Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1438082 > unrolled thread
| Started by | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| First post | 2016-07-07 03:30 +0200 |
| Last post | 2016-07-08 05:50 +0200 |
| Articles | 20 on this page of 22 — 5 participants |
Back to article view | Back to linux.kernel
[PATCH 4.4 00/32] 4.4.15-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
[PATCH 4.4 28/32] xhci: Fix handling timeouted commands on hosts in weird states. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
[PATCH 4.4 31/32] usb: host: ehci-tegra: Grab the correct UTMI pads reset Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
[PATCH 4.4 01/32] net_sched: fix pfifo_head_drop behavior vs backlog Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
[PATCH 4.4 25/32] xhci: Cleanup only when releasing primary hcd Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
[PATCH 4.4 23/32] usb: musb: Ensure rx reinit occurs for shared_fifo endpoints Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
[PATCH 4.4 14/32] AX.25: Close socket connection on session completion Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
[PATCH 4.4 13/32] bpf: try harder on clones when writing into skb Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
[PATCH 4.4 20/32] usb: quirks: Add no-lpm quirk for Acer C120 LED Projector Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
[PATCH 4.4 18/32] USB: uas: Fix slave queue_depth not being set Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
[PATCH 4.4 15/32] crypto: vmx - Increase priority of aes-cbc cipher Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
[PATCH 4.4 10/32] neigh: Explicitly declare RCU-bh read side critical section in neigh_xmit() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
[PATCH 4.4 05/32] netem: fix a use after free Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 03:30 +0200
Re: [PATCH 4.4 00/32] 4.4.15-stable review Nikolay Borisov <kernel@kyup.com> - 2016-07-07 10:10 +0200
Re: [PATCH 4.4 00/32] 4.4.15-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 21:20 +0200
Re: [PATCH 4.4 00/32] 4.4.15-stable review Guenter Roeck <linux@roeck-us.net> - 2016-07-07 15:40 +0200
Re: [PATCH 4.4 00/32] 4.4.15-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 21:20 +0200
Re: [PATCH 4.4 00/32] 4.4.15-stable review Kevin Hilman <khilman@baylibre.com> - 2016-07-07 19:00 +0200
Re: [PATCH 4.4 00/32] 4.4.15-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-07 21:20 +0200
Re: [PATCH 4.4 00/32] 4.4.15-stable review Kevin Hilman <khilman@baylibre.com> - 2016-07-08 00:30 +0200
Re: [PATCH 4.4 00/32] 4.4.15-stable review Kevin Hilman <khilman@baylibre.com> - 2016-07-07 20:00 +0200
Re: [PATCH 4.4 00/32] 4.4.15-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-07-08 05:50 +0200
Page 1 of 2 [1] 2 Next page →
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 03:30 +0200 |
| Subject | [PATCH 4.4 00/32] 4.4.15-stable review |
| Message-ID | <rS6iB-8uQ-5@gated-at.bofh.it> |
This is the start of the stable review cycle for the 4.4.15 release.
There are 32 patches in this series, all will be posted as a response
to this one. If anyone has any issues with these being applied, please
let me know.
Responses should be made by Sat Jul 9 01:16:17 UTC 2016.
Anything received after that time might be too late.
The whole patch series can be found in one patch at:
kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.4.15-rc1.gz
or in the git tree and branch at:
git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.4.y
and the diffstat can be found below.
thanks,
greg k-h
-------------
Pseudo-Shortlog of commits:
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Linux 4.4.15-rc1
Steinar H. Gunderson <sesse@google.com>
usb: dwc3: exynos: Fix deferred probing storm.
Thierry Reding <treding@nvidia.com>
usb: host: ehci-tegra: Grab the correct UTMI pads reset
Bin Liu <b-liu@ti.com>
usb: gadget: fix spinlock dead lock in gadgetfs
Sudip Mukherjee <sudipm.mukherjee@gmail.com>
USB: mos7720: delete parport
Mathias Nyman <mathias.nyman@linux.intel.com>
xhci: Fix handling timeouted commands on hosts in weird states.
Hans de Goede <hdegoede@redhat.com>
USB: xhci: Add broken streams quirk for Frescologic device id 1009
Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
usb: xhci-plat: properly handle probe deferral for devm_clk_get()
Gabriel Krisman Bertazi <krisman@linux.vnet.ibm.com>
xhci: Cleanup only when releasing primary hcd
Bin Liu <b-liu@ti.com>
usb: musb: host: correct cppi dma channel for isoch transfer
Andrew Goodbody <andrew.goodbody@cambrionix.com>
usb: musb: Ensure rx reinit occurs for shared_fifo endpoints
Andrew Goodbody <andrew.goodbody@cambrionix.com>
usb: musb: Stop bulk endpoint while queue is rotated
Bin Liu <b-liu@ti.com>
usb: musb: only restore devctl when session was set in backup
Hans de Goede <hdegoede@redhat.com>
usb: quirks: Add no-lpm quirk for Acer C120 LED Projector
Hans de Goede <hdegoede@redhat.com>
usb: quirks: Fix sorting
Hans de Goede <hdegoede@redhat.com>
USB: uas: Fix slave queue_depth not being set
Mathias Krause <minipli@googlemail.com>
crypto: user - re-add size check for CRYPTO_MSG_GETALG
Linus Walleij <linus.walleij@linaro.org>
crypto: ux500 - memmove the right size
Anton Blanchard <anton@samba.org>
crypto: vmx - Increase priority of aes-cbc cipher
Basil Gunn <basil@pacabunga.com>
AX.25: Close socket connection on session completion
Daniel Borkmann <daniel@iogearbox.net>
bpf: try harder on clones when writing into skb
Feng Tang <feng.tang@intel.com>
net: alx: Work around the DMA RX overflow issue
Nicolas Ferre <nicolas.ferre@atmel.com>
net: macb: fix default configuration for GMAC on AT91
David Barroso <dbarroso@fastly.com>
neigh: Explicitly declare RCU-bh read side critical section in neigh_xmit()
Daniel Borkmann <daniel@iogearbox.net>
bpf, perf: delay release of BPF prog after grace period
Willem de Bruijn <willemb@google.com>
sock_diag: do not broadcast raw socket destruction
daniel <daniel@dd-wrt.com>
Bridge: Fix ipv6 mc snooping if bridge has no ipv6 address
Tom Goff <thomas.goff@ll.mit.edu>
ipmr/ip6mr: Initialize the last assert time of mfc entries.
