Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1268321 > unrolled thread

[3.19.y-ckt stable] Linux 3.19.8-ckt10 stable review

Started byKamal Mostafa <kamal@canonical.com>
First post2015-11-13 00:20 +0100
Last post2015-11-13 01:20 +0100
Articles 20 on this page of 161 — 4 participants

Back to article view | Back to linux.kernel


Contents

  [3.19.y-ckt stable] Linux 3.19.8-ckt10 stable review Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:20 +0100
    [PATCH 3.19.y-ckt 029/155] x86/mm: Set NX on gap between __ex_table and rodata Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:20 +0100
    [PATCH 3.19.y-ckt 052/155] ALSA: hda: Add dock support for ThinkPad T550 Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:20 +0100
    [PATCH 3.19.y-ckt 088/155] af_unix: Convert the unix_sk macro to an inline function for type safety Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:20 +0100
    [PATCH 3.19.y-ckt 025/155] mm: hugetlbfs: skip shared VMAs when unmapping private pages to satisfy a fault Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:20 +0100
    [PATCH 3.19.y-ckt 153/155] ipv6: Fix IPsec pre-encap fragmentation check Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 150/155] md/raid5: fix locking in handle_stripe_clean_event() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 135/155] IB/cm: Fix rb-tree duplicate free and use-after-free Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 142/155] md/raid10: submit_bio_wait() returns 0 on success Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 141/155] md/raid1: submit_bio_wait() returns 0 on success Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 154/155] ipv6: gre: support SIT encapsulation Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 144/155] i2c: mv64xxx: really allow I2C offloading Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 146/155] mvsas: Fix NULL pointer dereference in mvs_slot_task_free Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 123/155] drm/nouveau/gem: return only valid domain when there's only one Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 145/155] drm/radeon: don't try to recreate sysfs entries on resume Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 151/155] Revert "md: allow a partially recovered device to be hot-added to an array." Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 126/155] mm: make sendfile(2) killable Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 148/155] Revert "ARM64: unwind: Fix PC calculation" Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 131/155] dm btree remove: fix a bug when rebalancing nodes after removal Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 132/155] dm btree: fix leak of bufio-backed block in btree_split_beneath error path Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 136/155] module: Fix locking in symbol_put_addr() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 149/155] rbd: require stable pages if message data CRCs are enabled Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 121/155] ASoC: wm8904: Correct number of EQ registers Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 124/155] powerpc/rtas: Validate rtas.entry before calling enter_rtas() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 137/155] PCI: Prevent out of bounds access in numa_node override Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 139/155] ovl: fix dentry reference leak Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 127/155] fault-inject: fix inverted interval/probability values in printk Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 143/155] iommu/amd: Don't clear DTE flags when modifying it Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 152/155] net/mlx4: Copy/set only sizeof struct mlx4_eqe bytes Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 122/155] drm: fix mutex leak in drm_dp_get_mst_branch_device Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 134/155] ARM: dts: am57xx-beagle-x15: set VDD_SD to always-on Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 147/155] arm64: compat: fix stxr failure case in SWP emulation Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 116/155] x86/setup: Extend low identity map to cover whole kernel range Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
      Re: [PATCH 3.19.y-ckt 116/155] x86/setup: Extend low identity map to  cover whole kernel range Matt Fleming <matt@codeblueprint.co.uk> - 2015-11-13 10:10 +0100
        Re: [PATCH 3.19.y-ckt 116/155] x86/setup: Extend low identity map  to cover whole kernel range Kamal Mostafa <kamal@canonical.com> - 2015-11-13 17:50 +0100
    [PATCH 3.19.y-ckt 140/155] crypto: api - Only abort operations on fatal signal Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 120/155] xhci: Add spurious wakeup quirk for LynxPoint-LP controllers Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 155/155] ppp: fix pppoe_dev deletion condition in pppoe_release() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 138/155] ovl: use O_LARGEFILE in ovl_copy_up() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 129/155] rbd: don't leak parent_spec in rbd_dev_probe_parent() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 115/155] x86/efi: Fix multiple GOP device support Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 133/155] bpf: fix panic in SO_GET_FILTER with native ebpf programs Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:30 +0100
    [PATCH 3.19.y-ckt 101/155] iwlwifi: mvm: fix D3 firmware PN programming Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 092/155] skbuff: Fix skb checksum partial check. Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 118/155] xhci: don't finish a TD if we get a short transfer event mid TD Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 113/155] drm/i915: Deny wrapping an userptr into a framebuffer Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 106/155] ARM: orion: Fix DSA platform device after mvmdio conversion Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 117/155] ASoC: Add info callback for SX_TLV controls Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 105/155] iwlwifi: mvm: init card correctly on ctkill exit check Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 114/155] iommu/vt-d: fix range computation when making room for large pages Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 112/155] drm/i915: Restore lost DPLL register write on gen2-4 Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 096/155] ethtool: Use kcalloc instead of kmalloc for ethtool_get_strings Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 108/155] iio: mxs-lradc: Fix temperature offset Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 107/155] xen-blkfront: check for null drvdata in blkback_changed (XenbusStateClosing) Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 103/155] iwlwifi: fix firmware filename for 3160 Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 090/155] net/unix: fix logic about sk_peek_offset Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 110/155] ALSA: hda - Fix inverted internal mic on Lenovo G50-80 Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 098/155] ath9k: declare required extra tx headroom Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 022/155] x86/efi: Fix boot crash by mapping EFI memmap entries bottom-up at runtime, instead of top-down Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 097/155] netlink: Trim skb to alloc size to avoid MSG_TRUNC Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 104/155] iwlwifi: pci: add a few more PCI subvendor IDs for the 7265 series Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 089/155] af_unix: return data from multiple SKBs on recv() with MSG_PEEK flag Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 111/155] drm/i915: Flush pipecontrol post-sync writes Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 102/155] iwlwifi: mvm: clear csa countdown when AP is stopped Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 125/155] [media] si2168: Bounds check firmware Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 119/155] xhci: handle no ping response error properly Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 093/155] net: add pfmemalloc check in sk_add_backlog() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 100/155] iwlwifi: dvm: fix D3 firmware PN programming Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 128/155] rbd: fix double free on rbd_dev->header_name Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 091/155] skbuff: Fix skb checksum flag on skb pull Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 099/155] iio: accel: sca3000: memory corruption in sca3000_read_first_n_hw_rb() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 109/155] ARM: dts: Fix audio card detection on Peach boards Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 130/155] rbd: prevent kernel stack blow up on rbd map Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:40 +0100
    [PATCH 3.19.y-ckt 095/155] ovs: do not allocate memory from offline numa node Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:50 +0100
    [PATCH 3.19.y-ckt 083/155] i2c: designware-platdrv: enable RuntimePM before registering to the core Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:50 +0100
    [PATCH 3.19.y-ckt 087/155] l2tp: protect tunnel->del_work by ref_count Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:50 +0100
    [PATCH 3.19.y-ckt 085/155] i2c: designware: Do not use parameters from ACPI on Dell Inspiron 7348 Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:50 +0100
    [PATCH 3.19.y-ckt 082/155] i2c: s3c2410: enable RuntimePM before registering to the core Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:50 +0100
    [PATCH 3.19.y-ckt 086/155] pinctrl: imx25: ensure that a pin with id i is at position i in the info array Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:50 +0100
    [PATCH 3.19.y-ckt 084/155] memcg: convert threshold to bytes Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:50 +0100
    [PATCH 3.19.y-ckt 080/155] drm/dp/mst: make mst i2c transfer code more robust. Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:50 +0100
    [PATCH 3.19.y-ckt 094/155] ppp: don't override sk->sk_state in pppoe_flush_dev() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:50 +0100
    [PATCH 3.19.y-ckt 047/155] dm: fix AB-BA deadlock in __dm_destroy() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:50 +0100
    [PATCH 3.19.y-ckt 028/155] x86/kexec: Fix kexec crash in syscall kexec_file_load() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:50 +0100
    [PATCH 3.19.y-ckt 081/155] i2c: rcar: enable RuntimePM before registering to the core Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:50 +0100
    [PATCH 3.19.y-ckt 078/155] btrfs: check unsupported filters in balance arguments Kamal Mostafa <kamal@canonical.com> - 2015-11-13 00:50 +0100
    [PATCH 3.19.y-ckt 060/155] ALSA: synth: Fix conflicting OSS device registration on AWE32 Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 071/155] cxl: Fix number of allocated pages in SPA Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 064/155] sched/core: Fix TASK_DEAD race in finish_task_switch() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 055/155] usb: Add device quirk for Logitech PTZ cameras Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 073/155] drm: Fix locking for sysfs dpms file Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 072/155] crypto: sparc - initialize blkcipher.ivsize Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 076/155] crypto: ahash - ensure statesize is non-zero Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 068/155] drm/radeon: add pm sysfs files late Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 075/155] arm64: errata: use KBUILD_CFLAGS_MODULE for erratum #843419 Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 054/155] USB: Add reset-resume quirk for two Plantronics usb headphones. Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 063/155] ASoC: tas2552: fix dBscale-min declaration Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 061/155] arm64: readahead: fault retry breaks mmap file read random detection Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 057/155] serial: 8250: add uart_config entry for PORT_RT2880 Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 056/155] tty: fix stall caused by missing memory barrier in drivers/tty/n_tty.c Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 077/155] dm thin: fix missing pool reference count decrement in pool_ctr error path Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 066/155] 3w-9xxx: don't unmap bounce buffered commands Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 045/155] svcrdma: handle rdma read with a non-zero initial page offset Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 079/155] btrfs: fix use after free iterating extrefs Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 065/155] dm cache: fix NULL pointer when switching from cleaner policy Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 067/155] workqueue: make sure delayed work run in local cpu Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 058/155] drivers/tty: require read access for controlling terminal Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 059/155] staging: speakup: fix speakup-r regression Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 053/155] ALSA: hda - Apply SPDIF pin ctl to MacBookPro 12,1 Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 018/155] x86/asm/entry: Create and use a 'TOP_OF_KERNEL_STACK_PADDING' macro Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 070/155] drm/radeon: add quirk for ASUS R7 370 Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 074/155] drm/nouveau/fbcon: take runpm reference when userspace has an open fd Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 019/155] x86/process: Add proper bound checks in 64bit get_wchan() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 049/155] clk: ti: fix dual-registration of uart4_ick Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 050/155] ASoC: dwc: correct irq clear method Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 069/155] drm/radeon: add quirk for MSI R7 370 Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 048/155] [SMB3] Do not fall back to SMBWriteX in set_file_size error cases Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 046/155] ASoC: sgtl5000: fix wrong register MIC_BIAS_VOLTAGE setup on probe Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
      Re: [PATCH 3.19.y-ckt 046/155] ASoC: sgtl5000: fix wrong register  MIC_BIAS_VOLTAGE setup on probe gianluca <gianlucarenzi@eurek.it> - 2015-11-13 10:20 +0100
    [PATCH 3.19.y-ckt 062/155] ASoC: tas2552: Correct the Speaker Driver Playback Volume (PGA_GAIN) Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 051/155] dm raid: fix round up of default region size Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:00 +0100
    [PATCH 3.19.y-ckt 007/155] m68k: Define asmlinkage_protect Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 041/155] ASoC: db1200: Fix DAI link format for db1300 and db1550 Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 020/155] drm/qxl: recreate the primary surface when the bo is not primary Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 035/155] mm/slab: fix unexpected index mapping result of kmalloc_size(INDEX_NODE+1) Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 031/155] md/raid0: apply base queue limits *before* disk_stack_limits Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 013/155] MIPS: dma-default: Fix 32-bit fall back to GFP_DMA Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 015/155] MIPS: CPS: Don't include MT code in non-MT kernels. Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 038/155] mtd: nand: sunxi: fix OOB handling in ->write_xxx() functions Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 003/155] [media] media/vivid-osd: fix info leak in ioctl Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 023/155] KVM: nSVM: Check for NRIPS support before updating control field Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 030/155] md/raid0: update queue parameter in a safer location. Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 039/155] mtd: nand: sunxi: fix sunxi_nand_chips_cleanup() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 012/155] drm/radeon: fix dpms when driver backlight control is disabled Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 044/155] s390/boot/decompression: disable floating point in decompressor Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 043/155] x86/xen: Do not clip xen_e820_map to xen_e820_map_entries when sanitizing map Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 036/155] regmap: debugfs: Ensure we don't underflow when printing access masks Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 027/155] drm/dp/mst: drop cancel work sync in the mstb destroy path (v2) Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 016/155] MIPS: CPS: #ifdef on CONFIG_MIPS_MT_SMP rather than CONFIG_MIPS_MT Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 040/155] ARM: dts: fix usb pin control for imx-rex dts Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 037/155] regmap: debugfs: Don't bother actually printing when calculating max length Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 032/155] arm64: ftrace: fix function_graph tracer panic Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 017/155] Initialize msg/shm IPC objects before doing ipc_addid() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 034/155] dmaengine: dw: properly read DWC_PARAMS register Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 033/155] clocksource: Fix abs() usage w/ 64bit values Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 024/155] Use WARN_ON_ONCE for missing X86_FEATURE_NRIPS Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 014/155] MIPS: CPS: Stop dangling delay slot from has_mt. Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 008/155] UBI: Validate data_size Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 021/155] genirq: Fix race in register_irq_proc() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 042/155] x86/xen: Support kexec/kdump in HVM guests by doing a soft reset Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
      Re: [PATCH 3.19.y-ckt 042/155] x86/xen: Support kexec/kdump in HVM  guests by doing a soft reset David Vrabel <david.vrabel@citrix.com> - 2015-11-13 11:30 +0100
        Re: [PATCH 3.19.y-ckt 042/155] x86/xen: Support kexec/kdump in HVM  guests by doing a soft reset Kamal Mostafa <kamal@canonical.com> - 2015-11-13 18:00 +0100
    [PATCH 3.19.y-ckt 026/155] drm/dp/mst: fixup handling hotplug on port removal. Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:10 +0100
    [PATCH 3.19.y-ckt 011/155] drm/radeon: move bl encoder assignment into bl init Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:20 +0100
    [PATCH 3.19.y-ckt 004/155] staging/dgnc: fix info leak in ioctl Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:20 +0100
    [PATCH 3.19.y-ckt 001/155] isdn_ppp: Add checks for allocation failure in isdn_ppp_open() Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:20 +0100
    [PATCH 3.19.y-ckt 009/155] UBI: return ENOSPC if no enough space available Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:20 +0100
    [PATCH 3.19.y-ckt 002/155] ppp, slip: Validate VJ compression slot parameters completely Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:20 +0100
    [PATCH 3.19.y-ckt 010/155] drm/radeon: Restore LCD backlight level on resume (>= R5xx) Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:20 +0100
    [PATCH 3.19.y-ckt 006/155] perf tools: Fix copying of /proc/kcore Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:20 +0100
    [PATCH 3.19.y-ckt 005/155] tools lib traceevent: Fix string handling in heterogeneous arch environments Kamal Mostafa <kamal@canonical.com> - 2015-11-13 01:20 +0100

