Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1315999 > unrolled thread

[3.16.y-ckt stable] Linux 3.16.7-ckt23 stable review

Started byLuis Henriques <luis.henriques@canonical.com>
First post2016-01-24 23:10 +0100
Last post2016-01-25 12:00 +0100
Articles 20 on this page of 122 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [3.16.y-ckt stable] Linux 3.16.7-ckt23 stable review Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 118/128] x86/mce: Ensure offline CPUs don't participate in rendezvous process Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 002/128] usb: gadget: pxa27x: fix suspend callback Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 008/128] jbd2: Fix unreclaimed pages after truncate in data=journal mode Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 077/128] xen-blkback: read from indirect descriptors only once Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 085/128] USB: fix invalid memory access in hub_activate() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 126/128] firmware: dmi_scan: Fix UUID endianness for SMBIOS >= 2.6 Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 125/128] kvm: x86: only channel 0 of the i8254 is linked to the HPET Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 104/128] parisc: Fix syscall restarts Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 034/128] dm thin metadata: fix bug when taking a metadata snapshot Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 123/128] net: filter: make JITs zero A for SKF_AD_ALU_XOR_X Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 098/128] ASoC: wm8974: set cache type for regmap Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 122/128] ASoC: Use nested lock for snd_soc_dapm_mutex_lock Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 062/128] n_tty: Fix poll() after buffer-limited eof push read Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 095/128] drm/i915: Fix SRC_COPY width on 830/845g Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 102/128] ALSA: hda - Set SKL+ hda controller power at freeze() and thaw() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 013/128] staging: lustre: echo_copy.._lsm() dereferences userland pointers directly Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 127/128] udp: properly support MSG_PEEK with truncated buffers Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
      Re: [PATCH 3.16.y-ckt 127/128] udp: properly support MSG_PEEK with  truncated buffers Ben Hutchings <ben@decadent.org.uk> - 2016-01-25 02:50 +0100
        Re: [PATCH 3.16.y-ckt 127/128] udp: properly support MSG_PEEK with  truncated buffers Luis Henriques <luis.henriques@canonical.com> - 2016-01-25 12:00 +0100
    [PATCH 3.16.y-ckt 124/128] net: possible use after free in dst_release Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 111/128] net/mlx4_en: Fix HW timestamp init issue upon system startup Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 120/128] async_tx: use GFP_NOWAIT rather than GFP_IO Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 023/128] ALSA: hda - Add inverted dmic for Packard Bell DOTS Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 109/128] mm/memory_hotplug.c: check for missing sections in test_pages_in_a_zone() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 119/128] ASoC: arizona: Fix bclk for sample rates that are multiple of 4kHz Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 071/128] powerpc/powernv: Fix the overflow of OPAL message notifiers head array Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 067/128] spi: fix parent-device reference leak Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 011/128] sata_sil: disable trim Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:10 +0100
    [PATCH 3.16.y-ckt 114/128] genirq: Prevent chip buslock deadlock Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 093/128] net: fix warnings in 'make htmldocs' by moving macro definition out of field declaration Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 112/128] ipv6/addrlabel: fix ip6addrlbl_get() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 091/128] qlcnic: fix a timeout loop Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 097/128] KVM: PPC: Book3S HV: Prohibit setting illegal transaction state in MSR Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 107/128] [PATCH] arm: fix handling of F_OFD_... in oabi_fcntl64() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 087/128] net: phy: mdio-mux: Check return value of mdiobus_alloc() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 092/128] ser_gigaset: fix deallocation of platform device structure Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 103/128] s390/dis: Fix handling of format specifiers Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 108/128] ocfs2: fix BUG when calculate new backup super Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 084/128] USB: ipaq.c: fix a timeout loop Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 094/128] include/linux/mmdebug.h: should include linux/bug.h Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 099/128] ARM: dts: imx6: Fix Ethernet PHY mode on Ventana boards Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 096/128] vmstat: allocate vmstat_wq before it is used Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 100/128] scripts: recordmcount: break hardlinks Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 106/128] MIPS: uaccess: Fix strlen_user with EVA Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 105/128] ALSA: hda/realtek - Fix silent headphone output on MacPro 4,1 (v2) Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 113/128] qlcnic: fix a loop exit condition better Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 080/128] xen/pciback: Return error on XEN_PCI_OP_enable_msix when device has MSI or MSI-X enabled Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 110/128] net/mlx4_en: Remove dependency between timestamping capability and service_task Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 090/128] amd-xgbe: fix a couple timeout loops Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 101/128] ftrace/scripts: Have recordmcount copy the object file Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 086/128] pinctrl: bcm2835: Fix initial value for direction_output Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 082/128] xen/pciback: For XEN_PCI_OP_disable_msi[|x] only disable if device has MSI(X) enabled. Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 088/128] sh_eth: fix TX buffer byte-swapping Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    Re: [PATCH 3.16.y-ckt 043/128] mm, vmstat: allow WQ concurrency to  discover memory reclaim doesn't make any progress Ben Hutchings <ben@decadent.org.uk> - 2016-01-24 23:20 +0100
      Re: [PATCH 3.16.y-ckt 043/128] mm, vmstat: allow WQ concurrency to  discover memory reclaim doesn't make any progress Luis Henriques <luis.henriques@canonical.com> - 2016-01-25 12:00 +0100
    [PATCH 3.16.y-ckt 081/128] xen/pciback: Do not install an IRQ handler for MSI interrupts. Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 083/128] xen/pciback: Don't allow MSI-X ops if PCI_COMMAND_MEMORY is not set. Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:20 +0100
    [PATCH 3.16.y-ckt 063/128] tty: Fix GPF in flush_to_ldisc() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 059/128] Revert "SCSI: Fix NULL pointer dereference in runtime PM" Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 074/128] xen-netback: don't use last request to determine minimum Tx credit Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 030/128] radeon/cik: Fix GFX IB test on Big-Endian Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 070/128] ARC: dw2 unwind: Ignore CIE version !=1 gracefully instead of bailing Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 075/128] xen-netback: use RING_COPY_REQUEST() throughout Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 057/128] rfkill: copy the name into the rfkill struct Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 060/128] ses: fix additional element traversal bug Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 079/128] xen/pciback: Return error on XEN_PCI_OP_enable_msi when device has MSI or MSI-X enabled Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 064/128] ALSA: usb-audio: Add a more accurate volume quirk for AudioQuest DragonFly Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 073/128] xen: Add RING_COPY_REQUEST() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 055/128] video: fbdev: fsl: Fix kernel crash when diu_ops is not implemented Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 019/128] SCSI: Fix NULL pointer dereference in runtime PM Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 027/128] IB/srp: Fix possible send queue overflow Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 068/128] dma-debug: Fix dma_debug_entry offset calculation Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 022/128] ALSA: rme96: Fix unexpected volume reset after rate changes Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 014/128] irqchip/versatile-fpga: Fix PCI IRQ mapping on Versatile PB Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 052/128] tools: Add a "make all" rule Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 056/128] crypto: skcipher - Copy iv from desc even for 0-len walks Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 069/128] ARC: dw2 unwind: Reinstante unwinding out of modules Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 054/128] xen/events/fifo: Consume unprocessed events when a CPU dies Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 016/128] USB: whci-hcd: add check for dma mapping error Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 017/128] usb: Use the USB_SS_MULT() macro to decode burst multiplier for log message Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 040/128] USB: add quirk for devices with broken LPM Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 018/128] dm btree: fix leak of bufio-backed block in btree_split_sibling error path Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 061/128] powercap / RAPL: fix BIOS lock check Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 058/128] ses: Fix problems with simple enclosures Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 076/128] xen-blkback: only read request operation from shared ring once Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 066/128] ALSA: hda - Add a fixup for Thinkpad X1 Carbon 2nd Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 072/128] powerpc/powernv: pr_warn_once on unsupported OPAL_MSG type Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 065/128] ARM: 8471/1: need to save/restore arm register(r11) when it is corrupted Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 053/128] i2c: mv64xxx: The n clockdiv factor is 0 based on sunxi SoCs Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:30 +0100
    [PATCH 3.16.y-ckt 042/128] mm: hugetlb: fix hugepage memory leak caused by wrong reserve count Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 033/128] ALSA: hda - Fix noise problems on Thinkpad T440s Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 049/128] efi: Disable interrupts around EFI calls, not in the epilog/prolog calls Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 039/128] xhci: fix usb2 resume timing and races. Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 046/128] ocfs2: fix SGID not inherited issue Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 045/128] drivers/base/memory.c: prohibit offlining of memory blocks with missing sections Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 005/128] USB: cdc_acm: Ignore Infineon Flash Loader utility Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 010/128] AHCI: Fix softreset failed issue of Port Multiplier Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 031/128] radeon: Fix VCE ring test for Big-Endian systems Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 004/128] USB: cp210x: Remove CP2110 ID from compatibility list Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 006/128] USB: serial: Another Infineon flash loader USB ID Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 050/128] MIPS: uaccess: Take EVA into account in __copy_from_user() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 037/128] dm btree: fix bufio buffer leaks in dm_btree_del() error path Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 051/128] MIPS: uaccess: Take EVA into account in [__]clear_user Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 007/128] ext4: Fix handling of extended tv_sec Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 036/128] ipmi: move timer init to before irq is setup Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 035/128] dm space map metadata: fix ref counting bug when bootstrapping a new space map Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 032/128] radeon: Fix VCE IB test on Big-Endian systems Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 043/128] mm, vmstat: allow WQ concurrency to discover memory reclaim doesn't make any progress Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 041/128] parisc iommu: fix panic due to trying to allocate too large region Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 048/128] usb: musb: USB_TI_CPPI41_DMA requires dmaengine support Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 047/128] sh64: fix __NR_fgetxattr Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 038/128] vgaarb: fix signal handling in vga_get() Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 044/128] mm: hugetlb: call huge_pte_alloc() only if ptep is null Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 029/128] 9p: ->evict_inode() should kick out ->i_data, not ->i_mapping Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:40 +0100
    [PATCH 3.16.y-ckt 028/128] ALSA: hda - Fixing speaker noise on the two latest thinkpad models Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:50 +0100
    [PATCH 3.16.y-ckt 025/128] nfs4: limit callback decoding to received bytes Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:50 +0100
    [PATCH 3.16.y-ckt 021/128] usb: xhci: fix config fail of FS hub behind a HS hub with MTT Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:50 +0100
    [PATCH 3.16.y-ckt 026/128] SUNRPC: Fix callback channel Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:50 +0100
    [PATCH 3.16.y-ckt 020/128] perf: Fix PERF_EVENT_IOC_PERIOD deadlock Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:50 +0100
    [PATCH 3.16.y-ckt 024/128] virtio: fix memory leak of virtio ida cache layers Luis Henriques <luis.henriques@canonical.com> - 2016-01-24 23:50 +0100
    [PATCH 3.16.y-ckt 129/129] Revert "[stable-only] net: add length argument to skb_copy_and_csum_datagram_iovec" Luis Henriques <luis.henriques@canonical.com> - 2016-01-25 12:00 +0100

