Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1573997 > unrolled thread

[PATCH 3.10 100/319] fix fault_in_multipages_...() on architectures with no-op access_ok()

Started byWilly Tarreau <w@1wt.eu>
First post2017-02-05 20:30 +0100
Last post2017-02-05 21:30 +0100
Articles 20 on this page of 215 — 4 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.10 100/319] fix fault_in_multipages_...() on architectures with no-op access_ok() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 155/319] ext4: sanity check the block and cluster size at mount time Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 116/319] usb: gadget: fsl_qe_udc: signedness bug in qe_get_frame() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 304/319] staging: iio: ad5933: avoid uninitialized variable in error case Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 125/319] ALSA: timer: fix NULL pointer dereference in read()/ioctl() race Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 206/319] IB/cm: Mark stale CM id's whenever the mad agent was unregistered Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 156/319] reiserfs: fix "new_insert_key may be used uninitialized ..." Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 181/319] drm/radeon: Ensure vblank interrupt is enabled on DPMS transition to on Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 303/319] hv: do not lose pending heartbeat vmbus packets Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 261/319] dccp: do not send reset to already closed sockets Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 123/319] Fix USB CB/CBI storage devices with CONFIG_VMAP_STACK=y Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 262/319] dccp: fix out of bound access in dccp_v4_err() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 249/319] firewire: net: guard against rx buffer overflows Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 315/319] ASoC: omap-mcpdm: Fix irq resource handling Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 201/319] IB/core: Fix use after free in send_leave function Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 193/319] iio: accel: kxsd9: Fix raw read return Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 179/319] drm/radeon: fix radeon_move_blit on 32bit systems Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 211/319] perf: Tighten (and fix) the grouping condition Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 241/319] ipvs: count pre-established TCP states as active Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 276/319] arch: Introduce smp_load_acquire(), smp_store_release() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
      Re: [PATCH 3.10 276/319] arch: Introduce smp_load_acquire(),  smp_store_release() Willy Tarreau <w@1wt.eu> - 2017-02-06 10:20 +0100
    [PATCH 3.10 202/319] IB/ipoib: Don't allow MC joins during light MC flush Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 127/319] ALSA: timer: fix NULL pointer dereference on memory allocation failure Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 184/319] Input: i8042 - set up shared ps2_cmd_mutex for AUX ports Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 191/319] i2c: core: fix NULL pointer dereference under race condition Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 205/319] IB/uverbs: Fix leak of XRC target QPs Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 290/319] PM / sleep: fix device reference leak in test_suspend Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 318/319] fbdev/efifb: Fix 16 color palette entry calculation Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 103/319] Fix potential infoleak in older kernels Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 234/319] tcp: fix wrong checksum calculation on MTU probing Willy Tarreau <w@1wt.eu> - 2017-02-05 20:30 +0100
    [PATCH 3.10 254/319] net: avoid sk_forward_alloc overflows Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 251/319] netfilter: fix namespace handling in nf_log_proc_dostring Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 228/319] ip6_tunnel: Clear IP6CB in ip6tunnel_xmit() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 131/319] zfcp: fix ELS/GS request&response length for hardware data router Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 274/319] kernel/fork: fix CLONE_CHILD_CLEARTID regression in nscd Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 170/319] NFSD: Using free_conn free connection Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 265/319] ipv4: use new_gw for redirect neigh lookup Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 121/319] usb: gadget: u_ether: remove interrupt throttling Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 309/319] dm flakey: fix reads to be issued if drop_writes configured Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 216/319] drivers/vfio: Rework offsetofend() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 246/319] brcmfmac: avoid potential stack overflow in brcmf_cfg80211_start_ap() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 258/319] sctp: validate chunk len before actually using it Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 292/319] mmc: block: don't use CMD23 with very old MMC cards Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 215/319] vt: clear selection before resizing Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 153/319] ext4: reinforce check of i_dtime when clearing high fields of uid and gid Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 159/319] libxfs: clean up _calc_dquots_per_chunk Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 182/319] qxl: check for kmap failures Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 252/319] can: bcm: fix warning in bcm_connect/proc_register Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 163/319] ubifs: Fix assertion in layout_in_gaps() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 291/319] mmc: mxs: Initialize the spinlock prior to using it Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 306/319] ACPI / APEI: Fix incorrect return value of ghes_proc() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 250/319] firewire: net: fix fragmented datagram_size off-by-one Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 152/319] ext4: use __GFP_NOFAIL in ext4_free_blocks() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 277/319] kernel: Provide READ_ONCE and ASSIGN_ONCE Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
      Re: [PATCH 3.10 277/319] kernel: Provide READ_ONCE and ASSIGN_ONCE Willy Tarreau <w@1wt.eu> - 2017-02-06 09:10 +0100
    [PATCH 3.10 281/319] compiler: Allow 1- and 2-byte smp_load_acquire() and smp_store_release() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
      Re: [PATCH 3.10 281/319] compiler: Allow 1- and 2-byte  smp_load_acquire() and smp_store_release() Willy Tarreau <w@1wt.eu> - 2017-02-06 09:10 +0100
    [PATCH 3.10 203/319] IB/mlx4: Fix incorrect MC join state bit-masking on SR-IOV Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 102/319] arc: don't leak bits of kernel stack into coredump Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 200/319] IB/ipoib: Fix memory corruption in ipoib cm mode connect flow Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 275/319] ipc: remove use of seq_printf return value Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
      Re: [PATCH 3.10 275/319] ipc: remove use of seq_printf return value Joe Perches <joe@perches.com> - 2017-02-05 20:50 +0100
        Re: [PATCH 3.10 275/319] ipc: remove use of seq_printf return value Willy Tarreau <w@1wt.eu> - 2017-02-05 21:40 +0100
      Re: [PATCH 3.10 275/319] ipc: remove use of seq_printf return value Willy Tarreau <w@1wt.eu> - 2017-02-06 09:10 +0100
    [PATCH 3.10 307/319] PCI: Handle read-only BARs on AMD CS553x devices Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 147/319] scsi: arcmsr: Buffer overflow in arcmsr_iop_message_xfer() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 284/319] drbd: Fix kernel_sendmsg() usage - potential NULL deref Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 245/319] brcmsmac: Initialize power in brcms_c_stf_ss_algo_channel_get() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 242/319] iwlwifi: pcie: fix access to scratch buffer Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
    [PATCH 3.10 280/319] locking: Remove atomicy checks from {READ,WRITE}_ONCE Willy Tarreau <w@1wt.eu> - 2017-02-05 20:40 +0100
      Re: [PATCH 3.10 280/319] locking: Remove atomicy checks from  {READ,WRITE}_ONCE Willy Tarreau <w@1wt.eu> - 2017-02-06 09:10 +0100
    [PATCH 3.10 256/319] packet: call fanout_release, while UNREGISTERING a netdev Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 286/319] tools/vm/slabinfo: fix an unintentional printf Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 199/319] IB/srpt: Simplify srpt_handle_tsk_mgmt() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
      Re: [PATCH 3.10 199/319] IB/srpt: Simplify srpt_handle_tsk_mgmt() Willy Tarreau <w@1wt.eu> - 2017-02-06 07:40 +0100
    [PATCH 3.10 317/319] dm: mark request_queue dead before destroying the DM device Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 233/319] tcp: fix overflow in __tcp_retransmit_skb() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 157/319] reiserfs: Unlock superblock before calling reiserfs_quota_on_mount() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 126/319] ALSA: timer: fix division by zero after SNDRV_TIMER_IOCTL_CONTINUE Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 231/319] tcp: fix use after free in tcp_xmit_retransmit_queue() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 226/319] ipv6: dccp: fix out of bound access in dccp_v6_err() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 119/319] usb: gadget: function: u_ether: don't starve tx request queue Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 149/319] scsi: arcmsr: Send SYNCHRONIZE_CACHE command to firmware Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 222/319] ipv6: addrconf: fix dev refcont leak when DAD failed Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 311/319] can: dev: fix deadlock reported after bus-off Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 177/319] driver core: Delete an unnecessary check before the function call "put_device" Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 269/319] mwifiex: printk() overflow with 32-byte SSIDs Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 270/319] ipv4: Set skb->protocol properly for local output Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 314/319] mfd: 88pm80x: Double shifting bug in suspend/resume Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 143/319] scsi: megaraid_sas: Fix data integrity failure for JBOD (passthrough) devices Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 218/319] stddef.h: move offsetofend inside #ifndef/#endif guard, neaten Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 195/319] thermal: hwmon: Properly report critical temperature in sysfs Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 111/319] USB: kobil_sct: fix non-atomic allocation in write path Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 158/319] xfs: fix superblock inprogress check Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 209/319] mtd: nand: davinci: Reinitialize the HW ECC engine in 4bit hwctl Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 114/319] usb: renesas_usbhs: fix clearing the {BRDY,BEMP}STS condition Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 272/319] kaweth: fix firmware download Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 105/319] coredump: fix unfreezable coredumping task Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 282/319] ipc/sem.c: fix complex_count vs. simple op race Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
      Re: [PATCH 3.10 282/319] ipc/sem.c: fix complex_count vs. simple op  race Willy Tarreau <w@1wt.eu> - 2017-02-06 09:10 +0100
    [PATCH 3.10 295/319] pstore/ram: Use memcpy_fromio() to save old buffer Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 310/319] mm,ksm: fix endless looping in allocating memory when ksm enable Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 210/319] perf symbols: Fixup symbol sizes before picking best ones Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 224/319] ip6_gre: fix flowi6_proto value in ip6gre_xmit_other() Willy Tarreau <w@1wt.eu> - 2017-02-05 20:50 +0100
    [PATCH 3.10 296/319] mb86a20s: fix the locking logic Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 279/319] kernel: make READ_ONCE() valid on const arguments Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
      Re: [PATCH 3.10 279/319] kernel: make READ_ONCE() valid on const  arguments Willy Tarreau <w@1wt.eu> - 2017-02-06 09:10 +0100
    [PATCH 3.10 174/319] fs/super.c: fix race between freeze_super() and thaw_super() Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 129/319] ALSA: pcm : Call kill_fasync() in stream lock Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 238/319] mISDN: Support DR6 indication in mISDNipac driver Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 293/319] pstore/core: drop cmpxchg based updates Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 141/319] scsi: mpt3sas: Fix secure erase premature termination Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
      RE: [PATCH 3.10 141/319] scsi: mpt3sas: Fix secure erase premature termination Sathya Prakash Veerichetty <sathya.prakash@broadcom.com> - 2017-02-06 17:30 +0100
        Re: [PATCH 3.10 141/319] scsi: mpt3sas: Fix secure erase premature  termination Willy Tarreau <w@1wt.eu> - 2017-02-06 23:30 +0100
          Re: [PATCH 3.10 141/319] scsi: mpt3sas: Fix secure erase premature  termination James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-07 07:40 +0100
            Re: [PATCH 3.10 141/319] scsi: mpt3sas: Fix secure erase premature  termination Willy Tarreau <w@1wt.eu> - 2017-02-07 08:10 +0100
              Re: [PATCH 3.10 141/319] scsi: mpt3sas: Fix secure erase premature  termination James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-07 18:10 +0100
                Re: [PATCH 3.10 141/319] scsi: mpt3sas: Fix secure erase premature  termination Willy Tarreau <w@1wt.eu> - 2017-02-07 18:20 +0100
                  Re: [PATCH 3.10 141/319] scsi: mpt3sas: Fix secure erase premature  termination Willy Tarreau <w@1wt.eu> - 2017-02-08 08:00 +0100
    [PATCH 3.10 268/319] cfg80211: limit scan results cache size Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 247/319] pstore: Fix buffer overflow while write offset equal to buffer size Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 130/319] zfcp: fix fc_host port_type with NPIV Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 219/319] ipv6: don't call fib6_run_gc() until routing is ready Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 104/319] swapfile: fix memory corruption via malformed swapfile Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 223/319] ipv6: fix rtnl locking in setsockopt for anycast and multicast Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 240/319] net: disable fragment reassembly if high_thresh is set to zero Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 204/319] IB/mlx4: Fix create CQ error flow Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 294/319] pstore/ram: Use memcpy_toio instead of memcpy Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 285/319] lib/genalloc.c: start search from start of chunk Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 257/319] net: sctp, forbid negative length Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 230/319] net/irda: handle iriap_register_lsap() allocation failure Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 313/319] mpi: Fix NULL ptr dereference in mpi_powm() [ver #3] Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 168/319] UBI: fastmap: scrub PEB when bitflips are detected in a free PEB EC header Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 162/319] ocfs2: fix start offset to ocfs2_zero_range_for_truncate() Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 225/319] ipv6: correctly add local routes when lo goes up Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 180/319] drm: Reject page_flip for !DRIVER_MODESET Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 194/319] iio: accel: kxsd9: Fix scaling bug Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 217/319] include/stddef.h: Move offsetofend() from vfio.h to a generic kernel header Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 196/319] cdc-acm: fix wrong pipe type on rx interrupt xfers Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 192/319] i2c: at91: fix write transfers by clearing pending interrupt first Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 312/319] hwmon: (adt7411) set bit 3 in CFG1 register Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 271/319] net: sky2: Fix shutdown crash Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 169/319] NFSv4.x: Fix a refcount leak in nfs_callback_up_net Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 264/319] neigh: check error pointer instead of NULL for ipv4_neigh_lookup() Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 283/319] cfq: fix starvation of asynchronous writes Willy Tarreau <w@1wt.eu> - 2017-02-05 21:00 +0100
    [PATCH 3.10 287/319] rcu: Fix soft lockup for rcu_nocb_kthread Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 301/319] uio: fix dmem_region_start computation Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 255/319] ipmr, ip6mr: fix scheduling while atomic and a deadlock with ipmr_get_route Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 213/319] tty: limit terminal size to 4M chars Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 239/319] mISDN: Fixing missing validation in base_sock_bind() Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 166/319] ubifs: Abort readdir upon error Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 188/319] hwrng: omap - Only fail if pm_runtime_get_sync returns < 0 Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 229/319] ip6_tunnel: disable caching when the traffic class is inherited Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 148/319] scsi: scsi_debug: Fix memory leak if LBP enabled and module is unloaded Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 302/319] KEYS: Fix short sprintf buffer in /proc/keys show function Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 259/319] net: clear sk_err_soft in sk_clone_lock() Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 164/319] ubifs: Fix xattr_names length in exit paths Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 175/319] isofs: Do not return EACCES for unknown filesystems Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 263/319] sctp: assign assoc_id earlier in __sctp_connect Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 117/319] USB: serial: cp210x: fix hardware flow-control disable Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 273/319] tracing: Move mutex to protect against resetting of seq data Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 136/319] zfcp: restore tracing of handle for port and LUN with HBA records Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 214/319] tty: vt, fix bogus division in csi_J Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 122/319] usb: chipidea: move the lock initialization to core file Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 308/319] tile: avoid using clocksource_cyc2ns with absolute cycle count Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 289/319] mfd: core: Fix device reference leak in mfd_clone_cell Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 300/319] gpio: mpc8xxx: Correct irq handler function Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 172/319] NFSv4: Open state recovery must account for file permission changes Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 227/319] ipv6: dccp: add missing bind_conflict to dccp_ipv6_mapped Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 221/319] ipv6: move DAD and addrconf_verify processing to workqueue Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 183/319] Input: i8042 - break load dependency between atkbd/psmouse and i8042 Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 319/319] metag: Only define atomic_dec_if_positive conditionally Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 108/319] USB: fix typo in wMaxPacketSize validation Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 161/319] ocfs2/dlm: fix race between convert and migration Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 266/319] mac80211: fix purging multicast PS buffer queue Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 134/319] zfcp: restore: Dont use 0 to indicate invalid LUN in rec trace Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 212/319] tty: Prevent ldisc drivers from re-using stale tty fields Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 244/319] brcmsmac: Free packet if dma_mapping_error() fails in dma_rxfill Willy Tarreau <w@1wt.eu> - 2017-02-05 21:10 +0100
    [PATCH 3.10 142/319] mpt2sas: Fix secure erase premature termination Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 171/319] NFS: Don't drop CB requests with invalid principals Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 197/319] timers: Use proper base migration in add_timer_on() Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 253/319] net: fix sk_mem_reclaim_partial() Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 186/319] hwrng: exynos - Disable runtime PM on probe failure Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 232/319] tcp: properly scale window in tcp_v[46]_reqsk_send_ack() Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 151/319] ext4: avoid modifying checksum fields directly during checksum verification Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 176/319] hostfs: Freeing an ERR_PTR in hostfs_fill_sb_common() Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 145/319] scsi: ibmvfc: Fix I/O hang when port is not mapped Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 160/319] btrfs: ensure that file descriptor used with subvol ioctls is a dir Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 243/319] svc: Avoid garbage replies when pc_func() returns rpc_drop_reply Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 140/319] scsi: zfcp: spin_lock_irqsave() is not nestable Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 124/319] ALSA: rawmidi: Fix possible deadlock with virmidi registration Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 115/319] USB: change bInterval default to 10 ms Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 112/319] USB: serial: mos7720: fix non-atomic allocation in write path Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 165/319] UBIFS: Fix possible memory leak in ubifs_readdir() Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 189/319] i2c-eg20t: fix race between i2c init and interrupt enable Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 267/319] mac80211: discard multicast and 4-addr A-MSDUs Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 237/319] net: ratelimit warnings about dst entry refcount underflow or overflow Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 248/319] net/mlx4_core: Allow resetting VF admin mac to zero Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 198/319] EDAC: Increment correct counter in edac_inc_ue_error() Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 236/319] bonding: Fix bonding crash Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 220/319] ipv6: split duplicate address detection and router solicitation timer Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 146/319] scsi: Fix use-after-free Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 135/319] zfcp: trace on request for open and close of WKA port Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 207/319] mtd: blkdevs: fix potential deadlock + lockdep warnings Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 150/319] ext4: validate that metadata blocks do not overlap superblock Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 208/319] mtd: pmcmsp-flash: Allocating too much in init_msp_flash() Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 107/319] USB: validate wMaxPacketValue entries in endpoint descriptors Willy Tarreau <w@1wt.eu> - 2017-02-05 21:20 +0100
    [PATCH 3.10 109/319] usb: xhci: Fix panic if disconnect Willy Tarreau <w@1wt.eu> - 2017-02-05 21:30 +0100
    [PATCH 3.10 110/319] USB: serial: fix memleak in driver-registration error path Willy Tarreau <w@1wt.eu> - 2017-02-05 21:30 +0100
    [PATCH 3.10 139/319] zfcp: trace full payload of all SAN records (req,resp,iels) Willy Tarreau <w@1wt.eu> - 2017-02-05 21:30 +0100
    [PATCH 3.10 167/319] ubifs: Fix regression in ubifs_readdir() Willy Tarreau <w@1wt.eu> - 2017-02-05 21:30 +0100
    [PATCH 3.10 154/319] ext4: allow DAX writeback for hole punch Willy Tarreau <w@1wt.eu> - 2017-02-05 21:30 +0100
    [PATCH 3.10 132/319] zfcp: close window with unblocked rport during rport gone Willy Tarreau <w@1wt.eu> - 2017-02-05 21:30 +0100
    [PATCH 3.10 144/319] scsi: megaraid_sas: fix macro MEGASAS_IS_LOGICAL to avoid regression Willy Tarreau <w@1wt.eu> - 2017-02-05 21:30 +0100
    [PATCH 3.10 128/319] ALSA: ali5451: Fix out-of-bound position reporting Willy Tarreau <w@1wt.eu> - 2017-02-05 21:30 +0100

