Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1349975 > unrolled thread

[PATCH 3.12 000/116] 3.12.56-stable review

Started byJiri Slaby <jslaby@suse.cz>
First post2016-03-04 10:10 +0100
Last post2016-03-04 15:50 +0100
Articles 13 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.12 000/116] 3.12.56-stable review Jiri Slaby <jslaby@suse.cz> - 2016-03-04 10:10 +0100
    [PATCH 3.12 001/116] proc: Fix ptrace-based permission checks for accessing task maps Jiri Slaby <jslaby@suse.cz> - 2016-03-04 11:00 +0100
      [PATCH 3.12 016/116] bonding: Fix ARP monitor validation Jiri Slaby <jslaby@suse.cz> - 2016-03-04 11:00 +0100
      [PATCH 3.12 007/116] pptp: fix illegal memory access caused by multiple bind()s Jiri Slaby <jslaby@suse.cz> - 2016-03-04 11:00 +0100
      [PATCH 3.12 012/116] net:Add sysctl_max_skb_frags Jiri Slaby <jslaby@suse.cz> - 2016-03-04 11:00 +0100
      [PATCH 3.12 006/116] af_unix: fix struct pid memory leak Jiri Slaby <jslaby@suse.cz> - 2016-03-04 11:00 +0100
      [PATCH 3.12 008/116] sctp: allow setting SCTP_SACK_IMMEDIATELY by the application Jiri Slaby <jslaby@suse.cz> - 2016-03-04 11:00 +0100
      [PATCH 3.12 009/116] ipv6/udp: use sticky pktinfo egress ifindex on connect() Jiri Slaby <jslaby@suse.cz> - 2016-03-04 11:00 +0100
      [PATCH 3.12 011/116] ipv6: fix a lockdep splat Jiri Slaby <jslaby@suse.cz> - 2016-03-04 11:00 +0100
      [PATCH 3.12 015/116] bonding: fix bond_arp_rcv() race of curr_active_slave Jiri Slaby <jslaby@suse.cz> - 2016-03-04 11:00 +0100
    Re: [PATCH 3.12 000/116] 3.12.56-stable review Guenter Roeck <linux@roeck-us.net> - 2016-03-04 15:10 +0100
      Re: [PATCH 3.12 000/116] 3.12.56-stable review Jiri Slaby <jslaby@suse.cz> - 2016-03-08 16:50 +0100
    Re: [PATCH 3.12 000/116] 3.12.56-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-03-04 15:50 +0100

#1349975 — [PATCH 3.12 000/116] 3.12.56-stable review

FromJiri Slaby <jslaby@suse.cz>
Date2016-03-04 10:10 +0100
Subject[PATCH 3.12 000/116] 3.12.56-stable review
Message-ID<r8TUf-4rg-31@gated-at.bofh.it>
This is the start of the stable review cycle for the 3.12.56 release.
There are 116 patches in this series, all will be posted as a response
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Tue Mar  8 10:01:48 CET 2016.
Anything received after that time might be too late.

The whole patch series can be found in one patch at:
	http://kernel.org/pub/linux/kernel/people/jirislaby/stable-review/patch-3.12.56-rc1.xz
and the diffstat can be found below.

thanks,
js

===============


Adrian Hunter (1):
  mmc: sdhci: Fix sdhci_runtime_pm_bus_on/off()

Al Viro (2):
  bcache: fix a leak in bch_cached_dev_run()
  do_last(): don't let a bogus return value from ->open() et.al. to
    confuse us

Alex Deucher (3):
  drm/radeon: make rv770_set_sw_state failures non-fatal
  drm/radeon: clean up fujitsu quirks
  drm/radeon/pm: adjust display configuration after powerstate

Amir Vadai (1):
  net/mlx4_en: Count HW buffer overrun only once

Anand Jain (1):
  Btrfs: add missing brelse when superblock checksum fails

Andrey Ryabinin (1):
  lockd: create NSM handles per net namespace

Andrey Skvortsov (1):
  USB: option: add support for SIM7100E

Andy Shevchenko (1):
  dmaengine: dw: convert to __ffs()

Anton Protopopov (1):
  rtnl: RTM_GETNETCONF: fix wrong return value

Antonio Ospite (1):
  gspca: ov534/topro: prevent a division by 0

Benjamin Coddington (1):
  NFSv4: Fix a dentry leak on alias use

Bin Liu (1):
  usb: musb: cppi41: correct the macro name EP_MODE_AUTOREG_*

Bjørn Mork (2):
  qmi_wwan: add "4G LTE usb-modem U901"
  USB: option: add "4G LTE usb-modem U901"

Borislav Petkov (2):
  EDAC: Robustify workqueues destruction
  EDAC, mc_sysfs: Fix freeing bus' name

Christian Borntraeger (1):
  KVM: async_pf: do not warn on page allocation failures

Christoph Hellwig (1):
  nfs: fix nfs_size_to_loff_t

Christophe Leroy (1):
  splice: sendfile() at once fails for big files

Corey Wright (1):
  proc: Fix ptrace-based permission checks for accessing task maps

Dan Carpenter (1):
  devres: fix a for loop bounds check

Dmitry V. Levin (2):
  unix_diag: fix incorrect sign extension in unix_lookup_by_ino
  sparc64: fix incorrect sign extension in sys_sparc64_personality

Egbert Eich (1):
  drm/ast: Initialized data needed to map fbdev memory

Eric Dumazet (4):
  tcp: fix NULL deref in tcp_v4_send_ack()
  af_unix: fix struct pid memory leak
  ipv6: fix a lockdep splat
  ipv4: fix memory leaks in ip_cmsg_send() callers

Eugenia Emantayev (1):
  net/mlx4_en: Choose time-stamping shift value according to HW
    frequency

Filipe Manana (2):
  Btrfs: send, don't BUG_ON() when an empty symlink is found
  Btrfs: fix number of transaction units required to create symlink

Gerd Hoffmann (1):
  drm/qxl: use kmalloc_array to alloc reloc_info in
    qxl_process_single_command

Gerhard Uttenthaler (1):
  can: ems_usb: Fix possible tx overflow

Guillaume Nault (1):
  pppoe: fix reference counting in PPPoE proxy

Hangbin Liu (1):
  net/ipv6: add sysctl option accept_ra_min_hop_limit

Hannes Frederic Sowa (1):
  pptp: fix illegal memory access caused by multiple bind()s

Hannes Reinecke (1):
  bio: return EINTR if copying to user space got interrupted

Hans Westgaard Ry (1):
  net:Add sysctl_max_skb_frags

Hariprasad S (1):
  iw_cxgb3: Fix incorrectly returning error on success

Ilya Dryomov (1):
  libceph: don't bail early from try_read() when skipping a message

