Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1321181 > unrolled thread

[3.19.y-ckt stable] Linux 3.19.8-ckt14 stable review

Started byKamal Mostafa <kamal@canonical.com>
First post2016-01-29 02:20 +0100
Last post2016-01-29 03:40 +0100
Articles 20 on this page of 210 — 1 participant

Back to article view | Back to linux.kernel


Contents

  [3.19.y-ckt stable] Linux 3.19.8-ckt14 stable review Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:20 +0100
    [PATCH 3.19.y-ckt 174/210] vmstat: make vmstat_updater deferrable again and shut down on idle Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 201/210] batman-adv: Drop immediate batadv_neigh_node free function Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 210/210] xfrm: dst_entries_init() per-net dst_ops Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 052/210] rtlwifi: rtl8192ce: Fix handling of module parameters Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 121/210] memcg: only free spare array when readers are done Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 197/210] bridge: fix lockdep addr_list_lock false positive splat Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 208/210] xen-netfront: respect user provided max_queues Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 193/210] bonding: Prevent IPv6 link local address on enslaved devices Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 172/210] mmc: sd: limit SD card power limit according to cards capabilities Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 004/210] ovl: allow zero size xattr Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 134/210] ALSA: seq: Fix snd_seq_call_port_info_ioctl in compat mode Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 205/210] team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 009/210] tools lib traceevent: Fix output of %llu for 64 bit values read on 32 bit machines Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 057/210] bcache: Add a cond_resched() call to gc Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 060/210] bcache: unregister reboot notifier if bcache fails to unregister device Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 194/210] phonet: properly unshare skbs in phonet_rcv() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 203/210] batman-adv: Drop immediate batadv_hard_iface free function Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 046/210] rtlwifi: rtl8723be: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 161/210] mmc: sdhci: restore behavior when setting VDD via external regulator Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 098/210] scripts/recordmcount.pl: support data in text section on powerpc Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 071/210] drm/dp/mst: always send reply for UP request Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 198/210] batman-adv: Avoid recursive call_rcu for batadv_bla_claim Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 035/210] mmc: sdhci: Fix sdhci_runtime_pm_bus_on/off() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 111/210] cifs: fix race between call_async() and reconnect() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 165/210] perf/x86: Fix filter_events() bug with event mappings Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 206/210] sctp: Prevent soft lockup when sctp_accept() is called during a timeout event Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 192/210] net: preserve IP control block during GSO segmentation Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 200/210] batman-adv: Drop immediate batadv_orig_ifinfo free function Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 081/210] uml: flush stdout before forking Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 117/210] ALSA: timer: Harden slave timer list handling Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 022/210] EDAC: Robustify workqueues destruction Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 038/210] nfs: Fix race in __update_open_stateid() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 006/210] [media] vb2: fix a regression in poll() behavior for output,streams Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 114/210] dma-debug: switch check from _text to _stext Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 207/210] xen-netback: respect user provided max_queues Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 170/210] um: Fix build error and kconfig for i386 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 202/210] batman-adv: Drop immediate neigh_ifinfo free function Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 107/210] mmc: mmci: fix an ages old detection error Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 076/210] iwlwifi: update and fix 7265 series PCI IDs Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 196/210] ipv6: update skb->csum when CE mark is propagated Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 209/210] xen-netfront: update num_queues to real created Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 019/210] wlcore/wl12xx: spi: fix oops on firmware load Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 013/210] xhci: refuse loading if nousb is used Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 204/210] batman-adv: Drop immediate orig_node free function Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 054/210] NFS: Fix attribute cache revalidation Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 168/210] target: Fix a memory leak in target_dev_lba_map_store() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 133/210] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 190/210] tcp_yeah: don't set ssthresh below 2 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 159/210] ALSA: fm801: propagate TUNER_ONLY bit when autodetected Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 195/210] net: bpf: reject invalid shifts Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 199/210] batman-adv: Avoid recursive call_rcu for batadv_nc_node Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 147/210] MAINTAINERS: return arch/sh to maintained state, with new maintainers Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 012/210] drm/radeon: call hpd_irq_event on resume Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 103/210] x86/mm: Improve switch_mm() barrier comments Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 003/210] hotplugcpu: Avoid deadlocks by waking active_writer Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
    [PATCH 3.19.y-ckt 166/210] power: test_power: correctly handle empty writes Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 185/210] connector: bump skb->users before callback invocation Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 188/210] vxlan: fix test which detect duplicate vxlan iface Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 189/210] net: sctp: prevent writes to cookie_hmac_alg from accessing invalid memory Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 163/210] sysrq: Fix warning in sysrq generated crash. Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 164/210] kconfig: return 'false' instead of 'no' in bool function Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 160/210] pinctrl: bcm2835: Fix memory leak in error path Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 177/210] printk: help pr_debug and pr_devel to optimize out arguments Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 157/210] Revert "ACPI / LPSS: allow to use specific PM domain during ->probe()" Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 183/210] net: cdc_ncm: avoid changing RX/TX buffers on MTU changes Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 191/210] udp: disallow UFO for sockets with SO_NO_CHECK option Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 186/210] unix: properly account for FDs passed over unix sockets Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 176/210] btrfs: initialize the seq counter in struct btrfs_device Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 181/210] net/mlx4: Remove unused macro Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 171/210] kbuild: Demote 'sign-compare' warning to W=2 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 175/210] Btrfs: clean up an error code in btrfs_init_space_info() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 167/210] firmware: actually return NULL on failed request_firmware_nowait() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 184/210] sctp: sctp should release assoc when sctp_make_abort_user return NULL in sctp_close Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 158/210] mtd: nand: denali: add missing nand_release() call in denali_remove() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 187/210] bridge: Only call /sbin/bridge-stp for the initial network namespace Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 182/210] veth: don’t modify ip_summed; doing so treats packets with bad checksums as good. Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 178/210] ARM: dts: armadillo800eva Correct extal1 frequency to 24 MHz Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 162/210] x86/LDT: Print the real LDT base address Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 169/210] m68k/atari, m68k/sun3: Fix SCSI platform device registration when driver is modular Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 180/210] IB/mlx4: Initialize hop_limit when creating address handle Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 173/210] net: tcp_memcontrol: properly detect ancestor socket pressure Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 179/210] mmc: debugfs: correct wrong voltage value Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
    [PATCH 3.19.y-ckt 125/210] ALSA: hda - Fix bass pin fixup for ASUS N550JX Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 135/210] ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 122/210] panic: release stale console lock to always get the logbuf printed out Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 149/210] drm/i915: On fb alloc failure, unref gem object where it gets refed Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 153/210] clk: st: avoid uninitialized variable use Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 141/210] IB/qib: Support creating qps with GFP_NOIO flag Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 123/210] kernel/panic.c: turn off locks debug before releasing console lock Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 132/210] ALSA: hrtimer: Fix stall by hrtimer_cancel() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 130/210] crypto: af_alg - Allow af_af_alg_release_parent to be called on nokey path Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 151/210] SCSI: initio: remove duplicate module device table Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 129/210] crypto: hash - Add crypto_ahash_has_setkey Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 131/210] crypto: af_alg - Forbid bind(2) when nokey child sockets are present Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 156/210] mtd: nand: fix ONFI parameter page layout Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 145/210] ALSA: timer: Handle disconnection more safely Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 144/210] ALSA: hda - Flush the pending probe work at remove Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 124/210] printk: do cond_resched() between lines while outputting to consoles Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 142/210] ideapad-laptop: Add Lenovo ideapad Y700-17ISK to no_hw_rfkill dmi list Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 152/210] clk: xgene: Fix divider with non-zero shift value Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 136/210] ARM: debug-ll: fix BCM63xx entry for multiplatform Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 140/210] IB/qib: fix mcast detach when qp not attached Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 139/210] crypto: crc32c - Fix crc32c soft dependency Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 146/210] ocfs2: NFS hangs in __ocfs2_cluster_lock due to race with ocfs2_unblock_lock Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 150/210] [media] rc: allow rc modules to be loaded if rc-main is not a module Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 092/210] x86/reboot/quirks: Add iMac10,1 to pci_reboot_dmi_table[] Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 154/210] ASoC: Intel: pass correct parameter in sst_alloc_stream_mrfld() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 143/210] iscsi-target: Fix potential dead-lock during node acl delete Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 085/210] x86/mm: Add barriers and document switch_mm()-vs-flush synchronization Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 155/210] ath9k_htc: check for underflow in ath9k_htc_rx_msg() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 148/210] ideapad-laptop: Add Lenovo Yoga 700 to no_hw_rfkill dmi list Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 127/210] crypto: af_alg - Fix socket double-free when accept fails Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 137/210] xfs: log mount failures don't wait for buffers to be released Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 138/210] crypto: algif_skcipher - Load TX SG list after waiting Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
    [PATCH 3.19.y-ckt 108/210] ALSA: timer: Fix race among timer ioctls Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 093/210] ALSA: seq: Fix missing NULL check at remove_events ioctl Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 116/210] ocfs2/dlm: ignore cleaning the migration mle that is inuse Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 109/210] sparc64: fix incorrect sign extension in sys_sparc64_personality Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 105/210] dmaengine: dw: fix cyclic transfer setup Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 119/210] zram: try vmalloc() after kmalloc() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 112/210] cifs_dbg() outputs an uninitialized buffer in cifs_readdir() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 120/210] mm: soft-offline: check return value in second __get_any_page() call Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 102/210] drm/i915: intel_hpd_init(): Fix suspend/resume reprobing Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 096/210] virtio_balloon: fix race between migration and ballooning Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 104/210] ALSA: timer: Fix double unlink of active_list Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 113/210] m32r: fix m32104ut_defconfig build fail Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 115/210] scripts/bloat-o-meter: fix python3 syntax error Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 090/210] clocksource/drivers/vt8500: Increase the minimum delta Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 106/210] dmaengine: dw: fix cyclic transfer callbacks Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 094/210] ALSA: seq: Fix race at timer setup and close Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 128/210] crypto: af_alg - Add nokey compatibility path Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 095/210] virtio_balloon: fix race by fill and leak Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 086/210] x86/boot: Double BOOT_HEAP_SIZE to 64KB Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 101/210] ALSA: usb-audio: Fix mixer ctl regression of Native Instrument devices Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 097/210] parisc: Fix __ARCH_SI_PREAMBLE_SIZE Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 099/210] powerpc/module: Handle R_PPC64_ENTRY relocations Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 110/210] cifs: Ratelimit kernel log messages Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 100/210] ALSA: hda - fix the headset mic detection problem for a Dell laptop Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 091/210] Input: elantech - mark protocols v2 and v3 as semi-mt Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 118/210] zram/zcomp: use GFP_NOIO to allocate streams Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 126/210] crypto: af_alg - Disallow bind/setkey/... after accept(2) Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
    [PATCH 3.19.y-ckt 059/210] bcache: fix a leak in bch_cached_dev_run() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 084/210] ALSA: hda - Fixup inverted internal mic for Lenovo E50-80 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 069/210] udf: Check output buffer length when converting name to CS0 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 051/210] rtlwifi: rtl8192se: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 066/210] libxfs: pack the agfl header structure so XFS_AGFL_SIZE is correct Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 055/210] rtlwifi: rtl_pci: Fix kernel panic Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 073/210] drm/dp/mst: fix in RAD element access Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 067/210] x86/xen: don't reset vcpu_info on a cancelled suspend Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 056/210] bcache: fix a livelock when we cause a huge number of cache misses Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 078/210] ASoC: compress: Fix compress device direction check Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 063/210] bcache: Change refill_dirty() to always scan entire disk if necessary Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 065/210] Input: i8042 - add Fujitsu Lifebook U745 to the nomux list Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 074/210] PCI: Fix minimum allocation address overwrite Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 053/210] rtlwifi: rtl8192cu: Add missing parameter setup Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 050/210] rtlwifi: rtl8192de: Fix incorrect module parameter descriptions Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 045/210] posix-clock: Fix return code on the poll method's error path Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 089/210] xfs: handle dquot buffer readahead in log recovery correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 068/210] udf: Prevent buffer overrun with multi-byte characters Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 082/210] drm/nouveau/kms: take mode_config mutex in connector hotplug path Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 083/210] ALSA: usb: Add native DSD support for Oppo HA-1 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 075/210] PCI: host: Mark PCIe/PCI (MSI) IRQ cascade handlers as IRQF_NO_THREAD Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 087/210] s390: fix normalization bug in exception table sorting Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 058/210] bcache: clear BCACHE_DEV_UNLINK_DONE flag when attaching a backing device Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 079/210] dm snapshot: fix hung bios when copy error occurs Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 072/210] drm/dp/mst: fix in MSTB RAD initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 062/210] bcache: prevent crash on changing writeback_running Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 061/210] bcache: allows use of register in udev to avoid "device_busy" error. Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 064/210] wlcore/wl12xx: spi: fix NULL pointer dereference (Oops) Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 088/210] xfs: inode recovery readahead can race with inode buffer creation Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 070/210] drm/dp/mst: process broadcast messages correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 080/210] uml: fix hostfs mknod() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 077/210] locks: fix unlock when fcntl_setlk races with a close Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
    [PATCH 3.19.y-ckt 027/210] dm thin: fix race condition when destroying thin pool workqueue Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 048/210] rtlwifi: rtl8821ae: Fix errors in parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 037/210] [media] rc: sunxi-cir: Initialize the spinlock properly Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 030/210] arm64: kernel: enforce pmuserenr_el0 initialization and restore Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 020/210] ovl: check dentry positiveness in ovl_cleanup_whiteouts() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 017/210] Bluetooth: Add support of Toshiba Broadcom based devices Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 033/210] mmc: sdio: Fix invalid vdd in voltage switch power cycle Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 047/210] rtlwifi: rtl8723ae: Fix initialization of module parameters Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 042/210] Thermal: initialize thermal zone device correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 040/210] NFSv4: Don't perform cached access checks before we've OPENed the file Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 049/210] rtlwifi: rtl8188ee: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 044/210] Thermal: do thermal zone update after a cooling device registered Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 026/210] dm space map metadata: remove unused variable in brb_pop() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 043/210] Thermal: handle thermal zone device properly during system sleep Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 024/210] powerpc: Make value-returning atomics fully ordered Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 025/210] powerpc: Make {cmp}xchg* and their atomic_ versions fully ordered Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 014/210] arm64: Clear out any singlestep state on a ptrace detach operation Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 029/210] arm64: mdscr_el1: avoid exposing DCC to userspace Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 018/210] rtlwifi: fix memory leak for USB device Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 041/210] NFS: Ensure we revalidate attributes before using execute_ok() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 028/210] futex: Drop refcount if requeue_pi() acquired the rtmutex Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 036/210] udf: limit the maximum number of indirect extents in a row Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 021/210] EDAC, mc_sysfs: Fix freeing bus' name Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 039/210] USB: cp210x: add ID for ELV Marble Sound Board 1 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 032/210] drm/radeon: clean up fujitsu quirks Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 034/210] mmc: sdhci: Fix DMA descriptor with zero data length Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 031/210] drm/radeon: Fix off-by-one errors in radeon_vm_bo_set_addr Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 023/210] arm64: mm: ensure that the zero page is visible to the page table walker Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
    [PATCH 3.19.y-ckt 016/210] ovl: root: copy attr Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:30 +0100
    [PATCH 3.19.y-ckt 015/210] time: Avoid signed overflow in timekeeping_get_ns() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:30 +0100
    [PATCH 3.19.y-ckt 008/210] [media] media: dvb-core: Don't force CAN_INVERSION_AUTO in oneshot mode Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:30 +0100
    [PATCH 3.19.y-ckt 010/210] KVM: x86: expose MSR_TSC_AUX to userspace Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:30 +0100
    [PATCH 3.19.y-ckt 011/210] KVM: x86: correctly print #AC in traces Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:30 +0100
    [PATCH 3.19.y-ckt 007/210] [media] gspca: ov534/topro: prevent a division by 0 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:30 +0100
    [PATCH 3.19.y-ckt 002/210] drm/nouveau/nv46: Change mc subdev oclass from nv44 to nv4c Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:40 +0100
    [PATCH 3.19.y-ckt 005/210] ovl: use a minimal buffer in ovl_copy_xattr Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:40 +0100

