Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1450166 > unrolled thread

[PATCH 4.6 000/203] 4.6.5-stable review

Started byGreg Kroah-Hartman <gregkh@linuxfoundation.org>
First post2016-07-26 00:30 +0200
Last post2016-07-27 06:50 +0200
Articles 20 on this page of 21 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 4.6 000/203] 4.6.5-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:30 +0200
    [PATCH 4.6 017/203] powerpc/tm: Always reclaim in start_thread() for exec() class syscalls Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
    [PATCH 4.6 014/203] powerpc/iommu: Remove the dependency on EEH struct in DDW mechanism Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
    [PATCH 4.6 023/203] mnt: Account for MS_RDONLY in fs_fully_visible Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
    [PATCH 4.6 022/203] mnt: fs_fully_visible test the proper mount for MNT_LOCKED Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
    [PATCH 4.6 010/203] IB/core: Fix bit curruption in ib_device_cap_flags structure Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
    [PATCH 4.6 018/203] usb: dwc2: fix regression on big-endian PowerPC/ARM systems Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
    [PATCH 4.6 002/203] mac80211: fix fast_tx header alignment Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
    [PATCH 4.6 012/203] IB/rdmavt: Correct qp_priv_alloc() return value test Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
    [PATCH 4.6 019/203] USB: EHCI: declare hostpc register as zero-length array Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
    [PATCH 4.6 013/203] IB/mlx4: Properly initialize GRH TClass and FlowLabel in AHs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
    [PATCH 4.6 016/203] powerpc/pseries: Fix IBM_ARCH_VEC_NRCORES_OFFSET since POWER8NVL was added Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
    [PATCH 4.6 025/203] of: fix autoloading due to broken modalias with no compatible Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
    [PATCH 4.6 020/203] USB: dont free bandwidth_mutex too early Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
    [PATCH 4.6 015/203] powerpc/pseries: Fix PCI config address for DDW Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 00:40 +0200
    Re: [PATCH 4.6 000/203] 4.6.5-stable review Shuah Khan <shuah.kh@samsung.com> - 2016-07-26 04:10 +0200
      Re: [PATCH 4.6 000/203] 4.6.5-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 04:50 +0200
    Re: [PATCH 4.6 000/203] 4.6.5-stable review Guenter Roeck <linux@roeck-us.net> - 2016-07-26 16:00 +0200
      Re: [PATCH 4.6 000/203] 4.6.5-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-26 16:30 +0200
        Re: [PATCH 4.6 000/203] 4.6.5-stable review Guenter Roeck <linux@roeck-us.net> - 2016-07-26 17:50 +0200
    Re: [PATCH 4.6 000/203] 4.6.5-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-07-27 06:50 +0200

Page 1 of 2  [1] 2  Next page →


#1450166 — [PATCH 4.6 000/203] 4.6.5-stable review

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:30 +0200
Subject[PATCH 4.6 000/203] 4.6.5-stable review
Message-ID<rYVs7-1c6-53@gated-at.bofh.it>
This is the start of the stable review cycle for the 4.6.5 release.
There are 203 patches in this series, all will be posted as a response
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Wed Jul 27 20:33:38 UTC 2016.
Anything received after that time might be too late.

The whole patch series can be found in one patch at:
	kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.6.5-rc1.gz
or in the git tree and branch at:
  git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.6.y
and the diffstat can be found below.

thanks,

greg k-h

-------------
Pseudo-Shortlog of commits:

Greg Kroah-Hartman <gregkh@linuxfoundation.org>
    Linux 4.6.5-rc1

Vivek Goyal <vgoyal@redhat.com>
    ovl: warn instead of error if d_type is not supported

Vivek Goyal <vgoyal@redhat.com>
    ovl: Do d_type check only if work dir creation was successful

Mika Kahola <mika.kahola@intel.com>
    drm/i915: Revert DisplayPort fast link training feature

Jan Stancek <jstancek@redhat.com>
    crypto: qat - make qat_asym_algs.o depend on asn1 headers

Herbert Xu <herbert@gondor.apana.org.au>
    crypto: rsa-pkcs1pad - fix rsa-pkcs1pad request struct

Hugh Dickins <hughd@google.com>
    tmpfs: fix regression hang in fallocate undo

Anthony Romano <anthony.romano@coreos.com>
    tmpfs: don't undo fallocate past its last page

Jan Beulich <JBeulich@suse.com>
    xen/acpi: allow xen-acpi-processor driver to load on Xen 4.7

Steve French <smfrench@gmail.com>
    File names with trailing period or space need special case conversion

Jerome Marchand <jmarchan@redhat.com>
    cifs: dynamic allocation of ntlmssp blob

Steve French <smfrench@gmail.com>
    Fix reconnect to not defer smb3 session reconnect long after socket reconnect

James Bottomley <jejb@linux.vnet.ibm.com>
    53c700: fix BUG on untagged commands

Michael Holzheu <holzheu@linux.vnet.ibm.com>
    Revert "s390/kdump: Clear subchannel ID to signal non-CCW/SCSI IPL"

Martin Schwidefsky <schwidefsky@de.ibm.com>
    s390: fix test_fp_ctl inline assembly contraints

Wei Fang <fangwei1@huawei.com>
    scsi: fix race between simultaneous decrements of ->host_failed

Maxim Patlasov <mpatlasov@virtuozzo.com>
    ovl: verify upper dentry in ovl_remove_and_whiteout()

Miklos Szeredi <mszeredi@redhat.com>
    ovl: handle ATTR_KILL*

Vivek Goyal <vgoyal@redhat.com>
    ovl: Copy up underlying inode's ->i_mode to overlay inode

Miklos Szeredi <mszeredi@redhat.com>
    ovl: get_write_access() in truncate

Miklos Szeredi <mszeredi@redhat.com>
    ovl: fix dentry leak for default_permissions

Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
    ARM: mvebu: fix HW I/O coherency related deadlocks

Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
    ARM: dts: armada-38x: fix MBUS_ID for crypto SRAM on Armada 385 Linksys

Boris Brezillon <boris.brezillon@free-electrons.com>
    ARM: sunxi/dt: make the CHIP inherit from allwinner,sun5i-a13

Awais Belal <awais_belal@mentor.com>
    ALSA: hda: add AMD Stoney PCI ID with proper driver caps

Peter Wu <peter@lekensteyn.nl>
    ALSA: hda - fix use-after-free after module unload

Takashi Iwai <tiwai@suse.de>
    ALSA: ctl: Stop notification after disconnection

Takashi Iwai <tiwai@suse.de>
    ALSA: pcm: Free chmap at PCM free callback, too

Hui Wang <hui.wang@canonical.com>
    ALSA: hda/realtek - add new pin definition in alc225 pin quirk table

Kazuki Oikawa <k@oikw.org>
    ALSA: usb-audio: Fix quirks code is not called

Bob Copeland <me@bobcopeland.com>
    ALSA: hda - fix read before array start

Vinod Koul <vinod.koul@intel.com>
    ALSA: hda - Add PCI ID for Kabylake-H

Torsten Hilbrich <torsten.hilbrich@secunet.com>
    ALSA: hda/realtek: Add Lenovo L460 to docking unit fixup

Takashi Iwai <tiwai@suse.de>
    ALSA: timer: Fix negative queue usage by racy accesses

Christophe JAILLET <christophe.jaillet@wanadoo.fr>
    ALSA: echoaudio: Fix memory allocation

Takashi Iwai <tiwai@suse.de>
    ALSA: au88x0: Fix calculation in vortex_wtdma_bufshift()

Jaroslav Kysela <perex@perex.cz>
    ALSA: hda / realtek - add two more Thinkpad IDs (5050,5053) for tpt460 fixup

Woodrow Shen <woodrow.shen@gmail.com>
    ALSA: hda - Fix the headset mic jack detection on Dell machine

Jaroslav Kysela <perex@perex.cz>
    ALSA: hdac_regmap - fix the register access for runtime PM

Takashi Iwai <tiwai@suse.de>
    ALSA: dummy: Fix a use-after-free at closing

Pali Rohár <pali.rohar@gmail.com>
    hwmon: (dell-smm) Cache fan_type() calls and change fan detection

Pali Rohár <pali.rohar@gmail.com>
    hwmon: (dell-smm) Disallow fan_type() calls on broken machines

Pali Rohár <pali.rohar@gmail.com>
    hwmon: (dell-smm) Restrict fan control and serial number to CAP_SYS_ADMIN by default

Dmitry Torokhov <dmitry.torokhov@gmail.com>
    tty/vt/keyboard: fix OOB access in do_compute_shiftstate()

David Daney <david.daney@cavium.com>
    tty: vt: Fix soft lockup in fbcon cursor blink timer.

Mark Brown <broonie@kernel.org>
    iio:ad7266: Fix probe deferral for vref

Mark Brown <broonie@kernel.org>
    iio:ad7266: Fix support for optional regulators

Mark Brown <broonie@kernel.org>
    iio:ad7266: Fix broken regulator error handling

Linus Walleij <linus.walleij@linaro.org>
    iio: accel: kxsd9: fix the usage of spi_w8r8()

Luis de Bethencourt <luisbg@osg.samsung.com>
    staging: iio: accel: fix error check

Matt Ranostay <mranostay@gmail.com>
    iio: hudmidity: hdc100x: fix incorrect shifting and scaling

Matt Ranostay <mranostay@gmail.com>
    iio: humidity: hdc100x: fix IIO_TEMP channel reporting

Alison Schofield <amsfield22@gmail.com>
    iio: humidity: hdc100x: correct humidity integration time mask

Matt Ranostay <mranostay@gmail.com>
    iio: proximity: as3935: fix buffer stack trashing

Matt Ranostay <mranostay@gmail.com>
    iio: proximity: as3935: remove triggered buffer processing

Matt Ranostay <mranostay@gmail.com>
    iio: proximity: as3935: correct IIO_CHAN_INFO_RAW output

Yong Li <sdliyong@gmail.com>
    iio: light apds9960: Add the missing dev.parent

Gregor Boirie <gregor.boirie@parrot.com>
    iio:st_pressure: fix sampling gains (bring inline with ABI)

Crestez Dan Leonard <leonard.crestez@intel.com>
    iio: Fix error handling in iio_trigger_attach_poll_func

Ross Lagerwall <ross.lagerwall@citrix.com>
    xen/balloon: Fix declared-but-not-defined warning

David Miller <davem@davemloft.net>
    PCI: Fix unaligned accesses in VC code

Ocquidant, Sebastien <sebastienocquidant@eaton.com>
    memory: omap-gpmc: Fix omap gpmc EXTRADELAY timing

Sinclair Yeh <syeh@vmware.com>
    drm/vmwgfx: Fix error paths when mapping framebuffer

Thomas Hellstrom <thellstrom@vmware.com>
    drm/vmwgfx: Fix corner case screen target management

Sinclair Yeh <syeh@vmware.com>
    drm/vmwgfx: Delay pinning fbdev framebuffer until after mode set

Sinclair Yeh <syeh@vmware.com>
    drm/vmwgfx: Check pin count before attempting to move a buffer

Sinclair Yeh <syeh@vmware.com>
    drm/vmwgfx: Work around mode set failure in 2D VMs

Sinclair Yeh <syeh@vmware.com>
    drm/vmwgfx: Add an option to change assumed FB bpp

Sinclair Yeh <syeh@vmware.com>
    drm/ttm: Make ttm_bo_mem_compat available

Maarten Lankhorst <maarten.lankhorst@linux.intel.com>
    drm/atomic: Make drm_atomic_legacy_backoff reset crtc->acquire_ctx

Boris Brezillon <boris.brezillon@free-electrons.com>
    drm: atmel-hlcdc: actually disable scaling when no scaling is required

Huang Rui <ray.huang@amd.com>
    drm/amd/powerplay: fix incorrect voltage table value for tonga

Rex Zhu <Rex.Zhu@amd.com>
    drm/amd/powerplay: incorrectly use of the function return value

Rex Zhu <Rex.Zhu@amd.com>
    drm/amd/powerplay: fix logic error.

