Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1635495 > unrolled thread
| Started by | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| First post | 2017-05-04 11:10 +0200 |
| Last post | 2017-05-04 21:00 +0200 |
| Articles | 20 on this page of 86 — 3 participants |
Back to article view | Back to linux.kernel
[PATCH 3.12 00/86] 3.12.74-stable review Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 01/86] drm/vmwgfx: NULL pointer dereference in vmw_surface_define_ioctl() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 04/86] drm/vmwgfx: fix integer overflow in vmw_surface_define_ioctl() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 81/86] ALSA: seq: Don't break snd_use_lock_sync() loop by timeout Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 25/86] perf/x86: Avoid exposing wrong/stale data in intel_pmu_lbr_read_32() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 03/86] drm/vmwgfx: Remove getparam error message Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 05/86] Reset TreeId to zero on SMB2 TREE_CONNECT Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 85/86] nfsd: check for oversized NFSv2/v3 arguments Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 59/86] kvm: arm/arm64: Fix locking for kvm_free_stage2_pgd Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 26/86] x86/vdso: Plug race between mapping and ELF header setup Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 82/86] MIPS: KGDB: Use kernel context for sleeping threads Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 31/86] xen, fbfront: fix connecting to backend Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 56/86] ACPI / power: Avoid maybe-uninitialized warning Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 78/86] MIPS: Fix crash registers on non-crashing CPUs Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 28/86] iscsi-target: Drop work-around for legacy GlobalSAN initiator Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 29/86] scsi: sr: Sanity check returned mode data Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 83/86] p9_client_readdir() fix Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 06/86] ptrace: fix PTRACE_LISTEN race corrupting task->state Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 80/86] xen/x86: don't lose event interrupts Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 55/86] Input: elantech - add Fujitsu Lifebook E547 to force crc_enabled Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 77/86] md:raid1: fix a dead loop when read from a WriteMostly disk Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 63/86] net/packet: fix overflow in check for tp_frame_nr Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 72/86] net: ipv4: fix multipath RTM_GETROUTE behavior when iif is given Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 61/86] powerpc: Reject binutils 2.24 when building little endian Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 75/86] ipv6: check raw payload size correctly in ioctl Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 60/86] block: fix del_gendisk() vs blkdev_ioctl crash Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 33/86] char: lack of bool string made CONFIG_DEVPORT always on Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 74/86] ip6mr: fix notification device destruction Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 66/86] tty: nozomi: avoid a harmless gcc warning Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 67/86] hostap: avoid uninitialized variable use in hfa384x_get_rid Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 64/86] net/packet: fix overflow in check for tp_reserve Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 76/86] ext4: check if in-inode xattr is corrupted in ext4_expand_extra_isize_ea() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 45/86] net: ipv6: check route protocol when deleting routes Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 46/86] KEYS: Disallow keyrings beginning with '.' to be joined as session keyrings Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 65/86] netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT" failed in 64bit kernel Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 42/86] rtl8150: Use heap buffers for all register access Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 30/86] scsi: sd: Fix capacity calculation with 32-bit sector_t Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 39/86] mm: Tighten x86 /dev/mem with zeroing reads Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 43/86] catc: Combine failure cleanup code in catc_probe() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 51/86] cifs: Do not send echoes before Negotiate is complete Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 40/86] virtio-console: avoid DMA from stack Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 69/86] net: neigh: guard against NULL solicit() method Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 49/86] tracing: Allocate the snapshot buffer before enabling probe Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 50/86] ring-buffer: Have ring_buffer_iter_empty() return true when empty Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 53/86] Drivers: hv: don't leak memory in vmbus_establish_gpadl() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 62/86] ping: implement proper locking Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 79/86] RDS: Fix the atomicity for congestion map update Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 84/86] Input: i8042 - add Clevo P650RS to the i8042 reset list Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 52/86] CIFS: remove bad_network_name flag Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 54/86] Drivers: hv: get rid of timeout in vmbus_open() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 47/86] KEYS: Change the name of the dead type to ".dead" to prevent user access Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 41/86] pegasus: Use heap buffers for all register access Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 37/86] ext4: fix inode checksum calculation problem if i_extra_size is small Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 38/86] platform/x86: acer-wmi: setup accelerometer when machine has appropriate notify event Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 71/86] l2tp: take reference on sessions being dumped Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 68/86] gfs2: avoid uninitialized variable warning Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 70/86] net: phy: handle state correctly in phy_stop_machine Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 58/86] x86/mce/AMD: Give a name to MCA bank 3 when accessed with legacy MSRs Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 73/86] sctp: listen on the sock only when it's state is listening or closed Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 18/86] usb: dwc3: gadget: delay unmap of bounced requests Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 32/86] char: Drop bogus dependency of DEVPORT on !M68K Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 36/86] dvb-usb-v2: avoid use-after-free Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 14/86] metag/usercopy: Add missing fixups Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 10/86] metag/usercopy: Add early abort to copy_to_user Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 21/86] usb: hub: Wait for connection to be reestablished after port reset Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 13/86] metag/usercopy: Fix src fixup in from user rapf loops Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 23/86] net/mlx4_core: Fix racy CQ (Completion Queue) free Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 34/86] zram: do not use copy_page with non-page aligned address Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 19/86] mtd: bcm47xxpart: fix parsing first block after aligned TRX Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 16/86] s390/decompressor: fix initrd corruption caused by bss clear Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 08/86] metag/usercopy: Drop unused macros Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 24/86] Input: xpad - add support for Razer Wildcat gamepad Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 44/86] catc: Use heap buffer for memory size test Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 35/86] powerpc: Disable HFSCR[TM] if TM is not supported Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 15/86] powerpc: Don't try to fix up misaligned load-with-reservation instructions Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 07/86] ring-buffer: Fix return value check in test_ringbuffer() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 17/86] mm/mempolicy.c: fix error handling in set_mempolicy and mbind. Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 09/86] metag/usercopy: Fix alignment error checking Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 22/86] net/mlx4_en: Fix bad WQE issue Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 20/86] net/packet: fix overflow in check for priv area size Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 12/86] metag/usercopy: Set flags before ADDZ Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 11/86] metag/usercopy: Zero rest of buffer from copy_from_user Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
Re: [PATCH 3.12 00/86] 3.12.74-stable review Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
Re: [PATCH 3.12 00/86] 3.12.74-stable review Guenter Roeck <linux@roeck-us.net> - 2017-05-04 18:00 +0200
Re: [PATCH 3.12 00/86] 3.12.74-stable review Jiri Slaby <jslaby@suse.cz> - 2017-05-09 21:00 +0200
Re: [PATCH 3.12 00/86] 3.12.74-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2017-05-04 21:00 +0200
Page 1 of 5 [1] 2 3 4 5 Next page →
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 00/86] 3.12.74-stable review |
| Message-ID | <tDkVQ-1oS-11@gated-at.bofh.it> |
This is the start of the stable review cycle for the 3.12.74 release.
There are 86 patches in this series, all will be posted as a response
to this one. If anyone has any issues with these being applied, please
let me know.
Responses should be made by Mon May 8 11:03:52 CEST 2017.
Anything received after that time might be too late.
The whole patch series can be found in one patch at:
http://kernel.org/pub/linux/kernel/people/jirislaby/stable-review/patch-3.12.74-rc1.xz
and the diffstat can be found below.
thanks,
js
===============
Al Viro (1):
p9_client_readdir() fix
Andrey Konovalov (3):
net/packet: fix overflow in check for priv area size
net/packet: fix overflow in check for tp_frame_nr
net/packet: fix overflow in check for tp_reserve
Arnd Bergmann (5):
dvb-usb-v2: avoid use-after-free
ACPI / power: Avoid maybe-uninitialized warning
tty: nozomi: avoid a harmless gcc warning
hostap: avoid uninitialized variable use in hfa384x_get_rid
gfs2: avoid uninitialized variable warning
Ben Hutchings (4):
pegasus: Use heap buffers for all register access
rtl8150: Use heap buffers for all register access
catc: Combine failure cleanup code in catc_probe()
catc: Use heap buffer for memory size test
Benjamin Herrenschmidt (1):
powerpc: Disable HFSCR[TM] if TM is not supported
Cameron Gutman (1):
Input: xpad - add support for Razer Wildcat gamepad
Chris Salls (1):
mm/mempolicy.c: fix error handling in set_mempolicy and mbind.
