Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1366649 > unrolled thread
| Started by | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| First post | 2016-03-29 22:20 +0200 |
| Last post | 2016-03-29 22:30 +0200 |
| Articles | 20 on this page of 34 — 2 participants |
Back to article view | Back to linux.kernel
[PATCH 3.2 00/62] 3.2.79-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
[PATCH 3.2 27/62] USB: option: add support for SIM7100E Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
[PATCH 3.2 13/62] xen/pciback: Check PF instead of VF for PCI_COMMAND_MEMORY Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
[PATCH 3.2 12/62] libata: fix HDIO_GET_32BIT ioctl Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
[PATCH 3.2 52/62] ALSA: seq: oss: Don't drain at closing a client Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
[PATCH 3.2 41/62] ipr: Fix out-of-bounds null overwrite Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
[PATCH 3.2 20/62] af_unix: Don't set err in unix_stream_read_generic unless there was an error Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
[PATCH 3.2 21/62] af_unix: Guard against other == sk in unix_dgram_sendmsg Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
[PATCH 3.2 35/62] sunrpc/cache: fix off-by-one in qword_get() Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
[PATCH 3.2 42/62] ipr: Fix regression when loading firmware Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
[PATCH 3.2 15/62] xen/pcifront: Fix mysterious crashes when NUMA locality information was extracted. Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
[PATCH 3.2 50/62] ASoC: wm8994: Fix enum ctl accesses in a wrong type Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
[PATCH 3.2 49/62] ASoC: wm8958: Fix enum ctl accesses in a wrong type Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
[PATCH 3.2 57/62] ubi: Fix out of bounds write in volume update code Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 03/62] iommu/vt-d: Fix 64-bit accesses to 32-bit DMAR_GSTS_REG Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 45/62] ALSA: timer: Fix broken compat timer user status ioctl Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 05/62] cfg80211/wext: fix message ordering Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 14/62] xen/pciback: Save the number of MSI-X entries to be copied later. Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 18/62] tracing: Fix freak link error caused by branch tracer Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 16/62] ALSA: seq: Fix leak of pool buffer at concurrent writes Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 62/62] HID: usbhid: fix recursive deadlock Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 08/62] drm/i915: fix error path in intel_setup_gmbus() Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 19/62] ALSA: seq: Fix double port list deletion Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 58/62] Revert "drm/radeon: call hpd_irq_event on resume" Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 10/62] s390/dasd: prevent incorrect length error under z/VM after PAV changes Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 07/62] nfs: fix nfs_size_to_loff_t Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 04/62] wext: fix message delay/ordering Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 06/62] mac80211: fix use of uninitialised values in RX aggregation Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 46/62] ALSA: hdspm: Fix wrong boolean ctl value accesses Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 01/62] Revert "crypto: algif_skcipher - Do not dereference ctx without socket lock" Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
[PATCH 3.2 17/62] tracepoints: Do not trace when cpu is offline Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
Re: [PATCH 3.2 00/62] 3.2.79-rc1 review Guenter Roeck <linux@roeck-us.net> - 2016-03-29 22:30 +0200
Re: [PATCH 3.2 00/62] 3.2.79-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 23:10 +0200
[PATCH 3.2 02/62] crypto: {blk,giv}cipher: Set has_setkey Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
Page 1 of 2 [1] 2 Next page →
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:20 +0200 |
| Subject | [PATCH 3.2 00/62] 3.2.79-rc1 review |
| Message-ID | <ri87D-2Ps-3@gated-at.bofh.it> |
This is the start of the stable review cycle for the 3.2.79 release.
There are 62 patches in this series, which will be posted as responses
to this one. If anyone has any issues with these being applied, please
let me know.
Responses should be made by Thu Mar 31 22:00:00 UTC 2016.
Anything received after that time might be too late.
A combined patch relative to 3.2.78 will be posted as an additional
response to this. A shortlog and diffstat can be found below.
Ben.
-------------
Alexandra Yates (1):
Adding Intel Lewisburg device IDs for SATA
[f5bdd66c705484b4bc77eb914be15c1b7881fae7]
Amir Vadai (1):
net/mlx4_en: Count HW buffer overrun only once
[281e8b2fdf8e4ef366b899453cae50e09b577ada]
Andrea Arcangeli (1):
mm: thp: fix SMP race condition between THP page fault and MADV_DONTNEED
[ad33bb04b2a6cee6c1f99fabb15cddbf93ff0433]
Andrey Skvortsov (1):
USB: option: add support for SIM7100E
[3158a8d416f4e1b79dcc867d67cb50013140772c]
Anton Protopopov (1):
cifs: fix erroneous return value
[4b550af519854421dfec9f7732cdddeb057134b2]
Arnd Bergmann (2):
libata: fix HDIO_GET_32BIT ioctl
[287e6611ab1eac76c2c5ebf6e345e04c80ca9c61]
tracing: Fix freak link error caused by branch tracer
[b33c8ff4431a343561e2319f17c14286f2aa52e2]
Ben Hutchings (2):
Revert "crypto: algif_skcipher - Do not dereference ctx without socket lock"
[not upstream; reverting a broken backport]
crypto: {blk,giv}cipher: Set has_setkey
[a1383cd86a062fc798899ab20f0ec2116cce39cb]
Benjamin Poirier (1):
mld, igmp: Fix reserved tailroom calculation
[1837b2e2bcd23137766555a63867e649c0b637f0]
Bjørn Mork (1):
USB: option: add "4G LTE usb-modem U901"
[d061c1caa31d4d9792cfe48a2c6b309a0e01ef46]
CQ Tang (1):
iommu/vt-d: Fix 64-bit accesses to 32-bit DMAR_GSTS_REG
[fda3bec12d0979aae3f02ee645913d66fbc8a26e]
Chris Bainbridge (1):
mac80211: fix use of uninitialised values in RX aggregation
[f39ea2690bd61efec97622c48323f40ed6e16317]
Christian Borntraeger (1):
KVM: async_pf: do not warn on page allocation failures
[d7444794a02ff655eda87e3cc54e86b940e7736f]
Christoph Hellwig (1):
nfs: fix nfs_size_to_loff_t
[50ab8ec74a153eb30db26529088bc57dd700b24c]
David Woodhouse (2):
Fix directory hardlinks from deleted directories
[be629c62a603e5935f8177fd8a19e014100a259e]
jffs2: Fix page lock / f->sem deadlock
[49e91e7079febe59a20ca885a87dd1c54240d0f1]
Felix Fietkau (1):
mac80211: minstrel_ht: set default tx aggregation timeout to 0
[7a36b930e6ed4702c866dc74a5ad07318a57c688]
Gabriel Krisman Bertazi (1):
ipr: Fix regression when loading firmware
[21b81716c6bff24cda52dc75588455f879ddbfe9]
Gerhard Uttenthaler (1):
can: ems_usb: Fix possible tx overflow
[90cfde46586d2286488d8ed636929e936c0c9ab2]
H. Peter Anvin (1):
x86, extable: Remove open-coded exception table entries in arch/x86/lib/copy_user_nocache_64.S
[0d8559feafbc9dc5a2c17ba42aea7de824b18308]
Harvey Hunt (1):
libata: Align ata_device's id on a cacheline
[4ee34ea3a12396f35b26d90a094c75db95080baa]
Insu Yun (1):
ipr: Fix out-of-bounds null overwrite
[d63c7dd5bcb9441af0526d370c43a65ca2c980d9]
Ioan-Adrian Ratiu (1):
HID: usbhid: fix recursive deadlock
[e470127e9606b1fa151c4184243e61296d1e0c0f]
Jan Kara (1):
ext4: fix bh->b_state corruption
[ed8ad83808f009ade97ebbf6519bc3a97fefbc0c]
Johannes Berg (2):
cfg80211/wext: fix message ordering
[cb150b9d23be6ee7f3a0fff29784f1c5b5ac514d]
wext: fix message delay/ordering
[8bf862739a7786ae72409220914df960a0aa80d8]
John Youn (1):
usb: dwc3: Fix assignment of EP transfer resources
[c450960187f45d4260db87c7dd4fc0bceb5565d8]
Ken Lin (1):
USB: cp210x: add IDs for GE B650V3 and B850V3 boards
[6627ae19385283b89356a199d7f03c75ba35fb29]
Konrad Rzeszutek Wilk (3):
xen/pciback: Check PF instead of VF for PCI_COMMAND_MEMORY
[8d47065f7d1980dde52abb874b301054f3013602]
xen/pciback: Save the number of MSI-X entries to be copied later.
