Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1581976 > unrolled thread

[PATCH 3.2 000/126] 3.2.85-rc1 review

Started byBen Hutchings <ben@decadent.org.uk>
First post2017-02-16 00:40 +0100
Last post2017-02-16 17:00 +0100
Articles 20 on this page of 56 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.2 000/126] 3.2.85-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 00:40 +0100
    [PATCH 3.2 111/126] lockdep: Silence warning if CONFIG_LOCKDEP  isn't set Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 00:40 +0100
    [PATCH 3.2 095/126] locking/rtmutex: Prevent dequeue vs. unlock race Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 00:40 +0100
    [PATCH 3.2 057/126] scsi: arcmsr: Send SYNCHRONIZE_CACHE command  to firmware Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 00:40 +0100
    [PATCH 3.2 110/126] perf: Fix perf_event_for_each() to use sibling Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 00:40 +0100
    [PATCH 3.2 098/126] net: ping: check minimum size on ICMP header  length Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 00:40 +0100
    [PATCH 3.2 114/126] perf/core: Fix concurrent sys_perf_event_open()  vs. 'move_group' race Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 00:40 +0100
      Re: [PATCH 3.2 114/126] perf/core: Fix concurrent  sys_perf_event_open() vs. 'move_group' race Ben Hutchings <ben@decadent.org.uk> - 2017-02-21 01:50 +0100
    [PATCH 3.2 085/126] Fix USB CB/CBI storage devices with  CONFIG_VMAP_STACK=y Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 00:50 +0100
    [PATCH 3.2 124/126] sg_write()/bsg_write() is not fit to be  called under KERNEL_DS Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 00:50 +0100
    [PATCH 3.2 053/126] scsi: megaraid_sas: Fix data integrity  failure for JBOD (passthrough) devices Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 00:50 +0100
    [PATCH 3.2 112/126] perf: Fix event->ctx locking Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 00:50 +0100
    [PATCH 3.2 089/126] IB/uverbs: Fix leak of XRC target QPs Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 00:50 +0100
    [PATCH 3.2 037/126] fuse: fix killing s[ug]id in setattr Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 026/126] net/mlx4_core: Fix deadlock when switching  between polling and event fw commands Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 047/126] ubifs: Abort readdir upon error Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 003/126] zfcp: fix ELS/GS request&response length for  hardware data router Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 065/126] ubifs: Fix regression in ubifs_readdir() Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 046/126] ubifs: Fix xattr_names length in exit paths Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 039/126] crypto: gcm - Fix IV buffer size in  crypto_gcm_setkey Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 015/126] [media] mb86a20s: fix the locking logic Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 049/126] batman-adv: fix splat on disabling an interface Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
      Re: [PATCH 3.2 049/126] batman-adv: fix splat on disabling an  interface Linus Lüssing <linus.luessing@c0d3.blue> - 2017-02-16 08:00 +0100
        Re: [PATCH 3.2 049/126] batman-adv: fix splat on disabling an  interface Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 17:10 +0100
    [PATCH 3.2 005/126] zfcp: retain trace level for SCSI and HBA FSF  response records Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 032/126] powerpc/vdso64: Use double word compare on  pointers Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 027/126] ALSA: usb-audio: Extend DragonFly dB scale  quirk to cover other variants Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 061/126] vt: clear selection before resizing Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 040/126] powerpc/64: Fix incorrect return value from  __copy_tofrom_user Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 044/126] isofs: Do not return EACCES for unknown  filesystems Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 030/126] USB: serial: cp210x: Add ID for a Juniper console Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 034/126] s390/con3270: fix use of uninitialised data Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 016/126] [media] cx231xx: don't return error on success Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 033/126] ext4: release bh in make_indexed_dir Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 035/126] s390/con3270: fix insufficient space padding Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 024/126] ALSA: ali5451: Fix out-of-bound position  reporting Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:40 +0100
    [PATCH 3.2 010/126] zfcp: fix payload trace length for SAN  request&response Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 028/126] regulator: tps65910: Work around silicon  erratum SWCZ010 Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 008/126] zfcp: restore tracing of handle for port and  LUN with HBA records Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 022/126] scsi: ibmvfc: Fix I/O hang when port is not  mapped Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 004/126] zfcp: close window with unblocked rport  during rport gone Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 017/126] [media] cx231xx: fix GPIOs for Pixelview  SBTVD hybrid Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 029/126] mmc: block: don't use CMD23 with very old MMC  cards Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 014/126] rtlwifi: Fix missing country code for Great  Britain Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 011/126] zfcp: trace full payload of all SAN records  (req,resp,iels) Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 002/126] zfcp: fix fc_host port_type with NPIV Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 013/126] rtlwifi: Update regulatory database Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 006/126] zfcp: restore: Dont use 0 to indicate invalid  LUN in rec trace Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 009/126] zfcp: fix D_ID field with actual value on  tracing SAN responses Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 025/126] usb: misc: legousbtower: Fix NULL pointer  deference Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 038/126] fuse: listxattr: verify xattr list Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 043/126] scsi: zfcp: spin_lock_irqsave() is not nestable Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 036/126] fuse: invalidate dir dentry after chmod Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    [PATCH 3.2 019/126] reiserfs: Unlock superblock before calling  reiserfs_quota_on_mount() Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 01:50 +0100
    Re: [PATCH 3.2 000/126] 3.2.85-rc1 review Guenter Roeck <linux@roeck-us.net> - 2017-02-16 07:10 +0100
      Re: [PATCH 3.2 000/126] 3.2.85-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2017-02-16 17:00 +0100

Page 1 of 3  [1] 2 3  Next page →


#1581976 — [PATCH 3.2 000/126] 3.2.85-rc1 review

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 00:40 +0100
Subject[PATCH 3.2 000/126] 3.2.85-rc1 review
Message-ID<tbgIi-5XZ-3@gated-at.bofh.it>
This is the start of the stable review cycle for the 3.2.85 release.
There are 126 patches in this series, which will be posted as responses
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Thu Feb 23 00:00:00 UTC 2017.
Anything received after that time might be too late.

A combined patch relative to 3.2.84 will be posted as an additional
response to this.  A shortlog and diffstat can be found below.

I have not yet worked through commits marked with 'cc: stable' or
'fixed:' that were merged after 4.9, and I haven't checked through all
the direct requests for inclusion in stable.  So if a fix is missing
from this but it falls into those categories, please be patient and
let me know only if it's still missing in the next review cycle.

Ben.

-------------

Al Viro (1):
      sg_write()/bsg_write() is not fit to be called under KERNEL_DS
         [a0ac402cfcdc904f9772e1762b3fda112dcc56a0]

Andrey Ryabinin (1):
      coredump: fix unfreezable coredumping task
         [70d78fe7c8b640b5acfad56ad341985b3810998a]

Anssi Hannula (1):
      ALSA: usb-audio: Extend DragonFly dB scale quirk to cover other variants
         [eb1a74b7bea17eea31915c4f76385cefe69d9795]

Anton Blanchard (1):
      powerpc/vdso64: Use double word compare on pointers
         [5045ea37377ce8cca6890d32b127ad6770e6dce5]

Arnd Bergmann (1):
      staging: iio: ad5933: avoid uninitialized variable in error case
         [34eee70a7b82b09dbda4cb453e0e21d460dae226]

Baoquan He (1):
      iommu/amd: Free domain id when free a domain of struct dma_ops_domain
         [c3db901c54466a9c135d1e6e95fec452e8a42666]

Ben Hutchings (1):
      net: Add __sock_queue_rcv_skb()
         [e6afc8ace6dd5cef5e812f26c72579da8806f5ac]

Benjamin Tissoires (1):
      HID: core: prevent out-of-bound readings
         [50220dead1650609206efe91f0cc116132d59b3f]

Brian King (1):
      scsi: ibmvfc: Fix I/O hang when port is not mapped
         [07d0e9a847401ffd2f09bd450d41644cd090e81d]

Brian Norris (1):
      mwifiex: printk() overflow with 32-byte SSIDs
         [fcd2042e8d36cf644bd2d69c26378d17158b17df]

Calvin Owens (1):
      sg: Fix double-free when drives detach during SG_IO
         [f3951a3709ff50990bf3e188c27d346792103432]

Ching Huang (1):
      scsi: arcmsr: Send SYNCHRONIZE_CACHE command to firmware
         [2bf7dc8443e113844d078fd6541b7f4aa544f92f]

Daeho Jeong (1):
      ext4: reinforce check of i_dtime when clearing high fields of uid and gid
         [93e3b4e6631d2a74a8cf7429138096862ff9f452]

Dan Carpenter (3):
      [media] media: info leak in __media_device_enum_links()
         [c88e739b1fad662240e99ecbd0bdaac871717987]
      scsi: zfcp: spin_lock_irqsave() is not nestable
         [e7cb08e894a0b876443ef8fdb0706575dc00a5d2]
      ser_gigaset: return -ENOMEM on error instead of success
         [93a97c50cbf1c007caf12db5cc23e0d5b9c8473c]

Daniel Glöckner (1):
      mmc: block: don't use CMD23 with very old MMC cards
         [0ed50abb2d8fc81570b53af25621dad560cd49b3]

Daniel Mentz (1):
      lib/genalloc.c: start search from start of chunk
         [62e931fac45b17c2a42549389879411572f75804]

Dmitry Vyukov (1):
      tty: limit terminal size to 4M chars
         [32b2921e6a7461fe63b71217067a6cf4bddb132f]

Doug Brown (1):
      USB: serial: ftdi_sio: add support for TI CC3200 LaunchPad
         [9bfef729a3d11f04d12788d749a3ce6b47645734]

Eli Cooper (1):
      ip6_tunnel: Clear IP6CB in ip6tunnel_xmit()
         [23f4ffedb7d751c7e298732ba91ca75d224bc1a6]

Erez Shitrit (1):
      net/mlx4_en: Process all completions in RX rings after port goes up
         [8d59de8f7bb3db296331c665779c653b0c8d13ba]

Eric Dumazet (4):
      ipv6: dccp: add missing bind_conflict to dccp_ipv6_mapped
         [990ff4d84408fc55942ca6644f67e361737b3d8e]
      net: avoid signed overflows for SO_{SND|RCV}BUFFORCE
         [b98b0bc8c431e3ceb4b26b0dfc8db509518fb290]
      net: cleanups in sock_setsockopt()
         [82981930125abfd39d7c8378a9cfdf5e1be2002b]
      tcp: take care of truncations done by sk_filter()
         [ac6e780070e30e4c35bd395acfe9191e6268bdd3]

Ewan D. Milne (1):
      scsi: scsi_debug: Fix memory leak if LBP enabled and module is unloaded
         [4d2b496f19f3c2cfaca1e8fa0710688b5ff3811d]

Fabio Estevam (1):
      mmc: mxs: Initialize the spinlock prior to using it
         [f91346e8b5f46aaf12f1df26e87140584ffd1b3f]

Felipe Balbi (1):
      usb: gadget: u_ether: remove interrupt throttling
         [fd9afd3cbe404998d732be6cc798f749597c5114]

Florian Fainelli (1):
      net: ep93xx_eth: Do not crash unloading module
         [c823abac17926767fb50175e098f087a6ac684c3]

Florian Westphal (1):
      netfilter: restart search if moved to other chain
         [95a8d19f28e6b29377a880c6264391a62e07fccc]

Gmail (1):
      ext4: release bh in make_indexed_dir
         [e81d44778d1d57bbaef9e24c4eac7c8a7a401d40]

Greg Kroah-Hartman (1):
      usb: misc: legousbtower: Fix NULL pointer deference
         [2fae9e5a7babada041e2e161699ade2447a01989]

Hangbin Liu (1):
      igmp: do not remove igmp souce list info when set link down
         [24803f38a5c0b6c57ed800b47e695f9ce474bc3a]

Ido Yariv (1):
      KVM: x86: fix wbinvd_dirty_mask use-after-free
         [bd768e146624cbec7122ed15dead8daa137d909d]

Ignacio Alvarado (1):
      KVM: Disable irq while unregistering user notifier
         [1650b4ebc99da4c137bfbfc531be4a2405f951dd]

Jack Morgenstein (1):
      net/mlx4_core: Fix deadlock when switching between polling and event fw commands
         [a7e1f04905e5b2b90251974dddde781301b6be37]

Jakub Sitnicki (1):
      ipv6: Don't use ufo handling on later transformed packets
         [f89c56ce710afa65e1b2ead555b52c4807f34ff7]

Jan Kara (1):
      isofs: Do not return EACCES for unknown filesystems
         [a2ed0b391dd9c3ef1d64c7c3e370f4a5ffcd324a]

Jan Remmet (1):
      regulator: tps65910: Work around silicon erratum SWCZ010
         [8f9165c981fed187bb483de84caf9adf835aefda]

Jann Horn (1):
      swapfile: fix memory corruption via malformed swapfile
         [dd111be69114cc867f8e826284559bfbc1c40e37]

