Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1669592 > unrolled thread

[PATCH 3.10 000/268] 3.10.107-stable review

Started byWilly Tarreau <w@1wt.eu>
First post2017-06-19 20:40 +0200
Last post2017-06-20 11:30 +0200
Articles 20 on this page of 274 — 6 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.10 000/268] 3.10.107-stable review Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 088/268] HID: hid-cypress: validate length of report Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 056/268] usb: dwc3: gadget: delay unmap of bounced requests Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 218/268] HID: i2c-hid: Add sleep between POWER ON and RESET Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 196/268] igb: add i211 to i210 PHY workaround Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 263/268] tun: read vnet_hdr_sz once Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 079/268] sg_write()/bsg_write() is not fit to be called under KERNEL_DS Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 174/268] crypto: improve gcc optimization flags for serpent and wp512 Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 260/268] nfsd: check for oversized NFSv2/v3 arguments Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 153/268] af_packet: remove a stray tab in packet_set_ring() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 194/268] cpufreq: Fix and clean up show_cpuinfo_cur_freq() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 259/268] p9_client_readdir() fix Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 101/268] pinctrl: sh-pfc: Do not unconditionally support PIN_CONFIG_BIAS_DISABLE Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 034/268] can: usb_8dev: Fix memory leak of priv->cmd_msg_buffer Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 234/268] xen, fbfront: fix connecting to backend Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 009/268] ext4: trim allocation requests to group size Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 073/268] scsi: sr: Sanity check returned mode data Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 180/268] dccp: Unlock sock before calling sk_free() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 221/268] drm/vmwgfx: avoid calling vzalloc with a 0 size in vmw_get_cap_3d_ioctl() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 092/268] Input: kbtab - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 053/268] USB: cdc-acm: fix failed open not being detected Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 182/268] uapi: fix linux/packet_diag.h userspace compilation error Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 187/268] give up on gcc ilog2() constant optimizations Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 063/268] xfs: clear _XBF_PAGES from buffers when readahead page Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 085/268] drop_monitor: add missing call to genlmsg_end Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 179/268] net: don't call strlen() on the user buffer in packet_bind_spkt() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 052/268] USB: cdc-acm: fix open and suspend race Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 099/268] vme: Fix wrong pointer utilization in ca91cx42_slave_get Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 004/268] ext4: fix in-superblock mount options processing Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 062/268] xfs: set AGI buffer type in xlog_recover_clear_agi_bucket Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 051/268] USB: cdc-acm: fix double usb_autopm_put_interface() in acm_port_activate() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 157/268] sd: get disk reference in sd_check_events() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 225/268] metag/usercopy: Drop unused macros Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 005/268] ext4: add sanity checking to count_overhead() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 113/268] apparmor: exec should not be returning ENOENT when it denies Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 205/268] c6x/ptrace: Remove useless PTRACE_SETREGSET implementation Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 145/268] packet: round up linear to header len Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 202/268] fbcon: Fix vc attr at deinit Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 211/268] ACPI: Fix incompatibility with mcount-based function graph tracing Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 089/268] Input: xpad - use correct product id for x360w controllers Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 164/268] KVM: VMX: use correct vmcs_read/write for guest segment selector/base Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 040/268] ALSA: seq: Fix racy cell insertions during snd_seq_pool_done() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 013/268] block: fix use-after-free in sys_ioprio_get() Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 201/268] uvcvideo: uvc_scan_fallback() for webcams with broken chain Willy Tarreau <w@1wt.eu> - 2017-06-19 20:40 +0200
    [PATCH 3.10 199/268] ACM gadget: fix endianness in notifications Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 118/268] apparmor: don't check for vmalloc_addr if kvzalloc() failed Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 027/268] ocfs2: fix crash caused by stale lvb with fsdlm plugin Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 095/268] Input: mpr121 - handle multiple bits change of status register Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 192/268] Drivers: hv: balloon: don't crash when memory is added in non-sorted order Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 038/268] ALSA: timer: Reject user params with too small ticks Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 123/268] bna: Add synchronization for tx ring. Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 186/268] futex: Add missing error handling to FUTEX_REQUEUE_PI Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 046/268] USB: gadgetfs: fix use-after-free bug Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 247/268] powerpc: Reject binutils 2.24 when building little endian Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 103/268] qla2xxx: Fix crash due to null pointer access Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 177/268] mvsas: fix misleading indentation Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 120/268] apparmor: fix module parameters can be changed after policy is locked Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 147/268] siano: make it work again with CONFIG_VMAP_STACK Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 125/268] move the call of __d_drop(anon) into __d_materialise_unique(dentry, anon) Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 132/268] parisc: Don't use BITS_PER_LONG in userspace-exported swab.h header Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 076/268] libceph: verify authorize reply on connect Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 236/268] platform/x86: acer-wmi: setup accelerometer when machine has appropriate notify event Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 226/268] metag/usercopy: Zero rest of buffer from copy_from_user Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 024/268] CIFS: remove bad_network_name flag Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 262/268] kvm: nVMX: Allow L1 to intercept software exceptions (#BP and #OF) Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 173/268] xhci: fix 10 second timeout on removal of PCI hotpluggable xhci controllers Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 235/268] char: lack of bool string made CONFIG_DEVPORT always on Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 227/268] powerpc: Don't try to fix up misaligned load-with-reservation instructions Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 114/268] apparmor: fix disconnected bind mnts reconnection Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 250/268] tty: nozomi: avoid a harmless gcc warning Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 070/268] scsi: storvsc: properly set residual data length on errors Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 267/268] x86/mm/32: Enable full randomization on i386 and X86_32 Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 152/268] rtlwifi: rtl_usb: Fix for URB leaking when doing ifconfig up/down Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 041/268] ALSA: seq: Fix race during FIFO resize Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 233/268] iscsi-target: Drop work-around for legacy GlobalSAN initiator Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 251/268] hostap: avoid uninitialized variable use in hfa384x_get_rid Willy Tarreau <w@1wt.eu> - 2017-06-19 20:50 +0200
    [PATCH 3.10 148/268] futex: Move futex_init() to core_initcall Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 138/268] ata: sata_mv:- Handle return value of devm_ioremap. Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 210/268] libceph: force GFP_NOIO for socket allocations Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 017/268] dm space map metadata: fix 'struct sm_metadata' leak on failed create Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 098/268] i2c: fix kernel memory disclosure in dev interface Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 217/268] HID: hid-lg: Fix immediate disconnection of Logitech Rumblepad 2 Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 082/268] net: ti: cpmac: Fix compiler warning due to type confusion Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 212/268] ACPI / power: Avoid maybe-uninitialized warning Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 128/268] tile/ptrace: Preserve previous registers for short regset write Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 035/268] ALSA: hda - Fix up GPIO for ASUS ROG Ranger Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 237/268] platform/x86: acer-wmi: setup accelerometer when ACPI device was found Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 057/268] usb: hub: Wait for connection to be reestablished after port reset Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 144/268] macvtap: read vnet_hdr_size once Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 176/268] cpmac: remove hopeless #warning Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 048/268] xhci: free xhci virtual devices with leaf nodes first Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 167/268] xtensa: move parse_tag_fdt out of #ifdef CONFIG_BLK_DEV_INITRD Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 150/268] irda: Fix lockdep annotations in hashbin_delete(). Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 097/268] Input: i8042 - add Clevo P650RS to the i8042 reset list Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 104/268] ARM: 8634/1: hw_breakpoint: blacklist Scorpion CPUs Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 231/268] x86/vdso: Plug race between mapping and ELF header setup Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 220/268] drm/vmwgfx: NULL pointer dereference in vmw_surface_define_ioctl() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 091/268] Input: iforce - validate number of endpoints before using them Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 122/268] vfio/pci: Fix integer overflows, bitmask check Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 166/268] s390: TASK_SIZE for kernel threads Willy Tarreau <w@1wt.eu> - 2017-06-19 21:00 +0200
    [PATCH 3.10 011/268] ext4: return EROFS if device is r/o and journal replay is needed Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 119/268] apparmor: fix oops in profile_unpack() when policy_db is not present Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 109/268] Compare prepaths when comparing superblocks Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 209/268] metag/ptrace: Reject partial NT_METAG_RPIPE writes Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 110/268] Move check for prefix path to within cifs_get_root() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 169/268] drm/ast: Fix test for VGA enabled Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 191/268] ACPI / video: skip evaluating _DOD when it does not exist Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 204/268] virtio_balloon: init 1st buffer in stats vq Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 193/268] s390/pci: fix use after free in dma_init Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 030/268] can: peak: fix bad memory access and free sequence Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 230/268] net/packet: fix overflow in check for priv area size Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 069/268] scsi: storvsc: properly handle SRB_ERROR when sense message is present Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 083/268] tick/broadcast: Prevent NULL pointer dereference Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 240/268] catc: Combine failure cleanup code in catc_probe() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 190/268] crypto: cryptd - Assign statesize properly Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 244/268] Drivers: hv: get rid of timeout in vmbus_open() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 252/268] gfs2: avoid uninitialized variable warning Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 127/268] bnx2x: Correct ringparam estimate when DOWN Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 121/268] apparmor: do not expose kernel stack Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 165/268] KVM: PPC: Book3S PR: Fix illegal opcode emulation Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 139/268] mm/memory_hotplug.c: check start_pfn in test_pages_in_a_zone() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 142/268] sched/debug: Don't dump sched debug info in SysRq-W Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 168/268] mac80211: flush delayed work when entering suspend Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 117/268] apparmor: add missing id bounds check on dfa verification Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 197/268] ipv4: provide stronger user input validation in nl_fib_input() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 172/268] drivers: hv: Turn off write permission on the hypercall page Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 198/268] tcp: initialize icsk_ack.lrcvtime at session start time Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 178/268] l2tp: avoid use-after-free caused by l2tp_ip_backlog_recv Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 154/268] MIPS: Fix special case in 64 bit IP checksumming. Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 137/268] crypto: api - Clear CRYPTO_ALG_DEAD bit before registering an alg Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 149/268] rtc: interface: ignore expired timers when enqueuing new timers Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 189/268] crypto: ghash-clmulni - Fix load failure Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 265/268] ipv6: check raw payload size correctly in ioctl Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 160/268] rdma_cm: fail iwarp accepts w/o connection params Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 266/268] x86: standardize mmap_rnd() usage Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 243/268] Drivers: hv: don't leak memory in vmbus_establish_gpadl() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 049/268] USB: serial: io_ti: bind to interface after fw download Willy Tarreau <w@1wt.eu> - 2017-06-19 21:10 +0200