Rex Zhu <Rex.Zhu@amd.com>
    drm/amd/powerplay: need to notify system bios pcie device ready

Rex Zhu <Rex.Zhu@amd.com>
    drm/amd/powerplay: fix bug that function parameter was incorect.

Chris Wilson <chris@chris-wilson.co.uk>
    drm: Wrap direct calls to driver->gem_free_object from CMA

Tomi Valkeinen <tomi.valkeinen@ti.com>
    drm: make drm_atomic_set_mode_prop_for_crtc() more reliable

Tomi Valkeinen <tomi.valkeinen@ti.com>
    drm: add missing drm_mode_set_crtcinfo call

Chris Wilson <chris@chris-wilson.co.uk>
    drm/i915: Update ifdeffery for mutex->owner

Ville Syrjälä <ville.syrjala@linux.intel.com>
    drm/i915: Refresh cached DP port register value on resume

Lyude <cpaul@redhat.com>
    drm/i915/fbc: Disable on HSW by default for now

Lyude <cpaul@redhat.com>
    drm/i915/ilk: Don't disable SSC source if it's in use

Ben Skeggs <bskeggs@redhat.com>
    drm/nouveau/disp/sor/gf119: select correct sor when poking training pattern

Dmitrii Tcvetkov <demfloro@demfloro.ru>
    drm/nouveau: fix for disabled fbdev emulation

Ben Skeggs <bskeggs@redhat.com>
    drm/nouveau/disp/sor/gm107: training pattern registers are like gm200

Ben Skeggs <bskeggs@redhat.com>
    drm/nouveau/fbcon: fix out-of-bounds memory accesses

Ben Skeggs <bskeggs@redhat.com>
    drm/nouveau/ltc/gm107-: fix typo in the address of NV_PLTCG_LTC0_LTS0_INTR

Ben Skeggs <bskeggs@redhat.com>
    drm/nouveau/gr/gf100-: update sm error decoding from gk20a nvgpu headers

Ben Skeggs <bskeggs@redhat.com>
    drm/nouveau/disp/sor/gf119: both links use the same training register

Ben Skeggs <bskeggs@redhat.com>
    drm/nouveau/bios/disp: fix handling of "match any protocol" entries

Michael S. Tsirkin <mst@redhat.com>
    virtio_balloon: fix PFN format for virtio-1

Andrey Grodzovsky <Andrey.Grodzovsky@amd.com>
    drm/dp/mst: Always clear proposed vcpi table for port.

Oded Gabbay <oded.gabbay@gmail.com>
    drm/amdkfd: destroy dbgmgr in notifier release

Oded Gabbay <oded.gabbay@gmail.com>
    drm/amdkfd: unbind only existing processes

Richard Weinberger <richard@nod.at>
    ubi: Make recover_peb power cut aware

Nicolas Iooss <nicolas.iooss_linux@m4x.org>
    drm/amdgpu: initialize amdgpu_cgs_acpi_eval_object result value

Alex Deucher <alexander.deucher@amd.com>
    drm/amdgpu: fix num_rbs exposed to userspace (v2)

Alex Deucher <alexander.deucher@amd.com>
    drm/amdgpu/gfx7: fix broken condition check

Alex Deucher <alexander.deucher@amd.com>
    drm/radeon: fix asic initialization for virtualized environments

Jeff Mahoney <jeffm@suse.com>
    btrfs: account for non-CoW'd blocks in btrfs_abort_transaction

Tejun Heo <tj@kernel.org>
    percpu: fix synchronization between synchronous map extension and chunk destruction

Tejun Heo <tj@kernel.org>
    percpu: fix synchronization between chunk->map_extend_work and chunk destruction

Miklos Szeredi <mszeredi@redhat.com>
    af_unix: fix hard linked sockets on overlay

Miklos Szeredi <mszeredi@redhat.com>
    vfs: add d_real_inode() helper

James Morse <james.morse@arm.com>
    arm64: kernel: Save and restore UAO and addr_limit on exception entry

Shaokun Zhang <zhangshaokun@hisilicon.com>
    arm64: mm: remove page_mapping check in __sync_icache_dcache

Mark Rutland <mark.rutland@arm.com>
    arm64: fix dump_instr when PAN and UAO are in use

Robin Murphy <robin.murphy@arm.com>
    drm/nouveau/Revert "drm/nouveau/device/pci: set as non-CPU-coherent on ARM64"

Junichi Nomura <j-nomura@ce.jp.nec.com>
    ipmi: Remove smi_msg from waiting_rcv_msgs list before handle_one_recv_msg()

Stefan Agner <stefan@agner.ch>
    drm/fsl-dcu: use flat regmap cache

Mathieu Larouche <mathieu.larouche@matrox.com>
    drm/mgag200: Black screen fix for G200e rev 4

Vegard Nossum <vegard.nossum@oracle.com>
    apparmor: fix oops, validate buffer size in apparmor_setprocattr()

Joerg Roedel <jroedel@suse.de>
    iommu/amd: Fix unity mapping initialization race

Joerg Roedel <jroedel@suse.de>
    iommu/vt-d: Enable QI on all IOMMUs before setting root entry

Jean-Philippe Brucker <jean-philippe.brucker@arm.com>
    iommu/arm-smmu: Wire up map_sg for arm-smmu-v3

John Keeping <john@metanate.com>
    iommu/rockchip: Fix zap cache during device attach

Jiri Slaby <jslaby@suse.cz>
    base: make module_create_drivers_dir race-free

Steven Rostedt (Red Hat) <rostedt@goodmis.org>
    tracing: Handle NULL formats in hold_module_trace_bprintk_format()

Allen Hung <allen_hung@dell.com>
    HID: multitouch: enable palm rejection for Windows Precision Touchpad

Allen Hung <allen_hung@dell.com>
    Revert "HID: multitouch: enable palm rejection if device implements confidence usage"

Scott Bauer <sbauer@plzdonthack.me>
    HID: hiddev: validate num_values for HIDIOCGUSAGES, HIDIOCSUSAGES commands

Oliver Neukum <oneukum@suse.com>
    HID: elo: kill not flush the work

Quentin Casasnovas <quentin.casasnovas@oracle.com>
    KVM: nVMX: VMX instructions: fix segment checks when L1 is in long mode.

James Morse <james.morse@arm.com>
    KVM: arm/arm64: Stop leaking vcpu pid references

Christian Borntraeger <borntraeger@de.ibm.com>
    KVM: s390/mm: Fix CMMA reset during reboot

Xiubo Li <lixiubo@cmss.chinamobile.com>
    kvm: Fix irq route entries exceeding KVM_MAX_IRQ_ROUTES

Yang Zhang <yang.zhang.wz@gmail.com>
    kvm: vmx: check apicv is active before using VT-d posted interrupt

Dan Carpenter <dan.carpenter@oracle.com>
    KEYS: potential uninitialized variable

Martin KaFai Lau <kafai@fb.com>
    ipv6: Fix mem leak in rt6i_pcpu

Bjørn Mork <bjorn@mork.no>
    cdc_ncm: workaround for EM7455 "silent" data interface

Haishuang Yan <yanhaishuang@cmss.chinamobile.com>
    geneve: fix max_mtu setting

Daniel Borkmann <daniel@iogearbox.net>
    macsec: set actual real device for xmit when !protect_frames

WANG Cong <xiyou.wangcong@gmail.com>
    net_sched: fix mirrored packets checksum

David S. Miller <davem@davemloft.net>
    packet: Use symmetric hash for PACKET_FANOUT_HASH.

Peter Zijlstra <peterz@infradead.org>
    sched/fair: Fix cfs_rq avg tracking underflow

Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
    UBIFS: Implement ->migratepage()

Richard Weinberger <richard@nod.at>
    mm: Export migrate_page_move_mapping and migrate_page_copy

Harvey Hunt <harvey.hunt@imgtec.com>
    irqchip/mips-gic: Fix IRQs in gic_dev_domain

James Hogan <james.hogan@imgtec.com>
    MIPS: KVM: Fix modular KVM under QEMU

Chen-Yu Tsai <wens@csie.org>
    ARM: dts: sun6i: primo81: Drop constraints on dc1sw regulator

Chen-Yu Tsai <wens@csie.org>
    ARM: dts: sun6i: yones-toptech-bs1078-v2: Drop constraints on dc1sw regulator

Steve Capper <steve.capper@arm.com>
    ARM: 8579/1: mm: Fix definition of pmd_mknotpresent

Will Deacon <will.deacon@arm.com>
    ARM: 8578/1: mm: ensure pmd_present only checks the valid bit

Fabio Estevam <fabio.estevam@nxp.com>
    ARM: imx6ul: Fix Micrel PHY mask

Srinivas Kandagatla <srinivas.kandagatla@linaro.org>
    regulator: qcom_smd: add regulator ops for pm8941 lnldo

Srinivas Kandagatla <srinivas.kandagatla@linaro.org>
    regulator: qcom_smd: add list_voltage callback

J. Bruce Fields <bfields@redhat.com>
    rpc: share one xps between all backchannels

J. Bruce Fields <bfields@redhat.com>
    SUNRPC: fix xprt leak on xps allocation failure

Trond Myklebust <trond.myklebust@primarydata.com>
    NFS: Fix another OPEN_DOWNGRADE bug

Al Viro <viro@ZenIV.linux.org.uk>
    make nfs_atomic_open() call d_drop() on all ->open_context() errors.