Page 2 of 7 — ← Prev page 1 [2] 3 4 5 6 7  Next page →


#1316018 — [PATCH 3.16.y-ckt 124/128] net: possible use after free in dst_release

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 124/128] net: possible use after free in dst_release
Message-ID<qUB1a-2KY-63@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Francesco Ruggeri <fruggeri@aristanetworks.com>

commit 07a5d38453599052aff0877b16bb9c1585f08609 upstream.

dst_release should not access dst->flags after decrementing
__refcnt to 0. The dst_entry may be in dst_busy_list and
dst_gc_task may dst_destroy it before dst_release gets a chance
to access dst->flags.

Fixes: d69bbf88c8d0 ("net: fix a race in dst_release()")
Fixes: 27b75c95f10d ("net: avoid RCU for NOCACHE dst")
Signed-off-by: Francesco Ruggeri <fruggeri@arista.com>
Acked-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/core/dst.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/net/core/dst.c b/net/core/dst.c
index a80e92346b9b..57746a18c957 100644
--- a/net/core/dst.c
+++ b/net/core/dst.c
@@ -282,10 +282,11 @@ void dst_release(struct dst_entry *dst)
 {
 	if (dst) {
 		int newrefcnt;
+		unsigned short nocache = dst->flags & DST_NOCACHE;
 
 		newrefcnt = atomic_dec_return(&dst->__refcnt);
 		WARN_ON(newrefcnt < 0);
-		if (!newrefcnt && unlikely(dst->flags & DST_NOCACHE))
+		if (!newrefcnt && unlikely(nocache))
 			call_rcu(&dst->rcu_head, dst_destroy_rcu);
 	}
 }

[toc] | [prev] | [next] | [standalone]


#1316019 — [PATCH 3.16.y-ckt 111/128] net/mlx4_en: Fix HW timestamp init issue upon system startup

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 111/128] net/mlx4_en: Fix HW timestamp init issue upon system startup
Message-ID<qUB1b-2KY-69@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Eugenia Emantayev <eugenia@mellanox.com>

commit 90683061dd50b0d70f01466c2d694f4e928a86f3 upstream.

mlx4_en_init_timestamp was called before creation of netdev and port
init, thus used uninitialized values.  Specifically - NIC frequency was
incorrect causing wrong calculations and later wrong HW timestamps.

Fixes: 1ec4864b1017 ('net/mlx4_en: Fixed crash when port type is changed')
Signed-off-by: Eugenia Emantayev <eugenia@mellanox.com>
Signed-off-by: Marina Varshaver <marinav@mellanox.com>
Signed-off-by: Eran Ben Elisha <eranbe@mellanox.com>
Signed-off-by: Or Gerlitz <ogerlitz@mellanox.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/net/ethernet/mellanox/mlx4/en_clock.c  | 7 +++++++
 drivers/net/ethernet/mellanox/mlx4/en_main.c   | 7 -------
 drivers/net/ethernet/mellanox/mlx4/en_netdev.c | 7 +++++++
 3 files changed, 14 insertions(+), 7 deletions(-)

diff --git a/drivers/net/ethernet/mellanox/mlx4/en_clock.c b/drivers/net/ethernet/mellanox/mlx4/en_clock.c
index 57dda95b67d8..74ed9f8fd267 100644
--- a/drivers/net/ethernet/mellanox/mlx4/en_clock.c
+++ b/drivers/net/ethernet/mellanox/mlx4/en_clock.c
@@ -291,6 +291,13 @@ void mlx4_en_init_timestamp(struct mlx4_en_dev *mdev)
 	unsigned long flags;
 	u64 ns;
 
+	/* mlx4_en_init_timestamp is called for each netdev.
+	 * mdev->ptp_clock is common for all ports, skip initialization if
+	 * was done for other port.
+	 */
+	if (mdev->ptp_clock)
+		return;
+
 	rwlock_init(&mdev->clock_lock);
 
 	memset(&mdev->cycles, 0, sizeof(mdev->cycles));
diff --git a/drivers/net/ethernet/mellanox/mlx4/en_main.c b/drivers/net/ethernet/mellanox/mlx4/en_main.c
index f953c1d7eae6..80af090463eb 100644
--- a/drivers/net/ethernet/mellanox/mlx4/en_main.c
+++ b/drivers/net/ethernet/mellanox/mlx4/en_main.c
@@ -206,9 +206,6 @@ static void mlx4_en_remove(struct mlx4_dev *dev, void *endev_ptr)
 		if (mdev->pndev[i])
 			mlx4_en_destroy_netdev(mdev->pndev[i]);
 
-	if (mdev->dev->caps.flags2 & MLX4_DEV_CAP_FLAG2_TS)
-		mlx4_en_remove_timestamp(mdev);
-
 	flush_workqueue(mdev->workqueue);
 	destroy_workqueue(mdev->workqueue);
 	(void) mlx4_mr_free(dev, &mdev->mr);
@@ -276,10 +273,6 @@ static void *mlx4_en_add(struct mlx4_dev *dev)
 	mlx4_foreach_port(i, dev, MLX4_PORT_TYPE_ETH)
 		mdev->port_cnt++;
 
-	/* Initialize time stamp mechanism */
-	if (mdev->dev->caps.flags2 & MLX4_DEV_CAP_FLAG2_TS)
-		mlx4_en_init_timestamp(mdev);
-
 	/* Set default number of RX rings*/
 	mlx4_en_set_num_rx_rings(mdev);
 
diff --git a/drivers/net/ethernet/mellanox/mlx4/en_netdev.c b/drivers/net/ethernet/mellanox/mlx4/en_netdev.c
index 3e663928b51e..bf3878823c96 100644
--- a/drivers/net/ethernet/mellanox/mlx4/en_netdev.c
+++ b/drivers/net/ethernet/mellanox/mlx4/en_netdev.c
@@ -2091,6 +2091,9 @@ void mlx4_en_destroy_netdev(struct net_device *dev)
 	/* flush any pending task for this netdev */
 	flush_workqueue(mdev->workqueue);
 
