Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1597344 > unrolled thread

[PATCH 3.2 000/199] 3.2.87-rc1 review

Started byBen Hutchings <ben@decadent.org.uk>
First post2017-03-10 13:20 +0100
Last post2017-03-12 19:20 +0100
Articles 20 on this page of 129 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.2 000/199] 3.2.87-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:20 +0100
    [PATCH 3.2 191/199] tun: read vnet_hdr_sz once Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:20 +0100
    [PATCH 3.2 017/199] ext4: fix stack memory corruption with 64k  block size Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 028/199] thermal: hwmon: Properly report critical  temperature in sysfs Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 188/199] ipv6: pointer math error in ip6_tnl_parse_tlv_enc_lim() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 186/199] can: Fix kernel panic at security_sock_rcv_skb Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 009/199] PCI: Check for PME in targeted sleep state Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 194/199] mld: do not remove mld souce list info when  set link down Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 012/199] powerpc/ibmebus: Fix device reference leaks  in sysfs interface Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 029/199] USB: serial: kl5kusb105: fix open error path Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 024/199] dm crypt: mark key as invalid until properly  loaded Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 016/199] ext4: fix mballoc breakage with 64k block size Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
    [PATCH 3.2 196/199] Revert "KVM: x86: expose MSR_TSC_AUX to  userspace" Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
    [PATCH 3.2 195/199] igmp, mld: Fix memory leak in igmpv3/mld_del_delrec() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
    [PATCH 3.2 015/199] usb: xhci-mem: use passed in GFP flags  instead of GFP_KERNEL Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
    [PATCH 3.2 025/199] [media] DaVinci-VPFE-Capture: fix error handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
    [PATCH 3.2 190/199] tun: Fix TUN_PKT_STRIP setting Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
    [PATCH 3.2 019/199] scsi: mvsas: fix command_active typo Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
    [PATCH 3.2 014/199] powerpc/pci/rpadlpar: Fix device reference leaks Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 146/199] net/llc: avoid BUG_ON() in skb_orphan() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    Re: [PATCH 3.2 000/199] 3.2.87-rc1 review Guenter Roeck <linux@roeck-us.net> - 2017-03-10 13:50 +0100
      Re: [PATCH 3.2 000/199] 3.2.87-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 021/199] ext4: fix in-superblock mount options processing Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 137/199] catc: Combine failure cleanup code in  catc_probe() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 004/199] perf scripting: Avoid leaking the  scripting_context variable Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 001/199] staging: iio: ad7606: fix improper setting of  oversampling pins Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 110/199] xhci: fix deadlock at host remove by running  watchdog correctly Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 129/199] can: bcm: fix hrtimer/tasklet termination in  bcm op removal Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 104/199] gro: Disable frag0 optimization on IPv6 ext  headers Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 113/199] svcrpc: don't leak contexts on PROC_DESTROY Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 086/199] x86/cpu: Fix bootup crashes by sanitizing the  argument of the 'clearcpuid=' command-line option Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 136/199] rtl8150: Use heap buffers for all register access Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 126/199] USB: Add quirk for WORLDE easykey.25 MIDI  keyboard Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 120/199] powerpc/ptrace: Preserve previous fprs/vsrs  on short regset write Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 087/199] usb: musb: Fix trying to free already-free IRQ 4 Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 141/199] ping: fix a null pointer dereference Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 082/199] USB: serial: pl2303: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 134/199] mac80211: Fix adding of mesh vendor IEs Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 132/199] mm, fs: check for fatal signals in  do_generic_file_read() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 116/199] can: ti_hecc: add missing prepare and  unprepare of the clock Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 145/199] net/sock: Add sock_efree() function Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 047/199] IB/mad: Fix an array index check Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 071/199] USB: serial: iuu_phoenix: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 119/199] nbd: only set MSG_MORE when we have more to send Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 122/199] platform/x86: intel_mid_powerbtn: Set IRQ_ONESHOT Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 083/199] USB: serial: spcp8x5: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 056/199] net: korina: Fix NAPI versus resources freeing Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 139/199] ALSA: seq: Fix race at creating a queue Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 117/199] ceph: fix bad endianness handling in  parse_reply_info_extra Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 106/199] sysrq: attach sysrq handler correctly for  32-bit kernel Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 103/199] gro: Enter slow-path if there is no tailroom Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 105/199] ocfs2: fix crash caused by stale lvb with  fsdlm plugin Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 125/199] mm/huge_memory.c: respect FOLL_FORCE/FOLL_COW  for thp Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 068/199] USB: serial: io_edgeport: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 124/199] USB: serial: option: add device ID for HP  lt2523 (Novatel E371) Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 131/199] USB: serial: pl2303: add ATEN device ID Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 123/199] crypto: api - Clear CRYPTO_ALG_DEAD bit  before registering an alg Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 127/199] sysctl: fix proc_doulongvec_ms_jiffies_minmax() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 096/199] USB: serial: ch341: fix initial modem-control  state Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 092/199] USB: ch341: remove redundant close from open  error path Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 115/199] ubifs: Fix journal replay wrt. xattr nodes Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 101/199] USB: serial: ch341: fix baud rate and  line-control handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 050/199] scsi: zfcp: do not trace pure benign residual  HBA responses at default level Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 088/199] USB: fix problems with duplicate endpoint  addresses Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 128/199] parisc: Don't use BITS_PER_LONG in  userspace-exported swab.h header Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 108/199] USB: serial: ch341: fix control-message error  handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 076/199] USB: serial: mos7720: fix parport  use-after-free on probe errors Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 090/199] ata: sata_mv:- Handle return value of  devm_ioremap. Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 080/199] USB: serial: omninet: fix NULL-derefs at open  and disconnect Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 061/199] usb: gadgetfs: restrict upper bound on device  configuration size Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 067/199] USB: serial: garmin_gps: fix memory leak on  failed URB submit Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 085/199] iommu/amd: Fix the left value check of cmd buffer Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 070/199] USB: serial: io_ti: fix another NULL-deref at  open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 062/199] USB: gadgetfs: fix unbounded memory  allocation bug Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 093/199] USB: ch341: set tty baud speed according to  tty struct Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 073/199] USB: serial: kobil_sct: fix NULL-deref in write Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 075/199] USB: serial: mos7720: fix use-after-free on  probe errors Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 063/199] USB: gadgetfs: fix use-after-free bug Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 048/199] IB/multicast: Check ib_find_pkey() return value Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 074/199] USB: serial: mos7720: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 053/199] target/iscsi: Fix double free in  lio_target_tiqn_addtpg() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 049/199] scsi: zfcp: fix use-after-"free" in FC  ingress path after TMF Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 079/199] USB: serial: mos7840: fix misleading  interrupt-URB comment Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 058/199] net/mlx4: Remove BUG_ON from ICM allocation  routine Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 069/199] USB: serial: io_ti: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 097/199] USB: serial: ch341: fix open and resume after B0 Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 064/199] USB: gadgetfs: fix checks of wTotalLength in  config descriptors Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 077/199] USB: serial: mos7720: fix parallel probe Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 078/199] USB: serial: mos7840: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 081/199] USB: serial: oti6858: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 066/199] USB: serial: cyberjack: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 098/199] USB: serial: ch341: fix modem-control and B0  handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 089/199] HID: hid-cypress: validate length of report Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 094/199] USB: serial: ch341: add register and USB  request definitions Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 055/199] net, sched: fix soft lockup in tc_classify Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 040/199] ext4: reject inodes with negative size Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 037/199] USB: serial: option: add support for Telit  LE922A PIDs 0x1040, 0x1041 Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 044/199] libceph: verify authorize reply on connect Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 005/199] usb: gadget: composite: correctly initialize  ep->maxpacket Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 051/199] scsi: zfcp: fix rport unblock race with LUN  recovery Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 059/199] usb: gadget: composite: Test get_alt()  presence instead of set_alt() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 038/199] hwmon: (ds620) Fix overflows seen when  writing temperature limits Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 045/199] fsnotify: Fix possible use-after-free in  inode iteration on umount Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 046/199] block_dev: don't test bdev->bd_contains when  it is not stable Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 031/199] drivers: base: dma-mapping: Fix typo in  dmam_alloc_non_coherent comments Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 065/199] xhci: free xhci virtual devices with leaf  nodes first Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 034/199] USB: cdc-acm: add device id for GW Instek AFG-125 Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 036/199] ALSA: usb-audio: Add QuickCam Communicate  Deluxe/S7500 to volume_control_quirks Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 022/199] ext4: use more strict checks for  inodes_per_block on mount Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 002/199] net/sched: em_meta: Fix 'meta vlan' to  correctly recognize zero VID frames Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 041/199] kconfig/nconf: Fix hang when editing symbol  with a long prompt Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 032/199] powerpc/ps3: Fix system hang with GCC 5 builds Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 010/199] USB: UHCI: report non-PME wakeup signalling  for Intel hardware Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 057/199] net/mlx4_en: Fix bad WQE issue Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 006/199] drm/gma500: Add compat ioctl Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 008/199] xfs: fix up xfs_swap_extent_forks inline  extent handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 035/199] hotplug: Make register and unregister  notifier API symmetric Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 039/199] nfs_write_end(): fix handling of short copies Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 026/199] regmap: cache: Remove unused 'blksize' variable Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 052/199] scsi: avoid a permanent stop of the scsi  device's request queue Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 033/199] Btrfs: fix tree search logic when replaying  directory entry deletes Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 030/199] USB: serial: kl5kusb105: abort on open  exception path Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 054/199] Input: i8042 - add Pegatron touchpad to  noloop table Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 060/199] USB: dummy-hcd: fix bug in stop_activity  (handle ep0) Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 000/202] 3.2.87-rc2 review Ben Hutchings <ben@decadent.org.uk> - 2017-03-11 16:30 +0100
      [PATCH 3.2 202/202] tty: n_hdlc: get rid of racy n_hdlc.tbuf Ben Hutchings <ben@decadent.org.uk> - 2017-03-11 16:30 +0100
      [PATCH 3.2 201/202] list: introduce list_first_entry_or_null Ben Hutchings <ben@decadent.org.uk> - 2017-03-11 16:30 +0100
      [PATCH 3.2 200/202] TTY: n_hdlc, fix lockdep false positive Ben Hutchings <ben@decadent.org.uk> - 2017-03-11 16:30 +0100
      Re: [PATCH 3.2 000/202] 3.2.87-rc2 review Guenter Roeck <linux@roeck-us.net> - 2017-03-12 19:20 +0100

Page 5 of 7 — ← Prev page 1 2 3 4 [5] 6 7  Next page →


#1597505 — [PATCH 3.2 053/199] target/iscsi: Fix double free in lio_target_tiqn_addtpg()

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 053/199] target/iscsi: Fix double free in lio_target_tiqn_addtpg()
Message-ID<tjssX-4sG-49@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Dan Carpenter <dan.carpenter@oracle.com>

commit a91918cd3ea11f91c68e08e1e8ce1b560447a80e upstream.

