sctp: Fix race between OOTB responce and route removal Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 001/185] ARM: clk-imx6q: refine sata's parent Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 018/185] [media] cx24117: fix a buffer overflow when checking userspace params Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 029/185] ASoC: wm8955: Fix setting wrong register for WM8955_K_8_0_MASK bits Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 026/185] ASoC: wm8737: Fixup setting VMID Impedance control register Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 004/185] bridge: fix multicast router rlist endless loop Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 032/185] KVM: mips: use id_to_memslot correctly Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 023/185] crypto: talitos - avoid memleak in talitos_alg_alloc() Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 007/185] bridge: fix br_stp_set_bridge_priority race conditions Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 011/185] tcp: Do not call tcp_fastopen_reset_cipher from interrupt context Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200
    [PATCH 3.16.y-ckt 012/185] net: phy: fix phy link up when limiting speed via device tree Luis Henriques <luis.henriques@canonical.com> - 2015-07-15 12:20 +0200

Page 1 of 10  [1] 2 3 … 10  Next page →


#1184435 — [3.16.y-ckt stable] Linux 3.16.7-ckt15 stable review

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[3.16.y-ckt stable] Linux 3.16.7-ckt15 stable review
Message-ID<pMr17-36Z-9@gated-at.bofh.it>
This is the start of the review cycle for the Linux 3.16.7-ckt15 stable kernel.

This version contains 185 new patches, summarized below.  The new patches are
posted as replies to this message and also available in this git branch:

http://kernel.ubuntu.com/git/ubuntu/linux.git/log/?h=linux-3.16.y-review

git://kernel.ubuntu.com/ubuntu/linux.git  linux-3.16.y-review

The review period for version 3.16.7-ckt15 will be open for the next three days.
To report a problem, please reply to the relevant follow-up patch message.

For more information about the Linux 3.16.y-ckt extended stable kernel version,
see https://wiki.ubuntu.com/Kernel/Dev/ExtendedStable .

 -Luis

--
 .../bindings/net/marvell-armada-370-neta.txt       |   2 +-
 .../pinctrl/marvell,armada-370-pinctrl.txt         |   4 +-
 .../pinctrl/marvell,armada-375-pinctrl.txt         |   4 +-
 .../pinctrl/marvell,armada-38x-pinctrl.txt         |  38 ++--
 .../bindings/pinctrl/marvell,armada-xp-pinctrl.txt |  32 ++--
 arch/arc/include/asm/atomic.h                      | 205 +++++++++------------
 arch/arc/include/asm/bitops.h                      |  19 ++
 arch/arc/include/asm/cmpxchg.h                     |  26 ++-
 arch/arc/include/asm/spinlock.h                    |  32 ++++
 arch/arm/boot/dts/armada-370-xp.dtsi               |   2 -
 arch/arm/boot/dts/armada-370.dtsi                  |   8 +
 arch/arm/boot/dts/armada-xp-mv78260.dtsi           |   2 +-
 arch/arm/boot/dts/armada-xp-mv78460.dtsi           |   2 +-
 arch/arm/boot/dts/armada-xp.dtsi                   |  10 +-
 arch/arm/kvm/interrupts.S                          |  10 +-
 arch/arm/kvm/interrupts_head.S                     |  20 +-
 arch/arm/mach-imx/clk-imx6q.c                      |   2 +-
 arch/arm64/kernel/vdso/Makefile                    |   4 +
 arch/arm64/mm/context.c                            |   8 +
 arch/arm64/mm/hugetlbpage.c                        |   4 +-
 arch/arm64/mm/init.c                               |   2 +-
 arch/mips/include/asm/mach-generic/spaces.h        |   4 +
 arch/mips/kvm/kvm_mips.c                           |   2 +-
 arch/powerpc/perf/core-book3s.c                    |  11 +-
 arch/powerpc/platforms/pseries/dlpar.c             |   3 +-
 arch/sparc/kernel/ldc.c                            |   2 +-
 arch/x86/Kconfig                                   |  14 +-
 arch/x86/include/asm/kvm_host.h                    |   2 +-
 arch/x86/kernel/cpu/mcheck/mce.c                   |   6 +-
 arch/x86/kvm/i8254.c                               |   2 +-
 arch/x86/kvm/lapic.c                               |   5 +-
 arch/x86/kvm/lapic.h                               |   2 +-
 arch/x86/kvm/svm.c                                 |   8 +-
 arch/x86/pci/acpi.c                                |  17 +-
 drivers/acpi/acpica/aclocal.h                      |   1 +
 drivers/acpi/acpica/tbfadt.c                       |  21 ++-
 drivers/acpi/acpica/tbutils.c                      |  34 ++--
 drivers/acpi/acpica/tbxfload.c                     |   3 +-
 drivers/acpi/acpica/utxfinit.c                     |  10 +-
 drivers/acpi/bus.c                                 |  56 ++++--
 drivers/acpi/device_pm.c                           |   1 +
 drivers/acpi/osl.c                                 |   6 +-
 drivers/ata/libata-core.c                          |   2 +-
 drivers/base/regmap/regmap.c                       |   5 +-
 drivers/block/rbd.c                                |   4 +-
 drivers/bluetooth/ath3k.c                          |   8 +
 drivers/bluetooth/btusb.c                          |   6 +
 drivers/char/agp/intel-gtt.c                       |   2 +-
 drivers/char/tpm/tpm_ibmvtpm.c                     |   5 +-
 drivers/clk/clk.c                                  |   5 +-
 drivers/clk/ti/clk-dra7-atl.c                      |   5 +
 drivers/clocksource/exynos_mct.c                   |  43 +++--
 drivers/cpufreq/intel_pstate.c                     |   2 +-
 drivers/crypto/talitos.c                           |   4 +-
 drivers/dma/mv_xor.c                               |  72 +++++---
 drivers/dma/mv_xor.h                               |   1 +
 drivers/gpu/drm/i915/i915_reg.h                    |   1 +
 drivers/gpu/drm/i915/intel_panel.c                 |   8 +
 drivers/gpu/drm/qxl/qxl_cmd.c                      |   1 +
 drivers/gpu/drm/qxl/qxl_ioctl.c                    |   4 +-
 drivers/gpu/drm/radeon/cik.c                       |  34 ++++
 drivers/gpu/drm/radeon/cik_sdma.c                  |  11 ++
 drivers/gpu/drm/radeon/radeon_irq_kms.c            |   2 +
 drivers/gpu/drm/tegra/dpaux.c                      |  18 +-
 drivers/hid/hid-rmi.c                              |   6 +-
 drivers/hid/i2c-hid/i2c-hid.c                      |   6 +-
 drivers/hwmon/mcp3021.c                            |  14 +-
 drivers/i2c/busses/i2c-at91.c                      |  70 +++++--
 drivers/infiniband/hw/mlx4/mad.c                   |  11 +-
 drivers/iommu/amd_iommu.c                          |   6 +
 drivers/leds/led-class.c                           |   7 +-
 drivers/md/dm-stats.c                              |   2 +
 drivers/md/persistent-data/dm-space-map-metadata.c |  50 +++--
 drivers/media/dvb-frontends/af9013.c               |   4 +
 drivers/media/dvb-frontends/cx24116.c              |   8 +-
 drivers/media/dvb-frontends/cx24117.c              |   2 +-
 drivers/media/dvb-frontends/s5h1420.c              |   2 +-
 drivers/mmc/card/block.c                           |   8 +-
 drivers/mtd/maps/dc21285.c                         |   4 +-
 drivers/mtd/mtd_blkdevs.c                          |   5 +
 drivers/net/ethernet/intel/e1000e/82571.c          |   2 +-
 drivers/net/ethernet/intel/e1000e/ich8lan.c        |   8 +-
 drivers/net/ethernet/intel/e1000e/netdev.c         |  18 +-
 drivers/net/ethernet/marvell/mvneta.c              |  27 ++-
 drivers/net/ethernet/mellanox/mlx4/cmd.c           |  10 +-
 drivers/net/ethernet/stmicro/stmmac/descs.h        |   2 +
 drivers/net/ethernet/stmicro/stmmac/enh_desc.c     |   3 +-
 drivers/net/ethernet/stmicro/stmmac/norm_desc.c    |   3 +-
 drivers/net/ethernet/stmicro/stmmac/stmmac_main.c  |  44 ++---
 drivers/net/phy/phy_device.c                       |   5 +-
 drivers/net/wireless/ath/ath9k/htc.h               |   6 +-
 drivers/net/wireless/ath/ath9k/main.c              |  12 +-
 drivers/net/wireless/b43/main.c                    |   4 +
 drivers/net/wireless/rndis_wlan.c                  |   6 +-
 drivers/of/base.c                                  |   2 +-
 drivers/pcmcia/topic.h                             |  16 ++
 drivers/phy/phy-twl4030-usb.c                      |   1 -
 drivers/pinctrl/mvebu/pinctrl-armada-370.c         |   4 +-
 drivers/pinctrl/mvebu/pinctrl-armada-375.c         |   4 +-
 drivers/pinctrl/mvebu/pinctrl-armada-38x.c         |  51 +++--
 drivers/pinctrl/mvebu/pinctrl-armada-xp.c          |  37 ++--
 drivers/platform/x86/dell-laptop.c                 |   8 +-
 drivers/platform/x86/ideapad-laptop.c              |  10 +-
 drivers/regulator/core.c                           |   2 +-
 drivers/s390/kvm/virtio_ccw.c                      |  11 +-
 drivers/scsi/ipr.h                                 |   2 +-
 drivers/scsi/scsi_transport_srp.c                  |  58 +++---
 drivers/spi/spi.c                                  |  11 +-
 drivers/staging/rtl8712/rtl8712_recv.c             |   3 +-
 drivers/staging/vt6655/device_main.c               |   4 +
 drivers/tty/sysrq.c                                |  19 +-
 drivers/usb/class/cdc-acm.c                        |   9 +
 drivers/usb/class/cdc-acm.h                        |   1 +
 drivers/usb/core/devio.c                           |   2 +-
 drivers/usb/core/hub.c                             |  81 ++++----
 drivers/usb/dwc3/gadget.c                          |   8 +-
 drivers/w1/slaves/w1_therm.c                       |  62 +++++--
 drivers/watchdog/omap_wdt.c                        |   7 +
 fs/btrfs/super.c                                   |   2 +
 fs/dcache.c                                        |  11 --
 fs/ext4/indirect.c                                 |   2 +-
 fs/ext4/inode.c                                    |  23 ++-
 fs/ext4/super.c                                    |   1 +
 fs/fuse/inode.c                                    |   2 +-
 fs/inode.c                                         |   4 +-
 fs/jbd2/checkpoint.c                               |   7 +-
 fs/jbd2/journal.c                                  |  38 +++-
 fs/kernfs/dir.c                                    |  38 +++-
 fs/kernfs/inode.c                                  |   2 +
 fs/libfs.c                                         |  96 ++++++++++
 fs/namespace.c                                     |  39 +++-
 fs/nfs/nfs3xdr.c                                   |   2 +-
 fs/nfs/nfs4proc.c                                  |   3 +
 fs/nfs/nfs4state.c                                 |   2 +
 fs/nfs/pnfs.c                                      |   2 +
 fs/proc/generic.c                                  |  24 +++
 fs/proc/inode.c                                    |   4 +
 fs/proc/internal.h                                 |   6 +
 fs/proc/proc_sysctl.c                              |  37 ++++
 fs/proc/root.c                                     |   9 +-
 fs/sysfs/dir.c                                     |  34 ++++
 fs/sysfs/mount.c                                   |   5 +-
 fs/ufs/balloc.c                                    |  34 ++--
 fs/ufs/ialloc.c                                    |  16 +-
 fs/ufs/inode.c                                     |   5 +-
 fs/ufs/namei.c                                     |  14 +-
 fs/ufs/super.c                                     |  11 ++
 fs/ufs/ufs.h                                       |   1 +
 fs/xfs/xfs_attr_inactive.c                         |  10 +-
 fs/xfs/xfs_symlink.c                               |   2 +-
 include/acpi/acpixf.h                              |  13 +-
 include/acpi/actypes.h                             |   1 +
 include/linux/acpi.h                               |   2 +
 include/linux/dcache.h                             |  57 ++++++
 include/linux/fs.h                                 |   4 +-
 include/linux/jbd2.h                               |   4 +-
 include/linux/kernfs.h                             |   3 +
 include/linux/nfs_xdr.h                            |   2 +-
 include/linux/of.h                                 |   5 +-
 include/linux/sysctl.h                             |   3 +
 include/linux/sysfs.h                              |  15 ++
 include/net/netfilter/nf_queue.h                   |   2 +
 include/net/netns/sctp.h                           |   1 +
 include/net/sctp/structs.h                         |   4 +
 init/main.c                                        |   1 +
 kernel/events/core.c                               |  14 +-
 kernel/irq/devres.c                                |   4 +-
 kernel/power/Kconfig                               |   2 +-
 kernel/printk/printk.c                             |  11 +-
 kernel/rcu/tiny.c                                  |   5 +
 kernel/sched/fair.c                                |  25 +--
 kernel/sysctl.c                                    |   8 +-
 kernel/trace/trace_events_filter.c                 |  10 +-
 lib/bitmap.c                                       |  17 +-
 lib/lz4/lz4_decompress.c                           |  15 +-
 mm/hugetlb.c                                       |  19 +-
 mm/kmemleak.c                                      |  19 +-
 net/9p/client.c                                    |   3 +-
 net/bridge/br_ioctl.c                              |   2 -
 net/bridge/br_multicast.c                          |  11 +-
 net/bridge/br_stp_if.c                             |   4 +-
 net/ceph/osdmap.c                                  |   2 +-
 net/core/neighbour.c                               |  13 ++
 net/core/pktgen.c                                  |   2 +-
 net/core/skbuff.c                                  |   4 +-
 net/core/sock.c                                    |   4 +-
 net/ieee802154/dgram.c                             |   6 +
 net/ipv4/af_inet.c                                 |   2 +
 net/ipv4/ipip.c                                    |   3 +-
 net/ipv4/tcp.c                                     |   7 +-
 net/ipv4/tcp_fastopen.c                            |   2 -
 net/mac80211/main.c                                |   3 +
 net/netfilter/core.c                               |   1 +
 net/netfilter/nf_internals.h                       |   1 +
 net/netfilter/nf_queue.c                           |  17 ++
 net/netfilter/nfnetlink_queue_core.c               |  24 ++-
 net/packet/af_packet.c                             |  20 +-
 net/rose/af_rose.c                                 |   3 +-
 net/sctp/output.c                                  |   4 +-
 net/sctp/socket.c                                  |  43 +++--
 net/sunrpc/backchannel_rqst.c                      |   2 +-
 net/wireless/util.c                                |   2 +-
 security/integrity/ima/ima.h                       |   2 +-
 security/integrity/ima/ima_fs.c                    |   4 +-
 security/integrity/ima/ima_template_lib.c          |   3 +-
 security/selinux/hooks.c                           |   3 +-
 sound/pci/hda/patch_realtek.c                      |  25 +++
 sound/soc/codecs/wm5102.c                          |   2 +-
 sound/soc/codecs/wm5110.c                          |   2 +-
 sound/soc/codecs/wm8737.c                          |   6 +-
 sound/soc/codecs/wm8903.h                          |   2 +-
 sound/soc/codecs/wm8955.c                          |   2 +-
 sound/soc/codecs/wm8960.c                          |   2 +-
 sound/soc/codecs/wm8997.c                          |   2 +-
 sound/soc/fsl/imx-wm8962.c                         |   2 +-
 215 files changed, 1821 insertions(+), 830 deletions(-)