    [PATCH 3.10 257/268] RDS: Fix the atomicity for congestion map update Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 245/268] ubi/upd: Always flush after prepared for an update Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 158/268] samples/seccomp: fix 64-bit comparison macros Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 140/268] mm, fs: check for fatal signals in do_generic_file_read() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 087/268] igmp: Make igmp group member RFC 3376 compliant Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 208/268] metag/ptrace: Provide default TXSTATUS for short NT_PRSTATUS Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 249/268] net/packet: fix overflow in check for tp_reserve Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 146/268] vfs: fix uninitialized flags in splice_to_pipe() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 006/268] ext4: validate s_first_meta_bg at mount time Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 241/268] catc: Use heap buffer for memory size test Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 124/268] sg: Fix double-free when drives detach during SG_IO Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 195/268] igb: Workaround for igb i210 firmware issue Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 264/268] printk: use rcuidle console tracepoint Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 050/268] usb: gadget: composite: always set ep->mult to a sensible value Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 064/268] ssb: Fix error routine when fallback SPROM fails Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 215/268] rtc: s35390a: improve irq handling Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 029/268] can: raw: raw_setsockopt: limit number of can_filter that can be set Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 107/268] vmxnet3: Wake queue from reset work Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 161/268] NFSv4: fix getacl ERANGE for some ACL buffer sizes Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 228/268] mm/mempolicy.c: fix error handling in set_mempolicy and mbind. Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 159/268] ath5k: drop bogus warning on drv_set_key with unsupported cipher Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 108/268] Fix memory leaks in cifs_do_mount() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 068/268] scsi: don't BUG_ON() empty DMA transfers Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 151/268] tty: serial: msm: Fix module autoload Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 239/268] virtio-console: avoid DMA from stack Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 232/268] iscsi-target: Fix TMR reference leak during session shutdown Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 094/268] Input: tca8418 - use the interrupt trigger from the device tree Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 242/268] net: ipv6: check route protocol when deleting routes Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 224/268] Reset TreeId to zero on SMB2 TREE_CONNECT Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 229/268] mtd: bcm47xxpart: fix parsing first block after aligned TRX Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 248/268] net/packet: fix overflow in check for tp_frame_nr Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 188/268] cancel the setfilesize transation when io error happen Willy Tarreau <w@1wt.eu> - 2017-06-19 21:20 +0200
    [PATCH 3.10 022/268] CIFS: Fix missing nls unload in smb2_reconnect() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 207/268] metag/ptrace: Preserve previous registers for short regset write Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 223/268] drm/vmwgfx: fix integer overflow in vmw_surface_define_ioctl() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 116/268] apparmor: check that xindex is in trans_table bounds Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 258/268] xen/x86: don't lose event interrupts Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 216/268] padata: avoid race in reordering Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 077/268] nfs_write_end(): fix handling of short copies Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 268/268] mm: larger stack guard gap, between vmas Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
      Re: [PATCH 3.10 268/268] mm: larger stack guard gap, between vmas Hugh Dickins <hughd@google.com> - 2017-06-21 09:10 +0200
        Re: [PATCH 3.10 268/268] mm: larger stack guard gap, between vmas Willy Tarreau <w@1wt.eu> - 2017-06-21 09:20 +0200
          Re: [PATCH 3.10 268/268] mm: larger stack guard gap, between vmas Willy Tarreau <w@1wt.eu> - 2017-06-21 18:30 +0200
    [PATCH 3.10 184/268] dccp: fix memory leak during tear-down of unsuccessful connection request Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 135/268] af_unix: move unix_mknod() out of bindlock Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 084/268] netvsc: reduce maximum GSO size Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 163/268] powerpc/xmon: Fix data-breakpoint Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 246/268] x86/mce/AMD: Give a name to MCA bank 3 when accessed with legacy MSRs Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 096/268] Input: mpr121 - set missing event capability Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 183/268] ipv6: avoid write to a possibly cloned skb Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 067/268] scsi: move the nr_phys_segments assert into scsi_init_io Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 255/268] ip6mr: fix notification device destruction Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 016/268] dm crypt: mark key as invalid until properly loaded Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 126/268] serial: 8250_pci: Detach low-level driver during PCI error recovery Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 203/268] crypto: algif_hash - avoid zero-sized array Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 112/268] apparmor: fix uninitialized lsm_audit member Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 111/268] Fix regression which breaks DFS mounting Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 021/268] CIFS: Fix a possible memory corruption during reconnect Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 200/268] mmc: sdhci: Do not disable interrupts while waiting for clock Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 171/268] fat: fix using uninitialized fields of fat_inode/fsinfo_inode Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 175/268] mtd: pmcmsp: use kstrndup instead of kmalloc+strncpy Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 075/268] s390/vmlogrdr: fix IUCV buffer allocation Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 181/268] tcp: fix various issues for sockets morphing to listen state Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 214/268] rtc: s35390a: implement reset routine as suggested by the reference Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 105/268] ARM: dts: da850-evm: fix read access to SPI flash Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 058/268] usb: gadget: composite: correctly initialize ep->maxpacket Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 254/268] sctp: listen on the sock only when it's state is listening or closed Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 219/268] tty/serial: atmel: fix race condition (TX+DMA) Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
      Re: [PATCH 3.10 219/268] tty/serial: atmel: fix race condition (TX+DMA) Richard Genoud <richard.genoud@gmail.com> - 2017-06-20 09:10 +0200
        Re: [PATCH 3.10 219/268] tty/serial: atmel: fix race condition  (TX+DMA) Willy Tarreau <w@1wt.eu> - 2017-06-20 09:30 +0200
    [PATCH 3.10 039/268] ALSA: seq: Fix link corruption by event error handling Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 031/268] can: c_can_pci: fix null-pointer-deref in c_can_start() - set device pointer Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 155/268] mm: vmpressure: fix sending wrong events on underflow Willy Tarreau <w@1wt.eu> - 2017-06-19 21:30 +0200
    [PATCH 3.10 253/268] net: neigh: guard against NULL solicit() method Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 037/268] ALSA: seq: Don't handle loop timeout at snd_seq_pool_done() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 206/268] sparc/ptrace: Preserve previous registers for short regset write Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 143/268] tcp: fix 0 divide in __tcp_select_window() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 055/268] usb: host: xhci-plat: Fix timeout on removal of hot pluggable xhci controllers Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 129/268] sysctl: fix proc_doulongvec_ms_jiffies_minmax() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 106/268] NFSv4: Ensure nfs_atomic_open set the dentry verifier on ENOENT Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 028/268] ocfs2: fix BUG_ON() in ocfs2_ci_checkpointed() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 238/268] mm: Tighten x86 /dev/mem with zeroing reads Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 090/268] Input: i8042 - add noloop quirk for Dell Embedded Box PC 3000 Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 045/268] USB: gadgetfs: fix unbounded memory allocation bug Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 014/268] block: allow WRITE_SAME commands with the SG_IO ioctl Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 026/268] cifs: Do not send echoes before Negotiate is complete Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 060/268] xen/gntdev: Use VM_MIXEDMAP instead of VM_IO to avoid NUMA balancing Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
      Re: [PATCH 3.10 060/268] xen/gntdev: Use VM_MIXEDMAP instead of  VM_IO to avoid NUMA balancing Hugh Dickins <hughd@google.com> - 2017-06-20 05:00 +0200
        Re: [PATCH 3.10 060/268] xen/gntdev: Use VM_MIXEDMAP instead of  VM_IO to avoid NUMA balancing Willy Tarreau <w@1wt.eu> - 2017-06-20 07:40 +0200
    [PATCH 3.10 066/268] scsi: avoid a permanent stop of the scsi device's request queue Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 043/268] ALSA: usb-audio: Add QuickCam Communicate Deluxe/S7500 to volume_control_quirks Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 136/268] drm/nouveau/nv1a,nv1f/disp: fix memory clock rate retrieval Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 072/268] scsi: lpfc: Add shutdown method for kexec Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 256/268] MIPS: Fix crash registers on non-crashing CPUs Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 170/268] drm/ttm: Make sure BOs being swapped out are cacheable Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 156/268] ipc/shm: Fix shmat mmap nil-page protection Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 008/268] ext4: fix fencepost in s_first_meta_bg validation Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 130/268] ISDN: eicon: silence misleading array-bounds warning Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 078/268] powerpc/ps3: Fix system hang with GCC 5 builds Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 025/268] fs/cifs: make share unaccessible at root level mountable Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 100/268] sysrq: attach sysrq handler correctly for 32-bit kernel Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 080/268] ftrace/x86: Set ftrace_stub to weak to prevent gcc from using short jumps to it Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 102/268] x86/PCI: Ignore _CRS on Supermicro X8DTH-i/6/iF/6F Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 010/268] ext4: preserve the needs_recovery flag when the journal is aborted Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 115/268] apparmor: internal paths should be treated as disconnected Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 081/268] cred/userns: define current_user_ns() as a function Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 222/268] drm/vmwgfx: Remove getparam error message Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 061/268] arm/xen: Use alloc_percpu rather than __alloc_percpu Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 213/268] rtc: s35390a: make sure all members in the output are set Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 036/268] ALSA: seq: Fix race at creating a queue Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 162/268] bcma: use (get|put)_device when probing/removing device driver Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
      Re: [PATCH 3.10 162/268] bcma: use (get|put)_device when probing/removing device driver Kalle Valo <kvalo@codeaurora.org> - 2017-06-20 07:20 +0200
        Re: [PATCH 3.10 162/268] bcma: use (get|put)_device when  probing/removing device driver Willy Tarreau <w@1wt.eu> - 2017-06-20 08:20 +0200
          Re: [PATCH 3.10 162/268] bcma: use (get|put)_device when  probing/removing device driver Willy Tarreau <w@1wt.eu> - 2017-06-20 10:00 +0200
            Re: [PATCH 3.10 162/268] bcma: use (get|put)_device when  probing/removing device driver Willy Tarreau <w@1wt.eu> - 2017-06-20 10:20 +0200
            Re: [PATCH 3.10 162/268] bcma: use (get|put)_device when  probing/removing device driver Rafał Miłecki <rafal@milecki.pl> - 2017-06-20 12:00 +0200
          Re: [PATCH 3.10 162/268] bcma: use (get|put)_device when  probing/removing device driver Rafał Miłecki <rafal@milecki.pl> - 2017-06-20 11:00 +0200
    [PATCH 3.10 086/268] drop_monitor: consider inserted data in genlmsg_end Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 023/268] CIFS: Fix a possible memory corruption in push locks Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 020/268] md linear: fix a race between linear_add() and linear_congested() Willy Tarreau <w@1wt.eu> - 2017-06-19 21:40 +0200
    [PATCH 3.10 015/268] block: fix del_gendisk() vs blkdev_ioctl crash Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
    [PATCH 3.10 012/268] ext4: fix inode checksum calculation problem if i_extra_size is small Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
    [PATCH 3.10 019/268] md:raid1: fix a dead loop when read from a WriteMostly disk Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
    [PATCH 3.10 071/268] target/pscsi: Fix TYPE_TAPE + TYPE_MEDIMUM_CHANGER export Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
    [PATCH 3.10 059/268] USB: UHCI: report non-PME wakeup signalling for Intel hardware Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
    [PATCH 3.10 033/268] can: bcm: fix hrtimer/tasklet termination in bcm op removal Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
    [PATCH 3.10 032/268] can: ti_hecc: add missing prepare and unprepare of the clock Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
    [PATCH 3.10 044/268] usb: gadgetfs: restrict upper bound on device configuration size Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
    [PATCH 3.10 001/268] Revert "Btrfs: don't delay inode ref updates during log, replay" Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
    [PATCH 3.10 002/268] Btrfs: fix memory leak in reading btree blocks Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
    [PATCH 3.10 065/268] drivers/gpu/drm/ast: Fix infinite loop if read fails Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
    [PATCH 3.10 042/268] ALSA: seq: Don't break snd_use_lock_sync() loop by timeout Willy Tarreau <w@1wt.eu> - 2017-06-19 21:50 +0200
    Re: [PATCH 3.10 000/268] 3.10.107-stable review Guenter Roeck <linux@roeck-us.net> - 2017-06-20 00:50 +0200
      Re: [PATCH 3.10 000/268] 3.10.107-stable review Willy Tarreau <w@1wt.eu> - 2017-06-20 01:00 +0200
        Re: [PATCH 3.10 000/268] 3.10.107-stable review Willy Tarreau <w@1wt.eu> - 2017-06-20 08:20 +0200
          Re: [PATCH 3.10 000/268] 3.10.107-stable review Guenter Roeck <linux@roeck-us.net> - 2017-06-20 11:20 +0200
            Re: [PATCH 3.10 000/268] 3.10.107-stable review Willy Tarreau <w@1wt.eu> - 2017-06-20 11:30 +0200

