Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1293144 > unrolled thread

[3.19.y-ckt stable] Linux 3.19.8-ckt12 stable review

Started byKamal Mostafa <kamal@canonical.com>
First post2015-12-16 18:40 +0100
Last post2015-12-16 19:30 +0100
Articles 20 on this page of 131 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [3.19.y-ckt stable] Linux 3.19.8-ckt12 stable review Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:40 +0100
    [PATCH 3.19.y-ckt 122/128] net/neighbour: fix crash at dumping device-agnostic proxy entries Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 116/128] remoteproc: avoid stack overflow in debugfs file Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 119/128] net: mvneta: add configuration for MBUS windows access protection Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 094/128] mac80211: mesh: fix call_rcu() usage Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 113/128] tcp: fix potential huge kmalloc() calls in TCP_REPAIR Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 123/128] sched/core: Remove false-positive warning from wake_up_process() Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 121/128] net: mvneta: fix bit assignment for RX packet irq enable Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 118/128] bpf, array: fix heap out-of-bounds access when updating elements Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 127/128] ipv4: igmp: Allow removing groups from a removed interface Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 090/128] Bluetooth: Fix l2cap_chan leak in SMP Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 095/128] can: sja1000: clear interrupts on start Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 109/128] x86/signal: Fix restart_syscall number for x32 tasks Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 115/128] isdn: Partially revert debug format string usage clean up Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 126/128] broadcom: fix PHY_ID_BCM5481 entry in the id table Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 124/128] net: ip6mr: fix static mfc/dev leaks on table destruction Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 128/128] sched/wait: Fix signal handling in bit wait helpers Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
      Re: [PATCH 3.19.y-ckt 128/128] sched/wait: Fix signal handling in  bit wait helpers Oleg Nesterov <oleg@redhat.com> - 2015-12-16 19:00 +0100
        Re: [PATCH 3.19.y-ckt 128/128] sched/wait: Fix signal handling in  bit wait helpers Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 003/128] iio:ad5064: Make sure ad5064_i2c_write() returns 0 on success Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 111/128] SUNRPC: Fix callback channel Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 117/128] drm/rockchip: unset pgoff when mmap'ing gems Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 108/128] x86/mpx: Fix instruction decoder condition Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 114/128] drm: imx: convert to drm_crtc_send_vblank_event() Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 105/128] sched/core: Clear the root_domain cpumasks in init_rootdomain() Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 077/128] PCI: Prevent out of bounds access in numa_node override Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 112/128] tcp: md5: fix lockdep annotation Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 125/128] unix: avoid use-after-free in ep_remove_wait_queue Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 107/128] ARM/arm64: KVM: correct PTE uncachedness check Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 104/128] drm: Fix an unwanted master inheritance v2 Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 120/128] net: mvneta: fix bit assignment in MVNETA_RXQ_CONFIG_REG Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 110/128] ovl: fix permission checking for setattr Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 088/128] ARM: dts: Kirkwood: Fix QNAP TS219 power-off Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 025/128] usb: chipidea: debug: disable usb irq while role switch Kamal Mostafa <kamal@canonical.com> - 2015-12-16 18:50 +0100
    [PATCH 3.19.y-ckt 106/128] rbd: don't put snap_context twice in rbd_queue_workfn() Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 102/128] mac80211: do not actively scan DFS channels Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 085/128] iscsi-target: Fix rx_login_comp hang after login failure Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 103/128] PM / Domains: Fix bad of_node_put() in failure paths of genpd_dev_pm_attach() Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 100/128] Fix a memory leak in scsi_host_dev_release() Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 091/128] crypto: nx - Fix timing leak in GCM and CCM decryption Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 009/128] x86/mpx: Do proper get_user() when running 32-bit binaries on 64-bit kernels Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 089/128] ath10k: fix invalid NSS for 4x4 devices Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 098/128] drm/i915: Don't override output type for DDI HDMI Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 093/128] ASoC: wm8962: correct addresses for HPF_C_0/1 Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 042/128] FS-Cache: Add missing initialization of ret in cachefiles_write_page() Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 087/128] target: fix COMPARE_AND_WRITE non zero SGL offset data corruption Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 097/128] RDS: fix race condition when sending a message on unbound socket Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 084/128] xen/gntdev: Grant maps should not be subject to NUMA balancing Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 099/128] block: Always check queue limits for cloned requests Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 086/128] target: Fix race for SCF_COMPARE_AND_WRITE_POST checking Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 092/128] crypto: talitos - Fix timing leak in ESP ICV verification Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 101/128] wan/x25: Fix use-after-free in x25_asy_open_tty() Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 010/128] x86/fpu: Fix 32-bit signal frame handling Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 080/128] ARM: dove: Fix legacy get_irqnr_and_base Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 083/128] nfs: if we have no valid attrs, then don't declare the attribute cache valid Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 096/128] ring-buffer: Update read stamp with first real commit on page Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:00 +0100
    [PATCH 3.19.y-ckt 064/128] powerpc/tm: Block signal return setting invalid MSR state Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 079/128] btrfs: fix signed overflows in btrfs_sync_file Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 008/128] x86/mpx: Introduce new 'directory entry' to 'addr' helper function Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 078/128] ALSA: hda - Fix noise on Gigabyte Z170X mobo Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 076/128] drm/radeon: make rv770_set_sw_state failures non-fatal Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 065/128] powerpc/tm: Check for already reclaimed tasks Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 031/128] usblp: do not set TASK_INTERRUPTIBLE before lock Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 066/128] ARC: dw2 unwind: Remove falllback linear search thru FDE entries Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 033/128] kernel/signal.c: unexport sigsuspend() Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 073/128] ARM: dts: vfxxx: Fix dspi[01] spi-num-chipselects. Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 057/128] MIPS: KVM: Uninit VCPU in vcpu_create error path Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 074/128] ARM/arm64: KVM: test properly for a PTE's uncachedness Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 056/128] MIPS: KVM: Fix CACHE immediate offset sign extension Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 075/128] arm64: KVM: Fix AArch32 to AArch64 register mapping Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 067/128] fix sysvfs symlinks Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 070/128] nfs4: start callback_ident at idr 1 Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 023/128] arm64: kernel: pause/unpause function graph tracer in cpu_suspend() Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 068/128] vfs: Make sendfile(2) killable even better Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 045/128] perf symbols: Fix dso lookup by long name and missing buildids Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 063/128] ALSA: hda - Apply HP headphone fixups more generically Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 062/128] mac: validate mac_partition is within sector Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 006/128] x86/mpx: Add temporary variable to reduce masking Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 071/128] nfs4: limit callback decoding to received bytes Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 055/128] MIPS: KVM: Fix ASID restoration logic Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 007/128] x86: Make is_64bit_mm() widely available Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 072/128] ALSA: hda - Fix headphone noise after Dell XPS 13 resume back from S3 Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 069/128] vfs: Avoid softlockups with sendfile(2) Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 082/128] drm/radeon: make some dpm errors debug only Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 032/128] fat: fix fake_offset handling on error path Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 081/128] ARM: orion5x: Fix legacy get_irqnr_and_base Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 035/128] tty: Fix tty_send_xchar() lock order inversion Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 060/128] KVM: s390: fix wrong lookup of VCPUs by array index Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:10 +0100
    [PATCH 3.19.y-ckt 030/128] USB: option: add XS Stick W100-2 from 4G Systems Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 034/128] ocfs2: fix umask ignored issue Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 043/128] ipvlan: fix leak in ipvlan_rcv_frame Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 029/128] arm64: restore bogomips information in /proc/cpuinfo Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 051/128] ALSA: usb-audio: prevent CH345 multiport output SysEx corruption Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 058/128] KVM: Provide function for VCPU lookup by id Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 036/128] parisc: Drop unused MADV_xxxK_PAGES flags from asm/mman.h Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 038/128] tools/net: Use include/uapi with __EXPORTED_HEADERS__ Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 021/128] drm/radeon: unconditionally set sysfs_initialized Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 049/128] macvlan: fix leak in macvlan_handle_frame Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 050/128] ALSA: usb-audio: add packet size quirk for the Medeli DD305 Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 037/128] mmc: remove bondage between REQ_META and reliable write Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 048/128] net/mlx4_core: Avoid returning success in case of an error flow Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 039/128] packet: do skb_probe_transport_header when we actually have data Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 026/128] xhci: Workaround to get Intel xHCI reset working more reliably Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 053/128] dm thin: restore requested 'error_if_no_space' setting on OODS to WRITE transition Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 054/128] dm: fix ioctl retry termination with signal Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 040/128] sctp: translate host order to network order when setting a hmacid Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 028/128] x86/cpu: Fix SMAP check in PVOPS environments Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 041/128] usb: musb: core: fix order of arguments to ulpi write callback Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 061/128] ALSA: hda - Add fixup for Acer Aspire One Cloudbook 14 Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 011/128] crypto: qat - don't use userspace pointer Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 024/128] usb: dwc3: gadget: let us set lower max_speed Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 047/128] packet: fix tpacket_snd max frame len Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 059/128] KVM: s390: avoid memory overwrites on emergency signal injection Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 022/128] USB: qcserial: Fix support for HP lt4112 LTE/HSPA+ Gobi 4G Modem Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 044/128] ipvlan: fix use after free of skb Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 052/128] ALSA: usb-audio: work around CH345 input SysEx corruption Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 027/128] xhci: Fix a race in usb2 LPM resume, blocking U3 for usb2 devices Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 020/128] drm/radeon: Disable uncacheable CPU mappings of GTT with RV6xx Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 046/128] packet: only allow extra vlan len on ethernet devices Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:20 +0100
    [PATCH 3.19.y-ckt 013/128] iio: adc: xilinx: Fix VREFN scale Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:30 +0100
    [PATCH 3.19.y-ckt 004/128] iio: ad5064: Fix ad5629/ad5669 shift Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:30 +0100
    [PATCH 3.19.y-ckt 018/128] USB: ti_usb_3410_5052: Add Honeywell HGI80 ID Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:30 +0100
    [PATCH 3.19.y-ckt 016/128] USB: qcserial: Add support for Quectel EC20 Mini PCIe module Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:30 +0100
    [PATCH 3.19.y-ckt 017/128] USB: serial: option: add support for Novatel MiFi USB620L Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:30 +0100
    [PATCH 3.19.y-ckt 019/128] drm/i915: get runtime PM reference around GEM set_caching IOCTL Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:30 +0100
    [PATCH 3.19.y-ckt 005/128] iio:ad7793: Fix ad7785 product ID Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:30 +0100
    [PATCH 3.19.y-ckt 015/128] drm/i915: quirk backlight present on Macbook 4, 1 Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:30 +0100
    [PATCH 3.19.y-ckt 012/128] iio: si7020: Swap data byte order Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:30 +0100
    [PATCH 3.19.y-ckt 001/128] vf610_adc: Fix internal temperature calculation Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:30 +0100
    [PATCH 3.19.y-ckt 002/128] iio: lpc32xx_adc: fix warnings caused by enabling unprepared clock Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:30 +0100
    [PATCH 3.19.y-ckt 014/128] ipmi: Start the timer and thread on internal msgs Kamal Mostafa <kamal@canonical.com> - 2015-12-16 19:30 +0100

