Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1341320 > unrolled thread
| Started by | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| First post | 2016-02-24 05:10 +0100 |
| Last post | 2016-02-25 20:00 +0100 |
| Articles | 20 on this page of 130 — 4 participants |
Back to article view | Back to linux.kernel
[PATCH 4.4 000/137] 4.4.3-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:10 +0100
[PATCH 4.4 023/137] Revert "btrfs: clear PF_NOFREEZE in cleaner_kthread()" Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:10 +0100
[PATCH 4.4 026/137] Btrfs: fix page reading in extent_same ioctl leading to csum errors Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:10 +0100
[PATCH 4.4 022/137] Btrfs: fix fitrim discarding device area reserved for boot loaders use Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:10 +0100
[PATCH 4.4 092/137] libnvdimm: fix namespace object confusion in is_uuid_busy() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 104/137] iommu/vt-d: Clear PPR bit to ensure we get more page request interrupts Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 128/137] libxfs: pack the agfl header structure so XFS_AGFL_SIZE is correct Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 068/137] powerpc/ioda: Set "read" permission when "write" is set Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 119/137] intel_scu_ipcutil: underflow in scu_reg_access() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 126/137] ovl: root: copy attr Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 108/137] dma-debug: switch check from _text to _stext Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 095/137] mm: fix regression in remap_file_pages() emulation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 122/137] futex: Drop refcount if requeue_pi() acquired the rtmutex Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 004/137] x86/uaccess/64: Handle the caching of 4-byte nocache copies properly in __copy_user_nocache() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 008/137] ALSA: seq: Fix leak of pool buffer at concurrent writes Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 123/137] ovl: allow zero size xattr Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 117/137] dump_stack: avoid potential deadlocks Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 129/137] xfs: inode recovery readahead can race with inode buffer creation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 127/137] ovl: setattr: check permissions before copy-up Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 003/137] x86/uaccess/64: Make the __copy_user_nocache() assembly code more readable Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 125/137] ovl: check dentry positiveness in ovl_cleanup_whiteouts() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 118/137] mm,thp: khugepaged: call pte flush at the time of collapse Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 006/137] ALSA: hda - Cancel probe work instead of flush at remove Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 121/137] devm_memremap_release(): fix memremapd addr handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 011/137] phy: twl4030-usb: Fix unbalanced pm_runtime_enable on module reload Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 124/137] ovl: use a minimal buffer in ovl_copy_xattr Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 109/137] scripts/bloat-o-meter: fix python3 syntax error Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 120/137] ipc/shm: handle removed segments gracefully in shm_mmap() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 007/137] ALSA: pcm: Fix rwsem deadlock for non-atomic PCM stream Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 103/137] iommu/vt-d: Fix 64-bit accesses to 32-bit DMAR_GSTS_REG Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 059/137] udf: limit the maximum number of indirect extents in a row Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 009/137] ALSA: seq: Fix double port list deletion Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:20 +0100
[PATCH 4.4 130/137] Revert "xfs: clear PF_NOFREEZE for xfsaild kthread" Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 107/137] m32r: fix m32104ut_defconfig build fail Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 106/137] xhci: Fix list corruption in urb dequeue at host removal Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 116/137] radix-tree: fix oops after radix_tree_iter_retry Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 067/137] powerpc/powernv: Fix stale PE primary bus Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 137/137] modules: fix modparam async_probe request Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 065/137] powerpc: Fix dedotify for binutils >= 2.26 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 136/137] module: wrapper for symbol name. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 110/137] fs/hugetlbfs/inode.c: fix bugs in hugetlb_vmtruncate_list() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 066/137] powerpc/eeh: Fix stale cached primary bus Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 094/137] mm: replace vma_lock_anon_vma with anon_vma_lock_read/write Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 105/137] Revert "xhci: dont finish a TD if we get a short-transfer event mid TD" Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 134/137] posix-timers: Handle relative timers with CONFIG_TIME_LOW_RES proper Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 093/137] mm: fix mlock accouting Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 101/137] iommu/amd: Correct the wrong setting of alias DTE in do_attach Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 112/137] memcg: only free spare array when readers are done Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 098/137] string_helpers: fix precision loss for some inputs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 113/137] MAINTAINERS: return arch/sh to maintained state, with new maintainers Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 114/137] radix-tree: fix race in gang lookup Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 063/137] powerpc/eeh: Fix PE location code Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 099/137] Input: vmmouse - fix absolute device registration Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 115/137] drivers/hwspinlock: fix race between radix tree insertion and lookup Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 064/137] powerpc: Simplify module TOC handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 100/137] iommu/vt-d: Dont skip PCI devices when disabling IOTLB Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 111/137] numa: fix /proc/<pid>/numa_maps for hugetlbfs on s390 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:30 +0100
[PATCH 4.4 086/137] arm64: dma-mapping: fix handling of devices registered before arch_initcall Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 132/137] prctl: take mmap sem for writing to protect against others Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 071/137] ARM: 8519/1: ICST: try other dividends than 1 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 062/137] SUNRPC: Fixup socket wait for memory Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 081/137] ARM: OMAP2+: Fix wait_dll_lock_timed for rodata Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 090/137] perf kvm record/report: unprocessable sample error while recording/reporting guest data Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 096/137] Input: elantech - mark protocols v2 and v3 as semi-mt Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 135/137] itimers: Handle relative timers with CONFIG_TIME_LOW_RES proper Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 072/137] ARM: 8517/1: ICST: avoid arithmetic overflow in icst_hz() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 060/137] udf: Prevent buffer overrun with multi-byte characters Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 087/137] KVM: arm/arm64: Fix reference to uninitialised VGIC Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 061/137] udf: Check output buffer length when converting name to CS0 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 051/137] cifs: Ratelimit kernel log messages Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 080/137] ARM: dts: at91: sama5d4ek: add phy address and IRQ for macb0 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 085/137] ARM: OMAP2+: Fix ppa_zero_params and ppa_por_params for rodata Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 075/137] ARM: dts: Fix omap5 PMIC control lines for RTC writes Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 069/137] ARM: mvebu: remove duplicated regulator definition in Armada 388 GP Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 054/137] cifs: fix erroneous return value Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 078/137] ARM: dts: at91: sama5d4: fix instance id of DBGU Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 133/137] timerfd: Handle relative timers with CONFIG_TIME_LOW_RES proper Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 083/137] ARM: OMAP2+: Fix l2dis_3630 for rodata Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 088/137] KVM: PPC: Fix emulation of H_SET_DABR/X on POWER8 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 089/137] KVM: PPC: Fix ONE_REG AltiVec support Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 073/137] ARM: nomadik: fix up SD/MMC DT settings Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 077/137] ARM: dts: at91: sama5d4 xplained: properly mux phy interrupt Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 076/137] ARM: dts: omap5-board-common: enable rtc and charging of backup battery Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 084/137] ARM: OMAP2+: Fix save_secure_ram_context for rodata Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 047/137] iio: dac: mcp4725: set iio name property in sysfs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 074/137] ARM: dts: Fix wl12xx missing clocks that cause hangs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 082/137] ARM: OMAP2+: Fix l2_inv_api_params for rodata Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 091/137] mm: soft-offline: check return value in second __get_any_page() call Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 079/137] ARM: dts: at91: sama5d4 xplained: fix phy0 IRQ type Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 131/137] xfs: log mount failures dont wait for buffers to be released Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 034/137] klist: fix starting point removed bug in klist iterators Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:40 +0100
[PATCH 4.4 017/137] serial: omap: Prevent DoS using unprivileged ioctl(TIOCSRS485) Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 043/137] iio:adc:ti_am335x_adc Fix buffered mode by identifying as software buffer. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 019/137] ext4: fix potential integer overflow Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 048/137] iio: light: acpi-als: Report data as processed Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 030/137] tools lib traceevent: Fix output of %llu for 64 bit values read on 32 bit machines Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 035/137] scsi: add Synology to 1024 sector blacklist Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 010/137] phy: twl4030-usb: Relase usb phy on unload Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 057/137] nfs: Fix race in __update_open_stateid() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 049/137] iio: pressure: mpl115: fix temperature offset sign Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 013/137] pty: fix possible use after free of tty->driver_data Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 058/137] pNFS/flexfiles: Fix an XDR encoding bug in layoutreturn Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 033/137] tracepoints: Do not trace when cpu is offline Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 040/137] SCSI: Add Marvell Console to VPD blacklist Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 039/137] scsi_dh_rdac: always retry MODE SELECT on command lock violation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 031/137] perf tools: tracepoint_error() can receive e=NULL, robustify it Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 044/137] iio-light: Use a signed return type for ltr501_match_samp_freq() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
Re: [PATCH 4.4 000/137] 4.4.3-stable review Mike Galbraith <umgwanakikbuti@gmail.com> - 2016-02-24 05:50 +0100
Re: [PATCH 4.4 000/137] 4.4.3-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 06:10 +0100
Re: [PATCH 4.4 000/137] 4.4.3-stable review Mike Galbraith <umgwanakikbuti@gmail.com> - 2016-02-24 07:30 +0100
[PATCH 4.4 032/137] tracing: Fix freak link error caused by branch tracer Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 038/137] drivers/scsi/sg.c: mark VMA as VM_IO to prevent migration Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 016/137] serial: 8250_pci: Add Intel Broadwell ports Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 052/137] cifs: fix race between call_async() and reconnect() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 042/137] iio: adis_buffer: Fix out-of-bounds memory access Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 014/137] pty: make sure super_block is still valid in final /dev/tty close Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 056/137] pNFS/flexfiles: Fix an Oopsable typo in ff_mirror_match_fh() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 018/137] ext4: fix scheduling in atomic on group checksum failure Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 045/137] iio: add HAS_IOMEM dependency to VF610_ADC Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 053/137] cifs_dbg() outputs an uninitialized buffer in cifs_readdir() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 055/137] NFS: Fix attribute cache revalidation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 015/137] tty: Add support for PCIe WCH382 2S multi-IO card Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 050/137] iio: inkern: fix a NULL dereference on error Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 041/137] scsi: fix soft lockup in scsi_remove_target() on module removal Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 036/137] iscsi-target: Fix potential dead-lock during node acl delete Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 05:50 +0100
[PATCH 4.4 037/137] SCSI: fix crashes in sd and sr runtime PM Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-24 06:00 +0100
Re: [PATCH 4.4 000/137] 4.4.3-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-02-24 19:30 +0100
Re: [PATCH 4.4 000/137] 4.4.3-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-25 20:10 +0100
Re: [PATCH 4.4 000/137] 4.4.3-stable review Guenter Roeck <linux@roeck-us.net> - 2016-02-25 07:00 +0100
Re: [PATCH 4.4 000/137] 4.4.3-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-25 20:00 +0100
Page 1 of 7 [1] 2 3 4 5 6 7 Next page →
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:10 +0100 |
| Subject | [PATCH 4.4 000/137] 4.4.3-stable review |
| Message-ID | <r5yVX-7pJ-3@gated-at.bofh.it> |
This is the start of the stable review cycle for the 4.4.3 release.
There are 137 patches in this series, all will be posted as a response
to this one. If anyone has any issues with these being applied, please
let me know.
Responses should be made by Fri Feb 26 03:33:58 UTC 2016.
Anything received after that time might be too late.
The whole patch series can be found in one patch at:
kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.4.3-rc1.gz
and the diffstat can be found below.
thanks,
greg k-h
-------------
Pseudo-Shortlog of commits:
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Linux 4.4.3-rc1
Luis R. Rodriguez <mcgrof@suse.com>
modules: fix modparam async_probe request
Rusty Russell <rusty@rustcorp.com.au>
module: wrapper for symbol name.