Page 8 of 14 — ← Prev page 1 … 6 7 [8] 9 10 … 14  Next page →


#1669760 — [PATCH 3.10 140/268] mm, fs: check for fatal signals in do_generic_file_read()

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 140/268] mm, fs: check for fatal signals in do_generic_file_read()
Message-ID<tUann-6Mf-5@gated-at.bofh.it>
In reply to#1669592
From: Michal Hocko <mhocko@suse.com>

commit 5abf186a30a89d5b9c18a6bf93a2c192c9fd52f6 upstream.

do_generic_file_read() can be told to perform a large request from
userspace.  If the system is under OOM and the reading task is the OOM
victim then it has an access to memory reserves and finishing the full
request can lead to the full memory depletion which is dangerous.  Make
sure we rather go with a short read and allow the killed task to
terminate.

Link: http://lkml.kernel.org/r/20170201092706.9966-3-mhocko@kernel.org
Signed-off-by: Michal Hocko <mhocko@suse.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Cc: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 mm/filemap.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/mm/filemap.c b/mm/filemap.c
index 725a100..7213078 100644
--- a/mm/filemap.c
+++ b/mm/filemap.c
@@ -1123,6 +1123,11 @@ static void do_generic_file_read(struct file *filp, loff_t *ppos,
 
 		cond_resched();
 find_page:
+		if (fatal_signal_pending(current)) {
+			error = -EINTR;
+			goto out;
+		}
+
 		page = find_get_page(mapping, index);
 		if (!page) {
 			page_cache_sync_readahead(mapping,
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669761 — [PATCH 3.10 087/268] igmp: Make igmp group member RFC 3376 compliant

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 087/268] igmp: Make igmp group member RFC 3376 compliant
Message-ID<tUann-6Mf-9@gated-at.bofh.it>
In reply to#1669592
From: Michal Tesar <mtesar@redhat.com>

commit 7ababb782690e03b78657e27bd051e20163af2d6 upstream.

5.2. Action on Reception of a Query

 When a system receives a Query, it does not respond immediately.
 Instead, it delays its response by a random amount of time, bounded
 by the Max Resp Time value derived from the Max Resp Code in the
 received Query message.  A system may receive a variety of Queries on
 different interfaces and of different kinds (e.g., General Queries,
 Group-Specific Queries, and Group-and-Source-Specific Queries), each
 of which may require its own delayed response.

 Before scheduling a response to a Query, the system must first
 consider previously scheduled pending responses and in many cases
 schedule a combined response.  Therefore, the system must be able to
 maintain the following state:

 o A timer per interface for scheduling responses to General Queries.

 o A per-group and interface timer for scheduling responses to Group-
   Specific and Group-and-Source-Specific Queries.

 o A per-group and interface list of sources to be reported in the
   response to a Group-and-Source-Specific Query.

 When a new Query with the Router-Alert option arrives on an
 interface, provided the system has state to report, a delay for a
 response is randomly selected in the range (0, [Max Resp Time]) where
 Max Resp Time is derived from Max Resp Code in the received Query
 message.  The following rules are then used to determine if a Report
 needs to be scheduled and the type of Report to schedule.  The rules
 are considered in order and only the first matching rule is applied.

 1. If there is a pending response to a previous General Query
    scheduled sooner than the selected delay, no additional response
    needs to be scheduled.

 2. If the received Query is a General Query, the interface timer is
    used to schedule a response to the General Query after the
    selected delay.  Any previously pending response to a General
    Query is canceled.
--8<--

Currently the timer is rearmed with new random expiration time for
every incoming query regardless of possibly already pending report.
Which is not aligned with the above RFE.
It also might happen that higher rate of incoming queries can
postpone the report after the expiration time of the first query
causing group membership loss.

Now the per interface general query timer is rearmed only
when there is no pending report already scheduled on that interface or
the newly selected expiration time is before the already pending
scheduled report.

Signed-off-by: Michal Tesar <mtesar@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/ipv4/igmp.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/net/ipv4/igmp.c b/net/ipv4/igmp.c
index b0178b0..4572ee7 100644
--- a/net/ipv4/igmp.c
+++ b/net/ipv4/igmp.c
@@ -196,9 +196,14 @@ static void igmp_start_timer(struct ip_mc_list *im, int max_delay)
 static void igmp_gq_start_timer(struct in_device *in_dev)
 {
 	int tv = net_random() % in_dev->mr_maxdelay;
+	unsigned long exp = jiffies + tv + 2;
+
+	if (in_dev->mr_gq_running &&
+	    time_after_eq(exp, (in_dev->mr_gq_timer).expires))
+		return;
 
 	in_dev->mr_gq_running = 1;
-	if (!mod_timer(&in_dev->mr_gq_timer, jiffies+tv+2))
+	if (!mod_timer(&in_dev->mr_gq_timer, exp))
 		in_dev_hold(in_dev);
 }
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669762 — [PATCH 3.10 208/268] metag/ptrace: Provide default TXSTATUS for short NT_PRSTATUS

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 208/268] metag/ptrace: Provide default TXSTATUS for short NT_PRSTATUS
Message-ID<tUann-6Mf-11@gated-at.bofh.it>
In reply to#1669592
From: Dave Martin <Dave.Martin@arm.com>

commit 5fe81fe98123ce41265c65e95d34418d30d005d1 upstream.

Ensure that if userspace supplies insufficient data to PTRACE_SETREGSET
to fill TXSTATUS, a well-defined default value is used, based on the
task's current value.