James Bottomley (2):
  ses: Fix problems with simple enclosures
  ses: fix additional element traversal bug

Jan Engelhardt (1):
  target: fix COMPARE_AND_WRITE non zero SGL offset data corruption

Jan Kara (1):
  vfs: Avoid softlockups with sendfile(2)

Jani Nikula (1):
  drm/i915/dp: fall back to 18 bpp when sink capability is unknown

Jay Vosburgh (1):
  bonding: Fix ARP monitor validation

Jeff Layton (1):
  locks: fix unlock when fcntl_setlk races with a close

Joe Thornber (3):
  dm thin metadata: fix bug when taking a metadata snapshot
  dm space map metadata: fix ref counting bug when bootstrapping a new
    space map
  dm btree: fix bufio buffer leaks in dm_btree_del() error path

Johannes Berg (3):
  mac80211: mesh: fix call_rcu() usage
  rfkill: copy the name into the rfkill struct
  rfkill: fix rfkill_fop_read wait_event usage

Josef Bacik (1):
  Btrfs: igrab inode in writepage

K. Y. Srinivasan (1):
  storvsc: Don't set the SRB_FLAGS_QUEUE_ACTION_ENABLE flag

Kees Cook (1):
  mac: validate mac_partition is within sector

Ken Lin (1):
  USB: cp210x: add IDs for GE B650V3 and B850V3 boards

Kirill A. Shutemov (1):
  vgaarb: fix signal handling in vga_get()

Konrad Rzeszutek Wilk (1):
  xen/pcifront: Fix mysterious crashes when NUMA locality information
    was extracted.

Linus Walleij (1):
  mmc: mmci: fix an ages old detection error

Luca Porzio (1):
  mmc: remove bondage between REQ_META and reliable write

Malcolm Priestley (1):
  media: dvb-core: Don't force CAN_INVERSION_AUTO in oneshot mode

Manfred Rudigier (1):
  net: dp83640: Fix tx timestamp overflow handling.

Manish Chopra (1):
  bnx2x: Don't notify about scratchpad parities

Marcelo Ricardo Leitner (1):
  sctp: allow setting SCTP_SACK_IMMEDIATELY by the application

Mauro Carvalho Chehab (1):
  tda1004x: only update the frontend properties if locked

Mike Marciniszyn (1):
  IB/qib: fix mcast detach when qp not attached

Mike Snitzer (1):
  dm space map metadata: remove unused variable in brb_pop()

Mikulas Patocka (2):
  sata_sil: disable trim
  dm snapshot: fix hung bios when copy error occurs

Neil Horman (1):
  sctp: Fix port hash table size computation

Nicholas Bellinger (1):
  target: Fix race for SCF_COMPARE_AND_WRITE_POST checking

Nicolai Hähnle (1):
  drm/radeon: hold reference to fences in radeon_sa_bo_new

Olga Kornievskaia (1):
  Failing to send a CLOSE if file is opened WRONLY and server reboots on
    a 4.x mount

Oliver Neukum (1):
  cdc-acm:exclude Samsung phone 04e8:685d

Paolo Abeni (1):
  ipv6/udp: use sticky pktinfo egress ifindex on connect()

Peter Rosin (1):
  hwmon: (ads1015) Handle negative conversion values correctly

Peter Zijlstra (5):
  sched: Clean up idle task SMP logic
  sched: Replace post_schedule with a balance callback list
  sched: Allow balance callbacks for check_class_changed()
  sched,rt: Remove return value from pull_rt_task()
  sched, rt: Convert switched_{from, to}_rt() / prio_changed_rt() to
    balance callbacks

Rainer Weikusat (1):
  af_unix: Guard against other == sk in unix_dgram_sendmsg

Rasmus Villemoes (1):
  drm/radeon: use post-decrement in error handling

Richard Cochran (1):
  posix-clock: Fix return code on the poll method's error path

Rob Clark (1):
  drm/vmwgfx: respect 'nomodeset'

Roman Volkov (2):
  dts: vt8500: Add SDHC node to DTS file for WM8650
  clocksource/drivers/vt8500: Increase the minimum delta

Russell King (1):
  scripts: recordmcount: break hardlinks

Sasha Levin (1):
  sched/core: Remove false-positive warning from wake_up_process()

Sebastian Andrzej Siewior (1):
  PCI/AER: Flush workqueue on device remove to avoid use-after-free

Simon Guinot (1):
  kernel/resource.c: fix muxed resource handling in __request_region()

Siva Reddy Kallam (1):
  tg3: Fix for tg3 transmit queue 0 timed out when too many gso_segs

Stefan Haberland (2):
  s390/dasd: prevent incorrect length error under z/VM after PAV changes
  s390/dasd: fix refcount for PAV reassignment

Stefan Hajnoczi (1):
  sunrpc/cache: fix off-by-one in qword_get()

Steven Rostedt (Red Hat) (3):
  tracepoints: Do not trace when cpu is offline
  ring-buffer: Update read stamp with first real commit on page
  tracing: Fix showing function event in available_events

Suman Anna (1):
  virtio: fix memory leak of virtio ida cache layers

Tejun Heo (1):
  libata: fix sff host state machine locking while polling

Thomas Gleixner (1):
  genirq: Prevent chip buslock deadlock

Ursula Braun (1):
  af_iucv: Validate socket address length in iucv_sock_bind()

Valentin Rothberg (1):
  wm831x_power: Use IRQF_ONESHOT to request threaded IRQs

Veaceslav Falico (1):
  bonding: fix bond_arp_rcv() race of curr_active_slave

Vegard Nossum (2):
  uml: flush stdout before forking
  uml: fix hostfs mknod()

Xin Long (2):
  sctp: translate network order to host order when users get a hmacid
  route: check and remove route cache when we get route

Xunlei Pang (1):
  sched/core: Clear the root_domain cpumasks in init_rootdomain()

Zheng Liu (1):
  bcache: unregister reboot notifier if bcache fails to unregister
    device

sumit.saxena@avagotech.com (2):
  megaraid_sas: Do not use PAGE_SIZE for max_sectors
  megaraid_sas : SMAP restriction--do not access user memory from IOCTL
    code

