Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1326014 > unrolled thread

[3.16.y-ckt stable] Linux 3.16.7-ckt24 stable review

Started byLuis Henriques <luis.henriques@canonical.com>
First post2016-02-03 23:40 +0100
Last post2016-02-04 01:10 +0100
Articles 19 on this page of 179 — 1 participant

Back to article view | Back to linux.kernel


Contents

  [3.16.y-ckt stable] Linux 3.16.7-ckt24 stable review Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 179/180] cifs: Ratelimit kernel log messages Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 017/180] xen-netfront: print correct number of queues Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 168/180] batman-adv: Drop immediate batadv_neigh_node free function Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 159/180] um: Fix build error and kconfig for i386 Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 120/180] crypto: af_alg - Disallow bind/setkey/... after accept(2) Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 170/180] batman-adv: Drop immediate batadv_hard_iface free function Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 057/180] rtlwifi: rtl8192cu: Add missing parameter setup Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 105/180] cifs: fix race between call_async() and reconnect() Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 046/180] arm64: kernel: enforce pmuserenr_el0 initialization and restore Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 050/180] udf: limit the maximum number of indirect extents in a row Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 020/180] sctp: Prevent soft lockup when sctp_accept() is called during a timeout event Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 156/180] power: test_power: correctly handle empty writes Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 160/180] ipv6: tcp: add rcu locking in tcp_v6_send_synack() Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 055/180] rtlwifi: rtl8192se: Fix module parameter initialization Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 010/180] bonding: Prevent IPv6 link local address on enslaved devices Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 071/180] x86/xen: don't reset vcpu_info on a cancelled suspend Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 098/180] x86/mm: Improve switch_mm() barrier comments Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 082/180] drm/nouveau/kms: take mode_config mutex in connector hotplug path Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 112/180] zram/zcomp: use GFP_NOIO to allocate streams Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 025/180] [media] media: dvb-core: Don't force CAN_INVERSION_AUTO in oneshot mode Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 004/180] connector: bump skb->users before callback invocation Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 006/180] bridge: Only call /sbin/bridge-stp for the initial network namespace Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 092/180] ALSA: seq: Fix race at timer setup and close Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 171/180] batman-adv: Drop immediate orig_node free function Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 180/180] HID: usbhid: fix recursive deadlock Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 040/180] powerpc: Make value-returning atomics fully ordered Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 149/180] mtd: nand: remove unused and buggy get_platform_nandchip() helper function Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 001/180] drm/nouveau/nv46: Change mc subdev oclass from nv44 to nv4c Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 036/180] EDAC: Fix the leak of mci->bus->name when bus_register fails Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 014/180] team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 096/180] scripts/recordmcount.pl: support data in text section on powerpc Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 077/180] locks: fix unlock when fcntl_setlk races with a close Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 054/180] rtlwifi: rtl8192de: Fix incorrect module parameter descriptions Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 030/180] xhci: refuse loading if nousb is used Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 143/180] SCSI: initio: remove duplicate module device table Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:40 +0100
    [PATCH 3.16.y-ckt 155/180] perf/x86: Fix filter_events() bug with event mappings Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 162/180] Btrfs: clean up an error code in btrfs_init_space_info() Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 164/180] batman-adv: Avoid recursive call_rcu for batadv_bla_claim Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 175/180] net/mlx4: Remove unused macro Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 174/180] IB/mlx4: Initialize hop_limit when creating address handle Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 157/180] firmware: actually return NULL on failed request_firmware_nowait() Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 163/180] bridge: fix lockdep addr_list_lock false positive splat Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 165/180] batman-adv: Avoid recursive call_rcu for batadv_nc_node Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 166/180] batman-adv: fix potential TT client + orig-node memory leak Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 167/180] batman-adv: Drop immediate batadv_orig_ifinfo free function Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 176/180] arm64: fix building without CONFIG_UID16 Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 173/180] mmc: debugfs: correct wrong voltage value Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 161/180] mmc: sd: limit SD card power limit according to cards capabilities Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 154/180] kconfig: return 'false' instead of 'no' in bool function Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 169/180] batman-adv: Drop immediate neigh_ifinfo free function Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 153/180] sysrq: Fix warning in sysrq generated crash. Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 152/180] x86/LDT: Print the real LDT base address Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 172/180] printk: help pr_debug and pr_devel to optimize out arguments Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 158/180] target: Fix a memory leak in target_dev_lba_map_store() Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 177/180] mn10300: Select CONFIG_HAVE_UID16 to fix build failure Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 178/180] openrisc: fix CONFIG_UID16 setting Luis Henriques <luis.henriques@canonical.com> - 2016-02-03 23:50 +0100
    [PATCH 3.16.y-ckt 151/180] pinctrl: bcm2835: Fix memory leak in error path Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:00 +0100
    [PATCH 3.16.y-ckt 141/180] drm/i915: On fb alloc failure, unref gem object where it gets refed Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:00 +0100
    [PATCH 3.16.y-ckt 145/180] clk: st: avoid uninitialized variable use Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:00 +0100
    [PATCH 3.16.y-ckt 144/180] clk: xgene: Fix divider with non-zero shift value Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:00 +0100
    [PATCH 3.16.y-ckt 147/180] mtd: nand: fix ONFI parameter page layout Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:00 +0100
    [PATCH 3.16.y-ckt 146/180] ath9k_htc: check for underflow in ath9k_htc_rx_msg() Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:00 +0100
    [PATCH 3.16.y-ckt 148/180] mtd: nand: denali: add missing nand_release() call in denali_remove() Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:00 +0100
    [PATCH 3.16.y-ckt 138/180] MAINTAINERS: return arch/sh to maintained state, with new maintainers Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:10 +0100
    [PATCH 3.16.y-ckt 142/180] [media] rc: allow rc modules to be loaded if rc-main is not a module Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:10 +0100
    [PATCH 3.16.y-ckt 134/180] ideapad-laptop: Add Lenovo ideapad Y700-17ISK to no_hw_rfkill dmi list Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:10 +0100
    [PATCH 3.16.y-ckt 133/180] IB/qib: Support creating qps with GFP_NOIO flag Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:10 +0100
    [PATCH 3.16.y-ckt 052/180] USB: cp210x: add ID for ELV Marble Sound Board 1 Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:10 +0100
    [PATCH 3.16.y-ckt 140/180] drm/i915: avoid deadlock on failure paths in __intel_framebuffer_create() Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:10 +0100
    [PATCH 3.16.y-ckt 139/180] ideapad-laptop: Add Lenovo Yoga 700 to no_hw_rfkill dmi list Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:10 +0100
    [PATCH 3.16.y-ckt 137/180] ocfs2: NFS hangs in __ocfs2_cluster_lock due to race with ocfs2_unblock_lock Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:10 +0100
    [PATCH 3.16.y-ckt 135/180] iscsi-target: Fix potential dead-lock during node acl delete Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:10 +0100
    [PATCH 3.16.y-ckt 129/180] ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0 Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:10 +0100
    [PATCH 3.16.y-ckt 136/180] ALSA: timer: Handle disconnection more safely Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:10 +0100
    [PATCH 3.16.y-ckt 115/180] memcg: only free spare array when readers are done Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 127/180] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 118/180] printk: do cond_resched() between lines while outputting to consoles Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 110/180] ocfs2/dlm: ignore cleaning the migration mle that is inuse Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 107/180] m32r: fix m32104ut_defconfig build fail Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 124/180] crypto: af_alg - Allow af_af_alg_release_parent to be called on nokey path Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 111/180] ALSA: timer: Harden slave timer list handling Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 132/180] IB/qib: fix mcast detach when qp not attached Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 117/180] kernel/panic.c: turn off locks debug before releasing console lock Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 114/180] mm: soft-offline: check return value in second __get_any_page() call Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 083/180] x86/mm: Add barriers and document switch_mm()-vs-flush synchronization Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 123/180] crypto: hash - Add crypto_ahash_has_setkey Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 128/180] ALSA: seq: Fix snd_seq_call_port_info_ioctl in compat mode Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 116/180] panic: release stale console lock to always get the logbuf printed out Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 126/180] ALSA: hrtimer: Fix stall by hrtimer_cancel() Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 119/180] ALSA: hda - Fix bass pin fixup for ASUS N550JX Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 122/180] crypto: af_alg - Add nokey compatibility path Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 130/180] crypto: algif_skcipher - Load TX SG list after waiting Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 131/180] crypto: crc32c - Fix crc32c soft dependency Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 125/180] crypto: af_alg - Forbid bind(2) when nokey child sockets are present Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 113/180] zram: try vmalloc() after kmalloc() Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 121/180] crypto: af_alg - Fix socket double-free when accept fails Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 090/180] x86/reboot/quirks: Add iMac10,1 to pci_reboot_dmi_table[] Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:20 +0100
    [PATCH 3.16.y-ckt 093/180] virtio_balloon: fix race by fill and leak Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 084/180] x86/boot: Double BOOT_HEAP_SIZE to 64KB Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 087/180] xfs: handle dquot buffer readahead in log recovery correctly Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 103/180] ALSA: timer: Fix race among timer ioctls Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 075/180] PCI: host: Mark PCIe/PCI (MSI) IRQ cascade handlers as IRQF_NO_THREAD Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 095/180] parisc: Fix __ARCH_SI_PREAMBLE_SIZE Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 094/180] virtio_balloon: fix race between migration and ballooning Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 104/180] sparc64: fix incorrect sign extension in sys_sparc64_personality Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 085/180] s390: fix normalization bug in exception table sorting Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 088/180] clocksource/drivers/vt8500: Increase the minimum delta Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 100/180] dmaengine: dw: fix cyclic transfer setup Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 091/180] ALSA: seq: Fix missing NULL check at remove_events ioctl Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 101/180] dmaengine: dw: fix cyclic transfer callbacks Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 097/180] powerpc/module: Handle R_PPC64_ENTRY relocations Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 108/180] dma-debug: switch check from _text to _stext Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 106/180] cifs_dbg() outputs an uninitialized buffer in cifs_readdir() Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 089/180] Input: elantech - mark protocols v2 and v3 as semi-mt Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 078/180] ASoC: compress: Fix compress device direction check Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 102/180] mmc: mmci: fix an ages old detection error Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 086/180] xfs: inode recovery readahead can race with inode buffer creation Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 109/180] scripts/bloat-o-meter: fix python3 syntax error Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:30 +0100
    [PATCH 3.16.y-ckt 068/180] wlcore/wl12xx: spi: fix NULL pointer dereference (Oops) Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:40 +0100
    [PATCH 3.16.y-ckt 079/180] dm snapshot: fix hung bios when copy error occurs Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:40 +0100
    [PATCH 3.16.y-ckt 067/180] bcache: Change refill_dirty() to always scan entire disk if necessary Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:40 +0100
    [PATCH 3.16.y-ckt 069/180] Input: i8042 - add Fujitsu Lifebook U745 to the nomux list Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:40 +0100
    [PATCH 3.16.y-ckt 072/180] udf: Prevent buffer overrun with multi-byte characters Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:40 +0100
    [PATCH 3.16.y-ckt 070/180] libxfs: pack the agfl header structure so XFS_AGFL_SIZE is correct Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:40 +0100
    [PATCH 3.16.y-ckt 073/180] udf: Check output buffer length when converting name to CS0 Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:40 +0100
    [PATCH 3.16.y-ckt 076/180] iwlwifi: update and fix 7265 series PCI IDs Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:40 +0100
    [PATCH 3.16.y-ckt 080/180] uml: fix hostfs mknod() Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:40 +0100
    [PATCH 3.16.y-ckt 074/180] PCI: Fix minimum allocation address overwrite Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:40 +0100
    [PATCH 3.16.y-ckt 081/180] uml: flush stdout before forking Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:40 +0100
    [PATCH 3.16.y-ckt 060/180] bcache: fix a livelock when we cause a huge number of cache misses Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 065/180] bcache: allows use of register in udev to avoid "device_busy" error. Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 047/180] drm/radeon: clean up fujitsu quirks Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 064/180] bcache: unregister reboot notifier if bcache fails to unregister device Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 056/180] rtlwifi: rtl8192ce: Fix handling of module parameters Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 063/180] bcache: fix a leak in bch_cached_dev_run() Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 049/180] mmc: sdhci: Fix sdhci_runtime_pm_bus_on/off() Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 058/180] NFSv4: Don't perform cached access checks before we've OPENed the file Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 062/180] bcache: clear BCACHE_DEV_UNLINK_DONE flag when attaching a backing device Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 044/180] futex: Drop refcount if requeue_pi() acquired the rtmutex Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 066/180] bcache: prevent crash on changing writeback_running Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 053/180] posix-clock: Fix return code on the poll method's error path Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 048/180] mmc: sdio: Fix invalid vdd in voltage switch power cycle Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 042/180] dm space map metadata: remove unused variable in brb_pop() Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 061/180] bcache: Add a cond_resched() call to gc Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 059/180] NFS: Fix attribute cache revalidation Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 051/180] nfs: Fix race in __update_open_stateid() Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 00:50 +0100
    [PATCH 3.16.y-ckt 016/180] xen-netfront: respect user provided max_queues Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 028/180] KVM: x86: correctly print #AC in traces Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 022/180] sctp: start t5 timer only when peer rwnd is 0 and local state is SHUTDOWN_PENDING Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 029/180] drm/radeon: call hpd_irq_event on resume Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 021/180] sctp: convert sack_needed and sack_generation to bits Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 039/180] arm64: mm: ensure that the zero page is visible to the page table walker Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 026/180] tools lib traceevent: Fix output of %llu for 64 bit values read on 32 bit machines Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 015/180] xen-netback: respect user provided max_queues Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 035/180] wlcore/wl12xx: spi: fix oops on firmware load Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 023/180] nfs: Fix unused variable error Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 041/180] powerpc: Make {cmp}xchg* and their atomic_ versions fully ordered Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 031/180] arm64: Clear out any singlestep state on a ptrace detach operation Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 024/180] [media] gspca: ov534/topro: prevent a division by 0 Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 034/180] rtlwifi: fix memory leak for USB device Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 043/180] dm thin: fix race condition when destroying thin pool workqueue Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 045/180] arm64: mdscr_el1: avoid exposing DCC to userspace Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 033/180] Bluetooth: Add support of Toshiba Broadcom based devices Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 032/180] time: Avoid signed overflow in timekeeping_get_ns() Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 027/180] KVM: x86: expose MSR_TSC_AUX to userspace Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 018/180] xen-netfront: update num_queues to real created Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 038/180] EDAC: Robustify workqueues destruction Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 037/180] EDAC, mc_sysfs: Fix freeing bus' name Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 019/180] xfrm: dst_entries_init() per-net dst_ops Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:00 +0100
    [PATCH 3.16.y-ckt 011/180] phonet: properly unshare skbs in phonet_rcv() Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:10 +0100
    [PATCH 3.16.y-ckt 009/180] tcp_yeah: don't set ssthresh below 2 Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:10 +0100
    [PATCH 3.16.y-ckt 012/180] net: bpf: reject invalid shifts Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:10 +0100
    [PATCH 3.16.y-ckt 003/180] sctp: sctp should release assoc when sctp_make_abort_user return NULL in sctp_close Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:10 +0100
    [PATCH 3.16.y-ckt 007/180] vxlan: fix test which detect duplicate vxlan iface Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:10 +0100
    [PATCH 3.16.y-ckt 013/180] ipv6: update skb->csum when CE mark is propagated Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:10 +0100
    [PATCH 3.16.y-ckt 005/180] unix: properly account for FDs passed over unix sockets Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:10 +0100
    [PATCH 3.16.y-ckt 002/180] veth: don’t modify ip_summed; doing so treats packets with bad checksums as good. Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:10 +0100
    [PATCH 3.16.y-ckt 008/180] net: sctp: prevent writes to cookie_hmac_alg from accessing invalid memory Luis Henriques <luis.henriques@canonical.com> - 2016-02-04 01:10 +0100

