Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1344036 > unrolled thread

[3.16.y-ckt stable] Linux 3.16.7-ckt25 stable review

Started byLuis Henriques <luis.henriques@canonical.com>
First post2016-02-26 11:30 +0100
Last post2016-02-29 12:40 +0100
Articles 20 on this page of 109 — 1 participant

Back to article view | Back to linux.kernel


Contents

  [3.16.y-ckt stable] Linux 3.16.7-ckt25 stable review Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:30 +0100
    [PATCH 3.16.y-ckt 117/129] ARM: 8519/1: ICST: try other dividends than 1 Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:30 +0100
    [PATCH 3.16.y-ckt 107/129] klist: fix starting point removed bug in klist iterators Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:40 +0100
    [PATCH 3.16.y-ckt 126/129] sctp: translate network order to host order when users get a hmacid Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:40 +0100
    [PATCH 3.16.y-ckt 109/129] ALSA: timer: Fix wrong instance passed to slave callbacks Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:40 +0100
    [PATCH 3.16.y-ckt 123/129] netlink: not trim skb for mmaped socket when dump Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:40 +0100
    [PATCH 3.16.y-ckt 108/129] ALSA: dummy: Implement timer backend switching more safely Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:40 +0100
    [PATCH 3.16.y-ckt 106/129] ALSA: hda - Fix speaker output from VAIO AiO machines Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:40 +0100
    [PATCH 3.16.y-ckt 100/129] mm: replace vma_lock_anon_vma with anon_vma_lock_read/write Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:40 +0100
    [PATCH 3.16.y-ckt 099/129] ocfs2/dlm: clear refmap bit of recovery lock while doing local recovery cleanup Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:40 +0100
    [PATCH 3.16.y-ckt 122/129] sctp: allow setting SCTP_SACK_IMMEDIATELY by the application Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:40 +0100
    [PATCH 3.16.y-ckt 115/129] workqueue: handle NUMA_NO_NODE for unbound pool_workqueue lookup Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:40 +0100
    [PATCH 3.16.y-ckt 111/129] ALSA: timer: Fix race between stop and interrupt Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:40 +0100
    [PATCH 3.16.y-ckt 125/129] ipv6: fix a lockdep splat Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:40 +0100
    [PATCH 3.16.y-ckt 110/129] ARM: 8517/1: ICST: avoid arithmetic overflow in icst_hz() Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:40 +0100
    [PATCH 3.16.y-ckt 120/129] af_unix: fix struct pid memory leak Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:40 +0100
    [PATCH 3.16.y-ckt 096/129] Revert "ALSA: hda - Fix noise on Gigabyte Z170X mobo" Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 093/129] SCSI: Add Marvell Console to VPD blacklist Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 084/129] radix-tree: fix race in gang lookup Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 077/129] ASoC: dpcm: fix the BE state on hw_free Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 094/129] drm: Add drm_fixp_from_fraction and drm_fixp2int_ceil Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 087/129] xhci: Fix list corruption in urb dequeue at host removal Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 098/129] mm, vmstat: fix wrong WQ sleep when memory reclaim doesn't make any progress Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 088/129] [media] tda1004x: only update the frontend properties if locked Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 083/129] drivers/scsi/sg.c: mark VMA as VM_IO to prevent migration Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 090/129] [media] saa7134-alsa: Only frees registered sound cards Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 095/129] ALSA: hda - Fix static checker warning in patch_hdmi.c Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 078/129] module: wrapper for symbol name. Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 085/129] Revert "xhci: don't finish a TD if we get a short-transfer event mid TD" Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 104/129] pty: fix possible use after free of tty->driver_data Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 097/129] dump_stack: avoid potential deadlocks Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 103/129] serial: omap: Prevent DoS using unprivileged ioctl(TIOCSRS485) Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 086/129] usb: xhci: apply XHCI_PME_STUCK_QUIRK to Intel Broxton-M platforms Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 076/129] cputime: Prevent 32bit overflow in time[val|spec]_to_cputime() Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 092/129] scsi_dh_rdac: always retry MODE SELECT on command lock violation Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 102/129] crypto: user - lock crypto_alg_list on alg dump Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 072/129] ALSA: timer: Code cleanup Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 082/129] ALSA: seq: Fix lockdep warnings due to double mutex locks Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 079/129] ALSA: hda - Add fixup for Mac Mini 7,1 model Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 101/129] radix-tree: fix oops after radix_tree_iter_retry Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 074/129] libata: fix sff host state machine locking while polling Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 069/129] ALSA: rawmidi: Remove kernel WARNING for NULL user-space buffer check Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 073/129] ALSA: timer: Fix link corruption due to double start or stop Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 091/129] Btrfs: fix hang on extent buffer lock caused by the inode_paths ioctl Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 080/129] ALSA: rawmidi: Make snd_rawmidi_transmit() race-free Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 11:50 +0100
    [PATCH 3.16.y-ckt 045/129] crypto: algif_skcipher - Add nokey compatibility path Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 046/129] crypto: algif_hash - Require setkey before accept(2) Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 067/129] intel_scu_ipcutil: underflow in scu_reg_access() Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 056/129] cgroup: make sure a parent css isn't offlined before its children Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 063/129] target: Fix WRITE_SAME/DISCARD conversion to linux 512b sectors Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 060/129] rfkill: fix rfkill_fop_read wait_event usage Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 044/129] crypto: algif_skcipher - Require setkey before accept(2) Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 053/129] iio: add HAS_IOMEM dependency to VF610_ADC Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 043/129] umount: Do not allow unmounting rootfs. Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 055/129] ASoC: rt5645: fix the shift bit of IN1 boost Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 048/129] crypto: algif_skcipher - Add key check exception for cipher_null Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 054/129] iio: dac: mcp4725: set iio name property in sysfs Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 051/129] crypto: algif_hash - Fix race condition in hash_check_key Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 050/129] crypto: algif_skcipher - Remove custom release parent function Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 061/129] crypto: shash - Fix has_key setting Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 062/129] drm/i915/dp: fall back to 18 bpp when sink capability is unknown Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 065/129] iio: inkern: fix a NULL dereference on error Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 059/129] mac80211: Requeue work after scan complete for all VIF types. Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 066/129] iio: pressure: mpl115: fix temperature offset sign Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 058/129] libata: disable forced PORTS_IMPL for >= AHCI 1.3 Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 064/129] crypto: algif_hash - wait for crypto_ahash_init() to complete Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 052/129] crypto: algif_skcipher - Fix race condition in skcipher_check_key Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 042/129] Revert "workqueue: make sure delayed work run in local cpu" Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 068/129] ALSA: seq: Fix race at closing in virmidi driver Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:00 +0100
    [PATCH 3.16.y-ckt 024/129] USB: serial: ftdi_sio: add support for Yaesu SCU-18 cable Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 039/129] perf hists: Fix HISTC_MEM_DCACHELINE width setting Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 020/129] USB: visor: fix null-deref at probe Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 033/129] n_tty: Fix unsafe reference to "other" ldisc Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 027/129] ALSA: usb-audio: Fix TEAC UD-501/UD-503/NT-503 usb delay Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 012/129] KVM: PPC: Fix emulation of H_SET_DABR/X on POWER8 Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 049/129] crypto: algif_hash - Remove custom release parent function Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 036/129] drm/vmwgfx: respect 'nomodeset' Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 019/129] USB: cp210x: add ID for IAI USB to RS485 adaptor Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 014/129] ACPI / PCI / hotplug: unlock in error path in acpiphp_enable_slot() Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 031/129] powerpc/eeh: Fix PE location code Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 047/129] crypto: skcipher - Add crypto_skcipher_has_setkey Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 032/129] SCSI: fix crashes in sd and sr runtime PM Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 018/129] usb: hub: do not clear BOS field during reset device Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 022/129] ALSA: seq: Fix incorrect sanity check at snd_seq_oss_synth_cleanup() Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 009/129] EVM: Use crypto_memneq() for digest comparisons Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 023/129] ALSA: seq: Degrade the error message for too many opens Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 040/129] powerpc/perf: Remove PPMU_HAS_SSLOT flag for Power8 Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 008/129] iw_cxgb3: Fix incorrectly returning error on success Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 028/129] virtio_pci: fix use after free on release Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 030/129] arm64: errata: Add -mpc-relative-literal-loads to build flags Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 010/129] ALSA: usb-audio: avoid freeing umidi object twice Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 029/129] ALSA: bebob: Use a signed return type for get_formation_index Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 015/129] usb: cdc-acm: handle unlinked urb in acm read callback Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 017/129] cdc-acm:exclude Samsung phone 04e8:685d Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 035/129] ALSA: dummy: Disable switching timer backend via sysfs Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 025/129] USB: option: fix Cinterion AHxx enumeration Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 021/129] USB: serial: option: Adding support for Telit LE922 Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 016/129] usb: cdc-acm: send zero packet for intel 7260 modem Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 034/129] staging/speakup: Use tty_ldisc_ref() for paste kworker Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 038/129] perf annotate browser: Fix behaviour of Shift-Tab with nothing focussed Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:10 +0100
    [PATCH 3.16.y-ckt 005/129] USB: serial: visor: fix crash on detecting device without write_urbs Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:20 +0100
    [PATCH 3.16.y-ckt 007/129] qeth: initialize net_device with carrier off Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:20 +0100
    [PATCH 3.16.y-ckt 011/129] iio: adis_buffer: Fix out-of-bounds memory access Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:20 +0100
    [PATCH 3.16.y-ckt 002/129] [media] usbvision: fix leak of usb_dev on failure paths in usbvision_probe() Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:20 +0100
    [PATCH 3.16.y-ckt 003/129] [media] usbvision: fix crash on detecting device with invalid configuration Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:20 +0100
    [PATCH 3.16.y-ckt 004/129] tty: Fix unsafe ldisc reference via ioctl(TIOCGETD) Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:20 +0100
    [PATCH 3.16.y-ckt 006/129] ASN.1: Fix non-match detection failure on data overrun Luis Henriques <luis.henriques@canonical.com> - 2016-02-26 12:20 +0100
    [PATCH 3.16.y-ckt 131/131] net: phy: Avoid polling PHY with PHY_IGNORE_INTERRUPTS Luis Henriques <luis.henriques@canonical.com> - 2016-02-29 12:40 +0100
    [PATCH 3.16.y-ckt 130/131] net: phy: fix PHY_RUNNING in phy_state_machine Luis Henriques <luis.henriques@canonical.com> - 2016-02-29 12:40 +0100

Page 1 of 6  [1] 2 3 4 5 6  Next page →


#1344036 — [3.16.y-ckt stable] Linux 3.16.7-ckt25 stable review

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:30 +0100
Subject[3.16.y-ckt stable] Linux 3.16.7-ckt25 stable review
Message-ID<r6nOO-1Jb-5@gated-at.bofh.it>
This is the start of the review cycle for the Linux 3.16.7-ckt25 stable
kernel.

This version contains 129 new patches, summarized below.  The new patches
are posted as replies to this message and also available in this git branch:

http://kernel.ubuntu.com/git/ubuntu/linux.git/log/?h=linux-3.16.y-review

git://kernel.ubuntu.com/ubuntu/linux.git  linux-3.16.y-review

The review period for version 3.16.7-ckt25 will be open for the next three
days.  To report a problem, please reply to the relevant follow-up patch
message.

