Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1660349 > unrolled thread

[PATCH 3.10 000/250] 3.10.106-stable review

Started byWilly Tarreau <w@1wt.eu>
First post2017-06-08 01:10 +0200
Last post2017-06-08 06:30 +0200
Articles 20 on this page of 214 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.10 000/250] 3.10.106-stable review Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 188/250] uwb: hwa-rc: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 167/250] USB: serial: io_ti: fix NULL-deref in interrupt callback Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 136/250] mfd: pm8921: Potential NULL dereference in pm8921_remove() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 099/250] ubifs: Fix journal replay wrt. xattr nodes Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 102/250] arm64/ptrace: Reject attempts to set incomplete hardware breakpoint fields Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 223/250] Staging: vt6655-6: potential NULL dereference in hostap_disable_hostapd() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 006/250] KVM: x86: Introduce segmented_write_std Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 181/250] Input: hanwang - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 049/250] USB: serial: io_edgeport: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 090/250] powerpc/ibmebus: Fix further device reference leaks Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 172/250] net: net_enable_timestamp() can be called from irq contexts Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 159/250] USB: serial: digi_acceleport: fix OOB data sanity check Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 139/250] vti4: Don't count header length twice. Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 178/250] net: properly release sk_frag.page Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 229/250] USB: dummy-hcd: fix bug in stop_activity (handle ep0) Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 123/250] packet: fix races in fanout_add() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 135/250] ocfs2: do not write error flag to user structure we cannot copy from/to Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 107/250] drm/i915: Don't leak edid in intel_crt_detect_ddc() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 116/250] drm/i915: fix use-after-free in page_flip_completed() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 202/250] metag/usercopy: Fix alignment error checking Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 236/250] ipv6: fix ip6_tnl_parse_tlv_enc_lim() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 134/250] goldfish: Sanitize the broken interrupt handler Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 234/250] xc2028: unlock on error in xc2028_set_config() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 158/250] dm: flush queued bios when process blocks to avoid deadlock Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 013/250] xfrm_user: validate XFRM_MSG_NEWAE incoming ESN size harder Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 120/250] ip6_gre: fix ip6gre_err() invalid reads Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 160/250] USB: serial: digi_acceleport: fix OOB-event processing Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 217/250] net: phy: handle state correctly in phy_stop_machine Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 062/250] staging: iio: ad7606: fix improper setting of oversampling pins Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 016/250] KEYS: fix keyctl_set_reqkey_keyring() to not leak thread keyrings Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 197/250] USB: OHCI: Fix race between ED unlink and URB submission Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 100/250] arm64/ptrace: Preserve previous registers for short regset write Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 133/250] x86/platform/goldfish: Prevent unconditional loading Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 220/250] ARM: dts: imx31: move CCM device node to AIPS2 bus devices Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 075/250] gro: Enter slow-path if there is no tailroom Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 083/250] USB: serial: ch341: fix open error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 230/250] mm/init: fix zone boundary creation Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 204/250] metag/usercopy: Set flags before ADDZ Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 149/250] scsi: aacraid: Reorder Adapter status check Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 101/250] arm64/ptrace: Avoid uninitialised struct padding in fpr_set() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 046/250] USB: serial: iuu_phoenix: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 026/250] ext4: fix stack memory corruption with 64k block size Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 012/250] xfrm_user: validate XFRM_MSG_NEWAE XFRMA_REPLAY_ESN_VAL replay_window Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 201/250] ring-buffer: Fix return value check in test_ringbuffer() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 091/250] powerpc/ibmebus: Fix device reference leaks in sysfs interface Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 118/250] ipv4: keep skb->dst around in presence of IP options Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 113/250] ARM: 8643/3: arm/ptrace: Preserve previous registers for short regset write Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 020/250] hotplug: Make register and unregister notifier API symmetric Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 156/250] ktest: Fix child exit code processing Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 078/250] powerpc: Fix build warning on 32-bit PPC Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 103/250] ARM: ux500: fix prcmu_is_cpu_in_wfi() calculation Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 060/250] ALSA: usb-audio: Fix bogus error return in snd_usb_create_stream() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 147/250] MIPS: Handle microMIPS jumps in the same way as MIPS32/MIPS64 jumps Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 036/250] IB/multicast: Check ib_find_pkey() return value Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 073/250] net, sched: fix soft lockup in tc_classify Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 173/250] dccp/tcp: fix routing redirect race Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 087/250] USB: serial: ch341: fix modem-control and B0 handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 203/250] metag/usercopy: Add early abort to copy_to_user Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 063/250] usb: dwc3: gadget: always unmap EP0 requests Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 094/250] perf scripting: Avoid leaking the scripting_context variable Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 219/250] MIPS: KGDB: Use kernel context for sleeping threads Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 132/250] USB: serial: ark3116: fix register-accessor error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 130/250] USB: serial: spcp8x5: fix modem-status handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 227/250] ping: implement proper locking Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 092/250] IB/mlx4: Set traffic class in AH Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 040/250] USB: serial: quatech2: fix sleep-while-atomic in close Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 187/250] uwb: i1480-dfu: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 242/250] kvm: exclude ioeventfd from counting kvm_io_range limit Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 222/250] tun: Fix TUN_PKT_STRIP setting Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 068/250] scsi: mvsas: fix command_active typo Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 207/250] s390/decompressor: fix initrd corruption caused by bss clear Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 161/250] MIPS: ip27: Disable qlge driver in defconfig Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 104/250] ite-cir: initialize use_demodulator before using it Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 228/250] USB: fix problems with duplicate endpoint addresses Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 143/250] MIPS: Prevent unaligned accesses during stack unwinding Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 208/250] net/mlx4_en: Fix bad WQE issue Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 119/250] netlabel: out of bound access in cipso_v4_validate() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 065/250] hwmon: (ds620) Fix overflows seen when writing temperature limits Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 162/250] tracing: Add #undef to fix compile error Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 177/250] xen: do not re-use pirq number cached in pci device msi msg data Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 144/250] MIPS: Fix get_frame_info() handling of microMIPS function size Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 237/250] ipv6: pointer math error in ip6_tnl_parse_tlv_enc_lim() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 216/250] netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT" failed in 64bit kernel Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 193/250] ALSA: ctxfi: Fix the incorrect check of dma_set_mask() call Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 206/250] metag/usercopy: Add missing fixups Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 225/250] perf trace: Use the syscall raw_syscalls:sys_enter timestamp Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 072/250] ser_gigaset: return -ENOMEM on error instead of success Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 051/250] USB: serial: cyberjack: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 155/250] IB/ipoib: Fix deadlock between rmmod and set_mode Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 175/250] perf/core: Fix event inheritance on fork() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 211/250] powerpc: Disable HFSCR[TM] if TM is not supported Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 192/250] ALSA: ctxfi: Fallback DMA mask to 32bit Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 232/250] Drivers: hv: avoid vfree() on crash Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 249/250] dccp/tcp: do not inherit mc_list from parent Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 033/250] scsi: zfcp: fix rport unblock race with LUN recovery Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 171/250] locking/static_keys: Add static_key_{en,dis}able() helpers Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 096/250] svcrpc: don't leak contexts on PROC_DESTROY Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 055/250] USB: serial: mos7720: fix use-after-free on probe errors Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 125/250] net: socket: fix recvmmsg not returning error from sock_error Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 039/250] USB: serial: omninet: fix NULL-derefs at open and disconnect Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 117/250] net: use a work queue to defer net_disable_timestamp() work Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 077/250] gro: Disable frag0 optimization on IPv6 ext headers Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 064/250] cris: Only build flash rescue image if CONFIG_ETRAX_AXISFLASHMAP is selected Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 110/250] net: fix harmonize_features() vs NETIF_F_HIGHDMA Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 180/250] Input: ims-pcu - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 244/250] TTY: n_hdlc, fix lockdep false positive Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 235/250] xc2028: Fix use-after-free bug properly Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 148/250] uvcvideo: Fix a wrong macro Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 004/250] libceph: don't set weight to IN when OSD is destroyed Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 200/250] ptrace: fix PTRACE_LISTEN race corrupting task->state Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 250/250] char: lp: fix possible integer overflow in lp_setup() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 239/250] sctp: avoid BUG_ON on sctp_wait_for_sndbuf Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 080/250] mm/hugetlb.c: fix reservation race when freeing surplus pages Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 041/250] USB: serial: pl2303: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 168/250] USB: serial: io_ti: fix information leak in completion handler Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 233/250] xc2028: avoid use after free Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 122/250] l2tp: do not use udp_ioctl() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 146/250] MIPS: Calculate microMIPS ra properly when unwinding the stack Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 048/250] USB: serial: ti_usb_3410_5052: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 231/250] can: Fix kernel panic at security_sock_rcv_skb Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 182/250] Input: yealink - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 183/250] Input: cm109 - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 240/250] sctp: deny peeloff operation on asocs with threads sleeping on it Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 176/250] isdn/gigaset: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 052/250] USB: serial: kobil_sct: fix NULL-deref in write Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 153/250] NFSv4: fix getacl head length estimation Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 082/250] USB: serial: ch341: fix initial modem-control state Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 190/250] ext4: mark inode dirty after converting inline directory Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 086/250] USB: serial: ch341: fix resume after reset Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 127/250] USB: serial: ftdi_sio: fix modem-status error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 218/250] l2tp: take reference on sessions being dumped Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 015/250] KEYS: Change the name of the dead type to ".dead" to prevent user access Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 198/250] i2c: at91: manage unexpected RXRDY flag when starting a transfer Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 021/250] Btrfs: fix tree search logic when replaying directory entry deletes Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 034/250] ftrace/x86_32: Set ftrace_stub to weak to prevent gcc from using short jumps to it Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 184/250] USB: uss720: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 005/250] KVM: x86: fix emulation of "MOV SS, null selector" Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 151/250] fuse: add missing FR_FORCE Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 154/250] s390/qdio: clear DSCI prior to scanning multiple input queues Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 224/250] net: sctp: rework multihoming retransmission path selection to rfc4960 Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 247/250] fs: exec: apply CLOEXEC before changing dumpable task flags Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 191/250] scsi: libsas: fix ata xfer length Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 032/250] scsi: zfcp: do not trace pure benign residual HBA responses at default level Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 088/250] x86/cpu: Fix bootup crashes by sanitizing the argument of the 'clearcpuid=' command-line option Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 189/250] mmc: ushc: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 141/250] MIPS: OCTEON: Fix copy_from_user fault handling for large buffers Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 108/250] s5k4ecgx: select CRC32 helper Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 150/250] ath9k: use correct OTP register offsets for the AR9340 and AR9550 Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 124/250] packet: Do not call fanout_release from atomic contexts Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 152/250] RDMA/core: Fix incorrect structure packing for booleans Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 076/250] gro: use min_t() in skb_gro_reset_offset() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 105/250] fuse: do not use iocb after it may have been freed Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 245/250] tty: n_hdlc: get rid of racy n_hdlc.tbuf Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 067/250] iommu/amd: Fix the left value check of cmd buffer Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 164/250] USB: serial: omninet: fix reference leaks at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 140/250] net/sched: em_meta: Fix 'meta vlan' to correctly recognize zero VID frames Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 029/250] f2fs: set ->owner for debugfs status file's file_operations Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 058/250] usb: xhci-mem: use passed in GFP flags instead of GFP_KERNEL Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 031/250] scsi: zfcp: fix use-after-"free" in FC ingress path after TMF Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 023/250] block_dev: don't test bdev->bd_contains when it is not stable Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 157/250] nlm: Ensure callback code also checks that the files match Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 089/250] NFSv4.1: nfs4_fl_prepare_ds must be careful about reporting success. Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 209/250] net/mlx4_core: Fix racy CQ (Completion Queue) free Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 112/250] svcrpc: fix oops in absence of krb5 module Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
      Re: [PATCH 3.10 112/250] svcrpc: fix oops in absence of krb5 module Simo Sorce <simo@redhat.com> - 2017-06-08 10:20 +0200
    [PATCH 3.10 114/250] mac80211: Fix adding of mesh vendor IEs Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 246/250] ipv6: handle -EFAULT from skb_copy_bits Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 138/250] net: 6lowpan: fix lowpan_header_create non-compression memcpy call Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 059/250] usb: musb: Fix trying to free already-free IRQ 4 Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 137/250] drm/nv50/disp: min/max are reversed in nv50_crtc_gamma_set() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 097/250] mmc: mxs-mmc: Fix additional cycles after transmission stop Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 205/250] metag/usercopy: Fix src fixup in from user rapf loops Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 165/250] USB: iowarrior: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 131/250] USB: serial: opticon: fix CTS retrieval at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 215/250] ring-buffer: Have ring_buffer_iter_empty() return true when empty Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 098/250] mtd: nand: xway: disable module support Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 044/250] USB: serial: io_ti: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 212/250] pegasus: Use heap buffers for all register access Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 214/250] tracing: Allocate the snapshot buffer before enabling probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 106/250] crypto: caam - fix non-hmac hashes Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 169/250] vxlan: correctly validate VXLAN ID against VXLAN_N_VID Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 002/250] crypto: crypto_memneq - add equality testing of memory regions w/o timing leaks Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 071/250] powerpc/pci/rpadlpar: Fix device reference leaks Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 194/250] ACPI / PNP: Avoid conflicting resource reservations Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 047/250] USB: serial: garmin_gps: fix memory leak on failed URB submit Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 018/250] locking/rtmutex: Prevent dequeue vs. unlock race Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 195/250] ACPI / resources: free memory on error in add_region_before() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 179/250] net: unix: properly re-increment inflight counter of GC discarded candidates Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 054/250] USB: serial: mos7720: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 074/250] net: stmmac: Fix race between stmmac_drv_probe and stmmac_open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 042/250] USB: serial: keyspan_pda: verify endpoints at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 028/250] ext4: return -ENOMEM instead of success Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 038/250] usb: gadget: composite: Test get_alt() presence instead of set_alt() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 017/250] ext4: fix data exposure after a crash Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 025/250] ext4: fix mballoc breakage with 64k block size Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 030/250] block: protect iterate_bdevs() against concurrent close Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 111/250] tcp: initialize max window for a new fastopen socket Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 009/250] fbdev: color map copying bounds checking Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 126/250] USB: serial: mos7840: fix another NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 035/250] IB/mad: Fix an array index check Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 050/250] USB: serial: oti6858: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 001/250] packet: fix race condition in packet_set_ring Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 081/250] USB: serial: kl5kusb105: fix line-state error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 079/250] Input: i8042 - add Pegatron touchpad to noloop table Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 037/250] powerpc: Convert cmp to cmpd in idle enter sequence Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 061/250] USB: serial: kl5kusb105: abort on open exception path Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 024/250] crypto: caam - fix AEAD givenc descriptors Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 010/250] selinux: fix off-by-one in setprocattr Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 043/250] USB: serial: spcp8x5: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 142/250] MIPS: Clear ISA bit correctly in get_frame_info() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 019/250] m68k: Fix ndelay() macro Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    Re: [PATCH 3.10 000/250] 3.10.106-stable review Guenter Roeck <linux@roeck-us.net> - 2017-06-08 02:40 +0200
      Re: [PATCH 3.10 000/250] 3.10.106-stable review Willy Tarreau <w@1wt.eu> - 2017-06-08 06:30 +0200