[d159457b84395927b5a52adb72f748dd089ad5e5]
xen/pcifront: Fix mysterious crashes when NUMA locality information was extracted.
[4d8c8bd6f2062c9988817183a91fe2e623c8aa5e]
Linus Torvalds (1):
Revert "drm/radeon: call hpd_irq_event on resume"
[256faedcfd646161477d47a1a78c32a562d2e845]
Maciej W. Rozycki (1):
MIPS: traps: Fix SIGFPE information leak from `do_ov' and `do_trap_or_bp'
[e723e3f7f9591b79e8c56b3d7c5a204a9c571b55]
Martin Schwidefsky (1):
s390/mm: four page table levels vs. fork
[3446c13b268af86391d06611327006b059b8bab1]
Mikulas Patocka (1):
hpfs: don't truncate the file when delete fails
[b6853f78e763d42c7a158d8de3549c9827c604ab]
Or Gerlitz (1):
IB/core: Use GRH when the path hop-limit > 0
[11d8d645343efba0c975aefe7c2cf3b33c836c75]
Rainer Weikusat (2):
af_unix: Don't set err in unix_stream_read_generic unless there was an error
[1b92ee3d03af6643df395300ba7748f19ecdb0c5]
af_unix: Guard against other == sk in unix_dgram_sendmsg
[a5527dda344fff0514b7989ef7a755729769daa1]
Rasmus Villemoes (1):
drm/i915: fix error path in intel_setup_gmbus()
[2417c8c03f508841b85bf61acc91836b7b0e2560]
Richard Weinberger (1):
ubi: Fix out of bounds write in volume update code
[e4f6daac20332448529b11f09388f1d55ef2084c]
Simon Guinot (1):
kernel/resource.c: fix muxed resource handling in __request_region()
[59ceeaaf355fa0fb16558ef7c24413c804932ada]
Stefan Haberland (2):
s390/dasd: fix refcount for PAV reassignment
[9d862ababb609439c5d6987f6d3ddd09e703aa0b]
s390/dasd: prevent incorrect length error under z/VM after PAV changes
[020bf042e5b397479c1174081b935d0ff15d1a64]
Stefan Hajnoczi (1):
sunrpc/cache: fix off-by-one in qword_get()
[b7052cd7bcf3c1478796e93e3dff2b44c9e82943]
Steven Rostedt (1):
tracepoints: Do not trace when cpu is offline
[f37755490fe9bf76f6ba1d8c6591745d3574a6a6]
Takashi Iwai (8):
ALSA: hdsp: Fix wrong boolean ctl value accesses
[eab3c4db193f5fcccf70e884de9a922ca2c63d80]
ALSA: hdspm: Fix wrong boolean ctl value accesses
[537e48136295c5860a92138c5ea3959b9542868b]
ALSA: seq: Fix double port list deletion
[13d5e5d4725c64ec06040d636832e78453f477b7]
ALSA: seq: Fix leak of pool buffer at concurrent writes
[d99a36f4728fcbcc501b78447f625bdcce15b842]
ALSA: seq: oss: Don't drain at closing a client
[197b958c1e76a575d77038cc98b4bebc2134279f]
ALSA: timer: Fix broken compat timer user status ioctl
[3a72494ac2a3bd229db941d51e7efe2f6ccd947b]
ASoC: wm8958: Fix enum ctl accesses in a wrong type
[d0784829ae3b0beeb69b476f017d5c8a2eb95198]
ASoC: wm8994: Fix enum ctl accesses in a wrong type
[8019c0b37cd5a87107808300a496388b777225bf]
Thomas Betker (1):
Revert "jffs2: Fix lock acquisition order bug in jffs2_write_begin"
[157078f64b8a9cd7011b6b900b2f2498df850748]
Todd E Brandt (1):
PM / sleep / x86: Fix crash on graph trace through x86 suspend
[92f9e179a702a6adbc11e2fedc76ecd6ffc9e3f7]
Toshi Kani (2):
x86/uaccess/64: Handle the caching of 4-byte nocache copies properly in __copy_user_nocache()
[a82eee7424525e34e98d821dd059ce14560a1e35]
x86/uaccess/64: Make the __copy_user_nocache() assembly code more readable
[ee9737c924706aaa72c2ead93e3ad5644681dc1c]
Vasily Kulikov (1):
include/linux/poison.h: fix LIST_POISON{1,2} offset
[8a5e5e02fc83aaf67053ab53b359af08c6c49aaf]
Vittorio Alfieri (1):
USB: cp210x: Add ID for Parrot NMEA GPS Flight Recorder
[3c4c615d70c8cbdc8ba8c79ed702640930652a79]
Vladis Dronov (1):
Input: aiptek - fix crash on detecting device without endpoints
[8e20cf2bce122ce9262d6034ee5d5b76fbb92f96]
Yegor Yefremov (1):
USB: serial: option: add support for Quectel UC20
[c0992d0f54847d0d1d85c60fcaa054f175ab1ccd]
Makefile | 4 +-
arch/mips/kernel/traps.c | 13 ++-
arch/s390/include/asm/mmu_context.h | 20 ++--
arch/s390/include/asm/pgalloc.h | 3 -
arch/x86/kernel/acpi/sleep.c | 7 ++
arch/x86/lib/copy_user_nocache_64.S | 152 ++++++++++++++++++---------
crypto/ablkcipher.c | 1 +
crypto/algif_skcipher.c | 5 +-
crypto/blkcipher.c | 1 +
drivers/ata/ahci.c | 6 ++
drivers/ata/libata-scsi.c | 11 +-
drivers/gpu/drm/i915/intel_i2c.c | 2 +-
drivers/gpu/drm/radeon/radeon_device.c | 1 -
drivers/hid/usbhid/hid-core.c | 4 +-
drivers/infiniband/core/sa_query.c | 2 +-
drivers/input/tablet/aiptek.c | 9 ++
drivers/iommu/dmar.c | 2 +-
drivers/iommu/intr_remapping.c | 2 +-
drivers/mtd/ubi/upd.c | 2 +-
drivers/net/can/usb/ems_usb.c | 14 ++-
drivers/net/ethernet/mellanox/mlx4/en_port.c | 4 +-
drivers/pci/xen-pcifront.c | 10 +-
drivers/s390/block/dasd_alias.c | 23 ++--
drivers/scsi/ipr.c | 10 +-
drivers/usb/dwc3/core.h | 1 -
drivers/usb/dwc3/ep0.c | 5 -
drivers/usb/dwc3/gadget.c | 70 ++++++++----
drivers/usb/serial/cp210x.c | 3 +
drivers/usb/serial/option.c | 11 ++
drivers/xen/xen-pciback/pciback_ops.c | 9 +-
fs/cifs/cifsencrypt.c | 2 +-
fs/ext4/inode.c | 32 +++++-
fs/hpfs/namei.c | 31 +-----
fs/jffs2/README.Locking | 5 +-
fs/jffs2/build.c | 75 +++++++++----
fs/jffs2/file.c | 39 ++++---
fs/jffs2/gc.c | 17 +--
fs/jffs2/nodelist.h | 6 +-
include/linux/ata.h | 4 +-
include/linux/compiler.h | 2 +-
include/linux/libata.h | 2 +-
include/linux/nfs_fs.h | 4 +-
include/linux/poison.h | 4 +-
include/linux/skbuff.h | 24 +++++
include/linux/tracepoint.h | 5 +
include/net/iw_handler.h | 6 ++
kernel/resource.c | 5 +-
mm/memory.c | 14 ++-
net/ipv4/igmp.c | 3 +-
net/ipv6/mcast.c | 3 +-
net/mac80211/agg-rx.c | 2 +-
net/mac80211/rc80211_minstrel_ht.c | 2 +-
net/sunrpc/cache.c | 2 +-
net/unix/af_unix.c | 23 ++--
net/wireless/core.c | 4 +
net/wireless/wext-core.c | 52 +++++++--
sound/core/seq/oss/seq_oss.c | 2 -
sound/core/seq/oss/seq_oss_device.h | 1 -
sound/core/seq/oss/seq_oss_init.c | 17 ---
sound/core/seq/seq_memory.c | 13 ++-
sound/core/seq/seq_ports.c | 13 ++-
sound/core/timer_compat.c | 5 +-
sound/pci/rme9652/hdsp.c | 4 +-
sound/pci/rme9652/hdspm.c | 6 +-
sound/soc/codecs/wm8958-dsp2.c | 8 +-
sound/soc/codecs/wm8994.c | 4 +-
virt/kvm/async_pf.c | 2 +-
67 files changed, 555 insertions(+), 295 deletions(-)
--
Ben Hutchings
Tomorrow will be cancelled due to lack of interest.