For more information about the Linux 3.16.y-ckt extended stable kernel
series, see https://wiki.ubuntu.com/Kernel/Dev/ExtendedStable .

 -Luis

--
 Documentation/sysctl/fs.txt                   |  23 +++
 arch/arm/common/icst.c                        |   9 +-
 arch/arm64/Makefile                           |   1 +
 arch/mips/include/asm/syscall.h               |   4 +-
 arch/powerpc/kernel/eeh_pe.c                  |  33 ++--
 arch/powerpc/kvm/book3s_hv_rmhandlers.S       |   2 +-
 arch/powerpc/perf/power8-pmu.c                |   2 +-
 arch/x86/kernel/apic/io_apic.c                |   6 +-
 arch/x86/mm/pageattr.c                        |   4 +-
 crypto/ablkcipher.c                           |   1 +
 crypto/algif_hash.c                           | 169 ++++++++++++++++++-
 crypto/algif_skcipher.c                       | 155 ++++++++++++++++-
 crypto/crypto_user.c                          |   6 +-
 crypto/shash.c                                |   7 +-
 drivers/ata/ahci.c                            |  20 +++
 drivers/ata/libahci.c                         |   4 +-
 drivers/ata/libata-sff.c                      |  32 ++--
 drivers/gpu/drm/i915/intel_display.c          |  20 ++-
 drivers/gpu/drm/radeon/radeon_sa.c            |   5 +
 drivers/gpu/drm/vmwgfx/vmwgfx_drv.c           |   7 +
 drivers/gpu/drm/vmwgfx/vmwgfx_fb.c            |   4 +-
 drivers/iio/adc/Kconfig                       |   1 +
 drivers/iio/dac/mcp4725.c                     |   1 +
 drivers/iio/imu/adis_buffer.c                 |   2 +-
 drivers/iio/inkern.c                          |   2 +
 drivers/iio/pressure/mpl115.c                 |   2 +-
 drivers/infiniband/hw/cxgb3/iwch_cm.c         |   4 +-
 drivers/infiniband/hw/mlx5/qp.c               |  12 +-
 drivers/media/dvb-frontends/tda1004x.c        |   9 +
 drivers/media/pci/saa7134/saa7134-alsa.c      |   5 +-
 drivers/media/usb/usbvision/usbvision-video.c |  47 +++++-
 drivers/net/phy/phy.c                         |  31 ++--
 drivers/net/ppp/pptp.c                        |  34 ++--
 drivers/pci/hotplug/acpiphp_glue.c            |   4 +-
 drivers/pci/pcie/aer/aerdrv.c                 |   4 +-
 drivers/pci/pcie/aer/aerdrv.h                 |   1 -
 drivers/pci/pcie/aer/aerdrv_core.c            |   2 -
 drivers/phy/phy-twl4030-usb.c                 |   1 +
 drivers/platform/x86/intel_scu_ipcutil.c      |   2 +-
 drivers/s390/net/qeth_l2_main.c               |   1 +
 drivers/s390/net/qeth_l3_main.c               |   1 +
 drivers/scsi/device_handler/scsi_dh_rdac.c    |   4 +-
 drivers/scsi/scsi_devinfo.c                   |   1 +
 drivers/scsi/sd.c                             |   7 +-
 drivers/scsi/sg.c                             |   2 +-
 drivers/scsi/sr.c                             |   4 +
 drivers/staging/speakup/selection.c           |   5 +-
 drivers/target/target_core_device.c           |  43 +++++
 drivers/target/target_core_file.c             |  29 +---
 drivers/target/target_core_iblock.c           |  56 ++-----
 drivers/tty/n_tty.c                           |   7 +-
 drivers/tty/pty.c                             |  21 ++-
 drivers/tty/serial/omap-serial.c              |   8 +-
 drivers/tty/tty_io.c                          |  24 ++-
 drivers/usb/class/cdc-acm.c                   |  14 +-
 drivers/usb/class/cdc-acm.h                   |   1 +
 drivers/usb/core/hub.c                        |   8 +-
 drivers/usb/host/xhci-pci.c                   |   4 +-
 drivers/usb/host/xhci-ring.c                  |  10 --
 drivers/usb/host/xhci.c                       |   4 +-
 drivers/usb/serial/cp210x.c                   |   1 +
 drivers/usb/serial/ftdi_sio.c                 |   1 +
 drivers/usb/serial/ftdi_sio_ids.h             |   1 +
 drivers/usb/serial/option.c                   |  18 +-
 drivers/usb/serial/visor.c                    |  11 +-
 drivers/virtio/virtio_pci.c                   |   2 +
 fs/btrfs/backref.c                            |  10 +-
 fs/btrfs/delayed-inode.c                      |   3 +-
 fs/btrfs/delayed-inode.h                      |   2 +-
 fs/btrfs/inode.c                              |  14 +-
 fs/devpts/inode.c                             |  20 +++
 fs/namespace.c                                |   1 +
 fs/ocfs2/dlm/dlmrecovery.c                    |   2 +
 fs/pipe.c                                     |  47 +++++-
 include/asm-generic/cputime_nsecs.h           |   5 +-
 include/drm/drm_fixed.h                       |  53 +++++-
 include/linux/cgroup.h                        |   6 +
 include/linux/crypto.h                        |   8 +
 include/linux/devpts_fs.h                     |   4 +
 include/linux/pipe_fs_i.h                     |   4 +
 include/linux/radix-tree.h                    |  22 ++-
 include/linux/rmap.h                          |  14 --
 include/linux/sched.h                         |   1 +
 include/net/af_unix.h                         |   4 +-
 include/net/scm.h                             |   1 +
 include/sound/rawmidi.h                       |   4 +
 include/target/target_core_backend.h          |   3 +
 kernel/cgroup.c                               |  22 ++-
 kernel/module.c                               |  26 +--
 kernel/sysctl.c                               |  14 ++
 kernel/workqueue.c                            |  18 +-
 lib/asn1_decoder.c                            |   5 +-
 lib/dump_stack.c                              |   7 +-
 lib/klist.c                                   |   6 +-
 lib/radix-tree.c                              |  12 +-
 mm/backing-dev.c                              |   2 +-
 mm/mmap.c                                     |  56 +++----
 mm/vmstat.c                                   |   3 +-
 net/core/scm.c                                |   7 +
 net/ipv6/ip6_flowlabel.c                      |   5 +-
 net/mac80211/ibss.c                           |   1 -
 net/mac80211/mesh.c                           |  11 --
 net/mac80211/mesh.h                           |   4 -
 net/mac80211/mlme.c                           |   2 -
 net/mac80211/scan.c                           |  12 +-
 net/netlink/af_netlink.c                      |   3 +-
 net/rfkill/core.c                             |  16 +-
 net/sctp/socket.c                             |  10 +-
 net/unix/af_unix.c                            |   5 +-
 net/unix/garbage.c                            |   8 +-
 security/integrity/evm/evm_main.c             |   3 +-
 sound/core/compress_offload.c                 |  11 ++
 sound/core/oss/pcm_oss.c                      |  21 ++-
 sound/core/rawmidi.c                          | 134 ++++++++++-----
 sound/core/seq/oss/seq_oss_init.c             |   2 +-
 sound/core/seq/oss/seq_oss_synth.c            |   2 +-
 sound/core/seq/seq_clientmgr.c                |   3 +
 sound/core/seq/seq_ports.c                    | 233 ++++++++++++++------------
 sound/core/seq/seq_timer.c                    |  87 +++++++---
 sound/core/seq/seq_virmidi.c                  |  23 ++-
 sound/core/timer.c                            |  98 ++++++-----
 sound/drivers/dummy.c                         |  35 ++--
 sound/firewire/bebob/bebob_stream.c           |  14 +-
 sound/pci/hda/patch_cirrus.c                  |  27 +++
 sound/pci/hda/patch_hdmi.c                    |   3 +-
 sound/pci/hda/patch_realtek.c                 |   9 +-
 sound/soc/codecs/rt5645.c                     |   2 +-
 sound/soc/soc-pcm.c                           |   3 +-
 sound/usb/midi.c                              |   1 -
 sound/usb/quirks.c                            |  14 +-
 tools/perf/ui/browsers/annotate.c             |   4 +-
 tools/perf/util/hist.c                        |   2 +
 132 files changed, 1567 insertions(+), 613 deletions(-)

Akinobu Mita (1):
      iio: pressure: mpl115: fix temperature offset sign

Alan Stern (1):
      SCSI: fix crashes in sd and sr runtime PM

Alexandra Yates (1):
      ahci: Intel DNV device IDs SATA

Alexey Khoroshilov (1):
      [media] usbvision: fix leak of usb_dev on failure paths in usbvision_probe()

Andrey Konovalov (1):
      ALSA: usb-audio: avoid freeing umidi object twice

Bard Liao (1):
      ASoC: rt5645: fix the shift bit of IN1 boost

Dan Carpenter (2):
      iio: inkern: fix a NULL dereference on error
      intel_scu_ipcutil: underflow in scu_reg_access()

Daniele Palmas (1):
      USB: serial: option: Adding support for Telit LE922

David Henningsson (1):
      ALSA: hda - Fix static checker warning in patch_hdmi.c

David Howells (1):
      ASN.1: Fix non-match detection failure on data overrun

David Sterba (1):
      btrfs: properly set the termination value of ctx->pos in readdir

Du, Changbin (1):
      usb: hub: do not clear BOS field during reset device

Eric Dumazet (3):
      dump_stack: avoid potential deadlocks
      af_unix: fix struct pid memory leak
      ipv6: fix a lockdep splat

Eric W. Biederman (1):
      umount: Do not allow unmounting rootfs.

