Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1352081 > unrolled thread

[4.2.y-ckt stable] Linux 4.2.8-ckt5 stable review

Started byKamal Mostafa <kamal@canonical.com>
First post2016-03-08 00:00 +0100
Last post2016-03-08 02:00 +0100
Articles 20 on this page of 231 — 1 participant

Back to article view | Back to linux.kernel


Contents

  [4.2.y-ckt stable] Linux 4.2.8-ckt5 stable review Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:00 +0100
    [PATCH 4.2.y-ckt 034/273] libata: disable forced PORTS_IMPL for >= AHCI 1.3 Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:00 +0100
    [PATCH 4.2.y-ckt 264/273] net: phy: bcm7xxx: Fix shadow mode 2 disabling Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 259/273] ARM: dts: kirkwood: use unique machine name for ds112 Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 256/273] af_unix: Don't set err in unix_stream_read_generic unless there was an error Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 247/273] l2tp: Fix error creating L2TP tunnels Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 253/273] net/mlx4_core: Do not BUG_ON during reset when PCI is offline Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 262/273] [media] exynos4-is: fix a format string bug Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 249/273] route: check and remove route cache when we get route Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 269/273] net: phy: Fix phy_mac_interrupt() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 270/273] net: phy: Avoid polling PHY with PHY_IGNORE_INTERRUPTS Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 268/273] s390/oprofile: fix address range for asynchronous stack Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 271/273] net: phy: bcm7xxx: Fix 40nm EPHY features Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 255/273] batman-adv: Avoid endless loop in bat-on-bat netdevice check Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 267/273] net: phy: bcm7xxx: Fix bcm7xxx_config_init() check Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 238/273] net: Copy inner L3 and L4 headers as unaligned on GRE TEB Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 243/273] qmi_wwan: add "4G LTE usb-modem U901" Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 273/273] IB/IPoIB: Do not set skb truesize since using one linearskb Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 246/273] net/mlx4_en: Avoid changing dev->features directly in run-time Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 251/273] unix_diag: fix incorrect sign extension in unix_lookup_by_ino Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 250/273] rtnl: RTM_GETNETCONF: fix wrong return value Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 254/273] s390/perf_event: fix address range for asynchronous stack Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 266/273] bonding: don't use stale speed and duplex information Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 245/273] net/mlx4_en: Choose time-stamping shift value according to HW frequency Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 242/273] af_unix: Guard against other == sk in unix_dgram_sendmsg Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 239/273] bpf: fix branch offset adjustment on backjumps after patching ctx expansion Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 261/273] MAINTAINERS: Remove stale entry for BCM33xx chips Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 265/273] writeback: initialize inode members that track writeback history Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 257/273] netlink: not trim skb for mmaped socket when dump Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 248/273] pppoe: fix reference counting in PPPoE proxy Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 263/273] net/mlx4_core: Fix potential corruption in counters database Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 252/273] sctp: Fix port hash table size computation Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 260/273] s390/stacktrace: fix address ranges for asynchronous and panic stack Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 258/273] Input: xpad - remove unused function Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 272/273] netfilter: nfnetlink: correctly validate length of batch messages Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 244/273] net/mlx4_en: Count HW buffer overrun only once Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:10 +0100
    [PATCH 4.2.y-ckt 225/273] tipc: fix connection abort during subscription cancel Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
      Re: [PATCH 4.2.y-ckt 225/273] tipc: fix connection abort during  subscription cancel Kamal Mostafa <kamal@canonical.com> - 2016-03-10 19:00 +0100
    [PATCH 4.2.y-ckt 131/273] ALSA: timer: Fix race between stop and interrupt Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 222/273] af_unix: fix struct pid memory leak Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 240/273] bonding: Fix ARP monitor validation Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 223/273] pptp: fix illegal memory access caused by multiple bind()s Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 241/273] ipv4: fix memory leaks in ip_cmsg_send() callers Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 224/273] sctp: allow setting SCTP_SACK_IMMEDIATELY by the application Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 221/273] tcp: fix NULL deref in tcp_v4_send_ack() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 176/273] x86/mm: Fix vmalloc_fault() to handle large pages properly Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 172/273] x86/uaccess/64: Handle the caching of 4-byte nocache copies properly in __copy_user_nocache() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 232/273] ipv6: fix a lockdep splat Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 231/273] ipv6: addrconf: Fix recursive spin lock call Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 228/273] ipv6: enforce flowi6_oif usage in ip6_dst_lookup_tail() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 227/273] tcp: beware of alignments in tcp_get_info() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 229/273] ipv6/udp: use sticky pktinfo egress ifindex on connect() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 219/273] af_iucv: Validate socket address length in iucv_sock_bind() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 226/273] switchdev: Require RTNL mutex to be held when sending FDB notifications Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 237/273] flow_dissector: Fix unaligned access in __skb_flow_dissector when used by eth_get_headlen Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 171/273] x86/uaccess/64: Make the __copy_user_nocache() assembly code more readable Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 233/273] unix: correctly track in-flight fds in sending process user_struct Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 230/273] net/ipv6: add sysctl option accept_ra_min_hop_limit Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:20 +0100
    [PATCH 4.2.y-ckt 190/273] drivers: android: correct the size of struct binder_uintptr_t for BC_DEAD_BINDER_DONE Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 215/273] do_last(): don't let a bogus return value from ->open() et.al. to confuse us Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 193/273] s390/compat: correct restore of high gprs on signal return Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 199/273] ARCv2: SMP: Emulate IPI to self using software triggered interrupt Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 197/273] sunrpc/cache: fix off-by-one in qword_get() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 191/273] can: ems_usb: Fix possible tx overflow Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 205/273] ALSA: hda - Fixing background noise on Dell Inspiron 3162 Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 201/273] KVM: async_pf: do not warn on page allocation failures Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 203/273] libceph: don't bail early from try_read() when skipping a message Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 220/273] net: dp83640: Fix tx timestamp overflow handling. Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 210/273] ALSA: hda - Loop interrupt handling until really cleared Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 213/273] ocfs2: unlock inode if deleting inode from orphan fails Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 207/273] ALSA: hda/realtek - Support Dell headset mode for ALC225 Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 218/273] do_last(): ELOOP failure exit should be done after leaving RCU mode Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 202/273] tracing: Fix showing function event in available_events Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 211/273] x86/mpx: Fix off-by-one comparison with nr_registers Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 208/273] ALSA: hda - Fixup speaker pass-through control for nid 0x14 on ALC225 Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 204/273] libceph: use the right footer size when skipping a message Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 209/273] ALSA: hda - Fix headset support and noise on HP EliteBook 755 G2 Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 192/273] dm: fix dm_rq_target_io leak on faults with .request_fn DM w/ blk-mq paths Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 217/273] should_follow_link(): validate ->d_seq after having decided to follow Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 212/273] mm: thp: fix SMP race condition between THP page fault and MADV_DONTNEED Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 206/273] KVM: x86: MMU: fix ubsan index-out-of-range warning Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 216/273] namei: ->d_inode of a pinned dentry is stable only for positives Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 214/273] hpfs: don't truncate the file when delete fails Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 200/273] KVM: x86: fix missed hardware breakpoints Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 198/273] KVM: arm/arm64: vgic: Ensure bitmaps are long enough Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:30 +0100
    [PATCH 4.2.y-ckt 155/273] iwlwifi: mvm: don't allow sched scans without matches to be started Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 174/273] powerpc/ioda: Set "read" permission when "write" is set Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 149/273] btrfs: properly set the termination value of ctx->pos in readdir Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 185/273] ext4: fix bh->b_state corruption Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 178/273] USB: option: add support for SIM7100E Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 153/273] ext4: don't read blocks from disk after extents being swapped Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 163/273] dmaengine: dw: disable BLOCK IRQs for non-cyclic xfer Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 164/273] tracepoints: Do not trace when cpu is offline Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 173/273] usb: dwc3: Fix assignment of EP transfer resources Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 182/273] ipc: convert invalid scenarios to use WARN_ON Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 165/273] tracing: Fix freak link error caused by branch tracer Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 160/273] xen/pcifront: Fix mysterious crashes when NUMA locality information was extracted. Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 179/273] USB: cp210x: add IDs for GE B650V3 and B850V3 boards Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 162/273] ALSA: hda - Cancel probe work instead of flush at remove Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 184/273] hwmon: (ads1015) Handle negative conversion values correctly Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 183/273] ipc/shm: handle removed segments gracefully in shm_mmap() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 151/273] scsi: fix soft lockup in scsi_remove_target() on module removal Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 152/273] ext4: fix potential integer overflow Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 154/273] bio: return EINTR if copying to user space got interrupted Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 180/273] USB: option: add "4G LTE usb-modem U901" Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 150/273] irqchip/gic-v3-its: Fix double ICC_EOIR write for LPI in EOImode==1 Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 181/273] mm: fix regression in remap_file_pages() emulation Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 169/273] drm/qxl: use kmalloc_array to alloc reloc_info in qxl_process_single_command Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 168/273] drm/radeon: use post-decrement in error handling Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 177/273] ALSA: pcm: Fix rwsem deadlock for non-atomic PCM stream Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 161/273] ALSA: seq: Fix leak of pool buffer at concurrent writes Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 157/273] powerpc/powernv: Fix stale PE primary bus Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 175/273] NFSv4: Fix a dentry leak on alias use Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 166/273] ALSA: seq: Fix double port list deletion Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 167/273] drm/amdgpu: use post-decrement in error handling Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:40 +0100
