Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1224789 > unrolled thread

[PATCH 3.4 000/146] 3.4.109-rc1 review

Started bylizf@kernel.org
First post2015-09-15 11:10 +0200
Last post2015-09-18 06:10 +0200
Articles 20 on this page of 139 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.4 000/146] 3.4.109-rc1 review lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 047/146] IB/mlx4: Fix WQE LSO segment calculation lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 051/146] memstick: mspro_block: add missing curly braces lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 022/146] btrfs: don't accept bare namespace as a valid xattr lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 054/146] nfs: fix high load average due to callback thread sleeping lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 030/146] selinux/nlmsg: add XFRM_MSG_GETSPDINFO lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 039/146] selinux/nlmsg: add XFRM_MSG_MAPPING lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 035/146] MIPS: Hibernate: flush TLB entries earlier lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 011/146] drm/radeon: fix doublescan modes (v2) lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 037/146] selinux/nlmsg: add XFRM_MSG_REPORT lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 020/146] Drivers: hv: vmbus: Don't wait after requesting offers lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 014/146] cdc-wdm: fix endianness bug in debug statements lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 043/146] ACPICA: Utilities: split IO address types from data type models. lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 078/146] nilfs2: fix sanity check of btree level in nilfs_btree_root_broken() lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 009/146] pinctrl: remove doc mention of the enable/disable API lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 003/146] Drivers: hv: vmbus: Fix a bug in the error path in vmbus_open() lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 004/146] e1000: add dummy allocator to fix race condition between mtu change and netpoll lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 025/146] ASoC: cs4271: Increase delay time after reset lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 010/146] pinctrl: fix example .get_group_pins implementation signature lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 075/146] xen/console: Update console event channel on resume lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 046/146] IB/core: disallow registering 0-sized memory region lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 065/146] serial: of-serial: Remove device_type = "serial" registration lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 002/146] Bluetooth: ath3k: Add support Atheros AR5B195 combo Mini PCIe card lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 006/146] usb: musb: core: fix TX/RX endpoint order lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 049/146] firmware/ihex2fw.c: restore missing default in switch statement lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 064/146] serial: xilinx: Use platform_get_irq to get irq description structure lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 031/146] selinux/nlmsg: add XFRM_MSG_[NEW|GET]SADINFO lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 062/146] 3w-xxxx: fix command completion race lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 023/146] ARM: 8320/1: fix integer overflow in ELF_ET_DYN_BASE lizf@kernel.org - 2015-09-15 11:10 +0200
    [PATCH 3.4 131/146] ring-buffer-benchmark: Fix the wrong sched_priority of producer lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 141/146] block: fix ext_dev_lock lockdep report lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 083/146] USB: cp210x: add ID for KCF Technologies PRN device lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 111/146] x86/mce: Fix MCE severity messages lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 136/146] x86, kvm: use kernel_fpu_begin/end() in kvm_load/put_guest_fpu() lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 143/146] pipe: iovec: Fix memory corruption when retrying atomic copy as non-atomic lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 146/146] ipv6: add check for blackhole or prohibited entry in rt6_redire lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 117/146] USB: serial: ftdi_sio: Add support for a Motion Tracker Development Board lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 088/146] xhci: fix isoc endpoint dequeue from advancing too far on transaction error lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 104/146] ALSA: hda - Add Conexant codecs CX20721, CX20722, CX20723 and CX20724 lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 084/146] USB: pl2303: Remove support for Samsung I330 lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 106/146] sd: Disable support for 256 byte/sector disks lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 127/146] MIPS: Fix enabling of DEBUG_STACKOVERFLOW lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 079/146] ocfs2: dlm: fix race between purge and get lock resource lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 126/146] USB: cp210x: add ID for HubZ dual ZigBee and Z-Wave dongle lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 133/146] udf: Check length of extended attributes and allocation descriptors lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 128/146] bridge: use _bh spinlock variant for br_fdb_update to avoid lockup lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 119/146] ozwpan: divide-by-zero leading to panic lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 129/146] bridge: disable softirqs around br_fdb_update to avoid lockup lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 130/146] bridge: fix multicast router rlist endless loop lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 090/146] xhci: gracefully handle xhci_irq dead device lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 116/146] target/pscsi: Don't leak scsi_host if hba is VIRTUAL_HOST lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 144/146] sched: Queue RT tasks to head when prio drops lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 115/146] d_walk() might skip too much lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 125/146] ALSA: usb-audio: add MAYA44 USB+ mixer control names lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 081/146] libata: Ignore spurious PHY event on LPM policy change lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 100/146] ASoC: wm8960: fix "RINPUT3" audio route error lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 121/146] drm/i915: Don't skip request retirement if the active list is empty lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 092/146] ahci: un-staticize ahci_dev_classify lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 138/146] ipmi: fix timeout calculation when bmc is disconnected lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 132/146] tracing: Have filter check for balanced ops lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 137/146] x86, kvm: fix kvm's usage of kernel_fpu_begin/end() lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 101/146] ASoC: wm8994: correct BCLK DIV 348 to 384 lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 140/146] bridge: superfluous skb->nfct check in br_nf_dev_queue_xmit lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 145/146] udp: fix behavior of wrong checksums lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 097/146] ipvs: fix memory leak in ip_vs_ctl.c lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 135/146] ipv4: Missing sk_nulls_node_init() in ping_unhash(). lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 124/146] ALSA: hda/realtek - Add a fixup for another Acer Aspire 9420 lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 142/146] NET: ROSE: Don't dereference NULL neighbour pointer. lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 096/146] ext4: check for zero length extent explicitly lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 108/146] crypto: s390/ghash - Fix incorrect ghash icv buffer handling. lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 086/146] nfsd: fix the check for confirmed openowner in nfs4_preprocess_stateid_op lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 134/146] md: use kzalloc() when bitmap is disabled lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 099/146] KVM: MMU: fix CR4.SMEP=1, CR0.WP=0 with shadow pages lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 112/146] x86: bpf_jit: fix compilation of large bpf programs lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 139/146] net: socket: Fix the wrong returns for recvmsg and sendmsg lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 123/146] Input: elantech - fix detection of touchpads where the revision matches a known rate lizf@kernel.org - 2015-09-15 11:20 +0200
    [PATCH 3.4 110/146] ARM: dts: imx27: only map 4 Kbyte for fec registers lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 102/146] Input: elantech - fix semi-mt protocol for v3 HW lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 107/146] xen/events: don't bind non-percpu VIRQs with percpu chip lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 089/146] xhci: Solve full event ring by increasing TRBS_PER_SEGMENT to 256 lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 122/146] vfs: read file_handle only once in handle_to_path lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 087/146] md/raid5: don't record new size if resize_stripes fails. lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 094/146] ARM: net: delegate filter to kernel interpreter when imm_offset() return value can't fit into 12bits. lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 109/146] bridge: fix parsing of MLDv2 reports lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 093/146] ahci: avoton port-disable reset-quirk lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 091/146] usb-storage: Add NO_WP_DETECT quirk for Lacie 059f:0651 devices lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 113/146] lguest: fix out-by-one error in address checking. lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 114/146] fs, omfs: add NULL terminator in the end up the token list lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 103/146] powerpc: Align TOC to 256 bytes lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 098/146] mac80211: move WEP tailroom size check lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 095/146] drm/radeon: fix VM_CONTEXT*_PAGE_TABLE_END_ADDR handling lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 118/146] ozwpan: Use proper check to prevent heap overflow lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 105/146] mmc: atmel-mci: fix bad variable type for clkdiv lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 120/146] ozwpan: unchecked signed subtraction leads to DoS lizf@kernel.org - 2015-09-15 11:30 +0200
    [PATCH 3.4 085/146] USB: visor: Match I330 phone more precisely lizf@kernel.org - 2015-09-15 11:40 +0200
    [PATCH 3.4 067/146] ALSA: emu10k1: Emu10k2 32 bit DMA mode lizf@kernel.org - 2015-09-15 11:40 +0200
    [PATCH 3.4 082/146] rtlwifi: rtl8192cu: Fix kernel deadlock lizf@kernel.org - 2015-09-15 11:40 +0200
    [PATCH 3.4 070/146] ARM: pxa: pxa_cplds: add lubbock and mainstone IO lizf@kernel.org - 2015-09-15 11:40 +0200
    [PATCH 3.4 069/146] ext4: move check under lock scope to close a race. lizf@kernel.org - 2015-09-15 11:40 +0200
    [PATCH 3.4 073/146] mmc: core: add missing pm event in mmc_pm_notify to fix hib restore lizf@kernel.org - 2015-09-15 11:40 +0200
    [PATCH 3.4 071/146] ARM: pxa: mainstone: use new pxa_cplds driver lizf@kernel.org - 2015-09-15 11:40 +0200
    [PATCH 3.4 077/146] mm/memory-failure: call shake_page() when error hits thp tail page lizf@kernel.org - 2015-09-15 11:40 +0200
    [PATCH 3.4 074/146] RDMA/CMA: Canonize IPv4 on IPV6 sockets properly lizf@kernel.org - 2015-09-15 11:40 +0200
    [PATCH 3.4 072/146] ARM: pxa: lubbock: use new pxa_cplds driver lizf@kernel.org - 2015-09-15 11:40 +0200
    [PATCH 3.4 080/146] libata: Add helper to determine when PHY events should be ignored lizf@kernel.org - 2015-09-15 11:40 +0200
    [PATCH 3.4 076/146] xen/events: Set irq_info->evtchn before binding the channel to CPU in __startup_pirq() lizf@kernel.org - 2015-09-15 11:40 +0200
    [PATCH 3.4 066/146] ALSA: emux: Fix mutex deadlock in OSS emulation lizf@kernel.org - 2015-09-15 11:40 +0200
    [PATCH 3.4 053/146] nfs: don't call blocking operations while !TASK_RUNNING lizf@kernel.org - 2015-09-15 11:50 +0200
    [PATCH 3.4 063/146] 3w-9xxx: fix command completion race lizf@kernel.org - 2015-09-15 11:50 +0200
    [PATCH 3.4 061/146] 3w-sas: fix command completion race lizf@kernel.org - 2015-09-15 11:50 +0200
    [PATCH 3.4 042/146] powerpc/perf: Cap 64bit userspace backtraces to PERF_MAX_STACK_DEPTH lizf@kernel.org - 2015-09-15 11:50 +0200
    [PATCH 3.4 044/146] fs/binfmt_elf.c: fix bug in loading of PIE binaries lizf@kernel.org - 2015-09-15 11:50 +0200
    [PATCH 3.4 050/146] ptrace: fix race between ptrace_resume() and wait_task_stopped() lizf@kernel.org - 2015-09-15 11:50 +0200
    [PATCH 3.4 040/146] s390/hibernate: fix save and restore of kernel text section lizf@kernel.org - 2015-09-15 11:50 +0200
    [PATCH 3.4 045/146] dm crypt: fix deadlock when async crypto algorithm returns -EBUSY lizf@kernel.org - 2015-09-15 11:50 +0200
    [PATCH 3.4 055/146] RCU pathwalk breakage when running into a symlink overmounting something lizf@kernel.org - 2015-09-15 11:50 +0200
    [PATCH 3.4 057/146] ALSA: emu10k1: Fix card shortname string buffer overflow lizf@kernel.org - 2015-09-15 11:50 +0200
    [PATCH 3.4 038/146] selinux/nlmsg: add XFRM_MSG_MIGRATE lizf@kernel.org - 2015-09-15 11:50 +0200
    [PATCH 3.4 056/146] ALSA: hda - Fix mute-LED fixed mode lizf@kernel.org - 2015-09-15 11:50 +0200
    [PATCH 3.4 012/146] usb: common: otg-fsm: only signal connect after switching to peripheral lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 028/146] Input: elantech - fix absolute mode setting on some ASUS laptops lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 005/146] KVM: s390: Zero out current VMDB of STSI before including level3 data. lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 029/146] RDS: Documentation: Document AF_RDS, PF_RDS and SOL_RDS correctly. lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 019/146] C6x: time: Ensure consistency in __init lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 033/146] scsi: storvsc: Fix a bug in copy_from_bounce_buffer() lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 036/146] powerpc: Fix missing L2 cache size in /sys/devices/system/cpu lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 026/146] ext4: make fsync to sync parent dir in no-journal for real this time lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 018/146] UBI: fix check for "too many bytes" lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 021/146] Btrfs: fix log tree corruption when fs mounted with -o discard lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 024/146] rtlwifi: rtl8192cu: Add new USB ID lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 015/146] staging: panel: fix lcd type lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 016/146] UBI: fix out of bounds write lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 008/146] compal-laptop: Check return value of power_supply_register lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 007/146] pinctrl: remove maxpin from documentation lizf@kernel.org - 2015-09-15 12:00 +0200
    [PATCH 3.4 001/146] ipv6: add check for blackhole or prohibited entry in rt6_redire lizf@kernel.org - 2015-09-15 12:10 +0200
    Re: [PATCH 3.4 000/146] 3.4.109-rc1 review Guenter Roeck <linux@roeck-us.net> - 2015-09-15 16:30 +0200
      Re: [PATCH 3.4 000/146] 3.4.109-rc1 review Zefan Li <lizefan@huawei.com> - 2015-09-18 03:50 +0200
        Re: [PATCH 3.4 000/146] 3.4.109-rc1 review Zefan Li <lizefan@huawei.com> - 2015-09-18 04:50 +0200
        Re: [PATCH 3.4 000/146] 3.4.109-rc1 review Guenter Roeck <linux@roeck-us.net> - 2015-09-18 06:10 +0200

