Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1443159 > unrolled thread

[PATCH 3.12 00/88] 3.12.62-stable review

Started byJiri Slaby <jslaby@suse.cz>
First post2016-07-14 10:20 +0200
Last post2016-07-14 23:50 +0200
Articles 20 on this page of 98 — 8 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.12 00/88] 3.12.62-stable review Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:20 +0200
    [PATCH 3.12 01/88] PCI/AER: Clear error status registers during enumeration and restore Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:20 +0200
      [PATCH 3.12 10/88] sparc64: Fix return from trap window fill crashes. Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:20 +0200
      [PATCH 3.12 86/88] cdc_ncm: workaround for EM7455 "silent" data interface Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:20 +0200
      [PATCH 3.12 40/88] netfilter: x_tables: xt_compat_match_from_user doesn't need a retval Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:20 +0200
      [PATCH 3.12 15/88] tcp: record TLP and ER timer stats in v6 stats Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:20 +0200
      [PATCH 3.12 62/88] NFS: Fix another OPEN_DOWNGRADE bug Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:20 +0200
      [PATCH 3.12 38/88] netfilter: ip_tables: simplify translate_compat_table args Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:20 +0200
      [PATCH 3.12 61/88] make nfs_atomic_open() call d_drop() on all ->open_context() errors. Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:20 +0200
      [PATCH 3.12 85/88] HID: elo: kill not flush the work Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:20 +0200
      [PATCH 3.12 83/88] HID: hiddev: validate num_values for HIDIOCGUSAGES, HIDIOCSUSAGES commands Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:20 +0200
      [PATCH 3.12 64/88] mm: Export migrate_page_move_mapping and migrate_page_copy Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 53/88] mac80211_hwsim: Add missing check for HWSIM_ATTR_SIGNAL Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 60/88] x86/amd_nb: Fix boot crash on non-AMD systems Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 65/88] UBIFS: Implement ->migratepage() Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 81/88] KVM: x86: expose invariant tsc cpuid bit (v2) Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
        Re: [PATCH 3.12 81/88] KVM: x86: expose invariant tsc cpuid bit (v2) Paolo Bonzini <pbonzini@redhat.com> - 2016-07-14 10:50 +0200
          Re: [PATCH 3.12 81/88] KVM: x86: expose invariant tsc cpuid bit (v2) Jiri Slaby <jslaby@suse.cz> - 2016-07-14 11:30 +0200
            Re: [PATCH 3.12 81/88] KVM: x86: expose invariant tsc cpuid bit (v2) Paolo Bonzini <pbonzini@redhat.com> - 2016-07-14 11:50 +0200
      [PATCH 3.12 79/88] KEYS: potential uninitialized variable Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 76/88] rds: fix an infoleak in rds_inc_info_copy Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 80/88] base: make module_create_drivers_dir race-free Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 78/88] SCSI: Increase REPORT_LUNS timeout Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 71/88] ALSA: hrtimer: Handle start/stop more properly Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 84/88] ALSA: compress: fix an integer overflow check Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 58/88] x86, build: copy ldlinux.c32 to image.iso Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 75/88] net/qlge: Avoids recursive EEH error Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 69/88] USB: usbfs: fix potential infoleak in devio Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 52/88] mac80211: mesh: flush mesh paths unconditionally Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 54/88] IB/mlx4: Properly initialize GRH TClass and FlowLabel in AHs Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 70/88] ktime: export ktime_divns Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 57/88] USB: EHCI: declare hostpc register as zero-length array Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 50/88] usb: musb: Stop bulk endpoint while queue is rotated Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 72/88] ALSA: timer: Fix leak in SNDRV_TIMER_IOCTL_PARAMS Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 73/88] ALSA: timer: Fix leak in events via snd_timer_user_ccallback Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 56/88] powerpc/pseries: Fix PCI config address for DDW Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 68/88] Bridge: Fix ipv6 mc snooping if bridge has no ipv6 address Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 63/88] ARM: 8578/1: mm: ensure pmd_present only checks the valid bit Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 74/88] ALSA: timer: Fix leak in events via snd_timer_user_tinterrupt Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 67/88] scsi_lib: correctly retry failed zero length REQ_TYPE_FS commands Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 77/88] EDAC: Remove arbitrary limit on number of channels Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 59/88] kprobes/x86: Clear TF bit in fault on single-stepping Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 55/88] powerpc/iommu: Remove the dependency on EEH struct in DDW mechanism Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 66/88] scsi: remove scsi_end_request Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:30 +0200
      [PATCH 3.12 37/88] netfilter: arp_tables: simplify translate_compat_table args Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:40 +0200
      [PATCH 3.12 51/88] usb: musb: Ensure rx reinit occurs for shared_fifo endpoints Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:40 +0200
      [PATCH 3.12 45/88] crypto: ux500 - memmove the right size Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:40 +0200
      [PATCH 3.12 43/88] Revert "netfilter: ensure number of counters is >0 in do_replace()" Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:40 +0200
      [PATCH 3.12 48/88] net: alx: Work around the DMA RX overflow issue Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:40 +0200
      [PATCH 3.12 47/88] ipmr/ip6mr: Initialize the last assert time of mfc entries. Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:40 +0200
      [PATCH 3.12 44/88] netfilter: x_tables: introduce and use xt_copy_counters_from_user Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:40 +0200
      [PATCH 3.12 46/88] sit: correct IP protocol used in ipip6_err Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:40 +0200
      [PATCH 3.12 41/88] netfilter: ensure number of counters is >0 in do_replace() Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:40 +0200
      [PATCH 3.12 42/88] netfilter: x_tables: do compat validation via translate_table Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:40 +0200
        Re: [PATCH 3.12 42/88] netfilter: x_tables: do compat validation via  translate_table Michal Kubecek <mkubecek@suse.cz> - 2016-07-19 09:20 +0200
          Re: [PATCH 3.12 42/88] netfilter: x_tables: do compat validation via  translate_table Florian Westphal <fw@strlen.de> - 2016-07-19 10:50 +0200
            Re: [PATCH 3.12 42/88] netfilter: x_tables: do compat validation via  translate_table Florian Westphal <fw@strlen.de> - 2016-07-19 11:20 +0200
              Re: [PATCH 3.12 42/88] netfilter: x_tables: do compat validation via  translate_table Michal Kubecek <mkubecek@suse.cz> - 2016-07-19 11:50 +0200
      [PATCH 3.12 49/88] usb: quirks: Add no-lpm quirk for Acer C120 LED Projector Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:40 +0200
      [PATCH 3.12 19/88] KVM: x86: fix OOPS after invalid KVM_SET_DEBUGREGS Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
        Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps Jiri Slaby <jirislaby@gmail.com> - 2016-07-21 08:40 +0200
          Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps Greg KH <greg@kroah.com> - 2016-07-21 21:00 +0200
            Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps Jiri Slaby <jslaby@suse.cz> - 2016-07-21 21:10 +0200
              Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps Michal Kubecek <mkubecek@suse.cz> - 2016-07-25 07:50 +0200
                Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps Michal Kubecek <mkubecek@suse.cz> - 2016-07-25 09:00 +0200
                  Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps Florian Westphal <fw@strlen.de> - 2016-07-25 09:30 +0200
                Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps Florian Westphal <fw@strlen.de> - 2016-07-25 09:10 +0200
      [PATCH 3.12 11/88] perf/x86: Honor the architectural performance monitoring version Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 09/88] sparc: Harden signal return frame checks. Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 22/88] powerpc: Use privileged SPR number for MMCR2 Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 20/88] ARM: fix PTRACE_SETVFPREGS on SMP systems Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 21/88] powerpc: Fix definition of SIAR and SDAR registers Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 02/88] MIPS: Fix 64k page support for 32 bit kernels. Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 25/88] wext: Fix 32 bit iwpriv compatibility issue with 64 bit Kernel Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 13/88] netlink: Fix dump skb leak/double free Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 29/88] netfilter: x_tables: add and use xt_check_entry_offsets Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 24/88] ecryptfs: forbid opening files without mmap handler Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 18/88] drivers: macintosh: rack-meter: limit idle ticks to total ticks Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 17/88] macintosh/therm_windtunnel: Export I2C module alias information Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 06/88] sparc64: Fix sparc64_set_context stack handling. Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 36/88] netfilter: x_tables: don't reject valid target size on some architectures Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 05/88] sparc64: Fix bootup regressions on some Kconfig combinations. Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 26/88] fix d_walk()/non-delayed __d_free() race Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 23/88] parisc: Fix pagefault crash in unaligned __get_user() call Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 31/88] netfilter: x_tables: assert minimum target size Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 33/88] netfilter: x_tables: check standard target size too Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 12/88] perf/x86: Fix undefined shift on 32-bit kernels Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 30/88] netfilter: x_tables: kill check_entry helper Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 16/88] ipv6: Skip XFRM lookup if dst_entry in socket cache is valid Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 34/88] netfilter: x_tables: check for bogus target offset Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 32/88] netfilter: x_tables: add compat version of xt_check_entry_offsets Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 07/88] sparc/PCI: Fix for panic while enabling SR-IOV Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 35/88] netfilter: x_tables: validate all offsets and sizes in a rule Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
      [PATCH 3.12 27/88] netfilter: x_tables: don't move to non-existent next rule Jiri Slaby <jslaby@suse.cz> - 2016-07-14 10:50 +0200
    Re: [PATCH 3.12 00/88] 3.12.62-stable review Guenter Roeck <linux@roeck-us.net> - 2016-07-14 22:30 +0200
      Re: [PATCH 3.12 00/88] 3.12.62-stable review Jiri Slaby <jslaby@suse.cz> - 2016-07-15 09:40 +0200
    Re: [PATCH 3.12 00/88] 3.12.62-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-07-14 23:50 +0200

Page 4 of 5 — ← Prev page 1 2 3 [4] 5  Next page →


#1443262 — [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps

FromJiri Slaby <jslaby@suse.cz>
Date2016-07-14 10:50 +0200
Subject[PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps
Message-ID<rUKvg-7nE-5@gated-at.bofh.it>
In reply to#1443166
From: Florian Westphal <fw@strlen.de>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 36472341017529e2b12573093cc0f68719300997 upstream.