Al Viro (1):
      9p: forgetting to cancel request on interrupted zero-copy RPC

Alex Deucher (1):
      drm/radeon: take the mode_config mutex when dealing with hpds (v2)

Alexander Duyck (1):
      e1000e: Cleanup handling of VLAN_HLEN as a part of max frame size

Alexander Sverdlin (1):
      sctp: Fix race between OOTB responce and route removal

Alexey Brodkin (1):
      stmmac: troubleshoot unexpected bits in des0 & des1

Alexey Sokolov (1):
      cdc-acm: Add support of ATOL FPrint fiscal printers

Anton Blanchard (1):
      powerpc/perf: Fix book3s kernel to userspace backtraces

Arnd Bergmann (2):
      ideapad: fix software rfkill setting
      tty: remove platform_sysrq_reset_seq

Arun Chandran (1):
      regmap: Fix regmap_bulk_read in BE mode

Axel Lin (4):
      genirq: devres: Fix testing return value of request_any_context_irq()
      ASoC: wm8737: Fixup setting VMID Impedance control register
      ASoC: wm8903: Fix define for WM8903_VMID_RES_250K
      ASoC: wm8955: Fix setting wrong register for WM8955_K_8_0_MASK bits

Bandan Das (1):
      KVM: nSVM: Check for NRIPS support before updating control field

Bart Van Assche (2):
      scsi_transport_srp: Introduce srp_wait_for_queuecommand()
      scsi_transport_srp: Fix a race condition

Ben Segall (1):
      sched/fair: Prevent throttling in early pick_next_task_fair()

Bjorn Helgaas (2):
      x86/PCI: Use host bridge _CRS info on Foxconn K8M890-8237A
      x86/PCI: Use host bridge _CRS info on systems with >32 bit addressing

Borislav Petkov (1):
      x86/mce: Fix MCE severity messages

Brian Foster (1):
      xfs: don't truncate attribute extents if no extents exist

Brian King (1):
      ipr: Increase default adapter init stage change timeout

Brian Norris (1):
      mtd: fix: avoid race condition when accessing mtd->usecount

Catalin Marinas (2):
      arm64: Do not attempt to use init_mm in reset_context()
      mm: kmemleak: allow safe memory scanning during kmemleak disabling

Chris Metcalf (1):
      __bitmap_parselist: fix bug in empty string handling

Chris Wilson (1):
      agp/intel: Fix typo in needs_ilk_vtd_wa()

Christoffer Dall (1):
      arm64: Don't report clear pmds and puds as huge

Christoph Paasch (1):
      tcp: Do not call tcp_fastopen_reset_cipher from interrupt context

Chuck Lever (1):
      NFS: Fix size of NFSACL SETACL operations

Cornelia Huck (1):
      KVM: s390: virtio-ccw: don't overwrite config space values

Cyrille Pitchen (1):
      i2c: at91: fix a race condition when using the DMA controller

Damian Eppel (1):
      clocksource: exynos_mct: Avoid blocking calls in the cpu hotplug notifier

Dan Carpenter (7):
      ACPI / resources: free memory on error in add_region_before()
      HID: rmi: fix some harmless BIT() mistakes
      HID: i2c-hid: fix harmless test_bit() issue
      USB: devio: fix a condition in async_completed()
      ath9k_htc: memory corruption calling set_bit()
      rndis_wlan: harmless issue calling set_bit()
      ASoC: imx-wm8962: Add a missing error check

Darrick J. Wong (1):
      ext4: don't retry file block mapping on bigalloc fs with non-extent file

Dave P Martin (1):
      arm64: mm: Fix freeing of the wrong memmap entries with !SPARSEMEM_VMEMMAP

David E. Box (1):
      x86/iosf: Add Kconfig prompt for IOSF_MBI selection

David Fries (1):
      w1_therm reference count family data

David Henningsson (1):
      ALSA: hda - Fix Dock Headphone on Thinkpad X250 seen as a Line Out

David Howells (1):
      VFS: Introduce inode-getting helpers for layered/unioned fs environments

Ding Wang (1):
      mmc: card: Fixup request missing in mmc_blk_issue_rw_rq

Dmitry Monakhov (1):
      jbd2: use GFP_NOFS in jbd2_cleanup_journal_tail()

Dmitry Tunin (5):
      ideapad_laptop: Lenovo G50-30 fix rfkill reports wireless blocked
      ath3k: Add support of 0489:e076 AR3012 device
      ath3k: add support of 13d3:3474 AR3012 device
      Bluetooth: ath3k: add support of 04ca:300f AR3012 device
      Bluetooth: ath3k: Add support of 04ca:300d AR3012 device

Eric Dumazet (2):
      packet: read num_members once in packet_rcv_fanout()
      ipip: fix one sparse error

Eric Sandeen (1):
      xfs: fix remote symlinks on V5/CRC filesystems

Eric W. Biederman (11):
      mnt: Refactor the logic for mounting sysfs and proc in a user namespace
      mnt: Modify fs_fully_visible to deal with locked ro nodev and atime
      netfilter: nf_qeueue: Drop queue entries on nf_unregister_hook
      vfs: Ignore unlocked mounts in fs_fully_visible
      fs: Add helper functions for permanently empty directories.
      sysctl: Allow creating permanently empty directories that serve as mountpoints.
      proc: Allow creating permanently empty directories that serve as mount points
      kernfs: Add support for always empty directories.
      sysfs: Add support for permanently empty directories to serve as mount points.
      mnt: Update fs_fully_visible to test for permanently empty directories
      vfs: Remove incorrect debugging WARN in prepend_path

Fabian Frederick (3):
      fs/ufs: revert "ufs: fix deadlocks introduced by sb mutex merge"
      fs/ufs: restore s_lock mutex
      fs/ufs: restore s_lock mutex_init()

Felipe Balbi (1):
      usb: dwc3: gadget: don't clear EP_BUSY too early

Felix Fietkau (1):
      ath9k: fix DMA stop sequence for AR9003+

Frediano Ziglio (2):
      drm/qxl: Do not cause spice-server to clean our objects
      drm/qxl: Do not leak memory if qxl_release_list_add fails

Grygorii Strashko (1):
      leds / PM: fix hibernation on arm when gpio-led used with CPU led trigger

Haggai Eran (1):
      staging: rtl8712: prevent buffer overrun in recvbuf2recvframe

Hon Ching \\(Vicky\\) Lo (1):
      vTPM: set virtual device before passing to ibmvtpm_reset_crq

Horia Geant? (2):
      crypto: talitos - avoid memleak in talitos_alg_alloc()
      Revert "crypto: talitos - convert to use be16_add_cpu()"

Ilya Dryomov (2):
      crush: fix a bug in tree bucket decode
      rbd: use GFP_NOIO in rbd_obj_request_create()

J. Bruce Fields (1):
      selinux: fix setting of security labels on NFS

James Hogan (1):
      MIPS: Fix KVM guest fixmap address

Jan Kara (1):
      fs: Fix S_NOSEC handling

Jani Nikula (1):
      drm/i915: fix backlight after resume on 855gm

JeHyeon Yeon (1):
      LZ4 : fix the data abort issue

Jeff Layton (2):
      nfs: take extra reference to fl->fl_file when running a setlk
      nfs: increase size of EXCHANGE_ID name string buffer

Jesper Dangaard Brouer (1):
      pktgen: adjust spacing in proc file interface output

Joe Konno (1):
      intel_pstate: set BYT MSR with wrmsrl_on_cpu()

Joe Thornber (1):
      dm space map metadata: fix occasional leak of a metadata block on resize

Joerg Roedel (1):
      iommu/amd: Handle large pages correctly in free_pagetable

Joseph Qi (1):
      jbd2: fix ocfs2 corrupt when updating journal superblock fails

Julian Anastasov (1):
      neigh: do not modify unlinked entries

Jérôme Glisse (2):
      drm/radeon: compute ring fix hibernation (CI GPU family) v2.
      drm/radeon: SDMA fix hibernation (CI GPU family).