Thomas Gleixner <tglx@linutronix.de>
itimers: Handle relative timers with CONFIG_TIME_LOW_RES proper
Thomas Gleixner <tglx@linutronix.de>
posix-timers: Handle relative timers with CONFIG_TIME_LOW_RES proper
Thomas Gleixner <tglx@linutronix.de>
timerfd: Handle relative timers with CONFIG_TIME_LOW_RES proper
Mateusz Guzik <mguzik@redhat.com>
prctl: take mmap sem for writing to protect against others
Dave Chinner <dchinner@redhat.com>
xfs: log mount failures don't wait for buffers to be released
Dave Chinner <david@fromorbit.com>
Revert "xfs: clear PF_NOFREEZE for xfsaild kthread"
Dave Chinner <dchinner@redhat.com>
xfs: inode recovery readahead can race with inode buffer creation
Darrick J. Wong <darrick.wong@oracle.com>
libxfs: pack the agfl header structure so XFS_AGFL_SIZE is correct
Miklos Szeredi <miklos@szeredi.hu>
ovl: setattr: check permissions before copy-up
Miklos Szeredi <miklos@szeredi.hu>
ovl: root: copy attr
Konstantin Khlebnikov <khlebnikov@yandex-team.ru>
ovl: check dentry positiveness in ovl_cleanup_whiteouts()
Vito Caputo <vito.caputo@coreos.com>
ovl: use a minimal buffer in ovl_copy_xattr
Miklos Szeredi <miklos@szeredi.hu>
ovl: allow zero size xattr
Thomas Gleixner <tglx@linutronix.de>
futex: Drop refcount if requeue_pi() acquired the rtmutex
Toshi Kani <toshi.kani@hpe.com>
devm_memremap_release(): fix memremap'd addr handling
Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
ipc/shm: handle removed segments gracefully in shm_mmap()
Dan Carpenter <dan.carpenter@oracle.com>
intel_scu_ipcutil: underflow in scu_reg_access()
Vineet Gupta <Vineet.Gupta1@synopsys.com>
mm,thp: khugepaged: call pte flush at the time of collapse
Eric Dumazet <edumazet@google.com>
dump_stack: avoid potential deadlocks
Konstantin Khlebnikov <koct9i@gmail.com>
radix-tree: fix oops after radix_tree_iter_retry
Matthew Wilcox <willy@linux.intel.com>
drivers/hwspinlock: fix race between radix tree insertion and lookup
Matthew Wilcox <willy@linux.intel.com>
radix-tree: fix race in gang lookup
Rich Felker <dalias@libc.org>
MAINTAINERS: return arch/sh to maintained state, with new maintainers
Martijn Coenen <maco@google.com>
memcg: only free spare array when readers are done
Michael Holzheu <holzheu@linux.vnet.ibm.com>
numa: fix /proc/<pid>/numa_maps for hugetlbfs on s390
Mike Kravetz <mike.kravetz@oracle.com>
fs/hugetlbfs/inode.c: fix bugs in hugetlb_vmtruncate_list()
Sergey Senozhatsky <sergey.senozhatsky.work@gmail.com>
scripts/bloat-o-meter: fix python3 syntax error
Laura Abbott <labbott@fedoraproject.org>
dma-debug: switch check from _text to _stext
Sudip Mukherjee <sudipm.mukherjee@gmail.com>
m32r: fix m32104ut_defconfig build fail
Mathias Nyman <mathias.nyman@linux.intel.com>
xhci: Fix list corruption in urb dequeue at host removal
Mathias Nyman <mathias.nyman@linux.intel.com>
Revert "xhci: don't finish a TD if we get a short-transfer event mid TD"
David Woodhouse <David.Woodhouse@intel.com>
iommu/vt-d: Clear PPR bit to ensure we get more page request interrupts
CQ Tang <cq.tang@intel.com>
iommu/vt-d: Fix 64-bit accesses to 32-bit DMAR_GSTS_REG
David Woodhouse <David.Woodhouse@intel.com>
iommu/vt-d: Fix mm refcounting to hold mm_count not mm_users
Baoquan He <bhe@redhat.com>
iommu/amd: Correct the wrong setting of alias DTE in do_attach
Jeremy McNicoll <jmcnicol@redhat.com>
iommu/vt-d: Don't skip PCI devices when disabling IOTLB
Dmitry Torokhov <dmitry.torokhov@gmail.com>
Input: vmmouse - fix absolute device registration
James Bottomley <JBottomley@Odin.com>
string_helpers: fix precision loss for some inputs
Aurélien Francillon <aurelien@francillon.net>
Input: i8042 - add Fujitsu Lifebook U745 to the nomux list
Benjamin Tissoires <benjamin.tissoires@redhat.com>
Input: elantech - mark protocols v2 and v3 as semi-mt
Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
mm: fix regression in remap_file_pages() emulation
Konstantin Khlebnikov <koct9i@gmail.com>
mm: replace vma_lock_anon_vma with anon_vma_lock_read/write
Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
mm: fix mlock accouting
Dan Williams <dan.j.williams@intel.com>
libnvdimm: fix namespace object confusion in is_uuid_busy()
Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
mm: soft-offline: check return value in second __get_any_page() call
Ravi Bangoria <ravi.bangoria@linux.vnet.ibm.com>
perf kvm record/report: 'unprocessable sample' error while recording/reporting guest data
Greg Kurz <gkurz@linux.vnet.ibm.com>
KVM: PPC: Fix ONE_REG AltiVec support
Thomas Huth <thuth@redhat.com>
KVM: PPC: Fix emulation of H_SET_DABR/X on POWER8
Andre Przywara <andre.przywara@arm.com>
KVM: arm/arm64: Fix reference to uninitialised VGIC
Marek Szyprowski <m.szyprowski@samsung.com>
arm64: dma-mapping: fix handling of devices registered before arch_initcall
Tony Lindgren <tony@atomide.com>
ARM: OMAP2+: Fix ppa_zero_params and ppa_por_params for rodata
Tony Lindgren <tony@atomide.com>
ARM: OMAP2+: Fix save_secure_ram_context for rodata
Tony Lindgren <tony@atomide.com>
ARM: OMAP2+: Fix l2dis_3630 for rodata
Tony Lindgren <tony@atomide.com>
ARM: OMAP2+: Fix l2_inv_api_params for rodata
Tony Lindgren <tony@atomide.com>
ARM: OMAP2+: Fix wait_dll_lock_timed for rodata
Wenyou Yang <wenyou.yang@atmel.com>
ARM: dts: at91: sama5d4ek: add phy address and IRQ for macb0
Nicolas Ferre <nicolas.ferre@atmel.com>
ARM: dts: at91: sama5d4 xplained: fix phy0 IRQ type
Mohamed Jamsheeth Hajanajubudeen <mohamedjamsheeth.hajanajubudeen@atmel.com>
ARM: dts: at91: sama5d4: fix instance id of DBGU
Alexandre Belloni <alexandre.belloni@free-electrons.com>
ARM: dts: at91: sama5d4 xplained: properly mux phy interrupt
H. Nikolaus Schaller <hns@goldelico.com>
ARM: dts: omap5-board-common: enable rtc and charging of backup battery
Tony Lindgren <tony@atomide.com>
ARM: dts: Fix omap5 PMIC control lines for RTC writes
Adam Ford <aford173@gmail.com>
ARM: dts: Fix wl12xx missing clocks that cause hangs
Linus Walleij <linus.walleij@linaro.org>
ARM: nomadik: fix up SD/MMC DT settings
Linus Walleij <linus.walleij@linaro.org>
ARM: 8517/1: ICST: avoid arithmetic overflow in icst_hz()
Linus Walleij <linus.walleij@linaro.org>
ARM: 8519/1: ICST: try other dividends than 1
Mika Penttilä <mika.penttila@nextfour.com>
arm64: mm: avoid calling apply_to_page_range on empty range
Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
ARM: mvebu: remove duplicated regulator definition in Armada 388 GP
Alexey Kardashevskiy <aik@ozlabs.ru>
powerpc/ioda: Set "read" permission when "write" is set
Gavin Shan <gwshan@linux.vnet.ibm.com>
powerpc/powernv: Fix stale PE primary bus
Gavin Shan <gwshan@linux.vnet.ibm.com>
powerpc/eeh: Fix stale cached primary bus
Andreas Schwab <schwab@linux-m68k.org>
powerpc: Fix dedotify for binutils >= 2.26
Alan Modra <amodra@gmail.com>
powerpc: Simplify module TOC handling
Gavin Shan <gwshan@linux.vnet.ibm.com>
powerpc/eeh: Fix PE location code
Trond Myklebust <trond.myklebust@primarydata.com>
SUNRPC: Fixup socket wait for memory
Andrew Gabbasov <andrew_gabbasov@mentor.com>
udf: Check output buffer length when converting name to CS0
Andrew Gabbasov <andrew_gabbasov@mentor.com>
udf: Prevent buffer overrun with multi-byte characters
Vegard Nossum <vegard.nossum@oracle.com>
udf: limit the maximum number of indirect extents in a row
Trond Myklebust <trond.myklebust@primarydata.com>
pNFS/flexfiles: Fix an XDR encoding bug in layoutreturn
Andrew Elble <aweits@rit.edu>
nfs: Fix race in __update_open_stateid()
Trond Myklebust <trond.myklebust@primarydata.com>
pNFS/flexfiles: Fix an Oopsable typo in ff_mirror_match_fh()
Trond Myklebust <trond.myklebust@primarydata.com>
NFS: Fix attribute cache revalidation
Anton Protopopov <a.s.protopopov@gmail.com>
cifs: fix erroneous return value
Vasily Averin <vvs@virtuozzo.com>
cifs_dbg() outputs an uninitialized buffer in cifs_readdir()
Rabin Vincent <rabin.vincent@axis.com>
cifs: fix race between call_async() and reconnect()
Jamie Bainbridge <jamie.bainbridge@gmail.com>
cifs: Ratelimit kernel log messages
Dan Carpenter <dan.carpenter@oracle.com>
iio: inkern: fix a NULL dereference on error
Akinobu Mita <akinobu.mita@gmail.com>
iio: pressure: mpl115: fix temperature offset sign
Gabriele Mazzotta <gabriele.mzt@gmail.com>
iio: light: acpi-als: Report data as processed
Yong Li <sdliyong@gmail.com>
iio: dac: mcp4725: set iio name property in sysfs
Vegard Nossum <vegard.nossum@oracle.com>
iio: add IIO_TRIGGER dependency to STK8BA50
Vegard Nossum <vegard.nossum@oracle.com>
iio: add HAS_IOMEM dependency to VF610_ADC
Markus Elfring <elfring@users.sourceforge.net>
iio-light: Use a signed return type for ltr501_match_samp_freq()
Jonathan Cameron <jic23@kernel.org>
iio:adc:ti_am335x_adc Fix buffered mode by identifying as software buffer.