    [PATCH 4.2.y-ckt 126/273] powerpc: Fix dedotify for binutils >= 2.26 Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 148/273] ARM: 8519/1: ICST: try other dividends than 1 Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 122/273] klist: fix starting point removed bug in klist iterators Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 138/273] drm/i915: fix error path in intel_setup_gmbus() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 130/273] nfs: fix nfs_size_to_loff_t Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 147/273] s390/dasd: fix refcount for PAV reassignment Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 124/273] drm/i915/dsi: defend gpio table against out of bounds access Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 015/273] x86/entry/compat: Add missing CLAC to entry_INT80_32 Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 123/273] ALSA: dummy: Implement timer backend switching more safely Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 132/273] ALSA: hda - Fix bad dereference of jack object Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 144/273] drm/amdgpu: fix issue with overlapping userptrs Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 128/273] ARM: 8517/1: ICST: avoid arithmetic overflow in icst_hz() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 125/273] drm/i915/dsi: don't pass arbitrary data to sideband Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 143/273] drm/radeon: hold reference to fences in radeon_sa_bo_new Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 136/273] phy: twl4030-usb: Fix unbalanced pm_runtime_enable on module reload Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 115/273] target: Fix race with SCF_SEND_DELAYED_TAS handling Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 140/273] workqueue: handle NUMA_NO_NODE for unbound pool_workqueue lookup Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 137/273] drm/i915/skl: Don't skip mst encoders in skl_ddi_pll_select() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 127/273] ALSA: timer: Fix wrong instance passed to slave callbacks Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 134/273] phy: core: fix wrong err handle for phy_power_on Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 135/273] phy: twl4030-usb: Relase usb phy on unload Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 145/273] cifs: fix erroneous return value Kamal Mostafa <kamal@canonical.com> - 2016-03-08 00:50 +0100
    [PATCH 4.2.y-ckt 039/273] ARM: dts: at91: sama5d4 xplained: fix phy0 IRQ type Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:10 +0100
    [PATCH 4.2.y-ckt 108/273] ocfs2/dlm: clear refmap bit of recovery lock while doing local recovery cleanup Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:10 +0100
    [PATCH 4.2.y-ckt 113/273] crypto: atmel-sha - fix atmel_sha_remove() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:10 +0100
    [PATCH 4.2.y-ckt 121/273] ALSA: hda - Fix speaker output from VAIO AiO machines Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:10 +0100
    [PATCH 4.2.y-ckt 117/273] serial: omap: Prevent DoS using unprivileged ioctl(TIOCSRS485) Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:10 +0100
    [PATCH 4.2.y-ckt 120/273] pty: make sure super_block is still valid in final /dev/tty close Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:10 +0100
    [PATCH 4.2.y-ckt 112/273] crypto: algif_skcipher - Do not set MAY_BACKLOG on the async path Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:30 +0100
    [PATCH 4.2.y-ckt 104/273] Revert "ALSA: hda - Fix noise on Gigabyte Z170X mobo" Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:30 +0100
    [PATCH 4.2.y-ckt 110/273] radix-tree: fix oops after radix_tree_iter_retry Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:30 +0100
    [PATCH 4.2.y-ckt 111/273] crypto: user - lock crypto_alg_list on alg dump Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:30 +0100
    [PATCH 4.2.y-ckt 109/273] mm: replace vma_lock_anon_vma with anon_vma_lock_read/write Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:30 +0100
    [PATCH 4.2.y-ckt 114/273] crypto: marvell/cesa - fix test in mv_cesa_dev_dma_init() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:30 +0100
    [PATCH 4.2.y-ckt 107/273] mm, vmstat: fix wrong WQ sleep when memory reclaim doesn't make any progress Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:30 +0100
    [PATCH 4.2.y-ckt 090/273] target: Fix TAS handling for multi-session se_node_acls Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 103/273] ALSA: hda - Fix static checker warning in patch_hdmi.c Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 068/273] drm/amdgpu: pull topaz gmc bits into gmc_v7 Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 085/273] usb: xhci: apply XHCI_PME_STUCK_QUIRK to Intel Broxton-M platforms Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 070/273] modules: fix modparam async_probe request Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 102/273] drm/dp/mst: deallocate payload on port destruction Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 073/273] ALSA: rawmidi: Make snd_rawmidi_transmit() race-free Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 087/273] target: Invoke release_cmd() callback without holding a spinlock Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 074/273] ALSA: rawmidi: Fix race at copying & updating the position Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 080/273] Btrfs: fix invalid page accesses in extent_same (dedup) ioctl Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 071/273] module: wrapper for symbol name. Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 065/273] drm/amdgpu: move gmc7 support out of CIK dependency Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 098/273] drm: fix missing reference counting decrease Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 069/273] drm/amdgpu: drop topaz support from gmc8 module Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 064/273] ASoC: dpcm: fix the BE state on hw_free Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 066/273] drm/amdgpu: iceland use CI based MC IP Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 076/273] drivers/scsi/sg.c: mark VMA as VM_IO to prevent migration Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 096/273] scsi_dh_rdac: always retry MODE SELECT on command lock violation Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 061/273] drm: add helper to check for wc memory support Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 095/273] Btrfs: fix hang on extent buffer lock caused by the inode_paths ioctl Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 083/273] usb: xhci: add a quirk bit for ssic port unused Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 072/273] ALSA: hda - Add fixup for Mac Mini 7,1 model Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 084/273] usb: xhci: set SSIC port unused only if xhci_suspend succeeds Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 089/273] target: Fix LUN_RESET active TMR descriptor handling Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 101/273] drm/dp/mst: Reverse order of MST enable and clearing VC payload table. Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 075/273] ALSA: seq: Fix lockdep warnings due to double mutex locks Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 093/273] [media] saa7134-alsa: Only frees registered sound cards Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 088/273] target: Fix LUN_RESET active I/O handling for ACK_KREF Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 106/273] dump_stack: avoid potential deadlocks Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 100/273] drm/dp/mst: Calculate MST PBN with 31.32 fixed point Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 105/273] target: Fix remote-port TMR ABORT + se_cmd fabric stop Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 092/273] ALSA: timer: Fix leftover link at closing Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 097/273] SCSI: Add Marvell Console to VPD blacklist Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 094/273] ARM: nomadik: fix up SD/MMC DT settings Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 099/273] drm: Add drm_fixp_from_fraction and drm_fixp2int_ceil Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 067/273] drm/amdgpu: The VI specific EXE bit should only apply to GMC v8.0 above Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:40 +0100
    [PATCH 4.2.y-ckt 026/273] ARM: OMAP2+: Fix wait_dll_lock_timed for rodata Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 032/273] PCI/AER: Flush workqueue on device remove to avoid use-after-free Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 046/273] ALSA: usb-audio: Add quirk for Microsoft LifeCam HD-6000 Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 058/273] libata: fix sff host state machine locking while polling Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 033/273] ARM: dts: Fix wl12xx missing clocks that cause hangs Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 037/273] ARM: dts: at91: sama5d4: fix instance id of DBGU Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 036/273] rfkill: fix rfkill_fop_read wait_event usage Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 049/273] iio: inkern: fix a NULL dereference on error Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 042/273] spi: atmel: fix gpio chip-select in case of non-DT platform Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 043/273] drm/i915/dp: fall back to 18 bpp when sink capability is unknown Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 044/273] ALSA: usb-audio: Fix OPPO HA-1 vendor ID Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 012/273] Revert "workqueue: make sure delayed work run in local cpu" Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 041/273] Input: vmmouse - fix absolute device registration Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 028/273] ARM: OMAP2+: Fix save_secure_ram_context for rodata Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 056/273] ALSA: timer: Code cleanup Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 055/273] ALSA: seq: Fix yet another races among ALSA timer accesses Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 062/273] drm/radeon: mask out WC from BO on unsupported arches Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 045/273] ALSA: usb-audio: Add native DSD support for PS Audio NuWave DAC Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 060/273] cputime: Prevent 32bit overflow in time[val|spec]_to_cputime() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 053/273] ALSA: rawmidi: Remove kernel WARNING for NULL user-space buffer check Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 027/273] ARM: OMAP2+: Fix l2dis_3630 for rodata Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 047/273] target: Fix WRITE_SAME/DISCARD conversion to linux 512b sectors Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 048/273] crypto: algif_hash - wait for crypto_ahash_init() to complete Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 051/273] intel_scu_ipcutil: underflow in scu_reg_access() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 035/273] mac80211: Requeue work after scan complete for all VIF types. Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 063/273] drm/amdgpu: mask out WC from BO on unsupported arches Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 025/273] cgroup: make sure a parent css isn't offlined before its children Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 023/273] ASoC: rt5645: fix the shift bit of IN1 boost Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 054/273] ALSA: pcm: Fix potential deadlock in OSS emulation Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 052/273] ALSA: seq: Fix race at closing in virmidi driver Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 057/273] ALSA: timer: Fix link corruption due to double start or stop Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 050/273] iio: pressure: mpl115: fix temperature offset sign Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 040/273] crypto: shash - Fix has_key setting Kamal Mostafa <kamal@canonical.com> - 2016-03-08 01:50 +0100
    [PATCH 4.2.y-ckt 009/273] EVM: Use crypto_memneq() for digest comparisons Kamal Mostafa <kamal@canonical.com> - 2016-03-08 02:00 +0100
    [PATCH 4.2.y-ckt 010/273] ALSA: usb-audio: avoid freeing umidi object twice Kamal Mostafa <kamal@canonical.com> - 2016-03-08 02:00 +0100
    [PATCH 4.2.y-ckt 022/273] iio:adc:ti_am335x_adc Fix buffered mode by identifying as software buffer. Kamal Mostafa <kamal@canonical.com> - 2016-03-08 02:00 +0100
    [PATCH 4.2.y-ckt 017/273] iio: add IIO_TRIGGER dependency to STK8BA50 Kamal Mostafa <kamal@canonical.com> - 2016-03-08 02:00 +0100
    [PATCH 4.2.y-ckt 013/273] drm/vmwgfx: Fix an fb unlocking bug Kamal Mostafa <kamal@canonical.com> - 2016-03-08 02:00 +0100
    [PATCH 4.2.y-ckt 016/273] iio-light: Use a signed return type for ltr501_match_samp_freq() Kamal Mostafa <kamal@canonical.com> - 2016-03-08 02:00 +0100
    [PATCH 4.2.y-ckt 024/273] ARCv2: STAR 9000950267: Handle return from intr to Delay Slot #2 Kamal Mostafa <kamal@canonical.com> - 2016-03-08 02:00 +0100
    [PATCH 4.2.y-ckt 020/273] iommu/vt-d: Fix 64-bit accesses to 32-bit DMAR_GSTS_REG Kamal Mostafa <kamal@canonical.com> - 2016-03-08 02:00 +0100
    [PATCH 4.2.y-ckt 018/273] iio: add HAS_IOMEM dependency to VF610_ADC Kamal Mostafa <kamal@canonical.com> - 2016-03-08 02:00 +0100
    [PATCH 4.2.y-ckt 019/273] iio: dac: mcp4725: set iio name property in sysfs Kamal Mostafa <kamal@canonical.com> - 2016-03-08 02:00 +0100
    [PATCH 4.2.y-ckt 021/273] iio: light: acpi-als: Report data as processed Kamal Mostafa <kamal@canonical.com> - 2016-03-08 02:00 +0100
    [PATCH 4.2.y-ckt 011/273] vmstat: explicitly schedule per-cpu work on the CPU we need it to run on Kamal Mostafa <kamal@canonical.com> - 2016-03-08 02:00 +0100