 Documentation/networking/ip-sysctl.txt             |  8 +++
 arch/arm/boot/dts/wm8650.dtsi                      |  9 +++
 arch/sparc/kernel/sys_sparc_64.c                   |  2 +-
 arch/um/os-Linux/start_up.c                        |  2 +
 block/partitions/mac.c                             | 10 ++-
 drivers/ata/libata-sff.c                           | 32 ++++-----
 drivers/ata/sata_sil.c                             |  3 +
 drivers/clocksource/vt8500_timer.c                 |  6 +-
 drivers/dma/dw/core.c                              | 12 ++--
 drivers/edac/edac_device.c                         |  9 +--
 drivers/edac/edac_mc.c                             | 14 +---
 drivers/edac/edac_mc_sysfs.c                       | 18 +++--
 drivers/edac/edac_pci.c                            |  9 ++-
 drivers/gpu/drm/ast/ast_drv.h                      |  1 +
 drivers/gpu/drm/ast/ast_fb.c                       |  7 ++
 drivers/gpu/drm/ast/ast_main.c                     |  1 +
 drivers/gpu/drm/ast/ast_mode.c                     |  2 +
 drivers/gpu/drm/i915/intel_display.c               | 20 ++++--
 drivers/gpu/drm/qxl/qxl_ioctl.c                    |  3 +-
 drivers/gpu/drm/radeon/radeon_atombios.c           | 12 +---
 drivers/gpu/drm/radeon/radeon_pm.c                 |  5 +-
 drivers/gpu/drm/radeon/radeon_sa.c                 |  5 ++
 drivers/gpu/drm/radeon/radeon_ttm.c                |  2 +-
 drivers/gpu/drm/radeon/rv770_dpm.c                 |  2 +-
 drivers/gpu/drm/vmwgfx/vmwgfx_drv.c                |  7 ++
 drivers/gpu/vga/vgaarb.c                           |  6 +-
 drivers/hwmon/ads1015.c                            |  2 +-
 drivers/infiniband/hw/cxgb3/iwch_cm.c              |  4 +-
 drivers/infiniband/hw/qib/qib_verbs_mcast.c        | 35 +++++-----
 drivers/md/bcache/super.c                          |  9 ++-
 drivers/md/dm-exception-store.h                    |  2 +-
 drivers/md/dm-snap-persistent.c                    |  5 +-
 drivers/md/dm-snap-transient.c                     |  4 +-
 drivers/md/dm-snap.c                               | 20 ++----
 drivers/md/dm-thin-metadata.c                      |  6 ++
 drivers/md/persistent-data/dm-btree.c              | 16 ++++-
 drivers/md/persistent-data/dm-space-map-metadata.c | 29 +++++---
 drivers/media/dvb-core/dvb_frontend.c              |  6 +-
 drivers/media/dvb-frontends/tda1004x.c             |  9 +++
 drivers/media/usb/gspca/ov534.c                    |  9 ++-
 drivers/media/usb/gspca/topro.c                    |  6 +-
 drivers/mmc/card/block.c                           | 11 +---
 drivers/mmc/host/mmci.c                            |  2 +-
 drivers/mmc/host/sdhci.c                           |  4 +-
 drivers/net/bonding/bond_main.c                    | 46 +++++++++----
 drivers/net/can/usb/ems_usb.c                      | 14 ++--
 drivers/net/ethernet/broadcom/bnx2x/bnx2x.h        | 11 ++--
 drivers/net/ethernet/broadcom/bnx2x/bnx2x_main.c   | 20 ++++--
 drivers/net/ethernet/broadcom/tg3.c                | 22 +++++--
 drivers/net/ethernet/mellanox/mlx4/en_clock.c      | 25 +++++--
 drivers/net/ethernet/mellanox/mlx4/en_port.c       |  4 +-
 drivers/net/phy/dp83640.c                          | 17 +++++
 drivers/net/ppp/pppoe.c                            |  2 +
 drivers/net/ppp/pptp.c                             | 34 +++++++---
 drivers/net/usb/qmi_wwan.c                         |  1 +
 drivers/pci/pcie/aer/aerdrv.c                      |  4 +-
 drivers/pci/pcie/aer/aerdrv.h                      |  1 -
 drivers/pci/pcie/aer/aerdrv_core.c                 |  2 -
 drivers/pci/xen-pcifront.c                         | 10 +--
 drivers/power/wm831x_power.c                       |  6 +-
 drivers/s390/block/dasd_alias.c                    | 23 +++++--
 drivers/scsi/megaraid/megaraid_sas.h               |  2 +
 drivers/scsi/megaraid/megaraid_sas_base.c          | 15 ++++-
 drivers/scsi/ses.c                                 | 30 ++++++++-
 drivers/scsi/storvsc_drv.c                         |  3 +-
 drivers/target/target_core_sbc.c                   | 17 +++--
 drivers/target/target_core_transport.c             | 14 ++--
 drivers/usb/class/cdc-acm.c                        |  5 ++
 drivers/usb/musb/musb_cppi41.c                     | 12 ++--
 drivers/usb/serial/cp210x.c                        |  2 +
 drivers/usb/serial/option.c                        |  9 +++
 drivers/virtio/virtio.c                            |  1 +
 fs/bio.c                                           | 12 ++--
 fs/btrfs/disk-io.c                                 |  1 +
 fs/btrfs/inode.c                                   | 21 +++++-
 fs/btrfs/send.c                                    | 16 ++++-
 fs/hostfs/hostfs_kern.c                            |  4 +-
 fs/lockd/host.c                                    |  7 +-
 fs/lockd/mon.c                                     | 36 ++++++----
 fs/lockd/netns.h                                   |  1 +
 fs/lockd/svc.c                                     |  1 +
 fs/lockd/svc4proc.c                                |  2 +-
 fs/lockd/svcproc.c                                 |  2 +-
 fs/locks.c                                         | 51 ++++++++------
 fs/namei.c                                         |  4 ++
 fs/nfs/nfs4proc.c                                  |  4 +-
 fs/nfs/nfs4state.c                                 |  2 +-
 fs/proc/task_mmu.c                                 |  4 +-
 fs/proc/task_nommu.c                               |  2 +-
 fs/splice.c                                        | 13 +++-
 include/linux/enclosure.h                          |  4 ++
 include/linux/ipv6.h                               |  1 +
 include/linux/lockd/lockd.h                        |  9 ++-
 include/linux/nfs_fs.h                             |  4 +-
 include/linux/skbuff.h                             |  1 +
 include/linux/tracepoint.h                         |  6 ++
 include/net/ip_fib.h                               |  1 +
 include/target/target_core_base.h                  |  2 +-
 include/uapi/linux/ipv6.h                          |  2 +
 kernel/irq/manage.c                                |  6 +-
 kernel/resource.c                                  |  5 +-
 kernel/sched/core.c                                | 67 ++++++++++++++-----
 kernel/sched/idle_task.c                           |  9 +--
 kernel/sched/rt.c                                  | 71 +++++++++++---------
 kernel/sched/sched.h                               | 19 +++++-
 kernel/time/posix-clock.c                          |  4 +-
 kernel/trace/ring_buffer.c                         | 12 ++--
 kernel/trace/trace_events.c                        |  3 +-
 lib/devres.c                                       |  2 +-
 net/ceph/messenger.c                               |  4 +-
 net/core/skbuff.c                                  |  2 +
 net/core/sysctl_net_core.c                         | 10 +++
 net/ipv4/devinet.c                                 |  2 +-
 net/ipv4/ip_sockglue.c                             |  2 +
 net/ipv4/ping.c                                    |  4 +-
 net/ipv4/raw.c                                     |  4 +-
 net/ipv4/route.c                                   | 77 ++++++++++++++++++----
 net/ipv4/tcp.c                                     |  4 +-
 net/ipv4/tcp_ipv4.c                                | 13 ++--
 net/ipv4/udp.c                                     |  4 +-
 net/ipv6/addrconf.c                                | 12 +++-
 net/ipv6/datagram.c                                |  3 +
 net/ipv6/ip6_flowlabel.c                           |  5 +-
 net/ipv6/ndisc.c                                   | 16 ++---
 net/iucv/af_iucv.c                                 |  3 +
 net/mac80211/mesh_pathtbl.c                        |  8 +--
 net/rfkill/core.c                                  | 22 ++-----
 net/sctp/protocol.c                                | 47 ++++++++++---
 net/sctp/socket.c                                  | 10 ++-
 net/sunrpc/cache.c                                 |  2 +-
 net/unix/af_unix.c                                 |  8 ++-
 net/unix/diag.c                                    |  2 +-
 scripts/recordmcount.c                             | 14 ++++
 virt/kvm/async_pf.c                                |  2 +-
 134 files changed, 971 insertions(+), 458 deletions(-)

