Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1449869 > unrolled thread
| Started by | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| First post | 2016-07-25 23:10 +0200 |
| Last post | 2016-07-27 06:50 +0200 |
| Articles | 20 on this page of 100 — 4 participants |
Back to article view | Back to linux.kernel
[PATCH 4.4 000/146] 4.4.16-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:10 +0200
[PATCH 4.4 060/146] iommu/amd: Fix unity mapping initialization race Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:20 +0200
[PATCH 4.4 134/146] ovl: verify upper dentry in ovl_remove_and_whiteout() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:20 +0200
[PATCH 4.4 139/146] cifs: dynamic allocation of ntlmssp blob Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:20 +0200
[PATCH 4.4 145/146] drm/i915: Revert DisplayPort fast link training feature Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:20 +0200
[PATCH 4.4 097/146] iio: Fix error handling in iio_trigger_attach_poll_func Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:20 +0200
[PATCH 4.4 054/146] HID: hiddev: validate num_values for HIDIOCGUSAGES, HIDIOCSUSAGES commands Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:20 +0200
[PATCH 4.4 116/146] ALSA: dummy: Fix a use-after-free at closing Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:20 +0200
[PATCH 4.4 096/146] xen/balloon: Fix declared-but-not-defined warning Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:20 +0200
[PATCH 4.4 146/146] ovl: verify upper dentry before unlink and rename Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:20 +0200
[PATCH 4.4 143/146] tmpfs: dont undo fallocate past its last page Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:20 +0200
[PATCH 4.4 144/146] tmpfs: fix regression hang in fallocate undo Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:20 +0200
[PATCH 4.4 072/146] drm/amdkfd: unbind only existing processes Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:20 +0200
[PATCH 4.4 105/146] iio: hudmidity: hdc100x: fix incorrect shifting and scaling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 119/146] ALSA: au88x0: Fix calculation in vortex_wtdma_bufshift() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 141/146] xen/acpi: allow xen-acpi-processor driver to load on Xen 4.7 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 102/146] iio: proximity: as3935: fix buffer stack trashing Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 110/146] iio:ad7266: Fix probe deferral for vref Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 132/146] ARM: mvebu: fix HW I/O coherency related deadlocks Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 099/146] iio: light apds9960: Add the missing dev.parent Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 137/146] 53c700: fix BUG on untagged commands Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 138/146] Fix reconnect to not defer smb3 session reconnect long after socket reconnect Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 142/146] crypto: qat - make qat_asym_algs.o depend on asn1 headers Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 129/146] ALSA: hda: add AMD Stoney PCI ID with proper driver caps Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 123/146] ALSA: hda - Add PCI ID for Kabylake-H Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 117/146] ALSA: hda - Fix the headset mic jack detection on Dell machine Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 135/146] scsi: fix race between simultaneous decrements of ->host_failed Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 100/146] iio: proximity: as3935: correct IIO_CHAN_INFO_RAW output Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 121/146] ALSA: timer: Fix negative queue usage by racy accesses Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 062/146] ipmi: Remove smi_msg from waiting_rcv_msgs list before handle_one_recv_msg() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 120/146] ALSA: echoaudio: Fix memory allocation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 064/146] vfs: add d_real_inode() helper Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 106/146] staging: iio: accel: fix error check Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 133/146] ovl: Copy up underlying inodes ->i_mode to overlay inode Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
Re: [PATCH 4.4 133/146] ovl: Copy up underlying inodes ->i_mode to overlay inode Eryu Guan <eguan@redhat.com> - 2016-08-03 09:40 +0200
Re: [PATCH 4.4 133/146] ovl: Copy up underlying inodes ->i_mode to overlay inode Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-08-03 10:00 +0200
Re: [PATCH 4.4 133/146] ovl: Copy up underlying inodes ->i_mode to overlay inode Eryu Guan <eguan@redhat.com> - 2016-08-03 10:20 +0200
Re: [PATCH 4.4 133/146] ovl: Copy up underlying inodes ->i_mode to overlay inode Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-08-03 13:20 +0200
[PATCH 4.4 090/146] drm/vmwgfx: Work around mode set failure in 2D VMs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 130/146] ARM: sunxi/dt: make the CHIP inherit from allwinner,sun5i-a13 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 126/146] ALSA: pcm: Free chmap at PCM free callback, too Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 103/146] iio: humidity: hdc100x: correct humidity integration time mask Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 122/146] ALSA: hda/realtek: Add Lenovo L460 to docking unit fixup Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 124/146] ALSA: hda - fix read before array start Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 128/146] ALSA: hda - fix use-after-free after module unload Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 104/146] iio: humidity: hdc100x: fix IIO_TEMP channel reporting Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 140/146] File names with trailing period or space need special case conversion Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 111/146] tty: vt: Fix soft lockup in fbcon cursor blink timer. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 118/146] ALSA: hda / realtek - add two more Thinkpad IDs (5050,5053) for tpt460 fixup Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 127/146] ALSA: ctl: Stop notification after disconnection Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 131/146] ARM: dts: armada-38x: fix MBUS_ID for crypto SRAM on Armada 385 Linksys Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 101/146] iio: proximity: as3935: remove triggered buffer processing Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 125/146] ALSA: hda/realtek - add new pin definition in alc225 pin quirk table Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 136/146] s390: fix test_fp_ctl inline assembly contraints Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:30 +0200
[PATCH 4.4 112/146] tty/vt/keyboard: fix OOB access in do_compute_shiftstate() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:40 +0200
[PATCH 4.4 063/146] arm64: Rework valid_user_regs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:40 +0200
[PATCH 4.4 109/146] iio:ad7266: Fix support for optional regulators Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-25 23:40 +0200
[PATCH 4.4 108/146] iio:ad7266: Fix broken regulator error handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:30 +0200
[PATCH 4.4 079/146] drm/nouveau: fix for disabled fbdev emulation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 078/146] drm/nouveau/fbcon: fix out-of-bounds memory accesses Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 022/146] locking/static_key: Fix concurrent static_key_slow_inc() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 083/146] drm/i915: Update ifdeffery for mutex->owner Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 059/146] iommu/vt-d: Enable QI on all IOMMUs before setting root entry Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 093/146] drm/vmwgfx: Fix error paths when mapping framebuffer Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 107/146] iio: accel: kxsd9: fix the usage of spi_w8r8() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 098/146] iio:st_pressure: fix sampling gains (bring inline with ABI) Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 089/146] drm/vmwgfx: Add an option to change assumed FB bpp Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 058/146] iommu/arm-smmu: Wire up map_sg for arm-smmu-v3 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 088/146] drm/ttm: Make ttm_bo_mem_compat available Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 086/146] drm: make drm_atomic_set_mode_prop_for_crtc() more reliable Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 061/146] drm/mgag200: Black screen fix for G200e rev 4 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 087/146] drm: atmel-hlcdc: actually disable scaling when no scaling is required Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 092/146] drm/vmwgfx: Delay pinning fbdev framebuffer until after mode set Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 091/146] drm/vmwgfx: Check pin count before attempting to move a buffer Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 085/146] drm: add missing drm_mode_set_crtcinfo call Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 095/146] perf/x86: Fix undefined shift on 32-bit kernels Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 077/146] drm/nouveau/gr/gf100-: update sm error decoding from gk20a nvgpu headers Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 055/146] HID: multitouch: enable palm rejection for Windows Precision Touchpad Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 080/146] drm/nouveau/disp/sor/gf119: select correct sor when poking training pattern Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
[PATCH 4.4 066/146] percpu: fix synchronization between chunk->map_extend_work and chunk destruction Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 068/146] btrfs: account for non-CoWd blocks in btrfs_abort_transaction Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 023/146] x86, build: copy ldlinux.c32 to image.iso Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 065/146] af_unix: fix hard linked sockets on overlay Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 019/146] of: irq: fix of_irq_get[_byname]() kernel-doc Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 073/146] drm/amdkfd: destroy dbgmgr in notifier release Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 075/146] virtio_balloon: fix PFN format for virtio-1 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 018/146] of: fix autoloading due to broken modalias with no compatible Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 074/146] drm/dp/mst: Always clear proposed vcpi table for port. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 056/146] tracing: Handle NULL formats in hold_module_trace_bprintk_format() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 014/146] usb: common: otg-fsm: add license to usb-otg-fsm Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 020/146] locking/ww_mutex: Report recursive ww_mutex locking early Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 070/146] drm/amdgpu/gfx7: fix broken condition check Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 021/146] locking/qspinlock: Fix spin_unlock_wait() some more Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 057/146] base: make module_create_drivers_dir race-free Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 076/146] drm/nouveau/disp/sor/gf119: both links use the same training register Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 067/146] percpu: fix synchronization between synchronous map extension and chunk destruction Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
[PATCH 4.4 069/146] drm/radeon: fix asic initialization for virtualized environments Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:50 +0200
Re: [PATCH 4.4 000/146] 4.4.16-stable review Shuah Khan <shuah.kh@samsung.com> - 2016-07-26 04:10 +0200
Re: [PATCH 4.4 000/146] 4.4.16-stable review Guenter Roeck <linux@roeck-us.net> - 2016-07-26 16:00 +0200
Re: [PATCH 4.4 000/146] 4.4.16-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-27 06:50 +0200
Page 1 of 5 [1] 2 3 4 5 Next page →
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:10 +0200 |
| Subject | [PATCH 4.4 000/146] 4.4.16-stable review |
| Message-ID | <rYV8K-Pn-13@gated-at.bofh.it> |
This is the start of the stable review cycle for the 4.4.16 release.
There are 146 patches in this series, all will be posted as a response
to this one. If anyone has any issues with these being applied, please
let me know.
Responses should be made by Wed Jul 27 20:34:55 UTC 2016.
Anything received after that time might be too late.
The whole patch series can be found in one patch at:
kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.4.16-rc1.gz
or in the git tree and branch at:
git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.4.y
and the diffstat can be found below.
