Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1421229 > unrolled thread

[PATCH 3.16 000/114] 3.16.36-rc1 review

Started byBen Hutchings <ben@decadent.org.uk>
First post2016-06-13 21:20 +0200
Last post2016-06-14 13:30 +0200
Articles 18 — 4 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.16 000/114] 3.16.36-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2016-06-13 21:20 +0200
    [PATCH 3.16 014/114] kvm: x86: do not leak guest xcr0 into host  interrupt handlers Ben Hutchings <ben@decadent.org.uk> - 2016-06-13 21:20 +0200
    [PATCH 3.16 045/114] batman-adv: Reduce refcnt of removed router  when updating route Ben Hutchings <ben@decadent.org.uk> - 2016-06-13 21:20 +0200
    [PATCH 3.16 040/114] s390/hugetlb: add hugepages_supported define Ben Hutchings <ben@decadent.org.uk> - 2016-06-13 21:20 +0200
    [PATCH 3.16 013/114] assoc_array: don't call compare_object() on  a node Ben Hutchings <ben@decadent.org.uk> - 2016-06-13 21:20 +0200
    [PATCH 3.16 027/114] crypto: ccp - Prevent information leakage on  export Ben Hutchings <ben@decadent.org.uk> - 2016-06-13 21:20 +0200
    [PATCH 3.16 069/114] tracing: Don't display trigger file for  events that can't be enabled Ben Hutchings <ben@decadent.org.uk> - 2016-06-13 21:20 +0200
    [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler()  after one pass Ben Hutchings <ben@decadent.org.uk> - 2016-06-13 21:20 +0200
      Re: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler()  after one pass Ville Syrjälä <ville.syrjala@linux.intel.com> - 2016-06-14 12:50 +0200
        Re: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler()  after one pass Ben Hutchings <ben@decadent.org.uk> - 2016-06-14 13:40 +0200
          Re: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler()  after one pass Ville Syrjälä <ville.syrjala@linux.intel.com> - 2016-06-14 14:10 +0200
            Re: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler()  after one pass Ben Hutchings <ben@decadent.org.uk> - 2016-06-14 14:50 +0200
              Re: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler()  after one pass Ville Syrjälä <ville.syrjala@linux.intel.com> - 2016-06-14 15:10 +0200
    [PATCH 3.16 009/114] Input: gtco - fix crash on detecting device  without endpoints Ben Hutchings <ben@decadent.org.uk> - 2016-06-13 21:20 +0200
    [PATCH 3.16 058/114] mm/huge_memory: replace VM_NO_THP VM_BUG_ON  with actual VMA check Ben Hutchings <ben@decadent.org.uk> - 2016-06-13 21:20 +0200
    Re: [PATCH 3.16 000/114] 3.16.36-rc1 review Sudip Mukherjee <sudipm.mukherjee@gmail.com> - 2016-06-13 23:20 +0200
    Re: [PATCH 3.16 000/114] 3.16.36-rc1 review Guenter Roeck <linux@roeck-us.net> - 2016-06-14 04:00 +0200
      Re: [PATCH 3.16 000/114] 3.16.36-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2016-06-14 13:30 +0200

#1421229 — [PATCH 3.16 000/114] 3.16.36-rc1 review

FromBen Hutchings <ben@decadent.org.uk>
Date2016-06-13 21:20 +0200
Subject[PATCH 3.16 000/114] 3.16.36-rc1 review
Message-ID<rJEWe-1BQ-3@gated-at.bofh.it>
This is the start of the stable review cycle for the 3.16.36 release.
There are 114 patches in this series, which will be posted as responses
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Wed Jun 15 19:00:00 UTC 2016.
Anything received after that time might be too late.

A combined patch relative to 3.16.35 will be posted as an additional
response to this.  A shortlog and diffstat can be found below.

Ben.

-------------

Al Viro (2):
      atomic_open(): fix the handling of create_error
         [10c64cea04d3c75c306b3f990586ffb343b63287]
      get_rock_ridge_filename(): handle malformed NM entries
         [99d825822eade8d827a1817357cbf3f889a552d6]

Alan Stern (1):
      HID: usbhid: fix inconsistent reset/resume/reset-resume behavior
         [972e6a993f278b416a8ee3ec65475724fc36feb2]

Alex Deucher (2):
      drm/radeon: add a quirk for a XFX R9 270X
         [bcb31eba4a4ea356fd61cbd5dec5511c3883f57e]
      drm/radeon: make sure vertical front porch is at least 1
         [3104b8128d4d646a574ed9d5b17c7d10752cd70b]

Anton Blanchard (2):
      powerpc: Fix bad inline asm constraint in create_zero_mask()
         [b4c112114aab9aff5ed4568ca5e662bb02cdfe74]
      powerpc: scan_features() updates incorrect bits for REAL_LE
         [6997e57d693b07289694239e52a10d2f02c3a46f]

Antonio Quartulli (1):
      batman-adv: fix DAT candidate selection (must use vid)
         [2871734e85e920503d49b3a8bc0afbe0773b6036]

Ben Hutchings (5):
      Revert "ax25: add link layer header validation function"
         [not upstream; commit being reverted was a useless backport to 3.2]
      Revert "net: validate variable length ll headers"
         [not upstream; commit being reverted was a useless backport to 3.2]
      atl2: Disable unimplemented scatter/gather feature
         [f43bfaeddc79effbf3d0fcb53ca477cca66f3db8]
      spi: spi-ti-qspi: Fix FLEN and WLEN settings if bits_per_word is overridden
         [ea1b60fb085839a9544cb3a0069992991beabb7f]
      spi: spi-ti-qspi: Handle truncated frames properly
         [1ff7760ff66b98ef244bf0e5e2bd5310651205ad]

Chen Yu (1):
      x86/tsc: Read all ratio bits from MSR_PLATFORM_INFO
         [886123fb3a8656699dff40afa0573df359abeb18]

Chris Wilson (2):
      drm/i915/userptr: Hold mmref whilst calling get-user-pages
         [40313f0cd0b711a7a5905e5182422799e157d8aa]
      drm/i915: Exit cherryview_irq_handler() after one pass
         [579de73b048a0a4c66c25a033ac76a2836e0cf73]

Christopher Oo (1):
      Drivers: hv_vmbus: Fix signal to host condition
         [a5cca686ce0ef4909deaee4ed46dd991e3a9ece4]

Chunyu Hu (1):
      tracing: Don't display trigger file for events that can't be enabled
         [854145e0a8e9a05f7366d240e2f99d9c1ca6d6dd]

Conrad Kostecki (1):
      ALSA: hda - Add dock support for ThinkPad X260
         [037e119738120c1cdc460c6ae33871c3000531f3]

Dan Carpenter (1):
      ocfs2: dereferencing freed pointers in ocfs2_reflink()
         [e073fc58dfe6a4c9b614320c1d56bb71cb213ec4]

Daniel Vetter (1):
      drm/i915: Bail out of pipe config compute loop on LPT
         [f58a1acc7e4a1f37d26124ce4c875c647fbcc61f]

Dave Chinner (8):
      xfs: fix swapext ilock deadlock
         [812176832169c77b4bacddd01edc3e55340263fd]
      xfs: introduce mmap/truncate lock
         [653c60b633a9019a54a80d64b5ed33ecb214823c]
      xfs: lock out page faults from extent swap operations
         [723cac48473358939759885a18e8df113ea96138]
      xfs: mmap lock needs to be inside freeze protection
         [ec56b1f1fdc69599963574ce94cc5693d535dd64]
      xfs: take i_mmap_lock on extent manipulation operations
         [e8e9ad42c1f1e1bfbe0e8c32c8cac02e9ebfb7ef]
      xfs: use i_mmaplock on read faults
         [de0e8c20ba3a65b0f15040aabbefdc1999876e6b]
      xfs: use i_mmaplock on write faults
         [075a924d45cc69c75a35f20b4912b85aa98b180a]
      xfs: xfs_setattr_size no longer races with page faults
         [0f9160b444e4de33b65dfcd3b901358a3129461a]

David Howells (1):
      KEYS: Fix ASN.1 indefinite length object parsing
         [23c8a812dc3c621009e4f0e5342aa4e2ede1ceaa]

David Matlack (1):
      kvm: x86: do not leak guest xcr0 into host interrupt handlers
         [fc5b7f3bf1e1414bd4e91db6918c85ace0c873a5]

Davidlohr Bueso (1):
      futex: Acknowledge a new waiter in counter before plist
         [fe1bce9e2107ba3a8faffe572483b6974201a0e6]

Dmitry Ivanov (1):
      nl80211: check netlink protocol in socket release notification
         [8f815cdde3e550e10c2736990d791f60c2ce43eb]

Dmitry V. Levin (1):
      parisc: fix a bug when syscall number of tracee is __NR_Linux_syscalls
         [f0b22d1bb2a37a665a969e95785c75a4f49d1499]

Dominik Dingel (2):
      mm: hugetlb: allow hugepages_supported to be architecture specific
         [2531c8cf56a640cd7d17057df8484e570716a450]
      s390/hugetlb: add hugepages_supported define
         [7f9be77555bb2e52de84e9dddf7b4eb20cc6e171]

Eric Dumazet (3):
      macvtap: segmented packet is consumed
         [be0bd3160165e42783d8215f426e41c07179c08a]
      net/mlx4_en: fix spurious timestamping callbacks
         [fc96256c906362e845d848d0f6a6354450059e81]
      net: bcmgenet: device stats are unsigned long
         [6517eb59b03965689e6bb16bb2d480096b3ef95d]

Eric W. Biederman (1):
      propogate_mnt: Handle the first propogated copy being a slave
         [5ec0811d30378ae104f250bfc9b3640242d81e3f]

Hans de Goede (1):
      USB: uas: Add a new NO_REPORT_LUNS quirk
         [1363074667a6b7d0507527742ccd7bbed5e3ceaa]

Heiko Carstens (1):
      s390/spinlock: avoid yield to non existent cpu
         [8497695243f70fd19ed6cf28b63584f1b608b5f9]

Herbert Xu (1):
      crypto: hash - Fix page length clamping in hash walk
         [13f4bb78cf6a312bbdec367ba3da044b09bf0e29]

Hugh Dickins (1):
      mm: migrate dirty page without clear_page_dirty_for_io etc
         [42cb14b110a5698ccf26ce59c4441722605a3743]

Ilya Dryomov (3):
      libceph: kfree() in put_osd() shouldn't depend on authorizer
         [b28ec2f37e6a2bbd0bdf74b39cb89c74e4ad17f3]
      libceph: make authorizer destruction independent of ceph_auth_client
         [6c1ea260f89709e0021d2c59f8fd2a104b5b1123]
      rbd: fix rbd map vs notify races
         [811c6688774613a78bfa020f64b570b73f6974c8]

Imre Deak (1):
      drm/i915: Fix system resume if PCI device remained enabled
         [44410cd0bfb26bde9288da34c190cc9267d42a20]

Jack Pham (1):
      regmap: spmi: Fix regmap_spmi_ext_read in multi-byte case
         [dec8e8f6e6504aa3496c0f7cc10c756bb0e10f44]

Jan Beulich (1):
      x86/mm/xen: Suppress hugetlbfs in PV guests
         [103f6112f253017d7062cd74d17f4a514ed4485c]

Jasem Mutlaq (1):
      USB: serial: cp210x: add Straizona Focusers device ids
         [613ac23a46e10d4d4339febdd534fafadd68e059]