Lars-Peter Clausen <lars@metafoo.de>
iio: adis_buffer: Fix out-of-bounds memory access
James Bottomley <James.Bottomley@HansenPartnership.com>
scsi: fix soft lockup in scsi_remove_target() on module removal
Mika Westerberg <mika.westerberg@linux.intel.com>
SCSI: Add Marvell Console to VPD blacklist
Hannes Reinecke <hare@suse.de>
scsi_dh_rdac: always retry MODE SELECT on command lock violation
Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
drivers/scsi/sg.c: mark VMA as VM_IO to prevent migration
Alan Stern <stern@rowland.harvard.edu>
SCSI: fix crashes in sd and sr runtime PM
Nicholas Bellinger <nab@linux-iscsi.org>
iscsi-target: Fix potential dead-lock during node acl delete
Mike Christie <mchristi@redhat.com>
scsi: add Synology to 1024 sector blacklist
James Bottomley <James.Bottomley@HansenPartnership.com>
klist: fix starting point removed bug in klist iterators
Steven Rostedt (Red Hat) <rostedt@goodmis.org>
tracepoints: Do not trace when cpu is offline
Arnd Bergmann <arnd@arndb.de>
tracing: Fix freak link error caused by branch tracer
Adrian Hunter <adrian.hunter@intel.com>
perf tools: tracepoint_error() can receive e=NULL, robustify it
Steven Rostedt <rostedt@goodmis.org>
tools lib traceevent: Fix output of %llu for 64 bit values read on 32 bit machines
Jann Horn <jann@thejh.net>
ptrace: use fsuid, fsgid, effective creds for fs access checks
Filipe Manana <fdmanana@suse.com>
Btrfs: fix direct IO requests not reporting IO error to user space
Filipe Manana <fdmanana@suse.com>
Btrfs: fix hang on extent buffer lock caused by the inode_paths ioctl
Filipe Manana <fdmanana@suse.com>
Btrfs: fix page reading in extent_same ioctl leading to csum errors
Filipe Manana <fdmanana@suse.com>
Btrfs: fix invalid page accesses in extent_same (dedup) ioctl
David Sterba <dsterba@suse.com>
btrfs: properly set the termination value of ctx->pos in readdir
David Sterba <dsterba@suse.com>
Revert "btrfs: clear PF_NOFREEZE in cleaner_kthread()"
Filipe Manana <fdmanana@suse.com>
Btrfs: fix fitrim discarding device area reserved for boot loader's use
David Sterba <dsterba@suse.com>
btrfs: handle invalid num_stripes in sys_array
Eryu Guan <guaneryu@gmail.com>
ext4: don't read blocks from disk after extents being swapped
Insu Yun <wuninsu@gmail.com>
ext4: fix potential integer overflow
Jan Kara <jack@suse.cz>
ext4: fix scheduling in atomic on group checksum failure
Peter Hurley <peter@hurleysoftware.com>
serial: omap: Prevent DoS using unprivileged ioctl(TIOCSRS485)
Mika Westerberg <mika.westerberg@linux.intel.com>
serial: 8250_pci: Add Intel Broadwell ports
Jeremy McNicoll <jmcnicol@redhat.com>
tty: Add support for PCIe WCH382 2S multi-IO card
Herton R. Krzesinski <herton@redhat.com>
pty: make sure super_block is still valid in final /dev/tty close
Herton R. Krzesinski <herton@redhat.com>
pty: fix possible use after free of tty->driver_data
Peter Hurley <peter@hurleysoftware.com>
staging/speakup: Use tty_ldisc_ref() for paste kworker
Tony Lindgren <tony@atomide.com>
phy: twl4030-usb: Fix unbalanced pm_runtime_enable on module reload
Tony Lindgren <tony@atomide.com>
phy: twl4030-usb: Relase usb phy on unload
Takashi Iwai <tiwai@suse.de>
ALSA: seq: Fix double port list deletion
Takashi Iwai <tiwai@suse.de>
ALSA: seq: Fix leak of pool buffer at concurrent writes
Takashi Iwai <tiwai@suse.de>
ALSA: pcm: Fix rwsem deadlock for non-atomic PCM stream
Takashi Iwai <tiwai@suse.de>
ALSA: hda - Cancel probe work instead of flush at remove
Toshi Kani <toshi.kani@hpe.com>
x86/mm: Fix vmalloc_fault() to handle large pages properly
Toshi Kani <toshi.kani@hpe.com>
x86/uaccess/64: Handle the caching of 4-byte nocache copies properly in __copy_user_nocache()
Toshi Kani <toshi.kani@hpe.com>
x86/uaccess/64: Make the __copy_user_nocache() assembly code more readable
Matt Fleming <matt@codeblueprint.co.uk>
x86/mm/pat: Avoid truncation when converting cpa->numpages to address
Jan Beulich <JBeulich@suse.com>
x86/mm: Fix types used in pgprot cacheability flags translations
-------------
Diffstat:
MAINTAINERS | 4 +-
Makefile | 4 +-
arch/arm/boot/dts/armada-388-gp.dts | 10 --
arch/arm/boot/dts/at91-sama5d4_xplained.dts | 8 +-
arch/arm/boot/dts/at91-sama5d4ek.dts | 11 +++
arch/arm/boot/dts/logicpd-torpedo-som.dtsi | 1 +
arch/arm/boot/dts/omap5-board-common.dtsi | 33 +++++++
arch/arm/boot/dts/sama5d4.dtsi | 2 +-
arch/arm/boot/dts/ste-nomadik-stn8815.dtsi | 37 +++----
arch/arm/common/icst.c | 9 +-
arch/arm/mach-omap2/sleep34xx.S | 61 ++++++------
arch/arm/mach-omap2/sleep44xx.S | 25 +++--
arch/arm64/mm/dma-mapping.c | 4 +
arch/arm64/mm/pageattr.c | 3 +
arch/m32r/kernel/setup.c | 3 +
arch/powerpc/include/asm/eeh.h | 1 +
arch/powerpc/kernel/eeh_driver.c | 3 +
arch/powerpc/kernel/eeh_pe.c | 35 +++----
arch/powerpc/kernel/misc_64.S | 28 ------
arch/powerpc/kernel/module_64.c | 14 ++-
arch/powerpc/kvm/book3s_hv_rmhandlers.S | 2 +-
arch/powerpc/kvm/powerpc.c | 20 ++--
arch/powerpc/platforms/powernv/eeh-powernv.c | 5 +-
arch/powerpc/platforms/powernv/pci-ioda.c | 1 +
arch/powerpc/platforms/powernv/pci.c | 26 +++++
arch/powerpc/platforms/powernv/pci.h | 1 +
arch/x86/include/asm/pgtable_types.h | 6 +-
arch/x86/lib/copy_user_64.S | 142 +++++++++++++++++++--------
arch/x86/mm/fault.c | 15 ++-
arch/x86/mm/pageattr.c | 4 +-
drivers/hwspinlock/hwspinlock_core.c | 4 +
drivers/iio/accel/Kconfig | 1 +
drivers/iio/adc/Kconfig | 1 +
drivers/iio/adc/ti_am335x_adc.c | 2 +-
drivers/iio/dac/mcp4725.c | 1 +
drivers/iio/imu/adis_buffer.c | 2 +-
drivers/iio/inkern.c | 2 +
drivers/iio/light/acpi-als.c | 6 +-
drivers/iio/light/ltr501.c | 2 +-
drivers/iio/pressure/mpl115.c | 2 +-
drivers/input/mouse/elantech.c | 2 +-
drivers/input/mouse/vmmouse.c | 13 +--
drivers/input/serio/i8042-x86ia64io.h | 7 ++
drivers/iommu/amd_iommu.c | 2 +-
drivers/iommu/dmar.c | 2 +-
drivers/iommu/intel-iommu.c | 2 +-
drivers/iommu/intel-svm.c | 37 +++++--
drivers/iommu/intel_irq_remapping.c | 2 +-
drivers/nvdimm/namespace_devs.c | 53 ++++++++++
drivers/nvdimm/region_devs.c | 56 -----------
drivers/phy/phy-twl4030-usb.c | 14 ++-
drivers/platform/x86/intel_scu_ipcutil.c | 2 +-
drivers/scsi/device_handler/scsi_dh_rdac.c | 4 +-
drivers/scsi/scsi_devinfo.c | 2 +
drivers/scsi/scsi_sysfs.c | 6 +-
drivers/scsi/sd.c | 7 +-
drivers/scsi/sg.c | 2 +-
drivers/scsi/sr.c | 4 +
drivers/staging/speakup/selection.c | 5 +-
drivers/target/iscsi/iscsi_target_configfs.c | 16 ++-
drivers/tty/pty.c | 21 +++-
drivers/tty/serial/8250/8250_pci.c | 50 ++++++++++
drivers/tty/serial/omap-serial.c | 8 +-
drivers/usb/host/xhci-ring.c | 10 --
drivers/usb/host/xhci.c | 4 +-
fs/btrfs/backref.c | 10 +-
fs/btrfs/delayed-inode.c | 3 +-
fs/btrfs/delayed-inode.h | 2 +-
fs/btrfs/disk-io.c | 1 -
fs/btrfs/inode.c | 16 ++-
fs/btrfs/ioctl.c | 119 +++++++++++++++++-----
fs/btrfs/volumes.c | 28 ++++--
fs/cifs/cifs_debug.c | 2 +-
fs/cifs/cifs_debug.h | 9 +-
fs/cifs/cifsencrypt.c | 2 +-
fs/cifs/connect.c | 2 +-
fs/cifs/readdir.c | 1 +
fs/cifs/transport.c | 6 +-
fs/devpts/inode.c | 20 ++++
fs/ext4/balloc.c | 7 +-
fs/ext4/ialloc.c | 6 +-
fs/ext4/move_extent.c | 15 ++-
fs/ext4/resize.c | 2 +-
fs/hugetlbfs/inode.c | 19 ++--
fs/nfs/flexfilelayout/flexfilelayout.c | 8 +-
fs/nfs/inode.c | 54 +++++++---
fs/nfs/nfs4proc.c | 2 +-
fs/overlayfs/copy_up.c | 41 +++++---
fs/overlayfs/inode.c | 13 +++
fs/overlayfs/readdir.c | 3 +-
fs/overlayfs/super.c | 5 +
fs/proc/array.c | 2 +-
fs/proc/base.c | 21 ++--
fs/proc/namespaces.c | 4 +-
fs/proc/task_mmu.c | 7 +-
fs/timerfd.c | 2 +-
fs/udf/inode.c | 15 +++
fs/udf/unicode.c | 21 +++-
fs/xfs/libxfs/xfs_format.h | 2 +-
fs/xfs/libxfs/xfs_inode_buf.c | 12 ++-
fs/xfs/xfs_buf.c | 17 ++++
fs/xfs/xfs_trans_ail.c | 1 -
include/linux/compiler.h | 2 +-
include/linux/devpts_fs.h | 4 +
include/linux/intel-iommu.h | 3 +
include/linux/ptrace.h | 24 ++++-
include/linux/radix-tree.h | 22 ++++-
include/linux/rmap.h | 14 ---
include/linux/tracepoint.h | 5 +
ipc/shm.c | 53 ++++++++--
kernel/events/core.c | 2 +-
kernel/futex.c | 7 +-
kernel/futex_compat.c | 2 +-
kernel/kcmp.c | 4 +-
kernel/memremap.c | 2 +-
kernel/module.c | 28 +++---
kernel/ptrace.c | 39 ++++++--
kernel/sys.c | 20 ++--
kernel/time/itimer.c | 2 +-
kernel/time/posix-timers.c | 2 +-
lib/dma-debug.c | 2 +-
lib/dump_stack.c | 7 +-
lib/klist.c | 6 +-
lib/radix-tree.c | 12 ++-
lib/string_helpers.c | 63 ++++++++----
mm/memcontrol.c | 11 ++-
mm/memory-failure.c | 2 +-
mm/mlock.c | 2 +-
mm/mmap.c | 89 ++++++++++-------
mm/pgtable-generic.c | 4 +-
mm/process_vm_access.c | 2 +-
net/sunrpc/xprtsock.c | 49 ++++-----
scripts/bloat-o-meter | 8 +-
scripts/mod/modpost.c | 3 +-
security/commoncap.c | 7 +-
sound/core/pcm_native.c | 16 ++-
sound/core/seq/seq_memory.c | 13 ++-
sound/core/seq/seq_ports.c | 13 ++-
sound/pci/hda/hda_intel.c | 4 +-
tools/lib/traceevent/event-parse.c | 5 +-
tools/perf/util/parse-events.c | 3 +
tools/perf/util/session.c | 2 +-
virt/kvm/arm/arch_timer.c | 9 +-
143 files changed, 1320 insertions(+), 619 deletions(-)
[toc] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:10 +0100 |
| Subject | [PATCH 4.4 023/137] Revert "btrfs: clear PF_NOFREEZE in cleaner_kthread()" |
| Message-ID | <r5yVZ-7pJ-45@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Sterba <dsterba@suse.com>
commit 80ad623edd2d0ccb47d85357ee31c97e6c684e82 upstream.