Page 4 of 7 — ← Prev page 1 2 3 [4] 5 6 7  Next page →


#1224852 — [PATCH 3.4 137/146] x86, kvm: fix kvm's usage of kernel_fpu_begin/end()

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 137/146] x86, kvm: fix kvm's usage of kernel_fpu_begin/end()
Message-ID<q8Uzb-u1-79@gated-at.bofh.it>
In reply to#1224789
From: Suresh Siddha <suresh.b.siddha@intel.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit b1a74bf8212367be2b1d6685c11a84e056eaaaf1 upstream.

Preemption is disabled between kernel_fpu_begin/end() and as such
it is not a good idea to use these routines in kvm_load/put_guest_fpu()
which can be very far apart.

kvm_load/put_guest_fpu() routines are already called with
preemption disabled and KVM already uses the preempt notifier to save
the guest fpu state using kvm_put_guest_fpu().

So introduce __kernel_fpu_begin/end() routines which don't touch
preemption and use them instead of kernel_fpu_begin/end()
for KVM's use model of saving/restoring guest FPU state.

Also with this change (and with eagerFPU model), fix the host cr0.TS vm-exit
state in the case of VMX. For eagerFPU case, host cr0.TS is always clear.
So no need to worry about it. For the traditional lazyFPU restore case,
change the cr0.TS bit for the host state during vm-exit to be always clear
and cr0.TS bit is set in the __vmx_load_host_state() when the FPU
(guest FPU or the host task's FPU) state is not active. This ensures
that the host/guest FPU state is properly saved, restored
during context-switch and with interrupts (using irq_fpu_usable()) not
stomping on the active FPU state.

Signed-off-by: Suresh Siddha <suresh.b.siddha@intel.com>
Link: http://lkml.kernel.org/r/1348164109.26695.338.camel@sbsiddha-desk.sc.intel.com
Cc: Avi Kivity <avi@redhat.com>
Signed-off-by: H. Peter Anvin <hpa@linux.intel.com>
Signed-off-by: Zefan Li <lizefan@huawei.com>
[xr: Backported to 3.4: Adjust context]
Signed-off-by: Rui Xiang <rui.xiang@huawei.com>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 arch/x86/include/asm/i387.h | 28 ++++++++++++++++++++++++++--
 arch/x86/kernel/i387.c      | 13 +++++--------
 arch/x86/kvm/vmx.c          | 10 +++++++---
 arch/x86/kvm/x86.c          |  4 ++--
 4 files changed, 40 insertions(+), 15 deletions(-)

diff --git a/arch/x86/include/asm/i387.h b/arch/x86/include/asm/i387.h
index 257d9cc..1262fb6 100644
--- a/arch/x86/include/asm/i387.h
+++ b/arch/x86/include/asm/i387.h
@@ -23,8 +23,32 @@ extern int dump_fpu(struct pt_regs *, struct user_i387_struct *);
 extern void math_state_restore(void);
 
 extern bool irq_fpu_usable(void);
-extern void kernel_fpu_begin(void);
-extern void kernel_fpu_end(void);
+
+/*
+ * Careful: __kernel_fpu_begin/end() must be called with preempt disabled
+ * and they don't touch the preempt state on their own.
+ * If you enable preemption after __kernel_fpu_begin(), preempt notifier
+ * should call the __kernel_fpu_end() to prevent the kernel/user FPU
+ * state from getting corrupted. KVM for example uses this model.
+ *
+ * All other cases use kernel_fpu_begin/end() which disable preemption
+ * during kernel FPU usage.
+ */
+extern void __kernel_fpu_begin(void);
+extern void __kernel_fpu_end(void);
+
+static inline void kernel_fpu_begin(void)
+{
+	WARN_ON_ONCE(!irq_fpu_usable());
+	preempt_disable();
+	__kernel_fpu_begin();
+}
+
+static inline void kernel_fpu_end(void)
+{
+	__kernel_fpu_end();
+	preempt_enable();
+}
 
