Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1319730 > unrolled thread

[4.2.y-ckt stable] Linux 4.2.8-ckt3 stable review

Started byKamal Mostafa <kamal@canonical.com>
First post2016-01-27 21:40 +0100
Last post2016-01-27 23:10 +0100
Articles 20 on this page of 254 — 1 participant

Back to article view | Back to linux.kernel


Contents

  [4.2.y-ckt stable] Linux 4.2.8-ckt3 stable review Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 051/268] udf: limit the maximum number of indirect extents in a row Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 002/268] ovl: allow zero size xattr Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 001/268] drm/nouveau/nv46: Change mc subdev oclass from nv44 to nv4c Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 147/268] ALSA: hda - Fix bass pin fixup for ASUS N550JX Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 057/268] Thermal: do thermal zone update after a cooling device registered Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 140/268] ACPI / video: Add disable_backlight_sysfs_if quirk for the Toshiba Satellite R830 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 127/268] sparc64: fix incorrect sign extension in sys_sparc64_personality Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:40 +0100
    [PATCH 4.2.y-ckt 238/268] batman-adv: Avoid recursive call_rcu for batadv_bla_claim Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 257/268] unix: properly account for FDs passed over unix sockets Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 243/268] batman-adv: Drop immediate orig_node free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 259/268] tcp_yeah: don't set ssthresh below 2 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 208/268] Drivers: hv: utils: use memdup_user in hvt_op_write Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 256/268] af_unix: Fix splice-bind deadlock Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 263/268] phonet: properly unshare skbs in phonet_rcv() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 203/268] mtd: nand: fix ONFI parameter page layout Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 264/268] net: bpf: reject invalid shifts Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 246/268] team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 253/268] net: cdc_ncm: avoid changing RX/TX buffers on MTU changes Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 240/268] batman-adv: Drop immediate batadv_orig_ifinfo free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 242/268] batman-adv: Drop immediate neigh_ifinfo free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 219/268] perf/x86: Fix filter_events() bug with event mappings Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 262/268] net: preserve IP control block during GSO segmentation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 245/268] ARM: dts: armadillo800eva Correct extal1 frequency to 24 MHz Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 266/268] xfrm: dst_entries_init() per-net dst_ops Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 268/268] ipv6: update skb->csum when CE mark is propagated Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 254/268] sctp: sctp should release assoc when sctp_make_abort_user return NULL in sctp_close Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 248/268] IB/mlx4: Initialize hop_limit when creating address handle Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 255/268] connector: bump skb->users before callback invocation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 234/268] include/linux/memblock.h: fix ordering of 'flags' argument in comments Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 251/268] NFS: Ensure we revalidate attributes before using execute_ok() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 202/268] ASoC: tegra_alc5632: check return value Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 250/268] NFSv4: Don't perform cached access checks before we've OPENed the file Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 258/268] bridge: Only call /sbin/bridge-stp for the initial network namespace Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 247/268] mmc: debugfs: correct wrong voltage value Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 261/268] udp: disallow UFO for sockets with SO_NO_CHECK option Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 260/268] sched,cls_flower: set key address type when present Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 265/268] batman-adv: Drop immediate batadv_hard_iface free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 236/268] btrfs: initialize the seq counter in struct btrfs_device Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 220/268] perf/x86: fix PEBS issues on Intel Atom/Core2 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 267/268] vxlan: fix test which detect duplicate vxlan iface Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 249/268] net/mlx4: Remove unused macro Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 244/268] printk: help pr_debug and pr_devel to optimize out arguments Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 252/268] veth: don’t modify ip_summed; doing so treats packets with bad checksums as good. Kamal Mostafa <kamal@canonical.com> - 2016-01-27 21:50 +0100
    [PATCH 4.2.y-ckt 205/268] Revert "ACPI / LPSS: allow to use specific PM domain during ->probe()" Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 214/268] pinctrl: bcm2835: Fix memory leak in error path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 233/268] vmstat: make vmstat_updater deferrable again and shut down on idle Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 222/268] firmware: actually return NULL on failed request_firmware_nowait() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 216/268] x86/LDT: Print the real LDT base address Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 213/268] ALSA: fm801: detect FM-only card earlier Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 212/268] ALSA: fm801: propagate TUNER_ONLY bit when autodetected Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 228/268] ipv6: tcp: add rcu locking in tcp_v6_send_synack() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 225/268] m68k/atari, m68k/sun3: Fix SCSI platform device registration when driver is modular Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 227/268] net: sctp: prevent writes to cookie_hmac_alg from accessing invalid memory Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 211/268] ARM: imx: select SRC for i.MX7 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 231/268] mmc: sd: limit SD card power limit according to cards capabilities Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 204/268] mac80211: fix mgmt-tx abort cookie and leak Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 221/268] power: test_power: correctly handle empty writes Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 229/268] bonding: Prevent IPv6 link local address on enslaved devices Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 239/268] batman-adv: Avoid recursive call_rcu for batadv_nc_node Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 226/268] um: Fix build error and kconfig for i386 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 230/268] kbuild: Demote 'sign-compare' warning to W=2 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 215/268] mmc: sdhci: restore behavior when setting VDD via external regulator Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 209/268] tpm_tis: Use devm_free_irq not free_irq Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 200/268] PCI/MSI: Initialize MSI capability for all architectures Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 223/268] target: Fix a memory leak in target_dev_lba_map_store() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 235/268] Btrfs: clean up an error code in btrfs_init_space_info() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 241/268] batman-adv: Drop immediate batadv_neigh_node free function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 199/268] ASoC: Intel: pass correct parameter in sst_alloc_stream_mrfld() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 218/268] kconfig: return 'false' instead of 'no' in bool function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 232/268] net: tcp_memcontrol: properly detect ancestor socket pressure Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 201/268] ath9k_htc: check for underflow in ath9k_htc_rx_msg() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 237/268] bridge: fix lockdep addr_list_lock false positive splat Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 224/268] phy: micrel: Fix finding PHY properties in MAC node for KSZ9031. Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 217/268] sysrq: Fix warning in sysrq generated crash. Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:00 +0100
    [PATCH 4.2.y-ckt 195/268] SCSI: initio: remove duplicate module device table Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 189/268] MAINTAINERS: return arch/sh to maintained state, with new maintainers Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 198/268] MAINTAINERS: gpio-brcmstb: Remove stray '>' Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 181/268] prctl: take mmap sem for writing to protect against others Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 184/268] MIPS: Loongson-3: Fix SMP_ASK_C0COUNT IPI handler Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 186/268] ocfs2: NFS hangs in __ocfs2_cluster_lock due to race with ocfs2_unblock_lock Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 185/268] MIPS: hpet: Choose a safe value for the ETIME check Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 188/268] make sure that freeing shmem fast symlinks is RCU-delayed Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 196/268] clk: xgene: Fix divider with non-zero shift value Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 206/268] mtd: nand: denali: add missing nand_release() call in denali_remove() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 194/268] [media] lirc_imon: do not leave imon_probe() with mutex held Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 190/268] MIPS: Fix some missing CONFIG_CPU_MIPSR6 #ifdefs Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 192/268] drm/i915: On fb alloc failure, unref gem object where it gets refed Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 183/268] libceph: fix ceph_msg_revoke() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 210/268] ALSA: fm801: explicitly free IRQ line Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 174/268] IB/cm: Fix a recently introduced deadlock Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 175/268] ideapad-laptop: Add Lenovo ideapad Y700-17ISK to no_hw_rfkill dmi list Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 177/268] iscsi-target: Fix potential dead-lock during node acl delete Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 193/268] [media] rc: allow rc modules to be loaded if rc-main is not a module Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 207/268] Drivers: hv: util: catch allocation errors Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 191/268] ideapad-laptop: Add Lenovo Yoga 700 to no_hw_rfkill dmi list Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 182/268] ALSA: timer: Handle disconnection more safely Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 178/268] crypto: algif_skcipher - sendmsg SG marking is off by one Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 187/268] pNFS/flexfiles: Fix an XDR encoding bug in layoutreturn Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 197/268] clk: st: avoid uninitialized variable use Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:10 +0100
    [PATCH 4.2.y-ckt 166/268] ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 167/268] ARM: debug-ll: fix BCM63xx entry for multiplatform Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 168/268] xfs: log mount failures don't wait for buffers to be released Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 179/268] ALSA: hda - Flush the pending probe work at remove Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 108/268] x86/reboot/quirks: Add iMac10,1 to pci_reboot_dmi_table[] Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 170/268] crypto: crc32c - Fix crc32c soft dependency Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 173/268] IB/mlx5: Expose correct maximum number of CQE capacity Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 171/268] IB/qib: fix mcast detach when qp not attached Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 169/268] crypto: algif_skcipher - Load TX SG list after waiting Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 121/268] x86/mm: Improve switch_mm() barrier comments Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:20 +0100
    [PATCH 4.2.y-ckt 161/268] crypto: algif_skcipher - Fix race condition in skcipher_check_key Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 153/268] crypto: hash - Add crypto_ahash_has_setkey Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 164/268] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 139/268] ACPI / video: Add disable_backlight_sysfs_if quirk for the Toshiba Portege R700 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 136/268] ALSA: timer: Harden slave timer list handling Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 160/268] crypto: algif_hash - Fix race condition in hash_check_key Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 135/268] ALSA: hda - Add fixup for Dell Latitidue E6540 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 146/268] printk: do cond_resched() between lines while outputting to consoles Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 157/268] crypto: algif_skcipher - Remove custom release parent function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 154/268] crypto: algif_hash - Require setkey before accept(2) Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 142/268] zram: don't call idr_remove() from zram_remove() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 138/268] zram: try vmalloc() after kmalloc() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 145/268] kernel/panic.c: turn off locks debug before releasing console lock Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 149/268] crypto: af_alg - Disallow bind/setkey/... after accept(2) Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 163/268] dmaengine: at_xdmac: fix resume for cyclic transfers Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 162/268] ALSA: hrtimer: Fix stall by hrtimer_cancel() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 143/268] memcg: only free spare array when readers are done Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 133/268] scripts/bloat-o-meter: fix python3 syntax error Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 141/268] mm: soft-offline: check return value in second __get_any_page() call Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 137/268] zram/zcomp: use GFP_NOIO to allocate streams Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 165/268] ALSA: seq: Fix snd_seq_call_port_info_ioctl in compat mode Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 158/268] crypto: af_alg - Forbid bind(2) when nokey child sockets are present Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 152/268] crypto: algif_skcipher - Add nokey compatibility path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 144/268] panic: release stale console lock to always get the logbuf printed out Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 148/268] crypto: algif_skcipher - Require setkey before accept(2) Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 101/268] x86/mm: Add barriers and document switch_mm()-vs-flush synchronization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 150/268] crypto: af_alg - Fix socket double-free when accept fails Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 156/268] crypto: algif_hash - Remove custom release parent function Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 155/268] crypto: af_alg - Allow af_af_alg_release_parent to be called on nokey path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 151/268] crypto: af_alg - Add nokey compatibility path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 134/268] ocfs2/dlm: ignore cleaning the migration mle that is inuse Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 130/268] cifs_dbg() outputs an uninitialized buffer in cifs_readdir() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:30 +0100
    [PATCH 4.2.y-ckt 104/268] xfs: inode recovery readahead can race with inode buffer creation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 119/268] drm/i915: Restore inhibiting the load of the default context Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 110/268] ALSA: seq: Fix race at timer setup and close Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 111/268] virtio_balloon: fix race by fill and leak Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 113/268] ALSA: hda - Fix white noise on Dell Latitude E5550 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 126/268] ALSA: timer: Fix race among timer ioctls Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 129/268] cifs: fix race between call_async() and reconnect() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 099/268] ALSA: usb: Add native DSD support for Oppo HA-1 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 114/268] parisc: Fix __ARCH_SI_PREAMBLE_SIZE Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 098/268] drm/nouveau/kms: take mode_config mutex in connector hotplug path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 116/268] powerpc/module: Handle R_PPC64_ENTRY relocations Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 118/268] ALSA: usb-audio: Fix mixer ctl regression of Native Instrument devices Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 100/268] ALSA: hda - Fixup inverted internal mic for Lenovo E50-80 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 117/268] ALSA: hda - fix the headset mic detection problem for a Dell laptop Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 123/268] dmaengine: dw: fix cyclic transfer setup Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 128/268] cifs: Ratelimit kernel log messages Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 103/268] s390: fix normalization bug in exception table sorting Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 109/268] ALSA: seq: Fix missing NULL check at remove_events ioctl Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 105/268] xfs: handle dquot buffer readahead in log recovery correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 085/268] drm/dp/mst: fix in MSTB RAD initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 096/268] uml: fix hostfs mknod() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 131/268] m32r: fix m32104ut_defconfig build fail Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 120/268] drm/i915: intel_hpd_init(): Fix suspend/resume reprobing Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 112/268] virtio_balloon: fix race between migration and ballooning Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 115/268] scripts/recordmcount.pl: support data in text section on powerpc Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 097/268] uml: flush stdout before forking Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 125/268] mmc: mmci: fix an ages old detection error Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 102/268] x86/boot: Double BOOT_HEAP_SIZE to 64KB Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 106/268] clocksource/drivers/vt8500: Increase the minimum delta Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 124/268] dmaengine: dw: fix cyclic transfer callbacks Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:40 +0100
    [PATCH 4.2.y-ckt 072/268] bcache: fix a leak in bch_cached_dev_run() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 063/268] rtlwifi: rtl8192de: Fix incorrect module parameter descriptions Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 077/268] wlcore/wl12xx: spi: fix NULL pointer dereference (Oops) Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 080/268] x86/xen: don't reset vcpu_info on a cancelled suspend Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 067/268] NFS: Fix attribute cache revalidation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 070/268] bcache: Add a cond_resched() call to gc Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 060/268] rtlwifi: rtl8723ae: Fix initialization of module parameters Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 066/268] rtlwifi: rtl8192cu: Add missing parameter setup Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 088/268] PCI: host: Mark PCIe/PCI (MSI) IRQ cascade handlers as IRQF_NO_THREAD Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 074/268] bcache: allows use of register in udev to avoid "device_busy" error. Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 071/268] bcache: clear BCACHE_DEV_UNLINK_DONE flag when attaching a backing device Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 093/268] scsi: add Synology to 1024 sector blacklist Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 083/268] drm/dp/mst: process broadcast messages correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 082/268] udf: Check output buffer length when converting name to CS0 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 089/268] btrfs: handle invalid num_stripes in sys_array Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 092/268] locks: fix unlock when fcntl_setlk races with a close Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 062/268] rtlwifi: rtl8188ee: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 078/268] Input: i8042 - add Fujitsu Lifebook U745 to the nomux list Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 061/268] rtlwifi: rtl8821ae: Fix errors in parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 075/268] bcache: prevent crash on changing writeback_running Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 064/268] rtlwifi: rtl8192se: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 084/268] drm/dp/mst: always send reply for UP request Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 079/268] libxfs: pack the agfl header structure so XFS_AGFL_SIZE is correct Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 076/268] bcache: Change refill_dirty() to always scan entire disk if necessary Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 095/268] dm snapshot: fix hung bios when copy error occurs Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 094/268] ASoC: compress: Fix compress device direction check Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 065/268] rtlwifi: rtl8192ce: Fix handling of module parameters Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 081/268] udf: Prevent buffer overrun with multi-byte characters Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 069/268] bcache: fix a livelock when we cause a huge number of cache misses Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 059/268] rtlwifi: rtl8723be: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 090/268] iwlwifi: update and fix 7265 series PCI IDs Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 091/268] iwlwifi: pcie: properly configure the debug buffer size for 8000 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 22:50 +0100
    [PATCH 4.2.y-ckt 049/268] mmc: sdhci: Fix sdhci_runtime_pm_bus_on/off() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 058/268] posix-clock: Fix return code on the poll method's error path Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 024/268] ovl: setattr: check permissions before copy-up Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 043/268] drm/amdgpu: Fix off-by-one errors in amdgpu_vm_bo_map Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 045/268] mmc: mmc: Fix incorrect use of driver strength switching HS200 and HS400 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 036/268] dm thin: fix race condition when destroying thin pool workqueue Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 022/268] rtlwifi: fix memory leak for USB device Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 044/268] drm/radeon: clean up fujitsu quirks Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 038/268] futex: Drop refcount if requeue_pi() acquired the rtmutex Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 041/268] coresight: checking for NULL string in coresight_name_match() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 028/268] arm64: mm: ensure that the zero page is visible to the page table walker Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 042/268] drm/radeon: Fix off-by-one errors in radeon_vm_bo_set_addr Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 025/268] ovl: check dentry positiveness in ovl_cleanup_whiteouts() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 033/268] tools: hv: vss: fix the write()'s argument: error -> vss_msg Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 030/268] powerpc: Make {cmp}xchg* and their atomic_ versions fully ordered Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 034/268] clk: exynos: use irqsave version of spin_lock to avoid deadlock with irqs Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 021/268] ext4 crypto: add missing locking for keyring_key access Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 054/268] USB: cp210x: add ID for ELV Marble Sound Board 1 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 056/268] Thermal: handle thermal zone device properly during system sleep Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 026/268] EDAC, mc_sysfs: Fix freeing bus' name Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 040/268] arm64: kernel: enforce pmuserenr_el0 initialization and restore Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 048/268] mmc: sdhci: Fix DMA descriptor with zero data length Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 023/268] wlcore/wl12xx: spi: fix oops on firmware load Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 050/268] regulator: axp20x: Fix GPIO LDO enable value for AXP22x Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 047/268] mmc: sdio: Fix invalid vdd in voltage switch power cycle Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 053/268] nfs: Fix race in __update_open_stateid() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 037/268] drm/radeon: Fix "slow" audio over DP on DCE8+ Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 032/268] Drivers: hv: vmbus: Fix a Host signaling bug Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 035/268] iommu/io-pgtable-arm: Ensure we free the final level on teardown Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 046/268] mmc: sdhci-pci: Do not default to 33 Ohm driver strength for Intel SPT Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 039/268] arm64: mdscr_el1: avoid exposing DCC to userspace Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 055/268] Thermal: initialize thermal zone device correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 052/268] [media] rc: sunxi-cir: Initialize the spinlock properly Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:00 +0100
    [PATCH 4.2.y-ckt 017/268] time: Avoid signed overflow in timekeeping_get_ns() Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 012/268] drm/amdgpu: call hpd_irq_event on resume Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 007/268] [media] si2157: return -EINVAL if firmware blob is too big Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 019/268] Bluetooth: Add support of Toshiba Broadcom based devices Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 016/268] arm64: Clear out any singlestep state on a ptrace detach operation Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 015/268] ARM: mvebu: remove duplicated regulator definition in Armada 388 GP Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 011/268] KVM: x86: correctly print #AC in traces Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 005/268] [media] gspca: ov534/topro: prevent a division by 0 Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 004/268] [media] vb2: fix a regression in poll() behavior for output,streams Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 018/268] ovl: root: copy attr Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 003/268] ovl: use a minimal buffer in ovl_copy_xattr Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 008/268] tools lib traceevent: Fix output of %llu for 64 bit values read on 32 bit machines Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 020/268] ext4 crypto: exit cleanly if ext4_derive_key_aes() fails Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 014/268] xhci: refuse loading if nousb is used Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 006/268] [media] media: dvb-core: Don't force CAN_INVERSION_AUTO in oneshot mode Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 009/268] cxl: use correct operator when writing pcie config space values Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100
    [PATCH 4.2.y-ckt 010/268] KVM: x86: expose MSR_TSC_AUX to userspace Kamal Mostafa <kamal@canonical.com> - 2016-01-27 23:10 +0100

