Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1319730 > unrolled thread

[4.2.y-ckt stable] Linux 4.2.8-ckt3 stable review

Started byKamal Mostafa <kamal@canonical.com>
First post2016-01-27 21:40 +0100
Last post2016-01-27 23:10 +0100
Articles 20 on this page of 254 — 1 participant

Back to article view | Back to linux.kernel


Contents

  [4.2.y-ckt stable] Linux 4.2.8-ckt3 stable review Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 051/268] udf: limit the maximum number of indirect extents in a row Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 002/268] ovl: allow zero size xattr Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 001/268] drm/nouveau/nv46: Change mc subdev oclass from nv44 to nv4c Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 147/268] ALSA: hda - Fix bass pin fixup for ASUS N550JX Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 057/268] Thermal: do thermal zone update after a cooling device registered Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 140/268] ACPI / video: Add disable_backlight_sysfs_if quirk for the Toshiba Satellite R830 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 127/268] sparc64: fix incorrect sign extension in sys_sparc64_personality Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 238/268] batman-adv: Avoid recursive call_rcu for batadv_bla_claim Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 257/268] unix: properly account for FDs passed over unix sockets Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 243/268] batman-adv: Drop immediate orig_node free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 259/268] tcp_yeah: don't set ssthresh below 2 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 208/268] Drivers: hv: utils: use memdup_user in hvt_op_write Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 256/268] af_unix: Fix splice-bind deadlock Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 263/268] phonet: properly unshare skbs in phonet_rcv() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 203/268] mtd: nand: fix ONFI parameter page layout Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 264/268] net: bpf: reject invalid shifts Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 246/268] team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 253/268] net: cdc_ncm: avoid changing RX/TX buffers on MTU changes Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 240/268] batman-adv: Drop immediate batadv_orig_ifinfo free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 242/268] batman-adv: Drop immediate neigh_ifinfo free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 219/268] perf/x86: Fix filter_events() bug with event mappings Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 262/268] net: preserve IP control block during GSO segmentation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 245/268] ARM: dts: armadillo800eva Correct extal1 frequency to 24 MHz Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 266/268] xfrm: dst_entries_init() per-net dst_ops Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 268/268] ipv6: update skb->csum when CE mark is propagated Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 254/268] sctp: sctp should release assoc when sctp_make_abort_user return NULL in sctp_close Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 248/268] IB/mlx4: Initialize hop_limit when creating address handle Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 255/268] connector: bump skb->users before callback invocation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 234/268] include/linux/memblock.h: fix ordering of 'flags' argument in comments Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 251/268] NFS: Ensure we revalidate attributes before using execute_ok() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 202/268] ASoC: tegra_alc5632: check return value Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 250/268] NFSv4: Don't perform cached access checks before we've OPENed the file Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 258/268] bridge: Only call /sbin/bridge-stp for the initial network namespace Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 247/268] mmc: debugfs: correct wrong voltage value Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 261/268] udp: disallow UFO for sockets with SO_NO_CHECK option Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 260/268] sched,cls_flower: set key address type when present Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 265/268] batman-adv: Drop immediate batadv_hard_iface free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 236/268] btrfs: initialize the seq counter in struct btrfs_device Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 220/268] perf/x86: fix PEBS issues on Intel Atom/Core2 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 267/268] vxlan: fix test which detect duplicate vxlan iface Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 249/268] net/mlx4: Remove unused macro Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 244/268] printk: help pr_debug and pr_devel to optimize out arguments Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 252/268] veth: don’t modify ip_summed; doing so treats packets with bad checksums as good. Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 205/268] Revert "ACPI / LPSS: allow to use specific PM domain during ->probe()" Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 214/268] pinctrl: bcm2835: Fix memory leak in error path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 233/268] vmstat: make vmstat_updater deferrable again and shut down on idle Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 222/268] firmware: actually return NULL on failed request_firmware_nowait() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 216/268] x86/LDT: Print the real LDT base address Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 213/268] ALSA: fm801: detect FM-only card earlier Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 212/268] ALSA: fm801: propagate TUNER_ONLY bit when autodetected Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 228/268] ipv6: tcp: add rcu locking in tcp_v6_send_synack() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 225/268] m68k/atari, m68k/sun3: Fix SCSI platform device registration when driver is modular Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 227/268] net: sctp: prevent writes to cookie_hmac_alg from accessing invalid memory Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 211/268] ARM: imx: select SRC for i.MX7 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 231/268] mmc: sd: limit SD card power limit according to cards capabilities Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 204/268] mac80211: fix mgmt-tx abort cookie and leak Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 221/268] power: test_power: correctly handle empty writes Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 229/268] bonding: Prevent IPv6 link local address on enslaved devices Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 239/268] batman-adv: Avoid recursive call_rcu for batadv_nc_node Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 226/268] um: Fix build error and kconfig for i386 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 230/268] kbuild: Demote 'sign-compare' warning to W=2 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 215/268] mmc: sdhci: restore behavior when setting VDD via external regulator Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 209/268] tpm_tis: Use devm_free_irq not free_irq Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 200/268] PCI/MSI: Initialize MSI capability for all architectures Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 223/268] target: Fix a memory leak in target_dev_lba_map_store() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 235/268] Btrfs: clean up an error code in btrfs_init_space_info() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 241/268] batman-adv: Drop immediate batadv_neigh_node free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 199/268] ASoC: Intel: pass correct parameter in sst_alloc_stream_mrfld() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 218/268] kconfig: return 'false' instead of 'no' in bool function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 232/268] net: tcp_memcontrol: properly detect ancestor socket pressure Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 201/268] ath9k_htc: check for underflow in ath9k_htc_rx_msg() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 237/268] bridge: fix lockdep addr_list_lock false positive splat Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 224/268] phy: micrel: Fix finding PHY properties in MAC node for KSZ9031. Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 217/268] sysrq: Fix warning in sysrq generated crash. Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 195/268] SCSI: initio: remove duplicate module device table Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 189/268] MAINTAINERS: return arch/sh to maintained state, with new maintainers Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 198/268] MAINTAINERS: gpio-brcmstb: Remove stray '>' Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 181/268] prctl: take mmap sem for writing to protect against others Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 184/268] MIPS: Loongson-3: Fix SMP_ASK_C0COUNT IPI handler Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 186/268] ocfs2: NFS hangs in __ocfs2_cluster_lock due to race with ocfs2_unblock_lock Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 185/268] MIPS: hpet: Choose a safe value for the ETIME check Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 188/268] make sure that freeing shmem fast symlinks is RCU-delayed Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 196/268] clk: xgene: Fix divider with non-zero shift value Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 206/268] mtd: nand: denali: add missing nand_release() call in denali_remove() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 194/268] [media] lirc_imon: do not leave imon_probe() with mutex held Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 190/268] MIPS: Fix some missing CONFIG_CPU_MIPSR6 #ifdefs Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 192/268] drm/i915: On fb alloc failure, unref gem object where it gets refed Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 183/268] libceph: fix ceph_msg_revoke() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 210/268] ALSA: fm801: explicitly free IRQ line Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 174/268] IB/cm: Fix a recently introduced deadlock Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 175/268] ideapad-laptop: Add Lenovo ideapad Y700-17ISK to no_hw_rfkill dmi list Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 177/268] iscsi-target: Fix potential dead-lock during node acl delete Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 193/268] [media] rc: allow rc modules to be loaded if rc-main is not a module Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 207/268] Drivers: hv: util: catch allocation errors Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 191/268] ideapad-laptop: Add Lenovo Yoga 700 to no_hw_rfkill dmi list Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 182/268] ALSA: timer: Handle disconnection more safely Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 178/268] crypto: algif_skcipher - sendmsg SG marking is off by one Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 187/268] pNFS/flexfiles: Fix an XDR encoding bug in layoutreturn Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 197/268] clk: st: avoid uninitialized variable use Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 166/268] ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 167/268] ARM: debug-ll: fix BCM63xx entry for multiplatform Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 168/268] xfs: log mount failures don't wait for buffers to be released Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 179/268] ALSA: hda - Flush the pending probe work at remove Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 108/268] x86/reboot/quirks: Add iMac10,1 to pci_reboot_dmi_table[] Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 170/268] crypto: crc32c - Fix crc32c soft dependency Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 173/268] IB/mlx5: Expose correct maximum number of CQE capacity Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 171/268] IB/qib: fix mcast detach when qp not attached Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 169/268] crypto: algif_skcipher - Load TX SG list after waiting Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 121/268] x86/mm: Improve switch_mm() barrier comments Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 161/268] crypto: algif_skcipher - Fix race condition in skcipher_check_key Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 153/268] crypto: hash - Add crypto_ahash_has_setkey Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 164/268] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 139/268] ACPI / video: Add disable_backlight_sysfs_if quirk for the Toshiba Portege R700 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 136/268] ALSA: timer: Harden slave timer list handling Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 160/268] crypto: algif_hash - Fix race condition in hash_check_key Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 135/268] ALSA: hda - Add fixup for Dell Latitidue E6540 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 146/268] printk: do cond_resched() between lines while outputting to consoles Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 157/268] crypto: algif_skcipher - Remove custom release parent function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 154/268] crypto: algif_hash - Require setkey before accept(2) Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 142/268] zram: don't call idr_remove() from zram_remove() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 138/268] zram: try vmalloc() after kmalloc() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 145/268] kernel/panic.c: turn off locks debug before releasing console lock Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 149/268] crypto: af_alg - Disallow bind/setkey/... after accept(2) Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 163/268] dmaengine: at_xdmac: fix resume for cyclic transfers Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 162/268] ALSA: hrtimer: Fix stall by hrtimer_cancel() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 143/268] memcg: only free spare array when readers are done Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 133/268] scripts/bloat-o-meter: fix python3 syntax error Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 141/268] mm: soft-offline: check return value in second __get_any_page() call Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 137/268] zram/zcomp: use GFP_NOIO to allocate streams Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 165/268] ALSA: seq: Fix snd_seq_call_port_info_ioctl in compat mode Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 158/268] crypto: af_alg - Forbid bind(2) when nokey child sockets are present Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 152/268] crypto: algif_skcipher - Add nokey compatibility path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 144/268] panic: release stale console lock to always get the logbuf printed out Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 148/268] crypto: algif_skcipher - Require setkey before accept(2) Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 101/268] x86/mm: Add barriers and document switch_mm()-vs-flush synchronization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 150/268] crypto: af_alg - Fix socket double-free when accept fails Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 156/268] crypto: algif_hash - Remove custom release parent function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 155/268] crypto: af_alg - Allow af_af_alg_release_parent to be called on nokey path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 151/268] crypto: af_alg - Add nokey compatibility path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 134/268] ocfs2/dlm: ignore cleaning the migration mle that is inuse Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 130/268] cifs_dbg() outputs an uninitialized buffer in cifs_readdir() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 104/268] xfs: inode recovery readahead can race with inode buffer creation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 119/268] drm/i915: Restore inhibiting the load of the default context Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 110/268] ALSA: seq: Fix race at timer setup and close Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 111/268] virtio_balloon: fix race by fill and leak Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 113/268] ALSA: hda - Fix white noise on Dell Latitude E5550 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 126/268] ALSA: timer: Fix race among timer ioctls Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 129/268] cifs: fix race between call_async() and reconnect() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 099/268] ALSA: usb: Add native DSD support for Oppo HA-1 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 114/268] parisc: Fix __ARCH_SI_PREAMBLE_SIZE Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 098/268] drm/nouveau/kms: take mode_config mutex in connector hotplug path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 116/268] powerpc/module: Handle R_PPC64_ENTRY relocations Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 118/268] ALSA: usb-audio: Fix mixer ctl regression of Native Instrument devices Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 100/268] ALSA: hda - Fixup inverted internal mic for Lenovo E50-80 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 117/268] ALSA: hda - fix the headset mic detection problem for a Dell laptop Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 123/268] dmaengine: dw: fix cyclic transfer setup Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 128/268] cifs: Ratelimit kernel log messages Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 103/268] s390: fix normalization bug in exception table sorting Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 109/268] ALSA: seq: Fix missing NULL check at remove_events ioctl Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 105/268] xfs: handle dquot buffer readahead in log recovery correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 085/268] drm/dp/mst: fix in MSTB RAD initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 096/268] uml: fix hostfs mknod() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 131/268] m32r: fix m32104ut_defconfig build fail Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 120/268] drm/i915: intel_hpd_init(): Fix suspend/resume reprobing Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 112/268] virtio_balloon: fix race between migration and ballooning Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 115/268] scripts/recordmcount.pl: support data in text section on powerpc Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 097/268] uml: flush stdout before forking Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 125/268] mmc: mmci: fix an ages old detection error Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 102/268] x86/boot: Double BOOT_HEAP_SIZE to 64KB Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 106/268] clocksource/drivers/vt8500: Increase the minimum delta Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 124/268] dmaengine: dw: fix cyclic transfer callbacks Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 072/268] bcache: fix a leak in bch_cached_dev_run() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 063/268] rtlwifi: rtl8192de: Fix incorrect module parameter descriptions Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 077/268] wlcore/wl12xx: spi: fix NULL pointer dereference (Oops) Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 080/268] x86/xen: don't reset vcpu_info on a cancelled suspend Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 067/268] NFS: Fix attribute cache revalidation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 070/268] bcache: Add a cond_resched() call to gc Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 060/268] rtlwifi: rtl8723ae: Fix initialization of module parameters Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 066/268] rtlwifi: rtl8192cu: Add missing parameter setup Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 088/268] PCI: host: Mark PCIe/PCI (MSI) IRQ cascade handlers as IRQF_NO_THREAD Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 074/268] bcache: allows use of register in udev to avoid "device_busy" error. Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 071/268] bcache: clear BCACHE_DEV_UNLINK_DONE flag when attaching a backing device Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 093/268] scsi: add Synology to 1024 sector blacklist Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 083/268] drm/dp/mst: process broadcast messages correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 082/268] udf: Check output buffer length when converting name to CS0 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 089/268] btrfs: handle invalid num_stripes in sys_array Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 092/268] locks: fix unlock when fcntl_setlk races with a close Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 062/268] rtlwifi: rtl8188ee: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 078/268] Input: i8042 - add Fujitsu Lifebook U745 to the nomux list Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 061/268] rtlwifi: rtl8821ae: Fix errors in parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 075/268] bcache: prevent crash on changing writeback_running Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 064/268] rtlwifi: rtl8192se: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 084/268] drm/dp/mst: always send reply for UP request Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 079/268] libxfs: pack the agfl header structure so XFS_AGFL_SIZE is correct Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 076/268] bcache: Change refill_dirty() to always scan entire disk if necessary Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 095/268] dm snapshot: fix hung bios when copy error occurs Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 094/268] ASoC: compress: Fix compress device direction check Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 065/268] rtlwifi: rtl8192ce: Fix handling of module parameters Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 081/268] udf: Prevent buffer overrun with multi-byte characters Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 069/268] bcache: fix a livelock when we cause a huge number of cache misses Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 059/268] rtlwifi: rtl8723be: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 090/268] iwlwifi: update and fix 7265 series PCI IDs Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 091/268] iwlwifi: pcie: properly configure the debug buffer size for 8000 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 049/268] mmc: sdhci: Fix sdhci_runtime_pm_bus_on/off() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 058/268] posix-clock: Fix return code on the poll method's error path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 024/268] ovl: setattr: check permissions before copy-up Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 043/268] drm/amdgpu: Fix off-by-one errors in amdgpu_vm_bo_map Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 045/268] mmc: mmc: Fix incorrect use of driver strength switching HS200 and HS400 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 036/268] dm thin: fix race condition when destroying thin pool workqueue Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 022/268] rtlwifi: fix memory leak for USB device Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 044/268] drm/radeon: clean up fujitsu quirks Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 038/268] futex: Drop refcount if requeue_pi() acquired the rtmutex Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 041/268] coresight: checking for NULL string in coresight_name_match() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 028/268] arm64: mm: ensure that the zero page is visible to the page table walker Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 042/268] drm/radeon: Fix off-by-one errors in radeon_vm_bo_set_addr Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 025/268] ovl: check dentry positiveness in ovl_cleanup_whiteouts() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 033/268] tools: hv: vss: fix the write()'s argument: error -> vss_msg Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 030/268] powerpc: Make {cmp}xchg* and their atomic_ versions fully ordered Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 034/268] clk: exynos: use irqsave version of spin_lock to avoid deadlock with irqs Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 021/268] ext4 crypto: add missing locking for keyring_key access Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 054/268] USB: cp210x: add ID for ELV Marble Sound Board 1 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 056/268] Thermal: handle thermal zone device properly during system sleep Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 026/268] EDAC, mc_sysfs: Fix freeing bus' name Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 040/268] arm64: kernel: enforce pmuserenr_el0 initialization and restore Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 048/268] mmc: sdhci: Fix DMA descriptor with zero data length Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 023/268] wlcore/wl12xx: spi: fix oops on firmware load Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 050/268] regulator: axp20x: Fix GPIO LDO enable value for AXP22x Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 047/268] mmc: sdio: Fix invalid vdd in voltage switch power cycle Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 053/268] nfs: Fix race in __update_open_stateid() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 037/268] drm/radeon: Fix "slow" audio over DP on DCE8+ Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 032/268] Drivers: hv: vmbus: Fix a Host signaling bug Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 035/268] iommu/io-pgtable-arm: Ensure we free the final level on teardown Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 046/268] mmc: sdhci-pci: Do not default to 33 Ohm driver strength for Intel SPT Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 039/268] arm64: mdscr_el1: avoid exposing DCC to userspace Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 055/268] Thermal: initialize thermal zone device correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 052/268] [media] rc: sunxi-cir: Initialize the spinlock properly Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 017/268] time: Avoid signed overflow in timekeeping_get_ns() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 012/268] drm/amdgpu: call hpd_irq_event on resume Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 007/268] [media] si2157: return -EINVAL if firmware blob is too big Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 019/268] Bluetooth: Add support of Toshiba Broadcom based devices Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 016/268] arm64: Clear out any singlestep state on a ptrace detach operation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 015/268] ARM: mvebu: remove duplicated regulator definition in Armada 388 GP Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 011/268] KVM: x86: correctly print #AC in traces Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 005/268] [media] gspca: ov534/topro: prevent a division by 0 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 004/268] [media] vb2: fix a regression in poll() behavior for output,streams Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 018/268] ovl: root: copy attr Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 003/268] ovl: use a minimal buffer in ovl_copy_xattr Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 008/268] tools lib traceevent: Fix output of %llu for 64 bit values read on 32 bit machines Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 020/268] ext4 crypto: exit cleanly if ext4_derive_key_aes() fails Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 014/268] xhci: refuse loading if nousb is used Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 006/268] [media] media: dvb-core: Don't force CAN_INVERSION_AUTO in oneshot mode Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 009/268] cxl: use correct operator when writing pcie config space values Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 010/268] KVM: x86: expose MSR_TSC_AUX to userspace Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100