Page 1 of 7  [1] 2 3 4 5 6 7  Next page →


#1293144 — [3.19.y-ckt stable] Linux 3.19.8-ckt12 stable review

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:40 +0100
Subject[3.19.y-ckt stable] Linux 3.19.8-ckt12 stable review
Message-ID<qGods-4KL-3@gated-at.bofh.it>
This is the start of the review cycle for the Linux 3.19.8-ckt12 stable kernel.

This version contains 128 new patches, summarized below.  The new patches are
posted as replies to this message and also available in this git branch:

http://kernel.ubuntu.com/git/ubuntu/linux.git/log/?h=linux-3.19.y-review

git://kernel.ubuntu.com/ubuntu/linux.git  linux-3.19.y-review

The review period for version 3.19.8-ckt12 will be open for the next three days.
To report a problem, please reply to the relevant follow-up patch message.

For more information about the Linux 3.19.y-ckt extended stable kernel version,
see https://wiki.ubuntu.com/Kernel/Dev/ExtendedStable .

 -Kamal

--
 arch/arc/kernel/unwind.c                         |  37 +----
 arch/arm/boot/dts/kirkwood-ts219.dtsi            |   2 +-
 arch/arm/boot/dts/vfxxx.dtsi                     |   2 +-
 arch/arm/kvm/mmu.c                               |  15 +-
 arch/arm/mach-dove/include/mach/entry-macro.S    |   4 +-
 arch/arm/mach-orion5x/include/mach/entry-macro.S |   2 +-
 arch/arm64/include/asm/kvm_emulate.h             |   8 +-
 arch/arm64/kernel/setup.c                        |   3 +
 arch/arm64/kernel/suspend.c                      |  10 ++
 arch/arm64/kvm/inject_fault.c                    |   2 +-
 arch/mips/kvm/emulate.c                          |   2 +-
 arch/mips/kvm/locore.S                           |  16 +-
 arch/mips/kvm/mips.c                             |   5 +-
 arch/parisc/include/uapi/asm/mman.h              |  10 --
 arch/powerpc/include/asm/reg.h                   |   1 +
 arch/powerpc/kernel/process.c                    |  18 +++
 arch/powerpc/kernel/signal_32.c                  |  14 +-
 arch/powerpc/kernel/signal_64.c                  |   4 +
 arch/s390/kvm/interrupt.c                        |   4 +
 arch/s390/kvm/sigp.c                             |   8 +-
 arch/x86/include/asm/mmu_context.h               |  13 ++
 arch/x86/include/asm/mpx.h                       |   1 -
 arch/x86/kernel/cpu/common.c                     |   3 +-
 arch/x86/kernel/signal.c                         |  17 ++-
 arch/x86/kernel/uprobes.c                        |  10 +-
 arch/x86/kernel/xsave.c                          |  11 +-
 arch/x86/mm/mpx.c                                |  77 ++++++++--
 block/blk-core.c                                 |  21 +--
 block/partitions/mac.c                           |  10 +-
 drivers/base/power/domain.c                      |   3 +-
 drivers/block/rbd.c                              |   1 +
 drivers/char/ipmi/ipmi_si_intf.c                 |  73 +++++----
 drivers/crypto/nx/nx-aes-ccm.c                   |   2 +-
 drivers/crypto/nx/nx-aes-gcm.c                   |   2 +-
 drivers/crypto/qat/qat_common/adf_ctl_drv.c      |   2 +-
 drivers/crypto/talitos.c                         |   2 +-
 drivers/gpu/drm/drm_drv.c                        |   5 +
 drivers/gpu/drm/drm_fops.c                       |  84 +++++++----
 drivers/gpu/drm/i915/i915_gem.c                  |   8 +-
 drivers/gpu/drm/i915/intel_display.c             |   3 +
 drivers/gpu/drm/i915/intel_dp.c                  |   3 +-
 drivers/gpu/drm/imx/ipuv3-crtc.c                 |   3 +-
 drivers/gpu/drm/radeon/radeon_object.c           |   6 +
 drivers/gpu/drm/radeon/radeon_pm.c               |   3 +-
 drivers/gpu/drm/radeon/rv730_dpm.c               |   2 +-
 drivers/gpu/drm/radeon/rv770_dpm.c               |   4 +-
 drivers/gpu/drm/rockchip/rockchip_drm_gem.c      |   1 +
 drivers/iio/adc/ad7793.c                         |   2 +-
 drivers/iio/adc/vf610_adc.c                      |  19 ++-
 drivers/iio/adc/xilinx-xadc-core.c               |   1 +
 drivers/iio/dac/ad5064.c                         |  91 +++++++----
 drivers/iio/humidity/si7020.c                    |   8 +-
 drivers/isdn/hisax/config.c                      |   2 +-
 drivers/isdn/hisax/hfc_pci.c                     |   2 +-
 drivers/isdn/hisax/hfc_sx.c                      |   2 +-
 drivers/isdn/hisax/q931.c                        |   6 +-
 drivers/md/dm-mpath.c                            |   2 +-
 drivers/md/dm-thin.c                             |   1 +
 drivers/md/dm.c                                  |   2 +-
 drivers/mmc/card/block.c                         |  11 +-
 drivers/net/can/sja1000/sja1000.c                |   3 +
 drivers/net/ethernet/marvell/mvneta.c            |   6 +-
 drivers/net/ethernet/mellanox/mlx4/main.c        |   8 +-
 drivers/net/ipvlan/ipvlan_core.c                 |  14 +-
 drivers/net/macvlan.c                            |   2 +
 drivers/net/phy/broadcom.c                       |   2 +-
 drivers/net/wan/x25_asy.c                        |   6 +-
 drivers/net/wireless/ath/ath10k/mac.c            |   2 +-
 drivers/pci/pci-sysfs.c                          |   5 +-
 drivers/remoteproc/remoteproc_debugfs.c          |   2 +-
 drivers/scsi/hosts.c                             |  11 ++
 drivers/staging/iio/adc/lpc32xx_adc.c            |   4 +-
 drivers/target/iscsi/iscsi_target.c              |  13 +-
 drivers/target/iscsi/iscsi_target_nego.c         |   1 +
 drivers/target/target_core_sbc.c                 |  17 ++-
 drivers/target/target_core_transport.c           |  14 +-
 drivers/tty/tty_io.c                             |   4 +
 drivers/tty/tty_ioctl.c                          |   4 -
 drivers/usb/chipidea/debug.c                     |   2 +
 drivers/usb/class/usblp.c                        |   2 +-
 drivers/usb/dwc3/gadget.c                        |  23 ++-
 drivers/usb/host/xhci-hub.c                      |  15 +-
 drivers/usb/host/xhci.c                          |  10 ++
 drivers/usb/musb/musb_core.c                     |  10 +-
 drivers/usb/serial/option.c                      |  11 ++
 drivers/usb/serial/qcserial.c                    |  94 +++++++++---
 drivers/usb/serial/ti_usb_3410_5052.c            |   2 +
 drivers/usb/serial/ti_usb_3410_5052.h            |   4 +
 drivers/xen/gntdev.c                             |   2 +-
 fs/btrfs/file.c                                  |  11 +-
 fs/cachefiles/rdwr.c                             |   2 +-
 fs/fat/dir.c                                     |  16 +-
 fs/nfs/inode.c                                   |   6 +-
 fs/nfs/nfs4client.c                              |   2 +-
 fs/ocfs2/namei.c                                 |   2 +
 fs/overlayfs/inode.c                             |   8 +-
 fs/splice.c                                      |   8 +
 fs/sysv/inode.c                                  |  10 +-
 include/drm/drmP.h                               |   6 +
 include/linux/blkdev.h                           |   1 -
 include/linux/kvm_host.h                         |  11 ++
 include/linux/signal.h                           |   1 -
 include/net/af_unix.h                            |   1 +
 include/target/target_core_base.h                |   2 +-
 kernel/bpf/arraymap.c                            |   2 +-
 kernel/sched/core.c                              |   9 +-
 kernel/sched/wait.c                              |  16 +-
 kernel/signal.c                                  |   2 +-
 kernel/trace/ring_buffer.c                       |  12 +-
 net/bluetooth/smp.c                              |   7 +-
 net/core/neighbour.c                             |   4 +-
 net/ipv4/igmp.c                                  |   5 +-
 net/ipv4/tcp_input.c                             |  22 ++-
 net/ipv4/tcp_ipv4.c                              |   3 +-
 net/ipv6/ip6mr.c                                 |  15 +-
 net/mac80211/mesh_pathtbl.c                      |   8 +-
 net/mac80211/scan.c                              |   9 +-
 net/packet/af_packet.c                           |  72 ++++-----
 net/rds/connection.c                             |   6 -
 net/rds/send.c                                   |   4 +-
 net/sctp/auth.c                                  |   4 +-
 net/sunrpc/svc.c                                 |  13 ++
 net/unix/af_unix.c                               | 183 ++++++++++++++++++++---
 sound/pci/hda/patch_realtek.c                    |  22 +++
 sound/pci/hda/patch_sigmatel.c                   |  45 ++++--
 sound/soc/codecs/wm8962.c                        |   4 +-
 sound/usb/midi.c                                 |  46 ++++++
 sound/usb/quirks-table.h                         |  11 ++
 sound/usb/quirks.c                               |   1 +
 sound/usb/usbaudio.h                             |   1 +
 tools/net/Makefile                               |   7 +-
 tools/perf/util/dso.c                            |  17 +++
 tools/perf/util/dso.h                            |   1 +
 tools/perf/util/machine.c                        |   1 +
 134 files changed, 1126 insertions(+), 492 deletions(-)

