Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1315999 > unrolled thread

[3.16.y-ckt stable] Linux 3.16.7-ckt23 stable review

Started byLuis Henriques <luis.henriques@canonical.com>
First post2016-01-24 23:10 +0100
Last post2016-01-25 12:00 +0100
Articles 20 on this page of 122 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [3.16.y-ckt stable] Linux 3.16.7-ckt23 stable review Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 118/128] x86/mce: Ensure offline CPUs don't participate in rendezvous process Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 002/128] usb: gadget: pxa27x: fix suspend callback Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 008/128] jbd2: Fix unreclaimed pages after truncate in data=journal mode Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 077/128] xen-blkback: read from indirect descriptors only once Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 085/128] USB: fix invalid memory access in hub_activate() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 126/128] firmware: dmi_scan: Fix UUID endianness for SMBIOS >= 2.6 Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 125/128] kvm: x86: only channel 0 of the i8254 is linked to the HPET Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 104/128] parisc: Fix syscall restarts Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 034/128] dm thin metadata: fix bug when taking a metadata snapshot Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 123/128] net: filter: make JITs zero A for SKF_AD_ALU_XOR_X Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 098/128] ASoC: wm8974: set cache type for regmap Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 122/128] ASoC: Use nested lock for snd_soc_dapm_mutex_lock Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 062/128] n_tty: Fix poll() after buffer-limited eof push read Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 095/128] drm/i915: Fix SRC_COPY width on 830/845g Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 102/128] ALSA: hda - Set SKL+ hda controller power at freeze() and thaw() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 013/128] staging: lustre: echo_copy.._lsm() dereferences userland pointers directly Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 127/128] udp: properly support MSG_PEEK with truncated buffers Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
      Re: [PATCH 3.16.y-ckt 127/128] udp: properly support MSG_PEEK with  truncated buffers Ben Hutchings <ben@decadent.org.uk> - 2016-01-25 02:50 +0100
        Re: [PATCH 3.16.y-ckt 127/128] udp: properly support MSG_PEEK with  truncated buffers Luis Henriques <luis.henriques@canonical.com> - 2016-01-25 12:00 +0100
    [PATCH 3.16.y-ckt 124/128] net: possible use after free in dst_release Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 111/128] net/mlx4_en: Fix HW timestamp init issue upon system startup Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 120/128] async_tx: use GFP_NOWAIT rather than GFP_IO Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 023/128] ALSA: hda - Add inverted dmic for Packard Bell DOTS Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 109/128] mm/memory_hotplug.c: check for missing sections in test_pages_in_a_zone() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 119/128] ASoC: arizona: Fix bclk for sample rates that are multiple of 4kHz Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 071/128] powerpc/powernv: Fix the overflow of OPAL message notifiers head array Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 067/128] spi: fix parent-device reference leak Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 011/128] sata_sil: disable trim Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 114/128] genirq: Prevent chip buslock deadlock Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 093/128] net: fix warnings in 'make htmldocs' by moving macro definition out of field declaration Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 112/128] ipv6/addrlabel: fix ip6addrlbl_get() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 091/128] qlcnic: fix a timeout loop Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 097/128] KVM: PPC: Book3S HV: Prohibit setting illegal transaction state in MSR Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 107/128] [PATCH] arm: fix handling of F_OFD_... in oabi_fcntl64() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 087/128] net: phy: mdio-mux: Check return value of mdiobus_alloc() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 092/128] ser_gigaset: fix deallocation of platform device structure Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 103/128] s390/dis: Fix handling of format specifiers Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 108/128] ocfs2: fix BUG when calculate new backup super Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 084/128] USB: ipaq.c: fix a timeout loop Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 094/128] include/linux/mmdebug.h: should include linux/bug.h Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 099/128] ARM: dts: imx6: Fix Ethernet PHY mode on Ventana boards Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 096/128] vmstat: allocate vmstat_wq before it is used Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 100/128] scripts: recordmcount: break hardlinks Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 106/128] MIPS: uaccess: Fix strlen_user with EVA Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 105/128] ALSA: hda/realtek - Fix silent headphone output on MacPro 4,1 (v2) Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 113/128] qlcnic: fix a loop exit condition better Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 080/128] xen/pciback: Return error on XEN_PCI_OP_enable_msix when device has MSI or MSI-X enabled Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 110/128] net/mlx4_en: Remove dependency between timestamping capability and service_task Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 090/128] amd-xgbe: fix a couple timeout loops Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 101/128] ftrace/scripts: Have recordmcount copy the object file Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 086/128] pinctrl: bcm2835: Fix initial value for direction_output Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 082/128] xen/pciback: For XEN_PCI_OP_disable_msi[|x] only disable if device has MSI(X) enabled. Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 088/128] sh_eth: fix TX buffer byte-swapping Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    Re: [PATCH 3.16.y-ckt 043/128] mm, vmstat: allow WQ concurrency to  discover memory reclaim doesn't make any progress Ben Hutchings <ben@decadent.org.uk> - 2016-01-24 23:20 +0100
      Re: [PATCH 3.16.y-ckt 043/128] mm, vmstat: allow WQ concurrency to  discover memory reclaim doesn't make any progress Luis Henriques <luis.henriques@canonical.com> - 2016-01-25 12:00 +0100
    [PATCH 3.16.y-ckt 081/128] xen/pciback: Do not install an IRQ handler for MSI interrupts. Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 083/128] xen/pciback: Don't allow MSI-X ops if PCI_COMMAND_MEMORY is not set. Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 063/128] tty: Fix GPF in flush_to_ldisc() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 059/128] Revert "SCSI: Fix NULL pointer dereference in runtime PM" Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 074/128] xen-netback: don't use last request to determine minimum Tx credit Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 030/128] radeon/cik: Fix GFX IB test on Big-Endian Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 070/128] ARC: dw2 unwind: Ignore CIE version !=1 gracefully instead of bailing Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 075/128] xen-netback: use RING_COPY_REQUEST() throughout Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 057/128] rfkill: copy the name into the rfkill struct Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 060/128] ses: fix additional element traversal bug Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 079/128] xen/pciback: Return error on XEN_PCI_OP_enable_msi when device has MSI or MSI-X enabled Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 064/128] ALSA: usb-audio: Add a more accurate volume quirk for AudioQuest DragonFly Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 073/128] xen: Add RING_COPY_REQUEST() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 055/128] video: fbdev: fsl: Fix kernel crash when diu_ops is not implemented Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 019/128] SCSI: Fix NULL pointer dereference in runtime PM Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 027/128] IB/srp: Fix possible send queue overflow Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 068/128] dma-debug: Fix dma_debug_entry offset calculation Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 022/128] ALSA: rme96: Fix unexpected volume reset after rate changes Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 014/128] irqchip/versatile-fpga: Fix PCI IRQ mapping on Versatile PB Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 052/128] tools: Add a "make all" rule Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 056/128] crypto: skcipher - Copy iv from desc even for 0-len walks Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 069/128] ARC: dw2 unwind: Reinstante unwinding out of modules Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 054/128] xen/events/fifo: Consume unprocessed events when a CPU dies Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 016/128] USB: whci-hcd: add check for dma mapping error Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 017/128] usb: Use the USB_SS_MULT() macro to decode burst multiplier for log message Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 040/128] USB: add quirk for devices with broken LPM Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 018/128] dm btree: fix leak of bufio-backed block in btree_split_sibling error path Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 061/128] powercap / RAPL: fix BIOS lock check Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 058/128] ses: Fix problems with simple enclosures Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 076/128] xen-blkback: only read request operation from shared ring once Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 066/128] ALSA: hda - Add a fixup for Thinkpad X1 Carbon 2nd Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 072/128] powerpc/powernv: pr_warn_once on unsupported OPAL_MSG type Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 065/128] ARM: 8471/1: need to save/restore arm register(r11) when it is corrupted Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 053/128] i2c: mv64xxx: The n clockdiv factor is 0 based on sunxi SoCs Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 042/128] mm: hugetlb: fix hugepage memory leak caused by wrong reserve count Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 033/128] ALSA: hda - Fix noise problems on Thinkpad T440s Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 049/128] efi: Disable interrupts around EFI calls, not in the epilog/prolog calls Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 039/128] xhci: fix usb2 resume timing and races. Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 046/128] ocfs2: fix SGID not inherited issue Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 045/128] drivers/base/memory.c: prohibit offlining of memory blocks with missing sections Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 005/128] USB: cdc_acm: Ignore Infineon Flash Loader utility Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 010/128] AHCI: Fix softreset failed issue of Port Multiplier Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 031/128] radeon: Fix VCE ring test for Big-Endian systems Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 004/128] USB: cp210x: Remove CP2110 ID from compatibility list Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 006/128] USB: serial: Another Infineon flash loader USB ID Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 050/128] MIPS: uaccess: Take EVA into account in __copy_from_user() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 037/128] dm btree: fix bufio buffer leaks in dm_btree_del() error path Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 051/128] MIPS: uaccess: Take EVA into account in [__]clear_user Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 007/128] ext4: Fix handling of extended tv_sec Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 036/128] ipmi: move timer init to before irq is setup Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 035/128] dm space map metadata: fix ref counting bug when bootstrapping a new space map Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 032/128] radeon: Fix VCE IB test on Big-Endian systems Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 043/128] mm, vmstat: allow WQ concurrency to discover memory reclaim doesn't make any progress Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 041/128] parisc iommu: fix panic due to trying to allocate too large region Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 048/128] usb: musb: USB_TI_CPPI41_DMA requires dmaengine support Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 047/128] sh64: fix __NR_fgetxattr Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 038/128] vgaarb: fix signal handling in vga_get() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 044/128] mm: hugetlb: call huge_pte_alloc() only if ptep is null Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 029/128] 9p: ->evict_inode() should kick out ->i_data, not ->i_mapping Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 028/128] ALSA: hda - Fixing speaker noise on the two latest thinkpad models Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:50 +0100
    [PATCH 3.16.y-ckt 025/128] nfs4: limit callback decoding to received bytes Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:50 +0100
    [PATCH 3.16.y-ckt 021/128] usb: xhci: fix config fail of FS hub behind a HS hub with MTT Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:50 +0100
    [PATCH 3.16.y-ckt 026/128] SUNRPC: Fix callback channel Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:50 +0100
    [PATCH 3.16.y-ckt 020/128] perf: Fix PERF_EVENT_IOC_PERIOD deadlock Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:50 +0100
    [PATCH 3.16.y-ckt 024/128] virtio: fix memory leak of virtio ida cache layers Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:50 +0100
    [PATCH 3.16.y-ckt 129/129] Revert "[stable-only] net: add length argument to skb_copy_and_csum_datagram_iovec" Luis Henriques <luis.henriques@canonical.com> - 2016-01-25 12:00 +0100

Page 1 of 7  [1] 2 3 4 5 6 7  Next page →


#1315999 — [3.16.y-ckt stable] Linux 3.16.7-ckt23 stable review

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[3.16.y-ckt stable] Linux 3.16.7-ckt23 stable review
Message-ID<qUB17-2KY-3@gated-at.bofh.it>
This is the start of the review cycle for the Linux 3.16.7-ckt23 stable kernel.

This version contains 128 new patches, summarized below.  The new patches are
posted as replies to this message and also available in this git branch:

http://kernel.ubuntu.com/git/ubuntu/linux.git/log/?h=linux-3.16.y-review

git://kernel.ubuntu.com/ubuntu/linux.git  linux-3.16.y-review

The review period for version 3.16.7-ckt23 will be open for the next three days.
To report a problem, please reply to the relevant follow-up patch message.

