Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1660349 > unrolled thread
| Started by | Willy Tarreau <w@1wt.eu> |
|---|---|
| First post | 2017-06-08 01:10 +0200 |
| Last post | 2017-06-08 06:30 +0200 |
| Articles | 20 on this page of 214 — 3 participants |
Back to article view | Back to linux.kernel
[PATCH 3.10 000/250] 3.10.106-stable review Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 188/250] uwb: hwa-rc: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 167/250] USB: serial: io_ti: fix NULL-deref in interrupt callback Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 136/250] mfd: pm8921: Potential NULL dereference in pm8921_remove() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 099/250] ubifs: Fix journal replay wrt. xattr nodes Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 102/250] arm64/ptrace: Reject attempts to set incomplete hardware breakpoint fields Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 223/250] Staging: vt6655-6: potential NULL dereference in hostap_disable_hostapd() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 006/250] KVM: x86: Introduce segmented_write_std Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 181/250] Input: hanwang - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 049/250] USB: serial: io_edgeport: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 090/250] powerpc/ibmebus: Fix further device reference leaks Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 172/250] net: net_enable_timestamp() can be called from irq contexts Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 159/250] USB: serial: digi_acceleport: fix OOB data sanity check Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 139/250] vti4: Don't count header length twice. Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 178/250] net: properly release sk_frag.page Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
[PATCH 3.10 229/250] USB: dummy-hcd: fix bug in stop_activity (handle ep0) Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 123/250] packet: fix races in fanout_add() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 135/250] ocfs2: do not write error flag to user structure we cannot copy from/to Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 107/250] drm/i915: Don't leak edid in intel_crt_detect_ddc() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 116/250] drm/i915: fix use-after-free in page_flip_completed() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 202/250] metag/usercopy: Fix alignment error checking Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 236/250] ipv6: fix ip6_tnl_parse_tlv_enc_lim() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 134/250] goldfish: Sanitize the broken interrupt handler Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 234/250] xc2028: unlock on error in xc2028_set_config() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 158/250] dm: flush queued bios when process blocks to avoid deadlock Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 013/250] xfrm_user: validate XFRM_MSG_NEWAE incoming ESN size harder Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 120/250] ip6_gre: fix ip6gre_err() invalid reads Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 160/250] USB: serial: digi_acceleport: fix OOB-event processing Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 217/250] net: phy: handle state correctly in phy_stop_machine Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 062/250] staging: iio: ad7606: fix improper setting of oversampling pins Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 016/250] KEYS: fix keyctl_set_reqkey_keyring() to not leak thread keyrings Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 197/250] USB: OHCI: Fix race between ED unlink and URB submission Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 100/250] arm64/ptrace: Preserve previous registers for short regset write Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 133/250] x86/platform/goldfish: Prevent unconditional loading Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 220/250] ARM: dts: imx31: move CCM device node to AIPS2 bus devices Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 075/250] gro: Enter slow-path if there is no tailroom Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 083/250] USB: serial: ch341: fix open error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 230/250] mm/init: fix zone boundary creation Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 204/250] metag/usercopy: Set flags before ADDZ Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 149/250] scsi: aacraid: Reorder Adapter status check Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 101/250] arm64/ptrace: Avoid uninitialised struct padding in fpr_set() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 046/250] USB: serial: iuu_phoenix: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 026/250] ext4: fix stack memory corruption with 64k block size Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
[PATCH 3.10 012/250] xfrm_user: validate XFRM_MSG_NEWAE XFRMA_REPLAY_ESN_VAL replay_window Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 201/250] ring-buffer: Fix return value check in test_ringbuffer() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 091/250] powerpc/ibmebus: Fix device reference leaks in sysfs interface Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 118/250] ipv4: keep skb->dst around in presence of IP options Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 113/250] ARM: 8643/3: arm/ptrace: Preserve previous registers for short regset write Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 020/250] hotplug: Make register and unregister notifier API symmetric Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 156/250] ktest: Fix child exit code processing Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 078/250] powerpc: Fix build warning on 32-bit PPC Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 103/250] ARM: ux500: fix prcmu_is_cpu_in_wfi() calculation Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 060/250] ALSA: usb-audio: Fix bogus error return in snd_usb_create_stream() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 147/250] MIPS: Handle microMIPS jumps in the same way as MIPS32/MIPS64 jumps Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 036/250] IB/multicast: Check ib_find_pkey() return value Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 073/250] net, sched: fix soft lockup in tc_classify Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 173/250] dccp/tcp: fix routing redirect race Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 087/250] USB: serial: ch341: fix modem-control and B0 handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 203/250] metag/usercopy: Add early abort to copy_to_user Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 063/250] usb: dwc3: gadget: always unmap EP0 requests Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 094/250] perf scripting: Avoid leaking the scripting_context variable Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 219/250] MIPS: KGDB: Use kernel context for sleeping threads Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 132/250] USB: serial: ark3116: fix register-accessor error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
[PATCH 3.10 130/250] USB: serial: spcp8x5: fix modem-status handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 227/250] ping: implement proper locking Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 092/250] IB/mlx4: Set traffic class in AH Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 040/250] USB: serial: quatech2: fix sleep-while-atomic in close Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 187/250] uwb: i1480-dfu: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 242/250] kvm: exclude ioeventfd from counting kvm_io_range limit Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 222/250] tun: Fix TUN_PKT_STRIP setting Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 068/250] scsi: mvsas: fix command_active typo Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 207/250] s390/decompressor: fix initrd corruption caused by bss clear Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 161/250] MIPS: ip27: Disable qlge driver in defconfig Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 104/250] ite-cir: initialize use_demodulator before using it Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 228/250] USB: fix problems with duplicate endpoint addresses Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 143/250] MIPS: Prevent unaligned accesses during stack unwinding Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 208/250] net/mlx4_en: Fix bad WQE issue Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 119/250] netlabel: out of bound access in cipso_v4_validate() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 065/250] hwmon: (ds620) Fix overflows seen when writing temperature limits Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 162/250] tracing: Add #undef to fix compile error Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 177/250] xen: do not re-use pirq number cached in pci device msi msg data Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 144/250] MIPS: Fix get_frame_info() handling of microMIPS function size Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 237/250] ipv6: pointer math error in ip6_tnl_parse_tlv_enc_lim() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 216/250] netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT" failed in 64bit kernel Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 193/250] ALSA: ctxfi: Fix the incorrect check of dma_set_mask() call Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 206/250] metag/usercopy: Add missing fixups Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 225/250] perf trace: Use the syscall raw_syscalls:sys_enter timestamp Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 072/250] ser_gigaset: return -ENOMEM on error instead of success Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 051/250] USB: serial: cyberjack: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 155/250] IB/ipoib: Fix deadlock between rmmod and set_mode Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 175/250] perf/core: Fix event inheritance on fork() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 211/250] powerpc: Disable HFSCR[TM] if TM is not supported Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 192/250] ALSA: ctxfi: Fallback DMA mask to 32bit Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 232/250] Drivers: hv: avoid vfree() on crash Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
[PATCH 3.10 249/250] dccp/tcp: do not inherit mc_list from parent Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 033/250] scsi: zfcp: fix rport unblock race with LUN recovery Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 171/250] locking/static_keys: Add static_key_{en,dis}able() helpers Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 096/250] svcrpc: don't leak contexts on PROC_DESTROY Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 055/250] USB: serial: mos7720: fix use-after-free on probe errors Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 125/250] net: socket: fix recvmmsg not returning error from sock_error Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 039/250] USB: serial: omninet: fix NULL-derefs at open and disconnect Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 117/250] net: use a work queue to defer net_disable_timestamp() work Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 077/250] gro: Disable frag0 optimization on IPv6 ext headers Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 064/250] cris: Only build flash rescue image if CONFIG_ETRAX_AXISFLASHMAP is selected Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 110/250] net: fix harmonize_features() vs NETIF_F_HIGHDMA Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 180/250] Input: ims-pcu - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 244/250] TTY: n_hdlc, fix lockdep false positive Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 235/250] xc2028: Fix use-after-free bug properly Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 148/250] uvcvideo: Fix a wrong macro Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 004/250] libceph: don't set weight to IN when OSD is destroyed Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 200/250] ptrace: fix PTRACE_LISTEN race corrupting task->state Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 250/250] char: lp: fix possible integer overflow in lp_setup() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 239/250] sctp: avoid BUG_ON on sctp_wait_for_sndbuf Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 080/250] mm/hugetlb.c: fix reservation race when freeing surplus pages Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 041/250] USB: serial: pl2303: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 168/250] USB: serial: io_ti: fix information leak in completion handler Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 233/250] xc2028: avoid use after free Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