Chun-Yi Lee (1):
platform/x86: acer-wmi: setup accelerometer when machine has
appropriate notify event
Corey Minyard (1):
MIPS: Fix crash registers on non-crashing CPUs
Daeho Jeong (1):
ext4: fix inode checksum calculation problem if i_extra_size is small
Dan Williams (1):
block: fix del_gendisk() vs blkdev_ioctl crash
David Howells (2):
KEYS: Disallow keyrings beginning with '.' to be joined as session
keyrings
KEYS: Change the name of the dead type to ".dead" to prevent user
access
Dmitry Torokhov (1):
Input: i8042 - add Clevo P650RS to the i8042 reset list
Eric Biggers (1):
KEYS: fix keyctl_set_reqkey_keyring() to not leak thread keyrings
Eric Dumazet (2):
ping: implement proper locking
net: neigh: guard against NULL solicit() method
Eugenia Emantayev (1):
net/mlx4_en: Fix bad WQE issue
Florian Larysch (1):
net: ipv4: fix multipath RTM_GETROUTE behavior when iif is given
Geert Uytterhoeven (1):
char: Drop bogus dependency of DEVPORT on !M68K
Germano Percossi (1):
CIFS: remove bad_network_name flag
Guenter Roeck (1):
usb: hub: Wait for connection to be reestablished after port reset
Guillaume Nault (1):
l2tp: take reference on sessions being dumped
Hongxu Jia (1):
netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT"
failed in 64bit kernel
J. Bruce Fields (1):
nfsd: check for oversized NFSv2/v3 arguments
Jack Morgenstein (1):
net/mlx4_core: Fix racy CQ (Completion Queue) free
James Hogan (8):
metag/usercopy: Drop unused macros
metag/usercopy: Fix alignment error checking
metag/usercopy: Add early abort to copy_to_user
metag/usercopy: Zero rest of buffer from copy_from_user
metag/usercopy: Set flags before ADDZ
metag/usercopy: Fix src fixup in from user rapf loops
metag/usercopy: Add missing fixups
MIPS: KGDB: Use kernel context for sleeping threads
Jamie Bainbridge (1):
ipv6: check raw payload size correctly in ioctl
Jan-Marek Glogowski (1):
Reset TreeId to zero on SMB2 TREE_CONNECT
Janusz Dziedzic (1):
usb: dwc3: gadget: delay unmap of bounced requests
Josh Poimboeuf (1):
ftrace/x86: Fix triple fault with graph tracing and suspend-to-ram
Juergen Gross (1):
xen, fbfront: fix connecting to backend
Kees Cook (1):
mm: Tighten x86 /dev/mem with zeroing reads
Li Qiang (1):
drm/vmwgfx: fix integer overflow in vmw_surface_define_ioctl()
Mantas M (1):
net: ipv6: check route protocol when deleting routes
Marcelo Henrique Cerri (1):
s390/decompressor: fix initrd corruption caused by bss clear
Martin K. Petersen (2):
scsi: sr: Sanity check returned mode data
scsi: sd: Fix capacity calculation with 32-bit sector_t
Max Bires (1):
char: lack of bool string made CONFIG_DEVPORT always on
Michael Ellerman (1):
powerpc: Reject binutils 2.24 when building little endian
Minchan Kim (1):
zram: do not use copy_page with non-page aligned address
Murray McAllister (2):
drm/vmwgfx: NULL pointer dereference in vmw_surface_define_ioctl()
drm/vmwgfx: avoid calling vzalloc with a 0 size in
vmw_get_cap_3d_ioctl()
Nathan Sullivan (1):
net: phy: handle state correctly in phy_stop_machine
Nicholas Bellinger (2):
iscsi-target: Fix TMR reference leak during session shutdown
iscsi-target: Drop work-around for legacy GlobalSAN initiator
Nikolay Aleksandrov (1):
ip6mr: fix notification device destruction
Omar Sandoval (1):
virtio-console: avoid DMA from stack
Paul Mackerras (1):
powerpc: Don't try to fix up misaligned load-with-reservation
instructions
Peter Zijlstra (1):
perf/x86: Avoid exposing wrong/stale data in intel_pmu_lbr_read_32()
Rafał Miłecki (1):
mtd: bcm47xxpart: fix parsing first block after aligned TRX
Sachin Prabhu (1):
cifs: Do not send echoes before Negotiate is complete
Sebastian Siewior (1):
ubi/upd: Always flush after prepared for an update
Stefano Stabellini (1):
xen/x86: don't lose event interrupts
Steven Rostedt (VMware) (2):
tracing: Allocate the snapshot buffer before enabling probe
ring-buffer: Have ring_buffer_iter_empty() return true when empty
Suzuki K Poulose (1):
kvm: arm/arm64: Fix locking for kvm_free_stage2_pgd
Takashi Iwai (1):
ALSA: seq: Don't break snd_use_lock_sync() loop by timeout
Theodore Ts'o (1):
ext4: check if in-inode xattr is corrupted in
ext4_expand_extra_isize_ea()
Thomas Gleixner (1):
x86/vdso: Plug race between mapping and ELF header setup
Thomas Hellstrom (1):
drm/vmwgfx: Remove getparam error message
Thorsten Leemhuis (1):
Input: elantech - add Fujitsu Lifebook E547 to force crc_enabled
Vitaly Kuznetsov (2):
Drivers: hv: don't leak memory in vmbus_establish_gpadl()
Drivers: hv: get rid of timeout in vmbus_open()
Wei Fang (1):
md:raid1: fix a dead loop when read from a WriteMostly disk
Wei Yongjun (1):
ring-buffer: Fix return value check in test_ringbuffer()
Xin Long (1):
sctp: listen on the sock only when it's state is listening or closed
Yazen Ghannam (1):
x86/mce/AMD: Give a name to MCA bank 3 when accessed with legacy MSRs
bsegall@google.com (1):
ptrace: fix PTRACE_LISTEN race corrupting task->state
santosh.shilimkar@oracle.com (1):
RDS: Fix the atomicity for congestion map update
arch/arm/kvm/mmu.c | 12 +
arch/metag/include/asm/uaccess.h | 15 +-
arch/metag/lib/usercopy.c | 312 ++++++++++---------------
arch/mips/kernel/crash.c | 16 +-
arch/mips/kernel/kgdb.c | 48 ++--
arch/powerpc/Makefile | 8 +
arch/powerpc/kernel/align.c | 28 ++-
arch/powerpc/kernel/setup_64.c | 9 +
arch/s390/boot/compressed/misc.c | 35 +--
arch/x86/include/asm/elf.h | 2 +-
arch/x86/kernel/cpu/mcheck/mce_amd.c | 2 +-
arch/x86/kernel/cpu/perf_event_intel_lbr.c | 2 +
arch/x86/kernel/ftrace.c | 12 +
arch/x86/mm/init.c | 41 +++-
arch/x86/xen/time.c | 6 +-
block/genhd.c | 1 -
drivers/acpi/power.c | 1 +
drivers/char/Kconfig | 6 +-
drivers/char/mem.c | 82 ++++---
drivers/char/virtio_console.c | 12 +-
drivers/gpu/drm/vmwgfx/vmwgfx_ioctl.c | 4 +-
drivers/gpu/drm/vmwgfx/vmwgfx_surface.c | 9 +-
drivers/hv/channel.c | 17 +-