Page 2 of 11 — ← Prev page 1 [2] 3 4 … 11  Next page →


#1321201 — [PATCH 3.19.y-ckt 098/210] scripts/recordmcount.pl: support data in text section on powerpc

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 098/210] scripts/recordmcount.pl: support data in text section on powerpc
Message-ID<qW62U-3zN-39@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Ulrich Weigand <ulrich.weigand@de.ibm.com>

commit 2e50c4bef77511b42cc226865d6bc568fa7f8769 upstream.

If a text section starts out with a data blob before the first
function start label, disassembly parsing doing in recordmcount.pl
gets confused on powerpc, leading to creation of corrupted module
objects.

This was not a problem so far since the compiler would never create
such text sections.  However, this has changed with a recent change
in GCC 6 to support distances of > 2GB between a function and its
assoicated TOC in the ELFv2 ABI, exposing this problem.

There is already code in recordmcount.pl to handle such data blobs
on the sparc64 platform.  This patch uses the same method to handle
those on powerpc as well.

Acked-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Ulrich Weigand <ulrich.weigand@de.ibm.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 scripts/recordmcount.pl | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/scripts/recordmcount.pl b/scripts/recordmcount.pl
index 537c38c..6a31427 100755
--- a/scripts/recordmcount.pl
+++ b/scripts/recordmcount.pl
@@ -258,7 +258,8 @@ if ($arch eq "x86_64") {
 
 } elsif ($arch eq "powerpc") {
     $local_regex = "^[0-9a-fA-F]+\\s+t\\s+(\\.?\\S+)";
-    $function_regex = "^([0-9a-fA-F]+)\\s+<(\\.?.*?)>:";
+    # See comment in the sparc64 section for why we use '\w'.
+    $function_regex = "^([0-9a-fA-F]+)\\s+<(\\.?\\w*?)>:";
     $mcount_regex = "^\\s*([0-9a-fA-F]+):.*\\s\\.?_mcount\$";
 
     if ($bits == 64) {
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321202 — [PATCH 3.19.y-ckt 071/210] drm/dp/mst: always send reply for UP request

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 071/210] drm/dp/mst: always send reply for UP request
Message-ID<qW62T-3zN-37@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Mykola Lysenko <Mykola.Lysenko@amd.com>

commit 1f16ee7fa13649f4e55aa48ad31c3eb0722a62d3 upstream.

We should always send reply for UP request in order
to make downstream device clean-up resources appropriately.

Issue was that reply for UP request was sent only once.

Acked-by: Dave Airlie <airlied@gmail.com>
Signed-off-by: Mykola Lysenko <Mykola.Lysenko@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/gpu/drm/drm_dp_mst_topology.c | 30 +++++++++++-------------------
 include/drm/drm_dp_mst_helper.h       |  2 --
 2 files changed, 11 insertions(+), 21 deletions(-)

diff --git a/drivers/gpu/drm/drm_dp_mst_topology.c b/drivers/gpu/drm/drm_dp_mst_topology.c
index 7105bea..9840074 100644
--- a/drivers/gpu/drm/drm_dp_mst_topology.c
+++ b/drivers/gpu/drm/drm_dp_mst_topology.c
@@ -1484,26 +1484,18 @@ static void process_single_down_tx_qlock(struct drm_dp_mst_topology_mgr *mgr)
 }
 
 /* called holding qlock */
-static void process_single_up_tx_qlock(struct drm_dp_mst_topology_mgr *mgr)
+static void process_single_up_tx_qlock(struct drm_dp_mst_topology_mgr *mgr,
+				       struct drm_dp_sideband_msg_tx *txmsg)
 {
-	struct drm_dp_sideband_msg_tx *txmsg;
 	int ret;
 
 	/* construct a chunk from the first msg in the tx_msg queue */
-	if (list_empty(&mgr->tx_msg_upq)) {
-		mgr->tx_up_in_progress = false;
-		return;
-	}
-
-	txmsg = list_first_entry(&mgr->tx_msg_upq, struct drm_dp_sideband_msg_tx, next);
 	ret = process_single_tx_qlock(mgr, txmsg, true);
-	if (ret == 1) {
-		/* up txmsgs aren't put in slots - so free after we send it */
-		list_del(&txmsg->next);
-		kfree(txmsg);
-	} else if (ret)
+
+	if (ret != 1)
 		DRM_DEBUG_KMS("failed to send msg in q %d\n", ret);
-	mgr->tx_up_in_progress = true;
+
+	txmsg->dst->tx_slots[txmsg->seqno] = NULL;
 }
 
 static void drm_dp_queue_down_tx(struct drm_dp_mst_topology_mgr *mgr,
@@ -1888,11 +1880,12 @@ static int drm_dp_send_up_ack_reply(struct drm_dp_mst_topology_mgr *mgr,
 	drm_dp_encode_up_ack_reply(txmsg, req_type);
 
 	mutex_lock(&mgr->qlock);
-	list_add_tail(&txmsg->next, &mgr->tx_msg_upq);
-	if (!mgr->tx_up_in_progress) {
-		process_single_up_tx_qlock(mgr);
-	}
+
+	process_single_up_tx_qlock(mgr, txmsg);
+
 	mutex_unlock(&mgr->qlock);
+
+	kfree(txmsg);
 	return 0;
 }
 
@@ -2779,7 +2772,6 @@ int drm_dp_mst_topology_mgr_init(struct drm_dp_mst_topology_mgr *mgr,
 	mutex_init(&mgr->qlock);
 	mutex_init(&mgr->payload_lock);
 	mutex_init(&mgr->destroy_connector_lock);
-	INIT_LIST_HEAD(&mgr->tx_msg_upq);
 	INIT_LIST_HEAD(&mgr->tx_msg_downq);
 	INIT_LIST_HEAD(&mgr->destroy_connector_list);
 	INIT_WORK(&mgr->work, drm_dp_mst_link_probe_work);
diff --git a/include/drm/drm_dp_mst_helper.h b/include/drm/drm_dp_mst_helper.h
index 50d6eb3..f5ffb74 100644
--- a/include/drm/drm_dp_mst_helper.h
+++ b/include/drm/drm_dp_mst_helper.h
@@ -449,9 +449,7 @@ struct drm_dp_mst_topology_mgr {
 	   the mstb tx_slots and txmsg->state once they are queued */
 	struct mutex qlock;
 	struct list_head tx_msg_downq;
-	struct list_head tx_msg_upq;
 	bool tx_down_in_progress;
-	bool tx_up_in_progress;
 
 	/* payload info + lock for it */
 	struct mutex payload_lock;
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321203 — [PATCH 3.19.y-ckt 198/210] batman-adv: Avoid recursive call_rcu for batadv_bla_claim

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 198/210] batman-adv: Avoid recursive call_rcu for batadv_bla_claim
Message-ID<qW62U-3zN-43@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Sven Eckelmann <sven@narfation.org>

[ Upstream commit 63b399272294e7a939cde41792dca38c549f0484 ]

The batadv_claim_free_ref function uses call_rcu to delay the free of the
batadv_bla_claim object until no (already started) rcu_read_lock is enabled
anymore. This makes sure that no context is still trying to access the
object which should be removed. But batadv_bla_claim also contains a
reference to backbone_gw which must be removed.

