Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1418691 > unrolled thread

[4.2.y-ckt stable] Linux 4.2.8-ckt12 stable review

Started byKamal Mostafa <kamal@canonical.com>
First post2016-06-09 23:20 +0200
Last post2016-06-10 10:50 +0200
Articles 20 on this page of 190 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [4.2.y-ckt stable] Linux 4.2.8-ckt12 stable review Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:20 +0200
    [PATCH 4.2.y-ckt 018/206] [media] media: v4l2-compat-ioctl32: fix missing reserved field copy in put_v4l2_create32 Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:20 +0200
    [PATCH 4.2.y-ckt 007/206] ath5k: Change led pin configuration for compaq c700 laptop Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:20 +0200
    [PATCH 4.2.y-ckt 012/206] drm/gma500: Fix possible out of bounds read Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:20 +0200
    [PATCH 4.2.y-ckt 205/206] drivers/hwspinlock: use correct radix tree API Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 196/206] netlink: Fix dump skb leak/double free Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 185/206] MIPS: BMIPS: Clear MIPS_CACHE_ALIASES earlier Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 199/206] tipc: fix nametable publication field in nl compat Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 195/206] x86/PCI: Mark Broadwell-EP Home Agent 1 as having non-compliant BARs Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 181/206] s390/vmem: fix identity mapping Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 147/206] affs: fix remount failure when there are no options changed Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 176/206] ACPI / sysfs: fix error code in get_status() Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 190/206] MIPS: BMIPS: Adjust mips-hpt-frequency for BCM7435 Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 193/206] i40e: fix an uninitialized variable bug Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 192/206] IB/IWPM: Fix a potential skb leak Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 204/206] uapi glibc compat: fix compilation when !__USE_MISC in glibc Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 173/206] metag: Fix atomic_*_return inline asm constraints Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 186/206] MIPS: BMIPS: local_r4k___flush_cache_all needs to blast S-cache Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 202/206] net: ehea: avoid null pointer dereference Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 183/206] powerpc/sstep: Fix sstep.c compile on powerpcspe Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 201/206] batman-adv: fix skb deref after free Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 180/206] ata: sata_dwc_460ex: remove incorrect locking Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 178/206] MIPS: BMIPS: Fix PRID_IMP_BMIPS5000 masking for BMIPS5200 Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 188/206] MIPS: math-emu: Fix BC1{EQ,NE}Z emulation Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 194/206] blk-mq: fix undefined behaviour in order_to_size() Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 177/206] clk: qcom: msm8916: Fix crypto clock flags Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 189/206] MIPS: Fix BC1{EQ,NE}Z return offset calculation Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 206/206] RDMA/cxgb3: device driver frees DMA memory with different size Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 169/206] cxl: Fix DAR check & use REGION_ID instead of opencoding Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 191/206] IB/srp: Print "ib_srp: " prefix once Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 184/206] MIPS: BMIPS: BMIPS5000 has I cache filing from D cache Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 187/206] MIPS: BMIPS: Pretty print BMIPS5200 processor name Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 200/206] sunrpc: Update RPCBIND_MAXNETIDLEN Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 198/206] sched/preempt: Fix preempt_count manipulations Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 179/206] NFS: Fix an LOCK/OPEN race when unlinking an open file Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 203/206] tuntap: correctly wake up process during uninit Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 151/206] serial: doc: Un-document non-existing uart_write_console() Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 197/206] MIPS: ath79: fix regression in PCI window initialization Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 182/206] perf tools: Fix perf regs mask generation Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:30 +0200
    [PATCH 4.2.y-ckt 146/206] hpfs: fix remount failure when there are no options changed Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 170/206] taskstats: fix nl parsing in accounting/getdelays.c Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 148/206] hpfs: implement the show_options method Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 136/206] wait/ptrace: assume __WALL if the child is traced Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 150/206] ARM: dts: kirkwood: add kirkwood-ds112.dtb to Makefile Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 174/206] tty: vt, return error when con_startup fails Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 144/206] Input: pwm-beeper - fix - scheduling while atomic Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 165/206] EDAC: Increment correct counter in edac_inc_ue_error() Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 149/206] regmap: cache: Fix typo in cache_bypass parameter description Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 143/206] Input: xpad - prevent spurious input from wired Xbox 360 controllers Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 161/206] cx23885: uninitialized variable in cx23885_av_work_handler() Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 168/206] ARM: debug: remove extraneous DEBUG_HI3716_UART option Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 145/206] MIPS: lib: Mark intrinsics notrace Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 154/206] iommu/vt-d: Improve fault handler error messages Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 160/206] am437x-vpfe: fix an uninitialized variable bug Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 164/206] perf test: Ignore kcore files in the "vmlinux matches kallsyms" test Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 156/206] ARM: OMAP2+: hwmod: fix _idle() hwmod state sanity check sequence Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 162/206] ipv6, token: allow for clearing the current device token Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 166/206] PCI: Supply CPU physical address (not bus address) to iomem_is_exclusive() Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 171/206] char: Drop bogus dependency of DEVPORT on !M68K Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 157/206] security: drop the unused hook skb_owned_by Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 163/206] usb: gadget: f_fs: Fix EFAULT generation for async read operations Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 172/206] driver-core: use 'dev' argument in dev_dbg_ratelimited stub Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 159/206] am437x-vfpe: fix typo in vpfe_get_app_input_index Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 153/206] iommu/vt-d: Ratelimit fault handler Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 155/206] power: ipaq-micro-battery: freeing the wrong variable Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 167/206] alpha/PCI: Call iomem_is_exclusive() for IORESOURCE_MEM, but not IORESOURCE_IO Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 175/206] cpufreq: Fix GOV_LIMITS handling for the userspace governor Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 158/206] mfd: lp8788-irq: Uninitialized variable in irq handler Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 152/206] iio: buffer: add missing descriptions in iio_buffer_access_funcs Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 142/206] dell-rbtn: Ignore ACPI notifications if device is suspended Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:40 +0200
    [PATCH 4.2.y-ckt 127/206] Input: uinput - handle compat ioctl for UI_SET_PHYS Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 113/206] fs/cifs: correctly to anonymous authentication via NTLMSSP Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 124/206] cifs: Create dedicated keyring for spnego operations Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 114/206] fs/cifs: correctly to anonymous authentication for the LANMAN authentication Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 112/206] drm/fb_helper: Fix references to dev->mode_config.num_connector Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 094/206] powerpc/eeh: Don't report error in eeh_pe_reset_and_recover() Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 123/206] ASoC: ak4642: Enable cache usage to fix crashes on resume Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 117/206] remove directory incorrectly tries to set delete on close on non-empty directories Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 104/206] MIPS: Disable preemption during prctl(PR_SET_FP_MODE, ...) Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 116/206] fs/cifs: correctly to anonymous authentication for the NTLM(v2) authentication Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 133/206] mmc: sdhci-pci: Remove MMC_CAP_BUS_WIDTH_TEST for Intel controllers Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 134/206] mmc: sdhci-acpi: Remove MMC_CAP_BUS_WIDTH_TEST for Intel controllers Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 131/206] drm/i915: Don't leave old junk in ilk active watermarks on readout Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 121/206] xfs: skip stale inodes in xfs_iflush_cluster Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 109/206] PCI: Disable all BAR sizing for devices with non-compliant BARs Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 122/206] KVM: MTRR: remove MSR 0x2f8 Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 140/206] drm/amdgpu: Fix hdmi deep color support. Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 132/206] mmc: longer timeout for long read time quirk Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 118/206] cpuidle: Fix cpuidle_state_is_coupled() argument in cpuidle_enter() Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 106/206] ring-buffer: Use long for nr_pages to avoid overflow failures Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 128/206] PM / sleep: Handle failures in device_suspend_late() consistently Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 137/206] xen/x86: actually allocate legacy interrupts on PV guests Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 105/206] MIPS: Force CPUs to lose FP context during mode switches Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 119/206] xfs: xfs_iflush_cluster fails to abort on error Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 110/206] MIPS: MSA: Fix a link error on `_init_msa_upper' with older GCC Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 107/206] ring-buffer: Prevent overflow of size in ring_buffer_resize() Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 126/206] kvm: arm64: Fix EC field in inject_abt64 Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 120/206] xfs: fix inode validity check in xfs_iflush_cluster Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 125/206] ALSA: hda - Fix headphone noise on Dell XPS 13 9360 Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 135/206] sunrpc: fix stripping of padded MIC tokens Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 139/206] UBI: Fix static volume checks when Fastmap is used Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 129/206] mm: use phys_addr_t for reserve_bootmem_region() arguments Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 115/206] fs/cifs: correctly to anonymous authentication for the NTLM(v1) authentication Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 098/206] MIPS: Sync icache & dcache in set_pte_at Kamal Mostafa <kamal@canonical.com> - 2016-06-09 23:50 +0200
    [PATCH 4.2.y-ckt 073/206] MIPS: Reserve nosave data for hibernation Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 065/206] ext4: silence UBSAN in ext4_mb_init() Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 095/206] powerpc/eeh: Restore initial state in eeh_pe_reset_and_recover() Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 102/206] MIPS: ptrace: Fix FP context restoration FCSR regression Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 081/206] USB: serial: mxuport: fix use-after-free in probe error path Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 085/206] MIPS: KVM: Fix timer IRQ race when writing CP0_Compare Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 079/206] USB: serial: io_edgeport: fix memory leaks in probe error path Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 084/206] MIPS: KVM: Fix timer IRQ race when freezing timer Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 088/206] irqchip/gic-v3: Configure all interrupts as non-secure Group-1 Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 072/206] MIPS: Avoid using unwind_stack() with usermode Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 093/206] sched/loadavg: Fix loadavg artifacts on fully idle and on fully loaded systems Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 089/206] arm64: cpuinfo: Missing NULL terminator in compat_hwcap_str Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 092/206] rtlwifi: pci: use dev_kfree_skb_irq instead of kfree_skb in rtl_pci_reset_trx_ring Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 071/206] MIPS: Don't unwind to user mode with EVA Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 096/206] Revert "powerpc/eeh: Fix crash in eeh_add_device_early() on Cell" Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 078/206] USB: serial: io_edgeport: fix memory leaks in attach error path Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 100/206] MIPS: Fix uapi include in exported asm/siginfo.h Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 082/206] USB: serial: quatech2: fix use-after-free in probe error path Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 063/206] ext4: fix oops on corrupted filesystem Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 076/206] usb: host: xhci-rcar: Avoid long wait in xhci_reset() Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 097/206] MIPS: Handle highmem pages in __update_cache Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 101/206] MIPS: math-emu: Fix jalr emulation when rd == $0 Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 077/206] mfd: omap-usb-tll: Fix scheduling while atomic BUG Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 103/206] MIPS: ptrace: Prevent writes to read-only FCSR bits Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 091/206] rtlwifi: Fix logic error in enter/exit power-save mode Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 080/206] USB: serial: keyspan: fix use-after-free in probe error path Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 090/206] kbuild: move -Wunused-const-variable to W=1 warning level Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 083/206] crypto: caam - fix caam_jr_alloc() ret code Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 087/206] irqchip/gic: Ensure ordering between read of INTACK and shared data Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:00 +0200
    [PATCH 4.2.y-ckt 044/206] Drivers: hv_vmbus: Fix signal to host condition Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 066/206] arm64: Ensure pmd_present() returns false after pmd_mknotpresent() Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 040/206] aacraid: Fix for aac_command_thread hang Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 058/206] USB: serial: option: add more ZTE device ids Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 069/206] can: fix handling of unmodifiable configuration options Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 043/206] MIPS: ath79: make bootconsole wait for both THRE and TEMT Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 070/206] MIPS: Fix siginfo.h to use strict posix types Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 057/206] mcb: Fixed bar number assignment for the gdd Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 052/206] thunderbolt: Fix double free of drom buffer Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 064/206] ext4: address UBSAN warning in mb_find_order_for_block() Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 042/206] ext4: fix hang when processing corrupted orphaned inode list Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 047/206] mei: fix NULL dereferencing during FW initiated disconnection Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 050/206] Fix OpenSSH pty regression on close Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 053/206] USB: serial: option: add support for Cinterion PH8 and AHxx Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 049/206] tty: Abstract tty buffer work Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 068/206] ath10k: fix kernel panic, move arvifs list head init before htt init Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 067/206] ARM: dts: exynos: Add interrupt line to MAX8997 PMIC on exynos4210-trats Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 045/206] Drivers: hv: ring_buffer.c: fix comment style Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 051/206] QE-UART: add "fsl,t1040-ucc-uart" to of_device_id Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 033/206] usb: core: hub: hub_port_init lock controller instead of bus Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 055/206] usb: misc: usbtest: format the data pattern according to max packet size Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 048/206] mei: amthif: discard not read messages Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 059/206] USB: serial: option: add even more ZTE device ids Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 054/206] USB: leave LPM alone if possible when binding/unbinding interface drivers Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 041/206] aacraid: Fix for KDUMP driver hang Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 062/206] USB: serial: cp210x: fix hardware flow-control disable Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:10 +0200
    [PATCH 4.2.y-ckt 028/206] crypto: s5p-sss - Fix missed interrupts when working with 8 kB blocks Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 031/206] pinctrl: exynos5440: Use off-stack memory for pinctrl_gpio_range Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 039/206] aacraid: Relinquish CPU during timeout wait Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 017/206] mfd: intel_quark_i2c_gpio: Remove clock tree on error path Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 037/206] arm/arm64: KVM: Enforce Break-Before-Make on Stage-2 page tables Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 032/206] btrfs: bugfix: handle FS_IOC32_{GETFLAGS,SETFLAGS,GETVERSION} in btrfs_ioctl Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 016/206] mfd: intel_quark_i2c_gpio: Use clkdev_create() Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 026/206] powerpc/book3s64: Fix branching to OOL handlers in relocatable kernel Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 023/206] hwmon: (ads7828) Enable internal reference Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 003/206] ath10k: fix debugfs pktlog_filter write Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 034/206] serial: 8250_pci: fix divide error bug if baud rate is 0 Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 024/206] ath10k: fix rx_channel during hw reconfigure Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 030/206] ath9k: Fix LED polarity for some Mini PCI AR9220 MB92 cards. Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 020/206] Revert "scsi: fix soft lockup in scsi_remove_target() on module removal" Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 036/206] staging: comedi: das1800: fix possible NULL dereference Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 001/206] ath10k: fix firmware assert in monitor mode Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 022/206] usb: f_mass_storage: test whether thread is running before starting another Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 015/206] cpuidle: Indicate when a device has been unregistered Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 014/206] Bluetooth: vhci: purge unhandled skbs Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 013/206] Bluetooth: vhci: fix open_timeout vs. hdev race Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 010/206] rtlwifi: rtl8723be: Add antenna select module parameter Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 029/206] ath9k: Add a module parameter to invert LED polarity. Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 027/206] PM / Runtime: Fix error path in pm_runtime_force_resume() Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 025/206] Bluetooth: vhci: Fix race at creating hci device Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:20 +0200
    [PATCH 4.2.y-ckt 009/206] xfs: Don't wrap growfs AGFL indexes Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:30 +0200
    [PATCH 4.2.y-ckt 004/206] drm/i915: Call intel_dp_mst_resume() before resuming displays Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:30 +0200
    [PATCH 4.2.y-ckt 008/206] xfs: disallow rw remount on fs with unknown ro-compat features Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:30 +0200
    [PATCH 4.2.y-ckt 002/206] drm/i915: Fix race condition in intel_dp_destroy_mst_connector() Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:30 +0200
    [PATCH 4.2.y-ckt 011/206] rtlwifi: btcoexist: Implement antenna selection Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:30 +0200
    [PATCH 4.2.y-ckt 006/206] drm/i915: Exit cherryview_irq_handler() after one pass Kamal Mostafa <kamal@canonical.com> - 2016-06-10 00:30 +0200
      RE: [PATCH 4.2.y-ckt 006/206] drm/i915: Exit  cherryview_irq_handler() after one pass "Ursulin, Tvrtko" <tvrtko.ursulin@intel.com> - 2016-06-10 10:50 +0200