thanks,
greg k-h
-------------
Pseudo-Shortlog of commits:
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Linux 4.4.16-rc1
Miklos Szeredi <mszeredi@redhat.com>
ovl: verify upper dentry before unlink and rename
Mika Kahola <mika.kahola@intel.com>
drm/i915: Revert DisplayPort fast link training feature
Hugh Dickins <hughd@google.com>
tmpfs: fix regression hang in fallocate undo
Anthony Romano <anthony.romano@coreos.com>
tmpfs: don't undo fallocate past its last page
Jan Stancek <jstancek@redhat.com>
crypto: qat - make qat_asym_algs.o depend on asn1 headers
Jan Beulich <JBeulich@suse.com>
xen/acpi: allow xen-acpi-processor driver to load on Xen 4.7
Steve French <smfrench@gmail.com>
File names with trailing period or space need special case conversion
Jerome Marchand <jmarchan@redhat.com>
cifs: dynamic allocation of ntlmssp blob
Steve French <smfrench@gmail.com>
Fix reconnect to not defer smb3 session reconnect long after socket reconnect
James Bottomley <jejb@linux.vnet.ibm.com>
53c700: fix BUG on untagged commands
Martin Schwidefsky <schwidefsky@de.ibm.com>
s390: fix test_fp_ctl inline assembly contraints
Wei Fang <fangwei1@huawei.com>
scsi: fix race between simultaneous decrements of ->host_failed
Maxim Patlasov <mpatlasov@virtuozzo.com>
ovl: verify upper dentry in ovl_remove_and_whiteout()
Vivek Goyal <vgoyal@redhat.com>
ovl: Copy up underlying inode's ->i_mode to overlay inode
Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
ARM: mvebu: fix HW I/O coherency related deadlocks
Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
ARM: dts: armada-38x: fix MBUS_ID for crypto SRAM on Armada 385 Linksys
Boris Brezillon <boris.brezillon@free-electrons.com>
ARM: sunxi/dt: make the CHIP inherit from allwinner,sun5i-a13
Awais Belal <awais_belal@mentor.com>
ALSA: hda: add AMD Stoney PCI ID with proper driver caps
Peter Wu <peter@lekensteyn.nl>
ALSA: hda - fix use-after-free after module unload
Takashi Iwai <tiwai@suse.de>
ALSA: ctl: Stop notification after disconnection
Takashi Iwai <tiwai@suse.de>
ALSA: pcm: Free chmap at PCM free callback, too
Hui Wang <hui.wang@canonical.com>
ALSA: hda/realtek - add new pin definition in alc225 pin quirk table
Bob Copeland <me@bobcopeland.com>
ALSA: hda - fix read before array start
Vinod Koul <vinod.koul@intel.com>
ALSA: hda - Add PCI ID for Kabylake-H
Torsten Hilbrich <torsten.hilbrich@secunet.com>
ALSA: hda/realtek: Add Lenovo L460 to docking unit fixup
Takashi Iwai <tiwai@suse.de>
ALSA: timer: Fix negative queue usage by racy accesses
Christophe JAILLET <christophe.jaillet@wanadoo.fr>
ALSA: echoaudio: Fix memory allocation
Takashi Iwai <tiwai@suse.de>
ALSA: au88x0: Fix calculation in vortex_wtdma_bufshift()
Jaroslav Kysela <perex@perex.cz>
ALSA: hda / realtek - add two more Thinkpad IDs (5050,5053) for tpt460 fixup
Woodrow Shen <woodrow.shen@gmail.com>
ALSA: hda - Fix the headset mic jack detection on Dell machine
Takashi Iwai <tiwai@suse.de>
ALSA: dummy: Fix a use-after-free at closing
Pali Rohár <pali.rohar@gmail.com>
hwmon: (dell-smm) Cache fan_type() calls and change fan detection
Pali Rohár <pali.rohar@gmail.com>
hwmon: (dell-smm) Disallow fan_type() calls on broken machines
Pali Rohár <pali.rohar@gmail.com>
hwmon: (dell-smm) Restrict fan control and serial number to CAP_SYS_ADMIN by default
Dmitry Torokhov <dmitry.torokhov@gmail.com>
tty/vt/keyboard: fix OOB access in do_compute_shiftstate()
David Daney <david.daney@cavium.com>
tty: vt: Fix soft lockup in fbcon cursor blink timer.
Mark Brown <broonie@kernel.org>
iio:ad7266: Fix probe deferral for vref
Mark Brown <broonie@kernel.org>
iio:ad7266: Fix support for optional regulators
Mark Brown <broonie@kernel.org>
iio:ad7266: Fix broken regulator error handling
Linus Walleij <linus.walleij@linaro.org>
iio: accel: kxsd9: fix the usage of spi_w8r8()
Luis de Bethencourt <luisbg@osg.samsung.com>
staging: iio: accel: fix error check
Matt Ranostay <mranostay@gmail.com>
iio: hudmidity: hdc100x: fix incorrect shifting and scaling
Matt Ranostay <mranostay@gmail.com>
iio: humidity: hdc100x: fix IIO_TEMP channel reporting
Alison Schofield <amsfield22@gmail.com>
iio: humidity: hdc100x: correct humidity integration time mask
Matt Ranostay <mranostay@gmail.com>
iio: proximity: as3935: fix buffer stack trashing
Matt Ranostay <mranostay@gmail.com>
iio: proximity: as3935: remove triggered buffer processing
Matt Ranostay <mranostay@gmail.com>
iio: proximity: as3935: correct IIO_CHAN_INFO_RAW output
Yong Li <sdliyong@gmail.com>
iio: light apds9960: Add the missing dev.parent
Gregor Boirie <gregor.boirie@parrot.com>
iio:st_pressure: fix sampling gains (bring inline with ABI)
Crestez Dan Leonard <leonard.crestez@intel.com>
iio: Fix error handling in iio_trigger_attach_poll_func
Ross Lagerwall <ross.lagerwall@citrix.com>
xen/balloon: Fix declared-but-not-defined warning
Andrey Ryabinin <aryabinin@virtuozzo.com>
perf/x86: Fix undefined shift on 32-bit kernels
Ocquidant, Sebastien <sebastienocquidant@eaton.com>
memory: omap-gpmc: Fix omap gpmc EXTRADELAY timing
Sinclair Yeh <syeh@vmware.com>
drm/vmwgfx: Fix error paths when mapping framebuffer
Sinclair Yeh <syeh@vmware.com>
drm/vmwgfx: Delay pinning fbdev framebuffer until after mode set
Sinclair Yeh <syeh@vmware.com>
drm/vmwgfx: Check pin count before attempting to move a buffer
Sinclair Yeh <syeh@vmware.com>
drm/vmwgfx: Work around mode set failure in 2D VMs
Sinclair Yeh <syeh@vmware.com>
drm/vmwgfx: Add an option to change assumed FB bpp
Sinclair Yeh <syeh@vmware.com>
drm/ttm: Make ttm_bo_mem_compat available
Boris Brezillon <boris.brezillon@free-electrons.com>
drm: atmel-hlcdc: actually disable scaling when no scaling is required
Tomi Valkeinen <tomi.valkeinen@ti.com>
drm: make drm_atomic_set_mode_prop_for_crtc() more reliable
Tomi Valkeinen <tomi.valkeinen@ti.com>
drm: add missing drm_mode_set_crtcinfo call
Ville Syrjälä <ville.syrjala@linux.intel.com>
drm/i915: Update CDCLK_FREQ register on BDW after changing cdclk frequency
Chris Wilson <chris@chris-wilson.co.uk>
drm/i915: Update ifdeffery for mutex->owner
Ville Syrjälä <ville.syrjala@linux.intel.com>
drm/i915: Refresh cached DP port register value on resume
Lyude <cpaul@redhat.com>
drm/i915/ilk: Don't disable SSC source if it's in use
Ben Skeggs <bskeggs@redhat.com>
drm/nouveau/disp/sor/gf119: select correct sor when poking training pattern
Dmitrii Tcvetkov <demfloro@demfloro.ru>
drm/nouveau: fix for disabled fbdev emulation
Ben Skeggs <bskeggs@redhat.com>
drm/nouveau/fbcon: fix out-of-bounds memory accesses
Ben Skeggs <bskeggs@redhat.com>
drm/nouveau/gr/gf100-: update sm error decoding from gk20a nvgpu headers
Ben Skeggs <bskeggs@redhat.com>
drm/nouveau/disp/sor/gf119: both links use the same training register
Michael S. Tsirkin <mst@redhat.com>
virtio_balloon: fix PFN format for virtio-1
Andrey Grodzovsky <Andrey.Grodzovsky@amd.com>
drm/dp/mst: Always clear proposed vcpi table for port.
Oded Gabbay <oded.gabbay@gmail.com>
drm/amdkfd: destroy dbgmgr in notifier release
Oded Gabbay <oded.gabbay@gmail.com>
drm/amdkfd: unbind only existing processes
Richard Weinberger <richard@nod.at>
ubi: Make recover_peb power cut aware
Alex Deucher <alexander.deucher@amd.com>
drm/amdgpu/gfx7: fix broken condition check
Alex Deucher <alexander.deucher@amd.com>
drm/radeon: fix asic initialization for virtualized environments
Jeff Mahoney <jeffm@suse.com>
btrfs: account for non-CoW'd blocks in btrfs_abort_transaction
Tejun Heo <tj@kernel.org>
percpu: fix synchronization between synchronous map extension and chunk destruction
Tejun Heo <tj@kernel.org>
percpu: fix synchronization between chunk->map_extend_work and chunk destruction
Miklos Szeredi <mszeredi@redhat.com>
af_unix: fix hard linked sockets on overlay
Miklos Szeredi <mszeredi@redhat.com>
vfs: add d_real_inode() helper
Mark Rutland <mark.rutland@arm.com>
arm64: Rework valid_user_regs
Junichi Nomura <j-nomura@ce.jp.nec.com>
ipmi: Remove smi_msg from waiting_rcv_msgs list before handle_one_recv_msg()
Mathieu Larouche <mathieu.larouche@matrox.com>
drm/mgag200: Black screen fix for G200e rev 4
Joerg Roedel <jroedel@suse.de>
iommu/amd: Fix unity mapping initialization race
Joerg Roedel <jroedel@suse.de>
iommu/vt-d: Enable QI on all IOMMUs before setting root entry
Jean-Philippe Brucker <jean-philippe.brucker@arm.com>
iommu/arm-smmu: Wire up map_sg for arm-smmu-v3
Jiri Slaby <jslaby@suse.cz>
base: make module_create_drivers_dir race-free
Steven Rostedt (Red Hat) <rostedt@goodmis.org>
tracing: Handle NULL formats in hold_module_trace_bprintk_format()
Allen Hung <allen_hung@dell.com>
HID: multitouch: enable palm rejection for Windows Precision Touchpad
Scott Bauer <sbauer@plzdonthack.me>
HID: hiddev: validate num_values for HIDIOCGUSAGES, HIDIOCSUSAGES commands
Oliver Neukum <oneukum@suse.com>
HID: elo: kill not flush the work
Quentin Casasnovas <quentin.casasnovas@oracle.com>
KVM: nVMX: VMX instructions: fix segment checks when L1 is in long mode.
Xiubo Li <lixiubo@cmss.chinamobile.com>
kvm: Fix irq route entries exceeding KVM_MAX_IRQ_ROUTES
Dan Carpenter <dan.carpenter@oracle.com>
KEYS: potential uninitialized variable
Vineet Gupta <vgupta@synopsys.com>
ARCv2: LLSC: software backoff is NOT needed starting HS2.1c
Vineet Gupta <vgupta@synopsys.com>
ARCv2: Check for LL-SC livelock only if LLSC is enabled
Martin KaFai Lau <kafai@fb.com>
ipv6: Fix mem leak in rt6i_pcpu
Bjørn Mork <bjorn@mork.no>
cdc_ncm: workaround for EM7455 "silent" data interface
WANG Cong <xiyou.wangcong@gmail.com>
net_sched: fix mirrored packets checksum
David S. Miller <davem@davemloft.net>
packet: Use symmetric hash for PACKET_FANOUT_HASH.
Peter Zijlstra <peterz@infradead.org>
sched/fair: Fix cfs_rq avg tracking underflow
Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
UBIFS: Implement ->migratepage()
Richard Weinberger <richard@nod.at>
mm: Export migrate_page_move_mapping and migrate_page_copy
James Hogan <james.hogan@imgtec.com>
MIPS: KVM: Fix modular KVM under QEMU
Steve Capper <steve.capper@arm.com>
ARM: 8579/1: mm: Fix definition of pmd_mknotpresent
Will Deacon <will.deacon@arm.com>
ARM: 8578/1: mm: ensure pmd_present only checks the valid bit
Fabio Estevam <fabio.estevam@nxp.com>
ARM: imx6ul: Fix Micrel PHY mask
Trond Myklebust <trond.myklebust@primarydata.com>
NFS: Fix another OPEN_DOWNGRADE bug
Al Viro <viro@ZenIV.linux.org.uk>
make nfs_atomic_open() call d_drop() on all ->open_context() errors.
Ben Hutchings <ben@decadent.org.uk>
nfsd: check permissions when setting ACLs
Andreas Gruenbacher <agruenba@redhat.com>
posix_acl: Add set_posix_acl
Oleg Drokin <green@linuxhacker.ru>
nfsd: Extend the mutex holding region around in nfsd4_process_open2()
Oleg Drokin <green@linuxhacker.ru>
nfsd: Always lock state exclusively.