The reference drop of backbone_gw was done in the call_rcu function
batadv_claim_free_rcu but should actually be done in the
batadv_claim_release function to avoid nested call_rcus. This is important
because rcu_barrier (e.g. batadv_softif_free or batadv_exit) will not
detect the inner call_rcu as relevant for its execution. Otherwise this
barrier will most likely be inserted in the queue before the callback of
the first call_rcu was executed. The caller of rcu_barrier will therefore
continue to run before the inner call_rcu callback finished.

Fixes: 23721387c409 ("batman-adv: add basic bridge loop avoidance code")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Acked-by: Simon Wunderlich <sw@simonwunderlich.de>
Signed-off-by: Marek Lindner <mareklindner@neomailbox.ch>
Signed-off-by: Antonio Quartulli <a@unstable.cc>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/batman-adv/bridge_loop_avoidance.c | 10 +++-------
 1 file changed, 3 insertions(+), 7 deletions(-)

diff --git a/net/batman-adv/bridge_loop_avoidance.c b/net/batman-adv/bridge_loop_avoidance.c
index a957c81..90673ff 100644
--- a/net/batman-adv/bridge_loop_avoidance.c
+++ b/net/batman-adv/bridge_loop_avoidance.c
@@ -113,21 +113,17 @@ batadv_backbone_gw_free_ref(struct batadv_bla_backbone_gw *backbone_gw)
 }
 
 /* finally deinitialize the claim */
-static void batadv_claim_free_rcu(struct rcu_head *rcu)
+static void batadv_claim_release(struct batadv_bla_claim *claim)
 {
-	struct batadv_bla_claim *claim;
-
-	claim = container_of(rcu, struct batadv_bla_claim, rcu);
-
 	batadv_backbone_gw_free_ref(claim->backbone_gw);
-	kfree(claim);
+	kfree_rcu(claim, rcu);
 }
 
 /* free a claim, call claim_free_rcu if its the last reference */
 static void batadv_claim_free_ref(struct batadv_bla_claim *claim)
 {
 	if (atomic_dec_and_test(&claim->refcount))
-		call_rcu(&claim->rcu, batadv_claim_free_rcu);
+		batadv_claim_release(claim);
 }
 
 /**
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321204 — [PATCH 3.19.y-ckt 035/210] mmc: sdhci: Fix sdhci_runtime_pm_bus_on/off()

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 035/210] mmc: sdhci: Fix sdhci_runtime_pm_bus_on/off()
Message-ID<qW62U-3zN-47@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Adrian Hunter <adrian.hunter@intel.com>

commit 5c671c410c8704800f4f1673b6f572137e7e6ddd upstream.

sdhci has a legacy facility to prevent runtime suspend if the
bus power is on.  This is needed in cases where the power to
the card is dependent on the bus power.  It is controlled by
a pair of functions: sdhci_runtime_pm_bus_on() and
sdhci_runtime_pm_bus_off().  These functions use a boolean
variable 'bus_on' to ensure changes are always paired.
There is an additional check for 'runtime_suspended' which is
the problem.  In fact, its use is ill-conceived as the only
requirement for the logic is that 'on' and 'off' are paired,
which is actually broken by the check, for example if the bus
power is turned on during runtime resume.  So remove  the check.

Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/mmc/host/sdhci.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/mmc/host/sdhci.c b/drivers/mmc/host/sdhci.c
index 7cec488..f4a7abf 100644
--- a/drivers/mmc/host/sdhci.c
+++ b/drivers/mmc/host/sdhci.c
@@ -2743,7 +2743,7 @@ static int sdhci_runtime_pm_put(struct sdhci_host *host)
 
 static void sdhci_runtime_pm_bus_on(struct sdhci_host *host)
 {
-	if (host->runtime_suspended || host->bus_on)
+	if (host->bus_on)
 		return;
 	host->bus_on = true;
 	pm_runtime_get_noresume(host->mmc->parent);
@@ -2751,7 +2751,7 @@ static void sdhci_runtime_pm_bus_on(struct sdhci_host *host)
 
 static void sdhci_runtime_pm_bus_off(struct sdhci_host *host)
 {
-	if (host->runtime_suspended || !host->bus_on)
+	if (!host->bus_on)
 		return;
 	host->bus_on = false;
 	pm_runtime_put_noidle(host->mmc->parent);
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321205 — [PATCH 3.19.y-ckt 111/210] cifs: fix race between call_async() and reconnect()

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 111/210] cifs: fix race between call_async() and reconnect()
Message-ID<qW62U-3zN-51@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Rabin Vincent <rabin.vincent@axis.com>

commit 820962dc700598ffe8cd21b967e30e7520c34748 upstream.

cifs_call_async() queues the MID to the pending list and calls
smb_send_rqst().  If smb_send_rqst() performs a partial send, it sets
the tcpStatus to CifsNeedReconnect and returns an error code to
cifs_call_async().  In this case, cifs_call_async() removes the MID
from the list and returns to the caller.

However, cifs_call_async() releases the server mutex _before_ removing
the MID.  This means that a cifs_reconnect() can race with this function
and manage to remove the MID from the list and delete the entry before
cifs_call_async() calls cifs_delete_mid().  This leads to various
crashes due to the use after free in cifs_delete_mid().

Task1				Task2

cifs_call_async():
 - rc = -EAGAIN
 - mutex_unlock(srv_mutex)

				cifs_reconnect():
				 - mutex_lock(srv_mutex)
				 - mutex_unlock(srv_mutex)
				 - list_delete(mid)
				 - mid->callback()
				 	cifs_writev_callback():
				 		- mutex_lock(srv_mutex)
						- delete(mid)
				 		- mutex_unlock(srv_mutex)

 - cifs_delete_mid(mid) <---- use after free

Fix this by removing the MID in cifs_call_async() before releasing the
srv_mutex.  Also hold the srv_mutex in cifs_reconnect() until the MIDs
are moved out of the pending list.

Signed-off-by: Rabin Vincent <rabin.vincent@axis.com>
Acked-by: Shirish Pargaonkar <shirishpargaonkar@gmail.com>
Signed-off-by: Steve French <sfrench@localhost.localdomain>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/cifs/connect.c   | 2 +-
 fs/cifs/transport.c | 6 ++++--
 2 files changed, 5 insertions(+), 3 deletions(-)

diff --git a/fs/cifs/connect.c b/fs/cifs/connect.c
index 2a772da..82ebe7d 100644
--- a/fs/cifs/connect.c
+++ b/fs/cifs/connect.c
@@ -357,7 +357,6 @@ cifs_reconnect(struct TCP_Server_Info *server)
 	server->session_key.response = NULL;
 	server->session_key.len = 0;
 	server->lstrp = jiffies;
-	mutex_unlock(&server->srv_mutex);
 
 	/* mark submitted MIDs for retry and issue callback */
 	INIT_LIST_HEAD(&retry_list);
@@ -370,6 +369,7 @@ cifs_reconnect(struct TCP_Server_Info *server)
 		list_move(&mid_entry->qhead, &retry_list);
 	}
 	spin_unlock(&GlobalMid_Lock);
+	mutex_unlock(&server->srv_mutex);
 
 	cifs_dbg(FYI, "%s: issuing mid callbacks\n", __func__);
 	list_for_each_safe(tmp, tmp2, &retry_list) {
diff --git a/fs/cifs/transport.c b/fs/cifs/transport.c
index 126f46b..66106f6 100644
--- a/fs/cifs/transport.c
+++ b/fs/cifs/transport.c
@@ -576,14 +576,16 @@ cifs_call_async(struct TCP_Server_Info *server, struct smb_rqst *rqst,
 	cifs_in_send_dec(server);
 	cifs_save_when_sent(mid);
 
-	if (rc < 0)
+	if (rc < 0) {
 		server->sequence_number -= 2;
+		cifs_delete_mid(mid);
+	}
+
 	mutex_unlock(&server->srv_mutex);
 
 	if (rc == 0)
 		return 0;
 
-	cifs_delete_mid(mid);
 	add_credits_and_wake_if(server, credits, optype);
 	return rc;
 }
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321206 — [PATCH 3.19.y-ckt 165/210] perf/x86: Fix filter_events() bug with event mappings

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 165/210] perf/x86: Fix filter_events() bug with event mappings
Message-ID<qW62U-3zN-45@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Stephane Eranian <eranian@google.com>

commit 61b87cae6361ea6af161c1ffa549898892707b19 upstream.

This patch fixes a bug in the filter_events() function.