For more information about the Linux 3.16.y-ckt extended stable kernel version,
see https://wiki.ubuntu.com/Kernel/Dev/ExtendedStable .

 -Luis

--
 arch/arc/include/asm/unwind.h                      |   4 -
 arch/arc/kernel/setup.c                            |   1 -
 arch/arc/kernel/unwind.c                           |  53 +++++---
 arch/arm/boot/dts/imx6q-gw5400-a.dts               |   2 +-
 arch/arm/boot/dts/imx6qdl-gw51xx.dtsi              |   2 +-
 arch/arm/boot/dts/imx6qdl-gw52xx.dtsi              |   2 +-
 arch/arm/boot/dts/imx6qdl-gw53xx.dtsi              |   2 +-
 arch/arm/boot/dts/imx6qdl-gw54xx.dtsi              |   2 +-
 arch/arm/boot/dts/wm8650.dtsi                      |   9 ++
 arch/arm/kernel/sys_oabi-compat.c                  |  73 +++++------
 arch/arm/mm/proc-v7.S                              |   4 +-
 arch/arm/net/bpf_jit_32.c                          |  16 +--
 arch/mips/include/asm/uaccess.h                    |  46 ++++---
 arch/mips/kernel/mips_ksyms.c                      |   2 +
 arch/mips/lib/memset.S                             |   2 +
 arch/mips/net/bpf_jit.c                            |  16 +--
 arch/parisc/kernel/signal.c                        |  64 ++++++++--
 arch/powerpc/kvm/book3s_hv.c                       |   6 +
 arch/powerpc/net/bpf_jit_comp.c                    |  13 +-
 arch/powerpc/platforms/powernv/opal.c              |  14 +--
 arch/s390/kernel/dis.c                             |  15 ++-
 arch/sh/include/uapi/asm/unistd_64.h               |   2 +-
 arch/sparc/net/bpf_jit_comp.c                      |  17 +--
 arch/x86/kernel/cpu/mcheck/mce.c                   |  11 ++
 arch/x86/kvm/i8254.c                               |   1 +
 arch/x86/kvm/x86.c                                 |   3 +-
 arch/x86/platform/efi/efi.c                        |   7 ++
 arch/x86/platform/efi/efi_32.c                     |  11 +-
 arch/x86/platform/efi/efi_64.c                     |   3 -
 block/blk-core.c                                   |  12 ++
 crypto/ablkcipher.c                                |   2 +-
 crypto/async_tx/async_memcpy.c                     |   2 +-
 crypto/async_tx/async_pq.c                         |   4 +-
 crypto/async_tx/async_raid6_recov.c                |   4 +-
 crypto/async_tx/async_xor.c                        |   4 +-
 crypto/blkcipher.c                                 |   2 +-
 drivers/ata/libahci.c                              |   9 ++
 drivers/ata/sata_sil.c                             |   3 +
 drivers/base/memory.c                              |   4 +
 drivers/block/xen-blkback/blkback.c                |  15 ++-
 drivers/block/xen-blkback/common.h                 |   8 +-
 drivers/char/ipmi/ipmi_si_intf.c                   |   8 +-
 drivers/firmware/dmi_scan.c                        |   5 +-
 drivers/gpu/drm/i915/intel_ringbuffer.c            |   2 +-
 drivers/gpu/drm/radeon/cik.c                       |   6 +-
 drivers/gpu/drm/radeon/radeon_vce.c                | 100 +++++++--------
 drivers/gpu/drm/ttm/ttm_lock.c                     |   2 +-
 drivers/gpu/vga/vgaarb.c                           |   6 +-
 drivers/i2c/busses/i2c-mv64xxx.c                   |  27 ++--
 drivers/iio/industrialio-buffer.c                  |   2 +-
 drivers/iio/industrialio-core.c                    |   2 +-
 drivers/infiniband/ulp/srp/ib_srp.c                |   2 +-
 drivers/irqchip/irq-versatile-fpga.c               |   5 +
 drivers/isdn/gigaset/ser-gigaset.c                 |  10 +-
 drivers/isdn/hardware/mISDN/mISDNipac.c            |   7 +-
 drivers/md/dm-thin-metadata.c                      |   6 +
 drivers/md/persistent-data/dm-btree.c              |  20 ++-
 drivers/md/persistent-data/dm-space-map-metadata.c |  32 +++--
 drivers/net/ethernet/amd/xgbe/xgbe-dev.c           |   4 +-
 drivers/net/ethernet/mellanox/mlx4/en_clock.c      |   7 ++
 drivers/net/ethernet/mellanox/mlx4/en_main.c       |   7 --
 drivers/net/ethernet/mellanox/mlx4/en_netdev.c     |  10 +-
 .../net/ethernet/qlogic/qlcnic/qlcnic_83xx_vnic.c  |   5 +-
 drivers/net/ethernet/renesas/sh_eth.c              |   3 +-
 drivers/net/phy/mdio-mux.c                         |   7 +-
 drivers/net/xen-netback/netback.c                  |  34 +++--
 drivers/parisc/iommu-helpers.h                     |  15 +--
 drivers/pinctrl/pinctrl-bcm2835.c                  |  13 +-
 drivers/powercap/intel_rapl.c                      |   7 +-
 drivers/scsi/scsi_pm.c                             |  20 +--
 drivers/scsi/ses.c                                 |  30 ++++-
 drivers/spi/spi.c                                  |   2 +-
 .../staging/lustre/lustre/obdecho/echo_client.c    |  20 +--
 drivers/tty/n_tty.c                                |  22 ++--
 drivers/tty/tty_buffer.c                           |   2 +-
 drivers/usb/class/cdc-acm.c                        |   5 +
 drivers/usb/core/config.c                          |   3 +-
 drivers/usb/core/hub.c                             |  45 +++++--
 drivers/usb/core/quirks.c                          |   6 +
 drivers/usb/gadget/pxa27x_udc.c                    |   3 +
 drivers/usb/host/whci/qset.c                       |   4 +
 drivers/usb/host/xhci-hub.c                        |  47 ++++++-
 drivers/usb/host/xhci-ring.c                       |   3 +-
 drivers/usb/host/xhci.c                            |   8 ++
 drivers/usb/musb/Kconfig                           |   2 +-
 drivers/usb/serial/cp210x.c                        |   1 -
 drivers/usb/serial/ipaq.c                          |   3 +-
 drivers/usb/serial/usb-serial-simple.c             |   1 +
 drivers/usb/storage/uas.c                          |   4 +
 drivers/usb/storage/unusual_devs.h                 |   2 +-
 drivers/usb/storage/unusual_uas.h                  |   2 +-
 drivers/video/fbdev/fsl-diu-fb.c                   |  13 +-
 drivers/virtio/virtio.c                            |   1 +
 drivers/xen/events/events_fifo.c                   |  23 +++-
 drivers/xen/xen-pciback/pciback.h                  |   1 +
 drivers/xen/xen-pciback/pciback_ops.c              |  75 ++++++++---
 fs/9p/vfs_inode.c                                  |   4 +-
 fs/ext4/ext4.h                                     |  51 ++++++--
 fs/fuse/file.c                                     |   2 +-
 fs/jbd2/transaction.c                              |   2 +
 fs/ocfs2/namei.c                                   |   4 +-
 fs/ocfs2/resize.c                                  |  15 ++-
 include/linux/enclosure.h                          |   4 +
 include/linux/filter.h                             |  19 +++
 include/linux/ftrace.h                             |   1 +
 include/linux/mmdebug.h                            |   1 +
 include/linux/usb/quirks.h                         |   3 +
 include/net/sock.h                                 |   2 +-
 include/sound/soc.h                                |   2 +-
 include/xen/interface/io/ring.h                    |  14 +++
 kernel/events/core.c                               |   9 +-
 kernel/irq/manage.c                                |   6 +-
 kernel/module.c                                    |   6 +
 kernel/trace/trace_printk.c                        |   1 +
 lib/dma-debug.c                                    |   4 +-
 mm/backing-dev.c                                   |  19 ++-
 mm/hugetlb.c                                       |  13 +-
 mm/memory_hotplug.c                                |  31 +++--
 mm/vmstat.c                                        |   7 +-
 net/core/dst.c                                     |   3 +-
 net/ipv4/udp.c                                     |   6 +-
 net/ipv6/addrlabel.c                               |   2 +-
 net/ipv6/udp.c                                     |   6 +-
 net/rfkill/core.c                                  |   6 +-
 net/sunrpc/svc.c                                   |  13 ++
 scripts/recordmcount.c                             | 137 +++++++++++++++++----
 security/keys/process_keys.c                       |   1 +
 sound/pci/hda/hda_intel.c                          |  34 +++++
 sound/pci/hda/patch_realtek.c                      |  44 ++++++-
 sound/pci/rme96.c                                  |  41 +++---
 sound/soc/codecs/arizona.c                         |   2 +-
 sound/soc/codecs/wm8974.c                          |   1 +
 sound/usb/mixer.c                                  |   2 +
 sound/usb/mixer_maps.c                             |  12 --
 sound/usb/mixer_quirks.c                           |  37 ++++++
 sound/usb/mixer_quirks.h                           |   4 +
 tools/Makefile                                     |   9 ++
 137 files changed, 1226 insertions(+), 528 deletions(-)

Al Viro (3):
      staging: lustre: echo_copy.._lsm() dereferences userland pointers directly
      9p: ->evict_inode() should kick out ->i_data, not ->i_mapping
      arm: fix handling of F_OFD_... in oabi_fcntl64()

Alan Stern (2):
      USB: add quirk for devices with broken LPM
      USB: fix invalid memory access in hub_activate()

Alexey Khoroshilov (1):
      USB: whci-hcd: add check for dma mapping error

Andrea Arcangeli (1):
      firmware: dmi_scan: Fix UUID endianness for SMBIOS >= 2.6

Andrew Banman (1):
      mm/memory_hotplug.c: check for missing sections in test_pages_in_a_zone()

Andrey Ryabinin (1):
      ipv6/addrlabel: fix ip6addrlbl_get()

Anson Huang (1):
      ARM: 8471/1: need to save/restore arm register(r11) when it is corrupted

Anssi Hannula (1):
      ALSA: usb-audio: Add a more accurate volume quirk for AudioQuest DragonFly

Arnd Bergmann (1):
      usb: musb: USB_TI_CPPI41_DMA requires dmaengine support

Ashok Raj (1):
      x86/mce: Ensure offline CPUs don't participate in rendezvous process

Ben Hutchings (1):
      usb: Use the USB_SS_MULT() macro to decode burst multiplier for log message

Benjamin Coddington (1):
      nfs4: limit callback decoding to received bytes

Charles Keepax (1):
      ASoC: Use nested lock for snd_soc_dapm_mutex_lock

Chris Wilson (1):
      drm/i915: Fix SRC_COPY width on 830/845g

Chunfeng Yun (1):
      usb: xhci: fix config fail of FS hub behind a HS hub with MTT

Colin Ian King (1):
      ftrace/scripts: Fix incorrect use of sprintf in recordmcount

Dan Carpenter (6):
      iio: fix some warning messages
      USB: ipaq.c: fix a timeout loop
      mISDN: fix a loop count
      amd-xgbe: fix a couple timeout loops
      qlcnic: fix a timeout loop
      qlcnic: fix a loop exit condition better