drivers/input/joystick/xpad.c | 2 +
drivers/input/mouse/elantech.c | 8 +
drivers/input/serio/i8042-x86ia64io.h | 7 +
drivers/md/raid1.c | 2 +-
drivers/media/usb/dvb-usb-v2/dvb_usb_core.c | 9 +-
drivers/mtd/bcm47xxpart.c | 10 +-
drivers/mtd/ubi/upd.c | 8 +-
drivers/net/ethernet/mellanox/mlx4/cq.c | 38 +--
drivers/net/ethernet/mellanox/mlx4/en_rx.c | 8 +-
drivers/net/phy/phy.c | 2 +-
drivers/net/usb/catc.c | 56 +++--
drivers/net/usb/pegasus.c | 29 ++-
drivers/net/usb/rtl8150.c | 34 ++-
drivers/net/wireless/hostap/hostap_hw.c | 15 +-
drivers/platform/x86/acer-wmi.c | 22 +-
drivers/scsi/sd.c | 20 +-
drivers/scsi/sr.c | 6 +-
drivers/staging/zram/zram_drv.c | 6 +-
drivers/target/iscsi/iscsi_target_parameters.c | 16 --
drivers/target/iscsi/iscsi_target_util.c | 12 +-
drivers/tty/nozomi.c | 2 +-
drivers/usb/core/hub.c | 11 +-
drivers/usb/dwc3/gadget.c | 21 +-
drivers/video/xen-fbfront.c | 4 +-
fs/cifs/cifsglob.h | 1 -
fs/cifs/smb1ops.c | 10 +
fs/cifs/smb2pdu.c | 9 +-
fs/ext4/inode.c | 5 +-
fs/ext4/xattr.c | 32 ++-
fs/gfs2/dir.c | 4 +-
fs/nfsd/nfssvc.c | 36 +++
kernel/ptrace.c | 14 +-
kernel/trace/ring_buffer.c | 24 +-
kernel/trace/trace.c | 8 +-
mm/mempolicy.c | 20 +-
net/9p/client.c | 4 +
net/core/neighbour.c | 3 +-
net/ipv4/netfilter/arp_tables.c | 4 +-
net/ipv4/ping.c | 5 +-
net/ipv4/route.c | 2 +-
net/ipv6/ip6mr.c | 13 +-
net/ipv6/raw.c | 3 +-
net/ipv6/route.c | 2 +
net/l2tp/l2tp_core.c | 8 +-
net/l2tp/l2tp_core.h | 3 +-
net/l2tp/l2tp_debugfs.c | 10 +-
net/l2tp/l2tp_netlink.c | 7 +-
net/l2tp/l2tp_ppp.c | 10 +-
net/packet/af_packet.c | 8 +-
net/rds/cong.c | 4 +-
net/sctp/socket.c | 3 +
security/keys/gc.c | 2 +-
security/keys/keyctl.c | 20 +-
security/keys/process_keys.c | 44 ++--
sound/core/seq/seq_lock.c | 9 +-
78 files changed, 833 insertions(+), 522 deletions(-)
--
2.12.2
[toc] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 01/86] drm/vmwgfx: NULL pointer dereference in vmw_surface_define_ioctl() |
| Message-ID | <tDkVQ-1oS-3@gated-at.bofh.it> |
| In reply to | #1635495 |
From: Murray McAllister <murray.mcallister@insomniasec.com> 3.12-stable review patch. If anyone has any objections, please let me know. =============== commit 36274ab8c596f1240c606bb514da329add2a1bcd upstream. Before memory allocations vmw_surface_define_ioctl() checks the upper-bounds of a user-supplied size, but does not check if the supplied size is 0. Add check to avoid NULL pointer dereferences. Signed-off-by: Murray McAllister <murray.mcallister@insomniasec.com> Reviewed-by: Sinclair Yeh <syeh@vmware.com> Signed-off-by: Jiri Slaby <jslaby@suse.cz> --- drivers/gpu/drm/vmwgfx/vmwgfx_surface.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c b/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c index 582814339748..a518493836a0 100644 --- a/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c +++ b/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c @@ -680,8 +680,8 @@ int vmw_surface_define_ioctl(struct drm_device *dev, void *data, for (i = 0; i < DRM_VMW_MAX_SURFACE_FACES; ++i) num_sizes += req->mip_levels[i]; - if (num_sizes > DRM_VMW_MAX_SURFACE_FACES * - DRM_VMW_MAX_MIP_LEVELS) + if (num_sizes > DRM_VMW_MAX_SURFACE_FACES * DRM_VMW_MAX_MIP_LEVELS || + num_sizes == 0) return -EINVAL; size = vmw_user_surface_size + 128 + -- 2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 04/86] drm/vmwgfx: fix integer overflow in vmw_surface_define_ioctl() |
| Message-ID | <tDkVQ-1oS-17@gated-at.bofh.it> |
| In reply to | #1635498 |
From: Li Qiang <liq3ea@gmail.com>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit e7e11f99564222d82f0ce84bd521e57d78a6b678 upstream.
In vmw_surface_define_ioctl(), the 'num_sizes' is the sum of the
'req->mip_levels' array. This array can be assigned any value from
the user space. As both the 'num_sizes' and the array is uint32_t,
it is easy to make 'num_sizes' overflow. The later 'mip_levels' is
used as the loop count. This can lead an oob write. Add the check of
'req->mip_levels' to avoid this.
Signed-off-by: Li Qiang <liqiang6-s@360.cn>
Reviewed-by: Thomas Hellstrom <thellstrom@vmware.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
drivers/gpu/drm/vmwgfx/vmwgfx_surface.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c b/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c
index a518493836a0..12969378c06e 100644
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c
@@ -677,8 +677,11 @@ int vmw_surface_define_ioctl(struct drm_device *dev, void *data,
128;
num_sizes = 0;
- for (i = 0; i < DRM_VMW_MAX_SURFACE_FACES; ++i)
+ for (i = 0; i < DRM_VMW_MAX_SURFACE_FACES; ++i) {
+ if (req->mip_levels[i] > DRM_VMW_MAX_MIP_LEVELS)
+ return -EINVAL;
num_sizes += req->mip_levels[i];
+ }
if (num_sizes > DRM_VMW_MAX_SURFACE_FACES * DRM_VMW_MAX_MIP_LEVELS ||
num_sizes == 0)
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 81/86] ALSA: seq: Don't break snd_use_lock_sync() loop by timeout |
| Message-ID | <tDkVQ-1oS-19@gated-at.bofh.it> |
| In reply to | #1635498 |
From: Takashi Iwai <tiwai@suse.de>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit 4e7655fd4f47c23e5249ea260dc802f909a64611 upstream.
The snd_use_lock_sync() (thus its implementation
snd_use_lock_sync_helper()) has the 5 seconds timeout to break out of
the sync loop. It was introduced from the beginning, just to be
"safer", in terms of avoiding the stupid bugs.
However, as Ben Hutchings suggested, this timeout rather introduces a
potential leak or use-after-free that was apparently fixed by the
commit 2d7d54002e39 ("ALSA: seq: Fix race during FIFO resize"):
for example, snd_seq_fifo_event_in() -> snd_seq_event_dup() ->
copy_from_user() could block for a long time, and snd_use_lock_sync()
goes timeout and still leaves the cell at releasing the pool.
For fixing such a problem, we remove the break by the timeout while
still keeping the warning.
