Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1597344 > unrolled thread

[PATCH 3.2 000/199] 3.2.87-rc1 review

Started byBen Hutchings <ben@decadent.org.uk>
First post2017-03-10 13:20 +0100
Last post2017-03-12 19:20 +0100
Articles 20 on this page of 129 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 3.2 000/199] 3.2.87-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:20 +0100
    [PATCH 3.2 191/199] tun: read vnet_hdr_sz once Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:20 +0100
    [PATCH 3.2 017/199] ext4: fix stack memory corruption with 64k  block size Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 028/199] thermal: hwmon: Properly report critical  temperature in sysfs Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 188/199] ipv6: pointer math error in ip6_tnl_parse_tlv_enc_lim() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 186/199] can: Fix kernel panic at security_sock_rcv_skb Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 009/199] PCI: Check for PME in targeted sleep state Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 194/199] mld: do not remove mld souce list info when  set link down Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 012/199] powerpc/ibmebus: Fix device reference leaks  in sysfs interface Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 029/199] USB: serial: kl5kusb105: fix open error path Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 024/199] dm crypt: mark key as invalid until properly  loaded Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:30 +0100
    [PATCH 3.2 016/199] ext4: fix mballoc breakage with 64k block size Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
    [PATCH 3.2 196/199] Revert "KVM: x86: expose MSR_TSC_AUX to  userspace" Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
    [PATCH 3.2 195/199] igmp, mld: Fix memory leak in igmpv3/mld_del_delrec() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
    [PATCH 3.2 015/199] usb: xhci-mem: use passed in GFP flags  instead of GFP_KERNEL Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
    [PATCH 3.2 025/199] [media] DaVinci-VPFE-Capture: fix error handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
    [PATCH 3.2 190/199] tun: Fix TUN_PKT_STRIP setting Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
    [PATCH 3.2 019/199] scsi: mvsas: fix command_active typo Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:40 +0100
    [PATCH 3.2 014/199] powerpc/pci/rpadlpar: Fix device reference leaks Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 146/199] net/llc: avoid BUG_ON() in skb_orphan() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    Re: [PATCH 3.2 000/199] 3.2.87-rc1 review Guenter Roeck <linux@roeck-us.net> - 2017-03-10 13:50 +0100
      Re: [PATCH 3.2 000/199] 3.2.87-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 021/199] ext4: fix in-superblock mount options processing Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 137/199] catc: Combine failure cleanup code in  catc_probe() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 004/199] perf scripting: Avoid leaking the  scripting_context variable Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 001/199] staging: iio: ad7606: fix improper setting of  oversampling pins Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 110/199] xhci: fix deadlock at host remove by running  watchdog correctly Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 129/199] can: bcm: fix hrtimer/tasklet termination in  bcm op removal Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 104/199] gro: Disable frag0 optimization on IPv6 ext  headers Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 113/199] svcrpc: don't leak contexts on PROC_DESTROY Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 13:50 +0100
    [PATCH 3.2 086/199] x86/cpu: Fix bootup crashes by sanitizing the  argument of the 'clearcpuid=' command-line option Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 136/199] rtl8150: Use heap buffers for all register access Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 126/199] USB: Add quirk for WORLDE easykey.25 MIDI  keyboard Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 120/199] powerpc/ptrace: Preserve previous fprs/vsrs  on short regset write Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 087/199] usb: musb: Fix trying to free already-free IRQ 4 Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 141/199] ping: fix a null pointer dereference Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 082/199] USB: serial: pl2303: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 134/199] mac80211: Fix adding of mesh vendor IEs Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 132/199] mm, fs: check for fatal signals in  do_generic_file_read() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 116/199] can: ti_hecc: add missing prepare and  unprepare of the clock Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 145/199] net/sock: Add sock_efree() function Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 047/199] IB/mad: Fix an array index check Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 071/199] USB: serial: iuu_phoenix: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 119/199] nbd: only set MSG_MORE when we have more to send Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 122/199] platform/x86: intel_mid_powerbtn: Set IRQ_ONESHOT Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 083/199] USB: serial: spcp8x5: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 056/199] net: korina: Fix NAPI versus resources freeing Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 139/199] ALSA: seq: Fix race at creating a queue Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 117/199] ceph: fix bad endianness handling in  parse_reply_info_extra Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 106/199] sysrq: attach sysrq handler correctly for  32-bit kernel Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 103/199] gro: Enter slow-path if there is no tailroom Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 105/199] ocfs2: fix crash caused by stale lvb with  fsdlm plugin Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 125/199] mm/huge_memory.c: respect FOLL_FORCE/FOLL_COW  for thp Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 068/199] USB: serial: io_edgeport: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 124/199] USB: serial: option: add device ID for HP  lt2523 (Novatel E371) Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 131/199] USB: serial: pl2303: add ATEN device ID Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 123/199] crypto: api - Clear CRYPTO_ALG_DEAD bit  before registering an alg Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 127/199] sysctl: fix proc_doulongvec_ms_jiffies_minmax() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 096/199] USB: serial: ch341: fix initial modem-control  state Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 092/199] USB: ch341: remove redundant close from open  error path Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 115/199] ubifs: Fix journal replay wrt. xattr nodes Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 101/199] USB: serial: ch341: fix baud rate and  line-control handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 050/199] scsi: zfcp: do not trace pure benign residual  HBA responses at default level Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 088/199] USB: fix problems with duplicate endpoint  addresses Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 128/199] parisc: Don't use BITS_PER_LONG in  userspace-exported swab.h header Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 108/199] USB: serial: ch341: fix control-message error  handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:00 +0100
    [PATCH 3.2 076/199] USB: serial: mos7720: fix parport  use-after-free on probe errors Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 090/199] ata: sata_mv:- Handle return value of  devm_ioremap. Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 080/199] USB: serial: omninet: fix NULL-derefs at open  and disconnect Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 061/199] usb: gadgetfs: restrict upper bound on device  configuration size Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 067/199] USB: serial: garmin_gps: fix memory leak on  failed URB submit Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 085/199] iommu/amd: Fix the left value check of cmd buffer Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 070/199] USB: serial: io_ti: fix another NULL-deref at  open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 062/199] USB: gadgetfs: fix unbounded memory  allocation bug Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 093/199] USB: ch341: set tty baud speed according to  tty struct Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 073/199] USB: serial: kobil_sct: fix NULL-deref in write Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 075/199] USB: serial: mos7720: fix use-after-free on  probe errors Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 063/199] USB: gadgetfs: fix use-after-free bug Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 048/199] IB/multicast: Check ib_find_pkey() return value Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 074/199] USB: serial: mos7720: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 053/199] target/iscsi: Fix double free in  lio_target_tiqn_addtpg() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 049/199] scsi: zfcp: fix use-after-"free" in FC  ingress path after TMF Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 079/199] USB: serial: mos7840: fix misleading  interrupt-URB comment Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 058/199] net/mlx4: Remove BUG_ON from ICM allocation  routine Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 069/199] USB: serial: io_ti: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 097/199] USB: serial: ch341: fix open and resume after B0 Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 064/199] USB: gadgetfs: fix checks of wTotalLength in  config descriptors Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 077/199] USB: serial: mos7720: fix parallel probe Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 078/199] USB: serial: mos7840: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 081/199] USB: serial: oti6858: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 066/199] USB: serial: cyberjack: fix NULL-deref at open Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 098/199] USB: serial: ch341: fix modem-control and B0  handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 089/199] HID: hid-cypress: validate length of report Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 094/199] USB: serial: ch341: add register and USB  request definitions Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 055/199] net, sched: fix soft lockup in tc_classify Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 040/199] ext4: reject inodes with negative size Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:10 +0100
    [PATCH 3.2 037/199] USB: serial: option: add support for Telit  LE922A PIDs 0x1040, 0x1041 Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 044/199] libceph: verify authorize reply on connect Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 005/199] usb: gadget: composite: correctly initialize  ep->maxpacket Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 051/199] scsi: zfcp: fix rport unblock race with LUN  recovery Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 059/199] usb: gadget: composite: Test get_alt()  presence instead of set_alt() Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 038/199] hwmon: (ds620) Fix overflows seen when  writing temperature limits Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 045/199] fsnotify: Fix possible use-after-free in  inode iteration on umount Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 046/199] block_dev: don't test bdev->bd_contains when  it is not stable Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 031/199] drivers: base: dma-mapping: Fix typo in  dmam_alloc_non_coherent comments Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 065/199] xhci: free xhci virtual devices with leaf  nodes first Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 034/199] USB: cdc-acm: add device id for GW Instek AFG-125 Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 036/199] ALSA: usb-audio: Add QuickCam Communicate  Deluxe/S7500 to volume_control_quirks Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 022/199] ext4: use more strict checks for  inodes_per_block on mount Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 002/199] net/sched: em_meta: Fix 'meta vlan' to  correctly recognize zero VID frames Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 041/199] kconfig/nconf: Fix hang when editing symbol  with a long prompt Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 032/199] powerpc/ps3: Fix system hang with GCC 5 builds Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 010/199] USB: UHCI: report non-PME wakeup signalling  for Intel hardware Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 057/199] net/mlx4_en: Fix bad WQE issue Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 006/199] drm/gma500: Add compat ioctl Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 008/199] xfs: fix up xfs_swap_extent_forks inline  extent handling Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 035/199] hotplug: Make register and unregister  notifier API symmetric Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 039/199] nfs_write_end(): fix handling of short copies Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 026/199] regmap: cache: Remove unused 'blksize' variable Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 052/199] scsi: avoid a permanent stop of the scsi  device's request queue Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 033/199] Btrfs: fix tree search logic when replaying  directory entry deletes Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 030/199] USB: serial: kl5kusb105: abort on open  exception path Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 054/199] Input: i8042 - add Pegatron touchpad to  noloop table Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 060/199] USB: dummy-hcd: fix bug in stop_activity  (handle ep0) Ben Hutchings <ben@decadent.org.uk> - 2017-03-10 14:20 +0100
    [PATCH 3.2 000/202] 3.2.87-rc2 review Ben Hutchings <ben@decadent.org.uk> - 2017-03-11 16:30 +0100
      [PATCH 3.2 202/202] tty: n_hdlc: get rid of racy n_hdlc.tbuf Ben Hutchings <ben@decadent.org.uk> - 2017-03-11 16:30 +0100
      [PATCH 3.2 201/202] list: introduce list_first_entry_or_null Ben Hutchings <ben@decadent.org.uk> - 2017-03-11 16:30 +0100
      [PATCH 3.2 200/202] TTY: n_hdlc, fix lockdep false positive Ben Hutchings <ben@decadent.org.uk> - 2017-03-11 16:30 +0100
      Re: [PATCH 3.2 000/202] 3.2.87-rc2 review Guenter Roeck <linux@roeck-us.net> - 2017-03-12 19:20 +0100

