Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1565684 > unrolled thread

[PATCH 4.4 00/42] 4.4.45-stable review

Started byGreg Kroah-Hartman <gregkh@linuxfoundation.org>
First post2017-01-24 09:40 +0100
Last post2017-01-24 20:10 +0100
Articles 19 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 4.4 00/42] 4.4.45-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 02/42] IB/mlx5: Wait for all async command completions to complete Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 29/42] ARM: dts: da850-evm: fix read access to SPI flash Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 05/42] IB/mlx4: Fix port query for 56Gb Ethernet links Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 09/42] ARM: dts: imx31: fix clock control module interrupts description Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 37/42] ARM: 8613/1: Fix the uaccess crash on PB11MPCore Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 32/42] arm64/ptrace: Preserve previous registers for short regset write - 3 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 35/42] ARM: dts: imx6qdl-nitrogen6_max: fix sgtl5000 pinctrl init Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 14/42] svcrpc: dont leak contexts on PROC_DESTROY Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 24/42] ubifs: Fix journal replay wrt. xattr nodes Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 03/42] IB/mlx4: Set traffic class in AH Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 42/42] arm64: avoid returning from bad_mode Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 39/42] [media] ite-cir: initialize use_demodulator before using it Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 28/42] ceph: fix bad endianness handling in parse_reply_info_extra Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 31/42] arm64/ptrace: Preserve previous registers for short regset write - 2 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 34/42] arm64/ptrace: Reject attempts to set incomplete hardware breakpoint fields Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:40 +0100
    [PATCH 4.4 16/42] PCI: Enumerate switches below PCI-to-PCIe bridges Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-24 09:50 +0100
    Re: [PATCH 4.4 00/42] 4.4.45-stable review Shuah Khan <shuah.kh@samsung.com> - 2017-01-24 19:30 +0100
    Re: [PATCH 4.4 00/42] 4.4.45-stable review Guenter Roeck <linux@roeck-us.net> - 2017-01-24 20:10 +0100

#1565684 — [PATCH 4.4 00/42] 4.4.45-stable review

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 00/42] 4.4.45-stable review
Message-ID<t34bf-1t2-13@gated-at.bofh.it>
This is the start of the stable review cycle for the 4.4.45 release.
There are 42 patches in this series, all will be posted as a response
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Thu Jan 26 07:54:50 UTC 2017.
Anything received after that time might be too late.

The whole patch series can be found in one patch at:
	kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.4.45-rc1.gz
or in the git tree and branch at:
  git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.4.y
and the diffstat can be found below.

thanks,

greg k-h

-------------
Pseudo-Shortlog of commits:

Greg Kroah-Hartman <gregkh@linuxfoundation.org>
    Linux 4.4.45-rc1

Mark Rutland <mark.rutland@arm.com>
    arm64: avoid returning from bad_mode

Madhavan Srinivasan <maddy@linux.vnet.ibm.com>
    selftest/powerpc: Wrong PMC initialized in pmc56_overflow test

Marek Szyprowski <m.szyprowski@samsung.com>
    dmaengine: pl330: Fix runtime PM support for terminated transfers

Nicolas Iooss <nicolas.iooss_linux@m4x.org>
    ite-cir: initialize use_demodulator before using it

Dan Carpenter <dan.carpenter@oracle.com>
    blackfin: check devm_pinctrl_get() for errors

Linus Walleij <linus.walleij@linaro.org>
    ARM: 8613/1: Fix the uaccess crash on PB11MPCore

Arnd Bergmann <arnd@arndb.de>
    ARM: ux500: fix prcmu_is_cpu_in_wfi() calculation

Gary Bisson <gary.bisson@boundarydevices.com>
    ARM: dts: imx6qdl-nitrogen6_max: fix sgtl5000 pinctrl init

Dave Martin <Dave.Martin@arm.com>
    arm64/ptrace: Reject attempts to set incomplete hardware breakpoint fields

Dave Martin <Dave.Martin@arm.com>
    arm64/ptrace: Avoid uninitialised struct padding in fpr_set()

Dave Martin <Dave.Martin@arm.com>
    arm64/ptrace: Preserve previous registers for short regset write - 3

Dave Martin <Dave.Martin@arm.com>
    arm64/ptrace: Preserve previous registers for short regset write - 2

Dave Martin <Dave.Martin@arm.com>
    arm64/ptrace: Preserve previous registers for short regset write

Fabien Parent <fparent@baylibre.com>
    ARM: dts: da850-evm: fix read access to SPI flash

Jeff Layton <jlayton@redhat.com>
    ceph: fix bad endianness handling in parse_reply_info_extra

Mark Rutland <mark.rutland@arm.com>
    ARM: 8634/1: hw_breakpoint: blacklist Scorpion CPUs

Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
    svcrdma: avoid duplicate dma unmapping during error recovery

Joonyoung Shim <jy0922.shim@samsung.com>
    clocksource/exynos_mct: Clear interrupt when cpu is shut down

Richard Weinberger <richard@nod.at>
    ubifs: Fix journal replay wrt. xattr nodes

Quinn Tran <quinn.tran@cavium.com>
    qla2xxx: Fix crash due to null pointer access

Ruslan Ruslichenko <rruslich@cisco.com>
    x86/ioapic: Restore IO-APIC irq_chip retrigger callback

Hauke Mehrtens <hauke@hauke-m.de>
    mtd: nand: xway: disable module support

Stefan Schmidt <stefan@osg.samsung.com>
    ieee802154: atusb: do not use the stack for buffers to make them DMA able

Stefan Wahren <stefan.wahren@i2se.com>
    mmc: mxs-mmc: Fix additional cycles after transmission stop

Johan Hovold <johan@kernel.org>
    HID: corsair: fix control-transfer error handling

Johan Hovold <johan@kernel.org>
    HID: corsair: fix DMA buffers on stack

Bjorn Helgaas <bhelgaas@google.com>
    PCI: Enumerate switches below PCI-to-PCIe bridges

Tahsin Erdogan <tahsin@google.com>
    fuse: clear FR_PENDING flag when moving requests out of pending queue