Jason Gunthorpe (1):
      IB/security: Restrict use of the write() interface
         [e6bd18f57aad1a2d1ef40e646d03ed0f2515c9e3]

Javier Martinez Canillas (1):
      i2c: exynos5: Fix possible ABBA deadlock by keeping I2C clock prepared
         [10ff4c5239a137abfc896ec73ef3d15a0f86a16a]

Jerome Marchand (1):
      assoc_array: don't call compare_object() on a node
         [8d4a2ec1e0b41b0cf9a0c5cd4511da7f8e4f3de2]

Joe Perches (1):
      compiler-gcc: integrate the various compiler-gcc[345].h files
         [cb984d101b30eb7478d32df56a0023e4603cba7f]

John Keeping (1):
      drm/qxl: fix cursor position with non-zero hotspot
         [d59a1f71ff1aeda4b4630df92d3ad4e3b1dfc885]

Jon Hunter (1):
      ARM: OMAP2+: Only write the sysconfig on idle when necessary
         [127500ccb766f0e963436e25ddd57be8f1695498]

Junxiao Bi (1):
      ocfs2: fix posix_acl_create deadlock
         [c25a1e0671fbca7b2c0d0757d533bd2650d6dc0c]

K. Y. Srinivasan (1):
      Drivers: hv: vmbus: Fix signaling logic in hv_need_to_signal_on_read()
         [1db488d12894f1936360779d6ab2aede3dd7f06a]

Kaho Ng (1):
      ALSA: hda - Fix white noise on Asus UX501VW headset
         [2da2dc9ead232f25601404335cca13c0f722d41b]

Kailang Yang (1):
      ALSA: usb-audio: Skip volume controls triggers hangup on Dell USB Dock
         [adcdd0d5a1cb779f6d455ae70882c19c527627a8]

Kangjie Lu (3):
      net: fix a kernel infoleak in x25 module
         [79e48650320e6fba48369fccf13fd045315b19b8]
      net: fix infoleak in llc
         [b8670c09f37bdf2847cc44f36511a53afc6161fd]
      net: fix infoleak in rtnetlink
         [5f8e44741f9f216e33736ea4ec65ca9ac03036e6]

Keerthy (1):
      pinctrl: single: Fix pcs_parse_bits_in_pinctrl_entry to use __ffs than ffs
         [56b367c0cd67d4c3006738e7dc9dda9273fd2bfe]

Konstantin Khlebnikov (3):
      mm/balloon_compaction: fix deflation when compaction is disabled
         [4d88e6f7d5ffc84e6094a47925870f4a130555c2]
      mm/balloon_compaction: redesign ballooned pages management
         [d6d86c0a7f8ddc5b38cf089222cb1d9540762dc2]
      mm/huge_memory: replace VM_NO_THP VM_BUG_ON with actual VMA check
         [3486b85a29c1741db99d0c522211c82d2b7a56d0]

Krzysztof Kozlowski (2):
      iio: ak8975: Fix NULL pointer exception on early interrupt
         [07d2390e36ee5b3265e9cc8305f2a106c8721e16]
      regulator: s2mps11: Fix invalid selector mask and voltages for buck9
         [3b672623079bb3e5685b8549e514f2dfaa564406]

Laszlo Ersek (1):
      efi: Fix out-of-bounds read in variable_matches()
         [630ba0cc7a6dbafbdee43795617c872b35cde1b4]

Linus Lüssing (1):
      batman-adv: Fix broadcast/ogm queue limit on a removed interface
         [c4fdb6cff2aa0ae740c5f19b6f745cbbe786d42f]

Linus Torvalds (3):
      Make hash_64() use a 64-bit multiply when appropriate
         [23d0db76ffa13ffb95229946e4648568c3c29db5]
      Minimal fix-up of bad hashing behavior of hash_64()
         [689de1d6ca95b3b5bd8ee446863bf81a4883ea25]
      nf_conntrack: avoid kernel pointer value leak in slab name
         [31b0b385f69d8d5491a4bca288e25e63f1d945d0]

Lokesh Vutla (1):
      ARM: OMAP2+: hwmod: Fix updating of sysconfig register
         [3ca4a238106dedc285193ee47f494a6584b6fd2f]

Lorenzo Pieralisi (1):
      arm64: kernel: fix architected PMU registers unconditional access
         [f436b2ac90a095746beb6729b8ee8ed87c9eaede]

Lu Baolu (1):
      usb: xhci: fix wild pointers in xhci_mem_cleanup
         [71504062a7c34838c3fccd92c447f399d3cb5797]

Lucas Stach (1):
      drm/radeon: fix PLL sharing on DCE6.1 (v2)
         [e3c00d87845ab375f90fa6e10a5e72a3a5778cd3]

Mathias Krause (2):
      packet: fix heap info leak in PACKET_DIAG_MCLIST sock_diag interface
         [309cf37fe2a781279b7675d4bb7173198e532867]
      proc: prevent accessing /proc/<PID>/environ until it's ready
         [8148a73c9901a8794a50f950083c00ccf97d43b3]

Matt Fleming (1):
      MAINTAINERS: Remove asterisk from EFI directory names
         [e8dfe6d8f6762d515fcd4f30577f7bfcf7659887]

Maxim Patlasov (1):
      fs/pnode.c: treat zero mnt_group_id-s as unequal
         [7ae8fd0351f912b075149a1e03a017be8b903b9a]

Mike Manning (1):
      USB: serial: cp210x: add ID for Link ECU
         [1d377f4d690637a0121eac8701f84a0aa1e69a69]

Neil Armstrong (2):
      net: ethernet: davinci_emac: Fix Unbalanced pm_runtime_enable
         [99164f9e62a391b5f4b7923b624d182b5d2859e0]
      net: ethernet: davinci_emac: Fix platform_data overwrite
         [210990b05a1247886539078e857cd038881bb2d6]

Peter Zijlstra (6):
      sched, dl: Convert switched_{from,  to}_dl() / prio_changed_dl() to balance callbacks
         [9916e214998a4a363b152b637245e5c958067350]
      sched, rt: Convert switched_{from, to}_rt() / prio_changed_rt() to balance callbacks
         [9916e214998a4a363b152b637245e5c958067350]
      sched,dl: Remove return value from  pull_dl_task()
         [0ea60c2054fc3b0c3eb68ac4f6884f3ee78d9925]
      sched,rt: Remove return value from pull_rt_task()
         [8046d6806247088de5725eaf8a2580b29e50ac5a]
      sched: Allow balance callbacks for  check_class_changed()
         [4c9a4bc89a9cca8128bce67d6bc8870d6b7ee0b2]
      sched: Replace post_schedule with a balance callback list
         [e3fca9e7cbfb72694a21c886fcdf9f059cfded9c]

Prarit Bhargava (1):
      ACPICA: Dispatcher: Update thread ID for recursive method calls
         [93d68841a23a5779cef6fb9aa0ef32e7c5bd00da]

Rafal Redzimski (1):
      usb: xhci: applying XHCI_PME_STUCK_QUIRK to Intel BXT B0 host
         [0d46faca6f887a849efb07c1655b5a9f7c288b45]

Robert Dobrowolski (1):
      usb: hcd: out of bounds access in for_each_companion
         [e86103a75705c7c530768f4ffaba74cf382910f2]

Roman Pen (1):
      workqueue: fix ghost PENDING flag while doing MQ IO
         [346c09f80459a3ad97df1816d6d606169a51001a]

Rui Salvaterra (1):
      lib: lz4: fixed zram with lz4 on big endian machines
         [3e26a691fe3fe1e02a76e5bab0c143ace4b137b4]

Sascha Hauer (1):
      ARM: SoCFPGA: Fix secondary CPU startup in thumb2 kernel
         [5616f36713ea77f57ae908bf2fef641364403c9f]

Sebastian Ott (1):
      s390/scm_blk: fix deadlock for requests != REQ_TYPE_FS
         [b707c65ae70e24c47a0ce4a7279224ce8f0ffb7f]

Srinivas Kandagatla (1):
      libahci: save port map for forced port map
         [2fd0f46cb1b82587c7ae4a616d69057fb9bd0af7]

Stephen Boyd (1):
      Input: pmic8xxx-pwrkey - fix algorithm for converting trigger delay
         [eda5ecc0a6b865561997e177c393f0b0136fe3b7]

Steven Rostedt (1):
      tools lib traceevent: Do not reassign parg after collapse_tree()
         [106b816cb46ebd87408b4ed99a2e16203114daa6]

Sugar Zhang (1):
      ASoC: rt5640: Correct the digital interface data select
         [653aa4645244042826f105aab1be3d01b3d493ca]

Sven Eckelmann (4):
      batman-adv: Check skb size before using encapsulated ETH+VLAN header
         [c78296665c3d81f040117432ab9e1cb125521b0c]
      batman-adv: Fix invalid stack access in batadv_dat_select_candidates
         [b7fe3d4f4a65bc675e737d88071300ea9c4bcddd]
      batman-adv: Fix reference counting of vlan object for tt_local_entry
         [a33d970d0b54b09746d5540af8271fad4eb10229]
      batman-adv: Reduce refcnt of removed router when updating route
         [d1a65f1741bfd9c69f9e4e2ad447a89b6810427d]

Tom Lendacky (1):
      crypto: ccp - Prevent information leakage on export
         [f709b45ec461b548c41a00044dba1f1b572783bf]

Tony Luck (1):
      EDAC: i7core, sb_edac: Don't return NOTIFY_BAD from mce_decoder callback
         [c4fc1956fa31003bfbe4f597e359d751568e2954]

Vineet Gupta (1):
      ARC: unbork !LLSC build
         [daaf40e53b5dbdf75255d58a45ce8ac65ca511a8]

Vladis Dronov (1):
      Input: gtco - fix crash on detecting device without endpoints
         [162f98dea487206d9ab79fc12ed64700667a894d]

Wang YanQing (1):
      x86/sysfb_efi: Fix valid BAR address range check
         [c10fcb14c7afd6688c7b197a814358fecf244222]

Will Deacon (1):
      arm64: psci: move psci firmware calls out of line
         [f5e0a12ca2d939e47995f73428d9bf1ad372b289]

Yura Pakhuchiy (1):
      ALSA: hda - Fix subwoofer pin on ASUS N751 and N551
         [3231e2053eaeee70bdfb216a78a30f11e88e2243]