Page 6 of 10 — ← Prev page 1 … 4 5 [6] 7 8 … 10  Next page →


#1418800 — [PATCH 4.2.y-ckt 139/206] UBI: Fix static volume checks when Fastmap is used

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-09 23:50 +0200
Subject[PATCH 4.2.y-ckt 139/206] UBI: Fix static volume checks when Fastmap is used
Message-ID<rIfZV-3GB-65@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Richard Weinberger <richard@nod.at>

commit 1900149c835ab5b48bea31a823ea5e5a401fb560 upstream.

Ezequiel reported that he's facing UBI going into read-only
mode after power cut. It turned out that this behavior happens
only when updating a static volume is interrupted and Fastmap is
used.

A possible trace can look like:
ubi0 warning: ubi_io_read_vid_hdr [ubi]: no VID header found at PEB 2323, only 0xFF bytes
ubi0 warning: ubi_eba_read_leb [ubi]: switch to read-only mode
CPU: 0 PID: 833 Comm: ubiupdatevol Not tainted 4.6.0-rc2-ARCH #4
Hardware name: SAMSUNG ELECTRONICS CO., LTD. 300E4C/300E5C/300E7C/NP300E5C-AD8AR, BIOS P04RAP 10/15/2012
0000000000000286 00000000eba949bd ffff8800c45a7b38 ffffffff8140d841
ffff8801964be000 ffff88018eaa4800 ffff8800c45a7bb8 ffffffffa003abf6
ffffffff850e2ac0 8000000000000163 ffff8801850e2ac0 ffff8801850e2ac0
Call Trace:
[<ffffffff8140d841>] dump_stack+0x63/0x82
[<ffffffffa003abf6>] ubi_eba_read_leb+0x486/0x4a0 [ubi]
[<ffffffffa00453b3>] ubi_check_volume+0x83/0xf0 [ubi]
[<ffffffffa0039d97>] ubi_open_volume+0x177/0x350 [ubi]
[<ffffffffa00375d8>] vol_cdev_open+0x58/0xb0 [ubi]
[<ffffffff8124b08e>] chrdev_open+0xae/0x1d0
[<ffffffff81243bcf>] do_dentry_open+0x1ff/0x300
[<ffffffff8124afe0>] ? cdev_put+0x30/0x30
[<ffffffff81244d36>] vfs_open+0x56/0x60
[<ffffffff812545f4>] path_openat+0x4f4/0x1190
[<ffffffff81256621>] do_filp_open+0x91/0x100
[<ffffffff81263547>] ? __alloc_fd+0xc7/0x190
[<ffffffff812450df>] do_sys_open+0x13f/0x210
[<ffffffff812451ce>] SyS_open+0x1e/0x20
[<ffffffff81a99e32>] entry_SYSCALL_64_fastpath+0x1a/0xa4

UBI checks static volumes for data consistency and reads the
whole volume upon first open. If the volume is found erroneous
users of UBI cannot read from it, but another volume update is
possible to fix it. The check is performed by running
ubi_eba_read_leb() on every allocated LEB of the volume.
For static volumes ubi_eba_read_leb() computes the checksum of all
data stored in a LEB. To verify the computed checksum it has to read
the LEB's volume header which stores the original checksum.
If the volume header is not found UBI treats this as fatal internal
error and switches to RO mode. If the UBI device was attached via a
full scan the assumption is correct, the volume header has to be
present as it had to be there while scanning to get known as mapped.
If the attach operation happened via Fastmap the assumption is no
longer correct. When attaching via Fastmap UBI learns the mapping
table from Fastmap's snapshot of the system state and not via a full
scan. It can happen that a LEB got unmapped after a Fastmap was
written to the flash. Then UBI can learn the LEB still as mapped and
accessing it returns only 0xFF bytes. As UBI is not a FTL it is
allowed to have mappings to empty PEBs, it assumes that the layer
above takes care of LEB accounting and referencing.
UBIFS does so using the LEB property tree (LPT).
For static volumes UBI blindly assumes that all LEBs are present and
therefore special actions have to be taken.

The described situation can happen when updating a static volume is
interrupted, either by a user or a power cut.
The volume update code first unmaps all LEBs of a volume and then
writes LEB by LEB. If the sequence of operations is interrupted UBI
detects this either by the absence of LEBs, no volume header present
at scan time, or corrupted payload, detected via checksum.
In the Fastmap case the former method won't trigger as no scan
happened and UBI automatically thinks all LEBs are present.
Only by reading data from a LEB it detects that the volume header is
missing and incorrectly treats this as fatal error.
To deal with the situation ubi_eba_read_leb() from now on checks
whether we attached via Fastmap and handles the absence of a
volume header like a data corruption error.
This way interrupted static volume updates will correctly get detected
also when Fastmap is used.

Reported-by: Ezequiel Garcia <ezequiel@vanguardiasur.com.ar>
Tested-by: Ezequiel Garcia <ezequiel@vanguardiasur.com.ar>
Signed-off-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/mtd/ubi/eba.c     | 21 +++++++++++++++++++--
 drivers/mtd/ubi/fastmap.c |  1 +
 drivers/mtd/ubi/ubi.h     |  2 ++
 3 files changed, 22 insertions(+), 2 deletions(-)

diff --git a/drivers/mtd/ubi/eba.c b/drivers/mtd/ubi/eba.c
index 51bca03..1c73ba6 100644
--- a/drivers/mtd/ubi/eba.c
+++ b/drivers/mtd/ubi/eba.c
@@ -426,8 +426,25 @@ retry:
 						 pnum, vol_id, lnum);
 					err = -EBADMSG;
 				} else {
-					err = -EINVAL;
-					ubi_ro_mode(ubi);
+					/*
+					 * Ending up here in the non-Fastmap case
+					 * is a clear bug as the VID header had to
+					 * be present at scan time to have it referenced.
+					 * With fastmap the story is more complicated.
+					 * Fastmap has the mapping info without the need
+					 * of a full scan. So the LEB could have been
+					 * unmapped, Fastmap cannot know this and keeps
+					 * the LEB referenced.
+					 * This is valid and works as the layer above UBI
+					 * has to do bookkeeping about used/referenced
+					 * LEBs in any case.
+					 */
+					if (ubi->fast_attach) {
+						err = -EBADMSG;
+					} else {
+						err = -EINVAL;
+						ubi_ro_mode(ubi);
+					}
 				}
 			}
 			goto out_free;
diff --git a/drivers/mtd/ubi/fastmap.c b/drivers/mtd/ubi/fastmap.c
index 4aa2fd8..370a0e2 100644
--- a/drivers/mtd/ubi/fastmap.c
+++ b/drivers/mtd/ubi/fastmap.c
@@ -1058,6 +1058,7 @@ int ubi_scan_fastmap(struct ubi_device *ubi, struct ubi_attach_info *ai,
 	ubi_msg(ubi, "fastmap WL pool size: %d",
 		ubi->fm_wl_pool.max_size);
 	ubi->fm_disabled = 0;
+	ubi->fast_attach = 1;
 
 	ubi_free_vid_hdr(ubi, vh);
 	kfree(ech);
diff --git a/drivers/mtd/ubi/ubi.h b/drivers/mtd/ubi/ubi.h
index 2974b67..de1ea2e4 100644
--- a/drivers/mtd/ubi/ubi.h
+++ b/drivers/mtd/ubi/ubi.h
@@ -462,6 +462,7 @@ struct ubi_debug_info {
  * @fm_eba_sem: allows ubi_update_fastmap() to block EBA table changes
  * @fm_work: fastmap work queue
  * @fm_work_scheduled: non-zero if fastmap work was scheduled
+ * @fast_attach: non-zero if UBI was attached by fastmap
  *
  * @used: RB-tree of used physical eraseblocks
  * @erroneous: RB-tree of erroneous used physical eraseblocks
@@ -570,6 +571,7 @@ struct ubi_device {
 	size_t fm_size;
 	struct work_struct fm_work;
 	int fm_work_scheduled;
+	int fast_attach;
 
 	/* Wear-leveling sub-system's stuff */
 	struct rb_root used;
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418801 — [PATCH 4.2.y-ckt 129/206] mm: use phys_addr_t for reserve_bootmem_region() arguments

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-09 23:50 +0200
Subject[PATCH 4.2.y-ckt 129/206] mm: use phys_addr_t for reserve_bootmem_region() arguments
Message-ID<rIfZV-3GB-69@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Stefan Bader <stefan.bader@canonical.com>

commit 4b50bcc7eda4d3cc9e3f2a0aa60e590fedf728c5 upstream.

