Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1521019 > unrolled thread

[PATCH 3.2 000/152] 3.2.84-rc1 review

Started byBen Hutchings <ben@decadent.org.uk>
First post2016-11-14 04:10 +0100
Last post2016-11-14 18:20 +0100
Articles 20 on this page of 36 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.2 000/152] 3.2.84-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 070/152] cdc-acm: fix wrong pipe type on rx interrupt  xfers Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 108/152] frv: fix clear_user() Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 088/152] ALSA: timer: fix NULL pointer dereference on  memory allocation failure Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 044/152] KEYS: 64-bit MIPS needs to use  compat_sys_keyctl for 32-bit userspace Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 009/152] ext4: check for extents that wrap around Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
      Re: [PATCH 3.2 009/152] ext4: check for extents that wrap around Vegard Nossum <vegard.nossum@oracle.com> - 2016-11-14 16:40 +0100
        Re: [PATCH 3.2 009/152] ext4: check for extents that wrap around Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 17:20 +0100
    [PATCH 3.2 101/152] asm-generic: make copy_from_user() zero the  destination properly Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 077/152] USB: serial: option: add WeTelecom WM-D200 Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 125/152] microblaze: fix __get_user() Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 010/152] ext4: don't call ext4_should_journal_data()  on the journal inode Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 041/152] l2tp: Correctly return -EBADF from  pppol2tp_getname. Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 089/152] ALSA: timer: fix NULL pointer dereference in  read()/ioctl() race Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 045/152] drm/radeon: fix firmware info version checks Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 053/152] dm flakey: error READ bios during the  down_interval Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 030/152] crypto: scatterwalk - Fix test in  scatterwalk_done Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 131/152] openrisc: fix the fix of copy_from_user() Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 066/152] arm: oabi compat: add missing access checks Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 112/152] mn10300: copy_from_user() should zero on  access_ok() failure... Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 037/152] nfs: don't create zero-length requests Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:10 +0100
    [PATCH 3.2 015/152] x86/quirks: Apply nvidia_bugs quirk only on  root bus Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:20 +0100
    [PATCH 3.2 013/152] ALSA: ctl: Stop notification after disconnection Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:20 +0100
    [PATCH 3.2 019/152] NFS: Don't drop CB requests with invalid  principals Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:20 +0100
    [PATCH 3.2 007/152] usb: renesas_usbhs: protect the CFIFOSEL  setting in usbhsg_ep_enable() Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:20 +0100
    [PATCH 3.2 021/152] Bluetooth: Add support of 13d3:3490 AR3012 device Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:20 +0100
    [PATCH 3.2 003/152] sched/cputime: Fix prev steal time accouting  during CPU hotplug Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:20 +0100
    [PATCH 3.2 029/152] Bluetooth: Fix l2cap_sock_setsockopt() with  optname BT_RCVMTU Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:20 +0100
    [PATCH 3.2 008/152] Input: xpad - validate USB endpoint count  during probe Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:20 +0100
    [PATCH 3.2 036/152] MIPS: RM7000: Double locking bug in  rm7k_tc_disable() Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:20 +0100
    [PATCH 3.2 018/152] svc: Avoid garbage replies when pc_func()  returns rpc_drop_reply Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:20 +0100
    [PATCH 3.2 006/152] usb: renesas_usbhs: fix NULL pointer  dereference in xfer_work() Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:20 +0100
    [PATCH 3.2 035/152] tty/vt/keyboard: fix OOB access in  do_compute_shiftstate() Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:20 +0100
    [PATCH 3.2 012/152] drm/radeon: Poll for both connect/disconnect  on analog connectors Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 04:20 +0100
    Re: [PATCH 3.2 000/152] 3.2.84-rc1 review Guenter Roeck <linux@roeck-us.net> - 2016-11-14 06:50 +0100
      Re: [PATCH 3.2 000/152] 3.2.84-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2016-11-14 18:20 +0100

Page 1 of 2  [1] 2  Next page →


#1521019 — [PATCH 3.2 000/152] 3.2.84-rc1 review

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 000/152] 3.2.84-rc1 review
Message-ID<sDeSC-o3-13@gated-at.bofh.it>
This is the start of the stable review cycle for the 3.2.84 release.
There are 152 patches in this series, which will be posted as responses
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Sat Nov 19 00:00:00 UTC 2016.
Anything received after that time might be too late.

A combined patch relative to 3.2.83 will be posted as an additional
response to this.  A shortlog and diffstat can be found below.

Ben.

-------------

Al Viro (23):
      alpha: fix copy_from_user()
         [2561d309dfd1555e781484af757ed0115035ddb3]
      asm-generic: make copy_from_user() zero the destination properly
         [2545e5da080b4839dd859e3b09343a884f6ab0e3]
      asm-generic: make get_user() clear the destination on errors
         [9ad18b75c2f6e4a78ce204e79f37781f8815c0fa]
      avr32: fix copy_from_user()
         [8630c32275bac2de6ffb8aea9d9b11663e7ad28e]
      blackfin: fix copy_from_user()
         [8f035983dd826d7e04f67b28acf8e2f08c347e41]
      cris: buggered copy_from_user/copy_to_user/clear_user
         [eb47e0293baaa3044022059f1fa9ff474bfe35cb]
      frv: fix clear_user()
         [3b8767a8f00cc6538ba6b1cf0f88502e2fd2eb90]
      hexagon: fix strncpy_from_user() error return
         [f35c1e0671728d1c9abc405d05ef548b5fcb2fc4]
      ia64: copy_from_user() should zero the destination on access_ok() failure
         [a5e541f796f17228793694d64b507f5f57db4cd7]
      m32r: fix __get_user()
         [c90a3bc5061d57e7931a9b7ad14784e1a0ed497d]
      microblaze: fix __get_user()
         [e98b9e37ae04562d52c96f46b3cf4c2e80222dc1]
      microblaze: fix copy_from_user()
         [d0cf385160c12abd109746cad1f13e3b3e8b50b8]
      mn10300: copy_from_user() should zero on access_ok() failure...
         [ae7cc577ec2a4a6151c9e928fd1f595d953ecef1]
      mn10300: failing __get_user() and get_user() should zero
         [43403eabf558d2800b429cd886e996fd555aa542]
      openrisc: fix copy_from_user()
         [acb2505d0119033a80c85ac8d02dccae41271667]
      parisc: fix copy_from_user()
         [aace880feea38875fbc919761b77e5732a3659ef]
      ppc32: fix copy_from_user()
         [224264657b8b228f949b42346e09ed8c90136a8e]
      s390: get_user() should zero on failure
         [fd2d2b191fe75825c4c7a6f12f3fef35aaed7dd7]
      score: fix __get_user/get_user
         [c2f18fa4cbb3ad92e033a24efa27583978ce9600]
      score: fix copy_from_user() and friends
         [b615e3c74621e06cd97f86373ca90d43d6d998aa]
      sh64: failing __get_user() should zero
         [c6852389228df9fb3067f94f3b651de2a7921b36]
      sh: fix copy_from_user()
         [6e050503a150b2126620c1a1e9b3a368fcd51eac]
      sparc32: fix copy_from_user()
         [917400cecb4b52b5cde5417348322bb9c8272fa6]

Alan Stern (4):
      USB: avoid left shift by -1
         [53e5f36fbd2453ad69a3369a1db62dc06c30a4aa]
      USB: change bInterval default to 10 ms
         [08c5cd37480f59ea39682f4585d92269be6b1424]
      USB: fix typo in wMaxPacketSize validation
         [6c73358c83ce870c0cf32413e5cadb3b9a39c606]
      USB: validate wMaxPacketValue entries in endpoint descriptors
         [aed9d65ac3278d4febd8665bd7db59ef53e825fe]

Aleksandr Makarov (2):
      USB: serial: option: add WeTelecom 0x6802 and 0x6803 products
         [40d9c32525cba79130612650b1abc47c0c0f19a8]
      USB: serial: option: add WeTelecom WM-D200
         [6695593e4a7659db49ac6eca98c164f7b5589f72]

Alex Deucher (1):
      drm/radeon: fix firmware info version checks
         [3edc38a0facef45ee22af8afdce3737f421f36ab]

Alex Vesker (1):
      IB/ipoib: Don't allow MC joins during light MC flush
         [344bacca8cd811809fc33a249f2738ab757d327f]

Alexey Khoroshilov (2):
      USB: serial: mos7720: fix non-atomic allocation in write path
         [5a5a1d614287a647b36dff3f40c2b0ceabbc83ec]
      USB: serial: mos7840: fix non-atomic allocation in write path
         [3b7c7e52efda0d4640060de747768360ba70a7c0]

Amadeusz Sławiński (1):
      Bluetooth: Fix l2cap_sock_setsockopt() with optname BT_RCVMTU
         [23bc6ab0a0912146fd674a0becc758c3162baabc]

Andrey Pronin (1):
      tpm: read burstcount from TPM_STS in one 32-bit transaction
         [9754d45e997000ad4021bc4606cc266bb38d876f]

Ard Biesheuvel (1):
      crypto: cryptd - initialize child shash_desc on import
         [0bd2223594a4dcddc1e34b15774a3a4776f7749e]

Ashish Samant (1):
      ocfs2: fix start offset to ocfs2_zero_range_for_truncate()
         [d21c353d5e99c56cdd5b5c1183ffbcaf23b8b960]

Balbir Singh (1):
      sched/core: Fix a race between try_to_wake_up() and a woken up task
         [135e8c9250dd5c8c9aae5984fde6f230d0cbfeaf]

Benjamin Coddington (1):
      nfs: don't create zero-length requests
         [149a4fddd0a72d526abbeac0c8deaab03559836a]

Bharata B Rao (1):
      powerpc/numa: Fix multiple bugs in memory_hotplug_max()
         [45b64ee64970dee9392229302efe1d1567e8d304]

Cameron Gutman (1):
      Input: xpad - validate USB endpoint count during probe
         [caca925fca4fb30c67be88cacbe908eec6721e43]

Christian König (1):
      drm/radeon: fix radeon_move_blit on 32bit systems
         [13f479b9df4e2bbf2d16e7e1b02f3f55f70e2455]

Chuck Lever (2):
      NFS: Don't drop CB requests with invalid principals
         [a4e187d83d88eeaba6252aac0a2ffe5eaa73a818]
      svc: Avoid garbage replies when pc_func() returns rpc_drop_reply
         [0533b13072f4bf35738290d2cf9e299c7bc6c42a]

