Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1596796 > unrolled thread

[PATCH 4.10 000/167] 4.10.2-stable review

Started byGreg Kroah-Hartman <gregkh@linuxfoundation.org>
First post2017-03-10 10:30 +0100
Last post2017-03-12 06:30 +0100
Articles 20 on this page of 169 — 4 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 4.10 000/167] 4.10.2-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:30 +0100
    [PATCH 4.10 027/167] ALSA: timer: Reject user params with too small ticks Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:30 +0100
    [PATCH 4.10 035/167] staging/lustre/lnet: Fix allocation size for sv_cpt_data Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:30 +0100
    [PATCH 4.10 036/167] staging: rtl: fix possible NULL pointer dereference Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:30 +0100
    [PATCH 4.10 001/167] MIPS: pic32mzda: Fix linker error for pic32_get_pbclk() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:30 +0100
    [PATCH 4.10 039/167] regulator: Fix regulator_summary for deviceless consumers Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:30 +0100
    [PATCH 4.10 038/167] coresight: fix kernel panic caused by invalid CPU Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:30 +0100
    [PATCH 4.10 011/167] MIPS: Handle microMIPS jumps in the same way as MIPS32/MIPS64 jumps Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:30 +0100
    [PATCH 4.10 010/167] MIPS: Calculate microMIPS ra properly when unwinding the stack Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:30 +0100
    [PATCH 4.10 037/167] coresight: STM: Balance enable/disable Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:30 +0100
    [PATCH 4.10 030/167] ALSA: hda - Add subwoofer support for Dell Inspiron 17 7000 Gaming Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:30 +0100
    [PATCH 4.10 009/167] MIPS: Fix is_jump_ins() handling of 16b microMIPS instructions Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:30 +0100
    [PATCH 4.10 025/167] ALSA: hda/realtek - Cannot adjust speakers volume on a Dell AIO Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:30 +0100
    [PATCH 4.10 008/167] MIPS: Fix get_frame_info() handling of microMIPS function size Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:30 +0100
    [PATCH 4.10 144/167] f2fs: fix a problem of using memory after free Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 165/167] MIPS: IP22: Fix build error due to binutils 2.25 uselessnes. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 146/167] f2fs: add ovp valid_blocks check for bg gc victim to fg_gc Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 159/167] xprtrdma: Reduce required number of send SGEs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 150/167] rtc: sun6i: Add some locking Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 099/167] fuse: add missing FR_FORCE Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 073/167] loop: fix LO_FLAGS_PARTSCAN hang Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 130/167] rdma_cm: fail iwarp accepts w/o connection params Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 161/167] powerpc/mm: Add MMU_FTR_KERNEL_RO to possible feature mask Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 131/167] gfs2: Add missing rcu locking for glock   lookup Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 114/167] usb: host: xhci: plat: check hcc_params after add hcd Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 135/167] VME: restore bus_remove function causing incomplete module unload Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 106/167] iio: pressure: mpl115: do not rely on structure field ordering Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 166/167] scsi: lpfc: Correct WQ creation for pagesize Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 137/167] nfsd: special case truncates some more Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 095/167] crypto: xts - Propagate NEED_FALLBACK bit Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 091/167] PCI: altera: Fix TLP_CFG_DW0 for TLP write Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 089/167] PCI: hv: Fix wslot_to_devfn() to fix warnings on device removal Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 043/167] iommu/vt-d: Tylersburg isoch identity map check is done too late. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 164/167] MIPS: IP22: Reformat inline assembler code to modern standards. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 123/167] hv: dont reset hv_context.tsc_page on crash Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 111/167] w1: ds2490: USB transfer buffers need to be DMAable Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 143/167] NFSv4: fix getacl ERANGE for some ACL buffer sizes Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 071/167] jbd2: dont leak modified metadata buffers on an aborted journal Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 055/167] PM / devfreq: Fix available_governor sysfs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 097/167] crypto: vmx - Use skcipher for cbc fallback Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 087/167] ath9k: fix race condition in enabling/disabling IRQs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 122/167] hv: init percpu_list in hv_synic_alloc() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 059/167] dm round robin: revert "use percpu repeat_count and current_path" Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 119/167] usb: gadget: f_hid: Use spinlock instead of mutex Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 124/167] Drivers: hv: vmbus: Prevent sending data on a rescinded channel Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 075/167] ext4: do not polute the extents cache while shifting extents Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 103/167] arm64: fix erroneous __raw_read_system_reg() cases Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 141/167] Revert "NFSv4.1: Handle NFS4ERR_BADSESSION/NFS4ERR_DEADSESSION replies to OP_SEQUENCE" Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 132/167] remoteproc: qcom: mdt_loader: Dont overwrite firmware object Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 110/167] w1: dont leak refcount on slave attach failure in w1_attach_slave_device() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 085/167] ath10k: fix boot failure in UTF mode/testmode Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 060/167] dm raid: fix data corruption on reshape request Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 125/167] Drivers: hv: vmbus: Fix a rescind handling bug Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 064/167] scsi: qla2xxx: Cleaned up queue configuration code. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 121/167] hv: allocate synic pages for all present CPUs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 082/167] ext4: fix fencepost in s_first_meta_bg validation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 145/167] f2fs: fix multiple f2fs_add_link() calls having same name Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 154/167] mtd: nand: ifc: Fix location of eccstat registers for IFC V1.0 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 096/167] crypto: api - Add crypto_requires_off helper Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 155/167] dmaengine: ipu: Make sure the interrupt routine checks all interrupts. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 090/167] pci/hotplug/pnv-php: Disable MSI and PCI device properly Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 147/167] f2fs: avoid to issue redundant discard commands Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 078/167] ext4: fix use-after-iput when fscrypt contexts are inconsistent Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 104/167] KVM: arm/arm64: vgic: Stop injecting the MSI occurrence twice Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 158/167] xprtrdma: Disable pad optimization by default Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 100/167] x86/pkeys: Check against max pkey to avoid overflows Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 107/167] iio: pressure: mpl3115: do not rely on structure field ordering Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 116/167] usb: gadget: udc: fsl: Add missing complete function. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:40 +0100
    [PATCH 4.10 152/167] md linear: fix a race between linear_add() and linear_congested() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 149/167] rtc: sun6i: Disable the build as a module Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 102/167] arm64: dma-mapping: Fix dma_mapping_error() when bypassing SWIOTLB Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 163/167] module: fix memory leak on early load_module() failures Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 142/167] NFSv4: fix getacl head length estimation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 101/167] arm/arm64: KVM: Enforce unconditional flush to PoC when mapping to stage-2 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 139/167] NFSv4: Fix reboot recovery in copy offload Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 160/167] powerpc/xmon: Fix data-breakpoint Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 138/167] NFSv4: Fix memory and state leak in _nfs4_open_and_get_state Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 140/167] pNFS/flexfiles: If the layout is invalid, it must be updated before retrying Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 151/167] rtc: sun6i: Switch to the external oscillator Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 162/167] powerpc/mm/hash: Always clear UPRT and Host Radix bits when setting up CPU Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 156/167] xprtrdma: Fix Read chunk padding Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 148/167] f2fs: Fix zoned block device support Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 157/167] xprtrdma: Per-connection pad optimization Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 136/167] nfsd: minor nfsd_setattr cleanup Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 10:50 +0100
    [PATCH 4.10 133/167] rtlwifi: Fix alignment issues Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:00 +0100
    [PATCH 4.10 134/167] rtlwifi: rtl8192c-common: Fix "BUG: KASAN: Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:00 +0100
    [PATCH 4.10 128/167] Drivers: hv: util: Backup: Fix a rescind processing issue Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:00 +0100
    [PATCH 4.10 117/167] usb: gadget: f_hid: fix: Free out requests Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:00 +0100
    [PATCH 4.10 118/167] usb: gadget: f_hid: fix: Prevent accessing released memory Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:00 +0100
    [PATCH 4.10 115/167] usb: gadget: udc-core: Rescan pending list on driver unbind Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:00 +0100
    [PATCH 4.10 126/167] Drivers: hv: util: kvp: Fix a rescind processing issue Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:00 +0100
    [PATCH 4.10 129/167] RDMA/core: Fix incorrect structure packing for booleans Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:00 +0100
    [PATCH 4.10 127/167] Drivers: hv: util: Fcopy: Fix a rescind processing issue Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:00 +0100
    [PATCH 4.10 112/167] usb: musb: da8xx: Remove CPPI 3.0 quirk and methods Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:00 +0100
    [PATCH 4.10 113/167] usb: dwc3: gadget: skip Set/Clear Halt when invalid Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:00 +0100
    [PATCH 4.10 098/167] crypto: vmx - Use skcipher for xts fallback Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:00 +0100
    [PATCH 4.10 109/167] can: usb_8dev: Fix memory leak of priv->cmd_msg_buffer Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:00 +0100
    [PATCH 4.10 120/167] usb: gadget: f_hid: fix: Move IN request allocation to set_alt() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:00 +0100
    [PATCH 4.10 061/167] scsi: storvsc: use tagged SRB requests if supported by the device Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 105/167] Revert "arm64: mm: set the contiguous bit for kernel mappings where appropriate" Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 084/167] mei: remove support for broken parallel read Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 092/167] Drivers: hv: vmbus: Raise retry/wait limits in vmbus_post_msg() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 079/167] ext4: fix inline data error paths Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 077/167] ext4: fix data corruption in data=journal mode Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 088/167] ath9k: use correct OTP register offsets for the AR9340 and AR9550 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 058/167] dm stats: fix a leaked s->histogram_boundaries array Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 081/167] ext4: return EROFS if device is r/o and journal replay is needed Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 093/167] crypto: xts - Add ECB dependency Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 108/167] can: gs_usb: Dont use stack memory for USB transfers Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 076/167] ext4: trim allocation requests to group size Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 086/167] ath5k: drop bogus warning on drv_set_key with unsupported cipher Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 094/167] crypto: testmgr - Pad aes_ccm_enc_tv_template vector Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 063/167] scsi: storvsc: properly set residual data length on errors Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 080/167] ext4: preserve the needs_recovery flag when the journal is aborted Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 062/167] scsi: storvsc: properly handle SRB_ERROR when sense message is present Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:10 +0100
    [PATCH 4.10 049/167] mm balloon: umount balloon_mnt when removing vb device Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 052/167] sigaltstack: support SS_AUTODISARM for CONFIG_COMPAT Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 072/167] block/loop: fix race between I/O and set_status Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 057/167] dm cache: fix corruption seen when using cache > 2TB Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 054/167] ima: fix ima_d_path() possible race with rename Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 070/167] Fix: Disable sys_membarrier when nohz_full is enabled Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 021/167] spi: s3c64xx: fix inconsistency between binding and driver Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 050/167] mm, vmscan: cleanup lru size claculations Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 023/167] ARM: dts: at91: Enable DMA on sama5d4_xplained console Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 053/167] ipc/shm: Fix shmat mmap nil-page protection Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 041/167] tpm_tis: fix the error handling of init_tis() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 067/167] scsi: aacraid: Reorder Adapter status check Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 019/167] [media] media: Properly pass through media entity types in entity enumeration Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 065/167] scsi: qla2xxx: Fix response queue count for Target mode. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 024/167] ARM: dts: at91: Enable DMA on sama5d2_xplained console Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 051/167] mm, vmscan: consider eligible zones in get_scan_count Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 068/167] scsi: use scsi_device_from_queue() for scsi_dh Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 044/167] CIFS: Fix splice read for non-cached files Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 074/167] ext4: Include forgotten start block on fallocate insert range Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 056/167] PM / devfreq: Fix wrong trans_stat of passive devfreq device Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 066/167] scsi: qla2xxx: Fix Regression introduced by pci_alloc_irq_vectors_affinity call. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 069/167] power: reset: at91-poweroff: timely shutdown LPDDR memories Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 045/167] mm, devm_memremap_pages: hold device_hotplug lock over mem_hotplug_{begin, done} Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 022/167] ARM: at91: define LPDDR types Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 015/167] [media] media: fix dm1105.c build error Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 020/167] ext4: fix deadlock between inline_data and ext4_expand_extra_isize_ea() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:20 +0100
    [PATCH 4.10 006/167] MIPS: Clear ISA bit correctly in get_frame_info() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 046/167] mm/page_alloc: fix nodes for reclaim in fast path Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 005/167] MIPS: Lantiq: Keep ethernet enabled during boot Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 047/167] mm: vmpressure: fix sending wrong events on underflow Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 007/167] MIPS: Prevent unaligned accesses during stack unwinding Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 017/167] [media] dvb-usb: dont use stack for firmware load Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 029/167] ALSA: seq: Fix link corruption by event error handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 028/167] ALSA: ctxfi: Fallback DMA mask to 32bit Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 034/167] staging: greybus: loopback: fix broken udelay Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 018/167] [media] lirc_dev: LIRC_{G,S}ET_REC_MODE do not work Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 048/167] mm: do not access page->mapping directly on page_endio Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 004/167] MIPS: OCTEON: Fix copy_from_user fault handling for large buffers Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 032/167] hwmon: (it87) Do not overwrite bit 2..6 of pwm control registers Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 031/167] ALSA: hda - Fix micmute hotkey problem for a lenovo AIO machine Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 042/167] iommu/vt-d: Fix some macros that are incorrectly specified in intel-iommu Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:30 +0100
    [PATCH 4.10 002/167] MIPS: Fix special case in 64 bit IP checksumming. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:40 +0100
    [PATCH 4.10 014/167] [media] uvcvideo: Fix a wrong macro Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:40 +0100
    [PATCH 4.10 012/167] mmc: sdhci-acpi: support deferred probe Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:40 +0100
    [PATCH 4.10 013/167] [media] am437x-vpfe: always assign bpp variable Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 11:40 +0100
    [PATCH 4.10 167/167] ceph: update readpages osd request according to size of pages Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-10 16:00 +0100
    Re: [PATCH 4.10 000/167] 4.10.2-stable review Guenter Roeck <linux@roeck-us.net> - 2017-03-10 19:40 +0100
      Re: [PATCH 4.10 000/167] 4.10.2-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-12 06:30 +0100
    Re: [PATCH 4.10 000/167] 4.10.2-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2017-03-10 20:20 +0100
      Re: [PATCH 4.10 000/167] 4.10.2-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-12 06:30 +0100
    Re: [PATCH 4.10 000/167] 4.10.2-stable review Kevin Hilman <khilman@baylibre.com> - 2017-03-11 01:00 +0100
      Re: [PATCH 4.10 000/167] 4.10.2-stable review Guenter Roeck <linux@roeck-us.net> - 2017-03-11 02:10 +0100
        Re: [PATCH 4.10 000/167] 4.10.2-stable review Kevin Hilman <khilman@baylibre.com> - 2017-03-11 02:50 +0100
    Re: [PATCH 4.10 000/167] 4.10.2-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-03-12 06:30 +0100