Filipe Manana (1):
      Btrfs: fix hang on extent buffer lock caused by the inode_paths ioctl

Florian Fainelli (1):
      net: phy: Fix phy_mac_interrupt()

Gavin Shan (1):
      powerpc/eeh: Fix PE location code

Greg Kroah-Hartman (1):
      USB: serial: ftdi_sio: add support for Yaesu SCU-18 cable

Guillaume Fougnies (1):
      ALSA: usb-audio: Fix TEAC UD-501/UD-503/NT-503 usb delay

Hannes Frederic Sowa (2):
      pptp: fix illegal memory access caused by multiple bind()s
      unix: correctly track in-flight fds in sending process user_struct

Hannes Reinecke (1):
      scsi_dh_rdac: always retry MODE SELECT on command lock violation

Hariprasad S (1):
      iw_cxgb3: Fix incorrectly returning error on success

Harry Wentland (1):
      drm: Add drm_fixp_from_fraction and drm_fixp2int_ceil

Herbert Xu (10):
      crypto: algif_skcipher - Require setkey before accept(2)
      crypto: algif_skcipher - Add nokey compatibility path
      crypto: algif_hash - Require setkey before accept(2)
      crypto: skcipher - Add crypto_skcipher_has_setkey
      crypto: algif_skcipher - Add key check exception for cipher_null
      crypto: algif_hash - Remove custom release parent function
      crypto: algif_skcipher - Remove custom release parent function
      crypto: algif_hash - Fix race condition in hash_check_key
      crypto: algif_skcipher - Fix race condition in skcipher_check_key
      crypto: shash - Fix has_key setting

Herton R. Krzesinski (2):
      pty: fix possible use after free of tty->driver_data
      pty: make sure super_block is still valid in final /dev/tty close

Insu Yun (1):
      ACPI / PCI / hotplug: unlock in error path in acpiphp_enable_slot()

James Bottomley (1):
      klist: fix starting point removed bug in klist iterators

James Hogan (1):
      MIPS: Fix buffer overflow in syscall_get_arguments()

Jani Nikula (1):
      drm/i915/dp: fall back to 18 bpp when sink capability is unknown

Jiri Olsa (1):
      perf hists: Fix HISTC_MEM_DCACHELINE width setting

Johan Hovold (1):
      USB: visor: fix null-deref at probe

Johannes Berg (1):
      rfkill: fix rfkill_fop_read wait_event usage

John Ernberg (1):
      USB: option: fix Cinterion AHxx enumeration

Ken-ichirou MATSUZAWA (1):
      netlink: not trim skb for mmaped socket when dump

Kirill A. Shutemov (1):
      drivers/scsi/sg.c: mark VMA as VM_IO to prevent migration

Konstantin Khlebnikov (2):
      mm: replace vma_lock_anon_vma with anon_vma_lock_read/write
      radix-tree: fix oops after radix_tree_iter_retry

Lars-Peter Clausen (1):
      iio: adis_buffer: Fix out-of-bounds memory access

Leon Romanovsky (1):
      IB/mlx5: Fix RC transport send queue overhead computation

Linus Torvalds (1):
      vmstat: explicitly schedule per-cpu work on the CPU we need it to run on

Linus Walleij (2):
      ARM: 8517/1: ICST: avoid arithmetic overflow in icst_hz()
      ARM: 8519/1: ICST: try other dividends than 1

Lu Baolu (3):
      usb: cdc-acm: handle unlinked urb in acm read callback
      usb: cdc-acm: send zero packet for intel 7260 modem
      usb: xhci: apply XHCI_PME_STUCK_QUIRK to Intel Broxton-M platforms

Lucas Tanure (1):
      ALSA: bebob: Use a signed return type for get_formation_index

Madhavan Srinivasan (1):
      powerpc/perf: Remove PPMU_HAS_SSLOT flag for Power8

Marcelo Ricardo Leitner (1):
      sctp: allow setting SCTP_SACK_IMMEDIATELY by the application

Markus Trippelsdorf (1):
      perf annotate browser: Fix behaviour of Shift-Tab with nothing focussed

Mathias Krause (1):
      crypto: user - lock crypto_alg_list on alg dump

Mathias Nyman (2):
      Revert "xhci: don't finish a TD if we get a short-transfer event mid TD"
      xhci: Fix list corruption in urb dequeue at host removal

Matt Fleming (1):
      x86/mm/pat: Avoid truncation when converting cpa->numpages to address

Matthew Wilcox (1):
      radix-tree: fix race in gang lookup

Mauro Carvalho Chehab (2):
      [media] tda1004x: only update the frontend properties if locked
      [media] saa7134-alsa: Only frees registered sound cards

Michael S. Tsirkin (1):
      virtio_pci: fix use after free on release

Mika Westerberg (1):
      SCSI: Add Marvell Console to VPD blacklist

Mike Christie (1):
      target: Fix WRITE_SAME/DISCARD conversion to linux 512b sectors

Nicolai Hähnle (1):
      drm/radeon: hold reference to fences in radeon_sa_bo_new

Oliver Neukum (2):
      [media] usbvision fix overflow of interfaces array
      cdc-acm:exclude Samsung phone 04e8:685d

Peter Dedecker (1):
      USB: cp210x: add ID for IAI USB to RS485 adaptor

Peter Hurley (4):
      tty: Fix unsafe ldisc reference via ioctl(TIOCGETD)
      n_tty: Fix unsafe reference to "other" ldisc
      staging/speakup: Use tty_ldisc_ref() for paste kworker
      serial: omap: Prevent DoS using unprivileged ioctl(TIOCSRS485)

Rob Clark (1):
      drm/vmwgfx: respect 'nomodeset'

Rusty Russell (1):
      module: wrapper for symbol name.

Ryan Ware (1):
      EVM: Use crypto_memneq() for digest comparisons

Sachin Kulkarni (1):
      mac80211: Requeue work after scan complete for all VIF types.

Sebastian Andrzej Siewior (1):
      PCI/AER: Flush workqueue on device remove to avoid use-after-free

Takashi Iwai (21):
      ALSA: seq: Fix incorrect sanity check at snd_seq_oss_synth_cleanup()
      ALSA: seq: Degrade the error message for too many opens
      ALSA: compress: Disable GET_CODEC_CAPS ioctl for some architectures
      ALSA: dummy: Disable switching timer backend via sysfs
      ALSA: seq: Fix race at closing in virmidi driver
      ALSA: rawmidi: Remove kernel WARNING for NULL user-space buffer check
      ALSA: pcm: Fix potential deadlock in OSS emulation
      ALSA: seq: Fix yet another races among ALSA timer accesses
      ALSA: timer: Code cleanup
      ALSA: timer: Fix link corruption due to double start or stop
      ALSA: hda - Add fixup for Mac Mini 7,1 model
      ALSA: rawmidi: Make snd_rawmidi_transmit() race-free
      ALSA: rawmidi: Fix race at copying & updating the position
      ALSA: seq: Fix lockdep warnings due to double mutex locks
      ALSA: timer: Fix leftover link at closing
      Revert "ALSA: hda - Fix noise on Gigabyte Z170X mobo"
      ALSA: hda - Fix speaker output from VAIO AiO machines
      ALSA: dummy: Implement timer backend switching more safely
      ALSA: timer: Fix wrong instance passed to slave callbacks
      ALSA: timer: Fix race between stop and interrupt
      ALSA: timer: Fix race at concurrent reads

Tejun Heo (5):
      Revert "workqueue: make sure delayed work run in local cpu"
      cgroup: make sure a parent css isn't offlined before its children
      libata: disable forced PORTS_IMPL for >= AHCI 1.3
      libata: fix sff host state machine locking while polling
      workqueue: handle NUMA_NO_NODE for unbound pool_workqueue lookup

Tetsuo Handa (1):
      mm, vmstat: fix wrong WQ sleep when memory reclaim doesn't make any progress

Thomas Gleixner (1):
      x86/irq: Call chip->irq_set_affinity in proper context

Thomas Hellstrom (1):
      drm/vmwgfx: Fix an fb unlocking bug

Thomas Huth (1):
      KVM: PPC: Fix emulation of H_SET_DABR/X on POWER8

Tony Lindgren (1):
      phy: twl4030-usb: Relase usb phy on unload

Ursula Braun (1):
      qeth: initialize net_device with carrier off

Vegard Nossum (1):
      iio: add HAS_IOMEM dependency to VF610_ADC

Vinod Koul (1):
      ASoC: dpcm: fix the BE state on hw_free

Vladis Dronov (2):
      [media] usbvision: fix crash on detecting device with invalid configuration
      USB: serial: visor: fix crash on detecting device without write_urbs

Wang, Rui Y (1):
      crypto: algif_hash - wait for crypto_ahash_init() to complete

Willy Tarreau (1):
      pipe: limit the per-user amount of pages allocated in pipes

Xin Long (1):
      sctp: translate network order to host order when users get a hmacid

Yong Li (1):
      iio: dac: mcp4725: set iio name property in sysfs

dann frazier (1):
      arm64: errata: Add -mpc-relative-literal-loads to build flags

xuejiufei (1):
      ocfs2/dlm: clear refmap bit of recovery lock while doing local recovery cleanup

zengtao (1):
      cputime: Prevent 32bit overflow in time[val|spec]_to_cputime()

[toc] | [next] | [standalone]


#1344037 — [PATCH 3.16.y-ckt 117/129] ARM: 8519/1: ICST: try other dividends than 1

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:30 +0100
Subject[PATCH 3.16.y-ckt 117/129] ARM: 8519/1: ICST: try other dividends than 1
Message-ID<r6nOQ-1Jb-63@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Linus Walleij <linus.walleij@linaro.org>

commit e972c37459c813190461dabfeaac228e00aae259 upstream.

Since the dawn of time the ICST code has only supported divide
by one or hang in an eternal loop. Luckily we were always dividing
by one because the reference frequency for the systems using
the ICSTs is 24MHz and the [min,max] values for the PLL input
if [10,320] MHz for ICST307 and [6,200] for ICST525, so the loop
will always terminate immediately without assigning any divisor
for the reference frequency.

But for the code to make sense, let's insert the missing i++

Reported-by: David Binderman <dcb314@hotmail.com>
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 arch/arm/common/icst.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/arch/arm/common/icst.c b/arch/arm/common/icst.c
index d3c0e69df259..d7ed252708c5 100644
--- a/arch/arm/common/icst.c
+++ b/arch/arm/common/icst.c
@@ -62,6 +62,7 @@ icst_hz_to_vco(const struct icst_params *p, unsigned long freq)
 
 		if (f > p->vco_min && f <= p->vco_max)
 			break;
+		i++;
 	} while (i < 8);
 
 	if (i >= 8)

[toc] | [prev] | [next] | [standalone]


#1344039 — [PATCH 3.16.y-ckt 107/129] klist: fix starting point removed bug in klist iterators

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:40 +0100
Subject[PATCH 3.16.y-ckt 107/129] klist: fix starting point removed bug in klist iterators
Message-ID<r6nYt-1Np-3@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: James Bottomley <James.Bottomley@HansenPartnership.com>

commit 00cd29b799e3449f0c68b1cc77cd4a5f95b42d17 upstream.

