Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1467049 > unrolled thread
| Started by | Willy Tarreau <w@1wt.eu> |
|---|---|
| First post | 2016-08-21 17:40 +0200 |
| Last post | 2016-08-21 18:20 +0200 |
| Articles | 20 on this page of 141 — 4 participants |
Back to article view | Back to linux.kernel
[PATCH 3.10 000/180] 3.10.103-stable review Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
[PATCH 3.10 036/180] usb: renesas_usbhs: protect the CFIFOSEL setting in usbhsg_ep_enable() Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
[PATCH 3.10 028/180] udp: properly support MSG_PEEK with truncated buffers Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
[PATCH 3.10 017/180] netfilter: ip_tables: simplify translate_compat_table args Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
[PATCH 3.10 132/180] ALSA: timer: Fix leak in SNDRV_TIMER_IOCTL_PARAMS Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
[PATCH 3.10 053/180] MIPS: KVM: Propagate kseg0/mapped tlb fault errors Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
[PATCH 3.10 008/180] netfilter: x_tables: add and use xt_check_entry_offsets Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
[PATCH 3.10 135/180] scsi: fix race between simultaneous decrements of ->host_failed Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
[PATCH 3.10 131/180] ALSA: ctl: Stop notification after disconnection Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
[PATCH 3.10 178/180] isdn: hfcpci_softirq: get func return to suppress compiler warning Willy Tarreau <w@1wt.eu> - 2016-08-21 17:40 +0200
[PATCH 3.10 177/180] net: rfkill: Do not ignore errors from regulator_enable() Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 145/180] ARC: use ASL assembler mnemonic Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 093/180] KVM: x86: fix OOPS after invalid KVM_SET_DEBUGREGS Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 153/180] x86/mm: Improve switch_mm() barrier comments Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 061/180] Input: xpad - validate USB endpoint count during probe Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 104/180] sit: correct IP protocol used in ipip6_err Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 162/180] s5p-mfc: Add release callback for memory region devs Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 126/180] iio:ad7266: Fix broken regulator error handling Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 049/180] tcp: consider recv buf for the initial window scale Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 127/180] iio:ad7266: Fix probe deferral for vref Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 054/180] MIPS: math-emu: Fix jalr emulation when rd == $0 Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 173/180] be2iscsi: Fix bogus WARN_ON length check Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 020/180] netfilter: ensure number of counters is >0 in do_replace() Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 109/180] IB/mlx4: Properly initialize GRH TClass and FlowLabel in AHs Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 019/180] netfilter: x_tables: xt_compat_match_from_user doesn't need a retval Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 165/180] netlabel: add address family checks to netlbl_{sock,req}_delattr() Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 039/180] cdc_ncm: do not call usbnet_link_change from cdc_ncm_bind Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 055/180] MIPS: Fix siginfo.h to use strict posix types Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 071/180] powerpc/iommu: Remove the dependency on EEH struct in DDW mechanism Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 174/180] squash mm: Export migrate_page_... : also make it non-static Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 026/180] signal: remove warning about using SI_TKILL in rt_[tg]sigqueueinfo Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 129/180] ALSA: dummy: Fix a use-after-free at closing Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 009/180] netfilter: x_tables: kill check_entry helper Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 158/180] net/irda: fix NULL pointer dereference on memory allocation failure Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 015/180] netfilter: x_tables: don't reject valid target size on some architectures Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 058/180] MIPS: KVM: Fix modular KVM under QEMU Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 113/180] x86, build: copy ldlinux.c32 to image.iso Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 112/180] IB/mlx4: Fix the SQ size of an RC QP Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 095/180] arm: oabi compat: add missing access checks Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 096/180] parisc: Fix pagefault crash in unaligned __get_user() call Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 059/180] Input: uinput - handle compat ioctl for UI_SET_PHYS Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 064/180] aacraid: Fix for aac_command_thread hang Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 124/180] staging: iio: accel: fix error check Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 052/180] MIPS: KVM: Fix gfn range check in kseg0 tlb faults Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 012/180] netfilter: x_tables: check standard target size too Willy Tarreau <w@1wt.eu> - 2016-08-21 17:50 +0200
[PATCH 3.10 176/180] ALSA: oxygen: Fix logical-not-parentheses warning Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 111/180] IB/IPoIB: Don't update neigh validity for unresolved entries Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 163/180] Bluetooth: Fix l2cap_sock_setsockopt() with optname BT_RCVMTU Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 094/180] ARM: fix PTRACE_SETVFPREGS on SMP systems Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 024/180] perf/x86: Honor the architectural performance monitoring version Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 130/180] ALSA: au88x0: Fix calculation in vortex_wtdma_bufshift() Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 141/180] arc: unwind: warn only once if DW2_UNWIND is disabled Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 092/180] xfs: skip stale inodes in xfs_iflush_cluster Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 050/180] MIPS: KVM: Fix mapped fault broken commpage handling Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 128/180] tty/vt/keyboard: fix OOB access in do_compute_shiftstate() Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 161/180] s5p-mfc: Set device name for reserved memory region devs Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 140/180] fs/nilfs2: fix potential underflow in call to crc32_le Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 068/180] powerpc: Fix definition of SIAR and SDAR registers Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 078/180] drm/radeon: add a delay after ATPX dGPU power off Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 018/180] netfilter: ip6_tables: simplify translate_compat_table args Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 136/180] scsi: remove scsi_end_request Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 152/180] sctp: Prevent soft lockup when sctp_accept() is called during a timeout event Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 062/180] ath5k: Change led pin configuration for compaq c700 laptop Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 100/180] xfs: fix up backport error in fs/xfs/xfs_inode.c Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 076/180] drm/fb_helper: Fix references to dev->mode_config.num_connector Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 099/180] fix d_walk()/non-delayed __d_free() race Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 156/180] block: fix use-after-free in seq file Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 121/180] tracing: Handle NULL formats in hold_module_trace_bprintk_format() Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 066/180] rtlwifi: Fix logic error in enter/exit power-save mode Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 167/180] ftrace/recordmcount: Work around for addition of metag magic but not relocations Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 149/180] can: fix oops caused by wrong rtnl dellink usage Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 037/180] x86/mm: Add barriers and document switch_mm()-vs-flush synchronization Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 134/180] ALSA: timer: Fix leak in events via snd_timer_user_tinterrupt Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 098/180] wext: Fix 32 bit iwpriv compatibility issue with 64 bit Kernel Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
Re: [PATCH 3.10 098/180] wext: Fix 32 bit iwpriv compatibility issue with 64 bit Kernel Johannes Berg <johannes@sipsolutions.net> - 2016-08-22 07:40 +0200
Re: [PATCH 3.10 098/180] wext: Fix 32 bit iwpriv compatibility issue with 64 bit Kernel Willy Tarreau <w@1wt.eu> - 2016-08-22 07:50 +0200
[PATCH 3.10 044/180] libceph: apply new_state before new_up_client on incrementals Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 045/180] tmpfs: don't undo fallocate past its last page Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 168/180] metag: Fix __cmpxchg_u32 asm constraint for CMP Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 046/180] tmpfs: fix regression hang in fallocate undo Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 075/180] drm/gma500: Fix possible out of bounds read Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 169/180] ubi: Make volume resize power cut aware Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 179/180] stb6100: fix buffer length check in stb6100_write_reg_range() Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 089/180] dma-debug: avoid spinlock recursion when disabling dma-debug Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 139/180] s390/seccomp: fix error return for filtered system calls Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 103/180] crypto: scatterwalk - Fix test in scatterwalk_done Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 147/180] mmc: block: fix packed command header endianness Willy Tarreau <w@1wt.eu> - 2016-08-21 18:00 +0200
