Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1315368 > unrolled thread

[3.13.y-ckt stable] Linux 3.13.11-ckt33 stable review

Started byKamal Mostafa <kamal@canonical.com>
First post2016-01-23 00:40 +0100
Last post2016-01-23 01:10 +0100
Articles 20 on this page of 89 — 1 participant

Back to article view | Back to linux.kernel


Contents

  [3.13.y-ckt stable] Linux 3.13.11-ckt33 stable review Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 086/108] x86/mce: Ensure offline CPUs don't participate in rendezvous process Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 053/108] xhci: fix usb2 resume timing and races. Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 009/108] sh_eth: fix kernel oops in skb_put() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 093/108] async_tx: use GFP_NOWAIT rather than GFP_IO Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 102/108] pinctrl: bcm2835: Fix initial value for direction_output Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 105/108] qlcnic: fix a timeout loop Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 095/108] ftrace/module: Call clean up function when module init fails early Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 088/108] ALSA: hda/realtek - Fix silent headphone output on MacPro 4,1 (v2) Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 107/108] include/linux/mmdebug.h: should include linux/bug.h Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 090/108] mm/memory_hotplug.c: check for missing sections in test_pages_in_a_zone() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 075/108] xen-netback: use RING_COPY_REQUEST() throughout Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 096/108] vmstat: allocate vmstat_wq before it is used Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 103/108] mISDN: fix a loop count Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 092/108] tracing: Fix setting of start_index in find_next() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 099/108] ipv6/addrlabel: fix ip6addrlbl_get() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 091/108] ftrace/scripts: Fix incorrect use of sprintf in recordmcount Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 077/108] xen-blkback: read from indirect descriptors only once Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
    [PATCH 3.13.y-ckt 057/108] mm, vmstat: allow WQ concurrency to discover memory reclaim doesn't make any progress Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 076/108] xen-blkback: only read request operation from shared ring once Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 050/108] ses: Fix problems with simple enclosures Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 059/108] drivers/base/memory.c: prohibit offlining of memory blocks with missing sections Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 049/108] dm btree: fix bufio buffer leaks in dm_btree_del() error path Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 052/108] ses: fix additional element traversal bug Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 073/108] xen: Add RING_COPY_REQUEST() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 072/108] s390/dis: Fix handling of format specifiers Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 070/108] ARC: dw2 unwind: Ignore CIE version !=1 gracefully instead of bailing Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 045/108] dm space map metadata: fix ref counting bug when bootstrapping a new space map Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 071/108] ALSA: hda - Set SKL+ hda controller power at freeze() and thaw() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 068/108] ftrace/scripts: Have recordmcount copy the object file Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 066/108] spi: fix parent-device reference leak Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 064/108] ALSA: usb-audio: Add a more accurate volume quirk for AudioQuest DragonFly Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 058/108] mm: hugetlb: call huge_pte_alloc() only if ptep is null Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 062/108] tty: Fix GPF in flush_to_ldisc() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 082/108] xen/pciback: For XEN_PCI_OP_disable_msi[|x] only disable if device has MSI(X) enabled. Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 081/108] xen/pciback: Do not install an IRQ handler for MSI interrupts. Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 054/108] USB: add quirk for devices with broken LPM Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 083/108] xen/pciback: Don't allow MSI-X ops if PCI_COMMAND_MEMORY is not set. Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 051/108] vgaarb: fix signal handling in vga_get() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 046/108] ipmi: move timer init to before irq is setup Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 069/108] ARC: dw2 unwind: Reinstante unwinding out of modules Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 074/108] xen-netback: don't use last request to determine minimum Tx credit Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 063/108] genirq: Prevent chip buslock deadlock Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 060/108] sh64: fix __NR_fgetxattr Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 048/108] rfkill: copy the name into the rfkill struct Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 078/108] xen/pciback: Save xen_pci_op commands before processing it Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 079/108] xen/pciback: Return error on XEN_PCI_OP_enable_msi when device has MSI or MSI-X enabled Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 061/108] n_tty: Fix poll() after buffer-limited eof push read Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 056/108] parisc iommu: fix panic due to trying to allocate too large region Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 055/108] powercap / RAPL: fix BIOS lock check Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 080/108] xen/pciback: Return error on XEN_PCI_OP_enable_msix when device has MSI or MSI-X enabled Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
    [PATCH 3.13.y-ckt 022/108] USB: cdc_acm: Ignore Infineon Flash Loader utility Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 015/108] tools: Add a "make all" rule Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 020/108] iio: fix some warning messages Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 031/108] irqchip/versatile-fpga: Fix PCI IRQ mapping on Versatile PB Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 014/108] KVM: x86: Reload pit counters for all channels when restoring state Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 026/108] drm/ttm: Fixed a read/write lock imbalance Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 023/108] USB: serial: Another Infineon flash loader USB ID Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 042/108] radeon/cik: Fix GFX IB test on Big-Endian Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 025/108] jbd2: Fix unreclaimed pages after truncate in data=journal mode Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 021/108] USB: cp210x: Remove CP2110 ID from compatibility list Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 038/108] ALSA: rme96: Fix unexpected volume reset after rate changes Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 017/108] net: ipmr: fix static mfc/dev leaks on table destruction Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 036/108] SCSI: Fix NULL pointer dereference in runtime PM Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 007/108] ipv6: sctp: clone options to avoid use after free Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 018/108] fuse: break infinite loop in fuse_fill_write_pages() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 041/108] 9p: ->evict_inode() should kick out ->i_data, not ->i_mapping Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 029/108] sata_sil: disable trim Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 040/108] virtio: fix memory leak of virtio ida cache layers Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 010/108] pptp: verify sockaddr_len in pptp_bind() and pptp_connect() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 043/108] crypto: skcipher - Copy iv from desc even for 0-len walks Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 019/108] usb: gadget: pxa27x: fix suspend callback Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 030/108] staging: lustre: echo_copy.._lsm() dereferences userland pointers directly Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 037/108] usb: xhci: fix config fail of FS hub behind a HS hub with MTT Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 034/108] usb: Use the USB_SS_MULT() macro to decode burst multiplier for log message Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 027/108] i2c: mv64xxx: The n clockdiv factor is 0 based on sunxi SoCs Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 035/108] dm btree: fix leak of bufio-backed block in btree_split_sibling error path Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 033/108] USB: whci-hcd: add check for dma mapping error Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 016/108] efi: Disable interrupts around EFI calls, not in the epilog/prolog calls Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 008/108] net: add validation for the socket syscall protocol argument Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 028/108] AHCI: Fix softreset failed issue of Port Multiplier Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 044/108] dm thin metadata: fix bug when taking a metadata snapshot Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 011/108] bluetooth: Validate socket address length in sco_sock_bind(). Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 012/108] af_unix: Revert 'lock_interruptible' in stream receive code Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
    [PATCH 3.13.y-ckt 005/108] sctp: use the same clock as if sock source timestamps were on Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:10 +0100
    [PATCH 3.13.y-ckt 003/108] gre6: allow to update all parameters via rtnl Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:10 +0100
    [PATCH 3.13.y-ckt 004/108] atl1c: Improve driver not to do order 4 GFP_ATOMIC allocation Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:10 +0100
    [PATCH 3.13.y-ckt 001/108] ARC: Fix silly typo in MAINTAINERS file Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:10 +0100
    [PATCH 3.13.y-ckt 006/108] sctp: update the netstamp_needed counter when copying sockets Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:10 +0100

Page 4 of 5 — ← Prev page 1 2 3 [4] 5  Next page →


#1315431 — [PATCH 3.13.y-ckt 021/108] USB: cp210x: Remove CP2110 ID from compatibility list

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 021/108] USB: cp210x: Remove CP2110 ID from compatibility list
Message-ID<qTTMu-2Oo-23@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Konstantin Shkolnyy <konstantin.shkolnyy@gmail.com>

commit 7c90e610b60cd1ed6abafd806acfaedccbbe52d1 upstream.

CP2110 ID (0x10c4, 0xea80) doesn't belong here because it's a HID
and completely different from CP210x devices.