Page 1 of 13  [1] 2 3 … 13  Next page →


#1319730 — [4.2.y-ckt stable] Linux 4.2.8-ckt3 stable review

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:40 +0100
Subject[4.2.y-ckt stable] Linux 4.2.8-ckt3 stable review
Message-ID<qVF2F-Kd-3@gated-at.bofh.it>
This is the start of the review cycle for the Linux 4.2.8-ckt3 stable kernel.

This version contains 268 new patches, summarized below.  The new patches are
posted as replies to this message and also available in this git branch:

http://kernel.ubuntu.com/git/ubuntu/linux.git/log/?h=linux-4.2.y-review

git://kernel.ubuntu.com/ubuntu/linux.git  linux-4.2.y-review

The review period for version 4.2.8-ckt3 will be open for the next three days.
To report a problem, please reply to the relevant follow-up patch message.

For more information about the Linux 4.2.y-ckt extended stable kernel version,
see https://wiki.ubuntu.com/Kernel/Dev/ExtendedStable .

 -Kamal

--
 MAINTAINERS                                        |   6 +-
 arch/arm/Kconfig.debug                             |  17 +-
 arch/arm/boot/dts/armada-388-gp.dts                |  10 --
 arch/arm/boot/dts/r8a7740-armadillo800eva.dts      |   2 +-
 arch/arm/mach-imx/Kconfig                          |   1 +
 arch/arm64/kernel/perf_event.c                     |   3 -
 arch/arm64/kernel/ptrace.c                         |   6 +
 arch/arm64/mm/mmu.c                                |   3 +
 arch/arm64/mm/proc.S                               |   5 +-
 arch/m32r/kernel/setup.c                           |   3 +
 arch/m68k/atari/config.c                           |   4 +-
 arch/m68k/sun3/config.c                            |   2 +-
 arch/mips/include/asm/pgtable.h                    |   4 +-
 arch/mips/loongson64/loongson-3/hpet.c             |  10 +-
 arch/mips/loongson64/loongson-3/smp.c              |  20 ++-
 arch/mips/mm/tlbex.c                               |   2 +-
 arch/parisc/include/uapi/asm/siginfo.h             |   4 +
 arch/powerpc/include/asm/cmpxchg.h                 |  16 +-
 arch/powerpc/include/asm/synch.h                   |   2 +-
 arch/powerpc/include/uapi/asm/elf.h                |   2 +
 arch/powerpc/kernel/module_64.c                    |  27 ++++
 arch/powerpc/kernel/pci_of_scan.c                  |   3 -
 arch/s390/mm/extable.c                             |   8 +-
 arch/sparc/kernel/sys_sparc_64.c                   |   2 +-
 arch/um/os-Linux/start_up.c                        |   2 +
 arch/x86/include/asm/boot.h                        |   2 +-
 arch/x86/include/asm/mmu_context.h                 |  34 +++-
 arch/x86/kernel/cpu/perf_event.c                   |  11 +-
 arch/x86/kernel/cpu/perf_event_intel_ds.c          |   9 +-
 arch/x86/kernel/process_64.c                       |   2 +-
 arch/x86/kernel/reboot.c                           |   8 +
 arch/x86/kvm/trace.h                               |   2 +-
 arch/x86/kvm/x86.c                                 |  11 +-
 arch/x86/mm/tlb.c                                  |  29 +++-
 arch/x86/um/Makefile                               |   2 +-
 arch/x86/xen/suspend.c                             |   3 +-
 crypto/af_alg.c                                    |  55 ++++++-
 crypto/ahash.c                                     |   5 +-
 crypto/algif_hash.c                                | 165 +++++++++++++++++++-
 crypto/algif_skcipher.c                            | 172 +++++++++++++++++++--
 crypto/crc32c_generic.c                            |   1 -
 crypto/shash.c                                     |   4 +-
 drivers/acpi/acpi_lpss.c                           |   8 +-
 drivers/acpi/acpi_video.c                          |  18 +++
 drivers/base/firmware_class.c                      |   8 +-
 drivers/block/zram/zcomp.c                         |   4 +-
 drivers/block/zram/zcomp_lz4.c                     |  23 ++-
 drivers/block/zram/zcomp_lzo.c                     |  23 ++-
 drivers/block/zram/zram_drv.c                      |   7 +-
 drivers/bluetooth/btusb.c                          |   4 +
 drivers/char/tpm/tpm_tis.c                         |   2 +-
 drivers/clk/clk-xgene.c                            |   3 +-
 drivers/clk/samsung/clk-cpu.c                      |  10 +-
 drivers/clk/st/clkgen-fsyn.c                       |  17 +-
 drivers/clocksource/vt8500_timer.c                 |   6 +-
 drivers/connector/connector.c                      |  11 +-
 drivers/dma/at_xdmac.c                             |   3 +
 drivers/dma/dw/core.c                              |  44 ++----
 drivers/edac/edac_device.c                         |  11 +-
 drivers/edac/edac_mc.c                             |  14 +-
 drivers/edac/edac_mc_sysfs.c                       |  21 ++-
 drivers/edac/edac_pci.c                            |   9 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_device.c         |   1 +
 drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c             |  10 +-
 drivers/gpu/drm/drm_dp_mst_topology.c              | 141 ++++++++++++-----
 drivers/gpu/drm/i915/i915_gem_context.c            |   6 +-
 drivers/gpu/drm/i915/i915_irq.c                    |   9 +-
 drivers/gpu/drm/i915/intel_display.c               |  21 ++-
 drivers/gpu/drm/nouveau/nouveau_connector.c        |   3 +
 drivers/gpu/drm/nouveau/nvkm/engine/device/nv40.c  |   2 +-
 drivers/gpu/drm/radeon/dce6_afmt.c                 |  16 ++
 drivers/gpu/drm/radeon/radeon.h                    |   1 +
 drivers/gpu/drm/radeon/radeon_atombios.c           |  19 +--
 drivers/gpu/drm/radeon/radeon_device.c             |   1 +
 drivers/gpu/drm/radeon/radeon_vm.c                 |  12 +-
 drivers/gpu/drm/radeon/sid.h                       |   5 +
 drivers/hv/channel.c                               |  18 +++
 drivers/hv/hv_utils_transport.c                    |  18 ++-
 drivers/hwtracing/coresight/coresight.c            |   2 +-
 drivers/infiniband/core/cm.c                       |   4 +-
 drivers/infiniband/hw/mlx4/ah.c                    |   1 +
 drivers/infiniband/hw/mlx5/main.c                  |   2 +-
 drivers/infiniband/hw/qib/qib_qp.c                 |  46 ++++--
 drivers/infiniband/hw/qib/qib_verbs_mcast.c        |  35 ++---
 drivers/input/mouse/elantech.c                     |   2 +-
 drivers/input/serio/i8042-x86ia64io.h              |   7 +
 drivers/iommu/io-pgtable-arm.c                     |  11 +-
 drivers/md/bcache/btree.c                          |   5 +-
 drivers/md/bcache/super.c                          |  16 +-
 drivers/md/bcache/writeback.c                      |  37 ++++-
 drivers/md/bcache/writeback.h                      |   3 +-
 drivers/md/dm-exception-store.h                    |   2 +-
 drivers/md/dm-snap-persistent.c                    |   5 +-
 drivers/md/dm-snap-transient.c                     |   4 +-
 drivers/md/dm-snap.c                               |  20 +--
 drivers/md/dm-thin.c                               |   4 +-
 drivers/md/persistent-data/dm-space-map-metadata.c |   3 -
 drivers/media/dvb-core/dvb_frontend.c              |   6 +-
 drivers/media/rc/rc-main.c                         |   2 +-
 drivers/media/rc/sunxi-cir.c                       |   2 +
 drivers/media/tuners/si2157.c                      |   1 +
 drivers/media/usb/gspca/ov534.c                    |   9 +-
 drivers/media/usb/gspca/topro.c                    |   6 +-
 drivers/media/v4l2-core/videobuf2-core.c           |   6 +-
 drivers/misc/cxl/vphb.c                            |   2 +-
 drivers/mmc/core/debugfs.c                         |   2 +-
 drivers/mmc/core/mmc.c                             |   6 +-
 drivers/mmc/core/sd.c                              |  20 ++-
 drivers/mmc/core/sdio.c                            |   2 +-
 drivers/mmc/host/mmci.c                            |   2 +-
 drivers/mmc/host/sdhci-pci.c                       |   2 +-
 drivers/mmc/host/sdhci.c                           |  32 ++--
 drivers/mtd/nand/denali.c                          |  11 +-
 drivers/net/bonding/bond_main.c                    |   5 +-
 drivers/net/phy/micrel.c                           |  12 +-
 drivers/net/team/team.c                            |   6 +-
 drivers/net/usb/cdc_mbim.c                         |   2 +-
 drivers/net/usb/cdc_ncm.c                          |  31 ++++
 drivers/net/veth.c                                 |   6 -
 drivers/net/vxlan.c                                |  12 +-
 drivers/net/wireless/ath/ath9k/htc_hst.c           |   2 +-
 drivers/net/wireless/iwlwifi/pcie/drv.c            |   5 +-
 drivers/net/wireless/iwlwifi/pcie/trans.c          |  15 +-
 drivers/net/wireless/rtlwifi/pci.c                 |  11 +-
 drivers/net/wireless/rtlwifi/rtl8188ee/sw.c        |   7 +-
 drivers/net/wireless/rtlwifi/rtl8192ce/sw.c        |   2 +
 drivers/net/wireless/rtlwifi/rtl8192cu/sw.c        |   2 +
 drivers/net/wireless/rtlwifi/rtl8192de/sw.c        |   4 +-
 drivers/net/wireless/rtlwifi/rtl8192se/sw.c        |   6 +-
 drivers/net/wireless/rtlwifi/rtl8723ae/sw.c        |   9 ++
 drivers/net/wireless/rtlwifi/rtl8723be/sw.c        |   8 +-
 drivers/net/wireless/rtlwifi/rtl8821ae/sw.c        |   9 +-
 drivers/net/wireless/rtlwifi/usb.c                 |   2 +
 drivers/net/wireless/ti/wlcore/io.h                |  10 +-
 drivers/net/wireless/ti/wlcore/spi.c               |  10 +-
 drivers/pci/bus.c                                  |   6 +-
 drivers/pci/host/pci-dra7xx.c                      |   3 +-
 drivers/pci/host/pci-exynos.c                      |   3 +-
 drivers/pci/host/pci-imx6.c                        |   3 +-
 drivers/pci/host/pci-tegra.c                       |   2 +-
 drivers/pci/host/pcie-rcar.c                       |   6 +-
 drivers/pci/host/pcie-spear13xx.c                  |   3 +-
 drivers/pci/host/pcie-xilinx.c                     |   3 +-
 drivers/pci/probe.c                                |   7 +-
 drivers/pinctrl/bcm/pinctrl-bcm2835.c              |   2 +-
 drivers/platform/x86/ideapad-laptop.c              |  14 ++
 drivers/power/test_power.c                         |   2 +
 drivers/regulator/axp20x-regulator.c               |   4 +-
 drivers/scsi/initio.c                              |  16 --
 drivers/scsi/scsi_devinfo.c                        |   1 +
 drivers/staging/media/lirc/lirc_imon.c             |   2 +
 drivers/target/iscsi/iscsi_target_configfs.c       |  16 +-
 drivers/target/target_core_configfs.c              |   6 +-
 drivers/thermal/step_wise.c                        |  17 +-
 drivers/thermal/thermal_core.c                     |  75 ++++++++-
 drivers/thermal/thermal_core.h                     |   1 +
 drivers/tty/sysrq.c                                |   6 +
 drivers/usb/host/xhci.c                            |   4 +
 drivers/usb/serial/cp210x.c                        |   1 +
 drivers/virtio/virtio_balloon.c                    |   2 +-
 fs/btrfs/ctree.h                                   |   2 +-
 fs/btrfs/disk-io.c                                 |   5 +-
 fs/btrfs/extent-tree.c                             |  11 +-
 fs/btrfs/inode.c                                   |   4 -
 fs/btrfs/volumes.c                                 |   9 ++
 fs/cifs/cifs_debug.c                               |   2 +-
 fs/cifs/cifs_debug.h                               |   9 +-
 fs/cifs/connect.c                                  |   2 +-
 fs/cifs/readdir.c                                  |   1 +
 fs/cifs/transport.c                                |   6 +-
 fs/ext4/crypto_key.c                               |   6 +
 fs/hostfs/hostfs_kern.c                            |   4 +-
 fs/locks.c                                         |  51 +++---
 fs/nfs/dir.c                                       |  21 ++-
 fs/nfs/flexfilelayout/flexfilelayout.c             |   6 +-
 fs/nfs/inode.c                                     |  54 +++++--
 fs/nfs/nfs4proc.c                                  |   2 +-
 fs/ocfs2/dlm/dlmmaster.c                           |  26 ++--
 fs/ocfs2/dlmglue.c                                 |   6 +
 fs/overlayfs/copy_up.c                             |  41 +++--
 fs/overlayfs/inode.c                               |  13 ++
 fs/overlayfs/readdir.c                             |   3 +-
 fs/overlayfs/super.c                               |   5 +
 fs/udf/inode.c                                     |  15 ++
 fs/udf/unicode.c                                   |  21 ++-
 fs/xfs/libxfs/xfs_dquot_buf.c                      |  35 ++++-
 fs/xfs/libxfs/xfs_format.h                         |   2 +-
 fs/xfs/libxfs/xfs_inode_buf.c                      |  14 +-
 fs/xfs/libxfs/xfs_quota_defs.h                     |   2 +-
 fs/xfs/libxfs/xfs_shared.h                         |   1 +
 fs/xfs/xfs_buf.c                                   |  17 ++
 fs/xfs/xfs_log_recover.c                           |   9 +-
 include/crypto/hash.h                              |   6 +
 include/crypto/if_alg.h                            |  11 +-
 include/drm/drm_dp_mst_helper.h                    |   2 -
 include/linux/ceph/messenger.h                     |   2 +-
 include/linux/console.h                            |   1 +
 include/linux/hyperv.h                             |  18 +++
 include/linux/memblock.h                           |   4 +-
 include/linux/mlx4/device.h                        |   4 -
 include/linux/mtd/nand.h                           |   4 +-
 include/linux/pci.h                                |   2 -
 include/linux/printk.h                             |  12 +-
 include/linux/sched.h                              |   1 +
 include/linux/shmem_fs.h                           |   5 +-
 include/linux/skbuff.h                             |   3 +-
 include/linux/thermal.h                            |   5 +
 include/linux/usb/cdc_ncm.h                        |   1 +
 include/linux/vmstat.h                             |   2 +
 include/net/inet_ecn.h                             |  19 ++-
 include/net/sock.h                                 |  10 +-
 kernel/bpf/verifier.c                              |  10 ++
 kernel/futex.c                                     |   5 +
 kernel/panic.c                                     |  12 ++
 kernel/printk/printk.c                             |  35 ++++-
 kernel/sched/idle.c                                |   1 +
 kernel/sys.c                                       |  20 +--
 kernel/time/posix-clock.c                          |   4 +-
 kernel/time/timekeeping.c                          |   3 +-
 lib/Kconfig                                        |   2 +
 lib/dma-debug.c                                    |   2 +-
 lib/libcrc32c.c                                    |   1 +
 mm/balloon_compaction.c                            |   4 +-
 mm/memcontrol.c                                    |  11 +-
 mm/memory-failure.c                                |   2 +-
 mm/shmem.c                                         |   9 +-
 mm/vmstat.c                                        |  69 ++++++---
 mm/zsmalloc.c                                      |  14 +-
 net/batman-adv/bridge_loop_avoidance.c             |  10 +-
 net/batman-adv/hard-interface.h                    |  12 --
 net/batman-adv/network-coding.c                    |  19 +--
 net/batman-adv/originator.c                        | 149 +++++++-----------
 net/batman-adv/originator.h                        |   1 -
 net/batman-adv/translation-table.c                 |  28 ++--
 net/bridge/br_device.c                             |   8 +
 net/bridge/br_stp_if.c                             |   5 +-
 net/ceph/messenger.c                               |  76 ++++++---
 net/core/dev.c                                     |   5 +
 net/core/filter.c                                  |   5 +
 net/ipv4/ip_output.c                               |   3 +-
 net/ipv4/tcp_yeah.c                                |   2 +-
 net/ipv4/xfrm4_policy.c                            |  46 ++++--
 net/ipv6/ip6_output.c                              |   2 +-
 net/ipv6/tcp_ipv6.c                                |   2 +
 net/ipv6/xfrm6_mode_tunnel.c                       |   2 +-
 net/ipv6/xfrm6_policy.c                            |  53 +++++--
 net/mac80211/offchannel.c                          |   5 +-
 net/openvswitch/datapath.c                         |   5 +-
 net/phonet/af_phonet.c                             |   4 +
 net/sched/cls_flower.c                             |  10 +-
 net/sctp/sm_statefuns.c                            |   6 +-
 net/sctp/socket.c                                  |   3 +-
 net/sctp/sysctl.c                                  |   2 +-
 net/unix/af_unix.c                                 |  90 +++++++----
 net/unix/garbage.c                                 |  13 +-
 net/xfrm/xfrm_output.c                             |   2 +
 net/xfrm/xfrm_policy.c                             |  38 -----
 scripts/Makefile.extrawarn                         |   2 +
 scripts/bloat-o-meter                              |   8 +-
 scripts/kconfig/menu.c                             |   2 +-
 scripts/recordmcount.pl                            |   3 +-
 sound/core/control.c                               |   2 +
 sound/core/hrtimer.c                               |   3 +-
 sound/core/pcm_compat.c                            |  13 +-
 sound/core/seq/seq_clientmgr.c                     |   2 +-
 sound/core/seq/seq_compat.c                        |   9 +-
 sound/core/seq/seq_queue.c                         |   2 +
 sound/core/timer.c                                 | 100 +++++++++---
 sound/pci/fm801.c                                  |  73 +++++----
 sound/pci/hda/hda_intel.c                          |  10 +-
 sound/pci/hda/patch_realtek.c                      |  15 ++
 sound/soc/intel/atom/sst/sst_stream.c              |   2 +-
 sound/soc/soc-compress.c                           |  23 ++-
 sound/soc/tegra/tegra_alc5632.c                    |  12 +-
 sound/usb/mixer_quirks.c                           |   2 +-
 sound/usb/quirks.c                                 |   1 +
 tools/hv/hv_vss_daemon.c                           |   2 +-
 tools/lib/traceevent/event-parse.c                 |   5 +-
 278 files changed, 2482 insertions(+), 1045 deletions(-)