Daniel Mentz (1):
      dma-debug: Fix dma_debug_entry offset calculation

David Henningsson (1):
      ALSA: hda - Add inverted dmic for Packard Bell DOTS

David Turner (1):
      ext4: Fix handling of extended tv_sec

David Vrabel (3):
      xen: Add RING_COPY_REQUEST()
      xen-netback: don't use last request to determine minimum Tx credit
      xen-netback: use RING_COPY_REQUEST() throughout

Dmitry Katsubo (1):
      usb-storage: Fix scsi-sd failure "Invalid field in cdb" for USB adapter JMicron

Dmitry V. Levin (1):
      sh64: fix __NR_fgetxattr

Eric Dumazet (1):
      udp: properly support MSG_PEEK with truncated buffers

Eugenia Emantayev (2):
      net/mlx4_en: Remove dependency between timestamping capability and service_task
      net/mlx4_en: Fix HW timestamp init issue upon system startup

Felipe Balbi (1):
      usb: gadget: pxa27x: fix suspend callback

Francesco Ruggeri (1):
      net: possible use after free in dst_release

Guillaume Delbergue (1):
      irqchip/versatile-fpga: Fix PCI IRQ mapping on Versatile PB

Hannes Frederic Sowa (1):
      net: fix warnings in 'make htmldocs' by moving macro definition out of field declaration

Hans Yang (1):
      usb: core : hub: Fix BOS 'NULL pointer' kernel panic

Hans de Goede (1):
      i2c: mv64xxx: The n clockdiv factor is 0 based on sunxi SoCs

Helge Deller (1):
      parisc: Fix syscall restarts

Hui Wang (1):
      ALSA: hda - Fixing speaker noise on the two latest thinkpad models

Ingo Molnar (1):
      efi: Disable interrupts around EFI calls, not in the epilog/prolog calls

James Bottomley (2):
      ses: Fix problems with simple enclosures
      ses: fix additional element traversal bug

James Hogan (3):
      MIPS: uaccess: Take EVA into account in __copy_from_user()
      MIPS: uaccess: Take EVA into account in [__]clear_user
      MIPS: uaccess: Fix strlen_user with EVA

James Morse (1):
      include/linux/mmdebug.h: should include linux/bug.h

Jan Kara (1):
      jbd2: Fix unreclaimed pages after truncate in data=journal mode

Jan Stancek (1):
      ipmi: move timer init to before irq is setup

Jason A. Donenfeld (1):
      crypto: skcipher - Copy iv from desc even for 0-len walks

Joe Thornber (3):
      dm thin metadata: fix bug when taking a metadata snapshot
      dm space map metadata: fix ref counting bug when bootstrapping a new space map
      dm btree: fix bufio buffer leaks in dm_btree_del() error path

Johan Hovold (1):
      spi: fix parent-device reference leak

Johannes Berg (1):
      rfkill: copy the name into the rfkill struct

Jonas Jonsson (2):
      USB: cdc_acm: Ignore Infineon Flash Loader utility
      USB: serial: Another Infineon flash loader USB ID

Joseph Qi (1):
      ocfs2: fix BUG when calculate new backup super

Junxiao Bi (1):
      ocfs2: fix SGID not inherited issue

Kamal Mostafa (1):
      tools: Add a "make all" rule

Ken Xue (2):
      SCSI: Fix NULL pointer dereference in runtime PM
      Revert "SCSI: Fix NULL pointer dereference in runtime PM"

Kirill A. Shutemov (1):
      vgaarb: fix signal handling in vga_get()

Konrad Rzeszutek Wilk (6):
      xen/pciback: Save xen_pci_op commands before processing it
      xen/pciback: Return error on XEN_PCI_OP_enable_msi when device has MSI or MSI-X enabled
      xen/pciback: Return error on XEN_PCI_OP_enable_msix when device has MSI or MSI-X enabled
      xen/pciback: Do not install an IRQ handler for MSI interrupts.
      xen/pciback: For XEN_PCI_OP_disable_msi[|x] only disable if device has MSI(X) enabled.
      xen/pciback: Don't allow MSI-X ops if PCI_COMMAND_MEMORY is not set.

Konstantin Shkolnyy (1):
      USB: cp210x: Remove CP2110 ID from compatibility list

Krzysztof Hałasa (1):
      ARM: dts: imx6: Fix Ethernet PHY mode on Ventana boards

Mans Rullgard (1):
      ASoC: wm8974: set cache type for regmap

Mario Kleiner (1):
      ALSA: hda/realtek - Fix silent headphone output on MacPro 4,1 (v2)

Mathias Nyman (1):
      xhci: fix usb2 resume timing and races.

Michael Holzheu (1):
      s390/dis: Fix handling of format specifiers

Michal Hocko (2):
      mm, vmstat: allow WQ concurrency to discover memory reclaim doesn't make any progress
      vmstat: allocate vmstat_wq before it is used

Mike Snitzer (1):
      dm btree: fix leak of bufio-backed block in btree_split_sibling error path

Mikulas Patocka (2):
      sata_sil: disable trim
      parisc iommu: fix panic due to trying to allocate too large region

Naoya Horiguchi (2):
      mm: hugetlb: fix hugepage memory leak caused by wrong reserve count
      mm: hugetlb: call huge_pte_alloc() only if ptep is null

Neelesh Gupta (1):
      powerpc/powernv: Fix the overflow of OPAL message notifiers head array

NeilBrown (1):
      async_tx: use GFP_NOWAIT rather than GFP_IO

Nikesh Oswal (1):
      ASoC: arizona: Fix bclk for sample rates that are multiple of 4kHz

Oded Gabbay (3):
      radeon/cik: Fix GFX IB test on Big-Endian
      radeon: Fix VCE ring test for Big-Endian systems
      radeon: Fix VCE IB test on Big-Endian systems

Paolo Bonzini (1):
      kvm: x86: only channel 0 of the i8254 is linked to the HPET

Paul Mackerras (1):
      KVM: PPC: Book3S HV: Prohibit setting illegal transaction state in MSR

Peter Hurley (2):
      n_tty: Fix poll() after buffer-limited eof push read
      tty: Fix GPF in flush_to_ldisc()

Peter Zijlstra (1):
      perf: Fix PERF_EVENT_IOC_PERIOD deadlock

Prarit Bhargava (1):
      powercap / RAPL: fix BIOS lock check

Qiu Peiyang (1):
      tracing: Fix setting of start_index in find_next()

Rabin Vincent (1):
      net: filter: make JITs zero A for SKF_AD_ALU_XOR_X

Roger Pau Monné (2):
      xen-blkback: only read request operation from shared ring once
      xen-blkback: read from indirect descriptors only once

Roman Gushchin (1):
      fuse: break infinite loop in fuse_fill_write_pages()

Roman Volkov (1):
      dts: vt8500: Add SDHC node to DTS file for WM8650

Ross Lagerwall (1):
      xen/events/fifo: Consume unprocessed events when a CPU dies

Russell King (1):
      scripts: recordmcount: break hardlinks

Sagi Grimberg (1):
      IB/srp: Fix possible send queue overflow

Sergei Shtylyov (1):
      sh_eth: fix TX buffer byte-swapping

Seth Jennings (1):
      drivers/base/memory.c: prohibit offlining of memory blocks with missing sections

Stefan Wahren (1):
      pinctrl: bcm2835: Fix initial value for direction_output

Steven Rostedt (Red Hat) (2):
      ftrace/scripts: Have recordmcount copy the object file
      ftrace/module: Call clean up function when module init fails early

Stewart Smith (1):
      powerpc/powernv: pr_warn_once on unsupported OPAL_MSG type

Suman Anna (1):
      virtio: fix memory leak of virtio ida cache layers

Takashi Iwai (3):
      ALSA: rme96: Fix unexpected volume reset after rate changes
      ALSA: hda - Fix noise problems on Thinkpad T440s
      ALSA: hda - Add a fixup for Thinkpad X1 Carbon 2nd

Thomas Gleixner (1):
      genirq: Prevent chip buslock deadlock

Thomas Hellstrom (1):
      drm/ttm: Fixed a read/write lock imbalance

Tilman Schmidt (1):
      ser_gigaset: fix deallocation of platform device structure

Tobias Klauser (1):
      net: phy: mdio-mux: Check return value of mdiobus_alloc()

Trond Myklebust (1):
      SUNRPC: Fix callback channel

Vineet Gupta (2):
      ARC: dw2 unwind: Reinstante unwinding out of modules
      ARC: dw2 unwind: Ignore CIE version !=1 gracefully instead of bailing

Wang Dongsheng (1):
      video: fbdev: fsl: Fix kernel crash when diu_ops is not implemented

Xiangliang Yu (1):
      AHCI: Fix softreset failed issue of Port Multiplier

Xiong Zhang (1):
      ALSA: hda - Set SKL+ hda controller power at freeze() and thaw()

Yevgeny Pats (1):
      KEYS: Fix keyring ref leak in join_session_keyring()

[toc] | [next] | [standalone]


#1316000 — [PATCH 3.16.y-ckt 118/128] x86/mce: Ensure offline CPUs don't participate in rendezvous process

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 118/128] x86/mce: Ensure offline CPUs don't participate in rendezvous process
Message-ID<qUB18-2KY-29@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Ashok Raj <ashok.raj@intel.com>

commit d90167a941f62860f35eb960e1012aa2d30e7e94 upstream.

Intel's MCA implementation broadcasts MCEs to all CPUs on the
node. This poses a problem for offlined CPUs which cannot
participate in the rendezvous process:

  Kernel panic - not syncing: Timeout: Not all CPUs entered broadcast exception handler
  Kernel Offset: disabled
  Rebooting in 100 seconds..

More specifically, Linux does a soft offline of a CPU when
writing a 0 to /sys/devices/system/cpu/cpuX/online, which
doesn't prevent the #MC exception from being broadcasted to that
CPU.

Ensure that offline CPUs don't participate in the MCE rendezvous
and clear the RIP valid status bit so that a second MCE won't
cause a shutdown.

Without the patch, mce_start() will increment mce_callin and
wait for all CPUs. Offlined CPUs should avoid participating in
the rendezvous process altogether.

