Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1258058 > unrolled thread

[PATCH 3.12 038/123] spi: spi-pxa2xx: Check status register to determine if SSSR_TINT is disabled

Started byJiri Slaby <jslaby@suse.cz>
First post2015-10-28 15:00 +0100
Last post2015-10-28 15:30 +0100
Articles 20 on this page of 80 — 2 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  [PATCH 3.12 038/123] spi: spi-pxa2xx: Check status register to determine if SSSR_TINT is disabled Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:00 +0100
    [PATCH 3.12 118/123] usb: core: implement AMD remote wakeup quirk Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:00 +0100
    [PATCH 3.12 120/123] USB: Add OTG PET device to TPL Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:00 +0100
    [PATCH 3.12 092/123] crypto: sparc - initialize blkcipher.ivsize Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:00 +0100
    [PATCH 3.12 116/123] [media] v4l: vsp1: Fix VI6_WPF_SZCLIP_SIZE_MASK macro Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:00 +0100
    [PATCH 3.12 093/123] crypto: ahash - ensure statesize is non-zero Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:00 +0100
    [PATCH 3.12 115/123] [media] v4l: vsp1: Fix VI6_DPR_ROUTE_FP_MASK macro Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:00 +0100
    [PATCH 3.12 062/123] ipvs: do not use random local source address for tunnels Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:00 +0100
    [PATCH 3.12 122/123] ath9k: declare required extra tx headroom Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:00 +0100
    [PATCH 3.12 041/123] ALSA: hda - Apply SPDIF pin ctl to MacBookPro 12,1 Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:00 +0100
    [PATCH 3.12 121/123] Revert "USB: Add device quirk for ASUS T100 Base Station keyboard" Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:00 +0100
    [PATCH 3.12 117/123] [media] gscpa_m5602: use msecs_to_jiffies for conversions Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:00 +0100
      Re: [PATCH 3.12 117/123] [media] gscpa_m5602: use msecs_to_jiffies  for conversions Nicholas Mc Guire <der.herr@hofr.at> - 2015-10-28 15:50 +0100
    [PATCH 3.12 110/123] Input: serio - fix blocking of parport Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 094/123] btrfs: fix use after free iterating extrefs Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 100/123] drm/nouveau/fbcon: take runpm reference when userspace has an open fd Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 109/123] Input: psmouse - add small delay for IBM trackpoint pass-through mode Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 083/123] af_unix: return data from multiple SKBs on recv() with MSG_PEEK flag Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 103/123] usb: chipidea: debug: add runtime pm for register access Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 096/123] i2c: rcar: enable RuntimePM before registering to the core Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 095/123] arm64: errata: use KBUILD_CFLAGS_MODULE for erratum #843419 Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 079/123] mm/slab: fix unexpected index mapping result of kmalloc_size(INDEX_NODE+1) Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 090/123] asix: Don't reset PHY on if_up for ASIX 88772 Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 080/123] 3w-9xxx: don't unmap bounce buffered commands Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 108/123] HID: quirks: add QUIRK_NOGET for an other TPV touchscreen Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 099/123] workqueue: make sure delayed work run in local cpu Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 107/123] HID: apple: Add support for the 2015 Macbook Pro Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 097/123] i2c: s3c2410: enable RuntimePM before registering to the core Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 104/123] USB: symbolserial: Correct transferred data size Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 102/123] rbd: fix double free on rbd_dev->header_name Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 111/123] Input: omap4-keypad - fix memory leak Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 098/123] i2c: designware: Do not use parameters from ACPI on Dell Inspiron 7348 Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 105/123] usb: musb: cppi41: improve rx channel abort routine Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 089/123] ethtool: Use kcalloc instead of kmalloc for ethtool_get_strings Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 106/123] usb: musb: fix cppi channel teardown for isoch transfer Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 112/123] Input: zhenhua - ensure we have BITREVERSE Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 091/123] asix: Do full reset during ax88772_bind Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 101/123] dm thin: fix missing pool reference count decrement in pool_ctr error path Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:10 +0100
    [PATCH 3.12 070/123] USB: Add reset-resume quirk for two Plantronics usb headphones. Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 073/123] UBI: return ENOSPC if no enough space available Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 068/123] usb: Use the USB_SS_MULT() macro to get the burst multiplier. Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 088/123] ppp: don't override sk->sk_state in pppoe_flush_dev() Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 075/123] m68k: Define asmlinkage_protect Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 076/123] genirq: Fix race in register_irq_proc() Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 065/123] regmap: debugfs: Ensure we don't underflow when printing access masks Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 082/123] af_unix: Convert the unix_sk macro to an inline function for type safety Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 066/123] regmap: debugfs: Don't bother actually printing when calculating max length Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 058/123] usb: xhci: Clear XHCI_STATE_DYING on start Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 069/123] usb: Add device quirk for Logitech PTZ cameras Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 061/123] Initialize msg/shm IPC objects before doing ipc_addid() Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 085/123] skbuff: Fix skb checksum flag on skb pull Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 087/123] net: add pfmemalloc check in sk_add_backlog() Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 071/123] MIPS: dma-default: Fix 32-bit fall back to GFP_DMA Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 074/123] arm64: readahead: fault retry breaks mmap file read random detection Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 077/123] dm cache: fix NULL pointer when switching from cleaner policy Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 067/123] security: fix typo in security_task_prctl Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 072/123] UBI: Validate data_size Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 086/123] skbuff: Fix skb checksum partial check. Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 040/123] ALSA: synth: Fix conflicting OSS device registration on AWE32 Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 084/123] net/unix: fix logic about sk_peek_offset Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:20 +0100
    [PATCH 3.12 060/123] usb: xhci: Add support for URB_ZERO_PACKET to bulk/sg transfers Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 043/123] ASoC: fix broken pxa SoC support Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 039/123] mm: hugetlbfs: skip shared VMAs when unmapping private pages to satisfy a fault Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 047/123] Btrfs: update fix for read corruption of compressed and shared extents Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 048/123] dm btree: add ref counting ops for the leaves of top level btrees Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 045/123] btrfs: skip waiting on ordered range for special files Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 054/123] drm/qxl: only report first monitor as connected if we have no state Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 053/123] disabling oplocks/leases via module parm enable_oplocks broken for SMB3 Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 055/123] drm/qxl: recreate the primary surface when the bo is not primary Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 051/123] netfilter: nf_conntrack: Support expectations in different zones Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 049/123] USB: option: add ZTE PIDs Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 046/123] Btrfs: fix read corruption of compressed and shared extents Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 064/123] cifs: use server timestamp for ntlmv2 authentication Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 059/123] xhci: change xhci 1.0 only restrictions to support xhci 1.1 Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 056/123] drm: Reject DRI1 hw lock ioctl functions for kms drivers Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 042/123] ASoC: pxa: pxa2xx-ac97: fix dma requestor lines Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 057/123] USB: whiteheat: fix potential null-deref at probe Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 052/123] netfilter: ctnetlink: put back references to master ct and expect objects Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 044/123] ASoC: dwc: correct irq clear method Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100
    [PATCH 3.12 050/123] dm raid: fix round up of default region size Jiri Slaby <jslaby@suse.cz> - 2015-10-28 15:30 +0100

Page 3 of 4 — ← Prev page 1 2 [3] 4  Next page →


#1258115 — [PATCH 3.12 068/123] usb: Use the USB_SS_MULT() macro to get the burst multiplier.