Aaron Conole (1):
      printk: help pr_debug and pr_devel to optimize out arguments

Adrian Hunter (4):
      mmc: sdhci-pci: Do not default to 33 Ohm driver strength for Intel SPT
      mmc: sdio: Fix invalid vdd in voltage switch power cycle
      mmc: sdhci: Fix DMA descriptor with zero data length
      mmc: sdhci: Fix sdhci_runtime_pm_bus_on/off()

Al Viro (2):
      bcache: fix a leak in bch_cached_dev_run()
      make sure that freeing shmem fast symlinks is RCU-delayed

Alex Deucher (3):
      drm/amdgpu: call hpd_irq_event on resume
      drm/radeon: call hpd_irq_event on resume
      drm/radeon: clean up fujitsu quirks

Alexey Khoroshilov (1):
      [media] lirc_imon: do not leave imon_probe() with mutex held

Andrew Donnellan (1):
      cxl: use correct operator when writing pcie config space values

Andrew Elble (1):
      nfs: Fix race in __update_open_stateid()

Andrew Gabbasov (2):
      udf: Prevent buffer overrun with multi-byte characters
      udf: Check output buffer length when converting name to CS0

Andy Lutomirski (2):
      x86/mm: Add barriers and document switch_mm()-vs-flush synchronization
      x86/mm: Improve switch_mm() barrier comments

Andy Shevchenko (4):
      Revert "ACPI / LPSS: allow to use specific PM domain during ->probe()"
      ALSA: fm801: explicitly free IRQ line
      ALSA: fm801: propagate TUNER_ONLY bit when autodetected
      ALSA: fm801: detect FM-only card earlier

Ani Sinha (1):
      sysrq: Fix warning in sysrq generated crash.

Antonio Ospite (1):
      [media] gspca: ov534/topro: prevent a division by 0

Ard Biesheuvel (1):
      s390: fix normalization bug in exception table sorting

Arnd Bergmann (5):
      lib: sw842: select crc32
      ARM: debug-ll: fix BCM63xx entry for multiplatform
      SCSI: initio: remove duplicate module device table
      clk: st: avoid uninitialized variable use
      ARM: imx: select SRC for i.MX7

Aurélien Francillon (1):
      Input: i8042 - add Fujitsu Lifebook U745 to the nomux list

Bart Van Assche (2):
      IB/cm: Fix a recently introduced deadlock
      target: Fix a memory leak in target_dev_lba_map_store()

Ben Skeggs (1):
      drm/nouveau/kms: take mode_config mutex in connector hotplug path

Benjamin Tissoires (1):
      Input: elantech - mark protocols v2 and v3 as semi-mt

Bjørn Mork (1):
      net: cdc_ncm: avoid changing RX/TX buffers on MTU changes

Boqun Feng (2):
      powerpc: Make value-returning atomics fully ordered
      powerpc: Make {cmp}xchg* and their atomic_ versions fully ordered

Boris BREZILLON (2):
      mtd: nand: fix ONFI parameter page layout
      mtd: nand: denali: add missing nand_release() call in denali_remove()

Borislav Petkov (2):
      EDAC, mc_sysfs: Fix freeing bus' name
      EDAC: Robustify workqueues destruction

Brian Norris (1):
      firmware: actually return NULL on failed request_firmware_nowait()

Chen Yu (1):
      Thermal: do thermal zone update after a cooling device registered

Chen-Yu Tsai (2):
      regulator: axp20x: Fix GPIO LDO enable value for AXP22x
      [media] rc: sunxi-cir: Initialize the spinlock properly

Chris Wilson (1):
      drm/i915: Restore inhibiting the load of the default context

Christoph Biedl (1):
      PCI: Fix minimum allocation address overwrite

Christoph Lameter (1):
      vmstat: make vmstat_updater deferrable again and shut down on idle

Chuanxiao Dong (1):
      mmc: debugfs: correct wrong voltage value

Dan Carpenter (3):
      ASoC: Intel: pass correct parameter in sst_alloc_stream_mrfld()
      ath9k_htc: check for underflow in ath9k_htc_rx_msg()
      Btrfs: clean up an error code in btrfs_init_space_info()

Dan Streetman (1):
      xfrm: dst_entries_init() per-net dst_ops

Darrick J. Wong (1):
      libxfs: pack the agfl header structure so XFS_AGFL_SIZE is correct

Dave Chinner (3):
      xfs: inode recovery readahead can race with inode buffer creation
      xfs: handle dquot buffer readahead in log recovery correctly
      xfs: log mount failures don't wait for buffers to be released

David Gibson (1):
      time: Avoid signed overflow in timekeeping_get_ns()

David Henningsson (1):
      ALSA: hda - Fixup inverted internal mic for Lenovo E50-80

David Sterba (1):
      btrfs: handle invalid num_stripes in sys_array

Dexuan Cui (1):
      tools: hv: vss: fix the write()'s argument: error -> vss_msg

Dmitry Tunin (1):
      Bluetooth: Add support of Toshiba Broadcom based devices

Dmitry V. Levin (1):
      sparc64: fix incorrect sign extension in sys_sparc64_personality

Emmanuel Grumbach (1):
      iwlwifi: pcie: properly configure the debug buffer size for 8000

Eric Dumazet (3):
      ipv6: tcp: add rcu locking in tcp_v6_send_synack()
      phonet: properly unshare skbs in phonet_rcv()
      ipv6: update skb->csum when CE mark is propagated

Felix Kuehling (2):
      drm/radeon: Fix off-by-one errors in radeon_vm_bo_set_addr
      drm/amdgpu: Fix off-by-one errors in amdgpu_vm_bo_map

Filipe Manana (1):
      Btrfs: fix deadlock running delayed iputs at transaction commit time

Finn Thain (1):
      m68k/atari, m68k/sun3: Fix SCSI platform device registration when driver is modular

Florian Fainelli (2):
      MAINTAINERS: gpio-brcmstb: Remove stray '>'
      include/linux/memblock.h: fix ordering of 'flags' argument in comments

Florian Westphal (1):
      connector: bump skb->users before callback invocation

Gabriel de Perthuis (1):
      bcache: allows use of register in udev to avoid "device_busy" error.