Suggested-by: James Hogan <james.hogan@imgtec.com>
Signed-off-by: Dave Martin <Dave.Martin@arm.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 arch/metag/kernel/ptrace.c | 15 ++++++++++++---
 1 file changed, 12 insertions(+), 3 deletions(-)

diff --git a/arch/metag/kernel/ptrace.c b/arch/metag/kernel/ptrace.c
index ae659ba..2e4dfc1 100644
--- a/arch/metag/kernel/ptrace.c
+++ b/arch/metag/kernel/ptrace.c
@@ -24,6 +24,16 @@
  * user_regset definitions.
  */
 
+static unsigned long user_txstatus(const struct pt_regs *regs)
+{
+	unsigned long data = (unsigned long)regs->ctx.Flags;
+
+	if (regs->ctx.SaveMask & TBICTX_CBUF_BIT)
+		data |= USER_GP_REGS_STATUS_CATCH_BIT;
+
+	return data;
+}
+
 int metag_gp_regs_copyout(const struct pt_regs *regs,
 			  unsigned int pos, unsigned int count,
 			  void *kbuf, void __user *ubuf)
@@ -62,9 +72,7 @@ int metag_gp_regs_copyout(const struct pt_regs *regs,
 	if (ret)
 		goto out;
 	/* TXSTATUS */
-	data = (unsigned long)regs->ctx.Flags;
-	if (regs->ctx.SaveMask & TBICTX_CBUF_BIT)
-		data |= USER_GP_REGS_STATUS_CATCH_BIT;
+	data = user_txstatus(regs);
 	ret = user_regset_copyout(&pos, &count, &kbuf, &ubuf,
 				  &data, 4*25, 4*26);
 	if (ret)
@@ -119,6 +127,7 @@ int metag_gp_regs_copyin(struct pt_regs *regs,
 	if (ret)
 		goto out;
 	/* TXSTATUS */
+	data = user_txstatus(regs);
 	ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf,
 				 &data, 4*25, 4*26);
 	if (ret)
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669763 — [PATCH 3.10 249/268] net/packet: fix overflow in check for tp_reserve

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 249/268] net/packet: fix overflow in check for tp_reserve
Message-ID<tUann-6Mf-13@gated-at.bofh.it>
In reply to#1669592
From: Andrey Konovalov <andreyknvl@google.com>

commit bcc5364bdcfe131e6379363f089e7b4108d35b70 upstream.

When calculating po->tp_hdrlen + po->tp_reserve the result can overflow.

Fix by checking that tp_reserve <= INT_MAX on assign.

Signed-off-by: Andrey Konovalov <andreyknvl@google.com>
Acked-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 net/packet/af_packet.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/net/packet/af_packet.c b/net/packet/af_packet.c
index cea85d8..0bbb347 100644
--- a/net/packet/af_packet.c
+++ b/net/packet/af_packet.c
@@ -3187,6 +3187,8 @@ packet_setsockopt(struct socket *sock, int level, int optname, char __user *optv
 			return -EBUSY;
 		if (copy_from_user(&val, optval, sizeof(val)))
 			return -EFAULT;
+		if (val > INT_MAX)
+			return -EINVAL;
 		po->tp_reserve = val;
 		return 0;
 	}
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669764 — [PATCH 3.10 146/268] vfs: fix uninitialized flags in splice_to_pipe()

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 146/268] vfs: fix uninitialized flags in splice_to_pipe()
Message-ID<tUann-6Mf-15@gated-at.bofh.it>
In reply to#1669592
From: Miklos Szeredi <mszeredi@redhat.com>

commit 5a81e6a171cdbd1fa8bc1fdd80c23d3d71816fac upstream.

Flags (PIPE_BUF_FLAG_PACKET, PIPE_BUF_FLAG_GIFT) could remain on the
unused part of the pipe ring buffer.  Previously splice_to_pipe() left
the flags value alone, which could result in incorrect behavior.

Uninitialized flags appears to have been there from the introduction of
the splice syscall.

Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/splice.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/fs/splice.c b/fs/splice.c
index 2ffa7b0..ce6ffe9 100644
--- a/fs/splice.c
+++ b/fs/splice.c
@@ -215,6 +215,7 @@ ssize_t splice_to_pipe(struct pipe_inode_info *pipe,
 			buf->len = spd->partial[page_nr].len;
 			buf->private = spd->partial[page_nr].private;
 			buf->ops = spd->ops;
+			buf->flags = 0;
 			if (spd->flags & SPLICE_F_GIFT)
 				buf->flags |= PIPE_BUF_FLAG_GIFT;
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669765 — [PATCH 3.10 006/268] ext4: validate s_first_meta_bg at mount time

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 006/268] ext4: validate s_first_meta_bg at mount time
Message-ID<tUano-6Mf-17@gated-at.bofh.it>
In reply to#1669592
From: Eryu Guan <guaneryu@gmail.com>

commit 3a4b77cd47bb837b8557595ec7425f281f2ca1fe upstream.

Ralf Spenneberg reported that he hit a kernel crash when mounting a
modified ext4 image. And it turns out that kernel crashed when
calculating fs overhead (ext4_calculate_overhead()), this is because
the image has very large s_first_meta_bg (debug code shows it's
842150400), and ext4 overruns the memory in count_overhead() when
setting bitmap buffer, which is PAGE_SIZE.

ext4_calculate_overhead():
  buf = get_zeroed_page(GFP_NOFS);  <=== PAGE_SIZE buffer
  blks = count_overhead(sb, i, buf);

count_overhead():
  for (j = ext4_bg_num_gdb(sb, grp); j > 0; j--) { <=== j = 842150400
          ext4_set_bit(EXT4_B2C(sbi, s++), buf);   <=== buffer overrun
          count++;
  }

This can be reproduced easily for me by this script:

  #!/bin/bash
  rm -f fs.img
  mkdir -p /mnt/ext4
  fallocate -l 16M fs.img
  mke2fs -t ext4 -O bigalloc,meta_bg,^resize_inode -F fs.img
  debugfs -w -R "ssv first_meta_bg 842150400" fs.img
  mount -o loop fs.img /mnt/ext4

Fix it by validating s_first_meta_bg first at mount time, and
refusing to mount if its value exceeds the largest possible meta_bg
number.

[js] use EXT4_HAS_INCOMPAT_FEATURE instead of new
     ext4_has_feature_meta_bg

Reported-by: Ralf Spenneberg <ralf@os-t.de>
Signed-off-by: Eryu Guan <guaneryu@gmail.com>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Reviewed-by: Andreas Dilger <adilger@dilger.ca>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/ext4/super.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/fs/ext4/super.c b/fs/ext4/super.c
index d609efd..b44dc28 100644
--- a/fs/ext4/super.c
+++ b/fs/ext4/super.c
@@ -3777,6 +3777,15 @@ static int ext4_fill_super(struct super_block *sb, void *data, int silent)
 			(EXT4_MAX_BLOCK_FILE_PHYS / EXT4_BLOCKS_PER_GROUP(sb)));
 	db_count = (sbi->s_groups_count + EXT4_DESC_PER_BLOCK(sb) - 1) /
 		   EXT4_DESC_PER_BLOCK(sb);
+	if (EXT4_HAS_INCOMPAT_FEATURE(sb, EXT4_FEATURE_INCOMPAT_META_BG)) {
+		if (le32_to_cpu(es->s_first_meta_bg) >= db_count) {
+			ext4_msg(sb, KERN_WARNING,
+				 "first meta block group too large: %u "
+				 "(group descriptor block count %u)",
+				 le32_to_cpu(es->s_first_meta_bg), db_count);
+			goto failed_mount;
+		}
+	}
 	sbi->s_group_desc = ext4_kvmalloc(db_count *
 					  sizeof(struct buffer_head *),
 					  GFP_KERNEL);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669766 — [PATCH 3.10 241/268] catc: Use heap buffer for memory size test

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 241/268] catc: Use heap buffer for memory size test
Message-ID<tUano-6Mf-21@gated-at.bofh.it>
In reply to#1669592
From: Ben Hutchings <ben@decadent.org.uk>

commit 2d6a0e9de03ee658a9adc3bfb2f0ca55dff1e478 upstream.

Allocating USB buffers on the stack is not portable, and no longer
works on x86_64 (with VMAP_STACK enabled as per default).

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: David S. Miller <davem@davemloft.net>
Cc: Brad Spengler <spender@grsecurity.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/net/usb/catc.c | 25 ++++++++++++++++++-------
 1 file changed, 18 insertions(+), 7 deletions(-)

diff --git a/drivers/net/usb/catc.c b/drivers/net/usb/catc.c
index bf6e083..57da4c1 100644
--- a/drivers/net/usb/catc.c
+++ b/drivers/net/usb/catc.c
@@ -779,7 +779,7 @@ static int catc_probe(struct usb_interface *intf, const struct usb_device_id *id
 	struct net_device *netdev;
 	struct catc *catc;
 	u8 broadcast[6];
-	int i, pktsz, ret;
+	int pktsz, ret;
 
 	if (usb_set_interface(usbdev,
 			intf->altsetting->desc.bInterfaceNumber, 1)) {
@@ -843,15 +843,24 @@ static int catc_probe(struct usb_interface *intf, const struct usb_device_id *id
                 catc->irq_buf, 2, catc_irq_done, catc, 1);
 
 	if (!catc->is_f5u011) {
+		u32 *buf;
+		int i;
+
 		dev_dbg(dev, "Checking memory size\n");
 
-		i = 0x12345678;
-		catc_write_mem(catc, 0x7a80, &i, 4);
-		i = 0x87654321;	
-		catc_write_mem(catc, 0xfa80, &i, 4);
-		catc_read_mem(catc, 0x7a80, &i, 4);
+		buf = kmalloc(4, GFP_KERNEL);
+		if (!buf) {
+			ret = -ENOMEM;
+			goto fail_free;
+		}
+
+		*buf = 0x12345678;
+		catc_write_mem(catc, 0x7a80, buf, 4);
+		*buf = 0x87654321;
+		catc_write_mem(catc, 0xfa80, buf, 4);
+		catc_read_mem(catc, 0x7a80, buf, 4);
 	  
-		switch (i) {
+		switch (*buf) {
 		case 0x12345678:
 			catc_set_reg(catc, TxBufCount, 8);
 			catc_set_reg(catc, RxBufCount, 32);
@@ -866,6 +875,8 @@ static int catc_probe(struct usb_interface *intf, const struct usb_device_id *id
 			dev_dbg(dev, "32k Memory\n");
 			break;
 		}
+
+		kfree(buf);
 	  
 		dev_dbg(dev, "Getting MAC from SEEROM.\n");
 	  
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669767 — [PATCH 3.10 124/268] sg: Fix double-free when drives detach during SG_IO

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 124/268] sg: Fix double-free when drives detach during SG_IO
Message-ID<tUano-6Mf-19@gated-at.bofh.it>
In reply to#1669592
From: Calvin Owens <calvinowens@fb.com>

commit f3951a3709ff50990bf3e188c27d346792103432 upstream.

