Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1467049 > unrolled thread

[PATCH 3.10 000/180] 3.10.103-stable review

Started byWilly Tarreau <w@1wt.eu>
First post2016-08-21 17:40 +0200
Last post2016-08-21 18:20 +0200
Articles 20 on this page of 141 — 4 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.10 000/180] 3.10.103-stable review Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
    [PATCH 3.10 036/180] usb: renesas_usbhs: protect the CFIFOSEL setting in usbhsg_ep_enable() Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
    [PATCH 3.10 028/180] udp: properly support MSG_PEEK with truncated buffers Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
    [PATCH 3.10 017/180] netfilter: ip_tables: simplify translate_compat_table args Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
    [PATCH 3.10 132/180] ALSA: timer: Fix leak in SNDRV_TIMER_IOCTL_PARAMS Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
    [PATCH 3.10 053/180] MIPS: KVM: Propagate kseg0/mapped tlb fault errors Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
    [PATCH 3.10 008/180] netfilter: x_tables: add and use xt_check_entry_offsets Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
    [PATCH 3.10 135/180] scsi: fix race between simultaneous decrements of ->host_failed Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
    [PATCH 3.10 131/180] ALSA: ctl: Stop notification after disconnection Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
    [PATCH 3.10 178/180] isdn: hfcpci_softirq: get func return to suppress compiler warning Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
    [PATCH 3.10 177/180] net: rfkill: Do not ignore errors from regulator_enable() Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 145/180] ARC: use ASL assembler mnemonic Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 093/180] KVM: x86: fix OOPS after invalid KVM_SET_DEBUGREGS Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 153/180] x86/mm: Improve switch_mm() barrier comments Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 061/180] Input: xpad - validate USB endpoint count during probe Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 104/180] sit: correct IP protocol used in ipip6_err Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 162/180] s5p-mfc: Add release callback for memory region devs Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 126/180] iio:ad7266: Fix broken regulator error handling Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 049/180] tcp: consider recv buf for the initial window scale Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 127/180] iio:ad7266: Fix probe deferral for vref Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 054/180] MIPS: math-emu: Fix jalr emulation when rd == $0 Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 173/180] be2iscsi: Fix bogus WARN_ON length check Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 020/180] netfilter: ensure number of counters is >0 in do_replace() Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 109/180] IB/mlx4: Properly initialize GRH TClass and FlowLabel in AHs Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 019/180] netfilter: x_tables: xt_compat_match_from_user doesn't need a retval Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 165/180] netlabel: add address family checks to netlbl_{sock,req}_delattr() Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 039/180] cdc_ncm: do not call usbnet_link_change from cdc_ncm_bind Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 055/180] MIPS: Fix siginfo.h to use strict posix types Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 071/180] powerpc/iommu: Remove the dependency on EEH struct in DDW mechanism Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 174/180] squash mm: Export migrate_page_... : also make it non-static Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 026/180] signal: remove warning about using SI_TKILL in rt_[tg]sigqueueinfo Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 129/180] ALSA: dummy: Fix a use-after-free at closing Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 009/180] netfilter: x_tables: kill check_entry helper Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 158/180] net/irda: fix NULL pointer dereference on memory allocation failure Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 015/180] netfilter: x_tables: don't reject valid target size on some architectures Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 058/180] MIPS: KVM: Fix modular KVM under QEMU Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 113/180] x86, build: copy ldlinux.c32 to image.iso Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 112/180] IB/mlx4: Fix the SQ size of an RC QP Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 095/180] arm: oabi compat: add missing access checks Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 096/180] parisc: Fix pagefault crash in unaligned __get_user() call Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 059/180] Input: uinput - handle compat ioctl for UI_SET_PHYS Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 064/180] aacraid: Fix for aac_command_thread hang Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 124/180] staging: iio: accel: fix error check Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 052/180] MIPS: KVM: Fix gfn range check in kseg0 tlb faults Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 012/180] netfilter: x_tables: check standard target size too Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
    [PATCH 3.10 176/180] ALSA: oxygen: Fix logical-not-parentheses warning Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 111/180] IB/IPoIB: Don't update neigh validity for unresolved entries Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 163/180] Bluetooth: Fix l2cap_sock_setsockopt() with optname BT_RCVMTU Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 094/180] ARM: fix PTRACE_SETVFPREGS on SMP systems Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 024/180] perf/x86: Honor the architectural performance monitoring version Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 130/180] ALSA: au88x0: Fix calculation in vortex_wtdma_bufshift() Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 141/180] arc: unwind: warn only once if DW2_UNWIND is disabled Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 092/180] xfs: skip stale inodes in xfs_iflush_cluster Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 050/180] MIPS: KVM: Fix mapped fault broken commpage handling Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 128/180] tty/vt/keyboard: fix OOB access in do_compute_shiftstate() Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 161/180] s5p-mfc: Set device name for reserved memory region devs Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 140/180] fs/nilfs2: fix potential underflow in call to crc32_le Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 068/180] powerpc: Fix definition of SIAR and SDAR registers Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 078/180] drm/radeon: add a delay after ATPX dGPU power off Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 018/180] netfilter: ip6_tables: simplify translate_compat_table args Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 136/180] scsi: remove scsi_end_request Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 152/180] sctp: Prevent soft lockup when sctp_accept() is called during a timeout event Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 062/180] ath5k: Change led pin configuration for compaq c700 laptop Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 100/180] xfs: fix up backport error in fs/xfs/xfs_inode.c Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 076/180] drm/fb_helper: Fix references to dev->mode_config.num_connector Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 099/180] fix d_walk()/non-delayed __d_free() race Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 156/180] block: fix use-after-free in seq file Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 121/180] tracing: Handle NULL formats in hold_module_trace_bprintk_format() Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 066/180] rtlwifi: Fix logic error in enter/exit power-save mode Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 167/180] ftrace/recordmcount: Work around for addition of metag magic but not relocations Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 149/180] can: fix oops caused by wrong rtnl dellink usage Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 037/180] x86/mm: Add barriers and document switch_mm()-vs-flush synchronization Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 134/180] ALSA: timer: Fix leak in events via snd_timer_user_tinterrupt Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 098/180] wext: Fix 32 bit iwpriv compatibility issue with 64 bit Kernel Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
      Re: [PATCH 3.10 098/180] wext: Fix 32 bit iwpriv compatibility  issue with 64 bit Kernel Johannes Berg <johannes@sipsolutions.net> - 2016-08-22 07:40 +0200
        Re: [PATCH 3.10 098/180] wext: Fix 32 bit iwpriv compatibility issue  with 64 bit Kernel Willy Tarreau <w@1wt.eu> - 2016-08-22 07:50 +0200
    [PATCH 3.10 044/180] libceph: apply new_state before new_up_client on incrementals Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 045/180] tmpfs: don't undo fallocate past its last page Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 168/180] metag: Fix __cmpxchg_u32 asm constraint for CMP Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 046/180] tmpfs: fix regression hang in fallocate undo Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 075/180] drm/gma500: Fix possible out of bounds read Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 169/180] ubi: Make volume resize power cut aware Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 179/180] stb6100: fix buffer length check in stb6100_write_reg_range() Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 089/180] dma-debug: avoid spinlock recursion when disabling dma-debug Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 139/180] s390/seccomp: fix error return for filtered system calls Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 103/180] crypto: scatterwalk - Fix test in scatterwalk_done Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 147/180] mmc: block: fix packed command header endianness Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
    [PATCH 3.10 102/180] crypto: gcm - Filter out async ghash if necessary Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 142/180] xen/pciback: Fix conf_space read/write overlap check. Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on error Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
      Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on  error Dave Chinner <david@fromorbit.com> - 2016-08-22 06:30 +0200
        Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on  error Willy Tarreau <w@1wt.eu> - 2016-08-22 07:20 +0200
          Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on  error Willy Tarreau <w@1wt.eu> - 2016-08-22 07:30 +0200
          Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on  error Dave Chinner <dchinner@redhat.com> - 2016-08-22 13:00 +0200
            Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on  error Willy Tarreau <w@1wt.eu> - 2016-08-22 13:10 +0200
    [PATCH 3.10 003/180] netfilter: x_tables: validate e->target_offset early Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 025/180] perf/x86: Fix undefined shift on 32-bit kernels Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 164/180] cifs: Check for existing directory when opening file with O_CREAT Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 091/180] xfs: fix inode validity check in xfs_iflush_cluster Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 038/180] pipe: limit the per-user amount of pages allocated in pipes Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 118/180] UBIFS: Implement ->migratepage() Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 175/180] HID: hid-input: Add parentheses to quell gcc warning Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 065/180] PCI: Disable all BAR sizing for devices with non-compliant BARs Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 144/180] ecryptfs: don't allow mmap when the lower fs doesn't support it Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 043/180] HID: hiddev: validate num_values for HIDIOCGUSAGES, HIDIOCSUSAGES commands Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 067/180] powerpc/book3s64: Fix branching to OOL handlers in relocatable kernel Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 157/180] fuse: fix wrong assignment of ->flags in fuse_send_init() Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 023/180] netfilter: x_tables: introduce and use xt_copy_counters_from_user Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 011/180] netfilter: x_tables: add compat version of xt_check_entry_offsets Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 122/180] base: make module_create_drivers_dir race-free Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 087/180] ext4: short-cut orphan cleanup on error Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 125/180] iio: accel: kxsd9: fix the usage of spi_w8r8() Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 070/180] powerpc/pseries/eeh: Handle RTAS delay requests in configure_bridge Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 107/180] mac80211: mesh: flush mesh paths unconditionally Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 138/180] xen/acpi: allow xen-acpi-processor driver to load on Xen 4.7 Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 119/180] cdc_ncm: workaround for EM7455 "silent" data interface Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 106/180] net: alx: Work around the DMA RX overflow issue Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 032/180] USB: EHCI: declare hostpc register as zero-length array Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 031/180] USB: fix up faulty backports Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 150/180] ipr: Clear interrupt on croc/crocodile when running with LSI Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 041/180] mm: migrate dirty page without clear_page_dirty_for_io etc Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 116/180] NFS: Fix another OPEN_DOWNGRADE bug Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 069/180] powerpc: Use privileged SPR number for MMCR2 Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 085/180] ext4: check for extents that wrap around Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 072/180] powerpc/pseries: Fix PCI config address for DDW Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 110/180] IB/security: Restrict use of the write() interface Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 133/180] ALSA: timer: Fix leak in events via snd_timer_user_ccallback Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 123/180] iio: Fix error handling in iio_trigger_attach_poll_func Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 172/180] module: Invalidate signatures on force-loaded modules Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 160/180] hp-wmi: Fix wifi cannot be hard-unblocked Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
    [PATCH 3.10 004/180] netfilter: x_tables: make sure e->next_offset covers remaining blob size Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
    [PATCH 3.10 042/180] printk: do cond_resched() between lines while outputting to consoles Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
    [PATCH 3.10 001/180] X.509: remove possible code fragility: enumeration values not handled Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
    [PATCH 3.10 097/180] ecryptfs: forbid opening files without mmap handler Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
    [PATCH 3.10 021/180] netfilter: x_tables: do compat validation via translate_table Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
    [PATCH 3.10 030/180] USB: usbfs: fix potential infoleak in devio Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
    [PATCH 3.10 040/180] KEYS: potential uninitialized variable Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
    [PATCH 3.10 034/180] usb: musb: Stop bulk endpoint while queue is rotated Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
    [PATCH 3.10 005/180] netfilter: x_tables: fix unconditional helper Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
    [PATCH 3.10 014/180] netfilter: x_tables: validate all offsets and sizes in a rule Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
    [PATCH 3.10 022/180] Revert "netfilter: ensure number of counters is >0 in do_replace()" Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200

Page 1 of 8  [1] 2 3 4 5 6 7 8  Next page →


#1467049 — [PATCH 3.10 000/180] 3.10.103-stable review

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:40 +0200
Subject[PATCH 3.10 000/180] 3.10.103-stable review
Message-ID<s8D0R-26R-3@gated-at.bofh.it>
This is the start of the stable review cycle for the 3.10.103 release.
All patches will be posted as a response to this one. If anyone has any
issue with these being applied, please let me know. If anyone thinks some
important patches are missing and should be added prior to the release,
please report them quickly with their respective mainline commit IDs.

Responses should be made by Fri Aug 26 17:04:04 CEST 2016.
Anything received after that time might be too late. If someone
wants a bit more time for a deeper review, please let me know.

