Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1660349 > unrolled thread

[PATCH 3.10 000/250] 3.10.106-stable review

Started byWilly Tarreau <w@1wt.eu>
First post2017-06-08 01:10 +0200
Last post2017-06-08 06:30 +0200
Articles 20 on this page of 214 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.10 000/250] 3.10.106-stable review Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 188/250] uwb: hwa-rc: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 167/250] USB: serial: io_ti: fix NULL-deref in interrupt callback Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 136/250] mfd: pm8921: Potential NULL dereference in pm8921_remove() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 099/250] ubifs: Fix journal replay wrt. xattr nodes Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 102/250] arm64/ptrace: Reject attempts to set incomplete hardware breakpoint fields Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 223/250] Staging: vt6655-6: potential NULL dereference in hostap_disable_hostapd() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 006/250] KVM: x86: Introduce segmented_write_std Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 181/250] Input: hanwang - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 049/250] USB: serial: io_edgeport: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 090/250] powerpc/ibmebus: Fix further device reference leaks Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 172/250] net: net_enable_timestamp() can be called from irq contexts Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 159/250] USB: serial: digi_acceleport: fix OOB data sanity check Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 139/250] vti4: Don't count header length twice. Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 178/250] net: properly release sk_frag.page Willy Tarreau <w@1wt.eu> - 2017-06-08 01:10 +0200
    [PATCH 3.10 229/250] USB: dummy-hcd: fix bug in stop_activity (handle ep0) Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 123/250] packet: fix races in fanout_add() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 135/250] ocfs2: do not write error flag to user structure we cannot copy from/to Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 107/250] drm/i915: Don't leak edid in intel_crt_detect_ddc() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 116/250] drm/i915: fix use-after-free in page_flip_completed() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 202/250] metag/usercopy: Fix alignment error checking Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 236/250] ipv6: fix ip6_tnl_parse_tlv_enc_lim() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 134/250] goldfish: Sanitize the broken interrupt handler Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 234/250] xc2028: unlock on error in xc2028_set_config() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 158/250] dm: flush queued bios when process blocks to avoid deadlock Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 013/250] xfrm_user: validate XFRM_MSG_NEWAE incoming ESN size harder Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 120/250] ip6_gre: fix ip6gre_err() invalid reads Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 160/250] USB: serial: digi_acceleport: fix OOB-event processing Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 217/250] net: phy: handle state correctly in phy_stop_machine Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 062/250] staging: iio: ad7606: fix improper setting of oversampling pins Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 016/250] KEYS: fix keyctl_set_reqkey_keyring() to not leak thread keyrings Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 197/250] USB: OHCI: Fix race between ED unlink and URB submission Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 100/250] arm64/ptrace: Preserve previous registers for short regset write Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 133/250] x86/platform/goldfish: Prevent unconditional loading Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 220/250] ARM: dts: imx31: move CCM device node to AIPS2 bus devices Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 075/250] gro: Enter slow-path if there is no tailroom Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 083/250] USB: serial: ch341: fix open error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 230/250] mm/init: fix zone boundary creation Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 204/250] metag/usercopy: Set flags before ADDZ Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 149/250] scsi: aacraid: Reorder Adapter status check Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 101/250] arm64/ptrace: Avoid uninitialised struct padding in fpr_set() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 046/250] USB: serial: iuu_phoenix: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 026/250] ext4: fix stack memory corruption with 64k block size Willy Tarreau <w@1wt.eu> - 2017-06-08 01:20 +0200
    [PATCH 3.10 012/250] xfrm_user: validate XFRM_MSG_NEWAE XFRMA_REPLAY_ESN_VAL replay_window Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 201/250] ring-buffer: Fix return value check in test_ringbuffer() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 091/250] powerpc/ibmebus: Fix device reference leaks in sysfs interface Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 118/250] ipv4: keep skb->dst around in presence of IP options Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 113/250] ARM: 8643/3: arm/ptrace: Preserve previous registers for short regset write Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 020/250] hotplug: Make register and unregister notifier API symmetric Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 156/250] ktest: Fix child exit code processing Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 078/250] powerpc: Fix build warning on 32-bit PPC Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 103/250] ARM: ux500: fix prcmu_is_cpu_in_wfi() calculation Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 060/250] ALSA: usb-audio: Fix bogus error return in snd_usb_create_stream() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 147/250] MIPS: Handle microMIPS jumps in the same way as MIPS32/MIPS64 jumps Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 036/250] IB/multicast: Check ib_find_pkey() return value Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 073/250] net, sched: fix soft lockup in tc_classify Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 173/250] dccp/tcp: fix routing redirect race Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 087/250] USB: serial: ch341: fix modem-control and B0 handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 203/250] metag/usercopy: Add early abort to copy_to_user Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 063/250] usb: dwc3: gadget: always unmap EP0 requests Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 094/250] perf scripting: Avoid leaking the scripting_context variable Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 219/250] MIPS: KGDB: Use kernel context for sleeping threads Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 132/250] USB: serial: ark3116: fix register-accessor error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:30 +0200
    [PATCH 3.10 130/250] USB: serial: spcp8x5: fix modem-status handling Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 227/250] ping: implement proper locking Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 092/250] IB/mlx4: Set traffic class in AH Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 040/250] USB: serial: quatech2: fix sleep-while-atomic in close Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 187/250] uwb: i1480-dfu: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 242/250] kvm: exclude ioeventfd from counting kvm_io_range limit Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 222/250] tun: Fix TUN_PKT_STRIP setting Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 068/250] scsi: mvsas: fix command_active typo Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 207/250] s390/decompressor: fix initrd corruption caused by bss clear Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 161/250] MIPS: ip27: Disable qlge driver in defconfig Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 104/250] ite-cir: initialize use_demodulator before using it Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 228/250] USB: fix problems with duplicate endpoint addresses Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 143/250] MIPS: Prevent unaligned accesses during stack unwinding Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 208/250] net/mlx4_en: Fix bad WQE issue Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 119/250] netlabel: out of bound access in cipso_v4_validate() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 065/250] hwmon: (ds620) Fix overflows seen when writing temperature limits Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 162/250] tracing: Add #undef to fix compile error Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 177/250] xen: do not re-use pirq number cached in pci device msi msg data Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 144/250] MIPS: Fix get_frame_info() handling of microMIPS function size Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 237/250] ipv6: pointer math error in ip6_tnl_parse_tlv_enc_lim() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 216/250] netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT" failed in 64bit kernel Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 193/250] ALSA: ctxfi: Fix the incorrect check of dma_set_mask() call Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 206/250] metag/usercopy: Add missing fixups Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 225/250] perf trace: Use the syscall raw_syscalls:sys_enter timestamp Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 072/250] ser_gigaset: return -ENOMEM on error instead of success Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 051/250] USB: serial: cyberjack: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 155/250] IB/ipoib: Fix deadlock between rmmod and set_mode Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 175/250] perf/core: Fix event inheritance on fork() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 211/250] powerpc: Disable HFSCR[TM] if TM is not supported Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 192/250] ALSA: ctxfi: Fallback DMA mask to 32bit Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 232/250] Drivers: hv: avoid vfree() on crash Willy Tarreau <w@1wt.eu> - 2017-06-08 01:40 +0200
    [PATCH 3.10 249/250] dccp/tcp: do not inherit mc_list from parent Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 033/250] scsi: zfcp: fix rport unblock race with LUN recovery Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 171/250] locking/static_keys: Add static_key_{en,dis}able() helpers Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 096/250] svcrpc: don't leak contexts on PROC_DESTROY Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 055/250] USB: serial: mos7720: fix use-after-free on probe errors Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 125/250] net: socket: fix recvmmsg not returning error from sock_error Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 039/250] USB: serial: omninet: fix NULL-derefs at open and disconnect Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 117/250] net: use a work queue to defer net_disable_timestamp() work Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 077/250] gro: Disable frag0 optimization on IPv6 ext headers Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 064/250] cris: Only build flash rescue image if CONFIG_ETRAX_AXISFLASHMAP is selected Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 110/250] net: fix harmonize_features() vs NETIF_F_HIGHDMA Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 180/250] Input: ims-pcu - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 244/250] TTY: n_hdlc, fix lockdep false positive Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 235/250] xc2028: Fix use-after-free bug properly Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 148/250] uvcvideo: Fix a wrong macro Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 004/250] libceph: don't set weight to IN when OSD is destroyed Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 200/250] ptrace: fix PTRACE_LISTEN race corrupting task->state Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 250/250] char: lp: fix possible integer overflow in lp_setup() Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 239/250] sctp: avoid BUG_ON on sctp_wait_for_sndbuf Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 080/250] mm/hugetlb.c: fix reservation race when freeing surplus pages Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 041/250] USB: serial: pl2303: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 168/250] USB: serial: io_ti: fix information leak in completion handler Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 233/250] xc2028: avoid use after free Willy Tarreau <w@1wt.eu> - 2017-06-08 01:50 +0200