This reverts commit 696249132158014d594896df3a81390616069c5c. The
cleaner thread can block freezing when there's a snapshot cleaning in
progress and the other threads get suspended first. From the logs
provided by Martin we're waiting for reading extent pages:
kernel: PM: Syncing filesystems ... done.
kernel: Freezing user space processes ... (elapsed 0.015 seconds) done.
kernel: Freezing remaining freezable tasks ...
kernel: Freezing of tasks failed after 20.003 seconds (1 tasks refusing to freeze, wq_busy=0):
kernel: btrfs-cleaner D ffff88033dd13bc0 0 152 2 0x00000000
kernel: ffff88032ebc2e00 ffff88032e750000 ffff88032e74fa50 7fffffffffffffff
kernel: ffffffff814a58df 0000000000000002 ffffea000934d580 ffffffff814a5451
kernel: 7fffffffffffffff ffffffff814a6e8f 0000000000000000 0000000000000020
kernel: Call Trace:
kernel: [<ffffffff814a58df>] ? bit_wait+0x2c/0x2c
kernel: [<ffffffff814a5451>] ? schedule+0x6f/0x7c
kernel: [<ffffffff814a6e8f>] ? schedule_timeout+0x2f/0xd8
kernel: [<ffffffff81076f94>] ? timekeeping_get_ns+0xa/0x2e
kernel: [<ffffffff81077603>] ? ktime_get+0x36/0x44
kernel: [<ffffffff814a4f6c>] ? io_schedule_timeout+0x94/0xf2
kernel: [<ffffffff814a4f6c>] ? io_schedule_timeout+0x94/0xf2
kernel: [<ffffffff814a590b>] ? bit_wait_io+0x2c/0x30
kernel: [<ffffffff814a5694>] ? __wait_on_bit+0x41/0x73
kernel: [<ffffffff8109eba8>] ? wait_on_page_bit+0x6d/0x72
kernel: [<ffffffff8105d718>] ? autoremove_wake_function+0x2a/0x2a
kernel: [<ffffffff811a02d7>] ? read_extent_buffer_pages+0x1bd/0x203
kernel: [<ffffffff8117d9e9>] ? free_root_pointers+0x4c/0x4c
kernel: [<ffffffff8117e831>] ? btree_read_extent_buffer_pages.constprop.57+0x5a/0xe9
kernel: [<ffffffff8117f4f3>] ? read_tree_block+0x2d/0x45
kernel: [<ffffffff8116782a>] ? read_block_for_search.isra.34+0x22a/0x26b
kernel: [<ffffffff811656c3>] ? btrfs_set_path_blocking+0x1e/0x4a
kernel: [<ffffffff8116919b>] ? btrfs_search_slot+0x648/0x736
kernel: [<ffffffff81170559>] ? btrfs_lookup_extent_info+0xb7/0x2c7
kernel: [<ffffffff81170ee5>] ? walk_down_proc+0x9c/0x1ae
kernel: [<ffffffff81171c9d>] ? walk_down_tree+0x40/0xa4
kernel: [<ffffffff8117375f>] ? btrfs_drop_snapshot+0x2da/0x664
kernel: [<ffffffff8104ff21>] ? finish_task_switch+0x126/0x167
kernel: [<ffffffff811850f8>] ? btrfs_clean_one_deleted_snapshot+0xa6/0xb0
kernel: [<ffffffff8117eaba>] ? cleaner_kthread+0x13e/0x17b
kernel: [<ffffffff8117e97c>] ? btrfs_item_end+0x33/0x33
kernel: [<ffffffff8104d256>] ? kthread+0x95/0x9d
kernel: [<ffffffff8104d1c1>] ? kthread_parkme+0x16/0x16
kernel: [<ffffffff814a7b5f>] ? ret_from_fork+0x3f/0x70
kernel: [<ffffffff8104d1c1>] ? kthread_parkme+0x16/0x16
As this affects a released kernel (4.4) we need a minimal fix for
stable kernels.
Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=108361
Reported-by: Martin Ziegler <ziegler@uni-freiburg.de>
CC: Jiri Kosina <jkosina@suse.cz>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Chris Mason <clm@fb.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/btrfs/disk-io.c | 1 -
1 file changed, 1 deletion(-)
--- a/fs/btrfs/disk-io.c
+++ b/fs/btrfs/disk-io.c
@@ -1762,7 +1762,6 @@ static int cleaner_kthread(void *arg)
int again;
struct btrfs_trans_handle *trans;
- set_freezable();
do {
again = 0;
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:10 +0100 |
| Subject | [PATCH 4.4 026/137] Btrfs: fix page reading in extent_same ioctl leading to csum errors |
| Message-ID | <r5yW0-7pJ-57@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
commit 313140023026ae542ad76e7e268c56a1eaa2c28e upstream.
In the extent_same ioctl, we were grabbing the pages (locked) and
attempting to read them without bothering about any concurrent IO
against them. That is, we were not checking for any ongoing ordered
extents nor waiting for them to complete, which leads to a race where
the extent_same() code gets a checksum verification error when it
reads the pages, producing a message like the following in dmesg
and making the operation fail to user space with -ENOMEM:
[18990.161265] BTRFS warning (device sdc): csum failed ino 259 off 495616 csum 685204116 expected csum 1515870868
Fix this by using btrfs_readpage() for reading the pages instead of
extent_read_full_page_nolock(), which waits for any concurrent ordered
extents to complete and locks the io range. Also do better error handling
and don't treat all failures as -ENOMEM, as that's clearly misleasing,
becoming identical to the checks and operation of prepare_uptodate_page().
The use of extent_read_full_page_nolock() was required before
commit f441460202cb ("btrfs: fix deadlock with extent-same and readpage"),
as we had the range locked in an inode's io tree before attempting to
read the pages.
Fixes: f441460202cb ("btrfs: fix deadlock with extent-same and readpage")
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/btrfs/ioctl.c | 29 +++++++++++++++++++++--------
1 file changed, 21 insertions(+), 8 deletions(-)
--- a/fs/btrfs/ioctl.c
+++ b/fs/btrfs/ioctl.c
@@ -2782,21 +2782,27 @@ out:
static struct page *extent_same_get_page(struct inode *inode, pgoff_t index)
{
struct page *page;
- struct extent_io_tree *tree = &BTRFS_I(inode)->io_tree;
page = grab_cache_page(inode->i_mapping, index);
if (!page)
- return NULL;
+ return ERR_PTR(-ENOMEM);
if (!PageUptodate(page)) {
- if (extent_read_full_page_nolock(tree, page, btrfs_get_extent,
- 0))
- return NULL;
+ int ret;
+
+ ret = btrfs_readpage(NULL, page);
+ if (ret)
+ return ERR_PTR(ret);
lock_page(page);
if (!PageUptodate(page)) {
unlock_page(page);
page_cache_release(page);
- return NULL;
+ return ERR_PTR(-EIO);
+ }
+ if (page->mapping != inode->i_mapping) {
+ unlock_page(page);
+ page_cache_release(page);
+ return ERR_PTR(-EAGAIN);
}
}
@@ -2810,9 +2816,16 @@ static int gather_extent_pages(struct in
pgoff_t index = off >> PAGE_CACHE_SHIFT;
for (i = 0; i < num_pages; i++) {
+again:
pages[i] = extent_same_get_page(inode, index + i);
- if (!pages[i])
- return -ENOMEM;
+ if (IS_ERR(pages[i])) {
+ int err = PTR_ERR(pages[i]);
+
+ if (err == -EAGAIN)
+ goto again;
+ pages[i] = NULL;
+ return err;
+ }
}
return 0;
}
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:10 +0100 |
| Subject | [PATCH 4.4 022/137] Btrfs: fix fitrim discarding device area reserved for boot loaders use |
| Message-ID | <r5yW0-7pJ-63@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
commit 8cdc7c5b00d945a3c823fc4277af304abb9cb43d upstream.
As of the 4.3 kernel release, the fitrim ioctl can now discard any region
of a disk that is not allocated to any chunk/block group, including the
first megabyte which is used for our primary superblock and by the boot
loader (grub for example).
Fix this by not allowing to trim/discard any region in the device starting
with an offset not greater than min(alloc_start_mount_option, 1Mb), just
as it was not possible before 4.3.
A reproducer test case for xfstests follows.
seq=`basename $0`
seqres=$RESULT_DIR/$seq
echo "QA output created by $seq"
tmp=/tmp/$$
status=1 # failure is the default!
trap "_cleanup; exit \$status" 0 1 2 3 15
_cleanup()
{
cd /
rm -f $tmp.*
}
# get standard environment, filters and checks
. ./common/rc
. ./common/filter
# real QA test starts here
_need_to_be_root
_supported_fs btrfs
_supported_os Linux
_require_scratch
rm -f $seqres.full
_scratch_mkfs >>$seqres.full 2>&1
# Write to the [0, 64Kb[ and [68Kb, 1Mb[ ranges of the device. These ranges are
# reserved for a boot loader to use (GRUB for example) and btrfs should never
# use them - neither for allocating metadata/data nor should trim/discard them.
# The range [64Kb, 68Kb[ is used for the primary superblock of the filesystem.
$XFS_IO_PROG -c "pwrite -S 0xfd 0 64K" $SCRATCH_DEV | _filter_xfs_io
$XFS_IO_PROG -c "pwrite -S 0xfd 68K 956K" $SCRATCH_DEV | _filter_xfs_io
# Now mount the filesystem and perform a fitrim against it.
_scratch_mount
_require_batched_discard $SCRATCH_MNT
$FSTRIM_PROG $SCRATCH_MNT
# Now unmount the filesystem and verify the content of the ranges was not
# modified (no trim/discard happened on them).
_scratch_unmount
echo "Content of the ranges [0, 64Kb] and [68Kb, 1Mb[ after fitrim:"
od -t x1 -N $((64 * 1024)) $SCRATCH_DEV
od -t x1 -j $((68 * 1024)) -N $((956 * 1024)) $SCRATCH_DEV
status=0
exit
Reported-by: Vincent Petry <PVince81@yahoo.fr>
Reported-by: Andrei Borzenkov <arvidjaar@gmail.com>
Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=109341
Fixes: 499f377f49f0 (btrfs: iterate over unused chunk space in FITRIM)
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/btrfs/volumes.c | 20 ++++++++++----------
1 file changed, 10 insertions(+), 10 deletions(-)
--- a/fs/btrfs/volumes.c
+++ b/fs/btrfs/volumes.c
@@ -1257,6 +1257,15 @@ int find_free_dev_extent_start(struct bt
int ret;
int slot;
struct extent_buffer *l;
+ u64 min_search_start;
+
+ /*
+ * We don't want to overwrite the superblock on the drive nor any area
+ * used by the boot loader (grub for example), so we make sure to start
+ * at an offset of at least 1MB.
+ */
+ min_search_start = max(root->fs_info->alloc_start, 1024ull * 1024);
+ search_start = max(search_start, min_search_start);
path = btrfs_alloc_path();
if (!path)
@@ -1397,18 +1406,9 @@ int find_free_dev_extent(struct btrfs_tr
struct btrfs_device *device, u64 num_bytes,
u64 *start, u64 *len)
{
- struct btrfs_root *root = device->dev_root;
- u64 search_start;
-
/* FIXME use last free of some kind */
-
- /*
- * we don't want to overwrite the superblock on the drive,
- * so we make sure to start at an offset of at least 1MB
- */
- search_start = max(root->fs_info->alloc_start, 1024ull * 1024);
return find_free_dev_extent_start(trans->transaction, device,
- num_bytes, search_start, start, len);
+ num_bytes, 0, start, len);
}
static int btrfs_free_dev_extent(struct btrfs_trans_handle *trans,
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 092/137] libnvdimm: fix namespace object confusion in is_uuid_busy() |
| Message-ID | <r5z5E-7tx-7@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dan Williams <dan.j.williams@intel.com>
commit e07ecd76d4db7bda1e9495395b2110a3fe28845a upstream.
