Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1669592 > unrolled thread
| Started by | Willy Tarreau <w@1wt.eu> |
|---|---|
| First post | 2017-06-19 20:40 +0200 |
| Last post | 2017-06-20 11:30 +0200 |
| Articles | 20 on this page of 274 — 6 participants |
Back to article view | Back to linux.kernel
[PATCH 3.10 000/268] 3.10.107-stable review Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 088/268] HID: hid-cypress: validate length of report Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 056/268] usb: dwc3: gadget: delay unmap of bounced requests Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 218/268] HID: i2c-hid: Add sleep between POWER ON and RESET Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 196/268] igb: add i211 to i210 PHY workaround Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 263/268] tun: read vnet_hdr_sz once Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 079/268] sg_write()/bsg_write() is not fit to be called under KERNEL_DS Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 174/268] crypto: improve gcc optimization flags for serpent and wp512 Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 260/268] nfsd: check for oversized NFSv2/v3 arguments Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 153/268] af_packet: remove a stray tab in packet_set_ring() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 194/268] cpufreq: Fix and clean up show_cpuinfo_cur_freq() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 259/268] p9_client_readdir() fix Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 101/268] pinctrl: sh-pfc: Do not unconditionally support PIN_CONFIG_BIAS_DISABLE Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 034/268] can: usb_8dev: Fix memory leak of priv->cmd_msg_buffer Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 234/268] xen, fbfront: fix connecting to backend Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 009/268] ext4: trim allocation requests to group size Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 073/268] scsi: sr: Sanity check returned mode data Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 180/268] dccp: Unlock sock before calling sk_free() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 221/268] drm/vmwgfx: avoid calling vzalloc with a 0 size in vmw_get_cap_3d_ioctl() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 092/268] Input: kbtab - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 053/268] USB: cdc-acm: fix failed open not being detected Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 182/268] uapi: fix linux/packet_diag.h userspace compilation error Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 187/268] give up on gcc ilog2() constant optimizations Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 063/268] xfs: clear _XBF_PAGES from buffers when readahead page Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 085/268] drop_monitor: add missing call to genlmsg_end Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 179/268] net: don't call strlen() on the user buffer in packet_bind_spkt() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 052/268] USB: cdc-acm: fix open and suspend race Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 099/268] vme: Fix wrong pointer utilization in ca91cx42_slave_get Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 004/268] ext4: fix in-superblock mount options processing Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 062/268] xfs: set AGI buffer type in xlog_recover_clear_agi_bucket Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 051/268] USB: cdc-acm: fix double usb_autopm_put_interface() in acm_port_activate() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 157/268] sd: get disk reference in sd_check_events() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 225/268] metag/usercopy: Drop unused macros Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 005/268] ext4: add sanity checking to count_overhead() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 113/268] apparmor: exec should not be returning ENOENT when it denies Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 205/268] c6x/ptrace: Remove useless PTRACE_SETREGSET implementation Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 145/268] packet: round up linear to header len Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 202/268] fbcon: Fix vc attr at deinit Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 211/268] ACPI: Fix incompatibility with mcount-based function graph tracing Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 089/268] Input: xpad - use correct product id for x360w controllers Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 164/268] KVM: VMX: use correct vmcs_read/write for guest segment selector/base Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 040/268] ALSA: seq: Fix racy cell insertions during snd_seq_pool_done() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 013/268] block: fix use-after-free in sys_ioprio_get() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 201/268] uvcvideo: uvc_scan_fallback() for webcams with broken chain Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
[PATCH 3.10 199/268] ACM gadget: fix endianness in notifications Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 118/268] apparmor: don't check for vmalloc_addr if kvzalloc() failed Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 027/268] ocfs2: fix crash caused by stale lvb with fsdlm plugin Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 095/268] Input: mpr121 - handle multiple bits change of status register Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 192/268] Drivers: hv: balloon: don't crash when memory is added in non-sorted order Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 038/268] ALSA: timer: Reject user params with too small ticks Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 123/268] bna: Add synchronization for tx ring. Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 186/268] futex: Add missing error handling to FUTEX_REQUEUE_PI Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 046/268] USB: gadgetfs: fix use-after-free bug Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 247/268] powerpc: Reject binutils 2.24 when building little endian Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 103/268] qla2xxx: Fix crash due to null pointer access Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 177/268] mvsas: fix misleading indentation Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 120/268] apparmor: fix module parameters can be changed after policy is locked Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 147/268] siano: make it work again with CONFIG_VMAP_STACK Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 125/268] move the call of __d_drop(anon) into __d_materialise_unique(dentry, anon) Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 132/268] parisc: Don't use BITS_PER_LONG in userspace-exported swab.h header Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 076/268] libceph: verify authorize reply on connect Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 236/268] platform/x86: acer-wmi: setup accelerometer when machine has appropriate notify event Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 226/268] metag/usercopy: Zero rest of buffer from copy_from_user Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 024/268] CIFS: remove bad_network_name flag Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 262/268] kvm: nVMX: Allow L1 to intercept software exceptions (#BP and #OF) Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 173/268] xhci: fix 10 second timeout on removal of PCI hotpluggable xhci controllers Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 235/268] char: lack of bool string made CONFIG_DEVPORT always on Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 227/268] powerpc: Don't try to fix up misaligned load-with-reservation instructions Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 114/268] apparmor: fix disconnected bind mnts reconnection Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 250/268] tty: nozomi: avoid a harmless gcc warning Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 070/268] scsi: storvsc: properly set residual data length on errors Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 267/268] x86/mm/32: Enable full randomization on i386 and X86_32 Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 152/268] rtlwifi: rtl_usb: Fix for URB leaking when doing ifconfig up/down Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 041/268] ALSA: seq: Fix race during FIFO resize Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 233/268] iscsi-target: Drop work-around for legacy GlobalSAN initiator Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 251/268] hostap: avoid uninitialized variable use in hfa384x_get_rid Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
[PATCH 3.10 148/268] futex: Move futex_init() to core_initcall Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 138/268] ata: sata_mv:- Handle return value of devm_ioremap. Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 210/268] libceph: force GFP_NOIO for socket allocations Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 017/268] dm space map metadata: fix 'struct sm_metadata' leak on failed create Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 098/268] i2c: fix kernel memory disclosure in dev interface Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 217/268] HID: hid-lg: Fix immediate disconnection of Logitech Rumblepad 2 Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 082/268] net: ti: cpmac: Fix compiler warning due to type confusion Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 212/268] ACPI / power: Avoid maybe-uninitialized warning Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 128/268] tile/ptrace: Preserve previous registers for short regset write Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 035/268] ALSA: hda - Fix up GPIO for ASUS ROG Ranger Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 237/268] platform/x86: acer-wmi: setup accelerometer when ACPI device was found Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 057/268] usb: hub: Wait for connection to be reestablished after port reset Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 144/268] macvtap: read vnet_hdr_size once Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 176/268] cpmac: remove hopeless #warning Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 048/268] xhci: free xhci virtual devices with leaf nodes first Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 167/268] xtensa: move parse_tag_fdt out of #ifdef CONFIG_BLK_DEV_INITRD Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 150/268] irda: Fix lockdep annotations in hashbin_delete(). Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 097/268] Input: i8042 - add Clevo P650RS to the i8042 reset list Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 104/268] ARM: 8634/1: hw_breakpoint: blacklist Scorpion CPUs Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 231/268] x86/vdso: Plug race between mapping and ELF header setup Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 220/268] drm/vmwgfx: NULL pointer dereference in vmw_surface_define_ioctl() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 091/268] Input: iforce - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 122/268] vfio/pci: Fix integer overflows, bitmask check Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 166/268] s390: TASK_SIZE for kernel threads Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
[PATCH 3.10 011/268] ext4: return EROFS if device is r/o and journal replay is needed Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 119/268] apparmor: fix oops in profile_unpack() when policy_db is not present Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 109/268] Compare prepaths when comparing superblocks Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 209/268] metag/ptrace: Reject partial NT_METAG_RPIPE writes Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 110/268] Move check for prefix path to within cifs_get_root() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 169/268] drm/ast: Fix test for VGA enabled Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 191/268] ACPI / video: skip evaluating _DOD when it does not exist Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 204/268] virtio_balloon: init 1st buffer in stats vq Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 193/268] s390/pci: fix use after free in dma_init Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 030/268] can: peak: fix bad memory access and free sequence Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 230/268] net/packet: fix overflow in check for priv area size Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 069/268] scsi: storvsc: properly handle SRB_ERROR when sense message is present Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 083/268] tick/broadcast: Prevent NULL pointer dereference Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 240/268] catc: Combine failure cleanup code in catc_probe() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 190/268] crypto: cryptd - Assign statesize properly Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 244/268] Drivers: hv: get rid of timeout in vmbus_open() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 252/268] gfs2: avoid uninitialized variable warning Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 127/268] bnx2x: Correct ringparam estimate when DOWN Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 121/268] apparmor: do not expose kernel stack Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 165/268] KVM: PPC: Book3S PR: Fix illegal opcode emulation Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 139/268] mm/memory_hotplug.c: check start_pfn in test_pages_in_a_zone() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 142/268] sched/debug: Don't dump sched debug info in SysRq-W Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 168/268] mac80211: flush delayed work when entering suspend Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 117/268] apparmor: add missing id bounds check on dfa verification Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 197/268] ipv4: provide stronger user input validation in nl_fib_input() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 172/268] drivers: hv: Turn off write permission on the hypercall page Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 198/268] tcp: initialize icsk_ack.lrcvtime at session start time Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 178/268] l2tp: avoid use-after-free caused by l2tp_ip_backlog_recv Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 154/268] MIPS: Fix special case in 64 bit IP checksumming. Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 137/268] crypto: api - Clear CRYPTO_ALG_DEAD bit before registering an alg Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 149/268] rtc: interface: ignore expired timers when enqueuing new timers Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 189/268] crypto: ghash-clmulni - Fix load failure Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 265/268] ipv6: check raw payload size correctly in ioctl Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 160/268] rdma_cm: fail iwarp accepts w/o connection params Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 266/268] x86: standardize mmap_rnd() usage Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 243/268] Drivers: hv: don't leak memory in vmbus_establish_gpadl() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 049/268] USB: serial: io_ti: bind to interface after fw download Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
