Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1331957 > unrolled thread

[PATCH 3.12 00/64] 3.12.54-stable review

Started byJiri Slaby <jslaby@suse.cz>
First post2016-02-11 15:00 +0100
Last post2016-02-15 17:20 +0100
Articles 18 — 5 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.12 00/64] 3.12.54-stable review Jiri Slaby <jslaby@suse.cz> - 2016-02-11 15:00 +0100
    Re: [PATCH 3.12 00/64] 3.12.54-stable review Nikolay Borisov <kernel@kyup.com> - 2016-02-11 15:10 +0100
      Re: [PATCH 3.12 00/64] 3.12.54-stable review Jiri Slaby <jslaby@suse.cz> - 2016-02-11 15:20 +0100
        Re: [PATCH 3.12 00/64] 3.12.54-stable review Jiri Slaby <jslaby@suse.cz> - 2016-02-11 15:20 +0100
    [PATCH 3.12 65/65] dm thin: fix race condition when destroying thin pool workqueue Jiri Slaby <jslaby@suse.cz> - 2016-02-11 15:20 +0100
    [PATCH 3.12 01/64] ALSA: rme96: Fix unexpected volume reset after rate changes Jiri Slaby <jslaby@suse.cz> - 2016-02-11 15:40 +0100
      [PATCH 3.12 19/64] USB: cp210x: add ID for ELV Marble Sound Board 1 Jiri Slaby <jslaby@suse.cz> - 2016-02-11 15:40 +0100
      [PATCH 3.12 03/64] ALSA: hda - Set SKL+ hda controller power at freeze() and thaw() Jiri Slaby <jslaby@suse.cz> - 2016-02-11 15:50 +0100
      [PATCH 3.12 11/64] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode Jiri Slaby <jslaby@suse.cz> - 2016-02-11 15:50 +0100
      [PATCH 3.12 07/64] ALSA: timer: Harden slave timer list handling Jiri Slaby <jslaby@suse.cz> - 2016-02-11 15:50 +0100
      [PATCH 3.12 12/64] ALSA: hrtimer: Fix stall by hrtimer_cancel() Jiri Slaby <jslaby@suse.cz> - 2016-02-11 15:50 +0100
      [PATCH 3.12 04/64] ALSA: hda/realtek - Fix silent headphone output on MacPro 4,1 (v2) Jiri Slaby <jslaby@suse.cz> - 2016-02-11 15:50 +0100
      [PATCH 3.12 06/64] ALSA: seq: Fix race at timer setup and close Jiri Slaby <jslaby@suse.cz> - 2016-02-11 15:50 +0100
      [PATCH 3.12 05/64] ALSA: seq: Fix missing NULL check at remove_events ioctl Jiri Slaby <jslaby@suse.cz> - 2016-02-11 15:50 +0100
    Re: [PATCH 3.12 00/64] 3.12.54-stable review Guenter Roeck <linux@roeck-us.net> - 2016-02-11 19:20 +0100
    Re: [PATCH 3.12 00/64] 3.12.54-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-02-11 20:30 +0100
      Re: [PATCH 3.12 00/64] 3.12.54-stable review Jiri Slaby <jslaby@suse.cz> - 2016-02-15 16:30 +0100
        RE: [PATCH 3.12 00/64] 3.12.54-stable review "Winkler, Tomas" <tomas.winkler@intel.com> - 2016-02-15 17:20 +0100

#1331957 — [PATCH 3.12 00/64] 3.12.54-stable review

FromJiri Slaby <jslaby@suse.cz>
Date2016-02-11 15:00 +0100
Subject[PATCH 3.12 00/64] 3.12.54-stable review
Message-ID<r0ZWO-17m-3@gated-at.bofh.it>
This is the start of the stable review cycle for the 3.12.54 release.
There are 64 patches in this series, all will be posted as a response
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Mon Feb 15 14:54:53 CET 2016.
Anything received after that time might be too late.

The whole patch series can be found in one patch at:
	http://kernel.org/pub/linux/kernel/people/jirislaby/stable-review/patch-3.12.54-rc1.xz
and the diffstat can be found below.

thanks,
js

===============


Alex Deucher (1):
  drm/radeon: cypress_dpm: Fix unused variable warning when
    CONFIG_ACPI=n

Andrew Morton (1):
  openrisc: fix CONFIG_UID16 setting

Andrey Ryabinin (1):
  ipv6/addrlabel: fix ip6addrlbl_get()

Arnd Bergmann (2):
  mISDN: avoid arch specific __builtin_return_address call
  arm64: fix building without CONFIG_UID16

Behan Webster (1):
  ARM: 8158/1: LLVMLinux: use static inline in ARM ftrace.h

Boqun Feng (2):
  powerpc: Make value-returning atomics fully ordered
  powerpc: Make {cmp}xchg* and their atomic_ versions fully ordered

Chunfeng Yun (1):
  usb: xhci: fix config fail of FS hub behind a HS hub with MTT

Dan Carpenter (1):
  USB: ipaq.c: fix a timeout loop

Dan Streetman (1):
  xfrm: dst_entries_init() per-net dst_ops

David Henningsson (1):
  ALSA: hda - Add inverted dmic for Packard Bell DOTS

Eric Dumazet (3):
  ipv6: tcp: add rcu locking in tcp_v6_send_synack()
  phonet: properly unshare skbs in phonet_rcv()
  ipv6: update skb->csum when CE mark is propagated

Fabio Estevam (1):
  drm: radeon: ni_dpm: Fix unused variable warning when CONFIG_ACPI=n

Florian Westphal (1):
  connector: bump skb->users before callback invocation

Greg Kroah-Hartman (1):
  xhci: fix placement of call to usb_disabled()

Guenter Roeck (1):
  mn10300: Select CONFIG_HAVE_UID16 to fix build failure

Hannes Frederic Sowa (1):
  bridge: Only call /sbin/bridge-stp for the initial network namespace

Herbert Xu (1):
  crypto: algif_hash - Only export and import on sockets with data

Ido Schimmel (1):
  team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid

Ioan-Adrian Ratiu (1):
  HID: usbhid: fix recursive deadlock

Jiri Slaby (1):
  x86: vvar, fix excessive gcc-6 DECLARE_VVAR warnings

Joe Perches (1):
  compiler-gcc: integrate the various compiler-gcc[345].h files

John Blackwood (1):
  arm64: Clear out any singlestep state on a ptrace detach operation

Kees Cook (1):
  lkdtm: adjust recursion size to avoid warnings

Linus Torvalds (1):
  vmstat: explicitly schedule per-cpu work on the CPU we need it to run
    on

Marc Zyngier (1):
  arm64: KVM: Fix AArch32 to AArch64 register mapping

Mario Kleiner (1):
  ALSA: hda/realtek - Fix silent headphone output on MacPro 4,1 (v2)

Michael Neuling (1):
  powerpc/tm: Block signal return setting invalid MSR state

Mike Snitzer (1):
  dm btree: fix leak of bufio-backed block in btree_split_sibling error
    path

Mikulas Patocka (1):
  parisc iommu: fix panic due to trying to allocate too large region

Neal Cardwell (1):
  tcp_yeah: don't set ssthresh below 2

Nicolas Boichat (2):
  ALSA: seq: Fix snd_seq_call_port_info_ioctl in compat mode
  ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode

Nikesh Oswal (1):
  ASoC: arizona: Fix bclk for sample rates that are multiple of 4kHz

Oliver Freyermuth (1):
  USB: cp210x: add ID for ELV Marble Sound Board 1

Oliver Neukum (1):
  xhci: refuse loading if nousb is used

Paul Bolle (1):
  RDMA/cxgb4: Fix gcc warning on 32-bit arch

Richard Purdie (1):
  HID: core: Avoid uninitialized buffer access

Sachin Pandhare (1):
  ASoC: wm8962: correct addresses for HPF_C_0/1

Sasha Levin (1):
  net: sctp: prevent writes to cookie_hmac_alg from accessing invalid
    memory

Seth Jennings (1):
  drivers/base/memory.c: prohibit offlining of memory blocks with
    missing sections

Steven Noonan (1):
  compiler/gcc4+: Remove inaccurate comment about 'asm goto' miscompiles

Takashi Iwai (8):
  ALSA: rme96: Fix unexpected volume reset after rate changes
  ALSA: seq: Fix missing NULL check at remove_events ioctl
  ALSA: seq: Fix race at timer setup and close
  ALSA: timer: Harden slave timer list handling
  ALSA: timer: Fix race among timer ioctls
  ALSA: timer: Fix double unlink of active_list
  ALSA: hrtimer: Fix stall by hrtimer_cancel()
  ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0

Tejun Heo (1):
  Revert "workqueue: make sure delayed work run in local cpu"

Ulrich Weigand (1):
  scripts/recordmcount.pl: support data in text section on powerpc

Uwe Kleine-König (1):
  ARM: 8160/1: drop warning about return_address not using unwind tables

Vijay Pandurangan (1):
  veth: don’t modify ip_summed; doing so treats packets with bad
    checksums as good.

