Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1413978 > unrolled thread

[PATCH 3.10 000/143] 3.10.102-stable review

Started byWilly Tarreau <w@1wt.eu>
First post2016-06-05 12:30 +0200
Last post2016-06-08 07:30 +0200
Articles 20 on this page of 135 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 049/143] Input: ati_remote2 - fix crashes on detecting device with invalid descriptor Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 036/143] splice: handle zero nr_pages in splice_to_pipe() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 124/143] packet: fix heap info leak in PACKET_DIAG_MCLIST sock_diag interface Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 038/143] xtensa: clear all DBREAKC registers on start Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 016/143] be2iscsi: set the boot_kset pointer to NULL in case of failure Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 123/143] route: do not cache fib route info on local routes with oif Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 077/143] ext4: add lockdep annotations for i_data_sem Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 048/143] Input: ims-pcu - sanity check against missing interfaces Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 113/143] USB: serial: cp210x: add ID for Link ECU Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 046/143] tracing: Fix trace_printk() to print when not using bprintk() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 076/143] usb: renesas_usbhs: disable TX IRQ before starting TX DMAC transfer Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 106/143] clk: versatile: sp810: support reentrance Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 143/143] serial: samsung: Reorder the sequence of clock control when call s3c24xx_serial_set_termios() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 134/143] mfd: omap-usb-tll: Fix scheduling while atomic BUG Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 133/143] ring-buffer: Prevent overflow of size in ring_buffer_resize() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 061/143] ipv6: re-enable fragment header matching in ipv6_find_hdr Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 132/143] ring-buffer: Use long for nr_pages to avoid overflow failures Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 086/143] nl80211: check netlink protocol in socket release notification Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 006/143] KVM: i8254: change PIT discard tick policy Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 090/143] ASoC: s3c24xx: use const snd_soc_component_driver pointer Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 012/143] x86, processor-flags: Fix the datatypes and add bit number defines Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 085/143] crypto: gcm - Fix rfc4543 decryption crash Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 024/143] USB: serial: cp210x: Adding GE Healthcare Device ID Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 107/143] lpfc: fix misleading indentation Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 035/143] watchdog: rc32434_wdt: fix ioctl error handling Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 020/143] USB: usb_driver_claim_interface: add sanity checking Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 141/143] USB: serial: option: add support for Cinterion PH8 and AHxx Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 102/143] ARM: OMAP3: Add cpuidle parameters table for omap3430 Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 074/143] ip6_tunnel: set rtnl_link_ops before calling register_netdevice Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 008/143] EDAC, amd64_edac: Shift wrapping issue in f1x_get_norm_dct_addr() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
    [PATCH 3.10 028/143] net: irda: Fix use-after-free in irtty_open() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 064/143] udp6: fix UDP/IPv6 encap resubmit path Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 073/143] ipv6: l2tp: fix a potential issue in l2tp_ip6_recv Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 025/143] USB: option: add "D-Link DWM-221 B1" device id Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 138/143] USB: serial: keyspan: fix use-after-free in probe error path Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 027/143] Input: powermate - fix oops with malicious USB descriptors Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 087/143] Input: gtco - fix crash on detecting device without endpoints Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 080/143] [media] usbvision-video: fix memory leak of alt_max_pkt_size Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 122/143] decnet: Do not build routes to devices without decnet private data. Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 088/143] i2c: cpm: Fix build break due to incompatible pointer types Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 007/143] KVM: fix spin_lock_init order on x86 Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 098/143] drivers/misc/ad525x_dpot: AD5274 fix RDAC read back errors Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 116/143] powerpc: scan_features() updates incorrect bits for REAL_LE Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 051/143] ocfs2/dlm: fix BUG in dlm_move_lockres_to_recovery_list Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 063/143] usbnet: cleanup after bind() in probe() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 112/143] ACPICA: Dispatcher: Update thread ID for recursive method calls Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 083/143] usb: xhci: fix wild pointers in xhci_mem_cleanup Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 011/143] x86: Rename X86_CR4_RDWRGSFS to X86_CR4_FSGSBASE Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 053/143] sched/cputime: Fix steal time accounting vs. CPU hotplug Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 014/143] sg: fix dxferp in from_to case Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 121/143] ARM: OMAP3: Fix booting with thumb2 kernel Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 056/143] parisc: Avoid function pointers for kernel exception routines Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 130/143] net: fix a kernel infoleak in x25 module Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 115/143] Input: ads7846 - correct the value got from SPI Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 096/143] misc/bmp085: Enable building as a module Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 101/143] perf stat: Document --detailed option Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 103/143] compiler-gcc: disable -ftracer for __noclone functions Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 089/143] EDAC: i7core, sb_edac: Don't return NOTIFY_BAD from mce_decoder callback Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 120/143] asmlinkage, pnp: Make variables used from assembler code visible Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 109/143] proc: prevent accessing /proc/<PID>/environ until it's ready Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 079/143] drm/radeon: hold reference to fences in radeon_sa_bo_new (3.17 and older) Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
    [PATCH 3.10 021/143] USB: mct_u232: add sanity checking in probe Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 111/143] MAINTAINERS: Remove asterisk from EFI directory names Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 068/143] ath9k: fix buffer overrun for ar9287 Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 071/143] qmi_wwan: add "D-Link DWM-221 B1" device id Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 015/143] aacraid: Fix memory leak in aac_fib_map_free Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 117/143] crypto: hash - Fix page length clamping in hash walk Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 110/143] batman-adv: Fix broadcast/ogm queue limit on a removed interface Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 065/143] sh_eth: fix NULL pointer dereference in sh_eth_ring_format() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 137/143] Bluetooth: vhci: purge unhandled skbs Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 094/143] paride: make 'verbose' parameter an 'int' again Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 042/143] ipr: Fix regression when loading firmware Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 119/143] Input: max8997-haptic - fix NULL pointer dereference Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 052/143] mtd: onenand: fix deadlock in onenand_block_markbad Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 108/143] ARM: SoCFPGA: Fix secondary CPU startup in thumb2 kernel Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 099/143] include/linux/poison.h: fix LIST_POISON{1,2} offset Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 032/143] ALSA: intel8x0: Add clock quirk entry for AD1981B on IBM ThinkPad X41. Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 078/143] HID: usbhid: fix inconsistent reset/resume/reset-resume behavior Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 045/143] tracing: Fix crash from reading trace_pipe with sendfile Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 005/143] x86: LLVMLinux: Fix "incomplete type const struct x86cpu_device_id" Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 070/143] ppp: take reference on channels netns Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 135/143] mmc: mmc: Fix partition switch timeout for some eMMCs Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 067/143] farsync: fix off-by-one bug in fst_add_one Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 039/143] md/raid5: Compare apples to apples (or sectors to sectors) Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 131/143] fs/cifs: correctly to anonymous authentication via NTLMSSP Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 082/143] usbvision: fix crash on detecting device with invalid configuration Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 041/143] ipr: Fix out-of-bounds null overwrite Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 019/143] USB: iowarrior: fix oops with malicious USB descriptors Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 092/143] workqueue: fix ghost PENDING flag while doing MQ IO Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 127/143] net: fix infoleak in rtnetlink Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 013/143] x86/iopl: Fix iopl capability check on Xen PV Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 129/143] net: bridge: fix old ioctl unlocked net device walk Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 126/143] net: fix infoleak in llc Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 100/143] Drivers: hv: vmbus: prevent cpu offlining on newer hypervisors Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 002/143] x86/iopl/64: Properly context-switch IOPL on Xen PV Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 029/143] 8250: use callbacks to access UART_DLL/UART_DLM Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 139/143] USB: serial: quatech2: fix use-after-free in probe error path Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
    [PATCH 3.10 001/143] pipe: Fix buffer offset after partially failed read Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 010/143] linux/const.h: Add _BITUL() and _BITULL() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 026/143] pwc: Add USB id for Philips Spc880nc webcam Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 057/143] parisc: Fix kernel crash with reversed copy_from_user() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 031/143] media: v4l2-compat-ioctl32: fix missing length copy in put_v4l2_buffer32 Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 084/143] usb: hcd: out of bounds access in for_each_companion Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 069/143] qlge: Fix receive packets drop. Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 142/143] tty: vt, return error when con_startup fails Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 136/143] mmc: longer timeout for long read time quirk Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 037/143] xtensa: ISS: don't hang if stdin EOF is reached Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 017/143] usb: retry reset if a device times out Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 097/143] rtc: vr41xx: Wire up alarm_irq_enable Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 003/143] ext4: fix NULL pointer dereference in ext4_mark_inode_dirty() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 018/143] USB: cdc-acm: more sanity checking Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 044/143] tracing: Have preempt(irqs)off trace preempt disabled functions Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 040/143] rapidio/rionet: fix deadlock on SMP Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 066/143] net: Fix use after free in the recvmmsg exit path Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 091/143] efi: Fix out-of-bounds read in variable_matches() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 072/143] ipv4: l2tp: fix a potential issue in l2tp_ip_recv Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 033/143] jbd2: fix FS corruption possibility in jbd2_journal_destroy() on umount path Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 034/143] bcache: fix cache_set_flush() NULL pointer dereference on OOM Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 062/143] cdc_ncm: toggle altsetting to force reset before setup Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 075/143] usb: renesas_usbhs: avoid NULL pointer derefernce in usbhsf_pkt_handler() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 093/143] USB: usbip: fix potential out-of-bounds write Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 043/143] drm/radeon: Don't drop DP 2.7 Ghz link setup on some cards. Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 125/143] atl2: Disable unimplemented scatter/gather feature Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    [PATCH 3.10 009/143] PCI: Disable IO/MEM decoding for devices with non-compliant BARs Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
    Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-07 05:50 +0200
      Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-07 06:20 +0200
        Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-07 06:40 +0200
          Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-07 07:20 +0200
            Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-07 08:00 +0200
              Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-07 09:00 +0200
                Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-07 20:00 +0200
                  Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-07 20:30 +0200
                  Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-08 03:00 +0200
                    Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-08 07:30 +0200

Page 5 of 7 — ← Prev page 1 2 3 4 [5] 6 7  Next page →


#1414062 — [PATCH 3.10 005/143] x86: LLVMLinux: Fix "incomplete type const struct x86cpu_device_id"

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 005/143] x86: LLVMLinux: Fix "incomplete type const struct x86cpu_device_id"
Message-ID<rGDN0-5Ef-29@gated-at.bofh.it>
In reply to#1413978
From: Behan Webster <behanw@converseincode.com>

commit c4586256f0c440bc2bdb29d2cbb915f0ca785d26 upstream.