Eric Dumazet <edumazet@google.com>
netem: fix a use after free
Herbert Xu <herbert@gondor.apana.org.au>
esp: Fix ESN generation under UDP encapsulation
Simon Horman <simon.horman@netronome.com>
sit: correct IP protocol used in ipip6_err
Jason A. Donenfeld <Jason@zx2c4.com>
net: Don't forget pr_fmt on net_dbg_ratelimited for CONFIG_DYNAMIC_DEBUG
Eric Dumazet <edumazet@google.com>
net_sched: fix pfifo_head_drop behavior vs backlog
-------------
Diffstat:
Makefile | 4 +--
crypto/crypto_user.c | 1 +
drivers/crypto/ux500/hash/hash_core.c | 4 +--
drivers/crypto/vmx/aes_cbc.c | 2 +-
drivers/crypto/vmx/aes_ctr.c | 2 +-
drivers/net/ethernet/atheros/alx/main.c | 7 ++++-
drivers/net/ethernet/cadence/macb.c | 13 +++++----
drivers/net/ethernet/cadence/macb.h | 2 +-
drivers/usb/core/quirks.c | 23 ++++++++-------
drivers/usb/dwc3/dwc3-exynos.c | 19 +++++++-----
drivers/usb/gadget/legacy/inode.c | 17 ++++++++---
drivers/usb/host/ehci-tegra.c | 2 +-
drivers/usb/host/xhci-pci.c | 5 ++++
drivers/usb/host/xhci-plat.c | 3 ++
drivers/usb/host/xhci-ring.c | 30 +++++++++++++++----
drivers/usb/host/xhci.c | 27 +++++++++--------
drivers/usb/musb/musb_core.c | 3 +-
drivers/usb/musb/musb_host.c | 23 +++++++++------
drivers/usb/serial/mos7720.c | 1 +
drivers/usb/storage/uas.c | 1 +
include/linux/bpf.h | 4 +++
include/linux/net.h | 3 +-
include/linux/skbuff.h | 7 +++++
include/linux/sock_diag.h | 6 ++++
kernel/events/core.c | 2 +-
net/ax25/af_ax25.c | 3 +-
net/ax25/ax25_ds_timer.c | 5 +++-
net/ax25/ax25_std_timer.c | 5 +++-
net/ax25/ax25_subr.c | 3 +-
net/bridge/br_multicast.c | 4 +++
net/bridge/br_private.h | 23 ++++++++++++---
net/core/filter.c | 18 +++++++-----
net/core/neighbour.c | 6 +++-
net/ipv4/esp4.c | 52 ++++++++++++++++++++-------------
net/ipv4/ipmr.c | 4 ++-
net/ipv6/ip6mr.c | 1 +
net/ipv6/sit.c | 4 +--
net/sched/act_csum.c | 8 ++---
net/sched/act_nat.c | 18 ++++--------
net/sched/sch_fifo.c | 4 +++
net/sched/sch_netem.c | 12 ++++----
41 files changed, 249 insertions(+), 132 deletions(-)
[toc] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 03:30 +0200 |
| Subject | [PATCH 4.4 28/32] xhci: Fix handling timeouted commands on hosts in weird states. |
| Message-ID | <rS6iC-8uQ-51@gated-at.bofh.it> |
| In reply to | #1438082 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mathias Nyman <mathias.nyman@linux.intel.com>
commit 3425aa03f484d45dc21e0e791c2f6c74ea656421 upstream.
If commands timeout we mark them for abortion, then stop the command
ring, and turn the commands to no-ops and finally restart the command
ring.
If the host is working properly the no-op commands will finish and
pending completions are called.
If we notice the host is failing, driver clears the command ring and
completes, deletes and frees all pending commands.
There are two separate cases reported where host is believed to work
properly but is not. In the first case we successfully stop the ring
but no abort or stop command ring event is ever sent and host locks up.
The second case is if a host is removed, command times out and driver
believes the ring is stopped, and assumes it will be restarted, but
actually ends up timing out on the same command forever.
If one of the pending commands has the xhci->mutex held it will block
xhci_stop() in the remove codepath which otherwise would cleanup pending
commands.
Add a check that clears all pending commands in case host is removed,
or we are stuck timing out on the same command. Also restart the
command timeout timer when stopping the command ring to ensure we
recive an ring stop/abort event.
Tested-by: Joe Lawrence <joe.lawrence@stratus.com>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/usb/host/xhci-ring.c | 27 ++++++++++++++++++++++-----
1 file changed, 22 insertions(+), 5 deletions(-)
--- a/drivers/usb/host/xhci-ring.c
+++ b/drivers/usb/host/xhci-ring.c
@@ -289,6 +289,14 @@ static int xhci_abort_cmd_ring(struct xh
temp_64 = xhci_read_64(xhci, &xhci->op_regs->cmd_ring);
xhci->cmd_ring_state = CMD_RING_STATE_ABORTED;
+
+ /*
+ * Writing the CMD_RING_ABORT bit should cause a cmd completion event,
+ * however on some host hw the CMD_RING_RUNNING bit is correctly cleared
+ * but the completion event in never sent. Use the cmd timeout timer to
+ * handle those cases. Use twice the time to cover the bit polling retry
+ */
+ mod_timer(&xhci->cmd_timer, jiffies + (2 * XHCI_CMD_DEFAULT_TIMEOUT));
xhci_write_64(xhci, temp_64 | CMD_RING_ABORT,
&xhci->op_regs->cmd_ring);
@@ -313,6 +321,7 @@ static int xhci_abort_cmd_ring(struct xh
xhci_err(xhci, "Stopped the command ring failed, "
"maybe the host is dead\n");
+ del_timer(&xhci->cmd_timer);
xhci->xhc_state |= XHCI_STATE_DYING;
xhci_quiesce(xhci);
xhci_halt(xhci);
@@ -1252,22 +1261,21 @@ void xhci_handle_command_timeout(unsigne
int ret;
unsigned long flags;
u64 hw_ring_state;
- struct xhci_command *cur_cmd = NULL;
+ bool second_timeout = false;
xhci = (struct xhci_hcd *) data;
/* mark this command to be cancelled */
spin_lock_irqsave(&xhci->lock, flags);
if (xhci->current_cmd) {
- cur_cmd = xhci->current_cmd;
- cur_cmd->status = COMP_CMD_ABORT;
+ if (xhci->current_cmd->status == COMP_CMD_ABORT)
+ second_timeout = true;
+ xhci->current_cmd->status = COMP_CMD_ABORT;
}
-
/* Make sure command ring is running before aborting it */
hw_ring_state = xhci_read_64(xhci, &xhci->op_regs->cmd_ring);
if ((xhci->cmd_ring_state & CMD_RING_STATE_RUNNING) &&
(hw_ring_state & CMD_RING_RUNNING)) {
-
spin_unlock_irqrestore(&xhci->lock, flags);
xhci_dbg(xhci, "Command timeout\n");
ret = xhci_abort_cmd_ring(xhci);
@@ -1279,6 +1287,15 @@ void xhci_handle_command_timeout(unsigne
}
return;
}
+
+ /* command ring failed to restart, or host removed. Bail out */
+ if (second_timeout || xhci->xhc_state & XHCI_STATE_REMOVING) {
+ spin_unlock_irqrestore(&xhci->lock, flags);
+ xhci_dbg(xhci, "command timed out twice, ring start fail?\n");
+ xhci_cleanup_command_queue(xhci);
+ return;
+ }
+
/* command timeout on stopped ring, ring can't be aborted */
xhci_dbg(xhci, "Command timeout on stopped ring\n");
xhci_handle_stopped_cmd_ring(xhci, xhci->current_cmd);
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 03:30 +0200 |
| Subject | [PATCH 4.4 31/32] usb: host: ehci-tegra: Grab the correct UTMI pads reset |
| Message-ID | <rS6iC-8uQ-49@gated-at.bofh.it> |
| In reply to | #1438082 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thierry Reding <treding@nvidia.com>
commit f8a15a9650694feaa0dabf197b0c94d37cd3fb42 upstream.
There are three EHCI controllers on Tegra SoCs, each with its own reset
line. However, the first controller contains a set of UTMI configuration
registers that are shared with its siblings. These registers will only
be reset as part of the first controller's reset. For proper operation
it must be ensured that the UTMI configuration registers are reset
before any of the EHCI controllers are enabled, irrespective of the
probe order.
Commit a47cc24cd1e5 ("USB: EHCI: tegra: Fix probe order issue leading to
broken USB") introduced code that ensures the first controller is always
reset before setting up any of the controllers, and is never again reset
afterwards.
This code, however, grabs the wrong reset. Each EHCI controller has two
reset controls attached: 1) the USB controller reset and 2) the UTMI
pads reset (really the first controller's reset). In order to reset the
UTMI pads registers the code must grab the second reset, but instead it
grabbing the first.
