Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1413978 > unrolled thread
| Started by | Willy Tarreau <w@1wt.eu> |
|---|---|
| First post | 2016-06-05 12:30 +0200 |
| Last post | 2016-06-08 07:30 +0200 |
| Articles | 20 on this page of 135 — 2 participants |
Back to article view | Back to linux.kernel
[PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 049/143] Input: ati_remote2 - fix crashes on detecting device with invalid descriptor Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 036/143] splice: handle zero nr_pages in splice_to_pipe() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 124/143] packet: fix heap info leak in PACKET_DIAG_MCLIST sock_diag interface Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 038/143] xtensa: clear all DBREAKC registers on start Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 016/143] be2iscsi: set the boot_kset pointer to NULL in case of failure Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 123/143] route: do not cache fib route info on local routes with oif Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 077/143] ext4: add lockdep annotations for i_data_sem Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 048/143] Input: ims-pcu - sanity check against missing interfaces Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 113/143] USB: serial: cp210x: add ID for Link ECU Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 046/143] tracing: Fix trace_printk() to print when not using bprintk() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 076/143] usb: renesas_usbhs: disable TX IRQ before starting TX DMAC transfer Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 106/143] clk: versatile: sp810: support reentrance Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 143/143] serial: samsung: Reorder the sequence of clock control when call s3c24xx_serial_set_termios() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 134/143] mfd: omap-usb-tll: Fix scheduling while atomic BUG Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 133/143] ring-buffer: Prevent overflow of size in ring_buffer_resize() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 061/143] ipv6: re-enable fragment header matching in ipv6_find_hdr Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 132/143] ring-buffer: Use long for nr_pages to avoid overflow failures Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 086/143] nl80211: check netlink protocol in socket release notification Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 006/143] KVM: i8254: change PIT discard tick policy Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 090/143] ASoC: s3c24xx: use const snd_soc_component_driver pointer Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 012/143] x86, processor-flags: Fix the datatypes and add bit number defines Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 085/143] crypto: gcm - Fix rfc4543 decryption crash Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 024/143] USB: serial: cp210x: Adding GE Healthcare Device ID Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 107/143] lpfc: fix misleading indentation Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 035/143] watchdog: rc32434_wdt: fix ioctl error handling Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 020/143] USB: usb_driver_claim_interface: add sanity checking Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 141/143] USB: serial: option: add support for Cinterion PH8 and AHxx Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 102/143] ARM: OMAP3: Add cpuidle parameters table for omap3430 Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 074/143] ip6_tunnel: set rtnl_link_ops before calling register_netdevice Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 008/143] EDAC, amd64_edac: Shift wrapping issue in f1x_get_norm_dct_addr() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 028/143] net: irda: Fix use-after-free in irtty_open() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 064/143] udp6: fix UDP/IPv6 encap resubmit path Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 073/143] ipv6: l2tp: fix a potential issue in l2tp_ip6_recv Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 025/143] USB: option: add "D-Link DWM-221 B1" device id Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 138/143] USB: serial: keyspan: fix use-after-free in probe error path Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 027/143] Input: powermate - fix oops with malicious USB descriptors Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 087/143] Input: gtco - fix crash on detecting device without endpoints Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 080/143] [media] usbvision-video: fix memory leak of alt_max_pkt_size Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 122/143] decnet: Do not build routes to devices without decnet private data. Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 088/143] i2c: cpm: Fix build break due to incompatible pointer types Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 007/143] KVM: fix spin_lock_init order on x86 Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 098/143] drivers/misc/ad525x_dpot: AD5274 fix RDAC read back errors Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 116/143] powerpc: scan_features() updates incorrect bits for REAL_LE Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 051/143] ocfs2/dlm: fix BUG in dlm_move_lockres_to_recovery_list Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 063/143] usbnet: cleanup after bind() in probe() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 112/143] ACPICA: Dispatcher: Update thread ID for recursive method calls Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 083/143] usb: xhci: fix wild pointers in xhci_mem_cleanup Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 011/143] x86: Rename X86_CR4_RDWRGSFS to X86_CR4_FSGSBASE Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 053/143] sched/cputime: Fix steal time accounting vs. CPU hotplug Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 014/143] sg: fix dxferp in from_to case Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 121/143] ARM: OMAP3: Fix booting with thumb2 kernel Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 056/143] parisc: Avoid function pointers for kernel exception routines Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 130/143] net: fix a kernel infoleak in x25 module Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 115/143] Input: ads7846 - correct the value got from SPI Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 096/143] misc/bmp085: Enable building as a module Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 101/143] perf stat: Document --detailed option Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 103/143] compiler-gcc: disable -ftracer for __noclone functions Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 089/143] EDAC: i7core, sb_edac: Don't return NOTIFY_BAD from mce_decoder callback Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 120/143] asmlinkage, pnp: Make variables used from assembler code visible Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 109/143] proc: prevent accessing /proc/<PID>/environ until it's ready Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 079/143] drm/radeon: hold reference to fences in radeon_sa_bo_new (3.17 and older) Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 021/143] USB: mct_u232: add sanity checking in probe Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 111/143] MAINTAINERS: Remove asterisk from EFI directory names Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 068/143] ath9k: fix buffer overrun for ar9287 Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 071/143] qmi_wwan: add "D-Link DWM-221 B1" device id Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 015/143] aacraid: Fix memory leak in aac_fib_map_free Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 117/143] crypto: hash - Fix page length clamping in hash walk Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 110/143] batman-adv: Fix broadcast/ogm queue limit on a removed interface Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 065/143] sh_eth: fix NULL pointer dereference in sh_eth_ring_format() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 137/143] Bluetooth: vhci: purge unhandled skbs Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 094/143] paride: make 'verbose' parameter an 'int' again Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 042/143] ipr: Fix regression when loading firmware Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 119/143] Input: max8997-haptic - fix NULL pointer dereference Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 052/143] mtd: onenand: fix deadlock in onenand_block_markbad Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 108/143] ARM: SoCFPGA: Fix secondary CPU startup in thumb2 kernel Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 099/143] include/linux/poison.h: fix LIST_POISON{1,2} offset Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 032/143] ALSA: intel8x0: Add clock quirk entry for AD1981B on IBM ThinkPad X41. Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 078/143] HID: usbhid: fix inconsistent reset/resume/reset-resume behavior Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 045/143] tracing: Fix crash from reading trace_pipe with sendfile Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 005/143] x86: LLVMLinux: Fix "incomplete type const struct x86cpu_device_id" Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 070/143] ppp: take reference on channels netns Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 135/143] mmc: mmc: Fix partition switch timeout for some eMMCs Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 067/143] farsync: fix off-by-one bug in fst_add_one Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 039/143] md/raid5: Compare apples to apples (or sectors to sectors) Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 131/143] fs/cifs: correctly to anonymous authentication via NTLMSSP Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 082/143] usbvision: fix crash on detecting device with invalid configuration Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 041/143] ipr: Fix out-of-bounds null overwrite Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 019/143] USB: iowarrior: fix oops with malicious USB descriptors Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 092/143] workqueue: fix ghost PENDING flag while doing MQ IO Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 127/143] net: fix infoleak in rtnetlink Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 013/143] x86/iopl: Fix iopl capability check on Xen PV Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 129/143] net: bridge: fix old ioctl unlocked net device walk Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 126/143] net: fix infoleak in llc Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 100/143] Drivers: hv: vmbus: prevent cpu offlining on newer hypervisors Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 002/143] x86/iopl/64: Properly context-switch IOPL on Xen PV Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 029/143] 8250: use callbacks to access UART_DLL/UART_DLM Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 139/143] USB: serial: quatech2: fix use-after-free in probe error path Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 001/143] pipe: Fix buffer offset after partially failed read Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 010/143] linux/const.h: Add _BITUL() and _BITULL() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 026/143] pwc: Add USB id for Philips Spc880nc webcam Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 057/143] parisc: Fix kernel crash with reversed copy_from_user() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 031/143] media: v4l2-compat-ioctl32: fix missing length copy in put_v4l2_buffer32 Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 084/143] usb: hcd: out of bounds access in for_each_companion Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 069/143] qlge: Fix receive packets drop. Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 142/143] tty: vt, return error when con_startup fails Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 136/143] mmc: longer timeout for long read time quirk Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 037/143] xtensa: ISS: don't hang if stdin EOF is reached Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 017/143] usb: retry reset if a device times out Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 097/143] rtc: vr41xx: Wire up alarm_irq_enable Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 003/143] ext4: fix NULL pointer dereference in ext4_mark_inode_dirty() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 018/143] USB: cdc-acm: more sanity checking Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 044/143] tracing: Have preempt(irqs)off trace preempt disabled functions Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 040/143] rapidio/rionet: fix deadlock on SMP Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 066/143] net: Fix use after free in the recvmmsg exit path Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 091/143] efi: Fix out-of-bounds read in variable_matches() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 072/143] ipv4: l2tp: fix a potential issue in l2tp_ip_recv Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 033/143] jbd2: fix FS corruption possibility in jbd2_journal_destroy() on umount path Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 034/143] bcache: fix cache_set_flush() NULL pointer dereference on OOM Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 062/143] cdc_ncm: toggle altsetting to force reset before setup Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 075/143] usb: renesas_usbhs: avoid NULL pointer derefernce in usbhsf_pkt_handler() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 093/143] USB: usbip: fix potential out-of-bounds write Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 043/143] drm/radeon: Don't drop DP 2.7 Ghz link setup on some cards. Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 125/143] atl2: Disable unimplemented scatter/gather feature Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 009/143] PCI: Disable IO/MEM decoding for devices with non-compliant BARs Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-07 05:50 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-07 06:20 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-07 06:40 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-07 07:20 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-07 08:00 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-07 09:00 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-07 20:00 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-07 20:30 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-08 03:00 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-08 07:30 +0200
Page 4 of 7 — ← Prev page 1 2 3 [4] 5 6 7 Next page →
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:40 +0200 |
| Subject | [PATCH 3.10 109/143] proc: prevent accessing /proc/<PID>/environ until it's ready |
| Message-ID | <rGDDl-5zW-77@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Mathias Krause <minipli@googlemail.com>
commit 8148a73c9901a8794a50f950083c00ccf97d43b3 upstream.
If /proc/<PID>/environ gets read before the envp[] array is fully set up
in create_{aout,elf,elf_fdpic,flat}_tables(), we might end up trying to
read more bytes than are actually written, as env_start will already be
set but env_end will still be zero, making the range calculation
underflow, allowing to read beyond the end of what has been written.
Fix this as it is done for /proc/<PID>/cmdline by testing env_end for
zero. It is, apparently, intentionally set last in create_*_tables().
This bug was found by the PaX size_overflow plugin that detected the
arithmetic underflow of 'this_len = env_end - (env_start + src)' when
env_end is still zero.
The expected consequence is that userland trying to access
/proc/<PID>/environ of a not yet fully set up process may get
inconsistent data as we're in the middle of copying in the environment
variables.
Fixes: https://forums.grsecurity.net/viewtopic.php?f=3&t=4363
Fixes: https://bugzilla.kernel.org/show_bug.cgi?id=116461
Signed-off-by: Mathias Krause <minipli@googlemail.com>
Cc: Emese Revfy <re.emese@gmail.com>
Cc: Pax Team <pageexec@freemail.hu>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Mateusz Guzik <mguzik@redhat.com>
Cc: Alexey Dobriyan <adobriyan@gmail.com>
Cc: Cyrill Gorcunov <gorcunov@openvz.org>
Cc: Jarod Wilson <jarod@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
fs/proc/base.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/proc/base.c b/fs/proc/base.c
index 7b5d453..e5160b7 100644
--- a/fs/proc/base.c
+++ b/fs/proc/base.c
@@ -844,7 +844,8 @@ static ssize_t environ_read(struct file *file, char __user *buf,
int ret = 0;
struct mm_struct *mm = file->private_data;
- if (!mm)
+ /* Ensure the process spawned far enough to have an environment. */
+ if (!mm || !mm->env_end)
return 0;
page = (char *)__get_free_page(GFP_TEMPORARY);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:40 +0200 |
| Subject | [PATCH 3.10 079/143] drm/radeon: hold reference to fences in radeon_sa_bo_new (3.17 and older) |
| Message-ID | <rGDDl-5zW-81@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Nicolai Hähnle <nicolai.haehnle@amd.com>
[Backport of upstream commit f6ff4f67cdf8455d0a4226eeeaf5af17c37d05eb, with
an additional NULL pointer guard that is required for kernels 3.17 and older.
To be precise, any kernel that does *not* have commit 954605ca3 "drm/radeon:
use common fence implementation for fences, v4" requires this additional
NULL pointer guard.]
An arbitrary amount of time can pass between spin_unlock and
radeon_fence_wait_any, so we need to ensure that nobody frees the
fences from under us.
Based on the analogous fix for amdgpu.
Signed-off-by: Nicolai Hähnle <nicolai.haehnle@amd.com>
Reviewed-by: Christian König <christian.koenig@amd.com> (v1 + fix)
Tested-by: Lutz Euler <lutz.euler@freenet.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/gpu/drm/radeon/radeon_sa.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/gpu/drm/radeon/radeon_sa.c b/drivers/gpu/drm/radeon/radeon_sa.c
index f0bac68..8962411 100644
--- a/drivers/gpu/drm/radeon/radeon_sa.c
+++ b/drivers/gpu/drm/radeon/radeon_sa.c
@@ -349,8 +349,15 @@ int radeon_sa_bo_new(struct radeon_device *rdev,
/* see if we can skip over some allocations */
} while (radeon_sa_bo_next_hole(sa_manager, fences, tries));
+ for (i = 0; i < RADEON_NUM_RINGS; ++i) {
+ if (fences[i])
+ radeon_fence_ref(fences[i]);
+ }
+
spin_unlock(&sa_manager->wq.lock);
r = radeon_fence_wait_any(rdev, fences, false);
+ for (i = 0; i < RADEON_NUM_RINGS; ++i)
+ radeon_fence_unref(&fences[i]);
spin_lock(&sa_manager->wq.lock);
/* if we have nothing to wait for block */
if (r == -ENOENT && block) {
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 021/143] USB: mct_u232: add sanity checking in probe |
| Message-ID | <rGDMZ-5Ef-1@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Oliver Neukum <oneukum@suse.com>
commit 4e9a0b05257f29cf4b75f3209243ed71614d062e upstream.