Page 3 of 9 — ← Prev page 1 2 [3] 4 5 6 7 8 9  Next page →


#1268363 — [PATCH 3.19.y-ckt 115/155] x86/efi: Fix multiple GOP device support

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:30 +0100
Subject[PATCH 3.19.y-ckt 115/155] x86/efi: Fix multiple GOP device support
Message-ID<qu9ty-71V-79@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: =?UTF-8?q?K=C5=91v=C3=A1g=C3=B3=2C=20Zolt=C3=A1n?=

commit 8a53554e12e98d1759205afd7b8e9e2ea0936f48 upstream.

When multiple GOP devices exists, but none of them implements
ConOut, the code should just choose the first GOP (according to
the comments). But currently 'fb_base' will refer to the last GOP,
while other parameters to the first GOP, which will likely
result in a garbled display.

I can reliably reproduce this bug using my ASRock Z87M Extreme4
motherboard with CSM and integrated GPU disabled, and two PCIe
video cards (NVidia GT640 and GTX980), booting from efi-stub
(booting from grub works fine).  On the primary display the
ASRock logo remains and on the secondary screen it is garbled
up completely.

Signed-off-by: Kővágó, Zoltán <DirtY.iCE.hu@gmail.com>
Signed-off-by: Matt Fleming <matt.fleming@intel.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Matthew Garrett <mjg59@srcf.ucam.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Link: http://lkml.kernel.org/r/1444659236-24837-2-git-send-email-matt@codeblueprint.co.uk
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/x86/boot/compressed/eboot.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/arch/x86/boot/compressed/eboot.c b/arch/x86/boot/compressed/eboot.c
index b451033..7a4e75f 100644
--- a/arch/x86/boot/compressed/eboot.c
+++ b/arch/x86/boot/compressed/eboot.c
@@ -668,6 +668,7 @@ setup_gop32(struct screen_info *si, efi_guid_t *proto,
 		bool conout_found = false;
 		void *dummy = NULL;
 		u32 h = handles[i];
+		u32 current_fb_base;
 
 		status = efi_call_early(handle_protocol, h,
 					proto, (void **)&gop32);
@@ -679,7 +680,7 @@ setup_gop32(struct screen_info *si, efi_guid_t *proto,
 		if (status == EFI_SUCCESS)
 			conout_found = true;
 
-		status = __gop_query32(gop32, &info, &size, &fb_base);
+		status = __gop_query32(gop32, &info, &size, &current_fb_base);
 		if (status == EFI_SUCCESS && (!first_gop || conout_found)) {
 			/*
 			 * Systems that use the UEFI Console Splitter may
@@ -693,6 +694,7 @@ setup_gop32(struct screen_info *si, efi_guid_t *proto,
 			pixel_format = info->pixel_format;
 			pixel_info = info->pixel_information;
 			pixels_per_scan_line = info->pixels_per_scan_line;
+			fb_base = current_fb_base;
 
