Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1242879 > unrolled thread

[PATCH 3.2 000/107] 3.2.72-rc1 review

Started byBen Hutchings <ben@decadent.org.uk>
First post2015-10-09 02:30 +0200
Last post2015-10-09 03:00 +0200
Articles 20 on this page of 79 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.2 000/107] 3.2.72-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
    [PATCH 3.2 072/107] USB: option: add ZTE PIDs Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
    [PATCH 3.2 069/107] hfs,hfsplus: cache pages correctly between  bnode_create and bnode_free Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
    [PATCH 3.2 015/107] ocfs2: fix BUG in ocfs2_downconvert_thread_do_work() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
    [PATCH 3.2 049/107] DRM - radeon: Don't link train DisplayPort on  HPD until we get the dpcd Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
    [PATCH 3.2 098/107] ipv6: lock socket in ip6_datagram_connect() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
    [PATCH 3.2 024/107] libfc: Fix fc_fcp_cleanup_each_cmd() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
    [PATCH 3.2 094/107] Initialize msg/shm IPC objects before doing  ipc_addid() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 060/107] drm/i915: Always mark the object as dirty  when used by the GPU Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 047/107] eCryptfs: Invalidate dcache entries when  lower i_nlink is zero Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 009/107] target: REPORT LUNS should return LUN 0 even  for dynamic ACLs Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 095/107] net/tipc: initialize security state for new  connection  socket Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 018/107] x86/ldt: Make modify_ldt synchronous Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 036/107] PCI: Add VPD function 0 quirk for Intel  Ethernet devices Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 016/107] net: Clone skb before setting peeked flag Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 026/107] x86/ldt: Further fix FPU emulation Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 029/107] sparc64: Fix userspace FPU register corruptions. Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 023/107] libiscsi: Fix host busy blocking during  connection teardown Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 019/107] x86/ldt: Correct LDT access in single  stepping logic Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 017/107] net: Fix skb_set_peeked use-after-free bug Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 005/107] crypto: ixp4xx - Remove bogus BUG_ON on  scattered dst buffer Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 033/107] PCI: Fix TI816X class code quirk Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 051/107] rtlwifi: rtl8192cu: Add new device ID Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 032/107] [media] rc-core: fix remove uevent generation Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 068/107] powerpc/MSI: Fix race condition in tearing  down MSI interrupts Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 037/107] usb: gadget: m66592-udc: forever loop in  set_feature() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 054/107] xfs: return errors from partial I/O failures  to files Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 103/107] ipv6: prevent fib6_run_gc() contention Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 044/107] serial: 8250: bind to ALi Fast Infrared  Controller (ALI5123) Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 070/107] hfs: fix B-tree corruption after insertion at  position 0 Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 050/107] rtlwifi: rtl8192cu: Add new device ID Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 048/107] xfs: Fix xfs_attr_leafblock definition Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 025/107] ipc,sem: fix use after free on IPC_RMID after  a task using same semaphore set exits Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 007/107] target/iscsi: Fix double free of a TUR  followed by a solicited NOPOUT Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
    [PATCH 3.2 081/107] usb: Use the USB_SS_MULT() macro to get the  burst multiplier. Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 079/107] s390/compat: correct uc_sigmask of the compat  signal frame Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 091/107] virtio-net: drop NETIF_F_FRAGLIST Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 053/107] drivercore: Fix unregistration path of  platform devices Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 006/107] USB: sierra: add 1199:68AB device ID Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 059/107] spi: spi-pxa2xx: Check status register to  determine if SSSR_TINT is disabled Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 002/107] pktgen: Require CONFIG_INET due to use of  IPv4 checksum function Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 085/107] cifs: use server timestamp for ntlmv2  authentication Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 066/107] ARM: 8429/1: disable GCC SRA optimization Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 061/107] Add radeon suspend/resume quirk for HP Compaq  dc5750. Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 046/107] USB: ftdi_sio: Added custom PID for  CustomWare products Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 013/107] perf: Fix fasync handling on inherited events Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 074/107] btrfs: skip waiting on ordered range for  special files Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 052/107] of/address: Don't loop forever in  of_find_matching_node_by_address(). Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 042/107] NFSv4: don't set SETATTR for O_RDONLY|O_EXCL Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 093/107] ipc/sem.c: fully initialize sem_array before  making it visible Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 039/107] auxdisplay: ks0108: fix refcount Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 083/107] usb: xhci: Clear XHCI_STATE_DYING on start Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 062/107] IB/uverbs: reject invalid or unknown opcodes Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 058/107] IB/uverbs: Fix race between ib_uverbs_open  and remove_one Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 102/107] perf tools: Fix build with perl 5.18 Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 075/107] ARM: 7880/1: Clear the IT state independent  of the Thumb-2 mode Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 105/107] parisc: Filter out spurious interrupts in  PA-RISC irq handler Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 100/107] net/ipv6: Correct PIM6 mrt_lock handling Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 030/107] dcache: Handle escaped paths in prepend_path Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 041/107] windfarm: decrement client count when  unregistering Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 076/107] ARM: fix Thumb2 signal handling when ARMv6 is  enabled Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 057/107] IB/mlx4: Use correct SL on AH query under RoCE Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 090/107] ipv6: addrconf: validate new MTU before  applying it Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 010/107] MIPS: Fix sched_getaffinity with MT FPAFF enabled Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
    [PATCH 3.2 063/107] Input: evdev - do not report errors form flush() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
    [PATCH 3.2 078/107] ASoC: fix broken pxa SoC support Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
    [PATCH 3.2 064/107] crypto: ghash-clmulni: specify context size  for ghash async algorithm Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
    [PATCH 3.2 065/107] fs: create and use seq_show_option for escaping Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
    [PATCH 3.2 084/107] xhci: change xhci 1.0 only restrictions to  support xhci 1.1 Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
    [PATCH 3.2 071/107] perf header: Fixup reading of HEADER_NRCPUS  feature Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
    [PATCH 3.2 104/107] ipv6: update ip6_rt_last_gc every time GC is run Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
    [PATCH 3.2 055/107] IB/qib: Change lkey table allocation to  support more MRs Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
    [PATCH 3.2 073/107] Btrfs: fix read corruption of compressed and  shared extents Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
    Re: [PATCH 3.2 000/107] 3.2.72-rc1 review Guenter Roeck <linux@roeck-us.net> - 2015-10-09 03:00 +0200
      Re: [PATCH 3.2 000/107] 3.2.72-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:20 +0200
    [PATCH 3.2 077/107] x86/platform: Fix Geode LX timekeeping in the  generic x86 build Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
    [PATCH 3.2 087/107] ocfs2/dlm: fix deadlock when dispatch assert  master Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
    [PATCH 3.2 056/107] SUNRPC: xs_reset_transport must mark the  connection as disconnected Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
    [PATCH 3.2 082/107] xhci: give command abortion one more chance  before killing xhci Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200

Page 1 of 4  [1] 2 3 4  Next page →


#1242879 — [PATCH 3.2 000/107] 3.2.72-rc1 review

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:30 +0200
Subject[PATCH 3.2 000/107] 3.2.72-rc1 review
Message-ID<qhtzH-2tg-3@gated-at.bofh.it>
This is the start of the stable review cycle for the 3.2.72 release.
There are 107 patches in this series, which will be posted as responses
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Tue Oct 13 00:00:00 UTC 2015.
Anything received after that time might be too late.

A combined patch relative to 3.2.71 will be posted as an additional
response to this.  A shortlog and diffstat can be found below.

Ben.

-------------

Adrien Schildknecht (1):
      rtlwifi: rtl8192cu: Add new device ID
         [1642d09fb9b128e8e538b2a4179962a34f38dff9]

Alexei Potashnik (1):
      target/iscsi: Fix double free of a TUR followed by a solicited NOPOUT
         [9547308bda296b6f69876c840a0291fcfbeddbb8]

Andrey Ryabinin (1):
      crypto: ghash-clmulni: specify context size for ghash async algorithm
         [71c6da846be478a61556717ef1ee1cea91f5d6a8]

Andy Lutomirski (3):
      x86/ldt: Further fix FPU emulation
         [12e244f4b550498bbaf654a52f93633f7dde2dc7]
      x86/ldt: Make modify_ldt synchronous
         [37868fe113ff2ba814b3b4eb12df214df555f8dc]
      x86/paravirt: Replace the paravirt nop with a bona fide empty function
         [fc57a7c68020dcf954428869eafd934c0ab1536f]

Ard Biesheuvel (1):
      ARM: 8429/1: disable GCC SRA optimization
         [a077224fd35b2f7fbc93f14cf67074fc792fbac2]

Arnaldo Carvalho de Melo (1):
      perf header: Fixup reading of HEADER_NRCPUS feature
         [caa470475d9b59eeff093ae650800d34612c4379]

Bart Van Assche (1):
      libfc: Fix fc_fcp_cleanup_each_cmd()
         [8f2777f53e3d5ad8ef2a176a4463a5c8e1a16431]

Ben Hutchings (2):
      Revert "sctp: Fix race between OOTB responce and route  removal"
         [not upstream; fix was correct there]
      ipv6: Fix build failure when CONFIG_INET disabled
         [not upstream; bug was introduced on 3.2 branch]

Benjamin Randazzo (1):
      md: use kzalloc() when bitmap is disabled
         [b6878d9e03043695dbf3fa1caa6dfc09db225b16]

Bjorn Helgaas (1):
      PCI: Fix TI816X class code quirk
         [d1541dc977d376406f4584d8eb055488655c98ec]

Bob Copeland (1):
      mac80211: enable assoc check for mesh interfaces
         [3633ebebab2bbe88124388b7620442315c968e8f]

Chris Wilson (1):
      drm/i915: Always mark the object as dirty when used by the GPU
         [51bc140431e233284660b1d22c47dec9ecdb521e]

Christoph Hellwig (1):
      IB/uverbs: reject invalid or unknown opcodes
         [b632ffa7cee439ba5dce3b3bc4a5cbe2b3e20133]

Dan Carpenter (2):
      rds: fix an integer overflow test in rds_info_getsockopt()
         [468b732b6f76b138c0926eadf38ac88467dcd271]
      usb: gadget: m66592-udc: forever loop in set_feature()
         [5feb5d2003499b1094d898c010a7604d7afddc4c]

David Ahern (1):
      net: Fix RCU splat in af_key
         [ba51b6be38c122f7dab40965b4397aaf6188a464]

David Daney (2):
      MIPS: Make set_pte() SMP safe.
         [46011e6ea39235e4aca656673c500eac81a07a17]
      of/address: Don't loop forever in of_find_matching_node_by_address().
         [3a496b00b6f90c41bd21a410871dfc97d4f3c7ab]

David Härdeman (1):
      [media] rc-core: fix remove uevent generation
         [a66b0c41ad277ae62a3ae6ac430a71882f899557]

David Jeffery (1):
      xfs: return errors from partial I/O failures to files
         [c9eb256eda4420c06bb10f5e8fbdbe1a34bc98e0]

David S. Miller (1):
      sparc64: Fix userspace FPU register corruptions.
         [44922150d87cef616fd183220d43d8fde4d41390]

David Woodhouse (1):
      x86/platform: Fix Geode LX timekeeping in the generic x86 build
         [03da3ff1cfcd7774c8780d2547ba0d995f7dc03d]

Dingtianhong (1):
      bonding: correct the MAC address for "follow"  fail_over_mac policy
         [a951bc1e6ba58f11df5ed5ddc41311e10f5fd20b]

Dirk Behme (1):
      USB: sierra: add 1199:68AB device ID
         [74472233233f577eaa0ca6d6e17d9017b6e53150]

Eric Dumazet (1):
      ipv6: lock socket in ip6_datagram_connect()
         [03645a11a570d52e70631838cb786eb4253eb463]

Eric W. Biederman (2):
      dcache: Handle escaped paths in prepend_path
         [cde93be45a8a90d8c264c776fab63487b5038a65]
      vfs: Test for and handle paths that are unreachable from  their mnt_root
         [397d425dc26da728396e66d392d5dcb8dac30c37]

Felix Fietkau (1):
      MIPS: Fix sched_getaffinity with MT FPAFF enabled
         [1d62d737555e1378eb62a8bba26644f7d97139d2]

Filipe Manana (1):
      Btrfs: fix read corruption of compressed and shared extents
         [005efedf2c7d0a270ffbe28d8997b03844f3e3e7]

Grant Likely (1):
      drivercore: Fix unregistration path of platform devices
         [7f5dcaf1fdf289767a126a0a5cc3ef39b5254b06]

Helge Deller (1):
      parisc: Filter out spurious interrupts in PA-RISC irq handler
         [b1b4e435e4ef7de77f07bf2a42c8380b960c2d44]

Herbert Xu (4):
      crypto: ixp4xx - Remove bogus BUG_ON on scattered dst buffer
         [f898c522f0e9ac9f3177d0762b76e2ab2d2cf9c0]
      net: Clone skb before setting peeked flag
         [738ac1ebb96d02e0d23bc320302a6ea94c612dec]
      net: Fix skb csum races when peeking
         [89c22d8c3b278212eef6a8cc66b570bc840a6f5a]
      net: Fix skb_set_peeked use-after-free bug
         [a0a2a6602496a45ae838a96db8b8173794b5d398]

Herton R. Krzesinski (1):
      ipc,sem: fix use after free on IPC_RMID after a task using same semaphore set exits
         [602b8593d2b4138c10e922eeaafe306f6b51817b]

Hin-Tak Leung (2):
      hfs,hfsplus: cache pages correctly between bnode_create and bnode_free
         [7cb74be6fd827e314f81df3c5889b87e4c87c569]
      hfs: fix B-tree corruption after insertion at position 0
         [b4cc0efea4f0bfa2477c56af406cfcf3d3e58680]

Jan Kara (3):
      jbd2: avoid infinite loop when destroying aborted journal
         [841df7df196237ea63233f0f9eaa41db53afd70f]
      jbd2: protect all log tail updates with j_checkpoint_mutex
         [a78bb11d7acd525623c6a0c2ff4e213d527573fa]
      xfs: Fix xfs_attr_leafblock definition
         [ffeecc5213024ae663377b442eedcfbacf6d0c5d]

Jason Wang (1):
      virtio-net: drop NETIF_F_FRAGLIST
         [48900cb6af4282fa0fb6ff4d72a81aa3dadb5c39]

Jeff Mahoney (1):
      btrfs: skip waiting on ordered range for special files
         [a30e577c96f59b1e1678ea5462432b09bf7d5cbc]

Jeffery Miller (1):
      Add radeon suspend/resume quirk for HP Compaq dc5750.
         [09bfda10e6efd7b65bcc29237bee1765ed779657]