 /*
  * Some instructions like VIA's padlock instructions generate a spurious
diff --git a/arch/x86/kernel/i387.c b/arch/x86/kernel/i387.c
index 6610e81..7aa728d 100644
--- a/arch/x86/kernel/i387.c
+++ b/arch/x86/kernel/i387.c
@@ -77,29 +77,26 @@ bool irq_fpu_usable(void)
 }
 EXPORT_SYMBOL(irq_fpu_usable);
 
-void kernel_fpu_begin(void)
+void __kernel_fpu_begin(void)
 {
 	struct task_struct *me = current;
 
-	WARN_ON_ONCE(!irq_fpu_usable());
-	preempt_disable();
 	if (__thread_has_fpu(me)) {
 		__save_init_fpu(me);
 		__thread_clear_has_fpu(me);
-		/* We do 'stts()' in kernel_fpu_end() */
+		/* We do 'stts()' in __kernel_fpu_end() */
 	} else {
 		percpu_write(fpu_owner_task, NULL);
 		clts();
 	}
 }
-EXPORT_SYMBOL(kernel_fpu_begin);
+EXPORT_SYMBOL(__kernel_fpu_begin);
 
-void kernel_fpu_end(void)
+void __kernel_fpu_end(void)
 {
 	stts();
-	preempt_enable();
 }
-EXPORT_SYMBOL(kernel_fpu_end);
+EXPORT_SYMBOL(__kernel_fpu_end);
 
 void unlazy_fpu(struct task_struct *tsk)
 {
diff --git a/arch/x86/kvm/vmx.c b/arch/x86/kvm/vmx.c
index 2eb4e5a..4ad0d71 100644
--- a/arch/x86/kvm/vmx.c
+++ b/arch/x86/kvm/vmx.c
@@ -1455,8 +1455,12 @@ static void __vmx_load_host_state(struct vcpu_vmx *vmx)
 #ifdef CONFIG_X86_64
 	wrmsrl(MSR_KERNEL_GS_BASE, vmx->msr_host_kernel_gs_base);
 #endif
-	if (user_has_fpu())
-		clts();
+	/*
+	 * If the FPU is not active (through the host task or
+	 * the guest vcpu), then restore the cr0.TS bit.
+	 */
+	if (!user_has_fpu() && !vmx->vcpu.guest_fpu_loaded)
+		stts();
 	load_gdt(&__get_cpu_var(host_gdt));
 }
 
@@ -3633,7 +3637,7 @@ static void vmx_set_constant_host_state(struct vcpu_vmx *vmx)
 	struct desc_ptr dt;
 	unsigned long cr4;
 
-	vmcs_writel(HOST_CR0, read_cr0() | X86_CR0_TS);  /* 22.2.3 */
+	vmcs_writel(HOST_CR0, read_cr0() & ~X86_CR0_TS);  /* 22.2.3 */
 	vmcs_writel(HOST_CR3, read_cr3());  /* 22.2.3  FIXME: shadow tables */
 
 	/* Save the most likely value for this task's CR4 in the VMCS. */
diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index 55ee4ca..4ad2b7b 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -5907,7 +5907,7 @@ void kvm_load_guest_fpu(struct kvm_vcpu *vcpu)
 	 */
 	kvm_put_guest_xcr0(vcpu);
 	vcpu->guest_fpu_loaded = 1;
-	kernel_fpu_begin();
+	__kernel_fpu_begin();
 	fpu_restore_checking(&vcpu->arch.guest_fpu);
 	trace_kvm_fpu(1);
 }
@@ -5921,7 +5921,7 @@ void kvm_put_guest_fpu(struct kvm_vcpu *vcpu)
 
 	vcpu->guest_fpu_loaded = 0;
 	fpu_save_init(&vcpu->arch.guest_fpu);
-	kernel_fpu_end();
+	__kernel_fpu_end();
 	++vcpu->stat.fpu_reload;
 	kvm_make_request(KVM_REQ_DEACTIVATE_FPU, vcpu);
 	trace_kvm_fpu(0);
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224853 — [PATCH 3.4 101/146] ASoC: wm8994: correct BCLK DIV 348 to 384

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 101/146] ASoC: wm8994: correct BCLK DIV 348 to 384
Message-ID<q8Uzb-u1-89@gated-at.bofh.it>
In reply to#1224789
From: Zidan Wang <zidan.wang@freescale.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit 17fc2e0a3db11889e942c5ab15a1fcb876638f25 upstream.

According to the RM of wm8958, BCLK DIV 348 doesn't exist, correct it
to 384.

Signed-off-by: Zidan Wang <zidan.wang@freescale.com>
Acked-by: Charles Keepax <ckeepax@opensource.wolfsonmicro.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 sound/soc/codecs/wm8994.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sound/soc/codecs/wm8994.c b/sound/soc/codecs/wm8994.c
index d9924d7..c93c573 100644
--- a/sound/soc/codecs/wm8994.c
+++ b/sound/soc/codecs/wm8994.c
@@ -2636,7 +2636,7 @@ static struct {
 };
 
 static int fs_ratios[] = {
-	64, 128, 192, 256, 348, 512, 768, 1024, 1408, 1536
+	64, 128, 192, 256, 384, 512, 768, 1024, 1408, 1536
 };
 
 static int bclk_divs[] = {
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224854 — [PATCH 3.4 140/146] bridge: superfluous skb->nfct check in br_nf_dev_queue_xmit

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 140/146] bridge: superfluous skb->nfct check in br_nf_dev_queue_xmit
Message-ID<q8Uzc-u1-91@gated-at.bofh.it>
In reply to#1224789
From: Vasily Averin <vvs@parallels.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit aff09ce303f83bd370772349238482ae422a2341 upstream.

Currently bridge can silently drop ipv4 fragments.
If node have loaded nf_defrag_ipv4 module but have no nf_conntrack_ipv4,
br_nf_pre_routing defragments incoming ipv4 fragments
but nfct check in br_nf_dev_queue_xmit does not allow re-fragment combined
packet back, and therefore it is dropped in br_dev_queue_push_xmit without
incrementing of any failcounters

It seems the only way to hit the ip_fragment code in the bridge xmit
path is to have a fragment list whose reassembled fragments go over
the mtu. This only happens if nf_defrag is enabled. Thanks to
Florian Westphal for providing feedback to clarify this.

Defragmentation ipv4 is required not only in conntracks but at least in
TPROXY target and socket match, therefore #ifdef is changed from
NF_CONNTRACK_IPV4 to NF_DEFRAG_IPV4

Signed-off-by: Vasily Averin <vvs@openvz.org>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Cc: Kirill Tkhai <ktkhai@odin.com>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 net/bridge/br_netfilter.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/net/bridge/br_netfilter.c b/net/bridge/br_netfilter.c
index e54ef82..5ba4248 100644
--- a/net/bridge/br_netfilter.c
+++ b/net/bridge/br_netfilter.c
@@ -818,12 +818,12 @@ static unsigned int br_nf_forward_arp(unsigned int hook, struct sk_buff *skb,
 	return NF_STOLEN;
 }
 
-#if IS_ENABLED(CONFIG_NF_CONNTRACK_IPV4)
+#if IS_ENABLED(CONFIG_NF_DEFRAG_IPV4)
 static int br_nf_dev_queue_xmit(struct sk_buff *skb)
 {
 	int ret;
 
-	if (skb->nfct != NULL && skb->protocol == htons(ETH_P_IP) &&
+	if (skb->protocol == htons(ETH_P_IP) &&
 	    skb->len + nf_bridge_mtu_reduction(skb) > skb->dev->mtu &&
 	    !skb_is_gso(skb)) {
 		if (br_parse_ip_options(skb))
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224855 — [PATCH 3.4 145/146] udp: fix behavior of wrong checksums

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 145/146] udp: fix behavior of wrong checksums
Message-ID<q8Uzb-u1-81@gated-at.bofh.it>
In reply to#1224789
From: Eric Dumazet <edumazet@google.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit beb39db59d14990e401e235faf66a6b9b31240b0 upstream.

