Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1329762 > unrolled thread

[PATCH 3.2 00/87] 3.2.77-rc1 review

Started byBen Hutchings <ben@decadent.org.uk>
First post2016-02-09 01:20 +0100
Last post2016-02-10 02:10 +0100
Articles 20 on this page of 34 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.2 00/87] 3.2.77-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:20 +0100
    [PATCH 3.2 79/87] crypto: af_alg - Forbid bind(2) when nokey  child sockets are present Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:20 +0100
    [PATCH 3.2 17/87] asix: silence log message from oversize packet Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:20 +0100
    [PATCH 3.2 73/87] crypto: algif_hash - Require setkey before  accept(2) Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:20 +0100
    [PATCH 3.2 18/87] futex: Drop refcount if requeue_pi() acquired  the rtmutex Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:20 +0100
    [PATCH 3.2 60/87] crypto: af_alg - Fix socket double-free when  accept fails Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:20 +0100
    [PATCH 3.2 72/87] crypto: hash - Add crypto_ahash_has_setkey Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:20 +0100
    [PATCH 3.2 70/87] crypto: af_alg - Add nokey compatibility path Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:20 +0100
    [PATCH 3.2 57/87] ALSA: timer: Harden slave timer list handling Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:20 +0100
    [PATCH 3.2 61/87] ALSA: hrtimer: Fix stall by hrtimer_cancel() Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:20 +0100
    [PATCH 3.2 82/87] crypto: algif_skcipher - Load TX SG list after  waiting Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:20 +0100
    [PATCH 3.2 11/87] rtlwifi: fix memory leak for USB device Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:20 +0100
    [PATCH 3.2 64/87] ALSA: control: Avoid kernel warnings from tlv  ioctl with numid 0 Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:20 +0100
    [PATCH 3.2 01/87] [media] gspca: ov534/topro: prevent a division by 0 Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:20 +0100
    [PATCH 3.2 08/87] mtd: nand: fix ONFI parameter page layout Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 80/87] crypto: algif_hash - Fix race condition in  hash_check_key Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 04/87] SCSI: initio: remove duplicate module device table Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 87/87] [media] usbvision: fix crash on detecting  device with invalid configuration Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 15/87] powerpc: Make value-returning atomics fully ordered Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 10/87] xhci: refuse loading if nousb is used Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 05/87] KVM: x86: expose MSR_TSC_AUX to userspace Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 86/87] [media] usbvision fix overflow of interfaces array Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 85/87] [media] usbvision: fix leak of usb_dev on  failure paths in  usbvision_probe() Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 07/87] ath9k_htc: check for underflow in  ath9k_htc_rx_msg() Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 13/87] wlcore/wl12xx: spi: fix oops on firmware load Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 14/87] EDAC: Robustify workqueues destruction Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 19/87] ALSA: fm801: propagate TUNER_ONLY bit when  autodetected Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 84/87] [media] usbvision-video: fix memory leak of  alt_max_pkt_size Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 12/87] wlcore: SPI - fix spi transfer_list Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 16/87] powerpc: Make {cmp}xchg* and their atomic_  versions fully ordered Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 78/87] crypto: algif_skcipher - Remove custom release  parent function Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    [PATCH 3.2 03/87] [media] rc: allow rc modules to be loaded if  rc-main is not a module Ben Hutchings <ben@decadent.org.uk> - 2016-02-09 01:30 +0100
    Re: [PATCH 3.2 00/87] 3.2.77-rc1 review Guenter Roeck <linux@roeck-us.net> - 2016-02-09 05:00 +0100
      Re: [PATCH 3.2 00/87] 3.2.77-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2016-02-10 02:10 +0100

Page 1 of 2  [1] 2  Next page →


#1329762 — [PATCH 3.2 00/87] 3.2.77-rc1 review

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:20 +0100
Subject[PATCH 3.2 00/87] 3.2.77-rc1 review
Message-ID<r03SN-3V2-7@gated-at.bofh.it>
This is the start of the stable review cycle for the 3.2.77 release.
There are 87 patches in this series, which will be posted as responses
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Wed Feb 10 23:53:50 UTC 2016.
Anything received after that time might be too late.

A combined patch relative to 3.2.76 will be posted as an additional
response to this.  A shortlog and diffstat can be found below.

Ben.

-------------

Aaron Conole (1):
      printk: help pr_debug and pr_devel to optimize out arguments
         [fe22cd9b7c980b8b948ec85f034a8668c57ec867]

Alex Deucher (2):
      drm/radeon: call hpd_irq_event on resume
         [dbb17a21c131eca94eb31136eee9a7fe5aff00d9]
      drm/radeon: clean up fujitsu quirks
         [0eb1c3d4084eeb6fb3a703f88d6ce1521f8fcdd1]

Alexey Khoroshilov (2):
      [media] usbvision-video: fix memory leak of alt_max_pkt_size
         [090c65b694c362adb19ec9c27de216a808ee443c]
      [media] usbvision: fix leak of usb_dev on failure paths in  usbvision_probe()
         [afd270d1a45043cef14341bcceff62ed50e8dc9a]

Andrew Gabbasov (2):
      udf: Check output buffer length when converting name to CS0
         [bb00c898ad1ce40c4bb422a8207ae562e9aea7ae]
      udf: Prevent buffer overrun with multi-byte characters
         [ad402b265ecf6fa22d04043b41444cdfcdf4f52d]

Andy Lutomirski (2):
      x86/mm: Add barriers and document switch_mm()-vs-flush synchronization
         [71b3c126e61177eb693423f2e18a1914205b165e]
      x86/mm: Improve switch_mm() barrier comments
         [4eaffdd5a5fe6ff9f95e1ab4de1ac904d5e0fa8b]

Andy Shevchenko (1):
      ALSA: fm801: propagate TUNER_ONLY bit when autodetected
         [dbec6719ac036f68568d8488805d41346c021eff]

Antonio Ospite (1):
      [media] gspca: ov534/topro: prevent a division by 0
         [dcc7fdbec53a960588f2c40232db2c6466c09917]

Arnd Bergmann (1):
      SCSI: initio: remove duplicate module device table
         [d282e2b383e3f41a7758e8cbf3076091ef9d9447]

Aurélien Francillon (1):
      Input: i8042 - add Fujitsu Lifebook U745 to the nomux list
         [dd0d0d4de582a6a61c032332c91f4f4cb2bab569]

Boqun Feng (2):
      powerpc: Make value-returning atomics fully ordered
         [49e9cf3f0c04bf76ffa59242254110309554861d]
      powerpc: Make {cmp}xchg* and their atomic_ versions fully ordered
         [81d7a3294de7e9828310bbf986a67246b13fa01e]

Boris BREZILLON (1):
      mtd: nand: fix ONFI parameter page layout
         [de64aa9ec129ba627634088f662a4d09e356ddb6]

Borislav Petkov (1):
      EDAC: Robustify workqueues destruction
         [fcd5c4dd8201595d4c598c9cca5e54760277d687]

Dan Carpenter (1):
      ath9k_htc: check for underflow in ath9k_htc_rx_msg()
         [3a318426e09a9c9266fe6440842e11238f640a20]

Dmitry V. Levin (1):
      sparc64: fix incorrect sign extension in sys_sparc64_personality
         [525fd5a94e1be0776fa652df5c687697db508c91]

Eric Dumazet (1):
      ipv6: tcp: add rcu locking in tcp_v6_send_synack()
         [3e4006f0b86a5ae5eb0e8215f9a9e1db24506977]

H.J. Lu (1):
      x86/boot: Double BOOT_HEAP_SIZE to 64KB
         [8c31902cffc4d716450be549c66a67a8a3dd479c]

Helge Deller (1):
      parisc: Fix __ARCH_SI_PREAMBLE_SIZE
         [e60fc5aa608eb38b47ba4ee058f306f739eb70a0]

Herbert Xu (16):
      crypto: af_alg - Add nokey compatibility path
         [37766586c965d63758ad542325a96d5384f4a8c9]
      crypto: af_alg - Allow af_af_alg_release_parent to be called on nokey path
         [6a935170a980024dd29199e9dbb5c4da4767a1b9]
      crypto: af_alg - Disallow bind/setkey/... after accept(2)
         [c840ac6af3f8713a71b4d2363419145760bd6044]
      crypto: af_alg - Fix socket double-free when accept fails
         [a383292c86663bbc31ac62cc0c04fc77504636a6]
      crypto: af_alg - Forbid bind(2) when nokey child sockets are present
         [a6a48c565f6f112c6983e2a02b1602189ed6e26e]
      crypto: algif_hash - Fix race condition in hash_check_key
         [ad46d7e33219218605ea619e32553daf4f346b9f]
      crypto: algif_hash - Remove custom release parent function
         [f1d84af1835846a5a2b827382c5848faf2bb0e75]
      crypto: algif_hash - Require setkey before accept(2)
         [6de62f15b581f920ade22d758f4c338311c2f0d4]
      crypto: algif_skcipher - Add key check exception for cipher_null
         [6e8d8ecf438792ecf7a3207488fb4eebc4edb040]
      crypto: algif_skcipher - Add nokey compatibility path
         [a0fa2d037129a9849918a92d91b79ed6c7bd2818]
      crypto: algif_skcipher - Fix race condition in skcipher_check_key
         [1822793a523e5d5730b19cc21160ff1717421bc8]
      crypto: algif_skcipher - Load TX SG list after waiting
         [4f0414e54e4d1893c6f08260693f8ef84c929293]
      crypto: algif_skcipher - Remove custom release parent function
         [d7b65aee1e7b4c87922b0232eaba56a8a143a4a0]
      crypto: algif_skcipher - Require setkey before accept(2)
         [dd504589577d8e8e70f51f997ad487a4cb6c026f]
      crypto: hash - Add crypto_ahash_has_setkey
         [a5596d6332787fd383b3b5427b41f94254430827]
      crypto: skcipher - Add crypto_skcipher_has_setkey
         [a1383cd86a062fc798899ab20f0ec2116cce39cb]