[PATCH 3.10 102/180] crypto: gcm - Filter out async ghash if necessary Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 142/180] xen/pciback: Fix conf_space read/write overlap check. Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on error Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on error Dave Chinner <david@fromorbit.com> - 2016-08-22 06:30 +0200
Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on error Willy Tarreau <w@1wt.eu> - 2016-08-22 07:20 +0200
Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on error Willy Tarreau <w@1wt.eu> - 2016-08-22 07:30 +0200
Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on error Dave Chinner <dchinner@redhat.com> - 2016-08-22 13:00 +0200
Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on error Willy Tarreau <w@1wt.eu> - 2016-08-22 13:10 +0200
[PATCH 3.10 003/180] netfilter: x_tables: validate e->target_offset early Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 025/180] perf/x86: Fix undefined shift on 32-bit kernels Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 164/180] cifs: Check for existing directory when opening file with O_CREAT Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 091/180] xfs: fix inode validity check in xfs_iflush_cluster Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 038/180] pipe: limit the per-user amount of pages allocated in pipes Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 118/180] UBIFS: Implement ->migratepage() Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 175/180] HID: hid-input: Add parentheses to quell gcc warning Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 065/180] PCI: Disable all BAR sizing for devices with non-compliant BARs Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 144/180] ecryptfs: don't allow mmap when the lower fs doesn't support it Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 043/180] HID: hiddev: validate num_values for HIDIOCGUSAGES, HIDIOCSUSAGES commands Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 067/180] powerpc/book3s64: Fix branching to OOL handlers in relocatable kernel Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 157/180] fuse: fix wrong assignment of ->flags in fuse_send_init() Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 023/180] netfilter: x_tables: introduce and use xt_copy_counters_from_user Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 011/180] netfilter: x_tables: add compat version of xt_check_entry_offsets Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 122/180] base: make module_create_drivers_dir race-free Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 087/180] ext4: short-cut orphan cleanup on error Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 125/180] iio: accel: kxsd9: fix the usage of spi_w8r8() Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 070/180] powerpc/pseries/eeh: Handle RTAS delay requests in configure_bridge Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 107/180] mac80211: mesh: flush mesh paths unconditionally Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 138/180] xen/acpi: allow xen-acpi-processor driver to load on Xen 4.7 Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 119/180] cdc_ncm: workaround for EM7455 "silent" data interface Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 106/180] net: alx: Work around the DMA RX overflow issue Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 032/180] USB: EHCI: declare hostpc register as zero-length array Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 031/180] USB: fix up faulty backports Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 150/180] ipr: Clear interrupt on croc/crocodile when running with LSI Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 041/180] mm: migrate dirty page without clear_page_dirty_for_io etc Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 116/180] NFS: Fix another OPEN_DOWNGRADE bug Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 069/180] powerpc: Use privileged SPR number for MMCR2 Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 085/180] ext4: check for extents that wrap around Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 072/180] powerpc/pseries: Fix PCI config address for DDW Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 110/180] IB/security: Restrict use of the write() interface Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 133/180] ALSA: timer: Fix leak in events via snd_timer_user_ccallback Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 123/180] iio: Fix error handling in iio_trigger_attach_poll_func Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 172/180] module: Invalidate signatures on force-loaded modules Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 160/180] hp-wmi: Fix wifi cannot be hard-unblocked Willy Tarreau <w@1wt.eu> - 2016-08-21 18:10 +0200
[PATCH 3.10 004/180] netfilter: x_tables: make sure e->next_offset covers remaining blob size Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
[PATCH 3.10 042/180] printk: do cond_resched() between lines while outputting to consoles Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
[PATCH 3.10 001/180] X.509: remove possible code fragility: enumeration values not handled Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
[PATCH 3.10 097/180] ecryptfs: forbid opening files without mmap handler Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
[PATCH 3.10 021/180] netfilter: x_tables: do compat validation via translate_table Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
[PATCH 3.10 030/180] USB: usbfs: fix potential infoleak in devio Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
[PATCH 3.10 040/180] KEYS: potential uninitialized variable Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
[PATCH 3.10 034/180] usb: musb: Stop bulk endpoint while queue is rotated Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
[PATCH 3.10 005/180] netfilter: x_tables: fix unconditional helper Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
[PATCH 3.10 014/180] netfilter: x_tables: validate all offsets and sizes in a rule Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
[PATCH 3.10 022/180] Revert "netfilter: ensure number of counters is >0 in do_replace()" Willy Tarreau <w@1wt.eu> - 2016-08-21 18:20 +0200
Page 5 of 8 — ← Prev page 1 2 3 4 [5] 6 7 8 Next page →
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:00 +0200 |
| Subject | [PATCH 3.10 075/180] drm/gma500: Fix possible out of bounds read |
| Message-ID | <s8Dkg-2ft-77@gated-at.bofh.it> |
| In reply to | #1467049 |
From: Itai Handler <itai_handler@hotmail.com>
commit 7ccca1d5bf69fdd1d3c5fcf84faf1659a6e0ad11 upstream.
Fix possible out of bounds read, by adding missing comma.
The code may read pass the end of the dsi_errors array
when the most significant bit (bit #31) in the intr_stat register
is set.
This bug has been detected using CppCheck (static analysis tool).
Cc: stable@vger.kernel.org
Signed-off-by: Itai Handler <itai_handler@hotmail.com>
Signed-off-by: Patrik Jakobsson <patrik.r.jakobsson@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/gpu/drm/gma500/mdfld_dsi_pkg_sender.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/gma500/mdfld_dsi_pkg_sender.c b/drivers/gpu/drm/gma500/mdfld_dsi_pkg_sender.c
index 489ffd2..a3d37e4 100644
--- a/drivers/gpu/drm/gma500/mdfld_dsi_pkg_sender.c
+++ b/drivers/gpu/drm/gma500/mdfld_dsi_pkg_sender.c
@@ -85,7 +85,7 @@ static const char *const dsi_errors[] = {
"RX Prot Violation",
"HS Generic Write FIFO Full",
"LP Generic Write FIFO Full",
- "Generic Read Data Avail"
+ "Generic Read Data Avail",
"Special Packet Sent",
"Tearing Effect",
};
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:00 +0200 |
| Subject | [PATCH 3.10 169/180] ubi: Make volume resize power cut aware |
| Message-ID | <s8Dkg-2ft-83@gated-at.bofh.it> |
| In reply to | #1467049 |
From: Richard Weinberger <richard@nod.at>
commit 4946784bd3924b1374f05eebff2fd68660bae866 upstream.
When the volume resize operation shrinks a volume,
LEBs will be unmapped. Since unmapping will not erase these
LEBs immediately we have to wait for that operation to finish.
Otherwise in case of a power cut right after writing the new
volume table the UBI attach process can find more LEBs than the
volume table knows. This will render the UBI image unattachable.
Fix this issue by waiting for erase to complete and write the new
volume table afterward.
Cc: <stable@vger.kernel.org>
Reported-by: Boris Brezillon <boris.brezillon@free-electrons.com>
Reviewed-by: Boris Brezillon <boris.brezillon@free-electrons.com>
Signed-off-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/mtd/ubi/vmt.c | 25 ++++++++++++++++++-------
1 file changed, 18 insertions(+), 7 deletions(-)
diff --git a/drivers/mtd/ubi/vmt.c b/drivers/mtd/ubi/vmt.c
index 8330703..96131eb 100644
--- a/drivers/mtd/ubi/vmt.c
+++ b/drivers/mtd/ubi/vmt.c
@@ -534,13 +534,6 @@ int ubi_resize_volume(struct ubi_volume_desc *desc, int reserved_pebs)
spin_unlock(&ubi->volumes_lock);
}
- /* Change volume table record */
- vtbl_rec = ubi->vtbl[vol_id];
- vtbl_rec.reserved_pebs = cpu_to_be32(reserved_pebs);
- err = ubi_change_vtbl_record(ubi, vol_id, &vtbl_rec);
- if (err)
- goto out_acc;
-
if (pebs < 0) {
for (i = 0; i < -pebs; i++) {
err = ubi_eba_unmap_leb(ubi, vol, reserved_pebs + i);
@@ -558,6 +551,24 @@ int ubi_resize_volume(struct ubi_volume_desc *desc, int reserved_pebs)
spin_unlock(&ubi->volumes_lock);
}
+ /*
+ * When we shrink a volume we have to flush all pending (erase) work.
+ * Otherwise it can happen that upon next attach UBI finds a LEB with
+ * lnum > highest_lnum and refuses to attach.
+ */
+ if (pebs < 0) {
+ err = ubi_wl_flush(ubi, vol_id, UBI_ALL);
+ if (err)
+ goto out_acc;
+ }
+
+ /* Change volume table record */
+ vtbl_rec = ubi->vtbl[vol_id];
+ vtbl_rec.reserved_pebs = cpu_to_be32(reserved_pebs);
+ err = ubi_change_vtbl_record(ubi, vol_id, &vtbl_rec);
+ if (err)
+ goto out_acc;
+
vol->reserved_pebs = reserved_pebs;
if (vol->vol_type == UBI_DYNAMIC_VOLUME) {
vol->used_ebs = reserved_pebs;
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:00 +0200 |
| Subject | [PATCH 3.10 179/180] stb6100: fix buffer length check in stb6100_write_reg_range() |
| Message-ID | <s8Dkg-2ft-79@gated-at.bofh.it> |
| In reply to | #1467049 |
From: Alexander Shiyan <shc_work@mail.ru>
commit 7e6bd12fb77b0067df13fb3ba3fadbdff2945396 upstream.