We have two problems in UDP stack related to bogus checksums :

1) We return -EAGAIN to application even if receive queue is not empty.
   This breaks applications using edge trigger epoll()

2) Under UDP flood, we can loop forever without yielding to other
   processes, potentially hanging the host, especially on non SMP.

This patch is an attempt to make things better.

We might in the future add extra support for rt applications
wanting to better control time spent doing a recv() in a hostile
environment. For example we could validate checksums before queuing
packets in socket receive queue.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Willem de Bruijn <willemb@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 net/ipv4/udp.c | 6 ++----
 net/ipv6/udp.c | 6 ++----
 2 files changed, 4 insertions(+), 8 deletions(-)

diff --git a/net/ipv4/udp.c b/net/ipv4/udp.c
index 7949b5d..5f8c20b 100644
--- a/net/ipv4/udp.c
+++ b/net/ipv4/udp.c
@@ -1251,10 +1251,8 @@ csum_copy_err:
 		UDP_INC_STATS_USER(sock_net(sk), UDP_MIB_INERRORS, is_udplite);
 	unlock_sock_fast(sk, slow);
 
-	if (noblock)
-		return -EAGAIN;
-
-	/* starting over for a new packet */
+	/* starting over for a new packet, but check if we need to yield */
+	cond_resched();
 	msg->msg_flags &= ~MSG_TRUNC;
 	goto try_again;
 }
diff --git a/net/ipv6/udp.c b/net/ipv6/udp.c
index ef9052f..2f99b12 100644
--- a/net/ipv6/udp.c
+++ b/net/ipv6/udp.c
@@ -451,10 +451,8 @@ csum_copy_err:
 	}
 	unlock_sock_fast(sk, slow);
 
-	if (noblock)
-		return -EAGAIN;
-
-	/* starting over for a new packet */
+	/* starting over for a new packet, but check if we need to yield */
+	cond_resched();
 	msg->msg_flags &= ~MSG_TRUNC;
 	goto try_again;
 }
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224856 — [PATCH 3.4 097/146] ipvs: fix memory leak in ip_vs_ctl.c

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 097/146] ipvs: fix memory leak in ip_vs_ctl.c
Message-ID<q8Uzc-u1-93@gated-at.bofh.it>
In reply to#1224789
From: Tommi Rantala <tt.rantala@gmail.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit f30bf2a5cac6c60ab366c4bc6db913597bf4d6ab upstream.

Fix memory leak introduced in commit a0840e2e165a ("IPVS: netns,
ip_vs_ctl local vars moved to ipvs struct."):

unreferenced object 0xffff88005785b800 (size 2048):
  comm "(-localed)", pid 1434, jiffies 4294755650 (age 1421.089s)
  hex dump (first 32 bytes):
    bb 89 0b 83 ff ff ff ff b0 78 f0 4e 00 88 ff ff  .........x.N....
    04 00 00 00 a4 01 00 00 00 00 00 00 00 00 00 00  ................
  backtrace:
    [<ffffffff8262ea8e>] kmemleak_alloc+0x4e/0xb0
    [<ffffffff811fba74>] __kmalloc_track_caller+0x244/0x430
    [<ffffffff811b88a0>] kmemdup+0x20/0x50
    [<ffffffff823276b7>] ip_vs_control_net_init+0x1f7/0x510
    [<ffffffff8231d630>] __ip_vs_init+0x100/0x250
    [<ffffffff822363a1>] ops_init+0x41/0x190
    [<ffffffff82236583>] setup_net+0x93/0x150
    [<ffffffff82236cc2>] copy_net_ns+0x82/0x140
    [<ffffffff810ab13d>] create_new_namespaces+0xfd/0x190
    [<ffffffff810ab49a>] unshare_nsproxy_namespaces+0x5a/0xc0
    [<ffffffff810833e3>] SyS_unshare+0x173/0x310
    [<ffffffff8265cbd7>] system_call_fastpath+0x12/0x6f
    [<ffffffffffffffff>] 0xffffffffffffffff

Fixes: a0840e2e165a ("IPVS: netns, ip_vs_ctl local vars moved to ipvs struct.")
Signed-off-by: Tommi Rantala <tt.rantala@gmail.com>
Acked-by: Julian Anastasov <ja@ssi.bg>
Signed-off-by: Simon Horman <horms@verge.net.au>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 net/netfilter/ipvs/ip_vs_ctl.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/net/netfilter/ipvs/ip_vs_ctl.c b/net/netfilter/ipvs/ip_vs_ctl.c
index cbc5bfd..f2ed4a9 100644
--- a/net/netfilter/ipvs/ip_vs_ctl.c
+++ b/net/netfilter/ipvs/ip_vs_ctl.c
@@ -3689,6 +3689,9 @@ void __net_exit ip_vs_control_net_cleanup_sysctl(struct net *net)
 	cancel_delayed_work_sync(&ipvs->defense_work);
 	cancel_work_sync(&ipvs->defense_work.work);
 	unregister_net_sysctl_table(ipvs->sysctl_hdr);
+
+	if (!net_eq(net, &init_net))
+		kfree(ipvs->sysctl_tbl);
 }
 
 #else
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224857 — [PATCH 3.4 135/146] ipv4: Missing sk_nulls_node_init() in ping_unhash().

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 135/146] ipv4: Missing sk_nulls_node_init() in ping_unhash().
Message-ID<q8Uzb-u1-87@gated-at.bofh.it>
In reply to#1224789
From: "David S. Miller" <davem@davemloft.net>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit a134f083e79fb4c3d0a925691e732c56911b4326 upstream.

If we don't do that, then the poison value is left in the ->pprev
backlink.

This can cause crashes if we do a disconnect, followed by a connect().

Tested-by: Linus Torvalds <torvalds@linux-foundation.org>
Reported-by: Wen Xu <hotdog3645@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 net/ipv4/ping.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/net/ipv4/ping.c b/net/ipv4/ping.c
index cb90852..9f471c3 100644
--- a/net/ipv4/ping.c
+++ b/net/ipv4/ping.c
@@ -138,6 +138,7 @@ static void ping_v4_unhash(struct sock *sk)
 	if (sk_hashed(sk)) {
 		write_lock_bh(&ping_table.lock);
 		hlist_nulls_del(&sk->sk_nulls_node);
+		sk_nulls_node_init(&sk->sk_nulls_node);
 		sock_put(sk);
 		isk->inet_num = 0;
 		isk->inet_sport = 0;
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224858 — [PATCH 3.4 124/146] ALSA: hda/realtek - Add a fixup for another Acer Aspire 9420

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 124/146] ALSA: hda/realtek - Add a fixup for another Acer Aspire 9420
Message-ID<q8Uzc-u1-103@gated-at.bofh.it>
In reply to#1224789
From: Takashi Iwai <tiwai@suse.de>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit b5d724b1add6eabf3aa7276ab3454ea9f45eebd3 upstream.

Acer Aspire 9420 with ALC883 (1025:0107) needs the fixup for EAPD to
make the sound working like other Aspire models.

Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=94111
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 sound/pci/hda/patch_realtek.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index b16a37f..bf1f0ab 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -5412,6 +5412,7 @@ static const struct alc_fixup alc882_fixups[] = {
 static const struct snd_pci_quirk alc882_fixup_tbl[] = {
 	SND_PCI_QUIRK(0x1025, 0x006c, "Acer Aspire 9810", ALC883_FIXUP_ACER_EAPD),
 	SND_PCI_QUIRK(0x1025, 0x0090, "Acer Aspire", ALC883_FIXUP_ACER_EAPD),
+	SND_PCI_QUIRK(0x1025, 0x0107, "Acer Aspire", ALC883_FIXUP_ACER_EAPD),
 	SND_PCI_QUIRK(0x1025, 0x010a, "Acer Ferrari 5000", ALC883_FIXUP_ACER_EAPD),
 	SND_PCI_QUIRK(0x1025, 0x0110, "Acer Aspire", ALC883_FIXUP_ACER_EAPD),
 	SND_PCI_QUIRK(0x1025, 0x0112, "Acer Aspire 9303", ALC883_FIXUP_ACER_EAPD),
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224859 — [PATCH 3.4 142/146] NET: ROSE: Don't dereference NULL neighbour pointer.