Signed-off-by: Ashok Raj <ashok.raj@intel.com>
[ Massage commit message. ]
Signed-off-by: Borislav Petkov <bp@suse.de>
Reviewed-by: Tony Luck <tony.luck@intel.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: linux-edac <linux-edac@vger.kernel.org>
Link: http://lkml.kernel.org/r/1449742346-21470-2-git-send-email-bp@alien8.de
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 arch/x86/kernel/cpu/mcheck/mce.c | 11 +++++++++++
 1 file changed, 11 insertions(+)

diff --git a/arch/x86/kernel/cpu/mcheck/mce.c b/arch/x86/kernel/cpu/mcheck/mce.c
index 5648b506f3ae..8ae7e3f27b1b 100644
--- a/arch/x86/kernel/cpu/mcheck/mce.c
+++ b/arch/x86/kernel/cpu/mcheck/mce.c
@@ -1042,6 +1042,17 @@ void do_machine_check(struct pt_regs *regs, long error_code)
 	DECLARE_BITMAP(valid_banks, MAX_NR_BANKS);
 	char *msg = "Unknown";
 
+	/* If this CPU is offline, just bail out. */
+	if (cpu_is_offline(smp_processor_id())) {
+		u64 mcgstatus;
+
+		mcgstatus = mce_rdmsrl(MSR_IA32_MCG_STATUS);
+		if (mcgstatus & MCG_STATUS_RIPV) {
+			mce_wrmsrl(MSR_IA32_MCG_STATUS, 0);
+			return;
+		}
+	}
+
 	this_cpu_inc(mce_exception_count);
 
 	if (!cfg->banks)

[toc] | [prev] | [next] | [standalone]


#1316001 — [PATCH 3.16.y-ckt 002/128] usb: gadget: pxa27x: fix suspend callback

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 002/128] usb: gadget: pxa27x: fix suspend callback
Message-ID<qUB18-2KY-31@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Felipe Balbi <balbi@ti.com>

commit 391e6dcb37857d5659b53def2f41e2f56850d33c upstream.

pxa27x disconnects pullups on suspend but doesn't
notify the gadget driver about it, so gadget driver
can't disable the endpoints it was using.

This causes problems on resume because gadget core
will think endpoints are still enabled and just
ignore the following usb_ep_enable().

Fix this problem by calling
gadget_driver->disconnect().

Tested-by: Robert Jarzmik <robert.jarzmik@free.fr>
Signed-off-by: Felipe Balbi <balbi@ti.com>
[ luis: backported to 3.16:
  - file rename: drivers/usb/gadget/udc/pxa27x_udc.c ->
    drivers/usb/gadget/pxa27x_udc.c ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/usb/gadget/pxa27x_udc.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/usb/gadget/pxa27x_udc.c b/drivers/usb/gadget/pxa27x_udc.c
index cdf4d678be96..a63dee15bdc7 100644
--- a/drivers/usb/gadget/pxa27x_udc.c
+++ b/drivers/usb/gadget/pxa27x_udc.c
@@ -2558,6 +2558,9 @@ static int pxa_udc_suspend(struct platform_device *_dev, pm_message_t state)
 	udc->pullup_resume = udc->pullup_on;
 	dplus_pullup(udc, 0);
 
+	if (udc->driver)
+		udc->driver->disconnect(&udc->gadget);
+
 	return 0;
 }
 

[toc] | [prev] | [next] | [standalone]


#1316002 — [PATCH 3.16.y-ckt 008/128] jbd2: Fix unreclaimed pages after truncate in data=journal mode

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 008/128] jbd2: Fix unreclaimed pages after truncate in data=journal mode
Message-ID<qUB18-2KY-33@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Jan Kara <jack@suse.cz>

commit bc23f0c8d7ccd8d924c4e70ce311288cb3e61ea8 upstream.

Ted and Namjae have reported that truncated pages don't get timely
reclaimed after being truncated in data=journal mode. The following test
triggers the issue easily:

for (i = 0; i < 1000; i++) {
	pwrite(fd, buf, 1024*1024, 0);
	fsync(fd);
	fsync(fd);
	ftruncate(fd, 0);
}

The reason is that journal_unmap_buffer() finds that truncated buffers
are not journalled (jh->b_transaction == NULL), they are part of
checkpoint list of a transaction (jh->b_cp_transaction != NULL) and have
been already written out (!buffer_dirty(bh)). We clean such buffers but
we leave them in the checkpoint list. Since checkpoint transaction holds
a reference to the journal head, these buffers cannot be released until
the checkpoint transaction is cleaned up. And at that point we don't
call release_buffer_page() anymore so pages detached from mapping are
lingering in the system waiting for reclaim to find them and free them.

Fix the problem by removing buffers from transaction checkpoint lists
when journal_unmap_buffer() finds out they don't have to be there
anymore.

Reported-and-tested-by: Namjae Jeon <namjae.jeon@samsung.com>
Fixes: de1b794130b130e77ffa975bb58cb843744f9ae5
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 fs/jbd2/transaction.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/fs/jbd2/transaction.c b/fs/jbd2/transaction.c
index 99ebbd72a064..77303ba0c270 100644
--- a/fs/jbd2/transaction.c
+++ b/fs/jbd2/transaction.c
@@ -2064,6 +2064,7 @@ static int journal_unmap_buffer(journal_t *journal, struct buffer_head *bh,
 
 		if (!buffer_dirty(bh)) {
 			/* bdflush has written it.  We can drop it now */
+			__jbd2_journal_remove_checkpoint(jh);
 			goto zap_buffer;
 		}
 
@@ -2093,6 +2094,7 @@ static int journal_unmap_buffer(journal_t *journal, struct buffer_head *bh,
 				/* The orphan record's transaction has
 				 * committed.  We can cleanse this buffer */
 				clear_buffer_jbddirty(bh);
+				__jbd2_journal_remove_checkpoint(jh);
 				goto zap_buffer;
 			}
 		}

[toc] | [prev] | [next] | [standalone]


#1316003 — [PATCH 3.16.y-ckt 077/128] xen-blkback: read from indirect descriptors only once

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 077/128] xen-blkback: read from indirect descriptors only once
Message-ID<qUB19-2KY-35@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= <roger.pau@citrix.com>

commit 18779149101c0dd43ded43669ae2a92d21b6f9cb upstream.

Since indirect descriptors are in memory shared with the frontend, the
frontend could alter the first_sect and last_sect values after they have
been validated but before they are recorded in the request.  This may
result in I/O requests that overflow the foreign page, possibly
overwriting local pages when the I/O request is executed.

When parsing indirect descriptors, only read first_sect and last_sect
once.

This is part of XSA155.

Signed-off-by: Roger Pau Monné <roger.pau@citrix.com>
Signed-off-by: David Vrabel <david.vrabel@citrix.com>
Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
[ luis: backported to 3.16:
  - Use ACCESS_ONCE instead of READ_ONCE
  - Use PAGE_SIZE instead of XEN_PAGE_SIZE ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/block/xen-blkback/blkback.c | 15 ++++++++++-----
 1 file changed, 10 insertions(+), 5 deletions(-)

diff --git a/drivers/block/xen-blkback/blkback.c b/drivers/block/xen-blkback/blkback.c
index 02004e101678..c42c22e778d8 100644
--- a/drivers/block/xen-blkback/blkback.c
+++ b/drivers/block/xen-blkback/blkback.c
@@ -861,6 +861,8 @@ static int xen_blkbk_parse_indirect(struct blkif_request *req,
 		goto unmap;
 
 	for (n = 0, i = 0; n < nseg; n++) {
+		uint8_t first_sect, last_sect;
+
 		if ((n % SEGS_PER_INDIRECT_FRAME) == 0) {
 			/* Map indirect segments */
 			if (segments)
@@ -868,15 +870,18 @@ static int xen_blkbk_parse_indirect(struct blkif_request *req,
 			segments = kmap_atomic(pages[n/SEGS_PER_INDIRECT_FRAME]->page);
 		}
 		i = n % SEGS_PER_INDIRECT_FRAME;
+
 		pending_req->segments[n]->gref = segments[i].gref;
-		seg[n].nsec = segments[i].last_sect -
-			segments[i].first_sect + 1;
-		seg[n].offset = (segments[i].first_sect << 9);
-		if ((segments[i].last_sect >= (PAGE_SIZE >> 9)) ||
-		    (segments[i].last_sect < segments[i].first_sect)) {
+
+		first_sect = ACCESS_ONCE(segments[i].first_sect);
+		last_sect = ACCESS_ONCE(segments[i].last_sect);
+		if (last_sect >= (PAGE_SIZE >> 9) || last_sect < first_sect) {
 			rc = -EINVAL;
 			goto unmap;
 		}
+
+		seg[n].nsec = last_sect - first_sect + 1;
+		seg[n].offset = first_sect << 9;
 		preq->nr_sects += seg[n].nsec;
 	}
 

[toc] | [prev] | [next] | [standalone]


#1316004 — [PATCH 3.16.y-ckt 085/128] USB: fix invalid memory access in hub_activate()

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 085/128] USB: fix invalid memory access in hub_activate()
Message-ID<qUB19-2KY-41@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Alan Stern <stern@rowland.harvard.edu>

commit e50293ef9775c5f1cf3fcc093037dd6a8c5684ea upstream.

Commit 8520f38099cc ("USB: change hub initialization sleeps to
delayed_work") changed the hub_activate() routine to make part of it
run in a workqueue.  However, the commit failed to take a reference to
the usb_hub structure or to lock the hub interface while doing so.  As
a result, if a hub is plugged in and quickly unplugged before the work
routine can run, the routine will try to access memory that has been
deallocated.  Or, if the hub is unplugged while the routine is
running, the memory may be deallocated while it is in active use.

This patch fixes the problem by taking a reference to the usb_hub at
the start of hub_activate() and releasing it at the end (when the work
is finished), and by locking the hub interface while the work routine
is running.  It also adds a check at the start of the routine to see
if the hub has already been disconnected, in which nothing should be
done.

Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Reported-by: Alexandru Cornea <alexandru.cornea@intel.com>
Tested-by: Alexandru Cornea <alexandru.cornea@intel.com>
Fixes: 8520f38099cc ("USB: change hub initialization sleeps to delayed_work")
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ luis: backported to 3.16:
  - Added forward declaration of hub_release() which mainline had with commit
    32a6958998c5 ("usb: hub: convert khubd into workqueue") ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/usb/core/hub.c | 23 ++++++++++++++++++++---
 1 file changed, 20 insertions(+), 3 deletions(-)

diff --git a/drivers/usb/core/hub.c b/drivers/usb/core/hub.c
index a1e577777a02..673d426de13f 100644
--- a/drivers/usb/core/hub.c
+++ b/drivers/usb/core/hub.c
@@ -104,6 +104,7 @@ EXPORT_SYMBOL_GPL(ehci_cf_port_reset_rwsem);
 #define HUB_DEBOUNCE_STEP	  25
 #define HUB_DEBOUNCE_STABLE	 100
 
+static void hub_release(struct kref *kref);
 static int usb_reset_and_verify_device(struct usb_device *udev);
 
 static inline char *portspeed(struct usb_hub *hub, int portstatus)
@@ -1027,10 +1028,20 @@ static void hub_activate(struct usb_hub *hub, enum hub_activation_type type)
 	unsigned delay;
 
 	/* Continue a partial initialization */
-	if (type == HUB_INIT2)
-		goto init2;
-	if (type == HUB_INIT3)
+	if (type == HUB_INIT2 || type == HUB_INIT3) {
+		device_lock(hub->intfdev);
+
+		/* Was the hub disconnected while we were waiting? */
+		if (hub->disconnected) {
+			device_unlock(hub->intfdev);
+			kref_put(&hub->kref, hub_release);
+			return;
+		}
+		if (type == HUB_INIT2)
+			goto init2;
 		goto init3;
+	}
+	kref_get(&hub->kref);
 
 	/* The superspeed hub except for root hub has to use Hub Depth
 	 * value as an offset into the route string to locate the bits
@@ -1228,6 +1239,7 @@ static void hub_activate(struct usb_hub *hub, enum hub_activation_type type)
 			queue_delayed_work(system_power_efficient_wq,
 					&hub->init_work,
 					msecs_to_jiffies(delay));
+			device_unlock(hub->intfdev);
 			return;		/* Continues at init3: below */
 		} else {
 			msleep(delay);
@@ -1249,6 +1261,11 @@ static void hub_activate(struct usb_hub *hub, enum hub_activation_type type)
 	/* Allow autosuspend if it was suppressed */
 	if (type <= HUB_INIT3)
 		usb_autopm_put_interface_async(to_usb_interface(hub->intfdev));
+
+	if (type == HUB_INIT2 || type == HUB_INIT3)
+		device_unlock(hub->intfdev);
+
+	kref_put(&hub->kref, hub_release);
 }
 
 /* Implement the continuations for the delays above */

[toc] | [prev] | [next] | [standalone]


#1316005 — [PATCH 3.16.y-ckt 126/128] firmware: dmi_scan: Fix UUID endianness for SMBIOS >= 2.6

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 126/128] firmware: dmi_scan: Fix UUID endianness for SMBIOS >= 2.6
Message-ID<qUB1a-2KY-43@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Andrea Arcangeli <aarcange@redhat.com>

commit ff4319dc7cd58c92b389960e375038335d157a60 upstream.