Page 7 of 13 — ← Prev page 1 … 5 6 [7] 8 9 … 13  Next page →


#1319896 — [PATCH 4.2.y-ckt 142/268] zram: don't call idr_remove() from zram_remove()

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 142/268] zram: don't call idr_remove() from zram_remove()
Message-ID<qVFP5-1mL-35@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Jerome Marchand <jmarchan@redhat.com>

commit 17ec4cd985780a7e30aa45bb8f272237c12502a4 upstream.

The use of idr_remove() is forbidden in the callback functions of
idr_for_each().  It is therefore unsafe to call idr_remove in
zram_remove().

This patch moves the call to idr_remove() from zram_remove() to
hot_remove_store().  In the detroy_devices() path, idrs are removed by
idr_destroy().  This solves an use-after-free detected by KASan.

[akpm@linux-foundation.org: fix coding stype, per Sergey]
Signed-off-by: Jerome Marchand <jmarchan@redhat.com>
Acked-by: Sergey Senozhatsky <sergey.senozhatsky@gmail.com>
Cc: Minchan Kim <minchan@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/block/zram/zram_drv.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/drivers/block/zram/zram_drv.c b/drivers/block/zram/zram_drv.c
index 763301c..6a706f5 100644
--- a/drivers/block/zram/zram_drv.c
+++ b/drivers/block/zram/zram_drv.c
@@ -1319,7 +1319,6 @@ static int zram_remove(struct zram *zram)
 
 	pr_info("Removed device: %s\n", zram->disk->disk_name);
 
-	idr_remove(&zram_index_idr, zram->disk->first_minor);
 	blk_cleanup_queue(zram->disk->queue);
 	del_gendisk(zram->disk);
 	put_disk(zram->disk);
@@ -1361,10 +1360,12 @@ static ssize_t hot_remove_store(struct class *class,
 	mutex_lock(&zram_index_mutex);
 
 	zram = idr_find(&zram_index_idr, dev_id);
-	if (zram)
+	if (zram) {
 		ret = zram_remove(zram);
-	else
+		idr_remove(&zram_index_idr, dev_id);
+	} else {
 		ret = -ENODEV;
+	}
 
 	mutex_unlock(&zram_index_mutex);
 	return ret ? ret : count;
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319897 — [PATCH 4.2.y-ckt 138/268] zram: try vmalloc() after kmalloc()

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 138/268] zram: try vmalloc() after kmalloc()
Message-ID<qVFP5-1mL-39@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Kyeongdon Kim <kyeongdon.kim@lge.com>

commit d913897abace843bba20249f3190167f7895e9c3 upstream.

When we're using LZ4 multi compression streams for zram swap, we found
out page allocation failure message in system running test.  That was
not only once, but a few(2 - 5 times per test).  Also, some failure
cases were continually occurring to try allocation order 3.

In order to make parallel compression private data, we should call
kzalloc() with order 2/3 in runtime(lzo/lz4).  But if there is no order
2/3 size memory to allocate in that time, page allocation fails.  This
patch makes to use vmalloc() as fallback of kmalloc(), this prevents
page alloc failure warning.

After using this, we never found warning message in running test, also
It could reduce process startup latency about 60-120ms in each case.

