Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1597344 > unrolled thread
| Started by | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| First post | 2017-03-10 13:20 +0100 |
| Last post | 2017-03-12 19:20 +0100 |
| Articles | 9 on this page of 129 — 2 participants |
Back to article view | Back to linux.kernel
[PATCH 3.2 000/199] 3.2.87-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:20 +0100
[PATCH 3.2 191/199] tun: read vnet_hdr_sz once Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:20 +0100
[PATCH 3.2 017/199] ext4: fix stack memory corruption with 64k block size Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
[PATCH 3.2 028/199] thermal: hwmon: Properly report critical temperature in sysfs Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
[PATCH 3.2 188/199] ipv6: pointer math error in ip6_tnl_parse_tlv_enc_lim() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
[PATCH 3.2 186/199] can: Fix kernel panic at security_sock_rcv_skb Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
[PATCH 3.2 009/199] PCI: Check for PME in targeted sleep state Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
[PATCH 3.2 194/199] mld: do not remove mld souce list info when set link down Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
[PATCH 3.2 012/199] powerpc/ibmebus: Fix device reference leaks in sysfs interface Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
[PATCH 3.2 029/199] USB: serial: kl5kusb105: fix open error path Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
[PATCH 3.2 024/199] dm crypt: mark key as invalid until properly loaded Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
[PATCH 3.2 016/199] ext4: fix mballoc breakage with 64k block size Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
[PATCH 3.2 196/199] Revert "KVM: x86: expose MSR_TSC_AUX to userspace" Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
[PATCH 3.2 195/199] igmp, mld: Fix memory leak in igmpv3/mld_del_delrec() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
[PATCH 3.2 015/199] usb: xhci-mem: use passed in GFP flags instead of GFP_KERNEL Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
[PATCH 3.2 025/199] [media] DaVinci-VPFE-Capture: fix error handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
[PATCH 3.2 190/199] tun: Fix TUN_PKT_STRIP setting Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
[PATCH 3.2 019/199] scsi: mvsas: fix command_active typo Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
[PATCH 3.2 014/199] powerpc/pci/rpadlpar: Fix device reference leaks Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
[PATCH 3.2 146/199] net/llc: avoid BUG_ON() in skb_orphan() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
Re: [PATCH 3.2 000/199] 3.2.87-rc1 review Guenter Roeck <linux@roeck-us.net> - 2017-03-10 13:50 +0100
Re: [PATCH 3.2 000/199] 3.2.87-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 021/199] ext4: fix in-superblock mount options processing Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
[PATCH 3.2 137/199] catc: Combine failure cleanup code in catc_probe() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
[PATCH 3.2 004/199] perf scripting: Avoid leaking the scripting_context variable Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
[PATCH 3.2 001/199] staging: iio: ad7606: fix improper setting of oversampling pins Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
[PATCH 3.2 110/199] xhci: fix deadlock at host remove by running watchdog correctly Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
[PATCH 3.2 129/199] can: bcm: fix hrtimer/tasklet termination in bcm op removal Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
[PATCH 3.2 104/199] gro: Disable frag0 optimization on IPv6 ext headers Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
[PATCH 3.2 113/199] svcrpc: don't leak contexts on PROC_DESTROY Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
[PATCH 3.2 086/199] x86/cpu: Fix bootup crashes by sanitizing the argument of the 'clearcpuid=' command-line option Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 136/199] rtl8150: Use heap buffers for all register access Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 126/199] USB: Add quirk for WORLDE easykey.25 MIDI keyboard Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 120/199] powerpc/ptrace: Preserve previous fprs/vsrs on short regset write Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 087/199] usb: musb: Fix trying to free already-free IRQ 4 Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 141/199] ping: fix a null pointer dereference Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 082/199] USB: serial: pl2303: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 134/199] mac80211: Fix adding of mesh vendor IEs Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 132/199] mm, fs: check for fatal signals in do_generic_file_read() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 116/199] can: ti_hecc: add missing prepare and unprepare of the clock Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 145/199] net/sock: Add sock_efree() function Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 047/199] IB/mad: Fix an array index check Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 071/199] USB: serial: iuu_phoenix: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 119/199] nbd: only set MSG_MORE when we have more to send Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 122/199] platform/x86: intel_mid_powerbtn: Set IRQ_ONESHOT Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 083/199] USB: serial: spcp8x5: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 056/199] net: korina: Fix NAPI versus resources freeing Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 139/199] ALSA: seq: Fix race at creating a queue Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 117/199] ceph: fix bad endianness handling in parse_reply_info_extra Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 106/199] sysrq: attach sysrq handler correctly for 32-bit kernel Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 103/199] gro: Enter slow-path if there is no tailroom Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 105/199] ocfs2: fix crash caused by stale lvb with fsdlm plugin Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 125/199] mm/huge_memory.c: respect FOLL_FORCE/FOLL_COW for thp Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 068/199] USB: serial: io_edgeport: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 124/199] USB: serial: option: add device ID for HP lt2523 (Novatel E371) Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 131/199] USB: serial: pl2303: add ATEN device ID Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 123/199] crypto: api - Clear CRYPTO_ALG_DEAD bit before registering an alg Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 127/199] sysctl: fix proc_doulongvec_ms_jiffies_minmax() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 096/199] USB: serial: ch341: fix initial modem-control state Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 092/199] USB: ch341: remove redundant close from open error path Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 115/199] ubifs: Fix journal replay wrt. xattr nodes Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 101/199] USB: serial: ch341: fix baud rate and line-control handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 050/199] scsi: zfcp: do not trace pure benign residual HBA responses at default level Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 088/199] USB: fix problems with duplicate endpoint addresses Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 128/199] parisc: Don't use BITS_PER_LONG in userspace-exported swab.h header Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 108/199] USB: serial: ch341: fix control-message error handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