In sg_common_write(), we free the block request and return -ENODEV if
the device is detached in the middle of the SG_IO ioctl().

Unfortunately, sg_finish_rem_req() also tries to free srp->rq, so we
end up freeing rq->cmd in the already free rq object, and then free
the object itself out from under the current user.

This ends up corrupting random memory via the list_head on the rq
object. The most common crash trace I saw is this:

  ------------[ cut here ]------------
  kernel BUG at block/blk-core.c:1420!
  Call Trace:
  [<ffffffff81281eab>] blk_put_request+0x5b/0x80
  [<ffffffffa0069e5b>] sg_finish_rem_req+0x6b/0x120 [sg]
  [<ffffffffa006bcb9>] sg_common_write.isra.14+0x459/0x5a0 [sg]
  [<ffffffff8125b328>] ? selinux_file_alloc_security+0x48/0x70
  [<ffffffffa006bf95>] sg_new_write.isra.17+0x195/0x2d0 [sg]
  [<ffffffffa006cef4>] sg_ioctl+0x644/0xdb0 [sg]
  [<ffffffff81170f80>] do_vfs_ioctl+0x90/0x520
  [<ffffffff81258967>] ? file_has_perm+0x97/0xb0
  [<ffffffff811714a1>] SyS_ioctl+0x91/0xb0
  [<ffffffff81602afb>] tracesys+0xdd/0xe2
    RIP [<ffffffff81281e04>] __blk_put_request+0x154/0x1a0

The solution is straightforward: just set srp->rq to NULL in the
failure branch so that sg_finish_rem_req() doesn't attempt to re-free
it.

Additionally, since sg_rq_end_io() will never be called on the object
when this happens, we need to free memory backing ->cmd if it isn't
embedded in the object itself.

KASAN was extremely helpful in finding the root cause of this bug.

Signed-off-by: Calvin Owens <calvinowens@fb.com>
Acked-by: Douglas Gilbert <dgilbert@interlog.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Acked-by: Johannes Thumshirn <jthumshirn@suse.de>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/scsi/sg.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/drivers/scsi/sg.c b/drivers/scsi/sg.c
index 291791a..0b27d29 100644
--- a/drivers/scsi/sg.c
+++ b/drivers/scsi/sg.c
@@ -769,8 +769,14 @@ sg_common_write(Sg_fd * sfp, Sg_request * srp,
 		return k;	/* probably out of space --> ENOMEM */
 	}
 	if (sdp->detached) {
-		if (srp->bio)
+		if (srp->bio) {
+			if (srp->rq->cmd != srp->rq->__cmd)
+				kfree(srp->rq->cmd);
+
 			blk_end_request_all(srp->rq, -EIO);
+			srp->rq = NULL;
+		}
+
 		sg_finish_rem_req(srp);
 		return -ENODEV;
 	}
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669768 — [PATCH 3.10 195/268] igb: Workaround for igb i210 firmware issue

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 195/268] igb: Workaround for igb i210 firmware issue
Message-ID<tUano-6Mf-25@gated-at.bofh.it>
In reply to#1669592
From: Chris J Arges <christopherarges@gmail.com>

commit 4e684f59d760a2c7c716bb60190783546e2d08a1 upstream.

Sometimes firmware may not properly initialize I347AT4_PAGE_SELECT causing
the probe of an igb i210 NIC to fail. This patch adds an addition zeroing
of this register during igb_get_phy_id to workaround this issue.

Thanks for Jochen Henneberg for the idea and original patch.

Signed-off-by: Chris J Arges <christopherarges@gmail.com>
Tested-by: Aaron Brown <aaron.f.brown@intel.com>
Signed-off-by: Jeff Kirsher <jeffrey.t.kirsher@intel.com>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/net/ethernet/intel/igb/e1000_phy.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/net/ethernet/intel/igb/e1000_phy.c b/drivers/net/ethernet/intel/igb/e1000_phy.c
index 5dec66a..3012c09 100644
--- a/drivers/net/ethernet/intel/igb/e1000_phy.c
+++ b/drivers/net/ethernet/intel/igb/e1000_phy.c
@@ -87,6 +87,10 @@ s32 igb_get_phy_id(struct e1000_hw *hw)
 	s32 ret_val = 0;
 	u16 phy_id;
 
+	/* ensure PHY page selection to fix misconfigured i210 */
+	if (hw->mac.type == e1000_i210)
+		phy->ops.write_reg(hw, I347AT4_PAGE_SELECT, 0);
+
 	ret_val = phy->ops.read_reg(hw, PHY_ID1, &phy_id);
 	if (ret_val)
 		goto out;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669770 — [PATCH 3.10 264/268] printk: use rcuidle console tracepoint

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 264/268] printk: use rcuidle console tracepoint
Message-ID<tUano-6Mf-29@gated-at.bofh.it>
In reply to#1669592
From: Sergey Senozhatsky <sergey.senozhatsky.work@gmail.com>

commit fc98c3c8c9dcafd67adcce69e6ce3191d5306c9c upstream.

Use rcuidle console tracepoint because, apparently, it may be issued
from an idle CPU:

  hw-breakpoint: Failed to enable monitor mode on CPU 0.
  hw-breakpoint: CPU 0 failed to disable vector catch

  ===============================
  [ ERR: suspicious RCU usage.  ]
  4.10.0-rc8-next-20170215+ #119 Not tainted
  -------------------------------
  ./include/trace/events/printk.h:32 suspicious rcu_dereference_check() usage!

  other info that might help us debug this:

  RCU used illegally from idle CPU!
  rcu_scheduler_active = 2, debug_locks = 0
  RCU used illegally from extended quiescent state!
  2 locks held by swapper/0/0:
   #0:  (cpu_pm_notifier_lock){......}, at: [<c0237e2c>] cpu_pm_exit+0x10/0x54
   #1:  (console_lock){+.+.+.}, at: [<c01ab350>] vprintk_emit+0x264/0x474

  stack backtrace:
  CPU: 0 PID: 0 Comm: swapper/0 Not tainted 4.10.0-rc8-next-20170215+ #119
  Hardware name: Generic OMAP4 (Flattened Device Tree)
    console_unlock
    vprintk_emit
    vprintk_default
    printk
    reset_ctrl_regs
    dbg_cpu_pm_notify
    notifier_call_chain
    cpu_pm_exit
    omap_enter_idle_coupled
    cpuidle_enter_state
    cpuidle_enter_state_coupled
    do_idle
    cpu_startup_entry
    start_kernel

This RCU warning, however, is suppressed by lockdep_off() in printk().
lockdep_off() increments the ->lockdep_recursion counter and thus
disables RCU_LOCKDEP_WARN() and debug_lockdep_rcu_enabled(), which want
lockdep to be enabled "current->lockdep_recursion == 0".

Link: http://lkml.kernel.org/r/20170217015932.11898-1-sergey.senozhatsky@gmail.com
Signed-off-by: Sergey Senozhatsky <sergey.senozhatsky@gmail.com>
Reported-by: Tony Lindgren <tony@atomide.com>
Tested-by: Tony Lindgren <tony@atomide.com>
Acked-by: Paul E. McKenney <paulmck@linux.vnet.ibm.com>
Acked-by: Steven Rostedt (VMware) <rostedt@goodmis.org>
Cc: Petr Mladek <pmladek@suse.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Tony Lindgren <tony@atomide.com>
Cc: Russell King <rmk@armlinux.org.uk>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[wt: changes are in kernel/printk.c in 3.10]
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 kernel/printk.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/kernel/printk.c b/kernel/printk.c
index ee8f6be..8acc98a 100644
--- a/kernel/printk.c
+++ b/kernel/printk.c
@@ -1270,7 +1270,7 @@ static void call_console_drivers(int level, const char *text, size_t len)
 {
 	struct console *con;
 
-	trace_console(text, len);
+	trace_console_rcuidle(text, len);
 
 	if (level >= console_loglevel && !ignore_loglevel)
 		return;
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669771 — [PATCH 3.10 050/268] usb: gadget: composite: always set ep->mult to a sensible value

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 050/268] usb: gadget: composite: always set ep->mult to a sensible value
Message-ID<tUano-6Mf-27@gated-at.bofh.it>
In reply to#1669592
From: Felipe Balbi <felipe.balbi@linux.intel.com>

commit eaa496ffaaf19591fe471a36cef366146eeb9153 upstream.

ep->mult is supposed to be set to Isochronous and
Interrupt Endapoint's multiplier value. This value
is computed from different places depending on the
link speed.

If we're dealing with HighSpeed, then it's part of
bits [12:11] of wMaxPacketSize. This case wasn't
taken into consideration before.

