Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1511676 > unrolled thread

[PATCH 4.4 00/51] 4.4.29-stable review

Started byGreg Kroah-Hartman <gregkh@linuxfoundation.org>
First post2016-10-29 16:00 +0200
Last post2016-10-30 02:50 +0200
Articles 6 on this page of 46 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 4.4 00/51] 4.4.29-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:00 +0200
    [PATCH 4.4 23/51] powerpc/eeh: Null check uses of eeh_pe_bus_get Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:00 +0200
    [PATCH 4.4 36/51] ASoC: dapm: Fix kcontrol creation for output driver widget Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:00 +0200
    [PATCH 4.4 28/51] spi: spi-fsl-dspi: Drop extra spi_master_put in device remove function Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:00 +0200
    [PATCH 4.4 29/51] mwifiex: correct aid value during tdls setup Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:00 +0200
    [PATCH 4.4 16/51] drm/i915: Unalias obj->phys_handle and obj->userptr Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:00 +0200
    [PATCH 4.4 13/51] drm/i915/gen9: fix the WaWmMemoryReadLatency implementation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:00 +0200
    [PATCH 4.4 20/51] ipip: Properly mark ipip GRO packets as encapsulated. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:00 +0200
    [PATCH 4.4 06/51] drm/amdgpu/dce11: add missing drm_mode_config_cleanup call Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:00 +0200
    [PATCH 4.4 46/51] perf hists browser: Fix event group display Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:00 +0200
    [PATCH 4.4 03/51] drm/amdgpu/dce10: disable hpd on local panels Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:00 +0200
    [PATCH 4.4 41/51] s390/cio: fix accidental interrupt enabling during resume Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:00 +0200
    [PATCH 4.4 50/51] powerpc/nvram: Fix an incorrect partition merge Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 34/51] ASoC: dapm: Fix possible uninitialized variable in snd_soc_dapm_get_volsw() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 45/51] clk: divider: Fix clk_divider_round_rate() to use clk_readl() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 47/51] perf symbols: Check symbol_conf.allow_aliases for kallsyms loading too Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 10/51] drm/radeon: change vblank_times calculation method to reduce computational error. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 21/51] tunnels: Dont apply GRO to multiple layers of encapsulation. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 04/51] drm/amdgpu/dce8: disable hpd on local panels Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 17/51] mm/hugetlb: fix memory offline with hugepage size > memory block size Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 25/51] genirq/generic_chip: Add irq_unmap callback Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 02/51] drm/amdgpu: fix IB alignment for UVD Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 14/51] Revert "drm/i915: Check live status before reading edid" Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 42/51] s390/con3270: fix use of uninitialised data Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 05/51] drm/amdgpu/dce11: disable hpd on local panels Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 51/51] ARM: pxa: pxa_cplds: fix interrupt handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 44/51] clk: qoriq: fix a register offset error Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 26/51] uio: fix dmem_region_start computation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 32/51] hwrng: omap - Only fail if pm_runtime_get_sync returns < 0 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 31/51] crypto: arm/ghash-ce - add missing async import/export Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 40/51] x86/mm: Expand the exception table logic to allow new handling options Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 33/51] ASoC: topology: Fix error return code in soc_tplg_dapm_widget_create() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 22/51] tunnels: Remove encapsulation offloads on decap. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 08/51] drm/radeon: narrow asic_init for virtualization Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 37/51] staging: r8188eu: Fix scheduling while atomic splat Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 07/51] drm/amdgpu: change vblank_times calculation method to reduce computational error. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 19/51] posix_acl: Clear SGID bit when setting file permissions Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 09/51] drm/radeon/si/dpm: fix phase shedding setup Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 35/51] ASoC: dapm: Fix value setting for _ENUM_DOUBLE MUXs second channel Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 11/51] drm/vmwgfx: Limit the user-space command buffer size Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 43/51] s390/con3270: fix insufficient space padding Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 49/51] mpt3sas: Dont spam logs if logging level is 0 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 38/51] power: bq24257: Fix use of uninitialized pointer bq->charger Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    [PATCH 4.4 18/51] brcmfmac: avoid potential stack overflow in brcmf_cfg80211_start_ap() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-10-29 16:30 +0200
    Re: [PATCH 4.4 00/51] 4.4.29-stable review Shuah Khan <shuah.kh@samsung.com> - 2016-10-30 01:10 +0200
    Re: [PATCH 4.4 00/51] 4.4.29-stable review Guenter Roeck <linux@roeck-us.net> - 2016-10-30 02:50 +0200