[PATCH 3.10 257/268] RDS: Fix the atomicity for congestion map update Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 245/268] ubi/upd: Always flush after prepared for an update Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 158/268] samples/seccomp: fix 64-bit comparison macros Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 140/268] mm, fs: check for fatal signals in do_generic_file_read() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 087/268] igmp: Make igmp group member RFC 3376 compliant Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 208/268] metag/ptrace: Provide default TXSTATUS for short NT_PRSTATUS Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 249/268] net/packet: fix overflow in check for tp_reserve Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 146/268] vfs: fix uninitialized flags in splice_to_pipe() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 006/268] ext4: validate s_first_meta_bg at mount time Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 241/268] catc: Use heap buffer for memory size test Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 124/268] sg: Fix double-free when drives detach during SG_IO Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 195/268] igb: Workaround for igb i210 firmware issue Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 264/268] printk: use rcuidle console tracepoint Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 050/268] usb: gadget: composite: always set ep->mult to a sensible value Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 064/268] ssb: Fix error routine when fallback SPROM fails Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 215/268] rtc: s35390a: improve irq handling Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 029/268] can: raw: raw_setsockopt: limit number of can_filter that can be set Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 107/268] vmxnet3: Wake queue from reset work Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 161/268] NFSv4: fix getacl ERANGE for some ACL buffer sizes Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 228/268] mm/mempolicy.c: fix error handling in set_mempolicy and mbind. Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 159/268] ath5k: drop bogus warning on drv_set_key with unsupported cipher Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 108/268] Fix memory leaks in cifs_do_mount() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 068/268] scsi: don't BUG_ON() empty DMA transfers Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 151/268] tty: serial: msm: Fix module autoload Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 239/268] virtio-console: avoid DMA from stack Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 232/268] iscsi-target: Fix TMR reference leak during session shutdown Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 094/268] Input: tca8418 - use the interrupt trigger from the device tree Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 242/268] net: ipv6: check route protocol when deleting routes Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 224/268] Reset TreeId to zero on SMB2 TREE_CONNECT Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 229/268] mtd: bcm47xxpart: fix parsing first block after aligned TRX Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 248/268] net/packet: fix overflow in check for tp_frame_nr Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 188/268] cancel the setfilesize transation when io error happen Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
[PATCH 3.10 022/268] CIFS: Fix missing nls unload in smb2_reconnect() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 207/268] metag/ptrace: Preserve previous registers for short regset write Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 223/268] drm/vmwgfx: fix integer overflow in vmw_surface_define_ioctl() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 116/268] apparmor: check that xindex is in trans_table bounds Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 258/268] xen/x86: don't lose event interrupts Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 216/268] padata: avoid race in reordering Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 077/268] nfs_write_end(): fix handling of short copies Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 268/268] mm: larger stack guard gap, between vmas Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
Re: [PATCH 3.10 268/268] mm: larger stack guard gap, between vmas Hugh Dickins <hughd@google.com> - 2017-06-21 09:10 +0200
Re: [PATCH 3.10 268/268] mm: larger stack guard gap, between vmas Willy Tarreau <w@1wt.eu> - 2017-06-21 09:20 +0200
Re: [PATCH 3.10 268/268] mm: larger stack guard gap, between vmas Willy Tarreau <w@1wt.eu> - 2017-06-21 18:30 +0200
[PATCH 3.10 184/268] dccp: fix memory leak during tear-down of unsuccessful connection request Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 135/268] af_unix: move unix_mknod() out of bindlock Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 084/268] netvsc: reduce maximum GSO size Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 163/268] powerpc/xmon: Fix data-breakpoint Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 246/268] x86/mce/AMD: Give a name to MCA bank 3 when accessed with legacy MSRs Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 096/268] Input: mpr121 - set missing event capability Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 183/268] ipv6: avoid write to a possibly cloned skb Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 067/268] scsi: move the nr_phys_segments assert into scsi_init_io Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 255/268] ip6mr: fix notification device destruction Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 016/268] dm crypt: mark key as invalid until properly loaded Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 126/268] serial: 8250_pci: Detach low-level driver during PCI error recovery Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 203/268] crypto: algif_hash - avoid zero-sized array Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 112/268] apparmor: fix uninitialized lsm_audit member Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 111/268] Fix regression which breaks DFS mounting Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 021/268] CIFS: Fix a possible memory corruption during reconnect Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 200/268] mmc: sdhci: Do not disable interrupts while waiting for clock Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 171/268] fat: fix using uninitialized fields of fat_inode/fsinfo_inode Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 175/268] mtd: pmcmsp: use kstrndup instead of kmalloc+strncpy Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 075/268] s390/vmlogrdr: fix IUCV buffer allocation Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 181/268] tcp: fix various issues for sockets morphing to listen state Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 214/268] rtc: s35390a: implement reset routine as suggested by the reference Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 105/268] ARM: dts: da850-evm: fix read access to SPI flash Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 058/268] usb: gadget: composite: correctly initialize ep->maxpacket Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 254/268] sctp: listen on the sock only when it's state is listening or closed Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 219/268] tty/serial: atmel: fix race condition (TX+DMA) Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
Re: [PATCH 3.10 219/268] tty/serial: atmel: fix race condition (TX+DMA) Richard Genoud <richard.genoud@gmail.com> - 2017-06-20 09:10 +0200
Re: [PATCH 3.10 219/268] tty/serial: atmel: fix race condition (TX+DMA) Willy Tarreau <w@1wt.eu> - 2017-06-20 09:30 +0200
[PATCH 3.10 039/268] ALSA: seq: Fix link corruption by event error handling Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 031/268] can: c_can_pci: fix null-pointer-deref in c_can_start() - set device pointer Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 155/268] mm: vmpressure: fix sending wrong events on underflow Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
[PATCH 3.10 253/268] net: neigh: guard against NULL solicit() method Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 037/268] ALSA: seq: Don't handle loop timeout at snd_seq_pool_done() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 206/268] sparc/ptrace: Preserve previous registers for short regset write Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 143/268] tcp: fix 0 divide in __tcp_select_window() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 055/268] usb: host: xhci-plat: Fix timeout on removal of hot pluggable xhci controllers Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 129/268] sysctl: fix proc_doulongvec_ms_jiffies_minmax() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 106/268] NFSv4: Ensure nfs_atomic_open set the dentry verifier on ENOENT Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 028/268] ocfs2: fix BUG_ON() in ocfs2_ci_checkpointed() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 238/268] mm: Tighten x86 /dev/mem with zeroing reads Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 090/268] Input: i8042 - add noloop quirk for Dell Embedded Box PC 3000 Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 045/268] USB: gadgetfs: fix unbounded memory allocation bug Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 014/268] block: allow WRITE_SAME commands with the SG_IO ioctl Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 026/268] cifs: Do not send echoes before Negotiate is complete Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 060/268] xen/gntdev: Use VM_MIXEDMAP instead of VM_IO to avoid NUMA balancing Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
Re: [PATCH 3.10 060/268] xen/gntdev: Use VM_MIXEDMAP instead of VM_IO to avoid NUMA balancing Hugh Dickins <hughd@google.com> - 2017-06-20 05:00 +0200
Re: [PATCH 3.10 060/268] xen/gntdev: Use VM_MIXEDMAP instead of VM_IO to avoid NUMA balancing Willy Tarreau <w@1wt.eu> - 2017-06-20 07:40 +0200
[PATCH 3.10 066/268] scsi: avoid a permanent stop of the scsi device's request queue Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 043/268] ALSA: usb-audio: Add QuickCam Communicate Deluxe/S7500 to volume_control_quirks Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 136/268] drm/nouveau/nv1a,nv1f/disp: fix memory clock rate retrieval Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 072/268] scsi: lpfc: Add shutdown method for kexec Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 256/268] MIPS: Fix crash registers on non-crashing CPUs Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 170/268] drm/ttm: Make sure BOs being swapped out are cacheable Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 156/268] ipc/shm: Fix shmat mmap nil-page protection Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 008/268] ext4: fix fencepost in s_first_meta_bg validation Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 130/268] ISDN: eicon: silence misleading array-bounds warning Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 078/268] powerpc/ps3: Fix system hang with GCC 5 builds Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 025/268] fs/cifs: make share unaccessible at root level mountable Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 100/268] sysrq: attach sysrq handler correctly for 32-bit kernel Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 080/268] ftrace/x86: Set ftrace_stub to weak to prevent gcc from using short jumps to it Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 102/268] x86/PCI: Ignore _CRS on Supermicro X8DTH-i/6/iF/6F Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 010/268] ext4: preserve the needs_recovery flag when the journal is aborted Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 115/268] apparmor: internal paths should be treated as disconnected Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 081/268] cred/userns: define current_user_ns() as a function Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 222/268] drm/vmwgfx: Remove getparam error message Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 061/268] arm/xen: Use alloc_percpu rather than __alloc_percpu Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 213/268] rtc: s35390a: make sure all members in the output are set Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 036/268] ALSA: seq: Fix race at creating a queue Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 162/268] bcma: use (get|put)_device when probing/removing device driver Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
Re: [PATCH 3.10 162/268] bcma: use (get|put)_device when probing/removing device driver Kalle Valo <kvalo@codeaurora.org> - 2017-06-20 07:20 +0200
Re: [PATCH 3.10 162/268] bcma: use (get|put)_device when probing/removing device driver Willy Tarreau <w@1wt.eu> - 2017-06-20 08:20 +0200
Re: [PATCH 3.10 162/268] bcma: use (get|put)_device when probing/removing device driver Willy Tarreau <w@1wt.eu> - 2017-06-20 10:00 +0200
Re: [PATCH 3.10 162/268] bcma: use (get|put)_device when probing/removing device driver Willy Tarreau <w@1wt.eu> - 2017-06-20 10:20 +0200
Re: [PATCH 3.10 162/268] bcma: use (get|put)_device when probing/removing device driver Rafał Miłecki <rafal@milecki.pl> - 2017-06-20 12:00 +0200
Re: [PATCH 3.10 162/268] bcma: use (get|put)_device when probing/removing device driver Rafał Miłecki <rafal@milecki.pl> - 2017-06-20 11:00 +0200
[PATCH 3.10 086/268] drop_monitor: consider inserted data in genlmsg_end Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 023/268] CIFS: Fix a possible memory corruption in push locks Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 020/268] md linear: fix a race between linear_add() and linear_congested() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
[PATCH 3.10 015/268] block: fix del_gendisk() vs blkdev_ioctl crash Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
[PATCH 3.10 012/268] ext4: fix inode checksum calculation problem if i_extra_size is small Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
[PATCH 3.10 019/268] md:raid1: fix a dead loop when read from a WriteMostly disk Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
[PATCH 3.10 071/268] target/pscsi: Fix TYPE_TAPE + TYPE_MEDIMUM_CHANGER export Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
[PATCH 3.10 059/268] USB: UHCI: report non-PME wakeup signalling for Intel hardware Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
[PATCH 3.10 033/268] can: bcm: fix hrtimer/tasklet termination in bcm op removal Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
[PATCH 3.10 032/268] can: ti_hecc: add missing prepare and unprepare of the clock Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
[PATCH 3.10 044/268] usb: gadgetfs: restrict upper bound on device configuration size Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
[PATCH 3.10 001/268] Revert "Btrfs: don't delay inode ref updates during log, replay" Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
[PATCH 3.10 002/268] Btrfs: fix memory leak in reading btree blocks Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
[PATCH 3.10 065/268] drivers/gpu/drm/ast: Fix infinite loop if read fails Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
[PATCH 3.10 042/268] ALSA: seq: Don't break snd_use_lock_sync() loop by timeout Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
Re: [PATCH 3.10 000/268] 3.10.107-stable review Guenter Roeck <linux@roeck-us.net> - 2017-06-20 00:50 +0200
Re: [PATCH 3.10 000/268] 3.10.107-stable review Willy Tarreau <w@1wt.eu> - 2017-06-20 01:00 +0200
Re: [PATCH 3.10 000/268] 3.10.107-stable review Willy Tarreau <w@1wt.eu> - 2017-06-20 08:20 +0200
Re: [PATCH 3.10 000/268] 3.10.107-stable review Guenter Roeck <linux@roeck-us.net> - 2017-06-20 11:20 +0200
Re: [PATCH 3.10 000/268] 3.10.107-stable review Willy Tarreau <w@1wt.eu> - 2017-06-20 11:30 +0200
Page 12 of 14 — ← Prev page 1 … 10 11 [12] 13 14 Next page →
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 045/268] USB: gadgetfs: fix unbounded memory allocation bug |
| Message-ID | <tUaGK-6Vi-27@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Alan Stern <stern@rowland.harvard.edu>
commit faab50984fe6636e616c7cc3d30308ba391d36fd upstream.