J. Bruce Fields <bfields@redhat.com>
nfsd4/rpc: move backchannel create logic into rpc code
Tejun Heo <tj@kernel.org>
writeback: use higher precision calculation in domain_dirty_limits()
Lukasz Luba <lukasz.luba@arm.com>
thermal: cpu_cooling: fix improper order during initialization
Andy Lutomirski <luto@kernel.org>
uvc: Forward compat ioctls to their handlers directly
Johan Hovold <johan@kernel.org>
Revert "gpiolib: Split GPIO flags parsing and GPIO configuration"
Borislav Petkov <bp@suse.de>
x86/amd_nb: Fix boot crash on non-AMD systems
Masami Hiramatsu <mhiramat@kernel.org>
kprobes/x86: Clear TF bit in fault on single-stepping
H. Peter Anvin <hpa@zytor.com>
x86, build: copy ldlinux.c32 to image.iso
Paolo Bonzini <pbonzini@redhat.com>
locking/static_key: Fix concurrent static_key_slow_inc()
Peter Zijlstra <peterz@infradead.org>
locking/qspinlock: Fix spin_unlock_wait() some more
Chris Wilson <chris@chris-wilson.co.uk>
locking/ww_mutex: Report recursive ww_mutex locking early
Sergei Shtylyov <sergei.shtylyov@cogentembedded.com>
of: irq: fix of_irq_get[_byname]() kernel-doc
Wolfram Sang <wsa@the-dreams.de>
of: fix autoloading due to broken modalias with no 'compatible'
Eric W. Biederman <ebiederm@xmission.com>
mnt: If fs_fully_visible fails call put_filesystem.
Eric W. Biederman <ebiederm@xmission.com>
mnt: Account for MS_RDONLY in fs_fully_visible
Eric W. Biederman <ebiederm@xmission.com>
mnt: fs_fully_visible test the proper mount for MNT_LOCKED
Oscar <oscar@naiandei.net>
usb: common: otg-fsm: add license to usb-otg-fsm
Alan Stern <stern@rowland.harvard.edu>
USB: EHCI: declare hostpc register as zero-length array
Arnd Bergmann <arnd@arndb.de>
usb: dwc2: fix regression on big-endian PowerPC/ARM systems
Cyril Bur <cyrilbur@gmail.com>
powerpc/tm: Always reclaim in start_thread() for exec() class syscalls
Michael Ellerman <mpe@ellerman.id.au>
powerpc/pseries: Fix IBM_ARCH_VEC_NRCORES_OFFSET since POWER8NVL was added
Gavin Shan <gwshan@linux.vnet.ibm.com>
powerpc/pseries: Fix PCI config address for DDW
Guilherme G. Piccoli <gpiccoli@linux.vnet.ibm.com>
powerpc/iommu: Remove the dependency on EEH struct in DDW mechanism
Jason Gunthorpe <jgunthorpe@obsidianresearch.com>
IB/mlx4: Properly initialize GRH TClass and FlowLabel in AHs
Bart Van Assche <bart.vanassche@sandisk.com>
IB/cm: Fix a recently introduced locking bug
Tony Luck <tony.luck@intel.com>
EDAC, sb_edac: Fix rank lookup on Broadwell
Jouni Malinen <j@w1.fi>
mac80211: Fix mesh estab_plinks counting in STA removal case
Martin Willi <martin@strongswan.org>
mac80211_hwsim: Add missing check for HWSIM_ATTR_SIGNAL
Bob Copeland <me@bobcopeland.com>
mac80211: mesh: flush mesh paths unconditionally
Felix Fietkau <nbd@nbd.name>
mac80211: fix fast_tx header alignment
-------------
Diffstat:
.../ABI/testing/sysfs-bus-iio-proximity-as3935 | 2 +-
Documentation/scsi/scsi_eh.txt | 8 +-
Makefile | 4 +-
arch/arc/Kconfig | 2 +-
arch/arc/kernel/setup.c | 4 -
arch/arm/boot/dts/armada-385-linksys.dtsi | 4 +-
arch/arm/boot/dts/sun5i-r8-chip.dts | 2 +-
arch/arm/include/asm/pgtable-2level.h | 1 +
arch/arm/include/asm/pgtable-3level.h | 5 +-
arch/arm/include/asm/pgtable.h | 1 -
arch/arm/mach-imx/mach-imx6ul.c | 2 +-
arch/arm/mach-mvebu/coherency.c | 22 ++--
arch/arm64/include/asm/ptrace.h | 33 +-----
arch/arm64/kernel/ptrace.c | 81 ++++++++++++++-
arch/arm64/kernel/signal.c | 4 +-
arch/arm64/kernel/signal32.c | 2 +-
arch/mips/include/asm/kvm_host.h | 1 +
arch/mips/kvm/interrupt.h | 1 +
arch/mips/kvm/locore.S | 1 +
arch/mips/kvm/mips.c | 11 +-
arch/powerpc/kernel/process.c | 10 ++
arch/powerpc/kernel/prom_init.c | 2 +-
arch/powerpc/platforms/pseries/iommu.c | 24 ++---
arch/s390/include/asm/fpu/api.h | 2 +-
arch/x86/boot/Makefile | 3 +
arch/x86/kernel/amd_nb.c | 4 +-
arch/x86/kernel/cpu/perf_event_intel.c | 2 +-
arch/x86/kernel/kprobes/core.c | 12 +++
arch/x86/kvm/vmx.c | 23 ++---
drivers/ata/libata-eh.c | 2 +-
drivers/base/module.c | 8 +-
drivers/char/ipmi/ipmi_msghandler.c | 8 +-
drivers/crypto/qat/qat_common/Makefile | 1 +
drivers/edac/sb_edac.c | 13 ++-
drivers/gpio/gpiolib-legacy.c | 8 +-
drivers/gpio/gpiolib.c | 52 +++-------
drivers/gpu/drm/amd/amdgpu/gfx_v7_0.c | 2 +-
drivers/gpu/drm/amd/amdkfd/kfd_process.c | 70 ++++++++-----
drivers/gpu/drm/atmel-hlcdc/atmel_hlcdc_plane.c | 2 +
drivers/gpu/drm/drm_atomic.c | 3 +-
drivers/gpu/drm/drm_crtc.c | 2 -
drivers/gpu/drm/drm_dp_mst_topology.c | 8 +-
drivers/gpu/drm/drm_modes.c | 2 +
drivers/gpu/drm/i915/i915_gem_shrinker.c | 2 +-
drivers/gpu/drm/i915/i915_reg.h | 2 +
drivers/gpu/drm/i915/intel_display.c | 50 ++++++---
drivers/gpu/drm/i915/intel_dp.c | 36 ++-----
drivers/gpu/drm/i915/intel_drv.h | 1 -
drivers/gpu/drm/mgag200/mgag200_mode.c | 10 +-
drivers/gpu/drm/nouveau/nouveau_fbcon.c | 2 +
drivers/gpu/drm/nouveau/nv04_fbcon.c | 7 +-
drivers/gpu/drm/nouveau/nv50_fbcon.c | 6 +-
drivers/gpu/drm/nouveau/nvc0_fbcon.c | 6 +-
.../gpu/drm/nouveau/nvkm/engine/disp/sorgf119.c | 4 +-
drivers/gpu/drm/nouveau/nvkm/engine/gr/gf100.c | 37 +++++--
drivers/gpu/drm/radeon/radeon_device.c | 21 ++++
drivers/gpu/drm/ttm/ttm_bo.c | 7 +-
drivers/gpu/drm/vmwgfx/vmwgfx_dmabuf.c | 25 ++++-
drivers/gpu/drm/vmwgfx/vmwgfx_drv.c | 12 +++
drivers/gpu/drm/vmwgfx/vmwgfx_drv.h | 1 +
drivers/gpu/drm/vmwgfx/vmwgfx_fb.c | 47 +++++----
drivers/gpu/drm/vmwgfx/vmwgfx_kms.c | 10 +-
drivers/hid/hid-elo.c | 2 +-
drivers/hid/hid-multitouch.c | 18 +++-
drivers/hid/usbhid/hiddev.c | 10 +-
drivers/hwmon/dell-smm-hwmon.c | 80 ++++++++++-----
drivers/iio/accel/kxsd9.c | 4 +-
drivers/iio/adc/ad7266.c | 7 +-
drivers/iio/humidity/hdc100x.c | 20 ++--
drivers/iio/industrialio-trigger.c | 23 ++++-
drivers/iio/light/apds9960.c | 1 +
drivers/iio/pressure/st_pressure_core.c | 80 +++++++++------
drivers/iio/proximity/as3935.c | 17 +++-
drivers/infiniband/core/cm.c | 4 +-
drivers/infiniband/hw/mlx4/ah.c | 2 +-
drivers/iommu/amd_iommu_init.c | 14 ++-
drivers/iommu/arm-smmu-v3.c | 1 +
drivers/iommu/intel-iommu.c | 17 +++-
drivers/media/usb/uvc/uvc_v4l2.c | 39 ++++---
drivers/memory/omap-gpmc.c | 2 +-
drivers/mtd/ubi/eba.c | 22 ++--
drivers/net/usb/cdc_ncm.c | 7 ++
drivers/net/wireless/mac80211_hwsim.c | 1 +
drivers/of/irq.c | 19 ++--
drivers/scsi/53c700.c | 4 +-
drivers/scsi/scsi_error.c | 4 +-
drivers/staging/iio/accel/sca3000_core.c | 2 +-
drivers/thermal/cpu_cooling.c | 16 +--
drivers/tty/vt/keyboard.c | 30 ++----
drivers/tty/vt/vt.c | 1 +
drivers/usb/common/usb-otg-fsm.c | 2 +
drivers/usb/dwc2/core.h | 27 +++++
drivers/virtio/virtio_balloon.c | 20 ++--
drivers/xen/balloon.c | 28 +++--
drivers/xen/xen-acpi-processor.c | 35 +------
fs/btrfs/ctree.c | 5 +-
fs/btrfs/extent-tree.c | 2 +-
fs/btrfs/super.c | 2 +-
fs/btrfs/transaction.h | 2 +-
fs/cifs/cifs_unicode.c | 33 +++++-
fs/cifs/cifs_unicode.h | 2 +
fs/cifs/connect.c | 4 +-
fs/cifs/ntlmssp.h | 2 +-
fs/cifs/sess.c | 76 +++++++-------
fs/cifs/smb2pdu.c | 37 +++++--
fs/namespace.c | 10 +-
fs/nfs/dir.c | 2 +-
fs/nfs/nfs4proc.c | 5 +-
fs/nfsd/nfs2acl.c | 20 ++--
fs/nfsd/nfs3acl.c | 16 ++-
fs/nfsd/nfs4acl.c | 16 +--
fs/nfsd/nfs4callback.c | 18 +---
fs/nfsd/nfs4state.c | 50 +++++----
fs/nfsd/state.h | 2 +-
fs/overlayfs/dir.c | 113 +++++++++++----------
fs/overlayfs/inode.c | 3 +-
fs/overlayfs/overlayfs.h | 1 +
fs/posix_acl.c | 41 ++++----
fs/ubifs/file.c | 24 +++++
include/asm-generic/qspinlock.h | 53 ++++------
include/drm/ttm/ttm_bo_api.h | 14 +++
include/linux/dcache.h | 12 +++
include/linux/jump_label.h | 16 ++-
include/linux/skbuff.h | 20 ++++
include/linux/sunrpc/clnt.h | 2 -
include/linux/usb/ehci_def.h | 4 +-
kernel/jump_label.c | 36 ++++++-
kernel/locking/mutex.c | 9 +-
kernel/locking/qspinlock.c | 60 +++++++++++
kernel/sched/fair.c | 33 ++++--
kernel/trace/trace_printk.c | 7 +-
mm/migrate.c | 2 +
mm/page-writeback.c | 21 ++--
mm/percpu.c | 73 +++++++------
mm/shmem.c | 8 +-
net/core/flow_dissector.c | 43 ++++++++
net/core/skbuff.c | 18 ----
net/ipv6/ip6_fib.c | 1 +
net/mac80211/mesh.c | 11 +-
net/mac80211/sta_info.h | 2 +-
net/packet/af_packet.c | 2 +-
net/sched/act_mirred.c | 2 +-
net/sunrpc/clnt.c | 12 ++-
net/unix/af_unix.c | 6 +-
scripts/mod/file2alias.c | 2 +-
security/keys/key.c | 2 +-
sound/core/control.c | 2 +
sound/core/pcm.c | 14 ++-
sound/core/timer.c | 2 +-
sound/drivers/dummy.c | 1 +
sound/pci/au88x0/au88x0_core.c | 5 +-
sound/pci/echoaudio/echoaudio.c | 4 +-
sound/pci/hda/hda_generic.c | 2 +
sound/pci/hda/hda_intel.c | 12 ++-
sound/pci/hda/patch_realtek.c | 22 +++-
virt/kvm/kvm_main.c | 2 +-
156 files changed, 1476 insertions(+), 846 deletions(-)
[toc] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:20 +0200 |
| Subject | [PATCH 4.4 060/146] iommu/amd: Fix unity mapping initialization race |
| Message-ID | <rYVs5-1c6-1@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joerg Roedel <jroedel@suse.de>
commit 522e5cb76d0663c88f96b6a8301451c8efa37207 upstream.
