Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1499654 > unrolled thread
| Started by | lizf@kernel.org |
|---|---|
| First post | 2016-10-12 15:10 +0200 |
| Last post | 2016-10-13 03:10 +0200 |
| Articles | 6 — 3 participants |
Back to article view | Back to linux.kernel
[PATCH 3.4 000/125] 3.4.113-rc1 review lizf@kernel.org - 2016-10-12 15:10 +0200
[PATCH 3.4 116/125] sctp: Prevent soft lockup when sctp_accept() is called during a timeout event lizf@kernel.org - 2016-10-12 15:10 +0200
[PATCH 3.4 105/125] parisc: Fix syscall restarts lizf@kernel.org - 2016-10-12 15:10 +0200
[PATCH 3.4 075/125] rfkill: copy the name into the rfkill struct lizf@kernel.org - 2016-10-12 15:10 +0200
Re: [PATCH 3.4 000/125] 3.4.113-rc1 review Guenter Roeck <linux@roeck-us.net> - 2016-10-12 19:00 +0200
Re: [PATCH 3.4 000/125] 3.4.113-rc1 review Zefan Li <lizefan@huawei.com> - 2016-10-13 03:10 +0200
| From | lizf@kernel.org |
|---|---|
| Date | 2016-10-12 15:10 +0200 |
| Subject | [PATCH 3.4 000/125] 3.4.113-rc1 review |
| Message-ID | <srqZb-4nM-3@gated-at.bofh.it> |
From: Zefan Li <lizefan@huawei.com>
This is the start of the stable review cycle for the 3.4.113 release.
There are 125 patches in this series, all will be posted as a response
to this one. If anyone has any issues with these being applied, please
let me know.
Responses should be made by Fri Oct 14 12:32:05 UTC 2016.
Anything received after that time might be too late.
A combined patch relative to 3.4.112 will be posted as an additional
response to this. A shortlog and diffstat can be found below.
thanks,
Zefan Li
--------------------
Aaro Koskinen (1):
broadcom: fix PHY_ID_BCM5481 entry in the id table
Al Viro (2):
fix sysvfs symlinks
9p: ->evict_inode() should kick out ->i_data, not ->i_mapping
Alan Stern (1):
USB: fix invalid memory access in hub_activate()
Aleksander Morgado (1):
USB: serial: option: add support for Novatel MiFi USB620L
Alexey Khoroshilov (1):
USB: whci-hcd: add check for dma mapping error
Andrew Banman (1):
mm/memory_hotplug.c: check for missing sections in
test_pages_in_a_zone()
Andrey Ryabinin (1):
ipv6/addrlabel: fix ip6addrlbl_get()
Anson Huang (1):
ARM: 8471/1: need to save/restore arm register(r11) when it is
corrupted
Arnd Bergmann (1):
ARM: pxa: remove incorrect __init annotation on pxa27x_set_pwrmode
Ben Hutchings (1):
USB: ti_usb_3410_502: Fix ID table size
Bjørn Mork (1):
USB: option: add XS Stick W100-2 from 4G Systems
Boris BREZILLON (1):
mtd: mtdpart: fix add_mtd_partitions error path
Borislav Petkov (1):
x86/cpu: Call verify_cpu() after having entered long mode too
Chen Yu (1):
ACPI: Use correct IRQ when uninstalling ACPI interrupt handler
Christoph Hellwig (1):
scsi: restart list search after unlock in scsi_remove_target
Chunfeng Yun (1):
usb: xhci: fix config fail of FS hub behind a HS hub with MTT
Clemens Ladisch (3):
ALSA: usb-audio: add packet size quirk for the Medeli DD305
ALSA: usb-audio: prevent CH345 multiport output SysEx corruption
ALSA: usb-audio: work around CH345 input SysEx corruption
Colin Ian King (1):
ftrace/scripts: Fix incorrect use of sprintf in recordmcount
Daeho Jeong (1):
ext4, jbd2: ensure entering into panic after recording an error in
superblock
Dan Carpenter (4):
mwifiex: fix mwifiex_rdeeprom_read()
devres: fix a for loop bounds check
mISDN: fix a loop count
USB: ipaq.c: fix a timeout loop
Dave Airlie (1):
drm/radeon: fix hotplug race at startup
David Howells (2):
FS-Cache: Handle a write to the page immediately beyond the EOF marker
KEYS: Fix race between read and revoke
David Turner (1):
ext4: Fix handling of extended tv_sec
David Vrabel (3):
xen: Add RING_COPY_REQUEST()
xen-netback: don't use last request to determine minimum Tx credit
xen-netback: use RING_COPY_REQUEST() throughout
David Woodhouse (1):
iommu/vt-d: Fix ATSR handling for Root-Complex integrated endpoints
Dmitry Tunin (1):
Bluetooth: ath3k: Add support of AR3012 0cf3:817b device
Dmitry V. Levin (1):
