Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1620052 > unrolled thread

[PATCH 3.12 001/142] dm: flush queued bios when process blocks to avoid deadlock

Started byJiri Slaby <jslaby@suse.cz>
First post2017-04-10 17:40 +0200
Last post2017-04-10 18:20 +0200
Articles 7 on this page of 127 — 1 participant

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  [PATCH 3.12 001/142] dm: flush queued bios when process blocks to avoid deadlock Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 092/142] ext4: mark inode dirty after converting inline directory Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 134/142] ipv4: igmp: Allow removing groups from a removed interface Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 113/142] ALSA: seq: Fix race during FIFO resize Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 129/142] ACPI / PNP: Avoid conflicting resource reservations Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 123/142] padata: avoid race in reordering Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 135/142] HID: hid-lg: Fix immediate disconnection of Logitech Rumblepad 2 Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 142/142] tty/serial: atmel: fix race condition (TX+DMA) Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 131/142] ACPI / PNP: Reserve ACPI resources at the fs_initcall_sync stage Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 133/142] i2c: at91: manage unexpected RXRDY flag when starting a transfer Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 114/142] ACPI: Fix incompatibility with mcount-based function graph tracing Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 130/142] ACPI / resources: free memory on error in add_region_before() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 115/142] USB: fix linked-list corruption in rh_call_control() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 093/142] mmc: sdhci: Do not disable interrupts while waiting for clock Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 105/142] sparc/ptrace: Preserve previous registers for short regset write Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 121/142] rtc: s35390a: improve irq handling Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 112/142] scsi: libsas: fix ata xfer length Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 109/142] sched/rt: Add a missing rescheduling point Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 111/142] scsi: mpt3sas: fix hang on ata passthrough commands Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 088/142] usb: hub: Fix crash after failure to read BOS descriptor Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 103/142] virtio_balloon: init 1st buffer in stats vq Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 100/142] crypto: algif_hash - avoid zero-sized array Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 122/142] KVM: kvm_io_bus_unregister_dev() should never fail Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 097/142] block: allow WRITE_SAME commands with the SG_IO ioctl Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 116/142] KVM: x86: clear bus pointer when destroyed Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 099/142] fbcon: Fix vc attr at deinit Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 089/142] uwb: i1480-dfu: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 081/142] USB: serial: option: add Quectel UC15, UC20, EC21, and EC25 modems Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 079/142] Input: kbtab - validate number of endpoints before using them Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 094/142] nl80211: fix dumpit error path RTNL deadlocks Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 118/142] rtc: s35390a: fix reading out alarm Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 101/142] xfrm_user: validate XFRM_MSG_NEWAE XFRMA_REPLAY_ESN_VAL replay_window Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 083/142] ACM gadget: fix endianness in notifications Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 102/142] xfrm_user: validate XFRM_MSG_NEWAE incoming ESN size harder Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 095/142] USB: usbtmc: add missing endpoint sanity check Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 120/142] rtc: s35390a: implement reset routine as suggested by the reference Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 096/142] xfs: clear _XBF_PAGES from buffers when readahead page Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 106/142] metag/ptrace: Preserve previous registers for short regset write Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 110/142] libceph: force GFP_NOIO for socket allocations Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 107/142] metag/ptrace: Provide default TXSTATUS for short NT_PRSTATUS Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 090/142] uwb: hwa-rc: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 108/142] metag/ptrace: Reject partial NT_METAG_RPIPE writes Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 098/142] uvcvideo: uvc_scan_fallback() for webcams with broken chain Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 104/142] c6x/ptrace: Remove useless PTRACE_SETREGSET implementation Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 091/142] mmc: ushc: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 117/142] mm, hugetlb: use pte_present() instead of pmd_present() in follow_huge_pmd() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 126/142] Revert "cpufreq: fix garbage kobjects on errors during suspend/resume" Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 119/142] rtc: s35390a: make sure all members in the output are set Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 080/142] ALSA: seq: Fix racy cell insertions during snd_seq_pool_done() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 059/142] igb: add i211 to i210 PHY workaround Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 039/142] give up on gcc ilog2() constant optimizations Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 087/142] USB: wusbcore: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 069/142] USB: qcserial: add Sierra Wireless MC74xx/EM74xx Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 068/142] USB: qcserial: add HP lt4111 LTE/EV-DO/HSPA+ Gobi 4G Module Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 078/142] Input: cm109 - validate number of endpoints before using them Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 073/142] Input: i8042 - add noloop quirk for Dell Embedded Box PC 3000 Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 070/142] USB: qcserial: Add support for Quectel EC20 Mini PCIe module Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 067/142] USB: qcserial: Add support for Dell Wireless 5809e 4G Modem Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 046/142] ACPI / video: skip evaluating _DOD when it does not exist Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 086/142] USB: idmouse: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 052/142] perf/core: Fix event inheritance on fork() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 074/142] Input: iforce - validate number of endpoints before using them Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 065/142] tcp: initialize icsk_ack.lrcvtime at session start time Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 064/142] ipv4: provide