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 068/123] usb: Use the USB_SS_MULT() macro to get the burst multiplier.
Message-ID<qozK1-3GM-15@gated-at.bofh.it>
In reply to#1258058
From: Mathias Nyman <mathias.nyman@linux.intel.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit ff30cbc8da425754e8ab96904db1d295bd034f27 upstream.

Bits 1:0 of the bmAttributes are used for the burst multiplier.
The rest of the bits used to be reserved (zero), but USB3.1 takes bit 7
into use.

Use the existing USB_SS_MULT() macro instead to make sure the mult value
and hence max packet calculations are correct for USB3.1 devices.

Note that burst multiplier in bmAttributes is zero based and that
the USB_SS_MULT() macro adds one.

Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/usb/core/config.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/usb/core/config.c b/drivers/usb/core/config.c
index 98cb09617b20..b9560f485d21 100644
--- a/drivers/usb/core/config.c
+++ b/drivers/usb/core/config.c
@@ -114,7 +114,7 @@ static void usb_parse_ss_endpoint_companion(struct device *ddev, int cfgno,
 				cfgno, inum, asnum, ep->desc.bEndpointAddress);
 		ep->ss_ep_comp.bmAttributes = 16;
 	} else if (usb_endpoint_xfer_isoc(&ep->desc) &&
-			desc->bmAttributes > 2) {
+		   USB_SS_MULT(desc->bmAttributes) > 3) {
 		dev_warn(ddev, "Isoc endpoint has Mult of %d in "
 				"config %d interface %d altsetting %d ep %d: "
 				"setting to 3\n", desc->bmAttributes + 1,
@@ -123,7 +123,8 @@ static void usb_parse_ss_endpoint_companion(struct device *ddev, int cfgno,
 	}
 
 	if (usb_endpoint_xfer_isoc(&ep->desc))
-		max_tx = (desc->bMaxBurst + 1) * (desc->bmAttributes + 1) *
+		max_tx = (desc->bMaxBurst + 1) *
+			(USB_SS_MULT(desc->bmAttributes)) *
 			usb_endpoint_maxp(&ep->desc);
 	else if (usb_endpoint_xfer_int(&ep->desc))
 		max_tx = usb_endpoint_maxp(&ep->desc) *
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258116 — [PATCH 3.12 088/123] ppp: don't override sk->sk_state in pppoe_flush_dev()

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 088/123] ppp: don't override sk->sk_state in pppoe_flush_dev()
Message-ID<qozK1-3GM-11@gated-at.bofh.it>
In reply to#1258058
From: Guillaume Nault <g.nault@alphalink.fr>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit e6740165b8f7f06d8caee0fceab3fb9d790a6fed ]

Since commit 2b018d57ff18 ("pppoe: drop PPPOX_ZOMBIEs in pppoe_release"),
pppoe_release() calls dev_put(po->pppoe_dev) if sk is in the
PPPOX_ZOMBIE state. But pppoe_flush_dev() can set sk->sk_state to
PPPOX_ZOMBIE _and_ reset po->pppoe_dev to NULL. This leads to the
following oops:

[  570.140800] BUG: unable to handle kernel NULL pointer dereference at 00000000000004e0
[  570.142931] IP: [<ffffffffa018c701>] pppoe_release+0x50/0x101 [pppoe]
[  570.144601] PGD 3d119067 PUD 3dbc1067 PMD 0
[  570.144601] Oops: 0000 [#1] SMP
[  570.144601] Modules linked in: l2tp_ppp l2tp_netlink l2tp_core ip6_udp_tunnel udp_tunnel pppoe pppox ppp_generic slhc loop crc32c_intel ghash_clmulni_intel jitterentropy_rng sha256_generic hmac drbg ansi_cprng aesni_intel aes_x86_64 ablk_helper cryptd lrw gf128mul glue_helper acpi_cpufreq evdev serio_raw processor button ext4 crc16 mbcache jbd2 virtio_net virtio_blk virtio_pci virtio_ring virtio
[  570.144601] CPU: 1 PID: 15738 Comm: ppp-apitest Not tainted 4.2.0 #1
[  570.144601] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Debian-1.8.2-1 04/01/2014
[  570.144601] task: ffff88003d30d600 ti: ffff880036b60000 task.ti: ffff880036b60000
[  570.144601] RIP: 0010:[<ffffffffa018c701>]  [<ffffffffa018c701>] pppoe_release+0x50/0x101 [pppoe]
[  570.144601] RSP: 0018:ffff880036b63e08  EFLAGS: 00010202
[  570.144601] RAX: 0000000000000000 RBX: ffff880034340000 RCX: 0000000000000206
[  570.144601] RDX: 0000000000000006 RSI: ffff88003d30dd20 RDI: ffff88003d30dd20
[  570.144601] RBP: ffff880036b63e28 R08: 0000000000000001 R09: 0000000000000000
[  570.144601] R10: 00007ffee9b50420 R11: ffff880034340078 R12: ffff8800387ec780
[  570.144601] R13: ffff8800387ec7b0 R14: ffff88003e222aa0 R15: ffff8800387ec7b0
[  570.144601] FS:  00007f5672f48700(0000) GS:ffff88003fc80000(0000) knlGS:0000000000000000
[  570.144601] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  570.144601] CR2: 00000000000004e0 CR3: 0000000037f7e000 CR4: 00000000000406a0
[  570.144601] Stack:
[  570.144601]  ffffffffa018f240 ffff8800387ec780 ffffffffa018f240 ffff8800387ec7b0
[  570.144601]  ffff880036b63e48 ffffffff812caabe ffff880039e4e000 0000000000000008
[  570.144601]  ffff880036b63e58 ffffffff812cabad ffff880036b63ea8 ffffffff811347f5
[  570.144601] Call Trace:
[  570.144601]  [<ffffffff812caabe>] sock_release+0x1a/0x75
[  570.144601]  [<ffffffff812cabad>] sock_close+0xd/0x11
[  570.144601]  [<ffffffff811347f5>] __fput+0xff/0x1a5
[  570.144601]  [<ffffffff811348cb>] ____fput+0x9/0xb
[  570.144601]  [<ffffffff81056682>] task_work_run+0x66/0x90
[  570.144601]  [<ffffffff8100189e>] prepare_exit_to_usermode+0x8c/0xa7
[  570.144601]  [<ffffffff81001a26>] syscall_return_slowpath+0x16d/0x19b
[  570.144601]  [<ffffffff813babb1>] int_ret_from_sys_call+0x25/0x9f
[  570.144601] Code: 48 8b 83 c8 01 00 00 a8 01 74 12 48 89 df e8 8b 27 14 e1 b8 f7 ff ff ff e9 b7 00 00 00 8a 43 12 a8 0b 74 1c 48 8b 83 a8 04 00 00 <48> 8b 80 e0 04 00 00 65 ff 08 48 c7 83 a8 04 00 00 00 00 00 00
[  570.144601] RIP  [<ffffffffa018c701>] pppoe_release+0x50/0x101 [pppoe]
[  570.144601]  RSP <ffff880036b63e08>
[  570.144601] CR2: 00000000000004e0
[  570.200518] ---[ end trace 46956baf17349563 ]---

pppoe_flush_dev() has no reason to override sk->sk_state with
PPPOX_ZOMBIE. pppox_unbind_sock() already sets sk->sk_state to
PPPOX_DEAD, which is the correct state given that sk is unbound and
po->pppoe_dev is NULL.