+	if (mdev->dev->caps.flags2 & MLX4_DEV_CAP_FLAG2_TS)
+		mlx4_en_remove_timestamp(mdev);
+
 	/* Detach the netdev so tasks would not attempt to access it */
 	mutex_lock(&mdev->state_lock);
 	mdev->pndev[priv->port] = NULL;
@@ -2655,6 +2658,10 @@ int mlx4_en_init_netdev(struct mlx4_en_dev *mdev, int port,
 	}
 	queue_delayed_work(mdev->workqueue, &priv->stats_task, STATS_DELAY);
 
+	/* Initialize time stamp mechanism */
+	if (mdev->dev->caps.flags2 & MLX4_DEV_CAP_FLAG2_TS)
+		mlx4_en_init_timestamp(mdev);
+
 	queue_delayed_work(mdev->workqueue, &priv->service_task,
 			   SERVICE_TASK_DELAY);
 

[toc] | [prev] | [next] | [standalone]


#1316020 — [PATCH 3.16.y-ckt 120/128] async_tx: use GFP_NOWAIT rather than GFP_IO

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 120/128] async_tx: use GFP_NOWAIT rather than GFP_IO
Message-ID<qUB1b-2KY-73@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: NeilBrown <neilb@suse.com>

commit b02bab6b0f928d49dbfb03e1e4e9dd43647623d7 upstream.

These async_XX functions are called from md/raid5 in an atomic
section, between get_cpu() and put_cpu(), so they must not sleep.
So use GFP_NOWAIT rather than GFP_IO.

Dan Williams writes: Longer term async_tx needs to be merged into md
directly as we can allocate this unmap data statically per-stripe
rather than per request.

Fixed: 7476bd79fc01 ("async_pq: convert to dmaengine_unmap_data")
Reported-and-tested-by: Stanislav Samsonov <slava@annapurnalabs.com>
Acked-by: Dan Williams <dan.j.williams@intel.com>
Signed-off-by: NeilBrown <neilb@suse.com>
Signed-off-by: Vinod Koul <vinod.koul@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 crypto/async_tx/async_memcpy.c      | 2 +-
 crypto/async_tx/async_pq.c          | 4 ++--
 crypto/async_tx/async_raid6_recov.c | 4 ++--
 crypto/async_tx/async_xor.c         | 4 ++--
 4 files changed, 7 insertions(+), 7 deletions(-)

diff --git a/crypto/async_tx/async_memcpy.c b/crypto/async_tx/async_memcpy.c
index f8c0b8dbeb75..88bc8e6b2a54 100644
--- a/crypto/async_tx/async_memcpy.c
+++ b/crypto/async_tx/async_memcpy.c
@@ -53,7 +53,7 @@ async_memcpy(struct page *dest, struct page *src, unsigned int dest_offset,
 	struct dmaengine_unmap_data *unmap = NULL;
 
 	if (device)
-		unmap = dmaengine_get_unmap_data(device->dev, 2, GFP_NOIO);
+		unmap = dmaengine_get_unmap_data(device->dev, 2, GFP_NOWAIT);
 
 	if (unmap && is_dma_copy_aligned(device, src_offset, dest_offset, len)) {
 		unsigned long dma_prep_flags = 0;
diff --git a/crypto/async_tx/async_pq.c b/crypto/async_tx/async_pq.c
index d05327caf69d..7eb264e65267 100644
--- a/crypto/async_tx/async_pq.c
+++ b/crypto/async_tx/async_pq.c
@@ -176,7 +176,7 @@ async_gen_syndrome(struct page **blocks, unsigned int offset, int disks,
 	BUG_ON(disks > 255 || !(P(blocks, disks) || Q(blocks, disks)));
 
 	if (device)
-		unmap = dmaengine_get_unmap_data(device->dev, disks, GFP_NOIO);
+		unmap = dmaengine_get_unmap_data(device->dev, disks, GFP_NOWAIT);
 
 	if (unmap &&
 	    (src_cnt <= dma_maxpq(device, 0) ||
@@ -294,7 +294,7 @@ async_syndrome_val(struct page **blocks, unsigned int offset, int disks,
 	BUG_ON(disks < 4);
 
 	if (device)
-		unmap = dmaengine_get_unmap_data(device->dev, disks, GFP_NOIO);
+		unmap = dmaengine_get_unmap_data(device->dev, disks, GFP_NOWAIT);
 
 	if (unmap && disks <= dma_maxpq(device, 0) &&
 	    is_dma_pq_aligned(device, offset, 0, len)) {
diff --git a/crypto/async_tx/async_raid6_recov.c b/crypto/async_tx/async_raid6_recov.c
index 934a84981495..8fab6275ea1f 100644
--- a/crypto/async_tx/async_raid6_recov.c
+++ b/crypto/async_tx/async_raid6_recov.c
@@ -41,7 +41,7 @@ async_sum_product(struct page *dest, struct page **srcs, unsigned char *coef,
 	u8 *a, *b, *c;
 
 	if (dma)
-		unmap = dmaengine_get_unmap_data(dma->dev, 3, GFP_NOIO);
+		unmap = dmaengine_get_unmap_data(dma->dev, 3, GFP_NOWAIT);
 
 	if (unmap) {
 		struct device *dev = dma->dev;
@@ -105,7 +105,7 @@ async_mult(struct page *dest, struct page *src, u8 coef, size_t len,
 	u8 *d, *s;
 
 	if (dma)
-		unmap = dmaengine_get_unmap_data(dma->dev, 3, GFP_NOIO);
+		unmap = dmaengine_get_unmap_data(dma->dev, 3, GFP_NOWAIT);
 
 	if (unmap) {
 		dma_addr_t dma_dest[2];
diff --git a/crypto/async_tx/async_xor.c b/crypto/async_tx/async_xor.c
index e1bce26cd4f9..da75777f2b3f 100644
--- a/crypto/async_tx/async_xor.c
+++ b/crypto/async_tx/async_xor.c
@@ -182,7 +182,7 @@ async_xor(struct page *dest, struct page **src_list, unsigned int offset,
 	BUG_ON(src_cnt <= 1);
 
 	if (device)
-		unmap = dmaengine_get_unmap_data(device->dev, src_cnt+1, GFP_NOIO);
+		unmap = dmaengine_get_unmap_data(device->dev, src_cnt+1, GFP_NOWAIT);
 
 	if (unmap && is_dma_xor_aligned(device, offset, 0, len)) {
 		struct dma_async_tx_descriptor *tx;
@@ -278,7 +278,7 @@ async_xor_val(struct page *dest, struct page **src_list, unsigned int offset,
 	BUG_ON(src_cnt <= 1);
 
 	if (device)
-		unmap = dmaengine_get_unmap_data(device->dev, src_cnt, GFP_NOIO);
+		unmap = dmaengine_get_unmap_data(device->dev, src_cnt, GFP_NOWAIT);
 
 	if (unmap && src_cnt <= device->max_xor &&
 	    is_dma_xor_aligned(device, offset, 0, len)) {

[toc] | [prev] | [next] | [standalone]


#1316021 — [PATCH 3.16.y-ckt 023/128] ALSA: hda - Add inverted dmic for Packard Bell DOTS

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 023/128] ALSA: hda - Add inverted dmic for Packard Bell DOTS
Message-ID<qUB1c-2KY-77@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: David Henningsson <david.henningsson@canonical.com>

commit 02f6ff90400d055f08b0ba0b5f0707630b6faed7 upstream.

On the internal mic of the Packard Bell DOTS, one channel
has an inverted signal. Add a quirk to fix this up.