-- 
2.7.2

[toc] | [next] | [standalone]


#1350104 — [PATCH 3.12 001/116] proc: Fix ptrace-based permission checks for accessing task maps

FromJiri Slaby <jslaby@suse.cz>
Date2016-03-04 11:00 +0100
Subject[PATCH 3.12 001/116] proc: Fix ptrace-based permission checks for accessing task maps
Message-ID<r8TUd-4rg-3@gated-at.bofh.it>
In reply to#1349975
From: Corey Wright <undefined@pobox.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

Modify mm_access() calls in fs/proc/task_mmu.c and fs/proc/task_nommu.c to
have the mode include PTRACE_MODE_FSCREDS so accessing /proc/pid/maps and
/proc/pid/pagemap is not denied to all users.

In backporting upstream commit caaee623 to pre-3.18 kernel versions it was
overlooked that mm_access() is used in fs/proc/task_*mmu.c as those calls
were removed in 3.18 (by upstream commit 29a40ace) and did not exist at the
time of the original commit.

Fixes: caaee6234d ("ptrace: use fsuid, fsgid, effective creds for fs access checks")
Signed-off-by: Corey Wright <undefined@pobox.com>
Acked-by: Jann Horn <jann@thejh.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 fs/proc/task_mmu.c   | 4 ++--
 fs/proc/task_nommu.c | 2 +-
 2 files changed, 3 insertions(+), 3 deletions(-)

diff --git a/fs/proc/task_mmu.c b/fs/proc/task_mmu.c
index d20f37d1c6e7..4fe8b1082cf3 100644
--- a/fs/proc/task_mmu.c
+++ b/fs/proc/task_mmu.c
@@ -172,7 +172,7 @@ static void *m_start(struct seq_file *m, loff_t *pos)
 	if (!priv->task)
 		return ERR_PTR(-ESRCH);
 
-	mm = mm_access(priv->task, PTRACE_MODE_READ);
+	mm = mm_access(priv->task, PTRACE_MODE_READ_FSCREDS);
 	if (!mm || IS_ERR(mm))
 		return mm;
 	down_read(&mm->mmap_sem);
@@ -1186,7 +1186,7 @@ static ssize_t pagemap_read(struct file *file, char __user *buf,
 	if (!pm.buffer)
 		goto out_task;
 
-	mm = mm_access(task, PTRACE_MODE_READ);
+	mm = mm_access(task, PTRACE_MODE_READ_FSCREDS);
 	ret = PTR_ERR(mm);
 	if (!mm || IS_ERR(mm))
 		goto out_free;
diff --git a/fs/proc/task_nommu.c b/fs/proc/task_nommu.c
index 56123a6f462e..123c19890b14 100644
--- a/fs/proc/task_nommu.c
+++ b/fs/proc/task_nommu.c
@@ -223,7 +223,7 @@ static void *m_start(struct seq_file *m, loff_t *pos)
 	if (!priv->task)
 		return ERR_PTR(-ESRCH);
 
-	mm = mm_access(priv->task, PTRACE_MODE_READ);
+	mm = mm_access(priv->task, PTRACE_MODE_READ_FSCREDS);
 	if (!mm || IS_ERR(mm)) {
 		put_task_struct(priv->task);
 		priv->task = NULL;
-- 
2.7.2

[toc] | [prev] | [next] | [standalone]


#1350105 — [PATCH 3.12 016/116] bonding: Fix ARP monitor validation

FromJiri Slaby <jslaby@suse.cz>
Date2016-03-04 11:00 +0100
Subject[PATCH 3.12 016/116] bonding: Fix ARP monitor validation
Message-ID<r8UGD-4LF-5@gated-at.bofh.it>
In reply to#1350104
From: Jay Vosburgh <jay.vosburgh@canonical.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 21a75f0915dde8674708b39abfcda113911c49b1 ]

The current logic in bond_arp_rcv will accept an incoming ARP for
validation if (a) the receiving slave is either "active" (which includes
the currently active slave, or the current ARP slave) or, (b) there is a
currently active slave, and it has received an ARP since it became active.
For case (b), the receiving slave isn't the currently active slave, and is
receiving the original broadcast ARP request, not an ARP reply from the
target.

	This logic can fail if there is no currently active slave.  In
this situation, the ARP probe logic cycles through all slaves, assigning
each in turn as the "current_arp_slave" for one arp_interval, then setting
that one as "active," and sending an ARP probe from that slave.  The
current logic expects the ARP reply to arrive on the sending
current_arp_slave, however, due to switch FDB updating delays, the reply
may be directed to another slave.

	This can arise if the bonding slaves and switch are working, but
the ARP target is not responding.  When the ARP target recovers, a
condition may result wherein the ARP target host replies faster than the
switch can update its forwarding table, causing each ARP reply to be sent
to the previous current_arp_slave.  This will never pass the logic in
bond_arp_rcv, as neither of the above conditions (a) or (b) are met.

	Some experimentation on a LAN shows ARP reply round trips in the
200 usec range, but my available switches never update their FDB in less
than 4000 usec.

	This patch changes the logic in bond_arp_rcv to additionally
accept an ARP reply for validation on any slave if there is a current ARP
slave and it sent an ARP probe during the previous arp_interval.