The patch fixes the bug whereby if some mappings did not
exist, e.g., STALLED_CYCLES_FRONTEND, then any event after it
in the attrs array would disappear from the published list of
events in /sys/devices/cpu/events. This could be verified
easily on any system post SNB (which do not publish
STALLED_CYCLES_FRONTEND):

	$ ./perf stat -e cycles,ref-cycles true
	Performance counter stats for 'true':
              1,217,348      cycles
	<not supported>      ref-cycles

The problem is that in filter_events() there is an assumption
that the argument (attrs) is organized in increasing continuous
event indexes related to the event_map(). But if we remove the
non-supported events by shifing the position in the array, then
the lookup x86_pmu.event_map() needs to compensate for it, otherwise
we are looking up the wrong index. This patch corrects this problem
by compensating for the deleted events and with that ref-cycles
reappears (here shown on Haswell):

	$ perf stat -e ref-cycles,cycles true
	Performance counter stats for 'true':
         4,525,910      ref-cycles
         1,064,920      cycles
       0.002943888 seconds time elapsed

Signed-off-by: Stephane Eranian <eranian@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Arnaldo Carvalho de Melo <acme@redhat.com>
Cc: Jiri Olsa <jolsa@redhat.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Vince Weaver <vincent.weaver@maine.edu>
Cc: jolsa@kernel.org
Cc: kan.liang@intel.com
Fixes: 8300daa26755 ("perf/x86: Filter out undefined events from sysfs events attribute")
Link: http://lkml.kernel.org/r/1449516805-6637-1-git-send-email-eranian@google.com
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/x86/kernel/cpu/perf_event.c | 11 ++++++++++-
 1 file changed, 10 insertions(+), 1 deletion(-)

diff --git a/arch/x86/kernel/cpu/perf_event.c b/arch/x86/kernel/cpu/perf_event.c
index 82adb1a..783cfc1 100644
--- a/arch/x86/kernel/cpu/perf_event.c
+++ b/arch/x86/kernel/cpu/perf_event.c
@@ -1388,6 +1388,7 @@ static void __init filter_events(struct attribute **attrs)
 {
 	struct device_attribute *d;
 	struct perf_pmu_events_attr *pmu_attr;
+	int offset = 0;
 	int i, j;
 
 	for (i = 0; attrs[i]; i++) {
@@ -1396,7 +1397,7 @@ static void __init filter_events(struct attribute **attrs)
 		/* str trumps id */
 		if (pmu_attr->event_str)
 			continue;
-		if (x86_pmu.event_map(i))
+		if (x86_pmu.event_map(i + offset))
 			continue;
 
 		for (j = i; attrs[j]; j++)
@@ -1404,6 +1405,14 @@ static void __init filter_events(struct attribute **attrs)
 
 		/* Check the shifted attr. */
 		i--;
+
+		/*
+		 * event_map() is index based, the attrs array is organized
+		 * by increasing event index. If we shift the events, then
+		 * we need to compensate for the event_map(), otherwise
+		 * we are looking up the wrong event in the map
+		 */
+		offset++;
 	}
 }
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321207 — [PATCH 3.19.y-ckt 206/210] sctp: Prevent soft lockup when sctp_accept() is called during a timeout event

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 206/210] sctp: Prevent soft lockup when sctp_accept() is called during a timeout event
Message-ID<qW62U-3zN-49@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Karl Heiss <kheiss@gmail.com>

[ Upstream commit 635682a14427d241bab7bbdeebb48a7d7b91638e ]

A case can occur when sctp_accept() is called by the user during
a heartbeat timeout event after the 4-way handshake.  Since
sctp_assoc_migrate() changes both assoc->base.sk and assoc->ep, the
bh_sock_lock in sctp_generate_heartbeat_event() will be taken with
the listening socket but released with the new association socket.
The result is a deadlock on any future attempts to take the listening
socket lock.

Note that this race can occur with other SCTP timeouts that take
the bh_lock_sock() in the event sctp_accept() is called.

 BUG: soft lockup - CPU#9 stuck for 67s! [swapper:0]
 ...
 RIP: 0010:[<ffffffff8152d48e>]  [<ffffffff8152d48e>] _spin_lock+0x1e/0x30
 RSP: 0018:ffff880028323b20  EFLAGS: 00000206
 RAX: 0000000000000002 RBX: ffff880028323b20 RCX: 0000000000000000
 RDX: 0000000000000000 RSI: ffff880028323be0 RDI: ffff8804632c4b48
 RBP: ffffffff8100bb93 R08: 0000000000000000 R09: 0000000000000000
 R10: ffff880610662280 R11: 0000000000000100 R12: ffff880028323aa0
 R13: ffff8804383c3880 R14: ffff880028323a90 R15: ffffffff81534225
 FS:  0000000000000000(0000) GS:ffff880028320000(0000) knlGS:0000000000000000
 CS:  0010 DS: 0018 ES: 0018 CR0: 000000008005003b
 CR2: 00000000006df528 CR3: 0000000001a85000 CR4: 00000000000006e0
 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
 DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
 Process swapper (pid: 0, threadinfo ffff880616b70000, task ffff880616b6cab0)
 Stack:
 ffff880028323c40 ffffffffa01c2582 ffff880614cfb020 0000000000000000
 <d> 0100000000000000 00000014383a6c44 ffff8804383c3880 ffff880614e93c00
 <d> ffff880614e93c00 0000000000000000 ffff8804632c4b00 ffff8804383c38b8
 Call Trace:
 <IRQ>
 [<ffffffffa01c2582>] ? sctp_rcv+0x492/0xa10 [sctp]
 [<ffffffff8148c559>] ? nf_iterate+0x69/0xb0
 [<ffffffff814974a0>] ? ip_local_deliver_finish+0x0/0x2d0
 [<ffffffff8148c716>] ? nf_hook_slow+0x76/0x120
 [<ffffffff814974a0>] ? ip_local_deliver_finish+0x0/0x2d0
 [<ffffffff8149757d>] ? ip_local_deliver_finish+0xdd/0x2d0
 [<ffffffff81497808>] ? ip_local_deliver+0x98/0xa0
 [<ffffffff81496ccd>] ? ip_rcv_finish+0x12d/0x440
 [<ffffffff81497255>] ? ip_rcv+0x275/0x350
 [<ffffffff8145cfeb>] ? __netif_receive_skb+0x4ab/0x750
 ...

With lockdep debugging:

 =====================================
 [ BUG: bad unlock balance detected! ]
 -------------------------------------
 CslRx/12087 is trying to release lock (slock-AF_INET) at:
 [<ffffffffa01bcae0>] sctp_generate_timeout_event+0x40/0xe0 [sctp]
 but there are no more locks to release!

 other info that might help us debug this:
 2 locks held by CslRx/12087:
 #0:  (&asoc->timers[i]){+.-...}, at: [<ffffffff8108ce1f>] run_timer_softirq+0x16f/0x3e0
 #1:  (slock-AF_INET){+.-...}, at: [<ffffffffa01bcac3>] sctp_generate_timeout_event+0x23/0xe0 [sctp]

Ensure the socket taken is also the same one that is released by
saving a copy of the socket before entering the timeout event
critical section.

Signed-off-by: Karl Heiss <kheiss@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/sctp/sm_sideeffect.c | 42 +++++++++++++++++++++++-------------------
 1 file changed, 23 insertions(+), 19 deletions(-)

diff --git a/net/sctp/sm_sideeffect.c b/net/sctp/sm_sideeffect.c
index 85e6f03..9366510 100644
--- a/net/sctp/sm_sideeffect.c
+++ b/net/sctp/sm_sideeffect.c
@@ -244,12 +244,13 @@ void sctp_generate_t3_rtx_event(unsigned long peer)
 	int error;
 	struct sctp_transport *transport = (struct sctp_transport *) peer;
 	struct sctp_association *asoc = transport->asoc;
-	struct net *net = sock_net(asoc->base.sk);
+	struct sock *sk = asoc->base.sk;
+	struct net *net = sock_net(sk);
 
 	/* Check whether a task is in the sock.  */
 
-	bh_lock_sock(asoc->base.sk);
-	if (sock_owned_by_user(asoc->base.sk)) {
+	bh_lock_sock(sk);
+	if (sock_owned_by_user(sk)) {
 		pr_debug("%s: sock is busy\n", __func__);
 
 		/* Try again later.  */
@@ -272,10 +273,10 @@ void sctp_generate_t3_rtx_event(unsigned long peer)
 			   transport, GFP_ATOMIC);
 
 	if (error)
-		asoc->base.sk->sk_err = -error;
+		sk->sk_err = -error;
 
 out_unlock:
-	bh_unlock_sock(asoc->base.sk);
+	bh_unlock_sock(sk);
 	sctp_transport_put(transport);
 }
 
@@ -285,11 +286,12 @@ out_unlock:
 static void sctp_generate_timeout_event(struct sctp_association *asoc,
 					sctp_event_timeout_t timeout_type)
 {
-	struct net *net = sock_net(asoc->base.sk);
+	struct sock *sk = asoc->base.sk;
+	struct net *net = sock_net(sk);
 	int error = 0;
 
-	bh_lock_sock(asoc->base.sk);
-	if (sock_owned_by_user(asoc->base.sk)) {
+	bh_lock_sock(sk);
+	if (sock_owned_by_user(sk)) {
 		pr_debug("%s: sock is busy: timer %d\n", __func__,
 			 timeout_type);
 
@@ -312,10 +314,10 @@ static void sctp_generate_timeout_event(struct sctp_association *asoc,
 			   (void *)timeout_type, GFP_ATOMIC);
 
 	if (error)
-		asoc->base.sk->sk_err = -error;
+		sk->sk_err = -error;
 
 out_unlock:
-	bh_unlock_sock(asoc->base.sk);
+	bh_unlock_sock(sk);
 	sctp_association_put(asoc);
 }
 
@@ -365,10 +367,11 @@ void sctp_generate_heartbeat_event(unsigned long data)
 	int error = 0;
 	struct sctp_transport *transport = (struct sctp_transport *) data;
 	struct sctp_association *asoc = transport->asoc;
-	struct net *net = sock_net(asoc->base.sk);
+	struct sock *sk = asoc->base.sk;
+	struct net *net = sock_net(sk);
 
-	bh_lock_sock(asoc->base.sk);
-	if (sock_owned_by_user(asoc->base.sk)) {
+	bh_lock_sock(sk);
+	if (sock_owned_by_user(sk)) {
 		pr_debug("%s: sock is busy\n", __func__);
 
 		/* Try again later.  */
@@ -389,10 +392,10 @@ void sctp_generate_heartbeat_event(unsigned long data)
 			   transport, GFP_ATOMIC);
 
 	 if (error)
-		 asoc->base.sk->sk_err = -error;
+		sk->sk_err = -error;
 
 out_unlock:
-	bh_unlock_sock(asoc->base.sk);
+	bh_unlock_sock(sk);
 	sctp_transport_put(transport);
 }
 
@@ -403,10 +406,11 @@ void sctp_generate_proto_unreach_event(unsigned long data)
 {
 	struct sctp_transport *transport = (struct sctp_transport *) data;
 	struct sctp_association *asoc = transport->asoc;
-	struct net *net = sock_net(asoc->base.sk);
+	struct sock *sk = asoc->base.sk;
+	struct net *net = sock_net(sk);
 
-	bh_lock_sock(asoc->base.sk);
-	if (sock_owned_by_user(asoc->base.sk)) {
+	bh_lock_sock(sk);
+	if (sock_owned_by_user(sk)) {
 		pr_debug("%s: sock is busy\n", __func__);
 
 		/* Try again later.  */
@@ -427,7 +431,7 @@ void sctp_generate_proto_unreach_event(unsigned long data)
 		   asoc->state, asoc->ep, asoc, transport, GFP_ATOMIC);
 
 out_unlock:
-	bh_unlock_sock(asoc->base.sk);
+	bh_unlock_sock(sk);
 	sctp_association_put(asoc);
 }
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321208 — [PATCH 3.19.y-ckt 192/210] net: preserve IP control block during GSO segmentation

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 192/210] net: preserve IP control block during GSO segmentation
Message-ID<qW62U-3zN-53@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Konstantin Khlebnikov <koct9i@gmail.com>

[ Upstream commit 9207f9d45b0ad071baa128e846d7e7ed85016df3 ]

Skb_gso_segment() uses skb control block during segmentation.
This patch adds 32-bytes room for previous control block which
will be copied into all resulting segments.