Page 6 of 12 — ← Prev page 1 … 4 5 [6] 7 8 … 12  Next page →


#1352214 — [PATCH 4.2.y-ckt 183/273] ipc/shm: handle removed segments gracefully in shm_mmap()

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 183/273] ipc/shm: handle removed segments gracefully in shm_mmap()
Message-ID<racUP-18J-41@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>

commit 1ac0b6dec656f3f78d1c3dd216fad84cb4d0a01e upstream.

remap_file_pages(2) emulation can reach file which represents removed
IPC ID as long as a memory segment is mapped.  It breaks expectations of
IPC subsystem.

Test case (rewritten to be more human readable, originally autogenerated
by syzkaller[1]):

	#define _GNU_SOURCE
	#include <stdlib.h>
	#include <sys/ipc.h>
	#include <sys/mman.h>
	#include <sys/shm.h>

	#define PAGE_SIZE 4096

	int main()
	{
		int id;
		void *p;

		id = shmget(IPC_PRIVATE, 3 * PAGE_SIZE, 0);
		p = shmat(id, NULL, 0);
		shmctl(id, IPC_RMID, NULL);
		remap_file_pages(p, 3 * PAGE_SIZE, 0, 7, 0);

	        return 0;
	}

The patch changes shm_mmap() and code around shm_lock() to propagate
locking error back to caller of shm_mmap().

[1] http://github.com/google/syzkaller

Signed-off-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Cc: Davidlohr Bueso <dave@stgolabs.net>
Cc: Manfred Spraul <manfred@colorfullife.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 ipc/shm.c | 53 +++++++++++++++++++++++++++++++++++++++++++----------
 1 file changed, 43 insertions(+), 10 deletions(-)

diff --git a/ipc/shm.c b/ipc/shm.c
index 4178727..3174634 100644
--- a/ipc/shm.c
+++ b/ipc/shm.c
@@ -156,11 +156,12 @@ static inline struct shmid_kernel *shm_lock(struct ipc_namespace *ns, int id)
 	struct kern_ipc_perm *ipcp = ipc_lock(&shm_ids(ns), id);
 
 	/*
-	 * We raced in the idr lookup or with shm_destroy().  Either way, the
-	 * ID is busted.
+	 * Callers of shm_lock() must validate the status of the returned ipc
+	 * object pointer (as returned by ipc_lock()), and error out as
+	 * appropriate.
 	 */
-	WARN_ON(IS_ERR(ipcp));
-
+	if (IS_ERR(ipcp))
+		return (void *)ipcp;
 	return container_of(ipcp, struct shmid_kernel, shm_perm);
 }
 
@@ -186,18 +187,33 @@ static inline void shm_rmid(struct ipc_namespace *ns, struct shmid_kernel *s)
 }
 
 
-/* This is called by fork, once for every shm attach. */
-static void shm_open(struct vm_area_struct *vma)
+static int __shm_open(struct vm_area_struct *vma)
 {
 	struct file *file = vma->vm_file;
 	struct shm_file_data *sfd = shm_file_data(file);
 	struct shmid_kernel *shp;
 
 	shp = shm_lock(sfd->ns, sfd->id);
+
+	if (IS_ERR(shp))
+		return PTR_ERR(shp);
+
 	shp->shm_atim = get_seconds();
 	shp->shm_lprid = task_tgid_vnr(current);
 	shp->shm_nattch++;
 	shm_unlock(shp);
+	return 0;
+}
+
+/* This is called by fork, once for every shm attach. */
+static void shm_open(struct vm_area_struct *vma)
+{
+	int err = __shm_open(vma);
+	/*
+	 * We raced in the idr lookup or with shm_destroy().
+	 * Either way, the ID is busted.
+	 */
+	WARN_ON_ONCE(err);
 }
 
 /*
@@ -260,6 +276,14 @@ static void shm_close(struct vm_area_struct *vma)
 	down_write(&shm_ids(ns).rwsem);
 	/* remove from the list of attaches of the shm segment */
 	shp = shm_lock(ns, sfd->id);
+
+	/*
+	 * We raced in the idr lookup or with shm_destroy().
+	 * Either way, the ID is busted.
+	 */
+	if (WARN_ON_ONCE(IS_ERR(shp)))
+		goto done; /* no-op */
+
 	shp->shm_lprid = task_tgid_vnr(current);
 	shp->shm_dtim = get_seconds();
 	shp->shm_nattch--;
@@ -267,6 +291,7 @@ static void shm_close(struct vm_area_struct *vma)
 		shm_destroy(ns, shp);
 	else
 		shm_unlock(shp);
+done:
 	up_write(&shm_ids(ns).rwsem);
 }
 
@@ -388,17 +413,25 @@ static int shm_mmap(struct file *file, struct vm_area_struct *vma)
 	struct shm_file_data *sfd = shm_file_data(file);
 	int ret;
 
+	/*
+	 * In case of remap_file_pages() emulation, the file can represent
+	 * removed IPC ID: propogate shm_lock() error to caller.
+	 */
+	ret =__shm_open(vma);
+	if (ret)
+		return ret;
+
 	ret = sfd->file->f_op->mmap(sfd->file, vma);
-	if (ret != 0)
+	if (ret) {
+		shm_close(vma);
 		return ret;
+	}
 	sfd->vm_ops = vma->vm_ops;
 #ifdef CONFIG_MMU
 	WARN_ON(!sfd->vm_ops->fault);
 #endif
 	vma->vm_ops = &shm_vm_ops;
-	shm_open(vma);
-
-	return ret;
+	return 0;
 }
 
 static int shm_release(struct inode *ino, struct file *file)
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352215 — [PATCH 4.2.y-ckt 151/273] scsi: fix soft lockup in scsi_remove_target() on module removal

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 151/273] scsi: fix soft lockup in scsi_remove_target() on module removal
Message-ID<racUP-18J-43@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: James Bottomley <James.Bottomley@HansenPartnership.com>

commit 90a88d6ef88edcfc4f644dddc7eef4ea41bccf8b upstream.