BugLink: https://bugs.launchpad.net/bugs/1523232
Signed-off-by: David Henningsson <david.henningsson@canonical.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 sound/pci/hda/patch_realtek.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index a9bbfefb9d4a..e17824fff61d 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -6002,6 +6002,7 @@ static const struct hda_fixup alc662_fixups[] = {
 static const struct snd_pci_quirk alc662_fixup_tbl[] = {
 	SND_PCI_QUIRK(0x1019, 0x9087, "ECS", ALC662_FIXUP_ASUS_MODE2),
 	SND_PCI_QUIRK(0x1025, 0x022f, "Acer Aspire One", ALC662_FIXUP_INV_DMIC),
+	SND_PCI_QUIRK(0x1025, 0x0241, "Packard Bell DOTS", ALC662_FIXUP_INV_DMIC),
 	SND_PCI_QUIRK(0x1025, 0x0308, "Acer Aspire 8942G", ALC662_FIXUP_ASPIRE),
 	SND_PCI_QUIRK(0x1025, 0x031c, "Gateway NV79", ALC662_FIXUP_SKU_IGNORE),
 	SND_PCI_QUIRK(0x1025, 0x0349, "eMachines eM250", ALC662_FIXUP_INV_DMIC),

[toc] | [prev] | [next] | [standalone]


#1316022 — [PATCH 3.16.y-ckt 109/128] mm/memory_hotplug.c: check for missing sections in test_pages_in_a_zone()

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 109/128] mm/memory_hotplug.c: check for missing sections in test_pages_in_a_zone()
Message-ID<qUB1c-2KY-75@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Andrew Banman <abanman@sgi.com>

commit 5f0f2887f4de9508dcf438deab28f1de8070c271 upstream.

test_pages_in_a_zone() does not account for the possibility of missing
sections in the given pfn range.  pfn_valid_within always returns 1 when
CONFIG_HOLES_IN_ZONE is not set, allowing invalid pfns from missing
sections to pass the test, leading to a kernel oops.

Wrap an additional pfn loop with PAGES_PER_SECTION granularity to check
for missing sections before proceeding into the zone-check code.

This also prevents a crash from offlining memory devices with missing
sections.  Despite this, it may be a good idea to keep the related patch
'[PATCH 3/3] drivers: memory: prohibit offlining of memory blocks with
missing sections' because missing sections in a memory block may lead to
other problems not covered by the scope of this fix.

Signed-off-by: Andrew Banman <abanman@sgi.com>
Acked-by: Alex Thorlton <athorlton@sgi.com>
Cc: Russ Anderson <rja@sgi.com>
Cc: Alex Thorlton <athorlton@sgi.com>
Cc: Yinghai Lu <yinghai@kernel.org>
Cc: Greg KH <greg@kroah.com>
Cc: Seth Jennings <sjennings@variantweb.net>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 mm/memory_hotplug.c | 31 +++++++++++++++++++------------
 1 file changed, 19 insertions(+), 12 deletions(-)

diff --git a/mm/memory_hotplug.c b/mm/memory_hotplug.c
index 2c38c4fe9631..4ec1d4d7521a 100644
--- a/mm/memory_hotplug.c
+++ b/mm/memory_hotplug.c
@@ -1308,23 +1308,30 @@ int is_mem_section_removable(unsigned long start_pfn, unsigned long nr_pages)
  */
 static int test_pages_in_a_zone(unsigned long start_pfn, unsigned long end_pfn)
 {
-	unsigned long pfn;
+	unsigned long pfn, sec_end_pfn;
 	struct zone *zone = NULL;
 	struct page *page;
 	int i;
-	for (pfn = start_pfn;
+	for (pfn = start_pfn, sec_end_pfn = SECTION_ALIGN_UP(start_pfn);
 	     pfn < end_pfn;
-	     pfn += MAX_ORDER_NR_PAGES) {
-		i = 0;
-		/* This is just a CONFIG_HOLES_IN_ZONE check.*/
-		while ((i < MAX_ORDER_NR_PAGES) && !pfn_valid_within(pfn + i))
-			i++;
-		if (i == MAX_ORDER_NR_PAGES)
+	     pfn = sec_end_pfn + 1, sec_end_pfn += PAGES_PER_SECTION) {
+		/* Make sure the memory section is present first */
+		if (!present_section_nr(pfn_to_section_nr(pfn)))
 			continue;
-		page = pfn_to_page(pfn + i);
-		if (zone && page_zone(page) != zone)
-			return 0;
-		zone = page_zone(page);
+		for (; pfn < sec_end_pfn && pfn < end_pfn;
+		     pfn += MAX_ORDER_NR_PAGES) {
+			i = 0;
+			/* This is just a CONFIG_HOLES_IN_ZONE check.*/
+			while ((i < MAX_ORDER_NR_PAGES) &&
+				!pfn_valid_within(pfn + i))
+				i++;
+			if (i == MAX_ORDER_NR_PAGES)
+				continue;
+			page = pfn_to_page(pfn + i);
+			if (zone && page_zone(page) != zone)
+				return 0;
+			zone = page_zone(page);
+		}
 	}
 	return 1;
 }

[toc] | [prev] | [next] | [standalone]


#1316023 — [PATCH 3.16.y-ckt 119/128] ASoC: arizona: Fix bclk for sample rates that are multiple of 4kHz

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 119/128] ASoC: arizona: Fix bclk for sample rates that are multiple of 4kHz
Message-ID<qUB1c-2KY-83@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Nikesh Oswal <Nikesh.Oswal@cirrus.com>

commit e73694d871867cae8471d2350ce89acb38bc2b63 upstream.

For a sample rate of 12kHz the bclk was taken from the 44.1kHz table as
we test for a multiple of 8kHz. This patch fixes this issue by testing
for multiples of 4kHz instead.

Signed-off-by: Nikesh Oswal <Nikesh.Oswal@cirrus.com>
Signed-off-by: Charles Keepax <ckeepax@opensource.wolfsonmicro.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 sound/soc/codecs/arizona.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sound/soc/codecs/arizona.c b/sound/soc/codecs/arizona.c
index 29e198f57d4c..131fc593a4e8 100644
--- a/sound/soc/codecs/arizona.c
+++ b/sound/soc/codecs/arizona.c
@@ -1188,7 +1188,7 @@ static int arizona_hw_params(struct snd_pcm_substream *substream,
 	int chan_limit = arizona->pdata.max_channels_clocked[dai->id - 1];
 	int bclk, lrclk, wl, frame, bclk_target;
 
-	if (params_rate(params) % 8000)
+	if (params_rate(params) % 4000)
 		rates = &arizona_44k1_bclk_rates[0];
 	else
 		rates = &arizona_48k_bclk_rates[0];

[toc] | [prev] | [next] | [standalone]


#1316024 — [PATCH 3.16.y-ckt 071/128] powerpc/powernv: Fix the overflow of OPAL message notifiers head array

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 071/128] powerpc/powernv: Fix the overflow of OPAL message notifiers head array
Message-ID<qUB1c-2KY-85@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Neelesh Gupta <neelegup@linux.vnet.ibm.com>

commit 792f96e9a769b799a2944e9369e4ea1e467135b2 upstream.

Fixes the condition check of incoming message type which can
otherwise shoot beyond the message notifiers head array.

Signed-off-by: Neelesh Gupta <neelegup@linux.vnet.ibm.com>
Reviewed-by: Vasant Hegde <hegdevasant@linux.vnet.ibm.com>
Reviewed-by: Anshuman Khandual <khandual@linux.vnet.ibm.com>
Signed-off-by: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 arch/powerpc/platforms/powernv/opal.c | 12 ++++--------
 1 file changed, 4 insertions(+), 8 deletions(-)

diff --git a/arch/powerpc/platforms/powernv/opal.c b/arch/powerpc/platforms/powernv/opal.c
index 199975613fe9..d5e5794db989 100644
--- a/arch/powerpc/platforms/powernv/opal.c
+++ b/arch/powerpc/platforms/powernv/opal.c
@@ -286,16 +286,12 @@ void opal_notifier_disable(void)
 int opal_message_notifier_register(enum OpalMessageType msg_type,
 					struct notifier_block *nb)
 {
-	if (!nb) {
-		pr_warning("%s: Invalid argument (%p)\n",
-			   __func__, nb);
-		return -EINVAL;
-	}
-	if (msg_type > OPAL_MSG_TYPE_MAX) {
-		pr_warning("%s: Invalid message type argument (%d)\n",
+	if (!nb || msg_type >= OPAL_MSG_TYPE_MAX) {
+		pr_warning("%s: Invalid arguments, msg_type:%d\n",
 			   __func__, msg_type);
 		return -EINVAL;
 	}
+
 	return atomic_notifier_chain_register(
 				&opal_msg_notifier_head[msg_type], nb);
 }
@@ -332,7 +328,7 @@ static void opal_handle_message(void)
 	type = be32_to_cpu(msg.msg_type);
 
 	/* Sanity check */
-	if (type > OPAL_MSG_TYPE_MAX) {
+	if (type >= OPAL_MSG_TYPE_MAX) {
 		pr_warning("%s: Unknown message type: %u\n", __func__, type);
 		return;
 	}

[toc] | [prev] | [next] | [standalone]


#1316026 — [PATCH 3.16.y-ckt 067/128] spi: fix parent-device reference leak

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 067/128] spi: fix parent-device reference leak
Message-ID<qUB1d-2KY-95@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Johan Hovold <johan@kernel.org>

commit 157f38f993919b648187ba341bfb05d0e91ad2f6 upstream.