An attack using the lack of sanity checking in probe is known. This
patch checks for the existence of a second port.
CVE-2016-3136
Signed-off-by: Oliver Neukum <ONeukum@suse.com>
CC: stable@vger.kernel.org
[johan: add error message ]
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/usb/serial/mct_u232.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/drivers/usb/serial/mct_u232.c b/drivers/usb/serial/mct_u232.c
index 6a15adf..c14c29f 100644
--- a/drivers/usb/serial/mct_u232.c
+++ b/drivers/usb/serial/mct_u232.c
@@ -377,14 +377,21 @@ static void mct_u232_msr_to_state(struct usb_serial_port *port,
static int mct_u232_port_probe(struct usb_serial_port *port)
{
+ struct usb_serial *serial = port->serial;
struct mct_u232_private *priv;
+ /* check first to simplify error handling */
+ if (!serial->port[1] || !serial->port[1]->interrupt_in_urb) {
+ dev_err(&port->dev, "expected endpoint missing\n");
+ return -ENODEV;
+ }
+
priv = kzalloc(sizeof(*priv), GFP_KERNEL);
if (!priv)
return -ENOMEM;
/* Use second interrupt-in endpoint for reading. */
- priv->read_urb = port->serial->port[1]->interrupt_in_urb;
+ priv->read_urb = serial->port[1]->interrupt_in_urb;
priv->read_urb->context = port;
spin_lock_init(&priv->lock);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 111/143] MAINTAINERS: Remove asterisk from EFI directory names |
| Message-ID | <rGDMZ-5Ef-3@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Matt Fleming <matt@codeblueprint.co.uk> commit e8dfe6d8f6762d515fcd4f30577f7bfcf7659887 upstream. Mark reported that having asterisks on the end of directory names confuses get_maintainer.pl when it encounters subdirectories, and that my name does not appear when run on drivers/firmware/efi/libstub. Reported-by: Mark Rutland <mark.rutland@arm.com> Signed-off-by: Matt Fleming <matt@codeblueprint.co.uk> Cc: <stable@vger.kernel.org> Cc: Ard Biesheuvel <ard.biesheuvel@linaro.org> Cc: Catalin Marinas <catalin.marinas@arm.com> Cc: Linus Torvalds <torvalds@linux-foundation.org> Cc: Peter Zijlstra <peterz@infradead.org> Cc: Thomas Gleixner <tglx@linutronix.de> Cc: linux-efi@vger.kernel.org Link: http://lkml.kernel.org/r/1462303781-8686-2-git-send-email-matt@codeblueprint.co.uk Signed-off-by: Ingo Molnar <mingo@kernel.org> Signed-off-by: Willy Tarreau <w@1wt.eu> --- MAINTAINERS | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/MAINTAINERS b/MAINTAINERS index 48c7480..29d7d74 100644 --- a/MAINTAINERS +++ b/MAINTAINERS @@ -3032,8 +3032,8 @@ F: Documentation/x86/efi-stub.txt F: arch/ia64/kernel/efi.c F: arch/x86/boot/compressed/eboot.[ch] F: arch/x86/include/asm/efi.h -F: arch/x86/platform/efi/* -F: drivers/firmware/efi/* +F: arch/x86/platform/efi/ +F: drivers/firmware/efi/ F: include/linux/efi*.h EFI VARIABLE FILESYSTEM -- 2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 068/143] ath9k: fix buffer overrun for ar9287 |
| Message-ID | <rGDMZ-5Ef-5@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Arnd Bergmann <arnd@arndb.de>
commit 83d6f1f15f8cce844b0a131cbc63e444620e48b5 upstream.
Code that was added back in 2.6.38 has an obvious overflow
when accessing a static array, and at the time it was added
only a code comment was put in front of it as a reminder
to have it reviewed properly.
This has not happened, but gcc-6 now points to the specific
overflow:
drivers/net/wireless/ath/ath9k/eeprom.c: In function 'ath9k_hw_get_gain_boundaries_pdadcs':
drivers/net/wireless/ath/ath9k/eeprom.c:483:44: error: array subscript is above array bounds [-Werror=array-bounds]
maxPwrT4[i] = data_9287[idxL].pwrPdg[i][4];
~~~~~~~~~~~~~~~~~~~~~~~~~^~~
It turns out that the correct array length exists in the local
'intercepts' variable of this function, so we can just use that
instead of hardcoding '4', so this patch changes all three
instances to use that variable. The other two instances were
already correct, but it's more consistent this way.
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Fixes: 940cd2c12ebf ("ath9k_hw: merge the ar9287 version of ath9k_hw_get_gain_boundaries_pdadcs")
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/net/wireless/ath/ath9k/eeprom.c | 7 +++----
1 file changed, 3 insertions(+), 4 deletions(-)
diff --git a/drivers/net/wireless/ath/ath9k/eeprom.c b/drivers/net/wireless/ath/ath9k/eeprom.c
index 971d770..2ac0548 100644
--- a/drivers/net/wireless/ath/ath9k/eeprom.c
+++ b/drivers/net/wireless/ath/ath9k/eeprom.c
@@ -408,10 +408,9 @@ void ath9k_hw_get_gain_boundaries_pdadcs(struct ath_hw *ah,
if (match) {
if (AR_SREV_9287(ah)) {
- /* FIXME: array overrun? */
for (i = 0; i < numXpdGains; i++) {
minPwrT4[i] = data_9287[idxL].pwrPdg[i][0];
- maxPwrT4[i] = data_9287[idxL].pwrPdg[i][4];
+ maxPwrT4[i] = data_9287[idxL].pwrPdg[i][intercepts - 1];
ath9k_hw_fill_vpd_table(minPwrT4[i], maxPwrT4[i],
data_9287[idxL].pwrPdg[i],
data_9287[idxL].vpdPdg[i],
@@ -421,7 +420,7 @@ void ath9k_hw_get_gain_boundaries_pdadcs(struct ath_hw *ah,
} else if (eeprom_4k) {
for (i = 0; i < numXpdGains; i++) {
minPwrT4[i] = data_4k[idxL].pwrPdg[i][0];
- maxPwrT4[i] = data_4k[idxL].pwrPdg[i][4];
+ maxPwrT4[i] = data_4k[idxL].pwrPdg[i][intercepts - 1];
ath9k_hw_fill_vpd_table(minPwrT4[i], maxPwrT4[i],
data_4k[idxL].pwrPdg[i],
data_4k[idxL].vpdPdg[i],
@@ -431,7 +430,7 @@ void ath9k_hw_get_gain_boundaries_pdadcs(struct ath_hw *ah,
} else {
for (i = 0; i < numXpdGains; i++) {
minPwrT4[i] = data_def[idxL].pwrPdg[i][0];
- maxPwrT4[i] = data_def[idxL].pwrPdg[i][4];
+ maxPwrT4[i] = data_def[idxL].pwrPdg[i][intercepts - 1];
ath9k_hw_fill_vpd_table(minPwrT4[i], maxPwrT4[i],
data_def[idxL].pwrPdg[i],
data_def[idxL].vpdPdg[i],
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 071/143] qmi_wwan: add "D-Link DWM-221 B1" device id |
| Message-ID | <rGDN0-5Ef-9@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Bjørn Mork <bjorn@mork.no>
commit e84810c7b85a2d7897797b3ad3e879168a8e032a upstream.