Trond Myklebust <trond.myklebust@primarydata.com>
    NFS: Fix a double page unlock

Weston Andros Adamson <dros@monkey.org>
    pnfs_nfs: fix _cancel_empty_pagelist

Ben Hutchings <ben@decadent.org.uk>
    nfsd: check permissions when setting ACLs

Andreas Gruenbacher <agruenba@redhat.com>
    posix_acl: Add set_posix_acl

Oleg Drokin <green@linuxhacker.ru>
    nfsd: Extend the mutex holding region around in nfsd4_process_open2()

Oleg Drokin <green@linuxhacker.ru>
    nfsd: Always lock state exclusively.

J. Bruce Fields <bfields@redhat.com>
    nfsd4/rpc: move backchannel create logic into rpc code

Martin K. Petersen <martin.petersen@oracle.com>
    sd: Fix rw_max for devices that report an optimal xfer size

Tejun Heo <tj@kernel.org>
    writeback: use higher precision calculation in domain_dirty_limits()

Lukasz Luba <lukasz.luba@arm.com>
    thermal: cpu_cooling: fix improper order during initialization

Andy Lutomirski <luto@kernel.org>
    uvc: Forward compat ioctls to their handlers directly

Larry Finger <Larry.Finger@lwfinger.net>
    rtlwifi: Fix scheduling while atomic error from commit 49f86ec21c01

Al Viro <viro@zeniv.linux.org.uk>
    autofs braino fix for do_last()

Johan Hovold <johan@kernel.org>
    Revert "gpiolib: Split GPIO flags parsing and GPIO configuration"

Colin Pitrat <colin.pitrat@gmail.com>
    gpio: sch: Fix Oops on module load on Asus Eee PC 1201

Linus Walleij <linus.walleij@linaro.org>
    gpio: make library immune to error pointers

Roger Quadros <rogerq@ti.com>
    extcon: palmas: Fix boot up state of VBUS when using GPIO detection

Josh Poimboeuf <jpoimboe@redhat.com>
    perf/x86: Fix 32-bit perf user callgraph collection

Borislav Petkov <bp@suse.de>
    x86/amd_nb: Fix boot crash on non-AMD systems

Vincent Stehlé <vincent.stehle@intel.com>
    perf/x86/intel/rapl: Fix pmus free during cleanup

Masami Hiramatsu <mhiramat@kernel.org>
    kprobes/x86: Clear TF bit in fault on single-stepping

H. Peter Anvin <hpa@zytor.com>
    x86, build: copy ldlinux.c32 to image.iso

Catalin Marinas <catalin.marinas@arm.com>
    cpuidle: Do not access cpuidle_devices when !CONFIG_CPU_IDLE

Paolo Bonzini <pbonzini@redhat.com>
    locking/static_key: Fix concurrent static_key_slow_inc()

Peter Zijlstra <peterz@infradead.org>
    locking/qspinlock: Fix spin_unlock_wait() some more

Chris Wilson <chris@chris-wilson.co.uk>
    locking/ww_mutex: Report recursive ww_mutex locking early

Dr. David Alan Gilbert <dgilbert@redhat.com>
    x86/msr: Use the proper trace point conditional for writes

Sergei Shtylyov <sergei.shtylyov@cogentembedded.com>
    of: irq: fix of_irq_get[_byname]() kernel-doc

Wolfram Sang <wsa@the-dreams.de>
    of: fix autoloading due to broken modalias with no 'compatible'

Eric W. Biederman <ebiederm@xmission.com>
    mnt: If fs_fully_visible fails call put_filesystem.

Eric W. Biederman <ebiederm@xmission.com>
    mnt: Account for MS_RDONLY in fs_fully_visible

Eric W. Biederman <ebiederm@xmission.com>
    mnt: fs_fully_visible test the proper mount for MNT_LOCKED

Oscar <oscar@naiandei.net>
    usb: common: otg-fsm: add license to usb-otg-fsm

Alan Stern <stern@rowland.harvard.edu>
    USB: don't free bandwidth_mutex too early

Alan Stern <stern@rowland.harvard.edu>
    USB: EHCI: declare hostpc register as zero-length array

Arnd Bergmann <arnd@arndb.de>
    usb: dwc2: fix regression on big-endian PowerPC/ARM systems

Cyril Bur <cyrilbur@gmail.com>
    powerpc/tm: Always reclaim in start_thread() for exec() class syscalls

Michael Ellerman <mpe@ellerman.id.au>
    powerpc/pseries: Fix IBM_ARCH_VEC_NRCORES_OFFSET since POWER8NVL was added

Gavin Shan <gwshan@linux.vnet.ibm.com>
    powerpc/pseries: Fix PCI config address for DDW

Guilherme G. Piccoli <gpiccoli@linux.vnet.ibm.com>
    powerpc/iommu: Remove the dependency on EEH struct in DDW mechanism

Jason Gunthorpe <jgunthorpe@obsidianresearch.com>
    IB/mlx4: Properly initialize GRH TClass and FlowLabel in AHs

Mike Marciniszyn <mike.marciniszyn@intel.com>
    IB/rdmavt: Correct qp_priv_alloc() return value test

Bart Van Assche <bart.vanassche@sandisk.com>
    IB/cm: Fix a recently introduced locking bug

Max Gurtovoy <maxg@mellanox.com>
    IB/core: Fix bit curruption in ib_device_cap_flags structure

Mel Gorman <mgorman@suse.de>
    futex: Calculate the futex key based on a tail page for file-based futexes

Tony Luck <tony.luck@intel.com>
    EDAC, sb_edac: Fix rank lookup on Broadwell

Nicholas Krause <xerofoify@gmail.com>
    EDAC: Fix workqueues poll period resetting

Felix Fietkau <nbd@nbd.name>
    cfg80211: fix proto in ieee80211_data_to_8023 for frames without LLC header

Jouni Malinen <j@w1.fi>
    mac80211: Fix mesh estab_plinks counting in STA removal case

Martin Willi <martin@strongswan.org>
    mac80211_hwsim: Add missing check for HWSIM_ATTR_SIGNAL

Bob Copeland <me@bobcopeland.com>
    mac80211: mesh: flush mesh paths unconditionally

Felix Fietkau <nbd@nbd.name>
    mac80211: fix fast_tx header alignment

Johannes Berg <johannes.berg@intel.com>
    cfg80211: remove get/set antenna and tx power warnings


-------------

Diffstat:

 .../ABI/testing/sysfs-bus-iio-proximity-as3935     |  2 +-
 Documentation/scsi/scsi_eh.txt                     |  8 ++-
 Makefile                                           |  4 +-
 arch/arm/boot/dts/armada-385-linksys.dtsi          |  4 +-
 arch/arm/boot/dts/sun5i-r8-chip.dts                |  2 +-
 arch/arm/boot/dts/sun6i-a31s-primo81.dts           |  2 -
 .../dts/sun6i-a31s-yones-toptech-bs1078-v2.dts     |  2 -
 arch/arm/include/asm/pgtable-2level.h              |  1 +
 arch/arm/include/asm/pgtable-3level.h              |  5 +-
 arch/arm/include/asm/pgtable.h                     |  1 -
 arch/arm/kvm/arm.c                                 |  1 +
 arch/arm/mach-imx/mach-imx6ul.c                    |  2 +-
 arch/arm/mach-mvebu/coherency.c                    | 22 +++---
 arch/arm64/include/asm/ptrace.h                    |  2 +
 arch/arm64/kernel/asm-offsets.c                    |  1 +
 arch/arm64/kernel/entry.S                          | 19 ++++-
 arch/arm64/kernel/traps.c                          | 26 +++----
 arch/arm64/mm/fault.c                              |  3 +-
 arch/arm64/mm/flush.c                              |  4 --
 arch/mips/include/asm/kvm_host.h                   |  1 +
 arch/mips/kvm/interrupt.h                          |  1 +
 arch/mips/kvm/locore.S                             |  1 +
 arch/mips/kvm/mips.c                               | 11 ++-
 arch/powerpc/kernel/process.c                      | 10 +++
 arch/powerpc/kernel/prom_init.c                    |  2 +-
 arch/powerpc/platforms/pseries/iommu.c             | 24 +++----
 arch/s390/include/asm/fpu/api.h                    |  2 +-
 arch/s390/kernel/ipl.c                             |  7 --
 arch/s390/mm/pgtable.c                             |  2 +-
 arch/x86/boot/Makefile                             |  3 +
 arch/x86/events/core.c                             | 11 +--
 arch/x86/events/intel/rapl.c                       |  2 +-
 arch/x86/include/asm/msr.h                         |  4 +-
 arch/x86/kernel/amd_nb.c                           |  4 +-
 arch/x86/kernel/kprobes/core.c                     | 12 ++++
 arch/x86/kvm/vmx.c                                 | 38 +++++-----
 crypto/rsa-pkcs1pad.c                              |  4 +-
 drivers/ata/libata-eh.c                            |  2 +-
 drivers/base/module.c                              |  8 ++-
 drivers/char/ipmi/ipmi_msghandler.c                |  8 ++-
 drivers/crypto/qat/qat_common/Makefile             |  1 +
 drivers/edac/edac_mc.c                             |  3 +-
 drivers/edac/sb_edac.c                             | 13 ++--
 drivers/extcon/extcon-palmas.c                     |  2 +
 drivers/gpio/gpio-sch.c                            | 21 +++---
 drivers/gpio/gpiolib-legacy.c                      |  8 +--
 drivers/gpio/gpiolib.c                             | 66 ++++++++----------
 drivers/gpu/drm/amd/amdgpu/amdgpu_cgs.c            |  2 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_kms.c            |  3 +-
 drivers/gpu/drm/amd/amdgpu/gfx_v7_0.c              |  2 +-
 drivers/gpu/drm/amd/amdkfd/kfd_process.c           | 70 +++++++++++--------
 .../gpu/drm/amd/powerplay/hwmgr/hardwaremanager.c  |  6 +-
 drivers/gpu/drm/amd/powerplay/hwmgr/pp_acpi.c      | 18 ++++-
 drivers/gpu/drm/amd/powerplay/hwmgr/tonga_hwmgr.c  |  2 +-
 .../amd/powerplay/hwmgr/tonga_processpptables.c    |  2 +-
 drivers/gpu/drm/amd/powerplay/inc/pp_acpi.h        |  1 +
 drivers/gpu/drm/atmel-hlcdc/atmel_hlcdc_plane.c    |  2 +
 drivers/gpu/drm/drm_atomic.c                       | 30 +++++++-
 drivers/gpu/drm/drm_crtc.c                         |  2 -
 drivers/gpu/drm/drm_dp_mst_topology.c              |  8 +--
 drivers/gpu/drm/drm_fb_cma_helper.c                |  2 +-
 drivers/gpu/drm/drm_gem_cma_helper.c               | 12 +---
 drivers/gpu/drm/drm_modes.c                        |  2 +
 drivers/gpu/drm/fsl-dcu/fsl_dcu_drm_drv.c          |  3 +-
 drivers/gpu/drm/i915/i915_gem_shrinker.c           |  2 +-
 drivers/gpu/drm/i915/intel_display.c               | 48 +++++++++----
 drivers/gpu/drm/i915/intel_dp.c                    | 11 ++-
 drivers/gpu/drm/i915/intel_dp_link_training.c      | 25 +------
 drivers/gpu/drm/i915/intel_drv.h                   |  2 -
 drivers/gpu/drm/i915/intel_fbc.c                   |  3 +-
 drivers/gpu/drm/mgag200/mgag200_mode.c             | 10 ++-
 .../drm/nouveau/include/nvkm/subdev/bios/disp.h    |  5 +-
 drivers/gpu/drm/nouveau/nouveau_fbcon.c            |  2 +
 drivers/gpu/drm/nouveau/nv04_fbcon.c               |  7 +-
 drivers/gpu/drm/nouveau/nv50_fbcon.c               |  6 +-
 drivers/gpu/drm/nouveau/nvc0_fbcon.c               |  6 +-
 drivers/gpu/drm/nouveau/nvkm/engine/device/pci.c   |  2 +-
 drivers/gpu/drm/nouveau/nvkm/engine/disp/Kbuild    |  1 +
 drivers/gpu/drm/nouveau/nvkm/engine/disp/gf119.c   | 13 ++--
 drivers/gpu/drm/nouveau/nvkm/engine/disp/gm107.c   |  2 +-
 drivers/gpu/drm/nouveau/nvkm/engine/disp/nv50.c    | 12 ++--
 drivers/gpu/drm/nouveau/nvkm/engine/disp/outpdp.h  |  9 ++-
 .../gpu/drm/nouveau/nvkm/engine/disp/sorgf119.c    |  6 +-
 .../gpu/drm/nouveau/nvkm/engine/disp/sorgm107.c    | 53 ++++++++++++++
 .../gpu/drm/nouveau/nvkm/engine/disp/sorgm200.c    | 15 +---
 drivers/gpu/drm/nouveau/nvkm/engine/gr/gf100.c     | 37 +++++++---
 drivers/gpu/drm/nouveau/nvkm/subdev/bios/disp.c    |  8 ++-
 drivers/gpu/drm/nouveau/nvkm/subdev/ltc/gm107.c    |  6 +-
 drivers/gpu/drm/nouveau/nvkm/subdev/ltc/gm200.c    |  2 +-
 drivers/gpu/drm/radeon/radeon_device.c             | 21 ++++++
 drivers/gpu/drm/ttm/ttm_bo.c                       |  7 +-
 drivers/gpu/drm/vmwgfx/vmwgfx_dmabuf.c             | 25 ++++++-
 drivers/gpu/drm/vmwgfx/vmwgfx_drv.c                | 12 ++++
 drivers/gpu/drm/vmwgfx/vmwgfx_drv.h                |  1 +
 drivers/gpu/drm/vmwgfx/vmwgfx_fb.c                 | 47 +++++++------
 drivers/gpu/drm/vmwgfx/vmwgfx_kms.c                | 10 +--
 drivers/gpu/drm/vmwgfx/vmwgfx_stdu.c               |  8 +--
 drivers/hid/hid-elo.c                              |  2 +-
 drivers/hid/hid-multitouch.c                       | 21 ++++--
 drivers/hid/usbhid/hiddev.c                        | 10 +--
 drivers/hwmon/dell-smm-hwmon.c                     | 80 +++++++++++++++-------
 drivers/iio/accel/kxsd9.c                          |  4 +-
 drivers/iio/adc/ad7266.c                           |  7 +-
 drivers/iio/humidity/hdc100x.c                     | 20 +++---
 drivers/iio/industrialio-trigger.c                 | 23 +++++--
 drivers/iio/light/apds9960.c                       |  1 +
 drivers/iio/pressure/st_pressure_core.c            | 80 ++++++++++++++--------
 drivers/iio/proximity/as3935.c                     | 17 +++--
 drivers/infiniband/core/cm.c                       |  4 +-
 drivers/infiniband/hw/mlx4/ah.c                    |  2 +-
 drivers/infiniband/sw/rdmavt/qp.c                  |  4 +-
 drivers/iommu/amd_iommu_init.c                     | 14 +++-
 drivers/iommu/arm-smmu-v3.c                        |  1 +
 drivers/iommu/intel-iommu.c                        | 17 +++--
 drivers/iommu/rockchip-iommu.c                     |  2 +-
 drivers/irqchip/irq-mips-gic.c                     | 12 +++-
 drivers/media/usb/uvc/uvc_v4l2.c                   | 39 +++++------
 drivers/memory/omap-gpmc.c                         |  2 +-
 drivers/mtd/ubi/eba.c                              | 22 ++++--
 drivers/net/geneve.c                               |  9 ++-
 drivers/net/macsec.c                               |  1 +
 drivers/net/usb/cdc_ncm.c                          |  7 ++
 drivers/net/wireless/mac80211_hwsim.c              |  1 +
 drivers/net/wireless/realtek/rtlwifi/core.c        |  6 +-
 drivers/of/irq.c                                   | 19 ++---
 drivers/pci/vc.c                                   |  4 +-
 drivers/regulator/qcom_smd-regulator.c             | 14 +++-
 drivers/scsi/53c700.c                              |  4 +-
 drivers/scsi/scsi_error.c                          |  4 +-
 drivers/scsi/sd.c                                  |  8 +--
 drivers/scsi/sd.h                                  |  5 ++
 drivers/staging/iio/accel/sca3000_core.c           |  2 +-
 drivers/thermal/cpu_cooling.c                      | 16 ++---
 drivers/tty/vt/keyboard.c                          | 30 +++-----
 drivers/tty/vt/vt.c                                |  1 +
 drivers/usb/common/usb-otg-fsm.c                   |  2 +
 drivers/usb/core/hcd.c                             | 17 ++---
 drivers/usb/dwc2/core.h                            | 27 ++++++++
 drivers/virtio/virtio_balloon.c                    | 20 +++---
 drivers/xen/balloon.c                              | 28 ++++----
 drivers/xen/xen-acpi-processor.c                   | 35 +---------
 fs/btrfs/ctree.c                                   |  5 +-
 fs/btrfs/extent-tree.c                             |  2 +-
 fs/btrfs/super.c                                   |  2 +-
 fs/btrfs/transaction.h                             |  2 +-
 fs/cifs/cifs_unicode.c                             | 33 +++++++--
 fs/cifs/cifs_unicode.h                             |  2 +
 fs/cifs/connect.c                                  |  4 +-
 fs/cifs/ntlmssp.h                                  |  2 +-
 fs/cifs/sess.c                                     | 76 +++++++++++---------
 fs/cifs/smb2pdu.c                                  | 37 +++++++---
 fs/namei.c                                         |  8 +--
 fs/namespace.c                                     | 10 ++-
 fs/nfs/dir.c                                       |  2 +-
 fs/nfs/nfs4proc.c                                  |  5 +-
 fs/nfs/pnfs_nfs.c                                  | 12 +++-
 fs/nfs/read.c                                      |  4 +-
 fs/nfsd/nfs2acl.c                                  | 20 +++---
 fs/nfsd/nfs3acl.c                                  | 16 ++---
 fs/nfsd/nfs4acl.c                                  | 16 ++---
 fs/nfsd/nfs4callback.c                             | 18 +----
 fs/nfsd/nfs4state.c                                | 50 ++++++++------
 fs/nfsd/state.h                                    |  2 +-
 fs/overlayfs/dir.c                                 | 54 +++++++--------
 fs/overlayfs/inode.c                               | 35 ++++++++--
 fs/overlayfs/overlayfs.h                           |  1 +
 fs/overlayfs/super.c                               | 21 +++---
 fs/posix_acl.c                                     | 42 +++++++-----
 fs/ubifs/file.c                                    | 24 +++++++
 include/asm-generic/qspinlock.h                    | 53 +++++---------
 include/drm/ttm/ttm_bo_api.h                       | 14 ++++
 include/linux/cpuidle.h                            |  3 +
 include/linux/dcache.h                             | 12 ++++
 include/linux/jump_label.h                         | 16 ++++-
 include/linux/skbuff.h                             | 20 ++++++
 include/linux/sunrpc/clnt.h                        |  2 -
 include/linux/sunrpc/svc_xprt.h                    |  1 +
 include/linux/sunrpc/xprt.h                        |  1 +
 include/linux/usb/ehci_def.h                       |  4 +-
 include/rdma/ib_verbs.h                            |  2 +-
 include/rdma/rdma_vt.h                             |  4 +-
 kernel/futex.c                                     | 14 +++-
 kernel/jump_label.c                                | 36 +++++++++-
 kernel/locking/mutex.c                             |  9 ++-
 kernel/locking/qspinlock.c                         | 60 ++++++++++++++++
 kernel/sched/fair.c                                | 33 ++++++---
 kernel/sched/idle.c                                |  2 +-
 kernel/trace/trace_printk.c                        |  7 +-
 mm/migrate.c                                       |  2 +
 mm/page-writeback.c                                | 21 +++---
 mm/percpu.c                                        | 73 ++++++++++++--------
 mm/shmem.c                                         |  8 ++-
 net/core/flow_dissector.c                          | 43 ++++++++++++
 net/core/skbuff.c                                  | 18 -----
 net/ipv6/ip6_fib.c                                 |  1 +
 net/mac80211/mesh.c                                | 11 ++-
 net/mac80211/sta_info.h                            |  2 +-
 net/packet/af_packet.c                             |  2 +-
 net/sched/act_mirred.c                             |  2 +-
 net/sunrpc/clnt.c                                  | 31 +++++++--
 net/sunrpc/svc_xprt.c                              |  2 +
 net/sunrpc/xprtsock.c                              |  1 +
 net/unix/af_unix.c                                 |  6 +-
 net/wireless/core.c                                |  2 -
 net/wireless/util.c                                |  2 +-
 scripts/mod/file2alias.c                           |  2 +-
 security/apparmor/lsm.c                            | 36 +++++-----
 security/keys/key.c                                |  2 +-
 sound/core/control.c                               |  2 +
 sound/core/pcm.c                                   | 14 ++--
 sound/core/timer.c                                 |  2 +-
 sound/drivers/dummy.c                              |  1 +
 sound/hda/hdac_regmap.c                            |  4 +-
 sound/pci/au88x0/au88x0_core.c                     |  5 +-
 sound/pci/echoaudio/echoaudio.c                    |  4 +-
 sound/pci/hda/hda_generic.c                        |  2 +
 sound/pci/hda/hda_intel.c                          | 12 +++-
 sound/pci/hda/patch_realtek.c                      | 22 +++++-
 sound/usb/card.c                                   |  2 +-
 virt/kvm/kvm_main.c                                |  2 +-
 220 files changed, 1755 insertions(+), 999 deletions(-)

[toc] | [next] | [standalone]


#1450169 — [PATCH 4.6 017/203] powerpc/tm: Always reclaim in start_thread() for exec() class syscalls

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:40 +0200
Subject[PATCH 4.6 017/203] powerpc/tm: Always reclaim in start_thread() for exec() class syscalls
Message-ID<rYWHv-2cA-9@gated-at.bofh.it>
In reply to#1450166
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cyril Bur <cyrilbur@gmail.com>

commit 8e96a87c5431c256feb65bcfc5aec92d9f7839b6 upstream.