Page 7 of 11 — ← Prev page 1 … 5 6 [7] 8 9 … 11  Next page →


#1574132 — [PATCH 3.10 247/319] pstore: Fix buffer overflow while write offset equal to buffer size

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 247/319] pstore: Fix buffer overflow while write offset equal to buffer size
Message-ID<t7B8D-3eM-39@gated-at.bofh.it>
In reply to#1573997
From: Liu ShuoX <shuox.liu@intel.com>

commit 017321cf390045dd4c4afc4a232995ea50bcf66d upstream.

In case new offset is equal to prz->buffer_size, it won't wrap at this
time and will return old(overflow) value next time.

Signed-off-by: Liu ShuoX <shuox.liu@intel.com>
Acked-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Tony Luck <tony.luck@intel.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/pstore/ram_core.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/fs/pstore/ram_core.c b/fs/pstore/ram_core.c
index bda61a7..0b367ef 100644
--- a/fs/pstore/ram_core.c
+++ b/fs/pstore/ram_core.c
@@ -54,7 +54,7 @@ static size_t buffer_start_add_atomic(struct persistent_ram_zone *prz, size_t a)
 	do {
 		old = atomic_read(&prz->buffer->start);
 		new = old + a;
-		while (unlikely(new > prz->buffer_size))
+		while (unlikely(new >= prz->buffer_size))
 			new -= prz->buffer_size;
 	} while (atomic_cmpxchg(&prz->buffer->start, old, new) != old);
 
@@ -91,7 +91,7 @@ static size_t buffer_start_add_locked(struct persistent_ram_zone *prz, size_t a)
 
 	old = atomic_read(&prz->buffer->start);
 	new = old + a;
-	while (unlikely(new > prz->buffer_size))
+	while (unlikely(new >= prz->buffer_size))
 		new -= prz->buffer_size;
 	atomic_set(&prz->buffer->start, new);
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574133 — [PATCH 3.10 130/319] zfcp: fix fc_host port_type with NPIV

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 130/319] zfcp: fix fc_host port_type with NPIV
Message-ID<t7B8D-3eM-43@gated-at.bofh.it>
In reply to#1573997
From: Steffen Maier <maier@linux.vnet.ibm.com>

commit bd77befa5bcff8c51613de271913639edf85fbc2 upstream.

For an NPIV-enabled FCP device, zfcp can erroneously show
"NPort (fabric via point-to-point)" instead of "NPIV VPORT"
for the port_type sysfs attribute of the corresponding
fc_host.
s390-tools that can be affected are dbginfo.sh and ziomon.

zfcp_fsf_exchange_config_evaluate() ignores
fsf_qtcb_bottom_config.connection_features indicating NPIV
and only sets fc_host_port_type to FC_PORTTYPE_NPORT if
fsf_qtcb_bottom_config.fc_topology is FSF_TOPO_FABRIC.

Only the independent zfcp_fsf_exchange_port_evaluate()
evaluates connection_features to overwrite fc_host_port_type
to FC_PORTTYPE_NPIV in case of NPIV.
Code was introduced with upstream kernel 2.6.30
commit 0282985da5923fa6365adcc1a1586ae0c13c1617
("[SCSI] zfcp: Report fc_host_port_type as NPIV").

This works during FCP device recovery (such as set online)
because it performs FSF_QTCB_EXCHANGE_CONFIG_DATA followed by
FSF_QTCB_EXCHANGE_PORT_DATA in sequence.

However, the zfcp-specific scsi host sysfs attributes
"requests", "megabytes", or "seconds_active" trigger only
zfcp_fsf_exchange_config_evaluate() resetting fc_host
port_type to FC_PORTTYPE_NPORT despite NPIV.

