Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1664124 > unrolled thread

[PATCH 4.11 000/150] 4.11.5-stable review

Started byGreg Kroah-Hartman <gregkh@linuxfoundation.org>
First post2017-06-12 19:40 +0200
Last post2017-06-13 09:30 +0200
Articles 13 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 4.11 000/150] 4.11.5-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-12 19:40 +0200
    [PATCH 4.11 029/150] sparc64: delete old wrap code Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-12 19:40 +0200
    [PATCH 4.11 027/150] sparc64: add per-cpu mm of secondary contexts Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-12 19:40 +0200
    [PATCH 4.11 009/150] ip6_tunnel: fix traffic class routing for tunnels Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-12 19:40 +0200
    [PATCH 4.11 030/150] arch/sparc: support NR_CPUS = 4096 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-12 19:40 +0200
    [PATCH 4.11 016/150] ravb: Fix use-after-free on `ifconfig eth0 down` Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-12 19:40 +0200
    [PATCH 4.11 048/150] efi: Dont issue error message when booted under Xen Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-12 19:40 +0200
    [PATCH 4.11 010/150] sock: reset sk_err when the error queue is empty Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-12 19:40 +0200
    [PATCH 4.11 005/150] ipv6: xfrm: Handle errors reported by xfrm6_find_1stfragopt() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-12 19:40 +0200
    Re: [PATCH 4.11 000/150] 4.11.5-stable review Guenter Roeck <linux@roeck-us.net> - 2017-06-13 00:10 +0200
      Re: [PATCH 4.11 000/150] 4.11.5-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-13 09:30 +0200
    Re: [PATCH 4.11 000/150] 4.11.5-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2017-06-13 02:20 +0200
      Re: [PATCH 4.11 000/150] 4.11.5-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-13 09:30 +0200

#1664124 — [PATCH 4.11 000/150] 4.11.5-stable review

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-06-12 19:40 +0200
Subject[PATCH 4.11 000/150] 4.11.5-stable review
Message-ID<tRzrX-3OZ-3@gated-at.bofh.it>
This is the start of the stable review cycle for the 4.11.5 release.
There are 150 patches in this series, all will be posted as a response
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Wed Jun 14 15:24:44 UTC 2017.
Anything received after that time might be too late.

The whole patch series can be found in one patch at:
	kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.11.5-rc1.gz
or in the git tree and branch at:
  git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.11.y
and the diffstat can be found below.

thanks,

greg k-h

-------------
Pseudo-Shortlog of commits:

Greg Kroah-Hartman <gregkh@linuxfoundation.org>
    Linux 4.11.5-rc1

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: nft_set_rbtree: handle element re-addition after deletion

Jani Nikula <jani.nikula@intel.com>
    drm/i915/vbt: split out defaults that are set when there is no VBT

Jani Nikula <jani.nikula@intel.com>
    drm/i915/vbt: don't propagate errors from intel_bios_init()

Paul Moore <paul@paul-moore.com>
    audit: fix the RCU locking for the auditd_connection structure

Thomas Gleixner <tglx@linutronix.de>
    hwmon: (coretemp) Handle frozen hotplug state correctly

Amey Telawane <ameyt@codeaurora.org>
    tracing: Use strlcpy() instead of strcpy() in __trace_find_cmdline()

Chandan Rajendra <chandan@linux.vnet.ibm.com>
    iomap_dio_rw: Prevent reading file data beyond iomap_dio->i_size

Tejun Heo <tj@kernel.org>
    cgroup: mark cgroup_get() with __maybe_unused

Wei Yongjun <weiyongjun1@huawei.com>
    pinctrl: cherryview: Add terminate entry for dmi_system_id tables

Takatoshi Akiyama <takatoshi.akiyama.kj@ps.hitachi-solutions.com>
    serial: sh-sci: Fix panic when serial console and DMA are enabled

Michał Winiarski <michal.winiarski@intel.com>
    drm/i915/skl: Add missing SKL ID

Ville Syrjälä <ville.syrjala@linux.intel.com>
    drm/i915: Fix runtime PM for LPE audio

Julius Werner <jwerner@chromium.org>
    drivers: char: mem: Fix wraparound check to allow mappings up to the end

Sebastian Andrzej Siewior <bigeasy@linutronix.de>
    cpu/hotplug: Drop the device lock on error

Takashi Iwai <tiwai@suse.de>
    ASoC: Fix use-after-free at card unregistration

Takashi Iwai <tiwai@suse.de>
    ALSA: timer: Fix missing queue indices reset at SNDRV_TIMER_IOCTL_SELECT

Takashi Iwai <tiwai@suse.de>
    ALSA: timer: Fix race between read and ioctl

Ben Skeggs <bskeggs@redhat.com>
    drm/nouveau/tmr: fully separate alarm execution/pending lists

Dominik Brodowski <linux@dominikbrodowski.net>
    x86/microcode/intel: Clear patch pointer before jettisoning the initrd

Sinclair Yeh <syeh@vmware.com>
    drm/vmwgfx: Make sure backup_handle is always valid

Vladis Dronov <vdronov@redhat.com>
    drm/vmwgfx: limit the number of mip levels in vmw_gb_surface_define_ioctl()

Dan Carpenter <dan.carpenter@oracle.com>
    drm/vmwgfx: Handle vmalloc() failure in vmw_local_fifo_reserve()

Timur Tabi <timur@codeaurora.org>
    net: qcom/emac: do not use hardware mdio automatic polling

Paolo Bonzini <pbonzini@redhat.com>
    srcu: Allow use of Classic SRCU from both process and interrupt context

Jin Yao <yao.jin@linux.intel.com>
    perf/core: Drop kernel samples even though :u is specified

Andrew Lunn <andrew@lunn.ch>
    Revert "ata: sata_mv: Convert to devm_ioremap_resource()"

Breno Leitao <leitao@debian.org>
    powerpc/kernel: Initialize load_tm on task creation

Breno Leitao <leitao@debian.org>
    powerpc/kernel: Fix FP and vector register restoration

Michael Bringmann <mwb@linux.vnet.ibm.com>
    powerpc/hotplug-mem: Fix missing endian conversion of aa_index

Michael Ellerman <mpe@ellerman.id.au>
    powerpc/numa: Fix percpu allocations to be NUMA aware

Christophe Leroy <christophe.leroy@c-s.fr>
    powerpc/sysdev/simple_gpio: Fix oops in gpio save_regs function

Joe Carnuccio <joe.carnuccio@qlogic.com>
    scsi: qla2xxx: Fix mailbox pointer error in fwdump capture

Joe Carnuccio <joe.carnuccio@cavium.com>
    scsi: qla2xxx: Set bit 15 for DIAG_ECHO_TEST MBC

Joe Carnuccio <joe.carnuccio@cavium.com>
    scsi: qla2xxx: Modify T262 FW dump template to specify same start/end to debug customer issues

Quinn Tran <quinn.tran@cavium.com>
    scsi: qla2xxx: Fix NULL pointer access due to redundant fc_host_port_name call

Sawan Chandak <sawan.chandak@cavium.com>
    scsi: qla2xxx: Fix crash due to mismatch mumber of Q-pair creation for Multi queue

himanshu.madhani@cavium.com <himanshu.madhani@cavium.com>
    scsi: qla2xxx: Fix recursive loop during target mode configuration for ISP25XX leaving system unresponsive

Johannes Thumshirn <jthumshirn@suse.de>
    scsi: qla2xxx: don't disable a not previously enabled PCI device

Marc Zyngier <marc.zyngier@arm.com>
    KVM: arm/arm64: Handle possible NULL stage2 pud when ageing pages

Omar Sandoval <osandov@fb.com>
    Btrfs: fix delalloc accounting leak caused by u32 overflow

Jeff Mahoney <jeffm@suse.com>
    btrfs: fix race with relocation recovery and fs_root setup