This patch fixes kernel crash during fragmenting forwarded packets.
Fragmentation requires valid IP CB in skb for clearing ip options.
Also patch removes custom save/restore in ovs code, now it's redundant.

Signed-off-by: Konstantin Khlebnikov <koct9i@gmail.com>
Link: http://lkml.kernel.org/r/CALYGNiP-0MZ-FExV2HutTvE9U-QQtkKSoE--KN=JQE5STYsjAA@mail.gmail.com
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 include/linux/skbuff.h     | 3 ++-
 net/core/dev.c             | 5 +++++
 net/ipv4/ip_output.c       | 1 +
 net/openvswitch/datapath.c | 5 +----
 net/xfrm/xfrm_output.c     | 2 ++
 5 files changed, 11 insertions(+), 5 deletions(-)

diff --git a/include/linux/skbuff.h b/include/linux/skbuff.h
index b0e064e..85b1df30 100644
--- a/include/linux/skbuff.h
+++ b/include/linux/skbuff.h
@@ -3271,7 +3271,8 @@ struct skb_gso_cb {
 	int	encap_level;
 	__u16	csum_start;
 };
-#define SKB_GSO_CB(skb) ((struct skb_gso_cb *)(skb)->cb)
+#define SKB_SGO_CB_OFFSET	32
+#define SKB_GSO_CB(skb) ((struct skb_gso_cb *)((skb)->cb + SKB_SGO_CB_OFFSET))
 
 static inline int skb_tnl_header_len(const struct sk_buff *inner_skb)
 {
diff --git a/net/core/dev.c b/net/core/dev.c
index 9c14e87..a0d1188 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -2422,6 +2422,8 @@ static inline bool skb_needs_check(struct sk_buff *skb, bool tx_path)
  *
  *	It may return NULL if the skb requires no segmentation.  This is
  *	only possible when GSO is used for verifying header integrity.
+ *
+ *	Segmentation preserves SKB_SGO_CB_OFFSET bytes of previous skb cb.
  */
 struct sk_buff *__skb_gso_segment(struct sk_buff *skb,
 				  netdev_features_t features, bool tx_path)
@@ -2436,6 +2438,9 @@ struct sk_buff *__skb_gso_segment(struct sk_buff *skb,
 			return ERR_PTR(err);
 	}
 
+	BUILD_BUG_ON(SKB_SGO_CB_OFFSET +
+		     sizeof(*SKB_GSO_CB(skb)) > sizeof(skb->cb));
+
 	SKB_GSO_CB(skb)->mac_offset = skb_headroom(skb);
 	SKB_GSO_CB(skb)->encap_level = 0;
 
diff --git a/net/ipv4/ip_output.c b/net/ipv4/ip_output.c
index b70d9ae..4c8d4d5f 100644
--- a/net/ipv4/ip_output.c
+++ b/net/ipv4/ip_output.c
@@ -230,6 +230,7 @@ static int ip_finish_output_gso(struct sk_buff *skb)
 	 * from host network stack.
 	 */
 	features = netif_skb_features(skb);
+	BUILD_BUG_ON(sizeof(*IPCB(skb)) > SKB_SGO_CB_OFFSET);
 	segs = skb_gso_segment(skb, features & ~NETIF_F_GSO_MASK);
 	if (IS_ERR_OR_NULL(segs)) {
 		kfree_skb(skb);
diff --git a/net/openvswitch/datapath.c b/net/openvswitch/datapath.c
index 34d2643..23cea2a 100644
--- a/net/openvswitch/datapath.c
+++ b/net/openvswitch/datapath.c
@@ -336,12 +336,10 @@ static int queue_gso_packets(struct datapath *dp, struct sk_buff *skb,
 	unsigned short gso_type = skb_shinfo(skb)->gso_type;
 	struct sw_flow_key later_key;
 	struct sk_buff *segs, *nskb;
-	struct ovs_skb_cb ovs_cb;
 	int err;
 
-	ovs_cb = *OVS_CB(skb);
+	BUILD_BUG_ON(sizeof(*OVS_CB(skb)) > SKB_SGO_CB_OFFSET);
 	segs = __skb_gso_segment(skb, NETIF_F_SG, false);
-	*OVS_CB(skb) = ovs_cb;
 	if (IS_ERR(segs))
 		return PTR_ERR(segs);
 	if (segs == NULL)
@@ -359,7 +357,6 @@ static int queue_gso_packets(struct datapath *dp, struct sk_buff *skb,
 	/* Queue all of the segments. */
 	skb = segs;
 	do {
-		*OVS_CB(skb) = ovs_cb;
 		if (gso_type & SKB_GSO_UDP && skb != segs)
 			key = &later_key;
 
diff --git a/net/xfrm/xfrm_output.c b/net/xfrm/xfrm_output.c
index 7c53285..55f18c5 100644
--- a/net/xfrm/xfrm_output.c
+++ b/net/xfrm/xfrm_output.c
@@ -153,6 +153,8 @@ static int xfrm_output_gso(struct sk_buff *skb)
 {
 	struct sk_buff *segs;
 
+	BUILD_BUG_ON(sizeof(*IPCB(skb)) > SKB_SGO_CB_OFFSET);
+	BUILD_BUG_ON(sizeof(*IP6CB(skb)) > SKB_SGO_CB_OFFSET);
 	segs = skb_gso_segment(skb, 0);
 	kfree_skb(skb);
 	if (IS_ERR(segs))
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321209 — [PATCH 3.19.y-ckt 200/210] batman-adv: Drop immediate batadv_orig_ifinfo free function

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 200/210] batman-adv: Drop immediate batadv_orig_ifinfo free function
Message-ID<qW62U-3zN-55@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Sven Eckelmann <sven@narfation.org>

[ Upstream commit deed96605f5695cb945e0b3d79429581857a2b9d ]

It is not allowed to free the memory of an object which is part of a list
which is protected by rcu-read-side-critical sections without making sure
that no other context is accessing the object anymore. This usually happens
by removing the references to this object and then waiting until the rcu
grace period is over and no one (allowedly) accesses it anymore.

But the _now functions ignore this completely. They free the object
directly even when a different context still tries to access it. This has
to be avoided and thus these functions must be removed and all functions
have to use batadv_orig_ifinfo_free_ref.

Fixes: 7351a4822d42 ("batman-adv: split out router from orig_node")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Marek Lindner <mareklindner@neomailbox.ch>
Signed-off-by: Antonio Quartulli <a@unstable.cc>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/batman-adv/originator.c | 59 ++++++++++++++++++++++++---------------------
 1 file changed, 31 insertions(+), 28 deletions(-)

diff --git a/net/batman-adv/originator.c b/net/batman-adv/originator.c
index bea8198..751f769 100644
--- a/net/batman-adv/originator.c
+++ b/net/batman-adv/originator.c
@@ -516,76 +516,79 @@ static void batadv_orig_ifinfo_free_rcu(struct rcu_head *rcu)
 }
 
 /**
- * batadv_orig_ifinfo_free_ref - decrement the refcounter and possibly free
- *  the orig_ifinfo (without rcu callback)
+ * batadv_orig_ifinfo_free_ref - decrement the refcounter and possibly release
+ *  the orig_ifinfo
  * @orig_ifinfo: the orig_ifinfo object to release
  */
-static void
-batadv_orig_ifinfo_free_ref_now(struct batadv_orig_ifinfo *orig_ifinfo)
+void batadv_orig_ifinfo_free_ref(struct batadv_orig_ifinfo *orig_ifinfo)
 {
 	if (atomic_dec_and_test(&orig_ifinfo->refcount))
-		batadv_orig_ifinfo_free_rcu(&orig_ifinfo->rcu);
+		call_rcu(&orig_ifinfo->rcu, batadv_orig_ifinfo_free_rcu);
 }
 
 /**
- * batadv_orig_ifinfo_free_ref - decrement the refcounter and possibly free
- *  the orig_ifinfo
- * @orig_ifinfo: the orig_ifinfo object to release
+ * batadv_orig_node_free_rcu - free the orig_node
+ * @rcu: rcu pointer of the orig_node
  */
-void batadv_orig_ifinfo_free_ref(struct batadv_orig_ifinfo *orig_ifinfo)
+static void batadv_orig_node_free_rcu(struct rcu_head *rcu)
 {
-	if (atomic_dec_and_test(&orig_ifinfo->refcount))
-		call_rcu(&orig_ifinfo->rcu, batadv_orig_ifinfo_free_rcu);
+	struct batadv_orig_node *orig_node;
+
+	orig_node = container_of(rcu, struct batadv_orig_node, rcu);
+
+	batadv_mcast_purge_orig(orig_node);
+
+	batadv_frag_purge_orig(orig_node, NULL);
+
+	if (orig_node->bat_priv->bat_algo_ops->bat_orig_free)
+		orig_node->bat_priv->bat_algo_ops->bat_orig_free(orig_node);
+
+	kfree(orig_node->tt_buff);
+	kfree(orig_node);
 }
 
-static void batadv_orig_node_free_rcu(struct rcu_head *rcu)
+/**
+ * batadv_orig_node_release - release orig_node from lists and queue for
+ *  free after rcu grace period
+ * @orig_node: the orig node to free
+ */
+static void batadv_orig_node_release(struct batadv_orig_node *orig_node)
 {
 	struct hlist_node *node_tmp;
 	struct batadv_neigh_node *neigh_node;
-	struct batadv_orig_node *orig_node;
 	struct batadv_orig_ifinfo *orig_ifinfo;
 
-	orig_node = container_of(rcu, struct batadv_orig_node, rcu);
-
 	spin_lock_bh(&orig_node->neigh_list_lock);
 
 	/* for all neighbors towards this originator ... */
 	hlist_for_each_entry_safe(neigh_node, node_tmp,
 				  &orig_node->neigh_list, list) {
 		hlist_del_rcu(&neigh_node->list);
-		batadv_neigh_node_free_ref_now(neigh_node);
+		batadv_neigh_node_free_ref(neigh_node);
 	}
 
 	hlist_for_each_entry_safe(orig_ifinfo, node_tmp,
 				  &orig_node->ifinfo_list, list) {
 		hlist_del_rcu(&orig_ifinfo->list);
-		batadv_orig_ifinfo_free_ref_now(orig_ifinfo);
+		batadv_orig_ifinfo_free_ref(orig_ifinfo);
 	}
 	spin_unlock_bh(&orig_node->neigh_list_lock);
 