The dmi_ver wasn't updated correctly before the dmi_decode method run
to save the uuid.

That resulted in "dmidecode -s system-uuid" and
/sys/class/dmi/id/product_uuid disagreeing. The latter was buggy and
this fixes it.

Reported-by: Federico Simoncelli <fsimonce@redhat.com>
Fixes: 9f9c9cbb6057 ("drivers/firmware/dmi_scan.c: fetch dmi version from SMBIOS if it exists")
Fixes: 79bae42d51a5 ("dmi_scan: refactor dmi_scan_machine(), {smbios,dmi}_present()")
Signed-off-by: Andrea Arcangeli <aarcange@redhat.com>
Signed-off-by: Jean Delvare <jdelvare@suse.de>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/firmware/dmi_scan.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/firmware/dmi_scan.c b/drivers/firmware/dmi_scan.c
index 35286fe52823..48142b88e672 100644
--- a/drivers/firmware/dmi_scan.c
+++ b/drivers/firmware/dmi_scan.c
@@ -493,6 +493,7 @@ static int __init dmi_present(const u8 *buf)
 			dmi_ver = smbios_ver;
 		else
 			dmi_ver = (buf[14] & 0xF0) << 4 | (buf[14] & 0x0F);
+		dmi_ver <<= 8;
 		dmi_num = (buf[13] << 8) | buf[12];
 		dmi_len = (buf[7] << 8) | buf[6];
 		dmi_base = (buf[11] << 24) | (buf[10] << 16) |
@@ -501,10 +502,10 @@ static int __init dmi_present(const u8 *buf)
 		if (dmi_walk_early(dmi_decode) == 0) {
 			if (smbios_ver) {
 				pr_info("SMBIOS %d.%d present.\n",
-				       dmi_ver >> 8, dmi_ver & 0xFF);
+					dmi_ver >> 16, (dmi_ver >> 8) & 0xFF);
 			} else {
 				pr_info("Legacy DMI %d.%d present.\n",
-				       dmi_ver >> 8, dmi_ver & 0xFF);
+					dmi_ver >> 16, (dmi_ver >> 8) & 0xFF);
 			}
 			dmi_format_ids(dmi_ids_string, sizeof(dmi_ids_string));
 			printk(KERN_DEBUG "DMI: %s\n", dmi_ids_string);

[toc] | [prev] | [next] | [standalone]


#1316006 — [PATCH 3.16.y-ckt 125/128] kvm: x86: only channel 0 of the i8254 is linked to the HPET

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 125/128] kvm: x86: only channel 0 of the i8254 is linked to the HPET
Message-ID<qUB1a-2KY-45@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Paolo Bonzini <pbonzini@redhat.com>

commit e5e57e7a03b1cdcb98e4aed135def2a08cbf3257 upstream.

While setting the KVM PIT counters in 'kvm_pit_load_count', if
'hpet_legacy_start' is set, the function disables the timer on
channel[0], instead of the respective index 'channel'. This is
because channels 1-3 are not linked to the HPET.  Fix the caller
to only activate the special HPET processing for channel 0.

Reported-by: P J P <pjp@fedoraproject.org>
Fixes: 0185604c2d82c560dab2f2933a18f797e74ab5a8
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 arch/x86/kvm/i8254.c | 1 +
 arch/x86/kvm/x86.c   | 3 ++-
 2 files changed, 3 insertions(+), 1 deletion(-)

diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
index 1406ffde3e35..f2006e65a238 100644
--- a/arch/x86/kvm/i8254.c
+++ b/arch/x86/kvm/i8254.c
@@ -418,6 +418,7 @@ void kvm_pit_load_count(struct kvm *kvm, int channel, u32 val, int hpet_legacy_s
 	u8 saved_mode;
 	if (hpet_legacy_start) {
 		/* save existing mode for later reenablement */
+		WARN_ON(channel != 0);
 		saved_mode = kvm->arch.vpit->pit_state.channels[0].mode;
 		kvm->arch.vpit->pit_state.channels[0].mode = 0xff; /* disable timer */
 		pit_load_count(kvm, channel, val);
diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index e336615e0aae..14bd5c079ca3 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -3596,7 +3596,8 @@ static int kvm_vm_ioctl_set_pit2(struct kvm *kvm, struct kvm_pit_state2 *ps)
 	       sizeof(kvm->arch.vpit->pit_state.channels));
 	kvm->arch.vpit->pit_state.flags = ps->flags;
 	for (i = 0; i < 3; i++)
-		kvm_pit_load_count(kvm, i, kvm->arch.vpit->pit_state.channels[i].count, start);
+		kvm_pit_load_count(kvm, i, kvm->arch.vpit->pit_state.channels[i].count,
+				   start && i == 0);
 	mutex_unlock(&kvm->arch.vpit->pit_state.lock);
 	return r;
 }

[toc] | [prev] | [next] | [standalone]


#1316007 — [PATCH 3.16.y-ckt 104/128] parisc: Fix syscall restarts

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 104/128] parisc: Fix syscall restarts
Message-ID<qUB1a-2KY-47@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Helge Deller <deller@gmx.de>

commit 71a71fb5374a23be36a91981b5614590b9e722c3 upstream.

On parisc syscalls which are interrupted by signals sometimes failed to
restart and instead returned -ENOSYS which in the worst case lead to
userspace crashes.
A similiar problem existed on MIPS and was fixed by commit e967ef02
("MIPS: Fix restart of indirect syscalls").

On parisc the current syscall restart code assumes that all syscall
callers load the syscall number in the delay slot of the ble
instruction. That's how it is e.g. done in the unistd.h header file:
	ble 0x100(%sr2, %r0)
	ldi #syscall_nr, %r20
Because of that assumption the current code never restored %r20 before
returning to userspace.

This assumption is at least not true for code which uses the glibc
syscall() function, which instead uses this syntax:
	ble 0x100(%sr2, %r0)
	copy regX, %r20
where regX depend on how the compiler optimizes the code and register
usage.

This patch fixes this problem by adding code to analyze how the syscall
number is loaded in the delay branch and - if needed - copy the syscall
number to regX prior returning to userspace for the syscall restart.

Signed-off-by: Helge Deller <deller@gmx.de>
Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 arch/parisc/kernel/signal.c | 64 ++++++++++++++++++++++++++++++++++++---------
 1 file changed, 52 insertions(+), 12 deletions(-)

diff --git a/arch/parisc/kernel/signal.c b/arch/parisc/kernel/signal.c
index 1cba8f29bb49..78bb6dd88e03 100644
--- a/arch/parisc/kernel/signal.c
+++ b/arch/parisc/kernel/signal.c
@@ -442,6 +442,55 @@ handle_signal(unsigned long sig, siginfo_t *info, struct k_sigaction *ka,
 		regs->gr[28]);
 }
 
+/*
+ * Check how the syscall number gets loaded into %r20 within
+ * the delay branch in userspace and adjust as needed.
+ */
+
+static void check_syscallno_in_delay_branch(struct pt_regs *regs)
+{
+	u32 opcode, source_reg;
+	u32 __user *uaddr;
+	int err;
+
+	/* Usually we don't have to restore %r20 (the system call number)
+	 * because it gets loaded in the delay slot of the branch external
+	 * instruction via the ldi instruction.
+	 * In some cases a register-to-register copy instruction might have
+	 * been used instead, in which case we need to copy the syscall
+	 * number into the source register before returning to userspace.
+	 */
+
+	/* A syscall is just a branch, so all we have to do is fiddle the
+	 * return pointer so that the ble instruction gets executed again.
+	 */
+	regs->gr[31] -= 8; /* delayed branching */
+
+	/* Get assembler opcode of code in delay branch */
+	uaddr = (unsigned int *) ((regs->gr[31] & ~3) + 4);
+	err = get_user(opcode, uaddr);
+	if (err)
+		return;
+
+	/* Check if delay branch uses "ldi int,%r20" */
+	if ((opcode & 0xffff0000) == 0x34140000)
+		return;	/* everything ok, just return */
+
+	/* Check if delay branch uses "nop" */
+	if (opcode == INSN_NOP)
+		return;
+
+	/* Check if delay branch uses "copy %rX,%r20" */
+	if ((opcode & 0xffe0ffff) == 0x08000254) {
+		source_reg = (opcode >> 16) & 31;
+		regs->gr[source_reg] = regs->gr[20];
+		return;
+	}
+
+	pr_warn("syscall restart: %s (pid %d): unexpected opcode 0x%08x\n",
+		current->comm, task_pid_nr(current), opcode);
+}
+
 static inline void
 syscall_restart(struct pt_regs *regs, struct k_sigaction *ka)
 {
@@ -464,10 +513,7 @@ syscall_restart(struct pt_regs *regs, struct k_sigaction *ka)
 		}
 		/* fallthrough */
 	case -ERESTARTNOINTR:
-		/* A syscall is just a branch, so all
-		 * we have to do is fiddle the return pointer.
-		 */
-		regs->gr[31] -= 8; /* delayed branching */
+		check_syscallno_in_delay_branch(regs);
 		break;
 	}
 }
@@ -516,15 +562,9 @@ insert_restart_trampoline(struct pt_regs *regs)
 	}
 	case -ERESTARTNOHAND:
 	case -ERESTARTSYS:
-	case -ERESTARTNOINTR: {
-		/* Hooray for delayed branching.  We don't
-		 * have to restore %r20 (the system call
-		 * number) because it gets loaded in the delay
-		 * slot of the branch external instruction.
-		 */
-		regs->gr[31] -= 8;
+	case -ERESTARTNOINTR:
+		check_syscallno_in_delay_branch(regs);
 		return;
-	}
 	default:
 		break;
 	}

[toc] | [prev] | [next] | [standalone]


#1316008 — [PATCH 3.16.y-ckt 034/128] dm thin metadata: fix bug when taking a metadata snapshot

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 034/128] dm thin metadata: fix bug when taking a metadata snapshot
Message-ID<qUB1a-2KY-49@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Joe Thornber <ejt@redhat.com>

commit 49e99fc717f624aa75ca755d6e7bc029efd3f0e9 upstream.

When you take a metadata snapshot the btree roots for the mapping and
details tree need to have their reference counts incremented so they
persist for the lifetime of the metadata snap.

