Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1369682 > unrolled thread

[3.19.y-ckt stable] Linux 3.19.8-ckt18 stable review

Started byKamal Mostafa <kamal@canonical.com>
First post2016-04-02 03:00 +0200
Last post2016-04-02 03:50 +0200
Articles 20 on this page of 163 — 1 participant

Back to article view | Back to linux.kernel


Contents

  [3.19.y-ckt stable] Linux 3.19.8-ckt18 stable review Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 011/170] Input: powermate - fix oops with malicious USB descriptors Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 016/170] Input: ati_remote2 - fix crashes on detecting device with invalid descriptor Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 168/170] perf stat: Document --detailed option Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 054/170] xfs: fix two memory leaks in xfs_attr_list.c error paths Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 102/170] Input: synaptics - handle spurious release of trackstick buttons, again Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 094/170] HID: i2c-hid: fix OOB write in i2c_hid_set_or_send_report() Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 149/170] sunrpc/cache: drop reference when sunrpc_cache_pipe_upcall() detects a race Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 071/170] bcache: fix race of writeback thread starting before complete initialization Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 155/170] mlx4: add missing braces in verify_qp_parameters Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 170/170] rtc: max77686: Properly handle regmap_irq_get_virq() error code Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 020/170] ceph: fix request time stamp encoding Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 123/170] clk: qcom: msm8960: Fix ce3_src register offset Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 100/170] mmc: sdhci: Fix override of timeout clk wrt max_busy_timeout Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 144/170] ARM: davinci: make I2C support optional Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 167/170] drivers/misc/ad525x_dpot: AD5274 fix RDAC read back errors Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 119/170] ocfs2/dlm: fix race between convert and recovery Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 108/170] splice: handle zero nr_pages in splice_to_pipe() Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 163/170] regulator: s5m8767: fix get_register() error handling Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 169/170] [media] v4l: vsp1: Set the SRU CTRL0 register when starting the stream Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 164/170] ppp: ensure file->private_data can't be overridden Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 161/170] nbd: ratelimit error msgs after socket close Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 138/170] clk: qcom: msm8960: fix ce3_core clk enable register Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 048/170] mmc: sdhci: fix data timeout (part 1) Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 010/170] ipv4: Don't do expensive useless work during inetdev destroy. Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 147/170] efi: Expose non-blocking set_variable() wrapper to efivars Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:00 +0200
    [PATCH 3.19.y-ckt 139/170] ipvs: correct initial offset of Call-ID header search in SIP persistence engine Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 137/170] fbdev: da8xx-fb: fix videomodes of lcd panels Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 133/170] misc/bmp085: Enable building as a module Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 160/170] perf pmu: Fix misleadingly indented assignment (whitespace) Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 165/170] clk: versatile: sp810: support reentrance Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 150/170] ipv4: fix broadcast packets reception Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 121/170] mm/page_alloc: prevent merging between isolated and other pageblocks Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 151/170] lpfc: fix misleading indentation Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 153/170] spi/rockchip: Make sure spi clk is on in rockchip_spi_set_cs Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 142/170] ath9k: fix buffer overrun for ar9287 Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 135/170] net/mlx5: Make command timeout way shorter Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 136/170] ASoC: ssm4567: Reset device before regcache_sync() Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 141/170] spi: rockchip: modify DMA max burst to 1 Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 145/170] mtd: map: fix .set_vpp() documentation Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 158/170] mac80211: fix unnecessary frame drops in mesh fwding Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 148/170] rtc: vr41xx: Wire up alarm_irq_enable Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 120/170] ocfs2/dlm: fix BUG in dlm_move_lockres_to_recovery_list Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 166/170] net: bcmgenet: fix dma api length mismatch Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 156/170] [media] coda: fix error path in case of missing pdata on non-DT platform Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 162/170] paride: make 'verbose' parameter an 'int' again Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 146/170] ARM: OMAP3: Add cpuidle parameters table for omap3430 Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 152/170] ipip: Properly mark ipip GRO packets as encapsulated. Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 109/170] bitops: Do not default to __clear_bit() for __clear_bit_unlock() Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 159/170] rtc: hym8563: fix invalid year calculation Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 140/170] drm/i915: Cleanup phys status page too Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 134/170] HID: logitech: fix Dual Action gamepad support Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 143/170] perf tools: handle spaces in file names obtained from /proc/pid/maps Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 157/170] kbuild/mkspec: fix grub2 installkernel issue Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 114/170] fs/coredump: prevent fsuid=0 dumps into user-controlled directories Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:10 +0200
    [PATCH 3.19.y-ckt 111/170] KVM: VMX: avoid guest hang on invalid invept instruction Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 117/170] ideapad-laptop: Add ideapad Y700 (15) to the no_hw_rfkill DMI list Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 069/170] perf/x86/intel: Use PAGE_SIZE for PEBS buffer size on Core2 Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 095/170] ALSA: hda - Fix unconditional GPIO toggle via automute Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 105/170] USB: uas: Reduce can_queue to MAX_CMNDS Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 129/170] ath9k: fix misleading indentation Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 130/170] sctp: fix the transports round robin issue when init is retransmitted Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 096/170] mmc: mmc_spi: Add Card Detect comments and fix CD GPIO case Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 107/170] tracing: Fix crash from reading trace_pipe with sendfile Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 104/170] USB: usb_driver_claim_interface: add sanity checking Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 132/170] megaraid_sas: add missing curly braces in ioctl handler Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 079/170] EDAC/sb_edac: Fix computation of channel address Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 127/170] clk: rockchip: free memory in error cases when registering clock branches Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 112/170] KVM: fix spin_lock_init order on x86 Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 122/170] clk: xgene: Add missing parenthesis when clearing divider value Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 128/170] net: Fix use after free in the recvmmsg exit path Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 098/170] vfs: show_vfsstat: do not ignore errors from show_devname method Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 101/170] Input: ims-pcu - sanity check against missing interfaces Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 106/170] tracing: Have preempt(irqs)off trace preempt disabled functions Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 097/170] nfsd: fix deadlock secinfo+readdir compound Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 110/170] target: Fix target_release_cmd_kref shutdown comp leak Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 103/170] x86/apic: Fix suspicious RCU usage in smp_trace_call_function_interrupt() Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 125/170] ppp: take reference on channels netns Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 118/170] MAINTAINERS: Update mailing list and web page for hwmon subsystem Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 093/170] net: mvneta: enable change MAC address when interface is up Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 091/170] s390/pci: enforce fmb page boundary rule Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 115/170] rapidio/rionet: fix deadlock on SMP Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 131/170] ethernet: micrel: fix some error codes Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 116/170] staging: comedi: ni_mio_common: fix the ni_write[blw]() functions Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 124/170] xen kconfig: don't "select INPUT_XEN_KBDDEV_FRONTEND" Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:20 +0200
    [PATCH 3.19.y-ckt 086/170] xtensa: ISS: don't hang if stdin EOF is reached Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 082/170] dm thin metadata: don't issue prefetches if a transaction abort has failed Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 075/170] be2iscsi: set the boot_kset pointer to NULL in case of failure Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 064/170] KVM: i8254: change PIT discard tick policy Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 074/170] x86/PCI: Mark Broadwell-EP Home Agent & PCU as having non-compliant BARs Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 076/170] drm/radeon: Don't drop DP 2.7 Ghz link setup on some cards. Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 066/170] rt2x00: add new rt2800usb device Buffalo WLI-UC-G450 Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 080/170] Bluetooth: btusb: Add a new AR3012 ID 13d3:3472 Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 062/170] of: alloc anywhere from memblock if range not specified Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 092/170] md: multipath: don't hardcopy bio in .make_request path Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 063/170] usb: hub: fix a typo in hub_port_init() leading to wrong logic Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 058/170] mtip32xx: Print exact time when an internal command is interrupted Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 089/170] bus: imx-weim: Take the 'status' property value into account Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 052/170] watchdog: rc32434_wdt: fix ioctl error handling Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 068/170] perf/core: Fix perf_sched_count derailment Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 055/170] quota: Fix possible GPF due to uninitialised pointers Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 067/170] pinctrl-bcm2835: Fix cut-and-paste error in "pull" parsing Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 065/170] sched/cputime: Fix steal time accounting vs. CPU hotplug Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 085/170] iser-target: Separate flows for np listeners and connections cma events Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 056/170] mtip32xx: Fix broken service thread handling Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 059/170] mtip32xx: Avoid issuing standby immediate cmd during FTL rebuild Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 057/170] mtip32xx: Remove unwanted code from taskfile error handler Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 060/170] mtip32xx: Handle safe removal during IO Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 090/170] ALSA: intel8x0: Add clock quirk entry for AD1981B on IBM ThinkPad X41. Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 087/170] xtensa: fix preemption in {clear,copy}_user_highpage Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 078/170] jbd2: fix FS corruption possibility in jbd2_journal_destroy() on umount path Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 072/170] bcache: cleaned up error handling around register_cache() Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 070/170] sched/cputime: Fix steal_account_process_tick() to always return jiffies Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 083/170] iser-target: Fix identification of login rx descriptor type Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 081/170] ALSA: pcm: Avoid "BUG:" string for warnings again Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 050/170] IB/srpt: Simplify srpt_handle_tsk_mgmt() Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 077/170] sg: fix dxferp in from_to case Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 073/170] bcache: fix cache_set_flush() NULL pointer dereference on OOM Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 088/170] xtensa: clear all DBREAKC registers on start Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:30 +0200
    [PATCH 3.19.y-ckt 025/170] [media] pwc: Add USB id for Philips Spc880nc webcam Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 022/170] crypto: ccp - Add hash state import and export support Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 029/170] net: irda: Fix use-after-free in irtty_open() Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 027/170] crypto: ccp - Don't assume export/import areas are aligned Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 026/170] crypto: ccp - Limit the amount of information exported Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 028/170] 8250: use callbacks to access UART_DLL/UART_DLM Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 019/170] cpu: Provide smpboot_thread_init() on !CONFIG_SMP kernels as well Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 018/170] cpu: Defer smpboot kthread unparking until CPU known to scheduler Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 046/170] crypto: ccp - memset request context to zero during import Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 045/170] md/raid5: Compare apples to apples (or sectors to sectors) Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 051/170] [media] bttv: Width must be a multiple of 16 when capturing planar formats Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 043/170] mtd: onenand: fix deadlock in onenand_block_markbad Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 040/170] Bluetooth: Add new AR3012 ID 0489:e095 Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 039/170] Bluetooth: btusb: Add new AR3012 ID 13d3:3395 Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 037/170] [media] saa7134: Fix bytesperline not being set correctly for planar formats Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 023/170] tty: Fix GPF in flush_to_ldisc(), part 2 Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 044/170] PCI: Disable IO/MEM decoding for devices with non-compliant BARs Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 049/170] mmc: sdhci: fix data timeout (part 2) Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 047/170] Bluetooth: btusb: Add a new AR3012 ID 04ca:3014 Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 033/170] usb: retry reset if a device times out Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 038/170] perf tools: Dont stop PMU parsing on alias parse error Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 035/170] scripts/coccinelle: modernize & Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 034/170] HID: fix hid_ignore_special_drivers module parameter Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 031/170] tools/hv: Use include/uapi with __EXPORTED_HEADERS__ Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 041/170] aacraid: Fix memory leak in aac_fib_map_free Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 030/170] staging: comedi: ni_tiocmd: change mistaken use of start_src for start_arg Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 053/170] nfsd4: fix bad bounds checking Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 032/170] ARM: dts: armada-375: use armada-370-sata for SATA Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 042/170] aic7xxx: Fix queue depth handling Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 024/170] [media] media: v4l2-compat-ioctl32: fix missing length copy in put_v4l2_buffer32 Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 021/170] EDAC, amd64_edac: Shift wrapping issue in f1x_get_norm_dct_addr() Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:40 +0200
    [PATCH 3.19.y-ckt 003/170] crypto: algif_hash - Require setkey before accept(2) Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:50 +0200
    [PATCH 3.19.y-ckt 013/170] ALSA: usb-audio: Fix NULL dereference in create_fixed_stream_quirk() Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:50 +0200
    [PATCH 3.19.y-ckt 008/170] crypto: algif_hash - Fix race condition in hash_check_key Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:50 +0200
    [PATCH 3.19.y-ckt 005/170] crypto: algif_skcipher - Add key check exception for cipher_null Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:50 +0200
    [PATCH 3.19.y-ckt 015/170] include/linux/poison.h: fix LIST_POISON{1,2} offset Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:50 +0200
    [PATCH 3.19.y-ckt 017/170] USB: cdc-acm: more sanity checking Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:50 +0200
    [PATCH 3.19.y-ckt 012/170] USB: iowarrior: fix oops with malicious USB descriptors Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:50 +0200
    [PATCH 3.19.y-ckt 006/170] crypto: algif_hash - Remove custom release parent function Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:50 +0200
    [PATCH 3.19.y-ckt 002/170] crypto: algif_skcipher - Add nokey compatibility path Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:50 +0200
    [PATCH 3.19.y-ckt 014/170] ALSA: usb-audio: Add sanity checks for endpoint accesses Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:50 +0200
    [PATCH 3.19.y-ckt 004/170] crypto: skcipher - Add crypto_skcipher_has_setkey Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:50 +0200
    [PATCH 3.19.y-ckt 007/170] crypto: algif_skcipher - Remove custom release parent function Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:50 +0200
    [PATCH 3.19.y-ckt 009/170] crypto: algif_skcipher - Fix race condition in skcipher_check_key Kamal Mostafa <kamal@canonical.com> - 2016-04-02 03:50 +0200

