Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1319455 > unrolled thread

[PATCH 3.14 00/59] 3.14.60-stable review

Started byGreg Kroah-Hartman <gregkh@linuxfoundation.org>
First post2016-01-27 20:30 +0100
Last post2016-01-27 21:10 +0100
Articles 20 on this page of 51 — 1 participant

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.14 00/59] 3.14.60-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 18/59] ALSA: timer: Fix double unlink of active_list Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 42/59] ipv6: update skb->csum when CE mark is propagated Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 45/59] team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 05/59] x86/reboot/quirks: Add iMac10,1 to pci_reboot_dmi_table[] Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 08/59] ALSA: hda - Add Intel Lewisburg device IDs Audio Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 22/59] ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 02/59] xen/gntdev: Grant maps should not be subject to NUMA balancing Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 03/59] x86/xen: dont reset vcpu_info on a cancelled suspend Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 27/59] usb: xhci: fix config fail of FS hub behind a HS hub with MTT Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 26/59] ASoC: compress: Fix compress device direction check Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 24/59] ASoC: wm8974: set cache type for regmap Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 40/59] bonding: Prevent IPv6 link local address on enslaved devices Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 21/59] ALSA: hrtimer: Fix stall by hrtimer_cancel() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 07/59] ipmi: move timer init to before irq is setup Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 41/59] phonet: properly unshare skbs in phonet_rcv() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 04/59] KVM: PPC: Book3S HV: Prohibit setting illegal transaction state in MSR Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 20/59] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 28/59] USB: ipaq.c: fix a timeout loop Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 30/59] xhci: refuse loading if nousb is used Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 52/59] arm64: fix building without CONFIG_UID16 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 19/59] ALSA: seq: Fix snd_seq_call_port_info_ioctl in compat mode Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 09/59] ALSA: hda - Apply pin fixup for HP ProBook 6550b Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 53/59] arm64: Clear out any singlestep state on a ptrace detach operation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 49/59] powerpc: Make {cmp}xchg* and their atomic_ versions fully ordered Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 43/59] isdn_ppp: Add checks for allocation failure in isdn_ppp_open() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 39/59] tcp_yeah: dont set ssthresh below 2 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 46/59] powerpc/tm: Block signal return setting invalid MSR state Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 06/59] x86/boot: Double BOOT_HEAP_SIZE to 64KB Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 51/59] arm64: KVM: Fix AArch32 to AArch64 register mapping Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:30 +0100
    [PATCH 3.14 11/59] ALSA: hda - Add inverted dmic for Packard Bell DOTS Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:40 +0100
    [PATCH 3.14 14/59] ALSA: seq: Fix missing NULL check at remove_events ioctl Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:40 +0100
    [PATCH 3.14 23/59] ASoC: wm8962: correct addresses for HPF_C_0/1 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:40 +0100
    [PATCH 3.14 16/59] ALSA: timer: Harden slave timer list handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:40 +0100
    [PATCH 3.14 17/59] ALSA: timer: Fix race among timer ioctls Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:40 +0100
    [PATCH 3.14 25/59] ASoC: arizona: Fix bclk for sample rates that are multiple of 4kHz Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:40 +0100
    [PATCH 3.14 10/59] ALSA: rme96: Fix unexpected volume reset after rate changes Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:40 +0100
    [PATCH 3.14 13/59] ALSA: hda/realtek - Fix silent headphone output on MacPro 4,1 (v2) Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:40 +0100
    [PATCH 3.14 01/59] x86/signal: Fix restart_syscall number for x32 tasks Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:40 +0100
    [PATCH 3.14 12/59] ALSA: hda - Set SKL+ hda controller power at freeze() and thaw() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:40 +0100
    [PATCH 3.14 15/59] ALSA: seq: Fix race at timer setup and close Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 20:40 +0100
    [PATCH 3.14 32/59] ipv6/addrlabel: fix ip6addrlbl_get() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 21:00 +0100
    [PATCH 3.14 59/59] arm64: restore bogomips information in /proc/cpuinfo Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 21:00 +0100
    [PATCH 3.14 38/59] net: sctp: prevent writes to cookie_hmac_alg from accessing invalid memory Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 21:00 +0100
    [PATCH 3.14 29/59] USB: cp210x: add ID for ELV Marble Sound Board 1 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 21:10 +0100
    [PATCH 3.14 35/59] unix: properly account for FDs passed over unix sockets Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 21:10 +0100
    [PATCH 3.14 34/59] connector: bump skb->users before callback invocation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 21:10 +0100
    [PATCH 3.14 36/59] bridge: Only call /sbin/bridge-stp for the initial network namespace Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 21:10 +0100
    [PATCH 3.14 58/59] mn10300: Select CONFIG_HAVE_UID16 to fix build failure Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 21:10 +0100
    [PATCH 3.14 37/59] net: possible use after free in dst_release Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 21:10 +0100
    [PATCH 3.14 33/59] sctp: sctp should release assoc when sctp_make_abort_user return NULL in sctp_close Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-01-27 21:10 +0100

Page 1 of 3  [1] 2 3  Next page →


#1319455 — [PATCH 3.14 00/59] 3.14.60-stable review

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 00/59] 3.14.60-stable review
Message-ID<qVDNg-8kN-11@gated-at.bofh.it>
-------------------------
NOTE:
  There are still a lot of pending stable patches in the queue, well
  over 400 of them to be specific, so some of your favorite/pet patches
  might not be included in these releases.  Please be patient as I dig
  out from this backlog over the next few weeks.  If there are specific
  patches that you just _must_ have included in a stable release soon,
  please let me know.
-------------------------

This is the start of the stable review cycle for the 3.14.60 release.
There are 59 patches in this series, all will be posted as a response
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Fri Jan 29 18:06:59 UTC 2016.
Anything received after that time might be too late.