Vinod Koul (1):
  ASoC: compress: Fix compress device direction check

Will Deacon (1):
  arm64: mm: ensure that the zero page is visible to the page table
    walker

Xin Long (1):
  sctp: sctp should release assoc when sctp_make_abort_user return NULL
    in sctp_close

Xiong Zhang (1):
  ALSA: hda - Set SKL+ hda controller power at freeze() and thaw()

Yang Shi (1):
  arm64: restore bogomips information in /proc/cpuinfo

libin (1):
  recordmcount: Fix endianness handling bug for nop_mcount

willy tarreau (1):
  unix: properly account for FDs passed over unix sockets

 arch/arm/include/asm/ftrace.h           |   2 +-
 arch/arm/kernel/return_address.c        |   9 ---
 arch/arm64/include/asm/kvm_emulate.h    |   8 ++-
 arch/arm64/kernel/ptrace.c              |   6 ++
 arch/arm64/kernel/setup.c               |   4 ++
 arch/arm64/kvm/inject_fault.c           |   2 +-
 arch/arm64/mm/mmu.c                     |   3 +
 arch/mn10300/Kconfig                    |   4 +-
 arch/openrisc/Kconfig                   |   4 +-
 arch/powerpc/include/asm/cmpxchg.h      |  16 ++---
 arch/powerpc/include/asm/reg.h          |   1 +
 arch/powerpc/include/asm/synch.h        |   2 +-
 arch/powerpc/kernel/signal_32.c         |  14 ++--
 arch/powerpc/kernel/signal_64.c         |   4 ++
 arch/x86/include/asm/vvar.h             |   2 +-
 crypto/algif_hash.c                     |  12 +++-
 drivers/base/memory.c                   |   4 ++
 drivers/connector/connector.c           |  11 +--
 drivers/gpu/drm/radeon/cypress_dpm.c    |   2 +
 drivers/gpu/drm/radeon/ni_dpm.c         |   2 +-
 drivers/hid/hid-core.c                  |   2 +-
 drivers/hid/usbhid/hid-core.c           |   4 +-
 drivers/infiniband/hw/cxgb4/mem.c       |   2 +-
 drivers/isdn/hardware/mISDN/mISDNipac.c |  12 +++-
 drivers/isdn/hardware/mISDN/w6692.c     |   6 +-
 drivers/md/persistent-data/dm-btree.c   |   4 +-
 drivers/misc/lkdtm.c                    |  30 ++++++---
 drivers/net/team/team.c                 |   6 +-
 drivers/net/veth.c                      |   6 --
 drivers/parisc/iommu-helpers.h          |  15 +++--
 drivers/usb/host/xhci.c                 |  12 ++++
 drivers/usb/serial/cp210x.c             |   1 +
 drivers/usb/serial/ipaq.c               |   3 +-
 include/linux/compiler-gcc.h            | 114 ++++++++++++++++++++++++++++++--
 include/linux/compiler-gcc3.h           |  23 -------
 include/linux/compiler-gcc4.h           |  88 ------------------------
 include/linux/compiler-gcc5.h           |  66 ------------------
 include/linux/sched.h                   |   1 +
 include/linux/syscalls.h                |   2 +-
 include/linux/types.h                   |   2 +-
 include/net/inet_ecn.h                  |  19 +++++-
 kernel/workqueue.c                      |   8 +--
 mm/vmstat.c                             |   3 +-
 net/bridge/br_stp_if.c                  |   5 +-
 net/ipv4/tcp_yeah.c                     |   2 +-
 net/ipv4/xfrm4_policy.c                 |  46 ++++++++++---
 net/ipv6/addrlabel.c                    |   2 +-
 net/ipv6/tcp_ipv6.c                     |   2 +
 net/ipv6/xfrm6_mode_tunnel.c            |   2 +-
 net/ipv6/xfrm6_policy.c                 |  53 ++++++++++-----
 net/phonet/af_phonet.c                  |   4 ++
 net/sctp/sm_statefuns.c                 |   6 +-
 net/sctp/socket.c                       |   3 +-
 net/sctp/sysctl.c                       |   2 +-
 net/unix/af_unix.c                      |  24 +++++--
 net/unix/garbage.c                      |  16 +++--
 net/xfrm/xfrm_policy.c                  |  38 -----------
 scripts/recordmcount.h                  |   2 +-
 scripts/recordmcount.pl                 |   3 +-
 sound/core/control.c                    |   2 +
 sound/core/hrtimer.c                    |   3 +-
 sound/core/pcm_compat.c                 |  13 ++--
 sound/core/seq/seq_clientmgr.c          |   2 +-
 sound/core/seq/seq_compat.c             |   9 +--
 sound/core/seq/seq_queue.c              |   2 +
 sound/core/timer.c                      |  52 ++++++++++-----
 sound/pci/hda/hda_intel.c               |  34 ++++++++++
 sound/pci/hda/patch_realtek.c           |  12 +++-
 sound/pci/rme96.c                       |  41 +++++++-----
 sound/soc/codecs/arizona.c              |   2 +-
 sound/soc/codecs/wm8962.c               |   4 +-
 sound/soc/soc-compress.c                |  23 ++++++-
 72 files changed, 543 insertions(+), 407 deletions(-)
 delete mode 100644 include/linux/compiler-gcc3.h
 delete mode 100644 include/linux/compiler-gcc4.h
 delete mode 100644 include/linux/compiler-gcc5.h

-- 
2.7.1

[toc] | [next] | [standalone]


#1331993

FromNikolay Borisov <kernel@kyup.com>
Date2016-02-11 15:10 +0100
Message-ID<r106w-1qh-67@gated-at.bofh.it>
In reply to#1331957
Hi Jiri,

I think this commit should also be included:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=18d03e8c25f173f4107a40d0b8c24defb6ed69f3