Jiri Slaby (1):
      tty: vt, fix bogus division in csi_J
         [42acfc6615f47e465731c263bee0c799edb098f2]

Johan Hovold (2):
      mfd: core: Fix device reference leak in mfd_clone_cell
         [722f191080de641f023feaa7d5648caf377844f5]
      uwb: fix device reference leaks
         [d6124b409ca33c100170ffde51cd8dff761454a1]

Johannes Berg (1):
      mac80211: discard multicast and 4-addr A-MSDUs
         [ea720935cf6686f72def9d322298bf7e9bd53377]

John David Anglin (1):
      parisc: Ensure consistent state when switching to kernel stack at syscall entry
         [6ed518328d0189e0fdf1bb7c73290d546143ea66]

Kashyap Desai (1):
      scsi: megaraid_sas: Fix data integrity failure for JBOD (passthrough) devices
         [1e793f6fc0db920400574211c48f9157a37e3945]

Kees Cook (2):
      fbdev: color map copying bounds checking
         [2dc705a9930b4806250fbf5a76e55266e59389f2]
      net: ping: check minimum size on ICMP header length
         [0eab121ef8750a5c8637d51534d5e9143fb0633f]

Kyle Jones (1):
      USB: serial: cp210x: Add ID for a Juniper console
         [decc5360f23e9efe0252094f47f57f254dcbb3a9]

Larry Finger (1):
      rtlwifi: Fix missing country code for Great Britain
         [0c9d3491530773858ff9d705ec2a9c382f449230]

Laura Abbott (1):
      HID: usbhid: Add HID_QUIRK_NOGET for Aten DVI KVM switch
         [849eca7b9dae0364e2fbe8afdf0fb610d12c9c8f]

Linus Lüssing (1):
      batman-adv: fix splat on disabling an interface
         [9799c50372b23ed774791bdb87d700f1286ee8a9]

Linus Torvalds (1):
      Fix potential infoleak in older kernels
         [1c109fabbd51863475cd12ac206bdd249aee35af]

Long Li (1):
      hv: do not lose pending heartbeat vmbus packets
         [407a3aee6ee2d2cb46d9ba3fc380bc29f35d020c]

Marc Kleine-Budde (1):
      can: raw: raw_setsockopt: limit number of can_filter that can be set
         [332b05ca7a438f857c61a3c21a88489a21532364]

Marcel Hasler (1):
      ALSA: usb-audio: Add quirk for Syntek STK1160
         [bdc3478f90cd4d2928197f36629d5cf93b64dbe9]

Marcelo Ricardo Leitner (1):
      sctp: validate chunk len before actually using it
         [bf911e985d6bbaa328c20c3e05f4eb03de11fdd6]

Matan Barak (1):
      IB/mlx4: Fix create CQ error flow
         [593ff73bcfdc79f79a8a0df55504f75ad3e5d1a9]

Mathias Krause (1):
      rtnl: reset calcit fptr in rtnl_unregister()
         [f567e950bf51290755a2539ff2aaef4c26f735d3]

Mathias Nyman (1):
      xhci: add restart quirk for Intel Wildcatpoint PCH
         [4c39135aa412d2f1381e43802523da110ca7855c]

Mauro Carvalho Chehab (3):
      [media] cx231xx: don't return error on success
         [1871d718a9db649b70f0929d2778dc01bc49b286]
      [media] cx231xx: fix GPIOs for Pixelview SBTVD hybrid
         [24b923f073ac37eb744f56a2c7f77107b8219ab2]
      [media] mb86a20s: fix the locking logic
         [dafb65fb98d85d8e78405e82c83e81975e5d5480]

Max Staudt (1):
      fbdev/efifb: Fix 16 color palette entry calculation
         [d50b3f43db739f03fcf8c0a00664b3d2fed0496e]

Michael Ellerman (1):
      perf: Fix perf_event_for_each() to use sibling
         [724b6daa13e100067c30cfc4d1ad06629609dc4e]

Michal Kubeček (1):
      tipc: check minimum bearer MTU
         [3de81b758853f0b29c61e246679d20b513c4cfec]

Mike Galbraith (1):
      reiserfs: Unlock superblock before calling reiserfs_quota_on_mount()
         [420902c9d086848a7548c83e0a49021514bd71b7]

Miklos Szeredi (4):
      fuse: fix clearing suid, sgid for chown()
         [c01638f5d919728f565bf8b5e0a6a159642df0d9]
      fuse: fix killing s[ug]id in setattr
         [a09f99eddef44035ec764075a37bace8181bec38]
      fuse: invalidate dir dentry after chmod
         [5e2b8828ff3d79aca8c3a1730652758753205b61]
      fuse: listxattr: verify xattr list
         [cb3ae6d25a5471be62bfe6ac1fccc0e91edeaba0]

Ming Lei (1):
      scsi: Fix use-after-free
         [bcd8f2e94808fcddf6ef3af5f060a36820dcc432]

Oliver Hartkopp (1):
      can: bcm: fix warning in bcm_connect/proc_register
         [deb507f91f1adbf64317ad24ac46c56eeccfb754]

Oliver Neukum (1):
      HID: usbhid: add ATEN CS962 to list of quirky devices
         [cf0ea4da4c7df11f7a508b2f37518e0f117f3791]

Omar Sandoval (1):
      block: fix use-after-free in sys_ioprio_get()
         [8ba8682107ee2ca3347354e018865d8e1967c5f4]

Ondrej Mosnáček (1):
      crypto: gcm - Fix IV buffer size in crypto_gcm_setkey
         [50d2e6dc1f83db0563c7d6603967bf9585ce934b]

Pan Xinhui (1):
      powerpc/nvram: Fix an incorrect partition merge
         [11b7e154b132232535befe51c55db048069c8461]

Patrick Scheuring (1):
      Input: i8042 - add XMG C504 to keyboard reset table
         [da25311c7ca8b0254a686fc0d597075b9aa3b683]

Paul Bolle (1):
      lockdep: Silence warning if CONFIG_LOCKDEP isn't set
         [5cd3f5affad2109fd1458aab3f6216f2181e26ea]

Paul Jakma (1):
      USB: serial: cp210x: add ID for the Zone DPMX
         [2ab13292d7a314fa45de0acc808e41aaad31989c]

Paul Mackerras (1):
      powerpc/64: Fix incorrect return value from __copy_tofrom_user
         [1a34439e5a0b2235e43f96816dbb15ee1154f656]

Peter Hurley (1):
      tty: Prevent ldisc drivers from re-using stale tty fields
         [dd42bf1197144ede075a9d4793123f7689e164bc]

Peter Zijlstra (4):
      perf/core: Fix concurrent sys_perf_event_open() vs. 'move_group' race
         [321027c1fe77f892f4ea07846aeae08cefbbb290]
      perf: Do not double free
         [130056275ade730e7a79c110212c8815202773ee]
      perf: Fix event->ctx locking
         [f63a8daa5812afef4f06c962351687e1ff9ccb2b]
      perf: Fix race in swevent hash
         [12ca6ad2e3a896256f086497a7c7406a547ee373]

Petr Vandrovec (1):
      Fix USB CB/CBI storage devices with CONFIG_VMAP_STACK=y
         [2ce9d2272b98743b911196c49e7af5841381c206]

Philip Pettersson (1):
      packet: fix race condition in packet_set_ring
         [84ac7260236a49c79eede91617700174c2c19b0c]

Punit Agrawal (1):
      ACPI / APEI: Fix incorrect return value of ghes_proc()
         [806487a8fc8f385af75ed261e9ab658fc845e633]

Radim Krčmář (1):
      KVM: x86: drop error recovery in em_jmp_far and em_ret_far
         [2117d5398c81554fbf803f5fd1dc55eb78216c0c]

Richard Weinberger (3):
      ubifs: Abort readdir upon error
         [c83ed4c9dbb358b9e7707486e167e940d48bfeed]
      ubifs: Fix regression in ubifs_readdir()
         [a00052a296e54205cf238c75bd98d17d5d02a6db]
      ubifs: Fix xattr_names length in exit paths
         [843741c5778398ea67055067f4cc65ae6c80ca0e]

Russell King (1):
      ARM: dma-mapping: don't allow DMA mappings to be marked executable
         [0ea1ec713f04bdfac343c9702b21cd3a7c711826]

Sascha Silbe (2):
      s390/con3270: fix insufficient space padding
         [6cd997db911f28f2510b771691270c52b63ed2e6]
      s390/con3270: fix use of uninitialised data
         [c14f2aac7aa147861793eed9f41f91dd530f0be1]

Scot Doyle (1):
      vt: clear selection before resizing
         [009e39ae44f4191188aeb6dfbf661b771dbbe515]

Sean Young (1):
      dib0700: fix nec repeat handling
         [ba13e98f2cebd55a3744c5ffaa08f9dca73bf521]

Segher Boessenkool (1):
      powerpc: Convert cmp to cmpd in idle enter sequence
         [80f23935cadb1c654e81951f5a8b7ceae0acc1b4]

Shao Fu (1):
      rtlwifi: Update regulatory database
         [02b5fffbe9e02f5d63fa4a801fb807cf0aab4fc9]

Stefan Richter (1):
      firewire: net: fix fragmented datagram_size off-by-one
         [e9300a4b7bbae83af1f7703938c94cf6dc6d308f]

Steffen Maier (10):
      zfcp: close window with unblocked rport during rport gone
         [4eeaa4f3f1d6c47b69f70e222297a4df4743363e]
      zfcp: fix D_ID field with actual value on tracing SAN responses
         [771bf03537ddfa4a4dde62ef9dfbc82e4f77ab20]
      zfcp: fix ELS/GS request&response length for hardware data router
         [70369f8e15b220f50a16348c79a61d3f7054813c]
      zfcp: fix fc_host port_type with NPIV
         [bd77befa5bcff8c51613de271913639edf85fbc2]
      zfcp: fix payload trace length for SAN request&response
         [94db3725f049ead24c96226df4a4fb375b880a77]
      zfcp: restore tracing of handle for port and LUN with HBA records
         [7c964ffe586bc0c3d9febe9bf97a2e4b2866e5b7]
      zfcp: restore: Dont use 0 to indicate invalid LUN in rec trace
         [0102a30a6ff60f4bb4c07358ca3b1f92254a6c25]
      zfcp: retain trace level for SCSI and HBA FSF response records
         [35f040df97fa0e94c7851c054ec71533c88b4b81]
      zfcp: trace full payload of all SAN records (req,resp,iels)
         [aceeffbb59bb91404a0bda32a542d7ebf878433a]
      zfcp: trace on request for open and close of WKA port
         [d27a7cb91960cf1fdd11b10071e601828cbf4b1f]

Sumit Saxena (1):
      scsi: megaraid_sas: fix macro MEGASAS_IS_LOGICAL to avoid regression
         [5e5ec1759dd663a1d5a2f10930224dd009e500e8]

Takashi Iwai (2):
      ALSA: ali5451: Fix out-of-bound position reporting
         [db68577966abc1aeae4ec597b3dcfa0d56e92041]
      ALSA: pcm : Call kill_fasync() in stream lock
         [3aa02cb664c5fb1042958c8d1aa8c35055a2ebc4]

Tang.Junhui (1):
      dm table: fix missing dm_put_target_type() in dm_table_add_target()
         [dafa724bf582181d9a7d54f5cb4ca0bf8ef29269]

Tariq Toukan (1):
      IB/uverbs: Fix leak of XRC target QPs
         [5b810a242c28e1d8d64d718cebe75b79d86a0b2d]

Theodore Ts'o (1):
      ext4: sanity check the block and cluster size at mount time
         [8cdf3372fe8368f56315e66bea9f35053c418093]

Thomas Gleixner (1):
      locking/rtmutex: Prevent dequeue vs. unlock race
         [dbb26055defd03d59f678cb5f2c992abe05b064a]

Tilman Schmidt (1):
      isdn/gigaset: reset tty->receive_room when attaching ser_gigaset
         [fd98e9419d8d622a4de91f76b306af6aa627aa9c]

Trond Myklebust (1):
      NFSv4: Open state recovery must account for file permission changes
         [304020fe48c6c7fff8b5a38f382b54404f0f79d3]

Ulrich Weber (1):
      netfilter: nf_conntrack_sip: extend request line validation
         [444f901742d054a4cd5ff045871eac5131646cfb]

Vladimir Zapolskiy (1):
      i2c: core: fix NULL pointer dereference under race condition
         [147b36d5b70c083cc76770c47d60b347e8eaf231]

Willem de Bruijn (2):
      dccp: limit sk_filter trim to payload
         [4f0c40d94461cfd23893a17335b2ab78ecb333c8]
      rose: limit sk_filter trim to payload
         [f4979fcea7fd36d8e2f556abef86f80e0d5af1ba]