Userspace can quite legitimately perform an exec() syscall with a
suspended transaction. exec() does not return to the old process, rather
it load a new one and starts that, the expectation therefore is that the
new process starts not in a transaction. Currently exec() is not treated
any differently to any other syscall which creates problems.

Firstly it could allow a new process to start with a suspended
transaction for a binary that no longer exists. This means that the
checkpointed state won't be valid and if the suspended transaction were
ever to be resumed and subsequently aborted (a possibility which is
exceedingly likely as exec()ing will likely doom the transaction) the
new process will jump to invalid state.

Secondly the incorrect attempt to keep the transactional state while
still zeroing state for the new process creates at least two TM Bad
Things. The first triggers on the rfid to return to userspace as
start_thread() has given the new process a 'clean' MSR but the suspend
will still be set in the hardware MSR. The second TM Bad Thing triggers
in __switch_to() as the processor is still transactionally suspended but
__switch_to() wants to zero the TM sprs for the new process.

This is an example of the outcome of calling exec() with a suspended
transaction. Note the first 700 is likely the first TM bad thing
decsribed earlier only the kernel can't report it as we've loaded
userspace registers. c000000000009980 is the rfid in
fast_exception_return()

  Bad kernel stack pointer 3fffcfa1a370 at c000000000009980
  Oops: Bad kernel stack pointer, sig: 6 [#1]
  CPU: 0 PID: 2006 Comm: tm-execed Not tainted
  NIP: c000000000009980 LR: 0000000000000000 CTR: 0000000000000000
  REGS: c00000003ffefd40 TRAP: 0700   Not tainted
  MSR: 8000000300201031 <SF,ME,IR,DR,LE,TM[SE]>  CR: 00000000  XER: 00000000
  CFAR: c0000000000098b4 SOFTE: 0
  PACATMSCRATCH: b00000010000d033
  GPR00: 0000000000000000 00003fffcfa1a370 0000000000000000 0000000000000000
  GPR04: 0000000000000000 0000000000000000 0000000000000000 0000000000000000
  GPR08: 0000000000000000 0000000000000000 0000000000000000 0000000000000000
  GPR12: 00003fff966611c0 0000000000000000 0000000000000000 0000000000000000
  NIP [c000000000009980] fast_exception_return+0xb0/0xb8
  LR [0000000000000000]           (null)
  Call Trace:
  Instruction dump:
  f84d0278 e9a100d8 7c7b03a6 e84101a0 7c4ff120 e8410170 7c5a03a6 e8010070
  e8410080 e8610088 e8810090 e8210078 <4c000024> 48000000 e8610178 88ed023b

  Kernel BUG at c000000000043e80 [verbose debug info unavailable]
  Unexpected TM Bad Thing exception at c000000000043e80 (msr 0x201033)
  Oops: Unrecoverable exception, sig: 6 [#2]
  CPU: 0 PID: 2006 Comm: tm-execed Tainted: G      D
  task: c0000000fbea6d80 ti: c00000003ffec000 task.ti: c0000000fb7ec000
  NIP: c000000000043e80 LR: c000000000015a24 CTR: 0000000000000000
  REGS: c00000003ffef7e0 TRAP: 0700   Tainted: G      D
  MSR: 8000000300201033 <SF,ME,IR,DR,RI,LE,TM[SE]>  CR: 28002828  XER: 00000000
  CFAR: c000000000015a20 SOFTE: 0
  PACATMSCRATCH: b00000010000d033
  GPR00: 0000000000000000 c00000003ffefa60 c000000000db5500 c0000000fbead000
  GPR04: 8000000300001033 2222222222222222 2222222222222222 00000000ff160000
  GPR08: 0000000000000000 800000010000d033 c0000000fb7e3ea0 c00000000fe00004
  GPR12: 0000000000002200 c00000000fe00000 0000000000000000 0000000000000000
  GPR16: 0000000000000000 0000000000000000 0000000000000000 0000000000000000
  GPR20: 0000000000000000 0000000000000000 c0000000fbea7410 00000000ff160000
  GPR24: c0000000ffe1f600 c0000000fbea8700 c0000000fbea8700 c0000000fbead000
  GPR28: c000000000e20198 c0000000fbea6d80 c0000000fbeab680 c0000000fbea6d80
  NIP [c000000000043e80] tm_restore_sprs+0xc/0x1c
  LR [c000000000015a24] __switch_to+0x1f4/0x420
  Call Trace:
  Instruction dump:
  7c800164 4e800020 7c0022a6 f80304a8 7c0222a6 f80304b0 7c0122a6 f80304b8
  4e800020 e80304a8 7c0023a6 e80304b0 <7c0223a6> e80304b8 7c0123a6 4e800020

This fixes CVE-2016-5828.

Fixes: bc2a9408fa65 ("powerpc: Hook in new transactional memory code")
Signed-off-by: Cyril Bur <cyrilbur@gmail.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/powerpc/kernel/process.c |   10 ++++++++++
 1 file changed, 10 insertions(+)

--- a/arch/powerpc/kernel/process.c
+++ b/arch/powerpc/kernel/process.c
@@ -1501,6 +1501,16 @@ void start_thread(struct pt_regs *regs,
 		current->thread.regs = regs - 1;
 	}
 
+#ifdef CONFIG_PPC_TRANSACTIONAL_MEM
+	/*
+	 * Clear any transactional state, we're exec()ing. The cause is
+	 * not important as there will never be a recheckpoint so it's not
+	 * user visible.
+	 */
+	if (MSR_TM_SUSPENDED(mfmsr()))
+		tm_reclaim_current(0);
+#endif
+
 	memset(regs->gpr, 0, sizeof(regs->gpr));
 	regs->ctr = 0;
 	regs->link = 0;

[toc] | [prev] | [next] | [standalone]


#1450176 — [PATCH 4.6 014/203] powerpc/iommu: Remove the dependency on EEH struct in DDW mechanism

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:40 +0200
Subject[PATCH 4.6 014/203] powerpc/iommu: Remove the dependency on EEH struct in DDW mechanism
Message-ID<rYWHw-2cA-23@gated-at.bofh.it>
In reply to#1450166
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guilherme G. Piccoli <gpiccoli@linux.vnet.ibm.com>

commit 8445a87f7092bc8336ea1305be9306f26b846d93 upstream.

Commit 39baadbf36ce ("powerpc/eeh: Remove eeh information from pci_dn")
changed the pci_dn struct by removing its EEH-related members.
As part of this clean-up, DDW mechanism was modified to read the device
configuration address from eeh_dev struct.

As a consequence, now if we disable EEH mechanism on kernel command-line
for example, the DDW mechanism will fail, generating a kernel oops by
dereferencing a NULL pointer (which turns to be the eeh_dev pointer).

This patch just changes the configuration address calculation on DDW
functions to a manual calculation based on pci_dn members instead of
using eeh_dev-based address.

No functional changes were made. This was tested on pSeries, both
in PHyp and qemu guest.

Fixes: 39baadbf36ce ("powerpc/eeh: Remove eeh information from pci_dn")
Reviewed-by: Gavin Shan <gwshan@linux.vnet.ibm.com>
Signed-off-by: Guilherme G. Piccoli <gpiccoli@linux.vnet.ibm.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/powerpc/platforms/pseries/iommu.c |   24 ++++++++++++------------
 1 file changed, 12 insertions(+), 12 deletions(-)

--- a/arch/powerpc/platforms/pseries/iommu.c
+++ b/arch/powerpc/platforms/pseries/iommu.c
@@ -912,7 +912,8 @@ machine_arch_initcall(pseries, find_exis
 static int query_ddw(struct pci_dev *dev, const u32 *ddw_avail,
 			struct ddw_query_response *query)
 {
-	struct eeh_dev *edev;
+	struct device_node *dn;
+	struct pci_dn *pdn;
 	u32 cfg_addr;
 	u64 buid;
 	int ret;
@@ -923,11 +924,10 @@ static int query_ddw(struct pci_dev *dev
 	 * Retrieve them from the pci device, not the node with the
 	 * dma-window property
 	 */
-	edev = pci_dev_to_eeh_dev(dev);
-	cfg_addr = edev->config_addr;
-	if (edev->pe_config_addr)
-		cfg_addr = edev->pe_config_addr;
-	buid = edev->phb->buid;
+	dn = pci_device_to_OF_node(dev);
+	pdn = PCI_DN(dn);
+	buid = pdn->phb->buid;
+	cfg_addr = (pdn->busno << 8) | pdn->devfn;
 
 	ret = rtas_call(ddw_avail[0], 3, 5, (u32 *)query,
 		  cfg_addr, BUID_HI(buid), BUID_LO(buid));
@@ -941,7 +941,8 @@ static int create_ddw(struct pci_dev *de
 			struct ddw_create_response *create, int page_shift,
 			int window_shift)
 {
-	struct eeh_dev *edev;
+	struct device_node *dn;
+	struct pci_dn *pdn;
 	u32 cfg_addr;
 	u64 buid;
 	int ret;
@@ -952,11 +953,10 @@ static int create_ddw(struct pci_dev *de
 	 * Retrieve them from the pci device, not the node with the
 	 * dma-window property
 	 */
-	edev = pci_dev_to_eeh_dev(dev);
-	cfg_addr = edev->config_addr;
-	if (edev->pe_config_addr)
-		cfg_addr = edev->pe_config_addr;
-	buid = edev->phb->buid;
+	dn = pci_device_to_OF_node(dev);
+	pdn = PCI_DN(dn);
+	buid = pdn->phb->buid;
+	cfg_addr = (pdn->busno << 8) | pdn->devfn;
 
 	do {
 		/* extra outputs are LIOBN and dma-addr (hi, lo) */

[toc] | [prev] | [next] | [standalone]


#1450178 — [PATCH 4.6 023/203] mnt: Account for MS_RDONLY in fs_fully_visible

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:40 +0200
Subject[PATCH 4.6 023/203] mnt: Account for MS_RDONLY in fs_fully_visible
Message-ID<rYWHw-2cA-13@gated-at.bofh.it>
In reply to#1450166
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric W. Biederman <ebiederm@xmission.com>

commit 695e9df010e40f407f4830dc11d53dce957710ba upstream.

