Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1639409 > unrolled thread

[PATCH 3.18 00/39] 3.18.53-stable review

Started byGreg Kroah-Hartman <gregkh@linuxfoundation.org>
First post2017-05-11 15:10 +0200
Last post2017-05-15 08:20 +0200
Articles 20 on this page of 26 — 6 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.18 00/39] 3.18.53-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 15:10 +0200
    [PATCH 3.18 28/39] USB: serial: sierra: fix bogus alternate-setting assumption Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 15:10 +0200
    [PATCH 3.18 18/39] USB: serial: keyspan_pda: fix receive sanity checks Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 15:10 +0200
    [PATCH 3.18 34/39] ipv4, ipv6: ensure raw socket message is big enough to hold an IP header Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 15:10 +0200
    [PATCH 3.18 10/39] mwifiex: debugfs: Fix (sometimes) off-by-1 SSID print Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 15:10 +0200
    [PATCH 3.18 31/39] brcmfmac: Make skb header writable before use Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 15:10 +0200
    [PATCH 3.18 26/39] USB: serial: mct_u232: fix modem-status error handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 15:10 +0200
    [PATCH 3.18 03/39] mtd: cfi: reduce stack size Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 15:10 +0200
    [PATCH 3.18 06/39] powerpc/powernv: Fix opal_exit tracepoint opcode Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 15:20 +0200
    [PATCH 3.18 05/39] cpupower: Fix turbo frequency reporting for pre-Sandy Bridge cores Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 15:20 +0200
    [PATCH 3.18 09/39] ARM: OMAP5 / DRA7: Fix HYP mode boot for thumb2 build Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 15:20 +0200
    [PATCH 3.18 20/39] USB: serial: ssu100: fix control-message error handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 15:20 +0200
    [PATCH 3.18 08/39] power: supply: bq24190_charger: Call set_mode_host() on pm_resume() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 15:20 +0200
    Re: [PATCH 3.18 00/39] 3.18.53-stable review Guenter Roeck <linux@roeck-us.net> - 2017-05-11 23:20 +0200
      Re: [PATCH 3.18 00/39] 3.18.53-stable review Matthijs van Duin <matthijsvanduin@gmail.com> - 2017-05-11 23:40 +0200
        Re: [PATCH 3.18 00/39] 3.18.53-stable review Tony Lindgren <tony@atomide.com> - 2017-05-11 23:50 +0200
          Re: [PATCH 3.18 00/39] 3.18.53-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-12 11:40 +0200
            Re: [PATCH 3.18 00/39] 3.18.53-stable review Arnd Bergmann <arnd@arndb.de> - 2017-05-12 12:20 +0200
              Re: [PATCH 3.18 00/39] 3.18.53-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-12 12:50 +0200
    Re: [PATCH 3.18 00/39] 3.18.53-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2017-05-12 17:30 +0200
    Re: [PATCH 3.18 00/39] 3.18.53-stable review Guenter Roeck <linux@roeck-us.net> - 2017-05-12 21:50 +0200
      Re: [PATCH 3.18 00/39] 3.18.53-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-14 13:00 +0200
        Re: [PATCH 3.18 00/39] 3.18.53-stable review Guenter Roeck <linux@roeck-us.net> - 2017-05-14 16:10 +0200
          Re: [PATCH 3.18 00/39] 3.18.53-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-14 23:00 +0200
            Re: [PATCH 3.18 00/39] 3.18.53-stable review Guenter Roeck <linux@roeck-us.net> - 2017-05-15 01:40 +0200
              Re: [PATCH 3.18 00/39] 3.18.53-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-15 08:20 +0200

Page 1 of 2  [1] 2  Next page →


#1639409 — [PATCH 3.18 00/39] 3.18.53-stable review

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-11 15:10 +0200
Subject[PATCH 3.18 00/39] 3.18.53-stable review
Message-ID<tFW0W-6HP-5@gated-at.bofh.it>
This is the start of the stable review cycle for the 3.18.53 release.
There are 39 patches in this series, all will be posted as a response
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Sat May 13 13:02:15 UTC 2017.
Anything received after that time might be too late.

The whole patch series can be found in one patch at:
	kernel.org/pub/linux/kernel/v3.x/stable-review/patch-3.18.53-rc1.gz
or in the git tree and branch at:
  git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-3.18.y
and the diffstat can be found below.

thanks,

greg k-h

-------------
Pseudo-Shortlog of commits:

Greg Kroah-Hartman <gregkh@linuxfoundation.org>
    Linux 3.18.53-rc1

Nicolai Hähnle <nicolai.haehnle@amd.com>
    drm/ttm: fix use-after-free races in vm fault handling

Jin Qian <jinqian@google.com>
    f2fs: sanity check segment count

Eric Dumazet <edumazet@google.com>
    tcp: fix wraparound issue in tcp_lp

WANG Cong <xiyou.wangcong@gmail.com>
    ipv6: reorder ip6_route_dev_notifier after ipv6_dev_notf

WANG Cong <xiyou.wangcong@gmail.com>
    ipv6: initialize route null entry in addrconf_init()

Alexander Potapenko <glider@google.com>
    ipv4, ipv6: ensure raw socket message is big enough to hold an IP header

Eric Dumazet <edumazet@google.com>
    tcp: do not underestimate skb->truesize in tcp_trim_head()

Arnd Bergmann <arnd@arndb.de>
    staging: emxx_udc: remove incorrect __init annotations

James Hughes <james.hughes@raspberrypi.org>
    brcmfmac: Make skb header writable before use

James Hughes <james.hughes@raspberrypi.org>
    brcmfmac: Ensure pointer correctly set if skb data location changes

Dan Carpenter <dan.carpenter@oracle.com>
    scsi: scsi_dh_emc: return success in clariion_std_inquiry()

Johan Hovold <johan@kernel.org>
    USB: serial: sierra: fix bogus alternate-setting assumption

Johan Hovold <johan@kernel.org>
    USB: serial: io_edgeport: fix descriptor error handling

Johan Hovold <johan@kernel.org>
    USB: serial: mct_u232: fix modem-status error handling

Johan Hovold <johan@kernel.org>
    USB: serial: quatech2: fix control-message error handling

Johan Hovold <johan@kernel.org>
    USB: serial: ftdi_sio: fix latency-timer error handling

Johan Hovold <johan@kernel.org>
    USB: serial: ark3116: fix open error handling

Johan Hovold <johan@kernel.org>
    USB: serial: ti_usb_3410_5052: fix control-message error handling

