Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1413978 > unrolled thread
| Started by | Willy Tarreau <w@1wt.eu> |
|---|---|
| First post | 2016-06-05 12:30 +0200 |
| Last post | 2016-06-08 07:30 +0200 |
| Articles | 20 on this page of 135 — 2 participants |
Back to article view | Back to linux.kernel
[PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 049/143] Input: ati_remote2 - fix crashes on detecting device with invalid descriptor Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 036/143] splice: handle zero nr_pages in splice_to_pipe() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 124/143] packet: fix heap info leak in PACKET_DIAG_MCLIST sock_diag interface Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 038/143] xtensa: clear all DBREAKC registers on start Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 016/143] be2iscsi: set the boot_kset pointer to NULL in case of failure Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 123/143] route: do not cache fib route info on local routes with oif Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 077/143] ext4: add lockdep annotations for i_data_sem Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 048/143] Input: ims-pcu - sanity check against missing interfaces Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 113/143] USB: serial: cp210x: add ID for Link ECU Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 046/143] tracing: Fix trace_printk() to print when not using bprintk() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 076/143] usb: renesas_usbhs: disable TX IRQ before starting TX DMAC transfer Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 106/143] clk: versatile: sp810: support reentrance Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 143/143] serial: samsung: Reorder the sequence of clock control when call s3c24xx_serial_set_termios() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 134/143] mfd: omap-usb-tll: Fix scheduling while atomic BUG Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 133/143] ring-buffer: Prevent overflow of size in ring_buffer_resize() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 061/143] ipv6: re-enable fragment header matching in ipv6_find_hdr Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 132/143] ring-buffer: Use long for nr_pages to avoid overflow failures Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 086/143] nl80211: check netlink protocol in socket release notification Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 006/143] KVM: i8254: change PIT discard tick policy Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 090/143] ASoC: s3c24xx: use const snd_soc_component_driver pointer Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 012/143] x86, processor-flags: Fix the datatypes and add bit number defines Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 085/143] crypto: gcm - Fix rfc4543 decryption crash Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 024/143] USB: serial: cp210x: Adding GE Healthcare Device ID Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 107/143] lpfc: fix misleading indentation Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 035/143] watchdog: rc32434_wdt: fix ioctl error handling Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 020/143] USB: usb_driver_claim_interface: add sanity checking Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 141/143] USB: serial: option: add support for Cinterion PH8 and AHxx Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 102/143] ARM: OMAP3: Add cpuidle parameters table for omap3430 Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 074/143] ip6_tunnel: set rtnl_link_ops before calling register_netdevice Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 008/143] EDAC, amd64_edac: Shift wrapping issue in f1x_get_norm_dct_addr() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:30 +0200
[PATCH 3.10 028/143] net: irda: Fix use-after-free in irtty_open() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 064/143] udp6: fix UDP/IPv6 encap resubmit path Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 073/143] ipv6: l2tp: fix a potential issue in l2tp_ip6_recv Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 025/143] USB: option: add "D-Link DWM-221 B1" device id Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 138/143] USB: serial: keyspan: fix use-after-free in probe error path Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 027/143] Input: powermate - fix oops with malicious USB descriptors Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 087/143] Input: gtco - fix crash on detecting device without endpoints Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 080/143] [media] usbvision-video: fix memory leak of alt_max_pkt_size Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 122/143] decnet: Do not build routes to devices without decnet private data. Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 088/143] i2c: cpm: Fix build break due to incompatible pointer types Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 007/143] KVM: fix spin_lock_init order on x86 Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 098/143] drivers/misc/ad525x_dpot: AD5274 fix RDAC read back errors Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 116/143] powerpc: scan_features() updates incorrect bits for REAL_LE Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 051/143] ocfs2/dlm: fix BUG in dlm_move_lockres_to_recovery_list Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 063/143] usbnet: cleanup after bind() in probe() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 112/143] ACPICA: Dispatcher: Update thread ID for recursive method calls Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 083/143] usb: xhci: fix wild pointers in xhci_mem_cleanup Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 011/143] x86: Rename X86_CR4_RDWRGSFS to X86_CR4_FSGSBASE Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 053/143] sched/cputime: Fix steal time accounting vs. CPU hotplug Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 014/143] sg: fix dxferp in from_to case Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 121/143] ARM: OMAP3: Fix booting with thumb2 kernel Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 056/143] parisc: Avoid function pointers for kernel exception routines Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 130/143] net: fix a kernel infoleak in x25 module Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 115/143] Input: ads7846 - correct the value got from SPI Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 096/143] misc/bmp085: Enable building as a module Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 101/143] perf stat: Document --detailed option Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 103/143] compiler-gcc: disable -ftracer for __noclone functions Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 089/143] EDAC: i7core, sb_edac: Don't return NOTIFY_BAD from mce_decoder callback Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 120/143] asmlinkage, pnp: Make variables used from assembler code visible Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 109/143] proc: prevent accessing /proc/<PID>/environ until it's ready Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 079/143] drm/radeon: hold reference to fences in radeon_sa_bo_new (3.17 and older) Willy Tarreau <w@1wt.eu> - 2016-06-05 12:40 +0200
[PATCH 3.10 021/143] USB: mct_u232: add sanity checking in probe Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 111/143] MAINTAINERS: Remove asterisk from EFI directory names Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 068/143] ath9k: fix buffer overrun for ar9287 Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 071/143] qmi_wwan: add "D-Link DWM-221 B1" device id Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 015/143] aacraid: Fix memory leak in aac_fib_map_free Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 117/143] crypto: hash - Fix page length clamping in hash walk Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 110/143] batman-adv: Fix broadcast/ogm queue limit on a removed interface Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 065/143] sh_eth: fix NULL pointer dereference in sh_eth_ring_format() Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 137/143] Bluetooth: vhci: purge unhandled skbs Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 094/143] paride: make 'verbose' parameter an 'int' again Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 042/143] ipr: Fix regression when loading firmware Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 119/143] Input: max8997-haptic - fix NULL pointer dereference Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 052/143] mtd: onenand: fix deadlock in onenand_block_markbad Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 108/143] ARM: SoCFPGA: Fix secondary CPU startup in thumb2 kernel Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 099/143] include/linux/poison.h: fix LIST_POISON{1,2} offset Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 032/143] ALSA: intel8x0: Add clock quirk entry for AD1981B on IBM ThinkPad X41. Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 078/143] HID: usbhid: fix inconsistent reset/resume/reset-resume behavior Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 045/143] tracing: Fix crash from reading trace_pipe with sendfile Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 005/143] x86: LLVMLinux: Fix "incomplete type const struct x86cpu_device_id" Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 070/143] ppp: take reference on channels netns Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 135/143] mmc: mmc: Fix partition switch timeout for some eMMCs Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 067/143] farsync: fix off-by-one bug in fst_add_one Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 039/143] md/raid5: Compare apples to apples (or sectors to sectors) Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 131/143] fs/cifs: correctly to anonymous authentication via NTLMSSP Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 082/143] usbvision: fix crash on detecting device with invalid configuration Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 041/143] ipr: Fix out-of-bounds null overwrite Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 019/143] USB: iowarrior: fix oops with malicious USB descriptors Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 092/143] workqueue: fix ghost PENDING flag while doing MQ IO Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 127/143] net: fix infoleak in rtnetlink Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 013/143] x86/iopl: Fix iopl capability check on Xen PV Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 129/143] net: bridge: fix old ioctl unlocked net device walk Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 126/143] net: fix infoleak in llc Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 100/143] Drivers: hv: vmbus: prevent cpu offlining on newer hypervisors Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 002/143] x86/iopl/64: Properly context-switch IOPL on Xen PV Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 029/143] 8250: use callbacks to access UART_DLL/UART_DLM Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 139/143] USB: serial: quatech2: fix use-after-free in probe error path Willy Tarreau <w@1wt.eu> - 2016-06-05 12:50 +0200
[PATCH 3.10 001/143] pipe: Fix buffer offset after partially failed read Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 010/143] linux/const.h: Add _BITUL() and _BITULL() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 026/143] pwc: Add USB id for Philips Spc880nc webcam Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 057/143] parisc: Fix kernel crash with reversed copy_from_user() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 031/143] media: v4l2-compat-ioctl32: fix missing length copy in put_v4l2_buffer32 Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 084/143] usb: hcd: out of bounds access in for_each_companion Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 069/143] qlge: Fix receive packets drop. Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 142/143] tty: vt, return error when con_startup fails Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 136/143] mmc: longer timeout for long read time quirk Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 037/143] xtensa: ISS: don't hang if stdin EOF is reached Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 017/143] usb: retry reset if a device times out Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 097/143] rtc: vr41xx: Wire up alarm_irq_enable Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 003/143] ext4: fix NULL pointer dereference in ext4_mark_inode_dirty() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 018/143] USB: cdc-acm: more sanity checking Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 044/143] tracing: Have preempt(irqs)off trace preempt disabled functions Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 040/143] rapidio/rionet: fix deadlock on SMP Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 066/143] net: Fix use after free in the recvmmsg exit path Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 091/143] efi: Fix out-of-bounds read in variable_matches() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 072/143] ipv4: l2tp: fix a potential issue in l2tp_ip_recv Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 033/143] jbd2: fix FS corruption possibility in jbd2_journal_destroy() on umount path Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 034/143] bcache: fix cache_set_flush() NULL pointer dereference on OOM Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 062/143] cdc_ncm: toggle altsetting to force reset before setup Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 075/143] usb: renesas_usbhs: avoid NULL pointer derefernce in usbhsf_pkt_handler() Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 093/143] USB: usbip: fix potential out-of-bounds write Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 043/143] drm/radeon: Don't drop DP 2.7 Ghz link setup on some cards. Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 125/143] atl2: Disable unimplemented scatter/gather feature Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
[PATCH 3.10 009/143] PCI: Disable IO/MEM decoding for devices with non-compliant BARs Willy Tarreau <w@1wt.eu> - 2016-06-05 13:00 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-07 05:50 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-07 06:20 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-07 06:40 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-07 07:20 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-07 08:00 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-07 09:00 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-07 20:00 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-07 20:30 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck <linux@roeck-us.net> - 2016-06-08 03:00 +0200
Re: [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau <w@1wt.eu> - 2016-06-08 07:30 +0200
Page 1 of 7 [1] 2 3 4 5 6 7 Next page →
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 000/143] 3.10.102-stable review |
| Message-ID | <rGDtD-5uK-3@gated-at.bofh.it> |
This is the start of the stable review cycle for the 3.10.102 release.
All patches will be posted as a response to this one. If anyone has any
issue with these being applied, please let me know. If anyone thinks some
important patches are missing and should be added prior to the release,
please report them quickly with their respective mainline commit IDs.
Responses should be made by Sat Jun 11 11:48:43 CEST 2016.
Anything received after that time might be too late. If someone
wants a bit more time for a deeper review, please let me know.
The whole patch series can be found in one patch at :
https://kernel.org/pub/linux/kernel/v3.x/stable-review/patch-3.10.102-rc1.gz
The shortlog and diffstat are appended below.