Since commit 92923ca3aace ("mm: meminit: only set page reserved in the
memblock region") the reserved bit is set on reserved memblock regions.
However start and end address are passed as unsigned long.  This is only
32bit on i386, so it can end up marking the wrong pages reserved for
ranges at 4GB and above.

This was observed on a 32bit Xen dom0 which was booted with initial
memory set to a value below 4G but allowing to balloon in memory
(dom0_mem=1024M for example).  This would define a reserved bootmem
region for the additional memory (for example on a 8GB system there was
a reverved region covering the 4GB-8GB range).  But since the addresses
were passed on as unsigned long, this was actually marking all pages
from 0 to 4GB as reserved.

Fixes: 92923ca3aacef63 ("mm: meminit: only set page reserved in the memblock region")
Link: http://lkml.kernel.org/r/1463491221-10573-1-git-send-email-stefan.bader@canonical.com
Signed-off-by: Stefan Bader <stefan.bader@canonical.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 include/linux/mm.h | 2 +-
 mm/page_alloc.c    | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/include/linux/mm.h b/include/linux/mm.h
index 2b05068..63bb576 100644
--- a/include/linux/mm.h
+++ b/include/linux/mm.h
@@ -1684,7 +1684,7 @@ extern void free_highmem_page(struct page *page);
 extern void adjust_managed_page_count(struct page *page, long count);
 extern void mem_init_print_info(const char *str);
 
-extern void reserve_bootmem_region(unsigned long start, unsigned long end);
+extern void reserve_bootmem_region(phys_addr_t start, phys_addr_t end);
 
 /* Free the reserved page into the buddy system, so it gets managed. */
 static inline void __free_reserved_page(struct page *page)
diff --git a/mm/page_alloc.c b/mm/page_alloc.c
index 6d95dea..51fd491 100644
--- a/mm/page_alloc.c
+++ b/mm/page_alloc.c
@@ -908,7 +908,7 @@ static inline void init_reserved_page(unsigned long pfn)
  * marks the pages PageReserved. The remaining valid pages are later
  * sent to the buddy page allocator.
  */
-void __meminit reserve_bootmem_region(unsigned long start, unsigned long end)
+void __meminit reserve_bootmem_region(phys_addr_t start, phys_addr_t end)
 {
 	unsigned long start_pfn = PFN_DOWN(start);
 	unsigned long end_pfn = PFN_UP(end);
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418802 — [PATCH 4.2.y-ckt 115/206] fs/cifs: correctly to anonymous authentication for the NTLM(v1) authentication

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-09 23:50 +0200
Subject[PATCH 4.2.y-ckt 115/206] fs/cifs: correctly to anonymous authentication for the NTLM(v1) authentication
Message-ID<rIfZV-3GB-75@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Stefan Metzmacher <metze@samba.org>

commit 777f69b8d26bf35ade4a76b08f203c11e048365d upstream.

Only server which map unknown users to guest will allow
access using a non-null NTChallengeResponse.

For Samba it's the "map to guest = bad user" option.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=11913

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Signed-off-by: Steve French <smfrench@gmail.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/cifs/sess.c | 41 +++++++++++++++++++++++------------------
 1 file changed, 23 insertions(+), 18 deletions(-)

diff --git a/fs/cifs/sess.c b/fs/cifs/sess.c
index 91dbaca..a58b100 100644
--- a/fs/cifs/sess.c
+++ b/fs/cifs/sess.c
@@ -781,26 +781,31 @@ sess_auth_ntlm(struct sess_data *sess_data)
 	capabilities = cifs_ssetup_hdr(ses, pSMB);
 
 	pSMB->req_no_secext.Capabilities = cpu_to_le32(capabilities);
-	pSMB->req_no_secext.CaseInsensitivePasswordLength =
-			cpu_to_le16(CIFS_AUTH_RESP_SIZE);
-	pSMB->req_no_secext.CaseSensitivePasswordLength =
-			cpu_to_le16(CIFS_AUTH_RESP_SIZE);
+	if (ses->user_name != NULL) {
+		pSMB->req_no_secext.CaseInsensitivePasswordLength =
+				cpu_to_le16(CIFS_AUTH_RESP_SIZE);
+		pSMB->req_no_secext.CaseSensitivePasswordLength =
+				cpu_to_le16(CIFS_AUTH_RESP_SIZE);
 
-	/* calculate ntlm response and session key */
-	rc = setup_ntlm_response(ses, sess_data->nls_cp);
-	if (rc) {
-		cifs_dbg(VFS, "Error %d during NTLM authentication\n",
-				 rc);
-		goto out;
-	}
+		/* calculate ntlm response and session key */
+		rc = setup_ntlm_response(ses, sess_data->nls_cp);
+		if (rc) {
+			cifs_dbg(VFS, "Error %d during NTLM authentication\n",
+					 rc);
+			goto out;
+		}
 
-	/* copy ntlm response */
-	memcpy(bcc_ptr, ses->auth_key.response + CIFS_SESS_KEY_SIZE,
-			CIFS_AUTH_RESP_SIZE);
-	bcc_ptr += CIFS_AUTH_RESP_SIZE;
-	memcpy(bcc_ptr, ses->auth_key.response + CIFS_SESS_KEY_SIZE,
-			CIFS_AUTH_RESP_SIZE);
-	bcc_ptr += CIFS_AUTH_RESP_SIZE;
+		/* copy ntlm response */
+		memcpy(bcc_ptr, ses->auth_key.response + CIFS_SESS_KEY_SIZE,
+				CIFS_AUTH_RESP_SIZE);
+		bcc_ptr += CIFS_AUTH_RESP_SIZE;
+		memcpy(bcc_ptr, ses->auth_key.response + CIFS_SESS_KEY_SIZE,
+				CIFS_AUTH_RESP_SIZE);
+		bcc_ptr += CIFS_AUTH_RESP_SIZE;
+	} else {
+		pSMB->req_no_secext.CaseInsensitivePasswordLength = 0;
+		pSMB->req_no_secext.CaseSensitivePasswordLength = 0;
+	}
 
 	if (ses->capabilities & CAP_UNICODE) {
 		/* unicode strings must be word aligned */
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418804 — [PATCH 4.2.y-ckt 098/206] MIPS: Sync icache & dcache in set_pte_at

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-09 23:50 +0200
Subject[PATCH 4.2.y-ckt 098/206] MIPS: Sync icache & dcache in set_pte_at
Message-ID<rIfZV-3GB-77@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Paul Burton <paul.burton@imgtec.com>

commit 37d22a0d798b5c938b277d32cfd86dc231381342 upstream.

It's possible for pages to become visible prior to update_mmu_cache
running if a thread within the same address space preempts the current
thread or runs simultaneously on another CPU. That is, the following
scenario is possible:

    CPU0                            CPU1

    write to page
    flush_dcache_page
    flush_icache_page
    set_pte_at
                                    map page
    update_mmu_cache

If CPU1 maps the page in between CPU0's set_pte_at, which marks it valid
& visible, and update_mmu_cache where the dcache flush occurs then CPU1s
icache will fill from stale data (unless it fills from the dcache, in
which case all is good, but most MIPS CPUs don't have this property).
Commit 4d46a67a3eb8 ("MIPS: Fix race condition in lazy cache flushing.")
attempted to fix that by performing the dcache flush in
flush_icache_page such that it occurs before the set_pte_at call makes
the page visible. However it has the problem that not all code that
writes to pages exposed to userland call flush_icache_page. There are
many callers of set_pte_at under mm/ and only 2 of them do call
flush_icache_page. Thus the race window between a page becoming visible
& being coherent between the icache & dcache remains open in some cases.

To illustrate some of the cases, a WARN was added to __update_cache with
this patch applied that triggered in cases where a page about to be
flushed from the dcache was not the last page provided to
flush_icache_page. That is, backtraces were obtained for cases in which
the race window is left open without this patch. The 2 standout examples
follow.

When forking a process:

[   15.271842] [<80417630>] __update_cache+0xcc/0x188
[   15.277274] [<80530394>] copy_page_range+0x56c/0x6ac
[   15.282861] [<8042936c>] copy_process.part.54+0xd40/0x17ac
[   15.289028] [<80429f80>] do_fork+0xe4/0x420
[   15.293747] [<80413808>] handle_sys+0x128/0x14c

When exec'ing an ELF binary:

[   14.445964] [<80417630>] __update_cache+0xcc/0x188
[   14.451369] [<80538d88>] move_page_tables+0x414/0x498
[   14.457075] [<8055d848>] setup_arg_pages+0x220/0x318
[   14.462685] [<805b0f38>] load_elf_binary+0x530/0x12a0
[   14.468374] [<8055ec3c>] search_binary_handler+0xbc/0x214
[   14.474444] [<8055f6c0>] do_execveat_common+0x43c/0x67c
[   14.480324] [<8055f938>] do_execve+0x38/0x44
[   14.485137] [<80413808>] handle_sys+0x128/0x14c

These code paths write into a page, call flush_dcache_page then call
set_pte_at without flush_icache_page inbetween. The end result is that
the icache can become corrupted & userland processes may execute
unexpected or invalid code, typically resulting in a reserved
instruction exception, a trap or a segfault.

Fix this race condition fully by performing any cache maintenance
required to keep the icache & dcache in sync in set_pte_at, before the
page is made valid. This has the added bonus of ensuring the cache
maintenance always happens in one location, rather than being duplicated
in flush_icache_page & update_mmu_cache. It also matches the way other
architectures solve the same problem (see arm, ia64 & powerpc).