[PATCH 3.10 122/250] l2tp: do not use udp_ioctl() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 146/250] MIPS: Calculate microMIPS ra properly when unwinding the stack Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 048/250] USB: serial: ti_usb_3410_5052: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 231/250] can: Fix kernel panic at security_sock_rcv_skb Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 182/250] Input: yealink - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 183/250] Input: cm109 - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 240/250] sctp: deny peeloff operation on asocs with threads sleeping on it Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 176/250] isdn/gigaset: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 052/250] USB: serial: kobil_sct: fix NULL-deref in write Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 153/250] NFSv4: fix getacl head length estimation Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 082/250] USB: serial: ch341: fix initial modem-control state Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 190/250] ext4: mark inode dirty after converting inline directory Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 086/250] USB: serial: ch341: fix resume after reset Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 127/250] USB: serial: ftdi_sio: fix modem-status error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 218/250] l2tp: take reference on sessions being dumped Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 015/250] KEYS: Change the name of the dead type to ".dead" to prevent user access Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 198/250] i2c: at91: manage unexpected RXRDY flag when starting a transfer Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 021/250] Btrfs: fix tree search logic when replaying directory entry deletes Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 034/250] ftrace/x86_32: Set ftrace_stub to weak to prevent gcc from using short jumps to it Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 184/250] USB: uss720: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 005/250] KVM: x86: fix emulation of "MOV SS, null selector" Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 151/250] fuse: add missing FR_FORCE Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 154/250] s390/qdio: clear DSCI prior to scanning multiple input queues Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 224/250] net: sctp: rework multihoming retransmission path selection to rfc4960 Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 247/250] fs: exec: apply CLOEXEC before changing dumpable task flags Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 191/250] scsi: libsas: fix ata xfer length Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 032/250] scsi: zfcp: do not trace pure benign residual HBA responses at default level Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 088/250] x86/cpu: Fix bootup crashes by sanitizing the argument of the 'clearcpuid=' command-line option Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 189/250] mmc: ushc: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 141/250] MIPS: OCTEON: Fix copy_from_user fault handling for large buffers Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 108/250] s5k4ecgx: select CRC32 helper Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 150/250] ath9k: use correct OTP register offsets for the AR9340 and AR9550 Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 124/250] packet: Do not call fanout_release from atomic contexts Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 152/250] RDMA/core: Fix incorrect structure packing for booleans Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
[PATCH 3.10 076/250] gro: use min_t() in skb_gro_reset_offset() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 105/250] fuse: do not use iocb after it may have been freed Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 245/250] tty: n_hdlc: get rid of racy n_hdlc.tbuf Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 067/250] iommu/amd: Fix the left value check of cmd buffer Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 164/250] USB: serial: omninet: fix reference leaks at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 140/250] net/sched: em_meta: Fix 'meta vlan' to correctly recognize zero VID frames Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 029/250] f2fs: set ->owner for debugfs status file's file_operations Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 058/250] usb: xhci-mem: use passed in GFP flags instead of GFP_KERNEL Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 031/250] scsi: zfcp: fix use-after-"free" in FC ingress path after TMF Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 023/250] block_dev: don't test bdev->bd_contains when it is not stable Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 157/250] nlm: Ensure callback code also checks that the files match Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 089/250] NFSv4.1: nfs4_fl_prepare_ds must be careful about reporting success. Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 209/250] net/mlx4_core: Fix racy CQ (Completion Queue) free Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 112/250] svcrpc: fix oops in absence of krb5 module Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
Re: [PATCH 3.10 112/250] svcrpc: fix oops in absence of krb5 module Simo Sorce <simo@redhat.com> - 2017-06-08 10:20 +0200
[PATCH 3.10 114/250] mac80211: Fix adding of mesh vendor IEs Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 246/250] ipv6: handle -EFAULT from skb_copy_bits Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 138/250] net: 6lowpan: fix lowpan_header_create non-compression memcpy call Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 059/250] usb: musb: Fix trying to free already-free IRQ 4 Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 137/250] drm/nv50/disp: min/max are reversed in nv50_crtc_gamma_set() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 097/250] mmc: mxs-mmc: Fix additional cycles after transmission stop Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 205/250] metag/usercopy: Fix src fixup in from user rapf loops Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 165/250] USB: iowarrior: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 131/250] USB: serial: opticon: fix CTS retrieval at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 215/250] ring-buffer: Have ring_buffer_iter_empty() return true when empty Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 098/250] mtd: nand: xway: disable module support Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 044/250] USB: serial: io_ti: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 212/250] pegasus: Use heap buffers for all register access Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 214/250] tracing: Allocate the snapshot buffer before enabling probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 106/250] crypto: caam - fix non-hmac hashes Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 169/250] vxlan: correctly validate VXLAN ID against VXLAN_N_VID Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 002/250] crypto: crypto_memneq - add equality testing of memory regions w/o timing leaks Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 071/250] powerpc/pci/rpadlpar: Fix device reference leaks Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 194/250] ACPI / PNP: Avoid conflicting resource reservations Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 047/250] USB: serial: garmin_gps: fix memory leak on failed URB submit Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 018/250] locking/rtmutex: Prevent dequeue vs. unlock race Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 195/250] ACPI / resources: free memory on error in add_region_before() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 179/250] net: unix: properly re-increment inflight counter of GC discarded candidates Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 054/250] USB: serial: mos7720: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
[PATCH 3.10 074/250] net: stmmac: Fix race between stmmac_drv_probe and stmmac_open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 042/250] USB: serial: keyspan_pda: verify endpoints at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 028/250] ext4: return -ENOMEM instead of success Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 038/250] usb: gadget: composite: Test get_alt() presence instead of set_alt() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 017/250] ext4: fix data exposure after a crash Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 025/250] ext4: fix mballoc breakage with 64k block size Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 030/250] block: protect iterate_bdevs() against concurrent close Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 111/250] tcp: initialize max window for a new fastopen socket Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 009/250] fbdev: color map copying bounds checking Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 126/250] USB: serial: mos7840: fix another NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 035/250] IB/mad: Fix an array index check Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 050/250] USB: serial: oti6858: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 001/250] packet: fix race condition in packet_set_ring Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 081/250] USB: serial: kl5kusb105: fix line-state error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 079/250] Input: i8042 - add Pegatron touchpad to noloop table Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 037/250] powerpc: Convert cmp to cmpd in idle enter sequence Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 061/250] USB: serial: kl5kusb105: abort on open exception path Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 024/250] crypto: caam - fix AEAD givenc descriptors Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 010/250] selinux: fix off-by-one in setprocattr Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 043/250] USB: serial: spcp8x5: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 142/250] MIPS: Clear ISA bit correctly in get_frame_info() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
[PATCH 3.10 019/250] m68k: Fix ndelay() macro Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
Re: [PATCH 3.10 000/250] 3.10.106-stable review Guenter Roeck <linux@roeck-us.net> - 2017-06-08 02:40 +0200
Re: [PATCH 3.10 000/250] 3.10.106-stable review Willy Tarreau <w@1wt.eu> - 2017-06-08 06:30 +0200
Page 1 of 11 [1] 2 3 … 11 Next page →
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 000/250] 3.10.106-stable review |
| Message-ID | <tPSfn-4Fa-3@gated-at.bofh.it> |
This is the start of the stable review cycle for the 3.10.106 release.
It was build-tested on x86_64 with allmodconfig.
All patches will be posted as a response to this one. If anyone has any
issue with these being applied, please let me know. If anyone thinks some
important patches are missing and should be added prior to the release,
please report them quickly with their respective mainline commit IDs.
Responses should be made by Wed Jun 14 00:43:43 CEST 2017.
Anything received after that time might be too late. If someone
wants a bit more time for a deeper review, please let me know.
The whole patch series can be found in one patch at :
https://kernel.org/pub/linux/kernel/v3.x/stable-review/patch-3.10.106-rc1.gz
The shortlog and diffstat are appended below.
Thanks,
Willy
===============
Alan Stern (3):
USB: OHCI: Fix race between ED unlink and URB submission
USB: fix problems with duplicate endpoint addresses
USB: dummy-hcd: fix bug in stop_activity (handle ep0)
Aleksa Sarai (1):
fs: exec: apply CLOEXEC before changing dumpable task flags
Alex Porosanu (1):
crypto: caam - fix AEAD givenc descriptors
Alexander Popov (1):
tty: n_hdlc: get rid of racy n_hdlc.tbuf
Alexey Kodanev (1):
tcp: initialize max window for a new fastopen socket
Amos Kong (1):
kvm: exclude ioeventfd from counting kvm_io_range limit
Ander Conselvan de Oliveira (1):
drm/i915: Don't leak edid in intel_crt_detect_ddc()
Andrew Lunn (1):
ipv4: igmp: Allow removing groups from a removed interface
Andrey Ryabinin (1):