Page 9 of 9 — ← Prev page 1 2 3 4 5 6 7 8 [9]


#1326285 — [PATCH 3.16.y-ckt 034/180] rtlwifi: fix memory leak for USB device

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:00 +0100
Subject[PATCH 3.16.y-ckt 034/180] rtlwifi: fix memory leak for USB device
Message-ID<qYfv5-Cf-43@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Peter Wu <peter@lekensteyn.nl>

commit 17bc55864f81dd730d05f09b1641312a7990d636 upstream.

Free skb for received frames with a wrong checksum. This can happen
pretty rapidly, exhausting all memory.

This fixes a memleak (detected with kmemleak). Originally found while
using monitor mode, but it also appears during managed mode (once the
link is up).

Signed-off-by: Peter Wu <peter@lekensteyn.nl>
ACKed-by: Larry Finger <Larry.Finger@lwfinger.net>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
[ luis: backported to 3.16:
  - file rename: drivers/net/wireless/realtek/rtlwifi/usb.c ->
    drivers/net/wireless/rtlwifi/usb.c ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/net/wireless/rtlwifi/usb.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/net/wireless/rtlwifi/usb.c b/drivers/net/wireless/rtlwifi/usb.c
index cdd0dd7a938a..194bbe37050d 100644
--- a/drivers/net/wireless/rtlwifi/usb.c
+++ b/drivers/net/wireless/rtlwifi/usb.c
@@ -531,6 +531,8 @@ static void _rtl_usb_rx_process_noagg(struct ieee80211_hw *hw,
 			ieee80211_rx(hw, skb);
 		else
 			dev_kfree_skb_any(skb);
+	} else {
+		dev_kfree_skb_any(skb);
 	}
 }
 

[toc] | [prev] | [next] | [standalone]


#1326286 — [PATCH 3.16.y-ckt 043/180] dm thin: fix race condition when destroying thin pool workqueue

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:00 +0100
Subject[PATCH 3.16.y-ckt 043/180] dm thin: fix race condition when destroying thin pool workqueue
Message-ID<qYfv5-Cf-45@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Nikolay Borisov <kernel@kyup.com>

commit 18d03e8c25f173f4107a40d0b8c24defb6ed69f3 upstream.

When a thin pool is being destroyed delayed work items are
cancelled using cancel_delayed_work(), which doesn't guarantee that on
return the delayed item isn't running.  This can cause the work item to
requeue itself on an already destroyed workqueue.  Fix this by using
cancel_delayed_work_sync() which guarantees that on return the work item
is not running anymore.

Fixes: 905e51b39a555 ("dm thin: commit outstanding data every second")
Fixes: 85ad643b7e7e5 ("dm thin: add timeout to stop out-of-data-space mode holding IO forever")
Signed-off-by: Nikolay Borisov <kernel@kyup.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/md/dm-thin.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/md/dm-thin.c b/drivers/md/dm-thin.c
index e298762d29a6..94ca56b22b52 100644
--- a/drivers/md/dm-thin.c
+++ b/drivers/md/dm-thin.c
@@ -2726,8 +2726,8 @@ static void pool_postsuspend(struct dm_target *ti)
 	struct pool_c *pt = ti->private;
 	struct pool *pool = pt->pool;
 
-	cancel_delayed_work(&pool->waker);
-	cancel_delayed_work(&pool->no_space_timeout);
+	cancel_delayed_work_sync(&pool->waker);
+	cancel_delayed_work_sync(&pool->no_space_timeout);
 	flush_workqueue(pool->wq);
 	(void) commit(pool);
 }

[toc] | [prev] | [next] | [standalone]


#1326287 — [PATCH 3.16.y-ckt 045/180] arm64: mdscr_el1: avoid exposing DCC to userspace

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:00 +0100
Subject[PATCH 3.16.y-ckt 045/180] arm64: mdscr_el1: avoid exposing DCC to userspace
Message-ID<qYfv5-Cf-47@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Will Deacon <will.deacon@arm.com>

commit d8d23fa0f27f3b2942a7bbc7378c7735324ed519 upstream.

We don't want to expose the DCC to userspace, particularly as there is
a kernel console driver for it.

This patch resets mdscr_el1 to disable userspace access to the DCC
registers on the cold boot path.

Signed-off-by: Will Deacon <will.deacon@arm.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 arch/arm64/mm/proc.S | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/mm/proc.S b/arch/arm64/mm/proc.S
index 7736779c9809..63cf428c6834 100644
--- a/arch/arm64/mm/proc.S
+++ b/arch/arm64/mm/proc.S
@@ -186,7 +186,8 @@ ENTRY(__cpu_setup)
 
 	mov	x0, #3 << 20
 	msr	cpacr_el1, x0			// Enable FP/ASIMD
-	msr	mdscr_el1, xzr			// Reset mdscr_el1
+	mov	x0, #1 << 12			// Reset mdscr_el1 and disable
+	msr	mdscr_el1, x0			// access to the DCC from EL0
 	/*
 	 * Memory region attributes for LPAE:
 	 *

[toc] | [prev] | [next] | [standalone]


#1326289 — [PATCH 3.16.y-ckt 033/180] Bluetooth: Add support of Toshiba Broadcom based devices

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:00 +0100
Subject[PATCH 3.16.y-ckt 033/180] Bluetooth: Add support of Toshiba Broadcom based devices
Message-ID<qYfv5-Cf-53@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Dmitry Tunin <hanipouspilot@gmail.com>

commit 1623d0bf847d3b38d8cf24367b3689ba0e3fe2aa upstream.