While at that, also make sure the ep->mult defaults
to one so drivers can use it unconditionally and
assume they'll never multiply ep->maxpacket to zero.

Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/usb/gadget/composite.c | 9 +++++++--
 drivers/usb/gadget/uvc_video.c | 2 +-
 2 files changed, 8 insertions(+), 3 deletions(-)

diff --git a/drivers/usb/gadget/composite.c b/drivers/usb/gadget/composite.c
index 584e43c..00c03c7 100644
--- a/drivers/usb/gadget/composite.c
+++ b/drivers/usb/gadget/composite.c
@@ -129,7 +129,12 @@ ep_found:
 	_ep->desc = chosen_desc;
 	_ep->comp_desc = NULL;
 	_ep->maxburst = 0;
-	_ep->mult = 0;
+	_ep->mult = 1;
+
+	if (g->speed == USB_SPEED_HIGH && (usb_endpoint_xfer_isoc(_ep->desc) ||
+				usb_endpoint_xfer_int(_ep->desc)))
+		_ep->mult = ((usb_endpoint_maxp(_ep->desc) & 0x1800) >> 11) + 1;
+
 	if (!want_comp_desc)
 		return 0;
 
@@ -146,7 +151,7 @@ ep_found:
 		switch (usb_endpoint_type(_ep->desc)) {
 		case USB_ENDPOINT_XFER_ISOC:
 			/* mult: bits 1:0 of bmAttributes */
-			_ep->mult = comp_desc->bmAttributes & 0x3;
+			_ep->mult = (comp_desc->bmAttributes & 0x3) + 1;
 		case USB_ENDPOINT_XFER_BULK:
 		case USB_ENDPOINT_XFER_INT:
 			_ep->maxburst = comp_desc->bMaxBurst + 1;
diff --git a/drivers/usb/gadget/uvc_video.c b/drivers/usb/gadget/uvc_video.c
index 71e896d..43e8c65 100644
--- a/drivers/usb/gadget/uvc_video.c
+++ b/drivers/usb/gadget/uvc_video.c
@@ -240,7 +240,7 @@ uvc_video_alloc_requests(struct uvc_video *video)
 
 	req_size = video->ep->maxpacket
 		 * max_t(unsigned int, video->ep->maxburst, 1)
-		 * (video->ep->mult + 1);
+		 * (video->ep->mult);
 
 	for (i = 0; i < UVC_NUM_REQUESTS; ++i) {
 		video->req_buffer[i] = kmalloc(req_size, GFP_KERNEL);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669773 — [PATCH 3.10 064/268] ssb: Fix error routine when fallback SPROM fails

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 064/268] ssb: Fix error routine when fallback SPROM fails
Message-ID<tUano-6Mf-37@gated-at.bofh.it>
In reply to#1669592
From: Larry Finger <Larry.Finger@lwfinger.net>

commit 8052d7245b6089992343c80b38b14dbbd8354651 upstream.

When there is a CRC error in the SPROM read from the device, the code
attempts to handle a fallback SPROM. When this also fails, the driver
returns zero rather than an error code.

Signed-off-by: Larry Finger <Larry.Finger@lwfinger.net>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/ssb/pci.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/ssb/pci.c b/drivers/ssb/pci.c
index a8dc95e..7700cef 100644
--- a/drivers/ssb/pci.c
+++ b/drivers/ssb/pci.c
@@ -846,6 +846,7 @@ static int ssb_pci_sprom_get(struct ssb_bus *bus,
 			if (err) {
 				ssb_warn("WARNING: Using fallback SPROM failed (err %d)\n",
 					 err);
+				goto out_free;
 			} else {
 				ssb_dbg("Using SPROM revision %d provided by platform\n",
 					sprom->revision);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669774 — [PATCH 3.10 215/268] rtc: s35390a: improve irq handling

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 215/268] rtc: s35390a: improve irq handling
Message-ID<tUano-6Mf-31@gated-at.bofh.it>
In reply to#1669592
From: Uwe Kleine-König <uwe@kleine-koenig.org>

commit 3bd32722c827d00eafe8e6d5b83e9f3148ea7c7e upstream.

On some QNAP NAS devices the rtc can wake the machine. Several people
noticed that once the machine was woken this way it fails to shut down.
That's because the driver fails to acknowledge the interrupt and so it
keeps active and restarts the machine immediatly after shutdown. See
https://bugs.debian.org/794266 for a bug report.

Doing this correctly requires to interpret the INT2 flag of the first read
of the STATUS1 register because this bit is cleared by read.

Note this is not maximally robust though because a pending irq isn't
detected when the STATUS1 register was already read (and so INT2 is not
set) but the irq was not disabled. But that is a hardware imposed problem
that cannot easily be fixed by software.

Signed-off-by: Uwe Kleine-König <uwe@kleine-koenig.org>
Signed-off-by: Alexandre Belloni <alexandre.belloni@free-electrons.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/rtc/rtc-s35390a.c | 48 ++++++++++++++++++++++++++++++-----------------
 1 file changed, 31 insertions(+), 17 deletions(-)

diff --git a/drivers/rtc/rtc-s35390a.c b/drivers/rtc/rtc-s35390a.c
index ff6e7b4..b6e220f 100644
--- a/drivers/rtc/rtc-s35390a.c
+++ b/drivers/rtc/rtc-s35390a.c
@@ -35,10 +35,14 @@
 #define S35390A_ALRM_BYTE_HOURS	1
 #define S35390A_ALRM_BYTE_MINS	2
 
+/* flags for STATUS1 */
 #define S35390A_FLAG_POC	0x01
 #define S35390A_FLAG_BLD	0x02
+#define S35390A_FLAG_INT2	0x04
 #define S35390A_FLAG_24H	0x40
 #define S35390A_FLAG_RESET	0x80
+
+/* flag for STATUS2 */
 #define S35390A_FLAG_TEST	0x01
 
 #define S35390A_INT2_MODE_MASK		0xF0
@@ -386,11 +390,11 @@ static struct i2c_driver s35390a_driver;
 static int s35390a_probe(struct i2c_client *client,
 			 const struct i2c_device_id *id)
 {
-	int err;
+	int err, err_reset;
 	unsigned int i;
 	struct s35390a *s35390a;
 	struct rtc_time tm;
-	char buf[1], status1;
+	char buf, status1;
 
 	if (!i2c_check_functionality(client->adapter, I2C_FUNC_I2C)) {
 		err = -ENODEV;
@@ -419,29 +423,35 @@ static int s35390a_probe(struct i2c_client *client,
 		}
 	}
 
-	err = s35390a_reset(s35390a, &status1);
-	if (err < 0) {
+	err_reset = s35390a_reset(s35390a, &status1);
+	if (err_reset < 0) {
+		err = err_reset;
 		dev_err(&client->dev, "error resetting chip\n");
 		goto exit_dummy;
 	}
 
-	err = s35390a_disable_test_mode(s35390a);
-	if (err < 0) {
-		dev_err(&client->dev, "error disabling test mode\n");
-		goto exit_dummy;
-	}
-
-	err = s35390a_get_reg(s35390a, S35390A_CMD_STATUS1, buf, sizeof(buf));
-	if (err < 0) {
-		dev_err(&client->dev, "error checking 12/24 hour mode\n");
-		goto exit_dummy;
-	}
-	if (buf[0] & S35390A_FLAG_24H)
+	if (status1 & S35390A_FLAG_24H)
 		s35390a->twentyfourhour = 1;
 	else
 		s35390a->twentyfourhour = 0;
 
-	if (s35390a_get_datetime(client, &tm) < 0)
+	if (status1 & S35390A_FLAG_INT2) {
+		/* disable alarm (and maybe test mode) */
+		buf = 0;
+		err = s35390a_set_reg(s35390a, S35390A_CMD_STATUS2, &buf, 1);
+		if (err < 0) {
+			dev_err(&client->dev, "error disabling alarm");
+			goto exit_dummy;
+		}
+	} else {
+		err = s35390a_disable_test_mode(s35390a);
+		if (err < 0) {
+			dev_err(&client->dev, "error disabling test mode\n");
+			goto exit_dummy;
+		}
+	}
+
+	if (err_reset > 0 || s35390a_get_datetime(client, &tm) < 0)
 		dev_warn(&client->dev, "clock needs to be set\n");
 
 	device_set_wakeup_capable(&client->dev, 1);
@@ -454,6 +464,10 @@ static int s35390a_probe(struct i2c_client *client,
 		err = PTR_ERR(s35390a->rtc);
 		goto exit_dummy;
 	}
+
+	if (status1 & S35390A_FLAG_INT2)
+		rtc_update_irq(s35390a->rtc, 1, RTC_AF);
+
 	return 0;
 
 exit_dummy:
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669776 — [PATCH 3.10 029/268] can: raw: raw_setsockopt: limit number of can_filter that can be set

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 029/268] can: raw: raw_setsockopt: limit number of can_filter that can be set
Message-ID<tUanp-6Mf-43@gated-at.bofh.it>
In reply to#1669592
From: Marc Kleine-Budde <mkl@pengutronix.de>

commit 332b05ca7a438f857c61a3c21a88489a21532364 upstream.

This patch adds a check to limit the number of can_filters that can be
set via setsockopt on CAN_RAW sockets. Otherwise allocations > MAX_ORDER
are not prevented resulting in a warning.