Konstantin Khlebnikov (1):
      of: return NUMA_NO_NODE from fallback of_node_to_nid()

Krzysztof Kolasa (1):
      lz4: fix system halt at boot kernel on x86_64

Krzysztof Kozlowski (1):
      clk: ti: dra7-atl-clock: Fix possible ERR_PTR dereference

Lennert Buytenhek (1):
      ieee802154: Fix sockaddr_ieee802154 implicit padding information leak.

Lior Amsalem (1):
      dmaengine: mv_xor: bug fix for racing condition in descriptors cleanup

Lv Zheng (3):
      ACPICA: Tables: Enable both 32-bit and 64-bit FACS
      ACPICA: Tables: Fix an issue that FACS initialization is performed twice
      ACPICA: Tables: Enable default 64-bit FADT addresses favor

Malcolm Priestley (1):
      staging: vt6655: device_rx_srv check sk_buff is NULL

Marc Zyngier (1):
      arm: KVM: force execution of HCPTR access on VM exit

Marcel Holtmann (1):
      Bluetooth: btusb: Fix memory leak in Intel setup routine

Marcelo Ricardo Leitner (1):
      sctp: fix ASCONF list handling

Martin K. Petersen (1):
      libata: Do not blacklist Micron M500DC

Martin Sperl (1):
      spi: fix race freeing dummy_tx/rx before it is unmapped

Mauro Carvalho Chehab (4):
      [media] s5h1420: fix a buffer overflow when checking userspace params
      [media] cx24116: fix a buffer overflow when checking userspace params
      [media] af9013: Don't accept invalid bandwidth
      [media] cx24117: fix a buffer overflow when checking userspace params

Maxime Coquelin (1):
      regmap: Fix possible shift overflow in regmap_field_init()

Michal Kazior (2):
      mac80211: prevent possible crypto tx tailroom corruption
      cfg80211: ignore netif running state when changing iftype

Miklos Szeredi (1):
      fuse: initialize fc->release before calling it

Mikulas Patocka (1):
      dm stats: fix divide by zero if 'number_of_areas' arg is zero

Mimi Zohar (1):
      ima: fix ima_show_template_data_ascii()

Mugunthan V N (1):
      net: phy: fix phy link up when limiting speed via device tree

Naoya Horiguchi (1):
      mm/hugetlb: introduce minimum hugepage order

Nathan Fontenot (1):
      powerpc/pseries: Fix possible leaked device node reference

NeilBrown (1):
      phy: twl4030-usb: remove incorrect pm_runtime_get_sync() in probe function.

Nikolay Aleksandrov (2):
      bridge: fix multicast router rlist endless loop
      bridge: fix br_stp_set_bridge_priority race conditions

Oleg Nesterov (1):
      perf: Fix ring_buffer_attach() RCU sync, again

Olga Kornievskaia (1):
      fixing infinite OPEN loop in 4.0 stateid recovery

Omar Sandoval (1):
      Btrfs: lock superblock before remounting for rw subvol

Or Gerlitz (2):
      net/mlx4_core: Enhance the MAD_IFC wrapper to convert VF port to physical
      IB/mlx4: Convert slave port before building address-handle

Pali Rohár (1):
      dell-laptop: Fix allocating & freeing SMI buffer page

Paolo Bonzini (2):
      KVM: mips: use id_to_memslot correctly
      kvm: x86: fix kvm_apic_has_events to check for NULL pointer

Paul E. McKenney (1):
      rcu: Correctly handle non-empty Tiny RCU callback list with none ready

Peter Zijlstra (1):
      locking,arch,arc: Fold atomic_ops

Radim Krčmář (2):
      KVM: x86: make vapics_in_nmi_mode atomic
      KVM: x86: properly restore LVT0

Rafael J. Wysocki (4):
      ACPI / PM: Add missing pm_generic_complete() invocation
      ACPI / PNP: Avoid conflicting resource reservations
      ACPI / init: Switch over platform to the ACPI mode later
      ACPI / PNP: Reserve ACPI resources at the fs_initcall_sync stage

Rafał Miłecki (1):
      b43: fix support for 14e4:4321 PCI dev with BCM4321 chipset

Ralf Baechle (1):
      NET: ROSE: Don't dereference NULL neighbour pointer.

Richard Fitzgerald (1):
      ASoC: arizona: Fix noise generator gain TLV

Robert Schlabbach (1):
      usb: core: Fix USB 3.0 devices lost in NOTATTACHED state after a hub port reset

Ryan Underwood (1):
      Disable write buffering on Toshiba ToPIC95

Satish Ashok (1):
      bridge: multicast: restore router configuration on port link down/up

Sebastien Szymanski (1):
      ARM: clk-imx6q: refine sata's parent

Shaohua Li (1):
      net: don't wait for order-3 page allocation

Simon Guinot (3):
      net: mvneta: introduce compatible string "marvell, armada-xp-neta"
      ARM: mvebu: update Ethernet compatible string for Armada XP
      net: mvneta: disable IP checksum with jumbo frames for Armada 370

Sowmini Varadhan (1):
      sparc: Use GFP_ATOMIC in ldc_alloc_exp_dring() as it can be called in softirq context

Stefan Wahren (2):
      regulator: core: fix constraints output buffer
      clk: Fix JSON output in debugfs

Steven Rostedt (Red Hat) (2):
      tracing/filter: Do not WARN on operand count going below zero
      tracing/filter: Do not allow infix to exceed end of string

Stevens, Nick (1):
      hwmon: (mcp3021) Fix broken output scaling

Subbaraya Sundeep Bhatta (1):
      usb: dwc3: gadget: return error if command sent to DGCMD register fails

Takashi Iwai (3):
      PM / sleep: Increase default DPM watchdog timeout to 60
      ALSA: hda - Add headset support to Acer Aspire V5
      ALSA: hda - Fix the dock headphone output on Fujitsu Lifebook E780

Theodore Ts'o (2):
      ext4: fix race between truncate and __ext4_journalled_writepage()
      ext4: call sync_blockdev() before invalidate_bdev() in put_super()

Thierry Reding (1):
      drm/tegra: dpaux: Fix transfers larger than 4 bytes

Thomas Petazzoni (8):
      pinctrl: mvebu: armada-38x: fix PCIe functions
      pinctrl: mvebu: armada-370: fix spi0 pin description
      pinctrl: mvebu: armada-375: remove non-existing NAND re/we pins
      pinctrl: mvebu: armada-xp: remove non-existing NAND pins
      pinctrl: mvebu: armada-xp: remove non-existing VDD cpu_pd functions
      pinctrl: mvebu: armada-xp: fix functions of MPP48
      pinctrl: mvebu: armada-375: remove incorrect space in pin description
      pinctrl: mvebu: armada-38x: fix incorrect total number of GPIOs

Trond Myklebust (2):
      SUNRPC: Fix a memory leak in the backchannel code
      pNFS: Fix a memory leak when attempted pnfs fails

Uwe Kleine-König (2):
      mtd: dc21285: use raw spinlock functions for nw_gpio_lock
      watchdog: omap: assert the counter being stopped before reprogramming

Vasily Averin (1):
      security_syslog() should be called once only

Vineet Gupta (2):
      ARC: add compiler barrier to LLSC based cmpxchg
      ARC: add smp barriers around atomics per Documentation/atomic_ops.txt

Will Deacon (1):
      arm64: vdso: work-around broken ELF toolchains in Makefile

Willem de Bruijn (1):
      packet: avoid out of bounds read in round robin fanout

Zidan Wang (1):
      ASoC: wm8960: the enum of "DAC Polarity" should be wm8960_enum[1]
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [next] | [standalone]


#1184436 — [PATCH 3.16.y-ckt 060/185] x86/PCI: Use host bridge _CRS info on Foxconn K8M890-8237A

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 060/185] x86/PCI: Use host bridge _CRS info on Foxconn K8M890-8237A
Message-ID<pMr17-36Z-13@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bjorn Helgaas <bhelgaas@google.com>

commit 1dace0116d0b05c967d94644fc4dfe96be2ecd3d upstream.

The Foxconn K8M890-8237A has two PCI host bridges, and we can't assign
resources correctly without the information from _CRS that tells us which
address ranges are claimed by which bridge.  In the bugs mentioned below,
we incorrectly assign a sound card address (this example is from 1033299):

  bus: 00 index 2 [mem 0x80000000-0xfcffffffff]
  ACPI: PCI Root Bridge [PCI0] (domain 0000 [bus 00-7f])
  pci_root PNP0A08:00: host bridge window [mem 0x80000000-0xbfefffff] (ignored)
  pci_root PNP0A08:00: host bridge window [mem 0xc0000000-0xdfffffff] (ignored)
  pci_root PNP0A08:00: host bridge window [mem 0xf0000000-0xfebfffff] (ignored)
  ACPI: PCI Root Bridge [PCI1] (domain 0000 [bus 80-ff])
  pci_root PNP0A08:01: host bridge window [mem 0xbff00000-0xbfffffff] (ignored)
  pci 0000:80:01.0: [1106:3288] type 0 class 0x000403
  pci 0000:80:01.0: reg 10: [mem 0xbfffc000-0xbfffffff 64bit]
  pci 0000:80:01.0: address space collision: [mem 0xbfffc000-0xbfffffff 64bit] conflicts with PCI Bus #00 [mem 0x80000000-0xfcffffffff]
  pci 0000:80:01.0: BAR 0: assigned [mem 0xfd00000000-0xfd00003fff 64bit]
  BUG: unable to handle kernel paging request at ffffc90000378000
  IP: [<ffffffffa0345f63>] azx_create+0x37c/0x822 [snd_hda_intel]

We assigned 0xfd_0000_0000, but that is not in any of the host bridge
windows, and the sound card doesn't work.

Turn on pci=use_crs automatically for this system.

Link: https://bugs.launchpad.net/ubuntu/+source/alsa-driver/+bug/931368
Link: https://bugs.launchpad.net/ubuntu/+source/alsa-driver/+bug/1033299
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 arch/x86/pci/acpi.c | 11 +++++++++++
 1 file changed, 11 insertions(+)

diff --git a/arch/x86/pci/acpi.c b/arch/x86/pci/acpi.c
index 5075371ab593..46e6538a1a6a 100644
--- a/arch/x86/pci/acpi.c
+++ b/arch/x86/pci/acpi.c
@@ -84,6 +84,17 @@ static const struct dmi_system_id pci_crs_quirks[] __initconst = {
 			DMI_MATCH(DMI_BIOS_VENDOR, "Phoenix Technologies, LTD"),
 		},
 	},
+	/* https://bugs.launchpad.net/ubuntu/+source/alsa-driver/+bug/931368 */
+	/* https://bugs.launchpad.net/ubuntu/+source/alsa-driver/+bug/1033299 */
+	{
+		.callback = set_use_crs,
+		.ident = "Foxconn K8M890-8237A",
+		.matches = {
+			DMI_MATCH(DMI_BOARD_VENDOR, "Foxconn"),
+			DMI_MATCH(DMI_BOARD_NAME, "K8M890-8237A"),
+			DMI_MATCH(DMI_BIOS_VENDOR, "Phoenix Technologies, LTD"),
+		},
+	},
 
 	/* Now for the blacklist.. */
 
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184438 — [PATCH 3.16.y-ckt 111/185] mm: kmemleak: allow safe memory scanning during kmemleak disabling

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 111/185] mm: kmemleak: allow safe memory scanning during kmemleak disabling
Message-ID<pMr17-36Z-17@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Catalin Marinas <catalin.marinas@arm.com>

commit c5f3b1a51a591c18c8b33983908e7fdda6ae417e upstream.