 			/*
 			 * Once we've found a GOP supporting ConOut,
@@ -771,6 +773,7 @@ setup_gop64(struct screen_info *si, efi_guid_t *proto,
 		bool conout_found = false;
 		void *dummy = NULL;
 		u64 h = handles[i];
+		u32 current_fb_base;
 
 		status = efi_call_early(handle_protocol, h,
 					proto, (void **)&gop64);
@@ -782,7 +785,7 @@ setup_gop64(struct screen_info *si, efi_guid_t *proto,
 		if (status == EFI_SUCCESS)
 			conout_found = true;
 
-		status = __gop_query64(gop64, &info, &size, &fb_base);
+		status = __gop_query64(gop64, &info, &size, &current_fb_base);
 		if (status == EFI_SUCCESS && (!first_gop || conout_found)) {
 			/*
 			 * Systems that use the UEFI Console Splitter may
@@ -796,6 +799,7 @@ setup_gop64(struct screen_info *si, efi_guid_t *proto,
 			pixel_format = info->pixel_format;
 			pixel_info = info->pixel_information;
 			pixels_per_scan_line = info->pixels_per_scan_line;
+			fb_base = current_fb_base;
 
 			/*
 			 * Once we've found a GOP supporting ConOut,
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268364 — [PATCH 3.19.y-ckt 133/155] bpf: fix panic in SO_GET_FILTER with native ebpf programs

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:30 +0100
Subject[PATCH 3.19.y-ckt 133/155] bpf: fix panic in SO_GET_FILTER with native ebpf programs
Message-ID<qu9ty-71V-81@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <daniel@iogearbox.net>

commit 93d08b6966cf730ea669d4d98f43627597077153 upstream.

When sockets have a native eBPF program attached through
setsockopt(sk, SOL_SOCKET, SO_ATTACH_BPF, ...), and then try to
dump these over getsockopt(sk, SOL_SOCKET, SO_GET_FILTER, ...),
the following panic appears:

  [49904.178642] BUG: unable to handle kernel NULL pointer dereference at (null)
  [49904.178762] IP: [<ffffffff81610fd9>] sk_get_filter+0x39/0x90
  [49904.182000] PGD 86fc9067 PUD 531a1067 PMD 0
  [49904.185196] Oops: 0000 [#1] SMP
  [...]
  [49904.224677] Call Trace:
  [49904.226090]  [<ffffffff815e3d49>] sock_getsockopt+0x319/0x740
  [49904.227535]  [<ffffffff812f59e3>] ? sock_has_perm+0x63/0x70
  [49904.228953]  [<ffffffff815e2fc8>] ? release_sock+0x108/0x150
  [49904.230380]  [<ffffffff812f5a43>] ? selinux_socket_getsockopt+0x23/0x30
  [49904.231788]  [<ffffffff815dff36>] SyS_getsockopt+0xa6/0xc0
  [49904.233267]  [<ffffffff8171b9ae>] entry_SYSCALL_64_fastpath+0x12/0x71

The underlying issue is the very same as in commit b382c0865600
("sock, diag: fix panic in sock_diag_put_filterinfo"), that is,
native eBPF programs don't store an original program since this
is only needed in cBPF ones.

However, sk_get_filter() wasn't updated to test for this at the
time when eBPF could be attached. Just throw an error to the user
to indicate that eBPF cannot be dumped over this interface.
That way, it can also be known that a program _is_ attached (as
opposed to just return 0), and a different (future) method needs
to be consulted for a dump.

Fixes: 89aa075832b0 ("net: sock: allow eBPF programs to be attached to sockets")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Alexei Starovoitov <ast@plumgrid.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/core/filter.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/net/core/filter.c b/net/core/filter.c
index ec9baea..e1d48e4 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -1215,9 +1215,13 @@ int sk_get_filter(struct sock *sk, struct sock_filter __user *ubuf,
 		goto out;
 
 	/* We're copying the filter that has been originally attached,
-	 * so no conversion/decode needed anymore.
+	 * so no conversion/decode needed anymore. eBPF programs that
+	 * have no original program cannot be dumped through this.
 	 */
+	ret = -EACCES;
 	fprog = filter->prog->orig_prog;
+	if (!fprog)
+		goto out;
 
 	ret = fprog->len;
 	if (!len)
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268365 — [PATCH 3.19.y-ckt 101/155] iwlwifi: mvm: fix D3 firmware PN programming

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 101/155] iwlwifi: mvm: fix D3 firmware PN programming
Message-ID<qu9Dc-75u-1@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johannes Berg <johannes.berg@intel.com>

commit 2cf5eb3ab7bb7f2e3a70edcef236cd62c87db030 upstream.

The code to send the RX PN data (for each TID) to the firmware
has a devastating bug: it overwrites the data for TID 0 with
all the TID data, leaving the remaining TIDs zeroed. This will
allow replays to actually be accepted by the firmware, which
could allow waking up the system.

Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Luca Coelho <luciano.coelho@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/wireless/iwlwifi/mvm/d3.c | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/drivers/net/wireless/iwlwifi/mvm/d3.c b/drivers/net/wireless/iwlwifi/mvm/d3.c
index 185ff7b..0586266 100644
--- a/drivers/net/wireless/iwlwifi/mvm/d3.c
+++ b/drivers/net/wireless/iwlwifi/mvm/d3.c
@@ -298,12 +298,12 @@ static void iwl_mvm_wowlan_program_keys(struct ieee80211_hw *hw,
 			u8 *pn = seq.ccmp.pn;
 
 			ieee80211_get_key_rx_seq(key, i, &seq);
-			aes_sc->pn = cpu_to_le64((u64)pn[5] |
-						 ((u64)pn[4] << 8) |
-						 ((u64)pn[3] << 16) |
-						 ((u64)pn[2] << 24) |
-						 ((u64)pn[1] << 32) |
-						 ((u64)pn[0] << 40));
+			aes_sc[i].pn = cpu_to_le64((u64)pn[5] |
+						   ((u64)pn[4] << 8) |
+						   ((u64)pn[3] << 16) |
+						   ((u64)pn[2] << 24) |
+						   ((u64)pn[1] << 32) |
+						   ((u64)pn[0] << 40));
 		}
 		data->use_rsc_tsc = true;
 		break;
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268366 — [PATCH 3.19.y-ckt 092/155] skbuff: Fix skb checksum partial check.

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 092/155] skbuff: Fix skb checksum partial check.
Message-ID<qu9Dc-75u-3@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pravin B Shelar <pshelar@nicira.com>

[ Upstream commit 31b33dfb0a144469dd805514c9e63f4993729a48 ]

Earlier patch 6ae459bda tried to detect void ckecksum partial
skb by comparing pull length to checksum offset. But it does
not work for all cases since checksum-offset depends on
updates to skb->data.

Following patch fixes it by validating checksum start offset
after skb-data pointer is updated. Negative value of checksum
offset start means there is no need to checksum.

Fixes: 6ae459bda ("skbuff: Fix skb checksum flag on skb pull")
Reported-by: Andrew Vagin <avagin@odin.com>
Signed-off-by: Pravin B Shelar <pshelar@nicira.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 include/linux/skbuff.h | 2 +-
 net/core/skbuff.c      | 9 +++++----
 2 files changed, 6 insertions(+), 5 deletions(-)

diff --git a/include/linux/skbuff.h b/include/linux/skbuff.h
index 8271178..b0e064e 100644
--- a/include/linux/skbuff.h
+++ b/include/linux/skbuff.h
@@ -2576,7 +2576,7 @@ static inline void skb_postpull_rcsum(struct sk_buff *skb,
 	if (skb->ip_summed == CHECKSUM_COMPLETE)
 		skb->csum = csum_sub(skb->csum, csum_partial(start, len, 0));
 	else if (skb->ip_summed == CHECKSUM_PARTIAL &&
-		 skb_checksum_start_offset(skb) <= len)
+		 skb_checksum_start_offset(skb) < 0)
 		skb->ip_summed = CHECKSUM_NONE;
 }
 
diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 0998af7..ce3b085 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -2979,11 +2979,12 @@ EXPORT_SYMBOL(skb_append_datato_frags);
  */
 unsigned char *skb_pull_rcsum(struct sk_buff *skb, unsigned int len)
 {
+	unsigned char *data = skb->data;
+
 	BUG_ON(len > skb->len);
-	skb->len -= len;
-	BUG_ON(skb->len < skb->data_len);
-	skb_postpull_rcsum(skb, skb->data, len);
-	return skb->data += len;
+	__skb_pull(skb, len);
+	skb_postpull_rcsum(skb, data, len);
+	return skb->data;
 }
 EXPORT_SYMBOL_GPL(skb_pull_rcsum);
 
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268367 — [PATCH 3.19.y-ckt 118/155] xhci: don't finish a TD if we get a short transfer event mid TD

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 118/155] xhci: don't finish a TD if we get a short transfer event mid TD
Message-ID<qu9Dc-75u-5@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mathias Nyman <mathias.nyman@linux.intel.com>

commit e210c422b6fdd2dc123bedc588f399aefd8bf9de upstream.