    [PATCH 3.10 122/250] l2tp: do not use udp_ioctl() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 146/250] MIPS: Calculate microMIPS ra properly when unwinding the stack Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 048/250] USB: serial: ti_usb_3410_5052: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 231/250] can: Fix kernel panic at security_sock_rcv_skb Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 182/250] Input: yealink - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 183/250] Input: cm109 - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 240/250] sctp: deny peeloff operation on asocs with threads sleeping on it Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 176/250] isdn/gigaset: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 052/250] USB: serial: kobil_sct: fix NULL-deref in write Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 153/250] NFSv4: fix getacl head length estimation Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 082/250] USB: serial: ch341: fix initial modem-control state Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 190/250] ext4: mark inode dirty after converting inline directory Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 086/250] USB: serial: ch341: fix resume after reset Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 127/250] USB: serial: ftdi_sio: fix modem-status error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 218/250] l2tp: take reference on sessions being dumped Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 015/250] KEYS: Change the name of the dead type to ".dead" to prevent user access Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 198/250] i2c: at91: manage unexpected RXRDY flag when starting a transfer Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 021/250] Btrfs: fix tree search logic when replaying directory entry deletes Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 034/250] ftrace/x86_32: Set ftrace_stub to weak to prevent gcc from using short jumps to it Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 184/250] USB: uss720: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 005/250] KVM: x86: fix emulation of "MOV SS, null selector" Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 151/250] fuse: add missing FR_FORCE Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 154/250] s390/qdio: clear DSCI prior to scanning multiple input queues Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 224/250] net: sctp: rework multihoming retransmission path selection to rfc4960 Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 247/250] fs: exec: apply CLOEXEC before changing dumpable task flags Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 191/250] scsi: libsas: fix ata xfer length Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 032/250] scsi: zfcp: do not trace pure benign residual HBA responses at default level Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 088/250] x86/cpu: Fix bootup crashes by sanitizing the argument of the 'clearcpuid=' command-line option Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 189/250] mmc: ushc: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 141/250] MIPS: OCTEON: Fix copy_from_user fault handling for large buffers Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 108/250] s5k4ecgx: select CRC32 helper Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 150/250] ath9k: use correct OTP register offsets for the AR9340 and AR9550 Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 124/250] packet: Do not call fanout_release from atomic contexts Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 152/250] RDMA/core: Fix incorrect structure packing for booleans Willy Tarreau <w@1wt.eu> - 2017-06-08 02:00 +0200
    [PATCH 3.10 076/250] gro: use min_t() in skb_gro_reset_offset() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 105/250] fuse: do not use iocb after it may have been freed Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 245/250] tty: n_hdlc: get rid of racy n_hdlc.tbuf Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 067/250] iommu/amd: Fix the left value check of cmd buffer Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 164/250] USB: serial: omninet: fix reference leaks at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 140/250] net/sched: em_meta: Fix 'meta vlan' to correctly recognize zero VID frames Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 029/250] f2fs: set ->owner for debugfs status file's file_operations Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 058/250] usb: xhci-mem: use passed in GFP flags instead of GFP_KERNEL Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 031/250] scsi: zfcp: fix use-after-"free" in FC ingress path after TMF Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 023/250] block_dev: don't test bdev->bd_contains when it is not stable Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 157/250] nlm: Ensure callback code also checks that the files match Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 089/250] NFSv4.1: nfs4_fl_prepare_ds must be careful about reporting success. Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 209/250] net/mlx4_core: Fix racy CQ (Completion Queue) free Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 112/250] svcrpc: fix oops in absence of krb5 module Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
      Re: [PATCH 3.10 112/250] svcrpc: fix oops in absence of krb5 module Simo Sorce <simo@redhat.com> - 2017-06-08 10:20 +0200
    [PATCH 3.10 114/250] mac80211: Fix adding of mesh vendor IEs Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 246/250] ipv6: handle -EFAULT from skb_copy_bits Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 138/250] net: 6lowpan: fix lowpan_header_create non-compression memcpy call Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 059/250] usb: musb: Fix trying to free already-free IRQ 4 Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 137/250] drm/nv50/disp: min/max are reversed in nv50_crtc_gamma_set() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 097/250] mmc: mxs-mmc: Fix additional cycles after transmission stop Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 205/250] metag/usercopy: Fix src fixup in from user rapf loops Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 165/250] USB: iowarrior: fix NULL-deref at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 131/250] USB: serial: opticon: fix CTS retrieval at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 215/250] ring-buffer: Have ring_buffer_iter_empty() return true when empty Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 098/250] mtd: nand: xway: disable module support Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 044/250] USB: serial: io_ti: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 212/250] pegasus: Use heap buffers for all register access Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 214/250] tracing: Allocate the snapshot buffer before enabling probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 106/250] crypto: caam - fix non-hmac hashes Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 169/250] vxlan: correctly validate VXLAN ID against VXLAN_N_VID Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 002/250] crypto: crypto_memneq - add equality testing of memory regions w/o timing leaks Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 071/250] powerpc/pci/rpadlpar: Fix device reference leaks Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 194/250] ACPI / PNP: Avoid conflicting resource reservations Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 047/250] USB: serial: garmin_gps: fix memory leak on failed URB submit Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 018/250] locking/rtmutex: Prevent dequeue vs. unlock race Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 195/250] ACPI / resources: free memory on error in add_region_before() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 179/250] net: unix: properly re-increment inflight counter of GC discarded candidates Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 054/250] USB: serial: mos7720: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:10 +0200
    [PATCH 3.10 074/250] net: stmmac: Fix race between stmmac_drv_probe and stmmac_open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 042/250] USB: serial: keyspan_pda: verify endpoints at probe Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 028/250] ext4: return -ENOMEM instead of success Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 038/250] usb: gadget: composite: Test get_alt() presence instead of set_alt() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 017/250] ext4: fix data exposure after a crash Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 025/250] ext4: fix mballoc breakage with 64k block size Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 030/250] block: protect iterate_bdevs() against concurrent close Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 111/250] tcp: initialize max window for a new fastopen socket Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 009/250] fbdev: color map copying bounds checking Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 126/250] USB: serial: mos7840: fix another NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 035/250] IB/mad: Fix an array index check Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 050/250] USB: serial: oti6858: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 001/250] packet: fix race condition in packet_set_ring Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 081/250] USB: serial: kl5kusb105: fix line-state error handling Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 079/250] Input: i8042 - add Pegatron touchpad to noloop table Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 037/250] powerpc: Convert cmp to cmpd in idle enter sequence Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 061/250] USB: serial: kl5kusb105: abort on open exception path Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 024/250] crypto: caam - fix AEAD givenc descriptors Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 010/250] selinux: fix off-by-one in setprocattr Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 043/250] USB: serial: spcp8x5: fix NULL-deref at open Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 142/250] MIPS: Clear ISA bit correctly in get_frame_info() Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    [PATCH 3.10 019/250] m68k: Fix ndelay() macro Willy Tarreau <w@1wt.eu> - 2017-06-08 02:20 +0200
    Re: [PATCH 3.10 000/250] 3.10.106-stable review Guenter Roeck <linux@roeck-us.net> - 2017-06-08 02:40 +0200
      Re: [PATCH 3.10 000/250] 3.10.106-stable review Willy Tarreau <w@1wt.eu> - 2017-06-08 06:30 +0200