We are checking sizeof() the wrong variable!
Signed-off-by: Alexander Shiyan <shc_work@mail.ru>
Signed-off-by: Michael Krufky <mkrufky@linuxtv.org>
Signed-off-by: Mauro Carvalho Chehab <m.chehab@samsung.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/media/dvb-frontends/stb6100.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/media/dvb-frontends/stb6100.c b/drivers/media/dvb-frontends/stb6100.c
index cea175d..4ef8a5c 100644
--- a/drivers/media/dvb-frontends/stb6100.c
+++ b/drivers/media/dvb-frontends/stb6100.c
@@ -193,7 +193,7 @@ static int stb6100_write_reg_range(struct stb6100_state *state, u8 buf[], int st
.len = len + 1
};
- if (1 + len > sizeof(buf)) {
+ if (1 + len > sizeof(cmdbuf)) {
printk(KERN_WARNING
"%s: i2c wr: len=%d is too big!\n",
KBUILD_MODNAME, len);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:00 +0200 |
| Subject | [PATCH 3.10 089/180] dma-debug: avoid spinlock recursion when disabling dma-debug |
| Message-ID | <s8Dkg-2ft-85@gated-at.bofh.it> |
| In reply to | #1467049 |
From: Ville Syrjälä <ville.syrjala@linux.intel.com>
commit 3017cd63f26fc655d56875aaf497153ba60e9edf upstream.
With netconsole (at least) the pr_err("... disablingn") call can
recurse back into the dma-debug code, where it'll try to grab
free_entries_lock again. Avoid the problem by doing the printk after
dropping the lock.
Link: http://lkml.kernel.org/r/1463678421-18683-1-git-send-email-ville.syrjala@linux.intel.com
Signed-off-by: Ville Syrjälä <ville.syrjala@linux.intel.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
lib/dma-debug.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/lib/dma-debug.c b/lib/dma-debug.c
index eb43517b..c32437f 100644
--- a/lib/dma-debug.c
+++ b/lib/dma-debug.c
@@ -445,9 +445,9 @@ static struct dma_debug_entry *dma_entry_alloc(void)
spin_lock_irqsave(&free_entries_lock, flags);
if (list_empty(&free_entries)) {
- pr_err("DMA-API: debugging out of memory - disabling\n");
global_disable = true;
spin_unlock_irqrestore(&free_entries_lock, flags);
+ pr_err("DMA-API: debugging out of memory - disabling\n");
return NULL;
}
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:00 +0200 |
| Subject | [PATCH 3.10 139/180] s390/seccomp: fix error return for filtered system calls |
| Message-ID | <s8Dkg-2ft-81@gated-at.bofh.it> |
| In reply to | #1467049 |
From: Jan Willeke <willeke@de.ibm.com>
commit dc295880c6752076f8b94ba3885d0bfff09e3e82 upstream.
The syscall_set_return_value function of s390 negates the error argument
before storing the value to the return register gpr2. This is incorrect,
the seccomp code already passes the negative error value.
Store the unmodified error value to gpr2.
Signed-off-by: Jan Willeke <willeke@de.ibm.com>
Signed-off-by: Martin Schwidefsky <schwidefsky@de.ibm.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
arch/s390/include/asm/syscall.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/s390/include/asm/syscall.h b/arch/s390/include/asm/syscall.h
index cd29d2f..749313b 100644
--- a/arch/s390/include/asm/syscall.h
+++ b/arch/s390/include/asm/syscall.h
@@ -54,7 +54,7 @@ static inline void syscall_set_return_value(struct task_struct *task,
struct pt_regs *regs,
int error, long val)
{
- regs->gprs[2] = error ? -error : val;
+ regs->gprs[2] = error ? error : val;
}
static inline void syscall_get_arguments(struct task_struct *task,
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:00 +0200 |
| Subject | [PATCH 3.10 103/180] crypto: scatterwalk - Fix test in scatterwalk_done |
| Message-ID | <s8Dkg-2ft-87@gated-at.bofh.it> |
| In reply to | #1467049 |
From: Herbert Xu <herbert@gondor.apana.org.au>
commit 5f070e81bee35f1b7bd1477bb223a873ff657803 upstream.
When there is more data to be processed, the current test in
scatterwalk_done may prevent us from calling pagedone even when
we should.
In particular, if we're on an SG entry spanning multiple pages
where the last page is not a full page, we will incorrectly skip
calling pagedone on the second last page.
This patch fixes this by adding a separate test for whether we've
reached the end of a page.
Cc: stable@vger.kernel.org
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
crypto/scatterwalk.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/crypto/scatterwalk.c b/crypto/scatterwalk.c
index 7281b8a..79cbbbf 100644
--- a/crypto/scatterwalk.c
+++ b/crypto/scatterwalk.c
@@ -68,7 +68,8 @@ static void scatterwalk_pagedone(struct scatter_walk *walk, int out,
void scatterwalk_done(struct scatter_walk *walk, int out, int more)
{
- if (!(scatterwalk_pagelen(walk) & (PAGE_SIZE - 1)) || !more)
+ if (!more || walk->offset >= walk->sg->offset + walk->sg->length ||
+ !(walk->offset & (PAGE_SIZE - 1)))
scatterwalk_pagedone(walk, out, more);
}
EXPORT_SYMBOL_GPL(scatterwalk_done);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:00 +0200 |
| Subject | [PATCH 3.10 147/180] mmc: block: fix packed command header endianness |
| Message-ID | <s8Dkg-2ft-89@gated-at.bofh.it> |
| In reply to | #1467049 |
From: Taras Kondratiuk <takondra@cisco.com>
commit f68381a70bb2b26c31b13fdaf67c778f92fd32b4 upstream.
The code that fills packed command header assumes that CPU runs in
little-endian mode. Hence the header is malformed in big-endian mode
and causes MMC data transfer errors:
[ 563.200828] mmcblk0: error -110 transferring data, sector 2048, nr 8, cmd response 0x900, card status 0xc40
[ 563.219647] mmcblk0: packed cmd failed, nr 2, sectors 16, failure index: -1
Convert header data to LE.
Signed-off-by: Taras Kondratiuk <takondra@cisco.com>
Fixes: ce39f9d17c14 ("mmc: support packed write command for eMMC4.5 devices")
Cc: <stable@vger.kernel.org>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/mmc/card/block.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/drivers/mmc/card/block.c b/drivers/mmc/card/block.c
index c6bf235..a2863b7 100644
--- a/drivers/mmc/card/block.c
+++ b/drivers/mmc/card/block.c
@@ -1582,8 +1582,8 @@ static void mmc_blk_packed_hdr_wrq_prep(struct mmc_queue_req *mqrq,
packed_cmd_hdr = packed->cmd_hdr;
memset(packed_cmd_hdr, 0, sizeof(packed->cmd_hdr));
- packed_cmd_hdr[0] = (packed->nr_entries << 16) |
- (PACKED_CMD_WR << 8) | PACKED_CMD_VER;
+ packed_cmd_hdr[0] = cpu_to_le32((packed->nr_entries << 16) |
+ (PACKED_CMD_WR << 8) | PACKED_CMD_VER);
hdr_blocks = mmc_large_sector(card) ? 8 : 1;
/*
@@ -1597,14 +1597,14 @@ static void mmc_blk_packed_hdr_wrq_prep(struct mmc_queue_req *mqrq,
((brq->data.blocks * brq->data.blksz) >=
card->ext_csd.data_tag_unit_size);
/* Argument of CMD23 */
- packed_cmd_hdr[(i * 2)] =
+ packed_cmd_hdr[(i * 2)] = cpu_to_le32(
(do_rel_wr ? MMC_CMD23_ARG_REL_WR : 0) |
(do_data_tag ? MMC_CMD23_ARG_TAG_REQ : 0) |
- blk_rq_sectors(prq);
+ blk_rq_sectors(prq));
/* Argument of CMD18 or CMD25 */
- packed_cmd_hdr[((i * 2)) + 1] =
+ packed_cmd_hdr[((i * 2)) + 1] = cpu_to_le32(
mmc_card_blockaddr(card) ?
