Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1438055 > unrolled thread

[PATCH 4.6 00/31] 4.6.4-stable review

Started byGreg Kroah-Hartman <gregkh@linuxfoundation.org>
First post2016-07-07 03:20 +0200
Last post2016-07-09 07:20 +0200
Articles 20 on this page of 33 — 4 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 4.6 00/31] 4.6.4-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:20 +0200
    [PATCH 4.6 11/31] bpf, perf: delay release of BPF prog after grace period Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:20 +0200
    [PATCH 4.6 20/31] usb: musb: only restore devctl when session was set in backup Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:20 +0200
    [PATCH 4.6 03/31] net: Dont forget pr_fmt on net_dbg_ratelimited for CONFIG_DYNAMIC_DEBUG Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:20 +0200
    [PATCH 4.6 05/31] kcm: fix /proc memory leak Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
    [PATCH 4.6 07/31] netem: fix a use after free Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
    [PATCH 4.6 08/31] ipmr/ip6mr: Initialize the last assert time of mfc entries. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
    [PATCH 4.6 04/31] sit: correct IP protocol used in ipip6_err Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
    [PATCH 4.6 25/31] usb: xhci-plat: properly handle probe deferral for devm_clk_get() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 01/31] net_sched: fix pfifo_head_drop behavior vs backlog Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 23/31] usb: musb: host: correct cppi dma channel for isoch transfer Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 10/31] sock_diag: do not broadcast raw socket destruction Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 18/31] usb: quirks: Fix sorting Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 27/31] xhci: Fix handling timeouted commands on hosts in weird states. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 16/31] crypto: user - re-add size check for CRYPTO_MSG_GETALG Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 30/31] usb: host: ehci-tegra: Grab the correct UTMI pads reset Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 19/31] usb: quirks: Add no-lpm quirk for Acer C120 LED Projector Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 21/31] usb: musb: Stop bulk endpoint while queue is rotated Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 14/31] crypto: vmx - Increase priority of aes-cbc cipher Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 26/31] USB: xhci: Add broken streams quirk for Frescologic device id 1009 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 02/31] act_ipt: fix a bind refcnt leak Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 31/31] usb: dwc3: exynos: Fix deferred probing storm. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 17/31] USB: uas: Fix slave queue_depth not being set Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 13/31] AX.25: Close socket connection on session completion Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 12/31] neigh: Explicitly declare RCU-bh read side critical section in neigh_xmit() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 28/31] USB: mos7720: delete parport Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 15/31] crypto: ux500 - memmove the right size Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    [PATCH 4.6 22/31] usb: musb: Ensure rx reinit occurs for shared_fifo endpoints Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:40 +0200
    Re: [PATCH 4.6 00/31] 4.6.4-stable review Heinz Diehl <htd+ml@fritha.org> - 2016-07-07 14:50 +0200
      Re: [PATCH 4.6 00/31] 4.6.4-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 21:20 +0200
    Re: [PATCH 4.6 00/31] 4.6.4-stable review Guenter Roeck <linux@roeck-us.net> - 2016-07-07 15:40 +0200
    Re: [PATCH 4.6 00/31] 4.6.4-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-07-08 05:50 +0200
      Re: [PATCH 4.6 00/31] 4.6.4-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-09 07:20 +0200

Page 1 of 2  [1] 2  Next page →


#1438055 — [PATCH 4.6 00/31] 4.6.4-stable review

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:20 +0200
Subject[PATCH 4.6 00/31] 4.6.4-stable review
Message-ID<rS68W-8q2-5@gated-at.bofh.it>
-----------------------
Note, I'm on vacation this week, so I only took a few "easy" patches for
the stable trees, due to me not having much time to debug anything here,
and because, well, I'm on vacation and supposed to be ignoring patches.
So if you have marked patches for inclusion, or emailed asking for
things to be included, and you don't see them here (which you almost
certainly will not), just wait a week or so before panicking please.
-----------------------

This is the start of the stable review cycle for the 4.6.4 release.
There are 31 patches in this series, all will be posted as a response
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Sat Jul  9 01:15:40 UTC 2016.
Anything received after that time might be too late.

The whole patch series can be found in one patch at:
	kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.6.4-rc1.gz
or in the git tree and branch at:
  git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.6.y
and the diffstat can be found below.

thanks,

greg k-h

-------------
Pseudo-Shortlog of commits:

Greg Kroah-Hartman <gregkh@linuxfoundation.org>
    Linux 4.6.4-rc1

Steinar H. Gunderson <sesse@google.com>
    usb: dwc3: exynos: Fix deferred probing storm.

Thierry Reding <treding@nvidia.com>
    usb: host: ehci-tegra: Grab the correct UTMI pads reset

Bin Liu <b-liu@ti.com>
    usb: gadget: fix spinlock dead lock in gadgetfs

Sudip Mukherjee <sudipm.mukherjee@gmail.com>
    USB: mos7720: delete parport

Mathias Nyman <mathias.nyman@linux.intel.com>
    xhci: Fix handling timeouted commands on hosts in weird states.

Hans de Goede <hdegoede@redhat.com>
    USB: xhci: Add broken streams quirk for Frescologic device id 1009

Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
    usb: xhci-plat: properly handle probe deferral for devm_clk_get()

Gabriel Krisman Bertazi <krisman@linux.vnet.ibm.com>
    xhci: Cleanup only when releasing primary hcd

Bin Liu <b-liu@ti.com>
    usb: musb: host: correct cppi dma channel for isoch transfer

Andrew Goodbody <andrew.goodbody@cambrionix.com>
    usb: musb: Ensure rx reinit occurs for shared_fifo endpoints

Andrew Goodbody <andrew.goodbody@cambrionix.com>
    usb: musb: Stop bulk endpoint while queue is rotated

Bin Liu <b-liu@ti.com>
    usb: musb: only restore devctl when session was set in backup

Hans de Goede <hdegoede@redhat.com>
    usb: quirks: Add no-lpm quirk for Acer C120 LED Projector

Hans de Goede <hdegoede@redhat.com>
    usb: quirks: Fix sorting

Hans de Goede <hdegoede@redhat.com>
    USB: uas: Fix slave queue_depth not being set

Mathias Krause <minipli@googlemail.com>
    crypto: user - re-add size check for CRYPTO_MSG_GETALG

Linus Walleij <linus.walleij@linaro.org>
    crypto: ux500 - memmove the right size

Anton Blanchard <anton@samba.org>
    crypto: vmx - Increase priority of aes-cbc cipher

Basil Gunn <basil@pacabunga.com>
    AX.25: Close socket connection on session completion

David Barroso <dbarroso@fastly.com>
    neigh: Explicitly declare RCU-bh read side critical section in neigh_xmit()

Daniel Borkmann <daniel@iogearbox.net>
    bpf, perf: delay release of BPF prog after grace period

Willem de Bruijn <willemb@google.com>
    sock_diag: do not broadcast raw socket destruction

daniel <daniel@dd-wrt.com>
    Bridge: Fix ipv6 mc snooping if bridge has no ipv6 address

Tom Goff <thomas.goff@ll.mit.edu>
    ipmr/ip6mr: Initialize the last assert time of mfc entries.