Aaro Koskinen (1):
      broadcom: fix PHY_ID_BCM5481 entry in the id table

Adrian Hunter (1):
      perf symbols: Fix dso lookup by long name and missing buildids

Al Viro (1):
      fix sysvfs symlinks

Aleksander Morgado (1):
      USB: serial: option: add support for Novatel MiFi USB620L

Alex Deucher (3):
      drm/radeon: unconditionally set sysfs_initialized
      drm/radeon: make rv770_set_sw_state failures non-fatal
      drm/radeon: make some dpm errors debug only

Andrew Cooper (1):
      x86/cpu: Fix SMAP check in PVOPS environments

Andrew Lunn (1):
      ipv4: igmp: Allow removing groups from a removed interface

Antonio Quartulli (1):
      mac80211: do not actively scan DFS channels

Ard Biesheuvel (2):
      ARM/arm64: KVM: test properly for a PTE's uncachedness
      ARM/arm64: KVM: correct PTE uncachedness check

Arnd Bergmann (1):
      remoteproc: avoid stack overflow in debugfs file

Bart Van Assche (1):
      Fix a memory leak in scsi_host_dev_release()

Ben McCauley (1):
      usb: dwc3: gadget: let us set lower max_speed

Benjamin Coddington (2):
      nfs4: start callback_ident at idr 1
      nfs4: limit callback decoding to received bytes

Bhuvanchandra DV (1):
      vf610_adc: Fix internal temperature calculation

Bjørn Mork (2):
      USB: qcserial: Fix support for HP lt4112 LTE/HSPA+ Gobi 4G Modem
      USB: option: add XS Stick W100-2 from 4G Systems

Boris Ostrovsky (1):
      xen/gntdev: Grant maps should not be subject to NUMA balancing

Chris Lesiak (1):
      iio: si7020: Swap data byte order

Christoph Biedl (1):
      isdn: Partially revert debug format string usage clean up

Clemens Ladisch (3):
      ALSA: usb-audio: add packet size quirk for the Medeli DD305
      ALSA: usb-audio: prevent CH345 multiport output SysEx corruption
      ALSA: usb-audio: work around CH345 input SysEx corruption

Corey Minyard (1):
      ipmi: Start the timer and thread on internal msgs

Cory Tusar (1):
      ARM: dts: vfxxx: Fix dspi[01] spi-num-chipselects.

Daniel Borkmann (4):
      packet: do skb_probe_transport_header when we actually have data
      packet: only allow extra vlan len on ethernet devices
      packet: fix tpacket_snd max frame len
      bpf, array: fix heap out-of-bounds access when updating elements

Dave Hansen (6):
      x86/mpx: Add temporary variable to reduce masking
      x86: Make is_64bit_mm() widely available
      x86/mpx: Introduce new 'directory entry' to 'addr' helper function
      x86/mpx: Do proper get_user() when running 32-bit binaries on 64-bit kernels
      x86/fpu: Fix 32-bit signal frame handling
      x86/mpx: Fix instruction decoder condition

David Gstir (2):
      crypto: nx - Fix timing leak in GCM and CCM decryption
      crypto: talitos - Fix timing leak in ESP ICV verification

David Hildenbrand (3):
      KVM: Provide function for VCPU lookup by id
      KVM: s390: avoid memory overwrites on emergency signal injection
      KVM: s390: fix wrong lookup of VCPUs by array index

David Sterba (1):
      btrfs: fix signed overflows in btrfs_sync_file

David Woodhouse (1):
      USB: ti_usb_3410_5052: Add Honeywell HGI80 ID

Dmitry V. Levin (1):
      x86/signal: Fix restart_syscall number for x32 tasks

Eric Anholt (1):
      PM / Domains: Fix bad of_node_put() in failure paths of genpd_dev_pm_attach()

Eric Dumazet (2):
      tcp: md5: fix lockdep annotation
      tcp: fix potential huge kmalloc() calls in TCP_REPAIR

Geert Uytterhoeven (1):
      FS-Cache: Add missing initialization of ret in cachefiles_write_page()

Hannes Reinecke (1):
      block: Always check queue limits for cloned requests

Heiko Stuebner (1):
      drm/rockchip: unset pgoff when mmap'ing gems

Helge Deller (1):
      parisc: Drop unused MADV_xxxK_PAGES flags from asm/mman.h

Helmut Klein (1):
      ARM: dts: Kirkwood: Fix QNAP TS219 power-off

Hui Wang (1):
      ALSA: hda - Fix headphone noise after Dell XPS 13 resume back from S3

Ilya Dryomov (1):
      rbd: don't put snap_context twice in rbd_queue_workfn()

Imre Deak (1):
      drm/i915: get runtime PM reference around GEM set_caching IOCTL

James Hogan (3):
      MIPS: KVM: Fix ASID restoration logic
      MIPS: KVM: Fix CACHE immediate offset sign extension
      MIPS: KVM: Uninit VCPU in vcpu_create error path

Jan Engelhardt (1):
      target: fix COMPARE_AND_WRITE non zero SGL offset data corruption

Jan Kara (2):
      vfs: Make sendfile(2) killable even better
      vfs: Avoid softlockups with sendfile(2)

Jani Nikula (1):
      drm/i915: quirk backlight present on Macbook 4, 1

Jeff Layton (1):
      nfs: if we have no valid attrs, then don't declare the attribute cache valid

Jiri Slaby (1):
      usblp: do not set TASK_INTERRUPTIBLE before lock

Johan Hedberg (1):
      Bluetooth: Fix l2cap_chan leak in SMP

Johannes Berg (1):
      mac80211: mesh: fix call_rcu() usage

Junichi Nomura (1):
      dm: fix ioctl retry termination with signal

Junxiao Bi (1):
      ocfs2: fix umask ignored issue

Kamal Mostafa (1):
      tools/net: Use include/uapi with __EXPORTED_HEADERS__

Kees Cook (1):
      mac: validate mac_partition is within sector

Konstantin Khlebnikov (1):
      net/neighbour: fix crash at dumping device-agnostic proxy entries

Lars-Peter Clausen (2):
      iio: ad5064: Fix ad5629/ad5669 shift
      iio:ad7793: Fix ad7785 product ID

Li Jun (1):
      usb: chipidea: debug: disable usb irq while role switch

Lorenzo Pieralisi (1):
      arm64: kernel: pause/unpause function graph tracer in cpu_suspend()

Luca Porzio (1):
      mmc: remove bondage between REQ_META and reliable write

Marc Zyngier (1):
      arm64: KVM: Fix AArch32 to AArch64 register mapping

Marcin Wojtas (3):
      net: mvneta: add configuration for MBUS windows access protection
      net: mvneta: fix bit assignment in MVNETA_RXQ_CONFIG_REG
      net: mvneta: fix bit assignment for RX packet irq enable

Mathias Krause (1):
      PCI: Prevent out of bounds access in numa_node override

Mathias Nyman (1):
      xhci: Fix a race in usb2 LPM resume, blocking U3 for usb2 devices

Michael Hennerich (1):
      iio:ad5064: Make sure ad5064_i2c_write() returns 0 on success

Michael Neuling (2):
      powerpc/tm: Block signal return setting invalid MSR state
      powerpc/tm: Check for already reclaimed tasks

Michel Dänzer (1):
      drm/radeon: Disable uncacheable CPU mappings of GTT with RV6xx

Mike Snitzer (1):
      dm thin: restore requested 'error_if_no_space' setting on OODS to WRITE transition

Miklos Szeredi (1):
      ovl: fix permission checking for setattr

Mirza Krak (1):
      can: sja1000: clear interrupts on start

Nicholas Bellinger (2):
      iscsi-target: Fix rx_login_comp hang after login failure
      target: Fix race for SCF_COMPARE_AND_WRITE_POST checking

Nicolas Pitre (2):
      ARM: dove: Fix legacy get_irqnr_and_base
      ARM: orion5x: Fix legacy get_irqnr_and_base