For reference a call trace :

    Binder_1: page allocation failure: order:3, mode:0x10c0d0
    CPU: 0 PID: 424 Comm: Binder_1 Tainted: GW 3.10.49-perf-g991d02b-dirty #20
    Call trace:
      dump_backtrace+0x0/0x270
      show_stack+0x10/0x1c
      dump_stack+0x1c/0x28
      warn_alloc_failed+0xfc/0x11c
      __alloc_pages_nodemask+0x724/0x7f0
      __get_free_pages+0x14/0x5c
      kmalloc_order_trace+0x38/0xd8
      zcomp_lz4_create+0x2c/0x38
      zcomp_strm_alloc+0x34/0x78
      zcomp_strm_multi_find+0x124/0x1ec
      zcomp_strm_find+0xc/0x18
      zram_bvec_rw+0x2fc/0x780
      zram_make_request+0x25c/0x2d4
      generic_make_request+0x80/0xbc
      submit_bio+0xa4/0x15c
      __swap_writepage+0x218/0x230
      swap_writepage+0x3c/0x4c
      shrink_page_list+0x51c/0x8d0
      shrink_inactive_list+0x3f8/0x60c
      shrink_lruvec+0x33c/0x4cc
      shrink_zone+0x3c/0x100
      try_to_free_pages+0x2b8/0x54c
      __alloc_pages_nodemask+0x514/0x7f0
      __get_free_pages+0x14/0x5c
      proc_info_read+0x50/0xe4
      vfs_read+0xa0/0x12c
      SyS_read+0x44/0x74
    DMA: 3397*4kB (MC) 26*8kB (RC) 0*16kB 0*32kB 0*64kB 0*128kB 0*256kB
         0*512kB 0*1024kB 0*2048kB 0*4096kB = 13796kB

[minchan@kernel.org: change vmalloc gfp and adding comment about gfp]
[sergey.senozhatsky@gmail.com: tweak comments and styles]
Signed-off-by: Kyeongdon Kim <kyeongdon.kim@lge.com>
Signed-off-by: Minchan Kim <minchan@kernel.org>
Acked-by: Sergey Senozhatsky <sergey.senozhatsky@gmail.com>
Sergey Senozhatsky <sergey.senozhatsky.work@gmail.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/block/zram/zcomp_lz4.c | 23 +++++++++++++++++++++--
 drivers/block/zram/zcomp_lzo.c | 23 +++++++++++++++++++++--
 2 files changed, 42 insertions(+), 4 deletions(-)

diff --git a/drivers/block/zram/zcomp_lz4.c b/drivers/block/zram/zcomp_lz4.c
index ee44b51..dd60831 100644
--- a/drivers/block/zram/zcomp_lz4.c
+++ b/drivers/block/zram/zcomp_lz4.c
@@ -10,17 +10,36 @@
 #include <linux/kernel.h>
 #include <linux/slab.h>
 #include <linux/lz4.h>
+#include <linux/vmalloc.h>
+#include <linux/mm.h>
 
 #include "zcomp_lz4.h"
 
 static void *zcomp_lz4_create(void)
 {
-	return kzalloc(LZ4_MEM_COMPRESS, GFP_NOIO);
+	void *ret;
+
+	/*
+	 * This function can be called in swapout/fs write path
+	 * so we can't use GFP_FS|IO. And it assumes we already
+	 * have at least one stream in zram initialization so we
+	 * don't do best effort to allocate more stream in here.
+	 * A default stream will work well without further multiple
+	 * streams. That's why we use NORETRY | NOWARN.
+	 */
+	ret = kzalloc(LZ4_MEM_COMPRESS, GFP_NOIO | __GFP_NORETRY |
+					__GFP_NOWARN);
+	if (!ret)
+		ret = __vmalloc(LZ4_MEM_COMPRESS,
+				GFP_NOIO | __GFP_NORETRY | __GFP_NOWARN |
+				__GFP_ZERO | __GFP_HIGHMEM,
+				PAGE_KERNEL);
+	return ret;
 }
 
 static void zcomp_lz4_destroy(void *private)
 {
-	kfree(private);
+	kvfree(private);
 }
 
 static int zcomp_lz4_compress(const unsigned char *src, unsigned char *dst,
diff --git a/drivers/block/zram/zcomp_lzo.c b/drivers/block/zram/zcomp_lzo.c
index 683ce04..edc5499 100644
--- a/drivers/block/zram/zcomp_lzo.c
+++ b/drivers/block/zram/zcomp_lzo.c
@@ -10,17 +10,36 @@
 #include <linux/kernel.h>
 #include <linux/slab.h>
 #include <linux/lzo.h>
+#include <linux/vmalloc.h>
+#include <linux/mm.h>
 
 #include "zcomp_lzo.h"
 
 static void *lzo_create(void)
 {
-	return kzalloc(LZO1X_MEM_COMPRESS, GFP_NOIO);
+	void *ret;
+
+	/*
+	 * This function can be called in swapout/fs write path
+	 * so we can't use GFP_FS|IO. And it assumes we already
+	 * have at least one stream in zram initialization so we
+	 * don't do best effort to allocate more stream in here.
+	 * A default stream will work well without further multiple
+	 * streams. That's why we use NORETRY | NOWARN.
+	 */
+	ret = kzalloc(LZO1X_MEM_COMPRESS, GFP_NOIO | __GFP_NORETRY |
+					__GFP_NOWARN);
+	if (!ret)
+		ret = __vmalloc(LZO1X_MEM_COMPRESS,
+				GFP_NOIO | __GFP_NORETRY | __GFP_NOWARN |
+				__GFP_ZERO | __GFP_HIGHMEM,
+				PAGE_KERNEL);
+	return ret;
 }
 
 static void lzo_destroy(void *private)
 {
-	kfree(private);
+	kvfree(private);
 }
 
 static int lzo_compress(const unsigned char *src, unsigned char *dst,
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319898 — [PATCH 4.2.y-ckt 145/268] kernel/panic.c: turn off locks debug before releasing console lock

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 145/268] kernel/panic.c: turn off locks debug before releasing console lock
Message-ID<qVFP5-1mL-43@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Vitaly Kuznetsov <vkuznets@redhat.com>

commit 7625b3a0007decf2b135cb47ca67abc78a7b1bc1 upstream.

Commit 08d78658f393 ("panic: release stale console lock to always get the
logbuf printed out") introduced an unwanted bad unlock balance report when
panic() is called directly and not from OOPS (e.g.  from out_of_memory()).
The difference is that in case of OOPS we disable locks debug in
oops_enter() and on direct panic call nobody does that.

Fixes: 08d78658f393 ("panic: release stale console lock to always get the logbuf printed out")
Reported-by: kernel test robot <ying.huang@linux.intel.com>
Signed-off-by: Vitaly Kuznetsov <vkuznets@redhat.com>
Cc: HATAYAMA Daisuke <d.hatayama@jp.fujitsu.com>
Cc: Masami Hiramatsu <masami.hiramatsu.pt@hitachi.com>
Cc: Jiri Kosina <jkosina@suse.cz>
Cc: Baoquan He <bhe@redhat.com>
Cc: Prarit Bhargava <prarit@redhat.com>
Cc: Xie XiuQi <xiexiuqi@huawei.com>
Cc: Seth Jennings <sjenning@redhat.com>
Cc: "K. Y. Srinivasan" <kys@microsoft.com>
Cc: Jan Kara <jack@suse.cz>
Cc: Petr Mladek <pmladek@suse.cz>
Cc: Yasuaki Ishimatsu <isimatu.yasuaki@jp.fujitsu.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[ kamal: 4.2-stable prereq for
  8d91f8b printk: do cond_resched() between lines while outputting to consoles ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 kernel/panic.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/kernel/panic.c b/kernel/panic.c
index 4579dbb..4b150bc 100644
--- a/kernel/panic.c
+++ b/kernel/panic.c
@@ -152,8 +152,11 @@ void panic(const char *fmt, ...)
 	 * We may have ended up stopping the CPU holding the lock (in
 	 * smp_send_stop()) while still having some valuable data in the console
 	 * buffer.  Try to acquire the lock then release it regardless of the
-	 * result.  The release will also print the buffers out.
+	 * result.  The release will also print the buffers out.  Locks debug
+	 * should be disabled to avoid reporting bad unlock balance when
+	 * panic() is not being callled from OOPS.
 	 */
+	debug_locks_off();
 	console_trylock();
 	console_unlock();
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319899 — [PATCH 4.2.y-ckt 149/268] crypto: af_alg - Disallow bind/setkey/... after accept(2)

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 149/268] crypto: af_alg - Disallow bind/setkey/... after accept(2)
Message-ID<qVFP5-1mL-41@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit c840ac6af3f8713a71b4d2363419145760bd6044 upstream.

Each af_alg parent socket obtained by socket(2) corresponds to a
tfm object once bind(2) has succeeded.  An accept(2) call on that
parent socket creates a context which then uses the tfm object.

Therefore as long as any child sockets created by accept(2) exist
the parent socket must not be modified or freed.

This patch guarantees this by using locks and a reference count
on the parent socket.  Any attempt to modify the parent socket will
fail with EBUSY.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/af_alg.c         | 35 ++++++++++++++++++++++++++++++++---
 include/crypto/if_alg.h |  8 +++-----
 2 files changed, 35 insertions(+), 8 deletions(-)

diff --git a/crypto/af_alg.c b/crypto/af_alg.c
index a8e7aa3..7b5b592 100644
--- a/crypto/af_alg.c
+++ b/crypto/af_alg.c
@@ -125,6 +125,23 @@ int af_alg_release(struct socket *sock)
 }
 EXPORT_SYMBOL_GPL(af_alg_release);
 
+void af_alg_release_parent(struct sock *sk)
+{
+	struct alg_sock *ask = alg_sk(sk);
+	bool last;
+
+	sk = ask->parent;
+	ask = alg_sk(sk);
+
+	lock_sock(sk);
+	last = !--ask->refcnt;
+	release_sock(sk);
+
+	if (last)
+		sock_put(sk);
+}
+EXPORT_SYMBOL_GPL(af_alg_release_parent);
+
 static int alg_bind(struct socket *sock, struct sockaddr *uaddr, int addr_len)
 {
 	const u32 forbidden = CRYPTO_ALG_INTERNAL;
@@ -133,6 +150,7 @@ static int alg_bind(struct socket *sock, struct sockaddr *uaddr, int addr_len)
 	struct sockaddr_alg *sa = (void *)uaddr;
 	const struct af_alg_type *type;
 	void *private;
+	int err;
 
 	if (sock->state == SS_CONNECTED)
 		return -EINVAL;
@@ -160,16 +178,22 @@ static int alg_bind(struct socket *sock, struct sockaddr *uaddr, int addr_len)
 		return PTR_ERR(private);
 	}
 
+	err = -EBUSY;
 	lock_sock(sk);
+	if (ask->refcnt)
+		goto unlock;
 
 	swap(ask->type, type);
 	swap(ask->private, private);
 
+	err = 0;
+
+unlock:
 	release_sock(sk);
 
 	alg_do_release(type, private);
 
-	return 0;
+	return err;
 }
 
 static int alg_setkey(struct sock *sk, char __user *ukey,
@@ -202,11 +226,15 @@ static int alg_setsockopt(struct socket *sock, int level, int optname,
 	struct sock *sk = sock->sk;
 	struct alg_sock *ask = alg_sk(sk);
 	const struct af_alg_type *type;
-	int err = -ENOPROTOOPT;
+	int err = -EBUSY;
 
 	lock_sock(sk);
+	if (ask->refcnt)
+		goto unlock;
+
 	type = ask->type;
 
+	err = -ENOPROTOOPT;
 	if (level != SOL_ALG || !type)
 		goto unlock;
 
@@ -264,7 +292,8 @@ int af_alg_accept(struct sock *sk, struct socket *newsock)
 
 	sk2->sk_family = PF_ALG;
 