Geert Uytterhoeven (1):
      ARM: dts: armadillo800eva Correct extal1 frequency to 24 MHz

Grygorii Strashko (1):
      PCI: host: Mark PCIe/PCI (MSI) IRQ cascade handlers as IRQF_NO_THREAD

Guilherme G. Piccoli (1):
      PCI/MSI: Initialize MSI capability for all architectures

H.J. Lu (1):
      x86/boot: Double BOOT_HEAP_SIZE to 64KB

Hannes Frederic Sowa (1):
      bridge: Only call /sbin/bridge-stp for the initial network namespace

Hans Verkuil (1):
      [media] vb2: fix a regression in poll() behavior for output,streams

Hans de Goede (3):
      drm/nouveau/nv46: Change mc subdev oclass from nv44 to nv4c
      ACPI / video: Add disable_backlight_sysfs_if quirk for the Toshiba Portege R700
      ACPI / video: Add disable_backlight_sysfs_if quirk for the Toshiba Satellite R830

Helge Deller (1):
      parisc: Fix __ARCH_SI_PREAMBLE_SIZE

Herbert Xu (15):
      crypto: algif_skcipher - Require setkey before accept(2)
      crypto: af_alg - Disallow bind/setkey/... after accept(2)
      crypto: af_alg - Fix socket double-free when accept fails
      crypto: af_alg - Add nokey compatibility path
      crypto: algif_skcipher - Add nokey compatibility path
      crypto: hash - Add crypto_ahash_has_setkey
      crypto: algif_hash - Require setkey before accept(2)
      crypto: af_alg - Allow af_af_alg_release_parent to be called on nokey path
      crypto: algif_hash - Remove custom release parent function
      crypto: algif_skcipher - Remove custom release parent function
      crypto: af_alg - Forbid bind(2) when nokey child sockets are present
      crypto: algif_hash - Fix race condition in hash_check_key
      crypto: algif_skcipher - Fix race condition in skcipher_check_key
      crypto: algif_skcipher - Load TX SG list after waiting
      crypto: algif_skcipher - sendmsg SG marking is off by one

Huacai Chen (3):
      MIPS: Loongson-3: Fix SMP_ASK_C0COUNT IPI handler
      MIPS: hpet: Choose a safe value for the ETIME check
      MIPS: Fix some missing CONFIG_CPU_MIPSR6 #ifdefs

Hui Wang (1):
      ALSA: hda - fix the headset mic detection problem for a Dell laptop

Ido Schimmel (1):
      team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid

Ilya Dryomov (1):
      libceph: fix ceph_msg_revoke()

Jamal Hadi Salim (1):
      sched,cls_flower: set key address type when present

Jamie Bainbridge (1):
      cifs: Ratelimit kernel log messages

Jan Beulich (1):
      x86/LDT: Print the real LDT base address

Jason Gunthorpe (1):
      tpm_tis: Use devm_free_irq not free_irq

Jean Delvare (1):
      crypto: crc32c - Fix crc32c soft dependency

Jeff Layton (1):
      locks: fix unlock when fcntl_setlk races with a close

Jerome Marchand (1):
      zram: don't call idr_remove() from zram_remove()

Jisheng Zhang (1):
      mmc: sdhci: restore behavior when setting VDD via external regulator

Johannes Berg (1):
      mac80211: fix mgmt-tx abort cookie and leak

Johannes Weiner (1):
      net: tcp_memcontrol: properly detect ancestor socket pressure

John Blackwood (1):
      arm64: Clear out any singlestep state on a ptrace detach operation

Josh Boyer (2):
      ideapad-laptop: Add Lenovo ideapad Y700-17ISK to no_hw_rfkill dmi list
      ideapad-laptop: Add Lenovo Yoga 700 to no_hw_rfkill dmi list

Junil Lee (1):
      zsmalloc: fix migrate_zspage-zs_free race condition

Jurgen Kramer (1):
      ALSA: usb: Add native DSD support for Oppo HA-1

K. Y. Srinivasan (1):
      Drivers: hv: vmbus: Fix a Host signaling bug

Karl Heiss (1):
      bonding: Prevent IPv6 link local address on enslaved devices

Kent Overstreet (2):
      bcache: Add a cond_resched() call to gc
      bcache: Change refill_dirty() to always scan entire disk if necessary

Konstantin Khlebnikov (2):
      ovl: check dentry positiveness in ovl_cleanup_whiteouts()
      net: preserve IP control block during GSO segmentation

Kyeongdon Kim (1):
      zram: try vmalloc() after kmalloc()

Larry Finger (9):
      rtlwifi: rtl8723be: Fix module parameter initialization
      rtlwifi: rtl8723ae: Fix initialization of module parameters
      rtlwifi: rtl8821ae: Fix errors in parameter initialization
      rtlwifi: rtl8188ee: Fix module parameter initialization
      rtlwifi: rtl8192de: Fix incorrect module parameter descriptions
      rtlwifi: rtl8192se: Fix module parameter initialization
      rtlwifi: rtl8192ce: Fix handling of module parameters
      rtlwifi: rtl8192cu: Add missing parameter setup
      rtlwifi: rtl_pci: Fix kernel panic

Laura Abbott (2):
      [media] si2157: return -EINVAL if firmware blob is too big
      dma-debug: switch check from _text to _stext

Laurent Navet (1):
      ext4 crypto: exit cleanly if ext4_derive_key_aes() fails

Lee Jones (1):
      kbuild: Demote 'sign-compare' warning to W=2

Leon Romanovsky (1):
      IB/mlx5: Expose correct maximum number of CQE capacity

Linus Walleij (1):
      mmc: mmci: fix an ages old detection error

Loc Ho (1):
      clk: xgene: Fix divider with non-zero shift value

Lorenzo Pieralisi (1):
      arm64: kernel: enforce pmuserenr_el0 initialization and restore

Lukas Wunner (1):
      drm/i915: On fb alloc failure, unref gem object where it gets refed

Lyude (1):
      drm/i915: intel_hpd_init(): Fix suspend/resume reprobing

Malcolm Priestley (1):
      [media] media: dvb-core: Don't force CAN_INVERSION_AUTO in oneshot mode

Mans Rullgard (2):
      dmaengine: dw: fix cyclic transfer setup
      dmaengine: dw: fix cyclic transfer callbacks

Marek Szyprowski (1):
      clk: exynos: use irqsave version of spin_lock to avoid deadlock with irqs

Mario Kleiner (1):
      x86/reboot/quirks: Add iMac10,1 to pci_reboot_dmi_table[]

Martijn Coenen (1):
      memcg: only free spare array when readers are done

Matan Barak (1):
      IB/mlx4: Initialize hop_limit when creating address handle

Mateusz Guzik (1):
      prctl: take mmap sem for writing to protect against others

Mathieu Poirier (1):
      coresight: checking for NULL string in coresight_name_match()

Michal Kubeček (1):
      udp: disallow UFO for sockets with SO_NO_CHECK option

Mickaël Salaün (1):
      um: Fix build error and kconfig for i386

Mike Christie (1):
      scsi: add Synology to 1024 sector blacklist

Mike Marciniszyn (1):
      IB/qib: fix mcast detach when qp not attached

Mike Snitzer (1):
      dm space map metadata: remove unused variable in brb_pop()

Miklos Szeredi (3):
      ovl: allow zero size xattr
      ovl: root: copy attr
      ovl: setattr: check permissions before copy-up

Mikulas Patocka (1):
      dm snapshot: fix hung bios when copy error occurs

Minchan Kim (2):
      virtio_balloon: fix race by fill and leak
      virtio_balloon: fix race between migration and ballooning

Moni Shoua (1):
      net/mlx4: Remove unused macro

Mykola Lysenko (4):
      drm/dp/mst: process broadcast messages correctly
      drm/dp/mst: always send reply for UP request
      drm/dp/mst: fix in MSTB RAD initialization
      drm/dp/mst: fix in RAD element access

Naoya Horiguchi (1):
      mm: soft-offline: check return value in second __get_any_page() call

Neal Cardwell (1):
      tcp_yeah: don't set ssthresh below 2

Nicholas Bellinger (1):
      iscsi-target: Fix potential dead-lock during node acl delete

Nicolas Boichat (2):
      ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode
      ALSA: seq: Fix snd_seq_call_port_info_ioctl in compat mode

Nicolas Dichtel (1):
      vxlan: fix test which detect duplicate vxlan iface

Nikolay Aleksandrov (1):
      bridge: fix lockdep addr_list_lock false positive splat

Nikolay Borisov (1):
      dm thin: fix race condition when destroying thin pool workqueue

Olaf Hering (2):
      Drivers: hv: util: catch allocation errors
      Drivers: hv: utils: use memdup_user in hvt_op_write

Oliver Freyermuth (1):
      USB: cp210x: add ID for ELV Marble Sound Board 1

Oliver Neukum (1):
      xhci: refuse loading if nousb is used

Oren Givon (1):
      iwlwifi: update and fix 7265 series PCI IDs

Ouyang Zhaowei (Charles) (1):
      x86/xen: don't reset vcpu_info on a cancelled suspend

Paolo Bonzini (2):
      KVM: x86: expose MSR_TSC_AUX to userspace
      KVM: x86: correctly print #AC in traces

Peter Wu (1):
      rtlwifi: fix memory leak for USB device

Rabin Vincent (2):
      cifs: fix race between call_async() and reconnect()
      net: bpf: reject invalid shifts

Rainer Weikusat (1):
      af_unix: Fix splice-bind deadlock

Rich Felker (1):
      MAINTAINERS: return arch/sh to maintained state, with new maintainers

Richard Cochran (1):
      posix-clock: Fix return code on the poll method's error path

Roman Volkov (1):
      clocksource/drivers/vt8500: Increase the minimum delta

Roosen Henri (1):
      phy: micrel: Fix finding PHY properties in MAC node for KSZ9031.

Russell King (2):
      [media] rc: allow rc modules to be loaded if rc-main is not a module
      mmc: sd: limit SD card power limit according to cards capabilities

Sasha Levin (2):
      power: test_power: correctly handle empty writes
      net: sctp: prevent writes to cookie_hmac_alg from accessing invalid memory

Sebastian Andrzej Siewior (1):
      btrfs: initialize the seq counter in struct btrfs_device

Sergey Senozhatsky (2):
      scripts/bloat-o-meter: fix python3 syntax error
      zram/zcomp: use GFP_NOIO to allocate streams

Slava Grigorev (1):
      drm/radeon: Fix "slow" audio over DP on DCE8+

Songjun Wu (1):
      dmaengine: at_xdmac: fix resume for cyclic transfers

Stefan Bader (1):
      bcache: prevent crash on changing writeback_running

Stefan Wahren (1):
      pinctrl: bcm2835: Fix memory leak in error path

Stephane Eranian (2):
      perf/x86: Fix filter_events() bug with event mappings
      perf/x86: fix PEBS issues on Intel Atom/Core2

Steven Rostedt (1):
      tools lib traceevent: Fix output of %llu for 64 bit values read on 32 bit machines

Sudip Mukherjee (2):
      m32r: fix m32104ut_defconfig build fail
      ASoC: tegra_alc5632: check return value

Sven Eckelmann (7):
      batman-adv: Avoid recursive call_rcu for batadv_bla_claim
      batman-adv: Avoid recursive call_rcu for batadv_nc_node
      batman-adv: Drop immediate batadv_orig_ifinfo free function
      batman-adv: Drop immediate batadv_neigh_node free function
      batman-adv: Drop immediate neigh_ifinfo free function
      batman-adv: Drop immediate orig_node free function
      batman-adv: Drop immediate batadv_hard_iface free function

Takashi Iwai (13):
      ALSA: seq: Fix missing NULL check at remove_events ioctl
      ALSA: seq: Fix race at timer setup and close
      ALSA: hda - Fix white noise on Dell Latitude E5550
      ALSA: usb-audio: Fix mixer ctl regression of Native Instrument devices
      ALSA: timer: Fix double unlink of active_list
      ALSA: timer: Fix race among timer ioctls
      ALSA: hda - Add fixup for Dell Latitidue E6540
      ALSA: timer: Harden slave timer list handling
      ALSA: hda - Fix bass pin fixup for ASUS N550JX
      ALSA: hrtimer: Fix stall by hrtimer_cancel()
      ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0
      ALSA: hda - Flush the pending probe work at remove
      ALSA: timer: Handle disconnection more safely

Tariq Saeed (1):
      ocfs2: NFS hangs in __ocfs2_cluster_lock due to race with ocfs2_unblock_lock

Tejun Heo (1):
      printk: do cond_resched() between lines while outputting to consoles

Theodore Ts'o (1):
      ext4 crypto: add missing locking for keyring_key access

Thomas Gleixner (1):
      futex: Drop refcount if requeue_pi() acquired the rtmutex

Thomas Petazzoni (1):
      ARM: mvebu: remove duplicated regulator definition in Armada 388 GP

Trond Myklebust (4):
      NFS: Fix attribute cache revalidation
      pNFS/flexfiles: Fix an XDR encoding bug in layoutreturn
      NFSv4: Don't perform cached access checks before we've OPENed the file
      NFS: Ensure we revalidate attributes before using execute_ok()

Ulrich Weigand (2):
      scripts/recordmcount.pl: support data in text section on powerpc
      powerpc/module: Handle R_PPC64_ENTRY relocations

Uri Mashiach (2):
      wlcore/wl12xx: spi: fix oops on firmware load
      wlcore/wl12xx: spi: fix NULL pointer dereference (Oops)

Vasily Averin (1):
      cifs_dbg() outputs an uninitialized buffer in cifs_readdir()

Vegard Nossum (4):
      udf: limit the maximum number of indirect extents in a row
      uml: fix hostfs mknod()
      uml: flush stdout before forking
      kconfig: return 'false' instead of 'no' in bool function

Vijay Pandurangan (1):
      veth: don’t modify ip_summed; doing so treats packets with bad checksums as good.

Vinit Agnihotri (1):
      IB/qib: Support creating qps with GFP_NOIO flag

Vinod Koul (1):
      ASoC: compress: Fix compress device direction check

Vitaly Kuznetsov (2):
      panic: release stale console lock to always get the logbuf printed out
      kernel/panic.c: turn off locks debug before releasing console lock

Vito Caputo (1):
      ovl: use a minimal buffer in ovl_copy_xattr

Wenkai Du (1):
      mmc: mmc: Fix incorrect use of driver strength switching HS200 and HS400

Will Deacon (3):
      arm64: mm: ensure that the zero page is visible to the page table walker
      iommu/io-pgtable-arm: Ensure we free the final level on teardown
      arm64: mdscr_el1: avoid exposing DCC to userspace

Xin Long (1):
      sctp: sctp should release assoc when sctp_make_abort_user return NULL in sctp_close

Zhang Rui (2):
      Thermal: initialize thermal zone device correctly
      Thermal: handle thermal zone device properly during system sleep

Zheng Liu (3):
      bcache: fix a livelock when we cause a huge number of cache misses
      bcache: clear BCACHE_DEV_UNLINK_DONE flag when attaching a backing device
      bcache: unregister reboot notifier if bcache fails to unregister device

willy tarreau (1):
      unix: properly account for FDs passed over unix sockets

xuejiufei (1):
      ocfs2/dlm: ignore cleaning the migration mle that is inuse

[toc] | [next] | [standalone]


#1319732 — [PATCH 4.2.y-ckt 051/268] udf: limit the maximum number of indirect extents in a row

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:40 +0100
Subject[PATCH 4.2.y-ckt 051/268] udf: limit the maximum number of indirect extents in a row
Message-ID<qVF2I-Kd-67@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Vegard Nossum <vegard.nossum@oracle.com>

commit b0918d9f476a8434b055e362b83fa4fd1d462c3f upstream.

udf_next_aext() just follows extent pointers while extents are marked as
indirect. This can loop forever for corrupted filesystem. Limit number
the of indirect extents we are willing to follow in a row.