Johan Hovold <johan@kernel.org>
    USB: serial: io_edgeport: fix epic-descriptor handling

Johan Hovold <johan@kernel.org>
    USB: serial: ssu100: fix control-message error handling

Johan Hovold <johan@kernel.org>
    USB: serial: digi_acceleport: fix incomplete rx sanity check

Johan Hovold <johan@kernel.org>
    USB: serial: keyspan_pda: fix receive sanity checks

Krzysztof Kozlowski <krzk@kernel.org>
    usb: host: ohci-exynos: Decrese node refcount on exynos_ehci_get_phy() error paths

Krzysztof Kozlowski <krzk@kernel.org>
    usb: host: ehci-exynos: Decrese node refcount on exynos_ehci_get_phy() error paths

Jim Mattson <jmattson@google.com>
    Revert "KVM: nested VMX: disable perf cpuid reporting"

Andy Shevchenko <andriy.shevchenko@linux.intel.com>
    x86/platform/intel-mid: Correct MSI IRQ line for watchdog device

Masami Hiramatsu <mhiramat@kernel.org>
    kprobes/x86: Fix kernel panic when certain exception-handling addresses are probed

Nikola Pajkovsky <npajkovsky@suse.cz>
    x86/pci-calgary: Fix iommu_free() comparison of unsigned expression >= 0

Ganapathi Bhat <gbhat@marvell.com>
    mwifiex: Avoid skipping WEP key deletion for AP

Brian Norris <briannorris@chromium.org>
    mwifiex: debugfs: Fix (sometimes) off-by-1 SSID print

Matthijs van Duin <matthijsvanduin@gmail.com>
    ARM: OMAP5 / DRA7: Fix HYP mode boot for thumb2 build

Liam Breck <liam@networkimprov.net>
    power: supply: bq24190_charger: Call set_mode_host() on pm_resume()

Liam Breck <liam@networkimprov.net>
    power: supply: bq24190_charger: Fix irq trigger to IRQF_TRIGGER_FALLING

Michael Ellerman <mpe@ellerman.id.au>
    powerpc/powernv: Fix opal_exit tracepoint opcode

Ben Hutchings <ben@decadent.org.uk>
    cpupower: Fix turbo frequency reporting for pre-Sandy Bridge cores

Ard Biesheuvel <ard.biesheuvel@linaro.org>
    ARM: 8452/3: PJ4: make coprocessor access sequences buildable in Thumb2 mode

Arnd Bergmann <arnd@arndb.de>
    mtd: cfi: reduce stack size

Arnd Bergmann <arnd@arndb.de>
    tty: remove platform_sysrq_reset_seq

Cong Wang <xiyou.wangcong@gmail.com>
    9p: fix a potential acl leak


-------------

Diffstat:

 Makefile                                           |  4 +-
 arch/arm/kernel/Makefile                           |  1 -
 arch/arm/kernel/pj4-cp0.c                          |  4 ++
 arch/arm/mach-omap2/omap-headsmp.S                 |  3 +-
 arch/powerpc/platforms/powernv/opal-wrappers.S     |  2 +-
 arch/x86/kernel/kprobes/common.h                   |  2 +-
 arch/x86/kernel/kprobes/core.c                     |  6 +--
 arch/x86/kernel/kprobes/opt.c                      |  2 +-
 arch/x86/kernel/pci-calgary_64.c                   |  2 +-
 arch/x86/kvm/cpuid.c                               |  6 ---
 arch/x86/kvm/vmx.c                                 |  2 -
 .../platform/intel-mid/device_libs/platform_wdt.c  |  2 +-
 drivers/gpu/drm/ttm/ttm_bo_vm.c                    | 12 ++++++
 .../net/wireless/brcm80211/brcmfmac/dhd_linux.c    | 23 ++++-------
 drivers/net/wireless/mwifiex/debugfs.c             |  3 +-
 drivers/net/wireless/mwifiex/sta_ioctl.c           |  2 -
 drivers/power/bq24190_charger.c                    |  3 +-
 drivers/scsi/device_handler/scsi_dh_emc.c          |  2 +-
 drivers/staging/emxx_udc/emxx_udc.c                |  4 +-
 drivers/tty/sysrq.c                                | 19 +--------
 drivers/usb/host/ehci-exynos.c                     |  2 +
 drivers/usb/host/ohci-exynos.c                     |  2 +
 drivers/usb/serial/ark3116.c                       | 25 ++++++++---
 drivers/usb/serial/digi_acceleport.c               | 38 ++++++++++-------
 drivers/usb/serial/ftdi_sio.c                      |  7 +++-
 drivers/usb/serial/io_edgeport.c                   | 48 +++++++++++++++-------
 drivers/usb/serial/keyspan_pda.c                   | 19 ++++++---
 drivers/usb/serial/mct_u232.c                      |  6 ++-
 drivers/usb/serial/quatech2.c                      | 24 ++++++-----
 drivers/usb/serial/sierra.c                        | 28 +++----------
 drivers/usb/serial/ssu100.c                        | 31 ++++++++++----
 drivers/usb/serial/ti_usb_3410_5052.c              | 12 ++----
 fs/9p/acl.c                                        |  2 +
 fs/f2fs/super.c                                    |  7 ++++
 include/linux/f2fs_fs.h                            |  6 +++
 include/linux/mtd/map.h                            | 12 +++++-
 include/net/addrconf.h                             |  2 +
 include/net/ip6_route.h                            |  1 +
 net/ipv4/raw.c                                     |  3 ++
 net/ipv4/tcp_lp.c                                  |  6 ++-
 net/ipv4/tcp_output.c                              | 19 +++++----
 net/ipv6/addrconf.c                                |  3 ++
 net/ipv6/raw.c                                     |  2 +
 net/ipv6/route.c                                   | 39 ++++++++++++------
 tools/power/cpupower/utils/helpers/cpuid.c         |  1 +
 45 files changed, 273 insertions(+), 176 deletions(-)

[toc] | [next] | [standalone]


#1639410 — [PATCH 3.18 28/39] USB: serial: sierra: fix bogus alternate-setting assumption

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-11 15:10 +0200
Subject[PATCH 3.18 28/39] USB: serial: sierra: fix bogus alternate-setting assumption
Message-ID<tFW0Y-6HP-73@gated-at.bofh.it>
In reply to#1639409
3.18-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 16620b483eaf7750413bae472f4363b6b959fcaa upstream.

Interface numbers do not change when enabling alternate settings as
comment and code in this driver suggested.