Andrey Konovalov reports that fuzz testing with syzkaller causes a
KASAN warning in gadgetfs:
BUG: KASAN: slab-out-of-bounds in dev_config+0x86f/0x1190 at addr ffff88003c47e160
Write of size 65537 by task syz-executor0/6356
CPU: 3 PID: 6356 Comm: syz-executor0 Not tainted 4.9.0-rc7+ #19
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011
ffff88003c107ad8 ffffffff81f96aba ffffffff3dc11ef0 1ffff10007820eee
ffffed0007820ee6 ffff88003dc11f00 0000000041b58ab3 ffffffff8598b4c8
ffffffff81f96828 ffffffff813fb4a0 ffff88003b6eadc0 ffff88003c107738
Call Trace:
[< inline >] __dump_stack lib/dump_stack.c:15
[<ffffffff81f96aba>] dump_stack+0x292/0x398 lib/dump_stack.c:51
[<ffffffff817e4dec>] kasan_object_err+0x1c/0x70 mm/kasan/report.c:159
[< inline >] print_address_description mm/kasan/report.c:197
[<ffffffff817e5080>] kasan_report_error+0x1f0/0x4e0 mm/kasan/report.c:286
[<ffffffff817e5705>] kasan_report+0x35/0x40 mm/kasan/report.c:306
[< inline >] check_memory_region_inline mm/kasan/kasan.c:308
[<ffffffff817e3fb9>] check_memory_region+0x139/0x190 mm/kasan/kasan.c:315
[<ffffffff817e4044>] kasan_check_write+0x14/0x20 mm/kasan/kasan.c:326
[< inline >] copy_from_user arch/x86/include/asm/uaccess.h:689
[< inline >] ep0_write drivers/usb/gadget/legacy/inode.c:1135
[<ffffffff83228caf>] dev_config+0x86f/0x1190 drivers/usb/gadget/legacy/inode.c:1759
[<ffffffff817fdd55>] __vfs_write+0x5d5/0x760 fs/read_write.c:510
[<ffffffff817ff650>] vfs_write+0x170/0x4e0 fs/read_write.c:560
[< inline >] SYSC_write fs/read_write.c:607
[<ffffffff81803a5b>] SyS_write+0xfb/0x230 fs/read_write.c:599
[<ffffffff84f47ec1>] entry_SYSCALL_64_fastpath+0x1f/0xc2
Indeed, there is a comment saying that the value of len is restricted
to a 16-bit integer, but the code doesn't actually do this.
This patch fixes the warning. It replaces the comment with a
computation that forces the amount of data copied from the user in
ep0_write() to be no larger than the wLength size for the control
transfer, which is a 16-bit quantity.
Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Tested-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/usb/gadget/inode.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/usb/gadget/inode.c b/drivers/usb/gadget/inode.c
index 5b45429..77b981e 100644
--- a/drivers/usb/gadget/inode.c
+++ b/drivers/usb/gadget/inode.c
@@ -1200,7 +1200,7 @@ ep0_write (struct file *fd, const char __user *buf, size_t len, loff_t *ptr)
/* data and/or status stage for control request */
} else if (dev->state == STATE_DEV_SETUP) {
- /* IN DATA+STATUS caller makes len <= wLength */
+ len = min_t(size_t, len, dev->setup_wLength);
if (dev->setup_in) {
retval = setup_req (dev->gadget->ep0, dev->req, len);
if (retval == 0) {
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 014/268] block: allow WRITE_SAME commands with the SG_IO ioctl |
| Message-ID | <tUaGL-6Vi-31@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Mauricio Faria de Oliveira <mauricfo@linux.vnet.ibm.com>
commit 25cdb64510644f3e854d502d69c73f21c6df88a9 upstream.
The WRITE_SAME commands are not present in the blk_default_cmd_filter
write_ok list, and thus are failed with -EPERM when the SG_IO ioctl()
is executed without CAP_SYS_RAWIO capability (e.g., unprivileged users).
[ sg_io() -> blk_fill_sghdr_rq() > blk_verify_command() -> -EPERM ]
The problem can be reproduced with the sg_write_same command
# sg_write_same --num 1 --xferlen 512 /dev/sda
#
# capsh --drop=cap_sys_rawio -- -c \
'sg_write_same --num 1 --xferlen 512 /dev/sda'
Write same: pass through os error: Operation not permitted
#
For comparison, the WRITE_VERIFY command does not observe this problem,
since it is in that list:
# capsh --drop=cap_sys_rawio -- -c \
'sg_write_verify --num 1 --ilen 512 --lba 0 /dev/sda'
#
So, this patch adds the WRITE_SAME commands to the list, in order
for the SG_IO ioctl to finish successfully:
# capsh --drop=cap_sys_rawio -- -c \
'sg_write_same --num 1 --xferlen 512 /dev/sda'
#
That case happens to be exercised by QEMU KVM guests with 'scsi-block' devices
(qemu "-device scsi-block" [1], libvirt "<disk type='block' device='lun'>" [2]),
which employs the SG_IO ioctl() and runs as an unprivileged user (libvirt-qemu).
In that scenario, when a filesystem (e.g., ext4) performs its zero-out calls,
which are translated to write-same calls in the guest kernel, and then into
SG_IO ioctls to the host kernel, SCSI I/O errors may be observed in the guest:
[...] sd 0:0:0:0: [sda] tag#0 FAILED Result: hostbyte=DID_OK driverbyte=DRIVER_SENSE
[...] sd 0:0:0:0: [sda] tag#0 Sense Key : Aborted Command [current]
[...] sd 0:0:0:0: [sda] tag#0 Add. Sense: I/O process terminated
[...] sd 0:0:0:0: [sda] tag#0 CDB: Write Same(10) 41 00 01 04 e0 78 00 00 08 00
[...] blk_update_request: I/O error, dev sda, sector 17096824
Links:
[1] http://git.qemu.org/?p=qemu.git;a=commit;h=336a6915bc7089fb20fea4ba99972ad9a97c5f52
[2] https://libvirt.org/formatdomain.html#elementsDisks (see 'disk' -> 'device')
Signed-off-by: Mauricio Faria de Oliveira <mauricfo@linux.vnet.ibm.com>
Signed-off-by: Brahadambal Srinivasan <latha@linux.vnet.ibm.com>
Reported-by: Manjunatha H R <manjuhr1@in.ibm.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Jens Axboe <axboe@fb.com>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sumit Semwal <sumit.semwal@linaro.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
block/scsi_ioctl.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/block/scsi_ioctl.c b/block/scsi_ioctl.c
index 1b4988b..9bfbb51 100644
--- a/block/scsi_ioctl.c
+++ b/block/scsi_ioctl.c
@@ -175,6 +175,9 @@ static void blk_set_cmd_filter_defaults(struct blk_cmd_filter *filter)
__set_bit(WRITE_16, filter->write_ok);
__set_bit(WRITE_LONG, filter->write_ok);
__set_bit(WRITE_LONG_2, filter->write_ok);
+ __set_bit(WRITE_SAME, filter->write_ok);
+ __set_bit(WRITE_SAME_16, filter->write_ok);
+ __set_bit(WRITE_SAME_32, filter->write_ok);
__set_bit(ERASE, filter->write_ok);
__set_bit(GPCMD_MODE_SELECT_10, filter->write_ok);
__set_bit(MODE_SELECT, filter->write_ok);
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 026/268] cifs: Do not send echoes before Negotiate is complete |
| Message-ID | <tUaGL-6Vi-33@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Sachin Prabhu <sprabhu@redhat.com>
commit 62a6cfddcc0a5313e7da3e8311ba16226fe0ac10 upstream.
commit 4fcd1813e640 ("Fix reconnect to not defer smb3 session reconnect
long after socket reconnect") added support for Negotiate requests to
be initiated by echo calls.