The kmemleak scanning thread can run for minutes.  Callbacks like
kmemleak_free() are allowed during this time, the race being taken care
of by the object->lock spinlock.  Such lock also prevents a memory block
from being freed or unmapped while it is being scanned by blocking the
kmemleak_free() -> ...  -> __delete_object() function until the lock is
released in scan_object().

When a kmemleak error occurs (e.g.  it fails to allocate its metadata),
kmemleak_enabled is set and __delete_object() is no longer called on
freed objects.  If kmemleak_scan is running at the same time,
kmemleak_free() no longer waits for the object scanning to complete,
allowing the corresponding memory block to be freed or unmapped (in the
case of vfree()).  This leads to kmemleak_scan potentially triggering a
page fault.

This patch separates the kmemleak_free() enabling/disabling from the
overall kmemleak_enabled nob so that we can defer the disabling of the
object freeing tracking until the scanning thread completed.  The
kmemleak_free_part() is deliberately ignored by this patch since this is
only called during boot before the scanning thread started.

Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Reported-by: Vignesh Radhakrishnan <vigneshr@codeaurora.org>
Tested-by: Vignesh Radhakrishnan <vigneshr@codeaurora.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 mm/kmemleak.c | 19 ++++++++++++++++---
 1 file changed, 16 insertions(+), 3 deletions(-)

diff --git a/mm/kmemleak.c b/mm/kmemleak.c
index 3cda50c1e394..6691476a66fc 100644
--- a/mm/kmemleak.c
+++ b/mm/kmemleak.c
@@ -193,6 +193,8 @@ static struct kmem_cache *scan_area_cache;
 
 /* set if tracing memory operations is enabled */
 static int kmemleak_enabled;
+/* same as above but only for the kmemleak_free() callback */
+static int kmemleak_free_enabled;
 /* set in the late_initcall if there were no errors */
 static int kmemleak_initialized;
 /* enables or disables early logging of the memory operations */
@@ -940,7 +942,7 @@ void __ref kmemleak_free(const void *ptr)
 {
 	pr_debug("%s(0x%p)\n", __func__, ptr);
 
-	if (kmemleak_enabled && ptr && !IS_ERR(ptr))
+	if (kmemleak_free_enabled && ptr && !IS_ERR(ptr))
 		delete_object_full((unsigned long)ptr);
 	else if (kmemleak_early_log)
 		log_early(KMEMLEAK_FREE, ptr, 0, 0);
@@ -980,7 +982,7 @@ void __ref kmemleak_free_percpu(const void __percpu *ptr)
 
 	pr_debug("%s(0x%p)\n", __func__, ptr);
 
-	if (kmemleak_enabled && ptr && !IS_ERR(ptr))
+	if (kmemleak_free_enabled && ptr && !IS_ERR(ptr))
 		for_each_possible_cpu(cpu)
 			delete_object_full((unsigned long)per_cpu_ptr(ptr,
 								      cpu));
@@ -1743,6 +1745,13 @@ static void kmemleak_do_cleanup(struct work_struct *work)
 	mutex_lock(&scan_mutex);
 	stop_scan_thread();
 
+	/*
+	 * Once the scan thread has stopped, it is safe to no longer track
+	 * object freeing. Ordering of the scan thread stopping and the memory
+	 * accesses below is guaranteed by the kthread_stop() function.
+	 */
+	kmemleak_free_enabled = 0;
+
 	if (!kmemleak_found_leaks)
 		__kmemleak_do_cleanup();
 	else
@@ -1769,6 +1778,8 @@ static void kmemleak_disable(void)
 	/* check whether it is too early for a kernel thread */
 	if (kmemleak_initialized)
 		schedule_work(&cleanup_work);
+	else
+		kmemleak_free_enabled = 0;
 
 	pr_info("Kernel memory leak detector disabled\n");
 }
@@ -1833,8 +1844,10 @@ void __init kmemleak_init(void)
 	if (kmemleak_error) {
 		local_irq_restore(flags);
 		return;
-	} else
+	} else {
 		kmemleak_enabled = 1;
+		kmemleak_free_enabled = 1;
+	}
 	local_irq_restore(flags);
 
 	/*
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184439 — [PATCH 3.16.y-ckt 031/185] scsi_transport_srp: Fix a race condition

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 031/185] scsi_transport_srp: Fix a race condition
Message-ID<pMr17-36Z-19@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bart Van Assche <bart.vanassche@sandisk.com>

commit 535fb906225fb7436cb658144d0c0cea14a26f3e upstream.

Avoid that srp_terminate_io() can get invoked while srp_queuecommand()
is in progress. This patch avoids that an I/O timeout can trigger the
following kernel warning:

WARNING: at drivers/infiniband/ulp/srp/ib_srp.c:1447 srp_terminate_io+0xef/0x100 [ib_srp]()
Call Trace:
 [<ffffffff814c65a2>] dump_stack+0x4e/0x68
 [<ffffffff81051f71>] warn_slowpath_common+0x81/0xa0
 [<ffffffff8105204a>] warn_slowpath_null+0x1a/0x20
 [<ffffffffa075f51f>] srp_terminate_io+0xef/0x100 [ib_srp]
 [<ffffffffa07495da>] __rport_fail_io_fast+0xba/0xc0 [scsi_transport_srp]
 [<ffffffffa0749a90>] rport_fast_io_fail_timedout+0xe0/0xf0 [scsi_transport_srp]
 [<ffffffff8106e09b>] process_one_work+0x1db/0x780
 [<ffffffff8106e75b>] worker_thread+0x11b/0x450
 [<ffffffff81073c64>] kthread+0xe4/0x100
 [<ffffffff814cf26c>] ret_from_fork+0x7c/0xb0

See also patch "scsi_transport_srp: Add transport layer error
handling" (commit ID 29c17324803c).

Signed-off-by: Bart Van Assche <bart.vanassche@sandisk.com>
Cc: James Bottomley <JBottomley@Odin.com>
Cc: Sagi Grimberg <sagig@mellanox.com>
Cc: Sebastian Parschauer <sebastian.riemer@profitbricks.com>
Signed-off-by: Doug Ledford <dledford@redhat.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/scsi/scsi_transport_srp.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/scsi/scsi_transport_srp.c b/drivers/scsi/scsi_transport_srp.c
index 62afa8f7e3b3..a68079d66d9e 100644
--- a/drivers/scsi/scsi_transport_srp.c
+++ b/drivers/scsi/scsi_transport_srp.c
@@ -440,8 +440,10 @@ static void __rport_fail_io_fast(struct srp_rport *rport)
 
 	/* Involve the LLD if possible to terminate all I/O on the rport. */
 	i = to_srp_internal(shost->transportt);
-	if (i->f->terminate_rport_io)
+	if (i->f->terminate_rport_io) {
+		srp_wait_for_queuecommand(shost);
 		i->f->terminate_rport_io(rport);
+	}
 }
 
 /**
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184440 — [PATCH 3.16.y-ckt 173/185] perf: Fix ring_buffer_attach() RCU sync, again

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 173/185] perf: Fix ring_buffer_attach() RCU sync, again
Message-ID<pMr17-36Z-21@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Oleg Nesterov <oleg@redhat.com>

commit 2f993cf093643b98477c421fa2b9a98dcc940323 upstream.

While looking for other users of get_state/cond_sync. I Found
ring_buffer_attach() and it looks obviously buggy?

Don't we need to ensure that we have "synchronize" _between_
list_del() and list_add() ?

IOW. Suppose that ring_buffer_attach() preempts right_after
get_state_synchronize_rcu() and gp completes before spin_lock().

In this case cond_synchronize_rcu() does nothing and we reuse
->rb_entry without waiting for gp in between?

It also moves the ->rcu_pending check under "if (rb)", to make it
more readable imo.

Signed-off-by: Oleg Nesterov <oleg@redhat.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Brian Gerst <brgerst@gmail.com>
Cc: Denys Vlasenko <dvlasenk@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Paul E. McKenney <paulmck@linux.vnet.ibm.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: dave@stgolabs.net
Cc: der.herr@hofr.at
Cc: josh@joshtriplett.org
Cc: tj@kernel.org
Fixes: b69cf53640da ("perf: Fix a race between ring_buffer_detach() and ring_buffer_attach()")
Link: http://lkml.kernel.org/r/20150530200425.GA15748@redhat.com
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 kernel/events/core.c | 14 +++++++-------
 1 file changed, 7 insertions(+), 7 deletions(-)

diff --git a/kernel/events/core.c b/kernel/events/core.c
index 92320781b140..40338799dcb0 100644
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -3944,20 +3944,20 @@ static void ring_buffer_attach(struct perf_event *event,
 		WARN_ON_ONCE(event->rcu_pending);
 
 		old_rb = event->rb;
-		event->rcu_batches = get_state_synchronize_rcu();
-		event->rcu_pending = 1;
-
 		spin_lock_irqsave(&old_rb->event_lock, flags);
 		list_del_rcu(&event->rb_entry);
 		spin_unlock_irqrestore(&old_rb->event_lock, flags);
-	}
 
-	if (event->rcu_pending && rb) {
-		cond_synchronize_rcu(event->rcu_batches);
-		event->rcu_pending = 0;
+		event->rcu_batches = get_state_synchronize_rcu();
+		event->rcu_pending = 1;
 	}
 
 	if (rb) {
+		if (event->rcu_pending) {
+			cond_synchronize_rcu(event->rcu_batches);
+			event->rcu_pending = 0;
+		}
+
 		spin_lock_irqsave(&rb->event_lock, flags);
 		list_add_rcu(&event->rb_entry, &rb->event_list);
 		spin_unlock_irqrestore(&rb->event_lock, flags);
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184441 — [PATCH 3.16.y-ckt 008/185] packet: read num_members once in packet_rcv_fanout()

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 008/185] packet: read num_members once in packet_rcv_fanout()
Message-ID<pMr18-36Z-25@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

commit f98f4514d07871da7a113dd9e3e330743fd70ae4 upstream.

We need to tell compiler it must not read f->num_members multiple
times. Otherwise testing if num is not zero is flaky, and we could
attempt an invalid divide by 0 in fanout_demux_cpu()

Note bug was present in packet_rcv_fanout_hash() and
packet_rcv_fanout_lb() but final 3.1 had a simple location
after commit 95ec3eb417115fb ("packet: Add 'cpu' fanout policy.")

Fixes: dc99f600698dc ("packet: Add fanout support.")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Willem de Bruijn <willemb@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ luis: backported to 3.16: used davem's backport to 3.14 ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/packet/af_packet.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/packet/af_packet.c b/net/packet/af_packet.c
index 3eb786fd3f22..5d2e8d651747 100644
--- a/net/packet/af_packet.c
+++ b/net/packet/af_packet.c
@@ -1346,7 +1346,7 @@ static int packet_rcv_fanout(struct sk_buff *skb, struct net_device *dev,
 			     struct packet_type *pt, struct net_device *orig_dev)
 {
 	struct packet_fanout *f = pt->af_packet_priv;
-	unsigned int num = f->num_members;
+	unsigned int num = ACCESS_ONCE(f->num_members);
 	struct packet_sock *po;
 	unsigned int idx;
 
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184443 — [PATCH 3.16.y-ckt 067/185] pinctrl: mvebu: armada-375: remove incorrect space in pin description

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 067/185] pinctrl: mvebu: armada-375: remove incorrect space in pin description
Message-ID<pMr18-36Z-29@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>

commit d538990ee12b162f7ce6c0fcef3b643800102676 upstream.