Fix parent-device reference leak due to SPI-core taking an unnecessary
reference to the parent when allocating the master structure, a
reference that was never released.

Note that driver core takes its own reference to the parent when the
master device is registered.

Fixes: 49dce689ad4e ("spi doesn't need class_device")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/spi/spi.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/spi/spi.c b/drivers/spi/spi.c
index 8f2c442eb1e1..f8e4ca6be300 100644
--- a/drivers/spi/spi.c
+++ b/drivers/spi/spi.c
@@ -1475,7 +1475,7 @@ struct spi_master *spi_alloc_master(struct device *dev, unsigned size)
 	master->bus_num = -1;
 	master->num_chipselect = 1;
 	master->dev.class = &spi_master_class;
-	master->dev.parent = get_device(dev);
+	master->dev.parent = dev;
 	spi_master_set_devdata(master, &master[1]);
 
 	return master;

[toc] | [prev] | [next] | [standalone]


#1316027 — [PATCH 3.16.y-ckt 011/128] sata_sil: disable trim

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:10 +0100
Subject[PATCH 3.16.y-ckt 011/128] sata_sil: disable trim
Message-ID<qUB1e-2KY-99@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Mikulas Patocka <mpatocka@redhat.com>

commit d98f1cd0a3b70ea91f1dfda3ac36c3b2e1a4d5e2 upstream.

When I connect an Intel SSD to SATA SIL controller (PCI ID 1095:3114), any
TRIM command results in I/O errors being reported in the log. There is
other similar error reported with TRIM and the SIL controller:
https://bugs.centos.org/view.php?id=5880

Apparently the controller doesn't support TRIM commands. This patch
disables TRIM support on the SATA SIL controller.

ata7.00: exception Emask 0x0 SAct 0x0 SErr 0x0 action 0x0
ata7.00: BMDMA2 stat 0x50001
ata7.00: failed command: DATA SET MANAGEMENT
ata7.00: cmd 06/01:01:00:00:00/00:00:00:00:00/a0 tag 0 dma 512 out
         res 51/04:01:00:00:00/00:00:00:00:00/a0 Emask 0x1 (device error)
ata7.00: status: { DRDY ERR }
ata7.00: error: { ABRT }
ata7.00: device reported invalid CHS sector 0
sd 8:0:0:0: [sdb] tag#0 FAILED Result: hostbyte=DID_OK driverbyte=DRIVER_SENSE
sd 8:0:0:0: [sdb] tag#0 Sense Key : Illegal Request [current] [descriptor]
sd 8:0:0:0: [sdb] tag#0 Add. Sense: Unaligned write command
sd 8:0:0:0: [sdb] tag#0 CDB: Write same(16) 93 08 00 00 00 00 00 21 95 88 00 20 00 00 00 00
blk_update_request: I/O error, dev sdb, sector 2200968

Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/ata/sata_sil.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/ata/sata_sil.c b/drivers/ata/sata_sil.c
index 40b76b2d18c6..1fd6873d28c3 100644
--- a/drivers/ata/sata_sil.c
+++ b/drivers/ata/sata_sil.c
@@ -630,6 +630,9 @@ static void sil_dev_config(struct ata_device *dev)
 	unsigned int n, quirks = 0;
 	unsigned char model_num[ATA_ID_PROD_LEN + 1];
 
+	/* This controller doesn't support trim */
+	dev->horkage |= ATA_HORKAGE_NOTRIM;
+
 	ata_id_c_string(dev->id, model_num, ATA_ID_PROD, sizeof(model_num));
 
 	for (n = 0; sil_blacklist[n].product; n++)

[toc] | [prev] | [next] | [standalone]


#1316028 — [PATCH 3.16.y-ckt 114/128] genirq: Prevent chip buslock deadlock

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:20 +0100
Subject[PATCH 3.16.y-ckt 114/128] genirq: Prevent chip buslock deadlock
Message-ID<qUBaN-2PO-1@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Thomas Gleixner <tglx@linutronix.de>

commit abc7e40c81d113ef4bacb556f0a77ca63ac81d85 upstream.

If a interrupt chip utilizes chip->buslock then free_irq() can
deadlock in the following way:

CPU0				CPU1
				interrupt(X) (Shared or spurious)
free_irq(X)			interrupt_thread(X)
chip_bus_lock(X)
				   irq_finalize_oneshot(X)
				     chip_bus_lock(X)
synchronize_irq(X)

synchronize_irq() waits for the interrupt thread to complete,
i.e. forever.

Solution is simple: Drop chip_bus_lock() before calling
synchronize_irq() as we do with the irq_desc lock. There is nothing to
be protected after the point where irq_desc lock has been released.

This adds chip_bus_lock/unlock() to the remove_irq() code path, but
that's actually correct in the case where remove_irq() is called on
such an interrupt. The current users of remove_irq() are not affected
as none of those interrupts is on a chip which requires buslock.

Reported-by: Fredrik Markström <fredrik.markstrom@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 kernel/irq/manage.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/kernel/irq/manage.c b/kernel/irq/manage.c
index 3dc6a61bf06a..efd80f0af47f 100644
--- a/kernel/irq/manage.c
+++ b/kernel/irq/manage.c
@@ -1311,6 +1311,7 @@ static struct irqaction *__free_irq(unsigned int irq, void *dev_id)
 	if (!desc)
 		return NULL;
 
+	chip_bus_lock(desc);
 	raw_spin_lock_irqsave(&desc->lock, flags);
 
 	/*
@@ -1324,7 +1325,7 @@ static struct irqaction *__free_irq(unsigned int irq, void *dev_id)
 		if (!action) {
 			WARN(1, "Trying to free already-free IRQ %d\n", irq);
 			raw_spin_unlock_irqrestore(&desc->lock, flags);
-
+			chip_bus_sync_unlock(desc);
 			return NULL;
 		}
 
@@ -1349,6 +1350,7 @@ static struct irqaction *__free_irq(unsigned int irq, void *dev_id)
 #endif
 
 	raw_spin_unlock_irqrestore(&desc->lock, flags);
+	chip_bus_sync_unlock(desc);
 
 	unregister_handler_proc(irq, action);
 
@@ -1422,9 +1424,7 @@ void free_irq(unsigned int irq, void *dev_id)
 		desc->affinity_notify = NULL;
 #endif
 
-	chip_bus_lock(desc);
 	kfree(__free_irq(irq, dev_id));
-	chip_bus_sync_unlock(desc);
 }
 EXPORT_SYMBOL(free_irq);
 

[toc] | [prev] | [next] | [standalone]


#1316029 — [PATCH 3.16.y-ckt 093/128] net: fix warnings in 'make htmldocs' by moving macro definition out of field declaration

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:20 +0100
Subject[PATCH 3.16.y-ckt 093/128] net: fix warnings in 'make htmldocs' by moving macro definition out of field declaration
Message-ID<qUBaO-2PO-3@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Hannes Frederic Sowa <hannes@stressinduktion.org>

commit 7bbadd2d1009575dad675afc16650ebb5aa10612 upstream.

Docbook does not like the definition of macros inside a field declaration
and adds a warning. Move the definition out.

