Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1319730 > unrolled thread

[4.2.y-ckt stable] Linux 4.2.8-ckt3 stable review

Started byKamal Mostafa <kamal@canonical.com>
First post2016-01-27 21:40 +0100
Last post2016-01-27 23:10 +0100
Articles 20 on this page of 254 — 1 participant

Back to article view | Back to linux.kernel


Contents

  [4.2.y-ckt stable] Linux 4.2.8-ckt3 stable review Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 051/268] udf: limit the maximum number of indirect extents in a row Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 002/268] ovl: allow zero size xattr Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 001/268] drm/nouveau/nv46: Change mc subdev oclass from nv44 to nv4c Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 147/268] ALSA: hda - Fix bass pin fixup for ASUS N550JX Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 057/268] Thermal: do thermal zone update after a cooling device registered Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 140/268] ACPI / video: Add disable_backlight_sysfs_if quirk for the Toshiba Satellite R830 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 127/268] sparc64: fix incorrect sign extension in sys_sparc64_personality Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 238/268] batman-adv: Avoid recursive call_rcu for batadv_bla_claim Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 257/268] unix: properly account for FDs passed over unix sockets Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 243/268] batman-adv: Drop immediate orig_node free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 259/268] tcp_yeah: don't set ssthresh below 2 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 208/268] Drivers: hv: utils: use memdup_user in hvt_op_write Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 256/268] af_unix: Fix splice-bind deadlock Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 263/268] phonet: properly unshare skbs in phonet_rcv() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 203/268] mtd: nand: fix ONFI parameter page layout Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 264/268] net: bpf: reject invalid shifts Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 246/268] team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 253/268] net: cdc_ncm: avoid changing RX/TX buffers on MTU changes Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 240/268] batman-adv: Drop immediate batadv_orig_ifinfo free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 242/268] batman-adv: Drop immediate neigh_ifinfo free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 219/268] perf/x86: Fix filter_events() bug with event mappings Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 262/268] net: preserve IP control block during GSO segmentation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 245/268] ARM: dts: armadillo800eva Correct extal1 frequency to 24 MHz Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 266/268] xfrm: dst_entries_init() per-net dst_ops Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 268/268] ipv6: update skb->csum when CE mark is propagated Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 254/268] sctp: sctp should release assoc when sctp_make_abort_user return NULL in sctp_close Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 248/268] IB/mlx4: Initialize hop_limit when creating address handle Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 255/268] connector: bump skb->users before callback invocation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 234/268] include/linux/memblock.h: fix ordering of 'flags' argument in comments Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 251/268] NFS: Ensure we revalidate attributes before using execute_ok() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 202/268] ASoC: tegra_alc5632: check return value Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 250/268] NFSv4: Don't perform cached access checks before we've OPENed the file Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 258/268] bridge: Only call /sbin/bridge-stp for the initial network namespace Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 247/268] mmc: debugfs: correct wrong voltage value Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 261/268] udp: disallow UFO for sockets with SO_NO_CHECK option Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 260/268] sched,cls_flower: set key address type when present Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 265/268] batman-adv: Drop immediate batadv_hard_iface free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 236/268] btrfs: initialize the seq counter in struct btrfs_device Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 220/268] perf/x86: fix PEBS issues on Intel Atom/Core2 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 267/268] vxlan: fix test which detect duplicate vxlan iface Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 249/268] net/mlx4: Remove unused macro Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 244/268] printk: help pr_debug and pr_devel to optimize out arguments Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 252/268] veth: don’t modify ip_summed; doing so treats packets with bad checksums as good. Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 205/268] Revert "ACPI / LPSS: allow to use specific PM domain during ->probe()" Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 214/268] pinctrl: bcm2835: Fix memory leak in error path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 233/268] vmstat: make vmstat_updater deferrable again and shut down on idle Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 222/268] firmware: actually return NULL on failed request_firmware_nowait() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 216/268] x86/LDT: Print the real LDT base address Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 213/268] ALSA: fm801: detect FM-only card earlier Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 212/268] ALSA: fm801: propagate TUNER_ONLY bit when autodetected Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 228/268] ipv6: tcp: add rcu locking in tcp_v6_send_synack() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 225/268] m68k/atari, m68k/sun3: Fix SCSI platform device registration when driver is modular Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 227/268] net: sctp: prevent writes to cookie_hmac_alg from accessing invalid memory Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 211/268] ARM: imx: select SRC for i.MX7 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 231/268] mmc: sd: limit SD card power limit according to cards capabilities Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 204/268] mac80211: fix mgmt-tx abort cookie and leak Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 221/268] power: test_power: correctly handle empty writes Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 229/268] bonding: Prevent IPv6 link local address on enslaved devices Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 239/268] batman-adv: Avoid recursive call_rcu for batadv_nc_node Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 226/268] um: Fix build error and kconfig for i386 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 230/268] kbuild: Demote 'sign-compare' warning to W=2 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 215/268] mmc: sdhci: restore behavior when setting VDD via external regulator Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 209/268] tpm_tis: Use devm_free_irq not free_irq Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 200/268] PCI/MSI: Initialize MSI capability for all architectures Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 223/268] target: Fix a memory leak in target_dev_lba_map_store() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 235/268] Btrfs: clean up an error code in btrfs_init_space_info() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 241/268] batman-adv: Drop immediate batadv_neigh_node free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 199/268] ASoC: Intel: pass correct parameter in sst_alloc_stream_mrfld() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 218/268] kconfig: return 'false' instead of 'no' in bool function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 232/268] net: tcp_memcontrol: properly detect ancestor socket pressure Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 201/268] ath9k_htc: check for underflow in ath9k_htc_rx_msg() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 237/268] bridge: fix lockdep addr_list_lock false positive splat Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 224/268] phy: micrel: Fix finding PHY properties in MAC node for KSZ9031. Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 217/268] sysrq: Fix warning in sysrq generated crash. Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 195/268] SCSI: initio: remove duplicate module device table Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 189/268] MAINTAINERS: return arch/sh to maintained state, with new maintainers Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 198/268] MAINTAINERS: gpio-brcmstb: Remove stray '>' Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 181/268] prctl: take mmap sem for writing to protect against others Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 184/268] MIPS: Loongson-3: Fix SMP_ASK_C0COUNT IPI handler Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 186/268] ocfs2: NFS hangs in __ocfs2_cluster_lock due to race with ocfs2_unblock_lock Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 185/268] MIPS: hpet: Choose a safe value for the ETIME check Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 188/268] make sure that freeing shmem fast symlinks is RCU-delayed Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 196/268] clk: xgene: Fix divider with non-zero shift value Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 206/268] mtd: nand: denali: add missing nand_release() call in denali_remove() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 194/268] [media] lirc_imon: do not leave imon_probe() with mutex held Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 190/268] MIPS: Fix some missing CONFIG_CPU_MIPSR6 #ifdefs Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 192/268] drm/i915: On fb alloc failure, unref gem object where it gets refed Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 183/268] libceph: fix ceph_msg_revoke() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 210/268] ALSA: fm801: explicitly free IRQ line Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 174/268] IB/cm: Fix a recently introduced deadlock Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 175/268] ideapad-laptop: Add Lenovo ideapad Y700-17ISK to no_hw_rfkill dmi list Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 177/268] iscsi-target: Fix potential dead-lock during node acl delete Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 193/268] [media] rc: allow rc modules to be loaded if rc-main is not a module Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 207/268] Drivers: hv: util: catch allocation errors Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 191/268] ideapad-laptop: Add Lenovo Yoga 700 to no_hw_rfkill dmi list Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 182/268] ALSA: timer: Handle disconnection more safely Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 178/268] crypto: algif_skcipher - sendmsg SG marking is off by one Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 187/268] pNFS/flexfiles: Fix an XDR encoding bug in layoutreturn Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 197/268] clk: st: avoid uninitialized variable use Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 166/268] ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 167/268] ARM: debug-ll: fix BCM63xx entry for multiplatform Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 168/268] xfs: log mount failures don't wait for buffers to be released Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 179/268] ALSA: hda - Flush the pending probe work at remove Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 108/268] x86/reboot/quirks: Add iMac10,1 to pci_reboot_dmi_table[] Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 170/268] crypto: crc32c - Fix crc32c soft dependency Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 173/268] IB/mlx5: Expose correct maximum number of CQE capacity Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 171/268] IB/qib: fix mcast detach when qp not attached Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 169/268] crypto: algif_skcipher - Load TX SG list after waiting Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 121/268] x86/mm: Improve switch_mm() barrier comments Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 161/268] crypto: algif_skcipher - Fix race condition in skcipher_check_key Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 153/268] crypto: hash - Add crypto_ahash_has_setkey Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 164/268] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 139/268] ACPI / video: Add disable_backlight_sysfs_if quirk for the Toshiba Portege R700 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 136/268] ALSA: timer: Harden slave timer list handling Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 160/268] crypto: algif_hash - Fix race condition in hash_check_key Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 135/268] ALSA: hda - Add fixup for Dell Latitidue E6540 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 146/268] printk: do cond_resched() between lines while outputting to consoles Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 157/268] crypto: algif_skcipher - Remove custom release parent function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 154/268] crypto: algif_hash - Require setkey before accept(2) Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 142/268] zram: don't call idr_remove() from zram_remove() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 138/268] zram: try vmalloc() after kmalloc() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 145/268] kernel/panic.c: turn off locks debug before releasing console lock Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 149/268] crypto: af_alg - Disallow bind/setkey/... after accept(2) Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 163/268] dmaengine: at_xdmac: fix resume for cyclic transfers Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 162/268] ALSA: hrtimer: Fix stall by hrtimer_cancel() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 143/268] memcg: only free spare array when readers are done Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 133/268] scripts/bloat-o-meter: fix python3 syntax error Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 141/268] mm: soft-offline: check return value in second __get_any_page() call Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 137/268] zram/zcomp: use GFP_NOIO to allocate streams Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 165/268] ALSA: seq: Fix snd_seq_call_port_info_ioctl in compat mode Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 158/268] crypto: af_alg - Forbid bind(2) when nokey child sockets are present Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 152/268] crypto: algif_skcipher - Add nokey compatibility path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 144/268] panic: release stale console lock to always get the logbuf printed out Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 148/268] crypto: algif_skcipher - Require setkey before accept(2) Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 101/268] x86/mm: Add barriers and document switch_mm()-vs-flush synchronization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 150/268] crypto: af_alg - Fix socket double-free when accept fails Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 156/268] crypto: algif_hash - Remove custom release parent function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 155/268] crypto: af_alg - Allow af_af_alg_release_parent to be called on nokey path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 151/268] crypto: af_alg - Add nokey compatibility path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 134/268] ocfs2/dlm: ignore cleaning the migration mle that is inuse Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 130/268] cifs_dbg() outputs an uninitialized buffer in cifs_readdir() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 104/268] xfs: inode recovery readahead can race with inode buffer creation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 119/268] drm/i915: Restore inhibiting the load of the default context Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 110/268] ALSA: seq: Fix race at timer setup and close Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 111/268] virtio_balloon: fix race by fill and leak Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 113/268] ALSA: hda - Fix white noise on Dell Latitude E5550 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 126/268] ALSA: timer: Fix race among timer ioctls Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 129/268] cifs: fix race between call_async() and reconnect() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 099/268] ALSA: usb: Add native DSD support for Oppo HA-1 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 114/268] parisc: Fix __ARCH_SI_PREAMBLE_SIZE Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 098/268] drm/nouveau/kms: take mode_config mutex in connector hotplug path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 116/268] powerpc/module: Handle R_PPC64_ENTRY relocations Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 118/268] ALSA: usb-audio: Fix mixer ctl regression of Native Instrument devices Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 100/268] ALSA: hda - Fixup inverted internal mic for Lenovo E50-80 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 117/268] ALSA: hda - fix the headset mic detection problem for a Dell laptop Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 123/268] dmaengine: dw: fix cyclic transfer setup Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 128/268] cifs: Ratelimit kernel log messages Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 103/268] s390: fix normalization bug in exception table sorting Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 109/268] ALSA: seq: Fix missing NULL check at remove_events ioctl Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 105/268] xfs: handle dquot buffer readahead in log recovery correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 085/268] drm/dp/mst: fix in MSTB RAD initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 096/268] uml: fix hostfs mknod() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 131/268] m32r: fix m32104ut_defconfig build fail Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 120/268] drm/i915: intel_hpd_init(): Fix suspend/resume reprobing Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 112/268] virtio_balloon: fix race between migration and ballooning Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 115/268] scripts/recordmcount.pl: support data in text section on powerpc Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 097/268] uml: flush stdout before forking Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 125/268] mmc: mmci: fix an ages old detection error Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 102/268] x86/boot: Double BOOT_HEAP_SIZE to 64KB Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 106/268] clocksource/drivers/vt8500: Increase the minimum delta Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 124/268] dmaengine: dw: fix cyclic transfer callbacks Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 072/268] bcache: fix a leak in bch_cached_dev_run() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 063/268] rtlwifi: rtl8192de: Fix incorrect module parameter descriptions Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 077/268] wlcore/wl12xx: spi: fix NULL pointer dereference (Oops) Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 080/268] x86/xen: don't reset vcpu_info on a cancelled suspend Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 067/268] NFS: Fix attribute cache revalidation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 070/268] bcache: Add a cond_resched() call to gc Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 060/268] rtlwifi: rtl8723ae: Fix initialization of module parameters Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 066/268] rtlwifi: rtl8192cu: Add missing parameter setup Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 088/268] PCI: host: Mark PCIe/PCI (MSI) IRQ cascade handlers as IRQF_NO_THREAD Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 074/268] bcache: allows use of register in udev to avoid "device_busy" error. Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 071/268] bcache: clear BCACHE_DEV_UNLINK_DONE flag when attaching a backing device Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 093/268] scsi: add Synology to 1024 sector blacklist Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 083/268] drm/dp/mst: process broadcast messages correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 082/268] udf: Check output buffer length when converting name to CS0 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 089/268] btrfs: handle invalid num_stripes in sys_array Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 092/268] locks: fix unlock when fcntl_setlk races with a close Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 062/268] rtlwifi: rtl8188ee: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 078/268] Input: i8042 - add Fujitsu Lifebook U745 to the nomux list Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 061/268] rtlwifi: rtl8821ae: Fix errors in parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 075/268] bcache: prevent crash on changing writeback_running Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 064/268] rtlwifi: rtl8192se: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 084/268] drm/dp/mst: always send reply for UP request Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 079/268] libxfs: pack the agfl header structure so XFS_AGFL_SIZE is correct Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 076/268] bcache: Change refill_dirty() to always scan entire disk if necessary Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 095/268] dm snapshot: fix hung bios when copy error occurs Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 094/268] ASoC: compress: Fix compress device direction check Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 065/268] rtlwifi: rtl8192ce: Fix handling of module parameters Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 081/268] udf: Prevent buffer overrun with multi-byte characters Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 069/268] bcache: fix a livelock when we cause a huge number of cache misses Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 059/268] rtlwifi: rtl8723be: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 090/268] iwlwifi: update and fix 7265 series PCI IDs Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 091/268] iwlwifi: pcie: properly configure the debug buffer size for 8000 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 049/268] mmc: sdhci: Fix sdhci_runtime_pm_bus_on/off() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 058/268] posix-clock: Fix return code on the poll method's error path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 024/268] ovl: setattr: check permissions before copy-up Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 043/268] drm/amdgpu: Fix off-by-one errors in amdgpu_vm_bo_map Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 045/268] mmc: mmc: Fix incorrect use of driver strength switching HS200 and HS400 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 036/268] dm thin: fix race condition when destroying thin pool workqueue Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 022/268] rtlwifi: fix memory leak for USB device Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 044/268] drm/radeon: clean up fujitsu quirks Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 038/268] futex: Drop refcount if requeue_pi() acquired the rtmutex Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 041/268] coresight: checking for NULL string in coresight_name_match() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 028/268] arm64: mm: ensure that the zero page is visible to the page table walker Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 042/268] drm/radeon: Fix off-by-one errors in radeon_vm_bo_set_addr Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 025/268] ovl: check dentry positiveness in ovl_cleanup_whiteouts() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 033/268] tools: hv: vss: fix the write()'s argument: error -> vss_msg Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 030/268] powerpc: Make {cmp}xchg* and their atomic_ versions fully ordered Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 034/268] clk: exynos: use irqsave version of spin_lock to avoid deadlock with irqs Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 021/268] ext4 crypto: add missing locking for keyring_key access Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 054/268] USB: cp210x: add ID for ELV Marble Sound Board 1 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 056/268] Thermal: handle thermal zone device properly during system sleep Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 026/268] EDAC, mc_sysfs: Fix freeing bus' name Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 040/268] arm64: kernel: enforce pmuserenr_el0 initialization and restore Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 048/268] mmc: sdhci: Fix DMA descriptor with zero data length Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 023/268] wlcore/wl12xx: spi: fix oops on firmware load Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 050/268] regulator: axp20x: Fix GPIO LDO enable value for AXP22x Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 047/268] mmc: sdio: Fix invalid vdd in voltage switch power cycle Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 053/268] nfs: Fix race in __update_open_stateid() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 037/268] drm/radeon: Fix "slow" audio over DP on DCE8+ Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 032/268] Drivers: hv: vmbus: Fix a Host signaling bug Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 035/268] iommu/io-pgtable-arm: Ensure we free the final level on teardown Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 046/268] mmc: sdhci-pci: Do not default to 33 Ohm driver strength for Intel SPT Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 039/268] arm64: mdscr_el1: avoid exposing DCC to userspace Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 055/268] Thermal: initialize thermal zone device correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 052/268] [media] rc: sunxi-cir: Initialize the spinlock properly Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 017/268] time: Avoid signed overflow in timekeeping_get_ns() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 012/268] drm/amdgpu: call hpd_irq_event on resume Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 007/268] [media] si2157: return -EINVAL if firmware blob is too big Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 019/268] Bluetooth: Add support of Toshiba Broadcom based devices Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 016/268] arm64: Clear out any singlestep state on a ptrace detach operation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 015/268] ARM: mvebu: remove duplicated regulator definition in Armada 388 GP Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 011/268] KVM: x86: correctly print #AC in traces Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 005/268] [media] gspca: ov534/topro: prevent a division by 0 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 004/268] [media] vb2: fix a regression in poll() behavior for output,streams Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 018/268] ovl: root: copy attr Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 003/268] ovl: use a minimal buffer in ovl_copy_xattr Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 008/268] tools lib traceevent: Fix output of %llu for 64 bit values read on 32 bit machines Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 020/268] ext4 crypto: exit cleanly if ext4_derive_key_aes() fails Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 014/268] xhci: refuse loading if nousb is used Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 006/268] [media] media: dvb-core: Don't force CAN_INVERSION_AUTO in oneshot mode Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 009/268] cxl: use correct operator when writing pcie config space values Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 010/268] KVM: x86: expose MSR_TSC_AUX to userspace Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100