The starting node for a klist iteration is often passed in from
somewhere way above the klist infrastructure, meaning there's no
guarantee the node is still on the list.  We've seen this in SCSI where
we use bus_find_device() to iterate through a list of devices.  In the
face of heavy hotplug activity, the last device returned by
bus_find_device() can be removed before the next call.  This leads to

Dec  3 13:22:02 localhost kernel: WARNING: CPU: 2 PID: 28073 at include/linux/kref.h:47 klist_iter_init_node+0x3d/0x50()
Dec  3 13:22:02 localhost kernel: Modules linked in: scsi_debug x86_pkg_temp_thermal kvm_intel kvm irqbypass crc32c_intel joydev iTCO_wdt dcdbas ipmi_devintf acpi_power_meter iTCO_vendor_support ipmi_si imsghandler pcspkr wmi acpi_cpufreq tpm_tis tpm shpchp lpc_ich mfd_core nfsd nfs_acl lockd grace sunrpc tg3 ptp pps_core
Dec  3 13:22:02 localhost kernel: CPU: 2 PID: 28073 Comm: cat Not tainted 4.4.0-rc1+ #2
Dec  3 13:22:02 localhost kernel: Hardware name: Dell Inc. PowerEdge R320/08VT7V, BIOS 2.0.22 11/19/2013
Dec  3 13:22:02 localhost kernel: ffffffff81a20e77 ffff880613acfd18 ffffffff81321eef 0000000000000000
Dec  3 13:22:02 localhost kernel: ffff880613acfd50 ffffffff8107ca52 ffff88061176b198 0000000000000000
Dec  3 13:22:02 localhost kernel: ffffffff814542b0 ffff880610cfb100 ffff88061176b198 ffff880613acfd60
Dec  3 13:22:02 localhost kernel: Call Trace:
Dec  3 13:22:02 localhost kernel: [<ffffffff81321eef>] dump_stack+0x44/0x55
Dec  3 13:22:02 localhost kernel: [<ffffffff8107ca52>] warn_slowpath_common+0x82/0xc0
Dec  3 13:22:02 localhost kernel: [<ffffffff814542b0>] ? proc_scsi_show+0x20/0x20
Dec  3 13:22:02 localhost kernel: [<ffffffff8107cb4a>] warn_slowpath_null+0x1a/0x20
Dec  3 13:22:02 localhost kernel: [<ffffffff8167225d>] klist_iter_init_node+0x3d/0x50
Dec  3 13:22:02 localhost kernel: [<ffffffff81421d41>] bus_find_device+0x51/0xb0
Dec  3 13:22:02 localhost kernel: [<ffffffff814545ad>] scsi_seq_next+0x2d/0x40
[...]

And an eventual crash. It can actually occur in any hotplug system
which has a device finder and a starting device.

We can fix this globally by making sure the starting node for
klist_iter_init_node() is actually a member of the list before using it
(and by starting from the beginning if it isn't).

Reported-by: Ewan D. Milne <emilne@redhat.com>
Tested-by: Ewan D. Milne <emilne@redhat.com>
Signed-off-by: James Bottomley <James.Bottomley@HansenPartnership.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 lib/klist.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/lib/klist.c b/lib/klist.c
index 358a368a2947..2e59aecbec0d 100644
--- a/lib/klist.c
+++ b/lib/klist.c
@@ -282,9 +282,9 @@ void klist_iter_init_node(struct klist *k, struct klist_iter *i,
 			  struct klist_node *n)
 {
 	i->i_klist = k;
-	i->i_cur = n;
-	if (n)
-		kref_get(&n->n_ref);
+	i->i_cur = NULL;
+	if (n && kref_get_unless_zero(&n->n_ref))
+		i->i_cur = n;
 }
 EXPORT_SYMBOL_GPL(klist_iter_init_node);
 

[toc] | [prev] | [next] | [standalone]


#1344042 — [PATCH 3.16.y-ckt 126/129] sctp: translate network order to host order when users get a hmacid

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:40 +0100
Subject[PATCH 3.16.y-ckt 126/129] sctp: translate network order to host order when users get a hmacid
Message-ID<r6nYt-1Np-5@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Xin Long <lucien.xin@gmail.com>

commit 7a84bd46647ff181eb2659fdc99590e6f16e501d upstream.

Commit ed5a377d87dc ("sctp: translate host order to network order when
setting a hmacid") corrected the hmacid byte-order when setting a hmacid.
but the same issue also exists on getting a hmacid.

We fix it by changing hmacids to host order when users get them with
getsockopt.

Fixes: Commit ed5a377d87dc ("sctp: translate host order to network order when setting a hmacid")
Signed-off-by: Xin Long <lucien.xin@gmail.com>
Acked-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/sctp/socket.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/net/sctp/socket.c b/net/sctp/socket.c
index 70bac7a75b9c..adfb4b58831f 100644
--- a/net/sctp/socket.c
+++ b/net/sctp/socket.c
@@ -5411,6 +5411,7 @@ static int sctp_getsockopt_hmac_ident(struct sock *sk, int len,
 	struct sctp_hmac_algo_param *hmacs;
 	__u16 data_len = 0;
 	u32 num_idents;
+	int i;
 
 	if (!ep->auth_enable)
 		return -EACCES;
@@ -5428,8 +5429,12 @@ static int sctp_getsockopt_hmac_ident(struct sock *sk, int len,
 		return -EFAULT;
 	if (put_user(num_idents, &p->shmac_num_idents))
 		return -EFAULT;
-	if (copy_to_user(p->shmac_idents, hmacs->hmac_ids, data_len))
-		return -EFAULT;
+	for (i = 0; i < num_idents; i++) {
+		__u16 hmacid = ntohs(hmacs->hmac_ids[i]);
+
+		if (copy_to_user(&p->shmac_idents[i], &hmacid, sizeof(__u16)))
+			return -EFAULT;
+	}
 	return 0;
 }
 

[toc] | [prev] | [next] | [standalone]


#1344045 — [PATCH 3.16.y-ckt 109/129] ALSA: timer: Fix wrong instance passed to slave callbacks

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:40 +0100
Subject[PATCH 3.16.y-ckt 109/129] ALSA: timer: Fix wrong instance passed to slave callbacks
Message-ID<r6nYu-1Np-23@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit 117159f0b9d392fb433a7871426fad50317f06f7 upstream.

In snd_timer_notify1(), the wrong timer instance was passed for slave
ccallback function.  This leads to the access to the wrong data when
an incompatible master is handled (e.g. the master is the sequencer
timer and the slave is a user timer), as spotted by syzkaller fuzzer.

This patch fixes that wrong assignment.

BugLink: http://lkml.kernel.org/r/CACT4Y+Y_Bm+7epAb=8Wi=AaWd+DYS7qawX52qxdCfOfY49vozQ@mail.gmail.com
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 sound/core/timer.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sound/core/timer.c b/sound/core/timer.c
index 35146c65c46b..d6351b84fd29 100644
--- a/sound/core/timer.c
+++ b/sound/core/timer.c
@@ -422,7 +422,7 @@ static void snd_timer_notify1(struct snd_timer_instance *ti, int event)
 	spin_lock_irqsave(&timer->lock, flags);
 	list_for_each_entry(ts, &ti->slave_active_head, active_list)
 		if (ts->ccallback)
-			ts->ccallback(ti, event + 100, &tstamp, resolution);
+			ts->ccallback(ts, event + 100, &tstamp, resolution);
 	spin_unlock_irqrestore(&timer->lock, flags);
 }
 

[toc] | [prev] | [next] | [standalone]


#1344047 — [PATCH 3.16.y-ckt 123/129] netlink: not trim skb for mmaped socket when dump

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:40 +0100
Subject[PATCH 3.16.y-ckt 123/129] netlink: not trim skb for mmaped socket when dump
Message-ID<r6nYu-1Np-25@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Ken-ichirou MATSUZAWA <chamaken@gmail.com>

commit aa3a022094fac7f6e48050e139fa8a5a2e3265ce upstream.

We should not trim skb for mmaped socket since its buf size is fixed
and userspace will read as frame which data equals head. mmaped
socket will not call recvmsg, means max_recvmsg_len is 0,
skb_reserve was not called before commit: db65a3aaf29e.

Fixes: db65a3aaf29e (netlink: Trim skb to alloc size to avoid MSG_TRUNC)
Signed-off-by: Ken-ichirou MATSUZAWA <chamas@h4.dion.ne.jp>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/netlink/af_netlink.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c
index 7e1ac5b5de0a..46cac8e31a16 100644
--- a/net/netlink/af_netlink.c
+++ b/net/netlink/af_netlink.c
@@ -2740,7 +2740,8 @@ static int netlink_dump(struct sock *sk)
 	 * reasonable static buffer based on the expected largest dump of a
 	 * single netdev. The outcome is MSG_TRUNC error.
 	 */
-	skb_reserve(skb, skb_tailroom(skb) - alloc_size);
+	if (!netlink_rx_is_mmaped(sk))
+		skb_reserve(skb, skb_tailroom(skb) - alloc_size);
 	netlink_skb_set_owner_r(skb, sk);
 
 	len = cb->dump(skb, cb);

[toc] | [prev] | [next] | [standalone]


#1344048 — [PATCH 3.16.y-ckt 108/129] ALSA: dummy: Implement timer backend switching more safely

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:40 +0100
Subject[PATCH 3.16.y-ckt 108/129] ALSA: dummy: Implement timer backend switching more safely
Message-ID<r6nYu-1Np-27@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit ddce57a6f0a2d8d1bfacfa77f06043bc760403c2 upstream.

Currently the selected timer backend is referred at any moment from
the running PCM callbacks.  When the backend is switched, it's
possible to lead to inconsistency from the running backend.  This was
pointed by syzkaller fuzzer, and the commit [7ee96216c31a: ALSA:
dummy: Disable switching timer backend via sysfs] disabled the dynamic
switching for avoiding the crash.

This patch improves the handling of timer backend switching.  It keeps
the reference to the selected backend during the whole operation of an
opened stream so that it won't be changed by other streams.

Together with this change, the hrtimer parameter is reenabled as
writable now.

NOTE: this patch also turned out to fix the still remaining race.
Namely, ops was still replaced dynamically at dummy_pcm_open:

  static int dummy_pcm_open(struct snd_pcm_substream *substream)
  {
  ....
          dummy->timer_ops = &dummy_systimer_ops;
          if (hrtimer)
                  dummy->timer_ops = &dummy_hrtimer_ops;

Since dummy->timer_ops is common among all streams, and when the
replacement happens during accesses of other streams, it may lead to a
crash.  This was actually triggered by syzkaller fuzzer and KASAN.

This patch rewrites the code not to use the ops shared by all streams
any longer, too.