[toc] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:20 +0200 |
| Subject | [PATCH 3.2 27/62] USB: option: add support for SIM7100E |
| Message-ID | <ri8hl-2Tk-45@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Andrey Skvortsov <andrej.skvortzov@gmail.com>
commit 3158a8d416f4e1b79dcc867d67cb50013140772c upstream.
$ lsusb:
Bus 001 Device 101: ID 1e0e:9001 Qualcomm / Option
$ usb-devices:
T: Bus=01 Lev=02 Prnt=02 Port=00 Cnt=01 Dev#=101 Spd=480 MxCh= 0
D: Ver= 2.00 Cls=00(>ifc ) Sub=00 Prot=00 MxPS=64 #Cfgs= 2
P: Vendor=1e0e ProdID=9001 Rev= 2.32
S: Manufacturer=SimTech, Incorporated
S: Product=SimTech, Incorporated
S: SerialNumber=0123456789ABCDEF
C:* #Ifs= 7 Cfg#= 1 Atr=80 MxPwr=500mA
I:* If#= 0 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=ff Driver=option
I:* If#= 1 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
I:* If#= 2 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
I:* If#= 3 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
I:* If#= 4 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
I:* If#= 5 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=ff Driver=qmi_wwan
I:* If#= 6 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=42 Prot=01 Driver=(none)
The last interface (6) is used for Android Composite ADB interface.
Serial port layout:
0: QCDM/DIAG
1: NMEA
2: AT
3: AT/PPP
4: audio
Signed-off-by: Andrey Skvortsov <andrej.skvortzov@gmail.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/usb/serial/option.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/drivers/usb/serial/option.c
+++ b/drivers/usb/serial/option.c
@@ -316,6 +316,7 @@ static void option_instat_callback(struc
#define TOSHIBA_PRODUCT_G450 0x0d45
#define ALINK_VENDOR_ID 0x1e0e
+#define SIMCOM_PRODUCT_SIM7100E 0x9001 /* Yes, ALINK_VENDOR_ID */
#define ALINK_PRODUCT_PH300 0x9100
#define ALINK_PRODUCT_3GU 0x9200
@@ -613,6 +614,10 @@ static const struct option_blacklist_inf
.reserved = BIT(3) | BIT(4),
};
+static const struct option_blacklist_info simcom_sim7100e_blacklist = {
+ .reserved = BIT(5) | BIT(6),
+};
+
static const struct option_blacklist_info telit_le910_blacklist = {
.sendsetup = BIT(0),
.reserved = BIT(1) | BIT(2),
@@ -1644,6 +1649,8 @@ static const struct usb_device_id option
{ USB_DEVICE(ALINK_VENDOR_ID, 0x9000) },
{ USB_DEVICE(ALINK_VENDOR_ID, ALINK_PRODUCT_PH300) },
{ USB_DEVICE_AND_INTERFACE_INFO(ALINK_VENDOR_ID, ALINK_PRODUCT_3GU, 0xff, 0xff, 0xff) },
+ { USB_DEVICE(ALINK_VENDOR_ID, SIMCOM_PRODUCT_SIM7100E),
+ .driver_info = (kernel_ulong_t)&simcom_sim7100e_blacklist },
{ USB_DEVICE(ALCATEL_VENDOR_ID, ALCATEL_PRODUCT_X060S_X200),
.driver_info = (kernel_ulong_t)&alcatel_x200_blacklist
},
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:20 +0200 |
| Subject | [PATCH 3.2 13/62] xen/pciback: Check PF instead of VF for PCI_COMMAND_MEMORY |
| Message-ID | <ri8hl-2Tk-53@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know. ------------------ From: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com> commit 8d47065f7d1980dde52abb874b301054f3013602 upstream. Commit 408fb0e5aa7fda0059db282ff58c3b2a4278baa0 (xen/pciback: Don't allow MSI-X ops if PCI_COMMAND_MEMORY is not set) prevented enabling MSI-X on passed-through virtual functions, because it checked the VF for PCI_COMMAND_MEMORY but this is not a valid bit for VFs. Instead, check the physical function for PCI_COMMAND_MEMORY. Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com> Reviewed-by: Jan Beulich <jbeulich@suse.com> Signed-off-by: David Vrabel <david.vrabel@citrix.com> Signed-off-by: Ben Hutchings <ben@decadent.org.uk> --- drivers/xen/xen-pciback/pciback_ops.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) --- a/drivers/xen/xen-pciback/pciback_ops.c +++ b/drivers/xen/xen-pciback/pciback_ops.c @@ -225,8 +225,9 @@ int xen_pcibk_enable_msix(struct xen_pci /* * PCI_COMMAND_MEMORY must be enabled, otherwise we may not be able * to access the BARs where the MSI-X entries reside. + * But VF devices are unique in which the PF needs to be checked. */ - pci_read_config_word(dev, PCI_COMMAND, &cmd); + pci_read_config_word(pci_physfn(dev), PCI_COMMAND, &cmd); if (dev->msi_enabled || !(cmd & PCI_COMMAND_MEMORY)) return -ENXIO;
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:20 +0200 |
| Subject | [PATCH 3.2 12/62] libata: fix HDIO_GET_32BIT ioctl |
| Message-ID | <ri8hl-2Tk-51@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Arnd Bergmann <arnd@arndb.de>
commit 287e6611ab1eac76c2c5ebf6e345e04c80ca9c61 upstream.
As reported by Soohoon Lee, the HDIO_GET_32BIT ioctl does not
work correctly in compat mode with libata.
I have investigated the issue further and found multiple problems
that all appeared with the same commit that originally introduced
HDIO_GET_32BIT handling in libata back in linux-2.6.8 and presumably
also linux-2.4, as the code uses "copy_to_user(arg, &val, 1)" to copy
a 'long' variable containing either 0 or 1 to user space.