Page 6 of 11 — ← Prev page 1 … 4 5 [6] 7 8 … 11  Next page →


#1660488 — [PATCH 3.10 039/250] USB: serial: omninet: fix NULL-derefs at open and disconnect

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 039/250] USB: serial: omninet: fix NULL-derefs at open and disconnect
Message-ID<tPSS5-4Tk-13@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit a5bc01949e3b19d8a23b5eabc6fc71bb50dc820e upstream.

Fix NULL-pointer dereferences at open() and disconnect() should the
device lack the expected bulk-out endpoints:

Unable to handle kernel NULL pointer dereference at virtual address 000000b4
...
[c0170ff0>] (__lock_acquire) from [<c0172f00>] (lock_acquire+0x108/0x264)
[<c0172f00>] (lock_acquire) from [<c06a5090>] (_raw_spin_lock_irqsave+0x58/0x6c)
[<c06a5090>] (_raw_spin_lock_irqsave) from [<c0470684>] (tty_port_tty_set+0x28/0xa4)
[<c0470684>] (tty_port_tty_set) from [<bf08d384>] (omninet_open+0x30/0x40 [omninet])
[<bf08d384>] (omninet_open [omninet]) from [<bf07c118>] (serial_port_activate+0x68/0x98 [usbserial])

Unable to handle kernel NULL pointer dereference at virtual address 00000234
...
[<bf01f418>] (omninet_disconnect [omninet]) from [<bf0016c0>] (usb_serial_disconnect+0xe4/0x100 [usbserial])

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/serial/omninet.c | 13 +++++++++++++
 1 file changed, 13 insertions(+)

diff --git a/drivers/usb/serial/omninet.c b/drivers/usb/serial/omninet.c
index 5739bf6..24720f6 100644
--- a/drivers/usb/serial/omninet.c
+++ b/drivers/usb/serial/omninet.c
@@ -39,6 +39,7 @@ static int  omninet_write(struct tty_struct *tty, struct usb_serial_port *port,
 				const unsigned char *buf, int count);
 static int  omninet_write_room(struct tty_struct *tty);
 static void omninet_disconnect(struct usb_serial *serial);
+static int omninet_attach(struct usb_serial *serial);
 static int omninet_port_probe(struct usb_serial_port *port);
 static int omninet_port_remove(struct usb_serial_port *port);
 
@@ -57,6 +58,7 @@ static struct usb_serial_driver zyxel_omninet_device = {
 	.description =		"ZyXEL - omni.net lcd plus usb",
 	.id_table =		id_table,
 	.num_ports =		1,
+	.attach =		omninet_attach,
 	.port_probe =		omninet_port_probe,
 	.port_remove =		omninet_port_remove,
 	.open =			omninet_open,
@@ -105,6 +107,17 @@ struct omninet_data {
 	__u8	od_outseq;	/* Sequence number for bulk_out URBs */
 };
 
+static int omninet_attach(struct usb_serial *serial)
+{
+	/* The second bulk-out endpoint is used for writing. */
+	if (serial->num_bulk_out < 2) {
+		dev_err(&serial->interface->dev, "missing endpoints\n");
+		return -ENODEV;
+	}
+
+	return 0;
+}
+
 static int omninet_port_probe(struct usb_serial_port *port)
 {
 	struct omninet_data *od;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660489 — [PATCH 3.10 117/250] net: use a work queue to defer net_disable_timestamp() work

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 117/250] net: use a work queue to defer net_disable_timestamp() work
Message-ID<tPSS6-4Tk-17@gated-at.bofh.it>
In reply to#1660349
From: Eric Dumazet <edumazet@google.com>

commit 5fa8bbda38c668e56b0c6cdecced2eac2fe36dec upstream.

Dmitry reported a warning [1] showing that we were calling
net_disable_timestamp() -> static_key_slow_dec() from a non
process context.

Grabbing a mutex while holding a spinlock or rcu_read_lock()
is not allowed.

As Cong suggested, we now use a work queue.

It is possible netstamp_clear() exits while netstamp_needed_deferred
is not zero, but it is probably not worth trying to do better than that.

netstamp_needed_deferred atomic tracks the exact number of deferred
decrements.

[1]
[ INFO: suspicious RCU usage. ]
4.10.0-rc5+ #192 Not tainted
-------------------------------
./include/linux/rcupdate.h:561 Illegal context switch in RCU read-side
critical section!

other info that might help us debug this:

rcu_scheduler_active = 2, debug_locks = 0
2 locks held by syz-executor14/23111:
 #0:  (sk_lock-AF_INET6){+.+.+.}, at: [<ffffffff83a35c35>] lock_sock
include/net/sock.h:1454 [inline]
 #0:  (sk_lock-AF_INET6){+.+.+.}, at: [<ffffffff83a35c35>]
rawv6_sendmsg+0x1e65/0x3ec0 net/ipv6/raw.c:919
 #1:  (rcu_read_lock){......}, at: [<ffffffff83ae2678>] nf_hook
include/linux/netfilter.h:201 [inline]
 #1:  (rcu_read_lock){......}, at: [<ffffffff83ae2678>]
__ip6_local_out+0x258/0x840 net/ipv6/output_core.c:160