Fixes: a47cc24cd1e5 ("USB: EHCI: tegra: Fix probe order issue leading to broken USB")
Acked-by: Jon Hunter <jonathanh@nvidia.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/usb/host/ehci-tegra.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/usb/host/ehci-tegra.c
+++ b/drivers/usb/host/ehci-tegra.c
@@ -89,7 +89,7 @@ static int tegra_reset_usb_controller(st
if (!usb1_reset_attempted) {
struct reset_control *usb1_reset;
- usb1_reset = of_reset_control_get(phy_np, "usb");
+ usb1_reset = of_reset_control_get(phy_np, "utmi-pads");
if (IS_ERR(usb1_reset)) {
dev_warn(&pdev->dev,
"can't get utmi-pads reset from the PHY\n");
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 03:30 +0200 |
| Subject | [PATCH 4.4 01/32] net_sched: fix pfifo_head_drop behavior vs backlog |
| Message-ID | <rS6iD-8uQ-67@gated-at.bofh.it> |
| In reply to | #1438082 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 6c0d54f1897d229748d4f41ef919078db6db2123 ]
When the qdisc is full, we drop a packet at the head of the queue,
queue the current skb and return NET_XMIT_CN
Now we track backlog on upper qdiscs, we need to call
qdisc_tree_reduce_backlog(), even if the qlen did not change.
Fixes: 2ccccf5fb43f ("net_sched: update hierarchical backlog too")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: WANG Cong <xiyou.wangcong@gmail.com>
Cc: Jamal Hadi Salim <jhs@mojatatu.com>
Acked-by: Cong Wang <xiyou.wangcong@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sched/sch_fifo.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/net/sched/sch_fifo.c
+++ b/net/sched/sch_fifo.c
@@ -37,14 +37,18 @@ static int pfifo_enqueue(struct sk_buff
static int pfifo_tail_enqueue(struct sk_buff *skb, struct Qdisc *sch)
{
+ unsigned int prev_backlog;
+
if (likely(skb_queue_len(&sch->q) < sch->limit))
return qdisc_enqueue_tail(skb, sch);
+ prev_backlog = sch->qstats.backlog;
/* queue full, remove one skb to fulfill the limit */
__qdisc_queue_drop_head(sch, &sch->q);
qdisc_qstats_drop(sch);
qdisc_enqueue_tail(skb, sch);
+ qdisc_tree_reduce_backlog(sch, 0, prev_backlog - sch->qstats.backlog);
return NET_XMIT_CN;
}
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 03:30 +0200 |
| Subject | [PATCH 4.4 25/32] xhci: Cleanup only when releasing primary hcd |
| Message-ID | <rS6iC-8uQ-53@gated-at.bofh.it> |
| In reply to | #1438082 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gabriel Krisman Bertazi <krisman@linux.vnet.ibm.com>
commit 27a41a83ec54d0edfcaf079310244e7f013a7701 upstream.
Under stress occasions some TI devices might not return early when
reading the status register during the quirk invocation of xhci_irq made
by usb_hcd_pci_remove. This means that instead of returning, we end up
handling this interruption in the middle of a shutdown. Since
xhci->event_ring has already been freed in xhci_mem_cleanup, we end up
accessing freed memory, causing the Oops below.
commit 8c24d6d7b09d ("usb: xhci: stop everything on the first call to
xhci_stop") is the one that changed the instant in which we clean up the
event queue when stopping a device. Before, we didn't call
xhci_mem_cleanup at the first time xhci_stop is executed (for the shared
HCD), instead, we only did it after the invocation for the primary HCD,
much later at the removal path. The code flow for this oops looks like
this:
xhci_pci_remove()
usb_remove_hcd(xhci->shared)
xhci_stop(xhci->shared)
xhci_halt()
xhci_mem_cleanup(xhci); // Free the event_queue
usb_hcd_pci_remove(primary)
xhci_irq() // Access the event_queue if STS_EINT is set. Crash.
xhci_stop()
xhci_halt()
// return early
The fix modifies xhci_stop to only cleanup the xhci data when releasing
the primary HCD. This way, we still have the event_queue configured
when invoking xhci_irq. We still halt the device on the first call to
xhci_stop, though.
I could reproduce this issue several times on the mainline kernel by
doing a bind-unbind stress test with a specific storage gadget attached.
I also ran the same test over-night with my patch applied and didn't
observe the issue anymore.
[ 113.334124] Unable to handle kernel paging request for data at address 0x00000028
[ 113.335514] Faulting instruction address: 0xd00000000d4f767c
[ 113.336839] Oops: Kernel access of bad area, sig: 11 [#1]
[ 113.338214] SMP NR_CPUS=1024 NUMA PowerNV
[c000000efe47ba90] c000000000720850 usb_hcd_irq+0x50/0x80
[c000000efe47bac0] c00000000073d328 usb_hcd_pci_remove+0x68/0x1f0
[c000000efe47bb00] d00000000daf0128 xhci_pci_remove+0x78/0xb0
[xhci_pci]
[c000000efe47bb30] c00000000055cf70 pci_device_remove+0x70/0x110
[c000000efe47bb70] c00000000061c6bc __device_release_driver+0xbc/0x190
[c000000efe47bba0] c00000000061c7d0 device_release_driver+0x40/0x70
[c000000efe47bbd0] c000000000619510 unbind_store+0x120/0x150
[c000000efe47bc20] c0000000006183c4 drv_attr_store+0x64/0xa0
[c000000efe47bc60] c00000000039f1d0 sysfs_kf_write+0x80/0xb0
[c000000efe47bca0] c00000000039e14c kernfs_fop_write+0x18c/0x1f0
[c000000efe47bcf0] c0000000002e962c __vfs_write+0x6c/0x190
[c000000efe47bd90] c0000000002eab40 vfs_write+0xc0/0x200
[c000000efe47bde0] c0000000002ec85c SyS_write+0x6c/0x110
[c000000efe47be30] c000000000009260 system_call+0x38/0x108
Signed-off-by: Gabriel Krisman Bertazi <krisman@linux.vnet.ibm.com>
Cc: Roger Quadros <rogerq@ti.com>
Cc: joel@jms.id.au
Reviewed-by: Roger Quadros <rogerq@ti.com>
Tested-by: Joel Stanley <joel@jms.id.au>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/usb/host/xhci-ring.c | 3 ++-
drivers/usb/host/xhci.c | 29 ++++++++++++++++-------------
2 files changed, 18 insertions(+), 14 deletions(-)
--- a/drivers/usb/host/xhci-ring.c
+++ b/drivers/usb/host/xhci-ring.c
@@ -2727,7 +2727,8 @@ hw_died:
writel(irq_pending, &xhci->ir_set->irq_pending);
}
- if (xhci->xhc_state & XHCI_STATE_DYING) {
+ if (xhci->xhc_state & XHCI_STATE_DYING ||
+ xhci->xhc_state & XHCI_STATE_HALTED) {
xhci_dbg(xhci, "xHCI dying, ignoring interrupt. "
"Shouldn't IRQs be disabled?\n");
/* Clear the event handler busy flag (RW1C);
--- a/drivers/usb/host/xhci.c
+++ b/drivers/usb/host/xhci.c
@@ -680,20 +680,23 @@ void xhci_stop(struct usb_hcd *hcd)
u32 temp;
struct xhci_hcd *xhci = hcd_to_xhci(hcd);
- if (xhci->xhc_state & XHCI_STATE_HALTED)
- return;
-
mutex_lock(&xhci->mutex);
- spin_lock_irq(&xhci->lock);
- xhci->xhc_state |= XHCI_STATE_HALTED;
- xhci->cmd_ring_state = CMD_RING_STATE_STOPPED;
-
- /* Make sure the xHC is halted for a USB3 roothub
- * (xhci_stop() could be called as part of failed init).