BugLink: https://bugs.launchpad.net/bugs/1522949

    T: Bus=03 Lev=02 Prnt=02 Port=05 Cnt=02 Dev#= 4 Spd=12 MxCh= 0
    D: Ver= 2.00 Cls=ff(vend.) Sub=01 Prot=01 MxPS=64 #Cfgs= 1
    P: Vendor=0930 ProdID=0225 Rev=01.12
    S: Manufacturer=Broadcom Corp
    S: Product=BCM43142A0
    S: SerialNumber=4CBB58034671
    C: #Ifs= 4 Cfg#= 1 Atr=e0 MxPwr=0mA
    I: If#= 0 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=01 Prot=01 Driver=(none)
    I: If#= 1 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=(none)
    I: If#= 2 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=ff Driver=(none)
    I: If#= 3 Alt= 0 #EPs= 0 Cls=fe(app. ) Sub=01 Prot=01 Driver=(none)

Signed-off-by: Dmitry Tunin <hanipouspilot@gmail.com>
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/bluetooth/btusb.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index 78e20eb1b920..af2ab2e28da0 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -136,6 +136,10 @@ static const struct usb_device_id btusb_table[] = {
 	/* IMC Networks - Broadcom based */
 	{ USB_VENDOR_AND_INTERFACE_INFO(0x13d3, 0xff, 0x01, 0x01) },
 
+	/* Toshiba Corp - Broadcom based */
+	{ USB_VENDOR_AND_INTERFACE_INFO(0x0930, 0xff, 0x01, 0x01),
+	  .driver_info = BTUSB_BCM_PATCHRAM },
+
 	/* Intel Bluetooth USB Bootloader (RAM module) */
 	{ USB_DEVICE(0x8087, 0x0a5a),
 	  .driver_info = BTUSB_INTEL_BOOT | BTUSB_BROKEN_ISOC },

[toc] | [prev] | [next] | [standalone]


#1326290 — [PATCH 3.16.y-ckt 032/180] time: Avoid signed overflow in timekeeping_get_ns()

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:00 +0100
Subject[PATCH 3.16.y-ckt 032/180] time: Avoid signed overflow in timekeeping_get_ns()
Message-ID<qYfv6-Cf-57@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: David Gibson <david@gibson.dropbear.id.au>

commit 35a4933a895927990772ae96fdcfd2f806929ee2 upstream.

1e75fa8 "time: Condense timekeeper.xtime into xtime_sec" replaced a call to
clocksource_cyc2ns() from timekeeping_get_ns() with an open-coded version
of the same logic to avoid keeping a semi-redundant struct timespec
in struct timekeeper.

However, the commit also introduced a subtle semantic change - where
clocksource_cyc2ns() uses purely unsigned math, the new version introduces
a signed temporary, meaning that if (delta * tk->mult) has a 63-bit
overflow the following shift will still give a negative result.  The
choice of 'maxsec' in __clocksource_updatefreq_scale() means this will
generally happen if there's a ~10 minute pause in examining the
clocksource.

This can be triggered on a powerpc KVM guest by stopping it from qemu for
a bit over 10 minutes.  After resuming time has jumped backwards several
minutes causing numerous problems (jiffies does not advance, msleep()s can
be extended by minutes..).  It doesn't happen on x86 KVM guests, because
the guest TSC is effectively frozen while the guest is stopped, which is
not the case for the powerpc timebase.

Obviously an unsigned (64 bit) overflow will only take twice as long as a
signed, 63-bit overflow.  I don't know the time code well enough to know
if that will still cause incorrect calculations, or if a 64-bit overflow
is avoided elsewhere.

Still, an incorrect forwards clock adjustment will cause less trouble than
time going backwards.  So, this patch removes the potential for
intermediate signed overflow.

Suggested-by: Laurent Vivier <lvivier@redhat.com>
Tested-by: Laurent Vivier <lvivier@redhat.com>
Signed-off-by: David Gibson <david@gibson.dropbear.id.au>
Signed-off-by: John Stultz <john.stultz@linaro.org>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 kernel/time/timekeeping.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/kernel/time/timekeeping.c b/kernel/time/timekeeping.c
index 32d8d6aaedb8..268428930c99 100644
--- a/kernel/time/timekeeping.c
+++ b/kernel/time/timekeeping.c
@@ -178,8 +178,7 @@ static inline s64 timekeeping_get_ns(struct timekeeper *tk)
 	/* calculate the delta since the last update_wall_time: */
 	cycle_delta = (cycle_now - clock->cycle_last) & clock->mask;
 
-	nsec = cycle_delta * tk->mult + tk->xtime_nsec;
-	nsec >>= tk->shift;
+	nsec = (cycle_delta * tk->mult + tk->xtime_nsec) >> tk->shift;
 
 	/* If arch requires, add in get_arch_timeoffset() */
 	return nsec + get_arch_timeoffset();

[toc] | [prev] | [next] | [standalone]


#1326291 — [PATCH 3.16.y-ckt 027/180] KVM: x86: expose MSR_TSC_AUX to userspace

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:00 +0100
Subject[PATCH 3.16.y-ckt 027/180] KVM: x86: expose MSR_TSC_AUX to userspace
Message-ID<qYfv6-Cf-61@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Paolo Bonzini <pbonzini@redhat.com>

commit 9dbe6cf941a6fe82933aef565e4095fb10f65023 upstream.

If we do not do this, it is not properly saved and restored across
migration.  Windows notices due to its self-protection mechanisms,
and is very upset about it (blue screen of death).

Cc: Radim Krcmar <rkrcmar@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 arch/x86/kvm/x86.c | 11 ++++++-----
 1 file changed, 6 insertions(+), 5 deletions(-)

diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index 14bd5c079ca3..e9b9fc00da15 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -884,7 +884,7 @@ static u32 msrs_to_save[] = {
 	MSR_CSTAR, MSR_KERNEL_GS_BASE, MSR_SYSCALL_MASK, MSR_LSTAR,
 #endif
 	MSR_IA32_TSC, MSR_IA32_CR_PAT, MSR_VM_HSAVE_PA,
-	MSR_IA32_FEATURE_CONTROL, MSR_IA32_BNDCFGS
+	MSR_IA32_FEATURE_CONTROL, MSR_IA32_BNDCFGS, MSR_TSC_AUX,
 };
 
 static unsigned num_msrs_to_save;
@@ -3983,16 +3983,17 @@ static void kvm_init_msr_list(void)
 
 		/*
 		 * Even MSRs that are valid in the host may not be exposed
-		 * to the guests in some cases.  We could work around this
-		 * in VMX with the generic MSR save/load machinery, but it
-		 * is not really worthwhile since it will really only
-		 * happen with nested virtualization.
+		 * to the guests in some cases.
 		 */
 		switch (msrs_to_save[i]) {
 		case MSR_IA32_BNDCFGS:
 			if (!kvm_x86_ops->mpx_supported())
 				continue;
 			break;
+		case MSR_TSC_AUX:
+			if (!kvm_x86_ops->rdtscp_supported())
+				continue;
+			break;
 		default:
 			break;
 		}

[toc] | [prev] | [next] | [standalone]


#1326292 — [PATCH 3.16.y-ckt 018/180] xen-netfront: update num_queues to real created

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:00 +0100
Subject[PATCH 3.16.y-ckt 018/180] xen-netfront: update num_queues to real created
Message-ID<qYfv6-Cf-59@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Joe Jin <joe.jin@oracle.com>

commit ca88ea1247dfee094e2467a3578eaec9bdf0833a upstream.

Sometimes xennet_create_queues() may failed to created all requested
queues, we need to update num_queues to real created to avoid NULL
pointer dereference.

Signed-off-by: Joe Jin <joe.jin@oracle.com>
Cc: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Cc: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Cc: Wei Liu <wei.liu2@citrix.com>
Cc: Ian Campbell <ian.campbell@citrix.com>
Cc: David S. Miller <davem@davemloft.net>
Reviewed-by: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/net/xen-netfront.c | 14 +++++++-------
 1 file changed, 7 insertions(+), 7 deletions(-)

diff --git a/drivers/net/xen-netfront.c b/drivers/net/xen-netfront.c
index cb68b061754f..567d5c31dfd2 100644
--- a/drivers/net/xen-netfront.c
+++ b/drivers/net/xen-netfront.c
@@ -1804,19 +1804,19 @@ static void xennet_destroy_queues(struct netfront_info *info)
 }
 
 static int xennet_create_queues(struct netfront_info *info,
-				unsigned int num_queues)
+				unsigned int *num_queues)
 {
 	unsigned int i;
 	int ret;
 
-	info->queues = kcalloc(num_queues, sizeof(struct netfront_queue),
+	info->queues = kcalloc(*num_queues, sizeof(struct netfront_queue),
 			       GFP_KERNEL);
 	if (!info->queues)
 		return -ENOMEM;
 
 	rtnl_lock();
 
-	for (i = 0; i < num_queues; i++) {
+	for (i = 0; i < *num_queues; i++) {
 		struct netfront_queue *queue = &info->queues[i];
 
 		queue->id = i;
@@ -1826,7 +1826,7 @@ static int xennet_create_queues(struct netfront_info *info,
 		if (ret < 0) {
 			dev_warn(&info->netdev->dev,
 				 "only created %d queues\n", i);
-			num_queues = i;
+			*num_queues = i;
 			break;
 		}
 
@@ -1836,11 +1836,11 @@ static int xennet_create_queues(struct netfront_info *info,
 			napi_enable(&queue->napi);
 	}
 
-	netif_set_real_num_tx_queues(info->netdev, num_queues);
+	netif_set_real_num_tx_queues(info->netdev, *num_queues);
 
 	rtnl_unlock();
 
-	if (num_queues == 0) {
+	if (*num_queues == 0) {
 		dev_err(&info->netdev->dev, "no queues\n");
 		return -EINVAL;
 	}
@@ -1886,7 +1886,7 @@ static int talk_to_netback(struct xenbus_device *dev,
 	if (info->queues)
 		xennet_destroy_queues(info);
 
-	err = xennet_create_queues(info, num_queues);
+	err = xennet_create_queues(info, &num_queues);
 	if (err < 0)
 		goto destroy_ring;
 

[toc] | [prev] | [next] | [standalone]


#1326293 — [PATCH 3.16.y-ckt 038/180] EDAC: Robustify workqueues destruction

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:00 +0100
Subject[PATCH 3.16.y-ckt 038/180] EDAC: Robustify workqueues destruction
Message-ID<qYfv6-Cf-63@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Borislav Petkov <bp@suse.de>

commit fcd5c4dd8201595d4c598c9cca5e54760277d687 upstream.