Thanks,
Willy
===============
Aaro Koskinen (1):
mtd: onenand: fix deadlock in onenand_block_markbad
Adrian Hunter (1):
mmc: mmc: Fix partition switch timeout for some eMMCs
Al Viro (1):
get_rock_ridge_filename(): handle malformed NM entries
Alan Stern (1):
HID: usbhid: fix inconsistent reset/resume/reset-resume behavior
Alexey Khoroshilov (2):
[media] usbvision-video: fix memory leak of alt_max_pkt_size
usbvision: fix leak of usb_dev on failure paths in usbvision_probe()
Andi Kleen (2):
perf/x86/intel: Fix PEBS data source interpretation on
Nehalem/Westmere
asmlinkage, pnp: Make variables used from assembler code visible
Andrey Gelman (1):
Input: ads7846 - correct the value got from SPI
Andy Lutomirski (1):
x86/iopl: Fix iopl capability check on Xen PV
Anton Blanchard (1):
powerpc: scan_features() updates incorrect bits for REAL_LE
Arnaldo Carvalho de Melo (1):
net: Fix use after free in the recvmmsg exit path
Arnd Bergmann (5):
farsync: fix off-by-one bug in fst_add_one
ath9k: fix buffer overrun for ar9287
ASoC: s3c24xx: use const snd_soc_component_driver pointer
paride: make 'verbose' parameter an 'int' again
lpfc: fix misleading indentation
Aurelien Jacquiot (1):
rapidio/rionet: fix deadlock on SMP
Behan Webster (1):
x86: LLVMLinux: Fix "incomplete type const struct x86cpu_device_id"
Ben Hutchings (3):
pipe: Fix buffer offset after partially failed read
misc/bmp085: Enable building as a module
atl2: Disable unimplemented scatter/gather feature
Bill Sommerfeld (1):
udp6: fix UDP/IPv6 encap resubmit path
Bjorn Helgaas (1):
PCI: Disable IO/MEM decoding for devices with non-compliant BARs
Bj�rn Mork (3):
USB: option: add "D-Link DWM-221 B1" device id
cdc_ncm: toggle altsetting to force reset before setup
qmi_wwan: add "D-Link DWM-221 B1" device id
Borislav Petkov (1):
perf stat: Document --detailed option
Chanwoo Choi (1):
serial: samsung: Reorder the sequence of clock control when call
s3c24xx_serial_set_termios()
Chris Friesen (1):
route: do not cache fib route info on local routes with oif
Dan Carpenter (1):
EDAC, amd64_edac: Shift wrapping issue in f1x_get_norm_dct_addr()
Dan Streetman (1):
nbd: ratelimit error msgs after socket close
David S. Miller (1):
decnet: Do not build routes to devices without decnet private data.
Diego Viola (1):
net: jme: fix suspend/resume on JMC260
Dmitry Ivanov (1):
nl80211: check netlink protocol in socket release notification
Douglas Gilbert (1):
sg: fix dxferp in from_to case
Eric Wheeler (1):
bcache: fix cache_set_flush() NULL pointer dereference on OOM
Eryu Guan (1):
ext4: fix NULL pointer dereference in ext4_mark_inode_dirty()
Florian Westphal (1):
ipv6: re-enable fragment header matching in ipv6_find_hdr
Gabriel Krisman Bertazi (1):
ipr: Fix regression when loading firmware
Geert Uytterhoeven (1):
rtc: vr41xx: Wire up alarm_irq_enable
Guenter Roeck (1):
hwmon: (max1111) Return -ENODEV from max1111_read_channel if not
instantiated
Guillaume Nault (1):
ppp: take reference on channels netns
H. Peter Anvin (3):
linux/const.h: Add _BITUL() and _BITULL()
x86: Rename X86_CR4_RDWRGSFS to X86_CR4_FSGSBASE
x86, processor-flags: Fix the datatypes and add bit number defines
Haishuang Yan (2):
ipv4: l2tp: fix a potential issue in l2tp_ip_recv
ipv6: l2tp: fix a potential issue in l2tp_ip6_recv
Hans de Goede (2):
pwc: Add USB id for Philips Spc880nc webcam
bttv: Width must be a multiple of 16 when capturing planar formats
Helge Deller (2):
parisc: Avoid function pointers for kernel exception routines
parisc: Fix kernel crash with reversed copy_from_user()
Herbert Xu (2):
crypto: gcm - Fix rfc4543 decryption crash
crypto: hash - Fix page length clamping in hash walk
Ian Campbell (1):
VSOCK: do not disconnect socket when peer has shutdown SEND only
Ignat Korchagin (1):
USB: usbip: fix potential out-of-bounds write
Insu Yun (1):
ipr: Fix out-of-bounds null overwrite
Jasem Mutlaq (1):
USB: serial: cp210x: add Straizona Focusers device ids
Jes Sorensen (1):
md/raid5: Compare apples to apples (or sectors to sectors)
Jiri Slaby (2):
Bluetooth: vhci: purge unhandled skbs
tty: vt, return error when con_startup fails
Joe Perches (1):
compiler-gcc: integrate the various compiler-gcc[345].h files
Johan Hovold (3):
USB: serial: keyspan: fix use-after-free in probe error path
USB: serial: quatech2: fix use-after-free in probe error path
USB: serial: io_edgeport: fix memory leaks in probe error path
Joseph Qi (2):
ocfs2/dlm: fix race between convert and recovery
ocfs2/dlm: fix BUG in dlm_move_lockres_to_recovery_list
Josh Boyer (2):
USB: iowarrior: fix oops with malicious USB descriptors
Input: powermate - fix oops with malicious USB descriptors
Julia Lawall (1):
scripts/coccinelle: modernize &
Kamal Mostafa (1):
x86/iopl/64: Properly context-switch IOPL on Xen PV
Kangjie Lu (3):
net: fix infoleak in llc
net: fix infoleak in rtnetlink
net: fix a kernel infoleak in x25 module
Laszlo Ersek (1):
efi: Fix out-of-bounds read in variable_matches()
Linus L�ssing (1):
batman-adv: Fix broadcast/ogm queue limit on a removed interface
Linus Walleij (1):
clk: versatile: sp810: support reentrance
Lu Baolu (1):
usb: xhci: fix wild pointers in xhci_mem_cleanup
Manish Chopra (1):
qlge: Fix receive packets drop.
Marco Angaroni (1):
ipvs: correct initial offset of Call-ID header search in SIP
persistence engine
Marek Szyprowski (1):
Input: max8997-haptic - fix NULL pointer dereference
Mario Kleiner (1):
drm/radeon: Don't drop DP 2.7 Ghz link setup on some cards.
Martyn Welch (1):
USB: serial: cp210x: Adding GE Healthcare Device ID
Mathias Krause (2):
proc: prevent accessing /proc/<PID>/environ until it's ready
packet: fix heap info leak in PACKET_DIAG_MCLIST sock_diag interface
Matt Fleming (1):
MAINTAINERS: Remove asterisk from EFI directory names
Matt Gumbel (1):
mmc: longer timeout for long read time quirk
Maurizio Lombardi (1):
be2iscsi: set the boot_kset pointer to NULL in case of failure
Max Filippov (2):
xtensa: ISS: don't hang if stdin EOF is reached
xtensa: clear all DBREAKC registers on start
Michael Ellerman (1):
i2c: cpm: Fix build break due to incompatible pointer types
Michael Hennerich (1):
drivers/misc/ad525x_dpot: AD5274 fix RDAC read back errors
Michael S. Tsirkin (1):
watchdog: rc32434_wdt: fix ioctl error handling
Mike Manning (1):
USB: serial: cp210x: add ID for Link ECU
Nicolai H�hnle (1):
drm/radeon: hold reference to fences in radeon_sa_bo_new (3.17 and
older)
Nikolay Aleksandrov (1):
net: bridge: fix old ioctl unlocked net device walk
OGAWA Hirofumi (1):
jbd2: fix FS corruption possibility in jbd2_journal_destroy() on
umount path
Oliver Neukum (8):
usb: retry reset if a device times out
USB: cdc-acm: more sanity checking
USB: usb_driver_claim_interface: add sanity checking
USB: mct_u232: add sanity checking in probe
USB: digi_acceleport: do sanity checking for the number of ports
USB: cypress_m8: add endpoint sanity check
Input: ims-pcu - sanity check against missing interfaces
usbnet: cleanup after bind() in probe()
Pali Roh�r (1):
ARM: OMAP3: Add cpuidle parameters table for omap3430
Paolo Bonzini (2):
KVM: fix spin_lock_init order on x86
compiler-gcc: disable -ftracer for __noclone functions
Peter Hurley (1):
net: irda: Fix use-after-free in irtty_open()
Prarit Bhargava (1):
ACPICA: Dispatcher: Update thread ID for recursive method calls
Rabin Vincent (1):
splice: handle zero nr_pages in splice_to_pipe()
Radim Krčmář (1):
KVM: i8254: change PIT discard tick policy
Raghava Aditya Renukunta (1):
aacraid: Fix memory leak in aac_fib_map_free
Robert Dobrowolski (1):
usb: hcd: out of bounds access in for_each_companion
Roger Quadros (1):
mfd: omap-usb-tll: Fix scheduling while atomic BUG
Roman Pen (1):
workqueue: fix ghost PENDING flag while doing MQ IO
Sascha Hauer (1):
ARM: SoCFPGA: Fix secondary CPU startup in thumb2 kernel
Schemmel Hans-Christoph (1):
USB: serial: option: add support for Cinterion PH8 and AHxx
Sebastian Frias (1):
8250: use callbacks to access UART_DLL/UART_DLM
Sergei Shtylyov (1):
sh_eth: fix NULL pointer dereference in sh_eth_ring_format()
Stefan Metzmacher (1):
fs/cifs: correctly to anonymous authentication via NTLMSSP
Steven Rostedt (Red Hat) (5):
tracing: Have preempt(irqs)off trace preempt disabled functions
tracing: Fix crash from reading trace_pipe with sendfile
tracing: Fix trace_printk() to print when not using bprintk()
ring-buffer: Use long for nr_pages to avoid overflow failures
ring-buffer: Prevent overflow of size in ring_buffer_resize()
Sushaanth Srirangapathi (1):
fbdev: da8xx-fb: fix videomodes of lcd panels
Takashi Iwai (1):
ALSA: timer: Use mod_timer() for rearming the system timer
Thadeu Lima de Souza Cascardo (1):
ip6_tunnel: set rtnl_link_ops before calling register_netdevice
Theodore Ts'o (1):
ext4: add lockdep annotations for i_data_sem
Thomas Gleixner (1):
sched/cputime: Fix steal time accounting vs. CPU hotplug
Tiffany Lin (1):
media: v4l2-compat-ioctl32: fix missing length copy in
put_v4l2_buffer32
Tony Lindgren (1):
ARM: OMAP3: Fix booting with thumb2 kernel
Tony Luck (1):
EDAC: i7core, sb_edac: Don't return NOTIFY_BAD from mce_decoder
callback
Vasily Kulikov (1):
include/linux/poison.h: fix LIST_POISON{1,2} offset
Vitaly Kuznetsov (1):
Drivers: hv: vmbus: prevent cpu offlining on newer hypervisors
Vittorio Gambaletta (VittGam) (1):
ALSA: intel8x0: Add clock quirk entry for AD1981B on IBM ThinkPad X41.