Nikolay Aleksandrov (1):
      net: ip6mr: fix static mfc/dev leaks on table destruction

Noa Osherovich (1):
      net/mlx4_core: Avoid returning success in case of an error flow

OGAWA Hirofumi (1):
      fat: fix fake_offset handling on error path

Peter Hurley (2):
      tty: Fix tty_send_xchar() lock order inversion
      wan/x25: Fix use-after-free in x25_asy_open_tty()

Peter Zijlstra (1):
      sched/wait: Fix signal handling in bit wait helpers

Petr Štetiar (1):
      USB: qcserial: Add support for Quectel EC20 Mini PCIe module

Quentin Casasnovas (1):
      RDS: fix race condition when sending a message on unbound socket

Rainer Weikusat (1):
      unix: avoid use-after-free in ep_remove_wait_queue

Rajkumar Manoharan (1):
      ath10k: fix invalid NSS for 4x4 devices

Rajmohan Mani (1):
      xhci: Workaround to get Intel xHCI reset working more reliably

Richard Weinberger (1):
      kernel/signal.c: unexport sigsuspend()

Russell King (1):
      drm: imx: convert to drm_crtc_send_vblank_event()

Sabrina Dubroca (3):
      ipvlan: fix leak in ipvlan_rcv_frame
      ipvlan: fix use after free of skb
      macvlan: fix leak in macvlan_handle_frame

Sachin Pandhare (1):
      ASoC: wm8962: correct addresses for HPF_C_0/1

Sasha Levin (1):
      sched/core: Remove false-positive warning from wake_up_process()

Steven Rostedt (Red Hat) (1):
      ring-buffer: Update read stamp with first real commit on page

Tadeusz Struk (1):
      crypto: qat - don't use userspace pointer

Takashi Iwai (4):
      ALSA: hda - Add fixup for Acer Aspire One Cloudbook 14
      ALSA: hda - Apply HP headphone fixups more generically
      ALSA: hda - Fix noise on Gigabyte Z170X mobo
      drm/i915: Don't override output type for DDI HDMI

Thomas Betker (1):
      iio: adc: xilinx: Fix VREFN scale

Thomas Hellstrom (1):
      drm: Fix an unwanted master inheritance v2

Trond Myklebust (1):
      SUNRPC: Fix callback channel

Uwe Kleine-König (1):
      usb: musb: core: fix order of arguments to ulpi write callback

Vineet Gupta (1):
      ARC: dw2 unwind: Remove falllback linear search thru FDE entries

Vladimir Zapolskiy (1):
      iio: lpc32xx_adc: fix warnings caused by enabling unprepared clock

Xunlei Pang (1):
      sched/core: Clear the root_domain cpumasks in init_rootdomain()

Yang Shi (1):
      arm64: restore bogomips information in /proc/cpuinfo

lucien (1):
      sctp: translate host order to network order when setting a hmacid
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [next] | [standalone]


#1293147 — [PATCH 3.19.y-ckt 122/128] net/neighbour: fix crash at dumping device-agnostic proxy entries

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 122/128] net/neighbour: fix crash at dumping device-agnostic proxy entries
Message-ID<qGon7-4Os-1@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Konstantin Khlebnikov <koct9i@gmail.com>

commit 6adc5fd6a142c6e2c80574c1db0c7c17dedaa42e upstream.

Proxy entries could have null pointer to net-device.

Signed-off-by: Konstantin Khlebnikov <koct9i@gmail.com>
Fixes: 84920c1420e2 ("net: Allow ipv6 proxies and arp proxies be shown with iproute2")
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/core/neighbour.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index 0385351..9b1870d 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2239,7 +2239,7 @@ static int pneigh_fill_info(struct sk_buff *skb, struct pneigh_entry *pn,
 	ndm->ndm_pad2    = 0;
 	ndm->ndm_flags	 = pn->flags | NTF_PROXY;
 	ndm->ndm_type	 = RTN_UNICAST;
-	ndm->ndm_ifindex = pn->dev->ifindex;
+	ndm->ndm_ifindex = pn->dev ? pn->dev->ifindex : 0;
 	ndm->ndm_state	 = NUD_NONE;
 
 	if (nla_put(skb, NDA_DST, tbl->key_len, pn->key))
@@ -2313,7 +2313,7 @@ static int pneigh_dump_table(struct neigh_table *tbl, struct sk_buff *skb,
 		if (h > s_h)
 			s_idx = 0;
 		for (n = tbl->phash_buckets[h], idx = 0; n; n = n->next) {
-			if (dev_net(n->dev) != net)
+			if (pneigh_net(n) != net)
 				continue;
 			if (idx < s_idx)
 				goto next;
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293148 — [PATCH 3.19.y-ckt 116/128] remoteproc: avoid stack overflow in debugfs file

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 116/128] remoteproc: avoid stack overflow in debugfs file
Message-ID<qGon7-4Os-3@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnd Bergmann <arnd@arndb.de>

commit 92792e48e2ae6051af30468a87994b5432da2f06 upstream.

Recent gcc versions warn about reading from a negative offset of
an on-stack array:

drivers/remoteproc/remoteproc_debugfs.c: In function 'rproc_recovery_write':
drivers/remoteproc/remoteproc_debugfs.c:167:9: warning: 'buf[4294967295u]' may be used uninitialized in this function [-Wmaybe-uninitialized]

I don't see anything in sys_write() that prevents us from
being called with a zero 'count' argument, so we should
add an extra check in rproc_recovery_write() to prevent the
access and avoid the warning.

Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Fixes: 2e37abb89a2e ("remoteproc: create a 'recovery' debugfs entry")
Signed-off-by: Ohad Ben-Cohen <ohad@wizery.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/remoteproc/remoteproc_debugfs.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/remoteproc/remoteproc_debugfs.c b/drivers/remoteproc/remoteproc_debugfs.c
index 9d30809..916af50 100644
--- a/drivers/remoteproc/remoteproc_debugfs.c
+++ b/drivers/remoteproc/remoteproc_debugfs.c
@@ -156,7 +156,7 @@ rproc_recovery_write(struct file *filp, const char __user *user_buf,
 	char buf[10];
 	int ret;
 
-	if (count > sizeof(buf))
+	if (count < 1 || count > sizeof(buf))
 		return count;
 
 	ret = copy_from_user(buf, user_buf, count);
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293149 — [PATCH 3.19.y-ckt 119/128] net: mvneta: add configuration for MBUS windows access protection

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 119/128] net: mvneta: add configuration for MBUS windows access protection
Message-ID<qGon7-4Os-7@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marcin Wojtas <mw@semihalf.com>

commit db6ba9a5371f173489df126739d0a1c2a50f347b upstream.

This commit adds missing configuration of MBUS windows access protection
in mvneta_conf_mbus_windows function - a dedicated variable for that
purpose remained there unused since v3.8 initial mvneta support. Because
of that the register contents were inherited from the bootloader.

Signed-off-by: Marcin Wojtas <mw@semihalf.com>
Reviewed-by: Gregory CLEMENT <gregory.clement@free-electrons.com>

Fixes: c5aff18204da ("net: mvneta: driver for Marvell Armada 370/XP network
unit")
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/ethernet/marvell/mvneta.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/net/ethernet/marvell/mvneta.c b/drivers/net/ethernet/marvell/mvneta.c
index 5ff18c1..21b4550 100644
--- a/drivers/net/ethernet/marvell/mvneta.c
+++ b/drivers/net/ethernet/marvell/mvneta.c
@@ -61,6 +61,7 @@
 #define MVNETA_WIN_SIZE(w)                      (0x2204 + ((w) << 3))
 #define MVNETA_WIN_REMAP(w)                     (0x2280 + ((w) << 2))
 #define MVNETA_BASE_ADDR_ENABLE                 0x2290
+#define MVNETA_ACCESS_PROTECT_ENABLE            0x2294
 #define MVNETA_PORT_CONFIG                      0x2400
 #define      MVNETA_UNI_PROMISC_MODE            BIT(0)
 #define      MVNETA_DEF_RXQ(q)                  ((q) << 1)
@@ -2899,6 +2900,7 @@ static void mvneta_conf_mbus_windows(struct mvneta_port *pp,
 	}
 
 	mvreg_write(pp, MVNETA_BASE_ADDR_ENABLE, win_enable);
+	mvreg_write(pp, MVNETA_ACCESS_PROTECT_ENABLE, win_protect);
 }
 
 /* Power up the port */
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293150 — [PATCH 3.19.y-ckt 094/128] mac80211: mesh: fix call_rcu() usage

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 094/128] mac80211: mesh: fix call_rcu() usage
Message-ID<qGon7-4Os-13@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johannes Berg <johannes.berg@intel.com>

commit c2e703a55245bfff3db53b1f7cbe59f1ee8a4339 upstream.

When using call_rcu(), the called function may be delayed quite
significantly, and without a matching rcu_barrier() there's no
way to be sure it has finished.
Therefore, global state that could be gone/freed/reused should
never be touched in the callback.

Fix this in mesh by moving the atomic_dec() into the caller;
that's not really a problem since we already unlinked the path
and it will be destroyed anyway.

This fixes a crash Jouni observed when running certain tests in
a certain order, in which the mesh interface was torn down, the
memory reused for a function pointer (work struct) and running
that then crashed since the pointer had been decremented by 1,
resulting in an invalid instruction byte stream.