The zfcp-specific scsi host sysfs attribute "utilization"
triggers only zfcp_fsf_exchange_port_evaluate() correcting
the fc_host port_type again in case of NPIV.

Evaluate fsf_qtcb_bottom_config.connection_features
in zfcp_fsf_exchange_config_evaluate() where it belongs to.

Signed-off-by: Steffen Maier <maier@linux.vnet.ibm.com>
Fixes: 0282985da592 ("[SCSI] zfcp: Report fc_host_port_type as NPIV")
Reviewed-by: Benjamin Block <bblock@linux.vnet.ibm.com>
Reviewed-by: Hannes Reinecke <hare@suse.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/s390/scsi/zfcp_fsf.c | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

diff --git a/drivers/s390/scsi/zfcp_fsf.c b/drivers/s390/scsi/zfcp_fsf.c
index 9152999..8fa6bc4 100644
--- a/drivers/s390/scsi/zfcp_fsf.c
+++ b/drivers/s390/scsi/zfcp_fsf.c
@@ -3,7 +3,7 @@
  *
  * Implementation of FSF commands.
  *
- * Copyright IBM Corp. 2002, 2013
+ * Copyright IBM Corp. 2002, 2015
  */
 
 #define KMSG_COMPONENT "zfcp"
@@ -513,7 +513,10 @@ static int zfcp_fsf_exchange_config_evaluate(struct zfcp_fsf_req *req)
 		fc_host_port_type(shost) = FC_PORTTYPE_PTP;
 		break;
 	case FSF_TOPO_FABRIC:
-		fc_host_port_type(shost) = FC_PORTTYPE_NPORT;
+		if (bottom->connection_features & FSF_FEATURE_NPIV_MODE)
+			fc_host_port_type(shost) = FC_PORTTYPE_NPIV;
+		else
+			fc_host_port_type(shost) = FC_PORTTYPE_NPORT;
 		break;
 	case FSF_TOPO_AL:
 		fc_host_port_type(shost) = FC_PORTTYPE_NLPORT;
@@ -618,7 +621,6 @@ static void zfcp_fsf_exchange_port_evaluate(struct zfcp_fsf_req *req)
 
 	if (adapter->connection_features & FSF_FEATURE_NPIV_MODE) {
 		fc_host_permanent_port_name(shost) = bottom->wwpn;
-		fc_host_port_type(shost) = FC_PORTTYPE_NPIV;
 	} else
 		fc_host_permanent_port_name(shost) = fc_host_port_name(shost);
 	fc_host_maxframe_size(shost) = bottom->maximum_frame_size;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574134 — [PATCH 3.10 219/319] ipv6: don't call fib6_run_gc() until routing is ready

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 219/319] ipv6: don't call fib6_run_gc() until routing is ready
Message-ID<t7B8D-3eM-47@gated-at.bofh.it>
In reply to#1573997
From: Michal Kubeček <mkubecek@suse.cz>

commit 2c861cc65ef4604011a0082e4dcdba2819aa191a upstream.

When loading the ipv6 module, ndisc_init() is called before
ip6_route_init(). As the former registers a handler calling
fib6_run_gc(), this opens a window to run the garbage collector
before necessary data structures are initialized. If a network
device is initialized in this window, adding MAC address to it
triggers a NETDEV_CHANGEADDR event, leading to a crash in
fib6_clean_all().

Take the event handler registration out of ndisc_init() into a
separate function ndisc_late_init() and move it after
ip6_route_init().

Signed-off-by: Michal Kubecek <mkubecek@suse.cz>
Signed-off-by: David S. Miller <davem@davemloft.net>
Cc: <stable@vger.kernel.org> 
Signed-off-by: Mike Manning <mmanning@brocade.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 include/net/ndisc.h |  2 ++
 net/ipv6/af_inet6.c |  6 ++++++
 net/ipv6/ndisc.c    | 18 +++++++++++-------
 3 files changed, 19 insertions(+), 7 deletions(-)

diff --git a/include/net/ndisc.h b/include/net/ndisc.h
index 5043f8b..4b12d99 100644
--- a/include/net/ndisc.h
+++ b/include/net/ndisc.h
@@ -190,7 +190,9 @@ static inline struct neighbour *__ipv6_neigh_lookup(struct net_device *dev, cons
 }
 
 extern int			ndisc_init(void);
+extern int			ndisc_late_init(void);
 
+extern void			ndisc_late_cleanup(void);
 extern void			ndisc_cleanup(void);
 
 extern int			ndisc_rcv(struct sk_buff *skb);
diff --git a/net/ipv6/af_inet6.c b/net/ipv6/af_inet6.c
index a944f13..9443af7 100644
--- a/net/ipv6/af_inet6.c
+++ b/net/ipv6/af_inet6.c
@@ -900,6 +900,9 @@ static int __init inet6_init(void)
 	err = ip6_route_init();
 	if (err)
 		goto ip6_route_fail;
+	err = ndisc_late_init();
+	if (err)
+		goto ndisc_late_fail;
 	err = ip6_flowlabel_init();
 	if (err)
 		goto ip6_flowlabel_fail;
@@ -960,6 +963,8 @@ ipv6_exthdrs_fail:
 addrconf_fail:
 	ip6_flowlabel_cleanup();
 ip6_flowlabel_fail:
+	ndisc_late_cleanup();
+ndisc_late_fail:
 	ip6_route_cleanup();
 ip6_route_fail:
 #ifdef CONFIG_PROC_FS
@@ -1020,6 +1025,7 @@ static void __exit inet6_exit(void)
 	ipv6_exthdrs_exit();
 	addrconf_cleanup();
 	ip6_flowlabel_cleanup();
+	ndisc_late_cleanup();
 	ip6_route_cleanup();
 #ifdef CONFIG_PROC_FS
 
diff --git a/net/ipv6/ndisc.c b/net/ipv6/ndisc.c
index deedf7d..de10ccf 100644
--- a/net/ipv6/ndisc.c
+++ b/net/ipv6/ndisc.c
@@ -1716,24 +1716,28 @@ int __init ndisc_init(void)
 	if (err)
 		goto out_unregister_pernet;
 #endif
-	err = register_netdevice_notifier(&ndisc_netdev_notifier);
-	if (err)
-		goto out_unregister_sysctl;
 out:
 	return err;
 
-out_unregister_sysctl:
 #ifdef CONFIG_SYSCTL
-	neigh_sysctl_unregister(&nd_tbl.parms);
 out_unregister_pernet:
-#endif
 	unregister_pernet_subsys(&ndisc_net_ops);
 	goto out;
+#endif
 }
 
-void ndisc_cleanup(void)
+int __init ndisc_late_init(void)
+{
+	return register_netdevice_notifier(&ndisc_netdev_notifier);
+}
+
+void ndisc_late_cleanup(void)
 {
 	unregister_netdevice_notifier(&ndisc_netdev_notifier);
+}
+
+void ndisc_cleanup(void)
+{
 #ifdef CONFIG_SYSCTL
 	neigh_sysctl_unregister(&nd_tbl.parms);
 #endif
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574135 — [PATCH 3.10 104/319] swapfile: fix memory corruption via malformed swapfile

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 104/319] swapfile: fix memory corruption via malformed swapfile
Message-ID<t7B8D-3eM-41@gated-at.bofh.it>
In reply to#1573997
From: Jann Horn <jann@thejh.net>

commit dd111be69114cc867f8e826284559bfbc1c40e37 upstream.

When root activates a swap partition whose header has the wrong
endianness, nr_badpages elements of badpages are swabbed before
nr_badpages has been checked, leading to a buffer overrun of up to 8GB.

This normally is not a security issue because it can only be exploited
by root (more specifically, a process with CAP_SYS_ADMIN or the ability
to modify a swap file/partition), and such a process can already e.g.
modify swapped-out memory of any other userspace process on the system.

Link: http://lkml.kernel.org/r/1477949533-2509-1-git-send-email-jann@thejh.net
Signed-off-by: Jann Horn <jann@thejh.net>
Acked-by: Kees Cook <keescook@chromium.org>
Acked-by: Jerome Marchand <jmarchan@redhat.com>
Acked-by: Johannes Weiner <hannes@cmpxchg.org>
Cc: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>
Cc: Vlastimil Babka <vbabka@suse.cz>
Cc: Hugh Dickins <hughd@google.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 mm/swapfile.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/mm/swapfile.c b/mm/swapfile.c
index 746af55b..d0a8983 100644
--- a/mm/swapfile.c
+++ b/mm/swapfile.c
@@ -1922,6 +1922,8 @@ static unsigned long read_swap_header(struct swap_info_struct *p,
 		swab32s(&swap_header->info.version);
 		swab32s(&swap_header->info.last_page);
 		swab32s(&swap_header->info.nr_badpages);
+		if (swap_header->info.nr_badpages > MAX_SWAP_BADPAGES)
+			return 0;
 		for (i = 0; i < swap_header->info.nr_badpages; i++)
 			swab32s(&swap_header->info.badpages[i]);
 	}
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574136 — [PATCH 3.10 223/319] ipv6: fix rtnl locking in setsockopt for anycast and multicast

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 223/319] ipv6: fix rtnl locking in setsockopt for anycast and multicast
Message-ID<t7B8D-3eM-53@gated-at.bofh.it>
In reply to#1573997
From: Sabrina Dubroca <sd@queasysnail.net>

commit a9ed4a2986e13011fcf4ed2d1a1647c53112f55b upstream.

Calling setsockopt with IPV6_JOIN_ANYCAST or IPV6_LEAVE_ANYCAST
triggers the assertion in addrconf_join_solict()/addrconf_leave_solict()

ipv6_sock_ac_join(), ipv6_sock_ac_drop(), ipv6_sock_ac_close() need to
take RTNL before calling ipv6_dev_ac_inc/dec. Same thing with
ipv6_sock_mc_join(), ipv6_sock_mc_drop(), ipv6_sock_mc_close() before
calling ipv6_dev_mc_inc/dec.

This patch moves ASSERT_RTNL() up a level in the call stack.

Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
Signed-off-by: Sabrina Dubroca <sd@queasysnail.net>
Reported-by: Tommi Rantala <tt.rantala@gmail.com>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Cc: <stable@vger.kernel.org> 
Cc: <stable@vger.kernel.org> 
Cc: <stable@vger.kernel.org> 
[Mike Manning <mmanning@brocade.com>: resolved minor conflicts in addrconf.c]
Signed-off-by: Mike Manning <mmanning@brocade.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/ipv6/addrconf.c | 15 +++++----------
 net/ipv6/anycast.c  | 12 ++++++++++++
 net/ipv6/mcast.c    | 14 ++++++++++++++
 3 files changed, 31 insertions(+), 10 deletions(-)

diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
index 0f18d858..3bfd8a5 100644
--- a/net/ipv6/addrconf.c
+++ b/net/ipv6/addrconf.c
@@ -1697,14 +1697,12 @@ void addrconf_dad_failure(struct inet6_ifaddr *ifp)
 	in6_ifa_put(ifp);
 }
 
-/* Join to solicited addr multicast group. */
-
+/* Join to solicited addr multicast group.
+ * caller must hold RTNL */
 void addrconf_join_solict(struct net_device *dev, const struct in6_addr *addr)
 {
 	struct in6_addr maddr;
 
-	ASSERT_RTNL();
-
 	if (dev->flags&(IFF_LOOPBACK|IFF_NOARP))
 		return;
 
@@ -1712,12 +1710,11 @@ void addrconf_join_solict(struct net_device *dev, const struct in6_addr *addr)
 	ipv6_dev_mc_inc(dev, &maddr);
 }
 
+/* caller must hold RTNL */
 void addrconf_leave_solict(struct inet6_dev *idev, const struct in6_addr *addr)
 {
 	struct in6_addr maddr;
 
-	ASSERT_RTNL();
-
 	if (idev->dev->flags&(IFF_LOOPBACK|IFF_NOARP))
 		return;
 
@@ -1725,12 +1722,11 @@ void addrconf_leave_solict(struct inet6_dev *idev, const struct in6_addr *addr)
 	__ipv6_dev_mc_dec(idev, &maddr);
 }
 
+/* caller must hold RTNL */
 static void addrconf_join_anycast(struct inet6_ifaddr *ifp)
 {
 	struct in6_addr addr;
 
-	ASSERT_RTNL();
-
 	if (ifp->prefix_len == 127) /* RFC 6164 */
 		return;
 	ipv6_addr_prefix(&addr, &ifp->addr, ifp->prefix_len);
@@ -1739,12 +1735,11 @@ static void addrconf_join_anycast(struct inet6_ifaddr *ifp)
 	ipv6_dev_ac_inc(ifp->idev->dev, &addr);
 }
 
+/* caller must hold RTNL */
 static void addrconf_leave_anycast(struct inet6_ifaddr *ifp)
 {
 	struct in6_addr addr;
 
-	ASSERT_RTNL();
-
 	if (ifp->prefix_len == 127) /* RFC 6164 */
 		return;
 	ipv6_addr_prefix(&addr, &ifp->addr, ifp->prefix_len);
diff --git a/net/ipv6/anycast.c b/net/ipv6/anycast.c
index 5a80f15..c59083c 100644
--- a/net/ipv6/anycast.c
+++ b/net/ipv6/anycast.c
@@ -77,6 +77,7 @@ int ipv6_sock_ac_join(struct sock *sk, int ifindex, const struct in6_addr *addr)
 	pac->acl_next = NULL;
 	pac->acl_addr = *addr;
 
+	rtnl_lock();
 	rcu_read_lock();
 	if (ifindex == 0) {
 		struct rt6_info *rt;
@@ -137,6 +138,7 @@ int ipv6_sock_ac_join(struct sock *sk, int ifindex, const struct in6_addr *addr)
 
 error:
 	rcu_read_unlock();
+	rtnl_unlock();
 	if (pac)
 		sock_kfree_s(sk, pac, sizeof(*pac));
 	return err;
@@ -171,13 +173,17 @@ int ipv6_sock_ac_drop(struct sock *sk, int ifindex, const struct in6_addr *addr)
 
 	spin_unlock_bh(&ipv6_sk_ac_lock);
 
+	rtnl_lock();
 	rcu_read_lock();
 	dev = dev_get_by_index_rcu(net, pac->acl_ifindex);
 	if (dev)
 		ipv6_dev_ac_dec(dev, &pac->acl_addr);
 	rcu_read_unlock();
+	rtnl_unlock();
 
 	sock_kfree_s(sk, pac, sizeof(*pac));
+	if (!dev)
+		return -ENODEV;
 	return 0;
 }
 
@@ -198,6 +204,7 @@ void ipv6_sock_ac_close(struct sock *sk)
 	spin_unlock_bh(&ipv6_sk_ac_lock);
 
 	prev_index = 0;
+	rtnl_lock();
 	rcu_read_lock();
 	while (pac) {
 		struct ipv6_ac_socklist *next = pac->acl_next;
@@ -212,6 +219,7 @@ void ipv6_sock_ac_close(struct sock *sk)
 		pac = next;
 	}
 	rcu_read_unlock();
+	rtnl_unlock();
 }
 
 static void aca_put(struct ifacaddr6 *ac)
@@ -233,6 +241,8 @@ int ipv6_dev_ac_inc(struct net_device *dev, const struct in6_addr *addr)
 	struct rt6_info *rt;
 	int err;
 
+	ASSERT_RTNL();
+
 	idev = in6_dev_get(dev);
 
 	if (idev == NULL)
@@ -302,6 +312,8 @@ int __ipv6_dev_ac_dec(struct inet6_dev *idev, const struct in6_addr *addr)
 {
 	struct ifacaddr6 *aca, *prev_aca;
 
+	ASSERT_RTNL();
+
 	write_lock_bh(&idev->lock);
 	prev_aca = NULL;
 	for (aca = idev->ac_list; aca; aca = aca->aca_next) {
diff --git a/net/ipv6/mcast.c b/net/ipv6/mcast.c
index 7ba6180..cf16eb4 100644
--- a/net/ipv6/mcast.c
+++ b/net/ipv6/mcast.c
@@ -157,6 +157,7 @@ int ipv6_sock_mc_join(struct sock *sk, int ifindex, const struct in6_addr *addr)
 	mc_lst->next = NULL;
 	mc_lst->addr = *addr;
 
+	rtnl_lock();
 	rcu_read_lock();
 	if (ifindex == 0) {
 		struct rt6_info *rt;
@@ -170,6 +171,7 @@ int ipv6_sock_mc_join(struct sock *sk, int ifindex, const struct in6_addr *addr)
 
 	if (dev == NULL) {
 		rcu_read_unlock();
+		rtnl_unlock();
 		sock_kfree_s(sk, mc_lst, sizeof(*mc_lst));
 		return -ENODEV;
 	}
@@ -187,6 +189,7 @@ int ipv6_sock_mc_join(struct sock *sk, int ifindex, const struct in6_addr *addr)
 
 	if (err) {
 		rcu_read_unlock();
+		rtnl_unlock();
 		sock_kfree_s(sk, mc_lst, sizeof(*mc_lst));
 		return err;
 	}
@@ -197,6 +200,7 @@ int ipv6_sock_mc_join(struct sock *sk, int ifindex, const struct in6_addr *addr)
 	spin_unlock(&ipv6_sk_mc_lock);
 
 	rcu_read_unlock();
+	rtnl_unlock();
 
 	return 0;
 }
@@ -214,6 +218,7 @@ int ipv6_sock_mc_drop(struct sock *sk, int ifindex, const struct in6_addr *addr)
 	if (!ipv6_addr_is_multicast(addr))
 		return -EINVAL;
 
+	rtnl_lock();
 	spin_lock(&ipv6_sk_mc_lock);
 	for (lnk = &np->ipv6_mc_list;
 	     (mc_lst = rcu_dereference_protected(*lnk,
@@ -237,12 +242,15 @@ int ipv6_sock_mc_drop(struct sock *sk, int ifindex, const struct in6_addr *addr)
 			} else
 				(void) ip6_mc_leave_src(sk, mc_lst, NULL);
 			rcu_read_unlock();
+			rtnl_unlock();
+
 			atomic_sub(sizeof(*mc_lst), &sk->sk_omem_alloc);
 			kfree_rcu(mc_lst, rcu);
 			return 0;
 		}
 	}
 	spin_unlock(&ipv6_sk_mc_lock);
+	rtnl_unlock();
 
 	return -EADDRNOTAVAIL;
 }
@@ -287,6 +295,7 @@ void ipv6_sock_mc_close(struct sock *sk)
 	if (!rcu_access_pointer(np->ipv6_mc_list))
 		return;
 
+	rtnl_lock();
 	spin_lock(&ipv6_sk_mc_lock);
 	while ((mc_lst = rcu_dereference_protected(np->ipv6_mc_list,
 				lockdep_is_held(&ipv6_sk_mc_lock))) != NULL) {
@@ -313,6 +322,7 @@ void ipv6_sock_mc_close(struct sock *sk)
 		spin_lock(&ipv6_sk_mc_lock);
 	}
 	spin_unlock(&ipv6_sk_mc_lock);
+	rtnl_unlock();
 }
 
 int ip6_mc_source(int add, int omode, struct sock *sk,
@@ -830,6 +840,8 @@ int ipv6_dev_mc_inc(struct net_device *dev, const struct in6_addr *addr)
 	struct ifmcaddr6 *mc;
 	struct inet6_dev *idev;
 
+	ASSERT_RTNL();
+
 	/* we need to take a reference on idev */
 	idev = in6_dev_get(dev);
 
@@ -901,6 +913,8 @@ int __ipv6_dev_mc_dec(struct inet6_dev *idev, const struct in6_addr *addr)
 {
 	struct ifmcaddr6 *ma, **map;
 
+	ASSERT_RTNL();
+
 	write_lock_bh(&idev->lock);
 	for (map = &idev->mc_list; (ma=*map) != NULL; map = &ma->next) {
 		if (ipv6_addr_equal(&ma->mca_addr, addr)) {
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574137 — [PATCH 3.10 240/319] net: disable fragment reassembly if high_thresh is set to zero

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 240/319] net: disable fragment reassembly if high_thresh is set to zero
Message-ID<t7B8E-3eM-57@gated-at.bofh.it>
In reply to#1573997
From: Michal Kubecek <mkubecek@suse.cz>

commit 30759219f562cfaaebe7b9c1d1c0e6b5445c69b0 upstream.

Before commit 6d7b857d541e ("net: use lib/percpu_counter API for
fragmentation mem accounting"), setting high threshold to 0 prevented
fragment reassembly as first fragment would be always evicted before
second could be added to the queue. While inefficient, some users
apparently relied on it.

Since the commit mentioned above, a percpu counter is used for
reassembly memory accounting and high batch size avoids taking slow path
in most common scenarios. As a result, a whole full sized packet can be
reassembled without the percpu counter's main counter changing its
value so that even with high_thresh set to 0, fragmented packets can be
still reassembled and processed.

Add explicit checks preventing reassembly if high threshold is zero.