Page 6 of 13 — ← Prev page 1 … 4 5 [6] 7 8 … 13  Next page →


#1319851 — [PATCH 4.2.y-ckt 166/268] ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:20 +0100
Subject[PATCH 4.2.y-ckt 166/268] ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0
Message-ID<qVFFo-1hk-13@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit c0bcdbdff3ff73a54161fca3cb8b6cdbd0bb8762 upstream.

When a TLV ioctl with numid zero is handled, the driver may spew a
kernel warning with a stack trace at each call.  The check was
intended obviously only for a kernel driver, but not for a user
interaction.  Let's fix it.

This was spotted by syzkaller fuzzer.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/core/control.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/sound/core/control.c b/sound/core/control.c
index 196a6fe..a85d455 100644
--- a/sound/core/control.c
+++ b/sound/core/control.c
@@ -1405,6 +1405,8 @@ static int snd_ctl_tlv_ioctl(struct snd_ctl_file *file,
 		return -EFAULT;
 	if (tlv.length < sizeof(unsigned int) * 2)
 		return -EINVAL;
+	if (!tlv.numid)
+		return -EINVAL;
 	down_read(&card->controls_rwsem);
 	kctl = snd_ctl_find_numid(card, tlv.numid);
 	if (kctl == NULL) {
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319853 — [PATCH 4.2.y-ckt 167/268] ARM: debug-ll: fix BCM63xx entry for multiplatform

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:20 +0100
Subject[PATCH 4.2.y-ckt 167/268] ARM: debug-ll: fix BCM63xx entry for multiplatform
Message-ID<qVFFo-1hk-19@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Arnd Bergmann <arnd@arndb.de>

commit 6c54809977de3c9e2ef9e9934a2c6625f7e161e7 upstream.

During my randconfig build testing, I found that a kernel with
DEBUG_AT91_UART and ARCH_BCM_63XX fails to build:

arch/arm/include/debug/at91.S:18:0: error: "CONFIG_DEBUG_UART_VIRT" redefined [-Werror]

It turns out that the DEBUG_UART_BCM63XX option is enabled whenever
the ARCH_BCM_63XX is, and that breaks multiplatform kernels because
we then end up using the UART address from BCM63XX rather than the
one we actually configured (if any).

This changes the BCM63XX options to only have one Kconfig option,
and only enable that if the user explicitly turns it on.

Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Fixes: b51312bebfa4 ("ARM: BCM63XX: add low-level UART debug support")
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/arm/Kconfig.debug | 17 ++++++-----------
 1 file changed, 6 insertions(+), 11 deletions(-)

diff --git a/arch/arm/Kconfig.debug b/arch/arm/Kconfig.debug
index a2e16f9..55ef850 100644
--- a/arch/arm/Kconfig.debug
+++ b/arch/arm/Kconfig.debug
@@ -162,10 +162,9 @@ choice
 		  mobile SoCs in the Kona family of chips (e.g. bcm28155,
 		  bcm11351, etc...)
 