Eric Dumazet <edumazet@google.com>
    netem: fix a use after free

Herbert Xu <herbert@gondor.apana.org.au>
    esp: Fix ESN generation under UDP encapsulation

Jiri Slaby <jslaby@suse.cz>
    kcm: fix /proc memory leak

Simon Horman <simon.horman@netronome.com>
    sit: correct IP protocol used in ipip6_err

Jason A. Donenfeld <Jason@zx2c4.com>
    net: Don't forget pr_fmt on net_dbg_ratelimited for CONFIG_DYNAMIC_DEBUG

WANG Cong <xiyou.wangcong@gmail.com>
    act_ipt: fix a bind refcnt leak

Eric Dumazet <edumazet@google.com>
    net_sched: fix pfifo_head_drop behavior vs backlog


-------------

Diffstat:

 Makefile                              |  4 +--
 crypto/crypto_user.c                  |  1 +
 drivers/crypto/ux500/hash/hash_core.c |  4 +--
 drivers/crypto/vmx/aes_cbc.c          |  2 +-
 drivers/crypto/vmx/aes_ctr.c          |  2 +-
 drivers/usb/core/quirks.c             | 23 +++++++++-------
 drivers/usb/dwc3/dwc3-exynos.c        | 19 +++++++------
 drivers/usb/gadget/legacy/inode.c     | 17 +++++++++---
 drivers/usb/host/ehci-tegra.c         |  2 +-
 drivers/usb/host/xhci-pci.c           |  5 ++++
 drivers/usb/host/xhci-plat.c          |  3 ++
 drivers/usb/host/xhci-ring.c          | 30 ++++++++++++++++----
 drivers/usb/host/xhci.c               | 27 ++++++++++--------
 drivers/usb/musb/musb_core.c          |  3 +-
 drivers/usb/musb/musb_host.c          | 23 ++++++++++------
 drivers/usb/serial/mos7720.c          |  1 +
 drivers/usb/storage/uas.c             |  1 +
 include/linux/bpf.h                   |  4 +++
 include/linux/net.h                   |  3 +-
 include/linux/sock_diag.h             |  6 ++++
 kernel/events/core.c                  |  2 +-
 net/ax25/af_ax25.c                    |  3 +-
 net/ax25/ax25_ds_timer.c              |  5 +++-
 net/ax25/ax25_std_timer.c             |  5 +++-
 net/ax25/ax25_subr.c                  |  3 +-
 net/bridge/br_multicast.c             |  4 +++
 net/bridge/br_private.h               | 23 +++++++++++++---
 net/core/neighbour.c                  |  6 +++-
 net/ipv4/esp4.c                       | 52 +++++++++++++++++++++--------------
 net/ipv4/ipmr.c                       |  4 ++-
 net/ipv6/ip6mr.c                      |  1 +
 net/ipv6/sit.c                        |  4 +--
 net/kcm/kcmproc.c                     |  1 +
 net/sched/act_ipt.c                   |  7 +++--
 net/sched/sch_fifo.c                  |  4 +++
 net/sched/sch_netem.c                 | 12 ++++----
 36 files changed, 217 insertions(+), 99 deletions(-)

[toc] | [next] | [standalone]


#1438056 — [PATCH 4.6 11/31] bpf, perf: delay release of BPF prog after grace period

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:20 +0200
Subject[PATCH 4.6 11/31] bpf, perf: delay release of BPF prog after grace period
Message-ID<rS68W-8q2-17@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <daniel@iogearbox.net>

[ Upstream commit ceb56070359b7329b5678b5d95a376fcb24767be ]

Commit dead9f29ddcc ("perf: Fix race in BPF program unregister") moved
destruction of BPF program from free_event_rcu() callback to __free_event(),
which is problematic if used with tail calls: if prog A is attached as
trace event directly, but at the same time present in a tail call map used
by another trace event program elsewhere, then we need to delay destruction
via RCU grace period since it can still be in use by the program doing the
tail call (the prog first needs to be dropped from the tail call map, then
trace event with prog A attached destroyed, so we get immediate destruction).

Fixes: dead9f29ddcc ("perf: Fix race in BPF program unregister")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Cc: Jann Horn <jann@thejh.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 include/linux/bpf.h  |    4 ++++
 kernel/events/core.c |    2 +-
 2 files changed, 5 insertions(+), 1 deletion(-)

--- a/include/linux/bpf.h
+++ b/include/linux/bpf.h
@@ -229,6 +229,10 @@ static inline struct bpf_prog *bpf_prog_
 static inline void bpf_prog_put(struct bpf_prog *prog)
 {
 }
+
+static inline void bpf_prog_put_rcu(struct bpf_prog *prog)
+{
+}
 #endif /* CONFIG_BPF_SYSCALL */
 
 /* verifier prototypes for helper functions called from eBPF programs */
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -7143,7 +7143,7 @@ static void perf_event_free_bpf_prog(str
 	prog = event->tp_event->prog;
 	if (prog) {
 		event->tp_event->prog = NULL;
-		bpf_prog_put(prog);
+		bpf_prog_put_rcu(prog);
 	}
 }
 

[toc] | [prev] | [next] | [standalone]


#1438057 — [PATCH 4.6 20/31] usb: musb: only restore devctl when session was set in backup

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:20 +0200
Subject[PATCH 4.6 20/31] usb: musb: only restore devctl when session was set in backup
Message-ID<rS68W-8q2-19@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bin Liu <b-liu@ti.com>

commit 84ac5d1140f716a616522f952734e850448d2556 upstream.

If the session bit was not set in the backup of devctl register,
restoring devctl would clear the session bit. Therefor, only restore
devctl register when the session bit was set in the backup.

This solves the device enumeration failure in otg mode exposed by commit
56f487c (PM / Runtime: Update last_busy in rpm_resume).