Fixes: eb2b9311fd00 ("mac80211: mesh path table implementation")
Reported-by: Jouni Malinen <j@w1.fi>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/mac80211/mesh_pathtbl.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/net/mac80211/mesh_pathtbl.c b/net/mac80211/mesh_pathtbl.c
index b890e22..b3b44a5 100644
--- a/net/mac80211/mesh_pathtbl.c
+++ b/net/mac80211/mesh_pathtbl.c
@@ -779,10 +779,8 @@ void mesh_plink_broken(struct sta_info *sta)
 static void mesh_path_node_reclaim(struct rcu_head *rp)
 {
 	struct mpath_node *node = container_of(rp, struct mpath_node, rcu);
-	struct ieee80211_sub_if_data *sdata = node->mpath->sdata;
 
 	del_timer_sync(&node->mpath->timer);
-	atomic_dec(&sdata->u.mesh.mpaths);
 	kfree(node->mpath);
 	kfree(node);
 }
@@ -790,8 +788,9 @@ static void mesh_path_node_reclaim(struct rcu_head *rp)
 /* needs to be called with the corresponding hashwlock taken */
 static void __mesh_path_del(struct mesh_table *tbl, struct mpath_node *node)
 {
-	struct mesh_path *mpath;
-	mpath = node->mpath;
+	struct mesh_path *mpath = node->mpath;
+	struct ieee80211_sub_if_data *sdata = node->mpath->sdata;
+
 	spin_lock(&mpath->state_lock);
 	mpath->flags |= MESH_PATH_RESOLVING;
 	if (mpath->is_gate)
@@ -799,6 +798,7 @@ static void __mesh_path_del(struct mesh_table *tbl, struct mpath_node *node)
 	hlist_del_rcu(&node->list);
 	call_rcu(&node->rcu, mesh_path_node_reclaim);
 	spin_unlock(&mpath->state_lock);
+	atomic_dec(&sdata->u.mesh.mpaths);
 	atomic_dec(&tbl->entries);
 }
 
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293151 — [PATCH 3.19.y-ckt 113/128] tcp: fix potential huge kmalloc() calls in TCP_REPAIR

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 113/128] tcp: fix potential huge kmalloc() calls in TCP_REPAIR
Message-ID<qGon7-4Os-15@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

commit 5d4c9bfbabdb1d497f21afd81501e5c54b0c85d9 upstream.

tcp_send_rcvq() is used for re-injecting data into tcp receive queue.

Problems :

- No check against size is performed, allowed user to fool kernel in
  attempting very large memory allocations, eventually triggering
  OOM when memory is fragmented.

- In case of fault during the copy we do not return correct errno.

Lets use alloc_skb_with_frags() to cook optimal skbs.

Fixes: 292e8d8c8538 ("tcp: Move rcvq sending to tcp_input.c")
Fixes: c0e88ff0f256 ("tcp: Repair socket queues")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Pavel Emelyanov <xemul@parallels.com>
Acked-by: Pavel Emelyanov <xemul@parallels.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/ipv4/tcp_input.c | 22 +++++++++++++++++++---
 1 file changed, 19 insertions(+), 3 deletions(-)

diff --git a/net/ipv4/tcp_input.c b/net/ipv4/tcp_input.c
index 8e967ef..a2782c1 100644
--- a/net/ipv4/tcp_input.c
+++ b/net/ipv4/tcp_input.c
@@ -4354,19 +4354,34 @@ static int __must_check tcp_queue_rcv(struct sock *sk, struct sk_buff *skb, int
 int tcp_send_rcvq(struct sock *sk, struct msghdr *msg, size_t size)
 {
 	struct sk_buff *skb;
+	int err = -ENOMEM;
+	int data_len = 0;
 	bool fragstolen;
 
 	if (size == 0)
 		return 0;
 
-	skb = alloc_skb(size, sk->sk_allocation);
+	if (size > PAGE_SIZE) {
+		int npages = min_t(size_t, size >> PAGE_SHIFT, MAX_SKB_FRAGS);
+
+		data_len = npages << PAGE_SHIFT;
+		size = data_len + (size & ~PAGE_MASK);
+	}
+	skb = alloc_skb_with_frags(size - data_len, data_len,
+				   PAGE_ALLOC_COSTLY_ORDER,
+				   &err, sk->sk_allocation);
 	if (!skb)
 		goto err;
 
+	skb_put(skb, size - data_len);
+	skb->data_len = data_len;
+	skb->len = size;
+
 	if (tcp_try_rmem_schedule(sk, skb, skb->truesize))
 		goto err_free;
 
-	if (memcpy_from_msg(skb_put(skb, size), msg, size))
+	err = skb_copy_datagram_from_iter(skb, 0, &msg->msg_iter, size);
+	if (err)
 		goto err_free;
 
 	TCP_SKB_CB(skb)->seq = tcp_sk(sk)->rcv_nxt;
@@ -4382,7 +4397,8 @@ int tcp_send_rcvq(struct sock *sk, struct msghdr *msg, size_t size)
 err_free:
 	kfree_skb(skb);
 err:
-	return -ENOMEM;
+	return err;
+
 }
 
 static void tcp_data_queue(struct sock *sk, struct sk_buff *skb)
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293153 — [PATCH 3.19.y-ckt 123/128] sched/core: Remove false-positive warning from wake_up_process()

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 123/128] sched/core: Remove false-positive warning from wake_up_process()
Message-ID<qGon8-4Os-21@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sasha Levin <sasha.levin@oracle.com>

commit 119d6f6a3be8b424b200dcee56e74484d5445f7e upstream.

Because wakeups can (fundamentally) be late, a task might not be in
the expected state. Therefore testing against a task's state is racy,
and can yield false positives.

Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Acked-by: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Mike Galbraith <efault@gmx.de>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: oleg@redhat.com
Fixes: 9067ac85d533 ("wake_up_process() should be never used to wakeup a TASK_STOPPED/TRACED task")
Link: http://lkml.kernel.org/r/1448933660-23082-1-git-send-email-sasha.levin@oracle.com
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 kernel/sched/core.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/kernel/sched/core.c b/kernel/sched/core.c
index 2006f4f..6b5909b 100644
--- a/kernel/sched/core.c
+++ b/kernel/sched/core.c
@@ -1812,7 +1812,6 @@ out:
  */
 int wake_up_process(struct task_struct *p)
 {
-	WARN_ON(task_is_stopped_or_traced(p));
 	return try_to_wake_up(p, TASK_NORMAL, 0);
 }
 EXPORT_SYMBOL(wake_up_process);
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293155 — [PATCH 3.19.y-ckt 121/128] net: mvneta: fix bit assignment for RX packet irq enable

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 121/128] net: mvneta: fix bit assignment for RX packet irq enable
Message-ID<qGon8-4Os-31@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marcin Wojtas <mw@semihalf.com>

commit dc1aadf6f1e7609590fadf7a0252413732289b2e upstream.

A value originally defined in the driver was inappropriate. Even though
the ingress was somehow working, writing MVNETA_RXQ_INTR_ENABLE_ALL_MASK
to MVNETA_INTR_ENABLE didn't make any effect, because the bits [31:16]
are reserved and read-only.

This commit updates MVNETA_RXQ_INTR_ENABLE_ALL_MASK to be compliant with
the controller's documentation.

Signed-off-by: Marcin Wojtas <mw@semihalf.com>

Fixes: c5aff18204da ("net: mvneta: driver for Marvell Armada 370/XP network
unit")
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/ethernet/marvell/mvneta.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/marvell/mvneta.c b/drivers/net/ethernet/marvell/mvneta.c
index 4c715ff..3832570 100644
--- a/drivers/net/ethernet/marvell/mvneta.c
+++ b/drivers/net/ethernet/marvell/mvneta.c
@@ -154,7 +154,7 @@
 
 #define MVNETA_INTR_ENABLE                       0x25b8
 #define      MVNETA_TXQ_INTR_ENABLE_ALL_MASK     0x0000ff00
-#define      MVNETA_RXQ_INTR_ENABLE_ALL_MASK     0xff000000  // note: neta says it's 0x000000FF
+#define      MVNETA_RXQ_INTR_ENABLE_ALL_MASK     0x000000ff
 
 #define MVNETA_RXQ_CMD                           0x2680
 #define      MVNETA_RXQ_DISABLE_SHIFT            8
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293156 — [PATCH 3.19.y-ckt 118/128] bpf, array: fix heap out-of-bounds access when updating elements

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 118/128] bpf, array: fix heap out-of-bounds access when updating elements
Message-ID<qGon8-4Os-25@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <daniel@iogearbox.net>

commit fbca9d2d35c6ef1b323fae75cc9545005ba25097 upstream.

During own review but also reported by Dmitry's syzkaller [1] it has been
noticed that we trigger a heap out-of-bounds access on eBPF array maps
when updating elements. This happens with each map whose map->value_size
(specified during map creation time) is not multiple of 8 bytes.

In array_map_alloc(), elem_size is round_up(attr->value_size, 8) and
used to align array map slots for faster access. However, in function
array_map_update_elem(), we update the element as ...

memcpy(array->value + array->elem_size * index, value, array->elem_size);

... where we access 'value' out-of-bounds, since it was allocated from
map_update_elem() from syscall side as kmalloc(map->value_size, GFP_USER)
and later on copied through copy_from_user(value, uvalue, map->value_size).
Thus, up to 7 bytes, we can access out-of-bounds.

Same could happen from within an eBPF program, where in worst case we
access beyond an eBPF program's designated stack.

Since 1be7f75d1668 ("bpf: enable non-root eBPF programs") didn't hit an
official release yet, it only affects priviledged users.