The whole patch series can be found in one patch at :
   https://kernel.org/pub/linux/kernel/v3.x/stable-review/patch-3.10.103-rc1.gz

The shortlog and diffstat are appended below.

Thanks,
Willy

===============


Al Viro (1):
  fix d_walk()/non-delayed __d_free() race

Alan Stern (2):
  USB: fix invalid memory access in hub_activate()
  USB: EHCI: declare hostpc register as zero-length array

Alex Deucher (3):
  drm/radeon: fix asic initialization for virtualized environments
  drm/radeon: add a delay after ATPX dGPU power off
  drm/radeon: fix firmware info version checks

Alex Hung (1):
  hp-wmi: Fix wifi cannot be hard-unblocked

Alexander Shiyan (1):
  stb6100: fix buffer length check in stb6100_write_reg_range()

Alexey Brodkin (1):
  arc: unwind: warn only once if DW2_UNWIND is disabled

Amadeusz Sławiński (1):
  Bluetooth: Fix l2cap_sock_setsockopt() with optname BT_RCVMTU

Andi Kleen (1):
  x86, asmlinkage, apm: Make APM data structure used from assembler
    visible

Andrew Goodbody (2):
  usb: musb: Stop bulk endpoint while queue is rotated
  usb: musb: Ensure rx reinit occurs for shared_fifo endpoints

Andrey Grodzovsky (1):
  xen/pciback: Fix conf_space read/write overlap check.

Andrey Ryabinin (1):
  perf/x86: Fix undefined shift on 32-bit kernels

Andy Lutomirski (2):
  x86/mm: Add barriers and document switch_mm()-vs-flush synchronization
  x86/mm: Improve switch_mm() barrier comments

Anthony Romano (1):
  tmpfs: don't undo fallocate past its last page

Antonio Alecrim Jr (2):
  X.509: remove possible code fragility: enumeration values not handled
  isdn: hfcpci_softirq: get func return to suppress compiler warning

Ben Hutchings (1):
  module: Invalidate signatures on force-loaded modules

Bernhard Thaler (1):
  Revert "netfilter: ensure number of counters is >0 in do_replace()"

Bjørn Mork (1):
  cdc_ncm: do not call usbnet_link_change from cdc_ncm_bind

Bj�rn Mork (1):
  cdc_ncm: workaround for EM7455 "silent" data interface

Bob Copeland (1):
  mac80211: mesh: flush mesh paths unconditionally

Borislav Petkov (1):
  x86/amd_nb: Fix boot crash on non-AMD systems

Brian King (1):
  ipr: Clear interrupt on croc/crocodile when running with LSI

Cameron Gutman (1):
  Input: xpad - validate USB endpoint count during probe

Charles (Chas) Williams (1):
  tcp: make challenge acks less predictable

Christoph Hellwig (1):
  scsi: remove scsi_end_request

Crestez Dan Leonard (1):
  iio: Fix error handling in iio_trigger_attach_poll_func

Cyril Bur (1):
  powerpc/tm: Always reclaim in start_thread() for exec() class syscalls

Dan Carpenter (1):
  KEYS: potential uninitialized variable

Daniele Palmas (1):
  USB: serial: option: add support for Telit LE910 PID 0x1206

Dave Chinner (3):
  xfs: xfs_iflush_cluster fails to abort on error
  xfs: fix inode validity check in xfs_iflush_cluster
  xfs: skip stale inodes in xfs_iflush_cluster

Dave Jones (1):
  netfilter: ensure number of counters is >0 in do_replace()

Dave Weinstein (1):
  arm: oabi compat: add missing access checks

David Howells (1):
  KEYS: 64-bit MIPS needs to use compat_sys_keyctl for 32-bit userspace

Dmitri Epshtein (1):
  net: mvneta: set real interrupt per packet for tx_done

Dmitry Torokhov (1):
  tty/vt/keyboard: fix OOB access in do_compute_shiftstate()

Erez Shitrit (1):
  IB/IPoIB: Don't update neigh validity for unresolved entries

Eric Dumazet (1):
  udp: properly support MSG_PEEK with truncated buffers

Feng Tang (1):
  net: alx: Work around the DMA RX overflow issue

Florian Westphal (19):
  netfilter: x_tables: validate e->target_offset early
  netfilter: x_tables: make sure e->next_offset covers remaining blob
    size
  netfilter: x_tables: fix unconditional helper
  netfilter: x_tables: don't move to non-existent next rule
  netfilter: x_tables: validate targets of jumps
  netfilter: x_tables: add and use xt_check_entry_offsets
  netfilter: x_tables: kill check_entry helper
  netfilter: x_tables: assert minimum target size
  netfilter: x_tables: add compat version of xt_check_entry_offsets
  netfilter: x_tables: check standard target size too
  netfilter: x_tables: check for bogus target offset
  netfilter: x_tables: validate all offsets and sizes in a rule
  netfilter: x_tables: don't reject valid target size on some
    architectures
  netfilter: arp_tables: simplify translate_compat_table args
  netfilter: ip_tables: simplify translate_compat_table args
  netfilter: ip6_tables: simplify translate_compat_table args
  netfilter: x_tables: xt_compat_match_from_user doesn't need a retval
  netfilter: x_tables: do compat validation via translate_table
  netfilter: x_tables: introduce and use xt_copy_counters_from_user

Gavin Shan (1):
  powerpc/pseries: Fix PCI config address for DDW

Greg Kroah-Hartman (1):
  xfs: fix up backport error in fs/xfs/xfs_inode.c

Guilherme G. Piccoli (1):
  powerpc/iommu: Remove the dependency on EEH struct in DDW mechanism

H. Peter Anvin (1):
  x86, build: copy ldlinux.c32 to image.iso

Hari Bathini (1):
  powerpc/book3s64: Fix branching to OOL handlers in relocatable kernel

Helge Deller (1):
  parisc: Fix pagefault crash in unaligned __get_user() call

Herbert Xu (2):
  crypto: gcm - Filter out async ghash if necessary
  crypto: scatterwalk - Fix test in scatterwalk_done

Hugh Dickins (2):
  mm: migrate dirty page without clear_page_dirty_for_io etc
  tmpfs: fix regression hang in fallocate undo

Ilya Dryomov (1):
  libceph: apply new_state before new_up_client on incrementals

Iosif Harutyunov (1):
  ubi: Fix race condition between ubi device creation and udev

Itai Handler (1):
  drm/gma500: Fix possible out of bounds read

James Bottomley (1):
  scsi_lib: correctly retry failed zero length REQ_TYPE_FS commands

James C Boyd (1):
  HID: hid-input: Add parentheses to quell gcc warning

James Hogan (7):
  MIPS: KVM: Fix mapped fault broken commpage handling
  MIPS: KVM: Add missing gfn range check
  MIPS: KVM: Fix gfn range check in kseg0 tlb faults
  MIPS: KVM: Propagate kseg0/mapped tlb fault errors
  MIPS: Fix siginfo.h to use strict posix types
  MIPS: KVM: Fix modular KVM under QEMU
  metag: Fix __cmpxchg_u32 asm constraint for CMP

Jan Beulich (1):
  xen/acpi: allow xen-acpi-processor driver to load on Xen 4.7

Jan Willeke (1):
  s390/seccomp: fix error return for filtered system calls

Jann Horn (1):
  ecryptfs: forbid opening files without mmap handler

Jason Gunthorpe (2):
  IB/mlx4: Properly initialize GRH TClass and FlowLabel in AHs
  IB/security: Restrict use of the write() interface

Javier Martinez Canillas (2):
  s5p-mfc: Set device name for reserved memory region devs
  s5p-mfc: Add release callback for memory region devs

Jeff Mahoney (2):
  Revert "ecryptfs: forbid opening files without mmap handler"
  ecryptfs: don't allow mmap when the lower fs doesn't support it

Jiri Slaby (1):
  base: make module_create_drivers_dir race-free

Joseph Salisbury (1):
  ath5k: Change led pin configuration for compaq c700 laptop

Kangjie Lu (4):
  USB: usbfs: fix potential infoleak in devio
  ALSA: timer: Fix leak in SNDRV_TIMER_IOCTL_PARAMS
  ALSA: timer: Fix leak in events via snd_timer_user_ccallback
  ALSA: timer: Fix leak in events via snd_timer_user_tinterrupt

Karl Heiss (1):
  sctp: Prevent soft lockup when sctp_accept() is called during a
    timeout event

Kirill A. Shutemov (1):
  UBIFS: Implement ->migratepage()

Konstantin Neumoin (1):
  balloon: check the number of available pages in leak balloon

Laura Abbott (1):
  ftrace/recordmcount: Work around for addition of metag magic but not
    relocations

Linus Walleij (2):
  crypto: ux500 - memmove the right size
  iio: accel: kxsd9: fix the usage of spi_w8r8()

Luis Henriques (1):
  net: rfkill: Do not ignore errors from regulator_enable()

Luis de Bethencourt (1):
  staging: iio: accel: fix error check

Lyude (2):
  drm/fb_helper: Fix references to dev->mode_config.num_connector
  drm/radeon: Poll for both connect/disconnect on analog connectors

Mark Brown (2):
  iio:ad7266: Fix broken regulator error handling
  iio:ad7266: Fix probe deferral for vref

Martin Willi (1):
  mac80211_hwsim: Add missing check for HWSIM_ATTR_SIGNAL

Masami Hiramatsu (1):
  kprobes/x86: Clear TF bit in fault on single-stepping

Matthias Schiffer (1):
  MIPS: ath79: make bootconsole wait for both THRE and TEMT

Mike Snitzer (1):
  dm flakey: error READ bios during the down_interval

Neil Horman (1):
  PCI/ACPI: Fix _OSC ordering to allow PCIe hotplug use when available

Nicolai Stange (2):
  ext4: address UBSAN warning in mb_find_order_for_block()
  ext4: silence UBSAN in ext4_mb_init()

Oliver Hartkopp (1):
  can: fix oops caused by wrong rtnl dellink usage

Palik, Imre (1):
  perf/x86: Honor the architectural performance monitoring version

Paolo Bonzini (1):
  KVM: x86: fix OOPS after invalid KVM_SET_DEBUGREGS

Paul Burton (1):
  MIPS: math-emu: Fix jalr emulation when rd == $0

Paul Moore (1):
  netlabel: add address family checks to netlbl_{sock,req}_delattr()

Ping Cheng (1):
  Input: wacom_w8001 - w8001_MAX_LENGTH should be 13

Prarit Bhargava (1):
  PCI: Disable all BAR sizing for devices with non-compliant BARs

Prasun Maiti (1):
  wext: Fix 32 bit iwpriv compatibility issue with 64 bit Kernel

Raghava Aditya Renukunta (2):
  aacraid: Relinquish CPU during timeout wait
  aacraid: Fix for aac_command_thread hang

Ralf Baechle (1):
  MIPS: Fix 64k page support for 32 bit kernels.

Richard Weinberger (2):
  mm: Export migrate_page_move_mapping and migrate_page_copy
  ubi: Make volume resize power cut aware

Ricky Liang (1):
  Input: uinput - handle compat ioctl for UI_SET_PHYS

Russell Currey (1):
  powerpc/pseries/eeh: Handle RTAS delay requests in configure_bridge

Russell King (1):
  ARM: fix PTRACE_SETVFPREGS on SMP systems

Sachin Prabhu (1):
  cifs: Check for existing directory when opening file with O_CREAT

Scott Bauer (1):
  HID: hiddev: validate num_values for HIDIOCGUSAGES, HIDIOCSUSAGES
    commands

Simon Horman (1):
  sit: correct IP protocol used in ipip6_err

Soheil Hassas Yeganeh (1):
  tcp: consider recv buf for the initial window scale

Steve French (1):
  Fix reconnect to not defer smb3 session reconnect long after socket
    reconnect

Steven Rostedt (Red Hat) (1):
  tracing: Handle NULL formats in hold_module_trace_bprintk_format()

Takashi Iwai (3):
  ALSA: dummy: Fix a use-after-free at closing
  ALSA: au88x0: Fix calculation in vortex_wtdma_bufshift()
  ALSA: ctl: Stop notification after disconnection

Taras Kondratiuk (1):
  mmc: block: fix packed command header endianness

Tejun Heo (1):
  printk: do cond_resched() between lines while outputting to consoles

Theodore Ts'o (1):
  ext4: fix hang when processing corrupted orphaned inode list

Thomas Huth (2):
  powerpc: Fix definition of SIAR and SDAR registers
  powerpc: Use privileged SPR number for MMCR2

Tim Gardner (1):
  be2iscsi: Fix bogus WARN_ON length check

Tom Goff (1):
  ipmr/ip6mr: Initialize the last assert time of mfc entries.