This softlockup is currently happening:

[  444.088002] NMI watchdog: BUG: soft lockup - CPU#1 stuck for 22s! [kworker/1:1:29]
[  444.088002] Modules linked in: lpfc(-) qla2x00tgt(O) qla2xxx_scst(O) scst_vdisk(O) scsi_transport_fc libcrc32c scst(O) dlm configfs nfsd lockd grace nfs_acl auth_rpcgss sunrpc ed
d snd_pcm_oss snd_mixer_oss snd_seq snd_seq_device dm_mod iTCO_wdt snd_hda_codec_realtek snd_hda_codec_generic gpio_ich iTCO_vendor_support ppdev snd_hda_intel snd_hda_codec snd_hda
_core snd_hwdep tg3 snd_pcm snd_timer libphy lpc_ich parport_pc ptp acpi_cpufreq snd pps_core fjes parport i2c_i801 ehci_pci tpm_tis tpm sr_mod cdrom soundcore floppy hwmon sg 8250_
fintek pcspkr i915 drm_kms_helper uhci_hcd ehci_hcd drm fb_sys_fops sysimgblt sysfillrect syscopyarea i2c_algo_bit usbcore button video usb_common fan ata_generic ata_piix libata th
ermal
[  444.088002] CPU: 1 PID: 29 Comm: kworker/1:1 Tainted: G           O    4.4.0-rc5-2.g1e923a3-default #1
[  444.088002] Hardware name: FUJITSU SIEMENS ESPRIMO E           /D2164-A1, BIOS 5.00 R1.10.2164.A1               05/08/2006
[  444.088002] Workqueue: fc_wq_4 fc_rport_final_delete [scsi_transport_fc]
[  444.088002] task: f6266ec0 ti: f6268000 task.ti: f6268000
[  444.088002] EIP: 0060:[<c07e7044>] EFLAGS: 00000286 CPU: 1
[  444.088002] EIP is at _raw_spin_unlock_irqrestore+0x14/0x20
[  444.088002] EAX: 00000286 EBX: f20d3800 ECX: 00000002 EDX: 00000286
[  444.088002] ESI: f50ba800 EDI: f2146848 EBP: f6269ec8 ESP: f6269ec8
[  444.088002]  DS: 007b ES: 007b FS: 00d8 GS: 00e0 SS: 0068
[  444.088002] CR0: 8005003b CR2: 08f96600 CR3: 363ae000 CR4: 000006d0
[  444.088002] Stack:
[  444.088002]  f6269eec c066b0f7 00000286 f2146848 f50ba808 f50ba800 f50ba800 f2146a90
[  444.088002]  f2146848 f6269f08 f8f0a4ed f3141000 f2146800 f2146a90 f619fa00 00000040
[  444.088002]  f6269f40 c026cb25 00000001 166c6392 00000061 f6757140 f6136340 00000004
[  444.088002] Call Trace:
[  444.088002]  [<c066b0f7>] scsi_remove_target+0x167/0x1c0
[  444.088002]  [<f8f0a4ed>] fc_rport_final_delete+0x9d/0x1e0 [scsi_transport_fc]
[  444.088002]  [<c026cb25>] process_one_work+0x155/0x3e0
[  444.088002]  [<c026cde7>] worker_thread+0x37/0x490
[  444.088002]  [<c027214b>] kthread+0x9b/0xb0
[  444.088002]  [<c07e72c1>] ret_from_kernel_thread+0x21/0x40

What appears to be happening is that something has pinned the target
so it can't go into STARGET_DEL via final release and the loop in
scsi_remove_target spins endlessly until that happens.

The fix for this soft lockup is to not keep looping over a device that
we've called remove on but which hasn't gone into DEL state.  This
patch will retain a simplistic memory of the last target and not keep
looping over it.

Reported-by: Sebastian Herbszt <herbszt@gmx.de>
Tested-by: Sebastian Herbszt <herbszt@gmx.de>
Fixes: 40998193560dab6c3ce8d25f4fa58a23e252ef38
Signed-off-by: James Bottomley <James.Bottomley@HansenPartnership.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/scsi/scsi_sysfs.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/scsi/scsi_sysfs.c b/drivers/scsi/scsi_sysfs.c
index e71eb8e..168a509 100644
--- a/drivers/scsi/scsi_sysfs.c
+++ b/drivers/scsi/scsi_sysfs.c
@@ -1148,16 +1148,18 @@ static void __scsi_remove_target(struct scsi_target *starget)
 void scsi_remove_target(struct device *dev)
 {
 	struct Scsi_Host *shost = dev_to_shost(dev->parent);
-	struct scsi_target *starget;
+	struct scsi_target *starget, *last_target = NULL;
 	unsigned long flags;
 
 restart:
 	spin_lock_irqsave(shost->host_lock, flags);
 	list_for_each_entry(starget, &shost->__targets, siblings) {
-		if (starget->state == STARGET_DEL)
+		if (starget->state == STARGET_DEL ||
+		    starget == last_target)
 			continue;
 		if (starget->dev.parent == dev || &starget->dev == dev) {
 			kref_get(&starget->reap_ref);
+			last_target = starget;
 			spin_unlock_irqrestore(shost->host_lock, flags);
 			__scsi_remove_target(starget);
 			scsi_target_reap(starget);
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352216 — [PATCH 4.2.y-ckt 152/273] ext4: fix potential integer overflow

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 152/273] ext4: fix potential integer overflow
Message-ID<racUO-18J-37@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Insu Yun <wuninsu@gmail.com>

commit 46901760b46064964b41015d00c140c83aa05bcf upstream.

Since sizeof(ext_new_group_data) > sizeof(ext_new_flex_group_data),
integer overflow could be happened.
Therefore, need to fix integer overflow sanitization.

Signed-off-by: Insu Yun <wuninsu@gmail.com>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/ext4/resize.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/ext4/resize.c b/fs/ext4/resize.c
index c7c53fd..c9a514f 100644
--- a/fs/ext4/resize.c
+++ b/fs/ext4/resize.c
@@ -198,7 +198,7 @@ static struct ext4_new_flex_group_data *alloc_flex_gd(unsigned long flexbg_size)
 	if (flex_gd == NULL)
 		goto out3;
 
-	if (flexbg_size >= UINT_MAX / sizeof(struct ext4_new_flex_group_data))
+	if (flexbg_size >= UINT_MAX / sizeof(struct ext4_new_group_data))
 		goto out2;
 	flex_gd->count = flexbg_size;
 
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352217 — [PATCH 4.2.y-ckt 154/273] bio: return EINTR if copying to user space got interrupted

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 154/273] bio: return EINTR if copying to user space got interrupted
Message-ID<racUP-18J-45@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Hannes Reinecke <hare@suse.de>

commit 2d99b55d378c996b9692a0c93dd25f4ed5d58934 upstream.

Commit 35dc248383bbab0a7203fca4d722875bc81ef091 introduced a check for
current->mm to see if we have a user space context and only copies data
if we do. Now if an IO gets interrupted by a signal data isn't copied
into user space any more (as we don't have a user space context) but
user space isn't notified about it.

This patch modifies the behaviour to return -EINTR from bio_uncopy_user()
to notify userland that a signal has interrupted the syscall, otherwise
it could lead to a situation where the caller may get a buffer with
no data returned.

This can be reproduced by issuing SG_IO ioctl()s in one thread while
constantly sending signals to it.

Fixes: 35dc248 [SCSI] sg: Fix user memory corruption when SG_IO is interrupted by a signal
Signed-off-by: Johannes Thumshirn <jthumshirn@suse.de>
Signed-off-by: Hannes Reinecke <hare@suse.de>
Signed-off-by: Jens Axboe <axboe@fb.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 block/bio.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/block/bio.c b/block/bio.c
index d6e5ba3..60826f5 100644
--- a/block/bio.c
+++ b/block/bio.c
@@ -1137,9 +1137,12 @@ int bio_uncopy_user(struct bio *bio)
 	if (!bio_flagged(bio, BIO_NULL_MAPPED)) {
 		/*
 		 * if we're in a workqueue, the request is orphaned, so
-		 * don't copy into a random user address space, just free.
+		 * don't copy into a random user address space, just free
+		 * and return -EINTR so user space doesn't expect any data.
 		 */
-		if (current->mm && bio_data_dir(bio) == READ)
+		if (!current->mm)
+			ret = -EINTR;
+		else if (bio_data_dir(bio) == READ)
 			ret = bio_copy_to_iter(bio, bmd->iter);
 		if (bmd->is_our_pages)
 			bio_free_pages(bio);
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352218 — [PATCH 4.2.y-ckt 180/273] USB: option: add "4G LTE usb-modem U901"

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 180/273] USB: option: add "4G LTE usb-modem U901"
Message-ID<racUP-18J-47@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: =?UTF-8?q?Bj=C3=B8rn=20Mork?= <bjorn@mork.no>

commit d061c1caa31d4d9792cfe48a2c6b309a0e01ef46 upstream.

Thomas reports:

T:  Bus=01 Lev=01 Prnt=01 Port=03 Cnt=01 Dev#=  4 Spd=480 MxCh= 0
D:  Ver= 2.00 Cls=00(>ifc ) Sub=00 Prot=00 MxPS=64 #Cfgs=  1
P:  Vendor=05c6 ProdID=6001 Rev=00.00
S:  Manufacturer=USB Modem
S:  Product=USB Modem
S:  SerialNumber=1234567890ABCDEF
C:  #Ifs= 5 Cfg#= 1 Atr=e0 MxPwr=500mA
I:  If#= 0 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=ff Driver=option
I:  If#= 1 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=ff Driver=option
I:  If#= 2 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=ff Driver=option
I:  If#= 3 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=ff Driver=qmi_wwan
I:  If#= 4 Alt= 0 #EPs= 2 Cls=08(stor.) Sub=06 Prot=50 Driver=usb-storage