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 142/146] NET: ROSE: Don't dereference NULL neighbour pointer.
Message-ID<q8Uzc-u1-99@gated-at.bofh.it>
In reply to#1224789
From: Ralf Baechle <ralf@linux-mips.org>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit d496f7842aada20c61e6044b3395383fa972872c upstream.

A ROSE socket doesn't necessarily always have a neighbour pointer so check
if the neighbour pointer is valid before dereferencing it.

Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
Tested-by: Bernard Pidoux <f6bvp@free.fr>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 net/rose/af_rose.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/net/rose/af_rose.c b/net/rose/af_rose.c
index bde7d69..e895636 100644
--- a/net/rose/af_rose.c
+++ b/net/rose/af_rose.c
@@ -194,7 +194,8 @@ static void rose_kill_by_device(struct net_device *dev)
 
 		if (rose->device == dev) {
 			rose_disconnect(s, ENETUNREACH, ROSE_OUT_OF_ORDER, 0);
-			rose->neighbour->use--;
+			if (rose->neighbour)
+				rose->neighbour->use--;
 			rose->device = NULL;
 		}
 	}
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224860 — [PATCH 3.4 096/146] ext4: check for zero length extent explicitly

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 096/146] ext4: check for zero length extent explicitly
Message-ID<q8Uzc-u1-101@gated-at.bofh.it>
In reply to#1224789
From: Eryu Guan <guaneryu@gmail.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit 2f974865ffdfe7b9f46a9940836c8b167342563d upstream.

The following commit introduced a bug when checking for zero length extent

5946d08 ext4: check for overlapping extents in ext4_valid_extent_entries()

Zero length extent could pass the check if lblock is zero.

Adding the explicit check for zero length back.

Signed-off-by: Eryu Guan <guaneryu@gmail.com>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 fs/ext4/extents.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/ext4/extents.c b/fs/ext4/extents.c
index bb72833..bbe09a9 100644
--- a/fs/ext4/extents.c
+++ b/fs/ext4/extents.c
@@ -320,7 +320,7 @@ static int ext4_valid_extent(struct inode *inode, struct ext4_extent *ext)
 	ext4_lblk_t lblock = le32_to_cpu(ext->ee_block);
 	ext4_lblk_t last = lblock + len - 1;
 
-	if (lblock > last)
+	if (len == 0 || lblock > last)
 		return 0;
 	return ext4_data_block_valid(EXT4_SB(inode->i_sb), block, len);
 }
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224861 — [PATCH 3.4 108/146] crypto: s390/ghash - Fix incorrect ghash icv buffer handling.

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 108/146] crypto: s390/ghash - Fix incorrect ghash icv buffer handling.
Message-ID<q8Uzc-u1-95@gated-at.bofh.it>
In reply to#1224789
From: Harald Freudenberger <freude@linux.vnet.ibm.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit a1cae34e23b1293eccbcc8ee9b39298039c3952a upstream.

Multitheaded tests showed that the icv buffer in the current ghash
implementation is not handled correctly. A move of this working ghash
buffer value to the descriptor context fixed this. Code is tested and
verified with an multithreaded application via af_alg interface.

Signed-off-by: Harald Freudenberger <freude@linux.vnet.ibm.com>
Signed-off-by: Gerald Schaefer <geraldsc@linux.vnet.ibm.com>
Reported-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
[lizf: Backported to 3.4:
 - adjust context
 - drop the change to memcpy()]
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 arch/s390/crypto/ghash_s390.c | 24 ++++++++++++------------
 1 file changed, 12 insertions(+), 12 deletions(-)

diff --git a/arch/s390/crypto/ghash_s390.c b/arch/s390/crypto/ghash_s390.c
index b1bd170..c4a954e 100644
--- a/arch/s390/crypto/ghash_s390.c
+++ b/arch/s390/crypto/ghash_s390.c
@@ -16,11 +16,12 @@
 #define GHASH_DIGEST_SIZE	16
 
 struct ghash_ctx {
-	u8 icv[16];
-	u8 key[16];
+	u8 key[GHASH_BLOCK_SIZE];
 };
 
 struct ghash_desc_ctx {
+	u8 icv[GHASH_BLOCK_SIZE];
+	u8 key[GHASH_BLOCK_SIZE];
 	u8 buffer[GHASH_BLOCK_SIZE];
 	u32 bytes;
 };
@@ -28,8 +29,10 @@ struct ghash_desc_ctx {
 static int ghash_init(struct shash_desc *desc)
 {
 	struct ghash_desc_ctx *dctx = shash_desc_ctx(desc);
+	struct ghash_ctx *ctx = crypto_shash_ctx(desc->tfm);
 
 	memset(dctx, 0, sizeof(*dctx));
+	memcpy(dctx->key, ctx->key, GHASH_BLOCK_SIZE);
 
 	return 0;
 }
@@ -45,7 +48,6 @@ static int ghash_setkey(struct crypto_shash *tfm,
 	}
 
 	memcpy(ctx->key, key, GHASH_BLOCK_SIZE);
-	memset(ctx->icv, 0, GHASH_BLOCK_SIZE);
 
 	return 0;
 }
@@ -54,7 +56,6 @@ static int ghash_update(struct shash_desc *desc,
 			 const u8 *src, unsigned int srclen)
 {
 	struct ghash_desc_ctx *dctx = shash_desc_ctx(desc);
-	struct ghash_ctx *ctx = crypto_shash_ctx(desc->tfm);
 	unsigned int n;
 	u8 *buf = dctx->buffer;
 	int ret;
@@ -70,7 +71,7 @@ static int ghash_update(struct shash_desc *desc,
 		src += n;
 
 		if (!dctx->bytes) {
-			ret = crypt_s390_kimd(KIMD_GHASH, ctx, buf,
+			ret = crypt_s390_kimd(KIMD_GHASH, dctx, buf,
 					      GHASH_BLOCK_SIZE);
 			BUG_ON(ret != GHASH_BLOCK_SIZE);
 		}
@@ -78,7 +79,7 @@ static int ghash_update(struct shash_desc *desc,
 
 	n = srclen & ~(GHASH_BLOCK_SIZE - 1);
 	if (n) {
-		ret = crypt_s390_kimd(KIMD_GHASH, ctx, src, n);
+		ret = crypt_s390_kimd(KIMD_GHASH, dctx, src, n);
 		BUG_ON(ret != n);
 		src += n;
 		srclen -= n;
@@ -92,7 +93,7 @@ static int ghash_update(struct shash_desc *desc,
 	return 0;
 }
 
-static void ghash_flush(struct ghash_ctx *ctx, struct ghash_desc_ctx *dctx)
+static int ghash_flush(struct ghash_desc_ctx *dctx)
 {
 	u8 *buf = dctx->buffer;
 	int ret;
@@ -102,19 +103,18 @@ static void ghash_flush(struct ghash_ctx *ctx, struct ghash_desc_ctx *dctx)
 
 		memset(pos, 0, dctx->bytes);
 
-		ret = crypt_s390_kimd(KIMD_GHASH, ctx, buf, GHASH_BLOCK_SIZE);
+		ret = crypt_s390_kimd(KIMD_GHASH, dctx, buf, GHASH_BLOCK_SIZE);
 		BUG_ON(ret != GHASH_BLOCK_SIZE);
-	}
 
-	dctx->bytes = 0;
+		dctx->bytes = 0;
+	}
 }
 
 static int ghash_final(struct shash_desc *desc, u8 *dst)
 {
 	struct ghash_desc_ctx *dctx = shash_desc_ctx(desc);
-	struct ghash_ctx *ctx = crypto_shash_ctx(desc->tfm);
 
-	ghash_flush(ctx, dctx);
+	ghash_flush(dctx);
 	memcpy(dst, ctx->icv, GHASH_BLOCK_SIZE);
 
 	return 0;
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224862 — [PATCH 3.4 086/146] nfsd: fix the check for confirmed openowner in nfs4_preprocess_stateid_op

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 086/146] nfsd: fix the check for confirmed openowner in nfs4_preprocess_stateid_op
Message-ID<q8Uzc-u1-105@gated-at.bofh.it>
In reply to#1224789
From: Christoph Hellwig <hch@lst.de>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit ebe9cb3bb13e7b9b281969cd279ce70834f7500f upstream.