Xin Long (1):
      sctp: do not return the transmit err back to sctp_sendmsg
         [66388f2c08dfa38071f9eceae7bb29060d9be9aa]

 Makefile                                        |   4 +-
 arch/arm/mm/dma-mapping.c                       |   4 +-
 arch/parisc/kernel/syscall.S                    |  11 +-
 arch/powerpc/kernel/idle_power7.S               |   2 +-
 arch/powerpc/kernel/nvram_64.c                  |   6 +-
 arch/powerpc/kernel/vdso64/datapage.S           |   2 +-
 arch/powerpc/kernel/vdso64/gettimeofday.S       |   2 +-
 arch/powerpc/lib/copyuser_64.S                  |   2 +-
 arch/x86/include/asm/uaccess.h                  |  10 +-
 arch/x86/kvm/emulate.c                          |  36 +--
 arch/x86/kvm/x86.c                              |  17 +-
 block/bsg.c                                     |   3 +
 crypto/gcm.c                                    |   2 +-
 drivers/acpi/apei/ghes.c                        |   2 +-
 drivers/firewire/net.c                          |   8 +-
 drivers/hid/hid-core.c                          |   3 +
 drivers/hid/hid-ids.h                           |   2 +
 drivers/hid/usbhid/hid-quirks.c                 |   2 +
 drivers/hv/hv_util.c                            |  10 +-
 drivers/i2c/i2c-core.c                          |   2 +-
 drivers/infiniband/core/uverbs_main.c           |   7 +-
 drivers/infiniband/hw/mlx4/cq.c                 |   5 +-
 drivers/input/serio/i8042-x86ia64io.h           |   7 +
 drivers/iommu/amd_iommu.c                       |   3 +
 drivers/isdn/gigaset/ser-gigaset.c              |  15 +-
 drivers/md/dm-table.c                           |  24 +-
 drivers/media/dvb/dvb-usb/dib0700_core.c        |   5 +-
 drivers/media/dvb/frontends/mb86a20s.c          |  12 +-
 drivers/media/media-device.c                    |   3 +
 drivers/media/video/cx231xx/cx231xx-avcore.c    |   5 +-
 drivers/media/video/cx231xx/cx231xx-cards.c     |   2 +-
 drivers/media/video/cx231xx/cx231xx-core.c      |   3 +-
 drivers/mfd/mfd-core.c                          |   2 +
 drivers/mmc/card/block.c                        |   3 +-
 drivers/mmc/host/mxs-mmc.c                      |   4 +-
 drivers/net/ethernet/cirrus/ep93xx_eth.c        |   4 +
 drivers/net/ethernet/mellanox/mlx4/cmd.c        |  19 +-
 drivers/net/ethernet/mellanox/mlx4/en_netdev.c  |   7 +
 drivers/net/ethernet/mellanox/mlx4/mlx4.h       |   2 +
 drivers/net/wireless/mwifiex/cfg80211.c         |  13 +-
 drivers/net/wireless/rtlwifi/regd.c             |  46 +++-
 drivers/net/wireless/rtlwifi/regd.h             |   1 +
 drivers/regulator/tps65910-regulator.c          |   6 +
 drivers/s390/char/con3270.c                     |  11 +-
 drivers/s390/scsi/zfcp_dbf.c                    | 162 ++++++++++--
 drivers/s390/scsi/zfcp_dbf.h                    |  14 +-
 drivers/s390/scsi/zfcp_erp.c                    |  12 +-
 drivers/s390/scsi/zfcp_ext.h                    |   8 +-
 drivers/s390/scsi/zfcp_fsf.c                    |  22 +-
 drivers/s390/scsi/zfcp_fsf.h                    |   4 +-
 drivers/s390/scsi/zfcp_scsi.c                   |   8 +-
 drivers/scsi/arcmsr/arcmsr_hba.c                |   9 -
 drivers/scsi/ibmvscsi/ibmvfc.c                  |   1 -
 drivers/scsi/megaraid/megaraid_sas.h            |   2 +-
 drivers/scsi/megaraid/megaraid_sas_base.c       |  13 +-
 drivers/scsi/scsi_debug.c                       |   1 +
 drivers/scsi/scsi_scan.c                        |   2 +-
 drivers/scsi/sg.c                               |   8 +-
 drivers/staging/iio/impedance-analyzer/ad5933.c |  17 +-
 drivers/tty/tty_ldisc.c                         |   7 +
 drivers/tty/vt/vt.c                             |   7 +-
 drivers/usb/gadget/u_ether.c                    |   7 -
 drivers/usb/host/xhci-pci.c                     |   4 +-
 drivers/usb/misc/legousbtower.c                 |  35 ++-
 drivers/usb/serial/cp210x.c                     |   2 +
 drivers/usb/serial/ftdi_sio.c                   |   2 +
 drivers/usb/serial/ftdi_sio_ids.h               |   6 +
 drivers/usb/storage/transport.c                 |   7 +-
 drivers/uwb/lc-rc.c                             |  16 +-
 drivers/video/efifb.c                           |   6 +-
 drivers/video/fbcmap.c                          |  26 +-
 fs/exec.c                                       |   6 +-
 fs/ext4/ext4.h                                  |   1 +
 fs/ext4/inode.c                                 |   8 +-
 fs/ext4/namei.c                                 |  14 +-
 fs/ext4/super.c                                 |  17 +-
 fs/fuse/dir.c                                   |  63 ++++-
 fs/ioprio.c                                     |   2 +
 fs/isofs/inode.c                                |   8 +-
 fs/nfs/nfs4state.c                              |   3 +
 fs/reiserfs/super.c                             |  12 +-
 fs/ubifs/dir.c                                  |  16 +-
 fs/ubifs/xattr.c                                |   2 +
 include/linux/can.h                             |   1 +
 include/linux/filter.h                          |   6 +-
 include/linux/lockdep.h                         |   2 +-
 include/net/sock.h                              |  10 +-
 include/net/tcp.h                               |   1 +
 kernel/events/core.c                            | 315 +++++++++++++++++++-----
 kernel/rtmutex.c                                |  68 ++++-
 lib/genalloc.c                                  |   3 +-
 mm/swapfile.c                                   |   2 +
 net/batman-adv/hard-interface.c                 |   1 -
 net/can/bcm.c                                   |  32 ++-
 net/can/raw.c                                   |   3 +
 net/core/filter.c                               |  10 +-
 net/core/rtnetlink.c                            |   1 +
 net/core/sock.c                                 |  68 +++--
 net/dccp/ipv4.c                                 |   2 +-
 net/dccp/ipv6.c                                 |   3 +-
 net/ipv4/igmp.c                                 |  49 ++--
 net/ipv4/ping.c                                 |   4 +
 net/ipv4/tcp_ipv4.c                             |  19 +-
 net/ipv6/ip6_output.c                           |   2 +-
 net/ipv6/ip6_tunnel.c                           |   1 +
 net/ipv6/tcp_ipv6.c                             |   6 +-
 net/mac80211/rx.c                               |  24 +-
 net/netfilter/nf_conntrack_core.c               |   7 +
 net/netfilter/nf_conntrack_sip.c                |   5 +-
 net/packet/af_packet.c                          |  18 +-
 net/rose/rose_in.c                              |   3 +-
 net/sctp/sm_sideeffect.c                        |  16 +-
 net/sctp/sm_statefuns.c                         |  12 +-
 net/tipc/bearer.h                               |  16 ++
 net/tipc/eth_media.c                            |  12 +-
 sound/core/pcm_lib.c                            |   2 +-
 sound/pci/ali5451/ali5451.c                     |   2 +
 sound/usb/mixer_quirks.c                        |  22 +-
 sound/usb/quirks-table.h                        |  17 ++
 119 files changed, 1245 insertions(+), 419 deletions(-)

-- 
Ben Hutchings
Lowery's Law:
             If it jams, force it. If it breaks, it needed replacing anyway.

[toc] | [next] | [standalone]


#1581977 — [PATCH 3.2 111/126] lockdep: Silence warning if CONFIG_LOCKDEP isn't set

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 00:40 +0100
Subject[PATCH 3.2 111/126] lockdep: Silence warning if CONFIG_LOCKDEP isn't set
Message-ID<tbhl1-6vr-39@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Paul Bolle <pebolle@tiscali.nl>

commit 5cd3f5affad2109fd1458aab3f6216f2181e26ea upstream.

Since commit c9a4962881929df7f1ef6e63e1b9da304faca4dd ("nfsd:
make client_lock per net") compiling nfs4state.o without
CONFIG_LOCKDEP set, triggers this GCC warning:

    fs/nfsd/nfs4state.c: In function ‘free_client’:
    fs/nfsd/nfs4state.c:1051:19: warning: unused variable ‘nn’ [-Wunused-variable]

The cause of that warning is that lockdep_assert_held() compiles
away if CONFIG_LOCKDEP is not set. Silence this warning by using
the argument to lockdep_assert_held() as a nop if CONFIG_LOCKDEP
is not set.

Signed-off-by: Paul Bolle <pebolle@tiscali.nl>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Stanislav Kinsbursky <skinsbursky@parallels.com>
Cc: J. Bruce Fields <bfields@redhat.com>
Link: http://lkml.kernel.org/r/1359060797.1325.33.camel@x61.thuisdomein
Signed-off-by: Ingo Molnar <mingo@kernel.org>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 include/linux/lockdep.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/include/linux/lockdep.h
+++ b/include/linux/lockdep.h
@@ -394,7 +394,7 @@ struct lock_class_key { };
 
 #define lockdep_depth(tsk)	(0)
 
-#define lockdep_assert_held(l)			do { } while (0)
+#define lockdep_assert_held(l)			do { (void)(l); } while (0)
 #define lockdep_assert_held_once(l)		do { (void)(l); } while (0)
 
 #endif /* !LOCKDEP */

[toc] | [prev] | [next] | [standalone]


#1581980 — [PATCH 3.2 095/126] locking/rtmutex: Prevent dequeue vs. unlock race

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 00:40 +0100
Subject[PATCH 3.2 095/126] locking/rtmutex: Prevent dequeue vs. unlock race
Message-ID<tbhl1-6vr-45@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Gleixner <tglx@linutronix.de>

commit dbb26055defd03d59f678cb5f2c992abe05b064a upstream.

David reported a futex/rtmutex state corruption. It's caused by the
following problem:

CPU0		CPU1		CPU2

l->owner=T1
		rt_mutex_lock(l)
		lock(l->wait_lock)
		l->owner = T1 | HAS_WAITERS;
		enqueue(T2)
		boost()
		  unlock(l->wait_lock)
		schedule()

				rt_mutex_lock(l)
				lock(l->wait_lock)
				l->owner = T1 | HAS_WAITERS;
				enqueue(T3)
				boost()
				  unlock(l->wait_lock)
				schedule()
		signal(->T2)	signal(->T3)
		lock(l->wait_lock)
		dequeue(T2)
		deboost()
		  unlock(l->wait_lock)
				lock(l->wait_lock)
				dequeue(T3)
				  ===> wait list is now empty
				deboost()
				 unlock(l->wait_lock)
		lock(l->wait_lock)
		fixup_rt_mutex_waiters()
		  if (wait_list_empty(l)) {
		    owner = l->owner & ~HAS_WAITERS;
		    l->owner = owner
		     ==> l->owner = T1
		  }

				lock(l->wait_lock)
rt_mutex_unlock(l)		fixup_rt_mutex_waiters()
				  if (wait_list_empty(l)) {
				    owner = l->owner & ~HAS_WAITERS;
cmpxchg(l->owner, T1, NULL)
 ===> Success (l->owner = NULL)
				    l->owner = owner
				     ==> l->owner = T1
				  }

That means the problem is caused by fixup_rt_mutex_waiters() which does the
RMW to clear the waiters bit unconditionally when there are no waiters in
the rtmutexes rbtree.

This can be fatal: A concurrent unlock can release the rtmutex in the
fastpath because the waiters bit is not set. If the cmpxchg() gets in the
middle of the RMW operation then the previous owner, which just unlocked
the rtmutex is set as the owner again when the write takes place after the
successfull cmpxchg().

The solution is rather trivial: verify that the owner member of the rtmutex
has the waiters bit set before clearing it. This does not require a
cmpxchg() or other atomic operations because the waiters bit can only be
set and cleared with the rtmutex wait_lock held. It's also safe against the
fast path unlock attempt. The unlock attempt via cmpxchg() will either see
the bit set and take the slowpath or see the bit cleared and release it
atomically in the fastpath.

It's remarkable that the test program provided by David triggers on ARM64
and MIPS64 really quick, but it refuses to reproduce on x86-64, while the
problem exists there as well. That refusal might explain that this got not
discovered earlier despite the bug existing from day one of the rtmutex
implementation more than 10 years ago.