Signed-off-by: Konstantin Shkolnyy <konstantin.shkolnyy@gmail.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/usb/serial/cp210x.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/drivers/usb/serial/cp210x.c b/drivers/usb/serial/cp210x.c
index 8452030..c699a0b 100644
--- a/drivers/usb/serial/cp210x.c
+++ b/drivers/usb/serial/cp210x.c
@@ -132,7 +132,6 @@ static const struct usb_device_id id_table[] = {
 	{ USB_DEVICE(0x10C4, 0xEA60) }, /* Silicon Labs factory default */
 	{ USB_DEVICE(0x10C4, 0xEA61) }, /* Silicon Labs factory default */
 	{ USB_DEVICE(0x10C4, 0xEA70) }, /* Silicon Labs factory default */
-	{ USB_DEVICE(0x10C4, 0xEA80) }, /* Silicon Labs factory default */
 	{ USB_DEVICE(0x10C4, 0xEA71) }, /* Infinity GPS-MIC-1 Radio Monophone */
 	{ USB_DEVICE(0x10C4, 0xF001) }, /* Elan Digital Systems USBscope50 */
 	{ USB_DEVICE(0x10C4, 0xF002) }, /* Elan Digital Systems USBwave12 */
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315432 — [PATCH 3.13.y-ckt 038/108] ALSA: rme96: Fix unexpected volume reset after rate changes

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 038/108] ALSA: rme96: Fix unexpected volume reset after rate changes
Message-ID<qTTMu-2Oo-25@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit a74a821624c0c75388a193337babd17a8c02c740 upstream.

rme96 driver needs to reset DAC depending on the sample rate, and this
results in resetting to the max volume suddenly.  It's because of the
missing call of snd_rme96_apply_dac_volume().

However, calling this function right after the DAC reset still may not
work, and we need some delay before this call.  Since the DAC reset
and the procedure after that are performed in the spinlock, we delay
the DAC volume restore at the end after the spinlock.

Reported-and-tested-by: Sylvain LABOISNE <maeda1@free.fr>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/pci/rme96.c | 41 ++++++++++++++++++++++++++---------------
 1 file changed, 26 insertions(+), 15 deletions(-)

diff --git a/sound/pci/rme96.c b/sound/pci/rme96.c
index 0236363..8dcc834 100644
--- a/sound/pci/rme96.c
+++ b/sound/pci/rme96.c
@@ -742,10 +742,11 @@ snd_rme96_playback_setrate(struct rme96 *rme96,
 	{
 		/* change to/from double-speed: reset the DAC (if available) */
 		snd_rme96_reset_dac(rme96);
+		return 1; /* need to restore volume */
 	} else {
 		writel(rme96->wcreg, rme96->iobase + RME96_IO_CONTROL_REGISTER);
+		return 0;
 	}
-	return 0;
 }
 
 static int
@@ -983,6 +984,7 @@ snd_rme96_playback_hw_params(struct snd_pcm_substream *substream,
 	struct rme96 *rme96 = snd_pcm_substream_chip(substream);
 	struct snd_pcm_runtime *runtime = substream->runtime;
 	int err, rate, dummy;
+	bool apply_dac_volume = false;
 
 	runtime->dma_area = (void __force *)(rme96->iobase +
 					     RME96_IO_PLAY_BUFFER);
@@ -996,24 +998,26 @@ snd_rme96_playback_hw_params(struct snd_pcm_substream *substream,
 	{
                 /* slave clock */
                 if ((int)params_rate(params) != rate) {
-			spin_unlock_irq(&rme96->lock);
-			return -EIO;                    
-                }
-	} else if ((err = snd_rme96_playback_setrate(rme96, params_rate(params))) < 0) {
-		spin_unlock_irq(&rme96->lock);
-		return err;
-	}
-	if ((err = snd_rme96_playback_setformat(rme96, params_format(params))) < 0) {
-		spin_unlock_irq(&rme96->lock);
-		return err;
+			err = -EIO;
+			goto error;
+		}
+	} else {
+		err = snd_rme96_playback_setrate(rme96, params_rate(params));
+		if (err < 0)
+			goto error;
+		apply_dac_volume = err > 0; /* need to restore volume later? */
 	}
+
+	err = snd_rme96_playback_setformat(rme96, params_format(params));
+	if (err < 0)
+		goto error;
 	snd_rme96_setframelog(rme96, params_channels(params), 1);
 	if (rme96->capture_periodsize != 0) {
 		if (params_period_size(params) << rme96->playback_frlog !=
 		    rme96->capture_periodsize)
 		{
-			spin_unlock_irq(&rme96->lock);
-			return -EBUSY;
+			err = -EBUSY;
+			goto error;
 		}
 	}
 	rme96->playback_periodsize =
@@ -1024,9 +1028,16 @@ snd_rme96_playback_hw_params(struct snd_pcm_substream *substream,
 		rme96->wcreg &= ~(RME96_WCR_PRO | RME96_WCR_DOLBY | RME96_WCR_EMP);
 		writel(rme96->wcreg |= rme96->wcreg_spdif_stream, rme96->iobase + RME96_IO_CONTROL_REGISTER);
 	}
+
+	err = 0;
+ error:
 	spin_unlock_irq(&rme96->lock);
-		
-	return 0;
+	if (apply_dac_volume) {
+		usleep_range(3000, 10000);
+		snd_rme96_apply_dac_volume(rme96);
+	}
+
+	return err;
 }
 
 static int
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315433 — [PATCH 3.13.y-ckt 017/108] net: ipmr: fix static mfc/dev leaks on table destruction

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 017/108] net: ipmr: fix static mfc/dev leaks on table destruction
Message-ID<qTTMu-2Oo-17@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>

commit 0e615e9601a15efeeb8942cf7cd4dadba0c8c5a7 upstream.

When destroying an mrt table the static mfc entries and the static
devices are kept, which leads to devices that can never be destroyed
(because of refcnt taken) and leaked memory, for example:
unreferenced object 0xffff880034c144c0 (size 192):
  comm "mfc-broken", pid 4777, jiffies 4320349055 (age 46001.964s)
  hex dump (first 32 bytes):
    98 53 f0 34 00 88 ff ff 98 53 f0 34 00 88 ff ff  .S.4.....S.4....
    ef 0a 0a 14 01 02 03 04 00 00 00 00 01 00 00 00  ................
  backtrace:
    [<ffffffff815c1b9e>] kmemleak_alloc+0x4e/0xb0
    [<ffffffff811ea6e0>] kmem_cache_alloc+0x190/0x300
    [<ffffffff815931cb>] ip_mroute_setsockopt+0x5cb/0x910
    [<ffffffff8153d575>] do_ip_setsockopt.isra.11+0x105/0xff0
    [<ffffffff8153e490>] ip_setsockopt+0x30/0xa0
    [<ffffffff81564e13>] raw_setsockopt+0x33/0x90
    [<ffffffff814d1e14>] sock_common_setsockopt+0x14/0x20
    [<ffffffff814d0b51>] SyS_setsockopt+0x71/0xc0
    [<ffffffff815cdbf6>] entry_SYSCALL_64_fastpath+0x16/0x7a
    [<ffffffffffffffff>] 0xffffffffffffffff

Make sure that everything is cleaned on netns destruction.