The whole patch series can be found in one patch at:
	kernel.org/pub/linux/kernel/v3.x/stable-review/patch-3.14.60-rc1.gz
and the diffstat can be found below.

thanks,

greg k-h

-------------
Pseudo-Shortlog of commits:

Greg Kroah-Hartman <gregkh@linuxfoundation.org>
    Linux 3.14.60-rc1

Yang Shi <yang.shi@linaro.org>
    arm64: restore bogomips information in /proc/cpuinfo

Guenter Roeck <linux@roeck-us.net>
    mn10300: Select CONFIG_HAVE_UID16 to fix build failure

Andrew Morton <akpm@linux-foundation.org>
    openrisc: fix CONFIG_UID16 setting

Richard Purdie <richard.purdie@linuxfoundation.org>
    HID: core: Avoid uninitialized buffer access

Mikulas Patocka <mpatocka@redhat.com>
    parisc iommu: fix panic due to trying to allocate too large region

Will Deacon <will.deacon@arm.com>
    arm64: mm: ensure that the zero page is visible to the page table walker

John Blackwood <john.blackwood@ccur.com>
    arm64: Clear out any singlestep state on a ptrace detach operation

Arnd Bergmann <arnd@arndb.de>
    arm64: fix building without CONFIG_UID16

Marc Zyngier <marc.zyngier@arm.com>
    arm64: KVM: Fix AArch32 to AArch64 register mapping

Ulrich Weigand <ulrich.weigand@de.ibm.com>
    scripts/recordmcount.pl: support data in text section on powerpc

Boqun Feng <boqun.feng@gmail.com>
    powerpc: Make {cmp}xchg* and their atomic_ versions fully ordered

Boqun Feng <boqun.feng@gmail.com>
    powerpc: Make value-returning atomics fully ordered

Michael Neuling <mikey@neuling.org>
    powerpc/tm: Check for already reclaimed tasks

Michael Neuling <mikey@neuling.org>
    powerpc/tm: Block signal return setting invalid MSR state

Ido Schimmel <idosch@mellanox.com>
    team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid

Ben Hutchings <ben@decadent.org.uk>
    ppp, slip: Validate VJ compression slot parameters completely

Ben Hutchings <ben@decadent.org.uk>
    isdn_ppp: Add checks for allocation failure in isdn_ppp_open()

Eric Dumazet <edumazet@google.com>
    ipv6: update skb->csum when CE mark is propagated

Eric Dumazet <edumazet@google.com>
    phonet: properly unshare skbs in phonet_rcv()

Karl Heiss <kheiss@gmail.com>
    bonding: Prevent IPv6 link local address on enslaved devices

Neal Cardwell <ncardwell@google.com>
    tcp_yeah: don't set ssthresh below 2

Sasha Levin <sasha.levin@oracle.com>
    net: sctp: prevent writes to cookie_hmac_alg from accessing invalid memory

Francesco Ruggeri <fruggeri@aristanetworks.com>
    net: possible use after free in dst_release

Hannes Frederic Sowa <hannes@stressinduktion.org>
    bridge: Only call /sbin/bridge-stp for the initial network namespace

willy tarreau <w@1wt.eu>
    unix: properly account for FDs passed over unix sockets

Florian Westphal <fw@strlen.de>
    connector: bump skb->users before callback invocation

Xin Long <lucien.xin@gmail.com>
    sctp: sctp should release assoc when sctp_make_abort_user return NULL in sctp_close

Andrey Ryabinin <aryabinin@virtuozzo.com>
    ipv6/addrlabel: fix ip6addrlbl_get()

Vijay Pandurangan <vijayp@vijayp.ca>
    veth: don’t modify ip_summed; doing so treats packets with bad checksums as good.

Oliver Neukum <oneukum@suse.com>
    xhci: refuse loading if nousb is used

Oliver Freyermuth <o.freyermuth@googlemail.com>
    USB: cp210x: add ID for ELV Marble Sound Board 1

Dan Carpenter <dan.carpenter@oracle.com>
    USB: ipaq.c: fix a timeout loop

Chunfeng Yun <chunfeng.yun@mediatek.com>
    usb: xhci: fix config fail of FS hub behind a HS hub with MTT

Vinod Koul <vinod.koul@intel.com>
    ASoC: compress: Fix compress device direction check

Nikesh Oswal <Nikesh.Oswal@cirrus.com>
    ASoC: arizona: Fix bclk for sample rates that are multiple of 4kHz

Mans Rullgard <mans@mansr.com>
    ASoC: wm8974: set cache type for regmap

Sachin Pandhare <sachinpandhare@gmail.com>
    ASoC: wm8962: correct addresses for HPF_C_0/1

Takashi Iwai <tiwai@suse.de>
    ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0

Takashi Iwai <tiwai@suse.de>
    ALSA: hrtimer: Fix stall by hrtimer_cancel()

Nicolas Boichat <drinkcat@chromium.org>
    ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode

Nicolas Boichat <drinkcat@chromium.org>
    ALSA: seq: Fix snd_seq_call_port_info_ioctl in compat mode

Takashi Iwai <tiwai@suse.de>
    ALSA: timer: Fix double unlink of active_list

Takashi Iwai <tiwai@suse.de>
    ALSA: timer: Fix race among timer ioctls

Takashi Iwai <tiwai@suse.de>
    ALSA: timer: Harden slave timer list handling

Takashi Iwai <tiwai@suse.de>
    ALSA: seq: Fix race at timer setup and close

Takashi Iwai <tiwai@suse.de>
    ALSA: seq: Fix missing NULL check at remove_events ioctl

Mario Kleiner <mario.kleiner.de@gmail.com>
    ALSA: hda/realtek - Fix silent headphone output on MacPro 4,1 (v2)

Xiong Zhang <xiong.y.zhang@intel.com>
    ALSA: hda - Set SKL+ hda controller power at freeze() and thaw()

David Henningsson <david.henningsson@canonical.com>
    ALSA: hda - Add inverted dmic for Packard Bell DOTS

Takashi Iwai <tiwai@suse.de>
    ALSA: rme96: Fix unexpected volume reset after rate changes

Takashi Iwai <tiwai@suse.de>
    ALSA: hda - Apply pin fixup for HP ProBook 6550b

Alexandra Yates <alexandra.yates@linux.intel.com>
    ALSA: hda - Add Intel Lewisburg device IDs Audio

Jan Stancek <jstancek@redhat.com>
    ipmi: move timer init to before irq is setup

H.J. Lu <hjl.tools@gmail.com>
    x86/boot: Double BOOT_HEAP_SIZE to 64KB

Mario Kleiner <mario.kleiner.de@gmail.com>
    x86/reboot/quirks: Add iMac10,1 to pci_reboot_dmi_table[]

Paul Mackerras <paulus@ozlabs.org>
    KVM: PPC: Book3S HV: Prohibit setting illegal transaction state in MSR

Ouyang Zhaowei (Charles) <ouyangzhaowei@huawei.com>
    x86/xen: don't reset vcpu_info on a cancelled suspend

Boris Ostrovsky <boris.ostrovsky@oracle.com>
    xen/gntdev: Grant maps should not be subject to NUMA balancing

Dmitry V. Levin <ldv@altlinux.org>
    x86/signal: Fix restart_syscall number for x32 tasks


-------------

Diffstat:

 Makefile                             |  4 +--
 arch/arm64/include/asm/kvm_emulate.h |  8 +++---
 arch/arm64/kernel/ptrace.c           |  6 +++++
 arch/arm64/kernel/setup.c            |  4 +++
 arch/arm64/kvm/inject_fault.c        |  2 +-
 arch/arm64/mm/mmu.c                  |  3 +++
 arch/mn10300/Kconfig                 |  4 +--
 arch/openrisc/Kconfig                |  4 +--
 arch/powerpc/include/asm/cmpxchg.h   | 16 +++++------
 arch/powerpc/include/asm/reg.h       |  1 +
 arch/powerpc/include/asm/synch.h     |  2 +-
 arch/powerpc/kernel/process.c        | 18 +++++++++++++
 arch/powerpc/kernel/signal_32.c      | 14 ++++++----
 arch/powerpc/kernel/signal_64.c      |  4 +++
 arch/powerpc/kvm/book3s_hv.c         |  6 +++++
 arch/x86/include/asm/boot.h          |  2 +-
 arch/x86/kernel/reboot.c             |  8 ++++++
 arch/x86/kernel/signal.c             | 17 +++++++-----
 arch/x86/xen/suspend.c               |  3 ++-
 drivers/char/ipmi/ipmi_si_intf.c     |  8 +++---
 drivers/connector/connector.c        | 11 +++-----
 drivers/hid/hid-core.c               |  2 +-
 drivers/isdn/i4l/isdn_ppp.c          | 12 ++++++---
 drivers/net/bonding/bond_main.c      |  5 +++-
 drivers/net/ppp/ppp_generic.c        |  6 ++---
 drivers/net/slip/slhc.c              | 12 ++++++---
 drivers/net/slip/slip.c              |  2 +-
 drivers/net/team/team.c              |  6 ++---
 drivers/net/veth.c                   |  6 -----
 drivers/parisc/iommu-helpers.h       | 15 ++++++-----
 drivers/usb/host/xhci.c              | 12 +++++++++
 drivers/usb/serial/cp210x.c          |  1 +
 drivers/usb/serial/ipaq.c            |  3 ++-
 drivers/xen/gntdev.c                 |  2 +-
 include/linux/sched.h                |  1 +
 include/linux/syscalls.h             |  2 +-
 include/linux/types.h                |  2 +-
 include/net/inet_ecn.h               | 19 ++++++++++---
 net/bridge/br_stp_if.c               |  5 +++-
 net/core/dst.c                       |  3 ++-
 net/ipv4/tcp_yeah.c                  |  2 +-
 net/ipv6/addrlabel.c                 |  2 +-
 net/ipv6/xfrm6_mode_tunnel.c         |  2 +-
 net/phonet/af_phonet.c               |  4 +++
 net/sctp/sm_statefuns.c              |  6 +++--
 net/sctp/socket.c                    |  3 +--
 net/sctp/sysctl.c                    |  2 +-
 net/unix/af_unix.c                   | 24 ++++++++++++++---
 net/unix/garbage.c                   | 16 ++++++++---
 scripts/recordmcount.pl              |  3 ++-
 sound/core/control.c                 |  2 ++
 sound/core/hrtimer.c                 |  3 ++-
 sound/core/pcm_compat.c              | 13 ++++++---
 sound/core/seq/seq_clientmgr.c       |  2 +-
 sound/core/seq/seq_compat.c          |  9 ++++---
 sound/core/seq/seq_queue.c           |  2 ++
 sound/core/timer.c                   | 52 +++++++++++++++++++++++-------------
 sound/pci/hda/hda_intel.c            | 39 +++++++++++++++++++++++++++
 sound/pci/hda/patch_realtek.c        | 12 +++++++--
 sound/pci/hda/patch_sigmatel.c       |  1 +
 sound/pci/rme96.c                    | 41 +++++++++++++++++-----------
 sound/soc/codecs/arizona.c           |  2 +-
 sound/soc/codecs/wm8962.c            |  4 +--
 sound/soc/codecs/wm8974.c            |  1 +
 sound/soc/soc-compress.c             | 23 +++++++++++++---
 65 files changed, 376 insertions(+), 155 deletions(-)

[toc] | [next] | [standalone]


#1319456 — [PATCH 3.14 18/59] ALSA: timer: Fix double unlink of active_list

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 18/59] ALSA: timer: Fix double unlink of active_list
Message-ID<qVDWW-8oV-9@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Takashi Iwai <tiwai@suse.de>

commit ee8413b01045c74340aa13ad5bdf905de32be736 upstream.

ALSA timer instance object has a couple of linked lists and they are
unlinked unconditionally at snd_timer_stop().  Meanwhile
snd_timer_interrupt() unlinks it, but it calls list_del() which leaves
the element list itself unchanged.  This ends up with unlinking twice,
and it was caught by syzkaller fuzzer.

The fix is to use list_del_init() variant properly there, too.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Tested-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 sound/core/timer.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/sound/core/timer.c
+++ b/sound/core/timer.c
@@ -703,7 +703,7 @@ void snd_timer_interrupt(struct snd_time
 		} else {
 			ti->flags &= ~SNDRV_TIMER_IFLG_RUNNING;
 			if (--timer->running)
-				list_del(&ti->active_list);
+				list_del_init(&ti->active_list);
 		}
 		if ((timer->hw.flags & SNDRV_TIMER_HW_TASKLET) ||
 		    (ti->flags & SNDRV_TIMER_IFLG_FAST))

[toc] | [prev] | [next] | [standalone]


#1319457 — [PATCH 3.14 42/59] ipv6: update skb->csum when CE mark is propagated

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 42/59] ipv6: update skb->csum when CE mark is propagated
Message-ID<qVDWW-8oV-11@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 34ae6a1aa0540f0f781dd265366036355fdc8930 ]

When a tunnel decapsulates the outer header, it has to comply
with RFC 6080 and eventually propagate CE mark into inner header.