[PATCH 3.2 076/199] USB: serial: mos7720: fix parport use-after-free on probe errors Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 090/199] ata: sata_mv:- Handle return value of devm_ioremap. Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 080/199] USB: serial: omninet: fix NULL-derefs at open and disconnect Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 061/199] usb: gadgetfs: restrict upper bound on device configuration size Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 067/199] USB: serial: garmin_gps: fix memory leak on failed URB submit Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 085/199] iommu/amd: Fix the left value check of cmd buffer Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 070/199] USB: serial: io_ti: fix another NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 062/199] USB: gadgetfs: fix unbounded memory allocation bug Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 093/199] USB: ch341: set tty baud speed according to tty struct Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 073/199] USB: serial: kobil_sct: fix NULL-deref in write Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 075/199] USB: serial: mos7720: fix use-after-free on probe errors Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 063/199] USB: gadgetfs: fix use-after-free bug Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 048/199] IB/multicast: Check ib_find_pkey() return value Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 074/199] USB: serial: mos7720: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 053/199] target/iscsi: Fix double free in lio_target_tiqn_addtpg() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 049/199] scsi: zfcp: fix use-after-"free" in FC ingress path after TMF Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 079/199] USB: serial: mos7840: fix misleading interrupt-URB comment Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 058/199] net/mlx4: Remove BUG_ON from ICM allocation routine Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 069/199] USB: serial: io_ti: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 097/199] USB: serial: ch341: fix open and resume after B0 Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 064/199] USB: gadgetfs: fix checks of wTotalLength in config descriptors Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 077/199] USB: serial: mos7720: fix parallel probe Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 078/199] USB: serial: mos7840: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 081/199] USB: serial: oti6858: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 066/199] USB: serial: cyberjack: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 098/199] USB: serial: ch341: fix modem-control and B0 handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 089/199] HID: hid-cypress: validate length of report Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 094/199] USB: serial: ch341: add register and USB request definitions Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 055/199] net, sched: fix soft lockup in tc_classify Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 040/199] ext4: reject inodes with negative size Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
[PATCH 3.2 037/199] USB: serial: option: add support for Telit LE922A PIDs 0x1040, 0x1041 Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 044/199] libceph: verify authorize reply on connect Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 005/199] usb: gadget: composite: correctly initialize ep->maxpacket Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 051/199] scsi: zfcp: fix rport unblock race with LUN recovery Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 059/199] usb: gadget: composite: Test get_alt() presence instead of set_alt() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 038/199] hwmon: (ds620) Fix overflows seen when writing temperature limits Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 045/199] fsnotify: Fix possible use-after-free in inode iteration on umount Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 046/199] block_dev: don't test bdev->bd_contains when it is not stable Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 031/199] drivers: base: dma-mapping: Fix typo in dmam_alloc_non_coherent comments Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 065/199] xhci: free xhci virtual devices with leaf nodes first Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 034/199] USB: cdc-acm: add device id for GW Instek AFG-125 Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 036/199] ALSA: usb-audio: Add QuickCam Communicate Deluxe/S7500 to volume_control_quirks Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 022/199] ext4: use more strict checks for inodes_per_block on mount Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 002/199] net/sched: em_meta: Fix 'meta vlan' to correctly recognize zero VID frames Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 041/199] kconfig/nconf: Fix hang when editing symbol with a long prompt Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 032/199] powerpc/ps3: Fix system hang with GCC 5 builds Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 010/199] USB: UHCI: report non-PME wakeup signalling for Intel hardware Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 057/199] net/mlx4_en: Fix bad WQE issue Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 006/199] drm/gma500: Add compat ioctl Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 008/199] xfs: fix up xfs_swap_extent_forks inline extent handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 035/199] hotplug: Make register and unregister notifier API symmetric Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 039/199] nfs_write_end(): fix handling of short copies Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 026/199] regmap: cache: Remove unused 'blksize' variable Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 052/199] scsi: avoid a permanent stop of the scsi device's request queue Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 033/199] Btrfs: fix tree search logic when replaying directory entry deletes Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 030/199] USB: serial: kl5kusb105: abort on open exception path Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 054/199] Input: i8042 - add Pegatron touchpad to noloop table Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 060/199] USB: dummy-hcd: fix bug in stop_activity (handle ep0) Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
[PATCH 3.2 000/202] 3.2.87-rc2 review Ben Hutchings <ben@decadent.org.uk> - 2017-03-11 16:30 +0100
[PATCH 3.2 202/202] tty: n_hdlc: get rid of racy n_hdlc.tbuf Ben Hutchings <ben@decadent.org.uk> - 2017-03-11 16:30 +0100
[PATCH 3.2 201/202] list: introduce list_first_entry_or_null Ben Hutchings <ben@decadent.org.uk> - 2017-03-11 16:30 +0100
[PATCH 3.2 200/202] TTY: n_hdlc, fix lockdep false positive Ben Hutchings <ben@decadent.org.uk> - 2017-03-11 16:30 +0100
Re: [PATCH 3.2 000/202] 3.2.87-rc2 review Guenter Roeck <linux@roeck-us.net> - 2017-03-12 19:20 +0100
Page 7 of 7 — ← Prev page 1 2 3 4 5 6 [7]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-03-10 14:20 +0100 |
| Subject | [PATCH 3.2 033/199] Btrfs: fix tree search logic when replaying directory entry deletes |
| Message-ID | <tjsCE-4wB-77@gated-at.bofh.it> |
| In reply to | #1597344 |
3.2.87-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Robbie Ko <robbieko@synology.com>
commit 2a7bf53f577e49c43de4ffa7776056de26db65d9 upstream.