J. Bruce Fields <bfields@redhat.com>
    svcrpc: don't leak contexts on PROC_DESTROY

Bjorn Helgaas <bhelgaas@google.com>
    x86/PCI: Ignore _CRS on Supermicro X8DTH-i/6/iF/6F

Gu Zheng <guzheng1@huawei.com>
    tmpfs: clear S_ISGID when setting posix ACLs

Vladimir Zapolskiy <vladimir_zapolskiy@mentor.com>
    ARM: dts: imx31: fix AVIC base address

Vladimir Zapolskiy <vz@mleia.com>
    ARM: dts: imx31: move CCM device node to AIPS2 bus devices

Vladimir Zapolskiy <vz@mleia.com>
    ARM: dts: imx31: fix clock control module interrupts description

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf scripting: Avoid leaking the scripting_context variable

Kamal Heib <kamalh@mellanox.com>
    IB/IPoIB: Remove can't use GFP_NOIO warning

Eran Ben Elisha <eranbe@mellanox.com>
    IB/mlx4: When no DMFS for IPoIB, don't allow NET_IF QPs

Saeed Mahameed <saeedm@mellanox.com>
    IB/mlx4: Fix port query for 56Gb Ethernet links

Jack Morgenstein <jackm@dev.mellanox.co.il>
    IB/mlx4: Fix out-of-range array index in destroy qp flow

Maor Gottlieb <maorg@mellanox.com>
    IB/mlx4: Set traffic class in AH

Eli Cohen <eli@mellanox.com>
    IB/mlx5: Wait for all async command completions to complete

Steven Rostedt <rostedt@goodmis.org>
    ftrace/x86: Set ftrace_stub to weak to prevent gcc from using short jumps to it


-------------

Diffstat:

 .../devicetree/bindings/clock/imx31-clock.txt      |  2 +-
 Makefile                                           |  4 +-
 arch/arm/boot/dts/da850-evm.dts                    |  1 +
 arch/arm/boot/dts/imx31.dtsi                       | 18 +++----
 arch/arm/boot/dts/imx6qdl-nitrogen6_max.dtsi       |  4 +-
 arch/arm/include/asm/cputype.h                     |  3 ++
 arch/arm/kernel/hw_breakpoint.c                    | 16 ++++++
 arch/arm/kernel/smp_tlb.c                          |  7 +++
 arch/arm/mach-ux500/pm.c                           |  4 +-
 arch/arm64/include/uapi/asm/ptrace.h               |  1 +
 arch/arm64/kernel/entry.S                          |  2 +-
 arch/arm64/kernel/ptrace.c                         | 16 ++++--
 arch/arm64/kernel/traps.c                          | 28 ++++++++--
 arch/x86/kernel/apic/io_apic.c                     |  2 +
 arch/x86/kernel/mcount_64.S                        |  3 +-
 arch/x86/pci/acpi.c                                | 10 ++++
 drivers/clocksource/exynos_mct.c                   |  1 +
 drivers/dma/pl330.c                                | 11 ++++
 drivers/hid/hid-corsair.c                          | 60 ++++++++++++++++------
 drivers/infiniband/hw/mlx4/ah.c                    |  6 ++-
 drivers/infiniband/hw/mlx4/main.c                  | 29 +++++++----
 drivers/infiniband/hw/mlx4/qp.c                    |  3 +-
 drivers/infiniband/hw/mlx5/mr.c                    | 28 ++++++++++
 drivers/infiniband/ulp/ipoib/ipoib_cm.c            |  2 -
 drivers/media/platform/blackfin/ppi.c              |  2 +
 drivers/media/rc/ite-cir.c                         |  2 +
 drivers/mmc/host/mxs-mmc.c                         |  6 ++-
 drivers/mtd/nand/Kconfig                           |  2 +-
 drivers/net/ieee802154/atusb.c                     | 31 +++++++++--
 drivers/pci/probe.c                                | 12 +++--
 drivers/scsi/qla2xxx/qla_os.c                      | 16 ++++--
 fs/ceph/mds_client.c                               |  9 ++--
 fs/fuse/dev.c                                      |  3 +-
 fs/posix_acl.c                                     |  9 ++--
 fs/ubifs/tnc.c                                     | 25 ++++++++-
 net/sunrpc/auth_gss/svcauth_gss.c                  |  2 +-
 net/sunrpc/xprtrdma/svc_rdma_recvfrom.c            |  2 -
 tools/perf/util/trace-event-scripting.c            |  6 ++-
 .../powerpc/pmu/ebb/pmc56_overflow_test.c          |  2 +-
 39 files changed, 298 insertions(+), 92 deletions(-)

[toc] | [next] | [standalone]


#1565685 — [PATCH 4.4 02/42] IB/mlx5: Wait for all async command completions to complete

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 02/42] IB/mlx5: Wait for all async command completions to complete
Message-ID<t34NY-1Xv-17@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eli Cohen <eli@mellanox.com>

commit acbda523884dcf45613bf6818d8ead5180df35c2 upstream.

Wait before continuing unload till all pending mkey async creation requests
are done.

Fixes: e126ba97dba9 ('mlx5: Add driver for Mellanox Connect-IB adapters')
Signed-off-by: Eli Cohen <eli@mellanox.com>
Signed-off-by: Maor Gottlieb <maorg@mellanox.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Doug Ledford <dledford@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/infiniband/hw/mlx5/mr.c |   28 ++++++++++++++++++++++++++++
 1 file changed, 28 insertions(+)

--- a/drivers/infiniband/hw/mlx5/mr.c
+++ b/drivers/infiniband/hw/mlx5/mr.c
@@ -614,6 +614,33 @@ int mlx5_mr_cache_init(struct mlx5_ib_de
 	return 0;
 }
 