If the difference is big enough between the bytes asked and received
in a bulk transfer we can get a short transfer event pointing to a TRB in
the middle of the TD. We don't want to handle the TD yet as we will anyway
receive a new event for the last TRB in the TD.

Hold off from finishing the TD and removing it from the list until we
receive an event for the last TRB in the TD

Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/usb/host/xhci-ring.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/drivers/usb/host/xhci-ring.c b/drivers/usb/host/xhci-ring.c
index 06c247e..66bc627 100644
--- a/drivers/usb/host/xhci-ring.c
+++ b/drivers/usb/host/xhci-ring.c
@@ -2156,6 +2156,10 @@ static int process_bulk_intr_td(struct xhci_hcd *xhci, struct xhci_td *td,
 				EVENT_TRB_LEN(le32_to_cpu(event->transfer_len)));
 	/* Fast path - was this the last TRB in the TD for this URB? */
 	if (event_trb == td->last_trb) {
+		if (td->urb_length_set && trb_comp_code == COMP_SHORT_TX)
+			return finish_td(xhci, td, event_trb, event, ep,
+					 status, false);
+
 		if (EVENT_TRB_LEN(le32_to_cpu(event->transfer_len)) != 0) {
 			td->urb->actual_length =
 				td->urb->transfer_buffer_length -
@@ -2207,6 +2211,12 @@ static int process_bulk_intr_td(struct xhci_hcd *xhci, struct xhci_td *td,
 			td->urb->actual_length +=
 				TRB_LEN(le32_to_cpu(cur_trb->generic.field[2])) -
 				EVENT_TRB_LEN(le32_to_cpu(event->transfer_len));
+
+		if (trb_comp_code == COMP_SHORT_TX) {
+			xhci_dbg(xhci, "mid bulk/intr SP, wait for last TRB event\n");
+			td->urb_length_set = true;
+			return 0;
+		}
 	}
 
 	return finish_td(xhci, td, event_trb, event, ep, status, false);
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268368 — [PATCH 3.19.y-ckt 113/155] drm/i915: Deny wrapping an userptr into a framebuffer

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 113/155] drm/i915: Deny wrapping an userptr into a framebuffer
Message-ID<qu9Dc-75u-7@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chris Wilson <chris@chris-wilson.co.uk>

commit cc917ab43541db3ff66d0136042686d40a1b4c9a upstream.

Pinning a userptr onto the hardware raises interesting questions about
the lifetime of such a surface as the framebuffer extends that life
beyond the client's address space. That is the hardware will need to
keep scanning out from the backing storage even after the client wants
to remap its address space. As the hardware pins the backing storage,
the userptr becomes invalid and this raises a WARN when the clients
tries to unmap its address space. The situation can be even more
complicated when the buffer is passed between processes, between a
client and display server, where the lifetime and hardware access is
even more confusing. Deny it.

Signed-off-by: Chris Wilson <chris@chris-wilson.co.uk>
Cc: Daniel Vetter <daniel.vetter@ffwll.ch>
Cc: Tvrtko Ursulin <tvrtko.ursulin@intel.com>
Cc: Michał Winiarski <michal.winiarski@intel.com>
Reviewed-by: Tvrtko Ursulin <tvrtko.ursulin@intel.com>
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/gpu/drm/i915/i915_gem_userptr.c | 5 ++++-
 drivers/gpu/drm/i915/intel_display.c    | 5 +++++
 2 files changed, 9 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/i915/i915_gem_userptr.c b/drivers/gpu/drm/i915/i915_gem_userptr.c
index 1719078..ce175d0 100644
--- a/drivers/gpu/drm/i915/i915_gem_userptr.c
+++ b/drivers/gpu/drm/i915/i915_gem_userptr.c
@@ -776,7 +776,10 @@ static const struct drm_i915_gem_object_ops i915_gem_userptr_ops = {
  * Also note, that the object created here is not currently a "first class"
  * object, in that several ioctls are banned. These are the CPU access
  * ioctls: mmap(), pwrite and pread. In practice, you are expected to use
- * direct access via your pointer rather than use those ioctls.
+ * direct access via your pointer rather than use those ioctls. Another
+ * restriction is that we do not allow userptr surfaces to be pinned to the
+ * hardware and so we reject any attempt to create a framebuffer out of a
+ * userptr.
  *
  * If you think this is a good interface to use to pass GPU memory between
  * drivers, please use dma-buf instead. In fact, wherever possible use
diff --git a/drivers/gpu/drm/i915/intel_display.c b/drivers/gpu/drm/i915/intel_display.c
index a67dde0..66adee1 100644
--- a/drivers/gpu/drm/i915/intel_display.c
+++ b/drivers/gpu/drm/i915/intel_display.c
@@ -12595,6 +12595,11 @@ static int intel_user_framebuffer_create_handle(struct drm_framebuffer *fb,
 	struct intel_framebuffer *intel_fb = to_intel_framebuffer(fb);
 	struct drm_i915_gem_object *obj = intel_fb->obj;
 
+	if (obj->userptr.mm) {
+		DRM_DEBUG("attempting to use a userptr for a framebuffer, denied\n");
+		return -EINVAL;
+	}
+
 	return drm_gem_handle_create(file, &obj->base, handle);
 }
 
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268369 — [PATCH 3.19.y-ckt 106/155] ARM: orion: Fix DSA platform device after mvmdio conversion

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 106/155] ARM: orion: Fix DSA platform device after mvmdio conversion
Message-ID<qu9Dc-75u-9@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Florian Fainelli <f.fainelli@gmail.com>

commit d836ace65ee98d7079bc3c5afdbcc0e27dca20a3 upstream.

DSA expects the host_dev pointer to be the device structure associated
with the MDIO bus controller driver. First commit breaking that was
c3a07134e6aa ("mv643xx_eth: convert to use the Marvell Orion MDIO
driver"), and then, it got completely under the radar for a while.

Reported-by: Frans van de Wiel <fvdw@fvdw.eu>
Fixes: c3a07134e6aa ("mv643xx_eth: convert to use the Marvell Orion MDIO driver")
Signed-off-by: Florian Fainelli <f.fainelli@gmail.com>
Signed-off-by: Gregory CLEMENT <gregory.clement@free-electrons.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/arm/plat-orion/common.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm/plat-orion/common.c b/arch/arm/plat-orion/common.c
index f5b00f4..b8b6e22 100644
--- a/arch/arm/plat-orion/common.c
+++ b/arch/arm/plat-orion/common.c
@@ -499,7 +499,7 @@ void __init orion_ge00_switch_init(struct dsa_platform_data *d, int irq)
 
 	d->netdev = &orion_ge00.dev;
 	for (i = 0; i < d->nr_chips; i++)
-		d->chip[i].host_dev = &orion_ge00_shared.dev;
+		d->chip[i].host_dev = &orion_ge_mvmdio.dev;
 	orion_switch_device.dev.platform_data = d;
 
 	platform_device_register(&orion_switch_device);
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268370 — [PATCH 3.19.y-ckt 117/155] ASoC: Add info callback for SX_TLV controls

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 117/155] ASoC: Add info callback for SX_TLV controls
Message-ID<qu9Dc-75u-13@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Charles Keepax <ckeepax@opensource.wolfsonmicro.com>

commit 34198710f55b5f359f43e67d9a08fe5aadfbca1b upstream.

SX_TLV controls are intended for situations where the register behind
the control has some non-zero value indicating the minimum gain
and then gains increasing from there and eventually overflowing through
zero.

Currently every CODEC implementing these controls specifies the minimum
as the non-zero value for the minimum and the maximum as the number of
gain settings available.

This means when the info callback subtracts the minimum value from the
maximum value to calculate the number of gain levels available it is
actually under reporting the available levels. This patch fixes this
issue by adding a new snd_soc_info_volsw_sx callback that does not
subtract the minimum value.