Remove the confusing comment and redundant retrieval of the interface
number in probe, while simplifying and renaming the interface-number
helper.

Fixes: 4db2299da213 ("sierra: driver interface blacklisting")
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/serial/sierra.c |   28 +++++-----------------------
 1 file changed, 5 insertions(+), 23 deletions(-)

--- a/drivers/usb/serial/sierra.c
+++ b/drivers/usb/serial/sierra.c
@@ -137,24 +137,9 @@ static int is_himemory(const u8 ifnum,
 	return 0;
 }
 
-static int sierra_calc_interface(struct usb_serial *serial)
+static u8 sierra_interface_num(struct usb_serial *serial)
 {
-	int interface;
-	struct usb_interface *p_interface;
-	struct usb_host_interface *p_host_interface;
-
-	/* Get the interface structure pointer from the serial struct */
-	p_interface = serial->interface;
-
-	/* Get a pointer to the host interface structure */
-	p_host_interface = p_interface->cur_altsetting;
-
-	/* read the interface descriptor for this active altsetting
-	 * to find out the interface number we are on
-	*/
-	interface = p_host_interface->desc.bInterfaceNumber;
-
-	return interface;
+	return serial->interface->cur_altsetting->desc.bInterfaceNumber;
 }
 
 static int sierra_probe(struct usb_serial *serial,
@@ -165,7 +150,7 @@ static int sierra_probe(struct usb_seria
 	u8 ifnum;
 
 	udev = serial->dev;
-	ifnum = sierra_calc_interface(serial);
+	ifnum = sierra_interface_num(serial);
 
 	/*
 	 * If this interface supports more than 1 alternate
@@ -178,9 +163,6 @@ static int sierra_probe(struct usb_seria
 		usb_set_interface(udev, ifnum, 1);
 	}
 
-	/* ifnum could have changed - by calling usb_set_interface */
-	ifnum = sierra_calc_interface(serial);
-
 	if (is_blacklisted(ifnum,
 				(struct sierra_iface_info *)id->driver_info)) {
 		dev_dbg(&serial->dev->dev,
@@ -342,7 +324,7 @@ static int sierra_send_setup(struct usb_
 
 	/* If composite device then properly report interface */
 	if (serial->num_ports == 1) {
-		interface = sierra_calc_interface(serial);
+		interface = sierra_interface_num(serial);
 		/* Control message is sent only to interfaces with
 		 * interrupt_in endpoints
 		 */
@@ -916,7 +898,7 @@ static int sierra_port_probe(struct usb_
 	/* Determine actual memory requirements */
 	if (serial->num_ports == 1) {
 		/* Get interface number for composite device */
-		ifnum = sierra_calc_interface(serial);
+		ifnum = sierra_interface_num(serial);
 		himemoryp = &typeB_interface_list;
 	} else {
 		/* This is really the usb-serial port number of the interface

[toc] | [prev] | [next] | [standalone]


#1639411 — [PATCH 3.18 18/39] USB: serial: keyspan_pda: fix receive sanity checks

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-11 15:10 +0200
Subject[PATCH 3.18 18/39] USB: serial: keyspan_pda: fix receive sanity checks
Message-ID<tFW0Y-6HP-77@gated-at.bofh.it>
In reply to#1639409
3.18-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit c528fcb116e61afc379a2e0a0f70906b937f1e2c upstream.

Make sure to check for short transfers before parsing the receive buffer
to avoid acting on stale data.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/serial/keyspan_pda.c |   19 ++++++++++++++-----
 1 file changed, 14 insertions(+), 5 deletions(-)

--- a/drivers/usb/serial/keyspan_pda.c
+++ b/drivers/usb/serial/keyspan_pda.c
@@ -139,6 +139,7 @@ static void keyspan_pda_rx_interrupt(str
 {
 	struct usb_serial_port *port = urb->context;
 	unsigned char *data = urb->transfer_buffer;
+	unsigned int len = urb->actual_length;
 	int retval;
 	int status = urb->status;
 	struct keyspan_pda_private *priv;
@@ -159,18 +160,26 @@ static void keyspan_pda_rx_interrupt(str
 		goto exit;
 	}
 
+	if (len < 1) {
+		dev_warn(&port->dev, "short message received\n");
+		goto exit;
+	}
+
 	/* see if the message is data or a status interrupt */
 	switch (data[0]) {
 	case 0:
 		 /* rest of message is rx data */
-		if (urb->actual_length) {
-			tty_insert_flip_string(&port->port, data + 1,
-						urb->actual_length - 1);
-			tty_flip_buffer_push(&port->port);
-		}
+		if (len < 2)
+			break;
+		tty_insert_flip_string(&port->port, data + 1, len - 1);
+		tty_flip_buffer_push(&port->port);
 		break;
 	case 1:
 		/* status interrupt */
+		if (len < 3) {
+			dev_warn(&port->dev, "short interrupt message received\n");
+			break;
+		}
 		dev_dbg(&port->dev, "rx int, d1=%d, d2=%d\n", data[1], data[2]);
 		switch (data[1]) {
 		case 1: /* modemline change */

[toc] | [prev] | [next] | [standalone]


#1639412 — [PATCH 3.18 34/39] ipv4, ipv6: ensure raw socket message is big enough to hold an IP header

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-11 15:10 +0200
Subject[PATCH 3.18 34/39] ipv4, ipv6: ensure raw socket message is big enough to hold an IP header
Message-ID<tFW0Y-6HP-79@gated-at.bofh.it>
In reply to#1639409
3.18-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alexander Potapenko <glider@google.com>


[ Upstream commit 86f4c90a1c5c1493f07f2d12c1079f5bf01936f2 ]

raw_send_hdrinc() and rawv6_send_hdrinc() expect that the buffer copied
from the userspace contains the IPv4/IPv6 header, so if too few bytes are
copied, parts of the header may remain uninitialized.

This bug has been detected with KMSAN.