[mk] backport to 3.12

Signed-off-by: Michal Kubecek <mkubecek@suse.cz>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/ipv4/ip_fragment.c                  | 4 ++++
 net/ipv6/netfilter/nf_conntrack_reasm.c | 3 +++
 net/ipv6/reassembly.c                   | 4 ++++
 3 files changed, 11 insertions(+)

diff --git a/net/ipv4/ip_fragment.c b/net/ipv4/ip_fragment.c
index 4d98a6b..04c7e46 100644
--- a/net/ipv4/ip_fragment.c
+++ b/net/ipv4/ip_fragment.c
@@ -656,6 +656,9 @@ int ip_defrag(struct sk_buff *skb, u32 user)
 	net = skb->dev ? dev_net(skb->dev) : dev_net(skb_dst(skb)->dev);
 	IP_INC_STATS_BH(net, IPSTATS_MIB_REASMREQDS);
 
+	if (!net->ipv4.frags.high_thresh)
+		goto fail;
+
 	/* Start by cleaning up the memory. */
 	ip_evictor(net);
 
@@ -672,6 +675,7 @@ int ip_defrag(struct sk_buff *skb, u32 user)
 		return ret;
 	}
 
+fail:
 	IP_INC_STATS_BH(net, IPSTATS_MIB_REASMFAILS);
 	kfree_skb(skb);
 	return -ENOMEM;
diff --git a/net/ipv6/netfilter/nf_conntrack_reasm.c b/net/ipv6/netfilter/nf_conntrack_reasm.c
index 7cd6235..c11a40c 100644
--- a/net/ipv6/netfilter/nf_conntrack_reasm.c
+++ b/net/ipv6/netfilter/nf_conntrack_reasm.c
@@ -569,6 +569,9 @@ struct sk_buff *nf_ct_frag6_gather(struct sk_buff *skb, u32 user)
 	if (find_prev_fhdr(skb, &prevhdr, &nhoff, &fhoff) < 0)
 		return skb;
 
+	if (!net->nf_frag.frags.high_thresh)
+		return skb;
+
 	clone = skb_clone(skb, GFP_ATOMIC);
 	if (clone == NULL) {
 		pr_debug("Can't clone skb\n");
diff --git a/net/ipv6/reassembly.c b/net/ipv6/reassembly.c
index a1fb511..1a5318e 100644
--- a/net/ipv6/reassembly.c
+++ b/net/ipv6/reassembly.c
@@ -556,6 +556,9 @@ static int ipv6_frag_rcv(struct sk_buff *skb)
 		return 1;
 	}
 
+	if (!net->ipv6.frags.high_thresh)
+		goto fail_mem;
+
 	evicted = inet_frag_evictor(&net->ipv6.frags, &ip6_frags, false);
 	if (evicted)
 		IP6_ADD_STATS_BH(net, ip6_dst_idev(skb_dst(skb)),
@@ -575,6 +578,7 @@ static int ipv6_frag_rcv(struct sk_buff *skb)
 		return ret;
 	}
 
+fail_mem:
 	IP6_INC_STATS_BH(net, ip6_dst_idev(skb_dst(skb)), IPSTATS_MIB_REASMFAILS);
 	kfree_skb(skb);
 	return -1;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574138 — [PATCH 3.10 204/319] IB/mlx4: Fix create CQ error flow

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 204/319] IB/mlx4: Fix create CQ error flow
Message-ID<t7B8D-3eM-49@gated-at.bofh.it>
In reply to#1573997
From: Matan Barak <matanb@mellanox.com>

commit 593ff73bcfdc79f79a8a0df55504f75ad3e5d1a9 upstream.

Currently, if ib_copy_to_udata fails, the CQ
won't be deleted from the radix tree and the HW (HW2SW).

Fixes: 225c7b1feef1 ('IB/mlx4: Add a driver Mellanox ConnectX InfiniBand adapters')
Signed-off-by: Matan Barak <matanb@mellanox.com>
Signed-off-by: Daniel Jurgens <danielj@mellanox.com>
Reviewed-by: Mark Bloch <markb@mellanox.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Doug Ledford <dledford@redhat.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/infiniband/hw/mlx4/cq.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/drivers/infiniband/hw/mlx4/cq.c b/drivers/infiniband/hw/mlx4/cq.c
index d5e60f4..5b8a62c 100644
--- a/drivers/infiniband/hw/mlx4/cq.c
+++ b/drivers/infiniband/hw/mlx4/cq.c
@@ -239,11 +239,14 @@ struct ib_cq *mlx4_ib_create_cq(struct ib_device *ibdev, int entries, int vector
 	if (context)
 		if (ib_copy_to_udata(udata, &cq->mcq.cqn, sizeof (__u32))) {
 			err = -EFAULT;
-			goto err_dbmap;
+			goto err_cq_free;
 		}
 
 	return &cq->ibcq;
 
+err_cq_free:
+	mlx4_cq_free(dev->dev, &cq->mcq);
+
 err_dbmap:
 	if (context)
 		mlx4_ib_db_unmap_user(to_mucontext(context), &cq->db);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574139 — [PATCH 3.10 294/319] pstore/ram: Use memcpy_toio instead of memcpy

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 294/319] pstore/ram: Use memcpy_toio instead of memcpy
Message-ID<t7B8D-3eM-45@gated-at.bofh.it>
In reply to#1573997
From: Furquan Shaikh <furquan@google.com>

commit 7e75678d23167c2527e655658a8ef36a36c8b4d9 upstream.

persistent_ram_update uses vmap / iomap based on whether the buffer is in
memory region or reserved region. However, both map it as non-cacheable
memory. For armv8 specifically, non-cacheable mapping requests use a
memory type that has to be accessed aligned to the request size. memcpy()
doesn't guarantee that.

Signed-off-by: Furquan Shaikh <furquan@google.com>
Signed-off-by: Enric Balletbo Serra <enric.balletbo@collabora.com>
Reviewed-by: Aaron Durbin <adurbin@chromium.org>
Reviewed-by: Olof Johansson <olofj@chromium.org>
Tested-by: Furquan Shaikh <furquan@chromium.org>
Signed-off-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/pstore/ram_core.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/pstore/ram_core.c b/fs/pstore/ram_core.c
index ee3c6ec..eb42483 100644
--- a/fs/pstore/ram_core.c
+++ b/fs/pstore/ram_core.c
@@ -263,7 +263,7 @@ static void notrace persistent_ram_update(struct persistent_ram_zone *prz,
 	const void *s, unsigned int start, unsigned int count)
 {
 	struct persistent_ram_buffer *buffer = prz->buffer;
-	memcpy(buffer->data + start, s, count);
+	memcpy_toio(buffer->data + start, s, count);
 	persistent_ram_update_ecc(prz, start, count);
 }
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574140 — [PATCH 3.10 285/319] lib/genalloc.c: start search from start of chunk

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 285/319] lib/genalloc.c: start search from start of chunk
Message-ID<t7B8E-3eM-59@gated-at.bofh.it>
In reply to#1573997
From: Daniel Mentz <danielmentz@google.com>

commit 62e931fac45b17c2a42549389879411572f75804 upstream.

gen_pool_alloc_algo() iterates over the chunks of a pool trying to find
a contiguous block of memory that satisfies the allocation request.

The shortcut

	if (size > atomic_read(&chunk->avail))
		continue;

makes the loop skip over chunks that do not have enough bytes left to
fulfill the request.  There are two situations, though, where an
allocation might still fail:

(1) The available memory is not contiguous, i.e.  the request cannot
    be fulfilled due to external fragmentation.

(2) A race condition.  Another thread runs the same code concurrently
    and is quicker to grab the available memory.

In those situations, the loop calls pool->algo() to search the entire
chunk, and pool->algo() returns some value that is >= end_bit to
indicate that the search failed.  This return value is then assigned to
start_bit.  The variables start_bit and end_bit describe the range that
should be searched, and this range should be reset for every chunk that
is searched.  Today, the code fails to reset start_bit to 0.  As a
result, prefixes of subsequent chunks are ignored.  Memory allocations
might fail even though there is plenty of room left in these prefixes of
those other chunks.

Fixes: 7f184275aa30 ("lib, Make gen_pool memory allocator lockless")
Link: http://lkml.kernel.org/r/1477420604-28918-1-git-send-email-danielmentz@google.com
Signed-off-by: Daniel Mentz <danielmentz@google.com>
Reviewed-by: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Acked-by: Will Deacon <will.deacon@arm.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 lib/genalloc.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/lib/genalloc.c b/lib/genalloc.c
index 2a39bf6..ac5fba9 100644
--- a/lib/genalloc.c
+++ b/lib/genalloc.c
@@ -273,7 +273,7 @@ unsigned long gen_pool_alloc(struct gen_pool *pool, size_t size)
 	struct gen_pool_chunk *chunk;
 	unsigned long addr = 0;
 	int order = pool->min_alloc_order;
-	int nbits, start_bit = 0, end_bit, remain;
+	int nbits, start_bit, end_bit, remain;
 
 #ifndef CONFIG_ARCH_HAVE_NMI_SAFE_CMPXCHG
 	BUG_ON(in_nmi());
@@ -288,6 +288,7 @@ unsigned long gen_pool_alloc(struct gen_pool *pool, size_t size)
 		if (size > atomic_read(&chunk->avail))
 			continue;
 
+		start_bit = 0;
 		end_bit = chunk_size(chunk) >> order;
 retry:
 		start_bit = pool->algo(chunk->bits, end_bit, start_bit, nbits,
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574141 — [PATCH 3.10 257/319] net: sctp, forbid negative length

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 257/319] net: sctp, forbid negative length
Message-ID<t7B8E-3eM-61@gated-at.bofh.it>
In reply to#1573997
From: Jiri Slaby <jslaby@suse.cz>

commit a4b8e71b05c27bae6bad3bdecddbc6b68a3ad8cf upstream.

Most of getsockopt handlers in net/sctp/socket.c check len against
sizeof some structure like:
        if (len < sizeof(int))
                return -EINVAL;

On the first look, the check seems to be correct. But since len is int
and sizeof returns size_t, int gets promoted to unsigned size_t too. So
the test returns false for negative lengths. Yes, (-1 < sizeof(long)) is
false.

Fix this in sctp by explicitly checking len < 0 before any getsockopt
handler is called.

Note that sctp_getsockopt_events already handled the negative case.
Since we added the < 0 check elsewhere, this one can be removed.

If not checked, this is the result:
UBSAN: Undefined behaviour in ../mm/page_alloc.c:2722:19
shift exponent 52 is too large for 32-bit type 'int'
CPU: 1 PID: 24535 Comm: syz-executor Not tainted 4.8.1-0-syzkaller #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.9.1-0-gb3ef39f-prebuilt.qemu-project.org 04/01/2014
 0000000000000000 ffff88006d99f2a8 ffffffffb2f7bdea 0000000041b58ab3
 ffffffffb4363c14 ffffffffb2f7bcde ffff88006d99f2d0 ffff88006d99f270
 0000000000000000 0000000000000000 0000000000000034 ffffffffb5096422
Call Trace:
 [<ffffffffb3051498>] ? __ubsan_handle_shift_out_of_bounds+0x29c/0x300
...
 [<ffffffffb273f0e4>] ? kmalloc_order+0x24/0x90
 [<ffffffffb27416a4>] ? kmalloc_order_trace+0x24/0x220
 [<ffffffffb2819a30>] ? __kmalloc+0x330/0x540
 [<ffffffffc18c25f4>] ? sctp_getsockopt_local_addrs+0x174/0xca0 [sctp]
 [<ffffffffc18d2bcd>] ? sctp_getsockopt+0x10d/0x1b0 [sctp]
 [<ffffffffb37c1219>] ? sock_common_getsockopt+0xb9/0x150
 [<ffffffffb37be2f5>] ? SyS_getsockopt+0x1a5/0x270

Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Cc: Vlad Yasevich <vyasevich@gmail.com>
Cc: Neil Horman <nhorman@tuxdriver.com>
Cc: "David S. Miller" <davem@davemloft.net>
Cc: linux-sctp@vger.kernel.org
Cc: netdev@vger.kernel.org
Acked-by: Neil Horman <nhorman@tuxdriver.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/sctp/socket.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/net/sctp/socket.c b/net/sctp/socket.c
index bdc3fb6..86e7352 100644
--- a/net/sctp/socket.c
+++ b/net/sctp/socket.c
@@ -4259,7 +4259,7 @@ static int sctp_getsockopt_disable_fragments(struct sock *sk, int len,
 static int sctp_getsockopt_events(struct sock *sk, int len, char __user *optval,
 				  int __user *optlen)
 {
-	if (len <= 0)
+	if (len == 0)
 		return -EINVAL;
 	if (len > sizeof(struct sctp_event_subscribe))
 		len = sizeof(struct sctp_event_subscribe);
@@ -5770,6 +5770,9 @@ SCTP_STATIC int sctp_getsockopt(struct sock *sk, int level, int optname,
 	if (get_user(len, optlen))
 		return -EFAULT;
 
+	if (len < 0)
+		return -EINVAL;
+
 	sctp_lock_sock(sk);
 
 	switch (optname) {
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574142 — [PATCH 3.10 230/319] net/irda: handle iriap_register_lsap() allocation failure

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 230/319] net/irda: handle iriap_register_lsap() allocation failure
Message-ID<t7B8E-3eM-73@gated-at.bofh.it>
In reply to#1573997
From: Vegard Nossum <vegard.nossum@oracle.com>

commit 5ba092efc7ddff040777ae7162f1d195f513571b upstream.