+static void wait_for_async_commands(struct mlx5_ib_dev *dev)
+{
+	struct mlx5_mr_cache *cache = &dev->cache;
+	struct mlx5_cache_ent *ent;
+	int total = 0;
+	int i;
+	int j;
+
+	for (i = 0; i < MAX_MR_CACHE_ENTRIES; i++) {
+		ent = &cache->ent[i];
+		for (j = 0 ; j < 1000; j++) {
+			if (!ent->pending)
+				break;
+			msleep(50);
+		}
+	}
+	for (i = 0; i < MAX_MR_CACHE_ENTRIES; i++) {
+		ent = &cache->ent[i];
+		total += ent->pending;
+	}
+
+	if (total)
+		mlx5_ib_warn(dev, "aborted while there are %d pending mr requests\n", total);
+	else
+		mlx5_ib_warn(dev, "done with all pending requests\n");
+}
+
 int mlx5_mr_cache_cleanup(struct mlx5_ib_dev *dev)
 {
 	int i;
@@ -627,6 +654,7 @@ int mlx5_mr_cache_cleanup(struct mlx5_ib
 		clean_keys(dev, i);
 
 	destroy_workqueue(dev->cache.wq);
+	wait_for_async_commands(dev);
 	del_timer_sync(&dev->delay_timer);
 
 	return 0;

[toc] | [prev] | [next] | [standalone]


#1565686 — [PATCH 4.4 29/42] ARM: dts: da850-evm: fix read access to SPI flash

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 29/42] ARM: dts: da850-evm: fix read access to SPI flash
Message-ID<t34NY-1Xv-31@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fabien Parent <fparent@baylibre.com>

commit 43849785e1079f6606a31cb7fda92d1200849728 upstream.

Read access to the SPI flash are broken on da850-evm, i.e. the data
read is not what is actually programmed on the flash.
According to the datasheet for the M25P64 part present on the da850-evm,
if the SPI frequency is higher than 20MHz then the READ command is not
usable anymore and only the FAST_READ command can be used to read data.

This commit specifies in the DTS that we should use FAST_READ command
instead of the READ command.

Tested-by: Kevin Hilman <khilman@baylibre.com>
Signed-off-by: Fabien Parent <fparent@baylibre.com>
[nsekhar@ti.com: subject line adjustment]
Signed-off-by: Sekhar Nori <nsekhar@ti.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Signed-off-by: Olof Johansson <olof@lixom.net>

---
 arch/arm/boot/dts/da850-evm.dts |    1 +
 1 file changed, 1 insertion(+)

--- a/arch/arm/boot/dts/da850-evm.dts
+++ b/arch/arm/boot/dts/da850-evm.dts
@@ -85,6 +85,7 @@
 				#size-cells = <1>;
 				compatible = "m25p64";
 				spi-max-frequency = <30000000>;
+				m25p,fast-read;
 				reg = <0>;
 				partition@0 {
 					label = "U-Boot-SPL";

[toc] | [prev] | [next] | [standalone]


#1565687 — [PATCH 4.4 05/42] IB/mlx4: Fix port query for 56Gb Ethernet links

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 05/42] IB/mlx4: Fix port query for 56Gb Ethernet links
Message-ID<t34NY-1Xv-19@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Saeed Mahameed <saeedm@mellanox.com>

commit 6fa26208206c406fa529cd73f7ae6bf4181e270b upstream.

Report the correct speed in the port attributes when using a 56Gbps
ethernet link.  Without this change the field is incorrectly set to 10.

Fixes: a9c766bb75ee ('IB/mlx4: Fix info returned when querying IBoE ports')
Fixes: 2e96691c31ec ('IB: Use central enum for speed instead of hard-coded values')
Signed-off-by: Saeed Mahameed <saeedm@mellanox.com>
Signed-off-by: Yishai Hadas <yishaih@mellanox.com>
Signed-off-by: Daniel Jurgens <danielj@mellanox.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Doug Ledford <dledford@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/infiniband/hw/mlx4/main.c |    8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

--- a/drivers/infiniband/hw/mlx4/main.c
+++ b/drivers/infiniband/hw/mlx4/main.c
@@ -630,9 +630,11 @@ static int eth_link_query_port(struct ib
 	if (err)
 		goto out;
 
-	props->active_width	=  (((u8 *)mailbox->buf)[5] == 0x40) ?
-						IB_WIDTH_4X : IB_WIDTH_1X;
-	props->active_speed	= IB_SPEED_QDR;
+	props->active_width	=  (((u8 *)mailbox->buf)[5] == 0x40) ||
+				   (((u8 *)mailbox->buf)[5] == 0x20 /*56Gb*/) ?
+					   IB_WIDTH_4X : IB_WIDTH_1X;
+	props->active_speed	=  (((u8 *)mailbox->buf)[5] == 0x20 /*56Gb*/) ?
+					   IB_SPEED_FDR : IB_SPEED_QDR;
 	props->port_cap_flags	= IB_PORT_CM_SUP | IB_PORT_IP_BASED_GIDS;
 	props->gid_tbl_len	= mdev->dev->caps.gid_table_len[port];
 	props->max_msg_sz	= mdev->dev->caps.max_msg_sz;

[toc] | [prev] | [next] | [standalone]


#1565688 — [PATCH 4.4 09/42] ARM: dts: imx31: fix clock control module interrupts description

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 09/42] ARM: dts: imx31: fix clock control module interrupts description
Message-ID<t34NY-1Xv-33@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Vladimir Zapolskiy <vz@mleia.com>

commit 2e575cbc930901718cc18e084566ecbb9a4b5ebb upstream.

The type of AVIC interrupt controller found on i.MX31 is one-cell,
namely 31 for CCM DVFS and 53 for CCM, however for clock control
module its interrupts are specified as 3-cells, fix it.