Joe Thornber (1):
      dm btree: add ref counting ops for the leaves of top level btrees
         [b0dc3c8bc157c60b1d470163882be8c13e1950af]

Johan Hovold (1):
      USB: whiteheat: fix potential null-deref at probe
         [cbb4be652d374f64661137756b8f357a1827d6a4]

John Soni Jose (1):
      libiscsi: Fix host busy blocking during connection teardown
         [660d0831d1494a6837b2f810d08b5be092c1f31d]

Joseph Qi (2):
      ocfs2/dlm: fix deadlock when dispatch assert master
         [012572d4fc2e4ddd5c8ec8614d51414ec6cae02a]
      ocfs2: fix BUG in ocfs2_downconvert_thread_do_work()
         [209f7512d007980fd111a74a064d70a3656079cf]

Juergen Gross (2):
      x86/ldt: Correct FPU emulation access to LDT
         [4809146b86c3d41ce588fdb767d021e2a80600dd]
      x86/ldt: Correct LDT access in single stepping logic
         [136d9d83c07c5e30ac49fc83b27e8c4842f108fc]

Jui Nee Tan (1):
      spi: spi-pxa2xx: Check status register to determine if SSSR_TINT is disabled
         [02bc933ebb59208f42c2e6305b2c17fd306f695d]

Kees Cook (1):
      fs: create and use seq_show_option for escaping
         [a068acf2ee77693e0bf39d6e07139ba704f461c3]

Kirill A. Shutemov (1):
      perf tools: Fix build with perl 5.18
         [575bf1d04e908469d26da424b52fc1b12a1db9d8]

Konstantin Khlebnikov (1):
      pagemap: hide physical addresses from non-privileged users
         [1c90308e7a77af6742a97d1021cca923b23b7f0d]

Linus Torvalds (1):
      Initialize msg/shm IPC objects before doing ipc_addid()
         [b9a532277938798b53178d5a66af6e2915cb27cf]

Liu.Zhao (1):
      USB: option: add ZTE PIDs
         [19ab6bc5674a30fdb6a2436b068d19a3c17dc73e]

Lucien (1):
      sctp: donot reset the overall_error_count in SHUTDOWN_RECEIVE state
         [f648f807f61e64d247d26611e34cc97e4ed03401]

Maciej S. Szmigiero (1):
      serial: 8250: bind to ALi Fast Infrared Controller (ALI5123)
         [1d7002777a8fe8188caaa98d4a8eb4ed298fcdae]

Manfred Spraul (1):
      ipc/sem.c: fully initialize sem_array before making it visible
         [e8577d1f0329d4842e8302e289fb2c22156abef4]

Marcelo Leitner (1):
      ipv6: addrconf: validate new MTU before applying it
         [77751427a1ff25b27d47a4c36b12c3c8667855ac]

Marek Marczykowski-Górecki (1):
      xen/gntdevt: Fix race condition in gntdev_release()
         [30b03d05e07467b8c6ec683ea96b5bffcbcd3931]

Marek Vasut (1):
      rtlwifi: rtl8192cu: Add new device ID
         [9374e7d2fdcad3c36dafc8d3effd554bc702c4b6]

Mark Rustad (2):
      PCI: Add VPD function 0 quirk for Intel Ethernet devices
         [7aa6ca4d39edf01f997b9e02cf6d2fdeb224f351]
      PCI: Add dev_flags bit to access VPD through function 0
         [932c435caba8a2ce473a91753bad0173269ef334]

Martin Schwidefsky (1):
      s390/compat: correct uc_sigmask of the compat signal frame
         [8d4bd0ed0439dfc780aab801a085961925ed6838]

Masahiro Yamada (1):
      devres: fix devres_get()
         [64526370d11ce8868ca495723d595b61e8697fbf]

Mathias Nyman (4):
      usb: Use the USB_SS_MULT() macro to get the burst multiplier.
         [ff30cbc8da425754e8ab96904db1d295bd034f27]
      xhci: change xhci 1.0 only restrictions to support xhci 1.1
         [dca7794539eff04b786fb6907186989e5eaaa9c2]
      xhci: fix off by one error in TRB DMA address boundary check
         [7895086afde2a05fa24a0e410d8e6b75ca7c8fdd]
      xhci: give command abortion one more chance before killing xhci
         [a6809ffd1687b3a8c192960e69add559b9d32649]

Matthijs Kooijman (1):
      USB: ftdi_sio: Added custom PID for CustomWare products
         [1fb8dc36384ae1140ee6ccc470de74397606a9d5]

Michal Kubeček (2):
      ipv6: prevent fib6_run_gc() contention
         [2ac3ac8f86f2fe065d746d9a9abaca867adec577]
      ipv6: update ip6_rt_last_gc every time GC is run
         [49a18d86f66d33a20144ecb5a34bba0d1856b260]

Mike Marciniszyn (1):
      IB/qib: Change lkey table allocation to support more MRs
         [d6f1c17e162b2a11e708f28fa93f2f79c164b442]

NeilBrown (2):
      NFSv4: don't set SETATTR for O_RDONLY|O_EXCL
         [efcbc04e16dfa95fef76309f89710dd1d99a5453]
      md/raid1: extend spinlock to protect raid1_end_read_request against inconsistencies
         [423f04d63cf421ea436bcc5be02543d549ce4b28]

Nikhil Badola (1):
      drivers: usb: fsl: Workaround for USB erratum-A005275
         [f8786a91548df6930643a052e40e5c0b7a8403a5]

Noa Osherovich (1):
      IB/mlx4: Use correct SL on AH query under RoCE
         [5e99b139f1b68acd65e36515ca347b03856dfb5a]

Oleg Nesterov (1):
      net: pktgen: fix race between pktgen_thread_worker()  and kthread_stop()
         [fecdf8be2d91e04b0a9a4f79ff06499a36f5d14f]

Paolo Bonzini (1):
      KVM: x86: trap AMD MSRs for the TSeg base and mask
         [3afb1121800128aae9f5722e50097fcf1a9d4d88]

Paul Bolle (1):
      windfarm: decrement client count when unregistering
         [fe2b592173ff0274e70dc44d1d28c19bb995aa7c]

Paul Mackerras (1):
      powerpc/MSI: Fix race condition in tearing down MSI interrupts
         [e297c939b745e420ef0b9dc989cb87bda617b399]

Peter Chen (1):
      usb: host: ehci-sys: delete useless bus_to_hcd conversion
         [0521cfd06e1ebcd575e7ae36aab068b38df23850]

Peter Seiderer (1):
      cifs: use server timestamp for ntlmv2 authentication
         [98ce94c8df762d413b3ecb849e2b966b21606d04]

Peter Zijlstra (1):
      perf: Fix fasync handling on inherited events
         [fed66e2cdd4f127a43fd11b8d92a99bdd429528c]

Richard Laing (1):
      net/ipv6: Correct PIM6 mrt_lock handling
         [25b4a44c19c83d98e8c0807a7ede07c1f28eab8b]

Richard Weinberger (1):
      localmodconfig: Use Kbuild files too
         [c0ddc8c745b7f89c50385fd7aa03c78dc543fa7a]

Robert Jarzmik (1):
      ASoC: fix broken pxa SoC support
         [3c8f7710c1c44fb650bc29b6ef78ed8b60cfaa28]

Roger Quadros (1):
      usb: xhci: Clear XHCI_STATE_DYING on start
         [e5bfeab0ad515b4f6df39fe716603e9dc6d3dfd0]

Roland Dreier (1):
      target: REPORT LUNS should return LUN 0 even for dynamic ACLs
         [9c395170a559d3b23dad100b01fc4a89d661c698]

Russell King (1):
      ARM: fix Thumb2 signal handling when ARMv6 is enabled
         [9b55613f42e8d40d5c9ccb8970bde6af4764b2ab]

Sasha Levin (1):
      RDS: verify the underlying transport exists before creating a connection
         [74e98eb085889b0d2d4908f59f6e00026063014f]

Stephen Chandler Paul (1):
      DRM - radeon: Don't link train DisplayPort on HPD until we get the dpcd
         [924f92bf12bfbef3662619e3ed24a1cea7c1cbcd]

Stephen Smalley (1):
      net/tipc: initialize security state for new connection  socket
         [fdd75ea8df370f206a8163786e7470c1277a5064]

Sudip Mukherjee (1):
      auxdisplay: ks0108: fix refcount
         [bab383de3b84e584b0f09227151020b2a43dc34c]

T.J. Purtell (1):
      ARM: 7880/1: Clear the IT state independent of the Thumb-2 mode
         [6ecf830e5029598732e04067e325d946097519cb]

Takashi Iwai (1):
      Input: evdev - do not report errors form flush()
         [eb38f3a4f6e86f8bb10a3217ebd85ecc5d763aae]

Thomas Graf (1):
      pktgen: Require CONFIG_INET due to use of IPv4 checksum function
         [ffd756b3174e496cf6f3c5458c434e31d2cd48b0]

Trond Myklebust (1):
      SUNRPC: xs_reset_transport must mark the connection as disconnected
         [0c78789e3a030615c6650fde89546cadf40ec2cc]

Tyler Hicks (1):
      eCryptfs: Invalidate dcache entries when lower i_nlink is zero
         [5556e7e6d30e8e9b5ee51b0e5edd526ee80e5e36]

Wilson Kok (1):
      fib_rules: fix fib rule dumps across multiple skbs
         [41fc014332d91ee90c32840bf161f9685b7fbf2b]

Xiao Guangrong (1):
      KVM: MMU: fix validation of mmio page fault
         [6f691251c0350ac52a007c54bf3ef62e9d8cdc5e]

Yishai Hadas (1):
      IB/uverbs: Fix race between ib_uverbs_open and remove_one
         [35d4a0b63dc0c6d1177d4f532a9deae958f0662c]

 Makefile                                       |   4 +-
 arch/arm/Makefile                              |   8 +
 arch/arm/kernel/signal.c                       |  19 +-
 arch/mips/include/asm/pgtable.h                |  31 +++
 arch/mips/kernel/mips-mt-fpaff.c               |   5 +-
 arch/parisc/kernel/irq.c                       |   8 +-
 arch/powerpc/platforms/powernv/pci.c           |   4 +-
 arch/powerpc/sysdev/fsl_msi.c                  |   5 +-
 arch/powerpc/sysdev/mpic_pasemi_msi.c          |   5 +-
 arch/powerpc/sysdev/mpic_u3msi.c               |   5 +-
 arch/powerpc/sysdev/ppc4xx_msi.c               |   5 +-
 arch/s390/kernel/compat_signal.c               |  30 ++-
 arch/sparc/include/asm/visasm.h                |  14 +-
 arch/sparc/lib/VISsave.S                       |  67 +------
 arch/x86/crypto/ghash-clmulni-intel_glue.c     |   1 +
 arch/x86/include/asm/desc.h                    |  15 --
 arch/x86/include/asm/mmu.h                     |   3 +-
 arch/x86/include/asm/mmu_context.h             |  49 ++++-
 arch/x86/include/asm/msr-index.h               |   1 +
 arch/x86/kernel/cpu/common.c                   |   4 +-
 arch/x86/kernel/entry_64.S                     |  11 +
 arch/x86/kernel/ldt.c                          | 267 ++++++++++++++-----------
 arch/x86/kernel/paravirt.c                     |  16 +-
 arch/x86/kernel/process_64.c                   |   4 +-
 arch/x86/kernel/step.c                         |   8 +-
 arch/x86/kernel/tsc.c                          |  17 +-
 arch/x86/kvm/mmu.c                             |  45 -----
 arch/x86/kvm/x86.c                             |   2 +
 arch/x86/math-emu/fpu_entry.c                  |   3 +-
 arch/x86/math-emu/fpu_system.h                 |  21 +-
 arch/x86/math-emu/get_address.c                |   3 +-
 arch/x86/power/cpu.c                           |   3 +-
 drivers/auxdisplay/ks0108.c                    |   1 +
 drivers/base/devres.c                          |   4 +-
 drivers/base/platform.c                        |   8 +-
 drivers/crypto/ixp4xx_crypto.c                 |   1 -
 drivers/gpu/drm/i915/i915_gem_execbuffer.c     |   2 +-
 drivers/gpu/drm/radeon/radeon_combios.c        |   8 +
 drivers/gpu/drm/radeon/radeon_connectors.c     |   5 +
 drivers/infiniband/core/uverbs.h               |   3 +-
 drivers/infiniband/core/uverbs_cmd.c           |  10 +-
 drivers/infiniband/core/uverbs_main.c          |  43 ++--
 drivers/infiniband/hw/mlx4/ah.c                |   6 +-
 drivers/infiniband/hw/qib/qib.h                |   4 +
 drivers/infiniband/hw/qib/qib_keys.c           |   4 +
 drivers/infiniband/hw/qib/qib_verbs.c          |  14 +-
 drivers/infiniband/hw/qib/qib_verbs.h          |   2 +
 drivers/input/evdev.c                          |  13 +-
 drivers/macintosh/windfarm_core.c              |   2 +-
 drivers/md/md.c                                |   4 +-
 drivers/md/persistent-data/dm-btree-internal.h |   6 +
 drivers/md/persistent-data/dm-btree-remove.c   |  12 +-
 drivers/md/persistent-data/dm-btree-spine.c    |  37 ++++
 drivers/md/persistent-data/dm-btree.c          |   7 +-
 drivers/md/raid1.c                             |  10 +-
 drivers/media/rc/rc-main.c                     |   3 -
 drivers/net/bonding/bond_main.c                |  20 ++
 drivers/net/virtio_net.c                       |   4 +-
 drivers/net/wireless/rtlwifi/rtl8192cu/sw.c    |   2 +
 drivers/of/address.c                           |   6 +-
 drivers/pci/access.c                           |  61 +++++-
 drivers/pci/quirks.c                           |  14 +-
 drivers/scsi/libfc/fc_fcp.c                    |  19 +-
 drivers/scsi/libiscsi.c                        |  25 +--
 drivers/spi/spi-pxa2xx.c                       |   4 +
 drivers/target/iscsi/iscsi_target.c            |   2 +-
 drivers/target/target_core_device.c            |  13 +-
 drivers/tty/serial/8250_pnp.c                  |   6 +
 drivers/usb/core/config.c                      |   5 +-
 drivers/usb/gadget/m66592-udc.c                |   2 +-
 drivers/usb/host/ehci-fsl.c                    |   4 +
 drivers/usb/host/ehci-hub.c                    |   7 +
 drivers/usb/host/ehci-sysfs.c                  |  14 +-
 drivers/usb/host/ehci.h                        |  12 ++
 drivers/usb/host/fsl-mph-dr-of.c               |   4 +
 drivers/usb/host/xhci-mem.c                    |   6 +-
 drivers/usb/host/xhci-ring.c                   |  15 +-
 drivers/usb/host/xhci.c                        |   3 +-
 drivers/usb/serial/ftdi_sio.c                  |   4 +
 drivers/usb/serial/ftdi_sio_ids.h              |   8 +
 drivers/usb/serial/option.c                    |  24 +++
 drivers/usb/serial/sierra.c                    |   1 +
 drivers/usb/serial/whiteheat.c                 |  31 +++
 drivers/xen/gntdev.c                           |   4 +
 fs/btrfs/extent_io.c                           |  67 ++++++-
 fs/btrfs/inode.c                               |   3 +-
 fs/ceph/super.c                                |   8 +-
 fs/cifs/cifsencrypt.c                          |  52 ++++-
 fs/cifs/cifsfs.c                               |   4 +-
 fs/dcache.c                                    |  10 +
 fs/ecryptfs/dentry.c                           |  32 +--
 fs/ext4/super.c                                |   4 +-
 fs/gfs2/super.c                                |   6 +-
 fs/hfs/bnode.c                                 |   9 +-
 fs/hfs/brec.c                                  |  20 +-
 fs/hfs/super.c                                 |   4 +-
 fs/hfsplus/bnode.c                             |   3 -
 fs/hfsplus/options.c                           |   4 +-
 fs/hostfs/hostfs_kern.c                        |   2 +-
 fs/jbd2/checkpoint.c                           |  39 +++-
 fs/jbd2/commit.c                               |   4 +-
 fs/jbd2/journal.c                              |  34 +++-
 fs/namei.c                                     |  29 ++-
 fs/nfs/nfs4proc.c                              |   2 +-
 fs/ocfs2/dlm/dlmmaster.c                       |   7 +-
 fs/ocfs2/dlm/dlmrecovery.c                     |   6 +-
 fs/ocfs2/dlmglue.c                             |  10 +-
 fs/ocfs2/super.c                               |   4 +-
 fs/proc/task_mmu.c                             |  28 ++-
 fs/xfs/xfs_aops.c                              |   3 +-
 fs/xfs/xfs_attr_leaf.h                         |  11 +-
 fs/xfs/xfs_super.c                             |   4 +-
 include/linux/fsl_devices.h                    |   1 +
 include/linux/jbd2.h                           |   3 +-
 include/linux/pci.h                            |   2 +
 include/linux/seq_file.h                       |  35 ++++
 include/net/ip.h                               |   1 +
 include/net/ip6_fib.h                          |   2 +-
 ipc/msg.c                                      |  18 +-
 ipc/sem.c                                      |  40 ++--
 ipc/shm.c                                      |  13 +-
 ipc/util.c                                     |   8 +-
 kernel/cgroup.c                                |   7 +-
 kernel/events/core.c                           |  12 +-
 net/Kconfig                                    |   2 +-
 net/core/datagram.c                            |  46 ++++-
 net/core/fib_rules.c                           |  14 +-
 net/core/pktgen.c                              |   4 +-
 net/ipv4/datagram.c                            |  16 +-
 net/ipv6/Makefile                              |   3 +-
 net/ipv6/addrconf.c                            |  17 +-
 net/ipv6/datagram.c                            |  20 +-
 net/ipv6/ip6_fib.c                             |  25 +--
 net/ipv6/ip6mr.c                               |   2 +-
 net/ipv6/ndisc.c                               |   4 +-
 net/ipv6/route.c                               |   8 +-
 net/key/af_key.c                               |  46 ++---
 net/mac80211/tx.c                              |   3 -
 net/rds/connection.c                           |   6 +
 net/rds/info.c                                 |   2 +-
 net/sctp/output.c                              |   4 +-
 net/sctp/sm_sideeffect.c                       |   2 +-
 net/sunrpc/xprtsock.c                          |   2 +
 net/tipc/socket.c                              |   2 +
 scripts/kconfig/streamline_config.pl           |   2 +-
 security/selinux/hooks.c                       |   2 +-
 sound/arm/Kconfig                              |  15 +-
 sound/soc/pxa/Kconfig                          |   2 -
 tools/perf/Makefile                            |   4 +-
 tools/perf/util/header.c                       |  22 +-
 150 files changed, 1372 insertions(+), 666 deletions(-)