To avoid delays in calling echo after a reconnect, I added the patch
introduced by the commit b8c600120fc8 ("Call echo service immediately
after socket reconnect").
This has however caused a regression with cifs shares which do not have
support for echo calls to trigger Negotiate requests. On connections
which need to call Negotiation, the echo calls trigger an error which
triggers a reconnect which in turn triggers another echo call. This
results in a loop which is only broken when an operation is performed on
the cifs share. For an idle share, it can DOS a server.
The patch uses the smb_operation can_echo() for cifs so that it is
called only if connection has been already been setup.
kernel bz: 194531
Signed-off-by: Sachin Prabhu <sprabhu@redhat.com>
Tested-by: Jonathan Liu <net147@gmail.com>
Acked-by: Pavel Shilovsky <pshilov@microsoft.com>
Signed-off-by: Steve French <smfrench@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
fs/cifs/smb1ops.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/fs/cifs/smb1ops.c b/fs/cifs/smb1ops.c
index 610c6c2..d97841e 100644
--- a/fs/cifs/smb1ops.c
+++ b/fs/cifs/smb1ops.c
@@ -891,6 +891,15 @@ cifs_dir_needs_close(struct cifsFileInfo *cfile)
return !cfile->srch_inf.endOfSearch && !cfile->invalidHandle;
}
+static bool
+cifs_can_echo(struct TCP_Server_Info *server)
+{
+ if (server->tcpStatus == CifsGood)
+ return true;
+
+ return false;
+}
+
struct smb_version_operations smb1_operations = {
.send_cancel = send_nt_cancel,
.compare_fids = cifs_compare_fids,
@@ -923,6 +932,7 @@ struct smb_version_operations smb1_operations = {
.get_dfs_refer = CIFSGetDFSRefer,
.qfs_tcon = cifs_qfs_tcon,
.is_path_accessible = cifs_is_path_accessible,
+ .can_echo = cifs_can_echo,
.query_path_info = cifs_query_path_info,
.query_file_info = cifs_query_file_info,
.get_srv_inum = cifs_get_srv_inum,
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 060/268] xen/gntdev: Use VM_MIXEDMAP instead of VM_IO to avoid NUMA balancing |
| Message-ID | <tUaGL-6Vi-37@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Boris Ostrovsky <boris.ostrovsky@oracle.com>
commit 30faaafdfa0c754c91bac60f216c9f34a2bfdf7e upstream.
Commit 9c17d96500f7 ("xen/gntdev: Grant maps should not be subject to
NUMA balancing") set VM_IO flag to prevent grant maps from being
subjected to NUMA balancing.
It was discovered recently that this flag causes get_user_pages() to
always fail with -EFAULT.
check_vma_flags
__get_user_pages
__get_user_pages_locked
__get_user_pages_unlocked
get_user_pages_fast
iov_iter_get_pages
dio_refill_pages
do_direct_IO
do_blockdev_direct_IO
do_blockdev_direct_IO
ext4_direct_IO_read
generic_file_read_iter
aio_run_iocb
(which can happen if guest's vdisk has direct-io-safe option).
To avoid this let's use VM_MIXEDMAP flag instead --- it prevents
NUMA balancing just as VM_IO does and has no effect on
check_vma_flags().
Reported-by: Olaf Hering <olaf@aepfle.de>
Suggested-by: Hugh Dickins <hughd@google.com>
Signed-off-by: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Acked-by: Hugh Dickins <hughd@google.com>
Tested-by: Olaf Hering <olaf@aepfle.de>
Signed-off-by: Juergen Gross <jgross@suse.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/xen/gntdev.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/xen/gntdev.c b/drivers/xen/gntdev.c
index 3d8e609..6c6d253 100644
--- a/drivers/xen/gntdev.c
+++ b/drivers/xen/gntdev.c
@@ -770,7 +770,7 @@ static int gntdev_mmap(struct file *flip, struct vm_area_struct *vma)
vma->vm_ops = &gntdev_vmops;
- vma->vm_flags |= VM_DONTEXPAND | VM_DONTDUMP | VM_IO;
+ vma->vm_flags |= VM_DONTEXPAND | VM_DONTDUMP | VM_MIXEDMAP;
if (use_ptemod)
vma->vm_flags |= VM_DONTCOPY;
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Hugh Dickins <hughd@google.com> |
|---|---|
| Date | 2017-06-20 05:00 +0200 |
| Subject | Re: [PATCH 3.10 060/268] xen/gntdev: Use VM_MIXEDMAP instead of VM_IO to avoid NUMA balancing |
| Message-ID | <tUhyx-2Le-3@gated-at.bofh.it> |
| In reply to | #1669850 |
On Mon, 19 Jun 2017, Willy Tarreau wrote:
> From: Boris Ostrovsky <boris.ostrovsky@oracle.com>
>
> commit 30faaafdfa0c754c91bac60f216c9f34a2bfdf7e upstream.
>
> Commit 9c17d96500f7 ("xen/gntdev: Grant maps should not be subject to
> NUMA balancing") set VM_IO flag to prevent grant maps from being
> subjected to NUMA balancing.
>
> It was discovered recently that this flag causes get_user_pages() to
> always fail with -EFAULT.
>
> check_vma_flags
> __get_user_pages
> __get_user_pages_locked
> __get_user_pages_unlocked
> get_user_pages_fast
> iov_iter_get_pages
> dio_refill_pages
> do_direct_IO
> do_blockdev_direct_IO
> do_blockdev_direct_IO
> ext4_direct_IO_read
> generic_file_read_iter
> aio_run_iocb
>
> (which can happen if guest's vdisk has direct-io-safe option).
>
> To avoid this let's use VM_MIXEDMAP flag instead --- it prevents
> NUMA balancing just as VM_IO does and has no effect on
> check_vma_flags().
This is only valid if kernel/sched/fair.c is checking for VM_MIXEDMAP,
and that came in v4.1's 8e76d4eecf7a ("sched, numa: do not hint for
NUMA balancing on VM_MIXEDMAP mappings"), which I don't see in your
tree nor in this series (please double check, I may have missed it).
It would be good to have that one in too, and it was marked for
stable; but maybe it didn't apply, because of depending on another
commit adding the is_vm_hugetlb_page(vma) check there? Which I
expect would also be good to have, but I haven't looked it up.
Maybe drop this one for this round, and gather up its dependencies
for the next round.
Ben's 3.16 tree appeared to be in the same position,
I didn't look at the EOL 3.18.
(I've not yet checked through backports of the "larger stack guard gap"
- thank you all for those - will do so, but won't get through them
tonight - I must look into DaveJ's trinity VM_BUG_ON now.)
Hugh
>
> Reported-by: Olaf Hering <olaf@aepfle.de>
> Suggested-by: Hugh Dickins <hughd@google.com>
> Signed-off-by: Boris Ostrovsky <boris.ostrovsky@oracle.com>
> Acked-by: Hugh Dickins <hughd@google.com>
> Tested-by: Olaf Hering <olaf@aepfle.de>
> Signed-off-by: Juergen Gross <jgross@suse.com>
> Signed-off-by: Willy Tarreau <w@1wt.eu>
> ---
> drivers/xen/gntdev.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/xen/gntdev.c b/drivers/xen/gntdev.c
> index 3d8e609..6c6d253 100644
> --- a/drivers/xen/gntdev.c
> +++ b/drivers/xen/gntdev.c
> @@ -770,7 +770,7 @@ static int gntdev_mmap(struct file *flip, struct vm_area_struct *vma)
>
> vma->vm_ops = &gntdev_vmops;
>
> - vma->vm_flags |= VM_DONTEXPAND | VM_DONTDUMP | VM_IO;
> + vma->vm_flags |= VM_DONTEXPAND | VM_DONTDUMP | VM_MIXEDMAP;
>
> if (use_ptemod)
> vma->vm_flags |= VM_DONTCOPY;
> --
> 2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-20 07:40 +0200 |
| Subject | Re: [PATCH 3.10 060/268] xen/gntdev: Use VM_MIXEDMAP instead of VM_IO to avoid NUMA balancing |
| Message-ID | <tUk3o-4sK-11@gated-at.bofh.it> |
| In reply to | #1670214 |
On Mon, Jun 19, 2017 at 07:57:27PM -0700, Hugh Dickins wrote:
> On Mon, 19 Jun 2017, Willy Tarreau wrote:
>
> > From: Boris Ostrovsky <boris.ostrovsky@oracle.com>
> >
> > commit 30faaafdfa0c754c91bac60f216c9f34a2bfdf7e upstream.
> >
> > Commit 9c17d96500f7 ("xen/gntdev: Grant maps should not be subject to
> > NUMA balancing") set VM_IO flag to prevent grant maps from being
> > subjected to NUMA balancing.
> >
> > It was discovered recently that this flag causes get_user_pages() to
> > always fail with -EFAULT.