Suggested-by: Ben Hutchings <ben.hutchings@codethink.co.uk>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
sound/core/seq/seq_lock.c | 9 +++------
1 file changed, 3 insertions(+), 6 deletions(-)
diff --git a/sound/core/seq/seq_lock.c b/sound/core/seq/seq_lock.c
index 2cfe50c71a9d..8a6b7baafa35 100644
--- a/sound/core/seq/seq_lock.c
+++ b/sound/core/seq/seq_lock.c
@@ -28,19 +28,16 @@
/* wait until all locks are released */
void snd_use_lock_sync_helper(snd_use_lock_t *lockp, const char *file, int line)
{
- int max_count = 5 * HZ;
+ int warn_count = 5 * HZ;
if (atomic_read(lockp) < 0) {
printk(KERN_WARNING "seq_lock: lock trouble [counter = %d] in %s:%d\n", atomic_read(lockp), file, line);
return;
}
while (atomic_read(lockp) > 0) {
- if (max_count == 0) {
- snd_printk(KERN_WARNING "seq_lock: timeout [%d left] in %s:%d\n", atomic_read(lockp), file, line);
- break;
- }
+ if (warn_count-- == 0)
+ pr_warn("ALSA: seq_lock: waiting [%d left] in %s:%d\n", atomic_read(lockp), file, line);
schedule_timeout_uninterruptible(1);
- max_count--;
}
}
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 25/86] perf/x86: Avoid exposing wrong/stale data in intel_pmu_lbr_read_32() |
| Message-ID | <tDkVQ-1oS-21@gated-at.bofh.it> |
| In reply to | #1635498 |
From: Peter Zijlstra <peterz@infradead.org>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit f2200ac311302fcdca6556fd0c5127eab6c65a3e upstream.
When the perf_branch_entry::{in_tx,abort,cycles} fields were added,
intel_pmu_lbr_read_32() wasn't updated to initialize them.
[js] there is no cycles in 3.12 yet
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: linux-kernel@vger.kernel.org
Fixes: 135c5612c460 ("perf/x86/intel: Support Haswell/v4 LBR format")
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
arch/x86/kernel/cpu/perf_event_intel_lbr.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/x86/kernel/cpu/perf_event_intel_lbr.c b/arch/x86/kernel/cpu/perf_event_intel_lbr.c
index d5be06a5005e..ea28a92e563a 100644
--- a/arch/x86/kernel/cpu/perf_event_intel_lbr.c
+++ b/arch/x86/kernel/cpu/perf_event_intel_lbr.c
@@ -268,6 +268,8 @@ static void intel_pmu_lbr_read_32(struct cpu_hw_events *cpuc)
cpuc->lbr_entries[i].to = msr_lastbranch.to;
cpuc->lbr_entries[i].mispred = 0;
cpuc->lbr_entries[i].predicted = 0;
+ cpuc->lbr_entries[i].in_tx = 0;
+ cpuc->lbr_entries[i].abort = 0;
cpuc->lbr_entries[i].reserved = 0;
}
cpuc->lbr_stack.nr = i;
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 03/86] drm/vmwgfx: Remove getparam error message |
| Message-ID | <tDkVR-1oS-27@gated-at.bofh.it> |
| In reply to | #1635498 |
From: Thomas Hellstrom <thellstrom@vmware.com>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit 53e16798b0864464c5444a204e1bb93ae246c429 upstream.
The mesa winsys sometimes uses unimplemented parameter requests to
check for features. Remove the error message to avoid bloating the
kernel log.
Signed-off-by: Thomas Hellstrom <thellstrom@vmware.com>
Reviewed-by: Brian Paul <brianp@vmware.com>
Reviewed-by: Sinclair Yeh <syeh@vmware.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
drivers/gpu/drm/vmwgfx/vmwgfx_ioctl.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/gpu/drm/vmwgfx/vmwgfx_ioctl.c b/drivers/gpu/drm/vmwgfx/vmwgfx_ioctl.c
index f435b6c187f0..17a503ff260f 100644
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_ioctl.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_ioctl.c
@@ -69,8 +69,6 @@ int vmw_getparam_ioctl(struct drm_device *dev, void *data,
break;
}
default:
- DRM_ERROR("Illegal vmwgfx get param request: %d\n",
- param->param);
return -EINVAL;
}
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 05/86] Reset TreeId to zero on SMB2 TREE_CONNECT |
| Message-ID | <tDkVR-1oS-25@gated-at.bofh.it> |
| In reply to | #1635498 |
From: Jan-Marek Glogowski <glogow@fbihome.de>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit 806a28efe9b78ffae5e2757e1ee924b8e50c08ab upstream.
Currently the cifs module breaks the CIFS specs on reconnect as
described in http://msdn.microsoft.com/en-us/library/cc246529.aspx:
"TreeId (4 bytes): Uniquely identifies the tree connect for the
command. This MUST be 0 for the SMB2 TREE_CONNECT Request."
Signed-off-by: Jan-Marek Glogowski <glogow@fbihome.de>
Reviewed-by: Aurelien Aptel <aaptel@suse.com>
Tested-by: Aurelien Aptel <aaptel@suse.com>
Signed-off-by: Steve French <smfrench@gmail.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
fs/cifs/smb2pdu.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/fs/cifs/smb2pdu.c b/fs/cifs/smb2pdu.c
index 30d0751626e3..c7a400415d02 100644
--- a/fs/cifs/smb2pdu.c
+++ b/fs/cifs/smb2pdu.c
@@ -853,6 +853,10 @@ SMB2_tcon(const unsigned int xid, struct cifs_ses *ses, const char *tree,
return -EINVAL;
}
+ /* SMB2 TREE_CONNECT request must be called with TreeId == 0 */
+ if (tcon)
+ tcon->tid = 0;
+
rc = small_smb2_init(SMB2_TREE_CONNECT, tcon, (void **) &req);
if (rc) {
kfree(unc_path);
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 85/86] nfsd: check for oversized NFSv2/v3 arguments |
| Message-ID | <tDkVR-1oS-29@gated-at.bofh.it> |
| In reply to | #1635498 |
From: "J. Bruce Fields" <bfields@redhat.com>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit e6838a29ecb484c97e4efef9429643b9851fba6e upstream.
A client can append random data to the end of an NFSv2 or NFSv3 RPC call
without our complaining; we'll just stop parsing at the end of the
expected data and ignore the rest.
Encoded arguments and replies are stored together in an array of pages,
and if a call is too large it could leave inadequate space for the
reply. This is normally OK because NFS RPC's typically have either
short arguments and long replies (like READ) or long arguments and short
replies (like WRITE). But a client that sends an incorrectly long reply
can violate those assumptions. This was observed to cause crashes.
Also, several operations increment rq_next_page in the decode routine
before checking the argument size, which can leave rq_next_page pointing
well past the end of the page array, causing trouble later in
svc_free_pages.
So, following a suggestion from Neil Brown, add a central check to
enforce our expectation that no NFSv2/v3 call has both a large call and
a large reply.
As followup we may also want to rewrite the encoding routines to check
more carefully that they aren't running off the end of the page array.
We may also consider rejecting calls that have any extra garbage
appended. That would be safer, and within our rights by spec, but given
the age of our server and the NFS protocol, and the fact that we've
never enforced this before, we may need to balance that against the
possibility of breaking some oddball client.