Fixes: ef0e4a606fb6 ("ARM: mx31: Replace clk_register_clkdev with clock DT lookup")
Acked-by: Rob Herring <robh@kernel.org>
Signed-off-by: Vladimir Zapolskiy <vz@mleia.com>
Signed-off-by: Shawn Guo <shawnguo@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 Documentation/devicetree/bindings/clock/imx31-clock.txt |    2 +-
 arch/arm/boot/dts/imx31.dtsi                            |    2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

--- a/Documentation/devicetree/bindings/clock/imx31-clock.txt
+++ b/Documentation/devicetree/bindings/clock/imx31-clock.txt
@@ -77,7 +77,7 @@ Examples:
 clks: ccm@53f80000{
 	compatible = "fsl,imx31-ccm";
 	reg = <0x53f80000 0x4000>;
-	interrupts = <0 31 0x04 0 53 0x04>;
+	interrupts = <31>, <53>;
 	#clock-cells = <1>;
 };
 
--- a/arch/arm/boot/dts/imx31.dtsi
+++ b/arch/arm/boot/dts/imx31.dtsi
@@ -114,7 +114,7 @@
 			clks: ccm@53f80000{
 				compatible = "fsl,imx31-ccm";
 				reg = <0x53f80000 0x4000>;
-				interrupts = <0 31 0x04 0 53 0x04>;
+				interrupts = <31>, <53>;
 				#clock-cells = <1>;
 			};
 		};

[toc] | [prev] | [next] | [standalone]


#1565689 — [PATCH 4.4 37/42] ARM: 8613/1: Fix the uaccess crash on PB11MPCore

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 37/42] ARM: 8613/1: Fix the uaccess crash on PB11MPCore
Message-ID<t34NY-1Xv-35@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Linus Walleij <linus.walleij@linaro.org>

commit 90f92c631b210c1e97080b53a9d863783281a932 upstream.

The following patch was sketched by Russell in response to my
crashes on the PB11MPCore after the patch for software-based
priviledged no access support for ARMv8.1. See this thread:
http://marc.info/?l=linux-arm-kernel&m=144051749807214&w=2

I am unsure what is going on, I suspect everyone involved in
the discussion is. I just want to repost this to get the
discussion restarted, as I still have to apply this patch
with every kernel iteration to get my PB11MPCore Realview
running.

Testing by Neil Armstrong on the Oxnas NAS has revealed that
this bug exist also on that widely deployed hardware, so
we are probably currently regressing all ARM11MPCore systems.

Cc: Russell King <linux@armlinux.org.uk>
Cc: Will Deacon <will.deacon@arm.com>
Fixes: a5e090acbf54 ("ARM: software-based priviledged-no-access support")
Tested-by: Neil Armstrong <narmstrong@baylibre.com>
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/arm/kernel/smp_tlb.c |    7 +++++++
 1 file changed, 7 insertions(+)

--- a/arch/arm/kernel/smp_tlb.c
+++ b/arch/arm/kernel/smp_tlb.c
@@ -9,6 +9,7 @@
  */
 #include <linux/preempt.h>
 #include <linux/smp.h>
+#include <linux/uaccess.h>
 
 #include <asm/smp_plat.h>
 #include <asm/tlbflush.h>
@@ -40,8 +41,11 @@ static inline void ipi_flush_tlb_mm(void
 static inline void ipi_flush_tlb_page(void *arg)
 {
 	struct tlb_args *ta = (struct tlb_args *)arg;
+	unsigned int __ua_flags = uaccess_save_and_enable();
 
 	local_flush_tlb_page(ta->ta_vma, ta->ta_start);
+
+	uaccess_restore(__ua_flags);
 }
 
 static inline void ipi_flush_tlb_kernel_page(void *arg)
@@ -54,8 +58,11 @@ static inline void ipi_flush_tlb_kernel_
 static inline void ipi_flush_tlb_range(void *arg)
 {
 	struct tlb_args *ta = (struct tlb_args *)arg;
+	unsigned int __ua_flags = uaccess_save_and_enable();
 
 	local_flush_tlb_range(ta->ta_vma, ta->ta_start, ta->ta_end);
+
+	uaccess_restore(__ua_flags);
 }
 
 static inline void ipi_flush_tlb_kernel_range(void *arg)

[toc] | [prev] | [next] | [standalone]


#1565690 — [PATCH 4.4 32/42] arm64/ptrace: Preserve previous registers for short regset write - 3

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 32/42] arm64/ptrace: Preserve previous registers for short regset write - 3
Message-ID<t34NY-1Xv-27@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dave Martin <Dave.Martin@arm.com>

commit a672401c00f82e4e19704aff361d9bad18003714 upstream.

Ensure that if userspace supplies insufficient data to
PTRACE_SETREGSET to fill all the registers, the thread's old
registers are preserved.

Fixes: 5d220ff9420f ("arm64: Better native ptrace support for compat tasks")
Signed-off-by: Dave Martin <Dave.Martin@arm.com>
Acked-by: Will Deacon <Will.Deacon@arm.com>
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/arm64/kernel/ptrace.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/arm64/kernel/ptrace.c
+++ b/arch/arm64/kernel/ptrace.c
@@ -849,7 +849,7 @@ static int compat_tls_set(struct task_st
 			  const void __user *ubuf)
 {
 	int ret;
-	compat_ulong_t tls;
+	compat_ulong_t tls = target->thread.tp_value;
 
 	ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &tls, 0, -1);
 	if (ret)

[toc] | [prev] | [next] | [standalone]


#1565691 — [PATCH 4.4 35/42] ARM: dts: imx6qdl-nitrogen6_max: fix sgtl5000 pinctrl init

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 35/42] ARM: dts: imx6qdl-nitrogen6_max: fix sgtl5000 pinctrl init
Message-ID<t34NY-1Xv-23@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Gary Bisson <gary.bisson@boundarydevices.com>

commit 6ab5c2b662e2dcbb964099bf7f19e9dbc9ae5a41 upstream.

This patch fixes the following error:
sgtl5000 0-000a: Error reading chip id -6
imx-sgtl5000 sound: ASoC: CODEC DAI sgtl5000 not registered
imx-sgtl5000 sound: snd_soc_register_card failed (-517)

The problem was that the pinctrl group was linked to the sound driver
instead of the codec node. Since the codec is probed first, the sys_mclk
was missing and it would therefore fail to initialize.