x86/signal: Fix restart_syscall number for x32 tasks
Eric Dumazet (5):
net: fix a race in dst_release()
tcp: md5: fix lockdep annotation
af_unix: fix a fatal race with bit fields
udp: properly support MSG_PEEK with truncated buffers
tcp: make challenge acks less predictable
Filipe Manana (1):
Btrfs: fix race leading to BUG_ON when running delalloc for nodatacow
Francesco Ruggeri (1):
net: possible use after free in dst_release
Helge Deller (1):
parisc: Fix syscall restarts
Herbert Xu (2):
crypto: algif_hash - Only export and import on sockets with data
net: Fix skb csum races when peeking
James Bottomley (2):
ses: Fix problems with simple enclosures
ses: fix additional element traversal bug
Jan Kara (3):
vfs: Make sendfile(2) killable even better
vfs: Avoid softlockups with sendfile(2)
jbd2: Fix unreclaimed pages after truncate in data=journal mode
Jason A. Donenfeld (1):
crypto: skcipher - Copy iv from desc even for 0-len walks
Jeff Layton (1):
nfs: if we have no valid attrs, then don't declare the attribute cache
valid
Jiri Slaby (1):
usblp: do not set TASK_INTERRUPTIBLE before lock
Joe Thornber (1):
dm btree: fix bufio buffer leaks in dm_btree_del() error path
Johan Hovold (1):
spi: fix parent-device reference leak
Johannes Berg (3):
mac80211: fix driver RSSI event calculations
mac80211: mesh: fix call_rcu() usage
rfkill: copy the name into the rfkill struct
John Stultz (1):
time: Prevent early expiry of hrtimers[CLOCK_REALTIME] at the leap
second edge
Joseph Qi (1):
ocfs2: fix BUG when calculate new backup super
Karl Heiss (1):
sctp: Prevent soft lockup when sctp_accept() is called during a
timeout event
Kees Cook (1):
mac: validate mac_partition is within sector
Kinglong Mee (2):
FS-Cache: Increase reference of parent after registering, netfs
success
FS-Cache: Don't override netfs's primary_index if registering failed
Kirill A. Shutemov (1):
vgaarb: fix signal handling in vga_get()
Konrad Rzeszutek Wilk (6):
xen/pciback: Save xen_pci_op commands before processing it
xen/pciback: Return error on XEN_PCI_OP_enable_msi when device has MSI
or MSI-X enabled
xen/pciback: Return error on XEN_PCI_OP_enable_msix when device has
MSI or MSI-X enabled
xen/pciback: Do not install an IRQ handler for MSI interrupts.
xen/pciback: For XEN_PCI_OP_disable_msi[|x] only disable if device has
MSI(X) enabled.
xen/pciback: Don't allow MSI-X ops if PCI_COMMAND_MEMORY is not set.
Konstantin Khlebnikov (1):
net/neighbour: fix crash at dumping device-agnostic proxy entries
Konstantin Shkolnyy (1):
USB: cp210x: Remove CP2110 ID from compatibility list
Larry Finger (1):
staging: rtl8712: Add device ID for Sitecom WLA2100
Maciej W. Rozycki (1):
binfmt_elf: Don't clobber passed executable's file header
Mauricio Faria de Oliveira (1):
Revert "dm mpath: fix stalls when handling invalid ioctls"
Michal Hocko (1):
mm, vmstat: allow WQ concurrency to discover memory reclaim doesn't
make any progress
Michal Kubeček (3):
ipv6: fix tunnel error handling
ipv6: update ip6_rt_last_gc every time GC is run
ipv6: don't call fib6_run_gc() until routing is ready
Mike Snitzer (1):
dm btree: fix leak of bufio-backed block in btree_split_sibling error
path
Mikulas Patocka (2):
sata_sil: disable trim
parisc iommu: fix panic due to trying to allocate too large region
Mirza Krak (1):
can: sja1000: clear interrupts on start
Naoya Horiguchi (1):
mm: hugetlb: call huge_pte_alloc() only if ptep is null
Nicolas Dichtel (1):
ipv6: fix handling of blackhole and prohibit routes
Nikolay Aleksandrov (2):
net: fix __netdev_update_features return on ndo_set_features failure
net: ip6mr: fix static mfc/dev leaks on table destruction
Peter Hurley (2):
wan/x25: Fix use-after-free in x25_asy_open_tty()
tty: Fix GPF in flush_to_ldisc()
Peter Oberparleiter (1):
scsi_sysfs: Fix queue_ramp_up_period return code
Peter Zijlstra (1):
perf: Fix inherited events vs. tracepoint filters
Ralf Baechle (1):
MIPS: atomic: Fix comment describing atomic64_add_unless's return
value.
