Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1660349 > unrolled thread

[PATCH 3.10 000/250] 3.10.106-stable review

Started byWilly Tarreau <w@1wt.eu>
First post2017-06-08 01:10 +0200
Last post2017-06-08 06:30 +0200
Articles 20 on this page of 214 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.10 000/250] 3.10.106-stable review Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 188/250] uwb: hwa-rc: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 167/250] USB: serial: io_ti: fix NULL-deref in interrupt callback Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 136/250] mfd: pm8921: Potential NULL dereference in pm8921_remove() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 099/250] ubifs: Fix journal replay wrt. xattr nodes Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 102/250] arm64/ptrace: Reject attempts to set incomplete hardware breakpoint fields Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 223/250] Staging: vt6655-6: potential NULL dereference in hostap_disable_hostapd() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 006/250] KVM: x86: Introduce segmented_write_std Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 181/250] Input: hanwang - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 049/250] USB: serial: io_edgeport: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 090/250] powerpc/ibmebus: Fix further device reference leaks Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 172/250] net: net_enable_timestamp() can be called from irq contexts Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 159/250] USB: serial: digi_acceleport: fix OOB data sanity check Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 139/250] vti4: Don't count header length twice. Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 178/250] net: properly release sk_frag.page Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 229/250] USB: dummy-hcd: fix bug in stop_activity (handle ep0) Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 123/250] packet: fix races in fanout_add() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 135/250] ocfs2: do not write error flag to user structure we cannot copy from/to Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 107/250] drm/i915: Don't leak edid in intel_crt_detect_ddc() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 116/250] drm/i915: fix use-after-free in page_flip_completed() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 202/250] metag/usercopy: Fix alignment error checking Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 236/250] ipv6: fix ip6_tnl_parse_tlv_enc_lim() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 134/250] goldfish: Sanitize the broken interrupt handler Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 234/250] xc2028: unlock on error in xc2028_set_config() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 158/250] dm: flush queued bios when process blocks to avoid deadlock Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 013/250] xfrm_user: validate XFRM_MSG_NEWAE incoming ESN size harder Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 120/250] ip6_gre: fix ip6gre_err() invalid reads Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 160/250] USB: serial: digi_acceleport: fix OOB-event processing Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 217/250] net: phy: handle state correctly in phy_stop_machine Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 062/250] staging: iio: ad7606: fix improper setting of oversampling pins Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 016/250] KEYS: fix keyctl_set_reqkey_keyring() to not leak thread keyrings Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 197/250] USB: OHCI: Fix race between ED unlink and URB submission Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 100/250] arm64/ptrace: Preserve previous registers for short regset write Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 133/250] x86/platform/goldfish: Prevent unconditional loading Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 220/250] ARM: dts: imx31: move CCM device node to AIPS2 bus devices Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 075/250] gro: Enter slow-path if there is no tailroom Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 083/250] USB: serial: ch341: fix open error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 230/250] mm/init: fix zone boundary creation Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 204/250] metag/usercopy: Set flags before ADDZ Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 149/250] scsi: aacraid: Reorder Adapter status check Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 101/250] arm64/ptrace: Avoid uninitialised struct padding in fpr_set() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 046/250] USB: serial: iuu_phoenix: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 026/250] ext4: fix stack memory corruption with 64k block size Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 012/250] xfrm_user: validate XFRM_MSG_NEWAE XFRMA_REPLAY_ESN_VAL replay_window Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 201/250] ring-buffer: Fix return value check in test_ringbuffer() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 091/250] powerpc/ibmebus: Fix device reference leaks in sysfs interface Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 118/250] ipv4: keep skb->dst around in presence of IP options Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 113/250] ARM: 8643/3: arm/ptrace: Preserve previous registers for short regset write Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 020/250] hotplug: Make register and unregister notifier API symmetric Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 156/250] ktest: Fix child exit code processing Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 078/250] powerpc: Fix build warning on 32-bit PPC Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 103/250] ARM: ux500: fix prcmu_is_cpu_in_wfi() calculation Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 060/250] ALSA: usb-audio: Fix bogus error return in snd_usb_create_stream() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 147/250] MIPS: Handle microMIPS jumps in the same way as MIPS32/MIPS64 jumps Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 036/250] IB/multicast: Check ib_find_pkey() return value Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 073/250] net, sched: fix soft lockup in tc_classify Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 173/250] dccp/tcp: fix routing redirect race Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 087/250] USB: serial: ch341: fix modem-control and B0 handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 203/250] metag/usercopy: Add early abort to copy_to_user Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 063/250] usb: dwc3: gadget: always unmap EP0 requests Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 094/250] perf scripting: Avoid leaking the scripting_context variable Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 219/250] MIPS: KGDB: Use kernel context for sleeping threads Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 132/250] USB: serial: ark3116: fix register-accessor error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 130/250] USB: serial: spcp8x5: fix modem-status handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 227/250] ping: implement proper locking Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 092/250] IB/mlx4: Set traffic class in AH Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 040/250] USB: serial: quatech2: fix sleep-while-atomic in close Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 187/250] uwb: i1480-dfu: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 242/250] kvm: exclude ioeventfd from counting kvm_io_range limit Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 222/250] tun: Fix TUN_PKT_STRIP setting Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 068/250] scsi: mvsas: fix command_active typo Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 207/250] s390/decompressor: fix initrd corruption caused by bss clear Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 161/250] MIPS: ip27: Disable qlge driver in defconfig Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 104/250] ite-cir: initialize use_demodulator before using it Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 228/250] USB: fix problems with duplicate endpoint addresses Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 143/250] MIPS: Prevent unaligned accesses during stack unwinding Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 208/250] net/mlx4_en: Fix bad WQE issue Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 119/250] netlabel: out of bound access in cipso_v4_validate() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 065/250] hwmon: (ds620) Fix overflows seen when writing temperature limits Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 162/250] tracing: Add #undef to fix compile error Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 177/250] xen: do not re-use pirq number cached in pci device msi msg data Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 144/250] MIPS: Fix get_frame_info() handling of microMIPS function size Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 237/250] ipv6: pointer math error in ip6_tnl_parse_tlv_enc_lim() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 216/250] netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT" failed in 64bit kernel Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 193/250] ALSA: ctxfi: Fix the incorrect check of dma_set_mask() call Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 206/250] metag/usercopy: Add missing fixups Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 225/250] perf trace: Use the syscall raw_syscalls:sys_enter timestamp Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 072/250] ser_gigaset: return -ENOMEM on error instead of success Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 051/250] USB: serial: cyberjack: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 155/250] IB/ipoib: Fix deadlock between rmmod and set_mode Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 175/250] perf/core: Fix event inheritance on fork() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 211/250] powerpc: Disable HFSCR[TM] if TM is not supported Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 192/250] ALSA: ctxfi: Fallback DMA mask to 32bit Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 232/250] Drivers: hv: avoid vfree() on crash Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 249/250] dccp/tcp: do not inherit mc_list from parent Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 033/250] scsi: zfcp: fix rport unblock race with LUN recovery Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 171/250] locking/static_keys: Add static_key_{en,dis}able() helpers Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 096/250] svcrpc: don't leak contexts on PROC_DESTROY Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 055/250] USB: serial: mos7720: fix use-after-free on probe errors Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 125/250] net: socket: fix recvmmsg not returning error from sock_error Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 039/250] USB: serial: omninet: fix NULL-derefs at open and disconnect Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 117/250] net: use a work queue to defer net_disable_timestamp() work Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 077/250] gro: Disable frag0 optimization on IPv6 ext headers Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 064/250] cris: Only build flash rescue image if CONFIG_ETRAX_AXISFLASHMAP is selected Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 110/250] net: fix harmonize_features() vs NETIF_F_HIGHDMA Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 180/250] Input: ims-pcu - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 244/250] TTY: n_hdlc, fix lockdep false positive Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 235/250] xc2028: Fix use-after-free bug properly Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 148/250] uvcvideo: Fix a wrong macro Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 004/250] libceph: don't set weight to IN when OSD is destroyed Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 200/250] ptrace: fix PTRACE_LISTEN race corrupting task->state Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 250/250] char: lp: fix possible integer overflow in lp_setup() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 239/250] sctp: avoid BUG_ON on sctp_wait_for_sndbuf Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 080/250] mm/hugetlb.c: fix reservation race when freeing surplus pages Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 041/250] USB: serial: pl2303: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 168/250] USB: serial: io_ti: fix information leak in completion handler Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 233/250] xc2028: avoid use after free Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 122/250] l2tp: do not use udp_ioctl() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 146/250] MIPS: Calculate microMIPS ra properly when unwinding the stack Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 048/250] USB: serial: ti_usb_3410_5052: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 231/250] can: Fix kernel panic at security_sock_rcv_skb Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 182/250] Input: yealink - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 183/250] Input: cm109 - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 240/250] sctp: deny peeloff operation on asocs with threads sleeping on it Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 176/250] isdn/gigaset: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 052/250] USB: serial: kobil_sct: fix NULL-deref in write Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 153/250] NFSv4: fix getacl head length estimation Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 082/250] USB: serial: ch341: fix initial modem-control state Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 190/250] ext4: mark inode dirty after converting inline directory Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 086/250] USB: serial: ch341: fix resume after reset Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 127/250] USB: serial: ftdi_sio: fix modem-status error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 218/250] l2tp: take reference on sessions being dumped Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 015/250] KEYS: Change the name of the dead type to ".dead" to prevent user access Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 198/250] i2c: at91: manage unexpected RXRDY flag when starting a transfer Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 021/250] Btrfs: fix tree search logic when replaying directory entry deletes Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 034/250] ftrace/x86_32: Set ftrace_stub to weak to prevent gcc from using short jumps to it Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 184/250] USB: uss720: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 005/250] KVM: x86: fix emulation of "MOV SS, null selector" Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 151/250] fuse: add missing FR_FORCE Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 154/250] s390/qdio: clear DSCI prior to scanning multiple input queues Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 224/250] net: sctp: rework multihoming retransmission path selection to rfc4960 Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 247/250] fs: exec: apply CLOEXEC before changing dumpable task flags Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 191/250] scsi: libsas: fix ata xfer length Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 032/250] scsi: zfcp: do not trace pure benign residual HBA responses at default level Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 088/250] x86/cpu: Fix bootup crashes by sanitizing the argument of the 'clearcpuid=' command-line option Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 189/250] mmc: ushc: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 141/250] MIPS: OCTEON: Fix copy_from_user fault handling for large buffers Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 108/250] s5k4ecgx: select CRC32 helper Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 150/250] ath9k: use correct OTP register offsets for the AR9340 and AR9550 Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 124/250] packet: Do not call fanout_release from atomic contexts Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 152/250] RDMA/core: Fix incorrect structure packing for booleans Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 076/250] gro: use min_t() in skb_gro_reset_offset() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 105/250] fuse: do not use iocb after it may have been freed Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 245/250] tty: n_hdlc: get rid of racy n_hdlc.tbuf Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 067/250] iommu/amd: Fix the left value check of cmd buffer Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 164/250] USB: serial: omninet: fix reference leaks at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 140/250] net/sched: em_meta: Fix 'meta vlan' to correctly recognize zero VID frames Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 029/250] f2fs: set ->owner for debugfs status file's file_operations Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 058/250] usb: xhci-mem: use passed in GFP flags instead of GFP_KERNEL Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 031/250] scsi: zfcp: fix use-after-"free" in FC ingress path after TMF Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 023/250] block_dev: don't test bdev->bd_contains when it is not stable Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 157/250] nlm: Ensure callback code also checks that the files match Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 089/250] NFSv4.1: nfs4_fl_prepare_ds must be careful about reporting success. Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 209/250] net/mlx4_core: Fix racy CQ (Completion Queue) free Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 112/250] svcrpc: fix oops in absence of krb5 module Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
      Re: [PATCH 3.10 112/250] svcrpc: fix oops in absence of krb5 module Simo Sorce <simo@redhat.com> - 2017-06-08 10:20 +0200
    [PATCH 3.10 114/250] mac80211: Fix adding of mesh vendor IEs Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 246/250] ipv6: handle -EFAULT from skb_copy_bits Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 138/250] net: 6lowpan: fix lowpan_header_create non-compression memcpy call Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 059/250] usb: musb: Fix trying to free already-free IRQ 4 Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 137/250] drm/nv50/disp: min/max are reversed in nv50_crtc_gamma_set() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 097/250] mmc: mxs-mmc: Fix additional cycles after transmission stop Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 205/250] metag/usercopy: Fix src fixup in from user rapf loops Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 165/250] USB: iowarrior: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 131/250] USB: serial: opticon: fix CTS retrieval at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 215/250] ring-buffer: Have ring_buffer_iter_empty() return true when empty Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 098/250] mtd: nand: xway: disable module support Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 044/250] USB: serial: io_ti: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 212/250] pegasus: Use heap buffers for all register access Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 214/250] tracing: Allocate the snapshot buffer before enabling probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 106/250] crypto: caam - fix non-hmac hashes Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 169/250] vxlan: correctly validate VXLAN ID against VXLAN_N_VID Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 002/250] crypto: crypto_memneq - add equality testing of memory regions w/o timing leaks Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 071/250] powerpc/pci/rpadlpar: Fix device reference leaks Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 194/250] ACPI / PNP: Avoid conflicting resource reservations Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 047/250] USB: serial: garmin_gps: fix memory leak on failed URB submit Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 018/250] locking/rtmutex: Prevent dequeue vs. unlock race Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 195/250] ACPI / resources: free memory on error in add_region_before() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 179/250] net: unix: properly re-increment inflight counter of GC discarded candidates Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 054/250] USB: serial: mos7720: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 074/250] net: stmmac: Fix race between stmmac_drv_probe and stmmac_open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 042/250] USB: serial: keyspan_pda: verify endpoints at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 028/250] ext4: return -ENOMEM instead of success Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 038/250] usb: gadget: composite: Test get_alt() presence instead of set_alt() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 017/250] ext4: fix data exposure after a crash Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 025/250] ext4: fix mballoc breakage with 64k block size Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 030/250] block: protect iterate_bdevs() against concurrent close Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 111/250] tcp: initialize max window for a new fastopen socket Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 009/250] fbdev: color map copying bounds checking Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 126/250] USB: serial: mos7840: fix another NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 035/250] IB/mad: Fix an array index check Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 050/250] USB: serial: oti6858: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 001/250] packet: fix race condition in packet_set_ring Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 081/250] USB: serial: kl5kusb105: fix line-state error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 079/250] Input: i8042 - add Pegatron touchpad to noloop table Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 037/250] powerpc: Convert cmp to cmpd in idle enter sequence Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 061/250] USB: serial: kl5kusb105: abort on open exception path Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 024/250] crypto: caam - fix AEAD givenc descriptors Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 010/250] selinux: fix off-by-one in setprocattr Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 043/250] USB: serial: spcp8x5: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 142/250] MIPS: Clear ISA bit correctly in get_frame_info() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 019/250] m68k: Fix ndelay() macro Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    Re: [PATCH 3.10 000/250] 3.10.106-stable review Guenter Roeck <linux@roeck-us.net> - 2017-06-08 02:40 +0200
      Re: [PATCH 3.10 000/250] 3.10.106-stable review Willy Tarreau <w@1wt.eu> - 2017-06-08 06:30 +0200