It turns out IP6_ECN_set_ce() does not correctly update skb->csum
for CHECKSUM_COMPLETE packets, triggering infamous "hw csum failure"
messages and stack traces.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 include/net/inet_ecn.h       |   19 ++++++++++++++++---
 net/ipv6/xfrm6_mode_tunnel.c |    2 +-
 2 files changed, 17 insertions(+), 4 deletions(-)

--- a/include/net/inet_ecn.h
+++ b/include/net/inet_ecn.h
@@ -111,11 +111,24 @@ static inline void ipv4_copy_dscp(unsign
 
 struct ipv6hdr;
 
-static inline int IP6_ECN_set_ce(struct ipv6hdr *iph)
+/* Note:
+ * IP_ECN_set_ce() has to tweak IPV4 checksum when setting CE,
+ * meaning both changes have no effect on skb->csum if/when CHECKSUM_COMPLETE
+ * In IPv6 case, no checksum compensates the change in IPv6 header,
+ * so we have to update skb->csum.
+ */
+static inline int IP6_ECN_set_ce(struct sk_buff *skb, struct ipv6hdr *iph)
 {
+	__be32 from, to;
+
 	if (INET_ECN_is_not_ect(ipv6_get_dsfield(iph)))
 		return 0;
-	*(__be32*)iph |= htonl(INET_ECN_CE << 20);
+
+	from = *(__be32 *)iph;
+	to = from | htonl(INET_ECN_CE << 20);
+	*(__be32 *)iph = to;
+	if (skb->ip_summed == CHECKSUM_COMPLETE)
+		skb->csum = csum_add(csum_sub(skb->csum, from), to);
 	return 1;
 }
 
@@ -142,7 +155,7 @@ static inline int INET_ECN_set_ce(struct
 	case cpu_to_be16(ETH_P_IPV6):
 		if (skb_network_header(skb) + sizeof(struct ipv6hdr) <=
 		    skb_tail_pointer(skb))
-			return IP6_ECN_set_ce(ipv6_hdr(skb));
+			return IP6_ECN_set_ce(skb, ipv6_hdr(skb));
 		break;
 	}
 
--- a/net/ipv6/xfrm6_mode_tunnel.c
+++ b/net/ipv6/xfrm6_mode_tunnel.c
@@ -83,7 +83,7 @@ static inline void ipip6_ecn_decapsulate
 	struct ipv6hdr *inner_iph = ipipv6_hdr(skb);
 
 	if (INET_ECN_is_ce(ipv6_get_dsfield(outer_iph)))
-		IP6_ECN_set_ce(inner_iph);
+		IP6_ECN_set_ce(skb, inner_iph);
 }
 
 /* Add encapsulation header.

[toc] | [prev] | [next] | [standalone]


#1319458 — [PATCH 3.14 45/59] team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 45/59] team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid
Message-ID<qVDWW-8oV-5@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ido Schimmel <idosch@mellanox.com>

[ Upstream commit 60a6531bfe49555581ccd65f66a350cc5693fcde ]

We can't be within an RCU read-side critical section when deleting
VLANs, as underlying drivers might sleep during the hardware operation.
Therefore, replace the RCU critical section with a mutex. This is
consistent with team_vlan_rx_add_vid.

Fixes: 3d249d4ca7d0 ("net: introduce ethernet teaming device")
Acked-by: Jiri Pirko <jiri@mellanox.com>
Signed-off-by: Ido Schimmel <idosch@mellanox.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/net/team/team.c |    6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

--- a/drivers/net/team/team.c
+++ b/drivers/net/team/team.c
@@ -1838,10 +1838,10 @@ static int team_vlan_rx_kill_vid(struct
 	struct team *team = netdev_priv(dev);
 	struct team_port *port;
 
-	rcu_read_lock();
-	list_for_each_entry_rcu(port, &team->port_list, list)
+	mutex_lock(&team->lock);
+	list_for_each_entry(port, &team->port_list, list)
 		vlan_vid_del(port->dev, proto, vid);
-	rcu_read_unlock();
+	mutex_unlock(&team->lock);
 
 	return 0;
 }

[toc] | [prev] | [next] | [standalone]


#1319459 — [PATCH 3.14 05/59] x86/reboot/quirks: Add iMac10,1 to pci_reboot_dmi_table[]

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 05/59] x86/reboot/quirks: Add iMac10,1 to pci_reboot_dmi_table[]
Message-ID<qVDWW-8oV-13@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mario Kleiner <mario.kleiner.de@gmail.com>

commit 2f0c0b2d96b1205efb14347009748d786c2d9ba5 upstream.

Without the reboot=pci method, the iMac 10,1 simply
hangs after printing "Restarting system" at the point
when it should reboot. This fixes it.

Signed-off-by: Mario Kleiner <mario.kleiner.de@gmail.com>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Brian Gerst <brgerst@gmail.com>
Cc: Dave Jones <davej@codemonkey.org.uk>
Cc: Denys Vlasenko <dvlasenk@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Link: http://lkml.kernel.org/r/1450466646-26663-1-git-send-email-mario.kleiner.de@gmail.com
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/x86/kernel/reboot.c |    8 ++++++++
 1 file changed, 8 insertions(+)

--- a/arch/x86/kernel/reboot.c
+++ b/arch/x86/kernel/reboot.c
@@ -180,6 +180,14 @@ static struct dmi_system_id __initdata r
 			DMI_MATCH(DMI_PRODUCT_NAME, "iMac9,1"),
 		},
 	},
+	{	/* Handle problems with rebooting on the iMac10,1. */
+		.callback = set_pci_reboot,
+		.ident = "Apple iMac10,1",
+		.matches = {
+		    DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."),
+		    DMI_MATCH(DMI_PRODUCT_NAME, "iMac10,1"),
+		},
+	},
 
 	/* ASRock */
 	{	/* Handle problems with rebooting on ASRock Q1900DC-ITX */

[toc] | [prev] | [next] | [standalone]


#1319461 — [PATCH 3.14 08/59] ALSA: hda - Add Intel Lewisburg device IDs Audio

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 08/59] ALSA: hda - Add Intel Lewisburg device IDs Audio
Message-ID<qVDWW-8oV-17@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alexandra Yates <alexandra.yates@linux.intel.com>

commit 5cf92c8b3dc5da59e05dc81bdc069cedf6f38313 upstream.

Adding Intel codename Lewisburg platform device IDs for audio.

[rearranged the position by tiwai]

Signed-off-by: Alexandra Yates <alexandra.yates@linux.intel.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 sound/pci/hda/hda_intel.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/sound/pci/hda/hda_intel.c
+++ b/sound/pci/hda/hda_intel.c
@@ -3996,6 +3996,11 @@ static DEFINE_PCI_DEVICE_TABLE(azx_ids)
 	  .driver_data = AZX_DRIVER_PCH | AZX_DCAPS_INTEL_PCH },
 	{ PCI_DEVICE(0x8086, 0x8d21),
 	  .driver_data = AZX_DRIVER_PCH | AZX_DCAPS_INTEL_PCH },
+	/* Lewisburg */
+	{ PCI_DEVICE(0x8086, 0xa1f0),
+	  .driver_data = AZX_DRIVER_PCH | AZX_DCAPS_INTEL_PCH },
+	{ PCI_DEVICE(0x8086, 0xa270),
+	  .driver_data = AZX_DRIVER_PCH | AZX_DCAPS_INTEL_PCH },
 	/* Lynx Point-LP */
 	{ PCI_DEVICE(0x8086, 0x9c20),
 	  .driver_data = AZX_DRIVER_PCH | AZX_DCAPS_INTEL_PCH },

[toc] | [prev] | [next] | [standalone]


#1319462 — [PATCH 3.14 22/59] ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 22/59] ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0
Message-ID<qVDWW-8oV-15@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Takashi Iwai <tiwai@suse.de>

commit c0bcdbdff3ff73a54161fca3cb8b6cdbd0bb8762 upstream.