Signed-off-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
Reviewed-by: Cong Wang <cwang@twopensource.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/ipv4/ipmr.c | 15 ++++++++-------
 1 file changed, 8 insertions(+), 7 deletions(-)

diff --git a/net/ipv4/ipmr.c b/net/ipv4/ipmr.c
index a99f914..2f8de5f 100644
--- a/net/ipv4/ipmr.c
+++ b/net/ipv4/ipmr.c
@@ -136,7 +136,7 @@ static int __ipmr_fill_mroute(struct mr_table *mrt, struct sk_buff *skb,
 			      struct mfc_cache *c, struct rtmsg *rtm);
 static void mroute_netlink_event(struct mr_table *mrt, struct mfc_cache *mfc,
 				 int cmd);
-static void mroute_clean_tables(struct mr_table *mrt);
+static void mroute_clean_tables(struct mr_table *mrt, bool all);
 static void ipmr_expire_process(unsigned long arg);
 
 #ifdef CONFIG_IP_MROUTE_MULTIPLE_TABLES
@@ -348,7 +348,7 @@ static struct mr_table *ipmr_new_table(struct net *net, u32 id)
 static void ipmr_free_table(struct mr_table *mrt)
 {
 	del_timer_sync(&mrt->ipmr_expire_timer);
-	mroute_clean_tables(mrt);
+	mroute_clean_tables(mrt, true);
 	kfree(mrt);
 }
 
@@ -1199,7 +1199,7 @@ static int ipmr_mfc_add(struct net *net, struct mr_table *mrt,
  *	Close the multicast socket, and clear the vif tables etc
  */
 
-static void mroute_clean_tables(struct mr_table *mrt)
+static void mroute_clean_tables(struct mr_table *mrt, bool all)
 {
 	int i;
 	LIST_HEAD(list);
@@ -1208,8 +1208,9 @@ static void mroute_clean_tables(struct mr_table *mrt)
 	/* Shut down all active vif entries */
 
 	for (i = 0; i < mrt->maxvif; i++) {
-		if (!(mrt->vif_table[i].flags & VIFF_STATIC))
-			vif_delete(mrt, i, 0, &list);
+		if (!all && (mrt->vif_table[i].flags & VIFF_STATIC))
+			continue;
+		vif_delete(mrt, i, 0, &list);
 	}
 	unregister_netdevice_many(&list);
 
@@ -1217,7 +1218,7 @@ static void mroute_clean_tables(struct mr_table *mrt)
 
 	for (i = 0; i < MFC_LINES; i++) {
 		list_for_each_entry_safe(c, next, &mrt->mfc_cache_array[i], list) {
-			if (c->mfc_flags & MFC_STATIC)
+			if (!all && (c->mfc_flags & MFC_STATIC))
 				continue;
 			list_del_rcu(&c->list);
 			mroute_netlink_event(mrt, c, RTM_DELROUTE);
@@ -1252,7 +1253,7 @@ static void mrtsock_destruct(struct sock *sk)
 						    NETCONFA_IFINDEX_ALL,
 						    net->ipv4.devconf_all);
 			RCU_INIT_POINTER(mrt->mroute_sk, NULL);
-			mroute_clean_tables(mrt);
+			mroute_clean_tables(mrt, false);
 		}
 	}
 	rtnl_unlock();
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315434 — [PATCH 3.13.y-ckt 036/108] SCSI: Fix NULL pointer dereference in runtime PM

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 036/108] SCSI: Fix NULL pointer dereference in runtime PM
Message-ID<qTTMu-2Oo-27@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Ken Xue <ken.xue@amd.com>

commit 4fd41a8552afc01054d9d9fc7f1a63c324867d27 upstream.

The routines in scsi_pm.c assume that if a runtime-PM callback is
invoked for a SCSI device, it can only mean that the device's driver
has asked the block layer to handle the runtime power management (by
calling blk_pm_runtime_init(), which among other things sets q->dev).

However, this assumption turns out to be wrong for things like the ses
driver.  Normally ses devices are not allowed to do runtime PM, but
userspace can override this setting.  If this happens, the kernel gets
a NULL pointer dereference when blk_post_runtime_resume() tries to use
the uninitialized q->dev pointer.

This patch fixes the problem by checking q->dev in block layer before
handle runtime PM. Since ses doesn't define any PM callbacks and call
blk_pm_runtime_init(), the crash won't occur.

This fixes Bugzilla #101371.
https://bugzilla.kernel.org/show_bug.cgi?id=101371

More discussion can be found from below link.
http://marc.info/?l=linux-scsi&m=144163730531875&w=2

Signed-off-by: Ken Xue <Ken.Xue@amd.com>
Acked-by: Alan Stern <stern@rowland.harvard.edu>
Cc: Xiangliang Yu <Xiangliang.Yu@amd.com>
Cc: James E.J. Bottomley <JBottomley@odin.com>
Cc: Jens Axboe <axboe@kernel.dk>
Cc: Michael Terry <Michael.terry@canonical.com>
Signed-off-by: Jens Axboe <axboe@fb.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 block/blk-core.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/block/blk-core.c b/block/blk-core.c
index 3b974be..b885e23 100644
--- a/block/blk-core.c
+++ b/block/blk-core.c
@@ -3132,6 +3132,9 @@ int blk_pre_runtime_suspend(struct request_queue *q)
 {
 	int ret = 0;
 
+	if (!q->dev)
+		return ret;
+
 	spin_lock_irq(q->queue_lock);
 	if (q->nr_pending) {
 		ret = -EBUSY;
@@ -3159,6 +3162,9 @@ EXPORT_SYMBOL(blk_pre_runtime_suspend);
  */
 void blk_post_runtime_suspend(struct request_queue *q, int err)
 {
+	if (!q->dev)
+		return;
+
 	spin_lock_irq(q->queue_lock);
 	if (!err) {
 		q->rpm_status = RPM_SUSPENDED;
@@ -3183,6 +3189,9 @@ EXPORT_SYMBOL(blk_post_runtime_suspend);
  */
 void blk_pre_runtime_resume(struct request_queue *q)
 {
+	if (!q->dev)
+		return;
+
 	spin_lock_irq(q->queue_lock);
 	q->rpm_status = RPM_RESUMING;
 	spin_unlock_irq(q->queue_lock);
@@ -3205,6 +3214,9 @@ EXPORT_SYMBOL(blk_pre_runtime_resume);
  */
 void blk_post_runtime_resume(struct request_queue *q, int err)
 {
+	if (!q->dev)
+		return;
+
 	spin_lock_irq(q->queue_lock);
 	if (!err) {
 		q->rpm_status = RPM_ACTIVE;
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315435 — [PATCH 3.13.y-ckt 007/108] ipv6: sctp: clone options to avoid use after free

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 007/108] ipv6: sctp: clone options to avoid use after free
Message-ID<qTTMu-2Oo-21@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 9470e24f35ab81574da54e69df90c1eb4a96b43f ]

SCTP is lacking proper np->opt cloning at accept() time.

TCP and DCCP use ipv6_dup_options() helper, do the same
in SCTP.

We might later factorize this code in a common helper to avoid
future mistakes.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Vlad Yasevich <vyasevich@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/sctp/ipv6.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/net/sctp/ipv6.c b/net/sctp/ipv6.c
index 7567e6f..526e88c 100644
--- a/net/sctp/ipv6.c
+++ b/net/sctp/ipv6.c
@@ -638,6 +638,7 @@ static struct sock *sctp_v6_create_accept_sk(struct sock *sk,
 	struct sock *newsk;
 	struct ipv6_pinfo *newnp, *np = inet6_sk(sk);
 	struct sctp6_sock *newsctp6sk;
+	struct ipv6_txoptions *opt;
 
 	newsk = sk_alloc(sock_net(sk), PF_INET6, GFP_KERNEL, sk->sk_prot);
 	if (!newsk)
@@ -657,6 +658,13 @@ static struct sock *sctp_v6_create_accept_sk(struct sock *sk,
 
 	memcpy(newnp, np, sizeof(struct ipv6_pinfo));
 
+	rcu_read_lock();
+	opt = rcu_dereference(np->opt);
+	if (opt)
+		opt = ipv6_dup_options(newsk, opt);
+	RCU_INIT_POINTER(newnp->opt, opt);
+	rcu_read_unlock();
+
 	/* Initialize sk's sport, dport, rcv_saddr and daddr for getsockname()
 	 * and getpeername().
 	 */
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315436 — [PATCH 3.13.y-ckt 018/108] fuse: break infinite loop in fuse_fill_write_pages()

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 018/108] fuse: break infinite loop in fuse_fill_write_pages()
Message-ID<qTTMv-2Oo-29@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Roman Gushchin <klamm@yandex-team.ru>

commit 3ca8138f014a913f98e6ef40e939868e1e9ea876 upstream.