Page 8 of 9 — ← Prev page 1 2 3 4 5 6 7 [8] 9  Next page →


#1369831 — [PATCH 3.19.y-ckt 035/170] scripts/coccinelle: modernize &

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:40 +0200
Subject[PATCH 3.19.y-ckt 035/170] scripts/coccinelle: modernize &
Message-ID<rjiHE-4AY-43@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Julia Lawall <Julia.Lawall@lip6.fr>

commit 1b669e713f277a4d4b3cec84e13d16544ac8286d upstream.

& is no longer allowed in column 0, since Coccinelle 1.0.4.

Signed-off-by: Julia Lawall <Julia.Lawall@lip6.fr>
Tested-by: Nishanth Menon <nm@ti.com>
Signed-off-by: Michal Marek <mmarek@suse.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 scripts/coccinelle/iterators/use_after_iter.cocci | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/scripts/coccinelle/iterators/use_after_iter.cocci b/scripts/coccinelle/iterators/use_after_iter.cocci
index f085f59..ce8cc9c 100644
--- a/scripts/coccinelle/iterators/use_after_iter.cocci
+++ b/scripts/coccinelle/iterators/use_after_iter.cocci
@@ -123,7 +123,7 @@ list_remove_head(x,c,...)
 |
 sizeof(<+...c...+>)
 |
-&c->member
+ &c->member
 |
 c = E
 |
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369832 — [PATCH 3.19.y-ckt 034/170] HID: fix hid_ignore_special_drivers module parameter

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:40 +0200
Subject[PATCH 3.19.y-ckt 034/170] HID: fix hid_ignore_special_drivers module parameter
Message-ID<rjiHF-4AY-51@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Benjamin Tissoires <benjamin.tissoires@redhat.com>

commit 4392bf333388cabdad5afe5b1500002d7b9c318e upstream.

hid_ignore_special_drivers works fine until hid_scan_report autodetects and
reassign devices (for hid-multitouch, hid-microsoft and hid-rmi).

Simplify the handling of the parameter: if it is there, use hid-generic, no
matter what, and if not, scan the device or rely on the hid_have_special_driver
table.

This was detected while trying to disable hid-multitouch on a Surface Pro cover
which prevented to use the keyboard.

Signed-off-by: Benjamin Tissoires <benjamin.tissoires@redhat.com>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/hid/hid-core.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c
index d7d965f..53f3ad2 100644
--- a/drivers/hid/hid-core.c
+++ b/drivers/hid/hid-core.c
@@ -2540,9 +2540,10 @@ int hid_add_device(struct hid_device *hdev)
 	/*
 	 * Scan generic devices for group information
 	 */
-	if (hid_ignore_special_drivers ||
-	    (!hdev->group &&
-	     !hid_match_id(hdev, hid_have_special_driver))) {
+	if (hid_ignore_special_drivers) {
+		hdev->group = HID_GROUP_GENERIC;
+	} else if (!hdev->group &&
+		   !hid_match_id(hdev, hid_have_special_driver)) {
 		ret = hid_scan_report(hdev);
 		if (ret)
 			hid_warn(hdev, "bad device descriptor (%d)\n", ret);
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369834 — [PATCH 3.19.y-ckt 031/170] tools/hv: Use include/uapi with __EXPORTED_HEADERS__

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:40 +0200
Subject[PATCH 3.19.y-ckt 031/170] tools/hv: Use include/uapi with __EXPORTED_HEADERS__
Message-ID<rjiHF-4AY-59@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Kamal Mostafa <kamal@canonical.com>

commit 50fe6dd10069e7c062e27f29606f6e91ea979399 upstream.

Use the local uapi headers to keep in sync with "recently" added #define's
(e.g. VSS_OP_REGISTER1).