Signed-off-by: Bin Liu <b-liu@ti.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/musb/musb_core.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/usb/musb/musb_core.c
+++ b/drivers/usb/musb/musb_core.c
@@ -2429,7 +2429,8 @@ static void musb_restore_context(struct
 	musb_writew(musb_base, MUSB_INTRTXE, musb->intrtxe);
 	musb_writew(musb_base, MUSB_INTRRXE, musb->intrrxe);
 	musb_writeb(musb_base, MUSB_INTRUSBE, musb->context.intrusbe);
-	musb_writeb(musb_base, MUSB_DEVCTL, musb->context.devctl);
+	if (musb->context.devctl & MUSB_DEVCTL_SESSION)
+		musb_writeb(musb_base, MUSB_DEVCTL, musb->context.devctl);
 
 	for (i = 0; i < musb->config->num_eps; ++i) {
 		struct musb_hw_ep	*hw_ep;

[toc] | [prev] | [next] | [standalone]


#1438058 — [PATCH 4.6 03/31] net: Dont forget pr_fmt on net_dbg_ratelimited for CONFIG_DYNAMIC_DEBUG

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:20 +0200
Subject[PATCH 4.6 03/31] net: Dont forget pr_fmt on net_dbg_ratelimited for CONFIG_DYNAMIC_DEBUG
Message-ID<rS68W-8q2-21@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: "Jason A. Donenfeld" <Jason@zx2c4.com>

[ Upstream commit daddef76c3deaaa7922f9d7b18edbf0a061215c3 ]

The implementation of net_dbg_ratelimited in the CONFIG_DYNAMIC_DEBUG
case was added with 2c94b5373 ("net: Implement net_dbg_ratelimited() for
CONFIG_DYNAMIC_DEBUG case"). The implementation strategy was to take the
usual definition of the dynamic_pr_debug macro, but alter it by adding a
call to "net_ratelimit()" in the if statement. This is, in fact, the
correct approach.

However, while doing this, the author of the commit forgot to surround
fmt by pr_fmt, resulting in unprefixed log messages appearing in the
console. So, this commit adds back the pr_fmt(fmt) invocation, making
net_dbg_ratelimited properly consistent across DEBUG, no DEBUG, and
DYNAMIC_DEBUG cases, and bringing parity with the behavior of
dynamic_pr_debug as well.

Fixes: 2c94b5373 ("net: Implement net_dbg_ratelimited() for CONFIG_DYNAMIC_DEBUG case")
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Cc: Tim Bingham <tbingham@akamai.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 include/linux/net.h |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/include/linux/net.h
+++ b/include/linux/net.h
@@ -252,7 +252,8 @@ do {									\
 	DEFINE_DYNAMIC_DEBUG_METADATA(descriptor, fmt);			\
 	if (unlikely(descriptor.flags & _DPRINTK_FLAGS_PRINT) &&	\
 	    net_ratelimit())						\
-		__dynamic_pr_debug(&descriptor, fmt, ##__VA_ARGS__);	\
+		__dynamic_pr_debug(&descriptor, pr_fmt(fmt),		\
+		                   ##__VA_ARGS__);			\
 } while (0)
 #elif defined(DEBUG)
 #define net_dbg_ratelimited(fmt, ...)				\

[toc] | [prev] | [next] | [standalone]


#1438059 — [PATCH 4.6 05/31] kcm: fix /proc memory leak

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:30 +0200
Subject[PATCH 4.6 05/31] kcm: fix /proc memory leak
Message-ID<rS6iB-8uQ-1@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jiri Slaby <jslaby@suse.cz>

[ Upstream commit d19af0a76444fde629667ecb823c0ee28f9f67d8 ]

Every open of /proc/net/kcm leaks 16 bytes of memory as is reported by
kmemleak:
unreferenced object 0xffff88059c0e3458 (size 192):
  comm "cat", pid 1401, jiffies 4294935742 (age 310.720s)
  hex dump (first 32 bytes):
    28 45 71 96 05 88 ff ff 00 10 00 00 00 00 00 00  (Eq.............
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
  backtrace:
    [<ffffffff8156a2de>] kmem_cache_alloc_trace+0x16e/0x230
    [<ffffffff8162a479>] seq_open+0x79/0x1d0
    [<ffffffffa0578510>] kcm_seq_open+0x0/0x30 [kcm]
    [<ffffffff8162a479>] seq_open+0x79/0x1d0
    [<ffffffff8162a8cf>] __seq_open_private+0x2f/0xa0
    [<ffffffff81712548>] seq_open_net+0x38/0xa0
...

It is caused by a missing free in the ->release path. So fix it by
providing seq_release_net as the ->release method.

Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Fixes: cd6e111bf5 (kcm: Add statistics and proc interfaces)
Cc: "David S. Miller" <davem@davemloft.net>
Cc: Tom Herbert <tom@herbertland.com>
Cc: netdev@vger.kernel.org
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/kcm/kcmproc.c |    1 +
 1 file changed, 1 insertion(+)

--- a/net/kcm/kcmproc.c
+++ b/net/kcm/kcmproc.c
@@ -241,6 +241,7 @@ static const struct file_operations kcm_
 	.open		= kcm_seq_open,
 	.read		= seq_read,
 	.llseek		= seq_lseek,
+	.release	= seq_release_net,
 };
 
 static struct kcm_seq_muxinfo kcm_seq_muxinfo = {

[toc] | [prev] | [next] | [standalone]


#1438066 — [PATCH 4.6 07/31] netem: fix a use after free

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:30 +0200
Subject[PATCH 4.6 07/31] netem: fix a use after free
Message-ID<rS6iC-8uQ-19@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 21de12ee5568fd1aec47890c72967abf791ac80a ]

If the packet was dropped by lower qdisc, then we must not
access it later.

Save qdisc_pkt_len(skb) in a temp variable.

Fixes: 2ccccf5fb43f ("net_sched: update hierarchical backlog too")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: WANG Cong <xiyou.wangcong@gmail.com>
Cc: Jamal Hadi Salim <jhs@mojatatu.com>
Cc: Stephen Hemminger <stephen@networkplumber.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/sched/sch_netem.c |   12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

--- a/net/sched/sch_netem.c
+++ b/net/sched/sch_netem.c
@@ -650,14 +650,14 @@ deliver:
 #endif
 
 			if (q->qdisc) {
+				unsigned int pkt_len = qdisc_pkt_len(skb);
 				int err = qdisc_enqueue(skb, q->qdisc);
 
-				if (unlikely(err != NET_XMIT_SUCCESS)) {
-					if (net_xmit_drop_count(err)) {
-						qdisc_qstats_drop(sch);
-						qdisc_tree_reduce_backlog(sch, 1,
-									  qdisc_pkt_len(skb));
-					}
+				if (err != NET_XMIT_SUCCESS &&
+				    net_xmit_drop_count(err)) {
+					qdisc_qstats_drop(sch);
+					qdisc_tree_reduce_backlog(sch, 1,
+								  pkt_len);
 				}
 				goto tfifo_dequeue;
 			}

[toc] | [prev] | [next] | [standalone]


#1438067 — [PATCH 4.6 08/31] ipmr/ip6mr: Initialize the last assert time of mfc entries.