On 02/11/2016 03:59 PM, Jiri Slaby wrote:
> This is the start of the stable review cycle for the 3.12.54 release.
> There are 64 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Mon Feb 15 14:54:53 CET 2016.
> Anything received after that time might be too late.
> 
> The whole patch series can be found in one patch at:
> 	http://kernel.org/pub/linux/kernel/people/jirislaby/stable-review/patch-3.12.54-rc1.xz
> and the diffstat can be found below.
> 
> thanks,
> js
> 
> ===============
> 
> 
> Alex Deucher (1):
>   drm/radeon: cypress_dpm: Fix unused variable warning when
>     CONFIG_ACPI=n
> 
> Andrew Morton (1):
>   openrisc: fix CONFIG_UID16 setting
> 
> Andrey Ryabinin (1):
>   ipv6/addrlabel: fix ip6addrlbl_get()
> 
> Arnd Bergmann (2):
>   mISDN: avoid arch specific __builtin_return_address call
>   arm64: fix building without CONFIG_UID16
> 
> Behan Webster (1):
>   ARM: 8158/1: LLVMLinux: use static inline in ARM ftrace.h
> 
> Boqun Feng (2):
>   powerpc: Make value-returning atomics fully ordered
>   powerpc: Make {cmp}xchg* and their atomic_ versions fully ordered
> 
> Chunfeng Yun (1):
>   usb: xhci: fix config fail of FS hub behind a HS hub with MTT
> 
> Dan Carpenter (1):
>   USB: ipaq.c: fix a timeout loop
> 
> Dan Streetman (1):
>   xfrm: dst_entries_init() per-net dst_ops
> 
> David Henningsson (1):
>   ALSA: hda - Add inverted dmic for Packard Bell DOTS
> 
> Eric Dumazet (3):
>   ipv6: tcp: add rcu locking in tcp_v6_send_synack()
>   phonet: properly unshare skbs in phonet_rcv()
>   ipv6: update skb->csum when CE mark is propagated
> 
> Fabio Estevam (1):
>   drm: radeon: ni_dpm: Fix unused variable warning when CONFIG_ACPI=n
> 
> Florian Westphal (1):
>   connector: bump skb->users before callback invocation
> 
> Greg Kroah-Hartman (1):
>   xhci: fix placement of call to usb_disabled()
> 
> Guenter Roeck (1):
>   mn10300: Select CONFIG_HAVE_UID16 to fix build failure
> 
> Hannes Frederic Sowa (1):
>   bridge: Only call /sbin/bridge-stp for the initial network namespace
> 
> Herbert Xu (1):
>   crypto: algif_hash - Only export and import on sockets with data
> 
> Ido Schimmel (1):
>   team: Replace rcu_read_lock with a mutex in team_vlan_rx_kill_vid
> 
> Ioan-Adrian Ratiu (1):
>   HID: usbhid: fix recursive deadlock
> 
> Jiri Slaby (1):
>   x86: vvar, fix excessive gcc-6 DECLARE_VVAR warnings
> 
> Joe Perches (1):
>   compiler-gcc: integrate the various compiler-gcc[345].h files
> 
> John Blackwood (1):
>   arm64: Clear out any singlestep state on a ptrace detach operation
> 
> Kees Cook (1):
>   lkdtm: adjust recursion size to avoid warnings
> 
> Linus Torvalds (1):
>   vmstat: explicitly schedule per-cpu work on the CPU we need it to run
>     on
> 
> Marc Zyngier (1):
>   arm64: KVM: Fix AArch32 to AArch64 register mapping
> 
> Mario Kleiner (1):
>   ALSA: hda/realtek - Fix silent headphone output on MacPro 4,1 (v2)
> 
> Michael Neuling (1):
>   powerpc/tm: Block signal return setting invalid MSR state
> 
> Mike Snitzer (1):
>   dm btree: fix leak of bufio-backed block in btree_split_sibling error
>     path
> 
> Mikulas Patocka (1):
>   parisc iommu: fix panic due to trying to allocate too large region
> 
> Neal Cardwell (1):
>   tcp_yeah: don't set ssthresh below 2
> 
> Nicolas Boichat (2):
>   ALSA: seq: Fix snd_seq_call_port_info_ioctl in compat mode
>   ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode
> 
> Nikesh Oswal (1):
>   ASoC: arizona: Fix bclk for sample rates that are multiple of 4kHz
> 
> Oliver Freyermuth (1):
>   USB: cp210x: add ID for ELV Marble Sound Board 1
> 
> Oliver Neukum (1):
>   xhci: refuse loading if nousb is used
> 
> Paul Bolle (1):
>   RDMA/cxgb4: Fix gcc warning on 32-bit arch
> 
> Richard Purdie (1):
>   HID: core: Avoid uninitialized buffer access
> 
> Sachin Pandhare (1):
>   ASoC: wm8962: correct addresses for HPF_C_0/1
> 
> Sasha Levin (1):
>   net: sctp: prevent writes to cookie_hmac_alg from accessing invalid
>     memory
> 
> Seth Jennings (1):
>   drivers/base/memory.c: prohibit offlining of memory blocks with
>     missing sections
> 
> Steven Noonan (1):
>   compiler/gcc4+: Remove inaccurate comment about 'asm goto' miscompiles
> 
> Takashi Iwai (8):
>   ALSA: rme96: Fix unexpected volume reset after rate changes
>   ALSA: seq: Fix missing NULL check at remove_events ioctl
>   ALSA: seq: Fix race at timer setup and close
>   ALSA: timer: Harden slave timer list handling
>   ALSA: timer: Fix race among timer ioctls
>   ALSA: timer: Fix double unlink of active_list
>   ALSA: hrtimer: Fix stall by hrtimer_cancel()
>   ALSA: control: Avoid kernel warnings from tlv ioctl with numid 0
> 
> Tejun Heo (1):
>   Revert "workqueue: make sure delayed work run in local cpu"
> 
> Ulrich Weigand (1):
>   scripts/recordmcount.pl: support data in text section on powerpc
> 
> Uwe Kleine-König (1):
>   ARM: 8160/1: drop warning about return_address not using unwind tables
> 
> Vijay Pandurangan (1):
>   veth: don’t modify ip_summed; doing so treats packets with bad
>     checksums as good.
> 
> Vinod Koul (1):
>   ASoC: compress: Fix compress device direction check
> 
> Will Deacon (1):
>   arm64: mm: ensure that the zero page is visible to the page table
>     walker
> 
> Xin Long (1):
>   sctp: sctp should release assoc when sctp_make_abort_user return NULL
>     in sctp_close
> 
> Xiong Zhang (1):
>   ALSA: hda - Set SKL+ hda controller power at freeze() and thaw()
> 
> Yang Shi (1):
>   arm64: restore bogomips information in /proc/cpuinfo
> 
> libin (1):
>   recordmcount: Fix endianness handling bug for nop_mcount
> 
> willy tarreau (1):
>   unix: properly account for FDs passed over unix sockets
> 
>  arch/arm/include/asm/ftrace.h           |   2 +-
>  arch/arm/kernel/return_address.c        |   9 ---
>  arch/arm64/include/asm/kvm_emulate.h    |   8 ++-
>  arch/arm64/kernel/ptrace.c              |   6 ++
>  arch/arm64/kernel/setup.c               |   4 ++
>  arch/arm64/kvm/inject_fault.c           |   2 +-
>  arch/arm64/mm/mmu.c                     |   3 +
>  arch/mn10300/Kconfig                    |   4 +-
>  arch/openrisc/Kconfig                   |   4 +-
>  arch/powerpc/include/asm/cmpxchg.h      |  16 ++---
>  arch/powerpc/include/asm/reg.h          |   1 +
>  arch/powerpc/include/asm/synch.h        |   2 +-
>  arch/powerpc/kernel/signal_32.c         |  14 ++--
>  arch/powerpc/kernel/signal_64.c         |   4 ++
>  arch/x86/include/asm/vvar.h             |   2 +-
>  crypto/algif_hash.c                     |  12 +++-
>  drivers/base/memory.c                   |   4 ++
>  drivers/connector/connector.c           |  11 +--
>  drivers/gpu/drm/radeon/cypress_dpm.c    |   2 +
>  drivers/gpu/drm/radeon/ni_dpm.c         |   2 +-
>  drivers/hid/hid-core.c                  |   2 +-
>  drivers/hid/usbhid/hid-core.c           |   4 +-
>  drivers/infiniband/hw/cxgb4/mem.c       |   2 +-
>  drivers/isdn/hardware/mISDN/mISDNipac.c |  12 +++-
>  drivers/isdn/hardware/mISDN/w6692.c     |   6 +-
>  drivers/md/persistent-data/dm-btree.c   |   4 +-
>  drivers/misc/lkdtm.c                    |  30 ++++++---
>  drivers/net/team/team.c                 |   6 +-
>  drivers/net/veth.c                      |   6 --
>  drivers/parisc/iommu-helpers.h          |  15 +++--
>  drivers/usb/host/xhci.c                 |  12 ++++
>  drivers/usb/serial/cp210x.c             |   1 +
>  drivers/usb/serial/ipaq.c               |   3 +-
>  include/linux/compiler-gcc.h            | 114 ++++++++++++++++++++++++++++++--
>  include/linux/compiler-gcc3.h           |  23 -------
>  include/linux/compiler-gcc4.h           |  88 ------------------------
>  include/linux/compiler-gcc5.h           |  66 ------------------
>  include/linux/sched.h                   |   1 +
>  include/linux/syscalls.h                |   2 +-
>  include/linux/types.h                   |   2 +-
>  include/net/inet_ecn.h                  |  19 +++++-
>  kernel/workqueue.c                      |   8 +--
>  mm/vmstat.c                             |   3 +-
>  net/bridge/br_stp_if.c                  |   5 +-
>  net/ipv4/tcp_yeah.c                     |   2 +-
>  net/ipv4/xfrm4_policy.c                 |  46 ++++++++++---
>  net/ipv6/addrlabel.c                    |   2 +-
>  net/ipv6/tcp_ipv6.c                     |   2 +
>  net/ipv6/xfrm6_mode_tunnel.c            |   2 +-
>  net/ipv6/xfrm6_policy.c                 |  53 ++++++++++-----
>  net/phonet/af_phonet.c                  |   4 ++
>  net/sctp/sm_statefuns.c                 |   6 +-
>  net/sctp/socket.c                       |   3 +-
>  net/sctp/sysctl.c                       |   2 +-
>  net/unix/af_unix.c                      |  24 +++++--
>  net/unix/garbage.c                      |  16 +++--
>  net/xfrm/xfrm_policy.c                  |  38 -----------
>  scripts/recordmcount.h                  |   2 +-
>  scripts/recordmcount.pl                 |   3 +-
>  sound/core/control.c                    |   2 +
>  sound/core/hrtimer.c                    |   3 +-
>  sound/core/pcm_compat.c                 |  13 ++--
>  sound/core/seq/seq_clientmgr.c          |   2 +-
>  sound/core/seq/seq_compat.c             |   9 +--
>  sound/core/seq/seq_queue.c              |   2 +
>  sound/core/timer.c                      |  52 ++++++++++-----
>  sound/pci/hda/hda_intel.c               |  34 ++++++++++
>  sound/pci/hda/patch_realtek.c           |  12 +++-
>  sound/pci/rme96.c                       |  41 +++++++-----
>  sound/soc/codecs/arizona.c              |   2 +-
>  sound/soc/codecs/wm8962.c               |   4 +-
>  sound/soc/soc-compress.c                |  23 ++++++-
>  72 files changed, 543 insertions(+), 407 deletions(-)
>  delete mode 100644 include/linux/compiler-gcc3.h
>  delete mode 100644 include/linux/compiler-gcc4.h
>  delete mode 100644 include/linux/compiler-gcc5.h
> 