Jeff Mahoney <jeffm@suse.com>
    btrfs: fix memory leak in update_space_info failure path

David Sterba <dsterba@suse.com>
    btrfs: use correct types for page indices in btrfs_page_exists_in_range

Vaibhav Jain <vaibhav@linux.vnet.ibm.com>
    cxl: Avoid double free_irq() for psl,slice interrupts

Frederic Barrat <fbarrat@linux.vnet.ibm.com>
    cxl: Fix error path on bad ioctl

Al Viro <viro@zeniv.linux.org.uk>
    excessive checks in ufs_write_failed() and ufs_evict_inode()

Al Viro <viro@zeniv.linux.org.uk>
    ufs_getfrag_block(): we only grab ->truncate_mutex on block creation path

Al Viro <viro@zeniv.linux.org.uk>
    ufs_extend_tail(): fix the braino in calling conventions of ufs_new_fragments()

Al Viro <viro@zeniv.linux.org.uk>
    ufs: set correct ->s_maxsize

Al Viro <viro@zeniv.linux.org.uk>
    ufs: restore maintaining ->i_blocks

Al Viro <viro@zeniv.linux.org.uk>
    fix ufs_isblockset()

Al Viro <viro@zeniv.linux.org.uk>
    ufs: restore proper tail allocation

Tejun Heo <tj@kernel.org>
    cpuset: consider dying css as offline

Ulrik De Bie <ulrik.debie-os@e2big.org>
    Input: elantech - add Fujitsu Lifebook E546/E557 to force crc_enabled

Waiman Long <longman@redhat.com>
    cgroup: Prevent kill_css() from being called more than once

Sean Young <sean@mess.org>
    rc-core: race condition during ir_raw_event_register()

Sui Chen <suichen6@gmail.com>
    ahci: Acer SA5-271 SSD Not Detected Fix

Rob Clark <robdclark@gmail.com>
    drm/msm/mdp5: use __drm_atomic_helper_plane_duplicate_state()

Eric Anholt <eric@anholt.net>
    drm/msm: Expose our reservation object when exporting a dmabuf.

Nicholas Bellinger <nab@linux-iscsi.org>
    target: Re-add check to reject control WRITEs with overflow data

David Arcari <darcari@redhat.com>
    cpufreq: cpufreq_register_driver() should return -ENODEV if init fails

Jason A. Donenfeld <Jason@zx2c4.com>
    random: invalidate batched entropy after crng init

Pratyush Anand <panand@redhat.com>
    mei: make sysfs modalias format similar as uevent modalias

Bart Van Assche <bart.vanassche@sandisk.com>
    block: Avoid that blk_exit_rl() triggers a use-after-free

Matt Ranostay <matt.ranostay@konsulko.com>
    iio: proximity: as3935: fix iio_trigger_poll issue

Matt Ranostay <matt.ranostay@konsulko.com>
    iio: proximity: as3935: fix AS3935_INT mask

Marcin Niestroj <m.niestroj@grinn-global.com>
    iio: trigger: fix NULL pointer dereference in iio_trigger_write_current()

Franziska Naepelt <franziska.naepelt@idt.com>
    iio: light: ltr501 Fix interchanged als/ps register field

Raveendra Padasalagi <raveendra.padasalagi@broadcom.com>
    iio: adc: bcm_iproc_adc: swap primary and secondary isr handler's

Oleg Drokin <green@linuxhacker.ru>
    staging/lustre/lov: remove set_fs() call from lov_getstripe()

Michael Thalmeier <michael.thalmeier@hale.at>
    usb: chipidea: debug: check before accessing ci_role

Jisheng Zhang <jszhang@marvell.com>
    usb: chipidea: udc: fix NULL pointer dereference if udc_start failed

Andrey Smirnov <andrew.smirnov@gmail.com>
    usb: chipidea: imx: Do not access CLKONOFF on i.MX51

Bin Liu <b-liu@ti.com>
    usb: musb: dsps: keep VBUS on for host-only mode

Thinh Nguyen <Thinh.Nguyen@synopsys.com>
    usb: gadget: f_mass_storage: Serialize wake and sleep execution

Hans de Goede <hdegoede@redhat.com>
    drm: Fix oops + Xserver hang when unplugging USB drm devices

Jan Kara <jack@suse.cz>
    ext4: fix fdatasync(2) after extent manipulation operations

Jan Kara <jack@suse.cz>
    ext4: fix data corruption with EXT4_GET_BLOCKS_ZERO

Konstantin Khlebnikov <khlebnikov@yandex-team.ru>
    ext4: keep existing extra fields when inode expands

Jan Kara <jack@suse.cz>
    ext4: fix SEEK_HOLE

Julien Grall <julien.grall@arm.com>
    xen/privcmd: Support correctly 64KB page granularity when mapping memory

Marc Gonzalez <marc_gonzalez@sigmadesigns.com>
    mtd: nand: tango: Update ecc_stats.corrected

Andres Galacho <andresgalacho@gmail.com>
    mtd: nand: tango: Export OF device ID table as module aliases

Jan Kara <jack@suse.cz>
    reiserfs: Make flush bios explicitely sync

Hou Tao <houtao1@huawei.com>
    cfq-iosched: fix the delay of cfq_group's vdisktime under iops mode

Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
    dmaengine: mv_xor_v2: set DMA mask to 40 bits

Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
    dmaengine: mv_xor_v2: remove interrupt coalescing

Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
    dmaengine: mv_xor_v2: fix tx_submit() implementation

Hanna Hawa <hannah@marvell.com>
    dmaengine: mv_xor_v2: enable XOR engine after its configuration

Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
    dmaengine: mv_xor_v2: do not use descriptors not acked by async_tx

Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
    dmaengine: mv_xor_v2: properly handle wrapping in the array of HW descriptors

Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
    dmaengine: mv_xor_v2: handle mv_xor_v2_prep_sw_desc() error properly

Alexander Sverdlin <alexander.sverdlin@gmail.com>
    dmaengine: ep93xx: Don't drain the transfers in terminate_all()

Alexander Sverdlin <alexander.sverdlin@gmail.com>
    dmaengine: ep93xx: Always start from BASE0

Hiroyuki Yokoyama <hiroyuki.yokoyama.vx@renesas.com>
    dmaengine: usb-dmac: Fix DMAOR AE bit definition

Wanpeng Li <wanpeng.li@hotmail.com>
    KVM: async_pf: avoid async pf injection when in guest mode

Marc Zyngier <marc.zyngier@arm.com>
    arm: KVM: Allow unaligned accesses at HYP

Marc Zyngier <marc.zyngier@arm.com>
    arm64: KVM: Allow unaligned accesses at EL2

Marc Zyngier <marc.zyngier@arm.com>
    arm64: KVM: Preserve RES1 bits in SCTLR_EL2

Wanpeng Li <wanpeng.li@hotmail.com>
    KVM: cpuid: Fix read/write out-of-bounds vulnerability in cpuid emulation

Paolo Bonzini <pbonzini@redhat.com>
    kvm: async_pf: fix rcu_irq_enter() with irqs enabled

Dave Young <dyoung@redhat.com>
    efi/bgrt: Skip efi_bgrt_init() in case of non-EFI boot

Juergen Gross <jgross@suse.com>
    efi: Don't issue error message when booted under Xen

Jan Kara <jack@suse.cz>
    gfs2: Make flush bios explicitely sync

J. Bruce Fields <bfields@redhat.com>
    nfsd4: fix null dereference on replay

Alex Deucher <alexander.deucher@amd.com>
    drm/amdgpu/ci: disable mclk switching for high refresh rates (v2)

Vegard Nossum <vegard.nossum@oracle.com>
    kthread: Fix use-after-free if kthread fork fails