I got a report about unkillable task eating CPU. Further
investigation shows, that the problem is in the fuse_fill_write_pages()
function. If iov's first segment has zero length, we get an infinite
loop, because we never reach iov_iter_advance() call.

Fix this by calling iov_iter_advance() before repeating an attempt to
copy data from userspace.

A similar problem is described in 124d3b7041f ("fix writev regression:
pan hanging unkillable and un-straceable"). If zero-length segmend
is followed by segment with invalid address,
iov_iter_fault_in_readable() checks only first segment (zero-length),
iov_iter_copy_from_user_atomic() skips it, fails at second and
returns zero -> goto again without skipping zero-length segment.

Patch calls iov_iter_advance() before goto again: we'll skip zero-length
segment at second iteraction and iov_iter_fault_in_readable() will detect
invalid address.

Special thanks to Konstantin Khlebnikov, who helped a lot with the commit
description.

Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Maxim Patlasov <mpatlasov@parallels.com>
Cc: Konstantin Khlebnikov <khlebnikov@yandex-team.ru>
Signed-off-by: Roman Gushchin <klamm@yandex-team.ru>
Signed-off-by: Miklos Szeredi <miklos@szeredi.hu>
Fixes: ea9b9907b82a ("fuse: implement perform_write")
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/fuse/file.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/fuse/file.c b/fs/fuse/file.c
index 7e70506..f536000 100644
--- a/fs/fuse/file.c
+++ b/fs/fuse/file.c
@@ -993,6 +993,7 @@ static ssize_t fuse_fill_write_pages(struct fuse_req *req,
 
 		mark_page_accessed(page);
 
+		iov_iter_advance(ii, tmp);
 		if (!tmp) {
 			unlock_page(page);
 			page_cache_release(page);
@@ -1005,7 +1006,6 @@ static ssize_t fuse_fill_write_pages(struct fuse_req *req,
 		req->page_descs[req->num_pages].length = tmp;
 		req->num_pages++;
 
-		iov_iter_advance(ii, tmp);
 		count += tmp;
 		pos += tmp;
 		offset += tmp;
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315437 — [PATCH 3.13.y-ckt 041/108] 9p: ->evict_inode() should kick out ->i_data, not ->i_mapping

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 041/108] 9p: ->evict_inode() should kick out ->i_data, not ->i_mapping
Message-ID<qTTMv-2Oo-31@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Al Viro <viro@zeniv.linux.org.uk>

commit 4ad78628445d26e5e9487b2e8f23274ad7b0f5d3 upstream.

For block devices the pagecache is associated with the inode
on bdevfs, not with the aliasing ones on the mountable filesystems.
The latter have its own ->i_data empty and ->i_mapping pointing
to the (unique per major/minor) bdevfs inode.  That guarantees
cache coherence between all block device inodes with the same
device number.

Eviction of an alias inode has no business trying to evict the
pages belonging to bdevfs one; moreover, ->i_mapping is only
safe to access when the thing is opened.  At the time of
->evict_inode() the victim is definitely *not* opened.  We are
about to kill the address space embedded into struct inode
(inode->i_data) and that's what we need to empty of any pages.

9p instance tries to empty inode->i_mapping instead, which is
both unsafe and bogus - if we have several device nodes with
the same device number in different places, closing one of them
should not try to empty the (shared) page cache.

Fortunately, other instances in the tree are OK; they are
evicting from &inode->i_data instead, as 9p one should.

Reported-by: "Suzuki K. Poulose" <Suzuki.Poulose@arm.com>
Tested-by: "Suzuki K. Poulose" <Suzuki.Poulose@arm.com>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
[ kamal: backport to 3.13-stable: context ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/9p/vfs_inode.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/fs/9p/vfs_inode.c b/fs/9p/vfs_inode.c
index 5a80d7a..15e00c7 100644
--- a/fs/9p/vfs_inode.c
+++ b/fs/9p/vfs_inode.c
@@ -444,9 +444,9 @@ void v9fs_evict_inode(struct inode *inode)
 {
 	struct v9fs_inode *v9inode = V9FS_I(inode);
 
-	truncate_inode_pages(inode->i_mapping, 0);
+	truncate_inode_pages(&inode->i_data, 0);
 	clear_inode(inode);
-	filemap_fdatawrite(inode->i_mapping);
+	filemap_fdatawrite(&inode->i_data);
 
 	v9fs_cache_inode_put_cookie(inode);
 	/* clunk the fid stashed in writeback_fid */
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315438 — [PATCH 3.13.y-ckt 029/108] sata_sil: disable trim

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 029/108] sata_sil: disable trim
Message-ID<qTTMv-2Oo-33@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Mikulas Patocka <mpatocka@redhat.com>

commit d98f1cd0a3b70ea91f1dfda3ac36c3b2e1a4d5e2 upstream.

When I connect an Intel SSD to SATA SIL controller (PCI ID 1095:3114), any
TRIM command results in I/O errors being reported in the log. There is
other similar error reported with TRIM and the SIL controller:
https://bugs.centos.org/view.php?id=5880

Apparently the controller doesn't support TRIM commands. This patch
disables TRIM support on the SATA SIL controller.

ata7.00: exception Emask 0x0 SAct 0x0 SErr 0x0 action 0x0
ata7.00: BMDMA2 stat 0x50001
ata7.00: failed command: DATA SET MANAGEMENT
ata7.00: cmd 06/01:01:00:00:00/00:00:00:00:00/a0 tag 0 dma 512 out
         res 51/04:01:00:00:00/00:00:00:00:00/a0 Emask 0x1 (device error)
ata7.00: status: { DRDY ERR }
ata7.00: error: { ABRT }
ata7.00: device reported invalid CHS sector 0
sd 8:0:0:0: [sdb] tag#0 FAILED Result: hostbyte=DID_OK driverbyte=DRIVER_SENSE
sd 8:0:0:0: [sdb] tag#0 Sense Key : Illegal Request [current] [descriptor]
sd 8:0:0:0: [sdb] tag#0 Add. Sense: Unaligned write command
sd 8:0:0:0: [sdb] tag#0 CDB: Write same(16) 93 08 00 00 00 00 00 21 95 88 00 20 00 00 00 00
blk_update_request: I/O error, dev sdb, sector 2200968

Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/ata/sata_sil.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/ata/sata_sil.c b/drivers/ata/sata_sil.c
index b7695e8..fa94fba 100644
--- a/drivers/ata/sata_sil.c
+++ b/drivers/ata/sata_sil.c
@@ -631,6 +631,9 @@ static void sil_dev_config(struct ata_device *dev)
 	unsigned int n, quirks = 0;
 	unsigned char model_num[ATA_ID_PROD_LEN + 1];
 
+	/* This controller doesn't support trim */
+	dev->horkage |= ATA_HORKAGE_NOTRIM;
+
 	ata_id_c_string(dev->id, model_num, ATA_ID_PROD, sizeof(model_num));
 
 	for (n = 0; sil_blacklist[n].product; n++)
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315439 — [PATCH 3.13.y-ckt 040/108] virtio: fix memory leak of virtio ida cache layers

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 040/108] virtio: fix memory leak of virtio ida cache layers
Message-ID<qTTMv-2Oo-35@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Suman Anna <s-anna@ti.com>

commit c13f99b7e945dad5273a8b7ee230f4d1f22d3354 upstream.

The virtio core uses a static ida named virtio_index_ida for
assigning index numbers to virtio devices during registration.
The ida core may allocate some internal idr cache layers and
an ida bitmap upon any ida allocation, and all these layers are
truely freed only upon the ida destruction. The virtio_index_ida
is not destroyed at present, leading to a memory leak when using
the virtio core as a module and atleast one virtio device is
registered and unregistered.

Fix this by invoking ida_destroy() in the virtio core module
exit.

