Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1321181 > unrolled thread
| Started by | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| First post | 2016-01-29 02:20 +0100 |
| Last post | 2016-01-29 03:40 +0100 |
| Articles | 20 on this page of 210 — 1 participant |
Back to article view | Back to linux.kernel
[3.19.y-ckt stable] Linux 3.19.8-ckt14 stable review Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:20 +0100
[PATCH 3.19.y-ckt 174/210] vmstat: make vmstat_updater deferrable again and shut down on idle Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 201/210] batman-adv: Drop immediate batadv_neigh_node free function Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 210/210] xfrm: dst_entries_init() per-net dst_ops Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 052/210] rtlwifi: rtl8192ce: Fix handling of module parameters Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 121/210] memcg: only free spare array when readers are done Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 197/210] bridge: fix lockdep addr_list_lock false positive splat Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 208/210] xen-netfront: respect user provided max_queues Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 193/210] bonding: Prevent IPv6 link local address on enslaved devices Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 172/210] mmc: sd: limit SD card power limit according to cards capabilities Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 004/210] ovl: allow zero size xattr Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 134/210] ALSA: seq: Fix snd_seq_call_port_info_ioctl in compat mode Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 205/210] team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 009/210] tools lib traceevent: Fix output of %llu for 64 bit values read on 32 bit machines Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 057/210] bcache: Add a cond_resched() call to gc Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 060/210] bcache: unregister reboot notifier if bcache fails to unregister device Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 194/210] phonet: properly unshare skbs in phonet_rcv() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 203/210] batman-adv: Drop immediate batadv_hard_iface free function Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 046/210] rtlwifi: rtl8723be: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 161/210] mmc: sdhci: restore behavior when setting VDD via external regulator Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 098/210] scripts/recordmcount.pl: support data in text section on powerpc Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 071/210] drm/dp/mst: always send reply for UP request Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 198/210] batman-adv: Avoid recursive call_rcu for batadv_bla_claim Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 035/210] mmc: sdhci: Fix sdhci_runtime_pm_bus_on/off() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 111/210] cifs: fix race between call_async() and reconnect() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 165/210] perf/x86: Fix filter_events() bug with event mappings Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 206/210] sctp: Prevent soft lockup when sctp_accept() is called during a timeout event Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 192/210] net: preserve IP control block during GSO segmentation Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 200/210] batman-adv: Drop immediate batadv_orig_ifinfo free function Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 081/210] uml: flush stdout before forking Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 117/210] ALSA: timer: Harden slave timer list handling Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 022/210] EDAC: Robustify workqueues destruction Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 038/210] nfs: Fix race in __update_open_stateid() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 006/210] [media] vb2: fix a regression in poll() behavior for output,streams Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 114/210] dma-debug: switch check from _text to _stext Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 207/210] xen-netback: respect user provided max_queues Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 170/210] um: Fix build error and kconfig for i386 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 202/210] batman-adv: Drop immediate neigh_ifinfo free function Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 107/210] mmc: mmci: fix an ages old detection error Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 076/210] iwlwifi: update and fix 7265 series PCI IDs Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 196/210] ipv6: update skb->csum when CE mark is propagated Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 209/210] xen-netfront: update num_queues to real created Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 019/210] wlcore/wl12xx: spi: fix oops on firmware load Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 013/210] xhci: refuse loading if nousb is used Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 204/210] batman-adv: Drop immediate orig_node free function Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 054/210] NFS: Fix attribute cache revalidation Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 168/210] target: Fix a memory leak in target_dev_lba_map_store() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 133/210] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 190/210] tcp_yeah: don't set ssthresh below 2 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 159/210] ALSA: fm801: propagate TUNER_ONLY bit when autodetected Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 195/210] net: bpf: reject invalid shifts Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 199/210] batman-adv: Avoid recursive call_rcu for batadv_nc_node Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 147/210] MAINTAINERS: return arch/sh to maintained state, with new maintainers Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 012/210] drm/radeon: call hpd_irq_event on resume Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 103/210] x86/mm: Improve switch_mm() barrier comments Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 003/210] hotplugcpu: Avoid deadlocks by waking active_writer Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:30 +0100
[PATCH 3.19.y-ckt 166/210] power: test_power: correctly handle empty writes Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 185/210] connector: bump skb->users before callback invocation Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 188/210] vxlan: fix test which detect duplicate vxlan iface Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 189/210] net: sctp: prevent writes to cookie_hmac_alg from accessing invalid memory Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 163/210] sysrq: Fix warning in sysrq generated crash. Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 164/210] kconfig: return 'false' instead of 'no' in bool function Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 160/210] pinctrl: bcm2835: Fix memory leak in error path Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 177/210] printk: help pr_debug and pr_devel to optimize out arguments Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 157/210] Revert "ACPI / LPSS: allow to use specific PM domain during ->probe()" Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 183/210] net: cdc_ncm: avoid changing RX/TX buffers on MTU changes Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 191/210] udp: disallow UFO for sockets with SO_NO_CHECK option Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 186/210] unix: properly account for FDs passed over unix sockets Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 176/210] btrfs: initialize the seq counter in struct btrfs_device Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 181/210] net/mlx4: Remove unused macro Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 171/210] kbuild: Demote 'sign-compare' warning to W=2 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 175/210] Btrfs: clean up an error code in btrfs_init_space_info() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 167/210] firmware: actually return NULL on failed request_firmware_nowait() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 184/210] sctp: sctp should release assoc when sctp_make_abort_user return NULL in sctp_close Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 158/210] mtd: nand: denali: add missing nand_release() call in denali_remove() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 187/210] bridge: Only call /sbin/bridge-stp for the initial network namespace Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 182/210] veth: don’t modify ip_summed; doing so treats packets with bad checksums as good. Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 178/210] ARM: dts: armadillo800eva Correct extal1 frequency to 24 MHz Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 162/210] x86/LDT: Print the real LDT base address Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 169/210] m68k/atari, m68k/sun3: Fix SCSI platform device registration when driver is modular Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 180/210] IB/mlx4: Initialize hop_limit when creating address handle Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 173/210] net: tcp_memcontrol: properly detect ancestor socket pressure Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 179/210] mmc: debugfs: correct wrong voltage value Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:40 +0100
[PATCH 3.19.y-ckt 125/210] ALSA: hda - Fix bass pin fixup for ASUS N550JX Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 135/210] ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 122/210] panic: release stale console lock to always get the logbuf printed out Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 149/210] drm/i915: On fb alloc failure, unref gem object where it gets refed Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 153/210] clk: st: avoid uninitialized variable use Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 141/210] IB/qib: Support creating qps with GFP_NOIO flag Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 123/210] kernel/panic.c: turn off locks debug before releasing console lock Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 132/210] ALSA: hrtimer: Fix stall by hrtimer_cancel() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 130/210] crypto: af_alg - Allow af_af_alg_release_parent to be called on nokey path Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 151/210] SCSI: initio: remove duplicate module device table Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 129/210] crypto: hash - Add crypto_ahash_has_setkey Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 131/210] crypto: af_alg - Forbid bind(2) when nokey child sockets are present Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 156/210] mtd: nand: fix ONFI parameter page layout Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 145/210] ALSA: timer: Handle disconnection more safely Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 144/210] ALSA: hda - Flush the pending probe work at remove Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 124/210] printk: do cond_resched() between lines while outputting to consoles Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 142/210] ideapad-laptop: Add Lenovo ideapad Y700-17ISK to no_hw_rfkill dmi list Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 152/210] clk: xgene: Fix divider with non-zero shift value Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 136/210] ARM: debug-ll: fix BCM63xx entry for multiplatform Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 140/210] IB/qib: fix mcast detach when qp not attached Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 139/210] crypto: crc32c - Fix crc32c soft dependency Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 146/210] ocfs2: NFS hangs in __ocfs2_cluster_lock due to race with ocfs2_unblock_lock Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 150/210] [media] rc: allow rc modules to be loaded if rc-main is not a module Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 092/210] x86/reboot/quirks: Add iMac10,1 to pci_reboot_dmi_table[] Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 154/210] ASoC: Intel: pass correct parameter in sst_alloc_stream_mrfld() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 143/210] iscsi-target: Fix potential dead-lock during node acl delete Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 085/210] x86/mm: Add barriers and document switch_mm()-vs-flush synchronization Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 155/210] ath9k_htc: check for underflow in ath9k_htc_rx_msg() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 148/210] ideapad-laptop: Add Lenovo Yoga 700 to no_hw_rfkill dmi list Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 127/210] crypto: af_alg - Fix socket double-free when accept fails Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 137/210] xfs: log mount failures don't wait for buffers to be released Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 138/210] crypto: algif_skcipher - Load TX SG list after waiting Kamal Mostafa <kamal@canonical.com> - 2016-01-29 02:50 +0100