Signed-off-by: Paul Burton <paul.burton@imgtec.com>
Reported-by: Ionela Voinescu <ionela.voinescu@imgtec.com>
Cc: Lars Persson <lars.persson@axis.com>
Fixes: 4d46a67a3eb8 ("MIPS: Fix race condition in lazy cache flushing.")
Cc: Steven J. Hill <sjhill@realitydiluted.com>
Cc: David Daney <david.daney@cavium.com>
Cc: Huacai Chen <chenhc@lemote.com>
Cc: Aneesh Kumar K.V <aneesh.kumar@linux.vnet.ibm.com>
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Jerome Marchand <jmarchan@redhat.com>
Cc: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Cc: linux-mips@linux-mips.org
Cc: linux-kernel@vger.kernel.org
Patchwork: https://patchwork.linux-mips.org/patch/12722/
Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/mips/include/asm/cacheflush.h |  6 ------
 arch/mips/include/asm/pgtable.h    | 26 +++++++++++++++++++++-----
 arch/mips/mm/cache.c               | 19 +++----------------
 3 files changed, 24 insertions(+), 27 deletions(-)

diff --git a/arch/mips/include/asm/cacheflush.h b/arch/mips/include/asm/cacheflush.h
index 723229f..176de58 100644
--- a/arch/mips/include/asm/cacheflush.h
+++ b/arch/mips/include/asm/cacheflush.h
@@ -51,7 +51,6 @@ extern void (*flush_cache_range)(struct vm_area_struct *vma,
 	unsigned long start, unsigned long end);
 extern void (*flush_cache_page)(struct vm_area_struct *vma, unsigned long page, unsigned long pfn);
 extern void __flush_dcache_page(struct page *page);
-extern void __flush_icache_page(struct vm_area_struct *vma, struct page *page);
 
 #define ARCH_IMPLEMENTS_FLUSH_DCACHE_PAGE 1
 static inline void flush_dcache_page(struct page *page)
@@ -77,11 +76,6 @@ static inline void flush_anon_page(struct vm_area_struct *vma,
 static inline void flush_icache_page(struct vm_area_struct *vma,
 	struct page *page)
 {
-	if (!cpu_has_ic_fills_f_dc && (vma->vm_flags & VM_EXEC) &&
-	    Page_dcache_dirty(page)) {
-		__flush_icache_page(vma, page);
-		ClearPageDcacheDirty(page);
-	}
 }
 
 extern void (*flush_icache_range)(unsigned long start, unsigned long end);
diff --git a/arch/mips/include/asm/pgtable.h b/arch/mips/include/asm/pgtable.h
index 6bc427f..29a9de2 100644
--- a/arch/mips/include/asm/pgtable.h
+++ b/arch/mips/include/asm/pgtable.h
@@ -127,10 +127,14 @@ do {									\
 	}								\
 } while(0)
 
+static inline void set_pte_at(struct mm_struct *mm, unsigned long addr,
+			      pte_t *ptep, pte_t pteval);
+
 #if defined(CONFIG_PHYS_ADDR_T_64BIT) && defined(CONFIG_CPU_MIPS32)
 
 #define pte_none(pte)		(!(((pte).pte_high) & ~_PAGE_GLOBAL))
 #define pte_present(pte)	((pte).pte_low & _PAGE_PRESENT)
+#define pte_no_exec(pte)	((pte).pte_low & _PAGE_NO_EXEC)
 
 static inline void set_pte(pte_t *ptep, pte_t pte)
 {
@@ -148,7 +152,6 @@ static inline void set_pte(pte_t *ptep, pte_t pte)
 			buddy->pte_high |= _PAGE_GLOBAL;
 	}
 }
-#define set_pte_at(mm, addr, ptep, pteval) set_pte(ptep, pteval)
 
 static inline void pte_clear(struct mm_struct *mm, unsigned long addr, pte_t *ptep)
 {
@@ -166,6 +169,7 @@ static inline void pte_clear(struct mm_struct *mm, unsigned long addr, pte_t *pt
 
 #define pte_none(pte)		(!(pte_val(pte) & ~_PAGE_GLOBAL))
 #define pte_present(pte)	(pte_val(pte) & _PAGE_PRESENT)
+#define pte_no_exec(pte)	(pte_val(pte) & _PAGE_NO_EXEC)
 
 /*
  * Certain architectures need to do special things when pte's
@@ -218,7 +222,6 @@ static inline void set_pte(pte_t *ptep, pte_t pteval)
 	}
 #endif
 }
-#define set_pte_at(mm, addr, ptep, pteval) set_pte(ptep, pteval)
 
 static inline void pte_clear(struct mm_struct *mm, unsigned long addr, pte_t *ptep)
 {
@@ -234,6 +237,22 @@ static inline void pte_clear(struct mm_struct *mm, unsigned long addr, pte_t *pt
 }
 #endif
 
+static inline void set_pte_at(struct mm_struct *mm, unsigned long addr,
+			      pte_t *ptep, pte_t pteval)
+{
+	extern void __update_cache(unsigned long address, pte_t pte);
+
+	if (!pte_present(pteval))
+		goto cache_sync_done;
+
+	if (pte_present(*ptep) && (pte_pfn(*ptep) == pte_pfn(pteval)))
+		goto cache_sync_done;
+
+	__update_cache(addr, pteval);
+cache_sync_done:
+	set_pte(ptep, pteval);
+}
+
 /*
  * (pmds are folded into puds so this doesn't get actually called,
  * but the define is needed for a generic inline function.)
@@ -428,15 +447,12 @@ static inline pte_t pte_modify(pte_t pte, pgprot_t newprot)
 
 extern void __update_tlb(struct vm_area_struct *vma, unsigned long address,
 	pte_t pte);
-extern void __update_cache(struct vm_area_struct *vma, unsigned long address,
-	pte_t pte);
 
 static inline void update_mmu_cache(struct vm_area_struct *vma,
 	unsigned long address, pte_t *ptep)
 {
 	pte_t pte = *ptep;
 	__update_tlb(vma, address, pte);
-	__update_cache(vma, address, pte);
 }
 
 static inline void update_mmu_cache_pmd(struct vm_area_struct *vma,
diff --git a/arch/mips/mm/cache.c b/arch/mips/mm/cache.c
index 0d71fdd..48e8172 100644
--- a/arch/mips/mm/cache.c
+++ b/arch/mips/mm/cache.c
@@ -119,30 +119,17 @@ void __flush_anon_page(struct page *page, unsigned long vmaddr)
 
 EXPORT_SYMBOL(__flush_anon_page);
 
-void __flush_icache_page(struct vm_area_struct *vma, struct page *page)
-{
-	unsigned long addr;
-
-	if (PageHighMem(page))
-		return;
-
-	addr = (unsigned long) page_address(page);
-	flush_data_cache_page(addr);
-}
-EXPORT_SYMBOL_GPL(__flush_icache_page);
-
-void __update_cache(struct vm_area_struct *vma, unsigned long address,
-	pte_t pte)
+void __update_cache(unsigned long address, pte_t pte)
 {
 	struct page *page;
 	unsigned long pfn, addr;
-	int exec = (vma->vm_flags & VM_EXEC) && !cpu_has_ic_fills_f_dc;
+	int exec = !pte_no_exec(pte) && !cpu_has_ic_fills_f_dc;
 
 	pfn = pte_pfn(pte);
 	if (unlikely(!pfn_valid(pfn)))
 		return;
 	page = pfn_to_page(pfn);
-	if (page_mapping(page) && Page_dcache_dirty(page)) {
+	if (Page_dcache_dirty(page)) {
 		if (PageHighMem(page))
 			addr = (unsigned long)kmap_atomic(page);
 		else
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418805 — [PATCH 4.2.y-ckt 073/206] MIPS: Reserve nosave data for hibernation

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 073/206] MIPS: Reserve nosave data for hibernation
Message-ID<rIg9A-3KD-7@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Huacai Chen <chenhc@lemote.com>

commit a95d069204e178f18476f5499abab0d0d9cbc32c upstream.

After commit 92923ca3aacef63c92d ("mm: meminit: only set page reserved
in the memblock region"), the MIPS hibernation is broken. Because pages
in nosave data section should be "reserved", but currently they aren't
set to "reserved" at initialization. This patch makes hibernation work
again.

Signed-off-by: Huacai Chen <chenhc@lemote.com>
Cc: Aurelien Jarno <aurelien@aurel32.net>
Cc: Steven J . Hill <sjhill@realitydiluted.com>
Cc: Fuxin Zhang <zhangfx@lemote.com>
Cc: Zhangjin Wu <wuzhangjin@gmail.com>
Cc: linux-mips@linux-mips.org
Patchwork: https://patchwork.linux-mips.org/patch/12888/
Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/mips/kernel/setup.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/arch/mips/kernel/setup.c b/arch/mips/kernel/setup.c
index 4ceac5c..c737bc1 100644
--- a/arch/mips/kernel/setup.c
+++ b/arch/mips/kernel/setup.c
@@ -691,6 +691,9 @@ static void __init arch_mem_init(char **cmdline_p)
 	for_each_memblock(reserved, reg)
 		if (reg->size != 0)
 			reserve_bootmem(reg->base, reg->size, BOOTMEM_DEFAULT);
+
+	reserve_bootmem_region(__pa_symbol(&__nosave_begin),
+			__pa_symbol(&__nosave_end)); /* Reserve for hibernation */
 }
 
 static void __init resource_init(void)
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418806 — [PATCH 4.2.y-ckt 065/206] ext4: silence UBSAN in ext4_mb_init()

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 065/206] ext4: silence UBSAN in ext4_mb_init()
Message-ID<rIg9z-3KD-1@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Nicolai Stange <nicstange@gmail.com>

commit 935244cd54b86ca46e69bc6604d2adfb1aec2d42 upstream.

Currently, in ext4_mb_init(), there's a loop like the following:

  do {
    ...
    offset += 1 << (sb->s_blocksize_bits - i);
    i++;
  } while (i <= sb->s_blocksize_bits + 1);

Note that the updated offset is used in the loop's next iteration only.

However, at the last iteration, that is at i == sb->s_blocksize_bits + 1,
the shift count becomes equal to (unsigned)-1 > 31 (c.f. C99 6.5.7(3))
and UBSAN reports

  UBSAN: Undefined behaviour in fs/ext4/mballoc.c:2621:15
  shift exponent 4294967295 is too large for 32-bit type 'int'
  [...]
  Call Trace:
   [<ffffffff818c4d25>] dump_stack+0xbc/0x117
   [<ffffffff818c4c69>] ? _atomic_dec_and_lock+0x169/0x169
   [<ffffffff819411ab>] ubsan_epilogue+0xd/0x4e
   [<ffffffff81941cac>] __ubsan_handle_shift_out_of_bounds+0x1fb/0x254
   [<ffffffff81941ab1>] ? __ubsan_handle_load_invalid_value+0x158/0x158
   [<ffffffff814b6dc1>] ? kmem_cache_alloc+0x101/0x390
   [<ffffffff816fc13b>] ? ext4_mb_init+0x13b/0xfd0
   [<ffffffff814293c7>] ? create_cache+0x57/0x1f0
   [<ffffffff8142948a>] ? create_cache+0x11a/0x1f0
   [<ffffffff821c2168>] ? mutex_lock+0x38/0x60
   [<ffffffff821c23ab>] ? mutex_unlock+0x1b/0x50
   [<ffffffff814c26ab>] ? put_online_mems+0x5b/0xc0
   [<ffffffff81429677>] ? kmem_cache_create+0x117/0x2c0
   [<ffffffff816fcc49>] ext4_mb_init+0xc49/0xfd0
   [...]

Observe that the mentioned shift exponent, 4294967295, equals (unsigned)-1.

Unless compilers start to do some fancy transformations (which at least
GCC 6.0.0 doesn't currently do), the issue is of cosmetic nature only: the
such calculated value of offset is never used again.

Silence UBSAN by introducing another variable, offset_incr, holding the
next increment to apply to offset and adjust that one by right shifting it
by one position per loop iteration.

Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=114701
Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=112161

Signed-off-by: Nicolai Stange <nicstange@gmail.com>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/ext4/mballoc.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/fs/ext4/mballoc.c b/fs/ext4/mballoc.c
index d9f9361..5162921 100644
--- a/fs/ext4/mballoc.c
+++ b/fs/ext4/mballoc.c
@@ -2571,7 +2571,7 @@ int ext4_mb_init(struct super_block *sb)
 {
 	struct ext4_sb_info *sbi = EXT4_SB(sb);
 	unsigned i, j;
-	unsigned offset;
+	unsigned offset, offset_incr;
 	unsigned max;
 	int ret;
 
@@ -2600,11 +2600,13 @@ int ext4_mb_init(struct super_block *sb)
 
 	i = 1;
 	offset = 0;
+	offset_incr = 1 << (sb->s_blocksize_bits - 1);
 	max = sb->s_blocksize << 2;
 	do {
 		sbi->s_mb_offsets[i] = offset;
 		sbi->s_mb_maxs[i] = max;
-		offset += 1 << (sb->s_blocksize_bits - i);
+		offset += offset_incr;
+		offset_incr = offset_incr >> 1;
 		max = max >> 1;
 		i++;
 	} while (i <= sb->s_blocksize_bits + 1);
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418807 — [PATCH 4.2.y-ckt 095/206] powerpc/eeh: Restore initial state in eeh_pe_reset_and_recover()

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 095/206] powerpc/eeh: Restore initial state in eeh_pe_reset_and_recover()
Message-ID<rIg9z-3KD-3@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Gavin Shan <gwshan@linux.vnet.ibm.com>

commit 5a0cdbfd17b90a89c64a71d8aec9773ecdb20d0d upstream.