Signed-off-by: Suman Anna <s-anna@ti.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/virtio/virtio.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/virtio/virtio.c b/drivers/virtio/virtio.c
index fed0ce1..64eba4f 100644
--- a/drivers/virtio/virtio.c
+++ b/drivers/virtio/virtio.c
@@ -249,6 +249,7 @@ static int virtio_init(void)
 static void __exit virtio_exit(void)
 {
 	bus_unregister(&virtio_bus);
+	ida_destroy(&virtio_index_ida);
 }
 core_initcall(virtio_init);
 module_exit(virtio_exit);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315440 — [PATCH 3.13.y-ckt 010/108] pptp: verify sockaddr_len in pptp_bind() and pptp_connect()

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 010/108] pptp: verify sockaddr_len in pptp_bind() and pptp_connect()
Message-ID<qTTMv-2Oo-37@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: WANG Cong <xiyou.wangcong@gmail.com>

[ Upstream commit 09ccfd238e5a0e670d8178cf50180ea81ae09ae1 ]

Reported-by: Dmitry Vyukov <dvyukov@gmail.com>
Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/ppp/pptp.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/net/ppp/pptp.c b/drivers/net/ppp/pptp.c
index 1dc628f..0710214 100644
--- a/drivers/net/ppp/pptp.c
+++ b/drivers/net/ppp/pptp.c
@@ -420,6 +420,9 @@ static int pptp_bind(struct socket *sock, struct sockaddr *uservaddr,
 	struct pptp_opt *opt = &po->proto.pptp;
 	int error = 0;
 
+	if (sockaddr_len < sizeof(struct sockaddr_pppox))
+		return -EINVAL;
+
 	lock_sock(sk);
 
 	opt->src_addr = sp->sa_addr.pptp;
@@ -441,6 +444,9 @@ static int pptp_connect(struct socket *sock, struct sockaddr *uservaddr,
 	struct flowi4 fl4;
 	int error = 0;
 
+	if (sockaddr_len < sizeof(struct sockaddr_pppox))
+		return -EINVAL;
+
 	if (sp->sa_protocol != PX_PROTO_PPTP)
 		return -EINVAL;
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315441 — [PATCH 3.13.y-ckt 043/108] crypto: skcipher - Copy iv from desc even for 0-len walks

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 043/108] crypto: skcipher - Copy iv from desc even for 0-len walks
Message-ID<qTTMv-2Oo-39@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: "Jason A. Donenfeld" <Jason@zx2c4.com>

commit 70d906bc17500edfa9bdd8c8b7e59618c7911613 upstream.

Some ciphers actually support encrypting zero length plaintexts. For
example, many AEAD modes support this. The resulting ciphertext for
those winds up being only the authentication tag, which is a result of
the key, the iv, the additional data, and the fact that the plaintext
had zero length. The blkcipher constructors won't copy the IV to the
right place, however, when using a zero length input, resulting in
some significant problems when ciphers call their initialization
routines, only to find that the ->iv parameter is uninitialized. One
such example of this would be using chacha20poly1305 with a zero length
input, which then calls chacha20, which calls the key setup routine,
which eventually OOPSes due to the uninitialized ->iv member.

Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/ablkcipher.c | 2 +-
 crypto/blkcipher.c  | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/crypto/ablkcipher.c b/crypto/ablkcipher.c
index 520729d..f02fdbe 100644
--- a/crypto/ablkcipher.c
+++ b/crypto/ablkcipher.c
@@ -276,12 +276,12 @@ static int ablkcipher_walk_first(struct ablkcipher_request *req,
 	if (WARN_ON_ONCE(in_irq()))
 		return -EDEADLK;
 
+	walk->iv = req->info;
 	walk->nbytes = walk->total;
 	if (unlikely(!walk->total))
 		return 0;
 
 	walk->iv_buffer = NULL;
-	walk->iv = req->info;
 	if (unlikely(((unsigned long)walk->iv & alignmask))) {
 		int err = ablkcipher_copy_iv(walk, tfm, alignmask);
 		if (err)
diff --git a/crypto/blkcipher.c b/crypto/blkcipher.c
index a79e7e9..fd4aec7 100644
--- a/crypto/blkcipher.c
+++ b/crypto/blkcipher.c
@@ -329,12 +329,12 @@ static int blkcipher_walk_first(struct blkcipher_desc *desc,
 	if (WARN_ON_ONCE(in_irq()))
 		return -EDEADLK;
 
+	walk->iv = desc->info;
 	walk->nbytes = walk->total;
 	if (unlikely(!walk->total))
 		return 0;
 
 	walk->buffer = NULL;
-	walk->iv = desc->info;
 	if (unlikely(((unsigned long)walk->iv & alignmask))) {
 		int err = blkcipher_copy_iv(walk, tfm, alignmask);
 		if (err)
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315442 — [PATCH 3.13.y-ckt 019/108] usb: gadget: pxa27x: fix suspend callback

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 019/108] usb: gadget: pxa27x: fix suspend callback
Message-ID<qTTMv-2Oo-41@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Felipe Balbi <balbi@ti.com>

commit 391e6dcb37857d5659b53def2f41e2f56850d33c upstream.

pxa27x disconnects pullups on suspend but doesn't
notify the gadget driver about it, so gadget driver
can't disable the endpoints it was using.

This causes problems on resume because gadget core
will think endpoints are still enabled and just
ignore the following usb_ep_enable().

Fix this problem by calling
gadget_driver->disconnect().

Tested-by: Robert Jarzmik <robert.jarzmik@free.fr>
Signed-off-by: Felipe Balbi <balbi@ti.com>
[ luis: backported to 3.16:
  - file rename: drivers/usb/gadget/udc/pxa27x_udc.c ->
    drivers/usb/gadget/pxa27x_udc.c ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/usb/gadget/pxa27x_udc.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/usb/gadget/pxa27x_udc.c b/drivers/usb/gadget/pxa27x_udc.c
index 3c97da7..22b0e20 100644
--- a/drivers/usb/gadget/pxa27x_udc.c
+++ b/drivers/usb/gadget/pxa27x_udc.c
@@ -2555,6 +2555,9 @@ static int pxa_udc_suspend(struct platform_device *_dev, pm_message_t state)
 	udc->pullup_resume = udc->pullup_on;
 	dplus_pullup(udc, 0);
 
+	if (udc->driver)
+		udc->driver->disconnect(&udc->gadget);
+
 	return 0;
 }
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315443 — [PATCH 3.13.y-ckt 030/108] staging: lustre: echo_copy.._lsm() dereferences userland pointers directly

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 030/108] staging: lustre: echo_copy.._lsm() dereferences userland pointers directly
Message-ID<qTTMv-2Oo-43@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Al Viro <viro@ZenIV.linux.org.uk>

commit 9225c0b7b976dd9ceac2b80727a60d8fcb906a62 upstream.

missing get_user()

Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/staging/lustre/lustre/obdecho/echo_client.c | 20 +++++++++++---------
 1 file changed, 11 insertions(+), 9 deletions(-)

diff --git a/drivers/staging/lustre/lustre/obdecho/echo_client.c b/drivers/staging/lustre/lustre/obdecho/echo_client.c
index 1fb0ac4..b5ba46c 100644
--- a/drivers/staging/lustre/lustre/obdecho/echo_client.c
+++ b/drivers/staging/lustre/lustre/obdecho/echo_client.c
@@ -1381,6 +1381,7 @@ static int
 echo_copyout_lsm (struct lov_stripe_md *lsm, void *_ulsm, int ulsm_nob)
 {
 	struct lov_stripe_md *ulsm = _ulsm;
+	struct lov_oinfo **p;
 	int nob, i;
 
 	nob = offsetof (struct lov_stripe_md, lsm_oinfo[lsm->lsm_stripe_count]);
@@ -1390,9 +1391,10 @@ echo_copyout_lsm (struct lov_stripe_md *lsm, void *_ulsm, int ulsm_nob)
 	if (copy_to_user (ulsm, lsm, sizeof(*ulsm)))
 		return (-EFAULT);
 