[PATCH 3.19.y-ckt 108/210] ALSA: timer: Fix race among timer ioctls Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 093/210] ALSA: seq: Fix missing NULL check at remove_events ioctl Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 116/210] ocfs2/dlm: ignore cleaning the migration mle that is inuse Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 109/210] sparc64: fix incorrect sign extension in sys_sparc64_personality Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 105/210] dmaengine: dw: fix cyclic transfer setup Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 119/210] zram: try vmalloc() after kmalloc() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 112/210] cifs_dbg() outputs an uninitialized buffer in cifs_readdir() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 120/210] mm: soft-offline: check return value in second __get_any_page() call Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 102/210] drm/i915: intel_hpd_init(): Fix suspend/resume reprobing Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 096/210] virtio_balloon: fix race between migration and ballooning Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 104/210] ALSA: timer: Fix double unlink of active_list Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 113/210] m32r: fix m32104ut_defconfig build fail Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 115/210] scripts/bloat-o-meter: fix python3 syntax error Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 090/210] clocksource/drivers/vt8500: Increase the minimum delta Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 106/210] dmaengine: dw: fix cyclic transfer callbacks Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 094/210] ALSA: seq: Fix race at timer setup and close Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 128/210] crypto: af_alg - Add nokey compatibility path Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 095/210] virtio_balloon: fix race by fill and leak Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 086/210] x86/boot: Double BOOT_HEAP_SIZE to 64KB Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 101/210] ALSA: usb-audio: Fix mixer ctl regression of Native Instrument devices Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 097/210] parisc: Fix __ARCH_SI_PREAMBLE_SIZE Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 099/210] powerpc/module: Handle R_PPC64_ENTRY relocations Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 110/210] cifs: Ratelimit kernel log messages Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 100/210] ALSA: hda - fix the headset mic detection problem for a Dell laptop Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 091/210] Input: elantech - mark protocols v2 and v3 as semi-mt Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 118/210] zram/zcomp: use GFP_NOIO to allocate streams Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 126/210] crypto: af_alg - Disallow bind/setkey/... after accept(2) Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:00 +0100
[PATCH 3.19.y-ckt 059/210] bcache: fix a leak in bch_cached_dev_run() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 084/210] ALSA: hda - Fixup inverted internal mic for Lenovo E50-80 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 069/210] udf: Check output buffer length when converting name to CS0 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 051/210] rtlwifi: rtl8192se: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 066/210] libxfs: pack the agfl header structure so XFS_AGFL_SIZE is correct Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 055/210] rtlwifi: rtl_pci: Fix kernel panic Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 073/210] drm/dp/mst: fix in RAD element access Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 067/210] x86/xen: don't reset vcpu_info on a cancelled suspend Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 056/210] bcache: fix a livelock when we cause a huge number of cache misses Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 078/210] ASoC: compress: Fix compress device direction check Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 063/210] bcache: Change refill_dirty() to always scan entire disk if necessary Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 065/210] Input: i8042 - add Fujitsu Lifebook U745 to the nomux list Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 074/210] PCI: Fix minimum allocation address overwrite Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 053/210] rtlwifi: rtl8192cu: Add missing parameter setup Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 050/210] rtlwifi: rtl8192de: Fix incorrect module parameter descriptions Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 045/210] posix-clock: Fix return code on the poll method's error path Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 089/210] xfs: handle dquot buffer readahead in log recovery correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 068/210] udf: Prevent buffer overrun with multi-byte characters Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 082/210] drm/nouveau/kms: take mode_config mutex in connector hotplug path Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 083/210] ALSA: usb: Add native DSD support for Oppo HA-1 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 075/210] PCI: host: Mark PCIe/PCI (MSI) IRQ cascade handlers as IRQF_NO_THREAD Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 087/210] s390: fix normalization bug in exception table sorting Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 058/210] bcache: clear BCACHE_DEV_UNLINK_DONE flag when attaching a backing device Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 079/210] dm snapshot: fix hung bios when copy error occurs Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 072/210] drm/dp/mst: fix in MSTB RAD initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 062/210] bcache: prevent crash on changing writeback_running Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 061/210] bcache: allows use of register in udev to avoid "device_busy" error. Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 064/210] wlcore/wl12xx: spi: fix NULL pointer dereference (Oops) Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 088/210] xfs: inode recovery readahead can race with inode buffer creation Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 070/210] drm/dp/mst: process broadcast messages correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 080/210] uml: fix hostfs mknod() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 077/210] locks: fix unlock when fcntl_setlk races with a close Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:10 +0100
[PATCH 3.19.y-ckt 027/210] dm thin: fix race condition when destroying thin pool workqueue Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 048/210] rtlwifi: rtl8821ae: Fix errors in parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 037/210] [media] rc: sunxi-cir: Initialize the spinlock properly Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 030/210] arm64: kernel: enforce pmuserenr_el0 initialization and restore Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 020/210] ovl: check dentry positiveness in ovl_cleanup_whiteouts() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 017/210] Bluetooth: Add support of Toshiba Broadcom based devices Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 033/210] mmc: sdio: Fix invalid vdd in voltage switch power cycle Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 047/210] rtlwifi: rtl8723ae: Fix initialization of module parameters Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 042/210] Thermal: initialize thermal zone device correctly Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 040/210] NFSv4: Don't perform cached access checks before we've OPENed the file Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 049/210] rtlwifi: rtl8188ee: Fix module parameter initialization Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 044/210] Thermal: do thermal zone update after a cooling device registered Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 026/210] dm space map metadata: remove unused variable in brb_pop() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 043/210] Thermal: handle thermal zone device properly during system sleep Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 024/210] powerpc: Make value-returning atomics fully ordered Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 025/210] powerpc: Make {cmp}xchg* and their atomic_ versions fully ordered Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 014/210] arm64: Clear out any singlestep state on a ptrace detach operation Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 029/210] arm64: mdscr_el1: avoid exposing DCC to userspace Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 018/210] rtlwifi: fix memory leak for USB device Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 041/210] NFS: Ensure we revalidate attributes before using execute_ok() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 028/210] futex: Drop refcount if requeue_pi() acquired the rtmutex Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 036/210] udf: limit the maximum number of indirect extents in a row Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 021/210] EDAC, mc_sysfs: Fix freeing bus' name Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 039/210] USB: cp210x: add ID for ELV Marble Sound Board 1 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 032/210] drm/radeon: clean up fujitsu quirks Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 034/210] mmc: sdhci: Fix DMA descriptor with zero data length Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 031/210] drm/radeon: Fix off-by-one errors in radeon_vm_bo_set_addr Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 023/210] arm64: mm: ensure that the zero page is visible to the page table walker Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:20 +0100
[PATCH 3.19.y-ckt 016/210] ovl: root: copy attr Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:30 +0100
[PATCH 3.19.y-ckt 015/210] time: Avoid signed overflow in timekeeping_get_ns() Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:30 +0100
[PATCH 3.19.y-ckt 008/210] [media] media: dvb-core: Don't force CAN_INVERSION_AUTO in oneshot mode Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:30 +0100
[PATCH 3.19.y-ckt 010/210] KVM: x86: expose MSR_TSC_AUX to userspace Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:30 +0100
[PATCH 3.19.y-ckt 011/210] KVM: x86: correctly print #AC in traces Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:30 +0100
[PATCH 3.19.y-ckt 007/210] [media] gspca: ov534/topro: prevent a division by 0 Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:30 +0100
[PATCH 3.19.y-ckt 002/210] drm/nouveau/nv46: Change mc subdev oclass from nv44 to nv4c Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:40 +0100
[PATCH 3.19.y-ckt 005/210] ovl: use a minimal buffer in ovl_copy_xattr Kamal Mostafa <kamal@canonical.com> - 2016-01-29 03:40 +0100
Page 3 of 11 — ← Prev page 1 2 [3] 4 5 … 11 Next page →
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 196/210] ipv6: update skb->csum when CE mark is propagated |
| Message-ID | <qW62V-3zN-79@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 34ae6a1aa0540f0f781dd265366036355fdc8930 ]
When a tunnel decapsulates the outer header, it has to comply
with RFC 6080 and eventually propagate CE mark into inner header.
It turns out IP6_ECN_set_ce() does not correctly update skb->csum
for CHECKSUM_COMPLETE packets, triggering infamous "hw csum failure"
messages and stack traces.
Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
include/net/inet_ecn.h | 19 ++++++++++++++++---
net/ipv6/xfrm6_mode_tunnel.c | 2 +-
2 files changed, 17 insertions(+), 4 deletions(-)
diff --git a/include/net/inet_ecn.h b/include/net/inet_ecn.h
index 84b2083..0dc0a51 100644
--- a/include/net/inet_ecn.h
+++ b/include/net/inet_ecn.h
@@ -111,11 +111,24 @@ static inline void ipv4_copy_dscp(unsigned int dscp, struct iphdr *inner)
struct ipv6hdr;
-static inline int IP6_ECN_set_ce(struct ipv6hdr *iph)
+/* Note:
+ * IP_ECN_set_ce() has to tweak IPV4 checksum when setting CE,
+ * meaning both changes have no effect on skb->csum if/when CHECKSUM_COMPLETE
+ * In IPv6 case, no checksum compensates the change in IPv6 header,
+ * so we have to update skb->csum.
+ */
+static inline int IP6_ECN_set_ce(struct sk_buff *skb, struct ipv6hdr *iph)
{
+ __be32 from, to;
+
if (INET_ECN_is_not_ect(ipv6_get_dsfield(iph)))
return 0;
- *(__be32*)iph |= htonl(INET_ECN_CE << 20);
+
+ from = *(__be32 *)iph;
+ to = from | htonl(INET_ECN_CE << 20);
+ *(__be32 *)iph = to;
+ if (skb->ip_summed == CHECKSUM_COMPLETE)
+ skb->csum = csum_add(csum_sub(skb->csum, from), to);
return 1;
}
@@ -142,7 +155,7 @@ static inline int INET_ECN_set_ce(struct sk_buff *skb)
case cpu_to_be16(ETH_P_IPV6):
if (skb_network_header(skb) + sizeof(struct ipv6hdr) <=
skb_tail_pointer(skb))
- return IP6_ECN_set_ce(ipv6_hdr(skb));
+ return IP6_ECN_set_ce(skb, ipv6_hdr(skb));
break;
}
diff --git a/net/ipv6/xfrm6_mode_tunnel.c b/net/ipv6/xfrm6_mode_tunnel.c
index 901ef6f..5266ad2 100644
--- a/net/ipv6/xfrm6_mode_tunnel.c
+++ b/net/ipv6/xfrm6_mode_tunnel.c
@@ -24,7 +24,7 @@ static inline void ipip6_ecn_decapsulate(struct sk_buff *skb)
struct ipv6hdr *inner_iph = ipipv6_hdr(skb);
if (INET_ECN_is_ce(ipv6_get_dsfield(outer_iph)))
- IP6_ECN_set_ce(inner_iph);
+ IP6_ECN_set_ce(skb, inner_iph);
}
/* Add encapsulation header.
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 209/210] xen-netfront: update num_queues to real created |
| Message-ID | <qW62V-3zN-81@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Joe Jin <joe.jin@oracle.com>
[ Upstream commit ca88ea1247dfee094e2467a3578eaec9bdf0833a ]
Sometimes xennet_create_queues() may failed to created all requested
queues, we need to update num_queues to real created to avoid NULL
pointer dereference.