If iriap_register_lsap() fails to allocate memory, self->lsap is
set to NULL. However, none of the callers handle the failure and
irlmp_connect_request() will happily dereference it:

    iriap_register_lsap: Unable to allocated LSAP!
    ================================================================================
    UBSAN: Undefined behaviour in net/irda/irlmp.c:378:2
    member access within null pointer of type 'struct lsap_cb'
    CPU: 1 PID: 15403 Comm: trinity-c0 Not tainted 4.8.0-rc1+ #81
    Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.9.3-0-ge2fc41e-prebuilt.qemu-project.org
    04/01/2014
     0000000000000000 ffff88010c7e78a8 ffffffff82344f40 0000000041b58ab3
     ffffffff84f98000 ffffffff82344e94 ffff88010c7e78d0 ffff88010c7e7880
     ffff88010630ad00 ffffffff84a5fae0 ffffffff84d3f5c0 000000000000017a
    Call Trace:
     [<ffffffff82344f40>] dump_stack+0xac/0xfc
     [<ffffffff8242f5a8>] ubsan_epilogue+0xd/0x8a
     [<ffffffff824302bf>] __ubsan_handle_type_mismatch+0x157/0x411
     [<ffffffff83b7bdbc>] irlmp_connect_request+0x7ac/0x970
     [<ffffffff83b77cc0>] iriap_connect_request+0xa0/0x160
     [<ffffffff83b77f48>] state_s_disconnect+0x88/0xd0
     [<ffffffff83b78904>] iriap_do_client_event+0x94/0x120
     [<ffffffff83b77710>] iriap_getvaluebyclass_request+0x3e0/0x6d0
     [<ffffffff83ba6ebb>] irda_find_lsap_sel+0x1eb/0x630
     [<ffffffff83ba90c8>] irda_connect+0x828/0x12d0
     [<ffffffff833c0dfb>] SYSC_connect+0x22b/0x340
     [<ffffffff833c7e09>] SyS_connect+0x9/0x10
     [<ffffffff81007bd3>] do_syscall_64+0x1b3/0x4b0
     [<ffffffff845f946a>] entry_SYSCALL64_slow_path+0x25/0x25
    ================================================================================

The bug seems to have been around since forever.

There's more problems with missing error checks in iriap_init() (and
indeed all of irda_init()), but that's a bigger problem that needs
very careful review and testing. This patch will fix the most serious
bug (as it's easily reached from unprivileged userspace).

I have tested my patch with a reproducer.

Signed-off-by: Vegard Nossum <vegard.nossum@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/irda/iriap.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/net/irda/iriap.c b/net/irda/iriap.c
index e1b37f5..bd42516 100644
--- a/net/irda/iriap.c
+++ b/net/irda/iriap.c
@@ -191,8 +191,12 @@ struct iriap_cb *iriap_open(__u8 slsap_sel, int mode, void *priv,
 
 	self->magic = IAS_MAGIC;
 	self->mode = mode;
-	if (mode == IAS_CLIENT)
-		iriap_register_lsap(self, slsap_sel, mode);
+	if (mode == IAS_CLIENT) {
+		if (iriap_register_lsap(self, slsap_sel, mode)) {
+			kfree(self);
+			return NULL;
+		}
+	}
 
 	self->confirm = callback;
 	self->priv = priv;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574143 — [PATCH 3.10 313/319] mpi: Fix NULL ptr dereference in mpi_powm() [ver #3]

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 313/319] mpi: Fix NULL ptr dereference in mpi_powm() [ver #3]
Message-ID<t7B8E-3eM-71@gated-at.bofh.it>
In reply to#1573997
From: Andrey Ryabinin <aryabinin@virtuozzo.com>

commit f5527fffff3f002b0a6b376163613b82f69de073 upstream.

This fixes CVE-2016-8650.

If mpi_powm() is given a zero exponent, it wants to immediately return
either 1 or 0, depending on the modulus.  However, if the result was
initalised with zero limb space, no limbs space is allocated and a
NULL-pointer exception ensues.

Fix this by allocating a minimal amount of limb space for the result when
the 0-exponent case when the result is 1 and not touching the limb space
when the result is 0.

This affects the use of RSA keys and X.509 certificates that carry them.

BUG: unable to handle kernel NULL pointer dereference at           (null)
IP: [<ffffffff8138ce5d>] mpi_powm+0x32/0x7e6
PGD 0
Oops: 0002 [#1] SMP
Modules linked in:
CPU: 3 PID: 3014 Comm: keyctl Not tainted 4.9.0-rc6-fscache+ #278
Hardware name: ASUS All Series/H97-PLUS, BIOS 2306 10/09/2014
task: ffff8804011944c0 task.stack: ffff880401294000
RIP: 0010:[<ffffffff8138ce5d>]  [<ffffffff8138ce5d>] mpi_powm+0x32/0x7e6
RSP: 0018:ffff880401297ad8  EFLAGS: 00010212
RAX: 0000000000000000 RBX: ffff88040868bec0 RCX: ffff88040868bba0
RDX: ffff88040868b260 RSI: ffff88040868bec0 RDI: ffff88040868bee0
RBP: ffff880401297ba8 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000047 R11: ffffffff8183b210 R12: 0000000000000000
R13: ffff8804087c7600 R14: 000000000000001f R15: ffff880401297c50
FS:  00007f7a7918c700(0000) GS:ffff88041fb80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000401250000 CR4: 00000000001406e0
Stack:
 ffff88040868bec0 0000000000000020 ffff880401297b00 ffffffff81376cd4
 0000000000000100 ffff880401297b10 ffffffff81376d12 ffff880401297b30
 ffffffff81376f37 0000000000000100 0000000000000000 ffff880401297ba8
Call Trace:
 [<ffffffff81376cd4>] ? __sg_page_iter_next+0x43/0x66
 [<ffffffff81376d12>] ? sg_miter_get_next_page+0x1b/0x5d
 [<ffffffff81376f37>] ? sg_miter_next+0x17/0xbd
 [<ffffffff8138ba3a>] ? mpi_read_raw_from_sgl+0xf2/0x146
 [<ffffffff8132a95c>] rsa_verify+0x9d/0xee
 [<ffffffff8132acca>] ? pkcs1pad_sg_set_buf+0x2e/0xbb
 [<ffffffff8132af40>] pkcs1pad_verify+0xc0/0xe1
 [<ffffffff8133cb5e>] public_key_verify_signature+0x1b0/0x228
 [<ffffffff8133d974>] x509_check_for_self_signed+0xa1/0xc4
 [<ffffffff8133cdde>] x509_cert_parse+0x167/0x1a1
 [<ffffffff8133d609>] x509_key_preparse+0x21/0x1a1
 [<ffffffff8133c3d7>] asymmetric_key_preparse+0x34/0x61
 [<ffffffff812fc9f3>] key_create_or_update+0x145/0x399
 [<ffffffff812fe227>] SyS_add_key+0x154/0x19e
 [<ffffffff81001c2b>] do_syscall_64+0x80/0x191
 [<ffffffff816825e4>] entry_SYSCALL64_slow_path+0x25/0x25
Code: 56 41 55 41 54 53 48 81 ec a8 00 00 00 44 8b 71 04 8b 42 04 4c 8b 67 18 45 85 f6 89 45 80 0f 84 b4 06 00 00 85 c0 75 2f 41 ff ce <49> c7 04 24 01 00 00 00 b0 01 75 0b 48 8b 41 18 48 83 38 01 0f
RIP  [<ffffffff8138ce5d>] mpi_powm+0x32/0x7e6
 RSP <ffff880401297ad8>
CR2: 0000000000000000
---[ end trace d82015255d4a5d8d ]---

Basically, this is a backport of a libgcrypt patch:

	http://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=patch;h=6e1adb05d290aeeb1c230c763970695f4a538526

Fixes: cdec9cb5167a ("crypto: GnuPG based MPI lib - source files (part 1)")
Signed-off-by: Andrey Ryabinin <aryabinin@virtuozzo.com>
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Dmitry Kasatkin <dmitry.kasatkin@gmail.com>
cc: linux-ima-devel@lists.sourceforge.net
Signed-off-by: James Morris <james.l.morris@oracle.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 lib/mpi/mpi-pow.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/lib/mpi/mpi-pow.c b/lib/mpi/mpi-pow.c
index 5464c87..e24388a 100644
--- a/lib/mpi/mpi-pow.c
+++ b/lib/mpi/mpi-pow.c
@@ -64,8 +64,13 @@ int mpi_powm(MPI res, MPI base, MPI exp, MPI mod)
 	if (!esize) {
 		/* Exponent is zero, result is 1 mod MOD, i.e., 1 or 0
 		 * depending on if MOD equals 1.  */
-		rp[0] = 1;
 		res->nlimbs = (msize == 1 && mod->d[0] == 1) ? 0 : 1;
+		if (res->nlimbs) {
+			if (mpi_resize(res, 1) < 0)
+				goto enomem;
+			rp = res->d;
+			rp[0] = 1;
+		}
 		res->sign = 0;
 		goto leave;
 	}
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574144 — [PATCH 3.10 168/319] UBI: fastmap: scrub PEB when bitflips are detected in a free PEB EC header

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 168/319] UBI: fastmap: scrub PEB when bitflips are detected in a free PEB EC header
Message-ID<t7B8E-3eM-75@gated-at.bofh.it>
In reply to#1573997
From: Boris Brezillon <boris.brezillon@free-electrons.com>

commit ecbfa8eabae9cd73522d1d3d15869703c263d859 upstream.

scan_pool() does not mark the PEB for scrubing when bitflips are
detected in the EC header of a free PEB (VID header region left to
0xff).
Make sure we scrub the PEB in this case.

Signed-off-by: Boris Brezillon <boris.brezillon@free-electrons.com>
Fixes: dbb7d2a88d2a ("UBI: Add fastmap core")
Signed-off-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/mtd/ubi/fastmap.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/drivers/mtd/ubi/fastmap.c b/drivers/mtd/ubi/fastmap.c
index bf8108d..f6f1604 100644
--- a/drivers/mtd/ubi/fastmap.c
+++ b/drivers/mtd/ubi/fastmap.c
@@ -438,10 +438,11 @@ static int scan_pool(struct ubi_device *ubi, struct ubi_attach_info *ai,
 			unsigned long long ec = be64_to_cpu(ech->ec);
 			unmap_peb(ai, pnum);
 			dbg_bld("Adding PEB to free: %i", pnum);
+
 			if (err == UBI_IO_FF_BITFLIPS)
-				add_aeb(ai, free, pnum, ec, 1);
-			else
-				add_aeb(ai, free, pnum, ec, 0);
+				scrub = 1;
+
+			add_aeb(ai, free, pnum, ec, scrub);
 			continue;
 		} else if (err == 0 || err == UBI_IO_BITFLIPS) {
 			dbg_bld("Found non empty PEB:%i in pool", pnum);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574145 — [PATCH 3.10 162/319] ocfs2: fix start offset to ocfs2_zero_range_for_truncate()

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 162/319] ocfs2: fix start offset to ocfs2_zero_range_for_truncate()
Message-ID<t7B8E-3eM-77@gated-at.bofh.it>
In reply to#1573997
From: Ashish Samant <ashish.samant@oracle.com>

commit d21c353d5e99c56cdd5b5c1183ffbcaf23b8b960 upstream.