-	sock_hold(sk);
+	if (!ask->refcnt++)
+		sock_hold(sk);
 	alg_sk(sk2)->parent = sk;
 	alg_sk(sk2)->type = type;
 
diff --git a/include/crypto/if_alg.h b/include/crypto/if_alg.h
index 018afb2..589716f 100644
--- a/include/crypto/if_alg.h
+++ b/include/crypto/if_alg.h
@@ -30,6 +30,8 @@ struct alg_sock {
 
 	struct sock *parent;
 
+	unsigned int refcnt;
+
 	const struct af_alg_type *type;
 	void *private;
 };
@@ -67,6 +69,7 @@ int af_alg_register_type(const struct af_alg_type *type);
 int af_alg_unregister_type(const struct af_alg_type *type);
 
 int af_alg_release(struct socket *sock);
+void af_alg_release_parent(struct sock *sk);
 int af_alg_accept(struct sock *sk, struct socket *newsock);
 
 int af_alg_make_sg(struct af_alg_sgl *sgl, struct iov_iter *iter, int len);
@@ -83,11 +86,6 @@ static inline struct alg_sock *alg_sk(struct sock *sk)
 	return (struct alg_sock *)sk;
 }
 
-static inline void af_alg_release_parent(struct sock *sk)
-{
-	sock_put(alg_sk(sk)->parent);
-}
-
 static inline void af_alg_init_completion(struct af_alg_completion *completion)
 {
 	init_completion(&completion->completion);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319900 — [PATCH 4.2.y-ckt 163/268] dmaengine: at_xdmac: fix resume for cyclic transfers

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 163/268] dmaengine: at_xdmac: fix resume for cyclic transfers
Message-ID<qVFP6-1mL-45@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Songjun Wu <songjun.wu@atmel.com>

commit 611dcadb01c89d1d3521450c05a4ded332e5a32d upstream.

When having cyclic transfers, the channel was paused when performing
suspend but was not correctly resumed.

Signed-off-by: Songjun Wu <songjun.wu@atmel.com>
Signed-off-by: Ludovic Desroches <ludovic.desroches@atmel.com>
Fixes: e1f7c9eee707 ("dmaengine: at_xdmac: creation of the atmel
eXtended DMA Controller driver")
Signed-off-by: Vinod Koul <vinod.koul@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/dma/at_xdmac.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/dma/at_xdmac.c b/drivers/dma/at_xdmac.c
index c01cdec..756210a 100644
--- a/drivers/dma/at_xdmac.c
+++ b/drivers/dma/at_xdmac.c
@@ -1524,6 +1524,7 @@ static int at_xdmac_device_terminate_all(struct dma_chan *chan)
 	list_for_each_entry_safe(desc, _desc, &atchan->xfers_list, xfer_node)
 		at_xdmac_remove_xfer(atchan, desc);
 
+	clear_bit(AT_XDMAC_CHAN_IS_PAUSED, &atchan->status);
 	clear_bit(AT_XDMAC_CHAN_IS_CYCLIC, &atchan->status);
 	spin_unlock_irqrestore(&atchan->lock, flags);
 
@@ -1656,6 +1657,8 @@ static int atmel_xdmac_resume(struct device *dev)
 		atchan = to_at_xdmac_chan(chan);
 		at_xdmac_chan_write(atchan, AT_XDMAC_CC, atchan->save_cc);
 		if (at_xdmac_chan_is_cyclic(atchan)) {
+			if (at_xdmac_chan_is_paused(atchan))
+				at_xdmac_device_resume(chan);
 			at_xdmac_chan_write(atchan, AT_XDMAC_CNDA, atchan->save_cnda);
 			at_xdmac_chan_write(atchan, AT_XDMAC_CNDC, atchan->save_cndc);
 			at_xdmac_chan_write(atchan, AT_XDMAC_CIE, atchan->save_cim);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319901 — [PATCH 4.2.y-ckt 162/268] ALSA: hrtimer: Fix stall by hrtimer_cancel()

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 162/268] ALSA: hrtimer: Fix stall by hrtimer_cancel()
Message-ID<qVFP6-1mL-47@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit 2ba1fe7a06d3624f9a7586d672b55f08f7c670f3 upstream.

hrtimer_cancel() waits for the completion from the callback, thus it
must not be called inside the callback itself.  This was already a
problem in the past with ALSA hrtimer driver, and the early commit
[fcfdebe70759: ALSA: hrtimer - Fix lock-up] tried to address it.

However, the previous fix is still insufficient: it may still cause a
lockup when the ALSA timer instance reprograms itself in its callback.
Then it invokes the start function even in snd_timer_interrupt() that
is called in hrtimer callback itself, results in a CPU stall.  This is
no hypothetical problem but actually triggered by syzkaller fuzzer.

This patch tries to fix the issue again.  Now we call
hrtimer_try_to_cancel() at both start and stop functions so that it
won't fall into a deadlock, yet giving some chance to cancel the queue
if the functions have been called outside the callback.  The proper
hrtimer_cancel() is called in anyway at closing, so this should be
enough.

Reported-and-tested-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/core/hrtimer.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/sound/core/hrtimer.c b/sound/core/hrtimer.c
index f845ecf..656d9a9 100644
--- a/sound/core/hrtimer.c
+++ b/sound/core/hrtimer.c
@@ -90,7 +90,7 @@ static int snd_hrtimer_start(struct snd_timer *t)
 	struct snd_hrtimer *stime = t->private_data;
 
 	atomic_set(&stime->running, 0);
-	hrtimer_cancel(&stime->hrt);
+	hrtimer_try_to_cancel(&stime->hrt);
 	hrtimer_start(&stime->hrt, ns_to_ktime(t->sticks * resolution),
 		      HRTIMER_MODE_REL);
 	atomic_set(&stime->running, 1);
@@ -101,6 +101,7 @@ static int snd_hrtimer_stop(struct snd_timer *t)
 {
 	struct snd_hrtimer *stime = t->private_data;
 	atomic_set(&stime->running, 0);
+	hrtimer_try_to_cancel(&stime->hrt);
 	return 0;
 }
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319902 — [PATCH 4.2.y-ckt 143/268] memcg: only free spare array when readers are done

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 143/268] memcg: only free spare array when readers are done
Message-ID<qVFP6-1mL-49@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Martijn Coenen <maco@google.com>

commit 6611d8d76132f86faa501de9451a89bf23fb2371 upstream.

A spare array holding mem cgroup threshold events is kept around to make
sure we can always safely deregister an event and have an array to store
the new set of events in.

In the scenario where we're going from 1 to 0 registered events, the
pointer to the primary array containing 1 event is copied to the spare
slot, and then the spare slot is freed because no events are left.
However, it is freed before calling synchronize_rcu(), which means
readers may still be accessing threshold->primary after it is freed.

Fixed by only freeing after synchronize_rcu().

Signed-off-by: Martijn Coenen <maco@google.com>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Acked-by: Michal Hocko <mhocko@suse.com>
Cc: Vladimir Davydov <vdavydov@virtuozzo.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 mm/memcontrol.c | 11 ++++++-----
 1 file changed, 6 insertions(+), 5 deletions(-)

diff --git a/mm/memcontrol.c b/mm/memcontrol.c
index 364f972..48540e5 100644
--- a/mm/memcontrol.c
+++ b/mm/memcontrol.c
@@ -3833,16 +3833,17 @@ static void __mem_cgroup_usage_unregister_event(struct mem_cgroup *memcg,
 swap_buffers:
 	/* Swap primary and spare array */
 	thresholds->spare = thresholds->primary;
-	/* If all events are unregistered, free the spare array */
-	if (!new) {
-		kfree(thresholds->spare);
-		thresholds->spare = NULL;
-	}
 
 	rcu_assign_pointer(thresholds->primary, new);
 
 	/* To be sure that nobody uses thresholds */
 	synchronize_rcu();
+
+	/* If all events are unregistered, free the spare array */
+	if (!new) {
+		kfree(thresholds->spare);
+		thresholds->spare = NULL;
+	}
 unlock:
 	mutex_unlock(&memcg->thresholds_lock);
 }
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319903 — [PATCH 4.2.y-ckt 133/268] scripts/bloat-o-meter: fix python3 syntax error

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 133/268] scripts/bloat-o-meter: fix python3 syntax error
Message-ID<qVFP6-1mL-51@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Sergey Senozhatsky <sergey.senozhatsky.work@gmail.com>

commit 72214a24a7677d4c7501eecc9517ed681b5f2db2 upstream.

In Python3+ print is a function so the old syntax is not correct
anymore:

  $ ./scripts/bloat-o-meter vmlinux.o vmlinux.o.old
    File "./scripts/bloat-o-meter", line 61
      print "add/remove: %s/%s grow/shrink: %s/%s up/down: %s/%s (%s)" % \
                                                                     ^
  SyntaxError: invalid syntax

Fix by calling print as a function.

Tested on python 2.7.11, 3.5.1

Signed-off-by: Sergey Senozhatsky <sergey.senozhatsky@gmail.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 scripts/bloat-o-meter | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/scripts/bloat-o-meter b/scripts/bloat-o-meter
index 23e78dc..38b64f4 100755
--- a/scripts/bloat-o-meter
+++ b/scripts/bloat-o-meter
@@ -58,8 +58,8 @@ for name in common:
 delta.sort()
 delta.reverse()
 
-print "add/remove: %s/%s grow/shrink: %s/%s up/down: %s/%s (%s)" % \
-      (add, remove, grow, shrink, up, -down, up-down)
-print "%-40s %7s %7s %+7s" % ("function", "old", "new", "delta")
+print("add/remove: %s/%s grow/shrink: %s/%s up/down: %s/%s (%s)" % \
+      (add, remove, grow, shrink, up, -down, up-down))
+print("%-40s %7s %7s %+7s" % ("function", "old", "new", "delta"))
 for d, n in delta:
-    if d: print "%-40s %7s %7s %+7d" % (n, old.get(n,"-"), new.get(n,"-"), d)
+    if d: print("%-40s %7s %7s %+7d" % (n, old.get(n,"-"), new.get(n,"-"), d))
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319904 — [PATCH 4.2.y-ckt 141/268] mm: soft-offline: check return value in second __get_any_page() call

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 141/268] mm: soft-offline: check return value in second __get_any_page() call
Message-ID<qVFP7-1mL-53@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>

commit d96b339f453997f2f08c52da3f41423be48c978f upstream.