In case of array_map_lookup_elem(), the verifier prevents eBPF programs
from accessing beyond map->value_size through check_map_access(). Also
from syscall side map_lookup_elem() only copies map->value_size back to
user, so nothing could leak.

  [1] http://github.com/google/syzkaller

Fixes: 28fbcfa08d8e ("bpf: add array type of eBPF maps")
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 kernel/bpf/arraymap.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/kernel/bpf/arraymap.c b/kernel/bpf/arraymap.c
index 9eb4d8a..264073e 100644
--- a/kernel/bpf/arraymap.c
+++ b/kernel/bpf/arraymap.c
@@ -109,7 +109,7 @@ static int array_map_update_elem(struct bpf_map *map, void *key, void *value,
 		/* all elements already exist */
 		return -EEXIST;
 
-	memcpy(array->value + array->elem_size * index, value, array->elem_size);
+	memcpy(array->value + array->elem_size * index, value, map->value_size);
 	return 0;
 }
 
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293157 — [PATCH 3.19.y-ckt 127/128] ipv4: igmp: Allow removing groups from a removed interface

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 127/128] ipv4: igmp: Allow removing groups from a removed interface
Message-ID<qGon8-4Os-27@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Andrew Lunn <andrew@lunn.ch>

commit 4eba7bb1d72d9bde67d810d09bf62dc207b63c5c upstream.

When a multicast group is joined on a socket, a struct ip_mc_socklist
is appended to the sockets mc_list containing information about the
joined group.

If the interface is hot unplugged, this entry becomes stale. Prior to
commit 52ad353a5344f ("igmp: fix the problem when mc leave group") it
was possible to remove the stale entry by performing a
IP_DROP_MEMBERSHIP, passing either the old ifindex or ip address on
the interface. However, this fix enforces that the interface must
still exist. Thus with time, the number of stale entries grows, until
sysctl_igmp_max_memberships is reached and then it is not possible to
join and more groups.

The previous patch fixes an issue where a IP_DROP_MEMBERSHIP is
performed without specifying the interface, either by ifindex or ip
address. However here we do supply one of these. So loosen the
restriction on device existence to only apply when the interface has
not been specified. This then restores the ability to clean up the
stale entries.

Signed-off-by: Andrew Lunn <andrew@lunn.ch>
Fixes: 52ad353a5344f "(igmp: fix the problem when mc leave group")
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/ipv4/igmp.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/net/ipv4/igmp.c b/net/ipv4/igmp.c
index 666cf36..9ffa231 100644
--- a/net/ipv4/igmp.c
+++ b/net/ipv4/igmp.c
@@ -1942,7 +1942,7 @@ int ip_mc_leave_group(struct sock *sk, struct ip_mreqn *imr)
 
 	rtnl_lock();
 	in_dev = ip_mc_find_dev(net, imr);
-	if (!in_dev) {
+	if (!imr->imr_ifindex && !imr->imr_address.s_addr && !in_dev) {
 		ret = -ENODEV;
 		goto out;
 	}
@@ -1963,7 +1963,8 @@ int ip_mc_leave_group(struct sock *sk, struct ip_mreqn *imr)
 
 		*imlp = iml->next_rcu;
 
-		ip_mc_dec_group(in_dev, group);
+		if (in_dev)
+			ip_mc_dec_group(in_dev, group);
 		rtnl_unlock();
 		/* decrease mem now to avoid the memleak warning */
 		atomic_sub(sizeof(*iml), &sk->sk_omem_alloc);
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293158 — [PATCH 3.19.y-ckt 090/128] Bluetooth: Fix l2cap_chan leak in SMP

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 090/128] Bluetooth: Fix l2cap_chan leak in SMP
Message-ID<qGon8-4Os-29@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hedberg <johan.hedberg@intel.com>

commit 7883746bc663150e8acd7a57397fc889698b0b33 upstream.

The L2CAP core expects channel implementations to manage the reference
returned by the new_connection callback. With sockets this is already
handled with each channel being tied to the corresponding socket. With
SMP however there's no context to tie the pointer to in the
smp_new_conn_cb function. The function can also not just drop the
reference since it's the only one at that point.

For fixed channels (like SMP) the code path inside the L2CAP core from
new_connection() to ready() is short and straight-forwards. The
crucial difference is that in ready() the implementation has access to
the l2cap_conn that SMP needs associate its l2cap_chan. Instead of
taking a new reference in smp_ready_cb() we can simply assume to
already own the reference created in smp_new_conn_cb(), i.e. there is
no need to call l2cap_chan_hold().

Signed-off-by: Johan Hedberg <johan.hedberg@intel.com>
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/bluetooth/smp.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/net/bluetooth/smp.c b/net/bluetooth/smp.c
index 757ae32..e7162a4 100644
--- a/net/bluetooth/smp.c
+++ b/net/bluetooth/smp.c
@@ -2812,8 +2812,13 @@ static void smp_ready_cb(struct l2cap_chan *chan)
 
 	BT_DBG("chan %p", chan);
 
+	/* No need to call l2cap_chan_hold() here since we already own
+	 * the reference taken in smp_new_conn_cb(). This is just the
+	 * first time that we tie it to a specific pointer. The code in
+	 * l2cap_core.c ensures that there's no risk this function wont
+	 * get called if smp_new_conn_cb was previously called.
+	 */
 	conn->smp = chan;
-	l2cap_chan_hold(chan);
 
 	if (hcon->type == ACL_LINK && test_bit(HCI_CONN_ENCRYPT, &hcon->flags))
 		bredr_pairing(chan);
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293159 — [PATCH 3.19.y-ckt 095/128] can: sja1000: clear interrupts on start

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 095/128] can: sja1000: clear interrupts on start
Message-ID<qGon8-4Os-35@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mirza Krak <mirza.krak@hostmobility.com>

commit 7cecd9ab80f43972c056dc068338f7bcc407b71c upstream.

According to SJA1000 data sheet error-warning (EI) interrupt is not
cleared by setting the controller in to reset-mode.

Then if we have the following case:
- system is suspended (echo mem > /sys/power/state) and SJA1000 is left
  in operating state
- A bus error condition occurs which activates EI interrupt, system is
  still suspended which means EI interrupt will be not be handled nor
  cleared.

If the above two events occur, on resume there is no way to return the
SJA1000 to operating state, except to cycle power to it.

By simply reading the IR register on start we will clear any previous
conditions that could be present.

Signed-off-by: Mirza Krak <mirza.krak@hostmobility.com>
Reported-by: Christian Magnusson <Christian.Magnusson@semcon.com>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/can/sja1000/sja1000.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/net/can/sja1000/sja1000.c b/drivers/net/can/sja1000/sja1000.c
index 32bd7f4..0c048e2 100644
--- a/drivers/net/can/sja1000/sja1000.c
+++ b/drivers/net/can/sja1000/sja1000.c
@@ -218,6 +218,9 @@ static void sja1000_start(struct net_device *dev)
 	priv->write_reg(priv, SJA1000_RXERR, 0x0);
 	priv->read_reg(priv, SJA1000_ECC);
 
+	/* clear interrupt flags */
+	priv->read_reg(priv, SJA1000_IR);
+
 	/* leave reset mode */
 	set_normal_mode(dev);
 }
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293160 — [PATCH 3.19.y-ckt 109/128] x86/signal: Fix restart_syscall number for x32 tasks

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 109/128] x86/signal: Fix restart_syscall number for x32 tasks
Message-ID<qGon8-4Os-33@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: "Dmitry V. Levin" <ldv@altlinux.org>

commit 22eab1108781eff09961ae7001704f7bd8fb1dce upstream.

When restarting a syscall with regs->ax == -ERESTART_RESTARTBLOCK,
regs->ax is assigned to a restart_syscall number.  For x32 tasks, this
syscall number must have __X32_SYSCALL_BIT set, otherwise it will be
an x86_64 syscall number instead of a valid x32 syscall number. This
issue has been there since the introduction of x32.

Reported-by: strace/tests/restart_syscall.test
Reported-and-tested-by: Elvira Khabirova <lineprinter0@gmail.com>
Signed-off-by: Dmitry V. Levin <ldv@altlinux.org>
Cc: Elvira Khabirova <lineprinter0@gmail.com>
Link: http://lkml.kernel.org/r/20151130215436.GA25996@altlinux.org
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/x86/kernel/signal.c | 17 ++++++++++-------
 1 file changed, 10 insertions(+), 7 deletions(-)

diff --git a/arch/x86/kernel/signal.c b/arch/x86/kernel/signal.c
index ed37a76..11577f5 100644
--- a/arch/x86/kernel/signal.c
+++ b/arch/x86/kernel/signal.c
@@ -684,12 +684,15 @@ handle_signal(struct ksignal *ksig, struct pt_regs *regs)
 	signal_setup_done(failed, ksig, test_thread_flag(TIF_SINGLESTEP));
 }
 
-#ifdef CONFIG_X86_32
-#define NR_restart_syscall	__NR_restart_syscall
-#else /* !CONFIG_X86_32 */
-#define NR_restart_syscall	\
-	test_thread_flag(TIF_IA32) ? __NR_ia32_restart_syscall : __NR_restart_syscall
-#endif /* CONFIG_X86_32 */
+static inline unsigned long get_nr_restart_syscall(const struct pt_regs *regs)
+{
+#if defined(CONFIG_X86_32) || !defined(CONFIG_X86_64)
+	return __NR_restart_syscall;
+#else /* !CONFIG_X86_32 && CONFIG_X86_64 */
+	return test_thread_flag(TIF_IA32) ? __NR_ia32_restart_syscall :
+		__NR_restart_syscall | (regs->orig_ax & __X32_SYSCALL_BIT);
+#endif /* CONFIG_X86_32 || !CONFIG_X86_64 */
+}
 
 /*
  * Note that 'init' is a special process: it doesn't get signals it doesn't
@@ -718,7 +721,7 @@ static void do_signal(struct pt_regs *regs)
 			break;
 
 		case -ERESTART_RESTARTBLOCK:
-			regs->ax = NR_restart_syscall;
+			regs->ax = get_nr_restart_syscall(regs);
 			regs->ip -= 2;
 			break;
 		}
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293161 — [PATCH 3.19.y-ckt 115/128] isdn: Partially revert debug format string usage clean up

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 115/128] isdn: Partially revert debug format string usage clean up
Message-ID<qGon8-4Os-37@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christoph Biedl <linux-kernel.bfrz@manchmal.in-ulm.de>

commit 19cebbcb04c8277bb8a7905957c8af11967c4e28 upstream.