Page 4 of 7 — ← Prev page 1 2 3 [4] 5 6 7  Next page →


#1597474 — [PATCH 3.2 115/199] ubifs: Fix journal replay wrt. xattr nodes

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:00 +0100
Subject[PATCH 3.2 115/199] ubifs: Fix journal replay wrt. xattr nodes
Message-ID<tjsji-49K-75@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Richard Weinberger <richard@nod.at>

commit 1cb51a15b576ee325d527726afff40947218fd5e upstream.

When replaying the journal it can happen that a journal entry points to
a garbage collected node.
This is the case when a power-cut occurred between a garbage collect run
and a commit. In such a case nodes have to be read using the failable
read functions to detect whether the found node matches what we expect.

One corner case was forgotten, when the journal contains an entry to
remove an inode all xattrs have to be removed too. UBIFS models xattr
like directory entries, so the TNC code iterates over
all xattrs of the inode and removes them too. This code re-uses the
functions for walking directories and calls ubifs_tnc_next_ent().
ubifs_tnc_next_ent() expects to be used only after the journal and
aborts when a node does not match the expected result. This behavior can
render an UBIFS volume unmountable after a power-cut when xattrs are
used.

Fix this issue by using failable read functions in ubifs_tnc_next_ent()
too when replaying the journal.
Fixes: 1e51764a3c2ac05a ("UBIFS: add new flash file system")
Reported-by: Rock Lee <rockdotlee@gmail.com>
Reviewed-by: David Gstir <david@sigma-star.at>
Signed-off-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 fs/ubifs/tnc.c | 25 +++++++++++++++++++++++--
 1 file changed, 23 insertions(+), 2 deletions(-)

--- a/fs/ubifs/tnc.c
+++ b/fs/ubifs/tnc.c
@@ -34,6 +34,11 @@
 #include <linux/slab.h>
 #include "ubifs.h"
 
+static int try_read_node(const struct ubifs_info *c, void *buf, int type,
+			 int len, int lnum, int offs);
+static int fallible_read_node(struct ubifs_info *c, const union ubifs_key *key,
+			      struct ubifs_zbranch *zbr, void *node);
+
 /*
  * Returned codes of 'matches_name()' and 'fallible_matches_name()' functions.
  * @NAME_LESS: name corresponding to the first argument is less than second
@@ -420,7 +425,19 @@ static int tnc_read_node_nm(struct ubifs
 		return 0;
 	}
 
-	err = ubifs_tnc_read_node(c, zbr, node);
+	if (c->replaying) {
+		err = fallible_read_node(c, &zbr->key, zbr, node);
+		/*
+		 * When the node was not found, return -ENOENT, 0 otherwise.
+		 * Negative return codes stay as-is.
+		 */
+		if (err == 0)
+			err = -ENOENT;
+		else if (err == 1)
+			err = 0;
+	} else {
+		err = ubifs_tnc_read_node(c, zbr, node);
+	}
 	if (err)
 		return err;
 
@@ -2785,7 +2802,11 @@ struct ubifs_dent_node *ubifs_tnc_next_e
 	if (nm->name) {
 		if (err) {
 			/* Handle collisions */
-			err = resolve_collision(c, key, &znode, &n, nm);
+			if (c->replaying)
+				err = fallible_resolve_collision(c, key, &znode, &n,
+							 nm, 0);
+			else
+				err = resolve_collision(c, key, &znode, &n, nm);
 			dbg_tnc("rc returned %d, znode %p, n %d",
 				err, znode, n);
 			if (unlikely(err < 0))

[toc] | [prev] | [next] | [standalone]


#1597476 — [PATCH 3.2 101/199] USB: serial: ch341: fix baud rate and line-control handling

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:00 +0100
Subject[PATCH 3.2 101/199] USB: serial: ch341: fix baud rate and line-control handling
Message-ID<tjsji-49K-79@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 55fa15b5987db22b4f35d3f0798928c126be5f1c upstream.

Revert to using direct register writes to set the divisor and
line-control registers.

A recent change switched to using the init vendor command to update
these registers, something which also enabled support for CH341A
devices. It turns out that simply setting bit 7 in the divisor register
is sufficient to support CH341A and specifically prevent data from being
buffered until a full endpoint-size packet (32 bytes) has been received.

Using the init command also had the side-effect of temporarily
deasserting the DTR/RTS signals on every termios change (including
initialisation on open) something which for example could cause problems
in setups where DTR is used to trigger a reset.