There was an incorrect space in the definition of the function of one
pin in the Armada 375 pinctrl driver, which this commit fixes.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
Fixes: ce3ed59dcddd ("pinctrl: mvebu: add pin-muxing driver for the Marvell Armada 375")
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/pinctrl/mvebu/pinctrl-armada-375.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/pinctrl/mvebu/pinctrl-armada-375.c b/drivers/pinctrl/mvebu/pinctrl-armada-375.c
index a5089029ba6c..64cc1184ecc2 100644
--- a/drivers/pinctrl/mvebu/pinctrl-armada-375.c
+++ b/drivers/pinctrl/mvebu/pinctrl-armada-375.c
@@ -92,7 +92,7 @@ static struct mvebu_mpp_mode mv88f6720_mpp_modes[] = {
 		 MPP_FUNCTION(0x5, "nand", "io1")),
 	MPP_MODE(8,
 		 MPP_FUNCTION(0x0, "gpio", NULL),
-		 MPP_FUNCTION(0x1, "dev ", "bootcs"),
+		 MPP_FUNCTION(0x1, "dev", "bootcs"),
 		 MPP_FUNCTION(0x2, "spi0", "cs0"),
 		 MPP_FUNCTION(0x3, "spi1", "cs0"),
 		 MPP_FUNCTION(0x5, "nand", "ce")),
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184446 — [PATCH 3.16.y-ckt 138/185] vfs: Remove incorrect debugging WARN in prepend_path

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 138/185] vfs: Remove incorrect debugging WARN in prepend_path
Message-ID<pMr18-36Z-37@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: "Eric W. Biederman" <ebiederm@xmission.com>

commit 93e3bce6287e1fb3e60d3324ed08555b5bbafa89 upstream.

The warning message in prepend_path is unclear and outdated.  It was
added as a warning that the mechanism for generating names of pseudo
files had been removed from prepend_path and d_dname should be used
instead.  Unfortunately the warning reads like a general warning,
making it unclear what to do with it.

Remove the warning.  The transition it was added to warn about is long
over, and I added code several years ago which in rare cases causes
the warning to fire on legitimate code, and the warning is now firing
and scaring people for no good reason.

Reported-by: Ivan Delalande <colona@arista.com>
Reported-by: Omar Sandoval <osandov@osandov.com>
Fixes: f48cfddc6729e ("vfs: In d_path don't call d_dname on a mount point")
Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 fs/dcache.c | 11 -----------
 1 file changed, 11 deletions(-)

diff --git a/fs/dcache.c b/fs/dcache.c
index 05a041a134c4..df0de6b95409 100644
--- a/fs/dcache.c
+++ b/fs/dcache.c
@@ -2898,17 +2898,6 @@ restart:
 				vfsmnt = &mnt->mnt;
 				continue;
 			}
-			/*
-			 * Filesystems needing to implement special "root names"
-			 * should do so with ->d_dname()
-			 */
-			if (IS_ROOT(dentry) &&
-			   (dentry->d_name.len != 1 ||
-			    dentry->d_name.name[0] != '/')) {
-				WARN(1, "Root dentry has weird name <%.*s>\n",
-				     (int) dentry->d_name.len,
-				     dentry->d_name.name);
-			}
 			if (!error)
 				error = is_mounted(vfsmnt) ? 1 : 2;
 			break;
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184447 — [PATCH 3.16.y-ckt 178/185] __bitmap_parselist: fix bug in empty string handling

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 178/185] __bitmap_parselist: fix bug in empty string handling
Message-ID<pMr18-36Z-39@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chris Metcalf <cmetcalf@ezchip.com>

commit 2528a8b8f457d7432552d0e2b6f0f4046bb702f4 upstream.

bitmap_parselist("", &mask, nmaskbits) will erroneously set bit zero in
the mask.  The same bug is visible in cpumask_parselist() since it is
layered on top of the bitmask code, e.g.  if you boot with "isolcpus=",
you will actually end up with cpu zero isolated.

The bug was introduced in commit 4b060420a596 ("bitmap, irq: add
smp_affinity_list interface to /proc/irq") when bitmap_parselist() was
generalized to support userspace as well as kernelspace.

Fixes: 4b060420a596 ("bitmap, irq: add smp_affinity_list interface to /proc/irq")
Signed-off-by: Chris Metcalf <cmetcalf@ezchip.com>
Cc: Rasmus Villemoes <linux@rasmusvillemoes.dk>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 lib/bitmap.c | 17 +++++++++--------
 1 file changed, 9 insertions(+), 8 deletions(-)

diff --git a/lib/bitmap.c b/lib/bitmap.c
index e5c4ebe586ba..c0634aa923a6 100644
--- a/lib/bitmap.c
+++ b/lib/bitmap.c
@@ -603,12 +603,12 @@ static int __bitmap_parselist(const char *buf, unsigned int buflen,
 	unsigned a, b;
 	int c, old_c, totaldigits;
 	const char __user __force *ubuf = (const char __user __force *)buf;
-	int exp_digit, in_range;
+	int at_start, in_range;
 
 	totaldigits = c = 0;
 	bitmap_zero(maskp, nmaskbits);
 	do {
-		exp_digit = 1;
+		at_start = 1;
 		in_range = 0;
 		a = b = 0;
 
@@ -637,11 +637,10 @@ static int __bitmap_parselist(const char *buf, unsigned int buflen,
 				break;
 
 			if (c == '-') {
-				if (exp_digit || in_range)
+				if (at_start || in_range)
 					return -EINVAL;
 				b = 0;
 				in_range = 1;
-				exp_digit = 1;
 				continue;
 			}
 
@@ -651,16 +650,18 @@ static int __bitmap_parselist(const char *buf, unsigned int buflen,
 			b = b * 10 + (c - '0');
 			if (!in_range)
 				a = b;
-			exp_digit = 0;
+			at_start = 0;
 			totaldigits++;
 		}
 		if (!(a <= b))
 			return -EINVAL;
 		if (b >= nmaskbits)
 			return -ERANGE;
-		while (a <= b) {
-			set_bit(a, maskp);
-			a++;
+		if (!at_start) {
+			while (a <= b) {
+				set_bit(a, maskp);
+				a++;
+			}
 		}
 	} while (buflen && c == ',');
 	return 0;
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184448 — [PATCH 3.16.y-ckt 104/185] fs: Fix S_NOSEC handling

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 104/185] fs: Fix S_NOSEC handling
Message-ID<pMr18-36Z-41@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jan Kara <jack@suse.cz>

commit 2426f3910069ed47c0cc58559a6d088af7920201 upstream.

file_remove_suid() could mistakenly set S_NOSEC inode bit when root was
modifying the file. As a result following writes to the file by ordinary
user would avoid clearing suid or sgid bits.

Fix the bug by checking actual mode bits before setting S_NOSEC.

Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 fs/inode.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/fs/inode.c b/fs/inode.c
index 6eecb7ff0b9a..f5a842698580 100644
--- a/fs/inode.c
+++ b/fs/inode.c
@@ -1630,8 +1630,8 @@ int file_remove_suid(struct file *file)
 		error = security_inode_killpriv(dentry);
 	if (!error && killsuid)
 		error = __remove_suid(dentry, killsuid);
-	if (!error && (inode->i_sb->s_flags & MS_NOSEC))
-		inode->i_flags |= S_NOSEC;
+	if (!error)
+		inode_has_no_xattr(inode);
 
 	return error;
 }
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184449 — [PATCH 3.16.y-ckt 180/185] kvm: x86: fix kvm_apic_has_events to check for NULL pointer

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 180/185] kvm: x86: fix kvm_apic_has_events to check for NULL pointer
Message-ID<pMr18-36Z-43@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Paolo Bonzini <pbonzini@redhat.com>

commit ce40cd3fc7fa40a6119e5fe6c0f2bc0eb4541009 upstream.

Malicious (or egregiously buggy) userspace can trigger it, but it
should never happen in normal operation.

Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 arch/x86/kvm/lapic.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/x86/kvm/lapic.h b/arch/x86/kvm/lapic.h
index 6a11845fd8b9..72051730caf1 100644
--- a/arch/x86/kvm/lapic.h
+++ b/arch/x86/kvm/lapic.h
@@ -165,7 +165,7 @@ static inline u16 apic_logical_id(struct kvm_apic_map *map, u32 ldr)
 
 static inline bool kvm_apic_has_events(struct kvm_vcpu *vcpu)
 {
-	return vcpu->arch.apic->pending_events;
+	return kvm_vcpu_has_lapic(vcpu) && vcpu->arch.apic->pending_events;
 }
 
 bool kvm_apic_pending_eoi(struct kvm_vcpu *vcpu, int vector);
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184451 — [PATCH 3.16.y-ckt 056/185] b43: fix support for 14e4:4321 PCI dev with BCM4321 chipset

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 056/185] b43: fix support for 14e4:4321 PCI dev with BCM4321 chipset
Message-ID<pMr18-36Z-47@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: =?UTF-8?q?Rafa=C5=82=20Mi=C5=82ecki?= <zajec5@gmail.com>

commit 90f91b129810c3f169e443252be30ed7c0130326 upstream.

It seems Broadcom released two devices with conflicting device id. There
are for sure 14e4:4321 PCI devices with BCM4321 (N-PHY) chipset, they
can be found in routers, e.g. Netgear WNR834Bv2. However, according to
Broadcom public sources 0x4321 is also used for 5 GHz BCM4306 (G-PHY).
It's unsure if they meant PCI device id, or "virtual" id (from SPROM).
To distinguish these devices lets check PHY type (G vs. N).

Signed-off-by: Rafał Miłecki <zajec5@gmail.com>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/net/wireless/b43/main.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/net/wireless/b43/main.c b/drivers/net/wireless/b43/main.c
index 0d6a0bb1f876..8556325e98a3 100644
--- a/drivers/net/wireless/b43/main.c
+++ b/drivers/net/wireless/b43/main.c
@@ -5130,6 +5130,10 @@ static void b43_supported_bands(struct b43_wldev *dev, bool *have_2ghz_phy,
 		*have_5ghz_phy = true;
 		return;
 	case 0x4321: /* BCM4306 */
+		/* There are 14e4:4321 PCI devs with 2.4 GHz BCM4321 (N-PHY) */
+		if (dev->phy.type != B43_PHYTYPE_G)
+			break;
+		/* fall through */
 	case 0x4313: /* BCM4311 */
 	case 0x431a: /* BCM4318 */
 	case 0x432a: /* BCM4321 */
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184452 — [PATCH 3.16.y-ckt 184/185] LZ4 : fix the data abort issue

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 184/185] LZ4 : fix the data abort issue
Message-ID<pMr18-36Z-49@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: JeHyeon Yeon <tom.yeon@windriver.com>

commit d5e7cafd69da24e6d6cc988fab6ea313a2577efc upstream.

If the part of the compression data are corrupted, or the compression
data is totally fake, the memory access over the limit is possible.