stack backtrace:
CPU: 2 PID: 23111 Comm: syz-executor14 Not tainted 4.10.0-rc5+ #192
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs
01/01/2011
Call Trace:
 __dump_stack lib/dump_stack.c:15 [inline]
 dump_stack+0x2ee/0x3ef lib/dump_stack.c:51
 lockdep_rcu_suspicious+0x139/0x180 kernel/locking/lockdep.c:4452
 rcu_preempt_sleep_check include/linux/rcupdate.h:560 [inline]
 ___might_sleep+0x560/0x650 kernel/sched/core.c:7748
 __might_sleep+0x95/0x1a0 kernel/sched/core.c:7739
 mutex_lock_nested+0x24f/0x1730 kernel/locking/mutex.c:752
 atomic_dec_and_mutex_lock+0x119/0x160 kernel/locking/mutex.c:1060
 __static_key_slow_dec+0x7a/0x1e0 kernel/jump_label.c:149
 static_key_slow_dec+0x51/0x90 kernel/jump_label.c:174
 net_disable_timestamp+0x3b/0x50 net/core/dev.c:1728
 sock_disable_timestamp+0x98/0xc0 net/core/sock.c:403
 __sk_destruct+0x27d/0x6b0 net/core/sock.c:1441
 sk_destruct+0x47/0x80 net/core/sock.c:1460
 __sk_free+0x57/0x230 net/core/sock.c:1468
 sock_wfree+0xae/0x120 net/core/sock.c:1645
 skb_release_head_state+0xfc/0x200 net/core/skbuff.c:655
 skb_release_all+0x15/0x60 net/core/skbuff.c:668
 __kfree_skb+0x15/0x20 net/core/skbuff.c:684
 kfree_skb+0x16e/0x4c0 net/core/skbuff.c:705
 inet_frag_destroy+0x121/0x290 net/ipv4/inet_fragment.c:304
 inet_frag_put include/net/inet_frag.h:133 [inline]
 nf_ct_frag6_gather+0x1106/0x3840
net/ipv6/netfilter/nf_conntrack_reasm.c:617
 ipv6_defrag+0x1be/0x2b0 net/ipv6/netfilter/nf_defrag_ipv6_hooks.c:68
 nf_hook_entry_hookfn include/linux/netfilter.h:102 [inline]
 nf_hook_slow+0xc3/0x290 net/netfilter/core.c:310
 nf_hook include/linux/netfilter.h:212 [inline]
 __ip6_local_out+0x489/0x840 net/ipv6/output_core.c:160
 ip6_local_out+0x2d/0x170 net/ipv6/output_core.c:170
 ip6_send_skb+0xa1/0x340 net/ipv6/ip6_output.c:1722
 ip6_push_pending_frames+0xb3/0xe0 net/ipv6/ip6_output.c:1742
 rawv6_push_pending_frames net/ipv6/raw.c:613 [inline]
 rawv6_sendmsg+0x2d1a/0x3ec0 net/ipv6/raw.c:927
 inet_sendmsg+0x164/0x5b0 net/ipv4/af_inet.c:744
 sock_sendmsg_nosec net/socket.c:635 [inline]
 sock_sendmsg+0xca/0x110 net/socket.c:645
 sock_write_iter+0x326/0x600 net/socket.c:848
 do_iter_readv_writev+0x2e3/0x5b0 fs/read_write.c:695
 do_readv_writev+0x42c/0x9b0 fs/read_write.c:872
 vfs_writev+0x87/0xc0 fs/read_write.c:911
 do_writev+0x110/0x2c0 fs/read_write.c:944
 SYSC_writev fs/read_write.c:1017 [inline]
 SyS_writev+0x27/0x30 fs/read_write.c:1014
 entry_SYSCALL_64_fastpath+0x1f/0xc2
RIP: 0033:0x445559
RSP: 002b:00007f6f46fceb58 EFLAGS: 00000292 ORIG_RAX: 0000000000000014
RAX: ffffffffffffffda RBX: 0000000000000005 RCX: 0000000000445559
RDX: 0000000000000001 RSI: 0000000020f1eff0 RDI: 0000000000000005
RBP: 00000000006e19c0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000292 R12: 0000000000700000
R13: 0000000020f59000 R14: 0000000000000015 R15: 0000000000020400
BUG: sleeping function called from invalid context at
kernel/locking/mutex.c:752
in_atomic(): 1, irqs_disabled(): 0, pid: 23111, name: syz-executor14
INFO: lockdep is turned off.
CPU: 2 PID: 23111 Comm: syz-executor14 Not tainted 4.10.0-rc5+ #192
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs
01/01/2011
Call Trace:
 __dump_stack lib/dump_stack.c:15 [inline]
 dump_stack+0x2ee/0x3ef lib/dump_stack.c:51
 ___might_sleep+0x47e/0x650 kernel/sched/core.c:7780
 __might_sleep+0x95/0x1a0 kernel/sched/core.c:7739
 mutex_lock_nested+0x24f/0x1730 kernel/locking/mutex.c:752
 atomic_dec_and_mutex_lock+0x119/0x160 kernel/locking/mutex.c:1060
 __static_key_slow_dec+0x7a/0x1e0 kernel/jump_label.c:149
 static_key_slow_dec+0x51/0x90 kernel/jump_label.c:174
 net_disable_timestamp+0x3b/0x50 net/core/dev.c:1728
 sock_disable_timestamp+0x98/0xc0 net/core/sock.c:403
 __sk_destruct+0x27d/0x6b0 net/core/sock.c:1441
 sk_destruct+0x47/0x80 net/core/sock.c:1460
 __sk_free+0x57/0x230 net/core/sock.c:1468
 sock_wfree+0xae/0x120 net/core/sock.c:1645
 skb_release_head_state+0xfc/0x200 net/core/skbuff.c:655
 skb_release_all+0x15/0x60 net/core/skbuff.c:668
 __kfree_skb+0x15/0x20 net/core/skbuff.c:684
 kfree_skb+0x16e/0x4c0 net/core/skbuff.c:705
 inet_frag_destroy+0x121/0x290 net/ipv4/inet_fragment.c:304
 inet_frag_put include/net/inet_frag.h:133 [inline]
 nf_ct_frag6_gather+0x1106/0x3840
net/ipv6/netfilter/nf_conntrack_reasm.c:617
 ipv6_defrag+0x1be/0x2b0 net/ipv6/netfilter/nf_defrag_ipv6_hooks.c:68
 nf_hook_entry_hookfn include/linux/netfilter.h:102 [inline]
 nf_hook_slow+0xc3/0x290 net/netfilter/core.c:310
 nf_hook include/linux/netfilter.h:212 [inline]
 __ip6_local_out+0x489/0x840 net/ipv6/output_core.c:160
 ip6_local_out+0x2d/0x170 net/ipv6/output_core.c:170
 ip6_send_skb+0xa1/0x340 net/ipv6/ip6_output.c:1722
 ip6_push_pending_frames+0xb3/0xe0 net/ipv6/ip6_output.c:1742
 rawv6_push_pending_frames net/ipv6/raw.c:613 [inline]
 rawv6_sendmsg+0x2d1a/0x3ec0 net/ipv6/raw.c:927
 inet_sendmsg+0x164/0x5b0 net/ipv4/af_inet.c:744
 sock_sendmsg_nosec net/socket.c:635 [inline]
 sock_sendmsg+0xca/0x110 net/socket.c:645
 sock_write_iter+0x326/0x600 net/socket.c:848
 do_iter_readv_writev+0x2e3/0x5b0 fs/read_write.c:695
 do_readv_writev+0x42c/0x9b0 fs/read_write.c:872
 vfs_writev+0x87/0xc0 fs/read_write.c:911
 do_writev+0x110/0x2c0 fs/read_write.c:944
 SYSC_writev fs/read_write.c:1017 [inline]
 SyS_writev+0x27/0x30 fs/read_write.c:1014
 entry_SYSCALL_64_fastpath+0x1f/0xc2
RIP: 0033:0x445559

Fixes: b90e5794c5bd ("net: dont call jump_label_dec from irq context")
Suggested-by: Cong Wang <xiyou.wangcong@gmail.com>
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/core/dev.c | 31 +++++++++++++------------------
 1 file changed, 13 insertions(+), 18 deletions(-)

diff --git a/net/core/dev.c b/net/core/dev.c
index 4dbc7af..11535a9 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -1559,24 +1559,19 @@ EXPORT_SYMBOL(call_netdevice_notifiers);
 
 static struct static_key netstamp_needed __read_mostly;
 #ifdef HAVE_JUMP_LABEL
-/* We are not allowed to call static_key_slow_dec() from irq context
- * If net_disable_timestamp() is called from irq context, defer the
- * static_key_slow_dec() calls.
- */
 static atomic_t netstamp_needed_deferred;
-#endif
-
-void net_enable_timestamp(void)
+static void netstamp_clear(struct work_struct *work)
 {
-#ifdef HAVE_JUMP_LABEL
 	int deferred = atomic_xchg(&netstamp_needed_deferred, 0);
 
-	if (deferred) {
-		while (--deferred)
-			static_key_slow_dec(&netstamp_needed);
-		return;
-	}
+	while (deferred--)
+		static_key_slow_dec(&netstamp_needed);
+}
+static DECLARE_WORK(netstamp_work, netstamp_clear);
 #endif
+
+void net_enable_timestamp(void)
+{
 	static_key_slow_inc(&netstamp_needed);
 }
 EXPORT_SYMBOL(net_enable_timestamp);
@@ -1584,12 +1579,12 @@ EXPORT_SYMBOL(net_enable_timestamp);
 void net_disable_timestamp(void)
 {
 #ifdef HAVE_JUMP_LABEL
-	if (in_interrupt()) {
-		atomic_inc(&netstamp_needed_deferred);
-		return;
-	}
-#endif
+	/* net_disable_timestamp() can be called from non process context */
+	atomic_inc(&netstamp_needed_deferred);
+	schedule_work(&netstamp_work);
+#else
 	static_key_slow_dec(&netstamp_needed);
+#endif
 }
 EXPORT_SYMBOL(net_disable_timestamp);
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660490 — [PATCH 3.10 077/250] gro: Disable frag0 optimization on IPv6 ext headers

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 077/250] gro: Disable frag0 optimization on IPv6 ext headers
Message-ID<tPSS6-4Tk-19@gated-at.bofh.it>
In reply to#1660349
From: Herbert Xu <herbert@gondor.apana.org.au>

commit 57ea52a865144aedbcd619ee0081155e658b6f7d upstream.

The GRO fast path caches the frag0 address.  This address becomes
invalid if frag0 is modified by pskb_may_pull or its variants.
So whenever that happens we must disable the frag0 optimization.

This is usually done through the combination of gro_header_hard
and gro_header_slow, however, the IPv6 extension header path did
the pulling directly and would continue to use the GRO fast path
incorrectly.

This patch fixes it by disabling the fast path when we enter the
IPv6 extension header path.

Fixes: 78a478d0efd9 ("gro: Inline skb_gro_header and cache frag0 virtual address")
Reported-by: Slava Shwartsman <slavash@mellanox.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 include/linux/netdevice.h | 9 +++++++--
 net/ipv6/ip6_offload.c    | 1 +
 2 files changed, 8 insertions(+), 2 deletions(-)

diff --git a/include/linux/netdevice.h b/include/linux/netdevice.h
index 45a618b..157a47c 100644
--- a/include/linux/netdevice.h
+++ b/include/linux/netdevice.h
@@ -1729,14 +1729,19 @@ static inline int skb_gro_header_hard(struct sk_buff *skb, unsigned int hlen)
 	return NAPI_GRO_CB(skb)->frag0_len < hlen;
 }
 
+static inline void skb_gro_frag0_invalidate(struct sk_buff *skb)
+{
+	NAPI_GRO_CB(skb)->frag0 = NULL;
+	NAPI_GRO_CB(skb)->frag0_len = 0;
+}
+
 static inline void *skb_gro_header_slow(struct sk_buff *skb, unsigned int hlen,
 					unsigned int offset)
 {
 	if (!pskb_may_pull(skb, hlen))
 		return NULL;
 
-	NAPI_GRO_CB(skb)->frag0 = NULL;
-	NAPI_GRO_CB(skb)->frag0_len = 0;
+	skb_gro_frag0_invalidate(skb);
 	return skb->data + offset;
 }
 
diff --git a/net/ipv6/ip6_offload.c b/net/ipv6/ip6_offload.c
index 71b766e..88a2e88 100644
--- a/net/ipv6/ip6_offload.c
+++ b/net/ipv6/ip6_offload.c
@@ -174,6 +174,7 @@ static struct sk_buff **ipv6_gro_receive(struct sk_buff **head,
 	ops = rcu_dereference(inet6_offloads[proto]);
 	if (!ops || !ops->callbacks.gro_receive) {
 		__pskb_pull(skb, skb_gro_offset(skb));
+		skb_gro_frag0_invalidate(skb);
 		proto = ipv6_gso_pull_exthdrs(skb, proto);
 		skb_gro_pull(skb, -skb_transport_offset(skb));
 		skb_reset_transport_header(skb);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660491 — [PATCH 3.10 064/250] cris: Only build flash rescue image if CONFIG_ETRAX_AXISFLASHMAP is selected

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 064/250] cris: Only build flash rescue image if CONFIG_ETRAX_AXISFLASHMAP is selected
Message-ID<tPSS6-4Tk-25@gated-at.bofh.it>
In reply to#1660349
From: Guenter Roeck <linux@roeck-us.net>

commit 328cf6927bb72cadefddebbc9a23c793108147a2 upstream.

If CONFIG_ETRAX_AXISFLASHMAP is not configured, the flash rescue image
object file is empty. With recent versions of binutils, this results
in the following build error.

cris-linux-objcopy: error:
	the input file 'arch/cris/boot/rescue/rescue.o' has no sections

This is seen, for example, when trying to build cris:allnoconfig
with recently generated toolchains.

Since it does not make sense to build a flash rescue image if there is
no flash, only build it if CONFIG_ETRAX_AXISFLASHMAP is enabled.