The roots being incremented were those currently written in the
superblock, which could possibly be out of date if concurrent IO is
triggering new mappings, breaking of sharing, etc.

Fix this by performing a commit with the metadata lock held while taking
a metadata snapshot.

Signed-off-by: Joe Thornber <ejt@redhat.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/md/dm-thin-metadata.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/md/dm-thin-metadata.c b/drivers/md/dm-thin-metadata.c
index 3412b86e79fd..7768de60f699 100644
--- a/drivers/md/dm-thin-metadata.c
+++ b/drivers/md/dm-thin-metadata.c
@@ -1205,6 +1205,12 @@ static int __reserve_metadata_snap(struct dm_pool_metadata *pmd)
 	dm_block_t held_root;
 
 	/*
+	 * We commit to ensure the btree roots which we increment in a
+	 * moment are up to date.
+	 */
+	__commit_transaction(pmd);
+
+	/*
 	 * Copy the superblock.
 	 */
 	dm_sm_inc_block(pmd->metadata_sm, THIN_SUPERBLOCK_LOCATION);

[toc] | [prev] | [next] | [standalone]


#1316009 — [PATCH 3.16.y-ckt 123/128] net: filter: make JITs zero A for SKF_AD_ALU_XOR_X

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 123/128] net: filter: make JITs zero A for SKF_AD_ALU_XOR_X
Message-ID<qUB1a-2KY-51@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Rabin Vincent <rabin@rab.in>

commit 55795ef5469290f89f04e12e662ded604909e462 upstream.

The SKF_AD_ALU_XOR_X ancillary is not like the other ancillary data
instructions since it XORs A with X while all the others replace A with
some loaded value.  All the BPF JITs fail to clear A if this is used as
the first instruction in a filter.  This was found using american fuzzy
lop.

Add a helper to determine if A needs to be cleared given the first
instruction in a filter, and use this in the JITs.  Except for ARM, the
rest have only been compile-tested.

Fixes: 3480593131e0 ("net: filter: get rid of BPF_S_* enum")
Signed-off-by: Rabin Vincent <rabin@rab.in>
Acked-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 arch/arm/net/bpf_jit_32.c       | 16 +---------------
 arch/mips/net/bpf_jit.c         | 16 +---------------
 arch/powerpc/net/bpf_jit_comp.c | 13 ++-----------
 arch/sparc/net/bpf_jit_comp.c   | 17 ++---------------
 include/linux/filter.h          | 19 +++++++++++++++++++
 5 files changed, 25 insertions(+), 56 deletions(-)

diff --git a/arch/arm/net/bpf_jit_32.c b/arch/arm/net/bpf_jit_32.c
index 75ee31c95ff3..4a7fe29635ea 100644
--- a/arch/arm/net/bpf_jit_32.c
+++ b/arch/arm/net/bpf_jit_32.c
@@ -161,23 +161,9 @@ static inline int mem_words_used(struct jit_ctx *ctx)
 	return fls(ctx->seen & SEEN_MEM);
 }
 
-static inline bool is_load_to_a(u16 inst)
-{
-	switch (inst) {
-	case BPF_LD | BPF_W | BPF_LEN:
-	case BPF_LD | BPF_W | BPF_ABS:
-	case BPF_LD | BPF_H | BPF_ABS:
-	case BPF_LD | BPF_B | BPF_ABS:
-		return true;
-	default:
-		return false;
-	}
-}
-
 static void build_prologue(struct jit_ctx *ctx)
 {
 	u16 reg_set = saved_regs(ctx);
-	u16 first_inst = ctx->skf->insns[0].code;
 	u16 off;
 
 #ifdef CONFIG_FRAME_POINTER
@@ -207,7 +193,7 @@ static void build_prologue(struct jit_ctx *ctx)
 		emit(ARM_MOV_I(r_X, 0), ctx);
 
 	/* do not leak kernel data to userspace */
-	if ((first_inst != (BPF_RET | BPF_K)) && !(is_load_to_a(first_inst)))
+	if (bpf_needs_clear_a(&ctx->skf->insns[0]))
 		emit(ARM_MOV_I(r_A, 0), ctx);
 
 	/* stack space for the BPF_MEM words */
diff --git a/arch/mips/net/bpf_jit.c b/arch/mips/net/bpf_jit.c
index 965f1c116cc5..32751a0bba58 100644
--- a/arch/mips/net/bpf_jit.c
+++ b/arch/mips/net/bpf_jit.c
@@ -566,19 +566,6 @@ static inline u16 align_sp(unsigned int num)
 	return num;
 }
 
-static bool is_load_to_a(u16 inst)
-{
-	switch (inst) {
-	case BPF_LD | BPF_W | BPF_LEN:
-	case BPF_LD | BPF_W | BPF_ABS:
-	case BPF_LD | BPF_H | BPF_ABS:
-	case BPF_LD | BPF_B | BPF_ABS:
-		return true;
-	default:
-		return false;
-	}
-}
-
 static void save_bpf_jit_regs(struct jit_ctx *ctx, unsigned offset)
 {
 	int i = 0, real_off = 0;
@@ -703,7 +690,6 @@ static unsigned int get_stack_depth(struct jit_ctx *ctx)
 
 static void build_prologue(struct jit_ctx *ctx)
 {
-	u16 first_inst = ctx->skf->insns[0].code;
 	int sp_off;
 
 	/* Calculate the total offset for the stack pointer */
@@ -717,7 +703,7 @@ static void build_prologue(struct jit_ctx *ctx)
 		emit_jit_reg_move(r_X, r_zero, ctx);
 
 	/* Do not leak kernel data to userspace */
-	if ((first_inst != (BPF_RET | BPF_K)) && !(is_load_to_a(first_inst)))
+	if (bpf_needs_clear_a(&ctx->skf->insns[0]))
 		emit_jit_reg_move(r_A, r_zero, ctx);
 }
 
diff --git a/arch/powerpc/net/bpf_jit_comp.c b/arch/powerpc/net/bpf_jit_comp.c
index 82e82cadcde5..6a1c7ecfdd2c 100644
--- a/arch/powerpc/net/bpf_jit_comp.c
+++ b/arch/powerpc/net/bpf_jit_comp.c
@@ -78,18 +78,9 @@ static void bpf_jit_build_prologue(struct sk_filter *fp, u32 *image,
 		PPC_LI(r_X, 0);
 	}
 
-	switch (filter[0].code) {
-	case BPF_RET | BPF_K:
-	case BPF_LD | BPF_W | BPF_LEN:
-	case BPF_LD | BPF_W | BPF_ABS:
-	case BPF_LD | BPF_H | BPF_ABS:
-	case BPF_LD | BPF_B | BPF_ABS:
-		/* first instruction sets A register (or is RET 'constant') */
-		break;
-	default:
-		/* make sure we dont leak kernel information to user */
+	/* make sure we dont leak kernel information to user */
+	if (bpf_needs_clear_a(&filter[0]))
 		PPC_LI(r_A, 0);
-	}
 }
 
 static void bpf_jit_build_epilogue(u32 *image, struct codegen_context *ctx)
diff --git a/arch/sparc/net/bpf_jit_comp.c b/arch/sparc/net/bpf_jit_comp.c
index 8d4152f94c5a..ae966f86dcec 100644
--- a/arch/sparc/net/bpf_jit_comp.c
+++ b/arch/sparc/net/bpf_jit_comp.c
@@ -420,22 +420,9 @@ void bpf_jit_compile(struct sk_filter *fp)
 		}
 		emit_reg_move(O7, r_saved_O7);
 
-		switch (filter[0].code) {
-		case BPF_RET | BPF_K:
-		case BPF_LD | BPF_W | BPF_LEN:
-		case BPF_LD | BPF_W | BPF_ABS:
-		case BPF_LD | BPF_H | BPF_ABS:
-		case BPF_LD | BPF_B | BPF_ABS:
-			/* The first instruction sets the A register (or is
-			 * a "RET 'constant'")
-			 */
-			break;
-		default:
-			/* Make sure we dont leak kernel information to the
-			 * user.
-			 */
+		/* Make sure we dont leak kernel information to the user. */
+		if (bpf_needs_clear_a(&filter[0]))
 			emit_clear(r_A); /* A = 0 */
-		}
 
 		for (i = 0; i < flen; i++) {
 			unsigned int K = filter[i].k;
diff --git a/include/linux/filter.h b/include/linux/filter.h
index a7e3c48d73a7..02f857260bcb 100644
--- a/include/linux/filter.h
+++ b/include/linux/filter.h
@@ -373,6 +373,25 @@ void bpf_int_jit_compile(struct sk_filter *fp);
 
 #define BPF_ANC		BIT(15)
 
+static inline bool bpf_needs_clear_a(const struct sock_filter *first)
+{
+	switch (first->code) {
+	case BPF_RET | BPF_K:
+	case BPF_LD | BPF_W | BPF_LEN:
+		return false;
+
+	case BPF_LD | BPF_W | BPF_ABS:
+	case BPF_LD | BPF_H | BPF_ABS:
+	case BPF_LD | BPF_B | BPF_ABS:
+		if (first->k == SKF_AD_OFF + SKF_AD_ALU_XOR_X)
+			return true;
+		return false;
+
+	default:
+		return true;
+	}
+}
+
 static inline u16 bpf_anc_helper(const struct sock_filter *ftest)
 {
 	BUG_ON(ftest->code & BPF_ANC);

[toc] | [prev] | [next] | [standalone]


#1316010 — [PATCH 3.16.y-ckt 098/128] ASoC: wm8974: set cache type for regmap

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 098/128] ASoC: wm8974: set cache type for regmap
Message-ID<qUB1a-2KY-53@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Mans Rullgard <mans@mansr.com>

commit 1ea5998afe903384ddc16391d4c023cd4c867bea upstream.

Attempting to use this codec driver triggers a BUG() in regcache_sync()
since no cache type is set.  The register map of this device is fairly
small and has few holes so a flat cache is suitable.

Signed-off-by: Mans Rullgard <mans@mansr.com>
Acked-by: Charles Keepax <ckeepax@opensource.wolfsonmicro.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 sound/soc/codecs/wm8974.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/soc/codecs/wm8974.c b/sound/soc/codecs/wm8974.c
index 0627c56fa44e..c2248db97fc4 100644
--- a/sound/soc/codecs/wm8974.c
+++ b/sound/soc/codecs/wm8974.c
@@ -587,6 +587,7 @@ static const struct regmap_config wm8974_regmap = {
 	.max_register = WM8974_MONOMIX,
 	.reg_defaults = wm8974_reg_defaults,
 	.num_reg_defaults = ARRAY_SIZE(wm8974_reg_defaults),
+	.cache_type = REGCACHE_FLAT,
 };
 
 static int wm8974_probe(struct snd_soc_codec *codec)

[toc] | [prev] | [next] | [standalone]


#1316011 — [PATCH 3.16.y-ckt 122/128] ASoC: Use nested lock for snd_soc_dapm_mutex_lock

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 122/128] ASoC: Use nested lock for snd_soc_dapm_mutex_lock
Message-ID<qUB1a-2KY-55@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Charles Keepax <ckeepax@opensource.wolfsonmicro.com>

commit 783513eec3209542fcd6ac0cbcb030b3c17a4827 upstream.

snd_soc_dapm_mutex_lock currently uses the un-nested call which can
cause lockdep warnings when called from control handlers (a relatively
common usage) and using modules. As creating the control causes a
potential mutex inversion with the handler, creating the control will
take the controls_rwsem under the dapm_mutex and accessing the control
will take the dapm_mutex under controls_rwsem.