If a log tree has a layout like the following:
leaf N:
...
item 240 key (282 DIR_LOG_ITEM 0) itemoff 8189 itemsize 8
dir log end 1275809046
leaf N + 1:
item 0 key (282 DIR_LOG_ITEM 3936149215) itemoff 16275 itemsize 8
dir log end 18446744073709551615
...
When we pass the value 1275809046 + 1 as the parameter start_ret to the
function tree-log.c:find_dir_range() (done by replay_dir_deletes()), we
end up with path->slots[0] having the value 239 (points to the last item
of leaf N, item 240). Because the dir log item in that position has an
offset value smaller than *start_ret (1275809046 + 1) we need to move on
to the next leaf, however the logic for that is wrong since it compares
the current slot to the number of items in the leaf, which is smaller
and therefore we don't lookup for the next leaf but instead we set the
slot to point to an item that does not exist, at slot 240, and we later
operate on that slot which has unexpected content or in the worst case
can result in an invalid memory access (accessing beyond the last page
of leaf N's extent buffer).
So fix the logic that checks when we need to lookup at the next leaf
by first incrementing the slot and only after to check if that slot
is beyond the last item of the current leaf.
Signed-off-by: Robbie Ko <robbieko@synology.com>
Reviewed-by: Filipe Manana <fdmanana@suse.com>
Fixes: e02119d5a7b4 (Btrfs: Add a write ahead tree log to optimize synchronous operations)
Signed-off-by: Filipe Manana <fdmanana@suse.com>
[Modified changelog for clarity and correctness]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
fs/btrfs/tree-log.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
--- a/fs/btrfs/tree-log.c
+++ b/fs/btrfs/tree-log.c
@@ -1415,12 +1415,11 @@ static noinline int find_dir_range(struc
next:
/* check the next slot in the tree to see if it is a valid item */
nritems = btrfs_header_nritems(path->nodes[0]);
+ path->slots[0]++;
if (path->slots[0] >= nritems) {
ret = btrfs_next_leaf(root, path);
if (ret)
goto out;
- } else {
- path->slots[0]++;
}
btrfs_item_key_to_cpu(path->nodes[0], &key, path->slots[0]);
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-03-10 14:20 +0100 |
| Subject | [PATCH 3.2 030/199] USB: serial: kl5kusb105: abort on open exception path |
| Message-ID | <tjsCE-4wB-85@gated-at.bofh.it> |
| In reply to | #1597344 |
3.2.87-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Pan Bian <bianpan2016@163.com>
commit 3c3dd1e058cb01e835dcade4b54a6f13ffaeaf7c upstream.
Function klsi_105_open() calls usb_control_msg() (to "enable read") and
checks its return value. When the return value is unexpected, it only
assigns the error code to the return variable retval, but does not
terminate the exception path. This patch fixes the bug by inserting
"goto err_generic_close;" when the call to usb_control_msg() fails.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Pan Bian <bianpan2016@163.com>
[johan: rebase on prerequisite fix and amend commit message]
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/usb/serial/kl5kusb105.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/usb/serial/kl5kusb105.c
+++ b/drivers/usb/serial/kl5kusb105.c
@@ -353,6 +353,7 @@ static int klsi_105_open(struct tty_str
if (rc < 0) {
dev_err(&port->dev, "Enabling read failed (error = %d)\n", rc);
retval = rc;
+ goto err_generic_close;
} else
dbg("%s - enabled reading", __func__);
@@ -379,6 +380,7 @@ err_disable_read:
0, /* index */
NULL, 0,
KLSI_TIMEOUT);
+err_generic_close:
usb_serial_generic_close(port);
err_free_cfg:
kfree(cfg);
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-03-10 14:20 +0100 |
| Subject | [PATCH 3.2 054/199] Input: i8042 - add Pegatron touchpad to noloop table |
| Message-ID | <tjsCE-4wB-79@gated-at.bofh.it> |
| In reply to | #1597344 |
3.2.87-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Marcos Paulo de Souza <marcos.souza.org@gmail.com>
commit 41c567a5d7d1a986763e58c3394782813c3bcb03 upstream.