Reported-by: kbuild test robot <fengguang.wu@intel.com>
Fixes: 66ab3a74c5ce ("CRIS: Merge machine dependent boot/compressed ..")
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Jesper Nilsson <jesper.nilsson@axis.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 arch/cris/boot/rescue/Makefile | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/arch/cris/boot/rescue/Makefile b/arch/cris/boot/rescue/Makefile
index 52bd0bd..d98edbb 100644
--- a/arch/cris/boot/rescue/Makefile
+++ b/arch/cris/boot/rescue/Makefile
@@ -10,6 +10,9 @@
 
 asflags-y += $(LINUXINCLUDE)
 ccflags-y += -O2 $(LINUXINCLUDE)
+
+ifdef CONFIG_ETRAX_AXISFLASHMAP
+
 arch-$(CONFIG_ETRAX_ARCH_V10) = v10
 arch-$(CONFIG_ETRAX_ARCH_V32) = v32
 
@@ -28,6 +31,11 @@ $(obj)/rescue.bin: $(obj)/rescue.o FORCE
 	$(call if_changed,objcopy)
 	cp -p $(obj)/rescue.bin $(objtree)
 
+else
+$(obj)/rescue.bin:
+
+endif
+
 $(obj)/testrescue.bin: $(obj)/testrescue.o
 	$(OBJCOPY) $(OBJCOPYFLAGS) $(obj)/testrescue.o tr.bin
 # Pad it to 784 bytes
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660492 — [PATCH 3.10 110/250] net: fix harmonize_features() vs NETIF_F_HIGHDMA

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 110/250] net: fix harmonize_features() vs NETIF_F_HIGHDMA
Message-ID<tPSS6-4Tk-21@gated-at.bofh.it>
In reply to#1660349
From: Eric Dumazet <edumazet@google.com>

commit 7be2c82cfd5d28d7adb66821a992604eb6dd112e upstream.

Ashizuka reported a highmem oddity and sent a patch for freescale
fec driver.

But the problem root cause is that core networking stack
must ensure no skb with highmem fragment is ever sent through
a device that does not assert NETIF_F_HIGHDMA in its features.

We need to call illegal_highdma() from harmonize_features()
regardless of CSUM checks.

Fixes: ec5f06156423 ("net: Kill link between CSUM and SG features.")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Pravin Shelar <pshelar@ovn.org>
Reported-by: "Ashizuka, Yuusuke" <ashiduka@jp.fujitsu.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/core/dev.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/net/core/dev.c b/net/core/dev.c
index 6900ff08..4dbc7af 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -2461,9 +2461,9 @@ static netdev_features_t harmonize_features(struct sk_buff *skb,
 	if (skb->ip_summed != CHECKSUM_NONE &&
 	    !can_checksum_protocol(features, protocol)) {
 		features &= ~NETIF_F_ALL_CSUM;
-	} else if (illegal_highdma(dev, skb)) {
-		features &= ~NETIF_F_SG;
 	}
+	if (illegal_highdma(dev, skb))
+		features &= ~NETIF_F_SG;
 
 	return features;
 }
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660493 — [PATCH 3.10 180/250] Input: ims-pcu - validate number of endpoints before using them

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 180/250] Input: ims-pcu - validate number of endpoints before using them
Message-ID<tPSS6-4Tk-31@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit 1916d319271664241b7aa0cd2b05e32bdb310ce9 upstream.

Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer should a malicious device lack control-interface endpoints.

Fixes: 628329d52474 ("Input: add IMS Passenger Control Unit driver")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/input/misc/ims-pcu.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/input/misc/ims-pcu.c b/drivers/input/misc/ims-pcu.c
index 77164dc..8fb814c 100644
--- a/drivers/input/misc/ims-pcu.c
+++ b/drivers/input/misc/ims-pcu.c
@@ -1437,6 +1437,10 @@ static int ims_pcu_parse_cdc_data(struct usb_interface *intf, struct ims_pcu *pc
 		return -EINVAL;
 
 	alt = pcu->ctrl_intf->cur_altsetting;
+
+	if (alt->desc.bNumEndpoints < 1)
+		return -ENODEV;
+
 	pcu->ep_ctrl = &alt->endpoint[0].desc;
 	pcu->max_ctrl_size = usb_endpoint_maxp(pcu->ep_ctrl);
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660494 — [PATCH 3.10 244/250] TTY: n_hdlc, fix lockdep false positive

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 244/250] TTY: n_hdlc, fix lockdep false positive
Message-ID<tPSS6-4Tk-23@gated-at.bofh.it>
In reply to#1660349
From: Jiri Slaby <jslaby@suse.cz>

commit e9b736d88af1a143530565929390cadf036dc799 upstream.

The class of 4 n_hdls buf locks is the same because a single function
n_hdlc_buf_list_init is used to init all the locks. But since
flush_tx_queue takes n_hdlc->tx_buf_list.spinlock and then calls
n_hdlc_buf_put which takes n_hdlc->tx_free_buf_list.spinlock, lockdep
emits a warning:
=============================================
[ INFO: possible recursive locking detected ]
4.3.0-25.g91e30a7-default #1 Not tainted
---------------------------------------------
a.out/1248 is trying to acquire lock:
 (&(&list->spinlock)->rlock){......}, at: [<ffffffffa01fd020>] n_hdlc_buf_put+0x20/0x60 [n_hdlc]

but task is already holding lock:
 (&(&list->spinlock)->rlock){......}, at: [<ffffffffa01fdc07>] n_hdlc_tty_ioctl+0x127/0x1d0 [n_hdlc]

other info that might help us debug this:
 Possible unsafe locking scenario:

       CPU0
       ----
  lock(&(&list->spinlock)->rlock);
  lock(&(&list->spinlock)->rlock);

 *** DEADLOCK ***

 May be due to missing lock nesting notation

2 locks held by a.out/1248:
 #0:  (&tty->ldisc_sem){++++++}, at: [<ffffffff814c9eb0>] tty_ldisc_ref_wait+0x20/0x50
 #1:  (&(&list->spinlock)->rlock){......}, at: [<ffffffffa01fdc07>] n_hdlc_tty_ioctl+0x127/0x1d0 [n_hdlc]
...
Call Trace:
...
 [<ffffffff81738fd0>] _raw_spin_lock_irqsave+0x50/0x70
 [<ffffffffa01fd020>] n_hdlc_buf_put+0x20/0x60 [n_hdlc]
 [<ffffffffa01fdc24>] n_hdlc_tty_ioctl+0x144/0x1d0 [n_hdlc]
 [<ffffffff814c25c1>] tty_ioctl+0x3f1/0xe40
...

Fix it by initializing the spin_locks separately. This removes also
reduntand memset of a freshly kzallocated space.

Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/tty/n_hdlc.c | 19 ++++---------------
 1 file changed, 4 insertions(+), 15 deletions(-)

diff --git a/drivers/tty/n_hdlc.c b/drivers/tty/n_hdlc.c
index 1b2db9a..f26657c 100644
--- a/drivers/tty/n_hdlc.c
+++ b/drivers/tty/n_hdlc.c
@@ -159,7 +159,6 @@ struct n_hdlc {
 /*
  * HDLC buffer list manipulation functions
  */
-static void n_hdlc_buf_list_init(struct n_hdlc_buf_list *list);
 static void n_hdlc_buf_put(struct n_hdlc_buf_list *list,
 			   struct n_hdlc_buf *buf);
 static struct n_hdlc_buf *n_hdlc_buf_get(struct n_hdlc_buf_list *list);
@@ -855,10 +854,10 @@ static struct n_hdlc *n_hdlc_alloc(void)
 
 	memset(n_hdlc, 0, sizeof(*n_hdlc));
 
-	n_hdlc_buf_list_init(&n_hdlc->rx_free_buf_list);
-	n_hdlc_buf_list_init(&n_hdlc->tx_free_buf_list);
-	n_hdlc_buf_list_init(&n_hdlc->rx_buf_list);
-	n_hdlc_buf_list_init(&n_hdlc->tx_buf_list);
+	spin_lock_init(&n_hdlc->rx_free_buf_list.spinlock);
+	spin_lock_init(&n_hdlc->tx_free_buf_list.spinlock);
+	spin_lock_init(&n_hdlc->rx_buf_list.spinlock);
+	spin_lock_init(&n_hdlc->tx_buf_list.spinlock);
 	
 	/* allocate free rx buffer list */
 	for(i=0;i<DEFAULT_RX_BUF_COUNT;i++) {
@@ -887,16 +886,6 @@ static struct n_hdlc *n_hdlc_alloc(void)
 }	/* end of n_hdlc_alloc() */
 
 /**
- * n_hdlc_buf_list_init - initialize specified HDLC buffer list
- * @list - pointer to buffer list
- */
-static void n_hdlc_buf_list_init(struct n_hdlc_buf_list *list)
-{
-	memset(list, 0, sizeof(*list));
-	spin_lock_init(&list->spinlock);
-}	/* end of n_hdlc_buf_list_init() */
-
-/**
  * n_hdlc_buf_put - add specified HDLC buffer to tail of specified list
  * @list - pointer to buffer list
  * @buf	- pointer to buffer
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660495 — [PATCH 3.10 235/250] xc2028: Fix use-after-free bug properly

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 235/250] xc2028: Fix use-after-free bug properly
Message-ID<tPSS6-4Tk-27@gated-at.bofh.it>
In reply to#1660349
From: Takashi Iwai <tiwai@suse.de>

commit 22a1e7783e173ab3d86018eb590107d68df46c11 upstream.

The commit 8dfbcc4351a0 ("[media] xc2028: avoid use after free") tried
to address the reported use-after-free by clearing the reference.

However, it's clearing the wrong pointer; it sets NULL to
priv->ctrl.fname, but it's anyway overwritten by the next line
memcpy(&priv->ctrl, p, sizeof(priv->ctrl)).

OTOH, the actual code accessing the freed string is the strcmp() call
with priv->fname:
	if (!firmware_name[0] && p->fname &&
	    priv->fname && strcmp(p->fname, priv->fname))
		free_firmware(priv);

where priv->fname points to the previous file name, and this was
already freed by kfree().