Tomer Barletz (1):
  ALSA: oxygen: Fix logical-not-parentheses warning

Tomáš Trnka (1):
  sunrpc: fix stripping of padded MIC tokens

Torsten Hilbrich (1):
  fs/nilfs2: fix potential underflow in call to crc32_le

Trond Myklebust (1):
  NFS: Fix another OPEN_DOWNGRADE bug

Ursula Braun (1):
  qeth: delete napi struct when removing a qeth device

Vegard Nossum (7):
  ext4: verify extent header depth
  ext4: check for extents that wrap around
  ext4: don't call ext4_should_journal_data() on the journal inode
  ext4: short-cut orphan cleanup on error
  ext4: fix reference counting bug on block allocation error
  block: fix use-after-free in seq file
  net/irda: fix NULL pointer dereference on memory allocation failure

Vignesh R (1):
  gpio: pca953x: Fix NBANK calculation for PCA9536

Ville Syrj�l� (1):
  dma-debug: avoid spinlock recursion when disabling dma-debug

Vineet Gupta (1):
  ARC: use ASL assembler mnemonic

Vladimir Davydov (1):
  signal: remove warning about using SI_TKILL in rt_[tg]sigqueueinfo

Wei Fang (2):
  scsi: fix race between simultaneous decrements of ->host_failed
  fuse: fix wrong assignment of ->flags in fuse_send_init()

Willy Tarreau (3):
  USB: fix up faulty backports
  pipe: limit the per-user amount of pages allocated in pipes
  squash mm: Export migrate_page_... : also make it non-static

Wolfgang Grandegger (1):
  can: at91_can: RX queue could get stuck at high bus load

Xiubo Li (1):
  kvm: Fix irq route entries exceeding KVM_MAX_IRQ_ROUTES

Yishai Hadas (1):
  IB/mlx4: Fix the SQ size of an RC QP

Yoshihiro Shimoda (1):
  usb: renesas_usbhs: protect the CFIFOSEL setting in usbhsg_ep_enable()

Yuchung Cheng (1):
  tcp: record TLP and ER timer stats in v6 stats

dan.carpenter@oracle.com (1):
  spi: spi-xilinx: cleanup a check in xilinx_spi_txrx_bufs()

wang yanqing (1):
  rtlwifi: Fix logic error in enter/exit power-save mode

 Documentation/scsi/scsi_eh.txt                |   8 +-
 Documentation/sysctl/fs.txt                   |  23 ++
 arch/arc/kernel/stacktrace.c                  |   2 +-
 arch/arc/mm/tlbex.S                           |   4 +-
 arch/arm/kernel/ptrace.c                      |   2 +-
 arch/arm/kernel/sys_oabi-compat.c             |   8 +-
 arch/metag/include/asm/cmpxchg_lnkget.h       |   2 +-
 arch/mips/ath79/early_printk.c                |   6 +-
 arch/mips/include/asm/kvm_host.h              |   1 +
 arch/mips/include/asm/processor.h             |   2 +-
 arch/mips/include/uapi/asm/siginfo.h          |  18 +-
 arch/mips/kernel/scall64-n32.S                |   2 +-
 arch/mips/kernel/scall64-o32.S                |   2 +-
 arch/mips/kvm/kvm_locore.S                    |   1 +
 arch/mips/kvm/kvm_mips.c                      |  11 +-
 arch/mips/kvm/kvm_mips_emul.c                 |  33 ++-
 arch/mips/kvm/kvm_mips_int.h                  |   2 +
 arch/mips/kvm/kvm_tlb.c                       |  61 +++--
 arch/mips/math-emu/cp1emu.c                   |   8 +-
 arch/parisc/kernel/unaligned.c                |  10 +-
 arch/powerpc/include/asm/reg.h                |   6 +-
 arch/powerpc/kernel/exceptions-64s.S          |  16 +-
 arch/powerpc/kernel/process.c                 |  10 +
 arch/powerpc/platforms/pseries/eeh_pseries.c  |  51 ++--
 arch/powerpc/platforms/pseries/iommu.c        |  24 +-
 arch/s390/include/asm/syscall.h               |   2 +-
 arch/x86/boot/Makefile                        |   3 +
 arch/x86/include/asm/mmu_context.h            |  33 ++-
 arch/x86/kernel/amd_nb.c                      |   4 +-
 arch/x86/kernel/apm_32.c                      |   2 +-
 arch/x86/kernel/cpu/perf_event_intel.c        |  11 +-
 arch/x86/kernel/kprobes/core.c                |  12 +
 arch/x86/kvm/x86.c                            |   5 +
 arch/x86/mm/tlb.c                             |  24 +-
 block/genhd.c                                 |   1 +
 crypto/gcm.c                                  |   4 +-
 crypto/scatterwalk.c                          |   3 +-
 drivers/acpi/pci_root.c                       |  67 ++---
 drivers/ata/libata-eh.c                       |   2 +-
 drivers/base/module.c                         |   8 +-
 drivers/crypto/ux500/hash/hash_core.c         |   4 +-
 drivers/gpio/gpio-pca953x.c                   |   2 +-
 drivers/gpu/drm/drm_fb_helper.c               |   5 +-
 drivers/gpu/drm/gma500/mdfld_dsi_pkg_sender.c |   2 +-
 drivers/gpu/drm/radeon/radeon_atombios.c      |   4 +-
 drivers/gpu/drm/radeon/radeon_atpx_handler.c  |   5 +
 drivers/gpu/drm/radeon/radeon_connectors.c    |  15 +-
 drivers/gpu/drm/radeon/radeon_device.c        |  21 ++
 drivers/hid/hid-input.c                       |   2 +-
 drivers/hid/usbhid/hiddev.c                   |  10 +-
 drivers/iio/accel/kxsd9.c                     |   4 +-
 drivers/iio/adc/ad7266.c                      |   6 +-
 drivers/iio/industrialio-trigger.c            |  23 +-
 drivers/infiniband/core/ucm.c                 |   4 +
 drivers/infiniband/core/ucma.c                |   4 +
 drivers/infiniband/core/uverbs_main.c         |   5 +
 drivers/infiniband/hw/mlx4/ah.c               |   2 +-
 drivers/infiniband/hw/mlx4/qp.c               |   2 +-
 drivers/infiniband/hw/qib/qib_file_ops.c      |   5 +
 drivers/infiniband/ulp/ipoib/ipoib_main.c     |   4 +-
 drivers/input/joystick/xpad.c                 |   3 +
 drivers/input/misc/uinput.c                   |   6 +
 drivers/input/touchscreen/wacom_w8001.c       |   2 +-
 drivers/isdn/hardware/mISDN/hfcpci.c          |   4 +-
 drivers/md/dm-flakey.c                        |  23 +-
 drivers/media/dvb-frontends/stb6100.c         |   2 +-
 drivers/media/platform/s5p-mfc/s5p_mfc.c      |  11 +
 drivers/mmc/card/block.c                      |  12 +-
 drivers/mtd/ubi/build.c                       |   5 +-
 drivers/mtd/ubi/vmt.c                         |  25 +-
 drivers/net/can/at91_can.c                    |   5 +-
 drivers/net/can/dev.c                         |   6 +
 drivers/net/ethernet/atheros/alx/main.c       |   7 +-
 drivers/net/ethernet/marvell/mvneta.c         |   2 +-
 drivers/net/usb/cdc_ncm.c                     |  27 +-
 drivers/net/wireless/ath/ath5k/led.c          |   2 +-
 drivers/net/wireless/mac80211_hwsim.c         |   1 +
 drivers/net/wireless/rtlwifi/base.c           |   4 +-
 drivers/pci/probe.c                           |   6 +-
 drivers/platform/x86/hp-wmi.c                 |   5 +
 drivers/s390/net/qeth_l2_main.c               |   1 +
 drivers/s390/net/qeth_l3_main.c               |   1 +
 drivers/scsi/aacraid/commsup.c                |  12 +-
 drivers/scsi/be2iscsi/be_main.c               |   2 +-
 drivers/scsi/ipr.c                            |   1 +
 drivers/scsi/scsi_error.c                     |   4 +-
 drivers/scsi/scsi_lib.c                       | 116 +++------
 drivers/spi/spi-xilinx.c                      |   2 +-
 drivers/staging/iio/accel/sca3000_core.c      |   2 +-
 drivers/tty/vt/keyboard.c                     |  30 +--
 drivers/usb/core/devio.c                      |   9 +-
 drivers/usb/core/hub.c                        |  23 +-
 drivers/usb/core/quirks.c                     |  16 +-
 drivers/usb/musb/musb_host.c                  |  21 +-
 drivers/usb/renesas_usbhs/mod_gadget.c        |   9 +-
 drivers/usb/serial/option.c                   |   3 +
 drivers/virtio/virtio_balloon.c               |   2 +
 drivers/xen/xen-acpi-processor.c              |  35 +--
 drivers/xen/xen-pciback/conf_space.c          |   6 +-
 fs/cifs/connect.c                             |   4 +-
 fs/cifs/dir.c                                 |  24 +-
 fs/cifs/smb2pdu.c                             |  27 ++
 fs/dcache.c                                   |   4 +-
 fs/ecryptfs/file.c                            |  15 +-
 fs/ext4/extents.c                             |  12 +-
 fs/ext4/ialloc.c                              |  10 +-
 fs/ext4/inode.c                               |   6 +-
 fs/ext4/mballoc.c                             |  27 +-
 fs/ext4/super.c                               |  10 +
 fs/fuse/inode.c                               |   2 +-
 fs/nfs/nfs4proc.c                             |   5 +-
 fs/nilfs2/the_nilfs.c                         |   2 +-
 fs/pipe.c                                     |  47 +++-
 fs/ubifs/file.c                               |  24 ++
 fs/xfs/xfs_inode.c                            |  26 +-
 include/linux/console.h                       |   1 +
 include/linux/migrate.h                       |   3 +
 include/linux/netfilter/x_tables.h            |  12 +-
 include/linux/pipe_fs_i.h                     |   4 +
 include/linux/sched.h                         |   1 +
 include/linux/usb/ehci_def.h                  |   4 +-
 include/rdma/ib.h                             |  54 ++++
 kernel/module.c                               |  13 +-
 kernel/panic.c                                |   3 +
 kernel/printk.c                               |  35 ++-
 kernel/signal.c                               |  14 +-
 kernel/sysctl.c                               |  14 +
 kernel/trace/trace_printk.c                   |   7 +-
 lib/dma-debug.c                               |   2 +-
 mm/migrate.c                                  |  55 ++--
 mm/shmem.c                                    |   8 +-
 net/bluetooth/l2cap_sock.c                    |   2 +-
 net/ceph/osdmap.c                             | 152 +++++++----
 net/ipv4/ipmr.c                               |   4 +-
 net/ipv4/netfilter/arp_tables.c               | 327 ++++++++---------------
 net/ipv4/netfilter/ip_tables.c                | 360 ++++++++------------------
 net/ipv4/tcp_input.c                          |  14 +-
 net/ipv4/tcp_output.c                         |   3 +-
 net/ipv4/udp.c                                |   6 +-
 net/ipv6/ip6mr.c                              |   1 +
 net/ipv6/netfilter/ip6_tables.c               | 354 ++++++++-----------------
 net/ipv6/sit.c                                |   4 +-
 net/ipv6/tcp_ipv6.c                           |   4 +-
 net/ipv6/udp.c                                |   6 +-
 net/irda/af_irda.c                            |   7 +-
 net/mac80211/mesh.c                           |   4 +
 net/netfilter/x_tables.c                      | 245 +++++++++++++++++-
 net/netlabel/netlabel_kapi.c                  |  12 +-
 net/rfkill/rfkill-regulator.c                 |   8 +-
 net/sctp/sm_sideeffect.c                      |  42 +--
 net/sunrpc/auth_gss/svcauth_gss.c             |   4 +-
 net/wireless/wext-core.c                      |  25 +-
 scripts/asn1_compiler.c                       |   2 +
 scripts/recordmcount.c                        |   9 +-
 security/keys/key.c                           |   2 +-
 sound/core/control.c                          |   2 +
 sound/core/timer.c                            |   3 +
 sound/drivers/dummy.c                         |   1 +
 sound/pci/au88x0/au88x0_core.c                |   5 +-
 sound/pci/oxygen/oxygen_mixer.c               |   2 +-
 virt/kvm/kvm_main.c                           |   2 +-
 161 files changed, 1869 insertions(+), 1294 deletions(-)
 create mode 100644 include/rdma/ib.h

-- 
2.8.0.rc2.1.gbe9624a

[toc] | [next] | [standalone]


#1467050 — [PATCH 3.10 036/180] usb: renesas_usbhs: protect the CFIFOSEL setting in usbhsg_ep_enable()

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:40 +0200
Subject[PATCH 3.10 036/180] usb: renesas_usbhs: protect the CFIFOSEL setting in usbhsg_ep_enable()
Message-ID<s8D0U-26R-113@gated-at.bofh.it>
In reply to#1467049
From: Yoshihiro Shimoda <yoshihiro.shimoda.uh@renesas.com>

commit 15e4292a2d21e9997fdb2b8c014cc461b3f268f0 upstream.