Avoid AUX loopback in Pegatron C15B touchpad, so input subsystem is able
to recognize a Synaptics touchpad in the AUX port.
Fixes: https://bugzilla.kernel.org/show_bug.cgi?id=93791
(Touchpad is not detected on DNS 0801480 notebook (PEGATRON C15B))
Suggested-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Marcos Paulo de Souza <marcos.souza.org@gmail.com>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/input/serio/i8042-x86ia64io.h | 6 ++++++
1 file changed, 6 insertions(+)
--- a/drivers/input/serio/i8042-x86ia64io.h
+++ b/drivers/input/serio/i8042-x86ia64io.h
@@ -211,6 +211,12 @@ static const struct dmi_system_id __init
DMI_MATCH(DMI_PRODUCT_VERSION, "Rev 1"),
},
},
+ {
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "PEGATRON CORPORATION"),
+ DMI_MATCH(DMI_PRODUCT_NAME, "C15B"),
+ },
+ },
{ }
};
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-03-10 14:20 +0100 |
| Subject | [PATCH 3.2 060/199] USB: dummy-hcd: fix bug in stop_activity (handle ep0) |
| Message-ID | <tjsCE-4wB-87@gated-at.bofh.it> |
| In reply to | #1597344 |
3.2.87-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Alan Stern <stern@rowland.harvard.edu>
commit bcdbeb844773333d2d1c08004f3b3e25921040e5 upstream.
The stop_activity() routine in dummy-hcd is supposed to unlink all
active requests for every endpoint, among other things. But it
doesn't handle ep0. As a result, fuzz testing can generate a WARNING
like the following:
WARNING: CPU: 0 PID: 4410 at drivers/usb/gadget/udc/dummy_hcd.c:672 dummy_free_request+0x153/0x170
Modules linked in:
CPU: 0 PID: 4410 Comm: syz-executor Not tainted 4.9.0-rc7+ #32
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011
ffff88006a64ed10 ffffffff81f96b8a ffffffff41b58ab3 1ffff1000d4c9d35
ffffed000d4c9d2d ffff880065f8ac00 0000000041b58ab3 ffffffff8598b510
ffffffff81f968f8 0000000041b58ab3 ffffffff859410e0 ffffffff813f0590
Call Trace:
[< inline >] __dump_stack lib/dump_stack.c:15
[<ffffffff81f96b8a>] dump_stack+0x292/0x398 lib/dump_stack.c:51
[<ffffffff812b808f>] __warn+0x19f/0x1e0 kernel/panic.c:550
[<ffffffff812b831c>] warn_slowpath_null+0x2c/0x40 kernel/panic.c:585
[<ffffffff830fcb13>] dummy_free_request+0x153/0x170 drivers/usb/gadget/udc/dummy_hcd.c:672
[<ffffffff830ed1b0>] usb_ep_free_request+0xc0/0x420 drivers/usb/gadget/udc/core.c:195
[<ffffffff83225031>] gadgetfs_unbind+0x131/0x190 drivers/usb/gadget/legacy/inode.c:1612
[<ffffffff830ebd8f>] usb_gadget_remove_driver+0x10f/0x2b0 drivers/usb/gadget/udc/core.c:1228
[<ffffffff830ec084>] usb_gadget_unregister_driver+0x154/0x240 drivers/usb/gadget/udc/core.c:1357
This patch fixes the problem by iterating over all the endpoints in
the driver's ep array instead of iterating over the gadget's ep_list,
which explicitly leaves out ep0.
Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
[bwh: Backported to 3.2: adjust filename, context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/usb/gadget/dummy_hcd.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
--- a/drivers/usb/gadget/dummy_hcd.c
+++ b/drivers/usb/gadget/dummy_hcd.c
@@ -261,7 +261,7 @@ static void nuke (struct dummy *dum, str
static void
stop_activity (struct dummy *dum)
{
- struct dummy_ep *ep;
+ int i;
/* prevent any more requests */
dum->address = 0;
@@ -269,8 +269,8 @@ stop_activity (struct dummy *dum)
/* The timer is left running so that outstanding URBs can fail */
/* nuke any pending requests first, so driver i/o is quiesced */
- list_for_each_entry (ep, &dum->gadget.ep_list, ep.ep_list)
- nuke (dum, ep);
+ for (i = 0; i < DUMMY_ENDPOINTS; ++i)
+ nuke(dum, &dum->ep[i]);
/* driver now does any non-usb quiescing necessary */
}
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-03-11 16:30 +0100 |
| Subject | [PATCH 3.2 000/202] 3.2.87-rc2 review |
| Message-ID | <tjR7X-4Eb-1@gated-at.bofh.it> |
| In reply to | #1597344 |
I've added three more patches to the queue for this release, which will be sent as replies to this message. Responses should be made by Wed Mar 15 00:00:00 UTC 2017. Anything received after that time might be too late. Ben. -- Ben Hutchings If you seem to know what you are doing, you'll be given more to do.