Fixes: 1d99f2436d0d ("ASoC: core: Rework SOC_DOUBLE_R_SX_TLV add SOC_SINGLE_SX_TLV")
Signed-off-by: Charles Keepax <ckeepax@opensource.wolfsonmicro.com>
Acked-by: Brian Austin <brian.austin@cirrus.com>
Tested-by: Brian Austin <brian.austin@cirrus.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 include/sound/soc.h |  6 ++++--
 sound/soc/soc-ops.c | 28 ++++++++++++++++++++++++++++
 2 files changed, 32 insertions(+), 2 deletions(-)

diff --git a/include/sound/soc.h b/include/sound/soc.h
index ac8b333..c62fcf8 100644
--- a/include/sound/soc.h
+++ b/include/sound/soc.h
@@ -85,7 +85,7 @@
 	.access = SNDRV_CTL_ELEM_ACCESS_TLV_READ | \
 	SNDRV_CTL_ELEM_ACCESS_READWRITE, \
 	.tlv.p  = (tlv_array),\
-	.info = snd_soc_info_volsw, \
+	.info = snd_soc_info_volsw_sx, \
 	.get = snd_soc_get_volsw_sx,\
 	.put = snd_soc_put_volsw_sx, \
 	.private_value = (unsigned long)&(struct soc_mixer_control) \
@@ -155,7 +155,7 @@
 	.access = SNDRV_CTL_ELEM_ACCESS_TLV_READ | \
 	SNDRV_CTL_ELEM_ACCESS_READWRITE, \
 	.tlv.p  = (tlv_array), \
-	.info = snd_soc_info_volsw, \
+	.info = snd_soc_info_volsw_sx, \
 	.get = snd_soc_get_volsw_sx, \
 	.put = snd_soc_put_volsw_sx, \
 	.private_value = (unsigned long)&(struct soc_mixer_control) \
@@ -546,6 +546,8 @@ int snd_soc_put_enum_double(struct snd_kcontrol *kcontrol,
 	struct snd_ctl_elem_value *ucontrol);
 int snd_soc_info_volsw(struct snd_kcontrol *kcontrol,
 	struct snd_ctl_elem_info *uinfo);
+int snd_soc_info_volsw_sx(struct snd_kcontrol *kcontrol,
+			  struct snd_ctl_elem_info *uinfo);
 #define snd_soc_info_bool_ext		snd_ctl_boolean_mono_info
 int snd_soc_get_volsw(struct snd_kcontrol *kcontrol,
 	struct snd_ctl_elem_value *ucontrol);
diff --git a/sound/soc/soc-ops.c b/sound/soc/soc-ops.c
index 100d92b..05977ae 100644
--- a/sound/soc/soc-ops.c
+++ b/sound/soc/soc-ops.c
@@ -207,6 +207,34 @@ int snd_soc_info_volsw(struct snd_kcontrol *kcontrol,
 EXPORT_SYMBOL_GPL(snd_soc_info_volsw);
 
 /**
+ * snd_soc_info_volsw_sx - Mixer info callback for SX TLV controls
+ * @kcontrol: mixer control
+ * @uinfo: control element information
+ *
+ * Callback to provide information about a single mixer control, or a double
+ * mixer control that spans 2 registers of the SX TLV type. SX TLV controls
+ * have a range that represents both positive and negative values either side
+ * of zero but without a sign bit.
+ *
+ * Returns 0 for success.
+ */
+int snd_soc_info_volsw_sx(struct snd_kcontrol *kcontrol,
+			  struct snd_ctl_elem_info *uinfo)
+{
+	struct soc_mixer_control *mc =
+		(struct soc_mixer_control *)kcontrol->private_value;
+
+	snd_soc_info_volsw(kcontrol, uinfo);
+	/* Max represents the number of levels in an SX control not the
+	 * maximum value, so add the minimum value back on
+	 */
+	uinfo->value.integer.max += mc->min;
+
+	return 0;
+}
+EXPORT_SYMBOL_GPL(snd_soc_info_volsw_sx);
+
+/**
  * snd_soc_get_volsw - single mixer get callback
  * @kcontrol: mixer control
  * @ucontrol: control element information
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268372 — [PATCH 3.19.y-ckt 105/155] iwlwifi: mvm: init card correctly on ctkill exit check

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 105/155] iwlwifi: mvm: init card correctly on ctkill exit check
Message-ID<qu9Dc-75u-17@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arik Nemtsov <arik@wizery.com>

commit 1a3fe0b2b6778b7866e2b3f5c9a299d5e9bbd89c upstream.

During the CT-kill exit flow, the card is powered up and partially
initialized to check if the temperature is already low enough.
Unfortunately the init bails early because the CT-kill flag is set.
Make the code bail early only for HW RF-kill, as was intended by the
author. CT-kill is self-imposed and is not really RF-kill.

Fixes: 31b8b343e019 ("iwlwifi: fix RFkill while calibrating")
Signed-off-by: Arik Nemtsov <arikx.nemtsov@intel.com>
Signed-off-by: Luca Coelho <luciano.coelho@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/wireless/iwlwifi/mvm/fw.c  | 4 ++--
 drivers/net/wireless/iwlwifi/mvm/mvm.h | 5 +++++
 2 files changed, 7 insertions(+), 2 deletions(-)

diff --git a/drivers/net/wireless/iwlwifi/mvm/fw.c b/drivers/net/wireless/iwlwifi/mvm/fw.c
index d0fa6e9..b33d80b 100644
--- a/drivers/net/wireless/iwlwifi/mvm/fw.c
+++ b/drivers/net/wireless/iwlwifi/mvm/fw.c
@@ -335,7 +335,7 @@ int iwl_run_init_mvm_ucode(struct iwl_mvm *mvm, bool read_nvm)
 	 * abort after reading the nvm in case RF Kill is on, we will complete
 	 * the init seq later when RF kill will switch to off
 	 */
-	if (iwl_mvm_is_radio_killed(mvm)) {
+	if (iwl_mvm_is_radio_hw_killed(mvm)) {
 		IWL_DEBUG_RF_KILL(mvm,
 				  "jump over all phy activities due to RF kill\n");
 		iwl_remove_notification(&mvm->notif_wait, &calib_wait);
@@ -370,7 +370,7 @@ int iwl_run_init_mvm_ucode(struct iwl_mvm *mvm, bool read_nvm)
 	if (!ret)
 		mvm->init_ucode_complete = true;
 
-	if (ret && iwl_mvm_is_radio_killed(mvm)) {
+	if (ret && iwl_mvm_is_radio_hw_killed(mvm)) {
 		IWL_DEBUG_RF_KILL(mvm, "RFKILL while calibrating.\n");
 		ret = 1;
 	}
diff --git a/drivers/net/wireless/iwlwifi/mvm/mvm.h b/drivers/net/wireless/iwlwifi/mvm/mvm.h
index a5db114..a17808a 100644
--- a/drivers/net/wireless/iwlwifi/mvm/mvm.h
+++ b/drivers/net/wireless/iwlwifi/mvm/mvm.h
@@ -810,6 +810,11 @@ static inline bool iwl_mvm_is_radio_killed(struct iwl_mvm *mvm)
 	       test_bit(IWL_MVM_STATUS_HW_CTKILL, &mvm->status);
 }
 
+static inline bool iwl_mvm_is_radio_hw_killed(struct iwl_mvm *mvm)
+{
+	return test_bit(IWL_MVM_STATUS_HW_RFKILL, &mvm->status);
+}
+
 /* Must be called with rcu_read_lock() held and it can only be
  * released when mvmsta is not needed anymore.
  */
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268373 — [PATCH 3.19.y-ckt 114/155] iommu/vt-d: fix range computation when making room for large pages

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 114/155] iommu/vt-d: fix range computation when making room for large pages
Message-ID<qu9Dc-75u-19@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Zander <christian@nervanasys.com>

commit ba2374fd2bf379f933773811fdb06cb6a5445f41 upstream.

In preparation for the installation of a large page, any small page
tables that may still exist in the target IOV address range are
removed.  However, if a scatter/gather list entry is large enough to
fit more than one large page, the address space for any subsequent
large pages is not cleared of conflicting small page tables.

This can cause legitimate mapping requests to fail with errors of the
form below, potentially followed by a series of IOMMU faults:

ERROR: DMA PTE for vPFN 0xfde00 already set (to 7f83a4003 not 7e9e00083)

In this example, a 4MiB scatter/gather list entry resulted in the
successful installation of a large page @ vPFN 0xfdc00, followed by
a failed attempt to install another large page @ vPFN 0xfde00, due to
the presence of a pointer to a small page table @ 0x7f83a4000.

To address this problem, compute the number of large pages that fit
into a given scatter/gather list entry, and use it to derive the
last vPFN covered by the large page(s).

Signed-off-by: Christian Zander <christian@nervanasys.com>
Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/iommu/intel-iommu.c | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/drivers/iommu/intel-iommu.c b/drivers/iommu/intel-iommu.c
index 0688303..3583db4 100644
--- a/drivers/iommu/intel-iommu.c
+++ b/drivers/iommu/intel-iommu.c
@@ -2032,15 +2032,19 @@ static int __domain_mapping(struct dmar_domain *domain, unsigned long iov_pfn,
 				return -ENOMEM;
 			/* It is large page*/
 			if (largepage_lvl > 1) {
+				unsigned long nr_superpages, end_pfn;
+
 				pteval |= DMA_PTE_LARGE_PAGE;
 				lvl_pages = lvl_to_nr_pages(largepage_lvl);
+
+				nr_superpages = sg_res / lvl_pages;
+				end_pfn = iov_pfn + nr_superpages * lvl_pages - 1;
+
 				/*
 				 * Ensure that old small page tables are
-				 * removed to make room for superpage,
-				 * if they exist.
+				 * removed to make room for superpage(s).
 				 */
-				dma_pte_free_pagetable(domain, iov_pfn,
-						       iov_pfn + lvl_pages - 1);
+				dma_pte_free_pagetable(domain, iov_pfn, end_pfn);
 			} else {
 				pteval &= ~(uint64_t)DMA_PTE_LARGE_PAGE;
 			}
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268374 — [PATCH 3.19.y-ckt 112/155] drm/i915: Restore lost DPLL register write on gen2-4

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 112/155] drm/i915: Restore lost DPLL register write on gen2-4
Message-ID<qu9Dc-75u-11@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: =?UTF-8?q?Ville=20Syrj=C3=A4l=C3=A4?= <ville.syrjala@linux.intel.com>

commit 8e7a65aa70bcc1235a44e40ae0da5056525fe081 upstream.