- blk_rq_pos(prq) : blk_rq_pos(prq) << 9;
+ blk_rq_pos(prq) : blk_rq_pos(prq) << 9);
packed->blocks += blk_rq_sectors(prq);
i++;
}
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:10 +0200 |
| Subject | [PATCH 3.10 102/180] crypto: gcm - Filter out async ghash if necessary |
| Message-ID | <s8DtT-2yc-1@gated-at.bofh.it> |
| In reply to | #1467049 |
From: Herbert Xu <herbert@gondor.apana.org.au> commit b30bdfa86431afbafe15284a3ad5ac19b49b88e3 upstream. As it is if you ask for a sync gcm you may actually end up with an async one because it does not filter out async implementations of ghash. This patch fixes this by adding the necessary filter when looking for ghash. Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by: Willy Tarreau <w@1wt.eu> --- crypto/gcm.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/crypto/gcm.c b/crypto/gcm.c index cd97cdd..451e420 100644 --- a/crypto/gcm.c +++ b/crypto/gcm.c @@ -716,7 +716,9 @@ static struct crypto_instance *crypto_gcm_alloc_common(struct rtattr **tb, ghash_alg = crypto_find_alg(ghash_name, &crypto_ahash_type, CRYPTO_ALG_TYPE_HASH, - CRYPTO_ALG_TYPE_AHASH_MASK); + CRYPTO_ALG_TYPE_AHASH_MASK | + crypto_requires_sync(algt->type, + algt->mask)); if (IS_ERR(ghash_alg)) return ERR_CAST(ghash_alg); -- 2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:10 +0200 |
| Subject | [PATCH 3.10 142/180] xen/pciback: Fix conf_space read/write overlap check. |
| Message-ID | <s8DtU-2yc-13@gated-at.bofh.it> |
| In reply to | #1467049 |
From: Andrey Grodzovsky <andrey2805@gmail.com>
commit 02ef871ecac290919ea0c783d05da7eedeffc10e upstream.
Current overlap check is evaluating to false a case where a filter
field is fully contained (proper subset) of a r/w request. This
change applies classical overlap check instead to include all the
scenarios.
More specifically, for (Hilscher GmbH CIFX 50E-DP(M/S)) device driver
the logic is such that the entire confspace is read and written in 4
byte chunks. In this case as an example, CACHE_LINE_SIZE,
LATENCY_TIMER and PCI_BIST are arriving together in one call to
xen_pcibk_config_write() with offset == 0xc and size == 4. With the
exsisting overlap check the LATENCY_TIMER field (offset == 0xd, length
== 1) is fully contained in the write request and hence is excluded
from write, which is incorrect.
Signed-off-by: Andrey Grodzovsky <andrey2805@gmail.com>
Reviewed-by: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Reviewed-by: Jan Beulich <JBeulich@suse.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: David Vrabel <david.vrabel@citrix.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/xen/xen-pciback/conf_space.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/drivers/xen/xen-pciback/conf_space.c b/drivers/xen/xen-pciback/conf_space.c
index 75fe3d4..ba3fac8 100644
--- a/drivers/xen/xen-pciback/conf_space.c
+++ b/drivers/xen/xen-pciback/conf_space.c
@@ -183,8 +183,7 @@ int xen_pcibk_config_read(struct pci_dev *dev, int offset, int size,
field_start = OFFSET(cfg_entry);
field_end = OFFSET(cfg_entry) + field->size;
- if ((req_start >= field_start && req_start < field_end)
- || (req_end > field_start && req_end <= field_end)) {
+ if (req_end > field_start && field_end > req_start) {
err = conf_space_read(dev, cfg_entry, field_start,
&tmp_val);
if (err)
@@ -230,8 +229,7 @@ int xen_pcibk_config_write(struct pci_dev *dev, int offset, int size, u32 value)
field_start = OFFSET(cfg_entry);
field_end = OFFSET(cfg_entry) + field->size;
- if ((req_start >= field_start && req_start < field_end)
- || (req_end > field_start && req_end <= field_end)) {
+ if (req_end > field_start && field_end > req_start) {
tmp_val = 0;
err = xen_pcibk_config_read(dev, field_start,
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:10 +0200 |
| Subject | [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on error |
| Message-ID | <s8DtU-2yc-19@gated-at.bofh.it> |
| In reply to | #1467049 |
From: Dave Chinner <dchinner@redhat.com>
commit b1438f477934f5a4d5a44df26f3079a7575d5946 upstream.
When a failure due to an inode buffer occurs, the error handling
fails to abort the inode writeback correctly. This can result in the
inode being reclaimed whilst still in the AIL, leading to
use-after-free situations as well as filesystems that cannot be
unmounted as the inode log items left in the AIL never get removed.
Fix this by ensuring fatal errors from xfs_imap_to_bp() result in
the inode flush being aborted correctly.
Reported-by: Shyam Kaushik <shyam@zadarastorage.com>
Diagnosed-by: Shyam Kaushik <shyam@zadarastorage.com>
Tested-by: Shyam Kaushik <shyam@zadarastorage.com>
Signed-off-by: Dave Chinner <dchinner@redhat.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Dave Chinner <david@fromorbit.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
fs/xfs/xfs_inode.c | 17 +++++++++++++----
1 file changed, 13 insertions(+), 4 deletions(-)
diff --git a/fs/xfs/xfs_inode.c b/fs/xfs/xfs_inode.c
index f010ab45..1f9c806 100644
--- a/fs/xfs/xfs_inode.c
+++ b/fs/xfs/xfs_inode.c
@@ -2726,7 +2726,7 @@ xfs_iflush(
struct xfs_buf **bpp)
{
struct xfs_mount *mp = ip->i_mount;
- struct xfs_buf *bp;
+ struct xfs_buf *bp = NULL;
struct xfs_dinode *dip;
int error;
@@ -2768,14 +2768,22 @@ xfs_iflush(
}
/*
- * Get the buffer containing the on-disk inode.
+ * Get the buffer containing the on-disk inode. We are doing a try-lock
+ * operation here, so we may get an EAGAIN error. In that case, we
+ * simply want to return with the inode still dirty.
+ *
+ * If we get any other error, we effectively have a corruption situation
+ * and we cannot flush the inode, so we treat it the same as failing
+ * xfs_iflush_int().
*/
error = xfs_imap_to_bp(mp, NULL, &ip->i_imap, &dip, &bp, XBF_TRYLOCK,
0);
- if (error || !bp) {
+ if (error == -EAGAIN) {
xfs_ifunlock(ip);
return error;
}
+ if (error)
+ goto corrupt_out;
/*
* First flush out the inode that xfs_iflush was called with.
@@ -2803,7 +2811,8 @@ xfs_iflush(
return 0;
corrupt_out:
- xfs_buf_relse(bp);
+ if (bp)
+ xfs_buf_relse(bp);
xfs_force_shutdown(mp, SHUTDOWN_CORRUPT_INCORE);
cluster_corrupt_out:
error = XFS_ERROR(EFSCORRUPTED);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Dave Chinner <david@fromorbit.com> |
|---|---|
| Date | 2016-08-22 06:30 +0200 |
| Subject | Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on error |
| Message-ID | <s8P22-1r7-11@gated-at.bofh.it> |
| In reply to | #1467137 |
On Sun, Aug 21, 2016 at 05:30:20PM +0200, Willy Tarreau wrote:
> From: Dave Chinner <dchinner@redhat.com>
>
> commit b1438f477934f5a4d5a44df26f3079a7575d5946 upstream.
>
> When a failure due to an inode buffer occurs, the error handling
> fails to abort the inode writeback correctly. This can result in the
> inode being reclaimed whilst still in the AIL, leading to
> use-after-free situations as well as filesystems that cannot be
> unmounted as the inode log items left in the AIL never get removed.
>
> Fix this by ensuring fatal errors from xfs_imap_to_bp() result in
> the inode flush being aborted correctly.