Fixes: 2b018d57ff18 ("pppoe: drop PPPOX_ZOMBIEs in pppoe_release")
Tested-by: Oleksii Berezhniak <core@irc.lg.ua>
Signed-off-by: Guillaume Nault <g.nault@alphalink.fr>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/net/ppp/pppoe.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/drivers/net/ppp/pppoe.c b/drivers/net/ppp/pppoe.c
index addd23246eb6..d66cf214e95e 100644
--- a/drivers/net/ppp/pppoe.c
+++ b/drivers/net/ppp/pppoe.c
@@ -313,7 +313,6 @@ static void pppoe_flush_dev(struct net_device *dev)
 			if (po->pppoe_dev == dev &&
 			    sk->sk_state & (PPPOX_CONNECTED | PPPOX_BOUND | PPPOX_ZOMBIE)) {
 				pppox_unbind_sock(sk);
-				sk->sk_state = PPPOX_ZOMBIE;
 				sk->sk_state_change(sk);
 				po->pppoe_dev = NULL;
 				dev_put(dev);
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258117 — [PATCH 3.12 075/123] m68k: Define asmlinkage_protect

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 075/123] m68k: Define asmlinkage_protect
Message-ID<qozK1-3GM-17@gated-at.bofh.it>
In reply to#1258058
From: Andreas Schwab <schwab@linux-m68k.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 8474ba74193d302e8340dddd1e16c85cc4b98caf upstream.

Make sure the compiler does not modify arguments of syscall functions.
This can happen if the compiler generates a tailcall to another
function.  For example, without asmlinkage_protect sys_openat is compiled
into this function:

sys_openat:
	clr.l %d0
	move.w 18(%sp),%d0
	move.l %d0,16(%sp)
	jbra do_sys_open

Note how the fourth argument is modified in place, modifying the register
%d4 that gets restored from this stack slot when the function returns to
user-space.  The caller may expect the register to be unmodified across
system calls.

Signed-off-by: Andreas Schwab <schwab@linux-m68k.org>
Signed-off-by: Geert Uytterhoeven <geert@linux-m68k.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 arch/m68k/include/asm/linkage.h | 30 ++++++++++++++++++++++++++++++
 1 file changed, 30 insertions(+)

diff --git a/arch/m68k/include/asm/linkage.h b/arch/m68k/include/asm/linkage.h
index 5a822bb790f7..066e74f666ae 100644
--- a/arch/m68k/include/asm/linkage.h
+++ b/arch/m68k/include/asm/linkage.h
@@ -4,4 +4,34 @@
 #define __ALIGN .align 4
 #define __ALIGN_STR ".align 4"
 
+/*
+ * Make sure the compiler doesn't do anything stupid with the
+ * arguments on the stack - they are owned by the *caller*, not
+ * the callee. This just fools gcc into not spilling into them,
+ * and keeps it from doing tailcall recursion and/or using the
+ * stack slots for temporaries, since they are live and "used"
+ * all the way to the end of the function.
+ */
+#define asmlinkage_protect(n, ret, args...) \
+	__asmlinkage_protect##n(ret, ##args)
+#define __asmlinkage_protect_n(ret, args...) \
+	__asm__ __volatile__ ("" : "=r" (ret) : "0" (ret), ##args)
+#define __asmlinkage_protect0(ret) \
+	__asmlinkage_protect_n(ret)
+#define __asmlinkage_protect1(ret, arg1) \
+	__asmlinkage_protect_n(ret, "m" (arg1))
+#define __asmlinkage_protect2(ret, arg1, arg2) \
+	__asmlinkage_protect_n(ret, "m" (arg1), "m" (arg2))
+#define __asmlinkage_protect3(ret, arg1, arg2, arg3) \
+	__asmlinkage_protect_n(ret, "m" (arg1), "m" (arg2), "m" (arg3))
+#define __asmlinkage_protect4(ret, arg1, arg2, arg3, arg4) \
+	__asmlinkage_protect_n(ret, "m" (arg1), "m" (arg2), "m" (arg3), \
+			      "m" (arg4))
+#define __asmlinkage_protect5(ret, arg1, arg2, arg3, arg4, arg5) \
+	__asmlinkage_protect_n(ret, "m" (arg1), "m" (arg2), "m" (arg3), \
+			      "m" (arg4), "m" (arg5))
+#define __asmlinkage_protect6(ret, arg1, arg2, arg3, arg4, arg5, arg6) \
+	__asmlinkage_protect_n(ret, "m" (arg1), "m" (arg2), "m" (arg3), \
+			      "m" (arg4), "m" (arg5), "m" (arg6))
+
 #endif
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258121 — [PATCH 3.12 076/123] genirq: Fix race in register_irq_proc()

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 076/123] genirq: Fix race in register_irq_proc()
Message-ID<qozK2-3GM-31@gated-at.bofh.it>
In reply to#1258058
From: Ben Hutchings <ben@decadent.org.uk>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 95c2b17534654829db428f11bcf4297c059a2a7e upstream.

Per-IRQ directories in procfs are created only when a handler is first
added to the irqdesc, not when the irqdesc is created.  In the case of
a shared IRQ, multiple tasks can race to create a directory.  This
race condition seems to have been present forever, but is easier to
hit with async probing.

Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Link: http://lkml.kernel.org/r/1443266636.2004.2.camel@decadent.org.uk
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 kernel/irq/proc.c | 19 +++++++++++++++++--
 1 file changed, 17 insertions(+), 2 deletions(-)

diff --git a/kernel/irq/proc.c b/kernel/irq/proc.c
index 095cd7230aef..56d7272199ff 100644
--- a/kernel/irq/proc.c
+++ b/kernel/irq/proc.c
@@ -12,6 +12,7 @@
 #include <linux/seq_file.h>
 #include <linux/interrupt.h>
 #include <linux/kernel_stat.h>
+#include <linux/mutex.h>
 
 #include "internals.h"
 
@@ -326,18 +327,29 @@ void register_handler_proc(unsigned int irq, struct irqaction *action)
 
 void register_irq_proc(unsigned int irq, struct irq_desc *desc)
 {
+	static DEFINE_MUTEX(register_lock);
 	char name [MAX_NAMELEN];
 
-	if (!root_irq_dir || (desc->irq_data.chip == &no_irq_chip) || desc->dir)
+	if (!root_irq_dir || (desc->irq_data.chip == &no_irq_chip))
 		return;
 