If we find a non-confirmed openowner we jump to exit the function, but do
not set an error value.  Fix this by factoring out a helper to do the
check and properly set the error from nfsd4_validate_stateid.

Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
[lizf: adjust the changes for nfsd4_validate_stateid()]
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 fs/nfsd/nfs4state.c | 19 +++++++++++--------
 1 file changed, 11 insertions(+), 8 deletions(-)

diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c
index a4b87c6..6143a1e 100644
--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -3364,10 +3364,17 @@ static int check_stateid_generation(stateid_t *in, stateid_t *ref, bool has_sess
 	return nfserr_old_stateid;
 }
 
+static __be32 nfsd4_check_openowner_confirmed(struct nfs4_ol_stateid *ols)
+{
+	if (ols->st_stateowner->so_is_open_owner &&
+	    !(openowner(ols->st_stateowner)->oo_flags & NFS4_OO_CONFIRMED))
+		return nfserr_bad_stateid;
+	return nfs_ok;
+}
+
 __be32 nfs4_validate_stateid(struct nfs4_client *cl, stateid_t *stateid)
 {
 	struct nfs4_stid *s;
-	struct nfs4_ol_stateid *ols;
 	__be32 status;
 
 	if (STALE_STATEID(stateid))
@@ -3381,11 +3388,7 @@ __be32 nfs4_validate_stateid(struct nfs4_client *cl, stateid_t *stateid)
 		return status;
 	if (!(s->sc_type & (NFS4_OPEN_STID | NFS4_LOCK_STID)))
 		return nfs_ok;
-	ols = openlockstateid(s);
-	if (ols->st_stateowner->so_is_open_owner
-	    && !(openowner(ols->st_stateowner)->oo_flags & NFS4_OO_CONFIRMED))
-		return nfserr_bad_stateid;
-	return nfs_ok;
+	return nfsd4_check_openowner_confirmed(openlockstateid(s));
 }
 
 static __be32 nfsd4_lookup_stateid(stateid_t *stateid, unsigned char typemask, struct nfs4_stid **s)
@@ -3452,8 +3455,8 @@ nfs4_preprocess_stateid_op(struct nfsd4_compound_state *cstate,
 		status = nfs4_check_fh(current_fh, stp);
 		if (status)
 			goto out;
-		if (stp->st_stateowner->so_is_open_owner
-		    && !(openowner(stp->st_stateowner)->oo_flags & NFS4_OO_CONFIRMED))
+		status = nfsd4_check_openowner_confirmed(stp);
+		if (status)
 			goto out;
 		status = nfs4_check_openmode(stp, flags);
 		if (status)
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224863 — [PATCH 3.4 134/146] md: use kzalloc() when bitmap is disabled

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 134/146] md: use kzalloc() when bitmap is disabled
Message-ID<q8Uzd-u1-115@gated-at.bofh.it>
In reply to#1224789
From: Benjamin Randazzo <benjamin@randazzo.fr>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit b6878d9e03043695dbf3fa1caa6dfc09db225b16 upstream.

In drivers/md/md.c get_bitmap_file() uses kmalloc() for creating a
mdu_bitmap_file_t called "file".

5769         file = kmalloc(sizeof(*file), GFP_NOIO);
5770         if (!file)
5771                 return -ENOMEM;

This structure is copied to user space at the end of the function.

5786         if (err == 0 &&
5787             copy_to_user(arg, file, sizeof(*file)))
5788                 err = -EFAULT

But if bitmap is disabled only the first byte of "file" is initialized
with zero, so it's possible to read some bytes (up to 4095) of kernel
space memory from user space. This is an information leak.

5775         /* bitmap disabled, zero the first byte and copy out */
5776         if (!mddev->bitmap_info.file)
5777                 file->pathname[0] = '\0';

Signed-off-by: Benjamin Randazzo <benjamin@randazzo.fr>
Signed-off-by: NeilBrown <neilb@suse.com>
[lizf: Backported to 3.4: fix both branches]
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 drivers/md/md.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/md/md.c b/drivers/md/md.c
index 17e2f52..83dba06 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -5431,9 +5431,9 @@ static int get_bitmap_file(struct mddev * mddev, void __user * arg)
 	int err = -ENOMEM;
 
 	if (md_allow_write(mddev))
-		file = kmalloc(sizeof(*file), GFP_NOIO);
+		file = kzalloc(sizeof(*file), GFP_NOIO);
 	else
-		file = kmalloc(sizeof(*file), GFP_KERNEL);
+		file = kzalloc(sizeof(*file), GFP_KERNEL);
 
 	if (!file)
 		goto out;
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224864 — [PATCH 3.4 099/146] KVM: MMU: fix CR4.SMEP=1, CR0.WP=0 with shadow pages

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 099/146] KVM: MMU: fix CR4.SMEP=1, CR0.WP=0 with shadow pages
Message-ID<q8Uzc-u1-109@gated-at.bofh.it>
In reply to#1224789
From: Paolo Bonzini <pbonzini@redhat.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit 898761158be7682082955e3efa4ad24725305fc7 upstream.

smep_andnot_wp is initialized in kvm_init_shadow_mmu and shadow pages
should not be reused for different values of it.  Thus, it has to be
added to the mask in kvm_mmu_pte_write.

Reviewed-by: Xiao Guangrong <guangrong.xiao@linux.intel.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
[lizf: Backported to 3.4: adjust context]
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 arch/x86/kvm/mmu.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/x86/kvm/mmu.c b/arch/x86/kvm/mmu.c
index 84f4bca..2da1a8c 100644
--- a/arch/x86/kvm/mmu.c
+++ b/arch/x86/kvm/mmu.c
@@ -3658,7 +3658,7 @@ void kvm_mmu_pte_write(struct kvm_vcpu *vcpu, gpa_t gpa,
 	++vcpu->kvm->stat.mmu_pte_write;
 	kvm_mmu_audit(vcpu, AUDIT_PRE_PTE_WRITE);
 
-	mask.cr0_wp = mask.cr4_pae = mask.nxe = 1;
+	mask.cr0_wp = mask.cr4_pae = mask.nxe = mask.smep_andnot_wp = 1;
 	for_each_gfn_indirect_valid_sp(vcpu->kvm, sp, gfn, node) {
 		if (detect_write_misaligned(sp, gpa, bytes) ||
 		      detect_write_flooding(sp)) {
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224865 — [PATCH 3.4 112/146] x86: bpf_jit: fix compilation of large bpf programs

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 112/146] x86: bpf_jit: fix compilation of large bpf programs
Message-ID<q8Uzc-u1-111@gated-at.bofh.it>
In reply to#1224789
From: Alexei Starovoitov <ast@plumgrid.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit 3f7352bf21f8fd7ba3e2fcef9488756f188e12be upstream.

x86 has variable length encoding. x86 JIT compiler is trying
to pick the shortest encoding for given bpf instruction.
While doing so the jump targets are changing, so JIT is doing
multiple passes over the program. Typical program needs 3 passes.
Some very short programs converge with 2 passes. Large programs
may need 4 or 5. But specially crafted bpf programs may hit the
pass limit and if the program converges on the last iteration
the JIT compiler will be producing an image full of 'int 3' insns.
Fix this corner case by doing final iteration over bpf program.

Fixes: 0a14842f5a3c ("net: filter: Just In Time compiler for x86-64")
Reported-by: Daniel Borkmann <daniel@iogearbox.net>
Signed-off-by: Alexei Starovoitov <ast@plumgrid.com>
Tested-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Daniel Borkmann <daniel@iogearbox.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
[lizf: Backported to 3.4: adjust context]
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 arch/x86/net/bpf_jit_comp.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/arch/x86/net/bpf_jit_comp.c b/arch/x86/net/bpf_jit_comp.c
index 0597f95..95f9934 100644
--- a/arch/x86/net/bpf_jit_comp.c
+++ b/arch/x86/net/bpf_jit_comp.c
@@ -155,7 +155,12 @@ void bpf_jit_compile(struct sk_filter *fp)
 	}
 	cleanup_addr = proglen; /* epilogue address */
 
-	for (pass = 0; pass < 10; pass++) {
+	/* JITed image shrinks with every pass and the loop iterates
+	 * until the image stops shrinking. Very large bpf programs
+	 * may converge on the last pass. In such case do one more
+	 * pass to emit the final image
+	 */
+	for (pass = 0; pass < 10 || image; pass++) {
 		u8 seen_or_pass0 = (pass == 0) ? (SEEN_XREG | SEEN_DATAREF | SEEN_MEM) : seen;
 		/* no prologue/epilogue for trivial filters (RET something) */
 		proglen = 0;
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224866 — [PATCH 3.4 139/146] net: socket: Fix the wrong returns for recvmsg and sendmsg

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 139/146] net: socket: Fix the wrong returns for recvmsg and sendmsg
Message-ID<q8Uzd-u1-113@gated-at.bofh.it>
In reply to#1224789
From: Junling Zheng <zhengjunling@huawei.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


Based on 08adb7dabd4874cc5666b4490653b26534702ce0 upstream.