I saw the following BUG_ON triggered in a testcase where a process calls
madvise(MADV_SOFT_OFFLINE) on thps, along with a background process that
calls migratepages command repeatedly (doing ping-pong among different
NUMA nodes) for the first process:

   Soft offlining page 0x60000 at 0x700000600000
   __get_any_page: 0x60000 free buddy page
   page:ffffea0001800000 count:0 mapcount:-127 mapping:          (null) index:0x1
   flags: 0x1fffc0000000000()
   page dumped because: VM_BUG_ON_PAGE(atomic_read(&page->_count) == 0)
   ------------[ cut here ]------------
   kernel BUG at /src/linux-dev/include/linux/mm.h:342!
   invalid opcode: 0000 [#1] SMP DEBUG_PAGEALLOC
   Modules linked in: cfg80211 rfkill crc32c_intel serio_raw virtio_balloon i2c_piix4 virtio_blk virtio_net ata_generic pata_acpi
   CPU: 3 PID: 3035 Comm: test_alloc_gene Tainted: G           O    4.4.0-rc8-v4.4-rc8-160107-1501-00000-rc8+ #74
   Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
   task: ffff88007c63d5c0 ti: ffff88007c210000 task.ti: ffff88007c210000
   RIP: 0010:[<ffffffff8118998c>]  [<ffffffff8118998c>] put_page+0x5c/0x60
   RSP: 0018:ffff88007c213e00  EFLAGS: 00010246
   Call Trace:
     put_hwpoison_page+0x4e/0x80
     soft_offline_page+0x501/0x520
     SyS_madvise+0x6bc/0x6f0
     entry_SYSCALL_64_fastpath+0x12/0x6a
   Code: 8b fc ff ff 5b 5d c3 48 89 df e8 b0 fa ff ff 48 89 df 31 f6 e8 c6 7d ff ff 5b 5d c3 48 c7 c6 08 54 a2 81 48 89 df e8 a4 c5 01 00 <0f> 0b 66 90 66 66 66 66 90 55 48 89 e5 41 55 41 54 53 48 8b 47
   RIP  [<ffffffff8118998c>] put_page+0x5c/0x60
    RSP <ffff88007c213e00>

The root cause resides in get_any_page() which retries to get a refcount
of the page to be soft-offlined.  This function calls
put_hwpoison_page(), expecting that the target page is putback to LRU
list.  But it can be also freed to buddy.  So the second check need to
care about such case.

Fixes: af8fae7c0886 ("mm/memory-failure.c: clean up soft_offline_page()")
Signed-off-by: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
Cc: Sasha Levin <sasha.levin@oracle.com>
Cc: Aneesh Kumar K.V <aneesh.kumar@linux.vnet.ibm.com>
Cc: Vlastimil Babka <vbabka@suse.cz>
Cc: Jerome Marchand <jmarchan@redhat.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Dave Hansen <dave.hansen@intel.com>
Cc: Mel Gorman <mgorman@suse.de>
Cc: Rik van Riel <riel@redhat.com>
Cc: Steve Capper <steve.capper@linaro.org>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Michal Hocko <mhocko@suse.cz>
Cc: Christoph Lameter <cl@linux.com>
Cc: David Rientjes <rientjes@google.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 mm/memory-failure.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/mm/memory-failure.c b/mm/memory-failure.c
index 1f4446a..20cc5b7 100644
--- a/mm/memory-failure.c
+++ b/mm/memory-failure.c
@@ -1540,7 +1540,7 @@ static int get_any_page(struct page *page, unsigned long pfn, int flags)
 		 * Did it turn free?
 		 */
 		ret = __get_any_page(page, pfn, 0);
-		if (!PageLRU(page)) {
+		if (ret == 1 && !PageLRU(page)) {
 			/* Drop page reference which is from __get_any_page() */
 			put_page(page);
 			pr_info("soft_offline: %#lx: unknown non LRU page type %lx\n",
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319905 — [PATCH 4.2.y-ckt 137/268] zram/zcomp: use GFP_NOIO to allocate streams

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 137/268] zram/zcomp: use GFP_NOIO to allocate streams
Message-ID<qVFP7-1mL-61@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Sergey Senozhatsky <sergey.senozhatsky@gmail.com>

commit 3d5fe03a3ea013060ebba2a811aeb0f23f56aefa upstream.

We can end up allocating a new compression stream with GFP_KERNEL from
within the IO path, which may result is nested (recursive) IO
operations.  That can introduce problems if the IO path in question is a
reclaimer, holding some locks that will deadlock nested IOs.

Allocate streams and working memory using GFP_NOIO flag, forbidding
recursive IO and FS operations.

An example:

  inconsistent {IN-RECLAIM_FS-W} -> {RECLAIM_FS-ON-W} usage.
  git/20158 [HC0[0]:SC0[0]:HE1:SE1] takes:
   (jbd2_handle){+.+.?.}, at:  start_this_handle+0x4ca/0x555
  {IN-RECLAIM_FS-W} state was registered at:
     __lock_acquire+0x8da/0x117b
     lock_acquire+0x10c/0x1a7
     start_this_handle+0x52d/0x555
     jbd2__journal_start+0xb4/0x237
     __ext4_journal_start_sb+0x108/0x17e
     ext4_dirty_inode+0x32/0x61
     __mark_inode_dirty+0x16b/0x60c
     iput+0x11e/0x274
     __dentry_kill+0x148/0x1b8
     shrink_dentry_list+0x274/0x44a
     prune_dcache_sb+0x4a/0x55
     super_cache_scan+0xfc/0x176
     shrink_slab.part.14.constprop.25+0x2a2/0x4d3
     shrink_zone+0x74/0x140
     kswapd+0x6b7/0x930
     kthread+0x107/0x10f
     ret_from_fork+0x3f/0x70
  irq event stamp: 138297
  hardirqs last  enabled at (138297):  debug_check_no_locks_freed+0x113/0x12f
  hardirqs last disabled at (138296):  debug_check_no_locks_freed+0x33/0x12f
  softirqs last  enabled at (137818):  __do_softirq+0x2d3/0x3e9
  softirqs last disabled at (137813):  irq_exit+0x41/0x95

               other info that might help us debug this:
   Possible unsafe locking scenario:
         CPU0
         ----
    lock(jbd2_handle);
    <Interrupt>
      lock(jbd2_handle);

                *** DEADLOCK ***
  5 locks held by git/20158:
   #0:  (sb_writers#7){.+.+.+}, at: [<ffffffff81155411>] mnt_want_write+0x24/0x4b
   #1:  (&type->i_mutex_dir_key#2/1){+.+.+.}, at: [<ffffffff81145087>] lock_rename+0xd9/0xe3
   #2:  (&sb->s_type->i_mutex_key#11){+.+.+.}, at: [<ffffffff8114f8e2>] lock_two_nondirectories+0x3f/0x6b
   #3:  (&sb->s_type->i_mutex_key#11/4){+.+.+.}, at: [<ffffffff8114f909>] lock_two_nondirectories+0x66/0x6b
   #4:  (jbd2_handle){+.+.?.}, at: [<ffffffff811e31db>] start_this_handle+0x4ca/0x555

               stack backtrace:
  CPU: 2 PID: 20158 Comm: git Not tainted 4.1.0-rc7-next-20150615-dbg-00016-g8bdf555-dirty #211
  Call Trace:
    dump_stack+0x4c/0x6e
    mark_lock+0x384/0x56d
    mark_held_locks+0x5f/0x76
    lockdep_trace_alloc+0xb2/0xb5
    kmem_cache_alloc_trace+0x32/0x1e2
    zcomp_strm_alloc+0x25/0x73 [zram]
    zcomp_strm_multi_find+0xe7/0x173 [zram]
    zcomp_strm_find+0xc/0xe [zram]
    zram_bvec_rw+0x2ca/0x7e0 [zram]
    zram_make_request+0x1fa/0x301 [zram]
    generic_make_request+0x9c/0xdb
    submit_bio+0xf7/0x120
    ext4_io_submit+0x2e/0x43
    ext4_bio_write_page+0x1b7/0x300
    mpage_submit_page+0x60/0x77
    mpage_map_and_submit_buffers+0x10f/0x21d
    ext4_writepages+0xc8c/0xe1b
    do_writepages+0x23/0x2c
    __filemap_fdatawrite_range+0x84/0x8b
    filemap_flush+0x1c/0x1e
    ext4_alloc_da_blocks+0xb8/0x117
    ext4_rename+0x132/0x6dc
    ? mark_held_locks+0x5f/0x76
    ext4_rename2+0x29/0x2b
    vfs_rename+0x540/0x636
    SyS_renameat2+0x359/0x44d
    SyS_rename+0x1e/0x20
    entry_SYSCALL_64_fastpath+0x12/0x6f

[minchan@kernel.org: add stable mark]
Signed-off-by: Sergey Senozhatsky <sergey.senozhatsky@gmail.com>
Acked-by: Minchan Kim <minchan@kernel.org>
Cc: Kyeongdon Kim <kyeongdon.kim@lge.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/block/zram/zcomp.c     | 4 ++--
 drivers/block/zram/zcomp_lz4.c | 2 +-
 drivers/block/zram/zcomp_lzo.c | 2 +-
 3 files changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/block/zram/zcomp.c b/drivers/block/zram/zcomp.c
index 5cb13ca..c536177 100644
--- a/drivers/block/zram/zcomp.c
+++ b/drivers/block/zram/zcomp.c
@@ -76,7 +76,7 @@ static void zcomp_strm_free(struct zcomp *comp, struct zcomp_strm *zstrm)
  */
 static struct zcomp_strm *zcomp_strm_alloc(struct zcomp *comp)
 {
-	struct zcomp_strm *zstrm = kmalloc(sizeof(*zstrm), GFP_KERNEL);
+	struct zcomp_strm *zstrm = kmalloc(sizeof(*zstrm), GFP_NOIO);
 	if (!zstrm)
 		return NULL;
 
@@ -85,7 +85,7 @@ static struct zcomp_strm *zcomp_strm_alloc(struct zcomp *comp)
 	 * allocate 2 pages. 1 for compressed data, plus 1 extra for the
 	 * case when compressed size is larger than the original one
 	 */
-	zstrm->buffer = (void *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 1);
+	zstrm->buffer = (void *)__get_free_pages(GFP_NOIO | __GFP_ZERO, 1);
 	if (!zstrm->private || !zstrm->buffer) {
 		zcomp_strm_free(comp, zstrm);
 		zstrm = NULL;
diff --git a/drivers/block/zram/zcomp_lz4.c b/drivers/block/zram/zcomp_lz4.c
index f2afb7e..ee44b51 100644
--- a/drivers/block/zram/zcomp_lz4.c
+++ b/drivers/block/zram/zcomp_lz4.c
@@ -15,7 +15,7 @@
 
 static void *zcomp_lz4_create(void)
 {
-	return kzalloc(LZ4_MEM_COMPRESS, GFP_KERNEL);
+	return kzalloc(LZ4_MEM_COMPRESS, GFP_NOIO);
 }
 
 static void zcomp_lz4_destroy(void *private)
diff --git a/drivers/block/zram/zcomp_lzo.c b/drivers/block/zram/zcomp_lzo.c
index da1bc47..683ce04 100644
--- a/drivers/block/zram/zcomp_lzo.c
+++ b/drivers/block/zram/zcomp_lzo.c
@@ -15,7 +15,7 @@
 
 static void *lzo_create(void)
 {
-	return kzalloc(LZO1X_MEM_COMPRESS, GFP_KERNEL);
+	return kzalloc(LZO1X_MEM_COMPRESS, GFP_NOIO);
 }
 
 static void lzo_destroy(void *private)
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319906 — [PATCH 4.2.y-ckt 165/268] ALSA: seq: Fix snd_seq_call_port_info_ioctl in compat mode

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 165/268] ALSA: seq: Fix snd_seq_call_port_info_ioctl in compat mode
Message-ID<qVFP7-1mL-57@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Nicolas Boichat <drinkcat@chromium.org>

commit 9586495dc3011a80602329094e746dbce16cb1f1 upstream.

This reverts one hunk of
commit ef44a1ec6eee ("ALSA: sound/core: use memdup_user()"), which
replaced a number of kmalloc followed by memcpy with memdup calls.

In this case, we are copying from a struct snd_seq_port_info32 to a
struct snd_seq_port_info, but the latter is 4 bytes longer than the
32-bit version, so we need to separate kmalloc and copy calls.