Reported-by: Thomas Schäfer <tschaefer@t-online.de>
Signed-off-by: Bjørn Mork <bjorn@mork.no>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/usb/serial/option.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/usb/serial/option.c b/drivers/usb/serial/option.c
index a581361..2590f1e4 100644
--- a/drivers/usb/serial/option.c
+++ b/drivers/usb/serial/option.c
@@ -1135,6 +1135,8 @@ static const struct usb_device_id option_ids[] = {
 	{ USB_DEVICE(KYOCERA_VENDOR_ID, KYOCERA_PRODUCT_KPC650) },
 	{ USB_DEVICE(KYOCERA_VENDOR_ID, KYOCERA_PRODUCT_KPC680) },
 	{ USB_DEVICE(QUALCOMM_VENDOR_ID, 0x6000)}, /* ZTE AC8700 */
+	{ USB_DEVICE_AND_INTERFACE_INFO(QUALCOMM_VENDOR_ID, 0x6001, 0xff, 0xff, 0xff), /* 4G LTE usb-modem U901 */
+	  .driver_info = (kernel_ulong_t)&net_intf3_blacklist },
 	{ USB_DEVICE(QUALCOMM_VENDOR_ID, 0x6613)}, /* Onda H600/ZTE MF330 */
 	{ USB_DEVICE(QUALCOMM_VENDOR_ID, 0x0023)}, /* ONYX 3G device */
 	{ USB_DEVICE(QUALCOMM_VENDOR_ID, 0x9000)}, /* SIMCom SIM5218 */
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352219 — [PATCH 4.2.y-ckt 150/273] irqchip/gic-v3-its: Fix double ICC_EOIR write for LPI in EOImode==1

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 150/273] irqchip/gic-v3-its: Fix double ICC_EOIR write for LPI in EOImode==1
Message-ID<racUP-18J-49@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Ashok Kumar <ashoks@broadcom.com>

commit 004fa08d7aba2a13974446bf212a48c0b3b0d9fd upstream.

When the GIC is using EOImode==1, the EOI is done immediately,
leaving the deactivation to be performed when the EOI was
previously done.

Unfortunately, the ITS is not aware of the EOImode at all, and
blindly EOIs the interrupt again. On most systems, this is ignored
(despite being a programming error), but some others do raise a
SError exception as there is no priority drop to perform for this
interrupt.

The fix is to stop trying to be clever, and always call into the
underlying GIC to perform the right access, irrespective of the
more we're in.

[Marc: Reworked commit message]

Fixes: 0b996fd35957a ("irqchip/GICv3: Convert to EOImode == 1")
Acked-by: Marc Zyngier <marc.zyngier@arm.com>
Signed-off-by: Ashok Kumar <ashoks@broadcom.com>
Signed-off-by: Marc Zyngier <marc.zyngier@arm.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/irqchip/irq-gic-v3-its.c | 7 +------
 1 file changed, 1 insertion(+), 6 deletions(-)

diff --git a/drivers/irqchip/irq-gic-v3-its.c b/drivers/irqchip/irq-gic-v3-its.c
index 9a791dd..3114fc6 100644
--- a/drivers/irqchip/irq-gic-v3-its.c
+++ b/drivers/irqchip/irq-gic-v3-its.c
@@ -597,11 +597,6 @@ static void its_unmask_irq(struct irq_data *d)
 	lpi_set_config(d, true);
 }
 
-static void its_eoi_irq(struct irq_data *d)
-{
-	gic_write_eoir(d->hwirq);
-}
-
 static int its_set_affinity(struct irq_data *d, const struct cpumask *mask_val,
 			    bool force)
 {
@@ -638,7 +633,7 @@ static struct irq_chip its_irq_chip = {
 	.name			= "ITS",
 	.irq_mask		= its_mask_irq,
 	.irq_unmask		= its_unmask_irq,
-	.irq_eoi		= its_eoi_irq,
+	.irq_eoi		= irq_chip_eoi_parent,
 	.irq_set_affinity	= its_set_affinity,
 	.irq_compose_msi_msg	= its_irq_compose_msi_msg,
 };
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352220 — [PATCH 4.2.y-ckt 181/273] mm: fix regression in remap_file_pages() emulation

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 181/273] mm: fix regression in remap_file_pages() emulation
Message-ID<racUP-18J-51@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>

commit 48f7df329474b49d83d0dffec1b6186647f11976 upstream.

Grazvydas Ignotas has reported a regression in remap_file_pages()
emulation.

Testcase:
	#define _GNU_SOURCE
	#include <assert.h>
	#include <stdlib.h>
	#include <stdio.h>
	#include <sys/mman.h>

	#define SIZE    (4096 * 3)

	int main(int argc, char **argv)
	{
		unsigned long *p;
		long i;

		p = mmap(NULL, SIZE, PROT_READ | PROT_WRITE,
				MAP_SHARED | MAP_ANONYMOUS, -1, 0);
		if (p == MAP_FAILED) {
			perror("mmap");
			return -1;
		}

		for (i = 0; i < SIZE / 4096; i++)
			p[i * 4096 / sizeof(*p)] = i;

		if (remap_file_pages(p, 4096, 0, 1, 0)) {
			perror("remap_file_pages");
			return -1;
		}

		if (remap_file_pages(p, 4096 * 2, 0, 1, 0)) {
			perror("remap_file_pages");
			return -1;
		}

		assert(p[0] == 1);

		munmap(p, SIZE);

		return 0;
	}

The second remap_file_pages() fails with -EINVAL.

The reason is that remap_file_pages() emulation assumes that the target
vma covers whole area we want to over map.  That assumption is broken by
first remap_file_pages() call: it split the area into two vma.

The solution is to check next adjacent vmas, if they map the same file
with the same flags.

Fixes: c8d78c1823f4 ("mm: replace remap_file_pages() syscall with emulation")
Signed-off-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Reported-by: Grazvydas Ignotas <notasas@gmail.com>
Tested-by: Grazvydas Ignotas <notasas@gmail.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 mm/mmap.c | 34 +++++++++++++++++++++++++++++-----
 1 file changed, 29 insertions(+), 5 deletions(-)

diff --git a/mm/mmap.c b/mm/mmap.c
index abb35c6e..8eef2d4 100644
--- a/mm/mmap.c
+++ b/mm/mmap.c
@@ -2654,12 +2654,29 @@ SYSCALL_DEFINE5(remap_file_pages, unsigned long, start, unsigned long, size,
 	if (!vma || !(vma->vm_flags & VM_SHARED))
 		goto out;
 
-	if (start < vma->vm_start || start + size > vma->vm_end)
+	if (start < vma->vm_start)
 		goto out;
 
-	if (pgoff == linear_page_index(vma, start)) {
-		ret = 0;
-		goto out;
+	if (start + size > vma->vm_end) {
+		struct vm_area_struct *next;
+
+		for (next = vma->vm_next; next; next = next->vm_next) {
+			/* hole between vmas ? */
+			if (next->vm_start != next->vm_prev->vm_end)
+				goto out;
+
+			if (next->vm_file != vma->vm_file)
+				goto out;
+
+			if (next->vm_flags != vma->vm_flags)
+				goto out;
+
+			if (start + size <= next->vm_end)
+				break;
+		}
+
+		if (!next)
+			goto out;
 	}
 
 	prot |= vma->vm_flags & VM_READ ? PROT_READ : 0;
@@ -2669,9 +2686,16 @@ SYSCALL_DEFINE5(remap_file_pages, unsigned long, start, unsigned long, size,
 	flags &= MAP_NONBLOCK;
 	flags |= MAP_SHARED | MAP_FIXED | MAP_POPULATE;
 	if (vma->vm_flags & VM_LOCKED) {
+		struct vm_area_struct *tmp;
 		flags |= MAP_LOCKED;
+
 		/* drop PG_Mlocked flag for over-mapped range */
-		munlock_vma_pages_range(vma, start, start + size);
+		for (tmp = vma; tmp->vm_start >= start + size;
+				tmp = tmp->vm_next) {
+			munlock_vma_pages_range(tmp,
+					max(tmp->vm_start, start),
+					min(tmp->vm_end, start + size));
+		}
 	}
 
 	file = get_file(vma->vm_file);
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352222 — [PATCH 4.2.y-ckt 169/273] drm/qxl: use kmalloc_array to alloc reloc_info in qxl_process_single_command

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 169/273] drm/qxl: use kmalloc_array to alloc reloc_info in qxl_process_single_command
Message-ID<racUP-18J-57@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Gerd Hoffmann <kraxel@redhat.com>

commit 34855706c30d52b0a744da44348b5d1cc39fbe51 upstream.

This avoids integer overflows on 32bit machines when calculating
reloc_info size, as reported by Alan Cox.

Cc: gnomes@lxorguk.ukuu.org.uk
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Reviewed-by: Daniel Vetter <daniel.vetter@ffwll.ch>
Signed-off-by: Dave Airlie <airlied@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/gpu/drm/qxl/qxl_ioctl.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/qxl/qxl_ioctl.c b/drivers/gpu/drm/qxl/qxl_ioctl.c
index bda5c5f..7adcbfb 100644
--- a/drivers/gpu/drm/qxl/qxl_ioctl.c
+++ b/drivers/gpu/drm/qxl/qxl_ioctl.c
@@ -168,7 +168,8 @@ static int qxl_process_single_command(struct qxl_device *qdev,
 		       cmd->command_size))
 		return -EFAULT;
 
-	reloc_info = kmalloc(sizeof(struct qxl_reloc_info) * cmd->relocs_num, GFP_KERNEL);
+	reloc_info = kmalloc_array(cmd->relocs_num,
+				   sizeof(struct qxl_reloc_info), GFP_KERNEL);
 	if (!reloc_info)
 		return -ENOMEM;
 
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352224 — [PATCH 4.2.y-ckt 168/273] drm/radeon: use post-decrement in error handling

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 168/273] drm/radeon: use post-decrement in error handling
Message-ID<racUP-18J-59@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Rasmus Villemoes <linux@rasmusvillemoes.dk>

commit bc3f5d8c4ca01555820617eb3b6c0857e4df710d upstream.