This iscsit_tpg_add_portal_group() function is only called from
lio_target_tiqn_addtpg().  Both functions free the "tpg" pointer on
error so it's a double free bug.  The memory is allocated in the caller
so it should be freed in the caller and not here.

Fixes: e48354ce078c ("iscsi-target: Add iSCSI fabric support for target v4.1")
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Reviewed-by: David Disseldorp <ddiss@suse.de>
[ bvanassche: Added "Fix" at start of patch title ]
Signed-off-by: Bart Van Assche <bart.vanassche@sandisk.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/target/iscsi/iscsi_target_tpg.c | 1 -
 1 file changed, 1 deletion(-)

--- a/drivers/target/iscsi/iscsi_target_tpg.c
+++ b/drivers/target/iscsi/iscsi_target_tpg.c
@@ -253,7 +253,6 @@ err_out:
 		iscsi_release_param_list(tpg->param_list);
 		tpg->param_list = NULL;
 	}
-	kfree(tpg);
 	return -ENOMEM;
 }
 

[toc] | [prev] | [next] | [standalone]


#1597506 — [PATCH 3.2 049/199] scsi: zfcp: fix use-after-"free" in FC ingress path after TMF

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 049/199] scsi: zfcp: fix use-after-"free" in FC ingress path after TMF
Message-ID<tjssX-4sG-47@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Benjamin Block <bblock@linux.vnet.ibm.com>

commit dac37e15b7d511e026a9313c8c46794c144103cd upstream.

When SCSI EH invokes zFCP's callbacks for eh_device_reset_handler() and
eh_target_reset_handler(), it expects us to relent the ownership over
the given scsi_cmnd and all other scsi_cmnds within the same scope - LUN
or target - when returning with SUCCESS from the callback ('release'
them).  SCSI EH can then reuse those commands.

We did not follow this rule to release commands upon SUCCESS; and if
later a reply arrived for one of those supposed to be released commands,
we would still make use of the scsi_cmnd in our ingress tasklet. This
will at least result in undefined behavior or a kernel panic because of
a wrong kernel pointer dereference.

To fix this, we NULLify all pointers to scsi_cmnds (struct zfcp_fsf_req
*)->data in the matching scope if a TMF was successful. This is done
under the locks (struct zfcp_adapter *)->abort_lock and (struct
zfcp_reqlist *)->lock to prevent the requests from being removed from
the request-hashtable, and the ingress tasklet from making use of the
scsi_cmnd-pointer in zfcp_fsf_fcp_cmnd_handler().

For cases where a reply arrives during SCSI EH, but before we get a
chance to NULLify the pointer - but before we return from the callback
-, we assume that the code is protected from races via the CAS operation
in blk_complete_request() that is called in scsi_done().

The following stacktrace shows an example for a crash resulting from the
previous behavior:

Unable to handle kernel pointer dereference at virtual kernel address fffffee17a672000
Oops: 0038 [#1] SMP
CPU: 2 PID: 0 Comm: swapper/2 Not tainted
task: 00000003f7ff5be0 ti: 00000003f3d38000 task.ti: 00000003f3d38000
Krnl PSW : 0404d00180000000 00000000001156b0 (smp_vcpu_scheduled+0x18/0x40)
           R:0 T:1 IO:0 EX:0 Key:0 M:1 W:0 P:0 AS:3 CC:1 PM:0 EA:3
Krnl GPRS: 000000200000007e 0000000000000000 fffffee17a671fd8 0000000300000015
           ffffffff80000000 00000000005dfde8 07000003f7f80e00 000000004fa4e800
           000000036ce8d8f8 000000036ce8d9c0 00000003ece8fe00 ffffffff969c9e93
           00000003fffffffd 000000036ce8da10 00000000003bf134 00000003f3b07918
Krnl Code: 00000000001156a2: a7190000        lghi    %r1,0
           00000000001156a6: a7380015        lhi    %r3,21
          #00000000001156aa: e32050000008    ag    %r2,0(%r5)
          >00000000001156b0: 482022b0        lh    %r2,688(%r2)
           00000000001156b4: ae123000        sigp    %r1,%r2,0(%r3)
           00000000001156b8: b2220020        ipm    %r2
           00000000001156bc: 8820001c        srl    %r2,28
           00000000001156c0: c02700000001    xilf    %r2,1
Call Trace:
([<0000000000000000>] 0x0)
 [<000003ff807bdb8e>] zfcp_fsf_fcp_cmnd_handler+0x3de/0x490 [zfcp]
 [<000003ff807be30a>] zfcp_fsf_req_complete+0x252/0x800 [zfcp]
 [<000003ff807c0a48>] zfcp_fsf_reqid_check+0xe8/0x190 [zfcp]
 [<000003ff807c194e>] zfcp_qdio_int_resp+0x66/0x188 [zfcp]
 [<000003ff80440c64>] qdio_kick_handler+0xdc/0x310 [qdio]
 [<000003ff804463d0>] __tiqdio_inbound_processing+0xf8/0xcd8 [qdio]
 [<0000000000141fd4>] tasklet_action+0x9c/0x170
 [<0000000000141550>] __do_softirq+0xe8/0x258
 [<000000000010ce0a>] do_softirq+0xba/0xc0
 [<000000000014187c>] irq_exit+0xc4/0xe8
 [<000000000046b526>] do_IRQ+0x146/0x1d8
 [<00000000005d6a3c>] io_return+0x0/0x8
 [<00000000005d6422>] vtime_stop_cpu+0x4a/0xa0
([<0000000000000000>] 0x0)
 [<0000000000103d8a>] arch_cpu_idle+0xa2/0xb0
 [<0000000000197f94>] cpu_startup_entry+0x13c/0x1f8
 [<0000000000114782>] smp_start_secondary+0xda/0xe8
 [<00000000005d6efe>] restart_int_handler+0x56/0x6c
 [<0000000000000000>] 0x0
Last Breaking-Event-Address:
 [<00000000003bf12e>] arch_spin_lock_wait+0x56/0xb0

Suggested-by: Steffen Maier <maier@linux.vnet.ibm.com>
Signed-off-by: Benjamin Block <bblock@linux.vnet.ibm.com>
Fixes: ea127f9754 ("[PATCH] s390 (7/7): zfcp host adapter.") (tglx/history.git)
Signed-off-by: Steffen Maier <maier@linux.vnet.ibm.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/s390/scsi/zfcp_dbf.h     | 11 ++++++++
 drivers/s390/scsi/zfcp_reqlist.h | 30 ++++++++++++++++++++-
 drivers/s390/scsi/zfcp_scsi.c    | 57 ++++++++++++++++++++++++++++++++++++++--
 3 files changed, 95 insertions(+), 3 deletions(-)

--- a/drivers/s390/scsi/zfcp_dbf.h
+++ b/drivers/s390/scsi/zfcp_dbf.h
@@ -388,4 +388,15 @@ void zfcp_dbf_scsi_devreset(char *tag, s
 	_zfcp_dbf_scsi(tmp_tag, 1, scmnd, NULL);
 }
 
+/**
+ * zfcp_dbf_scsi_nullcmnd() - trace NULLify of SCSI command in dev/tgt-reset.
+ * @scmnd: SCSI command that was NULLified.
+ * @fsf_req: request that owned @scmnd.
+ */
+static inline void zfcp_dbf_scsi_nullcmnd(struct scsi_cmnd *scmnd,
+					  struct zfcp_fsf_req *fsf_req)
+{
+	_zfcp_dbf_scsi("scfc__1", 3, scmnd, fsf_req);
+}
+
 #endif /* ZFCP_DBF_H */
--- a/drivers/s390/scsi/zfcp_reqlist.h
+++ b/drivers/s390/scsi/zfcp_reqlist.h
@@ -4,7 +4,7 @@
  * Data structure and helper functions for tracking pending FSF
  * requests.
  *
- * Copyright IBM Corporation 2009
+ * Copyright IBM Corp. 2009, 2016
  */
 
 #ifndef ZFCP_REQLIST_H
@@ -180,4 +180,32 @@ static inline void zfcp_reqlist_move(str
 	spin_unlock_irqrestore(&rl->lock, flags);
 }
 