drm/i915: fix use-after-free in page_flip_completed()
Andrey Ulanov (1):
net: unix: properly re-increment inflight counter of GC discarded
candidates
Andy Shevchenko (1):
platform/x86: intel_mid_powerbtn: Set IRQ_ONESHOT
Andy Whitcroft (2):
xfrm_user: validate XFRM_MSG_NEWAE XFRMA_REPLAY_ESN_VAL replay_window
xfrm_user: validate XFRM_MSG_NEWAE incoming ESN size harder
Anoob Soman (1):
packet: Do not call fanout_release from atomic contexts
Arnaldo Carvalho de Melo (2):
perf scripting: Avoid leaking the scripting_context variable
perf trace: Use the syscall raw_syscalls:sys_enter timestamp
Arnd Bergmann (4):
scsi: mvsas: fix command_active typo
ARM: ux500: fix prcmu_is_cpu_in_wfi() calculation
s5k4ecgx: select CRC32 helper
MIPS: ip27: Disable qlge driver in defconfig
Bart Van Assche (2):
IB/mad: Fix an array index check
IB/multicast: Check ib_find_pkey() return value
Ben Hutchings (3):
ocfs2: do not write error flag to user structure we cannot copy
from/to
pegasus: Use heap buffers for all register access
rtl8150: Use heap buffers for all register access
Benjamin Block (1):
scsi: zfcp: fix use-after-"free" in FC ingress path after TMF
Benjamin Herrenschmidt (1):
powerpc: Disable HFSCR[TM] if TM is not supported
Boris Brezillon (1):
m68k: Fix ndelay() macro
Chandan Rajendra (2):
ext4: fix mballoc breakage with 64k block size
ext4: fix stack memory corruption with 64k block size
Christian Lamparter (1):
ath9k: use correct OTP register offsets for the AR9340 and AR9550
Dan Carpenter (11):
ext4: return -ENOMEM instead of success
usb: xhci-mem: use passed in GFP flags instead of GFP_KERNEL
target/iscsi: Fix double free in lio_target_tiqn_addtpg()
mmc: mmc_test: Uninitialized return value
ser_gigaset: return -ENOMEM on error instead of success
mfd: pm8921: Potential NULL dereference in pm8921_remove()
drm/nv50/disp: min/max are reversed in nv50_crtc_gamma_set()
ACPI / resources: free memory on error in add_region_before()
Staging: vt6655-6: potential NULL dereference in
hostap_disable_hostapd()
xc2028: unlock on error in xc2028_set_config()
ipv6: pointer math error in ip6_tnl_parse_tlv_enc_lim()
Dan Streetman (1):
xen: do not re-use pirq number cached in pci device msi msg data
Daniel Borkmann (3):
net, sched: fix soft lockup in tc_classify
net: 6lowpan: fix lowpan_header_create non-compression memcpy call
net: sctp: rework multihoming retransmission path selection to rfc4960
Darrick J. Wong (1):
ext4: reject inodes with negative size
Dave Jones (1):
ipv6: handle -EFAULT from skb_copy_bits
Dave Martin (4):
arm64/ptrace: Preserve previous registers for short regset write
arm64/ptrace: Avoid uninitialised struct padding in fpr_set()
arm64/ptrace: Reject attempts to set incomplete hardware breakpoint
fields
ARM: 8643/3: arm/ptrace: Preserve previous registers for short regset
write
David Hildenbrand (1):
KVM: kvm_io_bus_unregister_dev() should never fail
David Howells (2):
KEYS: Disallow keyrings beginning with '.' to be joined as session
keyrings
KEYS: Change the name of the dead type to ".dead" to prevent user
access
Eric Biggers (2):
KEYS: fix keyctl_set_reqkey_keyring() to not leak thread keyrings
ext4: mark inode dirty after converting inline directory
Eric Dumazet (15):
tcp: avoid infinite loop in tcp_splice_read()
gro: use min_t() in skb_gro_reset_offset()
net: fix harmonize_features() vs NETIF_F_HIGHDMA
net: use a work queue to defer net_disable_timestamp() work
ipv4: keep skb->dst around in presence of IP options
netlabel: out of bound access in cipso_v4_validate()
ip6_gre: fix ip6gre_err() invalid reads
l2tp: do not use udp_ioctl()
packet: fix races in fanout_add()
net: net_enable_timestamp() can be called from irq contexts
net: properly release sk_frag.page
ping: implement proper locking
can: Fix kernel panic at security_sock_rcv_skb
ipv6: fix ip6_tnl_parse_tlv_enc_lim()
dccp/tcp: do not inherit mc_list from parent
Eugenia Emantayev (1):
net/mlx4_en: Fix bad WQE issue
Eva Rachel Retuya (1):
staging: iio: ad7606: fix improper setting of oversampling pins
Felipe Balbi (1):
usb: dwc3: gadget: always unmap EP0 requests
Feras Daoud (1):
IB/ipoib: Fix deadlock between rmmod and set_mode
Florian Fainelli (1):
net: stmmac: Fix race between stmmac_drv_probe and stmmac_open
Geert Uytterhoeven (1):
char: Drop bogus dependency of DEVPORT on !M68K
Gu Zheng (1):
tmpfs: clear S_ISGID when setting posix ACLs
Guennadi Liakhovetski (1):
uvcvideo: Fix a wrong macro
Guenter Roeck (2):
cris: Only build flash rescue image if CONFIG_ETRAX_AXISFLASHMAP is
selected
hwmon: (ds620) Fix overflows seen when writing temperature limits
Guillaume Nault (1):
l2tp: take reference on sessions being dumped
Hauke Mehrtens (1):
mtd: nand: xway: disable module support
Herbert Xu (3):
gro: Enter slow-path if there is no tailroom
gro: Disable frag0 optimization on IPv6 ext headers
tun: Fix TUN_PKT_STRIP setting
Hongxu Jia (1):
netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT"
failed in 64bit kernel
Huang Rui (1):
iommu/amd: Fix the left value check of cmd buffer
Ilya Dryomov (1):
libceph: don't set weight to IN when OSD is destroyed
J. Bruce Fields (3):
svcrpc: don't leak contexts on PROC_DESTROY
svcrpc: fix oops in absence of krb5 module
NFSv4: fix getacl head length estimation
Jack Morgenstein (1):
net/mlx4_core: Fix racy CQ (Completion Queue) free
James Cowgill (1):
MIPS: OCTEON: Fix copy_from_user fault handling for large buffers
James Hogan (6):
metag/usercopy: Fix alignment error checking
metag/usercopy: Add early abort to copy_to_user
metag/usercopy: Set flags before ADDZ
metag/usercopy: Fix src fixup in from user rapf loops
metag/usercopy: Add missing fixups
MIPS: KGDB: Use kernel context for sleeping threads
James Yonan (1):
crypto: crypto_memneq - add equality testing of memory regions w/o
timing leaks
Jan Kara (2):
posix_acl: Clear SGID bit when setting file permissions
ext4: fix data exposure after a crash
Jason Gunthorpe (1):
RDMA/core: Fix incorrect structure packing for booleans
Jiri Slaby (1):
TTY: n_hdlc, fix lockdep false positive
Johan Hovold (57):
USB: serial: kl5kusb105: fix open error path
USB: serial: omninet: fix NULL-derefs at open and disconnect
USB: serial: quatech2: fix sleep-while-atomic in close
USB: serial: pl2303: fix NULL-deref at open
USB: serial: keyspan_pda: verify endpoints at probe
USB: serial: spcp8x5: fix NULL-deref at open
USB: serial: io_ti: fix NULL-deref at open
USB: serial: io_ti: fix another NULL-deref at open
USB: serial: iuu_phoenix: fix NULL-deref at open
USB: serial: garmin_gps: fix memory leak on failed URB submit
USB: serial: ti_usb_3410_5052: fix NULL-deref at open
USB: serial: io_edgeport: fix NULL-deref at open
USB: serial: oti6858: fix NULL-deref at open
USB: serial: cyberjack: fix NULL-deref at open
USB: serial: kobil_sct: fix NULL-deref in write
USB: serial: mos7840: fix NULL-deref at open
USB: serial: mos7720: fix NULL-deref at open
USB: serial: mos7720: fix use-after-free on probe errors
USB: serial: mos7720: fix parport use-after-free on probe errors
USB: serial: mos7720: fix parallel probe
powerpc/pci/rpadlpar: Fix device reference leaks
USB: serial: kl5kusb105: fix line-state error handling
USB: serial: ch341: fix initial modem-control state
USB: serial: ch341: fix open error handling
USB: serial: ch341: fix control-message error handling
USB: serial: ch341: fix open and resume after B0
USB: serial: ch341: fix resume after reset
USB: serial: ch341: fix modem-control and B0 handling
powerpc/ibmebus: Fix further device reference leaks
powerpc/ibmebus: Fix device reference leaks in sysfs interface
USB: serial: mos7840: fix another NULL-deref at open
USB: serial: ftdi_sio: fix modem-status error handling
USB: serial: ftdi_sio: fix extreme low-latency setting
USB: serial: ftdi_sio: fix line-status over-reporting
USB: serial: spcp8x5: fix modem-status handling
USB: serial: opticon: fix CTS retrieval at open
USB: serial: ark3116: fix register-accessor error handling
USB: serial: digi_acceleport: fix OOB data sanity check
USB: serial: digi_acceleport: fix OOB-event processing
USB: serial: safe_serial: fix information leak in completion handler
USB: serial: omninet: fix reference leaks at open
USB: iowarrior: fix NULL-deref at probe
USB: iowarrior: fix NULL-deref in write
USB: serial: io_ti: fix NULL-deref in interrupt callback
USB: serial: io_ti: fix information leak in completion handler
isdn/gigaset: fix NULL-deref at probe
Input: ims-pcu - validate number of endpoints before using them
Input: hanwang - validate number of endpoints before using them
Input: yealink - validate number of endpoints before using them
Input: cm109 - validate number of endpoints before using them
USB: uss720: fix NULL-deref at probe
USB: idmouse: fix NULL-deref at probe
USB: wusbcore: fix NULL-deref at probe
uwb: i1480-dfu: fix NULL-deref at probe
uwb: hwa-rc: fix NULL-deref at probe
mmc: ushc: fix NULL-deref at probe
USB: usbtmc: add missing endpoint sanity check
John Garry (1):
scsi: libsas: fix ata xfer length
Jon Maxwell (1):
dccp/tcp: fix routing redirect race
Julian Anastasov (1):
ipv4: mask tos for input route
Julian Wiedmann (1):
s390/qdio: clear DSCI prior to scanning multiple input queues
Kees Cook (1):
fbdev: color map copying bounds checking
Keno Fischer (1):
mm/huge_memory.c: respect FOLL_FORCE/FOLL_COW for thp
Krzysztof Opasiak (1):
usb: gadget: composite: Test get_alt() presence instead of set_alt()
Larry Finger (1):
powerpc: Fix build warning on 32-bit PPC
Li RongQing (1):
ipv6: fix the use of pcpu_tstats in ip6_tunnel
Ludovic Desroches (1):
i2c: at91: manage unexpected RXRDY flag when starting a transfer
Lukasz Odzioba (1):
x86/cpu: Fix bootup crashes by sanitizing the argument of the
'clearcpuid=' command-line option
Maor Gottlieb (1):
IB/mlx4: Set traffic class in AH
Marcelo Henrique Cerri (1):
s390/decompressor: fix initrd corruption caused by bss clear
Marcelo Ricardo Leitner (2):
sctp: avoid BUG_ON on sctp_wait_for_sndbuf
sctp: deny peeloff operation on asocs with threads sleeping on it
Marcos Paulo de Souza (1):
Input: i8042 - add Pegatron touchpad to noloop table
Matthias Schiffer (1):
vxlan: correctly validate VXLAN ID against VXLAN_N_VID
Mauro Carvalho Chehab (1):
xc2028: avoid use after free
Maxime Jayat (1):
net: socket: fix recvmmsg not returning error from sock_error
Michal Hocko (1):
hotplug: Make register and unregister notifier API symmetric
Mike Kravetz (1):
mm/hugetlb.c: fix reservation race when freeing surplus pages
Miklos Szeredi (1):
fuse: add missing FR_FORCE
Mikulas Patocka (1):
dm: flush queued bios when process blocks to avoid deadlock
Nathan Sullivan (1):
net: phy: handle state correctly in phy_stop_machine
NeilBrown (2):
block_dev: don't test bdev->bd_contains when it is not stable
NFSv4.1: nfs4_fl_prepare_ds must be careful about reporting success.
Nicolai Stange (1):
f2fs: set ->owner for debugfs status file's file_operations
Nicolas Iooss (1):
ite-cir: initialize use_demodulator before using it
Oliver O'Halloran (1):
mm/init: fix zone boundary creation
Pan Bian (2):
USB: serial: kl5kusb105: abort on open exception path
clk: clk-wm831x: fix a logic error
Paolo Bonzini (1):
KVM: x86: fix emulation of "MOV SS, null selector"
Paul Burton (6):
MIPS: Clear ISA bit correctly in get_frame_info()
MIPS: Prevent unaligned accesses during stack unwinding
MIPS: Fix get_frame_info() handling of microMIPS function size
MIPS: Fix is_jump_ins() handling of 16b microMIPS instructions
MIPS: Calculate microMIPS ra properly when unwinding the stack
MIPS: Handle microMIPS jumps in the same way as MIPS32/MIPS64 jumps
Peter Xu (1):
KVM: x86: clear bus pointer when destroyed
Peter Zijlstra (2):
locking/static_keys: Add static_key_{en,dis}able() helpers
perf/core: Fix event inheritance on fork()
Philip Pettersson (1):
packet: fix race condition in packet_set_ring
Rabin Vincent (1):
block: protect iterate_bdevs() against concurrent close
Rafael J. Wysocki (2):
ACPI / PNP: Avoid conflicting resource reservations
ACPI / PNP: Reserve ACPI resources at the fs_initcall_sync stage
Raghava Aditya Renukunta (1):
scsi: aacraid: Reorder Adapter status check
Richard Weinberger (1):
ubifs: Fix journal replay wrt. xattr nodes
Rik van Riel (1):
tracing: Add #undef to fix compile error
Robbie Ko (1):
Btrfs: fix tree search logic when replaying directory entry deletes
Robert Doebbelin (1):
fuse: do not use iocb after it may have been freed
Roman Mashak (1):
net sched actions: decrement module reference count after table flush.
Russell King (1):
crypto: caam - fix non-hmac hashes
Ryan Ware (1):
EVM: Use crypto_memneq() for digest comparisons
Saeed Mahameed (1):
IB/mlx4: Fix port query for 56Gb Ethernet links
Segher Boessenkool (1):
powerpc: Convert cmp to cmpd in idle enter sequence
Shmulik Ladkani (1):
net/sched: em_meta: Fix 'meta vlan' to correctly recognize zero VID
frames
Stefan Wahren (1):
mmc: mxs-mmc: Fix additional cycles after transmission stop
Steffen Klassert (1):
vti4: Don't count header length twice.