Fixes: b32e700256bc ("ARM: dts: imx: add Boundary Devices Nitrogen6_Max board")
Signed-off-by: Gary Bisson <gary.bisson@boundarydevices.com>
Signed-off-by: Shawn Guo <shawnguo@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/arm/boot/dts/imx6qdl-nitrogen6_max.dtsi |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/arch/arm/boot/dts/imx6qdl-nitrogen6_max.dtsi
+++ b/arch/arm/boot/dts/imx6qdl-nitrogen6_max.dtsi
@@ -319,8 +319,6 @@
 		compatible = "fsl,imx6q-nitrogen6_max-sgtl5000",
 			     "fsl,imx-audio-sgtl5000";
 		model = "imx6q-nitrogen6_max-sgtl5000";
-		pinctrl-names = "default";
-		pinctrl-0 = <&pinctrl_sgtl5000>;
 		ssi-controller = <&ssi1>;
 		audio-codec = <&codec>;
 		audio-routing =
@@ -401,6 +399,8 @@
 
 	codec: sgtl5000@0a {
 		compatible = "fsl,sgtl5000";
+		pinctrl-names = "default";
+		pinctrl-0 = <&pinctrl_sgtl5000>;
 		reg = <0x0a>;
 		clocks = <&clks 201>;
 		VDDA-supply = <&reg_2p5v>;

[toc] | [prev] | [next] | [standalone]


#1565692 — [PATCH 4.4 14/42] svcrpc: dont leak contexts on PROC_DESTROY

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 14/42] svcrpc: dont leak contexts on PROC_DESTROY
Message-ID<t34NY-1Xv-29@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: J. Bruce Fields <bfields@redhat.com>

commit 78794d1890708cf94e3961261e52dcec2cc34722 upstream.

Context expiry times are in units of seconds since boot, not unix time.

The use of get_seconds() here therefore sets the expiry time decades in
the future.  This prevents timely freeing of contexts destroyed by
client RPC_GSS_PROC_DESTROY requests.  We'd still free them eventually
(when the module is unloaded or the container shut down), but a lot of
contexts could pile up before then.

Fixes: c5b29f885afe "sunrpc: use seconds since boot in expiry cache"
Reported-by: Andy Adamson <andros@netapp.com>
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 net/sunrpc/auth_gss/svcauth_gss.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/net/sunrpc/auth_gss/svcauth_gss.c
+++ b/net/sunrpc/auth_gss/svcauth_gss.c
@@ -1481,7 +1481,7 @@ svcauth_gss_accept(struct svc_rqst *rqst
 	case RPC_GSS_PROC_DESTROY:
 		if (gss_write_verf(rqstp, rsci->mechctx, gc->gc_seq))
 			goto auth_err;
-		rsci->h.expiry_time = get_seconds();
+		rsci->h.expiry_time = seconds_since_boot();
 		set_bit(CACHE_NEGATIVE, &rsci->h.flags);
 		if (resv->iov_len + 4 > PAGE_SIZE)
 			goto drop;

[toc] | [prev] | [next] | [standalone]


#1565694 — [PATCH 4.4 24/42] ubifs: Fix journal replay wrt. xattr nodes

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 24/42] ubifs: Fix journal replay wrt. xattr nodes
Message-ID<t34NY-1Xv-39@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Richard Weinberger <richard@nod.at>

commit 1cb51a15b576ee325d527726afff40947218fd5e upstream.

When replaying the journal it can happen that a journal entry points to
a garbage collected node.
This is the case when a power-cut occurred between a garbage collect run
and a commit. In such a case nodes have to be read using the failable
read functions to detect whether the found node matches what we expect.

One corner case was forgotten, when the journal contains an entry to
remove an inode all xattrs have to be removed too. UBIFS models xattr
like directory entries, so the TNC code iterates over
all xattrs of the inode and removes them too. This code re-uses the
functions for walking directories and calls ubifs_tnc_next_ent().
ubifs_tnc_next_ent() expects to be used only after the journal and
aborts when a node does not match the expected result. This behavior can
render an UBIFS volume unmountable after a power-cut when xattrs are
used.

Fix this issue by using failable read functions in ubifs_tnc_next_ent()
too when replaying the journal.
Fixes: 1e51764a3c2ac05a ("UBIFS: add new flash file system")
Reported-by: Rock Lee <rockdotlee@gmail.com>
Reviewed-by: David Gstir <david@sigma-star.at>
Signed-off-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 fs/ubifs/tnc.c |   25 +++++++++++++++++++++++--
 1 file changed, 23 insertions(+), 2 deletions(-)

--- a/fs/ubifs/tnc.c
+++ b/fs/ubifs/tnc.c
@@ -34,6 +34,11 @@
 #include <linux/slab.h>
 #include "ubifs.h"
 
+static int try_read_node(const struct ubifs_info *c, void *buf, int type,
+			 int len, int lnum, int offs);
+static int fallible_read_node(struct ubifs_info *c, const union ubifs_key *key,
+			      struct ubifs_zbranch *zbr, void *node);
+
 /*
  * Returned codes of 'matches_name()' and 'fallible_matches_name()' functions.
  * @NAME_LESS: name corresponding to the first argument is less than second
@@ -402,7 +407,19 @@ static int tnc_read_node_nm(struct ubifs
 		return 0;
 	}
 
-	err = ubifs_tnc_read_node(c, zbr, node);
+	if (c->replaying) {
+		err = fallible_read_node(c, &zbr->key, zbr, node);
+		/*
+		 * When the node was not found, return -ENOENT, 0 otherwise.
+		 * Negative return codes stay as-is.
+		 */
+		if (err == 0)
+			err = -ENOENT;
+		else if (err == 1)
+			err = 0;
+	} else {
+		err = ubifs_tnc_read_node(c, zbr, node);
+	}
 	if (err)
 		return err;
 
@@ -2766,7 +2783,11 @@ struct ubifs_dent_node *ubifs_tnc_next_e
 	if (nm->name) {
 		if (err) {
 			/* Handle collisions */
-			err = resolve_collision(c, key, &znode, &n, nm);
+			if (c->replaying)
+				err = fallible_resolve_collision(c, key, &znode, &n,
+							 nm, 0);
+			else
+				err = resolve_collision(c, key, &znode, &n, nm);
 			dbg_tnc("rc returned %d, znode %p, n %d",
 				err, znode, n);
 			if (unlikely(err < 0))

[toc] | [prev] | [next] | [standalone]


#1565695 — [PATCH 4.4 03/42] IB/mlx4: Set traffic class in AH

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 03/42] IB/mlx4: Set traffic class in AH
Message-ID<t34NZ-1Xv-43@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Maor Gottlieb <maorg@mellanox.com>

commit af4295c117b82a521b05d0daf39ce879d26e6cb1 upstream.