We need to use post-decrement to get the pci_map_page undone also for
i==0, and to avoid some very unpleasant behaviour if pci_map_page
failed already at i==0.

Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Rasmus Villemoes <linux@rasmusvillemoes.dk>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/gpu/drm/radeon/radeon_ttm.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/radeon/radeon_ttm.c b/drivers/gpu/drm/radeon/radeon_ttm.c
index 06ac59fe..fa6f041 100644
--- a/drivers/gpu/drm/radeon/radeon_ttm.c
+++ b/drivers/gpu/drm/radeon/radeon_ttm.c
@@ -758,7 +758,7 @@ static int radeon_ttm_tt_populate(struct ttm_tt *ttm)
 						       0, PAGE_SIZE,
 						       PCI_DMA_BIDIRECTIONAL);
 		if (pci_dma_mapping_error(rdev->pdev, gtt->ttm.dma_address[i])) {
-			while (--i) {
+			while (i--) {
 				pci_unmap_page(rdev->pdev, gtt->ttm.dma_address[i],
 					       PAGE_SIZE, PCI_DMA_BIDIRECTIONAL);
 				gtt->ttm.dma_address[i] = 0;
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352225 — [PATCH 4.2.y-ckt 177/273] ALSA: pcm: Fix rwsem deadlock for non-atomic PCM stream

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 177/273] ALSA: pcm: Fix rwsem deadlock for non-atomic PCM stream
Message-ID<racUP-18J-61@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit 67ec1072b053c15564e6090ab30127895dc77a89 upstream.

A non-atomic PCM stream may take snd_pcm_link_rwsem rw semaphore twice
in the same code path, e.g. one in snd_pcm_action_nonatomic() and
another in snd_pcm_stream_lock().  Usually this is OK, but when a
write lock is issued between these two read locks, the problem
happens: the write lock is blocked due to the first reade lock, and
the second read lock is also blocked by the write lock.  This
eventually deadlocks.

The reason is the way rwsem manages waiters; it's queued like FIFO, so
even if the writer itself doesn't take the lock yet, it blocks all the
waiters (including reads) queued after it.

As a workaround, in this patch, we replace the standard down_write()
with an spinning loop.  This is far from optimal, but it's good
enough, as the spinning time is supposed to be relatively short for
normal PCM operations, and the code paths requiring the write lock
aren't called so often.

Reported-by: Vinod Koul <vinod.koul@intel.com>
Tested-by: Ramesh Babu <ramesh.babu@intel.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/core/pcm_native.c | 16 ++++++++++++++--
 1 file changed, 14 insertions(+), 2 deletions(-)

diff --git a/sound/core/pcm_native.c b/sound/core/pcm_native.c
index 75888dd..aa999e7 100644
--- a/sound/core/pcm_native.c
+++ b/sound/core/pcm_native.c
@@ -74,6 +74,18 @@ static int snd_pcm_open(struct file *file, struct snd_pcm *pcm, int stream);
 static DEFINE_RWLOCK(snd_pcm_link_rwlock);
 static DECLARE_RWSEM(snd_pcm_link_rwsem);
 
+/* Writer in rwsem may block readers even during its waiting in queue,
+ * and this may lead to a deadlock when the code path takes read sem
+ * twice (e.g. one in snd_pcm_action_nonatomic() and another in
+ * snd_pcm_stream_lock()).  As a (suboptimal) workaround, let writer to
+ * spin until it gets the lock.
+ */
+static inline void down_write_nonblock(struct rw_semaphore *lock)
+{
+	while (!down_write_trylock(lock))
+		cond_resched();
+}
+
 /**
  * snd_pcm_stream_lock - Lock the PCM stream
  * @substream: PCM substream
@@ -1816,7 +1828,7 @@ static int snd_pcm_link(struct snd_pcm_substream *substream, int fd)
 		res = -ENOMEM;
 		goto _nolock;
 	}
-	down_write(&snd_pcm_link_rwsem);
+	down_write_nonblock(&snd_pcm_link_rwsem);
 	write_lock_irq(&snd_pcm_link_rwlock);
 	if (substream->runtime->status->state == SNDRV_PCM_STATE_OPEN ||
 	    substream->runtime->status->state != substream1->runtime->status->state ||
@@ -1863,7 +1875,7 @@ static int snd_pcm_unlink(struct snd_pcm_substream *substream)
 	struct snd_pcm_substream *s;
 	int res = 0;
 
-	down_write(&snd_pcm_link_rwsem);
+	down_write_nonblock(&snd_pcm_link_rwsem);
 	write_lock_irq(&snd_pcm_link_rwlock);
 	if (!snd_pcm_stream_linked(substream)) {
 		res = -EALREADY;
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352227 — [PATCH 4.2.y-ckt 161/273] ALSA: seq: Fix leak of pool buffer at concurrent writes

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 161/273] ALSA: seq: Fix leak of pool buffer at concurrent writes
Message-ID<racUQ-18J-67@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit d99a36f4728fcbcc501b78447f625bdcce15b842 upstream.

When multiple concurrent writes happen on the ALSA sequencer device
right after the open, it may try to allocate vmalloc buffer for each
write and leak some of them.  It's because the presence check and the
assignment of the buffer is done outside the spinlock for the pool.

The fix is to move the check and the assignment into the spinlock.

(The current implementation is suboptimal, as there can be multiple
 unnecessary vmallocs because the allocation is done before the check
 in the spinlock.  But the pool size is already checked beforehand, so
 this isn't a big problem; that is, the only possible path is the
 multiple writes before any pool assignment, and practically seen, the
 current coverage should be "good enough".)

The issue was triggered by syzkaller fuzzer.

BugLink: http://lkml.kernel.org/r/CACT4Y+bSzazpXNvtAr=WXaL8hptqjHwqEyFA+VN2AWEx=aurkg@mail.gmail.com
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Tested-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/core/seq/seq_memory.c | 13 +++++++++----
 1 file changed, 9 insertions(+), 4 deletions(-)

diff --git a/sound/core/seq/seq_memory.c b/sound/core/seq/seq_memory.c
index 8010766..c850345 100644
--- a/sound/core/seq/seq_memory.c
+++ b/sound/core/seq/seq_memory.c
@@ -383,15 +383,20 @@ int snd_seq_pool_init(struct snd_seq_pool *pool)
 
 	if (snd_BUG_ON(!pool))
 		return -EINVAL;
-	if (pool->ptr)			/* should be atomic? */
-		return 0;
 
-	pool->ptr = vmalloc(sizeof(struct snd_seq_event_cell) * pool->size);
-	if (!pool->ptr)
+	cellptr = vmalloc(sizeof(struct snd_seq_event_cell) * pool->size);
+	if (!cellptr)
 		return -ENOMEM;
 
 	/* add new cells to the free cell list */
 	spin_lock_irqsave(&pool->lock, flags);
+	if (pool->ptr) {
+		spin_unlock_irqrestore(&pool->lock, flags);
+		vfree(cellptr);
+		return 0;
+	}
+
+	pool->ptr = cellptr;
 	pool->free = NULL;
 
 	for (cell = 0; cell < pool->size; cell++) {
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352228 — [PATCH 4.2.y-ckt 157/273] powerpc/powernv: Fix stale PE primary bus

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 157/273] powerpc/powernv: Fix stale PE primary bus
Message-ID<racUQ-18J-65@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Gavin Shan <gwshan@linux.vnet.ibm.com>

commit 1bc74f1ccd457832dc515fc1febe6655985fdcd2 upstream.

When PCI bus is unplugged during full hotplug for EEH recovery,
the platform PE instance (struct pnv_ioda_pe) isn't released and
it dereferences the stale PCI bus that has been released. It leads
to kernel crash when referring to the stale PCI bus.

This fixes the issue by correcting the PE's primary bus when it's
oneline at plugging time, in pnv_pci_dma_bus_setup() which is to
be called by pcibios_fixup_bus().