 Documentation/kernel-parameters.txt            |   2 +
 MAINTAINERS                                    |   4 +-
 Makefile                                       |   4 +-
 arch/arc/include/asm/atomic.h                  |   2 +-
 arch/arm/mach-omap2/omap_hwmod.c               |  12 ++-
 arch/arm/mach-socfpga/headsmp.S                |   1 +
 arch/arm64/kernel/Makefile                     |   3 +-
 arch/arm64/kernel/head.S                       |   5 +
 arch/arm64/kernel/psci.c                       |  37 +------
 arch/arm64/mm/proc-macros.S                    |  12 +++
 arch/arm64/mm/proc.S                           |   4 +-
 arch/parisc/kernel/syscall.S                   |   2 +-
 arch/powerpc/include/asm/word-at-a-time.h      |   2 +-
 arch/powerpc/include/uapi/asm/cputable.h       |   1 +
 arch/powerpc/kernel/prom.c                     |   2 +-
 arch/s390/include/asm/hugetlb.h                |   1 +
 arch/s390/lib/spinlock.c                       |   1 +
 arch/x86/include/asm/hugetlb.h                 |   1 +
 arch/x86/kernel/sysfb_efi.c                    |  14 ++-
 arch/x86/kernel/tsc_msr.c                      |   2 +-
 arch/x86/kvm/x86.c                             |  10 +-
 crypto/ahash.c                                 |   3 +-
 drivers/acpi/acpica/dsmethod.c                 |   3 +
 drivers/ata/libahci.c                          |   1 +
 drivers/base/regmap/regmap-spmi.c              |   2 +-
 drivers/block/rbd.c                            |  43 ++++-----
 drivers/crypto/ccp/ccp-crypto-aes-cmac.c       |   3 +
 drivers/crypto/ccp/ccp-crypto-sha.c            |   3 +
 drivers/edac/i7core_edac.c                     |   2 +-
 drivers/edac/sb_edac.c                         |   2 +-
 drivers/firmware/efi/vars.c                    |  37 ++++---
 drivers/gpu/drm/i915/i915_drv.c                |  32 +++++++
 drivers/gpu/drm/i915/i915_gem_userptr.c        |  29 +++---
 drivers/gpu/drm/i915/i915_irq.c                |   4 +-
 drivers/gpu/drm/i915/intel_crt.c               |   8 +-
 drivers/gpu/drm/qxl/qxl_display.c              |  13 ++-
 drivers/gpu/drm/qxl/qxl_drv.h                  |   2 +
 drivers/gpu/drm/radeon/atombios_crtc.c         |  10 ++
 drivers/gpu/drm/radeon/atombios_encoders.c     |   4 +
 drivers/gpu/drm/radeon/si_dpm.c                |   1 +
 drivers/hid/usbhid/hid-core.c                  |  73 +++++++-------
 drivers/hv/ring_buffer.c                       |  34 ++++---
 drivers/i2c/busses/i2c-exynos5.c               |  24 ++++-
 drivers/iio/magnetometer/ak8975.c              |   4 +-
 drivers/infiniband/core/ucm.c                  |   4 +
 drivers/infiniband/core/ucma.c                 |   3 +
 drivers/infiniband/core/uverbs_main.c          |   5 +
 drivers/infiniband/hw/ipath/ipath_file_ops.c   |   5 +
 drivers/infiniband/hw/qib/qib_file_ops.c       |   5 +
 drivers/input/misc/pmic8xxx-pwrkey.c           |   7 +-
 drivers/input/tablet/gtco.c                    |  10 +-
 drivers/net/ethernet/atheros/atlx/atl2.c       |   2 +-
 drivers/net/ethernet/broadcom/genet/bcmgenet.c |   6 +-
 drivers/net/ethernet/mellanox/mlx4/en_tx.c     |   6 +-
 drivers/net/ethernet/ti/davinci_emac.c         |   3 +-
 drivers/net/macvtap.c                          |   2 +-
 drivers/pinctrl/pinctrl-single.c               |   6 +-
 drivers/regulator/s2mps11.c                    |   4 +-
 drivers/s390/block/scm_blk.c                   |   2 +-
 drivers/spi/spi-ti-qspi.c                      |  45 +++++----
 drivers/usb/core/hcd-pci.c                     |   9 ++
 drivers/usb/host/xhci-mem.c                    |   6 ++
 drivers/usb/host/xhci-pci.c                    |   4 +-
 drivers/usb/serial/cp210x.c                    |   4 +
 drivers/usb/storage/uas.c                      |  14 ++-
 drivers/usb/storage/unusual_uas.h              |   7 ++
 drivers/usb/storage/usb.c                      |   5 +-
 drivers/virtio/virtio_balloon.c                |  15 ++-
 fs/ceph/mds_client.c                           |   6 +-
 fs/isofs/rock.c                                |  13 ++-
 fs/namei.c                                     |  20 +---
 fs/ocfs2/acl.c                                 |  63 ++++++++++++
 fs/ocfs2/acl.h                                 |   4 +
 fs/ocfs2/namei.c                               |  23 +----
 fs/ocfs2/refcounttree.c                        |  17 +---
 fs/ocfs2/xattr.c                               |  14 +--
 fs/ocfs2/xattr.h                               |   4 +-
 fs/pnode.c                                     |  32 ++++---
 fs/proc/base.c                                 |   3 +-
 fs/xfs/xfs_bmap_util.c                         |  53 +++++-----
 fs/xfs/xfs_file.c                              |  76 +++++++++++----
 fs/xfs/xfs_inode.c                             | 128 +++++++++++++++++++------
 fs/xfs/xfs_inode.h                             |  29 ++++--
 fs/xfs/xfs_ioctl.c                             |   4 +-
 fs/xfs/xfs_iops.c                              |  31 +++---
 fs/xfs/xfs_super.c                             |   2 +
 fs/xfs/xfs_trace.h                             |   3 +
 include/linux/balloon_compaction.h             |  97 +++++--------------
 include/linux/ceph/auth.h                      |  10 +-
 include/linux/ceph/osd_client.h                |   1 -
 include/linux/compiler-gcc.h                   | 120 ++++++++++++++++++++++-
 include/linux/compiler-gcc3.h                  |  23 -----
 include/linux/compiler-gcc4.h                  |  88 -----------------
 include/linux/compiler-gcc5.h                  |  66 -------------
 include/linux/hash.h                           |  20 ++++
 include/linux/hugetlb.h                        |  17 ++--
 include/linux/mfd/samsung/s2mps11.h            |   2 +
 include/linux/migrate.h                        |  11 +--
 include/linux/mm.h                             |  19 ++++
 include/linux/netdevice.h                      |  21 +---
 include/linux/usb_usual.h                      |   2 +
 include/rdma/ib.h                              |  16 ++++
 kernel/futex.c                                 |   2 +-
 kernel/sched/core.c                            |  60 +++++++++---
 kernel/sched/deadline.c                        |  68 +++++++------
 kernel/sched/rt.c                              |  74 +++++++-------
 kernel/sched/sched.h                           |  19 +++-
 kernel/trace/trace_events.c                    |   9 +-
 kernel/workqueue.c                             |  29 ++++++
 lib/asn1_decoder.c                             |  16 ++--
 lib/assoc_array.c                              |   4 +-
 lib/lz4/lz4defs.h                              |  21 ++--
 mm/balloon_compaction.c                        |  28 +++---
 mm/compaction.c                                |   2 +-
 mm/huge_memory.c                               |   6 +-
 mm/migrate.c                                   |  70 +++++++-------
 net/ax25/ax25_ip.c                             |  15 ---
 net/batman-adv/distributed-arp-table.c         |  20 ++--
 net/batman-adv/routing.c                       |   9 ++
 net/batman-adv/send.c                          |   6 ++
 net/batman-adv/soft-interface.c                |   8 +-
 net/batman-adv/translation-table.c             |  44 +--------
 net/batman-adv/types.h                         |   2 +
 net/ceph/auth.c                                |   8 +-
 net/ceph/auth_none.c                           |  71 +++++++-------
 net/ceph/auth_none.h                           |   3 +-
 net/ceph/auth_x.c                              |  21 ++--
 net/ceph/auth_x.h                              |   1 +
 net/ceph/osd_client.c                          |   9 +-
 net/core/rtnetlink.c                           |  18 ++--
 net/llc/af_llc.c                               |   1 +
 net/netfilter/nf_conntrack_core.c              |   4 +-
 net/packet/af_packet.c                         |   1 +
 net/wireless/nl80211.c                         |   2 +-
 net/x25/x25_facilities.c                       |   1 +
 sound/pci/hda/patch_realtek.c                  |  14 +++
 sound/soc/codecs/rt5640.c                      |   2 +-
 sound/soc/codecs/rt5640.h                      |  36 +++----
 sound/usb/mixer_maps.c                         |  14 +++
 tools/lib/traceevent/parse-filter.c            |   4 +-
 140 files changed, 1391 insertions(+), 1007 deletions(-)

-- 
Ben Hutchings
One of the nice things about standards is that there are so many of them.

[toc] | [next] | [standalone]


#1421230 — [PATCH 3.16 014/114] kvm: x86: do not leak guest xcr0 into host interrupt handlers

FromBen Hutchings <ben@decadent.org.uk>
Date2016-06-13 21:20 +0200
Subject[PATCH 3.16 014/114] kvm: x86: do not leak guest xcr0 into host interrupt handlers
Message-ID<rJFyX-26n-59@gated-at.bofh.it>
In reply to#1421229
3.16.36-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: David Matlack <dmatlack@google.com>

commit fc5b7f3bf1e1414bd4e91db6918c85ace0c873a5 upstream.

An interrupt handler that uses the fpu can kill a KVM VM, if it runs
under the following conditions:
 - the guest's xcr0 register is loaded on the cpu
 - the guest's fpu context is not loaded
 - the host is using eagerfpu

Note that the guest's xcr0 register and fpu context are not loaded as
part of the atomic world switch into "guest mode". They are loaded by
KVM while the cpu is still in "host mode".

Usage of the fpu in interrupt context is gated by irq_fpu_usable(). The
interrupt handler will look something like this:

if (irq_fpu_usable()) {
        kernel_fpu_begin();

        [... code that uses the fpu ...]

        kernel_fpu_end();
}

As long as the guest's fpu is not loaded and the host is using eager
fpu, irq_fpu_usable() returns true (interrupted_kernel_fpu_idle()
returns true). The interrupt handler proceeds to use the fpu with
the guest's xcr0 live.

kernel_fpu_begin() saves the current fpu context. If this uses
XSAVE[OPT], it may leave the xsave area in an undesirable state.
According to the SDM, during XSAVE bit i of XSTATE_BV is not modified
if bit i is 0 in xcr0. So it's possible that XSTATE_BV[i] == 1 and
xcr0[i] == 0 following an XSAVE.

kernel_fpu_end() restores the fpu context. Now if any bit i in
XSTATE_BV == 1 while xcr0[i] == 0, XRSTOR generates a #GP. The
fault is trapped and SIGSEGV is delivered to the current process.

Only pre-4.2 kernels appear to be vulnerable to this sequence of
events. Commit 653f52c ("kvm,x86: load guest FPU context more eagerly")
from 4.2 forces the guest's fpu to always be loaded on eagerfpu hosts.

This patch fixes the bug by keeping the host's xcr0 loaded outside
of the interrupts-disabled region where KVM switches into guest mode.