When btt devices were re-worked to be child devices of regions this
routine was overlooked. It mistakenly attempts to_nd_namespace_pmem()
or to_nd_namespace_blk() conversions on btt and pfn devices. By luck to
date we have happened to be hitting valid memory leading to a uuid
miscompare, but a recent change to struct nd_namespace_common causes:
BUG: unable to handle kernel NULL pointer dereference at 0000000000000001
IP: [<ffffffff814610dc>] memcmp+0xc/0x40
[..]
Call Trace:
[<ffffffffa0028631>] is_uuid_busy+0xc1/0x2a0 [libnvdimm]
[<ffffffffa0028570>] ? to_nd_blk_region+0x50/0x50 [libnvdimm]
[<ffffffff8158c9c0>] device_for_each_child+0x50/0x90
Signed-off-by: Dan Williams <dan.j.williams@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/nvdimm/namespace_devs.c | 53 +++++++++++++++++++++++++++++++++++++
drivers/nvdimm/region_devs.c | 56 ----------------------------------------
2 files changed, 53 insertions(+), 56 deletions(-)
--- a/drivers/nvdimm/namespace_devs.c
+++ b/drivers/nvdimm/namespace_devs.c
@@ -77,6 +77,59 @@ static bool is_namespace_io(struct devic
return dev ? dev->type == &namespace_io_device_type : false;
}
+static int is_uuid_busy(struct device *dev, void *data)
+{
+ u8 *uuid1 = data, *uuid2 = NULL;
+
+ if (is_namespace_pmem(dev)) {
+ struct nd_namespace_pmem *nspm = to_nd_namespace_pmem(dev);
+
+ uuid2 = nspm->uuid;
+ } else if (is_namespace_blk(dev)) {
+ struct nd_namespace_blk *nsblk = to_nd_namespace_blk(dev);
+
+ uuid2 = nsblk->uuid;
+ } else if (is_nd_btt(dev)) {
+ struct nd_btt *nd_btt = to_nd_btt(dev);
+
+ uuid2 = nd_btt->uuid;
+ } else if (is_nd_pfn(dev)) {
+ struct nd_pfn *nd_pfn = to_nd_pfn(dev);
+
+ uuid2 = nd_pfn->uuid;
+ }
+
+ if (uuid2 && memcmp(uuid1, uuid2, NSLABEL_UUID_LEN) == 0)
+ return -EBUSY;
+
+ return 0;
+}
+
+static int is_namespace_uuid_busy(struct device *dev, void *data)
+{
+ if (is_nd_pmem(dev) || is_nd_blk(dev))
+ return device_for_each_child(dev, data, is_uuid_busy);
+ return 0;
+}
+
+/**
+ * nd_is_uuid_unique - verify that no other namespace has @uuid
+ * @dev: any device on a nvdimm_bus
+ * @uuid: uuid to check
+ */
+bool nd_is_uuid_unique(struct device *dev, u8 *uuid)
+{
+ struct nvdimm_bus *nvdimm_bus = walk_to_nvdimm_bus(dev);
+
+ if (!nvdimm_bus)
+ return false;
+ WARN_ON_ONCE(!is_nvdimm_bus_locked(&nvdimm_bus->dev));
+ if (device_for_each_child(&nvdimm_bus->dev, uuid,
+ is_namespace_uuid_busy) != 0)
+ return false;
+ return true;
+}
+
bool pmem_should_map_pages(struct device *dev)
{
struct nd_region *nd_region = to_nd_region(dev->parent);
--- a/drivers/nvdimm/region_devs.c
+++ b/drivers/nvdimm/region_devs.c
@@ -134,62 +134,6 @@ int nd_region_to_nstype(struct nd_region
}
EXPORT_SYMBOL(nd_region_to_nstype);
-static int is_uuid_busy(struct device *dev, void *data)
-{
- struct nd_region *nd_region = to_nd_region(dev->parent);
- u8 *uuid = data;
-
- switch (nd_region_to_nstype(nd_region)) {
- case ND_DEVICE_NAMESPACE_PMEM: {
- struct nd_namespace_pmem *nspm = to_nd_namespace_pmem(dev);
-
- if (!nspm->uuid)
- break;
- if (memcmp(uuid, nspm->uuid, NSLABEL_UUID_LEN) == 0)
- return -EBUSY;
- break;
- }
- case ND_DEVICE_NAMESPACE_BLK: {
- struct nd_namespace_blk *nsblk = to_nd_namespace_blk(dev);
-
- if (!nsblk->uuid)
- break;
- if (memcmp(uuid, nsblk->uuid, NSLABEL_UUID_LEN) == 0)
- return -EBUSY;
- break;
- }
- default:
- break;
- }
-
- return 0;
-}
-
-static int is_namespace_uuid_busy(struct device *dev, void *data)
-{
- if (is_nd_pmem(dev) || is_nd_blk(dev))
- return device_for_each_child(dev, data, is_uuid_busy);
- return 0;
-}
-
-/**
- * nd_is_uuid_unique - verify that no other namespace has @uuid
- * @dev: any device on a nvdimm_bus
- * @uuid: uuid to check
- */
-bool nd_is_uuid_unique(struct device *dev, u8 *uuid)
-{
- struct nvdimm_bus *nvdimm_bus = walk_to_nvdimm_bus(dev);
-
- if (!nvdimm_bus)
- return false;
- WARN_ON_ONCE(!is_nvdimm_bus_locked(&nvdimm_bus->dev));
- if (device_for_each_child(&nvdimm_bus->dev, uuid,
- is_namespace_uuid_busy) != 0)
- return false;
- return true;
-}
-
static ssize_t size_show(struct device *dev,
struct device_attribute *attr, char *buf)
{
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 104/137] iommu/vt-d: Clear PPR bit to ensure we get more page request interrupts |
| Message-ID | <r5z5E-7tx-5@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Woodhouse <David.Woodhouse@intel.com>
commit 46924008273ed03bd11dbb32136e3da4cfe056e1 upstream.
According to the VT-d specification we need to clear the PPR bit in
the Page Request Status register when handling page requests, or the
hardware won't generate any more interrupts.
This wasn't actually necessary on SKL/KBL (which may well be the
subject of a hardware erratum, although it's harmless enough). But
other implementations do appear to get it right, and we only ever get
one interrupt unless we clear the PPR bit.
Reported-by: CQ Tang <cq.tang@intel.com>
Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/iommu/intel-svm.c | 4 ++++
include/linux/intel-iommu.h | 3 +++
2 files changed, 7 insertions(+)
--- a/drivers/iommu/intel-svm.c
+++ b/drivers/iommu/intel-svm.c
@@ -524,6 +524,10 @@ static irqreturn_t prq_event_thread(int
struct intel_svm *svm = NULL;
int head, tail, handled = 0;
+ /* Clear PPR bit before reading head/tail registers, to
+ * ensure that we get a new interrupt if needed. */
+ writel(DMA_PRS_PPR, iommu->reg + DMAR_PRS_REG);
+
tail = dmar_readq(iommu->reg + DMAR_PQT_REG) & PRQ_RING_MASK;
head = dmar_readq(iommu->reg + DMAR_PQH_REG) & PRQ_RING_MASK;
while (head != tail) {
--- a/include/linux/intel-iommu.h
+++ b/include/linux/intel-iommu.h
@@ -235,6 +235,9 @@ static inline void dmar_writeq(void __io
/* low 64 bit */
#define dma_frcd_page_addr(d) (d & (((u64)-1) << PAGE_SHIFT))
+/* PRS_REG */
+#define DMA_PRS_PPR ((u32)1)
+
#define IOMMU_WAIT_OP(iommu, offset, op, cond, sts) \
do { \
cycles_t start_time = get_cycles(); \
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 128/137] libxfs: pack the agfl header structure so XFS_AGFL_SIZE is correct |
| Message-ID | <r5z5E-7tx-11@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <darrick.wong@oracle.com>
commit 96f859d52bcb1c6ea6f3388d39862bf7143e2f30 upstream.
Because struct xfs_agfl is 36 bytes long and has a 64-bit integer
inside it, gcc will quietly round the structure size up to the nearest
64 bits -- in this case, 40 bytes. This results in the XFS_AGFL_SIZE
macro returning incorrect results for v5 filesystems on 64-bit
machines (118 items instead of 119). As a result, a 32-bit xfs_repair
will see garbage in AGFL item 119 and complain.
Therefore, tell gcc not to pad the structure so that the AGFL size
calculation is correct.
Signed-off-by: Darrick J. Wong <darrick.wong@oracle.com>
Reviewed-by: Dave Chinner <dchinner@redhat.com>
Signed-off-by: Dave Chinner <david@fromorbit.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/libxfs/xfs_format.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/fs/xfs/libxfs/xfs_format.h
+++ b/fs/xfs/libxfs/xfs_format.h
@@ -786,7 +786,7 @@ typedef struct xfs_agfl {
__be64 agfl_lsn;
__be32 agfl_crc;
__be32 agfl_bno[]; /* actually XFS_AGFL_SIZE(mp) */
-} xfs_agfl_t;
+} __attribute__((packed)) xfs_agfl_t;
#define XFS_AGFL_CRC_OFF offsetof(struct xfs_agfl, agfl_crc)
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 068/137] powerpc/ioda: Set "read" permission when "write" is set |
| Message-ID | <r5z5E-7tx-9@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexey Kardashevskiy <aik@ozlabs.ru>
commit 6ecad912a0073c768db1491c27ca55ad2d0ee68f upstream.
Quite often drivers set only "write" permission assuming that this
includes "read" permission as well and this works on plenty of
platforms. However IODA2 is strict about this and produces an EEH when
"read" permission is not set and reading happens.
This adds a workaround in the IODA code to always add the "read" bit
when the "write" bit is set.
Fixes: 10b35b2b7485 ("powerpc/powernv: Do not set "read" flag if direction==DMA_NONE")
Cc: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Signed-off-by: Alexey Kardashevskiy <aik@ozlabs.ru>
Tested-by: Douglas Miller <dougmill@linux.vnet.ibm.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/powerpc/platforms/powernv/pci.c | 6 ++++++
1 file changed, 6 insertions(+)
--- a/arch/powerpc/platforms/powernv/pci.c
+++ b/arch/powerpc/platforms/powernv/pci.c
@@ -601,6 +601,9 @@ int pnv_tce_build(struct iommu_table *tb
u64 rpn = __pa(uaddr) >> tbl->it_page_shift;
long i;
+ if (proto_tce & TCE_PCI_WRITE)
+ proto_tce |= TCE_PCI_READ;
+
for (i = 0; i < npages; i++) {
unsigned long newtce = proto_tce |
((rpn + i) << tbl->it_page_shift);
@@ -622,6 +625,9 @@ int pnv_tce_xchg(struct iommu_table *tbl
BUG_ON(*hpa & ~IOMMU_PAGE_MASK(tbl));
+ if (newtce & TCE_PCI_WRITE)
+ newtce |= TCE_PCI_READ;
+
oldtce = xchg(pnv_tce(tbl, idx), cpu_to_be64(newtce));
*hpa = be64_to_cpu(oldtce) & ~(TCE_PCI_READ | TCE_PCI_WRITE);
*direction = iommu_tce_direction(oldtce);
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 119/137] intel_scu_ipcutil: underflow in scu_reg_access() |
| Message-ID | <r5z5E-7tx-19@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dan Carpenter <dan.carpenter@oracle.com>
commit b1d353ad3d5835b16724653b33c05124e1b5acf1 upstream.