The problems with this are:
* On big-endian machines, this will always write a zero because it
stores the wrong byte into user space.
* In compat mode, the upper three bytes of the variable are updated
by the compat_hdio_ioctl() function, but they now contain
uninitialized stack data.
* The hdparm tool calling this ioctl uses a 'static long' variable
to store the result. This means at least the upper bytes are
initialized to zero, but calling another ioctl like HDIO_GET_MULTCOUNT
would fill them with data that remains stale when the low byte
is overwritten. Fortunately libata doesn't implement any of the
affected ioctl commands, so this would only happen when we query
both an IDE and an ATA device in the same command such as
"hdparm -N -c /dev/hda /dev/sda"
* The libata code for unknown reasons started using ATA_IOC_GET_IO32
and ATA_IOC_SET_IO32 as aliases for HDIO_GET_32BIT and HDIO_SET_32BIT,
while the ioctl commands that were added later use the normal
HDIO_* names. This is harmless but rather confusing.
This addresses all four issues by changing the code to use put_user()
on an 'unsigned long' variable in HDIO_GET_32BIT, like the IDE subsystem
does, and by clarifying the names of the ioctl commands.
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Reported-by: Soohoon Lee <Soohoon.Lee@f5.com>
Tested-by: Soohoon Lee <Soohoon.Lee@f5.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/ata/libata-scsi.c | 11 +++++------
include/linux/ata.h | 4 ++--
2 files changed, 7 insertions(+), 8 deletions(-)
--- a/drivers/ata/libata-scsi.c
+++ b/drivers/ata/libata-scsi.c
@@ -672,19 +672,18 @@ static int ata_ioc32(struct ata_port *ap
int ata_sas_scsi_ioctl(struct ata_port *ap, struct scsi_device *scsidev,
int cmd, void __user *arg)
{
- int val = -EINVAL, rc = -EINVAL;
+ unsigned long val;
+ int rc = -EINVAL;
unsigned long flags;
switch (cmd) {
- case ATA_IOC_GET_IO32:
+ case HDIO_GET_32BIT:
spin_lock_irqsave(ap->lock, flags);
val = ata_ioc32(ap);
spin_unlock_irqrestore(ap->lock, flags);
- if (copy_to_user(arg, &val, 1))
- return -EFAULT;
- return 0;
+ return put_user(val, (unsigned long __user *)arg);
- case ATA_IOC_SET_IO32:
+ case HDIO_SET_32BIT:
val = (unsigned long) arg;
rc = 0;
spin_lock_irqsave(ap->lock, flags);
--- a/include/linux/ata.h
+++ b/include/linux/ata.h
@@ -464,8 +464,8 @@ enum ata_tf_protocols {
};
enum ata_ioctls {
- ATA_IOC_GET_IO32 = 0x309,
- ATA_IOC_SET_IO32 = 0x324,
+ ATA_IOC_GET_IO32 = 0x309, /* HDIO_GET_32BIT */
+ ATA_IOC_SET_IO32 = 0x324, /* HDIO_SET_32BIT */
};
/* core structures */
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:20 +0200 |
| Subject | [PATCH 3.2 52/62] ALSA: seq: oss: Don't drain at closing a client |
| Message-ID | <ri8hl-2Tk-55@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit 197b958c1e76a575d77038cc98b4bebc2134279f upstream.
The OSS sequencer client tries to drain the pending events at
releasing. Unfortunately, as spotted by syzkaller fuzzer, this may
lead to an unkillable process state when the event has been queued at
the far future. Since the process being released can't be signaled
any longer, it remains and waits for the echo-back event in that far
future.
Back to history, the draining feature was implemented at the time we
misinterpreted POSIX definition for blocking file operation.
Actually, such a behavior is superfluous at release, and we should
just release the device as is instead of keeping it up forever.
This patch just removes the draining call that may block the release
for too long time unexpectedly.
BugLink: http://lkml.kernel.org/r/CACT4Y+Y4kD-aBGj37rf-xBw9bH3GMU6P+MYg4W1e-s-paVD2pg@mail.gmail.com
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
[bwh: Backported to 3.2: snd_seq_oss_drain_write() has an extra log statement
to be deleted]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
sound/core/seq/oss/seq_oss.c | 2 --
sound/core/seq/oss/seq_oss_device.h | 1 -
sound/core/seq/oss/seq_oss_init.c | 16 ----------------
3 files changed, 19 deletions(-)
--- a/sound/core/seq/oss/seq_oss.c
+++ b/sound/core/seq/oss/seq_oss.c
@@ -150,8 +150,6 @@ odev_release(struct inode *inode, struct
if ((dp = file->private_data) == NULL)
return 0;
- snd_seq_oss_drain_write(dp);
-
mutex_lock(®ister_mutex);
snd_seq_oss_release(dp);
mutex_unlock(®ister_mutex);
--- a/sound/core/seq/oss/seq_oss_device.h
+++ b/sound/core/seq/oss/seq_oss_device.h
@@ -131,7 +131,6 @@ int snd_seq_oss_write(struct seq_oss_dev
unsigned int snd_seq_oss_poll(struct seq_oss_devinfo *dp, struct file *file, poll_table * wait);
void snd_seq_oss_reset(struct seq_oss_devinfo *dp);
-void snd_seq_oss_drain_write(struct seq_oss_devinfo *dp);
/* */
void snd_seq_oss_process_queue(struct seq_oss_devinfo *dp, abstime_t time);
--- a/sound/core/seq/oss/seq_oss_init.c
+++ b/sound/core/seq/oss/seq_oss_init.c
@@ -447,23 +447,6 @@ snd_seq_oss_release(struct seq_oss_devin
/*
- * Wait until the queue is empty (if we don't have nonblock)
- */
-void
-snd_seq_oss_drain_write(struct seq_oss_devinfo *dp)
-{
- if (! dp->timer->running)
- return;
- if (is_write_mode(dp->file_mode) && !is_nonblock_mode(dp->file_mode) &&
- dp->writeq) {
- debug_printk(("syncing..\n"));
- while (snd_seq_oss_writeq_sync(dp->writeq))
- ;
- }
-}
-
-
-/*
* reset sequencer devices
*/
void
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:20 +0200 |
| Subject | [PATCH 3.2 41/62] ipr: Fix out-of-bounds null overwrite |
| Message-ID | <ri8hl-2Tk-57@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Insu Yun <wuninsu@gmail.com>
commit d63c7dd5bcb9441af0526d370c43a65ca2c980d9 upstream.
Return value of snprintf is not bound by size value, 2nd argument.
(https://www.kernel.org/doc/htmldocs/kernel-api/API-snprintf.html).
Return value is number of printed chars, can be larger than 2nd
argument. Therefore, it can write null byte out of bounds ofbuffer.
Since snprintf puts null, it does not need to put additional null byte.
Signed-off-by: Insu Yun <wuninsu@gmail.com>
Reviewed-by: Shane Seymour <shane.seymour@hpe.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/scsi/ipr.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
--- a/drivers/scsi/ipr.c
+++ b/drivers/scsi/ipr.c
@@ -3736,13 +3736,12 @@ static ssize_t ipr_store_update_fw(struc
struct ipr_sglist *sglist;
char fname[100];
char *src;
- int len, result, dnld_size;
+ int result, dnld_size;
if (!capable(CAP_SYS_ADMIN))
return -EACCES;
- len = snprintf(fname, 99, "%s", buf);
- fname[len-1] = '\0';
+ snprintf(fname, sizeof(fname), "%s", buf);
if(request_firmware(&fw_entry, fname, &ioa_cfg->pdev->dev)) {
dev_err(&ioa_cfg->pdev->dev, "Firmware file %s not found\n", fname);
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:20 +0200 |
| Subject | [PATCH 3.2 20/62] af_unix: Don't set err in unix_stream_read_generic unless there was an error |
| Message-ID | <ri8hl-2Tk-59@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Rainer Weikusat <rweikusat@mobileactivedefense.com>
commit 1b92ee3d03af6643df395300ba7748f19ecdb0c5 upstream.