-	batadv_mcast_purge_orig(orig_node);
-
 	/* Free nc_nodes */
 	batadv_nc_purge_orig(orig_node->bat_priv, orig_node, NULL);
 
-	batadv_frag_purge_orig(orig_node, NULL);
-
-	if (orig_node->bat_priv->bat_algo_ops->bat_orig_free)
-		orig_node->bat_priv->bat_algo_ops->bat_orig_free(orig_node);
-
-	kfree(orig_node->tt_buff);
-	kfree(orig_node);
+	call_rcu(&orig_node->rcu, batadv_orig_node_free_rcu);
 }
 
 /**
  * batadv_orig_node_free_ref - decrement the orig node refcounter and possibly
- * schedule an rcu callback for freeing it
+ *  release it
  * @orig_node: the orig node to free
  */
 void batadv_orig_node_free_ref(struct batadv_orig_node *orig_node)
 {
 	if (atomic_dec_and_test(&orig_node->refcount))
-		call_rcu(&orig_node->rcu, batadv_orig_node_free_rcu);
+		batadv_orig_node_release(orig_node);
 }
 
 /**
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321210 — [PATCH 3.19.y-ckt 081/210] uml: flush stdout before forking

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 081/210] uml: flush stdout before forking
Message-ID<qW62U-3zN-59@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Vegard Nossum <vegard.nossum@oracle.com>

commit 0754fb298f2f2719f0393491d010d46cfb25d043 upstream.

I was seeing some really weird behaviour where piping UML's output
somewhere would cause output to get duplicated:

  $ ./vmlinux | head -n 40
  Checking that ptrace can change system call numbers...Core dump limits :
          soft - 0
          hard - NONE
  OK
  Checking syscall emulation patch for ptrace...Core dump limits :
          soft - 0
          hard - NONE
  OK
  Checking advanced syscall emulation patch for ptrace...Core dump limits :
          soft - 0
          hard - NONE
  OK
  Core dump limits :
          soft - 0
          hard - NONE

This is because these tests do a fork() which duplicates the non-empty
stdout buffer, then glibc flushes the duplicated buffer as each child
exits.

A simple workaround is to flush before forking.

Signed-off-by: Vegard Nossum <vegard.nossum@oracle.com>
Signed-off-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/um/os-Linux/start_up.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/arch/um/os-Linux/start_up.c b/arch/um/os-Linux/start_up.c
index 337518c..b412c62 100644
--- a/arch/um/os-Linux/start_up.c
+++ b/arch/um/os-Linux/start_up.c
@@ -95,6 +95,8 @@ static int start_ptraced_child(void)
 {
 	int pid, n, status;
 
+	fflush(stdout);
+
 	pid = fork();
 	if (pid == 0)
 		ptrace_child();
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321211 — [PATCH 3.19.y-ckt 117/210] ALSA: timer: Harden slave timer list handling

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 117/210] ALSA: timer: Harden slave timer list handling
Message-ID<qW62U-3zN-61@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit b5a663aa426f4884c71cd8580adae73f33570f0d upstream.

A slave timer instance might be still accessible in a racy way while
operating the master instance as it lacks of locking.  Since the
master operation is mostly protected with timer->lock, we should cope
with it while changing the slave instance, too.  Also, some linked
lists (active_list and ack_list) of slave instances aren't unlinked
immediately at stopping or closing, and this may lead to unexpected
accesses.

This patch tries to address these issues.  It adds spin lock of
timer->lock (either from master or slave, which is equivalent) in a
few places.  For avoiding a deadlock, we ensure that the global
slave_active_lock is always locked at first before each timer lock.

Also, ack and active_list of slave instances are properly unlinked at
snd_timer_stop() and snd_timer_close().

Last but not least, remove the superfluous call of _snd_timer_stop()
at removing slave links.  This is a noop, and calling it may confuse
readers wrt locking.  Further cleanup will follow in a later patch.

Actually we've got reports of use-after-free by syzkaller fuzzer, and
this hopefully fixes these issues.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/core/timer.c | 18 ++++++++++++++----
 1 file changed, 14 insertions(+), 4 deletions(-)

diff --git a/sound/core/timer.c b/sound/core/timer.c
index 79fd8a1..8eaffb5 100644
--- a/sound/core/timer.c
+++ b/sound/core/timer.c
@@ -215,11 +215,13 @@ static void snd_timer_check_master(struct snd_timer_instance *master)
 		    slave->slave_id == master->slave_id) {
 			list_move_tail(&slave->open_list, &master->slave_list_head);
 			spin_lock_irq(&slave_active_lock);
+			spin_lock(&master->timer->lock);
 			slave->master = master;
 			slave->timer = master->timer;
 			if (slave->flags & SNDRV_TIMER_IFLG_RUNNING)
 				list_add_tail(&slave->active_list,
 					      &master->slave_active_head);
+			spin_unlock(&master->timer->lock);
 			spin_unlock_irq(&slave_active_lock);
 		}
 	}
@@ -346,15 +348,18 @@ int snd_timer_close(struct snd_timer_instance *timeri)
 		    timer->hw.close)
 			timer->hw.close(timer);
 		/* remove slave links */
+		spin_lock_irq(&slave_active_lock);
+		spin_lock(&timer->lock);
 		list_for_each_entry_safe(slave, tmp, &timeri->slave_list_head,
 					 open_list) {
-			spin_lock_irq(&slave_active_lock);
-			_snd_timer_stop(slave, 1, SNDRV_TIMER_EVENT_RESOLUTION);
 			list_move_tail(&slave->open_list, &snd_timer_slave_list);
 			slave->master = NULL;
 			slave->timer = NULL;
-			spin_unlock_irq(&slave_active_lock);
+			list_del_init(&slave->ack_list);
+			list_del_init(&slave->active_list);
 		}
+		spin_unlock(&timer->lock);
+		spin_unlock_irq(&slave_active_lock);
 		mutex_unlock(&register_mutex);
 	}
  out:
@@ -441,9 +446,12 @@ static int snd_timer_start_slave(struct snd_timer_instance *timeri)
 
 	spin_lock_irqsave(&slave_active_lock, flags);
 	timeri->flags |= SNDRV_TIMER_IFLG_RUNNING;
-	if (timeri->master)
+	if (timeri->master && timeri->timer) {
+		spin_lock(&timeri->timer->lock);
 		list_add_tail(&timeri->active_list,
 			      &timeri->master->slave_active_head);
+		spin_unlock(&timeri->timer->lock);
+	}
 	spin_unlock_irqrestore(&slave_active_lock, flags);
 	return 1; /* delayed start */
 }
@@ -489,6 +497,8 @@ static int _snd_timer_stop(struct snd_timer_instance * timeri,
 		if (!keep_flag) {
 			spin_lock_irqsave(&slave_active_lock, flags);
 			timeri->flags &= ~SNDRV_TIMER_IFLG_RUNNING;
+			list_del_init(&timeri->ack_list);
+			list_del_init(&timeri->active_list);
 			spin_unlock_irqrestore(&slave_active_lock, flags);
 		}
 		goto __end;
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321212 — [PATCH 3.19.y-ckt 022/210] EDAC: Robustify workqueues destruction

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 022/210] EDAC: Robustify workqueues destruction
Message-ID<qW62U-3zN-57@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Borislav Petkov <bp@suse.de>

commit fcd5c4dd8201595d4c598c9cca5e54760277d687 upstream.

EDAC workqueue destruction is really fragile. We cancel delayed work
but if it is still running and requeues itself, we still go ahead and
destroy the workqueue and the queued work explodes when workqueue core
attempts to run it.

Make the destruction more robust by switching op_state to offline so
that requeuing stops. Cancel any pending work *synchronously* too.

  EDAC i7core: Driver loaded.
  general protection fault: 0000 [#1] SMP
  CPU 12
  Modules linked in:
  Supported: Yes
  Pid: 0, comm: kworker/0:1 Tainted: G          IE   3.0.101-0-default #1 HP ProLiant DL380 G7
  RIP: 0010:[<ffffffff8107dcd7>]  [<ffffffff8107dcd7>] __queue_work+0x17/0x3f0
  < ... regs ...>
  Process kworker/0:1 (pid: 0, threadinfo ffff88019def6000, task ffff88019def4600)
  Stack:
   ...
  Call Trace:
   call_timer_fn
   run_timer_softirq
   __do_softirq
   call_softirq
   do_softirq
   irq_exit
   smp_apic_timer_interrupt
   apic_timer_interrupt
   intel_idle
   cpuidle_idle_call
   cpu_idle
  Code: ...
  RIP  __queue_work
   RSP <...>

Signed-off-by: Borislav Petkov <bp@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/edac/edac_device.c | 11 ++++-------
 drivers/edac/edac_mc.c     | 14 +++-----------
 drivers/edac/edac_pci.c    |  9 ++++-----
 3 files changed, 11 insertions(+), 23 deletions(-)

diff --git a/drivers/edac/edac_device.c b/drivers/edac/edac_device.c
index 592af5f..5358737 100644
--- a/drivers/edac/edac_device.c
+++ b/drivers/edac/edac_device.c
@@ -435,16 +435,13 @@ void edac_device_workq_setup(struct edac_device_ctl_info *edac_dev,
  */
 void edac_device_workq_teardown(struct edac_device_ctl_info *edac_dev)
 {
-	int status;
-
 	if (!edac_dev->edac_check)
 		return;
 
-	status = cancel_delayed_work(&edac_dev->work);
-	if (status == 0) {
-		/* workq instance might be running, wait for it */
-		flush_workqueue(edac_workqueue);
-	}
+	edac_dev->op_state = OP_OFFLINE;
+
+	cancel_delayed_work_sync(&edac_dev->work);
+	flush_workqueue(edac_workqueue);
 }
 
 /*
diff --git a/drivers/edac/edac_mc.c b/drivers/edac/edac_mc.c
index 1747906..a65656c 100644
--- a/drivers/edac/edac_mc.c
+++ b/drivers/edac/edac_mc.c
@@ -581,18 +581,10 @@ static void edac_mc_workq_setup(struct mem_ctl_info *mci, unsigned msec,
  */
 static void edac_mc_workq_teardown(struct mem_ctl_info *mci)
 {
-	int status;
-
-	if (mci->op_state != OP_RUNNING_POLL)
-		return;
-
-	status = cancel_delayed_work(&mci->work);
-	if (status == 0) {
-		edac_dbg(0, "not canceled, flush the queue\n");
+	mci->op_state = OP_OFFLINE;
 
-		/* workq instance might be running, wait for it */
-		flush_workqueue(edac_workqueue);
-	}
+	cancel_delayed_work_sync(&mci->work);
+	flush_workqueue(edac_workqueue);
 }
 
 /*
diff --git a/drivers/edac/edac_pci.c b/drivers/edac/edac_pci.c
index 2cf44b4d..b4b3860 100644
--- a/drivers/edac/edac_pci.c
+++ b/drivers/edac/edac_pci.c
@@ -274,13 +274,12 @@ static void edac_pci_workq_setup(struct edac_pci_ctl_info *pci,
  */
 static void edac_pci_workq_teardown(struct edac_pci_ctl_info *pci)
 {
-	int status;
-
 	edac_dbg(0, "\n");
 
-	status = cancel_delayed_work(&pci->work);
-	if (status == 0)
-		flush_workqueue(edac_workqueue);
+	pci->op_state = OP_OFFLINE;
+
+	cancel_delayed_work_sync(&pci->work);
+	flush_workqueue(edac_workqueue);
 }
 
 /*
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321213 — [PATCH 3.19.y-ckt 038/210] nfs: Fix race in __update_open_stateid()

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 038/210] nfs: Fix race in __update_open_stateid()
Message-ID<qW62V-3zN-65@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Andrew Elble <aweits@rit.edu>

commit 361cad3c89070aeb37560860ea8bfc092d545adc upstream.