This is the log from my system usning lz4 decompression.
   [6502]data abort, halting
   [6503]r0  0x00000000 r1  0x00000000 r2  0xdcea0ffc r3  0xdcea0ffc
   [6509]r4  0xb9ab0bfd r5  0xdcea0ffc r6  0xdcea0ff8 r7  0xdce80000
   [6515]r8  0x00000000 r9  0x00000000 r10 0x00000000 r11 0xb9a98000
   [6522]r12 0xdcea1000 usp 0x00000000 ulr 0x00000000 pc  0x820149bc
   [6528]spsr 0x400001f3
and the memory addresses of some variables at the moment are
    ref:0xdcea0ffc, op:0xdcea0ffc, oend:0xdcea1000

As you can see, COPYLENGH is 8bytes, so @ref and @op can access the momory
over @oend.

Signed-off-by: JeHyeon Yeon <tom.yeon@windriver.com>
Reviewed-by: David Sterba <dsterba@suse.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 lib/lz4/lz4_decompress.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/lib/lz4/lz4_decompress.c b/lib/lz4/lz4_decompress.c
index 7a85967060a5..f0f5c5c3de12 100644
--- a/lib/lz4/lz4_decompress.c
+++ b/lib/lz4/lz4_decompress.c
@@ -139,6 +139,9 @@ static int lz4_uncompress(const char *source, char *dest, int osize)
 			/* Error: request to write beyond destination buffer */
 			if (cpy > oend)
 				goto _output_error;
+			if ((ref + COPYLENGTH) > oend ||
+					(op + COPYLENGTH) > oend)
+				goto _output_error;
 			LZ4_SECURECOPY(ref, op, (oend - COPYLENGTH));
 			while (op < cpy)
 				*op++ = *ref++;
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184453 — [PATCH 3.16.y-ckt 145/185] KVM: s390: virtio-ccw: don't overwrite config space values

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 145/185] KVM: s390: virtio-ccw: don't overwrite config space values
Message-ID<pMr19-36Z-51@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cornelia Huck <cornelia.huck@de.ibm.com>

commit 431dae778aea4eed31bd12e5ee82edc571cd4d70 upstream.

Eric noticed problems with vhost-scsi and virtio-ccw: vhost-scsi
complained about overwriting values in the config space, which
was triggered by a broken implementation of virtio-ccw's config
get/set routines. It was probably sheer luck that we did not hit
this before.

When writing a value to the config space, the WRITE_CONF ccw will
always write from the beginning of the config space up to and
including the value to be set. If the config space up to the value
has not yet been retrieved from the device, however, we'll end up
overwriting values. Keep track of the known config space and update
if needed to avoid this.

Moreover, READ_CONF will only read the number of bytes it has been
instructed to retrieve, so we must not copy more than that to the
buffer, or we might overwrite trailing values.

Reported-by: Eric Farman <farman@linux.vnet.ibm.com>
Signed-off-by: Cornelia Huck <cornelia.huck@de.ibm.com>
Reviewed-by: Eric Farman <farman@linux.vnet.ibm.com>
Tested-by: Eric Farman <farman@linux.vnet.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@de.ibm.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/s390/kvm/virtio_ccw.c | 11 +++++++++--
 1 file changed, 9 insertions(+), 2 deletions(-)

diff --git a/drivers/s390/kvm/virtio_ccw.c b/drivers/s390/kvm/virtio_ccw.c
index d2c0b442bce5..b6ade163445c 100644
--- a/drivers/s390/kvm/virtio_ccw.c
+++ b/drivers/s390/kvm/virtio_ccw.c
@@ -64,6 +64,7 @@ struct virtio_ccw_device {
 	bool is_thinint;
 	bool going_away;
 	bool device_lost;
+	unsigned int config_ready;
 	void *airq_info;
 };
 
@@ -758,8 +759,11 @@ static void virtio_ccw_get_config(struct virtio_device *vdev,
 	if (ret)
 		goto out_free;
 
-	memcpy(vcdev->config, config_area, sizeof(vcdev->config));
-	memcpy(buf, &vcdev->config[offset], len);
+	memcpy(vcdev->config, config_area, offset + len);
+	if (buf)
+		memcpy(buf, &vcdev->config[offset], len);
+	if (vcdev->config_ready < offset + len)
+		vcdev->config_ready = offset + len;
 
 out_free:
 	kfree(config_area);
@@ -782,6 +786,9 @@ static void virtio_ccw_set_config(struct virtio_device *vdev,
 	if (!config_area)
 		goto out_free;
 
+	/* Make sure we don't overwrite fields. */
+	if (vcdev->config_ready < offset)
+		virtio_ccw_get_config(vdev, 0, NULL, offset);
 	memcpy(&vcdev->config[offset], buf, len);
 	/* Write the config area to the host. */
 	memcpy(config_area, vcdev->config, sizeof(vcdev->config));
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184455 — [PATCH 3.16.y-ckt 113/185] ALSA: hda - Fix Dock Headphone on Thinkpad X250 seen as a Line Out

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 113/185] ALSA: hda - Fix Dock Headphone on Thinkpad X250 seen as a Line Out
Message-ID<pMr19-36Z-55@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Henningsson <david.henningsson@canonical.com>

commit ec56af67a10a0d82b79027878a81fce08d002d50 upstream.

Thinkpad X250, when attached to a dock, has two headphone outs but
no line out. Make sure we don't try to turn this into one headphone
and one line out (since that disables the headphone amp on the dock).

Alsa-info at http://www.alsa-project.org/db/?f=36f8764e1d782397928feec715d0ef90dfddd4c1

Signed-off-by: David Henningsson <david.henningsson@canonical.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 sound/pci/hda/patch_realtek.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index 9d2aedb84797..1115e8aed237 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -4314,6 +4314,7 @@ enum {
 	ALC255_FIXUP_HEADSET_MODE_NO_HP_MIC,
 	ALC293_FIXUP_DELL1_MIC_NO_PRESENCE,
 	ALC292_FIXUP_TPT440_DOCK,
+	ALC292_FIXUP_TPT440_DOCK2,
 };
 
 static const struct hda_fixup alc269_fixups[] = {
@@ -4738,6 +4739,12 @@ static const struct hda_fixup alc269_fixups[] = {
 		.chain_id = ALC269_FIXUP_HEADSET_MODE
 	},
 	[ALC292_FIXUP_TPT440_DOCK] = {
+		.type = HDA_FIXUP_FUNC,
+		.v.func = alc269_fixup_pincfg_no_hp_to_lineout,
+		.chained = true,
+		.chain_id = ALC292_FIXUP_TPT440_DOCK2
+	},
+	[ALC292_FIXUP_TPT440_DOCK2] = {
 		.type = HDA_FIXUP_PINS,
 		.v.pins = (const struct hda_pintbl[]) {
 			{ 0x16, 0x21211010 }, /* dock headphone */
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184456 — [PATCH 3.16.y-ckt 091/185] ACPI / PNP: Avoid conflicting resource reservations

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 091/185] ACPI / PNP: Avoid conflicting resource reservations
Message-ID<pMr19-36Z-57@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: "Rafael J. Wysocki" <rafael.j.wysocki@intel.com>

commit 0f1b414d190724617eb1cdd615592fa8cd9d0b50 upstream.

Commit b9a5e5e18fbf "ACPI / init: Fix the ordering of
acpi_reserve_resources()" overlooked the fact that the memory
and/or I/O regions reserved by acpi_reserve_resources() may
conflict with those reserved by the PNP "system" driver.

If that conflict actually takes place, it causes the reservations
made by the "system" driver to fail while before commit b9a5e5e18fbf
all reservations made by it and by acpi_reserve_resources() would be
successful.  In turn, that allows the resources that haven't been
reserved by the "system" driver to be used by others (e.g. PCI) which
sometimes leads to functional problems (up to and including boot
failures).

To fix that issue, introduce a common resource reservation routine,
acpi_reserve_region(), to be used by both acpi_reserve_resources()
and the "system" driver, that will track all resources reserved by
it and avoid making conflicting requests.

Link: https://bugzilla.kernel.org/show_bug.cgi?id=99831
Link: http://marc.info/?t=143389402600001&r=1&w=2
Fixes: b9a5e5e18fbf "ACPI / init: Fix the ordering of acpi_reserve_resources()"
Reported-by: Roland Dreier <roland@purestorage.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/acpi/osl.c      |   6 +-
 drivers/acpi/resource.c | 160 ++++++++++++++++++++++++++++++++++++++++++++++++
 drivers/pnp/system.c    |  35 ++++++++---
 include/linux/acpi.h    |  10 +++
 4 files changed, 197 insertions(+), 14 deletions(-)

diff --git a/drivers/acpi/osl.c b/drivers/acpi/osl.c
index 1b2d872c7398..bbde6af69584 100644
--- a/drivers/acpi/osl.c
+++ b/drivers/acpi/osl.c
@@ -165,11 +165,7 @@ static void __init acpi_request_region (struct acpi_generic_address *gas,
 	if (!addr || !length)
 		return;
 
-	/* Resources are never freed */
-	if (gas->space_id == ACPI_ADR_SPACE_SYSTEM_IO)
-		request_region(addr, length, desc);
-	else if (gas->space_id == ACPI_ADR_SPACE_SYSTEM_MEMORY)
-		request_mem_region(addr, length, desc);
+	acpi_reserve_region(addr, length, gas->space_id, 0, desc);
 }
 
 static void __init acpi_reserve_resources(void)
diff --git a/drivers/acpi/resource.c b/drivers/acpi/resource.c
index 2ba8f02ced36..28314ba82320 100644
--- a/drivers/acpi/resource.c
+++ b/drivers/acpi/resource.c
@@ -26,6 +26,7 @@
 #include <linux/device.h>
 #include <linux/export.h>
 #include <linux/ioport.h>
+#include <linux/list.h>
 #include <linux/slab.h>
 