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-03-11 16:30 +0100 |
| Subject | [PATCH 3.2 202/202] tty: n_hdlc: get rid of racy n_hdlc.tbuf |
| Message-ID | <tjR7X-4Eb-3@gated-at.bofh.it> |
| In reply to | #1598351 |
3.2.87-rc2 review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Popov <alex.popov@linux.com>
commit 82f2341c94d270421f383641b7cd670e474db56b upstream.
Currently N_HDLC line discipline uses a self-made singly linked list for
data buffers and has n_hdlc.tbuf pointer for buffer retransmitting after
an error.
The commit be10eb7589337e5defbe214dae038a53dd21add8
("tty: n_hdlc add buffer flushing") introduced racy access to n_hdlc.tbuf.
After tx error concurrent flush_tx_queue() and n_hdlc_send_frames() can put
one data buffer to tx_free_buf_list twice. That causes double free in
n_hdlc_release().
Let's use standard kernel linked list and get rid of n_hdlc.tbuf:
in case of tx error put current data buffer after the head of tx_buf_list.
Signed-off-by: Alexander Popov <alex.popov@linux.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/tty/n_hdlc.c | 132 +++++++++++++++++++++++++++------------------------
1 file changed, 69 insertions(+), 63 deletions(-)
--- a/drivers/tty/n_hdlc.c
+++ b/drivers/tty/n_hdlc.c
@@ -115,7 +115,7 @@
#define DEFAULT_TX_BUF_COUNT 3
struct n_hdlc_buf {
- struct n_hdlc_buf *link;
+ struct list_head list_item;
int count;
char buf[1];
};
@@ -123,8 +123,7 @@ struct n_hdlc_buf {
#define N_HDLC_BUF_SIZE (sizeof(struct n_hdlc_buf) + maxframe)
struct n_hdlc_buf_list {
- struct n_hdlc_buf *head;
- struct n_hdlc_buf *tail;
+ struct list_head list;
int count;
spinlock_t spinlock;
};
@@ -137,7 +136,6 @@ struct n_hdlc_buf_list {
* @backup_tty - TTY to use if tty gets closed
* @tbusy - reentrancy flag for tx wakeup code
* @woke_up - FIXME: describe this field
- * @tbuf - currently transmitting tx buffer
* @tx_buf_list - list of pending transmit frame buffers
* @rx_buf_list - list of received frame buffers
* @tx_free_buf_list - list unused transmit frame buffers
@@ -150,7 +148,6 @@ struct n_hdlc {
struct tty_struct *backup_tty;
int tbusy;
int woke_up;
- struct n_hdlc_buf *tbuf;
struct n_hdlc_buf_list tx_buf_list;
struct n_hdlc_buf_list rx_buf_list;
struct n_hdlc_buf_list tx_free_buf_list;
@@ -160,6 +157,8 @@ struct n_hdlc {
/*
* HDLC buffer list manipulation functions
*/
+static void n_hdlc_buf_return(struct n_hdlc_buf_list *buf_list,
+ struct n_hdlc_buf *buf);
static void n_hdlc_buf_put(struct n_hdlc_buf_list *list,
struct n_hdlc_buf *buf);
static struct n_hdlc_buf *n_hdlc_buf_get(struct n_hdlc_buf_list *list);
@@ -209,16 +208,9 @@ static void flush_tx_queue(struct tty_st
{
struct n_hdlc *n_hdlc = tty2n_hdlc(tty);
struct n_hdlc_buf *buf;
- unsigned long flags;
while ((buf = n_hdlc_buf_get(&n_hdlc->tx_buf_list)))
n_hdlc_buf_put(&n_hdlc->tx_free_buf_list, buf);
- spin_lock_irqsave(&n_hdlc->tx_buf_list.spinlock, flags);
- if (n_hdlc->tbuf) {
- n_hdlc_buf_put(&n_hdlc->tx_free_buf_list, n_hdlc->tbuf);
- n_hdlc->tbuf = NULL;
- }
- spin_unlock_irqrestore(&n_hdlc->tx_buf_list.spinlock, flags);
}
static struct tty_ldisc_ops n_hdlc_ldisc = {
@@ -284,7 +276,6 @@ static void n_hdlc_release(struct n_hdlc
} else
break;
}
- kfree(n_hdlc->tbuf);
kfree(n_hdlc);
} /* end of n_hdlc_release() */
@@ -403,13 +394,7 @@ static void n_hdlc_send_frames(struct n_
n_hdlc->woke_up = 0;
spin_unlock_irqrestore(&n_hdlc->tx_buf_list.spinlock, flags);
- /* get current transmit buffer or get new transmit */
- /* buffer from list of pending transmit buffers */
-
- tbuf = n_hdlc->tbuf;
- if (!tbuf)
- tbuf = n_hdlc_buf_get(&n_hdlc->tx_buf_list);
-
+ tbuf = n_hdlc_buf_get(&n_hdlc->tx_buf_list);
while (tbuf) {
if (debuglevel >= DEBUG_LEVEL_INFO)
printk("%s(%d)sending frame %p, count=%d\n",