The function eeh_pe_reset_and_recover() is used to recover EEH
error when the passthrou device are transferred to guest and
backwards. The content in the device's config space will be lost
on PE reset issued in the middle of the recovery. The function
saves/restores it before/after the reset. However, config access
to some adapters like Broadcom BCM5719 at this point will causes
fenced PHB. The config space is always blocked and we save 0xFF's
that are restored at late point. The memory BARs are totally
corrupted, causing another EEH error upon access to one of the
memory BARs.

This restores the config space on those adapters like BCM5719
from the content saved to the EEH device when it's populated,
to resolve above issue.

Fixes: 5cfb20b9 ("powerpc/eeh: Emulate EEH recovery for VFIO devices")
Signed-off-by: Gavin Shan <gwshan@linux.vnet.ibm.com>
Reviewed-by: Russell Currey <ruscur@russell.cc>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/powerpc/kernel/eeh_driver.c | 23 +++++++++++++++++++++++
 1 file changed, 23 insertions(+)

diff --git a/arch/powerpc/kernel/eeh_driver.c b/arch/powerpc/kernel/eeh_driver.c
index e5f488c..16f315f 100644
--- a/arch/powerpc/kernel/eeh_driver.c
+++ b/arch/powerpc/kernel/eeh_driver.c
@@ -166,6 +166,16 @@ static void *eeh_dev_save_state(void *data, void *userdata)
 	if (!edev)
 		return NULL;
 
+	/*
+	 * We cannot access the config space on some adapters.
+	 * Otherwise, it will cause fenced PHB. We don't save
+	 * the content in their config space and will restore
+	 * from the initial config space saved when the EEH
+	 * device is created.
+	 */
+	if (edev->pe && (edev->pe->state & EEH_PE_CFG_RESTRICTED))
+		return NULL;
+
 	pdev = eeh_dev_to_pci_dev(edev);
 	if (!pdev)
 		return NULL;
@@ -305,6 +315,19 @@ static void *eeh_dev_restore_state(void *data, void *userdata)
 	if (!edev)
 		return NULL;
 
+	/*
+	 * The content in the config space isn't saved because
+	 * the blocked config space on some adapters. We have
+	 * to restore the initial saved config space when the
+	 * EEH device is created.
+	 */
+	if (edev->pe && (edev->pe->state & EEH_PE_CFG_RESTRICTED)) {
+		if (list_is_last(&edev->list, &edev->pe->edevs))
+			eeh_pe_restore_bars(edev->pe);
+
+		return NULL;
+	}
+
 	pdev = eeh_dev_to_pci_dev(edev);
 	if (!pdev)
 		return NULL;
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418808 — [PATCH 4.2.y-ckt 102/206] MIPS: ptrace: Fix FP context restoration FCSR regression

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 102/206] MIPS: ptrace: Fix FP context restoration FCSR regression
Message-ID<rIg9A-3KD-15@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: "Maciej W. Rozycki" <macro@imgtec.com>

commit 4249548454f7ba4581aeee26bd83f42b48a14d15 upstream.

Fix a floating-point context restoration regression introduced with
commit 9b26616c8d9d ("MIPS: Respect the ISA level in FCSR handling")
that causes a Floating Point exception and consequently a kernel oops
with hard float configurations when one or more FCSR Enable and their
corresponding Cause bits are set both at a time via a ptrace(2) call.

To do so reinstate Cause bit masking originally introduced with commit
b1442d39fac2 ("MIPS: Prevent user from setting FCSR cause bits") to
address this exact problem and then inadvertently removed from the
PTRACE_SETFPREGS request with the commit referred above.

Signed-off-by: Maciej W. Rozycki <macro@imgtec.com>
Cc: linux-mips@linux-mips.org
Patchwork: https://patchwork.linux-mips.org/patch/13238/
Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/mips/kernel/ptrace.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/arch/mips/kernel/ptrace.c b/arch/mips/kernel/ptrace.c
index e933a30..d56642a 100644
--- a/arch/mips/kernel/ptrace.c
+++ b/arch/mips/kernel/ptrace.c
@@ -175,6 +175,7 @@ int ptrace_setfpregs(struct task_struct *child, __u32 __user *data)
 	}
 
 	__get_user(value, data + 64);
+	value &= ~FPU_CSR_ALL_X;
 	fcr31 = child->thread.fpu.fcr31;
 	mask = boot_cpu_data.fpu_msk31;
 	child->thread.fpu.fcr31 = (value & ~mask) | (fcr31 & mask);
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418809 — [PATCH 4.2.y-ckt 081/206] USB: serial: mxuport: fix use-after-free in probe error path

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 081/206] USB: serial: mxuport: fix use-after-free in probe error path
Message-ID<rIg9A-3KD-17@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Johan Hovold <johan@kernel.org>

commit 9e45284984096314994777f27e1446dfbfd2f0d7 upstream.

The interface read and event URBs are submitted in attach, but were
never explicitly unlinked by the driver. Instead the URBs would have
been killed by usb-serial core on disconnect.

In case of a late probe error (e.g. due to failed minor allocation),
disconnect is never called and we could end up with active URBs for an
unbound interface. This in turn could lead to deallocated memory being
dereferenced in the completion callbacks.

Fixes: ee467a1f2066 ("USB: serial: add Moxa UPORT 12XX/14XX/16XX
driver")
Signed-off-by: Johan Hovold <johan@kernel.org>
Acked-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/usb/serial/mxuport.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/drivers/usb/serial/mxuport.c b/drivers/usb/serial/mxuport.c
index 460a406..d029b2f 100644
--- a/drivers/usb/serial/mxuport.c
+++ b/drivers/usb/serial/mxuport.c
@@ -1263,6 +1263,15 @@ static int mxuport_attach(struct usb_serial *serial)
 	return 0;
 }
 
+static void mxuport_release(struct usb_serial *serial)
+{
+	struct usb_serial_port *port0 = serial->port[0];
+	struct usb_serial_port *port1 = serial->port[1];
+
+	usb_serial_generic_close(port1);
+	usb_serial_generic_close(port0);
+}
+
 static int mxuport_open(struct tty_struct *tty, struct usb_serial_port *port)
 {
 	struct mxuport_port *mxport = usb_get_serial_port_data(port);
@@ -1365,6 +1374,7 @@ static struct usb_serial_driver mxuport_device = {
 	.probe			= mxuport_probe,
 	.port_probe		= mxuport_port_probe,
 	.attach			= mxuport_attach,
+	.release		= mxuport_release,
 	.calc_num_ports		= mxuport_calc_num_ports,
 	.open			= mxuport_open,
 	.close			= mxuport_close,
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418810 — [PATCH 4.2.y-ckt 085/206] MIPS: KVM: Fix timer IRQ race when writing CP0_Compare

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 085/206] MIPS: KVM: Fix timer IRQ race when writing CP0_Compare
Message-ID<rIg9A-3KD-5@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: James Hogan <james.hogan@imgtec.com>

commit b45bacd2d048f405c7760e5cc9b60dd67708734f upstream.

Writing CP0_Compare clears the timer interrupt pending bit
(CP0_Cause.TI), but this wasn't being done atomically. If a timer
interrupt raced with the write of the guest CP0_Compare, the timer
interrupt could end up being pending even though the new CP0_Compare is
nowhere near CP0_Count.

We were already updating the hrtimer expiry with
kvm_mips_update_hrtimer(), which used both kvm_mips_freeze_hrtimer() and
kvm_mips_resume_hrtimer(). Close the race window by expanding out
kvm_mips_update_hrtimer(), and clearing CP0_Cause.TI and setting
CP0_Compare between the freeze and resume. Since the pending timer
interrupt should not be cleared when CP0_Compare is written via the KVM
user API, an ack argument is added to distinguish the source of the
write.

Fixes: e30492bbe95a ("MIPS: KVM: Rewrite count/compare timer emulation")
Signed-off-by: James Hogan <james.hogan@imgtec.com>
Cc: Paolo Bonzini <pbonzini@redhat.com>
Cc: "Radim Krčmář" <rkrcmar@redhat.com>
Cc: Ralf Baechle <ralf@linux-mips.org>
Cc: linux-mips@linux-mips.org
Cc: kvm@vger.kernel.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/mips/include/asm/kvm_host.h |  2 +-
 arch/mips/kvm/emulate.c          | 61 ++++++++++++++++++----------------------
 arch/mips/kvm/trap_emul.c        |  2 +-
 3 files changed, 29 insertions(+), 36 deletions(-)

diff --git a/arch/mips/include/asm/kvm_host.h b/arch/mips/include/asm/kvm_host.h
index e8c8d9d..4afe1ec 100644
--- a/arch/mips/include/asm/kvm_host.h
+++ b/arch/mips/include/asm/kvm_host.h
@@ -782,7 +782,7 @@ extern enum emulation_result kvm_mips_complete_mmio_load(struct kvm_vcpu *vcpu,
 
 uint32_t kvm_mips_read_count(struct kvm_vcpu *vcpu);
 void kvm_mips_write_count(struct kvm_vcpu *vcpu, uint32_t count);
-void kvm_mips_write_compare(struct kvm_vcpu *vcpu, uint32_t compare);
+void kvm_mips_write_compare(struct kvm_vcpu *vcpu, uint32_t compare, bool ack);
 void kvm_mips_init_count(struct kvm_vcpu *vcpu);
 int kvm_mips_set_count_ctl(struct kvm_vcpu *vcpu, s64 count_ctl);
 int kvm_mips_set_count_resume(struct kvm_vcpu *vcpu, s64 count_resume);
diff --git a/arch/mips/kvm/emulate.c b/arch/mips/kvm/emulate.c
index eaf77b5..dc10c77 100644
--- a/arch/mips/kvm/emulate.c
+++ b/arch/mips/kvm/emulate.c
@@ -438,32 +438,6 @@ static void kvm_mips_resume_hrtimer(struct kvm_vcpu *vcpu,
 }
 