+	/*
+	 * irq directories are registered only when a handler is
+	 * added, not when the descriptor is created, so multiple
+	 * tasks might try to register at the same time.
+	 */
+	mutex_lock(&register_lock);
+
+	if (desc->dir)
+		goto out_unlock;
+
 	memset(name, 0, MAX_NAMELEN);
 	sprintf(name, "%d", irq);
 
 	/* create /proc/irq/1234 */
 	desc->dir = proc_mkdir(name, root_irq_dir);
 	if (!desc->dir)
-		return;
+		goto out_unlock;
 
 #ifdef CONFIG_SMP
 	/* create /proc/irq/<irq>/smp_affinity */
@@ -358,6 +370,9 @@ void register_irq_proc(unsigned int irq, struct irq_desc *desc)
 
 	proc_create_data("spurious", 0444, desc->dir,
 			 &irq_spurious_proc_fops, (void *)(long)irq);
+
+out_unlock:
+	mutex_unlock(&register_lock);
 }
 
 void unregister_irq_proc(unsigned int irq, struct irq_desc *desc)
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258122 — [PATCH 3.12 065/123] regmap: debugfs: Ensure we don't underflow when printing access masks

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 065/123] regmap: debugfs: Ensure we don't underflow when printing access masks
Message-ID<qozK2-3GM-33@gated-at.bofh.it>
In reply to#1258058
From: Mark Brown <broonie@kernel.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit b763ec17ac762470eec5be8ebcc43e4f8b2c2b82 upstream.

If a read is attempted which is smaller than the line length then we may
underflow the subtraction we're doing with the unsigned size_t type so
move some of the calculation to be additions on the right hand side
instead in order to avoid this.

Reported-by: Rasmus Villemoes <linux@rasmusvillemoes.dk>
Signed-off-by: Mark Brown <broonie@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/base/regmap/regmap-debugfs.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/base/regmap/regmap-debugfs.c b/drivers/base/regmap/regmap-debugfs.c
index b18c7da77067..b8a17b52f8f3 100644
--- a/drivers/base/regmap/regmap-debugfs.c
+++ b/drivers/base/regmap/regmap-debugfs.c
@@ -423,7 +423,7 @@ static ssize_t regmap_access_read_file(struct file *file,
 		/* If we're in the region the user is trying to read */
 		if (p >= *ppos) {
 			/* ...but not beyond it */
-			if (buf_pos >= count - 1 - tot_len)
+			if (buf_pos + tot_len + 1 >= count)
 				break;
 
 			/* Format the register */
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258123 — [PATCH 3.12 082/123] af_unix: Convert the unix_sk macro to an inline function for type safety

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 082/123] af_unix: Convert the unix_sk macro to an inline function for type safety
Message-ID<qozK2-3GM-35@gated-at.bofh.it>
In reply to#1258058
From: Aaron Conole <aconole@bytheb.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 4613012db1d911f80897f9446a49de817b2c4c47 ]

As suggested by Eric Dumazet this change replaces the
#define with a static inline function to enjoy
complaints by the compiler when misusing the API.

Signed-off-by: Aaron Conole <aconole@bytheb.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 include/net/af_unix.h | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/include/net/af_unix.h b/include/net/af_unix.h
index a175ba4a7adb..dfe4ddfbb43c 100644
--- a/include/net/af_unix.h
+++ b/include/net/af_unix.h
@@ -64,7 +64,11 @@ struct unix_sock {
 #define UNIX_GC_MAYBE_CYCLE	1
 	struct socket_wq	peer_wq;
 };
-#define unix_sk(__sk) ((struct unix_sock *)__sk)
+
+static inline struct unix_sock *unix_sk(struct sock *sk)
+{
+	return (struct unix_sock *)sk;
+}
 
 #define peer_wait peer_wq.wait
 
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258124 — [PATCH 3.12 066/123] regmap: debugfs: Don't bother actually printing when calculating max length

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 066/123] regmap: debugfs: Don't bother actually printing when calculating max length
Message-ID<qozK2-3GM-37@gated-at.bofh.it>
In reply to#1258058
From: Mark Brown <broonie@kernel.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 176fc2d5770a0990eebff903ba680d2edd32e718 upstream.

The in kernel snprintf() will conveniently return the actual length of
the printed string even if not given an output beffer at all so just do
that rather than relying on the user to pass in a suitable buffer,
ensuring that we don't need to worry if the buffer was truncated due to
the size of the buffer passed in.

Reported-by: Rasmus Villemoes <linux@rasmusvillemoes.dk>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/base/regmap/regmap-debugfs.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/drivers/base/regmap/regmap-debugfs.c b/drivers/base/regmap/regmap-debugfs.c
index b8a17b52f8f3..8135feff72a2 100644
--- a/drivers/base/regmap/regmap-debugfs.c
+++ b/drivers/base/regmap/regmap-debugfs.c
@@ -23,8 +23,7 @@ static struct dentry *regmap_debugfs_root;
 /* Calculate the length of a fixed format  */
 static size_t regmap_calc_reg_len(int max_val, char *buf, size_t buf_size)
 {
-	snprintf(buf, buf_size, "%x", max_val);
-	return strlen(buf);
+	return snprintf(NULL, 0, "%x", max_val);
 }
 
 static ssize_t regmap_name_read_file(struct file *file,
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258125 — [PATCH 3.12 058/123] usb: xhci: Clear XHCI_STATE_DYING on start

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 058/123] usb: xhci: Clear XHCI_STATE_DYING on start
Message-ID<qozK2-3GM-41@gated-at.bofh.it>
In reply to#1258058
From: Roger Quadros <rogerq@ti.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit e5bfeab0ad515b4f6df39fe716603e9dc6d3dfd0 upstream.

For whatever reason if XHCI died in the previous instant
then it will never recover on the next xhci_start unless we
clear the DYING flag.

Signed-off-by: Roger Quadros <rogerq@ti.com>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/usb/host/xhci.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/usb/host/xhci.c b/drivers/usb/host/xhci.c
index 1dd08da9652a..319515406b4f 100644
--- a/drivers/usb/host/xhci.c
+++ b/drivers/usb/host/xhci.c
@@ -143,7 +143,8 @@ static int xhci_start(struct xhci_hcd *xhci)
 				"waited %u microseconds.\n",
 				XHCI_MAX_HALT_USEC);
 	if (!ret)
-		xhci->xhc_state &= ~XHCI_STATE_HALTED;
+		xhci->xhc_state &= ~(XHCI_STATE_HALTED | XHCI_STATE_DYING);
+
 	return ret;
 }
 
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258126 — [PATCH 3.12 069/123] usb: Add device quirk for Logitech PTZ cameras

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 069/123] usb: Add device quirk for Logitech PTZ cameras
Message-ID<qozK2-3GM-43@gated-at.bofh.it>
In reply to#1258058
From: Vincent Palatin <vpalatin@chromium.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 72194739f54607bbf8cfded159627a2015381557 upstream.

Add a device quirk for the Logitech PTZ Pro Camera and its sibling the
ConferenceCam CC3000e Camera.
This fixes the failed camera enumeration on some boot, particularly on
machines with fast CPU.