When we see a jump also check that the offset gets us to beginning of
a rule (an ipt_entry).

The extra overhead is negible, even with absurd cases.

300k custom rules, 300k jumps to 'next' user chain:
[ plus one jump from INPUT to first userchain ]:

Before:
real    0m24.874s
user    0m7.532s
sys     0m16.076s

After:
real    0m27.464s
user    0m7.436s
sys     0m18.840s

Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 net/ipv4/netfilter/arp_tables.c | 17 +++++++++++++++++
 net/ipv4/netfilter/ip_tables.c  | 17 +++++++++++++++++
 net/ipv6/netfilter/ip6_tables.c | 17 +++++++++++++++++
 3 files changed, 51 insertions(+)

diff --git a/net/ipv4/netfilter/arp_tables.c b/net/ipv4/netfilter/arp_tables.c
index 7460b7bef3ab..473ec559ce7b 100644
--- a/net/ipv4/netfilter/arp_tables.c
+++ b/net/ipv4/netfilter/arp_tables.c
@@ -358,6 +358,19 @@ static inline bool unconditional(const struct arpt_entry *e)
 	       memcmp(&e->arp, &uncond, sizeof(uncond)) == 0;
 }
 
+static bool find_jump_target(const struct xt_table_info *t,
+			     const void *entry0,
+			     const struct arpt_entry *target)
+{
+	struct arpt_entry *iter;
+
+	xt_entry_foreach(iter, entry0, t->size) {
+		 if (iter == target)
+			return true;
+	}
+	return false;
+}
+
 /* Figures out from what hook each rule can be called: returns 0 if
  * there are loops.  Puts hook bitmask in comefrom.
  */
@@ -451,6 +464,10 @@ static int mark_source_chains(const struct xt_table_info *newinfo,
 					/* This a jump; chase it. */
 					duprintf("Jump rule %u -> %u\n",
 						 pos, newpos);
+					e = (struct arpt_entry *)
+						(entry0 + newpos);
+					if (!find_jump_target(newinfo, entry0, e))
+						return 0;
 				} else {
 					/* ... this is a fallthru */
 					newpos = pos + e->next_offset;
diff --git a/net/ipv4/netfilter/ip_tables.c b/net/ipv4/netfilter/ip_tables.c
index 8fc22eed9603..dba9d8070d07 100644
--- a/net/ipv4/netfilter/ip_tables.c
+++ b/net/ipv4/netfilter/ip_tables.c
@@ -434,6 +434,19 @@ ipt_do_table(struct sk_buff *skb,
 #endif
 }
 
+static bool find_jump_target(const struct xt_table_info *t,
+			     const void *entry0,
+			     const struct ipt_entry *target)
+{
+	struct ipt_entry *iter;
+
+	xt_entry_foreach(iter, entry0, t->size) {
+		 if (iter == target)
+			return true;
+	}
+	return false;
+}
+
 /* Figures out from what hook each rule can be called: returns 0 if
    there are loops.  Puts hook bitmask in comefrom. */
 static int
@@ -531,6 +544,10 @@ mark_source_chains(const struct xt_table_info *newinfo,
 					/* This a jump; chase it. */
 					duprintf("Jump rule %u -> %u\n",
 						 pos, newpos);
+					e = (struct ipt_entry *)
+						(entry0 + newpos);
+					if (!find_jump_target(newinfo, entry0, e))
+						return 0;
 				} else {
 					/* ... this is a fallthru */
 					newpos = pos + e->next_offset;
diff --git a/net/ipv6/netfilter/ip6_tables.c b/net/ipv6/netfilter/ip6_tables.c
index 63f7876c4f29..97a8d2525c26 100644
--- a/net/ipv6/netfilter/ip6_tables.c
+++ b/net/ipv6/netfilter/ip6_tables.c
@@ -444,6 +444,19 @@ ip6t_do_table(struct sk_buff *skb,
 #endif
 }
 
+static bool find_jump_target(const struct xt_table_info *t,
+			     const void *entry0,
+			     const struct ip6t_entry *target)
+{
+	struct ip6t_entry *iter;
+
+	xt_entry_foreach(iter, entry0, t->size) {
+		 if (iter == target)
+			return true;
+	}
+	return false;
+}
+
 /* Figures out from what hook each rule can be called: returns 0 if
    there are loops.  Puts hook bitmask in comefrom. */
 static int
@@ -541,6 +554,10 @@ mark_source_chains(const struct xt_table_info *newinfo,
 					/* This a jump; chase it. */
 					duprintf("Jump rule %u -> %u\n",
 						 pos, newpos);
+					e = (struct ip6t_entry *)
+						(entry0 + newpos);
+					if (!find_jump_target(newinfo, entry0, e))
+						return 0;
 				} else {
 					/* ... this is a fallthru */
 					newpos = pos + e->next_offset;
-- 
2.9.1

[toc] | [prev] | [next] | [standalone]


#1447640 — Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps

FromJiri Slaby <jirislaby@gmail.com>
Date2016-07-21 08:40 +0200
SubjectRe: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps
Message-ID<rXfOh-3JM-7@gated-at.bofh.it>
In reply to#1443262
On 07/14/2016, 10:15 AM, Jiri Slaby wrote:
> From: Florian Westphal <fw@strlen.de>
> 
> 3.12-stable review patch.  If anyone has any objections, please let me know.
> 
> ===============
> 
> commit 36472341017529e2b12573093cc0f68719300997 upstream.

I am now dropping this one. 3.12.62 will be released without that patch.
After the performance issue is resolved, it will be requeued.

> When we see a jump also check that the offset gets us to beginning of
> a rule (an ipt_entry).
> 
> The extra overhead is negible, even with absurd cases.
> 
> 300k custom rules, 300k jumps to 'next' user chain:
> [ plus one jump from INPUT to first userchain ]:
> 
> Before:
> real    0m24.874s
> user    0m7.532s
> sys     0m16.076s
> 
> After:
> real    0m27.464s
> user    0m7.436s
> sys     0m18.840s
> 
> Signed-off-by: Florian Westphal <fw@strlen.de>
> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
> Signed-off-by: Jiri Slaby <jslaby@suse.cz>
> ---
>  net/ipv4/netfilter/arp_tables.c | 17 +++++++++++++++++
>  net/ipv4/netfilter/ip_tables.c  | 17 +++++++++++++++++
>  net/ipv6/netfilter/ip6_tables.c | 17 +++++++++++++++++
>  3 files changed, 51 insertions(+)
> 
> diff --git a/net/ipv4/netfilter/arp_tables.c b/net/ipv4/netfilter/arp_tables.c
> index 7460b7bef3ab..473ec559ce7b 100644
> --- a/net/ipv4/netfilter/arp_tables.c
> +++ b/net/ipv4/netfilter/arp_tables.c
> @@ -358,6 +358,19 @@ static inline bool unconditional(const struct arpt_entry *e)
>  	       memcmp(&e->arp, &uncond, sizeof(uncond)) == 0;
>  }
>  
> +static bool find_jump_target(const struct xt_table_info *t,
> +			     const void *entry0,
> +			     const struct arpt_entry *target)
> +{
> +	struct arpt_entry *iter;
> +
> +	xt_entry_foreach(iter, entry0, t->size) {
> +		 if (iter == target)
> +			return true;
> +	}
> +	return false;
> +}
> +
>  /* Figures out from what hook each rule can be called: returns 0 if
>   * there are loops.  Puts hook bitmask in comefrom.
>   */
> @@ -451,6 +464,10 @@ static int mark_source_chains(const struct xt_table_info *newinfo,
>  					/* This a jump; chase it. */
>  					duprintf("Jump rule %u -> %u\n",
>  						 pos, newpos);
> +					e = (struct arpt_entry *)
> +						(entry0 + newpos);
> +					if (!find_jump_target(newinfo, entry0, e))
> +						return 0;
>  				} else {
>  					/* ... this is a fallthru */
>  					newpos = pos + e->next_offset;
> diff --git a/net/ipv4/netfilter/ip_tables.c b/net/ipv4/netfilter/ip_tables.c
> index 8fc22eed9603..dba9d8070d07 100644
> --- a/net/ipv4/netfilter/ip_tables.c
> +++ b/net/ipv4/netfilter/ip_tables.c
> @@ -434,6 +434,19 @@ ipt_do_table(struct sk_buff *skb,
>  #endif
>  }
>  
> +static bool find_jump_target(const struct xt_table_info *t,
> +			     const void *entry0,
> +			     const struct ipt_entry *target)
> +{
> +	struct ipt_entry *iter;
> +
> +	xt_entry_foreach(iter, entry0, t->size) {
> +		 if (iter == target)
> +			return true;
> +	}
> +	return false;
> +}
> +
>  /* Figures out from what hook each rule can be called: returns 0 if
>     there are loops.  Puts hook bitmask in comefrom. */
>  static int
> @@ -531,6 +544,10 @@ mark_source_chains(const struct xt_table_info *newinfo,
>  					/* This a jump; chase it. */
>  					duprintf("Jump rule %u -> %u\n",
>  						 pos, newpos);
> +					e = (struct ipt_entry *)
> +						(entry0 + newpos);
> +					if (!find_jump_target(newinfo, entry0, e))
> +						return 0;
>  				} else {
>  					/* ... this is a fallthru */
>  					newpos = pos + e->next_offset;
> diff --git a/net/ipv6/netfilter/ip6_tables.c b/net/ipv6/netfilter/ip6_tables.c
> index 63f7876c4f29..97a8d2525c26 100644
> --- a/net/ipv6/netfilter/ip6_tables.c
> +++ b/net/ipv6/netfilter/ip6_tables.c
> @@ -444,6 +444,19 @@ ip6t_do_table(struct sk_buff *skb,
>  #endif
>  }
>  
> +static bool find_jump_target(const struct xt_table_info *t,
> +			     const void *entry0,
> +			     const struct ip6t_entry *target)
> +{
> +	struct ip6t_entry *iter;
> +
> +	xt_entry_foreach(iter, entry0, t->size) {
> +		 if (iter == target)
> +			return true;
> +	}
> +	return false;
> +}
> +
>  /* Figures out from what hook each rule can be called: returns 0 if
>     there are loops.  Puts hook bitmask in comefrom. */
>  static int
> @@ -541,6 +554,10 @@ mark_source_chains(const struct xt_table_info *newinfo,
>  					/* This a jump; chase it. */
>  					duprintf("Jump rule %u -> %u\n",
>  						 pos, newpos);
> +					e = (struct ip6t_entry *)
> +						(entry0 + newpos);
> +					if (!find_jump_target(newinfo, entry0, e))
> +						return 0;
>  				} else {
>  					/* ... this is a fallthru */
>  					newpos = pos + e->next_offset;
> 