 #ifdef CONFIG_X86
@@ -538,3 +539,162 @@ int acpi_dev_get_resources(struct acpi_device *adev, struct list_head *list,
 	return c.count;
 }
 EXPORT_SYMBOL_GPL(acpi_dev_get_resources);
+
+struct reserved_region {
+	struct list_head node;
+	u64 start;
+	u64 end;
+};
+
+static LIST_HEAD(reserved_io_regions);
+static LIST_HEAD(reserved_mem_regions);
+
+static int request_range(u64 start, u64 end, u8 space_id, unsigned long flags,
+			 char *desc)
+{
+	unsigned int length = end - start + 1;
+	struct resource *res;
+
+	res = space_id == ACPI_ADR_SPACE_SYSTEM_IO ?
+		request_region(start, length, desc) :
+		request_mem_region(start, length, desc);
+	if (!res)
+		return -EIO;
+
+	res->flags &= ~flags;
+	return 0;
+}
+
+static int add_region_before(u64 start, u64 end, u8 space_id,
+			     unsigned long flags, char *desc,
+			     struct list_head *head)
+{
+	struct reserved_region *reg;
+	int error;
+
+	reg = kmalloc(sizeof(*reg), GFP_KERNEL);
+	if (!reg)
+		return -ENOMEM;
+
+	error = request_range(start, end, space_id, flags, desc);
+	if (error)
+		return error;
+
+	reg->start = start;
+	reg->end = end;
+	list_add_tail(&reg->node, head);
+	return 0;
+}
+
+/**
+ * acpi_reserve_region - Reserve an I/O or memory region as a system resource.
+ * @start: Starting address of the region.
+ * @length: Length of the region.
+ * @space_id: Identifier of address space to reserve the region from.
+ * @flags: Resource flags to clear for the region after requesting it.
+ * @desc: Region description (for messages).
+ *
+ * Reserve an I/O or memory region as a system resource to prevent others from
+ * using it.  If the new region overlaps with one of the regions (in the given
+ * address space) already reserved by this routine, only the non-overlapping
+ * parts of it will be reserved.
+ *
+ * Returned is either 0 (success) or a negative error code indicating a resource
+ * reservation problem.  It is the code of the first encountered error, but the
+ * routine doesn't abort until it has attempted to request all of the parts of
+ * the new region that don't overlap with other regions reserved previously.
+ *
+ * The resources requested by this routine are never released.
+ */
+int acpi_reserve_region(u64 start, unsigned int length, u8 space_id,
+			unsigned long flags, char *desc)
+{
+	struct list_head *regions;
+	struct reserved_region *reg;
+	u64 end = start + length - 1;
+	int ret = 0, error = 0;
+
+	if (space_id == ACPI_ADR_SPACE_SYSTEM_IO)
+		regions = &reserved_io_regions;
+	else if (space_id == ACPI_ADR_SPACE_SYSTEM_MEMORY)
+		regions = &reserved_mem_regions;
+	else
+		return -EINVAL;
+
+	if (list_empty(regions))
+		return add_region_before(start, end, space_id, flags, desc, regions);
+
+	list_for_each_entry(reg, regions, node)
+		if (reg->start == end + 1) {
+			/* The new region can be prepended to this one. */
+			ret = request_range(start, end, space_id, flags, desc);
+			if (!ret)
+				reg->start = start;
+
+			return ret;
+		} else if (reg->start > end) {
+			/* No overlap.  Add the new region here and get out. */
+			return add_region_before(start, end, space_id, flags,
+						 desc, &reg->node);
+		} else if (reg->end == start - 1) {
+			goto combine;
+		} else if (reg->end >= start) {
+			goto overlap;
+		}
+
+	/* The new region goes after the last existing one. */
+	return add_region_before(start, end, space_id, flags, desc, regions);
+
+ overlap:
+	/*
+	 * The new region overlaps an existing one.
+	 *
+	 * The head part of the new region immediately preceding the existing
+	 * overlapping one can be combined with it right away.
+	 */
+	if (reg->start > start) {
+		error = request_range(start, reg->start - 1, space_id, flags, desc);
+		if (error)
+			ret = error;
+		else
+			reg->start = start;
+	}
+
+ combine:
+	/*
+	 * The new region is adjacent to an existing one.  If it extends beyond
+	 * that region all the way to the next one, it is possible to combine
+	 * all three of them.
+	 */
+	while (reg->end < end) {
+		struct reserved_region *next = NULL;
+		u64 a = reg->end + 1, b = end;
+
+		if (!list_is_last(&reg->node, regions)) {
+			next = list_next_entry(reg, node);
+			if (next->start <= end)
+				b = next->start - 1;
+		}
+		error = request_range(a, b, space_id, flags, desc);
+		if (!error) {
+			if (next && next->start == b + 1) {
+				reg->end = next->end;
+				list_del(&next->node);
+				kfree(next);
+			} else {
+				reg->end = end;
+				break;
+			}
+		} else if (next) {
+			if (!ret)
+				ret = error;
+
+			reg = next;
+		} else {
+			break;
+		}
+	}
+
+	return ret ? ret : error;
+}
+EXPORT_SYMBOL_GPL(acpi_reserve_region);
diff --git a/drivers/pnp/system.c b/drivers/pnp/system.c
index 49c1720df59a..515f33882ab8 100644
--- a/drivers/pnp/system.c
+++ b/drivers/pnp/system.c
@@ -7,6 +7,7 @@
  *	Bjorn Helgaas <bjorn.helgaas@hp.com>
  */
 
+#include <linux/acpi.h>
 #include <linux/pnp.h>
 #include <linux/device.h>
 #include <linux/init.h>
@@ -22,25 +23,41 @@ static const struct pnp_device_id pnp_dev_table[] = {
 	{"", 0}
 };
 
+#ifdef CONFIG_ACPI
+static bool __reserve_range(u64 start, unsigned int length, bool io, char *desc)
+{
+	u8 space_id = io ? ACPI_ADR_SPACE_SYSTEM_IO : ACPI_ADR_SPACE_SYSTEM_MEMORY;
+	return !acpi_reserve_region(start, length, space_id, IORESOURCE_BUSY, desc);
+}
+#else
+static bool __reserve_range(u64 start, unsigned int length, bool io, char *desc)
+{
+	struct resource *res;
+
+	res = io ? request_region(start, length, desc) :
+		request_mem_region(start, length, desc);
+	if (res) {
+		res->flags &= ~IORESOURCE_BUSY;
+		return true;
+	}
+	return false;
+}
+#endif
+
 static void reserve_range(struct pnp_dev *dev, struct resource *r, int port)
 {
 	char *regionid;
 	const char *pnpid = dev_name(&dev->dev);
 	resource_size_t start = r->start, end = r->end;
-	struct resource *res;
+	bool reserved;
 
 	regionid = kmalloc(16, GFP_KERNEL);
 	if (!regionid)
 		return;
 
 	snprintf(regionid, 16, "pnp %s", pnpid);
-	if (port)
-		res = request_region(start, end - start + 1, regionid);
-	else
-		res = request_mem_region(start, end - start + 1, regionid);
-	if (res)
-		res->flags &= ~IORESOURCE_BUSY;
-	else
+	reserved = __reserve_range(start, end - start + 1, !!port, regionid);
+	if (!reserved)
 		kfree(regionid);
 
 	/*
@@ -49,7 +66,7 @@ static void reserve_range(struct pnp_dev *dev, struct resource *r, int port)
 	 * have double reservations.
 	 */
 	dev_info(&dev->dev, "%pR %s reserved\n", r,
-		 res ? "has been" : "could not be");
+		 reserved ? "has been" : "could not be");
 }
 
 static void reserve_resources_of_dev(struct pnp_dev *dev)
diff --git a/include/linux/acpi.h b/include/linux/acpi.h
index 358c01b971db..fa91beba3cd0 100644
--- a/include/linux/acpi.h
+++ b/include/linux/acpi.h
@@ -306,6 +306,9 @@ int acpi_check_region(resource_size_t start, resource_size_t n,
 
 int acpi_resources_are_enforced(void);
 
+int acpi_reserve_region(u64 start, unsigned int length, u8 space_id,
+			unsigned long flags, char *desc);
+
 #ifdef CONFIG_HIBERNATION
 void __init acpi_no_s4_hw_signature(void);
 #endif
@@ -468,6 +471,13 @@ static inline int acpi_check_region(resource_size_t start, resource_size_t n,
 	return 0;
 }
 
+static inline int acpi_reserve_region(u64 start, unsigned int length,
+				      u8 space_id, unsigned long flags,
+				      char *desc)
+{
+	return -ENXIO;
+}
+
 struct acpi_table_header;
 static inline int acpi_table_parse(char *id,
 				int (*handler)(struct acpi_table_header *))
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184457 — [PATCH 3.16.y-ckt 082/185] ima: fix ima_show_template_data_ascii()

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 082/185] ima: fix ima_show_template_data_ascii()
Message-ID<pMr19-36Z-59@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mimi Zohar <zohar@linux.vnet.ibm.com>

commit 45b26133b97871896b8c5241d59f4ff7839db7b2 upstream.

This patch fixes a bug introduced in "4d7aeee ima: define new template
ima-ng and template fields d-ng and n-ng".

Changelog:
- change int to uint32 (Roberto Sassu's suggestion)

Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Signed-off-by: Roberto Sassu <rsassu@suse.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 security/integrity/ima/ima.h              | 2 +-
 security/integrity/ima/ima_fs.c           | 4 ++--
 security/integrity/ima/ima_template_lib.c | 3 ++-
 3 files changed, 5 insertions(+), 4 deletions(-)

diff --git a/security/integrity/ima/ima.h b/security/integrity/ima/ima.h
index f79fa8be203c..5cb7de9046fa 100644
--- a/security/integrity/ima/ima.h
+++ b/security/integrity/ima/ima.h
@@ -106,7 +106,7 @@ void ima_add_violation(struct file *file, const unsigned char *filename,
 		       const char *op, const char *cause);
 int ima_init_crypto(void);
 void ima_putc(struct seq_file *m, void *data, int datalen);
-void ima_print_digest(struct seq_file *m, u8 *digest, int size);
+void ima_print_digest(struct seq_file *m, u8 *digest, u32 size);
 struct ima_template_desc *ima_template_desc_current(void);
 int ima_init_template(void);
 
diff --git a/security/integrity/ima/ima_fs.c b/security/integrity/ima/ima_fs.c
index da92fcc08d15..d30afe461070 100644
--- a/security/integrity/ima/ima_fs.c
+++ b/security/integrity/ima/ima_fs.c
@@ -186,9 +186,9 @@ static const struct file_operations ima_measurements_ops = {
 	.release = seq_release,
 };
 
-void ima_print_digest(struct seq_file *m, u8 *digest, int size)
+void ima_print_digest(struct seq_file *m, u8 *digest, u32 size)
 {
-	int i;
+	u32 i;
 
 	for (i = 0; i < size; i++)
 		seq_printf(m, "%02x", *(digest + i));
diff --git a/security/integrity/ima/ima_template_lib.c b/security/integrity/ima/ima_template_lib.c
index 1506f0248572..1eb173ddefd6 100644
--- a/security/integrity/ima/ima_template_lib.c
+++ b/security/integrity/ima/ima_template_lib.c
@@ -70,7 +70,8 @@ static void ima_show_template_data_ascii(struct seq_file *m,
 					 enum data_formats datafmt,
 					 struct ima_field_data *field_data)
 {
-	u8 *buf_ptr = field_data->data, buflen = field_data->len;
+	u8 *buf_ptr = field_data->data;
+	u32 buflen = field_data->len;
 
 	switch (datafmt) {
 	case DATA_FMT_DIGEST_WITH_ALGO:
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184458 — [PATCH 3.16.y-ckt 177/185] security_syslog() should be called once only

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 177/185] security_syslog() should be called once only
Message-ID<pMr19-36Z-61@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Vasily Averin <vvs@virtuozzo.com>

commit d194e5d666225b04c7754471df0948f645b6ab3a upstream.

The final version of commit 637241a900cb ("kmsg: honor dmesg_restrict
sysctl on /dev/kmsg") lost few hooks, as result security_syslog() are
processed incorrectly:

- open of /dev/kmsg checks syslog access permissions by using
  check_syslog_permissions() where security_syslog() is not called if
  dmesg_restrict is set.

- syslog syscall and /proc/kmsg calls do_syslog() where security_syslog
  can be executed twice (inside check_syslog_permissions() and then
  directly in do_syslog())

With this patch security_syslog() is called once only in all
syslog-related operations regardless of dmesg_restrict value.