Thomas reports:
"Windows:
00 diagnostics
01 modem
02 at-port
03 nmea
04 nic
Linux:
T: Bus=02 Lev=01 Prnt=01 Port=03 Cnt=01 Dev#= 4 Spd=480 MxCh= 0
D: Ver= 2.00 Cls=00(>ifc ) Sub=00 Prot=00 MxPS=64 #Cfgs= 1
P: Vendor=2001 ProdID=7e19 Rev=02.32
S: Manufacturer=Mobile Connect
S: Product=Mobile Connect
S: SerialNumber=0123456789ABCDEF
C: #Ifs= 6 Cfg#= 1 Atr=a0 MxPwr=500mA
I: If#= 0 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=ff Driver=option
I: If#= 1 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
I: If#= 2 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
I: If#= 3 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
I: If#= 4 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=ff Driver=qmi_wwan
I: If#= 5 Alt= 0 #EPs= 2 Cls=08(stor.) Sub=06 Prot=50 Driver=usb-storage"
Reported-by: Thomas Schäfer <tschaefer@t-online.de>
Signed-off-by: Bjørn Mork <bjorn@mork.no>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/net/usb/qmi_wwan.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/usb/qmi_wwan.c b/drivers/net/usb/qmi_wwan.c
index 0244a1f..12aaf1f 100644
--- a/drivers/net/usb/qmi_wwan.c
+++ b/drivers/net/usb/qmi_wwan.c
@@ -724,6 +724,7 @@ static const struct usb_device_id products[] = {
{QMI_FIXED_INTF(0x19d2, 0x1426, 2)}, /* ZTE MF91 */
{QMI_FIXED_INTF(0x19d2, 0x1428, 2)}, /* Telewell TW-LTE 4G v2 */
{QMI_FIXED_INTF(0x19d2, 0x2002, 4)}, /* ZTE (Vodafone) K3765-Z */
+ {QMI_FIXED_INTF(0x2001, 0x7e19, 4)}, /* D-Link DWM-221 B1 */
{QMI_FIXED_INTF(0x0f3d, 0x68a2, 8)}, /* Sierra Wireless MC7700 */
{QMI_FIXED_INTF(0x114f, 0x68a2, 8)}, /* Sierra Wireless MC7750 */
{QMI_FIXED_INTF(0x1199, 0x68a2, 8)}, /* Sierra Wireless MC7710 in QMI mode */
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 015/143] aacraid: Fix memory leak in aac_fib_map_free |
| Message-ID | <rGDN0-5Ef-7@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Raghava Aditya Renukunta <raghavaaditya.renukunta@pmcs.com>
commit f88fa79a61726ce9434df9b4aede36961f709f17 upstream.
aac_fib_map_free() calls pci_free_consistent() without checking that
dev->hw_fib_va is not NULL and dev->max_fib_size is not zero.If they are
indeed NULL/0, this will result in a hang as pci_free_consistent() will
attempt to invalidate cache for the entire 64-bit address space
(which would take a very long time).
Fixed by adding a check to make sure that dev->hw_fib_va and
dev->max_fib_size are not NULL and 0 respectively.
Fixes: 9ad5204d6 - "[SCSI]aacraid: incorrect dma mapping mask during blinked recover or user initiated reset"
Cc: stable@vger.kernel.org
Signed-off-by: Raghava Aditya Renukunta <raghavaaditya.renukunta@pmcs.com>
Reviewed-by: Johannes Thumshirn <jthumshirn@suse.de>
Reviewed-by: Tomas Henzl <thenzl@redhat.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/scsi/aacraid/commsup.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/drivers/scsi/aacraid/commsup.c b/drivers/scsi/aacraid/commsup.c
index 1be0776..6a0d362 100644
--- a/drivers/scsi/aacraid/commsup.c
+++ b/drivers/scsi/aacraid/commsup.c
@@ -83,9 +83,12 @@ static int fib_map_alloc(struct aac_dev *dev)
void aac_fib_map_free(struct aac_dev *dev)
{
- pci_free_consistent(dev->pdev,
- dev->max_fib_size * (dev->scsi_host_ptr->can_queue + AAC_NUM_MGT_FIB),
- dev->hw_fib_va, dev->hw_fib_pa);
+ if (dev->hw_fib_va && dev->max_fib_size) {
+ pci_free_consistent(dev->pdev,
+ (dev->max_fib_size *
+ (dev->scsi_host_ptr->can_queue + AAC_NUM_MGT_FIB)),
+ dev->hw_fib_va, dev->hw_fib_pa);
+ }
dev->hw_fib_va = NULL;
dev->hw_fib_pa = 0;
}
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 117/143] crypto: hash - Fix page length clamping in hash walk |
| Message-ID | <rGDN0-5Ef-17@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Herbert Xu <herbert@gondor.apana.org.au> commit 13f4bb78cf6a312bbdec367ba3da044b09bf0e29 upstream. The crypto hash walk code is broken when supplied with an offset greater than or equal to PAGE_SIZE. This patch fixes it by adjusting walk->pg and walk->offset when this happens. Cc: <stable@vger.kernel.org> Reported-by: Steffen Klassert <steffen.klassert@secunet.com> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au> Signed-off-by: Willy Tarreau <w@1wt.eu> --- crypto/ahash.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/crypto/ahash.c b/crypto/ahash.c index 857ae2b..bcd5efc 100644 --- a/crypto/ahash.c +++ b/crypto/ahash.c @@ -64,8 +64,9 @@ static int hash_walk_new_entry(struct crypto_hash_walk *walk) struct scatterlist *sg; sg = walk->sg; - walk->pg = sg_page(sg); walk->offset = sg->offset; + walk->pg = sg_page(walk->sg) + (walk->offset >> PAGE_SHIFT); + walk->offset = offset_in_page(walk->offset); walk->entrylen = sg->length; if (walk->entrylen > walk->total) -- 2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 110/143] batman-adv: Fix broadcast/ogm queue limit on a removed interface |
| Message-ID | <rGDN0-5Ef-13@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Linus Lüssing <linus.luessing@c0d3.blue>
commit c4fdb6cff2aa0ae740c5f19b6f745cbbe786d42f upstream.
When removing a single interface while a broadcast or ogm packet is
still pending then we will free the forward packet without releasing the
queue slots again.
This patch is supposed to fix this issue.