Thanks to David for meticulously instrumenting the code and providing the
information which allowed to decode this subtle problem.

Reported-by: David Daney <ddaney@caviumnetworks.com>
Tested-by: David Daney <david.daney@cavium.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Reviewed-by: Steven Rostedt <rostedt@goodmis.org>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Mark Rutland <mark.rutland@arm.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Sebastian Siewior <bigeasy@linutronix.de>
Cc: Will Deacon <will.deacon@arm.com>
Fixes: 23f78d4a03c5 ("[PATCH] pi-futex: rt mutex core")
Link: http://lkml.kernel.org/r/20161130210030.351136722@linutronix.de
Signed-off-by: Ingo Molnar <mingo@kernel.org>
[bwh: Backported to 3.2:
 - Use ACCESS_ONCE() instead of {READ,WRITE}_ONCE()
 - Adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 kernel/rtmutex.c | 68 ++++++++++++++++++++++++++++++++++++++++++++++--
 1 file changed, 66 insertions(+), 2 deletions(-)

--- a/kernel/rtmutex.c
+++ b/kernel/rtmutex.c
@@ -63,8 +63,72 @@ static inline void clear_rt_mutex_waiter
 
 static void fixup_rt_mutex_waiters(struct rt_mutex *lock)
 {
-	if (!rt_mutex_has_waiters(lock))
-		clear_rt_mutex_waiters(lock);
+	unsigned long owner, *p = (unsigned long *) &lock->owner;
+
+	if (rt_mutex_has_waiters(lock))
+		return;
+
+	/*
+	 * The rbtree has no waiters enqueued, now make sure that the
+	 * lock->owner still has the waiters bit set, otherwise the
+	 * following can happen:
+	 *
+	 * CPU 0	CPU 1		CPU2
+	 * l->owner=T1
+	 *		rt_mutex_lock(l)
+	 *		lock(l->lock)
+	 *		l->owner = T1 | HAS_WAITERS;
+	 *		enqueue(T2)
+	 *		boost()
+	 *		  unlock(l->lock)
+	 *		block()
+	 *
+	 *				rt_mutex_lock(l)
+	 *				lock(l->lock)
+	 *				l->owner = T1 | HAS_WAITERS;
+	 *				enqueue(T3)
+	 *				boost()
+	 *				  unlock(l->lock)
+	 *				block()
+	 *		signal(->T2)	signal(->T3)
+	 *		lock(l->lock)
+	 *		dequeue(T2)
+	 *		deboost()
+	 *		  unlock(l->lock)
+	 *				lock(l->lock)
+	 *				dequeue(T3)
+	 *				 ==> wait list is empty
+	 *				deboost()
+	 *				 unlock(l->lock)
+	 *		lock(l->lock)
+	 *		fixup_rt_mutex_waiters()
+	 *		  if (wait_list_empty(l) {
+	 *		    l->owner = owner
+	 *		    owner = l->owner & ~HAS_WAITERS;
+	 *		      ==> l->owner = T1
+	 *		  }
+	 *				lock(l->lock)
+	 * rt_mutex_unlock(l)		fixup_rt_mutex_waiters()
+	 *				  if (wait_list_empty(l) {
+	 *				    owner = l->owner & ~HAS_WAITERS;
+	 * cmpxchg(l->owner, T1, NULL)
+	 *  ===> Success (l->owner = NULL)
+	 *
+	 *				    l->owner = owner
+	 *				      ==> l->owner = T1
+	 *				  }
+	 *
+	 * With the check for the waiter bit in place T3 on CPU2 will not
+	 * overwrite. All tasks fiddling with the waiters bit are
+	 * serialized by l->lock, so nothing else can modify the waiters
+	 * bit. If the bit is set then nothing can change l->owner either
+	 * so the simple RMW is safe. The cmpxchg() will simply fail if it
+	 * happens in the middle of the RMW because the waiters bit is
+	 * still set.
+	 */
+	owner = ACCESS_ONCE(*p);
+	if (owner & RT_MUTEX_HAS_WAITERS)
+		ACCESS_ONCE(*p) = owner & ~RT_MUTEX_HAS_WAITERS;
 }
 
 /*

[toc] | [prev] | [next] | [standalone]


#1581981 — [PATCH 3.2 057/126] scsi: arcmsr: Send SYNCHRONIZE_CACHE command to firmware

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 00:40 +0100
Subject[PATCH 3.2 057/126] scsi: arcmsr: Send SYNCHRONIZE_CACHE command to firmware
Message-ID<tbhl1-6vr-47@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Ching Huang <ching2048@areca.com.tw>

commit 2bf7dc8443e113844d078fd6541b7f4aa544f92f upstream.

The arcmsr driver failed to pass SYNCHRONIZE CACHE to controller
firmware. Depending on how drive caches are handled internally by
controller firmware this could potentially lead to data integrity
problems.

Ensure that cache flushes are passed to the controller.

[mkp: applied by hand and removed unused vars]

Signed-off-by: Ching Huang <ching2048@areca.com.tw>
Reported-by: Tomas Henzl <thenzl@redhat.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/scsi/arcmsr/arcmsr_hba.c | 9 ---------
 1 file changed, 9 deletions(-)

--- a/drivers/scsi/arcmsr/arcmsr_hba.c
+++ b/drivers/scsi/arcmsr/arcmsr_hba.c
@@ -2069,18 +2069,9 @@ static int arcmsr_queue_command_lck(stru
 	struct AdapterControlBlock *acb = (struct AdapterControlBlock *) host->hostdata;
 	struct CommandControlBlock *ccb;
 	int target = cmd->device->id;
-	int lun = cmd->device->lun;
-	uint8_t scsicmd = cmd->cmnd[0];
 	cmd->scsi_done = done;
 	cmd->host_scribble = NULL;
 	cmd->result = 0;
-	if ((scsicmd == SYNCHRONIZE_CACHE) ||(scsicmd == SEND_DIAGNOSTIC)){
-		if(acb->devstate[target][lun] == ARECA_RAID_GONE) {
-    			cmd->result = (DID_NO_CONNECT << 16);
-		}
-		cmd->scsi_done(cmd);
-		return 0;
-	}
 	if (target == 16) {
 		/* virtual device for iop message transfer */
 		arcmsr_handle_virtual_command(acb, cmd);

[toc] | [prev] | [next] | [standalone]


#1581991 — [PATCH 3.2 110/126] perf: Fix perf_event_for_each() to use sibling

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 00:40 +0100
Subject[PATCH 3.2 110/126] perf: Fix perf_event_for_each() to use sibling
Message-ID<tbhl1-6vr-63@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Ellerman <michael@ellerman.id.au>

commit 724b6daa13e100067c30cfc4d1ad06629609dc4e upstream.

In perf_event_for_each() we call a function on an event, and then
iterate over the siblings of the event.

However we don't call the function on the siblings, we call it
repeatedly on the original event - it seems "obvious" that we should
be calling it with sibling as the argument.

It looks like this broke in commit 75f937f24bd9 ("Fix ctx->mutex
vs counter->mutex inversion").

The only effect of the bug is that the PERF_IOC_FLAG_GROUP parameter
to the ioctls doesn't work.

Signed-off-by: Michael Ellerman <michael@ellerman.id.au>
Signed-off-by: Peter Zijlstra <a.p.zijlstra@chello.nl>
Link: http://lkml.kernel.org/r/1334109253-31329-1-git-send-email-michael@ellerman.id.au
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 kernel/events/core.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -3326,7 +3326,7 @@ static void perf_event_for_each(struct p
 	perf_event_for_each_child(event, func);
 	func(event);
 	list_for_each_entry(sibling, &event->sibling_list, group_entry)
-		perf_event_for_each_child(event, func);
+		perf_event_for_each_child(sibling, func);
 	mutex_unlock(&ctx->mutex);
 }
 

[toc] | [prev] | [next] | [standalone]


#1581997 — [PATCH 3.2 098/126] net: ping: check minimum size on ICMP header length

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 00:40 +0100
Subject[PATCH 3.2 098/126] net: ping: check minimum size on ICMP header length
Message-ID<tbhl2-6vr-77@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Kees Cook <keescook@chromium.org>

commit 0eab121ef8750a5c8637d51534d5e9143fb0633f upstream.

Prior to commit c0371da6047a ("put iov_iter into msghdr") in v3.19, there
was no check that the iovec contained enough bytes for an ICMP header,
and the read loop would walk across neighboring stack contents. Since the
iov_iter conversion, bad arguments are noticed, but the returned error is
EFAULT. Returning EINVAL is a clearer error and also solves the problem
prior to v3.19.

This was found using trinity with KASAN on v3.18:

BUG: KASAN: stack-out-of-bounds in memcpy_fromiovec+0x60/0x114 at addr ffffffc071077da0
Read of size 8 by task trinity-c2/9623
page:ffffffbe034b9a08 count:0 mapcount:0 mapping:          (null) index:0x0
flags: 0x0()
page dumped because: kasan: bad access detected
CPU: 0 PID: 9623 Comm: trinity-c2 Tainted: G    BU         3.18.0-dirty #15
Hardware name: Google Tegra210 Smaug Rev 1,3+ (DT)
Call trace:
[<ffffffc000209c98>] dump_backtrace+0x0/0x1ac arch/arm64/kernel/traps.c:90
[<ffffffc000209e54>] show_stack+0x10/0x1c arch/arm64/kernel/traps.c:171
[<     inline     >] __dump_stack lib/dump_stack.c:15
[<ffffffc000f18dc4>] dump_stack+0x7c/0xd0 lib/dump_stack.c:50
[<     inline     >] print_address_description mm/kasan/report.c:147
[<     inline     >] kasan_report_error mm/kasan/report.c:236
[<ffffffc000373dcc>] kasan_report+0x380/0x4b8 mm/kasan/report.c:259
[<     inline     >] check_memory_region mm/kasan/kasan.c:264
[<ffffffc00037352c>] __asan_load8+0x20/0x70 mm/kasan/kasan.c:507
[<ffffffc0005b9624>] memcpy_fromiovec+0x5c/0x114 lib/iovec.c:15
[<     inline     >] memcpy_from_msg include/linux/skbuff.h:2667
[<ffffffc000ddeba0>] ping_common_sendmsg+0x50/0x108 net/ipv4/ping.c:674
[<ffffffc000dded30>] ping_v4_sendmsg+0xd8/0x698 net/ipv4/ping.c:714
[<ffffffc000dc91dc>] inet_sendmsg+0xe0/0x12c net/ipv4/af_inet.c:749
[<     inline     >] __sock_sendmsg_nosec net/socket.c:624
[<     inline     >] __sock_sendmsg net/socket.c:632
[<ffffffc000cab61c>] sock_sendmsg+0x124/0x164 net/socket.c:643
[<     inline     >] SYSC_sendto net/socket.c:1797
[<ffffffc000cad270>] SyS_sendto+0x178/0x1d8 net/socket.c:1761

CVE-2016-8399

Reported-by: Qidan He <i@flanker017.me>
Fixes: c319b4d76b9e ("net: ipv4: add IPPROTO_ICMP socket kind")
Signed-off-by: Kees Cook <keescook@chromium.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
[bwh: Backported to 3.2: only ICMPv4 is supported]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 net/ipv4/ping.c | 4 ++++
 1 file changed, 4 insertions(+)

--- a/net/ipv4/ping.c
+++ b/net/ipv4/ping.c
@@ -482,6 +482,10 @@ static int ping_sendmsg(struct kiocb *io
 	if (len > 0xFFFF)
 		return -EMSGSIZE;
 
+	/* Must have at least a full ICMP header. */
+	if (len < sizeof(struct icmphdr))
+		return -EINVAL;
+
 	/*
 	 *	Check the flags.
 	 */

[toc] | [prev] | [next] | [standalone]


#1582003 — [PATCH 3.2 114/126] perf/core: Fix concurrent sys_perf_event_open() vs. 'move_group' race

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 00:40 +0100
Subject[PATCH 3.2 114/126] perf/core: Fix concurrent sys_perf_event_open() vs. 'move_group' race
Message-ID<tbhl3-6vr-93@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Zijlstra <peterz@infradead.org>

commit 321027c1fe77f892f4ea07846aeae08cefbbb290 upstream.

Di Shen reported a race between two concurrent sys_perf_event_open()
calls where both try and move the same pre-existing software group
into a hardware context.

The problem is exactly that described in commit:

  f63a8daa5812 ("perf: Fix event->ctx locking")

... where, while we wait for a ctx->mutex acquisition, the event->ctx
relation can have changed under us.

That very same commit failed to recognise sys_perf_event_context() as an
external access vector to the events and thereby didn't apply the
established locking rules correctly.