When a TLV ioctl with numid zero is handled, the driver may spew a
kernel warning with a stack trace at each call.  The check was
intended obviously only for a kernel driver, but not for a user
interaction.  Let's fix it.

This was spotted by syzkaller fuzzer.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 sound/core/control.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/sound/core/control.c
+++ b/sound/core/control.c
@@ -1325,6 +1325,8 @@ static int snd_ctl_tlv_ioctl(struct snd_
 		return -EFAULT;
 	if (tlv.length < sizeof(unsigned int) * 2)
 		return -EINVAL;
+	if (!tlv.numid)
+		return -EINVAL;
 	down_read(&card->controls_rwsem);
 	kctl = snd_ctl_find_numid(card, tlv.numid);
 	if (kctl == NULL) {

[toc] | [prev] | [next] | [standalone]


#1319463 — [PATCH 3.14 02/59] xen/gntdev: Grant maps should not be subject to NUMA balancing

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 02/59] xen/gntdev: Grant maps should not be subject to NUMA balancing
Message-ID<qVDWW-8oV-19@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Boris Ostrovsky <boris.ostrovsky@oracle.com>

commit 9c17d96500f78d7ecdb71ca6942830158bc75a2b upstream.

Doing so will cause the grant to be unmapped and then, during
fault handling, the fault to be mistakenly treated as NUMA hint
fault.

In addition, even if those maps could partcipate in NUMA
balancing, it wouldn't provide any benefit since we are unable
to determine physical page's node (even if/when VNUMA is
implemented).

Marking grant maps' VMAs as VM_IO will exclude them from being
part of NUMA balancing.

Signed-off-by: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Signed-off-by: David Vrabel <david.vrabel@citrix.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/xen/gntdev.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/xen/gntdev.c
+++ b/drivers/xen/gntdev.c
@@ -765,7 +765,7 @@ static int gntdev_mmap(struct file *flip
 
 	vma->vm_ops = &gntdev_vmops;
 
-	vma->vm_flags |= VM_DONTEXPAND | VM_DONTDUMP;
+	vma->vm_flags |= VM_DONTEXPAND | VM_DONTDUMP | VM_IO;
 
 	if (use_ptemod)
 		vma->vm_flags |= VM_DONTCOPY;

[toc] | [prev] | [next] | [standalone]


#1319464 — [PATCH 3.14 03/59] x86/xen: dont reset vcpu_info on a cancelled suspend

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 03/59] x86/xen: dont reset vcpu_info on a cancelled suspend
Message-ID<qVDWX-8oV-21@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: "Ouyang Zhaowei (Charles)" <ouyangzhaowei@huawei.com>

commit 6a1f513776b78c994045287073e55bae44ed9f8c upstream.

On a cancelled suspend the vcpu_info location does not change (it's
still in the per-cpu area registered by xen_vcpu_setup()).  So do not
call xen_hvm_init_shared_info() which would make the kernel think its
back in the shared info.  With the wrong vcpu_info, events cannot be
received and the domain will hang after a cancelled suspend.

Signed-off-by: Charles Ouyang <ouyangzhaowei@huawei.com>
Reviewed-by: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Signed-off-by: David Vrabel <david.vrabel@citrix.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/x86/xen/suspend.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/arch/x86/xen/suspend.c
+++ b/arch/x86/xen/suspend.c
@@ -30,7 +30,8 @@ void xen_arch_hvm_post_suspend(int suspe
 {
 #ifdef CONFIG_XEN_PVHVM
 	int cpu;
-	xen_hvm_init_shared_info();
+	if (!suspend_cancelled)
+	    xen_hvm_init_shared_info();
 	xen_callback_vector();
 	xen_unplug_emulated_devices();
 	if (xen_feature(XENFEAT_hvm_safe_pvclock)) {

[toc] | [prev] | [next] | [standalone]


#1319466 — [PATCH 3.14 27/59] usb: xhci: fix config fail of FS hub behind a HS hub with MTT

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 27/59] usb: xhci: fix config fail of FS hub behind a HS hub with MTT
Message-ID<qVDWX-8oV-25@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chunfeng Yun <chunfeng.yun@mediatek.com>

commit 096b110a3dd3c868e4610937c80d2e3f3357c1a9 upstream.

if a full speed hub connects to a high speed hub which
supports MTT, the MTT field of its slot context will be set
to 1 when xHCI driver setups an xHCI virtual device in
xhci_setup_addressable_virt_dev(); once usb core fetch its
hub descriptor, and need to update the xHC's internal data
structures for the device, the HUB field of its slot context
will be set to 1 too, meanwhile MTT is also set before,
this will cause configure endpoint command fail, so in the
case, we should clear MTT to 0 for full speed hub according
to section 6.2.2

Signed-off-by: Chunfeng Yun <chunfeng.yun@mediatek.com>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/host/xhci.c |    8 ++++++++
 1 file changed, 8 insertions(+)

--- a/drivers/usb/host/xhci.c
+++ b/drivers/usb/host/xhci.c
@@ -4696,8 +4696,16 @@ int xhci_update_hub_device(struct usb_hc
 	ctrl_ctx->add_flags |= cpu_to_le32(SLOT_FLAG);
 	slot_ctx = xhci_get_slot_ctx(xhci, config_cmd->in_ctx);
 	slot_ctx->dev_info |= cpu_to_le32(DEV_HUB);
+	/*
+	 * refer to section 6.2.2: MTT should be 0 for full speed hub,
+	 * but it may be already set to 1 when setup an xHCI virtual
+	 * device, so clear it anyway.
+	 */
 	if (tt->multi)
 		slot_ctx->dev_info |= cpu_to_le32(DEV_MTT);
+	else if (hdev->speed == USB_SPEED_FULL)
+		slot_ctx->dev_info &= cpu_to_le32(~DEV_MTT);
+
 	if (xhci->hci_version > 0x95) {
 		xhci_dbg(xhci, "xHCI version %x needs hub "
 				"TT think time and number of ports\n",

[toc] | [prev] | [next] | [standalone]


#1319467 — [PATCH 3.14 26/59] ASoC: compress: Fix compress device direction check

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 26/59] ASoC: compress: Fix compress device direction check
Message-ID<qVDWX-8oV-27@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Vinod Koul <vinod.koul@intel.com>

commit a1068045883ed4a18363a4ebad0c3d55e473b716 upstream.