-- 
Ben Hutchings
If the facts do not conform to your theory, they must be disposed of.

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [next] | [standalone]


#1242880 — [PATCH 3.2 072/107] USB: option: add ZTE PIDs

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:30 +0200
Subject[PATCH 3.2 072/107] USB: option: add ZTE PIDs
Message-ID<qhtJq-2EJ-59@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: "Liu.Zhao" <lzsos369@163.com>

commit 19ab6bc5674a30fdb6a2436b068d19a3c17dc73e upstream.

This is intended to add ZTE device PIDs on kernel.

Signed-off-by: Liu.Zhao <lzsos369@163.com>
[johan: sort the new entries ]
Signed-off-by: Johan Hovold <johan@kernel.org>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/option.c | 24 ++++++++++++++++++++++++
 1 file changed, 24 insertions(+)

--- a/drivers/usb/serial/option.c
+++ b/drivers/usb/serial/option.c
@@ -276,6 +276,10 @@ static void option_instat_callback(struc
 #define ZTE_PRODUCT_MF622			0x0001
 #define ZTE_PRODUCT_MF628			0x0015
 #define ZTE_PRODUCT_MF626			0x0031
+#define ZTE_PRODUCT_ZM8620_X			0x0396
+#define ZTE_PRODUCT_ME3620_MBIM			0x0426
+#define ZTE_PRODUCT_ME3620_X			0x1432
+#define ZTE_PRODUCT_ME3620_L			0x1433
 #define ZTE_PRODUCT_CDMA_TECH			0xfffe
 #define ZTE_PRODUCT_AC8710			0xfff1
 #define ZTE_PRODUCT_AC2726			0xfff5
@@ -547,6 +551,18 @@ static const struct option_blacklist_inf
 	.sendsetup = BIT(1) | BIT(2) | BIT(3),
 };
 
+static const struct option_blacklist_info zte_me3620_mbim_blacklist = {
+	.reserved = BIT(2) | BIT(3) | BIT(4),
+};
+
+static const struct option_blacklist_info zte_me3620_xl_blacklist = {
+	.reserved = BIT(3) | BIT(4) | BIT(5),
+};
+
+static const struct option_blacklist_info zte_zm8620_x_blacklist = {
+	.reserved = BIT(3) | BIT(4) | BIT(5),
+};
+
 static const struct option_blacklist_info huawei_cdc12_blacklist = {
 	.reserved = BIT(1) | BIT(2),
 };
@@ -1578,6 +1594,14 @@ static const struct usb_device_id option
 	 .driver_info = (kernel_ulong_t)&zte_ad3812_z_blacklist },
 	{ USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, ZTE_PRODUCT_MC2716, 0xff, 0xff, 0xff),
 	 .driver_info = (kernel_ulong_t)&zte_mc2716_z_blacklist },
+	{ USB_DEVICE(ZTE_VENDOR_ID, ZTE_PRODUCT_ME3620_L),
+	 .driver_info = (kernel_ulong_t)&zte_me3620_xl_blacklist },
+	{ USB_DEVICE(ZTE_VENDOR_ID, ZTE_PRODUCT_ME3620_MBIM),
+	 .driver_info = (kernel_ulong_t)&zte_me3620_mbim_blacklist },
+	{ USB_DEVICE(ZTE_VENDOR_ID, ZTE_PRODUCT_ME3620_X),
+	 .driver_info = (kernel_ulong_t)&zte_me3620_xl_blacklist },
+	{ USB_DEVICE(ZTE_VENDOR_ID, ZTE_PRODUCT_ZM8620_X),
+	 .driver_info = (kernel_ulong_t)&zte_zm8620_x_blacklist },
 	{ USB_VENDOR_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0xff, 0x02, 0x01) },
 	{ USB_VENDOR_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0xff, 0x02, 0x05) },
 	{ USB_VENDOR_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0xff, 0x86, 0x10) },

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242881 — [PATCH 3.2 069/107] hfs,hfsplus: cache pages correctly between bnode_create and bnode_free

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:30 +0200
Subject[PATCH 3.2 069/107] hfs,hfsplus: cache pages correctly between bnode_create and bnode_free
Message-ID<qhtJq-2EJ-61@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Hin-Tak Leung <htl10@users.sourceforge.net>

commit 7cb74be6fd827e314f81df3c5889b87e4c87c569 upstream.

Pages looked up by __hfs_bnode_create() (called by hfs_bnode_create() and
hfs_bnode_find() for finding or creating pages corresponding to an inode)
are immediately kmap()'ed and used (both read and write) and kunmap()'ed,
and should not be page_cache_release()'ed until hfs_bnode_free().

This patch fixes a problem I first saw in July 2012: merely running "du"
on a large hfsplus-mounted directory a few times on a reasonably loaded
system would get the hfsplus driver all confused and complaining about
B-tree inconsistencies, and generates a "BUG: Bad page state".  Most
recently, I can generate this problem on up-to-date Fedora 22 with shipped
kernel 4.0.5, by running "du /" (="/" + "/home" + "/mnt" + other smaller
mounts) and "du /mnt" simultaneously on two windows, where /mnt is a
lightly-used QEMU VM image of the full Mac OS X 10.9:

$ df -i / /home /mnt
Filesystem                  Inodes   IUsed      IFree IUse% Mounted on
/dev/mapper/fedora-root    3276800  551665    2725135   17% /
/dev/mapper/fedora-home   52879360  716221   52163139    2% /home
/dev/nbd0p2             4294967295 1387818 4293579477    1% /mnt

After applying the patch, I was able to run "du /" (60+ times) and "du
/mnt" (150+ times) continuously and simultaneously for 6+ hours.

There are many reports of the hfsplus driver getting confused under load
and generating "BUG: Bad page state" or other similar issues over the
years.  [1]

The unpatched code [2] has always been wrong since it entered the kernel
tree.  The only reason why it gets away with it is that the
kmap/memcpy/kunmap follow very quickly after the page_cache_release() so
the kernel has not had a chance to reuse the memory for something else,
most of the time.

The current RW driver appears to have followed the design and development
of the earlier read-only hfsplus driver [3], where-by version 0.1 (Dec
2001) had a B-tree node-centric approach to
read_cache_page()/page_cache_release() per bnode_get()/bnode_put(),
migrating towards version 0.2 (June 2002) of caching and releasing pages
per inode extents.  When the current RW code first entered the kernel [2]
in 2005, there was an REF_PAGES conditional (and "//" commented out code)
to switch between B-node centric paging to inode-centric paging.  There
was a mistake with the direction of one of the REF_PAGES conditionals in
__hfs_bnode_create().  In a subsequent "remove debug code" commit [4], the
read_cache_page()/page_cache_release() per bnode_get()/bnode_put() were
removed, but a page_cache_release() was mistakenly left in (propagating
the "REF_PAGES <-> !REF_PAGE" mistake), and the commented-out
page_cache_release() in bnode_release() (which should be spanned by
!REF_PAGES) was never enabled.

References:
[1]:
Michael Fox, Apr 2013
http://www.spinics.net/lists/linux-fsdevel/msg63807.html
("hfsplus volume suddenly inaccessable after 'hfs: recoff %d too large'")

Sasha Levin, Feb 2015
http://lkml.org/lkml/2015/2/20/85 ("use after free")

https://bugs.launchpad.net/ubuntu/+source/linux/+bug/740814
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1027887
https://bugzilla.kernel.org/show_bug.cgi?id=42342
https://bugzilla.kernel.org/show_bug.cgi?id=63841
https://bugzilla.kernel.org/show_bug.cgi?id=78761

[2]:
http://git.kernel.org/cgit/linux/kernel/git/tglx/history.git/commit/\
fs/hfs/bnode.c?id=d1081202f1d0ee35ab0beb490da4b65d4bc763db
commit d1081202f1d0ee35ab0beb490da4b65d4bc763db
Author: Andrew Morton <akpm@osdl.org>
Date:   Wed Feb 25 16:17:36 2004 -0800

    [PATCH] HFS rewrite

http://git.kernel.org/cgit/linux/kernel/git/tglx/history.git/commit/\
fs/hfsplus/bnode.c?id=91556682e0bf004d98a529bf829d339abb98bbbd

commit 91556682e0bf004d98a529bf829d339abb98bbbd
Author: Andrew Morton <akpm@osdl.org>
Date:   Wed Feb 25 16:17:48 2004 -0800

    [PATCH] HFS+ support

[3]:
http://sourceforge.net/projects/linux-hfsplus/

http://sourceforge.net/projects/linux-hfsplus/files/Linux%202.4.x%20patch/hfsplus%200.1/
http://sourceforge.net/projects/linux-hfsplus/files/Linux%202.4.x%20patch/hfsplus%200.2/

http://linux-hfsplus.cvs.sourceforge.net/viewvc/linux-hfsplus/linux/\
fs/hfsplus/bnode.c?r1=1.4&r2=1.5

Date:   Thu Jun 6 09:45:14 2002 +0000
Use buffer cache instead of page cache in bnode.c. Cache inode extents.