- */
- xhci_halt(xhci);
- xhci_reset(xhci);
- spin_unlock_irq(&xhci->lock);
+
+ if (!(xhci->xhc_state & XHCI_STATE_HALTED)) {
+ spin_lock_irq(&xhci->lock);
+
+ xhci->xhc_state |= XHCI_STATE_HALTED;
+ xhci->cmd_ring_state = CMD_RING_STATE_STOPPED;
+ xhci_halt(xhci);
+ xhci_reset(xhci);
+
+ spin_unlock_irq(&xhci->lock);
+ }
+
+ if (!usb_hcd_is_primary_hcd(hcd)) {
+ mutex_unlock(&xhci->mutex);
+ return;
+ }
xhci_cleanup_msix(xhci);
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 03:30 +0200 |
| Subject | [PATCH 4.4 23/32] usb: musb: Ensure rx reinit occurs for shared_fifo endpoints |
| Message-ID | <rS6iD-8uQ-59@gated-at.bofh.it> |
| In reply to | #1438082 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrew Goodbody <andrew.goodbody@cambrionix.com>
commit f3eec0cf784e0d6c47822ca6b66df3d5812af7e6 upstream.
shared_fifo endpoints would only get a previous tx state cleared
out, the rx state was only cleared for non shared_fifo endpoints
Change this so that the rx state is cleared for all endpoints.
This addresses an issue that resulted in rx packets being dropped
silently.
Signed-off-by: Andrew Goodbody <andrew.goodbody@cambrionix.com>
Signed-off-by: Bin Liu <b-liu@ti.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/usb/musb/musb_host.c | 13 ++++++-------
1 file changed, 6 insertions(+), 7 deletions(-)
--- a/drivers/usb/musb/musb_host.c
+++ b/drivers/usb/musb/musb_host.c
@@ -594,14 +594,13 @@ musb_rx_reinit(struct musb *musb, struct
musb_writew(ep->regs, MUSB_TXCSR, 0);
/* scrub all previous state, clearing toggle */
- } else {
- csr = musb_readw(ep->regs, MUSB_RXCSR);
- if (csr & MUSB_RXCSR_RXPKTRDY)
- WARNING("rx%d, packet/%d ready?\n", ep->epnum,
- musb_readw(ep->regs, MUSB_RXCOUNT));
-
- musb_h_flush_rxfifo(ep, MUSB_RXCSR_CLRDATATOG);
}
+ csr = musb_readw(ep->regs, MUSB_RXCSR);
+ if (csr & MUSB_RXCSR_RXPKTRDY)
+ WARNING("rx%d, packet/%d ready?\n", ep->epnum,
+ musb_readw(ep->regs, MUSB_RXCOUNT));
+
+ musb_h_flush_rxfifo(ep, MUSB_RXCSR_CLRDATATOG);
/* target addr and (for multipoint) hub addr/port */
if (musb->is_multipoint) {
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 03:30 +0200 |
| Subject | [PATCH 4.4 14/32] AX.25: Close socket connection on session completion |
| Message-ID | <rS6iD-8uQ-71@gated-at.bofh.it> |
| In reply to | #1438082 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Basil Gunn <basil@pacabunga.com>
[ Upstream commit 4a7d99ea1b27734558feb6833f180cd38a159940 ]
A socket connection made in ax.25 is not closed when session is
completed. The heartbeat timer is stopped prematurely and this is
where the socket gets closed. Allow heatbeat timer to run to close
socket. Symptom occurs in kernels >= 4.2.0
Originally sent 6/15/2016. Resend with distribution list matching
scripts/maintainer.pl output.
Signed-off-by: Basil Gunn <basil@pacabunga.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ax25/af_ax25.c | 3 ++-
net/ax25/ax25_ds_timer.c | 5 ++++-
net/ax25/ax25_std_timer.c | 5 ++++-
net/ax25/ax25_subr.c | 3 ++-
4 files changed, 12 insertions(+), 4 deletions(-)
--- a/net/ax25/af_ax25.c
+++ b/net/ax25/af_ax25.c
@@ -976,7 +976,8 @@ static int ax25_release(struct socket *s
release_sock(sk);
ax25_disconnect(ax25, 0);
lock_sock(sk);
- ax25_destroy_socket(ax25);
+ if (!sock_flag(ax25->sk, SOCK_DESTROY))
+ ax25_destroy_socket(ax25);
break;
case AX25_STATE_3:
--- a/net/ax25/ax25_ds_timer.c
+++ b/net/ax25/ax25_ds_timer.c
@@ -102,6 +102,7 @@ void ax25_ds_heartbeat_expiry(ax25_cb *a
switch (ax25->state) {
case AX25_STATE_0:
+ case AX25_STATE_2:
/* Magic here: If we listen() and a new link dies before it
is accepted() it isn't 'dead' so doesn't get removed. */
if (!sk || sock_flag(sk, SOCK_DESTROY) ||
@@ -111,6 +112,7 @@ void ax25_ds_heartbeat_expiry(ax25_cb *a
sock_hold(sk);
ax25_destroy_socket(ax25);
bh_unlock_sock(sk);
+ /* Ungrab socket and destroy it */
sock_put(sk);
} else
ax25_destroy_socket(ax25);
@@ -213,7 +215,8 @@ void ax25_ds_t1_timeout(ax25_cb *ax25)
case AX25_STATE_2:
if (ax25->n2count == ax25->n2) {
ax25_send_control(ax25, AX25_DISC, AX25_POLLON, AX25_COMMAND);
- ax25_disconnect(ax25, ETIMEDOUT);
+ if (!sock_flag(ax25->sk, SOCK_DESTROY))
+ ax25_disconnect(ax25, ETIMEDOUT);
return;
} else {
ax25->n2count++;
--- a/net/ax25/ax25_std_timer.c
+++ b/net/ax25/ax25_std_timer.c
@@ -38,6 +38,7 @@ void ax25_std_heartbeat_expiry(ax25_cb *
switch (ax25->state) {
case AX25_STATE_0:
+ case AX25_STATE_2:
/* Magic here: If we listen() and a new link dies before it
is accepted() it isn't 'dead' so doesn't get removed. */
if (!sk || sock_flag(sk, SOCK_DESTROY) ||
@@ -47,6 +48,7 @@ void ax25_std_heartbeat_expiry(ax25_cb *
sock_hold(sk);
ax25_destroy_socket(ax25);
bh_unlock_sock(sk);
+ /* Ungrab socket and destroy it */
sock_put(sk);
} else
ax25_destroy_socket(ax25);
@@ -144,7 +146,8 @@ void ax25_std_t1timer_expiry(ax25_cb *ax
case AX25_STATE_2:
if (ax25->n2count == ax25->n2) {
ax25_send_control(ax25, AX25_DISC, AX25_POLLON, AX25_COMMAND);
- ax25_disconnect(ax25, ETIMEDOUT);
+ if (!sock_flag(ax25->sk, SOCK_DESTROY))
+ ax25_disconnect(ax25, ETIMEDOUT);
return;
} else {
ax25->n2count++;
--- a/net/ax25/ax25_subr.c
+++ b/net/ax25/ax25_subr.c
@@ -264,7 +264,8 @@ void ax25_disconnect(ax25_cb *ax25, int
{
ax25_clear_queues(ax25);
- ax25_stop_heartbeat(ax25);
+ if (!sock_flag(ax25->sk, SOCK_DESTROY))
+ ax25_stop_heartbeat(ax25);
ax25_stop_t1timer(ax25);
ax25_stop_t2timer(ax25);
ax25_stop_t3timer(ax25);
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 03:30 +0200 |
| Subject | [PATCH 4.4 13/32] bpf: try harder on clones when writing into skb |
| Message-ID | <rS6iD-8uQ-57@gated-at.bofh.it> |
| In reply to | #1438082 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Borkmann <daniel@iogearbox.net>
[ Upstream commit 3697649ff29e0f647565eed04b27a7779c646a22 ]
When we're dealing with clones and the area is not writeable, try
harder and get a copy via pskb_expand_head(). Replace also other
occurences in tc actions with the new skb_try_make_writable().