Page 7 of 11 — ← Prev page 1 … 5 6 [7] 8 9 … 11  Next page →


#1660509 — [PATCH 3.10 231/250] can: Fix kernel panic at security_sock_rcv_skb

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 231/250] can: Fix kernel panic at security_sock_rcv_skb
Message-ID<tPT1L-4Xs-11@gated-at.bofh.it>
In reply to#1660349
From: Eric Dumazet <edumazet@google.com>

commit f1712c73714088a7252d276a57126d56c7d37e64 upstream.

Zhang Yanmin reported crashes [1] and provided a patch adding a
synchronize_rcu() call in can_rx_unregister()

The main problem seems that the sockets themselves are not RCU
protected.

If CAN uses RCU for delivery, then sockets should be freed only after
one RCU grace period.

Recent kernels could use sock_set_flag(sk, SOCK_RCU_FREE), but let's
ease stable backports with the following fix instead.

[1]
BUG: unable to handle kernel NULL pointer dereference at (null)
IP: [<ffffffff81495e25>] selinux_socket_sock_rcv_skb+0x65/0x2a0

Call Trace:
 <IRQ>
 [<ffffffff81485d8c>] security_sock_rcv_skb+0x4c/0x60
 [<ffffffff81d55771>] sk_filter+0x41/0x210
 [<ffffffff81d12913>] sock_queue_rcv_skb+0x53/0x3a0
 [<ffffffff81f0a2b3>] raw_rcv+0x2a3/0x3c0
 [<ffffffff81f06eab>] can_rcv_filter+0x12b/0x370
 [<ffffffff81f07af9>] can_receive+0xd9/0x120
 [<ffffffff81f07beb>] can_rcv+0xab/0x100
 [<ffffffff81d362ac>] __netif_receive_skb_core+0xd8c/0x11f0
 [<ffffffff81d36734>] __netif_receive_skb+0x24/0xb0
 [<ffffffff81d37f67>] process_backlog+0x127/0x280
 [<ffffffff81d36f7b>] net_rx_action+0x33b/0x4f0
 [<ffffffff810c88d4>] __do_softirq+0x184/0x440
 [<ffffffff81f9e86c>] do_softirq_own_stack+0x1c/0x30
 <EOI>
 [<ffffffff810c76fb>] do_softirq.part.18+0x3b/0x40
 [<ffffffff810c8bed>] do_softirq+0x1d/0x20
 [<ffffffff81d30085>] netif_rx_ni+0xe5/0x110
 [<ffffffff8199cc87>] slcan_receive_buf+0x507/0x520
 [<ffffffff8167ef7c>] flush_to_ldisc+0x21c/0x230
 [<ffffffff810e3baf>] process_one_work+0x24f/0x670
 [<ffffffff810e44ed>] worker_thread+0x9d/0x6f0
 [<ffffffff810e4450>] ? rescuer_thread+0x480/0x480
 [<ffffffff810ebafc>] kthread+0x12c/0x150
 [<ffffffff81f9ccef>] ret_from_fork+0x3f/0x70

Reported-by: Zhang Yanmin <yanmin.zhang@intel.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Oliver Hartkopp <socketcan@hartkopp.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 include/linux/can/core.h |  7 +++----
 net/can/af_can.c         | 12 ++++++++++--
 net/can/af_can.h         |  3 ++-
 net/can/bcm.c            |  4 ++--
 net/can/gw.c             |  2 +-
 net/can/raw.c            |  4 ++--
 6 files changed, 20 insertions(+), 12 deletions(-)

diff --git a/include/linux/can/core.h b/include/linux/can/core.h
index 78c6c52..6bdc00b 100644
--- a/include/linux/can/core.h
+++ b/include/linux/can/core.h
@@ -45,10 +45,9 @@ struct can_proto {
 extern int  can_proto_register(const struct can_proto *cp);
 extern void can_proto_unregister(const struct can_proto *cp);
 
-extern int  can_rx_register(struct net_device *dev, canid_t can_id,
-			    canid_t mask,
-			    void (*func)(struct sk_buff *, void *),
-			    void *data, char *ident);
+int can_rx_register(struct net_device *dev, canid_t can_id, canid_t mask,
+		    void (*func)(struct sk_buff *, void *),
+		    void *data, char *ident, struct sock *sk);
 
 extern void can_rx_unregister(struct net_device *dev, canid_t can_id,
 			      canid_t mask,
diff --git a/net/can/af_can.c b/net/can/af_can.c
index d3668c5..34064aa 100644
--- a/net/can/af_can.c
+++ b/net/can/af_can.c
@@ -425,6 +425,7 @@ static struct hlist_head *find_rcv_list(canid_t *can_id, canid_t *mask,
  * @func: callback function on filter match
  * @data: returned parameter for callback function
  * @ident: string for calling module indentification
+ * @sk: socket pointer (might be NULL)
  *
  * Description:
  *  Invokes the callback function with the received sk_buff and the given
@@ -448,7 +449,7 @@ static struct hlist_head *find_rcv_list(canid_t *can_id, canid_t *mask,
  */
 int can_rx_register(struct net_device *dev, canid_t can_id, canid_t mask,
 		    void (*func)(struct sk_buff *, void *), void *data,
-		    char *ident)
+		    char *ident, struct sock *sk)
 {
 	struct receiver *r;
 	struct hlist_head *rl;
@@ -476,6 +477,7 @@ int can_rx_register(struct net_device *dev, canid_t can_id, canid_t mask,
 		r->func    = func;
 		r->data    = data;
 		r->ident   = ident;
+		r->sk      = sk;
 
 		hlist_add_head_rcu(&r->list, rl);
 		d->entries++;
@@ -500,8 +502,11 @@ EXPORT_SYMBOL(can_rx_register);
 static void can_rx_delete_receiver(struct rcu_head *rp)
 {
 	struct receiver *r = container_of(rp, struct receiver, rcu);
+	struct sock *sk = r->sk;
 
 	kmem_cache_free(rcv_cache, r);
+	if (sk)
+		sock_put(sk);
 }
 
 /**
@@ -576,8 +581,11 @@ void can_rx_unregister(struct net_device *dev, canid_t can_id, canid_t mask,
 	spin_unlock(&can_rcvlists_lock);
 
 	/* schedule the receiver item for deletion */
-	if (r)
+	if (r) {
+		if (r->sk)
+			sock_hold(r->sk);
 		call_rcu(&r->rcu, can_rx_delete_receiver);
+	}
 }
 EXPORT_SYMBOL(can_rx_unregister);
 
diff --git a/net/can/af_can.h b/net/can/af_can.h
index 1dccb4c..0e95be4 100644
--- a/net/can/af_can.h
+++ b/net/can/af_can.h
@@ -50,13 +50,14 @@
 
 struct receiver {
 	struct hlist_node list;
-	struct rcu_head rcu;
 	canid_t can_id;
 	canid_t mask;
 	unsigned long matches;
 	void (*func)(struct sk_buff *, void *);
 	void *data;
 	char *ident;
+	struct sock *sk;
+	struct rcu_head rcu;
 };
 
 enum { RX_ERR, RX_ALL, RX_FIL, RX_INV, RX_EFF, RX_MAX };
diff --git a/net/can/bcm.c b/net/can/bcm.c
index dd0781c..725ce81 100644
--- a/net/can/bcm.c
+++ b/net/can/bcm.c
@@ -1169,7 +1169,7 @@ static int bcm_rx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
 				err = can_rx_register(dev, op->can_id,
 						      REGMASK(op->can_id),
 						      bcm_rx_handler, op,
-						      "bcm");
+						      "bcm", sk);
 
 				op->rx_reg_dev = dev;
 				dev_put(dev);
@@ -1178,7 +1178,7 @@ static int bcm_rx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
 		} else
 			err = can_rx_register(NULL, op->can_id,
 					      REGMASK(op->can_id),
-					      bcm_rx_handler, op, "bcm");
+					      bcm_rx_handler, op, "bcm", sk);
 		if (err) {
 			/* this bcm rx op is broken -> remove it */
 			list_del(&op->list);
diff --git a/net/can/gw.c b/net/can/gw.c
index de25455..2ad8aa4 100644
--- a/net/can/gw.c
+++ b/net/can/gw.c
@@ -435,7 +435,7 @@ static inline int cgw_register_filter(struct cgw_job *gwj)
 {
 	return can_rx_register(gwj->src.dev, gwj->ccgw.filter.can_id,
 			       gwj->ccgw.filter.can_mask, can_can_gw_rcv,
-			       gwj, "gw");
+			       gwj, "gw", NULL);
 }
 
 static inline void cgw_unregister_filter(struct cgw_job *gwj)
diff --git a/net/can/raw.c b/net/can/raw.c
index 1085e65..f4d8648 100644
--- a/net/can/raw.c
+++ b/net/can/raw.c
@@ -168,7 +168,7 @@ static int raw_enable_filters(struct net_device *dev, struct sock *sk,
 	for (i = 0; i < count; i++) {
 		err = can_rx_register(dev, filter[i].can_id,
 				      filter[i].can_mask,
-				      raw_rcv, sk, "raw");
+				      raw_rcv, sk, "raw", sk);
 		if (err) {
 			/* clean up successfully registered filters */
 			while (--i >= 0)
@@ -189,7 +189,7 @@ static int raw_enable_errfilter(struct net_device *dev, struct sock *sk,
 
 	if (err_mask)
 		err = can_rx_register(dev, 0, err_mask | CAN_ERR_FLAG,
-				      raw_rcv, sk, "raw");
+				      raw_rcv, sk, "raw", sk);
 
 	return err;
 }
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660510 — [PATCH 3.10 182/250] Input: yealink - validate number of endpoints before using them

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 182/250] Input: yealink - validate number of endpoints before using them
Message-ID<tPT1L-4Xs-9@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit 5cc4a1a9f5c179795c8a1f2b0f4361829d6a070e upstream.

Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer should a malicious device lack endpoints.

Fixes: aca951a22a1d ("[PATCH] input-driver-yealink-P1K-usb-phone")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/input/misc/yealink.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/input/misc/yealink.c b/drivers/input/misc/yealink.c
index 285a5bd..3b6fdb3 100644
--- a/drivers/input/misc/yealink.c
+++ b/drivers/input/misc/yealink.c
@@ -876,6 +876,10 @@ static int usb_probe(struct usb_interface *intf, const struct usb_device_id *id)
 	int ret, pipe, i;
 
 	interface = intf->cur_altsetting;
+
+	if (interface->desc.bNumEndpoints < 1)
+		return -ENODEV;
+
 	endpoint = &interface->endpoint[0].desc;
 	if (!usb_endpoint_is_int_in(endpoint))
 		return -ENODEV;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660511 — [PATCH 3.10 183/250] Input: cm109 - validate number of endpoints before using them

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 183/250] Input: cm109 - validate number of endpoints before using them
Message-ID<tPT1L-4Xs-13@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit ac2ee9ba953afe88f7a673e1c0c839227b1d7891 upstream.

Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer should a malicious device lack endpoints.