Fixes: 6d5808d4ae1b ("batman-adv: Add missing hardif_free_ref in forw_packet_free")
Signed-off-by: Linus Lüssing <linus.luessing@c0d3.blue>
[sven@narfation.org: fix conflicts with current version]
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Marek Lindner <mareklindner@neomailbox.ch>
Signed-off-by: Antonio Quartulli <a@unstable.cc>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
net/batman-adv/send.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/net/batman-adv/send.c b/net/batman-adv/send.c
index 263cfd1..cf5b766 100644
--- a/net/batman-adv/send.c
+++ b/net/batman-adv/send.c
@@ -353,6 +353,9 @@ batadv_purge_outstanding_packets(struct batadv_priv *bat_priv,
if (pending) {
hlist_del(&forw_packet->list);
+ if (!forw_packet->own)
+ atomic_inc(&bat_priv->batman_queue_left);
+
batadv_forw_packet_free(forw_packet);
}
}
@@ -379,6 +382,9 @@ batadv_purge_outstanding_packets(struct batadv_priv *bat_priv,
if (pending) {
hlist_del(&forw_packet->list);
+ if (!forw_packet->own)
+ atomic_inc(&bat_priv->bcast_queue_left);
+
batadv_forw_packet_free(forw_packet);
}
}
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 065/143] sh_eth: fix NULL pointer dereference in sh_eth_ring_format() |
| Message-ID | <rGDN0-5Ef-11@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Sergei Shtylyov <sergei.shtylyov@cogentembedded.com> commit c1b7fca65070bfadca94dd53a4e6b71cd4f69715 upstream. In a low memory situation, if netdev_alloc_skb() fails on a first RX ring loop iteration in sh_eth_ring_format(), 'rxdesc' is still NULL. Avoid kernel oops by adding the 'rxdesc' check after the loop. Reported-by: Wolfram Sang <wsa+renesas@sang-engineering.com> Signed-off-by: Sergei Shtylyov <sergei.shtylyov@cogentembedded.com> Signed-off-by: David S. Miller <davem@davemloft.net> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by: Willy Tarreau <w@1wt.eu> --- drivers/net/ethernet/renesas/sh_eth.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/net/ethernet/renesas/sh_eth.c b/drivers/net/ethernet/renesas/sh_eth.c index b93a0fb..93b6525 100644 --- a/drivers/net/ethernet/renesas/sh_eth.c +++ b/drivers/net/ethernet/renesas/sh_eth.c @@ -1161,7 +1161,8 @@ static void sh_eth_ring_format(struct net_device *ndev) mdp->dirty_rx = (u32) (i - mdp->num_rx_ring); /* Mark the last entry as wrapping the ring. */ - rxdesc->status |= cpu_to_edmac(mdp, RD_RDEL); + if (rxdesc) + rxdesc->status |= cpu_to_edmac(mdp, RD_RDEL); memset(mdp->tx_ring, 0, tx_ringsize); -- 2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 137/143] Bluetooth: vhci: purge unhandled skbs |
| Message-ID | <rGDN0-5Ef-15@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Jiri Slaby <jslaby@suse.cz>
commit 13407376b255325fa817798800117a839f3aa055 upstream.
The write handler allocates skbs and queues them into data->readq.
Read side should read them, if there is any. If there is none, skbs
should be dropped by hdev->flush. But this happens only if the device
is HCI_UP, i.e. hdev->power_on work was triggered already. When it was
not, skbs stay allocated in the queue when /dev/vhci is closed. So
purge the queue in ->release.
Program to reproduce:
#include <err.h>
#include <fcntl.h>
#include <stdio.h>
#include <unistd.h>
#include <sys/stat.h>
#include <sys/types.h>
#include <sys/uio.h>
int main()
{
char buf[] = { 0xff, 0 };
struct iovec iov = {
.iov_base = buf,
.iov_len = sizeof(buf),
};
int fd;
while (1) {
fd = open("/dev/vhci", O_RDWR);
if (fd < 0)
err(1, "open");
usleep(50);
if (writev(fd, &iov, 1) < 0)
err(1, "writev");
usleep(50);
close(fd);
}
return 0;
}
Result:
kmemleak: 4609 new suspected memory leaks
unreferenced object 0xffff88059f4d5440 (size 232):
comm "vhci", pid 1084, jiffies 4294912542 (age 37569.296s)
hex dump (first 32 bytes):
20 f0 23 87 05 88 ff ff 20 f0 23 87 05 88 ff ff .#..... .#.....
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
...
[<ffffffff81ece010>] __alloc_skb+0x0/0x5a0
[<ffffffffa021886c>] vhci_create_device+0x5c/0x580 [hci_vhci]
[<ffffffffa0219436>] vhci_write+0x306/0x4c8 [hci_vhci]
Fixes: 23424c0d31 (Bluetooth: Add support creating virtual AMP controllers)
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/bluetooth/hci_vhci.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/bluetooth/hci_vhci.c b/drivers/bluetooth/hci_vhci.c
index d8b7aed..f3ce1c4 100644
--- a/drivers/bluetooth/hci_vhci.c
+++ b/drivers/bluetooth/hci_vhci.c
@@ -265,6 +265,7 @@ static int vhci_release(struct inode *inode, struct file *file)
hci_unregister_dev(hdev);
hci_free_dev(hdev);
+ skb_queue_purge(&data->readq);
file->private_data = NULL;
kfree(data);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 094/143] paride: make 'verbose' parameter an 'int' again |
| Message-ID | <rGDN0-5Ef-19@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Arnd Bergmann <arnd@arndb.de>
commit dec63a4dec2d6d01346fd5d96062e67c0636852b upstream.
gcc-6.0 found an ancient bug in the paride driver, which had a
"module_param(verbose, bool, 0);" since before 2.6.12, but actually uses
it to accept '0', '1' or '2' as arguments:
drivers/block/paride/pd.c: In function 'pd_init_dev_parms':
drivers/block/paride/pd.c:298:29: warning: comparison of constant '1' with boolean expression is always false [-Wbool-compare]
#define DBMSG(msg) ((verbose>1)?(msg):NULL)
In 2012, Rusty did a cleanup patch that also changed the type of the
variable to 'bool', which introduced what is now a gcc warning.
This changes the type back to 'int' and adapts the module_param() line
instead, so it should work as documented in case anyone ever cares about
running the ancient driver with debugging.