Steffen Maier (3):
scsi: zfcp: do not trace pure benign residual HBA responses at default
level
scsi: zfcp: fix rport unblock race with LUN recovery
scsi: zfcp: fix use-after-free by not tracing WKA port open/close on
failed send
Stephen Smalley (1):
selinux: fix off-by-one in setprocattr
Steve Rutherford (1):
KVM: x86: Introduce segmented_write_std
Steven Rostedt (Red Hat) (1):
ftrace/x86_32: Set ftrace_stub to weak to prevent gcc from using short
jumps to it
Steven Rostedt (VMware) (3):
ktest: Fix child exit code processing
tracing: Allocate the snapshot buffer before enabling probe
ring-buffer: Have ring_buffer_iter_empty() return true when empty
Takashi Iwai (4):
ALSA: usb-audio: Fix bogus error return in snd_usb_create_stream()
ALSA: ctxfi: Fallback DMA mask to 32bit
ALSA: ctxfi: Fix the incorrect check of dma_set_mask() call
xc2028: Fix use-after-free bug properly
Thomas Gleixner (3):
locking/rtmutex: Prevent dequeue vs. unlock race
x86/platform/goldfish: Prevent unconditional loading
goldfish: Sanitize the broken interrupt handler
Thorsten Horstmann (1):
mac80211: Fix adding of mesh vendor IEs
Tony Lindgren (1):
usb: musb: Fix trying to free already-free IRQ 4
Trond Myklebust (1):
nlm: Ensure callback code also checks that the files match
Vitaly Kuznetsov (1):
Drivers: hv: avoid vfree() on crash
Vladimir Zapolskiy (3):
ARM: dts: imx31: fix clock control module interrupts description
ARM: dts: imx31: move CCM device node to AIPS2 bus devices
ARM: dts: imx31: fix AVIC base address
WANG Cong (1):
ping: fix a null pointer dereference
Wei Yongjun (1):
ring-buffer: Fix return value check in test_ringbuffer()
Willy Tarreau (1):
char: lp: fix possible integer overflow in lp_setup()
bsegall@google.com (1):
ptrace: fix PTRACE_LISTEN race corrupting task->state
.../devicetree/bindings/clock/imx31-clock.txt | 2 +-
Documentation/kernel-parameters.txt | 4 +
arch/arm/boot/dts/imx31.dtsi | 18 +--
arch/arm/kernel/ptrace.c | 2 +-
arch/arm/mach-ux500/pm.c | 4 +-
arch/arm64/include/uapi/asm/ptrace.h | 1 +
arch/arm64/kernel/ptrace.c | 11 +-
arch/cris/boot/rescue/Makefile | 8 ++
arch/m68k/include/asm/delay.h | 2 +-
arch/metag/lib/usercopy.c | 146 ++++++++++++++------
arch/mips/cavium-octeon/octeon-memcpy.S | 20 +--
arch/mips/configs/ip27_defconfig | 1 -
arch/mips/kernel/kgdb.c | 48 +++++--
arch/mips/kernel/process.c | 153 +++++++++++++--------
arch/powerpc/kernel/ibmebus.c | 16 ++-
arch/powerpc/kernel/idle_power7.S | 2 +-
arch/powerpc/kernel/misc_32.S | 2 +-
arch/powerpc/kernel/setup_64.c | 9 ++
arch/s390/boot/compressed/misc.c | 35 ++---
arch/x86/kernel/cpu/common.c | 2 +-
arch/x86/kernel/entry_32.S | 4 +-
arch/x86/kvm/emulate.c | 66 +++++++--
arch/x86/pci/xen.c | 23 +---
arch/x86/platform/goldfish/goldfish.c | 14 +-
crypto/Makefile | 7 +-
crypto/asymmetric_keys/rsa.c | 5 +-
crypto/authenc.c | 6 +-
crypto/authencesn.c | 8 +-
crypto/ccm.c | 4 +-
crypto/gcm.c | 2 +-
crypto/memneq.c | 138 +++++++++++++++++++
drivers/acpi/osl.c | 6 +-
drivers/char/Kconfig | 1 -
drivers/char/lp.c | 6 +-
drivers/clk/clk-wm831x.c | 2 +-
drivers/crypto/caam/caamalg.c | 4 +-
drivers/crypto/caam/caamhash.c | 1 +
drivers/gpu/drm/i915/intel_crt.c | 9 +-
drivers/gpu/drm/i915/intel_display.c | 4 +-
drivers/gpu/drm/nouveau/nv50_display.c | 2 +-
drivers/hv/hv.c | 5 +-
drivers/hv/hyperv_vmbus.h | 2 +-
drivers/hv/vmbus_drv.c | 4 +-
drivers/hwmon/ds620.c | 2 +-
drivers/i2c/busses/i2c-at91.c | 36 +++--
drivers/infiniband/core/mad.c | 2 +-
drivers/infiniband/core/multicast.c | 7 +-
drivers/infiniband/hw/mlx4/ah.c | 6 +-
drivers/infiniband/hw/mlx4/main.c | 8 +-
drivers/infiniband/ulp/ipoib/ipoib_cm.c | 12 +-
drivers/infiniband/ulp/ipoib/ipoib_main.c | 6 +-
drivers/input/misc/cm109.c | 4 +
drivers/input/misc/ims-pcu.c | 4 +
drivers/input/misc/yealink.c | 4 +
drivers/input/serio/i8042-x86ia64io.h | 6 +
drivers/input/tablet/hanwang.c | 3 +
drivers/iommu/amd_iommu.c | 2 +-
drivers/isdn/gigaset/bas-gigaset.c | 3 +
drivers/isdn/gigaset/ser-gigaset.c | 4 +-
drivers/md/dm.c | 55 ++++++++
drivers/media/i2c/Kconfig | 1 +
drivers/media/rc/ite-cir.c | 2 +
drivers/media/tuners/tuner-xc2028.c | 34 ++---
drivers/media/usb/uvc/uvc_queue.c | 2 +-
drivers/mfd/pm8921-core.c | 9 +-
drivers/mmc/card/mmc_test.c | 2 +-
drivers/mmc/host/mxs-mmc.c | 6 +-
drivers/mmc/host/ushc.c | 3 +
drivers/mtd/nand/Kconfig | 2 +-
drivers/net/ethernet/mellanox/mlx4/cq.c | 38 ++---
drivers/net/ethernet/mellanox/mlx4/en_rx.c | 8 +-
drivers/net/ethernet/stmicro/stmmac/stmmac_main.c | 20 +--
drivers/net/phy/phy.c | 2 +-
drivers/net/tun.c | 12 +-
drivers/net/usb/pegasus.c | 29 +++-
drivers/net/usb/rtl8150.c | 34 ++++-
drivers/net/vxlan.c | 2 +-
drivers/net/wireless/ath/ath9k/ar9003_eeprom.h | 4 +-
drivers/pci/hotplug/rpadlpar_core.c | 10 +-
drivers/platform/goldfish/pdev_bus.c | 13 +-
drivers/platform/x86/intel_mid_powerbtn.c | 4 +-
drivers/s390/cio/qdio_thinint.c | 8 +-
drivers/s390/scsi/zfcp_dbf.c | 17 ++-
drivers/s390/scsi/zfcp_dbf.h | 41 +++++-
drivers/s390/scsi/zfcp_erp.c | 61 +++++++-
drivers/s390/scsi/zfcp_ext.h | 4 +-
drivers/s390/scsi/zfcp_fsf.c | 8 +-
drivers/s390/scsi/zfcp_fsf.h | 3 +-
drivers/s390/scsi/zfcp_reqlist.h | 30 +++-
drivers/s390/scsi/zfcp_scsi.c | 61 +++++++-
drivers/scsi/aacraid/src.c | 21 ++-
drivers/scsi/libsas/sas_ata.c | 2 +-
drivers/scsi/mvsas/mv_94xx.c | 2 +-
drivers/staging/iio/adc/ad7606_core.c | 2 +-
drivers/staging/vt6656/hostap.c | 3 +-
drivers/target/iscsi/iscsi_target_tpg.c | 1 -
drivers/tty/n_hdlc.c | 143 ++++++++++---------
drivers/usb/class/usbtmc.c | 9 +-
drivers/usb/core/config.c | 10 ++
drivers/usb/dwc3/gadget.c | 8 +-
drivers/usb/gadget/composite.c | 12 +-
drivers/usb/gadget/dummy_hcd.c | 6 +-
drivers/usb/host/ohci-q.c | 7 +-
drivers/usb/host/xhci-mem.c | 4 +-
drivers/usb/misc/idmouse.c | 3 +
drivers/usb/misc/iowarrior.c | 21 ++-
drivers/usb/misc/uss720.c | 5 +
drivers/usb/musb/musbhsdma.h | 2 +-
drivers/usb/serial/ark3116.c | 13 +-
drivers/usb/serial/ch341.c | 90 +++++++-----
drivers/usb/serial/cyberjack.c | 10 ++
drivers/usb/serial/digi_acceleport.c | 14 +-
drivers/usb/serial/ftdi_sio.c | 31 +++--
drivers/usb/serial/garmin_gps.c | 1 +
drivers/usb/serial/io_edgeport.c | 5 +
drivers/usb/serial/io_ti.c | 22 ++-
drivers/usb/serial/iuu_phoenix.c | 11 ++
drivers/usb/serial/keyspan_pda.c | 14 ++
drivers/usb/serial/kl5kusb105.c | 44 ++++--
drivers/usb/serial/kobil_sct.c | 12 ++
drivers/usb/serial/mos7720.c | 51 +++----
drivers/usb/serial/mos7840.c | 14 ++
drivers/usb/serial/omninet.c | 19 ++-
drivers/usb/serial/opticon.c | 2 +-
drivers/usb/serial/oti6858.c | 16 +++
drivers/usb/serial/pl2303.c | 8 ++
drivers/usb/serial/quatech2.c | 4 -
drivers/usb/serial/safe_serial.c | 5 +
drivers/usb/serial/spcp8x5.c | 22 ++-
drivers/usb/serial/ti_usb_3410_5052.c | 7 +
drivers/usb/wusbcore/wa-hc.c | 3 +
drivers/uwb/hwa-rc.c | 3 +
drivers/uwb/i1480/dfu/usb.c | 3 +
drivers/video/fbcmap.c | 26 ++--
fs/9p/acl.c | 40 +++---
fs/block_dev.c | 9 +-
fs/btrfs/acl.c | 6 +-
fs/btrfs/tree-log.c | 3 +-
fs/exec.c | 10 +-
fs/ext2/acl.c | 12 +-
fs/ext3/acl.c | 10 +-
fs/ext4/acl.c | 12 +-
fs/ext4/inline.c | 9 +-
fs/ext4/inode.c | 29 ++--
fs/ext4/mballoc.c | 4 +-
fs/f2fs/acl.c | 6 +-
fs/f2fs/debug.c | 1 +
fs/fuse/file.c | 6 +-
fs/generic_acl.c | 12 +-
fs/gfs2/acl.c | 14 +-
fs/jffs2/acl.c | 9 +-
fs/jfs/xattr.c | 5 +-
fs/nfs/nfs4filelayoutdev.c | 3 +-
fs/nfs/nfs4xdr.c | 2 +-
fs/ocfs2/acl.c | 20 +--
fs/ocfs2/ioctl.c | 129 ++++++-----------
fs/posix_acl.c | 31 +++++
fs/reiserfs/xattr_acl.c | 8 +-
fs/ubifs/tnc.c | 25 +++-
fs/xfs/xfs_acl.c | 15 +-
include/crypto/algapi.h | 18 ++-
include/linux/can/core.h | 7 +-
include/linux/cpu.h | 12 +-
include/linux/jump_label.h | 16 +++
include/linux/kvm_host.h | 7 +-
include/linux/lockd/lockd.h | 3 +-
include/linux/netdevice.h | 9 +-
include/linux/posix_acl.h | 1 +
include/net/cipso_ipv4.h | 4 +
include/rdma/ib_sa.h | 6 +-
include/trace/events/syscalls.h | 1 +
kernel/cpu.c | 3 +-
kernel/events/core.c | 5 +-
kernel/ptrace.c | 14 +-
kernel/rtmutex.c | 68 ++++++++-
kernel/sched/core.c | 6 +-
kernel/trace/ring_buffer.c | 24 +++-
kernel/trace/trace.c | 8 +-
mm/huge_memory.c | 19 ++-
mm/hugetlb.c | 37 +++--
mm/page_alloc.c | 17 ++-
net/can/af_can.c | 12 +-
net/can/af_can.h | 3 +-
net/can/bcm.c | 4 +-
net/can/gw.c | 2 +-
net/can/raw.c | 4 +-
net/ceph/osdmap.c | 1 -
net/core/dev.c | 58 +++++---
net/core/sock.c | 10 +-
net/dccp/ipv4.c | 3 +-
net/dccp/ipv6.c | 8 +-
net/ieee802154/6lowpan.c | 2 +-
net/ipv4/cipso_ipv4.c | 4 +
net/ipv4/igmp.c | 6 +-
net/ipv4/inet_connection_sock.c | 2 +
net/ipv4/ip_sockglue.c | 9 +-
net/ipv4/ip_vti.c | 1 -
net/ipv4/netfilter/arp_tables.c | 4 +-
net/ipv4/ping.c | 7 +-
net/ipv4/route.c | 1 +
net/ipv4/tcp.c | 6 +
net/ipv4/tcp_ipv4.c | 4 +-
net/ipv6/ip6_gre.c | 41 +++---
net/ipv6/ip6_offload.c | 1 +
net/ipv6/ip6_tunnel.c | 55 +++++---
net/ipv6/raw.c | 7 +-
net/ipv6/tcp_ipv6.c | 8 +-
net/l2tp/l2tp_core.c | 8 +-
net/l2tp/l2tp_core.h | 4 +-
net/l2tp/l2tp_debugfs.c | 10 +-
net/l2tp/l2tp_ip.c | 27 +++-
net/l2tp/l2tp_ip6.c | 2 +-
net/l2tp/l2tp_netlink.c | 7 +-
net/l2tp/l2tp_ppp.c | 10 +-
net/mac80211/mesh.c | 2 +-
net/packet/af_packet.c | 65 ++++++---
net/sched/act_api.c | 5 +-
net/sched/cls_api.c | 4 +-
net/sched/em_meta.c | 9 +-
net/sctp/associola.c | 131 +++++++++++-------
net/sctp/socket.c | 7 +-
net/socket.c | 4 +-
net/sunrpc/auth_gss/gss_rpc_xdr.c | 2 +-
net/sunrpc/auth_gss/svcauth_gss.c | 2 +-
net/unix/garbage.c | 18 +--
net/xfrm/xfrm_user.c | 9 +-
security/integrity/evm/evm_main.c | 3 +-
security/keys/gc.c | 2 +-
security/keys/keyctl.c | 20 +--
security/keys/process_keys.c | 44 +++---
security/selinux/hooks.c | 2 +-
sound/pci/ctxfi/cthw20k1.c | 19 +--
sound/pci/ctxfi/cthw20k2.c | 18 +--
sound/usb/card.c | 1 -
tools/perf/builtin-trace.c | 4 +-
tools/perf/util/trace-event-scripting.c | 6 +-
tools/testing/ktest/ktest.pl | 2 +-
virt/kvm/eventfd.c | 3 +
virt/kvm/kvm_main.c | 41 ++++--
239 files changed, 2487 insertions(+), 1136 deletions(-)
create mode 100644 crypto/memneq.c
--
2.8.0.rc2.1.gbe9624a
[toc] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 188/250] uwb: hwa-rc: fix NULL-deref at probe |
| Message-ID | <tPSfr-4Fa-95@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Johan Hovold <johan@kernel.org>
commit daf229b15907fbfdb6ee183aac8ca428cb57e361 upstream.
Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer should a malicious device lack endpoints.
Note that the dereference happens in the start callback which is called
during probe.
Fixes: de520b8bd552 ("uwb: add HWA radio controller driver")
Cc: Inaky Perez-Gonzalez <inaky.perez-gonzalez@intel.com>
Cc: David Vrabel <david.vrabel@csr.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/uwb/hwa-rc.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/uwb/hwa-rc.c b/drivers/uwb/hwa-rc.c
index 810c90a..cd8bf69 100644
--- a/drivers/uwb/hwa-rc.c
+++ b/drivers/uwb/hwa-rc.c
@@ -811,6 +811,9 @@ static int hwarc_probe(struct usb_interface *iface,
struct hwarc *hwarc;
struct device *dev = &iface->dev;
+ if (iface->cur_altsetting->desc.bNumEndpoints < 1)
+ return -ENODEV;
+
result = -ENOMEM;
uwb_rc = uwb_rc_alloc();
if (uwb_rc == NULL) {
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 167/250] USB: serial: io_ti: fix NULL-deref in interrupt callback |
| Message-ID | <tPSfr-4Fa-99@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Johan Hovold <johan@kernel.org>
commit 0b1d250afb8eb9d65afb568bac9b9f9253a82b49 upstream.
Fix a NULL-pointer dereference in the interrupt callback should a
malicious device send data containing a bad port number by adding the
missing sanity check.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/usb/serial/io_ti.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/usb/serial/io_ti.c b/drivers/usb/serial/io_ti.c
index e1b3e79..e2dc182 100644
--- a/drivers/usb/serial/io_ti.c
+++ b/drivers/usb/serial/io_ti.c
@@ -1575,6 +1575,12 @@ static void edge_interrupt_callback(struct urb *urb)
function = TIUMP_GET_FUNC_FROM_CODE(data[0]);
dev_dbg(dev, "%s - port_number %d, function %d, info 0x%x\n", __func__,
port_number, function, data[1]);
+
+ if (port_number >= edge_serial->serial->num_ports) {
+ dev_err(dev, "bad port number %d\n", port_number);
+ goto exit;
+ }
+
port = edge_serial->serial->port[port_number];
edge_port = usb_get_serial_port_data(port);
if (!edge_port) {
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 136/250] mfd: pm8921: Potential NULL dereference in pm8921_remove() |
| Message-ID | <tPSfr-4Fa-91@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Dan Carpenter <dan.carpenter@oracle.com>
commit d6daef95127e41233ac8e2d8472d8c0cd8687d38 upstream.
We assume that "pmic" could be NULL and then dereference it two lines
later. I fix this by moving the dereference inside the NULL check.
Fixes: c013f0a56c56 ('mfd: Add pm8xxx irq support')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/mfd/pm8921-core.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/mfd/pm8921-core.c b/drivers/mfd/pm8921-core.c
index ecc137f..a28f434 100644
--- a/drivers/mfd/pm8921-core.c
+++ b/drivers/mfd/pm8921-core.c
@@ -173,11 +173,12 @@ static int pm8921_remove(struct platform_device *pdev)
drvdata = platform_get_drvdata(pdev);
if (drvdata)
pmic = drvdata->pm_chip_data;
- if (pmic)
+ if (pmic) {
mfd_remove_devices(pmic->dev);
- if (pmic->irq_chip) {
- pm8xxx_irq_exit(pmic->irq_chip);
- pmic->irq_chip = NULL;
+ if (pmic->irq_chip) {
+ pm8xxx_irq_exit(pmic->irq_chip);
+ pmic->irq_chip = NULL;
+ }
}
platform_set_drvdata(pdev, NULL);
kfree(pmic);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 099/250] ubifs: Fix journal replay wrt. xattr nodes |
| Message-ID | <tPSfr-4Fa-97@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Richard Weinberger <richard@nod.at>
commit 1cb51a15b576ee325d527726afff40947218fd5e upstream.
When replaying the journal it can happen that a journal entry points to
a garbage collected node.
This is the case when a power-cut occurred between a garbage collect run
and a commit. In such a case nodes have to be read using the failable
read functions to detect whether the found node matches what we expect.
One corner case was forgotten, when the journal contains an entry to
remove an inode all xattrs have to be removed too. UBIFS models xattr
like directory entries, so the TNC code iterates over
all xattrs of the inode and removes them too. This code re-uses the
functions for walking directories and calls ubifs_tnc_next_ent().
ubifs_tnc_next_ent() expects to be used only after the journal and
aborts when a node does not match the expected result. This behavior can
render an UBIFS volume unmountable after a power-cut when xattrs are
used.
Fix this issue by using failable read functions in ubifs_tnc_next_ent()
too when replaying the journal.
Fixes: 1e51764a3c2ac05a ("UBIFS: add new flash file system")
Reported-by: Rock Lee <rockdotlee@gmail.com>
Reviewed-by: David Gstir <david@sigma-star.at>
Signed-off-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
fs/ubifs/tnc.c | 25 +++++++++++++++++++++++--
1 file changed, 23 insertions(+), 2 deletions(-)
diff --git a/fs/ubifs/tnc.c b/fs/ubifs/tnc.c
index 349f31a..fdf2ca1 100644
--- a/fs/ubifs/tnc.c
+++ b/fs/ubifs/tnc.c
@@ -34,6 +34,11 @@
#include <linux/slab.h>
#include "ubifs.h"
+static int try_read_node(const struct ubifs_info *c, void *buf, int type,
+ int len, int lnum, int offs);
+static int fallible_read_node(struct ubifs_info *c, const union ubifs_key *key,
+ struct ubifs_zbranch *zbr, void *node);
+
/*
* Returned codes of 'matches_name()' and 'fallible_matches_name()' functions.
* @NAME_LESS: name corresponding to the first argument is less than second
@@ -419,7 +424,19 @@ static int tnc_read_node_nm(struct ubifs_info *c, struct ubifs_zbranch *zbr,
return 0;
}
- err = ubifs_tnc_read_node(c, zbr, node);
+ if (c->replaying) {
+ err = fallible_read_node(c, &zbr->key, zbr, node);
+ /*
+ * When the node was not found, return -ENOENT, 0 otherwise.
+ * Negative return codes stay as-is.
+ */
+ if (err == 0)
+ err = -ENOENT;
+ else if (err == 1)
+ err = 0;
+ } else {
+ err = ubifs_tnc_read_node(c, zbr, node);
+ }
if (err)
return err;
@@ -2783,7 +2800,11 @@ struct ubifs_dent_node *ubifs_tnc_next_ent(struct ubifs_info *c,
if (nm->name) {
if (err) {
/* Handle collisions */
- err = resolve_collision(c, key, &znode, &n, nm);
+ if (c->replaying)
+ err = fallible_resolve_collision(c, key, &znode, &n,
+ nm, 0);
+ else
+ err = resolve_collision(c, key, &znode, &n, nm);
dbg_tnc("rc returned %d, znode %p, n %d",
err, znode, n);
if (unlikely(err < 0))
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 102/250] arm64/ptrace: Reject attempts to set incomplete hardware breakpoint fields |
| Message-ID | <tPSfr-4Fa-103@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Dave Martin <Dave.Martin@arm.com>
commit ad9e202aa1ce571b1d7fed969d06f66067f8a086 upstream.
We cannot preserve partial fields for hardware breakpoints, because
the values written by userspace to the hardware breakpoint
registers can't subsequently be recovered intact from the hardware.
So, just reject attempts to write incomplete fields with -EINVAL.
Fixes: 478fcb2cdb23 ("arm64: Debugging support")
Signed-off-by: Dave Martin <Dave.Martin@arm.com>
Acked-by: Will Deacon <Will.Deacon@arm.com>
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
arch/arm64/kernel/ptrace.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/arch/arm64/kernel/ptrace.c b/arch/arm64/kernel/ptrace.c
index 777763d..015775a 100644
--- a/arch/arm64/kernel/ptrace.c
+++ b/arch/arm64/kernel/ptrace.c
@@ -464,6 +464,8 @@ static int hw_break_set(struct task_struct *target,
/* (address, ctrl) registers */
limit = regset->n * regset->size;
while (count && offset < limit) {
+ if (count < PTRACE_HBP_ADDR_SZ)
+ return -EINVAL;
ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &addr,
offset, offset + PTRACE_HBP_ADDR_SZ);
if (ret)
@@ -473,6 +475,8 @@ static int hw_break_set(struct task_struct *target,
return ret;
offset += PTRACE_HBP_ADDR_SZ;
+ if (!count)
+ break;
ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &ctrl,
offset, offset + PTRACE_HBP_CTRL_SZ);
if (ret)
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 223/250] Staging: vt6655-6: potential NULL dereference in hostap_disable_hostapd() |
| Message-ID | <tPSfr-4Fa-107@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Dan Carpenter <dan.carpenter@oracle.com>
commit cb4855b49deb1acce27706ad9509d63c4fe8e988 upstream.
We fixed this to use free_netdev() instead of kfree() but unfortunately
free_netdev() doesn't accept NULL pointers. Smatch complains about
this, it's not something I discovered through testing.
Fixes: 3030d40b5036 ('staging: vt6655: use free_netdev instead of kfree')
Fixes: 0a438d5b381e ('staging: vt6656: use free_netdev instead of kfree')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[wt: only vt6656 was converted to free_netdev in 3.10]
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/staging/vt6656/hostap.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/staging/vt6656/hostap.c b/drivers/staging/vt6656/hostap.c
index c699a30..cfffdd2 100644
--- a/drivers/staging/vt6656/hostap.c
+++ b/drivers/staging/vt6656/hostap.c
@@ -133,7 +133,8 @@ static int hostap_disable_hostapd(struct vnt_private *pDevice, int rtnl_locked)
DBG_PRT(MSG_LEVEL_DEBUG, KERN_INFO "%s: Netdevice %s unregistered\n",
pDevice->dev->name, pDevice->apdev->name);
}
- free_netdev(pDevice->apdev);
+ if (pDevice->apdev)
+ free_netdev(pDevice->apdev);
pDevice->apdev = NULL;
pDevice->bEnable8021x = false;
pDevice->bEnableHostWEP = false;
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 006/250] KVM: x86: Introduce segmented_write_std |
| Message-ID | <tPSfr-4Fa-109@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Steve Rutherford <srutherford@google.com>
commit 129a72a0d3c8e139a04512325384fe5ac119e74d upstream.
Introduces segemented_write_std.