For the record, the KMSAN report:

==================================================================
BUG: KMSAN: use of unitialized memory in nf_ct_frag6_gather+0xf5a/0x44a0
inter: 0
CPU: 0 PID: 1036 Comm: probe Not tainted 4.11.0-rc5+ #2455
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011
Call Trace:
 __dump_stack lib/dump_stack.c:16
 dump_stack+0x143/0x1b0 lib/dump_stack.c:52
 kmsan_report+0x16b/0x1e0 mm/kmsan/kmsan.c:1078
 __kmsan_warning_32+0x5c/0xa0 mm/kmsan/kmsan_instr.c:510
 nf_ct_frag6_gather+0xf5a/0x44a0 net/ipv6/netfilter/nf_conntrack_reasm.c:577
 ipv6_defrag+0x1d9/0x280 net/ipv6/netfilter/nf_defrag_ipv6_hooks.c:68
 nf_hook_entry_hookfn ./include/linux/netfilter.h:102
 nf_hook_slow+0x13f/0x3c0 net/netfilter/core.c:310
 nf_hook ./include/linux/netfilter.h:212
 NF_HOOK ./include/linux/netfilter.h:255
 rawv6_send_hdrinc net/ipv6/raw.c:673
 rawv6_sendmsg+0x2fcb/0x41a0 net/ipv6/raw.c:919
 inet_sendmsg+0x3f8/0x6d0 net/ipv4/af_inet.c:762
 sock_sendmsg_nosec net/socket.c:633
 sock_sendmsg net/socket.c:643
 SYSC_sendto+0x6a5/0x7c0 net/socket.c:1696
 SyS_sendto+0xbc/0xe0 net/socket.c:1664
 do_syscall_64+0x72/0xa0 arch/x86/entry/common.c:285
 entry_SYSCALL64_slow_path+0x25/0x25 arch/x86/entry/entry_64.S:246
RIP: 0033:0x436e03
RSP: 002b:00007ffce48baf38 EFLAGS: 00000246 ORIG_RAX: 000000000000002c
RAX: ffffffffffffffda RBX: 00000000004002b0 RCX: 0000000000436e03
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003
RBP: 00007ffce48baf90 R08: 00007ffce48baf50 R09: 000000000000001c
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000401790 R14: 0000000000401820 R15: 0000000000000000
origin: 00000000d9400053
 save_stack_trace+0x16/0x20 arch/x86/kernel/stacktrace.c:59
 kmsan_save_stack_with_flags mm/kmsan/kmsan.c:362
 kmsan_internal_poison_shadow+0xb1/0x1a0 mm/kmsan/kmsan.c:257
 kmsan_poison_shadow+0x6d/0xc0 mm/kmsan/kmsan.c:270
 slab_alloc_node mm/slub.c:2735
 __kmalloc_node_track_caller+0x1f4/0x390 mm/slub.c:4341
 __kmalloc_reserve net/core/skbuff.c:138
 __alloc_skb+0x2cd/0x740 net/core/skbuff.c:231
 alloc_skb ./include/linux/skbuff.h:933
 alloc_skb_with_frags+0x209/0xbc0 net/core/skbuff.c:4678
 sock_alloc_send_pskb+0x9ff/0xe00 net/core/sock.c:1903
 sock_alloc_send_skb+0xe4/0x100 net/core/sock.c:1920
 rawv6_send_hdrinc net/ipv6/raw.c:638
 rawv6_sendmsg+0x2918/0x41a0 net/ipv6/raw.c:919
 inet_sendmsg+0x3f8/0x6d0 net/ipv4/af_inet.c:762
 sock_sendmsg_nosec net/socket.c:633
 sock_sendmsg net/socket.c:643
 SYSC_sendto+0x6a5/0x7c0 net/socket.c:1696
 SyS_sendto+0xbc/0xe0 net/socket.c:1664
 do_syscall_64+0x72/0xa0 arch/x86/entry/common.c:285
 return_from_SYSCALL_64+0x0/0x6a arch/x86/entry/entry_64.S:246
==================================================================

, triggered by the following syscalls:
  socket(PF_INET6, SOCK_RAW, IPPROTO_RAW) = 3
  sendto(3, NULL, 0, 0, {sa_family=AF_INET6, sin6_port=htons(0), inet_pton(AF_INET6, "ff00::", &sin6_addr), sin6_flowinfo=0, sin6_scope_id=0}, 28) = -1 EPERM

A similar report is triggered in net/ipv4/raw.c if we use a PF_INET socket
instead of a PF_INET6 one.

Signed-off-by: Alexander Potapenko <glider@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/ipv4/raw.c |    3 +++
 net/ipv6/raw.c |    2 ++
 2 files changed, 5 insertions(+)

--- a/net/ipv4/raw.c
+++ b/net/ipv4/raw.c
@@ -345,6 +345,9 @@ static int raw_send_hdrinc(struct sock *
 			       rt->dst.dev->mtu);
 		return -EMSGSIZE;
 	}
+	if (length < sizeof(struct iphdr))
+		return -EINVAL;
+
 	if (flags&MSG_PROBE)
 		goto out;
 
--- a/net/ipv6/raw.c
+++ b/net/ipv6/raw.c
@@ -624,6 +624,8 @@ static int rawv6_send_hdrinc(struct sock
 		ipv6_local_error(sk, EMSGSIZE, fl6, rt->dst.dev->mtu);
 		return -EMSGSIZE;
 	}
+	if (length < sizeof(struct ipv6hdr))
+		return -EINVAL;
 	if (flags&MSG_PROBE)
 		goto out;
 

[toc] | [prev] | [next] | [standalone]


#1639413 — [PATCH 3.18 10/39] mwifiex: debugfs: Fix (sometimes) off-by-1 SSID print

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-11 15:10 +0200
Subject[PATCH 3.18 10/39] mwifiex: debugfs: Fix (sometimes) off-by-1 SSID print
Message-ID<tFW0Y-6HP-83@gated-at.bofh.it>
In reply to#1639409
3.18-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Brian Norris <briannorris@chromium.org>

commit 6183468a23fc6b6903f8597982017ad2c7fdefcf upstream.

Similar to commit fcd2042e8d36 ("mwifiex: printk() overflow with 32-byte
SSIDs"), we failed to account for the existence of 32-char SSIDs in our
debugfs code. Unlike in that case though, we zeroed out the containing
struct first, and I'm pretty sure we're guaranteed to have some padding
after the 'ssid.ssid' and 'ssid.ssid_len' fields (the struct is 33 bytes
long).