EDAC workqueue destruction is really fragile. We cancel delayed work
but if it is still running and requeues itself, we still go ahead and
destroy the workqueue and the queued work explodes when workqueue core
attempts to run it.

Make the destruction more robust by switching op_state to offline so
that requeuing stops. Cancel any pending work *synchronously* too.

  EDAC i7core: Driver loaded.
  general protection fault: 0000 [#1] SMP
  CPU 12
  Modules linked in:
  Supported: Yes
  Pid: 0, comm: kworker/0:1 Tainted: G          IE   3.0.101-0-default #1 HP ProLiant DL380 G7
  RIP: 0010:[<ffffffff8107dcd7>]  [<ffffffff8107dcd7>] __queue_work+0x17/0x3f0
  < ... regs ...>
  Process kworker/0:1 (pid: 0, threadinfo ffff88019def6000, task ffff88019def4600)
  Stack:
   ...
  Call Trace:
   call_timer_fn
   run_timer_softirq
   __do_softirq
   call_softirq
   do_softirq
   irq_exit
   smp_apic_timer_interrupt
   apic_timer_interrupt
   intel_idle
   cpuidle_idle_call
   cpu_idle
  Code: ...
  RIP  __queue_work
   RSP <...>

Signed-off-by: Borislav Petkov <bp@suse.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/edac/edac_device.c | 11 ++++-------
 drivers/edac/edac_mc.c     | 14 +++-----------
 drivers/edac/edac_pci.c    |  9 ++++-----
 3 files changed, 11 insertions(+), 23 deletions(-)

diff --git a/drivers/edac/edac_device.c b/drivers/edac/edac_device.c
index 592af5f0cf39..53587377e672 100644
--- a/drivers/edac/edac_device.c
+++ b/drivers/edac/edac_device.c
@@ -435,16 +435,13 @@ void edac_device_workq_setup(struct edac_device_ctl_info *edac_dev,
  */
 void edac_device_workq_teardown(struct edac_device_ctl_info *edac_dev)
 {
-	int status;
-
 	if (!edac_dev->edac_check)
 		return;
 
-	status = cancel_delayed_work(&edac_dev->work);
-	if (status == 0) {
-		/* workq instance might be running, wait for it */
-		flush_workqueue(edac_workqueue);
-	}
+	edac_dev->op_state = OP_OFFLINE;
+
+	cancel_delayed_work_sync(&edac_dev->work);
+	flush_workqueue(edac_workqueue);
 }
 
 /*
diff --git a/drivers/edac/edac_mc.c b/drivers/edac/edac_mc.c
index 2c694b5297cc..9e471c5e185b 100644
--- a/drivers/edac/edac_mc.c
+++ b/drivers/edac/edac_mc.c
@@ -584,18 +584,10 @@ static void edac_mc_workq_setup(struct mem_ctl_info *mci, unsigned msec,
  */
 static void edac_mc_workq_teardown(struct mem_ctl_info *mci)
 {
-	int status;
-
-	if (mci->op_state != OP_RUNNING_POLL)
-		return;
-
-	status = cancel_delayed_work(&mci->work);
-	if (status == 0) {
-		edac_dbg(0, "not canceled, flush the queue\n");
+	mci->op_state = OP_OFFLINE;
 
-		/* workq instance might be running, wait for it */
-		flush_workqueue(edac_workqueue);
-	}
+	cancel_delayed_work_sync(&mci->work);
+	flush_workqueue(edac_workqueue);
 }
 
 /*
diff --git a/drivers/edac/edac_pci.c b/drivers/edac/edac_pci.c
index 2cf44b4db80c..b4b38603b804 100644
--- a/drivers/edac/edac_pci.c
+++ b/drivers/edac/edac_pci.c
@@ -274,13 +274,12 @@ static void edac_pci_workq_setup(struct edac_pci_ctl_info *pci,
  */
 static void edac_pci_workq_teardown(struct edac_pci_ctl_info *pci)
 {
-	int status;
-
 	edac_dbg(0, "\n");
 
-	status = cancel_delayed_work(&pci->work);
-	if (status == 0)
-		flush_workqueue(edac_workqueue);
+	pci->op_state = OP_OFFLINE;
+
+	cancel_delayed_work_sync(&pci->work);
+	flush_workqueue(edac_workqueue);
 }
 
 /*

[toc] | [prev] | [next] | [standalone]


#1326295 — [PATCH 3.16.y-ckt 037/180] EDAC, mc_sysfs: Fix freeing bus' name

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:00 +0100
Subject[PATCH 3.16.y-ckt 037/180] EDAC, mc_sysfs: Fix freeing bus' name
Message-ID<qYfv6-Cf-69@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Borislav Petkov <bp@suse.de>

commit 12e26969b32c79018165d52caff3762135614aa1 upstream.

I get the splat below when modprobing/rmmoding EDAC drivers. It happens
because bus->name is invalid after bus_unregister() has run. The Code: section
below corresponds to:

  .loc 1 1108 0
  movq    672(%rbx), %rax # mci_1(D)->bus, mci_1(D)->bus
  .loc 1 1109 0
  popq    %rbx    #

  .loc 1 1108 0
  movq    (%rax), %rdi    # _7->name,
  jmp     kfree   #

and %rax has some funky stuff 2030203020312030 which looks a lot like
something walked over it.

Fix that by saving the name ptr before doing stuff to string it points to.

  general protection fault: 0000 [#1] SMP
  Modules linked in: ...
  CPU: 4 PID: 10318 Comm: modprobe Tainted: G          I EN  3.12.51-11-default+ #48
  Hardware name: HP ProLiant DL380 G7, BIOS P67 05/05/2011
  task: ffff880311320280 ti: ffff88030da3e000 task.ti: ffff88030da3e000
  RIP: 0010:[<ffffffffa019da92>]  [<ffffffffa019da92>] edac_unregister_sysfs+0x22/0x30 [edac_core]
  RSP: 0018:ffff88030da3fe28  EFLAGS: 00010292
  RAX: 2030203020312030 RBX: ffff880311b4e000 RCX: 000000000000095c
  RDX: 0000000000000001 RSI: ffff880327bb9600 RDI: 0000000000000286
  RBP: ffff880311b4e750 R08: 0000000000000000 R09: ffffffff81296110
  R10: 0000000000000400 R11: 0000000000000000 R12: ffff88030ba1ac68
  R13: 0000000000000001 R14: 00000000011b02f0 R15: 0000000000000000
  FS:  00007fc9bf8f5700(0000) GS:ffff8801a7c40000(0000) knlGS:0000000000000000
  CS:  0010 DS: 0000 ES: 0000 CR0: 000000008005003b
  CR2: 0000000000403c90 CR3: 000000019ebdf000 CR4: 00000000000007e0
  Stack:
  Call Trace:
    i7core_unregister_mci.isra.9
    i7core_remove
    pci_device_remove
    __device_release_driver
    driver_detach
    bus_remove_driver
    pci_unregister_driver
    i7core_exit
    SyS_delete_module
    system_call_fastpath
    0x7fc9bf426536
  Code: 2e 0f 1f 84 00 00 00 00 00 66 66 66 66 90 53 48 89 fb e8 52 2a 1f e1 48 8b bb a0 02 00 00 e8 46 59 1f e1 48 8b 83 a0 02 00 00 5b <48> 8b 38 e9 26 9a fe e0 66 0f 1f 44 00 00 66 66 66 66 90 48 8b
  RIP  [<ffffffffa019da92>] edac_unregister_sysfs+0x22/0x30 [edac_core]
   RSP <ffff88030da3fe28>

Signed-off-by: Borislav Petkov <bp@suse.de>
Cc: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Fixes: 7a623c039075 ("edac: rewrite the sysfs code to use struct device")
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/edac/edac_mc_sysfs.c | 21 ++++++++++++++-------
 1 file changed, 14 insertions(+), 7 deletions(-)

diff --git a/drivers/edac/edac_mc_sysfs.c b/drivers/edac/edac_mc_sysfs.c
index f122c8a6e33d..bffb263aa5d7 100644
--- a/drivers/edac/edac_mc_sysfs.c
+++ b/drivers/edac/edac_mc_sysfs.c
@@ -973,21 +973,26 @@ nomem:
  */
 int edac_create_sysfs_mci_device(struct mem_ctl_info *mci)
 {
+	char *name;
 	int i, err;
 
 	/*
 	 * The memory controller needs its own bus, in order to avoid
 	 * namespace conflicts at /sys/bus/edac.
 	 */
-	mci->bus->name = kasprintf(GFP_KERNEL, "mc%d", mci->mc_idx);
-	if (!mci->bus->name)
+	name = kasprintf(GFP_KERNEL, "mc%d", mci->mc_idx);
+	if (!name)
 		return -ENOMEM;
 
+	mci->bus->name = name;
+
 	edac_dbg(0, "creating bus %s\n", mci->bus->name);
 
 	err = bus_register(mci->bus);
-	if (err < 0)
-		goto fail_free_name;
+	if (err < 0) {
+		kfree(name);
+		return err;
+	}
 
 	/* get the /sys/devices/system/edac subsys reference */
 	mci->dev.type = &mci_attr_type;
@@ -1073,8 +1078,8 @@ fail_unregister_dev:
 	device_unregister(&mci->dev);
 fail_unregister_bus:
 	bus_unregister(mci->bus);
-fail_free_name:
-	kfree(mci->bus->name);
+	kfree(name);
+
 	return err;
 }
 
@@ -1105,10 +1110,12 @@ void edac_remove_sysfs_mci_device(struct mem_ctl_info *mci)
 
 void edac_unregister_sysfs(struct mem_ctl_info *mci)
 {
+	const char *name = mci->bus->name;
+
 	edac_dbg(1, "Unregistering device %s\n", dev_name(&mci->dev));
 	device_unregister(&mci->dev);
 	bus_unregister(mci->bus);
-	kfree(mci->bus->name);
+	kfree(name);
 }
 
 static void mc_attr_release(struct device *dev)

[toc] | [prev] | [next] | [standalone]


#1326297 — [PATCH 3.16.y-ckt 019/180] xfrm: dst_entries_init() per-net dst_ops

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:00 +0100
Subject[PATCH 3.16.y-ckt 019/180] xfrm: dst_entries_init() per-net dst_ops
Message-ID<qYfv7-Cf-73@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Dan Streetman <dan.streetman@canonical.com>

commit a8a572a6b5f2a79280d6e302cb3c1cb1fbaeb3e8 upstream.