Fixes: 4e46c410e050 ("USB: serial: ch341: reinitialize chip on
reconfiguration")
Signed-off-by: Johan Hovold <johan@kernel.org>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/ch341.c | 24 +++++++++++++++++-------
 1 file changed, 17 insertions(+), 7 deletions(-)

--- a/drivers/usb/serial/ch341.c
+++ b/drivers/usb/serial/ch341.c
@@ -133,8 +133,8 @@ static int ch341_control_in(struct usb_d
 	return r;
 }
 
-static int ch341_init_set_baudrate(struct usb_device *dev,
-				   struct ch341_private *priv, unsigned ctrl)
+static int ch341_set_baudrate_lcr(struct usb_device *dev,
+				  struct ch341_private *priv, u8 lcr)
 {
 	short a;
 	int r;
@@ -159,9 +159,19 @@ static int ch341_init_set_baudrate(struc
 	factor = 0x10000 - factor;
 	a = (factor & 0xff00) | divisor;
 
-	/* 0x9c is "enable SFR_UART Control register and timer" */
-	r = ch341_control_out(dev, CH341_REQ_SERIAL_INIT,
-			      0x9c | (ctrl << 8), a | 0x80);
+	/*
+	 * CH341A buffers data until a full endpoint-size packet (32 bytes)
+	 * has been received unless bit 7 is set.
+	 */
+	a |= BIT(7);
+
+	r = ch341_control_out(dev, CH341_REQ_WRITE_REG, 0x1312, a);
+	if (r)
+		return r;
+
+	r = ch341_control_out(dev, CH341_REQ_WRITE_REG, 0x2518, lcr);
+	if (r)
+		return r;
 
 	return r;
 }
@@ -240,7 +250,7 @@ static int ch341_configure(struct usb_de
 	if (r < 0)
 		goto out;
 
-	r = ch341_init_set_baudrate(dev, priv, 0);
+	r = ch341_set_baudrate_lcr(dev, priv, 0);
 	if (r < 0)
 		goto out;
 
@@ -378,7 +388,7 @@ static void ch341_set_termios(struct tty
 	if (baud_rate) {
 		priv->baud_rate = baud_rate;
 
-		r = ch341_init_set_baudrate(port->serial->dev, priv, ctrl);
+		r = ch341_set_baudrate_lcr(port->serial->dev, priv, ctrl);
 		if (r < 0 && old_termios) {
 			priv->baud_rate = tty_termios_baud_rate(old_termios);
 			tty_termios_copy_hw(tty->termios, old_termios);

[toc] | [prev] | [next] | [standalone]


#1597477 — [PATCH 3.2 050/199] scsi: zfcp: do not trace pure benign residual HBA responses at default level

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:00 +0100
Subject[PATCH 3.2 050/199] scsi: zfcp: do not trace pure benign residual HBA responses at default level
Message-ID<tjsjh-49K-67@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Steffen Maier <maier@linux.vnet.ibm.com>

commit 56d23ed7adf3974f10e91b643bd230e9c65b5f79 upstream.

Since quite a while, Linux issues enough SCSI commands per scsi_device
which successfully return with FCP_RESID_UNDER, FSF_FCP_RSP_AVAILABLE,
and SAM_STAT_GOOD.  This floods the HBA trace area and we cannot see
other and important HBA trace records long enough.

Therefore, do not trace HBA response errors for pure benign residual
under counts at the default trace level.

This excludes benign residual under count combined with other validity
bits set in FCP_RSP_IU, such as FCP_SNS_LEN_VAL.  For all those other
cases, we still do want to see both the HBA record and the corresponding
SCSI record by default.

Signed-off-by: Steffen Maier <maier@linux.vnet.ibm.com>
Fixes: a54ca0f62f95 ("[SCSI] zfcp: Redesign of the debug tracing for HBA records.")
Reviewed-by: Benjamin Block <bblock@linux.vnet.ibm.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/s390/scsi/zfcp_dbf.h | 30 ++++++++++++++++++++++++++++--
 drivers/s390/scsi/zfcp_fsf.h |  3 ++-
 2 files changed, 30 insertions(+), 3 deletions(-)

--- a/drivers/s390/scsi/zfcp_dbf.h
+++ b/drivers/s390/scsi/zfcp_dbf.h
@@ -2,7 +2,7 @@
  * zfcp device driver
  * debug feature declarations
  *
- * Copyright IBM Corp. 2008, 2015
+ * Copyright IBM Corp. 2008, 2016
  */
 
 #ifndef ZFCP_DBF_H
@@ -283,6 +283,30 @@ struct zfcp_dbf {
 	struct zfcp_dbf_scsi		scsi_buf;
 };
 
+/**
+ * zfcp_dbf_hba_fsf_resp_suppress - true if we should not trace by default
+ * @req: request that has been completed
+ *
+ * Returns true if FCP response with only benign residual under count.
+ */
+static inline
+bool zfcp_dbf_hba_fsf_resp_suppress(struct zfcp_fsf_req *req)
+{
+	struct fsf_qtcb *qtcb = req->qtcb;
+	u32 fsf_stat = qtcb->header.fsf_status;
+	struct fcp_resp *fcp_rsp;
+	u8 rsp_flags, fr_status;
+
+	if (qtcb->prefix.qtcb_type != FSF_IO_COMMAND)
+		return false; /* not an FCP response */
+	fcp_rsp = (struct fcp_resp *)&qtcb->bottom.io.fcp_rsp;
+	rsp_flags = fcp_rsp->fr_flags;
+	fr_status = fcp_rsp->fr_status;
+	return (fsf_stat == FSF_FCP_RSP_AVAILABLE) &&
+		(rsp_flags == FCP_RESID_UNDER) &&
+		(fr_status == SAM_STAT_GOOD);
+}
+
 static inline
 void zfcp_dbf_hba_fsf_resp(char *tag, int level, struct zfcp_fsf_req *req)
 {
@@ -304,7 +328,9 @@ void zfcp_dbf_hba_fsf_response(struct zf
 		zfcp_dbf_hba_fsf_resp("fs_perr", 1, req);
 
 	} else if (qtcb->header.fsf_status != FSF_GOOD) {
-		zfcp_dbf_hba_fsf_resp("fs_ferr", 1, req);
+		zfcp_dbf_hba_fsf_resp("fs_ferr",
+				      zfcp_dbf_hba_fsf_resp_suppress(req)
+				      ? 5 : 1, req);
 
 	} else if ((req->fsf_command == FSF_QTCB_OPEN_PORT_WITH_DID) ||
 		   (req->fsf_command == FSF_QTCB_OPEN_LUN)) {
--- a/drivers/s390/scsi/zfcp_fsf.h
+++ b/drivers/s390/scsi/zfcp_fsf.h
@@ -3,7 +3,7 @@
  *
  * Interface to the FSF support functions.
  *
- * Copyright IBM Corp. 2002, 2015
+ * Copyright IBM Corp. 2002, 2016
  */
 
 #ifndef FSF_H
@@ -86,6 +86,7 @@
 #define FSF_APP_TAG_CHECK_FAILURE		0x00000082
 #define FSF_REF_TAG_CHECK_FAILURE		0x00000083
 #define FSF_ADAPTER_STATUS_AVAILABLE		0x000000AD
+#define FSF_FCP_RSP_AVAILABLE			0x000000AF
 #define FSF_UNKNOWN_COMMAND			0x000000E2
 #define FSF_UNKNOWN_OP_SUBTYPE                  0x000000E3
 #define FSF_INVALID_COMMAND_OPTION              0x000000E5

[toc] | [prev] | [next] | [standalone]


#1597478 — [PATCH 3.2 088/199] USB: fix problems with duplicate endpoint addresses

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:00 +0100
Subject[PATCH 3.2 088/199] USB: fix problems with duplicate endpoint addresses
Message-ID<tjsji-49K-71@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Alan Stern <stern@rowland.harvard.edu>

commit 0a8fd1346254974c3a852338508e4a4cddbb35f1 upstream.

When checking a new device's descriptors, the USB core does not check
for duplicate endpoint addresses.  This can cause a problem when the
sysfs files for those endpoints are created; trying to create multiple
files with the same name will provoke a WARNING:

WARNING: CPU: 2 PID: 865 at fs/sysfs/dir.c:31 sysfs_warn_dup+0x8a/0xa0
sysfs: cannot create duplicate filename
'/devices/platform/dummy_hcd.0/usb2/2-1/2-1:64.0/ep_05'
Kernel panic - not syncing: panic_on_warn set ...