Dan Carpenter (7):
      MIPS: RM7000: Double locking bug in rm7k_tc_disable()
         [58a7e1c140f3ad61646bc0cd9a1f6a9cafc0b225]
      avr32: off by one in at32_init_pio()
         [55f1cf83d5cf885c75267269729805852039c834]
      ext3: NULL dereference in ext3_evict_inode()
         [bcdd0c1600903e9222abfcde28947406020ccb5d]
      hostfs: Freeing an ERR_PTR in hostfs_fill_sb_common()
         [8a545f185145e3c09348cd74326268ecfc6715a3]
      mtd: pmcmsp-flash: Allocating too much in init_msp_flash()
         [79ad07d45743721010e766e65dc004ad249bd429]
      scsi: arcmsr: Buffer overflow in arcmsr_iop_message_xfer()
         [7bc2b55a5c030685b399bb65b6baa9ccc3d1f167]
      usb: gadget: fsl_qe_udc: signedness bug in qe_get_frame()
         [f4693b08cc901912a87369c46537b94ed4084ea0]

Daniel Vetter (1):
      drm: Reject page_flip for !DRIVER_MODESET
         [6f00975c619064a18c23fd3aced325ae165a73b9]

Daniele Palmas (1):
      USB: serial: option: add support for Telit LE910 PID 0x1206
         [3c0415fa08548e3bc63ef741762664497ab187ed]

Dave Carroll (1):
      aacraid: Check size values after double-fetch from user
         [fa00c437eef8dc2e7b25f8cd868cfa405fcc2bb3]

Dave Weinstein (1):
      arm: oabi compat: add missing access checks
         [7de249964f5578e67b99699c5f0b405738d820a2]

David Howells (3):
      KEYS: 64-bit MIPS needs to use compat_sys_keyctl for 32-bit userspace
         [20f06ed9f61a185c6dabd662c310bed6189470df]
      KEYS: Fix short sprintf buffer in /proc/keys show function
         [03dab869b7b239c4e013ec82aea22e181e441cfc]
      x86/syscalls/64: Add compat_sys_keyctl for 32-bit userspace
         [f7d665627e103e82d34306c7d3f6f46f387c0d8b]

Dmitry Torokhov (3):
      Input: i8042 - break load dependency between atkbd/psmouse and i8042
         [4097461897df91041382ff6fcd2bfa7ee6b2448c]
      Input: i8042 - set up shared ps2_cmd_mutex for AUX ports
         [47af45d684b5f3ae000ad448db02ce4f13f73273]
      tty/vt/keyboard: fix OOB access in do_compute_shiftstate()
         [510cccb5b0c8868a2b302a0ab524da7912da648b]

Dmitry Tunin (1):
      Bluetooth: Add support of 13d3:3490 AR3012 device
         [12d868964f7352e8b18e755488f7265a93431de1]

Erez Shitrit (2):
      IB/core: Fix use after free in send_leave function
         [68c6bcdd8bd00394c234b915ab9b97c74104130c]
      IB/ipoib: Fix memory corruption in ipoib cm mode connect flow
         [546481c2816ea3c061ee9d5658eb48070f69212e]

Eric Dumazet (1):
      tcp: fix use after free in tcp_xmit_retransmit_queue()
         [bb1fceca22492109be12640d49f5ea5a544c6bb4]

Florian Fainelli (2):
      brcmsmac: Initialize power in brcms_c_stf_ss_algo_channel_get()
         [f823a2aa8f4674c095a5413b9e3ba12d82df06f2]
      net: ethoc: Fix early error paths
         [386512d18b268c6182903239f9f3390f03ce4c7b]

Gavin Li (1):
      cdc-acm: fix wrong pipe type on rx interrupt xfers
         [add125054b8727103631dce116361668436ef6a7]

Guenter Roeck (2):
      avr32: fix 'undefined reference to `___copy_from_user'
         [65c0044ca8d7c7bbccae37f0ff2972f0210e9f41]
      openrisc: fix the fix of copy_from_user()
         [8e4b72054f554967827e18be1de0e8122e6efc04]

Hector Palacios (1):
      mtd: nand: fix bug writing 1 byte less than page size
         [144f4c98399e2c0ca60eb414c15a2c68125c18b8]

Helge Deller (1):
      parisc: Fix order of EREFUSED define in errno.h
         [3eb53b20d7bd1374598cfb1feaa081fcac0e76cd]

Herbert Xu (3):
      crypto: gcm - Filter out async ghash if necessary
         [b30bdfa86431afbafe15284a3ad5ac19b49b88e3]
      crypto: scatterwalk - Fix test in scatterwalk_done
         [5f070e81bee35f1b7bd1477bb223a873ff657803]
      crypto: skcipher - Fix blkcipher walk OOM crash
         [acdb04d0b36769b3e05990c488dc74d8b7ac8060]

Ilan Tayari (1):
      xfrm: Fix memory leak of aead algorithm name
         [b588479358ce26f32138e0f0a7ab0678f8e3e601]

Iosif Harutyunov (1):
      ubi: Fix race condition between ubi device creation and udev
         [714fb87e8bc05ff78255afc0dca981e8c5242785]

Jaganath Kanakkassery (1):
      Bluetooth: Fix potential NULL dereference in RFCOMM bind callback
         [951b6a0717db97ce420547222647bcc40bf1eacd]

James Hogan (1):
      s390: Define AT_VECTOR_SIZE_ARCH for ARCH_DLINFO
         [68c5cf5a6091c2c3fabccfd42ca844d730ec24c6]

Jan Beulich (2):
      xenbus: don't BUG() on user mode induced condition
         [0beef634b86a1350c31da5fcc2992f0d7c8a622b]
      xenbus: don't look up transaction IDs for ordinary writes
         [9a035a40f7f3f6708b79224b86c5777a3334f7ea]

Jan Kara (3):
      fs: Avoid premature clearing of capabilities
         [030b533c4fd4d2ec3402363323de4bb2983c9cee]
      fs: Give dentry to inode_change_ok() instead of inode
         [31051c85b5e2aaaf6315f74c72a732673632a905]
      posix_acl: Clear SGID bit when setting file permissions
         [073931017b49d9458aa351605b43a7e34598caef]

Jeff Mahoney (1):
      btrfs: ensure that file descriptor used with subvol ioctls is a dir
         [325c50e3cebb9208009083e841550f98a863bfa0]

Jia He (1):
      mm/hugetlb: avoid soft lockup in set_max_huge_pages()
         [649920c6ab93429b94bc7c1aa7c0e8395351be32]

Jim Lin (1):
      usb: xhci: Fix panic if disconnect
         [88716a93766b8f095cdef37a8e8f2c93aa233b21]

Jim Mattson (1):
      KVM: nVMX: Fix memory corruption when using VMCS shadowing
         [2f1fe81123f59271bddda673b60116bde9660385]

Jiri Slaby (1):
      pps: do not crash when failed to register
         [368301f2fe4b07e5fb71dba3cc566bc59eb6705f]

Joseph Qi (1):
      ocfs2/dlm: fix race between convert and migration
         [e6f0c6e6170fec175fe676495f29029aecdf486c]

Karl Beldan (1):
      mtd: nand: davinci: Reinitialize the HW ECC engine in 4bit hwctl
         [f6d7c1b5598b6407c3f1da795dd54acf99c1990c]

Konstantin Neumoin (1):
      balloon: check the number of available pages in leak balloon
         [37cf99e08c6fb4dcea0f9ad2b13b6daa8c76a711]

Krzysztof Kozlowski (1):
      serial: samsung: Fix possible out of bounds access on non-DT platform
         [926b7b5122c96e1f18cd20e85a286c7ec8d18c97]

Lauro Costa (1):
      Bluetooth: Add USB ID 13D3:3487 to ath3k
         [72f9f8b58bc743e6b6abdc68f60db98486c3ffcf]

Linus Walleij (2):
      iio: accel: kxsd9: Fix raw read return
         [7ac61a062f3147dc23e3f12b9dfe7c4dd35f9cb8]
      iio: accel: kxsd9: Fix scaling bug
         [307fe9dd11ae44d4f8881ee449a7cbac36e1f5de]

Liping Zhang (1):
      netfilter: nfnetlink_queue: reject verdict request from different portid
         [00a3101f561816e58de054a470484996f78eb5eb]

Liu Bo (1):
      Btrfs: skip adding an acl attribute if we don't have to
         [755ac67f83e515af55adbfe55134eb7d90839cdb]

Lubomir Rintel (1):
      USB: serial: option: add D-Link DWM-156/A3
         [cf1b18030de29e4e5b0a57695ae5db4a89da0ff7]

Lukas Wunner (3):
      x86/quirks: Add early quirk to reset Apple AirPort card
         [abb2bafd295fe962bbadc329dbfb2146457283ac]
      x86/quirks: Apply nvidia_bugs quirk only on root bus
         [447d29d1d3aed839e74c2401ef63387780ac51ed]
      x86/quirks: Reintroduce scanning of secondary buses
         [850c321027c2e31d0afc71588974719a4b565550]

Lyude (1):
      drm/radeon: Poll for both connect/disconnect on analog connectors
         [14ff8d48f2235295dfb3117693008e367b49cdb5]

Mario Kleiner (1):
      drm/edid: Add 6 bpc quirk for display AEO model 0.
         [e10aec652f31ec61d6a0b4d00d8ef8d2b66fa0fd]

Mathias Krause (1):
      xfrm_user: propagate sec ctx allocation errors
         [2f30ea5090cbc57ea573cdc66421264b3de3fb0a]

Mathias Nyman (1):
      xhci: don't dereference a xhci member after removing xhci
         [f1f6d9a8b540df22b87a5bf6bc104edaade81f47]

Michael Walle (1):
      hwmon: (adt7411) set bit 3 in CFG1 register
         [b53893aae441a034bf4dbbad42fe218561d7d81f]

Mike Snitzer (1):
      dm flakey: error READ bios during the down_interval
         [99f3c90d0d85708e7401a81ce3314e50bf7f2819]

Nikolay Aleksandrov (1):
      ipmr, ip6mr: fix scheduling while atomic and a deadlock with ipmr_get_route
         [2cf750704bb6d7ed8c7d732e071dd1bc890ea5e8]

Paolo Bonzini (1):
      KVM: nVMX: fix lifetime issues for vmcs02
         [4fa7734c62cdd8c07edd54fa5a5e91482273071a]

Paul Moore (1):
      netlabel: add address family checks to netlbl_{sock,req}_delattr()
         [0e0e36774081534783aa8eeb9f6fbddf98d3c061]

Phil Turnbull (1):
      ceph: Correctly return NXIO errors from ceph_llseek
         [955818cd5b6c4b58ea574ace4573e7afa4c19c1e]

Phil.Turnbull@Oracle.Com (2):
      irda: Free skb on irda_accept error path.
         [8ab86c00e349cef9fb14719093a7f198bcc72629]
      l2tp: Correctly return -EBADF from pppol2tp_getname.
         [4ac36a4adaf80013a60013d6f829f5863d5d0e05]