Vladis Dronov (3):
Input: ati_remote2 - fix crashes on detecting device with invalid
descriptor
usbvision: fix crash on detecting device with invalid configuration
Input: gtco - fix crash on detecting device without endpoints
Xin Long (1):
sctp: lack the check for ports in sctp_v6_cmp_addr
Yoshihiro Shimoda (2):
usb: renesas_usbhs: avoid NULL pointer derefernce in
usbhsf_pkt_handler()
usb: renesas_usbhs: disable TX IRQ before starting TX DMAC transfer
MAINTAINERS | 4 +-
arch/arm/mach-omap2/cpuidle34xx.c | 69 +++++++++-
arch/arm/mach-omap2/sleep34xx.S | 22 +---
arch/arm/mach-socfpga/headsmp.S | 1 +
arch/parisc/kernel/parisc_ksyms.c | 10 +-
arch/parisc/kernel/traps.c | 3 +
arch/powerpc/include/uapi/asm/cputable.h | 1 +
arch/powerpc/kernel/prom.c | 2 +-
arch/x86/include/asm/kvm_host.h | 2 +-
arch/x86/include/asm/xen/hypervisor.h | 2 +
arch/x86/include/uapi/asm/processor-flags.h | 154 +++++++++++++++-------
arch/x86/kernel/cpu/perf_event.h | 2 +
arch/x86/kernel/cpu/perf_event_intel.c | 2 +
arch/x86/kernel/cpu/perf_event_intel_ds.c | 11 +-
arch/x86/kernel/ioport.c | 12 +-
arch/x86/kernel/process_64.c | 12 ++
arch/x86/kvm/i8254.c | 12 +-
arch/x86/kvm/x86.c | 2 +-
arch/x86/xen/enlighten.c | 2 +-
arch/xtensa/kernel/head.S | 2 +-
arch/xtensa/platforms/iss/console.c | 10 +-
crypto/ahash.c | 3 +-
crypto/gcm.c | 3 +
drivers/acpi/acpica/dsmethod.c | 3 +
drivers/block/nbd.c | 4 +-
drivers/block/paride/pd.c | 4 +-
drivers/block/paride/pt.c | 4 +-
drivers/bluetooth/hci_vhci.c | 1 +
drivers/clk/versatile/clk-sp810.c | 4 +-
drivers/edac/amd64_edac.c | 2 +-
drivers/edac/i7core_edac.c | 2 +-
drivers/edac/sb_edac.c | 2 +-
drivers/firmware/efi/vars.c | 37 ++++--
drivers/gpu/drm/radeon/atombios_encoders.c | 6 +-
drivers/gpu/drm/radeon/radeon_sa.c | 7 +
drivers/hid/usbhid/hid-core.c | 73 +++++-----
drivers/hv/vmbus_drv.c | 36 +++++
drivers/hwmon/max1111.c | 6 +
drivers/i2c/busses/i2c-cpm.c | 4 +-
drivers/input/misc/ati_remote2.c | 36 ++++-
drivers/input/misc/ims-pcu.c | 4 +
drivers/input/misc/max8997_haptic.c | 6 +-
drivers/input/misc/powermate.c | 3 +
drivers/input/tablet/gtco.c | 10 +-
drivers/input/touchscreen/ads7846.c | 8 +-
drivers/md/bcache/super.c | 3 +
drivers/md/raid5.c | 4 +-
drivers/media/pci/bt8xx/bttv-driver.c | 26 +++-
drivers/media/usb/pwc/pwc-if.c | 6 +
drivers/media/usb/usbvision/usbvision-video.c | 40 +++++-
drivers/media/v4l2-core/v4l2-compat-ioctl32.c | 21 ++-
drivers/mfd/omap-usb-tll.c | 9 +-
drivers/misc/Kconfig | 2 +-
drivers/misc/ad525x_dpot.c | 2 +-
drivers/mmc/card/block.c | 5 +-
drivers/mmc/core/core.c | 4 +-
drivers/mmc/core/mmc.c | 7 +
drivers/mtd/onenand/onenand_base.c | 3 +-
drivers/net/ethernet/atheros/atlx/atl2.c | 2 +-
drivers/net/ethernet/jme.c | 3 +-
drivers/net/ethernet/qlogic/qlge/qlge_main.c | 11 ++
drivers/net/ethernet/renesas/sh_eth.c | 3 +-
drivers/net/irda/irtty-sir.c | 10 --
drivers/net/ppp/ppp_generic.c | 4 +-
drivers/net/rionet.c | 4 +-
drivers/net/usb/cdc_ncm.c | 6 +-
drivers/net/usb/qmi_wwan.c | 1 +
drivers/net/usb/usbnet.c | 7 +
drivers/net/wan/farsync.c | 2 +-
drivers/net/wireless/ath/ath9k/eeprom.c | 7 +-
drivers/pci/probe.c | 14 ++
drivers/pnp/pnpbios/bioscalls.c | 9 +-
drivers/rtc/rtc-vr41xx.c | 13 +-
drivers/scsi/aacraid/commsup.c | 9 +-
drivers/scsi/be2iscsi/be_main.c | 1 +
drivers/scsi/ipr.c | 10 +-
drivers/scsi/lpfc/lpfc_init.c | 5 +-
drivers/scsi/sg.c | 3 +-
drivers/staging/usbip/usbip_common.c | 11 ++
drivers/tty/serial/8250/8250_core.c | 18 +--
drivers/tty/serial/samsung.c | 4 +-
drivers/tty/vt/vt.c | 5 +-
drivers/usb/class/cdc-acm.c | 3 +
drivers/usb/core/driver.c | 6 +-
drivers/usb/core/hcd-pci.c | 9 ++
drivers/usb/core/hub.c | 8 +-
drivers/usb/host/xhci-mem.c | 5 +
drivers/usb/misc/iowarrior.c | 6 +
drivers/usb/renesas_usbhs/fifo.c | 4 +-
drivers/usb/serial/cp210x.c | 5 +
drivers/usb/serial/cypress_m8.c | 11 +-
drivers/usb/serial/digi_acceleport.c | 19 +++
drivers/usb/serial/io_edgeport.c | 17 ++-
drivers/usb/serial/keyspan.c | 4 +
drivers/usb/serial/mct_u232.c | 9 +-
drivers/usb/serial/option.c | 28 +++-
drivers/usb/serial/quatech2.c | 1 +
drivers/video/da8xx-fb.c | 7 +-
drivers/watchdog/rc32434_wdt.c | 2 +-
fs/cifs/sess.c | 32 +++--
fs/ext4/ext4.h | 23 ++++
fs/ext4/inode.c | 6 +-
fs/ext4/move_extent.c | 11 +-
fs/ext4/super.c | 25 +++-
fs/isofs/rock.c | 13 +-
fs/jbd2/journal.c | 17 ++-
fs/ocfs2/dlm/dlmconvert.c | 24 +++-
fs/ocfs2/dlm/dlmrecovery.c | 1 -
fs/pipe.c | 5 +-
fs/proc/base.c | 3 +-
fs/splice.c | 3 +
include/linux/compiler-gcc.h | 114 +++++++++++++++-
include/linux/compiler-gcc3.h | 23 ----
include/linux/compiler-gcc4.h | 88 -------------
include/linux/compiler-gcc5.h | 66 ----------
include/linux/kernel.h | 6 +-
include/linux/mod_devicetable.h | 7 +
include/linux/pci.h | 1 +
include/linux/poison.h | 4 +-
include/uapi/linux/const.h | 3 +
kernel/sched/core.c | 1 +
kernel/sched/sched.h | 13 ++
kernel/trace/ring_buffer.c | 35 ++---
kernel/trace/trace.c | 5 +-
kernel/trace/trace_irqsoff.c | 8 +-
kernel/trace/trace_printk.c | 3 +
kernel/workqueue.c | 29 ++++
net/batman-adv/send.c | 6 +
net/bridge/br_ioctl.c | 5 +-
net/core/rtnetlink.c | 18 +--
net/decnet/dn_route.c | 9 +-
net/ipv4/route.c | 12 ++
net/ipv6/exthdrs_core.c | 6 +-
net/ipv6/ip6_tunnel.c | 2 +-
net/ipv6/udp.c | 6 +-
net/l2tp/l2tp_ip.c | 8 +-
net/l2tp/l2tp_ip6.c | 8 +-
net/llc/af_llc.c | 1 +
net/netfilter/ipvs/ip_vs_pe_sip.c | 2 +-
net/packet/af_packet.c | 1 +
net/sctp/ipv6.c | 2 +
net/socket.c | 38 +++---
net/vmw_vsock/af_vsock.c | 21 +--
net/wireless/nl80211.c | 2 +-
net/x25/x25_facilities.c | 1 +
scripts/coccinelle/iterators/use_after_iter.cocci | 2 +-
sound/core/timer.c | 4 +-
sound/pci/intel8x0.c | 1 +
sound/soc/samsung/s3c-i2s-v2.c | 2 +-
sound/soc/samsung/s3c-i2s-v2.h | 2 +-
tools/perf/Documentation/perf-stat.txt | 8 ++
virt/kvm/kvm_main.c | 21 +--
152 files changed, 1193 insertions(+), 607 deletions(-)
delete mode 100644 include/linux/compiler-gcc3.h
delete mode 100644 include/linux/compiler-gcc4.h
delete mode 100644 include/linux/compiler-gcc5.h
--
2.8.0.rc2.1.gbe9624a
[toc] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 049/143] Input: ati_remote2 - fix crashes on detecting device with invalid descriptor |
| Message-ID | <rGDtF-5uK-43@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Vladis Dronov <vdronov@redhat.com>
commit 950336ba3e4a1ffd2ca60d29f6ef386dd2c7351d upstream.
The ati_remote2 driver expects at least two interfaces with one
endpoint each. If given malicious descriptor that specify one
interface or no endpoints, it will crash in the probe function.
Ensure there is at least two interfaces and one endpoint for each
interface before using it.