Similar to the fix in 40413dcb7b273bda681dca38e6ff0bbb3728ef11

MODULE_DEVICE_TABLE(x86cpu, ...) expects the struct to be called struct
x86cpu_device_id, and not struct x86_cpu_id which is what is used in the rest
of the kernel code.  Although gcc seems to ignore this error, clang fails
without this define to fix the name.

Code from drivers/thermal/x86_pkg_temp_thermal.c
static const struct x86_cpu_id __initconst pkg_temp_thermal_ids[] = { ... };
MODULE_DEVICE_TABLE(x86cpu, pkg_temp_thermal_ids);

Error from clang:
drivers/thermal/x86_pkg_temp_thermal.c:577:1: error: variable has
      incomplete type 'const struct x86cpu_device_id'
MODULE_DEVICE_TABLE(x86cpu, pkg_temp_thermal_ids);
^
include/linux/module.h:145:3: note: expanded from macro
      'MODULE_DEVICE_TABLE'
  MODULE_GENERIC_TABLE(type##_device, name)
  ^
include/linux/module.h:87:32: note: expanded from macro
      'MODULE_GENERIC_TABLE'
extern const struct gtype##_id __mod_##gtype##_table            \
                               ^
<scratch space>:143:1: note: expanded from here
__mod_x86cpu_device_table
^
drivers/thermal/x86_pkg_temp_thermal.c:577:1: note: forward declaration of
      'struct x86cpu_device_id'
include/linux/module.h:145:3: note: expanded from macro
      'MODULE_DEVICE_TABLE'
  MODULE_GENERIC_TABLE(type##_device, name)
  ^
include/linux/module.h:87:21: note: expanded from macro
      'MODULE_GENERIC_TABLE'
extern const struct gtype##_id __mod_##gtype##_table            \
                    ^
<scratch space>:141:1: note: expanded from here
x86cpu_device_id
^
1 error generated.

Signed-off-by: Behan Webster <behanw@converseincode.com>
Signed-off-by: Jan-Simon Möller <dl9pf@gmx.de>
Acked-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: philm@manjaro.org
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 include/linux/mod_devicetable.h | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/include/linux/mod_devicetable.h b/include/linux/mod_devicetable.h
index b3bd7e7..d313648 100644
--- a/include/linux/mod_devicetable.h
+++ b/include/linux/mod_devicetable.h
@@ -397,6 +397,7 @@ struct virtio_device_id {
 /*
  * For Hyper-V devices we use the device guid as the id.
  */
+#define vmbus_device_id hv_vmbus_device_id
 struct hv_vmbus_device_id {
 	__u8 guid[16];
 	kernel_ulong_t driver_data;	/* Data private to the driver */
@@ -547,6 +548,11 @@ struct amba_id {
  * See documentation of "x86_match_cpu" for details.
  */
 
+/*
+ * MODULE_DEVICE_TABLE expects this struct to be called x86cpu_device_id.
+ * Although gcc seems to ignore this error, clang fails without this define.
+ */
+#define x86cpu_device_id x86_cpu_id
 struct x86_cpu_id {
 	__u16 vendor;
 	__u16 family;
@@ -574,6 +580,7 @@ struct ipack_device_id {
 #define MEI_CL_MODULE_PREFIX "mei:"
 #define MEI_CL_NAME_SIZE 32
 
+#define mei_device_id mei_cl_device_id
 struct mei_cl_device_id {
 	char name[MEI_CL_NAME_SIZE];
 	kernel_ulong_t driver_info;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414063 — [PATCH 3.10 070/143] ppp: take reference on channels netns

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 070/143] ppp: take reference on channels netns
Message-ID<rGDN1-5Ef-39@gated-at.bofh.it>
In reply to#1413978
From: Guillaume Nault <g.nault@alphalink.fr>

commit 1f461dcdd296eecedaffffc6bae2bfa90bd7eb89 upstream.

Let channels hold a reference on their network namespace.
Some channel types, like ppp_async and ppp_synctty, can have their
userspace controller running in a different namespace. Therefore they
can't rely on them to preclude their netns from being removed from
under them.

==================================================================
BUG: KASAN: use-after-free in ppp_unregister_channel+0x372/0x3a0 at
addr ffff880064e217e0
Read of size 8 by task syz-executor/11581
=============================================================================
BUG net_namespace (Not tainted): kasan: bad access detected
-----------------------------------------------------------------------------

Disabling lock debugging due to kernel taint
INFO: Allocated in copy_net_ns+0x6b/0x1a0 age=92569 cpu=3 pid=6906
[<      none      >] ___slab_alloc+0x4c7/0x500 kernel/mm/slub.c:2440
[<      none      >] __slab_alloc+0x4c/0x90 kernel/mm/slub.c:2469
[<     inline     >] slab_alloc_node kernel/mm/slub.c:2532
[<     inline     >] slab_alloc kernel/mm/slub.c:2574
[<      none      >] kmem_cache_alloc+0x23a/0x2b0 kernel/mm/slub.c:2579
[<     inline     >] kmem_cache_zalloc kernel/include/linux/slab.h:597
[<     inline     >] net_alloc kernel/net/core/net_namespace.c:325
[<      none      >] copy_net_ns+0x6b/0x1a0 kernel/net/core/net_namespace.c:360
[<      none      >] create_new_namespaces+0x2f6/0x610 kernel/kernel/nsproxy.c:95
[<      none      >] copy_namespaces+0x297/0x320 kernel/kernel/nsproxy.c:150
[<      none      >] copy_process.part.35+0x1bf4/0x5760 kernel/kernel/fork.c:1451
[<     inline     >] copy_process kernel/kernel/fork.c:1274
[<      none      >] _do_fork+0x1bc/0xcb0 kernel/kernel/fork.c:1723
[<     inline     >] SYSC_clone kernel/kernel/fork.c:1832
[<      none      >] SyS_clone+0x37/0x50 kernel/kernel/fork.c:1826
[<      none      >] entry_SYSCALL_64_fastpath+0x16/0x7a kernel/arch/x86/entry/entry_64.S:185

INFO: Freed in net_drop_ns+0x67/0x80 age=575 cpu=2 pid=2631
[<      none      >] __slab_free+0x1fc/0x320 kernel/mm/slub.c:2650
[<     inline     >] slab_free kernel/mm/slub.c:2805
[<      none      >] kmem_cache_free+0x2a0/0x330 kernel/mm/slub.c:2814
[<     inline     >] net_free kernel/net/core/net_namespace.c:341
[<      none      >] net_drop_ns+0x67/0x80 kernel/net/core/net_namespace.c:348
[<      none      >] cleanup_net+0x4e5/0x600 kernel/net/core/net_namespace.c:448
[<      none      >] process_one_work+0x794/0x1440 kernel/kernel/workqueue.c:2036
[<      none      >] worker_thread+0xdb/0xfc0 kernel/kernel/workqueue.c:2170
[<      none      >] kthread+0x23f/0x2d0 kernel/drivers/block/aoe/aoecmd.c:1303
[<      none      >] ret_from_fork+0x3f/0x70 kernel/arch/x86/entry/entry_64.S:468
INFO: Slab 0xffffea0001938800 objects=3 used=0 fp=0xffff880064e20000
flags=0x5fffc0000004080
INFO: Object 0xffff880064e20000 @offset=0 fp=0xffff880064e24200

