Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1312635 > unrolled thread

[3.19.y-ckt stable] Linux 3.19.8-ckt13 stable review

Started byKamal Mostafa <kamal@canonical.com>
First post2016-01-20 02:10 +0100
Last post2016-01-20 03:00 +0100
Articles 20 on this page of 158 — 1 participant

Back to article view | Back to linux.kernel


Contents

  [3.19.y-ckt stable] Linux 3.19.8-ckt13 stable review Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:10 +0100
    [PATCH 3.19.y-ckt 030/160] USB: cdc_acm: Ignore Infineon Flash Loader utility Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:10 +0100
    [PATCH 3.19.y-ckt 026/160] fuse: break infinite loop in fuse_fill_write_pages() Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:10 +0100
    [PATCH 3.19.y-ckt 156/160] net: filter: make JITs zero A for SKF_AD_ALU_XOR_X Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 059/160] ALSA: hda - Fixing speaker noise on the two latest thinkpad models Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 024/160] tools: Add a "make all" rule Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 040/160] irqchip/versatile-fpga: Fix PCI IRQ mapping on Versatile PB Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 131/160] mm/memory_hotplug.c: check for missing sections in test_pages_in_a_zone() Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 085/160] mm, vmstat: allow WQ concurrency to discover memory reclaim doesn't make any progress Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 052/160] net: mvpp2: fix refilling BM pools in RX path Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 063/160] radeon: Fix VCE IB test on Big-Endian systems Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 018/160] pptp: verify sockaddr_len in pptp_bind() and pptp_connect() Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 028/160] iio: fix some warning messages Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 037/160] sata_sil: disable trim Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 143/160] pinctrl: bcm2835: Fix initial value for direction_output Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 086/160] mm: hugetlb: call huge_pte_alloc() only if ptep is null Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 048/160] usb: xhci: fix config fail of FS hub behind a HS hub with MTT Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 134/160] tile: provide CONFIG_PAGE_SIZE_64KB etc for tilepro Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 088/160] ocfs2: fix SGID not inherited issue Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 148/160] qlcnic: fix a timeout loop Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 072/160] rfkill: copy the name into the rfkill struct Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 139/160] vmstat: allocate vmstat_wq before it is used Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 005/160] ip6mr: call del_timer_sync() in ip6mr_free_table() Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 159/160] kvm: x86: only channel 0 of the i8254 is linked to the HPET Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 060/160] 9p: ->evict_inode() should kick out ->i_data, not ->i_mapping Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 097/160] ALSA: hda - Add a fixup for Thinkpad X1 Carbon 2nd Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 108/160] xen: Add RING_COPY_REQUEST() Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 019/160] bluetooth: Validate socket address length in sco_sock_bind(). Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 074/160] ses: Fix problems with simple enclosures Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 122/160] USB: fix invalid memory access in hub_activate() Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 133/160] tracing: Fix setting of start_index in find_next() Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 033/160] jbd2: Fix unreclaimed pages after truncate in data=journal mode Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 120/160] [media] airspy: increase USB control message buffer size Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 073/160] dm btree: fix bufio buffer leaks in dm_btree_del() error path Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 035/160] i2c: mv64xxx: The n clockdiv factor is 0 based on sunxi SoCs Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 101/160] ftrace/scripts: Have recordmcount copy the object file Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 057/160] IB/srp: Fix a memory leak Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 004/160] ARC: Fix silly typo in MAINTAINERS file Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 098/160] spi: fix parent-device reference leak Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 069/160] ipmi: move timer init to before irq is setup Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 127/160] MIPS: uaccess: Fix strlen_user with EVA Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 099/160] scripts: recordmcount: break hardlinks Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 102/160] ARC: dw2 unwind: Reinstante unwinding out of modules Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 119/160] xen/pciback: Don't allow MSI-X ops if PCI_COMMAND_MEMORY is not set. Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 003/160] sched/wait: Fix the signal handling fix Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 042/160] USB: whci-hcd: add check for dma mapping error Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 017/160] skbuff: Fix offset error in skb_reorder_vlan_header Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 125/160] parisc: Fix syscall restarts Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 152/160] net/mlx4_en: Fix HW timestamp init issue upon system startup Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 050/160] net: mvpp2: fix missing DMA region unmap in egress processing Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 062/160] radeon: Fix VCE ring test for Big-Endian systems Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 113/160] xen-scsiback: safely copy requests Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 112/160] xen-blkback: read from indirect descriptors only once Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 084/160] vmstat: Reduce time interval to stat update on idle cpu Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 066/160] ALSA: hda - Fix noise problems on Thinkpad T440s Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:20 +0100
    [PATCH 3.19.y-ckt 068/160] dm space map metadata: fix ref counting bug when bootstrapping a new space map Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 124/160] i2c: rcar: disable runtime PM correctly in slave mode Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 034/160] drm/ttm: Fixed a read/write lock imbalance Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 020/160] fou: clean up socket with kfree_rcu Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 039/160] staging: lustre: echo_copy.._lsm() dereferences userland pointers directly Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 016/160] vlan: Fix untag operations of stacked vlans with REORDER_HEADER off Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 014/160] sh_eth: fix kernel oops in skb_put() Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 111/160] xen-blkback: only read request operation from shared ring once Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 155/160] ASoC: Use nested lock for snd_soc_dapm_mutex_lock Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 138/160] ftrace/module: Call clean up function when module init fails early Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 144/160] net: phy: mdio-mux: Check return value of mdiobus_alloc() Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 121/160] USB: ipaq.c: fix a timeout loop Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 095/160] ARM: dts: imx6: Fix Ethernet PHY mode on Ventana boards Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 137/160] dts: vt8500: Add SDHC node to DTS file for WM8650 Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 130/160] ocfs2: fix BUG when calculate new backup super Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 031/160] USB: serial: Another Infineon flash loader USB ID Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 045/160] dm btree: fix leak of bufio-backed block in btree_split_sibling error path Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 071/160] KVM: PPC: Book3S HV: Prohibit setting illegal transaction state in MSR Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 082/160] parisc iommu: fix panic due to trying to allocate too large region Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 044/160] xen/events/fifo: Consume unprocessed events when a CPU dies Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 115/160] xen/pciback: Return error on XEN_PCI_OP_enable_msi when device has MSI or MSI-X enabled Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 087/160] drivers/base/memory.c: prohibit offlining of memory blocks with missing sections Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 091/160] n_tty: Fix poll() after buffer-limited eof push read Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 015/160] net: fix IP early demux races Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 038/160] usb-storage: Fix scsi-sd failure "Invalid field in cdb" for USB adapter JMicron Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 154/160] ipv6/addrlabel: fix ip6addrlbl_get() Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 114/160] xen/pciback: Save xen_pci_op commands before processing it Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 011/160] net: qca_spi: fix transmit queue timeout handling Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 058/160] IB/srp: Fix possible send queue overflow Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 077/160] ARM: dts: vf610: use reset values for L2 cache latencies Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 006/160] gre6: allow to update all parameters via rtnl Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 001/160] [3.19-stable only] Revert "perf symbols: Fix dso lookup by long name and missing buildids" Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 029/160] USB: cp210x: Remove CP2110 ID from compatibility list Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:30 +0100
    [PATCH 3.19.y-ckt 032/160] ext4: Fix handling of extended tv_sec Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 129/160] [PATCH] arm: fix handling of F_OFD_... in oabi_fcntl64() Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 149/160] ser_gigaset: fix deallocation of platform device structure Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 065/160] crypto: skcipher - Copy iv from desc even for 0-len walks Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 117/160] xen/pciback: Do not install an IRQ handler for MSI interrupts. Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 153/160] include/linux/mmdebug.h: should include linux/bug.h Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 126/160] ALSA: hda/realtek - Fix silent headphone output on MacPro 4,1 (v2) Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 041/160] usb: core : hub: Fix BOS 'NULL pointer' kernel panic Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 022/160] KEYS: Fix race between read and revoke Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 151/160] net/mlx4_en: Remove dependency between timestamping capability and service_task Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 118/160] xen/pciback: For XEN_PCI_OP_disable_msi[|x] only disable if device has MSI(X) enabled. Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 008/160] sctp: use the same clock as if sock source timestamps were on Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 136/160] async_tx: use GFP_NOWAIT rather than GFP_IO Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 100/160] dma-debug: Fix dma_debug_entry offset calculation Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 090/160] ASoC: wm8974: set cache type for regmap Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 047/160] perf: Fix PERF_EVENT_IOC_PERIOD deadlock Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 027/160] usb: gadget: pxa27x: fix suspend callback Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 150/160] net: fix warnings in 'make htmldocs' by moving macro definition out of field declaration Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 092/160] tty: Fix GPF in flush_to_ldisc() Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 064/160] video: fbdev: fsl: Fix kernel crash when diu_ops is not implemented Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 053/160] dmaengine: at_xdmac: fix macro typo Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 076/160] ASoC: davinci-mcasp: Fix XDATA check in mcasp_start_tx Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 142/160] sctp: start t5 timer only when peer rwnd is 0 and local state is SHUTDOWN_PENDING Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 036/160] AHCI: Fix softreset failed issue of Port Multiplier Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 147/160] amd-xgbe: fix a couple timeout loops Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 141/160] sctp: convert sack_needed and sack_generation to bits Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 093/160] genirq: Prevent chip buslock deadlock Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 104/160] powerpc/powernv: Fix the overflow of OPAL message notifiers head array Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 107/160] s390/dis: Fix handling of format specifiers Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 106/160] ALSA: hda - Set SKL+ hda controller power at freeze() and thaw() Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 128/160] ASoC: arizona: Fix bclk for sample rates that are multiple of 4kHz Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:40 +0100
    [PATCH 3.19.y-ckt 009/160] sctp: update the netstamp_needed counter when copying sockets Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 116/160] xen/pciback: Return error on XEN_PCI_OP_enable_msix when device has MSI or MSI-X enabled Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 110/160] xen-netback: use RING_COPY_REQUEST() throughout Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 158/160] net: possible use after free in dst_release Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 051/160] net: mvpp2: fix buffers' DMA handling on RX path Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 055/160] vhost: relax log address alignment Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 067/160] dm thin metadata: fix bug when taking a metadata snapshot Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 160/160] firmware: dmi_scan: Fix UUID endianness for SMBIOS >= 2.6 Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 046/160] ARM: 8465/1: mm: keep reserved ASIDs in sync with mm after multiple rollovers Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 010/160] sctp: also copy sk_tsflags when copying the socket Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 103/160] ARC: dw2 unwind: Ignore CIE version !=1 gracefully instead of bailing Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 002/160] sched/wait: Fix signal handling in bit wait helpers Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 109/160] xen-netback: don't use last request to determine minimum Tx credit Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 105/160] powerpc/powernv: pr_warn_once on unsupported OPAL_MSG type Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 081/160] powercap / RAPL: fix BIOS lock check Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 023/160] KVM: x86: Reload pit counters for all channels when restoring state Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 080/160] USB: add quirk for devices with broken LPM Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 021/160] af_unix: Revert 'lock_interruptible' in stream receive code Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 049/160] ALSA: rme96: Fix unexpected volume reset after rate changes Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 079/160] xhci: fix usb2 resume timing and races. Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 132/160] ftrace/scripts: Fix incorrect use of sprintf in recordmcount Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 056/160] virtio: fix memory leak of virtio ida cache layers Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 007/160] atl1c: Improve driver not to do order 4 GFP_ATOMIC allocation Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 140/160] usb: musb: USB_TI_CPPI41_DMA requires dmaengine support Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 083/160] mm: hugetlb: fix hugepage memory leak caused by wrong reserve count Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 094/160] ALSA: usb-audio: Add a more accurate volume quirk for AudioQuest DragonFly Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 157/160] net: sched: fix missing free per cpu on qstats Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 135/160] ARM: versatile: fix MMC/SD interrupt assignment Kamal Mostafa <kamal@canonical.com> - 2016-01-20 02:50 +0100
    [PATCH 3.19.y-ckt 070/160] ASoC: es8328: Fix deemphasis values Kamal Mostafa <kamal@canonical.com> - 2016-01-20 03:00 +0100
    [PATCH 3.19.y-ckt 096/160] ARM: 8471/1: need to save/restore arm register(r11) when it is corrupted Kamal Mostafa <kamal@canonical.com> - 2016-01-20 03:00 +0100
    [PATCH 3.19.y-ckt 061/160] radeon/cik: Fix GFX IB test on Big-Endian Kamal Mostafa <kamal@canonical.com> - 2016-01-20 03:00 +0100
    [PATCH 3.19.y-ckt 043/160] usb: Use the USB_SS_MULT() macro to decode burst multiplier for log message Kamal Mostafa <kamal@canonical.com> - 2016-01-20 03:00 +0100
    [PATCH 3.19.y-ckt 146/160] mISDN: fix a loop count Kamal Mostafa <kamal@canonical.com> - 2016-01-20 03:00 +0100
    [PATCH 3.19.y-ckt 145/160] sh_eth: fix TX buffer byte-swapping Kamal Mostafa <kamal@canonical.com> - 2016-01-20 03:00 +0100
    [PATCH 3.19.y-ckt 123/160] x86/mce: Ensure offline CPUs don't participate in rendezvous process Kamal Mostafa <kamal@canonical.com> - 2016-01-20 03:00 +0100
    [PATCH 3.19.y-ckt 013/160] net: add validation for the socket syscall protocol argument Kamal Mostafa <kamal@canonical.com> - 2016-01-20 03:00 +0100
    [PATCH 3.19.y-ckt 078/160] ses: fix additional element traversal bug Kamal Mostafa <kamal@canonical.com> - 2016-01-20 03:00 +0100
    [PATCH 3.19.y-ckt 075/160] vgaarb: fix signal handling in vga_get() Kamal Mostafa <kamal@canonical.com> - 2016-01-20 03:00 +0100
    [PATCH 3.19.y-ckt 089/160] sh64: fix __NR_fgetxattr Kamal Mostafa <kamal@canonical.com> - 2016-01-20 03:00 +0100