>
> Reported-by: Shyam Kaushik <shyam@zadarastorage.com>
> Diagnosed-by: Shyam Kaushik <shyam@zadarastorage.com>
> Tested-by: Shyam Kaushik <shyam@zadarastorage.com>
> Signed-off-by: Dave Chinner <dchinner@redhat.com>
> Reviewed-by: Christoph Hellwig <hch@lst.de>
> Signed-off-by: Dave Chinner <david@fromorbit.com>
> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
> Signed-off-by: Willy Tarreau <w@1wt.eu>
....
> @@ -2768,14 +2768,22 @@ xfs_iflush(
> }
>
> /*
> - * Get the buffer containing the on-disk inode.
> + * Get the buffer containing the on-disk inode. We are doing a try-lock
> + * operation here, so we may get an EAGAIN error. In that case, we
> + * simply want to return with the inode still dirty.
> + *
> + * If we get any other error, we effectively have a corruption situation
> + * and we cannot flush the inode, so we treat it the same as failing
> + * xfs_iflush_int().
> */
> error = xfs_imap_to_bp(mp, NULL, &ip->i_imap, &dip, &bp, XBF_TRYLOCK,
> 0);
> - if (error || !bp) {
> + if (error == -EAGAIN) {
Wrong. Errors changed sign in XFS in 3.17.
/rant
So, after just having to point this out (again!) for a different
stable kernel patchset review, and this specific problem causing
user-reported stable kernel regression and filesystem corruption
*months ago*. That resulted in discussion and new stable commits to
fix the problem. So now I'm left to wonder about the process of
stable kernels.
AFAICT, stable kernel maintainers are not watching what happens with
other stable kernels, nor are they talking to other stable kernel
maintainers. I should not have to tell every single stable kernel
maintainer that a specific patch needs to be changed after it's
already been reported broken, triaged and fixed in other stable
kernels. You've all got a record that the patch needs to be included
in a stable kernel, but nobody is seems to notice when it comes to
fixing problems with a stable patch even when that all happens on
stable@vger.kernel.org.
Seriously, guys, pick up your act a bit and start talking between
yourselvesi and tracking regressions and fixes so the burden of
catching known reported and fixed problems with backports doesn't
rely on the upstream developers noticing the problem when hundreds
of patches for random stable kernels go past on lkml every week...
-Dave.
--
Dave Chinner
david@fromorbit.com
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-22 07:20 +0200 |
| Subject | Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on error |
| Message-ID | <s8POq-1XD-5@gated-at.bofh.it> |
| In reply to | #1467349 |
Hi Dave,
On Mon, Aug 22, 2016 at 02:21:08PM +1000, Dave Chinner wrote:
> > - if (error || !bp) {
> > + if (error == -EAGAIN) {
>
> Wrong. Errors changed sign in XFS in 3.17.
Ah my bad, sorry for this.
> /rant
>
> So, after just having to point this out (again!) for a different
> stable kernel patchset review, and this specific problem causing
> user-reported stable kernel regression and filesystem corruption
> *months ago*. That resulted in discussion and new stable commits to
> fix the problem. So now I'm left to wonder about the process of
> stable kernels.
Yep I remember this discussion now, I'm sorry.
> AFAICT, stable kernel maintainers are not watching what happens with
> other stable kernels, nor are they talking to other stable kernel
> maintainers. I should not have to tell every single stable kernel
> maintainer that a specific patch needs to be changed after it's
> already been reported broken, triaged and fixed in other stable
> kernels. You've all got a record that the patch needs to be included
> in a stable kernel, but nobody is seems to notice when it comes to
> fixing problems with a stable patch even when that all happens on
> stable@vger.kernel.org.
>
> Seriously, guys, pick up your act a bit and start talking between
> yourselvesi and tracking regressions and fixes so the burden of
> catching known reported and fixed problems with backports doesn't
> rely on the upstream developers noticing the problem when hundreds
> of patches for random stable kernels go past on lkml every week...
We definitely do exchange quite a bit and I pick patches from 3.14 for
3.10, but sometimes I can simply pick the original one for various
reasons (eg: I if had queued its upstream ID earlier). That's also why
the review process helps. I'm sincerely sorry that I failed on this one
and that you had to deal with it again, I'm going to fix it now.
Thanks,
Willy
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-22 07:30 +0200 |
| Subject | Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on error |
| Message-ID | <s8PY6-22v-19@gated-at.bofh.it> |
| In reply to | #1467371 |
On Mon, Aug 22, 2016 at 07:18:26AM +0200, Willy Tarreau wrote: > > Seriously, guys, pick up your act a bit and start talking between > > yourselvesi and tracking regressions and fixes so the burden of > > catching known reported and fixed problems with backports doesn't > > rely on the upstream developers noticing the problem when hundreds > > of patches for random stable kernels go past on lkml every week... > > We definitely do exchange quite a bit and I pick patches from 3.14 for > 3.10, but sometimes I can simply pick the original one for various > reasons (eg: I if had queued its upstream ID earlier). That's also why > the review process helps. I'm sincerely sorry that I failed on this one > and that you had to deal with it again, I'm going to fix it now. I've just checked, and this time I correctly picked the patches from 3.14, so much that I have the faulty one (this one) and its fix (patch 100/180). Admittedly I can merge them together so that if someone wants to pick it alone they're not left with a broken patch. Willy
[toc] | [prev] | [next] | [standalone]
| From | Dave Chinner <dchinner@redhat.com> |
|---|---|
| Date | 2016-08-22 13:00 +0200 |
| Subject | Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on error |
| Message-ID | <s8V7r-5dF-3@gated-at.bofh.it> |
| In reply to | #1467371 |
On Mon, Aug 22, 2016 at 07:18:26AM +0200, Willy Tarreau wrote:
> Hi Dave,
>
> On Mon, Aug 22, 2016 at 02:21:08PM +1000, Dave Chinner wrote:
> > > - if (error || !bp) {
> > > + if (error == -EAGAIN) {
> >
> > Wrong. Errors changed sign in XFS in 3.17.
>
> Ah my bad, sorry for this.
>
> > /rant
> >
> > So, after just having to point this out (again!) for a different
> > stable kernel patchset review, and this specific problem causing
> > user-reported stable kernel regression and filesystem corruption
> > *months ago*. That resulted in discussion and new stable commits to
> > fix the problem. So now I'm left to wonder about the process of
> > stable kernels.
>
> Yep I remember this discussion now, I'm sorry.
>
> > AFAICT, stable kernel maintainers are not watching what happens with
> > other stable kernels, nor are they talking to other stable kernel
> > maintainers. I should not have to tell every single stable kernel
> > maintainer that a specific patch needs to be changed after it's
> > already been reported broken, triaged and fixed in other stable
> > kernels. You've all got a record that the patch needs to be included
> > in a stable kernel, but nobody is seems to notice when it comes to
> > fixing problems with a stable patch even when that all happens on
> > stable@vger.kernel.org.
> >
> > Seriously, guys, pick up your act a bit and start talking between
> > yourselvesi and tracking regressions and fixes so the burden of
> > catching known reported and fixed problems with backports doesn't
> > rely on the upstream developers noticing the problem when hundreds
> > of patches for random stable kernels go past on lkml every week...
>
> We definitely do exchange quite a bit and I pick patches from 3.14 for
> 3.10, but sometimes I can simply pick the original one for various
> reasons (eg: I if had queued its upstream ID earlier). That's also why
> the review process helps. I'm sincerely sorry that I failed on this one
> and that you had to deal with it again, I'm going to fix it now.
Ok, I didn't notice that the fix from 3.14 was further down the
queue. I put a procmail filter in to catch this patch on lkml
so i didn't see it in the context of the entire series (way too much
traffic on lkml to keep up with it). So I probably pulled the
trigger a little early.
I agreed that it would be best to combine the two patches so there
isn't a bisection point that could result in corruptions...
Cheers,
Dave.