+/**
+ * zfcp_reqlist_apply_for_all() - apply a function to every request.
+ * @rl: the requestlist that contains the target requests.
+ * @f: the function to apply to each request; the first parameter of the
+ *     function will be the target-request; the second parameter is the same
+ *     pointer as given with the argument @data.
+ * @data: freely chosen argument; passed through to @f as second parameter.
+ *
+ * Uses :c:macro:`list_for_each_entry` to iterate over the lists in the hash-
+ * table (not a 'safe' variant, so don't modify the list).
+ *
+ * Holds @rl->lock over the entire request-iteration.
+ */
+static inline void
+zfcp_reqlist_apply_for_all(struct zfcp_reqlist *rl,
+			   void (*f)(struct zfcp_fsf_req *, void *), void *data)
+{
+	struct zfcp_fsf_req *req;
+	unsigned long flags;
+	unsigned int i;
+
+	spin_lock_irqsave(&rl->lock, flags);
+	for (i = 0; i < ZFCP_REQ_LIST_BUCKETS; i++)
+		list_for_each_entry(req, &rl->buckets[i], list)
+			f(req, data);
+	spin_unlock_irqrestore(&rl->lock, flags);
+}
+
 #endif /* ZFCP_REQLIST_H */
--- a/drivers/s390/scsi/zfcp_scsi.c
+++ b/drivers/s390/scsi/zfcp_scsi.c
@@ -3,7 +3,7 @@
  *
  * Interface to Linux SCSI midlayer.
  *
- * Copyright IBM Corp. 2002, 2015
+ * Copyright IBM Corp. 2002, 2016
  */
 
 #define KMSG_COMPONENT "zfcp"
@@ -230,6 +230,57 @@ static int zfcp_scsi_eh_abort_handler(st
 	return retval;
 }
 
+struct zfcp_scsi_req_filter {
+	u8 tmf_scope;
+	u32 lun_handle;
+	u32 port_handle;
+};
+
+static void zfcp_scsi_forget_cmnd(struct zfcp_fsf_req *old_req, void *data)
+{
+	struct zfcp_scsi_req_filter *filter =
+		(struct zfcp_scsi_req_filter *)data;
+
+	/* already aborted - prevent side-effects - or not a SCSI command */
+	if (old_req->data == NULL || old_req->fsf_command != FSF_QTCB_FCP_CMND)
+		return;
+
+	/* (tmf_scope == FCP_TMF_TGT_RESET || tmf_scope == FCP_TMF_LUN_RESET) */
+	if (old_req->qtcb->header.port_handle != filter->port_handle)
+		return;
+
+	if (filter->tmf_scope == FCP_TMF_LUN_RESET &&
+	    old_req->qtcb->header.lun_handle != filter->lun_handle)
+		return;
+
+	zfcp_dbf_scsi_nullcmnd((struct scsi_cmnd *)old_req->data, old_req);
+	old_req->data = NULL;
+}
+
+static void zfcp_scsi_forget_cmnds(struct zfcp_scsi_dev *zsdev, u8 tm_flags)
+{
+	struct zfcp_adapter *adapter = zsdev->port->adapter;
+	struct zfcp_scsi_req_filter filter = {
+		.tmf_scope = FCP_TMF_TGT_RESET,
+		.port_handle = zsdev->port->handle,
+	};
+	unsigned long flags;
+
+	if (tm_flags == FCP_TMF_LUN_RESET) {
+		filter.tmf_scope = FCP_TMF_LUN_RESET;
+		filter.lun_handle = zsdev->lun_handle;
+	}
+
+	/*
+	 * abort_lock secures against other processings - in the abort-function
+	 * and normal cmnd-handler - of (struct zfcp_fsf_req *)->data
+	 */
+	write_lock_irqsave(&adapter->abort_lock, flags);
+	zfcp_reqlist_apply_for_all(adapter->req_list, zfcp_scsi_forget_cmnd,
+				   &filter);
+	write_unlock_irqrestore(&adapter->abort_lock, flags);
+}
+
 static int zfcp_task_mgmt_function(struct scsi_cmnd *scpnt, u8 tm_flags)
 {
 	struct zfcp_scsi_dev *zfcp_sdev = sdev_to_zfcp(scpnt->device);
@@ -262,8 +313,10 @@ static int zfcp_task_mgmt_function(struc
 	if (fsf_req->status & ZFCP_STATUS_FSFREQ_TMFUNCFAILED) {
 		zfcp_dbf_scsi_devreset("fail", scpnt, tm_flags);
 		retval = FAILED;
-	} else
+	} else {
 		zfcp_dbf_scsi_devreset("okay", scpnt, tm_flags);
+		zfcp_scsi_forget_cmnds(zfcp_sdev, tm_flags);
+	}
 
 	zfcp_fsf_req_free(fsf_req);
 	return retval;

[toc] | [prev] | [next] | [standalone]


#1597507 — [PATCH 3.2 079/199] USB: serial: mos7840: fix misleading interrupt-URB comment

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 079/199] USB: serial: mos7840: fix misleading interrupt-URB comment
Message-ID<tjssX-4sG-53@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 472d7e55d559aa1cbf58c73b14fcfc4651b1a9f5 upstream.

The interrupt URB is killed at final port close since commit
0de9a7024e7a ("USB: overhaul of mos7840 driver").

Fixes: 0de9a7024e7a ("USB: overhaul of mos7840 driver")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/mos7840.c | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

--- a/drivers/usb/serial/mos7840.c
+++ b/drivers/usb/serial/mos7840.c
@@ -1071,9 +1071,7 @@ static int mos7840_open(struct tty_struc
 				serial,
 				serial->port[0]->interrupt_in_urb->interval);
 
-			/* start interrupt read for mos7840               *
-			 * will continue as long as mos7840 is connected  */
-
+			/* start interrupt read for mos7840 */
 			response =
 			    usb_submit_urb(serial->port[0]->interrupt_in_urb,
 					   GFP_KERNEL);

[toc] | [prev] | [next] | [standalone]


#1597508 — [PATCH 3.2 058/199] net/mlx4: Remove BUG_ON from ICM allocation routine

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 058/199] net/mlx4: Remove BUG_ON from ICM allocation routine
Message-ID<tjssX-4sG-59@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Leon Romanovsky <leonro@mellanox.com>

commit c1d5f8ff80ea84768f5fae1ca9d1abfbb5e6bbaa upstream.

This patch removes BUG_ON() macro from mlx4_alloc_icm_coherent()
by checking DMA address alignment in advance and performing proper
folding in case of error.

Fixes: 5b0bf5e25efe ("mlx4_core: Support ICM tables in coherent memory")
Reported-by: Ozgur Karatas <okaratas@member.fsf.org>
Signed-off-by: Leon Romanovsky <leonro@mellanox.com>
Signed-off-by: Tariq Toukan <tariqt@mellanox.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/net/ethernet/mellanox/mlx4/icm.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

--- a/drivers/net/ethernet/mellanox/mlx4/icm.c
+++ b/drivers/net/ethernet/mellanox/mlx4/icm.c
@@ -113,8 +113,13 @@ static int mlx4_alloc_icm_coherent(struc
 	if (!buf)
 		return -ENOMEM;
 
+	if (offset_in_page(buf)) {
+		dma_free_coherent(dev, PAGE_SIZE << order,
+				  buf, sg_dma_address(mem));
+		return -ENOMEM;
+	}
+
 	sg_set_buf(mem, buf, PAGE_SIZE << order);
-	BUG_ON(mem->offset);
 	sg_dma_len(mem) = PAGE_SIZE << order;
 	return 0;
 }

[toc] | [prev] | [next] | [standalone]


#1597509 — [PATCH 3.2 069/199] USB: serial: io_ti: fix NULL-deref at open

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 069/199] USB: serial: io_ti: fix NULL-deref at open
Message-ID<tjssY-4sG-63@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit a323fefc6f5079844dc62ffeb54f491d0242ca35 upstream.

Fix NULL-pointer dereference when clearing halt at open should a
malicious device lack the expected endpoints when in download mode.

Unable to handle kernel NULL pointer dereference at virtual address 00000030
...
[<bf011ed8>] (edge_open [io_ti]) from [<bf000118>] (serial_port_activate+0x68/0x98 [usbserial])
[<bf000118>] (serial_port_activate [usbserial]) from [<c0470ca4>] (tty_port_open+0x9c/0xe8)
[<c0470ca4>] (tty_port_open) from [<bf000da0>] (serial_open+0x48/0x6c [usbserial])
[<bf000da0>] (serial_open [usbserial]) from [<c0469178>] (tty_open+0xcc/0x5cc)

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/io_ti.c | 7 +++++++
 1 file changed, 7 insertions(+)

--- a/drivers/usb/serial/io_ti.c
+++ b/drivers/usb/serial/io_ti.c
@@ -2642,6 +2642,13 @@ static int edge_startup(struct usb_seria
 
 	dev = serial->dev;
 
+	/* Make sure we have the required endpoints when in download mode. */
+	if (serial->interface->cur_altsetting->desc.bNumEndpoints > 1) {
+		if (serial->num_bulk_in < serial->num_ports ||
+				serial->num_bulk_out < serial->num_ports)
+			return -ENODEV;
+	}
+
 	/* create our private serial structure */
 	edge_serial = kzalloc(sizeof(struct edgeport_serial), GFP_KERNEL);
 	if (edge_serial == NULL) {

[toc] | [prev] | [next] | [standalone]


#1597510 — [PATCH 3.2 097/199] USB: serial: ch341: fix open and resume after B0

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 097/199] USB: serial: ch341: fix open and resume after B0
Message-ID<tjssX-4sG-55@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit a20047f36e2f6a1eea4f1fd261aaa55882369868 upstream.

The private baud_rate variable is used to configure the port at open and
reset-resume and must never be set to (and left at) zero or reset-resume
and all further open attempts will fail.