BugLink: http://lkml.kernel.org/r/CACT4Y+aZ+xisrpuM6cOXbL21DuM0yVxPYXf4cD4Md9uw0C3dBQ@mail.gmail.com
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 sound/drivers/dummy.c | 37 +++++++++++++++++++------------------
 1 file changed, 19 insertions(+), 18 deletions(-)

diff --git a/sound/drivers/dummy.c b/sound/drivers/dummy.c
index 1e29a1983791..387bb8f603ac 100644
--- a/sound/drivers/dummy.c
+++ b/sound/drivers/dummy.c
@@ -87,7 +87,7 @@ MODULE_PARM_DESC(pcm_substreams, "PCM substreams # (1-128) for dummy driver.");
 module_param(fake_buffer, bool, 0444);
 MODULE_PARM_DESC(fake_buffer, "Fake buffer allocations.");
 #ifdef CONFIG_HIGH_RES_TIMERS
-module_param(hrtimer, bool, 0444);
+module_param(hrtimer, bool, 0644);
 MODULE_PARM_DESC(hrtimer, "Use hrtimer as the timer source.");
 #endif
 
@@ -109,6 +109,9 @@ struct dummy_timer_ops {
 	snd_pcm_uframes_t (*pointer)(struct snd_pcm_substream *);
 };
 
+#define get_dummy_ops(substream) \
+	(*(const struct dummy_timer_ops **)(substream)->runtime->private_data)
+
 struct dummy_model {
 	const char *name;
 	int (*playback_constraints)(struct snd_pcm_runtime *runtime);
@@ -137,7 +140,6 @@ struct snd_dummy {
 	int iobox;
 	struct snd_kcontrol *cd_volume_ctl;
 	struct snd_kcontrol *cd_switch_ctl;
-	const struct dummy_timer_ops *timer_ops;
 };
 
 /*
@@ -231,6 +233,8 @@ struct dummy_model *dummy_models[] = {
  */
 
 struct dummy_systimer_pcm {
+	/* ops must be the first item */
+	const struct dummy_timer_ops *timer_ops;
 	spinlock_t lock;
 	struct timer_list timer;
 	unsigned long base_time;
@@ -368,6 +372,8 @@ static struct dummy_timer_ops dummy_systimer_ops = {
  */
 
 struct dummy_hrtimer_pcm {
+	/* ops must be the first item */
+	const struct dummy_timer_ops *timer_ops;
 	ktime_t base_time;
 	ktime_t period_time;
 	atomic_t running;
@@ -494,31 +500,25 @@ static struct dummy_timer_ops dummy_hrtimer_ops = {
 
 static int dummy_pcm_trigger(struct snd_pcm_substream *substream, int cmd)
 {
-	struct snd_dummy *dummy = snd_pcm_substream_chip(substream);
-
 	switch (cmd) {
 	case SNDRV_PCM_TRIGGER_START:
 	case SNDRV_PCM_TRIGGER_RESUME:
-		return dummy->timer_ops->start(substream);
+		return get_dummy_ops(substream)->start(substream);
 	case SNDRV_PCM_TRIGGER_STOP:
 	case SNDRV_PCM_TRIGGER_SUSPEND:
-		return dummy->timer_ops->stop(substream);
+		return get_dummy_ops(substream)->stop(substream);
 	}
 	return -EINVAL;
 }
 
 static int dummy_pcm_prepare(struct snd_pcm_substream *substream)
 {
-	struct snd_dummy *dummy = snd_pcm_substream_chip(substream);
-
-	return dummy->timer_ops->prepare(substream);
+	return get_dummy_ops(substream)->prepare(substream);
 }
 
 static snd_pcm_uframes_t dummy_pcm_pointer(struct snd_pcm_substream *substream)
 {
-	struct snd_dummy *dummy = snd_pcm_substream_chip(substream);
-
-	return dummy->timer_ops->pointer(substream);
+	return get_dummy_ops(substream)->pointer(substream);
 }
 
 static struct snd_pcm_hardware dummy_pcm_hardware = {
@@ -564,17 +564,19 @@ static int dummy_pcm_open(struct snd_pcm_substream *substream)
 	struct snd_dummy *dummy = snd_pcm_substream_chip(substream);
 	struct dummy_model *model = dummy->model;
 	struct snd_pcm_runtime *runtime = substream->runtime;
+	const struct dummy_timer_ops *ops;
 	int err;
 
-	dummy->timer_ops = &dummy_systimer_ops;
+	ops = &dummy_systimer_ops;
 #ifdef CONFIG_HIGH_RES_TIMERS
 	if (hrtimer)
-		dummy->timer_ops = &dummy_hrtimer_ops;
+		ops = &dummy_hrtimer_ops;
 #endif
 
-	err = dummy->timer_ops->create(substream);
+	err = ops->create(substream);
 	if (err < 0)
 		return err;
+	get_dummy_ops(substream) = ops;
 
 	runtime->hw = dummy->pcm_hw;
 	if (substream->pcm->device & 1) {
@@ -596,7 +598,7 @@ static int dummy_pcm_open(struct snd_pcm_substream *substream)
 			err = model->capture_constraints(substream->runtime);
 	}
 	if (err < 0) {
-		dummy->timer_ops->free(substream);
+		get_dummy_ops(substream)->free(substream);
 		return err;
 	}
 	return 0;
@@ -604,8 +606,7 @@ static int dummy_pcm_open(struct snd_pcm_substream *substream)
 
 static int dummy_pcm_close(struct snd_pcm_substream *substream)
 {
-	struct snd_dummy *dummy = snd_pcm_substream_chip(substream);
-	dummy->timer_ops->free(substream);
+	get_dummy_ops(substream)->free(substream);
 	return 0;
 }
 

[toc] | [prev] | [next] | [standalone]


#1344050 — [PATCH 3.16.y-ckt 106/129] ALSA: hda - Fix speaker output from VAIO AiO machines

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:40 +0100
Subject[PATCH 3.16.y-ckt 106/129] ALSA: hda - Fix speaker output from VAIO AiO machines
Message-ID<r6nYu-1Np-29@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit c44d9b1181cf34e0860c72cc8a00e0c47417aac0 upstream.

Some Sony VAIO AiO models (VGC-JS4EF and VGC-JS25G, both with PCI SSID
104d:9044) need the same quirk to make the speaker working properly.

Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=112031
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 sound/pci/hda/patch_realtek.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index d76e45078866..af6448309a00 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -2285,6 +2285,7 @@ static const struct snd_pci_quirk alc882_fixup_tbl[] = {
 	SND_PCI_QUIRK(0x104d, 0x9047, "Sony Vaio TT", ALC889_FIXUP_VAIO_TT),
 	SND_PCI_QUIRK(0x104d, 0x905a, "Sony Vaio Z", ALC882_FIXUP_NO_PRIMARY_HP),
 	SND_PCI_QUIRK(0x104d, 0x9043, "Sony Vaio VGC-LN51JGB", ALC882_FIXUP_NO_PRIMARY_HP),
+	SND_PCI_QUIRK(0x104d, 0x9044, "Sony VAIO AiO", ALC882_FIXUP_NO_PRIMARY_HP),
 
 	/* All Apple entries are in codec SSIDs */
 	SND_PCI_QUIRK(0x106b, 0x00a0, "MacBookPro 3,1", ALC889_FIXUP_MBP_VREF),

[toc] | [prev] | [next] | [standalone]


#1344052 — [PATCH 3.16.y-ckt 100/129] mm: replace vma_lock_anon_vma with anon_vma_lock_read/write

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:40 +0100
Subject[PATCH 3.16.y-ckt 100/129] mm: replace vma_lock_anon_vma with anon_vma_lock_read/write
Message-ID<r6nYv-1Np-43@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Konstantin Khlebnikov <koct9i@gmail.com>

commit 12352d3cae2cebe18805a91fab34b534d7444231 upstream.

Sequence vma_lock_anon_vma() - vma_unlock_anon_vma() isn't safe if
anon_vma appeared between lock and unlock.  We have to check anon_vma
first or call anon_vma_prepare() to be sure that it's here.  There are
only few users of these legacy helpers.  Let's get rid of them.

This patch fixes anon_vma lock imbalance in validate_mm().  Write lock
isn't required here, read lock is enough.

And reorders expand_downwards/expand_upwards: security_mmap_addr() and
wrapping-around check don't have to be under anon vma lock.

Link: https://lkml.kernel.org/r/CACT4Y+Y908EjM2z=706dv4rV6dWtxTLK9nFg9_7DhRMLppBo2g@mail.gmail.com
Signed-off-by: Konstantin Khlebnikov <koct9i@gmail.com>
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Acked-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 include/linux/rmap.h | 14 -------------
 mm/mmap.c            | 56 ++++++++++++++++++++++++----------------------------
 2 files changed, 26 insertions(+), 44 deletions(-)

diff --git a/include/linux/rmap.h b/include/linux/rmap.h
index 28349a8fd08b..59bca41b7229 100644
--- a/include/linux/rmap.h
+++ b/include/linux/rmap.h
@@ -113,20 +113,6 @@ static inline struct anon_vma *page_anon_vma(struct page *page)
 	return page_rmapping(page);
 }
 
-static inline void vma_lock_anon_vma(struct vm_area_struct *vma)
-{
-	struct anon_vma *anon_vma = vma->anon_vma;
-	if (anon_vma)
-		down_write(&anon_vma->root->rwsem);
-}
-
-static inline void vma_unlock_anon_vma(struct vm_area_struct *vma)
-{
-	struct anon_vma *anon_vma = vma->anon_vma;
-	if (anon_vma)
-		up_write(&anon_vma->root->rwsem);
-}
-
 static inline void anon_vma_lock_write(struct anon_vma *anon_vma)
 {
 	down_write(&anon_vma->root->rwsem);
diff --git a/mm/mmap.c b/mm/mmap.c
index 0c144ec8c810..2859a1cb378a 100644
--- a/mm/mmap.c
+++ b/mm/mmap.c
@@ -416,11 +416,16 @@ static void validate_mm(struct mm_struct *mm)
 	unsigned long highest_address = 0;
 	struct vm_area_struct *vma = mm->mmap;
 	while (vma) {
+		struct anon_vma *anon_vma = vma->anon_vma;
 		struct anon_vma_chain *avc;
-		vma_lock_anon_vma(vma);
-		list_for_each_entry(avc, &vma->anon_vma_chain, same_vma)
-			anon_vma_interval_tree_verify(avc);
-		vma_unlock_anon_vma(vma);
+
+		if (anon_vma) {
+			anon_vma_lock_read(anon_vma);
+			list_for_each_entry(avc, &vma->anon_vma_chain, same_vma)
+				anon_vma_interval_tree_verify(avc);
+			anon_vma_unlock_read(anon_vma);
+		}
+
 		highest_address = vma->vm_end;
 		vma = vma->vm_next;
 		i++;
@@ -2111,32 +2116,27 @@ static int acct_stack_growth(struct vm_area_struct *vma, unsigned long size, uns
  */
 int expand_upwards(struct vm_area_struct *vma, unsigned long address)
 {
-	int error;
+	int error = 0;
 
 	if (!(vma->vm_flags & VM_GROWSUP))
 		return -EFAULT;
 
-	/*
-	 * We must make sure the anon_vma is allocated
-	 * so that the anon_vma locking is not a noop.
-	 */
+	/* Guard against wrapping around to address 0. */
+	if (address < PAGE_ALIGN(address+4))
+		address = PAGE_ALIGN(address+4);
+	else
+		return -ENOMEM;
+
+	/* We must make sure the anon_vma is allocated. */
 	if (unlikely(anon_vma_prepare(vma)))
 		return -ENOMEM;
-	vma_lock_anon_vma(vma);
 