This patch fixes an issue that the CFIFOSEL register value is possible
to be changed by usbhsg_ep_enable() wrongly. And then, a data transfer
using CFIFO may not work correctly.

For example:
 # modprobe g_multi file=usb-storage.bin
 # ifconfig usb0 192.168.1.1 up
 (During the USB host is sending file to the mass storage)
 # ifconfig usb0 down

In this case, since the u_ether.c may call usb_ep_enable() in
eth_stop(), if the renesas_usbhs driver is also using CFIFO for
mass storage, the mass storage may not work correctly.

So, this patch adds usbhs_lock() and usbhs_unlock() calling in
usbhsg_ep_enable() to protect CFIFOSEL register. This is because:
 - CFIFOSEL.CURPIPE = 0 is also needed for the pipe configuration
 - The CFIFOSEL (fifo->sel) is already protected by usbhs_lock()

Fixes: 97664a207bc2 ("usb: renesas_usbhs: shrink spin lock area")
Cc: <stable@vger.kernel.org> # v3.1+
Signed-off-by: Yoshihiro Shimoda <yoshihiro.shimoda.uh@renesas.com>
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/renesas_usbhs/mod_gadget.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/drivers/usb/renesas_usbhs/mod_gadget.c b/drivers/usb/renesas_usbhs/mod_gadget.c
index ed4949f..64223a9 100644
--- a/drivers/usb/renesas_usbhs/mod_gadget.c
+++ b/drivers/usb/renesas_usbhs/mod_gadget.c
@@ -558,6 +558,9 @@ static int usbhsg_ep_enable(struct usb_ep *ep,
 	struct usbhs_priv *priv = usbhsg_gpriv_to_priv(gpriv);
 	struct usbhs_pipe *pipe;
 	int ret = -EIO;
+	unsigned long flags;
+
+	usbhs_lock(priv, flags);
 
 	/*
 	 * if it already have pipe,
@@ -566,7 +569,8 @@ static int usbhsg_ep_enable(struct usb_ep *ep,
 	if (uep->pipe) {
 		usbhs_pipe_clear(uep->pipe);
 		usbhs_pipe_sequence_data0(uep->pipe);
-		return 0;
+		ret = 0;
+		goto usbhsg_ep_enable_end;
 	}
 
 	pipe = usbhs_pipe_malloc(priv,
@@ -594,6 +598,9 @@ static int usbhsg_ep_enable(struct usb_ep *ep,
 		ret = 0;
 	}
 
+usbhsg_ep_enable_end:
+	usbhs_unlock(priv, flags);
+
 	return ret;
 }
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467051 — [PATCH 3.10 028/180] udp: properly support MSG_PEEK with truncated buffers

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:40 +0200
Subject[PATCH 3.10 028/180] udp: properly support MSG_PEEK with truncated buffers
Message-ID<s8D0U-26R-115@gated-at.bofh.it>
In reply to#1467049
From: Eric Dumazet <edumazet@google.com>

commit 197c949e7798fbf28cfadc69d9ca0c2abbf93191 upstream.

Backport of this upstream commit into stable kernels :
89c22d8c3b27 ("net: Fix skb csum races when peeking")
exposed a bug in udp stack vs MSG_PEEK support, when user provides
a buffer smaller than skb payload.

In this case,
skb_copy_and_csum_datagram_iovec(skb, sizeof(struct udphdr),
                                 msg->msg_iov);
returns -EFAULT.

This bug does not happen in upstream kernels since Al Viro did a great
job to replace this into :
skb_copy_and_csum_datagram_msg(skb, sizeof(struct udphdr), msg);
This variant is safe vs short buffers.

For the time being, instead reverting Herbert Xu patch and add back
skb->ip_summed invalid changes, simply store the result of
udp_lib_checksum_complete() so that we avoid computing the checksum a
second time, and avoid the problematic
skb_copy_and_csum_datagram_iovec() call.

This patch can be applied on recent kernels as it avoids a double
checksumming, then backported to stable kernels as a bug fix.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
Signed-off-by: Charles (Chas) Williams <ciwillia@brocade.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/ipv4/udp.c | 6 ++++--
 net/ipv6/udp.c | 6 ++++--
 2 files changed, 8 insertions(+), 4 deletions(-)

diff --git a/net/ipv4/udp.c b/net/ipv4/udp.c
index 63b536b..68174e4 100644
--- a/net/ipv4/udp.c
+++ b/net/ipv4/udp.c
@@ -1208,6 +1208,7 @@ int udp_recvmsg(struct kiocb *iocb, struct sock *sk, struct msghdr *msg,
 	int peeked, off = 0;
 	int err;
 	int is_udplite = IS_UDPLITE(sk);
+	bool checksum_valid = false;
 	bool slow;
 
 	if (flags & MSG_ERRQUEUE)
@@ -1233,11 +1234,12 @@ try_again:
 	 */
 
 	if (copied < ulen || UDP_SKB_CB(skb)->partial_cov) {
-		if (udp_lib_checksum_complete(skb))
+		checksum_valid = !udp_lib_checksum_complete(skb);
+		if (!checksum_valid)
 			goto csum_copy_err;
 	}
 
-	if (skb_csum_unnecessary(skb))
+	if (checksum_valid || skb_csum_unnecessary(skb))
 		err = skb_copy_datagram_iovec(skb, sizeof(struct udphdr),
 					      msg->msg_iov, copied);
 	else {
diff --git a/net/ipv6/udp.c b/net/ipv6/udp.c
index 3046d02..d234e6f 100644
--- a/net/ipv6/udp.c
+++ b/net/ipv6/udp.c
@@ -370,6 +370,7 @@ int udpv6_recvmsg(struct kiocb *iocb, struct sock *sk,
 	int peeked, off = 0;
 	int err;
 	int is_udplite = IS_UDPLITE(sk);
+	bool checksum_valid = false;
 	int is_udp4;
 	bool slow;
 
@@ -401,11 +402,12 @@ try_again:
 	 */
 
 	if (copied < ulen || UDP_SKB_CB(skb)->partial_cov) {
-		if (udp_lib_checksum_complete(skb))
+		checksum_valid = !udp_lib_checksum_complete(skb);
+		if (!checksum_valid)
 			goto csum_copy_err;
 	}
 
-	if (skb_csum_unnecessary(skb))
+	if (checksum_valid || skb_csum_unnecessary(skb))
 		err = skb_copy_datagram_iovec(skb, sizeof(struct udphdr),
 					      msg->msg_iov, copied);
 	else {
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467052 — [PATCH 3.10 017/180] netfilter: ip_tables: simplify translate_compat_table args

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:40 +0200
Subject[PATCH 3.10 017/180] netfilter: ip_tables: simplify translate_compat_table args
Message-ID<s8D0U-26R-121@gated-at.bofh.it>
In reply to#1467049
From: Florian Westphal <fw@strlen.de>

commit 7d3f843eed29222254c9feab481f55175a1afcc9 upstream.

Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/ipv4/netfilter/ip_tables.c | 61 +++++++++++++++++-------------------------
 1 file changed, 25 insertions(+), 36 deletions(-)

diff --git a/net/ipv4/netfilter/ip_tables.c b/net/ipv4/netfilter/ip_tables.c
index 29f3092..ddfc3ac 100644
--- a/net/ipv4/netfilter/ip_tables.c
+++ b/net/ipv4/netfilter/ip_tables.c
@@ -1439,7 +1439,6 @@ compat_copy_entry_to_user(struct ipt_entry *e, void __user **dstptr,
 
 static int
 compat_find_calc_match(struct xt_entry_match *m,
-		       const char *name,
 		       const struct ipt_ip *ip,
 		       unsigned int hookmask,
 		       int *size)
@@ -1477,8 +1476,7 @@ check_compat_entry_size_and_hooks(struct compat_ipt_entry *e,
 				  const unsigned char *base,
 				  const unsigned char *limit,
 				  const unsigned int *hook_entries,
-				  const unsigned int *underflows,
-				  const char *name)
+				  const unsigned int *underflows)
 {
 	struct xt_entry_match *ematch;
 	struct xt_entry_target *t;
@@ -1514,8 +1512,8 @@ check_compat_entry_size_and_hooks(struct compat_ipt_entry *e,
 	entry_offset = (void *)e - (void *)base;
 	j = 0;
 	xt_ematch_foreach(ematch, e) {
-		ret = compat_find_calc_match(ematch, name,
-					     &e->ip, e->comefrom, &off);
+		ret = compat_find_calc_match(ematch, &e->ip, e->comefrom,
+					     &off);
 		if (ret != 0)
 			goto release_matches;
 		++j;
@@ -1564,7 +1562,7 @@ release_matches:
 
 static int
 compat_copy_entry_from_user(struct compat_ipt_entry *e, void **dstptr,
-			    unsigned int *size, const char *name,
+			    unsigned int *size,
 			    struct xt_table_info *newinfo, unsigned char *base)
 {
 	struct xt_entry_target *t;
@@ -1640,14 +1638,9 @@ compat_check_entry(struct ipt_entry *e, struct net *net, const char *name)
 
 static int
 translate_compat_table(struct net *net,
-		       const char *name,
-		       unsigned int valid_hooks,
 		       struct xt_table_info **pinfo,
 		       void **pentry0,
-		       unsigned int total_size,
-		       unsigned int number,
-		       unsigned int *hook_entries,
-		       unsigned int *underflows)
+		       const struct compat_ipt_replace *compatr)
 {
 	unsigned int i, j;
 	struct xt_table_info *newinfo, *info;
@@ -1659,8 +1652,8 @@ translate_compat_table(struct net *net,
 
 	info = *pinfo;
 	entry0 = *pentry0;
-	size = total_size;
-	info->number = number;
+	size = compatr->size;
+	info->number = compatr->num_entries;
 
 	/* Init all hooks to impossible value. */
 	for (i = 0; i < NF_INET_NUMHOOKS; i++) {
@@ -1671,40 +1664,39 @@ translate_compat_table(struct net *net,
 	duprintf("translate_compat_table: size %u\n", info->size);
 	j = 0;
 	xt_compat_lock(AF_INET);
-	xt_compat_init_offsets(AF_INET, number);
+	xt_compat_init_offsets(AF_INET, compatr->num_entries);
 	/* Walk through entries, checking offsets. */
-	xt_entry_foreach(iter0, entry0, total_size) {
+	xt_entry_foreach(iter0, entry0, compatr->size) {
 		ret = check_compat_entry_size_and_hooks(iter0, info, &size,
 							entry0,
-							entry0 + total_size,
-							hook_entries,
-							underflows,
-							name);
+							entry0 + compatr->size,
+							compatr->hook_entry,
+							compatr->underflow);
 		if (ret != 0)
 			goto out_unlock;
 		++j;
 	}
 
 	ret = -EINVAL;
-	if (j != number) {
+	if (j != compatr->num_entries) {
 		duprintf("translate_compat_table: %u not %u entries\n",
-			 j, number);
+			 j, compatr->num_entries);
 		goto out_unlock;
 	}
 