Amir Goldstein <amir73il@gmail.com>
    ovl: fix creds leak in copy up error path

Gilad Ben-Yossef <gilad@benyossef.com>
    crypto: gcm - wait for crypto op not signal safe

Gilad Ben-Yossef <gilad@benyossef.com>
    crypto: drbg - wait for crypto op not signal safe

Eric Biggers <ebiggers@google.com>
    KEYS: encrypted: avoid encrypting/decrypting stack buffers

Eric Biggers <ebiggers@google.com>
    KEYS: fix freeing uninitialized memory in key_update()

Eric Biggers <ebiggers@google.com>
    KEYS: fix dereferencing NULL payload with nonzero length

Gilad Ben-Yossef <gilad@benyossef.com>
    crypto: asymmetric_keys - handle EBUSY due to backlog correctly

Murali Karicheri <m-karicheri2@ti.com>
    ARM: dts: keystone-k2l: fix broken Ethernet due to disabled OSR

Eric W. Biederman <ebiederm@xmission.com>
    ptrace: Properly initialize ptracer_cred on fork

Lucas Stach <l.stach@pengutronix.de>
    serial: core: fix crash in uart_suspend_port

Johan Hovold <johan@kernel.org>
    serial: ifx6x60: fix use-after-free on module unload

Jan Kiszka <jan.kiszka@siemens.com>
    serial: exar: Fix stuck MSIs

Luis Henriques <lhenriques@suse.com>
    ftrace: Fix memory leak in ftrace_graph_release()

Jane Chu <jane.chu@oracle.com>
    arch/sparc: support NR_CPUS = 4096

Pavel Tatashin <pasha.tatashin@oracle.com>
    sparc64: delete old wrap code

Pavel Tatashin <pasha.tatashin@oracle.com>
    sparc64: new context wrap

Pavel Tatashin <pasha.tatashin@oracle.com>
    sparc64: add per-cpu mm of secondary contexts

Pavel Tatashin <pasha.tatashin@oracle.com>
    sparc64: redefine first version

Pavel Tatashin <pasha.tatashin@oracle.com>
    sparc64: combine activate_mm and switch_mm

Pavel Tatashin <pasha.tatashin@oracle.com>
    sparc64: reset mm cpumask after wrap

Liam R. Howlett <Liam.Howlett@Oracle.com>
    sparc/mm/hugepages: Fix setup_hugepagesz for invalid values.

James Clarke <jrtc27@jrtc27.com>
    sparc: Machine description indices can vary

Mike Kravetz <mike.kravetz@oracle.com>
    sparc64: mm: fix copy_tsb to correctly copy huge page TSBs

David S. Miller <davem@davemloft.net>
    sparc64: Add __multi3 for gcc 7.x and later.

Niklas Cassel <niklas.cassel@axis.com>
    net: stmmac: fix completely hung TX when using TSO

Max Filippov <jcmvbkbc@gmail.com>
    net: ethoc: enable NAPI before poll may be scheduled

Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
    net: bridge: fix a null pointer dereference in br_afspec

Eugeniu Rosca <erosca@de.adit-jv.com>
    ravb: Fix use-after-free on `ifconfig eth0 down`

Richard Haines <richard_c_haines@btinternet.com>
    net/ipv6: Fix CALIPSO causing GPF with datagram support

Eric Dumazet <edumazet@google.com>
    net: ping: do not abuse udp_poll()

Florian Fainelli <f.fainelli@gmail.com>
    net: dsa: Fix stale cpu_switch reference after unbind then bind

David S. Miller <davem@davemloft.net>
    ipv6: Fix leak in ipv6_gso_segment().

Eric Garver <e@erig.me>
    geneve: fix needed_headroom and max_mtu for collect_metadata

Soheil Hassas Yeganeh <soheil@google.com>
    sock: reset sk_err when the error queue is empty

Liam McBirnie <mcbirnie.l@gmail.com>
    ip6_tunnel: fix traffic class routing for tunnels

Mark Bloch <markb@mellanox.com>
    vxlan: fix use-after-free on deletion

Yuchung Cheng <ycheng@google.com>
    tcp: disallow cwnd undo when switching congestion control

Ganesh Goudar <ganeshgr@chelsio.com>
    cxgb4: avoid enabling napi twice to the same queue

Ben Hutchings <ben@decadent.org.uk>
    ipv6: xfrm: Handle errors reported by xfrm6_find_1stfragopt()

Florian Fainelli <f.fainelli@gmail.com>
    net: systemport: Fix missing Wake-on-LAN interrupt for SYSTEMPORT Lite

Lance Richardson <lrichard@redhat.com>
    vxlan: eliminate cached dst leak

Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
    net: bridge: start hello timer only if device is up

Mintz, Yuval <Yuval.Mintz@cavium.com>
    bnx2x: Fix Multi-Cos


-------------

Diffstat:

 Makefile                                           |   4 +-
 arch/arm/boot/dts/keystone-k2l-netcp.dtsi          |   4 +-
 arch/arm/boot/dts/keystone-k2l.dtsi                |   8 +
 arch/arm/kvm/init.S                                |   5 +-
 arch/arm/kvm/mmu.c                                 |   3 +
 arch/arm64/include/asm/sysreg.h                    |   4 +
 arch/arm64/kvm/hyp-init.S                          |  11 +-
 arch/powerpc/include/asm/topology.h                |  14 ++
 arch/powerpc/kernel/process.c                      |   3 +
 arch/powerpc/kernel/setup_64.c                     |   4 +-
 arch/powerpc/platforms/pseries/hotplug-memory.c    |   2 +
 arch/powerpc/sysdev/simple_gpio.c                  |   3 +-
 arch/sparc/Kconfig                                 |   4 +-
 arch/sparc/include/asm/mmu_64.h                    |   2 +-
 arch/sparc/include/asm/mmu_context_64.h            |  32 +---
 arch/sparc/include/asm/pil.h                       |   1 -
 arch/sparc/include/asm/vio.h                       |   1 +
 arch/sparc/kernel/irq_64.c                         |  17 ++-
 arch/sparc/kernel/kernel.h                         |   1 -
 arch/sparc/kernel/smp_64.c                         |  31 ----
 arch/sparc/kernel/tsb.S                            |  11 +-
 arch/sparc/kernel/ttable_64.S                      |   2 +-
 arch/sparc/kernel/vio.c                            |  68 ++++++++-
 arch/sparc/lib/Makefile                            |   1 +
 arch/sparc/lib/multi3.S                            |  35 +++++
 arch/sparc/mm/init_64.c                            |  89 +++++++----
 arch/sparc/mm/tsb.c                                |   7 +-
 arch/sparc/mm/ultra.S                              |   5 -
 arch/x86/kernel/cpu/microcode/intel.c              |   3 +
 arch/x86/kernel/kvm.c                              |   2 +-
 arch/x86/kvm/cpuid.c                               |  20 +--
 arch/x86/kvm/mmu.c                                 |   7 +-
 arch/x86/kvm/mmu.h                                 |   1 +
 arch/x86/kvm/x86.c                                 |   3 +-
 arch/x86/platform/efi/efi-bgrt.c                   |   3 +
 arch/x86/platform/efi/quirks.c                     |   3 +
 block/blk-cgroup.c                                 |   2 +-
 block/blk-core.c                                   |  10 +-
 block/blk-sysfs.c                                  |   2 +-
 block/blk.h                                        |   2 +-
 block/cfq-iosched.c                                |  17 ++-
 crypto/asymmetric_keys/public_key.c                |   2 +-
 crypto/drbg.c                                      |   5 +-
 crypto/gcm.c                                       |   6 +-
 drivers/ata/ahci.c                                 |  38 +++++
 drivers/ata/sata_mv.c                              |  13 +-
 drivers/char/mem.c                                 |   2 +-
 drivers/char/random.c                              |  37 +++++
 drivers/cpufreq/cpufreq.c                          |   1 +
 drivers/dma/ep93xx_dma.c                           |  39 ++++-
 drivers/dma/mv_xor_v2.c                            | 109 ++++++--------
 drivers/dma/sh/usb-dmac.c                          |   2 +-
 drivers/gpu/drm/amd/amdgpu/ci_dpm.c                |   6 +
 drivers/gpu/drm/drm_drv.c                          |   7 +-
 drivers/gpu/drm/i915/i915_drv.c                    |   4 +-
 drivers/gpu/drm/i915/i915_drv.h                    |   2 +-
 drivers/gpu/drm/i915/intel_bios.c                  |  46 ++++--
 drivers/gpu/drm/i915/intel_lpe_audio.c             |   5 +
 drivers/gpu/drm/msm/mdp/mdp5/mdp5_plane.c          |   5 +-
 drivers/gpu/drm/msm/msm_drv.c                      |   1 +
 drivers/gpu/drm/msm/msm_drv.h                      |   1 +
 drivers/gpu/drm/msm/msm_gem_prime.c                |   7 +
 .../gpu/drm/nouveau/include/nvkm/subdev/timer.h    |   1 +
 drivers/gpu/drm/nouveau/nvkm/subdev/timer/base.c   |   7 +-
 drivers/gpu/drm/vmwgfx/vmwgfx_fifo.c               |   2 +
 drivers/gpu/drm/vmwgfx/vmwgfx_surface.c            |  21 ++-
 drivers/hwmon/coretemp.c                           |  14 ++
 drivers/iio/adc/bcm_iproc_adc.c                    |   8 +-
 drivers/iio/industrialio-trigger.c                 |   3 +-
 drivers/iio/light/ltr501.c                         |   4 +-
 drivers/iio/proximity/as3935.c                     |   8 +-
 drivers/input/mouse/elantech.c                     |  16 ++
 drivers/media/rc/rc-ir-raw.c                       |  13 +-
 drivers/misc/cxl/file.c                            |   7 +-
 drivers/misc/cxl/native.c                          |  14 +-
 drivers/misc/mei/bus.c                             |   4 +-
 drivers/mtd/nand/tango_nand.c                      |  23 ++-
 drivers/net/ethernet/broadcom/bcmsysport.c         |   7 +-
 drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c    |   2 +-
 drivers/net/ethernet/chelsio/cxgb4/cxgb4_main.c    |   4 +
 drivers/net/ethernet/ethoc.c                       |   3 +-
 drivers/net/ethernet/qualcomm/emac/emac-mac.c      |   2 +-
 drivers/net/ethernet/qualcomm/emac/emac-phy.c      |  75 +--------
 drivers/net/ethernet/qualcomm/emac/emac.c          |  22 +--
 drivers/net/ethernet/renesas/ravb_main.c           |  24 +--
 drivers/net/ethernet/stmicro/stmmac/stmmac_main.c  |   2 +-
 drivers/net/geneve.c                               |   2 +-
 drivers/net/vxlan.c                                |  39 +++--
 drivers/pinctrl/intel/pinctrl-cherryview.c         |   3 +-
 drivers/scsi/qla2xxx/qla_bsg.c                     |   9 +-
 drivers/scsi/qla2xxx/qla_dbg.c                     |   4 +-
 drivers/scsi/qla2xxx/qla_def.h                     |   1 +
 drivers/scsi/qla2xxx/qla_init.c                    |   5 +-
 drivers/scsi/qla2xxx/qla_isr.c                     |   2 +-
 drivers/scsi/qla2xxx/qla_mbx.c                     |  13 +-
 drivers/scsi/qla2xxx/qla_os.c                      |   8 +-
 drivers/scsi/qla2xxx/qla_tmpl.c                    |   2 +-
 drivers/staging/lustre/lustre/lov/lov_pack.c       |   9 --
 drivers/target/target_core_transport.c             |  23 ++-
 drivers/tty/serial/8250/8250_port.c                |  19 +--
 drivers/tty/serial/ifx6x60.c                       |   2 +-
 drivers/tty/serial/serial_core.c                   |   2 +-
 drivers/tty/serial/sh-sci.c                        |  10 +-
 drivers/usb/chipidea/debug.c                       |   3 +-
 drivers/usb/chipidea/udc.c                         |   8 +-
 drivers/usb/chipidea/usbmisc_imx.c                 |  41 +++--
 drivers/usb/gadget/function/f_mass_storage.c       |  13 +-
 drivers/usb/musb/musb_dsps.c                       |   5 +
 drivers/xen/privcmd.c                              |   4 +-
 fs/btrfs/ctree.h                                   |   4 +-
 fs/btrfs/extent-tree.c                             |   7 +-
 fs/btrfs/inode.c                                   |   4 +-
 fs/ext4/extents.c                                  |  85 ++++++-----
 fs/ext4/file.c                                     |  50 ++----
 fs/ext4/inode.c                                    |   7 +-
 fs/gfs2/log.c                                      |   2 +-
 fs/iomap.c                                         |   3 +
 fs/nfsd/nfs4proc.c                                 |  13 +-
 fs/overlayfs/copy_up.c                             |  11 +-
 fs/reiserfs/journal.c                              |   4 +-
 fs/stat.c                                          |   1 +
 fs/ufs/balloc.c                                    |  26 +++-
 fs/ufs/inode.c                                     |  27 ++--
 fs/ufs/super.c                                     |  18 +++
 fs/ufs/util.h                                      |  10 +-
 include/drm/i915_pciids.h                          |   3 +-
 include/linux/cgroup-defs.h                        |   1 +
 include/linux/cgroup.h                             |  20 +++
 include/linux/ptrace.h                             |   7 +-
 include/linux/srcu.h                               |   2 -
 include/net/ipv6.h                                 |   1 +
 kernel/audit.c                                     | 167 ++++++++++++++-------
 kernel/cgroup/cgroup.c                             |   7 +-
 kernel/cgroup/cpuset.c                             |   4 +-
 kernel/cpu.c                                       |   4 +-
 kernel/events/core.c                               |  21 +++
 kernel/fork.c                                      |  17 ++-
 kernel/ptrace.c                                    |  20 ++-
 kernel/rcu/srcu.c                                  |   5 +-
 kernel/trace/ftrace.c                              |   2 +-
 kernel/trace/trace.c                               |   2 +-
 net/bridge/br_netlink.c                            |   2 +-
 net/bridge/br_stp_if.c                             |   3 +-
 net/core/skbuff.c                                  |   5 +-
 net/dsa/dsa2.c                                     |   4 +-
 net/ipv4/af_inet.c                                 |   2 +-
 net/ipv4/tcp_cong.c                                |   1 +
 net/ipv6/calipso.c                                 |   6 +-
 net/ipv6/ip6_offload.c                             |   4 +-
 net/ipv6/ip6_tunnel.c                              |   3 +
 net/ipv6/ping.c                                    |   2 +-
 net/ipv6/raw.c                                     |   2 +-
 net/ipv6/xfrm6_mode_ro.c                           |   2 +
 net/ipv6/xfrm6_mode_transport.c                    |   2 +
 net/netfilter/nft_set_rbtree.c                     |  22 +--
 security/keys/encrypted-keys/encrypted.c           |  17 ++-
 security/keys/key.c                                |   5 +-
 security/keys/keyctl.c                             |   4 +-
 sound/core/timer.c                                 |   7 +-
 sound/soc/soc-core.c                               |   5 +-
 sound/x86/intel_hdmi_audio.c                       |   4 -
 161 files changed, 1226 insertions(+), 729 deletions(-)

[toc] | [next] | [standalone]


#1664125 — [PATCH 4.11 029/150] sparc64: delete old wrap code

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-06-12 19:40 +0200
Subject[PATCH 4.11 029/150] sparc64: delete old wrap code
Message-ID<tRBtN-56r-37@gated-at.bofh.it>
In reply to#1664124
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pavel Tatashin <pasha.tatashin@oracle.com>


[ Upstream commit 0197e41ce70511dc3b71f7fefa1a676e2b5cd60b ]

The old method that is using xcall and softint to get new context id is
deleted, as it is replaced by a method of using per_cpu_secondary_mm
without xcall to perform the context wrap.