There is a race condition in the AMD IOMMU init code that
causes requested unity mappings to be blocked by the IOMMU
for a short period of time. This results on boot failures
and IO_PAGE_FAULTs on some machines.
Fix this by making sure the unity mappings are installed
before all other DMA is blocked.
Fixes: aafd8ba0ca74 ('iommu/amd: Implement add_device and remove_device')
Signed-off-by: Joerg Roedel <jroedel@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/iommu/amd_iommu_init.c | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)
--- a/drivers/iommu/amd_iommu_init.c
+++ b/drivers/iommu/amd_iommu_init.c
@@ -1363,13 +1363,23 @@ static int __init amd_iommu_init_pci(voi
break;
}
+ /*
+ * Order is important here to make sure any unity map requirements are
+ * fulfilled. The unity mappings are created and written to the device
+ * table during the amd_iommu_init_api() call.
+ *
+ * After that we call init_device_table_dma() to make sure any
+ * uninitialized DTE will block DMA, and in the end we flush the caches
+ * of all IOMMUs to make sure the changes to the device table are
+ * active.
+ */
+ ret = amd_iommu_init_api();
+
init_device_table_dma();
for_each_iommu(iommu)
iommu_flush_all_caches(iommu);
- ret = amd_iommu_init_api();
-
if (!ret)
print_iommu_info();
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:20 +0200 |
| Subject | [PATCH 4.4 134/146] ovl: verify upper dentry in ovl_remove_and_whiteout() |
| Message-ID | <rYVs5-1c6-9@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maxim Patlasov <mpatlasov@virtuozzo.com>
commit cfc9fde0b07c3b44b570057c5f93dda59dca1c94 upstream.
The upper dentry may become stale before we call ovl_lock_rename_workdir.
For example, someone could (mistakenly or maliciously) manually unlink(2)
it directly from upperdir.
To ensure it is not stale, let's lookup it after ovl_lock_rename_workdir
and and check if it matches the upper dentry.
Essentially, it is the same problem and similar solution as in
commit 11f3710417d0 ("ovl: verify upper dentry before unlink and rename").
Signed-off-by: Maxim Patlasov <mpatlasov@virtuozzo.com>
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/overlayfs/dir.c | 56 +++++++++++++++++++++++------------------------------
1 file changed, 25 insertions(+), 31 deletions(-)
--- a/fs/overlayfs/dir.c
+++ b/fs/overlayfs/dir.c
@@ -511,6 +511,7 @@ static int ovl_remove_and_whiteout(struc
struct dentry *upper;
struct dentry *opaquedir = NULL;
int err;
+ int flags = 0;
if (WARN_ON(!workdir))
return -EROFS;
@@ -540,46 +541,39 @@ static int ovl_remove_and_whiteout(struc
if (err)
goto out_dput;
+ upper = lookup_one_len(dentry->d_name.name, upperdir,
+ dentry->d_name.len);
+ err = PTR_ERR(upper);
+ if (IS_ERR(upper))
+ goto out_unlock;
+
+ err = -ESTALE;
+ if ((opaquedir && upper != opaquedir) ||
+ (!opaquedir && ovl_dentry_upper(dentry) &&
+ upper != ovl_dentry_upper(dentry))) {
+ goto out_dput_upper;
+ }
+
whiteout = ovl_whiteout(workdir, dentry);
err = PTR_ERR(whiteout);
if (IS_ERR(whiteout))
- goto out_unlock;
+ goto out_dput_upper;
- upper = ovl_dentry_upper(dentry);
- if (!upper) {
- upper = lookup_one_len(dentry->d_name.name, upperdir,
- dentry->d_name.len);
- err = PTR_ERR(upper);
- if (IS_ERR(upper))
- goto kill_whiteout;
-
- err = ovl_do_rename(wdir, whiteout, udir, upper, 0);
- dput(upper);
- if (err)
- goto kill_whiteout;
- } else {
- int flags = 0;
-
- if (opaquedir)
- upper = opaquedir;
- err = -ESTALE;
- if (upper->d_parent != upperdir)
- goto kill_whiteout;
-
- if (is_dir)
- flags |= RENAME_EXCHANGE;
-
- err = ovl_do_rename(wdir, whiteout, udir, upper, flags);
- if (err)
- goto kill_whiteout;
+ if (d_is_dir(upper))
+ flags = RENAME_EXCHANGE;
+
+ err = ovl_do_rename(wdir, whiteout, udir, upper, flags);
+ if (err)
+ goto kill_whiteout;
+ if (flags)
+ ovl_cleanup(wdir, upper);
- if (is_dir)
- ovl_cleanup(wdir, upper);
- }
ovl_dentry_version_inc(dentry->d_parent);
out_d_drop:
d_drop(dentry);
dput(whiteout);
+out_dput_upper:
+ dput(upper);
out_unlock:
unlock_rename(workdir, upperdir);
out_dput:
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:20 +0200 |
| Subject | [PATCH 4.4 139/146] cifs: dynamic allocation of ntlmssp blob |
| Message-ID | <rYVs6-1c6-41@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jerome Marchand <jmarchan@redhat.com>
commit b8da344b74c822e966c6d19d6b2321efe82c5d97 upstream.
In sess_auth_rawntlmssp_authenticate(), the ntlmssp blob is allocated
statically and its size is an "empirical" 5*sizeof(struct
_AUTHENTICATE_MESSAGE) (320B on x86_64). I don't know where this value
comes from or if it was ever appropriate, but it is currently
insufficient: the user and domain name in UTF16 could take 1kB by
themselves. Because of that, build_ntlmssp_auth_blob() might corrupt
memory (out-of-bounds write). The size of ntlmssp_blob in
SMB2_sess_setup() is too small too (sizeof(struct _NEGOTIATE_MESSAGE)
+ 500).
This patch allocates the blob dynamically in
build_ntlmssp_auth_blob().
Signed-off-by: Jerome Marchand <jmarchan@redhat.com>
Signed-off-by: Steve French <smfrench@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/cifs/ntlmssp.h | 2 -
fs/cifs/sess.c | 76 +++++++++++++++++++++++++++++-------------------------
fs/cifs/smb2pdu.c | 10 +------
3 files changed, 45 insertions(+), 43 deletions(-)
--- a/fs/cifs/ntlmssp.h
+++ b/fs/cifs/ntlmssp.h
@@ -133,6 +133,6 @@ typedef struct _AUTHENTICATE_MESSAGE {
int decode_ntlmssp_challenge(char *bcc_ptr, int blob_len, struct cifs_ses *ses);
void build_ntlmssp_negotiate_blob(unsigned char *pbuffer, struct cifs_ses *ses);
-int build_ntlmssp_auth_blob(unsigned char *pbuffer, u16 *buflen,
+int build_ntlmssp_auth_blob(unsigned char **pbuffer, u16 *buflen,
struct cifs_ses *ses,
const struct nls_table *nls_cp);
--- a/fs/cifs/sess.c
+++ b/fs/cifs/sess.c
@@ -364,19 +364,43 @@ void build_ntlmssp_negotiate_blob(unsign
sec_blob->DomainName.MaximumLength = 0;
}
-/* We do not malloc the blob, it is passed in pbuffer, because its
- maximum possible size is fixed and small, making this approach cleaner.