 /**
- * kvm_mips_update_hrtimer() - Update next expiry time of hrtimer.
- * @vcpu:	Virtual CPU.
- *
- * Recalculates and updates the expiry time of the hrtimer. This can be used
- * after timer parameters have been altered which do not depend on the time that
- * the change occurs (in those cases kvm_mips_freeze_hrtimer() and
- * kvm_mips_resume_hrtimer() are used directly).
- *
- * It is guaranteed that no timer interrupts will be lost in the process.
- *
- * Assumes !kvm_mips_count_disabled(@vcpu) (guest CP0_Count timer is running).
- */
-static void kvm_mips_update_hrtimer(struct kvm_vcpu *vcpu)
-{
-	ktime_t now;
-	uint32_t count;
-
-	/*
-	 * freeze_hrtimer takes care of a timer interrupts <= count, and
-	 * resume_hrtimer the hrtimer takes care of a timer interrupts > count.
-	 */
-	now = kvm_mips_freeze_hrtimer(vcpu, &count);
-	kvm_mips_resume_hrtimer(vcpu, now, count);
-}
-
-/**
  * kvm_mips_write_count() - Modify the count and update timer.
  * @vcpu:	Virtual CPU.
  * @count:	Guest CP0_Count value to set.
@@ -558,23 +532,42 @@ int kvm_mips_set_count_hz(struct kvm_vcpu *vcpu, s64 count_hz)
  * kvm_mips_write_compare() - Modify compare and update timer.
  * @vcpu:	Virtual CPU.
  * @compare:	New CP0_Compare value.
+ * @ack:	Whether to acknowledge timer interrupt.
  *
  * Update CP0_Compare to a new value and update the timeout.
+ * If @ack, atomically acknowledge any pending timer interrupt, otherwise ensure
+ * any pending timer interrupt is preserved.
  */
-void kvm_mips_write_compare(struct kvm_vcpu *vcpu, uint32_t compare)
+void kvm_mips_write_compare(struct kvm_vcpu *vcpu, uint32_t compare, bool ack)
 {
 	struct mips_coproc *cop0 = vcpu->arch.cop0;
+	int dc;
+	u32 old_compare = kvm_read_c0_guest_compare(cop0);
+	ktime_t now;
+	uint32_t count;
 
 	/* if unchanged, must just be an ack */
-	if (kvm_read_c0_guest_compare(cop0) == compare)
+	if (old_compare == compare) {
+		if (!ack)
+			return;
+		kvm_mips_callbacks->dequeue_timer_int(vcpu);
+		kvm_write_c0_guest_compare(cop0, compare);
 		return;
+	}
+
+	/* freeze_hrtimer() takes care of timer interrupts <= count */
+	dc = kvm_mips_count_disabled(vcpu);
+	if (!dc)
+		now = kvm_mips_freeze_hrtimer(vcpu, &count);
+
+	if (ack)
+		kvm_mips_callbacks->dequeue_timer_int(vcpu);
 
-	/* Update compare */
 	kvm_write_c0_guest_compare(cop0, compare);
 
-	/* Update timeout if count enabled */
-	if (!kvm_mips_count_disabled(vcpu))
-		kvm_mips_update_hrtimer(vcpu);
+	/* resume_hrtimer() takes care of timer interrupts > count */
+	if (!dc)
+		kvm_mips_resume_hrtimer(vcpu, now, count);
 }
 
 /**
@@ -1113,9 +1106,9 @@ enum emulation_result kvm_mips_emulate_CP0(uint32_t inst, uint32_t *opc,
 
 				/* If we are writing to COMPARE */
 				/* Clear pending timer interrupt, if any */
-				kvm_mips_callbacks->dequeue_timer_int(vcpu);
 				kvm_mips_write_compare(vcpu,
-						       vcpu->arch.gprs[rt]);
+						       vcpu->arch.gprs[rt],
+						       true);
 			} else if ((rd == MIPS_CP0_STATUS) && (sel == 0)) {
 				unsigned int old_val, val, change;
 
diff --git a/arch/mips/kvm/trap_emul.c b/arch/mips/kvm/trap_emul.c
index d836ed5..307cc4c 100644
--- a/arch/mips/kvm/trap_emul.c
+++ b/arch/mips/kvm/trap_emul.c
@@ -547,7 +547,7 @@ static int kvm_trap_emul_set_one_reg(struct kvm_vcpu *vcpu,
 		kvm_mips_write_count(vcpu, v);
 		break;
 	case KVM_REG_MIPS_CP0_COMPARE:
-		kvm_mips_write_compare(vcpu, v);
+		kvm_mips_write_compare(vcpu, v, false);
 		break;
 	case KVM_REG_MIPS_CP0_CAUSE:
 		/*
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418811 — [PATCH 4.2.y-ckt 079/206] USB: serial: io_edgeport: fix memory leaks in probe error path

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 079/206] USB: serial: io_edgeport: fix memory leaks in probe error path
Message-ID<rIg9A-3KD-11@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Johan Hovold <johan@kernel.org>

commit c8d62957d450cc1a22ce3242908709fe367ddc8e upstream.

URBs and buffers allocated in attach for Epic devices would never be
deallocated in case of a later probe error (e.g. failure to allocate
minor numbers) as disconnect is then never called.

Fix by moving deallocation to release and making sure that the
URBs are first unlinked.

Fixes: f9c99bb8b3a1 ("USB: usb-serial: replace shutdown with disconnect,
release")
Signed-off-by: Johan Hovold <johan@kernel.org>
Acked-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/usb/serial/io_edgeport.c | 17 ++++++++++-------
 1 file changed, 10 insertions(+), 7 deletions(-)

diff --git a/drivers/usb/serial/io_edgeport.c b/drivers/usb/serial/io_edgeport.c
index 1106e7d..1947ea0 100644
--- a/drivers/usb/serial/io_edgeport.c
+++ b/drivers/usb/serial/io_edgeport.c
@@ -2966,16 +2966,9 @@ static void edge_disconnect(struct usb_serial *serial)
 {
 	struct edgeport_serial *edge_serial = usb_get_serial_data(serial);
 
-	/* stop reads and writes on all ports */
-	/* free up our endpoint stuff */
 	if (edge_serial->is_epic) {
 		usb_kill_urb(edge_serial->interrupt_read_urb);
-		usb_free_urb(edge_serial->interrupt_read_urb);
-		kfree(edge_serial->interrupt_in_buffer);
-
 		usb_kill_urb(edge_serial->read_urb);
-		usb_free_urb(edge_serial->read_urb);
-		kfree(edge_serial->bulk_in_buffer);
 	}
 }
 
@@ -2988,6 +2981,16 @@ static void edge_release(struct usb_serial *serial)
 {
 	struct edgeport_serial *edge_serial = usb_get_serial_data(serial);
 
+	if (edge_serial->is_epic) {
+		usb_kill_urb(edge_serial->interrupt_read_urb);
+		usb_free_urb(edge_serial->interrupt_read_urb);
+		kfree(edge_serial->interrupt_in_buffer);
+
+		usb_kill_urb(edge_serial->read_urb);
+		usb_free_urb(edge_serial->read_urb);
+		kfree(edge_serial->bulk_in_buffer);
+	}
+
 	kfree(edge_serial);
 }
 
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418812 — [PATCH 4.2.y-ckt 084/206] MIPS: KVM: Fix timer IRQ race when freezing timer

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 084/206] MIPS: KVM: Fix timer IRQ race when freezing timer
Message-ID<rIg9A-3KD-27@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: James Hogan <james.hogan@imgtec.com>

commit 4355c44f063d3de4f072d796604c7f4ba4085cc3 upstream.

There's a particularly narrow and subtle race condition when the
software emulated guest timer is frozen which can allow a guest timer
interrupt to be missed.

This happens due to the hrtimer expiry being inexact, so very
occasionally the freeze time will be after the moment when the emulated
CP0_Count transitions to the same value as CP0_Compare (so an IRQ should
be generated), but before the moment when the hrtimer is due to expire
(so no IRQ is generated). The IRQ won't be generated when the timer is
resumed either, since the resume CP0_Count will already match CP0_Compare.

With VZ guests in particular this is far more likely to happen, since
the soft timer may be frozen frequently in order to restore the timer
state to the hardware guest timer. This happens after 5-10 hours of
guest soak testing, resulting in an overflow in guest kernel timekeeping
calculations, hanging the guest. A more focussed test case to
intentionally hit the race (with the help of a new hypcall to cause the
timer state to migrated between hardware & software) hits the condition
fairly reliably within around 30 seconds.

Instead of relying purely on the inexact hrtimer expiry to determine
whether an IRQ should be generated, read the guest CP0_Compare and
directly check whether the freeze time is before or after it. Only if
CP0_Count is on or after CP0_Compare do we check the hrtimer expiry to
determine whether the last IRQ has already been generated (which will
have pushed back the expiry by one timer period).

Fixes: e30492bbe95a ("MIPS: KVM: Rewrite count/compare timer emulation")
Signed-off-by: James Hogan <james.hogan@imgtec.com>
Cc: Paolo Bonzini <pbonzini@redhat.com>
Cc: "Radim Krčmář" <rkrcmar@redhat.com>
Cc: Ralf Baechle <ralf@linux-mips.org>
Cc: linux-mips@linux-mips.org
Cc: kvm@vger.kernel.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/mips/kvm/emulate.c | 28 +++++++++++++++++++++++-----
 1 file changed, 23 insertions(+), 5 deletions(-)

diff --git a/arch/mips/kvm/emulate.c b/arch/mips/kvm/emulate.c
index 41b1b09..eaf77b5 100644
--- a/arch/mips/kvm/emulate.c
+++ b/arch/mips/kvm/emulate.c
@@ -302,12 +302,31 @@ static inline ktime_t kvm_mips_count_time(struct kvm_vcpu *vcpu)
  */
 static uint32_t kvm_mips_read_count_running(struct kvm_vcpu *vcpu, ktime_t now)
 {
-	ktime_t expires;
+	struct mips_coproc *cop0 = vcpu->arch.cop0;
+	ktime_t expires, threshold;
+	uint32_t count, compare;
 	int running;
 
-	/* Is the hrtimer pending? */
+	/* Calculate the biased and scaled guest CP0_Count */
+	count = vcpu->arch.count_bias + kvm_mips_ktime_to_count(vcpu, now);
+	compare = kvm_read_c0_guest_compare(cop0);
+
+	/*
+	 * Find whether CP0_Count has reached the closest timer interrupt. If
+	 * not, we shouldn't inject it.
+	 */
+	if ((int32_t)(count - compare) < 0)
+		return count;
+
+	/*
+	 * The CP0_Count we're going to return has already reached the closest
+	 * timer interrupt. Quickly check if it really is a new interrupt by
+	 * looking at whether the interval until the hrtimer expiry time is
+	 * less than 1/4 of the timer period.
+	 */
 	expires = hrtimer_get_expires(&vcpu->arch.comparecount_timer);
-	if (ktime_compare(now, expires) >= 0) {
+	threshold = ktime_add_ns(now, vcpu->arch.count_period / 4);
+	if (ktime_before(expires, threshold)) {
 		/*
 		 * Cancel it while we handle it so there's no chance of
 		 * interference with the timeout handler.
@@ -329,8 +348,7 @@ static uint32_t kvm_mips_read_count_running(struct kvm_vcpu *vcpu, ktime_t now)
 		}
 	}
 
-	/* Return the biased and scaled guest CP0_Count */
-	return vcpu->arch.count_bias + kvm_mips_ktime_to_count(vcpu, now);
+	return count;
 }
 
 /**
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418813 — [PATCH 4.2.y-ckt 088/206] irqchip/gic-v3: Configure all interrupts as non-secure Group-1

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 088/206] irqchip/gic-v3: Configure all interrupts as non-secure Group-1
Message-ID<rIg9A-3KD-29@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Marc Zyngier <marc.zyngier@arm.com>

commit 7c9b973061b03af62734f613f6abec46c0dd4a88 upstream.

The GICv3 driver wrongly assumes that it runs on the non-secure
side of a secure-enabled system, while it could be on a system
with a single security state, or a GICv3 with GICD_CTLR.DS set.

Either way, it is important to configure this properly, or
interrupts will simply not be delivered on this HW.