[toc] | [prev] | [next] | [standalone]


#1332021

FromJiri Slaby <jslaby@suse.cz>
Date2016-02-11 15:20 +0100
Message-ID<r10gc-1uu-57@gated-at.bofh.it>
In reply to#1331993
On 02/11/2016, 03:09 PM, Nikolay Borisov wrote:
> Hi Jiri,
> 
> I think this commit should also be included:
> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=18d03e8c25f173f4107a40d0b8c24defb6ed69f3

Hi,

given it is marked as:
    Fixes: 905e51b39a555 ("dm thin: commit outstanding data every second")
    Fixes: 85ad643b7e7e5 ("dm thin: add timeout to stop
out-of-data-space mode holding IO forever")


and neither is in 3.12, why do you think so?

thanks,
-- 
js
suse labs

[toc] | [prev] | [next] | [standalone]


#1332032

FromJiri Slaby <jslaby@suse.cz>
Date2016-02-11 15:20 +0100
Message-ID<r10gd-1uu-77@gated-at.bofh.it>
In reply to#1332021
On 02/11/2016, 03:10 PM, Jiri Slaby wrote:
> On 02/11/2016, 03:09 PM, Nikolay Borisov wrote:
>> Hi Jiri,
>>
>> I think this commit should also be included:
>> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=18d03e8c25f173f4107a40d0b8c24defb6ed69f3
> 
> Hi,
> 
> given it is marked as:
>     Fixes: 905e51b39a555 ("dm thin: commit outstanding data every second")
>     Fixes: 85ad643b7e7e5 ("dm thin: add timeout to stop
> out-of-data-space mode holding IO forever")
> 
> 
> and neither is in 3.12, why do you think so?

Actually, it is. I will queue it up. Thanks.

-- 
js
suse labs

[toc] | [prev] | [next] | [standalone]


#1332005 — [PATCH 3.12 65/65] dm thin: fix race condition when destroying thin pool workqueue

FromJiri Slaby <jslaby@suse.cz>
Date2016-02-11 15:20 +0100
Subject[PATCH 3.12 65/65] dm thin: fix race condition when destroying thin pool workqueue
Message-ID<r10ga-1uu-17@gated-at.bofh.it>
In reply to#1331957
From: Nikolay Borisov <kernel@kyup.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 18d03e8c25f173f4107a40d0b8c24defb6ed69f3 upstream.

When a thin pool is being destroyed delayed work items are
cancelled using cancel_delayed_work(), which doesn't guarantee that on
return the delayed item isn't running.  This can cause the work item to
requeue itself on an already destroyed workqueue.  Fix this by using
cancel_delayed_work_sync() which guarantees that on return the work item
is not running anymore.

Fixes: 905e51b39a555 ("dm thin: commit outstanding data every second")
Fixes: 85ad643b7e7e5 ("dm thin: add timeout to stop out-of-data-space mode holding IO forever")
Signed-off-by: Nikolay Borisov <kernel@kyup.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Cc: Nikolay Borisov <kernel@kyup.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/md/dm-thin.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/md/dm-thin.c b/drivers/md/dm-thin.c
index 5ff934102f30..d14d1c1fff8b 100644
--- a/drivers/md/dm-thin.c
+++ b/drivers/md/dm-thin.c
@@ -2331,7 +2331,7 @@ static void pool_postsuspend(struct dm_target *ti)
 	struct pool_c *pt = ti->private;
 	struct pool *pool = pt->pool;
 
-	cancel_delayed_work(&pool->waker);
+	cancel_delayed_work_sync(&pool->waker);
 	flush_workqueue(pool->wq);
 	(void) commit(pool);
 }
-- 
2.7.1

[toc] | [prev] | [next] | [standalone]


#1332095 — [PATCH 3.12 01/64] ALSA: rme96: Fix unexpected volume reset after rate changes

FromJiri Slaby <jslaby@suse.cz>
Date2016-02-11 15:40 +0100
Subject[PATCH 3.12 01/64] ALSA: rme96: Fix unexpected volume reset after rate changes
Message-ID<r0ZWP-17m-23@gated-at.bofh.it>
In reply to#1331957
From: Takashi Iwai <tiwai@suse.de>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit a74a821624c0c75388a193337babd17a8c02c740 upstream.

rme96 driver needs to reset DAC depending on the sample rate, and this
results in resetting to the max volume suddenly.  It's because of the
missing call of snd_rme96_apply_dac_volume().

However, calling this function right after the DAC reset still may not
work, and we need some delay before this call.  Since the DAC reset
and the procedure after that are performed in the spinlock, we delay
the DAC volume restore at the end after the spinlock.