Page 2 of 8 — ← Prev page 1 [2] 3 4 5 6 7 8  Next page →


#1312657 — [PATCH 3.19.y-ckt 072/160] rfkill: copy the name into the rfkill struct

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 072/160] rfkill: copy the name into the rfkill struct
Message-ID<qSPBh-7xH-35@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Johannes Berg <johannes.berg@intel.com>

commit b7bb110008607a915298bf0f47d25886ecb94477 upstream.

Some users of rfkill, like NFC and cfg80211, use a dynamic name when
allocating rfkill, in those cases dev_name(). Therefore, the pointer
passed to rfkill_alloc() might not be valid forever, I specifically
found the case that the rfkill name was quite obviously an invalid
pointer (or at least garbage) when the wiphy had been renamed.

Fix this by making a copy of the rfkill name in rfkill_alloc().

Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/rfkill/core.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/net/rfkill/core.c b/net/rfkill/core.c
index fa7cd79..4b333ed 100644
--- a/net/rfkill/core.c
+++ b/net/rfkill/core.c
@@ -49,7 +49,6 @@
 struct rfkill {
 	spinlock_t		lock;
 
-	const char		*name;
 	enum rfkill_type	type;
 
 	unsigned long		state;
@@ -73,6 +72,7 @@ struct rfkill {
 	struct delayed_work	poll_work;
 	struct work_struct	uevent_work;
 	struct work_struct	sync_work;
+	char			name[];
 };
 #define to_rfkill(d)	container_of(d, struct rfkill, dev)
 
@@ -862,14 +862,14 @@ struct rfkill * __must_check rfkill_alloc(const char *name,
 	if (WARN_ON(type == RFKILL_TYPE_ALL || type >= NUM_RFKILL_TYPES))
 		return NULL;
 
-	rfkill = kzalloc(sizeof(*rfkill), GFP_KERNEL);
+	rfkill = kzalloc(sizeof(*rfkill) + strlen(name) + 1, GFP_KERNEL);
 	if (!rfkill)
 		return NULL;
 
 	spin_lock_init(&rfkill->lock);
 	INIT_LIST_HEAD(&rfkill->node);
 	rfkill->type = type;
-	rfkill->name = name;
+	strcpy(rfkill->name, name);
 	rfkill->ops = ops;
 	rfkill->data = ops_data;
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312658 — [PATCH 3.19.y-ckt 139/160] vmstat: allocate vmstat_wq before it is used

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 139/160] vmstat: allocate vmstat_wq before it is used
Message-ID<qSPBh-7xH-37@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Michal Hocko <mhocko@suse.com>

commit 751e5f5c753e8d447bcf89f9e96b9616ac081628 upstream.

kernel test robot has reported the following crash:

  BUG: unable to handle kernel NULL pointer dereference at 00000100
  IP: [<c1074df6>] __queue_work+0x26/0x390
  *pdpt = 0000000000000000 *pde = f000ff53f000ff53 *pde = f000ff53f000ff53
  Oops: 0000 [#1] PREEMPT PREEMPT SMP SMP
  CPU: 0 PID: 24 Comm: kworker/0:1 Not tainted 4.4.0-rc4-00139-g373ccbe #1
  Workqueue: events vmstat_shepherd
  task: cb684600 ti: cb7ba000 task.ti: cb7ba000
  EIP: 0060:[<c1074df6>] EFLAGS: 00010046 CPU: 0
  EIP is at __queue_work+0x26/0x390
  EAX: 00000046 EBX: cbb37800 ECX: cbb37800 EDX: 00000000
  ESI: 00000000 EDI: 00000000 EBP: cb7bbe68 ESP: cb7bbe38
   DS: 007b ES: 007b FS: 00d8 GS: 00e0 SS: 0068
  CR0: 8005003b CR2: 00000100 CR3: 01fd5000 CR4: 000006b0
  Stack:
  Call Trace:
    __queue_delayed_work+0xa1/0x160
    queue_delayed_work_on+0x36/0x60
    vmstat_shepherd+0xad/0xf0
    process_one_work+0x1aa/0x4c0
    worker_thread+0x41/0x440
    kthread+0xb0/0xd0
    ret_from_kernel_thread+0x21/0x40

The reason is that start_shepherd_timer schedules the shepherd work item
which uses vmstat_wq (vmstat_shepherd) before setup_vmstat allocates
that workqueue so if the further initialization takes more than HZ we
might end up scheduling on a NULL vmstat_wq.  This is really unlikely
but not impossible.