Page 6 of 9 — ← Prev page 1 2 3 4 5 [6] 7 8 9  Next page →


#1596956 — [PATCH 4.10 084/167] mei: remove support for broken parallel read

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 084/167] mei: remove support for broken parallel read
Message-ID<tjpEK-2rf-17@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alexander Usyskin <alexander.usyskin@intel.com>

commit cb97fbbcac15982406e0c74cd5512a8b6fcf10b3 upstream.

Parallel reads from multiple threads on a file descriptor
are not well defined and racy. It is safer to return to original
behavior and simply fail the additional read.
The solution is to remove request for next read credit.

Fixes: ff1586a7ea57 ("mei: enqueue consecutive reads")
Signed-off-by: Alexander Usyskin <alexander.usyskin@intel.com>
Signed-off-by: Tomas Winkler <tomas.winkler@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/misc/mei/main.c |   48 ++++++++++++++++++++++++++----------------------
 1 file changed, 26 insertions(+), 22 deletions(-)

--- a/drivers/misc/mei/main.c
+++ b/drivers/misc/mei/main.c
@@ -182,32 +182,36 @@ static ssize_t mei_read(struct file *fil
 		goto out;
 	}
 
-	if (rets == -EBUSY &&
-	    !mei_cl_enqueue_ctrl_wr_cb(cl, length, MEI_FOP_READ, file)) {
-		rets = -ENOMEM;
-		goto out;
+
+again:
+	mutex_unlock(&dev->device_lock);
+	if (wait_event_interruptible(cl->rx_wait,
+				     !list_empty(&cl->rd_completed) ||
+				     !mei_cl_is_connected(cl))) {
+		if (signal_pending(current))
+			return -EINTR;
+		return -ERESTARTSYS;
 	}
+	mutex_lock(&dev->device_lock);
 
-	do {
-		mutex_unlock(&dev->device_lock);
+	if (!mei_cl_is_connected(cl)) {
+		rets = -ENODEV;
+		goto out;
+	}
 
-		if (wait_event_interruptible(cl->rx_wait,
-					     (!list_empty(&cl->rd_completed)) ||
-					     (!mei_cl_is_connected(cl)))) {
-
-			if (signal_pending(current))
-				return -EINTR;
-			return -ERESTARTSYS;
-		}
-
-		mutex_lock(&dev->device_lock);
-		if (!mei_cl_is_connected(cl)) {
-			rets = -ENODEV;
-			goto out;
-		}
+	cb = mei_cl_read_cb(cl, file);
+	if (!cb) {
+		/*
+		 * For amthif all the waiters are woken up,
+		 * but only fp with matching cb->fp get the cb,
+		 * the others have to return to wait on read.
+		 */
+		if (cl == &dev->iamthif_cl)
+			goto again;
 
-		cb = mei_cl_read_cb(cl, file);
-	} while (!cb);
+		rets = 0;
+		goto out;
+	}
 
 copy_buffer:
 	/* now copy the data to user space */

[toc] | [prev] | [next] | [standalone]


#1596957 — [PATCH 4.10 092/167] Drivers: hv: vmbus: Raise retry/wait limits in vmbus_post_msg()

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 092/167] Drivers: hv: vmbus: Raise retry/wait limits in vmbus_post_msg()
Message-ID<tjpEJ-2rf-7@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Vitaly Kuznetsov <vkuznets@redhat.com>

commit c0bb03924f1a80e7f65900e36c8e6b3dc167c5f8 upstream.

DoS protection conditions were altered in WS2016 and now it's easy to get
-EAGAIN returned from vmbus_post_msg() (e.g. when we try changing MTU on a
netvsc device in a loop). All vmbus_post_msg() callers don't retry the
operation and we usually end up with a non-functional device or crash.