Reported-and-tested-by: Sylvain LABOISNE <maeda1@free.fr>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 sound/pci/rme96.c | 41 ++++++++++++++++++++++++++---------------
 1 file changed, 26 insertions(+), 15 deletions(-)

diff --git a/sound/pci/rme96.c b/sound/pci/rme96.c
index bb9ebc5543d7..2da24272e6a5 100644
--- a/sound/pci/rme96.c
+++ b/sound/pci/rme96.c
@@ -744,10 +744,11 @@ snd_rme96_playback_setrate(struct rme96 *rme96,
 	{
 		/* change to/from double-speed: reset the DAC (if available) */
 		snd_rme96_reset_dac(rme96);
+		return 1; /* need to restore volume */
 	} else {
 		writel(rme96->wcreg, rme96->iobase + RME96_IO_CONTROL_REGISTER);
+		return 0;
 	}
-	return 0;
 }
 
 static int
@@ -985,6 +986,7 @@ snd_rme96_playback_hw_params(struct snd_pcm_substream *substream,
 	struct rme96 *rme96 = snd_pcm_substream_chip(substream);
 	struct snd_pcm_runtime *runtime = substream->runtime;
 	int err, rate, dummy;
+	bool apply_dac_volume = false;
 
 	runtime->dma_area = (void __force *)(rme96->iobase +
 					     RME96_IO_PLAY_BUFFER);
@@ -998,24 +1000,26 @@ snd_rme96_playback_hw_params(struct snd_pcm_substream *substream,
 	{
                 /* slave clock */
                 if ((int)params_rate(params) != rate) {
-			spin_unlock_irq(&rme96->lock);
-			return -EIO;                    
-                }
-	} else if ((err = snd_rme96_playback_setrate(rme96, params_rate(params))) < 0) {
-		spin_unlock_irq(&rme96->lock);
-		return err;
-	}
-	if ((err = snd_rme96_playback_setformat(rme96, params_format(params))) < 0) {
-		spin_unlock_irq(&rme96->lock);
-		return err;
+			err = -EIO;
+			goto error;
+		}
+	} else {
+		err = snd_rme96_playback_setrate(rme96, params_rate(params));
+		if (err < 0)
+			goto error;
+		apply_dac_volume = err > 0; /* need to restore volume later? */
 	}
+
+	err = snd_rme96_playback_setformat(rme96, params_format(params));
+	if (err < 0)
+		goto error;
 	snd_rme96_setframelog(rme96, params_channels(params), 1);
 	if (rme96->capture_periodsize != 0) {
 		if (params_period_size(params) << rme96->playback_frlog !=
 		    rme96->capture_periodsize)
 		{
-			spin_unlock_irq(&rme96->lock);
-			return -EBUSY;
+			err = -EBUSY;
+			goto error;
 		}
 	}
 	rme96->playback_periodsize =
@@ -1026,9 +1030,16 @@ snd_rme96_playback_hw_params(struct snd_pcm_substream *substream,
 		rme96->wcreg &= ~(RME96_WCR_PRO | RME96_WCR_DOLBY | RME96_WCR_EMP);
 		writel(rme96->wcreg |= rme96->wcreg_spdif_stream, rme96->iobase + RME96_IO_CONTROL_REGISTER);
 	}
+
+	err = 0;
+ error:
 	spin_unlock_irq(&rme96->lock);
-		
-	return 0;
+	if (apply_dac_volume) {
+		usleep_range(3000, 10000);
+		snd_rme96_apply_dac_volume(rme96);
+	}
+
+	return err;
 }
 
 static int
-- 
2.7.1

[toc] | [prev] | [next] | [standalone]


#1332099 — [PATCH 3.12 19/64] USB: cp210x: add ID for ELV Marble Sound Board 1

FromJiri Slaby <jslaby@suse.cz>
Date2016-02-11 15:40 +0100
Subject[PATCH 3.12 19/64] USB: cp210x: add ID for ELV Marble Sound Board 1
Message-ID<r10zz-1Ec-77@gated-at.bofh.it>
In reply to#1332095
From: Oliver Freyermuth <o.freyermuth@googlemail.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit f7d7f59ab124748156ea551edf789994f05da342 upstream.

Add the USB device ID for ELV Marble Sound Board 1.

Signed-off-by: Oliver Freyermuth <o.freyermuth@googlemail.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/usb/serial/cp210x.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/usb/serial/cp210x.c b/drivers/usb/serial/cp210x.c
index 3597be0a5ae4..9a3c0f76db8c 100644
--- a/drivers/usb/serial/cp210x.c
+++ b/drivers/usb/serial/cp210x.c
@@ -160,6 +160,7 @@ static const struct usb_device_id id_table[] = {
 	{ USB_DEVICE(0x17F4, 0xAAAA) }, /* Wavesense Jazz blood glucose meter */
 	{ USB_DEVICE(0x1843, 0x0200) }, /* Vaisala USB Instrument Cable */
 	{ USB_DEVICE(0x18EF, 0xE00F) }, /* ELV USB-I2C-Interface */
+	{ USB_DEVICE(0x18EF, 0xE025) }, /* ELV Marble Sound Board 1 */
 	{ USB_DEVICE(0x1ADB, 0x0001) }, /* Schweitzer Engineering C662 Cable */
 	{ USB_DEVICE(0x1B1C, 0x1C00) }, /* Corsair USB Dongle */
 	{ USB_DEVICE(0x1BA4, 0x0002) },	/* Silicon Labs 358x factory default */
-- 
2.7.1

[toc] | [prev] | [next] | [standalone]


#1332104 — [PATCH 3.12 03/64] ALSA: hda - Set SKL+ hda controller power at freeze() and thaw()

FromJiri Slaby <jslaby@suse.cz>
Date2016-02-11 15:50 +0100
Subject[PATCH 3.12 03/64] ALSA: hda - Set SKL+ hda controller power at freeze() and thaw()
Message-ID<r10Jb-1HE-13@gated-at.bofh.it>
In reply to#1332095
From: Xiong Zhang <xiong.y.zhang@intel.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 3e6db33aaf1d42a30339f831ec4850570d6cc7a3 upstream.

It takes three minutes to enter into hibernation on some OEM SKL
machines and we see many codec spurious response after thaw() opertion.
This is because HDA is still in D0 state after freeze() call and
pci_pm_freeze/pci_pm_freeze_noirq() don't set D3 hot in pci_bus driver.
It seems bios still access HDA when system enter into freeze state,
HDA will receive codec response interrupt immediately after thaw() call.
Because of this unexpected interrupt, HDA enter into a abnormal
state and slow down the system enter into hibernation.

In this patch, we put HDA into D3 hot state in azx_freeze_noirq() and
put HDA into D0 state in azx_thaw_noirq().

V2: Only apply this fix to SKL+
    Fix compile error when CONFIG_PM_SLEEP isn't defined

[Yet another fix for CONFIG_PM_SLEEP ifdef and the additional comment
 by tiwai]

Signed-off-by: Xiong Zhang <xiong.y.zhang@intel.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 sound/pci/hda/hda_intel.c | 34 ++++++++++++++++++++++++++++++++++
 1 file changed, 34 insertions(+)

diff --git a/sound/pci/hda/hda_intel.c b/sound/pci/hda/hda_intel.c
index baf12f1a2820..6a5e36dc23e5 100644
--- a/sound/pci/hda/hda_intel.c
+++ b/sound/pci/hda/hda_intel.c
@@ -1180,6 +1180,36 @@ static unsigned int azx_get_response(struct hda_bus *bus,
 		return azx_rirb_get_response(bus, addr);
 }
 