Fixes: 373ccbe59270 ("mm, vmstat: allow WQ concurrency to discover memory reclaim doesn't make any progress")
Reported-by: kernel test robot <ying.huang@linux.intel.com>
Signed-off-by: Michal Hocko <mhocko@suse.com>
Tested-by: Tetsuo Handa <penguin-kernel@i-love.sakura.ne.jp>
Cc: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 mm/vmstat.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/mm/vmstat.c b/mm/vmstat.c
index 6a15b8d..24503df 100644
--- a/mm/vmstat.c
+++ b/mm/vmstat.c
@@ -1459,6 +1459,7 @@ static void __init start_shepherd_timer(void)
 		BUG();
 	cpumask_copy(cpu_stat_off, cpu_online_mask);
 
+	vmstat_wq = alloc_workqueue("vmstat", WQ_FREEZABLE|WQ_MEM_RECLAIM, 0);
 	schedule_delayed_work(&shepherd,
 		round_jiffies_relative(sysctl_stat_interval));
 }
@@ -1526,7 +1527,6 @@ static int __init setup_vmstat(void)
 
 	start_shepherd_timer();
 	cpu_notifier_register_done();
-	vmstat_wq = alloc_workqueue("vmstat", WQ_FREEZABLE|WQ_MEM_RECLAIM, 0);
 #endif
 #ifdef CONFIG_PROC_FS
 	proc_create("buddyinfo", S_IRUGO, NULL, &fragmentation_file_operations);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312659 — [PATCH 3.19.y-ckt 005/160] ip6mr: call del_timer_sync() in ip6mr_free_table()

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 005/160] ip6mr: call del_timer_sync() in ip6mr_free_table()
Message-ID<qSPBh-7xH-41@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: WANG Cong <xiyou.wangcong@gmail.com>

commit 7ba0c47c34a1ea5bc7a24ca67309996cce0569b5 upstream.

We need to wait for the flying timers, since we
are going to free the mrtable right after it.

Cc: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/ipv6/ip6mr.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/ipv6/ip6mr.c b/net/ipv6/ip6mr.c
index b301606..becb4d7 100644
--- a/net/ipv6/ip6mr.c
+++ b/net/ipv6/ip6mr.c
@@ -336,7 +336,7 @@ static struct mr6_table *ip6mr_new_table(struct net *net, u32 id)
 
 static void ip6mr_free_table(struct mr6_table *mrt)
 {
-	del_timer(&mrt->ipmr_expire_timer);
+	del_timer_sync(&mrt->ipmr_expire_timer);
 	mroute_clean_tables(mrt, true);
 	kfree(mrt);
 }
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312660 — [PATCH 3.19.y-ckt 159/160] kvm: x86: only channel 0 of the i8254 is linked to the HPET

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 159/160] kvm: x86: only channel 0 of the i8254 is linked to the HPET
Message-ID<qSPBi-7xH-43@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Paolo Bonzini <pbonzini@redhat.com>

commit e5e57e7a03b1cdcb98e4aed135def2a08cbf3257 upstream.

While setting the KVM PIT counters in 'kvm_pit_load_count', if
'hpet_legacy_start' is set, the function disables the timer on
channel[0], instead of the respective index 'channel'. This is
because channels 1-3 are not linked to the HPET.  Fix the caller
to only activate the special HPET processing for channel 0.

Reported-by: P J P <pjp@fedoraproject.org>
Fixes: 0185604c2d82c560dab2f2933a18f797e74ab5a8
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/x86/kvm/i8254.c | 1 +
 arch/x86/kvm/x86.c   | 3 ++-
 2 files changed, 3 insertions(+), 1 deletion(-)

diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
index 1406ffd..f2006e6 100644
--- a/arch/x86/kvm/i8254.c
+++ b/arch/x86/kvm/i8254.c
@@ -418,6 +418,7 @@ void kvm_pit_load_count(struct kvm *kvm, int channel, u32 val, int hpet_legacy_s
 	u8 saved_mode;
 	if (hpet_legacy_start) {
 		/* save existing mode for later reenablement */
+		WARN_ON(channel != 0);
 		saved_mode = kvm->arch.vpit->pit_state.channels[0].mode;
 		kvm->arch.vpit->pit_state.channels[0].mode = 0xff; /* disable timer */
 		pit_load_count(kvm, channel, val);
diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index 34f4e00..e279282 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -3716,7 +3716,8 @@ static int kvm_vm_ioctl_set_pit2(struct kvm *kvm, struct kvm_pit_state2 *ps)
 	       sizeof(kvm->arch.vpit->pit_state.channels));
 	kvm->arch.vpit->pit_state.flags = ps->flags;
 	for (i = 0; i < 3; i++)
-		kvm_pit_load_count(kvm, i, kvm->arch.vpit->pit_state.channels[i].count, start);
+		kvm_pit_load_count(kvm, i, kvm->arch.vpit->pit_state.channels[i].count,
+				   start && i == 0);
 	mutex_unlock(&kvm->arch.vpit->pit_state.lock);
 	return r;
 }
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312661 — [PATCH 3.19.y-ckt 060/160] 9p: ->evict_inode() should kick out ->i_data, not ->i_mapping

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 060/160] 9p: ->evict_inode() should kick out ->i_data, not ->i_mapping
Message-ID<qSPBi-7xH-47@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Al Viro <viro@zeniv.linux.org.uk>

commit 4ad78628445d26e5e9487b2e8f23274ad7b0f5d3 upstream.

For block devices the pagecache is associated with the inode
on bdevfs, not with the aliasing ones on the mountable filesystems.
The latter have its own ->i_data empty and ->i_mapping pointing
to the (unique per major/minor) bdevfs inode.  That guarantees
cache coherence between all block device inodes with the same
device number.

Eviction of an alias inode has no business trying to evict the
pages belonging to bdevfs one; moreover, ->i_mapping is only
safe to access when the thing is opened.  At the time of
->evict_inode() the victim is definitely *not* opened.  We are
about to kill the address space embedded into struct inode
(inode->i_data) and that's what we need to empty of any pages.

9p instance tries to empty inode->i_mapping instead, which is
both unsafe and bogus - if we have several device nodes with
the same device number in different places, closing one of them
should not try to empty the (shared) page cache.

Fortunately, other instances in the tree are OK; they are
evicting from &inode->i_data instead, as 9p one should.

Reported-by: "Suzuki K. Poulose" <Suzuki.Poulose@arm.com>
Tested-by: "Suzuki K. Poulose" <Suzuki.Poulose@arm.com>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/9p/vfs_inode.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/fs/9p/vfs_inode.c b/fs/9p/vfs_inode.c
index 2533005..711d744 100644
--- a/fs/9p/vfs_inode.c
+++ b/fs/9p/vfs_inode.c
@@ -451,9 +451,9 @@ void v9fs_evict_inode(struct inode *inode)
 {
 	struct v9fs_inode *v9inode = V9FS_I(inode);
 
-	truncate_inode_pages_final(inode->i_mapping);
+	truncate_inode_pages_final(&inode->i_data);
 	clear_inode(inode);
-	filemap_fdatawrite(inode->i_mapping);
+	filemap_fdatawrite(&inode->i_data);
 
 	v9fs_cache_inode_put_cookie(inode);
 	/* clunk the fid stashed in writeback_fid */
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312662 — [PATCH 3.19.y-ckt 097/160] ALSA: hda - Add a fixup for Thinkpad X1 Carbon 2nd

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 097/160] ALSA: hda - Add a fixup for Thinkpad X1 Carbon 2nd
Message-ID<qSPBi-7xH-45@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit b6903c0ed9f0bcbbe88f67f7ed43d1721cbc6235 upstream.

Apply the same fixup for Thinkpad with dock to Thinkpad X1 Carbon 2nd,
too.  This reduces the annoying loud cracking noise problem, as well
as the support of missing docking port.