Reported-by: Ashhad Sheikh <ashhadsheikh394@gmail.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/skbuff.h | 7 +++++++
net/core/filter.c | 18 ++++++++++--------
net/sched/act_csum.c | 8 ++------
net/sched/act_nat.c | 18 +++++-------------
4 files changed, 24 insertions(+), 27 deletions(-)
--- a/include/linux/skbuff.h
+++ b/include/linux/skbuff.h
@@ -2564,6 +2564,13 @@ static inline int skb_clone_writable(con
skb_headroom(skb) + len <= skb->hdr_len;
}
+static inline int skb_try_make_writable(struct sk_buff *skb,
+ unsigned int write_len)
+{
+ return skb_cloned(skb) && !skb_clone_writable(skb, write_len) &&
+ pskb_expand_head(skb, 0, 0, GFP_ATOMIC);
+}
+
static inline int __skb_cow(struct sk_buff *skb, unsigned int headroom,
int cloned)
{
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -1275,9 +1275,7 @@ static u64 bpf_skb_store_bytes(u64 r1, u
*/
if (unlikely((u32) offset > 0xffff || len > sizeof(buf)))
return -EFAULT;
-
- if (unlikely(skb_cloned(skb) &&
- !skb_clone_writable(skb, offset + len)))
+ if (unlikely(skb_try_make_writable(skb, offset + len)))
return -EFAULT;
ptr = skb_header_pointer(skb, offset, len, buf);
@@ -1321,8 +1319,7 @@ static u64 bpf_l3_csum_replace(u64 r1, u
if (unlikely((u32) offset > 0xffff))
return -EFAULT;
- if (unlikely(skb_cloned(skb) &&
- !skb_clone_writable(skb, offset + sizeof(sum))))
+ if (unlikely(skb_try_make_writable(skb, offset + sizeof(sum))))
return -EFAULT;
ptr = skb_header_pointer(skb, offset, sizeof(sum), &sum);
@@ -1367,9 +1364,7 @@ static u64 bpf_l4_csum_replace(u64 r1, u
if (unlikely((u32) offset > 0xffff))
return -EFAULT;
-
- if (unlikely(skb_cloned(skb) &&
- !skb_clone_writable(skb, offset + sizeof(sum))))
+ if (unlikely(skb_try_make_writable(skb, offset + sizeof(sum))))
return -EFAULT;
ptr = skb_header_pointer(skb, offset, sizeof(sum), &sum);
@@ -1554,6 +1549,13 @@ bool bpf_helper_changes_skb_data(void *f
return true;
if (func == bpf_skb_vlan_pop)
return true;
+ if (func == bpf_skb_store_bytes)
+ return true;
+ if (func == bpf_l3_csum_replace)
+ return true;
+ if (func == bpf_l4_csum_replace)
+ return true;
+
return false;
}
--- a/net/sched/act_csum.c
+++ b/net/sched/act_csum.c
@@ -105,9 +105,7 @@ static void *tcf_csum_skb_nextlayer(stru
int hl = ihl + jhl;
if (!pskb_may_pull(skb, ipl + ntkoff) || (ipl < hl) ||
- (skb_cloned(skb) &&
- !skb_clone_writable(skb, hl + ntkoff) &&
- pskb_expand_head(skb, 0, 0, GFP_ATOMIC)))
+ skb_try_make_writable(skb, hl + ntkoff))
return NULL;
else
return (void *)(skb_network_header(skb) + ihl);
@@ -365,9 +363,7 @@ static int tcf_csum_ipv4(struct sk_buff
}
if (update_flags & TCA_CSUM_UPDATE_FLAG_IPV4HDR) {
- if (skb_cloned(skb) &&
- !skb_clone_writable(skb, sizeof(*iph) + ntkoff) &&
- pskb_expand_head(skb, 0, 0, GFP_ATOMIC))
+ if (skb_try_make_writable(skb, sizeof(*iph) + ntkoff))
goto fail;
ip_send_check(ip_hdr(skb));
--- a/net/sched/act_nat.c
+++ b/net/sched/act_nat.c
@@ -126,9 +126,7 @@ static int tcf_nat(struct sk_buff *skb,
addr = iph->daddr;
if (!((old_addr ^ addr) & mask)) {
- if (skb_cloned(skb) &&
- !skb_clone_writable(skb, sizeof(*iph) + noff) &&
- pskb_expand_head(skb, 0, 0, GFP_ATOMIC))
+ if (skb_try_make_writable(skb, sizeof(*iph) + noff))
goto drop;
new_addr &= mask;
@@ -156,9 +154,7 @@ static int tcf_nat(struct sk_buff *skb,
struct tcphdr *tcph;
if (!pskb_may_pull(skb, ihl + sizeof(*tcph) + noff) ||
- (skb_cloned(skb) &&
- !skb_clone_writable(skb, ihl + sizeof(*tcph) + noff) &&
- pskb_expand_head(skb, 0, 0, GFP_ATOMIC)))
+ skb_try_make_writable(skb, ihl + sizeof(*tcph) + noff))
goto drop;
tcph = (void *)(skb_network_header(skb) + ihl);
@@ -171,9 +167,7 @@ static int tcf_nat(struct sk_buff *skb,
struct udphdr *udph;
if (!pskb_may_pull(skb, ihl + sizeof(*udph) + noff) ||
- (skb_cloned(skb) &&
- !skb_clone_writable(skb, ihl + sizeof(*udph) + noff) &&
- pskb_expand_head(skb, 0, 0, GFP_ATOMIC)))
+ skb_try_make_writable(skb, ihl + sizeof(*udph) + noff))
goto drop;
udph = (void *)(skb_network_header(skb) + ihl);
@@ -213,10 +207,8 @@ static int tcf_nat(struct sk_buff *skb,
if ((old_addr ^ addr) & mask)
break;
- if (skb_cloned(skb) &&
- !skb_clone_writable(skb, ihl + sizeof(*icmph) +
- sizeof(*iph) + noff) &&
- pskb_expand_head(skb, 0, 0, GFP_ATOMIC))
+ if (skb_try_make_writable(skb, ihl + sizeof(*icmph) +
+ sizeof(*iph) + noff))
goto drop;
icmph = (void *)(skb_network_header(skb) + ihl);
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 03:30 +0200 |
| Subject | [PATCH 4.4 20/32] usb: quirks: Add no-lpm quirk for Acer C120 LED Projector |
| Message-ID | <rS6iD-8uQ-61@gated-at.bofh.it> |
| In reply to | #1438082 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <hdegoede@redhat.com>
commit 32cb0b37098f4beeff5ad9e325f11b42a6ede56c upstream.
The Acer C120 LED Projector is a USB-3 connected pico projector which
takes both its power and video data from USB-3.
In combination with some hubs this device does not play well with
lpm, so disable lpm for it.