Fixes: c04148f915e5 ("Input: add driver for USB VoIP phones with CM109...")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/input/misc/cm109.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/input/misc/cm109.c b/drivers/input/misc/cm109.c
index 082684e..d6a35a7 100644
--- a/drivers/input/misc/cm109.c
+++ b/drivers/input/misc/cm109.c
@@ -669,6 +669,10 @@ static int cm109_usb_probe(struct usb_interface *intf,
 	int error = -ENOMEM;
 
 	interface = intf->cur_altsetting;
+
+	if (interface->desc.bNumEndpoints < 1)
+		return -ENODEV;
+
 	endpoint = &interface->endpoint[0].desc;
 
 	if (!usb_endpoint_is_int_in(endpoint))
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660512 — [PATCH 3.10 240/250] sctp: deny peeloff operation on asocs with threads sleeping on it

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 240/250] sctp: deny peeloff operation on asocs with threads sleeping on it
Message-ID<tPT1L-4Xs-17@gated-at.bofh.it>
In reply to#1660349
From: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>

commit dfcb9f4f99f1e9a49e43398a7bfbf56927544af1 upstream.

commit 2dcab5984841 ("sctp: avoid BUG_ON on sctp_wait_for_sndbuf")
attempted to avoid a BUG_ON call when the association being used for a
sendmsg() is blocked waiting for more sndbuf and another thread did a
peeloff operation on such asoc, moving it to another socket.

As Ben Hutchings noticed, then in such case it would return without
locking back the socket and would cause two unlocks in a row.

Further analysis also revealed that it could allow a double free if the
application managed to peeloff the asoc that is created during the
sendmsg call, because then sctp_sendmsg() would try to free the asoc
that was created only for that call.

This patch takes another approach. It will deny the peeloff operation
if there is a thread sleeping on the asoc, so this situation doesn't
exist anymore. This avoids the issues described above and also honors
the syscalls that are already being handled (it can be multiple sendmsg
calls).

Joint work with Xin Long.

Fixes: 2dcab5984841 ("sctp: avoid BUG_ON on sctp_wait_for_sndbuf")
Cc: Alexander Popov <alex.popov@linux.com>
Cc: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Signed-off-by: Xin Long <lucien.xin@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/sctp/socket.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/net/sctp/socket.c b/net/sctp/socket.c
index 152ab4b..4178cf3 100644
--- a/net/sctp/socket.c
+++ b/net/sctp/socket.c
@@ -4310,6 +4310,12 @@ int sctp_do_peeloff(struct sock *sk, sctp_assoc_t id, struct socket **sockp)
 	if (!asoc)
 		return -EINVAL;
 
+	/* If there is a thread waiting on more sndbuf space for
+	 * sending on this asoc, it cannot be peeled.
+	 */
+	if (waitqueue_active(&asoc->wait))
+		return -EBUSY;
+
 	/* An association cannot be branched off from an already peeled-off
 	 * socket, nor is this supported for tcp style sockets.
 	 */
@@ -6724,8 +6730,6 @@ static int sctp_wait_for_sndbuf(struct sctp_association *asoc, long *timeo_p,
 		 */
 		sctp_release_sock(sk);
 		current_timeo = schedule_timeout(current_timeo);
-		if (sk != asoc->base.sk)
-			goto do_error;
 		sctp_lock_sock(sk);
 
 		*timeo_p = current_timeo;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660513 — [PATCH 3.10 176/250] isdn/gigaset: fix NULL-deref at probe

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 176/250] isdn/gigaset: fix NULL-deref at probe
Message-ID<tPT1L-4Xs-15@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit 68c32f9c2a36d410aa242e661506e5b2c2764179 upstream.

Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer should a malicious device lack endpoints.

Fixes: cf7776dc05b8 ("[PATCH] isdn4linux: Siemens Gigaset drivers - direct USB connection")
Cc: Hansjoerg Lipp <hjlipp@web.de>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/isdn/gigaset/bas-gigaset.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/isdn/gigaset/bas-gigaset.c b/drivers/isdn/gigaset/bas-gigaset.c
index c44950d..6d4d9c1 100644
--- a/drivers/isdn/gigaset/bas-gigaset.c
+++ b/drivers/isdn/gigaset/bas-gigaset.c
@@ -2317,6 +2317,9 @@ static int gigaset_probe(struct usb_interface *interface,
 		return -ENODEV;
 	}
 
+	if (hostif->desc.bNumEndpoints < 1)
+		return -ENODEV;
+
 	dev_info(&udev->dev,
 		 "%s: Device matched (Vendor: 0x%x, Product: 0x%x)\n",
 		 __func__, le16_to_cpu(udev->descriptor.idVendor),
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660514 — [PATCH 3.10 052/250] USB: serial: kobil_sct: fix NULL-deref in write

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 052/250] USB: serial: kobil_sct: fix NULL-deref in write
Message-ID<tPT1M-4Xs-21@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit 21ce57840243c7b70fbc1ebd3dceeb70bb6e9e09 upstream.

Fix NULL-pointer dereference in write() should the device lack the
expected interrupt-out endpoint:

Unable to handle kernel NULL pointer dereference at virtual address 00000054
...
PC is at kobil_write+0x144/0x2a0 [kobil_sct]

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/serial/kobil_sct.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/drivers/usb/serial/kobil_sct.c b/drivers/usb/serial/kobil_sct.c
index efa75b4..63fa400 100644
--- a/drivers/usb/serial/kobil_sct.c
+++ b/drivers/usb/serial/kobil_sct.c
@@ -52,6 +52,7 @@
 
 
 /* Function prototypes */
+static int kobil_attach(struct usb_serial *serial);
 static int kobil_port_probe(struct usb_serial_port *probe);
 static int kobil_port_remove(struct usb_serial_port *probe);
 static int  kobil_open(struct tty_struct *tty, struct usb_serial_port *port);
@@ -87,6 +88,7 @@ static struct usb_serial_driver kobil_device = {
 	.description =		"KOBIL USB smart card terminal",
 	.id_table =		id_table,
 	.num_ports =		1,
+	.attach =		kobil_attach,
 	.port_probe =		kobil_port_probe,
 	.port_remove =		kobil_port_remove,
 	.ioctl =		kobil_ioctl,
@@ -114,6 +116,16 @@ struct kobil_private {
 };
 
 
+static int kobil_attach(struct usb_serial *serial)
+{
+	if (serial->num_interrupt_out < serial->num_ports) {
+		dev_err(&serial->interface->dev, "missing interrupt-out endpoint\n");
+		return -ENODEV;
+	}
+
+	return 0;
+}
+
 static int kobil_port_probe(struct usb_serial_port *port)
 {
 	struct usb_serial *serial = port->serial;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660515 — [PATCH 3.10 153/250] NFSv4: fix getacl head length estimation

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 153/250] NFSv4: fix getacl head length estimation
Message-ID<tPT1L-4Xs-19@gated-at.bofh.it>
In reply to#1660349
From: "J. Bruce Fields" <bfields@redhat.com>

commit 6682c14bbe505a8b912c57faf544f866777ee48d upstream.

Bitmap and attrlen follow immediately after the op reply header.  This
was an oversight from commit bf118a342f.

Consequences of this are just minor efficiency (extra calls to
xdr_shrink_bufhead).

Fixes: bf118a342f10 "NFSv4: include bitmap in nfsv4 get acl data"
Reviewed-by: Kinglong Mee <kinglongmee@gmail.com>
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
Signed-off-by: Anna Schumaker <Anna.Schumaker@Netapp.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/nfs/nfs4xdr.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/nfs/nfs4xdr.c b/fs/nfs/nfs4xdr.c
index 988efb4..f5d27ca 100644
--- a/fs/nfs/nfs4xdr.c
+++ b/fs/nfs/nfs4xdr.c
@@ -2435,7 +2435,7 @@ static void nfs4_xdr_enc_getacl(struct rpc_rqst *req, struct xdr_stream *xdr,
 	encode_compound_hdr(xdr, req, &hdr);
 	encode_sequence(xdr, &args->seq_args, &hdr);
 	encode_putfh(xdr, args->fh, &hdr);
-	replen = hdr.replen + op_decode_hdr_maxsz + 1;
+	replen = hdr.replen + op_decode_hdr_maxsz;
 	encode_getattr_two(xdr, FATTR4_WORD0_ACL, 0, &hdr);
 
 	xdr_inline_pages(&req->rq_rcv_buf, replen << 2,
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660516 — [PATCH 3.10 082/250] USB: serial: ch341: fix initial modem-control state

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 082/250] USB: serial: ch341: fix initial modem-control state
Message-ID<tPT1M-4Xs-25@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit 4e2da44691cffbfffb1535f478d19bc2dca3e62b upstream.

DTR and RTS will be asserted by the tty-layer when the port is opened
and deasserted on close (if HUPCL is set). Make sure the initial state
is not-asserted before the port is first opened as well.