So while one sys_perf_event_open() call is stuck waiting on
mutex_lock_double(), the other (which owns said locks) moves the group
about. So by the time the former sys_perf_event_open() acquires the
locks, the context we've acquired is stale (and possibly dead).

Apply the established locking rules as per perf_event_ctx_lock_nested()
to the mutex_lock_double() for the 'move_group' case. This obviously means
we need to validate state after we acquire the locks.

Reported-by: Di Shen (Keen Lab)
Tested-by: John Dias <joaodias@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Arnaldo Carvalho de Melo <acme@kernel.org>
Cc: Arnaldo Carvalho de Melo <acme@redhat.com>
Cc: Jiri Olsa <jolsa@redhat.com>
Cc: Kees Cook <keescook@chromium.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Min Chong <mchong@google.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Stephane Eranian <eranian@google.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Vince Weaver <vincent.weaver@maine.edu>
Fixes: f63a8daa5812 ("perf: Fix event->ctx locking")
Link: http://lkml.kernel.org/r/20170106131444.GZ3174@twins.programming.kicks-ass.net
Signed-off-by: Ingo Molnar <mingo@kernel.org>
[bwh: Backported to 3.2:
 - Use ACCESS_ONCE() instead of READ_ONCE()
 - Test perf_event::group_flags instead of group_caps
 - Add the err_locked cleanup block, which we didn't need before
 - Adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 kernel/events/core.c | 58 ++++++++++++++++++++++++++++++++++++++++++++++++----
 1 file changed, 54 insertions(+), 4 deletions(-)

--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -6474,6 +6474,37 @@ static void mutex_lock_double(struct mut
 	mutex_lock_nested(b, SINGLE_DEPTH_NESTING);
 }
 
+/*
+ * Variation on perf_event_ctx_lock_nested(), except we take two context
+ * mutexes.
+ */
+static struct perf_event_context *
+__perf_event_ctx_lock_double(struct perf_event *group_leader,
+			     struct perf_event_context *ctx)
+{
+	struct perf_event_context *gctx;
+
+again:
+	rcu_read_lock();
+	gctx = ACCESS_ONCE(group_leader->ctx);
+	if (!atomic_inc_not_zero(&gctx->refcount)) {
+		rcu_read_unlock();
+		goto again;
+	}
+	rcu_read_unlock();
+
+	mutex_lock_double(&gctx->mutex, &ctx->mutex);
+
+	if (group_leader->ctx != gctx) {
+		mutex_unlock(&ctx->mutex);
+		mutex_unlock(&gctx->mutex);
+		put_ctx(gctx);
+		goto again;
+	}
+
+	return gctx;
+}
+
 /**
  * sys_perf_event_open - open a performance event, associate it to a task/cpu
  *
@@ -6661,14 +6692,31 @@ SYSCALL_DEFINE5(perf_event_open,
 	}
 
 	if (move_group) {
-		gctx = group_leader->ctx;
+		gctx = __perf_event_ctx_lock_double(group_leader, ctx);
+
+		/*
+		 * Check if we raced against another sys_perf_event_open() call
+		 * moving the software group underneath us.
+		 */
+		if (!(group_leader->group_flags & PERF_GROUP_SOFTWARE)) {
+			/*
+			 * If someone moved the group out from under us, check
+			 * if this new event wound up on the same ctx, if so
+			 * its the regular !move_group case, otherwise fail.
+			 */
+			if (gctx != ctx) {
+				err = -EINVAL;
+				goto err_locked;
+			} else {
+				perf_event_ctx_unlock(group_leader, gctx);
+				move_group = 0;
+			}
+		}
 
 		/*
 		 * See perf_event_ctx_lock() for comments on the details
 		 * of swizzling perf_event::ctx.
 		 */
-		mutex_lock_double(&gctx->mutex, &ctx->mutex);
-
 		perf_remove_from_context(group_leader, false);
 
 		/*
@@ -6709,10 +6757,8 @@ SYSCALL_DEFINE5(perf_event_open,
 	++ctx->generation;
 	perf_unpin_context(ctx);
 
-	if (move_group) {
-		mutex_unlock(&gctx->mutex);
-		put_ctx(gctx);
-	}
+	if (move_group)
+		perf_event_ctx_unlock(group_leader, gctx);
 	mutex_unlock(&ctx->mutex);
 
 	event->owner = current;
@@ -6737,6 +6783,11 @@ SYSCALL_DEFINE5(perf_event_open,
 	fd_install(event_fd, event_file);
 	return event_fd;
 
+err_locked:
+	if (move_group)
+		perf_event_ctx_unlock(group_leader, gctx);
+	mutex_unlock(&ctx->mutex);
+	fput(event_file);
 err_context:
 	perf_unpin_context(ctx);
 	put_ctx(ctx);

[toc] | [prev] | [next] | [standalone]


#1584981 — Re: [PATCH 3.2 114/126] perf/core: Fix concurrent sys_perf_event_open() vs. 'move_group' race

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-21 01:50 +0100
SubjectRe: [PATCH 3.2 114/126] perf/core: Fix concurrent sys_perf_event_open() vs. 'move_group' race
Message-ID<td6Ot-3u9-7@gated-at.bofh.it>
In reply to#1582003

[Multipart message — attachments visible in raw view] — view raw

On Wed, 2017-02-15 at 22:41 +0000, Ben Hutchings wrote:
> 3.2.85-rc1 review patch.  If anyone has any objections, please let me know.
> 
> ------------------
> 
> From: Peter Zijlstra <peterz@infradead.org>
> 
> commit 321027c1fe77f892f4ea07846aeae08cefbbb290 upstream.
> 
> Di Shen reported a race between two concurrent sys_perf_event_open()
> calls where both try and move the same pre-existing software group
> into a hardware context.
> 
> The problem is exactly that described in commit:
> 
>   f63a8daa5812 ("perf: Fix event->ctx locking")
> 
> ... where, while we wait for a ctx->mutex acquisition, the event->ctx
> relation can have changed under us.
> 
> That very same commit failed to recognise sys_perf_event_context() as an
> external access vector to the events and thereby didn't apply the
> established locking rules correctly.
> 
> So while one sys_perf_event_open() call is stuck waiting on
> mutex_lock_double(), the other (which owns said locks) moves the group
> about. So by the time the former sys_perf_event_open() acquires the
> locks, the context we've acquired is stale (and possibly dead).
> 
> Apply the established locking rules as per perf_event_ctx_lock_nested()
> to the mutex_lock_double() for the 'move_group' case. This obviously means
> we need to validate state after we acquire the locks.
[...]
>  		/*
>  		 * See perf_event_ctx_lock() for comments on the details
>  		 * of swizzling perf_event::ctx.
>  		 */
> -		mutex_lock_double(&gctx->mutex, &ctx->mutex);
> -
>  		perf_remove_from_context(group_leader, false);
>  
>  		/*
> @@ -6709,10 +6757,8 @@ SYSCALL_DEFINE5(perf_event_open,
>  	++ctx->generation;
>  	perf_unpin_context(ctx);
>  
> -	if (move_group) {
> -		mutex_unlock(&gctx->mutex);
> -		put_ctx(gctx);
> -	}
> +	if (move_group)
> +		perf_event_ctx_unlock(group_leader, gctx);
>  	mutex_unlock(&ctx->mutex);
>  
>  	event->owner = current;
[...]

Peter has clarified that the last call to put_ctx(gctx) corresponds to
the reference cleared by perf_remove_from_context(group_leader, false)
above.  So although perf_event_ctx_unlock() also calls put_ctx(gctx),
we really do want to drop two references here now and should keep the
direct call.

I made the same error when backporting to 3.16, and will fix that as
well.

Ben.

-- 
Ben Hutchings
73.46% of all statistics are made up.

[toc] | [prev] | [next] | [standalone]


#1582010 — [PATCH 3.2 085/126] Fix USB CB/CBI storage devices with CONFIG_VMAP_STACK=y

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 00:50 +0100
Subject[PATCH 3.2 085/126] Fix USB CB/CBI storage devices with CONFIG_VMAP_STACK=y
Message-ID<tbhuG-6zA-9@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Petr Vandrovec <petr@vandrovec.name>

commit 2ce9d2272b98743b911196c49e7af5841381c206 upstream.

Some code (all error handling) submits CDBs that are allocated
on the stack.  This breaks with CB/CBI code that tries to create
URB directly from SCSI command buffer - which happens to be in
vmalloced memory with vmalloced kernel stacks.

Let's make copy of the command in usb_stor_CB_transport.

Signed-off-by: Petr Vandrovec <petr@vandrovec.name>
Acked-by: Alan Stern <stern@rowland.harvard.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/storage/transport.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

--- a/drivers/usb/storage/transport.c
+++ b/drivers/usb/storage/transport.c
@@ -922,10 +922,15 @@ int usb_stor_CB_transport(struct scsi_cm
 
 	/* COMMAND STAGE */
 	/* let's send the command via the control pipe */
+	/*
+	 * Command is sometime (f.e. after scsi_eh_prep_cmnd) on the stack.
+	 * Stack may be vmallocated.  So no DMA for us.  Make a copy.
+	 */
+	memcpy(us->iobuf, srb->cmnd, srb->cmd_len);
 	result = usb_stor_ctrl_transfer(us, us->send_ctrl_pipe,
 				      US_CBI_ADSC, 
 				      USB_TYPE_CLASS | USB_RECIP_INTERFACE, 0, 
-				      us->ifnum, srb->cmnd, srb->cmd_len);
+				      us->ifnum, us->iobuf, srb->cmd_len);
 
 	/* check the return code for the command */
 	US_DEBUGP("Call to usb_stor_ctrl_transfer() returned %d\n", result);

[toc] | [prev] | [next] | [standalone]


#1582011 — [PATCH 3.2 124/126] sg_write()/bsg_write() is not fit to be called under KERNEL_DS

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 00:50 +0100
Subject[PATCH 3.2 124/126] sg_write()/bsg_write() is not fit to be called under KERNEL_DS
Message-ID<tbhuG-6zA-13@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Al Viro <viro@zeniv.linux.org.uk>

commit a0ac402cfcdc904f9772e1762b3fda112dcc56a0 upstream.

Both damn things interpret userland pointers embedded into the payload;
worse, they are actually traversing those.  Leaving aside the bad
API design, this is very much _not_ safe to call with KERNEL_DS.
Bail out early if that happens.

Cc: stable@vger.kernel.org
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 block/bsg.c       | 3 +++
 drivers/scsi/sg.c | 3 +++
 2 files changed, 6 insertions(+)

--- a/block/bsg.c
+++ b/block/bsg.c
@@ -675,6 +675,9 @@ bsg_write(struct file *file, const char
 
 	dprintk("%s: write %Zd bytes\n", bd->name, count);
 
+	if (unlikely(segment_eq(get_fs(), KERNEL_DS)))
+		return -EINVAL;
+
 	bsg_set_block(bd, file);
 
 	bytes_written = 0;
--- a/drivers/scsi/sg.c
+++ b/drivers/scsi/sg.c
@@ -544,6 +544,9 @@ sg_write(struct file *filp, const char _
 	sg_io_hdr_t *hp;
 	unsigned char cmnd[MAX_COMMAND_SIZE];
 
+	if (unlikely(segment_eq(get_fs(), KERNEL_DS)))
+		return -EINVAL;
+
 	if ((!(sfp = (Sg_fd *) filp->private_data)) || (!(sdp = sfp->parentdp)))
 		return -ENXIO;
 	SCSI_LOG_TIMEOUT(3, printk("sg_write: %s, count=%d\n",

[toc] | [prev] | [next] | [standalone]


#1582018 — [PATCH 3.2 053/126] scsi: megaraid_sas: Fix data integrity failure for JBOD (passthrough) devices

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 00:50 +0100
Subject[PATCH 3.2 053/126] scsi: megaraid_sas: Fix data integrity failure for JBOD (passthrough) devices
Message-ID<tbhuG-6zA-29@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Kashyap Desai <kashyap.desai@broadcom.com>

commit 1e793f6fc0db920400574211c48f9157a37e3945 upstream.

Commit 02b01e010afe ("megaraid_sas: return sync cache call with
success") modified the driver to successfully complete SYNCHRONIZE_CACHE
commands without passing them to the controller. Disk drive caches are
only explicitly managed by controller firmware when operating in RAID
mode. So this commit effectively disabled writeback cache flushing for
any drives used in JBOD mode, leading to data integrity failures.