For fixing the bug properly, this patch does the following:

- Keep the copy of firmware file name in only priv->fname,
  priv->ctrl.fname isn't changed;
- The allocation is done only when the firmware gets loaded;
- The kfree() is called in free_firmware() commonly

Fixes: commit 8dfbcc4351a0 ('[media] xc2028: avoid use after free')
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/media/tuners/tuner-xc2028.c | 36 ++++++++++++++++--------------------
 1 file changed, 16 insertions(+), 20 deletions(-)

diff --git a/drivers/media/tuners/tuner-xc2028.c b/drivers/media/tuners/tuner-xc2028.c
index ab0bfc46..3a615e4 100644
--- a/drivers/media/tuners/tuner-xc2028.c
+++ b/drivers/media/tuners/tuner-xc2028.c
@@ -289,6 +289,14 @@ static void free_firmware(struct xc2028_data *priv)
 	int i;
 	tuner_dbg("%s called\n", __func__);
 
+	/* free allocated f/w string */
+	if (priv->fname != firmware_name)
+		kfree(priv->fname);
+	priv->fname = NULL;
+
+	priv->state = XC2028_NO_FIRMWARE;
+	memset(&priv->cur_fw, 0, sizeof(priv->cur_fw));
+
 	if (!priv->firm)
 		return;
 
@@ -299,9 +307,6 @@ static void free_firmware(struct xc2028_data *priv)
 
 	priv->firm = NULL;
 	priv->firm_size = 0;
-	priv->state = XC2028_NO_FIRMWARE;
-
-	memset(&priv->cur_fw, 0, sizeof(priv->cur_fw));
 }
 
 static int load_all_firmwares(struct dvb_frontend *fe,
@@ -890,9 +895,9 @@ read_not_reliable:
 	return 0;
 
 fail:
+	free_firmware(priv);
 	priv->state = XC2028_SLEEP;
 
-	memset(&priv->cur_fw, 0, sizeof(priv->cur_fw));
 	if (retry_count < 8) {
 		msleep(50);
 		retry_count++;
@@ -1314,11 +1319,8 @@ static int xc2028_dvb_release(struct dvb_frontend *fe)
 	mutex_lock(&xc2028_list_mutex);
 
 	/* only perform final cleanup if this is the last instance */
-	if (hybrid_tuner_report_instance_count(priv) == 1) {
+	if (hybrid_tuner_report_instance_count(priv) == 1)
 		free_firmware(priv);
-		kfree(priv->ctrl.fname);
-		priv->ctrl.fname = NULL;
-	}
 
 	if (priv)
 		hybrid_tuner_release_state(priv);
@@ -1381,19 +1383,8 @@ static int xc2028_set_config(struct dvb_frontend *fe, void *priv_cfg)
 
 	/*
 	 * Copy the config data.
-	 * For the firmware name, keep a local copy of the string,
-	 * in order to avoid troubles during device release.
 	 */
-	kfree(priv->ctrl.fname);
-	priv->ctrl.fname = NULL;
 	memcpy(&priv->ctrl, p, sizeof(priv->ctrl));
-	if (p->fname) {
-		priv->ctrl.fname = kstrdup(p->fname, GFP_KERNEL);
-		if (priv->ctrl.fname == NULL) {
-			rc = -ENOMEM;
-			goto unlock;
-		}
-	}
 
 	/*
 	 * If firmware name changed, frees firmware. As free_firmware will
@@ -1408,10 +1399,15 @@ static int xc2028_set_config(struct dvb_frontend *fe, void *priv_cfg)
 
 	if (priv->state == XC2028_NO_FIRMWARE) {
 		if (!firmware_name[0])
-			priv->fname = priv->ctrl.fname;
+			priv->fname = kstrdup(p->fname, GFP_KERNEL);
 		else
 			priv->fname = firmware_name;
 
+		if (!priv->fname) {
+			rc = -ENOMEM;
+			goto unlock;
+		}
+
 		rc = request_firmware_nowait(THIS_MODULE, 1,
 					     priv->fname,
 					     priv->i2c_props.adap->dev.parent,
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660496 — [PATCH 3.10 148/250] uvcvideo: Fix a wrong macro

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 148/250] uvcvideo: Fix a wrong macro
Message-ID<tPSS6-4Tk-29@gated-at.bofh.it>
In reply to#1660349
From: Guennadi Liakhovetski <g.liakhovetski@gmx.de>

commit 17c341ec0115837a610b2da15e32546e26068234 upstream.

Don't mix up UVC_BUF_STATE_* and VB2_BUF_STATE_* codes.

Fixes: 6998b6fb4b1c ("[media] uvcvideo: Use videobuf2-vmalloc")

Signed-off-by: Guennadi Liakhovetski <guennadi.liakhovetski@intel.com>
Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/media/usb/uvc/uvc_queue.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/media/usb/uvc/uvc_queue.c b/drivers/media/usb/uvc/uvc_queue.c
index cd962be..7e74395 100644
--- a/drivers/media/usb/uvc/uvc_queue.c
+++ b/drivers/media/usb/uvc/uvc_queue.c
@@ -375,7 +375,7 @@ struct uvc_buffer *uvc_queue_next_buffer(struct uvc_video_queue *queue,
 		nextbuf = NULL;
 	spin_unlock_irqrestore(&queue->irqlock, flags);
 
-	buf->state = buf->error ? VB2_BUF_STATE_ERROR : UVC_BUF_STATE_DONE;
+	buf->state = buf->error ? UVC_BUF_STATE_ERROR : UVC_BUF_STATE_DONE;
 	vb2_set_plane_payload(&buf->buf, 0, buf->bytesused);
 	vb2_buffer_done(&buf->buf, VB2_BUF_STATE_DONE);
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660497 — [PATCH 3.10 004/250] libceph: don't set weight to IN when OSD is destroyed

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 004/250] libceph: don't set weight to IN when OSD is destroyed
Message-ID<tPSS6-4Tk-33@gated-at.bofh.it>
In reply to#1660349
From: Ilya Dryomov <idryomov@gmail.com>

commit b581a5854eee4b7851dedb0f8c2ceb54fb902c06 upstream.

Since ceph.git commit 4e28f9e63644 ("osd/OSDMap: clear osd_info,
osd_xinfo on osd deletion"), weight is set to IN when OSD is deleted.
This changes the result of applying an incremental for clients, not
just OSDs.  Because CRUSH computations are obviously affected,
pre-4e28f9e63644 servers disagree with post-4e28f9e63644 clients on
object placement, resulting in misdirected requests.

Mirrors ceph.git commit a6009d1039a55e2c77f431662b3d6cc5a8e8e63f.

Fixes: 930c53286977 ("libceph: apply new_state before new_up_client on incrementals")
Link: http://tracker.ceph.com/issues/19122
Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
Reviewed-by: Sage Weil <sage@redhat.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/ceph/osdmap.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/net/ceph/osdmap.c b/net/ceph/osdmap.c
index c1de8d4..26e22353 100644
--- a/net/ceph/osdmap.c
+++ b/net/ceph/osdmap.c
@@ -870,7 +870,6 @@ static int decode_new_up_state_weight(void **p, void *end,
 		if ((map->osd_state[osd] & CEPH_OSD_EXISTS) &&
 		    (xorstate & CEPH_OSD_EXISTS)) {
 			pr_info("osd%d does not exist\n", osd);
-			map->osd_weight[osd] = CEPH_OSD_IN;
 			memset(map->osd_addr + osd, 0, sizeof(*map->osd_addr));
 			map->osd_state[osd] = 0;
 		} else {
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660498 — [PATCH 3.10 200/250] ptrace: fix PTRACE_LISTEN race corrupting task->state

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 200/250] ptrace: fix PTRACE_LISTEN race corrupting task->state
Message-ID<tPSS6-4Tk-35@gated-at.bofh.it>
In reply to#1660349
From: "bsegall@google.com" <bsegall@google.com>

commit 5402e97af667e35e54177af8f6575518bf251d51 upstream.

In PT_SEIZED + LISTEN mode STOP/CONT signals cause a wakeup against
__TASK_TRACED.  If this races with the ptrace_unfreeze_traced at the end
of a PTRACE_LISTEN, this can wake the task /after/ the check against
__TASK_TRACED, but before the reset of state to TASK_TRACED.  This
causes it to instead clobber TASK_WAKING, allowing a subsequent wakeup
against TRACED while the task is still on the rq wake_list, corrupting
it.

Oleg said:
 "The kernel can crash or this can lead to other hard-to-debug problems.
  In short, "task->state = TASK_TRACED" in ptrace_unfreeze_traced()
  assumes that nobody else can wake it up, but PTRACE_LISTEN breaks the
  contract. Obviusly it is very wrong to manipulate task->state if this
  task is already running, or WAKING, or it sleeps again"

[akpm@linux-foundation.org: coding-style fixes]
Fixes: 9899d11f ("ptrace: ensure arch_ptrace/ptrace_request can never race with SIGKILL")
Link: http://lkml.kernel.org/r/xm26y3vfhmkp.fsf_-_@bsegall-linux.mtv.corp.google.com
Signed-off-by: Ben Segall <bsegall@google.com>
Acked-by: Oleg Nesterov <oleg@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 kernel/ptrace.c | 14 ++++++++++----
 1 file changed, 10 insertions(+), 4 deletions(-)

diff --git a/kernel/ptrace.c b/kernel/ptrace.c
index 72b0b3e..d34c05a 100644
--- a/kernel/ptrace.c
+++ b/kernel/ptrace.c
@@ -150,11 +150,17 @@ static void ptrace_unfreeze_traced(struct task_struct *task)
 
 	WARN_ON(!task->ptrace || task->parent != current);
 
+	/*
+	 * PTRACE_LISTEN can allow ptrace_trap_notify to wake us up remotely.
+	 * Recheck state under the lock to close this race.
+	 */
 	spin_lock_irq(&task->sighand->siglock);
-	if (__fatal_signal_pending(task))
-		wake_up_state(task, __TASK_TRACED);
-	else
-		task->state = TASK_TRACED;
+	if (task->state == __TASK_TRACED) {
+		if (__fatal_signal_pending(task))
+			wake_up_state(task, __TASK_TRACED);
+		else
+			task->state = TASK_TRACED;
+	}
 	spin_unlock_irq(&task->sighand->siglock);
 }
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660499 — [PATCH 3.10 250/250] char: lp: fix possible integer overflow in lp_setup()

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 250/250] char: lp: fix possible integer overflow in lp_setup()
Message-ID<tPSS6-4Tk-39@gated-at.bofh.it>
In reply to#1660349
commit 3e21f4af170bebf47c187c1ff8bf155583c9f3b1 upstream.

The lp_setup() code doesn't apply any bounds checking when passing
"lp=none", and only in this case, resulting in an overflow of the
parport_nr[] array. All versions in Git history are affected.

Reported-By: Roee Hay <roee.hay@hcl.com>
Cc: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/char/lp.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/char/lp.c b/drivers/char/lp.c
index 0913d79..6b61910 100644
--- a/drivers/char/lp.c
+++ b/drivers/char/lp.c
@@ -857,7 +857,11 @@ static int __init lp_setup (char *str)
 	} else if (!strcmp(str, "auto")) {
 		parport_nr[0] = LP_PARPORT_AUTO;
 	} else if (!strcmp(str, "none")) {
-		parport_nr[parport_ptr++] = LP_PARPORT_NONE;
+		if (parport_ptr < LP_NO)
+			parport_nr[parport_ptr++] = LP_PARPORT_NONE;
+		else
+			printk(KERN_INFO "lp: too many ports, %s ignored.\n",
+			       str);
 	} else if (!strcmp(str, "reset")) {
 		reset = 1;
 	}
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660500 — [PATCH 3.10 239/250] sctp: avoid BUG_ON on sctp_wait_for_sndbuf

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 239/250] sctp: avoid BUG_ON on sctp_wait_for_sndbuf
Message-ID<tPSS7-4Tk-45@gated-at.bofh.it>
In reply to#1660349
From: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>

commit 2dcab598484185dea7ec22219c76dcdd59e3cb90 upstream.

Alexander Popov reported that an application may trigger a BUG_ON in
sctp_wait_for_sndbuf if the socket tx buffer is full, a thread is
waiting on it to queue more data and meanwhile another thread peels off
the association being used by the first thread.

This patch replaces the BUG_ON call with a proper error handling. It
will return -EPIPE to the original sendmsg call, similarly to what would
have been done if the association wasn't found in the first place.