We accidentally lost the initial DPLL register write in
1c4e02746147 drm/i915: Fix DVO 2x clock enable on 830M

The "three times for luck" hack probably saved us from a total
disaster. But anyway, bring the initial write back so that the
code actually makes some sense.

Reported-and-tested-by: Nick Bowler <nbowler@draconx.ca>
References: http://mid.gmane.org/CAN_QmVyMaArxYgEcVVsGvsMo7-6ohZr8HmF5VhkkL4i9KOmrhw@mail.gmail.com
Cc: Nick Bowler <nbowler@draconx.ca>
Signed-off-by: Ville Syrjälä <ville.syrjala@linux.intel.com>
Reviewed-by: Daniel Vetter <daniel.vetter@ffwll.ch>
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/gpu/drm/i915/intel_display.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/gpu/drm/i915/intel_display.c b/drivers/gpu/drm/i915/intel_display.c
index ada0210..a67dde0 100644
--- a/drivers/gpu/drm/i915/intel_display.c
+++ b/drivers/gpu/drm/i915/intel_display.c
@@ -1623,6 +1623,8 @@ static void i9xx_enable_pll(struct intel_crtc *crtc)
 			   I915_READ(DPLL(!crtc->pipe)) | DPLL_DVO_2X_MODE);
 	}
 
+	I915_WRITE(reg, dpll);
+
 	/* Wait for the clocks to stabilize. */
 	POSTING_READ(reg);
 	udelay(150);
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268375 — [PATCH 3.19.y-ckt 096/155] ethtool: Use kcalloc instead of kmalloc for ethtool_get_strings

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 096/155] ethtool: Use kcalloc instead of kmalloc for ethtool_get_strings
Message-ID<qu9Dc-75u-21@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joe Perches <joe@perches.com>

[ Upstream commit 077cb37fcf6f00a45f375161200b5ee0cd4e937b ]

It seems that kernel memory can leak into userspace by a
kmalloc, ethtool_get_strings, then copy_to_user sequence.

Avoid this by using kcalloc to zero fill the copied buffer.

Signed-off-by: Joe Perches <joe@perches.com>
Acked-by: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/core/ethtool.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/core/ethtool.c b/net/core/ethtool.c
index 550892c..0a62917 100644
--- a/net/core/ethtool.c
+++ b/net/core/ethtool.c
@@ -1272,7 +1272,7 @@ static int ethtool_get_strings(struct net_device *dev, void __user *useraddr)
 
 	gstrings.len = ret;
 
-	data = kmalloc(gstrings.len * ETH_GSTRING_LEN, GFP_USER);
+	data = kcalloc(gstrings.len, ETH_GSTRING_LEN, GFP_USER);
 	if (!data)
 		return -ENOMEM;
 
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268376 — [PATCH 3.19.y-ckt 108/155] iio: mxs-lradc: Fix temperature offset

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 108/155] iio: mxs-lradc: Fix temperature offset
Message-ID<qu9Dc-75u-25@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alexandre Belloni <alexandre.belloni@free-electrons.com>

commit b94e22805a2224061bb263a82b72e09544a5fbb3 upstream.

0° Kelvin is actually −273.15°C, not -272.15°C. Fix the temperature offset.
Also improve the comment explaining the calculation.

Reported-by: Janusz Użycki <j.uzycki@elpromaelectronics.com>
Signed-off-by: Alexandre Belloni <alexandre.belloni@free-electrons.com>
Acked-by: Stefan Wahren <stefan.wahren@i2se.com>
Acked-by: Marek Vasut <marex@denx.de>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/staging/iio/adc/mxs-lradc.c | 9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

diff --git a/drivers/staging/iio/adc/mxs-lradc.c b/drivers/staging/iio/adc/mxs-lradc.c
index 351339c..3b9859b 100644
--- a/drivers/staging/iio/adc/mxs-lradc.c
+++ b/drivers/staging/iio/adc/mxs-lradc.c
@@ -912,11 +912,12 @@ static int mxs_lradc_read_raw(struct iio_dev *iio_dev,
 	case IIO_CHAN_INFO_OFFSET:
 		if (chan->type == IIO_TEMP) {
 			/* The calculated value from the ADC is in Kelvin, we
-			 * want Celsius for hwmon so the offset is
-			 * -272.15 * scale
+			 * want Celsius for hwmon so the offset is -273.15
+			 * The offset is applied before scaling so it is
+			 * actually -213.15 * 4 / 1.012 = -1079.644268
 			 */
-			*val = -1075;
-			*val2 = 691699;
+			*val = -1079;
+			*val2 = 644268;
 
 			return IIO_VAL_INT_PLUS_MICRO;
 		}
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268377 — [PATCH 3.19.y-ckt 107/155] xen-blkfront: check for null drvdata in blkback_changed (XenbusStateClosing)

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 107/155] xen-blkfront: check for null drvdata in blkback_changed (XenbusStateClosing)
Message-ID<qu9Dd-75u-27@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cathy Avery <cathy.avery@oracle.com>

commit a54c8f0f2d7df525ff997e2afe71866a1a013064 upstream.

xen-blkfront will crash if the check to talk_to_blkback()
in blkback_changed()(XenbusStateInitWait) returns an error.
The driver data is freed and info is set to NULL. Later during
the close process via talk_to_blkback's call to xenbus_dev_fatal()
the null pointer is passed to and dereference in blkfront_closing.

Signed-off-by: Cathy Avery <cathy.avery@oracle.com>
Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/block/xen-blkfront.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/block/xen-blkfront.c b/drivers/block/xen-blkfront.c
index 7afb9ed..6259acc 100644
--- a/drivers/block/xen-blkfront.c
+++ b/drivers/block/xen-blkfront.c
@@ -1924,7 +1924,8 @@ static void blkback_changed(struct xenbus_device *dev,
 			break;
 		/* Missed the backend's Closing state -- fallthrough */
 	case XenbusStateClosing:
-		blkfront_closing(info);
+		if (info)
+			blkfront_closing(info);
 		break;
 	}
 }
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268378 — [PATCH 3.19.y-ckt 103/155] iwlwifi: fix firmware filename for 3160

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 103/155] iwlwifi: fix firmware filename for 3160
Message-ID<qu9Dd-75u-29@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johannes Berg <johannes.berg@intel.com>

commit b5a48134f8af08f5243328f8a0b05fc5ae7cf343 upstream.

The MODULE_FIRMWARE() for 3160 should be using the 7260 version as
it's done in the device configuration struct instead of referencing
IWL3160_UCODE_API_OK which doesn't even exist.

Reported-by: Hauke Mehrtens <hauke@hauke-m.de>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Luca Coelho <luciano.coelho@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/wireless/iwlwifi/iwl-7000.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/wireless/iwlwifi/iwl-7000.c b/drivers/net/wireless/iwlwifi/iwl-7000.c
index a5f9198..b5651a2 100644
--- a/drivers/net/wireless/iwlwifi/iwl-7000.c
+++ b/drivers/net/wireless/iwlwifi/iwl-7000.c
@@ -303,7 +303,7 @@ const struct iwl_cfg iwl7265d_n_cfg = {
 };
 
 MODULE_FIRMWARE(IWL7260_MODULE_FIRMWARE(IWL7260_UCODE_API_OK));
-MODULE_FIRMWARE(IWL3160_MODULE_FIRMWARE(IWL3160_UCODE_API_OK));
+MODULE_FIRMWARE(IWL3160_MODULE_FIRMWARE(IWL7260_UCODE_API_OK));
 MODULE_FIRMWARE(IWL3165_MODULE_FIRMWARE(IWL3160_UCODE_API_OK));
 MODULE_FIRMWARE(IWL7265_MODULE_FIRMWARE(IWL7260_UCODE_API_OK));
 MODULE_FIRMWARE(IWL7265D_MODULE_FIRMWARE(IWL7260_UCODE_API_OK));
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268379 — [PATCH 3.19.y-ckt 090/155] net/unix: fix logic about sk_peek_offset

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 090/155] net/unix: fix logic about sk_peek_offset
Message-ID<qu9Dd-75u-39@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Andrey Vagin <avagin@openvz.org>

[ Upstream commit e9193d60d363e4dff75ff6d43a48f22be26d59c7 ]

Now send with MSG_PEEK can return data from multiple SKBs.