Switches from emulated reads/writes to standard read/writes in fxsave,
fxrstor, sgdt, and sidt. This fixes CVE-2017-2584, a longstanding
kernel memory leak.
Since commit 283c95d0e389 ("KVM: x86: emulate FXSAVE and FXRSTOR",
2016-11-09), which is luckily not yet in any final release, this would
also be an exploitable kernel memory *write*!
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Fixes: 96051572c819194c37a8367624b285be10297eca
Fixes: 283c95d0e3891b64087706b344a4b545d04a6e62
Suggested-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Steve Rutherford <srutherford@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
arch/x86/kvm/emulate.c | 18 ++++++++++++++++--
1 file changed, 16 insertions(+), 2 deletions(-)
diff --git a/arch/x86/kvm/emulate.c b/arch/x86/kvm/emulate.c
index 364f020..c964850 100644
--- a/arch/x86/kvm/emulate.c
+++ b/arch/x86/kvm/emulate.c
@@ -906,6 +906,20 @@ static int segmented_read_std(struct x86_emulate_ctxt *ctxt,
return ctxt->ops->read_std(ctxt, linear, data, size, &ctxt->exception);
}
+static int segmented_write_std(struct x86_emulate_ctxt *ctxt,
+ struct segmented_address addr,
+ void *data,
+ unsigned int size)
+{
+ int rc;
+ ulong linear;
+
+ rc = linearize(ctxt, addr, size, true, &linear);
+ if (rc != X86EMUL_CONTINUE)
+ return rc;
+ return ctxt->ops->write_std(ctxt, linear, data, size, &ctxt->exception);
+}
+
/*
* Fetch the next byte of the instruction being emulated which is pointed to
* by ctxt->_eip, then increment ctxt->_eip.
@@ -3361,8 +3375,8 @@ static int emulate_store_desc_ptr(struct x86_emulate_ctxt *ctxt,
}
/* Disable writeback. */
ctxt->dst.type = OP_NONE;
- return segmented_write(ctxt, ctxt->dst.addr.mem,
- &desc_ptr, 2 + ctxt->op_bytes);
+ return segmented_write_std(ctxt, ctxt->dst.addr.mem,
+ &desc_ptr, 2 + ctxt->op_bytes);
}
static int em_sgdt(struct x86_emulate_ctxt *ctxt)
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 181/250] Input: hanwang - validate number of endpoints before using them |
| Message-ID | <tPSfs-4Fa-113@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Johan Hovold <johan@kernel.org>
commit ba340d7b83703768ce566f53f857543359aa1b98 upstream.
Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer should a malicious device lack endpoints.
Fixes: bba5394ad3bd ("Input: add support for Hanwang tablets")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/input/tablet/hanwang.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/input/tablet/hanwang.c b/drivers/input/tablet/hanwang.c
index 5cc0412..263c85e 100644
--- a/drivers/input/tablet/hanwang.c
+++ b/drivers/input/tablet/hanwang.c
@@ -341,6 +341,9 @@ static int hanwang_probe(struct usb_interface *intf, const struct usb_device_id
int error;
int i;
+ if (intf->cur_altsetting->desc.bNumEndpoints < 1)
+ return -ENODEV;
+
hanwang = kzalloc(sizeof(struct hanwang), GFP_KERNEL);
input_dev = input_allocate_device();
if (!hanwang || !input_dev) {
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 049/250] USB: serial: io_edgeport: fix NULL-deref at open |
| Message-ID | <tPSfr-4Fa-111@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Johan Hovold <johan@kernel.org>
commit 0dd408425eb21ddf26a692b3c8044c9e7d1a7948 upstream.
Fix NULL-pointer dereference when initialising URBs at open should a
non-EPIC device lack a bulk-in or interrupt-in endpoint.
Unable to handle kernel NULL pointer dereference at virtual address 00000028
...
PC is at edge_open+0x24c/0x3e8 [io_edgeport]
Note that the EPIC-device probe path has the required sanity checks so
this makes those checks partially redundant.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/usb/serial/io_edgeport.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/usb/serial/io_edgeport.c b/drivers/usb/serial/io_edgeport.c
index c574d312..9f24fd7 100644
--- a/drivers/usb/serial/io_edgeport.c
+++ b/drivers/usb/serial/io_edgeport.c
@@ -2795,6 +2795,11 @@ static int edge_startup(struct usb_serial *serial)
EDGE_COMPATIBILITY_MASK1,
EDGE_COMPATIBILITY_MASK2 };
+ if (serial->num_bulk_in < 1 || serial->num_interrupt_in < 1) {
+ dev_err(&serial->interface->dev, "missing endpoints\n");
+ return -ENODEV;
+ }
+
dev = serial->dev;
/* create our private serial structure */
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 090/250] powerpc/ibmebus: Fix further device reference leaks |
| Message-ID | <tPSfs-4Fa-115@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Johan Hovold <johan@kernel.org>
commit 815a7141c4d1b11610dccb7fcbb38633759824f2 upstream.
Make sure to drop any reference taken by bus_find_device() when creating
devices during init and driver registration.
Fixes: 55347cc9962f ("[POWERPC] ibmebus: Add device creation and bus probing based on of_device")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
arch/powerpc/kernel/ibmebus.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/arch/powerpc/kernel/ibmebus.c b/arch/powerpc/kernel/ibmebus.c
index 8220baa..cce1a44 100644
--- a/arch/powerpc/kernel/ibmebus.c
+++ b/arch/powerpc/kernel/ibmebus.c
@@ -180,6 +180,7 @@ static int ibmebus_create_device(struct device_node *dn)
static int ibmebus_create_devices(const struct of_device_id *matches)
{
struct device_node *root, *child;
+ struct device *dev;
int ret = 0;
root = of_find_node_by_path("/");
@@ -188,9 +189,12 @@ static int ibmebus_create_devices(const struct of_device_id *matches)
if (!of_match_node(matches, child))
continue;
- if (bus_find_device(&ibmebus_bus_type, NULL, child,
- ibmebus_match_node))
+ dev = bus_find_device(&ibmebus_bus_type, NULL, child,
+ ibmebus_match_node);
+ if (dev) {
+ put_device(dev);
continue;
+ }
ret = ibmebus_create_device(child);
if (ret) {
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 172/250] net: net_enable_timestamp() can be called from irq contexts |
| Message-ID | <tPSfs-4Fa-117@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Eric Dumazet <edumazet@google.com>
commit 13baa00ad01bb3a9f893e3a08cbc2d072fc0c15d upstream.
It is now very clear that silly TCP listeners might play with
enabling/disabling timestamping while new children are added
to their accept queue.
Meaning net_enable_timestamp() can be called from BH context
while current state of the static key is not enabled.
Lets play safe and allow all contexts.
The work queue is scheduled only under the problematic cases,
which are the static key enable/disable transition, to not slow down
critical paths.
This extends and improves what we did in commit 5fa8bbda38c6 ("net: use
a work queue to defer net_disable_timestamp() work")
Fixes: b90e5794c5bd ("net: dont call jump_label_dec from irq context")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
net/core/dev.c | 35 +++++++++++++++++++++++++++++++----
1 file changed, 31 insertions(+), 4 deletions(-)
diff --git a/net/core/dev.c b/net/core/dev.c
index 11535a9..682bf5a 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -1560,27 +1560,54 @@ EXPORT_SYMBOL(call_netdevice_notifiers);
static struct static_key netstamp_needed __read_mostly;
#ifdef HAVE_JUMP_LABEL
static atomic_t netstamp_needed_deferred;
+static atomic_t netstamp_wanted;
static void netstamp_clear(struct work_struct *work)
{
int deferred = atomic_xchg(&netstamp_needed_deferred, 0);
+ int wanted;
- while (deferred--)
- static_key_slow_dec(&netstamp_needed);
+ wanted = atomic_add_return(deferred, &netstamp_wanted);
+ if (wanted > 0)
+ static_key_enable(&netstamp_needed);
+ else
+ static_key_disable(&netstamp_needed);
}
static DECLARE_WORK(netstamp_work, netstamp_clear);
#endif
void net_enable_timestamp(void)
{
+#ifdef HAVE_JUMP_LABEL
+ int wanted;
+
+ while (1) {
+ wanted = atomic_read(&netstamp_wanted);
+ if (wanted <= 0)
+ break;
+ if (atomic_cmpxchg(&netstamp_wanted, wanted, wanted + 1) == wanted)
+ return;
+ }
+ atomic_inc(&netstamp_needed_deferred);
+ schedule_work(&netstamp_work);
+#else
static_key_slow_inc(&netstamp_needed);
+#endif
}
EXPORT_SYMBOL(net_enable_timestamp);
void net_disable_timestamp(void)
{
#ifdef HAVE_JUMP_LABEL
- /* net_disable_timestamp() can be called from non process context */
- atomic_inc(&netstamp_needed_deferred);
+ int wanted;
+
+ while (1) {
+ wanted = atomic_read(&netstamp_wanted);
+ if (wanted <= 1)
+ break;
+ if (atomic_cmpxchg(&netstamp_wanted, wanted, wanted - 1) == wanted)
+ return;
+ }
+ atomic_dec(&netstamp_needed_deferred);
schedule_work(&netstamp_work);
#else
static_key_slow_dec(&netstamp_needed);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 159/250] USB: serial: digi_acceleport: fix OOB data sanity check |
| Message-ID | <tPSfs-4Fa-123@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Johan Hovold <johan@kernel.org>
commit 2d380889215fe20b8523345649dee0579821800c upstream.
Make sure to check for short transfers to avoid underflow in a loop
condition when parsing the receive buffer.
Also fix an off-by-one error in the incomplete sanity check which could
lead to invalid data being parsed.
Fixes: 8c209e6782ca ("USB: make actual_length in struct urb field u32")
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/usb/serial/digi_acceleport.c | 14 +++++++++-----
1 file changed, 9 insertions(+), 5 deletions(-)
diff --git a/drivers/usb/serial/digi_acceleport.c b/drivers/usb/serial/digi_acceleport.c
index 8c34d9c..15b9cb3 100644
--- a/drivers/usb/serial/digi_acceleport.c
+++ b/drivers/usb/serial/digi_acceleport.c
@@ -1489,16 +1489,20 @@ static int digi_read_oob_callback(struct urb *urb)
struct usb_serial *serial = port->serial;
struct tty_struct *tty;
struct digi_port *priv = usb_get_serial_port_data(port);
+ unsigned char *buf = urb->transfer_buffer;
int opcode, line, status, val;
int i;
unsigned int rts;
+ if (urb->actual_length < 4)
+ return -1;
+
/* handle each oob command */
- for (i = 0; i < urb->actual_length - 3;) {
- opcode = ((unsigned char *)urb->transfer_buffer)[i++];
- line = ((unsigned char *)urb->transfer_buffer)[i++];
- status = ((unsigned char *)urb->transfer_buffer)[i++];
- val = ((unsigned char *)urb->transfer_buffer)[i++];
+ for (i = 0; i < urb->actual_length - 4; i += 4) {
+ opcode = buf[i];
+ line = buf[i + 1];
+ status = buf[i + 2];
+ val = buf[i + 3];
dev_dbg(&port->dev, "digi_read_oob_callback: opcode=%d, line=%d, status=%d, val=%d\n",
opcode, line, status, val);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 139/250] vti4: Don't count header length twice. |
| Message-ID | <tPSfs-4Fa-125@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Steffen Klassert <steffen.klassert@secunet.com>
commit a32452366b7250c42e96a18ffc3ad8db9e0ca3c2 upstream.
We currently count the size of LL_MAX_HEADER and struct iphdr
twice for vti4 devices, this leads to a wrong device mtu.