Remove the dst_entries_init/destroy calls for xfrm4 and xfrm6 dst_ops
templates; their dst_entries counters will never be used.  Move the
xfrm dst_ops initialization from the common xfrm/xfrm_policy.c to
xfrm4/xfrm4_policy.c and xfrm6/xfrm6_policy.c, and call dst_entries_init
and dst_entries_destroy for each net namespace.

The ipv4 and ipv6 xfrms each create dst_ops template, and perform
dst_entries_init on the templates.  The template values are copied to each
net namespace's xfrm.xfrm*_dst_ops.  The problem there is the dst_ops
pcpuc_entries field is a percpu counter and cannot be used correctly by
simply copying it to another object.

The result of this is a very subtle bug; changes to the dst entries
counter from one net namespace may sometimes get applied to a different
net namespace dst entries counter.  This is because of how the percpu
counter works; it has a main count field as well as a pointer to the
percpu variables.  Each net namespace maintains its own main count
variable, but all point to one set of percpu variables.  When any net
namespace happens to change one of the percpu variables to outside its
small batch range, its count is moved to the net namespace's main count
variable.  So with multiple net namespaces operating concurrently, the
dst_ops entries counter can stray from the actual value that it should
be; if counts are consistently moved from one net namespace to another
(which my testing showed is likely), then one net namespace winds up
with a negative dst_ops count while another winds up with a continually
increasing count, eventually reaching its gc_thresh limit, which causes
all new traffic on the net namespace to fail with -ENOBUFS.

Signed-off-by: Dan Streetman <dan.streetman@canonical.com>
Signed-off-by: Dan Streetman <ddstreet@ieee.org>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/ipv4/xfrm4_policy.c | 46 +++++++++++++++++++++++++++++++++---------
 net/ipv6/xfrm6_policy.c | 53 +++++++++++++++++++++++++++++++++++--------------
 net/xfrm/xfrm_policy.c  | 38 -----------------------------------
 3 files changed, 75 insertions(+), 62 deletions(-)

diff --git a/net/ipv4/xfrm4_policy.c b/net/ipv4/xfrm4_policy.c
index 6156f68a1e90..94fc16dad6c6 100644
--- a/net/ipv4/xfrm4_policy.c
+++ b/net/ipv4/xfrm4_policy.c
@@ -230,7 +230,7 @@ static void xfrm4_dst_ifdown(struct dst_entry *dst, struct net_device *dev,
 	xfrm_dst_ifdown(dst, dev);
 }
 
-static struct dst_ops xfrm4_dst_ops = {
+static struct dst_ops xfrm4_dst_ops_template = {
 	.family =		AF_INET,
 	.protocol =		cpu_to_be16(ETH_P_IP),
 	.gc =			xfrm4_garbage_collect,
@@ -245,7 +245,7 @@ static struct dst_ops xfrm4_dst_ops = {
 
 static struct xfrm_policy_afinfo xfrm4_policy_afinfo = {
 	.family = 		AF_INET,
-	.dst_ops =		&xfrm4_dst_ops,
+	.dst_ops =		&xfrm4_dst_ops_template,
 	.dst_lookup =		xfrm4_dst_lookup,
 	.get_saddr =		xfrm4_get_saddr,
 	.decode_session =	_decode_session4,
@@ -267,7 +267,7 @@ static struct ctl_table xfrm4_policy_table[] = {
 	{ }
 };
 
-static int __net_init xfrm4_net_init(struct net *net)
+static int __net_init xfrm4_net_sysctl_init(struct net *net)
 {
 	struct ctl_table *table;
 	struct ctl_table_header *hdr;
@@ -295,7 +295,7 @@ err_alloc:
 	return -ENOMEM;
 }
 
-static void __net_exit xfrm4_net_exit(struct net *net)
+static void __net_exit xfrm4_net_sysctl_exit(struct net *net)
 {
 	struct ctl_table *table;
 
@@ -307,12 +307,44 @@ static void __net_exit xfrm4_net_exit(struct net *net)
 	if (!net_eq(net, &init_net))
 		kfree(table);
 }
+#else /* CONFIG_SYSCTL */
+static int inline xfrm4_net_sysctl_init(struct net *net)
+{
+	return 0;
+}
+
+static void inline xfrm4_net_sysctl_exit(struct net *net)
+{
+}
+#endif
+
+static int __net_init xfrm4_net_init(struct net *net)
+{
+	int ret;
+
+	memcpy(&net->xfrm.xfrm4_dst_ops, &xfrm4_dst_ops_template,
+	       sizeof(xfrm4_dst_ops_template));
+	ret = dst_entries_init(&net->xfrm.xfrm4_dst_ops);
+	if (ret)
+		return ret;
+
+	ret = xfrm4_net_sysctl_init(net);
+	if (ret)
+		dst_entries_destroy(&net->xfrm.xfrm4_dst_ops);
+
+	return ret;
+}
+
+static void __net_exit xfrm4_net_exit(struct net *net)
+{
+	xfrm4_net_sysctl_exit(net);
+	dst_entries_destroy(&net->xfrm.xfrm4_dst_ops);
+}
 
 static struct pernet_operations __net_initdata xfrm4_net_ops = {
 	.init	= xfrm4_net_init,
 	.exit	= xfrm4_net_exit,
 };
-#endif
 
 static void __init xfrm4_policy_init(void)
 {
@@ -321,13 +353,9 @@ static void __init xfrm4_policy_init(void)
 
 void __init xfrm4_init(void)
 {
-	dst_entries_init(&xfrm4_dst_ops);
-
 	xfrm4_state_init();
 	xfrm4_policy_init();
 	xfrm4_protocol_init();
-#ifdef CONFIG_SYSCTL
 	register_pernet_subsys(&xfrm4_net_ops);
-#endif
 }
 
diff --git a/net/ipv6/xfrm6_policy.c b/net/ipv6/xfrm6_policy.c
index 2a0bbda2c76a..28af4e66d87a 100644
--- a/net/ipv6/xfrm6_policy.c
+++ b/net/ipv6/xfrm6_policy.c
@@ -279,7 +279,7 @@ static void xfrm6_dst_ifdown(struct dst_entry *dst, struct net_device *dev,
 	xfrm_dst_ifdown(dst, dev);
 }
 
-static struct dst_ops xfrm6_dst_ops = {
+static struct dst_ops xfrm6_dst_ops_template = {
 	.family =		AF_INET6,
 	.protocol =		cpu_to_be16(ETH_P_IPV6),
 	.gc =			xfrm6_garbage_collect,
@@ -294,7 +294,7 @@ static struct dst_ops xfrm6_dst_ops = {
 
 static struct xfrm_policy_afinfo xfrm6_policy_afinfo = {
 	.family =		AF_INET6,
-	.dst_ops =		&xfrm6_dst_ops,
+	.dst_ops =		&xfrm6_dst_ops_template,
 	.dst_lookup =		xfrm6_dst_lookup,
 	.get_saddr = 		xfrm6_get_saddr,
 	.decode_session =	_decode_session6,
@@ -327,7 +327,7 @@ static struct ctl_table xfrm6_policy_table[] = {
 	{ }
 };
 
-static int __net_init xfrm6_net_init(struct net *net)
+static int __net_init xfrm6_net_sysctl_init(struct net *net)
 {
 	struct ctl_table *table;
 	struct ctl_table_header *hdr;
@@ -355,7 +355,7 @@ err_alloc:
 	return -ENOMEM;
 }
 
-static void __net_exit xfrm6_net_exit(struct net *net)
+static void __net_exit xfrm6_net_sysctl_exit(struct net *net)
 {
 	struct ctl_table *table;
 
@@ -367,24 +367,52 @@ static void __net_exit xfrm6_net_exit(struct net *net)
 	if (!net_eq(net, &init_net))
 		kfree(table);
 }
+#else /* CONFIG_SYSCTL */
+static int inline xfrm6_net_sysctl_init(struct net *net)
+{
+	return 0;
+}
+
+static void inline xfrm6_net_sysctl_exit(struct net *net)
+{
+}
+#endif
+
+static int __net_init xfrm6_net_init(struct net *net)
+{
+	int ret;
+
+	memcpy(&net->xfrm.xfrm6_dst_ops, &xfrm6_dst_ops_template,
+	       sizeof(xfrm6_dst_ops_template));
+	ret = dst_entries_init(&net->xfrm.xfrm6_dst_ops);
+	if (ret)
+		return ret;
+
+	ret = xfrm6_net_sysctl_init(net);
+	if (ret)
+		dst_entries_destroy(&net->xfrm.xfrm6_dst_ops);
+
+	return ret;
+}
+
+static void __net_exit xfrm6_net_exit(struct net *net)
+{
+	xfrm6_net_sysctl_exit(net);
+	dst_entries_destroy(&net->xfrm.xfrm6_dst_ops);
+}
 
 static struct pernet_operations xfrm6_net_ops = {
 	.init	= xfrm6_net_init,
 	.exit	= xfrm6_net_exit,
 };
-#endif
 
 int __init xfrm6_init(void)
 {
 	int ret;
 
-	dst_entries_init(&xfrm6_dst_ops);
-
 	ret = xfrm6_policy_init();
-	if (ret) {
-		dst_entries_destroy(&xfrm6_dst_ops);
+	if (ret)
 		goto out;
-	}
 	ret = xfrm6_state_init();
 	if (ret)
 		goto out_policy;
@@ -393,9 +421,7 @@ int __init xfrm6_init(void)
 	if (ret)
 		goto out_state;
 