Fixes: 3eb2094c59e8 ("Adding makefile for tools/hv")
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
Signed-off-by: K. Y. Srinivasan <kys@microsoft.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 tools/hv/Makefile | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/tools/hv/Makefile b/tools/hv/Makefile
index bd22f78..dbd6248 100644
--- a/tools/hv/Makefile
+++ b/tools/hv/Makefile
@@ -5,6 +5,8 @@ PTHREAD_LIBS = -lpthread
 WARNINGS = -Wall -Wextra
 CFLAGS = $(WARNINGS) -g $(PTHREAD_LIBS)
 
+CFLAGS += -D__EXPORTED_HEADERS__ -I../../include/uapi -I../../include
+
 all: hv_kvp_daemon hv_vss_daemon
 %: %.c
 	$(CC) $(CFLAGS) -o $@ $^
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369835 — [PATCH 3.19.y-ckt 041/170] aacraid: Fix memory leak in aac_fib_map_free

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:40 +0200
Subject[PATCH 3.19.y-ckt 041/170] aacraid: Fix memory leak in aac_fib_map_free
Message-ID<rjiHF-4AY-61@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Raghava Aditya Renukunta <raghavaaditya.renukunta@pmcs.com>

commit f88fa79a61726ce9434df9b4aede36961f709f17 upstream.

aac_fib_map_free() calls pci_free_consistent() without checking that
dev->hw_fib_va is not NULL and dev->max_fib_size is not zero.If they are
indeed NULL/0, this will result in a hang as pci_free_consistent() will
attempt to invalidate cache for the entire 64-bit address space
(which would take a very long time).

Fixed by adding a check to make sure that dev->hw_fib_va and
dev->max_fib_size are not NULL and 0 respectively.

Fixes: 9ad5204d6 - "[SCSI]aacraid: incorrect dma mapping mask during blinked recover or user initiated reset"

Signed-off-by: Raghava Aditya Renukunta <raghavaaditya.renukunta@pmcs.com>
Reviewed-by: Johannes Thumshirn <jthumshirn@suse.de>
Reviewed-by: Tomas Henzl <thenzl@redhat.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/scsi/aacraid/commsup.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/drivers/scsi/aacraid/commsup.c b/drivers/scsi/aacraid/commsup.c
index cab190a..6b32ddc 100644
--- a/drivers/scsi/aacraid/commsup.c
+++ b/drivers/scsi/aacraid/commsup.c
@@ -83,9 +83,12 @@ static int fib_map_alloc(struct aac_dev *dev)
 
 void aac_fib_map_free(struct aac_dev *dev)
 {
-	pci_free_consistent(dev->pdev,
-	  dev->max_fib_size * (dev->scsi_host_ptr->can_queue + AAC_NUM_MGT_FIB),
-	  dev->hw_fib_va, dev->hw_fib_pa);
+	if (dev->hw_fib_va && dev->max_fib_size) {
+		pci_free_consistent(dev->pdev,
+		(dev->max_fib_size *
+		(dev->scsi_host_ptr->can_queue + AAC_NUM_MGT_FIB)),
+		dev->hw_fib_va, dev->hw_fib_pa);
+	}
 	dev->hw_fib_va = NULL;
 	dev->hw_fib_pa = 0;
 }
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369836 — [PATCH 3.19.y-ckt 030/170] staging: comedi: ni_tiocmd: change mistaken use of start_src for start_arg

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:40 +0200
Subject[PATCH 3.19.y-ckt 030/170] staging: comedi: ni_tiocmd: change mistaken use of start_src for start_arg
Message-ID<rjiHF-4AY-57@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: "Spencer E. Olson" <olsonse@umich.edu>

commit 1fd24a4702d2af0ea4d5845126cf57d4d1796216 upstream.

This fixes a bug in function ni_tio_input_inttrig().  The trigger number
should be compared to cmd->start_arg, not cmd->start_src.

Fixes: 6a760394d7eb ("staging: comedi: ni_tiocmd: clarify the cmd->start_arg validation and use")
Signed-off-by: Spencer E. Olson <olsonse@umich.edu>
Reviewed-by: Ian Abbott <abbotti@mev.co.uk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/staging/comedi/drivers/ni_tiocmd.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/staging/comedi/drivers/ni_tiocmd.c b/drivers/staging/comedi/drivers/ni_tiocmd.c
index 6037bec..a0a43bf 100644
--- a/drivers/staging/comedi/drivers/ni_tiocmd.c
+++ b/drivers/staging/comedi/drivers/ni_tiocmd.c
@@ -94,7 +94,7 @@ static int ni_tio_input_inttrig(struct comedi_device *dev,
 	unsigned long flags;
 	int ret = 0;
 
-	if (trig_num != cmd->start_src)
+	if (trig_num != cmd->start_arg)
 		return -EINVAL;
 
 	spin_lock_irqsave(&counter->lock, flags);
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369837 — [PATCH 3.19.y-ckt 053/170] nfsd4: fix bad bounds checking

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:40 +0200
Subject[PATCH 3.19.y-ckt 053/170] nfsd4: fix bad bounds checking
Message-ID<rjiHF-4AY-63@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: "J. Bruce Fields" <bfields@redhat.com>

commit 4aed9c46afb80164401143aa0fdcfe3798baa9d5 upstream.

A number of spots in the xdr decoding follow a pattern like

	n = be32_to_cpup(p++);
	READ_BUF(n + 4);

where n is a u32.  The only bounds checking is done in READ_BUF itself,
but since it's checking (n + 4), it won't catch cases where n is very
large, (u32)(-4) or higher.  I'm not sure exactly what the consequences
are, but we've seen crashes soon after.

Instead, just break these up into two READ_BUF()s.

Signed-off-by: J. Bruce Fields <bfields@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/nfsd/nfs4xdr.c | 13 ++++++++-----
 1 file changed, 8 insertions(+), 5 deletions(-)

diff --git a/fs/nfsd/nfs4xdr.c b/fs/nfsd/nfs4xdr.c
index 043ed3f..841df5e 100644
--- a/fs/nfsd/nfs4xdr.c
+++ b/fs/nfsd/nfs4xdr.c
@@ -1061,8 +1061,9 @@ nfsd4_decode_rename(struct nfsd4_compoundargs *argp, struct nfsd4_rename *rename
 
 	READ_BUF(4);
 	rename->rn_snamelen = be32_to_cpup(p++);
-	READ_BUF(rename->rn_snamelen + 4);
+	READ_BUF(rename->rn_snamelen);
 	SAVEMEM(rename->rn_sname, rename->rn_snamelen);
+	READ_BUF(4);
 	rename->rn_tnamelen = be32_to_cpup(p++);
 	READ_BUF(rename->rn_tnamelen);
 	SAVEMEM(rename->rn_tname, rename->rn_tnamelen);
@@ -1144,13 +1145,14 @@ nfsd4_decode_setclientid(struct nfsd4_compoundargs *argp, struct nfsd4_setclient
 	READ_BUF(8);
 	setclientid->se_callback_prog = be32_to_cpup(p++);
 	setclientid->se_callback_netid_len = be32_to_cpup(p++);
-
-	READ_BUF(setclientid->se_callback_netid_len + 4);
+	READ_BUF(setclientid->se_callback_netid_len);
 	SAVEMEM(setclientid->se_callback_netid_val, setclientid->se_callback_netid_len);
+	READ_BUF(4);
 	setclientid->se_callback_addr_len = be32_to_cpup(p++);
 
-	READ_BUF(setclientid->se_callback_addr_len + 4);
+	READ_BUF(setclientid->se_callback_addr_len);
 	SAVEMEM(setclientid->se_callback_addr_val, setclientid->se_callback_addr_len);
+	READ_BUF(4);
 	setclientid->se_callback_ident = be32_to_cpup(p++);
 
 	DECODE_TAIL;
@@ -1663,8 +1665,9 @@ nfsd4_decode_compound(struct nfsd4_compoundargs *argp)
 
 	READ_BUF(4);
 	argp->taglen = be32_to_cpup(p++);
-	READ_BUF(argp->taglen + 8);
+	READ_BUF(argp->taglen);
 	SAVEMEM(argp->tag, argp->taglen);
+	READ_BUF(8);
 	argp->minorversion = be32_to_cpup(p++);
 	argp->opcnt = be32_to_cpup(p++);
 	max_reply += 4 + (XDR_QUADLEN(argp->taglen) << 2);
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369838 — [PATCH 3.19.y-ckt 032/170] ARM: dts: armada-375: use armada-370-sata for SATA

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:40 +0200
Subject[PATCH 3.19.y-ckt 032/170] ARM: dts: armada-375: use armada-370-sata for SATA
Message-ID<rjiHF-4AY-67@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Lior Amsalem <alior@marvell.com>

commit b3a7f31eb7375633cd6a742f19488fc5a4208b36 upstream.