Richard Purdie (1):
HID: core: Avoid uninitialized buffer access
Roger Pau Monné (1):
xen-blkback: only read request operation from shared ring once
Roman Gushchin (1):
fuse: break infinite loop in fuse_fill_write_pages()
Russell King (1):
scripts: recordmcount: break hardlinks
Sabrina Dubroca (1):
macvlan: fix leak in macvlan_handle_frame
Sachin Pandhare (1):
ASoC: wm8962: correct addresses for HPF_C_0/1
Sergei Shtylyov (1):
sh_eth: fix TX buffer byte-swapping
Stefan Richter (1):
firewire: ohci: fix JMicron JMB38x IT context discovery
Steven Rostedt (Red Hat) (2):
ring-buffer: Update read stamp with first real commit on page
ftrace/scripts: Have recordmcount copy the object file
Takashi Iwai (3):
ALSA: hda - Disable 64bit address for Creative HDA controllers
ALSA: hda - Apply pin fixup for HP ProBook 6550b
ALSA: rme96: Fix unexpected volume reset after rate changes
Thomas Gleixner (1):
genirq: Prevent chip buslock deadlock
Thomas Hellstrom (1):
drm/ttm: Fixed a read/write lock imbalance
Tilman Schmidt (1):
ser_gigaset: fix deallocation of platform device structure
Uwe Kleine-König (1):
usb: musb: core: fix order of arguments to ulpi write callback
Valentin Rothberg (1):
wm831x_power: Use IRQF_ONESHOT to request threaded IRQs
Vladimir Zapolskiy (1):
iio: lpc32xx_adc: fix warnings caused by enabling unprepared clock
WANG Cong (1):
ip6mr: call del_timer_sync() in ip6mr_free_table()
Xiangliang Yu (1):
AHCI: Fix softreset failed issue of Port Multiplier
Xunlei Pang (1):
sched/core: Clear the root_domain cpumasks in init_rootdomain()
Zefan Li (4):
Fix incomplete backport of commit 423f04d63cf4
Fix incomplete backport of commit 0f792cf949a0
Revert "USB: Add device quirk for ASUS T100 Base Station keyboard"
Revert "USB: Add OTG PET device to TPL"
libin (1):
recordmcount: Fix endianness handling bug for nop_mcount
lucien (2):
sctp: translate host order to network order when setting a hmacid
sctp: start t5 timer only when peer rwnd is 0 and local state is
SHUTDOWN_PENDING
sumit.saxena@avagotech.com (2):
megaraid_sas: Do not use PAGE_SIZE for max_sectors
megaraid_sas : SMAP restriction--do not access user memory from IOCTL
code
arch/arm/mach-pxa/include/mach/pxa27x.h | 2 +-
arch/arm/mach-pxa/pxa27x.c | 2 +-
arch/arm/mm/proc-v7.S | 4 +-
arch/mips/include/asm/atomic.h | 2 +-
arch/parisc/kernel/signal.c | 67 +++++++++++----
arch/x86/kernel/head_64.S | 8 ++
arch/x86/kernel/signal.c | 17 ++--
arch/x86/kernel/verify_cpu.S | 12 +--
block/partitions/mac.c | 10 ++-
crypto/ablkcipher.c | 2 +-
crypto/algif_hash.c | 12 ++-
crypto/blkcipher.c | 2 +-
drivers/acpi/osl.c | 9 +-
drivers/ata/libahci.c | 9 ++
drivers/ata/sata_sil.c | 3 +
drivers/block/xen-blkback/common.h | 8 +-
drivers/bluetooth/ath3k.c | 2 +
drivers/bluetooth/btusb.c | 1 +
drivers/firewire/ohci.c | 5 ++
drivers/gpu/drm/radeon/radeon_irq_kms.c | 5 ++
drivers/gpu/drm/ttm/ttm_lock.c | 2 +-
drivers/gpu/vga/vgaarb.c | 6 +-
drivers/hid/hid-core.c | 2 +-
drivers/iommu/intel-iommu.c | 7 +-
drivers/isdn/gigaset/ser-gigaset.c | 10 ++-
drivers/isdn/hardware/mISDN/mISDNipac.c | 7 +-
drivers/md/dm-mpath.c | 7 +-
drivers/md/persistent-data/dm-btree.c | 20 ++++-
drivers/md/raid1.c | 3 -
drivers/mtd/mtdpart.c | 4 +-
drivers/net/can/sja1000/sja1000.c | 3 +
drivers/net/ethernet/renesas/sh_eth.c | 3 +-
drivers/net/macvlan.c | 2 +
drivers/net/phy/broadcom.c | 2 +-
drivers/net/wan/x25_asy.c | 6 +-
drivers/net/wireless/mwifiex/debugfs.c | 14 +--