--
Dave Chinner
dchinner@redhat.com
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-22 13:10 +0200 |
| Subject | Re: [PATCH 3.10 090/180] xfs: xfs_iflush_cluster fails to abort on error |
| Message-ID | <s8Vh7-5vY-3@gated-at.bofh.it> |
| In reply to | #1467545 |
On Mon, Aug 22, 2016 at 08:55:37PM +1000, Dave Chinner wrote: > Ok, I didn't notice that the fix from 3.14 was further down the > queue. I put a procmail filter in to catch this patch on lkml > so i didn't see it in the context of the entire series (way too much > traffic on lkml to keep up with it). So I probably pulled the > trigger a little early. No offence taken, don't worry. I prefer to see maintainers fight for reliability than not care :-) > I agreed that it would be best to combine the two patches so there > isn't a bisection point that could result in corruptions... yes, I've re-merged them already. Thanks, Willy
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:10 +0200 |
| Subject | [PATCH 3.10 003/180] netfilter: x_tables: validate e->target_offset early |
| Message-ID | <s8DtU-2yc-9@gated-at.bofh.it> |
| In reply to | #1467049 |
From: Florian Westphal <fw@strlen.de>
commit bdf533de6968e9686df777dc178486f600c6e617 upstream.
We should check that e->target_offset is sane before
mark_source_chains gets called since it will fetch the target entry
for loop detection.
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
net/ipv4/netfilter/arp_tables.c | 17 ++++++++---------
net/ipv4/netfilter/ip_tables.c | 17 ++++++++---------
net/ipv6/netfilter/ip6_tables.c | 17 ++++++++---------
3 files changed, 24 insertions(+), 27 deletions(-)
diff --git a/net/ipv4/netfilter/arp_tables.c b/net/ipv4/netfilter/arp_tables.c
index c8abe31..269759d 100644
--- a/net/ipv4/netfilter/arp_tables.c
+++ b/net/ipv4/netfilter/arp_tables.c
@@ -465,14 +465,12 @@ static int mark_source_chains(const struct xt_table_info *newinfo,
return 1;
}
-static inline int check_entry(const struct arpt_entry *e, const char *name)
+static inline int check_entry(const struct arpt_entry *e)
{
const struct xt_entry_target *t;
- if (!arp_checkentry(&e->arp)) {
- duprintf("arp_tables: arp check failed %p %s.\n", e, name);
+ if (!arp_checkentry(&e->arp))
return -EINVAL;
- }
if (e->target_offset + sizeof(struct xt_entry_target) > e->next_offset)
return -EINVAL;
@@ -513,10 +511,6 @@ find_check_entry(struct arpt_entry *e, const char *name, unsigned int size)
struct xt_target *target;
int ret;
- ret = check_entry(e, name);
- if (ret)
- return ret;
-
t = arpt_get_target(e);
target = xt_request_find_target(NFPROTO_ARP, t->u.user.name,
t->u.user.revision);
@@ -561,6 +555,7 @@ static inline int check_entry_size_and_hooks(struct arpt_entry *e,
unsigned int valid_hooks)
{
unsigned int h;
+ int err;
if ((unsigned long)e % __alignof__(struct arpt_entry) != 0 ||
(unsigned char *)e + sizeof(struct arpt_entry) >= limit) {
@@ -575,6 +570,10 @@ static inline int check_entry_size_and_hooks(struct arpt_entry *e,
return -EINVAL;
}
+ err = check_entry(e);
+ if (err)
+ return err;
+
/* Check hooks & underflows */
for (h = 0; h < NF_ARP_NUMHOOKS; h++) {
if (!(valid_hooks & (1 << h)))
@@ -1232,7 +1231,7 @@ check_compat_entry_size_and_hooks(struct compat_arpt_entry *e,
}
/* For purposes of check_entry casting the compat entry is fine */
- ret = check_entry((struct arpt_entry *)e, name);
+ ret = check_entry((struct arpt_entry *)e);
if (ret)
return ret;
diff --git a/net/ipv4/netfilter/ip_tables.c b/net/ipv4/netfilter/ip_tables.c
index 651c107..5ca478f 100644
--- a/net/ipv4/netfilter/ip_tables.c
+++ b/net/ipv4/netfilter/ip_tables.c
@@ -560,14 +560,12 @@ static void cleanup_match(struct xt_entry_match *m, struct net *net)
}
static int
-check_entry(const struct ipt_entry *e, const char *name)
+check_entry(const struct ipt_entry *e)
{
const struct xt_entry_target *t;
- if (!ip_checkentry(&e->ip)) {
- duprintf("ip check failed %p %s.\n", e, name);
+ if (!ip_checkentry(&e->ip))
return -EINVAL;
- }
if (e->target_offset + sizeof(struct xt_entry_target) >
e->next_offset)
@@ -657,10 +655,6 @@ find_check_entry(struct ipt_entry *e, struct net *net, const char *name,
struct xt_mtchk_param mtpar;
struct xt_entry_match *ematch;
- ret = check_entry(e, name);
- if (ret)
- return ret;
-
j = 0;
mtpar.net = net;
mtpar.table = name;
@@ -724,6 +718,7 @@ check_entry_size_and_hooks(struct ipt_entry *e,
unsigned int valid_hooks)
{
unsigned int h;
+ int err;
if ((unsigned long)e % __alignof__(struct ipt_entry) != 0 ||
(unsigned char *)e + sizeof(struct ipt_entry) >= limit) {
@@ -738,6 +733,10 @@ check_entry_size_and_hooks(struct ipt_entry *e,
return -EINVAL;
}
+ err = check_entry(e);
+ if (err)
+ return err;
+
/* Check hooks & underflows */
for (h = 0; h < NF_INET_NUMHOOKS; h++) {
if (!(valid_hooks & (1 << h)))
@@ -1498,7 +1497,7 @@ check_compat_entry_size_and_hooks(struct compat_ipt_entry *e,
}
/* For purposes of check_entry casting the compat entry is fine */
- ret = check_entry((struct ipt_entry *)e, name);
+ ret = check_entry((struct ipt_entry *)e);
if (ret)
return ret;
diff --git a/net/ipv6/netfilter/ip6_tables.c b/net/ipv6/netfilter/ip6_tables.c
index 89a4e4d..597f539 100644
--- a/net/ipv6/netfilter/ip6_tables.c
+++ b/net/ipv6/netfilter/ip6_tables.c
@@ -570,14 +570,12 @@ static void cleanup_match(struct xt_entry_match *m, struct net *net)
}
static int
-check_entry(const struct ip6t_entry *e, const char *name)
+check_entry(const struct ip6t_entry *e)
{
const struct xt_entry_target *t;
- if (!ip6_checkentry(&e->ipv6)) {
- duprintf("ip_tables: ip check failed %p %s.\n", e, name);
+ if (!ip6_checkentry(&e->ipv6))
return -EINVAL;
- }
if (e->target_offset + sizeof(struct xt_entry_target) >
e->next_offset)
@@ -668,10 +666,6 @@ find_check_entry(struct ip6t_entry *e, struct net *net, const char *name,
struct xt_mtchk_param mtpar;
struct xt_entry_match *ematch;
- ret = check_entry(e, name);
- if (ret)
- return ret;
-
j = 0;
mtpar.net = net;
mtpar.table = name;
@@ -735,6 +729,7 @@ check_entry_size_and_hooks(struct ip6t_entry *e,
unsigned int valid_hooks)
{
unsigned int h;
+ int err;
if ((unsigned long)e % __alignof__(struct ip6t_entry) != 0 ||
(unsigned char *)e + sizeof(struct ip6t_entry) >= limit) {
@@ -749,6 +744,10 @@ check_entry_size_and_hooks(struct ip6t_entry *e,
return -EINVAL;
}
+ err = check_entry(e);
+ if (err)
+ return err;
+
/* Check hooks & underflows */
for (h = 0; h < NF_INET_NUMHOOKS; h++) {
if (!(valid_hooks & (1 << h)))
@@ -1510,7 +1509,7 @@ check_compat_entry_size_and_hooks(struct compat_ip6t_entry *e,
}
/* For purposes of check_entry casting the compat entry is fine */
- ret = check_entry((struct ip6t_entry *)e, name);
+ ret = check_entry((struct ip6t_entry *)e);
if (ret)
return ret;
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:10 +0200 |
| Subject | [PATCH 3.10 025/180] perf/x86: Fix undefined shift on 32-bit kernels |
| Message-ID | <s8DtU-2yc-21@gated-at.bofh.it> |
| In reply to | #1467049 |
From: Andrey Ryabinin <aryabinin@virtuozzo.com>
commit 6d6f2833bfbf296101f9f085e10488aef2601ba5 upstream.