If we punch a hole on a reflink such that following conditions are met:

1. start offset is on a cluster boundary
2. end offset is not on a cluster boundary
3. (end offset is somewhere in another extent) or
   (hole range > MAX_CONTIG_BYTES(1MB)),

we dont COW the first cluster starting at the start offset.  But in this
case, we were wrongly passing this cluster to
ocfs2_zero_range_for_truncate() to zero out.  This will modify the
cluster in place and zero it in the source too.

Fix this by skipping this cluster in such a scenario.

To reproduce:

1. Create a random file of say 10 MB
     xfs_io -c 'pwrite -b 4k 0 10M' -f 10MBfile
2. Reflink  it
     reflink -f 10MBfile reflnktest
3. Punch a hole at starting at cluster boundary  with range greater that
1MB. You can also use a range that will put the end offset in another
extent.
     fallocate -p -o 0 -l 1048615 reflnktest
4. sync
5. Check the  first cluster in the source file. (It will be zeroed out).
    dd if=10MBfile iflag=direct bs=<cluster size> count=1 | hexdump -C

Link: http://lkml.kernel.org/r/1470957147-14185-1-git-send-email-ashish.samant@oracle.com
Signed-off-by: Ashish Samant <ashish.samant@oracle.com>
Reported-by: Saar Maoz <saar.maoz@oracle.com>
Reviewed-by: Srinivas Eeda <srinivas.eeda@oracle.com>
Cc: Mark Fasheh <mfasheh@versity.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Joseph Qi <joseph.qi@huawei.com>
Cc: Eric Ren <zren@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/ocfs2/file.c | 34 ++++++++++++++++++++++++----------
 1 file changed, 24 insertions(+), 10 deletions(-)

diff --git a/fs/ocfs2/file.c b/fs/ocfs2/file.c
index d0e8c0b..496af7f 100644
--- a/fs/ocfs2/file.c
+++ b/fs/ocfs2/file.c
@@ -1499,7 +1499,8 @@ static int ocfs2_zero_partial_clusters(struct inode *inode,
 				       u64 start, u64 len)
 {
 	int ret = 0;
-	u64 tmpend, end = start + len;
+	u64 tmpend = 0;
+	u64 end = start + len;
 	struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
 	unsigned int csize = osb->s_clustersize;
 	handle_t *handle;
@@ -1531,18 +1532,31 @@ static int ocfs2_zero_partial_clusters(struct inode *inode,
 	}
 
 	/*
-	 * We want to get the byte offset of the end of the 1st cluster.
+	 * If start is on a cluster boundary and end is somewhere in another
+	 * cluster, we have not COWed the cluster starting at start, unless
+	 * end is also within the same cluster. So, in this case, we skip this
+	 * first call to ocfs2_zero_range_for_truncate() truncate and move on
+	 * to the next one.
 	 */
-	tmpend = (u64)osb->s_clustersize + (start & ~(osb->s_clustersize - 1));
-	if (tmpend > end)
-		tmpend = end;
+	if ((start & (csize - 1)) != 0) {
+		/*
+		 * We want to get the byte offset of the end of the 1st
+		 * cluster.
+		 */
+		tmpend = (u64)osb->s_clustersize +
+			(start & ~(osb->s_clustersize - 1));
+		if (tmpend > end)
+			tmpend = end;
 
-	trace_ocfs2_zero_partial_clusters_range1((unsigned long long)start,
-						 (unsigned long long)tmpend);
+		trace_ocfs2_zero_partial_clusters_range1(
+			(unsigned long long)start,
+			(unsigned long long)tmpend);
 
-	ret = ocfs2_zero_range_for_truncate(inode, handle, start, tmpend);
-	if (ret)
-		mlog_errno(ret);
+		ret = ocfs2_zero_range_for_truncate(inode, handle, start,
+						    tmpend);
+		if (ret)
+			mlog_errno(ret);
+	}
 
 	if (tmpend < end) {
 		/*
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574146 — [PATCH 3.10 225/319] ipv6: correctly add local routes when lo goes up

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 225/319] ipv6: correctly add local routes when lo goes up
Message-ID<t7B8E-3eM-63@gated-at.bofh.it>
In reply to#1573997
From: Nicolas Dichtel <nicolas.dichtel@6wind.com>

commit a220445f9f4382c36a53d8ef3e08165fa27f7e2c upstream.

The goal of the patch is to fix this scenario:
 ip link add dummy1 type dummy
 ip link set dummy1 up
 ip link set lo down ; ip link set lo up

After that sequence, the local route to the link layer address of dummy1 is
not there anymore.

When the loopback is set down, all local routes are deleted by
addrconf_ifdown()/rt6_ifdown(). At this time, the rt6_info entry still
exists, because the corresponding idev has a reference on it. After the rcu
grace period, dst_rcu_free() is called, and thus ___dst_free(), which will
set obsolete to DST_OBSOLETE_DEAD.

In this case, init_loopback() is called before dst_rcu_free(), thus
obsolete is still sets to something <= 0. So, the function doesn't add the
route again. To avoid that race, let's check the rt6 refcnt instead.

Fixes: 25fb6ca4ed9c ("net IPv6 : Fix broken IPv6 routing table after loopback down-up")
Fixes: a881ae1f625c ("ipv6: don't call addrconf_dst_alloc again when enable lo")
Fixes: 33d99113b110 ("ipv6: reallocate addrconf router for ipv6 address when lo device up")
Reported-by: Francesco Santoro <francesco.santoro@6wind.com>
Reported-by: Samuel Gauthier <samuel.gauthier@6wind.com>
CC: Balakumaran Kannan <Balakumaran.Kannan@ap.sony.com>
CC: Maruthi Thotad <Maruthi.Thotad@ap.sony.com>
CC: Sabrina Dubroca <sd@queasysnail.net>
CC: Hannes Frederic Sowa <hannes@stressinduktion.org>
CC: Weilong Chen <chenweilong@huawei.com>
CC: Gao feng <gaofeng@cn.fujitsu.com>
Signed-off-by: Nicolas Dichtel <nicolas.dichtel@6wind.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/ipv6/addrconf.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
index 3bfd8a5..a3e2c34 100644
--- a/net/ipv6/addrconf.c
+++ b/net/ipv6/addrconf.c
@@ -2709,7 +2709,7 @@ static void init_loopback(struct net_device *dev)
 				 * lo device down, release this obsolete dst and
 				 * reallocate a new router for ifa.
 				 */
-				if (sp_ifa->rt->dst.obsolete > 0) {
+				if (!atomic_read(&sp_ifa->rt->rt6i_ref)) {
 					ip6_rt_put(sp_ifa->rt);
 					sp_ifa->rt = NULL;
 				} else {
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574147 — [PATCH 3.10 180/319] drm: Reject page_flip for !DRIVER_MODESET

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 180/319] drm: Reject page_flip for !DRIVER_MODESET
Message-ID<t7B8E-3eM-79@gated-at.bofh.it>
In reply to#1573997
From: Daniel Vetter <daniel.vetter@ffwll.ch>

commit 6f00975c619064a18c23fd3aced325ae165a73b9 upstream.

Somehow this one slipped through, which means drivers without modeset
support can be oopsed (since those also don't call
drm_mode_config_init, which means the crtc lookup will chase an
uninitalized idr).

Reported-by: Alexander Potapenko <glider@google.com>
Cc: Alexander Potapenko <glider@google.com>
Signed-off-by: Daniel Vetter <daniel.vetter@intel.com>
Reviewed-by: Chris Wilson <chris@chris-wilson.co.uk>
Signed-off-by: Dave Airlie <airlied@redhat.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/gpu/drm/drm_crtc.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/gpu/drm/drm_crtc.c b/drivers/gpu/drm/drm_crtc.c
index c24c356..121680f 100644
--- a/drivers/gpu/drm/drm_crtc.c
+++ b/drivers/gpu/drm/drm_crtc.c
@@ -3422,6 +3422,9 @@ int drm_mode_page_flip_ioctl(struct drm_device *dev,
 	int hdisplay, vdisplay;
 	int ret = -EINVAL;
 
+	if (!drm_core_check_feature(dev, DRIVER_MODESET))
+		return -EINVAL;
+
 	if (page_flip->flags & ~DRM_MODE_PAGE_FLIP_FLAGS ||
 	    page_flip->reserved != 0)
 		return -EINVAL;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574148 — [PATCH 3.10 194/319] iio: accel: kxsd9: Fix scaling bug

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 194/319] iio: accel: kxsd9: Fix scaling bug
Message-ID<t7B8E-3eM-81@gated-at.bofh.it>
In reply to#1573997
From: Linus Walleij <linus.walleij@linaro.org>

commit 307fe9dd11ae44d4f8881ee449a7cbac36e1f5de upstream.

All the scaling of the KXSD9 involves multiplication with a
fraction number < 1.

However the scaling value returned from IIO_INFO_SCALE was
unpredictable as only the micros of the value was assigned, and
not the integer part, resulting in scaling like this:

$cat in_accel_scale
-1057462640.011978

Fix this by assigning zero to the integer part.

Tested-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/iio/accel/kxsd9.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/iio/accel/kxsd9.c b/drivers/iio/accel/kxsd9.c
index d94c0ca..4f9d178 100644
--- a/drivers/iio/accel/kxsd9.c
+++ b/drivers/iio/accel/kxsd9.c
@@ -166,6 +166,7 @@ static int kxsd9_read_raw(struct iio_dev *indio_dev,
 		ret = spi_w8r8(st->us, KXSD9_READ(KXSD9_REG_CTRL_C));
 		if (ret < 0)
 			goto error_ret;
+		*val = 0;
 		*val2 = kxsd9_micro_scales[ret & KXSD9_FS_MASK];
 		ret = IIO_VAL_INT_PLUS_MICRO;
 		break;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574149 — [PATCH 3.10 217/319] include/stddef.h: Move offsetofend() from vfio.h to a generic kernel header

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 217/319] include/stddef.h: Move offsetofend() from vfio.h to a generic kernel header
Message-ID<t7B8E-3eM-65@gated-at.bofh.it>
In reply to#1573997
From: Denys Vlasenko <dvlasenk@redhat.com>

commit 3876488444e71238e287459c39d7692b6f718c3e upstream.

Suggested by Andy.