- This function returns the length of the data in the blob */
-int build_ntlmssp_auth_blob(unsigned char *pbuffer,
+static int size_of_ntlmssp_blob(struct cifs_ses *ses)
+{
+ int sz = sizeof(AUTHENTICATE_MESSAGE) + ses->auth_key.len
+ - CIFS_SESS_KEY_SIZE + CIFS_CPHTXT_SIZE + 2;
+
+ if (ses->domainName)
+ sz += 2 * strnlen(ses->domainName, CIFS_MAX_DOMAINNAME_LEN);
+ else
+ sz += 2;
+
+ if (ses->user_name)
+ sz += 2 * strnlen(ses->user_name, CIFS_MAX_USERNAME_LEN);
+ else
+ sz += 2;
+
+ return sz;
+}
+
+int build_ntlmssp_auth_blob(unsigned char **pbuffer,
u16 *buflen,
struct cifs_ses *ses,
const struct nls_table *nls_cp)
{
int rc;
- AUTHENTICATE_MESSAGE *sec_blob = (AUTHENTICATE_MESSAGE *)pbuffer;
+ AUTHENTICATE_MESSAGE *sec_blob;
__u32 flags;
unsigned char *tmp;
+ rc = setup_ntlmv2_rsp(ses, nls_cp);
+ if (rc) {
+ cifs_dbg(VFS, "Error %d during NTLMSSP authentication\n", rc);
+ *buflen = 0;
+ goto setup_ntlmv2_ret;
+ }
+ *pbuffer = kmalloc(size_of_ntlmssp_blob(ses), GFP_KERNEL);
+ sec_blob = (AUTHENTICATE_MESSAGE *)*pbuffer;
+
memcpy(sec_blob->Signature, NTLMSSP_SIGNATURE, 8);
sec_blob->MessageType = NtLmAuthenticate;
@@ -391,7 +415,7 @@ int build_ntlmssp_auth_blob(unsigned cha
flags |= NTLMSSP_NEGOTIATE_KEY_XCH;
}
- tmp = pbuffer + sizeof(AUTHENTICATE_MESSAGE);
+ tmp = *pbuffer + sizeof(AUTHENTICATE_MESSAGE);
sec_blob->NegotiateFlags = cpu_to_le32(flags);
sec_blob->LmChallengeResponse.BufferOffset =
@@ -399,13 +423,9 @@ int build_ntlmssp_auth_blob(unsigned cha
sec_blob->LmChallengeResponse.Length = 0;
sec_blob->LmChallengeResponse.MaximumLength = 0;
- sec_blob->NtChallengeResponse.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->NtChallengeResponse.BufferOffset =
+ cpu_to_le32(tmp - *pbuffer);
if (ses->user_name != NULL) {
- rc = setup_ntlmv2_rsp(ses, nls_cp);
- if (rc) {
- cifs_dbg(VFS, "Error %d during NTLMSSP authentication\n", rc);
- goto setup_ntlmv2_ret;
- }
memcpy(tmp, ses->auth_key.response + CIFS_SESS_KEY_SIZE,
ses->auth_key.len - CIFS_SESS_KEY_SIZE);
tmp += ses->auth_key.len - CIFS_SESS_KEY_SIZE;
@@ -423,7 +443,7 @@ int build_ntlmssp_auth_blob(unsigned cha
}
if (ses->domainName == NULL) {
- sec_blob->DomainName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->DomainName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
sec_blob->DomainName.Length = 0;
sec_blob->DomainName.MaximumLength = 0;
tmp += 2;
@@ -432,14 +452,14 @@ int build_ntlmssp_auth_blob(unsigned cha
len = cifs_strtoUTF16((__le16 *)tmp, ses->domainName,
CIFS_MAX_USERNAME_LEN, nls_cp);
len *= 2; /* unicode is 2 bytes each */
- sec_blob->DomainName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->DomainName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
sec_blob->DomainName.Length = cpu_to_le16(len);
sec_blob->DomainName.MaximumLength = cpu_to_le16(len);
tmp += len;
}
if (ses->user_name == NULL) {
- sec_blob->UserName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->UserName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
sec_blob->UserName.Length = 0;
sec_blob->UserName.MaximumLength = 0;
tmp += 2;
@@ -448,13 +468,13 @@ int build_ntlmssp_auth_blob(unsigned cha
len = cifs_strtoUTF16((__le16 *)tmp, ses->user_name,
CIFS_MAX_USERNAME_LEN, nls_cp);
len *= 2; /* unicode is 2 bytes each */
- sec_blob->UserName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->UserName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
sec_blob->UserName.Length = cpu_to_le16(len);
sec_blob->UserName.MaximumLength = cpu_to_le16(len);
tmp += len;
}
- sec_blob->WorkstationName.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->WorkstationName.BufferOffset = cpu_to_le32(tmp - *pbuffer);
sec_blob->WorkstationName.Length = 0;
sec_blob->WorkstationName.MaximumLength = 0;
tmp += 2;
@@ -463,19 +483,19 @@ int build_ntlmssp_auth_blob(unsigned cha
(ses->ntlmssp->server_flags & NTLMSSP_NEGOTIATE_EXTENDED_SEC))
&& !calc_seckey(ses)) {
memcpy(tmp, ses->ntlmssp->ciphertext, CIFS_CPHTXT_SIZE);
- sec_blob->SessionKey.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->SessionKey.BufferOffset = cpu_to_le32(tmp - *pbuffer);
sec_blob->SessionKey.Length = cpu_to_le16(CIFS_CPHTXT_SIZE);
sec_blob->SessionKey.MaximumLength =
cpu_to_le16(CIFS_CPHTXT_SIZE);
tmp += CIFS_CPHTXT_SIZE;
} else {
- sec_blob->SessionKey.BufferOffset = cpu_to_le32(tmp - pbuffer);
+ sec_blob->SessionKey.BufferOffset = cpu_to_le32(tmp - *pbuffer);
sec_blob->SessionKey.Length = 0;
sec_blob->SessionKey.MaximumLength = 0;
}
+ *buflen = tmp - *pbuffer;
setup_ntlmv2_ret:
- *buflen = tmp - pbuffer;
return rc;
}
@@ -1266,7 +1286,7 @@ sess_auth_rawntlmssp_authenticate(struct
struct cifs_ses *ses = sess_data->ses;
__u16 bytes_remaining;
char *bcc_ptr;
- char *ntlmsspblob = NULL;
+ unsigned char *ntlmsspblob = NULL;
u16 blob_len;
cifs_dbg(FYI, "rawntlmssp session setup authenticate phase\n");
@@ -1279,19 +1299,7 @@ sess_auth_rawntlmssp_authenticate(struct
/* Build security blob before we assemble the request */
pSMB = (SESSION_SETUP_ANDX *)sess_data->iov[0].iov_base;
smb_buf = (struct smb_hdr *)pSMB;
- /*
- * 5 is an empirical value, large enough to hold
- * authenticate message plus max 10 of av paris,
- * domain, user, workstation names, flags, etc.
- */
- ntlmsspblob = kzalloc(5*sizeof(struct _AUTHENTICATE_MESSAGE),
- GFP_KERNEL);
- if (!ntlmsspblob) {
- rc = -ENOMEM;
- goto out;
- }
-
- rc = build_ntlmssp_auth_blob(ntlmsspblob,
+ rc = build_ntlmssp_auth_blob(&ntlmsspblob,
&blob_len, ses, sess_data->nls_cp);
if (rc)
goto out_free_ntlmsspblob;
--- a/fs/cifs/smb2pdu.c
+++ b/fs/cifs/smb2pdu.c
@@ -591,7 +591,7 @@ SMB2_sess_setup(const unsigned int xid,
u16 blob_length = 0;
struct key *spnego_key = NULL;
char *security_blob = NULL;
- char *ntlmssp_blob = NULL;
+ unsigned char *ntlmssp_blob = NULL;
bool use_spnego = false; /* else use raw ntlmssp */
cifs_dbg(FYI, "Session Setup\n");
@@ -716,13 +716,7 @@ ssetup_ntlmssp_authenticate:
iov[1].iov_len = blob_length;
} else if (phase == NtLmAuthenticate) {
req->hdr.SessionId = ses->Suid;
- ntlmssp_blob = kzalloc(sizeof(struct _NEGOTIATE_MESSAGE) + 500,
- GFP_KERNEL);
- if (ntlmssp_blob == NULL) {
- rc = -ENOMEM;
- goto ssetup_exit;
- }
- rc = build_ntlmssp_auth_blob(ntlmssp_blob, &blob_length, ses,
+ rc = build_ntlmssp_auth_blob(&ntlmssp_blob, &blob_length, ses,
nls_cp);
if (rc) {
cifs_dbg(FYI, "build_ntlmssp_auth_blob failed %d\n",
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:20 +0200 |
| Subject | [PATCH 4.4 145/146] drm/i915: Revert DisplayPort fast link training feature |
| Message-ID | <rYVs6-1c6-31@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mika Kahola <mika.kahola@intel.com>
commit 34511dce4b35685d3988d5c8b100d11a068db5bd upstream.
It has been found out that in some HW combination the DisplayPort
fast link training feature caused screen flickering. Let's revert
this feature for now until we can ensure that the feature works for
all platforms.
This is a manual revert of commits 5fa836a9d859 ("drm/i915: DP link
training optimization") and 4e96c97742f4 ("drm/i915: eDP link training
optimization").
Fixes: 5fa836a9d859 ("drm/i915: DP link training optimization")
Fixes: 4e96c97742f4 ("drm/i915: eDP link training optimization")
Bugzilla: https://bugs.freedesktop.org/show_bug.cgi?id=91393
Reviewed-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Mika Kahola <mika.kahola@intel.com>
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Link: http://patchwork.freedesktop.org/patch/msgid/1466410226-19543-1-git-send-email-mika.kahola@intel.com
(cherry picked from commit 91df09d92ad82c8778ca218097bf827f154292ca)
Signed-off-by: Joakim Tjernlund <joakim.tjernlund@infinera.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/i915/intel_dp.c | 28 ++--------------------------
drivers/gpu/drm/i915/intel_drv.h | 1 -
2 files changed, 2 insertions(+), 27 deletions(-)
--- a/drivers/gpu/drm/i915/intel_dp.c
+++ b/drivers/gpu/drm/i915/intel_dp.c
@@ -3628,8 +3628,7 @@ static bool
intel_dp_reset_link_train(struct intel_dp *intel_dp, uint32_t *DP,
uint8_t dp_train_pat)
{
- if (!intel_dp->train_set_valid)
- memset(intel_dp->train_set, 0, sizeof(intel_dp->train_set));
+ memset(intel_dp->train_set, 0, sizeof(intel_dp->train_set));
intel_dp_set_signal_levels(intel_dp, DP);
return intel_dp_set_link_train(intel_dp, DP, dp_train_pat);
}
@@ -3746,22 +3745,6 @@ intel_dp_link_training_clock_recovery(st
break;
}
- /*
- * if we used previously trained voltage and pre-emphasis values
- * and we don't get clock recovery, reset link training values
- */
- if (intel_dp->train_set_valid) {
- DRM_DEBUG_KMS("clock recovery not ok, reset");
- /* clear the flag as we are not reusing train set */
- intel_dp->train_set_valid = false;
- if (!intel_dp_reset_link_train(intel_dp, &DP,
- DP_TRAINING_PATTERN_1 |
- DP_LINK_SCRAMBLING_DISABLE)) {
- DRM_ERROR("failed to enable link training\n");
- return;
- }
- continue;
- }
/* Check to see if we've tried the max voltage */
for (i = 0; i < intel_dp->lane_count; i++)
@@ -3854,7 +3837,6 @@ intel_dp_link_training_channel_equalizat
/* Make sure clock is still ok */
if (!drm_dp_clock_recovery_ok(link_status,
intel_dp->lane_count)) {
- intel_dp->train_set_valid = false;
intel_dp_link_training_clock_recovery(intel_dp);
intel_dp_set_link_train(intel_dp, &DP,
training_pattern |
@@ -3871,7 +3853,6 @@ intel_dp_link_training_channel_equalizat
/* Try 5 times, then try clock recovery if that fails */
if (tries > 5) {
- intel_dp->train_set_valid = false;
intel_dp_link_training_clock_recovery(intel_dp);
intel_dp_set_link_train(intel_dp, &DP,
training_pattern |
@@ -3893,10 +3874,8 @@ intel_dp_link_training_channel_equalizat
intel_dp->DP = DP;
- if (channel_eq) {
- intel_dp->train_set_valid = true;
+ if (channel_eq)
DRM_DEBUG_KMS("Channel EQ done. DP Training successful\n");
- }
}
void intel_dp_stop_link_train(struct intel_dp *intel_dp)
@@ -5159,9 +5138,6 @@ intel_dp_hpd_pulse(struct intel_digital_
intel_display_power_get(dev_priv, power_domain);
if (long_hpd) {
- /* indicate that we need to restart link training */
- intel_dp->train_set_valid = false;
-
if (!intel_digital_port_connected(dev_priv, intel_dig_port))
goto mst_fail;
--- a/drivers/gpu/drm/i915/intel_drv.h
+++ b/drivers/gpu/drm/i915/intel_drv.h
@@ -783,7 +783,6 @@ struct intel_dp {
bool has_aux_irq,
int send_bytes,
uint32_t aux_clock_divider);
- bool train_set_valid;
/* Displayport compliance testing */
unsigned long compliance_test_type;
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:20 +0200 |
| Subject | [PATCH 4.4 097/146] iio: Fix error handling in iio_trigger_attach_poll_func |
| Message-ID | <rYVs6-1c6-39@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Crestez Dan Leonard <leonard.crestez@intel.com>
commit 99543823357966ac938d9a310947e731b67338e6 upstream.