 	/* Check hooks all assigned */
 	for (i = 0; i < NF_INET_NUMHOOKS; i++) {
 		/* Only hooks which are valid */
-		if (!(valid_hooks & (1 << i)))
+		if (!(compatr->valid_hooks & (1 << i)))
 			continue;
 		if (info->hook_entry[i] == 0xFFFFFFFF) {
 			duprintf("Invalid hook entry %u %u\n",
-				 i, hook_entries[i]);
+				 i, info->hook_entry[i]);
 			goto out_unlock;
 		}
 		if (info->underflow[i] == 0xFFFFFFFF) {
 			duprintf("Invalid underflow %u %u\n",
-				 i, underflows[i]);
+				 i, info->underflow[i]);
 			goto out_unlock;
 		}
 	}
@@ -1714,17 +1706,17 @@ translate_compat_table(struct net *net,
 	if (!newinfo)
 		goto out_unlock;
 
-	newinfo->number = number;
+	newinfo->number = compatr->num_entries;
 	for (i = 0; i < NF_INET_NUMHOOKS; i++) {
 		newinfo->hook_entry[i] = info->hook_entry[i];
 		newinfo->underflow[i] = info->underflow[i];
 	}
 	entry1 = newinfo->entries[raw_smp_processor_id()];
 	pos = entry1;
-	size = total_size;
-	xt_entry_foreach(iter0, entry0, total_size) {
+	size = compatr->size;
+	xt_entry_foreach(iter0, entry0, compatr->size) {
 		ret = compat_copy_entry_from_user(iter0, &pos, &size,
-						  name, newinfo, entry1);
+						  newinfo, entry1);
 		if (ret != 0)
 			break;
 	}
@@ -1734,12 +1726,12 @@ translate_compat_table(struct net *net,
 		goto free_newinfo;
 
 	ret = -ELOOP;
-	if (!mark_source_chains(newinfo, valid_hooks, entry1))
+	if (!mark_source_chains(newinfo, compatr->valid_hooks, entry1))
 		goto free_newinfo;
 
 	i = 0;
 	xt_entry_foreach(iter1, entry1, newinfo->size) {
-		ret = compat_check_entry(iter1, net, name);
+		ret = compat_check_entry(iter1, net, compatr->name);
 		if (ret != 0)
 			break;
 		++i;
@@ -1784,7 +1776,7 @@ translate_compat_table(struct net *net,
 free_newinfo:
 	xt_free_table_info(newinfo);
 out:
-	xt_entry_foreach(iter0, entry0, total_size) {
+	xt_entry_foreach(iter0, entry0, compatr->size) {
 		if (j-- == 0)
 			break;
 		compat_release_entry(iter0);
@@ -1827,10 +1819,7 @@ compat_do_replace(struct net *net, void __user *user, unsigned int len)
 		goto free_newinfo;
 	}
 
-	ret = translate_compat_table(net, tmp.name, tmp.valid_hooks,
-				     &newinfo, &loc_cpu_entry, tmp.size,
-				     tmp.num_entries, tmp.hook_entry,
-				     tmp.underflow);
+	ret = translate_compat_table(net, &newinfo, &loc_cpu_entry, &tmp);
 	if (ret != 0)
 		goto free_newinfo;
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467053 — [PATCH 3.10 132/180] ALSA: timer: Fix leak in SNDRV_TIMER_IOCTL_PARAMS

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:40 +0200
Subject[PATCH 3.10 132/180] ALSA: timer: Fix leak in SNDRV_TIMER_IOCTL_PARAMS
Message-ID<s8D0U-26R-123@gated-at.bofh.it>
In reply to#1467049
From: Kangjie Lu <kangjielu@gmail.com>

commit cec8f96e49d9be372fdb0c3836dcf31ec71e457e upstream.

The stack object “tread” has a total size of 32 bytes. Its field
“event” and “val” both contain 4 bytes padding. These 8 bytes
padding bytes are sent to user without being initialized.

Signed-off-by: Kangjie Lu <kjlu@gatech.edu>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 sound/core/timer.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/core/timer.c b/sound/core/timer.c
index 38742e8..54ff806 100644
--- a/sound/core/timer.c
+++ b/sound/core/timer.c
@@ -1707,6 +1707,7 @@ static int snd_timer_user_params(struct file *file,
 	if (tu->timeri->flags & SNDRV_TIMER_IFLG_EARLY_EVENT) {
 		if (tu->tread) {
 			struct snd_timer_tread tread;
+			memset(&tread, 0, sizeof(tread));
 			tread.event = SNDRV_TIMER_EVENT_EARLY;
 			tread.tstamp.tv_sec = 0;
 			tread.tstamp.tv_nsec = 0;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467054 — [PATCH 3.10 053/180] MIPS: KVM: Propagate kseg0/mapped tlb fault errors

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:40 +0200
Subject[PATCH 3.10 053/180] MIPS: KVM: Propagate kseg0/mapped tlb fault errors
Message-ID<s8D0U-26R-125@gated-at.bofh.it>
In reply to#1467049
From: James Hogan <james.hogan@imgtec.com>

commit 9b731bcfdec4c159ad2e4312e25d69221709b96a upstream.

Propagate errors from kvm_mips_handle_kseg0_tlb_fault() and
kvm_mips_handle_mapped_seg_tlb_fault(), usually triggering an internal
error since they normally indicate the guest accessed bad physical
memory or the commpage in an unexpected way.

Fixes: 858dd5d45733 ("KVM/MIPS32: MMU/TLB operations for the Guest.")
Fixes: e685c689f3a8 ("KVM/MIPS32: Privileged instruction/target branch emulation.")
Signed-off-by: James Hogan <james.hogan@imgtec.com>
Cc: Paolo Bonzini <pbonzini@redhat.com>
Cc: "Radim Krčmář" <rkrcmar@redhat.com>
Cc: Ralf Baechle <ralf@linux-mips.org>
Cc: linux-mips@linux-mips.org
Cc: kvm@vger.kernel.org
Signed-off-by: Radim Krčmář <rkrcmar@redhat.com>
[james.hogan@imgtec.com: Backport to v3.10.y - v3.15.y]
Signed-off-by: James Hogan <james.hogan@imgtec.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 arch/mips/kvm/kvm_mips_emul.c | 33 ++++++++++++++++++++++++---------
 arch/mips/kvm/kvm_tlb.c       | 14 ++++++++++----
 2 files changed, 34 insertions(+), 13 deletions(-)

diff --git a/arch/mips/kvm/kvm_mips_emul.c b/arch/mips/kvm/kvm_mips_emul.c
index 3308581..9f76438 100644
--- a/arch/mips/kvm/kvm_mips_emul.c
+++ b/arch/mips/kvm/kvm_mips_emul.c
@@ -972,8 +972,13 @@ kvm_mips_emulate_cache(uint32_t inst, uint32_t *opc, uint32_t cause,
 	preempt_disable();
 	if (KVM_GUEST_KSEGX(va) == KVM_GUEST_KSEG0) {
 
-		if (kvm_mips_host_tlb_lookup(vcpu, va) < 0) {
-			kvm_mips_handle_kseg0_tlb_fault(va, vcpu);
+		if (kvm_mips_host_tlb_lookup(vcpu, va) < 0 &&
+		    kvm_mips_handle_kseg0_tlb_fault(va, vcpu)) {
+			kvm_err("%s: handling mapped kseg0 tlb fault for %lx, vcpu: %p, ASID: %#lx\n",
+				__func__, va, vcpu, read_c0_entryhi());
+			er = EMULATE_FAIL;
+			preempt_enable();
+			goto done;
 		}
 	} else if ((KVM_GUEST_KSEGX(va) < KVM_GUEST_KSEG0) ||
 		   KVM_GUEST_KSEGX(va) == KVM_GUEST_KSEG23) {
@@ -1006,11 +1011,16 @@ kvm_mips_emulate_cache(uint32_t inst, uint32_t *opc, uint32_t cause,
 								run, vcpu);
 				preempt_enable();
 				goto dont_update_pc;
-			} else {
-				/* We fault an entry from the guest tlb to the shadow host TLB */
-				kvm_mips_handle_mapped_seg_tlb_fault(vcpu, tlb,
-								     NULL,
-								     NULL);
+			}
+			/* We fault an entry from the guest tlb to the shadow host TLB */
+			if (kvm_mips_handle_mapped_seg_tlb_fault(vcpu, tlb,
+								 NULL, NULL)) {
+				kvm_err("%s: handling mapped seg tlb fault for %lx, index: %u, vcpu: %p, ASID: %#lx\n",
+					__func__, va, index, vcpu,
+					read_c0_entryhi());
+				er = EMULATE_FAIL;
+				preempt_enable();
+				goto done;
 			}
 		}
 	} else {
@@ -1821,8 +1831,13 @@ kvm_mips_handle_tlbmiss(unsigned long cause, uint32_t *opc,
 			     tlb->tlb_hi, tlb->tlb_lo0, tlb->tlb_lo1);
 #endif
 			/* OK we have a Guest TLB entry, now inject it into the shadow host TLB */
-			kvm_mips_handle_mapped_seg_tlb_fault(vcpu, tlb, NULL,
-							     NULL);
+			if (kvm_mips_handle_mapped_seg_tlb_fault(vcpu, tlb,
+								 NULL, NULL)) {
+				kvm_err("%s: handling mapped seg tlb fault for %lx, index: %u, vcpu: %p, ASID: %#lx\n",
+					__func__, va, index, vcpu,
+					read_c0_entryhi());
+				er = EMULATE_FAIL;
+			}
 		}
 	}
 
diff --git a/arch/mips/kvm/kvm_tlb.c b/arch/mips/kvm/kvm_tlb.c
index 5a3c373..4bee439 100644
--- a/arch/mips/kvm/kvm_tlb.c
+++ b/arch/mips/kvm/kvm_tlb.c
@@ -926,10 +926,16 @@ uint32_t kvm_get_inst(uint32_t *opc, struct kvm_vcpu *vcpu)
 				local_irq_restore(flags);
 				return KVM_INVALID_INST;
 			}
-			kvm_mips_handle_mapped_seg_tlb_fault(vcpu,
-							     &vcpu->arch.
-							     guest_tlb[index],
-							     NULL, NULL);
+			if (kvm_mips_handle_mapped_seg_tlb_fault(vcpu,
+						&vcpu->arch.guest_tlb[index],
+						NULL, NULL)) {
+				kvm_err("%s: handling mapped seg tlb fault failed for %p, index: %u, vcpu: %p, ASID: %#lx\n",
+					__func__, opc, index, vcpu,
+					read_c0_entryhi());
+				kvm_mips_dump_guest_tlbs(vcpu);
+				local_irq_restore(flags);
+				return KVM_INVALID_INST;
+			}
 			inst = *(opc);
 		}
 		local_irq_restore(flags);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467055 — [PATCH 3.10 008/180] netfilter: x_tables: add and use xt_check_entry_offsets

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:40 +0200
Subject[PATCH 3.10 008/180] netfilter: x_tables: add and use xt_check_entry_offsets
Message-ID<s8D0U-26R-127@gated-at.bofh.it>
In reply to#1467049
From: Florian Westphal <fw@strlen.de>

commit 7d35812c3214afa5b37a675113555259cfd67b98 upstream.

Currently arp/ip and ip6tables each implement a short helper to check that
the target offset is large enough to hold one xt_entry_target struct and
that t->u.target_size fits within the current rule.

Unfortunately these checks are not sufficient.

To avoid adding new tests to all of ip/ip6/arptables move the current
checks into a helper, then extend this helper in followup patches.

Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 include/linux/netfilter/x_tables.h |  4 ++++
 net/ipv4/netfilter/arp_tables.c    | 11 +----------
 net/ipv4/netfilter/ip_tables.c     | 12 +-----------
 net/ipv6/netfilter/ip6_tables.c    | 12 +-----------
 net/netfilter/x_tables.c           | 34 ++++++++++++++++++++++++++++++++++
 5 files changed, 41 insertions(+), 32 deletions(-)

diff --git a/include/linux/netfilter/x_tables.h b/include/linux/netfilter/x_tables.h
index dd49566..6da5c82 100644
--- a/include/linux/netfilter/x_tables.h
+++ b/include/linux/netfilter/x_tables.h
@@ -239,6 +239,10 @@ extern void xt_unregister_match(struct xt_match *target);
 extern int xt_register_matches(struct xt_match *match, unsigned int n);
 extern void xt_unregister_matches(struct xt_match *match, unsigned int n);
 
+int xt_check_entry_offsets(const void *base,
+                           unsigned int target_offset,
+                           unsigned int next_offset);
+
 extern int xt_check_match(struct xt_mtchk_param *,
 			  unsigned int size, u_int8_t proto, bool inv_proto);
 extern int xt_check_target(struct xt_tgchk_param *,
diff --git a/net/ipv4/netfilter/arp_tables.c b/net/ipv4/netfilter/arp_tables.c
index b2adc4b..839a698 100644
--- a/net/ipv4/netfilter/arp_tables.c
+++ b/net/ipv4/netfilter/arp_tables.c
@@ -487,19 +487,10 @@ static int mark_source_chains(const struct xt_table_info *newinfo,
 
 static inline int check_entry(const struct arpt_entry *e)
 {
-	const struct xt_entry_target *t;
-
 	if (!arp_checkentry(&e->arp))
 		return -EINVAL;
 
-	if (e->target_offset + sizeof(struct xt_entry_target) > e->next_offset)
-		return -EINVAL;
-
-	t = arpt_get_target_c(e);
-	if (e->target_offset + t->u.target_size > e->next_offset)
-		return -EINVAL;
-
-	return 0;
+	return xt_check_entry_offsets(e, e->target_offset, e->next_offset);
 }
 
 static inline int check_target(struct arpt_entry *e, const char *name)
diff --git a/net/ipv4/netfilter/ip_tables.c b/net/ipv4/netfilter/ip_tables.c
index eea26fc..ffd46717 100644
--- a/net/ipv4/netfilter/ip_tables.c
+++ b/net/ipv4/netfilter/ip_tables.c
@@ -581,20 +581,10 @@ static void cleanup_match(struct xt_entry_match *m, struct net *net)
 static int
 check_entry(const struct ipt_entry *e)
 {
-	const struct xt_entry_target *t;
-
 	if (!ip_checkentry(&e->ip))
 		return -EINVAL;
 
-	if (e->target_offset + sizeof(struct xt_entry_target) >
-	    e->next_offset)
-		return -EINVAL;
-
-	t = ipt_get_target_c(e);
-	if (e->target_offset + t->u.target_size > e->next_offset)
-		return -EINVAL;
-
-	return 0;
+	return xt_check_entry_offsets(e, e->target_offset, e->next_offset);
 }
 
 static int
diff --git a/net/ipv6/netfilter/ip6_tables.c b/net/ipv6/netfilter/ip6_tables.c
index 5eeec96..5692017 100644
--- a/net/ipv6/netfilter/ip6_tables.c
+++ b/net/ipv6/netfilter/ip6_tables.c
@@ -591,20 +591,10 @@ static void cleanup_match(struct xt_entry_match *m, struct net *net)
 static int
 check_entry(const struct ip6t_entry *e)
 {
-	const struct xt_entry_target *t;
-
 	if (!ip6_checkentry(&e->ipv6))
 		return -EINVAL;
 
-	if (e->target_offset + sizeof(struct xt_entry_target) >
-	    e->next_offset)
-		return -EINVAL;
-
-	t = ip6t_get_target_c(e);
-	if (e->target_offset + t->u.target_size > e->next_offset)
-		return -EINVAL;
-
-	return 0;
+	return xt_check_entry_offsets(e, e->target_offset, e->next_offset);
 }
 
 static int check_match(struct xt_entry_match *m, struct xt_mtchk_param *par)
diff --git a/net/netfilter/x_tables.c b/net/netfilter/x_tables.c
index 8b03028..55b1e0c 100644
--- a/net/netfilter/x_tables.c
+++ b/net/netfilter/x_tables.c
@@ -560,6 +560,40 @@ int xt_compat_match_to_user(const struct xt_entry_match *m,
 EXPORT_SYMBOL_GPL(xt_compat_match_to_user);
 #endif /* CONFIG_COMPAT */
 
+/**
+ * xt_check_entry_offsets - validate arp/ip/ip6t_entry
+ *
+ * @base: pointer to arp/ip/ip6t_entry
+ * @target_offset: the arp/ip/ip6_t->target_offset
+ * @next_offset: the arp/ip/ip6_t->next_offset
+ *
+ * validates that target_offset and next_offset are sane.
+ *
+ * The arp/ip/ip6t_entry structure @base must have passed following tests:
+ * - it must point to a valid memory location
+ * - base to base + next_offset must be accessible, i.e. not exceed allocated
+ *   length.
+ *
+ * Return: 0 on success, negative errno on failure.
+ */
+int xt_check_entry_offsets(const void *base,
+			   unsigned int target_offset,
+			   unsigned int next_offset)
+{
+	const struct xt_entry_target *t;
+	const char *e = base;
+
+	if (target_offset + sizeof(*t) > next_offset)
+		return -EINVAL;
+
+	t = (void *)(e + target_offset);
+	if (target_offset + t->u.target_size > next_offset)
+		return -EINVAL;
+
+	return 0;
+}
+EXPORT_SYMBOL(xt_check_entry_offsets);
+
 int xt_check_target(struct xt_tgchk_param *par,
 		    unsigned int size, u_int8_t proto, bool inv_proto)
 {
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467056 — [PATCH 3.10 135/180] scsi: fix race between simultaneous decrements of ->host_failed

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:40 +0200
Subject[PATCH 3.10 135/180] scsi: fix race between simultaneous decrements of ->host_failed
Message-ID<s8D0U-26R-129@gated-at.bofh.it>
In reply to#1467049
From: Wei Fang <fangwei1@huawei.com>

commit 72d8c36ec364c82bf1bf0c64dfa1041cfaf139f7 upstream.

sas_ata_strategy_handler() adds the works of the ata error handler to
system_unbound_wq. This workqueue asynchronously runs work items, so the
ata error handler will be performed concurrently on different CPUs. In
this case, ->host_failed will be decreased simultaneously in
scsi_eh_finish_cmd() on different CPUs, and become abnormal.

It will lead to permanently inequality between ->host_failed and
->host_busy, and scsi error handler thread won't start running. IO
errors after that won't be handled.

Since all scmds must have been handled in the strategy handler, just
remove the decrement in scsi_eh_finish_cmd() and zero ->host_busy after
the strategy handler to fix this race.

Fixes: 50824d6c5657 ("[SCSI] libsas: async ata-eh")
Cc: stable@vger.kernel.org
Signed-off-by: Wei Fang <fangwei1@huawei.com>
Reviewed-by: James Bottomley <jejb@linux.vnet.ibm.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 Documentation/scsi/scsi_eh.txt | 8 ++++++--
 drivers/ata/libata-eh.c        | 2 +-
 drivers/scsi/scsi_error.c      | 4 +++-
 3 files changed, 10 insertions(+), 4 deletions(-)

diff --git a/Documentation/scsi/scsi_eh.txt b/Documentation/scsi/scsi_eh.txt
index 6ff16b6..c08b62d 100644
--- a/Documentation/scsi/scsi_eh.txt
+++ b/Documentation/scsi/scsi_eh.txt
@@ -255,19 +255,23 @@ scmd->allowed.
 
  3. scmd recovered
     ACTION: scsi_eh_finish_cmd() is invoked to EH-finish scmd
-	- shost->host_failed--
 	- clear scmd->eh_eflags
 	- scsi_setup_cmd_retry()
 	- move from local eh_work_q to local eh_done_q
     LOCKING: none
+    CONCURRENCY: at most one thread per separate eh_work_q to
+		 keep queue manipulation lockless
 
  4. EH completes
     ACTION: scsi_eh_flush_done_q() retries scmds or notifies upper
-	    layer of failure.
+	    layer of failure. May be called concurrently but must have
+	    a no more than one thread per separate eh_work_q to
+	    manipulate the queue locklessly
 	- scmd is removed from eh_done_q and scmd->eh_entry is cleared
 	- if retry is necessary, scmd is requeued using
           scsi_queue_insert()
 	- otherwise, scsi_finish_command() is invoked for scmd
+	- zero shost->host_failed
     LOCKING: queue or finish function performs appropriate locking
 
 
diff --git a/drivers/ata/libata-eh.c b/drivers/ata/libata-eh.c
index 063036d..126eb86 100644
--- a/drivers/ata/libata-eh.c
+++ b/drivers/ata/libata-eh.c
@@ -604,7 +604,7 @@ void ata_scsi_error(struct Scsi_Host *host)
 	ata_scsi_port_error_handler(host, ap);
 
 	/* finish or retry handled scmd's and clean up */
-	WARN_ON(host->host_failed || !list_empty(&eh_work_q));
+	WARN_ON(!list_empty(&eh_work_q));
 
 	DPRINTK("EXIT\n");
 }
diff --git a/drivers/scsi/scsi_error.c b/drivers/scsi/scsi_error.c
index 9acbc88..5ba69ea 100644
--- a/drivers/scsi/scsi_error.c
+++ b/drivers/scsi/scsi_error.c
@@ -898,7 +898,6 @@ static int scsi_request_sense(struct scsi_cmnd *scmd)
  */
 void scsi_eh_finish_cmd(struct scsi_cmnd *scmd, struct list_head *done_q)
 {
-	scmd->device->host->host_failed--;
 	scmd->eh_eflags = 0;
 	list_move_tail(&scmd->eh_entry, done_q);
 }
@@ -1892,6 +1891,9 @@ int scsi_error_handler(void *data)
 		else
 			scsi_unjam_host(shost);
 
+		/* All scmds have been handled */
+		shost->host_failed = 0;
+
 		/*
 		 * Note - if the above fails completely, the action is to take
 		 * individual devices offline and flush the queue of any
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467057 — [PATCH 3.10 131/180] ALSA: ctl: Stop notification after disconnection

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:40 +0200
Subject[PATCH 3.10 131/180] ALSA: ctl: Stop notification after disconnection
Message-ID<s8D0U-26R-117@gated-at.bofh.it>
In reply to#1467049
From: Takashi Iwai <tiwai@suse.de>

commit f388cdcdd160687c6650833f286b9c89c50960ff upstream.

snd_ctl_remove() has a notification for the removal event.  It's
superfluous when done during the device got disconnected.  Although
the notification itself is mostly harmless, it may potentially be
harmful, and should be suppressed.  Actually some components PCM may
free ctl elements during the disconnect or free callbacks, thus it's
no theoretical issue.

This patch adds the check of card->shutdown flag for avoiding
unnecessary notifications after (or during) the disconnect.

Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 sound/core/control.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/sound/core/control.c b/sound/core/control.c
index 3fcead6..251bc57 100644
--- a/sound/core/control.c
+++ b/sound/core/control.c
@@ -150,6 +150,8 @@ void snd_ctl_notify(struct snd_card *card, unsigned int mask,
 	
 	if (snd_BUG_ON(!card || !id))
 		return;
+	if (card->shutdown)
+		return;
 	read_lock(&card->ctl_files_rwlock);
 #if defined(CONFIG_SND_MIXER_OSS) || defined(CONFIG_SND_MIXER_OSS_MODULE)
 	card->mixer_oss_change_count++;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467058 — [PATCH 3.10 178/180] isdn: hfcpci_softirq: get func return to suppress compiler warning

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:40 +0200
Subject[PATCH 3.10 178/180] isdn: hfcpci_softirq: get func return to suppress compiler warning
Message-ID<s8D0U-26R-131@gated-at.bofh.it>
In reply to#1467049
From: Antonio Alecrim Jr <antonio.alecrim@gmail.com>

commit d6d6d1bc44362112e10a48d434e5b3c716152003 upstream.