The Armada 375 has the same SATA IP as Armada 370 and Armada XP, which
requires the PHY speed to be set in the LP_PHY_CTL register for SATA
hotplug to work.

Therefore, this commit updates the compatible string used to describe
the SATA IP in Armada 375 from marvell,orion-sata to
marvell,armada-370-sata.

Fixes: 4de59085091f753d08c8429d756b46756ab94665 ("ARM: mvebu: add Device Tree description of the Armada 375 SoC")
Signed-off-by: Lior Amsalem <alior@marvell.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Signed-off-by: Gregory CLEMENT <gregory.clement@free-electrons.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/arm/boot/dts/armada-375.dtsi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm/boot/dts/armada-375.dtsi b/arch/arm/boot/dts/armada-375.dtsi
index 50096d3..45d7534 100644
--- a/arch/arm/boot/dts/armada-375.dtsi
+++ b/arch/arm/boot/dts/armada-375.dtsi
@@ -469,7 +469,7 @@
 			};
 
 			sata@a0000 {
-				compatible = "marvell,orion-sata";
+				compatible = "marvell,armada-370-sata";
 				reg = <0xa0000 0x5000>;
 				interrupts = <GIC_SPI 26 IRQ_TYPE_LEVEL_HIGH>;
 				clocks = <&gateclk 14>, <&gateclk 20>;
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369839 — [PATCH 3.19.y-ckt 042/170] aic7xxx: Fix queue depth handling

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:40 +0200
Subject[PATCH 3.19.y-ckt 042/170] aic7xxx: Fix queue depth handling
Message-ID<rjiHF-4AY-69@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Alan <gnomes@lxorguk.ukuu.org.uk>

commit 5a51a7abca133860a6f4429655a9eda3c4afde32 upstream.

We were setting the queue depth correctly, then setting it back to
two. If you hit this as a bisection point then please send me an email
as it would imply we've been hiding other bugs with this one.

Signed-off-by: Alan Cox <alan@linux.intel.com>
Reviewed-by: Hannes Reinicke <hare@suse.de>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/scsi/aic7xxx/aic7xxx_osm.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/scsi/aic7xxx/aic7xxx_osm.c b/drivers/scsi/aic7xxx/aic7xxx_osm.c
index 8836011..35c67bb 100644
--- a/drivers/scsi/aic7xxx/aic7xxx_osm.c
+++ b/drivers/scsi/aic7xxx/aic7xxx_osm.c
@@ -1338,6 +1338,7 @@ ahc_platform_set_tags(struct ahc_softc *ahc, struct scsi_device *sdev,
 	case AHC_DEV_Q_TAGGED:
 		scsi_change_queue_depth(sdev,
 				dev->openings + dev->active);
+		break;
 	default:
 		/*
 		 * We allow the OS to queue 2 untagged transactions to
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369840 — [PATCH 3.19.y-ckt 024/170] [media] media: v4l2-compat-ioctl32: fix missing length copy in put_v4l2_buffer32

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:40 +0200
Subject[PATCH 3.19.y-ckt 024/170] [media] media: v4l2-compat-ioctl32: fix missing length copy in put_v4l2_buffer32
Message-ID<rjiHF-4AY-65@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Tiffany Lin <tiffany.lin@mediatek.com>

commit 7df5ab8774aa383c6d2bff00688d004585d96dfd upstream.

In v4l2-compliance utility, test QUERYBUF required correct length
value to go through each planar to check planar's length in
multi-planar buffer type

Signed-off-by: Tiffany Lin <tiffany.lin@mediatek.com>
Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Hans Verkuil <hans.verkuil@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/media/v4l2-core/v4l2-compat-ioctl32.c | 21 ++++++++-------------
 1 file changed, 8 insertions(+), 13 deletions(-)

diff --git a/drivers/media/v4l2-core/v4l2-compat-ioctl32.c b/drivers/media/v4l2-core/v4l2-compat-ioctl32.c
index 788b31c..73138a3 100644
--- a/drivers/media/v4l2-core/v4l2-compat-ioctl32.c
+++ b/drivers/media/v4l2-core/v4l2-compat-ioctl32.c
@@ -394,7 +394,8 @@ static int get_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user
 		get_user(kp->index, &up->index) ||
 		get_user(kp->type, &up->type) ||
 		get_user(kp->flags, &up->flags) ||
-		get_user(kp->memory, &up->memory))
+		get_user(kp->memory, &up->memory) ||
+		get_user(kp->length, &up->length))
 			return -EFAULT;
 
 	if (V4L2_TYPE_IS_OUTPUT(kp->type))
@@ -406,9 +407,6 @@ static int get_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user
 			return -EFAULT;
 
 	if (V4L2_TYPE_IS_MULTIPLANAR(kp->type)) {
-		if (get_user(kp->length, &up->length))
-			return -EFAULT;
-
 		num_planes = kp->length;
 		if (num_planes == 0) {
 			kp->m.planes = NULL;
@@ -441,16 +439,14 @@ static int get_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user
 	} else {
 		switch (kp->memory) {
 		case V4L2_MEMORY_MMAP:
-			if (get_user(kp->length, &up->length) ||
-				get_user(kp->m.offset, &up->m.offset))
+			if (get_user(kp->m.offset, &up->m.offset))
 				return -EFAULT;
 			break;
 		case V4L2_MEMORY_USERPTR:
 			{
 			compat_long_t tmp;
 
-			if (get_user(kp->length, &up->length) ||
-			    get_user(tmp, &up->m.userptr))
+			if (get_user(tmp, &up->m.userptr))
 				return -EFAULT;
 
 			kp->m.userptr = (unsigned long)compat_ptr(tmp);
@@ -492,7 +488,8 @@ static int put_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user
 		copy_to_user(&up->timecode, &kp->timecode, sizeof(struct v4l2_timecode)) ||
 		put_user(kp->sequence, &up->sequence) ||
 		put_user(kp->reserved2, &up->reserved2) ||
-		put_user(kp->reserved, &up->reserved))
+		put_user(kp->reserved, &up->reserved) ||
+		put_user(kp->length, &up->length))
 			return -EFAULT;
 
 	if (V4L2_TYPE_IS_MULTIPLANAR(kp->type)) {
@@ -515,13 +512,11 @@ static int put_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user
 	} else {
 		switch (kp->memory) {
 		case V4L2_MEMORY_MMAP:
-			if (put_user(kp->length, &up->length) ||
-				put_user(kp->m.offset, &up->m.offset))
+			if (put_user(kp->m.offset, &up->m.offset))
 				return -EFAULT;
 			break;
 		case V4L2_MEMORY_USERPTR:
-			if (put_user(kp->length, &up->length) ||
-				put_user(kp->m.userptr, &up->m.userptr))
+			if (put_user(kp->m.userptr, &up->m.userptr))
 				return -EFAULT;
 			break;
 		case V4L2_MEMORY_OVERLAY:
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369841 — [PATCH 3.19.y-ckt 021/170] EDAC, amd64_edac: Shift wrapping issue in f1x_get_norm_dct_addr()

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:40 +0200
Subject[PATCH 3.19.y-ckt 021/170] EDAC, amd64_edac: Shift wrapping issue in f1x_get_norm_dct_addr()
Message-ID<rjiHG-4AY-71@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Dan Carpenter <dan.carpenter@oracle.com>

commit 6f3508f61c814ee852c199988a62bd954c50dfc1 upstream.

dct_sel_base_off is declared as a u64 but we're only using the lower 32
bits because of a shift wrapping bug. This can possibly truncate the
upper 16 bits of DctSelBaseOffset[47:26], causing us to misdecode the CS
row.