Unfortunately we take into account the peek offset for each skb,
that is wrong. We need to apply the peek offset only once.

In addition, the peek offset should be used only if MSG_PEEK is set.

Cc: "David S. Miller" <davem@davemloft.net> (maintainer:NETWORKING
Cc: Eric Dumazet <edumazet@google.com> (commit_signer:1/14=7%)
Cc: Aaron Conole <aconole@bytheb.org>
Fixes: 9f389e35674f ("af_unix: return data from multiple SKBs on recv() with MSG_PEEK flag")
Signed-off-by: Andrey Vagin <avagin@openvz.org>
Tested-by: Aaron Conole <aconole@bytheb.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/unix/af_unix.c | 12 +++++++-----
 1 file changed, 7 insertions(+), 5 deletions(-)

diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
index ca5fa61..6fab713 100644
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -1961,6 +1961,11 @@ static int unix_stream_recvmsg(struct kiocb *iocb, struct socket *sock,
 		goto out;
 	}
 
+	if (flags & MSG_PEEK)
+		skip = sk_peek_offset(sk, flags);
+	else
+		skip = 0;
+
 	do {
 		int chunk;
 		struct sk_buff *skb, *last;
@@ -2007,7 +2012,6 @@ again:
 			break;
 		}
 
-		skip = sk_peek_offset(sk, flags);
 		while (skip >= unix_skb_len(skb)) {
 			skip -= unix_skb_len(skb);
 			last = skb;
@@ -2069,14 +2073,12 @@ again:
 			if (UNIXCB(skb).fp)
 				siocb->scm->fp = scm_fp_dup(UNIXCB(skb).fp);
 
-			if (skip) {
-				sk_peek_offset_fwd(sk, chunk);
-				skip -= chunk;
-			}
+			sk_peek_offset_fwd(sk, chunk);
 
 			if (UNIXCB(skb).fp)
 				break;
 
+			skip = 0;
 			last = skb;
 			unix_state_lock(sk);
 			skb = skb_peek_next(skb, &sk->sk_receive_queue);
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268381 — [PATCH 3.19.y-ckt 110/155] ALSA: hda - Fix inverted internal mic on Lenovo G50-80

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 110/155] ALSA: hda - Fix inverted internal mic on Lenovo G50-80
Message-ID<qu9Dd-75u-35@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Henningsson <david.henningsson@canonical.com>

commit e8d65a8d985271a102f07c7456da5b86c19ffe16 upstream.

Add the appropriate quirk to indicate the Lenovo G50-80 has a stereo
mic input where one channel has reverse polarity.

Alsa-info available at:
https://launchpadlibrarian.net/220846272/AlsaInfo.txt

BugLink: https://bugs.launchpad.net/bugs/1504778
Signed-off-by: David Henningsson <david.henningsson@canonical.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/pci/hda/patch_conexant.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/pci/hda/patch_conexant.c b/sound/pci/hda/patch_conexant.c
index e27298b..7085fb9 100644
--- a/sound/pci/hda/patch_conexant.c
+++ b/sound/pci/hda/patch_conexant.c
@@ -803,6 +803,7 @@ static const struct snd_pci_quirk cxt5066_fixups[] = {
 	SND_PCI_QUIRK(0x17aa, 0x21da, "Lenovo X220", CXT_PINCFG_LENOVO_TP410),
 	SND_PCI_QUIRK(0x17aa, 0x21db, "Lenovo X220-tablet", CXT_PINCFG_LENOVO_TP410),
 	SND_PCI_QUIRK(0x17aa, 0x38af, "Lenovo IdeaPad Z560", CXT_FIXUP_MUTE_LED_EAPD),
+	SND_PCI_QUIRK(0x17aa, 0x390b, "Lenovo G50-80", CXT_FIXUP_STEREO_DMIC),
 	SND_PCI_QUIRK(0x17aa, 0x3975, "Lenovo U300s", CXT_FIXUP_STEREO_DMIC),
 	SND_PCI_QUIRK(0x17aa, 0x3977, "Lenovo IdeaPad U310", CXT_FIXUP_STEREO_DMIC),
 	SND_PCI_QUIRK(0x17aa, 0x397b, "Lenovo S205", CXT_FIXUP_STEREO_DMIC),
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268382 — [PATCH 3.19.y-ckt 098/155] ath9k: declare required extra tx headroom

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 098/155] ath9k: declare required extra tx headroom
Message-ID<qu9Dd-75u-41@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Fietkau <nbd@openwrt.org>

commit 029cd0370241641eb70235d205aa0b90c84dce44 upstream.

ath9k inserts padding between the 802.11 header and the data area (to
align it). Since it didn't declare this extra required headroom, this
led to some nasty issues like randomly dropped packets in some setups.

Signed-off-by: Felix Fietkau <nbd@openwrt.org>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/wireless/ath/ath9k/init.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/net/wireless/ath/ath9k/init.c b/drivers/net/wireless/ath/ath9k/init.c
index d1c3934..82d4f0a 100644
--- a/drivers/net/wireless/ath/ath9k/init.c
+++ b/drivers/net/wireless/ath/ath9k/init.c
@@ -855,6 +855,7 @@ static void ath9k_set_hw_capab(struct ath_softc *sc, struct ieee80211_hw *hw)
 	hw->max_rate_tries = 10;
 	hw->sta_data_size = sizeof(struct ath_node);
 	hw->vif_data_size = sizeof(struct ath_vif);
+	hw->extra_tx_headroom = 4;
 
 	hw->wiphy->available_antennas_rx = BIT(ah->caps.max_rxchains) - 1;
 	hw->wiphy->available_antennas_tx = BIT(ah->caps.max_txchains) - 1;
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268383 — [PATCH 3.19.y-ckt 022/155] x86/efi: Fix boot crash by mapping EFI memmap entries bottom-up at runtime, instead of top-down

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 022/155] x86/efi: Fix boot crash by mapping EFI memmap entries bottom-up at runtime, instead of top-down
Message-ID<qu9Dd-75u-37@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matt Fleming <matt.fleming@intel.com>

commit a5caa209ba9c29c6421292e7879d2387a2ef39c9 upstream.

Beginning with UEFI v2.5 EFI_PROPERTIES_TABLE was introduced
that signals that the firmware PE/COFF loader supports splitting
code and data sections of PE/COFF images into separate EFI
memory map entries. This allows the kernel to map those regions
with strict memory protections, e.g. EFI_MEMORY_RO for code,
EFI_MEMORY_XP for data, etc.

Unfortunately, an unwritten requirement of this new feature is
that the regions need to be mapped with the same offsets
relative to each other as observed in the EFI memory map. If
this is not done crashes like this may occur,

  BUG: unable to handle kernel paging request at fffffffefe6086dd
  IP: [<fffffffefe6086dd>] 0xfffffffefe6086dd
  Call Trace:
   [<ffffffff8104c90e>] efi_call+0x7e/0x100
   [<ffffffff81602091>] ? virt_efi_set_variable+0x61/0x90
   [<ffffffff8104c583>] efi_delete_dummy_variable+0x63/0x70
   [<ffffffff81f4e4aa>] efi_enter_virtual_mode+0x383/0x392
   [<ffffffff81f37e1b>] start_kernel+0x38a/0x417
   [<ffffffff81f37495>] x86_64_start_reservations+0x2a/0x2c
   [<ffffffff81f37582>] x86_64_start_kernel+0xeb/0xef

Here 0xfffffffefe6086dd refers to an address the firmware
expects to be mapped but which the OS never claimed was mapped.
The issue is that included in these regions are relative
addresses to other regions which were emitted by the firmware
toolchain before the "splitting" of sections occurred at
runtime.

Needless to say, we don't satisfy this unwritten requirement on
x86_64 and instead map the EFI memory map entries in reverse
order. The above crash is almost certainly triggerable with any
kernel newer than v3.13 because that's when we rewrote the EFI
runtime region mapping code, in commit d2f7cbe7b26a ("x86/efi:
Runtime services virtual mapping"). For kernel versions before
v3.13 things may work by pure luck depending on the
fragmentation of the kernel virtual address space at the time we
map the EFI regions.

Instead of mapping the EFI memory map entries in reverse order,
where entry N has a higher virtual address than entry N+1, map
them in the same order as they appear in the EFI memory map to
preserve this relative offset between regions.

This patch has been kept as small as possible with the intention
that it should be applied aggressively to stable and
distribution kernels. It is very much a bugfix rather than
support for a new feature, since when EFI_PROPERTIES_TABLE is
enabled we must map things as outlined above to even boot - we
have no way of asking the firmware not to split the code/data
regions.

In fact, this patch doesn't even make use of the more strict
memory protections available in UEFI v2.5. That will come later.