We found that after v3.10.73, recvmsg might return -EFAULT while -EINVAL
was expected.

We tested it through the recvmsg01 testcase come from LTP testsuit. It set
msg->msg_namelen to -1 and the recvmsg syscall returned errno 14, which is
unexpected (errno 22 is expected):

recvmsg01    4  TFAIL  :  invalid socket length ; returned -1 (expected -1),
errno 14 (expected 22)

Linux mainline has no this bug for commit 08adb7dab fixes it accidentally.
However, it is too large and complex to be backported to LTS 3.10.

Commit 281c9c36 (net: compat: Update get_compat_msghdr() to match
copy_msghdr_from_user() behaviour) made get_compat_msghdr() return
error if msg_sys->msg_namelen was negative, which changed the behaviors
of recvmsg and sendmsg syscall in a lib32 system:

Before commit 281c9c36, get_compat_msghdr() wouldn't fail and it would
return -EINVAL in move_addr_to_user() or somewhere if msg_sys->msg_namelen
was invalid and then syscall returned -EINVAL, which is correct.

And now, when msg_sys->msg_namelen is negative, get_compat_msghdr() will
fail and wants to return -EINVAL, however, the outer syscall will return
-EFAULT directly, which is unexpected.

This patch gets the return value of get_compat_msghdr() as well as
copy_msghdr_from_user(), then returns this expected value if
get_compat_msghdr() fails.

Fixes: 281c9c36 (net: compat: Update get_compat_msghdr() to match copy_msghdr_from_user() behaviour)
Signed-off-by: Junling Zheng <zhengjunling@huawei.com>
Signed-off-by: Hanbing Xu <xuhanbing@huawei.com>
Cc: Li Zefan <lizefan@huawei.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: David Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 net/socket.c | 24 ++++++++++--------------
 1 file changed, 10 insertions(+), 14 deletions(-)

diff --git a/net/socket.c b/net/socket.c
index 025f7f4..f5ce151 100644
--- a/net/socket.c
+++ b/net/socket.c
@@ -1934,14 +1934,12 @@ static int ___sys_sendmsg(struct socket *sock, struct msghdr __user *msg,
 	int err, ctl_len, iov_size, total_len;
 
 	err = -EFAULT;
-	if (MSG_CMSG_COMPAT & flags) {
-		if (get_compat_msghdr(msg_sys, msg_compat))
-			return -EFAULT;
-	} else {
+	if (MSG_CMSG_COMPAT & flags)
+		err = get_compat_msghdr(msg_sys, msg_compat);
+	else
 		err = copy_msghdr_from_user(msg_sys, msg);
-		if (err)
-			return err;
-	}
+	if (err)
+		return err;
 
 	/* do not move before msg_sys is valid */
 	err = -EMSGSIZE;
@@ -2149,14 +2147,12 @@ static int ___sys_recvmsg(struct socket *sock, struct msghdr __user *msg,
 	struct sockaddr __user *uaddr;
 	int __user *uaddr_len;
 
-	if (MSG_CMSG_COMPAT & flags) {
-		if (get_compat_msghdr(msg_sys, msg_compat))
-			return -EFAULT;
-	} else {
+	if (MSG_CMSG_COMPAT & flags)
+		err = get_compat_msghdr(msg_sys, msg_compat);
+	else
 		err = copy_msghdr_from_user(msg_sys, msg);
-		if (err)
-			return err;
-	}
+	if (err)
+		return err;
 
 	err = -EMSGSIZE;
 	if (msg_sys->msg_iovlen > UIO_MAXIOV)
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224867 — [PATCH 3.4 123/146] Input: elantech - fix detection of touchpads where the revision matches a known rate

Fromlizf@kernel.org
Date2015-09-15 11:20 +0200
Subject[PATCH 3.4 123/146] Input: elantech - fix detection of touchpads where the revision matches a known rate
Message-ID<q8Uzc-u1-107@gated-at.bofh.it>
In reply to#1224789
From: Hans de Goede <hdegoede@redhat.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit 5f0ee9d17aae628b22be86966471db65be21f262 upstream.

Make the check to skip the rate check more lax, so that it applies
to all hw_version 4 models.

This fixes the touchpad not being detected properly on Asus PU551LA
laptops.

Reported-and-tested-by: David Zafra Gómez <dezeta@klo.es>
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 drivers/input/mouse/elantech.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/drivers/input/mouse/elantech.c b/drivers/input/mouse/elantech.c
index c907f9d..8eeff9e 100644
--- a/drivers/input/mouse/elantech.c
+++ b/drivers/input/mouse/elantech.c
@@ -1236,10 +1236,11 @@ static bool elantech_is_signature_valid(const unsigned char *param)
 		return true;
 
 	/*
-	 * Some models have a revision higher then 20. Meaning param[2] may
-	 * be 10 or 20, skip the rates check for these.
+	 * Some hw_version >= 4 models have a revision higher then 20. Meaning
+	 * that param[2] may be 10 or 20, skip the rates check for these.
 	 */
-	if (param[0] == 0x46 && (param[1] & 0xef) == 0x0f && param[2] < 40)
+	if ((param[0] & 0x0f) >= 0x06 && (param[1] & 0xaf) == 0x0f &&
+	    param[2] < 40)
 		return true;
 
 	for (i = 0; i < ARRAY_SIZE(rates); i++)
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224868 — [PATCH 3.4 110/146] ARM: dts: imx27: only map 4 Kbyte for fec registers

Fromlizf@kernel.org
Date2015-09-15 11:30 +0200
Subject[PATCH 3.4 110/146] ARM: dts: imx27: only map 4 Kbyte for fec registers
Message-ID<q8UIN-FE-1@gated-at.bofh.it>
In reply to#1224789
From: Philippe Reynes <tremyfr@gmail.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit a29ef819f3f34f89a1b9b6a939b4c1cdfe1e85ce upstream.

According to the imx27 documentation, fec has a 4 Kbyte
memory space map. Moreover, the actual 16 Kbyte mapping
overlaps the SCC (Security Controller) memory register
space. So, we reduce the memory register space to 4 Kbyte.

Signed-off-by: Philippe Reynes <tremyfr@gmail.com>
Acked-by: Uwe Kleine-König <u.kleine-koenig@pengutronix.de>
Fixes: 9f0749e3eb88 ("ARM i.MX27: Add devicetree support")
Signed-off-by: Shawn Guo <shawn.guo@linaro.org>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 arch/arm/boot/dts/imx27.dtsi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm/boot/dts/imx27.dtsi b/arch/arm/boot/dts/imx27.dtsi
index bc5e7d5..9cc8ed2 100644
--- a/arch/arm/boot/dts/imx27.dtsi
+++ b/arch/arm/boot/dts/imx27.dtsi
@@ -208,7 +208,7 @@
 
 			fec: fec@1002b000 {
 				compatible = "fsl,imx27-fec";
-				reg = <0x1002b000 0x4000>;
+				reg = <0x1002b000 0x1000>;
 				interrupts = <50>;
 				status = "disabled";
 			};
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224869 — [PATCH 3.4 102/146] Input: elantech - fix semi-mt protocol for v3 HW

Fromlizf@kernel.org
Date2015-09-15 11:30 +0200
Subject[PATCH 3.4 102/146] Input: elantech - fix semi-mt protocol for v3 HW
Message-ID<q8UIO-FE-9@gated-at.bofh.it>
In reply to#1224789
From: Benjamin Tissoires <benjamin.tissoires@redhat.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit 3c0213d17a09601e0c6c0ae0e27caf70d988290f upstream.

When the v3 hardware sees more than one finger, it uses the semi-mt
protocol to report the touches. However, it currently works when
num_fingers is 0, 1 or 2, but when it is 3 and above, it sends only 1
finger as if num_fingers was 1.