Signed-off-by: Antonio Alecrim Jr <antonio.alecrim@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/isdn/hardware/mISDN/hfcpci.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/isdn/hardware/mISDN/hfcpci.c b/drivers/isdn/hardware/mISDN/hfcpci.c
index a7e4939..eab9167 100644
--- a/drivers/isdn/hardware/mISDN/hfcpci.c
+++ b/drivers/isdn/hardware/mISDN/hfcpci.c
@@ -2295,8 +2295,8 @@ _hfcpci_softirq(struct device *dev, void *arg)
 static void
 hfcpci_softirq(void *arg)
 {
-	(void) driver_for_each_device(&hfc_driver.driver, NULL, arg,
-				      _hfcpci_softirq);
+	WARN_ON_ONCE(driver_for_each_device(&hfc_driver.driver, NULL, arg,
+				      _hfcpci_softirq) != 0);
 
 	/* if next event would be in the past ... */
 	if ((s32)(hfc_jiffies + tics - jiffies) <= 0)
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467059 — [PATCH 3.10 177/180] net: rfkill: Do not ignore errors from regulator_enable()

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:50 +0200
Subject[PATCH 3.10 177/180] net: rfkill: Do not ignore errors from regulator_enable()
Message-ID<s8Dax-2bE-1@gated-at.bofh.it>
In reply to#1467049
From: Luis Henriques <luis.henriques@canonical.com>

commit dee08ab83d0378d922b67e7cf10bbec3e4ea343b upstream.

Function regulator_enable() may return an error that has to be checked.
This patch changes function rfkill_regulator_set_block() so that it checks
for the return code.  Also, rfkill_data->reg_enabled is set to 'true' only
if there is no error.

This fixes the following compilation warning:

net/rfkill/rfkill-regulator.c:43:20: warning: ignoring return value of 'regulator_enable', declared with attribute warn_unused_result [-Wunused-result]

Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/rfkill/rfkill-regulator.c | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

diff --git a/net/rfkill/rfkill-regulator.c b/net/rfkill/rfkill-regulator.c
index d11ac79..cf5b145 100644
--- a/net/rfkill/rfkill-regulator.c
+++ b/net/rfkill/rfkill-regulator.c
@@ -30,6 +30,7 @@ struct rfkill_regulator_data {
 static int rfkill_regulator_set_block(void *data, bool blocked)
 {
 	struct rfkill_regulator_data *rfkill_data = data;
+	int ret = 0;
 
 	pr_debug("%s: blocked: %d\n", __func__, blocked);
 
@@ -40,15 +41,16 @@ static int rfkill_regulator_set_block(void *data, bool blocked)
 		}
 	} else {
 		if (!rfkill_data->reg_enabled) {
-			regulator_enable(rfkill_data->vcc);
-			rfkill_data->reg_enabled = true;
+			ret = regulator_enable(rfkill_data->vcc);
+			if (!ret)
+				rfkill_data->reg_enabled = true;
 		}
 	}
 
 	pr_debug("%s: regulator_is_enabled after set_block: %d\n", __func__,
 		regulator_is_enabled(rfkill_data->vcc));
 
-	return 0;
+	return ret;
 }
 
 static struct rfkill_ops rfkill_regulator_ops = {
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467060 — [PATCH 3.10 145/180] ARC: use ASL assembler mnemonic

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:50 +0200
Subject[PATCH 3.10 145/180] ARC: use ASL assembler mnemonic
Message-ID<s8Dax-2bE-3@gated-at.bofh.it>
In reply to#1467049
From: Vineet Gupta <vgupta@synopsys.com>

commit a6416f57ce57fb390b6ee30b12c01c29032a26af upstream.

ARCompact and ARCv2 only have ASL, while binutils used to support LSL as
a alias mnemonic.

Newer binutils (upstream) don't want to do that so replace it.

Signed-off-by: Vineet Gupta <vgupta@synopsys.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 arch/arc/mm/tlbex.S | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/arc/mm/tlbex.S b/arch/arc/mm/tlbex.S
index 3357d26..74691e6 100644
--- a/arch/arc/mm/tlbex.S
+++ b/arch/arc/mm/tlbex.S
@@ -219,7 +219,7 @@ ex_saved_reg1:
 #ifdef CONFIG_SMP
 	sr  r0, [ARC_REG_SCRATCH_DATA0]	; freeup r0 to code with
 	GET_CPU_ID  r0			; get to per cpu scratch mem,
-	lsl r0, r0, L1_CACHE_SHIFT	; cache line wide per cpu
+	asl r0, r0, L1_CACHE_SHIFT	; cache line wide per cpu
 	add r0, @ex_saved_reg1, r0
 #else
 	st    r0, [@ex_saved_reg1]
@@ -239,7 +239,7 @@ ex_saved_reg1:
 .macro TLBMISS_RESTORE_REGS
 #ifdef CONFIG_SMP
 	GET_CPU_ID  r0			; get to per cpu scratch mem
-	lsl r0, r0, L1_CACHE_SHIFT	; each is cache line wide
+	asl r0, r0, L1_CACHE_SHIFT	; each is cache line wide
 	add r0, @ex_saved_reg1, r0
 	ld_s  r3, [r0,12]
 	ld_s  r2, [r0, 8]
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467061 — [PATCH 3.10 093/180] KVM: x86: fix OOPS after invalid KVM_SET_DEBUGREGS

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:50 +0200
Subject[PATCH 3.10 093/180] KVM: x86: fix OOPS after invalid KVM_SET_DEBUGREGS
Message-ID<s8Dax-2bE-5@gated-at.bofh.it>
In reply to#1467049
From: Paolo Bonzini <pbonzini@redhat.com>

commit d14bdb553f9196169f003058ae1cdabe514470e6 upstream.

MOV to DR6 or DR7 causes a #GP if an attempt is made to write a 1 to
any of bits 63:32.  However, this is not detected at KVM_SET_DEBUGREGS
time, and the next KVM_RUN oopses:

   general protection fault: 0000 [#1] SMP
   CPU: 2 PID: 14987 Comm: a.out Not tainted 4.4.9-300.fc23.x86_64 #1
   Hardware name: LENOVO 2325F51/2325F51, BIOS G2ET32WW (1.12 ) 05/30/2012
   [...]
   Call Trace:
    [<ffffffffa072c93d>] kvm_arch_vcpu_ioctl_run+0x141d/0x14e0 [kvm]
    [<ffffffffa071405d>] kvm_vcpu_ioctl+0x33d/0x620 [kvm]
    [<ffffffff81241648>] do_vfs_ioctl+0x298/0x480
    [<ffffffff812418a9>] SyS_ioctl+0x79/0x90
    [<ffffffff817a0f2e>] entry_SYSCALL_64_fastpath+0x12/0x71
   Code: 55 83 ff 07 48 89 e5 77 27 89 ff ff 24 fd 90 87 80 81 0f 23 fe 5d c3 0f 23 c6 5d c3 0f 23 ce 5d c3 0f 23 d6 5d c3 0f 23 de 5d c3 <0f> 23 f6 5d c3 0f 0b 66 66 66 66 66 2e 0f 1f 84 00 00 00 00 00
   RIP  [<ffffffff810639eb>] native_set_debugreg+0x2b/0x40
    RSP <ffff88005836bd50>

Testcase (beautified/reduced from syzkaller output):

    #include <unistd.h>
    #include <sys/syscall.h>
    #include <string.h>
    #include <stdint.h>
    #include <linux/kvm.h>
    #include <fcntl.h>
    #include <sys/ioctl.h>

    long r[8];

    int main()
    {
        struct kvm_debugregs dr = { 0 };

        r[2] = open("/dev/kvm", O_RDONLY);
        r[3] = ioctl(r[2], KVM_CREATE_VM, 0);
        r[4] = ioctl(r[3], KVM_CREATE_VCPU, 7);

        memcpy(&dr,
               "\x5d\x6a\x6b\xe8\x57\x3b\x4b\x7e\xcf\x0d\xa1\x72"
               "\xa3\x4a\x29\x0c\xfc\x6d\x44\x00\xa7\x52\xc7\xd8"
               "\x00\xdb\x89\x9d\x78\xb5\x54\x6b\x6b\x13\x1c\xe9"
               "\x5e\xd3\x0e\x40\x6f\xb4\x66\xf7\x5b\xe3\x36\xcb",
               48);
        r[7] = ioctl(r[4], KVM_SET_DEBUGREGS, &dr);
        r[6] = ioctl(r[4], KVM_RUN, 0);
    }

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Radim Krčmář <rkrcmar@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 arch/x86/kvm/x86.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index 3c0b085..8e57771 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -2966,6 +2966,11 @@ static int kvm_vcpu_ioctl_x86_set_debugregs(struct kvm_vcpu *vcpu,
 	if (dbgregs->flags)
 		return -EINVAL;
 
+	if (dbgregs->dr6 & ~0xffffffffull)
+		return -EINVAL;
+	if (dbgregs->dr7 & ~0xffffffffull)
+		return -EINVAL;
+
 	memcpy(vcpu->arch.db, dbgregs->db, sizeof(vcpu->arch.db));
 	vcpu->arch.dr6 = dbgregs->dr6;
 	vcpu->arch.dr7 = dbgregs->dr7;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467062 — [PATCH 3.10 153/180] x86/mm: Improve switch_mm() barrier comments

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:50 +0200
Subject[PATCH 3.10 153/180] x86/mm: Improve switch_mm() barrier comments
Message-ID<s8Dax-2bE-7@gated-at.bofh.it>
In reply to#1467049
From: Andy Lutomirski <luto@kernel.org>

commit 4eaffdd5a5fe6ff9f95e1ab4de1ac904d5e0fa8b upstream.

My previous comments were still a bit confusing and there was a
typo. Fix it up.

Reported-by: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Andy Lutomirski <luto@kernel.org>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Brian Gerst <brgerst@gmail.com>
Cc: Dave Hansen <dave.hansen@linux.intel.com>
Cc: Denys Vlasenko <dvlasenk@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Rik van Riel <riel@redhat.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: stable@vger.kernel.org
Fixes: 71b3c126e611 ("x86/mm: Add barriers and document switch_mm()-vs-flush synchronization")
Link: http://lkml.kernel.org/r/0a0b43cdcdd241c5faaaecfbcc91a155ddedc9a1.1452631609.git.luto@kernel.org
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 arch/x86/include/asm/mmu_context.h | 15 ++++++++-------
 1 file changed, 8 insertions(+), 7 deletions(-)

diff --git a/arch/x86/include/asm/mmu_context.h b/arch/x86/include/asm/mmu_context.h
index c0d2f6b..29a3d1b 100644
--- a/arch/x86/include/asm/mmu_context.h
+++ b/arch/x86/include/asm/mmu_context.h
@@ -58,14 +58,16 @@ static inline void switch_mm(struct mm_struct *prev, struct mm_struct *next,
 		 * be sent, and CPU 0's TLB will contain a stale entry.)
 		 *
 		 * The bad outcome can occur if either CPU's load is
-		 * reordered before that CPU's store, so both CPUs much
+		 * reordered before that CPU's store, so both CPUs must
 		 * execute full barriers to prevent this from happening.
 		 *
 		 * Thus, switch_mm needs a full barrier between the
 		 * store to mm_cpumask and any operation that could load
-		 * from next->pgd.  This barrier synchronizes with
-		 * remote TLB flushers.  Fortunately, load_cr3 is
-		 * serializing and thus acts as a full barrier.
+		 * from next->pgd.  TLB fills are special and can happen
+		 * due to instruction fetches or for no reason at all,
+		 * and neither LOCK nor MFENCE orders them.
+		 * Fortunately, load_cr3() is serializing and gives the
+		 * ordering guarantee we need.
 		 *
 		 */
 		load_cr3(next->pgd);
@@ -96,9 +98,8 @@ static inline void switch_mm(struct mm_struct *prev, struct mm_struct *next,
 			 * tlb flush IPI delivery. We must reload CR3
 			 * to make sure to use no freed page tables.
 			 *
-			 * As above, this is a barrier that forces
-			 * TLB repopulation to be ordered after the
-			 * store to mm_cpumask.
+			 * As above, load_cr3() is serializing and orders TLB
+			 * fills with respect to the mm_cpumask write.
 			 */
 			load_cr3(next->pgd);
 			load_LDT_nolock(&next->context);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467063 — [PATCH 3.10 061/180] Input: xpad - validate USB endpoint count during probe

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:50 +0200
Subject[PATCH 3.10 061/180] Input: xpad - validate USB endpoint count during probe
Message-ID<s8Day-2bE-23@gated-at.bofh.it>
In reply to#1467049
From: Cameron Gutman <aicommander@gmail.com>

commit caca925fca4fb30c67be88cacbe908eec6721e43 upstream.