Commit 35a4a57 ("isdn: clean up debug format string usage") introduced
a safeguard to avoid accidential format string interpolation of data
when calling debugl1 or HiSax_putstatus. This did however not take into
account VHiSax_putstatus (called by HiSax_putstatus) does *not* call
vsprintf if the head parameter is NULL - the format string is treated
as plain text then instead. As a result, the string "%s" is processed
literally, and the actual information is lost. This affects the isdnlog
userspace program which stopped logging information since that commit.

So revert the HiSax_putstatus invocations to the previous state.

Fixes: 35a4a5733b0a ("isdn: clean up debug format string usage")
Cc: Kees Cook <keescook@chromium.org>
Cc: Karsten Keil <isdn@linux-pingi.de>
Signed-off-by: Christoph Biedl <linux-kernel.bfrz@manchmal.in-ulm.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/isdn/hisax/config.c  | 2 +-
 drivers/isdn/hisax/hfc_pci.c | 2 +-
 drivers/isdn/hisax/hfc_sx.c  | 2 +-
 drivers/isdn/hisax/q931.c    | 6 +++---
 4 files changed, 6 insertions(+), 6 deletions(-)

diff --git a/drivers/isdn/hisax/config.c b/drivers/isdn/hisax/config.c
index b33f53b..bf04d2a 100644
--- a/drivers/isdn/hisax/config.c
+++ b/drivers/isdn/hisax/config.c
@@ -1896,7 +1896,7 @@ static void EChannel_proc_rcv(struct hisax_d_if *d_if)
 				ptr--;
 				*ptr++ = '\n';
 				*ptr = 0;
-				HiSax_putstatus(cs, NULL, "%s", cs->dlog);
+				HiSax_putstatus(cs, NULL, cs->dlog);
 			} else
 				HiSax_putstatus(cs, "LogEcho: ",
 						"warning Frame too big (%d)",
diff --git a/drivers/isdn/hisax/hfc_pci.c b/drivers/isdn/hisax/hfc_pci.c
index 4a48255..90449e1 100644
--- a/drivers/isdn/hisax/hfc_pci.c
+++ b/drivers/isdn/hisax/hfc_pci.c
@@ -901,7 +901,7 @@ Begin:
 					ptr--;
 					*ptr++ = '\n';
 					*ptr = 0;
-					HiSax_putstatus(cs, NULL, "%s", cs->dlog);
+					HiSax_putstatus(cs, NULL, cs->dlog);
 				} else
 					HiSax_putstatus(cs, "LogEcho: ", "warning Frame too big (%d)", total - 3);
 			}
diff --git a/drivers/isdn/hisax/hfc_sx.c b/drivers/isdn/hisax/hfc_sx.c
index b1fad81..13b2151 100644
--- a/drivers/isdn/hisax/hfc_sx.c
+++ b/drivers/isdn/hisax/hfc_sx.c
@@ -674,7 +674,7 @@ receive_emsg(struct IsdnCardState *cs)
 					ptr--;
 					*ptr++ = '\n';
 					*ptr = 0;
-					HiSax_putstatus(cs, NULL, "%s", cs->dlog);
+					HiSax_putstatus(cs, NULL, cs->dlog);
 				} else
 					HiSax_putstatus(cs, "LogEcho: ", "warning Frame too big (%d)", skb->len);
 			}
diff --git a/drivers/isdn/hisax/q931.c b/drivers/isdn/hisax/q931.c
index b420f8b..ba4beb2 100644
--- a/drivers/isdn/hisax/q931.c
+++ b/drivers/isdn/hisax/q931.c
@@ -1179,7 +1179,7 @@ LogFrame(struct IsdnCardState *cs, u_char *buf, int size)
 		dp--;
 		*dp++ = '\n';
 		*dp = 0;
-		HiSax_putstatus(cs, NULL, "%s", cs->dlog);
+		HiSax_putstatus(cs, NULL, cs->dlog);
 	} else
 		HiSax_putstatus(cs, "LogFrame: ", "warning Frame too big (%d)", size);
 }
@@ -1246,7 +1246,7 @@ dlogframe(struct IsdnCardState *cs, struct sk_buff *skb, int dir)
 	}
 	if (finish) {
 		*dp = 0;
-		HiSax_putstatus(cs, NULL, "%s", cs->dlog);
+		HiSax_putstatus(cs, NULL, cs->dlog);
 		return;
 	}
 	if ((0xfe & buf[0]) == PROTO_DIS_N0) {	/* 1TR6 */
@@ -1509,5 +1509,5 @@ dlogframe(struct IsdnCardState *cs, struct sk_buff *skb, int dir)
 		dp += sprintf(dp, "Unknown protocol %x!", buf[0]);
 	}
 	*dp = 0;
-	HiSax_putstatus(cs, NULL, "%s", cs->dlog);
+	HiSax_putstatus(cs, NULL, cs->dlog);
 }
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293163 — [PATCH 3.19.y-ckt 126/128] broadcom: fix PHY_ID_BCM5481 entry in the id table

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 126/128] broadcom: fix PHY_ID_BCM5481 entry in the id table
Message-ID<qGon8-4Os-43@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aaro Koskinen <aaro.koskinen@iki.fi>

commit 3c25a860d17b7378822f35d8c9141db9507e3beb upstream.

Commit fcb26ec5b18d ("broadcom: move all PHY_ID's to header")
updated broadcom_tbl to use PHY_IDs, but incorrectly replaced 0x0143bca0
with PHY_ID_BCM5482 (making a duplicate entry, and completely omitting
the original). Fix that.

Fixes: fcb26ec5b18d ("broadcom: move all PHY_ID's to header")
Signed-off-by: Aaro Koskinen <aaro.koskinen@iki.fi>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/phy/broadcom.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/phy/broadcom.c b/drivers/net/phy/broadcom.c
index a52afb2..ca5db60 100644
--- a/drivers/net/phy/broadcom.c
+++ b/drivers/net/phy/broadcom.c
@@ -661,7 +661,7 @@ static struct mdio_device_id __maybe_unused broadcom_tbl[] = {
 	{ PHY_ID_BCM5421, 0xfffffff0 },
 	{ PHY_ID_BCM5461, 0xfffffff0 },
 	{ PHY_ID_BCM5464, 0xfffffff0 },
-	{ PHY_ID_BCM5482, 0xfffffff0 },
+	{ PHY_ID_BCM5481, 0xfffffff0 },
 	{ PHY_ID_BCM5482, 0xfffffff0 },
 	{ PHY_ID_BCM50610, 0xfffffff0 },
 	{ PHY_ID_BCM50610M, 0xfffffff0 },
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293164 — [PATCH 3.19.y-ckt 124/128] net: ip6mr: fix static mfc/dev leaks on table destruction

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 124/128] net: ip6mr: fix static mfc/dev leaks on table destruction
Message-ID<qGon8-4Os-41@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>

[ Upstream commit 4c6980462f32b4f282c5d8e5f7ea8070e2937725 ]

Similar to ipv4, when destroying an mrt table the static mfc entries and
the static devices are kept, which leads to devices that can never be
destroyed (because of refcnt taken) and leaked memory. Make sure that
everything is cleaned up on netns destruction.