CPU: 1 PID: 11581 Comm: syz-executor Tainted: G    B           4.4.0+
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
rel-1.8.2-0-g33fbe13 by qemu-project.org 04/01/2014
 00000000ffffffff ffff8800662c7790 ffffffff8292049d ffff88003e36a300
 ffff880064e20000 ffff880064e20000 ffff8800662c77c0 ffffffff816f2054
 ffff88003e36a300 ffffea0001938800 ffff880064e20000 0000000000000000
Call Trace:
 [<     inline     >] __dump_stack kernel/lib/dump_stack.c:15
 [<ffffffff8292049d>] dump_stack+0x6f/0xa2 kernel/lib/dump_stack.c:50
 [<ffffffff816f2054>] print_trailer+0xf4/0x150 kernel/mm/slub.c:654
 [<ffffffff816f875f>] object_err+0x2f/0x40 kernel/mm/slub.c:661
 [<     inline     >] print_address_description kernel/mm/kasan/report.c:138
 [<ffffffff816fb0c5>] kasan_report_error+0x215/0x530 kernel/mm/kasan/report.c:236
 [<     inline     >] kasan_report kernel/mm/kasan/report.c:259
 [<ffffffff816fb4de>] __asan_report_load8_noabort+0x3e/0x40 kernel/mm/kasan/report.c:280
 [<     inline     >] ? ppp_pernet kernel/include/linux/compiler.h:218
 [<ffffffff83ad71b2>] ? ppp_unregister_channel+0x372/0x3a0 kernel/drivers/net/ppp/ppp_generic.c:2392
 [<     inline     >] ppp_pernet kernel/include/linux/compiler.h:218
 [<ffffffff83ad71b2>] ppp_unregister_channel+0x372/0x3a0 kernel/drivers/net/ppp/ppp_generic.c:2392
 [<     inline     >] ? ppp_pernet kernel/drivers/net/ppp/ppp_generic.c:293
 [<ffffffff83ad6f26>] ? ppp_unregister_channel+0xe6/0x3a0 kernel/drivers/net/ppp/ppp_generic.c:2392
 [<ffffffff83ae18f3>] ppp_asynctty_close+0xa3/0x130 kernel/drivers/net/ppp/ppp_async.c:241
 [<ffffffff83ae1850>] ? async_lcp_peek+0x5b0/0x5b0 kernel/drivers/net/ppp/ppp_async.c:1000
 [<ffffffff82c33239>] tty_ldisc_close.isra.1+0x99/0xe0 kernel/drivers/tty/tty_ldisc.c:478
 [<ffffffff82c332c0>] tty_ldisc_kill+0x40/0x170 kernel/drivers/tty/tty_ldisc.c:744
 [<ffffffff82c34943>] tty_ldisc_release+0x1b3/0x260 kernel/drivers/tty/tty_ldisc.c:772
 [<ffffffff82c1ef21>] tty_release+0xac1/0x13e0 kernel/drivers/tty/tty_io.c:1901
 [<ffffffff82c1e460>] ? release_tty+0x320/0x320 kernel/drivers/tty/tty_io.c:1688
 [<ffffffff8174de36>] __fput+0x236/0x780 kernel/fs/file_table.c:208
 [<ffffffff8174e405>] ____fput+0x15/0x20 kernel/fs/file_table.c:244
 [<ffffffff813595ab>] task_work_run+0x16b/0x200 kernel/kernel/task_work.c:115
 [<     inline     >] exit_task_work kernel/include/linux/task_work.h:21
 [<ffffffff81307105>] do_exit+0x8b5/0x2c60 kernel/kernel/exit.c:750
 [<ffffffff813fdd20>] ? debug_check_no_locks_freed+0x290/0x290 kernel/kernel/locking/lockdep.c:4123
 [<ffffffff81306850>] ? mm_update_next_owner+0x6f0/0x6f0 kernel/kernel/exit.c:357
 [<ffffffff813215e6>] ? __dequeue_signal+0x136/0x470 kernel/kernel/signal.c:550
 [<ffffffff8132067b>] ? recalc_sigpending_tsk+0x13b/0x180 kernel/kernel/signal.c:145
 [<ffffffff81309628>] do_group_exit+0x108/0x330 kernel/kernel/exit.c:880
 [<ffffffff8132b9d4>] get_signal+0x5e4/0x14f0 kernel/kernel/signal.c:2307
 [<     inline     >] ? kretprobe_table_lock kernel/kernel/kprobes.c:1113
 [<ffffffff8151d355>] ? kprobe_flush_task+0xb5/0x450 kernel/kernel/kprobes.c:1158
 [<ffffffff8115f7d3>] do_signal+0x83/0x1c90 kernel/arch/x86/kernel/signal.c:712
 [<ffffffff8151d2a0>] ? recycle_rp_inst+0x310/0x310 kernel/include/linux/list.h:655
 [<ffffffff8115f750>] ? setup_sigcontext+0x780/0x780 kernel/arch/x86/kernel/signal.c:165
 [<ffffffff81380864>] ? finish_task_switch+0x424/0x5f0 kernel/kernel/sched/core.c:2692
 [<     inline     >] ? finish_lock_switch kernel/kernel/sched/sched.h:1099
 [<ffffffff81380560>] ? finish_task_switch+0x120/0x5f0 kernel/kernel/sched/core.c:2678
 [<     inline     >] ? context_switch kernel/kernel/sched/core.c:2807
 [<ffffffff85d794e9>] ? __schedule+0x919/0x1bd0 kernel/kernel/sched/core.c:3283
 [<ffffffff81003901>] exit_to_usermode_loop+0xf1/0x1a0 kernel/arch/x86/entry/common.c:247
 [<     inline     >] prepare_exit_to_usermode kernel/arch/x86/entry/common.c:282
 [<ffffffff810062ef>] syscall_return_slowpath+0x19f/0x210 kernel/arch/x86/entry/common.c:344
 [<ffffffff85d88022>] int_ret_from_sys_call+0x25/0x9f kernel/arch/x86/entry/entry_64.S:281
Memory state around the buggy address:
 ffff880064e21680: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
 ffff880064e21700: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
>ffff880064e21780: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
                                                       ^
 ffff880064e21800: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
 ffff880064e21880: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
==================================================================

Fixes: 273ec51dd7ce ("net: ppp_generic - introduce net-namespace functionality v2")
Reported-by: Baozeng Ding <sploving1@gmail.com>
Signed-off-by: Guillaume Nault <g.nault@alphalink.fr>
Reviewed-by: Cyrill Gorcunov <gorcunov@openvz.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/net/ppp/ppp_generic.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ppp/ppp_generic.c b/drivers/net/ppp/ppp_generic.c
index a2d7d5f..14a8d29 100644
--- a/drivers/net/ppp/ppp_generic.c
+++ b/drivers/net/ppp/ppp_generic.c
@@ -2220,7 +2220,7 @@ int ppp_register_net_channel(struct net *net, struct ppp_channel *chan)
 
 	pch->ppp = NULL;
 	pch->chan = chan;
-	pch->chan_net = net;
+	pch->chan_net = get_net(net);
 	chan->ppp = pch;
 	init_ppp_file(&pch->file, CHANNEL);
 	pch->file.hdrlen = chan->hdrlen;
@@ -2317,6 +2317,8 @@ ppp_unregister_channel(struct ppp_channel *chan)
 	spin_lock_bh(&pn->all_channels_lock);
 	list_del(&pch->list);
 	spin_unlock_bh(&pn->all_channels_lock);
+	put_net(pch->chan_net);
+	pch->chan_net = NULL;
 
 	pch->file.dead = 1;
 	wake_up_interruptible(&pch->file.rwait);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414064 — [PATCH 3.10 135/143] mmc: mmc: Fix partition switch timeout for some eMMCs

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 135/143] mmc: mmc: Fix partition switch timeout for some eMMCs
Message-ID<rGDN1-5Ef-41@gated-at.bofh.it>
In reply to#1413978
From: Adrian Hunter <adrian.hunter@intel.com>

commit 1c447116d017a98c90f8f71c8c5a611e0aa42178 upstream.

Some eMMCs set the partition switch timeout too low.

Now typically eMMCs are considered a critical component (e.g. because
they store the root file system) and consequently are expected to be
reliable.  Thus we can neglect the use case where eMMCs can't switch
reliably and we might want a lower timeout to facilitate speedy
recovery.

Although we could employ a quirk for the cards that are affected (if
we could identify them all), as described above, there is little
benefit to having a low timeout, so instead simply set a minimum
timeout.

The minimum is set to 300ms somewhat arbitrarily - the examples that
have been seen had a timeout of 10ms but were sometimes taking 60-70ms.

Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/mmc/core/mmc.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/drivers/mmc/core/mmc.c b/drivers/mmc/core/mmc.c
index 0cbd1ef..dda1a42 100644
--- a/drivers/mmc/core/mmc.c
+++ b/drivers/mmc/core/mmc.c
@@ -266,6 +266,9 @@ static void mmc_select_card_type(struct mmc_card *card)
 	card->ext_csd.card_type = card_type;
 }
 
+/* Minimum partition switch timeout in milliseconds */
+#define MMC_MIN_PART_SWITCH_TIME	300
+
 /*
  * Decode extended CSD.
  */
@@ -330,6 +333,10 @@ static int mmc_read_ext_csd(struct mmc_card *card, u8 *ext_csd)
 
 		/* EXT_CSD value is in units of 10ms, but we store in ms */
 		card->ext_csd.part_time = 10 * ext_csd[EXT_CSD_PART_SWITCH_TIME];
+		/* Some eMMC set the value too low so set a minimum */
+		if (card->ext_csd.part_time &&
+		    card->ext_csd.part_time < MMC_MIN_PART_SWITCH_TIME)
+			card->ext_csd.part_time = MMC_MIN_PART_SWITCH_TIME;
 
 		/* Sleep / awake timeout in 100ns units */
 		if (sa_shift > 0 && sa_shift <= 0x17)
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414065 — [PATCH 3.10 067/143] farsync: fix off-by-one bug in fst_add_one

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 067/143] farsync: fix off-by-one bug in fst_add_one
Message-ID<rGDN1-5Ef-43@gated-at.bofh.it>
In reply to#1413978
From: Arnd Bergmann <arnd@arndb.de>

commit e725a66c0202b5f36c2f9d59d26a65c53bbf21f7 upstream.

gcc-6 finds an out of bounds access in the fst_add_one function
when calculating the end of the mmio area:

drivers/net/wan/farsync.c: In function 'fst_add_one':
drivers/net/wan/farsync.c:418:53: error: index 2 denotes an offset greater than size of 'u8[2][8192] {aka unsigned char[2][8192]}' [-Werror=array-bounds]
 #define BUF_OFFSET(X)   (BFM_BASE + offsetof(struct buf_window, X))
                                                     ^
include/linux/compiler-gcc.h:158:21: note: in definition of macro '__compiler_offsetof'
  __builtin_offsetof(a, b)
                     ^
drivers/net/wan/farsync.c:418:37: note: in expansion of macro 'offsetof'
 #define BUF_OFFSET(X)   (BFM_BASE + offsetof(struct buf_window, X))
                                     ^~~~~~~~
drivers/net/wan/farsync.c:2519:36: note: in expansion of macro 'BUF_OFFSET'
                                  + BUF_OFFSET ( txBuffer[i][NUM_TX_BUFFER][0]);
                                    ^~~~~~~~~~

The warning is correct, but not critical because this appears
to be a write-only variable that is set by each WAN driver but
never accessed afterwards.