Fixes: c8e518d5673d ('amd64_edac: Sanitize f10_get_base_addr_offset')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Cc: Aravind Gopalakrishnan <Aravind.Gopalakrishnan@amd.com>
Cc: linux-edac <linux-edac@vger.kernel.org>
Link: http://lkml.kernel.org/r/20160120095451.GB19898@mwanda
Signed-off-by: Borislav Petkov <bp@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/edac/amd64_edac.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/edac/amd64_edac.c b/drivers/edac/amd64_edac.c
index 5907c17..a3e482e 100644
--- a/drivers/edac/amd64_edac.c
+++ b/drivers/edac/amd64_edac.c
@@ -1434,7 +1434,7 @@ static u64 f1x_get_norm_dct_addr(struct amd64_pvt *pvt, u8 range,
 	u64 chan_off;
 	u64 dram_base		= get_dram_base(pvt, range);
 	u64 hole_off		= f10_dhar_offset(pvt);
-	u64 dct_sel_base_off	= (pvt->dct_sel_hi & 0xFFFFFC00) << 16;
+	u64 dct_sel_base_off	= (u64)(pvt->dct_sel_hi & 0xFFFFFC00) << 16;
 
 	if (hi_rng) {
 		/*
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369843 — [PATCH 3.19.y-ckt 003/170] crypto: algif_hash - Require setkey before accept(2)

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:50 +0200
Subject[PATCH 3.19.y-ckt 003/170] crypto: algif_hash - Require setkey before accept(2)
Message-ID<rjiRj-4Fn-5@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit 6de62f15b581f920ade22d758f4c338311c2f0d4 upstream.

Hash implementations that require a key may crash if you use
them without setting a key.  This patch adds the necessary checks
so that if you do attempt to use them without a key that we return
-ENOKEY instead of proceeding.

This patch also adds a compatibility path to support old applications
that do acept(2) before setkey.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
[bwh: Backported to 3.2:
 - Add struct kiocb * parameter to {recv,send}msg ops
 - Adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>

Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/algif_hash.c | 201 +++++++++++++++++++++++++++++++++++++++++++++++++---
 1 file changed, 193 insertions(+), 8 deletions(-)

diff --git a/crypto/algif_hash.c b/crypto/algif_hash.c
index 43a595e..fa4096d 100644
--- a/crypto/algif_hash.c
+++ b/crypto/algif_hash.c
@@ -34,6 +34,11 @@ struct hash_ctx {
 	struct ahash_request req;
 };
 
+struct algif_hash_tfm {
+	struct crypto_ahash *hash;
+	bool has_key;
+};
+
 static int hash_sendmsg(struct kiocb *unused, struct socket *sock,
 			struct msghdr *msg, size_t ignored)
 {
@@ -248,22 +253,151 @@ static struct proto_ops algif_hash_ops = {
 	.accept		=	hash_accept,
 };
 
+static int hash_check_key(struct socket *sock)
+{
+	int err;
+	struct sock *psk;
+	struct alg_sock *pask;
+	struct algif_hash_tfm *tfm;
+	struct sock *sk = sock->sk;
+	struct alg_sock *ask = alg_sk(sk);
+
+	if (ask->refcnt)
+		return 0;
+
+	psk = ask->parent;
+	pask = alg_sk(ask->parent);
+	tfm = pask->private;
+
+	err = -ENOKEY;
+	lock_sock(psk);
+	if (!tfm->has_key)
+		goto unlock;
+
+	if (!pask->refcnt++)
+		sock_hold(psk);
+
+	ask->refcnt = 1;
+	sock_put(psk);
+
+	err = 0;
+
+unlock:
+	release_sock(psk);
+
+	return err;
+}
+
+static int hash_sendmsg_nokey(struct kiocb *unused, struct socket *sock,
+			      struct msghdr *msg, size_t size)
+{
+	int err;
+
+	err = hash_check_key(sock);
+	if (err)
+		return err;
+
+	return hash_sendmsg(unused, sock, msg, size);
+}
+
+static ssize_t hash_sendpage_nokey(struct socket *sock, struct page *page,
+				   int offset, size_t size, int flags)
+{
+	int err;
+
+	err = hash_check_key(sock);
+	if (err)
+		return err;
+
+	return hash_sendpage(sock, page, offset, size, flags);
+}
+
+static int hash_recvmsg_nokey(struct kiocb *unused, struct socket *sock,
+			      struct msghdr *msg, size_t ignored, int flags)
+{
+	int err;
+
+	err = hash_check_key(sock);
+	if (err)
+		return err;
+
+	return hash_recvmsg(unused, sock, msg, ignored, flags);
+}
+
+static int hash_accept_nokey(struct socket *sock, struct socket *newsock,
+			     int flags)
+{
+	int err;
+
+	err = hash_check_key(sock);
+	if (err)
+		return err;
+
+	return hash_accept(sock, newsock, flags);
+}
+
+static struct proto_ops algif_hash_ops_nokey = {
+	.family		=	PF_ALG,
+
+	.connect	=	sock_no_connect,
+	.socketpair	=	sock_no_socketpair,
+	.getname	=	sock_no_getname,
+	.ioctl		=	sock_no_ioctl,
+	.listen		=	sock_no_listen,
+	.shutdown	=	sock_no_shutdown,
+	.getsockopt	=	sock_no_getsockopt,
+	.mmap		=	sock_no_mmap,
+	.bind		=	sock_no_bind,
+	.setsockopt	=	sock_no_setsockopt,
+	.poll		=	sock_no_poll,
+
+	.release	=	af_alg_release,
+	.sendmsg	=	hash_sendmsg_nokey,
+	.sendpage	=	hash_sendpage_nokey,
+	.recvmsg	=	hash_recvmsg_nokey,
+	.accept		=	hash_accept_nokey,
+};
+
 static void *hash_bind(const char *name, u32 type, u32 mask)
 {
-	return crypto_alloc_ahash(name, type, mask);
+	struct algif_hash_tfm *tfm;
+	struct crypto_ahash *hash;
+
+	tfm = kzalloc(sizeof(*tfm), GFP_KERNEL);
+	if (!tfm)
+		return ERR_PTR(-ENOMEM);
+
+	hash = crypto_alloc_ahash(name, type, mask);
+	if (IS_ERR(hash)) {
+		kfree(tfm);
+		return ERR_CAST(hash);
+	}
+
+	tfm->hash = hash;
+
+	return tfm;
 }
 
 static void hash_release(void *private)
 {
-	crypto_free_ahash(private);
+	struct algif_hash_tfm *tfm = private;
+
+	crypto_free_ahash(tfm->hash);
+	kfree(tfm);
 }
 
 static int hash_setkey(void *private, const u8 *key, unsigned int keylen)
 {
-	return crypto_ahash_setkey(private, key, keylen);
+	struct algif_hash_tfm *tfm = private;
+	int err;
+
+	err = crypto_ahash_setkey(tfm->hash, key, keylen);
+	tfm->has_key = !err;
+
+	return err;
 }
 
-static void hash_sock_destruct(struct sock *sk)
+static void hash_sock_destruct_common(struct sock *sk)
 {
 	struct alg_sock *ask = alg_sk(sk);
 	struct hash_ctx *ctx = ask->private;
@@ -271,15 +405,40 @@ static void hash_sock_destruct(struct sock *sk)
 	sock_kzfree_s(sk, ctx->result,
 		      crypto_ahash_digestsize(crypto_ahash_reqtfm(&ctx->req)));
 	sock_kfree_s(sk, ctx, ctx->len);
+}
+
+static void hash_sock_destruct(struct sock *sk)
+{
+	hash_sock_destruct_common(sk);
 	af_alg_release_parent(sk);
 }
 
-static int hash_accept_parent(void *private, struct sock *sk)
+static void hash_release_parent_nokey(struct sock *sk)
+{
+	struct alg_sock *ask = alg_sk(sk);
+
+	if (!ask->refcnt) {
+		sock_put(ask->parent);
+		return;
+	}
+
+	af_alg_release_parent(sk);
+}
+
+static void hash_sock_destruct_nokey(struct sock *sk)
+{
+	hash_sock_destruct_common(sk);
+	hash_release_parent_nokey(sk);
+}
+
+static int hash_accept_parent_common(void *private, struct sock *sk)
 {
 	struct hash_ctx *ctx;
 	struct alg_sock *ask = alg_sk(sk);
-	unsigned len = sizeof(*ctx) + crypto_ahash_reqsize(private);
-	unsigned ds = crypto_ahash_digestsize(private);
+	struct algif_hash_tfm *tfm = private;
+	struct crypto_ahash *hash = tfm->hash;
+	unsigned len = sizeof(*ctx) + crypto_ahash_reqsize(hash);
+	unsigned ds = crypto_ahash_digestsize(hash);
 
 	ctx = sock_kmalloc(sk, len, GFP_KERNEL);
 	if (!ctx)
@@ -299,7 +458,7 @@ static int hash_accept_parent(void *private, struct sock *sk)
 
 	ask->private = ctx;
 