While host's DoS protection conditions are unknown to me my tests show that
it can take up to 10 seconds before the message is sent so doing udelay()
is not an option, we really need to sleep. Almost all vmbus_post_msg()
callers are ready to sleep but there is one special case:
vmbus_initiate_unload() which can be called from interrupt/NMI context and
we can't sleep there. I'm also not sure about the lonely
vmbus_send_tl_connect_request() which has no in-tree users but its external
users are most likely waiting for the host to reply so sleeping there is
also appropriate.

Signed-off-by: Vitaly Kuznetsov <vkuznets@redhat.com>
Signed-off-by: K. Y. Srinivasan <kys@microsoft.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/hv/channel.c      |   17 +++++++++--------
 drivers/hv/channel_mgmt.c |   10 ++++++----
 drivers/hv/connection.c   |   17 ++++++++++++-----
 drivers/hv/hyperv_vmbus.h |    2 +-
 4 files changed, 28 insertions(+), 18 deletions(-)

--- a/drivers/hv/channel.c
+++ b/drivers/hv/channel.c
@@ -181,7 +181,7 @@ int vmbus_open(struct vmbus_channel *new
 	spin_unlock_irqrestore(&vmbus_connection.channelmsg_lock, flags);
 
 	ret = vmbus_post_msg(open_msg,
-			       sizeof(struct vmbus_channel_open_channel));
+			     sizeof(struct vmbus_channel_open_channel), true);
 
 	if (ret != 0) {
 		err = ret;
@@ -233,7 +233,7 @@ int vmbus_send_tl_connect_request(const
 	conn_msg.guest_endpoint_id = *shv_guest_servie_id;
 	conn_msg.host_service_id = *shv_host_servie_id;
 
-	return vmbus_post_msg(&conn_msg, sizeof(conn_msg));
+	return vmbus_post_msg(&conn_msg, sizeof(conn_msg), true);
 }
 EXPORT_SYMBOL_GPL(vmbus_send_tl_connect_request);
 
@@ -419,7 +419,7 @@ int vmbus_establish_gpadl(struct vmbus_c
 	spin_unlock_irqrestore(&vmbus_connection.channelmsg_lock, flags);
 
 	ret = vmbus_post_msg(gpadlmsg, msginfo->msgsize -
-			       sizeof(*msginfo));
+			     sizeof(*msginfo), true);
 	if (ret != 0)
 		goto cleanup;
 
@@ -433,8 +433,8 @@ int vmbus_establish_gpadl(struct vmbus_c
 		gpadl_body->gpadl = next_gpadl_handle;
 
 		ret = vmbus_post_msg(gpadl_body,
-				     submsginfo->msgsize -
-				     sizeof(*submsginfo));
+				     submsginfo->msgsize - sizeof(*submsginfo),
+				     true);
 		if (ret != 0)
 			goto cleanup;
 
@@ -485,8 +485,8 @@ int vmbus_teardown_gpadl(struct vmbus_ch
 	list_add_tail(&info->msglistentry,
 		      &vmbus_connection.chn_msg_list);
 	spin_unlock_irqrestore(&vmbus_connection.channelmsg_lock, flags);
-	ret = vmbus_post_msg(msg,
-			       sizeof(struct vmbus_channel_gpadl_teardown));
+	ret = vmbus_post_msg(msg, sizeof(struct vmbus_channel_gpadl_teardown),
+			     true);
 
 	if (ret)
 		goto post_msg_err;
@@ -557,7 +557,8 @@ static int vmbus_close_internal(struct v
 	msg->header.msgtype = CHANNELMSG_CLOSECHANNEL;
 	msg->child_relid = channel->offermsg.child_relid;
 
-	ret = vmbus_post_msg(msg, sizeof(struct vmbus_channel_close_channel));
+	ret = vmbus_post_msg(msg, sizeof(struct vmbus_channel_close_channel),
+			     true);
 
 	if (ret) {
 		pr_err("Close failed: close post msg return is %d\n", ret);
--- a/drivers/hv/channel_mgmt.c
+++ b/drivers/hv/channel_mgmt.c
@@ -321,7 +321,8 @@ static void vmbus_release_relid(u32 reli
 	memset(&msg, 0, sizeof(struct vmbus_channel_relid_released));
 	msg.child_relid = relid;
 	msg.header.msgtype = CHANNELMSG_RELID_RELEASED;
-	vmbus_post_msg(&msg, sizeof(struct vmbus_channel_relid_released));
+	vmbus_post_msg(&msg, sizeof(struct vmbus_channel_relid_released),
+		       true);
 }
 
 void hv_event_tasklet_disable(struct vmbus_channel *channel)
@@ -728,7 +729,8 @@ void vmbus_initiate_unload(bool crash)
 	init_completion(&vmbus_connection.unload_event);
 	memset(&hdr, 0, sizeof(struct vmbus_channel_message_header));
 	hdr.msgtype = CHANNELMSG_UNLOAD;
-	vmbus_post_msg(&hdr, sizeof(struct vmbus_channel_message_header));
+	vmbus_post_msg(&hdr, sizeof(struct vmbus_channel_message_header),
+		       !crash);
 
 	/*
 	 * vmbus_initiate_unload() is also called on crash and the crash can be
@@ -1116,8 +1118,8 @@ int vmbus_request_offers(void)
 	msg->msgtype = CHANNELMSG_REQUESTOFFERS;
 
 
-	ret = vmbus_post_msg(msg,
-			       sizeof(struct vmbus_channel_message_header));
+	ret = vmbus_post_msg(msg, sizeof(struct vmbus_channel_message_header),
+			     true);
 	if (ret != 0) {
 		pr_err("Unable to request offers - %d\n", ret);
 
--- a/drivers/hv/connection.c
+++ b/drivers/hv/connection.c
@@ -111,7 +111,8 @@ static int vmbus_negotiate_version(struc
 	spin_unlock_irqrestore(&vmbus_connection.channelmsg_lock, flags);
 
 	ret = vmbus_post_msg(msg,
-			       sizeof(struct vmbus_channel_initiate_contact));
+			     sizeof(struct vmbus_channel_initiate_contact),
+			     true);
 	if (ret != 0) {
 		spin_lock_irqsave(&vmbus_connection.channelmsg_lock, flags);
 		list_del(&msginfo->msglistentry);
@@ -435,7 +436,7 @@ void vmbus_on_event(unsigned long data)
 /*
  * vmbus_post_msg - Send a msg on the vmbus's message connection
  */
-int vmbus_post_msg(void *buffer, size_t buflen)
+int vmbus_post_msg(void *buffer, size_t buflen, bool can_sleep)
 {
 	union hv_connection_id conn_id;
 	int ret = 0;
@@ -450,7 +451,7 @@ int vmbus_post_msg(void *buffer, size_t
 	 * insufficient resources. Retry the operation a couple of
 	 * times before giving up.
 	 */
-	while (retries < 20) {
+	while (retries < 100) {
 		ret = hv_post_message(conn_id, 1, buffer, buflen);
 
 		switch (ret) {
@@ -473,8 +474,14 @@ int vmbus_post_msg(void *buffer, size_t
 		}
 
 		retries++;
-		udelay(usec);
-		if (usec < 2048)
+		if (can_sleep && usec > 1000)
+			msleep(usec / 1000);
+		else if (usec < MAX_UDELAY_MS * 1000)
+			udelay(usec);
+		else
+			mdelay(usec / 1000);
+
+		if (usec < 256000)
 			usec *= 2;
 	}
 	return ret;
--- a/drivers/hv/hyperv_vmbus.h
+++ b/drivers/hv/hyperv_vmbus.h
@@ -683,7 +683,7 @@ void vmbus_free_channels(void);
 int vmbus_connect(void);
 void vmbus_disconnect(void);
 
-int vmbus_post_msg(void *buffer, size_t buflen);
+int vmbus_post_msg(void *buffer, size_t buflen, bool can_sleep);
 
 void vmbus_on_event(unsigned long data);
 void vmbus_on_msg_dpc(unsigned long data);

[toc] | [prev] | [next] | [standalone]


#1596961 — [PATCH 4.10 079/167] ext4: fix inline data error paths

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 079/167] ext4: fix inline data error paths
Message-ID<tjpEL-2rf-35@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Theodore Ts'o <tytso@mit.edu>

commit eb5efbcb762aee4b454b04f7115f73ccbcf8f0ef upstream.

The write_end() function must always unlock the page and drop its ref
count, even on an error.

Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 fs/ext4/inline.c |    9 ++++++++-
 fs/ext4/inode.c  |   20 +++++++++++++++-----
 2 files changed, 23 insertions(+), 6 deletions(-)

--- a/fs/ext4/inline.c
+++ b/fs/ext4/inline.c
@@ -943,8 +943,15 @@ int ext4_da_write_inline_data_end(struct
 				  struct page *page)
 {
 	int i_size_changed = 0;
+	int ret;
 
-	copied = ext4_write_inline_data_end(inode, pos, len, copied, page);
+	ret = ext4_write_inline_data_end(inode, pos, len, copied, page);
+	if (ret < 0) {
+		unlock_page(page);
+		put_page(page);
+		return ret;
+	}
+	copied = ret;
 
 	/*
 	 * No need to use i_size_read() here, the i_size
--- a/fs/ext4/inode.c
+++ b/fs/ext4/inode.c
@@ -1330,8 +1330,11 @@ static int ext4_write_end(struct file *f
 	if (ext4_has_inline_data(inode)) {
 		ret = ext4_write_inline_data_end(inode, pos, len,
 						 copied, page);
-		if (ret < 0)
+		if (ret < 0) {
+			unlock_page(page);
+			put_page(page);
 			goto errout;
+		}
 		copied = ret;
 	} else
 		copied = block_write_end(file, mapping, pos,
@@ -1433,10 +1436,16 @@ static int ext4_journalled_write_end(str
 
 	BUG_ON(!ext4_handle_valid(handle));
 
-	if (ext4_has_inline_data(inode))
-		copied = ext4_write_inline_data_end(inode, pos, len,
-						    copied, page);
-	else if (unlikely(copied < len) && !PageUptodate(page)) {
+	if (ext4_has_inline_data(inode)) {
+		ret = ext4_write_inline_data_end(inode, pos, len,
+						 copied, page);
+		if (ret < 0) {
+			unlock_page(page);
+			put_page(page);
+			goto errout;
+		}
+		copied = ret;
+	} else if (unlikely(copied < len) && !PageUptodate(page)) {
 		copied = 0;
 		ext4_journalled_zero_new_buffers(handle, page, from, to);
 	} else {
@@ -1471,6 +1480,7 @@ static int ext4_journalled_write_end(str
 		 */
 		ext4_orphan_add(handle, inode);
 
+errout:
 	ret2 = ext4_journal_stop(handle);
 	if (!ret)
 		ret = ret2;

[toc] | [prev] | [next] | [standalone]


#1596962 — [PATCH 4.10 077/167] ext4: fix data corruption in data=journal mode

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 077/167] ext4: fix data corruption in data=journal mode
Message-ID<tjpEL-2rf-37@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jan Kara <jack@suse.cz>

commit 3b136499e906460919f0d21a49db1aaccf0ae963 upstream.

ext4_journalled_write_end() did not propely handle all the cases when
generic_perform_write() did not copy all the data into the target page
and could mark buffers with uninitialized contents as uptodate and dirty
leading to possible data corruption (which would be quickly fixed by
generic_perform_write() retrying the write but still). Fix the problem
by carefully handling the case when the page that is written to is not
uptodate.

Reported-by: Al Viro <viro@ZenIV.linux.org.uk>
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 fs/ext4/inode.c |   23 +++++++++++++----------
 1 file changed, 13 insertions(+), 10 deletions(-)

--- a/fs/ext4/inode.c
+++ b/fs/ext4/inode.c
@@ -1385,7 +1385,9 @@ errout:
  * set the buffer to be dirty, since in data=journalled mode we need
  * to call ext4_handle_dirty_metadata() instead.
  */
-static void zero_new_buffers(struct page *page, unsigned from, unsigned to)
+static void ext4_journalled_zero_new_buffers(handle_t *handle,
+					    struct page *page,
+					    unsigned from, unsigned to)
 {
 	unsigned int block_start = 0, block_end;
 	struct buffer_head *head, *bh;
@@ -1402,7 +1404,7 @@ static void zero_new_buffers(struct page
 					size = min(to, block_end) - start;
 
 					zero_user(page, start, size);
-					set_buffer_uptodate(bh);
+					write_end_fn(handle, bh);
 				}
 				clear_buffer_new(bh);
 			}
@@ -1434,15 +1436,16 @@ static int ext4_journalled_write_end(str
 	if (ext4_has_inline_data(inode))
 		copied = ext4_write_inline_data_end(inode, pos, len,
 						    copied, page);
-	else {
-		if (copied < len) {
-			if (!PageUptodate(page))
-				copied = 0;
-			zero_new_buffers(page, from+copied, to);
-		}
-
+	else if (unlikely(copied < len) && !PageUptodate(page)) {
+		copied = 0;
+		ext4_journalled_zero_new_buffers(handle, page, from, to);
+	} else {
+		if (unlikely(copied < len))
+			ext4_journalled_zero_new_buffers(handle, page,
+							 from + copied, to);
 		ret = ext4_walk_page_buffers(handle, page_buffers(page), from,
-					     to, &partial, write_end_fn);
+					     from + copied, &partial,
+					     write_end_fn);
 		if (!partial)
 			SetPageUptodate(page);
 	}

[toc] | [prev] | [next] | [standalone]


#1596963 — [PATCH 4.10 088/167] ath9k: use correct OTP register offsets for the AR9340 and AR9550

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 088/167] ath9k: use correct OTP register offsets for the AR9340 and AR9550
Message-ID<tjpEK-2rf-29@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Lamparter <chunkeey@googlemail.com>

commit c9f1e32600816d695f817477d56490bfc2ba43c6 upstream.

This patch fixes the OTP register definitions for the AR934x and AR9550
WMAC SoC.

Previously, the ath9k driver was unable to initialize the integrated
WMAC on an Aerohive AP121:

| ath: phy0: timeout (1000 us) on reg 0x30018: 0xbadc0ffe & 0x00000007 != 0x00000004
| ath: phy0: timeout (1000 us) on reg 0x30018: 0xbadc0ffe & 0x00000007 != 0x00000004
| ath: phy0: Unable to initialize hardware; initialization status: -5
| ath9k ar934x_wmac: failed to initialize device
| ath9k: probe of ar934x_wmac failed with error -5

It turns out that the AR9300_OTP_STATUS and AR9300_OTP_DATA
definitions contain a typo.

Cc: Gabor Juhos <juhosg@openwrt.org>
Fixes: add295a4afbdf5852d0 "ath9k: use correct OTP register offsets for AR9550"
Signed-off-by: Christian Lamparter <chunkeey@googlemail.com>
Signed-off-by: Chris Blake <chrisrblake93@gmail.com>
Signed-off-by: Kalle Valo <kvalo@qca.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/net/wireless/ath/ath9k/ar9003_eeprom.h |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/net/wireless/ath/ath9k/ar9003_eeprom.h
+++ b/drivers/net/wireless/ath/ath9k/ar9003_eeprom.h
@@ -73,13 +73,13 @@
 #define AR9300_OTP_BASE \
 		((AR_SREV_9340(ah) || AR_SREV_9550(ah)) ? 0x30000 : 0x14000)
 #define AR9300_OTP_STATUS \
-		((AR_SREV_9340(ah) || AR_SREV_9550(ah)) ? 0x30018 : 0x15f18)
+		((AR_SREV_9340(ah) || AR_SREV_9550(ah)) ? 0x31018 : 0x15f18)
 #define AR9300_OTP_STATUS_TYPE		0x7
 #define AR9300_OTP_STATUS_VALID		0x4
 #define AR9300_OTP_STATUS_ACCESS_BUSY	0x2
 #define AR9300_OTP_STATUS_SM_BUSY	0x1
 #define AR9300_OTP_READ_DATA \
-		((AR_SREV_9340(ah) || AR_SREV_9550(ah)) ? 0x3001c : 0x15f1c)
+		((AR_SREV_9340(ah) || AR_SREV_9550(ah)) ? 0x3101c : 0x15f1c)
 
 enum targetPowerHTRates {
 	HT_TARGET_RATE_0_8_16,

[toc] | [prev] | [next] | [standalone]


#1596964 — [PATCH 4.10 058/167] dm stats: fix a leaked s->histogram_boundaries array

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 058/167] dm stats: fix a leaked s->histogram_boundaries array
Message-ID<tjpEL-2rf-39@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikulas Patocka <mpatocka@redhat.com>

commit 6085831883c25860264721df15f05bbded45e2a2 upstream.

Fixes: dfcfac3e4cd9 ("dm stats: collect and report histogram of IO latencies")
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/md/dm-stats.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/md/dm-stats.c
+++ b/drivers/md/dm-stats.c
@@ -175,6 +175,7 @@ static void dm_stat_free(struct rcu_head
 	int cpu;
 	struct dm_stat *s = container_of(head, struct dm_stat, rcu_head);
 
+	kfree(s->histogram_boundaries);
 	kfree(s->program_id);
 	kfree(s->aux_data);
 	for_each_possible_cpu(cpu) {

[toc] | [prev] | [next] | [standalone]


#1596965 — [PATCH 4.10 081/167] ext4: return EROFS if device is r/o and journal replay is needed

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 081/167] ext4: return EROFS if device is r/o and journal replay is needed
Message-ID<tjpEK-2rf-33@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Theodore Ts'o <tytso@mit.edu>

commit 4753d8a24d4588657bc0a4cd66d4e282dff15c8c upstream.

If the file system requires journal recovery, and the device is
read-ony, return EROFS to the mount system call.  This allows xfstests
generic/050 to pass.

Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 fs/ext4/super.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/fs/ext4/super.c
+++ b/fs/ext4/super.c
@@ -3927,7 +3927,8 @@ static int ext4_fill_super(struct super_
 	 * root first: it may be modified in the journal!
 	 */
 	if (!test_opt(sb, NOLOAD) && ext4_has_feature_journal(sb)) {
-		if (ext4_load_journal(sb, es, journal_devnum))
+		err = ext4_load_journal(sb, es, journal_devnum);
+		if (err)
 			goto failed_mount3a;
 	} else if (test_opt(sb, NOLOAD) && !(sb->s_flags & MS_RDONLY) &&
 		   ext4_has_feature_journal_needs_recovery(sb)) {

[toc] | [prev] | [next] | [standalone]


#1596966 — [PATCH 4.10 093/167] crypto: xts - Add ECB dependency

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 093/167] crypto: xts - Add ECB dependency
Message-ID<tjpEL-2rf-41@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Milan Broz <gmazyland@gmail.com>

commit 12cb3a1c4184f891d965d1f39f8cfcc9ef617647 upstream.