Signed-off-by: Pavel Tatashin <pasha.tatashin@oracle.com>
Reviewed-by: Bob Picco <bob.picco@oracle.com>
Reviewed-by: Steven Sistare <steven.sistare@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/sparc/include/asm/mmu_context_64.h |    6 ------
 arch/sparc/include/asm/pil.h            |    1 -
 arch/sparc/kernel/kernel.h              |    1 -
 arch/sparc/kernel/smp_64.c              |   31 -------------------------------
 arch/sparc/kernel/ttable_64.S           |    2 +-
 arch/sparc/mm/ultra.S                   |    5 -----
 6 files changed, 1 insertion(+), 45 deletions(-)

--- a/arch/sparc/include/asm/mmu_context_64.h
+++ b/arch/sparc/include/asm/mmu_context_64.h
@@ -21,12 +21,6 @@ extern unsigned long mmu_context_bmap[];
 
 DECLARE_PER_CPU(struct mm_struct *, per_cpu_secondary_mm);
 void get_new_mmu_context(struct mm_struct *mm);
-#ifdef CONFIG_SMP
-void smp_new_mmu_context_version(void);
-#else
-#define smp_new_mmu_context_version() do { } while (0)
-#endif
-
 int init_new_context(struct task_struct *tsk, struct mm_struct *mm);
 void destroy_context(struct mm_struct *mm);
 
--- a/arch/sparc/include/asm/pil.h
+++ b/arch/sparc/include/asm/pil.h
@@ -20,7 +20,6 @@
 #define PIL_SMP_CALL_FUNC	1
 #define PIL_SMP_RECEIVE_SIGNAL	2
 #define PIL_SMP_CAPTURE		3
-#define PIL_SMP_CTX_NEW_VERSION	4
 #define PIL_DEVICE_IRQ		5
 #define PIL_SMP_CALL_FUNC_SNGL	6
 #define PIL_DEFERRED_PCR_WORK	7
--- a/arch/sparc/kernel/kernel.h
+++ b/arch/sparc/kernel/kernel.h
@@ -37,7 +37,6 @@ void handle_stdfmna(struct pt_regs *regs
 /* smp_64.c */
 void __irq_entry smp_call_function_client(int irq, struct pt_regs *regs);
 void __irq_entry smp_call_function_single_client(int irq, struct pt_regs *regs);
-void __irq_entry smp_new_mmu_context_version_client(int irq, struct pt_regs *regs);
 void __irq_entry smp_penguin_jailcell(int irq, struct pt_regs *regs);
 void __irq_entry smp_receive_signal_client(int irq, struct pt_regs *regs);
 
--- a/arch/sparc/kernel/smp_64.c
+++ b/arch/sparc/kernel/smp_64.c
@@ -964,37 +964,6 @@ void flush_dcache_page_all(struct mm_str
 	preempt_enable();
 }
 
-void __irq_entry smp_new_mmu_context_version_client(int irq, struct pt_regs *regs)
-{
-	struct mm_struct *mm;
-	unsigned long flags;
-
-	clear_softint(1 << irq);
-
-	/* See if we need to allocate a new TLB context because
-	 * the version of the one we are using is now out of date.
-	 */
-	mm = current->active_mm;
-	if (unlikely(!mm || (mm == &init_mm)))
-		return;
-
-	spin_lock_irqsave(&mm->context.lock, flags);
-
-	if (unlikely(!CTX_VALID(mm->context)))
-		get_new_mmu_context(mm);
-
-	spin_unlock_irqrestore(&mm->context.lock, flags);
-
-	load_secondary_context(mm);
-	__flush_tlb_mm(CTX_HWBITS(mm->context),
-		       SECONDARY_CONTEXT);
-}
-
-void smp_new_mmu_context_version(void)
-{
-	smp_cross_call(&xcall_new_mmu_context_version, 0, 0, 0);
-}
-
 #ifdef CONFIG_KGDB
 void kgdb_roundup_cpus(unsigned long flags)
 {
--- a/arch/sparc/kernel/ttable_64.S
+++ b/arch/sparc/kernel/ttable_64.S
@@ -50,7 +50,7 @@ tl0_resv03e:	BTRAP(0x3e) BTRAP(0x3f) BTR
 tl0_irq1:	TRAP_IRQ(smp_call_function_client, 1)
 tl0_irq2:	TRAP_IRQ(smp_receive_signal_client, 2)
 tl0_irq3:	TRAP_IRQ(smp_penguin_jailcell, 3)
-tl0_irq4:	TRAP_IRQ(smp_new_mmu_context_version_client, 4)
+tl0_irq4:       BTRAP(0x44)
 #else
 tl0_irq1:	BTRAP(0x41)
 tl0_irq2:	BTRAP(0x42)
--- a/arch/sparc/mm/ultra.S
+++ b/arch/sparc/mm/ultra.S
@@ -971,11 +971,6 @@ xcall_capture:
 	wr		%g0, (1 << PIL_SMP_CAPTURE), %set_softint
 	retry
 
-	.globl		xcall_new_mmu_context_version
-xcall_new_mmu_context_version:
-	wr		%g0, (1 << PIL_SMP_CTX_NEW_VERSION), %set_softint
-	retry
-
 #ifdef CONFIG_KGDB
 	.globl		xcall_kgdb_capture
 xcall_kgdb_capture:

[toc] | [prev] | [next] | [standalone]


#1664127 — [PATCH 4.11 027/150] sparc64: add per-cpu mm of secondary contexts

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-06-12 19:40 +0200
Subject[PATCH 4.11 027/150] sparc64: add per-cpu mm of secondary contexts
Message-ID<tRBtN-56r-41@gated-at.bofh.it>
In reply to#1664124
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pavel Tatashin <pasha.tatashin@oracle.com>


[ Upstream commit 7a5b4bbf49fe86ce77488a70c5dccfe2d50d7a2d ]

The new wrap is going to use information from this array to figure out
mm's that currently have valid secondary contexts setup.

Signed-off-by: Pavel Tatashin <pasha.tatashin@oracle.com>
Reviewed-by: Bob Picco <bob.picco@oracle.com>
Reviewed-by: Steven Sistare <steven.sistare@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/sparc/include/asm/mmu_context_64.h |    5 +++--
 arch/sparc/mm/init_64.c                 |    1 +
 2 files changed, 4 insertions(+), 2 deletions(-)

--- a/arch/sparc/include/asm/mmu_context_64.h
+++ b/arch/sparc/include/asm/mmu_context_64.h
@@ -19,6 +19,7 @@ extern spinlock_t ctx_alloc_lock;
 extern unsigned long tlb_context_cache;
 extern unsigned long mmu_context_bmap[];
 
+DECLARE_PER_CPU(struct mm_struct *, per_cpu_secondary_mm);
 void get_new_mmu_context(struct mm_struct *mm);
 #ifdef CONFIG_SMP
 void smp_new_mmu_context_version(void);
@@ -76,8 +77,9 @@ void __flush_tlb_mm(unsigned long, unsig
 static inline void switch_mm(struct mm_struct *old_mm, struct mm_struct *mm, struct task_struct *tsk)
 {
 	unsigned long ctx_valid, flags;
-	int cpu;
+	int cpu = smp_processor_id();
 
+	per_cpu(per_cpu_secondary_mm, cpu) = mm;
 	if (unlikely(mm == &init_mm))
 		return;
 