The detection of direction for compress was only taking into account codec
capabilities and not CPU ones. Fix this by checking the CPU side capabilities
as well

Tested-by: Ashish Panwar <ashish.panwar@intel.com>
Signed-off-by: Vinod Koul <vinod.koul@intel.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 sound/soc/soc-compress.c |   23 ++++++++++++++++++++---
 1 file changed, 20 insertions(+), 3 deletions(-)

--- a/sound/soc/soc-compress.c
+++ b/sound/soc/soc-compress.c
@@ -665,17 +665,34 @@ int soc_new_compress(struct snd_soc_pcm_
 	struct snd_pcm *be_pcm;
 	char new_name[64];
 	int ret = 0, direction = 0;
+	int playback = 0, capture = 0;
 
 	/* check client and interface hw capabilities */
 	snprintf(new_name, sizeof(new_name), "%s %s-%d",
 			rtd->dai_link->stream_name, codec_dai->name, num);
 
 	if (codec_dai->driver->playback.channels_min)
+		playback = 1;
+	if (codec_dai->driver->capture.channels_min)
+		capture = 1;
+
+	capture = capture && cpu_dai->driver->capture.channels_min;
+	playback = playback && cpu_dai->driver->playback.channels_min;
+
+	/*
+	 * Compress devices are unidirectional so only one of the directions
+	 * should be set, check for that (xor)
+	 */
+	if (playback + capture != 1) {
+		dev_err(rtd->card->dev, "Invalid direction for compress P %d, C %d\n",
+				playback, capture);
+		return -EINVAL;
+	}
+
+	if(playback)
 		direction = SND_COMPRESS_PLAYBACK;
-	else if (codec_dai->driver->capture.channels_min)
-		direction = SND_COMPRESS_CAPTURE;
 	else
-		return -EINVAL;
+		direction = SND_COMPRESS_CAPTURE;
 
 	compr = kzalloc(sizeof(*compr), GFP_KERNEL);
 	if (compr == NULL) {

[toc] | [prev] | [next] | [standalone]


#1319468 — [PATCH 3.14 24/59] ASoC: wm8974: set cache type for regmap

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 24/59] ASoC: wm8974: set cache type for regmap
Message-ID<qVDWX-8oV-29@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mans Rullgard <mans@mansr.com>

commit 1ea5998afe903384ddc16391d4c023cd4c867bea upstream.

Attempting to use this codec driver triggers a BUG() in regcache_sync()
since no cache type is set.  The register map of this device is fairly
small and has few holes so a flat cache is suitable.

Signed-off-by: Mans Rullgard <mans@mansr.com>
Acked-by: Charles Keepax <ckeepax@opensource.wolfsonmicro.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 sound/soc/codecs/wm8974.c |    1 +
 1 file changed, 1 insertion(+)

--- a/sound/soc/codecs/wm8974.c
+++ b/sound/soc/codecs/wm8974.c
@@ -587,6 +587,7 @@ static const struct regmap_config wm8974
 	.max_register = WM8974_MONOMIX,
 	.reg_defaults = wm8974_reg_defaults,
 	.num_reg_defaults = ARRAY_SIZE(wm8974_reg_defaults),
+	.cache_type = REGCACHE_FLAT,
 };
 
 static int wm8974_probe(struct snd_soc_codec *codec)

[toc] | [prev] | [next] | [standalone]


#1319469 — [PATCH 3.14 40/59] bonding: Prevent IPv6 link local address on enslaved devices

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 40/59] bonding: Prevent IPv6 link local address on enslaved devices
Message-ID<qVDWX-8oV-33@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Karl Heiss <kheiss@gmail.com>

[ Upstream commit 03d84a5f83a67e692af00a3d3901e7820e3e84d5 ]

Commit 1f718f0f4f97 ("bonding: populate neighbour's private on enslave")
undoes the fix provided by commit c2edacf80e15 ("bonding / ipv6: no addrconf
for slaves separately from master") by effectively setting the slave flag
after the slave has been opened.  If the slave comes up quickly enough, it
will go through the IPv6 addrconf before the slave flag has been set and
will get a link local IPv6 address.

In order to ensure that addrconf knows to ignore the slave devices on state
change, set IFF_SLAVE before dev_open() during bonding enslavement.

Fixes: 1f718f0f4f97 ("bonding: populate neighbour's private on enslave")
Signed-off-by: Karl Heiss <kheiss@gmail.com>
Signed-off-by: Jay Vosburgh <jay.vosburgh@canonical.com>
Reviewed-by: Jarod Wilson <jarod@redhat.com>
Signed-off-by: Andy Gospodarek <gospo@cumulusnetworks.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/net/bonding/bond_main.c |    5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

--- a/drivers/net/bonding/bond_main.c
+++ b/drivers/net/bonding/bond_main.c
@@ -1181,7 +1181,6 @@ static int bond_master_upper_dev_link(st
 	err = netdev_master_upper_dev_link_private(slave_dev, bond_dev, slave);
 	if (err)
 		return err;
-	slave_dev->flags |= IFF_SLAVE;
 	rtmsg_ifinfo(RTM_NEWLINK, slave_dev, IFF_SLAVE, GFP_KERNEL);
 	return 0;
 }
@@ -1363,6 +1362,9 @@ int bond_enslave(struct net_device *bond
 		}
 	}
 
+	/* set slave flag before open to prevent IPv6 addrconf */
+	slave_dev->flags |= IFF_SLAVE;
+
 	/* open the slave since the application closed it */
 	res = dev_open(slave_dev);
 	if (res) {
@@ -1617,6 +1619,7 @@ err_close:
 	dev_close(slave_dev);
 
 err_restore_mac:
+	slave_dev->flags &= ~IFF_SLAVE;
 	if (!bond->params.fail_over_mac ||
 	    bond->params.mode != BOND_MODE_ACTIVEBACKUP) {
 		/* XXX TODO - fom follow mode needs to change master's

[toc] | [prev] | [next] | [standalone]


#1319470 — [PATCH 3.14 21/59] ALSA: hrtimer: Fix stall by hrtimer_cancel()

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 21/59] ALSA: hrtimer: Fix stall by hrtimer_cancel()
Message-ID<qVDWX-8oV-37@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Takashi Iwai <tiwai@suse.de>

commit 2ba1fe7a06d3624f9a7586d672b55f08f7c670f3 upstream.

hrtimer_cancel() waits for the completion from the callback, thus it
must not be called inside the callback itself.  This was already a
problem in the past with ALSA hrtimer driver, and the early commit
[fcfdebe70759: ALSA: hrtimer - Fix lock-up] tried to address it.