[4]:
http://git.kernel.org/cgit/linux/kernel/git/\
stable/linux-stable.git/commit/?id=a5e3985fa014029eb6795664c704953720cc7f7d

commit a5e3985fa014029eb6795664c704953720cc7f7d
Author: Roman Zippel <zippel@linux-m68k.org>
Date:   Tue Sep 6 15:18:47 2005 -0700

[PATCH] hfs: remove debug code

Signed-off-by: Hin-Tak Leung <htl10@users.sourceforge.net>
Signed-off-by: Sergei Antonov <saproj@gmail.com>
Reviewed-by: Anton Altaparmakov <anton@tuxera.com>
Reported-by: Sasha Levin <sasha.levin@oracle.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Christoph Hellwig <hch@infradead.org>
Cc: Vyacheslav Dubeyko <slava@dubeyko.com>
Cc: Sougata Santra <sougata@tuxera.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 fs/hfs/bnode.c     | 9 ++++-----
 fs/hfsplus/bnode.c | 3 ---
 2 files changed, 4 insertions(+), 8 deletions(-)

--- a/fs/hfs/bnode.c
+++ b/fs/hfs/bnode.c
@@ -287,7 +287,6 @@ static struct hfs_bnode *__hfs_bnode_cre
 			page_cache_release(page);
 			goto fail;
 		}
-		page_cache_release(page);
 		node->page[i] = page;
 	}
 
@@ -397,11 +396,11 @@ node_error:
 
 void hfs_bnode_free(struct hfs_bnode *node)
 {
-	//int i;
+	int i;
 
-	//for (i = 0; i < node->tree->pages_per_bnode; i++)
-	//	if (node->page[i])
-	//		page_cache_release(node->page[i]);
+	for (i = 0; i < node->tree->pages_per_bnode; i++)
+		if (node->page[i])
+			page_cache_release(node->page[i]);
 	kfree(node);
 }
 
--- a/fs/hfsplus/bnode.c
+++ b/fs/hfsplus/bnode.c
@@ -454,7 +454,6 @@ static struct hfs_bnode *__hfs_bnode_cre
 			page_cache_release(page);
 			goto fail;
 		}
-		page_cache_release(page);
 		node->page[i] = page;
 	}
 
@@ -566,13 +565,11 @@ node_error:
 
 void hfs_bnode_free(struct hfs_bnode *node)
 {
-#if 0
 	int i;
 
 	for (i = 0; i < node->tree->pages_per_bnode; i++)
 		if (node->page[i])
 			page_cache_release(node->page[i]);
-#endif
 	kfree(node);
 }
 

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242882 — [PATCH 3.2 015/107] ocfs2: fix BUG in ocfs2_downconvert_thread_do_work()

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:30 +0200
Subject[PATCH 3.2 015/107] ocfs2: fix BUG in ocfs2_downconvert_thread_do_work()
Message-ID<qhtJq-2EJ-63@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Joseph Qi <joseph.qi@huawei.com>

commit 209f7512d007980fd111a74a064d70a3656079cf upstream.

The "BUG_ON(list_empty(&osb->blocked_lock_list))" in
ocfs2_downconvert_thread_do_work can be triggered in the following case:

ocfs2dc has firstly saved osb->blocked_lock_count to local varibale
processed, and then processes the dentry lockres.  During the dentry
put, it calls iput and then deletes rw, inode and open lockres from
blocked list in ocfs2_mark_lockres_freeing.  And this causes the
variable `processed' to not reflect the number of blocked lockres to be
processed, which triggers the BUG.

Signed-off-by: Joseph Qi <joseph.qi@huawei.com>
Cc: Mark Fasheh <mfasheh@suse.com>
Cc: Joel Becker <jlbec@evilplan.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 fs/ocfs2/dlmglue.c | 10 +++++++---
 1 file changed, 7 insertions(+), 3 deletions(-)

--- a/fs/ocfs2/dlmglue.c
+++ b/fs/ocfs2/dlmglue.c
@@ -3968,9 +3968,13 @@ static void ocfs2_downconvert_thread_do_
 	osb->dc_work_sequence = osb->dc_wake_sequence;
 
 	processed = osb->blocked_lock_count;
-	while (processed) {
-		BUG_ON(list_empty(&osb->blocked_lock_list));
-
+	/*
+	 * blocked lock processing in this loop might call iput which can
+	 * remove items off osb->blocked_lock_list. Downconvert up to
+	 * 'processed' number of locks, but stop short if we had some
+	 * removed in ocfs2_mark_lockres_freeing when downconverting.
+	 */
+	while (processed && !list_empty(&osb->blocked_lock_list)) {
 		lockres = list_entry(osb->blocked_lock_list.next,
 				     struct ocfs2_lock_res, l_blocked_list);
 		list_del_init(&lockres->l_blocked_list);

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242883 — [PATCH 3.2 049/107] DRM - radeon: Don't link train DisplayPort on HPD until we get the dpcd

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:30 +0200
Subject[PATCH 3.2 049/107] DRM - radeon: Don't link train DisplayPort on HPD until we get the dpcd
Message-ID<qhtJq-2EJ-65@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Stephen Chandler Paul <cpaul@redhat.com>

commit 924f92bf12bfbef3662619e3ed24a1cea7c1cbcd upstream.

Most of the time this isn't an issue since hotplugging an adaptor will
trigger a crtc mode change which in turn, causes the driver to probe
every DisplayPort for a dpcd. However, in cases where hotplugging
doesn't cause a mode change (specifically when one unplugs a monitor
from a DisplayPort connector, then plugs that same monitor back in
seconds later on the same port without any other monitors connected), we
never probe for the dpcd before starting the initial link training. What
happens from there looks like this:

	- GPU has only one monitor connected. It's connected via
	  DisplayPort, and does not go through an adaptor of any sort.

	- User unplugs DisplayPort connector from GPU.

	- Change in HPD is detected by the driver, we probe every
	  DisplayPort for a possible connection.

	- Probe the port the user originally had the monitor connected
	  on for it's dpcd. This fails, and we clear the first (and only
	  the first) byte of the dpcd to indicate we no longer have a
	  dpcd for this port.

	- User plugs the previously disconnected monitor back into the
	  same DisplayPort.

	- radeon_connector_hotplug() is called before everyone else,
	  and tries to handle the link training. Since only the first
	  byte of the dpcd is zeroed, the driver is able to complete
	  link training but does so against the wrong dpcd, causing it
	  to initialize the link with the wrong settings.

	- Display stays blank (usually), dpcd is probed after the
	  initial link training, and the driver prints no obvious
	  messages to the log.

In theory, since only one byte of the dpcd is chopped off (specifically,
the byte that contains the revision information for DisplayPort), it's
not entirely impossible that this bug may not show on certain monitors.
For instance, the only reason this bug was visible on my ASUS PB238
monitor was due to the fact that this monitor using the enhanced framing
symbol sequence, the flag for which is ignored if the radeon driver
thinks that the DisplayPort version is below 1.1.

Signed-off-by: Stephen Chandler Paul <cpaul@redhat.com>
Reviewed-by: Jerome Glisse <jglisse@redhat.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/gpu/drm/radeon/radeon_connectors.c | 5 +++++
 1 file changed, 5 insertions(+)

--- a/drivers/gpu/drm/radeon/radeon_connectors.c
+++ b/drivers/gpu/drm/radeon/radeon_connectors.c
@@ -82,6 +82,11 @@ void radeon_connector_hotplug(struct drm
 			if (!radeon_hpd_sense(rdev, radeon_connector->hpd.hpd)) {
 				drm_helper_connector_dpms(connector, DRM_MODE_DPMS_OFF);
 			} else if (radeon_dp_needs_link_train(radeon_connector)) {
+				/* Don't try to start link training before we
+				 * have the dpcd */
+				if (!radeon_dp_getdpcd(radeon_connector))
+					return;
+
 				/* set it to OFF so that drm_helper_connector_dpms()
 				 * won't return immediately since the current state
 				 * is ON at this point.

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242884 — [PATCH 3.2 098/107] ipv6: lock socket in ip6_datagram_connect()

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:30 +0200
Subject[PATCH 3.2 098/107] ipv6: lock socket in ip6_datagram_connect()
Message-ID<qhtJq-2EJ-67@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 03645a11a570d52e70631838cb786eb4253eb463 ]

ip6_datagram_connect() is doing a lot of socket changes without
socket being locked.

This looks wrong, at least for udp_lib_rehash() which could corrupt
lists because of concurrent udp_sk(sk)->udp_portaddr_hash accesses.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: David S. Miller <davem@davemloft.net>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 include/net/ip.h    |  1 +
 net/ipv4/datagram.c | 16 ++++++++++++----
 net/ipv6/datagram.c | 20 +++++++++++++++-----
 3 files changed, 28 insertions(+), 9 deletions(-)

--- a/include/net/ip.h
+++ b/include/net/ip.h
@@ -138,6 +138,7 @@ static inline struct sk_buff *ip_finish_
 }
 
 /* datagram.c */
+int __ip4_datagram_connect(struct sock *sk, struct sockaddr *uaddr, int addr_len);
 extern int		ip4_datagram_connect(struct sock *sk, 
 					     struct sockaddr *uaddr, int addr_len);
 
--- a/net/ipv4/datagram.c
+++ b/net/ipv4/datagram.c
@@ -20,7 +20,7 @@
 #include <net/route.h>
 #include <net/tcp_states.h>
 
-int ip4_datagram_connect(struct sock *sk, struct sockaddr *uaddr, int addr_len)
+int __ip4_datagram_connect(struct sock *sk, struct sockaddr *uaddr, int addr_len)
 {
 	struct inet_sock *inet = inet_sk(sk);
 	struct sockaddr_in *usin = (struct sockaddr_in *) uaddr;
@@ -39,8 +39,6 @@ int ip4_datagram_connect(struct sock *sk
 
 	sk_dst_reset(sk);
 
-	lock_sock(sk);
-
 	oif = sk->sk_bound_dev_if;
 	saddr = inet->inet_saddr;
 	if (ipv4_is_multicast(usin->sin_addr.s_addr)) {
@@ -81,7 +79,17 @@ int ip4_datagram_connect(struct sock *sk
 	sk_dst_set(sk, &rt->dst);
 	err = 0;
 out:
-	release_sock(sk);
 	return err;
 }
+EXPORT_SYMBOL(__ip4_datagram_connect);
+
+int ip4_datagram_connect(struct sock *sk, struct sockaddr *uaddr, int addr_len)
+{
+	int res;
+
+	lock_sock(sk);
+	res = __ip4_datagram_connect(sk, uaddr, addr_len);
+	release_sock(sk);
+	return res;
+}
 EXPORT_SYMBOL(ip4_datagram_connect);
--- a/net/ipv6/datagram.c
+++ b/net/ipv6/datagram.c
@@ -38,7 +38,7 @@ static inline int ipv6_mapped_addr_any(c
 	return (ipv6_addr_v4mapped(a) && (a->s6_addr32[3] == 0));
 }
 
-int ip6_datagram_connect(struct sock *sk, struct sockaddr *uaddr, int addr_len)
+static int __ip6_datagram_connect(struct sock *sk, struct sockaddr *uaddr, int addr_len)
 {
 	struct sockaddr_in6	*usin = (struct sockaddr_in6 *) uaddr;
 	struct inet_sock      	*inet = inet_sk(sk);
@@ -54,7 +54,7 @@ int ip6_datagram_connect(struct sock *sk
 	if (usin->sin6_family == AF_INET) {
 		if (__ipv6_only_sock(sk))
 			return -EAFNOSUPPORT;
-		err = ip4_datagram_connect(sk, uaddr, addr_len);
+		err = __ip4_datagram_connect(sk, uaddr, addr_len);
 		goto ipv4_connected;
 	}
 
@@ -97,9 +97,9 @@ int ip6_datagram_connect(struct sock *sk
 		sin.sin_addr.s_addr = daddr->s6_addr32[3];
 		sin.sin_port = usin->sin6_port;
 
-		err = ip4_datagram_connect(sk,
-					   (struct sockaddr*) &sin,
-					   sizeof(sin));
+		err = __ip4_datagram_connect(sk,
+					     (struct sockaddr *) &sin,
+					     sizeof(sin));
 
 ipv4_connected:
 		if (err)
@@ -203,6 +203,16 @@ out:
 	return err;
 }
 
+int ip6_datagram_connect(struct sock *sk, struct sockaddr *uaddr, int addr_len)
+{
+	int res;
+
+	lock_sock(sk);
+	res = __ip6_datagram_connect(sk, uaddr, addr_len);
+	release_sock(sk);
+	return res;
+}
+
 void ipv6_icmp_error(struct sock *sk, struct sk_buff *skb, int err,
 		     __be16 port, u32 info, u8 *payload)
 {

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242885 — [PATCH 3.2 024/107] libfc: Fix fc_fcp_cleanup_each_cmd()

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:30 +0200
Subject[PATCH 3.2 024/107] libfc: Fix fc_fcp_cleanup_each_cmd()
Message-ID<qhtJq-2EJ-69@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Bart Van Assche <bart.vanassche@sandisk.com>

commit 8f2777f53e3d5ad8ef2a176a4463a5c8e1a16431 upstream.

Since fc_fcp_cleanup_cmd() can sleep this function must not
be called while holding a spinlock. This patch avoids that
fc_fcp_cleanup_each_cmd() triggers the following bug:

BUG: scheduling while atomic: sg_reset/1512/0x00000202
1 lock held by sg_reset/1512:
 #0:  (&(&fsp->scsi_pkt_lock)->rlock){+.-...}, at: [<ffffffffc0225cd5>] fc_fcp_cleanup_each_cmd.isra.21+0xa5/0x150 [libfc]
Preemption disabled at:[<ffffffffc0225cd5>] fc_fcp_cleanup_each_cmd.isra.21+0xa5/0x150 [libfc]
Call Trace:
 [<ffffffff816c612c>] dump_stack+0x4f/0x7b
 [<ffffffff810828bc>] __schedule_bug+0x6c/0xd0
 [<ffffffff816c87aa>] __schedule+0x71a/0xa10
 [<ffffffff816c8ad2>] schedule+0x32/0x80
 [<ffffffffc0217eac>] fc_seq_set_resp+0xac/0x100 [libfc]
 [<ffffffffc0218b11>] fc_exch_done+0x41/0x60 [libfc]
 [<ffffffffc0225cff>] fc_fcp_cleanup_each_cmd.isra.21+0xcf/0x150 [libfc]
 [<ffffffffc0225f43>] fc_eh_device_reset+0x1c3/0x270 [libfc]
 [<ffffffff814a2cc9>] scsi_try_bus_device_reset+0x29/0x60
 [<ffffffff814a3908>] scsi_ioctl_reset+0x258/0x2d0
 [<ffffffff814a2650>] scsi_ioctl+0x150/0x440
 [<ffffffff814b3a9d>] sd_ioctl+0xad/0x120
 [<ffffffff8132f266>] blkdev_ioctl+0x1b6/0x810
 [<ffffffff811da608>] block_ioctl+0x38/0x40
 [<ffffffff811b4e08>] do_vfs_ioctl+0x2f8/0x530
 [<ffffffff811b50c1>] SyS_ioctl+0x81/0xa0
 [<ffffffff816cf8b2>] system_call_fastpath+0x16/0x7a

Signed-off-by: Bart Van Assche <bart.vanassche@sandisk.com>
Signed-off-by: Vasu Dev <vasu.dev@intel.com>
Signed-off-by: James Bottomley <JBottomley@Odin.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/scsi/libfc/fc_fcp.c | 19 +++++++++++++++++--
 1 file changed, 17 insertions(+), 2 deletions(-)

--- a/drivers/scsi/libfc/fc_fcp.c
+++ b/drivers/scsi/libfc/fc_fcp.c
@@ -1029,11 +1029,26 @@ restart:
 		fc_fcp_pkt_hold(fsp);
 		spin_unlock_irqrestore(&si->scsi_queue_lock, flags);
 
-		if (!fc_fcp_lock_pkt(fsp)) {
+		spin_lock_bh(&fsp->scsi_pkt_lock);
+		if (!(fsp->state & FC_SRB_COMPL)) {
+			fsp->state |= FC_SRB_COMPL;
+			/*
+			 * TODO: dropping scsi_pkt_lock and then reacquiring
+			 * again around fc_fcp_cleanup_cmd() is required,
+			 * since fc_fcp_cleanup_cmd() calls into
+			 * fc_seq_set_resp() and that func preempts cpu using
+			 * schedule. May be schedule and related code should be
+			 * removed instead of unlocking here to avoid scheduling
+			 * while atomic bug.
+			 */
+			spin_unlock_bh(&fsp->scsi_pkt_lock);
+
 			fc_fcp_cleanup_cmd(fsp, error);
+
+			spin_lock_bh(&fsp->scsi_pkt_lock);
 			fc_io_compl(fsp);
-			fc_fcp_unlock_pkt(fsp);
 		}
+		spin_unlock_bh(&fsp->scsi_pkt_lock);
 
 		fc_fcp_pkt_release(fsp);
 		spin_lock_irqsave(&si->scsi_queue_lock, flags);

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242887 — [PATCH 3.2 094/107] Initialize msg/shm IPC objects before doing ipc_addid()

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:40 +0200
Subject[PATCH 3.2 094/107] Initialize msg/shm IPC objects before doing ipc_addid()
Message-ID<qhtT3-2Qh-1@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Linus Torvalds <torvalds@linux-foundation.org>

commit b9a532277938798b53178d5a66af6e2915cb27cf upstream.