@@ -123,7 +125,6 @@ static inline void switch_mm(struct mm_s
 	 * for the first time, we must flush that context out of the
 	 * local TLB.
 	 */
-	cpu = smp_processor_id();
 	if (!ctx_valid || !cpumask_test_cpu(cpu, mm_cpumask(mm))) {
 		cpumask_set_cpu(cpu, mm_cpumask(mm));
 		__flush_tlb_mm(CTX_HWBITS(mm->context),
--- a/arch/sparc/mm/init_64.c
+++ b/arch/sparc/mm/init_64.c
@@ -711,6 +711,7 @@ unsigned long tlb_context_cache = CTX_FI
 #define MAX_CTX_NR	(1UL << CTX_NR_BITS)
 #define CTX_BMAP_SLOTS	BITS_TO_LONGS(MAX_CTX_NR)
 DECLARE_BITMAP(mmu_context_bmap, MAX_CTX_NR);
+DEFINE_PER_CPU(struct mm_struct *, per_cpu_secondary_mm) = {0};
 
 /* Caller does TLB context flushing on local CPU if necessary.
  * The caller also ensures that CTX_VALID(mm->context) is false.

[toc] | [prev] | [next] | [standalone]


#1664128 — [PATCH 4.11 009/150] ip6_tunnel: fix traffic class routing for tunnels

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-06-12 19:40 +0200
Subject[PATCH 4.11 009/150] ip6_tunnel: fix traffic class routing for tunnels
Message-ID<tRBtN-56r-45@gated-at.bofh.it>
In reply to#1664124
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Liam McBirnie <mcbirnie.l@gmail.com>


[ Upstream commit 5f733ee68f9a4df94775299ac6a7ab260704f6ed ]

ip6_route_output() requires that the flowlabel contains the traffic
class for policy routing.

Commit 0e9a709560db ("ip6_tunnel, ip6_gre: fix setting of DSCP on
encapsulated packets") removed the code which previously added the
traffic class to the flowlabel.

The traffic class is added here because only route lookup needs the
flowlabel to contain the traffic class.

Fixes: 0e9a709560db ("ip6_tunnel, ip6_gre: fix setting of DSCP on encapsulated packets")
Signed-off-by: Liam McBirnie <liam.mcbirnie@boeing.com>
Acked-by: Peter Dawson <peter.a.dawson@boeing.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/ipv6/ip6_tunnel.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/net/ipv6/ip6_tunnel.c
+++ b/net/ipv6/ip6_tunnel.c
@@ -1095,6 +1095,9 @@ int ip6_tnl_xmit(struct sk_buff *skb, st
 
 	if (!dst) {
 route_lookup:
+		/* add dsfield to flowlabel for route lookup */
+		fl6->flowlabel = ip6_make_flowinfo(dsfield, fl6->flowlabel);
+
 		dst = ip6_route_output(net, NULL, fl6);
 
 		if (dst->error)

[toc] | [prev] | [next] | [standalone]


#1664129 — [PATCH 4.11 030/150] arch/sparc: support NR_CPUS = 4096

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-06-12 19:40 +0200
Subject[PATCH 4.11 030/150] arch/sparc: support NR_CPUS = 4096
Message-ID<tRBtN-56r-53@gated-at.bofh.it>
In reply to#1664124
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jane Chu <jane.chu@oracle.com>


[ Upstream commit c79a13734d104b5b147d7cb0870276ccdd660dae ]

Linux SPARC64 limits NR_CPUS to 4064 because init_cpu_send_mondo_info()
only allocates a single page for NR_CPUS mondo entries. Thus we cannot
use all 4096 CPUs on some SPARC platforms.

To fix, allocate (2^order) pages where order is set according to the size
of cpu_list for possible cpus. Since cpu_list_pa and cpu_mondo_block_pa
are not used in asm code, there are no imm13 offsets from the base PA
that will break because they can only reach one page.

Orabug: 25505750

Signed-off-by: Jane Chu <jane.chu@oracle.com>

Reviewed-by: Bob Picco <bob.picco@oracle.com>
Reviewed-by: Atish Patra <atish.patra@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/sparc/Kconfig         |    4 ++--
 arch/sparc/kernel/irq_64.c |   17 +++++++++++++----
 2 files changed, 15 insertions(+), 6 deletions(-)

--- a/arch/sparc/Kconfig
+++ b/arch/sparc/Kconfig
@@ -192,9 +192,9 @@ config NR_CPUS
 	int "Maximum number of CPUs"
 	depends on SMP
 	range 2 32 if SPARC32
-	range 2 1024 if SPARC64
+	range 2 4096 if SPARC64
 	default 32 if SPARC32
-	default 64 if SPARC64
+	default 4096 if SPARC64
 
 source kernel/Kconfig.hz
 
--- a/arch/sparc/kernel/irq_64.c
+++ b/arch/sparc/kernel/irq_64.c
@@ -1034,17 +1034,26 @@ static void __init init_cpu_send_mondo_i
 {
 #ifdef CONFIG_SMP
 	unsigned long page;
+	void *mondo, *p;
 
-	BUILD_BUG_ON((NR_CPUS * sizeof(u16)) > (PAGE_SIZE - 64));
+	BUILD_BUG_ON((NR_CPUS * sizeof(u16)) > PAGE_SIZE);
+
+	/* Make sure mondo block is 64byte aligned */
+	p = kzalloc(127, GFP_KERNEL);
+	if (!p) {
+		prom_printf("SUN4V: Error, cannot allocate mondo block.\n");
+		prom_halt();
+	}
+	mondo = (void *)(((unsigned long)p + 63) & ~0x3f);
+	tb->cpu_mondo_block_pa = __pa(mondo);
 
 	page = get_zeroed_page(GFP_KERNEL);
 	if (!page) {
-		prom_printf("SUN4V: Error, cannot allocate cpu mondo page.\n");
+		prom_printf("SUN4V: Error, cannot allocate cpu list page.\n");
 		prom_halt();
 	}
 
-	tb->cpu_mondo_block_pa = __pa(page);
-	tb->cpu_list_pa = __pa(page + 64);
+	tb->cpu_list_pa = __pa(page);
 #endif
 }
 

[toc] | [prev] | [next] | [standalone]


#1664130 — [PATCH 4.11 016/150] ravb: Fix use-after-free on `ifconfig eth0 down`

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-06-12 19:40 +0200
Subject[PATCH 4.11 016/150] ravb: Fix use-after-free on `ifconfig eth0 down`
Message-ID<tRBtN-56r-49@gated-at.bofh.it>
In reply to#1664124
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eugeniu Rosca <erosca@de.adit-jv.com>


[ Upstream commit 79514ef670e9e575a1fe36922268c439d0f0ca8a ]

Commit a47b70ea86bd ("ravb: unmap descriptors when freeing rings") has
introduced the issue seen in [1] reproduced on H3ULCB board.

Fix this by relocating the RX skb ringbuffer free operation, so that
swiotlb page unmapping can be done first. Freeing of aligned TX buffers
is not relevant to the issue seen in [1]. Still, reposition TX free
calls as well, to have all kfree() operations performed consistently
_after_ dma_unmap_*()/dma_free_*().