[JK: Updated changelog, limit, style]

Signed-off-by: Vegard Nossum <vegard.nossum@oracle.com>
Cc: Jan Kara <jack@suse.com>
Cc: Quentin Casasnovas <quentin.casasnovas@oracle.com>
Cc: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/udf/inode.c | 15 +++++++++++++++
 1 file changed, 15 insertions(+)

diff --git a/fs/udf/inode.c b/fs/udf/inode.c
index 8d0b3ad..566df9b 100644
--- a/fs/udf/inode.c
+++ b/fs/udf/inode.c
@@ -2047,14 +2047,29 @@ void udf_write_aext(struct inode *inode, struct extent_position *epos,
 		epos->offset += adsize;
 }
 
+/*
+ * Only 1 indirect extent in a row really makes sense but allow upto 16 in case
+ * someone does some weird stuff.
+ */
+#define UDF_MAX_INDIR_EXTS 16
+
 int8_t udf_next_aext(struct inode *inode, struct extent_position *epos,
 		     struct kernel_lb_addr *eloc, uint32_t *elen, int inc)
 {
 	int8_t etype;
+	unsigned int indirections = 0;
 
 	while ((etype = udf_current_aext(inode, epos, eloc, elen, inc)) ==
 	       (EXT_NEXT_EXTENT_ALLOCDECS >> 30)) {
 		int block;
+
+		if (++indirections > UDF_MAX_INDIR_EXTS) {
+			udf_err(inode->i_sb,
+				"too many indirect extents in inode %lu\n",
+				inode->i_ino);
+			return -1;
+		}
+
 		epos->block = *eloc;
 		epos->offset = sizeof(struct allocExtDesc);
 		brelse(epos->bh);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319734 — [PATCH 4.2.y-ckt 002/268] ovl: allow zero size xattr

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:40 +0100
Subject[PATCH 4.2.y-ckt 002/268] ovl: allow zero size xattr
Message-ID<qVF2I-Kd-71@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Miklos Szeredi <miklos@szeredi.hu>

commit 97daf8b97ad6f913a34c82515be64dc9ac08d63e upstream.

When ovl_copy_xattr() encountered a zero size xattr no more xattrs were
copied and the function returned success.  This is clearly not the desired
behavior.

Signed-off-by: Miklos Szeredi <miklos@szeredi.hu>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/overlayfs/copy_up.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/overlayfs/copy_up.c b/fs/overlayfs/copy_up.c
index 871fcb6..394e87f 100644
--- a/fs/overlayfs/copy_up.c
+++ b/fs/overlayfs/copy_up.c
@@ -54,7 +54,7 @@ int ovl_copy_xattr(struct dentry *old, struct dentry *new)
 
 	for (name = buf; name < (buf + list_size); name += strlen(name) + 1) {
 		size = vfs_getxattr(old, name, value, XATTR_SIZE_MAX);
-		if (size <= 0) {
+		if (size < 0) {
 			error = size;
 			goto out_free_value;
 		}
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319735 — [PATCH 4.2.y-ckt 001/268] drm/nouveau/nv46: Change mc subdev oclass from nv44 to nv4c

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:40 +0100
Subject[PATCH 4.2.y-ckt 001/268] drm/nouveau/nv46: Change mc subdev oclass from nv44 to nv4c
Message-ID<qVF2J-Kd-77@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Hans de Goede <hdegoede@redhat.com>

commit 0a363e85cdafbceeee6a49b91c604d0d4d070dc7 upstream.

MSI interrupts appear to not work for nv46 based cards. Change the mc
subdev oclass for these cards from nv44 to nv4c, the nv4c mc code is
identical to the nv44 mc code except that it does not use msi
(it does not define a msi_rearm callback).

BugLink: https://bugs.freedesktop.org/show_bug.cgi?id=90435
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Ben Skeggs <bskeggs@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/gpu/drm/nouveau/nvkm/engine/device/nv40.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/nouveau/nvkm/engine/device/nv40.c b/drivers/gpu/drm/nouveau/nvkm/engine/device/nv40.c
index c630136..b4ad791 100644
--- a/drivers/gpu/drm/nouveau/nvkm/engine/device/nv40.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/device/nv40.c
@@ -265,7 +265,7 @@ nv40_identify(struct nvkm_device *device)
 		device->oclass[NVDEV_SUBDEV_CLK    ] = &nv40_clk_oclass;
 		device->oclass[NVDEV_SUBDEV_THERM  ] = &nv40_therm_oclass;
 		device->oclass[NVDEV_SUBDEV_DEVINIT] =  nv1a_devinit_oclass;
-		device->oclass[NVDEV_SUBDEV_MC     ] =  nv44_mc_oclass;
+		device->oclass[NVDEV_SUBDEV_MC     ] =  nv4c_mc_oclass;
 		device->oclass[NVDEV_SUBDEV_BUS    ] =  nv31_bus_oclass;
 		device->oclass[NVDEV_SUBDEV_TIMER  ] = &nv04_timer_oclass;
 		device->oclass[NVDEV_SUBDEV_FB     ] =  nv46_fb_oclass;
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319736 — [PATCH 4.2.y-ckt 147/268] ALSA: hda - Fix bass pin fixup for ASUS N550JX

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:40 +0100
Subject[PATCH 4.2.y-ckt 147/268] ALSA: hda - Fix bass pin fixup for ASUS N550JX
Message-ID<qVF2I-Kd-73@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit db8948e653e12b218058bb6696f4a33fa7845f64 upstream.

ASUS N550JX (PCI SSID 1043:13df) requires the same fixup for a bass
speaker output pin as other N550 models.

Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=110001
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/pci/hda/patch_realtek.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index c337197..7cace05 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -6774,6 +6774,7 @@ static const struct snd_pci_quirk alc662_fixup_tbl[] = {
 	SND_PCI_QUIRK(0x1028, 0x069f, "Dell", ALC668_FIXUP_DELL_MIC_NO_PRESENCE),
 	SND_PCI_QUIRK(0x103c, 0x1632, "HP RP5800", ALC662_FIXUP_HP_RP5800),
 	SND_PCI_QUIRK(0x1043, 0x11cd, "Asus N550", ALC662_FIXUP_BASS_1A),
+	SND_PCI_QUIRK(0x1043, 0x13df, "Asus N550JX", ALC662_FIXUP_BASS_1A),
 	SND_PCI_QUIRK(0x1043, 0x1477, "ASUS N56VZ", ALC662_FIXUP_BASS_MODE4_CHMAP),
 	SND_PCI_QUIRK(0x1043, 0x15a7, "ASUS UX51VZH", ALC662_FIXUP_BASS_16),
 	SND_PCI_QUIRK(0x1043, 0x1b73, "ASUS N55SF", ALC662_FIXUP_BASS_16),
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319738 — [PATCH 4.2.y-ckt 057/268] Thermal: do thermal zone update after a cooling device registered

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:40 +0100
Subject[PATCH 4.2.y-ckt 057/268] Thermal: do thermal zone update after a cooling device registered
Message-ID<qVF2J-Kd-79@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Chen Yu <yu.c.chen@intel.com>

commit 4511f7166a2deb5f7a578cf87fd2fe1ae83527e3 upstream.

When a new cooling device is registered, we need to update the
thermal zone to set the new registered cooling device to a proper
state.

This fixes a problem that the system is cool, while the fan devices
are left running on full speed after boot, if fan device is registered
after thermal zone device.

Here is the history of why current patch looks like this:
https://patchwork.kernel.org/patch/7273041/

Reference:https://bugzilla.kernel.org/show_bug.cgi?id=92431
Tested-by: Manuel Krause <manuelkrause@netscape.net>
Tested-by: szegad <szegadlo@poczta.onet.pl>
Tested-by: prash <prash.n.rao@gmail.com>
Tested-by: amish <ammdispose-arch@yahoo.com>
Reviewed-by: Javi Merino <javi.merino@arm.com>
Signed-off-by: Zhang Rui <rui.zhang@intel.com>
Signed-off-by: Chen Yu <yu.c.chen@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/thermal/thermal_core.c | 14 +++++++++++++-
 include/linux/thermal.h        |  2 ++
 2 files changed, 15 insertions(+), 1 deletion(-)

diff --git a/drivers/thermal/thermal_core.c b/drivers/thermal/thermal_core.c
index 480a222..090da0c 100644
--- a/drivers/thermal/thermal_core.c
+++ b/drivers/thermal/thermal_core.c
@@ -1296,6 +1296,7 @@ int thermal_zone_bind_cooling_device(struct thermal_zone_device *tz,
 	if (!result) {
 		list_add_tail(&dev->tz_node, &tz->thermal_instances);
 		list_add_tail(&dev->cdev_node, &cdev->thermal_instances);
+		atomic_set(&tz->need_update, 1);
 	}
 	mutex_unlock(&cdev->lock);
 	mutex_unlock(&tz->lock);
@@ -1405,6 +1406,7 @@ __thermal_cooling_device_register(struct device_node *np,
 				  const struct thermal_cooling_device_ops *ops)
 {
 	struct thermal_cooling_device *cdev;
+	struct thermal_zone_device *pos = NULL;
 	int result;
 
 	if (type && strlen(type) >= THERMAL_NAME_LENGTH)
@@ -1449,6 +1451,12 @@ __thermal_cooling_device_register(struct device_node *np,
 	/* Update binding information for 'this' new cdev */
 	bind_cdev(cdev);
 
+	mutex_lock(&thermal_list_lock);
+	list_for_each_entry(pos, &thermal_tz_list, node)
+		if (atomic_cmpxchg(&pos->need_update, 1, 0))
+			thermal_zone_device_update(pos);
+	mutex_unlock(&thermal_list_lock);
+
 	return cdev;
 }
 
@@ -1781,6 +1789,8 @@ struct thermal_zone_device *thermal_zone_device_register(const char *type,
 	tz->trips = trips;
 	tz->passive_delay = passive_delay;
 	tz->polling_delay = polling_delay;
+	/* A new thermal zone needs to be updated anyway. */
+	atomic_set(&tz->need_update, 1);
 
 	dev_set_name(&tz->device, "thermal_zone%d", tz->id);
 	result = device_register(&tz->device);
@@ -1873,7 +1883,9 @@ struct thermal_zone_device *thermal_zone_device_register(const char *type,
 		thermal_zone_device_set_polling(tz, 0);
 
 	thermal_zone_device_reset(tz);
-	thermal_zone_device_update(tz);
+	/* Update the new thermal zone and mark it as already updated. */
+	if (atomic_cmpxchg(&tz->need_update, 1, 0))
+		thermal_zone_device_update(tz);
 
 	return tz;
 
diff --git a/include/linux/thermal.h b/include/linux/thermal.h
index e103ff3..601c4f8 100644
--- a/include/linux/thermal.h
+++ b/include/linux/thermal.h
@@ -172,6 +172,7 @@ struct thermal_attr {
  * @forced_passive:	If > 0, temperature at which to switch on all ACPI
  *			processor cooling devices.  Currently only used by the
  *			step-wise governor.
+ * @need_update:	if equals 1, thermal_zone_device_update needs to be invoked.
  * @ops:	operations this &thermal_zone_device supports
  * @tzp:	thermal zone parameters
  * @governor:	pointer to the governor for this thermal zone
@@ -199,6 +200,7 @@ struct thermal_zone_device {
 	int emul_temperature;
 	int passive;
 	unsigned int forced_passive;
+	atomic_t need_update;
 	struct thermal_zone_device_ops *ops;
 	struct thermal_zone_params *tzp;
 	struct thermal_governor *governor;
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319739 — [PATCH 4.2.y-ckt 140/268] ACPI / video: Add disable_backlight_sysfs_if quirk for the Toshiba Satellite R830

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:40 +0100
Subject[PATCH 4.2.y-ckt 140/268] ACPI / video: Add disable_backlight_sysfs_if quirk for the Toshiba Satellite R830
Message-ID<qVF2J-Kd-81@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Hans de Goede <hdegoede@redhat.com>

commit b21f2e81bd3fd8ed260590e72901254bca2193cd upstream.

The Toshiba Satellite R830 needs disable_backlight_sysfs_if=1, just like
the Toshiba Portege R830. Add a quirk for this.

Link: https://bugzilla.kernel.org/show_bug.cgi?id=21012
Tested-by: To Do <entodoays@gmail.com>
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/acpi/acpi_video.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/drivers/acpi/acpi_video.c b/drivers/acpi/acpi_video.c
index 11506c0..586a87b 100644
--- a/drivers/acpi/acpi_video.c
+++ b/drivers/acpi/acpi_video.c
@@ -468,6 +468,15 @@ static struct dmi_system_id video_dmi_table[] = {
 		DMI_MATCH(DMI_PRODUCT_NAME, "PORTEGE R830"),
 		},
 	},
+	{
+	 /* https://bugzilla.kernel.org/show_bug.cgi?id=21012 */
+	 .callback = video_disable_backlight_sysfs_if,
+	 .ident = "Toshiba Satellite R830",
+	 .matches = {
+		DMI_MATCH(DMI_SYS_VENDOR, "TOSHIBA"),
+		DMI_MATCH(DMI_PRODUCT_NAME, "SATELLITE R830"),
+		},
+	},
 	{}
 };
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319740 — [PATCH 4.2.y-ckt 127/268] sparc64: fix incorrect sign extension in sys_sparc64_personality

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:40 +0100
Subject[PATCH 4.2.y-ckt 127/268] sparc64: fix incorrect sign extension in sys_sparc64_personality
Message-ID<qVF2J-Kd-83@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: "Dmitry V. Levin" <ldv@altlinux.org>

commit 525fd5a94e1be0776fa652df5c687697db508c91 upstream.

The value returned by sys_personality has type "long int".
It is saved to a variable of type "int", which is not a problem
yet because the type of task_struct->pesonality is "unsigned int".
The problem is the sign extension from "int" to "long int"
that happens on return from sys_sparc64_personality.

For example, a userspace call personality((unsigned) -EINVAL) will
result to any subsequent personality call, including absolutely
harmless read-only personality(0xffffffff) call, failing with
errno set to EINVAL.