Suggested-by: Andy Lutomirski <luto@amacapital.net>
Signed-off-by: David Matlack <dmatlack@google.com>
[Move load after goto cancel_injection. - Paolo]
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
[bwh: Backported to 3.16: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 arch/x86/kvm/x86.c | 10 ++++------
 1 file changed, 4 insertions(+), 6 deletions(-)

--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -626,7 +626,6 @@ int __kvm_set_xcr(struct kvm_vcpu *vcpu,
 	if ((!(xcr0 & XSTATE_BNDREGS)) != (!(xcr0 & XSTATE_BNDCSR)))
 		return 1;
 
-	kvm_put_guest_xcr0(vcpu);
 	vcpu->arch.xcr0 = xcr0;
 
 	if ((xcr0 ^ old_xcr0) & XSTATE_EXTEND_MASK)
@@ -6072,8 +6071,6 @@ static int vcpu_enter_guest(struct kvm_v
 	kvm_x86_ops->prepare_guest_switch(vcpu);
 	if (vcpu->fpu_active)
 		kvm_load_guest_fpu(vcpu);
-	kvm_load_guest_xcr0(vcpu);
-
 	vcpu->mode = IN_GUEST_MODE;
 
 	srcu_read_unlock(&vcpu->kvm->srcu, vcpu->srcu_idx);
@@ -6096,6 +6093,8 @@ static int vcpu_enter_guest(struct kvm_v
 		goto cancel_injection;
 	}
 
+	kvm_load_guest_xcr0(vcpu);
+
 	if (req_immediate_exit)
 		smp_send_reschedule(vcpu->cpu);
 
@@ -6144,6 +6143,8 @@ static int vcpu_enter_guest(struct kvm_v
 	vcpu->mode = OUTSIDE_GUEST_MODE;
 	smp_wmb();
 
+	kvm_put_guest_xcr0(vcpu);
+
 	/* Interrupt is enabled by handle_external_intr() */
 	kvm_x86_ops->handle_external_intr(vcpu);
 
@@ -6782,7 +6783,6 @@ void kvm_load_guest_fpu(struct kvm_vcpu
 	 * and assume host would use all available bits.
 	 * Guest xcr0 would be loaded later.
 	 */
-	kvm_put_guest_xcr0(vcpu);
 	vcpu->guest_fpu_loaded = 1;
 	__kernel_fpu_begin();
 	fpu_restore_checking(&vcpu->arch.guest_fpu);
@@ -6791,8 +6791,6 @@ void kvm_load_guest_fpu(struct kvm_vcpu
 
 void kvm_put_guest_fpu(struct kvm_vcpu *vcpu)
 {
-	kvm_put_guest_xcr0(vcpu);
-
 	if (!vcpu->guest_fpu_loaded)
 		return;
 

[toc] | [prev] | [next] | [standalone]


#1421231 — [PATCH 3.16 045/114] batman-adv: Reduce refcnt of removed router when updating route

FromBen Hutchings <ben@decadent.org.uk>
Date2016-06-13 21:20 +0200
Subject[PATCH 3.16 045/114] batman-adv: Reduce refcnt of removed router when updating route
Message-ID<rJFyW-26n-47@gated-at.bofh.it>
In reply to#1421229
3.16.36-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Sven Eckelmann <sven@narfation.org>

commit d1a65f1741bfd9c69f9e4e2ad447a89b6810427d upstream.

_batadv_update_route rcu_derefences orig_ifinfo->router outside of a
spinlock protected region to print some information messages to the debug
log. But this pointer is not checked again when the new pointer is assigned
in the spinlock protected region. Thus is can happen that the value of
orig_ifinfo->router changed in the meantime and thus the reference counter
of the wrong router gets reduced after the spinlock protected region.

Just rcu_dereferencing the value of orig_ifinfo->router inside the spinlock
protected region (which also set the new pointer) is enough to get the
correct old router object.

Fixes: e1a5382f978b ("batman-adv: Make orig_node->router an rcu protected pointer")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Marek Lindner <mareklindner@neomailbox.ch>
Signed-off-by: Antonio Quartulli <a@unstable.cc>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 net/batman-adv/routing.c | 9 +++++++++
 1 file changed, 9 insertions(+)

--- a/net/batman-adv/routing.c
+++ b/net/batman-adv/routing.c
@@ -88,6 +88,15 @@ static void _batadv_update_route(struct
 		neigh_node = NULL;
 
 	spin_lock_bh(&orig_node->neigh_list_lock);
+	/* curr_router used earlier may not be the current orig_ifinfo->router
+	 * anymore because it was dereferenced outside of the neigh_list_lock
+	 * protected region. After the new best neighbor has replace the current
+	 * best neighbor the reference counter needs to decrease. Consequently,
+	 * the code needs to ensure the curr_router variable contains a pointer
+	 * to the replaced best neighbor.
+	 */
+	curr_router = rcu_dereference_protected(orig_ifinfo->router, true);
+
 	rcu_assign_pointer(orig_ifinfo->router, neigh_node);
 	spin_unlock_bh(&orig_node->neigh_list_lock);
 	batadv_orig_ifinfo_free_ref(orig_ifinfo);

[toc] | [prev] | [next] | [standalone]


#1421232 — [PATCH 3.16 040/114] s390/hugetlb: add hugepages_supported define

FromBen Hutchings <ben@decadent.org.uk>
Date2016-06-13 21:20 +0200
Subject[PATCH 3.16 040/114] s390/hugetlb: add hugepages_supported define
Message-ID<rJFyW-26n-49@gated-at.bofh.it>
In reply to#1421229
3.16.36-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Dominik Dingel <dingel@linux.vnet.ibm.com>

commit 7f9be77555bb2e52de84e9dddf7b4eb20cc6e171 upstream.

On s390 we only can enable hugepages if the underlying hardware/hypervisor
also does support this.  Common code now would assume this to be
signaled by setting HPAGE_SHIFT to 0.  But on s390, where we only
support one hugepage size, there is a link between HPAGE_SHIFT and
pageblock_order.

So instead of setting HPAGE_SHIFT to 0, we will implement the check for
the hardware capability.

Signed-off-by: Dominik Dingel <dingel@linux.vnet.ibm.com>
Acked-by: Martin Schwidefsky <schwidefsky@de.ibm.com>
Cc: Heiko Carstens <heiko.carstens@de.ibm.com>
Cc: Christian Borntraeger <borntraeger@de.ibm.com>
Cc: Michael Holzheu <holzheu@linux.vnet.ibm.com>
Cc: Gerald Schaefer <gerald.schaefer@de.ibm.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 arch/s390/include/asm/hugetlb.h | 1 +
 1 file changed, 1 insertion(+)

--- a/arch/s390/include/asm/hugetlb.h
+++ b/arch/s390/include/asm/hugetlb.h
@@ -14,6 +14,7 @@
 
 #define is_hugepage_only_range(mm, addr, len)	0
 #define hugetlb_free_pgd_range			free_pgd_range
+#define hugepages_supported()			(MACHINE_HAS_HPAGE)
 
 void set_huge_pte_at(struct mm_struct *mm, unsigned long addr,
 		     pte_t *ptep, pte_t pte);

[toc] | [prev] | [next] | [standalone]


#1421234 — [PATCH 3.16 013/114] assoc_array: don't call compare_object() on a node

FromBen Hutchings <ben@decadent.org.uk>
Date2016-06-13 21:20 +0200
Subject[PATCH 3.16 013/114] assoc_array: don't call compare_object() on a node
Message-ID<rJFyW-26n-53@gated-at.bofh.it>
In reply to#1421229
3.16.36-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Jerome Marchand <jmarchan@redhat.com>

commit 8d4a2ec1e0b41b0cf9a0c5cd4511da7f8e4f3de2 upstream.

Changes since V1: fixed the description and added KASan warning.

In assoc_array_insert_into_terminal_node(), we call the
compare_object() method on all non-empty slots, even when they're
not leaves, passing a pointer to an unexpected structure to
compare_object(). Currently it causes an out-of-bound read access
in keyring_compare_object detected by KASan (see below). The issue
is easily reproduced with keyutils testsuite.
Only call compare_object() when the slot is a leave.

KASan warning:
==================================================================
BUG: KASAN: slab-out-of-bounds in keyring_compare_object+0x213/0x240 at addr ffff880060a6f838
Read of size 8 by task keyctl/1655
=============================================================================
BUG kmalloc-192 (Not tainted): kasan: bad access detected
-----------------------------------------------------------------------------

Disabling lock debugging due to kernel taint
INFO: Allocated in assoc_array_insert+0xfd0/0x3a60 age=69 cpu=1 pid=1647
	___slab_alloc+0x563/0x5c0
	__slab_alloc+0x51/0x90
	kmem_cache_alloc_trace+0x263/0x300
	assoc_array_insert+0xfd0/0x3a60
	__key_link_begin+0xfc/0x270
	key_create_or_update+0x459/0xaf0
	SyS_add_key+0x1ba/0x350
	entry_SYSCALL_64_fastpath+0x12/0x76
INFO: Slab 0xffffea0001829b80 objects=16 used=8 fp=0xffff880060a6f550 flags=0x3fff8000004080
INFO: Object 0xffff880060a6f740 @offset=5952 fp=0xffff880060a6e5d1

Bytes b4 ffff880060a6f730: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
Object ffff880060a6f740: d1 e5 a6 60 00 88 ff ff 0e 00 00 00 00 00 00 00  ...`............
Object ffff880060a6f750: 02 cf 8e 60 00 88 ff ff 02 c0 8e 60 00 88 ff ff  ...`.......`....
Object ffff880060a6f760: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
Object ffff880060a6f770: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
Object ffff880060a6f780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
Object ffff880060a6f790: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
Object ffff880060a6f7a0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
Object ffff880060a6f7b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
Object ffff880060a6f7c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
Object ffff880060a6f7d0: 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
Object ffff880060a6f7e0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
Object ffff880060a6f7f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
CPU: 0 PID: 1655 Comm: keyctl Tainted: G    B           4.5.0-rc4-kasan+ #291
Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
 0000000000000000 000000001b2800b4 ffff880060a179e0 ffffffff81b60491
 ffff88006c802900 ffff880060a6f740 ffff880060a17a10 ffffffff815e2969
 ffff88006c802900 ffffea0001829b80 ffff880060a6f740 ffff880060a6e650
Call Trace:
 [<ffffffff81b60491>] dump_stack+0x85/0xc4
 [<ffffffff815e2969>] print_trailer+0xf9/0x150
 [<ffffffff815e9454>] object_err+0x34/0x40
 [<ffffffff815ebe50>] kasan_report_error+0x230/0x550
 [<ffffffff819949be>] ? keyring_get_key_chunk+0x13e/0x210
 [<ffffffff815ec62d>] __asan_report_load_n_noabort+0x5d/0x70
 [<ffffffff81994cc3>] ? keyring_compare_object+0x213/0x240
 [<ffffffff81994cc3>] keyring_compare_object+0x213/0x240
 [<ffffffff81bc238c>] assoc_array_insert+0x86c/0x3a60
 [<ffffffff81bc1b20>] ? assoc_array_cancel_edit+0x70/0x70
 [<ffffffff8199797d>] ? __key_link_begin+0x20d/0x270
 [<ffffffff8199786c>] __key_link_begin+0xfc/0x270
 [<ffffffff81993389>] key_create_or_update+0x459/0xaf0
 [<ffffffff8128ce0d>] ? trace_hardirqs_on+0xd/0x10
 [<ffffffff81992f30>] ? key_type_lookup+0xc0/0xc0
 [<ffffffff8199e19d>] ? lookup_user_key+0x13d/0xcd0
 [<ffffffff81534763>] ? memdup_user+0x53/0x80
 [<ffffffff819983ea>] SyS_add_key+0x1ba/0x350
 [<ffffffff81998230>] ? key_get_type_from_user.constprop.6+0xa0/0xa0
 [<ffffffff828bcf4e>] ? retint_user+0x18/0x23
 [<ffffffff8128cc7e>] ? trace_hardirqs_on_caller+0x3fe/0x580
 [<ffffffff81004017>] ? trace_hardirqs_on_thunk+0x17/0x19
 [<ffffffff828bc432>] entry_SYSCALL_64_fastpath+0x12/0x76
Memory state around the buggy address:
 ffff880060a6f700: fc fc fc fc fc fc fc fc 00 00 00 00 00 00 00 00
 ffff880060a6f780: 00 00 00 00 00 00 00 00 00 00 00 fc fc fc fc fc
>ffff880060a6f800: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
                                        ^
 ffff880060a6f880: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
 ffff880060a6f900: fc fc fc fc fc fc 00 00 00 00 00 00 00 00 00 00
==================================================================

Signed-off-by: Jerome Marchand <jmarchan@redhat.com>
Signed-off-by: David Howells <dhowells@redhat.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 lib/assoc_array.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/lib/assoc_array.c
+++ b/lib/assoc_array.c
@@ -523,7 +523,9 @@ static bool assoc_array_insert_into_term
 			free_slot = i;
 			continue;
 		}
-		if (ops->compare_object(assoc_array_ptr_to_leaf(ptr), index_key)) {
+		if (assoc_array_ptr_is_leaf(ptr) &&
+		    ops->compare_object(assoc_array_ptr_to_leaf(ptr),
+					index_key)) {
 			pr_devel("replace in slot %d\n", i);
 			edit->leaf_p = &node->slots[i];
 			edit->dead_leaf = node->slots[i];

[toc] | [prev] | [next] | [standalone]


#1421235 — [PATCH 3.16 027/114] crypto: ccp - Prevent information leakage on export

FromBen Hutchings <ben@decadent.org.uk>
Date2016-06-13 21:20 +0200
Subject[PATCH 3.16 027/114] crypto: ccp - Prevent information leakage on export
Message-ID<rJFyW-26n-51@gated-at.bofh.it>
In reply to#1421229
3.16.36-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Tom Lendacky <thomas.lendacky@amd.com>

commit f709b45ec461b548c41a00044dba1f1b572783bf upstream.