drivers/net/xen-netback/netback.c | 34 ++++----
drivers/parisc/iommu-helpers.h | 15 ++--
drivers/power/wm831x_power.c | 6 +-
drivers/scsi/megaraid/megaraid_sas.h | 2 +
drivers/scsi/megaraid/megaraid_sas_base.c | 15 +++-
drivers/scsi/scsi_sysfs.c | 18 ++--
drivers/scsi/ses.c | 30 ++++++-
drivers/spi/spi.c | 2 +-
drivers/staging/iio/adc/lpc32xx_adc.c | 4 +-
drivers/staging/rtl8712/usb_intf.c | 1 +
drivers/tty/tty_buffer.c | 3 +-
drivers/usb/class/usblp.c | 2 +-
drivers/usb/core/hub.c | 29 +++++--
drivers/usb/core/otg_whitelist.h | 5 --
drivers/usb/core/quirks.c | 8 --
drivers/usb/host/whci/qset.c | 4 +
drivers/usb/host/xhci.c | 8 ++
drivers/usb/musb/musb_core.c | 10 +--
drivers/usb/serial/cp210x.c | 1 -
drivers/usb/serial/ipaq.c | 3 +-
drivers/usb/serial/option.c | 11 +++
drivers/usb/serial/ti_usb_3410_5052.c | 4 +-
drivers/xen/xen-pciback/pciback.h | 1 +
drivers/xen/xen-pciback/pciback_ops.c | 75 ++++++++++++----
fs/9p/vfs_inode.c | 4 +-
fs/binfmt_elf.c | 10 +--
fs/btrfs/inode.c | 10 ++-
fs/cachefiles/rdwr.c | 78 +++++++++--------
fs/ext4/ext4.h | 51 +++++++++--
fs/ext4/super.c | 12 ++-
fs/fscache/netfs.c | 34 ++++----
fs/fscache/page.c | 2 +-
fs/fuse/file.c | 2 +-
fs/jbd2/journal.c | 6 +-
fs/jbd2/transaction.c | 2 +
fs/nfs/inode.c | 6 +-
fs/ocfs2/resize.c | 15 +++-
fs/splice.c | 8 ++
fs/sysv/inode.c | 10 +--
include/linux/acpi.h | 6 ++
include/linux/enclosure.h | 4 +
include/linux/jbd2.h | 1 +
include/linux/usb/quirks.h | 3 -
include/net/af_unix.h | 5 +-
include/net/ip6_fib.h | 1 +
include/net/ndisc.h | 2 +
include/net/sctp/structs.h | 3 +-
include/xen/interface/io/ring.h | 14 +++
kernel/events/core.c | 4 +
kernel/irq/manage.c | 6 +-
kernel/sched/core.c | 6 +-
kernel/time/ntp.c | 45 ++++++++--
kernel/time/timekeeping.c | 37 +++++++-
kernel/trace/ring_buffer.c | 12 ++-
lib/devres.c | 2 +-
mm/backing-dev.c | 19 ++++-
mm/hugetlb.c | 22 +++--
mm/memory_hotplug.c | 31 ++++---
mm/vmstat.c | 6 +-
net/core/datagram.c | 3 +-
net/core/dev.c | 2 +-
net/core/dst.c | 3 +-
net/core/neighbour.c | 4 +-
net/ipv4/tcp_input.c | 13 ++-
net/ipv4/tcp_ipv4.c | 3 +-
net/ipv4/udp.c | 6 +-
net/ipv6/addrlabel.c | 2 +-
net/ipv6/af_inet6.c | 6 ++
net/ipv6/ip6_fib.c | 6 +-
net/ipv6/ip6mr.c | 17 ++--
net/ipv6/ndisc.c | 18 ++--
net/ipv6/route.c | 36 ++++++--
net/ipv6/tunnel6.c | 12 ++-
net/ipv6/udp.c | 6 +-
net/mac80211/mesh_pathtbl.c | 8 +-
net/mac80211/mlme.c | 2 +-
net/rfkill/core.c | 6 +-
net/sctp/auth.c | 4 +-
net/sctp/outqueue.c | 1 +
net/sctp/sm_sideeffect.c | 34 ++++----
net/sctp/sm_statefuns.c | 3 +-
net/unix/garbage.c | 12 +--
scripts/recordmcount.c | 137 ++++++++++++++++++++++++------
scripts/recordmcount.h | 2 +-
security/keys/keyctl.c | 18 ++--
sound/pci/hda/hda_intel.c | 2 +
sound/pci/hda/patch_sigmatel.c | 1 +
sound/pci/rme96.c | 41 +++++----
sound/soc/codecs/wm8962.c | 4 +-
sound/usb/midi.c | 46 ++++++++++
sound/usb/quirks-table.h | 11 +++
sound/usb/quirks.c | 1 +
sound/usb/usbaudio.h | 1 +
129 files changed, 1078 insertions(+), 443 deletions(-)
--
1.9.1
[toc] | [next] | [standalone]
| From | lizf@kernel.org |
|---|---|
| Date | 2016-10-12 15:10 +0200 |
| Subject | [PATCH 3.4 116/125] sctp: Prevent soft lockup when sctp_accept() is called during a timeout event |
| Message-ID | <srrsf-4OM-83@gated-at.bofh.it> |
| In reply to | #1499654 |
From: Karl Heiss <kheiss@gmail.com>
3.4.113-rc1 review patch. If anyone has any objections, please let me know.