Signed-off-by: Dmitry V. Levin <ldv@altlinux.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/sparc/kernel/sys_sparc_64.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/sparc/kernel/sys_sparc_64.c b/arch/sparc/kernel/sys_sparc_64.c
index 30e7ddb..c690c8e 100644
--- a/arch/sparc/kernel/sys_sparc_64.c
+++ b/arch/sparc/kernel/sys_sparc_64.c
@@ -413,7 +413,7 @@ out:
 
 SYSCALL_DEFINE1(sparc64_personality, unsigned long, personality)
 {
-	int ret;
+	long ret;
 
 	if (personality(current->personality) == PER_LINUX32 &&
 	    personality(personality) == PER_LINUX)
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319743 — [PATCH 4.2.y-ckt 238/268] batman-adv: Avoid recursive call_rcu for batadv_bla_claim

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:50 +0100
Subject[PATCH 4.2.y-ckt 238/268] batman-adv: Avoid recursive call_rcu for batadv_bla_claim
Message-ID<qVFcl-Oj-1@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Sven Eckelmann <sven@narfation.org>

commit 63b399272294e7a939cde41792dca38c549f0484 upstream.

The batadv_claim_free_ref function uses call_rcu to delay the free of the
batadv_bla_claim object until no (already started) rcu_read_lock is enabled
anymore. This makes sure that no context is still trying to access the
object which should be removed. But batadv_bla_claim also contains a
reference to backbone_gw which must be removed.

The reference drop of backbone_gw was done in the call_rcu function
batadv_claim_free_rcu but should actually be done in the
batadv_claim_release function to avoid nested call_rcus. This is important
because rcu_barrier (e.g. batadv_softif_free or batadv_exit) will not
detect the inner call_rcu as relevant for its execution. Otherwise this
barrier will most likely be inserted in the queue before the callback of
the first call_rcu was executed. The caller of rcu_barrier will therefore
continue to run before the inner call_rcu callback finished.

Fixes: 23721387c409 ("batman-adv: add basic bridge loop avoidance code")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Acked-by: Simon Wunderlich <sw@simonwunderlich.de>
Signed-off-by: Marek Lindner <mareklindner@neomailbox.ch>
Signed-off-by: Antonio Quartulli <a@unstable.cc>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/batman-adv/bridge_loop_avoidance.c | 10 +++-------
 1 file changed, 3 insertions(+), 7 deletions(-)

diff --git a/net/batman-adv/bridge_loop_avoidance.c b/net/batman-adv/bridge_loop_avoidance.c
index ba06092..7b521e7 100644
--- a/net/batman-adv/bridge_loop_avoidance.c
+++ b/net/batman-adv/bridge_loop_avoidance.c
@@ -126,21 +126,17 @@ batadv_backbone_gw_free_ref(struct batadv_bla_backbone_gw *backbone_gw)
 }
 
 /* finally deinitialize the claim */
-static void batadv_claim_free_rcu(struct rcu_head *rcu)
+static void batadv_claim_release(struct batadv_bla_claim *claim)
 {
-	struct batadv_bla_claim *claim;
-
-	claim = container_of(rcu, struct batadv_bla_claim, rcu);
-
 	batadv_backbone_gw_free_ref(claim->backbone_gw);
-	kfree(claim);
+	kfree_rcu(claim, rcu);
 }
 
 /* free a claim, call claim_free_rcu if its the last reference */
 static void batadv_claim_free_ref(struct batadv_bla_claim *claim)
 {
 	if (atomic_dec_and_test(&claim->refcount))
-		call_rcu(&claim->rcu, batadv_claim_free_rcu);
+		batadv_claim_release(claim);
 }
 
 /**
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319744 — [PATCH 4.2.y-ckt 257/268] unix: properly account for FDs passed over unix sockets

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:50 +0100
Subject[PATCH 4.2.y-ckt 257/268] unix: properly account for FDs passed over unix sockets
Message-ID<qVFcm-Oj-3@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: willy tarreau <w@1wt.eu>

[ Upstream commit 712f4aad406bb1ed67f3f98d04c044191f0ff593 ]

It is possible for a process to allocate and accumulate far more FDs than
the process' limit by sending them over a unix socket then closing them
to keep the process' fd count low.

This change addresses this problem by keeping track of the number of FDs
in flight per user and preventing non-privileged processes from having
more FDs in flight than their configured FD limit.

Reported-by: socketpair@gmail.com
Reported-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Mitigates: CVE-2013-4312 (Linux 2.0+)
Suggested-by: Linus Torvalds <torvalds@linux-foundation.org>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 include/linux/sched.h |  1 +
 net/unix/af_unix.c    | 24 ++++++++++++++++++++----
 net/unix/garbage.c    | 13 ++++++++-----
 3 files changed, 29 insertions(+), 9 deletions(-)

diff --git a/include/linux/sched.h b/include/linux/sched.h
index bfca8aa..8097d58 100644
--- a/include/linux/sched.h
+++ b/include/linux/sched.h
@@ -822,6 +822,7 @@ struct user_struct {
 	unsigned long mq_bytes;	/* How many bytes can be allocated to mqueue? */
 #endif
 	unsigned long locked_shm; /* How many pages of mlocked shm ? */
+	unsigned long unix_inflight;	/* How many files in flight in unix sockets */
 
 #ifdef CONFIG_KEYS
 	struct key *uid_keyring;	/* UID specific keyring */
diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
index 0e7bf2b..7926de1 100644
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -1512,6 +1512,21 @@ static void unix_destruct_scm(struct sk_buff *skb)
 	sock_wfree(skb);
 }
 
+/*
+ * The "user->unix_inflight" variable is protected by the garbage
+ * collection lock, and we just read it locklessly here. If you go
+ * over the limit, there might be a tiny race in actually noticing
+ * it across threads. Tough.
+ */
+static inline bool too_many_unix_fds(struct task_struct *p)
+{
+	struct user_struct *user = current_user();
+
+	if (unlikely(user->unix_inflight > task_rlimit(p, RLIMIT_NOFILE)))
+		return !capable(CAP_SYS_RESOURCE) && !capable(CAP_SYS_ADMIN);
+	return false;
+}
+
 #define MAX_RECURSION_LEVEL 4
 
 static int unix_attach_fds(struct scm_cookie *scm, struct sk_buff *skb)
@@ -1520,6 +1535,9 @@ static int unix_attach_fds(struct scm_cookie *scm, struct sk_buff *skb)
 	unsigned char max_level = 0;
 	int unix_sock_count = 0;
 
+	if (too_many_unix_fds(current))
+		return -ETOOMANYREFS;
+
 	for (i = scm->fp->count - 1; i >= 0; i--) {
 		struct sock *sk = unix_get_socket(scm->fp->fp[i]);
 
@@ -1541,10 +1559,8 @@ static int unix_attach_fds(struct scm_cookie *scm, struct sk_buff *skb)
 	if (!UNIXCB(skb).fp)
 		return -ENOMEM;
 
-	if (unix_sock_count) {
-		for (i = scm->fp->count - 1; i >= 0; i--)
-			unix_inflight(scm->fp->fp[i]);
-	}
+	for (i = scm->fp->count - 1; i >= 0; i--)
+		unix_inflight(scm->fp->fp[i]);
 	return max_level;
 }
 
diff --git a/net/unix/garbage.c b/net/unix/garbage.c
index a73a226..8fcdc22 100644
--- a/net/unix/garbage.c
+++ b/net/unix/garbage.c
@@ -120,11 +120,11 @@ void unix_inflight(struct file *fp)
 {
 	struct sock *s = unix_get_socket(fp);
 
+	spin_lock(&unix_gc_lock);
+
 	if (s) {
 		struct unix_sock *u = unix_sk(s);
 
-		spin_lock(&unix_gc_lock);
-
 		if (atomic_long_inc_return(&u->inflight) == 1) {
 			BUG_ON(!list_empty(&u->link));
 			list_add_tail(&u->link, &gc_inflight_list);
@@ -132,25 +132,28 @@ void unix_inflight(struct file *fp)
 			BUG_ON(list_empty(&u->link));
 		}
 		unix_tot_inflight++;
-		spin_unlock(&unix_gc_lock);
 	}
+	fp->f_cred->user->unix_inflight++;
+	spin_unlock(&unix_gc_lock);
 }
 
 void unix_notinflight(struct file *fp)
 {
 	struct sock *s = unix_get_socket(fp);
 
+	spin_lock(&unix_gc_lock);
+
 	if (s) {
 		struct unix_sock *u = unix_sk(s);
 
-		spin_lock(&unix_gc_lock);
 		BUG_ON(list_empty(&u->link));
 
 		if (atomic_long_dec_and_test(&u->inflight))
 			list_del_init(&u->link);
 		unix_tot_inflight--;
-		spin_unlock(&unix_gc_lock);
 	}
+	fp->f_cred->user->unix_inflight--;
+	spin_unlock(&unix_gc_lock);
 }
 
 static void scan_inflight(struct sock *x, void (*func)(struct unix_sock *),
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319745 — [PATCH 4.2.y-ckt 243/268] batman-adv: Drop immediate orig_node free function

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:50 +0100
Subject[PATCH 4.2.y-ckt 243/268] batman-adv: Drop immediate orig_node free function
Message-ID<qVFcm-Oj-7@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Sven Eckelmann <sven@narfation.org>

commit 42eff6a617e23b691f8e4467f4687ed7245a92db upstream.

It is not allowed to free the memory of an object which is part of a list
which is protected by rcu-read-side-critical sections without making sure
that no other context is accessing the object anymore. This usually happens
by removing the references to this object and then waiting until the rcu
grace period is over and no one (allowedly) accesses it anymore.

But the _now functions ignore this completely. They free the object
directly even when a different context still tries to access it. This has
to be avoided and thus these functions must be removed and all functions
have to use batadv_orig_node_free_ref.

Fixes: 72822225bd41 ("batman-adv: Fix rcu_barrier() miss due to double call_rcu() in TT code")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Marek Lindner <mareklindner@neomailbox.ch>
Signed-off-by: Antonio Quartulli <a@unstable.cc>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/batman-adv/originator.c        | 11 -----------
 net/batman-adv/originator.h        |  1 -
 net/batman-adv/translation-table.c | 28 +++++++++++++---------------
 3 files changed, 13 insertions(+), 27 deletions(-)

diff --git a/net/batman-adv/originator.c b/net/batman-adv/originator.c
index db5eff0..2a96811 100644
--- a/net/batman-adv/originator.c
+++ b/net/batman-adv/originator.c
@@ -582,17 +582,6 @@ void batadv_orig_node_free_ref(struct batadv_orig_node *orig_node)
 		batadv_orig_node_release(orig_node);
 }
 
-/**
- * batadv_orig_node_free_ref_now - decrement the orig node refcounter and
- * possibly free it (without rcu callback)
- * @orig_node: the orig node to free
- */
-void batadv_orig_node_free_ref_now(struct batadv_orig_node *orig_node)
-{
-	if (atomic_dec_and_test(&orig_node->refcount))
-		batadv_orig_node_free_rcu(&orig_node->rcu);
-}
-
 void batadv_originator_free(struct batadv_priv *bat_priv)
 {
 	struct batadv_hashtable *hash = bat_priv->orig_hash;
diff --git a/net/batman-adv/originator.h b/net/batman-adv/originator.h
index 79734d3..39c9906 100644
--- a/net/batman-adv/originator.h
+++ b/net/batman-adv/originator.h
@@ -38,7 +38,6 @@ int batadv_originator_init(struct batadv_priv *bat_priv);
 void batadv_originator_free(struct batadv_priv *bat_priv);
 void batadv_purge_orig_ref(struct batadv_priv *bat_priv);
 void batadv_orig_node_free_ref(struct batadv_orig_node *orig_node);
-void batadv_orig_node_free_ref_now(struct batadv_orig_node *orig_node);
 struct batadv_orig_node *batadv_orig_node_new(struct batadv_priv *bat_priv,
 					      const uint8_t *addr);
 struct batadv_neigh_node *
diff --git a/net/batman-adv/translation-table.c b/net/batman-adv/translation-table.c
index c9b2629..5d4644a 100644
--- a/net/batman-adv/translation-table.c
+++ b/net/batman-adv/translation-table.c
@@ -238,20 +238,6 @@ int batadv_tt_global_hash_count(struct batadv_priv *bat_priv,
 	return count;
 }
 
-static void batadv_tt_orig_list_entry_free_rcu(struct rcu_head *rcu)
-{
-	struct batadv_tt_orig_list_entry *orig_entry;
-
-	orig_entry = container_of(rcu, struct batadv_tt_orig_list_entry, rcu);
-
-	/* We are in an rcu callback here, therefore we cannot use
-	 * batadv_orig_node_free_ref() and its call_rcu():
-	 * An rcu_barrier() wouldn't wait for that to finish
-	 */
-	batadv_orig_node_free_ref_now(orig_entry->orig_node);
-	kfree(orig_entry);
-}
-
 /**
  * batadv_tt_local_size_mod - change the size by v of the local table identified
  *  by vid
@@ -347,13 +333,25 @@ static void batadv_tt_global_size_dec(struct batadv_orig_node *orig_node,
 	batadv_tt_global_size_mod(orig_node, vid, -1);
 }
 
+/**
+ * batadv_tt_orig_list_entry_release - release tt orig entry from lists and
+ *  queue for free after rcu grace period
+ * @orig_entry: tt orig entry to be free'd
+ */
+static void
+batadv_tt_orig_list_entry_release(struct batadv_tt_orig_list_entry *orig_entry)
+{
+	batadv_orig_node_free_ref(orig_entry->orig_node);
+	kfree_rcu(orig_entry, rcu);
+}
+
 static void
 batadv_tt_orig_list_entry_free_ref(struct batadv_tt_orig_list_entry *orig_entry)
 {
 	if (!atomic_dec_and_test(&orig_entry->refcount))
 		return;
 
-	call_rcu(&orig_entry->rcu, batadv_tt_orig_list_entry_free_rcu);
+	batadv_tt_orig_list_entry_release(orig_entry);
 }
 
 /**
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319746 — [PATCH 4.2.y-ckt 259/268] tcp_yeah: don't set ssthresh below 2

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:50 +0100
Subject[PATCH 4.2.y-ckt 259/268] tcp_yeah: don't set ssthresh below 2
Message-ID<qVFcm-Oj-5@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Neal Cardwell <ncardwell@google.com>

[ Upstream commit 83d15e70c4d8909d722c0d64747d8fb42e38a48f ]

For tcp_yeah, use an ssthresh floor of 2, the same floor used by Reno
and CUBIC, per RFC 5681 (equation 4).

tcp_yeah_ssthresh() was sometimes returning a 0 or negative ssthresh
value if the intended reduction is as big or bigger than the current
cwnd. Congestion control modules should never return a zero or
negative ssthresh. A zero ssthresh generally results in a zero cwnd,
causing the connection to stall. A negative ssthresh value will be
interpreted as a u32 and will set a target cwnd for PRR near 4
billion.