In rare cases it is possible for s_flags & MS_RDONLY to be set but
MNT_READONLY to be clear.  This starting combination can cause
fs_fully_visible to fail to ensure that the new mount is readonly.
Therefore force MNT_LOCK_READONLY in the new mount if MS_RDONLY
is set on the source filesystem of the mount.

In general both MS_RDONLY and MNT_READONLY are set at the same for
mounts so I don't expect any programs to care.  Nor do I expect
MS_RDONLY to be set on proc or sysfs in the initial user namespace,
which further decreases the likelyhood of problems.

Which means this change should only affect system configurations by
paranoid sysadmins who should welcome the additional protection
as it keeps people from wriggling out of their policies.

Fixes: 8c6cf9cc829f ("mnt: Modify fs_fully_visible to deal with locked ro nodev and atime")
Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 fs/namespace.c |    4 ++++
 1 file changed, 4 insertions(+)

--- a/fs/namespace.c
+++ b/fs/namespace.c
@@ -3245,6 +3245,10 @@ static bool fs_fully_visible(struct file
 		if (mnt->mnt.mnt_sb->s_iflags & SB_I_NOEXEC)
 			mnt_flags &= ~(MNT_LOCK_NOSUID | MNT_LOCK_NOEXEC);
 
+		/* Don't miss readonly hidden in the superblock flags */
+		if (mnt->mnt.mnt_sb->s_flags & MS_RDONLY)
+			mnt_flags |= MNT_LOCK_READONLY;
+
 		/* Verify the mount flags are equal to or more permissive
 		 * than the proposed new mount.
 		 */

[toc] | [prev] | [next] | [standalone]


#1450179 — [PATCH 4.6 022/203] mnt: fs_fully_visible test the proper mount for MNT_LOCKED

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:40 +0200
Subject[PATCH 4.6 022/203] mnt: fs_fully_visible test the proper mount for MNT_LOCKED
Message-ID<rYWHw-2cA-27@gated-at.bofh.it>
In reply to#1450166
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric W. Biederman <ebiederm@xmission.com>

commit d71ed6c930ac7d8f88f3cef6624a7e826392d61f upstream.

MNT_LOCKED implies on a child mount implies the child is locked to the
parent.  So while looping through the children the children should be
tested (not their parent).

Typically an unshare of a mount namespace locks all mounts together
making both the parent and the slave as locked but there are a few
corner cases where other things work.

Fixes: ceeb0e5d39fc ("vfs: Ignore unlocked mounts in fs_fully_visible")
Reported-by: Seth Forshee <seth.forshee@canonical.com>
Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 fs/namespace.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/fs/namespace.c
+++ b/fs/namespace.c
@@ -3271,7 +3271,7 @@ static bool fs_fully_visible(struct file
 		list_for_each_entry(child, &mnt->mnt_mounts, mnt_child) {
 			struct inode *inode = child->mnt_mountpoint->d_inode;
 			/* Only worry about locked mounts */
-			if (!(mnt_flags & MNT_LOCKED))
+			if (!(child->mnt.mnt_flags & MNT_LOCKED))
 				continue;
 			/* Is the directory permanetly empty? */
 			if (!is_empty_dir_inode(inode))

[toc] | [prev] | [next] | [standalone]


#1450180 — [PATCH 4.6 010/203] IB/core: Fix bit curruption in ib_device_cap_flags structure

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:40 +0200
Subject[PATCH 4.6 010/203] IB/core: Fix bit curruption in ib_device_cap_flags structure
Message-ID<rYWHw-2cA-19@gated-at.bofh.it>
In reply to#1450166
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Max Gurtovoy <maxg@mellanox.com>

commit 47355b3cd7d3c9c5226bff7c449b9d269fb17fa6 upstream.

ib_device_cap_flags 64-bit expansion caused caps overlapping
and made consumers read wrong device capabilities. For example
IB_DEVICE_SG_GAPS_REG was falsely read by the iser driver causing
it to use a non-existing capability. This happened because signed
int becomes sign extended when converted it to u64. Fix this by
casting IB_DEVICE_ON_DEMAND_PAGING enumeration to ULL.

Fixes: f5aa9159a418 ('IB/core: Add arbitrary sg_list support')
Reported-by: Robert LeBlanc <robert@leblancnet.us>
Acked-by: Sagi Grimberg <sagi@grimberg.me>
Signed-off-by: Max Gurtovoy <maxg@mellanox.com>
Signed-off-by: Matan Barak <matanb@mellanox.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Doug Ledford <dledford@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 include/rdma/ib_verbs.h |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/include/rdma/ib_verbs.h
+++ b/include/rdma/ib_verbs.h
@@ -217,7 +217,7 @@ enum ib_device_cap_flags {
 	IB_DEVICE_CROSS_CHANNEL		= (1 << 27),
 	IB_DEVICE_MANAGED_FLOW_STEERING		= (1 << 29),
 	IB_DEVICE_SIGNATURE_HANDOVER		= (1 << 30),
-	IB_DEVICE_ON_DEMAND_PAGING		= (1 << 31),
+	IB_DEVICE_ON_DEMAND_PAGING		= (1ULL << 31),
 	IB_DEVICE_SG_GAPS_REG			= (1ULL << 32),
 	IB_DEVICE_VIRTUAL_FUNCTION		= ((u64)1 << 33),
 };

[toc] | [prev] | [next] | [standalone]


#1450181 — [PATCH 4.6 018/203] usb: dwc2: fix regression on big-endian PowerPC/ARM systems

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:40 +0200
Subject[PATCH 4.6 018/203] usb: dwc2: fix regression on big-endian PowerPC/ARM systems
Message-ID<rYWHw-2cA-37@gated-at.bofh.it>
In reply to#1450166
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnd Bergmann <arnd@arndb.de>

commit 23e3439296a55affce3ef0ab78f1c2e03aec8767 upstream.

A patch that went into Linux-4.4 to fix big-endian mode on a Lantiq
MIPS system unfortunately broke big-endian operation on PowerPC
APM82181 as reported by Christian Lamparter, and likely other
systems.

It actually introduced multiple issues:

- it broke big-endian ARM kernels: any machine that was working
  correctly with a little-endian kernel is no longer using byteswaps
  on big-endian kernels, which clearly breaks them.
- On PowerPC the same thing must be true: if it was working before,
  using big-endian kernels is now broken. Unlike ARM, 32-bit PowerPC
  usually uses big-endian kernels, so they are likely all broken.
- The barrier for dwc2_writel is on the wrong side of the __raw_writel(),
  so the MMIO no longer synchronizes with DMA operations.
- On architectures that require specific CPU instructions for MMIO
  access, using the __raw_ variant may turn this into a pointer
  dereference that does not have the same effect as the readl/writel.

This patch is a simple revert for all architectures other than MIPS,
in the hope that we can more easily backport it to fix the regression
on PowerPC and ARM systems without breaking the Lantiq system again.

We should follow this up with a more elaborate change to add runtime
detection of endianness, to make sure it also works on all other
combinations of architectures and implementations of the usb-dwc2
device. That patch however will be fairly large and not appropriate
for backports to stable kernels.

Felipe suggested a different approach, using an endianness switching
register to always put the device into LE mode, but unfortunately
the dwc2 hardware does not provide a generic way to do that. Also,
I see no practical way of addressing the problem more generally by
patching architecture specific code on MIPS.

Fixes: 95c8bc360944 ("usb: dwc2: Use platform endianness when accessing registers")
Acked-by: John Youn <johnyoun@synopsys.com>
Tested-by: Christian Lamparter <chunkeey@googlemail.com>
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/dwc2/core.h |   27 +++++++++++++++++++++++++++
 1 file changed, 27 insertions(+)

--- a/drivers/usb/dwc2/core.h
+++ b/drivers/usb/dwc2/core.h
@@ -64,6 +64,17 @@
 	DWC2_TRACE_SCHEDULER_VB(pr_fmt("%s: SCH: " fmt),		\
 				dev_name(hsotg->dev), ##__VA_ARGS__)
 
+#ifdef CONFIG_MIPS
+/*
+ * There are some MIPS machines that can run in either big-endian
+ * or little-endian mode and that use the dwc2 register without
+ * a byteswap in both ways.
+ * Unlike other architectures, MIPS apparently does not require a
+ * barrier before the __raw_writel() to synchronize with DMA but does
+ * require the barrier after the __raw_writel() to serialize a set of
+ * writes. This set of operations was added specifically for MIPS and
+ * should only be used there.
+ */
 static inline u32 dwc2_readl(const void __iomem *addr)
 {
 	u32 value = __raw_readl(addr);
@@ -90,6 +101,22 @@ static inline void dwc2_writel(u32 value
 	pr_info("INFO:: wrote %08x to %p\n", value, addr);
 #endif
 }
+#else
+/* Normal architectures just use readl/write */
+static inline u32 dwc2_readl(const void __iomem *addr)
+{
+	return readl(addr);
+}
+
+static inline void dwc2_writel(u32 value, void __iomem *addr)
+{
+	writel(value, addr);
+
+#ifdef DWC2_LOG_WRITES
+	pr_info("info:: wrote %08x to %p\n", value, addr);
+#endif
+}
+#endif
 
 /* Maximum number of Endpoints/HostChannels */
 #define MAX_EPS_CHANNELS	16

[toc] | [prev] | [next] | [standalone]


#1450185 — [PATCH 4.6 002/203] mac80211: fix fast_tx header alignment

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:40 +0200
Subject[PATCH 4.6 002/203] mac80211: fix fast_tx header alignment
Message-ID<rYWHx-2cA-59@gated-at.bofh.it>
In reply to#1450166
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Fietkau <nbd@nbd.name>

commit 6fe04128f158c5ad27e7504bfdf1b12e63331bc9 upstream.

The header field is defined as u8[] but also accessed as struct
ieee80211_hdr. Enforce an alignment of 2 to prevent unnecessary
unaligned accesses, which can be very harmful for performance on many
platforms.

Fixes: e495c24731a2 ("mac80211: extend fast-xmit for more ciphers")
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 net/mac80211/sta_info.h |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/net/mac80211/sta_info.h
+++ b/net/mac80211/sta_info.h
@@ -275,7 +275,7 @@ struct ieee80211_fast_tx {
 	u8 sa_offs, da_offs, pn_offs;
 	u8 band;
 	u8 hdr[30 + 2 + IEEE80211_FAST_XMIT_MAX_IV +
-	       sizeof(rfc1042_header)];
+	       sizeof(rfc1042_header)] __aligned(2);
 
 	struct rcu_head rcu_head;
 };

[toc] | [prev] | [next] | [standalone]


#1450186 — [PATCH 4.6 012/203] IB/rdmavt: Correct qp_priv_alloc() return value test

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:40 +0200
Subject[PATCH 4.6 012/203] IB/rdmavt: Correct qp_priv_alloc() return value test
Message-ID<rYWHx-2cA-61@gated-at.bofh.it>
In reply to#1450166
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mike Marciniszyn <mike.marciniszyn@intel.com>

commit c755f4afa66ad3ed98870bd3254f37c47fb2c800 upstream.