Tested by connecting a Logitech PTZ Pro Camera to a machine with a
Haswell Core i7-4600U CPU @ 2.10GHz, and doing thousands of reboot cycles
while recording the kernel logs and taking camera picture after each boot.
Before the patch, more than 7% of the boots show some enumeration transfer
failures and in a few of them, the kernel is giving up before actually
enumerating the webcam. After the patch, the enumeration has been correct
on every reboot.

Signed-off-by: Vincent Palatin <vpalatin@chromium.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/usb/core/quirks.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/drivers/usb/core/quirks.c b/drivers/usb/core/quirks.c
index 5014a4282352..ecaca8e65356 100644
--- a/drivers/usb/core/quirks.c
+++ b/drivers/usb/core/quirks.c
@@ -53,6 +53,13 @@ static const struct usb_device_id usb_quirk_list[] = {
 	{ USB_DEVICE(0x046d, 0x082d), .driver_info = USB_QUIRK_DELAY_INIT },
 	{ USB_DEVICE(0x046d, 0x0843), .driver_info = USB_QUIRK_DELAY_INIT },
 
+	/* Logitech ConferenceCam CC3000e */
+	{ USB_DEVICE(0x046d, 0x0847), .driver_info = USB_QUIRK_DELAY_INIT },
+	{ USB_DEVICE(0x046d, 0x0848), .driver_info = USB_QUIRK_DELAY_INIT },
+
+	/* Logitech PTZ Pro Camera */
+	{ USB_DEVICE(0x046d, 0x0853), .driver_info = USB_QUIRK_DELAY_INIT },
+
 	/* Logitech Quickcam Fusion */
 	{ USB_DEVICE(0x046d, 0x08c1), .driver_info = USB_QUIRK_RESET_RESUME },
 
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258127 — [PATCH 3.12 061/123] Initialize msg/shm IPC objects before doing ipc_addid()

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 061/123] Initialize msg/shm IPC objects before doing ipc_addid()
Message-ID<qozK2-3GM-29@gated-at.bofh.it>
In reply to#1258058
From: Linus Torvalds <torvalds@linux-foundation.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit b9a532277938798b53178d5a66af6e2915cb27cf upstream.

As reported by Dmitry Vyukov, we really shouldn't do ipc_addid() before
having initialized the IPC object state.  Yes, we initialize the IPC
object in a locked state, but with all the lockless RCU lookup work,
that IPC object lock no longer means that the state cannot be seen.

We already did this for the IPC semaphore code (see commit e8577d1f0329:
"ipc/sem.c: fully initialize sem_array before making it visible") but we
clearly forgot about msg and shm.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Cc: Manfred Spraul <manfred@colorfullife.com>
Cc: Davidlohr Bueso <dbueso@suse.de>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 ipc/msg.c  | 14 +++++++-------
 ipc/shm.c  | 12 ++++++------
 ipc/util.c |  8 ++++----
 3 files changed, 17 insertions(+), 17 deletions(-)

diff --git a/ipc/msg.c b/ipc/msg.c
index 52770bfde2a5..32aaaab15c5c 100644
--- a/ipc/msg.c
+++ b/ipc/msg.c
@@ -202,13 +202,6 @@ static int newque(struct ipc_namespace *ns, struct ipc_params *params)
 		return retval;
 	}
 
-	/* ipc_addid() locks msq upon success. */
-	id = ipc_addid(&msg_ids(ns), &msq->q_perm, ns->msg_ctlmni);
-	if (id < 0) {
-		ipc_rcu_putref(msq, msg_rcu_free);
-		return id;
-	}
-
 	msq->q_stime = msq->q_rtime = 0;
 	msq->q_ctime = get_seconds();
 	msq->q_cbytes = msq->q_qnum = 0;
@@ -218,6 +211,13 @@ static int newque(struct ipc_namespace *ns, struct ipc_params *params)
 	INIT_LIST_HEAD(&msq->q_receivers);
 	INIT_LIST_HEAD(&msq->q_senders);
 
+	/* ipc_addid() locks msq upon success. */
+	id = ipc_addid(&msg_ids(ns), &msq->q_perm, ns->msg_ctlmni);
+	if (id < 0) {
+		ipc_rcu_putref(msq, msg_rcu_free);
+		return id;
+	}
+
 	ipc_unlock_object(&msq->q_perm);
 	rcu_read_unlock();
 
diff --git a/ipc/shm.c b/ipc/shm.c
index 623bc3877118..02f7125c8a0f 100644
--- a/ipc/shm.c
+++ b/ipc/shm.c
@@ -545,12 +545,6 @@ static int newseg(struct ipc_namespace *ns, struct ipc_params *params)
 	if (IS_ERR(file))
 		goto no_file;
 
-	id = ipc_addid(&shm_ids(ns), &shp->shm_perm, ns->shm_ctlmni);
-	if (id < 0) {
-		error = id;
-		goto no_id;
-	}
-
 	shp->shm_cprid = task_tgid_vnr(current);
 	shp->shm_lprid = 0;
 	shp->shm_atim = shp->shm_dtim = 0;
@@ -560,6 +554,12 @@ static int newseg(struct ipc_namespace *ns, struct ipc_params *params)
 	shp->shm_file = file;
 	shp->shm_creator = current;
 
+	id = ipc_addid(&shm_ids(ns), &shp->shm_perm, ns->shm_ctlmni);
+	if (id < 0) {
+		error = id;
+		goto no_id;
+	}
+
 	/*
 	 * shmid gets reported as "inode#" in /proc/pid/maps.
 	 * proc-ps tools use this. Changing this will break them.
diff --git a/ipc/util.c b/ipc/util.c
index 7684f41bce76..735342570a87 100644
--- a/ipc/util.c
+++ b/ipc/util.c
@@ -292,6 +292,10 @@ int ipc_addid(struct ipc_ids* ids, struct kern_ipc_perm* new, int size)
 	rcu_read_lock();
 	spin_lock(&new->lock);
 
+	current_euid_egid(&euid, &egid);
+	new->cuid = new->uid = euid;
+	new->gid = new->cgid = egid;
+
 	id = idr_alloc(&ids->ipcs_idr, new,
 		       (next_id < 0) ? 0 : ipcid_to_idx(next_id), 0,
 		       GFP_NOWAIT);
@@ -304,10 +308,6 @@ int ipc_addid(struct ipc_ids* ids, struct kern_ipc_perm* new, int size)
 
 	ids->in_use++;
 
-	current_euid_egid(&euid, &egid);
-	new->cuid = new->uid = euid;
-	new->gid = new->cgid = egid;
-
 	if (next_id < 0) {
 		new->seq = ids->seq++;
 		if (ids->seq > ids->seq_max)
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258128 — [PATCH 3.12 085/123] skbuff: Fix skb checksum flag on skb pull

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 085/123] skbuff: Fix skb checksum flag on skb pull
Message-ID<qozK2-3GM-45@gated-at.bofh.it>
In reply to#1258058
From: Pravin B Shelar <pshelar@nicira.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 6ae459bdaaeebc632b16e54dcbabb490c6931d61 ]

VXLAN device can receive skb with checksum partial. But the checksum
offset could be in outer header which is pulled on receive. This results
in negative checksum offset for the skb. Such skb can cause the assert
failure in skb_checksum_help(). Following patch fixes the bug by setting
checksum-none while pulling outer header.