Fixes: ef44a1ec6eee ('ALSA: sound/core: use memdup_user()')
Signed-off-by: Nicolas Boichat <drinkcat@chromium.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/core/seq/seq_compat.c | 9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

diff --git a/sound/core/seq/seq_compat.c b/sound/core/seq/seq_compat.c
index 81f7c10..6517590 100644
--- a/sound/core/seq/seq_compat.c
+++ b/sound/core/seq/seq_compat.c
@@ -49,11 +49,12 @@ static int snd_seq_call_port_info_ioctl(struct snd_seq_client *client, unsigned
 	struct snd_seq_port_info *data;
 	mm_segment_t fs;
 
-	data = memdup_user(data32, sizeof(*data32));
-	if (IS_ERR(data))
-		return PTR_ERR(data);
+	data = kmalloc(sizeof(*data), GFP_KERNEL);
+	if (!data)
+		return -ENOMEM;
 
-	if (get_user(data->flags, &data32->flags) ||
+	if (copy_from_user(data, data32, sizeof(*data32)) ||
+	    get_user(data->flags, &data32->flags) ||
 	    get_user(data->time_queue, &data32->time_queue))
 		goto error;
 	data->kernel = NULL;
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319907 — [PATCH 4.2.y-ckt 158/268] crypto: af_alg - Forbid bind(2) when nokey child sockets are present

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 158/268] crypto: af_alg - Forbid bind(2) when nokey child sockets are present
Message-ID<qVFP7-1mL-55@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit a6a48c565f6f112c6983e2a02b1602189ed6e26e upstream.

This patch forbids the calling of bind(2) when there are child
sockets created by accept(2) in existence, even if they are created
on the nokey path.

This is needed as those child sockets have references to the tfm
object which bind(2) will destroy.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/af_alg.c | 16 +++++++---------
 1 file changed, 7 insertions(+), 9 deletions(-)

diff --git a/crypto/af_alg.c b/crypto/af_alg.c
index e7cb836..f5e18c2 100644
--- a/crypto/af_alg.c
+++ b/crypto/af_alg.c
@@ -130,19 +130,16 @@ EXPORT_SYMBOL_GPL(af_alg_release);
 void af_alg_release_parent(struct sock *sk)
 {
 	struct alg_sock *ask = alg_sk(sk);
-	bool last;
+	unsigned int nokey = ask->nokey_refcnt;
+	bool last = nokey && !ask->refcnt;
 
 	sk = ask->parent;
-
-	if (ask->nokey_refcnt && !ask->refcnt) {
-		sock_put(sk);
-		return;
-	}
-
 	ask = alg_sk(sk);
 
 	lock_sock(sk);
-	last = !--ask->refcnt;
+	ask->nokey_refcnt -= nokey;
+	if (!last)
+		last = !--ask->refcnt;
 	release_sock(sk);
 
 	if (last)
@@ -188,7 +185,7 @@ static int alg_bind(struct socket *sock, struct sockaddr *uaddr, int addr_len)
 
 	err = -EBUSY;
 	lock_sock(sk);
-	if (ask->refcnt)
+	if (ask->refcnt | ask->nokey_refcnt)
 		goto unlock;
 
 	swap(ask->type, type);
@@ -306,6 +303,7 @@ int af_alg_accept(struct sock *sk, struct socket *newsock)
 
 	if (nokey || !ask->refcnt++)
 		sock_hold(sk);
+	ask->nokey_refcnt += nokey;
 	alg_sk(sk2)->parent = sk;
 	alg_sk(sk2)->type = type;
 	alg_sk(sk2)->nokey_refcnt = nokey;
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319908 — [PATCH 4.2.y-ckt 152/268] crypto: algif_skcipher - Add nokey compatibility path

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 152/268] crypto: algif_skcipher - Add nokey compatibility path
Message-ID<qVFP7-1mL-59@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit a0fa2d037129a9849918a92d91b79ed6c7bd2818 upstream.

This patch adds a compatibility path to support old applications
that do acept(2) before setkey.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/algif_skcipher.c | 149 ++++++++++++++++++++++++++++++++++++++++++++++--
 1 file changed, 144 insertions(+), 5 deletions(-)

diff --git a/crypto/algif_skcipher.c b/crypto/algif_skcipher.c
index 1e7e09b..cdfb1bf 100644
--- a/crypto/algif_skcipher.c
+++ b/crypto/algif_skcipher.c
@@ -754,6 +754,99 @@ static struct proto_ops algif_skcipher_ops = {
 	.poll		=	skcipher_poll,
 };
 
+static int skcipher_check_key(struct socket *sock)
+{
+	int err;
+	struct sock *psk;
+	struct alg_sock *pask;
+	struct skcipher_tfm *tfm;
+	struct sock *sk = sock->sk;
+	struct alg_sock *ask = alg_sk(sk);
+
+	if (ask->refcnt)
+		return 0;
+
+	psk = ask->parent;
+	pask = alg_sk(ask->parent);
+	tfm = pask->private;
+
+	err = -ENOKEY;
+	lock_sock(psk);
+	if (!tfm->has_key)
+		goto unlock;
+
+	if (!pask->refcnt++)
+		sock_hold(psk);
+
+	ask->refcnt = 1;
+	sock_put(psk);
+
+	err = 0;
+
+unlock:
+	release_sock(psk);
+
+	return err;
+}
+
+static int skcipher_sendmsg_nokey(struct socket *sock, struct msghdr *msg,
+				  size_t size)
+{
+	int err;
+
+	err = skcipher_check_key(sock);
+	if (err)
+		return err;
+
+	return skcipher_sendmsg(sock, msg, size);
+}
+
+static ssize_t skcipher_sendpage_nokey(struct socket *sock, struct page *page,
+				       int offset, size_t size, int flags)
+{
+	int err;
+
+	err = skcipher_check_key(sock);
+	if (err)
+		return err;
+
+	return skcipher_sendpage(sock, page, offset, size, flags);
+}
+
+static int skcipher_recvmsg_nokey(struct socket *sock, struct msghdr *msg,
+				  size_t ignored, int flags)
+{
+	int err;
+
+	err = skcipher_check_key(sock);
+	if (err)
+		return err;
+
+	return skcipher_recvmsg(sock, msg, ignored, flags);
+}
+
+static struct proto_ops algif_skcipher_ops_nokey = {
+	.family		=	PF_ALG,
+
+	.connect	=	sock_no_connect,
+	.socketpair	=	sock_no_socketpair,
+	.getname	=	sock_no_getname,
+	.ioctl		=	sock_no_ioctl,
+	.listen		=	sock_no_listen,
+	.shutdown	=	sock_no_shutdown,
+	.getsockopt	=	sock_no_getsockopt,
+	.mmap		=	sock_no_mmap,
+	.bind		=	sock_no_bind,
+	.accept		=	sock_no_accept,
+	.setsockopt	=	sock_no_setsockopt,
+
+	.release	=	af_alg_release,
+	.sendmsg	=	skcipher_sendmsg_nokey,
+	.sendpage	=	skcipher_sendpage_nokey,
+	.recvmsg	=	skcipher_recvmsg_nokey,
+	.poll		=	skcipher_poll,
+};
+
 static void *skcipher_bind(const char *name, u32 type, u32 mask)
 {
 	struct skcipher_tfm *tfm;
@@ -803,7 +896,7 @@ static void skcipher_wait(struct sock *sk)
 		msleep(100);
 }
 
-static void skcipher_sock_destruct(struct sock *sk)
+static void skcipher_sock_destruct_common(struct sock *sk)
 {
 	struct alg_sock *ask = alg_sk(sk);
 	struct skcipher_ctx *ctx = ask->private;
@@ -815,10 +908,33 @@ static void skcipher_sock_destruct(struct sock *sk)
 	skcipher_free_sgl(sk);
 	sock_kzfree_s(sk, ctx->iv, crypto_ablkcipher_ivsize(tfm));
 	sock_kfree_s(sk, ctx, ctx->len);
+}
+
+static void skcipher_sock_destruct(struct sock *sk)
+{
+	skcipher_sock_destruct_common(sk);
 	af_alg_release_parent(sk);
 }
 
-static int skcipher_accept_parent(void *private, struct sock *sk)
+static void skcipher_release_parent_nokey(struct sock *sk)
+{
+	struct alg_sock *ask = alg_sk(sk);
+
+	if (!ask->refcnt) {
+		sock_put(ask->parent);
+		return;
+	}
+
+	af_alg_release_parent(sk);
+}
+
+static void skcipher_sock_destruct_nokey(struct sock *sk)
+{
+	skcipher_sock_destruct_common(sk);
+	skcipher_release_parent_nokey(sk);
+}
+
+static int skcipher_accept_parent_common(void *private, struct sock *sk)
 {
 	struct skcipher_ctx *ctx;
 	struct alg_sock *ask = alg_sk(sk);
@@ -826,9 +942,6 @@ static int skcipher_accept_parent(void *private, struct sock *sk)
 	struct crypto_ablkcipher *skcipher = tfm->skcipher;
 	unsigned int len = sizeof(*ctx) + crypto_ablkcipher_reqsize(skcipher);
 
-	if (!tfm->has_key)
-		return -ENOKEY;
-
 	ctx = sock_kmalloc(sk, len, GFP_KERNEL);
 	if (!ctx)
 		return -ENOMEM;
@@ -862,12 +975,38 @@ static int skcipher_accept_parent(void *private, struct sock *sk)
 	return 0;
 }
 
+static int skcipher_accept_parent(void *private, struct sock *sk)
+{
+	struct skcipher_tfm *tfm = private;
+
+	if (!tfm->has_key)
+		return -ENOKEY;
+
+	return skcipher_accept_parent_common(private, sk);
+}
+
+static int skcipher_accept_parent_nokey(void *private, struct sock *sk)
+{
+	int err;
+
+	err = skcipher_accept_parent_common(private, sk);
+	if (err)
+		goto out;
+
+	sk->sk_destruct = skcipher_sock_destruct_nokey;
+
+out:
+	return err;
+}
+
 static const struct af_alg_type algif_type_skcipher = {
 	.bind		=	skcipher_bind,
 	.release	=	skcipher_release,
 	.setkey		=	skcipher_setkey,
 	.accept		=	skcipher_accept_parent,
+	.accept_nokey	=	skcipher_accept_parent_nokey,
 	.ops		=	&algif_skcipher_ops,
+	.ops_nokey	=	&algif_skcipher_ops_nokey,
 	.name		=	"skcipher",
 	.owner		=	THIS_MODULE
 };
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319909 — [PATCH 4.2.y-ckt 144/268] panic: release stale console lock to always get the logbuf printed out

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 144/268] panic: release stale console lock to always get the logbuf printed out
Message-ID<qVFP7-1mL-65@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Vitaly Kuznetsov <vkuznets@redhat.com>

commit 08d78658f393fefaa2e6507ea052c6f8ef4002a2 upstream.

In some cases we may end up killing the CPU holding the console lock
while still having valuable data in logbuf. E.g. I'm observing the
following:

- A crash is happening on one CPU and console_unlock() is being called on
  some other.

- console_unlock() tries to print out the buffer before releasing the lock
  and on slow console it takes time.

- in the meanwhile crashing CPU does lots of printk()-s with valuable data
  (which go to the logbuf) and sends IPIs to all other CPUs.

- console_unlock() finishes printing previous chunk and enables interrupts
  before trying to print out the rest, the CPU catches the IPI and never
  releases console lock.