Page 1 of 11  [1] 2 3 … 11  Next page →


#1660349 — [PATCH 3.10 000/250] 3.10.106-stable review

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 000/250] 3.10.106-stable review
Message-ID<tPSfn-4Fa-3@gated-at.bofh.it>
This is the start of the stable review cycle for the 3.10.106 release.
It was build-tested on x86_64 with allmodconfig.

All patches will be posted as a response to this one. If anyone has any
issue with these being applied, please let me know. If anyone thinks some
important patches are missing and should be added prior to the release,
please report them quickly with their respective mainline commit IDs.

Responses should be made by Wed Jun 14 00:43:43 CEST 2017.
Anything received after that time might be too late. If someone
wants a bit more time for a deeper review, please let me know.

The whole patch series can be found in one patch at :
   https://kernel.org/pub/linux/kernel/v3.x/stable-review/patch-3.10.106-rc1.gz

The shortlog and diffstat are appended below.

Thanks,
Willy

===============


Alan Stern (3):
  USB: OHCI: Fix race between ED unlink and URB submission
  USB: fix problems with duplicate endpoint addresses
  USB: dummy-hcd: fix bug in stop_activity (handle ep0)

Aleksa Sarai (1):
  fs: exec: apply CLOEXEC before changing dumpable task flags

Alex Porosanu (1):
  crypto: caam - fix AEAD givenc descriptors

Alexander Popov (1):
  tty: n_hdlc: get rid of racy n_hdlc.tbuf

Alexey Kodanev (1):
  tcp: initialize max window for a new fastopen socket

Amos Kong (1):
  kvm: exclude ioeventfd from counting kvm_io_range limit

Ander Conselvan de Oliveira (1):
  drm/i915: Don't leak edid in intel_crt_detect_ddc()

Andrew Lunn (1):
  ipv4: igmp: Allow removing groups from a removed interface

Andrey Ryabinin (1):
  drm/i915: fix use-after-free in page_flip_completed()

Andrey Ulanov (1):
  net: unix: properly re-increment inflight counter of GC discarded
    candidates

Andy Shevchenko (1):
  platform/x86: intel_mid_powerbtn: Set IRQ_ONESHOT

Andy Whitcroft (2):
  xfrm_user: validate XFRM_MSG_NEWAE XFRMA_REPLAY_ESN_VAL replay_window
  xfrm_user: validate XFRM_MSG_NEWAE incoming ESN size harder

Anoob Soman (1):
  packet: Do not call fanout_release from atomic contexts

Arnaldo Carvalho de Melo (2):
  perf scripting: Avoid leaking the scripting_context variable
  perf trace: Use the syscall raw_syscalls:sys_enter timestamp

Arnd Bergmann (4):
  scsi: mvsas: fix command_active typo
  ARM: ux500: fix prcmu_is_cpu_in_wfi() calculation
  s5k4ecgx: select CRC32 helper
  MIPS: ip27: Disable qlge driver in defconfig

Bart Van Assche (2):
  IB/mad: Fix an array index check
  IB/multicast: Check ib_find_pkey() return value

Ben Hutchings (3):
  ocfs2: do not write error flag to user structure we cannot copy
    from/to
  pegasus: Use heap buffers for all register access
  rtl8150: Use heap buffers for all register access

Benjamin Block (1):
  scsi: zfcp: fix use-after-"free" in FC ingress path after TMF

Benjamin Herrenschmidt (1):
  powerpc: Disable HFSCR[TM] if TM is not supported

Boris Brezillon (1):
  m68k: Fix ndelay() macro

Chandan Rajendra (2):
  ext4: fix mballoc breakage with 64k block size
  ext4: fix stack memory corruption with 64k block size

Christian Lamparter (1):
  ath9k: use correct OTP register offsets for the AR9340 and AR9550

Dan Carpenter (11):
  ext4: return -ENOMEM instead of success
  usb: xhci-mem: use passed in GFP flags instead of GFP_KERNEL
  target/iscsi: Fix double free in lio_target_tiqn_addtpg()
  mmc: mmc_test: Uninitialized return value
  ser_gigaset: return -ENOMEM on error instead of success
  mfd: pm8921: Potential NULL dereference in pm8921_remove()
  drm/nv50/disp: min/max are reversed in nv50_crtc_gamma_set()
  ACPI / resources: free memory on error in add_region_before()
  Staging: vt6655-6: potential NULL dereference in
    hostap_disable_hostapd()
  xc2028: unlock on error in xc2028_set_config()
  ipv6: pointer math error in ip6_tnl_parse_tlv_enc_lim()

Dan Streetman (1):
  xen: do not re-use pirq number cached in pci device msi msg data

Daniel Borkmann (3):
  net, sched: fix soft lockup in tc_classify
  net: 6lowpan: fix lowpan_header_create non-compression memcpy call
  net: sctp: rework multihoming retransmission path selection to rfc4960

Darrick J. Wong (1):
  ext4: reject inodes with negative size

Dave Jones (1):
  ipv6: handle -EFAULT from skb_copy_bits

Dave Martin (4):
  arm64/ptrace: Preserve previous registers for short regset write
  arm64/ptrace: Avoid uninitialised struct padding in fpr_set()
  arm64/ptrace: Reject attempts to set incomplete hardware breakpoint
    fields
  ARM: 8643/3: arm/ptrace: Preserve previous registers for short regset
    write

David Hildenbrand (1):
  KVM: kvm_io_bus_unregister_dev() should never fail

David Howells (2):
  KEYS: Disallow keyrings beginning with '.' to be joined as session
    keyrings
  KEYS: Change the name of the dead type to ".dead" to prevent user
    access

Eric Biggers (2):
  KEYS: fix keyctl_set_reqkey_keyring() to not leak thread keyrings
  ext4: mark inode dirty after converting inline directory

Eric Dumazet (15):
  tcp: avoid infinite loop in tcp_splice_read()
  gro: use min_t() in skb_gro_reset_offset()
  net: fix harmonize_features() vs NETIF_F_HIGHDMA
  net: use a work queue to defer net_disable_timestamp() work
  ipv4: keep skb->dst around in presence of IP options
  netlabel: out of bound access in cipso_v4_validate()
  ip6_gre: fix ip6gre_err() invalid reads
  l2tp: do not use udp_ioctl()
  packet: fix races in fanout_add()
  net: net_enable_timestamp() can be called from irq contexts
  net: properly release sk_frag.page
  ping: implement proper locking
  can: Fix kernel panic at security_sock_rcv_skb
  ipv6: fix ip6_tnl_parse_tlv_enc_lim()
  dccp/tcp: do not inherit mc_list from parent

Eugenia Emantayev (1):
  net/mlx4_en: Fix bad WQE issue

Eva Rachel Retuya (1):
  staging: iio: ad7606: fix improper setting of oversampling pins

Felipe Balbi (1):
  usb: dwc3: gadget: always unmap EP0 requests

Feras Daoud (1):
  IB/ipoib: Fix deadlock between rmmod and set_mode

Florian Fainelli (1):
  net: stmmac: Fix race between stmmac_drv_probe and stmmac_open

Geert Uytterhoeven (1):
  char: Drop bogus dependency of DEVPORT on !M68K

Gu Zheng (1):
  tmpfs: clear S_ISGID when setting posix ACLs

Guennadi Liakhovetski (1):
  uvcvideo: Fix a wrong macro

Guenter Roeck (2):
  cris: Only build flash rescue image if CONFIG_ETRAX_AXISFLASHMAP is
    selected
  hwmon: (ds620) Fix overflows seen when writing temperature limits

Guillaume Nault (1):
  l2tp: take reference on sessions being dumped

Hauke Mehrtens (1):
  mtd: nand: xway: disable module support

Herbert Xu (3):
  gro: Enter slow-path if there is no tailroom
  gro: Disable frag0 optimization on IPv6 ext headers
  tun: Fix TUN_PKT_STRIP setting

Hongxu Jia (1):
  netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT"
    failed in 64bit kernel

Huang Rui (1):
  iommu/amd: Fix the left value check of cmd buffer

Ilya Dryomov (1):
  libceph: don't set weight to IN when OSD is destroyed

J. Bruce Fields (3):
  svcrpc: don't leak contexts on PROC_DESTROY
  svcrpc: fix oops in absence of krb5 module
  NFSv4: fix getacl head length estimation

Jack Morgenstein (1):
  net/mlx4_core: Fix racy CQ (Completion Queue) free

James Cowgill (1):
  MIPS: OCTEON: Fix copy_from_user fault handling for large buffers

James Hogan (6):
  metag/usercopy: Fix alignment error checking
  metag/usercopy: Add early abort to copy_to_user
  metag/usercopy: Set flags before ADDZ
  metag/usercopy: Fix src fixup in from user rapf loops
  metag/usercopy: Add missing fixups
  MIPS: KGDB: Use kernel context for sleeping threads

James Yonan (1):
  crypto: crypto_memneq - add equality testing of memory regions w/o
    timing leaks

Jan Kara (2):
  posix_acl: Clear SGID bit when setting file permissions
  ext4: fix data exposure after a crash