CPU: 2 PID: 865 Comm: kworker/2:1 Not tainted 4.9.0-rc7+ #34
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011
Workqueue: usb_hub_wq hub_event
 ffff88006bee64c8 ffffffff81f96b8a ffffffff00000001 1ffff1000d7dcc2c
 ffffed000d7dcc24 0000000000000001 0000000041b58ab3 ffffffff8598b510
 ffffffff81f968f8 ffffffff850fee20 ffffffff85cff020 dffffc0000000000
Call Trace:
 [<     inline     >] __dump_stack lib/dump_stack.c:15
 [<ffffffff81f96b8a>] dump_stack+0x292/0x398 lib/dump_stack.c:51
 [<ffffffff8168c88e>] panic+0x1cb/0x3a9 kernel/panic.c:179
 [<ffffffff812b80b4>] __warn+0x1c4/0x1e0 kernel/panic.c:542
 [<ffffffff812b8195>] warn_slowpath_fmt+0xc5/0x110 kernel/panic.c:565
 [<ffffffff819e70ca>] sysfs_warn_dup+0x8a/0xa0 fs/sysfs/dir.c:30
 [<ffffffff819e7308>] sysfs_create_dir_ns+0x178/0x1d0 fs/sysfs/dir.c:59
 [<     inline     >] create_dir lib/kobject.c:71
 [<ffffffff81fa1b07>] kobject_add_internal+0x227/0xa60 lib/kobject.c:229
 [<     inline     >] kobject_add_varg lib/kobject.c:366
 [<ffffffff81fa2479>] kobject_add+0x139/0x220 lib/kobject.c:411
 [<ffffffff82737a63>] device_add+0x353/0x1660 drivers/base/core.c:1088
 [<ffffffff82738d8d>] device_register+0x1d/0x20 drivers/base/core.c:1206
 [<ffffffff82cb77d3>] usb_create_ep_devs+0x163/0x260 drivers/usb/core/endpoint.c:195
 [<ffffffff82c9f27b>] create_intf_ep_devs+0x13b/0x200 drivers/usb/core/message.c:1030
 [<ffffffff82ca39d3>] usb_set_configuration+0x1083/0x18d0 drivers/usb/core/message.c:1937
 [<ffffffff82cc9e2e>] generic_probe+0x6e/0xe0 drivers/usb/core/generic.c:172
 [<ffffffff82caa7fa>] usb_probe_device+0xaa/0xe0 drivers/usb/core/driver.c:263

This patch prevents the problem by checking for duplicate endpoint
addresses during enumeration and skipping any duplicates.

Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Tested-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/core/config.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

--- a/drivers/usb/core/config.c
+++ b/drivers/usb/core/config.c
@@ -207,6 +207,16 @@ static int usb_parse_endpoint(struct dev
 	if (ifp->desc.bNumEndpoints >= num_ep)
 		goto skip_to_next_endpoint_or_interface_descriptor;
 
+	/* Check for duplicate endpoint addresses */
+	for (i = 0; i < ifp->desc.bNumEndpoints; ++i) {
+		if (ifp->endpoint[i].desc.bEndpointAddress ==
+		    d->bEndpointAddress) {
+			dev_warn(ddev, "config %d interface %d altsetting %d has a duplicate endpoint with address 0x%X, skipping\n",
+			    cfgno, inum, asnum, d->bEndpointAddress);
+			goto skip_to_next_endpoint_or_interface_descriptor;
+		}
+	}
+
 	endpoint = &ifp->endpoint[ifp->desc.bNumEndpoints];
 	++ifp->desc.bNumEndpoints;
 

[toc] | [prev] | [next] | [standalone]


#1597479 — [PATCH 3.2 128/199] parisc: Don't use BITS_PER_LONG in userspace-exported swab.h header

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:00 +0100
Subject[PATCH 3.2 128/199] parisc: Don't use BITS_PER_LONG in userspace-exported swab.h header
Message-ID<tjsji-49K-77@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Helge Deller <deller@gmx.de>

commit 2ad5d52d42810bed95100a3d912679d8864421ec upstream.

In swab.h the "#if BITS_PER_LONG > 32" breaks compiling userspace programs if
BITS_PER_LONG is #defined by userspace with the sizeof() compiler builtin.

Solve this problem by using __BITS_PER_LONG instead.  Since we now
#include asm/bitsperlong.h avoid further potential userspace pollution
by moving the #define of SHIFT_PER_LONG to bitops.h which is not
exported to userspace.

This patch unbreaks compiling qemu on hppa/parisc.

Signed-off-by: Helge Deller <deller@gmx.de>
[bwh: Backported to 3.2: adjust filenames]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 arch/parisc/include/asm/bitops.h      | 8 +++++++-
 arch/parisc/include/asm/bitsperlong.h | 2 --
 arch/parisc/include/asm/swab.h        | 5 +++--
 3 files changed, 10 insertions(+), 5 deletions(-)

--- a/arch/parisc/include/asm/bitops.h
+++ b/arch/parisc/include/asm/bitops.h
@@ -6,7 +6,7 @@
 #endif
 
 #include <linux/compiler.h>
-#include <asm/types.h>		/* for BITS_PER_LONG/SHIFT_PER_LONG */
+#include <asm/types.h>
 #include <asm/byteorder.h>
 #include <linux/atomic.h>
 
@@ -16,6 +16,12 @@
  * to include/asm-i386/bitops.h or kerneldoc
  */
 
+#if __BITS_PER_LONG == 64
+#define SHIFT_PER_LONG 6
+#else
+#define SHIFT_PER_LONG 5
+#endif
+
 #define CHOP_SHIFTCOUNT(x) (((unsigned long) (x)) & (BITS_PER_LONG - 1))
 
 
--- a/arch/parisc/include/asm/bitsperlong.h
+++ b/arch/parisc/include/asm/bitsperlong.h
@@ -9,10 +9,8 @@
  */
 #if (defined(__KERNEL__) && defined(CONFIG_64BIT)) || defined (__LP64__)
 #define __BITS_PER_LONG 64
-#define SHIFT_PER_LONG 6
 #else
 #define __BITS_PER_LONG 32
-#define SHIFT_PER_LONG 5
 #endif
 
 #include <asm-generic/bitsperlong.h>
--- a/arch/parisc/include/asm/swab.h
+++ b/arch/parisc/include/asm/swab.h
@@ -1,6 +1,7 @@
 #ifndef _PARISC_SWAB_H
 #define _PARISC_SWAB_H
 
+#include <asm/bitsperlong.h>
 #include <linux/types.h>
 #include <linux/compiler.h>
 
@@ -38,7 +39,7 @@ static inline __attribute_const__ __u32
 }
 #define __arch_swab32 __arch_swab32
 
-#if BITS_PER_LONG > 32
+#if __BITS_PER_LONG > 32
 /*
 ** From "PA-RISC 2.0 Architecture", HP Professional Books.
 ** See Appendix I page 8 , "Endian Byte Swapping".
@@ -61,6 +62,6 @@ static inline __attribute_const__ __u64
 	return x;
 }
 #define __arch_swab64 __arch_swab64
-#endif /* BITS_PER_LONG > 32 */
+#endif /* __BITS_PER_LONG > 32 */
 
 #endif /* _PARISC_SWAB_H */

[toc] | [prev] | [next] | [standalone]


#1597481 — [PATCH 3.2 108/199] USB: serial: ch341: fix control-message error handling

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:00 +0100
Subject[PATCH 3.2 108/199] USB: serial: ch341: fix control-message error handling
Message-ID<tjsji-49K-83@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 2d5a9c72d0c4ac73cf97f4b7814ed6c44b1e49ae upstream.

A short control transfer would currently fail to be detected, something
which could lead to stale buffer data being used as valid input.

Check for short transfers, and make sure to log any transfer errors.

Note that this also avoids leaking heap data to user space (TIOCMGET)
and the remote device (break control).