+#ifdef CONFIG_PM_SLEEP
+/* put codec down to D3 at hibernation for Intel SKL+;
+ * otherwise BIOS may still access the codec and screw up the driver
+ */
+#define IS_SKL(pci) ((pci)->vendor == 0x8086 && (pci)->device == 0xa170)
+#define IS_SKL_LP(pci) ((pci)->vendor == 0x8086 && (pci)->device == 0x9d70)
+#define IS_BXT(pci) ((pci)->vendor == 0x8086 && (pci)->device == 0x5a98)
+#define IS_SKL_PLUS(pci) (IS_SKL(pci) || IS_SKL_LP(pci) || IS_BXT(pci))
+
+static int azx_freeze_noirq(struct device *dev)
+{
+	struct pci_dev *pci = to_pci_dev(dev);
+
+	if (IS_SKL_PLUS(pci))
+		pci_set_power_state(pci, PCI_D3hot);
+
+	return 0;
+}
+
+static int azx_thaw_noirq(struct device *dev)
+{
+	struct pci_dev *pci = to_pci_dev(dev);
+
+	if (IS_SKL_PLUS(pci))
+		pci_set_power_state(pci, PCI_D0);
+
+	return 0;
+}
+#endif /* CONFIG_PM_SLEEP */
+
 #ifdef CONFIG_PM
 static void azx_power_notify(struct hda_bus *bus, bool power_up);
 #endif
@@ -3139,6 +3169,10 @@ static int azx_runtime_idle(struct device *dev)
 #ifdef CONFIG_PM
 static const struct dev_pm_ops azx_pm = {
 	SET_SYSTEM_SLEEP_PM_OPS(azx_suspend, azx_resume)
+#ifdef CONFIG_PM_SLEEP
+	.freeze_noirq = azx_freeze_noirq,
+	.thaw_noirq = azx_thaw_noirq,
+#endif
 	SET_RUNTIME_PM_OPS(azx_runtime_suspend, azx_runtime_resume, azx_runtime_idle)
 };
 
-- 
2.7.1

[toc] | [prev] | [next] | [standalone]


#1332106 — [PATCH 3.12 11/64] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode

FromJiri Slaby <jslaby@suse.cz>
Date2016-02-11 15:50 +0100
Subject[PATCH 3.12 11/64] ALSA: pcm: Fix snd_pcm_hw_params struct copy in compat mode
Message-ID<r10Jb-1HE-11@gated-at.bofh.it>
In reply to#1332095
From: Nicolas Boichat <drinkcat@chromium.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 43c54b8c7cfe22f868a751ba8a59abf1724160b1 upstream.

This reverts one hunk of
commit ef44a1ec6eee ("ALSA: sound/core: use memdup_user()"), which
replaced a number of kmalloc followed by memcpy with memdup calls.

In this case, we are copying from a struct snd_pcm_hw_params32 to
a struct snd_pcm_hw_params, but the latter is 4 bytes longer than
the 32-bit version, so we need to separate kmalloc and copy calls.

This actually leads to an out-of-bounds memory access later on
in sound/soc/soc-pcm.c:soc_pcm_hw_params() (detected using KASan).

Fixes: ef44a1ec6eee ('ALSA: sound/core: use memdup_user()')
Signed-off-by: Nicolas Boichat <drinkcat@chromium.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 sound/core/pcm_compat.c | 13 +++++++++----
 1 file changed, 9 insertions(+), 4 deletions(-)

diff --git a/sound/core/pcm_compat.c b/sound/core/pcm_compat.c
index c4ac3c1e19af..1bb1a43c7d03 100644
--- a/sound/core/pcm_compat.c
+++ b/sound/core/pcm_compat.c
@@ -236,10 +236,15 @@ static int snd_pcm_ioctl_hw_params_compat(struct snd_pcm_substream *substream,
 	if (! (runtime = substream->runtime))
 		return -ENOTTY;
 
-	/* only fifo_size is different, so just copy all */
-	data = memdup_user(data32, sizeof(*data32));
-	if (IS_ERR(data))
-		return PTR_ERR(data);
+	data = kmalloc(sizeof(*data), GFP_KERNEL);
+	if (!data)
+		return -ENOMEM;
+
+	/* only fifo_size (RO from userspace) is different, so just copy all */
+	if (copy_from_user(data, data32, sizeof(*data32))) {
+		err = -EFAULT;
+		goto error;
+	}
 
 	if (refine)
 		err = snd_pcm_hw_refine(substream, data);
-- 
2.7.1

[toc] | [prev] | [next] | [standalone]


#1332107 — [PATCH 3.12 07/64] ALSA: timer: Harden slave timer list handling

FromJiri Slaby <jslaby@suse.cz>
Date2016-02-11 15:50 +0100
Subject[PATCH 3.12 07/64] ALSA: timer: Harden slave timer list handling
Message-ID<r10Jb-1HE-17@gated-at.bofh.it>
In reply to#1332095
From: Takashi Iwai <tiwai@suse.de>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit b5a663aa426f4884c71cd8580adae73f33570f0d upstream.

A slave timer instance might be still accessible in a racy way while
operating the master instance as it lacks of locking.  Since the
master operation is mostly protected with timer->lock, we should cope
with it while changing the slave instance, too.  Also, some linked
lists (active_list and ack_list) of slave instances aren't unlinked
immediately at stopping or closing, and this may lead to unexpected
accesses.

This patch tries to address these issues.  It adds spin lock of
timer->lock (either from master or slave, which is equivalent) in a
few places.  For avoiding a deadlock, we ensure that the global
slave_active_lock is always locked at first before each timer lock.

Also, ack and active_list of slave instances are properly unlinked at
snd_timer_stop() and snd_timer_close().

Last but not least, remove the superfluous call of _snd_timer_stop()
at removing slave links.  This is a noop, and calling it may confuse
readers wrt locking.  Further cleanup will follow in a later patch.

Actually we've got reports of use-after-free by syzkaller fuzzer, and
this hopefully fixes these issues.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 sound/core/timer.c | 18 ++++++++++++++----
 1 file changed, 14 insertions(+), 4 deletions(-)

diff --git a/sound/core/timer.c b/sound/core/timer.c
index 6ddcf06f52f9..38a137d6b04f 100644
--- a/sound/core/timer.c
+++ b/sound/core/timer.c
@@ -215,11 +215,13 @@ static void snd_timer_check_master(struct snd_timer_instance *master)
 		    slave->slave_id == master->slave_id) {
 			list_move_tail(&slave->open_list, &master->slave_list_head);
 			spin_lock_irq(&slave_active_lock);
+			spin_lock(&master->timer->lock);
 			slave->master = master;
 			slave->timer = master->timer;
 			if (slave->flags & SNDRV_TIMER_IFLG_RUNNING)
 				list_add_tail(&slave->active_list,
 					      &master->slave_active_head);
+			spin_unlock(&master->timer->lock);
 			spin_unlock_irq(&slave_active_lock);
 		}
 	}
@@ -345,15 +347,18 @@ int snd_timer_close(struct snd_timer_instance *timeri)
 		    timer->hw.close)
 			timer->hw.close(timer);
 		/* remove slave links */
+		spin_lock_irq(&slave_active_lock);
+		spin_lock(&timer->lock);
 		list_for_each_entry_safe(slave, tmp, &timeri->slave_list_head,
 					 open_list) {
-			spin_lock_irq(&slave_active_lock);
-			_snd_timer_stop(slave, 1, SNDRV_TIMER_EVENT_RESOLUTION);
 			list_move_tail(&slave->open_list, &snd_timer_slave_list);
 			slave->master = NULL;
 			slave->timer = NULL;
-			spin_unlock_irq(&slave_active_lock);
+			list_del_init(&slave->ack_list);
+			list_del_init(&slave->active_list);
 		}
+		spin_unlock(&timer->lock);
+		spin_unlock_irq(&slave_active_lock);
 		mutex_unlock(&register_mutex);
 	}
  out:
@@ -440,9 +445,12 @@ static int snd_timer_start_slave(struct snd_timer_instance *timeri)
 
 	spin_lock_irqsave(&slave_active_lock, flags);
 	timeri->flags |= SNDRV_TIMER_IFLG_RUNNING;
-	if (timeri->master)
+	if (timeri->master && timeri->timer) {
+		spin_lock(&timeri->timer->lock);
 		list_add_tail(&timeri->active_list,
 			      &timeri->master->slave_active_head);
+		spin_unlock(&timeri->timer->lock);
+	}
 	spin_unlock_irqrestore(&slave_active_lock, flags);
 	return 1; /* delayed start */
 }
@@ -488,6 +496,8 @@ static int _snd_timer_stop(struct snd_timer_instance * timeri,
 		if (!keep_flag) {
 			spin_lock_irqsave(&slave_active_lock, flags);
 			timeri->flags &= ~SNDRV_TIMER_IFLG_RUNNING;
+			list_del_init(&timeri->ack_list);
+			list_del_init(&timeri->active_list);
 			spin_unlock_irqrestore(&slave_active_lock, flags);
 		}
 		goto __end;
-- 
2.7.1