Robert Deliën (1):
      USB: serial: ftdi_sio: add PIDs for Ivium Technologies devices
         [6977495c06f7f47636a076ee5a0ca571279d9697]

Russell King (1):
      ARM: sa1111: fix pcmcia suspend/resume
         [06dfe5cc0cc684e735cb0232fdb756d30780b05d]

Sebastian Andrzej Siewior (1):
      x86/mm: Disable preemption during CR3 read+write
         [5cf0791da5c162ebc14b01eb01631cfa7ed4fa6e]

Sebastian Reichel (1):
      ARM: OMAP3: hwmod data: Add sysc information for DSI
         [b46211d6dcfb81a8af66b8684a42d629183670d4]

Sergei Miroshnichenko (1):
      can: dev: fix deadlock reported after bus-off
         [9abefcb1aaa58b9d5aa40a8bb12c87d02415e4c8]

Sheng-Hui J. Chu (1):
      USB: serial: ftdi_sio: add device ID for WICED USB UART dev board
         [ae34d12cc1e212ffcd92e069030e54dae69c832f]

Soheil Hassas Yeganeh (1):
      tcp: consider recv buf for the initial window scale
         [f626300a3e776ccc9671b0dd94698fb3aa315966]

Stefan Haberland (1):
      s390/dasd: fix hanging device after clear subchannel
         [9ba333dc55cbb9523553df973adb3024d223e905]

Stefan Richter (1):
      firewire: net: guard against rx buffer overflows
         [667121ace9dbafb368618dbabcf07901c962ddac]

Steven Rostedt (2):
      tracing: Move mutex to protect against resetting of seq data
         [1245800c0f96eb6ebb368593e251d66c01e61022]
      x86/paravirt: Do not trace _paravirt_ident_*() functions
         [15301a570754c7af60335d094dd2d1808b0641a5]

Takashi Iwai (4):
      ALSA: ctl: Stop notification after disconnection
         [f388cdcdd160687c6650833f286b9c89c50960ff]
      ALSA: rawmidi: Fix possible deadlock with virmidi registration
         [816f318b2364262a51024096da7ca3b84e78e3b5]
      ALSA: timer: Code cleanup
         [c3b1681375dc6e71d89a3ae00cc3ce9e775a8917]
      ALSA: timer: Fix zero-division by continue of uninitialized instance
         [9f8a7658bcafb2a7853f7a2eae8a94e87e6e695b]

Theodore Ts'o (2):
      ext4: validate s_reserved_gdt_blocks on mount
         [5b9554dc5bf008ae7f68a52e3d7e76c0920938a2]
      ext4: validate that metadata blocks do not overlap superblock
         [829fa70dddadf9dd041d62b82cd7cea63943899d]

Trond Myklebust (1):
      NFSv4.1: Fix the CREATE_SESSION slot number accounting
         [b519d408ea32040b1c7e10b155a3ee9a36660947]

Vegard Nossum (10):
      ALSA: timer: fix NULL pointer dereference in read()/ioctl() race
         [11749e086b2766cccf6217a527ef5c5604ba069c]
      ALSA: timer: fix NULL pointer dereference on memory allocation failure
         [8ddc05638ee42b18ba4fe99b5fb647fa3ad20456]
      ALSA: timer: fix division by zero after SNDRV_TIMER_IOCTL_CONTINUE
         [6b760bb2c63a9e322c0e4a0b5daf335ad93d5a33]
      block: fix use-after-free in seq file
         [77da160530dd1dc94f6ae15a981f24e5f0021e84]
      ext4: check for extents that wrap around
         [f70749ca42943faa4d4dcce46dfdcaadb1d0c4b6]
      ext4: don't call ext4_should_journal_data() on the journal inode
         [6a7fd522a7c94cdef0a3b08acf8e6702056e635c]
      ext4: fix reference counting bug on block allocation error
         [554a5ccc4e4a20c5f3ec859de0842db4b4b9c77e]
      ext4: short-cut orphan cleanup on error
         [c65d5c6c81a1f27dec5f627f67840726fcd146de]
      fs/seq_file: fix out-of-bounds read
         [088bf2ff5d12e2e32ee52a4024fec26e582f44d3]
      net/irda: fix NULL pointer dereference on memory allocation failure
         [d3e6952cfb7ba5f4bfa29d4803ba91f96ce1204d]

Vincent Stehlé (1):
      ubifs: Fix assertion in layout_in_gaps()
         [c0082e985fdf77b02fc9e0dac3b58504dcf11b7a]

Vladis Dronov (1):
      [media] usbvision: revert commit 588afcc1
         [d5468d7afaa9c9e961e150f0455a14a9f4872a98]

WANG Cong (1):
      ppp: defer netns reference release for ppp channel
         [205e1e255c479f3fd77446415706463b282f94e4]

Wanpeng Li (2):
      sched/cputime: Fix prev steal time accouting during CPU hotplug
         [3d89e5478bf550a50c99e93adf659369798263b0]
      x86/apic: Do not init irq remapping if ioapic is disabled
         [2e63ad4bd5dd583871e6602f9d398b9322d358d9]

Yadi.hu (1):
      i2c-eg20t: fix race between i2c init and interrupt enable
         [371a015344b6e270e7e3632107d9554ec6d27a6b]

Yinghai Lu (1):
      megaraid_sas: Fix probing cards without io port
         [e7f851684efb3377e9c93aca7fae6e76212e5680]

Yoshihiro Shimoda (2):
      usb: renesas_usbhs: fix NULL pointer dereference in xfer_work()
         [4fdef698383db07d829da567e0e405fc41ff3a89]
      usb: renesas_usbhs: protect the CFIFOSEL setting in usbhsg_ep_enable()
         [15e4292a2d21e9997fdb2b8c014cc461b3f268f0]

Zhong Jiang (1):
      mm,ksm: fix endless looping in allocating memory when ksm enable
         [5b398e416e880159fe55eefd93c6588fa072cd66]