Jason Gunthorpe (1):
  RDMA/core: Fix incorrect structure packing for booleans

Jiri Slaby (1):
  TTY: n_hdlc, fix lockdep false positive

Johan Hovold (57):
  USB: serial: kl5kusb105: fix open error path
  USB: serial: omninet: fix NULL-derefs at open and disconnect
  USB: serial: quatech2: fix sleep-while-atomic in close
  USB: serial: pl2303: fix NULL-deref at open
  USB: serial: keyspan_pda: verify endpoints at probe
  USB: serial: spcp8x5: fix NULL-deref at open
  USB: serial: io_ti: fix NULL-deref at open
  USB: serial: io_ti: fix another NULL-deref at open
  USB: serial: iuu_phoenix: fix NULL-deref at open
  USB: serial: garmin_gps: fix memory leak on failed URB submit
  USB: serial: ti_usb_3410_5052: fix NULL-deref at open
  USB: serial: io_edgeport: fix NULL-deref at open
  USB: serial: oti6858: fix NULL-deref at open
  USB: serial: cyberjack: fix NULL-deref at open
  USB: serial: kobil_sct: fix NULL-deref in write
  USB: serial: mos7840: fix NULL-deref at open
  USB: serial: mos7720: fix NULL-deref at open
  USB: serial: mos7720: fix use-after-free on probe errors
  USB: serial: mos7720: fix parport use-after-free on probe errors
  USB: serial: mos7720: fix parallel probe
  powerpc/pci/rpadlpar: Fix device reference leaks
  USB: serial: kl5kusb105: fix line-state error handling
  USB: serial: ch341: fix initial modem-control state
  USB: serial: ch341: fix open error handling
  USB: serial: ch341: fix control-message error handling
  USB: serial: ch341: fix open and resume after B0
  USB: serial: ch341: fix resume after reset
  USB: serial: ch341: fix modem-control and B0 handling
  powerpc/ibmebus: Fix further device reference leaks
  powerpc/ibmebus: Fix device reference leaks in sysfs interface
  USB: serial: mos7840: fix another NULL-deref at open
  USB: serial: ftdi_sio: fix modem-status error handling
  USB: serial: ftdi_sio: fix extreme low-latency setting
  USB: serial: ftdi_sio: fix line-status over-reporting
  USB: serial: spcp8x5: fix modem-status handling
  USB: serial: opticon: fix CTS retrieval at open
  USB: serial: ark3116: fix register-accessor error handling
  USB: serial: digi_acceleport: fix OOB data sanity check
  USB: serial: digi_acceleport: fix OOB-event processing
  USB: serial: safe_serial: fix information leak in completion handler
  USB: serial: omninet: fix reference leaks at open
  USB: iowarrior: fix NULL-deref at probe
  USB: iowarrior: fix NULL-deref in write
  USB: serial: io_ti: fix NULL-deref in interrupt callback
  USB: serial: io_ti: fix information leak in completion handler
  isdn/gigaset: fix NULL-deref at probe
  Input: ims-pcu - validate number of endpoints before using them
  Input: hanwang - validate number of endpoints before using them
  Input: yealink - validate number of endpoints before using them
  Input: cm109 - validate number of endpoints before using them
  USB: uss720: fix NULL-deref at probe
  USB: idmouse: fix NULL-deref at probe
  USB: wusbcore: fix NULL-deref at probe
  uwb: i1480-dfu: fix NULL-deref at probe
  uwb: hwa-rc: fix NULL-deref at probe
  mmc: ushc: fix NULL-deref at probe
  USB: usbtmc: add missing endpoint sanity check

John Garry (1):
  scsi: libsas: fix ata xfer length

Jon Maxwell (1):
  dccp/tcp: fix routing redirect race

Julian Anastasov (1):
  ipv4: mask tos for input route

Julian Wiedmann (1):
  s390/qdio: clear DSCI prior to scanning multiple input queues

Kees Cook (1):
  fbdev: color map copying bounds checking

Keno Fischer (1):
  mm/huge_memory.c: respect FOLL_FORCE/FOLL_COW for thp

Krzysztof Opasiak (1):
  usb: gadget: composite: Test get_alt() presence instead of set_alt()

Larry Finger (1):
  powerpc: Fix build warning on 32-bit PPC

Li RongQing (1):
  ipv6: fix the use of pcpu_tstats in ip6_tunnel

Ludovic Desroches (1):
  i2c: at91: manage unexpected RXRDY flag when starting a transfer

Lukasz Odzioba (1):
  x86/cpu: Fix bootup crashes by sanitizing the argument of the
    'clearcpuid=' command-line option

Maor Gottlieb (1):
  IB/mlx4: Set traffic class in AH

Marcelo Henrique Cerri (1):
  s390/decompressor: fix initrd corruption caused by bss clear

Marcelo Ricardo Leitner (2):
  sctp: avoid BUG_ON on sctp_wait_for_sndbuf
  sctp: deny peeloff operation on asocs with threads sleeping on it

Marcos Paulo de Souza (1):
  Input: i8042 - add Pegatron touchpad to noloop table

Matthias Schiffer (1):
  vxlan: correctly validate VXLAN ID against VXLAN_N_VID

Mauro Carvalho Chehab (1):
  xc2028: avoid use after free

Maxime Jayat (1):
  net: socket: fix recvmmsg not returning error from sock_error

Michal Hocko (1):
  hotplug: Make register and unregister notifier API symmetric

Mike Kravetz (1):
  mm/hugetlb.c: fix reservation race when freeing surplus pages

Miklos Szeredi (1):
  fuse: add missing FR_FORCE

Mikulas Patocka (1):
  dm: flush queued bios when process blocks to avoid deadlock

Nathan Sullivan (1):
  net: phy: handle state correctly in phy_stop_machine

NeilBrown (2):
  block_dev: don't test bdev->bd_contains when it is not stable
  NFSv4.1: nfs4_fl_prepare_ds must be careful about reporting success.

Nicolai Stange (1):
  f2fs: set ->owner for debugfs status file's file_operations

Nicolas Iooss (1):
  ite-cir: initialize use_demodulator before using it

Oliver O'Halloran (1):
  mm/init: fix zone boundary creation

Pan Bian (2):
  USB: serial: kl5kusb105: abort on open exception path
  clk: clk-wm831x: fix a logic error

Paolo Bonzini (1):
  KVM: x86: fix emulation of "MOV SS, null selector"

Paul Burton (6):
  MIPS: Clear ISA bit correctly in get_frame_info()
  MIPS: Prevent unaligned accesses during stack unwinding
  MIPS: Fix get_frame_info() handling of microMIPS function size
  MIPS: Fix is_jump_ins() handling of 16b microMIPS instructions
  MIPS: Calculate microMIPS ra properly when unwinding the stack
  MIPS: Handle microMIPS jumps in the same way as MIPS32/MIPS64 jumps

Peter Xu (1):
  KVM: x86: clear bus pointer when destroyed

Peter Zijlstra (2):
  locking/static_keys: Add static_key_{en,dis}able() helpers
  perf/core: Fix event inheritance on fork()

Philip Pettersson (1):
  packet: fix race condition in packet_set_ring

Rabin Vincent (1):
  block: protect iterate_bdevs() against concurrent close

Rafael J. Wysocki (2):
  ACPI / PNP: Avoid conflicting resource reservations
  ACPI / PNP: Reserve ACPI resources at the fs_initcall_sync stage

Raghava Aditya Renukunta (1):
  scsi: aacraid: Reorder Adapter status check

Richard Weinberger (1):
  ubifs: Fix journal replay wrt. xattr nodes

Rik van Riel (1):
  tracing: Add #undef to fix compile error

Robbie Ko (1):
  Btrfs: fix tree search logic when replaying directory entry deletes

Robert Doebbelin (1):
  fuse: do not use iocb after it may have been freed

Roman Mashak (1):
  net sched actions: decrement module reference count after table flush.

Russell King (1):
  crypto: caam - fix non-hmac hashes

Ryan Ware (1):
  EVM: Use crypto_memneq() for digest comparisons

Saeed Mahameed (1):
  IB/mlx4: Fix port query for 56Gb Ethernet links

Segher Boessenkool (1):
  powerpc: Convert cmp to cmpd in idle enter sequence

Shmulik Ladkani (1):
  net/sched: em_meta: Fix 'meta vlan' to correctly recognize zero VID
    frames

Stefan Wahren (1):
  mmc: mxs-mmc: Fix additional cycles after transmission stop

Steffen Klassert (1):
  vti4: Don't count header length twice.

Steffen Maier (3):
  scsi: zfcp: do not trace pure benign residual HBA responses at default
    level
  scsi: zfcp: fix rport unblock race with LUN recovery
  scsi: zfcp: fix use-after-free by not tracing WKA port open/close on
    failed send

Stephen Smalley (1):
  selinux: fix off-by-one in setprocattr

Steve Rutherford (1):
  KVM: x86: Introduce segmented_write_std

Steven Rostedt (Red Hat) (1):
  ftrace/x86_32: Set ftrace_stub to weak to prevent gcc from using short
    jumps to it

Steven Rostedt (VMware) (3):
  ktest: Fix child exit code processing
  tracing: Allocate the snapshot buffer before enabling probe
  ring-buffer: Have ring_buffer_iter_empty() return true when empty

Takashi Iwai (4):
  ALSA: usb-audio: Fix bogus error return in snd_usb_create_stream()
  ALSA: ctxfi: Fallback DMA mask to 32bit
  ALSA: ctxfi: Fix the incorrect check of dma_set_mask() call
  xc2028: Fix use-after-free bug properly

Thomas Gleixner (3):
  locking/rtmutex: Prevent dequeue vs. unlock race
  x86/platform/goldfish: Prevent unconditional loading
  goldfish: Sanitize the broken interrupt handler

Thorsten Horstmann (1):
  mac80211: Fix adding of mesh vendor IEs

Tony Lindgren (1):
  usb: musb: Fix trying to free already-free IRQ 4

Trond Myklebust (1):
  nlm: Ensure callback code also checks that the files match

Vitaly Kuznetsov (1):
  Drivers: hv: avoid vfree() on crash

Vladimir Zapolskiy (3):
  ARM: dts: imx31: fix clock control module interrupts description
  ARM: dts: imx31: move CCM device node to AIPS2 bus devices
  ARM: dts: imx31: fix AVIC base address

WANG Cong (1):
  ping: fix a null pointer dereference

Wei Yongjun (1):
  ring-buffer: Fix return value check in test_ringbuffer()

Willy Tarreau (1):
  char: lp: fix possible integer overflow in lp_setup()