The present unix_stream_read_generic contains various code sequences of
the form
err = -EDISASTER;
if (<test>)
goto out;
This has the unfortunate side effect of possibly causing the error code
to bleed through to the final
out:
return copied ? : err;
and then to be wrongly returned if no data was copied because the caller
didn't supply a data buffer, as demonstrated by the program available at
http://pad.lv/1540731
Change it such that err is only set if an error condition was detected.
Fixes: 3822b5c2fc62 ("af_unix: Revert 'lock_interruptible' in stream receive code")
Reported-by: Joseph Salisbury <joseph.salisbury@canonical.com>
Signed-off-by: Rainer Weikusat <rweikusat@mobileactivedefense.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
net/unix/af_unix.c | 16 ++++++++++------
1 file changed, 10 insertions(+), 6 deletions(-)
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -2059,13 +2059,15 @@ static int unix_stream_recvmsg(struct ki
int err = 0;
long timeo;
- err = -EINVAL;
- if (sk->sk_state != TCP_ESTABLISHED)
+ if (unlikely(sk->sk_state != TCP_ESTABLISHED)) {
+ err = -EINVAL;
goto out;
+ }
- err = -EOPNOTSUPP;
- if (flags&MSG_OOB)
+ if (unlikely(flags & MSG_OOB)) {
+ err = -EOPNOTSUPP;
goto out;
+ }
target = sock_rcvlowat(sk, flags&MSG_WAITALL, size);
timeo = sock_rcvtimeo(sk, noblock);
@@ -2107,9 +2109,11 @@ static int unix_stream_recvmsg(struct ki
goto unlock;
unix_state_unlock(sk);
- err = -EAGAIN;
- if (!timeo)
+ if (!timeo) {
+ err = -EAGAIN;
break;
+ }
+
mutex_unlock(&u->readlock);
timeo = unix_stream_data_wait(sk, timeo);
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:20 +0200 |
| Subject | [PATCH 3.2 21/62] af_unix: Guard against other == sk in unix_dgram_sendmsg |
| Message-ID | <ri8hl-2Tk-61@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Rainer Weikusat <rweikusat@mobileactivedefense.com>
commit a5527dda344fff0514b7989ef7a755729769daa1 upstream.
The unix_dgram_sendmsg routine use the following test
if (unlikely(unix_peer(other) != sk && unix_recvq_full(other))) {
to determine if sk and other are in an n:1 association (either
established via connect or by using sendto to send messages to an
unrelated socket identified by address). This isn't correct as the
specified address could have been bound to the sending socket itself or
because this socket could have been connected to itself by the time of
the unix_peer_get but disconnected before the unix_state_lock(other). In
both cases, the if-block would be entered despite other == sk which
might either block the sender unintentionally or lead to trying to unlock
the same spin lock twice for a non-blocking send. Add a other != sk
check to guard against this.
Fixes: 7d267278a9ec ("unix: avoid use-after-free in ep_remove_wait_queue")
Reported-By: Philipp Hahn <pmhahn@pmhahn.de>
Signed-off-by: Rainer Weikusat <rweikusat@mobileactivedefense.com>
Tested-by: Philipp Hahn <pmhahn@pmhahn.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
net/unix/af_unix.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -1694,7 +1694,12 @@ restart_locked:
goto out_unlock;
}
- if (unlikely(unix_peer(other) != sk && unix_recvq_full(other))) {
+ /* other == sk && unix_peer(other) != sk if
+ * - unix_peer(sk) == NULL, destination address bound to sk
+ * - unix_peer(sk) == sk by time of get but disconnected before lock
+ */
+ if (other != sk &&
+ unlikely(unix_peer(other) != sk && unix_recvq_full(other))) {
if (timeo) {
timeo = unix_wait_for_peer(other, timeo);
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:20 +0200 |
| Subject | [PATCH 3.2 35/62] sunrpc/cache: fix off-by-one in qword_get() |
| Message-ID | <ri8hm-2Tk-69@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Stefan Hajnoczi <stefanha@redhat.com>
commit b7052cd7bcf3c1478796e93e3dff2b44c9e82943 upstream.
The qword_get() function NUL-terminates its output buffer. If the input
string is in hex format \xXXXX... and the same length as the output
buffer, there is an off-by-one:
int qword_get(char **bpp, char *dest, int bufsize)
{
...
while (len < bufsize) {
...
*dest++ = (h << 4) | l;
len++;
}
...
*dest = '\0';
return len;
}
This patch ensures the NUL terminator doesn't fall outside the output
buffer.
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
net/sunrpc/cache.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/sunrpc/cache.c
+++ b/net/sunrpc/cache.c
@@ -1211,7 +1211,7 @@ int qword_get(char **bpp, char *dest, in
if (bp[0] == '\\' && bp[1] == 'x') {
/* HEX STRING */
bp += 2;
- while (len < bufsize) {
+ while (len < bufsize - 1) {
int h, l;
h = hex_to_bin(bp[0]);
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:20 +0200 |
| Subject | [PATCH 3.2 42/62] ipr: Fix regression when loading firmware |
| Message-ID | <ri8hm-2Tk-77@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Gabriel Krisman Bertazi <krisman@linux.vnet.ibm.com>
commit 21b81716c6bff24cda52dc75588455f879ddbfe9 upstream.
Commit d63c7dd5bcb9 ("ipr: Fix out-of-bounds null overwrite") removed
the end of line handling when storing the update_fw sysfs attribute.
This changed the userpace API because it started refusing writes
terminated by a line feed, which broke the update tools we already have.
This patch re-adds that handling, so both a write terminated by a line
feed or not can make it through with the update.
Fixes: d63c7dd5bcb9 ("ipr: Fix out-of-bounds null overwrite")
Signed-off-by: Gabriel Krisman Bertazi <krisman@linux.vnet.ibm.com>
Cc: Insu Yun <wuninsu@gmail.com>
Acked-by: Brian King <brking@linux.vnet.ibm.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/scsi/ipr.c | 5 +++++
1 file changed, 5 insertions(+)
--- a/drivers/scsi/ipr.c
+++ b/drivers/scsi/ipr.c
@@ -3736,6 +3736,7 @@ static ssize_t ipr_store_update_fw(struc
struct ipr_sglist *sglist;
char fname[100];
char *src;
+ char *endline;
int result, dnld_size;
if (!capable(CAP_SYS_ADMIN))
@@ -3743,6 +3744,10 @@ static ssize_t ipr_store_update_fw(struc
snprintf(fname, sizeof(fname), "%s", buf);
+ endline = strchr(fname, '\n');
+ if (endline)
+ *endline = '\0';
+
if(request_firmware(&fw_entry, fname, &ioa_cfg->pdev->dev)) {
dev_err(&ioa_cfg->pdev->dev, "Firmware file %s not found\n", fname);
return -EIO;
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:20 +0200 |
| Subject | [PATCH 3.2 15/62] xen/pcifront: Fix mysterious crashes when NUMA locality information was extracted. |
| Message-ID | <ri8hl-2Tk-65@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
commit 4d8c8bd6f2062c9988817183a91fe2e623c8aa5e upstream.
Occasionaly PV guests would crash with:
pciback 0000:00:00.1: Xen PCI mapped GSI0 to IRQ16
BUG: unable to handle kernel paging request at 0000000d1a8c0be0
.. snip..