 Documentation/filesystems/porting               |   4 +-
 Makefile                                        |   4 +-
 arch/alpha/include/asm/uaccess.h                |  19 ++---
 arch/arm/common/sa1111.c                        |  22 +++--
 arch/arm/kernel/sys_oabi-compat.c               |   8 +-
 arch/arm/mach-omap2/omap_hwmod_3xxx_data.c      |  12 +++
 arch/avr32/include/asm/uaccess.h                |  11 ++-
 arch/avr32/kernel/avr32_ksyms.c                 |   2 +-
 arch/avr32/lib/copy_user.S                      |   8 +-
 arch/avr32/mach-at32ap/pio.c                    |   2 +-
 arch/blackfin/include/asm/uaccess.h             |   9 +-
 arch/cris/include/asm/uaccess.h                 |  71 +++++++---------
 arch/frv/include/asm/uaccess.h                  |  12 ++-
 arch/hexagon/include/asm/uaccess.h              |   3 +-
 arch/ia64/include/asm/uaccess.h                 |  20 ++---
 arch/m32r/include/asm/uaccess.h                 |   2 +-
 arch/microblaze/include/asm/uaccess.h           |  11 ++-
 arch/mips/kernel/scall64-n32.S                  |   2 +-
 arch/mips/kernel/scall64-o32.S                  |   2 +-
 arch/mips/mm/sc-rm7k.c                          |   2 +-
 arch/mn10300/include/asm/uaccess.h              |   1 +
 arch/mn10300/lib/usercopy.c                     |   5 +-
 arch/openrisc/include/asm/uaccess.h             |  35 +++-----
 arch/parisc/include/asm/errno.h                 |   4 +-
 arch/parisc/include/asm/uaccess.h               |   7 +-
 arch/powerpc/include/asm/uaccess.h              |  21 +----
 arch/powerpc/mm/numa.c                          |  18 +++-
 arch/s390/include/asm/auxvec.h                  |   2 +
 arch/s390/include/asm/elf.h                     |   1 +
 arch/s390/include/asm/uaccess.h                 |   8 +-
 arch/score/include/asm/uaccess.h                |  46 +++++-----
 arch/sh/include/asm/uaccess.h                   |   5 +-
 arch/sh/include/asm/uaccess_64.h                |   1 +
 arch/sparc/include/asm/uaccess_32.h             |   4 +-
 arch/x86/ia32/ia32entry.S                       |   2 +-
 arch/x86/include/asm/tlbflush.h                 |   7 ++
 arch/x86/kernel/apic/apic.c                     |   3 +
 arch/x86/kernel/early-quirks.c                  | 106 +++++++++++++++++++++---
 arch/x86/kernel/paravirt.c                      |   4 +-
 arch/x86/kvm/vmx.c                              |  62 ++++++++++----
 block/genhd.c                                   |   1 +
 crypto/blkcipher.c                              |   3 +-
 crypto/cryptd.c                                 |   9 +-
 crypto/gcm.c                                    |   4 +-
 crypto/scatterwalk.c                            |   3 +-
 drivers/bcma/bcma_private.h                     |   2 -
 drivers/bluetooth/ath3k.c                       |   4 +
 drivers/bluetooth/btusb.c                       |   2 +
 drivers/char/tpm/tpm_tis.c                      |   9 +-
 drivers/firewire/net.c                          |  46 +++++++---
 drivers/gpu/drm/drm_crtc.c                      |   3 +
 drivers/gpu/drm/drm_edid.c                      |   8 ++
 drivers/gpu/drm/radeon/radeon_atombios.c        |   4 +-
 drivers/gpu/drm/radeon/radeon_connectors.c      |  15 ++--
 drivers/gpu/drm/radeon/radeon_ttm.c             |   4 +-
 drivers/hwmon/adt7411.c                         |   5 +-
 drivers/i2c/busses/i2c-eg20t.c                  |  18 ++--
 drivers/infiniband/core/multicast.c             |  13 +--
 drivers/infiniband/ulp/ipoib/ipoib.h            |   1 +
 drivers/infiniband/ulp/ipoib/ipoib_cm.c         |  16 ++++
 drivers/infiniband/ulp/ipoib/ipoib_ib.c         |   9 ++
 drivers/infiniband/ulp/ipoib/ipoib_main.c       |   2 +-
 drivers/input/joystick/xpad.c                   |   3 +
 drivers/input/serio/i8042.c                     |  17 +---
 drivers/input/serio/libps2.c                    |  10 +--
 drivers/md/dm-flakey.c                          |  23 +++--
 drivers/media/video/usbvision/usbvision-video.c |   7 --
 drivers/mtd/maps/pmcmsp-flash.c                 |   6 +-
 drivers/mtd/nand/davinci_nand.c                 |   3 +
 drivers/mtd/nand/nand_base.c                    |   2 +-
 drivers/mtd/ubi/build.c                         |   5 +-
 drivers/net/can/dev.c                           |  27 +++---
 drivers/net/ethernet/ethoc.c                    |  10 +--
 drivers/net/ppp/ppp_generic.c                   |   5 +-
 drivers/net/wireless/brcm80211/brcmsmac/stf.c   |   2 +-
 drivers/pps/clients/pps_parport.c               |   2 +-
 drivers/s390/block/dasd.c                       |  10 ++-
 drivers/scsi/aacraid/commctrl.c                 |  13 ++-
 drivers/scsi/arcmsr/arcmsr_hba.c                |   8 +-
 drivers/scsi/megaraid/megaraid_sas_base.c       |   6 +-
 drivers/scsi/megaraid/megaraid_sas_fusion.c     |   2 +-
 drivers/staging/iio/accel/kxsd9.c               |   2 +
 drivers/staging/pohmelfs/Kconfig                |   1 +
 drivers/tty/serial/samsung.c                    |   4 +-
 drivers/tty/vt/keyboard.c                       |  30 ++-----
 drivers/usb/class/cdc-acm.c                     |   5 +-
 drivers/usb/class/cdc-acm.h                     |   1 -
 drivers/usb/core/config.c                       |  93 +++++++++++++++++----
 drivers/usb/core/devio.c                        |  16 ++--
 drivers/usb/gadget/fsl_qe_udc.c                 |   7 +-
 drivers/usb/host/xhci-hub.c                     |   3 +
 drivers/usb/host/xhci-pci.c                     |   3 +-
 drivers/usb/renesas_usbhs/fifo.c                |  18 +++-
 drivers/usb/renesas_usbhs/mod_gadget.c          |   9 +-
 drivers/usb/serial/ftdi_sio.c                   |   3 +
 drivers/usb/serial/ftdi_sio_ids.h               |  12 +++
 drivers/usb/serial/mos7720.c                    |   2 +-
 drivers/usb/serial/mos7840.c                    |   4 +-
 drivers/usb/serial/option.c                     |  13 +++
 drivers/virtio/virtio_balloon.c                 |   2 +
 drivers/xen/xenfs/xenbus.c                      |  14 ++--
 fs/9p/acl.c                                     |  40 ++++-----
 fs/9p/vfs_inode.c                               |   2 +-
 fs/9p/vfs_inode_dotl.c                          |   2 +-
 fs/adfs/inode.c                                 |   2 +-
 fs/affs/inode.c                                 |   2 +-
 fs/attr.c                                       |  35 +++++---
 fs/btrfs/acl.c                                  |   4 +-
 fs/btrfs/inode.c                                |   2 +-
 fs/btrfs/ioctl.c                                |  12 +++
 fs/ceph/file.c                                  |  13 ++-
 fs/ceph/inode.c                                 |   2 +-
 fs/cifs/inode.c                                 |   4 +-
 fs/ecryptfs/inode.c                             |   2 +-
 fs/exofs/inode.c                                |   2 +-
 fs/ext2/acl.c                                   |  12 +--
 fs/ext2/inode.c                                 |   2 +-
 fs/ext3/acl.c                                   |  12 +--
 fs/ext3/inode.c                                 |   6 +-
 fs/ext4/acl.c                                   |  12 +--
 fs/ext4/extents.c                               |   8 +-
 fs/ext4/inode.c                                 |   8 +-
 fs/ext4/mballoc.c                               |  17 +---
 fs/ext4/super.c                                 |  35 +++++++-
 fs/fat/file.c                                   |   2 +-
 fs/fuse/dir.c                                   |   2 +-
 fs/generic_acl.c                                |  15 ++--
 fs/gfs2/acl.c                                   |  16 ++--
 fs/gfs2/inode.c                                 |   2 +-
 fs/hfs/inode.c                                  |   2 +-
 fs/hfsplus/inode.c                              |   2 +-
 fs/hostfs/hostfs_kern.c                         |   9 +-
 fs/hpfs/inode.c                                 |   2 +-
 fs/hugetlbfs/inode.c                            |   2 +-
 fs/jffs2/acl.c                                  |   9 +-
 fs/jffs2/fs.c                                   |   2 +-
 fs/jfs/file.c                                   |   2 +-
 fs/jfs/xattr.c                                  |   6 +-
 fs/libfs.c                                      |   2 +-
 fs/logfs/file.c                                 |   2 +-
 fs/minix/file.c                                 |   2 +-
 fs/ncpfs/inode.c                                |   2 +-
 fs/nfs/callback_xdr.c                           |   6 +-
 fs/nfs/nfs4proc.c                               |  15 +++-
 fs/nfs/write.c                                  |   5 +-
 fs/nfsd/vfs.c                                   |  12 +--
 fs/nilfs2/inode.c                               |   2 +-
 fs/ntfs/inode.c                                 |   2 +-
 fs/ocfs2/acl.c                                  |   9 +-
 fs/ocfs2/dlm/dlmconvert.c                       |  12 +--
 fs/ocfs2/dlmfs/dlmfs.c                          |   2 +-
 fs/ocfs2/file.c                                 |  36 +++++---
 fs/omfs/file.c                                  |   2 +-
 fs/posix_acl.c                                  |  30 +++++++
 fs/proc/base.c                                  |   2 +-
 fs/proc/generic.c                               |   2 +-
 fs/proc/proc_sysctl.c                           |   2 +-
 fs/ramfs/file-nommu.c                           |   2 +-
 fs/reiserfs/inode.c                             |   2 +-
 fs/reiserfs/xattr_acl.c                         |   8 +-
 fs/seq_file.c                                   |   4 +-
 fs/sysfs/inode.c                                |   2 +-
 fs/sysv/file.c                                  |   2 +-
 fs/ubifs/file.c                                 |   2 +-
 fs/ubifs/tnc_commit.c                           |   2 +-
 fs/udf/file.c                                   |   2 +-
 fs/ufs/truncate.c                               |   2 +-
 fs/utimes.c                                     |   4 +-
 fs/xfs/xfs_acl.c                                |  26 +++---
 fs/xfs/xfs_file.c                               |   6 +-
 fs/xfs/xfs_ioctl.c                              |   3 +-
 fs/xfs/xfs_iops.c                               |  26 ++++--
 fs/xfs/xfs_vnodeops.c                           |   5 +-
 fs/xfs/xfs_vnodeops.h                           |   7 +-
 include/asm-generic/uaccess.h                   |  20 +++--
 include/linux/bcma/bcma.h                       |   1 +
 include/linux/bcma/bcma_regs.h                  |   1 +
 include/linux/can/dev.h                         |   3 +-
 include/linux/fs.h                              |   2 +-
 include/linux/i8042.h                           |   6 --
 include/linux/mroute.h                          |   2 +-
 include/linux/mroute6.h                         |   2 +-
 include/linux/posix_acl.h                       |   1 +
 include/linux/serio.h                           |  24 ++++--
 include/net/tcp.h                               |   2 +
 kernel/sched.c                                  |  36 ++++----
 kernel/trace/trace.c                            |  15 ++--
 mm/hugetlb.c                                    |   4 +
 mm/ksm.c                                        |   3 +-
 mm/shmem.c                                      |   2 +-
 net/bluetooth/l2cap_sock.c                      |   2 +-
 net/bluetooth/rfcomm/sock.c                     |  19 +++--
 net/ipv4/ipmr.c                                 |   3 +-
 net/ipv4/route.c                                |   3 +-
 net/ipv4/tcp_output.c                           |   3 +-
 net/ipv6/ip6mr.c                                |   5 +-
 net/ipv6/route.c                                |   4 +-
 net/irda/af_irda.c                              |  12 +--
 net/l2tp/l2tp_ppp.c                             |   7 +-
 net/netfilter/nfnetlink_queue.c                 |   3 -
 net/netlabel/netlabel_kapi.c                    |  12 ++-
 net/sunrpc/svc.c                                |   7 +-
 net/xfrm/xfrm_state.c                           |   1 +
 net/xfrm/xfrm_user.c                            |   9 +-
 security/keys/proc.c                            |   2 +-
 sound/core/control.c                            |   2 +
 sound/core/rawmidi.c                            |   4 +-
 sound/core/timer.c                              |  72 ++++++++++------
 virt/kvm/kvm_main.c                             |   2 +
 209 files changed, 1278 insertions(+), 731 deletions(-)

-- 
Ben Hutchings
If more than one person is responsible for a bug, no one is at fault.

[toc] | [next] | [standalone]


#1521020 — [PATCH 3.2 070/152] cdc-acm: fix wrong pipe type on rx interrupt xfers

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 070/152] cdc-acm: fix wrong pipe type on rx interrupt xfers
Message-ID<sDfOH-11Z-41@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Gavin Li <git@thegavinli.com>

commit add125054b8727103631dce116361668436ef6a7 upstream.

This fixes the "BOGUS urb xfer" warning logged by usb_submit_urb().

Signed-off-by: Gavin Li <git@thegavinli.com>
Acked-by: Oliver Neukum <oneukum@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/class/cdc-acm.c | 5 ++---
 drivers/usb/class/cdc-acm.h | 1 -
 2 files changed, 2 insertions(+), 4 deletions(-)

--- a/drivers/usb/class/cdc-acm.c
+++ b/drivers/usb/class/cdc-acm.c
@@ -1156,7 +1156,6 @@ made_compressed_probe:
 	spin_lock_init(&acm->write_lock);
 	spin_lock_init(&acm->read_lock);
 	mutex_init(&acm->mutex);
-	acm->rx_endpoint = usb_rcvbulkpipe(usb_dev, epread->bEndpointAddress);
 	acm->is_int_ep = usb_endpoint_xfer_int(epread);
 	if (acm->is_int_ep)
 		acm->bInterval = epread->bInterval;
@@ -1205,14 +1204,14 @@ made_compressed_probe:
 		urb->transfer_dma = rb->dma;
 		if (acm->is_int_ep) {
 			usb_fill_int_urb(urb, acm->dev,
-					 acm->rx_endpoint,
+					 usb_rcvintpipe(usb_dev, epread->bEndpointAddress),
 					 rb->base,
 					 acm->readsize,
 					 acm_read_bulk_callback, rb,
 					 acm->bInterval);
 		} else {
 			usb_fill_bulk_urb(urb, acm->dev,
-					  acm->rx_endpoint,
+					  usb_rcvbulkpipe(usb_dev, epread->bEndpointAddress),
 					  rb->base,
 					  acm->readsize,
 					  acm_read_bulk_callback, rb);
--- a/drivers/usb/class/cdc-acm.h
+++ b/drivers/usb/class/cdc-acm.h
@@ -95,7 +95,6 @@ struct acm {
 	struct urb *read_urbs[ACM_NR];
 	struct acm_rb read_buffers[ACM_NR];
 	int rx_buflimit;
-	int rx_endpoint;
 	spinlock_t read_lock;
 	int write_used;					/* number of non-empty write buffers */
 	int transmitting;

[toc] | [prev] | [next] | [standalone]


#1521021 — [PATCH 3.2 108/152] frv: fix clear_user()

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 108/152] frv: fix clear_user()
Message-ID<sDfOH-11Z-55@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Al Viro <viro@zeniv.linux.org.uk>

commit 3b8767a8f00cc6538ba6b1cf0f88502e2fd2eb90 upstream.