Jim reported:
UBSAN: Undefined behaviour in arch/x86/events/intel/core.c:3708:12
shift exponent 35 is too large for 32-bit type 'long unsigned int'
The use of 'unsigned long' type obviously is not correct here, make it
'unsigned long long' instead.
Reported-by: Jim Cromie <jim.cromie@gmail.com>
Signed-off-by: Andrey Ryabinin <aryabinin@virtuozzo.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: <stable@vger.kernel.org>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Arnaldo Carvalho de Melo <acme@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Imre Palik <imrep@amazon.de>
Cc: Jiri Olsa <jolsa@redhat.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Stephane Eranian <eranian@google.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Vince Weaver <vincent.weaver@maine.edu>
Fixes: 2c33645d366d ("perf/x86: Honor the architectural performance monitoring version")
Link: http://lkml.kernel.org/r/1462974711-10037-1-git-send-email-aryabinin@virtuozzo.com
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: Kevin Christopher <kevinc@vmware.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
arch/x86/kernel/cpu/perf_event_intel.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/x86/kernel/cpu/perf_event_intel.c b/arch/x86/kernel/cpu/perf_event_intel.c
index bfc6bb5..a181544 100644
--- a/arch/x86/kernel/cpu/perf_event_intel.c
+++ b/arch/x86/kernel/cpu/perf_event_intel.c
@@ -2248,7 +2248,7 @@ __init int intel_pmu_init(void)
}
c->idxmsk64 &=
- ~(~0UL << (INTEL_PMC_IDX_FIXED + x86_pmu.num_counters_fixed));
+ ~(~0ULL << (INTEL_PMC_IDX_FIXED + x86_pmu.num_counters_fixed));
c->weight = hweight64(c->idxmsk64);
}
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:10 +0200 |
| Subject | [PATCH 3.10 164/180] cifs: Check for existing directory when opening file with O_CREAT |
| Message-ID | <s8DtT-2yc-3@gated-at.bofh.it> |
| In reply to | #1467049 |
From: Sachin Prabhu <sprabhu@redhat.com>
commit 8d9535b6efd86e6c07da59f97e68f44efb7fe080 upstream.
When opening a file with O_CREAT flag, check to see if the file opened
is an existing directory.
This prevents the directory from being opened which subsequently causes
a crash when the close function for directories cifs_closedir() is called
which frees up the file->private_data memory while the file is still
listed on the open file list for the tcon.
Signed-off-by: Sachin Prabhu <sprabhu@redhat.com>
Signed-off-by: Steve French <smfrench@gmail.com>
CC: Stable <stable@vger.kernel.org>
Reported-by: Xiaoli Feng <xifeng@redhat.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
fs/cifs/dir.c | 24 +++++++++++++++++++++---
1 file changed, 21 insertions(+), 3 deletions(-)
diff --git a/fs/cifs/dir.c b/fs/cifs/dir.c
index 0c2425b..a998c92 100644
--- a/fs/cifs/dir.c
+++ b/fs/cifs/dir.c
@@ -227,6 +227,13 @@ cifs_do_create(struct inode *inode, struct dentry *direntry, unsigned int xid,
goto cifs_create_get_file_info;
}
+ if (S_ISDIR(newinode->i_mode)) {
+ CIFSSMBClose(xid, tcon, fid->netfid);
+ iput(newinode);
+ rc = -EISDIR;
+ goto out;
+ }
+
if (!S_ISREG(newinode->i_mode)) {
/*
* The server may allow us to open things like
@@ -391,10 +398,14 @@ cifs_create_set_dentry:
if (rc != 0) {
cifs_dbg(FYI, "Create worked, get_inode_info failed rc = %d\n",
rc);
- if (server->ops->close)
- server->ops->close(xid, tcon, fid);
- goto out;
+ goto out_err;
}
+
+ if (S_ISDIR(newinode->i_mode)) {
+ rc = -EISDIR;
+ goto out_err;
+ }
+
d_drop(direntry);
d_add(direntry, newinode);
@@ -402,6 +413,13 @@ out:
kfree(buf);
kfree(full_path);
return rc;
+
+out_err:
+ if (server->ops->close)
+ server->ops->close(xid, tcon, fid);
+ if (newinode)
+ iput(newinode);
+ goto out;
}
int
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:10 +0200 |
| Subject | [PATCH 3.10 091/180] xfs: fix inode validity check in xfs_iflush_cluster |
| Message-ID | <s8DtU-2yc-7@gated-at.bofh.it> |
| In reply to | #1467049 |
From: Dave Chinner <dchinner@redhat.com>
commit 51b07f30a71c27405259a0248206ed4e22adbee2 upstream.
Some careless idiot(*) wrote crap code in commit 1a3e8f3 ("xfs:
convert inode cache lookups to use RCU locking") back in late 2010,
and so xfs_iflush_cluster checks the wrong inode for whether it is
still valid under RCU protection. Fix it to lock and check the
correct inode.
(*) Careless-idiot: Dave Chinner <dchinner@redhat.com>
cc: <stable@vger.kernel.org> # 3.10.x-
Discovered-by: Brain Foster <bfoster@redhat.com>
Signed-off-by: Dave Chinner <dchinner@redhat.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Dave Chinner <david@fromorbit.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
fs/xfs/xfs_inode.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/fs/xfs/xfs_inode.c b/fs/xfs/xfs_inode.c
index 1f9c806..52faf49 100644
--- a/fs/xfs/xfs_inode.c
+++ b/fs/xfs/xfs_inode.c
@@ -2604,13 +2604,13 @@ xfs_iflush_cluster(
* We need to check under the i_flags_lock for a valid inode
* here. Skip it if it is not valid or the wrong inode.
*/
- spin_lock(&ip->i_flags_lock);
- if (!ip->i_ino ||
+ spin_lock(&iq->i_flags_lock);
+ if (!iq->i_ino ||
(XFS_INO_TO_AGINO(mp, iq->i_ino) & mask) != first_index) {
- spin_unlock(&ip->i_flags_lock);
+ spin_unlock(&iq->i_flags_lock);
continue;
}
- spin_unlock(&ip->i_flags_lock);
+ spin_unlock(&iq->i_flags_lock);
/*
* Do an un-protected check to see if the inode is dirty and
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2016-08-21 18:10 +0200 |
| Subject | [PATCH 3.10 038/180] pipe: limit the per-user amount of pages allocated in pipes |
| Message-ID | <s8DtU-2yc-11@gated-at.bofh.it> |
| In reply to | #1467049 |
commit 759c01142a5d0f364a462346168a56de28a80f52 upstream.
On no-so-small systems, it is possible for a single process to cause an
OOM condition by filling large pipes with data that are never read. A
typical process filling 4000 pipes with 1 MB of data will use 4 GB of
memory. On small systems it may be tricky to set the pipe max size to
prevent this from happening.
This patch makes it possible to enforce a per-user soft limit above
which new pipes will be limited to a single page, effectively limiting
them to 4 kB each, as well as a hard limit above which no new pipes may
be created for this user. This has the effect of protecting the system
against memory abuse without hurting other users, and still allowing
pipes to work correctly though with less data at once.
The limit are controlled by two new sysctls : pipe-user-pages-soft, and
pipe-user-pages-hard. Both may be disabled by setting them to zero. The
default soft limit allows the default number of FDs per process (1024)
to create pipes of the default size (64kB), thus reaching a limit of 64MB
before starting to create only smaller pipes. With 256 processes limited
to 1024 FDs each, this results in 1024*64kB + (256*1024 - 1024) * 4kB =
1084 MB of memory allocated for a user. The hard limit is disabled by
default to avoid breaking existing applications that make intensive use
of pipes (eg: for splicing).
CVE-2016-2847
Reported-by: socketpair@gmail.com
Reported-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Mitigates: CVE-2013-4312 (Linux 2.0+)
Suggested-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
Signed-off-by: Chas Williams <3chas3@gmail.com>
---
Documentation/sysctl/fs.txt | 23 ++++++++++++++++++++++
fs/pipe.c | 47 +++++++++++++++++++++++++++++++++++++++++++--
include/linux/pipe_fs_i.h | 4 ++++
include/linux/sched.h | 1 +
kernel/sysctl.c | 14 ++++++++++++++
5 files changed, 87 insertions(+), 2 deletions(-)
diff --git a/Documentation/sysctl/fs.txt b/Documentation/sysctl/fs.txt
index 88152f2..302b5ed 100644
--- a/Documentation/sysctl/fs.txt
+++ b/Documentation/sysctl/fs.txt
@@ -32,6 +32,8 @@ Currently, these files are in /proc/sys/fs:
- nr_open
- overflowuid
- overflowgid
+- pipe-user-pages-hard
+- pipe-user-pages-soft
- protected_hardlinks
- protected_symlinks
- suid_dumpable
@@ -159,6 +161,27 @@ The default is 65534.