-	config DEBUG_BCM63XX
+	config DEBUG_BCM63XX_UART
 		bool "Kernel low-level debugging on BCM63XX UART"
 		depends on ARCH_BCM_63XX
-		select DEBUG_UART_BCM63XX
 
 	config DEBUG_BERLIN_UART
 		bool "Marvell Berlin SoC Debug UART"
@@ -1343,7 +1342,7 @@ config DEBUG_LL_INCLUDE
 	default "debug/vf.S" if DEBUG_VF_UART
 	default "debug/vt8500.S" if DEBUG_VT8500_UART0
 	default "debug/zynq.S" if DEBUG_ZYNQ_UART0 || DEBUG_ZYNQ_UART1
-	default "debug/bcm63xx.S" if DEBUG_UART_BCM63XX
+	default "debug/bcm63xx.S" if DEBUG_BCM63XX_UART
 	default "debug/digicolor.S" if DEBUG_DIGICOLOR_UA0
 	default "mach/debug-macro.S"
 
@@ -1359,10 +1358,6 @@ config DEBUG_UART_8250
 		ARCH_IOP33X || ARCH_IXP4XX || \
 		ARCH_LPC32XX || ARCH_MV78XX0 || ARCH_ORION5X || ARCH_RPC
 
-# Compatibility options for BCM63xx
-config DEBUG_UART_BCM63XX
-	def_bool ARCH_BCM_63XX
-
 config DEBUG_UART_PHYS
 	hex "Physical base address of debug UART"
 	default 0x00100a00 if DEBUG_NETX_UART
@@ -1457,7 +1452,7 @@ config DEBUG_UART_PHYS
 	default 0xfffb0000 if DEBUG_OMAP1UART1 || DEBUG_OMAP7XXUART1
 	default 0xfffb0800 if DEBUG_OMAP1UART2 || DEBUG_OMAP7XXUART2
 	default 0xfffb9800 if DEBUG_OMAP1UART3 || DEBUG_OMAP7XXUART3
-	default 0xfffe8600 if DEBUG_UART_BCM63XX
+	default 0xfffe8600 if DEBUG_BCM63XX_UART
 	default 0xfffff700 if ARCH_IOP33X
 	depends on ARCH_EP93XX || \
 	        DEBUG_LL_UART_8250 || DEBUG_LL_UART_PL01X || \
@@ -1469,7 +1464,7 @@ config DEBUG_UART_PHYS
 		DEBUG_RCAR_GEN2_SCIF0 || DEBUG_RCAR_GEN2_SCIF2 || \
 		DEBUG_RMOBILE_SCIFA0 || DEBUG_RMOBILE_SCIFA1 || \
 		DEBUG_RMOBILE_SCIFA4 || DEBUG_S3C24XX_UART || \
-		DEBUG_UART_BCM63XX || DEBUG_ASM9260_UART || \
+		DEBUG_BCM63XX_UART || DEBUG_ASM9260_UART || \
 		DEBUG_SIRFSOC_UART || DEBUG_DIGICOLOR_UA0
 
 config DEBUG_UART_VIRT
@@ -1509,7 +1504,7 @@ config DEBUG_UART_VIRT
 	default 0xfb10c000 if DEBUG_REALVIEW_PB1176_PORT
 	default 0xfc40ab00 if DEBUG_BRCMSTB_UART
 	default 0xfc705000 if DEBUG_ZTE_ZX
-	default 0xfcfe8600 if DEBUG_UART_BCM63XX
+	default 0xfcfe8600 if DEBUG_BCM63XX_UART
 	default 0xfd000000 if ARCH_SPEAR3XX || ARCH_SPEAR6XX
 	default 0xfd000000 if ARCH_SPEAR13XX
 	default 0xfd012000 if ARCH_MV78XX0
@@ -1560,7 +1555,7 @@ config DEBUG_UART_VIRT
 		DEBUG_UART_8250 || DEBUG_UART_PL01X || DEBUG_MESON_UARTAO || \
 		DEBUG_NETX_UART || \
 		DEBUG_QCOM_UARTDM || DEBUG_S3C24XX_UART || \
-		DEBUG_UART_BCM63XX || DEBUG_ASM9260_UART || \
+		DEBUG_BCM63XX_UART || DEBUG_ASM9260_UART || \
 		DEBUG_SIRFSOC_UART || DEBUG_DIGICOLOR_UA0
 
 config DEBUG_UART_8250_SHIFT
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319854 — [PATCH 4.2.y-ckt 168/268] xfs: log mount failures don't wait for buffers to be released

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:20 +0100
Subject[PATCH 4.2.y-ckt 168/268] xfs: log mount failures don't wait for buffers to be released
Message-ID<qVFFo-1hk-17@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Dave Chinner <dchinner@redhat.com>

commit 85bec5460ad8e05e0a8d70fb0f6750eb719ad092 upstream.

Recently I've been seeing xfs/051 fail on 1k block size filesystems.
Trying to trace the events during the test lead to the problem going
away, indicating that it was a race condition that lead to this
ASSERT failure:

XFS: Assertion failed: atomic_read(&pag->pag_ref) == 0, file: fs/xfs/xfs_mount.c, line: 156
.....
[<ffffffff814e1257>] xfs_free_perag+0x87/0xb0
[<ffffffff814e21b9>] xfs_mountfs+0x4d9/0x900
[<ffffffff814e5dff>] xfs_fs_fill_super+0x3bf/0x4d0
[<ffffffff811d8800>] mount_bdev+0x180/0x1b0
[<ffffffff814e3ff5>] xfs_fs_mount+0x15/0x20
[<ffffffff811d90a8>] mount_fs+0x38/0x170
[<ffffffff811f4347>] vfs_kern_mount+0x67/0x120
[<ffffffff811f7018>] do_mount+0x218/0xd60
[<ffffffff811f7e5b>] SyS_mount+0x8b/0xd0

When I finally caught it with tracing enabled, I saw that AG 2 had
an elevated reference count and a buffer was responsible for it. I
tracked down the specific buffer, and found that it was missing the
final reference count release that would put it back on the LRU and
hence be found by xfs_wait_buftarg() calls in the log mount failure
handling.

The last four traces for the buffer before the assert were (trimmed
for relevance)

kworker/0:1-5259   xfs_buf_iodone:        hold 2  lock 0 flags ASYNC
kworker/0:1-5259   xfs_buf_ioerror:       hold 2  lock 0 error -5
mount-7163	   xfs_buf_lock_done:     hold 2  lock 0 flags ASYNC
mount-7163	   xfs_buf_unlock:        hold 2  lock 1 flags ASYNC

This is an async write that is completing, so there's nobody waiting
for it directly.  Hence we call xfs_buf_relse() once all the
processing is complete. That does:

static inline void xfs_buf_relse(xfs_buf_t *bp)
{
	xfs_buf_unlock(bp);
	xfs_buf_rele(bp);
}

Now, it's clear that mount is waiting on the buffer lock, and that
it has been released by xfs_buf_relse() and gained by mount. This is
expected, because at this point the mount process is in
xfs_buf_delwri_submit() waiting for all the IO it submitted to
complete.

The mount process, however, is waiting on the lock for the buffer
because it is in xfs_buf_delwri_submit(). This waits for IO
completion, but it doesn't wait for the buffer reference owned by
the IO to go away. The mount process collects all the completions,
fails the log recovery, and the higher level code then calls
xfs_wait_buftarg() to free all the remaining buffers in the
filesystem.

The issue is that on unlocking the buffer, the scheduler has decided
that the mount process has higher priority than the the kworker
thread that is running the IO completion, and so immediately
switched contexts to the mount process from the semaphore unlock
code, hence preventing the kworker thread from finishing the IO
completion and releasing the IO reference to the buffer.

Hence by the time that xfs_wait_buftarg() is run, the buffer still
has an active reference and so isn't on the LRU list that the
function walks to free the remaining buffers. Hence we miss that
buffer and continue onwards to tear down the mount structures,
at which time we get find a stray reference count on the perag
structure. On a non-debug kernel, this will be ignored and the
structure torn down and freed. Hence when the kworker thread is then
rescheduled and the buffer released and freed, it will access a
freed perag structure.

The problem here is that when the log mount fails, we still need to
quiesce the log to ensure that the IO workqueues have returned to
idle before we run xfs_wait_buftarg(). By synchronising the
workqueues, we ensure that all IO completions are fully processed,
not just to the point where buffers have been unlocked. This ensures
we don't end up in the situation above.

Signed-off-by: Dave Chinner <dchinner@redhat.com>
Reviewed-by: Brian Foster <bfoster@redhat.com>
Signed-off-by: Dave Chinner <david@fromorbit.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/xfs/xfs_buf.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/fs/xfs/xfs_buf.c b/fs/xfs/xfs_buf.c
index 98bf50c..7cc9cf4 100644
--- a/fs/xfs/xfs_buf.c
+++ b/fs/xfs/xfs_buf.c
@@ -1529,6 +1529,16 @@ xfs_wait_buftarg(
 	LIST_HEAD(dispose);
 	int loop = 0;
 
+	/*
+	 * We need to flush the buffer workqueue to ensure that all IO
+	 * completion processing is 100% done. Just waiting on buffer locks is
+	 * not sufficient for async IO as the reference count held over IO is
+	 * not released until after the buffer lock is dropped. Hence we need to
+	 * ensure here that all reference counts have been dropped before we
+	 * start walking the LRU list.
+	 */
+	drain_workqueue(btp->bt_mount->m_buf_workqueue);
+
 	/* loop until there is nothing left on the lru list. */
 	while (list_lru_count(&btp->bt_lru)) {
 		list_lru_walk(&btp->bt_lru, xfs_buftarg_wait_rele,
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319856 — [PATCH 4.2.y-ckt 179/268] ALSA: hda - Flush the pending probe work at remove

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:20 +0100
Subject[PATCH 4.2.y-ckt 179/268] ALSA: hda - Flush the pending probe work at remove
Message-ID<qVFFo-1hk-21@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit 991f86d7ae4e1f8c15806e62f97af519e3cdd860 upstream.

As HD-audio driver does deferred probe internally via workqueue, the
driver might go into the mixed state doing both probe and remove when
the module gets unloaded during the probe work.  This eventually
triggers an Oops, unsurprisingly.

For avoiding this race, we just need to flush the pending probe work
explicitly before actually starting the resource release.