[1] Console screenshot with the problem reproduced:

salvator-x login: root
root@salvator-x:~# ifconfig eth0 up
Micrel KSZ9031 Gigabit PHY e6800000.ethernet-ffffffff:00: \
       attached PHY driver [Micrel KSZ9031 Gigabit PHY]   \
       (mii_bus:phy_addr=e6800000.ethernet-ffffffff:00, irq=235)
IPv6: ADDRCONF(NETDEV_UP): eth0: link is not ready
root@salvator-x:~#
root@salvator-x:~# ifconfig eth0 down

==================================================================
BUG: KASAN: use-after-free in swiotlb_tbl_unmap_single+0xc4/0x35c
Write of size 1538 at addr ffff8006d884f780 by task ifconfig/1649

CPU: 0 PID: 1649 Comm: ifconfig Not tainted 4.12.0-rc4-00004-g112eb07287d1 #32
Hardware name: Renesas H3ULCB board based on r8a7795 (DT)
Call trace:
[<ffff20000808f11c>] dump_backtrace+0x0/0x3a4
[<ffff20000808f4d4>] show_stack+0x14/0x1c
[<ffff20000865970c>] dump_stack+0xf8/0x150
[<ffff20000831f8b0>] print_address_description+0x7c/0x330
[<ffff200008320010>] kasan_report+0x2e0/0x2f4
[<ffff20000831eac0>] check_memory_region+0x20/0x14c
[<ffff20000831f054>] memcpy+0x48/0x68
[<ffff20000869ed50>] swiotlb_tbl_unmap_single+0xc4/0x35c
[<ffff20000869fcf4>] unmap_single+0x90/0xa4
[<ffff20000869fd14>] swiotlb_unmap_page+0xc/0x14
[<ffff2000080a2974>] __swiotlb_unmap_page+0xcc/0xe4
[<ffff2000088acdb8>] ravb_ring_free+0x514/0x870
[<ffff2000088b25dc>] ravb_close+0x288/0x36c
[<ffff200008aaf8c4>] __dev_close_many+0x14c/0x174
[<ffff200008aaf9b4>] __dev_close+0xc8/0x144
[<ffff200008ac2100>] __dev_change_flags+0xd8/0x194
[<ffff200008ac221c>] dev_change_flags+0x60/0xb0
[<ffff200008ba2dec>] devinet_ioctl+0x484/0x9d4
[<ffff200008ba7b78>] inet_ioctl+0x190/0x194
[<ffff200008a78c44>] sock_do_ioctl+0x78/0xa8
[<ffff200008a7a128>] sock_ioctl+0x110/0x3c4
[<ffff200008365a70>] vfs_ioctl+0x90/0xa0
[<ffff200008365dbc>] do_vfs_ioctl+0x148/0xc38
[<ffff2000083668f0>] SyS_ioctl+0x44/0x74
[<ffff200008083770>] el0_svc_naked+0x24/0x28

The buggy address belongs to the page:
page:ffff7e001b6213c0 count:0 mapcount:0 mapping:          (null) index:0x0
flags: 0x4000000000000000()
raw: 4000000000000000 0000000000000000 0000000000000000 00000000ffffffff
raw: 0000000000000000 ffff7e001b6213e0 0000000000000000 0000000000000000
page dumped because: kasan: bad access detected

Memory state around the buggy address:
 ffff8006d884f680: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
 ffff8006d884f700: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
>ffff8006d884f780: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
                   ^
 ffff8006d884f800: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
 ffff8006d884f880: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
==================================================================
Disabling lock debugging due to kernel taint
root@salvator-x:~#

Fixes: a47b70ea86bd ("ravb: unmap descriptors when freeing rings")
Signed-off-by: Eugeniu Rosca <erosca@de.adit-jv.com>
Acked-by: Sergei Shtylyov <sergei.shtylyov@cogentembedded.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/net/ethernet/renesas/ravb_main.c |   24 ++++++++++++------------
 1 file changed, 12 insertions(+), 12 deletions(-)

--- a/drivers/net/ethernet/renesas/ravb_main.c
+++ b/drivers/net/ethernet/renesas/ravb_main.c
@@ -230,18 +230,6 @@ static void ravb_ring_free(struct net_de
 	int ring_size;
 	int i;
 
-	/* Free RX skb ringbuffer */
-	if (priv->rx_skb[q]) {
-		for (i = 0; i < priv->num_rx_ring[q]; i++)
-			dev_kfree_skb(priv->rx_skb[q][i]);
-	}
-	kfree(priv->rx_skb[q]);
-	priv->rx_skb[q] = NULL;
-
-	/* Free aligned TX buffers */
-	kfree(priv->tx_align[q]);
-	priv->tx_align[q] = NULL;
-
 	if (priv->rx_ring[q]) {
 		for (i = 0; i < priv->num_rx_ring[q]; i++) {
 			struct ravb_ex_rx_desc *desc = &priv->rx_ring[q][i];
@@ -270,6 +258,18 @@ static void ravb_ring_free(struct net_de
 		priv->tx_ring[q] = NULL;
 	}
 
+	/* Free RX skb ringbuffer */
+	if (priv->rx_skb[q]) {
+		for (i = 0; i < priv->num_rx_ring[q]; i++)
+			dev_kfree_skb(priv->rx_skb[q][i]);
+	}
+	kfree(priv->rx_skb[q]);
+	priv->rx_skb[q] = NULL;
+
+	/* Free aligned TX buffers */
+	kfree(priv->tx_align[q]);
+	priv->tx_align[q] = NULL;
+
 	/* Free TX skb ringbuffer.
 	 * SKBs are freed by ravb_tx_free() call above.
 	 */

[toc] | [prev] | [next] | [standalone]


#1664131 — [PATCH 4.11 048/150] efi: Dont issue error message when booted under Xen

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-06-12 19:40 +0200
Subject[PATCH 4.11 048/150] efi: Dont issue error message when booted under Xen
Message-ID<tRBtN-56r-51@gated-at.bofh.it>
In reply to#1664124
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Juergen Gross <jgross@suse.com>

commit 1ea34adb87c969b89dfd83f1905a79161e9ada26 upstream.

When booted as Xen dom0 there won't be an EFI memmap allocated. Avoid
issuing an error message in this case:

  [    0.144079] efi: Failed to allocate new EFI memmap

Signed-off-by: Juergen Gross <jgross@suse.com>
Signed-off-by: Matt Fleming <matt@codeblueprint.co.uk>
Cc: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: linux-efi@vger.kernel.org
Link: http://lkml.kernel.org/r/20170526113652.21339-2-matt@codeblueprint.co.uk
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/x86/platform/efi/quirks.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/arch/x86/platform/efi/quirks.c
+++ b/arch/x86/platform/efi/quirks.c
@@ -358,6 +358,9 @@ void __init efi_free_boot_services(void)
 		free_bootmem_late(start, size);
 	}
 
+	if (!num_entries)
+		return;
+
 	new_size = efi.memmap.desc_size * num_entries;
 	new_phys = efi_memmap_alloc(num_entries);
 	if (!new_phys) {

[toc] | [prev] | [next] | [standalone]


#1664132 — [PATCH 4.11 010/150] sock: reset sk_err when the error queue is empty

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-06-12 19:40 +0200
Subject[PATCH 4.11 010/150] sock: reset sk_err when the error queue is empty
Message-ID<tRBtN-56r-55@gated-at.bofh.it>
In reply to#1664124
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Soheil Hassas Yeganeh <soheil@google.com>


[ Upstream commit 38b257938ac6655d0d6333743303231b9c465ec1 ]

Prior to f5f99309fa74 (sock: do not set sk_err in
sock_dequeue_err_skb), sk_err was reset to the error of
the skb on the head of the error queue.

Applications, most notably ping, are relying on this
behavior to reset sk_err for ICMP packets.

Set sk_err to the ICMP error when there is an ICMP packet
at the head of the error queue.