Signed-off-by: Joe Jin <joe.jin@oracle.com>
Cc: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Cc: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Cc: Wei Liu <wei.liu2@citrix.com>
Cc: Ian Campbell <ian.campbell@citrix.com>
Cc: David S. Miller <davem@davemloft.net>
Reviewed-by: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/xen-netfront.c | 14 +++++++-------
1 file changed, 7 insertions(+), 7 deletions(-)
diff --git a/drivers/net/xen-netfront.c b/drivers/net/xen-netfront.c
index e315fee..5cdfca1 100644
--- a/drivers/net/xen-netfront.c
+++ b/drivers/net/xen-netfront.c
@@ -1766,19 +1766,19 @@ static void xennet_destroy_queues(struct netfront_info *info)
}
static int xennet_create_queues(struct netfront_info *info,
- unsigned int num_queues)
+ unsigned int *num_queues)
{
unsigned int i;
int ret;
- info->queues = kcalloc(num_queues, sizeof(struct netfront_queue),
+ info->queues = kcalloc(*num_queues, sizeof(struct netfront_queue),
GFP_KERNEL);
if (!info->queues)
return -ENOMEM;
rtnl_lock();
- for (i = 0; i < num_queues; i++) {
+ for (i = 0; i < *num_queues; i++) {
struct netfront_queue *queue = &info->queues[i];
queue->id = i;
@@ -1788,7 +1788,7 @@ static int xennet_create_queues(struct netfront_info *info,
if (ret < 0) {
dev_warn(&info->netdev->dev,
"only created %d queues\n", i);
- num_queues = i;
+ *num_queues = i;
break;
}
@@ -1798,11 +1798,11 @@ static int xennet_create_queues(struct netfront_info *info,
napi_enable(&queue->napi);
}
- netif_set_real_num_tx_queues(info->netdev, num_queues);
+ netif_set_real_num_tx_queues(info->netdev, *num_queues);
rtnl_unlock();
- if (num_queues == 0) {
+ if (*num_queues == 0) {
dev_err(&info->netdev->dev, "no queues\n");
return -EINVAL;
}
@@ -1848,7 +1848,7 @@ static int talk_to_netback(struct xenbus_device *dev,
if (info->queues)
xennet_destroy_queues(info);
- err = xennet_create_queues(info, num_queues);
+ err = xennet_create_queues(info, &num_queues);
if (err < 0)
goto destroy_ring;
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 019/210] wlcore/wl12xx: spi: fix oops on firmware load |
| Message-ID | <qW62V-3zN-83@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Uri Mashiach <uri.mashiach@compulab.co.il>
commit 9b2761cb72dc41e1948c8a5512b4efd384eda130 upstream.
The maximum chunks used by the function is
(SPI_AGGR_BUFFER_SIZE / WSPI_MAX_CHUNK_SIZE + 1).
The original commands array had space for
(SPI_AGGR_BUFFER_SIZE / WSPI_MAX_CHUNK_SIZE) commands.
When the last chunk is used (len > 4 * WSPI_MAX_CHUNK_SIZE), the last
command is stored outside the bounds of the commands array.
Oops 5 (page fault) is generated during current wl1271 firmware load
attempt:
root@debian-armhf:~# ifconfig wlan0 up
[ 294.312399] Unable to handle kernel paging request at virtual address
00203fc4
[ 294.320173] pgd = de528000
[ 294.323028] [00203fc4] *pgd=00000000
[ 294.326916] Internal error: Oops: 5 [#1] SMP ARM
[ 294.331789] Modules linked in: bnep rfcomm bluetooth ipv6 arc4 wl12xx
wlcore mac80211 musb_dsps cfg80211 musb_hdrc usbcore usb_common
wlcore_spi omap_rng rng_core musb_am335x omap_wdt cpufreq_dt thermal_sys
hwmon
[ 294.351838] CPU: 0 PID: 1827 Comm: ifconfig Not tainted
4.2.0-00002-g3e9ad27-dirty #78
[ 294.360154] Hardware name: Generic AM33XX (Flattened Device Tree)
[ 294.366557] task: dc9d6d40 ti: de550000 task.ti: de550000
[ 294.372236] PC is at __spi_validate+0xa8/0x2ac
[ 294.376902] LR is at __spi_sync+0x78/0x210
[ 294.381200] pc : [<c049c760>] lr : [<c049ebe0>] psr: 60000013
[ 294.381200] sp : de551998 ip : de5519d8 fp : 00200000
[ 294.393242] r10: de551c8c r9 : de5519d8 r8 : de3a9000
[ 294.398730] r7 : de3a9258 r6 : de3a9400 r5 : de551a48 r4 :
00203fbc
[ 294.405577] r3 : 00000000 r2 : 00000000 r1 : 00000000 r0 :
de3a9000
[ 294.412420] Flags: nZCv IRQs on FIQs on Mode SVC_32 ISA ARM
Segment user
[ 294.419918] Control: 10c5387d Table: 9e528019 DAC: 00000015
[ 294.425954] Process ifconfig (pid: 1827, stack limit = 0xde550218)
[ 294.432437] Stack: (0xde551998 to 0xde552000)
...
[ 294.883613] [<c049c760>] (__spi_validate) from [<c049ebe0>]
(__spi_sync+0x78/0x210)
[ 294.891670] [<c049ebe0>] (__spi_sync) from [<bf036598>]
(wl12xx_spi_raw_write+0xfc/0x148 [wlcore_spi])
[ 294.901661] [<bf036598>] (wl12xx_spi_raw_write [wlcore_spi]) from
[<bf21c694>] (wlcore_boot_upload_firmware+0x1ec/0x458 [wlcore])
[ 294.914038] [<bf21c694>] (wlcore_boot_upload_firmware [wlcore]) from
[<bf24532c>] (wl12xx_boot+0xc10/0xfac [wl12xx])
[ 294.925161] [<bf24532c>] (wl12xx_boot [wl12xx]) from [<bf20d5cc>]
(wl1271_op_add_interface+0x5b0/0x910 [wlcore])
[ 294.936364] [<bf20d5cc>] (wl1271_op_add_interface [wlcore]) from
[<bf15c4ac>] (ieee80211_do_open+0x44c/0xf7c [mac80211])
[ 294.947963] [<bf15c4ac>] (ieee80211_do_open [mac80211]) from
[<c0537978>] (__dev_open+0xa8/0x110)
[ 294.957307] [<c0537978>] (__dev_open) from [<c0537bf8>]
(__dev_change_flags+0x88/0x148)
[ 294.965713] [<c0537bf8>] (__dev_change_flags) from [<c0537cd0>]
(dev_change_flags+0x18/0x48)
[ 294.974576] [<c0537cd0>] (dev_change_flags) from [<c05a55a0>]
(devinet_ioctl+0x6b4/0x7d0)
[ 294.983191] [<c05a55a0>] (devinet_ioctl) from [<c0517040>]
(sock_ioctl+0x1e4/0x2bc)
[ 294.991244] [<c0517040>] (sock_ioctl) from [<c017d378>]
(do_vfs_ioctl+0x420/0x6b0)
[ 294.999208] [<c017d378>] (do_vfs_ioctl) from [<c017d674>]
(SyS_ioctl+0x6c/0x7c)
[ 295.006880] [<c017d674>] (SyS_ioctl) from [<c000f4c0>]
(ret_fast_syscall+0x0/0x54)
[ 295.014835] Code: e1550004 e2444034 0a00007d e5953018 (e5942008)
[ 295.021544] ---[ end trace 66ed188198f4e24e ]---
Signed-off-by: Uri Mashiach <uri.mashiach@compulab.co.il>
Acked-by: Igor Grinberg <grinberg@compulab.co.il>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/ti/wlcore/spi.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/drivers/net/wireless/ti/wlcore/spi.c b/drivers/net/wireless/ti/wlcore/spi.c
index 69601f6..2073305 100644
--- a/drivers/net/wireless/ti/wlcore/spi.c
+++ b/drivers/net/wireless/ti/wlcore/spi.c
@@ -73,7 +73,10 @@
*/
#define SPI_AGGR_BUFFER_SIZE (4 * PAGE_SIZE)
-#define WSPI_MAX_NUM_OF_CHUNKS (SPI_AGGR_BUFFER_SIZE / WSPI_MAX_CHUNK_SIZE)
+/* Maximum number of SPI write chunks */
+#define WSPI_MAX_NUM_OF_CHUNKS \
+ ((SPI_AGGR_BUFFER_SIZE / WSPI_MAX_CHUNK_SIZE) + 1)
+
struct wl12xx_spi_glue {
struct device *dev;
@@ -268,9 +271,10 @@ static int __must_check wl12xx_spi_raw_write(struct device *child, int addr,
void *buf, size_t len, bool fixed)
{
struct wl12xx_spi_glue *glue = dev_get_drvdata(child->parent);
- struct spi_transfer t[2 * (WSPI_MAX_NUM_OF_CHUNKS + 1)];
+ /* SPI write buffers - 2 for each chunk */
+ struct spi_transfer t[2 * WSPI_MAX_NUM_OF_CHUNKS];
struct spi_message m;
- u32 commands[WSPI_MAX_NUM_OF_CHUNKS];
+ u32 commands[WSPI_MAX_NUM_OF_CHUNKS]; /* 1 command per chunk */
u32 *cmd;
u32 chunk_len;
int i;
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 013/210] xhci: refuse loading if nousb is used |
| Message-ID | <qW62V-3zN-85@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know. ---8<------------------------------------------------------------ From: Oliver Neukum <oneukum@suse.com> commit 1eaf35e4dd592c59041bc1ed3248c46326da1f5f upstream. The module should fail to load. Signed-off-by: Oliver Neukum <oneukum@suse.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by: Kamal Mostafa <kamal@canonical.com> --- drivers/usb/host/xhci.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/usb/host/xhci.c b/drivers/usb/host/xhci.c index 2142e96..93e2732 100644 --- a/drivers/usb/host/xhci.c +++ b/drivers/usb/host/xhci.c @@ -5049,6 +5049,10 @@ static int __init xhci_hcd_init(void) BUILD_BUG_ON(sizeof(struct xhci_intr_reg) != 8*32/8); /* xhci_run_regs has eight fields and embeds 128 xhci_intr_regs */ BUILD_BUG_ON(sizeof(struct xhci_run_regs) != (8+8*128)*32/8); + + if (usb_disabled()) + return -ENODEV; + return 0; } -- 1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 204/210] batman-adv: Drop immediate orig_node free function |
| Message-ID | <qW62W-3zN-91@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Sven Eckelmann <sven@narfation.org>
[ Upstream commit 42eff6a617e23b691f8e4467f4687ed7245a92db ]
It is not allowed to free the memory of an object which is part of a list
which is protected by rcu-read-side-critical sections without making sure
that no other context is accessing the object anymore. This usually happens
by removing the references to this object and then waiting until the rcu
grace period is over and no one (allowedly) accesses it anymore.