Bugzilla: https://bugzilla.opensuse.org/show_bug.cgi?id=960710
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/pci/hda/hda_intel.c | 10 +++++++++-
 1 file changed, 9 insertions(+), 1 deletion(-)

diff --git a/sound/pci/hda/hda_intel.c b/sound/pci/hda/hda_intel.c
index de2b2e2..e61fbf4 100644
--- a/sound/pci/hda/hda_intel.c
+++ b/sound/pci/hda/hda_intel.c
@@ -2100,9 +2100,17 @@ i915_power_fail:
 static void azx_remove(struct pci_dev *pci)
 {
 	struct snd_card *card = pci_get_drvdata(pci);
+	struct azx *chip;
+	struct hda_intel *hda;
+
+	if (card) {
+		/* flush the pending probing work */
+		chip = card->private_data;
+		hda = container_of(chip, struct hda_intel, chip);
+		flush_work(&hda->probe_work);
 
-	if (card)
 		snd_card_free(card);
+	}
 }
 
 static void azx_shutdown(struct pci_dev *pci)
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319858 — [PATCH 4.2.y-ckt 108/268] x86/reboot/quirks: Add iMac10,1 to pci_reboot_dmi_table[]

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:20 +0100
Subject[PATCH 4.2.y-ckt 108/268] x86/reboot/quirks: Add iMac10,1 to pci_reboot_dmi_table[]
Message-ID<qVFFo-1hk-25@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Mario Kleiner <mario.kleiner.de@gmail.com>

commit 2f0c0b2d96b1205efb14347009748d786c2d9ba5 upstream.

Without the reboot=pci method, the iMac 10,1 simply
hangs after printing "Restarting system" at the point
when it should reboot. This fixes it.

Signed-off-by: Mario Kleiner <mario.kleiner.de@gmail.com>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Brian Gerst <brgerst@gmail.com>
Cc: Dave Jones <davej@codemonkey.org.uk>
Cc: Denys Vlasenko <dvlasenk@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Link: http://lkml.kernel.org/r/1450466646-26663-1-git-send-email-mario.kleiner.de@gmail.com
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/x86/kernel/reboot.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/arch/x86/kernel/reboot.c b/arch/x86/kernel/reboot.c
index 86db4bc..0549ae3 100644
--- a/arch/x86/kernel/reboot.c
+++ b/arch/x86/kernel/reboot.c
@@ -182,6 +182,14 @@ static struct dmi_system_id __initdata reboot_dmi_table[] = {
 			DMI_MATCH(DMI_PRODUCT_NAME, "iMac9,1"),
 		},
 	},
+	{	/* Handle problems with rebooting on the iMac10,1. */
+		.callback = set_pci_reboot,
+		.ident = "Apple iMac10,1",
+		.matches = {
+		    DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."),
+		    DMI_MATCH(DMI_PRODUCT_NAME, "iMac10,1"),
+		},
+	},
 
 	/* ASRock */
 	{	/* Handle problems with rebooting on ASRock Q1900DC-ITX */
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319866 — [PATCH 4.2.y-ckt 170/268] crypto: crc32c - Fix crc32c soft dependency

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:20 +0100
Subject[PATCH 4.2.y-ckt 170/268] crypto: crc32c - Fix crc32c soft dependency
Message-ID<qVFFp-1hk-41@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Jean Delvare <jdelvare@suse.de>

commit fd7f6727102a1ccf6b4c1dfcc631f9b546526b26 upstream.

I don't think it makes sense for a module to have a soft dependency
on itself. This seems quite cyclic by nature and I can't see what
purpose it could serve.

OTOH libcrc32c calls crypto_alloc_shash("crc32c", 0, 0) so it pretty
much assumes that some incarnation of the "crc32c" hash algorithm has
been loaded. Therefore it makes sense to have the soft dependency
there (as crc-t10dif does.)

Cc: Tim Chen <tim.c.chen@linux.intel.com>
Cc: "David S. Miller" <davem@davemloft.net>
Signed-off-by: Jean Delvare <jdelvare@suse.de>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/crc32c_generic.c | 1 -
 lib/libcrc32c.c         | 1 +
 2 files changed, 1 insertion(+), 1 deletion(-)

diff --git a/crypto/crc32c_generic.c b/crypto/crc32c_generic.c
index 06f1b60..4c0a0e2 100644
--- a/crypto/crc32c_generic.c
+++ b/crypto/crc32c_generic.c
@@ -172,4 +172,3 @@ MODULE_DESCRIPTION("CRC32c (Castagnoli) calculations wrapper for lib/crc32c");
 MODULE_LICENSE("GPL");
 MODULE_ALIAS_CRYPTO("crc32c");
 MODULE_ALIAS_CRYPTO("crc32c-generic");
-MODULE_SOFTDEP("pre: crc32c");
diff --git a/lib/libcrc32c.c b/lib/libcrc32c.c
index 6a08ce7..acf9da4 100644
--- a/lib/libcrc32c.c
+++ b/lib/libcrc32c.c
@@ -74,3 +74,4 @@ module_exit(libcrc32c_mod_fini);
 MODULE_AUTHOR("Clay Haapala <chaapala@cisco.com>");
 MODULE_DESCRIPTION("CRC32c (Castagnoli) calculations");
 MODULE_LICENSE("GPL");
+MODULE_SOFTDEP("pre: crc32c");
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319870 — [PATCH 4.2.y-ckt 173/268] IB/mlx5: Expose correct maximum number of CQE capacity

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:20 +0100
Subject[PATCH 4.2.y-ckt 173/268] IB/mlx5: Expose correct maximum number of CQE capacity
Message-ID<qVFFp-1hk-55@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Leon Romanovsky <leonro@mellanox.com>

commit 9f17768611ebf81dfac69948dd12622b6f2e45fc upstream.

Maximum number of EQE capacity per CQ was mistakenly exposed
as CQE. Fix that.

Fixes: 938fe83c8dcb ("net/mlx5_core: New device capabilities handling")
Signed-off-by: Leon Romanovsky <leonro@mellanox.com>
Reviewed-by: Sagi Grimberg <sagig@mellanox.com>
Signed-off-by: Doug Ledford <dledford@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/infiniband/hw/mlx5/main.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/infiniband/hw/mlx5/main.c b/drivers/infiniband/hw/mlx5/main.c
index 085c24b..aa64c7b 100644
--- a/drivers/infiniband/hw/mlx5/main.c
+++ b/drivers/infiniband/hw/mlx5/main.c
@@ -274,7 +274,7 @@ static int mlx5_ib_query_device(struct ib_device *ibdev,
 		     sizeof(struct mlx5_wqe_data_seg);
 	props->max_sge = min(max_rq_sg, max_sq_sg);
 	props->max_cq		   = 1 << MLX5_CAP_GEN(mdev, log_max_cq);
-	props->max_cqe = (1 << MLX5_CAP_GEN(mdev, log_max_eq_sz)) - 1;
+	props->max_cqe = (1 << MLX5_CAP_GEN(mdev, log_max_cq_sz)) - 1;
 	props->max_mr		   = 1 << MLX5_CAP_GEN(mdev, log_max_mkey);
 	props->max_pd		   = 1 << MLX5_CAP_GEN(mdev, log_max_pd);
 	props->max_qp_rd_atom	   = 1 << MLX5_CAP_GEN(mdev, log_max_ra_req_qp);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319874 — [PATCH 4.2.y-ckt 171/268] IB/qib: fix mcast detach when qp not attached

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:20 +0100
Subject[PATCH 4.2.y-ckt 171/268] IB/qib: fix mcast detach when qp not attached
Message-ID<qVFFq-1hk-63@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Mike Marciniszyn <mike.marciniszyn@intel.com>

commit 09dc9cd6528f5b52bcbd3292a6312e762c85260f upstream.

The code produces the following trace:

[1750924.419007] general protection fault: 0000 [#3] SMP
[1750924.420364] Modules linked in: nfnetlink autofs4 rpcsec_gss_krb5 nfsv4
dcdbas rfcomm bnep bluetooth nfsd auth_rpcgss nfs_acl dm_multipath nfs lockd
scsi_dh sunrpc fscache radeon ttm drm_kms_helper drm serio_raw parport_pc
ppdev i2c_algo_bit lpc_ich ipmi_si ib_mthca ib_qib dca lp parport ib_ipoib
mac_hid ib_cm i3000_edac ib_sa ib_uverbs edac_core ib_umad ib_mad ib_core
ib_addr tg3 ptp dm_mirror dm_region_hash dm_log psmouse pps_core
[1750924.420364] CPU: 1 PID: 8401 Comm: python Tainted: G D
3.13.0-39-generic #66-Ubuntu
[1750924.420364] Hardware name: Dell Computer Corporation PowerEdge
860/0XM089, BIOS A04 07/24/2007
[1750924.420364] task: ffff8800366a9800 ti: ffff88007af1c000 task.ti:
ffff88007af1c000
[1750924.420364] RIP: 0010:[<ffffffffa0131d51>] [<ffffffffa0131d51>]
qib_mcast_qp_free+0x11/0x50 [ib_qib]
[1750924.420364] RSP: 0018:ffff88007af1dd70  EFLAGS: 00010246
[1750924.420364] RAX: 0000000000000001 RBX: ffff88007b822688 RCX:
000000000000000f
[1750924.420364] RDX: ffff88007b822688 RSI: ffff8800366c15a0 RDI:
6764697200000000
[1750924.420364] RBP: ffff88007af1dd78 R08: 0000000000000001 R09:
0000000000000000
[1750924.420364] R10: 0000000000000011 R11: 0000000000000246 R12:
ffff88007baa1d98
[1750924.420364] R13: ffff88003ecab000 R14: ffff88007b822660 R15:
0000000000000000
[1750924.420364] FS:  00007ffff7fd8740(0000) GS:ffff88007fc80000(0000)
knlGS:0000000000000000
[1750924.420364] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[1750924.420364] CR2: 00007ffff597c750 CR3: 000000006860b000 CR4:
00000000000007e0
[1750924.420364] Stack:
[1750924.420364]  ffff88007b822688 ffff88007af1ddf0 ffffffffa0132429
000000007af1de20
[1750924.420364]  ffff88007baa1dc8 ffff88007baa0000 ffff88007af1de70
ffffffffa00cb313
[1750924.420364]  00007fffffffde88 0000000000000000 0000000000000008
ffff88003ecab000
[1750924.420364] Call Trace:
[1750924.420364]  [<ffffffffa0132429>] qib_multicast_detach+0x1e9/0x350
[ib_qib]
[1750924.568035]  [<ffffffffa00cb313>] ? ib_uverbs_modify_qp+0x323/0x3d0
[ib_uverbs]
[1750924.568035]  [<ffffffffa0092d61>] ib_detach_mcast+0x31/0x50 [ib_core]
[1750924.568035]  [<ffffffffa00cc213>] ib_uverbs_detach_mcast+0x93/0x170
[ib_uverbs]
[1750924.568035]  [<ffffffffa00c61f6>] ib_uverbs_write+0xc6/0x2c0 [ib_uverbs]
[1750924.568035]  [<ffffffff81312e68>] ? apparmor_file_permission+0x18/0x20
[1750924.568035]  [<ffffffff812d4cd3>] ? security_file_permission+0x23/0xa0
[1750924.568035]  [<ffffffff811bd214>] vfs_write+0xb4/0x1f0
[1750924.568035]  [<ffffffff811bdc49>] SyS_write+0x49/0xa0
[1750924.568035]  [<ffffffff8172f7ed>] system_call_fastpath+0x1a/0x1f
[1750924.568035] Code: 66 2e 0f 1f 84 00 00 00 00 00 31 c0 5d c3 66 2e 0f 1f
84 00 00 00 00 00 66 90 0f 1f 44 00 00 55 48 89 e5 53 48 89 fb 48 8b 7f 10
<f0> ff 8f 40 01 00 00 74 0e 48 89 df e8 8e f8 06 e1 5b 5d c3 0f
[1750924.568035] RIP  [<ffffffffa0131d51>] qib_mcast_qp_free+0x11/0x50
[ib_qib]
[1750924.568035]  RSP <ffff88007af1dd70>
[1750924.650439] ---[ end trace 73d5d4b3f8ad4851 ]

The fix is to note the qib_mcast_qp that was found.   If none is found, then
return EINVAL indicating the error.