Bugzilla: https://bugzilla.suse.com/show_bug.cgi?id=958439
Reported-and-tested-by: Benjamin Poirier <bpoirier@suse.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/pci/hda/patch_realtek.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index 1fdddc7..9d49d79 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -5041,6 +5041,7 @@ static const struct snd_pci_quirk alc269_fixup_tbl[] = {
 	SND_PCI_QUIRK(0x17aa, 0x2212, "Thinkpad T440", ALC292_FIXUP_TPT440_DOCK),
 	SND_PCI_QUIRK(0x17aa, 0x2214, "Thinkpad X240", ALC292_FIXUP_TPT440_DOCK),
 	SND_PCI_QUIRK(0x17aa, 0x2215, "Thinkpad", ALC269_FIXUP_LIMIT_INT_MIC_BOOST),
+	SND_PCI_QUIRK(0x17aa, 0x2218, "Thinkpad X1 Carbon 2nd", ALC292_FIXUP_TPT440_DOCK),
 	SND_PCI_QUIRK(0x17aa, 0x2223, "ThinkPad T550", ALC292_FIXUP_TPT440_DOCK),
 	SND_PCI_QUIRK(0x17aa, 0x2226, "ThinkPad X250", ALC292_FIXUP_TPT440_DOCK),
 	SND_PCI_QUIRK(0x17aa, 0x2233, "Thinkpad", ALC293_FIXUP_LENOVO_SPK_NOISE),
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312663 — [PATCH 3.19.y-ckt 108/160] xen: Add RING_COPY_REQUEST()

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 108/160] xen: Add RING_COPY_REQUEST()
Message-ID<qSPBi-7xH-49@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: David Vrabel <david.vrabel@citrix.com>

commit 454d5d882c7e412b840e3c99010fe81a9862f6fb upstream.

Using RING_GET_REQUEST() on a shared ring is easy to use incorrectly
(i.e., by not considering that the other end may alter the data in the
shared ring while it is being inspected).  Safe usage of a request
generally requires taking a local copy.

Provide a RING_COPY_REQUEST() macro to use instead of
RING_GET_REQUEST() and an open-coded memcpy().  This takes care of
ensuring that the copy is done correctly regardless of any possible
compiler optimizations.

Use a volatile source to prevent the compiler from reordering or
omitting the copy.

This is part of XSA155.

Signed-off-by: David Vrabel <david.vrabel@citrix.com>
Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 include/xen/interface/io/ring.h | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git a/include/xen/interface/io/ring.h b/include/xen/interface/io/ring.h
index 7d28aff..7dc685b 100644
--- a/include/xen/interface/io/ring.h
+++ b/include/xen/interface/io/ring.h
@@ -181,6 +181,20 @@ struct __name##_back_ring {						\
 #define RING_GET_REQUEST(_r, _idx)					\
     (&((_r)->sring->ring[((_idx) & (RING_SIZE(_r) - 1))].req))
 
+/*
+ * Get a local copy of a request.
+ *
+ * Use this in preference to RING_GET_REQUEST() so all processing is
+ * done on a local copy that cannot be modified by the other end.
+ *
+ * Note that https://gcc.gnu.org/bugzilla/show_bug.cgi?id=58145 may cause this
+ * to be ineffective where _req is a struct which consists of only bitfields.
+ */
+#define RING_COPY_REQUEST(_r, _idx, _req) do {				\
+	/* Use volatile to force the copy into _req. */			\
+	*(_req) = *(volatile typeof(_req))RING_GET_REQUEST(_r, _idx);	\
+} while (0)
+
 #define RING_GET_RESPONSE(_r, _idx)					\
     (&((_r)->sring->ring[((_idx) & (RING_SIZE(_r) - 1))].rsp))
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312664 — [PATCH 3.19.y-ckt 019/160] bluetooth: Validate socket address length in sco_sock_bind().

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 019/160] bluetooth: Validate socket address length in sco_sock_bind().
Message-ID<qSPBi-7xH-51@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: "David S. Miller" <davem@davemloft.net>

[ Upstream commit 5233252fce714053f0151680933571a2da9cbfb4 ]

Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/bluetooth/sco.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/net/bluetooth/sco.c b/net/bluetooth/sco.c
index 30e5ea3..d050224 100644
--- a/net/bluetooth/sco.c
+++ b/net/bluetooth/sco.c
@@ -520,6 +520,9 @@ static int sco_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_le
 	if (!addr || addr->sa_family != AF_BLUETOOTH)
 		return -EINVAL;
 
+	if (addr_len < sizeof(struct sockaddr_sco))
+		return -EINVAL;
+
 	lock_sock(sk);
 
 	if (sk->sk_state != BT_OPEN) {
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312665 — [PATCH 3.19.y-ckt 074/160] ses: Fix problems with simple enclosures

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 074/160] ses: Fix problems with simple enclosures
Message-ID<qSPBi-7xH-53@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: James Bottomley <James.Bottomley@HansenPartnership.com>

commit 3417c1b5cb1fdc10261dbed42b05cc93166a78fd upstream.

Simple enclosure implementations (mostly USB) are allowed to return only
page 8 to every diagnostic query.  That really confuses our
implementation because we assume the return is the page we asked for and
end up doing incorrect offsets based on bogus information leading to
accesses outside of allocated ranges.  Fix that by checking the page
code of the return and giving an error if it isn't the one we asked for.
This should fix reported bugs with USB storage by simply refusing to
attach to enclosures that behave like this.  It's also good defensive
practise now that we're starting to see more USB enclosures.

Reported-by: Andrea Gelmini <andrea.gelmini@gelma.net>
Reviewed-by: Ewan D. Milne <emilne@redhat.com>
Reviewed-by: Tomas Henzl <thenzl@redhat.com>
Signed-off-by: James Bottomley <James.Bottomley@HansenPartnership.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/scsi/ses.c | 20 +++++++++++++++++++-
 1 file changed, 19 insertions(+), 1 deletion(-)

diff --git a/drivers/scsi/ses.c b/drivers/scsi/ses.c
index b7e79e7..ddd48b9 100644
--- a/drivers/scsi/ses.c
+++ b/drivers/scsi/ses.c
@@ -71,6 +71,7 @@ static int ses_probe(struct device *dev)
 static int ses_recv_diag(struct scsi_device *sdev, int page_code,
 			 void *buf, int bufflen)
 {
+	int ret;
 	unsigned char cmd[] = {
 		RECEIVE_DIAGNOSTIC,
 		1,		/* Set PCV bit */
@@ -79,9 +80,26 @@ static int ses_recv_diag(struct scsi_device *sdev, int page_code,
 		bufflen & 0xff,
 		0
 	};
+	unsigned char recv_page_code;
 
-	return scsi_execute_req(sdev, cmd, DMA_FROM_DEVICE, buf, bufflen,
+	ret =  scsi_execute_req(sdev, cmd, DMA_FROM_DEVICE, buf, bufflen,
 				NULL, SES_TIMEOUT, SES_RETRIES, NULL);
+	if (unlikely(!ret))
+		return ret;
+
+	recv_page_code = ((unsigned char *)buf)[0];
+
+	if (likely(recv_page_code == page_code))
+		return ret;
+
+	/* successful diagnostic but wrong page code.  This happens to some
+	 * USB devices, just print a message and pretend there was an error */
+
+	sdev_printk(KERN_ERR, sdev,
+		    "Wrong diagnostic page; asked for %d got %u\n",
+		    page_code, recv_page_code);
+
+	return -EINVAL;
 }
 
 static int ses_send_diag(struct scsi_device *sdev, int page_code,
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312666 — [PATCH 3.19.y-ckt 122/160] USB: fix invalid memory access in hub_activate()

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 122/160] USB: fix invalid memory access in hub_activate()
Message-ID<qSPBj-7xH-57@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Alan Stern <stern@rowland.harvard.edu>

commit e50293ef9775c5f1cf3fcc093037dd6a8c5684ea upstream.

Commit 8520f38099cc ("USB: change hub initialization sleeps to
delayed_work") changed the hub_activate() routine to make part of it
run in a workqueue.  However, the commit failed to take a reference to
the usb_hub structure or to lock the hub interface while doing so.  As
a result, if a hub is plugged in and quickly unplugged before the work
routine can run, the routine will try to access memory that has been
deallocated.  Or, if the hub is unplugged while the routine is
running, the memory may be deallocated while it is in active use.

This patch fixes the problem by taking a reference to the usb_hub at
the start of hub_activate() and releasing it at the end (when the work
is finished), and by locking the hub interface while the work routine
is running.  It also adds a check at the start of the routine to see
if the hub has already been disconnected, in which nothing should be
done.

Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Reported-by: Alexandru Cornea <alexandru.cornea@intel.com>
Tested-by: Alexandru Cornea <alexandru.cornea@intel.com>
Fixes: 8520f38099cc ("USB: change hub initialization sleeps to delayed_work")
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/usb/core/hub.c | 22 +++++++++++++++++++---
 1 file changed, 19 insertions(+), 3 deletions(-)

diff --git a/drivers/usb/core/hub.c b/drivers/usb/core/hub.c
index 5f719cb..fde1e10 100644
--- a/drivers/usb/core/hub.c
+++ b/drivers/usb/core/hub.c
@@ -1034,10 +1034,20 @@ static void hub_activate(struct usb_hub *hub, enum hub_activation_type type)
 	unsigned delay;
 
 	/* Continue a partial initialization */
-	if (type == HUB_INIT2)
-		goto init2;
-	if (type == HUB_INIT3)
+	if (type == HUB_INIT2 || type == HUB_INIT3) {
+		device_lock(hub->intfdev);
+
+		/* Was the hub disconnected while we were waiting? */
+		if (hub->disconnected) {
+			device_unlock(hub->intfdev);
+			kref_put(&hub->kref, hub_release);
+			return;
+		}
+		if (type == HUB_INIT2)
+			goto init2;
 		goto init3;
+	}
+	kref_get(&hub->kref);
 
 	/* The superspeed hub except for root hub has to use Hub Depth
 	 * value as an offset into the route string to locate the bits
@@ -1235,6 +1245,7 @@ static void hub_activate(struct usb_hub *hub, enum hub_activation_type type)
 			queue_delayed_work(system_power_efficient_wq,
 					&hub->init_work,
 					msecs_to_jiffies(delay));
+			device_unlock(hub->intfdev);
 			return;		/* Continues at init3: below */
 		} else {
 			msleep(delay);
@@ -1256,6 +1267,11 @@ static void hub_activate(struct usb_hub *hub, enum hub_activation_type type)
 	/* Allow autosuspend if it was suppressed */
 	if (type <= HUB_INIT3)
 		usb_autopm_put_interface_async(to_usb_interface(hub->intfdev));
+
+	if (type == HUB_INIT2 || type == HUB_INIT3)
+		device_unlock(hub->intfdev);
+
+	kref_put(&hub->kref, hub_release);
 }
 
 /* Implement the continuations for the delays above */
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312667 — [PATCH 3.19.y-ckt 133/160] tracing: Fix setting of start_index in find_next()

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 133/160] tracing: Fix setting of start_index in find_next()
Message-ID<qSPBj-7xH-59@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Qiu Peiyang <peiyangx.qiu@intel.com>

commit f36d1be2930ede0a1947686e1126ffda5d5ee1bb upstream.

When we do cat /sys/kernel/debug/tracing/printk_formats, we hit kernel
panic at t_show.

general protection fault: 0000 [#1] PREEMPT SMP
CPU: 0 PID: 2957 Comm: sh Tainted: G W  O 3.14.55-x86_64-01062-gd4acdc7 #2
RIP: 0010:[<ffffffff811375b2>]
 [<ffffffff811375b2>] t_show+0x22/0xe0
RSP: 0000:ffff88002b4ebe80  EFLAGS: 00010246
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000004
RDX: 0000000000000004 RSI: ffffffff81fd26a6 RDI: ffff880032f9f7b1
RBP: ffff88002b4ebe98 R08: 0000000000001000 R09: 000000000000ffec
R10: 0000000000000000 R11: 000000000000000f R12: ffff880004d9b6c0
R13: 7365725f6d706400 R14: ffff880004d9b6c0 R15: ffffffff82020570
FS:  0000000000000000(0000) GS:ffff88003aa00000(0063) knlGS:00000000f776bc40
CS:  0010 DS: 002b ES: 002b CR0: 0000000080050033
CR2: 00000000f6c02ff0 CR3: 000000002c2b3000 CR4: 00000000001007f0
Call Trace:
 [<ffffffff811dc076>] seq_read+0x2f6/0x3e0
 [<ffffffff811b749b>] vfs_read+0x9b/0x160
 [<ffffffff811b7f69>] SyS_read+0x49/0xb0
 [<ffffffff81a3a4b9>] ia32_do_call+0x13/0x13
 ---[ end trace 5bd9eb630614861e ]---
Kernel panic - not syncing: Fatal exception

When the first time find_next calls find_next_mod_format, it should
iterate the trace_bprintk_fmt_list to find the first print format of
the module. However in current code, start_index is smaller than *pos
at first, and code will not iterate the list. Latter container_of will
get the wrong address with former v, which will cause mod_fmt be a
meaningless object and so is the returned mod_fmt->fmt.

This patch will fix it by correcting the start_index. After fixed,
when the first time calls find_next_mod_format, start_index will be
equal to *pos, and code will iterate the trace_bprintk_fmt_list to
get the right module printk format, so is the returned mod_fmt->fmt.

Link: http://lkml.kernel.org/r/5684B900.9000309@intel.com

Fixes: 102c9323c35a8 "tracing: Add __tracepoint_string() to export string pointers"
Signed-off-by: Qiu Peiyang <peiyangx.qiu@intel.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 kernel/trace/trace_printk.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/kernel/trace/trace_printk.c b/kernel/trace/trace_printk.c
index c4e70b6..01443a1 100644
--- a/kernel/trace/trace_printk.c
+++ b/kernel/trace/trace_printk.c
@@ -269,6 +269,7 @@ static const char **find_next(void *v, loff_t *pos)
 	if (*pos < last_index + start_index)
 		return __start___tracepoint_str + (*pos - last_index);
 
+	start_index += last_index;
 	return find_next_mod_format(start_index, v, fmt, pos);
 }
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312668 — [PATCH 3.19.y-ckt 033/160] jbd2: Fix unreclaimed pages after truncate in data=journal mode

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 033/160] jbd2: Fix unreclaimed pages after truncate in data=journal mode
Message-ID<qSPBj-7xH-61@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Jan Kara <jack@suse.cz>

commit bc23f0c8d7ccd8d924c4e70ce311288cb3e61ea8 upstream.

Ted and Namjae have reported that truncated pages don't get timely
reclaimed after being truncated in data=journal mode. The following test
triggers the issue easily:

for (i = 0; i < 1000; i++) {
	pwrite(fd, buf, 1024*1024, 0);
	fsync(fd);
	fsync(fd);
	ftruncate(fd, 0);
}

The reason is that journal_unmap_buffer() finds that truncated buffers
are not journalled (jh->b_transaction == NULL), they are part of
checkpoint list of a transaction (jh->b_cp_transaction != NULL) and have
been already written out (!buffer_dirty(bh)). We clean such buffers but
we leave them in the checkpoint list. Since checkpoint transaction holds
a reference to the journal head, these buffers cannot be released until
the checkpoint transaction is cleaned up. And at that point we don't
call release_buffer_page() anymore so pages detached from mapping are
lingering in the system waiting for reclaim to find them and free them.

Fix the problem by removing buffers from transaction checkpoint lists
when journal_unmap_buffer() finds out they don't have to be there
anymore.

Reported-and-tested-by: Namjae Jeon <namjae.jeon@samsung.com>
Fixes: de1b794130b130e77ffa975bb58cb843744f9ae5
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/jbd2/transaction.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/fs/jbd2/transaction.c b/fs/jbd2/transaction.c
index ff2f2e6..72efc81 100644
--- a/fs/jbd2/transaction.c
+++ b/fs/jbd2/transaction.c
@@ -2058,6 +2058,7 @@ static int journal_unmap_buffer(journal_t *journal, struct buffer_head *bh,
 
 		if (!buffer_dirty(bh)) {
 			/* bdflush has written it.  We can drop it now */
+			__jbd2_journal_remove_checkpoint(jh);
 			goto zap_buffer;
 		}
 
@@ -2087,6 +2088,7 @@ static int journal_unmap_buffer(journal_t *journal, struct buffer_head *bh,
 				/* The orphan record's transaction has
 				 * committed.  We can cleanse this buffer */
 				clear_buffer_jbddirty(bh);
+				__jbd2_journal_remove_checkpoint(jh);
 				goto zap_buffer;
 			}
 		}
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312669 — [PATCH 3.19.y-ckt 120/160] [media] airspy: increase USB control message buffer size

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 120/160] [media] airspy: increase USB control message buffer size
Message-ID<qSPBj-7xH-63@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Antti Palosaari <crope@iki.fi>

commit aa0850e1d56623845b46350ffd971afa9241886d upstream.

Driver requested device firmware version string during probe using
only 24 byte long buffer. That buffer is too small for newer firmware
versions, which causes device firmware hang - device stops responding
to any commands after that. Increase buffer size to 128 which should
be enough for any current and future version strings.