> >
> > check_vma_flags
> > __get_user_pages
> > __get_user_pages_locked
> > __get_user_pages_unlocked
> > get_user_pages_fast
> > iov_iter_get_pages
> > dio_refill_pages
> > do_direct_IO
> > do_blockdev_direct_IO
> > do_blockdev_direct_IO
> > ext4_direct_IO_read
> > generic_file_read_iter
> > aio_run_iocb
> >
> > (which can happen if guest's vdisk has direct-io-safe option).
> >
> > To avoid this let's use VM_MIXEDMAP flag instead --- it prevents
> > NUMA balancing just as VM_IO does and has no effect on
> > check_vma_flags().
>
> This is only valid if kernel/sched/fair.c is checking for VM_MIXEDMAP,
> and that came in v4.1's 8e76d4eecf7a ("sched, numa: do not hint for
> NUMA balancing on VM_MIXEDMAP mappings"), which I don't see in your
> tree nor in this series (please double check, I may have missed it).
>
> It would be good to have that one in too, and it was marked for
> stable; but maybe it didn't apply, because of depending on another
> commit adding the is_vm_hugetlb_page(vma) check there? Which I
> expect would also be good to have, but I haven't looked it up.
>
> Maybe drop this one for this round, and gather up its dependencies
> for the next round.
Yep that's what I'm going to do, thanks for the details. I've found
that I'll simply have to pick 6b79c57b92 and 8e76d4eecf. I won't
take the onse adding vma_policy_mof() that late in the cycle as
apparently it's only about a performance regression.
> Ben's 3.16 tree appeared to be in the same position,
> I didn't look at the EOL 3.18.
I picked this one by reviewing what patches from 3.12 were missing in
3.10 and 3.12 had the same issue. We've probably lost this along the
chain of backports.
> (I've not yet checked through backports of the "larger stack guard gap"
> - thank you all for those - will do so, but won't get through them
> tonight - I must look into DaveJ's trinity VM_BUG_ON now.)
No pb, you're welcome. At least they didn't prevent Guenter's machines
from booting on 82 platforms, which is a good start ;-)
Willy
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 066/268] scsi: avoid a permanent stop of the scsi device's request queue |
| Message-ID | <tUaGL-6Vi-35@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Wei Fang <fangwei1@huawei.com> commit d2a145252c52792bc59e4767b486b26c430af4bb upstream. A race between scanning and fc_remote_port_delete() may result in a permanent stop if the device gets blocked before scsi_sysfs_add_sdev() and unblocked after. The reason is that blocking a device sets both the SDEV_BLOCKED state and the QUEUE_FLAG_STOPPED. However, scsi_sysfs_add_sdev() unconditionally sets SDEV_RUNNING which causes the device to be ignored by scsi_target_unblock() and thus never have its QUEUE_FLAG_STOPPED cleared leading to a device which is apparently running but has a stopped queue. We actually have two places where SDEV_RUNNING is set: once in scsi_add_lun() which respects the blocked flag and once in scsi_sysfs_add_sdev() which doesn't. Since the second set is entirely spurious, simply remove it to fix the problem. Reported-by: Zengxi Chen <chenzengxi@huawei.com> Signed-off-by: Wei Fang <fangwei1@huawei.com> Reviewed-by: Ewan D. Milne <emilne@redhat.com> Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com> Signed-off-by: Willy Tarreau <w@1wt.eu> --- drivers/scsi/scsi_sysfs.c | 4 ---- 1 file changed, 4 deletions(-) diff --git a/drivers/scsi/scsi_sysfs.c b/drivers/scsi/scsi_sysfs.c index 135d7b5..53da653 100644 --- a/drivers/scsi/scsi_sysfs.c +++ b/drivers/scsi/scsi_sysfs.c @@ -865,10 +865,6 @@ int scsi_sysfs_add_sdev(struct scsi_device *sdev) struct request_queue *rq = sdev->request_queue; struct scsi_target *starget = sdev->sdev_target; - error = scsi_device_set_state(sdev, SDEV_RUNNING); - if (error) - return error; - error = scsi_target_add(starget); if (error) return error; -- 2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 043/268] ALSA: usb-audio: Add QuickCam Communicate Deluxe/S7500 to volume_control_quirks |
| Message-ID | <tUaGL-6Vi-41@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Con Kolivas <con@kolivas.org>
commit 82ffb6fc637150b279f49e174166d2aa3853eaf4 upstream.
The Logitech QuickCam Communicate Deluxe/S7500 microphone fails with the
following warning.
[ 6.778995] usb 2-1.2.2.2: Warning! Unlikely big volume range (=3072),
cval->res is probably wrong.
[ 6.778996] usb 2-1.2.2.2: [5] FU [Mic Capture Volume] ch = 1, val =
4608/7680/1
Adding it to the list of devices in volume_control_quirks makes it work
properly, fixing related typo.
Signed-off-by: Con Kolivas <kernel@kolivas.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
sound/usb/mixer.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/sound/usb/mixer.c b/sound/usb/mixer.c
index 5ea5a18..77047e3 100644
--- a/sound/usb/mixer.c
+++ b/sound/usb/mixer.c
@@ -893,9 +893,10 @@ static void volume_control_quirks(struct usb_mixer_elem_info *cval,
case USB_ID(0x046d, 0x0826): /* HD Webcam c525 */
case USB_ID(0x046d, 0x08ca): /* Logitech Quickcam Fusion */
case USB_ID(0x046d, 0x0991):
+ case USB_ID(0x046d, 0x09a2): /* QuickCam Communicate Deluxe/S7500 */
/* Most audio usb devices lie about volume resolution.
* Most Logitech webcams have res = 384.
- * Proboly there is some logitech magic behind this number --fishor
+ * Probably there is some logitech magic behind this number --fishor
*/
if (!strcmp(kctl->id.name, "Mic Capture Volume")) {
snd_printk(KERN_INFO
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 136/268] drm/nouveau/nv1a,nv1f/disp: fix memory clock rate retrieval |
| Message-ID | <tUaGL-6Vi-43@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Ilia Mirkin <imirkin@alum.mit.edu> commit 24bf7ae359b8cca165bb30742d2b1c03a1eb23af upstream. Based on the xf86-video-nv code, NFORCE (NV1A) and NFORCE2 (NV1F) have a different way of retrieving clocks. See the nv_hw.c:nForceUpdateArbitrationSettings function in the original code for how these clocks were accessed. Bugzilla: https://bugs.freedesktop.org/show_bug.cgi?id=54587 Signed-off-by: Ilia Mirkin <imirkin@alum.mit.edu> Signed-off-by: Ben Skeggs <bskeggs@redhat.com> Signed-off-by: Willy Tarreau <w@1wt.eu> --- drivers/gpu/drm/nouveau/dispnv04/hw.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/nouveau/dispnv04/hw.c b/drivers/gpu/drm/nouveau/dispnv04/hw.c index 973056b..b16e051 100644 --- a/drivers/gpu/drm/nouveau/dispnv04/hw.c +++ b/drivers/gpu/drm/nouveau/dispnv04/hw.c @@ -224,6 +224,7 @@ nouveau_hw_get_clock(struct drm_device *dev, enum nvbios_pll_type plltype) uint32_t mpllP; pci_read_config_dword(pci_get_bus_and_slot(0, 3), 0x6c, &mpllP); + mpllP = (mpllP >> 8) & 0xf; if (!mpllP) mpllP = 4; @@ -234,7 +235,7 @@ nouveau_hw_get_clock(struct drm_device *dev, enum nvbios_pll_type plltype) uint32_t clock; pci_read_config_dword(pci_get_bus_and_slot(0, 5), 0x4c, &clock); - return clock; + return clock / 1000; } ret = nouveau_hw_get_pllvals(dev, plltype, &pllvals); -- 2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 072/268] scsi: lpfc: Add shutdown method for kexec |
| Message-ID | <tUaGL-6Vi-47@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Anton Blanchard <anton@samba.org>
commit 85e8a23936ab3442de0c42da97d53b29f004ece1 upstream.
We see lpfc devices regularly fail during kexec. Fix this by adding a
shutdown method which mirrors the remove method.
Signed-off-by: Anton Blanchard <anton@samba.org>
Reviewed-by: Mauricio Faria de Oliveira <mauricfo@linux.vnet.ibm.com>
Tested-by: Mauricio Faria de Oliveira <mauricfo@linux.vnet.ibm.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/scsi/lpfc/lpfc_init.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/scsi/lpfc/lpfc_init.c b/drivers/scsi/lpfc/lpfc_init.c
index e6e0679..b08b1e1 100644
--- a/drivers/scsi/lpfc/lpfc_init.c
+++ b/drivers/scsi/lpfc/lpfc_init.c
@@ -10909,6 +10909,7 @@ static struct pci_driver lpfc_driver = {
.id_table = lpfc_id_table,
.probe = lpfc_pci_probe_one,
.remove = lpfc_pci_remove_one,
+ .shutdown = lpfc_pci_remove_one,
.suspend = lpfc_pci_suspend_one,
.resume = lpfc_pci_resume_one,
.err_handler = &lpfc_err_handler,
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 256/268] MIPS: Fix crash registers on non-crashing CPUs |
| Message-ID | <tUaGL-6Vi-53@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Corey Minyard <cminyard@mvista.com>
commit c80e1b62ffca52e2d1d865ee58bc79c4c0c55005 upstream.
As part of handling a crash on an SMP system, an IPI is send to
all other CPUs to save their current registers and stop. It was
using task_pt_regs(current) to get the registers, but that will
only be accurate if the CPU was interrupted running in userland.
Instead allow the architecture to pass in the registers (all
pass NULL now, but allow for the future) and then use get_irq_regs()
which should be accurate as we are in an interrupt. Fall back to
task_pt_regs(current) if nothing else is available.