We've seen this in a packet capture - I've intermixed what I
think was going on. The fix here is to grab the so_lock sooner.

1964379 -> #1 open (for write) reply seqid=1
1964393 -> #2 open (for read) reply seqid=2

  __nfs4_close(), state->n_wronly--
  nfs4_state_set_mode_locked(), changes state->state = [R]
  state->flags is [RW]
  state->state is [R], state->n_wronly == 0, state->n_rdonly == 1

1964398 -> #3 open (for write) call -> because close is already running
1964399 -> downgrade (to read) call seqid=2 (close of #1)
1964402 -> #3 open (for write) reply seqid=3

 __update_open_stateid()
   nfs_set_open_stateid_locked(), changes state->flags
   state->flags is [RW]
   state->state is [R], state->n_wronly == 0, state->n_rdonly == 1
   new sequence number is exposed now via nfs4_stateid_copy()

   next step would be update_open_stateflags(), pending so_lock

1964403 -> downgrade reply seqid=2, fails with OLD_STATEID (close of #1)

   nfs4_close_prepare() gets so_lock and recalcs flags -> send close

1964405 -> downgrade (to read) call seqid=3 (close of #1 retry)

   __update_open_stateid() gets so_lock
 * update_open_stateflags() updates state->n_wronly.
   nfs4_state_set_mode_locked() updates state->state

   state->flags is [RW]
   state->state is [RW], state->n_wronly == 1, state->n_rdonly == 1

 * should have suppressed the preceding nfs4_close_prepare() from
   sending open_downgrade

1964406 -> write call
1964408 -> downgrade (to read) reply seqid=4 (close of #1 retry)

   nfs_clear_open_stateid_locked()
   state->flags is [R]
   state->state is [RW], state->n_wronly == 1, state->n_rdonly == 1

1964409 -> write reply (fails, openmode)

Signed-off-by: Andrew Elble <aweits@rit.edu>
Signed-off-by: Trond Myklebust <trond.myklebust@primarydata.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/nfs/nfs4proc.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/nfs/nfs4proc.c b/fs/nfs/nfs4proc.c
index 6849230..d05e5f3 100644
--- a/fs/nfs/nfs4proc.c
+++ b/fs/nfs/nfs4proc.c
@@ -1226,6 +1226,7 @@ static void __update_open_stateid(struct nfs4_state *state, nfs4_stateid *open_s
 	 * Protect the call to nfs4_state_set_mode_locked and
 	 * serialise the stateid update
 	 */
+	spin_lock(&state->owner->so_lock);
 	write_seqlock(&state->seqlock);
 	if (deleg_stateid != NULL) {
 		nfs4_stateid_copy(&state->stateid, deleg_stateid);
@@ -1234,7 +1235,6 @@ static void __update_open_stateid(struct nfs4_state *state, nfs4_stateid *open_s
 	if (open_stateid != NULL)
 		nfs_set_open_stateid_locked(state, open_stateid, fmode);
 	write_sequnlock(&state->seqlock);
-	spin_lock(&state->owner->so_lock);
 	update_open_stateflags(state, fmode);
 	spin_unlock(&state->owner->so_lock);
 }
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321214 — [PATCH 3.19.y-ckt 006/210] [media] vb2: fix a regression in poll() behavior for output,streams

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 006/210] [media] vb2: fix a regression in poll() behavior for output,streams
Message-ID<qW62V-3zN-67@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Hans Verkuil <hverkuil@xs4all.nl>

commit 4623e5967448444a4ea1e77beb58898c4af48693 upstream.

In the 3.17 kernel the poll() behavior changed for output streams:
as long as not all buffers were queued up poll() would return that
userspace can write. This is fine for the write() call, but when
using stream I/O this changed the behavior since the expectation
was that it would wait for buffers to become available for dequeuing.

This patch only enables the check whether you can queue buffers
for file I/O only, and skips it for stream I/O.

Signed-off-by: Hans Verkuil <hans.verkuil@cisco.com>
Acked-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Hans Verkuil <hans.verkuil@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
[ kamal: backport to 4.2-stable: file rename; context ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/media/v4l2-core/videobuf2-core.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/media/v4l2-core/videobuf2-core.c b/drivers/media/v4l2-core/videobuf2-core.c
index cc16e76..d2af9e9 100644
--- a/drivers/media/v4l2-core/videobuf2-core.c
+++ b/drivers/media/v4l2-core/videobuf2-core.c
@@ -2622,10 +2622,10 @@ unsigned int vb2_poll(struct vb2_queue *q, struct file *file, poll_table *wait)
 		return res | POLLERR;
 
 	/*
-	 * For output streams you can write as long as there are fewer buffers
-	 * queued than there are buffers available.
+	 * For output streams you can call write() as long as there are fewer
+	 * buffers queued than there are buffers available.
 	 */
-	if (V4L2_TYPE_IS_OUTPUT(q->type) && q->queued_count < q->num_buffers)
+	if (V4L2_TYPE_IS_OUTPUT(q->type) && q->fileio && q->queued_count < q->num_buffers)
 		return res | POLLOUT | POLLWRNORM;
 
 	if (list_empty(&q->done_list))
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321215 — [PATCH 3.19.y-ckt 114/210] dma-debug: switch check from _text to _stext

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 114/210] dma-debug: switch check from _text to _stext
Message-ID<qW62U-3zN-63@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Laura Abbott <labbott@fedoraproject.org>

commit ea535e418c01837d07b6c94e817540f50bfdadb0 upstream.

In include/asm-generic/sections.h:

  /*
   * Usage guidelines:
   * _text, _data: architecture specific, don't use them in
   * arch-independent code
   * [_stext, _etext]: contains .text.* sections, may also contain
   * .rodata.*
   *                   and/or .init.* sections

_text is not guaranteed across architectures.  Architectures such as ARM
may reuse parts which are not actually text and erroneously trigger a bug.
Switch to using _stext which is guaranteed to contain text sections.

Came out of https://lkml.kernel.org/g/<567B1176.4000106@redhat.com>

Signed-off-by: Laura Abbott <labbott@fedoraproject.org>
Reviewed-by: Kees Cook <keescook@chromium.org>
Cc: Russell King <linux@arm.linux.org.uk>
Cc: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 lib/dma-debug.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/lib/dma-debug.c b/lib/dma-debug.c
index 340776a..57f452f 100644
--- a/lib/dma-debug.c
+++ b/lib/dma-debug.c
@@ -1181,7 +1181,7 @@ static inline bool overlap(void *addr, unsigned long len, void *start, void *end
 
 static void check_for_illegal_area(struct device *dev, void *addr, unsigned long len)
 {
-	if (overlap(addr, len, _text, _etext) ||
+	if (overlap(addr, len, _stext, _etext) ||
 	    overlap(addr, len, __start_rodata, __end_rodata))
 		err_printk(dev, NULL, "DMA-API: device driver maps memory from kernel text or rodata [addr=%p] [len=%lu]\n", addr, len);
 }
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321216 — [PATCH 3.19.y-ckt 207/210] xen-netback: respect user provided max_queues

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 207/210] xen-netback: respect user provided max_queues
Message-ID<qW62V-3zN-71@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Wei Liu <wei.liu2@citrix.com>

[ Upstream commit 4c82ac3c37363e8c4ded6a5fe1ec5fa756b34df3 ]

Originally that parameter was always reset to num_online_cpus during
module initialisation, which renders it useless.

The fix is to only set max_queues to num_online_cpus when user has not
provided a value.

Reported-by: Johnny Strom <johnny.strom@linuxsolutions.fi>
Signed-off-by: Wei Liu <wei.liu2@citrix.com>
Reviewed-by: David Vrabel <david.vrabel@citrix.com>
Acked-by: Ian Campbell <ian.campbell@citrix.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/xen-netback/netback.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/drivers/net/xen-netback/netback.c b/drivers/net/xen-netback/netback.c
index 83f7da7..9a6dfb5 100644
--- a/drivers/net/xen-netback/netback.c
+++ b/drivers/net/xen-netback/netback.c
@@ -2178,8 +2178,11 @@ static int __init netback_init(void)
 	if (!xen_domain())
 		return -ENODEV;
 
-	/* Allow as many queues as there are CPUs, by default */
-	xenvif_max_queues = num_online_cpus();
+	/* Allow as many queues as there are CPUs if user has not
+	 * specified a value.
+	 */
+	if (xenvif_max_queues == 0)
+		xenvif_max_queues = num_online_cpus();
 
 	if (fatal_skb_slots < XEN_NETBK_LEGACY_SLOTS_MAX) {
 		pr_info("fatal_skb_slots too small (%d), bump it to XEN_NETBK_LEGACY_SLOTS_MAX (%d)\n",
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321217 — [PATCH 3.19.y-ckt 170/210] um: Fix build error and kconfig for i386

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 170/210] um: Fix build error and kconfig for i386
Message-ID<qW62V-3zN-73@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: =?UTF-8?q?Micka=C3=ABl=20Sala=C3=BCn?= <mic@digikod.net>

commit 42d91f612c879627c925d3779c36877cd440f9f9 upstream.