Acked-by: Alexander Popov <alex.popov@linux.com>
Signed-off-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Reviewed-by: Xin Long <lucien.xin@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/sctp/socket.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/net/sctp/socket.c b/net/sctp/socket.c
index ede7c54..152ab4b 100644
--- a/net/sctp/socket.c
+++ b/net/sctp/socket.c
@@ -6724,7 +6724,8 @@ static int sctp_wait_for_sndbuf(struct sctp_association *asoc, long *timeo_p,
 		 */
 		sctp_release_sock(sk);
 		current_timeo = schedule_timeout(current_timeo);
-		BUG_ON(sk != asoc->base.sk);
+		if (sk != asoc->base.sk)
+			goto do_error;
 		sctp_lock_sock(sk);
 
 		*timeo_p = current_timeo;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660501 — [PATCH 3.10 080/250] mm/hugetlb.c: fix reservation race when freeing surplus pages

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 080/250] mm/hugetlb.c: fix reservation race when freeing surplus pages
Message-ID<tPSS7-4Tk-43@gated-at.bofh.it>
In reply to#1660349
From: Mike Kravetz <mike.kravetz@oracle.com>

commit e5bbc8a6c992901058bc09e2ce01d16c111ff047 upstream.

return_unused_surplus_pages() decrements the global reservation count,
and frees any unused surplus pages that were backing the reservation.

Commit 7848a4bf51b3 ("mm/hugetlb.c: add cond_resched_lock() in
return_unused_surplus_pages()") added a call to cond_resched_lock in the
loop freeing the pages.

As a result, the hugetlb_lock could be dropped, and someone else could
use the pages that will be freed in subsequent iterations of the loop.
This could result in inconsistent global hugetlb page state, application
api failures (such as mmap) failures or application crashes.

When dropping the lock in return_unused_surplus_pages, make sure that
the global reservation count (resv_huge_pages) remains sufficiently
large to prevent someone else from claiming pages about to be freed.

Analyzed by Paul Cassella.

Fixes: 7848a4bf51b3 ("mm/hugetlb.c: add cond_resched_lock() in return_unused_surplus_pages()")
Link: http://lkml.kernel.org/r/1483991767-6879-1-git-send-email-mike.kravetz@oracle.com
Signed-off-by: Mike Kravetz <mike.kravetz@oracle.com>
Reported-by: Paul Cassella <cassella@cray.com>
Suggested-by: Michal Hocko <mhocko@kernel.org>
Cc: Masayoshi Mizuma <m.mizuma@jp.fujitsu.com>
Cc: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
Cc: Aneesh Kumar <aneesh.kumar@linux.vnet.ibm.com>
Cc: Hillf Danton <hillf.zj@alibaba-inc.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 mm/hugetlb.c | 37 ++++++++++++++++++++++++++++---------
 1 file changed, 28 insertions(+), 9 deletions(-)

diff --git a/mm/hugetlb.c b/mm/hugetlb.c
index e9fd382..6983229 100644
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -1070,23 +1070,32 @@ free:
 }
 
 /*
- * When releasing a hugetlb pool reservation, any surplus pages that were
- * allocated to satisfy the reservation must be explicitly freed if they were
- * never used.
- * Called with hugetlb_lock held.
+ * This routine has two main purposes:
+ * 1) Decrement the reservation count (resv_huge_pages) by the value passed
+ *    in unused_resv_pages.  This corresponds to the prior adjustments made
+ *    to the associated reservation map.
+ * 2) Free any unused surplus pages that may have been allocated to satisfy
+ *    the reservation.  As many as unused_resv_pages may be freed.
+ *
+ * Called with hugetlb_lock held.  However, the lock could be dropped (and
+ * reacquired) during calls to cond_resched_lock.  Whenever dropping the lock,
+ * we must make sure nobody else can claim pages we are in the process of
+ * freeing.  Do this by ensuring resv_huge_page always is greater than the
+ * number of huge pages we plan to free when dropping the lock.
  */
 static void return_unused_surplus_pages(struct hstate *h,
 					unsigned long unused_resv_pages)
 {
 	unsigned long nr_pages;
 
-	/* Uncommit the reservation */
-	h->resv_huge_pages -= unused_resv_pages;
-
 	/* Cannot return gigantic pages currently */
 	if (h->order >= MAX_ORDER)
-		return;
+		goto out;
 
+	/*
+	 * Part (or even all) of the reservation could have been backed
+	 * by pre-allocated pages. Only free surplus pages.
+	 */
 	nr_pages = min(unused_resv_pages, h->surplus_huge_pages);
 
 	/*
@@ -1096,12 +1105,22 @@ static void return_unused_surplus_pages(struct hstate *h,
 	 * when the nodes with surplus pages have no free pages.
 	 * free_pool_huge_page() will balance the the freed pages across the
 	 * on-line nodes with memory and will handle the hstate accounting.
+	 *
+	 * Note that we decrement resv_huge_pages as we free the pages.  If
+	 * we drop the lock, resv_huge_pages will still be sufficiently large
+	 * to cover subsequent pages we may free.
 	 */
 	while (nr_pages--) {
+		h->resv_huge_pages--;
+		unused_resv_pages--;
 		if (!free_pool_huge_page(h, &node_states[N_MEMORY], 1))
-			break;
+			goto out;
 		cond_resched_lock(&hugetlb_lock);
 	}
+
+out:
+	/* Fully uncommit the reservation */
+	h->resv_huge_pages -= unused_resv_pages;
 }
 
 /*
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660502 — [PATCH 3.10 041/250] USB: serial: pl2303: fix NULL-deref at open

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 041/250] USB: serial: pl2303: fix NULL-deref at open
Message-ID<tPSS6-4Tk-41@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit 76ab439ed1b68778e9059c79ecc5d14de76c89a8 upstream.

Fix NULL-pointer dereference in open() should a type-0 or type-1 device
lack the expected endpoints:

Unable to handle kernel NULL pointer dereference at virtual address 00000030
...
PC is at pl2303_open+0x38/0xec [pl2303]

Note that a missing interrupt-in endpoint would have caused open() to
fail.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/serial/pl2303.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/drivers/usb/serial/pl2303.c b/drivers/usb/serial/pl2303.c
index 33313ca..f496c38 100644
--- a/drivers/usb/serial/pl2303.c
+++ b/drivers/usb/serial/pl2303.c
@@ -175,9 +175,17 @@ static int pl2303_vendor_write(__u16 value, __u16 index,
 static int pl2303_startup(struct usb_serial *serial)
 {
 	struct pl2303_serial_private *spriv;
+	unsigned char num_ports = serial->num_ports;
 	enum pl2303_type type = type_0;
 	unsigned char *buf;
 
+	if (serial->num_bulk_in < num_ports ||
+			serial->num_bulk_out < num_ports ||
+			serial->num_interrupt_in < num_ports) {
+		dev_err(&serial->interface->dev, "missing endpoints\n");
+		return -ENODEV;
+	}
+
 	spriv = kzalloc(sizeof(*spriv), GFP_KERNEL);
 	if (!spriv)
 		return -ENOMEM;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660503 — [PATCH 3.10 168/250] USB: serial: io_ti: fix information leak in completion handler

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 168/250] USB: serial: io_ti: fix information leak in completion handler
Message-ID<tPSS6-4Tk-37@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit 654b404f2a222f918af9b0cd18ad469d0c941a8e upstream.

Add missing sanity check to the bulk-in completion handler to avoid an
integer underflow that can be triggered by a malicious device.

This avoids leaking 128 kB of memory content from after the URB transfer
buffer to user space.

Fixes: 8c209e6782ca ("USB: make actual_length in struct urb field u32")
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/serial/io_ti.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/usb/serial/io_ti.c b/drivers/usb/serial/io_ti.c
index e2dc182..20814d5 100644
--- a/drivers/usb/serial/io_ti.c
+++ b/drivers/usb/serial/io_ti.c
@@ -1661,7 +1661,7 @@ static void edge_bulk_in_callback(struct urb *urb)
 
 	port_number = edge_port->port->number - edge_port->port->serial->minor;
 
-	if (edge_port->lsr_event) {
+	if (urb->actual_length > 0 && edge_port->lsr_event) {
 		edge_port->lsr_event = 0;
 		dev_dbg(dev, "%s ===== Port %u LSR Status = %02x, Data = %02x ======\n",
 			__func__, port_number, edge_port->lsr_mask, *data);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660504 — [PATCH 3.10 233/250] xc2028: avoid use after free

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:50 +0200
Subject[PATCH 3.10 233/250] xc2028: avoid use after free
Message-ID<tPSS7-4Tk-47@gated-at.bofh.it>
In reply to#1660349
From: Mauro Carvalho Chehab <mchehab@osg.samsung.com>

commit 8dfbcc4351a0b6d2f2d77f367552f48ffefafe18 upstream.

If struct xc2028_config is passed without a firmware name,
the following trouble may happen:

[11009.907205] xc2028 5-0061: type set to XCeive xc2028/xc3028 tuner
[11009.907491] ==================================================================
[11009.907750] BUG: KASAN: use-after-free in strcmp+0x96/0xb0 at addr ffff8803bd78ab40
[11009.907992] Read of size 1 by task modprobe/28992
[11009.907994] =============================================================================
[11009.907997] BUG kmalloc-16 (Tainted: G        W      ): kasan: bad access detected
[11009.907999] -----------------------------------------------------------------------------

[11009.908008] INFO: Allocated in xhci_urb_enqueue+0x214/0x14c0 [xhci_hcd] age=0 cpu=3 pid=28992
[11009.908012] 	___slab_alloc+0x581/0x5b0
[11009.908014] 	__slab_alloc+0x51/0x90
[11009.908017] 	__kmalloc+0x27b/0x350
[11009.908022] 	xhci_urb_enqueue+0x214/0x14c0 [xhci_hcd]
[11009.908026] 	usb_hcd_submit_urb+0x1e8/0x1c60
[11009.908029] 	usb_submit_urb+0xb0e/0x1200
[11009.908032] 	usb_serial_generic_write_start+0xb6/0x4c0
[11009.908035] 	usb_serial_generic_write+0x92/0xc0
[11009.908039] 	usb_console_write+0x38a/0x560
[11009.908045] 	call_console_drivers.constprop.14+0x1ee/0x2c0
[11009.908051] 	console_unlock+0x40d/0x900
[11009.908056] 	vprintk_emit+0x4b4/0x830
[11009.908061] 	vprintk_default+0x1f/0x30
[11009.908064] 	printk+0x99/0xb5
[11009.908067] 	kasan_report_error+0x10a/0x550
[11009.908070] 	__asan_report_load1_noabort+0x43/0x50
[11009.908074] INFO: Freed in xc2028_set_config+0x90/0x630 [tuner_xc2028] age=1 cpu=3 pid=28992
[11009.908077] 	__slab_free+0x2ec/0x460
[11009.908080] 	kfree+0x266/0x280
[11009.908083] 	xc2028_set_config+0x90/0x630 [tuner_xc2028]
[11009.908086] 	xc2028_attach+0x310/0x8a0 [tuner_xc2028]
[11009.908090] 	em28xx_attach_xc3028.constprop.7+0x1f9/0x30d [em28xx_dvb]
[11009.908094] 	em28xx_dvb_init.part.3+0x8e4/0x5cf4 [em28xx_dvb]
[11009.908098] 	em28xx_dvb_init+0x81/0x8a [em28xx_dvb]
[11009.908101] 	em28xx_register_extension+0xd9/0x190 [em28xx]
[11009.908105] 	em28xx_dvb_register+0x10/0x1000 [em28xx_dvb]
[11009.908108] 	do_one_initcall+0x141/0x300
[11009.908111] 	do_init_module+0x1d0/0x5ad
[11009.908114] 	load_module+0x6666/0x9ba0
[11009.908117] 	SyS_finit_module+0x108/0x130
[11009.908120] 	entry_SYSCALL_64_fastpath+0x16/0x76
[11009.908123] INFO: Slab 0xffffea000ef5e280 objects=25 used=25 fp=0x          (null) flags=0x2ffff8000004080
[11009.908126] INFO: Object 0xffff8803bd78ab40 @offset=2880 fp=0x0000000000000001