This prevents a malicious USB device from causing an oops.

Signed-off-by: Cameron Gutman <aicommander@gmail.com>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/input/joystick/xpad.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/input/joystick/xpad.c b/drivers/input/joystick/xpad.c
index 856c1b0..685e125 100644
--- a/drivers/input/joystick/xpad.c
+++ b/drivers/input/joystick/xpad.c
@@ -843,6 +843,9 @@ static int xpad_probe(struct usb_interface *intf, const struct usb_device_id *id
 	struct usb_endpoint_descriptor *ep_irq_in;
 	int i, error;
 
+	if (intf->cur_altsetting->desc.bNumEndpoints != 2)
+		return -ENODEV;
+
 	for (i = 0; xpad_device[i].idVendor; i++) {
 		if ((le16_to_cpu(udev->descriptor.idVendor) == xpad_device[i].idVendor) &&
 		    (le16_to_cpu(udev->descriptor.idProduct) == xpad_device[i].idProduct))
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467064 — [PATCH 3.10 104/180] sit: correct IP protocol used in ipip6_err

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:50 +0200
Subject[PATCH 3.10 104/180] sit: correct IP protocol used in ipip6_err
Message-ID<s8Day-2bE-9@gated-at.bofh.it>
In reply to#1467049
From: Simon Horman <simon.horman@netronome.com>

commit d5d8760b78d0cfafe292f965f599988138b06a70 upstream.

Since 32b8a8e59c9c ("sit: add IPv4 over IPv4 support")
ipip6_err() may be called for packets whose IP protocol is
IPPROTO_IPIP as well as those whose IP protocol is IPPROTO_IPV6.

In the case of IPPROTO_IPIP packets the correct protocol value is not
passed to ipv4_update_pmtu() or ipv4_redirect().

This patch resolves this problem by using the IP protocol of the packet
rather than a hard-coded value. This appears to be consistent
with the usage of the protocol of a packet by icmp_socket_deliver()
the caller of ipip6_err().

I was able to exercise the redirect case by using a setup where an ICMP
redirect was received for the destination of the encapsulated packet.
However, it appears that although incorrect the protocol field is not used
in this case and thus no problem manifests.  On inspection it does not
appear that a problem will manifest in the fragmentation needed/update pmtu
case either.

In short I believe this is a cosmetic fix. None the less, the use of
IPPROTO_IPV6 seems wrong and confusing.

Reviewed-by: Dinan Gunawardena <dinan.gunawardena@netronome.com>
Signed-off-by: Simon Horman <simon.horman@netronome.com>
Acked-by: YOSHIFUJI Hideaki <yoshfuji@linux-ipv6.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/ipv6/sit.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/net/ipv6/sit.c b/net/ipv6/sit.c
index 4ddf67c..d9535bb 100644
--- a/net/ipv6/sit.c
+++ b/net/ipv6/sit.c
@@ -530,13 +530,13 @@ static int ipip6_err(struct sk_buff *skb, u32 info)
 
 	if (type == ICMP_DEST_UNREACH && code == ICMP_FRAG_NEEDED) {
 		ipv4_update_pmtu(skb, dev_net(skb->dev), info,
-				 t->parms.link, 0, IPPROTO_IPV6, 0);
+				 t->parms.link, 0, iph->protocol, 0);
 		err = 0;
 		goto out;
 	}
 	if (type == ICMP_REDIRECT) {
 		ipv4_redirect(skb, dev_net(skb->dev), t->parms.link, 0,
-			      IPPROTO_IPV6, 0);
+			      iph->protocol, 0);
 		err = 0;
 		goto out;
 	}
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467065 — [PATCH 3.10 162/180] s5p-mfc: Add release callback for memory region devs

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:50 +0200
Subject[PATCH 3.10 162/180] s5p-mfc: Add release callback for memory region devs
Message-ID<s8Day-2bE-11@gated-at.bofh.it>
In reply to#1467049
From: Javier Martinez Canillas <javier@osg.samsung.com>

commit 6311f1261f59ce5e51fbe5cc3b5e7737197316ac upstream.

When s5p_mfc_remove() calls put_device() for the reserved memory region
devs, the driver core warns that the dev doesn't have a release callback:

WARNING: CPU: 0 PID: 591 at drivers/base/core.c:251 device_release+0x8c/0x90
Device 's5p-mfc-l' does not have a release() function, it is broken and must be fixed.

Also, the declared DMA memory using dma_declare_coherent_memory() isn't
relased so add a dev .release that calls dma_release_declared_memory().

Cc: <stable@vger.kernel.org>
Fixes: 6e83e6e25eb4 ("[media] s5p-mfc: Fix kernel warning on memory init")
Signed-off-by: Javier Martinez Canillas <javier@osg.samsung.com>
Tested-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Sylwester Nawrocki <s.nawrocki@samsung.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/media/platform/s5p-mfc/s5p_mfc.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/drivers/media/platform/s5p-mfc/s5p_mfc.c b/drivers/media/platform/s5p-mfc/s5p_mfc.c
index fe91623..eb92027 100644
--- a/drivers/media/platform/s5p-mfc/s5p_mfc.c
+++ b/drivers/media/platform/s5p-mfc/s5p_mfc.c
@@ -1000,6 +1000,11 @@ static int match_child(struct device *dev, void *data)
 	return !strcmp(dev_name(dev), (char *)data);
 }
 
+static void s5p_mfc_memdev_release(struct device *dev)
+{
+	dma_release_declared_memory(dev);
+}
+
 static void *mfc_get_drv_data(struct platform_device *pdev);
 
 static int s5p_mfc_alloc_memdevs(struct s5p_mfc_dev *dev)
@@ -1014,6 +1019,7 @@ static int s5p_mfc_alloc_memdevs(struct s5p_mfc_dev *dev)
 	}
 
 	dev_set_name(dev->mem_dev_l, "%s", "s5p-mfc-l");
+	dev->mem_dev_l->release = s5p_mfc_memdev_release;
 	device_initialize(dev->mem_dev_l);
 	of_property_read_u32_array(dev->plat_dev->dev.of_node,
 			"samsung,mfc-l", mem_info, 2);
@@ -1033,6 +1039,7 @@ static int s5p_mfc_alloc_memdevs(struct s5p_mfc_dev *dev)
 	}
 
 	dev_set_name(dev->mem_dev_r, "%s", "s5p-mfc-r");
+	dev->mem_dev_r->release = s5p_mfc_memdev_release;
 	device_initialize(dev->mem_dev_r);
 	of_property_read_u32_array(dev->plat_dev->dev.of_node,
 			"samsung,mfc-r", mem_info, 2);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467066 — [PATCH 3.10 126/180] iio:ad7266: Fix broken regulator error handling

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:50 +0200
Subject[PATCH 3.10 126/180] iio:ad7266: Fix broken regulator error handling
Message-ID<s8Day-2bE-13@gated-at.bofh.it>
In reply to#1467049
From: Mark Brown <broonie@kernel.org>

commit 6b7f4e25f3309f106a5c7ff42c8231494cf285d3 upstream.

All regulator_get() variants return either a pointer to a regulator or an
ERR_PTR() so testing for NULL makes no sense and may lead to bugs if we
use NULL as a valid regulator. Fix this by using IS_ERR() as expected.

Signed-off-by: Mark Brown <broonie@kernel.org>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/iio/adc/ad7266.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/iio/adc/ad7266.c b/drivers/iio/adc/ad7266.c
index c2744a7..d08f417 100644
--- a/drivers/iio/adc/ad7266.c
+++ b/drivers/iio/adc/ad7266.c
@@ -406,7 +406,7 @@ static int ad7266_probe(struct spi_device *spi)
 	st = iio_priv(indio_dev);
 
 	st->reg = regulator_get(&spi->dev, "vref");
-	if (!IS_ERR_OR_NULL(st->reg)) {
+	if (!IS_ERR(st->reg)) {
 		ret = regulator_enable(st->reg);
 		if (ret)
 			goto error_put_reg;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467067 — [PATCH 3.10 049/180] tcp: consider recv buf for the initial window scale

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:50 +0200
Subject[PATCH 3.10 049/180] tcp: consider recv buf for the initial window scale
Message-ID<s8Day-2bE-31@gated-at.bofh.it>
In reply to#1467049
From: Soheil Hassas Yeganeh <soheil@google.com>

commit f626300a3e776ccc9671b0dd94698fb3aa315966 upstream.

tcp_select_initial_window() intends to advertise a window
scaling for the maximum possible window size. To do so,
it considers the maximum of net.ipv4.tcp_rmem[2] and
net.core.rmem_max as the only possible upper-bounds.
However, users with CAP_NET_ADMIN can use SO_RCVBUFFORCE
to set the socket's receive buffer size to values
larger than net.ipv4.tcp_rmem[2] and net.core.rmem_max.
Thus, SO_RCVBUFFORCE is effectively ignored by
tcp_select_initial_window().

To fix this, consider the maximum of net.ipv4.tcp_rmem[2],
net.core.rmem_max and socket's initial buffer space.

Fixes: b0573dea1fb3 ("[NET]: Introduce SO_{SND,RCV}BUFFORCE socket options")
Signed-off-by: Soheil Hassas Yeganeh <soheil@google.com>
Suggested-by: Neal Cardwell <ncardwell@google.com>
Acked-by: Neal Cardwell <ncardwell@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/ipv4/tcp_output.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/net/ipv4/tcp_output.c b/net/ipv4/tcp_output.c
index 76c80b59..276b283 100644
--- a/net/ipv4/tcp_output.c
+++ b/net/ipv4/tcp_output.c
@@ -222,7 +222,8 @@ void tcp_select_initial_window(int __space, __u32 mss,
 		/* Set window scaling on max possible window
 		 * See RFC1323 for an explanation of the limit to 14
 		 */
-		space = max_t(u32, sysctl_tcp_rmem[2], sysctl_rmem_max);
+		space = max_t(u32, space, sysctl_tcp_rmem[2]);
+		space = max_t(u32, space, sysctl_rmem_max);
 		space = min_t(u32, space, *window_clamp);
 		while (space > 65535 && (*rcv_wscale) < 14) {
 			space >>= 1;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1467068 — [PATCH 3.10 127/180] iio:ad7266: Fix probe deferral for vref

FromWilly Tarreau <w@1wt.eu>
Date2016-08-21 17:50 +0200
Subject[PATCH 3.10 127/180] iio:ad7266: Fix probe deferral for vref
Message-ID<s8Day-2bE-15@gated-at.bofh.it>
In reply to#1467049
From: Mark Brown <broonie@kernel.org>

commit 68b356eb3d9f5e38910fb62e22a78e2a18d544ae upstream.

Currently the ad7266 driver treats any failure to get vref as though the
regulator were not present but this means that if probe deferral is
triggered the driver will act as though the regulator were not present.
Instead only use the internal reference if we explicitly got -ENODEV which
is what is returned for absent regulators.

Signed-off-by: Mark Brown <broonie@kernel.org>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/iio/adc/ad7266.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/iio/adc/ad7266.c b/drivers/iio/adc/ad7266.c
index d08f417..6569a4e 100644
--- a/drivers/iio/adc/ad7266.c
+++ b/drivers/iio/adc/ad7266.c
@@ -417,6 +417,10 @@ static int ad7266_probe(struct spi_device *spi)
 
 		st->vref_uv = ret;
 	} else {
+		/* Any other error indicates that the regulator does exist */
+		if (PTR_ERR(st->reg) != -ENODEV)
+			return PTR_ERR(st->reg);
+
 		/* Use internal reference */
 		st->vref_uv = 2500000;
 	}
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


Page 1 of 8  [1] 2 3 4 5 6 7 8  Next page →

Back to top | Article view | linux.kernel


csiph-web