Reviewed-by: Dennis Dalessandro <dennis.dalessandro@intel.com>
Reported-by: Jason Gunthorpe <jgunthorpe@obsidianresearch.com>
Signed-off-by: Mike Marciniszyn <mike.marciniszyn@intel.com>
Signed-off-by: Doug Ledford <dledford@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/infiniband/hw/qib/qib_verbs_mcast.c | 35 +++++++++++++----------------
 1 file changed, 15 insertions(+), 20 deletions(-)

diff --git a/drivers/infiniband/hw/qib/qib_verbs_mcast.c b/drivers/infiniband/hw/qib/qib_verbs_mcast.c
index f8ea069..b2fb528 100644
--- a/drivers/infiniband/hw/qib/qib_verbs_mcast.c
+++ b/drivers/infiniband/hw/qib/qib_verbs_mcast.c
@@ -286,15 +286,13 @@ int qib_multicast_detach(struct ib_qp *ibqp, union ib_gid *gid, u16 lid)
 	struct qib_ibdev *dev = to_idev(ibqp->device);
 	struct qib_ibport *ibp = to_iport(ibqp->device, qp->port_num);
 	struct qib_mcast *mcast = NULL;
-	struct qib_mcast_qp *p, *tmp;
+	struct qib_mcast_qp *p, *tmp, *delp = NULL;
 	struct rb_node *n;
 	int last = 0;
 	int ret;
 
-	if (ibqp->qp_num <= 1 || qp->state == IB_QPS_RESET) {
-		ret = -EINVAL;
-		goto bail;
-	}
+	if (ibqp->qp_num <= 1 || qp->state == IB_QPS_RESET)
+		return -EINVAL;
 
 	spin_lock_irq(&ibp->lock);
 
@@ -303,8 +301,7 @@ int qib_multicast_detach(struct ib_qp *ibqp, union ib_gid *gid, u16 lid)
 	while (1) {
 		if (n == NULL) {
 			spin_unlock_irq(&ibp->lock);
-			ret = -EINVAL;
-			goto bail;
+			return -EINVAL;
 		}
 
 		mcast = rb_entry(n, struct qib_mcast, rb_node);
@@ -328,6 +325,7 @@ int qib_multicast_detach(struct ib_qp *ibqp, union ib_gid *gid, u16 lid)
 		 */
 		list_del_rcu(&p->list);
 		mcast->n_attached--;
+		delp = p;
 
 		/* If this was the last attached QP, remove the GID too. */
 		if (list_empty(&mcast->qp_list)) {
@@ -338,15 +336,16 @@ int qib_multicast_detach(struct ib_qp *ibqp, union ib_gid *gid, u16 lid)
 	}
 
 	spin_unlock_irq(&ibp->lock);
+	/* QP not attached */
+	if (!delp)
+		return -EINVAL;
+	/*
+	 * Wait for any list walkers to finish before freeing the
+	 * list element.
+	 */
+	wait_event(mcast->wait, atomic_read(&mcast->refcount) <= 1);
+	qib_mcast_qp_free(delp);
 
-	if (p) {
-		/*
-		 * Wait for any list walkers to finish before freeing the
-		 * list element.
-		 */
-		wait_event(mcast->wait, atomic_read(&mcast->refcount) <= 1);
-		qib_mcast_qp_free(p);
-	}
 	if (last) {
 		atomic_dec(&mcast->refcount);
 		wait_event(mcast->wait, !atomic_read(&mcast->refcount));
@@ -355,11 +354,7 @@ int qib_multicast_detach(struct ib_qp *ibqp, union ib_gid *gid, u16 lid)
 		dev->n_mcast_grps_allocated--;
 		spin_unlock_irq(&dev->n_mcast_grps_lock);
 	}
-
-	ret = 0;
-
-bail:
-	return ret;
+	return 0;
 }
 
 int qib_mcast_tree_empty(struct qib_ibport *ibp)
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319877 — [PATCH 4.2.y-ckt 169/268] crypto: algif_skcipher - Load TX SG list after waiting

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:20 +0100
Subject[PATCH 4.2.y-ckt 169/268] crypto: algif_skcipher - Load TX SG list after waiting
Message-ID<qVFFq-1hk-65@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit 4f0414e54e4d1893c6f08260693f8ef84c929293 upstream.

We need to load the TX SG list in sendmsg(2) after waiting for
incoming data, not before.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Tested-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/algif_skcipher.c | 14 +++++++-------
 1 file changed, 7 insertions(+), 7 deletions(-)

diff --git a/crypto/algif_skcipher.c b/crypto/algif_skcipher.c
index 74ffe56..1a0fe4f 100644
--- a/crypto/algif_skcipher.c
+++ b/crypto/algif_skcipher.c
@@ -647,13 +647,6 @@ static int skcipher_recvmsg_sync(struct socket *sock, struct msghdr *msg,
 
 	lock_sock(sk);
 	while (msg_data_left(msg)) {
-		sgl = list_first_entry(&ctx->tsgl,
-				       struct skcipher_sg_list, list);
-		sg = sgl->sg;
-
-		while (!sg->length)
-			sg++;
-
 		if (!ctx->used) {
 			err = skcipher_wait_for_data(sk, flags);
 			if (err)
@@ -674,6 +667,13 @@ static int skcipher_recvmsg_sync(struct socket *sock, struct msghdr *msg,
 		if (!used)
 			goto free;
 
+		sgl = list_first_entry(&ctx->tsgl,
+				       struct skcipher_sg_list, list);
+		sg = sgl->sg;
+
+		while (!sg->length)
+			sg++;
+
 		ablkcipher_request_set_crypt(&ctx->req, sg,
 					     ctx->rsgl.sg, used,
 					     ctx->iv);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319882 — [PATCH 4.2.y-ckt 121/268] x86/mm: Improve switch_mm() barrier comments

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:20 +0100
Subject[PATCH 4.2.y-ckt 121/268] x86/mm: Improve switch_mm() barrier comments
Message-ID<qVFFr-1hk-75@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Andy Lutomirski <luto@kernel.org>

commit 4eaffdd5a5fe6ff9f95e1ab4de1ac904d5e0fa8b upstream.

My previous comments were still a bit confusing and there was a
typo. Fix it up.

Reported-by: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Andy Lutomirski <luto@kernel.org>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Brian Gerst <brgerst@gmail.com>
Cc: Dave Hansen <dave.hansen@linux.intel.com>
Cc: Denys Vlasenko <dvlasenk@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Rik van Riel <riel@redhat.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Fixes: 71b3c126e611 ("x86/mm: Add barriers and document switch_mm()-vs-flush synchronization")
Link: http://lkml.kernel.org/r/0a0b43cdcdd241c5faaaecfbcc91a155ddedc9a1.1452631609.git.luto@kernel.org
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/x86/include/asm/mmu_context.h | 15 ++++++++-------
 1 file changed, 8 insertions(+), 7 deletions(-)

diff --git a/arch/x86/include/asm/mmu_context.h b/arch/x86/include/asm/mmu_context.h
index 48e8661..a009082 100644
--- a/arch/x86/include/asm/mmu_context.h
+++ b/arch/x86/include/asm/mmu_context.h
@@ -120,14 +120,16 @@ static inline void switch_mm(struct mm_struct *prev, struct mm_struct *next,
 		 * be sent, and CPU 0's TLB will contain a stale entry.)
 		 *
 		 * The bad outcome can occur if either CPU's load is
-		 * reordered before that CPU's store, so both CPUs much
+		 * reordered before that CPU's store, so both CPUs must
 		 * execute full barriers to prevent this from happening.
 		 *
 		 * Thus, switch_mm needs a full barrier between the
 		 * store to mm_cpumask and any operation that could load
-		 * from next->pgd.  This barrier synchronizes with
-		 * remote TLB flushers.  Fortunately, load_cr3 is
-		 * serializing and thus acts as a full barrier.
+		 * from next->pgd.  TLB fills are special and can happen
+		 * due to instruction fetches or for no reason at all,
+		 * and neither LOCK nor MFENCE orders them.
+		 * Fortunately, load_cr3() is serializing and gives the
+		 * ordering guarantee we need.
 		 *
 		 */
 		load_cr3(next->pgd);
@@ -174,9 +176,8 @@ static inline void switch_mm(struct mm_struct *prev, struct mm_struct *next,
 			 * tlb flush IPI delivery. We must reload CR3
 			 * to make sure to use no freed page tables.
 			 *
-			 * As above, this is a barrier that forces
-			 * TLB repopulation to be ordered after the
-			 * store to mm_cpumask.
+			 * As above, load_cr3() is serializing and orders TLB
+			 * fills with respect to the mm_cpumask write.
 			 */
 			load_cr3(next->pgd);
 			trace_tlb_flush(TLB_FLUSH_ON_TASK_SWITCH, TLB_FLUSH_ALL);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319884 — [PATCH 4.2.y-ckt 161/268] crypto: algif_skcipher - Fix race condition in skcipher_check_key

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 161/268] crypto: algif_skcipher - Fix race condition in skcipher_check_key
Message-ID<qVFP4-1mL-1@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit 1822793a523e5d5730b19cc21160ff1717421bc8 upstream.