Page 3 of 3 — ← Prev page 1 2 [3]


#1511819 — [PATCH 4.4 43/51] s390/con3270: fix insufficient space padding

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-10-29 16:30 +0200
Subject[PATCH 4.4 43/51] s390/con3270: fix insufficient space padding
Message-ID<sxCNY-7nb-61@gated-at.bofh.it>
In reply to#1511676
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sascha Silbe <silbe@linux.vnet.ibm.com>

commit 6cd997db911f28f2510b771691270c52b63ed2e6 upstream.

con3270 contains an optimisation that reduces the amount of data to be
transmitted to the 3270 terminal by putting a Repeat to Address (RA)
order into the data stream. The RA order itself takes up space, so
con3270 only uses it if there's enough space left in the line
buffer. Otherwise it just pads out the line manually.

For lines that were _just_ short enough that the RA order still fit in
the line buffer, the line was instead padded with an insufficient
amount of spaces. This was caused by examining the size of the
allocated line buffer rather than the length of the string to be
displayed.

For con3270_cline_end(), we just compare against the line length. For
con3270_update_string() however that isn't available anymore, so we
check whether the Repeat to Address order is present.

Fixes: f51320a5 ("[PATCH] s390: new 3270 driver.") (tglx/history.git)
Tested-by: Jing Liu <liujbjl@linux.vnet.ibm.com>
Tested-by: Yang Chen <bjcyang@linux.vnet.ibm.com>
Signed-off-by: Sascha Silbe <silbe@linux.vnet.ibm.com>
Signed-off-by: Martin Schwidefsky <schwidefsky@de.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/s390/char/con3270.c |    9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

--- a/drivers/s390/char/con3270.c
+++ b/drivers/s390/char/con3270.c
@@ -124,7 +124,12 @@ con3270_create_status(struct con3270 *cp
 static void
 con3270_update_string(struct con3270 *cp, struct string *s, int nr)
 {
-	if (s->len >= cp->view.cols - 5)
+	if (s->len < 4) {
+		/* This indicates a bug, but printing a warning would
+		 * cause a deadlock. */
+		return;
+	}
+	if (s->string[s->len - 4] != TO_RA)
 		return;
 	raw3270_buffer_address(cp->view.dev, s->string + s->len - 3,
 			       cp->view.cols * (nr + 1));
@@ -461,7 +466,7 @@ con3270_cline_end(struct con3270 *cp)
 		cp->cline->len + 4 : cp->view.cols;
 	s = con3270_alloc_string(cp, size);
 	memcpy(s->string, cp->cline->string, cp->cline->len);
-	if (s->len < cp->view.cols - 5) {
+	if (cp->cline->len < cp->view.cols - 5) {
 		s->string[s->len - 4] = TO_RA;
 		s->string[s->len - 1] = 0;
 	} else {

[toc] | [prev] | [next] | [standalone]


#1511820 — [PATCH 4.4 49/51] mpt3sas: Dont spam logs if logging level is 0

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-10-29 16:30 +0200
Subject[PATCH 4.4 49/51] mpt3sas: Dont spam logs if logging level is 0
Message-ID<sxCNY-7nb-65@gated-at.bofh.it>
In reply to#1511676
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johannes Thumshirn <jthumshirn@suse.de>

commit 0d667f72b2a20bbac72bec0ab11467fc70bb0f1f upstream.