-	for (i = 0; i < lsm->lsm_stripe_count; i++) {
-		if (copy_to_user (ulsm->lsm_oinfo[i], lsm->lsm_oinfo[i],
-				      sizeof(lsm->lsm_oinfo[0])))
+	for (i = 0, p = lsm->lsm_oinfo; i < lsm->lsm_stripe_count; i++, p++) {
+		struct lov_oinfo __user *up;
+		if (get_user(up, ulsm->lsm_oinfo + i) ||
+		    copy_to_user(up, *p, sizeof(struct lov_oinfo)))
 			return (-EFAULT);
 	}
 	return 0;
@@ -1400,9 +1402,10 @@ echo_copyout_lsm (struct lov_stripe_md *lsm, void *_ulsm, int ulsm_nob)
 
 static int
 echo_copyin_lsm (struct echo_device *ed, struct lov_stripe_md *lsm,
-		 void *ulsm, int ulsm_nob)
+		struct lov_stripe_md __user *ulsm, int ulsm_nob)
 {
 	struct echo_client_obd *ec = ed->ed_ec;
+	struct lov_oinfo **p;
 	int		     i;
 
 	if (ulsm_nob < sizeof (*lsm))
@@ -1418,11 +1421,10 @@ echo_copyin_lsm (struct echo_device *ed, struct lov_stripe_md *lsm,
 		return (-EINVAL);
 
 
-	for (i = 0; i < lsm->lsm_stripe_count; i++) {
-		if (copy_from_user(lsm->lsm_oinfo[i],
-				       ((struct lov_stripe_md *)ulsm)-> \
-				       lsm_oinfo[i],
-				       sizeof(lsm->lsm_oinfo[0])))
+	for (i = 0, p = lsm->lsm_oinfo; i < lsm->lsm_stripe_count; i++, p++) {
+		struct lov_oinfo __user *up;
+		if (get_user(up, ulsm->lsm_oinfo + i) ||
+		    copy_from_user(*p, up, sizeof(struct lov_oinfo)))
 			return (-EFAULT);
 	}
 	return (0);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315444 — [PATCH 3.13.y-ckt 037/108] usb: xhci: fix config fail of FS hub behind a HS hub with MTT

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 037/108] usb: xhci: fix config fail of FS hub behind a HS hub with MTT
Message-ID<qTTMv-2Oo-49@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Chunfeng Yun <chunfeng.yun@mediatek.com>

commit 096b110a3dd3c868e4610937c80d2e3f3357c1a9 upstream.

if a full speed hub connects to a high speed hub which
supports MTT, the MTT field of its slot context will be set
to 1 when xHCI driver setups an xHCI virtual device in
xhci_setup_addressable_virt_dev(); once usb core fetch its
hub descriptor, and need to update the xHC's internal data
structures for the device, the HUB field of its slot context
will be set to 1 too, meanwhile MTT is also set before,
this will cause configure endpoint command fail, so in the
case, we should clear MTT to 0 for full speed hub according
to section 6.2.2

Signed-off-by: Chunfeng Yun <chunfeng.yun@mediatek.com>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/usb/host/xhci.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/drivers/usb/host/xhci.c b/drivers/usb/host/xhci.c
index 3c42d4b..2951ccb 100644
--- a/drivers/usb/host/xhci.c
+++ b/drivers/usb/host/xhci.c
@@ -4689,8 +4689,16 @@ int xhci_update_hub_device(struct usb_hcd *hcd, struct usb_device *hdev,
 	ctrl_ctx->add_flags |= cpu_to_le32(SLOT_FLAG);
 	slot_ctx = xhci_get_slot_ctx(xhci, config_cmd->in_ctx);
 	slot_ctx->dev_info |= cpu_to_le32(DEV_HUB);
+	/*
+	 * refer to section 6.2.2: MTT should be 0 for full speed hub,
+	 * but it may be already set to 1 when setup an xHCI virtual
+	 * device, so clear it anyway.
+	 */
 	if (tt->multi)
 		slot_ctx->dev_info |= cpu_to_le32(DEV_MTT);
+	else if (hdev->speed == USB_SPEED_FULL)
+		slot_ctx->dev_info &= cpu_to_le32(~DEV_MTT);
+
 	if (xhci->hci_version > 0x95) {
 		xhci_dbg(xhci, "xHCI version %x needs hub "
 				"TT think time and number of ports\n",
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315445 — [PATCH 3.13.y-ckt 034/108] usb: Use the USB_SS_MULT() macro to decode burst multiplier for log message

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 034/108] usb: Use the USB_SS_MULT() macro to decode burst multiplier for log message
Message-ID<qTTMv-2Oo-45@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Ben Hutchings <ben@decadent.org.uk>

commit 5377adb092664d336ac212499961cac5e8728794 upstream.

usb_parse_ss_endpoint_companion() now decodes the burst multiplier
correctly in order to check that it's <= 3, but still uses the wrong
expression if warning that it's > 3.

Fixes: ff30cbc8da42 ("usb: Use the USB_SS_MULT() macro to get the ...")
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/usb/core/config.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/usb/core/config.c b/drivers/usb/core/config.c
index 85756bd..9b05e88 100644
--- a/drivers/usb/core/config.c
+++ b/drivers/usb/core/config.c
@@ -117,7 +117,8 @@ static void usb_parse_ss_endpoint_companion(struct device *ddev, int cfgno,
 		   USB_SS_MULT(desc->bmAttributes) > 3) {
 		dev_warn(ddev, "Isoc endpoint has Mult of %d in "
 				"config %d interface %d altsetting %d ep %d: "
-				"setting to 3\n", desc->bmAttributes + 1,
+				"setting to 3\n",
+				USB_SS_MULT(desc->bmAttributes),
 				cfgno, inum, asnum, ep->desc.bEndpointAddress);
 		ep->ss_ep_comp.bmAttributes = 2;
 	}
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315446 — [PATCH 3.13.y-ckt 027/108] i2c: mv64xxx: The n clockdiv factor is 0 based on sunxi SoCs

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 027/108] i2c: mv64xxx: The n clockdiv factor is 0 based on sunxi SoCs
Message-ID<qTTMv-2Oo-51@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Hans de Goede <hdegoede@redhat.com>

commit bba61f50f76574ca5b84b310925be7c2e8e64275 upstream.

According to the datasheets the n factor for dividing the tclk is
2 to the power n on Allwinner SoCs, not 2 to the power n + 1 as it is
on other mv64xxx implementations.

I've contacted Allwinner about this and they have confirmed that the
datasheet is correct.

This commit fixes the clk-divider calculations for Allwinner SoCs
accordingly.

Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Acked-by: Maxime Ripard <maxime.ripard@free-electrons.com>
Tested-by: Olliver Schinagl <oliver@schinagl.nl>
Signed-off-by: Wolfram Sang <wsa@the-dreams.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/i2c/busses/i2c-mv64xxx.c | 27 ++++++++++++++++++---------
 1 file changed, 18 insertions(+), 9 deletions(-)

diff --git a/drivers/i2c/busses/i2c-mv64xxx.c b/drivers/i2c/busses/i2c-mv64xxx.c
index cf89175..58dac22 100644
--- a/drivers/i2c/busses/i2c-mv64xxx.c
+++ b/drivers/i2c/busses/i2c-mv64xxx.c
@@ -148,6 +148,8 @@ struct mv64xxx_i2c_data {
 	bool			offload_enabled;
 /* 5us delay in order to avoid repeated start timing violation */
 	bool			errata_delay;
+	/* Clk div is 2 to the power n, not 2 to the power n + 1 */
+	bool			clk_n_base_0;
 };
 