Fixes: 8229efdaef1e ("netns: ip6mr: enable namespace support in ipv6 multicast forwarding code")
CC: Benjamin Thery <benjamin.thery@bull.net>
Signed-off-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
Reviewed-by: Cong Wang <cwang@twopensource.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/ipv6/ip6mr.c | 15 ++++++++-------
 1 file changed, 8 insertions(+), 7 deletions(-)

diff --git a/net/ipv6/ip6mr.c b/net/ipv6/ip6mr.c
index c7a69e8..b301606 100644
--- a/net/ipv6/ip6mr.c
+++ b/net/ipv6/ip6mr.c
@@ -120,7 +120,7 @@ static void mr6_netlink_event(struct mr6_table *mrt, struct mfc6_cache *mfc,
 			      int cmd);
 static int ip6mr_rtm_dumproute(struct sk_buff *skb,
 			       struct netlink_callback *cb);
-static void mroute_clean_tables(struct mr6_table *mrt);
+static void mroute_clean_tables(struct mr6_table *mrt, bool all);
 static void ipmr_expire_process(unsigned long arg);
 
 #ifdef CONFIG_IPV6_MROUTE_MULTIPLE_TABLES
@@ -337,7 +337,7 @@ static struct mr6_table *ip6mr_new_table(struct net *net, u32 id)
 static void ip6mr_free_table(struct mr6_table *mrt)
 {
 	del_timer(&mrt->ipmr_expire_timer);
-	mroute_clean_tables(mrt);
+	mroute_clean_tables(mrt, true);
 	kfree(mrt);
 }
 
@@ -1540,7 +1540,7 @@ static int ip6mr_mfc_add(struct net *net, struct mr6_table *mrt,
  *	Close the multicast socket, and clear the vif tables etc
  */
 
-static void mroute_clean_tables(struct mr6_table *mrt)
+static void mroute_clean_tables(struct mr6_table *mrt, bool all)
 {
 	int i;
 	LIST_HEAD(list);
@@ -1550,8 +1550,9 @@ static void mroute_clean_tables(struct mr6_table *mrt)
 	 *	Shut down all active vif entries
 	 */
 	for (i = 0; i < mrt->maxvif; i++) {
-		if (!(mrt->vif6_table[i].flags & VIFF_STATIC))
-			mif6_delete(mrt, i, &list);
+		if (!all && (mrt->vif6_table[i].flags & VIFF_STATIC))
+			continue;
+		mif6_delete(mrt, i, &list);
 	}
 	unregister_netdevice_many(&list);
 
@@ -1560,7 +1561,7 @@ static void mroute_clean_tables(struct mr6_table *mrt)
 	 */
 	for (i = 0; i < MFC6_LINES; i++) {
 		list_for_each_entry_safe(c, next, &mrt->mfc6_cache_array[i], list) {
-			if (c->mfc_flags & MFC_STATIC)
+			if (!all && (c->mfc_flags & MFC_STATIC))
 				continue;
 			write_lock_bh(&mrt_lock);
 			list_del(&c->list);
@@ -1623,7 +1624,7 @@ int ip6mr_sk_done(struct sock *sk)
 						     net->ipv6.devconf_all);
 			write_unlock_bh(&mrt_lock);
 
-			mroute_clean_tables(mrt);
+			mroute_clean_tables(mrt, false);
 			err = 0;
 			break;
 		}
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293165 — [PATCH 3.19.y-ckt 128/128] sched/wait: Fix signal handling in bit wait helpers

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 128/128] sched/wait: Fix signal handling in bit wait helpers
Message-ID<qGon9-4Os-45@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Zijlstra <peterz@infradead.org>

commit 68985633bccb6066bf1803e316fbc6c1f5b796d6 upstream.

Vladimir reported getting RCU stall warnings and bisected it back to
commit:

  743162013d40 ("sched: Remove proliferation of wait_on_bit() action functions")

That commit inadvertently reversed the calls to schedule() and signal_pending(),
thereby not handling the case where the signal receives while we sleep.

Reported-by: Vladimir Murzin <vladimir.murzin@arm.com>
Tested-by: Vladimir Murzin <vladimir.murzin@arm.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Mike Galbraith <efault@gmx.de>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: mark.rutland@arm.com
Cc: neilb@suse.de
Cc: oleg@redhat.com
Fixes: 743162013d40 ("sched: Remove proliferation of wait_on_bit() action functions")
Fixes: cbbce8220949 ("SCHED: add some "wait..on_bit...timeout()" interfaces.")
Link: http://lkml.kernel.org/r/20151201130404.GL3816@twins.programming.kicks-ass.net
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 kernel/sched/wait.c | 16 ++++++++--------
 1 file changed, 8 insertions(+), 8 deletions(-)

diff --git a/kernel/sched/wait.c b/kernel/sched/wait.c
index 852143a..e0bb7e6 100644
--- a/kernel/sched/wait.c
+++ b/kernel/sched/wait.c
@@ -583,18 +583,18 @@ EXPORT_SYMBOL(wake_up_atomic_t);
 
 __sched int bit_wait(struct wait_bit_key *word)
 {
-	if (signal_pending_state(current->state, current))
-		return 1;
 	schedule();
+	if (signal_pending(current))
+		return -EINTR;
 	return 0;
 }
 EXPORT_SYMBOL(bit_wait);
 
 __sched int bit_wait_io(struct wait_bit_key *word)
 {
-	if (signal_pending_state(current->state, current))
-		return 1;
 	io_schedule();
+	if (signal_pending(current))
+		return -EINTR;
 	return 0;
 }
 EXPORT_SYMBOL(bit_wait_io);
@@ -602,11 +602,11 @@ EXPORT_SYMBOL(bit_wait_io);
 __sched int bit_wait_timeout(struct wait_bit_key *word)
 {
 	unsigned long now = ACCESS_ONCE(jiffies);
-	if (signal_pending_state(current->state, current))
-		return 1;
 	if (time_after_eq(now, word->timeout))
 		return -EAGAIN;
 	schedule_timeout(word->timeout - now);
+	if (signal_pending(current))
+		return -EINTR;
 	return 0;
 }
 EXPORT_SYMBOL_GPL(bit_wait_timeout);
@@ -614,11 +614,11 @@ EXPORT_SYMBOL_GPL(bit_wait_timeout);
 __sched int bit_wait_io_timeout(struct wait_bit_key *word)
 {
 	unsigned long now = ACCESS_ONCE(jiffies);
-	if (signal_pending_state(current->state, current))
-		return 1;
 	if (time_after_eq(now, word->timeout))
 		return -EAGAIN;
 	io_schedule_timeout(word->timeout - now);
+	if (signal_pending(current))
+		return -EINTR;
 	return 0;
 }
 EXPORT_SYMBOL_GPL(bit_wait_io_timeout);
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293201 — Re: [PATCH 3.19.y-ckt 128/128] sched/wait: Fix signal handling in bit wait helpers

FromOleg Nesterov <oleg@redhat.com>
Date2015-12-16 19:00 +0100
SubjectRe: [PATCH 3.19.y-ckt 128/128] sched/wait: Fix signal handling in bit wait helpers
Message-ID<qGowQ-4RZ-43@gated-at.bofh.it>
In reply to#1293165
On 12/16, Kamal Mostafa wrote:
>
> 3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.
>
>
> commit 68985633bccb6066bf1803e316fbc6c1f5b796d6 upstream.

Please note that this patch is wrong without the next fix from Peter.

And in fact to me it is still not clear whether we really want to do
this, this probably needs more investigation.

Oleg.

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293229 — Re: [PATCH 3.19.y-ckt 128/128] sched/wait: Fix signal handling in bit wait helpers

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 19:10 +0100
SubjectRe: [PATCH 3.19.y-ckt 128/128] sched/wait: Fix signal handling in bit wait helpers
Message-ID<qGoGw-5ba-31@gated-at.bofh.it>
In reply to#1293201
On Wed, 2015-12-16 at 18:57 +0100, Oleg Nesterov wrote:
> On 12/16, Kamal Mostafa wrote:
> >
> > 3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.
> >
> >
> > commit 68985633bccb6066bf1803e316fbc6c1f5b796d6 upstream.
> 
> Please note that this patch is wrong without the next fix from Peter.
> 
> And in fact to me it is still not clear whether we really want to do
> this, this probably needs more investigation.
> 
> Oleg.
> 

Thanks for the heads-up, Linus and Oleg.  I'll just hold both of them
out of 3.19-stable until the dust settles.

Deferred until next 3.19 cycle:

6898563 sched/wait: Fix signal handling in bit wait helpers
dfd01f0 sched/wait: Fix the signal handling fix

 -Kamal

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1293166 — [PATCH 3.19.y-ckt 003/128] iio:ad5064: Make sure ad5064_i2c_write() returns 0 on success

FromKamal Mostafa <kamal@canonical.com>
Date2015-12-16 18:50 +0100
Subject[PATCH 3.19.y-ckt 003/128] iio:ad5064: Make sure ad5064_i2c_write() returns 0 on success
Message-ID<qGon9-4Os-49@gated-at.bofh.it>
In reply to#1293144
3.19.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Hennerich <michael.hennerich@analog.com>

commit 03fe472ef33b7f31fbd11d300dbb3fdab9c00fd4 upstream.

i2c_master_send() returns the number of bytes transferred on success while
the ad5064 driver expects that the write() callback returns 0 on success.
Fix that by translating any non negative return value of i2c_master_send()
to 0.

Fixes: commit 6a17a0768f77 ("iio:dac:ad5064: Add support for the ad5629r and ad5669r")
Signed-off-by: Michael Hennerich <michael.hennerich@analog.com>
Signed-off-by: Lars-Peter Clausen <lars@metafoo.de>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/iio/dac/ad5064.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/drivers/iio/dac/ad5064.c b/drivers/iio/dac/ad5064.c
index f03b92f..1b43069 100644
--- a/drivers/iio/dac/ad5064.c
+++ b/drivers/iio/dac/ad5064.c
@@ -598,10 +598,16 @@ static int ad5064_i2c_write(struct ad5064_state *st, unsigned int cmd,
 	unsigned int addr, unsigned int val)
 {
 	struct i2c_client *i2c = to_i2c_client(st->dev);
+	int ret;
 
 	st->data.i2c[0] = (cmd << 4) | addr;
 	put_unaligned_be16(val, &st->data.i2c[1]);
-	return i2c_master_send(i2c, st->data.i2c, 3);
+
+	ret = i2c_master_send(i2c, st->data.i2c, 3);
+	if (ret < 0)
+		return ret;
+
+	return 0;
 }
 
 static int ad5064_i2c_probe(struct i2c_client *i2c,
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


Page 1 of 7  [1] 2 3 4 5 6 7  Next page →

Back to top | Article view | linux.kernel


csiph-web