Since the
   commit f1c131b45410a202eb45cc55980a7a9e4e4b4f40
   crypto: xts - Convert to skcipher
the XTS mode is based on ECB, so the mode must select
ECB otherwise it can fail to initialize.

Signed-off-by: Milan Broz <gmazyland@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 crypto/Kconfig |    1 +
 1 file changed, 1 insertion(+)

--- a/crypto/Kconfig
+++ b/crypto/Kconfig
@@ -374,6 +374,7 @@ config CRYPTO_XTS
 	select CRYPTO_BLKCIPHER
 	select CRYPTO_MANAGER
 	select CRYPTO_GF128MUL
+	select CRYPTO_ECB
 	help
 	  XTS: IEEE1619/D16 narrow block cipher use with aes-xts-plain,
 	  key size 256, 384 or 512 bits. This implementation currently

[toc] | [prev] | [next] | [standalone]


#1596967 — [PATCH 4.10 108/167] can: gs_usb: Dont use stack memory for USB transfers

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 108/167] can: gs_usb: Dont use stack memory for USB transfers
Message-ID<tjpEK-2rf-27@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ethan Zonca <e@ethanzonca.com>

commit c919a3069c775c1c876bec55e00b2305d5125caa upstream.

Fixes: 05ca5270005c can: gs_usb: add ethtool set_phys_id callback to locate physical device

The gs_usb driver is performing USB transfers using buffers allocated on
the stack. This causes the driver to not function with vmapped stacks.
Instead, allocate memory for the transfer buffers.

Signed-off-by: Ethan Zonca <e@ethanzonca.com>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/net/can/usb/gs_usb.c |   40 +++++++++++++++++++++++++++++-----------
 1 file changed, 29 insertions(+), 11 deletions(-)

--- a/drivers/net/can/usb/gs_usb.c
+++ b/drivers/net/can/usb/gs_usb.c
@@ -908,10 +908,14 @@ static int gs_usb_probe(struct usb_inter
 	struct gs_usb *dev;
 	int rc = -ENOMEM;
 	unsigned int icount, i;
-	struct gs_host_config hconf = {
-		.byte_order = 0x0000beef,
-	};
-	struct gs_device_config dconf;
+	struct gs_host_config *hconf;
+	struct gs_device_config *dconf;
+
+	hconf = kmalloc(sizeof(*hconf), GFP_KERNEL);
+	if (!hconf)
+		return -ENOMEM;
+
+	hconf->byte_order = 0x0000beef;
 
 	/* send host config */
 	rc = usb_control_msg(interface_to_usbdev(intf),
@@ -920,16 +924,22 @@ static int gs_usb_probe(struct usb_inter
 			     USB_DIR_OUT|USB_TYPE_VENDOR|USB_RECIP_INTERFACE,
 			     1,
 			     intf->altsetting[0].desc.bInterfaceNumber,
-			     &hconf,
-			     sizeof(hconf),
+			     hconf,
+			     sizeof(*hconf),
 			     1000);
 
+	kfree(hconf);
+
 	if (rc < 0) {
 		dev_err(&intf->dev, "Couldn't send data format (err=%d)\n",
 			rc);
 		return rc;
 	}
 
+	dconf = kmalloc(sizeof(*dconf), GFP_KERNEL);
+	if (!dconf)
+		return -ENOMEM;
+
 	/* read device config */
 	rc = usb_control_msg(interface_to_usbdev(intf),
 			     usb_rcvctrlpipe(interface_to_usbdev(intf), 0),
@@ -937,28 +947,33 @@ static int gs_usb_probe(struct usb_inter
 			     USB_DIR_IN|USB_TYPE_VENDOR|USB_RECIP_INTERFACE,
 			     1,
 			     intf->altsetting[0].desc.bInterfaceNumber,
-			     &dconf,
-			     sizeof(dconf),
+			     dconf,
+			     sizeof(*dconf),
 			     1000);
 	if (rc < 0) {
 		dev_err(&intf->dev, "Couldn't get device config: (err=%d)\n",
 			rc);
+		kfree(dconf);
 		return rc;
 	}
 
-	icount = dconf.icount + 1;
+	icount = dconf->icount + 1;
 	dev_info(&intf->dev, "Configuring for %d interfaces\n", icount);
 
 	if (icount > GS_MAX_INTF) {
 		dev_err(&intf->dev,
 			"Driver cannot handle more that %d CAN interfaces\n",
 			GS_MAX_INTF);
+		kfree(dconf);
 		return -EINVAL;
 	}
 
 	dev = kzalloc(sizeof(*dev), GFP_KERNEL);
-	if (!dev)
+	if (!dev) {
+		kfree(dconf);
 		return -ENOMEM;
+	}
+
 	init_usb_anchor(&dev->rx_submitted);
 
 	atomic_set(&dev->active_channels, 0);
@@ -967,7 +982,7 @@ static int gs_usb_probe(struct usb_inter
 	dev->udev = interface_to_usbdev(intf);
 
 	for (i = 0; i < icount; i++) {
-		dev->canch[i] = gs_make_candev(i, intf, &dconf);
+		dev->canch[i] = gs_make_candev(i, intf, dconf);
 		if (IS_ERR_OR_NULL(dev->canch[i])) {
 			/* save error code to return later */
 			rc = PTR_ERR(dev->canch[i]);
@@ -978,12 +993,15 @@ static int gs_usb_probe(struct usb_inter
 				gs_destroy_candev(dev->canch[i]);
 
 			usb_kill_anchored_urbs(&dev->rx_submitted);
+			kfree(dconf);
 			kfree(dev);
 			return rc;
 		}
 		dev->canch[i]->parent = dev;
 	}
 
+	kfree(dconf);
+
 	return 0;
 }
 

[toc] | [prev] | [next] | [standalone]


#1596968 — [PATCH 4.10 076/167] ext4: trim allocation requests to group size

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 076/167] ext4: trim allocation requests to group size
Message-ID<tjpEL-2rf-43@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jan Kara <jack@suse.cz>

commit cd648b8a8fd5071d232242d5ee7ee3c0815776af upstream.

If filesystem groups are artifically small (using parameter -g to
mkfs.ext4), ext4_mb_normalize_request() can result in a request that is
larger than a block group. Trim the request size to not confuse
allocation code.

Reported-by: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 fs/ext4/mballoc.c |    7 +++++++
 1 file changed, 7 insertions(+)

--- a/fs/ext4/mballoc.c
+++ b/fs/ext4/mballoc.c
@@ -3123,6 +3123,13 @@ ext4_mb_normalize_request(struct ext4_al
 	if (ar->pright && start + size - 1 >= ar->lright)
 		size -= start + size - ar->lright;
 
+	/*
+	 * Trim allocation request for filesystems with artificially small
+	 * groups.
+	 */
+	if (size > EXT4_BLOCKS_PER_GROUP(ac->ac_sb))
+		size = EXT4_BLOCKS_PER_GROUP(ac->ac_sb);
+
 	end = start + size;
 
 	/* check we don't cross already preallocated blocks */

[toc] | [prev] | [next] | [standalone]


#1596969 — [PATCH 4.10 086/167] ath5k: drop bogus warning on drv_set_key with unsupported cipher

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 086/167] ath5k: drop bogus warning on drv_set_key with unsupported cipher
Message-ID<tjpEL-2rf-45@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Fietkau <nbd@nbd.name>

commit a70e1d6fd6b5e1a81fa6171600942bee34f5128f upstream.

Simply return -EOPNOTSUPP instead.

Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Kalle Valo <kvalo@qca.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/net/wireless/ath/ath5k/mac80211-ops.c |    3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

--- a/drivers/net/wireless/ath/ath5k/mac80211-ops.c
+++ b/drivers/net/wireless/ath/ath5k/mac80211-ops.c
@@ -502,8 +502,7 @@ ath5k_set_key(struct ieee80211_hw *hw, e
 			break;
 		return -EOPNOTSUPP;
 	default:
-		WARN_ON(1);
-		return -EINVAL;
+		return -EOPNOTSUPP;
 	}
 
 	mutex_lock(&ah->lock);

[toc] | [prev] | [next] | [standalone]


#1596971 — [PATCH 4.10 094/167] crypto: testmgr - Pad aes_ccm_enc_tv_template vector

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 094/167] crypto: testmgr - Pad aes_ccm_enc_tv_template vector
Message-ID<tjpEK-2rf-23@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Laura Abbott <labbott@redhat.com>

commit 1c68bb0f62bf8de8bb30123ea840d5168f25abea upstream.