Fixes: 79462ad02e86180 ("net: add validation for the socket syscall protocol argument")
Reported-by: kbuild test robot <lkp@intel.com>
Signed-off-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 include/net/sock.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/net/sock.h b/include/net/sock.h
index dd06b32abea3..2b2960fcc878 100644
--- a/include/net/sock.h
+++ b/include/net/sock.h
@@ -376,8 +376,8 @@ struct sock {
 				sk_no_check_rx : 1,
 				sk_userlocks : 4,
 				sk_protocol  : 8,
-#define SK_PROTOCOL_MAX U8_MAX
 				sk_type      : 16;
+#define SK_PROTOCOL_MAX U8_MAX
 	kmemcheck_bitfield_end(flags);
 	int			sk_wmem_queued;
 	gfp_t			sk_allocation;

[toc] | [prev] | [next] | [standalone]


#1316030 — [PATCH 3.16.y-ckt 112/128] ipv6/addrlabel: fix ip6addrlbl_get()

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:20 +0100
Subject[PATCH 3.16.y-ckt 112/128] ipv6/addrlabel: fix ip6addrlbl_get()
Message-ID<qUBaO-2PO-5@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Andrey Ryabinin <aryabinin@virtuozzo.com>

commit e459dfeeb64008b2d23bdf600f03b3605dbb8152 upstream.

ip6addrlbl_get() has never worked. If ip6addrlbl_hold() succeeded,
ip6addrlbl_get() will exit with '-ESRCH'. If ip6addrlbl_hold() failed,
ip6addrlbl_get() will use about to be free ip6addrlbl_entry pointer.

Fix this by inverting ip6addrlbl_hold() check.

Fixes: 2a8cc6c89039 ("[IPV6] ADDRCONF: Support RFC3484 configurable address selection policy table.")
Signed-off-by: Andrey Ryabinin <aryabinin@virtuozzo.com>
Reviewed-by: Cong Wang <cwang@twopensource.com>
Acked-by: YOSHIFUJI Hideaki <yoshfuji@linux-ipv6.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/ipv6/addrlabel.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/ipv6/addrlabel.c b/net/ipv6/addrlabel.c
index 731e1e1722d9..eb525d5908c3 100644
--- a/net/ipv6/addrlabel.c
+++ b/net/ipv6/addrlabel.c
@@ -558,7 +558,7 @@ static int ip6addrlbl_get(struct sk_buff *in_skb, struct nlmsghdr *nlh)
 
 	rcu_read_lock();
 	p = __ipv6_addr_label(net, addr, ipv6_addr_type(addr), ifal->ifal_index);
-	if (p && ip6addrlbl_hold(p))
+	if (p && !ip6addrlbl_hold(p))
 		p = NULL;
 	lseq = ip6addrlbl_table.seq;
 	rcu_read_unlock();

[toc] | [prev] | [next] | [standalone]


#1316031 — [PATCH 3.16.y-ckt 091/128] qlcnic: fix a timeout loop

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:20 +0100
Subject[PATCH 3.16.y-ckt 091/128] qlcnic: fix a timeout loop
Message-ID<qUBaO-2PO-9@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Dan Carpenter <dan.carpenter@oracle.com>

commit 389e4e04ad2d4887c7bdd7c01a93d3dfa5c14a06 upstream.

The problem here is that at the end of the loop we test for if
idc->vnic_wait_limit is zero, but since idc->vnic_wait_limit-- is a
post-op, it actually ends up set to (u8)-1.  I have fixed this by
moving the decrement inside the loop.

Fixes: 486a5bc77a4a ('qlcnic: Add support for 83xx suspend and resume.')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/net/ethernet/qlogic/qlcnic/qlcnic_83xx_vnic.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/qlogic/qlcnic/qlcnic_83xx_vnic.c b/drivers/net/ethernet/qlogic/qlcnic/qlcnic_83xx_vnic.c
index be7d7a62cc0d..b1a452f291ee 100644
--- a/drivers/net/ethernet/qlogic/qlcnic/qlcnic_83xx_vnic.c
+++ b/drivers/net/ethernet/qlogic/qlcnic/qlcnic_83xx_vnic.c
@@ -246,7 +246,8 @@ int qlcnic_83xx_check_vnic_state(struct qlcnic_adapter *adapter)
 	u32 state;
 
 	state = QLCRDX(ahw, QLC_83XX_VNIC_STATE);
-	while (state != QLCNIC_DEV_NPAR_OPER && idc->vnic_wait_limit--) {
+	while (state != QLCNIC_DEV_NPAR_OPER && idc->vnic_wait_limit) {
+		idc->vnic_wait_limit--;
 		msleep(1000);
 		state = QLCRDX(ahw, QLC_83XX_VNIC_STATE);
 	}

[toc] | [prev] | [next] | [standalone]


#1316032 — [PATCH 3.16.y-ckt 097/128] KVM: PPC: Book3S HV: Prohibit setting illegal transaction state in MSR

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:20 +0100
Subject[PATCH 3.16.y-ckt 097/128] KVM: PPC: Book3S HV: Prohibit setting illegal transaction state in MSR
Message-ID<qUBaO-2PO-7@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Paul Mackerras <paulus@ozlabs.org>

commit c20875a3e638e4a03e099b343ec798edd1af5cc6 upstream.

Currently it is possible for userspace (e.g. QEMU) to set a value
for the MSR for a guest VCPU which has both of the TS bits set,
which is an illegal combination.  The result of this is that when
we execute a hrfid (hypervisor return from interrupt doubleword)
instruction to enter the guest, the CPU will take a TM Bad Thing
type of program interrupt (vector 0x700).

Now, if PR KVM is configured in the kernel along with HV KVM, we
actually handle this without crashing the host or giving hypervisor
privilege to the guest; instead what happens is that we deliver a
program interrupt to the guest, with SRR0 reflecting the address
of the hrfid instruction and SRR1 containing the MSR value at that
point.  If PR KVM is not configured in the kernel, then we try to
run the host's program interrupt handler with the MMU set to the
guest context, which almost certainly causes a host crash.

This closes the hole by making kvmppc_set_msr_hv() check for the
illegal combination and force the TS field to a safe value (00,
meaning non-transactional).

Signed-off-by: Paul Mackerras <paulus@samba.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 arch/powerpc/kvm/book3s_hv.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/arch/powerpc/kvm/book3s_hv.c b/arch/powerpc/kvm/book3s_hv.c
index 0f3a19237444..89d4ebd8152b 100644
--- a/arch/powerpc/kvm/book3s_hv.c
+++ b/arch/powerpc/kvm/book3s_hv.c
@@ -166,6 +166,12 @@ static void kvmppc_core_vcpu_put_hv(struct kvm_vcpu *vcpu)
 
 static void kvmppc_set_msr_hv(struct kvm_vcpu *vcpu, u64 msr)
 {
+	/*
+	 * Check for illegal transactional state bit combination
+	 * and if we find it, force the TS field to a safe state.
+	 */
+	if ((msr & MSR_TS_MASK) == MSR_TS_MASK)
+		msr &= ~MSR_TS_MASK;
 	vcpu->arch.shregs.msr = msr;
 	kvmppc_end_cede(vcpu);
 }

[toc] | [prev] | [next] | [standalone]


#1316033 — [PATCH 3.16.y-ckt 107/128] [PATCH] arm: fix handling of F_OFD_... in oabi_fcntl64()

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:20 +0100
Subject[PATCH 3.16.y-ckt 107/128] [PATCH] arm: fix handling of F_OFD_... in oabi_fcntl64()
Message-ID<qUBaO-2PO-13@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Al Viro <viro@zeniv.linux.org.uk>

commit 76cc404bfdc0d419c720de4daaf2584542734f42 upstream.