In _scsih_io_done() we test if the ioc->logging_level does _not_ have
the MPT_DEBUG_REPLY bit set and if it hasn't we print the debug
messages. This unfortunately is the wrong way around.

Note, the actual bug is older than af0094115 but this commit removed the
CONFIG_SCSI_MPT3SAS_LOGGING Kconfig option which hid the bug.

Fixes: af0094115 'mpt2sas, mpt3sas: Remove SCSI_MPTXSAS_LOGGING entry from Kconfig'
Signed-off-by: Johannes Thumshirn <jthumshirn@suse.de>
Acked-by: Chaitra P B <chaitra.basappa@broadcom.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/scsi/mpt3sas/mpt3sas_scsih.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/scsi/mpt3sas/mpt3sas_scsih.c
+++ b/drivers/scsi/mpt3sas/mpt3sas_scsih.c
@@ -4510,7 +4510,7 @@ _scsih_io_done(struct MPT3SAS_ADAPTER *i
 			    le16_to_cpu(mpi_reply->DevHandle));
 		mpt3sas_trigger_scsi(ioc, data.skey, data.asc, data.ascq);
 
-		if (!(ioc->logging_level & MPT_DEBUG_REPLY) &&
+		if ((ioc->logging_level & MPT_DEBUG_REPLY) &&
 		     ((scmd->sense_buffer[2] == UNIT_ATTENTION) ||
 		     (scmd->sense_buffer[2] == MEDIUM_ERROR) ||
 		     (scmd->sense_buffer[2] == HARDWARE_ERROR)))

[toc] | [prev] | [next] | [standalone]


#1511821 — [PATCH 4.4 38/51] power: bq24257: Fix use of uninitialized pointer bq->charger

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-10-29 16:30 +0200
Subject[PATCH 4.4 38/51] power: bq24257: Fix use of uninitialized pointer bq->charger
Message-ID<sxCNZ-7nb-73@gated-at.bofh.it>
In reply to#1511676
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Georges Savoundararadj <savoundg@gmail.com>

commit 0610735928ee47870e083d5901caa371089216f1 upstream.

bq->charger is initialized in bq24257_power_supply_init.
Therefore, bq24257_power_supply_init should be called before the
registration of the IRQ handler bq24257_irq_handler_thread that calls
power_supply_changed(bq->charger).

Signed-off-by: Georges Savoundararadj <savoundg@gmail.com>
Cc: Aurelien Chanot <chanot.a@gmail.com>
Cc: Andreas Dannenberg <dannenberg@ti.com>
Cc: Sebastian Reichel <sre@kernel.org>
Cc: David Woodhouse <dwmw2@infradead.org>
Fixes: 2219a935963e ("power_supply: Add TI BQ24257 charger driver")
Signed-off-by: Sebastian Reichel <sre@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/power/bq24257_charger.c |   12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

--- a/drivers/power/bq24257_charger.c
+++ b/drivers/power/bq24257_charger.c
@@ -1068,6 +1068,12 @@ static int bq24257_probe(struct i2c_clie
 		return ret;
 	}
 
+	ret = bq24257_power_supply_init(bq);
+	if (ret < 0) {
+		dev_err(dev, "Failed to register power supply\n");
+		return ret;
+	}
+
 	ret = devm_request_threaded_irq(dev, client->irq, NULL,
 					bq24257_irq_handler_thread,
 					IRQF_TRIGGER_FALLING |
@@ -1078,12 +1084,6 @@ static int bq24257_probe(struct i2c_clie
 		return ret;
 	}
 
-	ret = bq24257_power_supply_init(bq);
-	if (ret < 0) {
-		dev_err(dev, "Failed to register power supply\n");
-		return ret;
-	}
-
 	ret = sysfs_create_group(&bq->charger->dev.kobj, &bq24257_attr_group);
 	if (ret < 0) {
 		dev_err(dev, "Can't create sysfs entries\n");