Reported-by: Andrew Donnellan <andrew.donnellan@au1.ibm.com>
Reported-by: Pradipta Ghosh <pradghos@in.ibm.com>
Signed-off-by: Gavin Shan <gwshan@linux.vnet.ibm.com>
Tested-by: Andrew Donnellan <andrew.donnellan@au1.ibm.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/powerpc/platforms/powernv/pci-ioda.c |  1 +
 arch/powerpc/platforms/powernv/pci.c      | 20 ++++++++++++++++++++
 arch/powerpc/platforms/powernv/pci.h      |  1 +
 3 files changed, 22 insertions(+)

diff --git a/arch/powerpc/platforms/powernv/pci-ioda.c b/arch/powerpc/platforms/powernv/pci-ioda.c
index 8b64f89..a02d22e 100644
--- a/arch/powerpc/platforms/powernv/pci-ioda.c
+++ b/arch/powerpc/platforms/powernv/pci-ioda.c
@@ -3063,6 +3063,7 @@ static void pnv_pci_ioda_shutdown(struct pci_controller *hose)
 
 static const struct pci_controller_ops pnv_pci_ioda_controller_ops = {
        .dma_dev_setup = pnv_pci_dma_dev_setup,
+       .dma_bus_setup = pnv_pci_dma_bus_setup,
 #ifdef CONFIG_PCI_MSI
        .setup_msi_irqs = pnv_setup_msi_irqs,
        .teardown_msi_irqs = pnv_teardown_msi_irqs,
diff --git a/arch/powerpc/platforms/powernv/pci.c b/arch/powerpc/platforms/powernv/pci.c
index fd16f86..74f4c9e 100644
--- a/arch/powerpc/platforms/powernv/pci.c
+++ b/arch/powerpc/platforms/powernv/pci.c
@@ -762,6 +762,26 @@ void pnv_pci_dma_dev_setup(struct pci_dev *pdev)
 		phb->dma_dev_setup(phb, pdev);
 }
 
+void pnv_pci_dma_bus_setup(struct pci_bus *bus)
+{
+	struct pci_controller *hose = bus->sysdata;
+	struct pnv_phb *phb = hose->private_data;
+	struct pnv_ioda_pe *pe;
+
+	list_for_each_entry(pe, &phb->ioda.pe_list, list) {
+		if (!(pe->flags & (PNV_IODA_PE_BUS | PNV_IODA_PE_BUS_ALL)))
+			continue;
+
+		if (!pe->pbus)
+			continue;
+
+		if (bus->number == ((pe->rid >> 8) & 0xFF)) {
+			pe->pbus = bus;
+			break;
+		}
+	}
+}
+
 u64 pnv_pci_dma_get_required_mask(struct pci_dev *pdev)
 {
 	struct pci_controller *hose = pci_bus_to_host(pdev->bus);
diff --git a/arch/powerpc/platforms/powernv/pci.h b/arch/powerpc/platforms/powernv/pci.h
index 8ef2d28..6809a5b 100644
--- a/arch/powerpc/platforms/powernv/pci.h
+++ b/arch/powerpc/platforms/powernv/pci.h
@@ -236,6 +236,7 @@ extern void pnv_pci_reset_secondary_bus(struct pci_dev *dev);
 extern int pnv_eeh_phb_reset(struct pci_controller *hose, int option);
 
 extern void pnv_pci_dma_dev_setup(struct pci_dev *pdev);
+extern void pnv_pci_dma_bus_setup(struct pci_bus *bus);
 extern int pnv_setup_msi_irqs(struct pci_dev *pdev, int nvec, int type);
 extern void pnv_teardown_msi_irqs(struct pci_dev *pdev);
 
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352229 — [PATCH 4.2.y-ckt 175/273] NFSv4: Fix a dentry leak on alias use

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 175/273] NFSv4: Fix a dentry leak on alias use
Message-ID<racUQ-18J-69@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Benjamin Coddington <bcodding@redhat.com>

commit d9dfd8d741683347ee159d25f5b50c346a0df557 upstream.

In the case where d_add_unique() finds an appropriate alias to use it will
have already incremented the reference count.  An additional dget() to swap
the open context's dentry is unnecessary and will leak a reference.

Signed-off-by: Benjamin Coddington <bcodding@redhat.com>
Fixes: 275bb307865a3 ("NFSv4: Move dentry instantiation into the NFSv4-...")
Signed-off-by: Trond Myklebust <trond.myklebust@primarydata.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/nfs/nfs4proc.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/fs/nfs/nfs4proc.c b/fs/nfs/nfs4proc.c
index 71e6b1b..731641a 100644
--- a/fs/nfs/nfs4proc.c
+++ b/fs/nfs/nfs4proc.c
@@ -2356,9 +2356,9 @@ static int _nfs4_open_and_get_state(struct nfs4_opendata *opendata,
 		dentry = d_add_unique(dentry, igrab(state->inode));
 		if (dentry == NULL) {
 			dentry = opendata->dentry;
-		} else if (dentry != ctx->dentry) {
+		} else {
 			dput(ctx->dentry);
-			ctx->dentry = dget(dentry);
+			ctx->dentry = dentry;
 		}
 		nfs_set_verifier(dentry,
 				nfs_save_change_attribute(d_inode(opendata->dir)));
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352231 — [PATCH 4.2.y-ckt 166/273] ALSA: seq: Fix double port list deletion

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 166/273] ALSA: seq: Fix double port list deletion
Message-ID<racUQ-18J-73@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit 13d5e5d4725c64ec06040d636832e78453f477b7 upstream.

The commit [7f0973e973cd: ALSA: seq: Fix lockdep warnings due to
double mutex locks] split the management of two linked lists (source
and destination) into two individual calls for avoiding the AB/BA
deadlock.  However, this may leave the possible double deletion of one
of two lists when the counterpart is being deleted concurrently.
It ends up with a list corruption, as revealed by syzkaller fuzzer.

This patch fixes it by checking the list emptiness and skipping the
deletion and the following process.

BugLink: http://lkml.kernel.org/r/CACT4Y+bay9qsrz6dQu31EcGaH9XwfW7o3oBzSQUG9fMszoh=Sg@mail.gmail.com
Fixes: 7f0973e973cd ('ALSA: seq: Fix lockdep warnings due to 'double mutex locks)
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Tested-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/core/seq/seq_ports.c | 13 ++++++++-----
 1 file changed, 8 insertions(+), 5 deletions(-)

diff --git a/sound/core/seq/seq_ports.c b/sound/core/seq/seq_ports.c
index 921fb2b..fe686ee 100644
--- a/sound/core/seq/seq_ports.c
+++ b/sound/core/seq/seq_ports.c
@@ -535,19 +535,22 @@ static void delete_and_unsubscribe_port(struct snd_seq_client *client,
 					bool is_src, bool ack)
 {
 	struct snd_seq_port_subs_info *grp;
+	struct list_head *list;
+	bool empty;
 
 	grp = is_src ? &port->c_src : &port->c_dest;
+	list = is_src ? &subs->src_list : &subs->dest_list;
 	down_write(&grp->list_mutex);
 	write_lock_irq(&grp->list_lock);
-	if (is_src)
-		list_del(&subs->src_list);
-	else
-		list_del(&subs->dest_list);
+	empty = list_empty(list);
+	if (!empty)
+		list_del_init(list);
 	grp->exclusive = 0;
 	write_unlock_irq(&grp->list_lock);
 	up_write(&grp->list_mutex);
 
-	unsubscribe_port(client, port, grp, &subs->info, ack);
+	if (!empty)
+		unsubscribe_port(client, port, grp, &subs->info, ack);
 }
 
 /* connect two ports */
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352232 — [PATCH 4.2.y-ckt 167/273] drm/amdgpu: use post-decrement in error handling

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:40 +0100
Subject[PATCH 4.2.y-ckt 167/273] drm/amdgpu: use post-decrement in error handling
Message-ID<racUQ-18J-75@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Rasmus Villemoes <linux@rasmusvillemoes.dk>

commit 09ccbb74b6718ad4d1290de3f5669212c0ac7d4b upstream.

We need to use post-decrement to get the pci_map_page undone also for
i==0, and to avoid some very unpleasant behaviour if pci_map_page
failed already at i==0.

Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Rasmus Villemoes <linux@rasmusvillemoes.dk>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c
index e3f73b7..0345298 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c
@@ -708,7 +708,7 @@ static int amdgpu_ttm_tt_populate(struct ttm_tt *ttm)
 						       0, PAGE_SIZE,
 						       PCI_DMA_BIDIRECTIONAL);
 		if (pci_dma_mapping_error(adev->pdev, gtt->ttm.dma_address[i])) {
-			while (--i) {
+			while (i--) {
 				pci_unmap_page(adev->pdev, gtt->ttm.dma_address[i],
 					       PAGE_SIZE, PCI_DMA_BIDIRECTIONAL);
 				gtt->ttm.dma_address[i] = 0;
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352234 — [PATCH 4.2.y-ckt 126/273] powerpc: Fix dedotify for binutils >= 2.26

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:50 +0100
Subject[PATCH 4.2.y-ckt 126/273] powerpc: Fix dedotify for binutils >= 2.26
Message-ID<rad4u-1cJ-5@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Andreas Schwab <schwab@linux-m68k.org>

commit f15838e9cac8f78f0cc506529bb9d3b9fa589c1f upstream.

Since binutils 2.26 BFD is doing suffix merging on STRTAB sections.  But
dedotify modifies the symbol names in place, which can also modify
unrelated symbols with a name that matches a suffix of a dotted name.  To
remove the leading dot of a symbol name we can just increment the pointer
into the STRTAB section instead.

Backport to all stables to avoid breakage when people update their
binutils - mpe.