Reported-by: Tuomas Haanpää <thaan@synopsys.com>
Reported-by: Ari Kauppi <ari@synopsys.com>
Reviewed-by: NeilBrown <neilb@suse.com>
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
fs/nfsd/nfssvc.c | 36 ++++++++++++++++++++++++++++++++++++
1 file changed, 36 insertions(+)
diff --git a/fs/nfsd/nfssvc.c b/fs/nfsd/nfssvc.c
index 4942f4370f60..a0903991a0fd 100644
--- a/fs/nfsd/nfssvc.c
+++ b/fs/nfsd/nfssvc.c
@@ -628,6 +628,37 @@ static __be32 map_new_errors(u32 vers, __be32 nfserr)
return nfserr;
}
+/*
+ * A write procedure can have a large argument, and a read procedure can
+ * have a large reply, but no NFSv2 or NFSv3 procedure has argument and
+ * reply that can both be larger than a page. The xdr code has taken
+ * advantage of this assumption to be a sloppy about bounds checking in
+ * some cases. Pending a rewrite of the NFSv2/v3 xdr code to fix that
+ * problem, we enforce these assumptions here:
+ */
+static bool nfs_request_too_big(struct svc_rqst *rqstp,
+ struct svc_procedure *proc)
+{
+ /*
+ * The ACL code has more careful bounds-checking and is not
+ * susceptible to this problem:
+ */
+ if (rqstp->rq_prog != NFS_PROGRAM)
+ return false;
+ /*
+ * Ditto NFSv4 (which can in theory have argument and reply both
+ * more than a page):
+ */
+ if (rqstp->rq_vers >= 4)
+ return false;
+ /* The reply will be small, we're OK: */
+ if (proc->pc_xdrressize > 0 &&
+ proc->pc_xdrressize < XDR_QUADLEN(PAGE_SIZE))
+ return false;
+
+ return rqstp->rq_arg.len > PAGE_SIZE;
+}
+
int
nfsd_dispatch(struct svc_rqst *rqstp, __be32 *statp)
{
@@ -640,6 +671,11 @@ nfsd_dispatch(struct svc_rqst *rqstp, __be32 *statp)
rqstp->rq_vers, rqstp->rq_proc);
proc = rqstp->rq_procinfo;
+ if (nfs_request_too_big(rqstp, proc)) {
+ dprintk("nfsd: NFSv%d argument too large\n", rqstp->rq_vers);
+ *statp = rpc_garbage_args;
+ return 1;
+ }
/*
* Give the xdr decoder a chance to change this if it wants
* (necessary in the NFSv4.0 compound case)
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 59/86] kvm: arm/arm64: Fix locking for kvm_free_stage2_pgd |
| Message-ID | <tDkVR-1oS-31@gated-at.bofh.it> |
| In reply to | #1635498 |
From: Suzuki K Poulose <suzuki.poulose@arm.com>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit 8b3405e345b5a098101b0c31b264c812bba045d9 upstream.
In kvm_free_stage2_pgd() we don't hold the kvm->mmu_lock while calling
unmap_stage2_range() on the entire memory range for the guest. This could
cause problems with other callers (e.g, munmap on a memslot) trying to
unmap a range. And since we have to unmap the entire Guest memory range
holding a spinlock, make sure we yield the lock if necessary, after we
unmap each PUD range.
[skp] provided backport for 3.12
Fixes: commit d5d8184d35c9 ("KVM: ARM: Memory virtualization setup")
Cc: Paolo Bonzini <pbonzin@redhat.com>
Cc: Marc Zyngier <marc.zyngier@arm.com>
Cc: Christoffer Dall <christoffer.dall@linaro.org>
Cc: Mark Rutland <mark.rutland@arm.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
[ Avoid vCPU starvation and lockup detector warnings ]
Signed-off-by: Marc Zyngier <marc.zyngier@arm.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Signed-off-by: Christoffer Dall <cdall@linaro.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
arch/arm/kvm/mmu.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/arch/arm/kvm/mmu.c b/arch/arm/kvm/mmu.c
index 683cac91a7f6..84f18dc83532 100644
--- a/arch/arm/kvm/mmu.c
+++ b/arch/arm/kvm/mmu.c
@@ -181,6 +181,14 @@ static void unmap_range(struct kvm *kvm, pgd_t *pgdp,
do {
next = kvm_pgd_addr_end(addr, end);
unmap_puds(kvm, pgd, addr, next);
+ /*
+ * If we are dealing with a large range in
+ * stage2 table, release the kvm->mmu_lock
+ * to prevent starvation and lockup detector
+ * warnings.
+ */
+ if (kvm && (next != end))
+ cond_resched_lock(&kvm->mmu_lock);
} while (pgd++, addr = next, addr != end);
}
@@ -525,6 +533,7 @@ int kvm_alloc_stage2_pgd(struct kvm *kvm)
*/
static void unmap_stage2_range(struct kvm *kvm, phys_addr_t start, u64 size)
{
+ assert_spin_locked(&kvm->mmu_lock);
unmap_range(kvm, kvm->arch.pgd, start, size);
}
@@ -609,7 +618,10 @@ void kvm_free_stage2_pgd(struct kvm *kvm)
if (kvm->arch.pgd == NULL)
return;
+ spin_lock(&kvm->mmu_lock);
unmap_stage2_range(kvm, 0, KVM_PHYS_SIZE);
+ spin_unlock(&kvm->mmu_lock);
+
free_pages((unsigned long)kvm->arch.pgd, S2_PGD_ORDER);
kvm->arch.pgd = NULL;
}
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 26/86] x86/vdso: Plug race between mapping and ELF header setup |
| Message-ID | <tDkVR-1oS-35@gated-at.bofh.it> |
| In reply to | #1635498 |
From: Thomas Gleixner <tglx@linutronix.de>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit 6fdc6dd90272ce7e75d744f71535cfbd8d77da81 upstream.
The vsyscall32 sysctl can racy against a concurrent fork when it switches
from disabled to enabled:
arch_setup_additional_pages()
if (vdso32_enabled)
--> No mapping
sysctl.vsysscall32()
--> vdso32_enabled = true
create_elf_tables()
ARCH_DLINFO_IA32
if (vdso32_enabled) {
--> Add VDSO entry with NULL pointer
Make ARCH_DLINFO_IA32 check whether the VDSO mapping has been set up for
the newly forked process or not.
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Acked-by: Andy Lutomirski <luto@amacapital.net>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Mathias Krause <minipli@googlemail.com>
Link: http://lkml.kernel.org/r/20170410151723.602367196@linutronix.de
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
arch/x86/include/asm/elf.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/x86/include/asm/elf.h b/arch/x86/include/asm/elf.h
index 01f15b227d7e..2fa7f4f6ecb3 100644
--- a/arch/x86/include/asm/elf.h
+++ b/arch/x86/include/asm/elf.h
@@ -272,7 +272,7 @@ struct task_struct;
#define ARCH_DLINFO_IA32(vdso_enabled) \
do { \
- if (vdso_enabled) { \
+ if (VDSO_CURRENT_BASE) { \
NEW_AUX_ENT(AT_SYSINFO, VDSO_ENTRY); \
NEW_AUX_ENT(AT_SYSINFO_EHDR, VDSO_CURRENT_BASE); \
} \
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 82/86] MIPS: KGDB: Use kernel context for sleeping threads |
| Message-ID | <tDkVR-1oS-39@gated-at.bofh.it> |
| In reply to | #1635498 |
From: James Hogan <james.hogan@imgtec.com>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit 162b270c664dca2e0944308e92f9fcc887151a72 upstream.
KGDB is a kernel debug stub and it can't be used to debug userland as it
can only safely access kernel memory.
On MIPS however KGDB has always got the register state of sleeping
processes from the userland register context at the beginning of the
kernel stack. This is meaningless for kernel threads (which never enter
userland), and for user threads it prevents the user seeing what it is
doing while in the kernel:
(gdb) info threads
Id Target Id Frame
...
3 Thread 2 (kthreadd) 0x0000000000000000 in ?? ()
2 Thread 1 (init) 0x000000007705c4b4 in ?? ()
1 Thread -2 (shadowCPU0) 0xffffffff8012524c in arch_kgdb_breakpoint () at arch/mips/kernel/kgdb.c:201
Get the register state instead from the (partial) kernel register
context stored in the task's thread_struct for resume() to restore. All
threads now correctly appear to be in context_switch():
(gdb) info threads
Id Target Id Frame
...
3 Thread 2 (kthreadd) context_switch (rq=<optimized out>, cookie=..., next=<optimized out>, prev=0x0) at kernel/sched/core.c:2903
2 Thread 1 (init) context_switch (rq=<optimized out>, cookie=..., next=<optimized out>, prev=0x0) at kernel/sched/core.c:2903
1 Thread -2 (shadowCPU0) 0xffffffff8012524c in arch_kgdb_breakpoint () at arch/mips/kernel/kgdb.c:201
Call clobbered registers which aren't saved and exception registers
(BadVAddr & Cause) which can't be easily determined without stack
unwinding are reported as 0. The PC is taken from the return address,
such that the state presented matches that found immediately after
returning from resume().