@@ -421,7 +406,7 @@ static void n_hdlc_send_frames(struct n_
/* rollback was possible and has been done */
if (actual == -ERESTARTSYS) {
- n_hdlc->tbuf = tbuf;
+ n_hdlc_buf_return(&n_hdlc->tx_buf_list, tbuf);
break;
}
/* if transmit error, throw frame away by */
@@ -436,10 +421,7 @@ static void n_hdlc_send_frames(struct n_
/* free current transmit buffer */
n_hdlc_buf_put(&n_hdlc->tx_free_buf_list, tbuf);
-
- /* this tx buffer is done */
- n_hdlc->tbuf = NULL;
-
+
/* wait up sleeping writers */
wake_up_interruptible(&tty->write_wait);
@@ -449,10 +431,12 @@ static void n_hdlc_send_frames(struct n_
if (debuglevel >= DEBUG_LEVEL_INFO)
printk("%s(%d)frame %p pending\n",
__FILE__,__LINE__,tbuf);
-
- /* buffer not accepted by driver */
- /* set this buffer as pending buffer */
- n_hdlc->tbuf = tbuf;
+
+ /*
+ * the buffer was not accepted by driver,
+ * return it back into tx queue
+ */
+ n_hdlc_buf_return(&n_hdlc->tx_buf_list, tbuf);
break;
}
}
@@ -750,7 +734,8 @@ static int n_hdlc_tty_ioctl(struct tty_s
int error = 0;
int count;
unsigned long flags;
-
+ struct n_hdlc_buf *buf = NULL;
+
if (debuglevel >= DEBUG_LEVEL_INFO)
printk("%s(%d)n_hdlc_tty_ioctl() called %d\n",
__FILE__,__LINE__,cmd);
@@ -764,8 +749,10 @@ static int n_hdlc_tty_ioctl(struct tty_s
/* report count of read data available */
/* in next available frame (if any) */
spin_lock_irqsave(&n_hdlc->rx_buf_list.spinlock,flags);
- if (n_hdlc->rx_buf_list.head)
- count = n_hdlc->rx_buf_list.head->count;
+ buf = list_first_entry_or_null(&n_hdlc->rx_buf_list.list,
+ struct n_hdlc_buf, list_item);
+ if (buf)
+ count = buf->count;
else
count = 0;
spin_unlock_irqrestore(&n_hdlc->rx_buf_list.spinlock,flags);
@@ -777,8 +764,10 @@ static int n_hdlc_tty_ioctl(struct tty_s
count = tty_chars_in_buffer(tty);
/* add size of next output frame in queue */
spin_lock_irqsave(&n_hdlc->tx_buf_list.spinlock,flags);
- if (n_hdlc->tx_buf_list.head)
- count += n_hdlc->tx_buf_list.head->count;
+ buf = list_first_entry_or_null(&n_hdlc->tx_buf_list.list,
+ struct n_hdlc_buf, list_item);
+ if (buf)
+ count += buf->count;
spin_unlock_irqrestore(&n_hdlc->tx_buf_list.spinlock,flags);
error = put_user(count, (int __user *)arg);
break;
@@ -826,14 +815,14 @@ static unsigned int n_hdlc_tty_poll(stru
poll_wait(filp, &tty->write_wait, wait);
/* set bits for operations that won't block */
- if (n_hdlc->rx_buf_list.head)
+ if (!list_empty(&n_hdlc->rx_buf_list.list))
mask |= POLLIN | POLLRDNORM; /* readable */
if (test_bit(TTY_OTHER_CLOSED, &tty->flags))
mask |= POLLHUP;
if (tty_hung_up_p(filp))
mask |= POLLHUP;
if (!tty_is_writelocked(tty) &&
- n_hdlc->tx_free_buf_list.head)
+ !list_empty(&n_hdlc->tx_free_buf_list.list))
mask |= POLLOUT | POLLWRNORM; /* writable */
}
return mask;
@@ -859,7 +848,12 @@ static struct n_hdlc *n_hdlc_alloc(void)
spin_lock_init(&n_hdlc->tx_free_buf_list.spinlock);
spin_lock_init(&n_hdlc->rx_buf_list.spinlock);
spin_lock_init(&n_hdlc->tx_buf_list.spinlock);
-
+
+ INIT_LIST_HEAD(&n_hdlc->rx_free_buf_list.list);
+ INIT_LIST_HEAD(&n_hdlc->tx_free_buf_list.list);
+ INIT_LIST_HEAD(&n_hdlc->rx_buf_list.list);
+ INIT_LIST_HEAD(&n_hdlc->tx_buf_list.list);
+
/* allocate free rx buffer list */
for(i=0;i<DEFAULT_RX_BUF_COUNT;i++) {
buf = kmalloc(N_HDLC_BUF_SIZE, GFP_KERNEL);
@@ -887,53 +881,65 @@ static struct n_hdlc *n_hdlc_alloc(void)
} /* end of n_hdlc_alloc() */
/**
+ * n_hdlc_buf_return - put the HDLC buffer after the head of the specified list
+ * @buf_list - pointer to the buffer list
+ * @buf - pointer to the buffer
+ */
+static void n_hdlc_buf_return(struct n_hdlc_buf_list *buf_list,
+ struct n_hdlc_buf *buf)
+{
+ unsigned long flags;
+
+ spin_lock_irqsave(&buf_list->spinlock, flags);
+
+ list_add(&buf->list_item, &buf_list->list);
+ buf_list->count++;
+