Oleksandr Natalenko reported that a system using tcp_yeah with ECN
could see a warning about a prior_cwnd of 0 in
tcp_cwnd_reduction(). Testing verified that this was due to
tcp_yeah_ssthresh() misbehaving in this way.

Reported-by: Oleksandr Natalenko <oleksandr@natalenko.name>
Signed-off-by: Neal Cardwell <ncardwell@google.com>
Signed-off-by: Yuchung Cheng <ycheng@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/ipv4/tcp_yeah.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/ipv4/tcp_yeah.c b/net/ipv4/tcp_yeah.c
index 17d3566..3e6a472 100644
--- a/net/ipv4/tcp_yeah.c
+++ b/net/ipv4/tcp_yeah.c
@@ -219,7 +219,7 @@ static u32 tcp_yeah_ssthresh(struct sock *sk)
 	yeah->fast_count = 0;
 	yeah->reno_count = max(yeah->reno_count>>1, 2U);
 
-	return tp->snd_cwnd - reduction;
+	return max_t(int, tp->snd_cwnd - reduction, 2);
 }
 
 static struct tcp_congestion_ops tcp_yeah __read_mostly = {
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319747 — [PATCH 4.2.y-ckt 208/268] Drivers: hv: utils: use memdup_user in hvt_op_write

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:50 +0100
Subject[PATCH 4.2.y-ckt 208/268] Drivers: hv: utils: use memdup_user in hvt_op_write
Message-ID<qVFcm-Oj-11@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Olaf Hering <olaf@aepfle.de>

commit b00359642c2427da89dc8f77daa2c9e8a84e6d76 upstream.

Use memdup_user to handle OOM.

Fixes: 14b50f80c32d ('Drivers: hv: util: introduce hv_utils_transport abstraction')

Signed-off-by: Olaf Hering <olaf@aepfle.de>
Signed-off-by: K. Y. Srinivasan <kys@microsoft.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/hv/hv_utils_transport.c | 9 ++++-----
 1 file changed, 4 insertions(+), 5 deletions(-)

diff --git a/drivers/hv/hv_utils_transport.c b/drivers/hv/hv_utils_transport.c
index 1505ee6..24b2766 100644
--- a/drivers/hv/hv_utils_transport.c
+++ b/drivers/hv/hv_utils_transport.c
@@ -80,11 +80,10 @@ static ssize_t hvt_op_write(struct file *file, const char __user *buf,
 
 	hvt = container_of(file->f_op, struct hvutil_transport, fops);
 
-	inmsg = kzalloc(count, GFP_KERNEL);
-	if (copy_from_user(inmsg, buf, count)) {
-		kfree(inmsg);
-		return -EFAULT;
-	}
+	inmsg = memdup_user(buf, count);
+	if (IS_ERR(inmsg))
+		return PTR_ERR(inmsg);
+
 	if (hvt->on_msg(inmsg, count))
 		return -EFAULT;
 	kfree(inmsg);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319748 — [PATCH 4.2.y-ckt 256/268] af_unix: Fix splice-bind deadlock

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:50 +0100
Subject[PATCH 4.2.y-ckt 256/268] af_unix: Fix splice-bind deadlock
Message-ID<qVFcm-Oj-13@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Rainer Weikusat <rweikusat@mobileactivedefense.com>

[ Upstream commit c845acb324aa85a39650a14e7696982ceea75dc1 ]

On 2015/11/06, Dmitry Vyukov reported a deadlock involving the splice
system call and AF_UNIX sockets,

http://lists.openwall.net/netdev/2015/11/06/24

The situation was analyzed as

(a while ago) A: socketpair()
B: splice() from a pipe to /mnt/regular_file
	does sb_start_write() on /mnt
C: try to freeze /mnt
	wait for B to finish with /mnt
A: bind() try to bind our socket to /mnt/new_socket_name
	lock our socket, see it not bound yet
	decide that it needs to create something in /mnt
	try to do sb_start_write() on /mnt, block (it's
	waiting for C).
D: splice() from the same pipe to our socket
	lock the pipe, see that socket is connected
	try to lock the socket, block waiting for A
B:	get around to actually feeding a chunk from
	pipe to file, try to lock the pipe.  Deadlock.

on 2015/11/10 by Al Viro,

http://lists.openwall.net/netdev/2015/11/10/4

The patch fixes this by removing the kern_path_create related code from
unix_mknod and executing it as part of unix_bind prior acquiring the
readlock of the socket in question. This means that A (as used above)
will sb_start_write on /mnt before it acquires the readlock, hence, it
won't indirectly block B which first did a sb_start_write and then
waited for a thread trying to acquire the readlock. Consequently, A
being blocked by C waiting for B won't cause a deadlock anymore
(effectively, both A and B acquire two locks in opposite order in the
situation described above).

Dmitry Vyukov(<dvyukov@google.com>) tested the original patch.

Signed-off-by: Rainer Weikusat <rweikusat@mobileactivedefense.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/unix/af_unix.c | 66 +++++++++++++++++++++++++++++++++---------------------
 1 file changed, 40 insertions(+), 26 deletions(-)

diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
index 0fc6dba..0e7bf2b 100644
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -952,32 +952,20 @@ fail:
 	return NULL;
 }
 
-static int unix_mknod(const char *sun_path, umode_t mode, struct path *res)
+static int unix_mknod(struct dentry *dentry, struct path *path, umode_t mode,
+		      struct path *res)
 {
-	struct dentry *dentry;
-	struct path path;
-	int err = 0;
-	/*
-	 * Get the parent directory, calculate the hash for last
-	 * component.
-	 */
-	dentry = kern_path_create(AT_FDCWD, sun_path, &path, 0);
-	err = PTR_ERR(dentry);
-	if (IS_ERR(dentry))
-		return err;
+	int err;
 
-	/*
-	 * All right, let's create it.
-	 */
-	err = security_path_mknod(&path, dentry, mode, 0);
+	err = security_path_mknod(path, dentry, mode, 0);
 	if (!err) {
-		err = vfs_mknod(d_inode(path.dentry), dentry, mode, 0);
+		err = vfs_mknod(d_inode(path->dentry), dentry, mode, 0);
 		if (!err) {
-			res->mnt = mntget(path.mnt);
+			res->mnt = mntget(path->mnt);
 			res->dentry = dget(dentry);
 		}
 	}
-	done_path_create(&path, dentry);
+
 	return err;
 }
 
@@ -988,10 +976,12 @@ static int unix_bind(struct socket *sock, struct sockaddr *uaddr, int addr_len)
 	struct unix_sock *u = unix_sk(sk);
 	struct sockaddr_un *sunaddr = (struct sockaddr_un *)uaddr;
 	char *sun_path = sunaddr->sun_path;
-	int err;
+	int err, name_err;
 	unsigned int hash;
 	struct unix_address *addr;
 	struct hlist_head *list;
+	struct path path;
+	struct dentry *dentry;
 
 	err = -EINVAL;
 	if (sunaddr->sun_family != AF_UNIX)
@@ -1007,14 +997,34 @@ static int unix_bind(struct socket *sock, struct sockaddr *uaddr, int addr_len)
 		goto out;
 	addr_len = err;
 
+	name_err = 0;
+	dentry = NULL;
+	if (sun_path[0]) {
+		/* Get the parent directory, calculate the hash for last
+		 * component.
+		 */
+		dentry = kern_path_create(AT_FDCWD, sun_path, &path, 0);
+
+		if (IS_ERR(dentry)) {
+			/* delay report until after 'already bound' check */
+			name_err = PTR_ERR(dentry);
+			dentry = NULL;
+		}
+	}
+
 	err = mutex_lock_interruptible(&u->readlock);
 	if (err)
-		goto out;
+		goto out_path;
 
 	err = -EINVAL;
 	if (u->addr)
 		goto out_up;
 
+	if (name_err) {
+		err = name_err == -EEXIST ? -EADDRINUSE : name_err;
+		goto out_up;
+	}
+
 	err = -ENOMEM;
 	addr = kmalloc(sizeof(*addr)+addr_len, GFP_KERNEL);
 	if (!addr)
@@ -1025,11 +1035,11 @@ static int unix_bind(struct socket *sock, struct sockaddr *uaddr, int addr_len)
 	addr->hash = hash ^ sk->sk_type;
 	atomic_set(&addr->refcnt, 1);
 
-	if (sun_path[0]) {
-		struct path path;
+	if (dentry) {
+		struct path u_path;
 		umode_t mode = S_IFSOCK |
 		       (SOCK_INODE(sock)->i_mode & ~current_umask());
-		err = unix_mknod(sun_path, mode, &path);
+		err = unix_mknod(dentry, &path, mode, &u_path);
 		if (err) {
 			if (err == -EEXIST)
 				err = -EADDRINUSE;
@@ -1037,9 +1047,9 @@ static int unix_bind(struct socket *sock, struct sockaddr *uaddr, int addr_len)
 			goto out_up;
 		}
 		addr->hash = UNIX_HASH_SIZE;
-		hash = d_backing_inode(path.dentry)->i_ino & (UNIX_HASH_SIZE-1);
+		hash = d_backing_inode(dentry)->i_ino & (UNIX_HASH_SIZE - 1);
 		spin_lock(&unix_table_lock);
-		u->path = path;
+		u->path = u_path;
 		list = &unix_socket_table[hash];
 	} else {
 		spin_lock(&unix_table_lock);
@@ -1062,6 +1072,10 @@ out_unlock:
 	spin_unlock(&unix_table_lock);
 out_up:
 	mutex_unlock(&u->readlock);
+out_path:
+	if (dentry)
+		done_path_create(&path, dentry);
+
 out:
 	return err;
 }
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319749 — [PATCH 4.2.y-ckt 263/268] phonet: properly unshare skbs in phonet_rcv()

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:50 +0100
Subject[PATCH 4.2.y-ckt 263/268] phonet: properly unshare skbs in phonet_rcv()
Message-ID<qVFcm-Oj-15@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 7aaed57c5c2890634cfadf725173c7c68ea4cb4f ]

Ivaylo Dimitrov reported a regression caused by commit 7866a621043f
("dev: add per net_device packet type chains").

skb->dev becomes NULL and we crash in __netif_receive_skb_core().

Before above commit, different kind of bugs or corruptions could happen
without major crash.

But the root cause is that phonet_rcv() can queue skb without checking
if skb is shared or not.

Many thanks to Ivaylo Dimitrov for his help, diagnosis and tests.

Reported-by: Ivaylo Dimitrov <ivo.g.dimitrov.75@gmail.com>
Tested-by: Ivaylo Dimitrov <ivo.g.dimitrov.75@gmail.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Remi Denis-Courmont <courmisch@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/phonet/af_phonet.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/net/phonet/af_phonet.c b/net/phonet/af_phonet.c
index 10d42f3..f925753 100644
--- a/net/phonet/af_phonet.c
+++ b/net/phonet/af_phonet.c
@@ -377,6 +377,10 @@ static int phonet_rcv(struct sk_buff *skb, struct net_device *dev,
 	struct sockaddr_pn sa;
 	u16 len;
 
+	skb = skb_share_check(skb, GFP_ATOMIC);
+	if (!skb)
+		return NET_RX_DROP;
+
 	/* check we have at least a full Phonet header */
 	if (!pskb_pull(skb, sizeof(struct phonethdr)))
 		goto out;
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319750 — [PATCH 4.2.y-ckt 203/268] mtd: nand: fix ONFI parameter page layout

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:50 +0100
Subject[PATCH 4.2.y-ckt 203/268] mtd: nand: fix ONFI parameter page layout
Message-ID<qVFcm-Oj-17@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Boris BREZILLON <boris.brezillon@free-electrons.com>

commit de64aa9ec129ba627634088f662a4d09e356ddb6 upstream.

src_ssync_features field is only 1 byte large, and the 4th reserved area
is actually 8 bytes large.

Fixes: d1e1f4e42b5 ("mtd: nand: add support for reading ONFI parameters from NAND device")
Signed-off-by: Boris Brezillon <boris.brezillon@free-electrons.com>
Signed-off-by: Brian Norris <computersforpeace@gmail.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 include/linux/mtd/nand.h | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/include/linux/mtd/nand.h b/include/linux/mtd/nand.h
index 272f429..bb2fd9a 100644
--- a/include/linux/mtd/nand.h
+++ b/include/linux/mtd/nand.h
@@ -276,7 +276,7 @@ struct nand_onfi_params {
 	__le16 t_r;
 	__le16 t_ccs;
 	__le16 src_sync_timing_mode;
-	__le16 src_ssync_features;
+	u8 src_ssync_features;
 	__le16 clk_pin_capacitance_typ;
 	__le16 io_pin_capacitance_typ;
 	__le16 input_pin_capacitance_typ;
@@ -284,7 +284,7 @@ struct nand_onfi_params {
 	u8 driver_strength_support;
 	__le16 t_int_r;
 	__le16 t_ald;
-	u8 reserved4[7];
+	u8 reserved4[8];
 
 	/* vendor */
 	__le16 vendor_revision;
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319751 — [PATCH 4.2.y-ckt 264/268] net: bpf: reject invalid shifts

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:50 +0100
Subject[PATCH 4.2.y-ckt 264/268] net: bpf: reject invalid shifts
Message-ID<qVFcm-Oj-21@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Rabin Vincent <rabin@rab.in>

[ Upstream commit 229394e8e62a4191d592842cf67e80c62a492937 ]

On ARM64, a BUG() is triggered in the eBPF JIT if a filter with a
constant shift that can't be encoded in the immediate field of the
UBFM/SBFM instructions is passed to the JIT.  Since these shifts
amounts, which are negative or >= regsize, are invalid, reject them in
the eBPF verifier and the classic BPF filter checker, for all
architectures.