This is not the only possible case: in VT/fb subsystems we have many other
console_lock()/console_unlock() users.  Non-masked interrupts (or
receiving NMI in case of extreme slowness) will have the same result.
Getting the whole console buffer printed out on crash should be top
priority.

[akpm@linux-foundation.org: tweak comment text]
Signed-off-by: Vitaly Kuznetsov <vkuznets@redhat.com>
Cc: HATAYAMA Daisuke <d.hatayama@jp.fujitsu.com>
Cc: Masami Hiramatsu <masami.hiramatsu.pt@hitachi.com>
Cc: Jiri Kosina <jkosina@suse.cz>
Cc: Baoquan He <bhe@redhat.com>
Cc: Prarit Bhargava <prarit@redhat.com>
Cc: Xie XiuQi <xiexiuqi@huawei.com>
Cc: Seth Jennings <sjenning@redhat.com>
Cc: "K. Y. Srinivasan" <kys@microsoft.com>
Cc: Jan Kara <jack@suse.cz>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[ kamal: 4.2-stable prereq for
  8d91f8b printk: do cond_resched() between lines while outputting to consoles ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 kernel/panic.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/kernel/panic.c b/kernel/panic.c
index 04e91ff..4579dbb 100644
--- a/kernel/panic.c
+++ b/kernel/panic.c
@@ -23,6 +23,7 @@
 #include <linux/sysrq.h>
 #include <linux/init.h>
 #include <linux/nmi.h>
+#include <linux/console.h>
 
 #define PANIC_TIMER_STEP 100
 #define PANIC_BLINK_SPD 18
@@ -147,6 +148,15 @@ void panic(const char *fmt, ...)
 
 	bust_spinlocks(0);
 
+	/*
+	 * We may have ended up stopping the CPU holding the lock (in
+	 * smp_send_stop()) while still having some valuable data in the console
+	 * buffer.  Try to acquire the lock then release it regardless of the
+	 * result.  The release will also print the buffers out.
+	 */
+	console_trylock();
+	console_unlock();
+
 	if (!panic_blink)
 		panic_blink = no_blink;
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319910 — [PATCH 4.2.y-ckt 148/268] crypto: algif_skcipher - Require setkey before accept(2)

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 148/268] crypto: algif_skcipher - Require setkey before accept(2)
Message-ID<qVFP7-1mL-63@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit dd504589577d8e8e70f51f997ad487a4cb6c026f upstream.

Some cipher implementations will crash if you try to use them
without calling setkey first.  This patch adds a check so that
the accept(2) call will fail with -ENOKEY if setkey hasn't been
done on the socket yet.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Tested-by: Dmitry Vyukov <dvyukov@google.com>
[ kamal: backport to 4.2-stable: crypto_alloc_ablkcipher API ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/algif_skcipher.c | 48 +++++++++++++++++++++++++++++++++++++++++-------
 1 file changed, 41 insertions(+), 7 deletions(-)

diff --git a/crypto/algif_skcipher.c b/crypto/algif_skcipher.c
index 9450752..1e7e09b 100644
--- a/crypto/algif_skcipher.c
+++ b/crypto/algif_skcipher.c
@@ -31,6 +31,11 @@ struct skcipher_sg_list {
 	struct scatterlist sg[0];
 };
 
+struct skcipher_tfm {
+	struct crypto_ablkcipher *skcipher;
+	bool has_key;
+};
+
 struct skcipher_ctx {
 	struct list_head tsgl;
 	struct af_alg_sgl rsgl;
@@ -751,17 +756,41 @@ static struct proto_ops algif_skcipher_ops = {
 
 static void *skcipher_bind(const char *name, u32 type, u32 mask)
 {
-	return crypto_alloc_ablkcipher(name, type, mask);
+	struct skcipher_tfm *tfm;
+	struct crypto_ablkcipher *skcipher;
+
+	tfm = kzalloc(sizeof(*tfm), GFP_KERNEL);
+	if (!tfm)
+		return ERR_PTR(-ENOMEM);
+
+	skcipher = crypto_alloc_ablkcipher(name, type, mask);
+	if (IS_ERR(skcipher)) {
+		kfree(tfm);
+		return ERR_CAST(skcipher);
+	}
+
+	tfm->skcipher = skcipher;
+
+	return tfm;
 }
 
 static void skcipher_release(void *private)
 {
-	crypto_free_ablkcipher(private);
+	struct skcipher_tfm *tfm = private;
+
+	crypto_free_ablkcipher(tfm->skcipher);
+	kfree(tfm);
 }
 
 static int skcipher_setkey(void *private, const u8 *key, unsigned int keylen)
 {
-	return crypto_ablkcipher_setkey(private, key, keylen);
+	struct skcipher_tfm *tfm = private;
+	int err;
+
+	err = crypto_ablkcipher_setkey(tfm->skcipher, key, keylen);
+	tfm->has_key = !err;
+
+	return err;
 }
 
 static void skcipher_wait(struct sock *sk)
@@ -793,20 +822,25 @@ static int skcipher_accept_parent(void *private, struct sock *sk)
 {
 	struct skcipher_ctx *ctx;
 	struct alg_sock *ask = alg_sk(sk);
-	unsigned int len = sizeof(*ctx) + crypto_ablkcipher_reqsize(private);
+	struct skcipher_tfm *tfm = private;
+	struct crypto_ablkcipher *skcipher = tfm->skcipher;
+	unsigned int len = sizeof(*ctx) + crypto_ablkcipher_reqsize(skcipher);
+
+	if (!tfm->has_key)
+		return -ENOKEY;
 
 	ctx = sock_kmalloc(sk, len, GFP_KERNEL);
 	if (!ctx)
 		return -ENOMEM;
 
-	ctx->iv = sock_kmalloc(sk, crypto_ablkcipher_ivsize(private),
+	ctx->iv = sock_kmalloc(sk, crypto_ablkcipher_ivsize(skcipher),
 			       GFP_KERNEL);
 	if (!ctx->iv) {
 		sock_kfree_s(sk, ctx, len);
 		return -ENOMEM;
 	}
 
-	memset(ctx->iv, 0, crypto_ablkcipher_ivsize(private));
+	memset(ctx->iv, 0, crypto_ablkcipher_ivsize(skcipher));
 
 	INIT_LIST_HEAD(&ctx->tsgl);
 	ctx->len = len;
@@ -819,7 +853,7 @@ static int skcipher_accept_parent(void *private, struct sock *sk)
 
 	ask->private = ctx;
 
-	ablkcipher_request_set_tfm(&ctx->req, private);
+	ablkcipher_request_set_tfm(&ctx->req, skcipher);
 	ablkcipher_request_set_callback(&ctx->req, CRYPTO_TFM_REQ_MAY_BACKLOG,
 					af_alg_complete, &ctx->completion);
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319911 — [PATCH 4.2.y-ckt 101/268] x86/mm: Add barriers and document switch_mm()-vs-flush synchronization

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 101/268] x86/mm: Add barriers and document switch_mm()-vs-flush synchronization
Message-ID<qVFP7-1mL-67@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Andy Lutomirski <luto@kernel.org>

commit 71b3c126e61177eb693423f2e18a1914205b165e upstream.

When switch_mm() activates a new PGD, it also sets a bit that
tells other CPUs that the PGD is in use so that TLB flush IPIs
will be sent.  In order for that to work correctly, the bit
needs to be visible prior to loading the PGD and therefore
starting to fill the local TLB.

Document all the barriers that make this work correctly and add
a couple that were missing.

Signed-off-by: Andy Lutomirski <luto@kernel.org>
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Brian Gerst <brgerst@gmail.com>
Cc: Dave Hansen <dave.hansen@linux.intel.com>
Cc: Denys Vlasenko <dvlasenk@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Rik van Riel <riel@redhat.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: linux-mm@kvack.org
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/x86/include/asm/mmu_context.h | 33 ++++++++++++++++++++++++++++++++-
 arch/x86/mm/tlb.c                  | 29 ++++++++++++++++++++++++++---
 2 files changed, 58 insertions(+), 4 deletions(-)

diff --git a/arch/x86/include/asm/mmu_context.h b/arch/x86/include/asm/mmu_context.h
index 984abfe..48e8661 100644
--- a/arch/x86/include/asm/mmu_context.h
+++ b/arch/x86/include/asm/mmu_context.h
@@ -104,8 +104,34 @@ static inline void switch_mm(struct mm_struct *prev, struct mm_struct *next,
 #endif
 		cpumask_set_cpu(cpu, mm_cpumask(next));
 
-		/* Re-load page tables */
+		/*
+		 * Re-load page tables.
+		 *
+		 * This logic has an ordering constraint:
+		 *
+		 *  CPU 0: Write to a PTE for 'next'
+		 *  CPU 0: load bit 1 in mm_cpumask.  if nonzero, send IPI.
+		 *  CPU 1: set bit 1 in next's mm_cpumask
+		 *  CPU 1: load from the PTE that CPU 0 writes (implicit)
+		 *
+		 * We need to prevent an outcome in which CPU 1 observes
+		 * the new PTE value and CPU 0 observes bit 1 clear in
+		 * mm_cpumask.  (If that occurs, then the IPI will never
+		 * be sent, and CPU 0's TLB will contain a stale entry.)
+		 *
+		 * The bad outcome can occur if either CPU's load is
+		 * reordered before that CPU's store, so both CPUs much
+		 * execute full barriers to prevent this from happening.
+		 *
+		 * Thus, switch_mm needs a full barrier between the
+		 * store to mm_cpumask and any operation that could load
+		 * from next->pgd.  This barrier synchronizes with
+		 * remote TLB flushers.  Fortunately, load_cr3 is
+		 * serializing and thus acts as a full barrier.
+		 *
+		 */
 		load_cr3(next->pgd);
+
 		trace_tlb_flush(TLB_FLUSH_ON_TASK_SWITCH, TLB_FLUSH_ALL);
 
 		/* Stop flush ipis for the previous mm */
@@ -142,10 +168,15 @@ static inline void switch_mm(struct mm_struct *prev, struct mm_struct *next,
 			 * schedule, protecting us from simultaneous changes.
 			 */
 			cpumask_set_cpu(cpu, mm_cpumask(next));
+
 			/*
 			 * We were in lazy tlb mode and leave_mm disabled
 			 * tlb flush IPI delivery. We must reload CR3
 			 * to make sure to use no freed page tables.
+			 *
+			 * As above, this is a barrier that forces
+			 * TLB repopulation to be ordered after the
+			 * store to mm_cpumask.
 			 */
 			load_cr3(next->pgd);
 			trace_tlb_flush(TLB_FLUSH_ON_TASK_SWITCH, TLB_FLUSH_ALL);
diff --git a/arch/x86/mm/tlb.c b/arch/x86/mm/tlb.c
index 90b924a..061e011 100644
--- a/arch/x86/mm/tlb.c
+++ b/arch/x86/mm/tlb.c
@@ -160,7 +160,10 @@ void flush_tlb_current_task(void)
 	preempt_disable();
 
 	count_vm_tlb_event(NR_TLB_LOCAL_FLUSH_ALL);
+
+	/* This is an implicit full barrier that synchronizes with switch_mm. */
 	local_flush_tlb();
+
 	trace_tlb_flush(TLB_LOCAL_SHOOTDOWN, TLB_FLUSH_ALL);
 	if (cpumask_any_but(mm_cpumask(mm), smp_processor_id()) < nr_cpu_ids)
 		flush_tlb_others(mm_cpumask(mm), mm, 0UL, TLB_FLUSH_ALL);
@@ -187,17 +190,29 @@ void flush_tlb_mm_range(struct mm_struct *mm, unsigned long start,
 	unsigned long base_pages_to_flush = TLB_FLUSH_ALL;
 
 	preempt_disable();
-	if (current->active_mm != mm)
+	if (current->active_mm != mm) {
+		/* Synchronize with switch_mm. */
+		smp_mb();
+
 		goto out;
+	}
 
 	if (!current->mm) {
 		leave_mm(smp_processor_id());
+
+		/* Synchronize with switch_mm. */
+		smp_mb();
+
 		goto out;
 	}
 
 	if ((end != TLB_FLUSH_ALL) && !(vmflag & VM_HUGETLB))
 		base_pages_to_flush = (end - start) >> PAGE_SHIFT;
 