 	/*
 	 * vma->vm_start/vm_end cannot change under us because the caller
 	 * is required to hold the mmap_sem in read mode.  We need the
 	 * anon_vma lock to serialize against concurrent expand_stacks.
-	 * Also guard against wrapping around to address 0.
 	 */
-	if (address < PAGE_ALIGN(address+4))
-		address = PAGE_ALIGN(address+4);
-	else {
-		vma_unlock_anon_vma(vma);
-		return -ENOMEM;
-	}
-	error = 0;
+	anon_vma_lock_write(vma->anon_vma);
 
 	/* Somebody else might have raced and expanded it already */
 	if (address > vma->vm_end) {
@@ -2154,7 +2154,7 @@ int expand_upwards(struct vm_area_struct *vma, unsigned long address)
 				 * updates, but we only hold a shared mmap_sem
 				 * lock here, so we need to protect against
 				 * concurrent vma expansions.
-				 * vma_lock_anon_vma() doesn't help here, as
+				 * anon_vma_lock_write() doesn't help here, as
 				 * we don't guarantee that all growable vmas
 				 * in a mm share the same root anon vma.
 				 * So, we reuse mm->page_table_lock to guard
@@ -2174,7 +2174,7 @@ int expand_upwards(struct vm_area_struct *vma, unsigned long address)
 			}
 		}
 	}
-	vma_unlock_anon_vma(vma);
+	anon_vma_unlock_write(vma->anon_vma);
 	khugepaged_enter_vma_merge(vma, vma->vm_flags);
 	validate_mm(vma->vm_mm);
 	return error;
@@ -2189,25 +2189,21 @@ int expand_downwards(struct vm_area_struct *vma,
 {
 	int error;
 
-	/*
-	 * We must make sure the anon_vma is allocated
-	 * so that the anon_vma locking is not a noop.
-	 */
-	if (unlikely(anon_vma_prepare(vma)))
-		return -ENOMEM;
-
 	address &= PAGE_MASK;
 	error = security_mmap_addr(address);
 	if (error)
 		return error;
 
-	vma_lock_anon_vma(vma);
+	/* We must make sure the anon_vma is allocated. */
+	if (unlikely(anon_vma_prepare(vma)))
+		return -ENOMEM;
 
 	/*
 	 * vma->vm_start/vm_end cannot change under us because the caller
 	 * is required to hold the mmap_sem in read mode.  We need the
 	 * anon_vma lock to serialize against concurrent expand_stacks.
 	 */
+	anon_vma_lock_write(vma->anon_vma);
 
 	/* Somebody else might have raced and expanded it already */
 	if (address < vma->vm_start) {
@@ -2225,7 +2221,7 @@ int expand_downwards(struct vm_area_struct *vma,
 				 * updates, but we only hold a shared mmap_sem
 				 * lock here, so we need to protect against
 				 * concurrent vma expansions.
-				 * vma_lock_anon_vma() doesn't help here, as
+				 * anon_vma_lock_write() doesn't help here, as
 				 * we don't guarantee that all growable vmas
 				 * in a mm share the same root anon vma.
 				 * So, we reuse mm->page_table_lock to guard
@@ -2243,7 +2239,7 @@ int expand_downwards(struct vm_area_struct *vma,
 			}
 		}
 	}
-	vma_unlock_anon_vma(vma);
+	anon_vma_unlock_write(vma->anon_vma);
 	khugepaged_enter_vma_merge(vma, vma->vm_flags);
 	validate_mm(vma->vm_mm);
 	return error;

[toc] | [prev] | [next] | [standalone]


#1344054 — [PATCH 3.16.y-ckt 099/129] ocfs2/dlm: clear refmap bit of recovery lock while doing local recovery cleanup

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:40 +0100
Subject[PATCH 3.16.y-ckt 099/129] ocfs2/dlm: clear refmap bit of recovery lock while doing local recovery cleanup
Message-ID<r6nYu-1Np-41@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: xuejiufei <xuejiufei@huawei.com>

commit c95a51807b730e4681e2ecbdfd669ca52601959e upstream.

When recovery master down, dlm_do_local_recovery_cleanup() only remove
the $RECOVERY lock owned by dead node, but do not clear the refmap bit.
Which will make umount thread falling in dead loop migrating $RECOVERY
to the dead node.

Signed-off-by: xuejiufei <xuejiufei@huawei.com>
Reviewed-by: Joseph Qi <joseph.qi@huawei.com>
Cc: Mark Fasheh <mfasheh@suse.de>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 fs/ocfs2/dlm/dlmrecovery.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/fs/ocfs2/dlm/dlmrecovery.c b/fs/ocfs2/dlm/dlmrecovery.c
index 5084ce856879..539b577740c7 100644
--- a/fs/ocfs2/dlm/dlmrecovery.c
+++ b/fs/ocfs2/dlm/dlmrecovery.c
@@ -2345,6 +2345,8 @@ static void dlm_do_local_recovery_cleanup(struct dlm_ctxt *dlm, u8 dead_node)
 						break;
 					}
 				}
+				dlm_lockres_clear_refmap_bit(dlm, res,
+						dead_node);
 				spin_unlock(&res->spinlock);
 				continue;
 			}

[toc] | [prev] | [next] | [standalone]


#1344055 — [PATCH 3.16.y-ckt 122/129] sctp: allow setting SCTP_SACK_IMMEDIATELY by the application

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:40 +0100
Subject[PATCH 3.16.y-ckt 122/129] sctp: allow setting SCTP_SACK_IMMEDIATELY by the application
Message-ID<r6nYv-1Np-47@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>

commit 27f7ed2b11d42ab6d796e96533c2076ec220affc upstream.

This patch extends commit b93d6471748d ("sctp: implement the sender side
for SACK-IMMEDIATELY extension") as it didn't white list
SCTP_SACK_IMMEDIATELY on sctp_msghdr_parse(), causing it to be
understood as an invalid flag and returning -EINVAL to the application.

Note that the actual handling of the flag is already there in
sctp_datamsg_from_user().

https://tools.ietf.org/html/rfc7053#section-7

Fixes: b93d6471748d ("sctp: implement the sender side for SACK-IMMEDIATELY extension")
Signed-off-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Acked-by: Vlad Yasevich <vyasevich@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ luis: backported to 3.16:
  - dropped changes to SCTP_SNDINFO case ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/sctp/socket.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/net/sctp/socket.c b/net/sctp/socket.c
index 88c5befcb569..70bac7a75b9c 100644
--- a/net/sctp/socket.c
+++ b/net/sctp/socket.c
@@ -6464,6 +6464,7 @@ static int sctp_msghdr_parse(const struct msghdr *msg, sctp_cmsgs_t *cmsgs)
 			/* Minimally, validate the sinfo_flags. */
 			if (cmsgs->info->sinfo_flags &
 			    ~(SCTP_UNORDERED | SCTP_ADDR_OVER |
+			      SCTP_SACK_IMMEDIATELY |
 			      SCTP_ABORT | SCTP_EOF))
 				return -EINVAL;
 			break;

[toc] | [prev] | [next] | [standalone]


#1344058 — [PATCH 3.16.y-ckt 115/129] workqueue: handle NUMA_NO_NODE for unbound pool_workqueue lookup

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:40 +0100
Subject[PATCH 3.16.y-ckt 115/129] workqueue: handle NUMA_NO_NODE for unbound pool_workqueue lookup
Message-ID<r6nYv-1Np-55@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Tejun Heo <tj@kernel.org>

commit d6e022f1d207a161cd88e08ef0371554680ffc46 upstream.

When looking up the pool_workqueue to use for an unbound workqueue,
workqueue assumes that the target CPU is always bound to a valid NUMA
node.  However, currently, when a CPU goes offline, the mapping is
destroyed and cpu_to_node() returns NUMA_NO_NODE.

This has always been broken but hasn't triggered often enough before
874bbfe600a6 ("workqueue: make sure delayed work run in local cpu").
After the commit, workqueue forcifully assigns the local CPU for
delayed work items without explicit target CPU to fix a different
issue.  This widens the window where CPU can go offline while a
delayed work item is pending causing delayed work items dispatched
with target CPU set to an already offlined CPU.  The resulting
NUMA_NO_NODE mapping makes workqueue try to queue the work item on a
NULL pool_workqueue and thus crash.

While 874bbfe600a6 has been reverted for a different reason making the
bug less visible again, it can still happen.  Fix it by mapping
NUMA_NO_NODE to the default pool_workqueue from unbound_pwq_by_node().
This is a temporary workaround.  The long term solution is keeping CPU
-> NODE mapping stable across CPU off/online cycles which is being
worked on.

Signed-off-by: Tejun Heo <tj@kernel.org>
Reported-by: Mike Galbraith <umgwanakikbuti@gmail.com>
Cc: Tang Chen <tangchen@cn.fujitsu.com>
Cc: Rafael J. Wysocki <rafael@kernel.org>
Cc: Len Brown <len.brown@intel.com>
Link: http://lkml.kernel.org/g/1454424264.11183.46.camel@gmail.com
Link: http://lkml.kernel.org/g/1453702100-2597-1-git-send-email-tangchen@cn.fujitsu.com
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 kernel/workqueue.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/kernel/workqueue.c b/kernel/workqueue.c
index cb7db323d1fb..6ab1f683ac49 100644
--- a/kernel/workqueue.c
+++ b/kernel/workqueue.c
@@ -553,6 +553,16 @@ static struct pool_workqueue *unbound_pwq_by_node(struct workqueue_struct *wq,
 						  int node)
 {
 	assert_rcu_or_wq_mutex(wq);
+
+	/*
+	 * XXX: @node can be NUMA_NO_NODE if CPU goes offline while a
+	 * delayed item is pending.  The plan is to keep CPU -> NODE
+	 * mapping valid and stable across CPU on/offlines.  Once that
+	 * happens, this workaround can be removed.
+	 */
+	if (unlikely(node == NUMA_NO_NODE))
+		return wq->dfl_pwq;
+
 	return rcu_dereference_raw(wq->numa_pwq_tbl[node]);
 }
 

[toc] | [prev] | [next] | [standalone]


#1344059 — [PATCH 3.16.y-ckt 111/129] ALSA: timer: Fix race between stop and interrupt

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:40 +0100
Subject[PATCH 3.16.y-ckt 111/129] ALSA: timer: Fix race between stop and interrupt
Message-ID<r6nYv-1Np-57@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit ed8b1d6d2c741ab26d60d499d7fbb7ac801f0f51 upstream.

A slave timer element also unlinks at snd_timer_stop() but it takes
only slave_active_lock.  When a slave is assigned to a master,
however, this may become a race against the master's interrupt
handling, eventually resulting in a list corruption.  The actual bug
could be seen with a syzkaller fuzzer test case in BugLink below.

As a fix, we need to take timeri->timer->lock when timer isn't NULL,
i.e. assigned to a master, while the assignment to a master itself is
protected by slave_active_lock.