Reviewed-by: Jeff Layton <jeff.layton@primarydata.com>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 arch/arm/kernel/sys_oabi-compat.c | 73 ++++++++++++++++++++-------------------
 1 file changed, 37 insertions(+), 36 deletions(-)

diff --git a/arch/arm/kernel/sys_oabi-compat.c b/arch/arm/kernel/sys_oabi-compat.c
index e90a3148f385..eb821e7b80f9 100644
--- a/arch/arm/kernel/sys_oabi-compat.c
+++ b/arch/arm/kernel/sys_oabi-compat.c
@@ -193,15 +193,44 @@ struct oabi_flock64 {
 	pid_t	l_pid;
 } __attribute__ ((packed,aligned(4)));
 
-asmlinkage long sys_oabi_fcntl64(unsigned int fd, unsigned int cmd,
+static long do_locks(unsigned int fd, unsigned int cmd,
 				 unsigned long arg)
 {
-	struct oabi_flock64 user;
 	struct flock64 kernel;
-	mm_segment_t fs = USER_DS; /* initialized to kill a warning */
-	unsigned long local_arg = arg;
-	int ret;
+	struct oabi_flock64 user;
+	mm_segment_t fs;
+	long ret;
+
+	if (copy_from_user(&user, (struct oabi_flock64 __user *)arg,
+			   sizeof(user)))
+		return -EFAULT;
+	kernel.l_type	= user.l_type;
+	kernel.l_whence	= user.l_whence;
+	kernel.l_start	= user.l_start;
+	kernel.l_len	= user.l_len;
+	kernel.l_pid	= user.l_pid;
+
+	fs = get_fs();
+	set_fs(KERNEL_DS);
+	ret = sys_fcntl64(fd, cmd, (unsigned long)&kernel);
+	set_fs(fs);
+
+	if (!ret && (cmd == F_GETLK64 || cmd == F_OFD_GETLK)) {
+		user.l_type	= kernel.l_type;
+		user.l_whence	= kernel.l_whence;
+		user.l_start	= kernel.l_start;
+		user.l_len	= kernel.l_len;
+		user.l_pid	= kernel.l_pid;
+		if (copy_to_user((struct oabi_flock64 __user *)arg,
+				 &user, sizeof(user)))
+			ret = -EFAULT;
+	}
+	return ret;
+}
 
+asmlinkage long sys_oabi_fcntl64(unsigned int fd, unsigned int cmd,
+				 unsigned long arg)
+{
 	switch (cmd) {
 	case F_OFD_GETLK:
 	case F_OFD_SETLK:
@@ -209,39 +238,11 @@ asmlinkage long sys_oabi_fcntl64(unsigned int fd, unsigned int cmd,
 	case F_GETLK64:
 	case F_SETLK64:
 	case F_SETLKW64:
-		if (copy_from_user(&user, (struct oabi_flock64 __user *)arg,
-				   sizeof(user)))
-			return -EFAULT;
-		kernel.l_type	= user.l_type;
-		kernel.l_whence	= user.l_whence;
-		kernel.l_start	= user.l_start;
-		kernel.l_len	= user.l_len;
-		kernel.l_pid	= user.l_pid;
-		local_arg = (unsigned long)&kernel;
-		fs = get_fs();
-		set_fs(KERNEL_DS);
-	}
-
-	ret = sys_fcntl64(fd, cmd, local_arg);
+		return do_locks(fd, cmd, arg);
 
-	switch (cmd) {
-	case F_GETLK64:
-		if (!ret) {
-			user.l_type	= kernel.l_type;
-			user.l_whence	= kernel.l_whence;
-			user.l_start	= kernel.l_start;
-			user.l_len	= kernel.l_len;
-			user.l_pid	= kernel.l_pid;
-			if (copy_to_user((struct oabi_flock64 __user *)arg,
-					 &user, sizeof(user)))
-				ret = -EFAULT;
-		}
-	case F_SETLK64:
-	case F_SETLKW64:
-		set_fs(fs);
+	default:
+		return sys_fcntl64(fd, cmd, arg);
 	}
-
-	return ret;
 }
 
 struct oabi_epoll_event {

[toc] | [prev] | [next] | [standalone]


#1316034 — [PATCH 3.16.y-ckt 087/128] net: phy: mdio-mux: Check return value of mdiobus_alloc()

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:20 +0100
Subject[PATCH 3.16.y-ckt 087/128] net: phy: mdio-mux: Check return value of mdiobus_alloc()
Message-ID<qUBaO-2PO-17@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Tobias Klauser <tklauser@distanz.ch>

commit 20b08e1a793d898f0f13040d5418ee0955f678cf upstream.

mdiobus_alloc() might return NULL, but its return value is not
checked in mdio_mux_init(). This could potentially lead to a NULL
pointer dereference. Fix it by checking the return value

Fixes: 0ca2997d1452 ("netdev/of/phy: Add MDIO bus multiplexer support.")
Signed-off-by: Tobias Klauser <tklauser@distanz.ch>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/net/phy/mdio-mux.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/net/phy/mdio-mux.c b/drivers/net/phy/mdio-mux.c
index 4d4d25efc1e1..ac8a82371f3b 100644
--- a/drivers/net/phy/mdio-mux.c
+++ b/drivers/net/phy/mdio-mux.c
@@ -148,9 +148,14 @@ int mdio_mux_init(struct device *dev,
 		}
 		cb->bus_number = v;
 		cb->parent = pb;
+
 		cb->mii_bus = mdiobus_alloc();
+		if (!cb->mii_bus) {
+			ret_val = -ENOMEM;
+			of_node_put(child_bus_node);
+			break;
+		}
 		cb->mii_bus->priv = cb;
-
 		cb->mii_bus->irq = cb->phy_irq;
 		cb->mii_bus->name = "mdio_mux";
 		snprintf(cb->mii_bus->id, MII_BUS_ID_SIZE, "%x.%x",

[toc] | [prev] | [next] | [standalone]


#1316035 — [PATCH 3.16.y-ckt 092/128] ser_gigaset: fix deallocation of platform device structure

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:20 +0100
Subject[PATCH 3.16.y-ckt 092/128] ser_gigaset: fix deallocation of platform device structure
Message-ID<qUBaO-2PO-11@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Tilman Schmidt <tilman@imap.cc>

commit 4c5e354a974214dfb44cd23fa0429327693bc3ea upstream.

When shutting down the device, the struct ser_cardstate must not be
kfree()d immediately after the call to platform_device_unregister()
since the embedded struct platform_device is still in use.
Move the kfree() call to the release method instead.

Signed-off-by: Tilman Schmidt <tilman@imap.cc>
Fixes: 2869b23e4b95 ("drivers/isdn/gigaset: new M101 driver (v2)")
Reported-by: Sasha Levin <sasha.levin@oracle.com>
Signed-off-by: Paul Bolle <pebolle@tiscali.nl>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/isdn/gigaset/ser-gigaset.c | 10 +++++++---
 1 file changed, 7 insertions(+), 3 deletions(-)

diff --git a/drivers/isdn/gigaset/ser-gigaset.c b/drivers/isdn/gigaset/ser-gigaset.c
index 3ac9c4194814..0ebb52b0336d 100644
--- a/drivers/isdn/gigaset/ser-gigaset.c
+++ b/drivers/isdn/gigaset/ser-gigaset.c
@@ -370,19 +370,23 @@ static void gigaset_freecshw(struct cardstate *cs)
 	tasklet_kill(&cs->write_tasklet);
 	if (!cs->hw.ser)
 		return;
-	dev_set_drvdata(&cs->hw.ser->dev.dev, NULL);
 	platform_device_unregister(&cs->hw.ser->dev);
-	kfree(cs->hw.ser);
-	cs->hw.ser = NULL;
 }
 
 static void gigaset_device_release(struct device *dev)
 {
 	struct platform_device *pdev = to_platform_device(dev);
+	struct cardstate *cs = dev_get_drvdata(dev);
 
 	/* adapted from platform_device_release() in drivers/base/platform.c */
 	kfree(dev->platform_data);
 	kfree(pdev->resource);
+
+	if (!cs)
+		return;
+	dev_set_drvdata(dev, NULL);
+	kfree(cs->hw.ser);
+	cs->hw.ser = NULL;
 }
 
 /*

[toc] | [prev] | [next] | [standalone]


#1316036 — [PATCH 3.16.y-ckt 103/128] s390/dis: Fix handling of format specifiers

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:20 +0100
Subject[PATCH 3.16.y-ckt 103/128] s390/dis: Fix handling of format specifiers
Message-ID<qUBaP-2PO-25@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Michael Holzheu <holzheu@linux.vnet.ibm.com>

commit 272fa59ccb4fc802af28b1d699c2463db6a71bf7 upstream.

The print_insn() function returns strings like "lghi %r1,0". To escape the
'%' character in sprintf() a second '%' is used. For example "lghi %%r1,0"
is converted into "lghi %r1,0".

After print_insn() the output string is passed to printk(). Because format
specifiers like "%r" or "%f" are ignored by printk() this works by chance
most of the time. But for instructions with control registers like
"lctl %c6,%c6,780" this fails because printk() interprets "%c" as
character format specifier.

Fix this problem and escape the '%' characters twice.

For example "lctl %%%%c6,%%%%c6,780" is then converted by sprintf()
into "lctl %%c6,%%c6,780" and by printk() into "lctl %c6,%c6,780".