-#ifdef CONFIG_SYSCTL
 	register_pernet_subsys(&xfrm6_net_ops);
-#endif
 out:
 	return ret;
 out_state:
@@ -407,11 +433,8 @@ out_policy:
 
 void xfrm6_fini(void)
 {
-#ifdef CONFIG_SYSCTL
 	unregister_pernet_subsys(&xfrm6_net_ops);
-#endif
 	xfrm6_protocol_fini();
 	xfrm6_policy_fini();
 	xfrm6_state_fini();
-	dst_entries_destroy(&xfrm6_dst_ops);
 }
diff --git a/net/xfrm/xfrm_policy.c b/net/xfrm/xfrm_policy.c
index d4d6fc96f6c5..48ce8f37e457 100644
--- a/net/xfrm/xfrm_policy.c
+++ b/net/xfrm/xfrm_policy.c
@@ -2686,7 +2686,6 @@ static struct neighbour *xfrm_neigh_lookup(const struct dst_entry *dst,
 
 int xfrm_policy_register_afinfo(struct xfrm_policy_afinfo *afinfo)
 {
-	struct net *net;
 	int err = 0;
 	if (unlikely(afinfo == NULL))
 		return -EINVAL;
@@ -2717,26 +2716,6 @@ int xfrm_policy_register_afinfo(struct xfrm_policy_afinfo *afinfo)
 	}
 	spin_unlock(&xfrm_policy_afinfo_lock);
 
-	rtnl_lock();
-	for_each_net(net) {
-		struct dst_ops *xfrm_dst_ops;
-
-		switch (afinfo->family) {
-		case AF_INET:
-			xfrm_dst_ops = &net->xfrm.xfrm4_dst_ops;
-			break;
-#if IS_ENABLED(CONFIG_IPV6)
-		case AF_INET6:
-			xfrm_dst_ops = &net->xfrm.xfrm6_dst_ops;
-			break;
-#endif
-		default:
-			BUG();
-		}
-		*xfrm_dst_ops = *afinfo->dst_ops;
-	}
-	rtnl_unlock();
-
 	return err;
 }
 EXPORT_SYMBOL(xfrm_policy_register_afinfo);
@@ -2772,22 +2751,6 @@ int xfrm_policy_unregister_afinfo(struct xfrm_policy_afinfo *afinfo)
 }
 EXPORT_SYMBOL(xfrm_policy_unregister_afinfo);
 
-static void __net_init xfrm_dst_ops_init(struct net *net)
-{
-	struct xfrm_policy_afinfo *afinfo;
-
-	rcu_read_lock();
-	afinfo = rcu_dereference(xfrm_policy_afinfo[AF_INET]);
-	if (afinfo)
-		net->xfrm.xfrm4_dst_ops = *afinfo->dst_ops;
-#if IS_ENABLED(CONFIG_IPV6)
-	afinfo = rcu_dereference(xfrm_policy_afinfo[AF_INET6]);
-	if (afinfo)
-		net->xfrm.xfrm6_dst_ops = *afinfo->dst_ops;
-#endif
-	rcu_read_unlock();
-}
-
 static int xfrm_dev_event(struct notifier_block *this, unsigned long event, void *ptr)
 {
 	struct net_device *dev = netdev_notifier_info_to_dev(ptr);
@@ -2924,7 +2887,6 @@ static int __net_init xfrm_net_init(struct net *net)
 	rv = xfrm_policy_init(net);
 	if (rv < 0)
 		goto out_policy;
-	xfrm_dst_ops_init(net);
 	rv = xfrm_sysctl_init(net);
 	if (rv < 0)
 		goto out_sysctl;

[toc] | [prev] | [next] | [standalone]


#1326298 — [PATCH 3.16.y-ckt 011/180] phonet: properly unshare skbs in phonet_rcv()

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:10 +0100
Subject[PATCH 3.16.y-ckt 011/180] phonet: properly unshare skbs in phonet_rcv()
Message-ID<qYfEJ-UD-1@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Eric Dumazet <edumazet@google.com>

commit 7aaed57c5c2890634cfadf725173c7c68ea4cb4f upstream.

Ivaylo Dimitrov reported a regression caused by commit 7866a621043f
("dev: add per net_device packet type chains").

skb->dev becomes NULL and we crash in __netif_receive_skb_core().

Before above commit, different kind of bugs or corruptions could happen
without major crash.

But the root cause is that phonet_rcv() can queue skb without checking
if skb is shared or not.

Many thanks to Ivaylo Dimitrov for his help, diagnosis and tests.

Reported-by: Ivaylo Dimitrov <ivo.g.dimitrov.75@gmail.com>
Tested-by: Ivaylo Dimitrov <ivo.g.dimitrov.75@gmail.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Remi Denis-Courmont <courmisch@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/phonet/af_phonet.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/net/phonet/af_phonet.c b/net/phonet/af_phonet.c
index 5a940dbd74a3..f0229223bf91 100644
--- a/net/phonet/af_phonet.c
+++ b/net/phonet/af_phonet.c
@@ -377,6 +377,10 @@ static int phonet_rcv(struct sk_buff *skb, struct net_device *dev,
 	struct sockaddr_pn sa;
 	u16 len;
 
+	skb = skb_share_check(skb, GFP_ATOMIC);
+	if (!skb)
+		return NET_RX_DROP;
+
 	/* check we have at least a full Phonet header */
 	if (!pskb_pull(skb, sizeof(struct phonethdr)))
 		goto out;

[toc] | [prev] | [next] | [standalone]


#1326299 — [PATCH 3.16.y-ckt 009/180] tcp_yeah: don't set ssthresh below 2

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:10 +0100
Subject[PATCH 3.16.y-ckt 009/180] tcp_yeah: don't set ssthresh below 2
Message-ID<qYfEJ-UD-5@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Neal Cardwell <ncardwell@google.com>

commit 83d15e70c4d8909d722c0d64747d8fb42e38a48f upstream.

For tcp_yeah, use an ssthresh floor of 2, the same floor used by Reno
and CUBIC, per RFC 5681 (equation 4).

tcp_yeah_ssthresh() was sometimes returning a 0 or negative ssthresh
value if the intended reduction is as big or bigger than the current
cwnd. Congestion control modules should never return a zero or
negative ssthresh. A zero ssthresh generally results in a zero cwnd,
causing the connection to stall. A negative ssthresh value will be
interpreted as a u32 and will set a target cwnd for PRR near 4
billion.

Oleksandr Natalenko reported that a system using tcp_yeah with ECN
could see a warning about a prior_cwnd of 0 in
tcp_cwnd_reduction(). Testing verified that this was due to
tcp_yeah_ssthresh() misbehaving in this way.

Reported-by: Oleksandr Natalenko <oleksandr@natalenko.name>
Signed-off-by: Neal Cardwell <ncardwell@google.com>
Signed-off-by: Yuchung Cheng <ycheng@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/ipv4/tcp_yeah.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/ipv4/tcp_yeah.c b/net/ipv4/tcp_yeah.c
index 599b79b8eac0..99f66d49b063 100644
--- a/net/ipv4/tcp_yeah.c
+++ b/net/ipv4/tcp_yeah.c
@@ -222,7 +222,7 @@ static u32 tcp_yeah_ssthresh(struct sock *sk) {
 	yeah->fast_count = 0;
 	yeah->reno_count = max(yeah->reno_count>>1, 2U);
 
-	return tp->snd_cwnd - reduction;
+	return max_t(int, tp->snd_cwnd - reduction, 2);
 }
 
 static struct tcp_congestion_ops tcp_yeah __read_mostly = {

[toc] | [prev] | [next] | [standalone]


#1326301 — [PATCH 3.16.y-ckt 012/180] net: bpf: reject invalid shifts

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:10 +0100
Subject[PATCH 3.16.y-ckt 012/180] net: bpf: reject invalid shifts
Message-ID<qYfEJ-UD-11@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Rabin Vincent <rabin@rab.in>

commit 229394e8e62a4191d592842cf67e80c62a492937 upstream.

On ARM64, a BUG() is triggered in the eBPF JIT if a filter with a
constant shift that can't be encoded in the immediate field of the
UBFM/SBFM instructions is passed to the JIT.  Since these shifts
amounts, which are negative or >= regsize, are invalid, reject them in
the eBPF verifier and the classic BPF filter checker, for all
architectures.

Signed-off-by: Rabin Vincent <rabin@rab.in>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Daniel Borkmann <daniel@iogearbox.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ luis: backported to 3.16:
  - drop changes to eBPF verifier, only added in 3.18 kernel
  - function rename: bpf_check_classic() -> sk_chk_filter() ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/core/filter.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/net/core/filter.c b/net/core/filter.c
index 3139f966a178..dfc5f31dc5a1 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -1251,6 +1251,11 @@ int sk_chk_filter(struct sock_filter *filter, unsigned int flen)
 			if (ftest->k == 0)
 				return -EINVAL;
 			break;
+		case BPF_ALU | BPF_LSH | BPF_K:
+		case BPF_ALU | BPF_RSH | BPF_K:
+			if (ftest->k >= 32)
+				return -EINVAL;
+			break;
 		case BPF_LD | BPF_MEM:
 		case BPF_LDX | BPF_MEM:
 		case BPF_ST:

[toc] | [prev] | [next] | [standalone]


#1326302 — [PATCH 3.16.y-ckt 003/180] sctp: sctp should release assoc when sctp_make_abort_user return NULL in sctp_close

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:10 +0100
Subject[PATCH 3.16.y-ckt 003/180] sctp: sctp should release assoc when sctp_make_abort_user return NULL in sctp_close
Message-ID<qYfEK-UD-15@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Xin Long <lucien.xin@gmail.com>

commit 068d8bd338e855286aea54e70d1c101569284b21 upstream.

In sctp_close, sctp_make_abort_user may return NULL because of memory
allocation failure. If this happens, it will bypass any state change
and never free the assoc. The assoc has no chance to be freed and it
will be kept in memory with the state it had even after the socket is
closed by sctp_close().

So if sctp_make_abort_user fails to allocate memory, we should abort
the asoc via sctp_primitive_ABORT as well. Just like the annotation in
sctp_sf_cookie_wait_prm_abort and sctp_sf_do_9_1_prm_abort said,
"Even if we can't send the ABORT due to low memory delete the TCB.
This is a departure from our typical NOMEM handling".

But then the chunk is NULL (low memory) and the SCTP_CMD_REPLY cmd would
dereference the chunk pointer, and system crash. So we should add
SCTP_CMD_REPLY cmd only when the chunk is not NULL, just like other
places where it adds SCTP_CMD_REPLY cmd.