All the users look like they want to be using the runtime class of the
lock anyway, so this patch just changes snd_soc_dapm_mutex_lock to use
the nested call, with the SND_SOC_DAPM_CLASS_RUNTIME class.

Fixes: f6d5e586b416 ("ASoC: dapm: Add helpers to lock/unlock DAPM mutex")
Signed-off-by: Charles Keepax <ckeepax@opensource.wolfsonmicro.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 include/sound/soc.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/sound/soc.h b/include/sound/soc.h
index a34d34649195..4dc6904ebbf9 100644
--- a/include/sound/soc.h
+++ b/include/sound/soc.h
@@ -1390,7 +1390,7 @@ extern const struct dev_pm_ops snd_soc_pm_ops;
 /* Helper functions */
 static inline void snd_soc_dapm_mutex_lock(struct snd_soc_dapm_context *dapm)
 {
-	mutex_lock(&dapm->card->dapm_mutex);
+	mutex_lock_nested(&dapm->card->dapm_mutex, SND_SOC_DAPM_CLASS_RUNTIME);
 }
 
 static inline void snd_soc_dapm_mutex_unlock(struct snd_soc_dapm_context *dapm)

[toc] | [prev] | [next] | [standalone]


#1316012 — [PATCH 3.16.y-ckt 062/128] n_tty: Fix poll() after buffer-limited eof push read

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 062/128] n_tty: Fix poll() after buffer-limited eof push read
Message-ID<qUB1a-2KY-61@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Peter Hurley <peter@hurleysoftware.com>

commit ac8f3bf8832a405cc6e4dccb1d26d5cb2994d234 upstream.

commit 40d5e0905a03 ("n_tty: Fix EOF push handling") fixed EOF push
for reads. However, that approach still allows a condition mismatch
between poll() and read(), where poll() returns POLLIN but read()
blocks. This state can happen when a previous read() returned because
the user buffer was full and the next character was an EOF not at the
beginning of the line. While the next read() will properly identify
the condition and advance the read buffer tail without improperly
indicating an EOF file condition (ie., read() will not mistakenly
return 0), poll() will mistakenly indicate POLLIN.

Although a possible solution would be to peek at the input buffer
in n_tty_poll(), the better solution in this patch is to eat the
EOF during the previous read() (ie., fix the problem by eliminating
the condition).

The current canon line buffer copy limits the scan for next end-of-line
to the smaller of either,
   a. the remaining user buffer size
   b. completed lines in the input buffer
When the remaining user buffer size is exactly one less than the
end-of-line marked by EOF push, the EOF is not scanned nor skipped
but left for subsequent reads. In the example below, the scan
index 'eol' has stopped at the EOF because it is past the scan
limit of 5 (not because it has found the next set bit in read_flags)

   user buffer [*nr = 5]    _ _ _ _ _

   read_flags               0 0 0 0 0   1
   input buffer             h e l l o [EOF]
                            ^           ^
                           /           /
                         tail        eol

   result: found = 0, tail += 5, *nr += 5

Instead, allow the scan to peek ahead 1 byte (while still limiting the
scan to completed lines in the input buffer). For the example above,

   result: found = 1, tail += 6, *nr += 5

Because the scan limit is now bumped +1 byte, when the scan is
completed, the tail advance and the user buffer copy limit is
re-clamped to *nr when EOF is _not_ found.

Fixes: 40d5e0905a03 ("n_tty: Fix EOF push handling")
Signed-off-by: Peter Hurley <peter@hurleysoftware.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/tty/n_tty.c | 22 +++++++++-------------
 1 file changed, 9 insertions(+), 13 deletions(-)

diff --git a/drivers/tty/n_tty.c b/drivers/tty/n_tty.c
index 29de4bfe5c70..d239fdba29d6 100644
--- a/drivers/tty/n_tty.c
+++ b/drivers/tty/n_tty.c
@@ -2048,13 +2048,13 @@ static int canon_copy_from_read_buf(struct tty_struct *tty,
 	size_t eol;
 	size_t tail;
 	int ret, found = 0;
-	bool eof_push = 0;
 
 	/* N.B. avoid overrun if nr == 0 */
-	n = min(*nr, read_cnt(ldata));
-	if (!n)
+	if (!*nr)
 		return 0;
 
+	n = min(*nr + 1, read_cnt(ldata));
+
 	tail = ldata->read_tail & (N_TTY_BUF_SIZE - 1);
 	size = min_t(size_t, tail + n, N_TTY_BUF_SIZE);
 
@@ -2075,12 +2075,11 @@ static int canon_copy_from_read_buf(struct tty_struct *tty,
 	n = eol - tail;
 	if (n > 4096)
 		n += 4096;
-	n += found;
-	c = n;
+	c = n + found;
 
-	if (found && !ldata->push && read_buf(ldata, eol) == __DISABLED_CHAR) {
-		n--;
-		eof_push = !n && ldata->read_tail != ldata->line_start;
+	if (!found || read_buf(ldata, eol) != __DISABLED_CHAR) {
+		c = min(*nr, c);
+		n = c;
 	}
 
 	n_tty_trace("%s: eol:%zu found:%d n:%zu c:%zu size:%zu more:%zu\n",
@@ -2111,7 +2110,7 @@ static int canon_copy_from_read_buf(struct tty_struct *tty,
 			ldata->push = 0;
 		tty_audit_push(tty);
 	}
-	return eof_push ? -EAGAIN : 0;
+	return 0;
 }
 
 extern ssize_t redirected_tty_write(struct file *, const char __user *,
@@ -2299,10 +2298,7 @@ static ssize_t n_tty_read(struct tty_struct *tty, struct file *file,
 
 		if (ldata->icanon && !L_EXTPROC(tty)) {
 			retval = canon_copy_from_read_buf(tty, &b, &nr);
-			if (retval == -EAGAIN) {
-				retval = 0;
-				continue;
-			} else if (retval)
+			if (retval)
 				break;
 		} else {
 			int uncopied;

[toc] | [prev] | [next] | [standalone]


#1316013 — [PATCH 3.16.y-ckt 095/128] drm/i915: Fix SRC_COPY width on 830/845g

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 095/128] drm/i915: Fix SRC_COPY width on 830/845g
Message-ID<qUB1a-2KY-57@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Chris Wilson <chris@chris-wilson.co.uk>

commit 611a7a4fd8b5fb6b25ab1f8bdcde61800a7feacf upstream.

One small change I forgot to make in

commit c4d69da167fa967749aeb70bc0e94a457e5d00c1
Author: Chris Wilson <chris@chris-wilson.co.uk>
Date:   Mon Sep 8 14:25:41 2014 +0100

    drm/i915: Evict CS TLBs between batches

was to update the copy width for the compact BLT copy instruction.

Reported-by: Thomas Richter <thor@math.tu-berlin.de>
Signed-off-by: Chris Wilson <chris@chris-wilson.co.uk>
Cc: Thomas Richter <thor@math.tu-berlin.de>
Cc: Jani Nikula <jani.nikula@intel.com>
Tested-by: Thomas Richter <thor@math.tu-berlin.de>
Acked-by: Daniel Vetter <daniel@ffwll.ch>
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/gpu/drm/i915/intel_ringbuffer.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/i915/intel_ringbuffer.c b/drivers/gpu/drm/i915/intel_ringbuffer.c
index 6a7a35acdfa7..b849fde1ea74 100644
--- a/drivers/gpu/drm/i915/intel_ringbuffer.c
+++ b/drivers/gpu/drm/i915/intel_ringbuffer.c
@@ -1284,7 +1284,7 @@ i830_dispatch_execbuffer(struct intel_engine_cs *ring,
 		 */
 		intel_ring_emit(ring, SRC_COPY_BLT_CMD | BLT_WRITE_RGBA);
 		intel_ring_emit(ring, BLT_DEPTH_32 | BLT_ROP_SRC_COPY | 4096);
-		intel_ring_emit(ring, DIV_ROUND_UP(len, 4096) << 16 | 1024);
+		intel_ring_emit(ring, DIV_ROUND_UP(len, 4096) << 16 | 4096);
 		intel_ring_emit(ring, cs_offset);
 		intel_ring_emit(ring, 4096);
 		intel_ring_emit(ring, offset);

[toc] | [prev] | [next] | [standalone]


#1316014 — [PATCH 3.16.y-ckt 102/128] ALSA: hda - Set SKL+ hda controller power at freeze() and thaw()

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 102/128] ALSA: hda - Set SKL+ hda controller power at freeze() and thaw()
Message-ID<qUB1a-2KY-59@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Xiong Zhang <xiong.y.zhang@intel.com>

commit 3e6db33aaf1d42a30339f831ec4850570d6cc7a3 upstream.

It takes three minutes to enter into hibernation on some OEM SKL
machines and we see many codec spurious response after thaw() opertion.
This is because HDA is still in D0 state after freeze() call and
pci_pm_freeze/pci_pm_freeze_noirq() don't set D3 hot in pci_bus driver.
It seems bios still access HDA when system enter into freeze state,
HDA will receive codec response interrupt immediately after thaw() call.
Because of this unexpected interrupt, HDA enter into a abnormal
state and slow down the system enter into hibernation.

In this patch, we put HDA into D3 hot state in azx_freeze_noirq() and
put HDA into D0 state in azx_thaw_noirq().

V2: Only apply this fix to SKL+
    Fix compile error when CONFIG_PM_SLEEP isn't defined

[Yet another fix for CONFIG_PM_SLEEP ifdef and the additional comment
 by tiwai]

Signed-off-by: Xiong Zhang <xiong.y.zhang@intel.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 sound/pci/hda/hda_intel.c | 34 ++++++++++++++++++++++++++++++++++
 1 file changed, 34 insertions(+)

diff --git a/sound/pci/hda/hda_intel.c b/sound/pci/hda/hda_intel.c
index d4268a2bbca7..2f523b08f576 100644
--- a/sound/pci/hda/hda_intel.c
+++ b/sound/pci/hda/hda_intel.c
@@ -663,6 +663,36 @@ static int azx_resume(struct device *dev)
 }
 #endif /* CONFIG_PM_SLEEP || SUPPORT_VGA_SWITCHEROO */
 