Fixes: 6ce76104781a ("USB: Driver for CH341 USB-serial adaptor")
Signed-off-by: Johan Hovold <johan@kernel.org>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/ch341.c | 32 +++++++++++++++++++++-----------
 1 file changed, 21 insertions(+), 11 deletions(-)

--- a/drivers/usb/serial/ch341.c
+++ b/drivers/usb/serial/ch341.c
@@ -115,6 +115,8 @@ static int ch341_control_out(struct usb_
 	r = usb_control_msg(dev, usb_sndctrlpipe(dev, 0), request,
 			    USB_TYPE_VENDOR | USB_RECIP_DEVICE | USB_DIR_OUT,
 			    value, index, NULL, 0, DEFAULT_TIMEOUT);
+	if (r < 0)
+		dev_err(&dev->dev, "failed to send control message: %d\n", r);
 
 	return r;
 }
@@ -130,7 +132,20 @@ static int ch341_control_in(struct usb_d
 	r = usb_control_msg(dev, usb_rcvctrlpipe(dev, 0), request,
 			    USB_TYPE_VENDOR | USB_RECIP_DEVICE | USB_DIR_IN,
 			    value, index, buf, bufsize, DEFAULT_TIMEOUT);
-	return r;
+	if (r < bufsize) {
+		if (r >= 0) {
+			dev_err(&dev->dev,
+				"short control message received (%d < %u)\n",
+				r, bufsize);
+			r = -EIO;
+		}
+
+		dev_err(&dev->dev, "failed to receive control message: %d\n",
+			r);
+		return r;
+	}
+
+	return 0;
 }
 
 static int ch341_set_baudrate_lcr(struct usb_device *dev,
@@ -184,9 +199,9 @@ static int ch341_set_handshake(struct us
 
 static int ch341_get_status(struct usb_device *dev, struct ch341_private *priv)
 {
+	const unsigned int size = 2;
 	char *buffer;
 	int r;
-	const unsigned size = 8;
 	unsigned long flags;
 
 	dbg("ch341_get_status()");
@@ -199,15 +214,10 @@ static int ch341_get_status(struct usb_d
 	if (r < 0)
 		goto out;
 
-	/* setup the private status if available */
-	if (r == 2) {
-		r = 0;
-		spin_lock_irqsave(&priv->lock, flags);
-		priv->line_status = (~(*buffer)) & CH341_BITS_MODEM_STAT;
-		priv->multi_status_change = 0;
-		spin_unlock_irqrestore(&priv->lock, flags);
-	} else
-		r = -EPROTO;
+	spin_lock_irqsave(&priv->lock, flags);
+	priv->line_status = (~(*buffer)) & CH341_BITS_MODEM_STAT;
+	priv->multi_status_change = 0;
+	spin_unlock_irqrestore(&priv->lock, flags);
 
 out:	kfree(buffer);
 	return r;
@@ -217,9 +227,9 @@ out:	kfree(buffer);
 
 static int ch341_configure(struct usb_device *dev, struct ch341_private *priv)
 {
+	const unsigned int size = 2;
 	char *buffer;
 	int r;
-	const unsigned size = 8;
 
 	dbg("ch341_configure()");
 

[toc] | [prev] | [next] | [standalone]


#1597485 — [PATCH 3.2 076/199] USB: serial: mos7720: fix parport use-after-free on probe errors

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 076/199] USB: serial: mos7720: fix parport use-after-free on probe errors
Message-ID<tjssV-4sG-11@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 75dd211e773afcbc264677b0749d1cf7d937ab2d upstream.

Do not submit the interrupt URB until after the parport has been
successfully registered to avoid another use-after-free in the
completion handler when accessing the freed parport private data in case
of a racing completion.

Fixes: b69578df7e98 ("USB: usbserial: mos7720: add support for parallel
port on moschip 7715")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/mos7720.c | 18 ++++++++----------
 1 file changed, 8 insertions(+), 10 deletions(-)

--- a/drivers/usb/serial/mos7720.c
+++ b/drivers/usb/serial/mos7720.c
@@ -2137,22 +2137,20 @@ static int mos7720_startup(struct usb_se
 	usb_control_msg(serial->dev, usb_sndctrlpipe(serial->dev, 0),
 			(__u8)0x03, 0x00, 0x01, 0x00, NULL, 0x00, 5000);
 
-	/* start the interrupt urb */
-	ret_val = usb_submit_urb(serial->port[0]->interrupt_in_urb, GFP_KERNEL);
-	if (ret_val)
-		dev_err(&dev->dev,
-			"%s - Error %d submitting control urb\n",
-			__func__, ret_val);
-
 #ifdef CONFIG_USB_SERIAL_MOS7715_PARPORT
 	if (product == MOSCHIP_DEVICE_ID_7715) {
 		ret_val = mos7715_parport_init(serial);
-		if (ret_val < 0) {
-			usb_kill_urb(serial->port[0]->interrupt_in_urb);
+		if (ret_val < 0)
 			return ret_val;
-		}
 	}
 #endif
+	/* start the interrupt urb */
+	ret_val = usb_submit_urb(serial->port[0]->interrupt_in_urb, GFP_KERNEL);
+	if (ret_val) {
+		dev_err(&dev->dev, "failed to submit interrupt urb: %d\n",
+			ret_val);
+	}
+
 	/* LSR For Port 1 */
 	read_mos_reg(serial, 0, LSR, &data);
 	dbg("LSR:%x", data);

[toc] | [prev] | [next] | [standalone]


#1597486 — [PATCH 3.2 090/199] ata: sata_mv:- Handle return value of devm_ioremap.

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 090/199] ata: sata_mv:- Handle return value of devm_ioremap.
Message-ID<tjssV-4sG-7@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Arvind Yadav <arvind.yadav.cs@gmail.com>

commit 064c3db9c564cc5be514ac21fb4aa26cc33db746 upstream.

Here, If devm_ioremap will fail. It will return NULL.
Then hpriv->base = NULL - 0x20000; Kernel can run into
a NULL-pointer dereference. This error check will avoid
NULL pointer dereference.

Signed-off-by: Arvind Yadav <arvind.yadav.cs@gmail.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/ata/sata_mv.c | 3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/ata/sata_mv.c
+++ b/drivers/ata/sata_mv.c
@@ -4059,6 +4059,9 @@ static int mv_platform_probe(struct plat
 	host->iomap = NULL;
 	hpriv->base = devm_ioremap(&pdev->dev, res->start,
 				   resource_size(res));
+	if (!hpriv->base)
+		return -ENOMEM;
+
 	hpriv->base -= SATAHC0_REG_BASE;
 
 #if defined(CONFIG_HAVE_CLK)

[toc] | [prev] | [next] | [standalone]


#1597488 — [PATCH 3.2 080/199] USB: serial: omninet: fix NULL-derefs at open and disconnect

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 080/199] USB: serial: omninet: fix NULL-derefs at open and disconnect
Message-ID<tjssW-4sG-13@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit a5bc01949e3b19d8a23b5eabc6fc71bb50dc820e upstream.

Fix NULL-pointer dereferences at open() and disconnect() should the
device lack the expected bulk-out endpoints:

Unable to handle kernel NULL pointer dereference at virtual address 000000b4
...
[c0170ff0>] (__lock_acquire) from [<c0172f00>] (lock_acquire+0x108/0x264)
[<c0172f00>] (lock_acquire) from [<c06a5090>] (_raw_spin_lock_irqsave+0x58/0x6c)
[<c06a5090>] (_raw_spin_lock_irqsave) from [<c0470684>] (tty_port_tty_set+0x28/0xa4)
[<c0470684>] (tty_port_tty_set) from [<bf08d384>] (omninet_open+0x30/0x40 [omninet])
[<bf08d384>] (omninet_open [omninet]) from [<bf07c118>] (serial_port_activate+0x68/0x98 [usbserial])

Unable to handle kernel NULL pointer dereference at virtual address 00000234
...
[<bf01f418>] (omninet_disconnect [omninet]) from [<bf0016c0>] (usb_serial_disconnect+0xe4/0x100 [usbserial])

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
[bwh: Backported to 3.2: add this check to the existing
 usb_serial_driver::attach implementation]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/drivers/usb/serial/omninet.c
+++ b/drivers/usb/serial/omninet.c
@@ -152,6 +152,12 @@ static int omninet_attach(struct usb_ser
 	struct omninet_data *od;
 	struct usb_serial_port *port = serial->port[0];
 
+	/* The second bulk-out endpoint is used for writing. */
+	if (serial->num_bulk_out < 2) {
+		dev_err(&serial->interface->dev, "missing endpoints\n");
+		return -ENODEV;
+	}
+
 	od = kmalloc(sizeof(struct omninet_data), GFP_KERNEL);
 	if (!od) {
 		dev_err(&port->dev, "%s- kmalloc(%Zd) failed.\n",

[toc] | [prev] | [next] | [standalone]


#1597490 — [PATCH 3.2 061/199] usb: gadgetfs: restrict upper bound on device configuration size

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 061/199] usb: gadgetfs: restrict upper bound on device configuration size
Message-ID<tjssW-4sG-17@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

commit 0994b0a257557e18ee8f0b7c5f0f73fe2b54eec1 upstream.