As reported by Dmitry Vyukov, we really shouldn't do ipc_addid() before
having initialized the IPC object state.  Yes, we initialize the IPC
object in a locked state, but with all the lockless RCU lookup work,
that IPC object lock no longer means that the state cannot be seen.

We already did this for the IPC semaphore code (see commit e8577d1f0329:
"ipc/sem.c: fully initialize sem_array before making it visible") but we
clearly forgot about msg and shm.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Cc: Manfred Spraul <manfred@colorfullife.com>
Cc: Davidlohr Bueso <dbueso@suse.de>
Cc: stable@vger.kernel.org
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[bwh: Backported to 3.2:
 - Adjust context
 - The error path being moved looks a little different]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/ipc/msg.c
+++ b/ipc/msg.c
@@ -198,6 +198,15 @@ static int newque(struct ipc_namespace *
 		return retval;
 	}
 
+	msq->q_stime = msq->q_rtime = 0;
+	msq->q_ctime = get_seconds();
+	msq->q_cbytes = msq->q_qnum = 0;
+	msq->q_qbytes = ns->msg_ctlmnb;
+	msq->q_lspid = msq->q_lrpid = 0;
+	INIT_LIST_HEAD(&msq->q_messages);
+	INIT_LIST_HEAD(&msq->q_receivers);
+	INIT_LIST_HEAD(&msq->q_senders);
+
 	/*
 	 * ipc_addid() locks msq
 	 */
@@ -208,15 +217,6 @@ static int newque(struct ipc_namespace *
 		return id;
 	}
 
-	msq->q_stime = msq->q_rtime = 0;
-	msq->q_ctime = get_seconds();
-	msq->q_cbytes = msq->q_qnum = 0;
-	msq->q_qbytes = ns->msg_ctlmnb;
-	msq->q_lspid = msq->q_lrpid = 0;
-	INIT_LIST_HEAD(&msq->q_messages);
-	INIT_LIST_HEAD(&msq->q_receivers);
-	INIT_LIST_HEAD(&msq->q_senders);
-
 	msg_unlock(msq);
 
 	return msq->q_perm.id;
--- a/ipc/shm.c
+++ b/ipc/shm.c
@@ -498,12 +498,6 @@ static int newseg(struct ipc_namespace *
 	if (IS_ERR(file))
 		goto no_file;
 
-	id = ipc_addid(&shm_ids(ns), &shp->shm_perm, ns->shm_ctlmni);
-	if (id < 0) {
-		error = id;
-		goto no_id;
-	}
-
 	shp->shm_cprid = task_tgid_vnr(current);
 	shp->shm_lprid = 0;
 	shp->shm_atim = shp->shm_dtim = 0;
@@ -512,6 +506,13 @@ static int newseg(struct ipc_namespace *
 	shp->shm_nattch = 0;
 	shp->shm_file = file;
 	shp->shm_creator = current;
+
+	id = ipc_addid(&shm_ids(ns), &shp->shm_perm, ns->shm_ctlmni);
+	if (id < 0) {
+		error = id;
+		goto no_id;
+	}
+
 	/*
 	 * shmid gets reported as "inode#" in /proc/pid/maps.
 	 * proc-ps tools use this. Changing this will break them.
--- a/ipc/util.c
+++ b/ipc/util.c
@@ -264,6 +264,10 @@ int ipc_addid(struct ipc_ids* ids, struc
 	rcu_read_lock();
 	spin_lock(&new->lock);
 
+	current_euid_egid(&euid, &egid);
+	new->cuid = new->uid = euid;
+	new->gid = new->cgid = egid;
+
 	err = idr_get_new(&ids->ipcs_idr, new, &id);
 	if (err) {
 		spin_unlock(&new->lock);
@@ -273,10 +277,6 @@ int ipc_addid(struct ipc_ids* ids, struc
 
 	ids->in_use++;
 
-	current_euid_egid(&euid, &egid);
-	new->cuid = new->uid = euid;
-	new->gid = new->cgid = egid;
-
 	new->seq = ids->seq++;
 	if(ids->seq > ids->seq_max)
 		ids->seq = 0;

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242888 — [PATCH 3.2 060/107] drm/i915: Always mark the object as dirty when used by the GPU

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:40 +0200
Subject[PATCH 3.2 060/107] drm/i915: Always mark the object as dirty when used by the GPU
Message-ID<qhtT3-2Qh-3@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Chris Wilson <chris@chris-wilson.co.uk>

commit 51bc140431e233284660b1d22c47dec9ecdb521e upstream.

There have been many hard to track down bugs whereby userspace forgot to
flag a write buffer and then cause graphics corruption or a hung GPU
when that buffer was later purged under memory pressure (as the buffer
appeared clean, its pages would have been evicted rather than preserved
and any changes more recent than in the backing storage would be lost).
In retrospect this is a rare optimisation against memory pressure,
already the slow path. If we always mark the buffer as dirty when
accessed by the GPU, anything not used can still be evicted cheaply
(ideal behaviour for mark-and-sweep eviction) but we do not run the risk
of corruption. For correct read serialisation, userspace still has to
notify when the GPU writes to an object. However, there are certain
situations under which userspace may wish to tell white lies to the
kernel...

Signed-off-by: Chris Wilson <chris@chris-wilson.co.uk>
Cc: Daniel Vetter <daniel.vetter@ffwll.ch>
Cc: Kristian Høgsberg <krh@bitplanet.net>
Cc: Jesse Barnes <jbarnes@virtuousgeek.org>
Cc: "Goel, Akash" <akash.goel@intel.co>
Cc: Michał Winiarski <michal.winiarski@intel.com>
Reviewed-by: Daniel Vetter <daniel.vetter@ffwll.ch>
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/gpu/drm/i915/i915_gem_execbuffer.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/gpu/drm/i915/i915_gem_execbuffer.c
+++ b/drivers/gpu/drm/i915/i915_gem_execbuffer.c
@@ -950,13 +950,13 @@ i915_gem_execbuffer_move_to_active(struc
 		  u32 old_write = obj->base.write_domain;
 
 
+		obj->dirty = 1; /* be paranoid  */
 		obj->base.read_domains = obj->base.pending_read_domains;
 		obj->base.write_domain = obj->base.pending_write_domain;
 		obj->fenced_gpu_access = obj->pending_fenced_gpu_access;
 
 		i915_gem_object_move_to_active(obj, ring, seqno);
 		if (obj->base.write_domain) {
-			obj->dirty = 1;
 			obj->pending_gpu_write = true;
 			list_move_tail(&obj->gpu_write_list,
 				       &ring->gpu_write_list);

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242889 — [PATCH 3.2 047/107] eCryptfs: Invalidate dcache entries when lower i_nlink is zero

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:40 +0200
Subject[PATCH 3.2 047/107] eCryptfs: Invalidate dcache entries when lower i_nlink is zero
Message-ID<qhtT3-2Qh-5@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Tyler Hicks <tyhicks@canonical.com>

commit 5556e7e6d30e8e9b5ee51b0e5edd526ee80e5e36 upstream.

Consider eCryptfs dcache entries to be stale when the corresponding
lower inode's i_nlink count is zero. This solves a problem caused by the
lower inode being directly modified, without going through the eCryptfs
mount, leaving stale eCryptfs dentries cached and the eCryptfs inode's
i_nlink count not being cleared.

Signed-off-by: Tyler Hicks <tyhicks@canonical.com>
Reported-by: Richard Weinberger <richard@nod.at>
[bwh: Backported to 3.2:
 - Test d_revalidate pointer directly rather than a DCACHE_OP flag
 - Open-code d_inode()
 - Adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 fs/ecryptfs/dentry.c | 16 ++++++++--------
 1 file changed, 8 insertions(+), 8 deletions(-)

--- a/fs/ecryptfs/dentry.c
+++ b/fs/ecryptfs/dentry.c
@@ -55,26 +55,26 @@ static int ecryptfs_d_revalidate(struct
 
 	lower_dentry = ecryptfs_dentry_to_lower(dentry);
 	lower_mnt = ecryptfs_dentry_to_lower_mnt(dentry);
-	if (!lower_dentry->d_op || !lower_dentry->d_op->d_revalidate)
-		goto out;
-	if (nd) {
-		dentry_save = nd->path.dentry;
-		vfsmount_save = nd->path.mnt;
-		nd->path.dentry = lower_dentry;
-		nd->path.mnt = lower_mnt;
-	}
-	rc = lower_dentry->d_op->d_revalidate(lower_dentry, nd);
-	if (nd) {
-		nd->path.dentry = dentry_save;
-		nd->path.mnt = vfsmount_save;
+	if (lower_dentry->d_op && lower_dentry->d_op->d_revalidate) {
+		if (nd) {
+			dentry_save = nd->path.dentry;
+			vfsmount_save = nd->path.mnt;
+			nd->path.dentry = lower_dentry;
+			nd->path.mnt = lower_mnt;
+		}
+		rc = lower_dentry->d_op->d_revalidate(lower_dentry, nd);
+		if (nd) {
+			nd->path.dentry = dentry_save;
+			nd->path.mnt = vfsmount_save;
+		}
 	}
 	if (dentry->d_inode) {
-		struct inode *lower_inode =
-			ecryptfs_inode_to_lower(dentry->d_inode);
+		struct inode *inode = dentry->d_inode;
 
-		fsstack_copy_attr_all(dentry->d_inode, lower_inode);
+		fsstack_copy_attr_all(inode, ecryptfs_inode_to_lower(inode));
+		if (!inode->i_nlink)
+			return 0;
 	}
-out:
 	return rc;
 }
 

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242890 — [PATCH 3.2 009/107] target: REPORT LUNS should return LUN 0 even for dynamic ACLs

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:40 +0200
Subject[PATCH 3.2 009/107] target: REPORT LUNS should return LUN 0 even for dynamic ACLs
Message-ID<qhtT4-2Qh-7@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Roland Dreier <roland@purestorage.com>

commit 9c395170a559d3b23dad100b01fc4a89d661c698 upstream.

If an initiator doesn't have any real LUNs assigned, we should report
LUN 0 and a LUN list length of 1.  Some versions of Solaris at least
go beserk if we report a LUN list length of 0.

Signed-off-by: Roland Dreier <roland@purestorage.com>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
[bwh: Backported to 3.2: adjust filename, context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/target/target_core_device.c | 14 ++++++++++----
 1 file changed, 10 insertions(+), 4 deletions(-)

--- a/drivers/target/target_core_device.c
+++ b/drivers/target/target_core_device.c
@@ -668,11 +668,8 @@ int target_report_luns(struct se_task *s
 	 * coming via a target_core_mod PASSTHROUGH op, and not through
 	 * a $FABRIC_MOD.  In that case, report LUN=0 only.
 	 */
-	if (!se_sess) {
-		int_to_scsilun(0, (struct scsi_lun *)&buf[offset]);
-		lun_count = 1;
+	if (!se_sess)
 		goto done;
-	}
 
 	spin_lock_irq(&se_sess->se_node_acl->device_list_lock);
 	for (i = 0; i < TRANSPORT_MAX_LUNS_PER_TPG; i++) {
@@ -699,6 +696,14 @@ int target_report_luns(struct se_task *s
 	 * See SPC3 r07, page 159.
 	 */
 done:
+	/*
+	 * If no LUNs are accessible, report virtual LUN 0.
+	 */
+	if (lun_count == 0) {
+		int_to_scsilun(0, (struct scsi_lun *)&buf[offset]);
+		lun_count = 1;
+	}
+
 	lun_count *= 8;
 	buf[0] = ((lun_count >> 24) & 0xff);
 	buf[1] = ((lun_count >> 16) & 0xff);

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242891 — [PATCH 3.2 095/107] net/tipc: initialize security state for new connection socket

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:40 +0200
Subject[PATCH 3.2 095/107] net/tipc: initialize security state for new connection socket
Message-ID<qhtT4-2Qh-9@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Stephen Smalley <sds@tycho.nsa.gov>

[ Upstream commit fdd75ea8df370f206a8163786e7470c1277a5064 ]

Calling connect() with an AF_TIPC socket would trigger a series
of error messages from SELinux along the lines of:
SELinux: Invalid class 0
type=AVC msg=audit(1434126658.487:34500): avc:  denied  { <unprintable> }
  for pid=292 comm="kworker/u16:5" scontext=system_u:system_r:kernel_t:s0
  tcontext=system_u:object_r:unlabeled_t:s0 tclass=<unprintable>
  permissive=0

This was due to a failure to initialize the security state of the new
connection sock by the tipc code, leaving it with junk in the security
class field and an unlabeled secid.  Add a call to security_sk_clone()
to inherit the security state from the parent socket.