It should check access_ok().  Otherwise a bunch of places turn into
trivially exploitable rootholes.

Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 arch/frv/include/asm/uaccess.h | 12 +++++++++---
 1 file changed, 9 insertions(+), 3 deletions(-)

--- a/arch/frv/include/asm/uaccess.h
+++ b/arch/frv/include/asm/uaccess.h
@@ -263,19 +263,25 @@ do {							\
 extern long __memset_user(void *dst, unsigned long count);
 extern long __memcpy_user(void *dst, const void *src, unsigned long count);
 
-#define clear_user(dst,count)			__memset_user(____force(dst), (count))
+#define __clear_user(dst,count)			__memset_user(____force(dst), (count))
 #define __copy_from_user_inatomic(to, from, n)	__memcpy_user((to), ____force(from), (n))
 #define __copy_to_user_inatomic(to, from, n)	__memcpy_user(____force(to), (from), (n))
 
 #else
 
-#define clear_user(dst,count)			(memset(____force(dst), 0, (count)), 0)
+#define __clear_user(dst,count)			(memset(____force(dst), 0, (count)), 0)
 #define __copy_from_user_inatomic(to, from, n)	(memcpy((to), ____force(from), (n)), 0)
 #define __copy_to_user_inatomic(to, from, n)	(memcpy(____force(to), (from), (n)), 0)
 
 #endif
 
-#define __clear_user clear_user
+static inline unsigned long __must_check
+clear_user(void __user *to, unsigned long n)
+{
+	if (likely(__access_ok(to, n)))
+		n = __clear_user(to, n);
+	return n;
+}
 
 static inline unsigned long __must_check
 __copy_to_user(void __user *to, const void *from, unsigned long n)

[toc] | [prev] | [next] | [standalone]


#1521022 — [PATCH 3.2 088/152] ALSA: timer: fix NULL pointer dereference on memory allocation failure

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 088/152] ALSA: timer: fix NULL pointer dereference on memory allocation failure
Message-ID<sDfOH-11Z-47@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Vegard Nossum <vegard.nossum@oracle.com>

commit 8ddc05638ee42b18ba4fe99b5fb647fa3ad20456 upstream.

I hit this with syzkaller:

    kasan: CONFIG_KASAN_INLINE enabled
    kasan: GPF could be caused by NULL-ptr deref or user memory access
    general protection fault: 0000 [#1] PREEMPT SMP KASAN
    CPU: 0 PID: 1327 Comm: a.out Not tainted 4.8.0-rc2+ #190
    Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.9.3-0-ge2fc41e-prebuilt.qemu-project.org 04/01/2014
    task: ffff88011278d600 task.stack: ffff8801120c0000
    RIP: 0010:[<ffffffff82c8ba07>]  [<ffffffff82c8ba07>] snd_hrtimer_start+0x77/0x100
    RSP: 0018:ffff8801120c7a60  EFLAGS: 00010006
    RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000007
    RDX: 0000000000000009 RSI: 1ffff10023483091 RDI: 0000000000000048
    RBP: ffff8801120c7a78 R08: ffff88011a5cf768 R09: ffff88011a5ba790
    R10: 0000000000000002 R11: ffffed00234b9ef1 R12: ffff880114843980
    R13: ffffffff84213c00 R14: ffff880114843ab0 R15: 0000000000000286
    FS:  00007f72958f3700(0000) GS:ffff88011aa00000(0000) knlGS:0000000000000000
    CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
    CR2: 0000000000603001 CR3: 00000001126ab000 CR4: 00000000000006f0
    Stack:
     ffff880114843980 ffff880111eb2dc0 ffff880114843a34 ffff8801120c7ad0
     ffffffff82c81ab1 0000000000000000 ffffffff842138e0 0000000100000000
     ffff880111eb2dd0 ffff880111eb2dc0 0000000000000001 ffff880111eb2dc0
    Call Trace:
     [<ffffffff82c81ab1>] snd_timer_start1+0x331/0x670
     [<ffffffff82c85bfd>] snd_timer_start+0x5d/0xa0
     [<ffffffff82c8795e>] snd_timer_user_ioctl+0x88e/0x2830
     [<ffffffff8159f3a0>] ? __follow_pte.isra.49+0x430/0x430
     [<ffffffff82c870d0>] ? snd_timer_pause+0x80/0x80
     [<ffffffff815a26fa>] ? do_wp_page+0x3aa/0x1c90
     [<ffffffff8132762f>] ? put_prev_entity+0x108f/0x21a0
     [<ffffffff82c870d0>] ? snd_timer_pause+0x80/0x80
     [<ffffffff816b0733>] do_vfs_ioctl+0x193/0x1050
     [<ffffffff813510af>] ? cpuacct_account_field+0x12f/0x1a0
     [<ffffffff816b05a0>] ? ioctl_preallocate+0x200/0x200
     [<ffffffff81002f2f>] ? syscall_trace_enter+0x3cf/0xdb0
     [<ffffffff815045ba>] ? __context_tracking_exit.part.4+0x9a/0x1e0
     [<ffffffff81002b60>] ? exit_to_usermode_loop+0x190/0x190
     [<ffffffff82001a97>] ? check_preemption_disabled+0x37/0x1e0
     [<ffffffff81d93889>] ? security_file_ioctl+0x89/0xb0
     [<ffffffff816b167f>] SyS_ioctl+0x8f/0xc0
     [<ffffffff816b15f0>] ? do_vfs_ioctl+0x1050/0x1050
     [<ffffffff81005524>] do_syscall_64+0x1c4/0x4e0
     [<ffffffff83c32b2a>] entry_SYSCALL64_slow_path+0x25/0x25
    Code: c7 c7 c4 b9 c8 82 48 89 d9 4c 89 ee e8 63 88 7f fe e8 7e 46 7b fe 48 8d 7b 48 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 04 84 c0 7e 65 80 7b 48 00 74 0e e8 52 46
    RIP  [<ffffffff82c8ba07>] snd_hrtimer_start+0x77/0x100
     RSP <ffff8801120c7a60>
    ---[ end trace 5955b08db7f2b029 ]---

This can happen if snd_hrtimer_open() fails to allocate memory and
returns an error, which is currently not checked by snd_timer_open():

    ioctl(SNDRV_TIMER_IOCTL_SELECT)
     - snd_timer_user_tselect()
	- snd_timer_close()
	   - snd_hrtimer_close()
	      - (struct snd_timer *) t->private_data = NULL
        - snd_timer_open()
           - snd_hrtimer_open()
              - kzalloc() fails; t->private_data is still NULL

    ioctl(SNDRV_TIMER_IOCTL_START)
     - snd_timer_user_start()
	- snd_timer_start()
	   - snd_timer_start1()
	      - snd_hrtimer_start()
		- t->private_data == NULL // boom

Signed-off-by: Vegard Nossum <vegard.nossum@oracle.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
[bwh: Backported to 3.2: don't put_device() since snd_timer_instance_new()
 doesn't take a device reference]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 sound/core/timer.c | 17 +++++++++++++++--
 1 file changed, 15 insertions(+), 2 deletions(-)

--- a/sound/core/timer.c
+++ b/sound/core/timer.c
@@ -290,8 +290,19 @@ int snd_timer_open(struct snd_timer_inst
 	}
 	timeri->slave_class = tid->dev_sclass;
 	timeri->slave_id = slave_id;
-	if (list_empty(&timer->open_list_head) && timer->hw.open)
-		timer->hw.open(timer);
+
+	if (list_empty(&timer->open_list_head) && timer->hw.open) {
+		int err = timer->hw.open(timer);
+		if (err) {
+			kfree(timeri->owner);
+			kfree(timeri);
+
+			module_put(timer->module);
+			mutex_unlock(&register_mutex);
+			return err;
+		}
+	}
+
 	list_add_tail(&timeri->open_list, &timer->open_list_head);
 	snd_timer_check_master(timeri);
 	mutex_unlock(&register_mutex);

[toc] | [prev] | [next] | [standalone]


#1521024 — [PATCH 3.2 044/152] KEYS: 64-bit MIPS needs to use compat_sys_keyctl for 32-bit userspace

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 044/152] KEYS: 64-bit MIPS needs to use compat_sys_keyctl for 32-bit userspace
Message-ID<sDfOH-11Z-53@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: David Howells <dhowells@redhat.com>

commit 20f06ed9f61a185c6dabd662c310bed6189470df upstream.

MIPS64 needs to use compat_sys_keyctl for 32-bit userspace rather than
calling sys_keyctl.  The latter will work in a lot of cases, thereby hiding
the issue.

Reported-by: Stephan Mueller <smueller@chronox.de>
Signed-off-by: David Howells <dhowells@redhat.com>
Cc: linux-mips@linux-mips.org
Cc: linux-kernel@vger.kernel.org
Cc: linux-security-module@vger.kernel.org
Cc: keyrings@vger.kernel.org
Patchwork: https://patchwork.linux-mips.org/patch/13832/
Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 arch/mips/kernel/scall64-n32.S | 2 +-
 arch/mips/kernel/scall64-o32.S | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

--- a/arch/mips/kernel/scall64-n32.S
+++ b/arch/mips/kernel/scall64-n32.S
@@ -366,7 +366,7 @@ EXPORT(sysn32_call_table)
 	PTR	sys_ni_syscall			/* available, was setaltroot */
 	PTR	sys_add_key
 	PTR	sys_request_key
-	PTR	sys_keyctl			/* 6245 */
+	PTR	compat_sys_keyctl		/* 6245 */
 	PTR	sys_set_thread_area
 	PTR	sys_inotify_init
 	PTR	sys_inotify_add_watch
--- a/arch/mips/kernel/scall64-o32.S
+++ b/arch/mips/kernel/scall64-o32.S
@@ -486,7 +486,7 @@ sys_call_table:
 	PTR	sys_ni_syscall			/* available, was setaltroot */
 	PTR	sys_add_key			/* 4280 */
 	PTR	sys_request_key
-	PTR	sys_keyctl
+	PTR	compat_sys_keyctl
 	PTR	sys_set_thread_area
 	PTR	sys_inotify_init
 	PTR	sys_inotify_add_watch		/* 4285 */

[toc] | [prev] | [next] | [standalone]


#1521025 — [PATCH 3.2 009/152] ext4: check for extents that wrap around

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 009/152] ext4: check for extents that wrap around
Message-ID<sDfOH-11Z-57@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Vegard Nossum <vegard.nossum@oracle.com>

commit f70749ca42943faa4d4dcce46dfdcaadb1d0c4b6 upstream.