"count" is controlled by the user and it can be negative. Let's prevent
that by making it unsigned. You have to have CAP_SYS_RAWIO to call this
function so the bug is not as serious as it could be.
Fixes: 5369c02d951a ('intel_scu_ipc: Utility driver for intel scu ipc')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Darren Hart <dvhart@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/platform/x86/intel_scu_ipcutil.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/platform/x86/intel_scu_ipcutil.c
+++ b/drivers/platform/x86/intel_scu_ipcutil.c
@@ -49,7 +49,7 @@ struct scu_ipc_data {
static int scu_reg_access(u32 cmd, struct scu_ipc_data *data)
{
- int count = data->count;
+ unsigned int count = data->count;
if (count == 0 || count == 3 || count > 4)
return -EINVAL;
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 126/137] ovl: root: copy attr |
| Message-ID | <r5z5E-7tx-13@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know. ------------------ From: Miklos Szeredi <miklos@szeredi.hu> commit ed06e069775ad9236087594a1c1667367e983fb5 upstream. We copy i_uid and i_gid of underlying inode into overlayfs inode. Except for the root inode. Fix this omission. Signed-off-by: Miklos Szeredi <miklos@szeredi.hu> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> --- fs/overlayfs/super.c | 3 +++ 1 file changed, 3 insertions(+) --- a/fs/overlayfs/super.c +++ b/fs/overlayfs/super.c @@ -1053,6 +1053,9 @@ static int ovl_fill_super(struct super_b root_dentry->d_fsdata = oe; + ovl_copyattr(ovl_dentry_real(root_dentry)->d_inode, + root_dentry->d_inode); + sb->s_magic = OVERLAYFS_SUPER_MAGIC; sb->s_op = &ovl_super_operations; sb->s_root = root_dentry;
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 108/137] dma-debug: switch check from _text to _stext |
| Message-ID | <r5z5F-7tx-29@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Laura Abbott <labbott@fedoraproject.org>
commit ea535e418c01837d07b6c94e817540f50bfdadb0 upstream.
In include/asm-generic/sections.h:
/*
* Usage guidelines:
* _text, _data: architecture specific, don't use them in
* arch-independent code
* [_stext, _etext]: contains .text.* sections, may also contain
* .rodata.*
* and/or .init.* sections
_text is not guaranteed across architectures. Architectures such as ARM
may reuse parts which are not actually text and erroneously trigger a bug.
Switch to using _stext which is guaranteed to contain text sections.
Came out of https://lkml.kernel.org/g/<567B1176.4000106@redhat.com>
Signed-off-by: Laura Abbott <labbott@fedoraproject.org>
Reviewed-by: Kees Cook <keescook@chromium.org>
Cc: Russell King <linux@arm.linux.org.uk>
Cc: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
lib/dma-debug.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/lib/dma-debug.c
+++ b/lib/dma-debug.c
@@ -1181,7 +1181,7 @@ static inline bool overlap(void *addr, u
static void check_for_illegal_area(struct device *dev, void *addr, unsigned long len)
{
- if (overlap(addr, len, _text, _etext) ||
+ if (overlap(addr, len, _stext, _etext) ||
overlap(addr, len, __start_rodata, __end_rodata))
err_printk(dev, NULL, "DMA-API: device driver maps memory from kernel text or rodata [addr=%p] [len=%lu]\n", addr, len);
}
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 095/137] mm: fix regression in remap_file_pages() emulation |
| Message-ID | <r5z5E-7tx-17@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
commit 48f7df329474b49d83d0dffec1b6186647f11976 upstream.
Grazvydas Ignotas has reported a regression in remap_file_pages()
emulation.
Testcase:
#define _GNU_SOURCE
#include <assert.h>
#include <stdlib.h>
#include <stdio.h>
#include <sys/mman.h>
#define SIZE (4096 * 3)
int main(int argc, char **argv)
{
unsigned long *p;
long i;
p = mmap(NULL, SIZE, PROT_READ | PROT_WRITE,
MAP_SHARED | MAP_ANONYMOUS, -1, 0);
if (p == MAP_FAILED) {
perror("mmap");
return -1;
}
for (i = 0; i < SIZE / 4096; i++)
p[i * 4096 / sizeof(*p)] = i;
if (remap_file_pages(p, 4096, 0, 1, 0)) {
perror("remap_file_pages");
return -1;
}
if (remap_file_pages(p, 4096 * 2, 0, 1, 0)) {
perror("remap_file_pages");
return -1;
}
assert(p[0] == 1);
munmap(p, SIZE);
return 0;
}
The second remap_file_pages() fails with -EINVAL.
The reason is that remap_file_pages() emulation assumes that the target
vma covers whole area we want to over map. That assumption is broken by
first remap_file_pages() call: it split the area into two vma.
The solution is to check next adjacent vmas, if they map the same file
with the same flags.
Fixes: c8d78c1823f4 ("mm: replace remap_file_pages() syscall with emulation")
Signed-off-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Reported-by: Grazvydas Ignotas <notasas@gmail.com>
Tested-by: Grazvydas Ignotas <notasas@gmail.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/mmap.c | 34 +++++++++++++++++++++++++++++-----
1 file changed, 29 insertions(+), 5 deletions(-)
--- a/mm/mmap.c
+++ b/mm/mmap.c
@@ -2668,12 +2668,29 @@ SYSCALL_DEFINE5(remap_file_pages, unsign
if (!vma || !(vma->vm_flags & VM_SHARED))
goto out;
- if (start < vma->vm_start || start + size > vma->vm_end)
+ if (start < vma->vm_start)
goto out;
- if (pgoff == linear_page_index(vma, start)) {
- ret = 0;
- goto out;
+ if (start + size > vma->vm_end) {
+ struct vm_area_struct *next;
+
+ for (next = vma->vm_next; next; next = next->vm_next) {
+ /* hole between vmas ? */
+ if (next->vm_start != next->vm_prev->vm_end)
+ goto out;
+
+ if (next->vm_file != vma->vm_file)
+ goto out;
+
+ if (next->vm_flags != vma->vm_flags)
+ goto out;
+
+ if (start + size <= next->vm_end)
+ break;
+ }
+
+ if (!next)
+ goto out;
}
prot |= vma->vm_flags & VM_READ ? PROT_READ : 0;
@@ -2683,9 +2700,16 @@ SYSCALL_DEFINE5(remap_file_pages, unsign
flags &= MAP_NONBLOCK;
flags |= MAP_SHARED | MAP_FIXED | MAP_POPULATE;
if (vma->vm_flags & VM_LOCKED) {
+ struct vm_area_struct *tmp;
flags |= MAP_LOCKED;
+
/* drop PG_Mlocked flag for over-mapped range */
- munlock_vma_pages_range(vma, start, start + size);
+ for (tmp = vma; tmp->vm_start >= start + size;
+ tmp = tmp->vm_next) {
+ munlock_vma_pages_range(tmp,
+ max(tmp->vm_start, start),
+ min(tmp->vm_end, start + size));
+ }
}
file = get_file(vma->vm_file);
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 122/137] futex: Drop refcount if requeue_pi() acquired the rtmutex |
| Message-ID | <r5z5E-7tx-21@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Gleixner <tglx@linutronix.de>
commit fb75a4282d0d9a3c7c44d940582c2d226cf3acfb upstream.
If the proxy lock in the requeue loop acquires the rtmutex for a
waiter then it acquired also refcount on the pi_state related to the
futex, but the waiter side does not drop the reference count.
Add the missing free_pi_state() call.
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Darren Hart <darren@dvhart.com>
Cc: Davidlohr Bueso <dave@stgolabs.net>
Cc: Bhuvanesh_Surachari@mentor.com
Cc: Andy Lowe <Andy_Lowe@mentor.com>
Link: http://lkml.kernel.org/r/20151219200607.178132067@linutronix.de
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/futex.c | 5 +++++
1 file changed, 5 insertions(+)
--- a/kernel/futex.c
+++ b/kernel/futex.c
@@ -2755,6 +2755,11 @@ static int futex_wait_requeue_pi(u32 __u
if (q.pi_state && (q.pi_state->owner != current)) {
spin_lock(q.lock_ptr);
ret = fixup_pi_state_owner(uaddr2, &q, current);
+ /*
+ * Drop the reference to the pi state which
+ * the requeue_pi() code acquired for us.
+ */
+ free_pi_state(q.pi_state);
spin_unlock(q.lock_ptr);
}
} else {
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 004/137] x86/uaccess/64: Handle the caching of 4-byte nocache copies properly in __copy_user_nocache() |
| Message-ID | <r5z5F-7tx-31@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know. ------------------ From: Toshi Kani <toshi.kani@hpe.com> commit a82eee7424525e34e98d821dd059ce14560a1e35 upstream. Data corruption issues were observed in tests which initiated a system crash/reset while accessing BTT devices. This problem is reproducible. The BTT driver calls pmem_rw_bytes() to update data in pmem devices. This interface calls __copy_user_nocache(), which uses non-temporal stores so that the stores to pmem are persistent. __copy_user_nocache() uses non-temporal stores when a request size is 8 bytes or larger (and is aligned by 8 bytes). The BTT driver updates the BTT map table, which entry size is 4 bytes. Therefore, updates to the map table entries remain cached, and are not written to pmem after a crash. Change __copy_user_nocache() to use non-temporal store when a request size is 4 bytes. The change extends the current byte-copy path for a less-than-8-bytes request, and does not add any overhead to the regular path. Reported-and-tested-by: Micah Parrish <micah.parrish@hpe.com> Reported-and-tested-by: Brian Boylston <brian.boylston@hpe.com> Signed-off-by: Toshi Kani <toshi.kani@hpe.com> Cc: Andrew Morton <akpm@linux-foundation.org> Cc: Andy Lutomirski <luto@amacapital.net> Cc: Borislav Petkov <bp@alien8.de> Cc: Borislav Petkov <bp@suse.de> Cc: Brian Gerst <brgerst@gmail.com> Cc: Dan Williams <dan.j.williams@intel.com> Cc: Denys Vlasenko <dvlasenk@redhat.com> Cc: H. Peter Anvin <hpa@zytor.com> Cc: Linus Torvalds <torvalds@linux-foundation.org> Cc: Luis R. Rodriguez <mcgrof@suse.com> Cc: Peter Zijlstra <peterz@infradead.org> Cc: Ross Zwisler <ross.zwisler@linux.intel.com> Cc: Thomas Gleixner <tglx@linutronix.de> Cc: Toshi Kani <toshi.kani@hp.com> Cc: Vishal Verma <vishal.l.verma@intel.com> Cc: linux-nvdimm@lists.01.org Link: http://lkml.kernel.org/r/1455225857-12039-3-git-send-email-toshi.kani@hpe.com [ Small readability edits. ] Signed-off-by: Ingo Molnar <mingo@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> --- arch/x86/lib/copy_user_64.S | 36 ++++++++++++++++++++++++++++++++---- 1 file changed, 32 insertions(+), 4 deletions(-) --- a/arch/x86/lib/copy_user_64.S +++ b/arch/x86/lib/copy_user_64.S @@ -237,13 +237,14 @@ ENDPROC(copy_user_enhanced_fast_string) * Note: Cached memory copy is used when destination or size is not * naturally aligned. That is: * - Require 8-byte alignment when size is 8 bytes or larger. + * - Require 4-byte alignment when size is 4 bytes. */ ENTRY(__copy_user_nocache) ASM_STAC - /* If size is less than 8 bytes, go to byte copy */ + /* If size is less than 8 bytes, go to 4-byte copy */ cmpl $8,%edx - jb .L_1b_cache_copy_entry + jb .L_4b_nocache_copy_entry /* If destination is not 8-byte aligned, "cache" copy to align it */ ALIGN_DESTINATION @@ -282,7 +283,7 @@ ENTRY(__copy_user_nocache) movl %edx,%ecx andl $7,%edx shrl $3,%ecx - jz .L_1b_cache_copy_entry /* jump if count is 0 */ + jz .L_4b_nocache_copy_entry /* jump if count is 0 */ /* Perform 8-byte nocache loop-copy */ .L_8b_nocache_copy_loop: @@ -294,11 +295,33 @@ ENTRY(__copy_user_nocache) jnz .L_8b_nocache_copy_loop /* If no byte left, we're done */ -.L_1b_cache_copy_entry: +.L_4b_nocache_copy_entry: + andl %edx,%edx + jz .L_finish_copy + + /* If destination is not 4-byte aligned, go to byte copy: */ + movl %edi,%ecx + andl $3,%ecx + jnz .L_1b_cache_copy_entry + + /* Set 4-byte copy count (1 or 0) and remainder */ + movl %edx,%ecx + andl $3,%edx + shrl $2,%ecx + jz .L_1b_cache_copy_entry /* jump if count is 0 */ + + /* Perform 4-byte nocache copy: */ +30: movl (%rsi),%r8d +31: movnti %r8d,(%rdi) + leaq 4(%rsi),%rsi + leaq 4(%rdi),%rdi + + /* If no bytes left, we're done: */ andl %edx,%edx jz .L_finish_copy /* Perform byte "cache" loop-copy for the remainder */ +.L_1b_cache_copy_entry: movl %edx,%ecx .L_1b_cache_copy_loop: 40: movb (%rsi),%al @@ -323,6 +346,9 @@ ENTRY(__copy_user_nocache) .L_fixup_8b_copy: lea (%rdx,%rcx,8),%rdx jmp .L_fixup_handle_tail +.L_fixup_4b_copy: + lea (%rdx,%rcx,4),%rdx + jmp .L_fixup_handle_tail .L_fixup_1b_copy: movl %ecx,%edx .L_fixup_handle_tail: @@ -348,6 +374,8 @@ ENTRY(__copy_user_nocache) _ASM_EXTABLE(16b,.L_fixup_4x8b_copy) _ASM_EXTABLE(20b,.L_fixup_8b_copy) _ASM_EXTABLE(21b,.L_fixup_8b_copy) + _ASM_EXTABLE(30b,.L_fixup_4b_copy) + _ASM_EXTABLE(31b,.L_fixup_4b_copy) _ASM_EXTABLE(40b,.L_fixup_1b_copy) _ASM_EXTABLE(41b,.L_fixup_1b_copy) ENDPROC(__copy_user_nocache)
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 008/137] ALSA: seq: Fix leak of pool buffer at concurrent writes |
| Message-ID | <r5z5E-7tx-23@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit d99a36f4728fcbcc501b78447f625bdcce15b842 upstream.