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:30 +0200
Subject[PATCH 4.6 08/31] ipmr/ip6mr: Initialize the last assert time of mfc entries.
Message-ID<rS6iB-8uQ-17@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tom Goff <thomas.goff@ll.mit.edu>

[ Upstream commit 70a0dec45174c976c64b4c8c1d0898581f759948 ]

This fixes wrong-interface signaling on 32-bit platforms for entries
created when jiffies > 2^31 + MFC_ASSERT_THRESH.

Signed-off-by: Tom Goff <thomas.goff@ll.mit.edu>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/ipv4/ipmr.c  |    4 +++-
 net/ipv6/ip6mr.c |    1 +
 2 files changed, 4 insertions(+), 1 deletion(-)

--- a/net/ipv4/ipmr.c
+++ b/net/ipv4/ipmr.c
@@ -891,8 +891,10 @@ static struct mfc_cache *ipmr_cache_allo
 {
 	struct mfc_cache *c = kmem_cache_zalloc(mrt_cachep, GFP_KERNEL);
 
-	if (c)
+	if (c) {
+		c->mfc_un.res.last_assert = jiffies - MFC_ASSERT_THRESH - 1;
 		c->mfc_un.res.minvif = MAXVIFS;
+	}
 	return c;
 }
 
--- a/net/ipv6/ip6mr.c
+++ b/net/ipv6/ip6mr.c
@@ -1074,6 +1074,7 @@ static struct mfc6_cache *ip6mr_cache_al
 	struct mfc6_cache *c = kmem_cache_zalloc(mrt_cachep, GFP_KERNEL);
 	if (!c)
 		return NULL;
+	c->mfc_un.res.last_assert = jiffies - MFC_ASSERT_THRESH - 1;
 	c->mfc_un.res.minvif = MAXMIFS;
 	return c;
 }

[toc] | [prev] | [next] | [standalone]


#1438080 — [PATCH 4.6 04/31] sit: correct IP protocol used in ipip6_err

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:30 +0200
Subject[PATCH 4.6 04/31] sit: correct IP protocol used in ipip6_err
Message-ID<rS6iC-8uQ-39@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Simon Horman <simon.horman@netronome.com>

[ Upstream commit d5d8760b78d0cfafe292f965f599988138b06a70 ]

Since 32b8a8e59c9c ("sit: add IPv4 over IPv4 support")
ipip6_err() may be called for packets whose IP protocol is
IPPROTO_IPIP as well as those whose IP protocol is IPPROTO_IPV6.

In the case of IPPROTO_IPIP packets the correct protocol value is not
passed to ipv4_update_pmtu() or ipv4_redirect().

This patch resolves this problem by using the IP protocol of the packet
rather than a hard-coded value. This appears to be consistent
with the usage of the protocol of a packet by icmp_socket_deliver()
the caller of ipip6_err().

I was able to exercise the redirect case by using a setup where an ICMP
redirect was received for the destination of the encapsulated packet.
However, it appears that although incorrect the protocol field is not used
in this case and thus no problem manifests.  On inspection it does not
appear that a problem will manifest in the fragmentation needed/update pmtu
case either.

In short I believe this is a cosmetic fix. None the less, the use of
IPPROTO_IPV6 seems wrong and confusing.

Reviewed-by: Dinan Gunawardena <dinan.gunawardena@netronome.com>
Signed-off-by: Simon Horman <simon.horman@netronome.com>
Acked-by: YOSHIFUJI Hideaki <yoshfuji@linux-ipv6.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/ipv6/sit.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/net/ipv6/sit.c
+++ b/net/ipv6/sit.c
@@ -560,13 +560,13 @@ static int ipip6_err(struct sk_buff *skb
 
 	if (type == ICMP_DEST_UNREACH && code == ICMP_FRAG_NEEDED) {
 		ipv4_update_pmtu(skb, dev_net(skb->dev), info,
-				 t->parms.link, 0, IPPROTO_IPV6, 0);
+				 t->parms.link, 0, iph->protocol, 0);
 		err = 0;
 		goto out;
 	}
 	if (type == ICMP_REDIRECT) {
 		ipv4_redirect(skb, dev_net(skb->dev), t->parms.link, 0,
-			      IPPROTO_IPV6, 0);
+			      iph->protocol, 0);
 		err = 0;
 		goto out;
 	}

[toc] | [prev] | [next] | [standalone]


#1438097 — [PATCH 4.6 25/31] usb: xhci-plat: properly handle probe deferral for devm_clk_get()

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:40 +0200
Subject[PATCH 4.6 25/31] usb: xhci-plat: properly handle probe deferral for devm_clk_get()
Message-ID<rS6si-75-3@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>

commit de95c40d5beaa47f6dc8fe9ac4159b4672b51523 upstream.

On some platforms, the clocks might be registered by a platform
driver. When this is the case, the clock platform driver may very well
be probed after xhci-plat, in which case the first probe() invocation
of xhci-plat will receive -EPROBE_DEFER as the return value of
devm_clk_get().

The current code handles that as a normal error, and simply assumes
that this means that the system doesn't have a clock for the XHCI
controller, and continues probing without calling
clk_prepare_enable(). Unfortunately, this doesn't work on systems
where the XHCI controller does have a clock, but that clock is
provided by another platform driver. In order to fix this situation,
we handle the -EPROBE_DEFER error condition specially, and abort the
XHCI controller probe(). It will be retried later automatically, the
clock will be available, devm_clk_get() will succeed, and the probe()
will continue with the clock prepared and enabled as expected.