I'm taking the minimal fix here, using the correct pointer by
pointing 'mem_end' to the last byte inside of the register area
as all other WAN drivers do, rather than the first byte outside of
it. An alternative would be to just remove the mem_end member
entirely.

Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/net/wan/farsync.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/wan/farsync.c b/drivers/net/wan/farsync.c
index bcfff0d..2dfa147 100644
--- a/drivers/net/wan/farsync.c
+++ b/drivers/net/wan/farsync.c
@@ -2545,7 +2545,7 @@ fst_add_one(struct pci_dev *pdev, const struct pci_device_id *ent)
                 dev->mem_start   = card->phys_mem
                                  + BUF_OFFSET ( txBuffer[i][0][0]);
                 dev->mem_end     = card->phys_mem
-                                 + BUF_OFFSET ( txBuffer[i][NUM_TX_BUFFER][0]);
+                                 + BUF_OFFSET ( txBuffer[i][NUM_TX_BUFFER - 1][LEN_RX_BUFFER - 1]);
                 dev->base_addr   = card->pci_conf;
                 dev->irq         = card->irq;
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414066 — [PATCH 3.10 039/143] md/raid5: Compare apples to apples (or sectors to sectors)

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 039/143] md/raid5: Compare apples to apples (or sectors to sectors)
Message-ID<rGDN1-5Ef-45@gated-at.bofh.it>
In reply to#1413978
From: Jes Sorensen <Jes.Sorensen@redhat.com>

commit e7597e69dec59b65c5525db1626b9d34afdfa678 upstream.

'max_discard_sectors' is in sectors, while 'stripe' is in bytes.

This fixes the problem where DISCARD would get disabled on some larger
RAID5 configurations (6 or more drives in my testing), while it worked
as expected with smaller configurations.

Fixes: 620125f2bf8 ("MD: raid5 trim support")
Cc: stable@vger.kernel.org v3.7+
Signed-off-by: Jes Sorensen <Jes.Sorensen@redhat.com>
Signed-off-by: Shaohua Li <shli@fb.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/md/raid5.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/md/raid5.c b/drivers/md/raid5.c
index ef18ca7..9ee3c46 100644
--- a/drivers/md/raid5.c
+++ b/drivers/md/raid5.c
@@ -5658,8 +5658,8 @@ static int run(struct mddev *mddev)
 		}
 
 		if (discard_supported &&
-		   mddev->queue->limits.max_discard_sectors >= stripe &&
-		   mddev->queue->limits.discard_granularity >= stripe)
+		    mddev->queue->limits.max_discard_sectors >= (stripe >> 9) &&
+		    mddev->queue->limits.discard_granularity >= stripe)
 			queue_flag_set_unlocked(QUEUE_FLAG_DISCARD,
 						mddev->queue);
 		else
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414067 — [PATCH 3.10 131/143] fs/cifs: correctly to anonymous authentication via NTLMSSP

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 131/143] fs/cifs: correctly to anonymous authentication via NTLMSSP
Message-ID<rGDN1-5Ef-49@gated-at.bofh.it>
In reply to#1413978
From: Stefan Metzmacher <metze@samba.org>

commit cfda35d98298131bf38fbad3ce4cd5ecb3cf18db upstream.

See [MS-NLMP] 3.2.5.1.2 Server Receives an AUTHENTICATE_MESSAGE from the Client:

   ...
   Set NullSession to FALSE
   If (AUTHENTICATE_MESSAGE.UserNameLen == 0 AND
      AUTHENTICATE_MESSAGE.NtChallengeResponse.Length == 0 AND
      (AUTHENTICATE_MESSAGE.LmChallengeResponse == Z(1)
       OR
       AUTHENTICATE_MESSAGE.LmChallengeResponse.Length == 0))
       -- Special case: client requested anonymous authentication
       Set NullSession to TRUE
   ...

Only server which map unknown users to guest will allow
access using a non-null NTChallengeResponse.

For Samba it's the "map to guest = bad user" option.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=11913

CC: Stable <stable@vger.kernel.org>
Signed-off-by: Stefan Metzmacher <metze@samba.org>
Signed-off-by: Steve French <smfrench@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/cifs/sess.c | 32 ++++++++++++++++++++------------
 1 file changed, 20 insertions(+), 12 deletions(-)

diff --git a/fs/cifs/sess.c b/fs/cifs/sess.c
index 8edc9eb..d65e16e 100644
--- a/fs/cifs/sess.c
+++ b/fs/cifs/sess.c
@@ -487,19 +487,27 @@ int build_ntlmssp_auth_blob(unsigned char *pbuffer,
 	sec_blob->LmChallengeResponse.MaximumLength = 0;
 
 	sec_blob->NtChallengeResponse.BufferOffset = cpu_to_le32(tmp - pbuffer);
-	rc = setup_ntlmv2_rsp(ses, nls_cp);
-	if (rc) {
-		cifs_dbg(VFS, "Error %d during NTLMSSP authentication\n", rc);
-		goto setup_ntlmv2_ret;
-	}
-	memcpy(tmp, ses->auth_key.response + CIFS_SESS_KEY_SIZE,
-			ses->auth_key.len - CIFS_SESS_KEY_SIZE);
-	tmp += ses->auth_key.len - CIFS_SESS_KEY_SIZE;
+	if (ses->user_name != NULL) {
+		rc = setup_ntlmv2_rsp(ses, nls_cp);
+		if (rc) {
+			cifs_dbg(VFS, "Error %d during NTLMSSP authentication\n", rc);
+			goto setup_ntlmv2_ret;
+		}
+		memcpy(tmp, ses->auth_key.response + CIFS_SESS_KEY_SIZE,
+				ses->auth_key.len - CIFS_SESS_KEY_SIZE);
+		tmp += ses->auth_key.len - CIFS_SESS_KEY_SIZE;
 
-	sec_blob->NtChallengeResponse.Length =
-			cpu_to_le16(ses->auth_key.len - CIFS_SESS_KEY_SIZE);
-	sec_blob->NtChallengeResponse.MaximumLength =
-			cpu_to_le16(ses->auth_key.len - CIFS_SESS_KEY_SIZE);
+		sec_blob->NtChallengeResponse.Length =
+				cpu_to_le16(ses->auth_key.len - CIFS_SESS_KEY_SIZE);
+		sec_blob->NtChallengeResponse.MaximumLength =
+				cpu_to_le16(ses->auth_key.len - CIFS_SESS_KEY_SIZE);
+	} else {
+		/*
+		 * don't send an NT Response for anonymous access
+		 */
+		sec_blob->NtChallengeResponse.Length = 0;
+		sec_blob->NtChallengeResponse.MaximumLength = 0;
+	}
 
 	if (ses->domainName == NULL) {
 		sec_blob->DomainName.BufferOffset = cpu_to_le32(tmp - pbuffer);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414068 — [PATCH 3.10 082/143] usbvision: fix crash on detecting device with invalid configuration

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 082/143] usbvision: fix crash on detecting device with invalid configuration
Message-ID<rGDN1-5Ef-51@gated-at.bofh.it>
In reply to#1413978
From: Vladis Dronov <vdronov@redhat.com>

commit fa52bd506f274b7619955917abfde355e3d19ffe upstream.

The usbvision driver crashes when a specially crafted usb device with invalid
number of interfaces or endpoints is detected. This fix adds checks that the
device has proper configuration expected by the driver.

Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/media/usb/usbvision/usbvision-video.c | 16 +++++++++++++++-
 1 file changed, 15 insertions(+), 1 deletion(-)

diff --git a/drivers/media/usb/usbvision/usbvision-video.c b/drivers/media/usb/usbvision/usbvision-video.c
index 017f4d1..bcfefe6 100644
--- a/drivers/media/usb/usbvision/usbvision-video.c
+++ b/drivers/media/usb/usbvision/usbvision-video.c
@@ -1538,9 +1538,23 @@ static int usbvision_probe(struct usb_interface *intf,
 
 	if (usbvision_device_data[model].interface >= 0)
 		interface = &dev->actconfig->interface[usbvision_device_data[model].interface]->altsetting[0];
-	else
+	else if (ifnum < dev->actconfig->desc.bNumInterfaces)
 		interface = &dev->actconfig->interface[ifnum]->altsetting[0];
+	else {
+		dev_err(&intf->dev, "interface %d is invalid, max is %d\n",
+		    ifnum, dev->actconfig->desc.bNumInterfaces - 1);
+		ret = -ENODEV;
+		goto err_usb;
+	}
+
+	if (interface->desc.bNumEndpoints < 2) {
+		dev_err(&intf->dev, "interface %d has %d endpoints, but must"
+		    " have minimum 2\n", ifnum, interface->desc.bNumEndpoints);
+		ret = -ENODEV;
+		goto err_usb;
+	}
 	endpoint = &interface->endpoint[1].desc;
+
 	if (!usb_endpoint_xfer_isoc(endpoint)) {
 		dev_err(&intf->dev, "%s: interface %d. has non-ISO endpoint!\n",
 		    __func__, ifnum);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414069 — [PATCH 3.10 041/143] ipr: Fix out-of-bounds null overwrite

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 041/143] ipr: Fix out-of-bounds null overwrite
Message-ID<rGDN1-5Ef-53@gated-at.bofh.it>
In reply to#1413978
From: Insu Yun <wuninsu@gmail.com>

commit d63c7dd5bcb9441af0526d370c43a65ca2c980d9 upstream.

Return value of snprintf is not bound by size value, 2nd argument.
(https://www.kernel.org/doc/htmldocs/kernel-api/API-snprintf.html).
Return value is number of printed chars, can be larger than 2nd
argument.  Therefore, it can write null byte out of bounds ofbuffer.
Since snprintf puts null, it does not need to put additional null byte.

Signed-off-by: Insu Yun <wuninsu@gmail.com>
Reviewed-by: Shane Seymour <shane.seymour@hpe.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/scsi/ipr.c | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/drivers/scsi/ipr.c b/drivers/scsi/ipr.c
index 4a79a5f..bde4771 100644
--- a/drivers/scsi/ipr.c
+++ b/drivers/scsi/ipr.c
@@ -3908,13 +3908,12 @@ static ssize_t ipr_store_update_fw(struct device *dev,
 	struct ipr_sglist *sglist;
 	char fname[100];
 	char *src;
-	int len, result, dnld_size;
+	int result, dnld_size;
 
 	if (!capable(CAP_SYS_ADMIN))
 		return -EACCES;
 
-	len = snprintf(fname, 99, "%s", buf);
-	fname[len-1] = '\0';
+	snprintf(fname, sizeof(fname), "%s", buf);
 
 	if (request_firmware(&fw_entry, fname, &ioa_cfg->pdev->dev)) {
 		dev_err(&ioa_cfg->pdev->dev, "Firmware file %s not found\n", fname);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414070 — [PATCH 3.10 019/143] USB: iowarrior: fix oops with malicious USB descriptors

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 019/143] USB: iowarrior: fix oops with malicious USB descriptors
Message-ID<rGDN1-5Ef-57@gated-at.bofh.it>
In reply to#1413978
From: Josh Boyer <jwboyer@fedoraproject.org>

commit 4ec0ef3a82125efc36173062a50624550a900ae0 upstream.

The iowarrior driver expects at least one valid endpoint.  If given
malicious descriptors that specify 0 for the number of endpoints,
it will crash in the probe function.  Ensure there is at least
one endpoint on the interface before using it.

The full report of this issue can be found here:
http://seclists.org/bugtraq/2016/Mar/87

Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Cc: stable <stable@vger.kernel.org>
Signed-off-by: Josh Boyer <jwboyer@fedoraproject.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/misc/iowarrior.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/usb/misc/iowarrior.c b/drivers/usb/misc/iowarrior.c
index d36f34e..4c24ba0 100644
--- a/drivers/usb/misc/iowarrior.c
+++ b/drivers/usb/misc/iowarrior.c
@@ -792,6 +792,12 @@ static int iowarrior_probe(struct usb_interface *interface,
 	iface_desc = interface->cur_altsetting;
 	dev->product_id = le16_to_cpu(udev->descriptor.idProduct);
 
+	if (iface_desc->desc.bNumEndpoints < 1) {
+		dev_err(&interface->dev, "Invalid number of endpoints\n");
+		retval = -EINVAL;
+		goto error;
+	}
+
 	/* set up the endpoint information */
 	for (i = 0; i < iface_desc->desc.bNumEndpoints; ++i) {
 		endpoint = &iface_desc->endpoint[i].desc;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414071 — [PATCH 3.10 092/143] workqueue: fix ghost PENDING flag while doing MQ IO

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 092/143] workqueue: fix ghost PENDING flag while doing MQ IO
Message-ID<rGDN1-5Ef-59@gated-at.bofh.it>
In reply to#1413978
From: Roman Pen <roman.penyaev@profitbricks.com>

commit 346c09f80459a3ad97df1816d6d606169a51001a upstream.

The bug in a workqueue leads to a stalled IO request in MQ ctx->rq_list
with the following backtrace:

[  601.347452] INFO: task kworker/u129:5:1636 blocked for more than 120 seconds.
[  601.347574]       Tainted: G           O    4.4.5-1-storage+ #6
[  601.347651] "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
[  601.348142] kworker/u129:5  D ffff880803077988     0  1636      2 0x00000000
[  601.348519] Workqueue: ibnbd_server_fileio_wq ibnbd_dev_file_submit_io_worker [ibnbd_server]
[  601.348999]  ffff880803077988 ffff88080466b900 ffff8808033f9c80 ffff880803078000
[  601.349662]  ffff880807c95000 7fffffffffffffff ffffffff815b0920 ffff880803077ad0
[  601.350333]  ffff8808030779a0 ffffffff815b01d5 0000000000000000 ffff880803077a38
[  601.350965] Call Trace:
[  601.351203]  [<ffffffff815b0920>] ? bit_wait+0x60/0x60
[  601.351444]  [<ffffffff815b01d5>] schedule+0x35/0x80
[  601.351709]  [<ffffffff815b2dd2>] schedule_timeout+0x192/0x230
[  601.351958]  [<ffffffff812d43f7>] ? blk_flush_plug_list+0xc7/0x220
[  601.352208]  [<ffffffff810bd737>] ? ktime_get+0x37/0xa0
[  601.352446]  [<ffffffff815b0920>] ? bit_wait+0x60/0x60
[  601.352688]  [<ffffffff815af784>] io_schedule_timeout+0xa4/0x110
[  601.352951]  [<ffffffff815b3a4e>] ? _raw_spin_unlock_irqrestore+0xe/0x10
[  601.353196]  [<ffffffff815b093b>] bit_wait_io+0x1b/0x70
[  601.353440]  [<ffffffff815b056d>] __wait_on_bit+0x5d/0x90
[  601.353689]  [<ffffffff81127bd0>] wait_on_page_bit+0xc0/0xd0
[  601.353958]  [<ffffffff81096db0>] ? autoremove_wake_function+0x40/0x40
[  601.354200]  [<ffffffff81127cc4>] __filemap_fdatawait_range+0xe4/0x140
[  601.354441]  [<ffffffff81127d34>] filemap_fdatawait_range+0x14/0x30
[  601.354688]  [<ffffffff81129a9f>] filemap_write_and_wait_range+0x3f/0x70
[  601.354932]  [<ffffffff811ced3b>] blkdev_fsync+0x1b/0x50
[  601.355193]  [<ffffffff811c82d9>] vfs_fsync_range+0x49/0xa0
[  601.355432]  [<ffffffff811cf45a>] blkdev_write_iter+0xca/0x100
[  601.355679]  [<ffffffff81197b1a>] __vfs_write+0xaa/0xe0
[  601.355925]  [<ffffffff81198379>] vfs_write+0xa9/0x1a0
[  601.356164]  [<ffffffff811c59d8>] kernel_write+0x38/0x50

The underlying device is a null_blk, with default parameters:

  queue_mode    = MQ
  submit_queues = 1

Verification that nullb0 has something inflight:

root@pserver8:~# cat /sys/block/nullb0/inflight
       0        1
root@pserver8:~# find /sys/block/nullb0/mq/0/cpu* -name rq_list -print -exec cat {} \;
...
/sys/block/nullb0/mq/0/cpu2/rq_list
CTX pending:
        ffff8838038e2400
...

During debug it became clear that stalled request is always inserted in
the rq_list from the following path:

   save_stack_trace_tsk + 34
   blk_mq_insert_requests + 231
   blk_mq_flush_plug_list + 281
   blk_flush_plug_list + 199
   wait_on_page_bit + 192
   __filemap_fdatawait_range + 228
   filemap_fdatawait_range + 20
   filemap_write_and_wait_range + 63
   blkdev_fsync + 27
   vfs_fsync_range + 73
   blkdev_write_iter + 202
   __vfs_write + 170
   vfs_write + 169
   kernel_write + 56

So blk_flush_plug_list() was called with from_schedule == true.

If from_schedule is true, that means that finally blk_mq_insert_requests()
offloads execution of __blk_mq_run_hw_queue() and uses kblockd workqueue,
i.e. it calls kblockd_schedule_delayed_work_on().

That means, that we race with another CPU, which is about to execute
__blk_mq_run_hw_queue() work.

Further debugging shows the following traces from different CPUs:

  CPU#0                                  CPU#1
  ----------------------------------     -------------------------------
  reqeust A inserted
  STORE hctx->ctx_map[0] bit marked
  kblockd_schedule...() returns 1
  <schedule to kblockd workqueue>
                                         request B inserted
                                         STORE hctx->ctx_map[1] bit marked
                                         kblockd_schedule...() returns 0
  *** WORK PENDING bit is cleared ***
  flush_busy_ctxs() is executed, but
  bit 1, set by CPU#1, is not observed

As a result request B pended forever.