Reference: https://lkml.org/lkml/2016/12/2/230

Reported-by: Andrey Konovalov <andreyknvl@google.com>
Tested-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 include/uapi/linux/can.h | 1 +
 net/can/raw.c            | 3 +++
 2 files changed, 4 insertions(+)

diff --git a/include/uapi/linux/can.h b/include/uapi/linux/can.h
index e52958d..3018528 100644
--- a/include/uapi/linux/can.h
+++ b/include/uapi/linux/can.h
@@ -158,5 +158,6 @@ struct can_filter {
 };
 
 #define CAN_INV_FILTER 0x20000000U /* to be set in can_filter.can_id */
+#define CAN_RAW_FILTER_MAX 512 /* maximum number of can_filter set via setsockopt() */
 
 #endif /* CAN_H */
diff --git a/net/can/raw.c b/net/can/raw.c
index f4d8648..602be0e 100644
--- a/net/can/raw.c
+++ b/net/can/raw.c
@@ -470,6 +470,9 @@ static int raw_setsockopt(struct socket *sock, int level, int optname,
 		if (optlen % sizeof(struct can_filter) != 0)
 			return -EINVAL;
 
+		if (optlen > CAN_RAW_FILTER_MAX * sizeof(struct can_filter))
+			return -EINVAL;
+
 		count = optlen / sizeof(struct can_filter);
 
 		if (count > 1) {
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669777 — [PATCH 3.10 107/268] vmxnet3: Wake queue from reset work

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 107/268] vmxnet3: Wake queue from reset work
Message-ID<tUanp-6Mf-45@gated-at.bofh.it>
In reply to#1669592
From: Benjamin Poirier <bpoirier@suse.com>

commit 277964e19e1416ca31301e113edb2580c81a8b66 upstream.

vmxnet3_reset_work() expects tx queues to be stopped (via
vmxnet3_quiesce_dev -> netif_tx_disable). However, this races with the
netif_wake_queue() call in netif_tx_timeout() such that the driver's
start_xmit routine may be called unexpectedly, triggering one of the BUG_ON
in vmxnet3_map_pkt with a stack trace like this:

RIP: 0010:[<ffffffffa00cf4bc>] vmxnet3_map_pkt+0x3ac/0x4c0 [vmxnet3]
 [<ffffffffa00cf7e0>] vmxnet3_tq_xmit+0x210/0x4e0 [vmxnet3]
 [<ffffffff813ab144>] dev_hard_start_xmit+0x2e4/0x4c0
 [<ffffffff813c956e>] sch_direct_xmit+0x17e/0x1e0
 [<ffffffff813c96a7>] __qdisc_run+0xd7/0x130
 [<ffffffff813a6a7a>] net_tx_action+0x10a/0x200
 [<ffffffff810691df>] __do_softirq+0x11f/0x260
 [<ffffffff81472fdc>] call_softirq+0x1c/0x30
 [<ffffffff81004695>] do_softirq+0x65/0xa0
 [<ffffffff81069b89>] local_bh_enable_ip+0x99/0xa0
 [<ffffffffa031ff36>] destroy_conntrack+0x96/0x110 [nf_conntrack]
 [<ffffffff813d65e2>] nf_conntrack_destroy+0x12/0x20
 [<ffffffff8139c6d5>] skb_release_head_state+0xb5/0xf0
 [<ffffffff8139d299>] skb_release_all+0x9/0x20
 [<ffffffff8139cfe9>] __kfree_skb+0x9/0x90
 [<ffffffffa00d0069>] vmxnet3_quiesce_dev+0x209/0x340 [vmxnet3]
 [<ffffffffa00d020a>] vmxnet3_reset_work+0x6a/0xa0 [vmxnet3]
 [<ffffffff8107d7cc>] process_one_work+0x16c/0x350
 [<ffffffff810804fa>] worker_thread+0x17a/0x410
 [<ffffffff810848c6>] kthread+0x96/0xa0
 [<ffffffff81472ee4>] kernel_thread_helper+0x4/0x10

Signed-off-by: Benjamin Poirier <bpoirier@suse.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/net/vmxnet3/vmxnet3_drv.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/vmxnet3/vmxnet3_drv.c b/drivers/net/vmxnet3/vmxnet3_drv.c
index d081585..e782dd7 100644
--- a/drivers/net/vmxnet3/vmxnet3_drv.c
+++ b/drivers/net/vmxnet3/vmxnet3_drv.c
@@ -2862,7 +2862,6 @@ vmxnet3_tx_timeout(struct net_device *netdev)
 
 	netdev_err(adapter->netdev, "tx hang\n");
 	schedule_work(&adapter->work);
-	netif_wake_queue(adapter->netdev);
 }
 
 
@@ -2889,6 +2888,7 @@ vmxnet3_reset_work(struct work_struct *data)
 	}
 	rtnl_unlock();
 
+	netif_wake_queue(adapter->netdev);
 	clear_bit(VMXNET3_STATE_BIT_RESETTING, &adapter->state);
 }
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669778 — [PATCH 3.10 161/268] NFSv4: fix getacl ERANGE for some ACL buffer sizes

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 161/268] NFSv4: fix getacl ERANGE for some ACL buffer sizes
Message-ID<tUanp-6Mf-49@gated-at.bofh.it>
In reply to#1669592
From: Weston Andros Adamson <dros@primarydata.com>

commit ed92d8c137b7794c2c2aa14479298b9885967607 upstream.

We're not taking into account that the space needed for the (variable
length) attr bitmap, with the result that we'd sometimes get a spurious
ERANGE when the ACL data got close to the end of a page.

Just add in an extra page to make sure.

Signed-off-by: Weston Andros Adamson <dros@primarydata.com>
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
Signed-off-by: Anna Schumaker <Anna.Schumaker@Netapp.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/nfs/nfs4proc.c | 8 ++------
 1 file changed, 2 insertions(+), 6 deletions(-)

diff --git a/fs/nfs/nfs4proc.c b/fs/nfs/nfs4proc.c
index c2b89a1..c1148e8 100644
--- a/fs/nfs/nfs4proc.c
+++ b/fs/nfs/nfs4proc.c
@@ -4047,7 +4047,7 @@ out:
  */
 static ssize_t __nfs4_get_acl_uncached(struct inode *inode, void *buf, size_t buflen)
 {
-	struct page *pages[NFS4ACL_MAXPAGES] = {NULL, };
+	struct page *pages[NFS4ACL_MAXPAGES + 1] = {NULL, };
 	struct nfs_getaclargs args = {
 		.fh = NFS_FH(inode),
 		.acl_pages = pages,
@@ -4061,13 +4061,9 @@ static ssize_t __nfs4_get_acl_uncached(struct inode *inode, void *buf, size_t bu
 		.rpc_argp = &args,
 		.rpc_resp = &res,
 	};
-	unsigned int npages = DIV_ROUND_UP(buflen, PAGE_SIZE);
+	unsigned int npages = DIV_ROUND_UP(buflen, PAGE_SIZE) + 1;
 	int ret = -ENOMEM, i;
 
-	/* As long as we're doing a round trip to the server anyway,
-	 * let's be prepared for a page of acl data. */
-	if (npages == 0)
-		npages = 1;
 	if (npages > ARRAY_SIZE(pages))
 		return -ERANGE;
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669779 — [PATCH 3.10 228/268] mm/mempolicy.c: fix error handling in set_mempolicy and mbind.

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 228/268] mm/mempolicy.c: fix error handling in set_mempolicy and mbind.
Message-ID<tUanp-6Mf-47@gated-at.bofh.it>
In reply to#1669592
From: Chris Salls <salls@cs.ucsb.edu>

commit cf01fb9985e8deb25ccf0ea54d916b8871ae0e62 upstream.

In the case that compat_get_bitmap fails we do not want to copy the
bitmap to the user as it will contain uninitialized stack data and leak
sensitive data.

Signed-off-by: Chris Salls <salls@cs.ucsb.edu>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 mm/mempolicy.c | 20 ++++++++------------
 1 file changed, 8 insertions(+), 12 deletions(-)

diff --git a/mm/mempolicy.c b/mm/mempolicy.c
index b2061bb..e57c967 100644
--- a/mm/mempolicy.c
+++ b/mm/mempolicy.c
@@ -1537,7 +1537,6 @@ asmlinkage long compat_sys_get_mempolicy(int __user *policy,
 asmlinkage long compat_sys_set_mempolicy(int mode, compat_ulong_t __user *nmask,
 				     compat_ulong_t maxnode)
 {
-	long err = 0;
 	unsigned long __user *nm = NULL;
 	unsigned long nr_bits, alloc_size;
 	DECLARE_BITMAP(bm, MAX_NUMNODES);
@@ -1546,14 +1545,13 @@ asmlinkage long compat_sys_set_mempolicy(int mode, compat_ulong_t __user *nmask,
 	alloc_size = ALIGN(nr_bits, BITS_PER_LONG) / 8;
 
 	if (nmask) {
-		err = compat_get_bitmap(bm, nmask, nr_bits);
+		if (compat_get_bitmap(bm, nmask, nr_bits))
+			return -EFAULT;
 		nm = compat_alloc_user_space(alloc_size);
-		err |= copy_to_user(nm, bm, alloc_size);
+		if (copy_to_user(nm, bm, alloc_size))
+			return -EFAULT;
 	}
 
-	if (err)
-		return -EFAULT;
-
 	return sys_set_mempolicy(mode, nm, nr_bits+1);
 }
 
@@ -1561,7 +1559,6 @@ asmlinkage long compat_sys_mbind(compat_ulong_t start, compat_ulong_t len,
 			     compat_ulong_t mode, compat_ulong_t __user *nmask,
 			     compat_ulong_t maxnode, compat_ulong_t flags)
 {
-	long err = 0;
 	unsigned long __user *nm = NULL;
 	unsigned long nr_bits, alloc_size;
 	nodemask_t bm;
@@ -1570,14 +1567,13 @@ asmlinkage long compat_sys_mbind(compat_ulong_t start, compat_ulong_t len,
 	alloc_size = ALIGN(nr_bits, BITS_PER_LONG) / 8;
 
 	if (nmask) {
-		err = compat_get_bitmap(nodes_addr(bm), nmask, nr_bits);
+		if (compat_get_bitmap(nodes_addr(bm), nmask, nr_bits))
+			return -EFAULT;
 		nm = compat_alloc_user_space(alloc_size);
-		err |= copy_to_user(nm, nodes_addr(bm), alloc_size);
+		if (copy_to_user(nm, nodes_addr(bm), alloc_size))
+			return -EFAULT;
 	}
 
-	if (err)
-		return -EFAULT;
-
 	return sys_mbind(start, len, mode, nm, nr_bits+1, flags);
 }
 
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669780 — [PATCH 3.10 159/268] ath5k: drop bogus warning on drv_set_key with unsupported cipher

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 159/268] ath5k: drop bogus warning on drv_set_key with unsupported cipher
Message-ID<tUanp-6Mf-51@gated-at.bofh.it>
In reply to#1669592
From: Felix Fietkau <nbd@nbd.name>

commit a70e1d6fd6b5e1a81fa6171600942bee34f5128f upstream.