BugLink: http://lkml.kernel.org/r/CACT4Y+Y_Bm+7epAb=8Wi=AaWd+DYS7qawX52qxdCfOfY49vozQ@mail.gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 sound/core/timer.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/sound/core/timer.c b/sound/core/timer.c
index d6351b84fd29..a5a758404943 100644
--- a/sound/core/timer.c
+++ b/sound/core/timer.c
@@ -518,9 +518,13 @@ static int _snd_timer_stop(struct snd_timer_instance *timeri, int event)
 			spin_unlock_irqrestore(&slave_active_lock, flags);
 			return -EBUSY;
 		}
+		if (timeri->timer)
+			spin_lock(&timeri->timer->lock);
 		timeri->flags &= ~SNDRV_TIMER_IFLG_RUNNING;
 		list_del_init(&timeri->ack_list);
 		list_del_init(&timeri->active_list);
+		if (timeri->timer)
+			spin_unlock(&timeri->timer->lock);
 		spin_unlock_irqrestore(&slave_active_lock, flags);
 		goto __end;
 	}

[toc] | [prev] | [next] | [standalone]


#1344060 — [PATCH 3.16.y-ckt 125/129] ipv6: fix a lockdep splat

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:40 +0100
Subject[PATCH 3.16.y-ckt 125/129] ipv6: fix a lockdep splat
Message-ID<r6nYv-1Np-61@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Eric Dumazet <edumazet@google.com>

commit 44c3d0c1c0a880354e9de5d94175742e2c7c9683 upstream.

Silence lockdep false positive about rcu_dereference() being
used in the wrong context.

First one should use rcu_dereference_protected() as we own the spinlock.

Second one should be a normal assignation, as no barrier is needed.

Fixes: 18367681a10bd ("ipv6 flowlabel: Convert np->ipv6_fl_list to RCU.")
Reported-by: Dave Jones <davej@codemonkey.org.uk>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/ipv6/ip6_flowlabel.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/net/ipv6/ip6_flowlabel.c b/net/ipv6/ip6_flowlabel.c
index 4052694c6f2c..f40ba684d69b 100644
--- a/net/ipv6/ip6_flowlabel.c
+++ b/net/ipv6/ip6_flowlabel.c
@@ -542,12 +542,13 @@ int ipv6_flowlabel_opt(struct sock *sk, char __user *optval, int optlen)
 		}
 		spin_lock_bh(&ip6_sk_fl_lock);
 		for (sflp = &np->ipv6_fl_list;
-		     (sfl = rcu_dereference(*sflp))!=NULL;
+		     (sfl = rcu_dereference_protected(*sflp,
+						      lockdep_is_held(&ip6_sk_fl_lock))) != NULL;
 		     sflp = &sfl->next) {
 			if (sfl->fl->label == freq.flr_label) {
 				if (freq.flr_label == (np->flow_label&IPV6_FLOWLABEL_MASK))
 					np->flow_label &= ~IPV6_FLOWLABEL_MASK;
-				*sflp = rcu_dereference(sfl->next);
+				*sflp = sfl->next;
 				spin_unlock_bh(&ip6_sk_fl_lock);
 				fl_release(sfl->fl);
 				kfree_rcu(sfl, rcu);

[toc] | [prev] | [next] | [standalone]


#1344061 — [PATCH 3.16.y-ckt 110/129] ARM: 8517/1: ICST: avoid arithmetic overflow in icst_hz()

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:40 +0100
Subject[PATCH 3.16.y-ckt 110/129] ARM: 8517/1: ICST: avoid arithmetic overflow in icst_hz()
Message-ID<r6nYv-1Np-59@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Linus Walleij <linus.walleij@linaro.org>

commit 5070fb14a0154f075c8b418e5bc58a620ae85a45 upstream.

When trying to set the ICST 307 clock to 25174000 Hz I ran into
this arithmetic error: the icst_hz_to_vco() correctly figure out
DIVIDE=2, RDW=100 and VDW=99 yielding a frequency of
25174000 Hz out of the VCO. (I replicated the icst_hz() function
in a spreadsheet to verify this.)

However, when I called icst_hz() on these VCO settings it would
instead return 4122709 Hz. This causes an error in the common
clock driver for ICST as the common clock framework will call
.round_rate() on the clock which will utilize icst_hz_to_vco()
followed by icst_hz() suggesting the erroneous frequency, and
then the clock gets set to this.

The error did not manifest in the old clock framework since
this high frequency was only used by the CLCD, which calls
clk_set_rate() without first calling clk_round_rate() and since
the old clock framework would not call clk_round_rate() before
setting the frequency, the correct values propagated into
the VCO.

After some experimenting I figured out that it was due to a simple
arithmetic overflow: the divisor for 24Mhz reference frequency
as reference becomes 24000000*2*(99+8)=0x132212400 and the "1"
in bit 32 overflows and is lost.

But introducing an explicit 64-by-32 bit do_div() and casting
the divisor into (u64) we get the right frequency back, and the
right frequency gets set.

Tested on the ARM Versatile.

Cc: linux-clk@vger.kernel.org
Cc: Pawel Moll <pawel.moll@arm.com>
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 arch/arm/common/icst.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/arch/arm/common/icst.c b/arch/arm/common/icst.c
index 2dc6da70ae59..d3c0e69df259 100644
--- a/arch/arm/common/icst.c
+++ b/arch/arm/common/icst.c
@@ -16,7 +16,7 @@
  */
 #include <linux/module.h>
 #include <linux/kernel.h>
-
+#include <asm/div64.h>
 #include <asm/hardware/icst.h>
 
 /*
@@ -29,7 +29,11 @@ EXPORT_SYMBOL(icst525_s2div);
 
 unsigned long icst_hz(const struct icst_params *p, struct icst_vco vco)
 {
-	return p->ref * 2 * (vco.v + 8) / ((vco.r + 2) * p->s2div[vco.s]);
+	u64 dividend = p->ref * 2 * (u64)(vco.v + 8);
+	u32 divisor = (vco.r + 2) * p->s2div[vco.s];
+
+	do_div(dividend, divisor);
+	return (unsigned long)dividend;
 }
 
 EXPORT_SYMBOL(icst_hz);

[toc] | [prev] | [next] | [standalone]


#1344062 — [PATCH 3.16.y-ckt 120/129] af_unix: fix struct pid memory leak

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:40 +0100
Subject[PATCH 3.16.y-ckt 120/129] af_unix: fix struct pid memory leak
Message-ID<r6nYw-1Np-67@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Eric Dumazet <edumazet@google.com>

commit fa0dc04df259ba2df3ce1920e9690c7842f8fa4b upstream.

Dmitry reported a struct pid leak detected by a syzkaller program.

Bug happens in unix_stream_recvmsg() when we break the loop when a
signal is pending, without properly releasing scm.

Fixes: b3ca9b02b007 ("net: fix multithreaded signal handling in unix recv routines")
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Rainer Weikusat <rweikusat@mobileactivedefense.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ luis: backported to 3.16:
  - use siocb->scm instead of &scm ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/unix/af_unix.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
index 20d752634efb..8ea231735292 100644
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -2155,6 +2155,7 @@ again:
 
 			if (signal_pending(current)) {
 				err = sock_intr_errno(timeo);
+				scm_destroy(siocb->scm);
 				goto out;
 			}
 

[toc] | [prev] | [next] | [standalone]


#1344063 — [PATCH 3.16.y-ckt 096/129] Revert "ALSA: hda - Fix noise on Gigabyte Z170X mobo"

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:50 +0100
Subject[PATCH 3.16.y-ckt 096/129] Revert "ALSA: hda - Fix noise on Gigabyte Z170X mobo"
Message-ID<r6o89-1Sy-1@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit 6c361d10e0eb859233c71954abcd20d2d8700587 upstream.

This reverts commit 0c25ad80408e95e0a4fbaf0056950206e95f726f.

The original commit disabled the aamixer path due to the noise
problem, but it turned out that some mobo with the same PCI SSID
doesn't suffer from the issue, and the disabled function (analog
loopback) is still demanded by users.

Since the recent commit [e7fdd52779a6: ALSA: hda - Implement loopback
control switch for Realtek and other codecs], we have the dynamic
mixer switch to enable/disable the aamix path, and we don't have to
disable the path statically any longer.  So, let's revert the
disablement, so that only the user suffering from the noise problem
can turn off the aamix on the fly.

Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=108301
Reported-by: <mutedbytes@gmail.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 sound/pci/hda/patch_realtek.c | 8 --------
 1 file changed, 8 deletions(-)

diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index 3b08cddabb17..d76e45078866 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -1849,7 +1849,6 @@ enum {
 	ALC882_FIXUP_NO_PRIMARY_HP,
 	ALC887_FIXUP_ASUS_BASS,
 	ALC887_FIXUP_BASS_CHMAP,
-	ALC882_FIXUP_DISABLE_AAMIX,
 };
 
 static void alc889_fixup_coef(struct hda_codec *codec,
@@ -2011,8 +2010,6 @@ static void alc882_fixup_no_primary_hp(struct hda_codec *codec,
 
 static void alc_fixup_bass_chmap(struct hda_codec *codec,
 				 const struct hda_fixup *fix, int action);
-static void alc_fixup_disable_aamix(struct hda_codec *codec,
-				    const struct hda_fixup *fix, int action);
 
 static const struct hda_fixup alc882_fixups[] = {
 	[ALC882_FIXUP_ABIT_AW9D_MAX] = {
@@ -2250,10 +2247,6 @@ static const struct hda_fixup alc882_fixups[] = {
 		.type = HDA_FIXUP_FUNC,
 		.v.func = alc_fixup_bass_chmap,
 	},
-	[ALC882_FIXUP_DISABLE_AAMIX] = {
-		.type = HDA_FIXUP_FUNC,
-		.v.func = alc_fixup_disable_aamix,
-	},
 };
 
 static const struct snd_pci_quirk alc882_fixup_tbl[] = {
@@ -2321,7 +2314,6 @@ static const struct snd_pci_quirk alc882_fixup_tbl[] = {
 	SND_PCI_QUIRK(0x1462, 0x7350, "MSI-7350", ALC889_FIXUP_CD),
 	SND_PCI_QUIRK_VENDOR(0x1462, "MSI", ALC882_FIXUP_GPIO3),
 	SND_PCI_QUIRK(0x1458, 0xa002, "Gigabyte EP45-DS3/Z87X-UD3H", ALC889_FIXUP_FRONT_HP_NO_PRESENCE),
-	SND_PCI_QUIRK(0x1458, 0xa182, "Gigabyte Z170X-UD3", ALC882_FIXUP_DISABLE_AAMIX),
 	SND_PCI_QUIRK(0x147b, 0x107a, "Abit AW9D-MAX", ALC882_FIXUP_ABIT_AW9D_MAX),
 	SND_PCI_QUIRK_VENDOR(0x1558, "Clevo laptop", ALC882_FIXUP_EAPD),
 	SND_PCI_QUIRK(0x161f, 0x2054, "Medion laptop", ALC883_FIXUP_EAPD),

[toc] | [prev] | [next] | [standalone]


#1344064 — [PATCH 3.16.y-ckt 093/129] SCSI: Add Marvell Console to VPD blacklist

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:50 +0100
Subject[PATCH 3.16.y-ckt 093/129] SCSI: Add Marvell Console to VPD blacklist
Message-ID<r6o8a-1Sy-13@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Mika Westerberg <mika.westerberg@linux.intel.com>

commit 82c43310508eb19eb41fe7862e89afeb74030b84 upstream.