An extent with lblock = 4294967295 and len = 1 will pass the
ext4_valid_extent() test:

	ext4_lblk_t last = lblock + len - 1;

	if (len == 0 || lblock > last)
		return 0;

since last = 4294967295 + 1 - 1 = 4294967295. This would later trigger
the BUG_ON(es->es_lblk + es->es_len < es->es_lblk) in ext4_es_end().

We can simplify it by removing the - 1 altogether and changing the test
to use lblock + len <= lblock, since now if len = 0, then lblock + 0 ==
lblock and it fails, and if len > 0 then lblock + len > lblock in order
to pass (i.e. it doesn't overflow).

Fixes: 5946d0893 ("ext4: check for overlapping extents in ext4_valid_extent_entries()")
Fixes: 2f974865f ("ext4: check for zero length extent explicitly")
Cc: Eryu Guan <guaneryu@gmail.com>
Signed-off-by: Phil Turnbull <phil.turnbull@oracle.com>
Signed-off-by: Vegard Nossum <vegard.nossum@oracle.com>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 fs/ext4/extents.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

--- a/fs/ext4/extents.c
+++ b/fs/ext4/extents.c
@@ -319,9 +319,13 @@ static int ext4_valid_extent(struct inod
 	ext4_fsblk_t block = ext4_ext_pblock(ext);
 	int len = ext4_ext_get_actual_len(ext);
 	ext4_lblk_t lblock = le32_to_cpu(ext->ee_block);
-	ext4_lblk_t last = lblock + len - 1;
 
-	if (len == 0 || lblock > last)
+	/*
+	 * We allow neither:
+	 *  - zero length
+	 *  - overflow/wrap-around
+	 */
+	if (lblock + len <= lblock)
 		return 0;
 	return ext4_data_block_valid(EXT4_SB(inode->i_sb), block, len);
 }

[toc] | [prev] | [next] | [standalone]


#1521754 — Re: [PATCH 3.2 009/152] ext4: check for extents that wrap around

FromVegard Nossum <vegard.nossum@oracle.com>
Date2016-11-14 16:40 +0100
SubjectRe: [PATCH 3.2 009/152] ext4: check for extents that wrap around
Message-ID<sDrwt-l5-5@gated-at.bofh.it>
In reply to#1521025
On 11/14/2016 01:14 AM, Ben Hutchings wrote:
> 3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

Just a general comment on stable review workflow, really:

It might be more useful to send the diff-of-diffs with the upstream
commit so I can easily see if you had any conflicts when cherry-picking
this and how they were resolved.

That's generally much more interesting than just the plain patch, where
I can't really tell if there were any changes at all (or conversely,
much more boring in case there were no changes, and thus easier to
review).

If you could push this commit to git before sending the review, you
could also include a command that I can use to quickly do the
diff-of-diffs myself without having to download and apply the patch (or
look for it), e.g. something like (using the 3.12 stable commit vs
upstream):

"""
diff -yw \
   <(echo upstream; git log -p -W f70749c^..f70749c) \
   <(echo 3.2; git log -p -W 33234c6^..33234c6)
"""

At least that would make it a lot easier for me (and I suspect other
casual stable contributors) to glance at a stable review email and tell
if the backport is correct or not. It should be pretty easy to script on
your end(s) for the benefit of everybody.

Just my 2 cents. Thanks,


Vegard

> ------------------
>
> From: Vegard Nossum <vegard.nossum@oracle.com>
>
> commit f70749ca42943faa4d4dcce46dfdcaadb1d0c4b6 upstream.
>
> An extent with lblock = 4294967295 and len = 1 will pass the
> ext4_valid_extent() test:
>
> 	ext4_lblk_t last = lblock + len - 1;
>
> 	if (len == 0 || lblock > last)
> 		return 0;
>
> since last = 4294967295 + 1 - 1 = 4294967295. This would later trigger
> the BUG_ON(es->es_lblk + es->es_len < es->es_lblk) in ext4_es_end().
>
> We can simplify it by removing the - 1 altogether and changing the test
> to use lblock + len <= lblock, since now if len = 0, then lblock + 0 ==
> lblock and it fails, and if len > 0 then lblock + len > lblock in order
> to pass (i.e. it doesn't overflow).
>
> Fixes: 5946d0893 ("ext4: check for overlapping extents in ext4_valid_extent_entries()")
> Fixes: 2f974865f ("ext4: check for zero length extent explicitly")
> Cc: Eryu Guan <guaneryu@gmail.com>
> Signed-off-by: Phil Turnbull <phil.turnbull@oracle.com>
> Signed-off-by: Vegard Nossum <vegard.nossum@oracle.com>
> Signed-off-by: Theodore Ts'o <tytso@mit.edu>
> Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
> ---
>  fs/ext4/extents.c | 8 ++++++--
>  1 file changed, 6 insertions(+), 2 deletions(-)
>
> --- a/fs/ext4/extents.c
> +++ b/fs/ext4/extents.c
> @@ -319,9 +319,13 @@ static int ext4_valid_extent(struct inod
>  	ext4_fsblk_t block = ext4_ext_pblock(ext);
>  	int len = ext4_ext_get_actual_len(ext);
>  	ext4_lblk_t lblock = le32_to_cpu(ext->ee_block);
> -	ext4_lblk_t last = lblock + len - 1;
>
> -	if (len == 0 || lblock > last)
> +	/*
> +	 * We allow neither:
> +	 *  - zero length
> +	 *  - overflow/wrap-around
> +	 */
> +	if (lblock + len <= lblock)
>  		return 0;
>  	return ext4_data_block_valid(EXT4_SB(inode->i_sb), block, len);
>  }
>

[toc] | [prev] | [next] | [standalone]


#1521814 — Re: [PATCH 3.2 009/152] ext4: check for extents that wrap around

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 17:20 +0100
SubjectRe: [PATCH 3.2 009/152] ext4: check for extents that wrap around
Message-ID<sDs9c-RG-29@gated-at.bofh.it>
In reply to#1521754

[Multipart message — attachments visible in raw view] — view raw

On Mon, 2016-11-14 at 16:29 +0100, Vegard Nossum wrote:
> On 11/14/2016 01:14 AM, Ben Hutchings wrote:
> > 3.2.84-rc1 review patch.  If anyone has any objections, please let me know.
> 
> Just a general comment on stable review workflow, really:
> 
> It might be more useful to send the diff-of-diffs with the upstream
> commit so I can easily see if you had any conflicts when cherry-picking
> this and how they were resolved.

When there are conflicts, I explain how they were resolved before my
Signed-off-by: line.  In this case there were none.

I'm not going to change to diff-of-diffs unless there is consensus for
this among stable maintainers and reviewers.

[...]
> If you could push this commit to git before sending the review, you
> could also include a command that I can use to quickly do the
> diff-of-diffs myself without having to download and apply the patch (or
> look for it), e.g. something like (using the 3.12 stable commit vs
> upstream):
[...]

You can find all the patches in a 3.2-rc or 3.16-rc review at
<https://git.kernel.org/cgit/linux/kernel/git/bwh/linux-stable-queue.git/>.

Ben.

-- 
Ben Hutchings
If more than one person is responsible for a bug, no one is at fault.

[toc] | [prev] | [next] | [standalone]


#1521026 — [PATCH 3.2 101/152] asm-generic: make copy_from_user() zero the destination properly

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 101/152] asm-generic: make copy_from_user() zero the destination properly
Message-ID<sDfOH-11Z-59@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Al Viro <viro@zeniv.linux.org.uk>

commit 2545e5da080b4839dd859e3b09343a884f6ab0e3 upstream.

... in all cases, including the failing access_ok()

Note that some architectures using asm-generic/uaccess.h have
__copy_from_user() not zeroing the tail on failure halfway
through.  This variant works either way.

Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 include/asm-generic/uaccess.h | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

--- a/include/asm-generic/uaccess.h
+++ b/include/asm-generic/uaccess.h
@@ -243,11 +243,13 @@ extern int __get_user_bad(void) __attrib
 static inline long copy_from_user(void *to,
 		const void __user * from, unsigned long n)
 {
+	unsigned long res = n;
 	might_sleep();
-	if (access_ok(VERIFY_READ, from, n))
-		return __copy_from_user(to, from, n);
-	else
-		return n;
+	if (likely(access_ok(VERIFY_READ, from, n)))
+		res = __copy_from_user(to, from, n);
+	if (unlikely(res))
+		memset(to + (n - res), 0, res);
+	return res;
 }
 
 static inline long copy_to_user(void __user *to,

[toc] | [prev] | [next] | [standalone]


#1521027 — [PATCH 3.2 077/152] USB: serial: option: add WeTelecom WM-D200

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 077/152] USB: serial: option: add WeTelecom WM-D200
Message-ID<sDfOH-11Z-63@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Aleksandr Makarov <aleksandr.o.makarov@gmail.com>

commit 6695593e4a7659db49ac6eca98c164f7b5589f72 upstream.

Add support for WeTelecom WM-D200.

T:  Bus=03 Lev=01 Prnt=01 Port=01 Cnt=01 Dev#=  4 Spd=12  MxCh= 0
D:  Ver= 1.10 Cls=00(>ifc ) Sub=00 Prot=00 MxPS=64 #Cfgs=  1
P:  Vendor=22de ProdID=6801 Rev=00.00
S:  Manufacturer=WeTelecom Incorporated
S:  Product=WeTelecom Mobile Products
C:  #Ifs= 4 Cfg#= 1 Atr=80 MxPwr=500mA
I:  If#= 0 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=ff Driver=(none)
I:  If#= 1 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=ff Driver=(none)
I:  If#= 2 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=ff Driver=(none)
I:  If#= 3 Alt= 0 #EPs= 2 Cls=08(stor.) Sub=06 Prot=50 Driver=usb-storage

Signed-off-by: Aleksandr Makarov <aleksandr.o.makarov@gmail.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/option.c | 5 +++++
 1 file changed, 5 insertions(+)

--- a/drivers/usb/serial/option.c
+++ b/drivers/usb/serial/option.c
@@ -512,6 +512,10 @@ static void option_instat_callback(struc
 #define VIATELECOM_VENDOR_ID			0x15eb
 #define VIATELECOM_PRODUCT_CDS7			0x0001
 
+/* WeTelecom products */
+#define WETELECOM_VENDOR_ID			0x22de
+#define WETELECOM_PRODUCT_WMD200		0x6801
+
 /* some devices interfaces need special handling due to a number of reasons */
 enum option_blacklist_reason {
 		OPTION_BLACKLIST_NONE = 0,
@@ -1948,6 +1952,7 @@ static const struct usb_device_id option
 	{ USB_DEVICE_AND_INTERFACE_INFO(0x07d1, 0x7e11, 0xff, 0xff, 0xff) }, /* D-Link DWM-156/A3 */
 	{ USB_DEVICE(INOVIA_VENDOR_ID, INOVIA_SEW858) },
 	{ USB_DEVICE(VIATELECOM_VENDOR_ID, VIATELECOM_PRODUCT_CDS7) },
+	{ USB_DEVICE_AND_INTERFACE_INFO(WETELECOM_VENDOR_ID, WETELECOM_PRODUCT_WMD200, 0xff, 0xff, 0xff) },
 	{ } /* Terminating entry */
 };
 MODULE_DEVICE_TABLE(usb, option_ids);

[toc] | [prev] | [next] | [standalone]


#1521028 — [PATCH 3.2 125/152] microblaze: fix __get_user()

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 125/152] microblaze: fix __get_user()
Message-ID<sDfOH-11Z-61@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Al Viro <viro@zeniv.linux.org.uk>

commit e98b9e37ae04562d52c96f46b3cf4c2e80222dc1 upstream.

Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 arch/microblaze/include/asm/uaccess.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/microblaze/include/asm/uaccess.h
+++ b/arch/microblaze/include/asm/uaccess.h
@@ -218,7 +218,7 @@ extern long __user_bad(void);
 
 #define __get_user(x, ptr)						\
 ({									\
-	unsigned long __gu_val;						\
+	unsigned long __gu_val = 0;					\
 	/*unsigned long __gu_ptr = (unsigned long)(ptr);*/		\
 	long __gu_err;							\
 	switch (sizeof(*(ptr))) {					\

[toc] | [prev] | [next] | [standalone]


#1521029 — [PATCH 3.2 010/152] ext4: don't call ext4_should_journal_data() on the journal inode

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 010/152] ext4: don't call ext4_should_journal_data() on the journal inode
Message-ID<sDfOH-11Z-67@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Vegard Nossum <vegard.nossum@oracle.com>

commit 6a7fd522a7c94cdef0a3b08acf8e6702056e635c upstream.

If ext4_fill_super() fails early, it's possible for ext4_evict_inode()
to call ext4_should_journal_data() before superblock options and flags
are fully set up.  In that case, the iput() on the journal inode can
end up causing a BUG().

Work around this problem by reordering the tests so we only call
ext4_should_journal_data() after we know it's not the journal inode.

Fixes: 2d859db3e4 ("ext4: fix data corruption in inodes with journalled data")
Fixes: 2b405bfa84 ("ext4: fix data=journal fast mount/umount hang")
Cc: Jan Kara <jack@suse.cz>
Signed-off-by: Vegard Nossum <vegard.nossum@oracle.com>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 fs/ext4/inode.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

--- a/fs/ext4/inode.c
+++ b/fs/ext4/inode.c
@@ -142,9 +142,9 @@ void ext4_evict_inode(struct inode *inod
 		 * Note that directories do not have this problem because they
 		 * don't use page cache.
 		 */
-		if (ext4_should_journal_data(inode) &&
-		    (S_ISLNK(inode->i_mode) || S_ISREG(inode->i_mode)) &&
-		    inode->i_ino != EXT4_JOURNAL_INO) {
+		if (inode->i_ino != EXT4_JOURNAL_INO &&
+		    ext4_should_journal_data(inode) &&
+		    (S_ISLNK(inode->i_mode) || S_ISREG(inode->i_mode))) {
 			journal_t *journal = EXT4_SB(inode->i_sb)->s_journal;
 			tid_t commit_tid = EXT4_I(inode)->i_datasync_tid;
 

[toc] | [prev] | [next] | [standalone]


#1521030 — [PATCH 3.2 041/152] l2tp: Correctly return -EBADF from pppol2tp_getname.

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 041/152] l2tp: Correctly return -EBADF from pppol2tp_getname.
Message-ID<sDfOH-11Z-69@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: "phil.turnbull@oracle.com" <phil.turnbull@oracle.com>

commit 4ac36a4adaf80013a60013d6f829f5863d5d0e05 upstream.

If 'tunnel' is NULL we should return -EBADF but the 'end_put_sess' path
unconditionally sets 'error' back to zero. Rework the error path so it
more closely matches pppol2tp_sendmsg.

Fixes: fd558d186df2 ("l2tp: Split pppol2tp patch into separate l2tp and ppp parts")
Signed-off-by: Phil Turnbull <phil.turnbull@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 net/l2tp/l2tp_ppp.c | 7 ++-----
 1 file changed, 2 insertions(+), 5 deletions(-)

--- a/net/l2tp/l2tp_ppp.c
+++ b/net/l2tp/l2tp_ppp.c
@@ -914,10 +914,8 @@ static int pppol2tp_getname(struct socke
 
 	pls = l2tp_session_priv(session);
 	tunnel = l2tp_sock_to_tunnel(pls->tunnel_sock);
-	if (tunnel == NULL) {
-		error = -EBADF;
+	if (tunnel == NULL)
 		goto end_put_sess;
-	}
 
 	inet = inet_sk(tunnel->sock);
 	if (tunnel->version == 2) {
@@ -955,12 +953,11 @@ static int pppol2tp_getname(struct socke
 	}
 
 	*usockaddr_len = len;
+	error = 0;
 
 	sock_put(pls->tunnel_sock);
 end_put_sess:
 	sock_put(sk);
-	error = 0;
-
 end:
 	return error;
 }

[toc] | [prev] | [next] | [standalone]


#1521032 — [PATCH 3.2 089/152] ALSA: timer: fix NULL pointer dereference in read()/ioctl() race

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 089/152] ALSA: timer: fix NULL pointer dereference in read()/ioctl() race
Message-ID<sDfOH-11Z-65@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Vegard Nossum <vegard.nossum@oracle.com>

commit 11749e086b2766cccf6217a527ef5c5604ba069c upstream.

I got this with syzkaller:

    ==================================================================
    BUG: KASAN: null-ptr-deref on address 0000000000000020
    Read of size 32 by task syz-executor/22519
    CPU: 1 PID: 22519 Comm: syz-executor Not tainted 4.8.0-rc2+ #169
    Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.9.3-0-ge2fc41e-prebuilt.qemu-project.org 04/01/2
    014
     0000000000000001 ffff880111a17a00 ffffffff81f9f141 ffff880111a17a90
     ffff880111a17c50 ffff880114584a58 ffff880114584a10 ffff880111a17a80
     ffffffff8161fe3f ffff880100000000 ffff880118d74a48 ffff880118d74a68
    Call Trace:
     [<ffffffff81f9f141>] dump_stack+0x83/0xb2
     [<ffffffff8161fe3f>] kasan_report_error+0x41f/0x4c0
     [<ffffffff8161ff74>] kasan_report+0x34/0x40
     [<ffffffff82c84b54>] ? snd_timer_user_read+0x554/0x790
     [<ffffffff8161e79e>] check_memory_region+0x13e/0x1a0
     [<ffffffff8161e9c1>] kasan_check_read+0x11/0x20
     [<ffffffff82c84b54>] snd_timer_user_read+0x554/0x790
     [<ffffffff82c84600>] ? snd_timer_user_info_compat.isra.5+0x2b0/0x2b0
     [<ffffffff817d0831>] ? proc_fault_inject_write+0x1c1/0x250
     [<ffffffff817d0670>] ? next_tgid+0x2a0/0x2a0
     [<ffffffff8127c278>] ? do_group_exit+0x108/0x330
     [<ffffffff8174653a>] ? fsnotify+0x72a/0xca0
     [<ffffffff81674dfe>] __vfs_read+0x10e/0x550
     [<ffffffff82c84600>] ? snd_timer_user_info_compat.isra.5+0x2b0/0x2b0
     [<ffffffff81674cf0>] ? do_sendfile+0xc50/0xc50
     [<ffffffff81745e10>] ? __fsnotify_update_child_dentry_flags+0x60/0x60
     [<ffffffff8143fec6>] ? kcov_ioctl+0x56/0x190
     [<ffffffff81e5ada2>] ? common_file_perm+0x2e2/0x380
     [<ffffffff81746b0e>] ? __fsnotify_parent+0x5e/0x2b0
     [<ffffffff81d93536>] ? security_file_permission+0x86/0x1e0
     [<ffffffff816728f5>] ? rw_verify_area+0xe5/0x2b0
     [<ffffffff81675355>] vfs_read+0x115/0x330
     [<ffffffff81676371>] SyS_read+0xd1/0x1a0
     [<ffffffff816762a0>] ? vfs_write+0x4b0/0x4b0
     [<ffffffff82001c2c>] ? __this_cpu_preempt_check+0x1c/0x20
     [<ffffffff8150455a>] ? __context_tracking_exit.part.4+0x3a/0x1e0
     [<ffffffff816762a0>] ? vfs_write+0x4b0/0x4b0
     [<ffffffff81005524>] do_syscall_64+0x1c4/0x4e0
     [<ffffffff810052fc>] ? syscall_return_slowpath+0x16c/0x1d0
     [<ffffffff83c3276a>] entry_SYSCALL64_slow_path+0x25/0x25
    ==================================================================

There are a couple of problems that I can see:

 - ioctl(SNDRV_TIMER_IOCTL_SELECT), which potentially sets
   tu->queue/tu->tqueue to NULL on memory allocation failure, so read()
   would get a NULL pointer dereference like the above splat

 - the same ioctl() can free tu->queue/to->tqueue which means read()
   could potentially see (and dereference) the freed pointer

We can fix both by taking the ioctl_lock mutex when dereferencing
->queue/->tqueue, since that's always held over all the ioctl() code.

Just looking at the code I find it likely that there are more problems
here such as tu->qhead pointing outside the buffer if the size is
changed concurrently using SNDRV_TIMER_IOCTL_PARAMS.

Signed-off-by: Vegard Nossum <vegard.nossum@oracle.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 sound/core/timer.c | 2 ++
 1 file changed, 2 insertions(+)

--- a/sound/core/timer.c
+++ b/sound/core/timer.c
@@ -1941,6 +1941,7 @@ static ssize_t snd_timer_user_read(struc
 		tu->qused--;
 		spin_unlock_irq(&tu->qlock);
 
+		mutex_lock(&tu->ioctl_lock);
 		if (tu->tread) {
 			if (copy_to_user(buffer, &tu->tqueue[qhead],
 					 sizeof(struct snd_timer_tread)))
@@ -1950,6 +1951,7 @@ static ssize_t snd_timer_user_read(struc
 					 sizeof(struct snd_timer_read)))
 				err = -EFAULT;
 		}
+		mutex_unlock(&tu->ioctl_lock);
 
 		spin_lock_irq(&tu->qlock);
 		if (err < 0)

[toc] | [prev] | [next] | [standalone]


#1521033 — [PATCH 3.2 045/152] drm/radeon: fix firmware info version checks

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 045/152] drm/radeon: fix firmware info version checks
Message-ID<sDfOH-11Z-73@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Alex Deucher <alexander.deucher@amd.com>

commit 3edc38a0facef45ee22af8afdce3737f421f36ab upstream.