+	/*
+	 * Both branches below are implicit full barriers (MOV to CR or
+	 * INVLPG) that synchronize with switch_mm.
+	 */
 	if (base_pages_to_flush > tlb_single_page_flush_ceiling) {
 		base_pages_to_flush = TLB_FLUSH_ALL;
 		count_vm_tlb_event(NR_TLB_LOCAL_FLUSH_ALL);
@@ -227,10 +242,18 @@ void flush_tlb_page(struct vm_area_struct *vma, unsigned long start)
 	preempt_disable();
 
 	if (current->active_mm == mm) {
-		if (current->mm)
+		if (current->mm) {
+			/*
+			 * Implicit full barrier (INVLPG) that synchronizes
+			 * with switch_mm.
+			 */
 			__flush_tlb_one(start);
-		else
+		} else {
 			leave_mm(smp_processor_id());
+
+			/* Synchronize with switch_mm. */
+			smp_mb();
+		}
 	}
 
 	if (cpumask_any_but(mm_cpumask(mm), smp_processor_id()) < nr_cpu_ids)
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319912 — [PATCH 4.2.y-ckt 150/268] crypto: af_alg - Fix socket double-free when accept fails

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 150/268] crypto: af_alg - Fix socket double-free when accept fails
Message-ID<qVFP7-1mL-69@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit a383292c86663bbc31ac62cc0c04fc77504636a6 upstream.

When we fail an accept(2) call we will end up freeing the socket
twice, once due to the direct sk_free call and once again through
newsock.

This patch fixes this by removing the sk_free call.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/af_alg.c | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

diff --git a/crypto/af_alg.c b/crypto/af_alg.c
index 7b5b592..eaf98e2 100644
--- a/crypto/af_alg.c
+++ b/crypto/af_alg.c
@@ -285,10 +285,8 @@ int af_alg_accept(struct sock *sk, struct socket *newsock)
 	security_sk_clone(sk, sk2);
 
 	err = type->accept(ask->private, sk2);
-	if (err) {
-		sk_free(sk2);
+	if (err)
 		goto unlock;
-	}
 
 	sk2->sk_family = PF_ALG;
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319914 — [PATCH 4.2.y-ckt 156/268] crypto: algif_hash - Remove custom release parent function

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 156/268] crypto: algif_hash - Remove custom release parent function
Message-ID<qVFP7-1mL-73@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit f1d84af1835846a5a2b827382c5848faf2bb0e75 upstream.

This patch removes the custom release parent function as the
generic af_alg_release_parent now works for nokey sockets too.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/algif_hash.c | 43 +++----------------------------------------
 1 file changed, 3 insertions(+), 40 deletions(-)

diff --git a/crypto/algif_hash.c b/crypto/algif_hash.c
index 46637be..3653ab6 100644
--- a/crypto/algif_hash.c
+++ b/crypto/algif_hash.c
@@ -384,7 +384,7 @@ static int hash_setkey(void *private, const u8 *key, unsigned int keylen)
 	return err;
 }
 
-static void hash_sock_destruct_common(struct sock *sk)
+static void hash_sock_destruct(struct sock *sk)
 {
 	struct alg_sock *ask = alg_sk(sk);
 	struct hash_ctx *ctx = ask->private;
@@ -392,33 +392,10 @@ static void hash_sock_destruct_common(struct sock *sk)
 	sock_kzfree_s(sk, ctx->result,
 		      crypto_ahash_digestsize(crypto_ahash_reqtfm(&ctx->req)));
 	sock_kfree_s(sk, ctx, ctx->len);
-}
-
-static void hash_sock_destruct(struct sock *sk)
-{
-	hash_sock_destruct_common(sk);
-	af_alg_release_parent(sk);
-}
-
-static void hash_release_parent_nokey(struct sock *sk)
-{
-	struct alg_sock *ask = alg_sk(sk);
-
-	if (!ask->refcnt) {
-		sock_put(ask->parent);
-		return;
-	}
-
 	af_alg_release_parent(sk);
 }
 
-static void hash_sock_destruct_nokey(struct sock *sk)
-{
-	hash_sock_destruct_common(sk);
-	hash_release_parent_nokey(sk);
-}
-
-static int hash_accept_parent_common(void *private, struct sock *sk)
+static int hash_accept_parent_nokey(void *private, struct sock *sk)
 {
 	struct hash_ctx *ctx;
 	struct alg_sock *ask = alg_sk(sk);
@@ -461,21 +438,7 @@ static int hash_accept_parent(void *private, struct sock *sk)
 	if (!tfm->has_key && crypto_ahash_has_setkey(tfm->hash))
 		return -ENOKEY;
 
-	return hash_accept_parent_common(private, sk);
-}
-
-static int hash_accept_parent_nokey(void *private, struct sock *sk)
-{
-	int err;
-
-	err = hash_accept_parent_common(private, sk);
-	if (err)
-		goto out;
-
-	sk->sk_destruct = hash_sock_destruct_nokey;
-
-out:
-	return err;
+	return hash_accept_parent_nokey(private, sk);
 }
 
 static const struct af_alg_type algif_type_hash = {
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319915 — [PATCH 4.2.y-ckt 155/268] crypto: af_alg - Allow af_af_alg_release_parent to be called on nokey path

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 155/268] crypto: af_alg - Allow af_af_alg_release_parent to be called on nokey path
Message-ID<qVFP7-1mL-75@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit 6a935170a980024dd29199e9dbb5c4da4767a1b9 upstream.

This patch allows af_alg_release_parent to be called even for
nokey sockets.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/af_alg.c         | 9 ++++++++-
 include/crypto/if_alg.h | 1 +
 2 files changed, 9 insertions(+), 1 deletion(-)

diff --git a/crypto/af_alg.c b/crypto/af_alg.c
index 6566d2e..e7cb836 100644
--- a/crypto/af_alg.c
+++ b/crypto/af_alg.c
@@ -133,6 +133,12 @@ void af_alg_release_parent(struct sock *sk)
 	bool last;
 
 	sk = ask->parent;
+
+	if (ask->nokey_refcnt && !ask->refcnt) {
+		sock_put(sk);
+		return;
+	}
+
 	ask = alg_sk(sk);
 
 	lock_sock(sk);
@@ -268,8 +274,8 @@ int af_alg_accept(struct sock *sk, struct socket *newsock)
 	struct alg_sock *ask = alg_sk(sk);
 	const struct af_alg_type *type;
 	struct sock *sk2;
+	unsigned int nokey;
 	int err;
-	bool nokey;
 
 	lock_sock(sk);
 	type = ask->type;
@@ -302,6 +308,7 @@ int af_alg_accept(struct sock *sk, struct socket *newsock)
 		sock_hold(sk);
 	alg_sk(sk2)->parent = sk;
 	alg_sk(sk2)->type = type;
+	alg_sk(sk2)->nokey_refcnt = nokey;
 
 	newsock->ops = type->ops;
 	newsock->state = SS_CONNECTED;
diff --git a/include/crypto/if_alg.h b/include/crypto/if_alg.h
index df82844..a2bfd78 100644
--- a/include/crypto/if_alg.h
+++ b/include/crypto/if_alg.h
@@ -31,6 +31,7 @@ struct alg_sock {
 	struct sock *parent;
 
 	unsigned int refcnt;
+	unsigned int nokey_refcnt;
 
 	const struct af_alg_type *type;
 	void *private;
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1319916 — [PATCH 4.2.y-ckt 151/268] crypto: af_alg - Add nokey compatibility path

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-27 22:30 +0100
Subject[PATCH 4.2.y-ckt 151/268] crypto: af_alg - Add nokey compatibility path
Message-ID<qVFP8-1mL-77@gated-at.bofh.it>
In reply to#1319730
4.2.8-ckt3 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit 37766586c965d63758ad542325a96d5384f4a8c9 upstream.

This patch adds a compatibility path to support old applications
that do acept(2) before setkey.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/af_alg.c         | 13 ++++++++++++-
 include/crypto/if_alg.h |  2 ++
 2 files changed, 14 insertions(+), 1 deletion(-)

diff --git a/crypto/af_alg.c b/crypto/af_alg.c
index eaf98e2..6566d2e 100644
--- a/crypto/af_alg.c
+++ b/crypto/af_alg.c
@@ -76,6 +76,8 @@ int af_alg_register_type(const struct af_alg_type *type)
 		goto unlock;
 
 	type->ops->owner = THIS_MODULE;
+	if (type->ops_nokey)
+		type->ops_nokey->owner = THIS_MODULE;
 	node->type = type;
 	list_add(&node->list, &alg_types);
 	err = 0;
@@ -267,6 +269,7 @@ int af_alg_accept(struct sock *sk, struct socket *newsock)
 	const struct af_alg_type *type;
 	struct sock *sk2;
 	int err;
+	bool nokey;
 
 	lock_sock(sk);
 	type = ask->type;
@@ -285,12 +288,17 @@ int af_alg_accept(struct sock *sk, struct socket *newsock)
 	security_sk_clone(sk, sk2);
 
 	err = type->accept(ask->private, sk2);
+
+	nokey = err == -ENOKEY;
+	if (nokey && type->accept_nokey)
+		err = type->accept_nokey(ask->private, sk2);
+
 	if (err)
 		goto unlock;
 
 	sk2->sk_family = PF_ALG;
 
-	if (!ask->refcnt++)
+	if (nokey || !ask->refcnt++)
 		sock_hold(sk);
 	alg_sk(sk2)->parent = sk;
 	alg_sk(sk2)->type = type;
@@ -298,6 +306,9 @@ int af_alg_accept(struct sock *sk, struct socket *newsock)
 	newsock->ops = type->ops;
 	newsock->state = SS_CONNECTED;
 
+	if (nokey)
+		newsock->ops = type->ops_nokey;
+
 	err = 0;
 
 unlock:
diff --git a/include/crypto/if_alg.h b/include/crypto/if_alg.h
index 589716f..df82844 100644
--- a/include/crypto/if_alg.h
+++ b/include/crypto/if_alg.h
@@ -52,9 +52,11 @@ struct af_alg_type {
 	void (*release)(void *private);
 	int (*setkey)(void *private, const u8 *key, unsigned int keylen);
 	int (*accept)(void *private, struct sock *sk);
+	int (*accept_nokey)(void *private, struct sock *sk);
 	int (*setauthsize)(void *private, unsigned int authsize);
 
 	struct proto_ops *ops;
+	struct proto_ops *ops_nokey;
 	struct module *owner;
 	char name[14];
 };
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


Page 7 of 13 — ← Prev page 1 … 5 6 [7] 8 9 … 13  Next page →

Back to top | Article view | linux.kernel


csiph-web