The full disclosure: http://seclists.org/bugtraq/2016/Mar/90
Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/input/misc/ati_remote2.c | 36 ++++++++++++++++++++++++++++++------
1 file changed, 30 insertions(+), 6 deletions(-)
diff --git a/drivers/input/misc/ati_remote2.c b/drivers/input/misc/ati_remote2.c
index f63341f..e8c6a48 100644
--- a/drivers/input/misc/ati_remote2.c
+++ b/drivers/input/misc/ati_remote2.c
@@ -817,26 +817,49 @@ static int ati_remote2_probe(struct usb_interface *interface, const struct usb_d
ar2->udev = udev;
+ /* Sanity check, first interface must have an endpoint */
+ if (alt->desc.bNumEndpoints < 1 || !alt->endpoint) {
+ dev_err(&interface->dev,
+ "%s(): interface 0 must have an endpoint\n", __func__);
+ r = -ENODEV;
+ goto fail1;
+ }
ar2->intf[0] = interface;
ar2->ep[0] = &alt->endpoint[0].desc;
+ /* Sanity check, the device must have two interfaces */
ar2->intf[1] = usb_ifnum_to_if(udev, 1);
+ if ((udev->actconfig->desc.bNumInterfaces < 2) || !ar2->intf[1]) {
+ dev_err(&interface->dev, "%s(): need 2 interfaces, found %d\n",
+ __func__, udev->actconfig->desc.bNumInterfaces);
+ r = -ENODEV;
+ goto fail1;
+ }
+
r = usb_driver_claim_interface(&ati_remote2_driver, ar2->intf[1], ar2);
if (r)
goto fail1;
+
+ /* Sanity check, second interface must have an endpoint */
alt = ar2->intf[1]->cur_altsetting;
+ if (alt->desc.bNumEndpoints < 1 || !alt->endpoint) {
+ dev_err(&interface->dev,
+ "%s(): interface 1 must have an endpoint\n", __func__);
+ r = -ENODEV;
+ goto fail2;
+ }
ar2->ep[1] = &alt->endpoint[0].desc;
r = ati_remote2_urb_init(ar2);
if (r)
- goto fail2;
+ goto fail3;
ar2->channel_mask = channel_mask;
ar2->mode_mask = mode_mask;
r = ati_remote2_setup(ar2, ar2->channel_mask);
if (r)
- goto fail2;
+ goto fail3;
usb_make_path(udev, ar2->phys, sizeof(ar2->phys));
strlcat(ar2->phys, "/input0", sizeof(ar2->phys));
@@ -845,11 +868,11 @@ static int ati_remote2_probe(struct usb_interface *interface, const struct usb_d
r = sysfs_create_group(&udev->dev.kobj, &ati_remote2_attr_group);
if (r)
- goto fail2;
+ goto fail3;
r = ati_remote2_input_init(ar2);
if (r)
- goto fail3;
+ goto fail4;
usb_set_intfdata(interface, ar2);
@@ -857,10 +880,11 @@ static int ati_remote2_probe(struct usb_interface *interface, const struct usb_d
return 0;
- fail3:
+ fail4:
sysfs_remove_group(&udev->dev.kobj, &ati_remote2_attr_group);
- fail2:
+ fail3:
ati_remote2_urb_cleanup(ar2);
+ fail2:
usb_driver_release_interface(&ati_remote2_driver, ar2->intf[1]);
fail1:
kfree(ar2);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 036/143] splice: handle zero nr_pages in splice_to_pipe() |
| Message-ID | <rGDtF-5uK-45@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Rabin Vincent <rabin@rab.in> commit d6785d9152147596f60234157da2b02540c3e60f upstream. Running the following command: busybox cat /sys/kernel/debug/tracing/trace_pipe > /dev/null with any tracing enabled pretty very quickly leads to various NULL pointer dereferences and VM BUG_ON()s, such as these: BUG: unable to handle kernel NULL pointer dereference at 0000000000000020 IP: [<ffffffff8119df6c>] generic_pipe_buf_release+0xc/0x40 Call Trace: [<ffffffff811c48a3>] splice_direct_to_actor+0x143/0x1e0 [<ffffffff811c42e0>] ? generic_pipe_buf_nosteal+0x10/0x10 [<ffffffff811c49cf>] do_splice_direct+0x8f/0xb0 [<ffffffff81196869>] do_sendfile+0x199/0x380 [<ffffffff81197600>] SyS_sendfile64+0x90/0xa0 [<ffffffff8192cbee>] entry_SYSCALL_64_fastpath+0x12/0x6d page dumped because: VM_BUG_ON_PAGE(atomic_read(&page->_count) == 0) kernel BUG at include/linux/mm.h:367! invalid opcode: 0000 [#1] PREEMPT SMP DEBUG_PAGEALLOC RIP: [<ffffffff8119df9c>] generic_pipe_buf_release+0x3c/0x40 Call Trace: [<ffffffff811c48a3>] splice_direct_to_actor+0x143/0x1e0 [<ffffffff811c42e0>] ? generic_pipe_buf_nosteal+0x10/0x10 [<ffffffff811c49cf>] do_splice_direct+0x8f/0xb0 [<ffffffff81196869>] do_sendfile+0x199/0x380 [<ffffffff81197600>] SyS_sendfile64+0x90/0xa0 [<ffffffff8192cd1e>] tracesys_phase2+0x84/0x89 (busybox's cat uses sendfile(2), unlike the coreutils version) This is because tracing_splice_read_pipe() can call splice_to_pipe() with spd->nr_pages == 0. spd_pages underflows in splice_to_pipe() and we fill the page pointers and the other fields of the pipe_buffers with garbage. All other callers of splice_to_pipe() avoid calling it when nr_pages == 0, and we could make tracing_splice_read_pipe() do that too, but it seems reasonable to have splice_to_page() handle this condition gracefully. Cc: stable@vger.kernel.org Signed-off-by: Rabin Vincent <rabin@rab.in> Reviewed-by: Christoph Hellwig <hch@lst.de> Signed-off-by: Al Viro <viro@zeniv.linux.org.uk> Signed-off-by: Willy Tarreau <w@1wt.eu> --- fs/splice.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/fs/splice.c b/fs/splice.c index 3b94a6b..2ffa7b0 100644 --- a/fs/splice.c +++ b/fs/splice.c @@ -189,6 +189,9 @@ ssize_t splice_to_pipe(struct pipe_inode_info *pipe, unsigned int spd_pages = spd->nr_pages; int ret, do_wakeup, page_nr; + if (!spd_pages) + return 0; + ret = 0; do_wakeup = 0; page_nr = 0; -- 2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 124/143] packet: fix heap info leak in PACKET_DIAG_MCLIST sock_diag interface |
| Message-ID | <rGDtF-5uK-51@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Mathias Krause <minipli@googlemail.com>
commit 309cf37fe2a781279b7675d4bb7173198e532867 upstream.
Because we miss to wipe the remainder of i->addr[] in packet_mc_add(),
pdiag_put_mclist() leaks uninitialized heap bytes via the
PACKET_DIAG_MCLIST netlink attribute.
Fix this by explicitly memset(0)ing the remaining bytes in i->addr[].
Fixes: eea68e2f1a00 ("packet: Report socket mclist info via diag module")
Signed-off-by: Mathias Krause <minipli@googlemail.com>
Cc: Eric W. Biederman <ebiederm@xmission.com>
Cc: Pavel Emelyanov <xemul@parallels.com>
Acked-by: Pavel Emelyanov <xemul@virtuozzo.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
net/packet/af_packet.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/packet/af_packet.c b/net/packet/af_packet.c
index 39fa339..2d454a2 100644
--- a/net/packet/af_packet.c
+++ b/net/packet/af_packet.c
@@ -2997,6 +2997,7 @@ static int packet_mc_add(struct sock *sk, struct packet_mreq_max *mreq)
i->ifindex = mreq->mr_ifindex;
i->alen = mreq->mr_alen;
memcpy(i->addr, mreq->mr_address, i->alen);
+ memset(i->addr + i->alen, 0, sizeof(i->addr) - i->alen);
i->count = 1;
i->next = po->mclist;
po->mclist = i;
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 038/143] xtensa: clear all DBREAKC registers on start |
| Message-ID | <rGDtF-5uK-53@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Max Filippov <jcmvbkbc@gmail.com> commit 7de7ac785ae18a2cdc78d7560f48e3213d9ea0ab upstream. There are XCHAL_NUM_DBREAK registers, clear them all. This also fixes cryptic assembler error message with binutils 2.25 when XCHAL_NUM_DBREAK is 0: as: out of memory allocating 18446744073709551575 bytes after a total of 495616 bytes Cc: stable@vger.kernel.org Signed-off-by: Max Filippov <jcmvbkbc@gmail.com> Signed-off-by: Willy Tarreau <w@1wt.eu> --- arch/xtensa/kernel/head.S | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/xtensa/kernel/head.S b/arch/xtensa/kernel/head.S index 7d740eb..bb12d77 100644 --- a/arch/xtensa/kernel/head.S +++ b/arch/xtensa/kernel/head.S @@ -118,7 +118,7 @@ ENTRY(_startup) wsr a0, icountlevel .set _index, 0 - .rept XCHAL_NUM_DBREAK - 1 + .rept XCHAL_NUM_DBREAK wsr a0, SREG_DBREAKC + _index .set _index, _index + 1 .endr -- 2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 016/143] be2iscsi: set the boot_kset pointer to NULL in case of failure |
| Message-ID | <rGDtF-5uK-49@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Maurizio Lombardi <mlombard@redhat.com> commit 84bd64993f916bcf86270c67686ecf4cea7b8933 upstream. In beiscsi_setup_boot_info(), the boot_kset pointer should be set to NULL in case of failure otherwise an invalid pointer dereference may occur later. Cc: <stable@vger.kernel.org> Signed-off-by: Maurizio Lombardi <mlombard@redhat.com> Reviewed-by: Johannes Thumshirn <jthumshirn@suse.de> Reviewed-by: Jitendra Bhivare <jitendra.bhivare@broadcom.com> Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com> Signed-off-by: Willy Tarreau <w@1wt.eu> --- drivers/scsi/be2iscsi/be_main.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/scsi/be2iscsi/be_main.c b/drivers/scsi/be2iscsi/be_main.c index bfe812f..a683a83 100644 --- a/drivers/scsi/be2iscsi/be_main.c +++ b/drivers/scsi/be2iscsi/be_main.c @@ -4040,6 +4040,7 @@ put_shost: scsi_host_put(phba->shost); free_kset: iscsi_boot_destroy_kset(phba->boot_kset); + phba->boot_kset = NULL; return -ENOMEM; } -- 2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 123/143] route: do not cache fib route info on local routes with oif |
| Message-ID | <rGDtF-5uK-57@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Chris Friesen <chris.friesen@windriver.com>
commit d6d5e999e5df67f8ec20b6be45e2229455ee3699 upstream.
For local routes that require a particular output interface we do not want
to cache the result. Caching the result causes incorrect behaviour when
there are multiple source addresses on the interface. The end result
being that if the intended recipient is waiting on that interface for the
packet he won't receive it because it will be delivered on the loopback
interface and the IP_PKTINFO ipi_ifindex will be set to the loopback
interface as well.
This can be tested by running a program such as "dhcp_release" which
attempts to inject a packet on a particular interface so that it is
received by another program on the same board. The receiving process
should see an IP_PKTINFO ipi_ifndex value of the source interface
(e.g., eth1) instead of the loopback interface (e.g., lo). The packet
will still appear on the loopback interface in tcpdump but the important
aspect is that the CMSG info is correct.