Fixes: 637241a900cb ("kmsg: honor dmesg_restrict sysctl on /dev/kmsg")
Signed-off-by: Vasily Averin <vvs@virtuozzo.com>
Cc: Kees Cook <keescook@chromium.org>
Cc: Josh Boyer <jwboyer@redhat.com>
Cc: Eric Paris <eparis@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 kernel/printk/printk.c | 11 ++++-------
 1 file changed, 4 insertions(+), 7 deletions(-)

diff --git a/kernel/printk/printk.c b/kernel/printk/printk.c
index cce20d2f38d5..f7f6f7e5ff8a 100644
--- a/kernel/printk/printk.c
+++ b/kernel/printk/printk.c
@@ -478,11 +478,11 @@ static int check_syslog_permissions(int type, bool from_file)
 	 * already done the capabilities checks at open time.
 	 */
 	if (from_file && type != SYSLOG_ACTION_OPEN)
-		return 0;
+		goto ok;
 
 	if (syslog_action_restricted(type)) {
 		if (capable(CAP_SYSLOG))
-			return 0;
+			goto ok;
 		/*
 		 * For historical reasons, accept CAP_SYS_ADMIN too, with
 		 * a warning.
@@ -492,10 +492,11 @@ static int check_syslog_permissions(int type, bool from_file)
 				     "CAP_SYS_ADMIN but no CAP_SYSLOG "
 				     "(deprecated).\n",
 				 current->comm, task_pid_nr(current));
-			return 0;
+			goto ok;
 		}
 		return -EPERM;
 	}
+ok:
 	return security_syslog(type);
 }
 
@@ -1221,10 +1222,6 @@ int do_syslog(int type, char __user *buf, int len, bool from_file)
 	if (error)
 		goto out;
 
-	error = security_syslog(type);
-	if (error)
-		return error;
-
 	switch (type) {
 	case SYSLOG_ACTION_CLOSE:	/* Close log */
 		break;
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184460 — [PATCH 3.16.y-ckt 170/185] ACPI / init: Switch over platform to the ACPI mode later

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 170/185] ACPI / init: Switch over platform to the ACPI mode later
Message-ID<pMr19-36Z-63@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: "Rafael J. Wysocki" <rafael.j.wysocki@intel.com>

commit b064a8fa77dfead647564c46ac8fc5b13bd1ab73 upstream.

Commit 73f7d1ca3263 "ACPI / init: Run acpi_early_init() before
timekeeping_init()" moved the ACPI subsystem initialization,
including the ACPI mode enabling, to an earlier point in the
initialization sequence, to allow the timekeeping subsystem
use ACPI early.  Unfortunately, that resulted in boot regressions
on some systems and the early ACPI initialization was moved toward
its original position in the kernel initialization code by commit
c4e1acbb35e4 "ACPI / init: Invoke early ACPI initialization later".

However, that turns out to be insufficient, as boot is still broken
on the Tyan S8812 mainboard.

To fix that issue, split the ACPI early initialization code into
two pieces so the majority of it still located in acpi_early_init()
and the part switching over the platform into the ACPI mode goes into
a new function, acpi_subsystem_init(), executed at the original early
ACPI initialization spot.

That fixes the Tyan S8812 boot problem, but still allows ACPI
tables to be loaded earlier which is useful to the EFI code in
efi_enter_virtual_mode().

Link: https://bugzilla.kernel.org/show_bug.cgi?id=97141
Fixes: 73f7d1ca3263 "ACPI / init: Run acpi_early_init() before timekeeping_init()"
Reported-and-tested-by: Marius Tolzmann <tolzmann@molgen.mpg.de>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Acked-by: Toshi Kani <toshi.kani@hp.com>
Reviewed-by: Hanjun Guo <hanjun.guo@linaro.org>
Reviewed-by: Lee, Chun-Yi <jlee@suse.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/acpi/bus.c   | 56 ++++++++++++++++++++++++++++++++++++++--------------
 include/linux/acpi.h |  2 ++
 init/main.c          |  1 +
 3 files changed, 44 insertions(+), 15 deletions(-)

diff --git a/drivers/acpi/bus.c b/drivers/acpi/bus.c
index c5bc8cfe09fa..60a38349f297 100644
--- a/drivers/acpi/bus.c
+++ b/drivers/acpi/bus.c
@@ -480,6 +480,16 @@ static int __init acpi_bus_init_irq(void)
 u8 acpi_gbl_permanent_mmap;
 
 
+/**
+ * acpi_early_init - Initialize ACPICA and populate the ACPI namespace.
+ *
+ * The ACPI tables are accessible after this, but the handling of events has not
+ * been initialized and the global lock is not available yet, so AML should not
+ * be executed at this point.
+ *
+ * Doing this before switching the EFI runtime services to virtual mode allows
+ * the EfiBootServices memory to be freed slightly earlier on boot.
+ */
 void __init acpi_early_init(void)
 {
 	acpi_status status;
@@ -543,26 +553,42 @@ void __init acpi_early_init(void)
 		acpi_gbl_FADT.sci_interrupt = acpi_sci_override_gsi;
 	}
 #endif
+	return;
+
+ error0:
+	disable_acpi();
+}
+
+/**
+ * acpi_subsystem_init - Finalize the early initialization of ACPI.
+ *
+ * Switch over the platform to the ACPI mode (if possible), initialize the
+ * handling of ACPI events, install the interrupt and global lock handlers.
+ *
+ * Doing this too early is generally unsafe, but at the same time it needs to be
+ * done before all things that really depend on ACPI.  The right spot appears to
+ * be before finalizing the EFI initialization.
+ */
+void __init acpi_subsystem_init(void)
+{
+	acpi_status status;
+
+	if (acpi_disabled)
+		return;
 
 	status = acpi_enable_subsystem(~ACPI_NO_ACPI_ENABLE);
 	if (ACPI_FAILURE(status)) {
 		printk(KERN_ERR PREFIX "Unable to enable ACPI\n");
-		goto error0;
+		disable_acpi();
+	} else {
+		/*
+		 * If the system is using ACPI then we can be reasonably
+		 * confident that any regulators are managed by the firmware
+		 * so tell the regulator core it has everything it needs to
+		 * know.
+		 */
+		regulator_has_full_constraints();
 	}
-
-	/*
-	 * If the system is using ACPI then we can be reasonably
-	 * confident that any regulators are managed by the firmware
-	 * so tell the regulator core it has everything it needs to
-	 * know.
-	 */
-	regulator_has_full_constraints();
-
-	return;
-
-      error0:
-	disable_acpi();
-	return;
 }
 
 static int __init acpi_bus_init(void)
diff --git a/include/linux/acpi.h b/include/linux/acpi.h
index fa91beba3cd0..ef152461bd46 100644
--- a/include/linux/acpi.h
+++ b/include/linux/acpi.h
@@ -406,6 +406,7 @@ extern acpi_status acpi_pci_osc_control_set(acpi_handle handle,
 #define ACPI_OST_SC_INSERT_NOT_SUPPORTED	0x82
 
 extern void acpi_early_init(void);
+extern void acpi_subsystem_init(void);
 
 extern int acpi_nvs_register(__u64 start, __u64 size);
 
@@ -440,6 +441,7 @@ static inline const char *acpi_dev_name(struct acpi_device *adev)
 }
 
 static inline void acpi_early_init(void) { }
+static inline void acpi_subsystem_init(void) { }
 
 static inline int early_acpi_boot_init(void)
 {
diff --git a/init/main.c b/init/main.c
index ed5f48edc7a8..44af5b583cf4 100644
--- a/init/main.c
+++ b/init/main.c
@@ -666,6 +666,7 @@ asmlinkage __visible void __init start_kernel(void)
 
 	check_bugs();
 
+	acpi_subsystem_init();
 	sfi_init_late();
 
 	if (efi_enabled(EFI_RUNTIME_SERVICES)) {
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1184463 — [PATCH 3.16.y-ckt 020/185] mtd: fix: avoid race condition when accessing mtd->usecount

FromLuis Henriques <luis.henriques@canonical.com>
Date2015-07-15 11:20 +0200
Subject[PATCH 3.16.y-ckt 020/185] mtd: fix: avoid race condition when accessing mtd->usecount
Message-ID<pMr19-36Z-69@gated-at.bofh.it>
In reply to#1184435
3.16.7-ckt15 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Brian Norris <computersforpeace@gmail.com>

commit 073db4a51ee43ccb827f54a4261c0583b028d5ab upstream.

On A MIPS 32-cores machine a BUG_ON was triggered because some acesses to
mtd->usecount were done without taking mtd_table_mutex.
kernel: Call Trace:
kernel: [<ffffffff80401818>] __put_mtd_device+0x20/0x50
kernel: [<ffffffff804086f4>] blktrans_release+0x8c/0xd8
kernel: [<ffffffff802577e0>] __blkdev_put+0x1a8/0x200
kernel: [<ffffffff802579a4>] blkdev_close+0x1c/0x30
kernel: [<ffffffff8022006c>] __fput+0xac/0x250
kernel: [<ffffffff80171208>] task_work_run+0xd8/0x120
kernel: [<ffffffff8012c23c>] work_notifysig+0x10/0x18
kernel:
kernel:
        Code: 2442ffff  ac8202d8  000217fe <00020336> dc820128  10400003
               00000000  0040f809  00000000
kernel: ---[ end trace 080fbb4579b47a73 ]---

Fixed by taking the mutex in blktrans_open and blktrans_release.

Note that this locking is already suggested in
include/linux/mtd/blktrans.h:

struct mtd_blktrans_ops {
...
	/* Called with mtd_table_mutex held; no race with add/remove */
	int (*open)(struct mtd_blktrans_dev *dev);
	void (*release)(struct mtd_blktrans_dev *dev);
...
};

But we weren't following it.

Originally reported by (and patched by) Zhang and Giuseppe,
independently. Improved and rewritten.

Reported-by: Zhang Xingcai <zhangxingcai@huawei.com>
Reported-by: Giuseppe Cantavenera <giuseppe.cantavenera.ext@nokia.com>
Tested-by: Giuseppe Cantavenera <giuseppe.cantavenera.ext@nokia.com>
Acked-by: Alexander Sverdlin <alexander.sverdlin@nokia.com>
Signed-off-by: Brian Norris <computersforpeace@gmail.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/mtd/mtd_blkdevs.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/mtd/mtd_blkdevs.c b/drivers/mtd/mtd_blkdevs.c
index 43e30992a369..7266a318628c 100644
--- a/drivers/mtd/mtd_blkdevs.c
+++ b/drivers/mtd/mtd_blkdevs.c
@@ -200,6 +200,7 @@ static int blktrans_open(struct block_device *bdev, fmode_t mode)
 		return -ERESTARTSYS; /* FIXME: busy loop! -arnd*/
 
 	mutex_lock(&dev->lock);
+	mutex_lock(&mtd_table_mutex);
 
 	if (dev->open)
 		goto unlock;
@@ -223,6 +224,7 @@ static int blktrans_open(struct block_device *bdev, fmode_t mode)
 
 unlock:
 	dev->open++;
+	mutex_unlock(&mtd_table_mutex);
 	mutex_unlock(&dev->lock);
 	blktrans_dev_put(dev);
 	return ret;
@@ -233,6 +235,7 @@ error_release:
 error_put:
 	module_put(dev->tr->owner);
 	kref_put(&dev->ref, blktrans_dev_release);
+	mutex_unlock(&mtd_table_mutex);
 	mutex_unlock(&dev->lock);
 	blktrans_dev_put(dev);
 	return ret;
@@ -246,6 +249,7 @@ static void blktrans_release(struct gendisk *disk, fmode_t mode)
 		return;
 
 	mutex_lock(&dev->lock);
+	mutex_lock(&mtd_table_mutex);
 
 	if (--dev->open)
 		goto unlock;
@@ -259,6 +263,7 @@ static void blktrans_release(struct gendisk *disk, fmode_t mode)
 		__put_mtd_device(dev->mtd);
 	}
 unlock:
+	mutex_unlock(&mtd_table_mutex);
 	mutex_unlock(&dev->lock);
 	blktrans_dev_put(dev);
 }
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


Page 1 of 10  [1] 2 3 … 10  Next page →

Back to top | Article view | linux.kernel


csiph-web