Jamie Bainbridge (1):
      cifs: Ratelimit kernel log messages
         [ec7147a99e33a9e4abad6fc6e1b40d15df045d53]

Jan Beulich (1):
      x86/LDT: Print the real LDT base address
         [0d430e3fb3f7cdc13c0d22078b820f682821b45a]

Janusz.Dziedzic@tieto.com (1):
      wlcore: SPI - fix spi transfer_list
         [4eeac22c159f053ea34527e4fea359ab10b4b5a5]

Jeff Layton (1):
      locks: fix unlock when fcntl_setlk races with a close
         [7f3697e24dc3820b10f445a4a7d914fc356012d1]

Karl Heiss (1):
      sctp: Prevent soft lockup when sctp_accept() is called during a timeout event
         [635682a14427d241bab7bbdeebb48a7d7b91638e]

Larry Finger (4):
      rtlwifi: rtl8192ce: Fix handling of module parameters
         [b24f19f16b9e43f54218c07609b783ea8625406a]
      rtlwifi: rtl8192cu: Add missing parameter setup
         [b68d0ae7e58624c33f2eddab471fee55db27dbf9]
      rtlwifi: rtl8192de: Fix incorrect module parameter descriptions
         [d4d60b4caaa5926e1b243070770968f05656107a]
      rtlwifi: rtl8192se: Fix module parameter initialization
         [7503efbd82c15c4070adffff1344e5169d3634b4]

Laura Abbott (1):
      dma-debug: switch check from _text to _stext
         [ea535e418c01837d07b6c94e817540f50bfdadb0]

Malcolm Priestley (1):
      [media] media: dvb-core: Don't force CAN_INVERSION_AUTO in oneshot mode
         [c9d57de6103e343f2d4e04ea8d9e417e10a24da7]

Mario Kleiner (1):
      x86/reboot/quirks: Add iMac10,1 to pci_reboot_dmi_table[]
         [2f0c0b2d96b1205efb14347009748d786c2d9ba5]

Martijn Coenen (1):
      memcg: only free spare array when readers are done
         [6611d8d76132f86faa501de9451a89bf23fb2371]

Matan Barak (1):
      IB/mlx4: Initialize hop_limit when creating address handle
         [4e4081673445485aa6bc90383bdb83e7a96cc48a]

Mike Marciniszyn (1):
      IB/qib: fix mcast detach when qp not attached
         [09dc9cd6528f5b52bcbd3292a6312e762c85260f]

Mikulas Patocka (1):
      dm snapshot: fix hung bios when copy error occurs
         [385277bfb57faac44e92497104ba542cdd82d5fe]

Nicolas Boichat (2):
      ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode
         [43c54b8c7cfe22f868a751ba8a59abf1724160b1]
      ALSA: seq: Fix snd_seq_call_port_info_ioctl in compat mode
         [9586495dc3011a80602329094e746dbce16cb1f1]

Oliver Freyermuth (1):
      USB: cp210x: add ID for ELV Marble Sound Board 1
         [f7d7f59ab124748156ea551edf789994f05da342]

Oliver Neukum (2):
      [media] usbvision fix overflow of interfaces array
         [588afcc1c0e45358159090d95bf7b246fb67565f]
      xhci: refuse loading if nousb is used
         [1eaf35e4dd592c59041bc1ed3248c46326da1f5f]

Ouyang Zhaowei (1):
      x86/xen: don't reset vcpu_info on a cancelled suspend
         [6a1f513776b78c994045287073e55bae44ed9f8c]

Paolo Bonzini (2):
      KVM: x86: correctly print #AC in traces
         [aba2f06c070f604e388cf77b1dcc7f4cf4577eb0]
      KVM: x86: expose MSR_TSC_AUX to userspace
         [9dbe6cf941a6fe82933aef565e4095fb10f65023]

Peter Wu (1):
      rtlwifi: fix memory leak for USB device
         [17bc55864f81dd730d05f09b1641312a7990d636]

Rabin Vincent (1):
      cifs: fix race between call_async() and reconnect()
         [820962dc700598ffe8cd21b967e30e7520c34748]

Richard Cochran (1):
      posix-clock: Fix return code on the poll method's error path
         [1b9f23727abb92c5e58f139e7d180befcaa06fe0]

Russell King (1):
      [media] rc: allow rc modules to be loaded if rc-main is not a module
         [2ff56fadd94cdaeeaeccbc0a9b703a0101ada128]

Sasha Levin (1):
      power: test_power: correctly handle empty writes
         [6b9140f39c2aaf76791197fbab0839c0e4af56e8]

Sergey Senozhatsky (1):
      scripts/bloat-o-meter: fix python3 syntax error
         [72214a24a7677d4c7501eecc9517ed681b5f2db2]

Stephen Hemminger (1):
      asix: silence log message from oversize packet
         [b70183db83552cf63cac51406aaf76a2cf5fca73]

Sudip Mukherjee (1):
      m32r: fix m32104ut_defconfig build fail
         [601f1db653217f205ffa5fb33514b4e1711e56d1]

Takashi Iwai (7):
      ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0
         [c0bcdbdff3ff73a54161fca3cb8b6cdbd0bb8762]
      ALSA: hrtimer: Fix stall by hrtimer_cancel()
         [2ba1fe7a06d3624f9a7586d672b55f08f7c670f3]
      ALSA: seq: Fix missing NULL check at remove_events ioctl
         [030e2c78d3a91dd0d27fef37e91950dde333eba1]
      ALSA: seq: Fix race at timer setup and close
         [3567eb6af614dac436c4b16a8d426f9faed639b3]
      ALSA: timer: Fix double unlink of active_list
         [ee8413b01045c74340aa13ad5bdf905de32be736]
      ALSA: timer: Fix race among timer ioctls
         [af368027a49a751d6ff4ee9e3f9961f35bb4fede]
      ALSA: timer: Harden slave timer list handling
         [b5a663aa426f4884c71cd8580adae73f33570f0d]

Tariq Saeed (1):
      ocfs2: NFS hangs in __ocfs2_cluster_lock due to race with ocfs2_unblock_lock
         [b1b1e15ef6b80facf76d6757649dfd7295eda29f]

Thomas Gleixner (1):
      futex: Drop refcount if requeue_pi() acquired the rtmutex
         [fb75a4282d0d9a3c7c44d940582c2d226cf3acfb]

Trond Myklebust (1):
      NFS: Fix attribute cache revalidation
         [ade14a7df796d4e86bd9d181193c883a57b13db0]

Uri Mashiach (1):
      wlcore/wl12xx: spi: fix oops on firmware load
         [9b2761cb72dc41e1948c8a5512b4efd384eda130]

Vasily Averin (1):
      cifs_dbg() outputs an uninitialized buffer in cifs_readdir()
         [01b9b0b28626db4a47d7f48744d70abca9914ef1]

Vegard Nossum (3):
      udf: limit the maximum number of indirect extents in a row
         [b0918d9f476a8434b055e362b83fa4fd1d462c3f]
      uml: fix hostfs mknod()
         [9f2dfda2f2f1c6181c3732c16b85c59ab2d195e0]
      uml: flush stdout before forking
         [0754fb298f2f2719f0393491d010d46cfb25d043]

Vladis Dronov (1):
      [media] usbvision: fix crash on detecting device with invalid configuration
         [fa52bd506f274b7619955917abfde355e3d19ffe]

Xuejiufei (1):
      ocfs2/dlm: ignore cleaning the migration mle that is inuse
         [bef5502de074b6f6fa647b94b73155d675694420]