Fixes: 8854700115ec ("[MIPS] kgdb: add arch support for the kernel's kgdb core")
Signed-off-by: James Hogan <james.hogan@imgtec.com>
Cc: Jason Wessel <jason.wessel@windriver.com>
Cc: linux-mips@linux-mips.org
Patchwork: https://patchwork.linux-mips.org/patch/15829/
Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
arch/mips/kernel/kgdb.c | 48 +++++++++++++++++++++++++++++++++---------------
1 file changed, 33 insertions(+), 15 deletions(-)
diff --git a/arch/mips/kernel/kgdb.c b/arch/mips/kernel/kgdb.c
index fcaac2f132f0..910db386d9ef 100644
--- a/arch/mips/kernel/kgdb.c
+++ b/arch/mips/kernel/kgdb.c
@@ -236,9 +236,6 @@ static int compute_signal(int tt)
void sleeping_thread_to_gdb_regs(unsigned long *gdb_regs, struct task_struct *p)
{
int reg;
- struct thread_info *ti = task_thread_info(p);
- unsigned long ksp = (unsigned long)ti + THREAD_SIZE - 32;
- struct pt_regs *regs = (struct pt_regs *)ksp - 1;
#if (KGDB_GDB_REG_SIZE == 32)
u32 *ptr = (u32 *)gdb_regs;
#else
@@ -246,25 +243,46 @@ void sleeping_thread_to_gdb_regs(unsigned long *gdb_regs, struct task_struct *p)
#endif
for (reg = 0; reg < 16; reg++)
- *(ptr++) = regs->regs[reg];
+ *(ptr++) = 0;
/* S0 - S7 */
- for (reg = 16; reg < 24; reg++)
- *(ptr++) = regs->regs[reg];
+ *(ptr++) = p->thread.reg16;
+ *(ptr++) = p->thread.reg17;
+ *(ptr++) = p->thread.reg18;
+ *(ptr++) = p->thread.reg19;
+ *(ptr++) = p->thread.reg20;
+ *(ptr++) = p->thread.reg21;
+ *(ptr++) = p->thread.reg22;
+ *(ptr++) = p->thread.reg23;
for (reg = 24; reg < 28; reg++)
*(ptr++) = 0;
/* GP, SP, FP, RA */
- for (reg = 28; reg < 32; reg++)
- *(ptr++) = regs->regs[reg];
-
- *(ptr++) = regs->cp0_status;
- *(ptr++) = regs->lo;
- *(ptr++) = regs->hi;
- *(ptr++) = regs->cp0_badvaddr;
- *(ptr++) = regs->cp0_cause;
- *(ptr++) = regs->cp0_epc;
+ *(ptr++) = (long)p;
+ *(ptr++) = p->thread.reg29;
+ *(ptr++) = p->thread.reg30;
+ *(ptr++) = p->thread.reg31;
+
+ *(ptr++) = p->thread.cp0_status;
+
+ /* lo, hi */
+ *(ptr++) = 0;
+ *(ptr++) = 0;
+
+ /*
+ * BadVAddr, Cause
+ * Ideally these would come from the last exception frame up the stack
+ * but that requires unwinding, otherwise we can't know much for sure.
+ */
+ *(ptr++) = 0;
+ *(ptr++) = 0;
+
+ /*
+ * PC
+ * use return address (RA), i.e. the moment after return from resume()
+ */
+ *(ptr++) = p->thread.reg31;
}
void kgdb_arch_set_pc(struct pt_regs *regs, unsigned long pc)
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 31/86] xen, fbfront: fix connecting to backend |
| Message-ID | <tDkVR-1oS-37@gated-at.bofh.it> |
| In reply to | #1635498 |
From: Juergen Gross <jgross@suse.com> 3.12-stable review patch. If anyone has any objections, please let me know. =============== commit 9121b15b5628b38b4695282dc18c553440e0f79b upstream. Connecting to the backend isn't working reliably in xen-fbfront: in case XenbusStateInitWait of the backend has been missed the backend transition to XenbusStateConnected will trigger the connected state only without doing the actions required when the backend has connected. Signed-off-by: Juergen Gross <jgross@suse.com> Reviewed-by: Boris Ostrovsky <boris.ostrovsky@oracle.com> Signed-off-by: Bartlomiej Zolnierkiewicz <b.zolnierkie@samsung.com> Signed-off-by: Jiri Slaby <jslaby@suse.cz> --- drivers/video/xen-fbfront.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/video/xen-fbfront.c b/drivers/video/xen-fbfront.c index 4b2d3ab870f3..fc56d1ed11fc 100644 --- a/drivers/video/xen-fbfront.c +++ b/drivers/video/xen-fbfront.c @@ -644,7 +644,6 @@ static void xenfb_backend_changed(struct xenbus_device *dev, break; case XenbusStateInitWait: -InitWait: xenbus_switch_state(dev, XenbusStateConnected); break; @@ -655,7 +654,8 @@ InitWait: * get Connected twice here. */ if (dev->state != XenbusStateConnected) - goto InitWait; /* no InitWait seen yet, fudge it */ + /* no InitWait seen yet, fudge it */ + xenbus_switch_state(dev, XenbusStateConnected); if (xenbus_scanf(XBT_NIL, info->xbdev->otherend, "request-update", "%d", &val) < 0) -- 2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 56/86] ACPI / power: Avoid maybe-uninitialized warning |
| Message-ID | <tDkVR-1oS-41@gated-at.bofh.it> |
| In reply to | #1635498 |
From: Arnd Bergmann <arnd@arndb.de>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit fe8c470ab87d90e4b5115902dd94eced7e3305c3 upstream.
gcc -O2 cannot always prove that the loop in acpi_power_get_inferred_state()
is enterered at least once, so it assumes that cur_state might not get
initialized:
drivers/acpi/power.c: In function 'acpi_power_get_inferred_state':
drivers/acpi/power.c:222:9: error: 'cur_state' may be used uninitialized in this function [-Werror=maybe-uninitialized]
This sets the variable to zero at the start of the loop, to ensure that
there is well-defined behavior even for an empty list. This gets rid of
the warning.
The warning first showed up when the -Os flag got removed in a bug fix
patch in linux-4.11-rc5.
I would suggest merging this addon patch on top of that bug fix to avoid
introducing a new warning in the stable kernels.
Fixes: 61b79e16c68d (ACPI: Fix incompatibility with mcount-based function graph tracing)
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
drivers/acpi/power.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/acpi/power.c b/drivers/acpi/power.c
index c2ad391d8041..4b35a115749c 100644
--- a/drivers/acpi/power.c
+++ b/drivers/acpi/power.c
@@ -204,6 +204,7 @@ static int acpi_power_get_list_state(struct list_head *list, int *state)
return -EINVAL;
/* The state of the list is 'on' IFF all resources are 'on'. */
+ cur_state = 0;
list_for_each_entry(entry, list, node) {
struct acpi_power_resource *resource = entry->resource;
acpi_handle handle = resource->device.handle;
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 78/86] MIPS: Fix crash registers on non-crashing CPUs |
| Message-ID | <tDkVR-1oS-43@gated-at.bofh.it> |
| In reply to | #1635498 |
From: Corey Minyard <cminyard@mvista.com>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit c80e1b62ffca52e2d1d865ee58bc79c4c0c55005 upstream.
As part of handling a crash on an SMP system, an IPI is send to
all other CPUs to save their current registers and stop. It was
using task_pt_regs(current) to get the registers, but that will
only be accurate if the CPU was interrupted running in userland.
Instead allow the architecture to pass in the registers (all
pass NULL now, but allow for the future) and then use get_irq_regs()
which should be accurate as we are in an interrupt. Fall back to
task_pt_regs(current) if nothing else is available.