[toc] | [prev] | [next] | [standalone]


#1511822 — [PATCH 4.4 18/51] brcmfmac: avoid potential stack overflow in brcmf_cfg80211_start_ap()

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-10-29 16:30 +0200
Subject[PATCH 4.4 18/51] brcmfmac: avoid potential stack overflow in brcmf_cfg80211_start_ap()
Message-ID<sxCNZ-7nb-69@gated-at.bofh.it>
In reply to#1511676
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arend Van Spriel <arend.vanspriel@broadcom.com>

commit ded89912156b1a47d940a0c954c43afbabd0c42c upstream.

User-space can choose to omit NL80211_ATTR_SSID and only provide raw
IE TLV data. When doing so it can provide SSID IE with length exceeding
the allowed size. The driver further processes this IE copying it
into a local variable without checking the length. Hence stack can be
corrupted and used as exploit.

Reported-by: Daxing Guo <freener.gdx@gmail.com>
Reviewed-by: Hante Meuleman <hante.meuleman@broadcom.com>
Reviewed-by: Pieter-Paul Giesberts <pieter-paul.giesberts@broadcom.com>
Reviewed-by: Franky Lin <franky.lin@broadcom.com>
Signed-off-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Signed-off-by: Juerg Haefliger <juerg.haefliger@hpe.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/net/wireless/brcm80211/brcmfmac/cfg80211.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/net/wireless/brcm80211/brcmfmac/cfg80211.c
+++ b/drivers/net/wireless/brcm80211/brcmfmac/cfg80211.c
@@ -4102,7 +4102,7 @@ brcmf_cfg80211_start_ap(struct wiphy *wi
 				(u8 *)&settings->beacon.head[ie_offset],
 				settings->beacon.head_len - ie_offset,
 				WLAN_EID_SSID);
-		if (!ssid_ie)
+		if (!ssid_ie || ssid_ie->len > IEEE80211_MAX_SSID_LEN)
 			return -EINVAL;
 
 		memcpy(ssid_le.SSID, ssid_ie->data, ssid_ie->len);

[toc] | [prev] | [next] | [standalone]


#1511929

FromShuah Khan <shuah.kh@samsung.com>
Date2016-10-30 01:10 +0200
Message-ID<sxKVb-4QC-1@gated-at.bofh.it>
In reply to#1511676
On 10/29/2016 07:49 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 4.4.29 release.
> There are 51 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Mon Oct 31 13:49:01 UTC 2016.
> Anything received after that time might be too late.
> 
> The whole patch series can be found in one patch at:
> 	kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.4.29-rc1.gz
> or in the git tree and branch at:
>   git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.4.y
> and the diffstat can be found below.
> 
> thanks,
> 
> greg k-h
> 

Compiled and booted on my test system. No dmesg regressions.

thanks,
-- Shuah

-- 
Shuah Khan
Sr. Linux Kernel Developer
Open Source Innovation Group
Samsung Research America(Silicon Valley)
shuah.kh@samsung.com

[toc] | [prev] | [next] | [standalone]


#1511980

FromGuenter Roeck <linux@roeck-us.net>
Date2016-10-30 02:50 +0200
Message-ID<sxMtZ-5GX-91@gated-at.bofh.it>
In reply to#1511676
On 10/29/2016 06:49 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 4.4.29 release.
> There are 51 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Mon Oct 31 13:49:01 UTC 2016.
> Anything received after that time might be too late.
>

Build results:
	total: 149 pass: 149 fail: 0
Qemu test results:
	total: 106 pass: 106 fail: 0

Details are available at http://kerneltests.org/builders.

Guenter

[toc] | [prev] | [standalone]


Page 3 of 3 — ← Prev page 1 2 [3]

Back to top | Article view | linux.kernel


csiph-web