Fixes: aa91def41a7b ("USB: ch341: set tty baud speed according to tty
struct")
Fixes: 664d5df92e88 ("USB: usb-serial ch341: support for DTR/RTS/CTS")
Signed-off-by: Johan Hovold <johan@kernel.org>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/drivers/usb/serial/ch341.c
+++ b/drivers/usb/serial/ch341.c
@@ -366,14 +366,15 @@ static void ch341_set_termios(struct tty
 
 	baud_rate = tty_get_baud_rate(tty);
 
-	priv->baud_rate = baud_rate;
-
 	ctrl = CH341_LCR_ENABLE_RX | CH341_LCR_ENABLE_TX | CH341_LCR_CS8;
 
 	if (baud_rate) {
 		spin_lock_irqsave(&priv->lock, flags);
 		priv->line_control |= (CH341_BIT_DTR | CH341_BIT_RTS);
 		spin_unlock_irqrestore(&priv->lock, flags);
+
+		priv->baud_rate = baud_rate;
+
 		r = ch341_init_set_baudrate(port->serial->dev, priv, ctrl);
 		if (r < 0 && old_termios) {
 			priv->baud_rate = tty_termios_baud_rate(old_termios);

[toc] | [prev] | [next] | [standalone]


#1597511 — [PATCH 3.2 064/199] USB: gadgetfs: fix checks of wTotalLength in config descriptors

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 064/199] USB: gadgetfs: fix checks of wTotalLength in config descriptors
Message-ID<tjssX-4sG-51@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Alan Stern <stern@rowland.harvard.edu>

commit 1c069b057dcf64fada952eaa868d35f02bb0cfc2 upstream.

Andrey Konovalov's fuzz testing of gadgetfs showed that we should
improve the driver's checks for valid configuration descriptors passed
in by the user.  In particular, the driver needs to verify that the
wTotalLength value in the descriptor is not too short (smaller
than USB_DT_CONFIG_SIZE).  And the check for whether wTotalLength is
too large has to be changed, because the driver assumes there is
always enough room remaining in the buffer to hold a device descriptor
(at least USB_DT_DEVICE_SIZE bytes).

This patch adds the additional check and fixes the existing check.  It
may do a little more than strictly necessary, but one extra check
won't hurt.

Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
CC: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
[bwh: Backported to 3.2: adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/gadget/inode.c | 10 +++++++---
 1 file changed, 7 insertions(+), 3 deletions(-)

--- a/drivers/usb/gadget/inode.c
+++ b/drivers/usb/gadget/inode.c
@@ -1841,10 +1841,12 @@ static struct usb_gadget_driver probe_dr
  * such as configuration notifications.
  */
 
-static int is_valid_config (struct usb_config_descriptor *config)
+static int is_valid_config(struct usb_config_descriptor *config,
+		unsigned int total)
 {
 	return config->bDescriptorType == USB_DT_CONFIG
 		&& config->bLength == USB_DT_CONFIG_SIZE
+		&& total >= USB_DT_CONFIG_SIZE
 		&& config->bConfigurationValue != 0
 		&& (config->bmAttributes & USB_CONFIG_ATT_ONE) != 0
 		&& (config->bmAttributes & USB_CONFIG_ATT_WAKEUP) == 0;
@@ -1886,7 +1888,8 @@ dev_config (struct file *fd, const char
 	/* full or low speed config */
 	dev->config = (void *) kbuf;
 	total = le16_to_cpu(dev->config->wTotalLength);
-	if (!is_valid_config (dev->config) || total >= length)
+	if (!is_valid_config(dev->config, total) ||
+			total > length - USB_DT_DEVICE_SIZE)
 		goto fail;
 	kbuf += total;
 	length -= total;
@@ -1895,7 +1898,8 @@ dev_config (struct file *fd, const char
 	if (kbuf [1] == USB_DT_CONFIG) {
 		dev->hs_config = (void *) kbuf;
 		total = le16_to_cpu(dev->hs_config->wTotalLength);
-		if (!is_valid_config (dev->hs_config) || total >= length)
+		if (!is_valid_config(dev->hs_config, total) ||
+				total > length - USB_DT_DEVICE_SIZE)
 			goto fail;
 		kbuf += total;
 		length -= total;

[toc] | [prev] | [next] | [standalone]


#1597512 — [PATCH 3.2 077/199] USB: serial: mos7720: fix parallel probe

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 077/199] USB: serial: mos7720: fix parallel probe
Message-ID<tjssY-4sG-67@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit fde1faf872ed86d88e245191bc15a8e57368cd1c upstream.

A static usb-serial-driver structure that is used to initialise the
interrupt URB was modified during probe depending on the currently
probed device type, something which could break a parallel probe of a
device of a different type.

Fix this up by overriding the default completion callback for MCS7715
devices in attach() instead. We may want to use two usb-serial driver
instances for the two types later.

Fixes: fb088e335d78 ("USB: serial: add support for serial port on the
moschip 7715")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/mos7720.c | 30 +++++++-----------------------
 1 file changed, 7 insertions(+), 23 deletions(-)

--- a/drivers/usb/serial/mos7720.c
+++ b/drivers/usb/serial/mos7720.c
@@ -73,8 +73,6 @@ struct moschip_port {
 
 static int debug;
 
-static struct usb_serial_driver moschip7720_2port_driver;
-
 #define USB_VENDOR_ID_MOSCHIP		0x9710
 #define MOSCHIP_DEVICE_ID_7720		0x7720
 #define MOSCHIP_DEVICE_ID_7715		0x7715
@@ -1001,25 +999,6 @@ static void mos7720_bulk_out_data_callba
 	tty_kref_put(tty);
 }
 
-/*
- * mos77xx_probe
- *	this function installs the appropriate read interrupt endpoint callback
- *	depending on whether the device is a 7720 or 7715, thus avoiding costly
- *	run-time checks in the high-frequency callback routine itself.
- */
-static int mos77xx_probe(struct usb_serial *serial,
-			 const struct usb_device_id *id)
-{
-	if (id->idProduct == MOSCHIP_DEVICE_ID_7715)
-		moschip7720_2port_driver.read_int_callback =
-			mos7715_interrupt_callback;
-	else
-		moschip7720_2port_driver.read_int_callback =
-			mos7720_interrupt_callback;
-
-	return 0;
-}
-
 static int mos77xx_calc_num_ports(struct usb_serial *serial)
 {
 	u16 product = le16_to_cpu(serial->dev->descriptor.idProduct);
@@ -2108,6 +2087,12 @@ static int mos7720_startup(struct usb_se
 			tmp->interrupt_in_endpointAddress;
 		serial->port[1]->interrupt_in_urb = NULL;
 		serial->port[1]->interrupt_in_buffer = NULL;
+
+		if (serial->port[0]->interrupt_in_urb) {
+			struct urb *urb = serial->port[0]->interrupt_in_urb;
+
+			urb->complete = mos7715_interrupt_callback;
+		}
 	}
 
 
@@ -2228,7 +2213,6 @@ static struct usb_serial_driver moschip7
 	.close			= mos7720_close,
 	.throttle		= mos7720_throttle,
 	.unthrottle		= mos7720_unthrottle,
-	.probe			= mos77xx_probe,
 	.attach			= mos7720_startup,
 	.release		= mos7720_release,
 	.ioctl			= mos7720_ioctl,
@@ -2241,7 +2225,7 @@ static struct usb_serial_driver moschip7
 	.chars_in_buffer	= mos7720_chars_in_buffer,
 	.break_ctl		= mos7720_break,
 	.read_bulk_callback	= mos7720_bulk_in_callback,
-	.read_int_callback	= NULL  /* dynamically assigned in probe() */
+	.read_int_callback	= mos7720_interrupt_callback,
 };
 
 static int __init moschip7720_init(void)

[toc] | [prev] | [next] | [standalone]


#1597513 — [PATCH 3.2 078/199] USB: serial: mos7840: fix NULL-deref at open

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 078/199] USB: serial: mos7840: fix NULL-deref at open
Message-ID<tjssY-4sG-69@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 5c75633ef751dd4cd8f443dc35152c1ae563162e upstream.

Fix NULL-pointer dereference in open() should the device lack the
expected endpoints:

Unable to handle kernel NULL pointer dereference at virtual address 00000030
...
PC is at mos7840_open+0x88/0x8dc [mos7840]

Note that we continue to treat the interrupt-in endpoint as optional for
now.

Fixes: 3f5429746d91 ("USB: Moschip 7840 USB-Serial Driver")
Signed-off-by: Johan Hovold <johan@kernel.org>
[bwh: Backported to 3.2: add this check to the existing
 usb_serial_driver::attach implementation]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/mos7840.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

--- a/drivers/usb/serial/mos7840.c
+++ b/drivers/usb/serial/mos7840.c
@@ -2386,6 +2386,12 @@ static int mos7840_startup(struct usb_se
 		return -1;
 	}
 
+	if (serial->num_bulk_in < serial->num_ports ||
+			serial->num_bulk_out < serial->num_ports) {
+		dev_err(&serial->interface->dev, "missing endpoints\n");
+		return -ENODEV;
+	}
+
 	dev = serial->dev;
 
 	dbg("%s", "Entering...");

[toc] | [prev] | [next] | [standalone]


#1597514 — [PATCH 3.2 081/199] USB: serial: oti6858: fix NULL-deref at open

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 081/199] USB: serial: oti6858: fix NULL-deref at open
Message-ID<tjssX-4sG-61@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 5afeef2366db14587b65558bbfd5a067542e07fb upstream.

Fix NULL-pointer dereference in open() should the device lack the
expected endpoints:

Unable to handle kernel NULL pointer dereference at virtual address 00000030
...
PC is at oti6858_open+0x30/0x1d0 [oti6858]

Note that a missing interrupt-in endpoint would have caused open() to
fail.