When attaching a pollfunc iio_trigger_attach_poll_func will allocate a
virtual irq and call the driver's set_trigger_state function. Fix error
handling to undo previous steps if any fails.
In particular this fixes handling errors from a driver's
set_trigger_state function. When using triggered buffers a failure to
enable the trigger used to make the buffer unusable.
Signed-off-by: Crestez Dan Leonard <leonard.crestez@intel.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/iio/industrialio-trigger.c | 23 ++++++++++++++++++-----
1 file changed, 18 insertions(+), 5 deletions(-)
--- a/drivers/iio/industrialio-trigger.c
+++ b/drivers/iio/industrialio-trigger.c
@@ -210,22 +210,35 @@ static int iio_trigger_attach_poll_func(
/* Prevent the module from being removed whilst attached to a trigger */
__module_get(pf->indio_dev->info->driver_module);
+
+ /* Get irq number */
pf->irq = iio_trigger_get_irq(trig);
+ if (pf->irq < 0)
+ goto out_put_module;
+
+ /* Request irq */
ret = request_threaded_irq(pf->irq, pf->h, pf->thread,
pf->type, pf->name,
pf);
- if (ret < 0) {
- module_put(pf->indio_dev->info->driver_module);
- return ret;
- }
+ if (ret < 0)
+ goto out_put_irq;
+ /* Enable trigger in driver */
if (trig->ops && trig->ops->set_trigger_state && notinuse) {
ret = trig->ops->set_trigger_state(trig, true);
if (ret < 0)
- module_put(pf->indio_dev->info->driver_module);
+ goto out_free_irq;
}
return ret;
+
+out_free_irq:
+ free_irq(pf->irq, pf);
+out_put_irq:
+ iio_trigger_put_irq(trig, pf->irq);
+out_put_module:
+ module_put(pf->indio_dev->info->driver_module);
+ return ret;
}
static int iio_trigger_detach_poll_func(struct iio_trigger *trig,
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:20 +0200 |
| Subject | [PATCH 4.4 054/146] HID: hiddev: validate num_values for HIDIOCGUSAGES, HIDIOCSUSAGES commands |
| Message-ID | <rYVs6-1c6-45@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Scott Bauer <sbauer@plzdonthack.me>
commit 93a2001bdfd5376c3dc2158653034c20392d15c5 upstream.
This patch validates the num_values parameter from userland during the
HIDIOCGUSAGES and HIDIOCSUSAGES commands. Previously, if the report id was set
to HID_REPORT_ID_UNKNOWN, we would fail to validate the num_values parameter
leading to a heap overflow.
Signed-off-by: Scott Bauer <sbauer@plzdonthack.me>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hid/usbhid/hiddev.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
--- a/drivers/hid/usbhid/hiddev.c
+++ b/drivers/hid/usbhid/hiddev.c
@@ -516,13 +516,13 @@ static noinline int hiddev_ioctl_usage(s
goto inval;
} else if (uref->usage_index >= field->report_count)
goto inval;
-
- else if ((cmd == HIDIOCGUSAGES || cmd == HIDIOCSUSAGES) &&
- (uref_multi->num_values > HID_MAX_MULTI_USAGES ||
- uref->usage_index + uref_multi->num_values > field->report_count))
- goto inval;
}
+ if ((cmd == HIDIOCGUSAGES || cmd == HIDIOCSUSAGES) &&
+ (uref_multi->num_values > HID_MAX_MULTI_USAGES ||
+ uref->usage_index + uref_multi->num_values > field->report_count))
+ goto inval;
+
switch (cmd) {
case HIDIOCGUSAGE:
uref->value = field->value[uref->usage_index];
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:20 +0200 |
| Subject | [PATCH 4.4 116/146] ALSA: dummy: Fix a use-after-free at closing |
| Message-ID | <rYVs6-1c6-47@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit d5dbbe6569481bf12dcbe3e12cff72c5f78d272c upstream.
syzkaller fuzzer spotted a potential use-after-free case in snd-dummy
driver when hrtimer is used as backend:
> ==================================================================
> BUG: KASAN: use-after-free in rb_erase+0x1b17/0x2010 at addr ffff88005e5b6f68
> Read of size 8 by task syz-executor/8984
> =============================================================================
> BUG kmalloc-192 (Not tainted): kasan: bad access detected
> -----------------------------------------------------------------------------
>
> Disabling lock debugging due to kernel taint
> INFO: Allocated in 0xbbbbbbbbbbbbbbbb age=18446705582212484632
> ....
> [< none >] dummy_hrtimer_create+0x49/0x1a0 sound/drivers/dummy.c:464
> ....
> INFO: Freed in 0xfffd8e09 age=18446705496313138713 cpu=2164287125 pid=-1
> [< none >] dummy_hrtimer_free+0x68/0x80 sound/drivers/dummy.c:481
> ....
> Call Trace:
> [<ffffffff8179e59e>] __asan_report_load8_noabort+0x3e/0x40 mm/kasan/report.c:333
> [< inline >] rb_set_parent include/linux/rbtree_augmented.h:111
> [< inline >] __rb_erase_augmented include/linux/rbtree_augmented.h:218
> [<ffffffff82ca5787>] rb_erase+0x1b17/0x2010 lib/rbtree.c:427
> [<ffffffff82cb02e8>] timerqueue_del+0x78/0x170 lib/timerqueue.c:86
> [<ffffffff814d0c80>] __remove_hrtimer+0x90/0x220 kernel/time/hrtimer.c:903
> [< inline >] remove_hrtimer kernel/time/hrtimer.c:945
> [<ffffffff814d23da>] hrtimer_try_to_cancel+0x22a/0x570 kernel/time/hrtimer.c:1046
> [<ffffffff814d2742>] hrtimer_cancel+0x22/0x40 kernel/time/hrtimer.c:1066
> [<ffffffff85420531>] dummy_hrtimer_stop+0x91/0xb0 sound/drivers/dummy.c:417
> [<ffffffff854228bf>] dummy_pcm_trigger+0x17f/0x1e0 sound/drivers/dummy.c:507
> [<ffffffff85392170>] snd_pcm_do_stop+0x160/0x1b0 sound/core/pcm_native.c:1106
> [<ffffffff85391b26>] snd_pcm_action_single+0x76/0x120 sound/core/pcm_native.c:956
> [<ffffffff85391e01>] snd_pcm_action+0x231/0x290 sound/core/pcm_native.c:974
> [< inline >] snd_pcm_stop sound/core/pcm_native.c:1139
> [<ffffffff8539754d>] snd_pcm_drop+0x12d/0x1d0 sound/core/pcm_native.c:1784
> [<ffffffff8539d3be>] snd_pcm_common_ioctl1+0xfae/0x2150 sound/core/pcm_native.c:2805
> [<ffffffff8539ee91>] snd_pcm_capture_ioctl1+0x2a1/0x5e0 sound/core/pcm_native.c:2976
> [<ffffffff8539f2ec>] snd_pcm_kernel_ioctl+0x11c/0x160 sound/core/pcm_native.c:3020
> [<ffffffff853d9a44>] snd_pcm_oss_sync+0x3a4/0xa30 sound/core/oss/pcm_oss.c:1693
> [<ffffffff853da27d>] snd_pcm_oss_release+0x1ad/0x280 sound/core/oss/pcm_oss.c:2483
> .....
A workaround is to call hrtimer_cancel() in dummy_hrtimer_sync() which
is called certainly before other blocking ops.
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Tested-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/drivers/dummy.c | 1 +
1 file changed, 1 insertion(+)
--- a/sound/drivers/dummy.c
+++ b/sound/drivers/dummy.c
@@ -420,6 +420,7 @@ static int dummy_hrtimer_stop(struct snd
static inline void dummy_hrtimer_sync(struct dummy_hrtimer_pcm *dpcm)
{
+ hrtimer_cancel(&dpcm->timer);
tasklet_kill(&dpcm->tasklet);
}
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:20 +0200 |
| Subject | [PATCH 4.4 096/146] xen/balloon: Fix declared-but-not-defined warning |
| Message-ID | <rYVs7-1c6-63@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ross Lagerwall <ross.lagerwall@citrix.com>
commit 842775f1509054ea969f1787f38d6a0ec2ccfaba upstream.
Fix a declared-but-not-defined warning when building with
XEN_BALLOON_MEMORY_HOTPLUG=n. This fixes a regression introduced by
commit dfd74a1edfab ("xen/balloon: Fix crash when ballooning on x86 32
bit PAE").
Signed-off-by: Ross Lagerwall <ross.lagerwall@citrix.com>
Acked-by: Juergen Gross <jgross@suse.com>
Signed-off-by: David Vrabel <david.vrabel@citrix.com>
Cc: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/xen/balloon.c | 28 +++++++++++++---------------
1 file changed, 13 insertions(+), 15 deletions(-)
--- a/drivers/xen/balloon.c
+++ b/drivers/xen/balloon.c
@@ -152,8 +152,6 @@ static DECLARE_WAIT_QUEUE_HEAD(balloon_w
static void balloon_process(struct work_struct *work);
static DECLARE_DELAYED_WORK(balloon_worker, balloon_process);
-static void release_memory_resource(struct resource *resource);
-
/* When ballooning out (allocating memory to return to Xen) we don't really
want the kernel to try too hard since that can trigger the oom killer. */
#define GFP_BALLOON \
@@ -249,6 +247,19 @@ static enum bp_state update_schedule(enu
}
#ifdef CONFIG_XEN_BALLOON_MEMORY_HOTPLUG
+static void release_memory_resource(struct resource *resource)
+{
+ if (!resource)
+ return;
+
+ /*
+ * No need to reset region to identity mapped since we now
+ * know that no I/O can be in this region
+ */
+ release_resource(resource);
+ kfree(resource);
+}
+
static struct resource *additional_memory_resource(phys_addr_t size)
{
struct resource *res;
@@ -287,19 +298,6 @@ static struct resource *additional_memor
return res;
}
-static void release_memory_resource(struct resource *resource)
-{
- if (!resource)
- return;
-
- /*
- * No need to reset region to identity mapped since we now
- * know that no I/O can be in this region
- */
- release_resource(resource);
- kfree(resource);
-}
-
static enum bp_state reserve_additional_memory(void)
{
long credit;
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:20 +0200 |
| Subject | [PATCH 4.4 146/146] ovl: verify upper dentry before unlink and rename |
| Message-ID | <rYVs7-1c6-67@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Miklos Szeredi <mszeredi@redhat.com>
commit 11f3710417d026ea2f4fcf362d866342c5274185 upstream.
Unlink and rename in overlayfs checked the upper dentry for staleness by
verifying upper->d_parent against upperdir. However the dentry can go
stale also by being unhashed, for example.
Expand the verification to actually look up the name again (under parent
lock) and check if it matches the upper dentry. This matches what the VFS
does before passing the dentry to filesytem's unlink/rename methods, which
excludes any inconsistency caused by overlayfs.