 Makefile                                        |   4 +-
 arch/m32r/kernel/setup.c                        |   3 +
 arch/parisc/include/asm/siginfo.h               |   4 +
 arch/powerpc/include/asm/synch.h                |   2 +-
 arch/powerpc/include/asm/system.h               |  16 +--
 arch/sparc/kernel/sys_sparc_64.c                |   2 +-
 arch/um/os-Linux/start_up.c                     |   2 +
 arch/x86/include/asm/boot.h                     |   2 +-
 arch/x86/include/asm/mmu_context.h              |  32 ++++-
 arch/x86/kernel/process_64.c                    |   2 +-
 arch/x86/kernel/reboot.c                        |   8 ++
 arch/x86/kvm/trace.h                            |   2 +-
 arch/x86/kvm/x86.c                              |  17 ++-
 arch/x86/mm/tlb.c                               |  28 +++-
 arch/x86/xen/suspend.c                          |   3 +-
 crypto/ablkcipher.c                             |   1 +
 crypto/af_alg.c                                 |  55 +++++++-
 crypto/ahash.c                                  |   5 +-
 crypto/algif_hash.c                             | 165 ++++++++++++++++++++++-
 crypto/algif_skcipher.c                         | 169 +++++++++++++++++++++---
 crypto/shash.c                                  |   4 +-
 drivers/edac/edac_device.c                      |   9 +-
 drivers/edac/edac_mc.c                          |  15 +--
 drivers/edac/edac_pci.c                         |   9 +-
 drivers/gpu/drm/radeon/radeon_atombios.c        |  12 +-
 drivers/gpu/drm/radeon/radeon_device.c          |   1 +
 drivers/infiniband/hw/mlx4/ah.c                 |   1 +
 drivers/infiniband/hw/qib/qib_verbs_mcast.c     |  35 +++--
 drivers/input/serio/i8042-x86ia64io.h           |   7 +
 drivers/md/dm-exception-store.h                 |   2 +-
 drivers/md/dm-snap-persistent.c                 |   5 +-
 drivers/md/dm-snap-transient.c                  |   4 +-
 drivers/md/dm-snap.c                            |  20 +--
 drivers/media/dvb/dvb-core/dvb_frontend.c       |   6 +-
 drivers/media/rc/rc-main.c                      |   2 +-
 drivers/media/video/gspca/ov534.c               |   9 +-
 drivers/media/video/gspca/topro.c               |   6 +-
 drivers/media/video/usbvision/usbvision-video.c |  47 ++++++-
 drivers/net/usb/asix.c                          |   2 +-
 drivers/net/wireless/ath/ath9k/htc_hst.c        |   2 +-
 drivers/net/wireless/rtlwifi/rtl8192ce/sw.c     |   2 +
 drivers/net/wireless/rtlwifi/rtl8192cu/sw.c     |   2 +
 drivers/net/wireless/rtlwifi/rtl8192de/sw.c     |   4 +-
 drivers/net/wireless/rtlwifi/rtl8192se/sw.c     |   6 +-
 drivers/net/wireless/rtlwifi/usb.c              |   2 +
 drivers/net/wireless/wl12xx/spi.c               |   8 +-
 drivers/power/test_power.c                      |   2 +
 drivers/scsi/initio.c                           |  16 ---
 drivers/usb/host/xhci.c                         |   3 +
 drivers/usb/serial/cp210x.c                     |   1 +
 fs/cifs/cifs_debug.h                            |   8 +-
 fs/cifs/connect.c                               |   2 +-
 fs/cifs/readdir.c                               |   1 +
 fs/cifs/transport.c                             |  17 ++-
 fs/hostfs/hostfs_kern.c                         |   4 +-
 fs/locks.c                                      |  51 ++++---
 fs/nfs/inode.c                                  |  54 +++++---
 fs/ocfs2/dlm/dlmmaster.c                        |  26 ++--
 fs/ocfs2/dlmglue.c                              |   6 +
 fs/udf/inode.c                                  |  15 +++
 fs/udf/unicode.c                                |  21 ++-
 include/crypto/hash.h                           |   6 +
 include/crypto/if_alg.h                         |  11 +-
 include/linux/crypto.h                          |   8 ++
 include/linux/mtd/nand.h                        |   4 +-
 include/linux/printk.h                          |  12 +-
 kernel/futex.c                                  |   5 +
 kernel/time/posix-clock.c                       |   4 +-
 lib/dma-debug.c                                 |   2 +-
 mm/memcontrol.c                                 |  11 +-
 net/ipv6/tcp_ipv6.c                             |   2 +
 net/sctp/sm_sideeffect.c                        |  34 ++---
 scripts/bloat-o-meter                           |   8 +-
 sound/core/control.c                            |   2 +
 sound/core/hrtimer.c                            |   3 +-
 sound/core/pcm_compat.c                         |  13 +-
 sound/core/seq/seq_clientmgr.c                  |   2 +-
 sound/core/seq/seq_compat.c                     |   9 +-
 sound/core/seq/seq_queue.c                      |   2 +
 sound/core/timer.c                              |  52 +++++---
 sound/pci/fm801.c                               |   4 +
 81 files changed, 870 insertions(+), 295 deletions(-)

-- 
Ben Hutchings
Nothing is ever a complete failure; it can always serve as a bad example.

[toc] | [next] | [standalone]


#1329763 — [PATCH 3.2 79/87] crypto: af_alg - Forbid bind(2) when nokey child sockets are present

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:20 +0100
Subject[PATCH 3.2 79/87] crypto: af_alg - Forbid bind(2) when nokey child sockets are present
Message-ID<r04cb-4m5-31@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit a6a48c565f6f112c6983e2a02b1602189ed6e26e upstream.

This patch forbids the calling of bind(2) when there are child
sockets created by accept(2) in existence, even if they are created
on the nokey path.

This is needed as those child sockets have references to the tfm
object which bind(2) will destroy.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 crypto/af_alg.c | 16 +++++++---------
 1 file changed, 7 insertions(+), 9 deletions(-)

--- a/crypto/af_alg.c
+++ b/crypto/af_alg.c
@@ -130,19 +130,16 @@ EXPORT_SYMBOL_GPL(af_alg_release);
 void af_alg_release_parent(struct sock *sk)
 {
 	struct alg_sock *ask = alg_sk(sk);
-	bool last;
+	unsigned int nokey = ask->nokey_refcnt;
+	bool last = nokey && !ask->refcnt;
 
 	sk = ask->parent;
-
-	if (ask->nokey_refcnt && !ask->refcnt) {
-		sock_put(sk);
-		return;
-	}
-
 	ask = alg_sk(sk);
 
 	lock_sock(sk);
-	last = !--ask->refcnt;
+	ask->nokey_refcnt -= nokey;
+	if (!last)
+		last = !--ask->refcnt;
 	release_sock(sk);
 
 	if (last)
@@ -185,7 +182,7 @@ static int alg_bind(struct socket *sock,
 
 	err = -EBUSY;
 	lock_sock(sk);
-	if (ask->refcnt)
+	if (ask->refcnt | ask->nokey_refcnt)
 		goto unlock;
 
 	swap(ask->type, type);
@@ -296,6 +293,7 @@ int af_alg_accept(struct sock *sk, struc
 
 	if (nokey || !ask->refcnt++)
 		sock_hold(sk);
+	ask->nokey_refcnt += nokey;
 	alg_sk(sk2)->parent = sk;
 	alg_sk(sk2)->type = type;
 	alg_sk(sk2)->nokey_refcnt = nokey;

[toc] | [prev] | [next] | [standalone]


#1329764 — [PATCH 3.2 17/87] asix: silence log message from oversize packet

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:20 +0100
Subject[PATCH 3.2 17/87] asix: silence log message from oversize packet
Message-ID<r04cb-4m5-33@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: stephen hemminger <stephen@networkplumber.org>

commit b70183db83552cf63cac51406aaf76a2cf5fca73 upstream.

Since it is possible for an external system to send oversize packets
at anytime, it is best for driver not to print a message and spam
the log (potential external DoS).

Fixes: https://bugzilla.kernel.org/show_bug.cgi?id=109471

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
[bwh: Backported to 3.2: adjust filename, context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/net/usb/asix_common.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/net/usb/asix.c
+++ b/drivers/net/usb/asix.c
@@ -361,7 +361,7 @@ static int asix_rx_fixup_internal(struct
 		}
 
 		if (rx->size > dev->net->mtu + ETH_HLEN + VLAN_HLEN) {
-			netdev_err(dev->net, "asix_rx_fixup() Bad RX Length %d\n",
+			netdev_dbg(dev->net, "asix_rx_fixup() Bad RX Length %d\n",
 				   rx->size);
 			kfree_skb(rx->ax_skb);
 			return 0;

[toc] | [prev] | [next] | [standalone]


#1329765 — [PATCH 3.2 73/87] crypto: algif_hash - Require setkey before accept(2)

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:20 +0100
Subject[PATCH 3.2 73/87] crypto: algif_hash - Require setkey before accept(2)
Message-ID<r04cb-4m5-23@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit 6de62f15b581f920ade22d758f4c338311c2f0d4 upstream.

Hash implementations that require a key may crash if you use
them without setting a key.  This patch adds the necessary checks
so that if you do attempt to use them without a key that we return
-ENOKEY instead of proceeding.