However, the previous fix is still insufficient: it may still cause a
lockup when the ALSA timer instance reprograms itself in its callback.
Then it invokes the start function even in snd_timer_interrupt() that
is called in hrtimer callback itself, results in a CPU stall.  This is
no hypothetical problem but actually triggered by syzkaller fuzzer.

This patch tries to fix the issue again.  Now we call
hrtimer_try_to_cancel() at both start and stop functions so that it
won't fall into a deadlock, yet giving some chance to cancel the queue
if the functions have been called outside the callback.  The proper
hrtimer_cancel() is called in anyway at closing, so this should be
enough.

Reported-and-tested-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 sound/core/hrtimer.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/sound/core/hrtimer.c
+++ b/sound/core/hrtimer.c
@@ -90,7 +90,7 @@ static int snd_hrtimer_start(struct snd_
 	struct snd_hrtimer *stime = t->private_data;
 
 	atomic_set(&stime->running, 0);
-	hrtimer_cancel(&stime->hrt);
+	hrtimer_try_to_cancel(&stime->hrt);
 	hrtimer_start(&stime->hrt, ns_to_ktime(t->sticks * resolution),
 		      HRTIMER_MODE_REL);
 	atomic_set(&stime->running, 1);
@@ -101,6 +101,7 @@ static int snd_hrtimer_stop(struct snd_t
 {
 	struct snd_hrtimer *stime = t->private_data;
 	atomic_set(&stime->running, 0);
+	hrtimer_try_to_cancel(&stime->hrt);
 	return 0;
 }
 

[toc] | [prev] | [next] | [standalone]


#1319471 — [PATCH 3.14 07/59] ipmi: move timer init to before irq is setup

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 07/59] ipmi: move timer init to before irq is setup
Message-ID<qVDWX-8oV-35@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jan Stancek <jstancek@redhat.com>

commit 27f972d3e00b50639deb4cc1392afaeb08d3cecc upstream.

We encountered a panic on boot in ipmi_si on a dell per320 due to an
uninitialized timer as follows.

static int smi_start_processing(void       *send_info,
                                ipmi_smi_t intf)
{
        /* Try to claim any interrupts. */
        if (new_smi->irq_setup)
                new_smi->irq_setup(new_smi);

 --> IRQ arrives here and irq handler tries to modify uninitialized timer

    which triggers BUG_ON(!timer->function) in __mod_timer().

 Call Trace:
   <IRQ>
   [<ffffffffa0532617>] start_new_msg+0x47/0x80 [ipmi_si]
   [<ffffffffa053269e>] start_check_enables+0x4e/0x60 [ipmi_si]
   [<ffffffffa0532bd8>] smi_event_handler+0x1e8/0x640 [ipmi_si]
   [<ffffffff810f5584>] ? __rcu_process_callbacks+0x54/0x350
   [<ffffffffa053327c>] si_irq_handler+0x3c/0x60 [ipmi_si]
   [<ffffffff810efaf0>] handle_IRQ_event+0x60/0x170
   [<ffffffff810f245e>] handle_edge_irq+0xde/0x180
   [<ffffffff8100fc59>] handle_irq+0x49/0xa0
   [<ffffffff8154643c>] do_IRQ+0x6c/0xf0
   [<ffffffff8100ba53>] ret_from_intr+0x0/0x11

        /* Set up the timer that drives the interface. */
        setup_timer(&new_smi->si_timer, smi_timeout, (long)new_smi);

The following patch fixes the problem.

To: Openipmi-developer@lists.sourceforge.net
To: Corey Minyard <minyard@acm.org>
CC: linux-kernel@vger.kernel.org

Signed-off-by: Jan Stancek <jstancek@redhat.com>
Signed-off-by: Tony Camuso <tcamuso@redhat.com>
Signed-off-by: Corey Minyard <cminyard@mvista.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/char/ipmi/ipmi_si_intf.c |    8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

--- a/drivers/char/ipmi/ipmi_si_intf.c
+++ b/drivers/char/ipmi/ipmi_si_intf.c
@@ -1152,14 +1152,14 @@ static int smi_start_processing(void
 
 	new_smi->intf = intf;
 
-	/* Try to claim any interrupts. */
-	if (new_smi->irq_setup)
-		new_smi->irq_setup(new_smi);
-
 	/* Set up the timer that drives the interface. */
 	setup_timer(&new_smi->si_timer, smi_timeout, (long)new_smi);
 	smi_mod_timer(new_smi, jiffies + SI_TIMEOUT_JIFFIES);
 
+	/* Try to claim any interrupts. */
+	if (new_smi->irq_setup)
+		new_smi->irq_setup(new_smi);
+
 	/*
 	 * Check if the user forcefully enabled the daemon.
 	 */

[toc] | [prev] | [next] | [standalone]


#1319472 — [PATCH 3.14 41/59] phonet: properly unshare skbs in phonet_rcv()

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 41/59] phonet: properly unshare skbs in phonet_rcv()
Message-ID<qVDWX-8oV-39@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 7aaed57c5c2890634cfadf725173c7c68ea4cb4f ]

Ivaylo Dimitrov reported a regression caused by commit 7866a621043f
("dev: add per net_device packet type chains").

skb->dev becomes NULL and we crash in __netif_receive_skb_core().

Before above commit, different kind of bugs or corruptions could happen
without major crash.

But the root cause is that phonet_rcv() can queue skb without checking
if skb is shared or not.

Many thanks to Ivaylo Dimitrov for his help, diagnosis and tests.

Reported-by: Ivaylo Dimitrov <ivo.g.dimitrov.75@gmail.com>
Tested-by: Ivaylo Dimitrov <ivo.g.dimitrov.75@gmail.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Remi Denis-Courmont <courmisch@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/phonet/af_phonet.c |    4 ++++
 1 file changed, 4 insertions(+)

--- a/net/phonet/af_phonet.c
+++ b/net/phonet/af_phonet.c
@@ -377,6 +377,10 @@ static int phonet_rcv(struct sk_buff *sk
 	struct sockaddr_pn sa;
 	u16 len;
 
+	skb = skb_share_check(skb, GFP_ATOMIC);
+	if (!skb)
+		return NET_RX_DROP;
+
 	/* check we have at least a full Phonet header */
 	if (!pskb_pull(skb, sizeof(struct phonethdr)))
 		goto out;

[toc] | [prev] | [next] | [standalone]


#1319473 — [PATCH 3.14 04/59] KVM: PPC: Book3S HV: Prohibit setting illegal transaction state in MSR

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 04/59] KVM: PPC: Book3S HV: Prohibit setting illegal transaction state in MSR
Message-ID<qVDWX-8oV-41@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Paul Mackerras <paulus@ozlabs.org>

commit c20875a3e638e4a03e099b343ec798edd1af5cc6 upstream.