Sample dhcp_release command line:
dhcp_release eth1 192.168.204.222 02:11:33:22:44:66
Signed-off-by: Allain Legacy <allain.legacy@windriver.com>
Signed off-by: Chris Friesen <chris.friesen@windriver.com>
Reviewed-by: Julian Anastasov <ja@ssi.bg>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
net/ipv4/route.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/net/ipv4/route.c b/net/ipv4/route.c
index 222e1b6..624ca8e 100644
--- a/net/ipv4/route.c
+++ b/net/ipv4/route.c
@@ -1876,6 +1876,18 @@ static struct rtable *__mkroute_output(const struct fib_result *res,
*/
if (fi && res->prefixlen < 4)
fi = NULL;
+ } else if ((type == RTN_LOCAL) && (orig_oif != 0) &&
+ (orig_oif != dev_out->ifindex)) {
+ /* For local routes that require a particular output interface
+ * we do not want to cache the result. Caching the result
+ * causes incorrect behaviour when there are multiple source
+ * addresses on the interface, the end result being that if the
+ * intended recipient is waiting on that interface for the
+ * packet he won't receive it because it will be delivered on
+ * the loopback interface and the IP_PKTINFO ipi_ifindex will
+ * be set to the loopback interface as well.
+ */
+ fi = NULL;
}
fnhe = NULL;
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 077/143] ext4: add lockdep annotations for i_data_sem |
| Message-ID | <rGDtF-5uK-59@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Theodore Ts'o <tytso@mit.edu>
commit daf647d2dd58cec59570d7698a45b98e580f2076 upstream.
With the internal Quota feature, mke2fs creates empty quota inodes and
quota usage tracking is enabled as soon as the file system is mounted.
Since quotacheck is no longer preallocating all of the blocks in the
quota inode that are likely needed to be written to, we are now seeing
a lockdep false positive caused by needing to allocate a quota block
from inside ext4_map_blocks(), while holding i_data_sem for a data
inode. This results in this complaint:
Possible unsafe locking scenario:
CPU0 CPU1
---- ----
lock(&ei->i_data_sem);
lock(&s->s_dquot.dqio_mutex);
lock(&ei->i_data_sem);
lock(&s->s_dquot.dqio_mutex);
Google-Bug-Id: 27907753
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
fs/ext4/ext4.h | 23 +++++++++++++++++++++++
fs/ext4/move_extent.c | 11 +++++++++--
fs/ext4/super.c | 25 +++++++++++++++++++++++--
3 files changed, 55 insertions(+), 4 deletions(-)
diff --git a/fs/ext4/ext4.h b/fs/ext4/ext4.h
index 6f74b89..046e3e9 100644
--- a/fs/ext4/ext4.h
+++ b/fs/ext4/ext4.h
@@ -851,6 +851,29 @@ do { \
#include "extents_status.h"
/*
+ * Lock subclasses for i_data_sem in the ext4_inode_info structure.
+ *
+ * These are needed to avoid lockdep false positives when we need to
+ * allocate blocks to the quota inode during ext4_map_blocks(), while
+ * holding i_data_sem for a normal (non-quota) inode. Since we don't
+ * do quota tracking for the quota inode, this avoids deadlock (as
+ * well as infinite recursion, since it isn't turtles all the way
+ * down...)
+ *
+ * I_DATA_SEM_NORMAL - Used for most inodes
+ * I_DATA_SEM_OTHER - Used by move_inode.c for the second normal inode
+ * where the second inode has larger inode number
+ * than the first
+ * I_DATA_SEM_QUOTA - Used for quota inodes only
+ */
+enum {
+ I_DATA_SEM_NORMAL = 0,
+ I_DATA_SEM_OTHER,
+ I_DATA_SEM_QUOTA,
+};
+
+
+/*
* fourth extended file system inode data in memory
*/
struct ext4_inode_info {
diff --git a/fs/ext4/move_extent.c b/fs/ext4/move_extent.c
index 3dcbf36..ad52ace 100644
--- a/fs/ext4/move_extent.c
+++ b/fs/ext4/move_extent.c
@@ -154,10 +154,10 @@ ext4_double_down_write_data_sem(struct inode *first, struct inode *second)
{
if (first < second) {
down_write(&EXT4_I(first)->i_data_sem);
- down_write_nested(&EXT4_I(second)->i_data_sem, SINGLE_DEPTH_NESTING);
+ down_write_nested(&EXT4_I(second)->i_data_sem, I_DATA_SEM_OTHER);
} else {
down_write(&EXT4_I(second)->i_data_sem);
- down_write_nested(&EXT4_I(first)->i_data_sem, SINGLE_DEPTH_NESTING);
+ down_write_nested(&EXT4_I(first)->i_data_sem, I_DATA_SEM_OTHER);
}
}
@@ -1117,6 +1117,13 @@ mext_check_arguments(struct inode *orig_inode,
return -EINVAL;
}
+ if (IS_NOQUOTA(orig_inode) || IS_NOQUOTA(donor_inode)) {
+ ext4_debug("ext4 move extent: The argument files should "
+ "not be quota files [ino:orig %lu, donor %lu]\n",
+ orig_inode->i_ino, donor_inode->i_ino);
+ return -EBUSY;
+ }
+
/* Ext4 move extent supports only extent based file */
if (!(ext4_test_inode_flag(orig_inode, EXT4_INODE_EXTENTS))) {
ext4_debug("ext4 move extent: orig file is not extents "
diff --git a/fs/ext4/super.c b/fs/ext4/super.c
index a7e0797..063eb50 100644
--- a/fs/ext4/super.c
+++ b/fs/ext4/super.c
@@ -4984,6 +4984,20 @@ static int ext4_quota_on_mount(struct super_block *sb, int type)
EXT4_SB(sb)->s_jquota_fmt, type);
}
+static void lockdep_set_quota_inode(struct inode *inode, int subclass)
+{
+ struct ext4_inode_info *ei = EXT4_I(inode);
+
+ /* The first argument of lockdep_set_subclass has to be
+ * *exactly* the same as the argument to init_rwsem() --- in
+ * this case, in init_once() --- or lockdep gets unhappy
+ * because the name of the lock is set using the
+ * stringification of the argument to init_rwsem().
+ */
+ (void) ei; /* shut up clang warning if !CONFIG_LOCKDEP */
+ lockdep_set_subclass(&ei->i_data_sem, subclass);
+}
+
/*
* Standard function to be called on quota_on
*/
@@ -5023,8 +5037,12 @@ static int ext4_quota_on(struct super_block *sb, int type, int format_id,
if (err)
return err;
}
-
- return dquot_quota_on(sb, type, format_id, path);
+ lockdep_set_quota_inode(path->dentry->d_inode, I_DATA_SEM_QUOTA);
+ err = dquot_quota_on(sb, type, format_id, path);
+ if (err)
+ lockdep_set_quota_inode(path->dentry->d_inode,
+ I_DATA_SEM_NORMAL);
+ return err;
}
static int ext4_quota_enable(struct super_block *sb, int type, int format_id,
@@ -5050,8 +5068,11 @@ static int ext4_quota_enable(struct super_block *sb, int type, int format_id,
/* Don't account quota for quota files to avoid recursion */
qf_inode->i_flags |= S_NOQUOTA;
+ lockdep_set_quota_inode(qf_inode, I_DATA_SEM_QUOTA);
err = dquot_enable(qf_inode, type, format_id, flags);
iput(qf_inode);
+ if (err)
+ lockdep_set_quota_inode(qf_inode, I_DATA_SEM_NORMAL);
return err;
}
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 048/143] Input: ims-pcu - sanity check against missing interfaces |
| Message-ID | <rGDtF-5uK-55@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Oliver Neukum <oneukum@suse.com>
commit a0ad220c96692eda76b2e3fd7279f3dcd1d8a8ff upstream.
A malicious device missing interface can make the driver oops.
Add sanity checking.
Signed-off-by: Oliver Neukum <ONeukum@suse.com>
CC: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/input/misc/ims-pcu.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/input/misc/ims-pcu.c b/drivers/input/misc/ims-pcu.c
index e204f26..77164dc 100644
--- a/drivers/input/misc/ims-pcu.c
+++ b/drivers/input/misc/ims-pcu.c
@@ -1433,6 +1433,8 @@ static int ims_pcu_parse_cdc_data(struct usb_interface *intf, struct ims_pcu *pc
pcu->ctrl_intf = usb_ifnum_to_if(pcu->udev,
union_desc->bMasterInterface0);
+ if (!pcu->ctrl_intf)
+ return -EINVAL;
alt = pcu->ctrl_intf->cur_altsetting;
pcu->ep_ctrl = &alt->endpoint[0].desc;
@@ -1440,6 +1442,8 @@ static int ims_pcu_parse_cdc_data(struct usb_interface *intf, struct ims_pcu *pc
pcu->data_intf = usb_ifnum_to_if(pcu->udev,
union_desc->bSlaveInterface0);
+ if (!pcu->data_intf)
+ return -EINVAL;
alt = pcu->data_intf->cur_altsetting;
if (alt->desc.bNumEndpoints != 2) {
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 113/143] USB: serial: cp210x: add ID for Link ECU |
| Message-ID | <rGDtG-5uK-73@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Mike Manning <michael@bsch.com.au>
commit 1d377f4d690637a0121eac8701f84a0aa1e69a69 upstream.
The Link ECU is an aftermarket ECU computer for vehicles that provides
full tuning abilities as well as datalogging and displaying capabilities
via the USB to Serial adapter built into the device.
Signed-off-by: Mike Manning <michael@bsch.com.au>
Cc: stable <stable@vger.kernel.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/usb/serial/cp210x.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/usb/serial/cp210x.c b/drivers/usb/serial/cp210x.c
index a4003d4..40e2d58 100644
--- a/drivers/usb/serial/cp210x.c
+++ b/drivers/usb/serial/cp210x.c
@@ -140,6 +140,8 @@ static const struct usb_device_id id_table[] = {
{ USB_DEVICE(0x10C4, 0xF004) }, /* Elan Digital Systems USBcount50 */
{ USB_DEVICE(0x10C5, 0xEA61) }, /* Silicon Labs MobiData GPRS USB Modem */
{ USB_DEVICE(0x10CE, 0xEA6A) }, /* Silicon Labs MobiData GPRS USB Modem 100EU */
+ { USB_DEVICE(0x12B8, 0xEC60) }, /* Link G4 ECU */
+ { USB_DEVICE(0x12B8, 0xEC62) }, /* Link G4+ ECU */
{ USB_DEVICE(0x13AD, 0x9999) }, /* Baltech card reader */
{ USB_DEVICE(0x1555, 0x0004) }, /* Owen AC4 USB-RS485 Converter */
{ USB_DEVICE(0x166A, 0x0201) }, /* Clipsal 5500PACA C-Bus Pascal Automation Controller */
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 046/143] tracing: Fix trace_printk() to print when not using bprintk() |
| Message-ID | <rGDtF-5uK-61@gated-at.bofh.it> |
| In reply to | #1413978 |
From: "Steven Rostedt (Red Hat)" <rostedt@goodmis.org>
commit 3debb0a9ddb16526de8b456491b7db60114f7b5e upstream.