Fixes: aeea64ac717a ("bonding: don't trust arp requests unless active slave really works")
Cc: Veaceslav Falico <vfalico@gmail.com>
Cc: Andy Gospodarek <gospo@cumulusnetworks.com>
Signed-off-by: Jay Vosburgh <jay.vosburgh@canonical.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/net/bonding/bond_main.c | 40 ++++++++++++++++++++++++++++------------
 1 file changed, 28 insertions(+), 12 deletions(-)

diff --git a/drivers/net/bonding/bond_main.c b/drivers/net/bonding/bond_main.c
index 282d416559dc..5dcac318e317 100644
--- a/drivers/net/bonding/bond_main.c
+++ b/drivers/net/bonding/bond_main.c
@@ -259,6 +259,8 @@ struct bond_parm_tbl ad_select_tbl[] = {
 
 static int bond_init(struct net_device *bond_dev);
 static void bond_uninit(struct net_device *bond_dev);
+static bool bond_time_in_interval(struct bonding *bond, unsigned long last_act,
+				  int mod);
 
 /*---------------------------- General routines -----------------------------*/
 
@@ -2435,7 +2437,7 @@ int bond_arp_rcv(const struct sk_buff *skb, struct bonding *bond,
 		 struct slave *slave)
 {
 	struct arphdr *arp = (struct arphdr *)skb->data;
-	struct slave *curr_active_slave;
+	struct slave *curr_active_slave, *curr_arp_slave;
 	unsigned char *arp_ptr;
 	__be32 sip, tip;
 	int alen;
@@ -2481,27 +2483,41 @@ int bond_arp_rcv(const struct sk_buff *skb, struct bonding *bond,
 		 &sip, &tip);
 
 	curr_active_slave = rcu_dereference(bond->curr_active_slave);
+	curr_arp_slave = rcu_dereference(bond->current_arp_slave);
 
-	/*
-	 * Backup slaves won't see the ARP reply, but do come through
-	 * here for each ARP probe (so we swap the sip/tip to validate
-	 * the probe).  In a "redundant switch, common router" type of
-	 * configuration, the ARP probe will (hopefully) travel from
-	 * the active, through one switch, the router, then the other
-	 * switch before reaching the backup.
+	/* We 'trust' the received ARP enough to validate it if:
+	 *
+	 * (a) the slave receiving the ARP is active (which includes the
+	 * current ARP slave, if any), or
+	 *
+	 * (b) the receiving slave isn't active, but there is a currently
+	 * active slave and it received valid arp reply(s) after it became
+	 * the currently active slave, or
 	 *
-	 * We 'trust' the arp requests if there is an active slave and
-	 * it received valid arp reply(s) after it became active. This
-	 * is done to avoid endless looping when we can't reach the
+	 * (c) there is an ARP slave that sent an ARP during the prior ARP
+	 * interval, and we receive an ARP reply on any slave.  We accept
+	 * these because switch FDB update delays may deliver the ARP
+	 * reply to a slave other than the sender of the ARP request.
+	 *
+	 * Note: for (b), backup slaves are receiving the broadcast ARP
+	 * request, not a reply.  This request passes from the sending
+	 * slave through the L2 switch(es) to the receiving slave.  Since
+	 * this is checking the request, sip/tip are swapped for
+	 * validation.
+	 *
+	 * This is done to avoid endless looping when we can't reach the
 	 * arp_ip_target and fool ourselves with our own arp requests.
 	 */
-
 	if (bond_is_active_slave(slave))
 		bond_validate_arp(bond, slave, sip, tip);
 	else if (curr_active_slave &&
 		 time_after(slave_last_rx(bond, curr_active_slave),
 			    curr_active_slave->jiffies))
 		bond_validate_arp(bond, slave, tip, sip);
+	else if (curr_arp_slave && (arp->ar_op == htons(ARPOP_REPLY)) &&
+		 bond_time_in_interval(bond,
+				       dev_trans_start(curr_arp_slave->dev), 1))
+		bond_validate_arp(bond, slave, sip, tip);
 
 out_unlock:
 	read_unlock(&bond->lock);
-- 
2.7.2

[toc] | [prev] | [next] | [standalone]


#1350106 — [PATCH 3.12 007/116] pptp: fix illegal memory access caused by multiple bind()s

FromJiri Slaby <jslaby@suse.cz>
Date2016-03-04 11:00 +0100
Subject[PATCH 3.12 007/116] pptp: fix illegal memory access caused by multiple bind()s
Message-ID<r8UGD-4LF-7@gated-at.bofh.it>
In reply to#1350104
From: Hannes Frederic Sowa <hannes@stressinduktion.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 9a368aff9cb370298fa02feeffa861f2db497c18 ]

Several times already this has been reported as kasan reports caused by
syzkaller and trinity and people always looked at RCU races, but it is
much more simple. :)

In case we bind a pptp socket multiple times, we simply add it to
the callid_sock list but don't remove the old binding. Thus the old
socket stays in the bucket with unused call_id indexes and doesn't get
cleaned up. This causes various forms of kasan reports which were hard
to pinpoint.

Simply don't allow multiple binds and correct error handling in
pptp_bind. Also keep sk_state bits in place in pptp_connect.

Fixes: 00959ade36acad ("PPTP: PPP over IPv4 (Point-to-Point Tunneling Protocol)")
Cc: Dmitry Kozlov <xeb@mail.ru>
Cc: Sasha Levin <sasha.levin@oracle.com>
Cc: Dmitry Vyukov <dvyukov@google.com>
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Cc: Dave Jones <davej@codemonkey.org.uk>
Reported-by: Dave Jones <davej@codemonkey.org.uk>
Signed-off-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/net/ppp/pptp.c | 34 ++++++++++++++++++++++++----------
 1 file changed, 24 insertions(+), 10 deletions(-)

diff --git a/drivers/net/ppp/pptp.c b/drivers/net/ppp/pptp.c
index 0710214df2bf..bb1ab1ffbc8b 100644
--- a/drivers/net/ppp/pptp.c
+++ b/drivers/net/ppp/pptp.c
@@ -131,24 +131,27 @@ static int lookup_chan_dst(u16 call_id, __be32 d_addr)
 	return i < MAX_CALLID;
 }
 
-static int add_chan(struct pppox_sock *sock)
+static int add_chan(struct pppox_sock *sock,
+		    struct pptp_addr *sa)
 {
 	static int call_id;
 
 	spin_lock(&chan_lock);
-	if (!sock->proto.pptp.src_addr.call_id)	{
+	if (!sa->call_id)	{
 		call_id = find_next_zero_bit(callid_bitmap, MAX_CALLID, call_id + 1);
 		if (call_id == MAX_CALLID) {
 			call_id = find_next_zero_bit(callid_bitmap, MAX_CALLID, 1);
 			if (call_id == MAX_CALLID)
 				goto out_err;
 		}
-		sock->proto.pptp.src_addr.call_id = call_id;
-	} else if (test_bit(sock->proto.pptp.src_addr.call_id, callid_bitmap))
+		sa->call_id = call_id;
+	} else if (test_bit(sa->call_id, callid_bitmap)) {
 		goto out_err;
+	}
 