Signed-off-by: Xin Long <lucien.xin@gmail.com>
Acked-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/sctp/sm_statefuns.c | 6 ++++--
 net/sctp/socket.c       | 3 +--
 2 files changed, 5 insertions(+), 4 deletions(-)

diff --git a/net/sctp/sm_statefuns.c b/net/sctp/sm_statefuns.c
index 3e287a3fa03b..af1da3188865 100644
--- a/net/sctp/sm_statefuns.c
+++ b/net/sctp/sm_statefuns.c
@@ -4833,7 +4833,8 @@ sctp_disposition_t sctp_sf_do_9_1_prm_abort(
 
 	retval = SCTP_DISPOSITION_CONSUME;
 
-	sctp_add_cmd_sf(commands, SCTP_CMD_REPLY, SCTP_CHUNK(abort));
+	if (abort)
+		sctp_add_cmd_sf(commands, SCTP_CMD_REPLY, SCTP_CHUNK(abort));
 
 	/* Even if we can't send the ABORT due to low memory delete the
 	 * TCB.  This is a departure from our typical NOMEM handling.
@@ -4970,7 +4971,8 @@ sctp_disposition_t sctp_sf_cookie_wait_prm_abort(
 			SCTP_TO(SCTP_EVENT_TIMEOUT_T1_INIT));
 	retval = SCTP_DISPOSITION_CONSUME;
 
-	sctp_add_cmd_sf(commands, SCTP_CMD_REPLY, SCTP_CHUNK(abort));
+	if (abort)
+		sctp_add_cmd_sf(commands, SCTP_CMD_REPLY, SCTP_CHUNK(abort));
 
 	sctp_add_cmd_sf(commands, SCTP_CMD_NEW_STATE,
 			SCTP_STATE(SCTP_STATE_CLOSED));
diff --git a/net/sctp/socket.c b/net/sctp/socket.c
index e58140abe17e..88c5befcb569 100644
--- a/net/sctp/socket.c
+++ b/net/sctp/socket.c
@@ -1518,8 +1518,7 @@ static void sctp_close(struct sock *sk, long timeout)
 			struct sctp_chunk *chunk;
 
 			chunk = sctp_make_abort_user(asoc, NULL, 0);
-			if (chunk)
-				sctp_primitive_ABORT(net, asoc, chunk);
+			sctp_primitive_ABORT(net, asoc, chunk);
 		} else
 			sctp_primitive_SHUTDOWN(net, asoc, NULL);
 	}

[toc] | [prev] | [next] | [standalone]


#1326303 — [PATCH 3.16.y-ckt 007/180] vxlan: fix test which detect duplicate vxlan iface

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:10 +0100
Subject[PATCH 3.16.y-ckt 007/180] vxlan: fix test which detect duplicate vxlan iface
Message-ID<qYfEK-UD-23@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Nicolas Dichtel <nicolas.dichtel@6wind.com>

commit 07b9b37c227cb8d88d478b4a9c5634fee514ede1 upstream.

When a vxlan interface is created, the driver checks that there is not
another vxlan interface with the same properties. To do this, it checks
the existing vxlan udp socket. Since commit 1c51a9159dde, the creation of
the vxlan socket is done only when the interface is set up, thus it breaks
that test.

Example:
$ ip l a vxlan10 type vxlan id 10 group 239.0.0.10 dev eth0 dstport 0
$ ip l a vxlan11 type vxlan id 10 group 239.0.0.10 dev eth0 dstport 0
$ ip -br l | grep vxlan
vxlan10          DOWN           f2:55:1c:6a:fb:00 <BROADCAST,MULTICAST>
vxlan11          DOWN           7a:cb:b9:38:59:0d <BROADCAST,MULTICAST>

Instead of checking sockets, let's loop over the vxlan iface list.

Fixes: 1c51a9159dde ("vxlan: fix race caused by dropping rtnl_unlock")
Reported-by: Thomas Faivre <thomas.faivre@6wind.com>
Signed-off-by: Nicolas Dichtel <nicolas.dichtel@6wind.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ luis: backported to 3.16: used davem's backport to 3.18 ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/net/vxlan.c | 12 ++++++++----
 include/net/vxlan.h |  5 +++++
 2 files changed, 13 insertions(+), 4 deletions(-)

diff --git a/drivers/net/vxlan.c b/drivers/net/vxlan.c
index 8a7a35c4f6bd..74dccfa00a5c 100644
--- a/drivers/net/vxlan.c
+++ b/drivers/net/vxlan.c
@@ -2579,7 +2579,7 @@ static int vxlan_newlink(struct net *net, struct net_device *dev,
 			 struct nlattr *tb[], struct nlattr *data[])
 {
 	struct vxlan_net *vn = net_generic(net, vxlan_net_id);
-	struct vxlan_dev *vxlan = netdev_priv(dev);
+	struct vxlan_dev *vxlan = netdev_priv(dev), *tmp;
 	struct vxlan_rdst *dst = &vxlan->default_dst;
 	__u32 vni;
 	int err;
@@ -2704,9 +2704,13 @@ static int vxlan_newlink(struct net *net, struct net_device *dev,
 	    nla_get_u8(data[IFLA_VXLAN_UDP_ZERO_CSUM6_RX]))
 		vxlan->flags |= VXLAN_F_UDP_ZERO_CSUM6_RX;
 
-	if (vxlan_find_vni(net, vni, use_ipv6 ? AF_INET6 : AF_INET,
-			   vxlan->dst_port)) {
-		pr_info("duplicate VNI %u\n", vni);
+	list_for_each_entry(tmp, &vn->vxlan_list, next) {
+		if (tmp->default_dst.remote_vni == vni &&
+		    (tmp->default_dst.remote_ip.sa.sa_family == AF_INET6 ||
+		     tmp->saddr.sa.sa_family == AF_INET6) == use_ipv6 &&
+		    tmp->dst_port == vxlan->dst_port &&
+		    (tmp->flags & VXLAN_F_RCV_FLAGS) ==
+		    (vxlan->flags & VXLAN_F_RCV_FLAGS))
 		return -EEXIST;
 	}
 
diff --git a/include/net/vxlan.h b/include/net/vxlan.h
index 12196ce661d9..94f5391736fe 100644
--- a/include/net/vxlan.h
+++ b/include/net/vxlan.h
@@ -34,6 +34,11 @@ struct vxlan_sock {
 #define VXLAN_F_UDP_ZERO_CSUM6_TX	0x80
 #define VXLAN_F_UDP_ZERO_CSUM6_RX	0x100
 
+/* Flags that are used in the receive path. These flags must match in
+ * order for a socket to be shareable
+ */
+#define VXLAN_F_RCV_FLAGS		VXLAN_F_UDP_ZERO_CSUM6_RX
+
 struct vxlan_sock *vxlan_sock_add(struct net *net, __be16 port,
 				  vxlan_rcv_t *rcv, void *data,
 				  bool no_share, u32 flags);

[toc] | [prev] | [next] | [standalone]


#1326304 — [PATCH 3.16.y-ckt 013/180] ipv6: update skb->csum when CE mark is propagated

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:10 +0100
Subject[PATCH 3.16.y-ckt 013/180] ipv6: update skb->csum when CE mark is propagated
Message-ID<qYfEK-UD-25@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Eric Dumazet <edumazet@google.com>

commit 34ae6a1aa0540f0f781dd265366036355fdc8930 upstream.

When a tunnel decapsulates the outer header, it has to comply
with RFC 6080 and eventually propagate CE mark into inner header.

It turns out IP6_ECN_set_ce() does not correctly update skb->csum
for CHECKSUM_COMPLETE packets, triggering infamous "hw csum failure"
messages and stack traces.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 include/net/inet_ecn.h       | 19 ++++++++++++++++---
 net/ipv6/xfrm6_mode_tunnel.c |  2 +-
 2 files changed, 17 insertions(+), 4 deletions(-)

diff --git a/include/net/inet_ecn.h b/include/net/inet_ecn.h
index 84b20835b736..0dc0a51da38f 100644
--- a/include/net/inet_ecn.h
+++ b/include/net/inet_ecn.h
@@ -111,11 +111,24 @@ static inline void ipv4_copy_dscp(unsigned int dscp, struct iphdr *inner)
 
 struct ipv6hdr;
 
-static inline int IP6_ECN_set_ce(struct ipv6hdr *iph)
+/* Note:
+ * IP_ECN_set_ce() has to tweak IPV4 checksum when setting CE,
+ * meaning both changes have no effect on skb->csum if/when CHECKSUM_COMPLETE
+ * In IPv6 case, no checksum compensates the change in IPv6 header,
+ * so we have to update skb->csum.
+ */
+static inline int IP6_ECN_set_ce(struct sk_buff *skb, struct ipv6hdr *iph)
 {
+	__be32 from, to;
+
 	if (INET_ECN_is_not_ect(ipv6_get_dsfield(iph)))
 		return 0;
-	*(__be32*)iph |= htonl(INET_ECN_CE << 20);
+
+	from = *(__be32 *)iph;
+	to = from | htonl(INET_ECN_CE << 20);
+	*(__be32 *)iph = to;
+	if (skb->ip_summed == CHECKSUM_COMPLETE)
+		skb->csum = csum_add(csum_sub(skb->csum, from), to);
 	return 1;
 }
 
@@ -142,7 +155,7 @@ static inline int INET_ECN_set_ce(struct sk_buff *skb)
 	case cpu_to_be16(ETH_P_IPV6):
 		if (skb_network_header(skb) + sizeof(struct ipv6hdr) <=
 		    skb_tail_pointer(skb))
-			return IP6_ECN_set_ce(ipv6_hdr(skb));
+			return IP6_ECN_set_ce(skb, ipv6_hdr(skb));
 		break;
 	}
 
diff --git a/net/ipv6/xfrm6_mode_tunnel.c b/net/ipv6/xfrm6_mode_tunnel.c
index 901ef6f8addc..5266ad2d6419 100644
--- a/net/ipv6/xfrm6_mode_tunnel.c
+++ b/net/ipv6/xfrm6_mode_tunnel.c
@@ -24,7 +24,7 @@ static inline void ipip6_ecn_decapsulate(struct sk_buff *skb)
 	struct ipv6hdr *inner_iph = ipipv6_hdr(skb);
 
 	if (INET_ECN_is_ce(ipv6_get_dsfield(outer_iph)))
-		IP6_ECN_set_ce(inner_iph);
+		IP6_ECN_set_ce(skb, inner_iph);
 }
 
 /* Add encapsulation header.

[toc] | [prev] | [next] | [standalone]


#1326305 — [PATCH 3.16.y-ckt 005/180] unix: properly account for FDs passed over unix sockets

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:10 +0100
Subject[PATCH 3.16.y-ckt 005/180] unix: properly account for FDs passed over unix sockets
Message-ID<qYfEK-UD-27@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: willy tarreau <w@1wt.eu>

commit 712f4aad406bb1ed67f3f98d04c044191f0ff593 upstream.