Fixes: 90ab5ee94171 ("module_param: make bool parameters really bool (drivers & misc)")
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Rusty Russell <rusty@rustcorp.com.au>
Cc: Tim Waugh <tim@cyberelk.net>
Cc: Sudip Mukherjee <sudipm.mukherjee@gmail.com>
Cc: Jens Axboe <axboe@fb.com>
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/block/paride/pd.c | 4 ++--
drivers/block/paride/pt.c | 4 ++--
2 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/block/paride/pd.c b/drivers/block/paride/pd.c
index 19ad8f0..897b6b9 100644
--- a/drivers/block/paride/pd.c
+++ b/drivers/block/paride/pd.c
@@ -126,7 +126,7 @@
*/
#include <linux/types.h>
-static bool verbose = 0;
+static int verbose = 0;
static int major = PD_MAJOR;
static char *name = PD_NAME;
static int cluster = 64;
@@ -161,7 +161,7 @@ enum {D_PRT, D_PRO, D_UNI, D_MOD, D_GEO, D_SBY, D_DLY, D_SLV};
static DEFINE_MUTEX(pd_mutex);
static DEFINE_SPINLOCK(pd_lock);
-module_param(verbose, bool, 0);
+module_param(verbose, int, 0);
module_param(major, int, 0);
module_param(name, charp, 0);
module_param(cluster, int, 0);
diff --git a/drivers/block/paride/pt.c b/drivers/block/paride/pt.c
index 2596042..ada4505 100644
--- a/drivers/block/paride/pt.c
+++ b/drivers/block/paride/pt.c
@@ -117,7 +117,7 @@
*/
-static bool verbose = 0;
+static int verbose = 0;
static int major = PT_MAJOR;
static char *name = PT_NAME;
static int disable = 0;
@@ -152,7 +152,7 @@ static int (*drives[4])[6] = {&drive0, &drive1, &drive2, &drive3};
#include <asm/uaccess.h>
-module_param(verbose, bool, 0);
+module_param(verbose, int, 0);
module_param(major, int, 0);
module_param(name, charp, 0);
module_param_array(drive0, int, NULL, 0);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 042/143] ipr: Fix regression when loading firmware |
| Message-ID | <rGDN0-5Ef-23@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Gabriel Krisman Bertazi <krisman@linux.vnet.ibm.com>
commit 21b81716c6bff24cda52dc75588455f879ddbfe9 upstream.
Commit d63c7dd5bcb9 ("ipr: Fix out-of-bounds null overwrite") removed
the end of line handling when storing the update_fw sysfs attribute.
This changed the userpace API because it started refusing writes
terminated by a line feed, which broke the update tools we already have.
This patch re-adds that handling, so both a write terminated by a line
feed or not can make it through with the update.
Fixes: d63c7dd5bcb9 ("ipr: Fix out-of-bounds null overwrite")
Signed-off-by: Gabriel Krisman Bertazi <krisman@linux.vnet.ibm.com>
Cc: Insu Yun <wuninsu@gmail.com>
Acked-by: Brian King <brking@linux.vnet.ibm.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/scsi/ipr.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/scsi/ipr.c b/drivers/scsi/ipr.c
index bde4771..25ac2c0 100644
--- a/drivers/scsi/ipr.c
+++ b/drivers/scsi/ipr.c
@@ -3908,6 +3908,7 @@ static ssize_t ipr_store_update_fw(struct device *dev,
struct ipr_sglist *sglist;
char fname[100];
char *src;
+ char *endline;
int result, dnld_size;
if (!capable(CAP_SYS_ADMIN))
@@ -3915,6 +3916,10 @@ static ssize_t ipr_store_update_fw(struct device *dev,
snprintf(fname, sizeof(fname), "%s", buf);
+ endline = strchr(fname, '\n');
+ if (endline)
+ *endline = '\0';
+
if (request_firmware(&fw_entry, fname, &ioa_cfg->pdev->dev)) {
dev_err(&ioa_cfg->pdev->dev, "Firmware file %s not found\n", fname);
return -EIO;
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 119/143] Input: max8997-haptic - fix NULL pointer dereference |
| Message-ID | <rGDN0-5Ef-21@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Marek Szyprowski <m.szyprowski@samsung.com>
commit 6ae645d5fa385f3787bf1723639cd907fe5865e7 upstream.
NULL pointer derefence happens when booting with DTB because the
platform data for haptic device is not set in supplied data from parent
MFD device.
The MFD device creates only platform data (from Device Tree) for itself,
not for haptic child.
Unable to handle kernel NULL pointer dereference at virtual address 0000009c
pgd = c0004000
[0000009c] *pgd=00000000
Internal error: Oops: 5 [#1] PREEMPT SMP ARM
(max8997_haptic_probe) from [<c03f9cec>] (platform_drv_probe+0x4c/0xb0)
(platform_drv_probe) from [<c03f8440>] (driver_probe_device+0x214/0x2c0)
(driver_probe_device) from [<c03f8598>] (__driver_attach+0xac/0xb0)
(__driver_attach) from [<c03f67ac>] (bus_for_each_dev+0x68/0x9c)
(bus_for_each_dev) from [<c03f7a38>] (bus_add_driver+0x1a0/0x218)
(bus_add_driver) from [<c03f8db0>] (driver_register+0x78/0xf8)
(driver_register) from [<c0101774>] (do_one_initcall+0x90/0x1d8)
(do_one_initcall) from [<c0a00dbc>] (kernel_init_freeable+0x15c/0x1fc)
(kernel_init_freeable) from [<c06bb5b4>] (kernel_init+0x8/0x114)
(kernel_init) from [<c0107938>] (ret_from_fork+0x14/0x3c)
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Cc: <stable@vger.kernel.org>
Fixes: 104594b01ce7 ("Input: add driver support for MAX8997-haptic")
[k.kozlowski: Write commit message, add CC-stable]
Signed-off-by: Krzysztof Kozlowski <k.kozlowski@samsung.com>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/input/misc/max8997_haptic.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/input/misc/max8997_haptic.c b/drivers/input/misc/max8997_haptic.c
index e973133..a8c9122 100644
--- a/drivers/input/misc/max8997_haptic.c
+++ b/drivers/input/misc/max8997_haptic.c
@@ -246,12 +246,14 @@ static int max8997_haptic_probe(struct platform_device *pdev)
struct max8997_dev *iodev = dev_get_drvdata(pdev->dev.parent);
const struct max8997_platform_data *pdata =
dev_get_platdata(iodev->dev);
- const struct max8997_haptic_platform_data *haptic_pdata =
- pdata->haptic_pdata;
+ const struct max8997_haptic_platform_data *haptic_pdata = NULL;
struct max8997_haptic *chip;
struct input_dev *input_dev;
int error;
+ if (pdata)
+ haptic_pdata = pdata->haptic_pdata;
+
if (!haptic_pdata) {
dev_err(&pdev->dev, "no haptic platform data\n");
return -EINVAL;
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 052/143] mtd: onenand: fix deadlock in onenand_block_markbad |
| Message-ID | <rGDN0-5Ef-25@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Aaro Koskinen <aaro.koskinen@iki.fi>
commit 5e64c29e98bfbba1b527b0a164f9493f3db9e8cb upstream.
Commit 5942ddbc500d ("mtd: introduce mtd_block_markbad interface")
incorrectly changed onenand_block_markbad() to call mtd_block_markbad
instead of onenand_chip's block_markbad function. As a result the function
will now recurse and deadlock. Fix by reverting the change.