Fixes: 664d5df92e88 ("USB: usb-serial ch341: support for DTR/RTS/CTS")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/serial/ch341.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/drivers/usb/serial/ch341.c b/drivers/usb/serial/ch341.c
index c2a4171..2272f4f 100644
--- a/drivers/usb/serial/ch341.c
+++ b/drivers/usb/serial/ch341.c
@@ -252,7 +252,6 @@ static int ch341_port_probe(struct usb_serial_port *port)
 
 	spin_lock_init(&priv->lock);
 	priv->baud_rate = DEFAULT_BAUD_RATE;
-	priv->line_control = CH341_BIT_RTS | CH341_BIT_DTR;
 
 	r = ch341_configure(port->serial->dev, priv);
 	if (r < 0)
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660517 — [PATCH 3.10 190/250] ext4: mark inode dirty after converting inline directory

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 190/250] ext4: mark inode dirty after converting inline directory
Message-ID<tPT1M-4Xs-23@gated-at.bofh.it>
In reply to#1660349
From: Eric Biggers <ebiggers@google.com>

commit b9cf625d6ecde0d372e23ae022feead72b4228a6 upstream.

If ext4_convert_inline_data() was called on a directory with inline
data, the filesystem was left in an inconsistent state (as considered by
e2fsck) because the file size was not increased to cover the new block.
This happened because the inode was not marked dirty after i_disksize
was updated.  Fix this by marking the inode dirty at the end of
ext4_finish_convert_inline_dir().

This bug was probably not noticed before because most users mark the
inode dirty afterwards for other reasons.  But if userspace executed
FS_IOC_SET_ENCRYPTION_POLICY with invalid parameters, as exercised by
'kvm-xfstests -c adv generic/396', then the inode was never marked dirty
after updating i_disksize.

Fixes: 3c47d54170b6a678875566b1b8d6dcf57904e49b
Signed-off-by: Eric Biggers <ebiggers@google.com>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/ext4/inline.c | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/fs/ext4/inline.c b/fs/ext4/inline.c
index b390de0..55af0d9 100644
--- a/fs/ext4/inline.c
+++ b/fs/ext4/inline.c
@@ -1147,10 +1147,9 @@ static int ext4_finish_convert_inline_dir(handle_t *handle,
 	set_buffer_uptodate(dir_block);
 	err = ext4_handle_dirty_dirent_node(handle, inode, dir_block);
 	if (err)
-		goto out;
+		return err;
 	set_buffer_verified(dir_block);
-out:
-	return err;
+	return ext4_mark_inode_dirty(handle, inode);
 }
 
 static int ext4_convert_inline_data_nolock(handle_t *handle,
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660518 — [PATCH 3.10 086/250] USB: serial: ch341: fix resume after reset

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 086/250] USB: serial: ch341: fix resume after reset
Message-ID<tPT1M-4Xs-29@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit ce5e292828117d1b71cbd3edf9e9137cf31acd30 upstream.

Fix reset-resume handling which failed to resubmit the read and
interrupt URBs, thereby leaving a port that was open before suspend in a
broken state until closed and reopened.

Fixes: 1ded7ea47b88 ("USB: ch341 serial: fix port number changed after
resume")
Fixes: 2bfd1c96a9fb ("USB: serial: ch341: remove reset_resume callback")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/serial/ch341.c | 17 +++++++++++++----
 1 file changed, 13 insertions(+), 4 deletions(-)

diff --git a/drivers/usb/serial/ch341.c b/drivers/usb/serial/ch341.c
index e9cfd40..be51cd9 100644
--- a/drivers/usb/serial/ch341.c
+++ b/drivers/usb/serial/ch341.c
@@ -585,14 +585,23 @@ static int ch341_tiocmget(struct tty_struct *tty)
 
 static int ch341_reset_resume(struct usb_serial *serial)
 {
-	struct ch341_private *priv;
-
-	priv = usb_get_serial_port_data(serial->port[0]);
+	struct usb_serial_port *port = serial->port[0];
+	struct ch341_private *priv = usb_get_serial_port_data(port);
+	int ret;
 
 	/* reconfigure ch341 serial port after bus-reset */
 	ch341_configure(serial->dev, priv);
 
-	return 0;
+	if (test_bit(ASYNCB_INITIALIZED, &port->port.flags)) {
+		ret = usb_submit_urb(port->interrupt_in_urb, GFP_NOIO);
+		if (ret) {
+			dev_err(&port->dev, "failed to submit interrupt urb: %d\n",
+				ret);
+			return ret;
+		}
+	}
+
+	return usb_serial_generic_resume(serial);
 }
 
 static struct usb_serial_driver ch341_device = {
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660519 — [PATCH 3.10 127/250] USB: serial: ftdi_sio: fix modem-status error handling

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 127/250] USB: serial: ftdi_sio: fix modem-status error handling
Message-ID<tPT1M-4Xs-31@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit 427c3a95e3e29e65f59d99aaf320d7506f3eed57 upstream.

Make sure to detect short responses when fetching the modem status in
order to avoid parsing uninitialised buffer data and having bits of it
leak to user space.

Note that we still allow for short 1-byte responses.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/serial/ftdi_sio.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/usb/serial/ftdi_sio.c b/drivers/usb/serial/ftdi_sio.c
index 4e86566..ba04308 100644
--- a/drivers/usb/serial/ftdi_sio.c
+++ b/drivers/usb/serial/ftdi_sio.c
@@ -2452,8 +2452,12 @@ static int ftdi_get_modem_status(struct usb_serial_port *port,
 			FTDI_SIO_GET_MODEM_STATUS_REQUEST_TYPE,
 			0, priv->interface,
 			buf, len, WDR_TIMEOUT);
-	if (ret < 0) {
+
+	/* NOTE: We allow short responses and handle that below. */
+	if (ret < 1) {
 		dev_err(&port->dev, "failed to get modem status: %d\n", ret);
+		if (ret >= 0)
+			ret = -EIO;
 		ret = usb_translate_errors(ret);
 		goto out;
 	}
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660520 — [PATCH 3.10 218/250] l2tp: take reference on sessions being dumped

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 218/250] l2tp: take reference on sessions being dumped
Message-ID<tPT1M-4Xs-33@gated-at.bofh.it>
In reply to#1660349
From: Guillaume Nault <g.nault@alphalink.fr>

commit e08293a4ccbcc993ded0fdc46f1e57926b833d63 upstream.

Take a reference on the sessions returned by l2tp_session_find_nth()
(and rename it l2tp_session_get_nth() to reflect this change), so that
caller is assured that the session isn't going to disappear while
processing it.

For procfs and debugfs handlers, the session is held in the .start()
callback and dropped in .show(). Given that pppol2tp_seq_session_show()
dereferences the associated PPPoL2TP socket and that
l2tp_dfs_seq_session_show() might call pppol2tp_show(), we also need to
call the session's .ref() callback to prevent the socket from going
away from under us.

Fixes: fd558d186df2 ("l2tp: Split pppol2tp patch into separate l2tp and ppp parts")
Fixes: 0ad6614048cf ("l2tp: Add debugfs files for dumping l2tp debug info")
Fixes: 309795f4bec2 ("l2tp: Add netlink control API for L2TP")
Signed-off-by: Guillaume Nault <g.nault@alphalink.fr>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/l2tp/l2tp_core.c    |  8 ++++++--
 net/l2tp/l2tp_core.h    |  3 ++-
 net/l2tp/l2tp_debugfs.c | 10 +++++++---
 net/l2tp/l2tp_netlink.c |  7 +++++--
 net/l2tp/l2tp_ppp.c     | 10 +++++++---
 5 files changed, 27 insertions(+), 11 deletions(-)

diff --git a/net/l2tp/l2tp_core.c b/net/l2tp/l2tp_core.c
index 797ff37..787ac0e 100644
--- a/net/l2tp/l2tp_core.c
+++ b/net/l2tp/l2tp_core.c
@@ -280,7 +280,8 @@ struct l2tp_session *l2tp_session_find(struct net *net, struct l2tp_tunnel *tunn
 }
 EXPORT_SYMBOL_GPL(l2tp_session_find);
 
-struct l2tp_session *l2tp_session_find_nth(struct l2tp_tunnel *tunnel, int nth)
+struct l2tp_session *l2tp_session_get_nth(struct l2tp_tunnel *tunnel, int nth,
+					  bool do_ref)
 {
 	int hash;
 	struct l2tp_session *session;
@@ -290,6 +291,9 @@ struct l2tp_session *l2tp_session_find_nth(struct l2tp_tunnel *tunnel, int nth)
 	for (hash = 0; hash < L2TP_HASH_SIZE; hash++) {
 		hlist_for_each_entry(session, &tunnel->session_hlist[hash], hlist) {
 			if (++count > nth) {
+				l2tp_session_inc_refcount(session);
+				if (do_ref && session->ref)
+					session->ref(session);
 				read_unlock_bh(&tunnel->hlist_lock);
 				return session;
 			}
@@ -300,7 +304,7 @@ struct l2tp_session *l2tp_session_find_nth(struct l2tp_tunnel *tunnel, int nth)
 
 	return NULL;
 }
-EXPORT_SYMBOL_GPL(l2tp_session_find_nth);
+EXPORT_SYMBOL_GPL(l2tp_session_get_nth);
 