Signed-off-by: Andreas Schwab <schwab@linux-m68k.org>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/powerpc/kernel/module_64.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/powerpc/kernel/module_64.c b/arch/powerpc/kernel/module_64.c
index 59663af..e4f7d4e 100644
--- a/arch/powerpc/kernel/module_64.c
+++ b/arch/powerpc/kernel/module_64.c
@@ -335,7 +335,7 @@ static void dedotify(Elf64_Sym *syms, unsigned int numsyms, char *strtab)
 		if (syms[i].st_shndx == SHN_UNDEF) {
 			char *name = strtab + syms[i].st_name;
 			if (name[0] == '.')
-				memmove(name, name+1, strlen(name));
+				syms[i].st_name++;
 		}
 	}
 }
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352235 — [PATCH 4.2.y-ckt 148/273] ARM: 8519/1: ICST: try other dividends than 1

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:50 +0100
Subject[PATCH 4.2.y-ckt 148/273] ARM: 8519/1: ICST: try other dividends than 1
Message-ID<rad4u-1cJ-7@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Linus Walleij <linus.walleij@linaro.org>

commit e972c37459c813190461dabfeaac228e00aae259 upstream.

Since the dawn of time the ICST code has only supported divide
by one or hang in an eternal loop. Luckily we were always dividing
by one because the reference frequency for the systems using
the ICSTs is 24MHz and the [min,max] values for the PLL input
if [10,320] MHz for ICST307 and [6,200] for ICST525, so the loop
will always terminate immediately without assigning any divisor
for the reference frequency.

But for the code to make sense, let's insert the missing i++

Reported-by: David Binderman <dcb314@hotmail.com>
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/arm/common/icst.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/arch/arm/common/icst.c b/arch/arm/common/icst.c
index d3c0e69..d7ed252 100644
--- a/arch/arm/common/icst.c
+++ b/arch/arm/common/icst.c
@@ -62,6 +62,7 @@ icst_hz_to_vco(const struct icst_params *p, unsigned long freq)
 
 		if (f > p->vco_min && f <= p->vco_max)
 			break;
+		i++;
 	} while (i < 8);
 
 	if (i >= 8)
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352236 — [PATCH 4.2.y-ckt 122/273] klist: fix starting point removed bug in klist iterators

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:50 +0100
Subject[PATCH 4.2.y-ckt 122/273] klist: fix starting point removed bug in klist iterators
Message-ID<rad4u-1cJ-9@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: James Bottomley <James.Bottomley@HansenPartnership.com>

commit 00cd29b799e3449f0c68b1cc77cd4a5f95b42d17 upstream.

The starting node for a klist iteration is often passed in from
somewhere way above the klist infrastructure, meaning there's no
guarantee the node is still on the list.  We've seen this in SCSI where
we use bus_find_device() to iterate through a list of devices.  In the
face of heavy hotplug activity, the last device returned by
bus_find_device() can be removed before the next call.  This leads to

Dec  3 13:22:02 localhost kernel: WARNING: CPU: 2 PID: 28073 at include/linux/kref.h:47 klist_iter_init_node+0x3d/0x50()
Dec  3 13:22:02 localhost kernel: Modules linked in: scsi_debug x86_pkg_temp_thermal kvm_intel kvm irqbypass crc32c_intel joydev iTCO_wdt dcdbas ipmi_devintf acpi_power_meter iTCO_vendor_support ipmi_si imsghandler pcspkr wmi acpi_cpufreq tpm_tis tpm shpchp lpc_ich mfd_core nfsd nfs_acl lockd grace sunrpc tg3 ptp pps_core
Dec  3 13:22:02 localhost kernel: CPU: 2 PID: 28073 Comm: cat Not tainted 4.4.0-rc1+ #2
Dec  3 13:22:02 localhost kernel: Hardware name: Dell Inc. PowerEdge R320/08VT7V, BIOS 2.0.22 11/19/2013
Dec  3 13:22:02 localhost kernel: ffffffff81a20e77 ffff880613acfd18 ffffffff81321eef 0000000000000000
Dec  3 13:22:02 localhost kernel: ffff880613acfd50 ffffffff8107ca52 ffff88061176b198 0000000000000000
Dec  3 13:22:02 localhost kernel: ffffffff814542b0 ffff880610cfb100 ffff88061176b198 ffff880613acfd60
Dec  3 13:22:02 localhost kernel: Call Trace:
Dec  3 13:22:02 localhost kernel: [<ffffffff81321eef>] dump_stack+0x44/0x55
Dec  3 13:22:02 localhost kernel: [<ffffffff8107ca52>] warn_slowpath_common+0x82/0xc0
Dec  3 13:22:02 localhost kernel: [<ffffffff814542b0>] ? proc_scsi_show+0x20/0x20
Dec  3 13:22:02 localhost kernel: [<ffffffff8107cb4a>] warn_slowpath_null+0x1a/0x20
Dec  3 13:22:02 localhost kernel: [<ffffffff8167225d>] klist_iter_init_node+0x3d/0x50
Dec  3 13:22:02 localhost kernel: [<ffffffff81421d41>] bus_find_device+0x51/0xb0
Dec  3 13:22:02 localhost kernel: [<ffffffff814545ad>] scsi_seq_next+0x2d/0x40
[...]

And an eventual crash. It can actually occur in any hotplug system
which has a device finder and a starting device.

We can fix this globally by making sure the starting node for
klist_iter_init_node() is actually a member of the list before using it
(and by starting from the beginning if it isn't).

Reported-by: Ewan D. Milne <emilne@redhat.com>
Tested-by: Ewan D. Milne <emilne@redhat.com>
Signed-off-by: James Bottomley <James.Bottomley@HansenPartnership.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 lib/klist.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/lib/klist.c b/lib/klist.c
index 89b485a..2a072bf 100644
--- a/lib/klist.c
+++ b/lib/klist.c
@@ -282,9 +282,9 @@ void klist_iter_init_node(struct klist *k, struct klist_iter *i,
 			  struct klist_node *n)
 {
 	i->i_klist = k;
-	i->i_cur = n;
-	if (n)
-		kref_get(&n->n_ref);
+	i->i_cur = NULL;
+	if (n && kref_get_unless_zero(&n->n_ref))
+		i->i_cur = n;
 }
 EXPORT_SYMBOL_GPL(klist_iter_init_node);
 
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352237 — [PATCH 4.2.y-ckt 138/273] drm/i915: fix error path in intel_setup_gmbus()

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:50 +0100
Subject[PATCH 4.2.y-ckt 138/273] drm/i915: fix error path in intel_setup_gmbus()
Message-ID<rad4u-1cJ-13@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Rasmus Villemoes <linux@rasmusvillemoes.dk>

commit ed3f9fd1e865975ceefdb2a43b453e090b1fd787 upstream.

This fails to undo the setup for pin==0; moreover, something
interesting happens if the setup failed already at pin==0.

Signed-off-by: Rasmus Villemoes <linux@rasmusvillemoes.dk>
Fixes: f899fc64cda8 ("drm/i915: use GMBUS to manage i2c links")
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Link: http://patchwork.freedesktop.org/patch/msgid/1455048677-19882-3-git-send-email-linux@rasmusvillemoes.dk
(cherry picked from commit 2417c8c03f508841b85bf61acc91836b7b0e2560)
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/gpu/drm/i915/intel_i2c.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/i915/intel_i2c.c b/drivers/gpu/drm/i915/intel_i2c.c
index a64f26c..e5d39f2 100644
--- a/drivers/gpu/drm/i915/intel_i2c.c
+++ b/drivers/gpu/drm/i915/intel_i2c.c
@@ -681,7 +681,7 @@ int intel_setup_gmbus(struct drm_device *dev)
 	return 0;
 
 err:
-	while (--pin) {
+	while (pin--) {
 		if (!intel_gmbus_is_valid_pin(dev_priv, pin))
 			continue;
 
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


#1352240 — [PATCH 4.2.y-ckt 130/273] nfs: fix nfs_size_to_loff_t

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-08 00:50 +0100
Subject[PATCH 4.2.y-ckt 130/273] nfs: fix nfs_size_to_loff_t
Message-ID<rad4u-1cJ-17@gated-at.bofh.it>
In reply to#1352081
4.2.8-ckt5 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Christoph Hellwig <hch@lst.de>

commit 50ab8ec74a153eb30db26529088bc57dd700b24c upstream.

See http: //www.infradead.org/rpr.html
X-Evolution-Source: 1451162204.2173.11@leira.trondhjem.org
Content-Transfer-Encoding: 8bit
Mime-Version: 1.0

We support OFFSET_MAX just fine, so don't round down below it.  Also
switch to using min_t to make the helper more readable.

Signed-off-by: Christoph Hellwig <hch@lst.de>
Fixes: 433c92379d9c ("NFS: Clean up nfs_size_to_loff_t()")
Signed-off-by: Trond Myklebust <trond.myklebust@primarydata.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 include/linux/nfs_fs.h | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

diff --git a/include/linux/nfs_fs.h b/include/linux/nfs_fs.h
index 874b772..b18488f 100644
--- a/include/linux/nfs_fs.h
+++ b/include/linux/nfs_fs.h
@@ -544,9 +544,7 @@ extern int  nfs_readpage_async(struct nfs_open_context *, struct inode *,
 
 static inline loff_t nfs_size_to_loff_t(__u64 size)
 {
-	if (size > (__u64) OFFSET_MAX - 1)
-		return OFFSET_MAX - 1;
-	return (loff_t) size;
+	return min_t(u64, size, OFFSET_MAX);
 }
 
 static inline ino_t
-- 
2.7.0

[toc] | [prev] | [next] | [standalone]


Page 6 of 12 — ← Prev page 1 … 4 5 [6] 7 8 … 12  Next page →

Back to top | Article view | linux.kernel


csiph-web