[toc] | [prev] | [next] | [standalone]


#1448072 — Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps

FromGreg KH <greg@kroah.com>
Date2016-07-21 21:00 +0200
SubjectRe: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps
Message-ID<rXrmp-2WQ-13@gated-at.bofh.it>
In reply to#1447640
On Thu, Jul 21, 2016 at 08:36:18AM +0200, Jiri Slaby wrote:
> On 07/14/2016, 10:15 AM, Jiri Slaby wrote:
> > From: Florian Westphal <fw@strlen.de>
> > 
> > 3.12-stable review patch.  If anyone has any objections, please let me know.
> > 
> > ===============
> > 
> > commit 36472341017529e2b12573093cc0f68719300997 upstream.
> 
> I am now dropping this one. 3.12.62 will be released without that patch.
> After the performance issue is resolved, it will be requeued.

Personally, I think the bug fixes were more important than the
performance issues at this point in time, but it's your call to make :)

greg k-h

[toc] | [prev] | [next] | [standalone]


#1448081 — Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps

FromJiri Slaby <jslaby@suse.cz>
Date2016-07-21 21:10 +0200
SubjectRe: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps
Message-ID<rXrw5-3fM-27@gated-at.bofh.it>
In reply to#1448072
On 07/21/2016, 08:56 PM, Greg KH wrote:
> On Thu, Jul 21, 2016 at 08:36:18AM +0200, Jiri Slaby wrote:
>> On 07/14/2016, 10:15 AM, Jiri Slaby wrote:
>>> From: Florian Westphal <fw@strlen.de>
>>>
>>> 3.12-stable review patch.  If anyone has any objections, please let me know.
>>>
>>> ===============
>>>
>>> commit 36472341017529e2b12573093cc0f68719300997 upstream.
>>
>> I am now dropping this one. 3.12.62 will be released without that patch.
>> After the performance issue is resolved, it will be requeued.
> 
> Personally, I think the bug fixes were more important than the
> performance issues at this point in time, but it's your call to make :)

Ok, but to quote [1]:
iptables-restore will take forever (gave up after 10 minutes)

I would say it proved itself not to be a performance issue, but rather a
functional issue :). Both Pablo and Florian suggested to postpone the patch.

[1]
http://thread.gmane.org/gmane.comp.security.firewalls.netfilter.devel/64099

thanks,
-- 
js
suse labs

[toc] | [prev] | [next] | [standalone]


#1449291 — Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps

FromMichal Kubecek <mkubecek@suse.cz>
Date2016-07-25 07:50 +0200
SubjectRe: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps
Message-ID<rYGW6-Ht-5@gated-at.bofh.it>
In reply to#1448081
On Thu, Jul 21, 2016 at 09:00:33PM +0200, Jiri Slaby wrote:
> On 07/21/2016, 08:56 PM, Greg KH wrote:
> > On Thu, Jul 21, 2016 at 08:36:18AM +0200, Jiri Slaby wrote:
> >> On 07/14/2016, 10:15 AM, Jiri Slaby wrote:
> >>> From: Florian Westphal <fw@strlen.de>
> >>>
> >>> 3.12-stable review patch.  If anyone has any objections, please let me know.
> >>>
> >>> ===============
> >>>
> >>> commit 36472341017529e2b12573093cc0f68719300997 upstream.
> >>
> >> I am now dropping this one. 3.12.62 will be released without that patch.
> >> After the performance issue is resolved, it will be requeued.
> > 
> > Personally, I think the bug fixes were more important than the
> > performance issues at this point in time, but it's your call to make :)
> 
> Ok, but to quote [1]:
> iptables-restore will take forever (gave up after 10 minutes)
> 
> I would say it proved itself not to be a performance issue, but rather a
> functional issue :). Both Pablo and Florian suggested to postpone the patch.

Even worse: because of a shared lock which is held for all this time,
this allows (on kernel >= 3.8) an unprivileged user to block similar
operation in all network namespaces including init_net.

While a partial DoS like this is certainly better than allowing to crash
the system, it could still be considered a security issue.

Michal Kubecek

[toc] | [prev] | [next] | [standalone]


#1449313 — Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps

FromMichal Kubecek <mkubecek@suse.cz>
Date2016-07-25 09:00 +0200
SubjectRe: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps
Message-ID<rYI1Q-1jd-9@gated-at.bofh.it>
In reply to#1449291
On pondělí 25. července 2016 8:41 Florian Westphal wrote:
> Michal Kubecek <mkubecek@suse.cz> wrote:
> > On Thu, Jul 21, 2016 at 09:00:33PM +0200, Jiri Slaby wrote:
> > > On 07/21/2016, 08:56 PM, Greg KH wrote:
> > > > On Thu, Jul 21, 2016 at 08:36:18AM +0200, Jiri Slaby wrote:
> > > >> On 07/14/2016, 10:15 AM, Jiri Slaby wrote:
> > > >>> From: Florian Westphal <fw@strlen.de>
> > > >>> 
> > > >>> 3.12-stable review patch.  If anyone has any objections,
> > > >>> please let me know.
> > > >>> 
> > > >>> ===============
> > > >>> 
> > > >>> commit 36472341017529e2b12573093cc0f68719300997 upstream.
> > > >> 
> > > >> I am now dropping this one. 3.12.62 will be released without
> > > >> that patch. After the performance issue is resolved, it will
> > > >> be requeued.> > > 
> > > > Personally, I think the bug fixes were more important than the
> > > > performance issues at this point in time, but it's your call to
> > > > make :)> > 
> > > Ok, but to quote [1]:
> > > iptables-restore will take forever (gave up after 10 minutes)
> > > 
> > > I would say it proved itself not to be a performance issue, but
> > > rather a functional issue :). Both Pablo and Florian suggested to
> > > postpone the patch.> 
> > Even worse: because of a shared lock which is held for all this
> > time,
> > this allows (on kernel >= 3.8) an unprivileged user to block similar
> > operation in all network namespaces including init_net.
> 
> What lock are you talking about?
> 
> The table lock is aquired after the sanity/translation pass.

I meant xt_compat_lock(AF_INET) (or AF_INET6 or NFPROTO_ARP) which is 
held for almost all of translate_compat_table().

Michal Kubecek

[toc] | [prev] | [next] | [standalone]


#1449325 — Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps

FromFlorian Westphal <fw@strlen.de>
Date2016-07-25 09:30 +0200
SubjectRe: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps
Message-ID<rYIuR-1Id-7@gated-at.bofh.it>
In reply to#1449313
Michal Kubecek <mkubecek@suse.cz> wrote:
> > What lock are you talking about?
> > 
> > The table lock is aquired after the sanity/translation pass.
> 
> I meant xt_compat_lock(AF_INET) (or AF_INET6 or NFPROTO_ARP) which is 
> held for almost all of translate_compat_table().