Fixes: 49cdee0ed0fc ("USB: oti6858 usb-serial driver (in Nokia CA-42
cable)")
Signed-off-by: Johan Hovold <johan@kernel.org>
[bwh: Backported to 3.2: add this check to the existing
 usb_serial_driver::attach implementation]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/drivers/usb/serial/oti6858.c
+++ b/drivers/usb/serial/oti6858.c
@@ -347,9 +347,17 @@ static void send_data(struct work_struct
 static int oti6858_startup(struct usb_serial *serial)
 {
 	struct usb_serial_port *port = serial->port[0];
+	unsigned char num_ports = serial->num_ports;
 	struct oti6858_private *priv;
 	int i;
 
+	if (serial->num_bulk_in < num_ports ||
+			serial->num_bulk_out < num_ports ||
+			serial->num_interrupt_in < num_ports) {
+		dev_err(&serial->interface->dev, "missing endpoints\n");
+		return -ENODEV;
+	}
+
 	for (i = 0; i < serial->num_ports; ++i) {
 		priv = kzalloc(sizeof(struct oti6858_private), GFP_KERNEL);
 		if (!priv)

[toc] | [prev] | [next] | [standalone]


#1597515 — [PATCH 3.2 066/199] USB: serial: cyberjack: fix NULL-deref at open

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 066/199] USB: serial: cyberjack: fix NULL-deref at open
Message-ID<tjssY-4sG-65@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 3dca01114dcecb1cf324534cd8d75fd1306a516b upstream.

Fix NULL-pointer dereference when clearing halt at open should the device
lack a bulk-out endpoint.

Unable to handle kernel NULL pointer dereference at virtual address 00000030
...
PC is at cyberjack_open+0x40/0x9c [cyberjack]

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
[bwh: Backported to 3.2: add this check to the existing
 usb_serial_driver::attach implementation]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/drivers/usb/serial/cyberjack.c
+++ b/drivers/usb/serial/cyberjack.c
@@ -122,6 +122,9 @@ static int cyberjack_startup(struct usb_
 
 	dbg("%s", __func__);
 
+	if (serial->num_bulk_out < serial->num_ports)
+		return -ENODEV;
+
 	/* allocate the private data structure */
 	priv = kmalloc(sizeof(struct cyberjack_private), GFP_KERNEL);
 	if (!priv)

[toc] | [prev] | [next] | [standalone]


#1597516 — [PATCH 3.2 098/199] USB: serial: ch341: fix modem-control and B0 handling

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 098/199] USB: serial: ch341: fix modem-control and B0 handling
Message-ID<tjssY-4sG-77@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 030ee7ae52a46a2be52ccc8242c4a330aba8d38e upstream.

The modem-control signals are managed by the tty-layer during open and
should not be asserted prematurely when set_termios is called from
driver open.

Also make sure that the signals are asserted only when changing speed
from B0.

Fixes: 664d5df92e88 ("USB: usb-serial ch341: support for DTR/RTS/CTS")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/ch341.c | 16 +++++++---------
 1 file changed, 7 insertions(+), 9 deletions(-)

--- a/drivers/usb/serial/ch341.c
+++ b/drivers/usb/serial/ch341.c
@@ -369,10 +369,6 @@ static void ch341_set_termios(struct tty
 	ctrl = CH341_LCR_ENABLE_RX | CH341_LCR_ENABLE_TX | CH341_LCR_CS8;
 
 	if (baud_rate) {
-		spin_lock_irqsave(&priv->lock, flags);
-		priv->line_control |= (CH341_BIT_DTR | CH341_BIT_RTS);
-		spin_unlock_irqrestore(&priv->lock, flags);
-
 		priv->baud_rate = baud_rate;
 
 		r = ch341_init_set_baudrate(port->serial->dev, priv, ctrl);
@@ -380,13 +376,14 @@ static void ch341_set_termios(struct tty
 			priv->baud_rate = tty_termios_baud_rate(old_termios);
 			tty_termios_copy_hw(tty->termios, old_termios);
 		}
-	} else {
-		spin_lock_irqsave(&priv->lock, flags);
-		priv->line_control &= ~(CH341_BIT_DTR | CH341_BIT_RTS);
-		spin_unlock_irqrestore(&priv->lock, flags);
 	}
 
-	ch341_set_handshake(port->serial->dev, priv->line_control);
+	spin_lock_irqsave(&priv->lock, flags);
+	if (C_BAUD(tty) == B0)
+		priv->line_control &= ~(CH341_BIT_DTR | CH341_BIT_RTS);
+	else if (old_termios && (old_termios->c_cflag & CBAUD) == B0)
+		priv->line_control |= (CH341_BIT_DTR | CH341_BIT_RTS);
+	spin_unlock_irqrestore(&priv->lock, flags);
 
 	/* Unimplemented:
 	 * (cflag & CSIZE) : data bits [5, 8]

[toc] | [prev] | [next] | [standalone]


#1597518 — [PATCH 3.2 089/199] HID: hid-cypress: validate length of report

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 089/199] HID: hid-cypress: validate length of report
Message-ID<tjssY-4sG-73@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

commit 1ebb71143758f45dc0fa76e2f48429e13b16d110 upstream.

Make sure we have enough of a report structure to validate before
looking at it.

Reported-by: Benoit Camredon <benoit.camredon@airbus.com>
Tested-by: Benoit Camredon <benoit.camredon@airbus.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/hid/hid-cypress.c | 3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/hid/hid-cypress.c
+++ b/drivers/hid/hid-cypress.c
@@ -40,6 +40,9 @@ static __u8 *cp_report_fixup(struct hid_
 	if (!(quirks & CP_RDESC_SWAPPED_MIN_MAX))
 		return rdesc;
 
+	if (*rsize < 4)
+		return rdesc;
+
 	for (i = 0; i < *rsize - 4; i++)
 		if (rdesc[i] == 0x29 && rdesc[i + 2] == 0x19) {
 			__u8 tmp;

[toc] | [prev] | [next] | [standalone]


#1597520 — [PATCH 3.2 094/199] USB: serial: ch341: add register and USB request definitions

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 094/199] USB: serial: ch341: add register and USB request definitions
Message-ID<tjssY-4sG-75@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Aidan Thornton <makosoft@gmail.com>

commit 6fde8d29b0424f292a4ec5dbce01458ad759a41f upstream.

No functional changes, this just gives names to some registers and USB
requests based on Grigori Goronzy's work and WinChipTech's Linux driver
(which reassuringly agree), then uses them in place of magic numbers.
This also renames the misnamed BREAK2 register (actually UART config)

Signed-off-by: Aidan Thornton <makosoft@gmail.com>
Reviewed-by: Grigori Goronzy <greg@chown.ath.cx>
Signed-off-by: Johan Hovold <johan@kernel.org>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/ch341.c | 51 +++++++++++++++++++++++++++++-----------------
 1 file changed, 32 insertions(+), 19 deletions(-)

--- a/drivers/usb/serial/ch341.c
+++ b/drivers/usb/serial/ch341.c
@@ -62,13 +62,26 @@
  * the Net/FreeBSD uchcom.c driver by Takanori Watanabe.  Domo arigato.
  */
 
+#define CH341_REQ_READ_VERSION 0x5F
 #define CH341_REQ_WRITE_REG    0x9A
 #define CH341_REQ_READ_REG     0x95
-#define CH341_REG_BREAK1       0x05
-#define CH341_REG_BREAK2       0x18
-#define CH341_NBREAK_BITS_REG1 0x01
-#define CH341_NBREAK_BITS_REG2 0x40
+#define CH341_REQ_SERIAL_INIT  0xA1
+#define CH341_REQ_MODEM_CTRL   0xA4
 
+#define CH341_REG_BREAK        0x05
+#define CH341_REG_LCR          0x18
+#define CH341_NBREAK_BITS      0x01
+
+#define CH341_LCR_ENABLE_RX    0x80
+#define CH341_LCR_ENABLE_TX    0x40
+#define CH341_LCR_MARK_SPACE   0x20
+#define CH341_LCR_PAR_EVEN     0x10
+#define CH341_LCR_ENABLE_PAR   0x08
+#define CH341_LCR_STOP_BITS_2  0x04
+#define CH341_LCR_CS8          0x03
+#define CH341_LCR_CS7          0x02
+#define CH341_LCR_CS6          0x01
+#define CH341_LCR_CS5          0x00
 
 static int debug;
 
@@ -147,9 +160,9 @@ static int ch341_set_baudrate(struct usb
 	a = (factor & 0xff00) | divisor;
 	b = factor & 0xff;
 
-	r = ch341_control_out(dev, 0x9a, 0x1312, a);
+	r = ch341_control_out(dev, CH341_REQ_WRITE_REG, 0x1312, a);
 	if (!r)
-		r = ch341_control_out(dev, 0x9a, 0x0f2c, b);
+		r = ch341_control_out(dev, CH341_REQ_WRITE_REG, 0x0f2c, b);
 
 	return r;
 }
@@ -157,7 +170,7 @@ static int ch341_set_baudrate(struct usb
 static int ch341_set_handshake(struct usb_device *dev, u8 control)
 {
 	dbg("ch341_set_handshake(0x%02x)", control);
-	return ch341_control_out(dev, 0xa4, ~control, 0);
+	return ch341_control_out(dev, CH341_REQ_MODEM_CTRL, ~control, 0);
 }
 
 static int ch341_get_status(struct usb_device *dev, struct ch341_private *priv)
@@ -173,7 +186,7 @@ static int ch341_get_status(struct usb_d
 	if (!buffer)
 		return -ENOMEM;
 
-	r = ch341_control_in(dev, 0x95, 0x0706, 0, buffer, size);
+	r = ch341_control_in(dev, CH341_REQ_READ_REG, 0x0706, 0, buffer, size);
 	if (r < 0)
 		goto out;
 
@@ -206,11 +219,11 @@ static int ch341_configure(struct usb_de
 		return -ENOMEM;
 
 	/* expect two bytes 0x27 0x00 */
-	r = ch341_control_in(dev, 0x5f, 0, 0, buffer, size);
+	r = ch341_control_in(dev, CH341_REQ_READ_VERSION, 0, 0, buffer, size);
 	if (r < 0)
 		goto out;
 
-	r = ch341_control_out(dev, 0xa1, 0, 0);
+	r = ch341_control_out(dev, CH341_REQ_SERIAL_INIT, 0, 0);
 	if (r < 0)
 		goto out;
 
@@ -219,11 +232,11 @@ static int ch341_configure(struct usb_de
 		goto out;
 