When multiple concurrent writes happen on the ALSA sequencer device
right after the open, it may try to allocate vmalloc buffer for each
write and leak some of them. It's because the presence check and the
assignment of the buffer is done outside the spinlock for the pool.
The fix is to move the check and the assignment into the spinlock.
(The current implementation is suboptimal, as there can be multiple
unnecessary vmallocs because the allocation is done before the check
in the spinlock. But the pool size is already checked beforehand, so
this isn't a big problem; that is, the only possible path is the
multiple writes before any pool assignment, and practically seen, the
current coverage should be "good enough".)
The issue was triggered by syzkaller fuzzer.
BugLink: http://lkml.kernel.org/r/CACT4Y+bSzazpXNvtAr=WXaL8hptqjHwqEyFA+VN2AWEx=aurkg@mail.gmail.com
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Tested-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/core/seq/seq_memory.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
--- a/sound/core/seq/seq_memory.c
+++ b/sound/core/seq/seq_memory.c
@@ -383,15 +383,20 @@ int snd_seq_pool_init(struct snd_seq_poo
if (snd_BUG_ON(!pool))
return -EINVAL;
- if (pool->ptr) /* should be atomic? */
- return 0;
- pool->ptr = vmalloc(sizeof(struct snd_seq_event_cell) * pool->size);
- if (!pool->ptr)
+ cellptr = vmalloc(sizeof(struct snd_seq_event_cell) * pool->size);
+ if (!cellptr)
return -ENOMEM;
/* add new cells to the free cell list */
spin_lock_irqsave(&pool->lock, flags);
+ if (pool->ptr) {
+ spin_unlock_irqrestore(&pool->lock, flags);
+ vfree(cellptr);
+ return 0;
+ }
+
+ pool->ptr = cellptr;
pool->free = NULL;
for (cell = 0; cell < pool->size; cell++) {
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 123/137] ovl: allow zero size xattr |
| Message-ID | <r5z5F-7tx-33@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Miklos Szeredi <miklos@szeredi.hu>
commit 97daf8b97ad6f913a34c82515be64dc9ac08d63e upstream.
When ovl_copy_xattr() encountered a zero size xattr no more xattrs were
copied and the function returned success. This is clearly not the desired
behavior.
Signed-off-by: Miklos Szeredi <miklos@szeredi.hu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/overlayfs/copy_up.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/fs/overlayfs/copy_up.c
+++ b/fs/overlayfs/copy_up.c
@@ -54,7 +54,7 @@ int ovl_copy_xattr(struct dentry *old, s
for (name = buf; name < (buf + list_size); name += strlen(name) + 1) {
size = vfs_getxattr(old, name, value, XATTR_SIZE_MAX);
- if (size <= 0) {
+ if (size < 0) {
error = size;
goto out_free_value;
}
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 117/137] dump_stack: avoid potential deadlocks |
| Message-ID | <r5z5F-7tx-35@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
commit d7ce36924344ace0dbdc855b1206cacc46b36d45 upstream.
Some servers experienced fatal deadlocks because of a combination of
bugs, leading to multiple cpus calling dump_stack().
The checksumming bug was fixed in commit 34ae6a1aa054 ("ipv6: update
skb->csum when CE mark is propagated").
The second problem is a faulty locking in dump_stack()
CPU1 runs in process context and calls dump_stack(), grabs dump_lock.
CPU2 receives a TCP packet under softirq, grabs socket spinlock, and
call dump_stack() from netdev_rx_csum_fault().
dump_stack() spins on atomic_cmpxchg(&dump_lock, -1, 2), since
dump_lock is owned by CPU1
While dumping its stack, CPU1 is interrupted by a softirq, and happens
to process a packet for the TCP socket locked by CPU2.
CPU1 spins forever in spin_lock() : deadlock
Stack trace on CPU1 looked like :
NMI backtrace for cpu 1
RIP: _raw_spin_lock+0x25/0x30
...
Call Trace:
<IRQ>
tcp_v6_rcv+0x243/0x620
ip6_input_finish+0x11f/0x330
ip6_input+0x38/0x40
ip6_rcv_finish+0x3c/0x90
ipv6_rcv+0x2a9/0x500
process_backlog+0x461/0xaa0
net_rx_action+0x147/0x430
__do_softirq+0x167/0x2d0
call_softirq+0x1c/0x30
do_softirq+0x3f/0x80
irq_exit+0x6e/0xc0
smp_call_function_single_interrupt+0x35/0x40
call_function_single_interrupt+0x6a/0x70
<EOI>
printk+0x4d/0x4f
printk_address+0x31/0x33
print_trace_address+0x33/0x3c
print_context_stack+0x7f/0x119
dump_trace+0x26b/0x28e
show_trace_log_lvl+0x4f/0x5c
show_stack_log_lvl+0x104/0x113
show_stack+0x42/0x44
dump_stack+0x46/0x58
netdev_rx_csum_fault+0x38/0x3c
__skb_checksum_complete_head+0x6e/0x80
__skb_checksum_complete+0x11/0x20
tcp_rcv_established+0x2bd5/0x2fd0
tcp_v6_do_rcv+0x13c/0x620
sk_backlog_rcv+0x15/0x30
release_sock+0xd2/0x150
tcp_recvmsg+0x1c1/0xfc0
inet_recvmsg+0x7d/0x90
sock_recvmsg+0xaf/0xe0
___sys_recvmsg+0x111/0x3b0
SyS_recvmsg+0x5c/0xb0
system_call_fastpath+0x16/0x1b
Fixes: b58d977432c8 ("dump_stack: serialize the output from dump_stack()")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Alex Thorlton <athorlton@sgi.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
lib/dump_stack.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
--- a/lib/dump_stack.c
+++ b/lib/dump_stack.c
@@ -25,6 +25,7 @@ static atomic_t dump_lock = ATOMIC_INIT(
asmlinkage __visible void dump_stack(void)
{
+ unsigned long flags;
int was_locked;
int old;
int cpu;
@@ -33,9 +34,8 @@ asmlinkage __visible void dump_stack(voi
* Permit this cpu to perform nested stack dumps while serialising
* against other CPUs
*/
- preempt_disable();
-
retry:
+ local_irq_save(flags);
cpu = smp_processor_id();
old = atomic_cmpxchg(&dump_lock, -1, cpu);
if (old == -1) {
@@ -43,6 +43,7 @@ retry:
} else if (old == cpu) {
was_locked = 1;
} else {
+ local_irq_restore(flags);
cpu_relax();
goto retry;
}
@@ -52,7 +53,7 @@ retry:
if (!was_locked)
atomic_set(&dump_lock, -1);
- preempt_enable();
+ local_irq_restore(flags);
}
#else
asmlinkage __visible void dump_stack(void)
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 129/137] xfs: inode recovery readahead can race with inode buffer creation |
| Message-ID | <r5z5E-7tx-25@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dave Chinner <dchinner@redhat.com>
commit b79f4a1c68bb99152d0785ee4ea3ab4396cdacc6 upstream.
When we do inode readahead in log recovery, we do can do the
readahead before we've replayed the icreate transaction that stamps
the buffer with inode cores. The inode readahead verifier catches
this and marks the buffer as !done to indicate that it doesn't yet
contain valid inodes.
In adding buffer error notification (i.e. setting b_error = -EIO at
the same time as as we clear the done flag) to such a readahead
verifier failure, we can then get subsequent inode recovery failing
with this error:
XFS (dm-0): metadata I/O error: block 0xa00060 ("xlog_recover_do..(read#2)") error 5 numblks 32
This occurs when readahead completion races with icreate item replay
such as:
inode readahead
find buffer
lock buffer
submit RA io
....
icreate recovery
xfs_trans_get_buffer
find buffer
lock buffer
<blocks on RA completion>
.....
<ra completion>
fails verifier
clear XBF_DONE
set bp->b_error = -EIO
release and unlock buffer
<icreate gains lock>
icreate initialises buffer
marks buffer as done
adds buffer to delayed write queue
releases buffer
At this point, we have an initialised inode buffer that is up to
date but has an -EIO state registered against it. When we finally
get to recovering an inode in that buffer:
inode item recovery
xfs_trans_read_buffer
find buffer
lock buffer
sees XBF_DONE is set, returns buffer
sees bp->b_error is set
fail log recovery!
Essentially, we need xfs_trans_get_buf_map() to clear the error status of
the buffer when doing a lookup. This function returns uninitialised
buffers, so the buffer returned can not be in an error state and
none of the code that uses this function expects b_error to be set
on return. Indeed, there is an ASSERT(!bp->b_error); in the
transaction case in xfs_trans_get_buf_map() that would have caught
this if log recovery used transactions....
This patch firstly changes the inode readahead failure to set -EIO
on the buffer, and secondly changes xfs_buf_get_map() to never
return a buffer with an error state set so this first change doesn't
cause unexpected log recovery failures.