Ah, true.  Fortunately most installations won't use this.

[toc] | [prev] | [next] | [standalone]


#1449316 — Re: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps

FromFlorian Westphal <fw@strlen.de>
Date2016-07-25 09:10 +0200
SubjectRe: [PATCH 3.12 28/88] netfilter: x_tables: validate targets of jumps
Message-ID<rYI1Q-1jd-11@gated-at.bofh.it>
In reply to#1449291
Michal Kubecek <mkubecek@suse.cz> wrote:
> On Thu, Jul 21, 2016 at 09:00:33PM +0200, Jiri Slaby wrote:
> > On 07/21/2016, 08:56 PM, Greg KH wrote:
> > > On Thu, Jul 21, 2016 at 08:36:18AM +0200, Jiri Slaby wrote:
> > >> On 07/14/2016, 10:15 AM, Jiri Slaby wrote:
> > >>> From: Florian Westphal <fw@strlen.de>
> > >>>
> > >>> 3.12-stable review patch.  If anyone has any objections, please let me know.
> > >>>
> > >>> ===============
> > >>>
> > >>> commit 36472341017529e2b12573093cc0f68719300997 upstream.
> > >>
> > >> I am now dropping this one. 3.12.62 will be released without that patch.
> > >> After the performance issue is resolved, it will be requeued.
> > > 
> > > Personally, I think the bug fixes were more important than the
> > > performance issues at this point in time, but it's your call to make :)
> > 
> > Ok, but to quote [1]:
> > iptables-restore will take forever (gave up after 10 minutes)
> > 
> > I would say it proved itself not to be a performance issue, but rather a
> > functional issue :). Both Pablo and Florian suggested to postpone the patch.
> 
> Even worse: because of a shared lock which is held for all this time,
> this allows (on kernel >= 3.8) an unprivileged user to block similar
> operation in all network namespaces including init_net.

What lock are you talking about?

The table lock is aquired after the sanity/translation pass.

[toc] | [prev] | [next] | [standalone]


#1443263 — [PATCH 3.12 11/88] perf/x86: Honor the architectural performance monitoring version

FromJiri Slaby <jslaby@suse.cz>
Date2016-07-14 10:50 +0200
Subject[PATCH 3.12 11/88] perf/x86: Honor the architectural performance monitoring version
Message-ID<rUKvg-7nE-7@gated-at.bofh.it>
In reply to#1443166
From: "Palik, Imre" <imrep@amazon.de>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 2c33645d366d13b969d936b68b9f4875b1fdddea upstream.

Architectural performance monitoring, version 1, doesn't support fixed counters.

Currently, even if a hypervisor advertises support for architectural
performance monitoring version 1, perf may still try to use the fixed
counters, as the constraints are set up based on the CPU model.

This patch ensures that perf honors the architectural performance monitoring
version returned by CPUID, and it only uses the fixed counters for version 2
and above.

(Some of the ideas in this patch came from Peter Zijlstra.)

Signed-off-by: Imre Palik <imrep@amazon.de>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Anthony Liguori <aliguori@amazon.com>
Cc: Arnaldo Carvalho de Melo <acme@kernel.org>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Brian Gerst <brgerst@gmail.com>
Cc: Denys Vlasenko <dvlasenk@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Oleg Nesterov <oleg@redhat.com>
Cc: Paul Mackerras <paulus@samba.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Link: http://lkml.kernel.org/r/1433767609-1039-1-git-send-email-imrep.amz@gmail.com
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: Kevin Christopher <kevinc@vmware.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 arch/x86/kernel/cpu/perf_event_intel.c | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/arch/x86/kernel/cpu/perf_event_intel.c b/arch/x86/kernel/cpu/perf_event_intel.c
index 0c8fc76b2d2c..491d6813ea3f 100644
--- a/arch/x86/kernel/cpu/perf_event_intel.c
+++ b/arch/x86/kernel/cpu/perf_event_intel.c
@@ -2538,13 +2538,13 @@ __init int intel_pmu_init(void)
 		 * counter, so do not extend mask to generic counters
 		 */
 		for_each_event_constraint(c, x86_pmu.event_constraints) {
-			if (c->cmask != FIXED_EVENT_FLAGS
-			    || c->idxmsk64 == INTEL_PMC_MSK_FIXED_REF_CYCLES) {
-				continue;
+			if (c->cmask == FIXED_EVENT_FLAGS
+			    && c->idxmsk64 != INTEL_PMC_MSK_FIXED_REF_CYCLES) {
+				c->idxmsk64 |= (1ULL << x86_pmu.num_counters) - 1;
 			}
-
-			c->idxmsk64 |= (1ULL << x86_pmu.num_counters) - 1;
-			c->weight += x86_pmu.num_counters;
+			c->idxmsk64 &=
+				~(~0UL << (INTEL_PMC_IDX_FIXED + x86_pmu.num_counters_fixed));
+			c->weight = hweight64(c->idxmsk64);
 		}
 	}
 
-- 
2.9.1

[toc] | [prev] | [next] | [standalone]


#1443264 — [PATCH 3.12 09/88] sparc: Harden signal return frame checks.

FromJiri Slaby <jslaby@suse.cz>
Date2016-07-14 10:50 +0200
Subject[PATCH 3.12 09/88] sparc: Harden signal return frame checks.
Message-ID<rUKvg-7nE-9@gated-at.bofh.it>
In reply to#1443166
From: "David S. Miller" <davem@davemloft.net>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit d11c2a0de2824395656cf8ed15811580c9dd38aa ]

All signal frames must be at least 16-byte aligned, because that is
the alignment we explicitly create when we build signal return stack
frames.

All stack pointers must be at least 8-byte aligned.

Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 arch/sparc/kernel/signal32.c   | 46 +++++++++++++++++++++++++++---------------
 arch/sparc/kernel/signal_32.c  | 41 +++++++++++++++++++++++--------------
 arch/sparc/kernel/signal_64.c  | 31 ++++++++++++++++++----------
 arch/sparc/kernel/sigutil_32.c |  9 ++++++++-
 arch/sparc/kernel/sigutil_64.c | 10 +++++++--
 5 files changed, 92 insertions(+), 45 deletions(-)

diff --git a/arch/sparc/kernel/signal32.c b/arch/sparc/kernel/signal32.c
index b524f91dd0e5..d45b112908c1 100644
--- a/arch/sparc/kernel/signal32.c
+++ b/arch/sparc/kernel/signal32.c
@@ -137,12 +137,24 @@ int copy_siginfo_from_user32(siginfo_t *to, compat_siginfo_t __user *from)
 	return 0;
 }
 
+/* Checks if the fp is valid.  We always build signal frames which are
+ * 16-byte aligned, therefore we can always enforce that the restore
+ * frame has that property as well.
+ */
+static bool invalid_frame_pointer(void __user *fp, int fplen)
+{
+	if ((((unsigned long) fp) & 15) ||
+	    ((unsigned long)fp) > 0x100000000ULL - fplen)
+		return true;
+	return false;
+}
+
 void do_sigreturn32(struct pt_regs *regs)
 {
 	struct signal_frame32 __user *sf;
 	compat_uptr_t fpu_save;
 	compat_uptr_t rwin_save;
-	unsigned int psr;
+	unsigned int psr, ufp;
 	unsigned pc, npc;
 	sigset_t set;
 	unsigned seta[_COMPAT_NSIG_WORDS];
@@ -157,11 +169,16 @@ void do_sigreturn32(struct pt_regs *regs)
 	sf = (struct signal_frame32 __user *) regs->u_regs[UREG_FP];
 
 	/* 1. Make sure we are not getting garbage from the user */
-	if (!access_ok(VERIFY_READ, sf, sizeof(*sf)) ||
-	    (((unsigned long) sf) & 3))
+	if (invalid_frame_pointer(sf, sizeof(*sf)))
+		goto segv;
+
+	if (get_user(ufp, &sf->info.si_regs.u_regs[UREG_FP]))
+		goto segv;
+
+	if (ufp & 0x7)
 		goto segv;
 
-	if (get_user(pc, &sf->info.si_regs.pc) ||
+	if (__get_user(pc, &sf->info.si_regs.pc) ||
 	    __get_user(npc, &sf->info.si_regs.npc))
 		goto segv;
 
@@ -230,7 +247,7 @@ segv:
 asmlinkage void do_rt_sigreturn32(struct pt_regs *regs)
 {
 	struct rt_signal_frame32 __user *sf;
-	unsigned int psr, pc, npc;
+	unsigned int psr, pc, npc, ufp;
 	compat_uptr_t fpu_save;
 	compat_uptr_t rwin_save;
 	sigset_t set;
@@ -245,11 +262,16 @@ asmlinkage void do_rt_sigreturn32(struct pt_regs *regs)
 	sf = (struct rt_signal_frame32 __user *) regs->u_regs[UREG_FP];
 
 	/* 1. Make sure we are not getting garbage from the user */
-	if (!access_ok(VERIFY_READ, sf, sizeof(*sf)) ||
-	    (((unsigned long) sf) & 3))
+	if (invalid_frame_pointer(sf, sizeof(*sf)))
 		goto segv;
 