Running with KASAN and crypto tests currently gives

 BUG: KASAN: global-out-of-bounds in __test_aead+0x9d9/0x2200 at addr ffffffff8212fca0
 Read of size 16 by task cryptomgr_test/1107
 Address belongs to variable 0xffffffff8212fca0
 CPU: 0 PID: 1107 Comm: cryptomgr_test Not tainted 4.10.0+ #45
 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.9.1-1.fc24 04/01/2014
 Call Trace:
  dump_stack+0x63/0x8a
  kasan_report.part.1+0x4a7/0x4e0
  ? __test_aead+0x9d9/0x2200
  ? crypto_ccm_init_crypt+0x218/0x3c0 [ccm]
  kasan_report+0x20/0x30
  check_memory_region+0x13c/0x1a0
  memcpy+0x23/0x50
  __test_aead+0x9d9/0x2200
  ? kasan_unpoison_shadow+0x35/0x50
  ? alg_test_akcipher+0xf0/0xf0
  ? crypto_skcipher_init_tfm+0x2e3/0x310
  ? crypto_spawn_tfm2+0x37/0x60
  ? crypto_ccm_init_tfm+0xa9/0xd0 [ccm]
  ? crypto_aead_init_tfm+0x7b/0x90
  ? crypto_alloc_tfm+0xc4/0x190
  test_aead+0x28/0xc0
  alg_test_aead+0x54/0xd0
  alg_test+0x1eb/0x3d0
  ? alg_find_test+0x90/0x90
  ? __sched_text_start+0x8/0x8
  ? __wake_up_common+0x70/0xb0
  cryptomgr_test+0x4d/0x60
  kthread+0x173/0x1c0
  ? crypto_acomp_scomp_free_ctx+0x60/0x60
  ? kthread_create_on_node+0xa0/0xa0
  ret_from_fork+0x2c/0x40
 Memory state around the buggy address:
  ffffffff8212fb80: 00 00 00 00 01 fa fa fa fa fa fa fa 00 00 00 00
  ffffffff8212fc00: 00 01 fa fa fa fa fa fa 00 00 00 00 01 fa fa fa
 >ffffffff8212fc80: fa fa fa fa 00 05 fa fa fa fa fa fa 00 00 00 00
                                   ^
  ffffffff8212fd00: 01 fa fa fa fa fa fa fa 00 00 00 00 01 fa fa fa
  ffffffff8212fd80: fa fa fa fa 00 00 00 00 00 05 fa fa fa fa fa fa

This always happens on the same IV which is less than 16 bytes.

Per Ard,

"CCM IVs are 16 bytes, but due to the way they are constructed
internally, the final couple of bytes of input IV are dont-cares.

Apparently, we do read all 16 bytes, which triggers the KASAN errors."

Fix this by padding the IV with null bytes to be at least 16 bytes.

Fixes: 0bc5a6c5c79a ("crypto: testmgr - Disable rfc4309 test and convert test vectors")
Acked-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Laura Abbott <labbott@redhat.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 crypto/testmgr.h |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/crypto/testmgr.h
+++ b/crypto/testmgr.h
@@ -22827,7 +22827,7 @@ static struct aead_testvec aes_ccm_enc_t
 			  "\x09\x75\x9a\x9b\x3c\x9b\x27\x39",
 		.klen	= 32,
 		.iv	= "\x03\xf9\xd9\x4e\x63\xb5\x3d\x9d"
-			  "\x43\xf6\x1e\x50",
+			  "\x43\xf6\x1e\x50\0\0\0\0",
 		.assoc	= "\x57\xf5\x6b\x8b\x57\x5c\x3d\x3b"
 			  "\x13\x02\x01\x0c\x83\x4c\x96\x35"
 			  "\x8e\xd6\x39\xcf\x7d\x14\x9b\x94"

[toc] | [prev] | [next] | [standalone]


#1596972 — [PATCH 4.10 063/167] scsi: storvsc: properly set residual data length on errors

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 063/167] scsi: storvsc: properly set residual data length on errors
Message-ID<tjpEK-2rf-25@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Long Li <longli@microsoft.com>

commit 40630f462824ee24bc00d692865c86c3828094e0 upstream.

On I/O errors, the Windows driver doesn't set data_transfer_length
on error conditions other than SRB_STATUS_DATA_OVERRUN.
In these cases we need to set data_transfer_length to 0,
indicating there is no data transferred. On SRB_STATUS_DATA_OVERRUN,
data_transfer_length is set by the Windows driver to the actual data transferred.

Reported-by: Shiva Krishna <Shiva.Krishna@nimblestorage.com>
Signed-off-by: Long Li <longli@microsoft.com>
Reviewed-by: K. Y. Srinivasan <kys@microsoft.com>
Signed-off-by: K. Y. Srinivasan <kys@microsoft.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/scsi/storvsc_drv.c |   16 +++++++++++++---
 1 file changed, 13 insertions(+), 3 deletions(-)

--- a/drivers/scsi/storvsc_drv.c
+++ b/drivers/scsi/storvsc_drv.c
@@ -377,6 +377,7 @@ enum storvsc_request_type {
 #define SRB_STATUS_SUCCESS	0x01
 #define SRB_STATUS_ABORTED	0x02
 #define SRB_STATUS_ERROR	0x04
+#define SRB_STATUS_DATA_OVERRUN	0x12
 
 #define SRB_STATUS(status) \
 	(status & ~(SRB_STATUS_AUTOSENSE_VALID | SRB_STATUS_QUEUE_FROZEN))
@@ -962,6 +963,7 @@ static void storvsc_command_completion(s
 	struct scsi_cmnd *scmnd = cmd_request->cmd;
 	struct scsi_sense_hdr sense_hdr;
 	struct vmscsi_request *vm_srb;
+	u32 data_transfer_length;
 	struct Scsi_Host *host;
 	u32 payload_sz = cmd_request->payload_sz;
 	void *payload = cmd_request->payload;
@@ -969,6 +971,7 @@ static void storvsc_command_completion(s
 	host = stor_dev->host;
 
 	vm_srb = &cmd_request->vstor_packet.vm_srb;
+	data_transfer_length = vm_srb->data_transfer_length;
 
 	scmnd->result = vm_srb->scsi_status;
 
@@ -982,13 +985,20 @@ static void storvsc_command_completion(s
 					     &sense_hdr);
 	}
 
-	if (vm_srb->srb_status != SRB_STATUS_SUCCESS)
+	if (vm_srb->srb_status != SRB_STATUS_SUCCESS) {
 		storvsc_handle_error(vm_srb, scmnd, host, sense_hdr.asc,
 					 sense_hdr.ascq);
+		/*
+		 * The Windows driver set data_transfer_length on
+		 * SRB_STATUS_DATA_OVERRUN. On other errors, this value
+		 * is untouched.  In these cases we set it to 0.
+		 */
+		if (vm_srb->srb_status != SRB_STATUS_DATA_OVERRUN)
+			data_transfer_length = 0;
+	}
 
 	scsi_set_resid(scmnd,
-		cmd_request->payload->range.len -
-		vm_srb->data_transfer_length);
+		cmd_request->payload->range.len - data_transfer_length);
 
 	scmnd->scsi_done(scmnd);
 

[toc] | [prev] | [next] | [standalone]


#1596973 — [PATCH 4.10 080/167] ext4: preserve the needs_recovery flag when the journal is aborted

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 080/167] ext4: preserve the needs_recovery flag when the journal is aborted
Message-ID<tjpEL-2rf-49@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Theodore Ts'o <tytso@mit.edu>

commit 97abd7d4b5d9c48ec15c425485f054e1c15e591b upstream.

If the journal is aborted, the needs_recovery feature flag should not
be removed.  Otherwise, it's the journal might not get replayed and
this could lead to more data getting lost.

Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 fs/ext4/super.c |    6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

--- a/fs/ext4/super.c
+++ b/fs/ext4/super.c
@@ -825,6 +825,7 @@ static void ext4_put_super(struct super_
 {
 	struct ext4_sb_info *sbi = EXT4_SB(sb);
 	struct ext4_super_block *es = sbi->s_es;
+	int aborted = 0;
 	int i, err;
 
 	ext4_unregister_li_request(sb);
@@ -834,9 +835,10 @@ static void ext4_put_super(struct super_
 	destroy_workqueue(sbi->rsv_conversion_wq);
 
 	if (sbi->s_journal) {
+		aborted = is_journal_aborted(sbi->s_journal);
 		err = jbd2_journal_destroy(sbi->s_journal);
 		sbi->s_journal = NULL;
-		if (err < 0)
+		if ((err < 0) && !aborted)
 			ext4_abort(sb, "Couldn't clean up the journal");
 	}
 
@@ -847,7 +849,7 @@ static void ext4_put_super(struct super_
 	ext4_mb_release(sb);
 	ext4_ext_release(sb);
 
-	if (!(sb->s_flags & MS_RDONLY)) {
+	if (!(sb->s_flags & MS_RDONLY) && !aborted) {
 		ext4_clear_feature_journal_needs_recovery(sb);
 		es->s_state = cpu_to_le16(sbi->s_mount_state);
 	}

[toc] | [prev] | [next] | [standalone]


#1596974 — [PATCH 4.10 062/167] scsi: storvsc: properly handle SRB_ERROR when sense message is present

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:10 +0100
Subject[PATCH 4.10 062/167] scsi: storvsc: properly handle SRB_ERROR when sense message is present
Message-ID<tjpEL-2rf-47@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Long Li <longli@microsoft.com>

commit bba5dc332ec2d3a685cb4dae668c793f6a3713a3 upstream.