 	/* expect two bytes 0x56 0x00 */
-	r = ch341_control_in(dev, 0x95, 0x2518, 0, buffer, size);
+	r = ch341_control_in(dev, CH341_REQ_READ_REG, 0x2518, 0, buffer, size);
 	if (r < 0)
 		goto out;
 
-	r = ch341_control_out(dev, 0x9a, 0x2518, 0x0050);
+	r = ch341_control_out(dev, CH341_REQ_WRITE_REG, 0x2518, 0x0050);
 	if (r < 0)
 		goto out;
 
@@ -232,7 +245,7 @@ static int ch341_configure(struct usb_de
 	if (r < 0)
 		goto out;
 
-	r = ch341_control_out(dev, 0xa1, 0x501f, 0xd90a);
+	r = ch341_control_out(dev, CH341_REQ_SERIAL_INIT, 0x501f, 0xd90a);
 	if (r < 0)
 		goto out;
 
@@ -382,7 +395,7 @@ static void ch341_set_termios(struct tty
 static void ch341_break_ctl(struct tty_struct *tty, int break_state)
 {
 	const uint16_t ch341_break_reg =
-		CH341_REG_BREAK1 | ((uint16_t) CH341_REG_BREAK2 << 8);
+			((uint16_t) CH341_REG_LCR << 8) | CH341_REG_BREAK;
 	struct usb_serial_port *port = tty->driver_data;
 	int r;
 	uint16_t reg_contents;
@@ -407,12 +420,12 @@ static void ch341_break_ctl(struct tty_s
 			__func__, break_reg[0], break_reg[1]);
 	if (break_state != 0) {
 		dbg("%s - Enter break state requested", __func__);
-		break_reg[0] &= ~CH341_NBREAK_BITS_REG1;
-		break_reg[1] &= ~CH341_NBREAK_BITS_REG2;
+		break_reg[0] &= ~CH341_NBREAK_BITS;
+		break_reg[1] &= ~CH341_LCR_ENABLE_TX;
 	} else {
 		dbg("%s - Leave break state requested", __func__);
-		break_reg[0] |= CH341_NBREAK_BITS_REG1;
-		break_reg[1] |= CH341_NBREAK_BITS_REG2;
+		break_reg[0] |= CH341_NBREAK_BITS;
+		break_reg[1] |= CH341_LCR_ENABLE_TX;
 	}
 	dbg("%s - New ch341 break register contents - reg1: %x, reg2: %x",
 			__func__, break_reg[0], break_reg[1]);

[toc] | [prev] | [next] | [standalone]


#1597521 — [PATCH 3.2 055/199] net, sched: fix soft lockup in tc_classify

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 055/199] net, sched: fix soft lockup in tc_classify
Message-ID<tjssY-4sG-81@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <daniel@iogearbox.net>

commit 628185cfddf1dfb701c4efe2cfd72cf5b09f5702 upstream.

Shahar reported a soft lockup in tc_classify(), where we run into an
endless loop when walking the classifier chain due to tp->next == tp
which is a state we should never run into. The issue only seems to
trigger under load in the tc control path.

What happens is that in tc_ctl_tfilter(), thread A allocates a new
tp, initializes it, sets tp_created to 1, and calls into tp->ops->change()
with it. In that classifier callback we had to unlock/lock the rtnl
mutex and returned with -EAGAIN. One reason why we need to drop there
is, for example, that we need to request an action module to be loaded.

This happens via tcf_exts_validate() -> tcf_action_init/_1() meaning
after we loaded and found the requested action, we need to redo the
whole request so we don't race against others. While we had to unlock
rtnl in that time, thread B's request was processed next on that CPU.
Thread B added a new tp instance successfully to the classifier chain.
When thread A returned grabbing the rtnl mutex again, propagating -EAGAIN
and destroying its tp instance which never got linked, we goto replay
and redo A's request.

This time when walking the classifier chain in tc_ctl_tfilter() for
checking for existing tp instances we had a priority match and found
the tp instance that was created and linked by thread B. Now calling
again into tp->ops->change() with that tp was successful and returned
without error.

tp_created was never cleared in the second round, thus kernel thinks
that we need to link it into the classifier chain (once again). tp and
*back point to the same object due to the match we had earlier on. Thus
for thread B's already public tp, we reset tp->next to tp itself and
link it into the chain, which eventually causes the mentioned endless
loop in tc_classify() once a packet hits the data path.

Fix is to clear tp_created at the beginning of each request, also when
we replay it. On the paths that can cause -EAGAIN we already destroy
the original tp instance we had and on replay we really need to start
from scratch. It seems that this issue was first introduced in commit
12186be7d2e1 ("net_cls: fix unconfigured struct tcf_proto keeps chaining
and avoid kernel panic when we use cls_cgroup").

Fixes: 12186be7d2e1 ("net_cls: fix unconfigured struct tcf_proto keeps chaining and avoid kernel panic when we use cls_cgroup")
Reported-by: Shahar Klein <shahark@mellanox.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Cc: Cong Wang <xiyou.wangcong@gmail.com>
Acked-by: Eric Dumazet <edumazet@google.com>
Tested-by: Shahar Klein <shahark@mellanox.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 net/sched/cls_api.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/net/sched/cls_api.c
+++ b/net/sched/cls_api.c
@@ -137,9 +137,11 @@ static int tc_ctl_tfilter(struct sk_buff
 	unsigned long cl;
 	unsigned long fh;
 	int err;
-	int tp_created = 0;
+	int tp_created;
 
 replay:
+	tp_created = 0;
+
 	t = NLMSG_DATA(n);
 	protocol = TC_H_MIN(t->tcm_info);
 	prio = TC_H_MAJ(t->tcm_info);

[toc] | [prev] | [next] | [standalone]


#1597522 — [PATCH 3.2 040/199] ext4: reject inodes with negative size

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 040/199] ext4: reject inodes with negative size
Message-ID<tjssY-4sG-83@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: "Darrick J. Wong" <darrick.wong@oracle.com>

commit 7e6e1ef48fc02f3ac5d0edecbb0c6087cd758d58 upstream.

Don't load an inode with a negative size; this causes integer overflow
problems in the VFS.

[ Added EXT4_ERROR_INODE() to mark file system as corrupted. -TYT]

Fixes: a48380f769df (ext4: rename i_dir_acl to i_size_high)
Signed-off-by: Darrick J. Wong <darrick.wong@oracle.com>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
[bwh: Backported to 3.2: use EIO instead of EFSCORRUPTED]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 fs/ext4/inode.c | 6 ++++++
 1 file changed, 6 insertions(+)

--- a/fs/ext4/inode.c
+++ b/fs/ext4/inode.c
@@ -3829,6 +3829,7 @@ struct inode *ext4_iget(struct super_blo
 	struct inode *inode;
 	journal_t *journal = EXT4_SB(sb)->s_journal;
 	long ret;
+	loff_t size;
 	int block;
 
 	inode = iget_locked(sb, ino);
@@ -3880,6 +3881,11 @@ struct inode *ext4_iget(struct super_blo
 		ei->i_file_acl |=
 			((__u64)le16_to_cpu(raw_inode->i_file_acl_high)) << 32;
 	inode->i_size = ext4_isize(raw_inode);
+	if ((size = i_size_read(inode)) < 0) {
+		EXT4_ERROR_INODE(inode, "bad i_size value: %lld", size);
+		ret = -EIO;
+		goto bad_inode;
+	}
 	ei->i_disksize = inode->i_size;
 #ifdef CONFIG_QUOTA
 	ei->i_reserved_quota = 0;

[toc] | [prev] | [next] | [standalone]


#1597523 — [PATCH 3.2 037/199] USB: serial: option: add support for Telit LE922A PIDs 0x1040, 0x1041

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:20 +0100
Subject[PATCH 3.2 037/199] USB: serial: option: add support for Telit LE922A PIDs 0x1040, 0x1041
Message-ID<tjsCB-4wB-3@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Daniele Palmas <dnlplm@gmail.com>

commit 5b09eff0c379002527ad72ea5ea38f25da8a8650 upstream.

This patch adds support for PIDs 0x1040, 0x1041 of Telit LE922A.

Since the interface positions are the same than the ones used
for other Telit compositions, previous defined blacklists are used.

Signed-off-by: Daniele Palmas <dnlplm@gmail.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/option.c | 6 ++++++
 1 file changed, 6 insertions(+)

--- a/drivers/usb/serial/option.c
+++ b/drivers/usb/serial/option.c
@@ -269,6 +269,8 @@ static void option_instat_callback(struc
 #define TELIT_PRODUCT_CC864_SINGLE		0x1006
 #define TELIT_PRODUCT_DE910_DUAL		0x1010
 #define TELIT_PRODUCT_UE910_V2			0x1012
+#define TELIT_PRODUCT_LE922_USBCFG1		0x1040
+#define TELIT_PRODUCT_LE922_USBCFG2		0x1041
 #define TELIT_PRODUCT_LE922_USBCFG0		0x1042
 #define TELIT_PRODUCT_LE922_USBCFG3		0x1043
 #define TELIT_PRODUCT_LE920			0x1200
@@ -1196,6 +1198,10 @@ static const struct usb_device_id option
 	{ USB_DEVICE(TELIT_VENDOR_ID, TELIT_PRODUCT_UE910_V2) },
 	{ USB_DEVICE(TELIT_VENDOR_ID, TELIT_PRODUCT_LE922_USBCFG0),
 		.driver_info = (kernel_ulong_t)&telit_le922_blacklist_usbcfg0 },
+	{ USB_DEVICE(TELIT_VENDOR_ID, TELIT_PRODUCT_LE922_USBCFG1),
+		.driver_info = (kernel_ulong_t)&telit_le910_blacklist },
+	{ USB_DEVICE(TELIT_VENDOR_ID, TELIT_PRODUCT_LE922_USBCFG2),
+		.driver_info = (kernel_ulong_t)&telit_le922_blacklist_usbcfg3 },
 	{ USB_DEVICE(TELIT_VENDOR_ID, TELIT_PRODUCT_LE922_USBCFG3),
 		.driver_info = (kernel_ulong_t)&telit_le922_blacklist_usbcfg3 },
 	{ USB_DEVICE(TELIT_VENDOR_ID, TELIT_PRODUCT_LE910),

[toc] | [prev] | [next] | [standalone]


#1597530 — [PATCH 3.2 044/199] libceph: verify authorize reply on connect

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:20 +0100
Subject[PATCH 3.2 044/199] libceph: verify authorize reply on connect
Message-ID<tjsCB-4wB-13@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Ilya Dryomov <idryomov@gmail.com>

commit 5c056fdc5b474329037f2aa18401bd73033e0ce0 upstream.