<ffffffff8139ce1b>] find_next_bit+0xb/0x10
[<ffffffff81387f22>] cpumask_next_and+0x22/0x40
[<ffffffff813c1ef8>] pci_device_probe+0xb8/0x120
[<ffffffff81529097>] ? driver_sysfs_add+0x77/0xa0
[<ffffffff815293e4>] driver_probe_device+0x1a4/0x2d0
[<ffffffff813c1ddd>] ? pci_match_device+0xdd/0x110
[<ffffffff81529657>] __device_attach_driver+0xa7/0xb0
[<ffffffff815295b0>] ? __driver_attach+0xa0/0xa0
[<ffffffff81527622>] bus_for_each_drv+0x62/0x90
[<ffffffff8152978d>] __device_attach+0xbd/0x110
[<ffffffff815297fb>] device_attach+0xb/0x10
[<ffffffff813b75ac>] pci_bus_add_device+0x3c/0x70
[<ffffffff813b7618>] pci_bus_add_devices+0x38/0x80
[<ffffffff813dc34e>] pcifront_scan_root+0x13e/0x1a0
[<ffffffff817a0692>] pcifront_backend_changed+0x262/0x60b
[<ffffffff814644c6>] ? xenbus_gather+0xd6/0x160
[<ffffffff8120900f>] ? put_object+0x2f/0x50
[<ffffffff81465c1d>] xenbus_otherend_changed+0x9d/0xa0
[<ffffffff814678ee>] backend_changed+0xe/0x10
[<ffffffff81463a28>] xenwatch_thread+0xc8/0x190
[<ffffffff810f22f0>] ? woken_wake_function+0x10/0x10
which was the result of two things:
When we call pci_scan_root_bus we would pass in 'sd' (sysdata)
pointer which was an 'pcifront_sd' structure. However in the
pci_device_add it expects that the 'sd' is 'struct sysdata' and
sets the dev->node to what is in sd->node (offset 4):
set_dev_node(&dev->dev, pcibus_to_node(bus));
__pcibus_to_node(const struct pci_bus *bus)
{
const struct pci_sysdata *sd = bus->sysdata;
return sd->node;
}
However our structure was pcifront_sd which had nothing at that
offset:
struct pcifront_sd {
int domain; /* 0 4 */
/* XXX 4 bytes hole, try to pack */
struct pcifront_device * pdev; /* 8 8 */
}
That is an hole - filled with garbage as we used kmalloc instead of
kzalloc (the second problem).
This patch fixes the issue by:
1) Use kzalloc to initialize to a well known state.
2) Put 'struct pci_sysdata' at the start of 'pcifront_sd'. That
way access to the 'node' will access the right offset.
Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Reviewed-by: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Signed-off-by: David Vrabel <david.vrabel@citrix.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/pci/xen-pcifront.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
--- a/drivers/pci/xen-pcifront.c
+++ b/drivers/pci/xen-pcifront.c
@@ -50,7 +50,7 @@ struct pcifront_device {
};
struct pcifront_sd {
- int domain;
+ struct pci_sysdata sd;
struct pcifront_device *pdev;
};
@@ -64,7 +64,9 @@ static inline void pcifront_init_sd(stru
unsigned int domain, unsigned int bus,
struct pcifront_device *pdev)
{
- sd->domain = domain;
+ /* Because we do not expose that information via XenBus. */
+ sd->sd.node = first_online_node;
+ sd->sd.domain = domain;
sd->pdev = pdev;
}
@@ -461,8 +463,8 @@ static int __devinit pcifront_scan_root(
dev_info(&pdev->xdev->dev, "Creating PCI Frontend Bus %04x:%02x\n",
domain, bus);
- bus_entry = kmalloc(sizeof(*bus_entry), GFP_KERNEL);
- sd = kmalloc(sizeof(*sd), GFP_KERNEL);
+ bus_entry = kzalloc(sizeof(*bus_entry), GFP_KERNEL);
+ sd = kzalloc(sizeof(*sd), GFP_KERNEL);
if (!bus_entry || !sd) {
err = -ENOMEM;
goto err_out;
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:20 +0200 |
| Subject | [PATCH 3.2 50/62] ASoC: wm8994: Fix enum ctl accesses in a wrong type |
| Message-ID | <ri8hm-2Tk-67@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know. ------------------ From: Takashi Iwai <tiwai@suse.de> commit 8019c0b37cd5a87107808300a496388b777225bf upstream. The DRC Mode like "AIF1DRC1 Mode" and EQ Mode like "AIF1.1 EQ Mode" in wm8994 codec driver are enum ctls, while the current driver accesses wrongly via value.integer.value[]. They have to be via value.enumerated.item[] instead. Signed-off-by: Takashi Iwai <tiwai@suse.de> Signed-off-by: Mark Brown <broonie@kernel.org> Signed-off-by: Ben Hutchings <ben@decadent.org.uk> --- sound/soc/codecs/wm8994.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) --- a/sound/soc/codecs/wm8994.c +++ b/sound/soc/codecs/wm8994.c @@ -386,7 +386,7 @@ static int wm8994_put_drc_enum(struct sn struct wm8994_priv *wm8994 = snd_soc_codec_get_drvdata(codec); struct wm8994_pdata *pdata = wm8994->pdata; int drc = wm8994_get_drc(kcontrol->id.name); - int value = ucontrol->value.integer.value[0]; + int value = ucontrol->value.enumerated.item[0]; if (drc < 0) return drc; @@ -489,7 +489,7 @@ static int wm8994_put_retune_mobile_enum struct wm8994_priv *wm8994 = snd_soc_codec_get_drvdata(codec); struct wm8994_pdata *pdata = wm8994->pdata; int block = wm8994_get_retune_mobile_block(kcontrol->id.name); - int value = ucontrol->value.integer.value[0]; + int value = ucontrol->value.enumerated.item[0]; if (block < 0) return block;
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:20 +0200 |
| Subject | [PATCH 3.2 49/62] ASoC: wm8958: Fix enum ctl accesses in a wrong type |
| Message-ID | <ri8hm-2Tk-71@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know. ------------------ From: Takashi Iwai <tiwai@suse.de> commit d0784829ae3b0beeb69b476f017d5c8a2eb95198 upstream. "MBC Mode", "VSS Mode", "VSS HPF Mode" and "Enhanced EQ Mode" ctls in wm8958 codec driver are enum, while the current driver accesses wrongly via value.integer.value[]. They have to be via value.enumerated.item[] instead. Signed-off-by: Takashi Iwai <tiwai@suse.de> Signed-off-by: Mark Brown <broonie@kernel.org> [bwh: Backported to 3.2: adjust context] Signed-off-by: Ben Hutchings <ben@decadent.org.uk> --- sound/soc/codecs/wm8958-dsp2.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) --- a/sound/soc/codecs/wm8958-dsp2.c +++ b/sound/soc/codecs/wm8958-dsp2.c @@ -458,7 +458,7 @@ static int wm8958_put_mbc_enum(struct sn struct snd_soc_codec *codec = snd_kcontrol_chip(kcontrol); struct wm8994_priv *wm8994 = snd_soc_codec_get_drvdata(codec); struct wm8994_pdata *pdata = wm8994->pdata; - int value = ucontrol->value.integer.value[0]; + int value = ucontrol->value.enumerated.item[0]; int reg; /* Don't allow on the fly reconfiguration */ @@ -548,7 +548,7 @@ static int wm8958_put_vss_enum(struct sn struct snd_soc_codec *codec = snd_kcontrol_chip(kcontrol); struct wm8994_priv *wm8994 = snd_soc_codec_get_drvdata(codec); struct wm8994_pdata *pdata = wm8994->pdata; - int value = ucontrol->value.integer.value[0]; + int value = ucontrol->value.enumerated.item[0]; int reg; /* Don't allow on the fly reconfiguration */ @@ -581,7 +581,7 @@ static int wm8958_put_vss_hpf_enum(struc struct snd_soc_codec *codec = snd_kcontrol_chip(kcontrol); struct wm8994_priv *wm8994 = snd_soc_codec_get_drvdata(codec); struct wm8994_pdata *pdata = wm8994->pdata; - int value = ucontrol->value.integer.value[0]; + int value = ucontrol->value.enumerated.item[0]; int reg; /* Don't allow on the fly reconfiguration */ @@ -748,7 +748,7 @@ static int wm8958_put_enh_eq_enum(struct struct snd_soc_codec *codec = snd_kcontrol_chip(kcontrol); struct wm8994_priv *wm8994 = snd_soc_codec_get_drvdata(codec); struct wm8994_pdata *pdata = wm8994->pdata; - int value = ucontrol->value.integer.value[0]; + int value = ucontrol->value.enumerated.item[0]; int reg; /* Don't allow on the fly reconfiguration */