Set traffic class within sl_tclass_flowlabel when create iboe AH.
Without this the TOS value will be empty when running VLAN tagged
traffic, because the TOS value is taken from the traffic class in the
address handle attributes.

Fixes: 9106c4106974 ('IB/mlx4: Fix SL to 802.1Q priority-bits mapping for IBoE')
Signed-off-by: Maor Gottlieb <maorg@mellanox.com>
Signed-off-by: Daniel Jurgens <danielj@mellanox.com>
Reviewed-by: Mark Bloch <markb@mellanox.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Doug Ledford <dledford@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/infiniband/hw/mlx4/ah.c |    6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

--- a/drivers/infiniband/hw/mlx4/ah.c
+++ b/drivers/infiniband/hw/mlx4/ah.c
@@ -113,7 +113,9 @@ static struct ib_ah *create_iboe_ah(stru
 		       !(1 << ah->av.eth.stat_rate & dev->caps.stat_rate_support))
 			--ah->av.eth.stat_rate;
 	}
-
+	ah->av.eth.sl_tclass_flowlabel |=
+			cpu_to_be32((ah_attr->grh.traffic_class << 20) |
+				    ah_attr->grh.flow_label);
 	/*
 	 * HW requires multicast LID so we just choose one.
 	 */
@@ -121,7 +123,7 @@ static struct ib_ah *create_iboe_ah(stru
 		ah->av.ib.dlid = cpu_to_be16(0xc000);
 
 	memcpy(ah->av.eth.dgid, ah_attr->grh.dgid.raw, 16);
-	ah->av.eth.sl_tclass_flowlabel = cpu_to_be32(ah_attr->sl << 29);
+	ah->av.eth.sl_tclass_flowlabel |= cpu_to_be32(ah_attr->sl << 29);
 
 	return &ah->ibah;
 }

[toc] | [prev] | [next] | [standalone]


#1565696 — [PATCH 4.4 42/42] arm64: avoid returning from bad_mode

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 42/42] arm64: avoid returning from bad_mode
Message-ID<t34NZ-1Xv-41@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mark Rutland <mark.rutland@arm.com>

commit 7d9e8f71b989230bc613d121ca38507d34ada849 upstream.

Generally, taking an unexpected exception should be a fatal event, and
bad_mode is intended to cater for this. However, it should be possible
to contain unexpected synchronous exceptions from EL0 without bringing
the kernel down, by sending a SIGILL to the task.

We tried to apply this approach in commit 9955ac47f4ba1c95 ("arm64:
don't kill the kernel on a bad esr from el0"), by sending a signal for
any bad_mode call resulting from an EL0 exception.

However, this also applies to other unexpected exceptions, such as
SError and FIQ. The entry paths for these exceptions branch to bad_mode
without configuring the link register, and have no kernel_exit. Thus, if
we take one of these exceptions from EL0, bad_mode will eventually
return to the original user link register value.

This patch fixes this by introducing a new bad_el0_sync handler to cater
for the recoverable case, and restoring bad_mode to its original state,
whereby it calls panic() and never returns. The recoverable case
branches to bad_el0_sync with a bl, and returns to userspace via the
usual ret_to_user mechanism.

Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Fixes: 9955ac47f4ba1c95 ("arm64: don't kill the kernel on a bad esr from el0")
Reported-by: Mark Salter <msalter@redhat.com>
Cc: Will Deacon <will.deacon@arm.com>
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/arm64/kernel/entry.S |    2 +-
 arch/arm64/kernel/traps.c |   28 ++++++++++++++++++++++++----
 2 files changed, 25 insertions(+), 5 deletions(-)

--- a/arch/arm64/kernel/entry.S
+++ b/arch/arm64/kernel/entry.S
@@ -562,7 +562,7 @@ el0_inv:
 	mov	x0, sp
 	mov	x1, #BAD_SYNC
 	mov	x2, x25
-	bl	bad_mode
+	bl	bad_el0_sync
 	b	ret_to_user
 ENDPROC(el0_sync)
 
--- a/arch/arm64/kernel/traps.c
+++ b/arch/arm64/kernel/traps.c
@@ -434,16 +434,33 @@ const char *esr_get_class_string(u32 esr
 }
 
 /*
- * bad_mode handles the impossible case in the exception vector.
+ * bad_mode handles the impossible case in the exception vector. This is always
+ * fatal.
  */
 asmlinkage void bad_mode(struct pt_regs *regs, int reason, unsigned int esr)
 {
-	siginfo_t info;
-	void __user *pc = (void __user *)instruction_pointer(regs);
 	console_verbose();
 
 	pr_crit("Bad mode in %s handler detected, code 0x%08x -- %s\n",
 		handler[reason], esr, esr_get_class_string(esr));
+
+	die("Oops - bad mode", regs, 0);
+	local_irq_disable();
+	panic("bad mode");
+}
+
+/*
+ * bad_el0_sync handles unexpected, but potentially recoverable synchronous
+ * exceptions taken from EL0. Unlike bad_mode, this returns.
+ */
+asmlinkage void bad_el0_sync(struct pt_regs *regs, int reason, unsigned int esr)
+{
+	siginfo_t info;
+	void __user *pc = (void __user *)instruction_pointer(regs);
+	console_verbose();
+
+	pr_crit("Bad EL0 synchronous exception detected on CPU%d, code 0x%08x -- %s\n",
+		smp_processor_id(), esr, esr_get_class_string(esr));
 	__show_regs(regs);
 
 	info.si_signo = SIGILL;
@@ -451,7 +468,10 @@ asmlinkage void bad_mode(struct pt_regs
 	info.si_code  = ILL_ILLOPC;
 	info.si_addr  = pc;
 
-	arm64_notify_die("Oops - bad mode", regs, &info, 0);
+	current->thread.fault_address = 0;
+	current->thread.fault_code = 0;
+
+	force_sig_info(info.si_signo, &info, current);
 }
 
 void __pte_error(const char *file, int line, unsigned long val)

[toc] | [prev] | [next] | [standalone]


#1565698 — [PATCH 4.4 39/42] [media] ite-cir: initialize use_demodulator before using it

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 39/42] [media] ite-cir: initialize use_demodulator before using it
Message-ID<t34NZ-1Xv-57@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nicolas Iooss <nicolas.iooss_linux@m4x.org>

commit 7ec03e60ef81c19b5d3a46dd070ee966774b860f upstream.