Suggested-by: Andy Lutomirski <luto@amacapital.net>
Signed-off-by: Denys Vlasenko <dvlasenk@redhat.com>
Acked-by: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Alexei Starovoitov <ast@plumgrid.com>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Frederic Weisbecker <fweisbec@gmail.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Kees Cook <keescook@chromium.org>
Cc: Oleg Nesterov <oleg@redhat.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Will Drewry <wad@chromium.org>
Link: http://lkml.kernel.org/r/1425912738-559-1-git-send-email-dvlasenk@redhat.com
Signed-off-by: Ingo Molnar <mingo@kernel.org>
[wt: backported only for ipv6 out-of-bounds fix]

Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 include/linux/stddef.h |  9 +++++++++
 include/linux/vfio.h   | 13 -------------
 2 files changed, 9 insertions(+), 13 deletions(-)

diff --git a/include/linux/stddef.h b/include/linux/stddef.h
index f4aec0e..076af43 100644
--- a/include/linux/stddef.h
+++ b/include/linux/stddef.h
@@ -19,3 +19,12 @@ enum {
 #define offsetof(TYPE, MEMBER) ((size_t) &((TYPE *)0)->MEMBER)
 #endif
 #endif
+
+/**
+ * offsetofend(TYPE, MEMBER)
+ *
+ * @TYPE: The type of the structure
+ * @MEMBER: The member within the structure to get the end offset of
+ */
+#define offsetofend(TYPE, MEMBER) \
+	(offsetof(TYPE, MEMBER)	+ sizeof(((TYPE *)0)->MEMBER))
diff --git a/include/linux/vfio.h b/include/linux/vfio.h
index 1a7f0ac..ef4f737 100644
--- a/include/linux/vfio.h
+++ b/include/linux/vfio.h
@@ -76,17 +76,4 @@ extern int vfio_register_iommu_driver(const struct vfio_iommu_driver_ops *ops);
 extern void vfio_unregister_iommu_driver(
 				const struct vfio_iommu_driver_ops *ops);
 
-/**
- * offsetofend(TYPE, MEMBER)
- *
- * @TYPE: The type of the structure
- * @MEMBER: The member within the structure to get the end offset of
- *
- * Simple helper macro for dealing with variable sized structures passed
- * from user space.  This allows us to easily determine if the provided
- * structure is sized to include various fields.
- */
-#define offsetofend(TYPE, MEMBER) \
-	(offsetof(TYPE, MEMBER)	+ sizeof(((TYPE *)0)->MEMBER))
-
 #endif /* VFIO_H */
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574152 — [PATCH 3.10 196/319] cdc-acm: fix wrong pipe type on rx interrupt xfers

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 196/319] cdc-acm: fix wrong pipe type on rx interrupt xfers
Message-ID<t7B8F-3eM-85@gated-at.bofh.it>
In reply to#1573997
From: Gavin Li <git@thegavinli.com>

commit add125054b8727103631dce116361668436ef6a7 upstream.

This fixes the "BOGUS urb xfer" warning logged by usb_submit_urb().

Signed-off-by: Gavin Li <git@thegavinli.com>
Acked-by: Oliver Neukum <oneukum@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/class/cdc-acm.c | 5 ++---
 drivers/usb/class/cdc-acm.h | 1 -
 2 files changed, 2 insertions(+), 4 deletions(-)

diff --git a/drivers/usb/class/cdc-acm.c b/drivers/usb/class/cdc-acm.c
index e7436eb..b364845 100644
--- a/drivers/usb/class/cdc-acm.c
+++ b/drivers/usb/class/cdc-acm.c
@@ -1213,7 +1213,6 @@ made_compressed_probe:
 	spin_lock_init(&acm->write_lock);
 	spin_lock_init(&acm->read_lock);
 	mutex_init(&acm->mutex);
-	acm->rx_endpoint = usb_rcvbulkpipe(usb_dev, epread->bEndpointAddress);
 	acm->is_int_ep = usb_endpoint_xfer_int(epread);
 	if (acm->is_int_ep)
 		acm->bInterval = epread->bInterval;
@@ -1262,14 +1261,14 @@ made_compressed_probe:
 		urb->transfer_dma = rb->dma;
 		if (acm->is_int_ep) {
 			usb_fill_int_urb(urb, acm->dev,
-					 acm->rx_endpoint,
+					 usb_rcvintpipe(usb_dev, epread->bEndpointAddress),
 					 rb->base,
 					 acm->readsize,
 					 acm_read_bulk_callback, rb,
 					 acm->bInterval);
 		} else {
 			usb_fill_bulk_urb(urb, acm->dev,
-					  acm->rx_endpoint,
+					  usb_rcvbulkpipe(usb_dev, epread->bEndpointAddress),
 					  rb->base,
 					  acm->readsize,
 					  acm_read_bulk_callback, rb);
diff --git a/drivers/usb/class/cdc-acm.h b/drivers/usb/class/cdc-acm.h
index 1683ac1..bf4e1bb 100644
--- a/drivers/usb/class/cdc-acm.h
+++ b/drivers/usb/class/cdc-acm.h
@@ -95,7 +95,6 @@ struct acm {
 	struct urb *read_urbs[ACM_NR];
 	struct acm_rb read_buffers[ACM_NR];
 	int rx_buflimit;
-	int rx_endpoint;
 	spinlock_t read_lock;
 	int write_used;					/* number of non-empty write buffers */
 	int transmitting;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1574153 — [PATCH 3.10 192/319] i2c: at91: fix write transfers by clearing pending interrupt first

FromWilly Tarreau <w@1wt.eu>
Date2017-02-05 21:00 +0100
Subject[PATCH 3.10 192/319] i2c: at91: fix write transfers by clearing pending interrupt first
Message-ID<t7B8F-3eM-93@gated-at.bofh.it>
In reply to#1573997
From: Cyrille Pitchen <cyrille.pitchen@atmel.com>

commit 6f6ddbb09d2a5baded0e23add3ad2d9e9417ab30 upstream.

In some cases a NACK interrupt may be pending in the Status Register (SR)
as a result of a previous transfer. However at91_do_twi_transfer() did not
read the SR to clear pending interruptions before starting a new transfer.
Hence a NACK interrupt rose as soon as it was enabled again at the I2C
controller level, resulting in a wrong sequence of operations and strange
patterns of behaviour on the I2C bus, such as a clock stretch followed by
a restart of the transfer.

This first issue occurred with both DMA and PIO write transfers.

Also when a NACK error was detected during a PIO write transfer, the
interrupt handler used to wrongly start a new transfer by writing into the
Transmit Holding Register (THR). Then the I2C slave was likely to reply
with a second NACK.

This second issue is fixed in atmel_twi_interrupt() by handling the TXRDY
status bit only if both the TXCOMP and NACK status bits are cleared.

Tested with a at24 eeprom on sama5d36ek board running a linux-4.1-at91
kernel image. Adapted to linux-next.

Reported-by: Peter Rosin <peda@lysator.liu.se>
Signed-off-by: Cyrille Pitchen <cyrille.pitchen@atmel.com>
Signed-off-by: Ludovic Desroches <ludovic.desroches@atmel.com>
Tested-by: Peter Rosin <peda@lysator.liu.se>
Signed-off-by: Wolfram Sang <wsa@the-dreams.de>
Fixes: 93563a6a71bb ("i2c: at91: fix a race condition when using the DMA controller")
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/i2c/busses/i2c-at91.c | 58 +++++++++++++++++++++++++++++++++++++------
 1 file changed, 50 insertions(+), 8 deletions(-)

diff --git a/drivers/i2c/busses/i2c-at91.c b/drivers/i2c/busses/i2c-at91.c
index ceabcfe..c880d13 100644
--- a/drivers/i2c/busses/i2c-at91.c
+++ b/drivers/i2c/busses/i2c-at91.c
@@ -371,19 +371,57 @@ static irqreturn_t atmel_twi_interrupt(int irq, void *dev_id)
 
 	if (!irqstatus)
 		return IRQ_NONE;
-	else if (irqstatus & AT91_TWI_RXRDY)
-		at91_twi_read_next_byte(dev);
-	else if (irqstatus & AT91_TWI_TXRDY)
-		at91_twi_write_next_byte(dev);
-
-	/* catch error flags */
-	dev->transfer_status |= status;
 
+	/*
+	 * When a NACK condition is detected, the I2C controller sets the NACK,
+	 * TXCOMP and TXRDY bits all together in the Status Register (SR).
+	 *
+	 * 1 - Handling NACK errors with CPU write transfer.
+	 *
+	 * In such case, we should not write the next byte into the Transmit
+	 * Holding Register (THR) otherwise the I2C controller would start a new
+	 * transfer and the I2C slave is likely to reply by another NACK.
+	 *
+	 * 2 - Handling NACK errors with DMA write transfer.
+	 *
+	 * By setting the TXRDY bit in the SR, the I2C controller also triggers
+	 * the DMA controller to write the next data into the THR. Then the
+	 * result depends on the hardware version of the I2C controller.
+	 *
+	 * 2a - Without support of the Alternative Command mode.
+	 *
+	 * This is the worst case: the DMA controller is triggered to write the
+	 * next data into the THR, hence starting a new transfer: the I2C slave
+	 * is likely to reply by another NACK.
+	 * Concurrently, this interrupt handler is likely to be called to manage
+	 * the first NACK before the I2C controller detects the second NACK and
+	 * sets once again the NACK bit into the SR.
+	 * When handling the first NACK, this interrupt handler disables the I2C
+	 * controller interruptions, especially the NACK interrupt.
+	 * Hence, the NACK bit is pending into the SR. This is why we should
+	 * read the SR to clear all pending interrupts at the beginning of
+	 * at91_do_twi_transfer() before actually starting a new transfer.
+	 *
+	 * 2b - With support of the Alternative Command mode.
+	 *
+	 * When a NACK condition is detected, the I2C controller also locks the
+	 * THR (and sets the LOCK bit in the SR): even though the DMA controller
+	 * is triggered by the TXRDY bit to write the next data into the THR,
+	 * this data actually won't go on the I2C bus hence a second NACK is not
+	 * generated.
+	 */
 	if (irqstatus & (AT91_TWI_TXCOMP | AT91_TWI_NACK)) {
 		at91_disable_twi_interrupts(dev);
 		complete(&dev->cmd_complete);
+	} else if (irqstatus & AT91_TWI_RXRDY) {
+		at91_twi_read_next_byte(dev);
+	} else if (irqstatus & AT91_TWI_TXRDY) {
+		at91_twi_write_next_byte(dev);
 	}
 
+	/* catch error flags */
+	dev->transfer_status |= status;
+
 	return IRQ_HANDLED;
 }
 
@@ -391,6 +429,7 @@ static int at91_do_twi_transfer(struct at91_twi_dev *dev)
 {
 	int ret;
 	bool has_unre_flag = dev->pdata->has_unre_flag;
+	unsigned sr;
 
 	/*
 	 * WARNING: the TXCOMP bit in the Status Register is NOT a clear on
@@ -426,13 +465,16 @@ static int at91_do_twi_transfer(struct at91_twi_dev *dev)
 	INIT_COMPLETION(dev->cmd_complete);
 	dev->transfer_status = 0;
 
+	/* Clear pending interrupts, such as NACK. */
+	sr = at91_twi_read(dev, AT91_TWI_SR);
+
 	if (!dev->buf_len) {
 		at91_twi_write(dev, AT91_TWI_CR, AT91_TWI_QUICK);
 		at91_twi_write(dev, AT91_TWI_IER, AT91_TWI_TXCOMP);
 	} else if (dev->msg->flags & I2C_M_RD) {
 		unsigned start_flags = AT91_TWI_START;
 
-		if (at91_twi_read(dev, AT91_TWI_SR) & AT91_TWI_RXRDY) {
+		if (sr & AT91_TWI_RXRDY) {
 			dev_err(dev->dev, "RXRDY still set!");
 			at91_twi_read(dev, AT91_TWI_RHR);
 		}
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


Page 7 of 11 — ← Prev page 1 … 5 6 [7] 8 9 … 11  Next page →

Back to top | Article view | linux.kernel


csiph-web