 static struct mv64xxx_i2c_regs mv64xxx_i2c_regs_mv64xxx = {
@@ -695,25 +697,29 @@ MODULE_DEVICE_TABLE(of, mv64xxx_i2c_of_match_table);
 #ifdef CONFIG_OF
 #ifdef CONFIG_HAVE_CLK
 static int
-mv64xxx_calc_freq(const int tclk, const int n, const int m)
+mv64xxx_calc_freq(struct mv64xxx_i2c_data *drv_data,
+		  const int tclk, const int n, const int m)
 {
-	return tclk / (10 * (m + 1) * (2 << n));
+	if (drv_data->clk_n_base_0)
+		return tclk / (10 * (m + 1) * (1 << n));
+	else
+		return tclk / (10 * (m + 1) * (2 << n));
 }
 
 static bool
-mv64xxx_find_baud_factors(const u32 req_freq, const u32 tclk, u32 *best_n,
-			  u32 *best_m)
+mv64xxx_find_baud_factors(struct mv64xxx_i2c_data *drv_data,
+			  const u32 req_freq, const u32 tclk)
 {
 	int freq, delta, best_delta = INT_MAX;
 	int m, n;
 
 	for (n = 0; n <= 7; n++)
 		for (m = 0; m <= 15; m++) {
-			freq = mv64xxx_calc_freq(tclk, n, m);
+			freq = mv64xxx_calc_freq(drv_data, tclk, n, m);
 			delta = req_freq - freq;
 			if (delta >= 0 && delta < best_delta) {
-				*best_m = m;
-				*best_n = n;
+				drv_data->freq_m = m;
+				drv_data->freq_n = n;
 				best_delta = delta;
 			}
 			if (best_delta == 0)
@@ -751,8 +757,11 @@ mv64xxx_of_config(struct mv64xxx_i2c_data *drv_data,
 	if (of_property_read_u32(np, "clock-frequency", &bus_freq))
 		bus_freq = 100000; /* 100kHz by default */
 
-	if (!mv64xxx_find_baud_factors(bus_freq, tclk,
-				       &drv_data->freq_n, &drv_data->freq_m)) {
+	if (of_device_is_compatible(np, "allwinner,sun4i-a10-i2c") ||
+	    of_device_is_compatible(np, "allwinner,sun6i-a31-i2c"))
+		drv_data->clk_n_base_0 = true;
+
+	if (!mv64xxx_find_baud_factors(drv_data, bus_freq, tclk)) {
 		rc = -EINVAL;
 		goto out;
 	}
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315447 — [PATCH 3.13.y-ckt 035/108] dm btree: fix leak of bufio-backed block in btree_split_sibling error path

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 035/108] dm btree: fix leak of bufio-backed block in btree_split_sibling error path
Message-ID<qTTMw-2Oo-53@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Mike Snitzer <snitzer@redhat.com>

commit 30ce6e1cc5a0f781d60227e9096c86e188d2c2bd upstream.

The block allocated at the start of btree_split_sibling() is never
released if later insert_at() fails.

Fix this by releasing the previously allocated bufio block using
unlock_block().

Reported-by: Mikulas Patocka <mpatocka@redhat.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/md/persistent-data/dm-btree.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/md/persistent-data/dm-btree.c b/drivers/md/persistent-data/dm-btree.c
index fc3d733..28662bd 100644
--- a/drivers/md/persistent-data/dm-btree.c
+++ b/drivers/md/persistent-data/dm-btree.c
@@ -471,8 +471,10 @@ static int btree_split_sibling(struct shadow_spine *s, dm_block_t root,
 
 	r = insert_at(sizeof(__le64), pn, parent_index + 1,
 		      le64_to_cpu(rn->keys[0]), &location);
-	if (r)
+	if (r) {
+		unlock_block(s->info, right);
 		return r;
+	}
 
 	if (key < le64_to_cpu(rn->keys[0])) {
 		unlock_block(s->info, right);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315448 — [PATCH 3.13.y-ckt 033/108] USB: whci-hcd: add check for dma mapping error

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 033/108] USB: whci-hcd: add check for dma mapping error
Message-ID<qTTMw-2Oo-57@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Alexey Khoroshilov <khoroshilov@ispras.ru>

commit f9fa1887dcf26bd346665a6ae3d3f53dec54cba1 upstream.

qset_fill_page_list() do not check for dma mapping errors.

Found by Linux Driver Verification project (linuxtesting.org).

Signed-off-by: Alexey Khoroshilov <khoroshilov@ispras.ru>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/usb/host/whci/qset.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/usb/host/whci/qset.c b/drivers/usb/host/whci/qset.c
index dc31c42..9f1c053 100644
--- a/drivers/usb/host/whci/qset.c
+++ b/drivers/usb/host/whci/qset.c
@@ -377,6 +377,10 @@ static int qset_fill_page_list(struct whc *whc, struct whc_std *std, gfp_t mem_f
 	if (std->pl_virt == NULL)
 		return -ENOMEM;
 	std->dma_addr = dma_map_single(whc->wusbhc.dev, std->pl_virt, pl_len, DMA_TO_DEVICE);
+	if (dma_mapping_error(whc->wusbhc.dev, std->dma_addr)) {
+		kfree(std->pl_virt);
+		return -EFAULT;
+	}
 
 	for (p = 0; p < std->num_pointers; p++) {
 		std->pl_virt[p].buf_ptr = cpu_to_le64(dma_addr);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315449 — [PATCH 3.13.y-ckt 016/108] efi: Disable interrupts around EFI calls, not in the epilog/prolog calls

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 016/108] efi: Disable interrupts around EFI calls, not in the epilog/prolog calls
Message-ID<qTTMw-2Oo-59@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Ingo Molnar <mingo@kernel.org>

commit 23a0d4e8fa6d3a1d7fb819f79bcc0a3739c30ba9 upstream.

Tapasweni Pathak reported that we do a kmalloc() in efi_call_phys_prolog()
on x86-64 while having interrupts disabled, which is a big no-no, as
kmalloc() can sleep.

Solve this by removing the irq disabling from the prolog/epilog calls
around EFI calls: it's unnecessary, as in this stage we are single
threaded in the boot thread, and we don't ever execute this from
interrupt contexts.

Reported-by: Tapasweni Pathak <tapaswenipathak@gmail.com>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Matt Fleming <matt.fleming@intel.com>
[ luis: backported to 3.10: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/x86/platform/efi/efi.c    |  7 +++++++
 arch/x86/platform/efi/efi_32.c | 11 +++--------
 arch/x86/platform/efi/efi_64.c |  3 ---
 3 files changed, 10 insertions(+), 11 deletions(-)

diff --git a/arch/x86/platform/efi/efi.c b/arch/x86/platform/efi/efi.c
index 30075f9..a697fa5 100644
--- a/arch/x86/platform/efi/efi.c
+++ b/arch/x86/platform/efi/efi.c
@@ -244,12 +244,19 @@ static efi_status_t __init phys_efi_set_virtual_address_map(
 	efi_memory_desc_t *virtual_map)
 {
 	efi_status_t status;
+	unsigned long flags;
 
 	efi_call_phys_prelog();
+
+	/* Disable interrupts around EFI calls: */
+	local_irq_save(flags);
 	status = efi_call_phys4(efi_phys.set_virtual_address_map,
 				memory_map_size, descriptor_size,
 				descriptor_version, virtual_map);
+	local_irq_restore(flags);
+
 	efi_call_phys_epilog();
+
 	return status;
 }
 
diff --git a/arch/x86/platform/efi/efi_32.c b/arch/x86/platform/efi/efi_32.c
index 40e4469..bebbee0 100644
--- a/arch/x86/platform/efi/efi_32.c
+++ b/arch/x86/platform/efi/efi_32.c
@@ -33,19 +33,16 @@
 
 /*
  * To make EFI call EFI runtime service in physical addressing mode we need
- * prelog/epilog before/after the invocation to disable interrupt, to
- * claim EFI runtime service handler exclusively and to duplicate a memory in
- * low memory space say 0 - 3G.
+ * prolog/epilog before/after the invocation to claim the EFI runtime service
+ * handler exclusively and to duplicate a memory mapping in low memory space,
+ * say 0 - 3G.
  */
 