In practice, such issue is seen on the ARM64 Marvell 7K/8K platform,
where the clocks are registered by a platform driver.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/host/xhci-plat.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/usb/host/xhci-plat.c
+++ b/drivers/usb/host/xhci-plat.c
@@ -194,6 +194,9 @@ static int xhci_plat_probe(struct platfo
 		ret = clk_prepare_enable(clk);
 		if (ret)
 			goto put_hcd;
+	} else if (PTR_ERR(clk) == -EPROBE_DEFER) {
+		ret = -EPROBE_DEFER;
+		goto put_hcd;
 	}
 
 	xhci = hcd_to_xhci(hcd);

[toc] | [prev] | [next] | [standalone]


#1438098 — [PATCH 4.6 01/31] net_sched: fix pfifo_head_drop behavior vs backlog

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:40 +0200
Subject[PATCH 4.6 01/31] net_sched: fix pfifo_head_drop behavior vs backlog
Message-ID<rS6si-75-5@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 6c0d54f1897d229748d4f41ef919078db6db2123 ]

When the qdisc is full, we drop a packet at the head of the queue,
queue the current skb and return NET_XMIT_CN

Now we track backlog on upper qdiscs, we need to call
qdisc_tree_reduce_backlog(), even if the qlen did not change.

Fixes: 2ccccf5fb43f ("net_sched: update hierarchical backlog too")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: WANG Cong <xiyou.wangcong@gmail.com>
Cc: Jamal Hadi Salim <jhs@mojatatu.com>
Acked-by: Cong Wang <xiyou.wangcong@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/sched/sch_fifo.c |    4 ++++
 1 file changed, 4 insertions(+)

--- a/net/sched/sch_fifo.c
+++ b/net/sched/sch_fifo.c
@@ -37,14 +37,18 @@ static int pfifo_enqueue(struct sk_buff
 
 static int pfifo_tail_enqueue(struct sk_buff *skb, struct Qdisc *sch)
 {
+	unsigned int prev_backlog;
+
 	if (likely(skb_queue_len(&sch->q) < sch->limit))
 		return qdisc_enqueue_tail(skb, sch);
 
+	prev_backlog = sch->qstats.backlog;
 	/* queue full, remove one skb to fulfill the limit */
 	__qdisc_queue_drop_head(sch, &sch->q);
 	qdisc_qstats_drop(sch);
 	qdisc_enqueue_tail(skb, sch);
 
+	qdisc_tree_reduce_backlog(sch, 0, prev_backlog - sch->qstats.backlog);
 	return NET_XMIT_CN;
 }
 

[toc] | [prev] | [next] | [standalone]


#1438099 — [PATCH 4.6 23/31] usb: musb: host: correct cppi dma channel for isoch transfer

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:40 +0200
Subject[PATCH 4.6 23/31] usb: musb: host: correct cppi dma channel for isoch transfer
Message-ID<rS6si-75-7@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bin Liu <b-liu@ti.com>

commit 04471eb8c3158c0ad9df4b24da845a63b2e8f23a upstream.

Incorrect cppi dma channel is referenced in musb_rx_dma_iso_cppi41(),
which causes kernel NULL pointer reference oops later when calling
cppi41_dma_channel_program().

Fixes: 069a3fd (usb: musb: Remove ifdefs for musb_host_rx in musb_host.c
part1)

Reported-by: Matwey V. Kornilov <matwey@sai.msu.ru>
Acked-by: Tony Lindgren <tony@atomide.com>
Signed-off-by: Bin Liu <b-liu@ti.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/musb/musb_host.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/usb/musb/musb_host.c
+++ b/drivers/usb/musb/musb_host.c
@@ -1556,7 +1556,7 @@ static int musb_rx_dma_iso_cppi41(struct
 				  struct urb *urb,
 				  size_t len)
 {
-	struct dma_channel *channel = hw_ep->tx_channel;
+	struct dma_channel *channel = hw_ep->rx_channel;
 	void __iomem *epio = hw_ep->regs;
 	dma_addr_t *buf;
 	u32 length, res;

[toc] | [prev] | [next] | [standalone]


#1438100 — [PATCH 4.6 10/31] sock_diag: do not broadcast raw socket destruction

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:40 +0200
Subject[PATCH 4.6 10/31] sock_diag: do not broadcast raw socket destruction
Message-ID<rS6si-75-9@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Willem de Bruijn <willemb@google.com>

[ Upstream commit 9a0fee2b552b1235fb1706ae1fc664ae74573be8 ]

Diag intends to broadcast tcp_sk and udp_sk socket destruction.
Testing sk->sk_protocol for IPPROTO_TCP/IPPROTO_UDP alone is not
sufficient for this. Raw sockets can have the same type.

Add a test for sk->sk_type.

Fixes: eb4cb008529c ("sock_diag: define destruction multicast groups")
Signed-off-by: Willem de Bruijn <willemb@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 include/linux/sock_diag.h |    6 ++++++
 1 file changed, 6 insertions(+)

--- a/include/linux/sock_diag.h
+++ b/include/linux/sock_diag.h
@@ -36,6 +36,9 @@ enum sknetlink_groups sock_diag_destroy_
 {
 	switch (sk->sk_family) {
 	case AF_INET:
+		if (sk->sk_type == SOCK_RAW)
+			return SKNLGRP_NONE;
+
 		switch (sk->sk_protocol) {
 		case IPPROTO_TCP:
 			return SKNLGRP_INET_TCP_DESTROY;
@@ -45,6 +48,9 @@ enum sknetlink_groups sock_diag_destroy_
 			return SKNLGRP_NONE;
 		}
 	case AF_INET6:
+		if (sk->sk_type == SOCK_RAW)
+			return SKNLGRP_NONE;
+
 		switch (sk->sk_protocol) {
 		case IPPROTO_TCP:
 			return SKNLGRP_INET6_TCP_DESTROY;

[toc] | [prev] | [next] | [standalone]


#1438101 — [PATCH 4.6 18/31] usb: quirks: Fix sorting

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:40 +0200
Subject[PATCH 4.6 18/31] usb: quirks: Fix sorting
Message-ID<rS6si-75-11@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hans de Goede <hdegoede@redhat.com>

commit 81099f97bd31e25ff2719a435b1860fc3876122f upstream.

Properly sort all the entries by vendor id.

Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/core/quirks.c |   20 ++++++++++----------
 1 file changed, 10 insertions(+), 10 deletions(-)

--- a/drivers/usb/core/quirks.c
+++ b/drivers/usb/core/quirks.c
@@ -44,6 +44,9 @@ static const struct usb_device_id usb_qu
 	/* Creative SB Audigy 2 NX */
 	{ USB_DEVICE(0x041e, 0x3020), .driver_info = USB_QUIRK_RESET_RESUME },
 
+	/* USB3503 */
+	{ USB_DEVICE(0x0424, 0x3503), .driver_info = USB_QUIRK_RESET_RESUME },
+
 	/* Microsoft Wireless Laser Mouse 6000 Receiver */
 	{ USB_DEVICE(0x045e, 0x00e1), .driver_info = USB_QUIRK_RESET_RESUME },
 
@@ -173,6 +176,10 @@ static const struct usb_device_id usb_qu
 	/* MAYA44USB sound device */
 	{ USB_DEVICE(0x0a92, 0x0091), .driver_info = USB_QUIRK_RESET_RESUME },
 
+	/* ASUS Base Station(T100) */
+	{ USB_DEVICE(0x0b05, 0x17e0), .driver_info =
+			USB_QUIRK_IGNORE_REMOTE_WAKEUP },
+
 	/* Action Semiconductor flash disk */
 	{ USB_DEVICE(0x10d6, 0x2200), .driver_info =
 			USB_QUIRK_STRING_FETCH_255 },
@@ -188,16 +195,6 @@ static const struct usb_device_id usb_qu
 	{ USB_DEVICE(0x1908, 0x1315), .driver_info =
 			USB_QUIRK_HONOR_BNUMINTERFACES },
 
-	/* INTEL VALUE SSD */
-	{ USB_DEVICE(0x8086, 0xf1a5), .driver_info = USB_QUIRK_RESET_RESUME },
-
-	/* USB3503 */
-	{ USB_DEVICE(0x0424, 0x3503), .driver_info = USB_QUIRK_RESET_RESUME },
-
-	/* ASUS Base Station(T100) */
-	{ USB_DEVICE(0x0b05, 0x17e0), .driver_info =
-			USB_QUIRK_IGNORE_REMOTE_WAKEUP },
-
 	/* Protocol and OTG Electrical Test Device */
 	{ USB_DEVICE(0x1a0a, 0x0200), .driver_info =
 			USB_QUIRK_LINEAR_UFRAME_INTR_BINTERVAL },
@@ -208,6 +205,9 @@ static const struct usb_device_id usb_qu
 	/* Blackmagic Design UltraStudio SDI */
 	{ USB_DEVICE(0x1edb, 0xbd4f), .driver_info = USB_QUIRK_NO_LPM },
 
+	/* INTEL VALUE SSD */
+	{ USB_DEVICE(0x8086, 0xf1a5), .driver_info = USB_QUIRK_RESET_RESUME },
+
 	{ }  /* terminating entry must be last */
 };
 

[toc] | [prev] | [next] | [standalone]


#1438102 — [PATCH 4.6 27/31] xhci: Fix handling timeouted commands on hosts in weird states.

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:40 +0200
Subject[PATCH 4.6 27/31] xhci: Fix handling timeouted commands on hosts in weird states.
Message-ID<rS6si-75-15@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mathias Nyman <mathias.nyman@linux.intel.com>

commit 3425aa03f484d45dc21e0e791c2f6c74ea656421 upstream.

If commands timeout we mark them for abortion, then stop the command
ring, and turn the commands to no-ops and finally restart the command
ring.

If the host is working properly the no-op commands will finish and
pending completions are called.
If we notice the host is failing, driver clears the command ring and
completes, deletes and frees all pending commands.

There are two separate cases reported where host is believed to work
properly but is not. In the first case we successfully stop the ring
but no abort or stop command ring event is ever sent and host locks up.

The second case is if a host is removed, command times out and driver
believes the ring is stopped, and assumes it will be restarted, but
actually ends up timing out on the same command forever.
If one of the pending commands has the xhci->mutex held it will block
xhci_stop() in the remove codepath which otherwise would cleanup pending
commands.

Add a check that clears all pending commands in case host is removed,
or we are stuck timing out on the same command. Also restart the
command timeout timer when stopping the command ring to ensure we
recive an ring stop/abort event.

Tested-by: Joe Lawrence <joe.lawrence@stratus.com>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/host/xhci-ring.c |   27 ++++++++++++++++++++++-----
 1 file changed, 22 insertions(+), 5 deletions(-)

--- a/drivers/usb/host/xhci-ring.c
+++ b/drivers/usb/host/xhci-ring.c
@@ -290,6 +290,14 @@ static int xhci_abort_cmd_ring(struct xh
 
 	temp_64 = xhci_read_64(xhci, &xhci->op_regs->cmd_ring);
 	xhci->cmd_ring_state = CMD_RING_STATE_ABORTED;
+
+	/*
+	 * Writing the CMD_RING_ABORT bit should cause a cmd completion event,
+	 * however on some host hw the CMD_RING_RUNNING bit is correctly cleared
+	 * but the completion event in never sent. Use the cmd timeout timer to
+	 * handle those cases. Use twice the time to cover the bit polling retry
+	 */
+	mod_timer(&xhci->cmd_timer, jiffies + (2 * XHCI_CMD_DEFAULT_TIMEOUT));
 	xhci_write_64(xhci, temp_64 | CMD_RING_ABORT,
 			&xhci->op_regs->cmd_ring);
 
@@ -314,6 +322,7 @@ static int xhci_abort_cmd_ring(struct xh
 
 		xhci_err(xhci, "Stopped the command ring failed, "
 				"maybe the host is dead\n");
+		del_timer(&xhci->cmd_timer);
 		xhci->xhc_state |= XHCI_STATE_DYING;
 		xhci_quiesce(xhci);
 		xhci_halt(xhci);
@@ -1253,22 +1262,21 @@ void xhci_handle_command_timeout(unsigne
 	int ret;
 	unsigned long flags;
 	u64 hw_ring_state;
-	struct xhci_command *cur_cmd = NULL;
+	bool second_timeout = false;
 	xhci = (struct xhci_hcd *) data;
 
 	/* mark this command to be cancelled */
 	spin_lock_irqsave(&xhci->lock, flags);
 	if (xhci->current_cmd) {
-		cur_cmd = xhci->current_cmd;
-		cur_cmd->status = COMP_CMD_ABORT;
+		if (xhci->current_cmd->status == COMP_CMD_ABORT)
+			second_timeout = true;
+		xhci->current_cmd->status = COMP_CMD_ABORT;
 	}
 