But the _now functions ignore this completely. They free the object
directly even when a different context still tries to access it. This has
to be avoided and thus these functions must be removed and all functions
have to use batadv_orig_node_free_ref.
Fixes: 72822225bd41 ("batman-adv: Fix rcu_barrier() miss due to double call_rcu() in TT code")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Marek Lindner <mareklindner@neomailbox.ch>
Signed-off-by: Antonio Quartulli <a@unstable.cc>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
net/batman-adv/originator.c | 11 -----------
net/batman-adv/originator.h | 1 -
net/batman-adv/translation-table.c | 28 +++++++++++++---------------
3 files changed, 13 insertions(+), 27 deletions(-)
diff --git a/net/batman-adv/originator.c b/net/batman-adv/originator.c
index 6c24428..441042f 100644
--- a/net/batman-adv/originator.c
+++ b/net/batman-adv/originator.c
@@ -562,17 +562,6 @@ void batadv_orig_node_free_ref(struct batadv_orig_node *orig_node)
batadv_orig_node_release(orig_node);
}
-/**
- * batadv_orig_node_free_ref_now - decrement the orig node refcounter and
- * possibly free it (without rcu callback)
- * @orig_node: the orig node to free
- */
-void batadv_orig_node_free_ref_now(struct batadv_orig_node *orig_node)
-{
- if (atomic_dec_and_test(&orig_node->refcount))
- batadv_orig_node_free_rcu(&orig_node->rcu);
-}
-
void batadv_originator_free(struct batadv_priv *bat_priv)
{
struct batadv_hashtable *hash = bat_priv->orig_hash;
diff --git a/net/batman-adv/originator.h b/net/batman-adv/originator.h
index db3a9ed..ce75339 100644
--- a/net/batman-adv/originator.h
+++ b/net/batman-adv/originator.h
@@ -25,7 +25,6 @@ int batadv_originator_init(struct batadv_priv *bat_priv);
void batadv_originator_free(struct batadv_priv *bat_priv);
void batadv_purge_orig_ref(struct batadv_priv *bat_priv);
void batadv_orig_node_free_ref(struct batadv_orig_node *orig_node);
-void batadv_orig_node_free_ref_now(struct batadv_orig_node *orig_node);
struct batadv_orig_node *batadv_orig_node_new(struct batadv_priv *bat_priv,
const uint8_t *addr);
struct batadv_neigh_node *
diff --git a/net/batman-adv/translation-table.c b/net/batman-adv/translation-table.c
index 4503069..f775f06 100644
--- a/net/batman-adv/translation-table.c
+++ b/net/batman-adv/translation-table.c
@@ -218,20 +218,6 @@ int batadv_tt_global_hash_count(struct batadv_priv *bat_priv,
return count;
}
-static void batadv_tt_orig_list_entry_free_rcu(struct rcu_head *rcu)
-{
- struct batadv_tt_orig_list_entry *orig_entry;
-
- orig_entry = container_of(rcu, struct batadv_tt_orig_list_entry, rcu);
-
- /* We are in an rcu callback here, therefore we cannot use
- * batadv_orig_node_free_ref() and its call_rcu():
- * An rcu_barrier() wouldn't wait for that to finish
- */
- batadv_orig_node_free_ref_now(orig_entry->orig_node);
- kfree(orig_entry);
-}
-
/**
* batadv_tt_local_size_mod - change the size by v of the local table identified
* by vid
@@ -327,13 +313,25 @@ static void batadv_tt_global_size_dec(struct batadv_orig_node *orig_node,
batadv_tt_global_size_mod(orig_node, vid, -1);
}
+/**
+ * batadv_tt_orig_list_entry_release - release tt orig entry from lists and
+ * queue for free after rcu grace period
+ * @orig_entry: tt orig entry to be free'd
+ */
+static void
+batadv_tt_orig_list_entry_release(struct batadv_tt_orig_list_entry *orig_entry)
+{
+ batadv_orig_node_free_ref(orig_entry->orig_node);
+ kfree_rcu(orig_entry, rcu);
+}
+
static void
batadv_tt_orig_list_entry_free_ref(struct batadv_tt_orig_list_entry *orig_entry)
{
if (!atomic_dec_and_test(&orig_entry->refcount))
return;
- call_rcu(&orig_entry->rcu, batadv_tt_orig_list_entry_free_rcu);
+ batadv_tt_orig_list_entry_release(orig_entry);
}
/**
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 054/210] NFS: Fix attribute cache revalidation |
| Message-ID | <qW62V-3zN-87@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Trond Myklebust <trond.myklebust@primarydata.com>
commit ade14a7df796d4e86bd9d181193c883a57b13db0 upstream.
If a NFSv4 client uses the cache_consistency_bitmask in order to
request only information about the change attribute, timestamps and
size, then it has not revalidated all attributes, and hence the
attribute timeout timestamp should not be updated.
Reported-by: Donald Buczek <buczek@molgen.mpg.de>
Signed-off-by: Trond Myklebust <trond.myklebust@primarydata.com>
[ kamal: backport to 3.19-stable: context ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
fs/nfs/inode.c | 54 +++++++++++++++++++++++++++++++++++++++---------------
1 file changed, 39 insertions(+), 15 deletions(-)
diff --git a/fs/nfs/inode.c b/fs/nfs/inode.c
index 246455a..47135b5 100644
--- a/fs/nfs/inode.c
+++ b/fs/nfs/inode.c
@@ -1537,6 +1537,7 @@ static int nfs_update_inode(struct inode *inode, struct nfs_fattr *fattr)
unsigned long invalid = 0;
unsigned long now = jiffies;
unsigned long save_cache_validity;
+ bool cache_revalidated = true;
dfprintk(VFS, "NFS: %s(%s/%lu fh_crc=0x%08x ct=%d info=0x%x)\n",
__func__, inode->i_sb->s_id, inode->i_ino,
@@ -1598,22 +1599,28 @@ static int nfs_update_inode(struct inode *inode, struct nfs_fattr *fattr)
nfs_force_lookup_revalidate(inode);
inode->i_version = fattr->change_attr;
}
- } else if (server->caps & NFS_CAP_CHANGE_ATTR)
+ } else if (server->caps & NFS_CAP_CHANGE_ATTR) {
nfsi->cache_validity |= save_cache_validity;
+ cache_revalidated = false;
+ }
if (fattr->valid & NFS_ATTR_FATTR_MTIME) {
memcpy(&inode->i_mtime, &fattr->mtime, sizeof(inode->i_mtime));
- } else if (server->caps & NFS_CAP_MTIME)
+ } else if (server->caps & NFS_CAP_MTIME) {
nfsi->cache_validity |= save_cache_validity &
(NFS_INO_INVALID_ATTR
| NFS_INO_REVAL_FORCED);
+ cache_revalidated = false;
+ }
if (fattr->valid & NFS_ATTR_FATTR_CTIME) {
memcpy(&inode->i_ctime, &fattr->ctime, sizeof(inode->i_ctime));
- } else if (server->caps & NFS_CAP_CTIME)
+ } else if (server->caps & NFS_CAP_CTIME) {
nfsi->cache_validity |= save_cache_validity &
(NFS_INO_INVALID_ATTR
| NFS_INO_REVAL_FORCED);
+ cache_revalidated = false;
+ }
/* Check if our cached file size is stale */
if (fattr->valid & NFS_ATTR_FATTR_SIZE) {
@@ -1633,19 +1640,23 @@ static int nfs_update_inode(struct inode *inode, struct nfs_fattr *fattr)
(long long)cur_isize,
(long long)new_isize);
}
- } else
+ } else {
nfsi->cache_validity |= save_cache_validity &
(NFS_INO_INVALID_ATTR
| NFS_INO_REVAL_PAGECACHE
| NFS_INO_REVAL_FORCED);
+ cache_revalidated = false;
+ }
if (fattr->valid & NFS_ATTR_FATTR_ATIME)
memcpy(&inode->i_atime, &fattr->atime, sizeof(inode->i_atime));
- else if (server->caps & NFS_CAP_ATIME)
+ else if (server->caps & NFS_CAP_ATIME) {
nfsi->cache_validity |= save_cache_validity &
(NFS_INO_INVALID_ATIME
| NFS_INO_REVAL_FORCED);
+ cache_revalidated = false;
+ }
if (fattr->valid & NFS_ATTR_FATTR_MODE) {
if ((inode->i_mode & S_IALLUGO) != (fattr->mode & S_IALLUGO)) {
@@ -1654,36 +1665,42 @@ static int nfs_update_inode(struct inode *inode, struct nfs_fattr *fattr)
inode->i_mode = newmode;
invalid |= NFS_INO_INVALID_ATTR|NFS_INO_INVALID_ACCESS|NFS_INO_INVALID_ACL;
}
- } else if (server->caps & NFS_CAP_MODE)
+ } else if (server->caps & NFS_CAP_MODE) {
nfsi->cache_validity |= save_cache_validity &
(NFS_INO_INVALID_ATTR
| NFS_INO_INVALID_ACCESS
| NFS_INO_INVALID_ACL
| NFS_INO_REVAL_FORCED);
+ cache_revalidated = false;
+ }