-	if (get_user(pc, &sf->regs.pc) || 
+	if (get_user(ufp, &sf->regs.u_regs[UREG_FP]))
+		goto segv;
+
+	if (ufp & 0x7)
+		goto segv;
+
+	if (__get_user(pc, &sf->regs.pc) || 
 	    __get_user(npc, &sf->regs.npc))
 		goto segv;
 
@@ -315,14 +337,6 @@ segv:
 	force_sig(SIGSEGV, current);
 }
 
-/* Checks if the fp is valid */
-static int invalid_frame_pointer(void __user *fp, int fplen)
-{
-	if ((((unsigned long) fp) & 7) || ((unsigned long)fp) > 0x100000000ULL - fplen)
-		return 1;
-	return 0;
-}
-
 static void __user *get_sigframe(struct ksignal *ksig, struct pt_regs *regs, unsigned long framesize)
 {
 	unsigned long sp;
diff --git a/arch/sparc/kernel/signal_32.c b/arch/sparc/kernel/signal_32.c
index 7d5d8e1f8415..e751dbc527e2 100644
--- a/arch/sparc/kernel/signal_32.c
+++ b/arch/sparc/kernel/signal_32.c
@@ -59,10 +59,22 @@ struct rt_signal_frame {
 #define SF_ALIGNEDSZ  (((sizeof(struct signal_frame) + 7) & (~7)))
 #define RT_ALIGNEDSZ  (((sizeof(struct rt_signal_frame) + 7) & (~7)))
 
+/* Checks if the fp is valid.  We always build signal frames which are
+ * 16-byte aligned, therefore we can always enforce that the restore
+ * frame has that property as well.
+ */
+static inline bool invalid_frame_pointer(void __user *fp, int fplen)
+{
+	if ((((unsigned long) fp) & 15) || !__access_ok((unsigned long)fp, fplen))
+		return true;
+
+	return false;
+}
+
 asmlinkage void do_sigreturn(struct pt_regs *regs)
 {
+	unsigned long up_psr, pc, npc, ufp;
 	struct signal_frame __user *sf;
-	unsigned long up_psr, pc, npc;
 	sigset_t set;
 	__siginfo_fpu_t __user *fpu_save;
 	__siginfo_rwin_t __user *rwin_save;
@@ -76,10 +88,13 @@ asmlinkage void do_sigreturn(struct pt_regs *regs)
 	sf = (struct signal_frame __user *) regs->u_regs[UREG_FP];
 
 	/* 1. Make sure we are not getting garbage from the user */
-	if (!access_ok(VERIFY_READ, sf, sizeof(*sf)))
+	if (!invalid_frame_pointer(sf, sizeof(*sf)))
+		goto segv_and_exit;
+
+	if (get_user(ufp, &sf->info.si_regs.u_regs[UREG_FP]))
 		goto segv_and_exit;
 
-	if (((unsigned long) sf) & 3)
+	if (ufp & 0x7)
 		goto segv_and_exit;
 
 	err = __get_user(pc,  &sf->info.si_regs.pc);
@@ -126,7 +141,7 @@ segv_and_exit:
 asmlinkage void do_rt_sigreturn(struct pt_regs *regs)
 {
 	struct rt_signal_frame __user *sf;
-	unsigned int psr, pc, npc;
+	unsigned int psr, pc, npc, ufp;
 	__siginfo_fpu_t __user *fpu_save;
 	__siginfo_rwin_t __user *rwin_save;
 	sigset_t set;
@@ -134,8 +149,13 @@ asmlinkage void do_rt_sigreturn(struct pt_regs *regs)
 
 	synchronize_user_stack();
 	sf = (struct rt_signal_frame __user *) regs->u_regs[UREG_FP];
-	if (!access_ok(VERIFY_READ, sf, sizeof(*sf)) ||
-	    (((unsigned long) sf) & 0x03))
+	if (!invalid_frame_pointer(sf, sizeof(*sf)))
+		goto segv;
+
+	if (get_user(ufp, &sf->regs.u_regs[UREG_FP]))
+		goto segv;
+
+	if (ufp & 0x7)
 		goto segv;
 
 	err = __get_user(pc, &sf->regs.pc);
@@ -177,15 +197,6 @@ segv:
 	force_sig(SIGSEGV, current);
 }
 
-/* Checks if the fp is valid */
-static inline int invalid_frame_pointer(void __user *fp, int fplen)
-{
-	if ((((unsigned long) fp) & 7) || !__access_ok((unsigned long)fp, fplen))
-		return 1;
-
-	return 0;
-}
-
 static inline void __user *get_sigframe(struct ksignal *ksig, struct pt_regs *regs, unsigned long framesize)
 {
 	unsigned long sp = regs->u_regs[UREG_FP];
diff --git a/arch/sparc/kernel/signal_64.c b/arch/sparc/kernel/signal_64.c
index 90f08055b7d2..5a2e50bcc3b8 100644
--- a/arch/sparc/kernel/signal_64.c
+++ b/arch/sparc/kernel/signal_64.c
@@ -226,6 +226,17 @@ do_sigsegv:
 	force_sig(SIGSEGV, current);
 }
 
+/* Checks if the fp is valid.  We always build rt signal frames which
+ * are 16-byte aligned, therefore we can always enforce that the
+ * restore frame has that property as well.
+ */
+static bool invalid_frame_pointer(void __user *fp)
+{
+	if (((unsigned long) fp) & 15)
+		return true;
+	return false;
+}
+
 struct rt_signal_frame {
 	struct sparc_stackf	ss;
 	siginfo_t		info;
@@ -238,8 +249,8 @@ struct rt_signal_frame {
 
 void do_rt_sigreturn(struct pt_regs *regs)
 {
+	unsigned long tpc, tnpc, tstate, ufp;
 	struct rt_signal_frame __user *sf;
-	unsigned long tpc, tnpc, tstate;
 	__siginfo_fpu_t __user *fpu_save;
 	__siginfo_rwin_t __user *rwin_save;
 	sigset_t set;
@@ -253,10 +264,16 @@ void do_rt_sigreturn(struct pt_regs *regs)
 		(regs->u_regs [UREG_FP] + STACK_BIAS);
 
 	/* 1. Make sure we are not getting garbage from the user */
-	if (((unsigned long) sf) & 3)
+	if (invalid_frame_pointer(sf))
+		goto segv;
+
+	if (get_user(ufp, &sf->regs.u_regs[UREG_FP]))
 		goto segv;
 
-	err = get_user(tpc, &sf->regs.tpc);
+	if ((ufp + STACK_BIAS) & 0x7)
+		goto segv;
+
+	err = __get_user(tpc, &sf->regs.tpc);
 	err |= __get_user(tnpc, &sf->regs.tnpc);
 	if (test_thread_flag(TIF_32BIT)) {
 		tpc &= 0xffffffff;
@@ -300,14 +317,6 @@ segv:
 	force_sig(SIGSEGV, current);
 }
 
-/* Checks if the fp is valid */
-static int invalid_frame_pointer(void __user *fp)
-{
-	if (((unsigned long) fp) & 15)
-		return 1;
-	return 0;
-}
-
 static inline void __user *get_sigframe(struct ksignal *ksig, struct pt_regs *regs, unsigned long framesize)
 {
 	unsigned long sp = regs->u_regs[UREG_FP] + STACK_BIAS;
diff --git a/arch/sparc/kernel/sigutil_32.c b/arch/sparc/kernel/sigutil_32.c
index 0f6eebe71e6c..e5fe8cef9a69 100644
--- a/arch/sparc/kernel/sigutil_32.c
+++ b/arch/sparc/kernel/sigutil_32.c
@@ -48,6 +48,10 @@ int save_fpu_state(struct pt_regs *regs, __siginfo_fpu_t __user *fpu)
 int restore_fpu_state(struct pt_regs *regs, __siginfo_fpu_t __user *fpu)
 {
 	int err;
+
+	if (((unsigned long) fpu) & 3)
+		return -EFAULT;
+
 #ifdef CONFIG_SMP
 	if (test_tsk_thread_flag(current, TIF_USEDFPU))
 		regs->psr &= ~PSR_EF;
@@ -97,7 +101,10 @@ int restore_rwin_state(__siginfo_rwin_t __user *rp)
 	struct thread_info *t = current_thread_info();
 	int i, wsaved, err;
 
-	__get_user(wsaved, &rp->wsaved);
+	if (((unsigned long) rp) & 3)
+		return -EFAULT;
+
+	get_user(wsaved, &rp->wsaved);
 	if (wsaved > NSWINS)
 		return -EFAULT;
 
diff --git a/arch/sparc/kernel/sigutil_64.c b/arch/sparc/kernel/sigutil_64.c
index 387834a9c56a..36aadcbeac69 100644
--- a/arch/sparc/kernel/sigutil_64.c
+++ b/arch/sparc/kernel/sigutil_64.c
@@ -37,7 +37,10 @@ int restore_fpu_state(struct pt_regs *regs, __siginfo_fpu_t __user *fpu)
 	unsigned long fprs;
 	int err;
 
-	err = __get_user(fprs, &fpu->si_fprs);
+	if (((unsigned long) fpu) & 7)
+		return -EFAULT;
+
+	err = get_user(fprs, &fpu->si_fprs);
 	fprs_write(0);
 	regs->tstate &= ~TSTATE_PEF;
 	if (fprs & FPRS_DL)
@@ -72,7 +75,10 @@ int restore_rwin_state(__siginfo_rwin_t __user *rp)
 	struct thread_info *t = current_thread_info();
 	int i, wsaved, err;
 
-	__get_user(wsaved, &rp->wsaved);
+	if (((unsigned long) rp) & 7)
+		return -EFAULT;
+
+	get_user(wsaved, &rp->wsaved);
 	if (wsaved > NSWINS)
 		return -EFAULT;
 
-- 
2.9.1

[toc] | [prev] | [next] | [standalone]


#1443265 — [PATCH 3.12 22/88] powerpc: Use privileged SPR number for MMCR2

FromJiri Slaby <jslaby@suse.cz>
Date2016-07-14 10:50 +0200
Subject[PATCH 3.12 22/88] powerpc: Use privileged SPR number for MMCR2
Message-ID<rUKvg-7nE-11@gated-at.bofh.it>
In reply to#1443166
From: Thomas Huth <thuth@redhat.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 8dd75ccb571f3c92c48014b3dabd3d51a115ab41 upstream.