------------------
commit 635682a14427d241bab7bbdeebb48a7d7b91638e upstream.
A case can occur when sctp_accept() is called by the user during
a heartbeat timeout event after the 4-way handshake. Since
sctp_assoc_migrate() changes both assoc->base.sk and assoc->ep, the
bh_sock_lock in sctp_generate_heartbeat_event() will be taken with
the listening socket but released with the new association socket.
The result is a deadlock on any future attempts to take the listening
socket lock.
Note that this race can occur with other SCTP timeouts that take
the bh_lock_sock() in the event sctp_accept() is called.
BUG: soft lockup - CPU#9 stuck for 67s! [swapper:0]
...
RIP: 0010:[<ffffffff8152d48e>] [<ffffffff8152d48e>] _spin_lock+0x1e/0x30
RSP: 0018:ffff880028323b20 EFLAGS: 00000206
RAX: 0000000000000002 RBX: ffff880028323b20 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffff880028323be0 RDI: ffff8804632c4b48
RBP: ffffffff8100bb93 R08: 0000000000000000 R09: 0000000000000000
R10: ffff880610662280 R11: 0000000000000100 R12: ffff880028323aa0
R13: ffff8804383c3880 R14: ffff880028323a90 R15: ffffffff81534225
FS: 0000000000000000(0000) GS:ffff880028320000(0000) knlGS:0000000000000000
CS: 0010 DS: 0018 ES: 0018 CR0: 000000008005003b
CR2: 00000000006df528 CR3: 0000000001a85000 CR4: 00000000000006e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Process swapper (pid: 0, threadinfo ffff880616b70000, task ffff880616b6cab0)
Stack:
ffff880028323c40 ffffffffa01c2582 ffff880614cfb020 0000000000000000
<d> 0100000000000000 00000014383a6c44 ffff8804383c3880 ffff880614e93c00
<d> ffff880614e93c00 0000000000000000 ffff8804632c4b00 ffff8804383c38b8
Call Trace:
<IRQ>
[<ffffffffa01c2582>] ? sctp_rcv+0x492/0xa10 [sctp]
[<ffffffff8148c559>] ? nf_iterate+0x69/0xb0
[<ffffffff814974a0>] ? ip_local_deliver_finish+0x0/0x2d0
[<ffffffff8148c716>] ? nf_hook_slow+0x76/0x120
[<ffffffff814974a0>] ? ip_local_deliver_finish+0x0/0x2d0
[<ffffffff8149757d>] ? ip_local_deliver_finish+0xdd/0x2d0
[<ffffffff81497808>] ? ip_local_deliver+0x98/0xa0
[<ffffffff81496ccd>] ? ip_rcv_finish+0x12d/0x440
[<ffffffff81497255>] ? ip_rcv+0x275/0x350
[<ffffffff8145cfeb>] ? __netif_receive_skb+0x4ab/0x750
...
With lockdep debugging:
=====================================
[ BUG: bad unlock balance detected! ]
-------------------------------------
CslRx/12087 is trying to release lock (slock-AF_INET) at:
[<ffffffffa01bcae0>] sctp_generate_timeout_event+0x40/0xe0 [sctp]
but there are no more locks to release!
other info that might help us debug this:
2 locks held by CslRx/12087:
#0: (&asoc->timers[i]){+.-...}, at: [<ffffffff8108ce1f>] run_timer_softirq+0x16f/0x3e0
#1: (slock-AF_INET){+.-...}, at: [<ffffffffa01bcac3>] sctp_generate_timeout_event+0x23/0xe0 [sctp]
Ensure the socket taken is also the same one that is released by
saving a copy of the socket before entering the timeout event
critical section.