[11009.908130] Bytes b4 ffff8803bd78ab30: 01 00 00 00 2a 07 00 00 9d 28 00 00 01 00 00 00  ....*....(......
[11009.908133] Object ffff8803bd78ab40: 01 00 00 00 00 00 00 00 b0 1d c3 6a 00 88 ff ff  ...........j....
[11009.908137] CPU: 3 PID: 28992 Comm: modprobe Tainted: G    B   W       4.5.0-rc1+ #43
[11009.908140] Hardware name:                  /NUC5i7RYB, BIOS RYBDWi35.86A.0350.2015.0812.1722 08/12/2015
[11009.908142]  ffff8803bd78a000 ffff8802c273f1b8 ffffffff81932007 ffff8803c6407a80
[11009.908148]  ffff8802c273f1e8 ffffffff81556759 ffff8803c6407a80 ffffea000ef5e280
[11009.908153]  ffff8803bd78ab40 dffffc0000000000 ffff8802c273f210 ffffffff8155ccb4
[11009.908158] Call Trace:
[11009.908162]  [<ffffffff81932007>] dump_stack+0x4b/0x64
[11009.908165]  [<ffffffff81556759>] print_trailer+0xf9/0x150
[11009.908168]  [<ffffffff8155ccb4>] object_err+0x34/0x40
[11009.908171]  [<ffffffff8155f260>] kasan_report_error+0x230/0x550
[11009.908175]  [<ffffffff81237d71>] ? trace_hardirqs_off_caller+0x21/0x290
[11009.908179]  [<ffffffff8155e926>] ? kasan_unpoison_shadow+0x36/0x50
[11009.908182]  [<ffffffff8155f5c3>] __asan_report_load1_noabort+0x43/0x50
[11009.908185]  [<ffffffff8155ea00>] ? __asan_register_globals+0x50/0xa0
[11009.908189]  [<ffffffff8194cea6>] ? strcmp+0x96/0xb0
[11009.908192]  [<ffffffff8194cea6>] strcmp+0x96/0xb0
[11009.908196]  [<ffffffffa13ba4ac>] xc2028_set_config+0x15c/0x630 [tuner_xc2028]
[11009.908200]  [<ffffffffa13bac90>] xc2028_attach+0x310/0x8a0 [tuner_xc2028]
[11009.908203]  [<ffffffff8155ea78>] ? memset+0x28/0x30
[11009.908206]  [<ffffffffa13ba980>] ? xc2028_set_config+0x630/0x630 [tuner_xc2028]
[11009.908211]  [<ffffffffa157a59a>] em28xx_attach_xc3028.constprop.7+0x1f9/0x30d [em28xx_dvb]
[11009.908215]  [<ffffffffa157aa2a>] ? em28xx_dvb_init.part.3+0x37c/0x5cf4 [em28xx_dvb]
[11009.908219]  [<ffffffffa157a3a1>] ? hauppauge_hvr930c_init+0x487/0x487 [em28xx_dvb]
[11009.908222]  [<ffffffffa01795ac>] ? lgdt330x_attach+0x1cc/0x370 [lgdt330x]
[11009.908226]  [<ffffffffa01793e0>] ? i2c_read_demod_bytes.isra.2+0x210/0x210 [lgdt330x]
[11009.908230]  [<ffffffff812e87d0>] ? ref_module.part.15+0x10/0x10
[11009.908233]  [<ffffffff812e56e0>] ? module_assert_mutex_or_preempt+0x80/0x80
[11009.908238]  [<ffffffffa157af92>] em28xx_dvb_init.part.3+0x8e4/0x5cf4 [em28xx_dvb]
[11009.908242]  [<ffffffffa157a6ae>] ? em28xx_attach_xc3028.constprop.7+0x30d/0x30d [em28xx_dvb]
[11009.908245]  [<ffffffff8195222d>] ? string+0x14d/0x1f0
[11009.908249]  [<ffffffff8195381f>] ? symbol_string+0xff/0x1a0
[11009.908253]  [<ffffffff81953720>] ? uuid_string+0x6f0/0x6f0
[11009.908257]  [<ffffffff811a775e>] ? __kernel_text_address+0x7e/0xa0
[11009.908260]  [<ffffffff8104b02f>] ? print_context_stack+0x7f/0xf0
[11009.908264]  [<ffffffff812e9846>] ? __module_address+0xb6/0x360
[11009.908268]  [<ffffffff8137fdc9>] ? is_ftrace_trampoline+0x99/0xe0
[11009.908271]  [<ffffffff811a775e>] ? __kernel_text_address+0x7e/0xa0
[11009.908275]  [<ffffffff81240a70>] ? debug_check_no_locks_freed+0x290/0x290
[11009.908278]  [<ffffffff8104a24b>] ? dump_trace+0x11b/0x300
[11009.908282]  [<ffffffffa13e8143>] ? em28xx_register_extension+0x23/0x190 [em28xx]
[11009.908285]  [<ffffffff81237d71>] ? trace_hardirqs_off_caller+0x21/0x290
[11009.908289]  [<ffffffff8123ff56>] ? trace_hardirqs_on_caller+0x16/0x590
[11009.908292]  [<ffffffff812404dd>] ? trace_hardirqs_on+0xd/0x10
[11009.908296]  [<ffffffffa13e8143>] ? em28xx_register_extension+0x23/0x190 [em28xx]
[11009.908299]  [<ffffffff822dcbb0>] ? mutex_trylock+0x400/0x400
[11009.908302]  [<ffffffff810021a1>] ? do_one_initcall+0x131/0x300
[11009.908306]  [<ffffffff81296dc7>] ? call_rcu_sched+0x17/0x20
[11009.908309]  [<ffffffff8159e708>] ? put_object+0x48/0x70
[11009.908314]  [<ffffffffa1579f11>] em28xx_dvb_init+0x81/0x8a [em28xx_dvb]
[11009.908317]  [<ffffffffa13e81f9>] em28xx_register_extension+0xd9/0x190 [em28xx]
[11009.908320]  [<ffffffffa0150000>] ? 0xffffffffa0150000
[11009.908324]  [<ffffffffa0150010>] em28xx_dvb_register+0x10/0x1000 [em28xx_dvb]
[11009.908327]  [<ffffffff810021b1>] do_one_initcall+0x141/0x300
[11009.908330]  [<ffffffff81002070>] ? try_to_run_init_process+0x40/0x40
[11009.908333]  [<ffffffff8123ff56>] ? trace_hardirqs_on_caller+0x16/0x590
[11009.908337]  [<ffffffff8155e926>] ? kasan_unpoison_shadow+0x36/0x50
[11009.908340]  [<ffffffff8155e926>] ? kasan_unpoison_shadow+0x36/0x50
[11009.908343]  [<ffffffff8155e926>] ? kasan_unpoison_shadow+0x36/0x50
[11009.908346]  [<ffffffff8155ea37>] ? __asan_register_globals+0x87/0xa0
[11009.908350]  [<ffffffff8144da7b>] do_init_module+0x1d0/0x5ad
[11009.908353]  [<ffffffff812f2626>] load_module+0x6666/0x9ba0
[11009.908356]  [<ffffffff812e9c90>] ? symbol_put_addr+0x50/0x50
[11009.908361]  [<ffffffffa1580037>] ? em28xx_dvb_init.part.3+0x5989/0x5cf4 [em28xx_dvb]
[11009.908366]  [<ffffffff812ebfc0>] ? module_frob_arch_sections+0x20/0x20
[11009.908369]  [<ffffffff815bc940>] ? open_exec+0x50/0x50
[11009.908374]  [<ffffffff811671bb>] ? ns_capable+0x5b/0xd0
[11009.908377]  [<ffffffff812f5e58>] SyS_finit_module+0x108/0x130
[11009.908379]  [<ffffffff812f5d50>] ? SyS_init_module+0x1f0/0x1f0
[11009.908383]  [<ffffffff81004044>] ? lockdep_sys_exit_thunk+0x12/0x14
[11009.908394]  [<ffffffff822e6936>] entry_SYSCALL_64_fastpath+0x16/0x76
[11009.908396] Memory state around the buggy address:
[11009.908398]  ffff8803bd78aa00: 00 00 fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[11009.908401]  ffff8803bd78aa80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[11009.908403] >ffff8803bd78ab00: fc fc fc fc fc fc fc fc 00 00 fc fc fc fc fc fc
[11009.908405]                                            ^
[11009.908407]  ffff8803bd78ab80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[11009.908409]  ffff8803bd78ac00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[11009.908411] ==================================================================

In order to avoid it, let's set the cached value of the firmware
name to NULL after freeing it. While here, return an error if
the memory allocation fails.

Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/media/tuners/tuner-xc2028.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/media/tuners/tuner-xc2028.c b/drivers/media/tuners/tuner-xc2028.c
index 9771cd8..38afc54 100644
--- a/drivers/media/tuners/tuner-xc2028.c
+++ b/drivers/media/tuners/tuner-xc2028.c
@@ -1385,11 +1385,12 @@ static int xc2028_set_config(struct dvb_frontend *fe, void *priv_cfg)
 	 * in order to avoid troubles during device release.
 	 */
 	kfree(priv->ctrl.fname);
+	priv->ctrl.fname = NULL;
 	memcpy(&priv->ctrl, p, sizeof(priv->ctrl));
 	if (p->fname) {
 		priv->ctrl.fname = kstrdup(p->fname, GFP_KERNEL);
 		if (priv->ctrl.fname == NULL)
-			rc = -ENOMEM;
+			return -ENOMEM;
 	}
 
 	/*
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660505 — [PATCH 3.10 122/250] l2tp: do not use udp_ioctl()

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 122/250] l2tp: do not use udp_ioctl()
Message-ID<tPT1L-4Xs-1@gated-at.bofh.it>
In reply to#1660349
From: Eric Dumazet <edumazet@google.com>

commit 72fb96e7bdbbdd4421b0726992496531060f3636 upstream.

udp_ioctl(), as its name suggests, is used by UDP protocols,
but is also used by L2TP :(

L2TP should use its own handler, because it really does not
look the same.

SIOCINQ for instance should not assume UDP checksum or headers.

Thanks to Andrey and syzkaller team for providing the report
and a nice reproducer.

While crashes only happen on recent kernels (after commit
7c13f97ffde6 ("udp: do fwd memory scheduling on dequeue")), this
probably needs to be backported to older kernels.