So, this is the difference between:

  # cat /sys/kernel/debug/mwifiex/mlan0/info
  ...
  essid="0123456789abcdef0123456789abcdef "
  ...

and the correct output:

  # cat /sys/kernel/debug/mwifiex/mlan0/info
  ...
  essid="0123456789abcdef0123456789abcdef"
  ...

Fixes: 5e6e3a92b9a4 ("wireless: mwifiex: initial commit for Marvell mwifiex driver")
Signed-off-by: Brian Norris <briannorris@chromium.org>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/net/wireless/mwifiex/debugfs.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/net/wireless/mwifiex/debugfs.c
+++ b/drivers/net/wireless/mwifiex/debugfs.c
@@ -220,7 +220,8 @@ mwifiex_info_read(struct file *file, cha
 	if (GET_BSS_ROLE(priv) == MWIFIEX_BSS_ROLE_STA) {
 		p += sprintf(p, "multicast_count=\"%d\"\n",
 			     netdev_mc_count(netdev));
-		p += sprintf(p, "essid=\"%s\"\n", info.ssid.ssid);
+		p += sprintf(p, "essid=\"%.*s\"\n", info.ssid.ssid_len,
+			     info.ssid.ssid);
 		p += sprintf(p, "bssid=\"%pM\"\n", info.bssid);
 		p += sprintf(p, "channel=\"%d\"\n", (int) info.bss_chan);
 		p += sprintf(p, "country_code = \"%s\"\n", info.country_code);

[toc] | [prev] | [next] | [standalone]


#1639414 — [PATCH 3.18 31/39] brcmfmac: Make skb header writable before use

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-11 15:10 +0200
Subject[PATCH 3.18 31/39] brcmfmac: Make skb header writable before use
Message-ID<tFW0Y-6HP-81@gated-at.bofh.it>
In reply to#1639409
3.18-stable review patch.  If anyone has any objections, please let me know.

------------------

From: James Hughes <james.hughes@raspberrypi.org>

commit 9cc4b7cb86cbcc6330a3faa8cd65268cd2d3c227 upstream.

The driver was making changes to the skb_header without
ensuring it was writable (i.e. uncloned).
This patch also removes some boiler plate header size
checking/adjustment code as that is also handled by the
skb_cow_header function used to make header writable.

Signed-off-by: James Hughes <james.hughes@raspberrypi.org>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Signed-off-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/net/wireless/brcm80211/brcmfmac/dhd_linux.c |   19 +++++--------------
 1 file changed, 5 insertions(+), 14 deletions(-)

--- a/drivers/net/wireless/brcm80211/brcmfmac/dhd_linux.c
+++ b/drivers/net/wireless/brcm80211/brcmfmac/dhd_linux.c
@@ -213,22 +213,13 @@ static netdev_tx_t brcmf_netdev_start_xm
 		goto done;
 	}
 
-	/* Make sure there's enough room for any header */
-	if (skb_headroom(skb) < drvr->hdrlen) {
-		struct sk_buff *skb2;
-
-		brcmf_dbg(INFO, "%s: insufficient headroom\n",
+	/* Make sure there's enough writable headroom*/
+	ret = skb_cow_head(skb, drvr->hdrlen);
+	if (ret < 0) {
+		brcmf_err("%s: skb_cow_head failed\n",
 			  brcmf_ifname(drvr, ifp->bssidx));
-		drvr->bus_if->tx_realloc++;
-		skb2 = skb_realloc_headroom(skb, drvr->hdrlen);
 		dev_kfree_skb(skb);
-		skb = skb2;
-		if (skb == NULL) {
-			brcmf_err("%s: skb_realloc_headroom failed\n",
-				  brcmf_ifname(drvr, ifp->bssidx));
-			ret = -ENOMEM;
-			goto done;
-		}
+		goto done;
 	}
 
 	/* validate length for ether packet */

[toc] | [prev] | [next] | [standalone]


#1639415 — [PATCH 3.18 26/39] USB: serial: mct_u232: fix modem-status error handling

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-11 15:10 +0200
Subject[PATCH 3.18 26/39] USB: serial: mct_u232: fix modem-status error handling
Message-ID<tFW0Z-6HP-87@gated-at.bofh.it>
In reply to#1639409
3.18-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 36356a669eddb32917fc4b5c2b9b8bf80ede69de upstream.

Make sure to detect short control-message transfers so that errors are
logged when reading the modem status at open.

Note that while this also avoids initialising the modem status using
uninitialised heap data, these bits could not leak to user space as they
are currently not used.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/serial/mct_u232.c |    6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

--- a/drivers/usb/serial/mct_u232.c
+++ b/drivers/usb/serial/mct_u232.c
@@ -322,8 +322,12 @@ static int mct_u232_get_modem_stat(struc
 			MCT_U232_GET_REQUEST_TYPE,
 			0, 0, buf, MCT_U232_GET_MODEM_STAT_SIZE,
 			WDR_TIMEOUT);
-	if (rc < 0) {
+	if (rc < MCT_U232_GET_MODEM_STAT_SIZE) {
 		dev_err(&port->dev, "Get MODEM STATus failed (error = %d)\n", rc);
+
+		if (rc >= 0)
+			rc = -EIO;
+
 		*msr = 0;
 	} else {
 		*msr = buf[0];

[toc] | [prev] | [next] | [standalone]


#1639416 — [PATCH 3.18 03/39] mtd: cfi: reduce stack size

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-11 15:10 +0200
Subject[PATCH 3.18 03/39] mtd: cfi: reduce stack size
Message-ID<tFW0Z-6HP-89@gated-at.bofh.it>
In reply to#1639409
3.18-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnd Bergmann <arnd@arndb.de>

commit d09957fbb4d0b059b3176b510540df69048ad170 upstream.

The cfi_staa_write_buffers function uses a large amount of kernel stack
whenever CONFIG_MTD_MAP_BANK_WIDTH_32 is set, and that results in a
warning on ARM allmodconfig builds:

drivers/mtd/chips/cfi_cmdset_0020.c: In function 'cfi_staa_write_buffers':
drivers/mtd/chips/cfi_cmdset_0020.c:651:1: warning: the frame size of 1208 bytes is larger than 1024 bytes [-Wframe-larger-than=]

It turns out that this is largely a result of a suboptimal implementation
of map_word_andequal(). Replacing this function with a straightforward
one reduces the stack size in this function by exactly 200 bytes,
shrinks the .text segment for this file from 27648 bytes to 26608 bytes,
and makes the warning go away.

Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Brian Norris <computersforpeace@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 include/linux/mtd/map.h |   12 +++++++++++-
 1 file changed, 11 insertions(+), 1 deletion(-)

--- a/include/linux/mtd/map.h
+++ b/include/linux/mtd/map.h
@@ -309,7 +309,17 @@ static inline map_word map_word_or(struc
 	return r;
 }
 
-#define map_word_andequal(m, a, b, z) map_word_equal(m, z, map_word_and(m, a, b))
+static inline int map_word_andequal(struct map_info *map, map_word val1, map_word val2, map_word val3)
+{
+	int i;
+
+	for (i = 0; i < map_words(map); i++) {
+		if ((val1.x[i] & val2.x[i]) != val3.x[i])
+			return 0;
+	}
+
+	return 1;
+}
 
 static inline int map_word_bitsset(struct map_info *map, map_word val1, map_word val2)
 {

[toc] | [prev] | [next] | [standalone]


#1639417 — [PATCH 3.18 06/39] powerpc/powernv: Fix opal_exit tracepoint opcode

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-11 15:20 +0200
Subject[PATCH 3.18 06/39] powerpc/powernv: Fix opal_exit tracepoint opcode
Message-ID<tFWaB-6KK-1@gated-at.bofh.it>
In reply to#1639409
3.18-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Ellerman <mpe@ellerman.id.au>

commit a7e0fb6c2029a780444d09560f739e020d54fe4d upstream.

Currently the opal_exit tracepoint usually shows the opcode as 0:

  <idle>-0     [047] d.h.   635.654292: opal_entry: opcode=63
  <idle>-0     [047] d.h.   635.654296: opal_exit: opcode=0 retval=0
  kopald-1209  [019] d...   636.420943: opal_entry: opcode=10
  kopald-1209  [019] d...   636.420959: opal_exit: opcode=0 retval=0

This is because we incorrectly load the opcode into r0 before calling
__trace_opal_exit(), whereas it expects the opcode in r3 (first function
parameter). In fact we are leaving the retval in r3, so opcode and
retval will always show the same value.

Instead load the opcode into r3, resulting in:

  <idle>-0     [040] d.h.   636.618625: opal_entry: opcode=63
  <idle>-0     [040] d.h.   636.618627: opal_exit: opcode=63 retval=0

Fixes: c49f63530bb6 ("powernv: Add OPAL tracepoints")
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/powerpc/platforms/powernv/opal-wrappers.S |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/powerpc/platforms/powernv/opal-wrappers.S
+++ b/arch/powerpc/platforms/powernv/opal-wrappers.S
@@ -148,7 +148,7 @@ opal_tracepoint_entry:
 opal_tracepoint_return:
 	std	r3,STK_REG(R31)(r1)
 	mr	r4,r3
-	ld	r0,STK_REG(R23)(r1)
+	ld	r3,STK_REG(R23)(r1)
 	bl	__trace_opal_exit
 	ld	r3,STK_REG(R31)(r1)
 	addi	r1,r1,STACKFRAMESIZE

[toc] | [prev] | [next] | [standalone]


#1639419 — [PATCH 3.18 05/39] cpupower: Fix turbo frequency reporting for pre-Sandy Bridge cores

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-11 15:20 +0200
Subject[PATCH 3.18 05/39] cpupower: Fix turbo frequency reporting for pre-Sandy Bridge cores
Message-ID<tFWaC-6KK-7@gated-at.bofh.it>
In reply to#1639409
3.18-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ben Hutchings <ben@decadent.org.uk>

commit 4cca0457686e4ee1677d69469e4ddfd94d389a80 upstream.

The switch that conditionally sets CPUPOWER_CAP_HAS_TURBO_RATIO and
CPUPOWER_CAP_IS_SNB flags is missing a break, so all cores get both
flags set and an assumed base clock of 100 MHz for turbo values.

Reported-by: GSR <gsr.bugs@infernal-iceberg.com>
Tested-by: GSR <gsr.bugs@infernal-iceberg.com>
References: https://bugs.debian.org/859978
Fixes: 8fb2e440b223 (cpupower: Show Intel turbo ratio support via ...)
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 tools/power/cpupower/utils/helpers/cpuid.c |    1 +
 1 file changed, 1 insertion(+)

--- a/tools/power/cpupower/utils/helpers/cpuid.c
+++ b/tools/power/cpupower/utils/helpers/cpuid.c
@@ -156,6 +156,7 @@ out:
 					 */
 			case 0x2C:	/* Westmere EP - Gulftown */
 				cpu_info->caps |= CPUPOWER_CAP_HAS_TURBO_RATIO;
+				break;
 			case 0x2A:	/* SNB */
 			case 0x2D:	/* SNB Xeon */
 			case 0x3A:	/* IVB */

[toc] | [prev] | [next] | [standalone]


#1639420 — [PATCH 3.18 09/39] ARM: OMAP5 / DRA7: Fix HYP mode boot for thumb2 build

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-11 15:20 +0200
Subject[PATCH 3.18 09/39] ARM: OMAP5 / DRA7: Fix HYP mode boot for thumb2 build
Message-ID<tFWaC-6KK-5@gated-at.bofh.it>
In reply to#1639409
3.18-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matthijs van Duin <matthijsvanduin@gmail.com>

commit 448c077eeb02240c430db2a2c3bf5285a4c65d66 upstream.

'adr' yields a data-pointer, not a function-pointer.

Fixes: 999f934de195 ("ARM: omap5/dra7xx: Enable booting secondary
CPU in HYP mode")
Signed-off-by: Matthijs van Duin <matthijsvanduin@gmail.com>
Signed-off-by: Tony Lindgren <tony@atomide.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/arm/mach-omap2/omap-headsmp.S |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/arch/arm/mach-omap2/omap-headsmp.S
+++ b/arch/arm/mach-omap2/omap-headsmp.S
@@ -17,6 +17,7 @@
 
 #include <linux/linkage.h>
 #include <linux/init.h>
+#include <asm/assembler.h>
 
 #include "omap44xx.h"
 
@@ -56,7 +57,7 @@ wait_2:	ldr	r2, =AUX_CORE_BOOT0_PA	@ rea
 	cmp	r0, r4
 	bne	wait_2
 	ldr	r12, =API_HYP_ENTRY
-	adr	r0, hyp_boot
+	badr	r0, hyp_boot
 	smc	#0
 hyp_boot:
 	b	secondary_startup

[toc] | [prev] | [next] | [standalone]


#1639421 — [PATCH 3.18 20/39] USB: serial: ssu100: fix control-message error handling

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-11 15:20 +0200
Subject[PATCH 3.18 20/39] USB: serial: ssu100: fix control-message error handling
Message-ID<tFWaC-6KK-17@gated-at.bofh.it>
In reply to#1639409
3.18-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 1eac5c244f705182d1552a53e2f74e2775ed95d6 upstream.

Make sure to detect short control-message transfers rather than continue
with zero-initialised data when retrieving modem status and during
device initialisation.