When sense message is present on error, we should pass along to the upper
layer to decide how to deal with the error.
This patch fixes connectivity issues with Fiber Channel devices.

Signed-off-by: Long Li <longli@microsoft.com>
Reviewed-by: K. Y. Srinivasan <kys@microsoft.com>
Signed-off-by: K. Y. Srinivasan <kys@microsoft.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/scsi/storvsc_drv.c |    7 +++++++
 1 file changed, 7 insertions(+)

--- a/drivers/scsi/storvsc_drv.c
+++ b/drivers/scsi/storvsc_drv.c
@@ -891,6 +891,13 @@ static void storvsc_handle_error(struct
 	switch (SRB_STATUS(vm_srb->srb_status)) {
 	case SRB_STATUS_ERROR:
 		/*
+		 * Let upper layer deal with error when
+		 * sense message is present.
+		 */
+
+		if (vm_srb->srb_status & SRB_STATUS_AUTOSENSE_VALID)
+			break;
+		/*
 		 * If there is an error; offline the device since all
 		 * error recovery strategies would have already been
 		 * deployed on the host side. However, if the command

[toc] | [prev] | [next] | [standalone]


#1596975 — [PATCH 4.10 049/167] mm balloon: umount balloon_mnt when removing vb device

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:20 +0100
Subject[PATCH 4.10 049/167] mm balloon: umount balloon_mnt when removing vb device
Message-ID<tjpOp-2xo-3@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yisheng Xie <xieyisheng1@huawei.com>

commit 9c57b5808c625f4fc93da330b932647eaff321f7 upstream.

With CONFIG_BALLOON_COMPACTION=y the kernel will mount balloon_mnt for
balloon page migration when we probe a virtio_balloon device.  However
we do not unmount it when removing the device.  Fix this.

Fixes: b1123ea6d3b3 ("mm: balloon: use general non-lru movable page feature")
Link: http://lkml.kernel.org/r/1486531318-35189-1-git-send-email-xieyisheng1@huawei.com
Signed-off-by: Yisheng Xie <xieyisheng1@huawei.com>
Acked-by: Minchan Kim <minchan@kernel.org>
Cc: Rafael Aquini <aquini@redhat.com>
Cc: Konstantin Khlebnikov <koct9i@gmail.com>
Cc: Gioh Kim <gi-oh.kim@profitbricks.com>
Cc: Vlastimil Babka <vbabka@suse.cz>
Cc: Michal Hocko <mhocko@kernel.org>
Cc: Michael S. Tsirkin <mst@redhat.com>
Cc: Jason Wang <jasowang@redhat.com>
Cc: Hanjun Guo <guohanjun@huawei.com>
Cc: Xishi Qiu <qiuxishi@huawei.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/virtio/virtio_balloon.c |    4 ++++
 1 file changed, 4 insertions(+)

--- a/drivers/virtio/virtio_balloon.c
+++ b/drivers/virtio/virtio_balloon.c
@@ -615,8 +615,12 @@ static void virtballoon_remove(struct vi
 	cancel_work_sync(&vb->update_balloon_stats_work);
 
 	remove_common(vb);
+#ifdef CONFIG_BALLOON_COMPACTION
 	if (vb->vb_dev_info.inode)
 		iput(vb->vb_dev_info.inode);
+
+	kern_unmount(balloon_mnt);
+#endif
 	kfree(vb);
 }
 

[toc] | [prev] | [next] | [standalone]


#1596976 — [PATCH 4.10 052/167] sigaltstack: support SS_AUTODISARM for CONFIG_COMPAT

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:20 +0100
Subject[PATCH 4.10 052/167] sigaltstack: support SS_AUTODISARM for CONFIG_COMPAT
Message-ID<tjpOp-2xo-1@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stas Sergeev <stsp@list.ru>

commit 441398d378f29a5ad6d0fcda07918e54e4961800 upstream.

Currently SS_AUTODISARM is not supported in compatibility mode, but does
not return -EINVAL either.  This makes dosemu built with -m32 on x86_64
to crash.  Also the kernel's sigaltstack selftest fails if compiled with
-m32.

This patch adds the needed support.

Link: http://lkml.kernel.org/r/20170205101213.8163-2-stsp@list.ru
Signed-off-by: Stas Sergeev <stsp@users.sourceforge.net>
Cc: Milosz Tanski <milosz@adfin.com>
Cc: Andy Lutomirski <luto@kernel.org>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Arnd Bergmann <arnd@arndb.de>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Ingo Molnar <mingo@kernel.org>
Cc: Oleg Nesterov <oleg@redhat.com>
Cc: Nicolas Pitre <nicolas.pitre@linaro.org>
Cc: Waiman Long <Waiman.Long@hpe.com>
Cc: Dave Hansen <dave.hansen@linux.intel.com>
Cc: Dmitry Safonov <dsafonov@virtuozzo.com>
Cc: Wang Xiaoqiang <wangxq10@lzu.edu.cn>
Cc: Oleg Nesterov <oleg@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 include/linux/compat.h |    4 +++-
 kernel/signal.c        |   11 +++++++++--
 2 files changed, 12 insertions(+), 3 deletions(-)

--- a/include/linux/compat.h
+++ b/include/linux/compat.h
@@ -711,8 +711,10 @@ int __compat_save_altstack(compat_stack_
 	compat_stack_t __user *__uss = uss; \
 	struct task_struct *t = current; \
 	put_user_ex(ptr_to_compat((void __user *)t->sas_ss_sp), &__uss->ss_sp); \
-	put_user_ex(sas_ss_flags(sp), &__uss->ss_flags); \
+	put_user_ex(t->sas_ss_flags, &__uss->ss_flags); \
 	put_user_ex(t->sas_ss_size, &__uss->ss_size); \
+	if (t->sas_ss_flags & SS_AUTODISARM) \
+		sas_ss_reset(t); \
 } while (0);
 
 asmlinkage long compat_sys_sched_rr_get_interval(compat_pid_t pid,
--- a/kernel/signal.c
+++ b/kernel/signal.c
@@ -3239,10 +3239,17 @@ int compat_restore_altstack(const compat
 
 int __compat_save_altstack(compat_stack_t __user *uss, unsigned long sp)
 {
+	int err;
 	struct task_struct *t = current;
-	return  __put_user(ptr_to_compat((void __user *)t->sas_ss_sp), &uss->ss_sp) |
-		__put_user(sas_ss_flags(sp), &uss->ss_flags) |
+	err = __put_user(ptr_to_compat((void __user *)t->sas_ss_sp),
+			 &uss->ss_sp) |
+		__put_user(t->sas_ss_flags, &uss->ss_flags) |
 		__put_user(t->sas_ss_size, &uss->ss_size);
+	if (err)
+		return err;
+	if (t->sas_ss_flags & SS_AUTODISARM)
+		sas_ss_reset(t);
+	return 0;
 }
 #endif
 

[toc] | [prev] | [next] | [standalone]


#1596977 — [PATCH 4.10 072/167] block/loop: fix race between I/O and set_status

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:20 +0100
Subject[PATCH 4.10 072/167] block/loop: fix race between I/O and set_status
Message-ID<tjpOp-2xo-5@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ming Lei <tom.leiming@gmail.com>

commit ecdd09597a57251323b0de50e3d45e69298c4a83 upstream.

Inside set_status, transfer need to setup again, so
we have to drain IO before the transition, otherwise
oops may be triggered like the following:

	divide error: 0000 [#1] SMP KASAN
	CPU: 0 PID: 2935 Comm: loop7 Not tainted 4.10.0-rc7+ #213
	Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs
	01/01/2011
	task: ffff88006ba1e840 task.stack: ffff880067338000
	RIP: 0010:transfer_xor+0x1d1/0x440 drivers/block/loop.c:110
	RSP: 0018:ffff88006733f108 EFLAGS: 00010246
	RAX: 0000000000000000 RBX: ffff8800688d7000 RCX: 0000000000000059
	RDX: 0000000000000000 RSI: 1ffff1000d743f43 RDI: ffff880068891c08
	RBP: ffff88006733f160 R08: ffff8800688d7001 R09: 0000000000000000
	R10: 0000000000000000 R11: 0000000000000000 R12: ffff8800688d7000
	R13: ffff880067b7d000 R14: dffffc0000000000 R15: 0000000000000000
	FS:  0000000000000000(0000) GS:ffff88006d000000(0000)
	knlGS:0000000000000000
	CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
	CR2: 00000000006c17e0 CR3: 0000000066e3b000 CR4: 00000000001406f0
	Call Trace:
	 lo_do_transfer drivers/block/loop.c:251 [inline]
	 lo_read_transfer drivers/block/loop.c:392 [inline]
	 do_req_filebacked drivers/block/loop.c:541 [inline]
	 loop_handle_cmd drivers/block/loop.c:1677 [inline]
	 loop_queue_work+0xda0/0x49b0 drivers/block/loop.c:1689
	 kthread_worker_fn+0x4c3/0xa30 kernel/kthread.c:630
	 kthread+0x326/0x3f0 kernel/kthread.c:227
	 ret_from_fork+0x31/0x40 arch/x86/entry/entry_64.S:430
	Code: 03 83 e2 07 41 29 df 42 0f b6 04 30 4d 8d 44 24 01 38 d0 7f 08
	84 c0 0f 85 62 02 00 00 44 89 f8 41 0f b6 48 ff 25 ff 01 00 00 99 <f7>
	7d c8 48 63 d2 48 03 55 d0 48 89 d0 48 89 d7 48 c1 e8 03 83
	RIP: transfer_xor+0x1d1/0x440 drivers/block/loop.c:110 RSP:
	ffff88006733f108
	---[ end trace 0166f7bd3b0c0933 ]---