The size of LL_MAX_HEADER and struct iphdr is already counted in
ip_tunnel_bind_dev(), so don't do it again in vti_tunnel_init().
Fixes: b9959fd3 ("vti: switch to new ip tunnel code")
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
net/ipv4/ip_vti.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/net/ipv4/ip_vti.c b/net/ipv4/ip_vti.c
index 4ec3427..eadafac 100644
--- a/net/ipv4/ip_vti.c
+++ b/net/ipv4/ip_vti.c
@@ -582,7 +582,6 @@ static void vti_tunnel_setup(struct net_device *dev)
dev->type = ARPHRD_TUNNEL;
dev->destructor = vti_dev_free;
- dev->hard_header_len = LL_MAX_HEADER + sizeof(struct iphdr);
dev->mtu = ETH_DATA_LEN;
dev->flags = IFF_NOARP;
dev->iflink = 0;
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Subject | [PATCH 3.10 178/250] net: properly release sk_frag.page |
| Message-ID | <tPSfs-4Fa-119@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Eric Dumazet <edumazet@google.com>
commit 22a0e18eac7a9e986fec76c60fa4a2926d1291e2 upstream.
I mistakenly added the code to release sk->sk_frag in
sk_common_release() instead of sk_destruct()
TCP sockets using sk->sk_allocation == GFP_ATOMIC do no call
sk_common_release() at close time, thus leaking one (order-3) page.
iSCSI is using such sockets.
Fixes: 5640f7685831 ("net: use a per task frag allocator")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
net/core/sock.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/net/core/sock.c b/net/core/sock.c
index e3cb454..96e1259 100644
--- a/net/core/sock.c
+++ b/net/core/sock.c
@@ -1403,6 +1403,11 @@ static void __sk_free(struct sock *sk)
pr_debug("%s: optmem leakage (%d bytes) detected\n",
__func__, atomic_read(&sk->sk_omem_alloc));
+ if (sk->sk_frag.page) {
+ put_page(sk->sk_frag.page);
+ sk->sk_frag.page = NULL;
+ }
+
if (sk->sk_peer_cred)
put_cred(sk->sk_peer_cred);
put_pid(sk->sk_peer_pid);
@@ -2556,11 +2561,6 @@ void sk_common_release(struct sock *sk)
sk_refcnt_debug_release(sk);
- if (sk->sk_frag.page) {
- put_page(sk->sk_frag.page);
- sk->sk_frag.page = NULL;
- }
-
sock_put(sk);
}
EXPORT_SYMBOL(sk_common_release);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:20 +0200 |
| Subject | [PATCH 3.10 229/250] USB: dummy-hcd: fix bug in stop_activity (handle ep0) |
| Message-ID | <tPSp3-4Iz-1@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Alan Stern <stern@rowland.harvard.edu>
commit bcdbeb844773333d2d1c08004f3b3e25921040e5 upstream.
The stop_activity() routine in dummy-hcd is supposed to unlink all
active requests for every endpoint, among other things. But it
doesn't handle ep0. As a result, fuzz testing can generate a WARNING
like the following:
WARNING: CPU: 0 PID: 4410 at drivers/usb/gadget/udc/dummy_hcd.c:672 dummy_free_request+0x153/0x170
Modules linked in:
CPU: 0 PID: 4410 Comm: syz-executor Not tainted 4.9.0-rc7+ #32
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011
ffff88006a64ed10 ffffffff81f96b8a ffffffff41b58ab3 1ffff1000d4c9d35
ffffed000d4c9d2d ffff880065f8ac00 0000000041b58ab3 ffffffff8598b510
ffffffff81f968f8 0000000041b58ab3 ffffffff859410e0 ffffffff813f0590
Call Trace:
[< inline >] __dump_stack lib/dump_stack.c:15
[<ffffffff81f96b8a>] dump_stack+0x292/0x398 lib/dump_stack.c:51
[<ffffffff812b808f>] __warn+0x19f/0x1e0 kernel/panic.c:550
[<ffffffff812b831c>] warn_slowpath_null+0x2c/0x40 kernel/panic.c:585
[<ffffffff830fcb13>] dummy_free_request+0x153/0x170 drivers/usb/gadget/udc/dummy_hcd.c:672
[<ffffffff830ed1b0>] usb_ep_free_request+0xc0/0x420 drivers/usb/gadget/udc/core.c:195
[<ffffffff83225031>] gadgetfs_unbind+0x131/0x190 drivers/usb/gadget/legacy/inode.c:1612
[<ffffffff830ebd8f>] usb_gadget_remove_driver+0x10f/0x2b0 drivers/usb/gadget/udc/core.c:1228
[<ffffffff830ec084>] usb_gadget_unregister_driver+0x154/0x240 drivers/usb/gadget/udc/core.c:1357
This patch fixes the problem by iterating over all the endpoints in
the driver's ep array instead of iterating over the gadget's ep_list,
which explicitly leaves out ep0.
Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/usb/gadget/dummy_hcd.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/usb/gadget/dummy_hcd.c b/drivers/usb/gadget/dummy_hcd.c
index ac0e79e..644c105 100644
--- a/drivers/usb/gadget/dummy_hcd.c
+++ b/drivers/usb/gadget/dummy_hcd.c
@@ -266,7 +266,7 @@ static void nuke(struct dummy *dum, struct dummy_ep *ep)
/* caller must hold lock */
static void stop_activity(struct dummy *dum)
{
- struct dummy_ep *ep;
+ int i;
/* prevent any more requests */
dum->address = 0;
@@ -274,8 +274,8 @@ static void stop_activity(struct dummy *dum)
/* The timer is left running so that outstanding URBs can fail */
/* nuke any pending requests first, so driver i/o is quiesced */
- list_for_each_entry(ep, &dum->gadget.ep_list, ep.ep_list)
- nuke(dum, ep);
+ for (i = 0; i < DUMMY_ENDPOINTS; ++i)
+ nuke(dum, &dum->ep[i]);
/* driver now does any non-usb quiescing necessary */
}
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:20 +0200 |
| Subject | [PATCH 3.10 123/250] packet: fix races in fanout_add() |
| Message-ID | <tPSp3-4Iz-3@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Eric Dumazet <edumazet@google.com>
commit d199fab63c11998a602205f7ee7ff7c05c97164b upstream.
Multiple threads can call fanout_add() at the same time.
We need to grab fanout_mutex earlier to avoid races that could
lead to one thread freeing po->rollover that was set by another thread.
Do the same in fanout_release(), for peace of mind, and to help us
finding lockdep issues earlier.
[js] no rollover in 3.12
Fixes: dc99f600698d ("packet: Add fanout support.")
Fixes: 0648ab70afe6 ("packet: rollover prepare: per-socket state")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Willem de Bruijn <willemb@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
net/packet/af_packet.c | 26 ++++++++++++++------------
1 file changed, 14 insertions(+), 12 deletions(-)
diff --git a/net/packet/af_packet.c b/net/packet/af_packet.c
index e38c699..25ef495 100644
--- a/net/packet/af_packet.c
+++ b/net/packet/af_packet.c
@@ -1304,13 +1304,16 @@ static int fanout_add(struct sock *sk, u16 id, u16 type_flags)
return -EINVAL;
}
+ mutex_lock(&fanout_mutex);
+
+ err = -EINVAL;
if (!po->running)
- return -EINVAL;
+ goto out;
+ err = -EALREADY;
if (po->fanout)
- return -EALREADY;
+ goto out;
- mutex_lock(&fanout_mutex);
match = NULL;
list_for_each_entry(f, &fanout_list, list) {
if (f->id == id &&
@@ -1366,17 +1369,16 @@ static void fanout_release(struct sock *sk)
struct packet_sock *po = pkt_sk(sk);
struct packet_fanout *f;
- f = po->fanout;
- if (!f)
- return;
-
mutex_lock(&fanout_mutex);
- po->fanout = NULL;
+ f = po->fanout;
+ if (f) {
+ po->fanout = NULL;
- if (atomic_dec_and_test(&f->sk_ref)) {
- list_del(&f->list);
- dev_remove_pack(&f->prot_hook);
- kfree(f);
+ if (atomic_dec_and_test(&f->sk_ref)) {
+ list_del(&f->list);
+ dev_remove_pack(&f->prot_hook);
+ kfree(f);
+ }
}
mutex_unlock(&fanout_mutex);
}
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:20 +0200 |
| Subject | [PATCH 3.10 135/250] ocfs2: do not write error flag to user structure we cannot copy from/to |
| Message-ID | <tPSp3-4Iz-5@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Ben Hutchings <ben@decadent.org.uk>
commit 2b462638e41ea62230297c21c4da9955937b7a3c upstream.
If we failed to copy from the structure, writing back the flags leaks 31
bits of kernel memory (the rest of the ir_flags field).
In any case, if we cannot copy from/to the structure, why should we
expect putting just the flags to work?
Also make sure ocfs2_info_handle_freeinode() returns the right error
code if the copy_to_user() fails.
Fixes: ddee5cdb70e6 ('Ocfs2: Add new OCFS2_IOC_INFO ioctl for ocfs2 v8.')
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Cc: Joel Becker <jlbec@evilplan.org>
Acked-by: Mark Fasheh <mfasheh@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
fs/ocfs2/ioctl.c | 129 +++++++++++++++++++------------------------------------
1 file changed, 43 insertions(+), 86 deletions(-)
diff --git a/fs/ocfs2/ioctl.c b/fs/ocfs2/ioctl.c
index 0c60ef2..b9d1609 100644
--- a/fs/ocfs2/ioctl.c
+++ b/fs/ocfs2/ioctl.c
@@ -34,9 +34,8 @@
copy_to_user((typeof(a) __user *)b, &(a), sizeof(a))
/*
- * This call is void because we are already reporting an error that may
- * be -EFAULT. The error will be returned from the ioctl(2) call. It's
- * just a best-effort to tell userspace that this request caused the error.
+ * This is just a best-effort to tell userspace that this request
+ * caused the error.