Reported-by: Peter Maydell <peter.maydell@linaro.org>
Tested-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Marc Zyngier <marc.zyngier@arm.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/irqchip/irq-gic-v3.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/drivers/irqchip/irq-gic-v3.c b/drivers/irqchip/irq-gic-v3.c
index f5c518b..0daa31d 100644
--- a/drivers/irqchip/irq-gic-v3.c
+++ b/drivers/irqchip/irq-gic-v3.c
@@ -379,6 +379,15 @@ static void __init gic_dist_init(void)
 	writel_relaxed(0, base + GICD_CTLR);
 	gic_dist_wait_for_rwp();
 
+	/*
+	 * Configure SPIs as non-secure Group-1. This will only matter
+	 * if the GIC only has a single security state. This will not
+	 * do the right thing if the kernel is running in secure mode,
+	 * but that's not the intended use case anyway.
+	 */
+	for (i = 32; i < gic_data.irq_nr; i += 32)
+		writel_relaxed(~0, base + GICD_IGROUPR + i / 8);
+
 	gic_dist_config(base, gic_data.irq_nr, gic_dist_wait_for_rwp);
 
 	/* Enable distributor with ARE, Group1 */
@@ -482,6 +491,9 @@ static void gic_cpu_init(void)
 
 	rbase = gic_data_rdist_sgi_base();
 
+	/* Configure SGIs/PPIs as non-secure Group-1 */
+	writel_relaxed(~0, rbase + GICR_IGROUPR0);
+
 	gic_cpu_config(rbase, gic_redist_wait_for_rwp);
 
 	/* Give LPIs a spin */
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418815 — [PATCH 4.2.y-ckt 072/206] MIPS: Avoid using unwind_stack() with usermode

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 072/206] MIPS: Avoid using unwind_stack() with usermode
Message-ID<rIg9A-3KD-13@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: James Hogan <james.hogan@imgtec.com>

commit 81a76d7119f63c359750e4adeff922a31ad1135f upstream.

When showing backtraces in response to traps, for example crashes and
address errors (usually unaligned accesses) when they are set in debugfs
to be reported, unwind_stack will be used if the PC was in the kernel
text address range. However since EVA it is possible for user and kernel
address ranges to overlap, and even without EVA userland can still
trigger an address error by jumping to a KSeg0 address.

Adjust the check to also ensure that it was running in kernel mode. I
don't believe any harm can come of this problem, since unwind_stack() is
sufficiently defensive, however it is only meant for unwinding kernel
code, so to be correct it should use the raw backtracing instead.

Signed-off-by: James Hogan <james.hogan@imgtec.com>
Reviewed-by: Leonid Yegoshin <Leonid.Yegoshin@imgtec.com>
Cc: linux-mips@linux-mips.org
Patchwork: https://patchwork.linux-mips.org/patch/11701/
Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
(cherry picked from commit d2941a975ac745c607dfb590e92bb30bc352dad9)
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/mips/kernel/traps.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/mips/kernel/traps.c b/arch/mips/kernel/traps.c
index ef1e9d3..86454f5 100644
--- a/arch/mips/kernel/traps.c
+++ b/arch/mips/kernel/traps.c
@@ -143,7 +143,7 @@ static void show_backtrace(struct task_struct *task, const struct pt_regs *regs)
 	if (!task)
 		task = current;
 
-	if (raw_show_trace || !__kernel_text_address(pc)) {
+	if (raw_show_trace || user_mode(regs) || !__kernel_text_address(pc)) {
 		show_raw_backtrace(sp);
 		return;
 	}
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418816 — [PATCH 4.2.y-ckt 093/206] sched/loadavg: Fix loadavg artifacts on fully idle and on fully loaded systems

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 093/206] sched/loadavg: Fix loadavg artifacts on fully idle and on fully loaded systems
Message-ID<rIg9A-3KD-35@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Vik Heyndrickx <vik.heyndrickx@veribox.net>

commit 20878232c52329f92423d27a60e48b6a6389e0dd upstream.

Systems show a minimal load average of 0.00, 0.01, 0.05 even when they
have no load at all.

Uptime and /proc/loadavg on all systems with kernels released during the
last five years up until kernel version 4.6-rc5, show a 5- and 15-minute
minimum loadavg of 0.01 and 0.05 respectively. This should be 0.00 on
idle systems, but the way the kernel calculates this value prevents it
from getting lower than the mentioned values.

Likewise but not as obviously noticeable, a fully loaded system with no
processes waiting, shows a maximum 1/5/15 loadavg of 1.00, 0.99, 0.95
(multiplied by number of cores).

Once the (old) load becomes 93 or higher, it mathematically can never
get lower than 93, even when the active (load) remains 0 forever.
This results in the strange 0.00, 0.01, 0.05 uptime values on idle
systems.  Note: 93/2048 = 0.0454..., which rounds up to 0.05.

It is not correct to add a 0.5 rounding (=1024/2048) here, since the
result from this function is fed back into the next iteration again,
so the result of that +0.5 rounding value then gets multiplied by
(2048-2037), and then rounded again, so there is a virtual "ghost"
load created, next to the old and active load terms.

By changing the way the internally kept value is rounded, that internal
value equivalent now can reach 0.00 on idle, and 1.00 on full load. Upon
increasing load, the internally kept load value is rounded up, when the
load is decreasing, the load value is rounded down.

The modified code was tested on nohz=off and nohz kernels. It was tested
on vanilla kernel 4.6-rc5 and on centos 7.1 kernel 3.10.0-327. It was
tested on single, dual, and octal cores system. It was tested on virtual
hosts and bare hardware. No unwanted effects have been observed, and the
problems that the patch intended to fix were indeed gone.

Tested-by: Damien Wyart <damien.wyart@free.fr>
Signed-off-by: Vik Heyndrickx <vik.heyndrickx@veribox.net>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Doug Smythies <dsmythies@telus.net>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Mike Galbraith <efault@gmx.de>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Fixes: 0f004f5a696a ("sched: Cure more NO_HZ load average woes")
Link: http://lkml.kernel.org/r/e8d32bff-d544-7748-72b5-3c86cc71f09f@veribox.net
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 kernel/sched/loadavg.c | 11 +++++++----
 1 file changed, 7 insertions(+), 4 deletions(-)

diff --git a/kernel/sched/loadavg.c b/kernel/sched/loadavg.c
index ef71590..b0b93fd 100644
--- a/kernel/sched/loadavg.c
+++ b/kernel/sched/loadavg.c
@@ -99,10 +99,13 @@ long calc_load_fold_active(struct rq *this_rq)
 static unsigned long
 calc_load(unsigned long load, unsigned long exp, unsigned long active)
 {
-	load *= exp;
-	load += active * (FIXED_1 - exp);
-	load += 1UL << (FSHIFT - 1);
-	return load >> FSHIFT;
+	unsigned long newload;
+
+	newload = load * exp + active * (FIXED_1 - exp);
+	if (active >= load)
+		newload += FIXED_1-1;
+
+	return newload / FIXED_1;
 }
 
 #ifdef CONFIG_NO_HZ_COMMON
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418817 — [PATCH 4.2.y-ckt 089/206] arm64: cpuinfo: Missing NULL terminator in compat_hwcap_str

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 089/206] arm64: cpuinfo: Missing NULL terminator in compat_hwcap_str
Message-ID<rIg9A-3KD-37@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Julien Grall <julien.grall@arm.com>

commit f228b494e56d949be8d8ea09d4f973d1979201bf upstream.

The loop that browses the array compat_hwcap_str will stop when a NULL
is encountered, however NULL is missing at the end of array. This will
lead to overrun until a NULL is found somewhere in the following memory.
In reality, this works out because the compat_hwcap2_str array tends to
follow immediately in memory, and that *is* terminated correctly.
Furthermore, the unsigned int compat_elf_hwcap is checked before
printing each capability, so we end up doing the right thing because
the size of the two arrays is less than 32. Still, this is an obvious
mistake and should be fixed.

Note for backporting: commit 12d11817eaafa414 ("arm64: Move
/proc/cpuinfo handling code") moved this code in v4.4. Prior to that
commit, the same change should be made in arch/arm64/kernel/setup.c.

Fixes: 44b82b7700d0 "arm64: Fix up /proc/cpuinfo"
Signed-off-by: Julien Grall <julien.grall@arm.com>
Signed-off-by: Will Deacon <will.deacon@arm.com>
[ kamal: backport to 4.2-stable: applied to setup.c ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/arm64/kernel/setup.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/kernel/setup.c b/arch/arm64/kernel/setup.c
index f3067d4..448b501 100644
--- a/arch/arm64/kernel/setup.c
+++ b/arch/arm64/kernel/setup.c
@@ -482,7 +482,8 @@ static const char *compat_hwcap_str[] = {
 	"idivt",
 	"vfpd32",
 	"lpae",
-	"evtstrm"
+	"evtstrm",
+	NULL
 };
 
 static const char *compat_hwcap2_str[] = {
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418818 — [PATCH 4.2.y-ckt 092/206] rtlwifi: pci: use dev_kfree_skb_irq instead of kfree_skb in rtl_pci_reset_trx_ring

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 092/206] rtlwifi: pci: use dev_kfree_skb_irq instead of kfree_skb in rtl_pci_reset_trx_ring
Message-ID<rIg9A-3KD-19@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: wang yanqing <udknight@gmail.com>

commit cf968937d27751296920e6b82ffa89735e3a0023 upstream.

We can't use kfree_skb in irq disable context, because spin_lock_irqsave
make sure we are always in irq disable context, use dev_kfree_skb_irq
instead of kfree_skb is better than dev_kfree_skb_any.

This patch fix below kernel warning:
[ 7612.095528] ------------[ cut here ]------------
[ 7612.095546] WARNING: CPU: 3 PID: 4460 at kernel/softirq.c:150 __local_bh_enable_ip+0x58/0x80()
[ 7612.095550] Modules linked in: rtl8723be x86_pkg_temp_thermal btcoexist rtl_pci rtlwifi rtl8723_common
[ 7612.095567] CPU: 3 PID: 4460 Comm: ifconfig Tainted: G        W       4.4.0+ #4
[ 7612.095570] Hardware name: LENOVO 20DFA04FCD/20DFA04FCD, BIOS J5ET48WW (1.19 ) 08/27/2015
[ 7612.095574]  00000000 00000000 da37fc70 c12ce7c5 00000000 da37fca0 c104cc59 c19d4454
[ 7612.095584]  00000003 0000116c c19d4784 00000096 c10508a8 c10508a8 00000200 c1b42400
[ 7612.095594]  f29be780 da37fcb0 c104ccad 00000009 00000000 da37fcbc c10508a8 f21f08b8
[ 7612.095604] Call Trace:
[ 7612.095614]  [<c12ce7c5>] dump_stack+0x41/0x5c
[ 7612.095620]  [<c104cc59>] warn_slowpath_common+0x89/0xc0
[ 7612.095628]  [<c10508a8>] ? __local_bh_enable_ip+0x58/0x80
[ 7612.095634]  [<c10508a8>] ? __local_bh_enable_ip+0x58/0x80
[ 7612.095640]  [<c104ccad>] warn_slowpath_null+0x1d/0x20
[ 7612.095646]  [<c10508a8>] __local_bh_enable_ip+0x58/0x80
[ 7612.095653]  [<c16b7d34>] destroy_conntrack+0x64/0xa0
[ 7612.095660]  [<c16b300f>] nf_conntrack_destroy+0xf/0x20
[ 7612.095665]  [<c1677565>] skb_release_head_state+0x55/0xa0
[ 7612.095670]  [<c16775bb>] skb_release_all+0xb/0x20
[ 7612.095674]  [<c167760b>] __kfree_skb+0xb/0x60
[ 7612.095679]  [<c16776f0>] kfree_skb+0x30/0x70
[ 7612.095686]  [<f81b869d>] ? rtl_pci_reset_trx_ring+0x22d/0x370 [rtl_pci]
[ 7612.095692]  [<f81b869d>] rtl_pci_reset_trx_ring+0x22d/0x370 [rtl_pci]
[ 7612.095698]  [<f81b87f9>] rtl_pci_start+0x19/0x190 [rtl_pci]
[ 7612.095705]  [<f81970e6>] rtl_op_start+0x56/0x90 [rtlwifi]
[ 7612.095712]  [<c17e3f16>] drv_start+0x36/0xc0
[ 7612.095717]  [<c17f5ab3>] ieee80211_do_open+0x2d3/0x890
[ 7612.095725]  [<c16820fe>] ? call_netdevice_notifiers_info+0x2e/0x60
[ 7612.095730]  [<c17f60bd>] ieee80211_open+0x4d/0x50
[ 7612.095736]  [<c16891b3>] __dev_open+0xa3/0x130
[ 7612.095742]  [<c183fa53>] ? _raw_spin_unlock_bh+0x13/0x20
[ 7612.095748]  [<c1689499>] __dev_change_flags+0x89/0x140
[ 7612.095753]  [<c127c70d>] ? selinux_capable+0xd/0x10
[ 7612.095759]  [<c1689589>] dev_change_flags+0x29/0x60
[ 7612.095765]  [<c1700b93>] devinet_ioctl+0x553/0x670
[ 7612.095772]  [<c12db758>] ? _copy_to_user+0x28/0x40
[ 7612.095777]  [<c17018b5>] inet_ioctl+0x85/0xb0
[ 7612.095783]  [<c166e647>] sock_ioctl+0x67/0x260
[ 7612.095788]  [<c166e5e0>] ? sock_fasync+0x80/0x80
[ 7612.095795]  [<c115c99b>] do_vfs_ioctl+0x6b/0x550
[ 7612.095800]  [<c127c812>] ? selinux_file_ioctl+0x102/0x1e0
[ 7612.095807]  [<c10a8914>] ? timekeeping_suspend+0x294/0x320
[ 7612.095813]  [<c10a256a>] ? __hrtimer_run_queues+0x14a/0x210
[ 7612.095820]  [<c1276e24>] ? security_file_ioctl+0x34/0x50
[ 7612.095827]  [<c115cef0>] SyS_ioctl+0x70/0x80
[ 7612.095832]  [<c1001804>] do_fast_syscall_32+0x84/0x120
[ 7612.095839]  [<c183ff91>] sysenter_past_esp+0x36/0x55
[ 7612.095844] ---[ end trace 97e9c637a20e8348 ]---