+ spin_unlock_irqrestore(&buf_list->spinlock, flags);
+}
+
+/**
* n_hdlc_buf_put - add specified HDLC buffer to tail of specified list
- * @list - pointer to buffer list
+ * @buf_list - pointer to buffer list
* @buf - pointer to buffer
*/
-static void n_hdlc_buf_put(struct n_hdlc_buf_list *list,
+static void n_hdlc_buf_put(struct n_hdlc_buf_list *buf_list,
struct n_hdlc_buf *buf)
{
unsigned long flags;
- spin_lock_irqsave(&list->spinlock,flags);
-
- buf->link=NULL;
- if (list->tail)
- list->tail->link = buf;
- else
- list->head = buf;
- list->tail = buf;
- (list->count)++;
-
- spin_unlock_irqrestore(&list->spinlock,flags);
-
+
+ spin_lock_irqsave(&buf_list->spinlock, flags);
+
+ list_add_tail(&buf->list_item, &buf_list->list);
+ buf_list->count++;
+
+ spin_unlock_irqrestore(&buf_list->spinlock, flags);
} /* end of n_hdlc_buf_put() */
/**
* n_hdlc_buf_get - remove and return an HDLC buffer from list
- * @list - pointer to HDLC buffer list
+ * @buf_list - pointer to HDLC buffer list
*
* Remove and return an HDLC buffer from the head of the specified HDLC buffer
* list.
* Returns a pointer to HDLC buffer if available, otherwise %NULL.
*/
-static struct n_hdlc_buf* n_hdlc_buf_get(struct n_hdlc_buf_list *list)
+static struct n_hdlc_buf *n_hdlc_buf_get(struct n_hdlc_buf_list *buf_list)
{
unsigned long flags;
struct n_hdlc_buf *buf;
- spin_lock_irqsave(&list->spinlock,flags);
-
- buf = list->head;
+
+ spin_lock_irqsave(&buf_list->spinlock, flags);
+
+ buf = list_first_entry_or_null(&buf_list->list,
+ struct n_hdlc_buf, list_item);
if (buf) {
- list->head = buf->link;
- (list->count)--;
+ list_del(&buf->list_item);
+ buf_list->count--;
}
- if (!list->head)
- list->tail = NULL;
-
- spin_unlock_irqrestore(&list->spinlock,flags);
+
+ spin_unlock_irqrestore(&buf_list->spinlock, flags);
return buf;
-
} /* end of n_hdlc_buf_get() */
static char hdlc_banner[] __initdata =
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-03-11 16:30 +0100 |
| Subject | [PATCH 3.2 201/202] list: introduce list_first_entry_or_null |
| Message-ID | <tjR7X-4Eb-13@gated-at.bofh.it> |
| In reply to | #1598351 |
3.2.87-rc2 review patch. If anyone has any objections, please let me know. ------------------ From: Jiri Pirko <jiri@resnulli.us> commit 6d7581e62f8be462440d7b22c6361f7c9fa4902b upstream. non-rcu variant of list_first_or_null_rcu Signed-off-by: Jiri Pirko <jiri@resnulli.us> Signed-off-by: David S. Miller <davem@davemloft.net> Signed-off-by: Ben Hutchings <ben@decadent.org.uk> --- include/linux/list.h | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/include/linux/list.h b/include/linux/list.h index 6a1f8df9144b..b83e5657365a 100644 --- a/include/linux/list.h +++ b/include/linux/list.h @@ -362,6 +362,17 @@ static inline void list_splice_tail_init(struct list_head *list, list_entry((ptr)->next, type, member) /** + * list_first_entry_or_null - get the first element from a list + * @ptr: the list head to take the element from. + * @type: the type of the struct this is embedded in. + * @member: the name of the list_struct within the struct. + * + * Note that if the list is empty, it returns NULL. + */ +#define list_first_entry_or_null(ptr, type, member) \ + (!list_empty(ptr) ? list_first_entry(ptr, type, member) : NULL) + +/** * list_for_each - iterate over a list * @pos: the &struct list_head to use as a loop cursor. * @head: the head for your list.
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-03-11 16:30 +0100 |
| Subject | [PATCH 3.2 200/202] TTY: n_hdlc, fix lockdep false positive |
| Message-ID | <tjR7X-4Eb-17@gated-at.bofh.it> |
| In reply to | #1598351 |
3.2.87-rc2 review patch. If anyone has any objections, please let me know.
------------------
From: Jiri Slaby <jslaby@suse.cz>
commit e9b736d88af1a143530565929390cadf036dc799 upstream.