Reported-by: Tim Shearer <tim.shearer@overturenetworks.com>
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Acked-by: Paul Moore <paul@paul-moore.com>
Acked-by: Ying Xue <ying.xue@windriver.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[bwh: Backported to 3.2: adjust context, indentation]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/net/tipc/socket.c
+++ b/net/tipc/socket.c
@@ -1541,6 +1541,8 @@ static int accept(struct socket *sock, s
 		u32 new_ref = new_tport->ref;
 		struct tipc_msg *msg = buf_msg(buf);
 
+		security_sk_clone(sock->sk, new_sock->sk);
+
 		lock_sock(new_sk);
 
 		/*

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242892 — [PATCH 3.2 018/107] x86/ldt: Make modify_ldt synchronous

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:40 +0200
Subject[PATCH 3.2 018/107] x86/ldt: Make modify_ldt synchronous
Message-ID<qhtT4-2Qh-11@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Andy Lutomirski <luto@kernel.org>

commit 37868fe113ff2ba814b3b4eb12df214df555f8dc upstream.

modify_ldt() has questionable locking and does not synchronize
threads.  Improve it: redesign the locking and synchronize all
threads' LDTs using an IPI on all modifications.

This will dramatically slow down modify_ldt in multithreaded
programs, but there shouldn't be any multithreaded programs that
care about modify_ldt's performance in the first place.

This fixes some fallout from the CVE-2015-5157 fixes.

Signed-off-by: Andy Lutomirski <luto@kernel.org>
Reviewed-by: Borislav Petkov <bp@suse.de>
Cc: Andrew Cooper <andrew.cooper3@citrix.com>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Brian Gerst <brgerst@gmail.com>
Cc: Denys Vlasenko <dvlasenk@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Jan Beulich <jbeulich@suse.com>
Cc: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Sasha Levin <sasha.levin@oracle.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: security@kernel.org <security@kernel.org>
Cc: xen-devel <xen-devel@lists.xen.org>
Link: http://lkml.kernel.org/r/4c6978476782160600471bd865b318db34c7b628.1438291540.git.luto@kernel.org
Signed-off-by: Ingo Molnar <mingo@kernel.org>
[bwh: Backported to 3.2:
 - Adjust context
 - Drop comment changes in switch_mm()
 - Drop changes to get_segment_base() in arch/x86/kernel/cpu/perf_event.c
 - Open-code lockless_dereference(), smp_store_release(), on_each_cpu_mask()]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/arch/x86/include/asm/desc.h
+++ b/arch/x86/include/asm/desc.h
@@ -277,21 +277,6 @@ static inline void clear_LDT(void)
 	set_ldt(NULL, 0);
 }
 
-/*
- * load one particular LDT into the current CPU
- */
-static inline void load_LDT_nolock(mm_context_t *pc)
-{
-	set_ldt(pc->ldt, pc->size);
-}
-
-static inline void load_LDT(mm_context_t *pc)
-{
-	preempt_disable();
-	load_LDT_nolock(pc);
-	preempt_enable();
-}
-
 static inline unsigned long get_desc_base(const struct desc_struct *desc)
 {
 	return (unsigned)(desc->base0 | ((desc->base1) << 16) | ((desc->base2) << 24));
--- a/arch/x86/include/asm/mmu.h
+++ b/arch/x86/include/asm/mmu.h
@@ -9,8 +9,7 @@
  * we put the segment information here.
  */
 typedef struct {
-	void *ldt;
-	int size;
+	struct ldt_struct *ldt;
 
 #ifdef CONFIG_X86_64
 	/* True if mm supports a task running in 32 bit compatibility mode. */
--- a/arch/x86/include/asm/mmu_context.h
+++ b/arch/x86/include/asm/mmu_context.h
@@ -16,6 +16,51 @@ static inline void paravirt_activate_mm(
 #endif	/* !CONFIG_PARAVIRT */
 
 /*
+ * ldt_structs can be allocated, used, and freed, but they are never
+ * modified while live.
+ */
+struct ldt_struct {
+	/*
+	 * Xen requires page-aligned LDTs with special permissions.  This is
+	 * needed to prevent us from installing evil descriptors such as
+	 * call gates.  On native, we could merge the ldt_struct and LDT
+	 * allocations, but it's not worth trying to optimize.
+	 */
+	struct desc_struct *entries;
+	int size;
+};
+
+static inline void load_mm_ldt(struct mm_struct *mm)
+{
+	struct ldt_struct *ldt;
+
+	/* smp_read_barrier_depends synchronizes with barrier in install_ldt */
+	ldt = ACCESS_ONCE(mm->context.ldt);
+	smp_read_barrier_depends();
+
+	/*
+	 * Any change to mm->context.ldt is followed by an IPI to all
+	 * CPUs with the mm active.  The LDT will not be freed until
+	 * after the IPI is handled by all such CPUs.  This means that,
+	 * if the ldt_struct changes before we return, the values we see
+	 * will be safe, and the new values will be loaded before we run
+	 * any user code.
+	 *
+	 * NB: don't try to convert this to use RCU without extreme care.
+	 * We would still need IRQs off, because we don't want to change
+	 * the local LDT after an IPI loaded a newer value than the one
+	 * that we can see.
+	 */
+
+	if (unlikely(ldt))
+		set_ldt(ldt->entries, ldt->size);
+	else
+		clear_LDT();
+
+	DEBUG_LOCKS_WARN_ON(preemptible());
+}
+
+/*
  * Used for LDT copy/destruction.
  */
 int init_new_context(struct task_struct *tsk, struct mm_struct *mm);
@@ -52,7 +97,7 @@ static inline void switch_mm(struct mm_s
 		 * load the LDT, if the LDT is different:
 		 */
 		if (unlikely(prev->context.ldt != next->context.ldt))
-			load_LDT_nolock(&next->context);
+			load_mm_ldt(next);
 	}
 #ifdef CONFIG_SMP
 	else {
@@ -65,7 +110,7 @@ static inline void switch_mm(struct mm_s
 			 * to make sure to use no freed page tables.
 			 */
 			load_cr3(next->pgd);
-			load_LDT_nolock(&next->context);
+			load_mm_ldt(next);
 		}
 	}
 #endif
--- a/arch/x86/kernel/cpu/common.c
+++ b/arch/x86/kernel/cpu/common.c
@@ -1225,7 +1225,7 @@ void __cpuinit cpu_init(void)
 	load_sp0(t, &current->thread);
 	set_tss_desc(cpu, t);
 	load_TR_desc();
-	load_LDT(&init_mm.context);
+	load_mm_ldt(&init_mm);
 
 	clear_all_debug_regs();
 	dbg_restore_debug_regs();
@@ -1273,7 +1273,7 @@ void __cpuinit cpu_init(void)
 	load_sp0(t, thread);
 	set_tss_desc(cpu, t);
 	load_TR_desc();
-	load_LDT(&init_mm.context);
+	load_mm_ldt(&init_mm);
 
 	t->x86_tss.io_bitmap_base = offsetof(struct tss_struct, io_bitmap);
 
--- a/arch/x86/kernel/ldt.c
+++ b/arch/x86/kernel/ldt.c
@@ -12,6 +12,7 @@
 #include <linux/string.h>
 #include <linux/mm.h>
 #include <linux/smp.h>
+#include <linux/slab.h>
 #include <linux/vmalloc.h>
 #include <linux/uaccess.h>
 
@@ -21,82 +22,87 @@
 #include <asm/mmu_context.h>
 #include <asm/syscalls.h>
 
-#ifdef CONFIG_SMP
+/* context.lock is held for us, so we don't need any locking. */
 static void flush_ldt(void *current_mm)
 {
-	if (current->active_mm == current_mm)
-		load_LDT(&current->active_mm->context);
+	mm_context_t *pc;
+
+	if (current->active_mm != current_mm)
+		return;
+
+	pc = &current->active_mm->context;
+	set_ldt(pc->ldt->entries, pc->ldt->size);
 }
-#endif
 
-static int alloc_ldt(mm_context_t *pc, int mincount, int reload)
+/* The caller must call finalize_ldt_struct on the result. LDT starts zeroed. */
+static struct ldt_struct *alloc_ldt_struct(int size)
 {
-	void *oldldt, *newldt;
-	int oldsize;
+	struct ldt_struct *new_ldt;
+	int alloc_size;
 
-	if (mincount <= pc->size)
-		return 0;
-	oldsize = pc->size;
-	mincount = (mincount + (PAGE_SIZE / LDT_ENTRY_SIZE - 1)) &
-			(~(PAGE_SIZE / LDT_ENTRY_SIZE - 1));
-	if (mincount * LDT_ENTRY_SIZE > PAGE_SIZE)
-		newldt = vmalloc(mincount * LDT_ENTRY_SIZE);
-	else
-		newldt = (void *)__get_free_page(GFP_KERNEL);
+	if (size > LDT_ENTRIES)
+		return NULL;
 
-	if (!newldt)
-		return -ENOMEM;
+	new_ldt = kmalloc(sizeof(struct ldt_struct), GFP_KERNEL);
+	if (!new_ldt)
+		return NULL;
+
+	BUILD_BUG_ON(LDT_ENTRY_SIZE != sizeof(struct desc_struct));
+	alloc_size = size * LDT_ENTRY_SIZE;
+
+	/*
+	 * Xen is very picky: it requires a page-aligned LDT that has no
+	 * trailing nonzero bytes in any page that contains LDT descriptors.
+	 * Keep it simple: zero the whole allocation and never allocate less
+	 * than PAGE_SIZE.
+	 */
+	if (alloc_size > PAGE_SIZE)
+		new_ldt->entries = vzalloc(alloc_size);
+	else
+		new_ldt->entries = kzalloc(PAGE_SIZE, GFP_KERNEL);
 
-	if (oldsize)
-		memcpy(newldt, pc->ldt, oldsize * LDT_ENTRY_SIZE);
-	oldldt = pc->ldt;
-	memset(newldt + oldsize * LDT_ENTRY_SIZE, 0,
-	       (mincount - oldsize) * LDT_ENTRY_SIZE);
-
-	paravirt_alloc_ldt(newldt, mincount);
-
-#ifdef CONFIG_X86_64
-	/* CHECKME: Do we really need this ? */
-	wmb();
-#endif
-	pc->ldt = newldt;
-	wmb();
-	pc->size = mincount;
-	wmb();
-
-	if (reload) {
-#ifdef CONFIG_SMP
-		preempt_disable();
-		load_LDT(pc);
-		if (!cpumask_equal(mm_cpumask(current->mm),
-				   cpumask_of(smp_processor_id())))
-			smp_call_function(flush_ldt, current->mm, 1);
-		preempt_enable();
-#else
-		load_LDT(pc);
-#endif
-	}
-	if (oldsize) {
-		paravirt_free_ldt(oldldt, oldsize);
-		if (oldsize * LDT_ENTRY_SIZE > PAGE_SIZE)
-			vfree(oldldt);
-		else
-			put_page(virt_to_page(oldldt));
+	if (!new_ldt->entries) {
+		kfree(new_ldt);
+		return NULL;
 	}
-	return 0;
+
+	new_ldt->size = size;
+	return new_ldt;
 }
 
-static inline int copy_ldt(mm_context_t *new, mm_context_t *old)
+/* After calling this, the LDT is immutable. */
+static void finalize_ldt_struct(struct ldt_struct *ldt)
 {
-	int err = alloc_ldt(new, old->size, 0);
-	int i;
+	paravirt_alloc_ldt(ldt->entries, ldt->size);
+}
+
+/* context.lock is held */
+static void install_ldt(struct mm_struct *current_mm,
+			struct ldt_struct *ldt)
+{
+	/* Synchronizes with smp_read_barrier_depends in load_mm_ldt. */
+        barrier();
+        ACCESS_ONCE(current_mm->context.ldt) = ldt;
+
+	/* Activate the LDT for all CPUs using current_mm. */
+	smp_call_function_many(mm_cpumask(current_mm), flush_ldt, current_mm,
+			       true);
+	local_irq_disable();
+	flush_ldt(current_mm);
+	local_irq_enable();
+}
 
-	if (err < 0)
-		return err;
+static void free_ldt_struct(struct ldt_struct *ldt)
+{
+	if (likely(!ldt))
+		return;
 
-	for (i = 0; i < old->size; i++)
-		write_ldt_entry(new->ldt, i, old->ldt + i * LDT_ENTRY_SIZE);
-	return 0;
+	paravirt_free_ldt(ldt->entries, ldt->size);
+	if (ldt->size * LDT_ENTRY_SIZE > PAGE_SIZE)
+		vfree(ldt->entries);
+	else
+		kfree(ldt->entries);
+	kfree(ldt);
 }
 
 /*
@@ -105,17 +111,37 @@ static inline int copy_ldt(mm_context_t
  */
 int init_new_context(struct task_struct *tsk, struct mm_struct *mm)
 {
+	struct ldt_struct *new_ldt;
 	struct mm_struct *old_mm;
 	int retval = 0;
 
 	mutex_init(&mm->context.lock);
-	mm->context.size = 0;
 	old_mm = current->mm;
-	if (old_mm && old_mm->context.size > 0) {
-		mutex_lock(&old_mm->context.lock);
-		retval = copy_ldt(&mm->context, &old_mm->context);
-		mutex_unlock(&old_mm->context.lock);
+	if (!old_mm) {
+		mm->context.ldt = NULL;
+		return 0;
+	}
+
+	mutex_lock(&old_mm->context.lock);
+	if (!old_mm->context.ldt) {
+		mm->context.ldt = NULL;
+		goto out_unlock;
 	}
+
+	new_ldt = alloc_ldt_struct(old_mm->context.ldt->size);
+	if (!new_ldt) {
+		retval = -ENOMEM;
+		goto out_unlock;
+	}
+
+	memcpy(new_ldt->entries, old_mm->context.ldt->entries,
+	       new_ldt->size * LDT_ENTRY_SIZE);
+	finalize_ldt_struct(new_ldt);
+
+	mm->context.ldt = new_ldt;
+
+out_unlock:
+	mutex_unlock(&old_mm->context.lock);
 	return retval;
 }
 