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:30 +0200 |
| Subject | [PATCH 3.2 57/62] ubi: Fix out of bounds write in volume update code |
| Message-ID | <ri8r0-2Xn-1@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know. ------------------ From: Richard Weinberger <richard@nod.at> commit e4f6daac20332448529b11f09388f1d55ef2084c upstream. ubi_start_leb_change() allocates too few bytes. ubi_more_leb_change_data() will write up to req->upd_bytes + ubi->min_io_size bytes. Signed-off-by: Richard Weinberger <richard@nod.at> Reviewed-by: Boris Brezillon <boris.brezillon@free-electrons.com> Signed-off-by: Ben Hutchings <ben@decadent.org.uk> --- drivers/mtd/ubi/upd.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) --- a/drivers/mtd/ubi/upd.c +++ b/drivers/mtd/ubi/upd.c @@ -197,7 +197,7 @@ int ubi_start_leb_change(struct ubi_devi vol->ch_lnum = req->lnum; vol->ch_dtype = req->dtype; - vol->upd_buf = vmalloc(req->bytes); + vol->upd_buf = vmalloc(ALIGN((int)req->bytes, ubi->min_io_size)); if (!vol->upd_buf) return -ENOMEM;
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:30 +0200 |
| Subject | [PATCH 3.2 03/62] iommu/vt-d: Fix 64-bit accesses to 32-bit DMAR_GSTS_REG |
| Message-ID | <ri8r0-2Xn-3@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know. ------------------ From: CQ Tang <cq.tang@intel.com> commit fda3bec12d0979aae3f02ee645913d66fbc8a26e upstream. This is a 32-bit register. Apparently harmless on real hardware, but causing justified warnings in simulation. Signed-off-by: CQ Tang <cq.tang@intel.com> Signed-off-by: David Woodhouse <David.Woodhouse@intel.com> [bwh: Backported to 3.2: adjust filename] Signed-off-by: Ben Hutchings <ben@decadent.org.uk> --- drivers/iommu/dmar.c | 2 +- drivers/iommu/intr_remapping.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) --- a/drivers/iommu/dmar.c +++ b/drivers/iommu/dmar.c @@ -923,7 +923,7 @@ void dmar_disable_qi(struct intel_iommu raw_spin_lock_irqsave(&iommu->register_lock, flags); - sts = dmar_readq(iommu->reg + DMAR_GSTS_REG); + sts = readl(iommu->reg + DMAR_GSTS_REG); if (!(sts & DMA_GSTS_QIES)) goto end; --- a/drivers/iommu/intr_remapping.c +++ b/drivers/iommu/intr_remapping.c @@ -496,7 +496,7 @@ static void iommu_disable_intr_remapping raw_spin_lock_irqsave(&iommu->register_lock, flags); - sts = dmar_readq(iommu->reg + DMAR_GSTS_REG); + sts = readl(iommu->reg + DMAR_GSTS_REG); if (!(sts & DMA_GSTS_IRES)) goto end;
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:30 +0200 |
| Subject | [PATCH 3.2 45/62] ALSA: timer: Fix broken compat timer user status ioctl |
| Message-ID | <ri8r0-2Xn-11@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit 3a72494ac2a3bd229db941d51e7efe2f6ccd947b upstream.
The timer user status compat ioctl returned the bogus struct used for
64bit architectures instead of the 32bit one. This patch addresses
it to return the proper struct.
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
sound/core/timer_compat.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
--- a/sound/core/timer_compat.c
+++ b/sound/core/timer_compat.c
@@ -70,13 +70,14 @@ static int snd_timer_user_status_compat(
struct snd_timer_status32 __user *_status)
{
struct snd_timer_user *tu;
- struct snd_timer_status status;
+ struct snd_timer_status32 status;
tu = file->private_data;
if (snd_BUG_ON(!tu->timeri))
return -ENXIO;
memset(&status, 0, sizeof(status));
- status.tstamp = tu->tstamp;
+ status.tstamp.tv_sec = tu->tstamp.tv_sec;
+ status.tstamp.tv_nsec = tu->tstamp.tv_nsec;
status.resolution = snd_timer_resolution(tu->timeri);
status.lost = tu->timeri->lost;
status.overrun = tu->overrun;
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:30 +0200 |
| Subject | [PATCH 3.2 05/62] cfg80211/wext: fix message ordering |
| Message-ID | <ri8r1-2Xn-15@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
commit cb150b9d23be6ee7f3a0fff29784f1c5b5ac514d upstream.
Since cfg80211 frequently takes actions from its netdev notifier
call, wireless extensions messages could still be ordered badly
since the wext netdev notifier, since wext is built into the
kernel, runs before the cfg80211 netdev notifier. For example,
the following can happen:
5: wlan1: <BROADCAST,MULTICAST> mtu 1500 qdisc mq state DOWN group default
link/ether 02:00:00:00:01:00 brd ff:ff:ff:ff:ff:ff
5: wlan1: <BROADCAST,MULTICAST,UP>
link/ether
when setting the interface down causes the wext message.
To also fix this, export the wireless_nlevent_flush() function
and also call it from the cfg80211 notifier.
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
[bwh: Backported to 3.2:
- Add default case in cfg80211_netdev_notifier_call() which bypasses
the added wireless_nlevent_flush() (added upstream by commit
6784c7db8d43 "cfg80211: change return value of notifier function")
- Adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/include/net/iw_handler.h
+++ b/include/net/iw_handler.h
@@ -442,6 +442,12 @@ extern void wireless_send_event(struct n
unsigned int cmd,
union iwreq_data * wrqu,
const char * extra);
+#ifdef CONFIG_WEXT_CORE
+/* flush all previous wext events - if work is done from netdev notifiers */
+void wireless_nlevent_flush(void);
+#else
+static inline void wireless_nlevent_flush(void) {}
+#endif
/* We may need a function to send a stream of events to user space.
* More on that later... */
--- a/net/wireless/core.c
+++ b/net/wireless/core.c
@@ -985,8 +985,12 @@ static int cfg80211_netdev_notifier_call
if (ret)
return notifier_from_errno(ret);
break;
+ default:
+ return NOTIFY_DONE;
}
+ wireless_nlevent_flush();
+
return NOTIFY_DONE;
}
--- a/net/wireless/wext-core.c
+++ b/net/wireless/wext-core.c
@@ -342,7 +342,7 @@ static const int compat_event_type_size[
/* IW event code */
-static void wireless_nlevent_flush(void)
+void wireless_nlevent_flush(void)
{
struct sk_buff *skb;
struct net *net;
@@ -355,6 +355,7 @@ static void wireless_nlevent_flush(void)
GFP_KERNEL);
}
}
+EXPORT_SYMBOL_GPL(wireless_nlevent_flush);
static int wext_netdev_notifier_call(struct notifier_block *nb,
unsigned long state, void *ptr)
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:30 +0200 |
| Subject | [PATCH 3.2 14/62] xen/pciback: Save the number of MSI-X entries to be copied later. |
| Message-ID | <ri8r1-2Xn-17@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
commit d159457b84395927b5a52adb72f748dd089ad5e5 upstream.