if (fattr->valid & NFS_ATTR_FATTR_OWNER) {
if (!uid_eq(inode->i_uid, fattr->uid)) {
invalid |= NFS_INO_INVALID_ATTR|NFS_INO_INVALID_ACCESS|NFS_INO_INVALID_ACL;
inode->i_uid = fattr->uid;
}
- } else if (server->caps & NFS_CAP_OWNER)
+ } else if (server->caps & NFS_CAP_OWNER) {
nfsi->cache_validity |= save_cache_validity &
(NFS_INO_INVALID_ATTR
| NFS_INO_INVALID_ACCESS
| NFS_INO_INVALID_ACL
| NFS_INO_REVAL_FORCED);
+ cache_revalidated = false;
+ }
if (fattr->valid & NFS_ATTR_FATTR_GROUP) {
if (!gid_eq(inode->i_gid, fattr->gid)) {
invalid |= NFS_INO_INVALID_ATTR|NFS_INO_INVALID_ACCESS|NFS_INO_INVALID_ACL;
inode->i_gid = fattr->gid;
}
- } else if (server->caps & NFS_CAP_OWNER_GROUP)
+ } else if (server->caps & NFS_CAP_OWNER_GROUP) {
nfsi->cache_validity |= save_cache_validity &
(NFS_INO_INVALID_ATTR
| NFS_INO_INVALID_ACCESS
| NFS_INO_INVALID_ACL
| NFS_INO_REVAL_FORCED);
+ cache_revalidated = false;
+ }
if (fattr->valid & NFS_ATTR_FATTR_NLINK) {
if (inode->i_nlink != fattr->nlink) {
@@ -1692,19 +1709,22 @@ static int nfs_update_inode(struct inode *inode, struct nfs_fattr *fattr)
invalid |= NFS_INO_INVALID_DATA;
set_nlink(inode, fattr->nlink);
}
- } else if (server->caps & NFS_CAP_NLINK)
+ } else if (server->caps & NFS_CAP_NLINK) {
nfsi->cache_validity |= save_cache_validity &
(NFS_INO_INVALID_ATTR
| NFS_INO_REVAL_FORCED);
+ cache_revalidated = false;
+ }
if (fattr->valid & NFS_ATTR_FATTR_SPACE_USED) {
/*
* report the blocks in 512byte units
*/
inode->i_blocks = nfs_calc_block_size(fattr->du.nfs3.used);
- }
- if (fattr->valid & NFS_ATTR_FATTR_BLOCKS_USED)
+ } else if (fattr->valid & NFS_ATTR_FATTR_BLOCKS_USED)
inode->i_blocks = fattr->du.nfs2.blocks;
+ else
+ cache_revalidated = false;
/* Update attrtimeo value if we're out of the unstable period */
if (invalid & NFS_INO_INVALID_ATTR) {
@@ -1713,15 +1733,19 @@ static int nfs_update_inode(struct inode *inode, struct nfs_fattr *fattr)
nfsi->attrtimeo_timestamp = now;
nfsi->attr_gencount = nfs_inc_attr_generation_counter();
} else {
- if (!time_in_range_open(now, nfsi->attrtimeo_timestamp, nfsi->attrtimeo_timestamp + nfsi->attrtimeo)) {
- if ((nfsi->attrtimeo <<= 1) > NFS_MAXATTRTIMEO(inode))
- nfsi->attrtimeo = NFS_MAXATTRTIMEO(inode);
+ if (cache_revalidated) {
+ if (!time_in_range_open(now, nfsi->attrtimeo_timestamp,
+ nfsi->attrtimeo_timestamp + nfsi->attrtimeo)) {
+ nfsi->attrtimeo <<= 1;
+ if (nfsi->attrtimeo > NFS_MAXATTRTIMEO(inode))
+ nfsi->attrtimeo = NFS_MAXATTRTIMEO(inode);
+ }
nfsi->attrtimeo_timestamp = now;
}
}
/* Don't declare attrcache up to date if there were no attrs! */
- if (fattr->valid != 0)
+ if (cache_revalidated)
invalid &= ~NFS_INO_INVALID_ATTR;
/* Don't invalidate the data if we were to blame */
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 168/210] target: Fix a memory leak in target_dev_lba_map_store() |
| Message-ID | <qW62W-3zN-95@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know. ---8<------------------------------------------------------------ From: Bart Van Assche <bart.vanassche@sandisk.com> commit f0a8afecb29ad0005e7e946228a0ef5422058b85 upstream. strsep() modifies its first argument. Make the pointer passed to kfree() match the return value of kmalloc(). Fixes: 229d4f112fd6 (commit "target_core_alua: Referrals configfs integration") Signed-off-by: Bart Van Assche <bart.vanassche@sandisk.com> Cc: Hannes Reinecke <hare@suse.com> Cc: Christoph Hellwig <hch@lst.de> Cc: Andy Grover <agrover@redhat.com> Cc: Sagi Grimberg <sagig@mellanox.com> Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org> Signed-off-by: Kamal Mostafa <kamal@canonical.com> --- drivers/target/target_core_configfs.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/drivers/target/target_core_configfs.c b/drivers/target/target_core_configfs.c index 75d89ad..186a305 100644 --- a/drivers/target/target_core_configfs.c +++ b/drivers/target/target_core_configfs.c @@ -1645,14 +1645,14 @@ static ssize_t target_core_store_dev_lba_map( struct se_device *dev = p; struct t10_alua_lba_map *lba_map = NULL; struct list_head lba_list; - char *map_entries, *ptr; + char *map_entries, *orig, *ptr; char state; int pg_num = -1, pg; int ret = 0, num = 0, pg_id, alua_state; unsigned long start_lba = -1, end_lba = -1; unsigned long segment_size = -1, segment_mult = -1; - map_entries = kstrdup(page, GFP_KERNEL); + orig = map_entries = kstrdup(page, GFP_KERNEL); if (!map_entries) return -ENOMEM; @@ -1750,7 +1750,7 @@ out: } else core_alua_set_lba_map(dev, &lba_list, segment_size, segment_mult); - kfree(map_entries); + kfree(orig); return count; } -- 1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 133/210] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode |
| Message-ID | <qW62W-3zN-93@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Nicolas Boichat <drinkcat@chromium.org>
commit 43c54b8c7cfe22f868a751ba8a59abf1724160b1 upstream.
This reverts one hunk of
commit ef44a1ec6eee ("ALSA: sound/core: use memdup_user()"), which
replaced a number of kmalloc followed by memcpy with memdup calls.
In this case, we are copying from a struct snd_pcm_hw_params32 to
a struct snd_pcm_hw_params, but the latter is 4 bytes longer than
the 32-bit version, so we need to separate kmalloc and copy calls.
This actually leads to an out-of-bounds memory access later on
in sound/soc/soc-pcm.c:soc_pcm_hw_params() (detected using KASan).
Fixes: ef44a1ec6eee ('ALSA: sound/core: use memdup_user()')
Signed-off-by: Nicolas Boichat <drinkcat@chromium.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/core/pcm_compat.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/sound/core/pcm_compat.c b/sound/core/pcm_compat.c
index 2d957ba..33347a7 100644
--- a/sound/core/pcm_compat.c
+++ b/sound/core/pcm_compat.c
@@ -240,10 +240,15 @@ static int snd_pcm_ioctl_hw_params_compat(struct snd_pcm_substream *substream,
if (! (runtime = substream->runtime))
return -ENOTTY;
- /* only fifo_size is different, so just copy all */
- data = memdup_user(data32, sizeof(*data32));
- if (IS_ERR(data))
- return PTR_ERR(data);
+ data = kmalloc(sizeof(*data), GFP_KERNEL);
+ if (!data)
+ return -ENOMEM;
+
+ /* only fifo_size (RO from userspace) is different, so just copy all */
+ if (copy_from_user(data, data32, sizeof(*data32))) {
+ err = -EFAULT;
+ goto error;
+ }
if (refine)
err = snd_pcm_hw_refine(substream, data);
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 190/210] tcp_yeah: don't set ssthresh below 2 |
| Message-ID | <qW62X-3zN-97@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Neal Cardwell <ncardwell@google.com>
[ Upstream commit 83d15e70c4d8909d722c0d64747d8fb42e38a48f ]
For tcp_yeah, use an ssthresh floor of 2, the same floor used by Reno
and CUBIC, per RFC 5681 (equation 4).
tcp_yeah_ssthresh() was sometimes returning a 0 or negative ssthresh
value if the intended reduction is as big or bigger than the current
cwnd. Congestion control modules should never return a zero or
negative ssthresh. A zero ssthresh generally results in a zero cwnd,
causing the connection to stall. A negative ssthresh value will be
interpreted as a u32 and will set a target cwnd for PRR near 4
billion.
Oleksandr Natalenko reported that a system using tcp_yeah with ECN
could see a warning about a prior_cwnd of 0 in
tcp_cwnd_reduction(). Testing verified that this was due to
tcp_yeah_ssthresh() misbehaving in this way.