Signed-off-by: Michael Holzheu <holzheu@linux.vnet.ibm.com>
Signed-off-by: Martin Schwidefsky <schwidefsky@de.ibm.com>
[ luis: backported to 3.16:
  - drop condition with OPERAND_VR introduced only with commit
    3585cb028065 ("s390/disassembler: add vector instructions") ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 arch/s390/kernel/dis.c | 15 +++++++++++----
 1 file changed, 11 insertions(+), 4 deletions(-)

diff --git a/arch/s390/kernel/dis.c b/arch/s390/kernel/dis.c
index 993efe6a887c..3d942314818b 100644
--- a/arch/s390/kernel/dis.c
+++ b/arch/s390/kernel/dis.c
@@ -1726,14 +1726,21 @@ static int print_insn(char *buffer, unsigned char *code, unsigned long addr)
 			}
 			if (separator)
 				ptr += sprintf(ptr, "%c", separator);
+			/*
+			 * Use four '%' characters below because of the
+			 * following two conversions:
+			 *
+			 *  1) sprintf: %%%%r -> %%r
+			 *  2) printk : %%r   -> %r
+			 */
 			if (operand->flags & OPERAND_GPR)
-				ptr += sprintf(ptr, "%%r%i", value);
+				ptr += sprintf(ptr, "%%%%r%i", value);
 			else if (operand->flags & OPERAND_FPR)
-				ptr += sprintf(ptr, "%%f%i", value);
+				ptr += sprintf(ptr, "%%%%f%i", value);
 			else if (operand->flags & OPERAND_AR)
-				ptr += sprintf(ptr, "%%a%i", value);
+				ptr += sprintf(ptr, "%%%%a%i", value);
 			else if (operand->flags & OPERAND_CR)
-				ptr += sprintf(ptr, "%%c%i", value);
+				ptr += sprintf(ptr, "%%%%c%i", value);
 			else if (operand->flags & OPERAND_PCREL)
 				ptr += sprintf(ptr, "%lx", (signed int) value
 								      + addr);

[toc] | [prev] | [next] | [standalone]


#1316037 — [PATCH 3.16.y-ckt 108/128] ocfs2: fix BUG when calculate new backup super

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:20 +0100
Subject[PATCH 3.16.y-ckt 108/128] ocfs2: fix BUG when calculate new backup super
Message-ID<qUBaO-2PO-23@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Joseph Qi <joseph.qi@huawei.com>

commit 5c9ee4cbf2a945271f25b89b137f2c03bbc3be33 upstream.

When resizing, it firstly extends the last gd.  Once it should backup
super in the gd, it calculates new backup super and update the
corresponding value.

But it currently doesn't consider the situation that the backup super is
already done.  And in this case, it still sets the bit in gd bitmap and
then decrease from bg_free_bits_count, which leads to a corrupted gd and
trigger the BUG in ocfs2_block_group_set_bits:

    BUG_ON(le16_to_cpu(bg->bg_free_bits_count) < num_bits);

So check whether the backup super is done and then do the updates.

Signed-off-by: Joseph Qi <joseph.qi@huawei.com>
Reviewed-by: Jiufei Xue <xuejiufei@huawei.com>
Reviewed-by: Yiwen Jiang <jiangyiwen@huawei.com>
Cc: Mark Fasheh <mfasheh@suse.de>
Cc: Joel Becker <jlbec@evilplan.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 fs/ocfs2/resize.c | 15 ++++++++++++---
 1 file changed, 12 insertions(+), 3 deletions(-)

diff --git a/fs/ocfs2/resize.c b/fs/ocfs2/resize.c
index d5da6f624142..79b8021302b3 100644
--- a/fs/ocfs2/resize.c
+++ b/fs/ocfs2/resize.c
@@ -54,11 +54,12 @@
 static u16 ocfs2_calc_new_backup_super(struct inode *inode,
 				       struct ocfs2_group_desc *gd,
 				       u16 cl_cpg,
+				       u16 old_bg_clusters,
 				       int set)
 {
 	int i;
 	u16 backups = 0;
-	u32 cluster;
+	u32 cluster, lgd_cluster;
 	u64 blkno, gd_blkno, lgd_blkno = le64_to_cpu(gd->bg_blkno);
 
 	for (i = 0; i < OCFS2_MAX_BACKUP_SUPERBLOCKS; i++) {
@@ -71,6 +72,12 @@ static u16 ocfs2_calc_new_backup_super(struct inode *inode,
 		else if (gd_blkno > lgd_blkno)
 			break;
 
+		/* check if already done backup super */
+		lgd_cluster = ocfs2_blocks_to_clusters(inode->i_sb, lgd_blkno);
+		lgd_cluster += old_bg_clusters;
+		if (lgd_cluster >= cluster)
+			continue;
+
 		if (set)
 			ocfs2_set_bit(cluster % cl_cpg,
 				      (unsigned long *)gd->bg_bitmap);
@@ -99,6 +106,7 @@ static int ocfs2_update_last_group_and_inode(handle_t *handle,
 	u16 chain, num_bits, backups = 0;
 	u16 cl_bpc = le16_to_cpu(cl->cl_bpc);
 	u16 cl_cpg = le16_to_cpu(cl->cl_cpg);
+	u16 old_bg_clusters;
 
 	trace_ocfs2_update_last_group_and_inode(new_clusters,
 						first_new_cluster);
@@ -112,6 +120,7 @@ static int ocfs2_update_last_group_and_inode(handle_t *handle,
 
 	group = (struct ocfs2_group_desc *)group_bh->b_data;
 
+	old_bg_clusters = le16_to_cpu(group->bg_bits) / cl_bpc;
 	/* update the group first. */
 	num_bits = new_clusters * cl_bpc;
 	le16_add_cpu(&group->bg_bits, num_bits);
@@ -125,7 +134,7 @@ static int ocfs2_update_last_group_and_inode(handle_t *handle,
 				     OCFS2_FEATURE_COMPAT_BACKUP_SB)) {
 		backups = ocfs2_calc_new_backup_super(bm_inode,
 						     group,
-						     cl_cpg, 1);
+						     cl_cpg, old_bg_clusters, 1);
 		le16_add_cpu(&group->bg_free_bits_count, -1 * backups);
 	}
 
@@ -163,7 +172,7 @@ out_rollback:
 	if (ret < 0) {
 		ocfs2_calc_new_backup_super(bm_inode,
 					    group,
-					    cl_cpg, 0);
+					    cl_cpg, old_bg_clusters, 0);
 		le16_add_cpu(&group->bg_free_bits_count, backups);
 		le16_add_cpu(&group->bg_bits, -1 * num_bits);
 		le16_add_cpu(&group->bg_free_bits_count, -1 * num_bits);

[toc] | [prev] | [next] | [standalone]


#1316038 — [PATCH 3.16.y-ckt 084/128] USB: ipaq.c: fix a timeout loop

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-01-24 23:20 +0100
Subject[PATCH 3.16.y-ckt 084/128] USB: ipaq.c: fix a timeout loop
Message-ID<qUBaP-2PO-27@gated-at.bofh.it>
In reply to#1315999
3.16.7-ckt23 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Dan Carpenter <dan.carpenter@oracle.com>

commit abdc9a3b4bac97add99e1d77dc6d28623afe682b upstream.

The code expects the loop to end with "retries" set to zero but, because
it is a post-op, it will end set to -1.  I have fixed this by moving the
decrement inside the loop.

Fixes: 014aa2a3c32e ('USB: ipaq: minor ipaq_open() cleanup.')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/usb/serial/ipaq.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/usb/serial/ipaq.c b/drivers/usb/serial/ipaq.c
index f51a5d52c0ed..ec1b8f2c1183 100644
--- a/drivers/usb/serial/ipaq.c
+++ b/drivers/usb/serial/ipaq.c
@@ -531,7 +531,8 @@ static int ipaq_open(struct tty_struct *tty,
 	 * through. Since this has a reasonably high failure rate, we retry
 	 * several times.
 	 */
-	while (retries--) {
+	while (retries) {
+		retries--;
 		result = usb_control_msg(serial->dev,
 				usb_sndctrlpipe(serial->dev, 0), 0x22, 0x21,
 				0x1, 0, NULL, 0, 100);

[toc] | [prev] | [next] | [standalone]


Page 2 of 7 — ← Prev page 1 [2] 3 4 5 6 7  Next page →

Back to top | Article view | linux.kernel


csiph-web