Andrey Konovalov reported that we were not properly checking the upper
limit before of a device configuration size before calling
memdup_user(), which could cause some problems.

So set the upper limit to PAGE_SIZE * 4, which should be good enough for
all devices.

Reported-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
[bwh: Backported to 3.2: adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/gadget/inode.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/usb/gadget/inode.c
+++ b/drivers/usb/gadget/inode.c
@@ -1861,7 +1861,8 @@ dev_config (struct file *fd, const char
 	u32			tag;
 	char			*kbuf;
 
-	if (len < (USB_DT_CONFIG_SIZE + USB_DT_DEVICE_SIZE + 4))
+	if ((len < (USB_DT_CONFIG_SIZE + USB_DT_DEVICE_SIZE + 4)) ||
+	    (len > PAGE_SIZE * 4))
 		return -EINVAL;
 
 	/* we might need to change message format someday */

[toc] | [prev] | [next] | [standalone]


#1597491 — [PATCH 3.2 067/199] USB: serial: garmin_gps: fix memory leak on failed URB submit

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 067/199] USB: serial: garmin_gps: fix memory leak on failed URB submit
Message-ID<tjssW-4sG-21@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit c4ac4496e835b78a45dfbf74f6173932217e4116 upstream.

Make sure to free the URB transfer buffer in case submission fails (e.g.
due to a disconnect).

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/garmin_gps.c | 1 +
 1 file changed, 1 insertion(+)

--- a/drivers/usb/serial/garmin_gps.c
+++ b/drivers/usb/serial/garmin_gps.c
@@ -1075,6 +1075,7 @@ static int garmin_write_bulk(struct usb_
 		   "%s - usb_submit_urb(write bulk) failed with status = %d\n",
 				__func__, status);
 		count = status;
+		kfree(buffer);
 	}
 
 	/* we are done with this urb, so let the host driver

[toc] | [prev] | [next] | [standalone]


#1597492 — [PATCH 3.2 085/199] iommu/amd: Fix the left value check of cmd buffer

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 085/199] iommu/amd: Fix the left value check of cmd buffer
Message-ID<tjssW-4sG-23@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Huang Rui <ray.huang@amd.com>

commit 432abf68a79332282329286d190e21fe3ac02a31 upstream.

The generic command buffer entry is 128 bits (16 bytes), so the offset
of tail and head pointer should be 16 bytes aligned and increased with
0x10 per command.

When cmd buf is full, head = (tail + 0x10) % CMD_BUFFER_SIZE.

So when left space of cmd buf should be able to store only two
command, we should be issued one COMPLETE_WAIT additionally to wait
all older commands completed. Then the left space should be increased
after IOMMU fetching from cmd buf.

So left check value should be left <= 0x20 (two commands).

Signed-off-by: Huang Rui <ray.huang@amd.com>
Fixes: ac0ea6e92b222 ('x86/amd-iommu: Improve handling of full command buffer')
Signed-off-by: Joerg Roedel <jroedel@suse.de>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/iommu/amd_iommu.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/iommu/amd_iommu.c
+++ b/drivers/iommu/amd_iommu.c
@@ -641,7 +641,7 @@ again:
 	next_tail = (tail + sizeof(*cmd)) % iommu->cmd_buf_size;
 	left      = (head - next_tail) % iommu->cmd_buf_size;
 
-	if (left <= 2) {
+	if (left <= 0x20) {
 		struct iommu_cmd sync_cmd;
 		volatile u64 sem = 0;
 		int ret;

[toc] | [prev] | [next] | [standalone]


#1597493 — [PATCH 3.2 070/199] USB: serial: io_ti: fix another NULL-deref at open

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 070/199] USB: serial: io_ti: fix another NULL-deref at open
Message-ID<tjssW-4sG-25@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 4f9785cc99feeb3673993b471f646b4dbaec2cc1 upstream.

In case a device is left in "boot-mode" we must not register any port
devices in order to avoid a NULL-pointer dereference on open due to
missing endpoints. This could be used by a malicious device to trigger
an OOPS:

Unable to handle kernel NULL pointer dereference at virtual address 00000030
...
[<bf0caa84>] (edge_open [io_ti]) from [<bf0b0118>] (serial_port_activate+0x68/0x98 [usbserial])
[<bf0b0118>] (serial_port_activate [usbserial]) from [<c0470ca4>] (tty_port_open+0x9c/0xe8)
[<c0470ca4>] (tty_port_open) from [<bf0b0da0>] (serial_open+0x48/0x6c [usbserial])
[<bf0b0da0>] (serial_open [usbserial]) from [<c0469178>] (tty_open+0xcc/0x5cc)

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
[bwh: Backported to 3.2:
 - No heartbeat_work to initialise earlier
 - No separate port_probe and port_remove operations, so add check for null
   port pointers in edge_release()
 - Adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/io_ti.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

--- a/drivers/usb/serial/io_ti.c
+++ b/drivers/usb/serial/io_ti.c
@@ -1500,7 +1500,7 @@ stayinbootmode:
 	dbg("%s - STAYING IN BOOT MODE", __func__);
 	serial->product_info.TiMode = TI_MODE_BOOT;
 
-	return 0;
+	return 1;
 }
 
 
@@ -2660,11 +2660,14 @@ static int edge_startup(struct usb_seria
 	usb_set_serial_data(serial, edge_serial);
 
 	status = download_fw(edge_serial);
-	if (status) {
+	if (status < 0) {
 		kfree(edge_serial);
 		return status;
 	}
 
+	if (status > 0)
+		return 1;	/* bind but do not register any ports */
+
 	/* set up our port private structures */
 	for (i = 0; i < serial->num_ports; ++i) {
 		edge_port = kzalloc(sizeof(struct edgeport_port), GFP_KERNEL);
@@ -2715,6 +2718,8 @@ static void edge_release(struct usb_seri
 
 	for (i = 0; i < serial->num_ports; ++i) {
 		edge_port = usb_get_serial_port_data(serial->port[i]);
+		if (!edge_port)
+			continue;
 		kfifo_free(&edge_port->write_fifo);
 		kfree(edge_port);
 	}

[toc] | [prev] | [next] | [standalone]


#1597495 — [PATCH 3.2 062/199] USB: gadgetfs: fix unbounded memory allocation bug

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 062/199] USB: gadgetfs: fix unbounded memory allocation bug
Message-ID<tjssW-4sG-29@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Alan Stern <stern@rowland.harvard.edu>

commit faab50984fe6636e616c7cc3d30308ba391d36fd upstream.