We are already using the privileged versions of MMCR0, MMCR1
and MMCRA in the kernel, so for MMCR2, we should better use
the privileged versions, too, to be consistent.

Fixes: 240686c13687 ("powerpc: Initialise PMU related regs on Power8")
Suggested-by: Paul Mackerras <paulus@ozlabs.org>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Acked-by: Paul Mackerras <paulus@ozlabs.org>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 arch/powerpc/include/asm/reg.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/powerpc/include/asm/reg.h b/arch/powerpc/include/asm/reg.h
index ad261d56ae39..53762dbf547c 100644
--- a/arch/powerpc/include/asm/reg.h
+++ b/arch/powerpc/include/asm/reg.h
@@ -647,7 +647,7 @@
 #define   MMCR0_FCWAIT	0x00000002UL /* freeze counter in WAIT state */
 #define   MMCR0_FCHV	0x00000001UL /* freeze conditions in hypervisor mode */
 #define SPRN_MMCR1	798
-#define SPRN_MMCR2	769
+#define SPRN_MMCR2	785
 #define SPRN_MMCRA	0x312
 #define   MMCRA_SDSYNC	0x80000000UL /* SDAR synced with SIAR */
 #define   MMCRA_SDAR_DCACHE_MISS 0x40000000UL
-- 
2.9.1

[toc] | [prev] | [next] | [standalone]


#1443266 — [PATCH 3.12 20/88] ARM: fix PTRACE_SETVFPREGS on SMP systems

FromJiri Slaby <jslaby@suse.cz>
Date2016-07-14 10:50 +0200
Subject[PATCH 3.12 20/88] ARM: fix PTRACE_SETVFPREGS on SMP systems
Message-ID<rUKvg-7nE-13@gated-at.bofh.it>
In reply to#1443166
From: Russell King <rmk+kernel@armlinux.org.uk>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit e2dfb4b880146bfd4b6aa8e138c0205407cebbaf upstream.

PTRACE_SETVFPREGS fails to properly mark the VFP register set to be
reloaded, because it undoes one of the effects of vfp_flush_hwstate().

Specifically vfp_flush_hwstate() sets thread->vfpstate.hard.cpu to
an invalid CPU number, but vfp_set() overwrites this with the original
CPU number, thereby rendering the hardware state as apparently "valid",
even though the software state is more recent.

Fix this by reverting the previous change.

Fixes: 8130b9d7b9d8 ("ARM: 7308/1: vfp: flush thread hwstate before copying ptrace registers")
Acked-by: Will Deacon <will.deacon@arm.com>
Tested-by: Simon Marchi <simon.marchi@ericsson.com>
Signed-off-by: Russell King <rmk+kernel@armlinux.org.uk>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 arch/arm/kernel/ptrace.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm/kernel/ptrace.c b/arch/arm/kernel/ptrace.c
index 0dd3b79b15c3..ec33df500f86 100644
--- a/arch/arm/kernel/ptrace.c
+++ b/arch/arm/kernel/ptrace.c
@@ -733,8 +733,8 @@ static int vfp_set(struct task_struct *target,
 	if (ret)
 		return ret;
 
-	vfp_flush_hwstate(thread);
 	thread->vfpstate.hard = new_vfp;
+	vfp_flush_hwstate(thread);
 
 	return 0;
 }
-- 
2.9.1

[toc] | [prev] | [next] | [standalone]


#1443267 — [PATCH 3.12 21/88] powerpc: Fix definition of SIAR and SDAR registers

FromJiri Slaby <jslaby@suse.cz>
Date2016-07-14 10:50 +0200
Subject[PATCH 3.12 21/88] powerpc: Fix definition of SIAR and SDAR registers
Message-ID<rUKvg-7nE-19@gated-at.bofh.it>
In reply to#1443166
From: Thomas Huth <thuth@redhat.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit d23fac2b27d94aeb7b65536a50d32bfdc21fe01e upstream.

The SIAR and SDAR registers are available twice, one time as SPRs
780 / 781 (unprivileged, but read-only), and one time as the SPRs
796 / 797 (privileged, but read and write). The Linux kernel code
currently uses the unprivileged  SPRs - while this is OK for reading,
writing to that register of course does not work.
Since the KVM code tries to write to this register, too (see the mtspr
in book3s_hv_rmhandlers.S), the contents of this register sometimes get
lost for the guests, e.g. during migration of a VM.
To fix this issue, simply switch to the privileged SPR numbers instead.

Signed-off-by: Thomas Huth <thuth@redhat.com>
Acked-by: Paul Mackerras <paulus@ozlabs.org>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 arch/powerpc/include/asm/reg.h | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/powerpc/include/asm/reg.h b/arch/powerpc/include/asm/reg.h
index 3ce6b7b5ca19..ad261d56ae39 100644
--- a/arch/powerpc/include/asm/reg.h
+++ b/arch/powerpc/include/asm/reg.h
@@ -681,13 +681,13 @@
 #define SPRN_PMC6	792
 #define SPRN_PMC7	793
 #define SPRN_PMC8	794
-#define SPRN_SIAR	780
-#define SPRN_SDAR	781
 #define SPRN_SIER	784
 #define   SIER_SIPR		0x2000000	/* Sampled MSR_PR */
 #define   SIER_SIHV		0x1000000	/* Sampled MSR_HV */
 #define   SIER_SIAR_VALID	0x0400000	/* SIAR contents valid */
 #define   SIER_SDAR_VALID	0x0200000	/* SDAR contents valid */
+#define SPRN_SIAR	796
+#define SPRN_SDAR	797
 
 /* When EBB is enabled, some of MMCR0/MMCR2/SIER are user accessible */
 #define MMCR0_USER_MASK	(MMCR0_FC | MMCR0_PMXE | MMCR0_PMAO)
-- 
2.9.1

[toc] | [prev] | [next] | [standalone]


#1443268 — [PATCH 3.12 02/88] MIPS: Fix 64k page support for 32 bit kernels.

FromJiri Slaby <jslaby@suse.cz>
Date2016-07-14 10:50 +0200
Subject[PATCH 3.12 02/88] MIPS: Fix 64k page support for 32 bit kernels.
Message-ID<rUKvg-7nE-15@gated-at.bofh.it>
In reply to#1443166
From: Ralf Baechle <ralf@linux-mips.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit d7de413475f443957a0c1d256e405d19b3a2cb22 upstream.

TASK_SIZE was defined as 0x7fff8000UL which for 64k pages is not a
multiple of the page size.  Somewhere further down the math fails
such that executing an ELF binary fails.

Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
Tested-by: Joshua Henderson <joshua.henderson@microchip.com>
Cc: James Hogan <james.hogan@imgtec.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 arch/mips/include/asm/processor.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/mips/include/asm/processor.h b/arch/mips/include/asm/processor.h
index 3605b844ad87..efe9964ea9b4 100644
--- a/arch/mips/include/asm/processor.h
+++ b/arch/mips/include/asm/processor.h
@@ -51,7 +51,7 @@ extern unsigned int vced_count, vcei_count;
  * User space process size: 2GB. This is hardcoded into a few places,
  * so don't change it unless you know what you are doing.
  */
-#define TASK_SIZE	0x7fff8000UL
+#define TASK_SIZE	0x80000000UL
 #endif
 
 #ifdef __KERNEL__
-- 
2.9.1

[toc] | [prev] | [next] | [standalone]


#1443269 — [PATCH 3.12 25/88] wext: Fix 32 bit iwpriv compatibility issue with 64 bit Kernel

FromJiri Slaby <jslaby@suse.cz>
Date2016-07-14 10:50 +0200
Subject[PATCH 3.12 25/88] wext: Fix 32 bit iwpriv compatibility issue with 64 bit Kernel
Message-ID<rUKvg-7nE-17@gated-at.bofh.it>
In reply to#1443166
From: Prasun Maiti <prasunmaiti87@gmail.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 3d5fdff46c4b2b9534fa2f9fc78e90a48e0ff724 upstream.

iwpriv app uses iw_point structure to send data to Kernel. The iw_point
structure holds a pointer. For compatibility Kernel converts the pointer
as required for WEXT IOCTLs (SIOCIWFIRST to SIOCIWLAST). Some drivers
may use iw_handler_def.private_args to populate iwpriv commands instead
of iw_handler_def.private. For those case, the IOCTLs from
SIOCIWFIRSTPRIV to SIOCIWLASTPRIV will follow the path ndo_do_ioctl().
Accordingly when the filled up iw_point structure comes from 32 bit
iwpriv to 64 bit Kernel, Kernel will not convert the pointer and sends
it to driver. So, the driver may get the invalid data.