[toc] | [prev] | [next] | [standalone]


#1332110 — [PATCH 3.12 12/64] ALSA: hrtimer: Fix stall by hrtimer_cancel()

FromJiri Slaby <jslaby@suse.cz>
Date2016-02-11 15:50 +0100
Subject[PATCH 3.12 12/64] ALSA: hrtimer: Fix stall by hrtimer_cancel()
Message-ID<r10Jc-1HE-25@gated-at.bofh.it>
In reply to#1332095
From: Takashi Iwai <tiwai@suse.de>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 2ba1fe7a06d3624f9a7586d672b55f08f7c670f3 upstream.

hrtimer_cancel() waits for the completion from the callback, thus it
must not be called inside the callback itself.  This was already a
problem in the past with ALSA hrtimer driver, and the early commit
[fcfdebe70759: ALSA: hrtimer - Fix lock-up] tried to address it.

However, the previous fix is still insufficient: it may still cause a
lockup when the ALSA timer instance reprograms itself in its callback.
Then it invokes the start function even in snd_timer_interrupt() that
is called in hrtimer callback itself, results in a CPU stall.  This is
no hypothetical problem but actually triggered by syzkaller fuzzer.

This patch tries to fix the issue again.  Now we call
hrtimer_try_to_cancel() at both start and stop functions so that it
won't fall into a deadlock, yet giving some chance to cancel the queue
if the functions have been called outside the callback.  The proper
hrtimer_cancel() is called in anyway at closing, so this should be
enough.

Reported-and-tested-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 sound/core/hrtimer.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/sound/core/hrtimer.c b/sound/core/hrtimer.c
index b8b31c433d64..14d483d6b3b0 100644
--- a/sound/core/hrtimer.c
+++ b/sound/core/hrtimer.c
@@ -90,7 +90,7 @@ static int snd_hrtimer_start(struct snd_timer *t)
 	struct snd_hrtimer *stime = t->private_data;
 
 	atomic_set(&stime->running, 0);
-	hrtimer_cancel(&stime->hrt);
+	hrtimer_try_to_cancel(&stime->hrt);
 	hrtimer_start(&stime->hrt, ns_to_ktime(t->sticks * resolution),
 		      HRTIMER_MODE_REL);
 	atomic_set(&stime->running, 1);
@@ -101,6 +101,7 @@ static int snd_hrtimer_stop(struct snd_timer *t)
 {
 	struct snd_hrtimer *stime = t->private_data;
 	atomic_set(&stime->running, 0);
+	hrtimer_try_to_cancel(&stime->hrt);
 	return 0;
 }
 
-- 
2.7.1

[toc] | [prev] | [next] | [standalone]


#1332114 — [PATCH 3.12 04/64] ALSA: hda/realtek - Fix silent headphone output on MacPro 4,1 (v2)

FromJiri Slaby <jslaby@suse.cz>
Date2016-02-11 15:50 +0100
Subject[PATCH 3.12 04/64] ALSA: hda/realtek - Fix silent headphone output on MacPro 4,1 (v2)
Message-ID<r10Jc-1HE-35@gated-at.bofh.it>
In reply to#1332095
From: Mario Kleiner <mario.kleiner.de@gmail.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 9f660a1c43890c2cdd1f423fd73654e7ca08fe56 upstream.

Without this patch, internal speaker and line-out work,
but front headphone output jack stays silent on the
Mac Pro 4,1.

This code path also gets executed on the MacPro 5,1 due
to identical codec SSID, but i don't know if it has any
positive or adverse effects there or not.

(v2) Implement feedback from Takashi Iwai: Reuse
     alc889_fixup_mbp_vref and just add a new nid
     0x19 for the MacPro 4,1.

Signed-off-by: Mario Kleiner <mario.kleiner.de@gmail.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 sound/pci/hda/patch_realtek.c | 11 +++++++++--
 1 file changed, 9 insertions(+), 2 deletions(-)

diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index 6d9a42a16a16..1dc0702ff818 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -1775,6 +1775,7 @@ enum {
 	ALC889_FIXUP_MBA11_VREF,
 	ALC889_FIXUP_MBA21_VREF,
 	ALC889_FIXUP_MP11_VREF,
+	ALC889_FIXUP_MP41_VREF,
 	ALC882_FIXUP_INV_DMIC,
 	ALC882_FIXUP_NO_PRIMARY_HP,
 	ALC887_FIXUP_ASUS_BASS,
@@ -1861,7 +1862,7 @@ static void alc889_fixup_mbp_vref(struct hda_codec *codec,
 				  const struct hda_fixup *fix, int action)
 {
 	struct alc_spec *spec = codec->spec;
-	static hda_nid_t nids[2] = { 0x14, 0x15 };
+	static hda_nid_t nids[3] = { 0x14, 0x15, 0x19 };
 	int i;
 
 	if (action != HDA_FIXUP_ACT_INIT)
@@ -2137,6 +2138,12 @@ static const struct hda_fixup alc882_fixups[] = {
 		.chained = true,
 		.chain_id = ALC885_FIXUP_MACPRO_GPIO,
 	},
+	[ALC889_FIXUP_MP41_VREF] = {
+		.type = HDA_FIXUP_FUNC,
+		.v.func = alc889_fixup_mbp_vref,
+		.chained = true,
+		.chain_id = ALC885_FIXUP_MACPRO_GPIO,
+	},
 	[ALC882_FIXUP_INV_DMIC] = {
 		.type = HDA_FIXUP_FUNC,
 		.v.func = alc_fixup_inv_dmic_0x12,
@@ -2209,7 +2216,7 @@ static const struct snd_pci_quirk alc882_fixup_tbl[] = {
 	SND_PCI_QUIRK(0x106b, 0x3f00, "Macbook 5,1", ALC889_FIXUP_IMAC91_VREF),
 	SND_PCI_QUIRK(0x106b, 0x4000, "MacbookPro 5,1", ALC889_FIXUP_IMAC91_VREF),
 	SND_PCI_QUIRK(0x106b, 0x4100, "Macmini 3,1", ALC889_FIXUP_IMAC91_VREF),
-	SND_PCI_QUIRK(0x106b, 0x4200, "Mac Pro 5,1", ALC885_FIXUP_MACPRO_GPIO),
+	SND_PCI_QUIRK(0x106b, 0x4200, "Mac Pro 4,1/5,1", ALC889_FIXUP_MP41_VREF),
 	SND_PCI_QUIRK(0x106b, 0x4300, "iMac 9,1", ALC889_FIXUP_IMAC91_VREF),
 	SND_PCI_QUIRK(0x106b, 0x4600, "MacbookPro 5,2", ALC889_FIXUP_IMAC91_VREF),
 	SND_PCI_QUIRK(0x106b, 0x4900, "iMac 9,1 Aluminum", ALC889_FIXUP_IMAC91_VREF),
-- 
2.7.1

[toc] | [prev] | [next] | [standalone]


#1332115 — [PATCH 3.12 06/64] ALSA: seq: Fix race at timer setup and close

FromJiri Slaby <jslaby@suse.cz>
Date2016-02-11 15:50 +0100
Subject[PATCH 3.12 06/64] ALSA: seq: Fix race at timer setup and close
Message-ID<r10Jd-1HE-37@gated-at.bofh.it>
In reply to#1332095
From: Takashi Iwai <tiwai@suse.de>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 3567eb6af614dac436c4b16a8d426f9faed639b3 upstream.