Following is the kernel panic msg from old kernel hitting the bug.

------------[ cut here ]------------
kernel BUG at net/core/dev.c:1906!
RIP: 0010:[<ffffffff81518034>] skb_checksum_help+0x144/0x150
Call Trace:
<IRQ>
[<ffffffffa0164c28>] queue_userspace_packet+0x408/0x470 [openvswitch]
[<ffffffffa016614d>] ovs_dp_upcall+0x5d/0x60 [openvswitch]
[<ffffffffa0166236>] ovs_dp_process_packet_with_key+0xe6/0x100 [openvswitch]
[<ffffffffa016629b>] ovs_dp_process_received_packet+0x4b/0x80 [openvswitch]
[<ffffffffa016c51a>] ovs_vport_receive+0x2a/0x30 [openvswitch]
[<ffffffffa0171383>] vxlan_rcv+0x53/0x60 [openvswitch]
[<ffffffffa01734cb>] vxlan_udp_encap_recv+0x8b/0xf0 [openvswitch]
[<ffffffff8157addc>] udp_queue_rcv_skb+0x2dc/0x3b0
[<ffffffff8157b56f>] __udp4_lib_rcv+0x1cf/0x6c0
[<ffffffff8157ba7a>] udp_rcv+0x1a/0x20
[<ffffffff8154fdbd>] ip_local_deliver_finish+0xdd/0x280
[<ffffffff81550128>] ip_local_deliver+0x88/0x90
[<ffffffff8154fa7d>] ip_rcv_finish+0x10d/0x370
[<ffffffff81550365>] ip_rcv+0x235/0x300
[<ffffffff8151ba1d>] __netif_receive_skb+0x55d/0x620
[<ffffffff8151c360>] netif_receive_skb+0x80/0x90
[<ffffffff81459935>] virtnet_poll+0x555/0x6f0
[<ffffffff8151cd04>] net_rx_action+0x134/0x290
[<ffffffff810683d8>] __do_softirq+0xa8/0x210
[<ffffffff8162fe6c>] call_softirq+0x1c/0x30
[<ffffffff810161a5>] do_softirq+0x65/0xa0
[<ffffffff810687be>] irq_exit+0x8e/0xb0
[<ffffffff81630733>] do_IRQ+0x63/0xe0
[<ffffffff81625f2e>] common_interrupt+0x6e/0x6e

Reported-by: Anupam Chanda <achanda@vmware.com>
Signed-off-by: Pravin B Shelar <pshelar@nicira.com>
Acked-by: Tom Herbert <tom@herbertland.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 include/linux/skbuff.h | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/include/linux/skbuff.h b/include/linux/skbuff.h
index 47032528386a..80fad984cd8e 100644
--- a/include/linux/skbuff.h
+++ b/include/linux/skbuff.h
@@ -2264,6 +2264,9 @@ static inline void skb_postpull_rcsum(struct sk_buff *skb,
 {
 	if (skb->ip_summed == CHECKSUM_COMPLETE)
 		skb->csum = csum_sub(skb->csum, csum_partial(start, len, 0));
+	else if (skb->ip_summed == CHECKSUM_PARTIAL &&
+		 skb_checksum_start_offset(skb) <= len)
+		skb->ip_summed = CHECKSUM_NONE;
 }
 
 unsigned char *skb_pull_rcsum(struct sk_buff *skb, unsigned int len);
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258130 — [PATCH 3.12 087/123] net: add pfmemalloc check in sk_add_backlog()

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 087/123] net: add pfmemalloc check in sk_add_backlog()
Message-ID<qozK3-3GM-49@gated-at.bofh.it>
In reply to#1258058
From: Eric Dumazet <edumazet@google.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit c7c49b8fde26b74277188bdc6c9dca38db6fa35b ]

Greg reported crashes hitting the following check in __sk_backlog_rcv()

	BUG_ON(!sock_flag(sk, SOCK_MEMALLOC));

The pfmemalloc bit is currently checked in sk_filter().

This works correctly for TCP, because sk_filter() is ran in
tcp_v[46]_rcv() before hitting the prequeue or backlog checks.

For UDP or other protocols, this does not work, because the sk_filter()
is ran from sock_queue_rcv_skb(), which might be called _after_ backlog
queuing if socket is owned by user by the time packet is processed by
softirq handler.

Fixes: b4b9e35585089 ("netvm: set PF_MEMALLOC as appropriate during SKB processing")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Greg Thelen <gthelen@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 include/net/sock.h | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/include/net/sock.h b/include/net/sock.h
index d157f4f56f01..4f355e69e5d2 100644
--- a/include/net/sock.h
+++ b/include/net/sock.h
@@ -788,6 +788,14 @@ static inline __must_check int sk_add_backlog(struct sock *sk, struct sk_buff *s
 	if (sk_rcvqueues_full(sk, skb, limit))
 		return -ENOBUFS;
 
+	/*
+	 * If the skb was allocated from pfmemalloc reserves, only
+	 * allow SOCK_MEMALLOC sockets to use it as this socket is
+	 * helping free memory
+	 */
+	if (skb_pfmemalloc(skb) && !sock_flag(sk, SOCK_MEMALLOC))
+		return -ENOMEM;
+
 	__sk_add_backlog(sk, skb);
 	sk->sk_backlog.len += skb->truesize;
 	return 0;
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258131 — [PATCH 3.12 071/123] MIPS: dma-default: Fix 32-bit fall back to GFP_DMA

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 071/123] MIPS: dma-default: Fix 32-bit fall back to GFP_DMA
Message-ID<qozK3-3GM-53@gated-at.bofh.it>
In reply to#1258058
From: James Hogan <james.hogan@imgtec.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 53960059d56ecef67d4ddd546731623641a3d2d1 upstream.

If there is a DMA zone (usually 24bit = 16MB I believe), but no DMA32
zone, as is the case for some 32-bit kernels, then massage_gfp_flags()
will cause DMA memory allocated for devices with a 32..63-bit
coherent_dma_mask to fall back to using __GFP_DMA, even though there may
only be 32-bits of physical address available anyway.

Correct that case to compare against a mask the size of phys_addr_t
instead of always using a 64-bit mask.