The trace_printk() code will allocate extra buffers if the compile detects
that a trace_printk() is used. To do this, the format of the trace_printk()
is saved to the __trace_printk_fmt section, and if that section is bigger
than zero, the buffers are allocated (along with a message that this has
happened).
If trace_printk() uses a format that is not a constant, and thus something
not guaranteed to be around when the print happens, the compiler optimizes
the fmt out, as it is not used, and the __trace_printk_fmt section is not
filled. This means the kernel will not allocate the special buffers needed
for the trace_printk() and the trace_printk() will not write anything to the
tracing buffer.
Adding a "__used" to the variable in the __trace_printk_fmt section will
keep it around, even though it is set to NULL. This will keep the string
from being printed in the debugfs/tracing/printk_formats section as it is
not needed.
Reported-by: Vlastimil Babka <vbabka@suse.cz>
Fixes: 07d777fe8c398 "tracing: Add percpu buffers for trace_printk()"
Cc: stable@vger.kernel.org # v3.5+
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
include/linux/kernel.h | 6 +++---
kernel/trace/trace_printk.c | 3 +++
2 files changed, 6 insertions(+), 3 deletions(-)
diff --git a/include/linux/kernel.h b/include/linux/kernel.h
index 341551c..5f4554b 100644
--- a/include/linux/kernel.h
+++ b/include/linux/kernel.h
@@ -557,7 +557,7 @@ do { \
#define do_trace_printk(fmt, args...) \
do { \
- static const char *trace_printk_fmt \
+ static const char *trace_printk_fmt __used \
__attribute__((section("__trace_printk_fmt"))) = \
__builtin_constant_p(fmt) ? fmt : NULL; \
\
@@ -604,7 +604,7 @@ extern int __trace_puts(unsigned long ip, const char *str, int size);
*/
#define trace_puts(str) ({ \
- static const char *trace_printk_fmt \
+ static const char *trace_printk_fmt __used \
__attribute__((section("__trace_printk_fmt"))) = \
__builtin_constant_p(str) ? str : NULL; \
\
@@ -624,7 +624,7 @@ extern void trace_dump_stack(int skip);
#define ftrace_vprintk(fmt, vargs) \
do { \
if (__builtin_constant_p(fmt)) { \
- static const char *trace_printk_fmt \
+ static const char *trace_printk_fmt __used \
__attribute__((section("__trace_printk_fmt"))) = \
__builtin_constant_p(fmt) ? fmt : NULL; \
\
diff --git a/kernel/trace/trace_printk.c b/kernel/trace/trace_printk.c
index a9077c1..fdb23e8 100644
--- a/kernel/trace/trace_printk.c
+++ b/kernel/trace/trace_printk.c
@@ -272,6 +272,9 @@ static int t_show(struct seq_file *m, void *v)
const char *str = *fmt;
int i;
+ if (!*fmt)
+ return 0;
+
seq_printf(m, "0x%lx : \"", *(unsigned long *)fmt);
/*
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 076/143] usb: renesas_usbhs: disable TX IRQ before starting TX DMAC transfer |
| Message-ID | <rGDtG-5uK-65@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Yoshihiro Shimoda <yoshihiro.shimoda.uh@renesas.com>
commit 6490865c67825277b29638e839850882600b48ec upstream.
This patch adds a code to surely disable TX IRQ of the pipe before
starting TX DMAC transfer. Otherwise, a lot of unnecessary TX IRQs
may happen in rare cases when DMAC is used.
Fixes: e73a989 ("usb: renesas_usbhs: add DMAEngine support")
Cc: <stable@vger.kernel.org> # v3.1+
Signed-off-by: Yoshihiro Shimoda <yoshihiro.shimoda.uh@renesas.com>
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/usb/renesas_usbhs/fifo.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/usb/renesas_usbhs/fifo.c b/drivers/usb/renesas_usbhs/fifo.c
index 540e688..157a9f9 100644
--- a/drivers/usb/renesas_usbhs/fifo.c
+++ b/drivers/usb/renesas_usbhs/fifo.c
@@ -934,6 +934,7 @@ static int usbhsf_dma_try_pop(struct usbhs_pkt *pkt, int *is_done)
pkt->trans = len;
+ usbhsf_tx_irq_ctrl(pipe, 0);
INIT_WORK(&pkt->work, xfer_work);
schedule_work(&pkt->work);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 106/143] clk: versatile: sp810: support reentrance |
| Message-ID | <rGDtG-5uK-69@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Linus Walleij <linus.walleij@linaro.org>
commit ec7957a6aa0aaf981fb8356dc47a2cdd01cde03c upstream.
Despite care take to allocate clocks state containers the
SP810 driver actually just supports creating one instance:
all clocks registered for every instance will end up with the
exact same name and __clk_init() will fail.
Rename the timclken<0> .. timclken<n> to sp810_<instance>_<n>
so every clock on every instance gets a unique name.
This is necessary for the RealView PBA8 which has two SP810
blocks: the second block will not register its clocks unless
every clock on every instance is unique and results in boot
logs like this:
------------[ cut here ]------------
WARNING: CPU: 0 PID: 0 at ../drivers/clk/versatile/clk-sp810.c:137
clk_sp810_of_setup+0x110/0x154()
Modules linked in:
CPU: 0 PID: 0 Comm: swapper/0 Not tainted
4.5.0-rc2-00030-g352718fc39f6-dirty #225
Hardware name: ARM RealView Machine (Device Tree Support)
[<c00167f8>] (unwind_backtrace) from [<c0013204>]
(show_stack+0x10/0x14)
[<c0013204>] (show_stack) from [<c01a049c>]
(dump_stack+0x84/0x9c)
[<c01a049c>] (dump_stack) from [<c0024990>]
(warn_slowpath_common+0x74/0xb0)
[<c0024990>] (warn_slowpath_common) from [<c0024a68>]
(warn_slowpath_null+0x1c/0x24)
[<c0024a68>] (warn_slowpath_null) from [<c051eb44>]
(clk_sp810_of_setup+0x110/0x154)
[<c051eb44>] (clk_sp810_of_setup) from [<c051e3a4>]
(of_clk_init+0x12c/0x1c8)
[<c051e3a4>] (of_clk_init) from [<c0504714>]
(time_init+0x20/0x2c)
[<c0504714>] (time_init) from [<c0501b18>]
(start_kernel+0x244/0x3c4)
[<c0501b18>] (start_kernel) from [<7000807c>] (0x7000807c)
---[ end trace cb88537fdc8fa200 ]---
Cc: Michael Turquette <mturquette@baylibre.com>
Cc: Pawel Moll <pawel.moll@arm.com>
Fixes: 6e973d2c4385 "clk: vexpress: Add separate SP810 driver"
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Stephen Boyd <sboyd@codeaurora.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/clk/versatile/clk-sp810.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/clk/versatile/clk-sp810.c b/drivers/clk/versatile/clk-sp810.c
index b9e05bd..a21e2fa 100644
--- a/drivers/clk/versatile/clk-sp810.c
+++ b/drivers/clk/versatile/clk-sp810.c
@@ -141,6 +141,7 @@ void __init clk_sp810_of_setup(struct device_node *node)
const char *parent_names[2];
char name[12];
struct clk_init_data init;
+ static int instance;
int i;
if (!sp810) {
@@ -172,7 +173,7 @@ void __init clk_sp810_of_setup(struct device_node *node)
init.num_parents = ARRAY_SIZE(parent_names);
for (i = 0; i < ARRAY_SIZE(sp810->timerclken); i++) {
- snprintf(name, ARRAY_SIZE(name), "timerclken%d", i);
+ snprintf(name, sizeof(name), "sp810_%d_%d", instance, i);
sp810->timerclken[i].sp810 = sp810;
sp810->timerclken[i].channel = i;
@@ -184,5 +185,6 @@ void __init clk_sp810_of_setup(struct device_node *node)
}
of_clk_add_provider(node, clk_sp810_timerclken_of_get, sp810);
+ instance++;
}
CLK_OF_DECLARE(sp810, "arm,sp810", clk_sp810_of_setup);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 143/143] serial: samsung: Reorder the sequence of clock control when call s3c24xx_serial_set_termios() |
| Message-ID | <rGDtG-5uK-79@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Chanwoo Choi <cw00.choi@samsung.com>
commit b8995f527aac143e83d3900ff39357651ea4e0f6 upstream.
This patch fixes the broken serial log when changing the clock source
of uart device. Before disabling the original clock source, this patch
enables the new clock source to protect the clock off state for a split second.
Signed-off-by: Chanwoo Choi <cw00.choi@samsung.com>
Reviewed-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/tty/serial/samsung.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/tty/serial/samsung.c b/drivers/tty/serial/samsung.c
index b8366b1..921bf90 100644
--- a/drivers/tty/serial/samsung.c
+++ b/drivers/tty/serial/samsung.c
@@ -724,6 +724,8 @@ static void s3c24xx_serial_set_termios(struct uart_port *port,
/* check to see if we need to change clock source */
if (ourport->baudclk != clk) {
+ clk_prepare_enable(clk);
+
s3c24xx_serial_setsource(port, clk_sel);
if (!IS_ERR(ourport->baudclk)) {
@@ -731,8 +733,6 @@ static void s3c24xx_serial_set_termios(struct uart_port *port,
ourport->baudclk = ERR_PTR(-EINVAL);
}
- clk_prepare_enable(clk);
-
ourport->baudclk = clk;
ourport->baudclk_rate = clk ? clk_get_rate(clk) : 0;
}
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 134/143] mfd: omap-usb-tll: Fix scheduling while atomic BUG |
| Message-ID | <rGDtF-5uK-63@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Roger Quadros <rogerq@ti.com>
commit b49b927f16acee626c56a1af4ab4cb062f75b5df upstream.
We shouldn't be calling clk_prepare_enable()/clk_prepare_disable()
in an atomic context.