@@ -126,53 +152,47 @@ int init_new_context(struct task_struct
  */
 void destroy_context(struct mm_struct *mm)
 {
-	if (mm->context.size) {
-#ifdef CONFIG_X86_32
-		/* CHECKME: Can this ever happen ? */
-		if (mm == current->active_mm)
-			clear_LDT();
-#endif
-		paravirt_free_ldt(mm->context.ldt, mm->context.size);
-		if (mm->context.size * LDT_ENTRY_SIZE > PAGE_SIZE)
-			vfree(mm->context.ldt);
-		else
-			put_page(virt_to_page(mm->context.ldt));
-		mm->context.size = 0;
-	}
+	free_ldt_struct(mm->context.ldt);
+	mm->context.ldt = NULL;
 }
 
 static int read_ldt(void __user *ptr, unsigned long bytecount)
 {
-	int err;
+	int retval;
 	unsigned long size;
 	struct mm_struct *mm = current->mm;
 
-	if (!mm->context.size)
-		return 0;
+	mutex_lock(&mm->context.lock);
+
+	if (!mm->context.ldt) {
+		retval = 0;
+		goto out_unlock;
+	}
+
 	if (bytecount > LDT_ENTRY_SIZE * LDT_ENTRIES)
 		bytecount = LDT_ENTRY_SIZE * LDT_ENTRIES;
 
-	mutex_lock(&mm->context.lock);
-	size = mm->context.size * LDT_ENTRY_SIZE;
+	size = mm->context.ldt->size * LDT_ENTRY_SIZE;
 	if (size > bytecount)
 		size = bytecount;
 
-	err = 0;
-	if (copy_to_user(ptr, mm->context.ldt, size))
-		err = -EFAULT;
-	mutex_unlock(&mm->context.lock);
-	if (err < 0)
-		goto error_return;
+	if (copy_to_user(ptr, mm->context.ldt->entries, size)) {
+		retval = -EFAULT;
+		goto out_unlock;
+	}
+
 	if (size != bytecount) {
-		/* zero-fill the rest */
-		if (clear_user(ptr + size, bytecount - size) != 0) {
-			err = -EFAULT;
-			goto error_return;
+		/* Zero-fill the rest and pretend we read bytecount bytes. */
+		if (clear_user(ptr + size, bytecount - size)) {
+			retval = -EFAULT;
+			goto out_unlock;
 		}
 	}
-	return bytecount;
-error_return:
-	return err;
+	retval = bytecount;
+
+out_unlock:
+	mutex_unlock(&mm->context.lock);
+	return retval;
 }
 
 static int read_default_ldt(void __user *ptr, unsigned long bytecount)
@@ -196,6 +216,8 @@ static int write_ldt(void __user *ptr, u
 	struct desc_struct ldt;
 	int error;
 	struct user_desc ldt_info;
+	int oldsize, newsize;
+	struct ldt_struct *new_ldt, *old_ldt;
 
 	error = -EINVAL;
 	if (bytecount != sizeof(ldt_info))
@@ -214,34 +236,39 @@ static int write_ldt(void __user *ptr, u
 			goto out;
 	}
 
-	mutex_lock(&mm->context.lock);
-	if (ldt_info.entry_number >= mm->context.size) {
-		error = alloc_ldt(&current->mm->context,
-				  ldt_info.entry_number + 1, 1);
-		if (error < 0)
-			goto out_unlock;
-	}
-
-	/* Allow LDTs to be cleared by the user. */
-	if (ldt_info.base_addr == 0 && ldt_info.limit == 0) {
-		if (oldmode || LDT_empty(&ldt_info)) {
-			memset(&ldt, 0, sizeof(ldt));
-			goto install;
+	if ((oldmode && !ldt_info.base_addr && !ldt_info.limit) ||
+	    LDT_empty(&ldt_info)) {
+		/* The user wants to clear the entry. */
+		memset(&ldt, 0, sizeof(ldt));
+	} else {
+		if (!IS_ENABLED(CONFIG_X86_16BIT) && !ldt_info.seg_32bit) {
+			error = -EINVAL;
+			goto out;
 		}
+
+		fill_ldt(&ldt, &ldt_info);
+		if (oldmode)
+			ldt.avl = 0;
 	}
 
-	if (!IS_ENABLED(CONFIG_X86_16BIT) && !ldt_info.seg_32bit) {
-		error = -EINVAL;
+	mutex_lock(&mm->context.lock);
+
+	old_ldt = mm->context.ldt;
+	oldsize = old_ldt ? old_ldt->size : 0;
+	newsize = max((int)(ldt_info.entry_number + 1), oldsize);
+
+	error = -ENOMEM;
+	new_ldt = alloc_ldt_struct(newsize);
+	if (!new_ldt)
 		goto out_unlock;
-	}
 
-	fill_ldt(&ldt, &ldt_info);
-	if (oldmode)
-		ldt.avl = 0;
-
-	/* Install the new entry ...  */
-install:
-	write_ldt_entry(mm->context.ldt, ldt_info.entry_number, &ldt);
+	if (old_ldt)
+		memcpy(new_ldt->entries, old_ldt->entries, oldsize * LDT_ENTRY_SIZE);
+	new_ldt->entries[ldt_info.entry_number] = ldt;
+	finalize_ldt_struct(new_ldt);
+
+	install_ldt(mm, new_ldt);
+	free_ldt_struct(old_ldt);
 	error = 0;
 
 out_unlock:
--- a/arch/x86/kernel/process_64.c
+++ b/arch/x86/kernel/process_64.c
@@ -218,11 +218,11 @@ void __show_regs(struct pt_regs *regs, i
 void release_thread(struct task_struct *dead_task)
 {
 	if (dead_task->mm) {
-		if (dead_task->mm->context.size) {
+		if (dead_task->mm->context.ldt) {
 			printk("WARNING: dead process %8s still has LDT? <%p/%d>\n",
 					dead_task->comm,
 					dead_task->mm->context.ldt,
-					dead_task->mm->context.size);
+					dead_task->mm->context.ldt->size);
 			BUG();
 		}
 	}
--- a/arch/x86/kernel/step.c
+++ b/arch/x86/kernel/step.c
@@ -5,6 +5,7 @@
 #include <linux/mm.h>
 #include <linux/ptrace.h>
 #include <asm/desc.h>
+#include <asm/mmu_context.h>
 
 unsigned long convert_ip_to_linear(struct task_struct *child, struct pt_regs *regs)
 {
@@ -30,10 +31,11 @@ unsigned long convert_ip_to_linear(struc
 		seg &= ~7UL;
 
 		mutex_lock(&child->mm->context.lock);
-		if (unlikely((seg >> 3) >= child->mm->context.size))
+		if (unlikely(!child->mm->context.ldt ||
+			     (seg >> 3) >= child->mm->context.ldt->size))
 			addr = -1L; /* bogus selector, access would fault */
 		else {
-			desc = child->mm->context.ldt + seg;
+			desc = &child->mm->context.ldt->entries[seg];
 			base = get_desc_base(desc);
 
 			/* 16-bit code segment? */
--- a/arch/x86/power/cpu.c
+++ b/arch/x86/power/cpu.c
@@ -21,6 +21,7 @@
 #include <asm/xcr.h>
 #include <asm/suspend.h>
 #include <asm/debugreg.h>
+#include <asm/mmu_context.h>
 
 #ifdef CONFIG_X86_32
 static struct saved_context saved_context;
@@ -147,7 +148,7 @@ static void fix_processor_context(void)
 	syscall_init();				/* This sets MSR_*STAR and related */
 #endif
 	load_TR_desc();				/* This does ltr */
-	load_LDT(&current->active_mm->context);	/* This does lldt */
+	load_mm_ldt(current->active_mm);	/* This does lldt */
 }
 
 /**

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242893 — [PATCH 3.2 036/107] PCI: Add VPD function 0 quirk for Intel Ethernet devices

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:40 +0200
Subject[PATCH 3.2 036/107] PCI: Add VPD function 0 quirk for Intel Ethernet devices
Message-ID<qhtT4-2Qh-15@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Mark Rustad <mark.d.rustad@intel.com>

commit 7aa6ca4d39edf01f997b9e02cf6d2fdeb224f351 upstream.

Set the PCI_DEV_FLAGS_VPD_REF_F0 flag on all Intel Ethernet device
functions other than function 0, so that on multi-function devices, we will
always read VPD from function 0 instead of from the other functions.

[bhelgaas: changelog]
Signed-off-by: Mark Rustad <mark.d.rustad@intel.com>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Acked-by: Alexander Duyck <alexander.h.duyck@redhat.com>
[bwh: Backported to 3.2:
 - Put the class check in the new function as there is no
   DECLARE_PCI_FIXUP_CLASS_EARLY(
 - Adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/pci/quirks.c | 9 +++++++++
 1 file changed, 9 insertions(+)

--- a/drivers/pci/quirks.c
+++ b/drivers/pci/quirks.c
@@ -1941,6 +1941,15 @@ static void __devinit quirk_netmos(struc
 }
 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_NETMOS, PCI_ANY_ID, quirk_netmos);
 
+static void quirk_f0_vpd_link(struct pci_dev *dev)
+{
+	if ((dev->class >> 8) != PCI_CLASS_NETWORK_ETHERNET ||
+	    !dev->multifunction || !PCI_FUNC(dev->devfn))
+		return;
+	dev->dev_flags |= PCI_DEV_FLAGS_VPD_REF_F0;
+}
+DECLARE_PCI_FIXUP_EARLY(PCI_VENDOR_ID_INTEL, PCI_ANY_ID, quirk_f0_vpd_link);
+
 static void __devinit quirk_e100_interrupt(struct pci_dev *dev)
 {
 	u16 command, pmcsr;

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242895 — [PATCH 3.2 016/107] net: Clone skb before setting peeked flag

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:40 +0200
Subject[PATCH 3.2 016/107] net: Clone skb before setting peeked flag
Message-ID<qhtT4-2Qh-19@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit 738ac1ebb96d02e0d23bc320302a6ea94c612dec upstream.

Shared skbs must not be modified and this is crucial for broadcast
and/or multicast paths where we use it as an optimisation to avoid
unnecessary cloning.

The function skb_recv_datagram breaks this rule by setting peeked
without cloning the skb first.  This causes funky races which leads
to double-free.

This patch fixes this by cloning the skb and replacing the skb
in the list when setting skb->peeked.

Fixes: a59322be07c9 ("[UDP]: Only increment counter on first peek/recv")
Reported-by: Konstantin Khlebnikov <khlebnikov@yandex-team.ru>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: David S. Miller <davem@davemloft.net>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 net/core/datagram.c | 41 ++++++++++++++++++++++++++++++++++++++---
 1 file changed, 38 insertions(+), 3 deletions(-)

--- a/net/core/datagram.c
+++ b/net/core/datagram.c
@@ -128,6 +128,35 @@ out_noerr:
 	goto out;
 }
 
+static int skb_set_peeked(struct sk_buff *skb)
+{
+	struct sk_buff *nskb;
+
+	if (skb->peeked)
+		return 0;
+
+	/* We have to unshare an skb before modifying it. */
+	if (!skb_shared(skb))
+		goto done;
+
+	nskb = skb_clone(skb, GFP_ATOMIC);
+	if (!nskb)
+		return -ENOMEM;
+
+	skb->prev->next = nskb;
+	skb->next->prev = nskb;
+	nskb->prev = skb->prev;
+	nskb->next = skb->next;
+
+	consume_skb(skb);
+	skb = nskb;
+
+done:
+	skb->peeked = 1;
+
+	return 0;
+}
+
 /**
  *	__skb_recv_datagram - Receive a datagram skbuff
  *	@sk: socket
@@ -160,7 +189,9 @@ out_noerr:
 struct sk_buff *__skb_recv_datagram(struct sock *sk, unsigned flags,
 				    int *peeked, int *err)
 {
+	struct sk_buff_head *queue = &sk->sk_receive_queue;
 	struct sk_buff *skb;
+	unsigned long cpu_flags;
 	long timeo;
 	/*
 	 * Caller is allowed not to check sk->sk_err before skb_recv_datagram()
@@ -179,15 +210,16 @@ struct sk_buff *__skb_recv_datagram(stru
 		 * Look at current nfs client by the way...
 		 * However, this function was correct in any case. 8)
 		 */
-		unsigned long cpu_flags;
-		struct sk_buff_head *queue = &sk->sk_receive_queue;
-
 		spin_lock_irqsave(&queue->lock, cpu_flags);
 		skb = skb_peek(queue);
 		if (skb) {
 			*peeked = skb->peeked;
 			if (flags & MSG_PEEK) {
-				skb->peeked = 1;
+
+				error = skb_set_peeked(skb);
+				if (error)
+					goto unlock_err;
+
 				atomic_inc(&skb->users);
 			} else
 				__skb_unlink(skb, queue);
@@ -206,6 +238,8 @@ struct sk_buff *__skb_recv_datagram(stru
 
 	return NULL;
 
+unlock_err:
+	spin_unlock_irqrestore(&queue->lock, cpu_flags);
 no_packet:
 	*err = error;
 	return NULL;

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242897 — [PATCH 3.2 026/107] x86/ldt: Further fix FPU emulation

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:40 +0200
Subject[PATCH 3.2 026/107] x86/ldt: Further fix FPU emulation
Message-ID<qhtT4-2Qh-21@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Andy Lutomirski <luto@kernel.org>

commit 12e244f4b550498bbaf654a52f93633f7dde2dc7 upstream.

The previous fix confused a selector with a segment prefix.  Fix it.

Compile-tested only.

Cc: Juergen Gross <jgross@suse.com>
Reported-by: Linus Torvalds <torvalds@linux-foundation.org>
Fixes: 4809146b86c3 ("x86/ldt: Correct FPU emulation access to LDT")
Signed-off-by: Andy Lutomirski <luto@kernel.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 arch/x86/math-emu/get_address.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/x86/math-emu/get_address.c
+++ b/arch/x86/math-emu/get_address.c
@@ -157,7 +157,7 @@ static long pm_address(u_char FPU_modrm,
 		addr->selector = PM_REG_(segment);
 	}
 
-	descriptor = FPU_get_ldt_descriptor(segment);
+	descriptor = FPU_get_ldt_descriptor(addr->selector);
 	base_address = SEG_BASE_ADDR(descriptor);
 	address = base_address + offset;
 	limit = base_address

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242898 — [PATCH 3.2 029/107] sparc64: Fix userspace FPU register corruptions.