After sending an authorizer (ceph_x_authorize_a + ceph_x_authorize_b),
the client gets back a ceph_x_authorize_reply, which it is supposed to
verify to ensure the authenticity and protect against replay attacks.
The code for doing this is there (ceph_x_verify_authorizer_reply(),
ceph_auth_verify_authorizer_reply() + plumbing), but it is never
invoked by the the messenger.

AFAICT this goes back to 2009, when ceph authentication protocols
support was added to the kernel client in 4e7a5dcd1bba ("ceph:
negotiate authentication protocol; implement AUTH_NONE protocol").

The second param of ceph_connection_operations::verify_authorizer_reply
is unused all the way down.  Pass 0 to facilitate backporting, and kill
it in the next commit.

Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
Reviewed-by: Sage Weil <sage@redhat.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 net/ceph/messenger.c | 13 +++++++++++++
 1 file changed, 13 insertions(+)

--- a/net/ceph/messenger.c
+++ b/net/ceph/messenger.c
@@ -1350,6 +1350,19 @@ static int process_connect(struct ceph_c
 
 	dout("process_connect on %p tag %d\n", con, (int)con->in_tag);
 
+	if (con->auth_reply_buf) {
+		/*
+		 * Any connection that defines ->get_authorizer()
+		 * should also define ->verify_authorizer_reply().
+		 * See get_connect_authorizer().
+		 */
+		ret = con->ops->verify_authorizer_reply(con, 0);
+		if (ret < 0) {
+			con->error_msg = "bad authorize reply";
+			return ret;
+		}
+	}
+
 	switch (con->in_reply.tag) {
 	case CEPH_MSGR_TAG_FEATURES:
 		pr_err("%s%lld %s feature set mismatch,"

[toc] | [prev] | [next] | [standalone]


#1597531 — [PATCH 3.2 005/199] usb: gadget: composite: correctly initialize ep->maxpacket

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:20 +0100
Subject[PATCH 3.2 005/199] usb: gadget: composite: correctly initialize ep->maxpacket
Message-ID<tjsCB-4wB-17@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Felipe Balbi <felipe.balbi@linux.intel.com>

commit e8f29bb719b47a234f33b0af62974d7a9521a52c upstream.

usb_endpoint_maxp() returns wMaxPacketSize in its
raw form. Without taking into consideration that it
also contains other bits reserved for isochronous
endpoints.

This patch fixes one occasion where this is a
problem by making sure that we initialize
ep->maxpacket only with lower 10 bits of the value
returned by usb_endpoint_maxp(). Note that seperate
patches will be necessary to audit all call sites of
usb_endpoint_maxp() and make sure that
usb_endpoint_maxp() only returns lower 10 bits of
wMaxPacketSize.

Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/gadget/composite.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/usb/gadget/composite.c
+++ b/drivers/usb/gadget/composite.c
@@ -156,7 +156,7 @@ int config_ep_by_speed(struct usb_gadget
 
 ep_found:
 	/* commit results */
-	_ep->maxpacket = usb_endpoint_maxp(chosen_desc);
+	_ep->maxpacket = usb_endpoint_maxp(chosen_desc) & 0x7ff;
 	_ep->desc = chosen_desc;
 	_ep->comp_desc = NULL;
 	_ep->maxburst = 0;

[toc] | [prev] | [next] | [standalone]


#1597532 — [PATCH 3.2 051/199] scsi: zfcp: fix rport unblock race with LUN recovery

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:20 +0100
Subject[PATCH 3.2 051/199] scsi: zfcp: fix rport unblock race with LUN recovery
Message-ID<tjsCC-4wB-21@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Steffen Maier <maier@linux.vnet.ibm.com>

commit 6f2ce1c6af37191640ee3ff6e8fc39ea10352f4c upstream.

It is unavoidable that zfcp_scsi_queuecommand() has to finish requests
with DID_IMM_RETRY (like fc_remote_port_chkready()) during the time
window when zfcp detected an unavailable rport but
fc_remote_port_delete(), which is asynchronous via
zfcp_scsi_schedule_rport_block(), has not yet blocked the rport.

However, for the case when the rport becomes available again, we should
prevent unblocking the rport too early.  In contrast to other FCP LLDDs,
zfcp has to open each LUN with the FCP channel hardware before it can
send I/O to a LUN.  So if a port already has LUNs attached and we
unblock the rport just after port recovery, recoveries of LUNs behind
this port can still be pending which in turn force
zfcp_scsi_queuecommand() to unnecessarily finish requests with
DID_IMM_RETRY.

This also opens a time window with unblocked rport (until the followup
LUN reopen recovery has finished).  If a scsi_cmnd timeout occurs during
this time window fc_timed_out() cannot work as desired and such command
would indeed time out and trigger scsi_eh. This prevents a clean and
timely path failover.  This should not happen if the path issue can be
recovered on FC transport layer such as path issues involving RSCNs.

Fix this by only calling zfcp_scsi_schedule_rport_register(), to
asynchronously trigger fc_remote_port_add(), after all LUN recoveries as
children of the rport have finished and no new recoveries of equal or
higher order were triggered meanwhile.  Finished intentionally includes
any recovery result no matter if successful or failed (still unblock
rport so other successful LUNs work).  For simplicity, we check after
each finished LUN recovery if there is another LUN recovery pending on
the same port and then do nothing.  We handle the special case of a
successful recovery of a port without LUN children the same way without
changing this case's semantics.

For debugging we introduce 2 new trace records written if the rport
unblock attempt was aborted due to still unfinished or freshly triggered
recovery. The records are only written above the default trace level.

Benjamin noticed the important special case of new recovery that can be
triggered between having given up the erp_lock and before calling
zfcp_erp_action_cleanup() within zfcp_erp_strategy().  We must avoid the
following sequence:

ERP thread                 rport_work      other context
-------------------------  --------------  --------------------------------
port is unblocked, rport still blocked,
 due to pending/running ERP action,
 so ((port->status & ...UNBLOCK) != 0)
 and (port->rport == NULL)
unlock ERP
zfcp_erp_action_cleanup()
case ZFCP_ERP_ACTION_REOPEN_LUN:
zfcp_erp_try_rport_unblock()
((status & ...UNBLOCK) != 0) [OLD!]
                                           zfcp_erp_port_reopen()
                                           lock ERP
                                           zfcp_erp_port_block()
                                           port->status clear ...UNBLOCK
                                           unlock ERP
                                           zfcp_scsi_schedule_rport_block()
                                           port->rport_task = RPORT_DEL
                                           queue_work(rport_work)
                           zfcp_scsi_rport_work()
                           (port->rport_task != RPORT_ADD)
                           port->rport_task = RPORT_NONE
                           zfcp_scsi_rport_block()
                           if (!port->rport) return
zfcp_scsi_schedule_rport_register()
port->rport_task = RPORT_ADD
queue_work(rport_work)
                           zfcp_scsi_rport_work()
                           (port->rport_task == RPORT_ADD)
                           port->rport_task = RPORT_NONE
                           zfcp_scsi_rport_register()
                           (port->rport == NULL)
                           rport = fc_remote_port_add()
                           port->rport = rport;

Now the rport was erroneously unblocked while the zfcp_port is blocked.
This is another situation we want to avoid due to scsi_eh
potential. This state would at least remain until the new recovery from
the other context finished successfully, or potentially forever if it
failed.  In order to close this race, we take the erp_lock inside
zfcp_erp_try_rport_unblock() when checking the status of zfcp_port or
LUN.  With that, the possible corresponding rport state sequences would
be: (unblock[ERP thread],block[other context]) if the ERP thread gets
erp_lock first and still sees ((port->status & ...UNBLOCK) != 0),
(block[other context],NOP[ERP thread]) if the ERP thread gets erp_lock
after the other context has already cleard ...UNBLOCK from port->status.

Since checking fields of struct erp_action is unsafe because they could
have been overwritten (re-used for new recovery) meanwhile, we only
check status of zfcp_port and LUN since these are only changed under
erp_lock elsewhere. Regarding the check of the proper status flags (port
or port_forced are similar to the shown adapter recovery):

[zfcp_erp_adapter_shutdown()]
zfcp_erp_adapter_reopen()
 zfcp_erp_adapter_block()
  * clear UNBLOCK ---------------------------------------+
 zfcp_scsi_schedule_rports_block()                       |
 write_lock_irqsave(&adapter->erp_lock, flags);-------+  |
 zfcp_erp_action_enqueue()                            |  |
  zfcp_erp_setup_act()                                |  |
   * set ERP_INUSE -----------------------------------|--|--+
 write_unlock_irqrestore(&adapter->erp_lock, flags);--+  |  |
.context-switch.                                         |  |
zfcp_erp_thread()                                        |  |
 zfcp_erp_strategy()                                     |  |
  write_lock_irqsave(&adapter->erp_lock, flags);------+  |  |
  ...                                                 |  |  |
  zfcp_erp_strategy_check_target()                    |  |  |
   zfcp_erp_strategy_check_adapter()                  |  |  |
    zfcp_erp_adapter_unblock()                        |  |  |
     * set UNBLOCK -----------------------------------|--+  |
  zfcp_erp_action_dequeue()                           |     |
   * clear ERP_INUSE ---------------------------------|-----+
  ...                                                 |
  write_unlock_irqrestore(&adapter->erp_lock, flags);-+

Hence, we should check for both UNBLOCK and ERP_INUSE because they are
interleaved.  Also we need to explicitly check ERP_FAILED for the link
down case which currently does not clear the UNBLOCK flag in
zfcp_fsf_link_down_info_eval().