-	set_bit(sock->proto.pptp.src_addr.call_id, callid_bitmap);
-	rcu_assign_pointer(callid_sock[sock->proto.pptp.src_addr.call_id], sock);
+	sock->proto.pptp.src_addr = *sa;
+	set_bit(sa->call_id, callid_bitmap);
+	rcu_assign_pointer(callid_sock[sa->call_id], sock);
 	spin_unlock(&chan_lock);
 
 	return 0;
@@ -417,7 +420,6 @@ static int pptp_bind(struct socket *sock, struct sockaddr *uservaddr,
 	struct sock *sk = sock->sk;
 	struct sockaddr_pppox *sp = (struct sockaddr_pppox *) uservaddr;
 	struct pppox_sock *po = pppox_sk(sk);
-	struct pptp_opt *opt = &po->proto.pptp;
 	int error = 0;
 
 	if (sockaddr_len < sizeof(struct sockaddr_pppox))
@@ -425,10 +427,22 @@ static int pptp_bind(struct socket *sock, struct sockaddr *uservaddr,
 
 	lock_sock(sk);
 
-	opt->src_addr = sp->sa_addr.pptp;
-	if (add_chan(po))
+	if (sk->sk_state & PPPOX_DEAD) {
+		error = -EALREADY;
+		goto out;
+	}
+
+	if (sk->sk_state & PPPOX_BOUND) {
 		error = -EBUSY;
+		goto out;
+	}
+
+	if (add_chan(po, &sp->sa_addr.pptp))
+		error = -EBUSY;
+	else
+		sk->sk_state |= PPPOX_BOUND;
 
+out:
 	release_sock(sk);
 	return error;
 }
@@ -499,7 +513,7 @@ static int pptp_connect(struct socket *sock, struct sockaddr *uservaddr,
 	}
 
 	opt->dst_addr = sp->sa_addr.pptp;
-	sk->sk_state = PPPOX_CONNECTED;
+	sk->sk_state |= PPPOX_CONNECTED;
 
  end:
 	release_sock(sk);
-- 
2.7.2

[toc] | [prev] | [next] | [standalone]


#1350107 — [PATCH 3.12 012/116] net:Add sysctl_max_skb_frags

FromJiri Slaby <jslaby@suse.cz>
Date2016-03-04 11:00 +0100
Subject[PATCH 3.12 012/116] net:Add sysctl_max_skb_frags
Message-ID<r8UGD-4LF-9@gated-at.bofh.it>
In reply to#1350104
From: Hans Westgaard Ry <hans.westgaard.ry@oracle.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 5f74f82ea34c0da80ea0b49192bb5ea06e063593 ]

Devices may have limits on the number of fragments in an skb they support.
Current codebase uses a constant as maximum for number of fragments one
skb can hold and use.
When enabling scatter/gather and running traffic with many small messages
the codebase uses the maximum number of fragments and may thereby violate
the max for certain devices.
The patch introduces a global variable as max number of fragments.

Signed-off-by: Hans Westgaard Ry <hans.westgaard.ry@oracle.com>
Reviewed-by: Håkon Bugge <haakon.bugge@oracle.com>
Acked-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 include/linux/skbuff.h     |  1 +
 net/core/skbuff.c          |  2 ++
 net/core/sysctl_net_core.c | 10 ++++++++++
 net/ipv4/tcp.c             |  4 ++--
 4 files changed, 15 insertions(+), 2 deletions(-)

diff --git a/include/linux/skbuff.h b/include/linux/skbuff.h
index 16e753a9922a..e492ab7aadbf 100644
--- a/include/linux/skbuff.h
+++ b/include/linux/skbuff.h
@@ -149,6 +149,7 @@ struct sk_buff;
 #else
 #define MAX_SKB_FRAGS (65536/PAGE_SIZE + 1)
 #endif
+extern int sysctl_max_skb_frags;
 
 typedef struct skb_frag_struct skb_frag_t;
 
diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 56cdf3bb1e7f..7df6f539a402 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -76,6 +76,8 @@
 
 struct kmem_cache *skbuff_head_cache __read_mostly;
 static struct kmem_cache *skbuff_fclone_cache __read_mostly;
+int sysctl_max_skb_frags __read_mostly = MAX_SKB_FRAGS;
+EXPORT_SYMBOL(sysctl_max_skb_frags);
 
 /**
  *	skb_panic - private function for out-of-line support
diff --git a/net/core/sysctl_net_core.c b/net/core/sysctl_net_core.c
index f3413ae3d973..d7962397d90f 100644
--- a/net/core/sysctl_net_core.c
+++ b/net/core/sysctl_net_core.c
@@ -27,6 +27,7 @@ static int one = 1;
 static int ushort_max = USHRT_MAX;
 static int min_sndbuf = SOCK_MIN_SNDBUF;
 static int min_rcvbuf = SOCK_MIN_RCVBUF;
+static int max_skb_frags = MAX_SKB_FRAGS;
 
 #ifdef CONFIG_RPS
 static int rps_sock_flow_sysctl(struct ctl_table *table, int write,
@@ -362,6 +363,15 @@ static struct ctl_table net_core_table[] = {
 		.mode		= 0644,
 		.proc_handler	= proc_dointvec
 	},
+	{
+		.procname	= "max_skb_frags",
+		.data		= &sysctl_max_skb_frags,
+		.maxlen		= sizeof(int),
+		.mode		= 0644,
+		.proc_handler	= proc_dointvec_minmax,
+		.extra1		= &one,
+		.extra2		= &max_skb_frags,
+	},
 	{ }
 };
 
diff --git a/net/ipv4/tcp.c b/net/ipv4/tcp.c
index a880ccc10f61..392d3259f9ad 100644
--- a/net/ipv4/tcp.c
+++ b/net/ipv4/tcp.c
@@ -886,7 +886,7 @@ new_segment:
 
 		i = skb_shinfo(skb)->nr_frags;
 		can_coalesce = skb_can_coalesce(skb, i, page, offset);
-		if (!can_coalesce && i >= MAX_SKB_FRAGS) {
+		if (!can_coalesce && i >= sysctl_max_skb_frags) {
 			tcp_mark_push(tp, skb);
 			goto new_segment;
 		}
@@ -1169,7 +1169,7 @@ new_segment:
 
 				if (!skb_can_coalesce(skb, i, pfrag->page,
 						      pfrag->offset)) {
-					if (i == MAX_SKB_FRAGS || !sg) {
+					if (i == sysctl_max_skb_frags || !sg) {
 						tcp_mark_push(tp, skb);
 						goto new_segment;
 					}
-- 
2.7.2

[toc] | [prev] | [next] | [standalone]


#1350108 — [PATCH 3.12 006/116] af_unix: fix struct pid memory leak

FromJiri Slaby <jslaby@suse.cz>
Date2016-03-04 11:00 +0100
Subject[PATCH 3.12 006/116] af_unix: fix struct pid memory leak
Message-ID<r8UGD-4LF-11@gated-at.bofh.it>
In reply to#1350104
From: Eric Dumazet <edumazet@google.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit fa0dc04df259ba2df3ce1920e9690c7842f8fa4b ]

Dmitry reported a struct pid leak detected by a syzkaller program.