-	ahash_request_set_tfm(&ctx->req, private);
+	ahash_request_set_tfm(&ctx->req, hash);
 	ahash_request_set_callback(&ctx->req, CRYPTO_TFM_REQ_MAY_BACKLOG,
 				   af_alg_complete, &ctx->completion);
 
@@ -308,12 +467,38 @@ static int hash_accept_parent(void *private, struct sock *sk)
 	return 0;
 }
 
+static int hash_accept_parent(void *private, struct sock *sk)
+{
+	struct algif_hash_tfm *tfm = private;
+
+	if (!tfm->has_key && crypto_ahash_has_setkey(tfm->hash))
+		return -ENOKEY;
+
+	return hash_accept_parent_common(private, sk);
+}
+
+static int hash_accept_parent_nokey(void *private, struct sock *sk)
+{
+	int err;
+
+	err = hash_accept_parent_common(private, sk);
+	if (err)
+		goto out;
+
+	sk->sk_destruct = hash_sock_destruct_nokey;
+
+out:
+	return err;
+}
+
 static const struct af_alg_type algif_type_hash = {
 	.bind		=	hash_bind,
 	.release	=	hash_release,
 	.setkey		=	hash_setkey,
 	.accept		=	hash_accept_parent,
+	.accept_nokey	=	hash_accept_parent_nokey,
 	.ops		=	&algif_hash_ops,
+	.ops_nokey	=	&algif_hash_ops_nokey,
 	.name		=	"hash",
 	.owner		=	THIS_MODULE
 };
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369844 — [PATCH 3.19.y-ckt 013/170] ALSA: usb-audio: Fix NULL dereference in create_fixed_stream_quirk()

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:50 +0200
Subject[PATCH 3.19.y-ckt 013/170] ALSA: usb-audio: Fix NULL dereference in create_fixed_stream_quirk()
Message-ID<rjiRj-4Fn-7@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit 0f886ca12765d20124bd06291c82951fd49a33be upstream.

create_fixed_stream_quirk() may cause a NULL-pointer dereference by
accessing the non-existing endpoint when a USB device with a malformed
USB descriptor is used.

This patch avoids it simply by adding a sanity check of bNumEndpoints
before the accesses.

Bugzilla: https://bugzilla.suse.com/show_bug.cgi?id=971125
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/usb/quirks.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/sound/usb/quirks.c b/sound/usb/quirks.c
index fb9c394..20ed435 100644
--- a/sound/usb/quirks.c
+++ b/sound/usb/quirks.c
@@ -177,6 +177,12 @@ static int create_fixed_stream_quirk(struct snd_usb_audio *chip,
 	}
 	alts = &iface->altsetting[fp->altset_idx];
 	altsd = get_iface_desc(alts);
+	if (altsd->bNumEndpoints < 1) {
+		kfree(fp);
+		kfree(rate_table);
+		return -EINVAL;
+	}
+
 	fp->protocol = altsd->bInterfaceProtocol;
 
 	if (fp->datainterval == 0)
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369845 — [PATCH 3.19.y-ckt 008/170] crypto: algif_hash - Fix race condition in hash_check_key

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:50 +0200
Subject[PATCH 3.19.y-ckt 008/170] crypto: algif_hash - Fix race condition in hash_check_key
Message-ID<rjiRk-4Fn-9@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit ad46d7e33219218605ea619e32553daf4f346b9f upstream.

We need to lock the child socket in hash_check_key as otherwise
two simultaneous calls can cause the parent socket to be freed.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/algif_hash.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/crypto/algif_hash.c b/crypto/algif_hash.c
index e76385d..1952e4f 100644
--- a/crypto/algif_hash.c
+++ b/crypto/algif_hash.c
@@ -255,22 +255,23 @@ static struct proto_ops algif_hash_ops = {
 
 static int hash_check_key(struct socket *sock)
 {
-	int err;
+	int err = 0;
 	struct sock *psk;
 	struct alg_sock *pask;
 	struct algif_hash_tfm *tfm;
 	struct sock *sk = sock->sk;
 	struct alg_sock *ask = alg_sk(sk);
 
+	lock_sock(sk);
 	if (ask->refcnt)
-		return 0;
+		goto unlock_child;
 
 	psk = ask->parent;
 	pask = alg_sk(ask->parent);
 	tfm = pask->private;
 
 	err = -ENOKEY;
-	lock_sock(psk);
+	lock_sock_nested(psk, SINGLE_DEPTH_NESTING);
 	if (!tfm->has_key)
 		goto unlock;
 
@@ -284,6 +285,8 @@ static int hash_check_key(struct socket *sock)
 
 unlock:
 	release_sock(psk);
+unlock_child:
+	release_sock(sk);
 
 	return err;
 }
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369846 — [PATCH 3.19.y-ckt 005/170] crypto: algif_skcipher - Add key check exception for cipher_null

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:50 +0200
Subject[PATCH 3.19.y-ckt 005/170] crypto: algif_skcipher - Add key check exception for cipher_null
Message-ID<rjiRk-4Fn-11@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit 6e8d8ecf438792ecf7a3207488fb4eebc4edb040 upstream.

This patch adds an exception to the key check so that cipher_null
users may continue to use algif_skcipher without setting a key.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
[bwh: Backported to 3.2: use crypto_ablkcipher_has_setkey()]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>

Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/algif_skcipher.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/crypto/algif_skcipher.c b/crypto/algif_skcipher.c
index e98f2b8..75c2d72 100644
--- a/crypto/algif_skcipher.c
+++ b/crypto/algif_skcipher.c
@@ -757,7 +757,7 @@ static int skcipher_accept_parent(void *private, struct sock *sk)
 {
 	struct skcipher_tfm *tfm = private;
 
-	if (!tfm->has_key)
+	if (!tfm->has_key && crypto_ablkcipher_has_setkey(tfm->skcipher))
 		return -ENOKEY;
 
 	return skcipher_accept_parent_common(private, sk);
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369847 — [PATCH 3.19.y-ckt 015/170] include/linux/poison.h: fix LIST_POISON{1,2} offset

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:50 +0200
Subject[PATCH 3.19.y-ckt 015/170] include/linux/poison.h: fix LIST_POISON{1,2} offset
Message-ID<rjiRk-4Fn-15@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Vasily Kulikov <segoon@openwall.com>

commit 8a5e5e02fc83aaf67053ab53b359af08c6c49aaf upstream.

Poison pointer values should be small enough to find a room in
non-mmap'able/hardly-mmap'able space.  E.g.  on x86 "poison pointer space"
is located starting from 0x0.  Given unprivileged users cannot mmap
anything below mmap_min_addr, it should be safe to use poison pointers
lower than mmap_min_addr.

The current poison pointer values of LIST_POISON{1,2} might be too big for
mmap_min_addr values equal or less than 1 MB (common case, e.g.  Ubuntu
uses only 0x10000).  There is little point to use such a big value given
the "poison pointer space" below 1 MB is not yet exhausted.  Changing it
to a smaller value solves the problem for small mmap_min_addr setups.

The values are suggested by Solar Designer:
http://www.openwall.com/lists/oss-security/2015/05/02/6

Signed-off-by: Vasily Kulikov <segoon@openwall.com>
Cc: Solar Designer <solar@openwall.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 include/linux/poison.h | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/include/linux/poison.h b/include/linux/poison.h
index 2110a81..253c9b4 100644
--- a/include/linux/poison.h
+++ b/include/linux/poison.h
@@ -19,8 +19,8 @@
  * under normal circumstances, used to verify that nobody uses
  * non-initialized list entries.
  */
-#define LIST_POISON1  ((void *) 0x00100100 + POISON_POINTER_DELTA)
-#define LIST_POISON2  ((void *) 0x00200200 + POISON_POINTER_DELTA)
+#define LIST_POISON1  ((void *) 0x100 + POISON_POINTER_DELTA)
+#define LIST_POISON2  ((void *) 0x200 + POISON_POINTER_DELTA)
 
 /********** include/linux/timer.h **********/
 /*
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369848 — [PATCH 3.19.y-ckt 017/170] USB: cdc-acm: more sanity checking

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:50 +0200
Subject[PATCH 3.19.y-ckt 017/170] USB: cdc-acm: more sanity checking
Message-ID<rjiRk-4Fn-19@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Oliver Neukum <oneukum@suse.com>

commit 8835ba4a39cf53f705417b3b3a94eb067673f2c9 upstream.

An attack has become available which pretends to be a quirky
device circumventing normal sanity checks and crashes the kernel
by an insufficient number of interfaces. This patch adds a check
to the code path for quirky devices.