Fixes the following issue:
[ 5.830970] ehci-omap: OMAP-EHCI Host Controller driver
[ 5.830974] driver_register 'ehci-omap'
[ 5.895849] driver_register 'wl1271_sdio'
[ 5.896870] BUG: scheduling while atomic: udevd/994/0x00000002
[ 5.896876] 4 locks held by udevd/994:
[ 5.896904] #0: (&dev->mutex){......}, at: [<c049597c>] __driver_attach+0x60/0xac
[ 5.896923] #1: (&dev->mutex){......}, at: [<c049598c>] __driver_attach+0x70/0xac
[ 5.896946] #2: (tll_lock){+.+...}, at: [<c04c2630>] omap_tll_enable+0x2c/0xd0
[ 5.896966] #3: (prepare_lock){+.+...}, at: [<c05ce9c8>] clk_prepare_lock+0x48/0xe0
[ 5.897042] Modules linked in: wlcore_sdio(+) ehci_omap(+) dwc3_omap snd_soc_ts3a225e leds_is31fl319x bq27xxx_battery_i2c tsc2007 bq27xxx_battery bq2429x_charger ina2xx tca8418_keypad as5013 leds_tca6507 twl6040_vibra gpio_twl6040 bmp085_i2c(+) palmas_gpadc usb3503 palmas_pwrbutton bmg160_i2c(+) bmp085 bma150(+) bmg160_core bmp280 input_polldev snd_soc_omap_mcbsp snd_soc_omap_mcpdm snd_soc_omap snd_pcm_dmaengine
[ 5.897048] Preemption disabled at:[< (null)>] (null)
[ 5.897051]
[ 5.897059] CPU: 0 PID: 994 Comm: udevd Not tainted 4.6.0-rc5-letux+ #233
[ 5.897062] Hardware name: Generic OMAP5 (Flattened Device Tree)
[ 5.897076] [<c010e714>] (unwind_backtrace) from [<c010af34>] (show_stack+0x10/0x14)
[ 5.897087] [<c010af34>] (show_stack) from [<c040aa7c>] (dump_stack+0x88/0xc0)
[ 5.897099] [<c040aa7c>] (dump_stack) from [<c020c558>] (__schedule_bug+0xac/0xd0)
[ 5.897111] [<c020c558>] (__schedule_bug) from [<c06f3d44>] (__schedule+0x88/0x7e4)
[ 5.897120] [<c06f3d44>] (__schedule) from [<c06f46d8>] (schedule+0x9c/0xc0)
[ 5.897129] [<c06f46d8>] (schedule) from [<c06f4904>] (schedule_preempt_disabled+0x14/0x20)
[ 5.897140] [<c06f4904>] (schedule_preempt_disabled) from [<c06f64e4>] (mutex_lock_nested+0x258/0x43c)
[ 5.897150] [<c06f64e4>] (mutex_lock_nested) from [<c05ce9c8>] (clk_prepare_lock+0x48/0xe0)
[ 5.897160] [<c05ce9c8>] (clk_prepare_lock) from [<c05d0e7c>] (clk_prepare+0x10/0x28)
[ 5.897169] [<c05d0e7c>] (clk_prepare) from [<c04c2668>] (omap_tll_enable+0x64/0xd0)
[ 5.897180] [<c04c2668>] (omap_tll_enable) from [<c04c1728>] (usbhs_runtime_resume+0x18/0x17c)
[ 5.897192] [<c04c1728>] (usbhs_runtime_resume) from [<c049d404>] (pm_generic_runtime_resume+0x2c/0x40)
[ 5.897202] [<c049d404>] (pm_generic_runtime_resume) from [<c049f180>] (__rpm_callback+0x38/0x68)
[ 5.897210] [<c049f180>] (__rpm_callback) from [<c049f220>] (rpm_callback+0x70/0x88)
[ 5.897218] [<c049f220>] (rpm_callback) from [<c04a0a00>] (rpm_resume+0x4ec/0x7ec)
[ 5.897227] [<c04a0a00>] (rpm_resume) from [<c04a0f48>] (__pm_runtime_resume+0x4c/0x64)
[ 5.897236] [<c04a0f48>] (__pm_runtime_resume) from [<c04958dc>] (driver_probe_device+0x30/0x70)
[ 5.897246] [<c04958dc>] (driver_probe_device) from [<c04959a4>] (__driver_attach+0x88/0xac)
[ 5.897256] [<c04959a4>] (__driver_attach) from [<c04940f8>] (bus_for_each_dev+0x50/0x84)
[ 5.897267] [<c04940f8>] (bus_for_each_dev) from [<c0494e40>] (bus_add_driver+0xcc/0x1e4)
[ 5.897276] [<c0494e40>] (bus_add_driver) from [<c0496914>] (driver_register+0xac/0xf4)
[ 5.897286] [<c0496914>] (driver_register) from [<c01018e0>] (do_one_initcall+0x100/0x1b8)
[ 5.897296] [<c01018e0>] (do_one_initcall) from [<c01c7a54>] (do_init_module+0x58/0x1c0)
[ 5.897304] [<c01c7a54>] (do_init_module) from [<c01c8a3c>] (SyS_finit_module+0x88/0x90)
[ 5.897313] [<c01c8a3c>] (SyS_finit_module) from [<c0107120>] (ret_fast_syscall+0x0/0x1c)
[ 5.912697] ------------[ cut here ]------------
[ 5.912711] WARNING: CPU: 0 PID: 994 at kernel/sched/core.c:2996 _raw_spin_unlock+0x28/0x58
[ 5.912717] DEBUG_LOCKS_WARN_ON(val > preempt_count())
Reported-by: H. Nikolaus Schaller <hns@goldelico.com>
Tested-by: H. Nikolaus Schaller <hns@goldelico.com>
Signed-off-by: Roger Quadros <rogerq@ti.com>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/mfd/omap-usb-tll.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/drivers/mfd/omap-usb-tll.c b/drivers/mfd/omap-usb-tll.c
index e59ac4c..c7576a5 100644
--- a/drivers/mfd/omap-usb-tll.c
+++ b/drivers/mfd/omap-usb-tll.c
@@ -269,6 +269,8 @@ static int usbtll_omap_probe(struct platform_device *pdev)
if (IS_ERR(tll->ch_clk[i]))
dev_dbg(dev, "can't get clock : %s\n", clkname);
+ else
+ clk_prepare(tll->ch_clk[i]);
}
pm_runtime_put_sync(dev);
@@ -301,9 +303,12 @@ static int usbtll_omap_remove(struct platform_device *pdev)
tll_dev = NULL;
spin_unlock(&tll_lock);
- for (i = 0; i < tll->nch; i++)
- if (!IS_ERR(tll->ch_clk[i]))
+ for (i = 0; i < tll->nch; i++) {
+ if (!IS_ERR(tll->ch_clk[i])) {
+ clk_unprepare(tll->ch_clk[i]);
clk_put(tll->ch_clk[i]);
+ }
+ }
pm_runtime_disable(&pdev->dev);
return 0;
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 133/143] ring-buffer: Prevent overflow of size in ring_buffer_resize() |
| Message-ID | <rGDtG-5uK-71@gated-at.bofh.it> |
| In reply to | #1413978 |
From: "Steven Rostedt (Red Hat)" <rostedt@goodmis.org>
commit 59643d1535eb220668692a5359de22545af579f6 upstream.
If the size passed to ring_buffer_resize() is greater than MAX_LONG - BUF_PAGE_SIZE
then the DIV_ROUND_UP() will return zero.
Here's the details:
# echo 18014398509481980 > /sys/kernel/debug/tracing/buffer_size_kb
tracing_entries_write() processes this and converts kb to bytes.
18014398509481980 << 10 = 18446744073709547520
and this is passed to ring_buffer_resize() as unsigned long size.
size = DIV_ROUND_UP(size, BUF_PAGE_SIZE);
Where DIV_ROUND_UP(a, b) is (a + b - 1)/b
BUF_PAGE_SIZE is 4080 and here
18446744073709547520 + 4080 - 1 = 18446744073709551599
where 18446744073709551599 is still smaller than 2^64
2^64 - 18446744073709551599 = 17
But now 18446744073709551599 / 4080 = 4521260802379792
and size = size * 4080 = 18446744073709551360
This is checked to make sure its still greater than 2 * 4080,
which it is.
Then we convert to the number of buffer pages needed.
nr_page = DIV_ROUND_UP(size, BUF_PAGE_SIZE)
but this time size is 18446744073709551360 and
2^64 - (18446744073709551360 + 4080 - 1) = -3823
Thus it overflows and the resulting number is less than 4080, which makes
3823 / 4080 = 0
an nr_pages is set to this. As we already checked against the minimum that
nr_pages may be, this causes the logic to fail as well, and we crash the
kernel.
There's no reason to have the two DIV_ROUND_UP() (that's just result of
historical code changes), clean up the code and fix this bug.
Cc: stable@vger.kernel.org # 3.5+
Fixes: 83f40318dab00 ("ring-buffer: Make removal of ring buffer pages atomic")
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
kernel/trace/ring_buffer.c | 9 ++++-----
1 file changed, 4 insertions(+), 5 deletions(-)
diff --git a/kernel/trace/ring_buffer.c b/kernel/trace/ring_buffer.c
index 6f70235..c4ce3a9 100644
--- a/kernel/trace/ring_buffer.c
+++ b/kernel/trace/ring_buffer.c
@@ -1644,14 +1644,13 @@ int ring_buffer_resize(struct ring_buffer *buffer, unsigned long size,
!cpumask_test_cpu(cpu_id, buffer->cpumask))
return size;
- size = DIV_ROUND_UP(size, BUF_PAGE_SIZE);
- size *= BUF_PAGE_SIZE;
+ nr_pages = DIV_ROUND_UP(size, BUF_PAGE_SIZE);
/* we need a minimum of two pages */
- if (size < BUF_PAGE_SIZE * 2)
- size = BUF_PAGE_SIZE * 2;
+ if (nr_pages < 2)
+ nr_pages = 2;
- nr_pages = DIV_ROUND_UP(size, BUF_PAGE_SIZE);
+ size = nr_pages * BUF_PAGE_SIZE;
/*
* Don't succeed if resizing is disabled, as a reader might be
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 061/143] ipv6: re-enable fragment header matching in ipv6_find_hdr |
| Message-ID | <rGDtG-5uK-67@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Florian Westphal <fw@strlen.de>
commit 5d150a985520bbe3cb2aa1ceef24a7e32f20c15f upstream.
When ipv6_find_hdr is used to find a fragment header
(caller specifies target NEXTHDR_FRAGMENT) we erronously return
-ENOENT for all fragments with nonzero offset.
Before commit 9195bb8e381d, when target was specified, we did not
enter the exthdr walk loop as nexthdr == target so this used to work.
Now we do (so we can skip empty route headers). When we then stumble upon
a frag with nonzero frag_off we must return -ENOENT ("header not found")
only if the caller did not specifically request NEXTHDR_FRAGMENT.
This allows nfables exthdr expression to match ipv6 fragments, e.g. via
nft add rule ip6 filter input frag frag-off gt 0
Fixes: 9195bb8e381d ("ipv6: improve ipv6_find_hdr() to skip empty routing headers")
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
net/ipv6/exthdrs_core.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/net/ipv6/exthdrs_core.c b/net/ipv6/exthdrs_core.c
index 51af9d0..f66c1b6 100644
--- a/net/ipv6/exthdrs_core.c
+++ b/net/ipv6/exthdrs_core.c
@@ -257,7 +257,11 @@ int ipv6_find_hdr(const struct sk_buff *skb, unsigned int *offset,
*fragoff = _frag_off;
return hp->nexthdr;
}
- return -ENOENT;
+ if (!found)
+ return -ENOENT;
+ if (fragoff)
+ *fragoff = _frag_off;
+ break;
}
hdrlen = 8;
} else if (nexthdr == NEXTHDR_AUTH) {
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 132/143] ring-buffer: Use long for nr_pages to avoid overflow failures |
| Message-ID | <rGDtG-5uK-75@gated-at.bofh.it> |
| In reply to | #1413978 |
From: "Steven Rostedt (Red Hat)" <rostedt@goodmis.org>
commit 9b94a8fba501f38368aef6ac1b30e7335252a220 upstream.