Some of the checks didn't handle frev 2 tables properly.

Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/gpu/drm/radeon/radeon_atombios.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/gpu/drm/radeon/radeon_atombios.c
+++ b/drivers/gpu/drm/radeon/radeon_atombios.c
@@ -1138,7 +1138,7 @@ bool radeon_atom_get_clock_info(struct d
 		    le16_to_cpu(firmware_info->info.usReferenceClock);
 		p1pll->reference_div = 0;
 
-		if (crev < 2)
+		if ((frev < 2) && (crev < 2))
 			p1pll->pll_out_min =
 				le16_to_cpu(firmware_info->info.usMinPixelClockPLL_Output);
 		else
@@ -1147,7 +1147,7 @@ bool radeon_atom_get_clock_info(struct d
 		p1pll->pll_out_max =
 		    le32_to_cpu(firmware_info->info.ulMaxPixelClockPLL_Output);
 
-		if (crev >= 4) {
+		if (((frev < 2) && (crev >= 4)) || (frev >= 2)) {
 			p1pll->lcd_pll_out_min =
 				le16_to_cpu(firmware_info->info_14.usLcdMinPixelClockPLL_Output) * 100;
 			if (p1pll->lcd_pll_out_min == 0)

[toc] | [prev] | [next] | [standalone]


#1521034 — [PATCH 3.2 053/152] dm flakey: error READ bios during the down_interval

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 053/152] dm flakey: error READ bios during the down_interval
Message-ID<sDfOH-11Z-75@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Mike Snitzer <snitzer@redhat.com>

commit 99f3c90d0d85708e7401a81ce3314e50bf7f2819 upstream.

When the corrupt_bio_byte feature was introduced it caused READ bios to
no longer be errored with -EIO during the down_interval.  This had to do
with the complexity of needing to submit READs if the corrupt_bio_byte
feature was used.

Fix it so READ bios are properly errored with -EIO; doing so early in
flakey_map() as long as there isn't a match for the corrupt_bio_byte
feature.

Fixes: a3998799fb4df ("dm flakey: add corrupt_bio_byte feature")
Reported-by: Akira Hayakawa <ruby.wktk@gmail.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
[bwh: Backported to 3.2: in flakey_end_io(), keep using
 bio_submitted_while_down instead of pb->bio_submitted]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/md/dm-flakey.c | 23 +++++++++++++++--------
 1 file changed, 15 insertions(+), 8 deletions(-)

--- a/drivers/md/dm-flakey.c
+++ b/drivers/md/dm-flakey.c
@@ -279,10 +279,16 @@ static int flakey_map(struct dm_target *
 		map_context->ll = 1;
 
 		/*
-		 * Map reads as normal.
+		 * Map reads as normal only if corrupt_bio_byte set.
 		 */
-		if (bio_data_dir(bio) == READ)
-			goto map_bio;
+		if (bio_data_dir(bio) == READ) {
+			/* If flags were specified, only corrupt those that match. */
+			if (fc->corrupt_bio_byte && (fc->corrupt_bio_rw == READ) &&
+			    all_corrupt_bio_flags_match(bio, fc))
+				goto map_bio;
+			else
+				return -EIO;
+		}
 
 		/*
 		 * Drop writes?
@@ -321,12 +327,13 @@ static int flakey_end_io(struct dm_targe
 
 	/*
 	 * Corrupt successful READs while in down state.
-	 * If flags were specified, only corrupt those that match.
 	 */
-	if (fc->corrupt_bio_byte && !error && bio_submitted_while_down &&
-	    (bio_data_dir(bio) == READ) && (fc->corrupt_bio_rw == READ) &&
-	    all_corrupt_bio_flags_match(bio, fc))
-		corrupt_bio_data(bio, fc);
+	if (!error && bio_submitted_while_down && (bio_data_dir(bio) == READ)) {
+		if (fc->corrupt_bio_byte)
+			corrupt_bio_data(bio, fc);
+		else
+			return -EIO;
+	}
 
 	return error;
 }

[toc] | [prev] | [next] | [standalone]


#1521036 — [PATCH 3.2 030/152] crypto: scatterwalk - Fix test in scatterwalk_done

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 030/152] crypto: scatterwalk - Fix test in scatterwalk_done
Message-ID<sDfOI-11Z-81@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

commit 5f070e81bee35f1b7bd1477bb223a873ff657803 upstream.

When there is more data to be processed, the current test in
scatterwalk_done may prevent us from calling pagedone even when
we should.

In particular, if we're on an SG entry spanning multiple pages
where the last page is not a full page, we will incorrectly skip
calling pagedone on the second last page.

This patch fixes this by adding a separate test for whether we've
reached the end of a page.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 crypto/scatterwalk.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/crypto/scatterwalk.c
+++ b/crypto/scatterwalk.c
@@ -68,7 +68,8 @@ static void scatterwalk_pagedone(struct
 
 void scatterwalk_done(struct scatter_walk *walk, int out, int more)
 {
-	if (!(scatterwalk_pagelen(walk) & (PAGE_SIZE - 1)) || !more)
+	if (!more || walk->offset >= walk->sg->offset + walk->sg->length ||
+	    !(walk->offset & (PAGE_SIZE - 1)))
 		scatterwalk_pagedone(walk, out, more);
 }
 EXPORT_SYMBOL_GPL(scatterwalk_done);

[toc] | [prev] | [next] | [standalone]


#1521037 — [PATCH 3.2 131/152] openrisc: fix the fix of copy_from_user()

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 131/152] openrisc: fix the fix of copy_from_user()
Message-ID<sDfOI-11Z-79@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Guenter Roeck <linux@roeck-us.net>

commit 8e4b72054f554967827e18be1de0e8122e6efc04 upstream.

Since commit acb2505d0119 ("openrisc: fix copy_from_user()"),
copy_from_user() returns the number of bytes requested, not the
number of bytes not copied.

Cc: Al Viro <viro@zeniv.linux.org.uk>
Fixes: acb2505d0119 ("openrisc: fix copy_from_user()")
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 arch/openrisc/include/asm/uaccess.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/openrisc/include/asm/uaccess.h
+++ b/arch/openrisc/include/asm/uaccess.h
@@ -277,7 +277,7 @@ copy_from_user(void *to, const void *fro
 	unsigned long res = n;
 
 	if (likely(access_ok(VERIFY_READ, from, n)))
-		n = __copy_tofrom_user(to, from, n);
+		res = __copy_tofrom_user(to, from, n);
 	if (unlikely(res))
 		memset(to + (n - res), 0, res);
 	return res;

[toc] | [prev] | [next] | [standalone]


#1521038 — [PATCH 3.2 066/152] arm: oabi compat: add missing access checks

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 066/152] arm: oabi compat: add missing access checks
Message-ID<sDfOI-11Z-83@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Dave Weinstein <olorin@google.com>

commit 7de249964f5578e67b99699c5f0b405738d820a2 upstream.

Add access checks to sys_oabi_epoll_wait() and sys_oabi_semtimedop().
This fixes CVE-2016-3857, a local privilege escalation under
CONFIG_OABI_COMPAT.

Reported-by: Chiachih Wu <wuchiachih@gmail.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Reviewed-by: Nicolas Pitre <nico@linaro.org>
Signed-off-by: Dave Weinstein <olorin@google.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 arch/arm/kernel/sys_oabi-compat.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

--- a/arch/arm/kernel/sys_oabi-compat.c
+++ b/arch/arm/kernel/sys_oabi-compat.c
@@ -275,8 +275,12 @@ asmlinkage long sys_oabi_epoll_wait(int
 	mm_segment_t fs;
 	long ret, err, i;
 
-	if (maxevents <= 0 || maxevents > (INT_MAX/sizeof(struct epoll_event)))
+	if (maxevents <= 0 ||
+			maxevents > (INT_MAX/sizeof(*kbuf)) ||
+			maxevents > (INT_MAX/sizeof(*events)))
 		return -EINVAL;
+	if (!access_ok(VERIFY_WRITE, events, sizeof(*events) * maxevents))
+		return -EFAULT;
 	kbuf = kmalloc(sizeof(*kbuf) * maxevents, GFP_KERNEL);
 	if (!kbuf)
 		return -ENOMEM;
@@ -313,6 +317,8 @@ asmlinkage long sys_oabi_semtimedop(int
 
 	if (nsops < 1 || nsops > SEMOPM)
 		return -EINVAL;
+	if (!access_ok(VERIFY_READ, tsops, sizeof(*tsops) * nsops))
+		return -EFAULT;
 	sops = kmalloc(sizeof(*sops) * nsops, GFP_KERNEL);
 	if (!sops)
 		return -ENOMEM;

[toc] | [prev] | [next] | [standalone]


#1521039 — [PATCH 3.2 112/152] mn10300: copy_from_user() should zero on access_ok() failure...

FromBen Hutchings <ben@decadent.org.uk>
Date2016-11-14 04:10 +0100
Subject[PATCH 3.2 112/152] mn10300: copy_from_user() should zero on access_ok() failure...
Message-ID<sDfOI-11Z-87@gated-at.bofh.it>
In reply to#1521019
3.2.84-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Al Viro <viro@zeniv.linux.org.uk>

commit ae7cc577ec2a4a6151c9e928fd1f595d953ecef1 upstream.

Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
[bwh: Backported to 3.2: include <linux/string.h> to get declaration of memset()]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 arch/mn10300/lib/usercopy.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/arch/mn10300/lib/usercopy.c
+++ b/arch/mn10300/lib/usercopy.c
@@ -9,7 +9,8 @@
  * as published by the Free Software Foundation; either version
  * 2 of the Licence, or (at your option) any later version.
  */
-#include <asm/uaccess.h>
+#include <linux/string.h>
+#include <linux/uaccess.h>
 
 unsigned long
 __generic_copy_to_user(void *to, const void *from, unsigned long n)
@@ -24,6 +25,8 @@ __generic_copy_from_user(void *to, const
 {
 	if (access_ok(VERIFY_READ, from, n))
 		__copy_user_zeroing(to, from, n);
+	else
+		memset(to, 0, n);
 	return n;
 }
 

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.kernel


csiph-web