Signed-off-by: Oliver Neukum <ONeukum@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/usb/class/cdc-acm.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/usb/class/cdc-acm.c b/drivers/usb/class/cdc-acm.c
index 672005d..9fa7296 100644
--- a/drivers/usb/class/cdc-acm.c
+++ b/drivers/usb/class/cdc-acm.c
@@ -1109,6 +1109,9 @@ static int acm_probe(struct usb_interface *intf,
 	if (quirks == NO_UNION_NORMAL) {
 		data_interface = usb_ifnum_to_if(usb_dev, 1);
 		control_interface = usb_ifnum_to_if(usb_dev, 0);
+		/* we would crash */
+		if (!data_interface || !control_interface)
+			return -ENODEV;
 		goto skip_normal_probe;
 	}
 
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369849 — [PATCH 3.19.y-ckt 012/170] USB: iowarrior: fix oops with malicious USB descriptors

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:50 +0200
Subject[PATCH 3.19.y-ckt 012/170] USB: iowarrior: fix oops with malicious USB descriptors
Message-ID<rjiRk-4Fn-17@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Josh Boyer <jwboyer@fedoraproject.org>

commit 4ec0ef3a82125efc36173062a50624550a900ae0 upstream.

The iowarrior driver expects at least one valid endpoint.  If given
malicious descriptors that specify 0 for the number of endpoints,
it will crash in the probe function.  Ensure there is at least
one endpoint on the interface before using it.

The full report of this issue can be found here:
http://seclists.org/bugtraq/2016/Mar/87

Reported-by: Ralf Spenneberg <ralf@spenneberg.net>
Signed-off-by: Josh Boyer <jwboyer@fedoraproject.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/usb/misc/iowarrior.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/usb/misc/iowarrior.c b/drivers/usb/misc/iowarrior.c
index c6bfd13..1950e87 100644
--- a/drivers/usb/misc/iowarrior.c
+++ b/drivers/usb/misc/iowarrior.c
@@ -787,6 +787,12 @@ static int iowarrior_probe(struct usb_interface *interface,
 	iface_desc = interface->cur_altsetting;
 	dev->product_id = le16_to_cpu(udev->descriptor.idProduct);
 
+	if (iface_desc->desc.bNumEndpoints < 1) {
+		dev_err(&interface->dev, "Invalid number of endpoints\n");
+		retval = -EINVAL;
+		goto error;
+	}
+
 	/* set up the endpoint information */
 	for (i = 0; i < iface_desc->desc.bNumEndpoints; ++i) {
 		endpoint = &iface_desc->endpoint[i].desc;
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369850 — [PATCH 3.19.y-ckt 006/170] crypto: algif_hash - Remove custom release parent function

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:50 +0200
Subject[PATCH 3.19.y-ckt 006/170] crypto: algif_hash - Remove custom release parent function
Message-ID<rjiRk-4Fn-21@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit f1d84af1835846a5a2b827382c5848faf2bb0e75 upstream.

This patch removes the custom release parent function as the
generic af_alg_release_parent now works for nokey sockets too.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/algif_hash.c | 43 +++----------------------------------------
 1 file changed, 3 insertions(+), 40 deletions(-)

diff --git a/crypto/algif_hash.c b/crypto/algif_hash.c
index fa4096d..e76385d 100644
--- a/crypto/algif_hash.c
+++ b/crypto/algif_hash.c
@@ -397,7 +397,7 @@ static int hash_setkey(void *private, const u8 *key, unsigned int keylen)
 	return err;
 }
 
-static void hash_sock_destruct_common(struct sock *sk)
+static void hash_sock_destruct(struct sock *sk)
 {
 	struct alg_sock *ask = alg_sk(sk);
 	struct hash_ctx *ctx = ask->private;
@@ -405,33 +405,10 @@ static void hash_sock_destruct_common(struct sock *sk)
 	sock_kzfree_s(sk, ctx->result,
 		      crypto_ahash_digestsize(crypto_ahash_reqtfm(&ctx->req)));
 	sock_kfree_s(sk, ctx, ctx->len);
-}
-
-static void hash_sock_destruct(struct sock *sk)
-{
-	hash_sock_destruct_common(sk);
-	af_alg_release_parent(sk);
-}
-
-static void hash_release_parent_nokey(struct sock *sk)
-{
-	struct alg_sock *ask = alg_sk(sk);
-
-	if (!ask->refcnt) {
-		sock_put(ask->parent);
-		return;
-	}
-
 	af_alg_release_parent(sk);
 }
 
-static void hash_sock_destruct_nokey(struct sock *sk)
-{
-	hash_sock_destruct_common(sk);
-	hash_release_parent_nokey(sk);
-}
-
-static int hash_accept_parent_common(void *private, struct sock *sk)
+static int hash_accept_parent_nokey(void *private, struct sock *sk)
 {
 	struct hash_ctx *ctx;
 	struct alg_sock *ask = alg_sk(sk);
@@ -474,21 +451,7 @@ static int hash_accept_parent(void *private, struct sock *sk)
 	if (!tfm->has_key && crypto_ahash_has_setkey(tfm->hash))
 		return -ENOKEY;
 
-	return hash_accept_parent_common(private, sk);
-}
-
-static int hash_accept_parent_nokey(void *private, struct sock *sk)
-{
-	int err;
-
-	err = hash_accept_parent_common(private, sk);
-	if (err)
-		goto out;
-
-	sk->sk_destruct = hash_sock_destruct_nokey;
-
-out:
-	return err;
+	return hash_accept_parent_nokey(private, sk);
 }
 
 static const struct af_alg_type algif_type_hash = {
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369851 — [PATCH 3.19.y-ckt 002/170] crypto: algif_skcipher - Add nokey compatibility path

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:50 +0200
Subject[PATCH 3.19.y-ckt 002/170] crypto: algif_skcipher - Add nokey compatibility path
Message-ID<rjiRk-4Fn-25@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit a0fa2d037129a9849918a92d91b79ed6c7bd2818 upstream.

This patch adds a compatibility path to support old applications
that do acept(2) before setkey.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
[bwh: Backported to 3.2: add struct kiocb * parameter to {recv,send}msg ops]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>

Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 crypto/algif_skcipher.c | 149 ++++++++++++++++++++++++++++++++++++++++++++++--
 1 file changed, 144 insertions(+), 5 deletions(-)

diff --git a/crypto/algif_skcipher.c b/crypto/algif_skcipher.c
index e8eedce..e98f2b8 100644
--- a/crypto/algif_skcipher.c
+++ b/crypto/algif_skcipher.c
@@ -546,6 +546,99 @@ static struct proto_ops algif_skcipher_ops = {
 	.poll		=	skcipher_poll,
 };
 
+static int skcipher_check_key(struct socket *sock)
+{
+	int err;
+	struct sock *psk;
+	struct alg_sock *pask;
+	struct skcipher_tfm *tfm;
+	struct sock *sk = sock->sk;
+	struct alg_sock *ask = alg_sk(sk);
+
+	if (ask->refcnt)
+		return 0;
+
+	psk = ask->parent;
+	pask = alg_sk(ask->parent);
+	tfm = pask->private;
+
+	err = -ENOKEY;
+	lock_sock(psk);
+	if (!tfm->has_key)
+		goto unlock;
+
+	if (!pask->refcnt++)
+		sock_hold(psk);
+
+	ask->refcnt = 1;
+	sock_put(psk);
+
+	err = 0;
+
+unlock:
+	release_sock(psk);
+
+	return err;
+}
+
+static int skcipher_sendmsg_nokey(struct kiocb *unused, struct socket *sock,
+				  struct msghdr *msg, size_t size)
+{
+	int err;
+
+	err = skcipher_check_key(sock);
+	if (err)
+		return err;
+
+	return skcipher_sendmsg(unused, sock, msg, size);
+}
+
+static ssize_t skcipher_sendpage_nokey(struct socket *sock, struct page *page,
+				       int offset, size_t size, int flags)
+{
+	int err;
+
+	err = skcipher_check_key(sock);
+	if (err)
+		return err;
+
+	return skcipher_sendpage(sock, page, offset, size, flags);
+}
+
+static int skcipher_recvmsg_nokey(struct kiocb *unused, struct socket *sock,
+				  struct msghdr *msg, size_t ignored, int flags)
+{
+	int err;
+
+	err = skcipher_check_key(sock);
+	if (err)
+		return err;
+
+	return skcipher_recvmsg(unused, sock, msg, ignored, flags);
+}
+
+static struct proto_ops algif_skcipher_ops_nokey = {
+	.family		=	PF_ALG,
+
+	.connect	=	sock_no_connect,
+	.socketpair	=	sock_no_socketpair,
+	.getname	=	sock_no_getname,
+	.ioctl		=	sock_no_ioctl,
+	.listen		=	sock_no_listen,
+	.shutdown	=	sock_no_shutdown,
+	.getsockopt	=	sock_no_getsockopt,
+	.mmap		=	sock_no_mmap,
+	.bind		=	sock_no_bind,
+	.accept		=	sock_no_accept,
+	.setsockopt	=	sock_no_setsockopt,
+
+	.release	=	af_alg_release,
+	.sendmsg	=	skcipher_sendmsg_nokey,
+	.sendpage	=	skcipher_sendpage_nokey,
+	.recvmsg	=	skcipher_recvmsg_nokey,
+	.poll		=	skcipher_poll,
+};
+
 static void *skcipher_bind(const char *name, u32 type, u32 mask)
 {
 	struct skcipher_tfm *tfm;
@@ -585,7 +678,7 @@ static int skcipher_setkey(void *private, const u8 *key, unsigned int keylen)
 	return err;
 }
 