+#ifdef CONFIG_PM_SLEEP
+/* put codec down to D3 at hibernation for Intel SKL+;
+ * otherwise BIOS may still access the codec and screw up the driver
+ */
+#define IS_SKL(pci) ((pci)->vendor == 0x8086 && (pci)->device == 0xa170)
+#define IS_SKL_LP(pci) ((pci)->vendor == 0x8086 && (pci)->device == 0x9d70)
+#define IS_BXT(pci) ((pci)->vendor == 0x8086 && (pci)->device == 0x5a98)
+#define IS_SKL_PLUS(pci) (IS_SKL(pci) || IS_SKL_LP(pci) || IS_BXT(pci))
+
+static int azx_freeze_noirq(struct device *dev)
+{
+	struct pci_dev *pci = to_pci_dev(dev);
+
+	if (IS_SKL_PLUS(pci))
+		pci_set_power_state(pci, PCI_D3hot);
+
+	return 0;
+}
+
+static int azx_thaw_noirq(struct device *dev)
+{
+	struct pci_dev *pci = to_pci_dev(dev);
+
+	if (IS_SKL_PLUS(pci))
+		pci_set_power_state(pci, PCI_D0);
+
+	return 0;
+}
+#endif /* CONFIG_PM_SLEEP */
+
 #ifdef CONFIG_PM_RUNTIME
 static int azx_runtime_suspend(struct device *dev)
 {
@@ -748,6 +778,10 @@ static int azx_runtime_idle(struct device *dev)
 #ifdef CONFIG_PM
 static const struct dev_pm_ops azx_pm = {
 	SET_SYSTEM_SLEEP_PM_OPS(azx_suspend, azx_resume)
+#ifdef CONFIG_PM_SLEEP
+	.freeze_noirq = azx_freeze_noirq,
+	.thaw_noirq = azx_thaw_noirq,
+#endif
 	SET_RUNTIME_PM_OPS(azx_runtime_suspend, azx_runtime_resume, azx_runtime_idle)
 };
 

[toc] | [prev] | [next] | [standalone]


#1316015 — [PATCH 3.16.y-ckt 013/128] staging: lustre: echo_copy.._lsm() dereferences userland pointers directly

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 013/128] staging: lustre: echo_copy.._lsm() dereferences userland pointers directly
Message-ID<qUB1a-2KY-65@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Al Viro <viro@ZenIV.linux.org.uk>

commit 9225c0b7b976dd9ceac2b80727a60d8fcb906a62 upstream.

missing get_user()

Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/staging/lustre/lustre/obdecho/echo_client.c | 20 +++++++++++---------
 1 file changed, 11 insertions(+), 9 deletions(-)

diff --git a/drivers/staging/lustre/lustre/obdecho/echo_client.c b/drivers/staging/lustre/lustre/obdecho/echo_client.c
index cdc46719bbd4..95c0bdb45d2a 100644
--- a/drivers/staging/lustre/lustre/obdecho/echo_client.c
+++ b/drivers/staging/lustre/lustre/obdecho/echo_client.c
@@ -1380,6 +1380,7 @@ static int
 echo_copyout_lsm (struct lov_stripe_md *lsm, void *_ulsm, int ulsm_nob)
 {
 	struct lov_stripe_md *ulsm = _ulsm;
+	struct lov_oinfo **p;
 	int nob, i;
 
 	nob = offsetof (struct lov_stripe_md, lsm_oinfo[lsm->lsm_stripe_count]);
@@ -1389,9 +1390,10 @@ echo_copyout_lsm (struct lov_stripe_md *lsm, void *_ulsm, int ulsm_nob)
 	if (copy_to_user (ulsm, lsm, sizeof(*ulsm)))
 		return (-EFAULT);
 
-	for (i = 0; i < lsm->lsm_stripe_count; i++) {
-		if (copy_to_user (ulsm->lsm_oinfo[i], lsm->lsm_oinfo[i],
-				      sizeof(lsm->lsm_oinfo[0])))
+	for (i = 0, p = lsm->lsm_oinfo; i < lsm->lsm_stripe_count; i++, p++) {
+		struct lov_oinfo __user *up;
+		if (get_user(up, ulsm->lsm_oinfo + i) ||
+		    copy_to_user(up, *p, sizeof(struct lov_oinfo)))
 			return (-EFAULT);
 	}
 	return 0;
@@ -1399,9 +1401,10 @@ echo_copyout_lsm (struct lov_stripe_md *lsm, void *_ulsm, int ulsm_nob)
 
 static int
 echo_copyin_lsm (struct echo_device *ed, struct lov_stripe_md *lsm,
-		 void *ulsm, int ulsm_nob)
+		struct lov_stripe_md __user *ulsm, int ulsm_nob)
 {
 	struct echo_client_obd *ec = ed->ed_ec;
+	struct lov_oinfo **p;
 	int		     i;
 
 	if (ulsm_nob < sizeof (*lsm))
@@ -1417,11 +1420,10 @@ echo_copyin_lsm (struct echo_device *ed, struct lov_stripe_md *lsm,
 		return (-EINVAL);
 
 
-	for (i = 0; i < lsm->lsm_stripe_count; i++) {
-		if (copy_from_user(lsm->lsm_oinfo[i],
-				       ((struct lov_stripe_md *)ulsm)-> \
-				       lsm_oinfo[i],
-				       sizeof(lsm->lsm_oinfo[0])))
+	for (i = 0, p = lsm->lsm_oinfo; i < lsm->lsm_stripe_count; i++, p++) {
+		struct lov_oinfo __user *up;
+		if (get_user(up, ulsm->lsm_oinfo + i) ||
+		    copy_from_user(*p, up, sizeof(struct lov_oinfo)))
 			return (-EFAULT);
 	}
 	return (0);

[toc] | [prev] | [next] | [standalone]


#1316016 — [PATCH 3.16.y-ckt 127/128] udp: properly support MSG_PEEK with truncated buffers

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 127/128] udp: properly support MSG_PEEK with truncated buffers
Message-ID<qUB1a-2KY-67@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Eric Dumazet <edumazet@google.com>

commit 197c949e7798fbf28cfadc69d9ca0c2abbf93191 upstream.

Backport of this upstream commit into stable kernels :
89c22d8c3b27 ("net: Fix skb csum races when peeking")
exposed a bug in udp stack vs MSG_PEEK support, when user provides
a buffer smaller than skb payload.

In this case,
skb_copy_and_csum_datagram_iovec(skb, sizeof(struct udphdr),
                                 msg->msg_iov);
returns -EFAULT.

This bug does not happen in upstream kernels since Al Viro did a great
job to replace this into :
skb_copy_and_csum_datagram_msg(skb, sizeof(struct udphdr), msg);
This variant is safe vs short buffers.

For the time being, instead reverting Herbert Xu patch and add back
skb->ip_summed invalid changes, simply store the result of
udp_lib_checksum_complete() so that we avoid computing the checksum a
second time, and avoid the problematic
skb_copy_and_csum_datagram_iovec() call.

This patch can be applied on recent kernels as it avoids a double
checksumming, then backported to stable kernels as a bug fix.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/ipv4/udp.c | 6 ++++--
 net/ipv6/udp.c | 6 ++++--
 2 files changed, 8 insertions(+), 4 deletions(-)

diff --git a/net/ipv4/udp.c b/net/ipv4/udp.c
index 4b9e4aba11b0..c57fa4c74c94 100644
--- a/net/ipv4/udp.c
+++ b/net/ipv4/udp.c
@@ -1272,6 +1272,7 @@ int udp_recvmsg(struct kiocb *iocb, struct sock *sk, struct msghdr *msg,
 	int peeked, off = 0;
 	int err;
 	int is_udplite = IS_UDPLITE(sk);
+	bool checksum_valid = false;
 	bool slow;
 
 	if (flags & MSG_ERRQUEUE)
@@ -1297,11 +1298,12 @@ try_again:
 	 */
 
 	if (copied < ulen || UDP_SKB_CB(skb)->partial_cov) {
-		if (udp_lib_checksum_complete(skb))
+		checksum_valid = !udp_lib_checksum_complete(skb);
+		if (!checksum_valid)
 			goto csum_copy_err;
 	}
 
-	if (skb_csum_unnecessary(skb))
+	if (checksum_valid || skb_csum_unnecessary(skb))
 		err = skb_copy_datagram_iovec(skb, sizeof(struct udphdr),
 					      msg->msg_iov, copied);
 	else {
diff --git a/net/ipv6/udp.c b/net/ipv6/udp.c
index eb38829d8919..e432f8eb3c60 100644
--- a/net/ipv6/udp.c
+++ b/net/ipv6/udp.c
@@ -389,6 +389,7 @@ int udpv6_recvmsg(struct kiocb *iocb, struct sock *sk,
 	int peeked, off = 0;
 	int err;
 	int is_udplite = IS_UDPLITE(sk);
+	bool checksum_valid = false;
 	int is_udp4;
 	bool slow;
 
@@ -420,11 +421,12 @@ try_again:
 	 */
 
 	if (copied < ulen || UDP_SKB_CB(skb)->partial_cov) {
-		if (udp_lib_checksum_complete(skb))
+		checksum_valid = !udp_lib_checksum_complete(skb);
+		if (!checksum_valid)
 			goto csum_copy_err;
 	}
 
-	if (skb_csum_unnecessary(skb))
+	if (checksum_valid || skb_csum_unnecessary(skb))
 		err = skb_copy_datagram_iovec(skb, sizeof(struct udphdr),
 					      msg->msg_iov, copied);
 	else {

[toc] | [prev] | [next] | [standalone]


#1316160 — Re: [PATCH 3.16.y-ckt 127/128] udp: properly support MSG_PEEK with truncated buffers

FromBen Hutchings <ben@decadent.org.uk>
Date2016-01-25 02:50 +0100
SubjectRe: [PATCH 3.16.y-ckt 127/128] udp: properly support MSG_PEEK with truncated buffers
Message-ID<qUEs3-4Xi-13@gated-at.bofh.it>
In reply to#1316016

[Multipart message — attachments visible in raw view] — view raw

On Sun, 2016-01-24 at 22:01 +0000, Luis Henriques wrote:
> 3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.
> 
> ---8<------------------------------------------------------------
> 
> From: Eric Dumazet <edumazet@google.com>
> 
> commit 197c949e7798fbf28cfadc69d9ca0c2abbf93191 upstream.
[...]

Please also revert commit fa89ae5548ed282f0ceb4660b3b93e4e2ee875f3
which was the previous attempt to fix this.

Ben.

-- 
Ben Hutchings
Klipstein's 4th Law of Prototyping and Production:
                                    A fail-safe circuit will destroy others.

[toc] | [prev] | [next] | [standalone]


#1316480 — Re: [PATCH 3.16.y-ckt 127/128] udp: properly support MSG_PEEK with truncated buffers

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-25 12:00 +0100
SubjectRe: [PATCH 3.16.y-ckt 127/128] udp: properly support MSG_PEEK with truncated buffers
Message-ID<qUN2j-2Gb-21@gated-at.bofh.it>
In reply to#1316160
On Mon, Jan 25, 2016 at 01:41:23AM +0000, Ben Hutchings wrote:
> On Sun, 2016-01-24 at 22:01 +0000, Luis Henriques wrote:
> > 3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.
> > 
> > ---8<------------------------------------------------------------
> > 
> > From: Eric Dumazet <edumazet@google.com>
> > 
> > commit 197c949e7798fbf28cfadc69d9ca0c2abbf93191 upstream.
> [...]
> 
> Please also revert commit fa89ae5548ed282f0ceb4660b3b93e4e2ee875f3
> which was the previous attempt to fix this.
> 

Thanks, I'll add that revert to 3.16.7-ckt23 as well.

Cheers,
--
Luís

> Ben.
> 
> -- 
> Ben Hutchings
> Klipstein's 4th Law of Prototyping and Production:
>                                     A fail-safe circuit will destroy others.

[toc] | [prev] | [next] | [standalone]


Page 1 of 7  [1] 2 3 4 5 6 7  Next page →

Back to top | Article view | linux.kernel


csiph-web