Signed-off-by: Karl Heiss <kheiss@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[bwh: Backported to 3.2:
- Net namespaces are not used
- Keep using sctp_bh_{,un}lock_sock()
- Adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
net/sctp/sm_sideeffect.c | 34 +++++++++++++++++++---------------
1 file changed, 19 insertions(+), 15 deletions(-)
diff --git a/net/sctp/sm_sideeffect.c b/net/sctp/sm_sideeffect.c
index 5fa033a..06c75b1 100644
--- a/net/sctp/sm_sideeffect.c
+++ b/net/sctp/sm_sideeffect.c
@@ -249,11 +249,12 @@ void sctp_generate_t3_rtx_event(unsigned long peer)
int error;
struct sctp_transport *transport = (struct sctp_transport *) peer;
struct sctp_association *asoc = transport->asoc;
+ struct sock *sk = asoc->base.sk;
/* Check whether a task is in the sock. */
- sctp_bh_lock_sock(asoc->base.sk);
- if (sock_owned_by_user(asoc->base.sk)) {
+ sctp_bh_lock_sock(sk);
+ if (sock_owned_by_user(sk)) {
SCTP_DEBUG_PRINTK("%s:Sock is busy.\n", __func__);
/* Try again later. */
@@ -276,10 +277,10 @@ void sctp_generate_t3_rtx_event(unsigned long peer)
transport, GFP_ATOMIC);
if (error)
- asoc->base.sk->sk_err = -error;
+ sk->sk_err = -error;
out_unlock:
- sctp_bh_unlock_sock(asoc->base.sk);
+ sctp_bh_unlock_sock(sk);
sctp_transport_put(transport);
}
@@ -289,10 +290,11 @@ out_unlock:
static void sctp_generate_timeout_event(struct sctp_association *asoc,
sctp_event_timeout_t timeout_type)
{
+ struct sock *sk = asoc->base.sk;
int error = 0;
- sctp_bh_lock_sock(asoc->base.sk);
- if (sock_owned_by_user(asoc->base.sk)) {
+ sctp_bh_lock_sock(sk);
+ if (sock_owned_by_user(sk)) {
SCTP_DEBUG_PRINTK("%s:Sock is busy: timer %d\n",
__func__,
timeout_type);
@@ -316,10 +318,10 @@ static void sctp_generate_timeout_event(struct sctp_association *asoc,
(void *)timeout_type, GFP_ATOMIC);
if (error)
- asoc->base.sk->sk_err = -error;
+ sk->sk_err = -error;
out_unlock:
- sctp_bh_unlock_sock(asoc->base.sk);
+ sctp_bh_unlock_sock(sk);
sctp_association_put(asoc);
}
@@ -369,9 +371,10 @@ void sctp_generate_heartbeat_event(unsigned long data)
int error = 0;
struct sctp_transport *transport = (struct sctp_transport *) data;
struct sctp_association *asoc = transport->asoc;
+ struct sock *sk = asoc->base.sk;
- sctp_bh_lock_sock(asoc->base.sk);
- if (sock_owned_by_user(asoc->base.sk)) {
+ sctp_bh_lock_sock(sk);
+ if (sock_owned_by_user(sk)) {
SCTP_DEBUG_PRINTK("%s:Sock is busy.\n", __func__);
/* Try again later. */
@@ -392,10 +395,10 @@ void sctp_generate_heartbeat_event(unsigned long data)
transport, GFP_ATOMIC);
if (error)
- asoc->base.sk->sk_err = -error;
+ sk->sk_err = -error;
out_unlock:
- sctp_bh_unlock_sock(asoc->base.sk);
+ sctp_bh_unlock_sock(sk);
sctp_transport_put(transport);
}
@@ -406,9 +409,10 @@ void sctp_generate_proto_unreach_event(unsigned long data)
{
struct sctp_transport *transport = (struct sctp_transport *) data;
struct sctp_association *asoc = transport->asoc;
+ struct sock *sk = asoc->base.sk;
- sctp_bh_lock_sock(asoc->base.sk);
- if (sock_owned_by_user(asoc->base.sk)) {
+ sctp_bh_lock_sock(sk);
+ if (sock_owned_by_user(sk)) {
SCTP_DEBUG_PRINTK("%s:Sock is busy.\n", __func__);
/* Try again later. */
@@ -429,7 +433,7 @@ void sctp_generate_proto_unreach_event(unsigned long data)
asoc->state, asoc->ep, asoc, transport, GFP_ATOMIC);
out_unlock:
- sctp_bh_unlock_sock(asoc->base.sk);
+ sctp_bh_unlock_sock(sk);
sctp_association_put(asoc);
}
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | lizf@kernel.org |
|---|---|
| Date | 2016-10-12 15:10 +0200 |
| Subject | [PATCH 3.4 105/125] parisc: Fix syscall restarts |
| Message-ID | <srrsf-4OM-91@gated-at.bofh.it> |
| In reply to | #1499654 |
From: Helge Deller <deller@gmx.de>
3.4.113-rc1 review patch. If anyone has any objections, please let me know.