Signed-off-by: Corey Minyard <cminyard@mvista.com>
Cc: David Daney <ddaney@caviumnetworks.com>
Cc: linux-mips@linux-mips.org
Patchwork: https://patchwork.linux-mips.org/patch/13050/
Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
Cc: Julia Lawall <julia.lawall@lip6.fr>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
arch/mips/kernel/crash.c | 16 +++++++++++++---
1 file changed, 13 insertions(+), 3 deletions(-)
diff --git a/arch/mips/kernel/crash.c b/arch/mips/kernel/crash.c
index 93aa302948d7..c68312947ed9 100644
--- a/arch/mips/kernel/crash.c
+++ b/arch/mips/kernel/crash.c
@@ -15,12 +15,22 @@ static int crashing_cpu = -1;
static cpumask_t cpus_in_crash = CPU_MASK_NONE;
#ifdef CONFIG_SMP
-static void crash_shutdown_secondary(void *ignore)
+static void crash_shutdown_secondary(void *passed_regs)
{
- struct pt_regs *regs;
+ struct pt_regs *regs = passed_regs;
int cpu = smp_processor_id();
- regs = task_pt_regs(current);
+ /*
+ * If we are passed registers, use those. Otherwise get the
+ * regs from the last interrupt, which should be correct, as
+ * we are in an interrupt. But if the regs are not there,
+ * pull them from the top of the stack. They are probably
+ * wrong, but we need something to keep from crashing again.
+ */
+ if (!regs)
+ regs = get_irq_regs();
+ if (!regs)
+ regs = task_pt_regs(current);
if (!cpu_online(cpu))
return;
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 28/86] iscsi-target: Drop work-around for legacy GlobalSAN initiator |
| Message-ID | <tDkVR-1oS-47@gated-at.bofh.it> |
| In reply to | #1635498 |
From: Nicholas Bellinger <nab@linux-iscsi.org>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit 1c99de981f30b3e7868b8d20ce5479fa1c0fea46 upstream.
Once upon a time back in 2009, a work-around was added to support
the GlobalSAN iSCSI initiator v3.3 for MacOSX, which during login
did not propose nor respond to MaxBurstLength, FirstBurstLength,
DefaultTime2Wait and DefaultTime2Retain keys.
The work-around in iscsi_check_proposer_for_optional_reply()
allowed the missing keys to be proposed, but did not require
waiting for a response before moving to full feature phase
operation. This allowed GlobalSAN v3.3 to work out-of-the
box, and for many years we didn't run into login interopt
issues with any other initiators..
Until recently, when Martin tried a QLogic 57840S iSCSI Offload
HBA on Windows 2016 which completed login, but subsequently
failed with:
Got unknown iSCSI OpCode: 0x43
The issue was QLogic MSFT side did not propose DefaultTime2Wait +
DefaultTime2Retain, so LIO proposes them itself, and immediately
transitions to full feature phase because of the GlobalSAN hack.
However, the QLogic MSFT side still attempts to respond to
DefaultTime2Retain + DefaultTime2Wait, even though LIO has set
ISCSI_FLAG_LOGIN_NEXT_STAGE3 + ISCSI_FLAG_LOGIN_TRANSIT
in last login response.
So while the QLogic MSFT side should have been proposing these
two keys to start, it was doing the correct thing per RFC-3720
attempting to respond to proposed keys before transitioning to
full feature phase.
All that said, recent versions of GlobalSAN iSCSI (v5.3.0.541)
does correctly propose the four keys during login, making the
original work-around moot.
So in order to allow QLogic MSFT to run unmodified as-is, go
ahead and drop this long standing work-around.
Reported-by: Martin Svec <martin.svec@zoner.cz>
Cc: Martin Svec <martin.svec@zoner.cz>
Cc: Himanshu Madhani <Himanshu.Madhani@cavium.com>
Cc: Arun Easi <arun.easi@cavium.com>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
drivers/target/iscsi/iscsi_target_parameters.c | 16 ----------------
1 file changed, 16 deletions(-)
diff --git a/drivers/target/iscsi/iscsi_target_parameters.c b/drivers/target/iscsi/iscsi_target_parameters.c
index 43b7e6a616b8..c9df3cd89a13 100644
--- a/drivers/target/iscsi/iscsi_target_parameters.c
+++ b/drivers/target/iscsi/iscsi_target_parameters.c
@@ -804,22 +804,6 @@ static void iscsi_check_proposer_for_optional_reply(struct iscsi_param *param)
if (!strcmp(param->name, MAXRECVDATASEGMENTLENGTH))
SET_PSTATE_REPLY_OPTIONAL(param);
/*
- * The GlobalSAN iSCSI Initiator for MacOSX does
- * not respond to MaxBurstLength, FirstBurstLength,
- * DefaultTime2Wait or DefaultTime2Retain parameter keys.
- * So, we set them to 'reply optional' here, and assume the
- * the defaults from iscsi_parameters.h if the initiator
- * is not RFC compliant and the keys are not negotiated.
- */
- if (!strcmp(param->name, MAXBURSTLENGTH))
- SET_PSTATE_REPLY_OPTIONAL(param);
- if (!strcmp(param->name, FIRSTBURSTLENGTH))
- SET_PSTATE_REPLY_OPTIONAL(param);
- if (!strcmp(param->name, DEFAULTTIME2WAIT))
- SET_PSTATE_REPLY_OPTIONAL(param);
- if (!strcmp(param->name, DEFAULTTIME2RETAIN))
- SET_PSTATE_REPLY_OPTIONAL(param);
- /*
* Required for gPXE iSCSI boot client
*/
if (!strcmp(param->name, MAXCONNECTIONS))
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 29/86] scsi: sr: Sanity check returned mode data |
| Message-ID | <tDkVR-1oS-49@gated-at.bofh.it> |
| In reply to | #1635498 |
From: "Martin K. Petersen" <martin.petersen@oracle.com>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit a00a7862513089f17209b732f230922f1942e0b9 upstream.
Kefeng Wang discovered that old versions of the QEMU CD driver would
return mangled mode data causing us to walk off the end of the buffer in
an attempt to parse it. Sanity check the returned mode sense data.
Reported-by: Kefeng Wang <wangkefeng.wang@huawei.com>
Tested-by: Kefeng Wang <wangkefeng.wang@huawei.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
drivers/scsi/sr.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/scsi/sr.c b/drivers/scsi/sr.c
index 1ac9943cbb93..c1f23abd754a 100644
--- a/drivers/scsi/sr.c
+++ b/drivers/scsi/sr.c
@@ -855,6 +855,7 @@ static void get_capabilities(struct scsi_cd *cd)
unsigned char *buffer;
struct scsi_mode_data data;
struct scsi_sense_hdr sshdr;
+ unsigned int ms_len = 128;
int rc, n;
static const char *loadmech[] =
@@ -881,10 +882,11 @@ static void get_capabilities(struct scsi_cd *cd)
scsi_test_unit_ready(cd->device, SR_TIMEOUT, MAX_RETRIES, &sshdr);
/* ask for mode page 0x2a */
- rc = scsi_mode_sense(cd->device, 0, 0x2a, buffer, 128,
+ rc = scsi_mode_sense(cd->device, 0, 0x2a, buffer, ms_len,
SR_TIMEOUT, 3, &data, NULL);
- if (!scsi_status_is_good(rc)) {
+ if (!scsi_status_is_good(rc) || data.length > ms_len ||
+ data.header_length + data.block_descriptor_length > data.length) {
/* failed, drive doesn't have capabilities mode page */
cd->cdi.speed = 1;
cd->cdi.mask |= (CDC_CD_R | CDC_CD_RW | CDC_DVD_R |
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 83/86] p9_client_readdir() fix |
| Message-ID | <tDkVS-1oS-51@gated-at.bofh.it> |
| In reply to | #1635498 |
From: Al Viro <viro@zeniv.linux.org.uk>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit 71d6ad08379304128e4bdfaf0b4185d54375423e upstream.
Don't assume that server is sane and won't return more data than
asked for.