Currently it is possible for userspace (e.g. QEMU) to set a value
for the MSR for a guest VCPU which has both of the TS bits set,
which is an illegal combination.  The result of this is that when
we execute a hrfid (hypervisor return from interrupt doubleword)
instruction to enter the guest, the CPU will take a TM Bad Thing
type of program interrupt (vector 0x700).

Now, if PR KVM is configured in the kernel along with HV KVM, we
actually handle this without crashing the host or giving hypervisor
privilege to the guest; instead what happens is that we deliver a
program interrupt to the guest, with SRR0 reflecting the address
of the hrfid instruction and SRR1 containing the MSR value at that
point.  If PR KVM is not configured in the kernel, then we try to
run the host's program interrupt handler with the MMU set to the
guest context, which almost certainly causes a host crash.

This closes the hole by making kvmppc_set_msr_hv() check for the
illegal combination and force the TS field to a safe value (00,
meaning non-transactional).

Signed-off-by: Paul Mackerras <paulus@samba.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/powerpc/kvm/book3s_hv.c |    6 ++++++
 1 file changed, 6 insertions(+)

--- a/arch/powerpc/kvm/book3s_hv.c
+++ b/arch/powerpc/kvm/book3s_hv.c
@@ -166,6 +166,12 @@ static void kvmppc_core_vcpu_put_hv(stru
 
 static void kvmppc_set_msr_hv(struct kvm_vcpu *vcpu, u64 msr)
 {
+	/*
+	 * Check for illegal transactional state bit combination
+	 * and if we find it, force the TS field to a safe state.
+	 */
+	if ((msr & MSR_TS_MASK) == MSR_TS_MASK)
+		msr &= ~MSR_TS_MASK;
 	vcpu->arch.shregs.msr = msr;
 	kvmppc_end_cede(vcpu);
 }

[toc] | [prev] | [next] | [standalone]


#1319474 — [PATCH 3.14 20/59] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 20/59] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode
Message-ID<qVDWX-8oV-43@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nicolas Boichat <drinkcat@chromium.org>

commit 43c54b8c7cfe22f868a751ba8a59abf1724160b1 upstream.

This reverts one hunk of
commit ef44a1ec6eee ("ALSA: sound/core: use memdup_user()"), which
replaced a number of kmalloc followed by memcpy with memdup calls.

In this case, we are copying from a struct snd_pcm_hw_params32 to
a struct snd_pcm_hw_params, but the latter is 4 bytes longer than
the 32-bit version, so we need to separate kmalloc and copy calls.

This actually leads to an out-of-bounds memory access later on
in sound/soc/soc-pcm.c:soc_pcm_hw_params() (detected using KASan).

Fixes: ef44a1ec6eee ('ALSA: sound/core: use memdup_user()')
Signed-off-by: Nicolas Boichat <drinkcat@chromium.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 sound/core/pcm_compat.c |   13 +++++++++----
 1 file changed, 9 insertions(+), 4 deletions(-)

--- a/sound/core/pcm_compat.c
+++ b/sound/core/pcm_compat.c
@@ -236,10 +236,15 @@ static int snd_pcm_ioctl_hw_params_compa
 	if (! (runtime = substream->runtime))
 		return -ENOTTY;
 
-	/* only fifo_size is different, so just copy all */
-	data = memdup_user(data32, sizeof(*data32));
-	if (IS_ERR(data))
-		return PTR_ERR(data);
+	data = kmalloc(sizeof(*data), GFP_KERNEL);
+	if (!data)
+		return -ENOMEM;
+
+	/* only fifo_size (RO from userspace) is different, so just copy all */
+	if (copy_from_user(data, data32, sizeof(*data32))) {
+		err = -EFAULT;
+		goto error;
+	}
 
 	if (refine)
 		err = snd_pcm_hw_refine(substream, data);

[toc] | [prev] | [next] | [standalone]


#1319475 — [PATCH 3.14 28/59] USB: ipaq.c: fix a timeout loop

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 28/59] USB: ipaq.c: fix a timeout loop
Message-ID<qVDWY-8oV-49@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dan Carpenter <dan.carpenter@oracle.com>

commit abdc9a3b4bac97add99e1d77dc6d28623afe682b upstream.

The code expects the loop to end with "retries" set to zero but, because
it is a post-op, it will end set to -1.  I have fixed this by moving the
decrement inside the loop.

Fixes: 014aa2a3c32e ('USB: ipaq: minor ipaq_open() cleanup.')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/serial/ipaq.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/usb/serial/ipaq.c
+++ b/drivers/usb/serial/ipaq.c
@@ -531,7 +531,8 @@ static int ipaq_open(struct tty_struct *
 	 * through. Since this has a reasonably high failure rate, we retry
 	 * several times.
 	 */
-	while (retries--) {
+	while (retries) {
+		retries--;
 		result = usb_control_msg(serial->dev,
 				usb_sndctrlpipe(serial->dev, 0), 0x22, 0x21,
 				0x1, 0, NULL, 0, 100);

[toc] | [prev] | [next] | [standalone]


#1319476 — [PATCH 3.14 30/59] xhci: refuse loading if nousb is used

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-01-27 20:30 +0100
Subject[PATCH 3.14 30/59] xhci: refuse loading if nousb is used
Message-ID<qVDWY-8oV-47@gated-at.bofh.it>
In reply to#1319455
3.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Oliver Neukum <oneukum@suse.com>

commit 1eaf35e4dd592c59041bc1ed3248c46326da1f5f upstream.

The module should fail to load.

Signed-off-by: Oliver Neukum <oneukum@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/host/xhci.c |    4 ++++
 1 file changed, 4 insertions(+)

--- a/drivers/usb/host/xhci.c
+++ b/drivers/usb/host/xhci.c
@@ -4893,6 +4893,10 @@ static int __init xhci_hcd_init(void)
 	BUILD_BUG_ON(sizeof(struct xhci_intr_reg) != 8*32/8);
 	/* xhci_run_regs has eight fields and embeds 128 xhci_intr_regs */
 	BUILD_BUG_ON(sizeof(struct xhci_run_regs) != (8+8*128)*32/8);
+
+	if (usb_disabled())
+		return -ENODEV;
+
 	return 0;
 unreg_pci:
 	xhci_unregister_pci();

[toc] | [prev] | [next] | [standalone]


Page 1 of 3  [1] 2 3  Next page →

Back to top | Article view | linux.kernel


csiph-web