-
 	/* Make sure command ring is running before aborting it */
 	hw_ring_state = xhci_read_64(xhci, &xhci->op_regs->cmd_ring);
 	if ((xhci->cmd_ring_state & CMD_RING_STATE_RUNNING) &&
 	    (hw_ring_state & CMD_RING_RUNNING))  {
-
 		spin_unlock_irqrestore(&xhci->lock, flags);
 		xhci_dbg(xhci, "Command timeout\n");
 		ret = xhci_abort_cmd_ring(xhci);
@@ -1280,6 +1288,15 @@ void xhci_handle_command_timeout(unsigne
 		}
 		return;
 	}
+
+	/* command ring failed to restart, or host removed. Bail out */
+	if (second_timeout || xhci->xhc_state & XHCI_STATE_REMOVING) {
+		spin_unlock_irqrestore(&xhci->lock, flags);
+		xhci_dbg(xhci, "command timed out twice, ring start fail?\n");
+		xhci_cleanup_command_queue(xhci);
+		return;
+	}
+
 	/* command timeout on stopped ring, ring can't be aborted */
 	xhci_dbg(xhci, "Command timeout on stopped ring\n");
 	xhci_handle_stopped_cmd_ring(xhci, xhci->current_cmd);

[toc] | [prev] | [next] | [standalone]


#1438103 — [PATCH 4.6 16/31] crypto: user - re-add size check for CRYPTO_MSG_GETALG

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:40 +0200
Subject[PATCH 4.6 16/31] crypto: user - re-add size check for CRYPTO_MSG_GETALG
Message-ID<rS6si-75-17@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mathias Krause <minipli@googlemail.com>

commit 055ddaace03580455a7b7dbea8e93d62acee61fc upstream.

Commit 9aa867e46565 ("crypto: user - Add CRYPTO_MSG_DELRNG")
accidentally removed the minimum size check for CRYPTO_MSG_GETALG
netlink messages. This allows userland to send a truncated
CRYPTO_MSG_GETALG message as short as a netlink header only making
crypto_report() operate on uninitialized memory by accessing data
beyond the end of the netlink message.

Fix this be re-adding the minimum required size of CRYPTO_MSG_GETALG
messages to the crypto_msg_min[] array.

Fixes: 9aa867e46565 ("crypto: user - Add CRYPTO_MSG_DELRNG")
Signed-off-by: Mathias Krause <minipli@googlemail.com>
Cc: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 crypto/crypto_user.c |    1 +
 1 file changed, 1 insertion(+)

--- a/crypto/crypto_user.c
+++ b/crypto/crypto_user.c
@@ -455,6 +455,7 @@ static const int crypto_msg_min[CRYPTO_N
 	[CRYPTO_MSG_NEWALG	- CRYPTO_MSG_BASE] = MSGSIZE(crypto_user_alg),
 	[CRYPTO_MSG_DELALG	- CRYPTO_MSG_BASE] = MSGSIZE(crypto_user_alg),
 	[CRYPTO_MSG_UPDATEALG	- CRYPTO_MSG_BASE] = MSGSIZE(crypto_user_alg),
+	[CRYPTO_MSG_GETALG	- CRYPTO_MSG_BASE] = MSGSIZE(crypto_user_alg),
 	[CRYPTO_MSG_DELRNG	- CRYPTO_MSG_BASE] = 0,
 };
 

[toc] | [prev] | [next] | [standalone]


#1438104 — [PATCH 4.6 30/31] usb: host: ehci-tegra: Grab the correct UTMI pads reset

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:40 +0200
Subject[PATCH 4.6 30/31] usb: host: ehci-tegra: Grab the correct UTMI pads reset
Message-ID<rS6si-75-21@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thierry Reding <treding@nvidia.com>

commit f8a15a9650694feaa0dabf197b0c94d37cd3fb42 upstream.

There are three EHCI controllers on Tegra SoCs, each with its own reset
line. However, the first controller contains a set of UTMI configuration
registers that are shared with its siblings. These registers will only
be reset as part of the first controller's reset. For proper operation
it must be ensured that the UTMI configuration registers are reset
before any of the EHCI controllers are enabled, irrespective of the
probe order.

Commit a47cc24cd1e5 ("USB: EHCI: tegra: Fix probe order issue leading to
broken USB") introduced code that ensures the first controller is always
reset before setting up any of the controllers, and is never again reset
afterwards.

This code, however, grabs the wrong reset. Each EHCI controller has two
reset controls attached: 1) the USB controller reset and 2) the UTMI
pads reset (really the first controller's reset). In order to reset the
UTMI pads registers the code must grab the second reset, but instead it
grabbing the first.

Fixes: a47cc24cd1e5 ("USB: EHCI: tegra: Fix probe order issue leading to broken USB")
Acked-by: Jon Hunter <jonathanh@nvidia.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/host/ehci-tegra.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/usb/host/ehci-tegra.c
+++ b/drivers/usb/host/ehci-tegra.c
@@ -89,7 +89,7 @@ static int tegra_reset_usb_controller(st
 	if (!usb1_reset_attempted) {
 		struct reset_control *usb1_reset;
 
-		usb1_reset = of_reset_control_get(phy_np, "usb");
+		usb1_reset = of_reset_control_get(phy_np, "utmi-pads");
 		if (IS_ERR(usb1_reset)) {
 			dev_warn(&pdev->dev,
 				 "can't get utmi-pads reset from the PHY\n");

[toc] | [prev] | [next] | [standalone]


#1438105 — [PATCH 4.6 19/31] usb: quirks: Add no-lpm quirk for Acer C120 LED Projector

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:40 +0200
Subject[PATCH 4.6 19/31] usb: quirks: Add no-lpm quirk for Acer C120 LED Projector
Message-ID<rS6si-75-19@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hans de Goede <hdegoede@redhat.com>

commit 32cb0b37098f4beeff5ad9e325f11b42a6ede56c upstream.

The Acer C120 LED Projector is a USB-3 connected pico projector which
takes both its power and video data from USB-3.

In combination with some hubs this device does not play well with
lpm, so disable lpm for it.

Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/core/quirks.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/usb/core/quirks.c
+++ b/drivers/usb/core/quirks.c
@@ -199,6 +199,9 @@ static const struct usb_device_id usb_qu
 	{ USB_DEVICE(0x1a0a, 0x0200), .driver_info =
 			USB_QUIRK_LINEAR_UFRAME_INTR_BINTERVAL },
 
+	/* Acer C120 LED Projector */
+	{ USB_DEVICE(0x1de1, 0xc102), .driver_info = USB_QUIRK_NO_LPM },
+
 	/* Blackmagic Design Intensity Shuttle */
 	{ USB_DEVICE(0x1edb, 0xbd3b), .driver_info = USB_QUIRK_NO_LPM },
 

[toc] | [prev] | [next] | [standalone]


#1438106 — [PATCH 4.6 21/31] usb: musb: Stop bulk endpoint while queue is rotated

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:40 +0200
Subject[PATCH 4.6 21/31] usb: musb: Stop bulk endpoint while queue is rotated
Message-ID<rS6si-75-13@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Andrew Goodbody <andrew.goodbody@cambrionix.com>

commit 7b2c17f829545df27a910e8d82e133c21c9a8c9c upstream.