Bug happens in unix_stream_recvmsg() when we break the loop when a
signal is pending, without properly releasing scm.

Fixes: b3ca9b02b007 ("net: fix multithreaded signal handling in unix recv routines")
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Rainer Weikusat <rweikusat@mobileactivedefense.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 net/unix/af_unix.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
index 31b88dcb0f01..5fb2d2af3e52 100644
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -2131,6 +2131,7 @@ again:
 
 			if (signal_pending(current)) {
 				err = sock_intr_errno(timeo);
+				scm_destroy(siocb->scm);
 				goto out;
 			}
 
-- 
2.7.2

[toc] | [prev] | [next] | [standalone]


#1350109 — [PATCH 3.12 008/116] sctp: allow setting SCTP_SACK_IMMEDIATELY by the application

FromJiri Slaby <jslaby@suse.cz>
Date2016-03-04 11:00 +0100
Subject[PATCH 3.12 008/116] sctp: allow setting SCTP_SACK_IMMEDIATELY by the application
Message-ID<r8UGD-4LF-13@gated-at.bofh.it>
In reply to#1350104
From: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 27f7ed2b11d42ab6d796e96533c2076ec220affc ]

This patch extends commit b93d6471748d ("sctp: implement the sender side
for SACK-IMMEDIATELY extension") as it didn't white list
SCTP_SACK_IMMEDIATELY on sctp_msghdr_parse(), causing it to be
understood as an invalid flag and returning -EINVAL to the application.

Note that the actual handling of the flag is already there in
sctp_datamsg_from_user().

https://tools.ietf.org/html/rfc7053#section-7

Fixes: b93d6471748d ("sctp: implement the sender side for SACK-IMMEDIATELY extension")
Signed-off-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Acked-by: Vlad Yasevich <vyasevich@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 net/sctp/socket.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/net/sctp/socket.c b/net/sctp/socket.c
index 9c47fbc5de0c..92de688a966f 100644
--- a/net/sctp/socket.c
+++ b/net/sctp/socket.c
@@ -6420,6 +6420,7 @@ static int sctp_msghdr_parse(const struct msghdr *msg, sctp_cmsgs_t *cmsgs)
 			/* Minimally, validate the sinfo_flags. */
 			if (cmsgs->info->sinfo_flags &
 			    ~(SCTP_UNORDERED | SCTP_ADDR_OVER |
+			      SCTP_SACK_IMMEDIATELY |
 			      SCTP_ABORT | SCTP_EOF))
 				return -EINVAL;
 			break;
-- 
2.7.2

[toc] | [prev] | [next] | [standalone]


#1350110 — [PATCH 3.12 009/116] ipv6/udp: use sticky pktinfo egress ifindex on connect()

FromJiri Slaby <jslaby@suse.cz>
Date2016-03-04 11:00 +0100
Subject[PATCH 3.12 009/116] ipv6/udp: use sticky pktinfo egress ifindex on connect()
Message-ID<r8UGD-4LF-15@gated-at.bofh.it>
In reply to#1350104
From: Paolo Abeni <pabeni@redhat.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 1cdda91871470f15e79375991bd2eddc6e86ddb1 ]

Currently, the egress interface index specified via IPV6_PKTINFO
is ignored by __ip6_datagram_connect(), so that RFC 3542 section 6.7
can be subverted when the user space application calls connect()
before sendmsg().
Fix it by initializing properly flowi6_oif in connect() before
performing the route lookup.

Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 net/ipv6/datagram.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/net/ipv6/datagram.c b/net/ipv6/datagram.c
index e24fa8c01dd2..fcfa2885df0e 100644
--- a/net/ipv6/datagram.c
+++ b/net/ipv6/datagram.c
@@ -163,6 +163,9 @@ ipv4_connected:
 	fl6.fl6_dport = inet->inet_dport;
 	fl6.fl6_sport = inet->inet_sport;
 
+	if (!fl6.flowi6_oif)
+		fl6.flowi6_oif = np->sticky_pktinfo.ipi6_ifindex;
+
 	if (!fl6.flowi6_oif && (addr_type&IPV6_ADDR_MULTICAST))
 		fl6.flowi6_oif = np->mcast_oif;
 
-- 
2.7.2

[toc] | [prev] | [next] | [standalone]


#1350112 — [PATCH 3.12 011/116] ipv6: fix a lockdep splat

FromJiri Slaby <jslaby@suse.cz>
Date2016-03-04 11:00 +0100
Subject[PATCH 3.12 011/116] ipv6: fix a lockdep splat
Message-ID<r8UGD-4LF-19@gated-at.bofh.it>
In reply to#1350104
From: Eric Dumazet <edumazet@google.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 44c3d0c1c0a880354e9de5d94175742e2c7c9683 ]

Silence lockdep false positive about rcu_dereference() being
used in the wrong context.

First one should use rcu_dereference_protected() as we own the spinlock.

Second one should be a normal assignation, as no barrier is needed.