The pointer conversion for the IOCTLs (SIOCIWFIRSTPRIV to
SIOCIWLASTPRIV), which follow the path ndo_do_ioctl(), is mandatory.
This patch adds pointer conversion from 32 bit to 64 bit and vice versa,
if the ioctl comes from 32 bit iwpriv to 64 bit Kernel.

Signed-off-by: Prasun Maiti <prasunmaiti87@gmail.com>
Signed-off-by: Ujjal Roy <royujjal@gmail.com>
Tested-by: Dibyajyoti Ghosh <dibyajyotig@gmail.com>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 net/wireless/wext-core.c | 25 +++++++++++++++++++++++--
 1 file changed, 23 insertions(+), 2 deletions(-)

diff --git a/net/wireless/wext-core.c b/net/wireless/wext-core.c
index 87dd619fb2e9..1c9a505b7019 100644
--- a/net/wireless/wext-core.c
+++ b/net/wireless/wext-core.c
@@ -954,8 +954,29 @@ static int wireless_process_ioctl(struct net *net, struct ifreq *ifr,
 			return private(dev, iwr, cmd, info, handler);
 	}
 	/* Old driver API : call driver ioctl handler */
-	if (dev->netdev_ops->ndo_do_ioctl)
-		return dev->netdev_ops->ndo_do_ioctl(dev, ifr, cmd);
+	if (dev->netdev_ops->ndo_do_ioctl) {
+#ifdef CONFIG_COMPAT
+		if (info->flags & IW_REQUEST_FLAG_COMPAT) {
+			int ret = 0;
+			struct iwreq iwr_lcl;
+			struct compat_iw_point *iwp_compat = (void *) &iwr->u.data;
+
+			memcpy(&iwr_lcl, iwr, sizeof(struct iwreq));
+			iwr_lcl.u.data.pointer = compat_ptr(iwp_compat->pointer);
+			iwr_lcl.u.data.length = iwp_compat->length;
+			iwr_lcl.u.data.flags = iwp_compat->flags;
+
+			ret = dev->netdev_ops->ndo_do_ioctl(dev, (void *) &iwr_lcl, cmd);
+
+			iwp_compat->pointer = ptr_to_compat(iwr_lcl.u.data.pointer);
+			iwp_compat->length = iwr_lcl.u.data.length;
+			iwp_compat->flags = iwr_lcl.u.data.flags;
+
+			return ret;
+		} else
+#endif
+			return dev->netdev_ops->ndo_do_ioctl(dev, ifr, cmd);
+	}
 	return -EOPNOTSUPP;
 }
 
-- 
2.9.1

[toc] | [prev] | [next] | [standalone]


#1443270 — [PATCH 3.12 13/88] netlink: Fix dump skb leak/double free

FromJiri Slaby <jslaby@suse.cz>
Date2016-07-14 10:50 +0200
Subject[PATCH 3.12 13/88] netlink: Fix dump skb leak/double free
Message-ID<rUKvg-7nE-23@gated-at.bofh.it>
In reply to#1443166
From: Herbert Xu <herbert@gondor.apana.org.au>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 92964c79b357efd980812c4de5c1fd2ec8bb5520 ]

When we free cb->skb after a dump, we do it after releasing the
lock.  This means that a new dump could have started in the time
being and we'll end up freeing their skb instead of ours.

This patch saves the skb and module before we unlock so we free
the right memory.

Fixes: 16b304f3404f ("netlink: Eliminate kmalloc in netlink dump operation.")
Reported-by: Baozeng Ding <sploving1@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Acked-by: Cong Wang <xiyou.wangcong@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 net/netlink/af_netlink.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c
index 10805856dfba..bb04abe72d76 100644
--- a/net/netlink/af_netlink.c
+++ b/net/netlink/af_netlink.c
@@ -2658,6 +2658,7 @@ static int netlink_dump(struct sock *sk)
 	struct netlink_callback *cb;
 	struct sk_buff *skb = NULL;
 	struct nlmsghdr *nlh;
+	struct module *module;
 	int len, err = -ENOBUFS;
 	int alloc_size;
 
@@ -2707,9 +2708,11 @@ static int netlink_dump(struct sock *sk)
 		cb->done(cb);
 
 	nlk->cb_running = false;
+	module = cb->module;
+	skb = cb->skb;
 	mutex_unlock(nlk->cb_mutex);
-	module_put(cb->module);
-	consume_skb(cb->skb);
+	module_put(module);
+	consume_skb(skb);
 	return 0;
 
 errout_skb:
-- 
2.9.1

[toc] | [prev] | [next] | [standalone]


#1443271 — [PATCH 3.12 29/88] netfilter: x_tables: add and use xt_check_entry_offsets

FromJiri Slaby <jslaby@suse.cz>
Date2016-07-14 10:50 +0200
Subject[PATCH 3.12 29/88] netfilter: x_tables: add and use xt_check_entry_offsets
Message-ID<rUKvg-7nE-31@gated-at.bofh.it>
In reply to#1443166
From: Florian Westphal <fw@strlen.de>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 7d35812c3214afa5b37a675113555259cfd67b98 upstream.

Currently arp/ip and ip6tables each implement a short helper to check that
the target offset is large enough to hold one xt_entry_target struct and
that t->u.target_size fits within the current rule.

Unfortunately these checks are not sufficient.

To avoid adding new tests to all of ip/ip6/arptables move the current
checks into a helper, then extend this helper in followup patches.

Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 include/linux/netfilter/x_tables.h |  4 ++++
 net/ipv4/netfilter/arp_tables.c    | 11 +----------
 net/ipv4/netfilter/ip_tables.c     | 12 +-----------
 net/ipv6/netfilter/ip6_tables.c    | 12 +-----------
 net/netfilter/x_tables.c           | 34 ++++++++++++++++++++++++++++++++++
 5 files changed, 41 insertions(+), 32 deletions(-)

diff --git a/include/linux/netfilter/x_tables.h b/include/linux/netfilter/x_tables.h
index dd49566315c6..20ced1191c50 100644
--- a/include/linux/netfilter/x_tables.h
+++ b/include/linux/netfilter/x_tables.h
@@ -239,6 +239,10 @@ extern void xt_unregister_match(struct xt_match *target);
 extern int xt_register_matches(struct xt_match *match, unsigned int n);
 extern void xt_unregister_matches(struct xt_match *match, unsigned int n);
 
+int xt_check_entry_offsets(const void *base,
+			   unsigned int target_offset,
+			   unsigned int next_offset);
+
 extern int xt_check_match(struct xt_mtchk_param *,
 			  unsigned int size, u_int8_t proto, bool inv_proto);
 extern int xt_check_target(struct xt_tgchk_param *,
diff --git a/net/ipv4/netfilter/arp_tables.c b/net/ipv4/netfilter/arp_tables.c
index 473ec559ce7b..7232b8301ea9 100644
--- a/net/ipv4/netfilter/arp_tables.c
+++ b/net/ipv4/netfilter/arp_tables.c
@@ -488,19 +488,10 @@ static int mark_source_chains(const struct xt_table_info *newinfo,
 
 static inline int check_entry(const struct arpt_entry *e)
 {
-	const struct xt_entry_target *t;
-
 	if (!arp_checkentry(&e->arp))
 		return -EINVAL;
 
-	if (e->target_offset + sizeof(struct xt_entry_target) > e->next_offset)
-		return -EINVAL;
-
-	t = arpt_get_target_c(e);
-	if (e->target_offset + t->u.target_size > e->next_offset)
-		return -EINVAL;
-
-	return 0;
+	return xt_check_entry_offsets(e, e->target_offset, e->next_offset);
 }
 
 static inline int check_target(struct arpt_entry *e, const char *name)
diff --git a/net/ipv4/netfilter/ip_tables.c b/net/ipv4/netfilter/ip_tables.c
index dba9d8070d07..ce2ba7365434 100644
--- a/net/ipv4/netfilter/ip_tables.c
+++ b/net/ipv4/netfilter/ip_tables.c
@@ -582,20 +582,10 @@ static void cleanup_match(struct xt_entry_match *m, struct net *net)
 static int
 check_entry(const struct ipt_entry *e)
 {
-	const struct xt_entry_target *t;
-
 	if (!ip_checkentry(&e->ip))
 		return -EINVAL;
 