bsegall@google.com (1):
  ptrace: fix PTRACE_LISTEN race corrupting task->state

 .../devicetree/bindings/clock/imx31-clock.txt      |   2 +-
 Documentation/kernel-parameters.txt                |   4 +
 arch/arm/boot/dts/imx31.dtsi                       |  18 +--
 arch/arm/kernel/ptrace.c                           |   2 +-
 arch/arm/mach-ux500/pm.c                           |   4 +-
 arch/arm64/include/uapi/asm/ptrace.h               |   1 +
 arch/arm64/kernel/ptrace.c                         |  11 +-
 arch/cris/boot/rescue/Makefile                     |   8 ++
 arch/m68k/include/asm/delay.h                      |   2 +-
 arch/metag/lib/usercopy.c                          | 146 ++++++++++++++------
 arch/mips/cavium-octeon/octeon-memcpy.S            |  20 +--
 arch/mips/configs/ip27_defconfig                   |   1 -
 arch/mips/kernel/kgdb.c                            |  48 +++++--
 arch/mips/kernel/process.c                         | 153 +++++++++++++--------
 arch/powerpc/kernel/ibmebus.c                      |  16 ++-
 arch/powerpc/kernel/idle_power7.S                  |   2 +-
 arch/powerpc/kernel/misc_32.S                      |   2 +-
 arch/powerpc/kernel/setup_64.c                     |   9 ++
 arch/s390/boot/compressed/misc.c                   |  35 ++---
 arch/x86/kernel/cpu/common.c                       |   2 +-
 arch/x86/kernel/entry_32.S                         |   4 +-
 arch/x86/kvm/emulate.c                             |  66 +++++++--
 arch/x86/pci/xen.c                                 |  23 +---
 arch/x86/platform/goldfish/goldfish.c              |  14 +-
 crypto/Makefile                                    |   7 +-
 crypto/asymmetric_keys/rsa.c                       |   5 +-
 crypto/authenc.c                                   |   6 +-
 crypto/authencesn.c                                |   8 +-
 crypto/ccm.c                                       |   4 +-
 crypto/gcm.c                                       |   2 +-
 crypto/memneq.c                                    | 138 +++++++++++++++++++
 drivers/acpi/osl.c                                 |   6 +-
 drivers/char/Kconfig                               |   1 -
 drivers/char/lp.c                                  |   6 +-
 drivers/clk/clk-wm831x.c                           |   2 +-
 drivers/crypto/caam/caamalg.c                      |   4 +-
 drivers/crypto/caam/caamhash.c                     |   1 +
 drivers/gpu/drm/i915/intel_crt.c                   |   9 +-
 drivers/gpu/drm/i915/intel_display.c               |   4 +-
 drivers/gpu/drm/nouveau/nv50_display.c             |   2 +-
 drivers/hv/hv.c                                    |   5 +-
 drivers/hv/hyperv_vmbus.h                          |   2 +-
 drivers/hv/vmbus_drv.c                             |   4 +-
 drivers/hwmon/ds620.c                              |   2 +-
 drivers/i2c/busses/i2c-at91.c                      |  36 +++--
 drivers/infiniband/core/mad.c                      |   2 +-
 drivers/infiniband/core/multicast.c                |   7 +-
 drivers/infiniband/hw/mlx4/ah.c                    |   6 +-
 drivers/infiniband/hw/mlx4/main.c                  |   8 +-
 drivers/infiniband/ulp/ipoib/ipoib_cm.c            |  12 +-
 drivers/infiniband/ulp/ipoib/ipoib_main.c          |   6 +-
 drivers/input/misc/cm109.c                         |   4 +
 drivers/input/misc/ims-pcu.c                       |   4 +
 drivers/input/misc/yealink.c                       |   4 +
 drivers/input/serio/i8042-x86ia64io.h              |   6 +
 drivers/input/tablet/hanwang.c                     |   3 +
 drivers/iommu/amd_iommu.c                          |   2 +-
 drivers/isdn/gigaset/bas-gigaset.c                 |   3 +
 drivers/isdn/gigaset/ser-gigaset.c                 |   4 +-
 drivers/md/dm.c                                    |  55 ++++++++
 drivers/media/i2c/Kconfig                          |   1 +
 drivers/media/rc/ite-cir.c                         |   2 +
 drivers/media/tuners/tuner-xc2028.c                |  34 ++---
 drivers/media/usb/uvc/uvc_queue.c                  |   2 +-
 drivers/mfd/pm8921-core.c                          |   9 +-
 drivers/mmc/card/mmc_test.c                        |   2 +-
 drivers/mmc/host/mxs-mmc.c                         |   6 +-
 drivers/mmc/host/ushc.c                            |   3 +
 drivers/mtd/nand/Kconfig                           |   2 +-
 drivers/net/ethernet/mellanox/mlx4/cq.c            |  38 ++---
 drivers/net/ethernet/mellanox/mlx4/en_rx.c         |   8 +-
 drivers/net/ethernet/stmicro/stmmac/stmmac_main.c  |  20 +--
 drivers/net/phy/phy.c                              |   2 +-
 drivers/net/tun.c                                  |  12 +-
 drivers/net/usb/pegasus.c                          |  29 +++-
 drivers/net/usb/rtl8150.c                          |  34 ++++-
 drivers/net/vxlan.c                                |   2 +-
 drivers/net/wireless/ath/ath9k/ar9003_eeprom.h     |   4 +-
 drivers/pci/hotplug/rpadlpar_core.c                |  10 +-
 drivers/platform/goldfish/pdev_bus.c               |  13 +-
 drivers/platform/x86/intel_mid_powerbtn.c          |   4 +-
 drivers/s390/cio/qdio_thinint.c                    |   8 +-
 drivers/s390/scsi/zfcp_dbf.c                       |  17 ++-
 drivers/s390/scsi/zfcp_dbf.h                       |  41 +++++-
 drivers/s390/scsi/zfcp_erp.c                       |  61 +++++++-
 drivers/s390/scsi/zfcp_ext.h                       |   4 +-
 drivers/s390/scsi/zfcp_fsf.c                       |   8 +-
 drivers/s390/scsi/zfcp_fsf.h                       |   3 +-
 drivers/s390/scsi/zfcp_reqlist.h                   |  30 +++-
 drivers/s390/scsi/zfcp_scsi.c                      |  61 +++++++-
 drivers/scsi/aacraid/src.c                         |  21 ++-
 drivers/scsi/libsas/sas_ata.c                      |   2 +-
 drivers/scsi/mvsas/mv_94xx.c                       |   2 +-
 drivers/staging/iio/adc/ad7606_core.c              |   2 +-
 drivers/staging/vt6656/hostap.c                    |   3 +-
 drivers/target/iscsi/iscsi_target_tpg.c            |   1 -
 drivers/tty/n_hdlc.c                               | 143 ++++++++++---------
 drivers/usb/class/usbtmc.c                         |   9 +-
 drivers/usb/core/config.c                          |  10 ++
 drivers/usb/dwc3/gadget.c                          |   8 +-
 drivers/usb/gadget/composite.c                     |  12 +-
 drivers/usb/gadget/dummy_hcd.c                     |   6 +-
 drivers/usb/host/ohci-q.c                          |   7 +-
 drivers/usb/host/xhci-mem.c                        |   4 +-
 drivers/usb/misc/idmouse.c                         |   3 +
 drivers/usb/misc/iowarrior.c                       |  21 ++-
 drivers/usb/misc/uss720.c                          |   5 +
 drivers/usb/musb/musbhsdma.h                       |   2 +-
 drivers/usb/serial/ark3116.c                       |  13 +-
 drivers/usb/serial/ch341.c                         |  90 +++++++-----
 drivers/usb/serial/cyberjack.c                     |  10 ++
 drivers/usb/serial/digi_acceleport.c               |  14 +-
 drivers/usb/serial/ftdi_sio.c                      |  31 +++--
 drivers/usb/serial/garmin_gps.c                    |   1 +
 drivers/usb/serial/io_edgeport.c                   |   5 +
 drivers/usb/serial/io_ti.c                         |  22 ++-
 drivers/usb/serial/iuu_phoenix.c                   |  11 ++
 drivers/usb/serial/keyspan_pda.c                   |  14 ++
 drivers/usb/serial/kl5kusb105.c                    |  44 ++++--
 drivers/usb/serial/kobil_sct.c                     |  12 ++
 drivers/usb/serial/mos7720.c                       |  51 +++----
 drivers/usb/serial/mos7840.c                       |  14 ++
 drivers/usb/serial/omninet.c                       |  19 ++-
 drivers/usb/serial/opticon.c                       |   2 +-
 drivers/usb/serial/oti6858.c                       |  16 +++
 drivers/usb/serial/pl2303.c                        |   8 ++
 drivers/usb/serial/quatech2.c                      |   4 -
 drivers/usb/serial/safe_serial.c                   |   5 +
 drivers/usb/serial/spcp8x5.c                       |  22 ++-
 drivers/usb/serial/ti_usb_3410_5052.c              |   7 +
 drivers/usb/wusbcore/wa-hc.c                       |   3 +
 drivers/uwb/hwa-rc.c                               |   3 +
 drivers/uwb/i1480/dfu/usb.c                        |   3 +
 drivers/video/fbcmap.c                             |  26 ++--
 fs/9p/acl.c                                        |  40 +++---
 fs/block_dev.c                                     |   9 +-
 fs/btrfs/acl.c                                     |   6 +-
 fs/btrfs/tree-log.c                                |   3 +-
 fs/exec.c                                          |  10 +-
 fs/ext2/acl.c                                      |  12 +-
 fs/ext3/acl.c                                      |  10 +-
 fs/ext4/acl.c                                      |  12 +-
 fs/ext4/inline.c                                   |   9 +-
 fs/ext4/inode.c                                    |  29 ++--
 fs/ext4/mballoc.c                                  |   4 +-
 fs/f2fs/acl.c                                      |   6 +-
 fs/f2fs/debug.c                                    |   1 +
 fs/fuse/file.c                                     |   6 +-
 fs/generic_acl.c                                   |  12 +-
 fs/gfs2/acl.c                                      |  14 +-
 fs/jffs2/acl.c                                     |   9 +-
 fs/jfs/xattr.c                                     |   5 +-
 fs/nfs/nfs4filelayoutdev.c                         |   3 +-
 fs/nfs/nfs4xdr.c                                   |   2 +-
 fs/ocfs2/acl.c                                     |  20 +--
 fs/ocfs2/ioctl.c                                   | 129 ++++++-----------
 fs/posix_acl.c                                     |  31 +++++
 fs/reiserfs/xattr_acl.c                            |   8 +-
 fs/ubifs/tnc.c                                     |  25 +++-
 fs/xfs/xfs_acl.c                                   |  15 +-
 include/crypto/algapi.h                            |  18 ++-
 include/linux/can/core.h                           |   7 +-
 include/linux/cpu.h                                |  12 +-
 include/linux/jump_label.h                         |  16 +++
 include/linux/kvm_host.h                           |   7 +-
 include/linux/lockd/lockd.h                        |   3 +-
 include/linux/netdevice.h                          |   9 +-
 include/linux/posix_acl.h                          |   1 +
 include/net/cipso_ipv4.h                           |   4 +
 include/rdma/ib_sa.h                               |   6 +-
 include/trace/events/syscalls.h                    |   1 +
 kernel/cpu.c                                       |   3 +-
 kernel/events/core.c                               |   5 +-
 kernel/ptrace.c                                    |  14 +-
 kernel/rtmutex.c                                   |  68 ++++++++-
 kernel/sched/core.c                                |   6 +-
 kernel/trace/ring_buffer.c                         |  24 +++-
 kernel/trace/trace.c                               |   8 +-
 mm/huge_memory.c                                   |  19 ++-
 mm/hugetlb.c                                       |  37 +++--
 mm/page_alloc.c                                    |  17 ++-
 net/can/af_can.c                                   |  12 +-
 net/can/af_can.h                                   |   3 +-
 net/can/bcm.c                                      |   4 +-
 net/can/gw.c                                       |   2 +-
 net/can/raw.c                                      |   4 +-
 net/ceph/osdmap.c                                  |   1 -
 net/core/dev.c                                     |  58 +++++---
 net/core/sock.c                                    |  10 +-
 net/dccp/ipv4.c                                    |   3 +-
 net/dccp/ipv6.c                                    |   8 +-
 net/ieee802154/6lowpan.c                           |   2 +-
 net/ipv4/cipso_ipv4.c                              |   4 +
 net/ipv4/igmp.c                                    |   6 +-
 net/ipv4/inet_connection_sock.c                    |   2 +
 net/ipv4/ip_sockglue.c                             |   9 +-
 net/ipv4/ip_vti.c                                  |   1 -
 net/ipv4/netfilter/arp_tables.c                    |   4 +-
 net/ipv4/ping.c                                    |   7 +-
 net/ipv4/route.c                                   |   1 +
 net/ipv4/tcp.c                                     |   6 +
 net/ipv4/tcp_ipv4.c                                |   4 +-
 net/ipv6/ip6_gre.c                                 |  41 +++---
 net/ipv6/ip6_offload.c                             |   1 +
 net/ipv6/ip6_tunnel.c                              |  55 +++++---
 net/ipv6/raw.c                                     |   7 +-
 net/ipv6/tcp_ipv6.c                                |   8 +-
 net/l2tp/l2tp_core.c                               |   8 +-
 net/l2tp/l2tp_core.h                               |   4 +-
 net/l2tp/l2tp_debugfs.c                            |  10 +-
 net/l2tp/l2tp_ip.c                                 |  27 +++-
 net/l2tp/l2tp_ip6.c                                |   2 +-
 net/l2tp/l2tp_netlink.c                            |   7 +-
 net/l2tp/l2tp_ppp.c                                |  10 +-
 net/mac80211/mesh.c                                |   2 +-
 net/packet/af_packet.c                             |  65 ++++++---
 net/sched/act_api.c                                |   5 +-
 net/sched/cls_api.c                                |   4 +-
 net/sched/em_meta.c                                |   9 +-
 net/sctp/associola.c                               | 131 +++++++++++-------
 net/sctp/socket.c                                  |   7 +-
 net/socket.c                                       |   4 +-
 net/sunrpc/auth_gss/gss_rpc_xdr.c                  |   2 +-
 net/sunrpc/auth_gss/svcauth_gss.c                  |   2 +-
 net/unix/garbage.c                                 |  18 +--
 net/xfrm/xfrm_user.c                               |   9 +-
 security/integrity/evm/evm_main.c                  |   3 +-
 security/keys/gc.c                                 |   2 +-
 security/keys/keyctl.c                             |  20 +--
 security/keys/process_keys.c                       |  44 +++---
 security/selinux/hooks.c                           |   2 +-
 sound/pci/ctxfi/cthw20k1.c                         |  19 +--
 sound/pci/ctxfi/cthw20k2.c                         |  18 +--
 sound/usb/card.c                                   |   1 -
 tools/perf/builtin-trace.c                         |   4 +-
 tools/perf/util/trace-event-scripting.c            |   6 +-
 tools/testing/ktest/ktest.pl                       |   2 +-
 virt/kvm/eventfd.c                                 |   3 +
 virt/kvm/kvm_main.c                                |  41 ++++--
 239 files changed, 2487 insertions(+), 1136 deletions(-)
 create mode 100644 crypto/memneq.c

-- 
2.8.0.rc2.1.gbe9624a

[toc] | [next] | [standalone]


#1660350 — [PATCH 3.10 188/250] uwb: hwa-rc: fix NULL-deref at probe

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 188/250] uwb: hwa-rc: fix NULL-deref at probe
Message-ID<tPSfr-4Fa-95@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit daf229b15907fbfdb6ee183aac8ca428cb57e361 upstream.

Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer should a malicious device lack endpoints.

Note that the dereference happens in the start callback which is called
during probe.

Fixes: de520b8bd552 ("uwb: add HWA radio controller driver")
Cc: Inaky Perez-Gonzalez <inaky.perez-gonzalez@intel.com>
Cc: David Vrabel <david.vrabel@csr.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/uwb/hwa-rc.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/uwb/hwa-rc.c b/drivers/uwb/hwa-rc.c
index 810c90a..cd8bf69 100644
--- a/drivers/uwb/hwa-rc.c
+++ b/drivers/uwb/hwa-rc.c
@@ -811,6 +811,9 @@ static int hwarc_probe(struct usb_interface *iface,
 	struct hwarc *hwarc;
 	struct device *dev = &iface->dev;
 
+	if (iface->cur_altsetting->desc.bNumEndpoints < 1)
+		return -ENODEV;
+
 	result = -ENOMEM;
 	uwb_rc = uwb_rc_alloc();
 	if (uwb_rc == NULL) {
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660351 — [PATCH 3.10 167/250] USB: serial: io_ti: fix NULL-deref in interrupt callback

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 167/250] USB: serial: io_ti: fix NULL-deref in interrupt callback
Message-ID<tPSfr-4Fa-99@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit 0b1d250afb8eb9d65afb568bac9b9f9253a82b49 upstream.

Fix a NULL-pointer dereference in the interrupt callback should a
malicious device send data containing a bad port number by adding the
missing sanity check.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/serial/io_ti.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/usb/serial/io_ti.c b/drivers/usb/serial/io_ti.c
index e1b3e79..e2dc182 100644
--- a/drivers/usb/serial/io_ti.c
+++ b/drivers/usb/serial/io_ti.c
@@ -1575,6 +1575,12 @@ static void edge_interrupt_callback(struct urb *urb)
 	function    = TIUMP_GET_FUNC_FROM_CODE(data[0]);
 	dev_dbg(dev, "%s - port_number %d, function %d, info 0x%x\n", __func__,
 		port_number, function, data[1]);
+
+	if (port_number >= edge_serial->serial->num_ports) {
+		dev_err(dev, "bad port number %d\n", port_number);
+		goto exit;
+	}
+
 	port = edge_serial->serial->port[port_number];
 	edge_port = usb_get_serial_port_data(port);
 	if (!edge_port) {
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660352 — [PATCH 3.10 136/250] mfd: pm8921: Potential NULL dereference in pm8921_remove()

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 136/250] mfd: pm8921: Potential NULL dereference in pm8921_remove()
Message-ID<tPSfr-4Fa-91@gated-at.bofh.it>
In reply to#1660349
From: Dan Carpenter <dan.carpenter@oracle.com>

commit d6daef95127e41233ac8e2d8472d8c0cd8687d38 upstream.

We assume that "pmic" could be NULL and then dereference it two lines
later.  I fix this by moving the dereference inside the NULL check.

Fixes: c013f0a56c56 ('mfd: Add pm8xxx irq support')

Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/mfd/pm8921-core.c | 9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

diff --git a/drivers/mfd/pm8921-core.c b/drivers/mfd/pm8921-core.c
index ecc137f..a28f434 100644
--- a/drivers/mfd/pm8921-core.c
+++ b/drivers/mfd/pm8921-core.c
@@ -173,11 +173,12 @@ static int pm8921_remove(struct platform_device *pdev)
 	drvdata = platform_get_drvdata(pdev);
 	if (drvdata)
 		pmic = drvdata->pm_chip_data;
-	if (pmic)
+	if (pmic) {
 		mfd_remove_devices(pmic->dev);
-	if (pmic->irq_chip) {
-		pm8xxx_irq_exit(pmic->irq_chip);
-		pmic->irq_chip = NULL;
+		if (pmic->irq_chip) {
+			pm8xxx_irq_exit(pmic->irq_chip);
+			pmic->irq_chip = NULL;
+		}
 	}
 	platform_set_drvdata(pdev, NULL);
 	kfree(pmic);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660353 — [PATCH 3.10 099/250] ubifs: Fix journal replay wrt. xattr nodes

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 099/250] ubifs: Fix journal replay wrt. xattr nodes
Message-ID<tPSfr-4Fa-97@gated-at.bofh.it>
In reply to#1660349
From: Richard Weinberger <richard@nod.at>

commit 1cb51a15b576ee325d527726afff40947218fd5e upstream.

When replaying the journal it can happen that a journal entry points to
a garbage collected node.
This is the case when a power-cut occurred between a garbage collect run
and a commit. In such a case nodes have to be read using the failable
read functions to detect whether the found node matches what we expect.

One corner case was forgotten, when the journal contains an entry to
remove an inode all xattrs have to be removed too. UBIFS models xattr
like directory entries, so the TNC code iterates over
all xattrs of the inode and removes them too. This code re-uses the
functions for walking directories and calls ubifs_tnc_next_ent().
ubifs_tnc_next_ent() expects to be used only after the journal and
aborts when a node does not match the expected result. This behavior can
render an UBIFS volume unmountable after a power-cut when xattrs are
used.

Fix this issue by using failable read functions in ubifs_tnc_next_ent()
too when replaying the journal.
Fixes: 1e51764a3c2ac05a ("UBIFS: add new flash file system")
Reported-by: Rock Lee <rockdotlee@gmail.com>
Reviewed-by: David Gstir <david@sigma-star.at>
Signed-off-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/ubifs/tnc.c | 25 +++++++++++++++++++++++--
 1 file changed, 23 insertions(+), 2 deletions(-)

diff --git a/fs/ubifs/tnc.c b/fs/ubifs/tnc.c
index 349f31a..fdf2ca1 100644
--- a/fs/ubifs/tnc.c
+++ b/fs/ubifs/tnc.c
@@ -34,6 +34,11 @@
 #include <linux/slab.h>
 #include "ubifs.h"
 
+static int try_read_node(const struct ubifs_info *c, void *buf, int type,
+			 int len, int lnum, int offs);
+static int fallible_read_node(struct ubifs_info *c, const union ubifs_key *key,
+			      struct ubifs_zbranch *zbr, void *node);
+
 /*
  * Returned codes of 'matches_name()' and 'fallible_matches_name()' functions.
  * @NAME_LESS: name corresponding to the first argument is less than second
@@ -419,7 +424,19 @@ static int tnc_read_node_nm(struct ubifs_info *c, struct ubifs_zbranch *zbr,
 		return 0;
 	}
 
-	err = ubifs_tnc_read_node(c, zbr, node);
+	if (c->replaying) {
+		err = fallible_read_node(c, &zbr->key, zbr, node);
+		/*
+		 * When the node was not found, return -ENOENT, 0 otherwise.
+		 * Negative return codes stay as-is.
+		 */
+		if (err == 0)
+			err = -ENOENT;
+		else if (err == 1)
+			err = 0;
+	} else {
+		err = ubifs_tnc_read_node(c, zbr, node);
+	}
 	if (err)
 		return err;
 
@@ -2783,7 +2800,11 @@ struct ubifs_dent_node *ubifs_tnc_next_ent(struct ubifs_info *c,
 	if (nm->name) {
 		if (err) {
 			/* Handle collisions */
-			err = resolve_collision(c, key, &znode, &n, nm);
+			if (c->replaying)
+				err = fallible_resolve_collision(c, key, &znode, &n,
+							 nm, 0);
+			else
+				err = resolve_collision(c, key, &znode, &n, nm);
 			dbg_tnc("rc returned %d, znode %p, n %d",
 				err, znode, n);
 			if (unlikely(err < 0))
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660354 — [PATCH 3.10 102/250] arm64/ptrace: Reject attempts to set incomplete hardware breakpoint fields

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 102/250] arm64/ptrace: Reject attempts to set incomplete hardware breakpoint fields
Message-ID<tPSfr-4Fa-103@gated-at.bofh.it>
In reply to#1660349
From: Dave Martin <Dave.Martin@arm.com>

commit ad9e202aa1ce571b1d7fed969d06f66067f8a086 upstream.

We cannot preserve partial fields for hardware breakpoints, because
the values written by userspace to the hardware breakpoint
registers can't subsequently be recovered intact from the hardware.

So, just reject attempts to write incomplete fields with -EINVAL.

Fixes: 478fcb2cdb23 ("arm64: Debugging support")
Signed-off-by: Dave Martin <Dave.Martin@arm.com>
Acked-by: Will Deacon <Will.Deacon@arm.com>
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 arch/arm64/kernel/ptrace.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/arch/arm64/kernel/ptrace.c b/arch/arm64/kernel/ptrace.c
index 777763d..015775a 100644
--- a/arch/arm64/kernel/ptrace.c
+++ b/arch/arm64/kernel/ptrace.c
@@ -464,6 +464,8 @@ static int hw_break_set(struct task_struct *target,
 	/* (address, ctrl) registers */
 	limit = regset->n * regset->size;
 	while (count && offset < limit) {
+		if (count < PTRACE_HBP_ADDR_SZ)
+			return -EINVAL;
 		ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &addr,
 					 offset, offset + PTRACE_HBP_ADDR_SZ);
 		if (ret)
@@ -473,6 +475,8 @@ static int hw_break_set(struct task_struct *target,
 			return ret;
 		offset += PTRACE_HBP_ADDR_SZ;
 
+		if (!count)
+			break;
 		ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &ctrl,
 					 offset, offset + PTRACE_HBP_CTRL_SZ);
 		if (ret)
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660355 — [PATCH 3.10 223/250] Staging: vt6655-6: potential NULL dereference in hostap_disable_hostapd()

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 223/250] Staging: vt6655-6: potential NULL dereference in hostap_disable_hostapd()
Message-ID<tPSfr-4Fa-107@gated-at.bofh.it>
In reply to#1660349
From: Dan Carpenter <dan.carpenter@oracle.com>

commit cb4855b49deb1acce27706ad9509d63c4fe8e988 upstream.

We fixed this to use free_netdev() instead of kfree() but unfortunately
free_netdev() doesn't accept NULL pointers.  Smatch complains about
this, it's not something I discovered through testing.

Fixes: 3030d40b5036 ('staging: vt6655: use free_netdev instead of kfree')
Fixes: 0a438d5b381e ('staging: vt6656: use free_netdev instead of kfree')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[wt: only vt6656 was converted to free_netdev in 3.10]
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/staging/vt6656/hostap.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/staging/vt6656/hostap.c b/drivers/staging/vt6656/hostap.c
index c699a30..cfffdd2 100644
--- a/drivers/staging/vt6656/hostap.c
+++ b/drivers/staging/vt6656/hostap.c
@@ -133,7 +133,8 @@ static int hostap_disable_hostapd(struct vnt_private *pDevice, int rtnl_locked)
             DBG_PRT(MSG_LEVEL_DEBUG, KERN_INFO "%s: Netdevice %s unregistered\n",
 		       pDevice->dev->name, pDevice->apdev->name);
 	}
-	free_netdev(pDevice->apdev);
+	if (pDevice->apdev)
+		free_netdev(pDevice->apdev);
 	pDevice->apdev = NULL;
     pDevice->bEnable8021x = false;
     pDevice->bEnableHostWEP = false;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660356 — [PATCH 3.10 006/250] KVM: x86: Introduce segmented_write_std

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 006/250] KVM: x86: Introduce segmented_write_std
Message-ID<tPSfr-4Fa-109@gated-at.bofh.it>
In reply to#1660349
From: Steve Rutherford <srutherford@google.com>

commit 129a72a0d3c8e139a04512325384fe5ac119e74d upstream.

Introduces segemented_write_std.

Switches from emulated reads/writes to standard read/writes in fxsave,
fxrstor, sgdt, and sidt.  This fixes CVE-2017-2584, a longstanding
kernel memory leak.

Since commit 283c95d0e389 ("KVM: x86: emulate FXSAVE and FXRSTOR",
2016-11-09), which is luckily not yet in any final release, this would
also be an exploitable kernel memory *write*!