This patch also adds a compatibility path to support old applications
that do acept(2) before setkey.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
[bwh: Backported to 3.2:
 - Add struct kiocb * parameter to {recv,send}msg ops
 - Adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 crypto/algif_hash.c | 201 +++++++++++++++++++++++++++++++++++++++++++++++++---
 1 file changed, 193 insertions(+), 8 deletions(-)

--- a/crypto/algif_hash.c
+++ b/crypto/algif_hash.c
@@ -34,6 +34,11 @@ struct hash_ctx {
 	struct ahash_request req;
 };
 
+struct algif_hash_tfm {
+	struct crypto_ahash *hash;
+	bool has_key;
+};
+
 static int hash_sendmsg(struct kiocb *unused, struct socket *sock,
 			struct msghdr *msg, size_t ignored)
 {
@@ -246,22 +251,151 @@ static struct proto_ops algif_hash_ops =
 	.accept		=	hash_accept,
 };
 
+static int hash_check_key(struct socket *sock)
+{
+	int err;
+	struct sock *psk;
+	struct alg_sock *pask;
+	struct algif_hash_tfm *tfm;
+	struct sock *sk = sock->sk;
+	struct alg_sock *ask = alg_sk(sk);
+
+	if (ask->refcnt)
+		return 0;
+
+	psk = ask->parent;
+	pask = alg_sk(ask->parent);
+	tfm = pask->private;
+
+	err = -ENOKEY;
+	lock_sock(psk);
+	if (!tfm->has_key)
+		goto unlock;
+
+	if (!pask->refcnt++)
+		sock_hold(psk);
+
+	ask->refcnt = 1;
+	sock_put(psk);
+
+	err = 0;
+
+unlock:
+	release_sock(psk);
+
+	return err;
+}
+
+static int hash_sendmsg_nokey(struct kiocb *unused, struct socket *sock,
+			      struct msghdr *msg, size_t size)
+{
+	int err;
+
+	err = hash_check_key(sock);
+	if (err)
+		return err;
+
+	return hash_sendmsg(unused, sock, msg, size);
+}
+
+static ssize_t hash_sendpage_nokey(struct socket *sock, struct page *page,
+				   int offset, size_t size, int flags)
+{
+	int err;
+
+	err = hash_check_key(sock);
+	if (err)
+		return err;
+
+	return hash_sendpage(sock, page, offset, size, flags);
+}
+
+static int hash_recvmsg_nokey(struct kiocb *unused, struct socket *sock,
+			      struct msghdr *msg, size_t ignored, int flags)
+{
+	int err;
+
+	err = hash_check_key(sock);
+	if (err)
+		return err;
+
+	return hash_recvmsg(unused, sock, msg, ignored, flags);
+}
+
+static int hash_accept_nokey(struct socket *sock, struct socket *newsock,
+			     int flags)
+{
+	int err;
+
+	err = hash_check_key(sock);
+	if (err)
+		return err;
+
+	return hash_accept(sock, newsock, flags);
+}
+
+static struct proto_ops algif_hash_ops_nokey = {
+	.family		=	PF_ALG,
+
+	.connect	=	sock_no_connect,
+	.socketpair	=	sock_no_socketpair,
+	.getname	=	sock_no_getname,
+	.ioctl		=	sock_no_ioctl,
+	.listen		=	sock_no_listen,
+	.shutdown	=	sock_no_shutdown,
+	.getsockopt	=	sock_no_getsockopt,
+	.mmap		=	sock_no_mmap,
+	.bind		=	sock_no_bind,
+	.setsockopt	=	sock_no_setsockopt,
+	.poll		=	sock_no_poll,
+
+	.release	=	af_alg_release,
+	.sendmsg	=	hash_sendmsg_nokey,
+	.sendpage	=	hash_sendpage_nokey,
+	.recvmsg	=	hash_recvmsg_nokey,
+	.accept		=	hash_accept_nokey,
+};
+
 static void *hash_bind(const char *name, u32 type, u32 mask)
 {
-	return crypto_alloc_ahash(name, type, mask);
+	struct algif_hash_tfm *tfm;
+	struct crypto_ahash *hash;
+
+	tfm = kzalloc(sizeof(*tfm), GFP_KERNEL);
+	if (!tfm)
+		return ERR_PTR(-ENOMEM);
+
+	hash = crypto_alloc_ahash(name, type, mask);
+	if (IS_ERR(hash)) {
+		kfree(tfm);
+		return ERR_CAST(hash);
+	}
+
+	tfm->hash = hash;
+
+	return tfm;
 }
 
 static void hash_release(void *private)
 {
-	crypto_free_ahash(private);
+	struct algif_hash_tfm *tfm = private;
+
+	crypto_free_ahash(tfm->hash);
+	kfree(tfm);
 }
 
 static int hash_setkey(void *private, const u8 *key, unsigned int keylen)
 {
-	return crypto_ahash_setkey(private, key, keylen);
+	struct algif_hash_tfm *tfm = private;
+	int err;
+
+	err = crypto_ahash_setkey(tfm->hash, key, keylen);
+	tfm->has_key = !err;
+
+	return err;
 }
 
-static void hash_sock_destruct(struct sock *sk)
+static void hash_sock_destruct_common(struct sock *sk)
 {
 	struct alg_sock *ask = alg_sk(sk);
 	struct hash_ctx *ctx = ask->private;
@@ -269,15 +403,40 @@ static void hash_sock_destruct(struct so
 	sock_kfree_s(sk, ctx->result,
 		     crypto_ahash_digestsize(crypto_ahash_reqtfm(&ctx->req)));
 	sock_kfree_s(sk, ctx, ctx->len);
+}
+
+static void hash_sock_destruct(struct sock *sk)
+{
+	hash_sock_destruct_common(sk);
 	af_alg_release_parent(sk);
 }
 
-static int hash_accept_parent(void *private, struct sock *sk)
+static void hash_release_parent_nokey(struct sock *sk)
+{
+	struct alg_sock *ask = alg_sk(sk);
+
+	if (!ask->refcnt) {
+		sock_put(ask->parent);
+		return;
+	}
+
+	af_alg_release_parent(sk);
+}
+
+static void hash_sock_destruct_nokey(struct sock *sk)
+{
+	hash_sock_destruct_common(sk);
+	hash_release_parent_nokey(sk);
+}
+
+static int hash_accept_parent_common(void *private, struct sock *sk)
 {
 	struct hash_ctx *ctx;
 	struct alg_sock *ask = alg_sk(sk);
-	unsigned len = sizeof(*ctx) + crypto_ahash_reqsize(private);
-	unsigned ds = crypto_ahash_digestsize(private);
+	struct algif_hash_tfm *tfm = private;
+	struct crypto_ahash *hash = tfm->hash;
+	unsigned len = sizeof(*ctx) + crypto_ahash_reqsize(hash);
+	unsigned ds = crypto_ahash_digestsize(hash);
 
 	ctx = sock_kmalloc(sk, len, GFP_KERNEL);
 	if (!ctx)
@@ -297,7 +456,7 @@ static int hash_accept_parent(void *priv
 
 	ask->private = ctx;
 
-	ahash_request_set_tfm(&ctx->req, private);
+	ahash_request_set_tfm(&ctx->req, hash);
 	ahash_request_set_callback(&ctx->req, CRYPTO_TFM_REQ_MAY_BACKLOG,
 				   af_alg_complete, &ctx->completion);
 
@@ -306,12 +465,38 @@ static int hash_accept_parent(void *priv
 	return 0;
 }
 
+static int hash_accept_parent(void *private, struct sock *sk)
+{
+	struct algif_hash_tfm *tfm = private;
+
+	if (!tfm->has_key && crypto_ahash_has_setkey(tfm->hash))
+		return -ENOKEY;
+
+	return hash_accept_parent_common(private, sk);
+}
+
+static int hash_accept_parent_nokey(void *private, struct sock *sk)
+{
+	int err;
+
+	err = hash_accept_parent_common(private, sk);
+	if (err)
+		goto out;
+
+	sk->sk_destruct = hash_sock_destruct_nokey;
+
+out:
+	return err;
+}
+
 static const struct af_alg_type algif_type_hash = {
 	.bind		=	hash_bind,
 	.release	=	hash_release,
 	.setkey		=	hash_setkey,
 	.accept		=	hash_accept_parent,
+	.accept_nokey	=	hash_accept_parent_nokey,
 	.ops		=	&algif_hash_ops,
+	.ops_nokey	=	&algif_hash_ops_nokey,
 	.name		=	"hash",
 	.owner		=	THIS_MODULE
 };

[toc] | [prev] | [next] | [standalone]


#1329766 — [PATCH 3.2 18/87] futex: Drop refcount if requeue_pi() acquired the rtmutex

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:20 +0100
Subject[PATCH 3.2 18/87] futex: Drop refcount if requeue_pi() acquired the rtmutex
Message-ID<r04cb-4m5-37@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Gleixner <tglx@linutronix.de>

commit fb75a4282d0d9a3c7c44d940582c2d226cf3acfb upstream.

If the proxy lock in the requeue loop acquires the rtmutex for a
waiter then it acquired also refcount on the pi_state related to the
futex, but the waiter side does not drop the reference count.

Add the missing free_pi_state() call.

Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Darren Hart <darren@dvhart.com>
Cc: Davidlohr Bueso <dave@stgolabs.net>
Cc: Bhuvanesh_Surachari@mentor.com
Cc: Andy Lowe <Andy_Lowe@mentor.com>
Link: http://lkml.kernel.org/r/20151219200607.178132067@linutronix.de
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 kernel/futex.c | 5 +++++
 1 file changed, 5 insertions(+)

--- a/kernel/futex.c
+++ b/kernel/futex.c
@@ -2492,6 +2492,11 @@ static int futex_wait_requeue_pi(u32 __u
 		if (q.pi_state && (q.pi_state->owner != current)) {
 			spin_lock(q.lock_ptr);
 			ret = fixup_pi_state_owner(uaddr2, &q, current);
+			/*
+			 * Drop the reference to the pi state which
+			 * the requeue_pi() code acquired for us.
+			 */
+			free_pi_state(q.pi_state);
 			spin_unlock(q.lock_ptr);
 		}
 	} else {

[toc] | [prev] | [next] | [standalone]


#1329767 — [PATCH 3.2 60/87] crypto: af_alg - Fix socket double-free when accept fails

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:20 +0100
Subject[PATCH 3.2 60/87] crypto: af_alg - Fix socket double-free when accept fails
Message-ID<r04cb-4m5-39@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit a383292c86663bbc31ac62cc0c04fc77504636a6 upstream.

When we fail an accept(2) call we will end up freeing the socket
twice, once due to the direct sk_free call and once again through
newsock.

This patch fixes this by removing the sk_free call.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 crypto/af_alg.c | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

--- a/crypto/af_alg.c
+++ b/crypto/af_alg.c
@@ -247,10 +247,8 @@ int af_alg_accept(struct sock *sk, struc
 	security_sk_clone(sk, sk2);
 
 	err = type->accept(ask->private, sk2);
-	if (err) {
-		sk_free(sk2);
+	if (err)
 		goto unlock;
-	}
 
 	sk2->sk_family = PF_ALG;
 

[toc] | [prev] | [next] | [standalone]


#1329768 — [PATCH 3.2 72/87] crypto: hash - Add crypto_ahash_has_setkey

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:20 +0100
Subject[PATCH 3.2 72/87] crypto: hash - Add crypto_ahash_has_setkey
Message-ID<r04cb-4m5-41@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit a5596d6332787fd383b3b5427b41f94254430827 upstream.

This patch adds a way for ahash users to determine whether a key
is required by a crypto_ahash transform.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 crypto/ahash.c        | 5 ++++-
 crypto/shash.c        | 4 +++-
 include/crypto/hash.h | 6 ++++++
 3 files changed, 13 insertions(+), 2 deletions(-)

--- a/crypto/ahash.c
+++ b/crypto/ahash.c
@@ -369,6 +369,7 @@ static int crypto_ahash_init_tfm(struct
 	struct ahash_alg *alg = crypto_ahash_alg(hash);
 
 	hash->setkey = ahash_nosetkey;
+	hash->has_setkey = false;
 	hash->export = ahash_no_export;
 	hash->import = ahash_no_import;
 
@@ -381,8 +382,10 @@ static int crypto_ahash_init_tfm(struct
 	hash->finup = alg->finup ?: ahash_def_finup;
 	hash->digest = alg->digest;
 
-	if (alg->setkey)
+	if (alg->setkey) {
 		hash->setkey = alg->setkey;
+		hash->has_setkey = true;
+	}
 	if (alg->export)
 		hash->export = alg->export;
 	if (alg->import)
--- a/crypto/shash.c
+++ b/crypto/shash.c
@@ -354,8 +354,10 @@ int crypto_init_shash_ops_async(struct c
 	crt->finup = shash_async_finup;
 	crt->digest = shash_async_digest;
 
-	if (alg->setkey)
+	if (alg->setkey) {
 		crt->setkey = shash_async_setkey;
+		crt->has_setkey = true;
+	}
 	if (alg->export)
 		crt->export = shash_async_export;
 	if (alg->import)
--- a/include/crypto/hash.h
+++ b/include/crypto/hash.h
@@ -94,6 +94,7 @@ struct crypto_ahash {
 		      unsigned int keylen);
 
 	unsigned int reqsize;
+	bool has_setkey;
 	struct crypto_tfm base;
 };
 
@@ -181,6 +182,11 @@ static inline void *ahash_request_ctx(st
 
 int crypto_ahash_setkey(struct crypto_ahash *tfm, const u8 *key,
 			unsigned int keylen);
+static inline bool crypto_ahash_has_setkey(struct crypto_ahash *tfm)
+{
+	return tfm->has_setkey;
+}
+
 int crypto_ahash_finup(struct ahash_request *req);
 int crypto_ahash_final(struct ahash_request *req);
 int crypto_ahash_digest(struct ahash_request *req);

[toc] | [prev] | [next] | [standalone]


#1329769 — [PATCH 3.2 70/87] crypto: af_alg - Add nokey compatibility path

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:20 +0100
Subject[PATCH 3.2 70/87] crypto: af_alg - Add nokey compatibility path
Message-ID<r04cb-4m5-27@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit 37766586c965d63758ad542325a96d5384f4a8c9 upstream.

This patch adds a compatibility path to support old applications
that do acept(2) before setkey.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 crypto/af_alg.c         | 13 ++++++++++++-
 include/crypto/if_alg.h |  2 ++
 2 files changed, 14 insertions(+), 1 deletion(-)

--- a/crypto/af_alg.c
+++ b/crypto/af_alg.c
@@ -76,6 +76,8 @@ int af_alg_register_type(const struct af
 		goto unlock;
 
 	type->ops->owner = THIS_MODULE;
+	if (type->ops_nokey)
+		type->ops_nokey->owner = THIS_MODULE;
 	node->type = type;
 	list_add(&node->list, &alg_types);
 	err = 0;
@@ -257,6 +259,7 @@ int af_alg_accept(struct sock *sk, struc
 	const struct af_alg_type *type;
 	struct sock *sk2;
 	int err;
+	bool nokey;
 
 	lock_sock(sk);
 	type = ask->type;
@@ -275,12 +278,17 @@ int af_alg_accept(struct sock *sk, struc
 	security_sk_clone(sk, sk2);
 
 	err = type->accept(ask->private, sk2);
+
+	nokey = err == -ENOKEY;
+	if (nokey && type->accept_nokey)
+		err = type->accept_nokey(ask->private, sk2);
+
 	if (err)
 		goto unlock;
 
 	sk2->sk_family = PF_ALG;
 
-	if (!ask->refcnt++)
+	if (nokey || !ask->refcnt++)
 		sock_hold(sk);
 	alg_sk(sk2)->parent = sk;
 	alg_sk(sk2)->type = type;
@@ -288,6 +296,9 @@ int af_alg_accept(struct sock *sk, struc
 	newsock->ops = type->ops;
 	newsock->state = SS_CONNECTED;
 
+	if (nokey)
+		newsock->ops = type->ops_nokey;
+
 	err = 0;
 
 unlock:
--- a/include/crypto/if_alg.h
+++ b/include/crypto/if_alg.h
@@ -51,8 +51,10 @@ struct af_alg_type {
 	void (*release)(void *private);
 	int (*setkey)(void *private, const u8 *key, unsigned int keylen);
 	int (*accept)(void *private, struct sock *sk);
+	int (*accept_nokey)(void *private, struct sock *sk);
 
 	struct proto_ops *ops;
+	struct proto_ops *ops_nokey;
 	struct module *owner;
 	char name[14];
 };

[toc] | [prev] | [next] | [standalone]


#1329770 — [PATCH 3.2 57/87] ALSA: timer: Harden slave timer list handling

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:20 +0100
Subject[PATCH 3.2 57/87] ALSA: timer: Harden slave timer list handling
Message-ID<r04cb-4m5-35@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Takashi Iwai <tiwai@suse.de>

commit b5a663aa426f4884c71cd8580adae73f33570f0d upstream.

A slave timer instance might be still accessible in a racy way while
operating the master instance as it lacks of locking.  Since the
master operation is mostly protected with timer->lock, we should cope
with it while changing the slave instance, too.  Also, some linked
lists (active_list and ack_list) of slave instances aren't unlinked
immediately at stopping or closing, and this may lead to unexpected
accesses.

This patch tries to address these issues.  It adds spin lock of
timer->lock (either from master or slave, which is equivalent) in a
few places.  For avoiding a deadlock, we ensure that the global
slave_active_lock is always locked at first before each timer lock.

Also, ack and active_list of slave instances are properly unlinked at
snd_timer_stop() and snd_timer_close().

Last but not least, remove the superfluous call of _snd_timer_stop()
at removing slave links.  This is a noop, and calling it may confuse
readers wrt locking.  Further cleanup will follow in a later patch.