------------------
commit 71a71fb5374a23be36a91981b5614590b9e722c3 upstream.
On parisc syscalls which are interrupted by signals sometimes failed to
restart and instead returned -ENOSYS which in the worst case lead to
userspace crashes.
A similiar problem existed on MIPS and was fixed by commit e967ef02
("MIPS: Fix restart of indirect syscalls").
On parisc the current syscall restart code assumes that all syscall
callers load the syscall number in the delay slot of the ble
instruction. That's how it is e.g. done in the unistd.h header file:
ble 0x100(%sr2, %r0)
ldi #syscall_nr, %r20
Because of that assumption the current code never restored %r20 before
returning to userspace.
This assumption is at least not true for code which uses the glibc
syscall() function, which instead uses this syntax:
ble 0x100(%sr2, %r0)
copy regX, %r20
where regX depend on how the compiler optimizes the code and register
usage.
This patch fixes this problem by adding code to analyze how the syscall
number is loaded in the delay branch and - if needed - copy the syscall
number to regX prior returning to userspace for the syscall restart.
Signed-off-by: Helge Deller <deller@gmx.de>
Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
[lizf: Backported to 3.4: adjust context]
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
arch/parisc/kernel/signal.c | 67 +++++++++++++++++++++++++++++++++++----------
1 file changed, 52 insertions(+), 15 deletions(-)
diff --git a/arch/parisc/kernel/signal.c b/arch/parisc/kernel/signal.c
index 12c1ed3..c626855 100644
--- a/arch/parisc/kernel/signal.c
+++ b/arch/parisc/kernel/signal.c
@@ -468,6 +468,55 @@ handle_signal(unsigned long sig, siginfo_t *info, struct k_sigaction *ka,
return 1;
}
+/*
+ * Check how the syscall number gets loaded into %r20 within
+ * the delay branch in userspace and adjust as needed.
+ */
+
+static void check_syscallno_in_delay_branch(struct pt_regs *regs)
+{
+ u32 opcode, source_reg;
+ u32 __user *uaddr;
+ int err;
+
+ /* Usually we don't have to restore %r20 (the system call number)
+ * because it gets loaded in the delay slot of the branch external
+ * instruction via the ldi instruction.
+ * In some cases a register-to-register copy instruction might have
+ * been used instead, in which case we need to copy the syscall
+ * number into the source register before returning to userspace.
+ */
+
+ /* A syscall is just a branch, so all we have to do is fiddle the
+ * return pointer so that the ble instruction gets executed again.
+ */
+ regs->gr[31] -= 8; /* delayed branching */
+
+ /* Get assembler opcode of code in delay branch */
+ uaddr = (unsigned int *) ((regs->gr[31] & ~3) + 4);
+ err = get_user(opcode, uaddr);
+ if (err)
+ return;
+
+ /* Check if delay branch uses "ldi int,%r20" */
+ if ((opcode & 0xffff0000) == 0x34140000)
+ return; /* everything ok, just return */
+
+ /* Check if delay branch uses "nop" */
+ if (opcode == INSN_NOP)
+ return;
+
+ /* Check if delay branch uses "copy %rX,%r20" */
+ if ((opcode & 0xffe0ffff) == 0x08000254) {
+ source_reg = (opcode >> 16) & 31;
+ regs->gr[source_reg] = regs->gr[20];
+ return;
+ }
+
+ pr_warn("syscall restart: %s (pid %d): unexpected opcode 0x%08x\n",
+ current->comm, task_pid_nr(current), opcode);
+}
+
static inline void
syscall_restart(struct pt_regs *regs, struct k_sigaction *ka)
{
@@ -489,10 +538,7 @@ syscall_restart(struct pt_regs *regs, struct k_sigaction *ka)
}
/* fallthrough */
case -ERESTARTNOINTR:
- /* A syscall is just a branch, so all
- * we have to do is fiddle the return pointer.
- */
- regs->gr[31] -= 8; /* delayed branching */
+ check_syscallno_in_delay_branch(regs);
/* Preserve original r28. */
regs->gr[28] = regs->orig_r28;
break;
@@ -543,18 +589,9 @@ insert_restart_trampoline(struct pt_regs *regs)
}
case -ERESTARTNOHAND:
case -ERESTARTSYS:
- case -ERESTARTNOINTR: {
- /* Hooray for delayed branching. We don't
- * have to restore %r20 (the system call
- * number) because it gets loaded in the delay
- * slot of the branch external instruction.