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/overlayfs/dir.c | 59 ++++++++++++++++++++++++++++++++++-------------------
1 file changed, 38 insertions(+), 21 deletions(-)
--- a/fs/overlayfs/dir.c
+++ b/fs/overlayfs/dir.c
@@ -590,21 +590,25 @@ static int ovl_remove_upper(struct dentr
{
struct dentry *upperdir = ovl_dentry_upper(dentry->d_parent);
struct inode *dir = upperdir->d_inode;
- struct dentry *upper = ovl_dentry_upper(dentry);
+ struct dentry *upper;
int err;
mutex_lock_nested(&dir->i_mutex, I_MUTEX_PARENT);
+ upper = lookup_one_len(dentry->d_name.name, upperdir,
+ dentry->d_name.len);
+ err = PTR_ERR(upper);
+ if (IS_ERR(upper))
+ goto out_unlock;
+
err = -ESTALE;
- if (upper->d_parent == upperdir) {
- /* Don't let d_delete() think it can reset d_inode */
- dget(upper);
+ if (upper == ovl_dentry_upper(dentry)) {
if (is_dir)
err = vfs_rmdir(dir, upper);
else
err = vfs_unlink(dir, upper, NULL);
- dput(upper);
ovl_dentry_version_inc(dentry->d_parent);
}
+ dput(upper);
/*
* Keeping this dentry hashed would mean having to release
@@ -614,6 +618,7 @@ static int ovl_remove_upper(struct dentr
*/
if (!err)
d_drop(dentry);
+out_unlock:
mutex_unlock(&dir->i_mutex);
return err;
@@ -834,29 +839,39 @@ static int ovl_rename2(struct inode *old
trap = lock_rename(new_upperdir, old_upperdir);
- olddentry = ovl_dentry_upper(old);
- newdentry = ovl_dentry_upper(new);
- if (newdentry) {
+
+ olddentry = lookup_one_len(old->d_name.name, old_upperdir,
+ old->d_name.len);
+ err = PTR_ERR(olddentry);
+ if (IS_ERR(olddentry))
+ goto out_unlock;
+
+ err = -ESTALE;
+ if (olddentry != ovl_dentry_upper(old))
+ goto out_dput_old;
+
+ newdentry = lookup_one_len(new->d_name.name, new_upperdir,
+ new->d_name.len);
+ err = PTR_ERR(newdentry);
+ if (IS_ERR(newdentry))
+ goto out_dput_old;
+
+ err = -ESTALE;
+ if (ovl_dentry_upper(new)) {
if (opaquedir) {
- newdentry = opaquedir;
- opaquedir = NULL;
+ if (newdentry != opaquedir)
+ goto out_dput;
} else {
- dget(newdentry);
+ if (newdentry != ovl_dentry_upper(new))
+ goto out_dput;
}
} else {
new_create = true;
- newdentry = lookup_one_len(new->d_name.name, new_upperdir,
- new->d_name.len);
- err = PTR_ERR(newdentry);
- if (IS_ERR(newdentry))
- goto out_unlock;
+ if (!d_is_negative(newdentry) &&
+ (!new_opaque || !ovl_is_whiteout(newdentry)))
+ goto out_dput;
}
- err = -ESTALE;
- if (olddentry->d_parent != old_upperdir)
- goto out_dput;
- if (newdentry->d_parent != new_upperdir)
- goto out_dput;
if (olddentry == trap)
goto out_dput;
if (newdentry == trap)
@@ -919,6 +934,8 @@ static int ovl_rename2(struct inode *old
out_dput:
dput(newdentry);
+out_dput_old:
+ dput(olddentry);
out_unlock:
unlock_rename(new_upperdir, old_upperdir);
out_revert_creds:
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:20 +0200 |
| Subject | [PATCH 4.4 143/146] tmpfs: dont undo fallocate past its last page |
| Message-ID | <rYVs7-1c6-69@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Anthony Romano <anthony.romano@coreos.com>
commit b9b4bb26af017dbe930cd4df7f9b2fc3a0497bfe upstream.
When fallocate is interrupted it will undo a range that extends one byte
past its range of allocated pages. This can corrupt an in-use page by
zeroing out its first byte. Instead, undo using the inclusive byte
range.
Fixes: 1635f6a74152f1d ("tmpfs: undo fallocation on failure")
Link: http://lkml.kernel.org/r/1462713387-16724-1-git-send-email-anthony.romano@coreos.com
Signed-off-by: Anthony Romano <anthony.romano@coreos.com>
Cc: Vlastimil Babka <vbabka@suse.cz>
Cc: Hugh Dickins <hughd@google.com>
Cc: Brandon Philips <brandon@ifup.co>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/shmem.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/mm/shmem.c
+++ b/mm/shmem.c
@@ -2155,7 +2155,7 @@ static long shmem_fallocate(struct file
/* Remove the !PageUptodate pages we added */
shmem_undo_range(inode,
(loff_t)start << PAGE_CACHE_SHIFT,
- (loff_t)index << PAGE_CACHE_SHIFT, true);
+ ((loff_t)index << PAGE_CACHE_SHIFT) - 1, true);
goto undone;
}
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:20 +0200 |
| Subject | [PATCH 4.4 144/146] tmpfs: fix regression hang in fallocate undo |
| Message-ID | <rYVs7-1c6-75@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hugh Dickins <hughd@google.com>
commit 7f556567036cb7f89aabe2f0954b08566b4efb53 upstream.
The well-spotted fallocate undo fix is good in most cases, but not when
fallocate failed on the very first page. index 0 then passes lend -1
to shmem_undo_range(), and that has two bad effects: (a) that it will
undo every fallocation throughout the file, unrestricted by the current
range; but more importantly (b) it can cause the undo to hang, because
lend -1 is treated as truncation, which makes it keep on retrying until
every page has gone, but those already fully instantiated will never go
away. Big thank you to xfstests generic/269 which demonstrates this.
Fixes: b9b4bb26af01 ("tmpfs: don't undo fallocate past its last page")
Signed-off-by: Hugh Dickins <hughd@google.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/shmem.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
--- a/mm/shmem.c
+++ b/mm/shmem.c
@@ -2153,9 +2153,11 @@ static long shmem_fallocate(struct file
NULL);
if (error) {
/* Remove the !PageUptodate pages we added */
- shmem_undo_range(inode,
- (loff_t)start << PAGE_CACHE_SHIFT,
- ((loff_t)index << PAGE_CACHE_SHIFT) - 1, true);
+ if (index > start) {
+ shmem_undo_range(inode,
+ (loff_t)start << PAGE_CACHE_SHIFT,
+ ((loff_t)index << PAGE_CACHE_SHIFT) - 1, true);
+ }
goto undone;
}
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:20 +0200 |
| Subject | [PATCH 4.4 072/146] drm/amdkfd: unbind only existing processes |
| Message-ID | <rYVs7-1c6-61@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Oded Gabbay <oded.gabbay@gmail.com>
commit 121b78e679ee3ffab780115e260b2775d0cc1f73 upstream.
When unbinding a process from a device (initiated by amd_iommu_v2), the
driver needs to make sure that process still exists in the process table.
There is a possibility that amdkfd's own notifier handler -
kfd_process_notifier_release() - was called before the unbind function
and it already removed the process from the process table.
v2:
Because there can be only one process with the specified pasid, and
because *p can't be NULL inside the hash_for_each_rcu macro, it is more
reasonable to just put the whole code inside the if statement that
compares the pasid value. That way, when we exit hash_for_each_rcu, we
simply exit the function as well.
Signed-off-by: Oded Gabbay <oded.gabbay@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdkfd/kfd_process.c | 60 ++++++++++++++++++-------------
1 file changed, 35 insertions(+), 25 deletions(-)
--- a/drivers/gpu/drm/amd/amdkfd/kfd_process.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_process.c
@@ -404,42 +404,52 @@ void kfd_unbind_process_from_device(stru
idx = srcu_read_lock(&kfd_processes_srcu);
+ /*
+ * Look for the process that matches the pasid. If there is no such
+ * process, we either released it in amdkfd's own notifier, or there
+ * is a bug. Unfortunately, there is no way to tell...
+ */
hash_for_each_rcu(kfd_processes_table, i, p, kfd_processes)
- if (p->pasid == pasid)
- break;
+ if (p->pasid == pasid) {
- srcu_read_unlock(&kfd_processes_srcu, idx);
+ srcu_read_unlock(&kfd_processes_srcu, idx);
- BUG_ON(p->pasid != pasid);
+ pr_debug("Unbinding process %d from IOMMU\n", pasid);
- mutex_lock(&p->mutex);
+ mutex_lock(&p->mutex);
- if ((dev->dbgmgr) && (dev->dbgmgr->pasid == p->pasid))
- kfd_dbgmgr_destroy(dev->dbgmgr);
+ if ((dev->dbgmgr) && (dev->dbgmgr->pasid == p->pasid))
+ kfd_dbgmgr_destroy(dev->dbgmgr);
- pqm_uninit(&p->pqm);
+ pqm_uninit(&p->pqm);
- pdd = kfd_get_process_device_data(dev, p);
+ pdd = kfd_get_process_device_data(dev, p);
- if (!pdd) {
- mutex_unlock(&p->mutex);
- return;
- }
+ if (!pdd) {
+ mutex_unlock(&p->mutex);
+ return;
+ }
- if (pdd->reset_wavefronts) {
- dbgdev_wave_reset_wavefronts(pdd->dev, p);
- pdd->reset_wavefronts = false;
- }
+ if (pdd->reset_wavefronts) {
+ dbgdev_wave_reset_wavefronts(pdd->dev, p);
+ pdd->reset_wavefronts = false;
+ }
- /*
- * Just mark pdd as unbound, because we still need it to call
- * amd_iommu_unbind_pasid() in when the process exits.
- * We don't call amd_iommu_unbind_pasid() here
- * because the IOMMU called us.
- */
- pdd->bound = false;
+ /*
+ * Just mark pdd as unbound, because we still need it
+ * to call amd_iommu_unbind_pasid() in when the
+ * process exits.
+ * We don't call amd_iommu_unbind_pasid() here
+ * because the IOMMU called us.
+ */
+ pdd->bound = false;
+
+ mutex_unlock(&p->mutex);
- mutex_unlock(&p->mutex);
+ return;
+ }
+
+ srcu_read_unlock(&kfd_processes_srcu, idx);
}
struct kfd_process_device *kfd_get_first_process_device_data(struct kfd_process *p)
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:30 +0200 |
| Subject | [PATCH 4.4 105/146] iio: hudmidity: hdc100x: fix incorrect shifting and scaling |
| Message-ID | <rYVBL-1gH-11@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matt Ranostay <mranostay@gmail.com>
commit 94bef000f1d4aa111f4ddda1482cf3b30ad069ce upstream.
Shifting sensor data to the right 2 bits was incorrect and caused the
scaling values + offsets to be invalid.
Reported-by: Alison Schofield <amsfield22@gmail.com>
Signed-off-by: Matt Ranostay <mranostay@gmail.com>
Tested-by: Alison Schofield <amsfield22@gmail.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/iio/humidity/hdc100x.c | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
--- a/drivers/iio/humidity/hdc100x.c
+++ b/drivers/iio/humidity/hdc100x.c
@@ -164,14 +164,14 @@ static int hdc100x_get_measurement(struc
dev_err(&client->dev, "cannot read high byte measurement");
return ret;
}
- val = ret << 6;
+ val = ret << 8;
ret = i2c_smbus_read_byte(client);
if (ret < 0) {
dev_err(&client->dev, "cannot read low byte measurement");
return ret;
}
- val |= ret >> 2;
+ val |= ret;
return val;
}
@@ -212,17 +212,17 @@ static int hdc100x_read_raw(struct iio_d
case IIO_CHAN_INFO_SCALE:
if (chan->type == IIO_TEMP) {
*val = 165000;
- *val2 = 65536 >> 2;
+ *val2 = 65536;
return IIO_VAL_FRACTIONAL;
} else {
- *val = 0;
- *val2 = 10000;
- return IIO_VAL_INT_PLUS_MICRO;
+ *val = 100;
+ *val2 = 65536;
+ return IIO_VAL_FRACTIONAL;
}
break;
case IIO_CHAN_INFO_OFFSET:
- *val = -3971;
- *val2 = 879096;
+ *val = -15887;
+ *val2 = 515151;
return IIO_VAL_INT_PLUS_MICRO;
default:
return -EINVAL;
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:30 +0200 |
| Subject | [PATCH 4.4 119/146] ALSA: au88x0: Fix calculation in vortex_wtdma_bufshift() |
| Message-ID | <rYVBL-1gH-13@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit 62db7152c924e4c060e42b34a69cd39658e8a0dc upstream.
vortex_wtdma_bufshift() function does calculate the page index
wrongly, first masking then shift, which always results in zero.