Signed-off-by: James Hogan <james.hogan@imgtec.com>
Fixes: a2e715a86c6d ("MIPS: DMA: Fix computation of DMA flags from device's coherent_dma_mask.")
Cc: Ralf Baechle <ralf@linux-mips.org>
Cc: linux-mips@linux-mips.org
Patchwork: https://patchwork.linux-mips.org/patch/9610/
Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 arch/mips/mm/dma-default.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/mips/mm/dma-default.c b/arch/mips/mm/dma-default.c
index 5f8b95512580..7dd78fc991bf 100644
--- a/arch/mips/mm/dma-default.c
+++ b/arch/mips/mm/dma-default.c
@@ -92,7 +92,7 @@ static gfp_t massage_gfp_flags(const struct device *dev, gfp_t gfp)
 	else
 #endif
 #if defined(CONFIG_ZONE_DMA) && !defined(CONFIG_ZONE_DMA32)
-	     if (dev->coherent_dma_mask < DMA_BIT_MASK(64))
+	     if (dev->coherent_dma_mask < DMA_BIT_MASK(sizeof(phys_addr_t) * 8))
 		dma_flag = __GFP_DMA;
 	else
 #endif
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258132 — [PATCH 3.12 074/123] arm64: readahead: fault retry breaks mmap file read random detection

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 074/123] arm64: readahead: fault retry breaks mmap file read random detection
Message-ID<qozK3-3GM-57@gated-at.bofh.it>
In reply to#1258058
From: Mark Salyzyn <salyzyn@android.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 569ba74a7ba69f46ce2950bf085b37fea2408385 upstream.

This is the arm64 portion of commit 45cac65b0fcd ("readahead: fault
retry breaks mmap file read random detection"), which was absent from
the initial port and has since gone unnoticed. The original commit says:

> .fault now can retry.  The retry can break state machine of .fault.  In
> filemap_fault, if page is miss, ra->mmap_miss is increased.  In the second
> try, since the page is in page cache now, ra->mmap_miss is decreased.  And
> these are done in one fault, so we can't detect random mmap file access.
>
> Add a new flag to indicate .fault is tried once.  In the second try, skip
> ra->mmap_miss decreasing.  The filemap_fault state machine is ok with it.

With this change, Mark reports that:

> Random read improves by 250%, sequential read improves by 40%, and
> random write by 400% to an eMMC device with dm crypto wrapped around it.

Cc: Shaohua Li <shli@kernel.org>
Cc: Rik van Riel <riel@redhat.com>
Cc: Wu Fengguang <fengguang.wu@intel.com>
Signed-off-by: Mark Salyzyn <salyzyn@android.com>
Signed-off-by: Riley Andrews <riandrews@android.com>
Signed-off-by: Will Deacon <will.deacon@arm.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 arch/arm64/mm/fault.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/arch/arm64/mm/fault.c b/arch/arm64/mm/fault.c
index c23751b06120..cc083b6e4ce7 100644
--- a/arch/arm64/mm/fault.c
+++ b/arch/arm64/mm/fault.c
@@ -278,6 +278,7 @@ retry:
 			 * starvation.
 			 */
 			mm_flags &= ~FAULT_FLAG_ALLOW_RETRY;
+			mm_flags |= FAULT_FLAG_TRIED;
 			goto retry;
 		}
 	}
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258134 — [PATCH 3.12 077/123] dm cache: fix NULL pointer when switching from cleaner policy

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 077/123] dm cache: fix NULL pointer when switching from cleaner policy
Message-ID<qozK3-3GM-67@gated-at.bofh.it>
In reply to#1258058
From: Joe Thornber <ejt@redhat.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 2bffa1503c5c06192eb1459180fac4416575a966 upstream.

The cleaner policy doesn't make use of the per cache block hint space in
the metadata (unlike the other policies).  When switching from the
cleaner policy to mq or smq a NULL pointer crash (in dm_tm_new_block)
was observed.  The crash was caused by bugs in dm-cache-metadata.c
when trying to skip creation of the hint btree.

The minimal fix is to change hint size for the cleaner policy to 4 bytes
(only hint size supported).

Signed-off-by: Joe Thornber <ejt@redhat.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/md/dm-cache-policy-cleaner.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/md/dm-cache-policy-cleaner.c b/drivers/md/dm-cache-policy-cleaner.c
index b04d1f904d07..2eca9084defe 100644
--- a/drivers/md/dm-cache-policy-cleaner.c
+++ b/drivers/md/dm-cache-policy-cleaner.c
@@ -434,7 +434,7 @@ static struct dm_cache_policy *wb_create(dm_cblock_t cache_size,
 static struct dm_cache_policy_type wb_policy_type = {
 	.name = "cleaner",
 	.version = {1, 0, 0},
-	.hint_size = 0,
+	.hint_size = 4,
 	.owner = THIS_MODULE,
 	.create = wb_create
 };
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258135 — [PATCH 3.12 067/123] security: fix typo in security_task_prctl

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 067/123] security: fix typo in security_task_prctl
Message-ID<qozK3-3GM-71@gated-at.bofh.it>
In reply to#1258058
From: Jann Horn <jann@thejh.net>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit b7f76ea2ef6739ee484a165ffbac98deb855d3d3 upstream.

Signed-off-by: Jann Horn <jann@thejh.net>
Reviewed-by: Andy Lutomirski <luto@kernel.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 include/linux/security.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/linux/security.h b/include/linux/security.h
index 9d37e2b9d3ec..dd7c1a16ab5e 100644
--- a/include/linux/security.h
+++ b/include/linux/security.h
@@ -2441,7 +2441,7 @@ static inline int security_task_prctl(int option, unsigned long arg2,
 				      unsigned long arg4,
 				      unsigned long arg5)
 {
-	return cap_task_prctl(option, arg2, arg3, arg3, arg5);
+	return cap_task_prctl(option, arg2, arg3, arg4, arg5);
 }
 
 static inline void security_task_to_inode(struct task_struct *p, struct inode *inode)
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258136 — [PATCH 3.12 072/123] UBI: Validate data_size

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 072/123] UBI: Validate data_size
Message-ID<qozK3-3GM-59@gated-at.bofh.it>
In reply to#1258058
From: Richard Weinberger <richard@nod.at>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 281fda27673f833a01d516658a64d22a32c8e072 upstream.

Make sure that data_size is less than LEB size.
Otherwise a handcrafted UBI image is able to trigger
an out of bounds memory access in ubi_compare_lebs().

Signed-off-by: Richard Weinberger <richard@nod.at>
Reviewed-by: David Gstir <david@sigma-star.at>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/mtd/ubi/io.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/mtd/ubi/io.c b/drivers/mtd/ubi/io.c
index bf79def40126..8822e880833b 100644
--- a/drivers/mtd/ubi/io.c
+++ b/drivers/mtd/ubi/io.c
@@ -931,6 +931,11 @@ static int validate_vid_hdr(const struct ubi_device *ubi,
 		goto bad;
 	}
 
+	if (data_size > ubi->leb_size) {
+		ubi_err("bad data_size");
+		goto bad;
+	}
+
 	if (vol_type == UBI_VID_STATIC) {
 		/*
 		 * Although from high-level point of view static volumes may
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258137 — [PATCH 3.12 086/123] skbuff: Fix skb checksum partial check.