Function ite_set_carrier_params() uses variable use_demodulator after
having initialized it to false in some if branches, but this variable is
never set to true otherwise.

This bug has been found using clang -Wsometimes-uninitialized warning
flag.

Fixes: 620a32bba4a2 ("[media] rc: New rc-based ite-cir driver for
several ITE CIRs")

Signed-off-by: Nicolas Iooss <nicolas.iooss_linux@m4x.org>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/media/rc/ite-cir.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/media/rc/ite-cir.c
+++ b/drivers/media/rc/ite-cir.c
@@ -263,6 +263,8 @@ static void ite_set_carrier_params(struc
 
 			if (allowance > ITE_RXDCR_MAX)
 				allowance = ITE_RXDCR_MAX;
+
+			use_demodulator = true;
 		}
 	}
 

[toc] | [prev] | [next] | [standalone]


#1565703 — [PATCH 4.4 28/42] ceph: fix bad endianness handling in parse_reply_info_extra

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 28/42] ceph: fix bad endianness handling in parse_reply_info_extra
Message-ID<t34O0-1Xv-61@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jeff Layton <jlayton@redhat.com>

commit 6df8c9d80a27cb587f61b4f06b57e248d8bc3f86 upstream.

sparse says:

    fs/ceph/mds_client.c:291:23: warning: restricted __le32 degrades to integer
    fs/ceph/mds_client.c:293:28: warning: restricted __le32 degrades to integer
    fs/ceph/mds_client.c:294:28: warning: restricted __le32 degrades to integer
    fs/ceph/mds_client.c:296:28: warning: restricted __le32 degrades to integer

The op value is __le32, so we need to convert it before comparing it.

Signed-off-by: Jeff Layton <jlayton@redhat.com>
Reviewed-by: Sage Weil <sage@redhat.com>
Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 fs/ceph/mds_client.c |    9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

--- a/fs/ceph/mds_client.c
+++ b/fs/ceph/mds_client.c
@@ -274,12 +274,13 @@ static int parse_reply_info_extra(void *
 				  struct ceph_mds_reply_info_parsed *info,
 				  u64 features)
 {
-	if (info->head->op == CEPH_MDS_OP_GETFILELOCK)
+	u32 op = le32_to_cpu(info->head->op);
+
+	if (op == CEPH_MDS_OP_GETFILELOCK)
 		return parse_reply_info_filelock(p, end, info, features);
-	else if (info->head->op == CEPH_MDS_OP_READDIR ||
-		 info->head->op == CEPH_MDS_OP_LSSNAP)
+	else if (op == CEPH_MDS_OP_READDIR || op == CEPH_MDS_OP_LSSNAP)
 		return parse_reply_info_dir(p, end, info, features);
-	else if (info->head->op == CEPH_MDS_OP_CREATE)
+	else if (op == CEPH_MDS_OP_CREATE)
 		return parse_reply_info_create(p, end, info, features);
 	else
 		return -EIO;

[toc] | [prev] | [next] | [standalone]


#1565706 — [PATCH 4.4 31/42] arm64/ptrace: Preserve previous registers for short regset write - 2

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 31/42] arm64/ptrace: Preserve previous registers for short regset write - 2
Message-ID<t34O0-1Xv-73@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dave Martin <Dave.Martin@arm.com>

commit 9dd73f72f218320c6c90da5f834996e7360dc227 upstream.

Ensure that if userspace supplies insufficient data to
PTRACE_SETREGSET to fill all the registers, the thread's old
registers are preserved.

Fixes: 766a85d7bc5d ("arm64: ptrace: add NT_ARM_SYSTEM_CALL regset")
Signed-off-by: Dave Martin <Dave.Martin@arm.com>
Acked-by: Will Deacon <Will.Deacon@arm.com>
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/arm64/kernel/ptrace.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/arch/arm64/kernel/ptrace.c
+++ b/arch/arm64/kernel/ptrace.c
@@ -576,7 +576,8 @@ static int system_call_set(struct task_s
 			   unsigned int pos, unsigned int count,
 			   const void *kbuf, const void __user *ubuf)
 {
-	int syscallno, ret;
+	int syscallno = task_pt_regs(target)->syscallno;
+	int ret;
 
 	ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &syscallno, 0, -1);
 	if (ret)

[toc] | [prev] | [next] | [standalone]


#1565707 — [PATCH 4.4 34/42] arm64/ptrace: Reject attempts to set incomplete hardware breakpoint fields

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:40 +0100
Subject[PATCH 4.4 34/42] arm64/ptrace: Reject attempts to set incomplete hardware breakpoint fields
Message-ID<t34O0-1Xv-69@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dave Martin <Dave.Martin@arm.com>

commit ad9e202aa1ce571b1d7fed969d06f66067f8a086 upstream.

We cannot preserve partial fields for hardware breakpoints, because
the values written by userspace to the hardware breakpoint
registers can't subsequently be recovered intact from the hardware.

So, just reject attempts to write incomplete fields with -EINVAL.

Fixes: 478fcb2cdb23 ("arm64: Debugging support")
Signed-off-by: Dave Martin <Dave.Martin@arm.com>
Acked-by: Will Deacon <Will.Deacon@arm.com>
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/arm64/kernel/ptrace.c |    4 ++++
 1 file changed, 4 insertions(+)

--- a/arch/arm64/kernel/ptrace.c
+++ b/arch/arm64/kernel/ptrace.c
@@ -450,6 +450,8 @@ static int hw_break_set(struct task_stru
 	/* (address, ctrl) registers */
 	limit = regset->n * regset->size;
 	while (count && offset < limit) {
+		if (count < PTRACE_HBP_ADDR_SZ)
+			return -EINVAL;
 		ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &addr,
 					 offset, offset + PTRACE_HBP_ADDR_SZ);
 		if (ret)
@@ -459,6 +461,8 @@ static int hw_break_set(struct task_stru
 			return ret;
 		offset += PTRACE_HBP_ADDR_SZ;
 
+		if (!count)
+			break;
 		ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &ctrl,
 					 offset, offset + PTRACE_HBP_CTRL_SZ);
 		if (ret)

[toc] | [prev] | [next] | [standalone]


#1565709 — [PATCH 4.4 16/42] PCI: Enumerate switches below PCI-to-PCIe bridges

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-01-24 09:50 +0100
Subject[PATCH 4.4 16/42] PCI: Enumerate switches below PCI-to-PCIe bridges
Message-ID<t34XD-21g-1@gated-at.bofh.it>
In reply to#1565684
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bjorn Helgaas <bhelgaas@google.com>

commit 51ebfc92b72b4f7dac1ab45683bf56741e454b8c upstream.