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Fixes: 96051572c819194c37a8367624b285be10297eca
Fixes: 283c95d0e3891b64087706b344a4b545d04a6e62
Suggested-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Steve Rutherford <srutherford@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 arch/x86/kvm/emulate.c | 18 ++++++++++++++++--
 1 file changed, 16 insertions(+), 2 deletions(-)

diff --git a/arch/x86/kvm/emulate.c b/arch/x86/kvm/emulate.c
index 364f020..c964850 100644
--- a/arch/x86/kvm/emulate.c
+++ b/arch/x86/kvm/emulate.c
@@ -906,6 +906,20 @@ static int segmented_read_std(struct x86_emulate_ctxt *ctxt,
 	return ctxt->ops->read_std(ctxt, linear, data, size, &ctxt->exception);
 }
 
+static int segmented_write_std(struct x86_emulate_ctxt *ctxt,
+			       struct segmented_address addr,
+			       void *data,
+			       unsigned int size)
+{
+	int rc;
+	ulong linear;
+
+	rc = linearize(ctxt, addr, size, true, &linear);
+	if (rc != X86EMUL_CONTINUE)
+		return rc;
+	return ctxt->ops->write_std(ctxt, linear, data, size, &ctxt->exception);
+}
+
 /*
  * Fetch the next byte of the instruction being emulated which is pointed to
  * by ctxt->_eip, then increment ctxt->_eip.
@@ -3361,8 +3375,8 @@ static int emulate_store_desc_ptr(struct x86_emulate_ctxt *ctxt,
 	}
 	/* Disable writeback. */
 	ctxt->dst.type = OP_NONE;
-	return segmented_write(ctxt, ctxt->dst.addr.mem,
-			       &desc_ptr, 2 + ctxt->op_bytes);
+	return segmented_write_std(ctxt, ctxt->dst.addr.mem,
+				   &desc_ptr, 2 + ctxt->op_bytes);
 }
 
 static int em_sgdt(struct x86_emulate_ctxt *ctxt)
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660357 — [PATCH 3.10 181/250] Input: hanwang - validate number of endpoints before using them

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 181/250] Input: hanwang - validate number of endpoints before using them
Message-ID<tPSfs-4Fa-113@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit ba340d7b83703768ce566f53f857543359aa1b98 upstream.

Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer should a malicious device lack endpoints.

Fixes: bba5394ad3bd ("Input: add support for Hanwang tablets")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/input/tablet/hanwang.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/input/tablet/hanwang.c b/drivers/input/tablet/hanwang.c
index 5cc0412..263c85e 100644
--- a/drivers/input/tablet/hanwang.c
+++ b/drivers/input/tablet/hanwang.c
@@ -341,6 +341,9 @@ static int hanwang_probe(struct usb_interface *intf, const struct usb_device_id
 	int error;
 	int i;
 
+	if (intf->cur_altsetting->desc.bNumEndpoints < 1)
+		return -ENODEV;
+
 	hanwang = kzalloc(sizeof(struct hanwang), GFP_KERNEL);
 	input_dev = input_allocate_device();
 	if (!hanwang || !input_dev) {
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660358 — [PATCH 3.10 049/250] USB: serial: io_edgeport: fix NULL-deref at open

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 049/250] USB: serial: io_edgeport: fix NULL-deref at open
Message-ID<tPSfr-4Fa-111@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit 0dd408425eb21ddf26a692b3c8044c9e7d1a7948 upstream.

Fix NULL-pointer dereference when initialising URBs at open should a
non-EPIC device lack a bulk-in or interrupt-in endpoint.

Unable to handle kernel NULL pointer dereference at virtual address 00000028
...
PC is at edge_open+0x24c/0x3e8 [io_edgeport]

Note that the EPIC-device probe path has the required sanity checks so
this makes those checks partially redundant.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/serial/io_edgeport.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/usb/serial/io_edgeport.c b/drivers/usb/serial/io_edgeport.c
index c574d312..9f24fd7 100644
--- a/drivers/usb/serial/io_edgeport.c
+++ b/drivers/usb/serial/io_edgeport.c
@@ -2795,6 +2795,11 @@ static int edge_startup(struct usb_serial *serial)
 					EDGE_COMPATIBILITY_MASK1,
 					EDGE_COMPATIBILITY_MASK2 };
 
+	if (serial->num_bulk_in < 1 || serial->num_interrupt_in < 1) {
+		dev_err(&serial->interface->dev, "missing endpoints\n");
+		return -ENODEV;
+	}
+
 	dev = serial->dev;
 
 	/* create our private serial structure */
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660359 — [PATCH 3.10 090/250] powerpc/ibmebus: Fix further device reference leaks

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 090/250] powerpc/ibmebus: Fix further device reference leaks
Message-ID<tPSfs-4Fa-115@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit 815a7141c4d1b11610dccb7fcbb38633759824f2 upstream.

Make sure to drop any reference taken by bus_find_device() when creating
devices during init and driver registration.

Fixes: 55347cc9962f ("[POWERPC] ibmebus: Add device creation and bus probing based on of_device")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 arch/powerpc/kernel/ibmebus.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/arch/powerpc/kernel/ibmebus.c b/arch/powerpc/kernel/ibmebus.c
index 8220baa..cce1a44 100644
--- a/arch/powerpc/kernel/ibmebus.c
+++ b/arch/powerpc/kernel/ibmebus.c
@@ -180,6 +180,7 @@ static int ibmebus_create_device(struct device_node *dn)
 static int ibmebus_create_devices(const struct of_device_id *matches)
 {
 	struct device_node *root, *child;
+	struct device *dev;
 	int ret = 0;
 
 	root = of_find_node_by_path("/");
@@ -188,9 +189,12 @@ static int ibmebus_create_devices(const struct of_device_id *matches)
 		if (!of_match_node(matches, child))
 			continue;
 
-		if (bus_find_device(&ibmebus_bus_type, NULL, child,
-				    ibmebus_match_node))
+		dev = bus_find_device(&ibmebus_bus_type, NULL, child,
+				      ibmebus_match_node);
+		if (dev) {
+			put_device(dev);
 			continue;
+		}
 
 		ret = ibmebus_create_device(child);
 		if (ret) {
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660360 — [PATCH 3.10 172/250] net: net_enable_timestamp() can be called from irq contexts

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 172/250] net: net_enable_timestamp() can be called from irq contexts
Message-ID<tPSfs-4Fa-117@gated-at.bofh.it>
In reply to#1660349
From: Eric Dumazet <edumazet@google.com>

commit 13baa00ad01bb3a9f893e3a08cbc2d072fc0c15d upstream.

It is now very clear that silly TCP listeners might play with
enabling/disabling timestamping while new children are added
to their accept queue.

Meaning net_enable_timestamp() can be called from BH context
while current state of the static key is not enabled.

Lets play safe and allow all contexts.

The work queue is scheduled only under the problematic cases,
which are the static key enable/disable transition, to not slow down
critical paths.

This extends and improves what we did in commit 5fa8bbda38c6 ("net: use
a work queue to defer net_disable_timestamp() work")

Fixes: b90e5794c5bd ("net: dont call jump_label_dec from irq context")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/core/dev.c | 35 +++++++++++++++++++++++++++++++----
 1 file changed, 31 insertions(+), 4 deletions(-)

diff --git a/net/core/dev.c b/net/core/dev.c
index 11535a9..682bf5a 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -1560,27 +1560,54 @@ EXPORT_SYMBOL(call_netdevice_notifiers);
 static struct static_key netstamp_needed __read_mostly;
 #ifdef HAVE_JUMP_LABEL
 static atomic_t netstamp_needed_deferred;
+static atomic_t netstamp_wanted;
 static void netstamp_clear(struct work_struct *work)
 {
 	int deferred = atomic_xchg(&netstamp_needed_deferred, 0);
+	int wanted;
 
-	while (deferred--)
-		static_key_slow_dec(&netstamp_needed);
+	wanted = atomic_add_return(deferred, &netstamp_wanted);
+	if (wanted > 0)
+		static_key_enable(&netstamp_needed);
+	else
+		static_key_disable(&netstamp_needed);
 }
 static DECLARE_WORK(netstamp_work, netstamp_clear);
 #endif
 
 void net_enable_timestamp(void)
 {
+#ifdef HAVE_JUMP_LABEL
+	int wanted;
+
+	while (1) {
+		wanted = atomic_read(&netstamp_wanted);
+		if (wanted <= 0)
+			break;
+		if (atomic_cmpxchg(&netstamp_wanted, wanted, wanted + 1) == wanted)
+			return;
+	}
+	atomic_inc(&netstamp_needed_deferred);
+	schedule_work(&netstamp_work);
+#else
 	static_key_slow_inc(&netstamp_needed);
+#endif
 }
 EXPORT_SYMBOL(net_enable_timestamp);
 
 void net_disable_timestamp(void)
 {
 #ifdef HAVE_JUMP_LABEL
-	/* net_disable_timestamp() can be called from non process context */
-	atomic_inc(&netstamp_needed_deferred);
+	int wanted;
+
+	while (1) {
+		wanted = atomic_read(&netstamp_wanted);
+		if (wanted <= 1)
+			break;
+		if (atomic_cmpxchg(&netstamp_wanted, wanted, wanted - 1) == wanted)
+			return;
+	}
+	atomic_dec(&netstamp_needed_deferred);
 	schedule_work(&netstamp_work);
 #else
 	static_key_slow_dec(&netstamp_needed);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660362 — [PATCH 3.10 159/250] USB: serial: digi_acceleport: fix OOB data sanity check

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 159/250] USB: serial: digi_acceleport: fix OOB data sanity check
Message-ID<tPSfs-4Fa-123@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit 2d380889215fe20b8523345649dee0579821800c upstream.

Make sure to check for short transfers to avoid underflow in a loop
condition when parsing the receive buffer.

Also fix an off-by-one error in the incomplete sanity check which could
lead to invalid data being parsed.

Fixes: 8c209e6782ca ("USB: make actual_length in struct urb field u32")
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/serial/digi_acceleport.c | 14 +++++++++-----
 1 file changed, 9 insertions(+), 5 deletions(-)

diff --git a/drivers/usb/serial/digi_acceleport.c b/drivers/usb/serial/digi_acceleport.c
index 8c34d9c..15b9cb3 100644
--- a/drivers/usb/serial/digi_acceleport.c
+++ b/drivers/usb/serial/digi_acceleport.c
@@ -1489,16 +1489,20 @@ static int digi_read_oob_callback(struct urb *urb)
 	struct usb_serial *serial = port->serial;
 	struct tty_struct *tty;
 	struct digi_port *priv = usb_get_serial_port_data(port);
+	unsigned char *buf = urb->transfer_buffer;
 	int opcode, line, status, val;
 	int i;
 	unsigned int rts;
 
+	if (urb->actual_length < 4)
+		return -1;
+
 	/* handle each oob command */
-	for (i = 0; i < urb->actual_length - 3;) {
-		opcode = ((unsigned char *)urb->transfer_buffer)[i++];
-		line = ((unsigned char *)urb->transfer_buffer)[i++];
-		status = ((unsigned char *)urb->transfer_buffer)[i++];
-		val = ((unsigned char *)urb->transfer_buffer)[i++];
+	for (i = 0; i < urb->actual_length - 4; i += 4) {
+		opcode = buf[i];
+		line = buf[i + 1];
+		status = buf[i + 2];
+		val = buf[i + 3];
 
 		dev_dbg(&port->dev, "digi_read_oob_callback: opcode=%d, line=%d, status=%d, val=%d\n",
 			opcode, line, status, val);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660363 — [PATCH 3.10 139/250] vti4: Don't count header length twice.

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 139/250] vti4: Don't count header length twice.
Message-ID<tPSfs-4Fa-125@gated-at.bofh.it>
In reply to#1660349
From: Steffen Klassert <steffen.klassert@secunet.com>

commit a32452366b7250c42e96a18ffc3ad8db9e0ca3c2 upstream.

We currently count the size of LL_MAX_HEADER and struct iphdr
twice for vti4 devices, this leads to a wrong device mtu.
The size of LL_MAX_HEADER and struct iphdr is already counted in
ip_tunnel_bind_dev(), so don't do it again in vti_tunnel_init().