Reported-by: Oleksandr Natalenko <oleksandr@natalenko.name>
Signed-off-by: Neal Cardwell <ncardwell@google.com>
Signed-off-by: Yuchung Cheng <ycheng@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
net/ipv4/tcp_yeah.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/ipv4/tcp_yeah.c b/net/ipv4/tcp_yeah.c
index 17d3566..3e6a472 100644
--- a/net/ipv4/tcp_yeah.c
+++ b/net/ipv4/tcp_yeah.c
@@ -219,7 +219,7 @@ static u32 tcp_yeah_ssthresh(struct sock *sk)
yeah->fast_count = 0;
yeah->reno_count = max(yeah->reno_count>>1, 2U);
- return tp->snd_cwnd - reduction;
+ return max_t(int, tp->snd_cwnd - reduction, 2);
}
static struct tcp_congestion_ops tcp_yeah __read_mostly = {
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 159/210] ALSA: fm801: propagate TUNER_ONLY bit when autodetected |
| Message-ID | <qW62X-3zN-103@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
commit dbec6719ac036f68568d8488805d41346c021eff upstream.
The commit d7ba858a7f7a (ALSA: fm801: implement TEA575x tuner autodetection)
brings autodetection to the driver. However the autodetection algorithm misses
the TUNER_ONLY bit if it is supplied by the user.
Thus, user gets weird messages and no card registered.
snd_fm801 0000:0d:01.0: detected TEA575x radio type SF64-PCR
snd_fm801 0000:0d:01.0: AC'97 interface is busy (1)
snd_fm801 0000:0d:01.0: AC'97 interface is busy (1)
...
snd_fm801 0000:0d:01.0: AC'97 0 does not respond - RESET
snd_fm801 0000:0d:01.0: AC'97 interface is busy (1)
snd_fm801 0000:0d:01.0: AC'97 interface is busy (1)
snd_fm801 0000:0d:01.0: AC'97 0 access is not valid [0x0], removing mixer.
snd_fm801: probe of 0000:0d:01.0 failed with error -5
Do a copy of TUNER_ONLY bit to be applied after autodetection is done.
Fixes: d7ba858a7f7a (ALSA: fm801: implement TEA575x tuner autodetection)
Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Cc: Ondrej Zary <linux@rainbow-software.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/pci/fm801.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/sound/pci/fm801.c b/sound/pci/fm801.c
index d167aff..c848e72 100644
--- a/sound/pci/fm801.c
+++ b/sound/pci/fm801.c
@@ -1280,6 +1280,8 @@ static int snd_fm801_create(struct snd_card *card,
return -ENODEV;
}
} else if ((tea575x_tuner & TUNER_TYPE_MASK) == 0) {
+ unsigned int tuner_only = tea575x_tuner & TUNER_ONLY;
+
/* autodetect tuner connection */
for (tea575x_tuner = 1; tea575x_tuner <= 3; tea575x_tuner++) {
chip->tea575x_tuner = tea575x_tuner;
@@ -1294,6 +1296,8 @@ static int snd_fm801_create(struct snd_card *card,
dev_err(card->dev, "TEA575x radio not found\n");
chip->tea575x_tuner = TUNER_DISABLED;
}
+
+ chip->tea575x_tuner |= tuner_only;
}
if (!(chip->tea575x_tuner & TUNER_DISABLED)) {
strlcpy(chip->tea.card, get_tea575x_gpio(chip)->name,
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 195/210] net: bpf: reject invalid shifts |
| Message-ID | <qW62X-3zN-101@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Rabin Vincent <rabin@rab.in>
[ Upstream commit 229394e8e62a4191d592842cf67e80c62a492937 ]
On ARM64, a BUG() is triggered in the eBPF JIT if a filter with a
constant shift that can't be encoded in the immediate field of the
UBFM/SBFM instructions is passed to the JIT. Since these shifts
amounts, which are negative or >= regsize, are invalid, reject them in
the eBPF verifier and the classic BPF filter checker, for all
architectures.
Signed-off-by: Rabin Vincent <rabin@rab.in>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Daniel Borkmann <daniel@iogearbox.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
kernel/bpf/verifier.c | 10 ++++++++++
net/core/filter.c | 5 +++++
2 files changed, 15 insertions(+)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 5d8ea3d..7f68ff6 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -1017,6 +1017,16 @@ static int check_alu_op(struct reg_state *regs, struct bpf_insn *insn)
return -EINVAL;
}
+ if ((opcode == BPF_LSH || opcode == BPF_RSH ||
+ opcode == BPF_ARSH) && BPF_SRC(insn->code) == BPF_K) {
+ int size = BPF_CLASS(insn->code) == BPF_ALU64 ? 64 : 32;
+
+ if (insn->imm < 0 || insn->imm >= size) {
+ verbose("invalid shift %d\n", insn->imm);
+ return -EINVAL;
+ }
+ }
+
/* pattern match 'bpf_add Rx, imm' instruction */
if (opcode == BPF_ADD && BPF_CLASS(insn->code) == BPF_ALU64 &&
regs[insn->dst_reg].type == FRAME_PTR &&
diff --git a/net/core/filter.c b/net/core/filter.c
index e1d48e4..10a4c36 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -729,6 +729,11 @@ int bpf_check_classic(const struct sock_filter *filter, unsigned int flen)
if (ftest->k == 0)
return -EINVAL;
break;
+ case BPF_ALU | BPF_LSH | BPF_K:
+ case BPF_ALU | BPF_RSH | BPF_K:
+ if (ftest->k >= 32)
+ return -EINVAL;
+ break;
case BPF_LD | BPF_MEM:
case BPF_LDX | BPF_MEM:
case BPF_ST:
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 199/210] batman-adv: Avoid recursive call_rcu for batadv_nc_node |
| Message-ID | <qW62X-3zN-99@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Sven Eckelmann <sven@narfation.org>
[ Upstream commit 44e8e7e91d6c7c7ab19688750f7257292640d1a0 ]
The batadv_nc_node_free_ref function uses call_rcu to delay the free of the
batadv_nc_node object until no (already started) rcu_read_lock is enabled
anymore. This makes sure that no context is still trying to access the
object which should be removed. But batadv_nc_node also contains a
reference to orig_node which must be removed.
The reference drop of orig_node was done in the call_rcu function
batadv_nc_node_free_rcu but should actually be done in the
batadv_nc_node_release function to avoid nested call_rcus. This is
important because rcu_barrier (e.g. batadv_softif_free or batadv_exit) will
not detect the inner call_rcu as relevant for its execution. Otherwise this
barrier will most likely be inserted in the queue before the callback of
the first call_rcu was executed. The caller of rcu_barrier will therefore
continue to run before the inner call_rcu callback finished.
Fixes: d56b1705e28c ("batman-adv: network coding - detect coding nodes and remove these after timeout")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Marek Lindner <mareklindner@neomailbox.ch>
Signed-off-by: Antonio Quartulli <a@unstable.cc>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
net/batman-adv/network-coding.c | 19 ++++++++-----------
1 file changed, 8 insertions(+), 11 deletions(-)
diff --git a/net/batman-adv/network-coding.c b/net/batman-adv/network-coding.c
index 65adf30..4022fda 100644
--- a/net/batman-adv/network-coding.c
+++ b/net/batman-adv/network-coding.c
@@ -175,28 +175,25 @@ void batadv_nc_init_orig(struct batadv_orig_node *orig_node)
}
/**
- * batadv_nc_node_free_rcu - rcu callback to free an nc node and remove
- * its refcount on the orig_node
- * @rcu: rcu pointer of the nc node
+ * batadv_nc_node_release - release nc_node from lists and queue for free after
+ * rcu grace period
+ * @nc_node: the nc node to free
*/
-static void batadv_nc_node_free_rcu(struct rcu_head *rcu)
+static void batadv_nc_node_release(struct batadv_nc_node *nc_node)
{
- struct batadv_nc_node *nc_node;
-
- nc_node = container_of(rcu, struct batadv_nc_node, rcu);
batadv_orig_node_free_ref(nc_node->orig_node);
- kfree(nc_node);
+ kfree_rcu(nc_node, rcu);
}
/**
- * batadv_nc_node_free_ref - decrements the nc node refcounter and possibly
- * frees it
+ * batadv_nc_node_free_ref - decrement the nc node refcounter and possibly
+ * release it
* @nc_node: the nc node to free
*/
static void batadv_nc_node_free_ref(struct batadv_nc_node *nc_node)
{
if (atomic_dec_and_test(&nc_node->refcount))
- call_rcu(&nc_node->rcu, batadv_nc_node_free_rcu);
+ batadv_nc_node_release(nc_node);
}
/**
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 147/210] MAINTAINERS: return arch/sh to maintained state, with new maintainers |
| Message-ID | <qW62X-3zN-105@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know. ---8<------------------------------------------------------------ From: Rich Felker <dalias@libc.org> commit 114bf37e04d839b555b3dc460b5e6ce156f49cf0 upstream. Add Yoshinori Sato and Rich Felker as maintainers for arch/sh (SUPERH). Signed-off-by: Rich Felker <dalias@libc.org> Signed-off-by: Yoshinori Sato <ysato@users.sourceforge.jp> Acked-by: D. Jeff Dionne <jeff@uClinux.org> Acked-by: Rob Landley <rob@landley.net> Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org> Acked-by: Simon Horman <horms+renesas@verge.net.au> Acked-by: Geert Uytterhoeven <geert+renesas@glider.be> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org> Signed-off-by: Kamal Mostafa <kamal@canonical.com> --- MAINTAINERS | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/MAINTAINERS b/MAINTAINERS index f69bfcd..052550c 100644 --- a/MAINTAINERS +++ b/MAINTAINERS @@ -9250,9 +9250,11 @@ S: Maintained F: drivers/net/ethernet/dlink/sundance.c SUPERH +M: Yoshinori Sato <ysato@users.sourceforge.jp> +M: Rich Felker <dalias@libc.org> L: linux-sh@vger.kernel.org Q: http://patchwork.kernel.org/project/linux-sh/list/ -S: Orphan +S: Maintained F: Documentation/sh/ F: arch/sh/ F: drivers/sh/ -- 1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 012/210] drm/radeon: call hpd_irq_event on resume |
| Message-ID | <qW62X-3zN-109@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know. ---8<------------------------------------------------------------ From: Alex Deucher <alexander.deucher@amd.com> commit dbb17a21c131eca94eb31136eee9a7fe5aff00d9 upstream. Need to call this on resume if displays changes during suspend in order to properly be notified of changes. Signed-off-by: Alex Deucher <alexander.deucher@amd.com> Signed-off-by: Kamal Mostafa <kamal@canonical.com> --- drivers/gpu/drm/radeon/radeon_device.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/gpu/drm/radeon/radeon_device.c b/drivers/gpu/drm/radeon/radeon_device.c index b3dfefb..8d09074 100644 --- a/drivers/gpu/drm/radeon/radeon_device.c +++ b/drivers/gpu/drm/radeon/radeon_device.c @@ -1729,6 +1729,7 @@ int radeon_resume_kms(struct drm_device *dev, bool resume, bool fbcon) } drm_kms_helper_poll_enable(dev); + drm_helper_hpd_irq_event(dev); /* set the power state here in case we are a PX system or headless */ if ((rdev->pm.pm_method == PM_METHOD_DPM) && rdev->pm.dpm_enabled) -- 1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 103/210] x86/mm: Improve switch_mm() barrier comments |
| Message-ID | <qW62X-3zN-107@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Andy Lutomirski <luto@kernel.org>
commit 4eaffdd5a5fe6ff9f95e1ab4de1ac904d5e0fa8b upstream.