Prevent information from leaking to userspace by doing a memset to 0 of
the export state structure before setting the structure values and copying
it. This prevents un-initialized padding areas from being copied into the
export area.

Reported-by: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: Tom Lendacky <thomas.lendacky@amd.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/crypto/ccp/ccp-crypto-aes-cmac.c | 3 +++
 drivers/crypto/ccp/ccp-crypto-sha.c      | 3 +++
 2 files changed, 6 insertions(+)

--- a/drivers/crypto/ccp/ccp-crypto-aes-cmac.c
+++ b/drivers/crypto/ccp/ccp-crypto-aes-cmac.c
@@ -206,6 +206,9 @@ static int ccp_aes_cmac_export(struct ah
 	struct ccp_aes_cmac_req_ctx *rctx = ahash_request_ctx(req);
 	struct ccp_aes_cmac_exp_ctx state;
 
+	/* Don't let anything leak to 'out' */
+	memset(&state, 0, sizeof(state));
+
 	state.null_msg = rctx->null_msg;
 	memcpy(state.iv, rctx->iv, sizeof(state.iv));
 	state.buf_count = rctx->buf_count;
--- a/drivers/crypto/ccp/ccp-crypto-sha.c
+++ b/drivers/crypto/ccp/ccp-crypto-sha.c
@@ -198,6 +198,9 @@ static int ccp_sha_export(struct ahash_r
 	struct ccp_sha_req_ctx *rctx = ahash_request_ctx(req);
 	struct ccp_sha_exp_ctx state;
 
+	/* Don't let anything leak to 'out' */
+	memset(&state, 0, sizeof(state));
+
 	state.type = rctx->type;
 	state.msg_bits = rctx->msg_bits;
 	state.first = rctx->first;

[toc] | [prev] | [next] | [standalone]


#1421236 — [PATCH 3.16 069/114] tracing: Don't display trigger file for events that can't be enabled

FromBen Hutchings <ben@decadent.org.uk>
Date2016-06-13 21:20 +0200
Subject[PATCH 3.16 069/114] tracing: Don't display trigger file for events that can't be enabled
Message-ID<rJFyW-26n-55@gated-at.bofh.it>
In reply to#1421229
3.16.36-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Chunyu Hu <chuhu@redhat.com>

commit 854145e0a8e9a05f7366d240e2f99d9c1ca6d6dd upstream.

Currently register functions for events will be called
through the 'reg' field of event class directly without
any check when seting up triggers.

Triggers for events that don't support register through
debug fs (events under events/ftrace are for trace-cmd to
read event format, and most of them don't have a register
function except events/ftrace/functionx) can't be enabled
at all, and an oops will be hit when setting up trigger
for those events, so just not creating them is an easy way
to avoid the oops.

Link: http://lkml.kernel.org/r/1462275274-3911-1-git-send-email-chuhu@redhat.com

Fixes: 85f2b08268c01 ("tracing: Add basic event trigger framework")
Signed-off-by: Chunyu Hu <chuhu@redhat.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 kernel/trace/trace_events.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

--- a/kernel/trace/trace_events.c
+++ b/kernel/trace/trace_events.c
@@ -1584,8 +1584,13 @@ event_create_dir(struct dentry *parent,
 	trace_create_file("filter", 0644, file->dir, file,
 			  &ftrace_event_filter_fops);
 
-	trace_create_file("trigger", 0644, file->dir, file,
-			  &event_trigger_fops);
+	/*
+	 * Only event directories that can be enabled should have
+	 * triggers.
+	 */
+	if (!(call->flags & TRACE_EVENT_FL_IGNORE_ENABLE))
+		trace_create_file("trigger", 0644, file->dir, file,
+				  &event_trigger_fops);
 
 	trace_create_file("format", 0444, file->dir, call,
 			  &ftrace_event_format_fops);

[toc] | [prev] | [next] | [standalone]


#1421238 — [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler() after one pass

FromBen Hutchings <ben@decadent.org.uk>
Date2016-06-13 21:20 +0200
Subject[PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler() after one pass
Message-ID<rJFyX-26n-63@gated-at.bofh.it>
In reply to#1421229
3.16.36-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Chris Wilson <chris@chris-wilson.co.uk>

commit 9dbaab56ac09f07a73fe83bf69bec3e31060080a upstream.

This effectively reverts

commit 8e5fd599eb219f1054e39b40d18b217af669eea9
Author: Ville Syrjälä <ville.syrjala@linux.intel.com>
Date:   Wed Apr 9 13:28:50 2014 +0300

    drm/i915/chv: Make CHV irq handler loop until all interrupts are consumed

as under continuous execlists load we can saturate the IRQ handler,
destablising the tsc clock and triggering the NMI watchdog to declare a hung
CPU.

[  552.756051] clocksource: timekeeping watchdog on CPU0: Marking clocksource 'tsc' as unstable because the skew is too large:
[  552.756080] clocksource:                       'refined-jiffies' wd_now: 10003b480 wd_last: 10003b28c mask: ffffffff
[  552.756091] clocksource:                       'tsc' cs_now: d55d31aa50 cs_last: d17446166c mask: ffffffffffffffff
[  552.756210] clocksource: Switched to clocksource refined-jiffies
[  575.217870] NMI watchdog: Watchdog detected hard LOCKUP on cpu 1
[  575.217893] CPU: 1 PID: 0 Comm: swapper/1 Not tainted 4.5.0-rc7+ #18
[  575.217905] Hardware name:                  /NUC5CPYB, BIOS PYBSWCEL.86A.0027.2015.0507.1758 05/07/2015
[  575.217915]  0000000000000000 ffff88027fd05bc0 ffffffff81288c6d 0000000000000000
[  575.217935]  0000000000000001 ffff88027fd05be0 ffffffff810e72d1 0000000000000000
[  575.217951]  ffff88027fd05c80 ffff88027fd05c20 ffffffff81114b60 0000000181015f1e
[  575.217967] Call Trace:
[  575.217973]  <NMI>  [<ffffffff81288c6d>] dump_stack+0x4f/0x72
[  575.217994]  [<ffffffff810e72d1>] watchdog_overflow_callback+0x151/0x160
[  575.218003]  [<ffffffff81114b60>] __perf_event_overflow+0xa0/0x1e0
[  575.218016]  [<ffffffff811154c4>] perf_event_overflow+0x14/0x20
[  575.218028]  [<ffffffff8101d2ca>] intel_pmu_handle_irq+0x1da/0x460
[  575.218042]  [<ffffffff814a8aae>] ? poll_idle+0x3e/0x70
[  575.218052]  [<ffffffff814a8aae>] ? poll_idle+0x3e/0x70
[  575.218064]  [<ffffffff81014ae8>] perf_event_nmi_handler+0x28/0x50
[  575.218075]  [<ffffffff81007540>] nmi_handle+0x60/0x130
[  575.218086]  [<ffffffff814a8aae>] ? poll_idle+0x3e/0x70
[  575.218096]  [<ffffffff810079c0>] do_nmi+0x140/0x470
[  575.218108]  [<ffffffff81559ec7>] end_repeat_nmi+0x1a/0x1e
[  575.218119]  [<ffffffff814a8aae>] ? poll_idle+0x3e/0x70
[  575.218129]  [<ffffffff814a8aae>] ? poll_idle+0x3e/0x70
[  575.218139]  [<ffffffff814a8aae>] ? poll_idle+0x3e/0x70
[  575.218148]  <<EOE>>  [<ffffffff814a8353>] cpuidle_enter_state+0xf3/0x2f0
[  575.218164]  [<ffffffff814a8587>] cpuidle_enter+0x17/0x20
[  575.218175]  [<ffffffff810aaa3a>] call_cpuidle+0x2a/0x40
[  575.218185]  [<ffffffff810aade3>] cpu_startup_entry+0x273/0x330
[  575.218196]  [<ffffffff81033a1e>] start_secondary+0x10e/0x130

However, not servicing all available IIR within the handler does hurt the
throughput of pathological nop execbuf by about 20%, with a similar effect
upon the dispatch latency of a series of execbuf.

v2: use do {} while(0) for a smaller patch, and easier to revert again

I have reasonable confidence that we do not miss GT interrupts (as
execlists provides a stress case with a failure mechanism easily
detected by igt), however I have less confidence about all the other
sources of interrupts and worry that may lose a display hotplug
interrupt, for example.

Bugzilla: https://bugs.freedesktop.org/show_bug.cgi?id=93467
Testcase: igt/gem_exec_nop/basic # requires NMI watchdog
Signed-off-by: Chris Wilson <chris@chris-wilson.co.uk>
Cc: Ville Syrjälä <ville.syrjala@linux.intel.com>
Cc: Antti Koskipää <antti.koskipaa@linux.intel.com>
Cc: Tvrtko Ursulin <tvrtko.ursulin@intel.com>
Reviewed-by: Tvrtko Ursulin <tvrtko.ursulin@intel.com>
Reviewed-by: Ville Syrjälä <ville.syrjala@linux.intel.com>
Link: http://patchwork.freedesktop.org/patch/msgid/1457946117-6714-1-git-send-email-chris@chris-wilson.co.uk
(cherry picked from commit 579de73b048a0a4c66c25a033ac76a2836e0cf73)
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/gpu/drm/i915/i915_irq.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/gpu/drm/i915/i915_irq.c
+++ b/drivers/gpu/drm/i915/i915_irq.c
@@ -1875,7 +1875,7 @@ static irqreturn_t cherryview_irq_handle
 	u32 master_ctl, iir;
 	irqreturn_t ret = IRQ_NONE;
 
-	for (;;) {
+	do {
 		master_ctl = I915_READ(GEN8_MASTER_IRQ) & ~GEN8_MASTER_IRQ_CONTROL;
 		iir = I915_READ(VLV_IIR);
 
@@ -1897,7 +1897,7 @@ static irqreturn_t cherryview_irq_handle
 		POSTING_READ(GEN8_MASTER_IRQ);
 
 		ret = IRQ_HANDLED;
-	}
+	} while (0);
 
 	return ret;
 }

[toc] | [prev] | [next] | [standalone]


#1421764 — Re: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler() after one pass

FromVille Syrjälä <ville.syrjala@linux.intel.com>
Date2016-06-14 12:50 +0200
SubjectRe: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler() after one pass
Message-ID<rJU4W-3FD-27@gated-at.bofh.it>
In reply to#1421238
On Mon, Jun 13, 2016 at 07:36:37PM +0100, Ben Hutchings wrote:
> 3.16.36-rc1 review patch.  If anyone has any objections, please let me know.