Signed-off-by: Corey Minyard <cminyard@mvista.com>
Cc: David Daney <ddaney@caviumnetworks.com>
Cc: linux-mips@linux-mips.org
Patchwork: https://patchwork.linux-mips.org/patch/13050/
Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
Cc: Julia Lawall <julia.lawall@lip6.fr>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
arch/mips/kernel/crash.c | 16 +++++++++++++---
1 file changed, 13 insertions(+), 3 deletions(-)
diff --git a/arch/mips/kernel/crash.c b/arch/mips/kernel/crash.c
index 93aa302..c683129 100644
--- a/arch/mips/kernel/crash.c
+++ b/arch/mips/kernel/crash.c
@@ -15,12 +15,22 @@ static int crashing_cpu = -1;
static cpumask_t cpus_in_crash = CPU_MASK_NONE;
#ifdef CONFIG_SMP
-static void crash_shutdown_secondary(void *ignore)
+static void crash_shutdown_secondary(void *passed_regs)
{
- struct pt_regs *regs;
+ struct pt_regs *regs = passed_regs;
int cpu = smp_processor_id();
- regs = task_pt_regs(current);
+ /*
+ * If we are passed registers, use those. Otherwise get the
+ * regs from the last interrupt, which should be correct, as
+ * we are in an interrupt. But if the regs are not there,
+ * pull them from the top of the stack. They are probably
+ * wrong, but we need something to keep from crashing again.
+ */
+ if (!regs)
+ regs = get_irq_regs();
+ if (!regs)
+ regs = task_pt_regs(current);
if (!cpu_online(cpu))
return;
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 170/268] drm/ttm: Make sure BOs being swapped out are cacheable |
| Message-ID | <tUaGM-6Vi-55@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Michel Dänzer <michel.daenzer@amd.com>
commit 239ac65fa5ffab71adf66e642750f940e7241d99 upstream.
The current caching state may not be tt_cached, even though the
placement contains TTM_PL_FLAG_CACHED, because placement can contain
multiple caching flags. Trying to swap out such a BO would trip up the
BUG_ON(ttm->caching_state != tt_cached);
in ttm_tt_swapout.
Signed-off-by: Michel Dänzer <michel.daenzer@amd.com>
Reviewed-by: Thomas Hellstrom <thellstrom@vmware.com>
Reviewed-by: Christian König <christian.koenig@amd.com>.
Reviewed-by: Sinclair Yeh <syeh@vmware.com>
Signed-off-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/gpu/drm/ttm/ttm_bo.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/ttm/ttm_bo.c b/drivers/gpu/drm/ttm/ttm_bo.c
index 0ac0a88..f1672f3 100644
--- a/drivers/gpu/drm/ttm/ttm_bo.c
+++ b/drivers/gpu/drm/ttm/ttm_bo.c
@@ -1866,7 +1866,6 @@ static int ttm_bo_swapout(struct ttm_mem_shrink *shrink)
struct ttm_buffer_object *bo;
int ret = -EBUSY;
int put_count;
- uint32_t swap_placement = (TTM_PL_FLAG_CACHED | TTM_PL_FLAG_SYSTEM);
spin_lock(&glob->lru_lock);
list_for_each_entry(bo, &glob->swap_lru, swap) {
@@ -1904,7 +1903,8 @@ static int ttm_bo_swapout(struct ttm_mem_shrink *shrink)
if (unlikely(ret != 0))
goto out;
- if ((bo->mem.placement & swap_placement) != swap_placement) {
+ if (bo->mem.mem_type != TTM_PL_SYSTEM ||
+ bo->ttm->caching_state != tt_cached) {
struct ttm_mem_reg evict_mem;
evict_mem = bo->mem;
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 156/268] ipc/shm: Fix shmat mmap nil-page protection |
| Message-ID | <tUaGM-6Vi-57@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Davidlohr Bueso <dave@stgolabs.net>
commit 95e91b831f87ac8e1f8ed50c14d709089b4e01b8 upstream.
The issue is described here, with a nice testcase:
https://bugzilla.kernel.org/show_bug.cgi?id=192931
The problem is that shmat() calls do_mmap_pgoff() with MAP_FIXED, and
the address rounded down to 0. For the regular mmap case, the
protection mentioned above is that the kernel gets to generate the
address -- arch_get_unmapped_area() will always check for MAP_FIXED and
return that address. So by the time we do security_mmap_addr(0) things
get funky for shmat().
The testcase itself shows that while a regular user crashes, root will
not have a problem attaching a nil-page. There are two possible fixes
to this. The first, and which this patch does, is to simply allow root
to crash as well -- this is also regular mmap behavior, ie when hacking
up the testcase and adding mmap(... |MAP_FIXED). While this approach
is the safer option, the second alternative is to ignore SHM_RND if the
rounded address is 0, thus only having MAP_SHARED flags. This makes the
behavior of shmat() identical to the mmap() case. The downside of this
is obviously user visible, but does make sense in that it maintains
semantics after the round-down wrt 0 address and mmap.
Passes shm related ltp tests.
Link: http://lkml.kernel.org/r/1486050195-18629-1-git-send-email-dave@stgolabs.net
Signed-off-by: Davidlohr Bueso <dbueso@suse.de>
Reported-by: Gareth Evans <gareth.evans@contextis.co.uk>
Cc: Manfred Spraul <manfred@colorfullife.com>
Cc: Michael Kerrisk <mtk.manpages@googlemail.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
ipc/shm.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/ipc/shm.c b/ipc/shm.c
index 08b14f6..ddfad44 100644
--- a/ipc/shm.c
+++ b/ipc/shm.c
@@ -1041,8 +1041,8 @@ out_unlock1:
* "raddr" thing points to kernel space, and there has to be a wrapper around
* this.
*/
-long do_shmat(int shmid, char __user *shmaddr, int shmflg, ulong *raddr,
- unsigned long shmlba)
+long do_shmat(int shmid, char __user *shmaddr, int shmflg,
+ ulong *raddr, unsigned long shmlba)
{
struct shmid_kernel *shp;
unsigned long addr;
@@ -1063,8 +1063,13 @@ long do_shmat(int shmid, char __user *shmaddr, int shmflg, ulong *raddr,
goto out;
else if ((addr = (ulong)shmaddr)) {
if (addr & (shmlba - 1)) {
- if (shmflg & SHM_RND)
- addr &= ~(shmlba - 1); /* round down */
+ /*
+ * Round down to the nearest multiple of shmlba.
+ * For sane do_mmap_pgoff() parameters, avoid
+ * round downs that trigger nil-page and MAP_FIXED.
+ */
+ if ((shmflg & SHM_RND) && addr >= shmlba)
+ addr &= ~(shmlba - 1);
else
#ifndef __ARCH_FORCE_SHMLBA
if (addr & ~PAGE_MASK)
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 008/268] ext4: fix fencepost in s_first_meta_bg validation |
| Message-ID | <tUaGM-6Vi-61@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Theodore Ts'o <tytso@mit.edu>
commit 2ba3e6e8afc9b6188b471f27cf2b5e3cf34e7af2 upstream.
It is OK for s_first_meta_bg to be equal to the number of block group
descriptor blocks. (It rarely happens, but it shouldn't cause any
problems.)
https://bugzilla.kernel.org/show_bug.cgi?id=194567
Fixes: 3a4b77cd47bb837b8557595ec7425f281f2ca1fe
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
fs/ext4/super.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/ext4/super.c b/fs/ext4/super.c
index b44dc28..ae1d5c4 100644
--- a/fs/ext4/super.c
+++ b/fs/ext4/super.c
@@ -3778,7 +3778,7 @@ static int ext4_fill_super(struct super_block *sb, void *data, int silent)
db_count = (sbi->s_groups_count + EXT4_DESC_PER_BLOCK(sb) - 1) /
EXT4_DESC_PER_BLOCK(sb);
if (EXT4_HAS_INCOMPAT_FEATURE(sb, EXT4_FEATURE_INCOMPAT_META_BG)) {
- if (le32_to_cpu(es->s_first_meta_bg) >= db_count) {
+ if (le32_to_cpu(es->s_first_meta_bg) > db_count) {
ext4_msg(sb, KERN_WARNING,
"first meta block group too large: %u "
"(group descriptor block count %u)",
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 130/268] ISDN: eicon: silence misleading array-bounds warning |
| Message-ID | <tUaGM-6Vi-63@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Arnd Bergmann <arnd@arndb.de> commit 950eabbd6ddedc1b08350b9169a6a51b130ebaaf upstream. With some gcc versions, we get a warning about the eicon driver, and that currently shows up as the only remaining warning in one of the build bots: In file included from ../drivers/isdn/hardware/eicon/message.c:30:0: eicon/message.c: In function 'mixer_notify_update': eicon/platform.h:333:18: warning: array subscript is above array bounds [-Warray-bounds] The code is easily changed to open-code the unusual PUT_WORD() line causing this to avoid the warning. Link: http://arm-soc.lixom.net/buildlogs/stable-rc/v4.4.45/ Signed-off-by: Arnd Bergmann <arnd@arndb.de> Signed-off-by: David S. Miller <davem@davemloft.net> Signed-off-by: Willy Tarreau <w@1wt.eu> --- drivers/isdn/hardware/eicon/message.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/isdn/hardware/eicon/message.c b/drivers/isdn/hardware/eicon/message.c index a82e542..fecbf1d2 100644 --- a/drivers/isdn/hardware/eicon/message.c +++ b/drivers/isdn/hardware/eicon/message.c @@ -11304,7 +11304,8 @@ static void mixer_notify_update(PLCI *plci, byte others) ((CAPI_MSG *) msg)->header.ncci = 0; ((CAPI_MSG *) msg)->info.facility_req.Selector = SELECTOR_LINE_INTERCONNECT; ((CAPI_MSG *) msg)->info.facility_req.structs[0] = 3; - PUT_WORD(&(((CAPI_MSG *) msg)->info.facility_req.structs[1]), LI_REQ_SILENT_UPDATE); + ((CAPI_MSG *) msg)->info.facility_req.structs[1] = LI_REQ_SILENT_UPDATE & 0xff; + ((CAPI_MSG *) msg)->info.facility_req.structs[2] = LI_REQ_SILENT_UPDATE >> 8; ((CAPI_MSG *) msg)->info.facility_req.structs[3] = 0; w = api_put(notify_plci->appl, (CAPI_MSG *) msg); if (w != _QUEUE_FULL) -- 2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 078/268] powerpc/ps3: Fix system hang with GCC 5 builds |
| Message-ID | <tUaGM-6Vi-65@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Geoff Levand <geoff@infradead.org>
commit 6dff5b67054e17c91bd630bcdda17cfca5aa4215 upstream.