Simply return -EOPNOTSUPP instead.

Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Kalle Valo <kvalo@qca.qualcomm.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/net/wireless/ath/ath5k/mac80211-ops.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/drivers/net/wireless/ath/ath5k/mac80211-ops.c b/drivers/net/wireless/ath/ath5k/mac80211-ops.c
index 06f86f4..1b8422c 100644
--- a/drivers/net/wireless/ath/ath5k/mac80211-ops.c
+++ b/drivers/net/wireless/ath/ath5k/mac80211-ops.c
@@ -511,8 +511,7 @@ ath5k_set_key(struct ieee80211_hw *hw, enum set_key_cmd cmd,
 			break;
 		return -EOPNOTSUPP;
 	default:
-		WARN_ON(1);
-		return -EINVAL;
+		return -EOPNOTSUPP;
 	}
 
 	mutex_lock(&ah->lock);
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669781 — [PATCH 3.10 108/268] Fix memory leaks in cifs_do_mount()

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 108/268] Fix memory leaks in cifs_do_mount()
Message-ID<tUanp-6Mf-55@gated-at.bofh.it>
In reply to#1669592
From: Sachin Prabhu <sprabhu@redhat.com>

commit 4214ebf4654798309364d0c678b799e402f38288 upstream.

Fix memory leaks introduced by the patch
Fs/cifs: make share unaccessible at root level mountable

Also move allocation of cifs_sb->prepath to cifs_setup_cifs_sb().

Signed-off-by: Sachin Prabhu <sprabhu@redhat.com>
Tested-by: Aurelien Aptel <aaptel@suse.com>
Signed-off-by: Steve French <smfrench@gmail.com>
Acked-by: Aurelien Aptel <aaptel@suse.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 fs/cifs/cifsfs.c    | 20 ++++++++------------
 fs/cifs/cifsproto.h |  2 +-
 fs/cifs/connect.c   | 11 ++++++++++-
 3 files changed, 19 insertions(+), 14 deletions(-)

diff --git a/fs/cifs/cifsfs.c b/fs/cifs/cifsfs.c
index 134607d..191ef6e 100644
--- a/fs/cifs/cifsfs.c
+++ b/fs/cifs/cifsfs.c
@@ -644,26 +644,22 @@ cifs_do_mount(struct file_system_type *fs_type,
 	cifs_sb->mountdata = kstrndup(data, PAGE_SIZE, GFP_KERNEL);
 	if (cifs_sb->mountdata == NULL) {
 		root = ERR_PTR(-ENOMEM);
-		goto out_cifs_sb;
+		goto out_free;
 	}
 
-	if (volume_info->prepath) {
-		cifs_sb->prepath = kstrdup(volume_info->prepath, GFP_KERNEL);
-		if (cifs_sb->prepath == NULL) {
-			root = ERR_PTR(-ENOMEM);
-			goto out_cifs_sb;
-		}
+	rc = cifs_setup_cifs_sb(volume_info, cifs_sb);
+	if (rc) {
+		root = ERR_PTR(rc);
+		goto out_free;
 	}
 
-	cifs_setup_cifs_sb(volume_info, cifs_sb);
-
 	rc = cifs_mount(cifs_sb, volume_info);
 	if (rc) {
 		if (!(flags & MS_SILENT))
 			cifs_dbg(VFS, "cifs_mount failed w/return code = %d\n",
 				 rc);
 		root = ERR_PTR(rc);
-		goto out_mountdata;
+		goto out_free;
 	}
 
 	mnt_data.vol = volume_info;
@@ -710,9 +706,9 @@ out:
 	cifs_cleanup_volume_info(volume_info);
 	return root;
 
-out_mountdata:
+out_free:
+	kfree(cifs_sb->prepath);
 	kfree(cifs_sb->mountdata);
-out_cifs_sb:
 	kfree(cifs_sb);
 out_nls:
 	unload_nls(volume_info->local_nls);
diff --git a/fs/cifs/cifsproto.h b/fs/cifs/cifsproto.h
index 1194a8b..871a309 100644
--- a/fs/cifs/cifsproto.h
+++ b/fs/cifs/cifsproto.h
@@ -174,7 +174,7 @@ extern int cifs_read_from_socket(struct TCP_Server_Info *server, char *buf,
 extern int cifs_readv_from_socket(struct TCP_Server_Info *server,
 		struct kvec *iov_orig, unsigned int nr_segs,
 		unsigned int to_read);
-extern void cifs_setup_cifs_sb(struct smb_vol *pvolume_info,
+extern int cifs_setup_cifs_sb(struct smb_vol *pvolume_info,
 			       struct cifs_sb_info *cifs_sb);
 extern int cifs_match_super(struct super_block *, void *);
 extern void cifs_cleanup_volume_info(struct smb_vol *pvolume_info);
diff --git a/fs/cifs/connect.c b/fs/cifs/connect.c
index ece9071..660c471 100644
--- a/fs/cifs/connect.c
+++ b/fs/cifs/connect.c
@@ -3178,7 +3178,7 @@ void reset_cifs_unix_caps(unsigned int xid, struct cifs_tcon *tcon,
 	}
 }
 
-void cifs_setup_cifs_sb(struct smb_vol *pvolume_info,
+int cifs_setup_cifs_sb(struct smb_vol *pvolume_info,
 			struct cifs_sb_info *cifs_sb)
 {
 	INIT_DELAYED_WORK(&cifs_sb->prune_tlinks, cifs_prune_tlinks);
@@ -3260,6 +3260,15 @@ void cifs_setup_cifs_sb(struct smb_vol *pvolume_info,
 
 	if ((pvolume_info->cifs_acl) && (pvolume_info->dynperm))
 		cifs_dbg(VFS, "mount option dynperm ignored if cifsacl mount option supported\n");
+
+
+	if (pvolume_info->prepath) {
+		cifs_sb->prepath = kstrdup(pvolume_info->prepath, GFP_KERNEL);
+		if (cifs_sb->prepath == NULL)
+			return -ENOMEM;
+	}
+
+	return 0;
 }
 
 static void
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


#1669782 — [PATCH 3.10 068/268] scsi: don't BUG_ON() empty DMA transfers

FromWilly Tarreau <w@1wt.eu>
Date2017-06-19 21:20 +0200
Subject[PATCH 3.10 068/268] scsi: don't BUG_ON() empty DMA transfers
Message-ID<tUanp-6Mf-57@gated-at.bofh.it>
In reply to#1669592
From: Johannes Thumshirn <jthumshirn@suse.de>

commit fd3fc0b4d7305fa7246622dcc0dec69c42443f45 upstream.

Don't crash the machine just because of an empty transfer. Use WARN_ON()
combined with returning an error.

Found by Dmitry Vyukov and syzkaller.

[ Changed to "WARN_ON_ONCE()". Al has a patch that should fix the root
  cause, but a BUG_ON() is not acceptable in any case, and a WARN_ON()
  might still be a cause of excessive log spamming.

  NOTE! If this warning ever triggers, we may end up leaking resources,
  since this doesn't bother to try to clean the command up. So this
  WARN_ON_ONCE() triggering does imply real problems. But BUG_ON() is
  much worse.

  People really need to stop using BUG_ON() for "this shouldn't ever
  happen". It makes pretty much any bug worse.     - Linus ]

Signed-off-by: Johannes Thumshirn <jthumshirn@suse.de>
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Cc: James Bottomley <jejb@linux.vnet.ibm.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/scsi/scsi_lib.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/scsi/scsi_lib.c b/drivers/scsi/scsi_lib.c
index 26e1afe..dc1c2f4 100644
--- a/drivers/scsi/scsi_lib.c
+++ b/drivers/scsi/scsi_lib.c
@@ -1011,7 +1011,8 @@ int scsi_init_io(struct scsi_cmnd *cmd, gfp_t gfp_mask)
 	struct request *rq = cmd->request;
 	int error;
 
-	BUG_ON(!rq->nr_phys_segments);
+	if (WARN_ON_ONCE(!rq->nr_phys_segments))
+		return -EINVAL;
 
 	error = scsi_init_sgtable(rq, &cmd->sdb, gfp_mask);
 	if (error)
-- 
2.8.0.rc2.1.gbe9624a

[toc] | [prev] | [next] | [standalone]


Page 8 of 14 — ← Prev page 1 … 6 7 [8] 9 10 … 14  Next page →

Back to top | Article view | linux.kernel


csiph-web