Signed-off-by: Wang YanQing <udknight@gmail.com>
Acked-by: Larry Finger <Larry.Finger@lwfinger.net>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
[ kamal: backport to 4.2-stable: files moved ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/wireless/rtlwifi/pci.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/wireless/rtlwifi/pci.c b/drivers/net/wireless/rtlwifi/pci.c
index 7f471bf..5b40480 100644
--- a/drivers/net/wireless/rtlwifi/pci.c
+++ b/drivers/net/wireless/rtlwifi/pci.c
@@ -1573,7 +1573,7 @@ int rtl_pci_reset_trx_ring(struct ieee80211_hw *hw)
 							 true,
 							 HW_DESC_TXBUFF_ADDR),
 						 skb->len, PCI_DMA_TODEVICE);
-				kfree_skb(skb);
+				dev_kfree_skb_irq(skb);
 				ring->idx = (ring->idx + 1) % ring->entries;
 			}
 			ring->idx = 0;
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418820 — [PATCH 4.2.y-ckt 071/206] MIPS: Don't unwind to user mode with EVA

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 071/206] MIPS: Don't unwind to user mode with EVA
Message-ID<rIg9A-3KD-39@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: James Hogan <james.hogan@imgtec.com>

commit a816b306c62195b7c43c92cb13330821a96bdc27 upstream.

When unwinding through IRQs and exceptions, the unwinding only continues
if the PC is a kernel text address, however since EVA it is possible for
user and kernel address ranges to overlap, potentially allowing
unwinding to continue to user mode if the user PC happens to be in the
kernel text address range.

Adjust the check to also ensure that the register state from before the
exception is actually running in kernel mode, i.e. !user_mode(regs).

I don't believe any harm can come of this problem, since the PC is only
output, the stack pointer is checked to ensure it resides within the
task's stack page before it is dereferenced in search of the return
address, and the return address register is similarly only output (if
the PC is in a leaf function or the beginning of a non-leaf function).

However unwind_stack() is only meant for unwinding kernel code, so to be
correct the unwind should stop there.

Signed-off-by: James Hogan <james.hogan@imgtec.com>
Reviewed-by: Leonid Yegoshin <Leonid.Yegoshin@imgtec.com>
Cc: linux-mips@linux-mips.org
Patchwork: https://patchwork.linux-mips.org/patch/11700/
Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/mips/kernel/process.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/mips/kernel/process.c b/arch/mips/kernel/process.c
index f2975d4..6b3ae73 100644
--- a/arch/mips/kernel/process.c
+++ b/arch/mips/kernel/process.c
@@ -457,7 +457,7 @@ unsigned long notrace unwind_stack_by_address(unsigned long stack_page,
 		    *sp + sizeof(*regs) <= stack_page + THREAD_SIZE - 32) {
 			regs = (struct pt_regs *)*sp;
 			pc = regs->cp0_epc;
-			if (__kernel_text_address(pc)) {
+			if (!user_mode(regs) && __kernel_text_address(pc)) {
 				*sp = regs->regs[29];
 				*ra = regs->regs[31];
 				return pc;
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418821 — [PATCH 4.2.y-ckt 096/206] Revert "powerpc/eeh: Fix crash in eeh_add_device_early() on Cell"

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 096/206] Revert "powerpc/eeh: Fix crash in eeh_add_device_early() on Cell"
Message-ID<rIg9A-3KD-43@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: "Guilherme G. Piccoli" <gpiccoli@linux.vnet.ibm.com>

commit c2078d9ef600bdbe568c89e5ddc2c6f15b7982c8 upstream.

This reverts commit 89a51df5ab1d38b257300b8ac940bbac3bb0eb9b.

The function eeh_add_device_early() is used to perform EEH
initialization in devices added later on the system, like in
hotplug/DLPAR scenarios. Since the commit 89a51df5ab1d ("powerpc/eeh:
Fix crash in eeh_add_device_early() on Cell") a new check was introduced
in this function - Cell has no EEH capabilities which led to kernel oops
if hotplug was performed, so checking for eeh_enabled() was introduced
to avoid the issue.

However, in architectures that EEH is present like pSeries or PowerNV,
we might reach a case in which no PCI devices are present on boot time
and so EEH is not initialized. Then, if a device is added via DLPAR for
example, eeh_add_device_early() fails because eeh_enabled() is false,
and EEH end up not being enabled at all.

This reverts the aforementioned patch since a new verification was
introduced by the commit d91dafc02f42 ("powerpc/eeh: Delay probing EEH
device during hotplug") and so the original Cell issue does not happen
anymore.

Reviewed-by: Gavin Shan <gwshan@linux.vnet.ibm.com>
Signed-off-by: Guilherme G. Piccoli <gpiccoli@linux.vnet.ibm.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/powerpc/kernel/eeh.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/powerpc/kernel/eeh.c b/arch/powerpc/kernel/eeh.c
index 01c961d..1109964 100644
--- a/arch/powerpc/kernel/eeh.c
+++ b/arch/powerpc/kernel/eeh.c
@@ -1071,7 +1071,7 @@ void eeh_add_device_early(struct pci_dn *pdn)
 	struct pci_controller *phb;
 	struct eeh_dev *edev = pdn_to_eeh_dev(pdn);
 
-	if (!edev || !eeh_enabled())
+	if (!edev)
 		return;
 
 	if (!eeh_has_flag(EEH_PROBE_MODE_DEVTREE))
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1418822 — [PATCH 4.2.y-ckt 078/206] USB: serial: io_edgeport: fix memory leaks in attach error path

FromKamal Mostafa <kamal@canonical.com>
Date2016-06-10 00:00 +0200
Subject[PATCH 4.2.y-ckt 078/206] USB: serial: io_edgeport: fix memory leaks in attach error path
Message-ID<rIg9A-3KD-41@gated-at.bofh.it>
In reply to#1418691
4.2.8-ckt12 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Johan Hovold <johan@kernel.org>

commit c5c0c55598cefc826d6cfb0a417eeaee3631715c upstream.

Private data, URBs and buffers allocated for Epic devices during
attach were never released on errors (e.g. missing endpoints).

Fixes: 6e8cf7751f9f ("USB: add EPIC support to the io_edgeport driver")
Signed-off-by: Johan Hovold <johan@kernel.org>
Acked-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/usb/serial/io_edgeport.c | 39 ++++++++++++++++++++++++++++-----------
 1 file changed, 28 insertions(+), 11 deletions(-)

diff --git a/drivers/usb/serial/io_edgeport.c b/drivers/usb/serial/io_edgeport.c
index c086697..1106e7d 100644
--- a/drivers/usb/serial/io_edgeport.c
+++ b/drivers/usb/serial/io_edgeport.c
@@ -2856,14 +2856,16 @@ static int edge_startup(struct usb_serial *serial)
 				/* not set up yet, so do it now */
 				edge_serial->interrupt_read_urb =
 						usb_alloc_urb(0, GFP_KERNEL);
-				if (!edge_serial->interrupt_read_urb)
-					return -ENOMEM;
+				if (!edge_serial->interrupt_read_urb) {
+					response = -ENOMEM;
+					break;
+				}
 
 				edge_serial->interrupt_in_buffer =
 					kmalloc(buffer_size, GFP_KERNEL);
 				if (!edge_serial->interrupt_in_buffer) {
-					usb_free_urb(edge_serial->interrupt_read_urb);
-					return -ENOMEM;
+					response = -ENOMEM;
+					break;
 				}
 				edge_serial->interrupt_in_endpoint =
 						endpoint->bEndpointAddress;
@@ -2891,14 +2893,16 @@ static int edge_startup(struct usb_serial *serial)
 				/* not set up yet, so do it now */
 				edge_serial->read_urb =
 						usb_alloc_urb(0, GFP_KERNEL);
-				if (!edge_serial->read_urb)
-					return -ENOMEM;
+				if (!edge_serial->read_urb) {
+					response = -ENOMEM;
+					break;
+				}
 
 				edge_serial->bulk_in_buffer =
 					kmalloc(buffer_size, GFP_KERNEL);
 				if (!edge_serial->bulk_in_buffer) {
-					usb_free_urb(edge_serial->read_urb);
-					return -ENOMEM;
+					response = -ENOMEM;
+					break;
 				}
 				edge_serial->bulk_in_endpoint =
 						endpoint->bEndpointAddress;
@@ -2924,9 +2928,22 @@ static int edge_startup(struct usb_serial *serial)
 			}
 		}
 
-		if (!interrupt_in_found || !bulk_in_found || !bulk_out_found) {
-			dev_err(ddev, "Error - the proper endpoints were not found!\n");
-			return -ENODEV;
+		if (response || !interrupt_in_found || !bulk_in_found ||
+							!bulk_out_found) {
+			if (!response) {
+				dev_err(ddev, "expected endpoints not found\n");
+				response = -ENODEV;
+			}
+
+			usb_free_urb(edge_serial->interrupt_read_urb);
+			kfree(edge_serial->interrupt_in_buffer);
+
+			usb_free_urb(edge_serial->read_urb);
+			kfree(edge_serial->bulk_in_buffer);
+
+			kfree(edge_serial);
+
+			return response;
 		}
 
 		/* start interrupt read for this edgeport this interrupt will
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


Page 6 of 10 — ← Prev page 1 … 4 5 [6] 7 8 … 10  Next page →

Back to top | Article view | linux.kernel


csiph-web