The proper computation is to first shift, then mask.
Reported-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/pci/au88x0/au88x0_core.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
--- a/sound/pci/au88x0/au88x0_core.c
+++ b/sound/pci/au88x0/au88x0_core.c
@@ -1444,9 +1444,8 @@ static int vortex_wtdma_bufshift(vortex_
int page, p, pp, delta, i;
page =
- (hwread(vortex->mmio, VORTEX_WTDMA_STAT + (wtdma << 2)) &
- WT_SUBBUF_MASK)
- >> WT_SUBBUF_SHIFT;
+ (hwread(vortex->mmio, VORTEX_WTDMA_STAT + (wtdma << 2))
+ >> WT_SUBBUF_SHIFT) & WT_SUBBUF_MASK;
if (dma->nr_periods >= 4)
delta = (page - dma->period_real) & 3;
else {
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:30 +0200 |
| Subject | [PATCH 4.4 141/146] xen/acpi: allow xen-acpi-processor driver to load on Xen 4.7 |
| Message-ID | <rYVBL-1gH-17@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jan Beulich <JBeulich@suse.com>
commit 6f2d9d99213514360034c6d52d2c3919290b3504 upstream.
As of Xen 4.7 PV CPUID doesn't expose either of CPUID[1].ECX[7] and
CPUID[0x80000007].EDX[7] anymore, causing the driver to fail to load on
both Intel and AMD systems. Doing any kind of hardware capability
checks in the driver as a prerequisite was wrong anyway: With the
hypervisor being in charge, all such checking should be done by it. If
ACPI data gets uploaded despite some missing capability, the hypervisor
is free to ignore part or all of that data.
Ditch the entire check_prereq() function, and do the only valid check
(xen_initial_domain()) in the caller in its place.
Signed-off-by: Jan Beulich <jbeulich@suse.com>
Signed-off-by: David Vrabel <david.vrabel@citrix.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/xen/xen-acpi-processor.c | 35 +++--------------------------------
1 file changed, 3 insertions(+), 32 deletions(-)
--- a/drivers/xen/xen-acpi-processor.c
+++ b/drivers/xen/xen-acpi-processor.c
@@ -423,36 +423,7 @@ upload:
return 0;
}
-static int __init check_prereq(void)
-{
- struct cpuinfo_x86 *c = &cpu_data(0);
-
- if (!xen_initial_domain())
- return -ENODEV;
-
- if (!acpi_gbl_FADT.smi_command)
- return -ENODEV;
- if (c->x86_vendor == X86_VENDOR_INTEL) {
- if (!cpu_has(c, X86_FEATURE_EST))
- return -ENODEV;
-
- return 0;
- }
- if (c->x86_vendor == X86_VENDOR_AMD) {
- /* Copied from powernow-k8.h, can't include ../cpufreq/powernow
- * as we get compile warnings for the static functions.
- */
-#define CPUID_FREQ_VOLT_CAPABILITIES 0x80000007
-#define USE_HW_PSTATE 0x00000080
- u32 eax, ebx, ecx, edx;
- cpuid(CPUID_FREQ_VOLT_CAPABILITIES, &eax, &ebx, &ecx, &edx);
- if ((edx & USE_HW_PSTATE) != USE_HW_PSTATE)
- return -ENODEV;
- return 0;
- }
- return -ENODEV;
-}
/* acpi_perf_data is a pointer to percpu data. */
static struct acpi_processor_performance __percpu *acpi_perf_data;
@@ -509,10 +480,10 @@ struct notifier_block xen_acpi_processor
static int __init xen_acpi_processor_init(void)
{
unsigned int i;
- int rc = check_prereq();
+ int rc;
- if (rc)
- return rc;
+ if (!xen_initial_domain())
+ return -ENODEV;
nr_acpi_bits = get_max_acpi_id() + 1;
acpi_ids_done = kcalloc(BITS_TO_LONGS(nr_acpi_bits), sizeof(unsigned long), GFP_KERNEL);
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:30 +0200 |
| Subject | [PATCH 4.4 102/146] iio: proximity: as3935: fix buffer stack trashing |
| Message-ID | <rYVBL-1gH-5@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matt Ranostay <mranostay@gmail.com>
commit 37b1ba2c68cfbe37f5f45bb91bcfaf2b016ae6a1 upstream.
Buffer wasn't of a valid size to allow the timestamp, and correct padding.
This patchset also moves the buffer off the stack, and onto the heap.
Cc: george.mccollister@gmail.com
Signed-off-by: Matt Ranostay <mranostay@gmail.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/iio/proximity/as3935.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/drivers/iio/proximity/as3935.c
+++ b/drivers/iio/proximity/as3935.c
@@ -64,6 +64,7 @@ struct as3935_state {
struct delayed_work work;
u32 tune_cap;
+ u8 buffer[16]; /* 8-bit data + 56-bit padding + 64-bit timestamp */
u8 buf[2] ____cacheline_aligned;
};
@@ -212,9 +213,10 @@ static irqreturn_t as3935_trigger_handle
ret = as3935_read(st, AS3935_DATA, &val);
if (ret)
goto err_read;
- val &= AS3935_DATA_MASK;
- iio_push_to_buffers_with_timestamp(indio_dev, &val, pf->timestamp);
+ st->buffer[0] = val & AS3935_DATA_MASK;
+ iio_push_to_buffers_with_timestamp(indio_dev, &st->buffer,
+ pf->timestamp);
err_read:
iio_trigger_notify_done(indio_dev->trig);
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:30 +0200 |
| Subject | [PATCH 4.4 110/146] iio:ad7266: Fix probe deferral for vref |
| Message-ID | <rYVBL-1gH-7@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Brown <broonie@kernel.org>
commit 68b356eb3d9f5e38910fb62e22a78e2a18d544ae upstream.
Currently the ad7266 driver treats any failure to get vref as though the
regulator were not present but this means that if probe deferral is
triggered the driver will act as though the regulator were not present.
Instead only use the internal reference if we explicitly got -ENODEV which
is what is returned for absent regulators.
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/iio/adc/ad7266.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/iio/adc/ad7266.c
+++ b/drivers/iio/adc/ad7266.c
@@ -408,6 +408,9 @@ static int ad7266_probe(struct spi_devic
st->vref_mv = ret / 1000;
} else {
+ /* Any other error indicates that the regulator does exist */
+ if (PTR_ERR(st->reg) != -ENODEV)
+ return PTR_ERR(st->reg);
/* Use internal reference */
st->vref_mv = 2500;
}
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:30 +0200 |
| Subject | [PATCH 4.4 132/146] ARM: mvebu: fix HW I/O coherency related deadlocks |
| Message-ID | <rYVBL-1gH-9@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
commit c5379ba8fccd99d5f99632c789f0393d84a57805 upstream.
Until now, our understanding for HW I/O coherency to work on the
Cortex-A9 based Marvell SoC was that only the PCIe regions should be
mapped strongly-ordered. However, we were still encountering some
deadlocks, especially when testing the CESA crypto engine. After
checking with the HW designers, it was concluded that all the MMIO
registers should be mapped as strongly ordered for the HW I/O coherency
mechanism to work properly.
This fixes some easy to reproduce deadlocks with the CESA crypto engine
driver (dmcrypt on a sufficiently large disk partition).
Tested-by: Terry Stockert <stockert@inkblotadmirer.me>
Tested-by: Romain Perier <romain.perier@free-electrons.com>
Cc: Terry Stockert <stockert@inkblotadmirer.me>
Cc: Romain Perier <romain.perier@free-electrons.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
Signed-off-by: Gregory CLEMENT <gregory.clement@free-electrons.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm/mach-mvebu/coherency.c | 22 ++++++++--------------
1 file changed, 8 insertions(+), 14 deletions(-)
--- a/arch/arm/mach-mvebu/coherency.c
+++ b/arch/arm/mach-mvebu/coherency.c
@@ -162,22 +162,16 @@ exit:
}
/*
- * This ioremap hook is used on Armada 375/38x to ensure that PCIe
- * memory areas are mapped as MT_UNCACHED instead of MT_DEVICE. This
- * is needed as a workaround for a deadlock issue between the PCIe
- * interface and the cache controller.
+ * This ioremap hook is used on Armada 375/38x to ensure that all MMIO
+ * areas are mapped as MT_UNCACHED instead of MT_DEVICE. This is
+ * needed for the HW I/O coherency mechanism to work properly without
+ * deadlock.
*/
static void __iomem *
-armada_pcie_wa_ioremap_caller(phys_addr_t phys_addr, size_t size,
- unsigned int mtype, void *caller)
+armada_wa_ioremap_caller(phys_addr_t phys_addr, size_t size,
+ unsigned int mtype, void *caller)
{
- struct resource pcie_mem;
-
- mvebu_mbus_get_pcie_mem_aperture(&pcie_mem);
-
- if (pcie_mem.start <= phys_addr && (phys_addr + size) <= pcie_mem.end)
- mtype = MT_UNCACHED;
-
+ mtype = MT_UNCACHED;
return __arm_ioremap_caller(phys_addr, size, mtype, caller);
}
@@ -186,7 +180,7 @@ static void __init armada_375_380_cohere
struct device_node *cache_dn;
coherency_cpu_base = of_iomap(np, 0);
- arch_ioremap_caller = armada_pcie_wa_ioremap_caller;
+ arch_ioremap_caller = armada_wa_ioremap_caller;
/*
* We should switch the PL310 to I/O coherency mode only if
[toc] | [prev] | [next] | [standalone]
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-07-25 23:30 +0200 |
| Subject | [PATCH 4.4 099/146] iio: light apds9960: Add the missing dev.parent |
| Message-ID | <rYVBL-1gH-19@gated-at.bofh.it> |
| In reply to | #1449869 |
4.4-stable review patch. If anyone has any objections, please let me know. ------------------ From: Yong Li <sdliyong@gmail.com> commit 590b92a30242dd3f73de3d9a51d9924f1ab33e93 upstream. Without this, the iio:deviceX is missing in the /sys/bus/i2c/devices/0-0039 Some userspace tools use this path to identify a specific instance of the device. Signed-off-by: Yong Li <sdliyong@gmail.com> Reviewed-By: Matt Ranostay <mranostay@gmail.com> Signed-off-by: Jonathan Cameron <jic23@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> --- drivers/iio/light/apds9960.c | 1 + 1 file changed, 1 insertion(+) --- a/drivers/iio/light/apds9960.c +++ b/drivers/iio/light/apds9960.c @@ -1005,6 +1005,7 @@ static int apds9960_probe(struct i2c_cli iio_device_attach_buffer(indio_dev, buffer); + indio_dev->dev.parent = &client->dev; indio_dev->info = &apds9960_info; indio_dev->name = APDS9960_DRV_NAME; indio_dev->channels = apds9960_channels;
[toc] | [prev] | [next] | [standalone]
Page 1 of 5 [1] 2 3 4 5 Next page →
Back to top | Article view | linux.kernel
csiph-web