==============================================================
+pipe-user-pages-hard:
+
+Maximum total number of pages a non-privileged user may allocate for pipes.
+Once this limit is reached, no new pipes may be allocated until usage goes
+below the limit again. When set to 0, no limit is applied, which is the default
+setting.
+
+==============================================================
+
+pipe-user-pages-soft:
+
+Maximum total number of pages a non-privileged user may allocate for pipes
+before the pipe size gets limited to a single page. Once this limit is reached,
+new pipes will be limited to a single page in size for this user in order to
+limit total memory usage, and trying to increase them using fcntl() will be
+denied until usage goes below the limit again. The default value allows to
+allocate up to 1024 pipes at their default size. When set to 0, no limit is
+applied.
+
+==============================================================
+
protected_hardlinks:
A long-standing class of security issues is the hardlink-based
diff --git a/fs/pipe.c b/fs/pipe.c
index 50267e6..c281867 100644
--- a/fs/pipe.c
+++ b/fs/pipe.c
@@ -39,6 +39,12 @@ unsigned int pipe_max_size = 1048576;
*/
unsigned int pipe_min_size = PAGE_SIZE;
+/* Maximum allocatable pages per user. Hard limit is unset by default, soft
+ * matches default values.
+ */
+unsigned long pipe_user_pages_hard;
+unsigned long pipe_user_pages_soft = PIPE_DEF_BUFFERS * INR_OPEN_CUR;
+
/*
* We use a start+len construction, which provides full use of the
* allocated memory.
@@ -794,20 +800,49 @@ pipe_fasync(int fd, struct file *filp, int on)
return retval;
}
+static void account_pipe_buffers(struct pipe_inode_info *pipe,
+ unsigned long old, unsigned long new)
+{
+ atomic_long_add(new - old, &pipe->user->pipe_bufs);
+}
+
+static bool too_many_pipe_buffers_soft(struct user_struct *user)
+{
+ return pipe_user_pages_soft &&
+ atomic_long_read(&user->pipe_bufs) >= pipe_user_pages_soft;
+}
+
+static bool too_many_pipe_buffers_hard(struct user_struct *user)
+{
+ return pipe_user_pages_hard &&
+ atomic_long_read(&user->pipe_bufs) >= pipe_user_pages_hard;
+}
+
struct pipe_inode_info *alloc_pipe_info(void)
{
struct pipe_inode_info *pipe;
pipe = kzalloc(sizeof(struct pipe_inode_info), GFP_KERNEL);
if (pipe) {
- pipe->bufs = kzalloc(sizeof(struct pipe_buffer) * PIPE_DEF_BUFFERS, GFP_KERNEL);
+ unsigned long pipe_bufs = PIPE_DEF_BUFFERS;
+ struct user_struct *user = get_current_user();
+
+ if (!too_many_pipe_buffers_hard(user)) {
+ if (too_many_pipe_buffers_soft(user))
+ pipe_bufs = 1;
+ pipe->bufs = kzalloc(sizeof(struct pipe_buffer) * pipe_bufs, GFP_KERNEL);
+ }
+
if (pipe->bufs) {
init_waitqueue_head(&pipe->wait);
pipe->r_counter = pipe->w_counter = 1;
- pipe->buffers = PIPE_DEF_BUFFERS;
+ pipe->buffers = pipe_bufs;
+ pipe->user = user;
+ account_pipe_buffers(pipe, 0, pipe_bufs);
mutex_init(&pipe->mutex);
return pipe;
}
+ free_uid(user);
kfree(pipe);
}
@@ -818,6 +853,8 @@ void free_pipe_info(struct pipe_inode_info *pipe)
{
int i;
+ account_pipe_buffers(pipe, pipe->buffers, 0);
+ free_uid(pipe->user);
for (i = 0; i < pipe->buffers; i++) {
struct pipe_buffer *buf = pipe->bufs + i;
if (buf->ops)
@@ -1208,6 +1245,7 @@ static long pipe_set_size(struct pipe_inode_info *pipe, unsigned long nr_pages)
memcpy(bufs + head, pipe->bufs, tail * sizeof(struct pipe_buffer));
}
+ account_pipe_buffers(pipe, pipe->buffers, nr_pages);
pipe->curbuf = 0;
kfree(pipe->bufs);
pipe->bufs = bufs;
@@ -1279,6 +1317,11 @@ long pipe_fcntl(struct file *file, unsigned int cmd, unsigned long arg)
if (!capable(CAP_SYS_RESOURCE) && size > pipe_max_size) {
ret = -EPERM;
goto out;
+ } else if ((too_many_pipe_buffers_hard(pipe->user) ||
+ too_many_pipe_buffers_soft(pipe->user)) &&
+ !capable(CAP_SYS_RESOURCE) && !capable(CAP_SYS_ADMIN)) {
+ ret = -EPERM;
+ goto out;
}
ret = pipe_set_size(pipe, nr_pages);
break;
diff --git a/include/linux/pipe_fs_i.h b/include/linux/pipe_fs_i.h
index ab57526..b3374f6 100644
--- a/include/linux/pipe_fs_i.h
+++ b/include/linux/pipe_fs_i.h
@@ -42,6 +42,7 @@ struct pipe_buffer {
* @fasync_readers: reader side fasync
* @fasync_writers: writer side fasync
* @bufs: the circular array of pipe buffers
+ * @user: the user who created this pipe
**/
struct pipe_inode_info {
struct mutex mutex;
@@ -57,6 +58,7 @@ struct pipe_inode_info {
struct fasync_struct *fasync_readers;
struct fasync_struct *fasync_writers;
struct pipe_buffer *bufs;
+ struct user_struct *user;
};
/*
@@ -140,6 +142,8 @@ void pipe_unlock(struct pipe_inode_info *);
void pipe_double_lock(struct pipe_inode_info *, struct pipe_inode_info *);
extern unsigned int pipe_max_size, pipe_min_size;
+extern unsigned long pipe_user_pages_hard;
+extern unsigned long pipe_user_pages_soft;
int pipe_proc_fn(struct ctl_table *, int, void __user *, size_t *, loff_t *);
diff --git a/include/linux/sched.h b/include/linux/sched.h
index 4781332..7728941 100644
--- a/include/linux/sched.h
+++ b/include/linux/sched.h
@@ -671,6 +671,7 @@ struct user_struct {
#endif
unsigned long locked_shm; /* How many pages of mlocked shm ? */
unsigned long unix_inflight; /* How many files in flight in unix sockets */
+ atomic_long_t pipe_bufs; /* how many pages are allocated in pipe buffers */
#ifdef CONFIG_KEYS
struct key *uid_keyring; /* UID specific keyring */
diff --git a/kernel/sysctl.c b/kernel/sysctl.c
index 9469f4c..4fd49fe 100644
--- a/kernel/sysctl.c
+++ b/kernel/sysctl.c
@@ -1632,6 +1632,20 @@ static struct ctl_table fs_table[] = {
.proc_handler = &pipe_proc_fn,
.extra1 = &pipe_min_size,
},
+ {
+ .procname = "pipe-user-pages-hard",
+ .data = &pipe_user_pages_hard,
+ .maxlen = sizeof(pipe_user_pages_hard),
+ .mode = 0644,
+ .proc_handler = proc_doulongvec_minmax,
+ },
+ {
+ .procname = "pipe-user-pages-soft",
+ .data = &pipe_user_pages_soft,
+ .maxlen = sizeof(pipe_user_pages_soft),
+ .mode = 0644,
+ .proc_handler = proc_doulongvec_minmax,
+ },
{ }
};
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
Page 5 of 8 — ← Prev page 1 2 3 4 [5] 6 7 8 Next page →
Back to top | Article view | linux.kernel
csiph-web