-	if (e->target_offset + sizeof(struct xt_entry_target) >
-	    e->next_offset)
-		return -EINVAL;
-
-	t = ipt_get_target_c(e);
-	if (e->target_offset + t->u.target_size > e->next_offset)
-		return -EINVAL;
-
-	return 0;
+	return xt_check_entry_offsets(e, e->target_offset, e->next_offset);
 }
 
 static int
diff --git a/net/ipv6/netfilter/ip6_tables.c b/net/ipv6/netfilter/ip6_tables.c
index 97a8d2525c26..ac061d40f920 100644
--- a/net/ipv6/netfilter/ip6_tables.c
+++ b/net/ipv6/netfilter/ip6_tables.c
@@ -592,20 +592,10 @@ static void cleanup_match(struct xt_entry_match *m, struct net *net)
 static int
 check_entry(const struct ip6t_entry *e)
 {
-	const struct xt_entry_target *t;
-
 	if (!ip6_checkentry(&e->ipv6))
 		return -EINVAL;
 
-	if (e->target_offset + sizeof(struct xt_entry_target) >
-	    e->next_offset)
-		return -EINVAL;
-
-	t = ip6t_get_target_c(e);
-	if (e->target_offset + t->u.target_size > e->next_offset)
-		return -EINVAL;
-
-	return 0;
+	return xt_check_entry_offsets(e, e->target_offset, e->next_offset);
 }
 
 static int check_match(struct xt_entry_match *m, struct xt_mtchk_param *par)
diff --git a/net/netfilter/x_tables.c b/net/netfilter/x_tables.c
index 8b03028cca69..55b1e0ccb0e2 100644
--- a/net/netfilter/x_tables.c
+++ b/net/netfilter/x_tables.c
@@ -560,6 +560,40 @@ int xt_compat_match_to_user(const struct xt_entry_match *m,
 EXPORT_SYMBOL_GPL(xt_compat_match_to_user);
 #endif /* CONFIG_COMPAT */
 
+/**
+ * xt_check_entry_offsets - validate arp/ip/ip6t_entry
+ *
+ * @base: pointer to arp/ip/ip6t_entry
+ * @target_offset: the arp/ip/ip6_t->target_offset
+ * @next_offset: the arp/ip/ip6_t->next_offset
+ *
+ * validates that target_offset and next_offset are sane.
+ *
+ * The arp/ip/ip6t_entry structure @base must have passed following tests:
+ * - it must point to a valid memory location
+ * - base to base + next_offset must be accessible, i.e. not exceed allocated
+ *   length.
+ *
+ * Return: 0 on success, negative errno on failure.
+ */
+int xt_check_entry_offsets(const void *base,
+			   unsigned int target_offset,
+			   unsigned int next_offset)
+{
+	const struct xt_entry_target *t;
+	const char *e = base;
+
+	if (target_offset + sizeof(*t) > next_offset)
+		return -EINVAL;
+
+	t = (void *)(e + target_offset);
+	if (target_offset + t->u.target_size > next_offset)
+		return -EINVAL;
+
+	return 0;
+}
+EXPORT_SYMBOL(xt_check_entry_offsets);
+
 int xt_check_target(struct xt_tgchk_param *par,
 		    unsigned int size, u_int8_t proto, bool inv_proto)
 {
-- 
2.9.1

[toc] | [prev] | [next] | [standalone]


#1443272 — [PATCH 3.12 24/88] ecryptfs: forbid opening files without mmap handler

FromJiri Slaby <jslaby@suse.cz>
Date2016-07-14 10:50 +0200
Subject[PATCH 3.12 24/88] ecryptfs: forbid opening files without mmap handler
Message-ID<rUKvg-7nE-21@gated-at.bofh.it>
In reply to#1443166
From: Jann Horn <jannh@google.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 2f36db71009304b3f0b95afacd8eba1f9f046b87 upstream.

This prevents users from triggering a stack overflow through a recursive
invocation of pagefault handling that involves mapping procfs files into
virtual memory.

Signed-off-by: Jann Horn <jannh@google.com>
Acked-by: Tyler Hicks <tyhicks@canonical.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 fs/ecryptfs/kthread.c | 13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

diff --git a/fs/ecryptfs/kthread.c b/fs/ecryptfs/kthread.c
index f1ea610362c6..9b661a4ccee7 100644
--- a/fs/ecryptfs/kthread.c
+++ b/fs/ecryptfs/kthread.c
@@ -25,6 +25,7 @@
 #include <linux/slab.h>
 #include <linux/wait.h>
 #include <linux/mount.h>
+#include <linux/file.h>
 #include "ecryptfs_kernel.h"
 
 struct ecryptfs_open_req {
@@ -147,7 +148,7 @@ int ecryptfs_privileged_open(struct file **lower_file,
 	flags |= IS_RDONLY(lower_dentry->d_inode) ? O_RDONLY : O_RDWR;
 	(*lower_file) = dentry_open(&req.path, flags, cred);
 	if (!IS_ERR(*lower_file))
-		goto out;
+		goto have_file;
 	if ((flags & O_ACCMODE) == O_RDONLY) {
 		rc = PTR_ERR((*lower_file));
 		goto out;
@@ -165,8 +166,16 @@ int ecryptfs_privileged_open(struct file **lower_file,
 	mutex_unlock(&ecryptfs_kthread_ctl.mux);
 	wake_up(&ecryptfs_kthread_ctl.wait);
 	wait_for_completion(&req.done);
-	if (IS_ERR(*lower_file))
+	if (IS_ERR(*lower_file)) {
 		rc = PTR_ERR(*lower_file);
+		goto out;
+	}
+have_file:
+	if ((*lower_file)->f_op->mmap == NULL) {
+		fput(*lower_file);
+		*lower_file = NULL;
+		rc = -EMEDIUMTYPE;
+	}
 out:
 	return rc;
 }
-- 
2.9.1

[toc] | [prev] | [next] | [standalone]


#1443273 — [PATCH 3.12 18/88] drivers: macintosh: rack-meter: limit idle ticks to total ticks

FromJiri Slaby <jslaby@suse.cz>
Date2016-07-14 10:50 +0200
Subject[PATCH 3.12 18/88] drivers: macintosh: rack-meter: limit idle ticks to total ticks
Message-ID<rUKvg-7nE-25@gated-at.bofh.it>
In reply to#1443166
From: Aaro Koskinen <aaro.koskinen@iki.fi>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit c796d1d97c3035cf54d4d5a9e75abd094db80e76 upstream.

Limit idle ticks to total ticks. This prevents the annoying rackmeter
leds fully ON / OFF blinking state that happens on fully idling
G5 Xserve systems.

Signed-off-by: Aaro Koskinen <aaro.koskinen@iki.fi>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Cc: Oliver Neukum <oliver@neukum.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/macintosh/rack-meter.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/macintosh/rack-meter.c b/drivers/macintosh/rack-meter.c
index cad0e19b47a2..0b569da3c467 100644
--- a/drivers/macintosh/rack-meter.c
+++ b/drivers/macintosh/rack-meter.c
@@ -225,6 +225,7 @@ static void rackmeter_do_timer(struct work_struct *work)
 
 	total_idle_ticks = get_cpu_idle_time(cpu);
 	idle_ticks = (unsigned int) (total_idle_ticks - rcpu->prev_idle);
+	idle_ticks = min(idle_ticks, total_ticks);
 	rcpu->prev_idle = total_idle_ticks;
 
 	/* We do a very dumb calculation to update the LEDs for now,
-- 
2.9.1

[toc] | [prev] | [next] | [standalone]


#1443274 — [PATCH 3.12 17/88] macintosh/therm_windtunnel: Export I2C module alias information

FromJiri Slaby <jslaby@suse.cz>
Date2016-07-14 10:50 +0200
Subject[PATCH 3.12 17/88] macintosh/therm_windtunnel: Export I2C module alias information
Message-ID<rUKvg-7nE-29@gated-at.bofh.it>
In reply to#1443166
From: Javier Martinez Canillas <javier@osg.samsung.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit cb0eefcc3271ea1d370476dd29685918b99c5a9f upstream.

The I2C core always reports the MODALIAS uevent as "i2c:<client name"
regardless if the driver was matched using the I2C id_table or the
of_match_table. So the driver needs to export the I2C table and this
be built into the module or udev won't have the necessary information
to auto load the correct module when the device is added.

Signed-off-by: Javier Martinez Canillas <javier@osg.samsung.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Cc: Oliver Neukum <oliver@neukum.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/macintosh/therm_windtunnel.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/macintosh/therm_windtunnel.c b/drivers/macintosh/therm_windtunnel.c
index 3b4a157714b1..b40ed32379ec 100644
--- a/drivers/macintosh/therm_windtunnel.c
+++ b/drivers/macintosh/therm_windtunnel.c
@@ -408,6 +408,7 @@ static const struct i2c_device_id therm_windtunnel_id[] = {
 	{ "therm_adm1030", adm1030 },
 	{ }
 };
+MODULE_DEVICE_TABLE(i2c, therm_windtunnel_id);
 
 static int
 do_probe(struct i2c_client *cl, const struct i2c_device_id *id)
-- 
2.9.1

[toc] | [prev] | [next] | [standalone]


Page 4 of 5 — ← Prev page 1 2 3 [4] 5  Next page →

Back to top | Article view | linux.kernel


csiph-web