Fixes: 7c13f97ffde6 ("udp: do fwd memory scheduling on dequeue")
Fixes: 85584672012e ("udp: Fix udp_poll() and ioctl()")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Acked-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/l2tp/l2tp_core.h |  1 +
 net/l2tp/l2tp_ip.c   | 27 ++++++++++++++++++++++++++-
 net/l2tp/l2tp_ip6.c  |  2 +-
 3 files changed, 28 insertions(+), 2 deletions(-)

diff --git a/net/l2tp/l2tp_core.h b/net/l2tp/l2tp_core.h
index 2f89d43..a98c854 100644
--- a/net/l2tp/l2tp_core.h
+++ b/net/l2tp/l2tp_core.h
@@ -256,6 +256,7 @@ extern int l2tp_xmit_skb(struct l2tp_session *session, struct sk_buff *skb, int
 
 extern int l2tp_nl_register_ops(enum l2tp_pwtype pw_type, const struct l2tp_nl_cmd_ops *ops);
 extern void l2tp_nl_unregister_ops(enum l2tp_pwtype pw_type);
+int l2tp_ioctl(struct sock *sk, int cmd, unsigned long arg);
 
 /* Session reference counts. Incremented when code obtains a reference
  * to a session.
diff --git a/net/l2tp/l2tp_ip.c b/net/l2tp/l2tp_ip.c
index 07f8b97..f4d30b5 100644
--- a/net/l2tp/l2tp_ip.c
+++ b/net/l2tp/l2tp_ip.c
@@ -11,6 +11,7 @@
 
 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
 
+#include <asm/ioctls.h>
 #include <linux/icmp.h>
 #include <linux/module.h>
 #include <linux/skbuff.h>
@@ -554,6 +555,30 @@ out:
 	return err ? err : copied;
 }
 
+int l2tp_ioctl(struct sock *sk, int cmd, unsigned long arg)
+{
+	struct sk_buff *skb;
+	int amount;
+
+	switch (cmd) {
+	case SIOCOUTQ:
+		amount = sk_wmem_alloc_get(sk);
+		break;
+	case SIOCINQ:
+		spin_lock_bh(&sk->sk_receive_queue.lock);
+		skb = skb_peek(&sk->sk_receive_queue);
+		amount = skb ? skb->len : 0;
+		spin_unlock_bh(&sk->sk_receive_queue.lock);
+		break;
+
+	default:
+		return -ENOIOCTLCMD;
+	}
+
+	return put_user(amount, (int __user *)arg);
+}
+EXPORT_SYMBOL(l2tp_ioctl);
+
 static struct proto l2tp_ip_prot = {
 	.name		   = "L2TP/IP",
 	.owner		   = THIS_MODULE,
@@ -562,7 +587,7 @@ static struct proto l2tp_ip_prot = {
 	.bind		   = l2tp_ip_bind,
 	.connect	   = l2tp_ip_connect,
 	.disconnect	   = l2tp_ip_disconnect,
-	.ioctl		   = udp_ioctl,
+	.ioctl		   = l2tp_ioctl,
 	.destroy	   = l2tp_ip_destroy_sock,
 	.setsockopt	   = ip_setsockopt,
 	.getsockopt	   = ip_getsockopt,
diff --git a/net/l2tp/l2tp_ip6.c b/net/l2tp/l2tp_ip6.c
index db96af9..1536791 100644
--- a/net/l2tp/l2tp_ip6.c
+++ b/net/l2tp/l2tp_ip6.c
@@ -716,7 +716,7 @@ static struct proto l2tp_ip6_prot = {
 	.bind		   = l2tp_ip6_bind,
 	.connect	   = l2tp_ip6_connect,
 	.disconnect	   = l2tp_ip6_disconnect,
-	.ioctl		   = udp_ioctl,
+	.ioctl		   = l2tp_ioctl,
 	.destroy	   = l2tp_ip6_destroy_sock,
 	.setsockopt	   = ipv6_setsockopt,
 	.getsockopt	   = ipv6_getsockopt,
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660506 — [PATCH 3.10 146/250] MIPS: Calculate microMIPS ra properly when unwinding the stack

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 146/250] MIPS: Calculate microMIPS ra properly when unwinding the stack
Message-ID<tPT1L-4Xs-3@gated-at.bofh.it>
In reply to#1660349
From: Paul Burton <paul.burton@imgtec.com>

commit bb9bc4689b9c635714fbcd5d335bad9934a7ebfc upstream.

get_frame_info() calculates the offset of the return address within a
stack frame simply by dividing a the bottom 16 bits of the instruction,
treated as a signed integer, by the size of a long. Whilst this works
for MIPS32 & MIPS64 ISAs where the sw or sd instructions are used, it's
incorrect for microMIPS where encodings differ. The result is that we
typically completely fail to unwind the stack on microMIPS.

Fix this by adjusting is_ra_save_ins() to calculate the return address
offset, and take into account the various different encodings there in
the same place as we consider whether an instruction is storing the
ra/$31 register.

With this we are now able to unwind the stack for kernels targetting the
microMIPS ISA, for example we can produce:

    Call Trace:
    [<80109e1f>] show_stack+0x63/0x7c
    [<8011ea17>] __warn+0x9b/0xac
    [<8011ea45>] warn_slowpath_fmt+0x1d/0x20
    [<8013fe53>] register_console+0x43/0x314
    [<8067c58d>] of_setup_earlycon+0x1dd/0x1ec
    [<8067f63f>] early_init_dt_scan_chosen_stdout+0xe7/0xf8
    [<8066c115>] do_early_param+0x75/0xac
    [<801302f9>] parse_args+0x1dd/0x308
    [<8066c459>] parse_early_options+0x25/0x28
    [<8066c48b>] parse_early_param+0x2f/0x38
    [<8066e8cf>] setup_arch+0x113/0x488
    [<8066c4f3>] start_kernel+0x57/0x328
    ---[ end trace 0000000000000000 ]---

Whereas previously we only produced:

    Call Trace:
    [<80109e1f>] show_stack+0x63/0x7c
    ---[ end trace 0000000000000000 ]---

Signed-off-by: Paul Burton <paul.burton@imgtec.com>
Fixes: 34c2f668d0f6 ("MIPS: microMIPS: Add unaligned access support.")
Cc: Leonid Yegoshin <leonid.yegoshin@imgtec.com>
Cc: linux-mips@linux-mips.org
Patchwork: https://patchwork.linux-mips.org/patch/14532/
Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 arch/mips/kernel/process.c | 83 +++++++++++++++++++++++++++++++++++-----------
 1 file changed, 63 insertions(+), 20 deletions(-)

diff --git a/arch/mips/kernel/process.c b/arch/mips/kernel/process.c
index 427187b1..5a93369 100644
--- a/arch/mips/kernel/process.c
+++ b/arch/mips/kernel/process.c
@@ -214,7 +214,7 @@ struct mips_frame_info {
 #define J_TARGET(pc,target)	\
 		(((unsigned long)(pc) & 0xf0000000) | ((target) << 2))
 
-static inline int is_ra_save_ins(union mips_instruction *ip)
+static inline int is_ra_save_ins(union mips_instruction *ip, int *poff)
 {
 #ifdef CONFIG_CPU_MICROMIPS
 	/*
@@ -227,25 +227,70 @@ static inline int is_ra_save_ins(union mips_instruction *ip)
 	 * microMIPS is way more fun...
 	 */
 	if (mm_insn_16bit(ip->halfword[1])) {
-		return (ip->mm16_r5_format.opcode == mm_swsp16_op &&
-			ip->mm16_r5_format.rt == 31) ||
-		       (ip->mm16_m_format.opcode == mm_pool16c_op &&
-			ip->mm16_m_format.func == mm_swm16_op);
+		switch (ip->mm16_r5_format.opcode) {
+		case mm_swsp16_op:
+			if (ip->mm16_r5_format.rt != 31)
+				return 0;
+
+			*poff = ip->mm16_r5_format.simmediate;
+			*poff = (*poff << 2) / sizeof(ulong);
+			return 1;
+
+		case mm_pool16c_op:
+			switch (ip->mm16_m_format.func) {
+			case mm_swm16_op:
+				*poff = ip->mm16_m_format.imm;
+				*poff += 1 + ip->mm16_m_format.rlist;
+				*poff = (*poff << 2) / sizeof(ulong);
+				return 1;
+
+			default:
+				return 0;
+			}
+
+		default:
+			return 0;
+		}
 	}
-	else {
-		return (ip->mm_m_format.opcode == mm_pool32b_op &&
-			ip->mm_m_format.rd > 9 &&
-			ip->mm_m_format.base == 29 &&
-			ip->mm_m_format.func == mm_swm32_func) ||
-		       (ip->i_format.opcode == mm_sw32_op &&
-			ip->i_format.rs == 29 &&
-			ip->i_format.rt == 31);
+
+	switch (ip->i_format.opcode) {
+	case mm_sw32_op:
+		if (ip->i_format.rs != 29)
+			return 0;
+		if (ip->i_format.rt != 31)
+			return 0;
+
+		*poff = ip->i_format.simmediate / sizeof(ulong);
+		return 1;
+
+	case mm_pool32b_op:
+		switch (ip->mm_m_format.func) {
+		case mm_swm32_func:
+			if (ip->mm_m_format.rd < 0x10)
+				return 0;
+			if (ip->mm_m_format.base != 29)
+				return 0;
+
+			*poff = ip->mm_m_format.simmediate;
+			*poff += (ip->mm_m_format.rd & 0xf) * sizeof(u32);
+			*poff /= sizeof(ulong);
+			return 1;
+		default:
+			return 0;
+		}
+
+	default:
+		return 0;
 	}
 #else
 	/* sw / sd $ra, offset($sp) */
-	return (ip->i_format.opcode == sw_op || ip->i_format.opcode == sd_op) &&
-		ip->i_format.rs == 29 &&
-		ip->i_format.rt == 31;
+	if ((ip->i_format.opcode == sw_op || ip->i_format.opcode == sd_op) &&
+		ip->i_format.rs == 29 && ip->i_format.rt == 31) {
+		*poff = ip->i_format.simmediate / sizeof(ulong);
+		return 1;
+	}
+
+	return 0;
 #endif
 }
 
@@ -368,11 +413,9 @@ static int get_frame_info(struct mips_frame_info *info)
 			}
 			continue;
 		}
-		if (info->pc_offset == -1 && is_ra_save_ins(&insn)) {
-			info->pc_offset =
-				ip->i_format.simmediate / sizeof(long);
+		if (info->pc_offset == -1 &&
+		    is_ra_save_ins(&insn, &info->pc_offset))
 			break;
-		}
 	}
 	if (info->frame_size && info->pc_offset >= 0) /* nested */
 		return 0;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660508 — [PATCH 3.10 048/250] USB: serial: ti_usb_3410_5052: fix NULL-deref at open

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 048/250] USB: serial: ti_usb_3410_5052: fix NULL-deref at open
Message-ID<tPT1L-4Xs-7@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit ef079936d3cd09e63612834fe2698eeada0d8e3f upstream.

Fix NULL-pointer dereference in open() should a malicious device lack
the expected endpoints:

Unable to handle kernel NULL pointer dereference at virtual address 00000030
..
[<bf06a6b0>] (ti_open [ti_usb_3410_5052]) from [<bf02e118>] (serial_port_activate+0x68/0x98 [usbserial])

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/serial/ti_usb_3410_5052.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/drivers/usb/serial/ti_usb_3410_5052.c b/drivers/usb/serial/ti_usb_3410_5052.c
index 0a7c68f..1ccf221 100644
--- a/drivers/usb/serial/ti_usb_3410_5052.c
+++ b/drivers/usb/serial/ti_usb_3410_5052.c
@@ -401,6 +401,13 @@ static int ti_startup(struct usb_serial *serial)
 		goto free_tdev;
 	}
 
+	if (serial->num_bulk_in < serial->num_ports ||
+			serial->num_bulk_out < serial->num_ports) {
+		dev_err(&serial->interface->dev, "missing endpoints\n");
+		status = -ENODEV;
+		goto free_tdev;
+	}
+
 	return 0;
 
 free_tdev:
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


Page 6 of 11 — ← Prev page 1 … 4 5 [6] 7 8 … 11  Next page →

Back to top | Article view | linux.kernel


csiph-web