Fixes: 52af95459939 ("USB: add USB serial ssu100 driver")
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/serial/ssu100.c |   31 ++++++++++++++++++++++++-------
 1 file changed, 24 insertions(+), 7 deletions(-)

--- a/drivers/usb/serial/ssu100.c
+++ b/drivers/usb/serial/ssu100.c
@@ -80,9 +80,17 @@ static inline int ssu100_setdevice(struc
 
 static inline int ssu100_getdevice(struct usb_device *dev, u8 *data)
 {
-	return usb_control_msg(dev, usb_rcvctrlpipe(dev, 0),
-			       QT_SET_GET_DEVICE, 0xc0, 0, 0,
-			       data, 3, 300);
+	int ret;
+
+	ret = usb_control_msg(dev, usb_rcvctrlpipe(dev, 0),
+			      QT_SET_GET_DEVICE, 0xc0, 0, 0,
+			      data, 3, 300);
+	if (ret < 3) {
+		if (ret >= 0)
+			ret = -EIO;
+	}
+
+	return ret;
 }
 
 static inline int ssu100_getregister(struct usb_device *dev,
@@ -90,10 +98,17 @@ static inline int ssu100_getregister(str
 				     unsigned short reg,
 				     u8 *data)
 {
-	return usb_control_msg(dev, usb_rcvctrlpipe(dev, 0),
-			       QT_SET_GET_REGISTER, 0xc0, reg,
-			       uart, data, sizeof(*data), 300);
+	int ret;
 
+	ret = usb_control_msg(dev, usb_rcvctrlpipe(dev, 0),
+			      QT_SET_GET_REGISTER, 0xc0, reg,
+			      uart, data, sizeof(*data), 300);
+	if (ret < sizeof(*data)) {
+		if (ret >= 0)
+			ret = -EIO;
+	}
+
+	return ret;
 }
 
 
@@ -289,8 +304,10 @@ static int ssu100_open(struct tty_struct
 				 QT_OPEN_CLOSE_CHANNEL,
 				 QT_TRANSFER_IN, 0x01,
 				 0, data, 2, 300);
-	if (result < 0) {
+	if (result < 2) {
 		dev_dbg(&port->dev, "%s - open failed %i\n", __func__, result);
+		if (result >= 0)
+			result = -EIO;
 		kfree(data);
 		return result;
 	}

[toc] | [prev] | [next] | [standalone]


#1639422 — [PATCH 3.18 08/39] power: supply: bq24190_charger: Call set_mode_host() on pm_resume()

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-11 15:20 +0200
Subject[PATCH 3.18 08/39] power: supply: bq24190_charger: Call set_mode_host() on pm_resume()
Message-ID<tFWaC-6KK-15@gated-at.bofh.it>
In reply to#1639409
3.18-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Liam Breck <liam@networkimprov.net>

commit e05ad7e0741ce0505e1df157c62b22b95172bb97 upstream.

pm_resume() does a register_reset() which clears charger host mode.

Fix by calling set_mode_host() after the reset.

Fixes: d7bf353fd0aa3 ("bq24190_charger: Add support for TI BQ24190 Battery Charger")
Signed-off-by: Liam Breck <kernel@networkimprov.net>
Acked-by: Mark Greer <mgreer@animalcreek.com>
Acked-by: Tony Lindgren <tony@atomide.com>
Signed-off-by: Sebastian Reichel <sre@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/power/bq24190_charger.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/power/bq24190_charger.c
+++ b/drivers/power/bq24190_charger.c
@@ -1496,6 +1496,7 @@ static int bq24190_pm_resume(struct devi
 
 	pm_runtime_get_sync(bdi->dev);
 	bq24190_register_reset(bdi);
+	bq24190_set_mode_host(bdi);
 	pm_runtime_put_sync(bdi->dev);
 
 	/* Things may have changed while suspended so alert upper layer */

[toc] | [prev] | [next] | [standalone]


#1640050

FromGuenter Roeck <linux@roeck-us.net>
Date2017-05-11 23:20 +0200
Message-ID<tG3F7-3bi-3@gated-at.bofh.it>
In reply to#1639409
On Thu, May 11, 2017 at 03:02:35PM +0200, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 3.18.53 release.
> There are 39 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Sat May 13 13:02:15 UTC 2017.
> Anything received after that time might be too late.
> 

c39a78443b01 ("ARM: OMAP5 / DRA7: Fix HYP mode boot for thumb2 build") results
in

Error log:
arch/arm/mach-omap2/omap-headsmp.S: Assembler messages:
arch/arm/mach-omap2/omap-headsmp.S:60: Error: bad instruction `badr r0,hyp_boot'

with arm:allmodconfig, arm:multi_v7_defconfig and arm:omap2plus_defconfig.
I see "badr" used in later kernels, but not in v3.18. Does this possibly
require some secondary patches ? Copying the author.

Guenter

[toc] | [prev] | [next] | [standalone]


#1640059

FromMatthijs van Duin <matthijsvanduin@gmail.com>
Date2017-05-11 23:40 +0200
Message-ID<tG3Yt-3hN-7@gated-at.bofh.it>
In reply to#1640050
On Thu, May 11, 2017 at 02:16:07PM -0700, Guenter Roeck wrote:
> arch/arm/mach-omap2/omap-headsmp.S:60: Error: bad instruction `badr r0,hyp_boot'
> 
> I see "badr" used in later kernels, but not in v3.18. Does this possibly
> require some secondary patches ?

It was introduced in kernel 4.2 by
	14327c662822 "ARM: replace BSYM() with badr assembly macro"

The correct backport would therefore just be:

-	adr	r0, hyp_boot
+	adr	r0, BSYM(hyp_boot)

Right?

[toc] | [prev] | [next] | [standalone]


#1640064

FromTony Lindgren <tony@atomide.com>
Date2017-05-11 23:50 +0200
Message-ID<tG489-3lp-5@gated-at.bofh.it>
In reply to#1640059
* Matthijs van Duin <matthijsvanduin@gmail.com> [170511 14:34]:
> On Thu, May 11, 2017 at 02:16:07PM -0700, Guenter Roeck wrote:
> > arch/arm/mach-omap2/omap-headsmp.S:60: Error: bad instruction `badr r0,hyp_boot'
> > 
> > I see "badr" used in later kernels, but not in v3.18. Does this possibly
> > require some secondary patches ?
> 
> It was introduced in kernel 4.2 by
> 	14327c662822 "ARM: replace BSYM() with badr assembly macro"
> 
> The correct backport would therefore just be:
> 
> -	adr	r0, hyp_boot
> +	adr	r0, BSYM(hyp_boot)
> 
> Right?