Ensure that the endpoint is stopped by clearing REQPKT before
clearing DATAERR_NAKTIMEOUT before rotating the queue on the
dedicated bulk endpoint.
This addresses an issue where a race could result in the endpoint
receiving data before it was reprogrammed resulting in a warning
about such data from musb_rx_reinit before it was thrown away.
The data thrown away was a valid packet that had been correctly
ACKed which meant the host and device got out of sync.

Signed-off-by: Andrew Goodbody <andrew.goodbody@cambrionix.com>
Signed-off-by: Bin Liu <b-liu@ti.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/musb/musb_host.c |    8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

--- a/drivers/usb/musb/musb_host.c
+++ b/drivers/usb/musb/musb_host.c
@@ -995,9 +995,15 @@ static void musb_bulk_nak_timeout(struct
 	if (is_in) {
 		dma = is_dma_capable() ? ep->rx_channel : NULL;
 
-		/* clear nak timeout bit */
+		/*
+		 * Need to stop the transaction by clearing REQPKT first
+		 * then the NAK Timeout bit ref MUSBMHDRC USB 2.0 HIGH-SPEED
+		 * DUAL-ROLE CONTROLLER Programmer's Guide, section 9.2.2
+		 */
 		rx_csr = musb_readw(epio, MUSB_RXCSR);
 		rx_csr |= MUSB_RXCSR_H_WZC_BITS;
+		rx_csr &= ~MUSB_RXCSR_H_REQPKT;
+		musb_writew(epio, MUSB_RXCSR, rx_csr);
 		rx_csr &= ~MUSB_RXCSR_DATAERROR;
 		musb_writew(epio, MUSB_RXCSR, rx_csr);
 

[toc] | [prev] | [next] | [standalone]


#1438107 — [PATCH 4.6 14/31] crypto: vmx - Increase priority of aes-cbc cipher

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:40 +0200
Subject[PATCH 4.6 14/31] crypto: vmx - Increase priority of aes-cbc cipher
Message-ID<rS6si-75-23@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Anton Blanchard <anton@samba.org>

commit 12d3f49e1ffbbf8cbbb60acae5a21103c5c841ac upstream.

All of the VMX AES ciphers (AES, AES-CBC and AES-CTR) are set at
priority 1000. Unfortunately this means we never use AES-CBC and
AES-CTR, because the base AES-CBC cipher that is implemented on
top of AES inherits its priority.

To fix this, AES-CBC and AES-CTR have to be a higher priority. Set
them to 2000.

Testing on a POWER8 with:

cryptsetup benchmark --cipher aes --key-size 256

Shows decryption speed increase from 402.4 MB/s to 3069.2 MB/s,
over 7x faster. Thanks to Mike Strosaker for helping me debug
this issue.

Fixes: 8c755ace357c ("crypto: vmx - Adding CBC routines for VMX module")
Signed-off-by: Anton Blanchard <anton@samba.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/crypto/vmx/aes_cbc.c |    2 +-
 drivers/crypto/vmx/aes_ctr.c |    2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/crypto/vmx/aes_cbc.c
+++ b/drivers/crypto/vmx/aes_cbc.c
@@ -182,7 +182,7 @@ struct crypto_alg p8_aes_cbc_alg = {
 	.cra_name = "cbc(aes)",
 	.cra_driver_name = "p8_aes_cbc",
 	.cra_module = THIS_MODULE,
-	.cra_priority = 1000,
+	.cra_priority = 2000,
 	.cra_type = &crypto_blkcipher_type,
 	.cra_flags = CRYPTO_ALG_TYPE_BLKCIPHER | CRYPTO_ALG_NEED_FALLBACK,
 	.cra_alignmask = 0,
--- a/drivers/crypto/vmx/aes_ctr.c
+++ b/drivers/crypto/vmx/aes_ctr.c
@@ -166,7 +166,7 @@ struct crypto_alg p8_aes_ctr_alg = {
 	.cra_name = "ctr(aes)",
 	.cra_driver_name = "p8_aes_ctr",
 	.cra_module = THIS_MODULE,
-	.cra_priority = 1000,
+	.cra_priority = 2000,
 	.cra_type = &crypto_blkcipher_type,
 	.cra_flags = CRYPTO_ALG_TYPE_BLKCIPHER | CRYPTO_ALG_NEED_FALLBACK,
 	.cra_alignmask = 0,

[toc] | [prev] | [next] | [standalone]


#1438108 — [PATCH 4.6 26/31] USB: xhci: Add broken streams quirk for Frescologic device id 1009

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-07 03:40 +0200
Subject[PATCH 4.6 26/31] USB: xhci: Add broken streams quirk for Frescologic device id 1009
Message-ID<rS6si-75-29@gated-at.bofh.it>
In reply to#1438055
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hans de Goede <hdegoede@redhat.com>

commit d95815ba6a0f287213118c136e64d8c56daeaeab upstream.

I got one of these cards for testing uas with, it seems that with streams
it dma-s all over the place, corrupting memory. On my first tests it
managed to dma over the BIOS of the motherboard somehow and completely
bricked it.

Tests on another motherboard show that it does work with streams disabled.

Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/host/xhci-pci.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/drivers/usb/host/xhci-pci.c
+++ b/drivers/usb/host/xhci-pci.c
@@ -37,6 +37,7 @@
 /* Device for a quirk */
 #define PCI_VENDOR_ID_FRESCO_LOGIC	0x1b73
 #define PCI_DEVICE_ID_FRESCO_LOGIC_PDK	0x1000
+#define PCI_DEVICE_ID_FRESCO_LOGIC_FL1009	0x1009
 #define PCI_DEVICE_ID_FRESCO_LOGIC_FL1400	0x1400
 
 #define PCI_VENDOR_ID_ETRON		0x1b6f
@@ -114,6 +115,10 @@ static void xhci_pci_quirks(struct devic
 		xhci->quirks |= XHCI_TRUST_TX_LENGTH;
 	}
 
+	if (pdev->vendor == PCI_VENDOR_ID_FRESCO_LOGIC &&
+			pdev->device == PCI_DEVICE_ID_FRESCO_LOGIC_FL1009)
+		xhci->quirks |= XHCI_BROKEN_STREAMS;
+
 	if (pdev->vendor == PCI_VENDOR_ID_NEC)
 		xhci->quirks |= XHCI_NEC_HOST;
 

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.kernel


csiph-web