My previous comments were still a bit confusing and there was a
typo. Fix it up.
Reported-by: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Andy Lutomirski <luto@kernel.org>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Brian Gerst <brgerst@gmail.com>
Cc: Dave Hansen <dave.hansen@linux.intel.com>
Cc: Denys Vlasenko <dvlasenk@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Rik van Riel <riel@redhat.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Fixes: 71b3c126e611 ("x86/mm: Add barriers and document switch_mm()-vs-flush synchronization")
Link: http://lkml.kernel.org/r/0a0b43cdcdd241c5faaaecfbcc91a155ddedc9a1.1452631609.git.luto@kernel.org
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/x86/include/asm/mmu_context.h | 15 ++++++++-------
1 file changed, 8 insertions(+), 7 deletions(-)
diff --git a/arch/x86/include/asm/mmu_context.h b/arch/x86/include/asm/mmu_context.h
index 2962f62..2917a4d 100644
--- a/arch/x86/include/asm/mmu_context.h
+++ b/arch/x86/include/asm/mmu_context.h
@@ -105,14 +105,16 @@ static inline void switch_mm(struct mm_struct *prev, struct mm_struct *next,
* be sent, and CPU 0's TLB will contain a stale entry.)
*
* The bad outcome can occur if either CPU's load is
- * reordered before that CPU's store, so both CPUs much
+ * reordered before that CPU's store, so both CPUs must
* execute full barriers to prevent this from happening.
*
* Thus, switch_mm needs a full barrier between the
* store to mm_cpumask and any operation that could load
- * from next->pgd. This barrier synchronizes with
- * remote TLB flushers. Fortunately, load_cr3 is
- * serializing and thus acts as a full barrier.
+ * from next->pgd. TLB fills are special and can happen
+ * due to instruction fetches or for no reason at all,
+ * and neither LOCK nor MFENCE orders them.
+ * Fortunately, load_cr3() is serializing and gives the
+ * ordering guarantee we need.
*
*/
load_cr3(next->pgd);
@@ -154,9 +156,8 @@ static inline void switch_mm(struct mm_struct *prev, struct mm_struct *next,
* tlb flush IPI delivery. We must reload CR3
* to make sure to use no freed page tables.
*
- * As above, this is a barrier that forces
- * TLB repopulation to be ordered after the
- * store to mm_cpumask.
+ * As above, load_cr3() is serializing and orders TLB
+ * fills with respect to the mm_cpumask write.
*/
load_cr3(next->pgd);
trace_tlb_flush(TLB_FLUSH_ON_TASK_SWITCH, TLB_FLUSH_ALL);
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:30 +0100 |
| Subject | [PATCH 3.19.y-ckt 003/210] hotplugcpu: Avoid deadlocks by waking active_writer |
| Message-ID | <qW62X-3zN-111@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: David Hildenbrand <dahi@linux.vnet.ibm.com>
commit 87af9e7ff9d909e70a006ca0974466e2a1d8db0a upstream.
Commit b2c4623dcd07 ("rcu: More on deadlock between CPU hotplug and expedited
grace periods") introduced another problem that can easily be reproduced by
starting/stopping cpus in a loop.
E.g.:
for i in `seq 5000`; do
echo 1 > /sys/devices/system/cpu/cpu1/online
echo 0 > /sys/devices/system/cpu/cpu1/online
done
Will result in:
INFO: task /cpu_start_stop:1 blocked for more than 120 seconds.
Call Trace:
([<00000000006a028e>] __schedule+0x406/0x91c)
[<0000000000130f60>] cpu_hotplug_begin+0xd0/0xd4
[<0000000000130ff6>] _cpu_up+0x3e/0x1c4
[<0000000000131232>] cpu_up+0xb6/0xd4
[<00000000004a5720>] device_online+0x80/0xc0
[<00000000004a57f0>] online_store+0x90/0xb0
...
And a deadlock.
Problem is that if the last ref in put_online_cpus() can't get the
cpu_hotplug.lock the puts_pending count is incremented, but a sleeping
active_writer might never be woken up, therefore never exiting the loop in
cpu_hotplug_begin().
This fix removes puts_pending and turns refcount into an atomic variable. We
also introduce a wait queue for the active_writer, to avoid possible races and
use-after-free. There is no need to take the lock in put_online_cpus() anymore.
Can't reproduce it with this fix.
Signed-off-by: David Hildenbrand <dahi@linux.vnet.ibm.com>
Signed-off-by: Paul E. McKenney <paulmck@linux.vnet.ibm.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
kernel/cpu.c | 56 +++++++++++++++++++++++---------------------------------
1 file changed, 23 insertions(+), 33 deletions(-)
diff --git a/kernel/cpu.c b/kernel/cpu.c
index 5d22023..1972b16 100644
--- a/kernel/cpu.c
+++ b/kernel/cpu.c
@@ -58,22 +58,23 @@ static int cpu_hotplug_disabled;
static struct {
struct task_struct *active_writer;
- struct mutex lock; /* Synchronizes accesses to refcount, */
+ /* wait queue to wake up the active_writer */
+ wait_queue_head_t wq;
+ /* verifies that no writer will get active while readers are active */
+ struct mutex lock;
/*
* Also blocks the new readers during
* an ongoing cpu hotplug operation.
*/
- int refcount;
- /* And allows lockless put_online_cpus(). */
- atomic_t puts_pending;
+ atomic_t refcount;
#ifdef CONFIG_DEBUG_LOCK_ALLOC
struct lockdep_map dep_map;
#endif
} cpu_hotplug = {
.active_writer = NULL,
+ .wq = __WAIT_QUEUE_HEAD_INITIALIZER(cpu_hotplug.wq),
.lock = __MUTEX_INITIALIZER(cpu_hotplug.lock),
- .refcount = 0,
#ifdef CONFIG_DEBUG_LOCK_ALLOC
.dep_map = {.name = "cpu_hotplug.lock" },
#endif
@@ -86,15 +87,6 @@ static struct {
#define cpuhp_lock_acquire() lock_map_acquire(&cpu_hotplug.dep_map)
#define cpuhp_lock_release() lock_map_release(&cpu_hotplug.dep_map)
-static void apply_puts_pending(int max)
-{
- int delta;
-
- if (atomic_read(&cpu_hotplug.puts_pending) >= max) {
- delta = atomic_xchg(&cpu_hotplug.puts_pending, 0);
- cpu_hotplug.refcount -= delta;
- }
-}
void get_online_cpus(void)
{
@@ -103,8 +95,7 @@ void get_online_cpus(void)
return;
cpuhp_lock_acquire_read();
mutex_lock(&cpu_hotplug.lock);
- apply_puts_pending(65536);
- cpu_hotplug.refcount++;
+ atomic_inc(&cpu_hotplug.refcount);
mutex_unlock(&cpu_hotplug.lock);
}
EXPORT_SYMBOL_GPL(get_online_cpus);
@@ -116,8 +107,7 @@ bool try_get_online_cpus(void)
if (!mutex_trylock(&cpu_hotplug.lock))
return false;
cpuhp_lock_acquire_tryread();
- apply_puts_pending(65536);
- cpu_hotplug.refcount++;
+ atomic_inc(&cpu_hotplug.refcount);
mutex_unlock(&cpu_hotplug.lock);
return true;
}
@@ -125,20 +115,18 @@ EXPORT_SYMBOL_GPL(try_get_online_cpus);
void put_online_cpus(void)
{
+ int refcount;
+
if (cpu_hotplug.active_writer == current)
return;
- if (!mutex_trylock(&cpu_hotplug.lock)) {
- atomic_inc(&cpu_hotplug.puts_pending);
- cpuhp_lock_release();
- return;
- }
- if (WARN_ON(!cpu_hotplug.refcount))
- cpu_hotplug.refcount++; /* try to fix things up */
+ refcount = atomic_dec_return(&cpu_hotplug.refcount);
+ if (WARN_ON(refcount < 0)) /* try to fix things up */
+ atomic_inc(&cpu_hotplug.refcount);
+
+ if (refcount <= 0 && waitqueue_active(&cpu_hotplug.wq))
+ wake_up(&cpu_hotplug.wq);
- if (!--cpu_hotplug.refcount && unlikely(cpu_hotplug.active_writer))
- wake_up_process(cpu_hotplug.active_writer);
- mutex_unlock(&cpu_hotplug.lock);
cpuhp_lock_release();
}
@@ -168,18 +156,20 @@ EXPORT_SYMBOL_GPL(put_online_cpus);
*/
void cpu_hotplug_begin(void)
{
- cpu_hotplug.active_writer = current;
+ DEFINE_WAIT(wait);
+ cpu_hotplug.active_writer = current;
cpuhp_lock_acquire();
+
for (;;) {
mutex_lock(&cpu_hotplug.lock);
- apply_puts_pending(1);
- if (likely(!cpu_hotplug.refcount))
- break;
- __set_current_state(TASK_UNINTERRUPTIBLE);
+ prepare_to_wait(&cpu_hotplug.wq, &wait, TASK_UNINTERRUPTIBLE);
+ if (likely(!atomic_read(&cpu_hotplug.refcount)))
+ break;
mutex_unlock(&cpu_hotplug.lock);
schedule();
}
+ finish_wait(&cpu_hotplug.wq, &wait);
}
void cpu_hotplug_done(void)
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:40 +0100 |
| Subject | [PATCH 3.19.y-ckt 166/210] power: test_power: correctly handle empty writes |
| Message-ID | <qW6cx-3Fb-1@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Sasha Levin <sasha.levin@oracle.com>
commit 6b9140f39c2aaf76791197fbab0839c0e4af56e8 upstream.