Andrey Konovalov reports that fuzz testing with syzkaller causes a
KASAN warning in gadgetfs:

BUG: KASAN: slab-out-of-bounds in dev_config+0x86f/0x1190 at addr ffff88003c47e160
Write of size 65537 by task syz-executor0/6356
CPU: 3 PID: 6356 Comm: syz-executor0 Not tainted 4.9.0-rc7+ #19
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011
 ffff88003c107ad8 ffffffff81f96aba ffffffff3dc11ef0 1ffff10007820eee
 ffffed0007820ee6 ffff88003dc11f00 0000000041b58ab3 ffffffff8598b4c8
 ffffffff81f96828 ffffffff813fb4a0 ffff88003b6eadc0 ffff88003c107738
Call Trace:
 [<     inline     >] __dump_stack lib/dump_stack.c:15
 [<ffffffff81f96aba>] dump_stack+0x292/0x398 lib/dump_stack.c:51
 [<ffffffff817e4dec>] kasan_object_err+0x1c/0x70 mm/kasan/report.c:159
 [<     inline     >] print_address_description mm/kasan/report.c:197
 [<ffffffff817e5080>] kasan_report_error+0x1f0/0x4e0 mm/kasan/report.c:286
 [<ffffffff817e5705>] kasan_report+0x35/0x40 mm/kasan/report.c:306
 [<     inline     >] check_memory_region_inline mm/kasan/kasan.c:308
 [<ffffffff817e3fb9>] check_memory_region+0x139/0x190 mm/kasan/kasan.c:315
 [<ffffffff817e4044>] kasan_check_write+0x14/0x20 mm/kasan/kasan.c:326
 [<     inline     >] copy_from_user arch/x86/include/asm/uaccess.h:689
 [<     inline     >] ep0_write drivers/usb/gadget/legacy/inode.c:1135
 [<ffffffff83228caf>] dev_config+0x86f/0x1190 drivers/usb/gadget/legacy/inode.c:1759
 [<ffffffff817fdd55>] __vfs_write+0x5d5/0x760 fs/read_write.c:510
 [<ffffffff817ff650>] vfs_write+0x170/0x4e0 fs/read_write.c:560
 [<     inline     >] SYSC_write fs/read_write.c:607
 [<ffffffff81803a5b>] SyS_write+0xfb/0x230 fs/read_write.c:599
 [<ffffffff84f47ec1>] entry_SYSCALL_64_fastpath+0x1f/0xc2

Indeed, there is a comment saying that the value of len is restricted
to a 16-bit integer, but the code doesn't actually do this.

This patch fixes the warning.  It replaces the comment with a
computation that forces the amount of data copied from the user in
ep0_write() to be no larger than the wLength size for the control
transfer, which is a 16-bit quantity.

Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Tested-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
[bwh: Backported to 3.2 adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/gadget/inode.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/usb/gadget/inode.c
+++ b/drivers/usb/gadget/inode.c
@@ -1196,7 +1196,7 @@ ep0_write (struct file *fd, const char _
 	/* data and/or status stage for control request */
 	} else if (dev->state == STATE_DEV_SETUP) {
 
-		/* IN DATA+STATUS caller makes len <= wLength */
+		len = min_t(size_t, len, dev->setup_wLength);
 		if (dev->setup_in) {
 			retval = setup_req (dev->gadget->ep0, dev->req, len);
 			if (retval == 0) {

[toc] | [prev] | [next] | [standalone]


#1597496 — [PATCH 3.2 093/199] USB: ch341: set tty baud speed according to tty struct

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 093/199] USB: ch341: set tty baud speed according to tty struct
Message-ID<tjssW-4sG-31@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Nicolas PLANEL <nicolas.planel@enovance.com>

commit aa91def41a7bb1fd65492934ce6bea19202b6080 upstream.

The ch341_set_baudrate() function initialize the device baud speed
according to the value on priv->baud_rate. By default the ch341_open() set
it to a hardcoded value (DEFAULT_BAUD_RATE 9600). Unfortunately, the
tty_struct is not initialized with the same default value. (usually 56700)

This means that the tty_struct and the device baud rate generator are not
synchronized after opening the port.

Fixup is done by calling ch341_set_termios() if tty exist.
Remove unnecessary variable priv->baud_rate setup as it's already done by
ch341_port_probe().
Remove unnecessary call to ch341_set_{handshake,baudrate}() in
ch341_open() as there already called in ch341_configure() and
ch341_set_termios()

Signed-off-by: Nicolas PLANEL <nicolas.planel@enovance.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/ch341.c | 15 ++++++---------
 1 file changed, 6 insertions(+), 9 deletions(-)

--- a/drivers/usb/serial/ch341.c
+++ b/drivers/usb/serial/ch341.c
@@ -88,6 +88,10 @@ struct ch341_private {
 	u8 multi_status_change; /* status changed multiple since last call */
 };
 
+static void ch341_set_termios(struct tty_struct *tty,
+			      struct usb_serial_port *port,
+			      struct ktermios *old_termios);
+
 static int ch341_control_out(struct usb_device *dev, u8 request,
 			     u16 value, u16 index)
 {
@@ -318,19 +322,12 @@ static int ch341_open(struct tty_struct
 
 	dbg("ch341_open()");
 
-	priv->baud_rate = DEFAULT_BAUD_RATE;
-
 	r = ch341_configure(serial->dev, priv);
 	if (r)
 		goto out;
 
-	r = ch341_set_handshake(serial->dev, priv->line_control);
-	if (r)
-		goto out;
-
-	r = ch341_set_baudrate(serial->dev, priv);
-	if (r)
-		goto out;
+	if (tty)
+		ch341_set_termios(tty, port, NULL);
 
 	dbg("%s - submitting interrupt urb", __func__);
 	port->interrupt_in_urb->dev = serial->dev;

[toc] | [prev] | [next] | [standalone]


#1597498 — [PATCH 3.2 073/199] USB: serial: kobil_sct: fix NULL-deref in write

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 073/199] USB: serial: kobil_sct: fix NULL-deref in write
Message-ID<tjssX-4sG-37@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 21ce57840243c7b70fbc1ebd3dceeb70bb6e9e09 upstream.

Fix NULL-pointer dereference in write() should the device lack the
expected interrupt-out endpoint:

Unable to handle kernel NULL pointer dereference at virtual address 00000054
...
PC is at kobil_write+0x144/0x2a0 [kobil_sct]

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
[bwh: Backported to 3.2: add this check to the existing
 usb_serial_driver::attach implementation]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/drivers/usb/serial/kobil_sct.c
+++ b/drivers/usb/serial/kobil_sct.c
@@ -150,6 +150,11 @@ static int kobil_startup(struct usb_seri
 	struct usb_host_interface *altsetting;
 	struct usb_host_endpoint *endpoint;
 
+	if (serial->num_interrupt_out < serial->num_ports) {
+		dev_err(&serial->interface->dev, "missing interrupt-out endpoint\n");
+		return -ENODEV;
+	}
+
 	priv = kmalloc(sizeof(struct kobil_private), GFP_KERNEL);
 	if (!priv)
 		return -ENOMEM;

[toc] | [prev] | [next] | [standalone]


#1597501 — [PATCH 3.2 075/199] USB: serial: mos7720: fix use-after-free on probe errors

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 075/199] USB: serial: mos7720: fix use-after-free on probe errors
Message-ID<tjssX-4sG-41@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 91a1ff4d53c5184d383d0baeeaeab6f9736f2ff3 upstream.

The interrupt URB was submitted on probe but never stopped on probe
errors. This can lead to use-after-free issues in the completion
handler when accessing the freed usb-serial struct:

Unable to handle kernel paging request at virtual address 6b6b6be7
...
[<bf052e70>] (mos7715_interrupt_callback [mos7720]) from [<c052a894>] (__usb_hcd_giveback_urb+0x80/0x140)
[<c052a894>] (__usb_hcd_giveback_urb) from [<c052a9a4>] (usb_hcd_giveback_urb+0x50/0x138)
[<c052a9a4>] (usb_hcd_giveback_urb) from [<c0550684>] (musb_giveback+0xc8/0x1cc)

Fixes: b69578df7e98 ("USB: usbserial: mos7720: add support for parallel
port on moschip 7715")
Signed-off-by: Johan Hovold <johan@kernel.org>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/mos7720.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

--- a/drivers/usb/serial/mos7720.c
+++ b/drivers/usb/serial/mos7720.c
@@ -2147,8 +2147,10 @@ static int mos7720_startup(struct usb_se
 #ifdef CONFIG_USB_SERIAL_MOS7715_PARPORT
 	if (product == MOSCHIP_DEVICE_ID_7715) {
 		ret_val = mos7715_parport_init(serial);
-		if (ret_val < 0)
+		if (ret_val < 0) {
+			usb_kill_urb(serial->port[0]->interrupt_in_urb);
 			return ret_val;
+		}
 	}
 #endif
 	/* LSR For Port 1 */
@@ -2162,6 +2164,8 @@ static void mos7720_release(struct usb_s
 {
 	int i;
 
+	usb_kill_urb(serial->port[0]->interrupt_in_urb);
+
 #ifdef CONFIG_USB_SERIAL_MOS7715_PARPORT
 	/* close the parallel port */
 

[toc] | [prev] | [next] | [standalone]


#1597502 — [PATCH 3.2 063/199] USB: gadgetfs: fix use-after-free bug

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 063/199] USB: gadgetfs: fix use-after-free bug
Message-ID<tjssX-4sG-39@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Alan Stern <stern@rowland.harvard.edu>

commit add333a81a16abbd4f106266a2553677a165725f upstream.