ALSA sequencer code has an open race between the timer setup ioctl and
the close of the client.  This was triggered by syzkaller fuzzer, and
a use-after-free was caught there as a result.

This patch papers over it by adding a proper queue->timer_mutex lock
around the timer-related calls in the relevant code path.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Tested-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 sound/core/seq/seq_queue.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/sound/core/seq/seq_queue.c b/sound/core/seq/seq_queue.c
index f9077361c119..4c9aa462de9b 100644
--- a/sound/core/seq/seq_queue.c
+++ b/sound/core/seq/seq_queue.c
@@ -144,8 +144,10 @@ static struct snd_seq_queue *queue_new(int owner, int locked)
 static void queue_delete(struct snd_seq_queue *q)
 {
 	/* stop and release the timer */
+	mutex_lock(&q->timer_mutex);
 	snd_seq_timer_stop(q->timer);
 	snd_seq_timer_close(q);
+	mutex_unlock(&q->timer_mutex);
 	/* wait until access free */
 	snd_use_lock_sync(&q->use_lock);
 	/* release resources... */
-- 
2.7.1

[toc] | [prev] | [next] | [standalone]


#1332117 — [PATCH 3.12 05/64] ALSA: seq: Fix missing NULL check at remove_events ioctl

FromJiri Slaby <jslaby@suse.cz>
Date2016-02-11 15:50 +0100
Subject[PATCH 3.12 05/64] ALSA: seq: Fix missing NULL check at remove_events ioctl
Message-ID<r10Jd-1HE-43@gated-at.bofh.it>
In reply to#1332095
From: Takashi Iwai <tiwai@suse.de>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 030e2c78d3a91dd0d27fef37e91950dde333eba1 upstream.

snd_seq_ioctl_remove_events() calls snd_seq_fifo_clear()
unconditionally even if there is no FIFO assigned, and this leads to
an Oops due to NULL dereference.  The fix is just to add a proper NULL
check.

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Tested-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 sound/core/seq/seq_clientmgr.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sound/core/seq/seq_clientmgr.c b/sound/core/seq/seq_clientmgr.c
index 4dc6bae80e15..ecfbf5f39d38 100644
--- a/sound/core/seq/seq_clientmgr.c
+++ b/sound/core/seq/seq_clientmgr.c
@@ -1950,7 +1950,7 @@ static int snd_seq_ioctl_remove_events(struct snd_seq_client *client,
 		 * No restrictions so for a user client we can clear
 		 * the whole fifo
 		 */
-		if (client->type == USER_CLIENT)
+		if (client->type == USER_CLIENT && client->data.user.fifo)
 			snd_seq_fifo_clear(client->data.user.fifo);
 	}
 
-- 
2.7.1

[toc] | [prev] | [next] | [standalone]


#1332278

FromGuenter Roeck <linux@roeck-us.net>
Date2016-02-11 19:20 +0100
Message-ID<r140q-40Y-21@gated-at.bofh.it>
In reply to#1331957
On Thu, Feb 11, 2016 at 02:59:26PM +0100, Jiri Slaby wrote:
> This is the start of the stable review cycle for the 3.12.54 release.
> There are 64 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Mon Feb 15 14:54:53 CET 2016.
> Anything received after that time might be too late.
> 
Build results:
	total: 124 pass: 124 fail: 0
Qemu test results:
	total: 79 pass: 79 fail: 0

Details are available at http://kerneltests.org/builders.

Guenter

[toc] | [prev] | [next] | [standalone]


#1332328

FromShuah Khan <shuahkh@osg.samsung.com>
Date2016-02-11 20:30 +0100
Message-ID<r156a-4K4-3@gated-at.bofh.it>
In reply to#1331957
On 02/11/2016 06:59 AM, Jiri Slaby wrote:
> This is the start of the stable review cycle for the 3.12.54 release.
> There are 64 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Mon Feb 15 14:54:53 CET 2016.
> Anything received after that time might be too late.
> 
> The whole patch series can be found in one patch at:
> 	http://kernel.org/pub/linux/kernel/people/jirislaby/stable-review/patch-3.12.54-rc1.xz
> and the diffstat can be found below.
> 

Compiled and booted on my test system. I did see
one additional error message:

mei_me 0000:00:16.0: version message write failed

Anything to be concerned about?

thanks,
-- Shuah


-- 
Shuah Khan
Sr. Linux Kernel Developer
Open Source Innovation Group
Samsung Research America (Silicon Valley)
shuahkh@osg.samsung.com | (970) 217-8978

[toc] | [prev] | [next] | [standalone]


#1334522

FromJiri Slaby <jslaby@suse.cz>
Date2016-02-15 16:30 +0100
Message-ID<r2tg6-2PB-29@gated-at.bofh.it>
In reply to#1332328
On 02/11/2016, 08:26 PM, Shuah Khan wrote:
> On 02/11/2016 06:59 AM, Jiri Slaby wrote:
>> This is the start of the stable review cycle for the 3.12.54 release.
>> There are 64 patches in this series, all will be posted as a response
>> to this one.  If anyone has any issues with these being applied, please
>> let me know.
>>
>> Responses should be made by Mon Feb 15 14:54:53 CET 2016.
>> Anything received after that time might be too late.
>>
>> The whole patch series can be found in one patch at:
>> 	http://kernel.org/pub/linux/kernel/people/jirislaby/stable-review/patch-3.12.54-rc1.xz
>> and the diffstat can be found below.
>>
> 
> Compiled and booted on my test system. I did see
> one additional error message:
> 
> mei_me 0000:00:16.0: version message write failed
> 
> Anything to be concerned about?

I hope not, given there are no relevant changes in mei in this release.
Ccing MEI maintainer if this rings a bell?

thanks,
-- 
js
suse labs

[toc] | [prev] | [next] | [standalone]


#1334570

From"Winkler, Tomas" <tomas.winkler@intel.com>
Date2016-02-15 17:20 +0100
Message-ID<r2u2u-3n5-27@gated-at.bofh.it>
In reply to#1334522

> -----Original Message-----
> From: Jiri Slaby [mailto:jslaby@suse.cz]
> Sent: Monday, February 15, 2016 17:20
> To: Shuah Khan <shuahkh@osg.samsung.com>; stable@vger.kernel.org
> Cc: linux@roeck-us.net; shuah.kh@samsung.com; linux-kernel@vger.kernel.org;
> Winkler, Tomas <tomas.winkler@intel.com>
> Subject: Re: [PATCH 3.12 00/64] 3.12.54-stable review
> 
> On 02/11/2016, 08:26 PM, Shuah Khan wrote:
> > On 02/11/2016 06:59 AM, Jiri Slaby wrote:
> >> This is the start of the stable review cycle for the 3.12.54 release.
> >> There are 64 patches in this series, all will be posted as a response
> >> to this one.  If anyone has any issues with these being applied, please
> >> let me know.
> >>
> >> Responses should be made by Mon Feb 15 14:54:53 CET 2016.
> >> Anything received after that time might be too late.
> >>
> >> The whole patch series can be found in one patch at:
> >> 	http://kernel.org/pub/linux/kernel/people/jirislaby/stable-review/patch-
> 3.12.54-rc1.xz
> >> and the diffstat can be found below.
> >>
> >
> > Compiled and booted on my test system. I did see
> > one additional error message:
> >
> > mei_me 0000:00:16.0: version message write failed
> >
> > Anything to be concerned about?
> 
> I hope not, given there are no relevant changes in mei in this release.
> Ccing MEI maintainer if this rings a bell?


On what platform is this happening? Do you have a more content in the log?
Thanks
Tomas 

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web