Signed-off-by: Steffen Maier <maier@linux.vnet.ibm.com>
Fixes: 8830271c4819 ("[SCSI] zfcp: Dont fail SCSI commands when transitioning to blocked fc_rport")
Fixes: a2fa0aede07c ("[SCSI] zfcp: Block FC transport rports early on errors")
Fixes: 5f852be9e11d ("[SCSI] zfcp: Fix deadlock between zfcp ERP and SCSI")
Fixes: 338151e06608 ("[SCSI] zfcp: make use of fc_remote_port_delete when target port is unavailable")
Fixes: 3859f6a248cb ("[PATCH] zfcp: add rports to enable scsi_add_device to work again")
Reviewed-by: Benjamin Block <bblock@linux.vnet.ibm.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/s390/scsi/zfcp_dbf.c  | 17 +++++++++---
 drivers/s390/scsi/zfcp_erp.c  | 61 +++++++++++++++++++++++++++++++++++++++++--
 drivers/s390/scsi/zfcp_ext.h  |  4 ++-
 drivers/s390/scsi/zfcp_scsi.c |  4 +--
 4 files changed, 77 insertions(+), 9 deletions(-)

--- a/drivers/s390/scsi/zfcp_dbf.c
+++ b/drivers/s390/scsi/zfcp_dbf.c
@@ -282,11 +282,12 @@ void zfcp_dbf_rec_trig(char *tag, struct
 
 
 /**
- * zfcp_dbf_rec_run - trace event related to running recovery
+ * zfcp_dbf_rec_run_lvl - trace event related to running recovery
+ * @level: trace level to be used for event
  * @tag: identifier for event
  * @erp: erp_action running
  */
-void zfcp_dbf_rec_run(char *tag, struct zfcp_erp_action *erp)
+void zfcp_dbf_rec_run_lvl(int level, char *tag, struct zfcp_erp_action *erp)
 {
 	struct zfcp_dbf *dbf = erp->adapter->dbf;
 	struct zfcp_dbf_rec *rec = &dbf->rec_buf;
@@ -312,11 +313,21 @@ void zfcp_dbf_rec_run(char *tag, struct
 	else
 		rec->u.run.rec_count = atomic_read(&erp->adapter->erp_counter);
 
-	debug_event(dbf->rec, 1, rec, sizeof(*rec));
+	debug_event(dbf->rec, level, rec, sizeof(*rec));
 	spin_unlock_irqrestore(&dbf->rec_lock, flags);
 }
 
 /**
+ * zfcp_dbf_rec_run - trace event related to running recovery
+ * @tag: identifier for event
+ * @erp: erp_action running
+ */
+void zfcp_dbf_rec_run(char *tag, struct zfcp_erp_action *erp)
+{
+	zfcp_dbf_rec_run_lvl(1, tag, erp);
+}
+
+/**
  * zfcp_dbf_rec_run_wka - trace wka port event with info like running recovery
  * @tag: identifier for event
  * @wka_port: well known address port
--- a/drivers/s390/scsi/zfcp_erp.c
+++ b/drivers/s390/scsi/zfcp_erp.c
@@ -3,7 +3,7 @@
  *
  * Error Recovery Procedures (ERP).
  *
- * Copyright IBM Corp. 2002, 2015
+ * Copyright IBM Corp. 2002, 2016
  */
 
 #define KMSG_COMPONENT "zfcp"
@@ -1212,6 +1212,62 @@ static void zfcp_erp_action_dequeue(stru
 	}
 }
 
+/**
+ * zfcp_erp_try_rport_unblock - unblock rport if no more/new recovery
+ * @port: zfcp_port whose fc_rport we should try to unblock
+ */
+static void zfcp_erp_try_rport_unblock(struct zfcp_port *port)
+{
+	unsigned long flags;
+	struct zfcp_adapter *adapter = port->adapter;
+	int port_status;
+	struct Scsi_Host *shost = adapter->scsi_host;
+	struct scsi_device *sdev;
+
+	write_lock_irqsave(&adapter->erp_lock, flags);
+	port_status = atomic_read(&port->status);
+	if ((port_status & ZFCP_STATUS_COMMON_UNBLOCKED)    == 0 ||
+	    (port_status & (ZFCP_STATUS_COMMON_ERP_INUSE |
+			    ZFCP_STATUS_COMMON_ERP_FAILED)) != 0) {
+		/* new ERP of severity >= port triggered elsewhere meanwhile or
+		 * local link down (adapter erp_failed but not clear unblock)
+		 */
+		zfcp_dbf_rec_run_lvl(4, "ertru_p", &port->erp_action);
+		write_unlock_irqrestore(&adapter->erp_lock, flags);
+		return;
+	}
+	spin_lock(shost->host_lock);
+	__shost_for_each_device(sdev, shost) {
+		struct zfcp_scsi_dev *zsdev = sdev_to_zfcp(sdev);
+		int lun_status;
+
+		if (zsdev->port != port)
+			continue;
+		/* LUN under port of interest */
+		lun_status = atomic_read(&zsdev->status);
+		if ((lun_status & ZFCP_STATUS_COMMON_ERP_FAILED) != 0)
+			continue; /* unblock rport despite failed LUNs */
+		/* LUN recovery not given up yet [maybe follow-up pending] */
+		if ((lun_status & ZFCP_STATUS_COMMON_UNBLOCKED) == 0 ||
+		    (lun_status & ZFCP_STATUS_COMMON_ERP_INUSE) != 0) {
+			/* LUN blocked:
+			 * not yet unblocked [LUN recovery pending]
+			 * or meanwhile blocked [new LUN recovery triggered]
+			 */
+			zfcp_dbf_rec_run_lvl(4, "ertru_l", &zsdev->erp_action);
+			spin_unlock(shost->host_lock);
+			write_unlock_irqrestore(&adapter->erp_lock, flags);
+			return;
+		}
+	}
+	/* now port has no child or all children have completed recovery,
+	 * and no ERP of severity >= port was meanwhile triggered elsewhere
+	 */
+	zfcp_scsi_schedule_rport_register(port);
+	spin_unlock(shost->host_lock);
+	write_unlock_irqrestore(&adapter->erp_lock, flags);
+}
+
 static void zfcp_erp_action_cleanup(struct zfcp_erp_action *act, int result)
 {
 	struct zfcp_adapter *adapter = act->adapter;
@@ -1222,6 +1278,7 @@ static void zfcp_erp_action_cleanup(stru
 	case ZFCP_ERP_ACTION_REOPEN_LUN:
 		if (!(act->status & ZFCP_STATUS_ERP_NO_REF))
 			scsi_device_put(sdev);
+		zfcp_erp_try_rport_unblock(port);
 		break;
 
 	case ZFCP_ERP_ACTION_REOPEN_PORT:
@@ -1232,7 +1289,7 @@ static void zfcp_erp_action_cleanup(stru
 		 */
 		if (act->step != ZFCP_ERP_STEP_UNINITIALIZED)
 			if (result == ZFCP_ERP_SUCCEEDED)
-				zfcp_scsi_schedule_rport_register(port);
+				zfcp_erp_try_rport_unblock(port);
 		/* fall through */
 	case ZFCP_ERP_ACTION_REOPEN_PORT_FORCED:
 		put_device(&port->dev);
--- a/drivers/s390/scsi/zfcp_ext.h
+++ b/drivers/s390/scsi/zfcp_ext.h
@@ -3,7 +3,7 @@
  *
  * External function declarations.
  *
- * Copyright IBM Corp. 2002, 2015
+ * Copyright IBM Corp. 2002, 2016
  */
 
 #ifndef ZFCP_EXT_H
@@ -49,6 +49,8 @@ extern void zfcp_dbf_adapter_unregister(
 extern void zfcp_dbf_rec_trig(char *, struct zfcp_adapter *,
 			      struct zfcp_port *, struct scsi_device *, u8, u8);
 extern void zfcp_dbf_rec_run(char *, struct zfcp_erp_action *);
+extern void zfcp_dbf_rec_run_lvl(int level, char *tag,
+				 struct zfcp_erp_action *erp);
 extern void zfcp_dbf_rec_run_wka(char *, struct zfcp_fc_wka_port *, u64);
 extern void zfcp_dbf_hba_fsf_uss(char *, struct zfcp_fsf_req *);
 extern void zfcp_dbf_hba_fsf_res(char *, int, struct zfcp_fsf_req *);
--- a/drivers/s390/scsi/zfcp_scsi.c
+++ b/drivers/s390/scsi/zfcp_scsi.c
@@ -109,9 +109,7 @@ int zfcp_scsi_queuecommand(struct Scsi_H
 	}
 
 	if (unlikely(!(status & ZFCP_STATUS_COMMON_UNBLOCKED))) {
-		/* This could be either
-		 * open LUN pending: this is temporary, will result in
-		 *	open LUN or ERP_FAILED, so retry command
+		/* This could be
 		 * call to rport_delete pending: mimic retry from
 		 * 	fc_remote_port_chkready until rport is BLOCKED
 		 */

[toc] | [prev] | [next] | [standalone]


Page 5 of 7 — ← Prev page 1 2 3 4 [5] 6 7  Next page →

Back to top | Article view | linux.kernel


csiph-web