 /* Lookup a session by interface name.
  * This is very inefficient but is only used by management interfaces.
diff --git a/net/l2tp/l2tp_core.h b/net/l2tp/l2tp_core.h
index a98c854..54f89f3 100644
--- a/net/l2tp/l2tp_core.h
+++ b/net/l2tp/l2tp_core.h
@@ -236,7 +236,8 @@ out:
 extern struct sock *l2tp_tunnel_sock_lookup(struct l2tp_tunnel *tunnel);
 extern void l2tp_tunnel_sock_put(struct sock *sk);
 extern struct l2tp_session *l2tp_session_find(struct net *net, struct l2tp_tunnel *tunnel, u32 session_id);
-extern struct l2tp_session *l2tp_session_find_nth(struct l2tp_tunnel *tunnel, int nth);
+extern struct l2tp_session *l2tp_session_get_nth(struct l2tp_tunnel *tunnel, int nth,
+						 bool do_ref);
 extern struct l2tp_session *l2tp_session_find_by_ifname(struct net *net, char *ifname);
 extern struct l2tp_tunnel *l2tp_tunnel_find(struct net *net, u32 tunnel_id);
 extern struct l2tp_tunnel *l2tp_tunnel_find_nth(struct net *net, int nth);
diff --git a/net/l2tp/l2tp_debugfs.c b/net/l2tp/l2tp_debugfs.c
index 072d720..c6bd783 100644
--- a/net/l2tp/l2tp_debugfs.c
+++ b/net/l2tp/l2tp_debugfs.c
@@ -53,7 +53,7 @@ static void l2tp_dfs_next_tunnel(struct l2tp_dfs_seq_data *pd)
 
 static void l2tp_dfs_next_session(struct l2tp_dfs_seq_data *pd)
 {
-	pd->session = l2tp_session_find_nth(pd->tunnel, pd->session_idx);
+	pd->session = l2tp_session_get_nth(pd->tunnel, pd->session_idx, true);
 	pd->session_idx++;
 
 	if (pd->session == NULL) {
@@ -237,10 +237,14 @@ static int l2tp_dfs_seq_show(struct seq_file *m, void *v)
 	}
 
 	/* Show the tunnel or session context */
-	if (pd->session == NULL)
+	if (!pd->session) {
 		l2tp_dfs_seq_tunnel_show(m, pd->tunnel);
-	else
+	} else {
 		l2tp_dfs_seq_session_show(m, pd->session);
+		if (pd->session->deref)
+			pd->session->deref(pd->session);
+		l2tp_session_dec_refcount(pd->session);
+	}
 
 out:
 	return 0;
diff --git a/net/l2tp/l2tp_netlink.c b/net/l2tp/l2tp_netlink.c
index 0825ff2..490024e 100644
--- a/net/l2tp/l2tp_netlink.c
+++ b/net/l2tp/l2tp_netlink.c
@@ -719,7 +719,7 @@ static int l2tp_nl_cmd_session_dump(struct sk_buff *skb, struct netlink_callback
 				goto out;
 		}
 
-		session = l2tp_session_find_nth(tunnel, si);
+		session = l2tp_session_get_nth(tunnel, si, false);
 		if (session == NULL) {
 			ti++;
 			tunnel = NULL;
@@ -729,8 +729,11 @@ static int l2tp_nl_cmd_session_dump(struct sk_buff *skb, struct netlink_callback
 
 		if (l2tp_nl_session_send(skb, NETLINK_CB(cb->skb).portid,
 					 cb->nlh->nlmsg_seq, NLM_F_MULTI,
-					 session) <= 0)
+					 session) <= 0) {
+			l2tp_session_dec_refcount(session);
 			break;
+		}
+		l2tp_session_dec_refcount(session);
 
 		si++;
 	}
diff --git a/net/l2tp/l2tp_ppp.c b/net/l2tp/l2tp_ppp.c
index c3ae241..c06c7ed 100644
--- a/net/l2tp/l2tp_ppp.c
+++ b/net/l2tp/l2tp_ppp.c
@@ -1576,7 +1576,7 @@ static void pppol2tp_next_tunnel(struct net *net, struct pppol2tp_seq_data *pd)
 
 static void pppol2tp_next_session(struct net *net, struct pppol2tp_seq_data *pd)
 {
-	pd->session = l2tp_session_find_nth(pd->tunnel, pd->session_idx);
+	pd->session = l2tp_session_get_nth(pd->tunnel, pd->session_idx, true);
 	pd->session_idx++;
 
 	if (pd->session == NULL) {
@@ -1703,10 +1703,14 @@ static int pppol2tp_seq_show(struct seq_file *m, void *v)
 
 	/* Show the tunnel or session context.
 	 */
-	if (pd->session == NULL)
+	if (!pd->session) {
 		pppol2tp_seq_tunnel_show(m, pd->tunnel);
-	else
+	} else {
 		pppol2tp_seq_session_show(m, pd->session);
+		if (pd->session->deref)
+			pd->session->deref(pd->session);
+		l2tp_session_dec_refcount(pd->session);
+	}
 
 out:
 	return 0;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660521 — [PATCH 3.10 015/250] KEYS: Change the name of the dead type to ".dead" to prevent user access

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 015/250] KEYS: Change the name of the dead type to ".dead" to prevent user access
Message-ID<tPT1M-4Xs-27@gated-at.bofh.it>
In reply to#1660349
From: David Howells <dhowells@redhat.com>

commit c1644fe041ebaf6519f6809146a77c3ead9193af upstream.

This fixes CVE-2017-6951.

Userspace should not be able to do things with the "dead" key type as it
doesn't have some of the helper functions set upon it that the kernel
needs.  Attempting to use it may cause the kernel to crash.

Fix this by changing the name of the type to ".dead" so that it's rejected
up front on userspace syscalls by key_get_type_from_user().

Though this doesn't seem to affect recent kernels, it does affect older
ones, certainly those prior to:

	commit c06cfb08b88dfbe13be44a69ae2fdc3a7c902d81
	Author: David Howells <dhowells@redhat.com>
	Date:   Tue Sep 16 17:36:06 2014 +0100
	KEYS: Remove key_type::match in favour of overriding default by match_preparse

which went in before 3.18-rc1.

Signed-off-by: David Howells <dhowells@redhat.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 security/keys/gc.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/security/keys/gc.c b/security/keys/gc.c
index de34c29..2e01e23 100644
--- a/security/keys/gc.c
+++ b/security/keys/gc.c
@@ -46,7 +46,7 @@ static unsigned long key_gc_flags;
  * immediately unlinked.
  */
 struct key_type key_type_dead = {
-	.name = "dead",
+	.name = ".dead",
 };
 
 /*
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660522 — [PATCH 3.10 198/250] i2c: at91: manage unexpected RXRDY flag when starting a transfer

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 198/250] i2c: at91: manage unexpected RXRDY flag when starting a transfer
Message-ID<tPT1M-4Xs-35@gated-at.bofh.it>
In reply to#1660349
From: Ludovic Desroches <ludovic.desroches@atmel.com>

commit a9bed6b10bd117a300cceb9062003f7a2761ef99 upstream.

In some cases, we could start a new i2c transfer with the RXRDY flag
set. It is not a clean state and it leads to print annoying error
messages even if there no real issue. The cause is only having garbage
data in the Receive Holding Register because of a weird behavior of the
RXRDY flag.

Reported-by: Peter Rosin <peda@lysator.liu.se>
Signed-off-by: Ludovic Desroches <ludovic.desroches@atmel.com>
Tested-by: Peter Rosin <peda@lysator.liu.se>
Signed-off-by: Wolfram Sang <wsa@the-dreams.de>
Fixes: 93563a6a71bb ("i2c: at91: fix a race condition when using the DMA controller")
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/i2c/busses/i2c-at91.c | 36 ++++++++++++++++++++++++++----------
 1 file changed, 26 insertions(+), 10 deletions(-)

diff --git a/drivers/i2c/busses/i2c-at91.c b/drivers/i2c/busses/i2c-at91.c
index c880d13..f079877 100644
--- a/drivers/i2c/busses/i2c-at91.c
+++ b/drivers/i2c/busses/i2c-at91.c
@@ -273,8 +273,14 @@ error:
 
 static void at91_twi_read_next_byte(struct at91_twi_dev *dev)
 {
-	if (dev->buf_len <= 0)
+	/*
+	 * If we are in this case, it means there is garbage data in RHR, so
+	 * delete them.
+	 */
+	if (!dev->buf_len) {
+		at91_twi_read(dev, AT91_TWI_RHR);
 		return;
+	}
 