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
net/9p/client.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/net/9p/client.c b/net/9p/client.c
index ae4778c84559..bde453ae5e2e 100644
--- a/net/9p/client.c
+++ b/net/9p/client.c
@@ -2099,6 +2099,10 @@ int p9_client_readdir(struct p9_fid *fid, char *data, u32 count, u64 offset)
trace_9p_protocol_dump(clnt, req->rc);
goto free_and_error;
}
+ if (rsize < count) {
+ pr_err("bogus RREADDIR count (%d > %d)\n", count, rsize);
+ count = rsize;
+ }
p9_debug(P9_DEBUG_9P, "<<< RREADDIR count %d\n", count);
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 06/86] ptrace: fix PTRACE_LISTEN race corrupting task->state |
| Message-ID | <tDkVS-1oS-55@gated-at.bofh.it> |
| In reply to | #1635498 |
From: "bsegall@google.com" <bsegall@google.com>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit 5402e97af667e35e54177af8f6575518bf251d51 upstream.
In PT_SEIZED + LISTEN mode STOP/CONT signals cause a wakeup against
__TASK_TRACED. If this races with the ptrace_unfreeze_traced at the end
of a PTRACE_LISTEN, this can wake the task /after/ the check against
__TASK_TRACED, but before the reset of state to TASK_TRACED. This
causes it to instead clobber TASK_WAKING, allowing a subsequent wakeup
against TRACED while the task is still on the rq wake_list, corrupting
it.
Oleg said:
"The kernel can crash or this can lead to other hard-to-debug problems.
In short, "task->state = TASK_TRACED" in ptrace_unfreeze_traced()
assumes that nobody else can wake it up, but PTRACE_LISTEN breaks the
contract. Obviusly it is very wrong to manipulate task->state if this
task is already running, or WAKING, or it sleeps again"
[akpm@linux-foundation.org: coding-style fixes]
Fixes: 9899d11f ("ptrace: ensure arch_ptrace/ptrace_request can never race with SIGKILL")
Link: http://lkml.kernel.org/r/xm26y3vfhmkp.fsf_-_@bsegall-linux.mtv.corp.google.com
Signed-off-by: Ben Segall <bsegall@google.com>
Acked-by: Oleg Nesterov <oleg@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
kernel/ptrace.c | 14 ++++++++++----
1 file changed, 10 insertions(+), 4 deletions(-)
diff --git a/kernel/ptrace.c b/kernel/ptrace.c
index 4524314ecbb4..3e3d7841179b 100644
--- a/kernel/ptrace.c
+++ b/kernel/ptrace.c
@@ -150,11 +150,17 @@ static void ptrace_unfreeze_traced(struct task_struct *task)
WARN_ON(!task->ptrace || task->parent != current);
+ /*
+ * PTRACE_LISTEN can allow ptrace_trap_notify to wake us up remotely.
+ * Recheck state under the lock to close this race.
+ */
spin_lock_irq(&task->sighand->siglock);
- if (__fatal_signal_pending(task))
- wake_up_state(task, __TASK_TRACED);
- else
- task->state = TASK_TRACED;
+ if (task->state == __TASK_TRACED) {
+ if (__fatal_signal_pending(task))
+ wake_up_state(task, __TASK_TRACED);
+ else
+ task->state = TASK_TRACED;
+ }
spin_unlock_irq(&task->sighand->siglock);
}
--
2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 80/86] xen/x86: don't lose event interrupts |
| Message-ID | <tDkVS-1oS-53@gated-at.bofh.it> |
| In reply to | #1635498 |
From: Stefano Stabellini <sstabellini@kernel.org> 3.12-stable review patch. If anyone has any objections, please let me know. =============== commit c06b6d70feb32d28f04ba37aa3df17973fd37b6b upstream. On slow platforms with unreliable TSC, such as QEMU emulated machines, it is possible for the kernel to request the next event in the past. In that case, in the current implementation of xen_vcpuop_clockevent, we simply return -ETIME. To be precise the Xen returns -ETIME and we pass it on. However the result of this is a missed event, which simply causes the kernel to hang. Instead it is better to always ask the hypervisor for a timer event, even if the timeout is in the past. That way there are no lost interrupts and the kernel survives. To do that, remove the VCPU_SSHOTTMR_future flag. Signed-off-by: Stefano Stabellini <sstabellini@kernel.org> Acked-by: Juergen Gross <jgross@suse.com> Cc: Julia Lawall <julia.lawall@lip6.fr> Signed-off-by: Jiri Slaby <jslaby@suse.cz> --- arch/x86/xen/time.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/arch/x86/xen/time.c b/arch/x86/xen/time.c index 90bfa524b11c..86dc28ce11ab 100644 --- a/arch/x86/xen/time.c +++ b/arch/x86/xen/time.c @@ -362,11 +362,11 @@ static int xen_vcpuop_set_next_event(unsigned long delta, WARN_ON(evt->mode != CLOCK_EVT_MODE_ONESHOT); single.timeout_abs_ns = get_abs_timeout(delta); - single.flags = VCPU_SSHOTTMR_future; + /* Get an event anyway, even if the timeout is already expired */ + single.flags = 0; ret = HYPERVISOR_vcpu_op(VCPUOP_set_singleshot_timer, cpu, &single); - - BUG_ON(ret != 0 && ret != -ETIME); + BUG_ON(ret != 0); return ret; } -- 2.12.2
[toc] | [prev] | [next] | [standalone]
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Date | 2017-05-04 11:10 +0200 |
| Subject | [PATCH 3.12 55/86] Input: elantech - add Fujitsu Lifebook E547 to force crc_enabled |
| Message-ID | <tDkVS-1oS-57@gated-at.bofh.it> |
| In reply to | #1635498 |
From: Thorsten Leemhuis <linux@leemhuis.info>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit 704de489e0e3640a2ee2d0daf173e9f7375582ba upstream.
Temporary got a Lifebook E547 into my hands and noticed the touchpad
only works after running:
echo "1" > /sys/devices/platform/i8042/serio2/crc_enabled
Add it to the list of machines that need this workaround.
Signed-off-by: Thorsten Leemhuis <linux@leemhuis.info>
Reviewed-by: Ulrik De Bie <ulrik.debie-os@e2big.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
drivers/input/mouse/elantech.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/input/mouse/elantech.c b/drivers/input/mouse/elantech.c
index a25fc40522f3..05453836edc7 100644
--- a/drivers/input/mouse/elantech.c
+++ b/drivers/input/mouse/elantech.c
@@ -1036,6 +1036,7 @@ static int elantech_get_resolution_v4(struct psmouse *psmouse,
* Asus UX32VD 0x361f02 00, 15, 0e clickpad
* Avatar AVIU-145A2 0x361f00 ? clickpad
* Fujitsu LIFEBOOK E544 0x470f00 d0, 12, 09 2 hw buttons
+ * Fujitsu LIFEBOOK E547 0x470f00 50, 12, 09 2 hw buttons
* Fujitsu LIFEBOOK E554 0x570f01 40, 14, 0c 2 hw buttons
* Gigabyte U2442 0x450f01 58, 17, 0c 2 hw buttons
* Lenovo L430 0x350f02 b9, 15, 0c 2 hw buttons (*)
@@ -1403,6 +1404,13 @@ static const struct dmi_system_id elantech_dmi_force_crc_enabled[] = {
},
},
{
+ /* Fujitsu LIFEBOOK E547 does not work with crc_enabled == 0 */
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "FUJITSU"),
+ DMI_MATCH(DMI_PRODUCT_NAME, "LIFEBOOK E547"),
+ },
+ },
+ {
/* Fujitsu LIFEBOOK E554 does not work with crc_enabled == 0 */
.matches = {
DMI_MATCH(DMI_SYS_VENDOR, "FUJITSU"),
--
2.12.2
[toc] | [prev] | [next] | [standalone]
Page 1 of 5 [1] 2 3 4 5 Next page →
Back to top | Article view | linux.kernel
csiph-web