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Ming Lei <tom.leiming@gmail.com>
Tested-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Jens Axboe <axboe@fb.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/block/loop.c |   17 ++++++++++++-----
 1 file changed, 12 insertions(+), 5 deletions(-)

--- a/drivers/block/loop.c
+++ b/drivers/block/loop.c
@@ -1097,9 +1097,12 @@ loop_set_status(struct loop_device *lo,
 	if ((unsigned int) info->lo_encrypt_key_size > LO_KEY_SIZE)
 		return -EINVAL;
 
+	/* I/O need to be drained during transfer transition */
+	blk_mq_freeze_queue(lo->lo_queue);
+
 	err = loop_release_xfer(lo);
 	if (err)
-		return err;
+		goto exit;
 
 	if (info->lo_encrypt_type) {
 		unsigned int type = info->lo_encrypt_type;
@@ -1114,12 +1117,14 @@ loop_set_status(struct loop_device *lo,
 
 	err = loop_init_xfer(lo, xfer, info);
 	if (err)
-		return err;
+		goto exit;
 
 	if (lo->lo_offset != info->lo_offset ||
 	    lo->lo_sizelimit != info->lo_sizelimit)
-		if (figure_loop_size(lo, info->lo_offset, info->lo_sizelimit))
-			return -EFBIG;
+		if (figure_loop_size(lo, info->lo_offset, info->lo_sizelimit)) {
+			err = -EFBIG;
+			goto exit;
+		}
 
 	loop_config_discard(lo);
 
@@ -1156,7 +1161,9 @@ loop_set_status(struct loop_device *lo,
 	/* update dio if lo_offset or transfer is changed */
 	__loop_update_dio(lo, lo->use_dio);
 
-	return 0;
+ exit:
+	blk_mq_unfreeze_queue(lo->lo_queue);
+	return err;
 }
 
 static int

[toc] | [prev] | [next] | [standalone]


#1596978 — [PATCH 4.10 057/167] dm cache: fix corruption seen when using cache > 2TB

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:20 +0100
Subject[PATCH 4.10 057/167] dm cache: fix corruption seen when using cache > 2TB
Message-ID<tjpOp-2xo-7@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joe Thornber <ejt@redhat.com>

commit ca763d0a53b264a650342cee206512bc92ac7050 upstream.

A rounding bug due to compiler generated temporary being 32bit was found
in remap_to_cache().  A localized cast in remap_to_cache() fixes the
corruption but this preferred fix (changing from uint32_t to sector_t)
eliminates potential for future rounding errors elsewhere.

Signed-off-by: Joe Thornber <ejt@redhat.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/md/dm-cache-target.c |    6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

--- a/drivers/md/dm-cache-target.c
+++ b/drivers/md/dm-cache-target.c
@@ -248,7 +248,7 @@ struct cache {
 	/*
 	 * Fields for converting from sectors to blocks.
 	 */
-	uint32_t sectors_per_block;
+	sector_t sectors_per_block;
 	int sectors_per_block_shift;
 
 	spinlock_t lock;
@@ -3547,11 +3547,11 @@ static void cache_status(struct dm_targe
 
 		residency = policy_residency(cache->policy);
 
-		DMEMIT("%u %llu/%llu %u %llu/%llu %u %u %u %u %u %u %lu ",
+		DMEMIT("%u %llu/%llu %llu %llu/%llu %u %u %u %u %u %u %lu ",
 		       (unsigned)DM_CACHE_METADATA_BLOCK_SIZE,
 		       (unsigned long long)(nr_blocks_metadata - nr_free_blocks_metadata),
 		       (unsigned long long)nr_blocks_metadata,
-		       cache->sectors_per_block,
+		       (unsigned long long)cache->sectors_per_block,
 		       (unsigned long long) from_cblock(residency),
 		       (unsigned long long) from_cblock(cache->cache_size),
 		       (unsigned) atomic_read(&cache->stats.read_hit),

[toc] | [prev] | [next] | [standalone]


#1596979 — [PATCH 4.10 054/167] ima: fix ima_d_path() possible race with rename

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-03-10 11:20 +0100
Subject[PATCH 4.10 054/167] ima: fix ima_d_path() possible race with rename
Message-ID<tjpOq-2xo-9@gated-at.bofh.it>
In reply to#1596796
4.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mimi Zohar <zohar@linux.vnet.ibm.com>

commit bc15ed663e7e53ee4dc3e60f8d09c93a0528c694 upstream.

On failure to return a pathname from ima_d_path(), a pointer to
dname is returned, which is subsequently used in the IMA measurement
list, the IMA audit records, and other audit logging.  Saving the
pointer to dname for later use has the potential to race with rename.

Intead of returning a pointer to dname on failure, this patch returns
a pointer to a copy of the filename.

Reported-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 security/integrity/ima/ima.h      |    2 +-
 security/integrity/ima/ima_api.c  |   20 ++++++++++++++++++--
 security/integrity/ima/ima_main.c |    8 +++++---
 3 files changed, 24 insertions(+), 6 deletions(-)

--- a/security/integrity/ima/ima.h
+++ b/security/integrity/ima/ima.h
@@ -204,7 +204,7 @@ int ima_store_template(struct ima_templa
 		       struct inode *inode,
 		       const unsigned char *filename, int pcr);
 void ima_free_template_entry(struct ima_template_entry *entry);
-const char *ima_d_path(const struct path *path, char **pathbuf);
+const char *ima_d_path(const struct path *path, char **pathbuf, char *filename);
 
 /* IMA policy related functions */
 int ima_match_policy(struct inode *inode, enum ima_hooks func, int mask,
--- a/security/integrity/ima/ima_api.c
+++ b/security/integrity/ima/ima_api.c
@@ -318,7 +318,17 @@ void ima_audit_measurement(struct integr
 	iint->flags |= IMA_AUDITED;
 }
 
-const char *ima_d_path(const struct path *path, char **pathbuf)
+/*
+ * ima_d_path - return a pointer to the full pathname
+ *
+ * Attempt to return a pointer to the full pathname for use in the
+ * IMA measurement list, IMA audit records, and auditing logs.
+ *
+ * On failure, return a pointer to a copy of the filename, not dname.
+ * Returning a pointer to dname, could result in using the pointer
+ * after the memory has been freed.
+ */
+const char *ima_d_path(const struct path *path, char **pathbuf, char *namebuf)
 {
 	char *pathname = NULL;
 
@@ -331,5 +341,11 @@ const char *ima_d_path(const struct path
 			pathname = NULL;
 		}
 	}
-	return pathname ?: (const char *)path->dentry->d_name.name;
+
+	if (!pathname) {
+		strlcpy(namebuf, path->dentry->d_name.name, NAME_MAX);
+		pathname = namebuf;
+	}
+
+	return pathname;
 }
--- a/security/integrity/ima/ima_main.c
+++ b/security/integrity/ima/ima_main.c
@@ -83,6 +83,7 @@ static void ima_rdwr_violation_check(str
 				     const char **pathname)
 {
 	struct inode *inode = file_inode(file);
+	char filename[NAME_MAX];
 	fmode_t mode = file->f_mode;
 	bool send_tomtou = false, send_writers = false;
 
@@ -102,7 +103,7 @@ static void ima_rdwr_violation_check(str
 	if (!send_tomtou && !send_writers)
 		return;
 
-	*pathname = ima_d_path(&file->f_path, pathbuf);
+	*pathname = ima_d_path(&file->f_path, pathbuf, filename);
 
 	if (send_tomtou)
 		ima_add_violation(file, *pathname, iint,
@@ -161,6 +162,7 @@ static int process_measurement(struct fi
 	struct integrity_iint_cache *iint = NULL;
 	struct ima_template_desc *template_desc;
 	char *pathbuf = NULL;
+	char filename[NAME_MAX];
 	const char *pathname = NULL;
 	int rc = -ENOMEM, action, must_appraise;
 	int pcr = CONFIG_IMA_MEASURE_PCR_IDX;
@@ -239,8 +241,8 @@ static int process_measurement(struct fi
 		goto out_digsig;
 	}
 
-	if (!pathname)	/* ima_rdwr_violation possibly pre-fetched */
-		pathname = ima_d_path(&file->f_path, &pathbuf);
+	if (!pathbuf)	/* ima_rdwr_violation possibly pre-fetched */
+		pathname = ima_d_path(&file->f_path, &pathbuf, filename);
 
 	if (action & IMA_MEASURE)
 		ima_store_measurement(iint, file, pathname,

[toc] | [prev] | [next] | [standalone]


Page 6 of 9 — ← Prev page 1 2 3 4 5 [6] 7 8 9  Next page →

Back to top | Article view | linux.kernel


csiph-web