Actually we've got reports of use-after-free by syzkaller fuzzer, and
this hopefully fixes these issues.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 sound/core/timer.c | 18 ++++++++++++++----
 1 file changed, 14 insertions(+), 4 deletions(-)

--- a/sound/core/timer.c
+++ b/sound/core/timer.c
@@ -214,11 +214,13 @@ static void snd_timer_check_master(struc
 		    slave->slave_id == master->slave_id) {
 			list_move_tail(&slave->open_list, &master->slave_list_head);
 			spin_lock_irq(&slave_active_lock);
+			spin_lock(&master->timer->lock);
 			slave->master = master;
 			slave->timer = master->timer;
 			if (slave->flags & SNDRV_TIMER_IFLG_RUNNING)
 				list_add_tail(&slave->active_list,
 					      &master->slave_active_head);
+			spin_unlock(&master->timer->lock);
 			spin_unlock_irq(&slave_active_lock);
 		}
 	}
@@ -344,15 +346,18 @@ int snd_timer_close(struct snd_timer_ins
 		    timer->hw.close)
 			timer->hw.close(timer);
 		/* remove slave links */
+		spin_lock_irq(&slave_active_lock);
+		spin_lock(&timer->lock);
 		list_for_each_entry_safe(slave, tmp, &timeri->slave_list_head,
 					 open_list) {
-			spin_lock_irq(&slave_active_lock);
-			_snd_timer_stop(slave, 1, SNDRV_TIMER_EVENT_RESOLUTION);
 			list_move_tail(&slave->open_list, &snd_timer_slave_list);
 			slave->master = NULL;
 			slave->timer = NULL;
-			spin_unlock_irq(&slave_active_lock);
+			list_del_init(&slave->ack_list);
+			list_del_init(&slave->active_list);
 		}
+		spin_unlock(&timer->lock);
+		spin_unlock_irq(&slave_active_lock);
 		mutex_unlock(&register_mutex);
 	}
  out:
@@ -439,9 +444,12 @@ static int snd_timer_start_slave(struct
 
 	spin_lock_irqsave(&slave_active_lock, flags);
 	timeri->flags |= SNDRV_TIMER_IFLG_RUNNING;
-	if (timeri->master)
+	if (timeri->master && timeri->timer) {
+		spin_lock(&timeri->timer->lock);
 		list_add_tail(&timeri->active_list,
 			      &timeri->master->slave_active_head);
+		spin_unlock(&timeri->timer->lock);
+	}
 	spin_unlock_irqrestore(&slave_active_lock, flags);
 	return 1; /* delayed start */
 }
@@ -487,6 +495,8 @@ static int _snd_timer_stop(struct snd_ti
 		if (!keep_flag) {
 			spin_lock_irqsave(&slave_active_lock, flags);
 			timeri->flags &= ~SNDRV_TIMER_IFLG_RUNNING;
+			list_del_init(&timeri->ack_list);
+			list_del_init(&timeri->active_list);
 			spin_unlock_irqrestore(&slave_active_lock, flags);
 		}
 		goto __end;

[toc] | [prev] | [next] | [standalone]


#1329771 — [PATCH 3.2 61/87] ALSA: hrtimer: Fix stall by hrtimer_cancel()

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:20 +0100
Subject[PATCH 3.2 61/87] ALSA: hrtimer: Fix stall by hrtimer_cancel()
Message-ID<r04cc-4m5-45@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Takashi Iwai <tiwai@suse.de>

commit 2ba1fe7a06d3624f9a7586d672b55f08f7c670f3 upstream.

hrtimer_cancel() waits for the completion from the callback, thus it
must not be called inside the callback itself.  This was already a
problem in the past with ALSA hrtimer driver, and the early commit
[fcfdebe70759: ALSA: hrtimer - Fix lock-up] tried to address it.

However, the previous fix is still insufficient: it may still cause a
lockup when the ALSA timer instance reprograms itself in its callback.
Then it invokes the start function even in snd_timer_interrupt() that
is called in hrtimer callback itself, results in a CPU stall.  This is
no hypothetical problem but actually triggered by syzkaller fuzzer.

This patch tries to fix the issue again.  Now we call
hrtimer_try_to_cancel() at both start and stop functions so that it
won't fall into a deadlock, yet giving some chance to cancel the queue
if the functions have been called outside the callback.  The proper
hrtimer_cancel() is called in anyway at closing, so this should be
enough.

Reported-and-tested-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 sound/core/hrtimer.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/sound/core/hrtimer.c
+++ b/sound/core/hrtimer.c
@@ -90,7 +90,7 @@ static int snd_hrtimer_start(struct snd_
 	struct snd_hrtimer *stime = t->private_data;
 
 	atomic_set(&stime->running, 0);
-	hrtimer_cancel(&stime->hrt);
+	hrtimer_try_to_cancel(&stime->hrt);
 	hrtimer_start(&stime->hrt, ns_to_ktime(t->sticks * resolution),
 		      HRTIMER_MODE_REL);
 	atomic_set(&stime->running, 1);
@@ -101,6 +101,7 @@ static int snd_hrtimer_stop(struct snd_t
 {
 	struct snd_hrtimer *stime = t->private_data;
 	atomic_set(&stime->running, 0);
+	hrtimer_try_to_cancel(&stime->hrt);
 	return 0;
 }
 

[toc] | [prev] | [next] | [standalone]


#1329773 — [PATCH 3.2 82/87] crypto: algif_skcipher - Load TX SG list after waiting

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:20 +0100
Subject[PATCH 3.2 82/87] crypto: algif_skcipher - Load TX SG list after waiting
Message-ID<r04cc-4m5-47@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit 4f0414e54e4d1893c6f08260693f8ef84c929293 upstream.

We need to load the TX SG list in sendmsg(2) after waiting for
incoming data, not before.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Tested-by: Dmitry Vyukov <dvyukov@google.com>
[bwh: Backported to 3.2: adjust context, indentation]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 crypto/algif_skcipher.c | 14 +++++++-------
 1 file changed, 7 insertions(+), 7 deletions(-)

--- a/crypto/algif_skcipher.c
+++ b/crypto/algif_skcipher.c
@@ -446,13 +446,6 @@ static int skcipher_recvmsg(struct kiocb
 		char __user *from = iov->iov_base;
 
 		while (seglen) {
-			sgl = list_first_entry(&ctx->tsgl,
-					       struct skcipher_sg_list, list);
-			sg = sgl->sg;
-
-			while (!sg->length)
-				sg++;
-
 			used = ctx->used;
 			if (!used) {
 				err = skcipher_wait_for_data(sk, flags);
@@ -474,6 +467,13 @@ static int skcipher_recvmsg(struct kiocb
 			if (!used)
 				goto free;
 
+			sgl = list_first_entry(&ctx->tsgl,
+					       struct skcipher_sg_list, list);
+			sg = sgl->sg;
+
+			while (!sg->length)
+				sg++;
+
 			ablkcipher_request_set_crypt(&ctx->req, sg,
 						     ctx->rsgl.sg, used,
 						     ctx->iv);

[toc] | [prev] | [next] | [standalone]


#1329774 — [PATCH 3.2 11/87] rtlwifi: fix memory leak for USB device

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:20 +0100
Subject[PATCH 3.2 11/87] rtlwifi: fix memory leak for USB device
Message-ID<r04cc-4m5-57@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Wu <peter@lekensteyn.nl>

commit 17bc55864f81dd730d05f09b1641312a7990d636 upstream.

Free skb for received frames with a wrong checksum. This can happen
pretty rapidly, exhausting all memory.

This fixes a memleak (detected with kmemleak). Originally found while
using monitor mode, but it also appears during managed mode (once the
link is up).

Signed-off-by: Peter Wu <peter@lekensteyn.nl>
ACKed-by: Larry Finger <Larry.Finger@lwfinger.net>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
[bwh: Backported to 3.2: adjust filename, context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/net/wireless/realtek/rtlwifi/usb.c | 2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/net/wireless/rtlwifi/usb.c
+++ b/drivers/net/wireless/rtlwifi/usb.c
@@ -500,6 +500,8 @@ static void _rtl_usb_rx_process_noagg(st
 		} else {
 			dev_kfree_skb_any(skb);
 		}
+	} else {
+		dev_kfree_skb_any(skb);
 	}
 }
 

[toc] | [prev] | [next] | [standalone]


#1329775 — [PATCH 3.2 64/87] ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:20 +0100
Subject[PATCH 3.2 64/87] ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0
Message-ID<r04cc-4m5-53@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Takashi Iwai <tiwai@suse.de>

commit c0bcdbdff3ff73a54161fca3cb8b6cdbd0bb8762 upstream.

When a TLV ioctl with numid zero is handled, the driver may spew a
kernel warning with a stack trace at each call.  The check was
intended obviously only for a kernel driver, but not for a user
interaction.  Let's fix it.