 	*dev->buf = at91_twi_read(dev, AT91_TWI_RHR) & 0xff;
 	--dev->buf_len;
@@ -371,6 +377,24 @@ static irqreturn_t atmel_twi_interrupt(int irq, void *dev_id)
 
 	if (!irqstatus)
 		return IRQ_NONE;
+	/*
+	 * In reception, the behavior of the twi device (before sama5d2) is
+	 * weird. There is some magic about RXRDY flag! When a data has been
+	 * almost received, the reception of a new one is anticipated if there
+	 * is no stop command to send. That is the reason why ask for sending
+	 * the stop command not on the last data but on the second last one.
+	 *
+	 * Unfortunately, we could still have the RXRDY flag set even if the
+	 * transfer is done and we have read the last data. It might happen
+	 * when the i2c slave device sends too quickly data after receiving the
+	 * ack from the master. The data has been almost received before having
+	 * the order to send stop. In this case, sending the stop command could
+	 * cause a RXRDY interrupt with a TXCOMP one. It is better to manage
+	 * the RXRDY interrupt first in order to not keep garbage data in the
+	 * Receive Holding Register for the next transfer.
+	 */
+	if (irqstatus & AT91_TWI_RXRDY)
+		at91_twi_read_next_byte(dev);
 
 	/*
 	 * When a NACK condition is detected, the I2C controller sets the NACK,
@@ -413,8 +437,6 @@ static irqreturn_t atmel_twi_interrupt(int irq, void *dev_id)
 	if (irqstatus & (AT91_TWI_TXCOMP | AT91_TWI_NACK)) {
 		at91_disable_twi_interrupts(dev);
 		complete(&dev->cmd_complete);
-	} else if (irqstatus & AT91_TWI_RXRDY) {
-		at91_twi_read_next_byte(dev);
 	} else if (irqstatus & AT91_TWI_TXRDY) {
 		at91_twi_write_next_byte(dev);
 	}
@@ -429,7 +451,6 @@ static int at91_do_twi_transfer(struct at91_twi_dev *dev)
 {
 	int ret;
 	bool has_unre_flag = dev->pdata->has_unre_flag;
-	unsigned sr;
 
 	/*
 	 * WARNING: the TXCOMP bit in the Status Register is NOT a clear on
@@ -466,7 +487,7 @@ static int at91_do_twi_transfer(struct at91_twi_dev *dev)
 	dev->transfer_status = 0;
 
 	/* Clear pending interrupts, such as NACK. */
-	sr = at91_twi_read(dev, AT91_TWI_SR);
+	at91_twi_read(dev, AT91_TWI_SR);
 
 	if (!dev->buf_len) {
 		at91_twi_write(dev, AT91_TWI_CR, AT91_TWI_QUICK);
@@ -474,11 +495,6 @@ static int at91_do_twi_transfer(struct at91_twi_dev *dev)
 	} else if (dev->msg->flags & I2C_M_RD) {
 		unsigned start_flags = AT91_TWI_START;
 
-		if (sr & AT91_TWI_RXRDY) {
-			dev_err(dev->dev, "RXRDY still set!");
-			at91_twi_read(dev, AT91_TWI_RHR);
-		}
-
 		/* if only one byte is to be read, immediately stop transfer */
 		if (dev->buf_len <= 1 && !(dev->msg->flags & I2C_M_RECV_LEN))
 			start_flags |= AT91_TWI_STOP;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660523 — [PATCH 3.10 021/250] Btrfs: fix tree search logic when replaying directory entry deletes

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 021/250] Btrfs: fix tree search logic when replaying directory entry deletes
Message-ID<tPT1M-4Xs-37@gated-at.bofh.it>
In reply to#1660349
From: Robbie Ko <robbieko@synology.com>

commit 2a7bf53f577e49c43de4ffa7776056de26db65d9 upstream.

If a log tree has a layout like the following:

leaf N:
        ...
        item 240 key (282 DIR_LOG_ITEM 0) itemoff 8189 itemsize 8
                dir log end 1275809046
leaf N + 1:
        item 0 key (282 DIR_LOG_ITEM 3936149215) itemoff 16275 itemsize 8
                dir log end 18446744073709551615
        ...

When we pass the value 1275809046 + 1 as the parameter start_ret to the
function tree-log.c:find_dir_range() (done by replay_dir_deletes()), we
end up with path->slots[0] having the value 239 (points to the last item
of leaf N, item 240). Because the dir log item in that position has an
offset value smaller than *start_ret (1275809046 + 1) we need to move on
to the next leaf, however the logic for that is wrong since it compares
the current slot to the number of items in the leaf, which is smaller
and therefore we don't lookup for the next leaf but instead we set the
slot to point to an item that does not exist, at slot 240, and we later
operate on that slot which has unexpected content or in the worst case
can result in an invalid memory access (accessing beyond the last page
of leaf N's extent buffer).

So fix the logic that checks when we need to lookup at the next leaf
by first incrementing the slot and only after to check if that slot
is beyond the last item of the current leaf.

Signed-off-by: Robbie Ko <robbieko@synology.com>
Reviewed-by: Filipe Manana <fdmanana@suse.com>
Fixes: e02119d5a7b4 (Btrfs: Add a write ahead tree log to optimize synchronous operations)
Signed-off-by: Filipe Manana <fdmanana@suse.com>
[Modified changelog for clarity and correctness]
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/btrfs/tree-log.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/fs/btrfs/tree-log.c b/fs/btrfs/tree-log.c
index 7d3331c..681782d 100644
--- a/fs/btrfs/tree-log.c
+++ b/fs/btrfs/tree-log.c
@@ -1691,12 +1691,11 @@ static noinline int find_dir_range(struct btrfs_root *root,
 next:
 	/* check the next slot in the tree to see if it is a valid item */
 	nritems = btrfs_header_nritems(path->nodes[0]);
+	path->slots[0]++;
 	if (path->slots[0] >= nritems) {
 		ret = btrfs_next_leaf(root, path);
 		if (ret)
 			goto out;
-	} else {
-		path->slots[0]++;
 	}
 
 	btrfs_item_key_to_cpu(path->nodes[0], &key, path->slots[0]);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660524 — [PATCH 3.10 034/250] ftrace/x86_32: Set ftrace_stub to weak to prevent gcc from using short jumps to it

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 034/250] ftrace/x86_32: Set ftrace_stub to weak to prevent gcc from using short jumps to it
Message-ID<tPT1M-4Xs-41@gated-at.bofh.it>
In reply to#1660349
From: "Steven Rostedt (Red Hat)" <rostedt@goodmis.org>

commit 847fa1a6d3d00f3bdf68ef5fa4a786f644a0dd67 upstream.

With new binutils, gcc may get smart with its optimization and change a jmp
from a 5 byte jump to a 2 byte one even though it was jumping to a global
function. But that global function existed within a 2 byte radius, and gcc
was able to optimize it. Unfortunately, that jump was also being modified
when function graph tracing begins. Since ftrace expected that jump to be 5
bytes, but it was only two, it overwrote code after the jump, causing a
crash.

This was fixed for x86_64 with commit 8329e818f149, with the same subject as
this commit, but nothing was done for x86_32.

Fixes: d61f82d06672 ("ftrace: use dynamic patching for updating mcount calls")
Reported-by: Colin Ian King <colin.king@canonical.com>
Tested-by: Colin Ian King <colin.king@canonical.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 arch/x86/kernel/entry_32.S | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/x86/kernel/entry_32.S b/arch/x86/kernel/entry_32.S
index 5c38e2b..c502340 100644
--- a/arch/x86/kernel/entry_32.S
+++ b/arch/x86/kernel/entry_32.S
@@ -1103,8 +1103,8 @@ ftrace_graph_call:
 	jmp ftrace_stub
 #endif
 
-.globl ftrace_stub
-ftrace_stub:
+/* This is weak to keep gas from relaxing the jumps */
+WEAK(ftrace_stub)
 	ret
 END(ftrace_caller)
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660525 — [PATCH 3.10 184/250] USB: uss720: fix NULL-deref at probe

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 184/250] USB: uss720: fix NULL-deref at probe
Message-ID<tPT1M-4Xs-43@gated-at.bofh.it>
In reply to#1660349
From: Johan Hovold <johan@kernel.org>

commit f259ca3eed6e4b79ac3d5c5c9fb259fb46e86217 upstream.

Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer or accessing memory beyond the endpoint array should a
malicious device lack the expected endpoints.

Note that the endpoint access that causes the NULL-deref is currently
only used for debugging purposes during probe so the oops only happens
when dynamic debugging is enabled. This means the driver could be
rewritten to continue to accept device with only two endpoints, should
such devices exist.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/misc/uss720.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/usb/misc/uss720.c b/drivers/usb/misc/uss720.c
index e129cf6..20d7e53 100644
--- a/drivers/usb/misc/uss720.c
+++ b/drivers/usb/misc/uss720.c
@@ -709,6 +709,11 @@ static int uss720_probe(struct usb_interface *intf,
 
 	interface = intf->cur_altsetting;
 
+	if (interface->desc.bNumEndpoints < 3) {
+		usb_put_dev(usbdev);
+		return -ENODEV;
+	}
+
 	/*
 	 * Allocate parport interface 
 	 */
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660526 — [PATCH 3.10 005/250] KVM: x86: fix emulation of "MOV SS, null selector"

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 005/250] KVM: x86: fix emulation of "MOV SS, null selector"
Message-ID<tPT1N-4Xs-45@gated-at.bofh.it>
In reply to#1660349
From: Paolo Bonzini <pbonzini@redhat.com>

commit 33ab91103b3415e12457e3104f0e4517ce12d0f3 upstream.