The current drivers return errors from this calldown
wrapped in an ERR_PTR().

The rdmavt code incorrectly tests for NULL.

The code is fixed to use IS_ERR() and change ret according
to the driver return value.

Reviewed-by: Dennis Dalessandro <dennis.dalessandro@intel.com>
Signed-off-by: Mike Marciniszyn <mike.marciniszyn@intel.com>
Signed-off-by: Dennis Dalessandro <dennis.dalessandro@intel.com>
Signed-off-by: Doug Ledford <dledford@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/infiniband/sw/rdmavt/qp.c |    4 +++-
 include/rdma/rdma_vt.h            |    4 +++-
 2 files changed, 6 insertions(+), 2 deletions(-)

--- a/drivers/infiniband/sw/rdmavt/qp.c
+++ b/drivers/infiniband/sw/rdmavt/qp.c
@@ -683,8 +683,10 @@ struct ib_qp *rvt_create_qp(struct ib_pd
 		 * initialization that is needed.
 		 */
 		priv = rdi->driver_f.qp_priv_alloc(rdi, qp, gfp);
-		if (!priv)
+		if (IS_ERR(priv)) {
+			ret = priv;
 			goto bail_qp;
+		}
 		qp->priv = priv;
 		qp->timeout_jiffies =
 			usecs_to_jiffies((4096UL * (1UL << qp->timeout)) /
--- a/include/rdma/rdma_vt.h
+++ b/include/rdma/rdma_vt.h
@@ -203,7 +203,9 @@ struct rvt_driver_provided {
 
 	/*
 	 * Allocate a private queue pair data structure for driver specific
-	 * information which is opaque to rdmavt.
+	 * information which is opaque to rdmavt.  Errors are returned via
+	 * ERR_PTR(err).  The driver is free to return NULL or a valid
+	 * pointer.
 	 */
 	void * (*qp_priv_alloc)(struct rvt_dev_info *rdi, struct rvt_qp *qp,
 				gfp_t gfp);

[toc] | [prev] | [next] | [standalone]


#1450187 — [PATCH 4.6 019/203] USB: EHCI: declare hostpc register as zero-length array

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:40 +0200
Subject[PATCH 4.6 019/203] USB: EHCI: declare hostpc register as zero-length array
Message-ID<rYWHw-2cA-47@gated-at.bofh.it>
In reply to#1450166
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alan Stern <stern@rowland.harvard.edu>

commit 7e8b3dfef16375dbfeb1f36a83eb9f27117c51fd upstream.

The HOSTPC extension registers found in some EHCI implementations form
a variable-length array, with one element for each port.  Therefore
the hostpc field in struct ehci_regs should be declared as a
zero-length array, not a single-element array.

This fixes a problem reported by UBSAN.

Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Reported-by: Wilfried Klaebe <linux-kernel@lebenslange-mailadresse.de>
Tested-by: Wilfried Klaebe <linux-kernel@lebenslange-mailadresse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 include/linux/usb/ehci_def.h |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/include/linux/usb/ehci_def.h
+++ b/include/linux/usb/ehci_def.h
@@ -180,11 +180,11 @@ struct ehci_regs {
  * PORTSCx
  */
 	/* HOSTPC: offset 0x84 */
-	u32		hostpc[1];	/* HOSTPC extension */
+	u32		hostpc[0];	/* HOSTPC extension */
 #define HOSTPC_PHCD	(1<<22)		/* Phy clock disable */
 #define HOSTPC_PSPD	(3<<25)		/* Port speed detection */
 
-	u32		reserved5[16];
+	u32		reserved5[17];
 
 	/* USBMODE_EX: offset 0xc8 */
 	u32		usbmode_ex;	/* USB Device mode extension */

[toc] | [prev] | [next] | [standalone]


#1450189 — [PATCH 4.6 013/203] IB/mlx4: Properly initialize GRH TClass and FlowLabel in AHs

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:40 +0200
Subject[PATCH 4.6 013/203] IB/mlx4: Properly initialize GRH TClass and FlowLabel in AHs
Message-ID<rYWHx-2cA-69@gated-at.bofh.it>
In reply to#1450166
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jason Gunthorpe <jgunthorpe@obsidianresearch.com>

commit 8c5122e45a10a9262f872b53f151a592e870f905 upstream.

When this code was reworked for IBoE support the order of assignments
for the sl_tclass_flowlabel got flipped around resulting in
TClass & FlowLabel being permanently set to 0 in the packet headers.

This breaks IB routers that rely on these headers, but only affects
kernel users - libmlx4 does this properly for user space.

Fixes: fa417f7b520e ("IB/mlx4: Add support for IBoE")
Signed-off-by: Jason Gunthorpe <jgunthorpe@obsidianresearch.com>
Signed-off-by: Doug Ledford <dledford@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/infiniband/hw/mlx4/ah.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/infiniband/hw/mlx4/ah.c
+++ b/drivers/infiniband/hw/mlx4/ah.c
@@ -47,6 +47,7 @@ static struct ib_ah *create_ib_ah(struct
 
 	ah->av.ib.port_pd = cpu_to_be32(to_mpd(pd)->pdn | (ah_attr->port_num << 24));
 	ah->av.ib.g_slid  = ah_attr->src_path_bits;
+	ah->av.ib.sl_tclass_flowlabel = cpu_to_be32(ah_attr->sl << 28);
 	if (ah_attr->ah_flags & IB_AH_GRH) {
 		ah->av.ib.g_slid   |= 0x80;
 		ah->av.ib.gid_index = ah_attr->grh.sgid_index;
@@ -64,7 +65,6 @@ static struct ib_ah *create_ib_ah(struct
 		       !(1 << ah->av.ib.stat_rate & dev->caps.stat_rate_support))
 			--ah->av.ib.stat_rate;
 	}
-	ah->av.ib.sl_tclass_flowlabel = cpu_to_be32(ah_attr->sl << 28);
 
 	return &ah->ibah;
 }

[toc] | [prev] | [next] | [standalone]


#1450199 — [PATCH 4.6 016/203] powerpc/pseries: Fix IBM_ARCH_VEC_NRCORES_OFFSET since POWER8NVL was added

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:40 +0200
Subject[PATCH 4.6 016/203] powerpc/pseries: Fix IBM_ARCH_VEC_NRCORES_OFFSET since POWER8NVL was added
Message-ID<rYWHx-2cA-91@gated-at.bofh.it>
In reply to#1450166
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Ellerman <mpe@ellerman.id.au>

commit 2c2a63e301fd19ccae673e79de59b30a232ff7f9 upstream.

The recent commit 7cc851039d64 ("powerpc/pseries: Add POWER8NVL support
to ibm,client-architecture-support call") added a new PVR mask & value
to the start of the ibm_architecture_vec[] array.

However it missed the fact that further down in the array, we hard code
the offset of one of the fields, and then at boot use that value to
patch the value in the array. This means every update to the array must
also update the #define, ugh.

This means that on pseries machines we will misreport to firmware the
number of cores we support, by a factor of threads_per_core.

Fix it for now by updating the #define.

Fixes: 7cc851039d64 ("powerpc/pseries: Add POWER8NVL support to ibm,client-architecture-support call")
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/powerpc/kernel/prom_init.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/powerpc/kernel/prom_init.c
+++ b/arch/powerpc/kernel/prom_init.c
@@ -719,7 +719,7 @@ unsigned char ibm_architecture_vec[] = {
 	 * must match by the macro below. Update the definition if
 	 * the structure layout changes.
 	 */
-#define IBM_ARCH_VEC_NRCORES_OFFSET	125
+#define IBM_ARCH_VEC_NRCORES_OFFSET	133
 	W(NR_CPUS),			/* number of cores supported */
 	0,
 	0,

[toc] | [prev] | [next] | [standalone]


#1450200 — [PATCH 4.6 025/203] of: fix autoloading due to broken modalias with no compatible

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:40 +0200
Subject[PATCH 4.6 025/203] of: fix autoloading due to broken modalias with no compatible
Message-ID<rYWHy-2cA-93@gated-at.bofh.it>
In reply to#1450166
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wolfram Sang <wsa@the-dreams.de>

commit b3c0a4dab7e35a9b6d69c0415641d2280fdefb2b upstream.

Because of an improper dereference, a stray 'C' character was output to
the modalias when no 'compatible' was specified. This is the case for
some old PowerMac drivers which only set the 'name' property. Fix it to
let them match again.

Reported-by: Mathieu Malaterre <malat@debian.org>
Signed-off-by: Wolfram Sang <wsa@the-dreams.de>
Tested-by: Mathieu Malaterre <malat@debian.org>
Cc: Philipp Zabel <p.zabel@pengutronix.de>
Cc: Andreas Schwab <schwab@linux-m68k.org>
Fixes: 6543becf26fff6 ("mod/file2alias: make modalias generation safe for cross compiling")
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 scripts/mod/file2alias.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/scripts/mod/file2alias.c
+++ b/scripts/mod/file2alias.c
@@ -384,7 +384,7 @@ static void do_of_entry_multi(void *symv
 	len = sprintf(alias, "of:N%sT%s", (*name)[0] ? *name : "*",
 		      (*type)[0] ? *type : "*");
 
-	if (compatible[0])
+	if ((*compatible)[0])
 		sprintf(&alias[len], "%sC%s", (*type)[0] ? "*" : "",
 			*compatible);
 

[toc] | [prev] | [next] | [standalone]


#1450201 — [PATCH 4.6 020/203] USB: dont free bandwidth_mutex too early

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:40 +0200
Subject[PATCH 4.6 020/203] USB: dont free bandwidth_mutex too early
Message-ID<rYWHy-2cA-95@gated-at.bofh.it>
In reply to#1450166
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alan Stern <stern@rowland.harvard.edu>

commit ab2a4bf83902c170d29ba130a8abb5f9d90559e1 upstream.

The USB core contains a bug that can show up when a USB-3 host
controller is removed.  If the primary (USB-2) hcd structure is
released before the shared (USB-3) hcd, the core will try to do a
double-free of the common bandwidth_mutex.