We need to lock the child socket in skcipher_check_key as otherwise
two simultaneous calls can cause the parent socket to be freed.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/algif_skcipher.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/crypto/algif_skcipher.c b/crypto/algif_skcipher.c
index 8d4bf6e..74ffe56 100644
--- a/crypto/algif_skcipher.c
+++ b/crypto/algif_skcipher.c
@@ -756,22 +756,23 @@ static struct proto_ops algif_skcipher_ops = {
 
 static int skcipher_check_key(struct socket *sock)
 {
-	int err;
+	int err = 0;
 	struct sock *psk;
 	struct alg_sock *pask;
 	struct skcipher_tfm *tfm;
 	struct sock *sk = sock->sk;
 	struct alg_sock *ask = alg_sk(sk);
 
+	lock_sock(sk);
 	if (ask->refcnt)
-		return 0;
+		goto unlock_child;
 
 	psk = ask->parent;
 	pask = alg_sk(ask->parent);
 	tfm = pask->private;
 
 	err = -ENOKEY;
-	lock_sock(psk);
+	lock_sock_nested(psk, SINGLE_DEPTH_NESTING);
 	if (!tfm->has_key)
 		goto unlock;
 
@@ -785,6 +786,8 @@ static int skcipher_check_key(struct socket *sock)
 
 unlock:
 	release_sock(psk);
+unlock_child:
+	release_sock(sk);
 
 	return err;
 }
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319885 — [PATCH 4.2.y-ckt 153/268] crypto: hash - Add crypto_ahash_has_setkey

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 153/268] crypto: hash - Add crypto_ahash_has_setkey
Message-ID<qVFP4-1mL-7@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit a5596d6332787fd383b3b5427b41f94254430827 upstream.

This patch adds a way for ahash users to determine whether a key
is required by a crypto_ahash transform.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/ahash.c        | 5 ++++-
 crypto/shash.c        | 4 +++-
 include/crypto/hash.h | 6 ++++++
 3 files changed, 13 insertions(+), 2 deletions(-)

diff --git a/crypto/ahash.c b/crypto/ahash.c
index 9c1dc8d..d19b523 100644
--- a/crypto/ahash.c
+++ b/crypto/ahash.c
@@ -451,6 +451,7 @@ static int crypto_ahash_init_tfm(struct crypto_tfm *tfm)
 	struct ahash_alg *alg = crypto_ahash_alg(hash);
 
 	hash->setkey = ahash_nosetkey;
+	hash->has_setkey = false;
 	hash->export = ahash_no_export;
 	hash->import = ahash_no_import;
 
@@ -463,8 +464,10 @@ static int crypto_ahash_init_tfm(struct crypto_tfm *tfm)
 	hash->finup = alg->finup ?: ahash_def_finup;
 	hash->digest = alg->digest;
 
-	if (alg->setkey)
+	if (alg->setkey) {
 		hash->setkey = alg->setkey;
+		hash->has_setkey = true;
+	}
 	if (alg->export)
 		hash->export = alg->export;
 	if (alg->import)
diff --git a/crypto/shash.c b/crypto/shash.c
index ecb1e3d..88a27de 100644
--- a/crypto/shash.c
+++ b/crypto/shash.c
@@ -355,8 +355,10 @@ int crypto_init_shash_ops_async(struct crypto_tfm *tfm)
 	crt->finup = shash_async_finup;
 	crt->digest = shash_async_digest;
 
-	if (alg->setkey)
+	if (alg->setkey) {
 		crt->setkey = shash_async_setkey;
+		crt->has_setkey = true;
+	}
 	if (alg->export)
 		crt->export = shash_async_export;
 	if (alg->import)
diff --git a/include/crypto/hash.h b/include/crypto/hash.h
index 57c8a6e..07c3a93 100644
--- a/include/crypto/hash.h
+++ b/include/crypto/hash.h
@@ -199,6 +199,7 @@ struct crypto_ahash {
 		      unsigned int keylen);
 
 	unsigned int reqsize;
+	bool has_setkey;
 	struct crypto_tfm base;
 };
 
@@ -356,6 +357,11 @@ static inline void *ahash_request_ctx(struct ahash_request *req)
 int crypto_ahash_setkey(struct crypto_ahash *tfm, const u8 *key,
 			unsigned int keylen);
 
+static inline bool crypto_ahash_has_setkey(struct crypto_ahash *tfm)
+{
+	return tfm->has_setkey;
+}
+
 /**
  * crypto_ahash_finup() - update and finalize message digest
  * @req: reference to the ahash_request handle that holds all information
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319886 — [PATCH 4.2.y-ckt 164/268] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 164/268] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode
Message-ID<qVFP4-1mL-11@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Nicolas Boichat <drinkcat@chromium.org>

commit 43c54b8c7cfe22f868a751ba8a59abf1724160b1 upstream.

This reverts one hunk of
commit ef44a1ec6eee ("ALSA: sound/core: use memdup_user()"), which
replaced a number of kmalloc followed by memcpy with memdup calls.

In this case, we are copying from a struct snd_pcm_hw_params32 to
a struct snd_pcm_hw_params, but the latter is 4 bytes longer than
the 32-bit version, so we need to separate kmalloc and copy calls.

This actually leads to an out-of-bounds memory access later on
in sound/soc/soc-pcm.c:soc_pcm_hw_params() (detected using KASan).

Fixes: ef44a1ec6eee ('ALSA: sound/core: use memdup_user()')
Signed-off-by: Nicolas Boichat <drinkcat@chromium.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/core/pcm_compat.c | 13 +++++++++----
 1 file changed, 9 insertions(+), 4 deletions(-)

diff --git a/sound/core/pcm_compat.c b/sound/core/pcm_compat.c
index b48b434..9630e9f 100644
--- a/sound/core/pcm_compat.c
+++ b/sound/core/pcm_compat.c
@@ -255,10 +255,15 @@ static int snd_pcm_ioctl_hw_params_compat(struct snd_pcm_substream *substream,
 	if (! (runtime = substream->runtime))
 		return -ENOTTY;
 
-	/* only fifo_size is different, so just copy all */
-	data = memdup_user(data32, sizeof(*data32));
-	if (IS_ERR(data))
-		return PTR_ERR(data);
+	data = kmalloc(sizeof(*data), GFP_KERNEL);
+	if (!data)
+		return -ENOMEM;
+
+	/* only fifo_size (RO from userspace) is different, so just copy all */
+	if (copy_from_user(data, data32, sizeof(*data32))) {
+		err = -EFAULT;
+		goto error;
+	}
 
 	if (refine)
 		err = snd_pcm_hw_refine(substream, data);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319887 — [PATCH 4.2.y-ckt 139/268] ACPI / video: Add disable_backlight_sysfs_if quirk for the Toshiba Portege R700

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 139/268] ACPI / video: Add disable_backlight_sysfs_if quirk for the Toshiba Portege R700
Message-ID<qVFP4-1mL-13@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Hans de Goede <hdegoede@redhat.com>

commit de588b8ff057d4de0751f337b930f90ca522bab2 upstream.

The Toshiba Portege R700 needs disable_backlight_sysfs_if=1, just like
the Toshiba Portege R830. Add a quirk for this.

Link: https://bugzilla.kernel.org/show_bug.cgi?id=21012
Tested-by: Emma Reisz <emmareisz@outlook.com>
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/acpi/acpi_video.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/drivers/acpi/acpi_video.c b/drivers/acpi/acpi_video.c
index 8c2fe2f..11506c0 100644
--- a/drivers/acpi/acpi_video.c
+++ b/drivers/acpi/acpi_video.c
@@ -451,6 +451,15 @@ static struct dmi_system_id video_dmi_table[] = {
 	 * as brightness control does not work.
 	 */
 	{
+	 /* https://bugzilla.kernel.org/show_bug.cgi?id=21012 */
+	 .callback = video_disable_backlight_sysfs_if,
+	 .ident = "Toshiba Portege R700",
+	 .matches = {
+		DMI_MATCH(DMI_SYS_VENDOR, "TOSHIBA"),
+		DMI_MATCH(DMI_PRODUCT_NAME, "PORTEGE R700"),
+		},
+	},
+	{
 	 /* https://bugs.freedesktop.org/show_bug.cgi?id=82634 */
 	 .callback = video_disable_backlight_sysfs_if,
 	 .ident = "Toshiba Portege R830",
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319888 — [PATCH 4.2.y-ckt 136/268] ALSA: timer: Harden slave timer list handling

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 136/268] ALSA: timer: Harden slave timer list handling
Message-ID<qVFP4-1mL-9@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit b5a663aa426f4884c71cd8580adae73f33570f0d upstream.

A slave timer instance might be still accessible in a racy way while
operating the master instance as it lacks of locking.  Since the
master operation is mostly protected with timer->lock, we should cope
with it while changing the slave instance, too.  Also, some linked
lists (active_list and ack_list) of slave instances aren't unlinked
immediately at stopping or closing, and this may lead to unexpected
accesses.

This patch tries to address these issues.  It adds spin lock of
timer->lock (either from master or slave, which is equivalent) in a
few places.  For avoiding a deadlock, we ensure that the global
slave_active_lock is always locked at first before each timer lock.

Also, ack and active_list of slave instances are properly unlinked at
snd_timer_stop() and snd_timer_close().

Last but not least, remove the superfluous call of _snd_timer_stop()
at removing slave links.  This is a noop, and calling it may confuse
readers wrt locking.  Further cleanup will follow in a later patch.

Actually we've got reports of use-after-free by syzkaller fuzzer, and
this hopefully fixes these issues.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/core/timer.c | 18 ++++++++++++++----
 1 file changed, 14 insertions(+), 4 deletions(-)

diff --git a/sound/core/timer.c b/sound/core/timer.c
index 3810ee8..4e8d7bf 100644
--- a/sound/core/timer.c
+++ b/sound/core/timer.c
@@ -215,11 +215,13 @@ static void snd_timer_check_master(struct snd_timer_instance *master)
 		    slave->slave_id == master->slave_id) {
 			list_move_tail(&slave->open_list, &master->slave_list_head);
 			spin_lock_irq(&slave_active_lock);
+			spin_lock(&master->timer->lock);
 			slave->master = master;
 			slave->timer = master->timer;
 			if (slave->flags & SNDRV_TIMER_IFLG_RUNNING)
 				list_add_tail(&slave->active_list,
 					      &master->slave_active_head);
+			spin_unlock(&master->timer->lock);
 			spin_unlock_irq(&slave_active_lock);
 		}
 	}
@@ -346,15 +348,18 @@ int snd_timer_close(struct snd_timer_instance *timeri)
 		    timer->hw.close)
 			timer->hw.close(timer);
 		/* remove slave links */
+		spin_lock_irq(&slave_active_lock);
+		spin_lock(&timer->lock);
 		list_for_each_entry_safe(slave, tmp, &timeri->slave_list_head,
 					 open_list) {
-			spin_lock_irq(&slave_active_lock);
-			_snd_timer_stop(slave, 1, SNDRV_TIMER_EVENT_RESOLUTION);
 			list_move_tail(&slave->open_list, &snd_timer_slave_list);
 			slave->master = NULL;
 			slave->timer = NULL;
-			spin_unlock_irq(&slave_active_lock);
+			list_del_init(&slave->ack_list);
+			list_del_init(&slave->active_list);
 		}
+		spin_unlock(&timer->lock);
+		spin_unlock_irq(&slave_active_lock);
 		mutex_unlock(&register_mutex);
 	}
  out:
@@ -441,9 +446,12 @@ static int snd_timer_start_slave(struct snd_timer_instance *timeri)
 
 	spin_lock_irqsave(&slave_active_lock, flags);
 	timeri->flags |= SNDRV_TIMER_IFLG_RUNNING;
-	if (timeri->master)
+	if (timeri->master && timeri->timer) {
+		spin_lock(&timeri->timer->lock);
 		list_add_tail(&timeri->active_list,
 			      &timeri->master->slave_active_head);
+		spin_unlock(&timeri->timer->lock);
+	}
 	spin_unlock_irqrestore(&slave_active_lock, flags);
 	return 1; /* delayed start */
 }
@@ -489,6 +497,8 @@ static int _snd_timer_stop(struct snd_timer_instance * timeri,
 		if (!keep_flag) {
 			spin_lock_irqsave(&slave_active_lock, flags);
 			timeri->flags &= ~SNDRV_TIMER_IFLG_RUNNING;
+			list_del_init(&timeri->ack_list);
+			list_del_init(&timeri->active_list);
 			spin_unlock_irqrestore(&slave_active_lock, flags);
 		}
 		goto __end;
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319889 — [PATCH 4.2.y-ckt 160/268] crypto: algif_hash - Fix race condition in hash_check_key

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 160/268] crypto: algif_hash - Fix race condition in hash_check_key
Message-ID<qVFP4-1mL-17@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit ad46d7e33219218605ea619e32553daf4f346b9f upstream.