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/usb/core/quirks.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/usb/core/quirks.c
+++ b/drivers/usb/core/quirks.c
@@ -199,6 +199,9 @@ static const struct usb_device_id usb_qu
{ USB_DEVICE(0x1a0a, 0x0200), .driver_info =
USB_QUIRK_LINEAR_UFRAME_INTR_BINTERVAL },
+ /* Acer C120 LED Projector */
+ { USB_DEVICE(0x1de1, 0xc102), .driver_info = USB_QUIRK_NO_LPM },
+
/* Blackmagic Design Intensity Shuttle */
{ USB_DEVICE(0x1edb, 0xbd3b), .driver_info = USB_QUIRK_NO_LPM },
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 03:30 +0200 |
| Subject | [PATCH 4.4 18/32] USB: uas: Fix slave queue_depth not being set |
| Message-ID | <rS6iD-8uQ-63@gated-at.bofh.it> |
| In reply to | #1438082 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <hdegoede@redhat.com>
commit 593224ea77b1ca842f45cf76f4deeef44dfbacd1 upstream.
Commit 198de51dbc34 ("USB: uas: Limit qdepth at the scsi-host level")
removed the scsi_change_queue_depth() call from uas_slave_configure()
assuming that the slave would inherit the host's queue_depth, which
that commit sets to the same value.
This is incorrect, without the scsi_change_queue_depth() call the slave's
queue_depth defaults to 1, introducing a performance regression.
This commit restores the call, fixing the performance regression.
Fixes: 198de51dbc34 ("USB: uas: Limit qdepth at the scsi-host level")
Reported-by: Tom Yan <tom.ty89@gmail.com>
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/usb/storage/uas.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/usb/storage/uas.c
+++ b/drivers/usb/storage/uas.c
@@ -811,6 +811,7 @@ static int uas_slave_configure(struct sc
if (devinfo->flags & US_FL_BROKEN_FUA)
sdev->broken_fua = 1;
+ scsi_change_queue_depth(sdev, devinfo->qdepth - 2);
return 0;
}
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 03:30 +0200 |
| Subject | [PATCH 4.4 15/32] crypto: vmx - Increase priority of aes-cbc cipher |
| Message-ID | <rS6iD-8uQ-65@gated-at.bofh.it> |
| In reply to | #1438082 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Anton Blanchard <anton@samba.org>
commit 12d3f49e1ffbbf8cbbb60acae5a21103c5c841ac upstream.
All of the VMX AES ciphers (AES, AES-CBC and AES-CTR) are set at
priority 1000. Unfortunately this means we never use AES-CBC and
AES-CTR, because the base AES-CBC cipher that is implemented on
top of AES inherits its priority.
To fix this, AES-CBC and AES-CTR have to be a higher priority. Set
them to 2000.
Testing on a POWER8 with:
cryptsetup benchmark --cipher aes --key-size 256
Shows decryption speed increase from 402.4 MB/s to 3069.2 MB/s,
over 7x faster. Thanks to Mike Strosaker for helping me debug
this issue.
Fixes: 8c755ace357c ("crypto: vmx - Adding CBC routines for VMX module")
Signed-off-by: Anton Blanchard <anton@samba.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/crypto/vmx/aes_cbc.c | 2 +-
drivers/crypto/vmx/aes_ctr.c | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/crypto/vmx/aes_cbc.c
+++ b/drivers/crypto/vmx/aes_cbc.c
@@ -182,7 +182,7 @@ struct crypto_alg p8_aes_cbc_alg = {
.cra_name = "cbc(aes)",
.cra_driver_name = "p8_aes_cbc",
.cra_module = THIS_MODULE,
- .cra_priority = 1000,
+ .cra_priority = 2000,
.cra_type = &crypto_blkcipher_type,
.cra_flags = CRYPTO_ALG_TYPE_BLKCIPHER | CRYPTO_ALG_NEED_FALLBACK,
.cra_alignmask = 0,
--- a/drivers/crypto/vmx/aes_ctr.c
+++ b/drivers/crypto/vmx/aes_ctr.c
@@ -166,7 +166,7 @@ struct crypto_alg p8_aes_ctr_alg = {
.cra_name = "ctr(aes)",
.cra_driver_name = "p8_aes_ctr",
.cra_module = THIS_MODULE,
- .cra_priority = 1000,
+ .cra_priority = 2000,
.cra_type = &crypto_blkcipher_type,
.cra_flags = CRYPTO_ALG_TYPE_BLKCIPHER | CRYPTO_ALG_NEED_FALLBACK,
.cra_alignmask = 0,
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 03:30 +0200 |
| Subject | [PATCH 4.4 10/32] neigh: Explicitly declare RCU-bh read side critical section in neigh_xmit() |
| Message-ID | <rS6iD-8uQ-73@gated-at.bofh.it> |
| In reply to | #1438082 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Barroso <dbarroso@fastly.com>
[ Upstream commit b560f03ddfb072bca65e9440ff0dc4f9b1d1f056 ]
neigh_xmit() expects to be called inside an RCU-bh read side critical
section, and while one of its two current callers gets this right, the
other one doesn't.
More specifically, neigh_xmit() has two callers, mpls_forward() and
mpls_output(), and while both callers call neigh_xmit() under
rcu_read_lock(), this provides sufficient protection for neigh_xmit()
only in the case of mpls_forward(), as that is always called from
softirq context and therefore doesn't need explicit BH protection,
while mpls_output() can be called from process context with softirqs
enabled.
When mpls_output() is called from process context, with softirqs
enabled, we can be preempted by a softirq at any time, and RCU-bh
considers the completion of a softirq as signaling the end of any
pending read-side critical sections, so if we do get a softirq
while we are in the part of neigh_xmit() that expects to be run inside
an RCU-bh read side critical section, we can end up with an unexpected
RCU grace period running right in the middle of that critical section,
making things go boom.
This patch fixes this impedance mismatch in the callee, by making
neigh_xmit() always take rcu_read_{,un}lock_bh() around the code that
expects to be treated as an RCU-bh read side critical section, as this
seems a safer option than fixing it in the callers.
Fixes: 4fd3d7d9e868f ("neigh: Add helper function neigh_xmit")
Signed-off-by: David Barroso <dbarroso@fastly.com>
Signed-off-by: Lennert Buytenhek <lbuytenhek@fastly.com>
Acked-by: David Ahern <dsa@cumulusnetworks.com>
Acked-by: Robert Shearman <rshearma@brocade.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/core/neighbour.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2467,13 +2467,17 @@ int neigh_xmit(int index, struct net_dev
tbl = neigh_tables[index];
if (!tbl)
goto out;
+ rcu_read_lock_bh();
neigh = __neigh_lookup_noref(tbl, addr, dev);
if (!neigh)
neigh = __neigh_create(tbl, addr, dev, false);
err = PTR_ERR(neigh);
- if (IS_ERR(neigh))
+ if (IS_ERR(neigh)) {
+ rcu_read_unlock_bh();
goto out_kfree_skb;
+ }
err = neigh->output(neigh, skb);
+ rcu_read_unlock_bh();
}
else if (index == NEIGH_LINK_TABLE) {
err = dev_hard_header(skb, dev, ntohs(skb->protocol),
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 03:30 +0200 |
| Subject | [PATCH 4.4 05/32] netem: fix a use after free |
| Message-ID | <rS6iD-8uQ-69@gated-at.bofh.it> |
| In reply to | #1438082 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 21de12ee5568fd1aec47890c72967abf791ac80a ]
If the packet was dropped by lower qdisc, then we must not
access it later.
Save qdisc_pkt_len(skb) in a temp variable.