It is possible for a process to allocate and accumulate far more FDs than
the process' limit by sending them over a unix socket then closing them
to keep the process' fd count low.

This change addresses this problem by keeping track of the number of FDs
in flight per user and preventing non-privileged processes from having
more FDs in flight than their configured FD limit.

Reported-by: socketpair@gmail.com
Reported-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Mitigates: CVE-2013-4312 (Linux 2.0+)
Suggested-by: Linus Torvalds <torvalds@linux-foundation.org>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 include/linux/sched.h |  1 +
 net/unix/af_unix.c    | 24 ++++++++++++++++++++----
 net/unix/garbage.c    | 16 ++++++++++++----
 3 files changed, 33 insertions(+), 8 deletions(-)

diff --git a/include/linux/sched.h b/include/linux/sched.h
index a632aaad1e59..767da1f3c5df 100644
--- a/include/linux/sched.h
+++ b/include/linux/sched.h
@@ -763,6 +763,7 @@ struct user_struct {
 	unsigned long mq_bytes;	/* How many bytes can be allocated to mqueue? */
 #endif
 	unsigned long locked_shm; /* How many pages of mlocked shm ? */
+	unsigned long unix_inflight;	/* How many files in flight in unix sockets */
 
 #ifdef CONFIG_KEYS
 	struct key *uid_keyring;	/* UID specific keyring */
diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
index 7229794c1419..20d752634efb 100644
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -1486,6 +1486,21 @@ static void unix_destruct_scm(struct sk_buff *skb)
 	sock_wfree(skb);
 }
 
+/*
+ * The "user->unix_inflight" variable is protected by the garbage
+ * collection lock, and we just read it locklessly here. If you go
+ * over the limit, there might be a tiny race in actually noticing
+ * it across threads. Tough.
+ */
+static inline bool too_many_unix_fds(struct task_struct *p)
+{
+	struct user_struct *user = current_user();
+
+	if (unlikely(user->unix_inflight > task_rlimit(p, RLIMIT_NOFILE)))
+		return !capable(CAP_SYS_RESOURCE) && !capable(CAP_SYS_ADMIN);
+	return false;
+}
+
 #define MAX_RECURSION_LEVEL 4
 
 static int unix_attach_fds(struct scm_cookie *scm, struct sk_buff *skb)
@@ -1494,6 +1509,9 @@ static int unix_attach_fds(struct scm_cookie *scm, struct sk_buff *skb)
 	unsigned char max_level = 0;
 	int unix_sock_count = 0;
 
+	if (too_many_unix_fds(current))
+		return -ETOOMANYREFS;
+
 	for (i = scm->fp->count - 1; i >= 0; i--) {
 		struct sock *sk = unix_get_socket(scm->fp->fp[i]);
 
@@ -1515,10 +1533,8 @@ static int unix_attach_fds(struct scm_cookie *scm, struct sk_buff *skb)
 	if (!UNIXCB(skb).fp)
 		return -ENOMEM;
 
-	if (unix_sock_count) {
-		for (i = scm->fp->count - 1; i >= 0; i--)
-			unix_inflight(scm->fp->fp[i]);
-	}
+	for (i = scm->fp->count - 1; i >= 0; i--)
+		unix_inflight(scm->fp->fp[i]);
 	return max_level;
 }
 
diff --git a/net/unix/garbage.c b/net/unix/garbage.c
index 9bc73f87f64a..06730fe6ad9d 100644
--- a/net/unix/garbage.c
+++ b/net/unix/garbage.c
@@ -125,9 +125,12 @@ struct sock *unix_get_socket(struct file *filp)
 void unix_inflight(struct file *fp)
 {
 	struct sock *s = unix_get_socket(fp);
+
+	spin_lock(&unix_gc_lock);
+
 	if (s) {
 		struct unix_sock *u = unix_sk(s);
-		spin_lock(&unix_gc_lock);
+
 		if (atomic_long_inc_return(&u->inflight) == 1) {
 			BUG_ON(!list_empty(&u->link));
 			list_add_tail(&u->link, &gc_inflight_list);
@@ -135,22 +138,27 @@ void unix_inflight(struct file *fp)
 			BUG_ON(list_empty(&u->link));
 		}
 		unix_tot_inflight++;
-		spin_unlock(&unix_gc_lock);
 	}
+	fp->f_cred->user->unix_inflight++;
+	spin_unlock(&unix_gc_lock);
 }
 
 void unix_notinflight(struct file *fp)
 {
 	struct sock *s = unix_get_socket(fp);
+
+	spin_lock(&unix_gc_lock);
+
 	if (s) {
 		struct unix_sock *u = unix_sk(s);
-		spin_lock(&unix_gc_lock);
+
 		BUG_ON(list_empty(&u->link));
 		if (atomic_long_dec_and_test(&u->inflight))
 			list_del_init(&u->link);
 		unix_tot_inflight--;
-		spin_unlock(&unix_gc_lock);
 	}
+	fp->f_cred->user->unix_inflight--;
+	spin_unlock(&unix_gc_lock);
 }
 
 static void scan_inflight(struct sock *x, void (*func)(struct unix_sock *),

[toc] | [prev] | [next] | [standalone]


#1326307 — [PATCH 3.16.y-ckt 002/180] veth: don’t modify ip_summed; doing so treats packets with bad checksums as good.

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:10 +0100
Subject[PATCH 3.16.y-ckt 002/180] veth: don’t modify ip_summed; doing so treats packets with bad checksums as good.
Message-ID<qYfEK-UD-31@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Vijay Pandurangan <vijayp@vijayp.ca>

commit ce8c839b74e3017996fad4e1b7ba2e2625ede82f upstream.

Packets that arrive from real hardware devices have ip_summed ==
CHECKSUM_UNNECESSARY if the hardware verified the checksums, or
CHECKSUM_NONE if the packet is bad or it was unable to verify it. The
current version of veth will replace CHECKSUM_NONE with
CHECKSUM_UNNECESSARY, which causes corrupt packets routed from hardware to
a veth device to be delivered to the application. This caused applications
at Twitter to receive corrupt data when network hardware was corrupting
packets.

We believe this was added as an optimization to skip computing and
verifying checksums for communication between containers. However, locally
generated packets have ip_summed == CHECKSUM_PARTIAL, so the code as
written does nothing for them. As far as we can tell, after removing this
code, these packets are transmitted from one stack to another unmodified
(tcpdump shows invalid checksums on both sides, as expected), and they are
delivered correctly to applications. We didn’t test every possible network
configuration, but we tried a few common ones such as bridging containers,
using NAT between the host and a container, and routing from hardware
devices to containers. We have effectively deployed this in production at
Twitter (by disabling RX checksum offloading on veth devices).

This code dates back to the first version of the driver, commit
<e314dbdc1c0dc6a548ecf> ("[NET]: Virtual ethernet device driver"), so I
suspect this bug occurred mostly because the driver API has evolved
significantly since then. Commit <0b7967503dc97864f283a> ("net/veth: Fix
packet checksumming") (in December 2010) fixed this for packets that get
created locally and sent to hardware devices, by not changing
CHECKSUM_PARTIAL. However, the same issue still occurs for packets coming
in from hardware devices.

Co-authored-by: Evan Jones <ej@evanjones.ca>
Signed-off-by: Evan Jones <ej@evanjones.ca>
Cc: Nicolas Dichtel <nicolas.dichtel@6wind.com>
Cc: Phil Sutter <phil@nwl.cc>
Cc: Toshiaki Makita <makita.toshiaki@lab.ntt.co.jp>
Cc: netdev@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Signed-off-by: Vijay Pandurangan <vijayp@vijayp.ca>
Acked-by: Cong Wang <cwang@twopensource.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/net/veth.c | 6 ------
 1 file changed, 6 deletions(-)

diff --git a/drivers/net/veth.c b/drivers/net/veth.c
index b4a10bcb66a0..e3a0e674136f 100644
--- a/drivers/net/veth.c
+++ b/drivers/net/veth.c
@@ -117,12 +117,6 @@ static netdev_tx_t veth_xmit(struct sk_buff *skb, struct net_device *dev)
 		kfree_skb(skb);
 		goto drop;
 	}
-	/* don't change ip_summed == CHECKSUM_PARTIAL, as that
-	 * will cause bad checksum on forwarded packets
-	 */
-	if (skb->ip_summed == CHECKSUM_NONE &&
-	    rcv->features & NETIF_F_RXCSUM)
-		skb->ip_summed = CHECKSUM_UNNECESSARY;
 
 	if (likely(dev_forward_skb(rcv, skb) == NET_RX_SUCCESS)) {
 		struct pcpu_vstats *stats = this_cpu_ptr(dev->vstats);

[toc] | [prev] | [next] | [standalone]


#1326308 — [PATCH 3.16.y-ckt 008/180] net: sctp: prevent writes to cookie_hmac_alg from accessing invalid memory

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-04 01:10 +0100
Subject[PATCH 3.16.y-ckt 008/180] net: sctp: prevent writes to cookie_hmac_alg from accessing invalid memory
Message-ID<qYfEK-UD-33@gated-at.bofh.it>
In reply to#1326014
3.16.7-ckt24 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Sasha Levin <sasha.levin@oracle.com>

commit 320f1a4a175e7cd5d3f006f92b4d4d3e2cbb7bb5 upstream.

proc_dostring() needs an initialized destination string, while the one
provided in proc_sctp_do_hmac_alg() contains stack garbage.

Thus, writing to cookie_hmac_alg would strlen() that garbage and end up
accessing invalid memory.

Fixes: 3c68198e7 ("sctp: Make hmac algorithm selection for cookie generation dynamic")
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/sctp/sysctl.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/sctp/sysctl.c b/net/sctp/sysctl.c
index 12c7e01c2677..0b8583647355 100644
--- a/net/sctp/sysctl.c
+++ b/net/sctp/sysctl.c
@@ -324,7 +324,7 @@ static int proc_sctp_do_hmac_alg(struct ctl_table *ctl, int write,
 	struct ctl_table tbl;
 	bool changed = false;
 	char *none = "none";
-	char tmp[8];
+	char tmp[8] = {0};
 	int ret;
 
 	memset(&tbl, 0, sizeof(struct ctl_table));

[toc] | [prev] | [standalone]


Page 9 of 9 — ← Prev page 1 2 3 4 5 6 7 8 [9]

Back to top | Article view | linux.kernel


csiph-web