Fixes: b9959fd3 ("vti: switch to new ip tunnel code")
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/ipv4/ip_vti.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/net/ipv4/ip_vti.c b/net/ipv4/ip_vti.c
index 4ec3427..eadafac 100644
--- a/net/ipv4/ip_vti.c
+++ b/net/ipv4/ip_vti.c
@@ -582,7 +582,6 @@ static void vti_tunnel_setup(struct net_device *dev)
 	dev->type		= ARPHRD_TUNNEL;
 	dev->destructor		= vti_dev_free;
 
-	dev->hard_header_len	= LL_MAX_HEADER + sizeof(struct iphdr);
 	dev->mtu		= ETH_DATA_LEN;
 	dev->flags		= IFF_NOARP;
 	dev->iflink		= 0;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660364 — [PATCH 3.10 178/250] net: properly release sk_frag.page

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:10 +0200
Subject[PATCH 3.10 178/250] net: properly release sk_frag.page
Message-ID<tPSfs-4Fa-119@gated-at.bofh.it>
In reply to#1660349
From: Eric Dumazet <edumazet@google.com>

commit 22a0e18eac7a9e986fec76c60fa4a2926d1291e2 upstream.

I mistakenly added the code to release sk->sk_frag in
sk_common_release() instead of sk_destruct()

TCP sockets using sk->sk_allocation == GFP_ATOMIC do no call
sk_common_release() at close time, thus leaking one (order-3) page.

iSCSI is using such sockets.

Fixes: 5640f7685831 ("net: use a per task frag allocator")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/core/sock.c | 10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

diff --git a/net/core/sock.c b/net/core/sock.c
index e3cb454..96e1259 100644
--- a/net/core/sock.c
+++ b/net/core/sock.c
@@ -1403,6 +1403,11 @@ static void __sk_free(struct sock *sk)
 		pr_debug("%s: optmem leakage (%d bytes) detected\n",
 			 __func__, atomic_read(&sk->sk_omem_alloc));
 
+	if (sk->sk_frag.page) {
+		put_page(sk->sk_frag.page);
+		sk->sk_frag.page = NULL;
+	}
+
 	if (sk->sk_peer_cred)
 		put_cred(sk->sk_peer_cred);
 	put_pid(sk->sk_peer_pid);
@@ -2556,11 +2561,6 @@ void sk_common_release(struct sock *sk)
 
 	sk_refcnt_debug_release(sk);
 
-	if (sk->sk_frag.page) {
-		put_page(sk->sk_frag.page);
-		sk->sk_frag.page = NULL;
-	}
-
 	sock_put(sk);
 }
 EXPORT_SYMBOL(sk_common_release);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660365 — [PATCH 3.10 229/250] USB: dummy-hcd: fix bug in stop_activity (handle ep0)

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:20 +0200
Subject[PATCH 3.10 229/250] USB: dummy-hcd: fix bug in stop_activity (handle ep0)
Message-ID<tPSp3-4Iz-1@gated-at.bofh.it>
In reply to#1660349
From: Alan Stern <stern@rowland.harvard.edu>

commit bcdbeb844773333d2d1c08004f3b3e25921040e5 upstream.

The stop_activity() routine in dummy-hcd is supposed to unlink all
active requests for every endpoint, among other things.  But it
doesn't handle ep0.  As a result, fuzz testing can generate a WARNING
like the following:

WARNING: CPU: 0 PID: 4410 at drivers/usb/gadget/udc/dummy_hcd.c:672 dummy_free_request+0x153/0x170
Modules linked in:
CPU: 0 PID: 4410 Comm: syz-executor Not tainted 4.9.0-rc7+ #32
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011
 ffff88006a64ed10 ffffffff81f96b8a ffffffff41b58ab3 1ffff1000d4c9d35
 ffffed000d4c9d2d ffff880065f8ac00 0000000041b58ab3 ffffffff8598b510
 ffffffff81f968f8 0000000041b58ab3 ffffffff859410e0 ffffffff813f0590
Call Trace:
 [<     inline     >] __dump_stack lib/dump_stack.c:15
 [<ffffffff81f96b8a>] dump_stack+0x292/0x398 lib/dump_stack.c:51
 [<ffffffff812b808f>] __warn+0x19f/0x1e0 kernel/panic.c:550
 [<ffffffff812b831c>] warn_slowpath_null+0x2c/0x40 kernel/panic.c:585
 [<ffffffff830fcb13>] dummy_free_request+0x153/0x170 drivers/usb/gadget/udc/dummy_hcd.c:672
 [<ffffffff830ed1b0>] usb_ep_free_request+0xc0/0x420 drivers/usb/gadget/udc/core.c:195
 [<ffffffff83225031>] gadgetfs_unbind+0x131/0x190 drivers/usb/gadget/legacy/inode.c:1612
 [<ffffffff830ebd8f>] usb_gadget_remove_driver+0x10f/0x2b0 drivers/usb/gadget/udc/core.c:1228
 [<ffffffff830ec084>] usb_gadget_unregister_driver+0x154/0x240 drivers/usb/gadget/udc/core.c:1357

This patch fixes the problem by iterating over all the endpoints in
the driver's ep array instead of iterating over the gadget's ep_list,
which explicitly leaves out ep0.

Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/gadget/dummy_hcd.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/usb/gadget/dummy_hcd.c b/drivers/usb/gadget/dummy_hcd.c
index ac0e79e..644c105 100644
--- a/drivers/usb/gadget/dummy_hcd.c
+++ b/drivers/usb/gadget/dummy_hcd.c
@@ -266,7 +266,7 @@ static void nuke(struct dummy *dum, struct dummy_ep *ep)
 /* caller must hold lock */
 static void stop_activity(struct dummy *dum)
 {
-	struct dummy_ep	*ep;
+	int i;
 
 	/* prevent any more requests */
 	dum->address = 0;
@@ -274,8 +274,8 @@ static void stop_activity(struct dummy *dum)
 	/* The timer is left running so that outstanding URBs can fail */
 
 	/* nuke any pending requests first, so driver i/o is quiesced */
-	list_for_each_entry(ep, &dum->gadget.ep_list, ep.ep_list)
-		nuke(dum, ep);
+	for (i = 0; i < DUMMY_ENDPOINTS; ++i)
+		nuke(dum, &dum->ep[i]);
 
 	/* driver now does any non-usb quiescing necessary */
 }
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660366 — [PATCH 3.10 123/250] packet: fix races in fanout_add()

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:20 +0200
Subject[PATCH 3.10 123/250] packet: fix races in fanout_add()
Message-ID<tPSp3-4Iz-3@gated-at.bofh.it>
In reply to#1660349
From: Eric Dumazet <edumazet@google.com>

commit d199fab63c11998a602205f7ee7ff7c05c97164b upstream.

Multiple threads can call fanout_add() at the same time.

We need to grab fanout_mutex earlier to avoid races that could
lead to one thread freeing po->rollover that was set by another thread.

Do the same in fanout_release(), for peace of mind, and to help us
finding lockdep issues earlier.

[js] no rollover in 3.12

Fixes: dc99f600698d ("packet: Add fanout support.")
Fixes: 0648ab70afe6 ("packet: rollover prepare: per-socket state")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Willem de Bruijn <willemb@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/packet/af_packet.c | 26 ++++++++++++++------------
 1 file changed, 14 insertions(+), 12 deletions(-)

diff --git a/net/packet/af_packet.c b/net/packet/af_packet.c
index e38c699..25ef495 100644
--- a/net/packet/af_packet.c
+++ b/net/packet/af_packet.c
@@ -1304,13 +1304,16 @@ static int fanout_add(struct sock *sk, u16 id, u16 type_flags)
 		return -EINVAL;
 	}
 
+	mutex_lock(&fanout_mutex);
+
+	err = -EINVAL;
 	if (!po->running)
-		return -EINVAL;
+		goto out;
 
+	err = -EALREADY;
 	if (po->fanout)
-		return -EALREADY;
+		goto out;
 
-	mutex_lock(&fanout_mutex);
 	match = NULL;
 	list_for_each_entry(f, &fanout_list, list) {
 		if (f->id == id &&
@@ -1366,17 +1369,16 @@ static void fanout_release(struct sock *sk)
 	struct packet_sock *po = pkt_sk(sk);
 	struct packet_fanout *f;
 
-	f = po->fanout;
-	if (!f)
-		return;
-
 	mutex_lock(&fanout_mutex);
-	po->fanout = NULL;
+	f = po->fanout;
+	if (f) {
+		po->fanout = NULL;
 
-	if (atomic_dec_and_test(&f->sk_ref)) {
-		list_del(&f->list);
-		dev_remove_pack(&f->prot_hook);
-		kfree(f);
+		if (atomic_dec_and_test(&f->sk_ref)) {
+			list_del(&f->list);
+			dev_remove_pack(&f->prot_hook);
+			kfree(f);
+		}
 	}
 	mutex_unlock(&fanout_mutex);
 }
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660367 — [PATCH 3.10 135/250] ocfs2: do not write error flag to user structure we cannot copy from/to

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:20 +0200
Subject[PATCH 3.10 135/250] ocfs2: do not write error flag to user structure we cannot copy from/to
Message-ID<tPSp3-4Iz-5@gated-at.bofh.it>
In reply to#1660349
From: Ben Hutchings <ben@decadent.org.uk>

commit 2b462638e41ea62230297c21c4da9955937b7a3c upstream.

If we failed to copy from the structure, writing back the flags leaks 31
bits of kernel memory (the rest of the ir_flags field).

In any case, if we cannot copy from/to the structure, why should we
expect putting just the flags to work?

Also make sure ocfs2_info_handle_freeinode() returns the right error
code if the copy_to_user() fails.

Fixes: ddee5cdb70e6 ('Ocfs2: Add new OCFS2_IOC_INFO ioctl for ocfs2 v8.')
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Cc: Joel Becker <jlbec@evilplan.org>
Acked-by: Mark Fasheh <mfasheh@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/ocfs2/ioctl.c | 129 +++++++++++++++++++------------------------------------
 1 file changed, 43 insertions(+), 86 deletions(-)

diff --git a/fs/ocfs2/ioctl.c b/fs/ocfs2/ioctl.c
index 0c60ef2..b9d1609 100644
--- a/fs/ocfs2/ioctl.c
+++ b/fs/ocfs2/ioctl.c
@@ -34,9 +34,8 @@
 		copy_to_user((typeof(a) __user *)b, &(a), sizeof(a))
 
 /*
- * This call is void because we are already reporting an error that may
- * be -EFAULT.  The error will be returned from the ioctl(2) call.  It's
- * just a best-effort to tell userspace that this request caused the error.
+ * This is just a best-effort to tell userspace that this request
+ * caused the error.
  */
 static inline void o2info_set_request_error(struct ocfs2_info_request *kreq,
 					struct ocfs2_info_request __user *req)
@@ -145,136 +144,105 @@ bail:
 int ocfs2_info_handle_blocksize(struct inode *inode,
 				struct ocfs2_info_request __user *req)
 {
-	int status = -EFAULT;
 	struct ocfs2_info_blocksize oib;
 
 	if (o2info_from_user(oib, req))
-		goto bail;
+		return -EFAULT;
 
 	oib.ib_blocksize = inode->i_sb->s_blocksize;
 
 	o2info_set_request_filled(&oib.ib_req);
 
 	if (o2info_to_user(oib, req))
-		goto bail;
-
-	status = 0;
-bail:
-	if (status)
-		o2info_set_request_error(&oib.ib_req, req);
+		return -EFAULT;
 
-	return status;
+	return 0;
 }
 
 int ocfs2_info_handle_clustersize(struct inode *inode,
 				  struct ocfs2_info_request __user *req)
 {
-	int status = -EFAULT;
 	struct ocfs2_info_clustersize oic;
 	struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
 
 	if (o2info_from_user(oic, req))
-		goto bail;
+		return -EFAULT;
 
 	oic.ic_clustersize = osb->s_clustersize;
 
 	o2info_set_request_filled(&oic.ic_req);
 
 	if (o2info_to_user(oic, req))
-		goto bail;
-
-	status = 0;
-bail:
-	if (status)
-		o2info_set_request_error(&oic.ic_req, req);
+		return -EFAULT;
 
-	return status;
+	return 0;
 }
 
 int ocfs2_info_handle_maxslots(struct inode *inode,
 			       struct ocfs2_info_request __user *req)
 {
-	int status = -EFAULT;
 	struct ocfs2_info_maxslots oim;
 	struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
 
 	if (o2info_from_user(oim, req))
-		goto bail;
+		return -EFAULT;
 
 	oim.im_max_slots = osb->max_slots;
 
 	o2info_set_request_filled(&oim.im_req);
 
 	if (o2info_to_user(oim, req))
-		goto bail;
+		return -EFAULT;
 