The size variable to change the ring buffer in ftrace is a long. The
nr_pages used to update the ring buffer based on the size is int. On 64 bit
machines this can cause an overflow problem.
For example, the following will cause the ring buffer to crash:
# cd /sys/kernel/debug/tracing
# echo 10 > buffer_size_kb
# echo 8556384240 > buffer_size_kb
Then you get the warning of:
WARNING: CPU: 1 PID: 318 at kernel/trace/ring_buffer.c:1527 rb_update_pages+0x22f/0x260
Which is:
RB_WARN_ON(cpu_buffer, nr_removed);
Note each ring buffer page holds 4080 bytes.
This is because:
1) 10 causes the ring buffer to have 3 pages.
(10kb requires 3 * 4080 pages to hold)
2) (2^31 / 2^10 + 1) * 4080 = 8556384240
The value written into buffer_size_kb is shifted by 10 and then passed
to ring_buffer_resize(). 8556384240 * 2^10 = 8761737461760
3) The size passed to ring_buffer_resize() is then divided by BUF_PAGE_SIZE
which is 4080. 8761737461760 / 4080 = 2147484672
4) nr_pages is subtracted from the current nr_pages (3) and we get:
2147484669. This value is saved in a signed integer nr_pages_to_update
5) 2147484669 is greater than 2^31 but smaller than 2^32, a signed int
turns into the value of -2147482627
6) As the value is a negative number, in update_pages_handler() it is
negated and passed to rb_remove_pages() and 2147482627 pages will
be removed, which is much larger than 3 and it causes the warning
because not all the pages asked to be removed were removed.
Link: https://bugzilla.kernel.org/show_bug.cgi?id=118001
Fixes: 7a8e76a3829f1 ("tracing: unified trace buffer")
Reported-by: Hao Qin <QEver.cn@gmail.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
kernel/trace/ring_buffer.c | 26 ++++++++++++++------------
1 file changed, 14 insertions(+), 12 deletions(-)
diff --git a/kernel/trace/ring_buffer.c b/kernel/trace/ring_buffer.c
index cb73c4e..6f70235 100644
--- a/kernel/trace/ring_buffer.c
+++ b/kernel/trace/ring_buffer.c
@@ -463,7 +463,7 @@ struct ring_buffer_per_cpu {
raw_spinlock_t reader_lock; /* serialize readers */
arch_spinlock_t lock;
struct lock_class_key lock_key;
- unsigned int nr_pages;
+ unsigned long nr_pages;
struct list_head *pages;
struct buffer_page *head_page; /* read from head */
struct buffer_page *tail_page; /* write to tail */
@@ -483,7 +483,7 @@ struct ring_buffer_per_cpu {
u64 write_stamp;
u64 read_stamp;
/* ring buffer pages to update, > 0 to add, < 0 to remove */
- int nr_pages_to_update;
+ long nr_pages_to_update;
struct list_head new_pages; /* new pages to add */
struct work_struct update_pages_work;
struct completion update_done;
@@ -1120,10 +1120,10 @@ static int rb_check_pages(struct ring_buffer_per_cpu *cpu_buffer)
return 0;
}
-static int __rb_allocate_pages(int nr_pages, struct list_head *pages, int cpu)
+static int __rb_allocate_pages(long nr_pages, struct list_head *pages, int cpu)
{
- int i;
struct buffer_page *bpage, *tmp;
+ long i;
for (i = 0; i < nr_pages; i++) {
struct page *page;
@@ -1160,7 +1160,7 @@ free_pages:
}
static int rb_allocate_pages(struct ring_buffer_per_cpu *cpu_buffer,
- unsigned nr_pages)
+ unsigned long nr_pages)
{
LIST_HEAD(pages);
@@ -1185,7 +1185,7 @@ static int rb_allocate_pages(struct ring_buffer_per_cpu *cpu_buffer,
}
static struct ring_buffer_per_cpu *
-rb_allocate_cpu_buffer(struct ring_buffer *buffer, int nr_pages, int cpu)
+rb_allocate_cpu_buffer(struct ring_buffer *buffer, long nr_pages, int cpu)
{
struct ring_buffer_per_cpu *cpu_buffer;
struct buffer_page *bpage;
@@ -1284,8 +1284,9 @@ struct ring_buffer *__ring_buffer_alloc(unsigned long size, unsigned flags,
struct lock_class_key *key)
{
struct ring_buffer *buffer;
+ long nr_pages;
int bsize;
- int cpu, nr_pages;
+ int cpu;
/* keep it in its own cache line */
buffer = kzalloc(ALIGN(sizeof(*buffer), cache_line_size()),
@@ -1408,12 +1409,12 @@ static inline unsigned long rb_page_write(struct buffer_page *bpage)
}
static int
-rb_remove_pages(struct ring_buffer_per_cpu *cpu_buffer, unsigned int nr_pages)
+rb_remove_pages(struct ring_buffer_per_cpu *cpu_buffer, unsigned long nr_pages)
{
struct list_head *tail_page, *to_remove, *next_page;
struct buffer_page *to_remove_page, *tmp_iter_page;
struct buffer_page *last_page, *first_page;
- unsigned int nr_removed;
+ unsigned long nr_removed;
unsigned long head_bit;
int page_entries;
@@ -1629,7 +1630,7 @@ int ring_buffer_resize(struct ring_buffer *buffer, unsigned long size,
int cpu_id)
{
struct ring_buffer_per_cpu *cpu_buffer;
- unsigned nr_pages;
+ unsigned long nr_pages;
int cpu, err = 0;
/*
@@ -4607,8 +4608,9 @@ static int rb_cpu_notify(struct notifier_block *self,
struct ring_buffer *buffer =
container_of(self, struct ring_buffer, cpu_notify);
long cpu = (long)hcpu;
- int cpu_i, nr_pages_same;
- unsigned int nr_pages;
+ long nr_pages_same;
+ int cpu_i;
+ unsigned long nr_pages;
switch (action) {
case CPU_UP_PREPARE:
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 086/143] nl80211: check netlink protocol in socket release notification |
| Message-ID | <rGDtG-5uK-81@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Dmitry Ivanov <dmitrijs.ivanovs@ubnt.com>
commit 8f815cdde3e550e10c2736990d791f60c2ce43eb upstream.
A non-privileged user can create a netlink socket with the same port_id as
used by an existing open nl80211 netlink socket (e.g. as used by a hostapd
process) with a different protocol number.
Closing this socket will then lead to the notification going to nl80211's
socket release notification handler, and possibly cause an action such as
removing a virtual interface.
Fix this issue by checking that the netlink protocol is NETLINK_GENERIC.
Since generic netlink has no notifier chain of its own, we can't fix the
problem more generically.
Fixes: 026331c4d9b5 ("cfg80211/mac80211: allow registering for and sending action frames")
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Ivanov <dima@ubnt.com>
[rewrite commit message]
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
net/wireless/nl80211.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index 90a0e55..dd3dbed 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -10685,7 +10685,7 @@ static int nl80211_netlink_notify(struct notifier_block * nb,
struct wireless_dev *wdev;
struct cfg80211_beacon_registration *reg, *tmp;
- if (state != NETLINK_URELEASE)
+ if (state != NETLINK_URELEASE || notify->protocol != NETLINK_GENERIC)
return NOTIFY_DONE;
rcu_read_lock();
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-06-05 12:30 +0200 |
| Subject | [PATCH 3.10 006/143] KVM: i8254: change PIT discard tick policy |
| Message-ID | <rGDtG-5uK-85@gated-at.bofh.it> |
| In reply to | #1413978 |
From: Radim KrÄmář <rkrcmar@redhat.com>
commit 7dd0fdff145c5be7146d0ac06732ae3613412ac1 upstream.
Discard policy uses ack_notifiers to prevent injection of PIT interrupts
before EOI from the last one.
This patch changes the policy to always try to deliver the interrupt,
which makes a difference when its vector is in ISR.
Old implementation would drop the interrupt, but proposed one injects to
IRR, like real hardware would.
The old policy breaks legacy NMI watchdogs, where PIT is used through
virtual wire (LVT0): PIT never sends an interrupt before receiving EOI,
thus a guest deadlock with disabled interrupts will stop NMIs.
Note that NMI doesn't do EOI, so PIT also had to send a normal interrupt
through IOAPIC. (KVM's PIT is deeply rotten and luckily not used much
in modern systems.)
Even though there is a chance of regressions, I think we can fix the
LVT0 NMI bug without introducing a new tick policy.
Cc: <stable@vger.kernel.org>
Reported-by: Yuki Shibuya <shibuya.yk@ncos.nec.co.jp>
Reviewed-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Radim KrÄmář <rkrcmar@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
arch/x86/kvm/i8254.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
index 1406ffd..b0a706d 100644
--- a/arch/x86/kvm/i8254.c
+++ b/arch/x86/kvm/i8254.c
@@ -244,7 +244,7 @@ static void kvm_pit_ack_irq(struct kvm_irq_ack_notifier *kian)
* PIC is being reset. Handle it gracefully here
*/
atomic_inc(&ps->pending);
- else if (value > 0)
+ else if (value > 0 && ps->reinject)
/* in this case, we had multiple outstanding pit interrupts
* that we needed to inject. Reinject
*/
@@ -287,7 +287,9 @@ static void pit_do_work(struct kthread_work *work)
* last one has been acked.
*/
spin_lock(&ps->inject_lock);
- if (ps->irq_ack) {
+ if (!ps->reinject)
+ inject = 1;
+ else if (ps->irq_ack) {
ps->irq_ack = 0;
inject = 1;
}
@@ -316,10 +318,10 @@ static enum hrtimer_restart pit_timer_fn(struct hrtimer *data)
struct kvm_kpit_state *ps = container_of(data, struct kvm_kpit_state, timer);
struct kvm_pit *pt = ps->kvm->arch.vpit;
- if (ps->reinject || !atomic_read(&ps->pending)) {
+ if (ps->reinject)
atomic_inc(&ps->pending);
- queue_kthread_work(&pt->worker, &pt->expired);
- }
+
+ queue_kthread_work(&pt->worker, &pt->expired);
if (ps->is_periodic) {
hrtimer_add_expires_ns(&ps->timer, ps->period);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
Page 1 of 7 [1] 2 3 4 5 6 7 Next page →
Back to top | Article view | linux.kernel
csiph-web