Suggested-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Reported-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Matt Fleming <matt.fleming@intel.com>
Cc: Borislav Petkov <bp@suse.de>
Cc: Chun-Yi <jlee@suse.com>
Cc: Dave Young <dyoung@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: James Bottomley <JBottomley@Odin.com>
Cc: Lee, Chun-Yi <jlee@suse.com>
Cc: Leif Lindholm <leif.lindholm@linaro.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Matthew Garrett <mjg59@srcf.ucam.org>
Cc: Mike Galbraith <efault@gmx.de>
Cc: Peter Jones <pjones@redhat.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: linux-kernel@vger.kernel.org
Link: http://lkml.kernel.org/r/1443218539-7610-2-git-send-email-matt@codeblueprint.co.uk
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/x86/platform/efi/efi.c | 67 ++++++++++++++++++++++++++++++++++++++++++++-
 1 file changed, 66 insertions(+), 1 deletion(-)

diff --git a/arch/x86/platform/efi/efi.c b/arch/x86/platform/efi/efi.c
index e752f79..c61bdec 100644
--- a/arch/x86/platform/efi/efi.c
+++ b/arch/x86/platform/efi/efi.c
@@ -670,6 +670,70 @@ out:
 }
 
 /*
+ * Iterate the EFI memory map in reverse order because the regions
+ * will be mapped top-down. The end result is the same as if we had
+ * mapped things forward, but doesn't require us to change the
+ * existing implementation of efi_map_region().
+ */
+static inline void *efi_map_next_entry_reverse(void *entry)
+{
+	/* Initial call */
+	if (!entry)
+		return memmap.map_end - memmap.desc_size;
+
+	entry -= memmap.desc_size;
+	if (entry < memmap.map)
+		return NULL;
+
+	return entry;
+}
+
+/*
+ * efi_map_next_entry - Return the next EFI memory map descriptor
+ * @entry: Previous EFI memory map descriptor
+ *
+ * This is a helper function to iterate over the EFI memory map, which
+ * we do in different orders depending on the current configuration.
+ *
+ * To begin traversing the memory map @entry must be %NULL.
+ *
+ * Returns %NULL when we reach the end of the memory map.
+ */
+static void *efi_map_next_entry(void *entry)
+{
+	if (!efi_enabled(EFI_OLD_MEMMAP) && efi_enabled(EFI_64BIT)) {
+		/*
+		 * Starting in UEFI v2.5 the EFI_PROPERTIES_TABLE
+		 * config table feature requires us to map all entries
+		 * in the same order as they appear in the EFI memory
+		 * map. That is to say, entry N must have a lower
+		 * virtual address than entry N+1. This is because the
+		 * firmware toolchain leaves relative references in
+		 * the code/data sections, which are split and become
+		 * separate EFI memory regions. Mapping things
+		 * out-of-order leads to the firmware accessing
+		 * unmapped addresses.
+		 *
+		 * Since we need to map things this way whether or not
+		 * the kernel actually makes use of
+		 * EFI_PROPERTIES_TABLE, let's just switch to this
+		 * scheme by default for 64-bit.
+		 */
+		return efi_map_next_entry_reverse(entry);
+	}
+
+	/* Initial call */
+	if (!entry)
+		return memmap.map;
+
+	entry += memmap.desc_size;
+	if (entry >= memmap.map_end)
+		return NULL;
+
+	return entry;
+}
+
+/*
  * Map the efi memory ranges of the runtime services and update new_mmap with
  * virtual addresses.
  */
@@ -679,7 +743,8 @@ static void * __init efi_map_regions(int *count, int *pg_shift)
 	unsigned long left = 0;
 	efi_memory_desc_t *md;
 
-	for (p = memmap.map; p < memmap.map_end; p += memmap.desc_size) {
+	p = NULL;
+	while ((p = efi_map_next_entry(p))) {
 		md = p;
 		if (!(md->attribute & EFI_MEMORY_RUNTIME)) {
 #ifdef CONFIG_X86_64
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1268384 — [PATCH 3.19.y-ckt 097/155] netlink: Trim skb to alloc size to avoid MSG_TRUNC

FromKamal Mostafa <kamal@canonical.com>
Date2015-11-13 00:40 +0100
Subject[PATCH 3.19.y-ckt 097/155] netlink: Trim skb to alloc size to avoid MSG_TRUNC
Message-ID<qu9Dd-75u-43@gated-at.bofh.it>
In reply to#1268321
3.19.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: "Arad, Ronen" <ronen.arad@intel.com>

[ Upstream commit db65a3aaf29ecce2e34271d52e8d2336b97bd9fe ]

netlink_dump() allocates skb based on the calculated min_dump_alloc or
a per socket max_recvmsg_len.
min_alloc_size is maximum space required for any single netdev
attributes as calculated by rtnl_calcit().
max_recvmsg_len tracks the user provided buffer to netlink_recvmsg.
It is capped at 16KiB.
The intention is to avoid small allocations and to minimize the number
of calls required to obtain dump information for all net devices.

netlink_dump packs as many small messages as could fit within an skb
that was sized for the largest single netdev information. The actual
space available within an skb is larger than what is requested. It could
be much larger and up to near 2x with align to next power of 2 approach.

Allowing netlink_dump to use all the space available within the
allocated skb increases the buffer size a user has to provide to avoid
truncaion (i.e. MSG_TRUNG flag set).

It was observed that with many VLANs configured on at least one netdev,
a larger buffer of near 64KiB was necessary to avoid "Message truncated"
error in "ip link" or "bridge [-c[ompressvlans]] vlan show" when
min_alloc_size was only little over 32KiB.

This patch trims skb to allocated size in order to allow the user to
avoid truncation with more reasonable buffer size.

Signed-off-by: Ronen Arad <ronen.arad@intel.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/netlink/af_netlink.c | 34 ++++++++++++++++++++++------------
 1 file changed, 22 insertions(+), 12 deletions(-)

diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c
index 4e37b2a..d78848d 100644
--- a/net/netlink/af_netlink.c
+++ b/net/netlink/af_netlink.c
@@ -2657,6 +2657,7 @@ static int netlink_dump(struct sock *sk)
 	struct sk_buff *skb = NULL;
 	struct nlmsghdr *nlh;
 	int len, err = -ENOBUFS;
+	int alloc_min_size;
 	int alloc_size;
 
 	mutex_lock(nlk->cb_mutex);
@@ -2665,9 +2666,6 @@ static int netlink_dump(struct sock *sk)
 		goto errout_skb;
 	}
 
-	cb = &nlk->cb;
-	alloc_size = max_t(int, cb->min_dump_alloc, NLMSG_GOODSIZE);
-
 	if (!netlink_rx_is_mmaped(sk) &&
 	    atomic_read(&sk->sk_rmem_alloc) >= sk->sk_rcvbuf)
 		goto errout_skb;
@@ -2677,23 +2675,35 @@ static int netlink_dump(struct sock *sk)
 	 * to reduce number of system calls on dump operations, if user
 	 * ever provided a big enough buffer.
 	 */
-	if (alloc_size < nlk->max_recvmsg_len) {
-		skb = netlink_alloc_skb(sk,
-					nlk->max_recvmsg_len,
-					nlk->portid,
+	cb = &nlk->cb;
+	alloc_min_size = max_t(int, cb->min_dump_alloc, NLMSG_GOODSIZE);
+
+	if (alloc_min_size < nlk->max_recvmsg_len) {
+		alloc_size = nlk->max_recvmsg_len;
+		skb = netlink_alloc_skb(sk, alloc_size, nlk->portid,
 					GFP_KERNEL |
 					__GFP_NOWARN |
 					__GFP_NORETRY);
-		/* available room should be exact amount to avoid MSG_TRUNC */
-		if (skb)
-			skb_reserve(skb, skb_tailroom(skb) -
-					 nlk->max_recvmsg_len);
 	}
-	if (!skb)
+	if (!skb) {
+		alloc_size = alloc_min_size;
 		skb = netlink_alloc_skb(sk, alloc_size, nlk->portid,
 					GFP_KERNEL);
+	}
 	if (!skb)
 		goto errout_skb;
+
+	/* Trim skb to allocated size. User is expected to provide buffer as
+	 * large as max(min_dump_alloc, 16KiB (mac_recvmsg_len capped at
+	 * netlink_recvmsg())). dump will pack as many smaller messages as
+	 * could fit within the allocated skb. skb is typically allocated
+	 * with larger space than required (could be as much as near 2x the
+	 * requested size with align to next power of 2 approach). Allowing
+	 * dump to use the excess space makes it difficult for a user to have a
+	 * reasonable static buffer based on the expected largest dump of a
+	 * single netdev. The outcome is MSG_TRUNC error.
+	 */
+	skb_reserve(skb, skb_tailroom(skb) - alloc_size);
 	netlink_skb_set_owner_r(skb, sk);
 
 	len = cb->dump(skb, cb);
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


Page 3 of 9 — ← Prev page 1 2 [3] 4 5 6 7 8 9  Next page →

Back to top | Article view | linux.kernel


csiph-web