-static unsigned long efi_rt_eflags;
 
 void efi_call_phys_prelog(void)
 {
 	struct desc_ptr gdt_descr;
 
-	local_irq_save(efi_rt_eflags);
-
 	load_cr3(initial_page_table);
 	__flush_tlb_all();
 
@@ -64,6 +61,4 @@ void efi_call_phys_epilog(void)
 
 	load_cr3(swapper_pg_dir);
 	__flush_tlb_all();
-
-	local_irq_restore(efi_rt_eflags);
 }
diff --git a/arch/x86/platform/efi/efi_64.c b/arch/x86/platform/efi/efi_64.c
index 39a0e7f..2f6c1a9 100644
--- a/arch/x86/platform/efi/efi_64.c
+++ b/arch/x86/platform/efi/efi_64.c
@@ -40,7 +40,6 @@
 #include <asm/fixmap.h>
 
 static pgd_t *save_pgd __initdata;
-static unsigned long efi_flags __initdata;
 
 static void __init early_code_mapping_set_exec(int executable)
 {
@@ -66,7 +65,6 @@ void __init efi_call_phys_prelog(void)
 	int n_pgds;
 
 	early_code_mapping_set_exec(1);
-	local_irq_save(efi_flags);
 
 	n_pgds = DIV_ROUND_UP((max_pfn << PAGE_SHIFT), PGDIR_SIZE);
 	save_pgd = kmalloc(n_pgds * sizeof(pgd_t), GFP_KERNEL);
@@ -90,7 +88,6 @@ void __init efi_call_phys_epilog(void)
 		set_pgd(pgd_offset_k(pgd * PGDIR_SIZE), save_pgd[pgd]);
 	kfree(save_pgd);
 	__flush_tlb_all();
-	local_irq_restore(efi_flags);
 	early_code_mapping_set_exec(0);
 }
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1315450 — [PATCH 3.13.y-ckt 008/108] net: add validation for the socket syscall protocol argument

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-23 01:00 +0100
Subject[PATCH 3.13.y-ckt 008/108] net: add validation for the socket syscall protocol argument
Message-ID<qTTMw-2Oo-61@gated-at.bofh.it>
In reply to#1315368
3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Hannes Frederic Sowa <hannes@stressinduktion.org>

[ Upstream commit 79462ad02e861803b3840cc782248c7359451cd9 ]

郭永刚 reported that one could simply crash the kernel as root by
using a simple program:

	int socket_fd;
	struct sockaddr_in addr;
	addr.sin_port = 0;
	addr.sin_addr.s_addr = INADDR_ANY;
	addr.sin_family = 10;

	socket_fd = socket(10,3,0x40000000);
	connect(socket_fd , &addr,16);

AF_INET, AF_INET6 sockets actually only support 8-bit protocol
identifiers. inet_sock's skc_protocol field thus is sized accordingly,
thus larger protocol identifiers simply cut off the higher bits and
store a zero in the protocol fields.

This could lead to e.g. NULL function pointer because as a result of
the cut off inet_num is zero and we call down to inet_autobind, which
is NULL for raw sockets.

kernel: Call Trace:
kernel:  [<ffffffff816db90e>] ? inet_autobind+0x2e/0x70
kernel:  [<ffffffff816db9a4>] inet_dgram_connect+0x54/0x80
kernel:  [<ffffffff81645069>] SYSC_connect+0xd9/0x110
kernel:  [<ffffffff810ac51b>] ? ptrace_notify+0x5b/0x80
kernel:  [<ffffffff810236d8>] ? syscall_trace_enter_phase2+0x108/0x200
kernel:  [<ffffffff81645e0e>] SyS_connect+0xe/0x10
kernel:  [<ffffffff81779515>] tracesys_phase2+0x84/0x89

I found no particular commit which introduced this problem.

CVE: CVE-2015-8543
Cc: Cong Wang <cwang@twopensource.com>
Reported-by: 郭永刚 <guoyonggang@360.cn>
Signed-off-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ kamal: backport to 3.13-stable: hardcoded U8_MAX value ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 include/net/sock.h     | 1 +
 net/ax25/af_ax25.c     | 3 +++
 net/decnet/af_decnet.c | 3 +++
 net/ipv4/af_inet.c     | 3 +++
 net/ipv6/af_inet6.c    | 3 +++
 net/irda/af_irda.c     | 3 +++
 6 files changed, 16 insertions(+)

diff --git a/include/net/sock.h b/include/net/sock.h
index 42377ef4..6367a0d 100644
--- a/include/net/sock.h
+++ b/include/net/sock.h
@@ -369,6 +369,7 @@ struct sock {
 				sk_no_check  : 2,
 				sk_userlocks : 4,
 				sk_protocol  : 8,
+#define SK_PROTOCOL_MAX ((u8)~0U)
 				sk_type      : 16;
 	kmemcheck_bitfield_end(flags);
 	int			sk_wmem_queued;
diff --git a/net/ax25/af_ax25.c b/net/ax25/af_ax25.c
index 7bb1605..8967279 100644
--- a/net/ax25/af_ax25.c
+++ b/net/ax25/af_ax25.c
@@ -806,6 +806,9 @@ static int ax25_create(struct net *net, struct socket *sock, int protocol,
 	struct sock *sk;
 	ax25_cb *ax25;
 
+	if (protocol < 0 || protocol > SK_PROTOCOL_MAX)
+		return -EINVAL;
+
 	if (!net_eq(net, &init_net))
 		return -EAFNOSUPPORT;
 
diff --git a/net/decnet/af_decnet.c b/net/decnet/af_decnet.c
index dd4d506..c030d5c 100644
--- a/net/decnet/af_decnet.c
+++ b/net/decnet/af_decnet.c
@@ -677,6 +677,9 @@ static int dn_create(struct net *net, struct socket *sock, int protocol,
 {
 	struct sock *sk;
 
+	if (protocol < 0 || protocol > SK_PROTOCOL_MAX)
+		return -EINVAL;
+
 	if (!net_eq(net, &init_net))
 		return -EAFNOSUPPORT;
 
diff --git a/net/ipv4/af_inet.c b/net/ipv4/af_inet.c
index 7dd59a8..24a8918 100644
--- a/net/ipv4/af_inet.c
+++ b/net/ipv4/af_inet.c
@@ -263,6 +263,9 @@ static int inet_create(struct net *net, struct socket *sock, int protocol,
 	int try_loading_module = 0;
 	int err;
 
+	if (protocol < 0 || protocol >= IPPROTO_MAX)
+		return -EINVAL;
+
 	sock->state = SS_UNCONNECTED;
 
 	/* Look for the requested type/protocol pair. */
diff --git a/net/ipv6/af_inet6.c b/net/ipv6/af_inet6.c
index 4fbdb70..d064527 100644
--- a/net/ipv6/af_inet6.c
+++ b/net/ipv6/af_inet6.c
@@ -110,6 +110,9 @@ static int inet6_create(struct net *net, struct socket *sock, int protocol,
 	int try_loading_module = 0;
 	int err;
 
+	if (protocol < 0 || protocol >= IPPROTO_MAX)
+		return -EINVAL;
+
 	/* Look for the requested type/protocol pair. */
 lookup_protocol:
 	err = -ESOCKTNOSUPPORT;
diff --git a/net/irda/af_irda.c b/net/irda/af_irda.c
index de7db23..d70e530 100644
--- a/net/irda/af_irda.c
+++ b/net/irda/af_irda.c
@@ -1105,6 +1105,9 @@ static int irda_create(struct net *net, struct socket *sock, int protocol,
 
 	IRDA_DEBUG(2, "%s()\n", __func__);
 
+	if (protocol < 0 || protocol > SK_PROTOCOL_MAX)
+		return -EINVAL;
+
 	if (net != &init_net)
 		return -EAFNOSUPPORT;
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


Page 4 of 5 — ← Prev page 1 2 3 [4] 5  Next page →

Back to top | Article view | linux.kernel


csiph-web