GCC 5 generates different code for this bootwrapper null check that
causes the PS3 to hang very early in its bootup. This check is of
limited value, so just get rid of it.
Signed-off-by: Geoff Levand <geoff@infradead.org>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
arch/powerpc/boot/ps3-head.S | 5 -----
arch/powerpc/boot/ps3.c | 8 +-------
2 files changed, 1 insertion(+), 12 deletions(-)
diff --git a/arch/powerpc/boot/ps3-head.S b/arch/powerpc/boot/ps3-head.S
index b6fcbaf..3dc44b0 100644
--- a/arch/powerpc/boot/ps3-head.S
+++ b/arch/powerpc/boot/ps3-head.S
@@ -57,11 +57,6 @@ __system_reset_overlay:
bctr
1:
- /* Save the value at addr zero for a null pointer write check later. */
-
- li r4, 0
- lwz r3, 0(r4)
-
/* Primary delays then goes to _zimage_start in wrapper. */
or 31, 31, 31 /* db16cyc */
diff --git a/arch/powerpc/boot/ps3.c b/arch/powerpc/boot/ps3.c
index 9954d98..029ea3c 100644
--- a/arch/powerpc/boot/ps3.c
+++ b/arch/powerpc/boot/ps3.c
@@ -119,13 +119,12 @@ void ps3_copy_vectors(void)
flush_cache((void *)0x100, 512);
}
-void platform_init(unsigned long null_check)
+void platform_init(void)
{
const u32 heapsize = 0x1000000 - (u32)_end; /* 16MiB */
void *chosen;
unsigned long ft_addr;
u64 rm_size;
- unsigned long val;
console_ops.write = ps3_console_write;
platform_ops.exit = ps3_exit;
@@ -153,11 +152,6 @@ void platform_init(unsigned long null_check)
printf(" flat tree at 0x%lx\n\r", ft_addr);
- val = *(unsigned long *)0;
-
- if (val != null_check)
- printf("null check failed: %lx != %lx\n\r", val, null_check);
-
((kernel_entry_t)0)(ft_addr, 0, NULL);
ps3_exit();
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 025/268] fs/cifs: make share unaccessible at root level mountable |
| Message-ID | <tUaGM-6Vi-67@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Aurelien Aptel <aaptel@suse.com>
commit a6b5058fafdf508904bbf16c29b24042cef3c496 upstream.
if, when mounting //HOST/share/sub/dir/foo we can query /sub/dir/foo but
not any of the path components above:
- store the /sub/dir/foo prefix in the cifs super_block info
- in the superblock, set root dentry to the subpath dentry (instead of
the share root)
- set a flag in the superblock to remember it
- use prefixpath when building path from a dentry
fixes bso#8950
Signed-off-by: Aurelien Aptel <aaptel@suse.com>
Reviewed-by: Pavel Shilovsky <pshilovsky@samba.org>
Signed-off-by: Steve French <smfrench@gmail.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
fs/cifs/cifs_fs_sb.h | 4 ++++
fs/cifs/cifsfs.c | 14 +++++++++++++-
fs/cifs/connect.c | 49 +++++++++++++++++++++++++++++++++++++++++++++++++
fs/cifs/dir.c | 20 ++++++++++++++++++--
fs/cifs/inode.c | 22 ++++++++++++++++++++--
5 files changed, 104 insertions(+), 5 deletions(-)
diff --git a/fs/cifs/cifs_fs_sb.h b/fs/cifs/cifs_fs_sb.h
index 37e4a72..ae4e35b 100644
--- a/fs/cifs/cifs_fs_sb.h
+++ b/fs/cifs/cifs_fs_sb.h
@@ -45,6 +45,9 @@
#define CIFS_MOUNT_POSIXACL 0x100000 /* mirror of MS_POSIXACL in mnt_cifs_flags */
#define CIFS_MOUNT_CIFS_BACKUPUID 0x200000 /* backup intent bit for a user */
#define CIFS_MOUNT_CIFS_BACKUPGID 0x400000 /* backup intent bit for a group */
+#define CIFS_MOUNT_USE_PREFIX_PATH 0x1000000 /* make subpath with unaccessible
+ * root mountable
+ */
struct cifs_sb_info {
struct rb_root tlink_tree;
@@ -65,5 +68,6 @@ struct cifs_sb_info {
char *mountdata; /* options received at mount time or via DFS refs */
struct backing_dev_info bdi;
struct delayed_work prune_tlinks;
+ char *prepath;
};
#endif /* _CIFS_FS_SB_H */
diff --git a/fs/cifs/cifsfs.c b/fs/cifs/cifsfs.c
index 3752b9f..134607d 100644
--- a/fs/cifs/cifsfs.c
+++ b/fs/cifs/cifsfs.c
@@ -647,6 +647,14 @@ cifs_do_mount(struct file_system_type *fs_type,
goto out_cifs_sb;
}
+ if (volume_info->prepath) {
+ cifs_sb->prepath = kstrdup(volume_info->prepath, GFP_KERNEL);
+ if (cifs_sb->prepath == NULL) {
+ root = ERR_PTR(-ENOMEM);
+ goto out_cifs_sb;
+ }
+ }
+
cifs_setup_cifs_sb(volume_info, cifs_sb);
rc = cifs_mount(cifs_sb, volume_info);
@@ -685,7 +693,11 @@ cifs_do_mount(struct file_system_type *fs_type,
sb->s_flags |= MS_ACTIVE;
}
- root = cifs_get_root(volume_info, sb);
+ if (cifs_sb->mnt_cifs_flags & CIFS_MOUNT_USE_PREFIX_PATH)
+ root = dget(sb->s_root);
+ else
+ root = cifs_get_root(volume_info, sb);
+
if (IS_ERR(root))
goto out_super;
diff --git a/fs/cifs/connect.c b/fs/cifs/connect.c
index 0808b08..ece9071 100644
--- a/fs/cifs/connect.c
+++ b/fs/cifs/connect.c
@@ -3430,6 +3430,44 @@ cifs_get_volume_info(char *mount_data, const char *devname)
return volume_info;
}
+static int
+cifs_are_all_path_components_accessible(struct TCP_Server_Info *server,
+ unsigned int xid,
+ struct cifs_tcon *tcon,
+ struct cifs_sb_info *cifs_sb,
+ char *full_path)
+{
+ int rc;
+ char *s;
+ char sep, tmp;
+
+ sep = CIFS_DIR_SEP(cifs_sb);
+ s = full_path;
+
+ rc = server->ops->is_path_accessible(xid, tcon, cifs_sb, "");
+ while (rc == 0) {
+ /* skip separators */
+ while (*s == sep)
+ s++;
+ if (!*s)
+ break;
+ /* next separator */
+ while (*s && *s != sep)
+ s++;
+
+ /*
+ * temporarily null-terminate the path at the end of
+ * the current component
+ */
+ tmp = *s;
+ *s = 0;
+ rc = server->ops->is_path_accessible(xid, tcon, cifs_sb,
+ full_path);
+ *s = tmp;
+ }
+ return rc;
+}
+
int
cifs_mount(struct cifs_sb_info *cifs_sb, struct smb_vol *volume_info)
{
@@ -3556,6 +3594,16 @@ remote_path_check:
kfree(full_path);
goto mount_fail_check;
}
+
+ rc = cifs_are_all_path_components_accessible(server,
+ xid, tcon, cifs_sb,
+ full_path);
+ if (rc != 0) {
+ cifs_dbg(VFS, "cannot query dirs between root and final path, "
+ "enabling CIFS_MOUNT_USE_PREFIX_PATH\n");
+ cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_USE_PREFIX_PATH;
+ rc = 0;
+ }
kfree(full_path);
}
@@ -3813,6 +3861,7 @@ cifs_umount(struct cifs_sb_info *cifs_sb)
bdi_destroy(&cifs_sb->bdi);
kfree(cifs_sb->mountdata);
+ kfree(cifs_sb->prepath);
unload_nls(cifs_sb->local_nls);
kfree(cifs_sb);
}
diff --git a/fs/cifs/dir.c b/fs/cifs/dir.c
index a998c92..5431247 100644
--- a/fs/cifs/dir.c
+++ b/fs/cifs/dir.c
@@ -83,6 +83,7 @@ build_path_from_dentry(struct dentry *direntry)
struct dentry *temp;
int namelen;
int dfsplen;
+ int pplen = 0;
char *full_path;
char dirsep;
struct cifs_sb_info *cifs_sb = CIFS_SB(direntry->d_sb);
@@ -94,8 +95,12 @@ build_path_from_dentry(struct dentry *direntry)
dfsplen = strnlen(tcon->treeName, MAX_TREE_SIZE + 1);
else
dfsplen = 0;
+
+ if (cifs_sb->mnt_cifs_flags & CIFS_MOUNT_USE_PREFIX_PATH)
+ pplen = cifs_sb->prepath ? strlen(cifs_sb->prepath) + 1 : 0;
+
cifs_bp_rename_retry:
- namelen = dfsplen;
+ namelen = dfsplen + pplen;
seq = read_seqbegin(&rename_lock);
rcu_read_lock();
for (temp = direntry; !IS_ROOT(temp);) {
@@ -136,7 +141,7 @@ cifs_bp_rename_retry:
}
}
rcu_read_unlock();
- if (namelen != dfsplen || read_seqretry(&rename_lock, seq)) {
+ if (namelen != dfsplen + pplen || read_seqretry(&rename_lock, seq)) {
cifs_dbg(FYI, "did not end path lookup where expected. namelen=%ddfsplen=%d\n",
namelen, dfsplen);
/* presumably this is only possible if racing with a rename
@@ -152,6 +157,17 @@ cifs_bp_rename_retry:
those safely to '/' if any are found in the middle of the prepath */
/* BB test paths to Windows with '/' in the midst of prepath */
+ if (pplen) {
+ int i;
+