Commit 8135cf8b092723dbfcc611fe6fdcb3a36c9951c5 (xen/pciback: Save
xen_pci_op commands before processing it) broke enabling MSI-X because
it would never copy the resulting vectors into the response. The
number of vectors requested was being overwritten by the return value
(typically zero for success).
Save the number of vectors before processing the op, so the correct
number of vectors are copied afterwards.
Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Reviewed-by: Jan Beulich <jbeulich@suse.com>
Signed-off-by: David Vrabel <david.vrabel@citrix.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/xen/xen-pciback/pciback_ops.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/drivers/xen/xen-pciback/pciback_ops.c
+++ b/drivers/xen/xen-pciback/pciback_ops.c
@@ -331,6 +331,9 @@ void xen_pcibk_do_op(struct work_struct
struct xen_pcibk_dev_data *dev_data = NULL;
struct xen_pci_op *op = &pdev->op;
int test_intx = 0;
+#ifdef CONFIG_PCI_MSI
+ unsigned int nr = 0;
+#endif
*op = pdev->sh_info->op;
barrier();
@@ -359,6 +362,7 @@ void xen_pcibk_do_op(struct work_struct
op->err = xen_pcibk_disable_msi(pdev, dev, op);
break;
case XEN_PCI_OP_enable_msix:
+ nr = op->value;
op->err = xen_pcibk_enable_msix(pdev, dev, op);
break;
case XEN_PCI_OP_disable_msix:
@@ -381,7 +385,7 @@ void xen_pcibk_do_op(struct work_struct
if (op->cmd == XEN_PCI_OP_enable_msix && op->err == 0) {
unsigned int i;
- for (i = 0; i < op->value; i++)
+ for (i = 0; i < nr; i++)
pdev->sh_info->op.msix_entries[i].vector =
op->msix_entries[i].vector;
}
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:30 +0200 |
| Subject | [PATCH 3.2 18/62] tracing: Fix freak link error caused by branch tracer |
| Message-ID | <ri8r1-2Xn-23@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Arnd Bergmann <arnd@arndb.de>
commit b33c8ff4431a343561e2319f17c14286f2aa52e2 upstream.
In my randconfig tests, I came across a bug that involves several
components:
* gcc-4.9 through at least 5.3
* CONFIG_GCOV_PROFILE_ALL enabling -fprofile-arcs for all files
* CONFIG_PROFILE_ALL_BRANCHES overriding every if()
* The optimized implementation of do_div() that tries to
replace a library call with an division by multiplication
* code in drivers/media/dvb-frontends/zl10353.c doing
u32 adc_clock = 450560; /* 45.056 MHz */
if (state->config.adc_clock)
adc_clock = state->config.adc_clock;
do_div(value, adc_clock);
In this case, gcc fails to determine whether the divisor
in do_div() is __builtin_constant_p(). In particular, it
concludes that __builtin_constant_p(adc_clock) is false, while
__builtin_constant_p(!!adc_clock) is true.
That in turn throws off the logic in do_div() that also uses
__builtin_constant_p(), and instead of picking either the
constant- optimized division, and the code in ilog2() that uses
__builtin_constant_p() to figure out whether it knows the answer at
compile time. The result is a link error from failing to find
multiple symbols that should never have been called based on
the __builtin_constant_p():
dvb-frontends/zl10353.c:138: undefined reference to `____ilog2_NaN'
dvb-frontends/zl10353.c:138: undefined reference to `__aeabi_uldivmod'
ERROR: "____ilog2_NaN" [drivers/media/dvb-frontends/zl10353.ko] undefined!
ERROR: "__aeabi_uldivmod" [drivers/media/dvb-frontends/zl10353.ko] undefined!
This patch avoids the problem by changing __trace_if() to check
whether the condition is known at compile-time to be nonzero, rather
than checking whether it is actually a constant.
I see this one link error in roughly one out of 1600 randconfig builds
on ARM, and the patch fixes all known instances.
Link: http://lkml.kernel.org/r/1455312410-1058841-1-git-send-email-arnd@arndb.de
Acked-by: Nicolas Pitre <nico@linaro.org>
Fixes: ab3c9c686e22 ("branch tracer, intel-iommu: fix build with CONFIG_BRANCH_TRACER=y")
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
include/linux/compiler.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/include/linux/compiler.h
+++ b/include/linux/compiler.h
@@ -125,7 +125,7 @@ void ftrace_likely_update(struct ftrace_
*/
#define if(cond, ...) __trace_if( (cond , ## __VA_ARGS__) )
#define __trace_if(cond) \
- if (__builtin_constant_p((cond)) ? !!(cond) : \
+ if (__builtin_constant_p(!!(cond)) ? !!(cond) : \
({ \
int ______r; \
static struct ftrace_branch_data \
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2016-03-29 22:30 +0200 |
| Subject | [PATCH 3.2 16/62] ALSA: seq: Fix leak of pool buffer at concurrent writes |
| Message-ID | <ri8r1-2Xn-21@gated-at.bofh.it> |
| In reply to | #1366649 |
3.2.79-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit d99a36f4728fcbcc501b78447f625bdcce15b842 upstream.
When multiple concurrent writes happen on the ALSA sequencer device
right after the open, it may try to allocate vmalloc buffer for each
write and leak some of them. It's because the presence check and the
assignment of the buffer is done outside the spinlock for the pool.
The fix is to move the check and the assignment into the spinlock.
(The current implementation is suboptimal, as there can be multiple
unnecessary vmallocs because the allocation is done before the check
in the spinlock. But the pool size is already checked beforehand, so
this isn't a big problem; that is, the only possible path is the
multiple writes before any pool assignment, and practically seen, the
current coverage should be "good enough".)
The issue was triggered by syzkaller fuzzer.
BugLink: http://lkml.kernel.org/r/CACT4Y+bSzazpXNvtAr=WXaL8hptqjHwqEyFA+VN2AWEx=aurkg@mail.gmail.com
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Tested-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
sound/core/seq/seq_memory.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
--- a/sound/core/seq/seq_memory.c
+++ b/sound/core/seq/seq_memory.c
@@ -383,17 +383,22 @@ int snd_seq_pool_init(struct snd_seq_poo
if (snd_BUG_ON(!pool))
return -EINVAL;
- if (pool->ptr) /* should be atomic? */
- return 0;
- pool->ptr = vmalloc(sizeof(struct snd_seq_event_cell) * pool->size);
- if (pool->ptr == NULL) {
+ cellptr = vmalloc(sizeof(struct snd_seq_event_cell) * pool->size);
+ if (!cellptr) {
snd_printd("seq: malloc for sequencer events failed\n");
return -ENOMEM;
}
/* add new cells to the free cell list */
spin_lock_irqsave(&pool->lock, flags);
+ if (pool->ptr) {
+ spin_unlock_irqrestore(&pool->lock, flags);
+ vfree(cellptr);
+ return 0;
+ }
+
+ pool->ptr = cellptr;
pool->free = NULL;
for (cell = 0; cell < pool->size; cell++) {
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | linux.kernel
csiph-web