Fixes: 2ccccf5fb43f ("net_sched: update hierarchical backlog too")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: WANG Cong <xiyou.wangcong@gmail.com>
Cc: Jamal Hadi Salim <jhs@mojatatu.com>
Cc: Stephen Hemminger <stephen@networkplumber.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sched/sch_netem.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
--- a/net/sched/sch_netem.c
+++ b/net/sched/sch_netem.c
@@ -650,14 +650,14 @@ deliver:
#endif
if (q->qdisc) {
+ unsigned int pkt_len = qdisc_pkt_len(skb);
int err = qdisc_enqueue(skb, q->qdisc);
- if (unlikely(err != NET_XMIT_SUCCESS)) {
- if (net_xmit_drop_count(err)) {
- qdisc_qstats_drop(sch);
- qdisc_tree_reduce_backlog(sch, 1,
- qdisc_pkt_len(skb));
- }
+ if (err != NET_XMIT_SUCCESS &&
+ net_xmit_drop_count(err)) {
+ qdisc_qstats_drop(sch);
+ qdisc_tree_reduce_backlog(sch, 1,
+ pkt_len);
}
goto tfifo_dequeue;
}
[toc] | [prev] | [next] | [standalone]
| From | Nikolay Borisov <kernel@kyup.com> |
|---|---|
| Date | 2016-07-07 10:10 +0200 |
| Message-ID | <rScxH-4ic-15@gated-at.bofh.it> |
| In reply to | #1438082 |
On 07/07/2016 04:19 AM, Greg Kroah-Hartman wrote: > This is the start of the stable review cycle for the 4.4.15 release. > There are 32 patches in this series, all will be posted as a response > to this one. If anyone has any issues with these being applied, please > let me know. Greg, I'd like you to include the following patch as well, since this has been causing crashes with current 4.4 series: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8974189222159154c55f24ddad33e3613960521a > > Responses should be made by Sat Jul 9 01:16:17 UTC 2016. > Anything received after that time might be too late. > [SNIP] > >
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 21:20 +0200 |
| Message-ID | <rSn05-2Gq-25@gated-at.bofh.it> |
| In reply to | #1438282 |
On Thu, Jul 07, 2016 at 11:08:36AM +0300, Nikolay Borisov wrote: > > > On 07/07/2016 04:19 AM, Greg Kroah-Hartman wrote: > > This is the start of the stable review cycle for the 4.4.15 release. > > There are 32 patches in this series, all will be posted as a response > > to this one. If anyone has any issues with these being applied, please > > let me know. > > Greg, I'd like you to include the following patch as well, since this > has been causing crashes with current 4.4 series: > > https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8974189222159154c55f24ddad33e3613960521a Please read the note from the 4.6 -rc announcement... And if you want a patch applied, make a new thread with the subject all about that specific one and send it to stable@, don't send it to the -rc1 announcement please. thanks, greg k-h
[toc] | [prev] | [next] | [standalone]
| From | Guenter Roeck <linux@roeck-us.net> |
|---|---|
| Date | 2016-07-07 15:40 +0200 |
| Message-ID | <rShH4-7v8-29@gated-at.bofh.it> |
| In reply to | #1438082 |
On 07/06/2016 06:19 PM, Greg Kroah-Hartman wrote: > This is the start of the stable review cycle for the 4.4.15 release. > There are 32 patches in this series, all will be posted as a response > to this one. If anyone has any issues with these being applied, please > let me know. > > Responses should be made by Sat Jul 9 01:16:17 UTC 2016. > Anything received after that time might be too late. > Build results: total: 148 pass: 148 fail: 0 Qemu test results: total: 101 pass: 101 fail: 0 Details are available at http://kerneltests.org/builders. Guenter
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 21:20 +0200 |
| Message-ID | <rSn05-2Gq-11@gated-at.bofh.it> |
| In reply to | #1438627 |
On Thu, Jul 07, 2016 at 06:29:29AM -0700, Guenter Roeck wrote: > On 07/06/2016 06:19 PM, Greg Kroah-Hartman wrote: > > This is the start of the stable review cycle for the 4.4.15 release. > > There are 32 patches in this series, all will be posted as a response > > to this one. If anyone has any issues with these being applied, please > > let me know. > > > > Responses should be made by Sat Jul 9 01:16:17 UTC 2016. > > Anything received after that time might be too late. > > > Build results: > total: 148 pass: 148 fail: 0 > Qemu test results: > total: 101 pass: 101 fail: 0 > > Details are available at http://kerneltests.org/builders. Thanks for testing both of these and letting me know. greg k-h
[toc] | [prev] | [next] | [standalone]
| From | Kevin Hilman <khilman@baylibre.com> |
|---|---|
| Date | 2016-07-07 19:00 +0200 |
| Message-ID | <rSkOC-16v-1@gated-at.bofh.it> |
| In reply to | #1438082 |
Greg Kroah-Hartman <gregkh@linuxfoundation.org> writes: > This is the start of the stable review cycle for the 4.4.15 release. > There are 32 patches in this series, all will be posted as a response > to this one. If anyone has any issues with these being applied, please > let me know. We were looking into why the kernelci.org bot isn't responding to this and it's because the actual patch count in the git tree is 33 (not 32) because it includes the commit adds -rc1 to the Makefile. So, the kernelci bot was waiting for a build to show up that matched this email (which it didn't find.) Can you update your scripts to include that final patch so the patch count is right? It's already included in the one-big patch, and the diffstat etc. below, so that would make everything line up. > Responses should be made by Sat Jul 9 01:16:17 UTC 2016. > Anything received after that time might be too late. > > The whole patch series can be found in one patch at: > kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.4.15-rc1.gz nit: this isn't a working URL, and adding an https://www. prefix onto that, that file dosen't seem to exist there yet. Thanks, Kevin [1] $ git checkout stable-rc/linux-4.4.y HEAD is now at 5db8024c795f... Linux 4.4.15-rc1 $ git describe v4.4.14-33-g5db8024c795f > > thanks, > > greg k-h > > ------------- > Pseudo-Shortlog of commits: > > Greg Kroah-Hartman <gregkh@linuxfoundation.org> > Linux 4.4.15-rc1 > > Steinar H. Gunderson <sesse@google.com> > usb: dwc3: exynos: Fix deferred probing storm. > > Thierry Reding <treding@nvidia.com> > usb: host: ehci-tegra: Grab the correct UTMI pads reset > > Bin Liu <b-liu@ti.com> > usb: gadget: fix spinlock dead lock in gadgetfs > > Sudip Mukherjee <sudipm.mukherjee@gmail.com> > USB: mos7720: delete parport > > Mathias Nyman <mathias.nyman@linux.intel.com> > xhci: Fix handling timeouted commands on hosts in weird states. > > Hans de Goede <hdegoede@redhat.com> > USB: xhci: Add broken streams quirk for Frescologic device id 1009 > > Thomas Petazzoni <thomas.petazzoni@free-electrons.com> > usb: xhci-plat: properly handle probe deferral for devm_clk_get() > > Gabriel Krisman Bertazi <krisman@linux.vnet.ibm.com> > xhci: Cleanup only when releasing primary hcd > > Bin Liu <b-liu@ti.com> > usb: musb: host: correct cppi dma channel for isoch transfer > > Andrew Goodbody <andrew.goodbody@cambrionix.com> > usb: musb: Ensure rx reinit occurs for shared_fifo endpoints > > Andrew Goodbody <andrew.goodbody@cambrionix.com> > usb: musb: Stop bulk endpoint while queue is rotated > > Bin Liu <b-liu@ti.com> > usb: musb: only restore devctl when session was set in backup > > Hans de Goede <hdegoede@redhat.com> > usb: quirks: Add no-lpm quirk for Acer C120 LED Projector > > Hans de Goede <hdegoede@redhat.com> > usb: quirks: Fix sorting > > Hans de Goede <hdegoede@redhat.com> > USB: uas: Fix slave queue_depth not being set > > Mathias Krause <minipli@googlemail.com> > crypto: user - re-add size check for CRYPTO_MSG_GETALG > > Linus Walleij <linus.walleij@linaro.org> > crypto: ux500 - memmove the right size > > Anton Blanchard <anton@samba.org> > crypto: vmx - Increase priority of aes-cbc cipher > > Basil Gunn <basil@pacabunga.com> > AX.25: Close socket connection on session completion > > Daniel Borkmann <daniel@iogearbox.net> > bpf: try harder on clones when writing into skb > > Feng Tang <feng.tang@intel.com> > net: alx: Work around the DMA RX overflow issue > > Nicolas Ferre <nicolas.ferre@atmel.com> > net: macb: fix default configuration for GMAC on AT91 > > David Barroso <dbarroso@fastly.com> > neigh: Explicitly declare RCU-bh read side critical section in neigh_xmit() > > Daniel Borkmann <daniel@iogearbox.net> > bpf, perf: delay release of BPF prog after grace period > > Willem de Bruijn <willemb@google.com> > sock_diag: do not broadcast raw socket destruction > > daniel <daniel@dd-wrt.com> > Bridge: Fix ipv6 mc snooping if bridge has no ipv6 address > > Tom Goff <thomas.goff@ll.mit.edu> > ipmr/ip6mr: Initialize the last assert time of mfc entries. > > Eric Dumazet <edumazet@google.com> > netem: fix a use after free > > Herbert Xu <herbert@gondor.apana.org.au> > esp: Fix ESN generation under UDP encapsulation > > Simon Horman <simon.horman@netronome.com> > sit: correct IP protocol used in ipip6_err > > Jason A. Donenfeld <Jason@zx2c4.com> > net: Don't forget pr_fmt on net_dbg_ratelimited for CONFIG_DYNAMIC_DEBUG > > Eric Dumazet <edumazet@google.com> > net_sched: fix pfifo_head_drop behavior vs backlog > > > ------------- > > Diffstat: > > Makefile | 4 +-- > crypto/crypto_user.c | 1 + > drivers/crypto/ux500/hash/hash_core.c | 4 +-- > drivers/crypto/vmx/aes_cbc.c | 2 +- > drivers/crypto/vmx/aes_ctr.c | 2 +- > drivers/net/ethernet/atheros/alx/main.c | 7 ++++- > drivers/net/ethernet/cadence/macb.c | 13 +++++---- > drivers/net/ethernet/cadence/macb.h | 2 +- > drivers/usb/core/quirks.c | 23 ++++++++------- > drivers/usb/dwc3/dwc3-exynos.c | 19 +++++++----- > drivers/usb/gadget/legacy/inode.c | 17 ++++++++--- > drivers/usb/host/ehci-tegra.c | 2 +- > drivers/usb/host/xhci-pci.c | 5 ++++ > drivers/usb/host/xhci-plat.c | 3 ++ > drivers/usb/host/xhci-ring.c | 30 +++++++++++++++---- > drivers/usb/host/xhci.c | 27 +++++++++-------- > drivers/usb/musb/musb_core.c | 3 +- > drivers/usb/musb/musb_host.c | 23 +++++++++------ > drivers/usb/serial/mos7720.c | 1 + > drivers/usb/storage/uas.c | 1 + > include/linux/bpf.h | 4 +++ > include/linux/net.h | 3 +- > include/linux/skbuff.h | 7 +++++ > include/linux/sock_diag.h | 6 ++++ > kernel/events/core.c | 2 +- > net/ax25/af_ax25.c | 3 +- > net/ax25/ax25_ds_timer.c | 5 +++- > net/ax25/ax25_std_timer.c | 5 +++- > net/ax25/ax25_subr.c | 3 +- > net/bridge/br_multicast.c | 4 +++ > net/bridge/br_private.h | 23 ++++++++++++--- > net/core/filter.c | 18 +++++++----- > net/core/neighbour.c | 6 +++- > net/ipv4/esp4.c | 52 ++++++++++++++++++++------------- > net/ipv4/ipmr.c | 4 ++- > net/ipv6/ip6mr.c | 1 + > net/ipv6/sit.c | 4 +-- > net/sched/act_csum.c | 8 ++--- > net/sched/act_nat.c | 18 ++++-------- > net/sched/sch_fifo.c | 4 +++ > net/sched/sch_netem.c | 12 ++++---- > 41 files changed, 249 insertions(+), 132 deletions(-)
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-07 21:20 +0200 |
| Message-ID | <rSn05-2Gq-3@gated-at.bofh.it> |
| In reply to | #1438724 |
On Thu, Jul 07, 2016 at 09:53:10AM -0700, Kevin Hilman wrote: > Greg Kroah-Hartman <gregkh@linuxfoundation.org> writes: > > > This is the start of the stable review cycle for the 4.4.15 release. > > There are 32 patches in this series, all will be posted as a response > > to this one. If anyone has any issues with these being applied, please > > let me know. > > We were looking into why the kernelci.org bot isn't responding to this > and it's because the actual patch count in the git tree is 33 (not 32) > because it includes the commit adds -rc1 to the Makefile. So, the > kernelci bot was waiting for a build to show up that matched this email > (which it didn't find.) > > Can you update your scripts to include that final patch so the patch > count is right? It's already included in the one-big patch, and the > diffstat etc. below, so that would make everything line up. > > > Responses should be made by Sat Jul 9 01:16:17 UTC 2016. > > Anything received after that time might be too late. > > > > The whole patch series can be found in one patch at: > > kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.4.15-rc1.gz > > nit: this isn't a working URL, and adding an https://www. prefix onto that, > that file dosen't seem to exist there yet. Should be there soon, sorry, an error on my end. I'll look into fixing all these things when I return from LinuxCon Japan, right now I'm on vacation and really don't want to be messing with my stable scripts... thanks, greg k-h
[toc] | [prev] | [next] | [standalone]
| From | Kevin Hilman <khilman@baylibre.com> |
|---|---|
| Date | 2016-07-08 00:30 +0200 |
| Message-ID | <rSpXX-4yB-7@gated-at.bofh.it> |
| In reply to | #1438907 |
Greg Kroah-Hartman <gregkh@linuxfoundation.org> writes: > On Thu, Jul 07, 2016 at 09:53:10AM -0700, Kevin Hilman wrote: >> Greg Kroah-Hartman <gregkh@linuxfoundation.org> writes: >> >> > This is the start of the stable review cycle for the 4.4.15 release. >> > There are 32 patches in this series, all will be posted as a response >> > to this one. If anyone has any issues with these being applied, please >> > let me know. >> >> We were looking into why the kernelci.org bot isn't responding to this >> and it's because the actual patch count in the git tree is 33 (not 32) >> because it includes the commit adds -rc1 to the Makefile. So, the >> kernelci bot was waiting for a build to show up that matched this email >> (which it didn't find.) >> >> Can you update your scripts to include that final patch so the patch >> count is right? It's already included in the one-big patch, and the >> diffstat etc. below, so that would make everything line up. >> >> > Responses should be made by Sat Jul 9 01:16:17 UTC 2016. >> > Anything received after that time might be too late. >> > >> > The whole patch series can be found in one patch at: >> > kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.4.15-rc1.gz >> >> nit: this isn't a working URL, and adding an https://www. prefix onto that, >> that file dosen't seem to exist there yet. > > Should be there soon, sorry, an error on my end. > > I'll look into fixing all these things when I return from LinuxCon > Japan, right now I'm on vacation and really don't want to be messing > with my stable scripts... OK, no problem. In the mean time, we'll manually trigger the kernel CI bot for the stable-rc reviews. Thanks, and safe travels. Kevin
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | linux.kernel
csiph-web