Fixes: 5942ddbc500d ("mtd: introduce mtd_block_markbad interface")
Signed-off-by: Aaro Koskinen <aaro.koskinen@iki.fi>
Acked-by: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Brian Norris <computersforpeace@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/mtd/onenand/onenand_base.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/mtd/onenand/onenand_base.c b/drivers/mtd/onenand/onenand_base.c
index b3f41f2..0f13fd4 100644
--- a/drivers/mtd/onenand/onenand_base.c
+++ b/drivers/mtd/onenand/onenand_base.c
@@ -2610,6 +2610,7 @@ static int onenand_default_block_markbad(struct mtd_info *mtd, loff_t ofs)
*/
static int onenand_block_markbad(struct mtd_info *mtd, loff_t ofs)
{
+ struct onenand_chip *this = mtd->priv;
int ret;
ret = onenand_block_isbad(mtd, ofs);
@@ -2621,7 +2622,7 @@ static int onenand_block_markbad(struct mtd_info *mtd, loff_t ofs)
}
onenand_get_device(mtd, FL_WRITING);
- ret = mtd_block_markbad(mtd, ofs);
+ ret = this->block_markbad(mtd, ofs);
onenand_release_device(mtd);
return ret;
}
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 108/143] ARM: SoCFPGA: Fix secondary CPU startup in thumb2 kernel |
| Message-ID | <rGDN0-5Ef-31@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Sascha Hauer <s.hauer@pengutronix.de> commit 5616f36713ea77f57ae908bf2fef641364403c9f upstream. The secondary CPU starts up in ARM mode. When the kernel is compiled in thumb2 mode we have to explicitly compile the secondary startup trampoline in ARM mode, otherwise the CPU will go to Nirvana. Signed-off-by: Sascha Hauer <s.hauer@pengutronix.de> Reported-by: Steffen Trumtrar <s.trumtrar@pengutronix.de> Suggested-by: Ard Biesheuvel <ard.biesheuvel@linaro.org> Signed-off-by: Dinh Nguyen <dinguyen@opensource.altera.com> Signed-off-by: Kevin Hilman <khilman@baylibre.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by: Willy Tarreau <w@1wt.eu> --- arch/arm/mach-socfpga/headsmp.S | 1 + 1 file changed, 1 insertion(+) diff --git a/arch/arm/mach-socfpga/headsmp.S b/arch/arm/mach-socfpga/headsmp.S index 9004bfb..a6f5519 100644 --- a/arch/arm/mach-socfpga/headsmp.S +++ b/arch/arm/mach-socfpga/headsmp.S @@ -12,6 +12,7 @@ __CPUINIT .arch armv7-a + .arm ENTRY(secondary_trampoline) movw r2, #:lower16:cpu1start_addr -- 2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 099/143] include/linux/poison.h: fix LIST_POISON{1,2} offset |
| Message-ID | <rGDN0-5Ef-27@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Vasily Kulikov <segoon@openwall.com>
commit 8a5e5e02fc83aaf67053ab53b359af08c6c49aaf upstream.
Poison pointer values should be small enough to find a room in
non-mmap'able/hardly-mmap'able space. E.g. on x86 "poison pointer space"
is located starting from 0x0. Given unprivileged users cannot mmap
anything below mmap_min_addr, it should be safe to use poison pointers
lower than mmap_min_addr.
The current poison pointer values of LIST_POISON{1,2} might be too big for
mmap_min_addr values equal or less than 1 MB (common case, e.g. Ubuntu
uses only 0x10000). There is little point to use such a big value given
the "poison pointer space" below 1 MB is not yet exhausted. Changing it
to a smaller value solves the problem for small mmap_min_addr setups.
The values are suggested by Solar Designer:
http://www.openwall.com/lists/oss-security/2015/05/02/6
Signed-off-by: Vasily Kulikov <segoon@openwall.com>
Cc: Solar Designer <solar@openwall.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
include/linux/poison.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/include/linux/poison.h b/include/linux/poison.h
index 2110a81..253c9b4 100644
--- a/include/linux/poison.h
+++ b/include/linux/poison.h
@@ -19,8 +19,8 @@
* under normal circumstances, used to verify that nobody uses
* non-initialized list entries.
*/
-#define LIST_POISON1 ((void *) 0x00100100 + POISON_POINTER_DELTA)
-#define LIST_POISON2 ((void *) 0x00200200 + POISON_POINTER_DELTA)
+#define LIST_POISON1 ((void *) 0x100 + POISON_POINTER_DELTA)
+#define LIST_POISON2 ((void *) 0x200 + POISON_POINTER_DELTA)
/********** include/linux/timer.h **********/
/*
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 032/143] ALSA: intel8x0: Add clock quirk entry for AD1981B on IBM ThinkPad X41. |
| Message-ID | <rGDN0-5Ef-33@gated-at.bofh.it> |
| In reply to | #1413978 |
From: "Vittorio Gambaletta (VittGam)" <linuxbugs@vittgam.net>
commit 4061db03dd71d195b9973ee466f6ed32f6a3fc16 upstream.
The clock measurement on the AC'97 audio card found in the IBM ThinkPad X41
will often fail, so add a quirk entry to fix it.
Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=441087
Cc: <stable@vger.kernel.org>
Signed-off-by: Vittorio Gambaletta <linuxbugs@vittgam.net>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
sound/pci/intel8x0.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sound/pci/intel8x0.c b/sound/pci/intel8x0.c
index b8fe405..7022450 100644
--- a/sound/pci/intel8x0.c
+++ b/sound/pci/intel8x0.c
@@ -2885,6 +2885,7 @@ static void intel8x0_measure_ac97_clock(struct intel8x0 *chip)
static struct snd_pci_quirk intel8x0_clock_list[] = {
SND_PCI_QUIRK(0x0e11, 0x008a, "AD1885", 41000),
+ SND_PCI_QUIRK(0x1014, 0x0581, "AD1981B", 48000),
SND_PCI_QUIRK(0x1028, 0x00be, "AD1885", 44100),
SND_PCI_QUIRK(0x1028, 0x0177, "AD1980", 48000),
SND_PCI_QUIRK(0x1028, 0x01ad, "AD1981B", 48000),
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 078/143] HID: usbhid: fix inconsistent reset/resume/reset-resume behavior |
| Message-ID | <rGDN0-5Ef-35@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Alan Stern <stern@rowland.harvard.edu>
commit 972e6a993f278b416a8ee3ec65475724fc36feb2 upstream.
The usbhid driver has inconsistently duplicated code in its post-reset,
resume, and reset-resume pathways.
reset-resume doesn't check HID_STARTED before trying to
restart the I/O queues.
resume fails to clear the HID_SUSPENDED flag if HID_STARTED
isn't set.
resume calls usbhid_restart_queues() with usbhid->lock held
and the others call it without holding the lock.
The first item in particular causes a problem following a reset-resume
if the driver hasn't started up its I/O. URB submission fails because
usbhid->urbin is NULL, and this triggers an unending reset-retry loop.
This patch fixes the problem by creating a new subroutine,
hid_restart_io(), to carry out all the common activities. It also
adds some checks that were missing in the original code:
After a reset, there's no need to clear any halted endpoints.
After a resume, if a reset is pending there's no need to
restart any I/O until the reset is finished.
After a resume, if the interrupt-IN endpoint is halted there's
no need to submit the input URB until the halt has been
cleared.
Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Reported-by: Daniel Fraga <fragabr@gmail.com>
Tested-by: Daniel Fraga <fragabr@gmail.com>
CC: <stable@vger.kernel.org>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/hid/usbhid/hid-core.c | 73 ++++++++++++++++++++++---------------------
1 file changed, 37 insertions(+), 36 deletions(-)
diff --git a/drivers/hid/usbhid/hid-core.c b/drivers/hid/usbhid/hid-core.c
index 5da58e3..92aef982 100644
--- a/drivers/hid/usbhid/hid-core.c
+++ b/drivers/hid/usbhid/hid-core.c
@@ -988,14 +988,6 @@ static int usbhid_output_raw_report(struct hid_device *hid, __u8 *buf, size_t co
return ret;
}
-static void usbhid_restart_queues(struct usbhid_device *usbhid)
-{
- if (usbhid->urbout && !test_bit(HID_OUT_RUNNING, &usbhid->iofl))
- usbhid_restart_out_queue(usbhid);
- if (!test_bit(HID_CTRL_RUNNING, &usbhid->iofl))
- usbhid_restart_ctrl_queue(usbhid);
-}
-
static void hid_free_buffers(struct usb_device *dev, struct hid_device *hid)
{
struct usbhid_device *usbhid = hid->driver_data;
@@ -1412,6 +1404,37 @@ static void hid_cease_io(struct usbhid_device *usbhid)
usb_kill_urb(usbhid->urbout);
}
+static void hid_restart_io(struct hid_device *hid)
+{
+ struct usbhid_device *usbhid = hid->driver_data;
+ int clear_halt = test_bit(HID_CLEAR_HALT, &usbhid->iofl);
+ int reset_pending = test_bit(HID_RESET_PENDING, &usbhid->iofl);
+
+ spin_lock_irq(&usbhid->lock);
+ clear_bit(HID_SUSPENDED, &usbhid->iofl);
+ usbhid_mark_busy(usbhid);
+
+ if (clear_halt || reset_pending)
+ schedule_work(&usbhid->reset_work);
+ usbhid->retry_delay = 0;
+ spin_unlock_irq(&usbhid->lock);
+
+ if (reset_pending || !test_bit(HID_STARTED, &usbhid->iofl))
+ return;
+
+ if (!clear_halt) {
+ if (hid_start_in(hid) < 0)
+ hid_io_error(hid);
+ }
+
+ spin_lock_irq(&usbhid->lock);
+ if (usbhid->urbout && !test_bit(HID_OUT_RUNNING, &usbhid->iofl))
+ usbhid_restart_out_queue(usbhid);
+ if (!test_bit(HID_CTRL_RUNNING, &usbhid->iofl))
+ usbhid_restart_ctrl_queue(usbhid);
+ spin_unlock_irq(&usbhid->lock);
+}
+
/* Treat USB reset pretty much the same as suspend/resume */
static int hid_pre_reset(struct usb_interface *intf)
{
@@ -1461,14 +1484,14 @@ static int hid_post_reset(struct usb_interface *intf)
return 1;
}
+ /* No need to do another reset or clear a halted endpoint */
spin_lock_irq(&usbhid->lock);
clear_bit(HID_RESET_PENDING, &usbhid->iofl);
+ clear_bit(HID_CLEAR_HALT, &usbhid->iofl);
spin_unlock_irq(&usbhid->lock);
hid_set_idle(dev, intf->cur_altsetting->desc.bInterfaceNumber, 0, 0);
- status = hid_start_in(hid);
- if (status < 0)
- hid_io_error(hid);
- usbhid_restart_queues(usbhid);
+
+ hid_restart_io(hid);
return 0;
}
@@ -1491,25 +1514,9 @@ void usbhid_put_power(struct hid_device *hid)
#ifdef CONFIG_PM
static int hid_resume_common(struct hid_device *hid, bool driver_suspended)
{
- struct usbhid_device *usbhid = hid->driver_data;
- int status;
-
- spin_lock_irq(&usbhid->lock);
- clear_bit(HID_SUSPENDED, &usbhid->iofl);
- usbhid_mark_busy(usbhid);
-
- if (test_bit(HID_CLEAR_HALT, &usbhid->iofl) ||
- test_bit(HID_RESET_PENDING, &usbhid->iofl))
- schedule_work(&usbhid->reset_work);
- usbhid->retry_delay = 0;
-
- usbhid_restart_queues(usbhid);
- spin_unlock_irq(&usbhid->lock);
-
- status = hid_start_in(hid);
- if (status < 0)
- hid_io_error(hid);
+ int status = 0;
+ hid_restart_io(hid);
if (driver_suspended && hid->driver && hid->driver->resume)
status = hid->driver->resume(hid);
return status;
@@ -1576,12 +1583,8 @@ static int hid_suspend(struct usb_interface *intf, pm_message_t message)
static int hid_resume(struct usb_interface *intf)
{
struct hid_device *hid = usb_get_intfdata (intf);
- struct usbhid_device *usbhid = hid->driver_data;
int status;
- if (!test_bit(HID_STARTED, &usbhid->iofl))
- return 0;
-
status = hid_resume_common(hid, true);
dev_dbg(&intf->dev, "resume status %d\n", status);
return 0;
@@ -1590,10 +1593,8 @@ static int hid_resume(struct usb_interface *intf)
static int hid_reset_resume(struct usb_interface *intf)
{
struct hid_device *hid = usb_get_intfdata(intf);
- struct usbhid_device *usbhid = hid->driver_data;
int status;
- clear_bit(HID_SUSPENDED, &usbhid->iofl);
status = hid_post_reset(intf);
if (status >= 0 && hid->driver && hid->driver->reset_resume) {
int ret = hid->driver->reset_resume(hid);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:50 +0200 |
| Subject | [PATCH 3.10 045/143] tracing: Fix crash from reading trace_pipe with sendfile |
| Message-ID | <rGDN1-5Ef-37@gated-at.bofh.it> |
| In reply to | #1413978 |
From: "Steven Rostedt (Red Hat)" <rostedt@goodmis.org> commit a29054d9478d0435ab01b7544da4f674ab13f533 upstream. If tracing contains data and the trace_pipe file is read with sendfile(), then it can trigger a NULL pointer dereference and various BUG_ON within the VM code. There's a patch to fix this in the splice_to_pipe() code, but it's also a good idea to not let that happen from trace_pipe either. Link: http://lkml.kernel.org/r/1457641146-9068-1-git-send-email-rabin@rab.in Cc: stable@vger.kernel.org # 2.6.30+ Reported-by: Rabin Vincent <rabin.vincent@gmail.com> Signed-off-by: Steven Rostedt <rostedt@goodmis.org> Signed-off-by: Willy Tarreau <w@1wt.eu> --- kernel/trace/trace.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/kernel/trace/trace.c b/kernel/trace/trace.c index 640e4c4..eff26a9 100644 --- a/kernel/trace/trace.c +++ b/kernel/trace/trace.c @@ -4351,7 +4351,10 @@ static ssize_t tracing_splice_read_pipe(struct file *filp, spd.nr_pages = i; - ret = splice_to_pipe(pipe, &spd); + if (i) + ret = splice_to_pipe(pipe, &spd); + else + ret = 0; out: splice_shrink_spd(&spd); return ret; -- 2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
Page 4 of 7 — ← Prev page 1 2 3 [4] 5 6 7 Next page →
Back to top | Article view | linux.kernel
csiph-web