This behaviour can be explained by speculative LOAD of hctx->ctx_map on
CPU#0, which is reordered with clear of PENDING bit and executed _before_
actual STORE of bit 1 on CPU#1.

The proper fix is an explicit full barrier <mfence>, which guarantees
that clear of PENDING bit is to be executed before all possible
speculative LOADS or STORES inside actual work function.

Signed-off-by: Roman Pen <roman.penyaev@profitbricks.com>
Cc: Gioh Kim <gi-oh.kim@profitbricks.com>
Cc: Michael Wang <yun.wang@profitbricks.com>
Cc: Tejun Heo <tj@kernel.org>
Cc: Jens Axboe <axboe@kernel.dk>
Cc: linux-block@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Cc: stable@vger.kernel.org
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 kernel/workqueue.c | 29 +++++++++++++++++++++++++++++
 1 file changed, 29 insertions(+)

diff --git a/kernel/workqueue.c b/kernel/workqueue.c
index fe7c4b91..66972ac 100644
--- a/kernel/workqueue.c
+++ b/kernel/workqueue.c
@@ -606,6 +606,35 @@ static void set_work_pool_and_clear_pending(struct work_struct *work,
 	 */
 	smp_wmb();
 	set_work_data(work, (unsigned long)pool_id << WORK_OFFQ_POOL_SHIFT, 0);
+	/*
+	 * The following mb guarantees that previous clear of a PENDING bit
+	 * will not be reordered with any speculative LOADS or STORES from
+	 * work->current_func, which is executed afterwards.  This possible
+	 * reordering can lead to a missed execution on attempt to qeueue
+	 * the same @work.  E.g. consider this case:
+	 *
+	 *   CPU#0                         CPU#1
+	 *   ----------------------------  --------------------------------
+	 *
+	 * 1  STORE event_indicated
+	 * 2  queue_work_on() {
+	 * 3    test_and_set_bit(PENDING)
+	 * 4 }                             set_..._and_clear_pending() {
+	 * 5                                 set_work_data() # clear bit
+	 * 6                                 smp_mb()
+	 * 7                               work->current_func() {
+	 * 8				      LOAD event_indicated
+	 *				   }
+	 *
+	 * Without an explicit full barrier speculative LOAD on line 8 can
+	 * be executed before CPU#0 does STORE on line 1.  If that happens,
+	 * CPU#0 observes the PENDING bit is still set and new execution of
+	 * a @work is not queued in a hope, that CPU#1 will eventually
+	 * finish the queued @work.  Meanwhile CPU#1 does not see
+	 * event_indicated is set, because speculative LOAD was executed
+	 * before actual STORE.
+	 */
+	smp_mb();
 }
 
 static void clear_work_data(struct work_struct *work)
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414072 — [PATCH 3.10 127/143] net: fix infoleak in rtnetlink

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 127/143] net: fix infoleak in rtnetlink
Message-ID<rGDN2-5Ef-71@gated-at.bofh.it>
In reply to#1413978
From: Kangjie Lu <kangjielu@gmail.com>

commit 5f8e44741f9f216e33736ea4ec65ca9ac03036e6 upstream.

The stack object “map” has a total size of 32 bytes. Its last 4
bytes are padding generated by compiler. These padding bytes are
not initialized and sent out via “nla_put”.

Signed-off-by: Kangjie Lu <kjlu@gatech.edu>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/core/rtnetlink.c | 18 ++++++++++--------
 1 file changed, 10 insertions(+), 8 deletions(-)

diff --git a/net/core/rtnetlink.c b/net/core/rtnetlink.c
index a67310e..602c6d0 100644
--- a/net/core/rtnetlink.c
+++ b/net/core/rtnetlink.c
@@ -899,14 +899,16 @@ static int rtnl_fill_ifinfo(struct sk_buff *skb, struct net_device *dev,
 		goto nla_put_failure;
 
 	if (1) {
-		struct rtnl_link_ifmap map = {
-			.mem_start   = dev->mem_start,
-			.mem_end     = dev->mem_end,
-			.base_addr   = dev->base_addr,
-			.irq         = dev->irq,
-			.dma         = dev->dma,
-			.port        = dev->if_port,
-		};
+		struct rtnl_link_ifmap map;
+
+		memset(&map, 0, sizeof(map));
+		map.mem_start   = dev->mem_start;
+		map.mem_end     = dev->mem_end;
+		map.base_addr   = dev->base_addr;
+		map.irq         = dev->irq;
+		map.dma         = dev->dma;
+		map.port        = dev->if_port;
+
 		if (nla_put(skb, IFLA_MAP, sizeof(map), &map))
 			goto nla_put_failure;
 	}
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414073 — [PATCH 3.10 013/143] x86/iopl: Fix iopl capability check on Xen PV

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 013/143] x86/iopl: Fix iopl capability check on Xen PV
Message-ID<rGDN1-5Ef-61@gated-at.bofh.it>
In reply to#1413978
From: Andy Lutomirski <luto@kernel.org>

commit c29016cf41fe9fa994a5ecca607cf5f1cd98801e upstream.

iopl(3) is supposed to work if iopl is already 3, even if
unprivileged.  This didn't work right on Xen PV.  Fix it.

Reviewewd-by: Jan Beulich <JBeulich@suse.com>
Signed-off-by: Andy Lutomirski <luto@kernel.org>
Cc: Andrew Cooper <andrew.cooper3@citrix.com>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Brian Gerst <brgerst@gmail.com>
Cc: David Vrabel <david.vrabel@citrix.com>
Cc: Denys Vlasenko <dvlasenk@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Jan Beulich <JBeulich@suse.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: stable@vger.kernel.org
Link: http://lkml.kernel.org/r/8ce12013e6e4c0a44a97e316be4a6faff31bd5ea.1458162709.git.luto@kernel.org
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 arch/x86/kernel/ioport.c | 12 +++++++++---
 1 file changed, 9 insertions(+), 3 deletions(-)

diff --git a/arch/x86/kernel/ioport.c b/arch/x86/kernel/ioport.c
index 4ddaf66..792621a 100644
--- a/arch/x86/kernel/ioport.c
+++ b/arch/x86/kernel/ioport.c
@@ -96,9 +96,14 @@ asmlinkage long sys_ioperm(unsigned long from, unsigned long num, int turn_on)
 SYSCALL_DEFINE1(iopl, unsigned int, level)
 {
 	struct pt_regs *regs = current_pt_regs();
-	unsigned int old = (regs->flags >> 12) & 3;
 	struct thread_struct *t = &current->thread;
 
+	/*
+	 * Careful: the IOPL bits in regs->flags are undefined under Xen PV
+	 * and changing them has no effect.
+	 */
+	unsigned int old = t->iopl >> X86_EFLAGS_IOPL_BIT;
+
 	if (level > 3)
 		return -EINVAL;
 	/* Trying to gain more privileges? */
@@ -106,8 +111,9 @@ SYSCALL_DEFINE1(iopl, unsigned int, level)
 		if (!capable(CAP_SYS_RAWIO))
 			return -EPERM;
 	}
-	regs->flags = (regs->flags & ~X86_EFLAGS_IOPL) | (level << 12);
-	t->iopl = level << 12;
+	regs->flags = (regs->flags & ~X86_EFLAGS_IOPL) |
+		(level << X86_EFLAGS_IOPL_BIT);
+	t->iopl = level << X86_EFLAGS_IOPL_BIT;
 	set_iopl_mask(t->iopl);
 
 	return 0;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414074 — [PATCH 3.10 129/143] net: bridge: fix old ioctl unlocked net device walk

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 129/143] net: bridge: fix old ioctl unlocked net device walk
Message-ID<rGDN1-5Ef-63@gated-at.bofh.it>
In reply to#1413978
From: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>

commit 31ca0458a61a502adb7ed192bf9716c6d05791a5 upstream.

get_bridge_ifindices() is used from the old "deviceless" bridge ioctl
calls which aren't called with rtnl held. The comment above says that it is
called with rtnl but that is not really the case.
Here's a sample output from a test ASSERT_RTNL() which I put in
get_bridge_ifindices and executed "brctl show":
[  957.422726] RTNL: assertion failed at net/bridge//br_ioctl.c (30)
[  957.422925] CPU: 0 PID: 1862 Comm: brctl Tainted: G        W  O
4.6.0-rc4+ #157
[  957.423009] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),
BIOS 1.8.1-20150318_183358- 04/01/2014
[  957.423009]  0000000000000000 ffff880058adfdf0 ffffffff8138dec5
0000000000000400
[  957.423009]  ffffffff81ce8380 ffff880058adfe58 ffffffffa05ead32
0000000000000001
[  957.423009]  00007ffec1a444b0 0000000000000400 ffff880053c19130
0000000000008940
[  957.423009] Call Trace:
[  957.423009]  [<ffffffff8138dec5>] dump_stack+0x85/0xc0
[  957.423009]  [<ffffffffa05ead32>]
br_ioctl_deviceless_stub+0x212/0x2e0 [bridge]
[  957.423009]  [<ffffffff81515beb>] sock_ioctl+0x22b/0x290
[  957.423009]  [<ffffffff8126ba75>] do_vfs_ioctl+0x95/0x700
[  957.423009]  [<ffffffff8126c159>] SyS_ioctl+0x79/0x90
[  957.423009]  [<ffffffff8163a4c0>] entry_SYSCALL_64_fastpath+0x23/0xc1

Since it only reads bridge ifindices, we can use rcu to safely walk the net
device list. Also remove the wrong rtnl comment above.