*/
static inline void o2info_set_request_error(struct ocfs2_info_request *kreq,
struct ocfs2_info_request __user *req)
@@ -145,136 +144,105 @@ bail:
int ocfs2_info_handle_blocksize(struct inode *inode,
struct ocfs2_info_request __user *req)
{
- int status = -EFAULT;
struct ocfs2_info_blocksize oib;
if (o2info_from_user(oib, req))
- goto bail;
+ return -EFAULT;
oib.ib_blocksize = inode->i_sb->s_blocksize;
o2info_set_request_filled(&oib.ib_req);
if (o2info_to_user(oib, req))
- goto bail;
-
- status = 0;
-bail:
- if (status)
- o2info_set_request_error(&oib.ib_req, req);
+ return -EFAULT;
- return status;
+ return 0;
}
int ocfs2_info_handle_clustersize(struct inode *inode,
struct ocfs2_info_request __user *req)
{
- int status = -EFAULT;
struct ocfs2_info_clustersize oic;
struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
if (o2info_from_user(oic, req))
- goto bail;
+ return -EFAULT;
oic.ic_clustersize = osb->s_clustersize;
o2info_set_request_filled(&oic.ic_req);
if (o2info_to_user(oic, req))
- goto bail;
-
- status = 0;
-bail:
- if (status)
- o2info_set_request_error(&oic.ic_req, req);
+ return -EFAULT;
- return status;
+ return 0;
}
int ocfs2_info_handle_maxslots(struct inode *inode,
struct ocfs2_info_request __user *req)
{
- int status = -EFAULT;
struct ocfs2_info_maxslots oim;
struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
if (o2info_from_user(oim, req))
- goto bail;
+ return -EFAULT;
oim.im_max_slots = osb->max_slots;
o2info_set_request_filled(&oim.im_req);
if (o2info_to_user(oim, req))
- goto bail;
+ return -EFAULT;
- status = 0;
-bail:
- if (status)
- o2info_set_request_error(&oim.im_req, req);
-
- return status;
+ return 0;
}
int ocfs2_info_handle_label(struct inode *inode,
struct ocfs2_info_request __user *req)
{
- int status = -EFAULT;
struct ocfs2_info_label oil;
struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
if (o2info_from_user(oil, req))
- goto bail;
+ return -EFAULT;
memcpy(oil.il_label, osb->vol_label, OCFS2_MAX_VOL_LABEL_LEN);
o2info_set_request_filled(&oil.il_req);
if (o2info_to_user(oil, req))
- goto bail;
+ return -EFAULT;
- status = 0;
-bail:
- if (status)
- o2info_set_request_error(&oil.il_req, req);
-
- return status;
+ return 0;
}
int ocfs2_info_handle_uuid(struct inode *inode,
struct ocfs2_info_request __user *req)
{
- int status = -EFAULT;
struct ocfs2_info_uuid oiu;
struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
if (o2info_from_user(oiu, req))
- goto bail;
+ return -EFAULT;
memcpy(oiu.iu_uuid_str, osb->uuid_str, OCFS2_TEXT_UUID_LEN + 1);
o2info_set_request_filled(&oiu.iu_req);
if (o2info_to_user(oiu, req))
- goto bail;
-
- status = 0;
-bail:
- if (status)
- o2info_set_request_error(&oiu.iu_req, req);
+ return -EFAULT;
- return status;
+ return 0;
}
int ocfs2_info_handle_fs_features(struct inode *inode,
struct ocfs2_info_request __user *req)
{
- int status = -EFAULT;
struct ocfs2_info_fs_features oif;
struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
if (o2info_from_user(oif, req))
- goto bail;
+ return -EFAULT;
oif.if_compat_features = osb->s_feature_compat;
oif.if_incompat_features = osb->s_feature_incompat;
@@ -283,39 +251,28 @@ int ocfs2_info_handle_fs_features(struct inode *inode,
o2info_set_request_filled(&oif.if_req);
if (o2info_to_user(oif, req))
- goto bail;
+ return -EFAULT;
- status = 0;
-bail:
- if (status)
- o2info_set_request_error(&oif.if_req, req);
-
- return status;
+ return 0;
}
int ocfs2_info_handle_journal_size(struct inode *inode,
struct ocfs2_info_request __user *req)
{
- int status = -EFAULT;
struct ocfs2_info_journal_size oij;
struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
if (o2info_from_user(oij, req))
- goto bail;
+ return -EFAULT;
oij.ij_journal_size = osb->journal->j_inode->i_size;
o2info_set_request_filled(&oij.ij_req);
if (o2info_to_user(oij, req))
- goto bail;
+ return -EFAULT;
- status = 0;
-bail:
- if (status)
- o2info_set_request_error(&oij.ij_req, req);
-
- return status;
+ return 0;
}
int ocfs2_info_scan_inode_alloc(struct ocfs2_super *osb,
@@ -371,7 +328,7 @@ int ocfs2_info_handle_freeinode(struct inode *inode,
u32 i;
u64 blkno = -1;
char namebuf[40];
- int status = -EFAULT, type = INODE_ALLOC_SYSTEM_INODE;
+ int status, type = INODE_ALLOC_SYSTEM_INODE;
struct ocfs2_info_freeinode *oifi = NULL;
struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
struct inode *inode_alloc = NULL;
@@ -383,8 +340,10 @@ int ocfs2_info_handle_freeinode(struct inode *inode,
goto out_err;
}
- if (o2info_from_user(*oifi, req))
- goto bail;
+ if (o2info_from_user(*oifi, req)) {
+ status = -EFAULT;
+ goto out_free;
+ }
oifi->ifi_slotnum = osb->max_slots;
@@ -421,14 +380,16 @@ int ocfs2_info_handle_freeinode(struct inode *inode,
o2info_set_request_filled(&oifi->ifi_req);
- if (o2info_to_user(*oifi, req))
- goto bail;
+ if (o2info_to_user(*oifi, req)) {
+ status = -EFAULT;
+ goto out_free;
+ }
status = 0;
bail:
if (status)
o2info_set_request_error(&oifi->ifi_req, req);
-
+out_free:
kfree(oifi);
out_err:
return status;
@@ -655,7 +616,7 @@ int ocfs2_info_handle_freefrag(struct inode *inode,
{
u64 blkno = -1;
char namebuf[40];
- int status = -EFAULT, type = GLOBAL_BITMAP_SYSTEM_INODE;
+ int status, type = GLOBAL_BITMAP_SYSTEM_INODE;
struct ocfs2_info_freefrag *oiff;
struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
@@ -668,8 +629,10 @@ int ocfs2_info_handle_freefrag(struct inode *inode,
goto out_err;
}
- if (o2info_from_user(*oiff, req))
- goto bail;
+ if (o2info_from_user(*oiff, req)) {
+ status = -EFAULT;
+ goto out_free;
+ }
/*
* chunksize from userspace should be power of 2.
*/
@@ -708,14 +671,14 @@ int ocfs2_info_handle_freefrag(struct inode *inode,
if (o2info_to_user(*oiff, req)) {
status = -EFAULT;
- goto bail;
+ goto out_free;
}
status = 0;
bail:
if (status)
o2info_set_request_error(&oiff->iff_req, req);
-
+out_free:
kfree(oiff);
out_err:
return status;
@@ -724,23 +687,17 @@ out_err:
int ocfs2_info_handle_unknown(struct inode *inode,
struct ocfs2_info_request __user *req)
{
- int status = -EFAULT;
struct ocfs2_info_request oir;
if (o2info_from_user(oir, req))
- goto bail;
+ return -EFAULT;
o2info_clear_request_filled(&oir);
if (o2info_to_user(oir, req))
- goto bail;
+ return -EFAULT;
- status = 0;
-bail:
- if (status)
- o2info_set_request_error(&oir, req);
-
- return status;
+ return 0;
}
/*
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:20 +0200 |
| Subject | [PATCH 3.10 107/250] drm/i915: Don't leak edid in intel_crt_detect_ddc() |
| Message-ID | <tPSp3-4Iz-9@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Ander Conselvan de Oliveira <ander.conselvan.de.oliveira@intel.com>
commit c34f078675f505c4437919bb1897b1351f16a050 upstream.
In the path where intel_crt_detect_ddc() detects a CRT, if would return
true without freeing the edid.
Fixes: a2bd1f541f19 ("drm/i915: check whether we actually received an edid in detect_ddc")
Cc: Chris Wilson <chris@chris-wilson.co.uk>
Cc: Daniel Vetter <daniel.vetter@ffwll.ch>
Cc: Daniel Vetter <daniel.vetter@intel.com>
Cc: Jani Nikula <jani.nikula@linux.intel.com>
Cc: intel-gfx@lists.freedesktop.org
Signed-off-by: Ander Conselvan de Oliveira <ander.conselvan.de.oliveira@intel.com>
Reviewed-by: Ville Syrjälä <ville.syrjala@linux.intel.com>
Reviewed-by: Jani Nikula <jani.nikula@intel.com>
Link: http://patchwork.freedesktop.org/patch/msgid/1484922525-6131-1-git-send-email-ander.conselvan.de.oliveira@intel.com
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/gpu/drm/i915/intel_crt.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/gpu/drm/i915/intel_crt.c b/drivers/gpu/drm/i915/intel_crt.c
index 53435a9..93c80d7 100644
--- a/drivers/gpu/drm/i915/intel_crt.c
+++ b/drivers/gpu/drm/i915/intel_crt.c
@@ -428,6 +428,7 @@ static bool intel_crt_detect_ddc(struct drm_connector *connector)
struct drm_i915_private *dev_priv = crt->base.base.dev->dev_private;
struct edid *edid;
struct i2c_adapter *i2c;
+ bool ret = false;
BUG_ON(crt->base.type != INTEL_OUTPUT_ANALOG);
@@ -444,17 +445,17 @@ static bool intel_crt_detect_ddc(struct drm_connector *connector)
*/
if (!is_digital) {
DRM_DEBUG_KMS("CRT detected via DDC:0x50 [EDID]\n");
- return true;
+ ret = true;
+ } else {
+ DRM_DEBUG_KMS("CRT not detected via DDC:0x50 [EDID reports a digital panel]\n");
}
-
- DRM_DEBUG_KMS("CRT not detected via DDC:0x50 [EDID reports a digital panel]\n");
} else {
DRM_DEBUG_KMS("CRT not detected via DDC:0x50 [no valid EDID found]\n");
}
kfree(edid);
- return false;
+ return ret;
}
static enum drm_connector_status
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-08 01:20 +0200 |
| Subject | [PATCH 3.10 116/250] drm/i915: fix use-after-free in page_flip_completed() |
| Message-ID | <tPSp3-4Iz-7@gated-at.bofh.it> |
| In reply to | #1660349 |
From: Andrey Ryabinin <aryabinin@virtuozzo.com>
commit 5351fbb1bf1413f6024892093528280769ca852f upstream.
page_flip_completed() dereferences 'work' variable after executing
queue_work(). This is not safe as the 'work' item might be already freed
by queued work:
BUG: KASAN: use-after-free in page_flip_completed+0x3ff/0x490 at addr ffff8803dc010f90
Call Trace:
__asan_report_load8_noabort+0x59/0x80
page_flip_completed+0x3ff/0x490
intel_finish_page_flip_mmio+0xe3/0x130
intel_pipe_handle_vblank+0x2d/0x40
gen8_irq_handler+0x4a7/0xed0
__handle_irq_event_percpu+0xf6/0x860
handle_irq_event_percpu+0x6b/0x160
handle_irq_event+0xc7/0x1b0
handle_edge_irq+0x1f4/0xa50
handle_irq+0x41/0x70
do_IRQ+0x9a/0x200
common_interrupt+0x89/0x89
Freed:
kfree+0x113/0x4d0
intel_unpin_work_fn+0x29a/0x3b0
process_one_work+0x79e/0x1b70
worker_thread+0x611/0x1460
kthread+0x241/0x3a0
ret_from_fork+0x27/0x40
Move queue_work() after trace_i915_flip_complete() to fix this.
Fixes: e5510fac98a7 ("drm/i915: add tracepoints for flip requests & completions")
Signed-off-by: Andrey Ryabinin <aryabinin@virtuozzo.com>
Reviewed-by: Chris Wilson <chris@chris-wilson.co.uk>
Signed-off-by: Daniel Vetter <daniel.vetter@ffwll.ch>
Link: http://patchwork.freedesktop.org/patch/msgid/20170126143211.24013-1-aryabinin@virtuozzo.com
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Andrey Ryabinin <aryabinin@virtuozzo.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/gpu/drm/i915/intel_display.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/i915/intel_display.c b/drivers/gpu/drm/i915/intel_display.c
index 8814b0d..a7dbdec 100644
--- a/drivers/gpu/drm/i915/intel_display.c
+++ b/drivers/gpu/drm/i915/intel_display.c
@@ -7052,9 +7052,9 @@ static void do_intel_finish_page_flip(struct drm_device *dev,
wake_up_all(&dev_priv->pending_flip_queue);
- queue_work(dev_priv->wq, &work->work);
-
trace_i915_flip_complete(intel_crtc->plane, work->pending_flip_obj);
+
+ queue_work(dev_priv->wq, &work->work);
}
void intel_finish_page_flip(struct drm_device *dev, int pipe)
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
Page 1 of 11 [1] 2 3 … 11 Next page →
Back to top | Article view | linux.kernel
csiph-web