- */
- regs->gr[31] -= 8;
- /* Preserve original r28. */
- regs->gr[28] = regs->orig_r28;
-
+ case -ERESTARTNOINTR:
+ check_syscallno_in_delay_branch(regs);
return;
- }
default:
break;
}
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | lizf@kernel.org |
|---|---|
| Date | 2016-10-12 15:10 +0200 |
| Subject | [PATCH 3.4 075/125] rfkill: copy the name into the rfkill struct |
| Message-ID | <srrsf-4OM-93@gated-at.bofh.it> |
| In reply to | #1499654 |
From: Johannes Berg <johannes.berg@intel.com>
3.4.113-rc1 review patch. If anyone has any objections, please let me know.
------------------
commit b7bb110008607a915298bf0f47d25886ecb94477 upstream.
Some users of rfkill, like NFC and cfg80211, use a dynamic name when
allocating rfkill, in those cases dev_name(). Therefore, the pointer
passed to rfkill_alloc() might not be valid forever, I specifically
found the case that the rfkill name was quite obviously an invalid
pointer (or at least garbage) when the wiphy had been renamed.
Fix this by making a copy of the rfkill name in rfkill_alloc().
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Zefan Li <lizefan@huawei.com>
---
net/rfkill/core.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/net/rfkill/core.c b/net/rfkill/core.c
index f974961..feef1a45 100644
--- a/net/rfkill/core.c
+++ b/net/rfkill/core.c
@@ -51,7 +51,6 @@
struct rfkill {
spinlock_t lock;
- const char *name;
enum rfkill_type type;
unsigned long state;
@@ -75,6 +74,7 @@ struct rfkill {
struct delayed_work poll_work;
struct work_struct uevent_work;
struct work_struct sync_work;
+ char name[];
};
#define to_rfkill(d) container_of(d, struct rfkill, dev)
@@ -849,14 +849,14 @@ struct rfkill * __must_check rfkill_alloc(const char *name,
if (WARN_ON(type == RFKILL_TYPE_ALL || type >= NUM_RFKILL_TYPES))
return NULL;
- rfkill = kzalloc(sizeof(*rfkill), GFP_KERNEL);
+ rfkill = kzalloc(sizeof(*rfkill) + strlen(name) + 1, GFP_KERNEL);
if (!rfkill)
return NULL;
spin_lock_init(&rfkill->lock);
INIT_LIST_HEAD(&rfkill->node);
rfkill->type = type;
- rfkill->name = name;
+ strcpy(rfkill->name, name);
rfkill->ops = ops;
rfkill->data = ops_data;
--
1.9.1
[toc] | [prev] | [next] | [standalone]
| From | Guenter Roeck <linux@roeck-us.net> |
|---|---|
| Date | 2016-10-12 19:00 +0200 |
| Message-ID | <srv2N-73S-11@gated-at.bofh.it> |
| In reply to | #1499654 |
On Wed, Oct 12, 2016 at 08:33:20PM +0800, lizf@kernel.org wrote: > From: Zefan Li <lizefan@huawei.com> > > This is the start of the stable review cycle for the 3.4.113 release. > There are 125 patches in this series, all will be posted as a response > to this one. If anyone has any issues with these being applied, please > let me know. > > Responses should be made by Fri Oct 14 12:32:05 UTC 2016. > Anything received after that time might be too late. > Build results: total: 92 pass: 92 fail: 0 Qemu test results: total: 65 pass: 65 fail: 0 Details are available at http://kerneltests.org/builders. Guenter
[toc] | [prev] | [next] | [standalone]
| From | Zefan Li <lizefan@huawei.com> |
|---|---|
| Date | 2016-10-13 03:10 +0200 |
| Message-ID | <srCGZ-4gp-5@gated-at.bofh.it> |
| In reply to | #1499823 |
On 2016/10/13 0:56, Guenter Roeck wrote: > On Wed, Oct 12, 2016 at 08:33:20PM +0800, lizf@kernel.org wrote: >> From: Zefan Li <lizefan@huawei.com> >> >> This is the start of the stable review cycle for the 3.4.113 release. >> There are 125 patches in this series, all will be posted as a response >> to this one. If anyone has any issues with these being applied, please >> let me know. >> >> Responses should be made by Fri Oct 14 12:32:05 UTC 2016. >> Anything received after that time might be too late. >> > > Build results: > total: 92 pass: 92 fail: 0 > Qemu test results: > total: 65 pass: 65 fail: 0 > > Details are available at http://kerneltests.org/builders. > Thanks for testing!
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web