Signed-off-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/bridge/br_ioctl.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/net/bridge/br_ioctl.c b/net/bridge/br_ioctl.c
index b73eaba..a882db4 100644
--- a/net/bridge/br_ioctl.c
+++ b/net/bridge/br_ioctl.c
@@ -21,18 +21,19 @@
 #include <asm/uaccess.h>
 #include "br_private.h"
 
-/* called with RTNL */
 static int get_bridge_ifindices(struct net *net, int *indices, int num)
 {
 	struct net_device *dev;
 	int i = 0;
 
-	for_each_netdev(net, dev) {
+	rcu_read_lock();
+	for_each_netdev_rcu(net, dev) {
 		if (i >= num)
 			break;
 		if (dev->priv_flags & IFF_EBRIDGE)
 			indices[i++] = dev->ifindex;
 	}
+	rcu_read_unlock();
 
 	return i;
 }
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414075 — [PATCH 3.10 126/143] net: fix infoleak in llc

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 126/143] net: fix infoleak in llc
Message-ID<rGDN2-5Ef-75@gated-at.bofh.it>
In reply to#1413978
From: Kangjie Lu <kangjielu@gmail.com>

commit b8670c09f37bdf2847cc44f36511a53afc6161fd upstream.

The stack object “info” has a total size of 12 bytes. Its last byte
is padding which is not initialized and leaked via “put_cmsg”.

Signed-off-by: Kangjie Lu <kjlu@gatech.edu>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/llc/af_llc.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/net/llc/af_llc.c b/net/llc/af_llc.c
index c3ee805..9d14059 100644
--- a/net/llc/af_llc.c
+++ b/net/llc/af_llc.c
@@ -626,6 +626,7 @@ static void llc_cmsg_rcv(struct msghdr *msg, struct sk_buff *skb)
 	if (llc->cmsg_flags & LLC_CMSG_PKTINFO) {
 		struct llc_pktinfo info;
 
+		memset(&info, 0, sizeof(info));
 		info.lpi_ifindex = llc_sk(skb->sk)->dev->ifindex;
 		llc_pdu_decode_dsap(skb, &info.lpi_sap);
 		llc_pdu_decode_da(skb, info.lpi_mac);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414076 — [PATCH 3.10 100/143] Drivers: hv: vmbus: prevent cpu offlining on newer hypervisors

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 100/143] Drivers: hv: vmbus: prevent cpu offlining on newer hypervisors
Message-ID<rGDN1-5Ef-65@gated-at.bofh.it>
In reply to#1413978
From: Vitaly Kuznetsov <vkuznets@redhat.com>

commit e513229b4c386e6c9f66298c13fde92f73e6e1ac upstream.

When an SMP Hyper-V guest is running on top of 2012R2 Server and secondary
cpus are sent offline (with echo 0 > /sys/devices/system/cpu/cpu$cpu/online)
the system freeze is observed. This happens due to the fact that on newer
hypervisors (Win8, WS2012R2, ...) vmbus channel handlers are distributed
across all cpus (see init_vp_index() function in drivers/hv/channel_mgmt.c)
and on cpu offlining nobody reassigns them to CPU0. Prevent cpu offlining
when vmbus is loaded until the issue is fixed host-side.

This patch also disables hibernation but it is OK as it is also broken (MCE
error is hit on resume). Suspend still works.

Tested with WS2008R2 and WS2012R2.

Signed-off-by: Vitaly Kuznetsov <vkuznets@redhat.com>
Signed-off-by: K. Y. Srinivasan <kys@microsoft.com>
[ 3chas3@gmail.com: rebase to 3.14-stable ]
Signed-off-by: Chas Williams <3chas3@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/hv/vmbus_drv.c | 36 ++++++++++++++++++++++++++++++++++++
 1 file changed, 36 insertions(+)

diff --git a/drivers/hv/vmbus_drv.c b/drivers/hv/vmbus_drv.c
index f445b08..80754e2 100644
--- a/drivers/hv/vmbus_drv.c
+++ b/drivers/hv/vmbus_drv.c
@@ -32,6 +32,7 @@
 #include <linux/acpi.h>
 #include <acpi/acpi_bus.h>
 #include <linux/completion.h>
+#include <linux/cpu.h>
 #include <linux/hyperv.h>
 #include <linux/kernel_stat.h>
 #include <asm/hyperv.h>
@@ -517,6 +518,39 @@ static void vmbus_flow_handler(unsigned int irq, struct irq_desc *desc)
 	desc->action->handler(irq, desc->action->dev_id);
 }
 
+#ifdef CONFIG_HOTPLUG_CPU
+static int hyperv_cpu_disable(void)
+{
+	return -ENOSYS;
+}
+
+static void hv_cpu_hotplug_quirk(bool vmbus_loaded)
+{
+	static void *previous_cpu_disable;
+
+	/*
+	 * Offlining a CPU when running on newer hypervisors (WS2012R2, Win8,
+	 * ...) is not supported at this moment as channel interrupts are
+	 * distributed across all of them.
+	 */
+
+	if ((vmbus_proto_version == VERSION_WS2008) ||
+	    (vmbus_proto_version == VERSION_WIN7))
+		return;
+
+	if (vmbus_loaded) {
+		previous_cpu_disable = smp_ops.cpu_disable;
+		smp_ops.cpu_disable = hyperv_cpu_disable;
+		pr_notice("CPU offlining is not supported by hypervisor\n");
+	} else if (previous_cpu_disable)
+		smp_ops.cpu_disable = previous_cpu_disable;
+}
+#else
+static void hv_cpu_hotplug_quirk(bool vmbus_loaded)
+{
+}
+#endif
+
 /*
  * vmbus_bus_init -Main vmbus driver initialization routine.
  *
@@ -572,6 +606,7 @@ static int vmbus_bus_init(int irq)
 	if (ret)
 		goto err_irq;
 
+	hv_cpu_hotplug_quirk(true);
 	vmbus_request_offers();
 
 	return 0;
@@ -808,6 +843,7 @@ static void __exit vmbus_exit(void)
 	bus_unregister(&hv_bus);
 	hv_cleanup();
 	acpi_bus_unregister_driver(&vmbus_acpi_driver);
+	hv_cpu_hotplug_quirk(false);
 }
 
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414077 — [PATCH 3.10 002/143] x86/iopl/64: Properly context-switch IOPL on Xen PV

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 002/143] x86/iopl/64: Properly context-switch IOPL on Xen PV
Message-ID<rGDN1-5Ef-67@gated-at.bofh.it>
In reply to#1413978
From: Kamal Mostafa <kamal@canonical.com>

commit b7a584598aea7ca73140cb87b40319944dd3393f upstream.

From: Andy Lutomirski <luto@kernel.org>

On Xen PV, regs->flags doesn't reliably reflect IOPL and the
exit-to-userspace code doesn't change IOPL.  We need to context
switch it manually.

I'm doing this without going through paravirt because this is
specific to Xen PV.  After the dust settles, we can merge this with
the 32-bit code, tidy up the iopl syscall implementation, and remove
the set_iopl pvop entirely.

Fixes XSA-171.

Reviewewd-by: Jan Beulich <JBeulich@suse.com>
Signed-off-by: Andy Lutomirski <luto@kernel.org>
Cc: Andrew Cooper <andrew.cooper3@citrix.com>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Brian Gerst <brgerst@gmail.com>
Cc: David Vrabel <david.vrabel@citrix.com>
Cc: Denys Vlasenko <dvlasenk@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Jan Beulich <JBeulich@suse.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Link: http://lkml.kernel.org/r/693c3bd7aeb4d3c27c92c622b7d0f554a458173c.1458162709.git.luto@kernel.org
Signed-off-by: Ingo Molnar <mingo@kernel.org>
[ kamal: backport to 3.19-stable: no X86_FEATURE_XENPV so just call
  xen_pv_domain() directly ]
Acked-by: Andy Lutomirski <luto@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 arch/x86/include/asm/xen/hypervisor.h |  2 ++
 arch/x86/kernel/process_64.c          | 12 ++++++++++++
 arch/x86/xen/enlighten.c              |  2 +-
 3 files changed, 15 insertions(+), 1 deletion(-)

diff --git a/arch/x86/include/asm/xen/hypervisor.h b/arch/x86/include/asm/xen/hypervisor.h
index 125f344..8ac93f0 100644
--- a/arch/x86/include/asm/xen/hypervisor.h
+++ b/arch/x86/include/asm/xen/hypervisor.h
@@ -71,4 +71,6 @@ static inline bool xen_x2apic_para_available(void)
 }
 #endif
 
+extern void xen_set_iopl_mask(unsigned mask);
+
 #endif /* _ASM_X86_XEN_HYPERVISOR_H */
diff --git a/arch/x86/kernel/process_64.c b/arch/x86/kernel/process_64.c
index 7099ab1..580001c 100644
--- a/arch/x86/kernel/process_64.c
+++ b/arch/x86/kernel/process_64.c
@@ -49,6 +49,7 @@
 #include <asm/syscalls.h>
 #include <asm/debugreg.h>
 #include <asm/switch_to.h>
+#include <asm/xen/hypervisor.h>
 
 asmlinkage extern void ret_from_fork(void);
 