Writing 0 length data into test_power makes it access an invalid array
location and kill the system.
Fixes: f17ef9b2d ("power: Make test_power driver more dynamic.")
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
Signed-off-by: Sebastian Reichel <sre@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/power/test_power.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/power/test_power.c b/drivers/power/test_power.c
index 0152f35..b47bd17 100644
--- a/drivers/power/test_power.c
+++ b/drivers/power/test_power.c
@@ -275,6 +275,8 @@ static int map_get_value(struct battery_property_map *map, const char *key,
buf[MAX_KEYLENGTH-1] = '\0';
cr = strnlen(buf, MAX_KEYLENGTH) - 1;
+ if (cr < 0)
+ return def_val;
if (buf[cr] == '\n')
buf[cr] = '\0';
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:40 +0100 |
| Subject | [PATCH 3.19.y-ckt 185/210] connector: bump skb->users before callback invocation |
| Message-ID | <qW6cx-3Fb-3@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Florian Westphal <fw@strlen.de>
[ Upstream commit 55285bf09427c5abf43ee1d54e892f352092b1f1 ]
Dmitry reports memleak with syskaller program.
Problem is that connector bumps skb usecount but might not invoke callback.
So move skb_get to where we invoke the callback.
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/connector/connector.c | 11 +++--------
1 file changed, 3 insertions(+), 8 deletions(-)
diff --git a/drivers/connector/connector.c b/drivers/connector/connector.c
index 30f5228..c19e7fc 100644
--- a/drivers/connector/connector.c
+++ b/drivers/connector/connector.c
@@ -178,26 +178,21 @@ static int cn_call_callback(struct sk_buff *skb)
*
* It checks skb, netlink header and msg sizes, and calls callback helper.
*/
-static void cn_rx_skb(struct sk_buff *__skb)
+static void cn_rx_skb(struct sk_buff *skb)
{
struct nlmsghdr *nlh;
- struct sk_buff *skb;
int len, err;
- skb = skb_get(__skb);
-
if (skb->len >= NLMSG_HDRLEN) {
nlh = nlmsg_hdr(skb);
len = nlmsg_len(nlh);
if (len < (int)sizeof(struct cn_msg) ||
skb->len < nlh->nlmsg_len ||
- len > CONNECTOR_MAX_MSG_SIZE) {
- kfree_skb(skb);
+ len > CONNECTOR_MAX_MSG_SIZE)
return;
- }
- err = cn_call_callback(skb);
+ err = cn_call_callback(skb_get(skb));
if (err < 0)
kfree_skb(skb);
}
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:40 +0100 |
| Subject | [PATCH 3.19.y-ckt 188/210] vxlan: fix test which detect duplicate vxlan iface |
| Message-ID | <qW6cy-3Fb-7@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Nicolas Dichtel <nicolas.dichtel@6wind.com>
[ Upstream commit 07b9b37c227cb8d88d478b4a9c5634fee514ede1 ]
When a vxlan interface is created, the driver checks that there is not
another vxlan interface with the same properties. To do this, it checks
the existing vxlan udp socket. Since commit 1c51a9159dde, the creation of
the vxlan socket is done only when the interface is set up, thus it breaks
that test.
Example:
$ ip l a vxlan10 type vxlan id 10 group 239.0.0.10 dev eth0 dstport 0
$ ip l a vxlan11 type vxlan id 10 group 239.0.0.10 dev eth0 dstport 0
$ ip -br l | grep vxlan
vxlan10 DOWN f2:55:1c:6a:fb:00 <BROADCAST,MULTICAST>
vxlan11 DOWN 7a:cb:b9:38:59:0d <BROADCAST,MULTICAST>
Instead of checking sockets, let's loop over the vxlan iface list.
Fixes: 1c51a9159dde ("vxlan: fix race caused by dropping rtnl_unlock")
Reported-by: Thomas Faivre <thomas.faivre@6wind.com>
Signed-off-by: Nicolas Dichtel <nicolas.dichtel@6wind.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/vxlan.c | 12 ++++++++----
include/net/vxlan.h | 5 +++++
2 files changed, 13 insertions(+), 4 deletions(-)
diff --git a/drivers/net/vxlan.c b/drivers/net/vxlan.c
index d1494f7..3f97a9f 100644
--- a/drivers/net/vxlan.c
+++ b/drivers/net/vxlan.c
@@ -2432,7 +2432,7 @@ static int vxlan_newlink(struct net *src_net, struct net_device *dev,
struct nlattr *tb[], struct nlattr *data[])
{
struct vxlan_net *vn = net_generic(src_net, vxlan_net_id);
- struct vxlan_dev *vxlan = netdev_priv(dev);
+ struct vxlan_dev *vxlan = netdev_priv(dev), *tmp;
struct vxlan_rdst *dst = &vxlan->default_dst;
__u32 vni;
int err;
@@ -2557,9 +2557,13 @@ static int vxlan_newlink(struct net *src_net, struct net_device *dev,
nla_get_u8(data[IFLA_VXLAN_UDP_ZERO_CSUM6_RX]))
vxlan->flags |= VXLAN_F_UDP_ZERO_CSUM6_RX;
- if (vxlan_find_vni(src_net, vni, use_ipv6 ? AF_INET6 : AF_INET,
- vxlan->dst_port)) {
- pr_info("duplicate VNI %u\n", vni);
+ list_for_each_entry(tmp, &vn->vxlan_list, next) {
+ if (tmp->default_dst.remote_vni == vni &&
+ (tmp->default_dst.remote_ip.sa.sa_family == AF_INET6 ||
+ tmp->saddr.sa.sa_family == AF_INET6) == use_ipv6 &&
+ tmp->dst_port == vxlan->dst_port &&
+ (tmp->flags & VXLAN_F_RCV_FLAGS) ==
+ (vxlan->flags & VXLAN_F_RCV_FLAGS))
return -EEXIST;
}
diff --git a/include/net/vxlan.h b/include/net/vxlan.h
index 903461a..2f3572f 100644
--- a/include/net/vxlan.h
+++ b/include/net/vxlan.h
@@ -43,6 +43,11 @@ struct vxlan_sock {
#define VXLAN_F_UDP_ZERO_CSUM6_TX 0x80
#define VXLAN_F_UDP_ZERO_CSUM6_RX 0x100
+/* Flags that are used in the receive path. These flags must match in
+ * order for a socket to be shareable
+ */
+#define VXLAN_F_RCV_FLAGS VXLAN_F_UDP_ZERO_CSUM6_RX
+
struct vxlan_sock *vxlan_sock_add(struct net *net, __be16 port,
vxlan_rcv_t *rcv, void *data,
bool no_share, u32 flags);
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Kamal Mostafa <kamal@canonical.com> |
|---|---|
| Date | 2016-01-29 02:40 +0100 |
| Subject | [PATCH 3.19.y-ckt 189/210] net: sctp: prevent writes to cookie_hmac_alg from accessing invalid memory |
| Message-ID | <qW6cx-3Fb-5@gated-at.bofh.it> |
| In reply to | #1321181 |
3.19.8-ckt14 -stable review patch. If anyone has any objections, please let me know.
---8<------------------------------------------------------------
From: Sasha Levin <sasha.levin@oracle.com>
[ Upstream commit 320f1a4a175e7cd5d3f006f92b4d4d3e2cbb7bb5 ]
proc_dostring() needs an initialized destination string, while the one
provided in proc_sctp_do_hmac_alg() contains stack garbage.
Thus, writing to cookie_hmac_alg would strlen() that garbage and end up
accessing invalid memory.
Fixes: 3c68198e7 ("sctp: Make hmac algorithm selection for cookie generation dynamic")
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
net/sctp/sysctl.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/sctp/sysctl.c b/net/sctp/sysctl.c
index 2e9ada1..5b6e757 100644
--- a/net/sctp/sysctl.c
+++ b/net/sctp/sysctl.c
@@ -324,7 +324,7 @@ static int proc_sctp_do_hmac_alg(struct ctl_table *ctl, int write,
struct ctl_table tbl;
bool changed = false;
char *none = "none";
- char tmp[8];
+ char tmp[8] = {0};
int ret;
memset(&tbl, 0, sizeof(struct ctl_table));
--
1.9.1
[toc] | [prev] | [next] | [standalone]
Page 3 of 11 — ← Prev page 1 2 [3] 4 5 … 11 Next page →
Back to top | Article view | linux.kernel
csiph-web