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 086/123] skbuff: Fix skb checksum partial check.
Message-ID<qozK3-3GM-69@gated-at.bofh.it>
In reply to#1258058
From: Pravin B Shelar <pshelar@nicira.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 31b33dfb0a144469dd805514c9e63f4993729a48 ]

Earlier patch 6ae459bda tried to detect void ckecksum partial
skb by comparing pull length to checksum offset. But it does
not work for all cases since checksum-offset depends on
updates to skb->data.

Following patch fixes it by validating checksum start offset
after skb-data pointer is updated. Negative value of checksum
offset start means there is no need to checksum.

Fixes: 6ae459bda ("skbuff: Fix skb checksum flag on skb pull")
Reported-by: Andrew Vagin <avagin@odin.com>
Signed-off-by: Pravin B Shelar <pshelar@nicira.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 include/linux/skbuff.h | 2 +-
 net/core/skbuff.c      | 9 +++++----
 2 files changed, 6 insertions(+), 5 deletions(-)

diff --git a/include/linux/skbuff.h b/include/linux/skbuff.h
index 80fad984cd8e..16e753a9922a 100644
--- a/include/linux/skbuff.h
+++ b/include/linux/skbuff.h
@@ -2265,7 +2265,7 @@ static inline void skb_postpull_rcsum(struct sk_buff *skb,
 	if (skb->ip_summed == CHECKSUM_COMPLETE)
 		skb->csum = csum_sub(skb->csum, csum_partial(start, len, 0));
 	else if (skb->ip_summed == CHECKSUM_PARTIAL &&
-		 skb_checksum_start_offset(skb) <= len)
+		 skb_checksum_start_offset(skb) < 0)
 		skb->ip_summed = CHECKSUM_NONE;
 }
 
diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index b01dd5f421da..de76393a9916 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -2726,11 +2726,12 @@ EXPORT_SYMBOL(skb_append_datato_frags);
  */
 unsigned char *skb_pull_rcsum(struct sk_buff *skb, unsigned int len)
 {
+	unsigned char *data = skb->data;
+
 	BUG_ON(len > skb->len);
-	skb->len -= len;
-	BUG_ON(skb->len < skb->data_len);
-	skb_postpull_rcsum(skb, skb->data, len);
-	return skb->data += len;
+	__skb_pull(skb, len);
+	skb_postpull_rcsum(skb, data, len);
+	return skb->data;
 }
 EXPORT_SYMBOL_GPL(skb_pull_rcsum);
 
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258139 — [PATCH 3.12 040/123] ALSA: synth: Fix conflicting OSS device registration on AWE32

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 040/123] ALSA: synth: Fix conflicting OSS device registration on AWE32
Message-ID<qozK4-3GM-77@gated-at.bofh.it>
In reply to#1258058
From: Takashi Iwai <tiwai@suse.de>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 225db5762dc1a35b26850477ffa06e5cd0097243 upstream.

When OSS emulation is loaded on ISA SB AWE32 chip, we get now kernel
warnings like:
  WARNING: CPU: 0 PID: 2791 at fs/sysfs/dir.c:31 sysfs_warn_dup+0x51/0x80()
  sysfs: cannot create duplicate filename '/devices/isa/sbawe.0/sound/card0/seq-oss-0-0'

It's because both emux synth and opl3 drivers try to register their
OSS device object with the same static index number 0.  This hasn't
been a big problem until the recent rewrite of device management code
(that exposes sysfs at the same time), but it's been an obvious bug.

This patch works around it just by using a different index number of
emux synth object.  There can be a more elegant way to fix, but it's
enough for now, as this code won't be touched so often, in anyway.

Reported-and-tested-by: Michael Shell <list1@michaelshell.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 sound/synth/emux/emux_oss.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/sound/synth/emux/emux_oss.c b/sound/synth/emux/emux_oss.c
index daf61abc3670..646b66703bd8 100644
--- a/sound/synth/emux/emux_oss.c
+++ b/sound/synth/emux/emux_oss.c
@@ -69,7 +69,8 @@ snd_emux_init_seq_oss(struct snd_emux *emu)
 	struct snd_seq_oss_reg *arg;
 	struct snd_seq_device *dev;
 
-	if (snd_seq_device_new(emu->card, 0, SNDRV_SEQ_DEV_ID_OSS,
+	/* using device#1 here for avoiding conflicts with OPL3 */
+	if (snd_seq_device_new(emu->card, 1, SNDRV_SEQ_DEV_ID_OSS,
 			       sizeof(struct snd_seq_oss_reg), &dev) < 0)
 		return;
 
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1258143 — [PATCH 3.12 084/123] net/unix: fix logic about sk_peek_offset

FromJiri Slaby <jslaby@suse.cz>
Date2015-10-28 15:20 +0100
Subject[PATCH 3.12 084/123] net/unix: fix logic about sk_peek_offset
Message-ID<qozK5-3GM-83@gated-at.bofh.it>
In reply to#1258058
From: Andrey Vagin <avagin@openvz.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit e9193d60d363e4dff75ff6d43a48f22be26d59c7 ]

Now send with MSG_PEEK can return data from multiple SKBs.

Unfortunately we take into account the peek offset for each skb,
that is wrong. We need to apply the peek offset only once.

In addition, the peek offset should be used only if MSG_PEEK is set.

Cc: "David S. Miller" <davem@davemloft.net>
Cc: Eric Dumazet <edumazet@google.com>
Cc: Aaron Conole <aconole@bytheb.org>
Fixes: 9f389e35674f ("af_unix: return data from multiple SKBs on recv() with MSG_PEEK flag")
Signed-off-by: Andrey Vagin <avagin@openvz.org>
Tested-by: Aaron Conole <aconole@bytheb.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 net/unix/af_unix.c | 12 +++++++-----
 1 file changed, 7 insertions(+), 5 deletions(-)

diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
index 39b9429c2c86..157b3595ef62 100644
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -1954,6 +1954,11 @@ static int unix_stream_recvmsg(struct kiocb *iocb, struct socket *sock,
 		goto out;
 	}
 
+	if (flags & MSG_PEEK)
+		skip = sk_peek_offset(sk, flags);
+	else
+		skip = 0;
+
 	do {
 		int chunk;
 		struct sk_buff *skb, *last;
@@ -2000,7 +2005,6 @@ again:
 			break;
 		}
 
-		skip = sk_peek_offset(sk, flags);
 		while (skip >= unix_skb_len(skb)) {
 			skip -= unix_skb_len(skb);
 			last = skb;
@@ -2062,14 +2066,12 @@ again:
 			if (UNIXCB(skb).fp)
 				siocb->scm->fp = scm_fp_dup(UNIXCB(skb).fp);
 
-			if (skip) {
-				sk_peek_offset_fwd(sk, chunk);
-				skip -= chunk;
-			}
+			sk_peek_offset_fwd(sk, chunk);
 
 			if (UNIXCB(skb).fp)
 				break;
 
+			skip = 0;
 			last = skb;
 			unix_state_lock(sk);
 			skb = skb_peek_next(skb, &sk->sk_receive_queue);
-- 
2.6.2

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


Page 3 of 4 — ← Prev page 1 2 [3] 4  Next page →

Back to top | Article view | linux.kernel


csiph-web