I have a Marvell 88SE9230 SATA Controller that has some sort of
integrated console SCSI device attached to one of the ports.

  ata14: SATA link up 1.5 Gbps (SStatus 113 SControl 300)
  ata14.00: ATAPI: MARVELL VIRTUALL, 1.09, max UDMA/66
  ata14.00: configured for UDMA/66
  scsi 13:0:0:0: Processor         Marvell  Console 1.01 PQ: 0 ANSI: 5

Sending it VPD INQUIRY command seem to always fail with following error:

  ata14.00: exception Emask 0x0 SAct 0x0 SErr 0x0 action 0x6
  ata14.00: irq_stat 0x40000001
  ata14.00: cmd a0/01:00:00:00:01/00:00:00:00:00/a0 tag 2 dma 16640 in
            Inquiry 12 01 00 00 ff 00res 00/00:00:00:00:00/00:00:00:00:00/00 Emask 0x3 (HSM violation)
  ata14: hard resetting link

This has been minor annoyance (only error printed on dmesg) until commit
09e2b0b14690 ("scsi: rescan VPD attributes") added call to scsi_attach_vpd()
in scsi_rescan_device(). The commit causes the system to splat out
following errors continuously without ever reaching the UI:

  ata14.00: configured for UDMA/66
  ata14: EH complete
  ata14.00: exception Emask 0x0 SAct 0x0 SErr 0x0 action 0x6
  ata14.00: irq_stat 0x40000001
  ata14.00: cmd a0/01:00:00:00:01/00:00:00:00:00/a0 tag 6 dma 16640 in
            Inquiry 12 01 00 00 ff 00res 00/00:00:00:00:00/00:00:00:00:00/00 Emask 0x3 (HSM violation)
  ata14: hard resetting link
  ata14: SATA link up 1.5 Gbps (SStatus 113 SControl 300)
  ata14.00: configured for UDMA/66
  ata14: EH complete
  ata14.00: exception Emask 0x0 SAct 0x0 SErr 0x0 action 0x6
  ata14.00: irq_stat 0x40000001
  ata14.00: cmd a0/01:00:00:00:01/00:00:00:00:00/a0 tag 7 dma 16640 in
            Inquiry 12 01 00 00 ff 00res 00/00:00:00:00:00/00:00:00:00:00/00 Emask 0x3 (HSM violation)

Without in-depth understanding of SCSI layer and the Marvell controller,
I suspect this happens because when the link goes down (because of an
error) we schedule scsi_rescan_device() which again fails to read VPD
data... ad infinitum.

Since VPD data cannot be read from the device anyway we prevent the SCSI
layer from even trying by blacklisting the device. This gets away the
error and the system starts up normally.

[mkp: Widened the match to all revisions of this device]

Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
Reported-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Reported-by: Alexander Duyck <alexander.duyck@gmail.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 drivers/scsi/scsi_devinfo.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/scsi/scsi_devinfo.c b/drivers/scsi/scsi_devinfo.c
index 9f77d23239a2..6e2256f7d7d6 100644
--- a/drivers/scsi/scsi_devinfo.c
+++ b/drivers/scsi/scsi_devinfo.c
@@ -205,6 +205,7 @@ static struct {
 	{"Intel", "Multi-Flex", NULL, BLIST_NO_RSOC},
 	{"iRiver", "iFP Mass Driver", NULL, BLIST_NOT_LOCKABLE | BLIST_INQUIRY_36},
 	{"LASOUND", "CDX7405", "3.10", BLIST_MAX5LUN | BLIST_SINGLELUN},
+	{"Marvell", "Console", NULL, BLIST_SKIP_VPD_PAGES},
 	{"MATSHITA", "PD-1", NULL, BLIST_FORCELUN | BLIST_SINGLELUN},
 	{"MATSHITA", "DMC-LC5", NULL, BLIST_NOT_LOCKABLE | BLIST_INQUIRY_36},
 	{"MATSHITA", "DMC-LC40", NULL, BLIST_NOT_LOCKABLE | BLIST_INQUIRY_36},

[toc] | [prev] | [next] | [standalone]


#1344065 — [PATCH 3.16.y-ckt 084/129] radix-tree: fix race in gang lookup

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:50 +0100
Subject[PATCH 3.16.y-ckt 084/129] radix-tree: fix race in gang lookup
Message-ID<r6o89-1Sy-11@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Matthew Wilcox <willy@linux.intel.com>

commit 46437f9a554fbe3e110580ca08ab703b59f2f95a upstream.

If the indirect_ptr bit is set on a slot, that indicates we need to redo
the lookup.  Introduce a new function radix_tree_iter_retry() which
forces the loop to retry the lookup by setting 'slot' to NULL and
turning the iterator back to point at the problematic entry.

This is a pretty rare problem to hit at the moment; the lookup has to
race with a grow of the radix tree from a height of 0.  The consequences
of hitting this race are that gang lookup could return a pointer to a
radix_tree_node instead of a pointer to whatever the user had inserted
in the tree.

Fixes: cebbd29e1c2f ("radix-tree: rewrite gang lookup using iterator")
Signed-off-by: Matthew Wilcox <willy@linux.intel.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Ohad Ben-Cohen <ohad@wizery.com>
Cc: Konstantin Khlebnikov <khlebnikov@openvz.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 include/linux/radix-tree.h | 16 ++++++++++++++++
 lib/radix-tree.c           | 12 ++++++++++--
 2 files changed, 26 insertions(+), 2 deletions(-)

diff --git a/include/linux/radix-tree.h b/include/linux/radix-tree.h
index 33170dbd9db4..1a2b2276ffb3 100644
--- a/include/linux/radix-tree.h
+++ b/include/linux/radix-tree.h
@@ -370,6 +370,22 @@ void **radix_tree_next_chunk(struct radix_tree_root *root,
 			     struct radix_tree_iter *iter, unsigned flags);
 
 /**
+ * radix_tree_iter_retry - retry this chunk of the iteration
+ * @iter:	iterator state
+ *
+ * If we iterate over a tree protected only by the RCU lock, a race
+ * against deletion or creation may result in seeing a slot for which
+ * radix_tree_deref_retry() returns true.  If so, call this function
+ * and continue the iteration.
+ */
+static inline __must_check
+void **radix_tree_iter_retry(struct radix_tree_iter *iter)
+{
+	iter->next_index = iter->index;
+	return NULL;
+}
+
+/**
  * radix_tree_chunk_size - get current chunk size
  *
  * @iter:	pointer to radix tree iterator
diff --git a/lib/radix-tree.c b/lib/radix-tree.c
index 3291a8e37490..b31e22ddc37c 100644
--- a/lib/radix-tree.c
+++ b/lib/radix-tree.c
@@ -1014,9 +1014,13 @@ radix_tree_gang_lookup(struct radix_tree_root *root, void **results,
 		return 0;
 
 	radix_tree_for_each_slot(slot, root, &iter, first_index) {
-		results[ret] = indirect_to_ptr(rcu_dereference_raw(*slot));
+		results[ret] = rcu_dereference_raw(*slot);
 		if (!results[ret])
 			continue;
+		if (radix_tree_is_indirect_ptr(results[ret])) {
+			slot = radix_tree_iter_retry(&iter);
+			continue;
+		}
 		if (++ret == max_items)
 			break;
 	}
@@ -1093,9 +1097,13 @@ radix_tree_gang_lookup_tag(struct radix_tree_root *root, void **results,
 		return 0;
 
 	radix_tree_for_each_tagged(slot, root, &iter, first_index, tag) {
-		results[ret] = indirect_to_ptr(rcu_dereference_raw(*slot));
+		results[ret] = rcu_dereference_raw(*slot);
 		if (!results[ret])
 			continue;
+		if (radix_tree_is_indirect_ptr(results[ret])) {
+			slot = radix_tree_iter_retry(&iter);
+			continue;
+		}
 		if (++ret == max_items)
 			break;
 	}

[toc] | [prev] | [next] | [standalone]


#1344066 — [PATCH 3.16.y-ckt 077/129] ASoC: dpcm: fix the BE state on hw_free

FromLuis Henriques <luis.henriques@canonical.com>
Date2016-02-26 11:50 +0100
Subject[PATCH 3.16.y-ckt 077/129] ASoC: dpcm: fix the BE state on hw_free
Message-ID<r6o8a-1Sy-17@gated-at.bofh.it>
In reply to#1344036
3.16.7-ckt25 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Vinod Koul <vinod.koul@intel.com>

commit 5e82d2be6ee53275c72e964507518d7964c82753 upstream.

While performing hw_free, DPCM checks the BE state but leaves out
the suspend state. The suspend state needs to be checked as well,
as we might be suspended and then usermode closes rather than
resuming the audio stream.

This was found by a stress testing of system with playback in
loop and killed after few seconds running in background and second
script running suspend-resume test in loop

Signed-off-by: Vinod Koul <vinod.koul@intel.com>
Acked-by: Liam Girdwood <liam.r.girdwood@linux.intel.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 sound/soc/soc-pcm.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/sound/soc/soc-pcm.c b/sound/soc/soc-pcm.c
index 61378f135075..9fa664de8580 100644
--- a/sound/soc/soc-pcm.c
+++ b/sound/soc/soc-pcm.c
@@ -1462,7 +1462,8 @@ int dpcm_be_dai_hw_free(struct snd_soc_pcm_runtime *fe, int stream)
 		    (be->dpcm[stream].state != SND_SOC_DPCM_STATE_PREPARE) &&
 		    (be->dpcm[stream].state != SND_SOC_DPCM_STATE_HW_FREE) &&
 		    (be->dpcm[stream].state != SND_SOC_DPCM_STATE_PAUSED) &&
-		    (be->dpcm[stream].state != SND_SOC_DPCM_STATE_STOP))
+		    (be->dpcm[stream].state != SND_SOC_DPCM_STATE_STOP) &&
+		    (be->dpcm[stream].state != SND_SOC_DPCM_STATE_SUSPEND))
 			continue;
 
 		dev_dbg(be->dev, "ASoC: hw_free BE %s\n",

[toc] | [prev] | [next] | [standalone]


Page 1 of 6  [1] 2 3 4 5 6  Next page →

Back to top | Article view | linux.kernel


csiph-web