Signed-off-by: Rabin Vincent <rabin@rab.in>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Daniel Borkmann <daniel@iogearbox.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 kernel/bpf/verifier.c | 10 ++++++++++
 net/core/filter.c     |  5 +++++
 2 files changed, 15 insertions(+)

diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 039d866..4d19a8c 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -1036,6 +1036,16 @@ static int check_alu_op(struct reg_state *regs, struct bpf_insn *insn)
 			return -EINVAL;
 		}
 
+		if ((opcode == BPF_LSH || opcode == BPF_RSH ||
+		     opcode == BPF_ARSH) && BPF_SRC(insn->code) == BPF_K) {
+			int size = BPF_CLASS(insn->code) == BPF_ALU64 ? 64 : 32;
+
+			if (insn->imm < 0 || insn->imm >= size) {
+				verbose("invalid shift %d\n", insn->imm);
+				return -EINVAL;
+			}
+		}
+
 		/* pattern match 'bpf_add Rx, imm' instruction */
 		if (opcode == BPF_ADD && BPF_CLASS(insn->code) == BPF_ALU64 &&
 		    regs[insn->dst_reg].type == FRAME_PTR &&
diff --git a/net/core/filter.c b/net/core/filter.c
index 8dcdd86..515b50b 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -779,6 +779,11 @@ static int bpf_check_classic(const struct sock_filter *filter,
 			if (ftest->k == 0)
 				return -EINVAL;
 			break;
+		case BPF_ALU | BPF_LSH | BPF_K:
+		case BPF_ALU | BPF_RSH | BPF_K:
+			if (ftest->k >= 32)
+				return -EINVAL;
+			break;
 		case BPF_LD | BPF_MEM:
 		case BPF_LDX | BPF_MEM:
 		case BPF_ST:
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319752 — [PATCH 4.2.y-ckt 246/268] team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:50 +0100
Subject[PATCH 4.2.y-ckt 246/268] team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid
Message-ID<qVFcm-Oj-19@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Ido Schimmel <idosch@mellanox.com>

commit 60a6531bfe49555581ccd65f66a350cc5693fcde upstream.

We can't be within an RCU read-side critical section when deleting
VLANs, as underlying drivers might sleep during the hardware operation.
Therefore, replace the RCU critical section with a mutex. This is
consistent with team_vlan_rx_add_vid.

Fixes: 3d249d4ca7d0 ("net: introduce ethernet teaming device")
Acked-by: Jiri Pirko <jiri@mellanox.com>
Signed-off-by: Ido Schimmel <idosch@mellanox.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/team/team.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/net/team/team.c b/drivers/net/team/team.c
index daa054b..88058480 100644
--- a/drivers/net/team/team.c
+++ b/drivers/net/team/team.c
@@ -1845,10 +1845,10 @@ static int team_vlan_rx_kill_vid(struct net_device *dev, __be16 proto, u16 vid)
 	struct team *team = netdev_priv(dev);
 	struct team_port *port;
 
-	rcu_read_lock();
-	list_for_each_entry_rcu(port, &team->port_list, list)
+	mutex_lock(&team->lock);
+	list_for_each_entry(port, &team->port_list, list)
 		vlan_vid_del(port->dev, proto, vid);
-	rcu_read_unlock();
+	mutex_unlock(&team->lock);
 
 	return 0;
 }
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319753 — [PATCH 4.2.y-ckt 253/268] net: cdc_ncm: avoid changing RX/TX buffers on MTU changes

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:50 +0100
Subject[PATCH 4.2.y-ckt 253/268] net: cdc_ncm: avoid changing RX/TX buffers on MTU changes
Message-ID<qVFcm-Oj-23@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: =?UTF-8?q?Bj=C3=B8rn=20Mork?= <bjorn@mork.no>

[ Upstream commit 1dfddff5fcd869fcab0c52fafae099dfa435a935 ]

NCM buffer sizes are negotiated with the device independently of
the network device MTU.  The RX buffers are allocated by the
usbnet framework based on the rx_urb_size value set by cdc_ncm. A
single RX buffer can hold a number of MTU sized packets.

The default usbnet change_mtu ndo only modifies rx_urb_size if it
is equal to hard_mtu.  And the cdc_ncm driver will set rx_urb_size
and hard_mtu independently of each other, based on dwNtbInMaxSize
and dwNtbOutMaxSize respectively. It was therefore assumed that
usbnet_change_mtu() would never touch rx_urb_size.  This failed to
consider the case where dwNtbInMaxSize and dwNtbOutMaxSize happens
to be equal.

Fix by implementing an NCM specific change_mtu ndo, modifying the
netdev MTU without touching the buffer size settings.

Signed-off-by: Bjørn Mork <bjorn@mork.no>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/usb/cdc_mbim.c  |  2 +-
 drivers/net/usb/cdc_ncm.c   | 31 +++++++++++++++++++++++++++++++
 include/linux/usb/cdc_ncm.h |  1 +
 3 files changed, 33 insertions(+), 1 deletion(-)

diff --git a/drivers/net/usb/cdc_mbim.c b/drivers/net/usb/cdc_mbim.c
index b6ea6ff..d87b4ac 100644
--- a/drivers/net/usb/cdc_mbim.c
+++ b/drivers/net/usb/cdc_mbim.c
@@ -100,7 +100,7 @@ static const struct net_device_ops cdc_mbim_netdev_ops = {
 	.ndo_stop             = usbnet_stop,
 	.ndo_start_xmit       = usbnet_start_xmit,
 	.ndo_tx_timeout       = usbnet_tx_timeout,
-	.ndo_change_mtu       = usbnet_change_mtu,
+	.ndo_change_mtu       = cdc_ncm_change_mtu,
 	.ndo_set_mac_address  = eth_mac_addr,
 	.ndo_validate_addr    = eth_validate_addr,
 	.ndo_vlan_rx_add_vid  = cdc_mbim_rx_add_vid,
diff --git a/drivers/net/usb/cdc_ncm.c b/drivers/net/usb/cdc_ncm.c
index fa41a6d..e278a7a 100644
--- a/drivers/net/usb/cdc_ncm.c
+++ b/drivers/net/usb/cdc_ncm.c
@@ -41,6 +41,7 @@
 #include <linux/module.h>
 #include <linux/netdevice.h>
 #include <linux/ctype.h>
+#include <linux/etherdevice.h>
 #include <linux/ethtool.h>
 #include <linux/workqueue.h>
 #include <linux/mii.h>
@@ -689,6 +690,33 @@ static void cdc_ncm_free(struct cdc_ncm_ctx *ctx)
 	kfree(ctx);
 }
 
+/* we need to override the usbnet change_mtu ndo for two reasons:
+ *  - respect the negotiated maximum datagram size
+ *  - avoid unwanted changes to rx and tx buffers
+ */
+int cdc_ncm_change_mtu(struct net_device *net, int new_mtu)
+{
+	struct usbnet *dev = netdev_priv(net);
+	struct cdc_ncm_ctx *ctx = (struct cdc_ncm_ctx *)dev->data[0];
+	int maxmtu = ctx->max_datagram_size - cdc_ncm_eth_hlen(dev);
+
+	if (new_mtu <= 0 || new_mtu > maxmtu)
+		return -EINVAL;
+	net->mtu = new_mtu;
+	return 0;
+}
+EXPORT_SYMBOL_GPL(cdc_ncm_change_mtu);
+
+static const struct net_device_ops cdc_ncm_netdev_ops = {
+	.ndo_open	     = usbnet_open,
+	.ndo_stop	     = usbnet_stop,
+	.ndo_start_xmit	     = usbnet_start_xmit,
+	.ndo_tx_timeout	     = usbnet_tx_timeout,
+	.ndo_change_mtu	     = cdc_ncm_change_mtu,
+	.ndo_set_mac_address = eth_mac_addr,
+	.ndo_validate_addr   = eth_validate_addr,
+};
+
 int cdc_ncm_bind_common(struct usbnet *dev, struct usb_interface *intf, u8 data_altsetting, int drvflags)
 {
 	const struct usb_cdc_union_desc *union_desc = NULL;
@@ -874,6 +902,9 @@ advance:
 	/* add our sysfs attrs */
 	dev->net->sysfs_groups[0] = &cdc_ncm_sysfs_attr_group;
 
+	/* must handle MTU changes */
+	dev->net->netdev_ops = &cdc_ncm_netdev_ops;
+
 	return 0;
 
 error2:
diff --git a/include/linux/usb/cdc_ncm.h b/include/linux/usb/cdc_ncm.h
index 1f6526c..3a375d0 100644
--- a/include/linux/usb/cdc_ncm.h
+++ b/include/linux/usb/cdc_ncm.h
@@ -138,6 +138,7 @@ struct cdc_ncm_ctx {
 };
 
 u8 cdc_ncm_select_altsetting(struct usb_interface *intf);
+int cdc_ncm_change_mtu(struct net_device *net, int new_mtu);
 int cdc_ncm_bind_common(struct usbnet *dev, struct usb_interface *intf, u8 data_altsetting, int drvflags);
 void cdc_ncm_unbind(struct usbnet *dev, struct usb_interface *intf);
 struct sk_buff *cdc_ncm_fill_tx_frame(struct usbnet *dev, struct sk_buff *skb, __le32 sign);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319754 — [PATCH 4.2.y-ckt 240/268] batman-adv: Drop immediate batadv_orig_ifinfo free function

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 21:50 +0100
Subject[PATCH 4.2.y-ckt 240/268] batman-adv: Drop immediate batadv_orig_ifinfo free function
Message-ID<qVFcm-Oj-27@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Sven Eckelmann <sven@narfation.org>

commit deed96605f5695cb945e0b3d79429581857a2b9d upstream.

It is not allowed to free the memory of an object which is part of a list
which is protected by rcu-read-side-critical sections without making sure
that no other context is accessing the object anymore. This usually happens
by removing the references to this object and then waiting until the rcu
grace period is over and no one (allowedly) accesses it anymore.

But the _now functions ignore this completely. They free the object
directly even when a different context still tries to access it. This has
to be avoided and thus these functions must be removed and all functions
have to use batadv_orig_ifinfo_free_ref.

Fixes: 7351a4822d42 ("batman-adv: split out router from orig_node")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Marek Lindner <mareklindner@neomailbox.ch>
Signed-off-by: Antonio Quartulli <a@unstable.cc>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/batman-adv/originator.c | 59 ++++++++++++++++++++++++---------------------
 1 file changed, 31 insertions(+), 28 deletions(-)

diff --git a/net/batman-adv/originator.c b/net/batman-adv/originator.c
index 32a0fcf..8200531 100644
--- a/net/batman-adv/originator.c
+++ b/net/batman-adv/originator.c
@@ -534,76 +534,79 @@ static void batadv_orig_ifinfo_free_rcu(struct rcu_head *rcu)
 }
 
 /**
- * batadv_orig_ifinfo_free_ref - decrement the refcounter and possibly free
- *  the orig_ifinfo (without rcu callback)
+ * batadv_orig_ifinfo_free_ref - decrement the refcounter and possibly release
+ *  the orig_ifinfo
  * @orig_ifinfo: the orig_ifinfo object to release
  */
-static void
-batadv_orig_ifinfo_free_ref_now(struct batadv_orig_ifinfo *orig_ifinfo)
+void batadv_orig_ifinfo_free_ref(struct batadv_orig_ifinfo *orig_ifinfo)
 {
 	if (atomic_dec_and_test(&orig_ifinfo->refcount))
-		batadv_orig_ifinfo_free_rcu(&orig_ifinfo->rcu);
+		call_rcu(&orig_ifinfo->rcu, batadv_orig_ifinfo_free_rcu);
 }
 
 /**
- * batadv_orig_ifinfo_free_ref - decrement the refcounter and possibly free
- *  the orig_ifinfo
- * @orig_ifinfo: the orig_ifinfo object to release
+ * batadv_orig_node_free_rcu - free the orig_node
+ * @rcu: rcu pointer of the orig_node
  */
-void batadv_orig_ifinfo_free_ref(struct batadv_orig_ifinfo *orig_ifinfo)
+static void batadv_orig_node_free_rcu(struct rcu_head *rcu)
 {
-	if (atomic_dec_and_test(&orig_ifinfo->refcount))
-		call_rcu(&orig_ifinfo->rcu, batadv_orig_ifinfo_free_rcu);
+	struct batadv_orig_node *orig_node;
+
+	orig_node = container_of(rcu, struct batadv_orig_node, rcu);
+
+	batadv_mcast_purge_orig(orig_node);
+
+	batadv_frag_purge_orig(orig_node, NULL);
+
+	if (orig_node->bat_priv->bat_algo_ops->bat_orig_free)
+		orig_node->bat_priv->bat_algo_ops->bat_orig_free(orig_node);
+
+	kfree(orig_node->tt_buff);
+	kfree(orig_node);
 }
 
-static void batadv_orig_node_free_rcu(struct rcu_head *rcu)
+/**
+ * batadv_orig_node_release - release orig_node from lists and queue for
+ *  free after rcu grace period
+ * @orig_node: the orig node to free
+ */
+static void batadv_orig_node_release(struct batadv_orig_node *orig_node)
 {
 	struct hlist_node *node_tmp;
 	struct batadv_neigh_node *neigh_node;
-	struct batadv_orig_node *orig_node;
 	struct batadv_orig_ifinfo *orig_ifinfo;
 
-	orig_node = container_of(rcu, struct batadv_orig_node, rcu);
-
 	spin_lock_bh(&orig_node->neigh_list_lock);
 
 	/* for all neighbors towards this originator ... */
 	hlist_for_each_entry_safe(neigh_node, node_tmp,
 				  &orig_node->neigh_list, list) {
 		hlist_del_rcu(&neigh_node->list);
-		batadv_neigh_node_free_ref_now(neigh_node);
+		batadv_neigh_node_free_ref(neigh_node);
 	}
 
 	hlist_for_each_entry_safe(orig_ifinfo, node_tmp,
 				  &orig_node->ifinfo_list, list) {
 		hlist_del_rcu(&orig_ifinfo->list);
-		batadv_orig_ifinfo_free_ref_now(orig_ifinfo);
+		batadv_orig_ifinfo_free_ref(orig_ifinfo);
 	}
 	spin_unlock_bh(&orig_node->neigh_list_lock);
 
-	batadv_mcast_purge_orig(orig_node);
-
 	/* Free nc_nodes */
 	batadv_nc_purge_orig(orig_node->bat_priv, orig_node, NULL);
 
-	batadv_frag_purge_orig(orig_node, NULL);
-
-	if (orig_node->bat_priv->bat_algo_ops->bat_orig_free)
-		orig_node->bat_priv->bat_algo_ops->bat_orig_free(orig_node);
-
-	kfree(orig_node->tt_buff);
-	kfree(orig_node);
+	call_rcu(&orig_node->rcu, batadv_orig_node_free_rcu);
 }
 
 /**
  * batadv_orig_node_free_ref - decrement the orig node refcounter and possibly
- * schedule an rcu callback for freeing it
+ *  release it
  * @orig_node: the orig node to free
  */
 void batadv_orig_node_free_ref(struct batadv_orig_node *orig_node)
 {
 	if (atomic_dec_and_test(&orig_node->refcount))
-		call_rcu(&orig_node->rcu, batadv_orig_node_free_rcu);
+		batadv_orig_node_release(orig_node);
 }
 
 /**
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


Page 1 of 13  [1] 2 3 … 13  Next page →

Back to top | Article view | linux.kernel


csiph-web