Signed-off-by: Dave Chinner <dchinner@redhat.com>
Reviewed-by: Brian Foster <bfoster@redhat.com>
Signed-off-by: Dave Chinner <david@fromorbit.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/libxfs/xfs_inode_buf.c | 12 +++++++-----
fs/xfs/xfs_buf.c | 7 +++++++
2 files changed, 14 insertions(+), 5 deletions(-)
--- a/fs/xfs/libxfs/xfs_inode_buf.c
+++ b/fs/xfs/libxfs/xfs_inode_buf.c
@@ -62,11 +62,12 @@ xfs_inobp_check(
* has not had the inode cores stamped into it. Hence for readahead, the buffer
* may be potentially invalid.
*
- * If the readahead buffer is invalid, we don't want to mark it with an error,
- * but we do want to clear the DONE status of the buffer so that a followup read
- * will re-read it from disk. This will ensure that we don't get an unnecessary
- * warnings during log recovery and we don't get unnecssary panics on debug
- * kernels.
+ * If the readahead buffer is invalid, we need to mark it with an error and
+ * clear the DONE status of the buffer so that a followup read will re-read it
+ * from disk. We don't report the error otherwise to avoid warnings during log
+ * recovery and we don't get unnecssary panics on debug kernels. We use EIO here
+ * because all we want to do is say readahead failed; there is no-one to report
+ * the error to, so this will distinguish it from a non-ra verifier failure.
*/
static void
xfs_inode_buf_verify(
@@ -93,6 +94,7 @@ xfs_inode_buf_verify(
XFS_RANDOM_ITOBP_INOTOBP))) {
if (readahead) {
bp->b_flags &= ~XBF_DONE;
+ xfs_buf_ioerror(bp, -EIO);
return;
}
--- a/fs/xfs/xfs_buf.c
+++ b/fs/xfs/xfs_buf.c
@@ -604,6 +604,13 @@ found:
}
}
+ /*
+ * Clear b_error if this is a lookup from a caller that doesn't expect
+ * valid data to be found in the buffer.
+ */
+ if (!(flags & XBF_READ))
+ xfs_buf_ioerror(bp, 0);
+
XFS_STATS_INC(target->bt_mount, xb_get);
trace_xfs_buf_get(bp, flags, _RET_IP_);
return bp;
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 127/137] ovl: setattr: check permissions before copy-up |
| Message-ID | <r5z5F-7tx-27@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Miklos Szeredi <miklos@szeredi.hu>
commit cf9a6784f7c1b5ee2b9159a1246e327c331c5697 upstream.
Without this copy-up of a file can be forced, even without actually being
allowed to do anything on the file.
[Arnd Bergmann] include <linux/pagemap.h> for PAGE_CACHE_SIZE (used by
MAX_LFS_FILESIZE definition).
Signed-off-by: Miklos Szeredi <miklos@szeredi.hu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/overlayfs/inode.c | 13 +++++++++++++
fs/overlayfs/super.c | 2 ++
2 files changed, 15 insertions(+)
--- a/fs/overlayfs/inode.c
+++ b/fs/overlayfs/inode.c
@@ -42,6 +42,19 @@ int ovl_setattr(struct dentry *dentry, s
int err;
struct dentry *upperdentry;
+ /*
+ * Check for permissions before trying to copy-up. This is redundant
+ * since it will be rechecked later by ->setattr() on upper dentry. But
+ * without this, copy-up can be triggered by just about anybody.
+ *
+ * We don't initialize inode->size, which just means that
+ * inode_newsize_ok() will always check against MAX_LFS_FILESIZE and not
+ * check for a swapfile (which this won't be anyway).
+ */
+ err = inode_change_ok(dentry->d_inode, attr);
+ if (err)
+ return err;
+
err = ovl_want_write(dentry);
if (err)
goto out;
--- a/fs/overlayfs/super.c
+++ b/fs/overlayfs/super.c
@@ -9,6 +9,7 @@
#include <linux/fs.h>
#include <linux/namei.h>
+#include <linux/pagemap.h>
#include <linux/xattr.h>
#include <linux/security.h>
#include <linux/mount.h>
@@ -910,6 +911,7 @@ static int ovl_fill_super(struct super_b
}
sb->s_stack_depth = 0;
+ sb->s_maxbytes = MAX_LFS_FILESIZE;
if (ufs->config.upperdir) {
if (!ufs->config.workdir) {
pr_err("overlayfs: missing 'workdir'\n");
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-02-24 05:20 +0100 |
| Subject | [PATCH 4.4 003/137] x86/uaccess/64: Make the __copy_user_nocache() assembly code more readable |
| Message-ID | <r5z5F-7tx-41@gated-at.bofh.it> |
| In reply to | #1341320 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Toshi Kani <toshi.kani@hpe.com>
commit ee9737c924706aaa72c2ead93e3ad5644681dc1c upstream.
Add comments to __copy_user_nocache() to clarify its procedures
and alignment requirements.
Also change numeric branch target labels to named local labels.
No code changed:
arch/x86/lib/copy_user_64.o:
text data bss dec hex filename
1239 0 0 1239 4d7 copy_user_64.o.before
1239 0 0 1239 4d7 copy_user_64.o.after
md5:
58bed94c2db98c1ca9a2d46d0680aaae copy_user_64.o.before.asm
58bed94c2db98c1ca9a2d46d0680aaae copy_user_64.o.after.asm
Signed-off-by: Toshi Kani <toshi.kani@hpe.com>
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Borislav Petkov <bp@suse.de>
Cc: Brian Gerst <brgerst@gmail.com>
Cc: Denys Vlasenko <dvlasenk@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Luis R. Rodriguez <mcgrof@suse.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Toshi Kani <toshi.kani@hp.com>
Cc: brian.boylston@hpe.com
Cc: dan.j.williams@intel.com
Cc: linux-nvdimm@lists.01.org
Cc: micah.parrish@hpe.com
Cc: ross.zwisler@linux.intel.com
Cc: vishal.l.verma@intel.com
Link: http://lkml.kernel.org/r/1455225857-12039-2-git-send-email-toshi.kani@hpe.com
[ Small readability edits and added object file comparison. ]
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/lib/copy_user_64.S | 114 ++++++++++++++++++++++++++++----------------
1 file changed, 73 insertions(+), 41 deletions(-)
--- a/arch/x86/lib/copy_user_64.S
+++ b/arch/x86/lib/copy_user_64.S
@@ -232,17 +232,30 @@ ENDPROC(copy_user_enhanced_fast_string)
/*
* copy_user_nocache - Uncached memory copy with exception handling
- * This will force destination/source out of cache for more performance.
+ * This will force destination out of cache for more performance.
+ *
+ * Note: Cached memory copy is used when destination or size is not
+ * naturally aligned. That is:
+ * - Require 8-byte alignment when size is 8 bytes or larger.
*/
ENTRY(__copy_user_nocache)
ASM_STAC
+
+ /* If size is less than 8 bytes, go to byte copy */
cmpl $8,%edx
- jb 20f /* less then 8 bytes, go to byte copy loop */
+ jb .L_1b_cache_copy_entry
+
+ /* If destination is not 8-byte aligned, "cache" copy to align it */
ALIGN_DESTINATION
+
+ /* Set 4x8-byte copy count and remainder */
movl %edx,%ecx
andl $63,%edx
shrl $6,%ecx
- jz 17f
+ jz .L_8b_nocache_copy_entry /* jump if count is 0 */
+
+ /* Perform 4x8-byte nocache loop-copy */
+.L_4x8b_nocache_copy_loop:
1: movq (%rsi),%r8
2: movq 1*8(%rsi),%r9
3: movq 2*8(%rsi),%r10
@@ -262,60 +275,79 @@ ENTRY(__copy_user_nocache)
leaq 64(%rsi),%rsi
leaq 64(%rdi),%rdi
decl %ecx
- jnz 1b
-17: movl %edx,%ecx
+ jnz .L_4x8b_nocache_copy_loop
+
+ /* Set 8-byte copy count and remainder */
+.L_8b_nocache_copy_entry:
+ movl %edx,%ecx
andl $7,%edx
shrl $3,%ecx
- jz 20f
-18: movq (%rsi),%r8
-19: movnti %r8,(%rdi)
+ jz .L_1b_cache_copy_entry /* jump if count is 0 */
+
+ /* Perform 8-byte nocache loop-copy */
+.L_8b_nocache_copy_loop:
+20: movq (%rsi),%r8
+21: movnti %r8,(%rdi)
leaq 8(%rsi),%rsi
leaq 8(%rdi),%rdi
decl %ecx
- jnz 18b
-20: andl %edx,%edx
- jz 23f
+ jnz .L_8b_nocache_copy_loop
+
+ /* If no byte left, we're done */
+.L_1b_cache_copy_entry:
+ andl %edx,%edx
+ jz .L_finish_copy
+
+ /* Perform byte "cache" loop-copy for the remainder */
movl %edx,%ecx
-21: movb (%rsi),%al
-22: movb %al,(%rdi)
+.L_1b_cache_copy_loop:
+40: movb (%rsi),%al
+41: movb %al,(%rdi)
incq %rsi
incq %rdi
decl %ecx
- jnz 21b
-23: xorl %eax,%eax
+ jnz .L_1b_cache_copy_loop
+
+ /* Finished copying; fence the prior stores */
+.L_finish_copy:
+ xorl %eax,%eax
ASM_CLAC
sfence
ret
.section .fixup,"ax"
-30: shll $6,%ecx
+.L_fixup_4x8b_copy:
+ shll $6,%ecx
addl %ecx,%edx
- jmp 60f
-40: lea (%rdx,%rcx,8),%rdx
- jmp 60f
-50: movl %ecx,%edx
-60: sfence
+ jmp .L_fixup_handle_tail
+.L_fixup_8b_copy:
+ lea (%rdx,%rcx,8),%rdx
+ jmp .L_fixup_handle_tail
+.L_fixup_1b_copy:
+ movl %ecx,%edx
+.L_fixup_handle_tail:
+ sfence
jmp copy_user_handle_tail
.previous
- _ASM_EXTABLE(1b,30b)
- _ASM_EXTABLE(2b,30b)
- _ASM_EXTABLE(3b,30b)
- _ASM_EXTABLE(4b,30b)
- _ASM_EXTABLE(5b,30b)
- _ASM_EXTABLE(6b,30b)
- _ASM_EXTABLE(7b,30b)
- _ASM_EXTABLE(8b,30b)
- _ASM_EXTABLE(9b,30b)
- _ASM_EXTABLE(10b,30b)
- _ASM_EXTABLE(11b,30b)
- _ASM_EXTABLE(12b,30b)
- _ASM_EXTABLE(13b,30b)
- _ASM_EXTABLE(14b,30b)
- _ASM_EXTABLE(15b,30b)
- _ASM_EXTABLE(16b,30b)
- _ASM_EXTABLE(18b,40b)
- _ASM_EXTABLE(19b,40b)
- _ASM_EXTABLE(21b,50b)
- _ASM_EXTABLE(22b,50b)
+ _ASM_EXTABLE(1b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(2b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(3b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(4b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(5b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(6b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(7b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(8b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(9b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(10b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(11b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(12b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(13b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(14b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(15b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(16b,.L_fixup_4x8b_copy)
+ _ASM_EXTABLE(20b,.L_fixup_8b_copy)
+ _ASM_EXTABLE(21b,.L_fixup_8b_copy)
+ _ASM_EXTABLE(40b,.L_fixup_1b_copy)
+ _ASM_EXTABLE(41b,.L_fixup_1b_copy)
ENDPROC(__copy_user_nocache)
[toc] | [prev] | [next] | [standalone]
Page 1 of 7 [1] 2 3 4 5 6 7 Next page →
Back to top | Article view | linux.kernel
csiph-web