-static void skcipher_sock_destruct(struct sock *sk)
+static void skcipher_sock_destruct_common(struct sock *sk)
 {
 	struct alg_sock *ask = alg_sk(sk);
 	struct skcipher_ctx *ctx = ask->private;
@@ -594,10 +687,33 @@ static void skcipher_sock_destruct(struct sock *sk)
 	skcipher_free_sgl(sk);
 	sock_kzfree_s(sk, ctx->iv, crypto_ablkcipher_ivsize(tfm));
 	sock_kfree_s(sk, ctx, ctx->len);
+}
+
+static void skcipher_sock_destruct(struct sock *sk)
+{
+	skcipher_sock_destruct_common(sk);
 	af_alg_release_parent(sk);
 }
 
-static int skcipher_accept_parent(void *private, struct sock *sk)
+static void skcipher_release_parent_nokey(struct sock *sk)
+{
+	struct alg_sock *ask = alg_sk(sk);
+
+	if (!ask->refcnt) {
+		sock_put(ask->parent);
+		return;
+	}
+
+	af_alg_release_parent(sk);
+}
+
+static void skcipher_sock_destruct_nokey(struct sock *sk)
+{
+	skcipher_sock_destruct_common(sk);
+	skcipher_release_parent_nokey(sk);
+}
+
+static int skcipher_accept_parent_common(void *private, struct sock *sk)
 {
 	struct skcipher_ctx *ctx;
 	struct alg_sock *ask = alg_sk(sk);
@@ -605,9 +721,6 @@ static int skcipher_accept_parent(void *private, struct sock *sk)
 	struct crypto_ablkcipher *skcipher = tfm->skcipher;
 	unsigned int len = sizeof(*ctx) + crypto_ablkcipher_reqsize(skcipher);
 
-	if (!tfm->has_key)
-		return -ENOKEY;
-
 	ctx = sock_kmalloc(sk, len, GFP_KERNEL);
 	if (!ctx)
 		return -ENOMEM;
@@ -640,12 +753,38 @@ static int skcipher_accept_parent(void *private, struct sock *sk)
 	return 0;
 }
 
+static int skcipher_accept_parent(void *private, struct sock *sk)
+{
+	struct skcipher_tfm *tfm = private;
+
+	if (!tfm->has_key)
+		return -ENOKEY;
+
+	return skcipher_accept_parent_common(private, sk);
+}
+
+static int skcipher_accept_parent_nokey(void *private, struct sock *sk)
+{
+	int err;
+
+	err = skcipher_accept_parent_common(private, sk);
+	if (err)
+		goto out;
+
+	sk->sk_destruct = skcipher_sock_destruct_nokey;
+
+out:
+	return err;
+}
+
 static const struct af_alg_type algif_type_skcipher = {
 	.bind		=	skcipher_bind,
 	.release	=	skcipher_release,
 	.setkey		=	skcipher_setkey,
 	.accept		=	skcipher_accept_parent,
+	.accept_nokey	=	skcipher_accept_parent_nokey,
 	.ops		=	&algif_skcipher_ops,
+	.ops_nokey	=	&algif_skcipher_ops_nokey,
 	.name		=	"skcipher",
 	.owner		=	THIS_MODULE
 };
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1369852 — [PATCH 3.19.y-ckt 014/170] ALSA: usb-audio: Add sanity checks for endpoint accesses

FromKamal Mostafa <kamal@canonical.com>
Date2016-04-02 03:50 +0200
Subject[PATCH 3.19.y-ckt 014/170] ALSA: usb-audio: Add sanity checks for endpoint accesses
Message-ID<rjiRk-4Fn-27@gated-at.bofh.it>
In reply to#1369682
3.19.8-ckt18 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit 447d6275f0c21f6cc97a88b3a0c601436a4cdf2a upstream.

Add some sanity check codes before actually accessing the endpoint via
get_endpoint() in order to avoid the invalid access through a
malformed USB descriptor.  Mostly just checking bNumEndpoints, but in
one place (snd_microii_spdif_default_get()), the validity of iface and
altsetting index is checked as well.

Bugzilla: https://bugzilla.suse.com/show_bug.cgi?id=971125
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/usb/clock.c        | 2 ++
 sound/usb/endpoint.c     | 3 +++
 sound/usb/mixer_quirks.c | 4 ++++
 sound/usb/pcm.c          | 2 ++
 4 files changed, 11 insertions(+)

diff --git a/sound/usb/clock.c b/sound/usb/clock.c
index 03fed66..56216a2 100644
--- a/sound/usb/clock.c
+++ b/sound/usb/clock.c
@@ -285,6 +285,8 @@ static int set_sample_rate_v1(struct snd_usb_audio *chip, int iface,
 	unsigned char data[3];
 	int err, crate;
 
+	if (get_iface_desc(alts)->bNumEndpoints < 1)
+		return -EINVAL;
 	ep = get_endpoint(alts, 0)->bEndpointAddress;
 
 	/* if endpoint doesn't have sampling rate control, bail out */
diff --git a/sound/usb/endpoint.c b/sound/usb/endpoint.c
index 03b0744..e7f470a 100644
--- a/sound/usb/endpoint.c
+++ b/sound/usb/endpoint.c
@@ -413,6 +413,9 @@ exit_clear:
  *
  * New endpoints will be added to chip->ep_list and must be freed by
  * calling snd_usb_endpoint_free().
+ *
+ * For SND_USB_ENDPOINT_TYPE_SYNC, the caller needs to guarantee that
+ * bNumEndpoints > 1 beforehand.
  */
 struct snd_usb_endpoint *snd_usb_add_endpoint(struct snd_usb_audio *chip,
 					      struct usb_host_interface *alts,
diff --git a/sound/usb/mixer_quirks.c b/sound/usb/mixer_quirks.c
index db9547d..f8ffcda4 100644
--- a/sound/usb/mixer_quirks.c
+++ b/sound/usb/mixer_quirks.c
@@ -1532,7 +1532,11 @@ static int snd_microii_spdif_default_get(struct snd_kcontrol *kcontrol,
 
 	/* use known values for that card: interface#1 altsetting#1 */
 	iface = usb_ifnum_to_if(chip->dev, 1);
+	if (!iface || iface->num_altsetting < 2)
+		return -EINVAL;
 	alts = &iface->altsetting[1];
+	if (get_iface_desc(alts)->bNumEndpoints < 1)
+		return -EINVAL;
 	ep = get_endpoint(alts, 0)->bEndpointAddress;
 
 	err = snd_usb_ctl_msg(chip->dev,
diff --git a/sound/usb/pcm.c b/sound/usb/pcm.c
index 0d8aba5..a7e97ba 100644
--- a/sound/usb/pcm.c
+++ b/sound/usb/pcm.c
@@ -159,6 +159,8 @@ static int init_pitch_v1(struct snd_usb_audio *chip, int iface,
 	unsigned char data[1];
 	int err;
 
+	if (get_iface_desc(alts)->bNumEndpoints < 1)
+		return -EINVAL;
 	ep = get_endpoint(alts, 0)->bEndpointAddress;
 
 	data[0] = 1;
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


Page 8 of 9 — ← Prev page 1 2 3 4 5 6 7 [8] 9  Next page →

Back to top | Article view | linux.kernel


csiph-web