Do not backport this one. It'll break things.

> 
> ------------------
> 
> From: Chris Wilson <chris@chris-wilson.co.uk>
> 
> commit 9dbaab56ac09f07a73fe83bf69bec3e31060080a upstream.
> 
> This effectively reverts
> 
> commit 8e5fd599eb219f1054e39b40d18b217af669eea9
> Author: Ville Syrjälä <ville.syrjala@linux.intel.com>
> Date:   Wed Apr 9 13:28:50 2014 +0300
> 
>     drm/i915/chv: Make CHV irq handler loop until all interrupts are consumed
> 
> as under continuous execlists load we can saturate the IRQ handler,
> destablising the tsc clock and triggering the NMI watchdog to declare a hung
> CPU.
> 
> [  552.756051] clocksource: timekeeping watchdog on CPU0: Marking clocksource 'tsc' as unstable because the skew is too large:
> [  552.756080] clocksource:                       'refined-jiffies' wd_now: 10003b480 wd_last: 10003b28c mask: ffffffff
> [  552.756091] clocksource:                       'tsc' cs_now: d55d31aa50 cs_last: d17446166c mask: ffffffffffffffff
> [  552.756210] clocksource: Switched to clocksource refined-jiffies
> [  575.217870] NMI watchdog: Watchdog detected hard LOCKUP on cpu 1
> [  575.217893] CPU: 1 PID: 0 Comm: swapper/1 Not tainted 4.5.0-rc7+ #18
> [  575.217905] Hardware name:                  /NUC5CPYB, BIOS PYBSWCEL.86A.0027.2015.0507.1758 05/07/2015
> [  575.217915]  0000000000000000 ffff88027fd05bc0 ffffffff81288c6d 0000000000000000
> [  575.217935]  0000000000000001 ffff88027fd05be0 ffffffff810e72d1 0000000000000000
> [  575.217951]  ffff88027fd05c80 ffff88027fd05c20 ffffffff81114b60 0000000181015f1e
> [  575.217967] Call Trace:
> [  575.217973]  <NMI>  [<ffffffff81288c6d>] dump_stack+0x4f/0x72
> [  575.217994]  [<ffffffff810e72d1>] watchdog_overflow_callback+0x151/0x160
> [  575.218003]  [<ffffffff81114b60>] __perf_event_overflow+0xa0/0x1e0
> [  575.218016]  [<ffffffff811154c4>] perf_event_overflow+0x14/0x20
> [  575.218028]  [<ffffffff8101d2ca>] intel_pmu_handle_irq+0x1da/0x460
> [  575.218042]  [<ffffffff814a8aae>] ? poll_idle+0x3e/0x70
> [  575.218052]  [<ffffffff814a8aae>] ? poll_idle+0x3e/0x70
> [  575.218064]  [<ffffffff81014ae8>] perf_event_nmi_handler+0x28/0x50
> [  575.218075]  [<ffffffff81007540>] nmi_handle+0x60/0x130
> [  575.218086]  [<ffffffff814a8aae>] ? poll_idle+0x3e/0x70
> [  575.218096]  [<ffffffff810079c0>] do_nmi+0x140/0x470
> [  575.218108]  [<ffffffff81559ec7>] end_repeat_nmi+0x1a/0x1e
> [  575.218119]  [<ffffffff814a8aae>] ? poll_idle+0x3e/0x70
> [  575.218129]  [<ffffffff814a8aae>] ? poll_idle+0x3e/0x70
> [  575.218139]  [<ffffffff814a8aae>] ? poll_idle+0x3e/0x70
> [  575.218148]  <<EOE>>  [<ffffffff814a8353>] cpuidle_enter_state+0xf3/0x2f0
> [  575.218164]  [<ffffffff814a8587>] cpuidle_enter+0x17/0x20
> [  575.218175]  [<ffffffff810aaa3a>] call_cpuidle+0x2a/0x40
> [  575.218185]  [<ffffffff810aade3>] cpu_startup_entry+0x273/0x330
> [  575.218196]  [<ffffffff81033a1e>] start_secondary+0x10e/0x130
> 
> However, not servicing all available IIR within the handler does hurt the
> throughput of pathological nop execbuf by about 20%, with a similar effect
> upon the dispatch latency of a series of execbuf.
> 
> v2: use do {} while(0) for a smaller patch, and easier to revert again
> 
> I have reasonable confidence that we do not miss GT interrupts (as
> execlists provides a stress case with a failure mechanism easily
> detected by igt), however I have less confidence about all the other
> sources of interrupts and worry that may lose a display hotplug
> interrupt, for example.
> 
> Bugzilla: https://bugs.freedesktop.org/show_bug.cgi?id=93467
> Testcase: igt/gem_exec_nop/basic # requires NMI watchdog
> Signed-off-by: Chris Wilson <chris@chris-wilson.co.uk>
> Cc: Ville Syrjälä <ville.syrjala@linux.intel.com>
> Cc: Antti Koskipää <antti.koskipaa@linux.intel.com>
> Cc: Tvrtko Ursulin <tvrtko.ursulin@intel.com>
> Reviewed-by: Tvrtko Ursulin <tvrtko.ursulin@intel.com>
> Reviewed-by: Ville Syrjälä <ville.syrjala@linux.intel.com>
> Link: http://patchwork.freedesktop.org/patch/msgid/1457946117-6714-1-git-send-email-chris@chris-wilson.co.uk
> (cherry picked from commit 579de73b048a0a4c66c25a033ac76a2836e0cf73)
> Signed-off-by: Jani Nikula <jani.nikula@intel.com>
> Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
> ---
>  drivers/gpu/drm/i915/i915_irq.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
> 
> --- a/drivers/gpu/drm/i915/i915_irq.c
> +++ b/drivers/gpu/drm/i915/i915_irq.c
> @@ -1875,7 +1875,7 @@ static irqreturn_t cherryview_irq_handle
>  	u32 master_ctl, iir;
>  	irqreturn_t ret = IRQ_NONE;
>  
> -	for (;;) {
> +	do {
>  		master_ctl = I915_READ(GEN8_MASTER_IRQ) & ~GEN8_MASTER_IRQ_CONTROL;
>  		iir = I915_READ(VLV_IIR);
>  
> @@ -1897,7 +1897,7 @@ static irqreturn_t cherryview_irq_handle
>  		POSTING_READ(GEN8_MASTER_IRQ);
>  
>  		ret = IRQ_HANDLED;
> -	}
> +	} while (0);
>  
>  	return ret;
>  }

-- 
Ville Syrjälä
Intel OTC

[toc] | [prev] | [next] | [standalone]


#1421811 — Re: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler() after one pass

FromBen Hutchings <ben@decadent.org.uk>
Date2016-06-14 13:40 +0200
SubjectRe: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler() after one pass
Message-ID<rJURk-4dg-31@gated-at.bofh.it>
In reply to#1421764

[Multipart message — attachments visible in raw view] — view raw

On Tue, 2016-06-14 at 13:47 +0300, Ville Syrjälä wrote:
> On Mon, Jun 13, 2016 at 07:36:37PM +0100, Ben Hutchings wrote:
> > 3.16.36-rc1 review patch.  If anyone has any objections, please let me know.
> 
> Do not backport this one. It'll break things.

But this has not been re-reverted in mainline, has it?  Is it that
3.16-stable would need more changes backported to make this work, or is
mainline currently broken on Cherryview hardware?

Ben.

> > 
> > ------------------
> > 
> > From: Chris Wilson <chris@chris-wilson.co.uk>
> > 
> > commit 9dbaab56ac09f07a73fe83bf69bec3e31060080a upstream.
> > 
> > This effectively reverts
> > 
> > commit 8e5fd599eb219f1054e39b40d18b217af669eea9
> > Author: Ville Syrjälä <ville.syrjala@linux.intel.com>
> > Date:   Wed Apr 9 13:28:50 2014 +0300
> > 
> >     drm/i915/chv: Make CHV irq handler loop until all interrupts are consumed
> > 
> > as under continuous execlists load we can saturate the IRQ handler,
> > destablising the tsc clock and triggering the NMI watchdog to declare a hung
> > CPU.
> > 
> > [  552.756051] clocksource: timekeeping watchdog on CPU0: Marking clocksource 'tsc' as unstable because the skew is too large:
> > [  552.756080] clocksource:                       'refined-jiffies' wd_now: 10003b480 wd_last: 10003b28c mask: ffffffff
> > [  552.756091] clocksource:                       'tsc' cs_now: d55d31aa50 cs_last: d17446166c mask: ffffffffffffffff
> > [  552.756210] clocksource: Switched to clocksource refined-jiffies
> > [  575.217870] NMI watchdog: Watchdog detected hard LOCKUP on cpu 1
> > [  575.217893] CPU: 1 PID: 0 Comm: swapper/1 Not tainted 4.5.0-rc7+ #18
> > [  575.217905] Hardware name:                  /NUC5CPYB, BIOS PYBSWCEL.86A.0027.2015.0507.1758 05/07/2015
> > [  575.217915]  0000000000000000 ffff88027fd05bc0 ffffffff81288c6d 0000000000000000
> > [  575.217935]  0000000000000001 ffff88027fd05be0 ffffffff810e72d1 0000000000000000
> > [  575.217951]  ffff88027fd05c80 ffff88027fd05c20 ffffffff81114b60 0000000181015f1e
> > [  575.217967] Call Trace:
> > [  575.217973]    [] dump_stack+0x4f/0x72
> > [  575.217994]  [] watchdog_overflow_callback+0x151/0x160
> > [  575.218003]  [] __perf_event_overflow+0xa0/0x1e0
> > [  575.218016]  [] perf_event_overflow+0x14/0x20
> > [  575.218028]  [] intel_pmu_handle_irq+0x1da/0x460
> > [  575.218042]  [] ? poll_idle+0x3e/0x70
> > [  575.218052]  [] ? poll_idle+0x3e/0x70
> > [  575.218064]  [] perf_event_nmi_handler+0x28/0x50
> > [  575.218075]  [] nmi_handle+0x60/0x130
> > [  575.218086]  [] ? poll_idle+0x3e/0x70
> > [  575.218096]  [] do_nmi+0x140/0x470
> > [  575.218108]  [] end_repeat_nmi+0x1a/0x1e
> > [  575.218119]  [] ? poll_idle+0x3e/0x70
> > [  575.218129]  [] ? poll_idle+0x3e/0x70
> > [  575.218139]  [] ? poll_idle+0x3e/0x70
> > [  575.218148]  <>  [] cpuidle_enter_state+0xf3/0x2f0
> > [  575.218164]  [] cpuidle_enter+0x17/0x20
> > [  575.218175]  [] call_cpuidle+0x2a/0x40
> > [  575.218185]  [] cpu_startup_entry+0x273/0x330
> > [  575.218196]  [] start_secondary+0x10e/0x130
> > 
> > However, not servicing all available IIR within the handler does hurt the
> > throughput of pathological nop execbuf by about 20%, with a similar effect
> > upon the dispatch latency of a series of execbuf.
> > 
> > v2: use do {} while(0) for a smaller patch, and easier to revert again
> > 
> > I have reasonable confidence that we do not miss GT interrupts (as
> > execlists provides a stress case with a failure mechanism easily
> > detected by igt), however I have less confidence about all the other
> > sources of interrupts and worry that may lose a display hotplug
> > interrupt, for example.
> > 
> > Bugzilla: https://bugs.freedesktop.org/show_bug.cgi?id=93467
> > Testcase: igt/gem_exec_nop/basic # requires NMI watchdog
> > Signed-off-by: Chris Wilson <chris@chris-wilson.co.uk>
> > Cc: Ville Syrjälä <ville.syrjala@linux.intel.com>
> > Cc: Antti Koskipää <antti.koskipaa@linux.intel.com>
> > Cc: Tvrtko Ursulin <tvrtko.ursulin@intel.com>
> > Reviewed-by: Tvrtko Ursulin <tvrtko.ursulin@intel.com>
> > Reviewed-by: Ville Syrjälä <ville.syrjala@linux.intel.com>
> > Link: http://patchwork.freedesktop.org/patch/msgid/1457946117-6714-1-git-send-email-chris@chris-wilson.co.uk
> > (cherry picked from commit 579de73b048a0a4c66c25a033ac76a2836e0cf73)
> > Signed-off-by: Jani Nikula <jani.nikula@intel.com>
> > Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
> > ---
> >  drivers/gpu/drm/i915/i915_irq.c | 4 ++--
> >  1 file changed, 2 insertions(+), 2 deletions(-)
> > 
> > --- a/drivers/gpu/drm/i915/i915_irq.c
> > +++ b/drivers/gpu/drm/i915/i915_irq.c
> > @@ -1875,7 +1875,7 @@ static irqreturn_t cherryview_irq_handle
> >  	u32 master_ctl, iir;
> >  	irqreturn_t ret = IRQ_NONE;
> >  
> > -	for (;;) {
> > +	do {
> >  		master_ctl = I915_READ(GEN8_MASTER_IRQ) & ~GEN8_MASTER_IRQ_CONTROL;
> >  		iir = I915_READ(VLV_IIR);
> >  
> > @@ -1897,7 +1897,7 @@ static irqreturn_t cherryview_irq_handle
> >  		POSTING_READ(GEN8_MASTER_IRQ);
> >  
> >  		ret = IRQ_HANDLED;
> > -	}
> > +	} while (0);
> >  
> >  	return ret;
> >  }
> 
-- 
Ben Hutchings
We get into the habit of living before acquiring the habit of thinking.
                                                              - Albert
Camus