We need to lock the child socket in hash_check_key as otherwise
two simultaneous calls can cause the parent socket to be freed.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/algif_hash.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/crypto/algif_hash.c b/crypto/algif_hash.c
index 3653ab6..608a756 100644
--- a/crypto/algif_hash.c
+++ b/crypto/algif_hash.c
@@ -242,22 +242,23 @@ static struct proto_ops algif_hash_ops = {
 
 static int hash_check_key(struct socket *sock)
 {
-	int err;
+	int err = 0;
 	struct sock *psk;
 	struct alg_sock *pask;
 	struct algif_hash_tfm *tfm;
 	struct sock *sk = sock->sk;
 	struct alg_sock *ask = alg_sk(sk);
 
+	lock_sock(sk);
 	if (ask->refcnt)
-		return 0;
+		goto unlock_child;
 
 	psk = ask->parent;
 	pask = alg_sk(ask->parent);
 	tfm = pask->private;
 
 	err = -ENOKEY;
-	lock_sock(psk);
+	lock_sock_nested(psk, SINGLE_DEPTH_NESTING);
 	if (!tfm->has_key)
 		goto unlock;
 
@@ -271,6 +272,8 @@ static int hash_check_key(struct socket *sock)
 
 unlock:
 	release_sock(psk);
+unlock_child:
+	release_sock(sk);
 
 	return err;
 }
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319890 — [PATCH 4.2.y-ckt 135/268] ALSA: hda - Add fixup for Dell Latitidue E6540

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 135/268] ALSA: hda - Add fixup for Dell Latitidue E6540
Message-ID<qVFP4-1mL-15@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit cf52103a218744f3fd18111325c28e95aa9cd226 upstream.

Another Dell model, another fixup entry: Latitude E6540 needs the same
fixup as other Latitude E series as workaround for noise problems.

Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=104341
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/pci/hda/patch_realtek.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index 228669d..c337197 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -5341,6 +5341,7 @@ static const struct snd_pci_quirk alc269_fixup_tbl[] = {
 	SND_PCI_QUIRK(0x1028, 0x0470, "Dell M101z", ALC269_FIXUP_DELL_M101Z),
 	SND_PCI_QUIRK(0x1028, 0x054b, "Dell XPS one 2710", ALC275_FIXUP_DELL_XPS),
 	SND_PCI_QUIRK(0x1028, 0x05bd, "Dell Latitude E6440", ALC292_FIXUP_DELL_E7X),
+	SND_PCI_QUIRK(0x1028, 0x05be, "Dell Latitude E6540", ALC292_FIXUP_DELL_E7X),
 	SND_PCI_QUIRK(0x1028, 0x05ca, "Dell Latitude E7240", ALC292_FIXUP_DELL_E7X),
 	SND_PCI_QUIRK(0x1028, 0x05cb, "Dell Latitude E7440", ALC292_FIXUP_DELL_E7X),
 	SND_PCI_QUIRK(0x1028, 0x05da, "Dell Vostro 5460", ALC290_FIXUP_SUBWOOFER),
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319891 — [PATCH 4.2.y-ckt 146/268] printk: do cond_resched() between lines while outputting to consoles

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 146/268] printk: do cond_resched() between lines while outputting to consoles
Message-ID<qVFP4-1mL-19@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Tejun Heo <tj@kernel.org>

commit 8d91f8b15361dfb438ab6eb3b319e2ded43458ff upstream.

@console_may_schedule tracks whether console_sem was acquired through
lock or trylock.  If the former, we're inside a sleepable context and
console_conditional_schedule() performs cond_resched().  This allows
console drivers which use console_lock for synchronization to yield
while performing time-consuming operations such as scrolling.

However, the actual console outputting is performed while holding
irq-safe logbuf_lock, so console_unlock() clears @console_may_schedule
before starting outputting lines.  Also, only a few drivers call
console_conditional_schedule() to begin with.  This means that when a
lot of lines need to be output by console_unlock(), for example on a
console registration, the task doing console_unlock() may not yield for
a long time on a non-preemptible kernel.

If this happens with a slow console devices, for example a serial
console, the outputting task may occupy the cpu for a very long time.
Long enough to trigger softlockup and/or RCU stall warnings, which in
turn pile more messages, sometimes enough to trigger the next cycle of
warnings incapacitating the system.

Fix it by making console_unlock() insert cond_resched() between lines if
@console_may_schedule.

Signed-off-by: Tejun Heo <tj@kernel.org>
Reported-by: Calvin Owens <calvinowens@fb.com>
Acked-by: Jan Kara <jack@suse.com>
Cc: Dave Jones <davej@codemonkey.org.uk>
Cc: Kyle McMartin <kyle@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 include/linux/console.h |  1 +
 kernel/panic.c          |  3 +--
 kernel/printk/printk.c  | 35 ++++++++++++++++++++++++++++++++++-
 3 files changed, 36 insertions(+), 3 deletions(-)

diff --git a/include/linux/console.h b/include/linux/console.h
index bd19434..ea731af 100644
--- a/include/linux/console.h
+++ b/include/linux/console.h
@@ -150,6 +150,7 @@ extern int console_trylock(void);
 extern void console_unlock(void);
 extern void console_conditional_schedule(void);
 extern void console_unblank(void);
+extern void console_flush_on_panic(void);
 extern struct tty_driver *console_device(int *);
 extern void console_stop(struct console *);
 extern void console_start(struct console *);
diff --git a/kernel/panic.c b/kernel/panic.c
index 4b150bc..41e2b54 100644
--- a/kernel/panic.c
+++ b/kernel/panic.c
@@ -157,8 +157,7 @@ void panic(const char *fmt, ...)
 	 * panic() is not being callled from OOPS.
 	 */
 	debug_locks_off();
-	console_trylock();
-	console_unlock();
+	console_flush_on_panic();
 
 	if (!panic_blink)
 		panic_blink = no_blink;
diff --git a/kernel/printk/printk.c b/kernel/printk/printk.c
index 2b0819b..66bfe91 100644
--- a/kernel/printk/printk.c
+++ b/kernel/printk/printk.c
@@ -2232,13 +2232,24 @@ void console_unlock(void)
 	static u64 seen_seq;
 	unsigned long flags;
 	bool wake_klogd = false;
-	bool retry;
+	bool do_cond_resched, retry;
 
 	if (console_suspended) {
 		up_console_sem();
 		return;
 	}
 
+	/*
+	 * Console drivers are called under logbuf_lock, so
+	 * @console_may_schedule should be cleared before; however, we may
+	 * end up dumping a lot of lines, for example, if called from
+	 * console registration path, and should invoke cond_resched()
+	 * between lines if allowable.  Not doing so can cause a very long
+	 * scheduling stall on a slow console leading to RCU stall and
+	 * softlockup warnings which exacerbate the issue with more
+	 * messages practically incapacitating the system.
+	 */
+	do_cond_resched = console_may_schedule;
 	console_may_schedule = 0;
 
 	/* flush buffered message fragment immediately to console */
@@ -2310,6 +2321,9 @@ skip:
 		call_console_drivers(level, ext_text, ext_len, text, len);
 		start_critical_timings();
 		local_irq_restore(flags);
+
+		if (do_cond_resched)
+			cond_resched();
 	}
 	console_locked = 0;
 
@@ -2377,6 +2391,25 @@ void console_unblank(void)
 	console_unlock();
 }
 
+/**
+ * console_flush_on_panic - flush console content on panic
+ *
+ * Immediately output all pending messages no matter what.
+ */
+void console_flush_on_panic(void)
+{
+	/*
+	 * If someone else is holding the console lock, trylock will fail
+	 * and may_schedule may be set.  Ignore and proceed to unlock so
+	 * that messages are flushed out.  As this can be called from any
+	 * context and we don't want to get preempted while flushing,
+	 * ensure may_schedule is cleared.
+	 */
+	console_trylock();
+	console_may_schedule = 0;
+	console_unlock();
+}
+
 /*
  * Return the console tty driver structure and its associated index
  */
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319892 — [PATCH 4.2.y-ckt 157/268] crypto: algif_skcipher - Remove custom release parent function

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 157/268] crypto: algif_skcipher - Remove custom release parent function
Message-ID<qVFP5-1mL-23@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit d7b65aee1e7b4c87922b0232eaba56a8a143a4a0 upstream.