[mkp: clarified patch description]

Fixes: 02b01e010afeeb49328d35650d70721d2ca3fd59
Signed-off-by: Kashyap Desai <kashyap.desai@broadcom.com>
Signed-off-by: Sumit Saxena <sumit.saxena@broadcom.com>
Reviewed-by: Tomas Henzl <thenzl@redhat.com>
Reviewed-by: Hannes Reinecke <hare@suse.com>
Reviewed-by: Ewan D. Milne <emilne@redhat.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/scsi/megaraid/megaraid_sas_base.c | 13 +++++--------
 1 file changed, 5 insertions(+), 8 deletions(-)

--- a/drivers/scsi/megaraid/megaraid_sas_base.c
+++ b/drivers/scsi/megaraid/megaraid_sas_base.c
@@ -1486,16 +1486,13 @@ megasas_queue_command_lck(struct scsi_cm
 		goto out_done;
 	}
 
-	switch (scmd->cmnd[0]) {
-	case SYNCHRONIZE_CACHE:
-		/*
-		 * FW takes care of flush cache on its own
-		 * No need to send it down
-		 */
+	/*
+	 * FW takes care of flush cache on its own for Virtual Disk.
+	 * No need to send it down for VD. For JBOD send SYNCHRONIZE_CACHE to FW.
+	 */
+	if ((scmd->cmnd[0] == SYNCHRONIZE_CACHE) && MEGASAS_IS_LOGICAL(scmd)) {
 		scmd->result = DID_OK << 16;
 		goto out_done;
-	default:
-		break;
 	}
 
 	if (instance->instancet->build_and_issue_cmd(instance, scmd)) {

[toc] | [prev] | [next] | [standalone]


#1582020 — [PATCH 3.2 112/126] perf: Fix event->ctx locking

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 00:50 +0100
Subject[PATCH 3.2 112/126] perf: Fix event->ctx locking
Message-ID<tbhuG-6zA-27@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Zijlstra <peterz@infradead.org>

commit f63a8daa5812afef4f06c962351687e1ff9ccb2b upstream.

There have been a few reported issues wrt. the lack of locking around
changing event->ctx. This patch tries to address those.

It avoids the whole rwsem thing; and while it appears to work, please
give it some thought in review.

What I did fail at is sensible runtime checks on the use of
event->ctx, the RCU use makes it very hard.

Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Paul E. McKenney <paulmck@linux.vnet.ibm.com>
Cc: Jiri Olsa <jolsa@redhat.com>
Cc: Arnaldo Carvalho de Melo <acme@kernel.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Link: http://lkml.kernel.org/r/20150123125834.209535886@infradead.org
Signed-off-by: Ingo Molnar <mingo@kernel.org>
[bwh: Backported to 3.2:
 - We don't have perf_pmu_migrate_context()
 - Adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -665,6 +665,76 @@ static void put_ctx(struct perf_event_co
 	}
 }
 
+/*
+ * Because of perf_event::ctx migration in sys_perf_event_open::move_group we
+ * need some magic.
+ *
+ * Those places that change perf_event::ctx will hold both
+ * perf_event_ctx::mutex of the 'old' and 'new' ctx value.
+ *
+ * Lock ordering is by mutex address. There is one other site where
+ * perf_event_context::mutex nests and that is put_event(). But remember that
+ * that is a parent<->child context relation, and migration does not affect
+ * children, therefore these two orderings should not interact.
+ *
+ * The change in perf_event::ctx does not affect children (as claimed above)
+ * because the sys_perf_event_open() case will install a new event and break
+ * the ctx parent<->child relation.
+ *
+ * The places that change perf_event::ctx will issue:
+ *
+ *   perf_remove_from_context();
+ *   synchronize_rcu();
+ *   perf_install_in_context();
+ *
+ * to affect the change. The remove_from_context() + synchronize_rcu() should
+ * quiesce the event, after which we can install it in the new location. This
+ * means that only external vectors (perf_fops, prctl) can perturb the event
+ * while in transit. Therefore all such accessors should also acquire
+ * perf_event_context::mutex to serialize against this.
+ *
+ * However; because event->ctx can change while we're waiting to acquire
+ * ctx->mutex we must be careful and use the below perf_event_ctx_lock()
+ * function.
+ *
+ * Lock order:
+ *	task_struct::perf_event_mutex
+ *	  perf_event_context::mutex
+ *	    perf_event_context::lock
+ *	    perf_event::child_mutex;
+ *	    perf_event::mmap_mutex
+ *	    mmap_sem
+ */
+static struct perf_event_context *perf_event_ctx_lock(struct perf_event *event)
+{
+	struct perf_event_context *ctx;
+
+again:
+	rcu_read_lock();
+	ctx = ACCESS_ONCE(event->ctx);
+	if (!atomic_inc_not_zero(&ctx->refcount)) {
+		rcu_read_unlock();
+		goto again;
+	}
+	rcu_read_unlock();
+
+	mutex_lock(&ctx->mutex);
+	if (event->ctx != ctx) {
+		mutex_unlock(&ctx->mutex);
+		put_ctx(ctx);
+		goto again;
+	}
+
+	return ctx;
+}
+
+static void perf_event_ctx_unlock(struct perf_event *event,
+				  struct perf_event_context *ctx)
+{
+	mutex_unlock(&ctx->mutex);
+	put_ctx(ctx);
+}
+
 static void unclone_ctx(struct perf_event_context *ctx)
 {
 	if (ctx->parent_ctx) {
@@ -1325,7 +1395,7 @@ static int __perf_event_disable(void *in
  * is the current context on this CPU and preemption is disabled,
  * hence we can't get into perf_event_task_sched_out for this context.
  */
-void perf_event_disable(struct perf_event *event)
+static void _perf_event_disable(struct perf_event *event)
 {
 	struct perf_event_context *ctx = event->ctx;
 	struct task_struct *task = ctx->task;
@@ -1367,6 +1437,19 @@ retry:
 	raw_spin_unlock_irq(&ctx->lock);
 }
 
+/*
+ * Strictly speaking kernel users cannot create groups and therefore this
+ * interface does not need the perf_event_ctx_lock() magic.
+ */
+void perf_event_disable(struct perf_event *event)
+{
+	struct perf_event_context *ctx;
+
+	ctx = perf_event_ctx_lock(event);
+	_perf_event_disable(event);
+	perf_event_ctx_unlock(event, ctx);
+}
+
 static void perf_set_shadow_time(struct perf_event *event,
 				 struct perf_event_context *ctx,
 				 u64 tstamp)
@@ -1813,7 +1896,7 @@ unlock:
  * perf_event_for_each_child or perf_event_for_each as described
  * for perf_event_disable.
  */
-void perf_event_enable(struct perf_event *event)
+static void _perf_event_enable(struct perf_event *event)
 {
 	struct perf_event_context *ctx = event->ctx;
 	struct task_struct *task = ctx->task;
@@ -1870,7 +1953,19 @@ out:
 	raw_spin_unlock_irq(&ctx->lock);
 }
 
-int perf_event_refresh(struct perf_event *event, int refresh)
+/*
+ * See perf_event_disable();
+ */
+void perf_event_enable(struct perf_event *event)
+{
+	struct perf_event_context *ctx;
+
+	ctx = perf_event_ctx_lock(event);
+	_perf_event_enable(event);
+	perf_event_ctx_unlock(event, ctx);
+}
+
+static int _perf_event_refresh(struct perf_event *event, int refresh)
 {
 	/*
 	 * not supported on inherited events
@@ -1879,10 +1974,25 @@ int perf_event_refresh(struct perf_event
 		return -EINVAL;
 
 	atomic_add(refresh, &event->event_limit);
-	perf_event_enable(event);
+	_perf_event_enable(event);
 
 	return 0;
 }
+
+/*
+ * See perf_event_disable()
+ */
+int perf_event_refresh(struct perf_event *event, int refresh)
+{
+	struct perf_event_context *ctx;
+	int ret;
+
+	ctx = perf_event_ctx_lock(event);
+	ret = _perf_event_refresh(event, refresh);
+	perf_event_ctx_unlock(event, ctx);
+
+	return ret;
+}
 EXPORT_SYMBOL_GPL(perf_event_refresh);
 
 static void ctx_sched_out(struct perf_event_context *ctx,
@@ -3110,7 +3220,16 @@ static void put_event(struct perf_event
 	rcu_read_unlock();
 
 	if (owner) {
-		mutex_lock(&owner->perf_event_mutex);
+		/*
+		 * If we're here through perf_event_exit_task() we're already
+		 * holding ctx->mutex which would be an inversion wrt. the
+		 * normal lock order.
+		 *
+		 * However we can safely take this lock because its the child
+		 * ctx->mutex.
+		 */
+		mutex_lock_nested(&owner->perf_event_mutex, SINGLE_DEPTH_NESTING);
+
 		/*
 		 * We have to re-check the event->owner field, if it is cleared
 		 * we raced with perf_event_exit_task(), acquiring the mutex
@@ -3162,12 +3281,13 @@ static int perf_event_read_group(struct
 				   u64 read_format, char __user *buf)
 {
 	struct perf_event *leader = event->group_leader, *sub;
-	int n = 0, size = 0, ret = -EFAULT;
 	struct perf_event_context *ctx = leader->ctx;
-	u64 values[5];
+	int n = 0, size = 0, ret;
 	u64 count, enabled, running;
+	u64 values[5];
+
+	lockdep_assert_held(&ctx->mutex);
 
-	mutex_lock(&ctx->mutex);
 	count = perf_event_read_value(leader, &enabled, &running);
 
 	values[n++] = 1 + leader->nr_siblings;
@@ -3182,7 +3302,7 @@ static int perf_event_read_group(struct
 	size = n * sizeof(u64);
 
 	if (copy_to_user(buf, values, size))
-		goto unlock;
+		return -EFAULT;
 
 	ret = size;
 
@@ -3196,14 +3316,11 @@ static int perf_event_read_group(struct
 		size = n * sizeof(u64);
 
 		if (copy_to_user(buf + ret, values, size)) {
-			ret = -EFAULT;
-			goto unlock;
+			return -EFAULT;
 		}
 
 		ret += size;
 	}
-unlock:
-	mutex_unlock(&ctx->mutex);
 
 	return ret;
 }
@@ -3262,8 +3379,14 @@ static ssize_t
 perf_read(struct file *file, char __user *buf, size_t count, loff_t *ppos)
 {
 	struct perf_event *event = file->private_data;
+	struct perf_event_context *ctx;
+	int ret;
 
-	return perf_read_hw(event, buf, count);
+	ctx = perf_event_ctx_lock(event);
+	ret = perf_read_hw(event, buf, count);
+	perf_event_ctx_unlock(event, ctx);
+
+	return ret;
 }
 
 static unsigned int perf_poll(struct file *file, poll_table *wait)
@@ -3287,7 +3410,7 @@ static unsigned int perf_poll(struct fil
 	return events;
 }
 
-static void perf_event_reset(struct perf_event *event)
+static void _perf_event_reset(struct perf_event *event)
 {
 	(void)perf_event_read(event);
 	local64_set(&event->count, 0);
@@ -3306,6 +3429,7 @@ static void perf_event_for_each_child(st
 	struct perf_event *child;
 
 	WARN_ON_ONCE(event->ctx->parent_ctx);
+
 	mutex_lock(&event->child_mutex);
 	func(event);
 	list_for_each_entry(child, &event->child_list, child_list)
@@ -3319,15 +3443,14 @@ static void perf_event_for_each(struct p
 	struct perf_event_context *ctx = event->ctx;
 	struct perf_event *sibling;
 
-	WARN_ON_ONCE(ctx->parent_ctx);
-	mutex_lock(&ctx->mutex);
+	lockdep_assert_held(&ctx->mutex);
+
 	event = event->group_leader;
 
 	perf_event_for_each_child(event, func);
 	func(event);
 	list_for_each_entry(sibling, &event->sibling_list, group_entry)
 		perf_event_for_each_child(sibling, func);
-	mutex_unlock(&ctx->mutex);
 }
 
 static int perf_event_period(struct perf_event *event, u64 __user *arg)
@@ -3386,25 +3509,24 @@ static int perf_event_set_output(struct
 				 struct perf_event *output_event);
 static int perf_event_set_filter(struct perf_event *event, void __user *arg);
 
-static long perf_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
+static long _perf_ioctl(struct perf_event *event, unsigned int cmd, unsigned long arg)
 {
-	struct perf_event *event = file->private_data;
 	void (*func)(struct perf_event *);
 	u32 flags = arg;
 
 	switch (cmd) {
 	case PERF_EVENT_IOC_ENABLE:
-		func = perf_event_enable;
+		func = _perf_event_enable;
 		break;
 	case PERF_EVENT_IOC_DISABLE:
-		func = perf_event_disable;
+		func = _perf_event_disable;
 		break;
 	case PERF_EVENT_IOC_RESET:
-		func = perf_event_reset;
+		func = _perf_event_reset;
 		break;
 
 	case PERF_EVENT_IOC_REFRESH:
-		return perf_event_refresh(event, arg);
+		return _perf_event_refresh(event, arg);
 
 	case PERF_EVENT_IOC_PERIOD:
 		return perf_event_period(event, (u64 __user *)arg);
@@ -3445,6 +3567,19 @@ static long perf_ioctl(struct file *file
 	return 0;
 }
 