Fix build error by generating elfcore.o only when ELF_CORE (depending on
COREDUMP) is selected:

arch/x86/um/built-in.o: In function `elf_core_write_extra_phdrs':
(.text+0x3e62): undefined reference to `dump_emit'
arch/x86/um/built-in.o: In function `elf_core_write_extra_data':
(.text+0x3eef): undefined reference to `dump_emit'

Fixes: 5d2acfc7b974 ("kconfig: make allnoconfig disable options behind EMBEDDED and EXPERT")
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Cc: Jeff Dike <jdike@addtoit.com>
Cc: Richard Weinberger <richard@nod.at>
Cc: Josh Triplett <josh@joshtriplett.org>
Cc: Paul E. McKenney <paulmck@linux.vnet.ibm.com>
Cc: Michal Marek <mmarek@suse.cz>
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Richard Weinberger <richard@nod.at>
Reviewed-by: Josh Triplett <josh@joshtriplett.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/x86/um/Makefile | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/x86/um/Makefile b/arch/x86/um/Makefile
index eafa324..7a97752 100644
--- a/arch/x86/um/Makefile
+++ b/arch/x86/um/Makefile
@@ -17,7 +17,7 @@ obj-y = bug.o bugs_$(BITS).o delay.o fault.o ksyms.o ldt.o \
 ifeq ($(CONFIG_X86_32),y)
 
 obj-y += checksum_32.o
-obj-$(CONFIG_BINFMT_ELF) += elfcore.o
+obj-$(CONFIG_ELF_CORE) += elfcore.o
 
 subarch-y = ../lib/string_32.o ../lib/atomic64_32.o ../lib/atomic64_cx8_32.o
 subarch-$(CONFIG_RWSEM_XCHGADD_ALGORITHM) += ../lib/rwsem.o
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321218 — [PATCH 3.19.y-ckt 202/210] batman-adv: Drop immediate neigh_ifinfo free function

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 202/210] batman-adv: Drop immediate neigh_ifinfo free function
Message-ID<qW62V-3zN-69@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Sven Eckelmann <sven@narfation.org>

[ Upstream commit ae3e1e36e3cb6c686a7a2725af20ca86aa46d62a ]

It is not allowed to free the memory of an object which is part of a list
which is protected by rcu-read-side-critical sections without making sure
that no other context is accessing the object anymore. This usually happens
by removing the references to this object and then waiting until the rcu
grace period is over and no one (allowedly) accesses it anymore.

But the _now functions ignore this completely. They free the object
directly even when a different context still tries to access it. This has
to be avoided and thus these functions must be removed and all functions
have to use batadv_neigh_ifinfo_free_ref.

Fixes: 89652331c00f ("batman-adv: split tq information in neigh_node struct")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Marek Lindner <mareklindner@neomailbox.ch>
Signed-off-by: Antonio Quartulli <a@unstable.cc>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/batman-adv/originator.c | 34 ++++++++++------------------------
 1 file changed, 10 insertions(+), 24 deletions(-)

diff --git a/net/batman-adv/originator.c b/net/batman-adv/originator.c
index edfb70e..1d1123b 100644
--- a/net/batman-adv/originator.c
+++ b/net/batman-adv/originator.c
@@ -150,42 +150,28 @@ err:
 }
 
 /**
- * batadv_neigh_ifinfo_free_rcu - free the neigh_ifinfo object
- * @rcu: rcu pointer of the neigh_ifinfo object
- */
-static void batadv_neigh_ifinfo_free_rcu(struct rcu_head *rcu)
-{
-	struct batadv_neigh_ifinfo *neigh_ifinfo;
-
-	neigh_ifinfo = container_of(rcu, struct batadv_neigh_ifinfo, rcu);
-
-	if (neigh_ifinfo->if_outgoing != BATADV_IF_DEFAULT)
-		batadv_hardif_free_ref_now(neigh_ifinfo->if_outgoing);
-
-	kfree(neigh_ifinfo);
-}
-
-/**
- * batadv_neigh_ifinfo_free_now - decrement the refcounter and possibly free
- *  the neigh_ifinfo (without rcu callback)
+ * batadv_neigh_ifinfo_release - release neigh_ifinfo from lists and queue for
+ *  free after rcu grace period
  * @neigh_ifinfo: the neigh_ifinfo object to release
  */
 static void
-batadv_neigh_ifinfo_free_ref_now(struct batadv_neigh_ifinfo *neigh_ifinfo)
+batadv_neigh_ifinfo_release(struct batadv_neigh_ifinfo *neigh_ifinfo)
 {
-	if (atomic_dec_and_test(&neigh_ifinfo->refcount))
-		batadv_neigh_ifinfo_free_rcu(&neigh_ifinfo->rcu);
+	if (neigh_ifinfo->if_outgoing != BATADV_IF_DEFAULT)
+		batadv_hardif_free_ref(neigh_ifinfo->if_outgoing);
+
+	kfree_rcu(neigh_ifinfo, rcu);
 }
 
 /**
- * batadv_neigh_ifinfo_free_ref - decrement the refcounter and possibly free
+ * batadv_neigh_ifinfo_free_ref - decrement the refcounter and possibly release
  *  the neigh_ifinfo
  * @neigh_ifinfo: the neigh_ifinfo object to release
  */
 void batadv_neigh_ifinfo_free_ref(struct batadv_neigh_ifinfo *neigh_ifinfo)
 {
 	if (atomic_dec_and_test(&neigh_ifinfo->refcount))
-		call_rcu(&neigh_ifinfo->rcu, batadv_neigh_ifinfo_free_rcu);
+		batadv_neigh_ifinfo_release(neigh_ifinfo);
 }
 
 /**
@@ -202,7 +188,7 @@ static void batadv_neigh_node_free_rcu(struct rcu_head *rcu)
 
 	hlist_for_each_entry_safe(neigh_ifinfo, node_tmp,
 				  &neigh_node->ifinfo_list, list) {
-		batadv_neigh_ifinfo_free_ref_now(neigh_ifinfo);
+		batadv_neigh_ifinfo_free_ref(neigh_ifinfo);
 	}
 	batadv_hardif_free_ref_now(neigh_node->if_incoming);
 
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321219 — [PATCH 3.19.y-ckt 107/210] mmc: mmci: fix an ages old detection error

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 107/210] mmc: mmci: fix an ages old detection error
Message-ID<qW62V-3zN-75@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Linus Walleij <linus.walleij@linaro.org>

commit 0bcb7efdff63564e80fe84dd36a9fbdfbf6697a4 upstream.

commit 4956e10903fd ("ARM: 6244/1: mmci: add variant data and default
MCICLOCK support") added variant data for ARM, U300 and Ux500 variants.
The Nomadik NHK8815/8820 variant was erroneously labeled as a U300
variant, and when the proper Nomadik variant was later introduced in
commit 34fd421349ff ("ARM: 7378/1: mmci: add support for the Nomadik MMCI
variant") this was not fixes. Let's say this fixes the latter commit as
there was no proper Nomadik support until then.

Fixes: 34fd421349ff ("ARM: 7378/1: mmci: add support for the Nomadik...")
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/mmc/host/mmci.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/mmc/host/mmci.c b/drivers/mmc/host/mmci.c
index 8232e9a..e25c66b 100644
--- a/drivers/mmc/host/mmci.c
+++ b/drivers/mmc/host/mmci.c
@@ -1888,7 +1888,7 @@ static struct amba_id mmci_ids[] = {
 	{
 		.id     = 0x00280180,
 		.mask   = 0x00ffffff,
-		.data	= &variant_u300,
+		.data	= &variant_nomadik,
 	},
 	{
 		.id     = 0x00480180,
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


#1321220 — [PATCH 3.19.y-ckt 076/210] iwlwifi: update and fix 7265 series PCI IDs

FromKamal Mostafa <kamal@canonical.com>
Date2016-01-29 02:30 +0100
Subject[PATCH 3.19.y-ckt 076/210] iwlwifi: update and fix 7265 series PCI IDs
Message-ID<qW62V-3zN-77@gated-at.bofh.it>
In reply to#1321181
3.19.8-ckt14 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Oren Givon <oren.givon@intel.com>

commit 006bda75d81fd27a583a3b310e9444fea2aa6ef2 upstream.

Update and fix some 7265 PCI IDs entries.

Signed-off-by: Oren Givon <oren.givon@intel.com>
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/wireless/iwlwifi/pcie/drv.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/net/wireless/iwlwifi/pcie/drv.c b/drivers/net/wireless/iwlwifi/pcie/drv.c
index e663f10..4c7be34 100644
--- a/drivers/net/wireless/iwlwifi/pcie/drv.c
+++ b/drivers/net/wireless/iwlwifi/pcie/drv.c
@@ -380,6 +380,7 @@ static const struct pci_device_id iwl_hw_card_ids[] = {
 	{IWL_PCI_DEVICE(0x095B, 0x5310, iwl7265_2ac_cfg)},
 	{IWL_PCI_DEVICE(0x095B, 0x5302, iwl7265_n_cfg)},
 	{IWL_PCI_DEVICE(0x095B, 0x5210, iwl7265_2ac_cfg)},
+	{IWL_PCI_DEVICE(0x095A, 0x5C10, iwl7265_2ac_cfg)},
 	{IWL_PCI_DEVICE(0x095A, 0x5012, iwl7265_2ac_cfg)},
 	{IWL_PCI_DEVICE(0x095A, 0x5412, iwl7265_2ac_cfg)},
 	{IWL_PCI_DEVICE(0x095A, 0x5410, iwl7265_2ac_cfg)},
@@ -397,10 +398,10 @@ static const struct pci_device_id iwl_hw_card_ids[] = {
 	{IWL_PCI_DEVICE(0x095A, 0x900A, iwl7265_2ac_cfg)},
 	{IWL_PCI_DEVICE(0x095A, 0x9110, iwl7265_2ac_cfg)},
 	{IWL_PCI_DEVICE(0x095A, 0x9112, iwl7265_2ac_cfg)},
-	{IWL_PCI_DEVICE(0x095A, 0x9210, iwl7265_2ac_cfg)},
+	{IWL_PCI_DEVICE(0x095B, 0x9210, iwl7265_2ac_cfg)},
 	{IWL_PCI_DEVICE(0x095B, 0x9200, iwl7265_2ac_cfg)},
 	{IWL_PCI_DEVICE(0x095A, 0x9510, iwl7265_2ac_cfg)},
-	{IWL_PCI_DEVICE(0x095A, 0x9310, iwl7265_2ac_cfg)},
+	{IWL_PCI_DEVICE(0x095B, 0x9310, iwl7265_2ac_cfg)},
 	{IWL_PCI_DEVICE(0x095A, 0x9410, iwl7265_2ac_cfg)},
 	{IWL_PCI_DEVICE(0x095A, 0x5020, iwl7265_2n_cfg)},
 	{IWL_PCI_DEVICE(0x095A, 0x502A, iwl7265_2n_cfg)},
-- 
1.9.1

[toc] | [prev] | [next] | [standalone]


Page 2 of 11 — ← Prev page 1 [2] 3 4 … 11  Next page →

Back to top | Article view | linux.kernel


csiph-web