This patch removes the custom release parent function as the
generic af_alg_release_parent now works for nokey sockets too.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/algif_skcipher.c | 43 +++----------------------------------------
 1 file changed, 3 insertions(+), 40 deletions(-)

diff --git a/crypto/algif_skcipher.c b/crypto/algif_skcipher.c
index cdfb1bf..8d4bf6e 100644
--- a/crypto/algif_skcipher.c
+++ b/crypto/algif_skcipher.c
@@ -896,7 +896,7 @@ static void skcipher_wait(struct sock *sk)
 		msleep(100);
 }
 
-static void skcipher_sock_destruct_common(struct sock *sk)
+static void skcipher_sock_destruct(struct sock *sk)
 {
 	struct alg_sock *ask = alg_sk(sk);
 	struct skcipher_ctx *ctx = ask->private;
@@ -908,33 +908,10 @@ static void skcipher_sock_destruct_common(struct sock *sk)
 	skcipher_free_sgl(sk);
 	sock_kzfree_s(sk, ctx->iv, crypto_ablkcipher_ivsize(tfm));
 	sock_kfree_s(sk, ctx, ctx->len);
-}
-
-static void skcipher_sock_destruct(struct sock *sk)
-{
-	skcipher_sock_destruct_common(sk);
-	af_alg_release_parent(sk);
-}
-
-static void skcipher_release_parent_nokey(struct sock *sk)
-{
-	struct alg_sock *ask = alg_sk(sk);
-
-	if (!ask->refcnt) {
-		sock_put(ask->parent);
-		return;
-	}
-
 	af_alg_release_parent(sk);
 }
 
-static void skcipher_sock_destruct_nokey(struct sock *sk)
-{
-	skcipher_sock_destruct_common(sk);
-	skcipher_release_parent_nokey(sk);
-}
-
-static int skcipher_accept_parent_common(void *private, struct sock *sk)
+static int skcipher_accept_parent_nokey(void *private, struct sock *sk)
 {
 	struct skcipher_ctx *ctx;
 	struct alg_sock *ask = alg_sk(sk);
@@ -982,21 +959,7 @@ static int skcipher_accept_parent(void *private, struct sock *sk)
 	if (!tfm->has_key)
 		return -ENOKEY;
 
-	return skcipher_accept_parent_common(private, sk);
-}
-
-static int skcipher_accept_parent_nokey(void *private, struct sock *sk)
-{
-	int err;
-
-	err = skcipher_accept_parent_common(private, sk);
-	if (err)
-		goto out;
-
-	sk->sk_destruct = skcipher_sock_destruct_nokey;
-
-out:
-	return err;
+	return skcipher_accept_parent_nokey(private, sk);
 }
 
 static const struct af_alg_type algif_type_skcipher = {
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319894 — [PATCH 4.2.y-ckt 154/268] crypto: algif_hash - Require setkey before accept(2)

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 154/268] crypto: algif_hash - Require setkey before accept(2)
Message-ID<qVFP5-1mL-29@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit 6de62f15b581f920ade22d758f4c338311c2f0d4 upstream.

Hash implementations that require a key may crash if you use
them without setting a key.  This patch adds the necessary checks
so that if you do attempt to use them without a key that we return
-ENOKEY instead of proceeding.

This patch also adds a compatibility path to support old applications
that do acept(2) before setkey.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/algif_hash.c | 201 +++++++++++++++++++++++++++++++++++++++++++++++++---
 1 file changed, 193 insertions(+), 8 deletions(-)

diff --git a/crypto/algif_hash.c b/crypto/algif_hash.c
index b4c24fe..46637be 100644
--- a/crypto/algif_hash.c
+++ b/crypto/algif_hash.c
@@ -34,6 +34,11 @@ struct hash_ctx {
 	struct ahash_request req;
 };
 
+struct algif_hash_tfm {
+	struct crypto_ahash *hash;
+	bool has_key;
+};
+
 static int hash_sendmsg(struct socket *sock, struct msghdr *msg,
 			size_t ignored)
 {
@@ -235,22 +240,151 @@ static struct proto_ops algif_hash_ops = {
 	.accept		=	hash_accept,
 };
 
+static int hash_check_key(struct socket *sock)
+{
+	int err;
+	struct sock *psk;
+	struct alg_sock *pask;
+	struct algif_hash_tfm *tfm;
+	struct sock *sk = sock->sk;
+	struct alg_sock *ask = alg_sk(sk);
+
+	if (ask->refcnt)
+		return 0;
+
+	psk = ask->parent;
+	pask = alg_sk(ask->parent);
+	tfm = pask->private;
+
+	err = -ENOKEY;
+	lock_sock(psk);
+	if (!tfm->has_key)
+		goto unlock;
+
+	if (!pask->refcnt++)
+		sock_hold(psk);
+
+	ask->refcnt = 1;
+	sock_put(psk);
+
+	err = 0;
+
+unlock:
+	release_sock(psk);
+
+	return err;
+}
+
+static int hash_sendmsg_nokey(struct socket *sock, struct msghdr *msg,
+			      size_t size)
+{
+	int err;
+
+	err = hash_check_key(sock);
+	if (err)
+		return err;
+
+	return hash_sendmsg(sock, msg, size);
+}
+
+static ssize_t hash_sendpage_nokey(struct socket *sock, struct page *page,
+				   int offset, size_t size, int flags)
+{
+	int err;
+
+	err = hash_check_key(sock);
+	if (err)
+		return err;
+
+	return hash_sendpage(sock, page, offset, size, flags);
+}
+
+static int hash_recvmsg_nokey(struct socket *sock, struct msghdr *msg,
+			      size_t ignored, int flags)
+{
+	int err;
+
+	err = hash_check_key(sock);
+	if (err)
+		return err;
+
+	return hash_recvmsg(sock, msg, ignored, flags);
+}
+
+static int hash_accept_nokey(struct socket *sock, struct socket *newsock,
+			     int flags)
+{
+	int err;
+
+	err = hash_check_key(sock);
+	if (err)
+		return err;
+
+	return hash_accept(sock, newsock, flags);
+}
+
+static struct proto_ops algif_hash_ops_nokey = {
+	.family		=	PF_ALG,
+
+	.connect	=	sock_no_connect,
+	.socketpair	=	sock_no_socketpair,
+	.getname	=	sock_no_getname,
+	.ioctl		=	sock_no_ioctl,
+	.listen		=	sock_no_listen,
+	.shutdown	=	sock_no_shutdown,
+	.getsockopt	=	sock_no_getsockopt,
+	.mmap		=	sock_no_mmap,
+	.bind		=	sock_no_bind,
+	.setsockopt	=	sock_no_setsockopt,
+	.poll		=	sock_no_poll,
+
+	.release	=	af_alg_release,
+	.sendmsg	=	hash_sendmsg_nokey,
+	.sendpage	=	hash_sendpage_nokey,
+	.recvmsg	=	hash_recvmsg_nokey,
+	.accept		=	hash_accept_nokey,
+};
+
 static void *hash_bind(const char *name, u32 type, u32 mask)
 {
-	return crypto_alloc_ahash(name, type, mask);
+	struct algif_hash_tfm *tfm;
+	struct crypto_ahash *hash;
+
+	tfm = kzalloc(sizeof(*tfm), GFP_KERNEL);
+	if (!tfm)
+		return ERR_PTR(-ENOMEM);
+
+	hash = crypto_alloc_ahash(name, type, mask);
+	if (IS_ERR(hash)) {
+		kfree(tfm);
+		return ERR_CAST(hash);
+	}
+
+	tfm->hash = hash;
+
+	return tfm;
 }
 
 static void hash_release(void *private)
 {
-	crypto_free_ahash(private);
+	struct algif_hash_tfm *tfm = private;
+
+	crypto_free_ahash(tfm->hash);
+	kfree(tfm);
 }
 
 static int hash_setkey(void *private, const u8 *key, unsigned int keylen)
 {
-	return crypto_ahash_setkey(private, key, keylen);
+	struct algif_hash_tfm *tfm = private;
+	int err;
+
+	err = crypto_ahash_setkey(tfm->hash, key, keylen);
+	tfm->has_key = !err;
+
+	return err;
 }
 
-static void hash_sock_destruct(struct sock *sk)
+static void hash_sock_destruct_common(struct sock *sk)
 {
 	struct alg_sock *ask = alg_sk(sk);
 	struct hash_ctx *ctx = ask->private;
@@ -258,15 +392,40 @@ static void hash_sock_destruct(struct sock *sk)
 	sock_kzfree_s(sk, ctx->result,
 		      crypto_ahash_digestsize(crypto_ahash_reqtfm(&ctx->req)));
 	sock_kfree_s(sk, ctx, ctx->len);
+}
+
+static void hash_sock_destruct(struct sock *sk)
+{
+	hash_sock_destruct_common(sk);
 	af_alg_release_parent(sk);
 }
 
-static int hash_accept_parent(void *private, struct sock *sk)
+static void hash_release_parent_nokey(struct sock *sk)
+{
+	struct alg_sock *ask = alg_sk(sk);
+
+	if (!ask->refcnt) {
+		sock_put(ask->parent);
+		return;
+	}
+
+	af_alg_release_parent(sk);
+}
+
+static void hash_sock_destruct_nokey(struct sock *sk)
+{
+	hash_sock_destruct_common(sk);
+	hash_release_parent_nokey(sk);
+}
+
+static int hash_accept_parent_common(void *private, struct sock *sk)
 {
 	struct hash_ctx *ctx;
 	struct alg_sock *ask = alg_sk(sk);
-	unsigned len = sizeof(*ctx) + crypto_ahash_reqsize(private);
-	unsigned ds = crypto_ahash_digestsize(private);
+	struct algif_hash_tfm *tfm = private;
+	struct crypto_ahash *hash = tfm->hash;
+	unsigned len = sizeof(*ctx) + crypto_ahash_reqsize(hash);
+	unsigned ds = crypto_ahash_digestsize(hash);
 
 	ctx = sock_kmalloc(sk, len, GFP_KERNEL);
 	if (!ctx)
@@ -286,7 +445,7 @@ static int hash_accept_parent(void *private, struct sock *sk)
 
 	ask->private = ctx;
 
-	ahash_request_set_tfm(&ctx->req, private);
+	ahash_request_set_tfm(&ctx->req, hash);
 	ahash_request_set_callback(&ctx->req, CRYPTO_TFM_REQ_MAY_BACKLOG,
 				   af_alg_complete, &ctx->completion);
 
@@ -295,12 +454,38 @@ static int hash_accept_parent(void *private, struct sock *sk)
 	return 0;
 }
 
+static int hash_accept_parent(void *private, struct sock *sk)
+{
+	struct algif_hash_tfm *tfm = private;
+
+	if (!tfm->has_key && crypto_ahash_has_setkey(tfm->hash))
+		return -ENOKEY;
+
+	return hash_accept_parent_common(private, sk);
+}
+
+static int hash_accept_parent_nokey(void *private, struct sock *sk)
+{
+	int err;
+
+	err = hash_accept_parent_common(private, sk);
+	if (err)
+		goto out;
+
+	sk->sk_destruct = hash_sock_destruct_nokey;
+
+out:
+	return err;
+}
+
 static const struct af_alg_type algif_type_hash = {
 	.bind		=	hash_bind,
 	.release	=	hash_release,
 	.setkey		=	hash_setkey,
 	.accept		=	hash_accept_parent,
+	.accept_nokey	=	hash_accept_parent_nokey,
 	.ops		=	&algif_hash_ops,
+	.ops_nokey	=	&algif_hash_ops_nokey,
 	.name		=	"hash",
 	.owner		=	THIS_MODULE
 };
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


Page 6 of 13 — ← Prev page 1 … 4 5 [6] 7 8 … 13  Next page →

Back to top | Article view | linux.kernel


csiph-web