+static long perf_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
+{
+	struct perf_event *event = file->private_data;
+	struct perf_event_context *ctx;
+	long ret;
+
+	ctx = perf_event_ctx_lock(event);
+	ret = _perf_ioctl(event, cmd, arg);
+	perf_event_ctx_unlock(event, ctx);
+
+	return ret;
+}
+
 #ifdef CONFIG_COMPAT
 static long perf_compat_ioctl(struct file *file, unsigned int cmd,
 				unsigned long arg)
@@ -3466,11 +3601,15 @@ static long perf_compat_ioctl(struct fil
 
 int perf_event_task_enable(void)
 {
+	struct perf_event_context *ctx;
 	struct perf_event *event;
 
 	mutex_lock(&current->perf_event_mutex);
-	list_for_each_entry(event, &current->perf_event_list, owner_entry)
-		perf_event_for_each_child(event, perf_event_enable);
+	list_for_each_entry(event, &current->perf_event_list, owner_entry) {
+		ctx = perf_event_ctx_lock(event);
+		perf_event_for_each_child(event, _perf_event_enable);
+		perf_event_ctx_unlock(event, ctx);
+	}
 	mutex_unlock(&current->perf_event_mutex);
 
 	return 0;
@@ -3478,11 +3617,15 @@ int perf_event_task_enable(void)
 
 int perf_event_task_disable(void)
 {
+	struct perf_event_context *ctx;
 	struct perf_event *event;
 
 	mutex_lock(&current->perf_event_mutex);
-	list_for_each_entry(event, &current->perf_event_list, owner_entry)
-		perf_event_for_each_child(event, perf_event_disable);
+	list_for_each_entry(event, &current->perf_event_list, owner_entry) {
+		ctx = perf_event_ctx_lock(event);
+		perf_event_for_each_child(event, _perf_event_disable);
+		perf_event_ctx_unlock(event, ctx);
+	}
 	mutex_unlock(&current->perf_event_mutex);
 
 	return 0;
@@ -6322,6 +6465,15 @@ out:
 	return ret;
 }
 
+static void mutex_lock_double(struct mutex *a, struct mutex *b)
+{
+	if (b < a)
+		swap(a, b);
+
+	mutex_lock(a);
+	mutex_lock_nested(b, SINGLE_DEPTH_NESTING);
+}
+
 /**
  * sys_perf_event_open - open a performance event, associate it to a task/cpu
  *
@@ -6337,7 +6489,7 @@ SYSCALL_DEFINE5(perf_event_open,
 	struct perf_event *group_leader = NULL, *output_event = NULL;
 	struct perf_event *event, *sibling;
 	struct perf_event_attr attr;
-	struct perf_event_context *ctx;
+	struct perf_event_context *ctx, *uninitialized_var(gctx);
 	struct file *event_file = NULL;
 	struct file *group_file = NULL;
 	struct task_struct *task = NULL;
@@ -6509,9 +6661,14 @@ SYSCALL_DEFINE5(perf_event_open,
 	}
 
 	if (move_group) {
-		struct perf_event_context *gctx = group_leader->ctx;
+		gctx = group_leader->ctx;
+
+		/*
+		 * See perf_event_ctx_lock() for comments on the details
+		 * of swizzling perf_event::ctx.
+		 */
+		mutex_lock_double(&gctx->mutex, &ctx->mutex);
 
-		mutex_lock(&gctx->mutex);
 		perf_remove_from_context(group_leader, false);
 
 		/*
@@ -6526,14 +6683,19 @@ SYSCALL_DEFINE5(perf_event_open,
 			perf_event__state_init(sibling);
 			put_ctx(gctx);
 		}
-		mutex_unlock(&gctx->mutex);
-		put_ctx(gctx);
+	} else {
+		mutex_lock(&ctx->mutex);
 	}
 
 	WARN_ON_ONCE(ctx->parent_ctx);
-	mutex_lock(&ctx->mutex);
 
 	if (move_group) {
+		/*
+		 * Wait for everybody to stop referencing the events through
+		 * the old lists, before installing it on new lists.
+		 */
+		synchronize_rcu();
+
 		perf_install_in_context(ctx, group_leader, cpu);
 		get_ctx(ctx);
 		list_for_each_entry(sibling, &group_leader->sibling_list,
@@ -6546,6 +6708,11 @@ SYSCALL_DEFINE5(perf_event_open,
 	perf_install_in_context(ctx, event, cpu);
 	++ctx->generation;
 	perf_unpin_context(ctx);
+
+	if (move_group) {
+		mutex_unlock(&gctx->mutex);
+		put_ctx(gctx);
+	}
 	mutex_unlock(&ctx->mutex);
 
 	event->owner = current;

[toc] | [prev] | [next] | [standalone]


#1582042 — [PATCH 3.2 089/126] IB/uverbs: Fix leak of XRC target QPs

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 00:50 +0100
Subject[PATCH 3.2 089/126] IB/uverbs: Fix leak of XRC target QPs
Message-ID<tbhuI-6zA-81@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Tariq Toukan <tariqt@mellanox.com>

commit 5b810a242c28e1d8d64d718cebe75b79d86a0b2d upstream.

The real QP is destroyed in case of the ref count reaches zero, but
for XRC target QPs this call was missed and caused to QP leaks.

Let's call to destroy for all flows.

Fixes: 0e0ec7e0638e ('RDMA/core: Export ib_open_qp() to share XRC...')
Signed-off-by: Tariq Toukan <tariqt@mellanox.com>
Signed-off-by: Noa Osherovich <noaos@mellanox.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Doug Ledford <dledford@redhat.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/infiniband/core/uverbs_main.c | 7 ++-----
 1 file changed, 2 insertions(+), 5 deletions(-)

--- a/drivers/infiniband/core/uverbs_main.c
+++ b/drivers/infiniband/core/uverbs_main.c
@@ -213,12 +213,9 @@ static int ib_uverbs_cleanup_ucontext(st
 			container_of(uobj, struct ib_uqp_object, uevent.uobject);
 
 		idr_remove_uobj(&ib_uverbs_qp_idr, uobj);
-		if (qp != qp->real_qp) {
-			ib_close_qp(qp);
-		} else {
+		if (qp == qp->real_qp)
 			ib_uverbs_detach_umcast(qp, uqp);
-			ib_destroy_qp(qp);
-		}
+		ib_destroy_qp(qp);
 		ib_uverbs_release_uevent(file, &uqp->uevent);
 		kfree(uqp);
 	}

[toc] | [prev] | [next] | [standalone]


#1582154 — [PATCH 3.2 037/126] fuse: fix killing s[ug]id in setattr

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 01:40 +0100
Subject[PATCH 3.2 037/126] fuse: fix killing s[ug]id in setattr
Message-ID<tbih3-768-1@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Miklos Szeredi <mszeredi@redhat.com>

commit a09f99eddef44035ec764075a37bace8181bec38 upstream.

Fuse allowed VFS to set mode in setattr in order to clear suid/sgid on
chown and truncate, and (since writeback_cache) write.  The problem with
this is that it'll potentially restore a stale mode.

The poper fix would be to let the filesystems do the suid/sgid clearing on
the relevant operations.  Possibly some are already doing it but there's no
way we can detect this.

So fix this by refreshing and recalculating the mode.  Do this only if
ATTR_KILL_S[UG]ID is set to not destroy performance for writes.  This is
still racy but the size of the window is reduced.

Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 fs/fuse/dir.c | 32 ++++++++++++++++++++++++++++----
 1 file changed, 28 insertions(+), 4 deletions(-)

--- a/fs/fuse/dir.c
+++ b/fs/fuse/dir.c
@@ -1393,13 +1393,38 @@ error:
 
 static int fuse_setattr(struct dentry *entry, struct iattr *attr)
 {
+	struct inode *inode = entry->d_inode;
+	struct file *file = (attr->ia_valid & ATTR_FILE) ? attr->ia_file : NULL;
 	int ret;
 
-	if (attr->ia_valid & ATTR_FILE)
-		ret = fuse_do_setattr(entry, attr, attr->ia_file);
-	else
-		ret = fuse_do_setattr(entry, attr, NULL);
+	if (attr->ia_valid & (ATTR_KILL_SUID | ATTR_KILL_SGID)) {
+		int kill;
 
+		attr->ia_valid &= ~(ATTR_KILL_SUID | ATTR_KILL_SGID |
+				    ATTR_MODE);
+		/*
+		 * ia_mode calculation may have used stale i_mode.  Refresh and
+		 * recalculate.
+		 */
+		ret = fuse_do_getattr(inode, NULL, file);
+		if (ret)
+			return ret;
+
+		attr->ia_mode = inode->i_mode;
+		kill = should_remove_suid(entry);
+		if (kill & ATTR_KILL_SUID) {
+			attr->ia_valid |= ATTR_MODE;
+			attr->ia_mode &= ~S_ISUID;
+		}
+		if (kill & ATTR_KILL_SGID) {
+			attr->ia_valid |= ATTR_MODE;
+			attr->ia_mode &= ~S_ISGID;
+		}
+	}
+	if (!attr->ia_valid)
+		return 0;
+
+	ret = fuse_do_setattr(entry, attr, file);
 	if (!ret) {
 		/* Directory mode changed, may need to revalidate access */
 		if (S_ISDIR(entry->d_inode->i_mode) &&

[toc] | [prev] | [next] | [standalone]


#1582156 — [PATCH 3.2 026/126] net/mlx4_core: Fix deadlock when switching between polling and event fw commands

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 01:40 +0100
Subject[PATCH 3.2 026/126] net/mlx4_core: Fix deadlock when switching between polling and event fw commands
Message-ID<tbih3-768-5@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Jack Morgenstein <jackm@dev.mellanox.co.il>

commit a7e1f04905e5b2b90251974dddde781301b6be37 upstream.

When switching from polling-based fw commands to event-based fw
commands, there is a race condition which could cause a fw command
in another task to hang: that task will keep waiting for the polling
sempahore, but may never be able to acquire it. This is due to
mlx4_cmd_use_events, which "down"s the sempahore back to 0.

During driver initialization, this is not a problem, since no other
tasks which invoke FW commands are active.

However, there is a problem if the driver switches to polling mode
and then back to event mode during normal operation.

The "test_interrupts" feature does exactly that.
Running "ethtool -t <eth device> offline" causes the PF driver to
temporarily switch to polling mode, and then back to event mode.
(Note that for VF drivers, such switching is not performed).

Fix this by adding a read-write semaphore for protection when
switching between modes.

Fixes: 225c7b1feef1 ("IB/mlx4: Add a driver Mellanox ConnectX InfiniBand adapters")
Signed-off-by: Jack Morgenstein <jackm@dev.mellanox.co.il>
Signed-off-by: Matan Barak <matanb@mellanox.com>
Signed-off-by: Tariq Toukan <tariqt@mellanox.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[bwh: Backported to 3.2: adjust context, indentation]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/drivers/net/ethernet/mellanox/mlx4/cmd.c
+++ b/drivers/net/ethernet/mellanox/mlx4/cmd.c
@@ -313,12 +313,18 @@ int __mlx4_cmd(struct mlx4_dev *dev, u64
 	       int out_is_imm, u32 in_modifier, u8 op_modifier,
 	       u16 op, unsigned long timeout)
 {
+	int ret;
+
+	down_read(&mlx4_priv(dev)->cmd.switch_sem);
 	if (mlx4_priv(dev)->cmd.use_events)
-		return mlx4_cmd_wait(dev, in_param, out_param, out_is_imm,
-				     in_modifier, op_modifier, op, timeout);
+		ret = mlx4_cmd_wait(dev, in_param, out_param, out_is_imm,
+				    in_modifier, op_modifier, op, timeout);
 	else
-		return mlx4_cmd_poll(dev, in_param, out_param, out_is_imm,
-				     in_modifier, op_modifier, op, timeout);
+		ret = mlx4_cmd_poll(dev, in_param, out_param, out_is_imm,
+				    in_modifier, op_modifier, op, timeout);
+
+	up_read(&mlx4_priv(dev)->cmd.switch_sem);
+	return ret;
 }
 EXPORT_SYMBOL_GPL(__mlx4_cmd);
 
@@ -326,6 +332,7 @@ int mlx4_cmd_init(struct mlx4_dev *dev)
 {
 	struct mlx4_priv *priv = mlx4_priv(dev);
 
+	init_rwsem(&priv->cmd.switch_sem);
 	mutex_init(&priv->cmd.hcr_mutex);
 	sema_init(&priv->cmd.poll_sem, 1);
 	priv->cmd.use_events = 0;
@@ -372,6 +379,7 @@ int mlx4_cmd_use_events(struct mlx4_dev
 	if (!priv->cmd.context)
 		return -ENOMEM;
 