The class of 4 n_hdls buf locks is the same because a single function
n_hdlc_buf_list_init is used to init all the locks. But since
flush_tx_queue takes n_hdlc->tx_buf_list.spinlock and then calls
n_hdlc_buf_put which takes n_hdlc->tx_free_buf_list.spinlock, lockdep
emits a warning:
=============================================
[ INFO: possible recursive locking detected ]
4.3.0-25.g91e30a7-default #1 Not tainted
---------------------------------------------
a.out/1248 is trying to acquire lock:
(&(&list->spinlock)->rlock){......}, at: [<ffffffffa01fd020>] n_hdlc_buf_put+0x20/0x60 [n_hdlc]
but task is already holding lock:
(&(&list->spinlock)->rlock){......}, at: [<ffffffffa01fdc07>] n_hdlc_tty_ioctl+0x127/0x1d0 [n_hdlc]
other info that might help us debug this:
Possible unsafe locking scenario:
CPU0
----
lock(&(&list->spinlock)->rlock);
lock(&(&list->spinlock)->rlock);
*** DEADLOCK ***
May be due to missing lock nesting notation
2 locks held by a.out/1248:
#0: (&tty->ldisc_sem){++++++}, at: [<ffffffff814c9eb0>] tty_ldisc_ref_wait+0x20/0x50
#1: (&(&list->spinlock)->rlock){......}, at: [<ffffffffa01fdc07>] n_hdlc_tty_ioctl+0x127/0x1d0 [n_hdlc]
...
Call Trace:
...
[<ffffffff81738fd0>] _raw_spin_lock_irqsave+0x50/0x70
[<ffffffffa01fd020>] n_hdlc_buf_put+0x20/0x60 [n_hdlc]
[<ffffffffa01fdc24>] n_hdlc_tty_ioctl+0x144/0x1d0 [n_hdlc]
[<ffffffff814c25c1>] tty_ioctl+0x3f1/0xe40
...
Fix it by initializing the spin_locks separately. This removes also
reduntand memset of a freshly kzallocated space.
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/tty/n_hdlc.c | 19 ++++---------------
1 file changed, 4 insertions(+), 15 deletions(-)
--- a/drivers/tty/n_hdlc.c
+++ b/drivers/tty/n_hdlc.c
@@ -160,7 +160,6 @@ struct n_hdlc {
/*
* HDLC buffer list manipulation functions
*/
-static void n_hdlc_buf_list_init(struct n_hdlc_buf_list *list);
static void n_hdlc_buf_put(struct n_hdlc_buf_list *list,
struct n_hdlc_buf *buf);
static struct n_hdlc_buf *n_hdlc_buf_get(struct n_hdlc_buf_list *list);
@@ -856,10 +855,10 @@ static struct n_hdlc *n_hdlc_alloc(void)
memset(n_hdlc, 0, sizeof(*n_hdlc));
- n_hdlc_buf_list_init(&n_hdlc->rx_free_buf_list);
- n_hdlc_buf_list_init(&n_hdlc->tx_free_buf_list);
- n_hdlc_buf_list_init(&n_hdlc->rx_buf_list);
- n_hdlc_buf_list_init(&n_hdlc->tx_buf_list);
+ spin_lock_init(&n_hdlc->rx_free_buf_list.spinlock);
+ spin_lock_init(&n_hdlc->tx_free_buf_list.spinlock);
+ spin_lock_init(&n_hdlc->rx_buf_list.spinlock);
+ spin_lock_init(&n_hdlc->tx_buf_list.spinlock);
/* allocate free rx buffer list */
for(i=0;i<DEFAULT_RX_BUF_COUNT;i++) {
@@ -888,16 +887,6 @@ static struct n_hdlc *n_hdlc_alloc(void)
} /* end of n_hdlc_alloc() */
/**
- * n_hdlc_buf_list_init - initialize specified HDLC buffer list
- * @list - pointer to buffer list
- */
-static void n_hdlc_buf_list_init(struct n_hdlc_buf_list *list)
-{
- memset(list, 0, sizeof(*list));
- spin_lock_init(&list->spinlock);
-} /* end of n_hdlc_buf_list_init() */
-
-/**
* n_hdlc_buf_put - add specified HDLC buffer to tail of specified list
* @list - pointer to buffer list
* @buf - pointer to buffer
[toc] | [prev] | [next] | [standalone]
| From | Guenter Roeck <linux@roeck-us.net> |
|---|---|
| Date | 2017-03-12 19:20 +0100 |
| Subject | Re: [PATCH 3.2 000/202] 3.2.87-rc2 review |
| Message-ID | <tkgg1-5dS-11@gated-at.bofh.it> |
| In reply to | #1598351 |
On 03/11/2017 07:15 AM, Ben Hutchings wrote: > I've added three more patches to the queue for this release, which > will be sent as replies to this message. > > Responses should be made by Wed Mar 15 00:00:00 UTC 2017. > Anything received after that time might be too late. > Still looks good. Guenter
[toc] | [prev] | [standalone]
Page 7 of 7 — ← Prev page 1 2 3 4 5 6 [7]
Back to top | Article view | linux.kernel
csiph-web