This was spotted by syzkaller fuzzer.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 sound/core/control.c | 2 ++
 1 file changed, 2 insertions(+)

--- a/sound/core/control.c
+++ b/sound/core/control.c
@@ -1321,6 +1321,8 @@ static int snd_ctl_tlv_ioctl(struct snd_
 		return -EFAULT;
 	if (tlv.length < sizeof(unsigned int) * 2)
 		return -EINVAL;
+	if (!tlv.numid)
+		return -EINVAL;
 	down_read(&card->controls_rwsem);
 	kctl = snd_ctl_find_numid(card, tlv.numid);
 	if (kctl == NULL) {

[toc] | [prev] | [next] | [standalone]


#1329777 — [PATCH 3.2 01/87] [media] gspca: ov534/topro: prevent a division by 0

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:20 +0100
Subject[PATCH 3.2 01/87] [media] gspca: ov534/topro: prevent a division by 0
Message-ID<r04cc-4m5-59@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Antonio Ospite <ao2@ao2.it>

commit dcc7fdbec53a960588f2c40232db2c6466c09917 upstream.

v4l2-compliance sends a zeroed struct v4l2_streamparm in
v4l2-test-formats.cpp::testParmType(), and this results in a division by
0 in some gspca subdrivers:

  divide error: 0000 [#1] SMP
  Modules linked in: gspca_ov534 gspca_main ...
  CPU: 0 PID: 17201 Comm: v4l2-compliance Not tainted 4.3.0-rc2-ao2 #1
  Hardware name: System manufacturer System Product Name/M2N-E SLI, BIOS
    ASUS M2N-E SLI ACPI BIOS Revision 1301 09/16/2010
  task: ffff8800818306c0 ti: ffff880095c4c000 task.ti: ffff880095c4c000
  RIP: 0010:[<ffffffffa079bd62>]  [<ffffffffa079bd62>] sd_set_streamparm+0x12/0x60 [gspca_ov534]
  RSP: 0018:ffff880095c4fce8  EFLAGS: 00010296
  RAX: 0000000000000000 RBX: ffff8800c9522000 RCX: ffffffffa077a140
  RDX: 0000000000000000 RSI: ffff880095e0c100 RDI: ffff8800c9522000
  RBP: ffff880095e0c100 R08: ffffffffa077a100 R09: 00000000000000cc
  R10: ffff880067ec7740 R11: 0000000000000016 R12: ffffffffa07bb400
  R13: 0000000000000000 R14: ffff880081b6a800 R15: 0000000000000000
  FS:  00007fda0de78740(0000) GS:ffff88012fc00000(0000) knlGS:0000000000000000
  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
  CR2: 00000000014630f8 CR3: 00000000cf349000 CR4: 00000000000006f0
  Stack:
   ffffffffa07a6431 ffff8800c9522000 ffffffffa077656e 00000000c0cc5616
   ffff8800c9522000 ffffffffa07a5e20 ffff880095e0c100 0000000000000000
   ffff880067ec7740 ffffffffa077a140 ffff880067ec7740 0000000000000016
  Call Trace:
   [<ffffffffa07a6431>] ? v4l_s_parm+0x21/0x50 [videodev]
   [<ffffffffa077656e>] ? vidioc_s_parm+0x4e/0x60 [gspca_main]
   [<ffffffffa07a5e20>] ? __video_do_ioctl+0x280/0x2f0 [videodev]
   [<ffffffffa07a5ba0>] ? video_ioctl2+0x20/0x20 [videodev]
   [<ffffffffa07a59b9>] ? video_usercopy+0x319/0x4e0 [videodev]
   [<ffffffff81182dc1>] ? page_add_new_anon_rmap+0x71/0xa0
   [<ffffffff811afb92>] ? mem_cgroup_commit_charge+0x52/0x90
   [<ffffffff81179b18>] ? handle_mm_fault+0xc18/0x1680
   [<ffffffffa07a15cc>] ? v4l2_ioctl+0xac/0xd0 [videodev]
   [<ffffffff811c846f>] ? do_vfs_ioctl+0x28f/0x480
   [<ffffffff811c86d4>] ? SyS_ioctl+0x74/0x80
   [<ffffffff8154a8b6>] ? entry_SYSCALL_64_fastpath+0x16/0x75
  Code: c7 93 d9 79 a0 5b 5d e9 f1 f3 9a e0 0f 1f 00 66 2e 0f 1f 84 00
    00 00 00 00 66 66 66 66 90 53 31 d2 48 89 fb 48 83 ec 08 8b 46 10 <f7>
    76 0c 80 bf ac 0c 00 00 00 88 87 4e 0e 00 00 74 09 80 bf 4f
  RIP  [<ffffffffa079bd62>] sd_set_streamparm+0x12/0x60 [gspca_ov534]
   RSP <ffff880095c4fce8>
  ---[ end trace 279710c2c6c72080 ]---

Following what the doc says about a zeroed timeperframe (see
http://www.linuxtv.org/downloads/v4l-dvb-apis/vidioc-g-parm.html):

  ...
  To reset manually applications can just set this field to zero.

fix the issue by resetting the frame rate to a default value in case of
an unusable timeperframe.

The fix is done in the subdrivers instead of gspca.c because only the
subdrivers have notion of a default frame rate to reset the camera to.

Signed-off-by: Antonio Ospite <ao2@ao2.it>
Reviewed-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Hans Verkuil <hans.verkuil@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
[bwh: Backported to 3.2: adjust filenames]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/media/video/gspca/ov534.c | 9 +++++++--
 drivers/media/video/gspca/topro.c | 6 +++++-
 2 files changed, 12 insertions(+), 3 deletions(-)

--- a/drivers/media/video/gspca/ov534.c
+++ b/drivers/media/video/gspca/ov534.c
@@ -1481,8 +1481,13 @@ static void sd_set_streamparm(struct gsp
 	struct v4l2_fract *tpf = &cp->timeperframe;
 	struct sd *sd = (struct sd *) gspca_dev;
 
-	/* Set requested framerate */
-	sd->frame_rate = tpf->denominator / tpf->numerator;
+	if (tpf->numerator == 0 || tpf->denominator == 0)
+		/* Set default framerate */
+		sd->frame_rate = 30;
+	else
+		/* Set requested framerate */
+		sd->frame_rate = tpf->denominator / tpf->numerator;
+
 	if (gspca_dev->streaming)
 		set_frame_rate(gspca_dev);
 
--- a/drivers/media/video/gspca/topro.c
+++ b/drivers/media/video/gspca/topro.c
@@ -4789,7 +4789,11 @@ static void sd_set_streamparm(struct gsp
 	struct v4l2_fract *tpf = &cp->timeperframe;
 	int fr, i;
 
-	sd->framerate = tpf->denominator / tpf->numerator;
+	if (tpf->numerator == 0 || tpf->denominator == 0)
+		sd->framerate = 30;
+	else
+		sd->framerate = tpf->denominator / tpf->numerator;
+
 	if (gspca_dev->streaming)
 		setframerate(gspca_dev);
 

[toc] | [prev] | [next] | [standalone]


#1329778 — [PATCH 3.2 08/87] mtd: nand: fix ONFI parameter page layout

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:30 +0100
Subject[PATCH 3.2 08/87] mtd: nand: fix ONFI parameter page layout
Message-ID<r04lP-4r7-1@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Boris BREZILLON <boris.brezillon@free-electrons.com>

commit de64aa9ec129ba627634088f662a4d09e356ddb6 upstream.

src_ssync_features field is only 1 byte large, and the 4th reserved area
is actually 8 bytes large.

Fixes: d1e1f4e42b5 ("mtd: nand: add support for reading ONFI parameters from NAND device")
Signed-off-by: Boris Brezillon <boris.brezillon@free-electrons.com>
Signed-off-by: Brian Norris <computersforpeace@gmail.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 include/linux/mtd/nand.h | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/include/linux/mtd/nand.h
+++ b/include/linux/mtd/nand.h
@@ -283,7 +283,7 @@ struct nand_onfi_params {
 	__le16 t_r;
 	__le16 t_ccs;
 	__le16 src_sync_timing_mode;
-	__le16 src_ssync_features;
+	u8 src_ssync_features;
 	__le16 clk_pin_capacitance_typ;
 	__le16 io_pin_capacitance_typ;
 	__le16 input_pin_capacitance_typ;
@@ -291,7 +291,7 @@ struct nand_onfi_params {
 	u8 driver_strenght_support;
 	__le16 t_int_r;
 	__le16 t_ald;
-	u8 reserved4[7];
+	u8 reserved4[8];
 
 	/* vendor */
 	u8 reserved5[90];

[toc] | [prev] | [next] | [standalone]


#1329779 — [PATCH 3.2 80/87] crypto: algif_hash - Fix race condition in hash_check_key

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:30 +0100
Subject[PATCH 3.2 80/87] crypto: algif_hash - Fix race condition in hash_check_key
Message-ID<r04lP-4r7-3@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit ad46d7e33219218605ea619e32553daf4f346b9f upstream.