Or just skip this for v3.18 until somebody actually needs thumb
kernel with hypervisor and can provide a Tested-by.

Regards,

Tony

[toc] | [prev] | [next] | [standalone]


#1640351

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-12 11:40 +0200
Message-ID<tGfdf-2rg-5@gated-at.bofh.it>
In reply to#1640064
On Thu, May 11, 2017 at 02:46:37PM -0700, Tony Lindgren wrote:
> * Matthijs van Duin <matthijsvanduin@gmail.com> [170511 14:34]:
> > On Thu, May 11, 2017 at 02:16:07PM -0700, Guenter Roeck wrote:
> > > arch/arm/mach-omap2/omap-headsmp.S:60: Error: bad instruction `badr r0,hyp_boot'
> > > 
> > > I see "badr" used in later kernels, but not in v3.18. Does this possibly
> > > require some secondary patches ?
> > 
> > It was introduced in kernel 4.2 by
> > 	14327c662822 "ARM: replace BSYM() with badr assembly macro"
> > 
> > The correct backport would therefore just be:
> > 
> > -	adr	r0, hyp_boot
> > +	adr	r0, BSYM(hyp_boot)
> > 
> > Right?
> 
> Or just skip this for v3.18 until somebody actually needs thumb
> kernel with hypervisor and can provide a Tested-by.

Ok, I'll drop this patch for now, it was added to fix a build warning
that Arnd found.  I'll wait for a proper backport if people really get
annoyed by it :)

thanks,

greg k-h

[toc] | [prev] | [next] | [standalone]


#1640379

FromArnd Bergmann <arnd@arndb.de>
Date2017-05-12 12:20 +0200
Message-ID<tGfPX-2XQ-9@gated-at.bofh.it>
In reply to#1640351
On Fri, May 12, 2017 at 11:37 AM, Greg Kroah-Hartman
<gregkh@linuxfoundation.org> wrote:
> On Thu, May 11, 2017 at 02:46:37PM -0700, Tony Lindgren wrote:
>> * Matthijs van Duin <matthijsvanduin@gmail.com> [170511 14:34]:
>> > On Thu, May 11, 2017 at 02:16:07PM -0700, Guenter Roeck wrote:
>> > > arch/arm/mach-omap2/omap-headsmp.S:60: Error: bad instruction `badr r0,hyp_boot'
>> > >
>> > > I see "badr" used in later kernels, but not in v3.18. Does this possibly
>> > > require some secondary patches ?
>> >
>> > It was introduced in kernel 4.2 by
>> >     14327c662822 "ARM: replace BSYM() with badr assembly macro"
>> >
>> > The correct backport would therefore just be:
>> >
>> > -   adr     r0, hyp_boot
>> > +   adr     r0, BSYM(hyp_boot)
>> >
>> > Right?
>>
>> Or just skip this for v3.18 until somebody actually needs thumb
>> kernel with hypervisor and can provide a Tested-by.
>
> Ok, I'll drop this patch for now, it was added to fix a build warning
> that Arnd found.  I'll wait for a proper backport if people really get
> annoyed by it :)

Are you sure it was one of mine? While it seems like an important
fix, I don't remember seeing it and it doesn't look like a warning fix
but a boot regression.

If I did send you this commit ID, it was probably a mistake on my
end, but then I'd like to find out where I went wrong.

      Arnd

[toc] | [prev] | [next] | [standalone]


#1640387

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-12 12:50 +0200
Message-ID<tGgiZ-3aJ-9@gated-at.bofh.it>
In reply to#1640379
On Fri, May 12, 2017 at 12:15:10PM +0200, Arnd Bergmann wrote:
> On Fri, May 12, 2017 at 11:37 AM, Greg Kroah-Hartman
> <gregkh@linuxfoundation.org> wrote:
> > On Thu, May 11, 2017 at 02:46:37PM -0700, Tony Lindgren wrote:
> >> * Matthijs van Duin <matthijsvanduin@gmail.com> [170511 14:34]:
> >> > On Thu, May 11, 2017 at 02:16:07PM -0700, Guenter Roeck wrote:
> >> > > arch/arm/mach-omap2/omap-headsmp.S:60: Error: bad instruction `badr r0,hyp_boot'
> >> > >
> >> > > I see "badr" used in later kernels, but not in v3.18. Does this possibly
> >> > > require some secondary patches ?
> >> >
> >> > It was introduced in kernel 4.2 by
> >> >     14327c662822 "ARM: replace BSYM() with badr assembly macro"
> >> >
> >> > The correct backport would therefore just be:
> >> >
> >> > -   adr     r0, hyp_boot
> >> > +   adr     r0, BSYM(hyp_boot)
> >> >
> >> > Right?
> >>
> >> Or just skip this for v3.18 until somebody actually needs thumb
> >> kernel with hypervisor and can provide a Tested-by.
> >
> > Ok, I'll drop this patch for now, it was added to fix a build warning
> > that Arnd found.  I'll wait for a proper backport if people really get
> > annoyed by it :)
> 
> Are you sure it was one of mine? While it seems like an important
> fix, I don't remember seeing it and it doesn't look like a warning fix
> but a boot regression.
> 
> If I did send you this commit ID, it was probably a mistake on my
> end, but then I'd like to find out where I went wrong.

Ok, no, this was my fault, it came from a list of patches I was digging
through that went into 4.11 to see if they were applicable to older
kernels as well.

sorry for the noise,

greg k-h

[toc] | [prev] | [next] | [standalone]


#1640539

FromShuah Khan <shuahkh@osg.samsung.com>
Date2017-05-12 17:30 +0200
Message-ID<tGkFY-6vb-11@gated-at.bofh.it>
In reply to#1639409
On 05/11/2017 07:02 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 3.18.53 release.
> There are 39 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Sat May 13 13:02:15 UTC 2017.
> Anything received after that time might be too late.
> 
> The whole patch series can be found in one patch at:
> 	kernel.org/pub/linux/kernel/v3.x/stable-review/patch-3.18.53-rc1.gz
> or in the git tree and branch at:
>   git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-3.18.y
> and the diffstat can be found below.
> 
> thanks,
> 
> greg k-h
> 

Compiled and booted on my test system. No dmesg regressions.

thanks,
-- Shuah

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.kernel


csiph-web