+	down_write(&priv->cmd.switch_sem);
 	for (i = 0; i < priv->cmd.max_cmds; ++i) {
 		priv->cmd.context[i].token = i;
 		priv->cmd.context[i].next  = i + 1;
@@ -390,6 +398,7 @@ int mlx4_cmd_use_events(struct mlx4_dev
 	--priv->cmd.token_mask;
 
 	priv->cmd.use_events = 1;
+	up_write(&priv->cmd.switch_sem);
 
 	down(&priv->cmd.poll_sem);
 
@@ -404,6 +413,7 @@ void mlx4_cmd_use_polling(struct mlx4_de
 	struct mlx4_priv *priv = mlx4_priv(dev);
 	int i;
 
+	down_write(&priv->cmd.switch_sem);
 	priv->cmd.use_events = 0;
 
 	for (i = 0; i < priv->cmd.max_cmds; ++i)
@@ -412,6 +422,7 @@ void mlx4_cmd_use_polling(struct mlx4_de
 	kfree(priv->cmd.context);
 
 	up(&priv->cmd.poll_sem);
+	up_write(&priv->cmd.switch_sem);
 }
 
 struct mlx4_cmd_mailbox *mlx4_alloc_cmd_mailbox(struct mlx4_dev *dev)
--- a/drivers/net/ethernet/mellanox/mlx4/mlx4.h
+++ b/drivers/net/ethernet/mellanox/mlx4/mlx4.h
@@ -42,6 +42,7 @@
 #include <linux/timer.h>
 #include <linux/semaphore.h>
 #include <linux/workqueue.h>
+#include <linux/rwsem.h>
 
 #include <linux/mlx4/device.h>
 #include <linux/mlx4/driver.h>
@@ -190,6 +191,7 @@ struct mlx4_cmd {
 	struct mutex		hcr_mutex;
 	struct semaphore	poll_sem;
 	struct semaphore	event_sem;
+	struct rw_semaphore	switch_sem;
 	int			max_cmds;
 	spinlock_t		context_lock;
 	int			free_head;

[toc] | [prev] | [next] | [standalone]


#1582157 — [PATCH 3.2 047/126] ubifs: Abort readdir upon error

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 01:40 +0100
Subject[PATCH 3.2 047/126] ubifs: Abort readdir upon error
Message-ID<tbih3-768-7@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Richard Weinberger <richard@nod.at>

commit c83ed4c9dbb358b9e7707486e167e940d48bfeed upstream.

If UBIFS is facing an error while walking a directory, it reports this
error and ubifs_readdir() returns the error code. But the VFS readdir
logic does not make the getdents system call fail in all cases. When the
readdir cursor indicates that more entries are present, the system call
will just return and the libc wrapper will try again since it also
knows that more entries are present.
This causes the libc wrapper to busy loop for ever when a directory is
corrupted on UBIFS.
A common approach do deal with corrupted directory entries is
skipping them by setting the cursor to the next entry. On UBIFS this
approach is not possible since we cannot compute the next directory
entry cursor position without reading the current entry. So all we can
do is setting the cursor to the "no more entries" position and make
getdents exit.

Signed-off-by: Richard Weinberger <richard@nod.at>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/fs/ubifs/dir.c
+++ b/fs/ubifs/dir.c
@@ -356,7 +356,7 @@ static unsigned int vfs_dent_type(uint8_
  */
 static int ubifs_readdir(struct file *file, void *dirent, filldir_t filldir)
 {
-	int err, over = 0;
+	int err = 0, over = 0;
 	loff_t pos = file->f_pos;
 	struct qstr nm;
 	union ubifs_key key;
@@ -475,16 +475,14 @@ static int ubifs_readdir(struct file *fi
 	}
 
 out:
-	if (err != -ENOENT) {
+	if (err != -ENOENT)
 		ubifs_err("cannot find next direntry, error %d", err);
-		return err;
-	}
 
 	kfree(file->private_data);
 	file->private_data = NULL;
 	/* 2 is a special value indicating that there are no more direntries */
 	file->f_pos = 2;
-	return 0;
+	return err;
 }
 
 static loff_t ubifs_dir_llseek(struct file *file, loff_t offset, int origin)

[toc] | [prev] | [next] | [standalone]


#1582159 — [PATCH 3.2 003/126] zfcp: fix ELS/GS request&response length for hardware data router

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 01:40 +0100
Subject[PATCH 3.2 003/126] zfcp: fix ELS/GS request&response length for hardware data router
Message-ID<tbih3-768-9@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Steffen Maier <maier@linux.vnet.ibm.com>

commit 70369f8e15b220f50a16348c79a61d3f7054813c upstream.

In the hardware data router case, introduced with kernel 3.2
commit 86a9668a8d29 ("[SCSI] zfcp: support for hardware data router")
the ELS/GS request&response length needs to be initialized
as in the chained SBAL case.

Otherwise, the FCP channel rejects ELS requests with
FSF_REQUEST_SIZE_TOO_LARGE.

Such ELS requests can be issued by user space through BSG / HBA API,
or zfcp itself uses ADISC ELS for remote port link test on RSCN.
The latter can cause a short path outage due to
unnecessary remote target port recovery because the always
failing ADISC cannot detect extremely short path interruptions
beyond the local FCP channel.

Below example is decoded with zfcpdbf from s390-tools:

Timestamp      : ...
Area           : SAN
Subarea        : 00
Level          : 1
Exception      : -
CPU id         : ..
Caller         : zfcp_dbf_san_req+0408
Record id      : 1
Tag            : fssels1
Request id     : 0x<reqid>
Destination ID : 0x00<target d_id>
Payload info   : 52000000 00000000 <our wwpn       >           [ADISC]
                 <our wwnn       > 00<s_id> 00000000
                 00000000 00000000 00000000 00000000

Timestamp      : ...
Area           : HBA
Subarea        : 00
Level          : 1
Exception      : -
CPU id         : ..
Caller         : zfcp_dbf_hba_fsf_res+0740
Record id      : 1
Tag            : fs_ferr
Request id     : 0x<reqid>
Request status : 0x00000010
FSF cmnd       : 0x0000000b               [FSF_QTCB_SEND_ELS]
FSF sequence no: 0x...
FSF issued     : ...
FSF stat       : 0x00000061		  [FSF_REQUEST_SIZE_TOO_LARGE]
FSF stat qual  : 00000000 00000000 00000000 00000000
Prot stat      : 0x00000100
Prot stat qual : 00000000 00000000 00000000 00000000

Signed-off-by: Steffen Maier <maier@linux.vnet.ibm.com>
Fixes: 86a9668a8d29 ("[SCSI] zfcp: support for hardware data router")
Reviewed-by: Benjamin Block <bblock@linux.vnet.ibm.com>
Reviewed-by: Hannes Reinecke <hare@suse.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/s390/scsi/zfcp_fsf.c | 4 ++++
 1 file changed, 4 insertions(+)

--- a/drivers/s390/scsi/zfcp_fsf.c
+++ b/drivers/s390/scsi/zfcp_fsf.c
@@ -960,8 +960,12 @@ static int zfcp_fsf_setup_ct_els_sbals(s
 	if (zfcp_adapter_multi_buffer_active(adapter)) {
 		if (zfcp_qdio_sbals_from_sg(qdio, &req->qdio_req, sg_req))
 			return -EIO;
+		qtcb->bottom.support.req_buf_length =
+			zfcp_qdio_real_bytes(sg_req);
 		if (zfcp_qdio_sbals_from_sg(qdio, &req->qdio_req, sg_resp))
 			return -EIO;
+		qtcb->bottom.support.resp_buf_length =
+			zfcp_qdio_real_bytes(sg_resp);
 
 		zfcp_qdio_set_data_div(qdio, &req->qdio_req,
 					zfcp_qdio_sbale_count(sg_req));

[toc] | [prev] | [next] | [standalone]


#1582160 — [PATCH 3.2 065/126] ubifs: Fix regression in ubifs_readdir()

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 01:40 +0100
Subject[PATCH 3.2 065/126] ubifs: Fix regression in ubifs_readdir()
Message-ID<tbih3-768-11@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Richard Weinberger <richard@nod.at>

commit a00052a296e54205cf238c75bd98d17d5d02a6db upstream.

Commit c83ed4c9dbb35 ("ubifs: Abort readdir upon error") broke
overlayfs support because the fix exposed an internal error
code to VFS.

Reported-by: Peter Rosin <peda@axentia.se>
Tested-by: Peter Rosin <peda@axentia.se>
Reported-by: Ralph Sennhauser <ralph.sennhauser@gmail.com>
Tested-by: Ralph Sennhauser <ralph.sennhauser@gmail.com>
Fixes: c83ed4c9dbb35 ("ubifs: Abort readdir upon error")
Signed-off-by: Richard Weinberger <richard@nod.at>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 fs/ubifs/dir.c | 8 ++++++++
 1 file changed, 8 insertions(+)

--- a/fs/ubifs/dir.c
+++ b/fs/ubifs/dir.c
@@ -477,6 +477,14 @@ static int ubifs_readdir(struct file *fi
 out:
 	if (err != -ENOENT)
 		ubifs_err("cannot find next direntry, error %d", err);
+	else
+		/*
+		 * -ENOENT is a non-fatal error in this context, the TNC uses
+		 * it to indicate that the cursor moved past the current directory
+		 * and readdir() has to stop.
+		 */
+		err = 0;
+
 
 	kfree(file->private_data);
 	file->private_data = NULL;

[toc] | [prev] | [next] | [standalone]


#1582161 — [PATCH 3.2 046/126] ubifs: Fix xattr_names length in exit paths

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 01:40 +0100
Subject[PATCH 3.2 046/126] ubifs: Fix xattr_names length in exit paths
Message-ID<tbih3-768-15@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Richard Weinberger <richard@nod.at>

commit 843741c5778398ea67055067f4cc65ae6c80ca0e upstream.

When the operation fails we also have to undo the changes
we made to ->xattr_names. Otherwise listxattr() will report
wrong lengths.

Signed-off-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 fs/ubifs/xattr.c | 2 ++
 1 file changed, 2 insertions(+)

--- a/fs/ubifs/xattr.c
+++ b/fs/ubifs/xattr.c
@@ -168,6 +168,7 @@ out_cancel:
 	host_ui->xattr_cnt -= 1;
 	host_ui->xattr_size -= CALC_DENT_SIZE(nm->len);
 	host_ui->xattr_size -= CALC_XATTR_BYTES(size);
+	host_ui->xattr_names -= nm->len;
 	mutex_unlock(&host_ui->ui_mutex);
 out_free:
 	make_bad_inode(inode);
@@ -516,6 +517,7 @@ out_cancel:
 	host_ui->xattr_cnt += 1;
 	host_ui->xattr_size += CALC_DENT_SIZE(nm->len);
 	host_ui->xattr_size += CALC_XATTR_BYTES(ui->data_len);
+	host_ui->xattr_names += nm->len;
 	mutex_unlock(&host_ui->ui_mutex);
 	ubifs_release_budget(c, &req);
 	make_bad_inode(inode);

[toc] | [prev] | [next] | [standalone]


#1582165 — [PATCH 3.2 039/126] crypto: gcm - Fix IV buffer size in crypto_gcm_setkey

FromBen Hutchings <ben@decadent.org.uk>
Date2017-02-16 01:40 +0100
Subject[PATCH 3.2 039/126] crypto: gcm - Fix IV buffer size in crypto_gcm_setkey
Message-ID<tbih4-768-23@gated-at.bofh.it>
In reply to#1581976
3.2.85-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Ondrej Mosnáček <omosnacek@gmail.com>

commit 50d2e6dc1f83db0563c7d6603967bf9585ce934b upstream.

The cipher block size for GCM is 16 bytes, and thus the CTR transform
used in crypto_gcm_setkey() will also expect a 16-byte IV. However,
the code currently reserves only 8 bytes for the IV, causing
an out-of-bounds access in the CTR transform. This patch fixes
the issue by setting the size of the IV buffer to 16 bytes.

Fixes: 84c911523020 ("[CRYPTO] gcm: Add support for async ciphers")
Signed-off-by: Ondrej Mosnacek <omosnacek@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 crypto/gcm.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/crypto/gcm.c
+++ b/crypto/gcm.c
@@ -103,7 +103,7 @@ static int crypto_gcm_setkey(struct cryp
 	struct crypto_ablkcipher *ctr = ctx->ctr;
 	struct {
 		be128 hash;
-		u8 iv[8];
+		u8 iv[16];
 
 		struct crypto_gcm_setkey_result result;
 

[toc] | [prev] | [next] | [standalone]


Page 1 of 3  [1] 2 3  Next page →

Back to top | Article view | linux.kernel


csiph-web