Link: https://github.com/airspy/host/issues/27

Reported-by: Benjamin Vernoux <bvernoux@gmail.com>
Signed-off-by: Antti Palosaari <crope@iki.fi>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/media/usb/airspy/airspy.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/media/usb/airspy/airspy.c b/drivers/media/usb/airspy/airspy.c
index 4069234..a50750c 100644
--- a/drivers/media/usb/airspy/airspy.c
+++ b/drivers/media/usb/airspy/airspy.c
@@ -132,7 +132,7 @@ struct airspy {
 	int            urbs_submitted;
 
 	/* USB control message buffer */
-	#define BUF_SIZE 24
+	#define BUF_SIZE 128
 	u8 buf[BUF_SIZE];
 
 	/* Current configuration */
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312670 — [PATCH 3.19.y-ckt 073/160] dm btree: fix bufio buffer leaks in dm_btree_del() error path

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 073/160] dm btree: fix bufio buffer leaks in dm_btree_del() error path
Message-ID<qSPBj-7xH-65@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Joe Thornber <ejt@redhat.com>

commit ed8b45a3679eb49069b094c0711b30833f27c734 upstream.

If dm_btree_del()'s call to push_frame() fails, e.g. due to
btree_node_validator finding invalid metadata, the dm_btree_del() error
path must unlock all frames (which have active dm-bufio buffers) that
were pushed onto the del_stack.

Otherwise, dm_bufio_client_destroy() will BUG_ON() because dm-bufio
buffers have leaked, e.g.:
  device-mapper: bufio: leaked buffer 3, hold count 1, list 0

Signed-off-by: Joe Thornber <ejt@redhat.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/md/persistent-data/dm-btree.c | 16 +++++++++++++++-
 1 file changed, 15 insertions(+), 1 deletion(-)

diff --git a/drivers/md/persistent-data/dm-btree.c b/drivers/md/persistent-data/dm-btree.c
index 7ba85e2..7b4bb1f 100644
--- a/drivers/md/persistent-data/dm-btree.c
+++ b/drivers/md/persistent-data/dm-btree.c
@@ -250,6 +250,16 @@ static void pop_frame(struct del_stack *s)
 	dm_tm_unlock(s->tm, f->b);
 }
 
+static void unlock_all_frames(struct del_stack *s)
+{
+	struct frame *f;
+
+	while (unprocessed_frames(s)) {
+		f = s->spine + s->top--;
+		dm_tm_unlock(s->tm, f->b);
+	}
+}
+
 int dm_btree_del(struct dm_btree_info *info, dm_block_t root)
 {
 	int r;
@@ -306,9 +316,13 @@ int dm_btree_del(struct dm_btree_info *info, dm_block_t root)
 			pop_frame(s);
 		}
 	}
-
 out:
+	if (r) {
+		/* cleanup all frames of del_stack */
+		unlock_all_frames(s);
+	}
 	kfree(s);
+
 	return r;
 }
 EXPORT_SYMBOL_GPL(dm_btree_del);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312671 — [PATCH 3.19.y-ckt 035/160] i2c: mv64xxx: The n clockdiv factor is 0 based on sunxi SoCs

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 035/160] i2c: mv64xxx: The n clockdiv factor is 0 based on sunxi SoCs
Message-ID<qSPBj-7xH-67@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Hans de Goede <hdegoede@redhat.com>

commit bba61f50f76574ca5b84b310925be7c2e8e64275 upstream.

According to the datasheets the n factor for dividing the tclk is
2 to the power n on Allwinner SoCs, not 2 to the power n + 1 as it is
on other mv64xxx implementations.

I've contacted Allwinner about this and they have confirmed that the
datasheet is correct.

This commit fixes the clk-divider calculations for Allwinner SoCs
accordingly.

Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Acked-by: Maxime Ripard <maxime.ripard@free-electrons.com>
Tested-by: Olliver Schinagl <oliver@schinagl.nl>
Signed-off-by: Wolfram Sang <wsa@the-dreams.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/i2c/busses/i2c-mv64xxx.c | 27 ++++++++++++++++++---------
 1 file changed, 18 insertions(+), 9 deletions(-)

diff --git a/drivers/i2c/busses/i2c-mv64xxx.c b/drivers/i2c/busses/i2c-mv64xxx.c
index 5801227..43207f5 100644
--- a/drivers/i2c/busses/i2c-mv64xxx.c
+++ b/drivers/i2c/busses/i2c-mv64xxx.c
@@ -146,6 +146,8 @@ struct mv64xxx_i2c_data {
 	bool			errata_delay;
 	struct reset_control	*rstc;
 	bool			irq_clear_inverted;
+	/* Clk div is 2 to the power n, not 2 to the power n + 1 */
+	bool			clk_n_base_0;
 };
 
 static struct mv64xxx_i2c_regs mv64xxx_i2c_regs_mv64xxx = {
@@ -757,25 +759,29 @@ MODULE_DEVICE_TABLE(of, mv64xxx_i2c_of_match_table);
 #ifdef CONFIG_OF
 #ifdef CONFIG_HAVE_CLK
 static int
-mv64xxx_calc_freq(const int tclk, const int n, const int m)
+mv64xxx_calc_freq(struct mv64xxx_i2c_data *drv_data,
+		  const int tclk, const int n, const int m)
 {
-	return tclk / (10 * (m + 1) * (2 << n));
+	if (drv_data->clk_n_base_0)
+		return tclk / (10 * (m + 1) * (1 << n));
+	else
+		return tclk / (10 * (m + 1) * (2 << n));
 }
 
 static bool
-mv64xxx_find_baud_factors(const u32 req_freq, const u32 tclk, u32 *best_n,
-			  u32 *best_m)
+mv64xxx_find_baud_factors(struct mv64xxx_i2c_data *drv_data,
+			  const u32 req_freq, const u32 tclk)
 {
 	int freq, delta, best_delta = INT_MAX;
 	int m, n;
 
 	for (n = 0; n <= 7; n++)
 		for (m = 0; m <= 15; m++) {
-			freq = mv64xxx_calc_freq(tclk, n, m);
+			freq = mv64xxx_calc_freq(drv_data, tclk, n, m);
 			delta = req_freq - freq;
 			if (delta >= 0 && delta < best_delta) {
-				*best_m = m;
-				*best_n = n;
+				drv_data->freq_m = m;
+				drv_data->freq_n = n;
 				best_delta = delta;
 			}
 			if (best_delta == 0)
@@ -813,8 +819,11 @@ mv64xxx_of_config(struct mv64xxx_i2c_data *drv_data,
 	if (of_property_read_u32(np, "clock-frequency", &bus_freq))
 		bus_freq = 100000; /* 100kHz by default */
 
-	if (!mv64xxx_find_baud_factors(bus_freq, tclk,
-				       &drv_data->freq_n, &drv_data->freq_m)) {
+	if (of_device_is_compatible(np, "allwinner,sun4i-a10-i2c") ||
+	    of_device_is_compatible(np, "allwinner,sun6i-a31-i2c"))
+		drv_data->clk_n_base_0 = true;
+
+	if (!mv64xxx_find_baud_factors(drv_data, bus_freq, tclk)) {
 		rc = -EINVAL;
 		goto out;
 	}
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312673 — [PATCH 3.19.y-ckt 101/160] ftrace/scripts: Have recordmcount copy the object file

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 101/160] ftrace/scripts: Have recordmcount copy the object file
Message-ID<qSPBj-7xH-69@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: "Steven Rostedt (Red Hat)" <rostedt@goodmis.org>

commit a50bd43935586420fb75f4558369eb08566fac5e upstream.

Russell King found that he had weird side effects when compiling the kernel
with hard linked ccache. The reason was that recordmcount modified the
kernel in place via mmap, and when a file gets modified twice by
recordmcount, it will complain about it. To fix this issue, Russell wrote a
patch that checked if the file was hard linked more than once and would
unlink it if it was.

Linus Torvalds was not happy with the fact that recordmcount does this in
place modification. Instead of doing the unlink only if the file has two or
more hard links, it does the unlink all the time. In otherwords, it always
does a copy if it changed something. That is, it does the write out if a
change was made.

Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 scripts/recordmcount.c | 145 +++++++++++++++++++++++++++++++++++++------------
 1 file changed, 110 insertions(+), 35 deletions(-)

diff --git a/scripts/recordmcount.c b/scripts/recordmcount.c
index fd42629..a3d96c2 100644
--- a/scripts/recordmcount.c
+++ b/scripts/recordmcount.c
@@ -48,12 +48,17 @@
 
 static int fd_map;	/* File descriptor for file being modified. */
 static int mmap_failed; /* Boolean flag. */
-static void *ehdr_curr; /* current ElfXX_Ehdr *  for resource cleanup */
 static char gpfx;	/* prefix for global symbol name (sometimes '_') */
 static struct stat sb;	/* Remember .st_size, etc. */
 static jmp_buf jmpenv;	/* setjmp/longjmp per-file error escape */
 static const char *altmcount;	/* alternate mcount symbol name */
 static int warn_on_notrace_sect; /* warn when section has mcount not being recorded */
+static void *file_map;	/* pointer of the mapped file */
+static void *file_end;	/* pointer to the end of the mapped file */
+static int file_updated; /* flag to state file was changed */
+static void *file_ptr;	/* current file pointer location */
+static void *file_append; /* added to the end of the file */
+static size_t file_append_size; /* how much is added to end of file */
 
 /* setjmp() return values */
 enum {
@@ -67,10 +72,14 @@ static void
 cleanup(void)
 {
 	if (!mmap_failed)
-		munmap(ehdr_curr, sb.st_size);
+		munmap(file_map, sb.st_size);
 	else
-		free(ehdr_curr);
-	close(fd_map);
+		free(file_map);
+	file_map = NULL;
+	free(file_append);
+	file_append = NULL;
+	file_append_size = 0;
+	file_updated = 0;
 }
 
 static void __attribute__((noreturn))
@@ -92,12 +101,22 @@ succeed_file(void)
 static off_t
 ulseek(int const fd, off_t const offset, int const whence)
 {
-	off_t const w = lseek(fd, offset, whence);
-	if (w == (off_t)-1) {
-		perror("lseek");
+	switch (whence) {
+	case SEEK_SET:
+		file_ptr = file_map + offset;
+		break;
+	case SEEK_CUR:
+		file_ptr += offset;
+		break;
+	case SEEK_END:
+		file_ptr = file_map + (sb.st_size - offset);
+		break;
+	}
+	if (file_ptr < file_map) {
+		fprintf(stderr, "lseek: seek before file\n");
 		fail_file();
 	}
-	return w;
+	return file_ptr - file_map;
 }
 
 static size_t
@@ -114,12 +133,38 @@ uread(int const fd, void *const buf, size_t const count)
 static size_t
 uwrite(int const fd, void const *const buf, size_t const count)
 {
-	size_t const n = write(fd, buf, count);
-	if (n != count) {
-		perror("write");
-		fail_file();
+	size_t cnt = count;
+	off_t idx = 0;
+
+	file_updated = 1;
+
+	if (file_ptr + count >= file_end) {
+		off_t aoffset = (file_ptr + count) - file_end;
+
+		if (aoffset > file_append_size) {
+			file_append = realloc(file_append, aoffset);
+			file_append_size = aoffset;
+		}
+		if (!file_append) {
+			perror("write");
+			fail_file();
+		}
+		if (file_ptr < file_end) {
+			cnt = file_end - file_ptr;
+		} else {
+			cnt = 0;
+			idx = aoffset - count;
+		}
 	}
-	return n;
+
+	if (cnt)
+		memcpy(file_ptr, buf, cnt);
+
+	if (cnt < count)
+		memcpy(file_append + idx, buf + cnt, count - cnt);
+
+	file_ptr += count;
+	return count;
 }
 
 static void *
@@ -192,9 +237,7 @@ static int make_nop_arm64(void *map, size_t const offset)
  */
 static void *mmap_file(char const *fname)
 {
-	void *addr;
-
-	fd_map = open(fname, O_RDWR);
+	fd_map = open(fname, O_RDONLY);
 	if (fd_map < 0 || fstat(fd_map, &sb) < 0) {
 		perror(fname);
 		fail_file();
@@ -203,29 +246,58 @@ static void *mmap_file(char const *fname)
 		fprintf(stderr, "not a regular file: %s\n", fname);
 		fail_file();
 	}
-	addr = mmap(0, sb.st_size, PROT_READ|PROT_WRITE, MAP_PRIVATE,
-		    fd_map, 0);
+	file_map = mmap(0, sb.st_size, PROT_READ|PROT_WRITE, MAP_PRIVATE,
+			fd_map, 0);
 	mmap_failed = 0;
-	if (addr == MAP_FAILED) {
+	if (file_map == MAP_FAILED) {
 		mmap_failed = 1;
-		addr = umalloc(sb.st_size);
-		uread(fd_map, addr, sb.st_size);
+		file_map = umalloc(sb.st_size);
+		uread(fd_map, file_map, sb.st_size);
 	}
-	if (sb.st_nlink != 1) {
-		/* file is hard-linked, break the hard link */
-		close(fd_map);
-		if (unlink(fname) < 0) {
-			perror(fname);
-			fail_file();
-		}
-		fd_map = open(fname, O_RDWR | O_CREAT, sb.st_mode);
-		if (fd_map < 0) {
-			perror(fname);
+	close(fd_map);
+
+	file_end = file_map + sb.st_size;
+
+	return file_map;
+}
+
+static void write_file(const char *fname)
+{
+	char tmp_file[strlen(fname) + 4];
+	size_t n;
+
+	if (!file_updated)
+		return;
+
+	sprintf(tmp_file, "%s.rc", fname);
+
+	/*
+	 * After reading the entire file into memory, delete it
+	 * and write it back, to prevent weird side effects of modifying
+	 * an object file in place.
+	 */
+	fd_map = open(tmp_file, O_WRONLY | O_TRUNC | O_CREAT, sb.st_mode);
+	if (fd_map < 0) {
+		perror(fname);
+		fail_file();
+	}
+	n = write(fd_map, file_map, sb.st_size);
+	if (n != sb.st_size) {
+		perror("write");
+		fail_file();
+	}
+	if (file_append_size) {
+		n = write(fd_map, file_append, file_append_size);
+		if (n != file_append_size) {
+			perror("write");
 			fail_file();
 		}
-		uwrite(fd_map, addr, sb.st_size);
 	}
-	return addr;
+	close(fd_map);
+	if (rename(tmp_file, fname) < 0) {
+		perror(fname);
+		fail_file();
+	}
 }
 
 /* w8rev, w8nat, ...: Handle endianness. */
@@ -332,7 +404,6 @@ do_file(char const *const fname)
 	Elf32_Ehdr *const ehdr = mmap_file(fname);
 	unsigned int reltype = 0;
 
-	ehdr_curr = ehdr;
 	w = w4nat;
 	w2 = w2nat;
 	w8 = w8nat;
@@ -453,6 +524,7 @@ do_file(char const *const fname)
 	}
 	}  /* end switch */
 
+	write_file(fname);
 	cleanup();
 }
 
@@ -505,11 +577,14 @@ main(int argc, char *argv[])
 		case SJ_SETJMP:    /* normal sequence */
 			/* Avoid problems if early cleanup() */
 			fd_map = -1;
-			ehdr_curr = NULL;
 			mmap_failed = 1;
+			file_map = NULL;
+			file_ptr = NULL;
+			file_updated = 0;
 			do_file(file);
 			break;
 		case SJ_FAIL:    /* error in do_file or below */
+			sprintf("%s: failed\n", file);
 			++n_error;
 			break;
 		case SJ_SUCCEED:    /* premature success */
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312674 — [PATCH 3.19.y-ckt 057/160] IB/srp: Fix a memory leak

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 057/160] IB/srp: Fix a memory leak
Message-ID<qSPBj-7xH-77@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Bart Van Assche <bart.vanassche@sandisk.com>

commit 4d59ad2995e4128c06d889f9e223099b1f19548e upstream.

If srp_connect_ch() returns a positive value then that is considered
by its caller as a connection failure but this does not result in a
scsi_host_put() call and additionally causes the srp_create_target()
function to return a positive value while it should return a negative
value. Avoid all this confusion and additionally fix a memory leak by
ensuring that srp_connect_ch() always returns a value that is <= 0.
This patch avoids that a rejected login triggers the following memory
leak:

unreferenced object 0xffff88021b24a220 (size 8):
  comm "srp_daemon", pid 56421, jiffies 4295006762 (age 4240.750s)
  hex dump (first 8 bytes):
    68 6f 73 74 35 38 00 a5                          host58..
  backtrace:
    [<ffffffff8151014a>] kmemleak_alloc+0x7a/0xc0
    [<ffffffff81165c1e>] __kmalloc_track_caller+0xfe/0x160
    [<ffffffff81260d2b>] kvasprintf+0x5b/0x90
    [<ffffffff81260e2d>] kvasprintf_const+0x8d/0xb0
    [<ffffffff81254b0c>] kobject_set_name_vargs+0x3c/0xa0
    [<ffffffff81337e3c>] dev_set_name+0x3c/0x40
    [<ffffffff81355757>] scsi_host_alloc+0x327/0x4b0
    [<ffffffffa03edc8e>] srp_create_target+0x4e/0x8a0 [ib_srp]
    [<ffffffff8133778b>] dev_attr_store+0x1b/0x20
    [<ffffffff811f27fa>] sysfs_kf_write+0x4a/0x60
    [<ffffffff811f1e8e>] kernfs_fop_write+0x14e/0x180
    [<ffffffff81176eef>] __vfs_write+0x2f/0xf0
    [<ffffffff811771e4>] vfs_write+0xa4/0x100
    [<ffffffff81177c64>] SyS_write+0x54/0xc0
    [<ffffffff8151b257>] entry_SYSCALL_64_fastpath+0x12/0x6f