[toc] | [prev] | [next] | [standalone]


#1421842 — Re: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler() after one pass

FromVille Syrjälä <ville.syrjala@linux.intel.com>
Date2016-06-14 14:10 +0200
SubjectRe: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler() after one pass
Message-ID<rJVkl-4Ei-7@gated-at.bofh.it>
In reply to#1421811
On Tue, Jun 14, 2016 at 12:37:34PM +0100, Ben Hutchings wrote:
> On Tue, 2016-06-14 at 13:47 +0300, Ville Syrjälä wrote:
> > On Mon, Jun 13, 2016 at 07:36:37PM +0100, Ben Hutchings wrote:
> > > 3.16.36-rc1 review patch.  If anyone has any objections, please let me know.
> > 
> > Do not backport this one. It'll break things.
> 
> But this has not been re-reverted in mainline, has it?  Is it that
> 3.16-stable would need more changes backported to make this work, or is
> mainline currently broken on Cherryview hardware?

No, as of 4.7 we have a proper fix, but it's a bit too big to backport
(see [1]). I think 4.6.x is still busted, but Greg said he'd revert
this broken patch there, so it should get fixed eventually.

OTOH CHV wasn't even officially supported until maybe 4.1, so whatever
you do in 3.16 shouldn't really matter.

It's a bit tedious having to block the same patch from different stable
trees over and over again. It would be nice it there would be some kind
of stable blacklist you guys could share so that we wouldn't have to
repeat this dance with every stable maintainer...

[1] http://thread.gmane.org/gmane.linux.kernel.stable/179312/focus=181316

> 
> Ben.
> 
> > > 
> > > ------------------
> > > 
> > > From: Chris Wilson <chris@chris-wilson.co.uk>
> > > 
> > > commit 9dbaab56ac09f07a73fe83bf69bec3e31060080a upstream.
> > > 
> > > This effectively reverts
> > > 
> > > commit 8e5fd599eb219f1054e39b40d18b217af669eea9
> > > Author: Ville Syrjälä <ville.syrjala@linux.intel.com>
> > > Date:   Wed Apr 9 13:28:50 2014 +0300
> > > 
> > >     drm/i915/chv: Make CHV irq handler loop until all interrupts are consumed
> > > 
> > > as under continuous execlists load we can saturate the IRQ handler,
> > > destablising the tsc clock and triggering the NMI watchdog to declare a hung
> > > CPU.
> > > 
> > > [  552.756051] clocksource: timekeeping watchdog on CPU0: Marking clocksource 'tsc' as unstable because the skew is too large:
> > > [  552.756080] clocksource:                       'refined-jiffies' wd_now: 10003b480 wd_last: 10003b28c mask: ffffffff
> > > [  552.756091] clocksource:                       'tsc' cs_now: d55d31aa50 cs_last: d17446166c mask: ffffffffffffffff
> > > [  552.756210] clocksource: Switched to clocksource refined-jiffies
> > > [  575.217870] NMI watchdog: Watchdog detected hard LOCKUP on cpu 1
> > > [  575.217893] CPU: 1 PID: 0 Comm: swapper/1 Not tainted 4.5.0-rc7+ #18
> > > [  575.217905] Hardware name:                  /NUC5CPYB, BIOS PYBSWCEL.86A.0027.2015.0507.1758 05/07/2015
> > > [  575.217915]  0000000000000000 ffff88027fd05bc0 ffffffff81288c6d 0000000000000000
> > > [  575.217935]  0000000000000001 ffff88027fd05be0 ffffffff810e72d1 0000000000000000
> > > [  575.217951]  ffff88027fd05c80 ffff88027fd05c20 ffffffff81114b60 0000000181015f1e
> > > [  575.217967] Call Trace:
> > > [  575.217973]    [] dump_stack+0x4f/0x72
> > > [  575.217994]  [] watchdog_overflow_callback+0x151/0x160
> > > [  575.218003]  [] __perf_event_overflow+0xa0/0x1e0
> > > [  575.218016]  [] perf_event_overflow+0x14/0x20
> > > [  575.218028]  [] intel_pmu_handle_irq+0x1da/0x460
> > > [  575.218042]  [] ? poll_idle+0x3e/0x70
> > > [  575.218052]  [] ? poll_idle+0x3e/0x70
> > > [  575.218064]  [] perf_event_nmi_handler+0x28/0x50
> > > [  575.218075]  [] nmi_handle+0x60/0x130
> > > [  575.218086]  [] ? poll_idle+0x3e/0x70
> > > [  575.218096]  [] do_nmi+0x140/0x470
> > > [  575.218108]  [] end_repeat_nmi+0x1a/0x1e
> > > [  575.218119]  [] ? poll_idle+0x3e/0x70
> > > [  575.218129]  [] ? poll_idle+0x3e/0x70
> > > [  575.218139]  [] ? poll_idle+0x3e/0x70
> > > [  575.218148]  <>  [] cpuidle_enter_state+0xf3/0x2f0
> > > [  575.218164]  [] cpuidle_enter+0x17/0x20
> > > [  575.218175]  [] call_cpuidle+0x2a/0x40
> > > [  575.218185]  [] cpu_startup_entry+0x273/0x330
> > > [  575.218196]  [] start_secondary+0x10e/0x130
> > > 
> > > However, not servicing all available IIR within the handler does hurt the
> > > throughput of pathological nop execbuf by about 20%, with a similar effect
> > > upon the dispatch latency of a series of execbuf.
> > > 
> > > v2: use do {} while(0) for a smaller patch, and easier to revert again
> > > 
> > > I have reasonable confidence that we do not miss GT interrupts (as
> > > execlists provides a stress case with a failure mechanism easily
> > > detected by igt), however I have less confidence about all the other
> > > sources of interrupts and worry that may lose a display hotplug
> > > interrupt, for example.
> > > 
> > > Bugzilla: https://bugs.freedesktop.org/show_bug.cgi?id=93467
> > > Testcase: igt/gem_exec_nop/basic # requires NMI watchdog
> > > Signed-off-by: Chris Wilson <chris@chris-wilson.co.uk>
> > > Cc: Ville Syrjälä <ville.syrjala@linux.intel.com>
> > > Cc: Antti Koskipää <antti.koskipaa@linux.intel.com>
> > > Cc: Tvrtko Ursulin <tvrtko.ursulin@intel.com>
> > > Reviewed-by: Tvrtko Ursulin <tvrtko.ursulin@intel.com>
> > > Reviewed-by: Ville Syrjälä <ville.syrjala@linux.intel.com>
> > > Link: http://patchwork.freedesktop.org/patch/msgid/1457946117-6714-1-git-send-email-chris@chris-wilson.co.uk
> > > (cherry picked from commit 579de73b048a0a4c66c25a033ac76a2836e0cf73)
> > > Signed-off-by: Jani Nikula <jani.nikula@intel.com>
> > > Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
> > > ---
> > >  drivers/gpu/drm/i915/i915_irq.c | 4 ++--
> > >  1 file changed, 2 insertions(+), 2 deletions(-)
> > > 
> > > --- a/drivers/gpu/drm/i915/i915_irq.c
> > > +++ b/drivers/gpu/drm/i915/i915_irq.c
> > > @@ -1875,7 +1875,7 @@ static irqreturn_t cherryview_irq_handle
> > >  	u32 master_ctl, iir;
> > >  	irqreturn_t ret = IRQ_NONE;
> > >  
> > > -	for (;;) {
> > > +	do {
> > >  		master_ctl = I915_READ(GEN8_MASTER_IRQ) & ~GEN8_MASTER_IRQ_CONTROL;
> > >  		iir = I915_READ(VLV_IIR);
> > >  
> > > @@ -1897,7 +1897,7 @@ static irqreturn_t cherryview_irq_handle
> > >  		POSTING_READ(GEN8_MASTER_IRQ);
> > >  
> > >  		ret = IRQ_HANDLED;
> > > -	}
> > > +	} while (0);
> > >  
> > >  	return ret;
> > >  }
> > 
> -- 
> Ben Hutchings
> We get into the habit of living before acquiring the habit of thinking.
>                                                               - Albert
> Camus



-- 
Ville Syrjälä
Intel OTC

[toc] | [prev] | [next] | [standalone]


#1421879 — Re: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler() after one pass

FromBen Hutchings <ben@decadent.org.uk>
Date2016-06-14 14:50 +0200
SubjectRe: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler() after one pass
Message-ID<rJVX4-4SP-31@gated-at.bofh.it>
In reply to#1421842

[Multipart message — attachments visible in raw view] — view raw

On Tue, 2016-06-14 at 15:08 +0300, Ville Syrjälä wrote:
> On Tue, Jun 14, 2016 at 12:37:34PM +0100, Ben Hutchings wrote:
> > On Tue, 2016-06-14 at 13:47 +0300, Ville Syrjälä wrote:
> > > On Mon, Jun 13, 2016 at 07:36:37PM +0100, Ben Hutchings wrote:
> > > > 3.16.36-rc1 review patch.  If anyone has any objections, please let me know.
> > > 
> > > Do not backport this one. It'll break things.
> > 
> > But this has not been re-reverted in mainline, has it?  Is it that
> > 3.16-stable would need more changes backported to make this work, or is
> > mainline currently broken on Cherryview hardware?
> 
> No, as of 4.7 we have a proper fix, but it's a bit too big to backport
> (see [1]). I think 4.6.x is still busted, but Greg said he'd revert
> this broken patch there, so it should get fixed eventually.
> 
> OTOH CHV wasn't even officially supported until maybe 4.1, so whatever
> you do in 3.16 shouldn't really matter.