This confuses userspace which knows how to deal with extra fingers
when all the slots are used, but not when some are missing.

Fixes: https://bugs.freedesktop.org/show_bug.cgi?id=90101

Signed-off-by: Benjamin Tissoires <benjamin.tissoires@redhat.com>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 drivers/input/mouse/elantech.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/input/mouse/elantech.c b/drivers/input/mouse/elantech.c
index 877dbc8..c907f9d 100644
--- a/drivers/input/mouse/elantech.c
+++ b/drivers/input/mouse/elantech.c
@@ -313,7 +313,7 @@ static void elantech_report_semi_mt_data(struct input_dev *dev,
 					 unsigned int x2, unsigned int y2)
 {
 	elantech_set_slot(dev, 0, num_fingers != 0, x1, y1);
-	elantech_set_slot(dev, 1, num_fingers == 2, x2, y2);
+	elantech_set_slot(dev, 1, num_fingers >= 2, x2, y2);
 }
 
 /*
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224871 — [PATCH 3.4 107/146] xen/events: don't bind non-percpu VIRQs with percpu chip

Fromlizf@kernel.org
Date2015-09-15 11:30 +0200
Subject[PATCH 3.4 107/146] xen/events: don't bind non-percpu VIRQs with percpu chip
Message-ID<q8UIO-FE-11@gated-at.bofh.it>
In reply to#1224789
From: David Vrabel <david.vrabel@citrix.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit 77bb3dfdc0d554befad58fdefbc41be5bc3ed38a upstream.

A non-percpu VIRQ (e.g., VIRQ_CONSOLE) may be freed on a different
VCPU than it is bound to.  This can result in a race between
handle_percpu_irq() and removing the action in __free_irq() because
handle_percpu_irq() does not take desc->lock.  The interrupt handler
sees a NULL action and oopses.

Only use the percpu chip/handler for per-CPU VIRQs (like VIRQ_TIMER).

  # cat /proc/interrupts | grep virq
   40:      87246          0  xen-percpu-virq      timer0
   44:          0          0  xen-percpu-virq      debug0
   47:          0      20995  xen-percpu-virq      timer1
   51:          0          0  xen-percpu-virq      debug1
   69:          0          0   xen-dyn-virq      xen-pcpu
   74:          0          0   xen-dyn-virq      mce
   75:         29          0   xen-dyn-virq      hvc_console

Signed-off-by: David Vrabel <david.vrabel@citrix.com>
[lizf: Backported to 3.4: adjust filename]
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 drivers/tty/hvc/hvc_xen.c |  2 +-
 drivers/xen/events.c      | 12 ++++++++----
 include/xen/events.h      |  2 +-
 3 files changed, 10 insertions(+), 6 deletions(-)

diff --git a/drivers/tty/hvc/hvc_xen.c b/drivers/tty/hvc/hvc_xen.c
index 53e02b7..160b1f3 100644
--- a/drivers/tty/hvc/hvc_xen.c
+++ b/drivers/tty/hvc/hvc_xen.c
@@ -290,7 +290,7 @@ static int xen_initial_domain_console_init(void)
 			return -ENOMEM;
 	}
 
-	info->irq = bind_virq_to_irq(VIRQ_CONSOLE, 0);
+	info->irq = bind_virq_to_irq(VIRQ_CONSOLE, 0, false);
 	info->vtermno = HVC_COOKIE;
 
 	spin_lock(&xencons_lock);
diff --git a/drivers/xen/events.c b/drivers/xen/events.c
index fdf842c..d6e2dee 100644
--- a/drivers/xen/events.c
+++ b/drivers/xen/events.c
@@ -906,7 +906,7 @@ static int find_virq(unsigned int virq, unsigned int cpu)
 	return rc;
 }
 
-int bind_virq_to_irq(unsigned int virq, unsigned int cpu)
+int bind_virq_to_irq(unsigned int virq, unsigned int cpu, bool percpu)
 {
 	struct evtchn_bind_virq bind_virq;
 	int evtchn, irq, ret;
@@ -920,8 +920,12 @@ int bind_virq_to_irq(unsigned int virq, unsigned int cpu)
 		if (irq == -1)
 			goto out;
 
-		irq_set_chip_and_handler_name(irq, &xen_percpu_chip,
-					      handle_percpu_irq, "virq");
+		if (percpu)
+			irq_set_chip_and_handler_name(irq, &xen_percpu_chip,
+						      handle_percpu_irq, "virq");
+		else
+			irq_set_chip_and_handler_name(irq, &xen_dynamic_chip,
+						      handle_edge_irq, "virq");
 
 		bind_virq.virq = virq;
 		bind_virq.vcpu = cpu;
@@ -1042,7 +1046,7 @@ int bind_virq_to_irqhandler(unsigned int virq, unsigned int cpu,
 {
 	int irq, retval;
 
-	irq = bind_virq_to_irq(virq, cpu);
+	irq = bind_virq_to_irq(virq, cpu, irqflags & IRQF_PERCPU);
 	if (irq < 0)
 		return irq;
 	retval = request_irq(irq, handler, irqflags, devname, dev_id);
diff --git a/include/xen/events.h b/include/xen/events.h
index 04399b2..f9cb630 100644
--- a/include/xen/events.h
+++ b/include/xen/events.h
@@ -12,7 +12,7 @@ int bind_evtchn_to_irqhandler(unsigned int evtchn,
 			      irq_handler_t handler,
 			      unsigned long irqflags, const char *devname,
 			      void *dev_id);
-int bind_virq_to_irq(unsigned int virq, unsigned int cpu);
+int bind_virq_to_irq(unsigned int virq, unsigned int cpu, bool percpu);
 int bind_virq_to_irqhandler(unsigned int virq, unsigned int cpu,
 			    irq_handler_t handler,
 			    unsigned long irqflags, const char *devname,
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1224872 — [PATCH 3.4 089/146] xhci: Solve full event ring by increasing TRBS_PER_SEGMENT to 256

Fromlizf@kernel.org
Date2015-09-15 11:30 +0200
Subject[PATCH 3.4 089/146] xhci: Solve full event ring by increasing TRBS_PER_SEGMENT to 256
Message-ID<q8UIO-FE-25@gated-at.bofh.it>
In reply to#1224789
From: Mathias Nyman <mathias.nyman@linux.intel.com>

3.4.109-rc1 review patch.  If anyone has any objections, please let me know.

------------------


commit 18cc2f4cbbaf825a4fedcf2d60fd388d291e0a38 upstream.

Our event ring consists of only one segment, and we risk filling
the event ring in case we get isoc transfers with short intervals
such as webcams that fill a TD every microframe (125us)

With 64 TRB segment size one usb camera could fill the event ring in 8ms.
A setup with several cameras and other devices can fill up the
event ring as it is shared between all devices.
This has occurred when uvcvideo queues 5 * 32TD URBs which then
get cancelled when the video mode changes. The cancelled URBs are returned
in the xhci interrupt context and blocks the interrupt handler from
handling the new events.

A full event ring will block xhci from scheduling traffic and affect all
devices conneted to the xhci, will see errors such as Missed Service
Intervals for isoc devices, and  and Split transaction errors for LS/FS
interrupt devices.

Increasing the TRB_PER_SEGMENT will also increase the default endpoint ring
size, which is welcome as for most isoc transfer we had to dynamically
expand the endpoint ring anyway to be able to queue the 5 * 32TDs uvcvideo
queues.

The default size used to be 64 TRBs per segment

Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
 drivers/usb/host/xhci.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/usb/host/xhci.h b/drivers/usb/host/xhci.h
index 80b3d85..855f084 100644
--- a/drivers/usb/host/xhci.h
+++ b/drivers/usb/host/xhci.h
@@ -1233,7 +1233,7 @@ union xhci_trb {
  * since the command ring is 64-byte aligned.
  * It must also be greater than 16.
  */
-#define TRBS_PER_SEGMENT	64
+#define TRBS_PER_SEGMENT	256
 /* Allow two commands + a link TRB, along with any reserved command TRBs */
 #define MAX_RSVD_CMD_TRBS	(TRBS_PER_SEGMENT - 3)
 #define SEGMENT_SIZE		(TRBS_PER_SEGMENT*16)
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


Page 4 of 7 — ← Prev page 1 2 3 [4] 5 6 7  Next page →

Back to top | Article view | linux.kernel


csiph-web