The problem was described in graphical form by Chung-Geol Kim, who
first reported it:

=================================================
     At *remove USB(3.0) Storage
     sequence <1> --> <5> ((Problem Case))
=================================================
                                  VOLD
------------------------------------|------------
                                 (uevent)
                            ________|_________
                           |<1>               |
                           |dwc3_otg_sm_work  |
                           |usb_put_hcd       |
                           |peer_hcd(kref=2)|
                           |__________________|
                            ________|_________
                           |<2>               |
                           |New USB BUS #2    |
                           |                  |
                           |peer_hcd(kref=1)  |
                           |                  |
                         --(Link)-bandXX_mutex|
                         | |__________________|
                         |
    ___________________  |
   |<3>                | |
   |dwc3_otg_sm_work   | |
   |usb_put_hcd        | |
   |primary_hcd(kref=1)| |
   |___________________| |
    _________|_________  |
   |<4>                | |
   |New USB BUS #1     | |
   |hcd_release        | |
   |primary_hcd(kref=0)| |
   |                   | |
   |bandXX_mutex(free) |<-
   |___________________|
                               (( VOLD ))
                            ______|___________
                           |<5>               |
                           |      SCSI        |
                           |usb_put_hcd       |
                           |peer_hcd(kref=0)  |
                           |*hcd_release      |
                           |bandXX_mutex(free*)|<- double free
                           |__________________|

=================================================

This happens because hcd_release() frees the bandwidth_mutex whenever
it sees a primary hcd being released (which is not a very good idea
in any case), but in the course of releasing the primary hcd, it
changes the pointers in the shared hcd in such a way that the shared
hcd will appear to be primary when it gets released.

This patch fixes the problem by changing hcd_release() so that it
deallocates the bandwidth_mutex only when the _last_ hcd structure
referencing it is released.  The patch also removes an unnecessary
test, so that when an hcd is released, both the shared_hcd and
primary_hcd pointers in the hcd's peer will be cleared.

Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Reported-by: Chung-Geol Kim <chunggeol.kim@samsung.com>
Tested-by: Chung-Geol Kim <chunggeol.kim@samsung.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/core/hcd.c |   17 +++++++----------
 1 file changed, 7 insertions(+), 10 deletions(-)

--- a/drivers/usb/core/hcd.c
+++ b/drivers/usb/core/hcd.c
@@ -2597,26 +2597,23 @@ EXPORT_SYMBOL_GPL(usb_create_hcd);
  * Don't deallocate the bandwidth_mutex until the last shared usb_hcd is
  * deallocated.
  *
- * Make sure to only deallocate the bandwidth_mutex when the primary HCD is
- * freed.  When hcd_release() is called for either hcd in a peer set
- * invalidate the peer's ->shared_hcd and ->primary_hcd pointers to
- * block new peering attempts
+ * Make sure to deallocate the bandwidth_mutex only when the last HCD is
+ * freed.  When hcd_release() is called for either hcd in a peer set,
+ * invalidate the peer's ->shared_hcd and ->primary_hcd pointers.
  */
 static void hcd_release(struct kref *kref)
 {
 	struct usb_hcd *hcd = container_of (kref, struct usb_hcd, kref);
 
 	mutex_lock(&usb_port_peer_mutex);
-	if (usb_hcd_is_primary_hcd(hcd)) {
-		kfree(hcd->address0_mutex);
-		kfree(hcd->bandwidth_mutex);
-	}
 	if (hcd->shared_hcd) {
 		struct usb_hcd *peer = hcd->shared_hcd;
 
 		peer->shared_hcd = NULL;
-		if (peer->primary_hcd == hcd)
-			peer->primary_hcd = NULL;
+		peer->primary_hcd = NULL;
+	} else {
+		kfree(hcd->address0_mutex);
+		kfree(hcd->bandwidth_mutex);
 	}
 	mutex_unlock(&usb_port_peer_mutex);
 	kfree(hcd);

[toc] | [prev] | [next] | [standalone]


#1450202 — [PATCH 4.6 015/203] powerpc/pseries: Fix PCI config address for DDW

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 00:40 +0200
Subject[PATCH 4.6 015/203] powerpc/pseries: Fix PCI config address for DDW
Message-ID<rYWHy-2cA-97@gated-at.bofh.it>
In reply to#1450166
4.6-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Gavin Shan <gwshan@linux.vnet.ibm.com>

commit 8a934efe94347eee843aeea65bdec8077a79e259 upstream.

In commit 8445a87f7092 "powerpc/iommu: Remove the dependency on EEH
struct in DDW mechanism", the PE address was replaced with the PCI
config address in order to remove dependency on EEH. According to PAPR
spec, firmware (pHyp or QEMU) should accept "xxBBSSxx" format PCI config
address, not "xxxxBBSS" provided by the patch. Note that "BB" is PCI bus
number and "SS" is the combination of slot and function number.

This fixes the PCI address passed to DDW RTAS calls.

Fixes: 8445a87f7092 ("powerpc/iommu: Remove the dependency on EEH struct in DDW mechanism")
Reported-by: Guilherme G. Piccoli <gpiccoli@linux.vnet.ibm.com>
Signed-off-by: Gavin Shan <gwshan@linux.vnet.ibm.com>
Tested-by: Guilherme G. Piccoli <gpiccoli@linux.vnet.ibm.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/powerpc/platforms/pseries/iommu.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/arch/powerpc/platforms/pseries/iommu.c
+++ b/arch/powerpc/platforms/pseries/iommu.c
@@ -927,7 +927,7 @@ static int query_ddw(struct pci_dev *dev
 	dn = pci_device_to_OF_node(dev);
 	pdn = PCI_DN(dn);
 	buid = pdn->phb->buid;
-	cfg_addr = (pdn->busno << 8) | pdn->devfn;
+	cfg_addr = ((pdn->busno << 16) | (pdn->devfn << 8));
 
 	ret = rtas_call(ddw_avail[0], 3, 5, (u32 *)query,
 		  cfg_addr, BUID_HI(buid), BUID_LO(buid));
@@ -956,7 +956,7 @@ static int create_ddw(struct pci_dev *de
 	dn = pci_device_to_OF_node(dev);
 	pdn = PCI_DN(dn);
 	buid = pdn->phb->buid;
-	cfg_addr = (pdn->busno << 8) | pdn->devfn;
+	cfg_addr = ((pdn->busno << 16) | (pdn->devfn << 8));
 
 	do {
 		/* extra outputs are LIOBN and dma-addr (hi, lo) */

[toc] | [prev] | [next] | [standalone]


#1450320

FromShuah Khan <shuah.kh@samsung.com>
Date2016-07-26 04:10 +0200
Message-ID<rYZYJ-4nC-5@gated-at.bofh.it>
In reply to#1450166
On 07/25/2016 02:53 PM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 4.6.5 release.
> There are 203 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Wed Jul 27 20:33:38 UTC 2016.
> Anything received after that time might be too late.
> 
> The whole patch series can be found in one patch at:
> 	kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.6.5-rc1.gz
> or in the git tree and branch at:
>   git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.6.y
> and the diffstat can be found below.
> 
Compiled and booted on my test system. No dmesg regressions,

thanks,
-- Shuah

[toc] | [prev] | [next] | [standalone]


#1450331

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 04:50 +0200
Message-ID<rZ0Br-4Hu-1@gated-at.bofh.it>
In reply to#1450320
On Mon, Jul 25, 2016 at 07:49:58PM -0600, Shuah Khan wrote:
> On 07/25/2016 02:53 PM, Greg Kroah-Hartman wrote:
> > This is the start of the stable review cycle for the 4.6.5 release.
> > There are 203 patches in this series, all will be posted as a response
> > to this one.  If anyone has any issues with these being applied, please
> > let me know.
> > 
> > Responses should be made by Wed Jul 27 20:33:38 UTC 2016.
> > Anything received after that time might be too late.
> > 
> > The whole patch series can be found in one patch at:
> > 	kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.6.5-rc1.gz
> > or in the git tree and branch at:
> >   git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.6.y
> > and the diffstat can be found below.
> > 
> Compiled and booted on my test system. No dmesg regressions,

Great, thanks for testing all of these and letting me know.

greg k-h

[toc] | [prev] | [next] | [standalone]


#1450608

FromGuenter Roeck <linux@roeck-us.net>
Date2016-07-26 16:00 +0200
Message-ID<rZb3Q-2Cx-19@gated-at.bofh.it>
In reply to#1450166
On 07/25/2016 01:53 PM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 4.6.5 release.
> There are 203 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Wed Jul 27 20:33:38 UTC 2016.
> Anything received after that time might be too late.
>

Build results:
	total: 148 pass: 146 fail: 2
Failed builds:
	unicore32:defconfig
	unicore32:allnoconfig

Qemu test results:
	total: 107 pass: 107 fail: 0

unicore32 is still not fixed in mainline.

Details are available at http://kerneltests.org/builders.

Guenter

[toc] | [prev] | [next] | [standalone]


#1450621

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-07-26 16:30 +0200
Message-ID<rZbwT-32n-63@gated-at.bofh.it>
In reply to#1450608
On Tue, Jul 26, 2016 at 06:53:48AM -0700, Guenter Roeck wrote:
> On 07/25/2016 01:53 PM, Greg Kroah-Hartman wrote:
> > This is the start of the stable review cycle for the 4.6.5 release.
> > There are 203 patches in this series, all will be posted as a response
> > to this one.  If anyone has any issues with these being applied, please
> > let me know.
> > 
> > Responses should be made by Wed Jul 27 20:33:38 UTC 2016.
> > Anything received after that time might be too late.
> > 
> 
> Build results:
> 	total: 148 pass: 146 fail: 2
> Failed builds:
> 	unicore32:defconfig
> 	unicore32:allnoconfig
> 
> Qemu test results:
> 	total: 107 pass: 107 fail: 0
> 
> unicore32 is still not fixed in mainline.

Does no one care about it?

Anyway, thanks for all of the testing results, much appreciated.

greg k-h

[toc] | [prev] | [next] | [standalone]


#1450657

FromGuenter Roeck <linux@roeck-us.net>
Date2016-07-26 17:50 +0200
Message-ID<rZcMi-3It-19@gated-at.bofh.it>
In reply to#1450621
On Tue, Jul 26, 2016 at 07:23:57AM -0700, Greg Kroah-Hartman wrote:
> On Tue, Jul 26, 2016 at 06:53:48AM -0700, Guenter Roeck wrote:
> > On 07/25/2016 01:53 PM, Greg Kroah-Hartman wrote:
> > > This is the start of the stable review cycle for the 4.6.5 release.
> > > There are 203 patches in this series, all will be posted as a response
> > > to this one.  If anyone has any issues with these being applied, please
> > > let me know.
> > > 
> > > Responses should be made by Wed Jul 27 20:33:38 UTC 2016.
> > > Anything received after that time might be too late.
> > > 
> > 
> > Build results:
> > 	total: 148 pass: 146 fail: 2
> > Failed builds:
> > 	unicore32:defconfig
> > 	unicore32:allnoconfig
> > 
> > Qemu test results:
> > 	total: 107 pass: 107 fail: 0
> > 
> > unicore32 is still not fixed in mainline.
> 
> Does no one care about it?
> 

Good question. The fix has been in -next for a while.

Guenter

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.kernel


csiph-web