-	status = 0;
-bail:
-	if (status)
-		o2info_set_request_error(&oim.im_req, req);
-
-	return status;
+	return 0;
 }
 
 int ocfs2_info_handle_label(struct inode *inode,
 			    struct ocfs2_info_request __user *req)
 {
-	int status = -EFAULT;
 	struct ocfs2_info_label oil;
 	struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
 
 	if (o2info_from_user(oil, req))
-		goto bail;
+		return -EFAULT;
 
 	memcpy(oil.il_label, osb->vol_label, OCFS2_MAX_VOL_LABEL_LEN);
 
 	o2info_set_request_filled(&oil.il_req);
 
 	if (o2info_to_user(oil, req))
-		goto bail;
+		return -EFAULT;
 
-	status = 0;
-bail:
-	if (status)
-		o2info_set_request_error(&oil.il_req, req);
-
-	return status;
+	return 0;
 }
 
 int ocfs2_info_handle_uuid(struct inode *inode,
 			   struct ocfs2_info_request __user *req)
 {
-	int status = -EFAULT;
 	struct ocfs2_info_uuid oiu;
 	struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
 
 	if (o2info_from_user(oiu, req))
-		goto bail;
+		return -EFAULT;
 
 	memcpy(oiu.iu_uuid_str, osb->uuid_str, OCFS2_TEXT_UUID_LEN + 1);
 
 	o2info_set_request_filled(&oiu.iu_req);
 
 	if (o2info_to_user(oiu, req))
-		goto bail;
-
-	status = 0;
-bail:
-	if (status)
-		o2info_set_request_error(&oiu.iu_req, req);
+		return -EFAULT;
 
-	return status;
+	return 0;
 }
 
 int ocfs2_info_handle_fs_features(struct inode *inode,
 				  struct ocfs2_info_request __user *req)
 {
-	int status = -EFAULT;
 	struct ocfs2_info_fs_features oif;
 	struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
 
 	if (o2info_from_user(oif, req))
-		goto bail;
+		return -EFAULT;
 
 	oif.if_compat_features = osb->s_feature_compat;
 	oif.if_incompat_features = osb->s_feature_incompat;
@@ -283,39 +251,28 @@ int ocfs2_info_handle_fs_features(struct inode *inode,
 	o2info_set_request_filled(&oif.if_req);
 
 	if (o2info_to_user(oif, req))
-		goto bail;
+		return -EFAULT;
 
-	status = 0;
-bail:
-	if (status)
-		o2info_set_request_error(&oif.if_req, req);
-
-	return status;
+	return 0;
 }
 
 int ocfs2_info_handle_journal_size(struct inode *inode,
 				   struct ocfs2_info_request __user *req)
 {
-	int status = -EFAULT;
 	struct ocfs2_info_journal_size oij;
 	struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
 
 	if (o2info_from_user(oij, req))
-		goto bail;
+		return -EFAULT;
 
 	oij.ij_journal_size = osb->journal->j_inode->i_size;
 
 	o2info_set_request_filled(&oij.ij_req);
 
 	if (o2info_to_user(oij, req))
-		goto bail;
+		return -EFAULT;
 
-	status = 0;
-bail:
-	if (status)
-		o2info_set_request_error(&oij.ij_req, req);
-
-	return status;
+	return 0;
 }
 
 int ocfs2_info_scan_inode_alloc(struct ocfs2_super *osb,
@@ -371,7 +328,7 @@ int ocfs2_info_handle_freeinode(struct inode *inode,
 	u32 i;
 	u64 blkno = -1;
 	char namebuf[40];
-	int status = -EFAULT, type = INODE_ALLOC_SYSTEM_INODE;
+	int status, type = INODE_ALLOC_SYSTEM_INODE;
 	struct ocfs2_info_freeinode *oifi = NULL;
 	struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
 	struct inode *inode_alloc = NULL;
@@ -383,8 +340,10 @@ int ocfs2_info_handle_freeinode(struct inode *inode,
 		goto out_err;
 	}
 
-	if (o2info_from_user(*oifi, req))
-		goto bail;
+	if (o2info_from_user(*oifi, req)) {
+		status = -EFAULT;
+		goto out_free;
+	}
 
 	oifi->ifi_slotnum = osb->max_slots;
 
@@ -421,14 +380,16 @@ int ocfs2_info_handle_freeinode(struct inode *inode,
 
 	o2info_set_request_filled(&oifi->ifi_req);
 
-	if (o2info_to_user(*oifi, req))
-		goto bail;
+	if (o2info_to_user(*oifi, req)) {
+		status = -EFAULT;
+		goto out_free;
+	}
 
 	status = 0;
 bail:
 	if (status)
 		o2info_set_request_error(&oifi->ifi_req, req);
-
+out_free:
 	kfree(oifi);
 out_err:
 	return status;
@@ -655,7 +616,7 @@ int ocfs2_info_handle_freefrag(struct inode *inode,
 {
 	u64 blkno = -1;
 	char namebuf[40];
-	int status = -EFAULT, type = GLOBAL_BITMAP_SYSTEM_INODE;
+	int status, type = GLOBAL_BITMAP_SYSTEM_INODE;
 
 	struct ocfs2_info_freefrag *oiff;
 	struct ocfs2_super *osb = OCFS2_SB(inode->i_sb);
@@ -668,8 +629,10 @@ int ocfs2_info_handle_freefrag(struct inode *inode,
 		goto out_err;
 	}
 
-	if (o2info_from_user(*oiff, req))
-		goto bail;
+	if (o2info_from_user(*oiff, req)) {
+		status = -EFAULT;
+		goto out_free;
+	}
 	/*
 	 * chunksize from userspace should be power of 2.
 	 */
@@ -708,14 +671,14 @@ int ocfs2_info_handle_freefrag(struct inode *inode,
 
 	if (o2info_to_user(*oiff, req)) {
 		status = -EFAULT;
-		goto bail;
+		goto out_free;
 	}
 
 	status = 0;
 bail:
 	if (status)
 		o2info_set_request_error(&oiff->iff_req, req);
-
+out_free:
 	kfree(oiff);
 out_err:
 	return status;
@@ -724,23 +687,17 @@ out_err:
 int ocfs2_info_handle_unknown(struct inode *inode,
 			      struct ocfs2_info_request __user *req)
 {
-	int status = -EFAULT;
 	struct ocfs2_info_request oir;
 
 	if (o2info_from_user(oir, req))
-		goto bail;
+		return -EFAULT;
 
 	o2info_clear_request_filled(&oir);
 
 	if (o2info_to_user(oir, req))
-		goto bail;
+		return -EFAULT;
 
-	status = 0;
-bail:
-	if (status)
-		o2info_set_request_error(&oir, req);
-
-	return status;
+	return 0;
 }
 
 /*
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660368 — [PATCH 3.10 107/250] drm/i915: Don't leak edid in intel_crt_detect_ddc()

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:20 +0200
Subject[PATCH 3.10 107/250] drm/i915: Don't leak edid in intel_crt_detect_ddc()
Message-ID<tPSp3-4Iz-9@gated-at.bofh.it>
In reply to#1660349
From: Ander Conselvan de Oliveira <ander.conselvan.de.oliveira@intel.com>

commit c34f078675f505c4437919bb1897b1351f16a050 upstream.

In the path where intel_crt_detect_ddc() detects a CRT, if would return
true without freeing the edid.

Fixes: a2bd1f541f19 ("drm/i915: check whether we actually received an edid in detect_ddc")
Cc: Chris Wilson <chris@chris-wilson.co.uk>
Cc: Daniel Vetter <daniel.vetter@ffwll.ch>
Cc: Daniel Vetter <daniel.vetter@intel.com>
Cc: Jani Nikula <jani.nikula@linux.intel.com>
Cc: intel-gfx@lists.freedesktop.org
Signed-off-by: Ander Conselvan de Oliveira <ander.conselvan.de.oliveira@intel.com>
Reviewed-by: Ville Syrjälä <ville.syrjala@linux.intel.com>
Reviewed-by: Jani Nikula <jani.nikula@intel.com>
Link: http://patchwork.freedesktop.org/patch/msgid/1484922525-6131-1-git-send-email-ander.conselvan.de.oliveira@intel.com
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/gpu/drm/i915/intel_crt.c | 9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

diff --git a/drivers/gpu/drm/i915/intel_crt.c b/drivers/gpu/drm/i915/intel_crt.c
index 53435a9..93c80d7 100644
--- a/drivers/gpu/drm/i915/intel_crt.c
+++ b/drivers/gpu/drm/i915/intel_crt.c
@@ -428,6 +428,7 @@ static bool intel_crt_detect_ddc(struct drm_connector *connector)
 	struct drm_i915_private *dev_priv = crt->base.base.dev->dev_private;
 	struct edid *edid;
 	struct i2c_adapter *i2c;
+	bool ret = false;
 
 	BUG_ON(crt->base.type != INTEL_OUTPUT_ANALOG);
 
@@ -444,17 +445,17 @@ static bool intel_crt_detect_ddc(struct drm_connector *connector)
 		 */
 		if (!is_digital) {
 			DRM_DEBUG_KMS("CRT detected via DDC:0x50 [EDID]\n");
-			return true;
+			ret = true;
+		} else {
+			DRM_DEBUG_KMS("CRT not detected via DDC:0x50 [EDID reports a digital panel]\n");
 		}
-
-		DRM_DEBUG_KMS("CRT not detected via DDC:0x50 [EDID reports a digital panel]\n");
 	} else {
 		DRM_DEBUG_KMS("CRT not detected via DDC:0x50 [no valid EDID found]\n");
 	}
 
 	kfree(edid);
 
-	return false;
+	return ret;
 }
 
 static enum drm_connector_status
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660369 — [PATCH 3.10 116/250] drm/i915: fix use-after-free in page_flip_completed()

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 01:20 +0200
Subject[PATCH 3.10 116/250] drm/i915: fix use-after-free in page_flip_completed()
Message-ID<tPSp3-4Iz-7@gated-at.bofh.it>
In reply to#1660349
From: Andrey Ryabinin <aryabinin@virtuozzo.com>

commit 5351fbb1bf1413f6024892093528280769ca852f upstream.

page_flip_completed() dereferences 'work' variable after executing
queue_work(). This is not safe as the 'work' item might be already freed
by queued work:

    BUG: KASAN: use-after-free in page_flip_completed+0x3ff/0x490 at addr ffff8803dc010f90
    Call Trace:
     __asan_report_load8_noabort+0x59/0x80
     page_flip_completed+0x3ff/0x490
     intel_finish_page_flip_mmio+0xe3/0x130
     intel_pipe_handle_vblank+0x2d/0x40
     gen8_irq_handler+0x4a7/0xed0
     __handle_irq_event_percpu+0xf6/0x860
     handle_irq_event_percpu+0x6b/0x160
     handle_irq_event+0xc7/0x1b0
     handle_edge_irq+0x1f4/0xa50
     handle_irq+0x41/0x70
     do_IRQ+0x9a/0x200
     common_interrupt+0x89/0x89

    Freed:
     kfree+0x113/0x4d0
     intel_unpin_work_fn+0x29a/0x3b0
     process_one_work+0x79e/0x1b70
     worker_thread+0x611/0x1460
     kthread+0x241/0x3a0
     ret_from_fork+0x27/0x40

Move queue_work() after	trace_i915_flip_complete() to fix this.

Fixes: e5510fac98a7 ("drm/i915: add tracepoints for flip requests & completions")
Signed-off-by: Andrey Ryabinin <aryabinin@virtuozzo.com>
Reviewed-by: Chris Wilson <chris@chris-wilson.co.uk>
Signed-off-by: Daniel Vetter <daniel.vetter@ffwll.ch>
Link: http://patchwork.freedesktop.org/patch/msgid/20170126143211.24013-1-aryabinin@virtuozzo.com
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Andrey Ryabinin <aryabinin@virtuozzo.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/gpu/drm/i915/intel_display.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/i915/intel_display.c b/drivers/gpu/drm/i915/intel_display.c
index 8814b0d..a7dbdec 100644
--- a/drivers/gpu/drm/i915/intel_display.c
+++ b/drivers/gpu/drm/i915/intel_display.c
@@ -7052,9 +7052,9 @@ static void do_intel_finish_page_flip(struct drm_device *dev,
 
 	wake_up_all(&dev_priv->pending_flip_queue);
 
-	queue_work(dev_priv->wq, &work->work);
-
 	trace_i915_flip_complete(intel_crtc->plane, work->pending_flip_obj);
+
+	queue_work(dev_priv->wq, &work->work);
 }
 
 void intel_finish_page_flip(struct drm_device *dev, int pipe)
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


Page 1 of 11  [1] 2 3 … 11  Next page →

Back to top | Article view | linux.kernel


csiph-web