This is CVE-2017-2583.  On Intel this causes a failed vmentry because
SS's type is neither 3 nor 7 (even though the manual says this check is
only done for usable SS, and the dmesg splat says that SS is unusable!).
On AMD it's worse: svm.c is confused and sets CPL to 0 in the vmcb.

The fix fabricates a data segment descriptor when SS is set to a null
selector, so that CPL and SS.DPL are set correctly in the VMCS/vmcb.
Furthermore, only allow setting SS to a NULL selector if SS.RPL < 3;
this in turn ensures CPL < 3 because RPL must be equal to CPL.

Thanks to Andy Lutomirski and Willy Tarreau for help in analyzing
the bug and deciphering the manuals.

[js] backport to 3.12

Reported-by: Xiaohan Zhang <zhangxiaohan1@huawei.com>
Fixes: 79d5b4c3cd809c770d4bf9812635647016c56011
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 arch/x86/kvm/emulate.c | 48 ++++++++++++++++++++++++++++++++++++++----------
 1 file changed, 38 insertions(+), 10 deletions(-)

diff --git a/arch/x86/kvm/emulate.c b/arch/x86/kvm/emulate.c
index ddad189..364f020 100644
--- a/arch/x86/kvm/emulate.c
+++ b/arch/x86/kvm/emulate.c
@@ -1599,7 +1599,6 @@ static int write_segment_descriptor(struct x86_emulate_ctxt *ctxt,
 				    &ctxt->exception);
 }
 
-/* Does not support long mode */
 static int load_segment_descriptor(struct x86_emulate_ctxt *ctxt,
 				   u16 selector, int seg)
 {
@@ -1612,6 +1611,21 @@ static int load_segment_descriptor(struct x86_emulate_ctxt *ctxt,
 	int ret;
 	u16 dummy;
 
+
+	/*
+	 * None of MOV, POP and LSS can load a NULL selector in CPL=3, but
+	 * they can load it at CPL<3 (Intel's manual says only LSS can,
+	 * but it's wrong).
+	 *
+	 * However, the Intel manual says that putting IST=1/DPL=3 in
+	 * an interrupt gate will result in SS=3 (the AMD manual instead
+	 * says it doesn't), so allow SS=3 in __load_segment_descriptor
+	 * and only forbid it here.
+	 */
+	if (seg == VCPU_SREG_SS && selector == 3 &&
+	    ctxt->mode == X86EMUL_MODE_PROT64)
+		return emulate_exception(ctxt, GP_VECTOR, 0, true);
+
 	memset(&seg_desc, 0, sizeof seg_desc);
 
 	if (ctxt->mode == X86EMUL_MODE_REAL) {
@@ -1634,20 +1648,34 @@ static int load_segment_descriptor(struct x86_emulate_ctxt *ctxt,
 	rpl = selector & 3;
 	cpl = ctxt->ops->cpl(ctxt);
 
-	/* NULL selector is not valid for TR, CS and SS (except for long mode) */
-	if ((seg == VCPU_SREG_CS
-	     || (seg == VCPU_SREG_SS
-		 && (ctxt->mode != X86EMUL_MODE_PROT64 || rpl != cpl))
-	     || seg == VCPU_SREG_TR)
-	    && null_selector)
-		goto exception;
-
 	/* TR should be in GDT only */
 	if (seg == VCPU_SREG_TR && (selector & (1 << 2)))
 		goto exception;
 
-	if (null_selector) /* for NULL selector skip all following checks */
+	/* NULL selector is not valid for TR, CS and (except for long mode) SS */
+	if (null_selector) {
+		if (seg == VCPU_SREG_CS || seg == VCPU_SREG_TR)
+			goto exception;
+
+		if (seg == VCPU_SREG_SS) {
+			if (ctxt->mode != X86EMUL_MODE_PROT64 || rpl != cpl)
+				goto exception;
+
+			/*
+			 * ctxt->ops->set_segment expects the CPL to be in
+			 * SS.DPL, so fake an expand-up 32-bit data segment.
+			 */
+			seg_desc.type = 3;
+			seg_desc.p = 1;
+			seg_desc.s = 1;
+			seg_desc.dpl = cpl;
+			seg_desc.d = 1;
+			seg_desc.g = 1;
+		}
+
+		/* Skip all following checks */
 		goto load;
+	}
 
 	ret = read_segment_descriptor(ctxt, selector, &seg_desc, &desc_addr);
 	if (ret != X86EMUL_CONTINUE)
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660527 — [PATCH 3.10 151/250] fuse: add missing FR_FORCE

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 151/250] fuse: add missing FR_FORCE
Message-ID<tPT1N-4Xs-51@gated-at.bofh.it>
In reply to#1660349
From: Miklos Szeredi <mszeredi@redhat.com>

commit 2e38bea99a80eab408adee27f873a188d57b76cb upstream.

fuse_file_put() was missing the "force" flag for the RELEASE request when
sending synchronously (fuseblk).

If this flag is not set, then a sync request may be interrupted before it
is dequeued by the userspace filesystem.  In this case the OPEN won't be
balanced with a RELEASE.

[js] force is a variable, not a bit

Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Fixes: 5a18ec176c93 ("fuse: fix hang of single threaded fuseblk filesystem")
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/fuse/file.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/fs/fuse/file.c b/fs/fuse/file.c
index 7ada0f0..1dce930 100644
--- a/fs/fuse/file.c
+++ b/fs/fuse/file.c
@@ -128,6 +128,7 @@ static void fuse_file_put(struct fuse_file *ff, bool sync)
 		struct fuse_req *req = ff->reserved_req;
 
 		if (sync) {
+			req->force = 1;
 			req->background = 0;
 			fuse_request_send(ff->fc, req);
 			path_put(&req->misc.release.path);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1660528 — [PATCH 3.10 154/250] s390/qdio: clear DSCI prior to scanning multiple input queues

FromWilly Tarreau <w@1wt.eu>
Date2017-06-08 02:00 +0200
Subject[PATCH 3.10 154/250] s390/qdio: clear DSCI prior to scanning multiple input queues
Message-ID<tPT1N-4Xs-49@gated-at.bofh.it>
In reply to#1660349
From: Julian Wiedmann <jwi@linux.vnet.ibm.com>

commit 1e4a382fdc0ba8d1a85b758c0811de3a3631085e upstream.

For devices with multiple input queues, tiqdio_call_inq_handlers()
iterates over all input queues and clears the device's DSCI
during each iteration. If the DSCI is re-armed during one
of the later iterations, we therefore do not scan the previous
queues again.
The re-arming also raises a new adapter interrupt. But its
handler does not trigger a rescan for the device, as the DSCI
has already been erroneously cleared.
This can result in queue stalls on devices with multiple
input queues.

Fix it by clearing the DSCI just once, prior to scanning the queues.

As the code is moved in front of the loop, we also need to access
the DSCI directly (ie irq->dsci) instead of going via each queue's
parent pointer to the same irq. This is not a functional change,
and a follow-up patch will clean up the other users.

In practice, this bug only affects CQ-enabled HiperSockets devices,
ie. devices with sysfs-attribute "hsuid" set. Setting a hsuid is
needed for AF_IUCV socket applications that use HiperSockets
communication.

Fixes: 104ea556ee7f ("qdio: support asynchronous delivery of storage blocks")
Reviewed-by: Ursula Braun <ubraun@linux.vnet.ibm.com>
Signed-off-by: Julian Wiedmann <jwi@linux.vnet.ibm.com>
Signed-off-by: Martin Schwidefsky <schwidefsky@de.ibm.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/s390/cio/qdio_thinint.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/s390/cio/qdio_thinint.c b/drivers/s390/cio/qdio_thinint.c
index bde5255..1d1e585 100644
--- a/drivers/s390/cio/qdio_thinint.c
+++ b/drivers/s390/cio/qdio_thinint.c
@@ -142,11 +142,11 @@ static inline void tiqdio_call_inq_handlers(struct qdio_irq *irq)
 	struct qdio_q *q;
 	int i;
 
-	for_each_input_queue(irq, q, i) {
-		if (!references_shared_dsci(irq) &&
-		    has_multiple_inq_on_dsci(irq))
-			xchg(q->irq_ptr->dsci, 0);
+	if (!references_shared_dsci(irq) &&
+	    has_multiple_inq_on_dsci(irq))
+		xchg(irq->dsci, 0);
 
+	for_each_input_queue(irq, q, i) {
 		if (q->u.in.queue_start_poll) {
 			/* skip if polling is enabled or already in work */
 			if (test_and_set_bit(QDIO_QUEUE_IRQS_DISABLED,
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


Page 7 of 11 — ← Prev page 1 … 5 6 [7] 8 9 … 11  Next page →

Back to top | Article view | linux.kernel


csiph-web