Signed-off-by: Bart Van Assche <bart.vanassche@sandisk.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Sagi Grimberg <sagig@mellanox.com>
Cc: Sebastian Parschauer <sebastian.riemer@profitbricks.com>
Signed-off-by: Doug Ledford <dledford@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/infiniband/ulp/srp/ib_srp.c | 22 +++++++++++++---------
 1 file changed, 13 insertions(+), 9 deletions(-)

diff --git a/drivers/infiniband/ulp/srp/ib_srp.c b/drivers/infiniband/ulp/srp/ib_srp.c
index 7ce100b..3dace1d 100644
--- a/drivers/infiniband/ulp/srp/ib_srp.c
+++ b/drivers/infiniband/ulp/srp/ib_srp.c
@@ -991,16 +991,16 @@ static int srp_connect_ch(struct srp_rdma_ch *ch, bool multich)
 
 	ret = srp_lookup_path(ch);
 	if (ret)
-		return ret;
+		goto out;
 
 	while (1) {
 		init_completion(&ch->done);
 		ret = srp_send_req(ch, multich);
 		if (ret)
-			return ret;
+			goto out;
 		ret = wait_for_completion_interruptible(&ch->done);
 		if (ret < 0)
-			return ret;
+			goto out;
 
 		/*
 		 * The CM event handling code will set status to
@@ -1008,15 +1008,16 @@ static int srp_connect_ch(struct srp_rdma_ch *ch, bool multich)
 		 * back, or SRP_DLID_REDIRECT if we get a lid/qp
 		 * redirect REJ back.
 		 */
-		switch (ch->status) {
+		ret = ch->status;
+		switch (ret) {
 		case 0:
 			ch->connected = true;
-			return 0;
+			goto out;
 
 		case SRP_PORT_REDIRECT:
 			ret = srp_lookup_path(ch);
 			if (ret)
-				return ret;
+				goto out;
 			break;
 
 		case SRP_DLID_REDIRECT:
@@ -1025,13 +1026,16 @@ static int srp_connect_ch(struct srp_rdma_ch *ch, bool multich)
 		case SRP_STALE_CONN:
 			shost_printk(KERN_ERR, target->scsi_host, PFX
 				     "giving up on stale connection\n");
-			ch->status = -ECONNRESET;
-			return ch->status;
+			ret = -ECONNRESET;
+			goto out;
 
 		default:
-			return ch->status;
+			goto out;
 		}
 	}
+
+out:
+	return ret <= 0 ? ret : -ENODEV;
 }
 
 static int srp_inv_rkey(struct srp_rdma_ch *ch, u32 rkey)
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312675 — [PATCH 3.19.y-ckt 004/160] ARC: Fix silly typo in MAINTAINERS file

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 004/160] ARC: Fix silly typo in MAINTAINERS file
Message-ID<qSPBj-7xH-81@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Vineet Gupta <vgupta@synopsys.com>

commit 30b9dbee895ff0d5cbf155bd1ef3f0f5992bca6f upstream.

Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 MAINTAINERS | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/MAINTAINERS b/MAINTAINERS
index 90f2094..f69bfcd 100644
--- a/MAINTAINERS
+++ b/MAINTAINERS
@@ -9295,7 +9295,7 @@ F:	include/net/switchdev.h
 
 SYNOPSYS ARC ARCHITECTURE
 M:	Vineet Gupta <vgupta@synopsys.com>
-L:	linux-snps-arc@lists.infraded.org
+L:	linux-snps-arc@lists.infradead.org
 S:	Supported
 F:	arch/arc/
 F:	Documentation/devicetree/bindings/arc/
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312676 — [PATCH 3.19.y-ckt 098/160] spi: fix parent-device reference leak

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 098/160] spi: fix parent-device reference leak
Message-ID<qSPBj-7xH-79@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Johan Hovold <johan@kernel.org>

commit 157f38f993919b648187ba341bfb05d0e91ad2f6 upstream.

Fix parent-device reference leak due to SPI-core taking an unnecessary
reference to the parent when allocating the master structure, a
reference that was never released.

Note that driver core takes its own reference to the parent when the
master device is registered.

Fixes: 49dce689ad4e ("spi doesn't need class_device")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/spi/spi.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/spi/spi.c b/drivers/spi/spi.c
index 2ebe805..346a20a 100644
--- a/drivers/spi/spi.c
+++ b/drivers/spi/spi.c
@@ -1509,7 +1509,7 @@ struct spi_master *spi_alloc_master(struct device *dev, unsigned size)
 	master->bus_num = -1;
 	master->num_chipselect = 1;
 	master->dev.class = &spi_master_class;
-	master->dev.parent = get_device(dev);
+	master->dev.parent = dev;
 	spi_master_set_devdata(master, &master[1]);
 
 	return master;
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1312677 — [PATCH 3.19.y-ckt 069/160] ipmi: move timer init to before irq is setup

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-20 02:20 +0100
Subject[PATCH 3.19.y-ckt 069/160] ipmi: move timer init to before irq is setup
Message-ID<qSPBk-7xH-83@gated-at.bofh.it>
In reply to#1312635
3.19.8-ckt13 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Jan Stancek <jstancek@redhat.com>

commit 27f972d3e00b50639deb4cc1392afaeb08d3cecc upstream.

We encountered a panic on boot in ipmi_si on a dell per320 due to an
uninitialized timer as follows.

static int smi_start_processing(void       *send_info,
                                ipmi_smi_t intf)
{
        /* Try to claim any interrupts. */
        if (new_smi->irq_setup)
                new_smi->irq_setup(new_smi);

 --> IRQ arrives here and irq handler tries to modify uninitialized timer

    which triggers BUG_ON(!timer->function) in __mod_timer().

 Call Trace:
   <IRQ>
   [<ffffffffa0532617>] start_new_msg+0x47/0x80 [ipmi_si]
   [<ffffffffa053269e>] start_check_enables+0x4e/0x60 [ipmi_si]
   [<ffffffffa0532bd8>] smi_event_handler+0x1e8/0x640 [ipmi_si]
   [<ffffffff810f5584>] ? __rcu_process_callbacks+0x54/0x350
   [<ffffffffa053327c>] si_irq_handler+0x3c/0x60 [ipmi_si]
   [<ffffffff810efaf0>] handle_IRQ_event+0x60/0x170
   [<ffffffff810f245e>] handle_edge_irq+0xde/0x180
   [<ffffffff8100fc59>] handle_irq+0x49/0xa0
   [<ffffffff8154643c>] do_IRQ+0x6c/0xf0
   [<ffffffff8100ba53>] ret_from_intr+0x0/0x11

        /* Set up the timer that drives the interface. */
        setup_timer(&new_smi->si_timer, smi_timeout, (long)new_smi);

The following patch fixes the problem.

To: Openipmi-developer@lists.sourceforge.net
To: Corey Minyard <minyard@acm.org>
CC: linux-kernel@vger.kernel.org

Signed-off-by: Jan Stancek <jstancek@redhat.com>
Signed-off-by: Tony Camuso <tcamuso@redhat.com>
Signed-off-by: Corey Minyard <cminyard@mvista.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/char/ipmi/ipmi_si_intf.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/char/ipmi/ipmi_si_intf.c b/drivers/char/ipmi/ipmi_si_intf.c
index ecc34a9..5b2bb8a 100644
--- a/drivers/char/ipmi/ipmi_si_intf.c
+++ b/drivers/char/ipmi/ipmi_si_intf.c
@@ -1223,14 +1223,14 @@ static int smi_start_processing(void       *send_info,
 
 	new_smi->intf = intf;
 
-	/* Try to claim any interrupts. */
-	if (new_smi->irq_setup)
-		new_smi->irq_setup(new_smi);
-
 	/* Set up the timer that drives the interface. */
 	setup_timer(&new_smi->si_timer, smi_timeout, (long)new_smi);
 	smi_mod_timer(new_smi, jiffies + SI_TIMEOUT_JIFFIES);
 
+	/* Try to claim any interrupts. */
+	if (new_smi->irq_setup)
+		new_smi->irq_setup(new_smi);
+
 	/*
 	 * Check if the user forcefully enabled the daemon.
 	 */
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


Page 2 of 8 — ← Prev page 1 [2] 3 4 5 6 7 8  Next page →

Back to top | Article view | linux.kernel


csiph-web