OK, I've dropped this.

> It's a bit tedious having to block the same patch from different stable
> trees over and over again. It would be nice it there would be some kind
> of stable blacklist you guys could share so that we wouldn't have to
> repeat this dance with every stable maintainer...

Sorry about that; I do try to look for things like that on the stable
list but it's too high volume for me to keep up with most of the time.

Ben.

-- 
Ben Hutchings
We get into the habit of living before acquiring the habit of thinking.
                                                              - Albert
Camus

[toc] | [prev] | [next] | [standalone]


#1421889 — Re: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler() after one pass

FromVille Syrjälä <ville.syrjala@linux.intel.com>
Date2016-06-14 15:10 +0200
SubjectRe: [PATCH 3.16 012/114] drm/i915: Exit cherryview_irq_handler() after one pass
Message-ID<rJWgq-5eJ-15@gated-at.bofh.it>
In reply to#1421879
On Tue, Jun 14, 2016 at 01:48:47PM +0100, Ben Hutchings wrote:
> On Tue, 2016-06-14 at 15:08 +0300, Ville Syrjälä wrote:
> > On Tue, Jun 14, 2016 at 12:37:34PM +0100, Ben Hutchings wrote:
> > > On Tue, 2016-06-14 at 13:47 +0300, Ville Syrjälä wrote:
> > > > On Mon, Jun 13, 2016 at 07:36:37PM +0100, Ben Hutchings wrote:
> > > > > 3.16.36-rc1 review patch.  If anyone has any objections, please let me know.
> > > > 
> > > > Do not backport this one. It'll break things.
> > > 
> > > But this has not been re-reverted in mainline, has it?  Is it that
> > > 3.16-stable would need more changes backported to make this work, or is
> > > mainline currently broken on Cherryview hardware?
> > 
> > No, as of 4.7 we have a proper fix, but it's a bit too big to backport
> > (see [1]). I think 4.6.x is still busted, but Greg said he'd revert
> > this broken patch there, so it should get fixed eventually.
> > 
> > OTOH CHV wasn't even officially supported until maybe 4.1, so whatever
> > you do in 3.16 shouldn't really matter.
> 
> OK, I've dropped this.
> 
> > It's a bit tedious having to block the same patch from different stable
> > trees over and over again. It would be nice it there would be some kind
> > of stable blacklist you guys could share so that we wouldn't have to
> > repeat this dance with every stable maintainer...
> 
> Sorry about that; I do try to look for things like that on the stable
> list but it's too high volume for me to keep up with most of the time.

I understand. Have the same problem myself often enough. Which is why I
think a blacklist type of thing might be the better option. But maybe
cc:stable mislabeling doesn't happen often enough to warrant it.

-- 
Ville Syrjälä
Intel OTC

[toc] | [prev] | [next] | [standalone]


#1421239 — [PATCH 3.16 009/114] Input: gtco - fix crash on detecting device without endpoints

FromBen Hutchings <ben@decadent.org.uk>
Date2016-06-13 21:20 +0200
Subject[PATCH 3.16 009/114] Input: gtco - fix crash on detecting device without endpoints
Message-ID<rJFyX-26n-65@gated-at.bofh.it>
In reply to#1421229
3.16.36-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Vladis Dronov <vdronov@redhat.com>

commit 162f98dea487206d9ab79fc12ed64700667a894d upstream.

The gtco driver expects at least one valid endpoint. If given malicious
descriptors that specify 0 for the number of endpoints, it will crash in
the probe function. Ensure there is at least one endpoint on the interface
before using it.

Also let's fix a minor coding style issue.

The full correct report of this issue can be found in the public
Red Hat Bugzilla:

https://bugzilla.redhat.com/show_bug.cgi?id=1283385

Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/input/tablet/gtco.c | 10 +++++++++-
 1 file changed, 9 insertions(+), 1 deletion(-)

--- a/drivers/input/tablet/gtco.c
+++ b/drivers/input/tablet/gtco.c
@@ -868,6 +868,14 @@ static int gtco_probe(struct usb_interfa
 		goto err_free_buf;
 	}
 
+	/* Sanity check that a device has an endpoint */
+	if (usbinterface->altsetting[0].desc.bNumEndpoints < 1) {
+		dev_err(&usbinterface->dev,
+			"Invalid number of endpoints\n");
+		error = -EINVAL;
+		goto err_free_urb;
+	}
+
 	/*
 	 * The endpoint is always altsetting 0, we know this since we know
 	 * this device only has one interrupt endpoint
@@ -889,7 +897,7 @@ static int gtco_probe(struct usb_interfa
 	 * HID report descriptor
 	 */
 	if (usb_get_extra_descriptor(usbinterface->cur_altsetting,
-				     HID_DEVICE_TYPE, &hid_desc) != 0){
+				     HID_DEVICE_TYPE, &hid_desc) != 0) {
 		dev_err(&usbinterface->dev,
 			"Can't retrieve exta USB descriptor to get hid report descriptor length\n");
 		error = -EIO;

[toc] | [prev] | [next] | [standalone]


#1421240 — [PATCH 3.16 058/114] mm/huge_memory: replace VM_NO_THP VM_BUG_ON with actual VMA check

FromBen Hutchings <ben@decadent.org.uk>
Date2016-06-13 21:20 +0200
Subject[PATCH 3.16 058/114] mm/huge_memory: replace VM_NO_THP VM_BUG_ON with actual VMA check
Message-ID<rJFyX-26n-61@gated-at.bofh.it>
In reply to#1421229
3.16.36-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Konstantin Khlebnikov <koct9i@gmail.com>

commit 3486b85a29c1741db99d0c522211c82d2b7a56d0 upstream.

Khugepaged detects own VMAs by checking vm_file and vm_ops but this way
it cannot distinguish private /dev/zero mappings from other special
mappings like /dev/hpet which has no vm_ops and popultes PTEs in mmap.

This fixes false-positive VM_BUG_ON and prevents installing THP where
they are not expected.

Link: http://lkml.kernel.org/r/CACT4Y+ZmuZMV5CjSFOeXviwQdABAgT7T+StKfTqan9YDtgEi5g@mail.gmail.com
Fixes: 78f11a255749 ("mm: thp: fix /dev/zero MAP_PRIVATE and vm_flags cleanups")
Signed-off-by: Konstantin Khlebnikov <koct9i@gmail.com>
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Acked-by: Vlastimil Babka <vbabka@suse.cz>
Acked-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Cc: Dmitry Vyukov <dvyukov@google.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[bwh: Backported to 3.16: deleted assertions used VM_BUG_ON()]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 mm/huge_memory.c | 6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)

--- a/mm/huge_memory.c
+++ b/mm/huge_memory.c
@@ -2068,10 +2068,9 @@ int khugepaged_enter_vma_merge(struct vm
 		 * page fault if needed.
 		 */
 		return 0;
-	if (vma->vm_ops)
+	if (vma->vm_ops || (vm_flags & VM_NO_THP))
 		/* khugepaged not yet working on file or special mappings */
 		return 0;
-	VM_BUG_ON(vm_flags & VM_NO_THP);
 	hstart = (vma->vm_start + ~HPAGE_PMD_MASK) & HPAGE_PMD_MASK;
 	hend = vma->vm_end & HPAGE_PMD_MASK;
 	if (hstart < hend)
@@ -2376,8 +2375,7 @@ static bool hugepage_vma_check(struct vm
 		return false;
 	if (is_vma_temporary_stack(vma))
 		return false;
-	VM_BUG_ON(vma->vm_flags & VM_NO_THP);
-	return true;
+	return !(vma->vm_flags & VM_NO_THP);
 }
 
 static void collapse_huge_page(struct mm_struct *mm,

[toc] | [prev] | [next] | [standalone]


#1421335

FromSudip Mukherjee <sudipm.mukherjee@gmail.com>
Date2016-06-13 23:20 +0200
Message-ID<rJHr3-3m2-9@gated-at.bofh.it>
In reply to#1421229
On Monday 13 June 2016 07:36 PM, Ben Hutchings wrote:
> This is the start of the stable review cycle for the 3.16.36 release.
> There are 114 patches in this series, which will be posted as responses
> to this one.  If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Wed Jun 15 19:00:00 UTC 2016.
> Anything received after that time might be too late.
>
> A combined patch relative to 3.16.35 will be posted as an additional
> response to this.  A shortlog and diffstat can be found below.

Hi Ben,
I am not able to find the mail with the combined patch, cant even find 
on lkml also. I think I am missing something. Can you please send it to 
me again.

Regards
Sudip

[toc] | [prev] | [next] | [standalone]


#1421501

FromGuenter Roeck <linux@roeck-us.net>
Date2016-06-14 04:00 +0200
Message-ID<rJLO2-6jG-25@gated-at.bofh.it>
In reply to#1421229
On 06/13/2016 11:36 AM, Ben Hutchings wrote:
> This is the start of the stable review cycle for the 3.16.36 release.
> There are 114 patches in this series, which will be posted as responses
> to this one.  If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Wed Jun 15 19:00:00 UTC 2016.
> Anything received after that time might be too late.
>

Build results:
	total: 139 pass: 139 fail: 0
Qemu test results:
	total: 98 pass: 98 fail: 0

Details are available at http://kerneltests.org/builders.

Guenter

[toc] | [prev] | [next] | [standalone]


#1421787

FromBen Hutchings <ben@decadent.org.uk>
Date2016-06-14 13:30 +0200
Message-ID<rJUHE-49V-31@gated-at.bofh.it>
In reply to#1421501

[Multipart message — attachments visible in raw view] — view raw

On Mon, 2016-06-13 at 18:51 -0700, Guenter Roeck wrote:
> On 06/13/2016 11:36 AM, Ben Hutchings wrote:
> > This is the start of the stable review cycle for the 3.16.36 release.
> > There are 114 patches in this series, which will be posted as responses
> > to this one.  If anyone has any issues with these being applied, please
> > let me know.
> > 
> > Responses should be made by Wed Jun 15 19:00:00 UTC 2016.
> > Anything received after that time might be too late.
> > 
> 
> Build results:
> 	total: 139 pass: 139 fail: 0
> Qemu test results:
> 	total: 98 pass: 98 fail: 0
> 
> Details are available at http://kerneltests.org/builders.
> 

Thanks for checking.

Ben.

-- 
Ben Hutchings
We get into the habit of living before acquiring the habit of thinking.
                                                              - Albert
Camus

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web