Fixes: f5f99309fa74 (sock: do not set sk_err in sock_dequeue_err_skb)
Reported-by: Cyril Hrubis <chrubis@suse.cz>
Tested-by: Cyril Hrubis <chrubis@suse.cz>
Signed-off-by: Soheil Hassas Yeganeh <soheil@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Willem de Bruijn <willemb@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/core/skbuff.c |    5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -3755,8 +3755,11 @@ struct sk_buff *sock_dequeue_err_skb(str
 
 	spin_lock_irqsave(&q->lock, flags);
 	skb = __skb_dequeue(q);
-	if (skb && (skb_next = skb_peek(q)))
+	if (skb && (skb_next = skb_peek(q))) {
 		icmp_next = is_icmp_err_skb(skb_next);
+		if (icmp_next)
+			sk->sk_err = SKB_EXT_ERR(skb_next)->ee.ee_origin;
+	}
 	spin_unlock_irqrestore(&q->lock, flags);
 
 	if (is_icmp_err_skb(skb) && !icmp_next)

[toc] | [prev] | [next] | [standalone]


#1664133 — [PATCH 4.11 005/150] ipv6: xfrm: Handle errors reported by xfrm6_find_1stfragopt()

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-06-12 19:40 +0200
Subject[PATCH 4.11 005/150] ipv6: xfrm: Handle errors reported by xfrm6_find_1stfragopt()
Message-ID<tRBtN-56r-47@gated-at.bofh.it>
In reply to#1664124
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ben Hutchings <ben@decadent.org.uk>


[ Upstream commit 6e80ac5cc992ab6256c3dae87f7e57db15e1a58c ]

xfrm6_find_1stfragopt() may now return an error code and we must
not treat it as a length.

Fixes: 2423496af35d ("ipv6: Prevent overrun when parsing v6 header options")
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Acked-by: Craig Gallek <kraig@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/ipv6/xfrm6_mode_ro.c        |    2 ++
 net/ipv6/xfrm6_mode_transport.c |    2 ++
 2 files changed, 4 insertions(+)

--- a/net/ipv6/xfrm6_mode_ro.c
+++ b/net/ipv6/xfrm6_mode_ro.c
@@ -47,6 +47,8 @@ static int xfrm6_ro_output(struct xfrm_s
 	iph = ipv6_hdr(skb);
 
 	hdr_len = x->type->hdr_offset(x, skb, &prevhdr);
+	if (hdr_len < 0)
+		return hdr_len;
 	skb_set_mac_header(skb, (prevhdr - x->props.header_len) - skb->data);
 	skb_set_network_header(skb, -x->props.header_len);
 	skb->transport_header = skb->network_header + hdr_len;
--- a/net/ipv6/xfrm6_mode_transport.c
+++ b/net/ipv6/xfrm6_mode_transport.c
@@ -28,6 +28,8 @@ static int xfrm6_transport_output(struct
 	iph = ipv6_hdr(skb);
 
 	hdr_len = x->type->hdr_offset(x, skb, &prevhdr);
+	if (hdr_len < 0)
+		return hdr_len;
 	skb_set_mac_header(skb, (prevhdr - x->props.header_len) - skb->data);
 	skb_set_network_header(skb, -x->props.header_len);
 	skb->transport_header = skb->network_header + hdr_len;

[toc] | [prev] | [next] | [standalone]


#1664261

FromGuenter Roeck <linux@roeck-us.net>
Date2017-06-13 00:10 +0200
Message-ID<tRFH3-800-3@gated-at.bofh.it>
In reply to#1664124
On Mon, Jun 12, 2017 at 05:23:27PM +0200, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 4.11.5 release.
> There are 150 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Wed Jun 14 15:24:44 UTC 2017.
> Anything received after that time might be too late.
> 

Build results:
	total: 145 pass: 145 fail: 0
Qemu test results:
	total: 122 pass: 113 fail: 9
Failed tests:
	mips:malta_defconfig:nosmp
	mips:malta_defconfig:smp
	mips64:malta_defconfig:nosmp
	mips64:malta_defconfig:smp
	mipsel:24Kf:malta_defconfig:nosmp
	mipsel:24Kf:malta_defconfig:smp
	mipsel64:malta_defconfig:nosmp
	mipsel64:malta_defconfig:smp
	mipsel64:fuloong2e_defconfig:fulong2e

All mips builds hang during boot. Bisect points to commit 9b99d86800f ("kthread:
Fix use-after-free if kthread fork fails"). The problem was also seen upstream,
and has been fixed with commit b0f5a8f32e ("kthread: fix boot hang (regression)
on MIPS/OpenRISC"). The problem is gone after this patch is applied.

Guenter

[toc] | [prev] | [next] | [standalone]


#1664542

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-06-13 09:30 +0200
Message-ID<tROr0-51u-7@gated-at.bofh.it>
In reply to#1664261
On Mon, Jun 12, 2017 at 03:03:32PM -0700, Guenter Roeck wrote:
> On Mon, Jun 12, 2017 at 05:23:27PM +0200, Greg Kroah-Hartman wrote:
> > This is the start of the stable review cycle for the 4.11.5 release.
> > There are 150 patches in this series, all will be posted as a response
> > to this one.  If anyone has any issues with these being applied, please
> > let me know.
> > 
> > Responses should be made by Wed Jun 14 15:24:44 UTC 2017.
> > Anything received after that time might be too late.
> > 
> 
> Build results:
> 	total: 145 pass: 145 fail: 0
> Qemu test results:
> 	total: 122 pass: 113 fail: 9
> Failed tests:
> 	mips:malta_defconfig:nosmp
> 	mips:malta_defconfig:smp
> 	mips64:malta_defconfig:nosmp
> 	mips64:malta_defconfig:smp
> 	mipsel:24Kf:malta_defconfig:nosmp
> 	mipsel:24Kf:malta_defconfig:smp
> 	mipsel64:malta_defconfig:nosmp
> 	mipsel64:malta_defconfig:smp
> 	mipsel64:fuloong2e_defconfig:fulong2e
> 
> All mips builds hang during boot. Bisect points to commit 9b99d86800f ("kthread:
> Fix use-after-free if kthread fork fails"). The problem was also seen upstream,
> and has been fixed with commit b0f5a8f32e ("kthread: fix boot hang (regression)
> on MIPS/OpenRISC"). The problem is gone after this patch is applied.

Thanks for the report, I've now queued this one up as well.

greg k-h

[toc] | [prev] | [next] | [standalone]


#1664307

FromShuah Khan <shuahkh@osg.samsung.com>
Date2017-06-13 02:20 +0200
Message-ID<tRHIR-LU-7@gated-at.bofh.it>
In reply to#1664124
On 06/12/2017 09:23 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 4.11.5 release.
> There are 150 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Wed Jun 14 15:24:44 UTC 2017.
> Anything received after that time might be too late.
> 
> The whole patch series can be found in one patch at:
> 	kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.11.5-rc1.gz
> or in the git tree and branch at:
>   git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.11.y
> and the diffstat can be found below.
> 
> thanks,
> 
> greg k-h
> 

Compiled and booted on my test system. No dmesg Regressions.

thanks,
-- Shuah

[toc] | [prev] | [next] | [standalone]


#1664545

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-06-13 09:30 +0200
Message-ID<tROr1-51u-21@gated-at.bofh.it>
In reply to#1664307
On Mon, Jun 12, 2017 at 06:12:43PM -0600, Shuah Khan wrote:
> On 06/12/2017 09:23 AM, Greg Kroah-Hartman wrote:
> > This is the start of the stable review cycle for the 4.11.5 release.
> > There are 150 patches in this series, all will be posted as a response
> > to this one.  If anyone has any issues with these being applied, please
> > let me know.
> > 
> > Responses should be made by Wed Jun 14 15:24:44 UTC 2017.
> > Anything received after that time might be too late.
> > 
> > The whole patch series can be found in one patch at:
> > 	kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.11.5-rc1.gz
> > or in the git tree and branch at:
> >   git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.11.y
> > and the diffstat can be found below.
> > 
> > thanks,
> > 
> > greg k-h
> > 
> 
> Compiled and booted on my test system. No dmesg Regressions.

Thanks for testing all of these and letting me know.

greg k-h

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web