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:40 +0200
Subject[PATCH 3.2 029/107] sparc64: Fix userspace FPU register corruptions.
Message-ID<qhtT4-2Qh-25@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: "David S. Miller" <davem@davemloft.net>

commit 44922150d87cef616fd183220d43d8fde4d41390 upstream.

If we have a series of events from userpsace, with %fprs=FPRS_FEF,
like follows:

ETRAP
	ETRAP
		VIS_ENTRY(fprs=0x4)
		VIS_EXIT
		RTRAP (kernel FPU restore with fpu_saved=0x4)
	RTRAP

We will not restore the user registers that were clobbered by the FPU
using kernel code in the inner-most trap.

Traps allocate FPU save slots in the thread struct, and FPU using
sequences save the "dirty" FPU registers only.

This works at the initial trap level because all of the registers
get recorded into the top-level FPU save area, and we'll return
to userspace with the FPU disabled so that any FPU use by the user
will take an FPU disabled trap wherein we'll load the registers
back up properly.

But this is not how trap returns from kernel to kernel operate.

The simplest fix for this bug is to always save all FPU register state
for anything other than the top-most FPU save area.

Getting rid of the optimized inner-slot FPU saving code ends up
making VISEntryHalf degenerate into plain VISEntry.

Longer term we need to do something smarter to reinstate the partial
save optimizations.  Perhaps the fundament error is having trap entry
and exit allocate FPU save slots and restore register state.  Instead,
the VISEntry et al. calls should be doing that work.

This bug is about two decades old.

Reported-by: James Y Knight <jyknight@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[bwh: Backported to 3.2:
 - Adjust context
 - Drop changes to NG4memcpy.S and ksyms.c]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/arch/sparc/include/asm/visasm.h
+++ b/arch/sparc/include/asm/visasm.h
@@ -28,18 +28,12 @@
  * Must preserve %o5 between VISEntryHalf and VISExitHalf */
 
 #define VISEntryHalf					\
-	rd		%fprs, %o5;			\
-	andcc		%o5, FPRS_FEF, %g0;		\
-	be,pt		%icc, 297f;			\
-	 sethi		%hi(298f), %g7;			\
-	sethi		%hi(VISenterhalf), %g1;		\
-	jmpl		%g1 + %lo(VISenterhalf), %g0;	\
-	 or		%g7, %lo(298f), %g7;		\
-	clr		%o5;				\
-297:	wr		%o5, FPRS_FEF, %fprs;		\
-298:
+	VISEntry
 
 #define VISExitHalf					\
+	VISExit
+
+#define VISExitHalfFast					\
 	wr		%o5, 0, %fprs;
 
 #ifndef __ASSEMBLY__
--- a/arch/sparc/lib/VISsave.S
+++ b/arch/sparc/lib/VISsave.S
@@ -44,9 +44,8 @@ vis1:	ldub		[%g6 + TI_FPSAVED], %g3
 
 	 stx		%g3, [%g6 + TI_GSR]
 2:	add		%g6, %g1, %g3
-	cmp		%o5, FPRS_DU
-	be,pn		%icc, 6f
-	 sll		%g1, 3, %g1
+	mov		FPRS_DU | FPRS_DL | FPRS_FEF, %o5
+	sll		%g1, 3, %g1
 	stb		%o5, [%g3 + TI_FPSAVED]
 	rd		%gsr, %g2
 	add		%g6, %g1, %g3
@@ -80,65 +79,3 @@ vis1:	ldub		[%g6 + TI_FPSAVED], %g3
 	.align		32
 80:	jmpl		%g7 + %g0, %g0
 	 nop
-
-6:	ldub		[%g3 + TI_FPSAVED], %o5
-	or		%o5, FPRS_DU, %o5
-	add		%g6, TI_FPREGS+0x80, %g2
-	stb		%o5, [%g3 + TI_FPSAVED]
-
-	sll		%g1, 5, %g1
-	add		%g6, TI_FPREGS+0xc0, %g3
-	wr		%g0, FPRS_FEF, %fprs
-	membar		#Sync
-	stda		%f32, [%g2 + %g1] ASI_BLK_P
-	stda		%f48, [%g3 + %g1] ASI_BLK_P
-	membar		#Sync
-	ba,pt		%xcc, 80f
-	 nop
-
-	.align		32
-80:	jmpl		%g7 + %g0, %g0
-	 nop
-
-	.align		32
-VISenterhalf:
-	ldub		[%g6 + TI_FPDEPTH], %g1
-	brnz,a,pn	%g1, 1f
-	 cmp		%g1, 1
-	stb		%g0, [%g6 + TI_FPSAVED]
-	stx		%fsr, [%g6 + TI_XFSR]
-	clr		%o5
-	jmpl		%g7 + %g0, %g0
-	 wr		%g0, FPRS_FEF, %fprs
-
-1:	bne,pn		%icc, 2f
-	 srl		%g1, 1, %g1
-	ba,pt		%xcc, vis1
-	 sub		%g7, 8, %g7
-2:	addcc		%g6, %g1, %g3
-	sll		%g1, 3, %g1
-	andn		%o5, FPRS_DU, %g2
-	stb		%g2, [%g3 + TI_FPSAVED]
-
-	rd		%gsr, %g2
-	add		%g6, %g1, %g3
-	stx		%g2, [%g3 + TI_GSR]
-	add		%g6, %g1, %g2
-	stx		%fsr, [%g2 + TI_XFSR]
-	sll		%g1, 5, %g1
-3:	andcc		%o5, FPRS_DL, %g0
-	be,pn		%icc, 4f
-	 add		%g6, TI_FPREGS, %g2
-
-	add		%g6, TI_FPREGS+0x40, %g3
-	membar		#Sync
-	stda		%f0, [%g2 + %g1] ASI_BLK_P
-	stda		%f16, [%g3 + %g1] ASI_BLK_P
-	membar		#Sync
-	ba,pt		%xcc, 4f
-	 nop
-
-	.align		32
-4:	and		%o5, FPRS_DU, %o5
-	jmpl		%g7 + %g0, %g0
-	 wr		%o5, FPRS_FEF, %fprs

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242899 — [PATCH 3.2 023/107] libiscsi: Fix host busy blocking during connection teardown

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:40 +0200
Subject[PATCH 3.2 023/107] libiscsi: Fix host busy blocking during connection teardown
Message-ID<qhtT4-2Qh-23@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: John Soni Jose <sony.john@avagotech.com>

commit 660d0831d1494a6837b2f810d08b5be092c1f31d upstream.

In case of hw iscsi offload, an host can have N-number of active
connections. There can be IO's running on some connections which
make host->host_busy always TRUE. Now if logout from a connection
is tried then the code gets into an infinite loop as host->host_busy
is always TRUE.

 iscsi_conn_teardown(....)
 {
   .........
    /*
     * Block until all in-progress commands for this connection
     * time out or fail.
     */
     for (;;) {
      spin_lock_irqsave(session->host->host_lock, flags);
      if (!atomic_read(&session->host->host_busy)) { /* OK for ERL == 0 */
	      spin_unlock_irqrestore(session->host->host_lock, flags);
              break;
      }
     spin_unlock_irqrestore(session->host->host_lock, flags);
     msleep_interruptible(500);
     iscsi_conn_printk(KERN_INFO, conn, "iscsi conn_destroy(): "
                 "host_busy %d host_failed %d\n",
	          atomic_read(&session->host->host_busy),
	          session->host->host_failed);

	................
	...............
     }
  }

This is not an issue with software-iscsi/iser as each cxn is a separate
host.

Fix:
Acquiring eh_mutex in iscsi_conn_teardown() before setting
session->state = ISCSI_STATE_TERMINATE.

Signed-off-by: John Soni Jose <sony.john@avagotech.com>
Reviewed-by: Mike Christie <michaelc@cs.wisc.edu>
Reviewed-by: Chris Leech <cleech@redhat.com>
Signed-off-by: James Bottomley <JBottomley@Odin.com>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/scsi/libiscsi.c | 25 ++-----------------------
 1 file changed, 2 insertions(+), 23 deletions(-)

--- a/drivers/scsi/libiscsi.c
+++ b/drivers/scsi/libiscsi.c
@@ -2906,10 +2906,10 @@ void iscsi_conn_teardown(struct iscsi_cl
 {
 	struct iscsi_conn *conn = cls_conn->dd_data;
 	struct iscsi_session *session = conn->session;
-	unsigned long flags;
 
 	del_timer_sync(&conn->transport_timer);
 
+	mutex_lock(&session->eh_mutex);
 	spin_lock_bh(&session->lock);
 	conn->c_stage = ISCSI_CONN_CLEANUP_WAIT;
 	if (session->leadconn == conn) {
@@ -2921,28 +2921,6 @@ void iscsi_conn_teardown(struct iscsi_cl
 	}
 	spin_unlock_bh(&session->lock);
 
-	/*
-	 * Block until all in-progress commands for this connection
-	 * time out or fail.
-	 */
-	for (;;) {
-		spin_lock_irqsave(session->host->host_lock, flags);
-		if (!session->host->host_busy) { /* OK for ERL == 0 */
-			spin_unlock_irqrestore(session->host->host_lock, flags);
-			break;
-		}
-		spin_unlock_irqrestore(session->host->host_lock, flags);
-		msleep_interruptible(500);
-		iscsi_conn_printk(KERN_INFO, conn, "iscsi conn_destroy(): "
-				  "host_busy %d host_failed %d\n",
-				  session->host->host_busy,
-				  session->host->host_failed);
-		/*
-		 * force eh_abort() to unblock
-		 */
-		wake_up(&conn->ehwait);
-	}
-
 	/* flush queued up work because we free the connection below */
 	iscsi_suspend_tx(conn);
 
@@ -2955,6 +2933,7 @@ void iscsi_conn_teardown(struct iscsi_cl
 	if (session->leadconn == conn)
 		session->leadconn = NULL;
 	spin_unlock_bh(&session->lock);
+	mutex_unlock(&session->eh_mutex);
 
 	iscsi_destroy_conn(cls_conn);
 }

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242900 — [PATCH 3.2 019/107] x86/ldt: Correct LDT access in single stepping logic

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:40 +0200
Subject[PATCH 3.2 019/107] x86/ldt: Correct LDT access in single stepping logic
Message-ID<qhtT5-2Qh-29@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Juergen Gross <jgross@suse.com>

commit 136d9d83c07c5e30ac49fc83b27e8c4842f108fc upstream.

Commit 37868fe113ff ("x86/ldt: Make modify_ldt synchronous")
introduced a new struct ldt_struct anchored at mm->context.ldt.

convert_ip_to_linear() was changed to reflect this, but indexing
into the ldt has to be changed as the pointer is no longer void *.

Signed-off-by: Juergen Gross <jgross@suse.com>
Reviewed-by: Andy Lutomirski <luto@kernel.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: bp@suse.de
Link: http://lkml.kernel.org/r/1438848278-12906-1-git-send-email-jgross@suse.com
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 arch/x86/kernel/step.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/arch/x86/kernel/step.c
+++ b/arch/x86/kernel/step.c
@@ -28,11 +28,11 @@ unsigned long convert_ip_to_linear(struc
 		struct desc_struct *desc;
 		unsigned long base;
 
-		seg &= ~7UL;
+		seg >>= 3;
 
 		mutex_lock(&child->mm->context.lock);
 		if (unlikely(!child->mm->context.ldt ||
-			     (seg >> 3) >= child->mm->context.ldt->size))
+			     seg >= child->mm->context.ldt->size))
 			addr = -1L; /* bogus selector, access would fault */
 		else {
 			desc = &child->mm->context.ldt->entries[seg];

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1242902 — [PATCH 3.2 017/107] net: Fix skb_set_peeked use-after-free bug

FromBen Hutchings <ben@decadent.org.uk>
Date2015-10-09 02:40 +0200
Subject[PATCH 3.2 017/107] net: Fix skb_set_peeked use-after-free bug
Message-ID<qhtT5-2Qh-31@gated-at.bofh.it>
In reply to#1242879
3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit a0a2a6602496a45ae838a96db8b8173794b5d398 upstream.

The commit 738ac1ebb96d02e0d23bc320302a6ea94c612dec ("net: Clone
skb before setting peeked flag") introduced a use-after-free bug
in skb_recv_datagram.  This is because skb_set_peeked may create
a new skb and free the existing one.  As it stands the caller will
continue to use the old freed skb.

This patch fixes it by making skb_set_peeked return the new skb
(or the old one if unchanged).

Fixes: 738ac1ebb96d ("net: Clone skb before setting peeked flag")
Reported-by: Brenden Blanco <bblanco@plumgrid.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Tested-by: Brenden Blanco <bblanco@plumgrid.com>
Reviewed-by: Konstantin Khlebnikov <khlebnikov@yandex-team.ru>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 net/core/datagram.c | 13 +++++++------
 1 file changed, 7 insertions(+), 6 deletions(-)

--- a/net/core/datagram.c
+++ b/net/core/datagram.c
@@ -128,12 +128,12 @@ out_noerr:
 	goto out;
 }
 
-static int skb_set_peeked(struct sk_buff *skb)
+static struct sk_buff *skb_set_peeked(struct sk_buff *skb)
 {
 	struct sk_buff *nskb;
 
 	if (skb->peeked)
-		return 0;
+		return skb;
 
 	/* We have to unshare an skb before modifying it. */
 	if (!skb_shared(skb))
@@ -141,7 +141,7 @@ static int skb_set_peeked(struct sk_buff
 
 	nskb = skb_clone(skb, GFP_ATOMIC);
 	if (!nskb)
-		return -ENOMEM;
+		return ERR_PTR(-ENOMEM);
 
 	skb->prev->next = nskb;
 	skb->next->prev = nskb;
@@ -154,7 +154,7 @@ static int skb_set_peeked(struct sk_buff
 done:
 	skb->peeked = 1;
 
-	return 0;
+	return skb;
 }
 
 /**
@@ -216,8 +216,9 @@ struct sk_buff *__skb_recv_datagram(stru
 			*peeked = skb->peeked;
 			if (flags & MSG_PEEK) {
 
-				error = skb_set_peeked(skb);
-				if (error)
+				skb = skb_set_peeked(skb);
+				error = PTR_ERR(skb);
+				if (IS_ERR(skb))
 					goto unlock_err;
 
 				atomic_inc(&skb->users);

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


Page 1 of 4  [1] 2 3 4  Next page →

Back to top | Article view | linux.kernel


csiph-web