A PCI-to-PCIe bridge (a "reverse bridge") has a PCI or PCI-X primary
interface and a PCI Express secondary interface.  The PCIe interface is a
Downstream Port that originates a Link.  See the "PCI Express to PCI/PCI-X
Bridge Specification", rev 1.0, sections 1.2 and A.6.

The bug report below involves a PCI-to-PCIe bridge and a PCIe switch below
the bridge:

  00:1e.0 Intel 82801 PCI Bridge to [bus 01-0a]
  01:00.0 Pericom PI7C9X111SL PCIe-to-PCI Reversible Bridge to [bus 02-0a]
  02:00.0 Pericom Device 8608 [PCIe Upstream Port] to [bus 03-0a]
  03:01.0 Pericom Device 8608 [PCIe Downstream Port] to [bus 0a]

01:00.0 is configured as a PCI-to-PCIe bridge (despite the name printed by
lspci).  As we traverse a PCIe hierarchy, device connections alternate
between PCIe Links and internal Switch logic.  Previously we did not
recognize that 01:00.0 had a secondary link, so we thought the 02:00.0
Upstream Port *did* have a secondary link.  In fact, it's the other way
around: 01:00.0 has a secondary link, and 02:00.0 has internal Switch logic
on its secondary side.

When we thought 02:00.0 had a secondary link, the pci_scan_slot() ->
only_one_child() path assumed 02:00.0 could have only one child, so 03:00.0
was the only possible downstream device.  But 03:00.0 doesn't exist, so we
didn't look for any other devices on bus 03.

Booting with "pci=pcie_scan_all" is a workaround, but we don't want users
to have to do that.

Recognize that PCI-to-PCIe bridges originate links on their secondary
interfaces.

Link: https://bugzilla.kernel.org/show_bug.cgi?id=189361
Fixes: d0751b98dfa3 ("PCI: Add dev->has_secondary_link to track downstream PCIe links")
Tested-by: Blake Moore <blake.moore@men.de>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/pci/probe.c |   12 +++++++-----
 1 file changed, 7 insertions(+), 5 deletions(-)

--- a/drivers/pci/probe.c
+++ b/drivers/pci/probe.c
@@ -1019,6 +1019,7 @@ void set_pcie_port_type(struct pci_dev *
 	pos = pci_find_capability(pdev, PCI_CAP_ID_EXP);
 	if (!pos)
 		return;
+
 	pdev->pcie_cap = pos;
 	pci_read_config_word(pdev, pos + PCI_EXP_FLAGS, &reg16);
 	pdev->pcie_flags_reg = reg16;
@@ -1026,13 +1027,14 @@ void set_pcie_port_type(struct pci_dev *
 	pdev->pcie_mpss = reg16 & PCI_EXP_DEVCAP_PAYLOAD;
 
 	/*
-	 * A Root Port is always the upstream end of a Link.  No PCIe
-	 * component has two Links.  Two Links are connected by a Switch
-	 * that has a Port on each Link and internal logic to connect the
-	 * two Ports.
+	 * A Root Port or a PCI-to-PCIe bridge is always the upstream end
+	 * of a Link.  No PCIe component has two Links.  Two Links are
+	 * connected by a Switch that has a Port on each Link and internal
+	 * logic to connect the two Ports.
 	 */
 	type = pci_pcie_type(pdev);
-	if (type == PCI_EXP_TYPE_ROOT_PORT)
+	if (type == PCI_EXP_TYPE_ROOT_PORT ||
+	    type == PCI_EXP_TYPE_PCIE_BRIDGE)
 		pdev->has_secondary_link = 1;
 	else if (type == PCI_EXP_TYPE_UPSTREAM ||
 		 type == PCI_EXP_TYPE_DOWNSTREAM) {

[toc] | [prev] | [next] | [standalone]


#1566048

FromShuah Khan <shuah.kh@samsung.com>
Date2017-01-24 19:30 +0100
Message-ID<t3e0W-7Jk-15@gated-at.bofh.it>
In reply to#1565684
On 01/24/2017 12:55 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 4.4.45 release.
> There are 42 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Thu Jan 26 07:54:50 UTC 2017.
> Anything received after that time might be too late.
> 
> The whole patch series can be found in one patch at:
> 	kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.4.45-rc1.gz
> or in the git tree and branch at:
>   git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.4.y
> and the diffstat can be found below.
> 
> thanks,
> 
> greg k-h
> 

Compiled and booted on my test system. No dmesg regressions.

thanks,
-- Shuah


-- 
Shuah Khan
Sr. Linux Kernel Developer
Open Source Innovation Group
Samsung Research America(Silicon Valley)
shuah.kh@samsung.com

[toc] | [prev] | [next] | [standalone]


#1566073

FromGuenter Roeck <linux@roeck-us.net>
Date2017-01-24 20:10 +0100
Message-ID<t3eDD-8cr-15@gated-at.bofh.it>
In reply to#1565684
On Tue, Jan 24, 2017 at 08:55:10AM +0100, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 4.4.45 release.
> There are 42 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Thu Jan 26 07:54:50 UTC 2017.
> Anything received after that time might be too late.
> 

Build results:
	total: 149 pass: 149 fail: 0
Qemu test results:
	total: 115 pass: 115 fail: 0

Details are available at http://kerneltests.org/builders.

Guenter

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web