@@ -412,6 +413,17 @@ __switch_to(struct task_struct *prev_p, struct task_struct *next_p)
 		     task_thread_info(prev_p)->flags & _TIF_WORK_CTXSW_PREV))
 		__switch_to_xtra(prev_p, next_p, tss);
 
+#ifdef CONFIG_XEN
+	/*
+	 * On Xen PV, IOPL bits in pt_regs->flags have no effect, and
+	 * current_pt_regs()->flags may not match the current task's
+	 * intended IOPL.  We need to switch it manually.
+	 */
+	if (unlikely(xen_pv_domain() &&
+		     prev->iopl != next->iopl))
+		xen_set_iopl_mask(next->iopl);
+#endif
+
 	return prev_p;
 }
 
diff --git a/arch/x86/xen/enlighten.c b/arch/x86/xen/enlighten.c
index 91cbe75..34511cf 100644
--- a/arch/x86/xen/enlighten.c
+++ b/arch/x86/xen/enlighten.c
@@ -952,7 +952,7 @@ static void xen_load_sp0(struct tss_struct *tss,
 	xen_mc_issue(PARAVIRT_LAZY_CPU);
 }
 
-static void xen_set_iopl_mask(unsigned mask)
+void xen_set_iopl_mask(unsigned mask)
 {
 	struct physdev_set_iopl set_iopl;
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414078 — [PATCH 3.10 029/143] 8250: use callbacks to access UART_DLL/UART_DLM

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 029/143] 8250: use callbacks to access UART_DLL/UART_DLM
Message-ID<rGDN2-5Ef-69@gated-at.bofh.it>
In reply to#1413978
From: Sebastian Frias <sf84@laposte.net>

commit 0b41ce991052022c030fd868e03877700220b090 upstream.

Some UART HW has a single register combining UART_DLL/UART_DLM
(this was probably forgotten in the change that introduced the
callbacks, commit b32b19b8ffc05cbd3bf91c65e205f6a912ca15d9)

Fixes: b32b19b8ffc0 ("[SERIAL] 8250: set divisor register correctly ...")

Signed-off-by: Sebastian Frias <sf84@laposte.net>
Reviewed-by: Peter Hurley <peter@hurleysoftware.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/tty/serial/8250/8250_core.c | 18 ++++++------------
 1 file changed, 6 insertions(+), 12 deletions(-)

diff --git a/drivers/tty/serial/8250/8250_core.c b/drivers/tty/serial/8250/8250_core.c
index d8c06a3..1119d53 100644
--- a/drivers/tty/serial/8250/8250_core.c
+++ b/drivers/tty/serial/8250/8250_core.c
@@ -686,22 +686,16 @@ static int size_fifo(struct uart_8250_port *up)
  */
 static unsigned int autoconfig_read_divisor_id(struct uart_8250_port *p)
 {
-	unsigned char old_dll, old_dlm, old_lcr;
-	unsigned int id;
+	unsigned char old_lcr;
+	unsigned int id, old_dl;
 
 	old_lcr = serial_in(p, UART_LCR);
 	serial_out(p, UART_LCR, UART_LCR_CONF_MODE_A);
+	old_dl = serial_dl_read(p);
+	serial_dl_write(p, 0);
+	id = serial_dl_read(p);
+	serial_dl_write(p, old_dl);
 
-	old_dll = serial_in(p, UART_DLL);
-	old_dlm = serial_in(p, UART_DLM);
-
-	serial_out(p, UART_DLL, 0);
-	serial_out(p, UART_DLM, 0);
-
-	id = serial_in(p, UART_DLL) | serial_in(p, UART_DLM) << 8;
-
-	serial_out(p, UART_DLL, old_dll);
-	serial_out(p, UART_DLM, old_dlm);
 	serial_out(p, UART_LCR, old_lcr);
 
 	return id;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414079 — [PATCH 3.10 139/143] USB: serial: quatech2: fix use-after-free in probe error path

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 12:50 +0200
Subject[PATCH 3.10 139/143] USB: serial: quatech2: fix use-after-free in probe error path
Message-ID<rGDN2-5Ef-73@gated-at.bofh.it>
In reply to#1413978
From: Johan Hovold <johan@kernel.org>

commit 028c49f5e02a257c94129cd815f7c8485f51d4ef upstream.

The interface read URB is submitted in attach, but was only unlinked by
the driver at disconnect.

In case of a late probe error (e.g. due to failed minor allocation),
disconnect is never called and we would end up with active URBs for an
unbound interface. This in turn could lead to deallocated memory being
dereferenced in the completion callback.

Fixes: f7a33e608d9a ("USB: serial: add quatech2 usb to serial driver")
Signed-off-by: Johan Hovold <johan@kernel.org>
Acked-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/serial/quatech2.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/usb/serial/quatech2.c b/drivers/usb/serial/quatech2.c
index 02b0803..13824b5 100644
--- a/drivers/usb/serial/quatech2.c
+++ b/drivers/usb/serial/quatech2.c
@@ -141,6 +141,7 @@ static void qt2_release(struct usb_serial *serial)
 
 	serial_priv = usb_get_serial_data(serial);
 
+	usb_kill_urb(serial_priv->read_urb);
 	usb_free_urb(serial_priv->read_urb);
 	kfree(serial_priv);
 }
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414080 — [PATCH 3.10 001/143] pipe: Fix buffer offset after partially failed read

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 13:00 +0200
Subject[PATCH 3.10 001/143] pipe: Fix buffer offset after partially failed read
Message-ID<rGDWF-5HJ-1@gated-at.bofh.it>
In reply to#1413978
From: Ben Hutchings <ben@decadent.org.uk>

Quoting the RHEL advisory:

> It was found that the fix for CVE-2015-1805 incorrectly kept buffer
> offset and buffer length in sync on a failed atomic read, potentially
> resulting in a pipe buffer state corruption. A local, unprivileged user
> could use this flaw to crash the system or leak kernel memory to user
> space. (CVE-2016-0774, Moderate)

The same flawed fix was applied to stable branches from 2.6.32.y to
3.14.y inclusive, and I was able to reproduce the issue on 3.2.y.
We need to give pipe_iov_copy_to_user() a separate offset variable
and only update the buffer offset if it succeeds.

References: https://rhn.redhat.com/errata/RHSA-2016-0103.html
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/pipe.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/fs/pipe.c b/fs/pipe.c
index 3e7ab27..50267e6 100644
--- a/fs/pipe.c
+++ b/fs/pipe.c
@@ -401,6 +401,7 @@ pipe_read(struct kiocb *iocb, const struct iovec *_iov,
 			void *addr;
 			size_t chars = buf->len, remaining;
 			int error, atomic;
+			int offset;
 
 			if (chars > total_len)
 				chars = total_len;
@@ -414,9 +415,10 @@ pipe_read(struct kiocb *iocb, const struct iovec *_iov,
 
 			atomic = !iov_fault_in_pages_write(iov, chars);
 			remaining = chars;
+			offset = buf->offset;
 redo:
 			addr = ops->map(pipe, buf, atomic);
-			error = pipe_iov_copy_to_user(iov, addr, &buf->offset,
+			error = pipe_iov_copy_to_user(iov, addr, &offset,
 						      &remaining, atomic);
 			ops->unmap(pipe, buf, addr);
 			if (unlikely(error)) {
@@ -432,6 +434,7 @@ redo:
 				break;
 			}
 			ret += chars;
+			buf->offset += chars;
 			buf->len -= chars;
 
 			/* Was it a packet buffer? Clean up and exit */
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1414081 — [PATCH 3.10 010/143] linux/const.h: Add _BITUL() and _BITULL()

FromWilly Tarreau <w@1wt.eu>
Date2016-06-05 13:00 +0200
Subject[PATCH 3.10 010/143] linux/const.h: Add _BITUL() and _BITULL()
Message-ID<rGDWF-5HJ-3@gated-at.bofh.it>
In reply to#1413978
From: "H. Peter Anvin" <hpa@linux.intel.com>

commit 2fc016c5bd8aad2e201cdf71b9fb4573f94775bd upstream.

Add macros for single bit definitions of a specific type.  These are
similar to the BIT() macro that already exists, but with a few
exceptions:

1. The namespace is such that they can be used in uapi definitions.
2. The type is set with the _AC() macro to allow it to be used in
   assembly.
3. The type is explicitly specified to be UL or ULL.

Signed-off-by: H. Peter Anvin <hpa@linux.intel.com>
Link: http://lkml.kernel.org/n/tip-nbca8p7cg6jyjoit7klh3o91@git.kernel.org
[wt: backported to 3.10 only to keep next patch clean]

Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 include/uapi/linux/const.h | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/include/uapi/linux/const.h b/include/uapi/linux/const.h
index c22c707..c872bfd 100644
--- a/include/uapi/linux/const.h
+++ b/include/uapi/linux/const.h
@@ -21,4 +21,7 @@
 #define _AT(T,X)	((T)(X))
 #endif
 
+#define _BITUL(x)	(_AC(1,UL) << (x))
+#define _BITULL(x)	(_AC(1,ULL) << (x))
+
 #endif /* !(_LINUX_CONST_H) */
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


Page 5 of 7 — ← Prev page 1 2 3 4 [5] 6 7  Next page →

Back to top | Article view | linux.kernel


csiph-web