We need to lock the child socket in hash_check_key as otherwise
two simultaneous calls can cause the parent socket to be freed.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 crypto/algif_hash.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

--- a/crypto/algif_hash.c
+++ b/crypto/algif_hash.c
@@ -253,22 +253,23 @@ static struct proto_ops algif_hash_ops =
 
 static int hash_check_key(struct socket *sock)
 {
-	int err;
+	int err = 0;
 	struct sock *psk;
 	struct alg_sock *pask;
 	struct algif_hash_tfm *tfm;
 	struct sock *sk = sock->sk;
 	struct alg_sock *ask = alg_sk(sk);
 
+	lock_sock(sk);
 	if (ask->refcnt)
-		return 0;
+		goto unlock_child;
 
 	psk = ask->parent;
 	pask = alg_sk(ask->parent);
 	tfm = pask->private;
 
 	err = -ENOKEY;
-	lock_sock(psk);
+	lock_sock_nested(psk, SINGLE_DEPTH_NESTING);
 	if (!tfm->has_key)
 		goto unlock;
 
@@ -282,6 +283,8 @@ static int hash_check_key(struct socket
 
 unlock:
 	release_sock(psk);
+unlock_child:
+	release_sock(sk);
 
 	return err;
 }

[toc] | [prev] | [next] | [standalone]


#1329780 — [PATCH 3.2 04/87] SCSI: initio: remove duplicate module device table

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:30 +0100
Subject[PATCH 3.2 04/87] SCSI: initio: remove duplicate module device table
Message-ID<r04lP-4r7-5@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Arnd Bergmann <arnd@arndb.de>

commit d282e2b383e3f41a7758e8cbf3076091ef9d9447 upstream.

The initio driver has for many years had two copies of the
same module device table. One of them is also used for registering
the other driver, the other one is entirely useless after the
large scale cleanup that Alan Cox did back in 2007.

The compiler warns about this whenever the driver is built-in:

drivers/scsi/initio.c:131:29: warning: 'i91u_pci_devices' defined but not used [-Wunused-variable]

This removes the extraneous table and the warning.

Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Fixes: 72d39fea901 ("[SCSI] initio: Convert into a real Linux driver and update to modern style")
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/scsi/initio.c | 16 ----------------
 1 file changed, 16 deletions(-)

--- a/drivers/scsi/initio.c
+++ b/drivers/scsi/initio.c
@@ -110,11 +110,6 @@
 #define i91u_MAXQUEUE		2
 #define i91u_REVID "Initio INI-9X00U/UW SCSI device driver; Revision: 1.04a"
 
-#define I950_DEVICE_ID	0x9500	/* Initio's inic-950 product ID   */
-#define I940_DEVICE_ID	0x9400	/* Initio's inic-940 product ID   */
-#define I935_DEVICE_ID	0x9401	/* Initio's inic-935 product ID   */
-#define I920_DEVICE_ID	0x0002	/* Initio's other product ID      */
-
 #ifdef DEBUG_i91u
 static unsigned int i91u_debug = DEBUG_DEFAULT;
 #endif
@@ -127,17 +122,6 @@ static int setup_debug = 0;
 
 static void i91uSCBPost(u8 * pHcb, u8 * pScb);
 
-/* PCI Devices supported by this driver */
-static struct pci_device_id i91u_pci_devices[] = {
-	{ PCI_VENDOR_ID_INIT,  I950_DEVICE_ID, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0},
-	{ PCI_VENDOR_ID_INIT,  I940_DEVICE_ID, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0},
-	{ PCI_VENDOR_ID_INIT,  I935_DEVICE_ID, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0},
-	{ PCI_VENDOR_ID_INIT,  I920_DEVICE_ID, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0},
-	{ PCI_VENDOR_ID_DOMEX, I920_DEVICE_ID, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0},
-	{ }
-};
-MODULE_DEVICE_TABLE(pci, i91u_pci_devices);
-
 #define DEBUG_INTERRUPT 0
 #define DEBUG_QUEUE     0
 #define DEBUG_STATE     0

[toc] | [prev] | [next] | [standalone]


#1329781 — [PATCH 3.2 87/87] [media] usbvision: fix crash on detecting device with invalid configuration

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:30 +0100
Subject[PATCH 3.2 87/87] [media] usbvision: fix crash on detecting device with invalid configuration
Message-ID<r04lP-4r7-7@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Vladis Dronov <vdronov@redhat.com>

commit fa52bd506f274b7619955917abfde355e3d19ffe upstream.

The usbvision driver crashes when a specially crafted usb device with invalid
number of interfaces or endpoints is detected. This fix adds checks that the
device has proper configuration expected by the driver.

Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
[bwh: Backport to 3.2: adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/media/video/usbvision/usbvision-video.c | 16 +++++++++++++++-
 1 file changed, 15 insertions(+), 1 deletion(-)

--- a/drivers/media/video/usbvision/usbvision-video.c
+++ b/drivers/media/video/usbvision/usbvision-video.c
@@ -1511,9 +1511,23 @@ static int __devinit usbvision_probe(str
 
 	if (usbvision_device_data[model].interface >= 0)
 		interface = &dev->actconfig->interface[usbvision_device_data[model].interface]->altsetting[0];
-	else
+	else if (ifnum < dev->actconfig->desc.bNumInterfaces)
 		interface = &dev->actconfig->interface[ifnum]->altsetting[0];
+	else {
+		dev_err(&intf->dev, "interface %d is invalid, max is %d\n",
+		    ifnum, dev->actconfig->desc.bNumInterfaces - 1);
+		ret = -ENODEV;
+		goto err_usb;
+	}
+
+	if (interface->desc.bNumEndpoints < 2) {
+		dev_err(&intf->dev, "interface %d has %d endpoints, but must"
+		    " have minimum 2\n", ifnum, interface->desc.bNumEndpoints);
+		ret = -ENODEV;
+		goto err_usb;
+	}
 	endpoint = &interface->endpoint[1].desc;
+
 	if (!usb_endpoint_xfer_isoc(endpoint)) {
 		dev_err(&intf->dev, "%s: interface %d. has non-ISO endpoint!\n",
 		    __func__, ifnum);

[toc] | [prev] | [next] | [standalone]


#1329782 — [PATCH 3.2 15/87] powerpc: Make value-returning atomics fully ordered

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:30 +0100
Subject[PATCH 3.2 15/87] powerpc: Make value-returning atomics fully ordered
Message-ID<r04lQ-4r7-15@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Boqun Feng <boqun.feng@gmail.com>

commit 49e9cf3f0c04bf76ffa59242254110309554861d upstream.

According to memory-barriers.txt:

> Any atomic operation that modifies some state in memory and returns
> information about the state (old or new) implies an SMP-conditional
> general memory barrier (smp_mb()) on each side of the actual
> operation ...

Which mean these operations should be fully ordered. However on PPC,
PPC_ATOMIC_ENTRY_BARRIER is the barrier before the actual operation,
which is currently "lwsync" if SMP=y. The leading "lwsync" can not
guarantee fully ordered atomics, according to Paul Mckenney:

https://lkml.org/lkml/2015/10/14/970

To fix this, we define PPC_ATOMIC_ENTRY_BARRIER as "sync" to guarantee
the fully-ordered semantics.

This also makes futex atomics fully ordered, which can avoid possible
memory ordering problems if userspace code relies on futex system call
for fully ordered semantics.

Fixes: b97021f85517 ("powerpc: Fix atomic_xxx_return barrier semantics")
Signed-off-by: Boqun Feng <boqun.feng@gmail.com>
Reviewed-by: Paul E. McKenney <paulmck@linux.vnet.ibm.com>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 arch/powerpc/include/asm/synch.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/powerpc/include/asm/synch.h
+++ b/arch/powerpc/include/asm/synch.h
@@ -44,7 +44,7 @@ static inline void isync(void)
 	MAKE_LWSYNC_SECTION_ENTRY(97, __lwsync_fixup);
 #define PPC_ACQUIRE_BARRIER	 "\n" stringify_in_c(__PPC_ACQUIRE_BARRIER)
 #define PPC_RELEASE_BARRIER	 stringify_in_c(LWSYNC) "\n"
-#define PPC_ATOMIC_ENTRY_BARRIER "\n" stringify_in_c(LWSYNC) "\n"
+#define PPC_ATOMIC_ENTRY_BARRIER "\n" stringify_in_c(sync) "\n"
 #define PPC_ATOMIC_EXIT_BARRIER	 "\n" stringify_in_c(sync) "\n"
 #else
 #define PPC_ACQUIRE_BARRIER

[toc] | [prev] | [next] | [standalone]


#1329783 — [PATCH 3.2 10/87] xhci: refuse loading if nousb is used

FromBen Hutchings <ben@decadent.org.uk>
Date2016-02-09 01:30 +0100
Subject[PATCH 3.2 10/87] xhci: refuse loading if nousb is used
Message-ID<r04lP-4r7-9@gated-at.bofh.it>
In reply to#1329762
3.2.77-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Oliver Neukum <oneukum@suse.com>

commit 1eaf35e4dd592c59041bc1ed3248c46326da1f5f upstream.

The module should fail to load.

Signed-off-by: Oliver Neukum <oneukum@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[bwh: Backported to 3.2: xhci_hcd_init() registers the PCI driver, so
 check before doing that rather than at the end of the function]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/host/xhci.c | 4 ++++
 1 file changed, 4 insertions(+)

--- a/drivers/usb/host/xhci.c
+++ b/drivers/usb/host/xhci.c
@@ -4300,6 +4300,9 @@ static int __init xhci_hcd_init(void)
 {
 	int retval;
 
+	if (usb_disabled())
+		return -ENODEV;
+
 	retval = xhci_register_pci();
 	if (retval < 0) {
 		printk(KERN_DEBUG "Problem registering PCI driver.");

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.kernel


csiph-web