+ cifs_dbg(FYI, "using cifs_sb prepath <%s>\n", cifs_sb->prepath);
+ memcpy(full_path+dfsplen+1, cifs_sb->prepath, pplen-1);
+ full_path[dfsplen] = '\\';
+ for (i = 0; i < pplen-1; i++)
+ if (full_path[dfsplen+1+i] == '/')
+ full_path[dfsplen+1+i] = CIFS_DIR_SEP(cifs_sb);
+ }
+
if (dfsplen) {
strncpy(full_path, tcon->treeName, dfsplen);
if (cifs_sb->mnt_cifs_flags & CIFS_MOUNT_POSIX_PATHS) {
diff --git a/fs/cifs/inode.c b/fs/cifs/inode.c
index 54304cc..971e7be 100644
--- a/fs/cifs/inode.c
+++ b/fs/cifs/inode.c
@@ -895,12 +895,29 @@ struct inode *cifs_root_iget(struct super_block *sb)
struct inode *inode = NULL;
long rc;
struct cifs_tcon *tcon = cifs_sb_master_tcon(cifs_sb);
+ char *path = NULL;
+ int len;
+
+ if ((cifs_sb->mnt_cifs_flags & CIFS_MOUNT_USE_PREFIX_PATH)
+ && cifs_sb->prepath) {
+ len = strlen(cifs_sb->prepath);
+ path = kzalloc(len + 2 /* leading sep + null */, GFP_KERNEL);
+ if (path == NULL)
+ return ERR_PTR(-ENOMEM);
+ path[0] = '/';
+ memcpy(path+1, cifs_sb->prepath, len);
+ } else {
+ path = kstrdup("", GFP_KERNEL);
+ if (path == NULL)
+ return ERR_PTR(-ENOMEM);
+ }
xid = get_xid();
+ convert_delimiter(path, CIFS_DIR_SEP(cifs_sb));
if (tcon->unix_ext)
- rc = cifs_get_inode_info_unix(&inode, "", sb, xid);
+ rc = cifs_get_inode_info_unix(&inode, path, sb, xid);
else
- rc = cifs_get_inode_info(&inode, "", NULL, sb, xid, NULL);
+ rc = cifs_get_inode_info(&inode, path, NULL, sb, xid, NULL);
if (!inode) {
inode = ERR_PTR(rc);
@@ -928,6 +945,7 @@ struct inode *cifs_root_iget(struct super_block *sb)
}
out:
+ kfree(path);
/* can not call macro free_xid here since in a void func
* TODO: This is no longer true
*/
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 100/268] sysrq: attach sysrq handler correctly for 32-bit kernel |
| Message-ID | <tUaGM-6Vi-73@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Akinobu Mita <akinobu.mita@gmail.com>
commit 802c03881f29844af0252b6e22be5d2f65f93fd0 upstream.
The sysrq input handler should be attached to the input device which has
a left alt key.
On 32-bit kernels, some input devices which has a left alt key cannot
attach sysrq handler. Because the keybit bitmap in struct input_device_id
for sysrq is not correctly initialized. KEY_LEFTALT is 56 which is
greater than BITS_PER_LONG on 32-bit kernels.
I found this problem when using a matrix keypad device which defines
a KEY_LEFTALT (56) but doesn't have a KEY_O (24 == 56%32).
Cc: Jiri Slaby <jslaby@suse.com>
Signed-off-by: Akinobu Mita <akinobu.mita@gmail.com>
Acked-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
drivers/tty/sysrq.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/tty/sysrq.c b/drivers/tty/sysrq.c
index b51c154..602c9a7 100644
--- a/drivers/tty/sysrq.c
+++ b/drivers/tty/sysrq.c
@@ -881,8 +881,8 @@ static const struct input_device_id sysrq_ids[] = {
{
.flags = INPUT_DEVICE_ID_MATCH_EVBIT |
INPUT_DEVICE_ID_MATCH_KEYBIT,
- .evbit = { BIT_MASK(EV_KEY) },
- .keybit = { BIT_MASK(KEY_LEFTALT) },
+ .evbit = { [BIT_WORD(EV_KEY)] = BIT_MASK(EV_KEY) },
+ .keybit = { [BIT_WORD(KEY_LEFTALT)] = BIT_MASK(KEY_LEFTALT) },
},
{ },
};
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 080/268] ftrace/x86: Set ftrace_stub to weak to prevent gcc from using short jumps to it |
| Message-ID | <tUaGM-6Vi-71@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Steven Rostedt <rostedt@goodmis.org>
commit 8329e818f14926a6040df86b2668568bde342ebf upstream.
Matt Fleming reported seeing crashes when enabling and disabling
function profiling which uses function graph tracer. Later Namhyung Kim
hit a similar issue and he found that the issue was due to the jmp to
ftrace_stub in ftrace_graph_call was only two bytes, and when it was
changed to jump to the tracing code, it overwrote the ftrace_stub that
was after it.
Masami Hiramatsu bisected this down to a binutils change:
8dcea93252a9ea7dff57e85220a719e2a5e8ab41 is the first bad commit
commit 8dcea93252a9ea7dff57e85220a719e2a5e8ab41
Author: H.J. Lu <hjl.tools@gmail.com>
Date: Fri May 15 03:17:31 2015 -0700
Add -mshared option to x86 ELF assembler
This patch adds -mshared option to x86 ELF assembler. By default,
assembler will optimize out non-PLT relocations against defined non-weak
global branch targets with default visibility. The -mshared option tells
the assembler to generate code which may go into a shared library
where all non-weak global branch targets with default visibility can
be preempted. The resulting code is slightly bigger. This option
only affects the handling of branch instructions.
Declaring ftrace_stub as a weak call prevents gas from using two byte
jumps to it, which would be converted to a jump to the function graph
code.
Link: http://lkml.kernel.org/r/20160516230035.1dbae571@gandalf.local.home
Reported-by: Matt Fleming <matt@codeblueprint.co.uk>
Reported-by: Namhyung Kim <namhyung@kernel.org>
Tested-by: Matt Fleming <matt@codeblueprint.co.uk>
Reviewed-by: Masami Hiramatsu <mhiramat@kernel.org>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
arch/x86/kernel/entry_64.S | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/x86/kernel/entry_64.S b/arch/x86/kernel/entry_64.S
index 6ed8f16..cc89b36 100644
--- a/arch/x86/kernel/entry_64.S
+++ b/arch/x86/kernel/entry_64.S
@@ -122,7 +122,8 @@ GLOBAL(ftrace_graph_call)
jmp ftrace_stub
#endif
-GLOBAL(ftrace_stub)
+/* This is weak to keep gas from relaxing the jumps */
+WEAK(ftrace_stub)
retq
END(ftrace_caller)
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
| From | Willy Tarreau <w@1wt.eu> |
|---|---|
| Date | 2017-06-19 21:40 +0200 |
| Subject | [PATCH 3.10 102/268] x86/PCI: Ignore _CRS on Supermicro X8DTH-i/6/iF/6F |
| Message-ID | <tUaGN-6Vi-77@gated-at.bofh.it> |
| In reply to | #1669592 |
From: Bjorn Helgaas <bhelgaas@google.com>
commit 89e9f7bcd8744ea25fcf0ac671b8d72c10d7d790 upstream.
Martin reported that the Supermicro X8DTH-i/6/iF/6F advertises incorrect
host bridge windows via _CRS:
pci_root PNP0A08:00: host bridge window [io 0xf000-0xffff]
pci_root PNP0A08:01: host bridge window [io 0xf000-0xffff]
Both bridges advertise the 0xf000-0xffff window, which cannot be correct.
Work around this by ignoring _CRS on this system. The downside is that we
may not assign resources correctly to hot-added PCI devices (if they are
possible on this system).
Link: https://bugzilla.kernel.org/show_bug.cgi?id=42606
Reported-by: Martin Burnicki <martin.burnicki@meinberg.de>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
arch/x86/pci/acpi.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/arch/x86/pci/acpi.c b/arch/x86/pci/acpi.c
index a3b0265..63462c8 100644
--- a/arch/x86/pci/acpi.c
+++ b/arch/x86/pci/acpi.c
@@ -118,6 +118,16 @@ static const struct dmi_system_id pci_crs_quirks[] __initconst = {
DMI_MATCH(DMI_BIOS_VERSION, "6JET85WW (1.43 )"),
},
},
+ /* https://bugzilla.kernel.org/show_bug.cgi?id=42606 */
+ {
+ .callback = set_nouse_crs,
+ .ident = "Supermicro X8DTH",
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "Supermicro"),
+ DMI_MATCH(DMI_PRODUCT_NAME, "X8DTH-i/6/iF/6F"),
+ DMI_MATCH(DMI_BIOS_VERSION, "2.0a"),
+ },
+ },
/* https://bugzilla.kernel.org/show_bug.cgi?id=15362 */
{
--
2.8.0.rc2.1.gbe9624a
[toc] | [prev] | [next] | [standalone]
Page 12 of 14 — ← Prev page 1 … 10 11 [12] 13 14 Next page →
Back to top | Article view | linux.kernel
csiph-web