Fixes: 18367681a10bd ("ipv6 flowlabel: Convert np->ipv6_fl_list to RCU.")
Reported-by: Dave Jones <davej@codemonkey.org.uk>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 net/ipv6/ip6_flowlabel.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/net/ipv6/ip6_flowlabel.c b/net/ipv6/ip6_flowlabel.c
index f0ccdb787100..d14c74b2dfa3 100644
--- a/net/ipv6/ip6_flowlabel.c
+++ b/net/ipv6/ip6_flowlabel.c
@@ -527,12 +527,13 @@ int ipv6_flowlabel_opt(struct sock *sk, char __user *optval, int optlen)
 	case IPV6_FL_A_PUT:
 		spin_lock_bh(&ip6_sk_fl_lock);
 		for (sflp = &np->ipv6_fl_list;
-		     (sfl = rcu_dereference(*sflp))!=NULL;
+		     (sfl = rcu_dereference_protected(*sflp,
+						      lockdep_is_held(&ip6_sk_fl_lock))) != NULL;
 		     sflp = &sfl->next) {
 			if (sfl->fl->label == freq.flr_label) {
 				if (freq.flr_label == (np->flow_label&IPV6_FLOWLABEL_MASK))
 					np->flow_label &= ~IPV6_FLOWLABEL_MASK;
-				*sflp = rcu_dereference(sfl->next);
+				*sflp = sfl->next;
 				spin_unlock_bh(&ip6_sk_fl_lock);
 				fl_release(sfl->fl);
 				kfree_rcu(sfl, rcu);
-- 
2.7.2

[toc] | [prev] | [next] | [standalone]


#1350113 — [PATCH 3.12 015/116] bonding: fix bond_arp_rcv() race of curr_active_slave

FromJiri Slaby <jslaby@suse.cz>
Date2016-03-04 11:00 +0100
Subject[PATCH 3.12 015/116] bonding: fix bond_arp_rcv() race of curr_active_slave
Message-ID<r8UGE-4LF-27@gated-at.bofh.it>
In reply to#1350104
From: Veaceslav Falico <vfalico@redhat.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 010d3c3989706d800ae72253773fa6537cc9f74c upstream.

bond->curr_active_slave can be changed between its deferences, even to
NULL, and thus we might panic.

We're always holding the rcu (rx_handler->bond_handle_frame()->bond_arp_rcv())
so fix this by rcu_dereferencing() it and using the saved.

Reported-by: Ding Tianhong <dingtianhong@huawei.com>
Fixes: aeea64a ("bonding: don't trust arp requests unless active slave really works")
CC: Jay Vosburgh <fubar@us.ibm.com>
CC: Andy Gospodarek <andy@greyhouse.net>
Signed-off-by: Veaceslav Falico <vfalico@redhat.com>
Acked-by: Ding Tianhong <dingtianhong@huawei.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/net/bonding/bond_main.c | 10 +++++++---
 1 file changed, 7 insertions(+), 3 deletions(-)

diff --git a/drivers/net/bonding/bond_main.c b/drivers/net/bonding/bond_main.c
index b3892b0d2e61..282d416559dc 100644
--- a/drivers/net/bonding/bond_main.c
+++ b/drivers/net/bonding/bond_main.c
@@ -2435,6 +2435,7 @@ int bond_arp_rcv(const struct sk_buff *skb, struct bonding *bond,
 		 struct slave *slave)
 {
 	struct arphdr *arp = (struct arphdr *)skb->data;
+	struct slave *curr_active_slave;
 	unsigned char *arp_ptr;
 	__be32 sip, tip;
 	int alen;
@@ -2479,6 +2480,8 @@ int bond_arp_rcv(const struct sk_buff *skb, struct bonding *bond,
 		 bond->params.arp_validate, slave_do_arp_validate(bond, slave),
 		 &sip, &tip);
 
+	curr_active_slave = rcu_dereference(bond->curr_active_slave);
+
 	/*
 	 * Backup slaves won't see the ARP reply, but do come through
 	 * here for each ARP probe (so we swap the sip/tip to validate
@@ -2492,11 +2495,12 @@ int bond_arp_rcv(const struct sk_buff *skb, struct bonding *bond,
 	 * is done to avoid endless looping when we can't reach the
 	 * arp_ip_target and fool ourselves with our own arp requests.
 	 */
+
 	if (bond_is_active_slave(slave))
 		bond_validate_arp(bond, slave, sip, tip);
-	else if (bond->curr_active_slave &&
-		 time_after(slave_last_rx(bond, bond->curr_active_slave),
-			    bond->curr_active_slave->jiffies))
+	else if (curr_active_slave &&
+		 time_after(slave_last_rx(bond, curr_active_slave),
+			    curr_active_slave->jiffies))
 		bond_validate_arp(bond, slave, tip, sip);
 
 out_unlock:
-- 
2.7.2

[toc] | [prev] | [next] | [standalone]


#1350250

FromGuenter Roeck <linux@roeck-us.net>
Date2016-03-04 15:10 +0100
Message-ID<r8YAy-7Tq-7@gated-at.bofh.it>
In reply to#1349975
On 03/04/2016 01:02 AM, Jiri Slaby wrote:
> This is the start of the stable review cycle for the 3.12.56 release.
> There are 116 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Tue Mar  8 10:01:48 CET 2016.
> Anything received after that time might be too late.
>

Build results:
	total: 124 pass: 124 fail: 0
Qemu test results:
	total: 79 pass: 79 fail: 0

Details are available at http://kerneltests.org/builders.

Thanks,
Guenter

[toc] | [prev] | [next] | [standalone]


#1353159

FromJiri Slaby <jslaby@suse.cz>
Date2016-03-08 16:50 +0100
Message-ID<ras3w-2Le-19@gated-at.bofh.it>
In reply to#1350250
On 03/04/2016, 03:02 PM, Guenter Roeck wrote:
> On 03/04/2016 01:02 AM, Jiri Slaby wrote:
>> This is the start of the stable review cycle for the 3.12.56 release.
>> There are 116 patches in this series, all will be posted as a response
>> to this one.  If anyone has any issues with these being applied, please
>> let me know.
>>
>> Responses should be made by Tue Mar  8 10:01:48 CET 2016.
>> Anything received after that time might be too late.
>>
> 
> Build results:
>     total: 124 pass: 124 fail: 0
> Qemu test results:
>     total: 79 pass: 79 fail: 0

On 03/04/2016, 03:47 PM, Shuah Khan wrote:
> Compiled and booted on my test system. No dmesg regressions.

Thank you both!

-- 
js
suse labs

[toc] | [prev] | [next] | [standalone]


#1350260

FromShuah Khan <shuahkh@osg.samsung.com>
Date2016-03-04 15:50 +0100
Message-ID<r8Zdf-89n-1@gated-at.bofh.it>
In reply to#1349975
On 03/04/2016 02:02 AM, Jiri Slaby wrote:
> This is the start of the stable review cycle for the 3.12.56 release.
> There are 116 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Tue Mar  8 10:01:48 CET 2016.
> Anything received after that time might be too late.
> 
> The whole patch series can be found in one patch at:
> 	http://kernel.org/pub/linux/kernel/people/jirislaby/stable-review/patch-3.12.56-rc1.xz
> and the diffstat can be found below.
> 

Compiled and booted on my test system. No dmesg regressions.

thanks,
-- Shuah


-- 
Shuah Khan
Sr. Linux Kernel Developer
Open Source Innovation Group
Samsung Research America (Silicon Valley)
shuahkh@osg.samsung.com | (970) 217-8978

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web