Andrey Konovalov reports that fuzz testing with syzkaller causes a
KASAN use-after-free bug report in gadgetfs:

BUG: KASAN: use-after-free in gadgetfs_setup+0x208a/0x20e0 at addr ffff88003dfe5bf2
Read of size 2 by task syz-executor0/22994
CPU: 3 PID: 22994 Comm: syz-executor0 Not tainted 4.9.0-rc7+ #16
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011
 ffff88006df06a18 ffffffff81f96aba ffffffffe0528500 1ffff1000dbe0cd6
 ffffed000dbe0cce ffff88006df068f0 0000000041b58ab3 ffffffff8598b4c8
 ffffffff81f96828 1ffff1000dbe0ccd ffff88006df06708 ffff88006df06748
Call Trace:
 <IRQ> [  201.343209]  [<     inline     >] __dump_stack lib/dump_stack.c:15
 <IRQ> [  201.343209]  [<ffffffff81f96aba>] dump_stack+0x292/0x398 lib/dump_stack.c:51
 [<ffffffff817e4dec>] kasan_object_err+0x1c/0x70 mm/kasan/report.c:159
 [<     inline     >] print_address_description mm/kasan/report.c:197
 [<ffffffff817e5080>] kasan_report_error+0x1f0/0x4e0 mm/kasan/report.c:286
 [<     inline     >] kasan_report mm/kasan/report.c:306
 [<ffffffff817e562a>] __asan_report_load_n_noabort+0x3a/0x40 mm/kasan/report.c:337
 [<     inline     >] config_buf drivers/usb/gadget/legacy/inode.c:1298
 [<ffffffff8322c8fa>] gadgetfs_setup+0x208a/0x20e0 drivers/usb/gadget/legacy/inode.c:1368
 [<ffffffff830fdcd0>] dummy_timer+0x11f0/0x36d0 drivers/usb/gadget/udc/dummy_hcd.c:1858
 [<ffffffff814807c1>] call_timer_fn+0x241/0x800 kernel/time/timer.c:1308
 [<     inline     >] expire_timers kernel/time/timer.c:1348
 [<ffffffff81482de6>] __run_timers+0xa06/0xec0 kernel/time/timer.c:1641
 [<ffffffff814832c1>] run_timer_softirq+0x21/0x80 kernel/time/timer.c:1654
 [<ffffffff84f4af8b>] __do_softirq+0x2fb/0xb63 kernel/softirq.c:284

The cause of the bug is subtle.  The dev_config() routine gets called
twice by the fuzzer.  The first time, the user data contains both a
full-speed configuration descriptor and a high-speed config
descriptor, causing dev->hs_config to be set.  But it also contains an
invalid device descriptor, so the buffer containing the descriptors is
deallocated and dev_config() returns an error.

The second time dev_config() is called, the user data contains only a
full-speed config descriptor.  But dev->hs_config still has the stale
pointer remaining from the first call, causing the routine to think
that there is a valid high-speed config.  Later on, when the driver
dereferences the stale pointer to copy that descriptor, we get a
use-after-free access.

The fix is simple: Clear dev->hs_config if the passed-in data does not
contain a high-speed config descriptor.

Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Tested-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
[bwh: Backported to 3.2: adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/gadget/inode.c | 2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/usb/gadget/inode.c
+++ b/drivers/usb/gadget/inode.c
@@ -1899,6 +1899,8 @@ dev_config (struct file *fd, const char
 			goto fail;
 		kbuf += total;
 		length -= total;
+	} else {
+		dev->hs_config = NULL;
 	}
 
 	/* could support multiple configs, using another encoding! */

[toc] | [prev] | [next] | [standalone]


#1597503 — [PATCH 3.2 048/199] IB/multicast: Check ib_find_pkey() return value

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 048/199] IB/multicast: Check ib_find_pkey() return value
Message-ID<tjssX-4sG-43@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Bart Van Assche <bart.vanassche@sandisk.com>

commit d3a2418ee36a59bc02e9d454723f3175dcf4bfd9 upstream.

This patch avoids that Coverity complains about not checking the
ib_find_pkey() return value.

Fixes: commit 547af76521b3 ("IB/multicast: Report errors on multicast groups if P_key changes")
Signed-off-by: Bart Van Assche <bart.vanassche@sandisk.com>
Cc: Sean Hefty <sean.hefty@intel.com>
Signed-off-by: Doug Ledford <dledford@redhat.com>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/infiniband/core/multicast.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

--- a/drivers/infiniband/core/multicast.c
+++ b/drivers/infiniband/core/multicast.c
@@ -516,8 +516,11 @@ static void join_handler(int status, str
 	if (status)
 		process_join_error(group, status);
 	else {
-		ib_find_pkey(group->port->dev->device, group->port->port_num,
-			     be16_to_cpu(rec->pkey), &pkey_index);
+
+		if (ib_find_pkey(group->port->dev->device,
+				 group->port->port_num, be16_to_cpu(rec->pkey),
+				 &pkey_index))
+			pkey_index = MCAST_INVALID_PKEY_INDEX;
 
 		spin_lock_irq(&group->port->lock);
 		group->rec = *rec;

[toc] | [prev] | [next] | [standalone]


#1597504 — [PATCH 3.2 074/199] USB: serial: mos7720: fix NULL-deref at open

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-10 14:10 +0100
Subject[PATCH 3.2 074/199] USB: serial: mos7720: fix NULL-deref at open
Message-ID<tjssX-4sG-45@gated-at.bofh.it>
In reply to#1597344
3.2.87-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit b05aebc25fdc5aeeac3ee29f0dc9f58dd07c13cc upstream.

Fix NULL-pointer dereference at port open if a device lacks the expected
bulk in and out endpoints.

Unable to handle kernel NULL pointer dereference at virtual address 00000030
...
[<bf071c20>] (mos7720_open [mos7720]) from [<bf0490e0>] (serial_port_activate+0x68/0x98 [usbserial])
[<bf0490e0>] (serial_port_activate [usbserial]) from [<c0470ca4>] (tty_port_open+0x9c/0xe8)
[<c0470ca4>] (tty_port_open) from [<bf049d98>] (serial_open+0x48/0x6c [usbserial])
[<bf049d98>] (serial_open [usbserial]) from [<c0469178>] (tty_open+0xcc/0x5cc)

Fixes: 0f64478cbc7a ("USB: add USB serial mos7720 driver")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/serial/mos7720.c | 5 +++++
 1 file changed, 5 insertions(+)

--- a/drivers/usb/serial/mos7720.c
+++ b/drivers/usb/serial/mos7720.c
@@ -2079,6 +2079,11 @@ static int mos7720_startup(struct usb_se
 		return -ENODEV;
 	}
 
+	if (serial->num_bulk_in < 2 || serial->num_bulk_out < 2) {
+		dev_err(&serial->interface->dev, "missing bulk endpoints\n");
+		return -ENODEV;
+	}
+
 	product = le16_to_cpu(serial->dev->descriptor.idProduct);
 	dev = serial->dev;
 

[toc] | [prev] | [next] | [standalone]


Page 4 of 7 — ← Prev page 1 2 3 [4] 5 6 7  Next page →

Back to top | Article view | linux.kernel


csiph-web