stronger user input validation in nl_fib_input() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 060/142] net: properly release sk_frag.page Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 076/142] Input: hanwang - validate number of endpoints before using them Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 058/142] igb: Workaround for igb i210 firmware issue Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 066/142] libceph: don't set weight to IN when OSD is destroyed Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 082/142] USB: serial: qcserial: add Dell DW5811e Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 075/142] Input: ims-pcu - validate number of endpoints before using them Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 072/142] USB: qcserial: add Sierra Wireless EM74xx device ID Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 077/142] Input: yealink - validate number of endpoints before using them Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 071/142] USB: qcserial: add Dell Wireless 5809e Gobi 4G HSPA+ (rev3) Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 084/142] usb-core: Add LINEAR_FRAME_INTR_BINTERVAL USB quirk Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 085/142] USB: uss720: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 063/142] net/mlx5: Increase number of max QPs in default profile Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 049/142] KVM: PPC: Book3S PR: Fix illegal opcode emulation Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 038/142] futex: Add missing error handling to FUTEX_REQUEUE_PI Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 034/142] dccp/tcp: fix routing redirect race Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 062/142] qmi_wwan: add Dell DW5811e Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 061/142] net: unix: properly re-increment inflight counter of GC discarded candidates Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 045/142] crypto: cryptd - Assign statesize properly Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 033/142] ipv6: avoid write to a possibly cloned skb Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 030/142] dccp: Unlock sock before calling sk_free() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 048/142] Drivers: hv: avoid vfree() on crash Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 055/142] scsi: lpfc: Add shutdown method for kexec Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 043/142] netlink: remove mmapped netlink support Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 028/142] net: don't call strlen() on the user buffer in packet_bind_spkt() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 032/142] uapi: fix linux/packet_diag.h userspace compilation error Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 053/142] cpufreq: Fix and clean up show_cpuinfo_cur_freq() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 054/142] target/pscsi: Fix TYPE_TAPE + TYPE_MEDIMUM_CHANGER export Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 051/142] kernek/fork.c: allocate idle task for a CPU always on its local node Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 056/142] isdn/gigaset: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 026/142] ipv4: mask tos for input route Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 041/142] xfs: fix up xfs_swap_extent_forks inline extent handling Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 044/142] crypto: ghash-clmulni - Fix load failure Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 057/142] xen: do not re-use pirq number cached in pci device msi msg data Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 036/142] net sched actions: decrement module reference count after table flush. Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 047/142] Drivers: hv: balloon: don't crash when memory is added in non-sorted order Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 050/142] s390/pci: fix use after free in dma_init Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 024/142] locking/static_keys: Add static_key_{en,dis}able() helpers Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 012/142] cpmac: remove hopeless #warning Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 035/142] dccp: fix memory leak during tear-down of unsuccessful connection request Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 017/142] USB: serial: safe_serial: fix information leak in completion handler Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 019/142] USB: iowarrior: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 015/142] usb: dwc3: gadget: make Set Endpoint Configuration macros safe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 018/142] USB: serial: omninet: fix reference leaks at open Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 005/142] USB: serial: digi_acceleport: fix OOB data sanity check Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 029/142] net: net_enable_timestamp() can be called from irq contexts Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 004/142] xhci: fix 10 second timeout on removal of PCI hotpluggable xhci controllers Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 016/142] usb: host: xhci-plat: Fix timeout on removal of hot pluggable xhci controllers Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 007/142] crypto: improve gcc optimization flags for serpent and wp512 Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 013/142] MIPS: DEC: Avoid la pseudo-instruction in delay slots Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 025/142] vxlan: correctly validate VXLAN ID against VXLAN_N_VID Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 014/142] tracing: Add #undef to fix compile error Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 002/142] xfs: pass total block res. as total xfs_bmapi_write() parameter Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 009/142] MIPS: ip22: Fix ip28 build for modern gcc Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 011/142] MIPS: ralink: Cosmetic change to prom_init(). Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 010/142] mtd: pmcmsp: use kstrndup instead of kmalloc+strncpy Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 022/142] USB: serial: io_ti: fix information leak in completion handler Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 020/142] USB: iowarrior: fix NULL-deref in write Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 008/142] MIPS: ip27: Disable qlge driver in defconfig Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 021/142] USB: serial: io_ti: fix NULL-deref in interrupt callback Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 031/142] tcp: fix various issues for sockets morphing to listen state Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 006/142] USB: serial: digi_acceleport: fix OOB-event processing Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 027/142] l2tp: avoid use-after-free caused by l2tp_ip_backlog_recv Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 003/142] mm/huge_memory.c: respect FOLL_FORCE/FOLL_COW for thp Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200

Page 7 of 7 — ← Prev page 1 2 3 4 5 6 [7]


#1620205 — [PATCH 3.12 020/142] USB: iowarrior: fix NULL-deref in write

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:20 +0200
Subject[PATCH 3.12 020/142] USB: iowarrior: fix NULL-deref in write
Message-ID<tuKcP-2ZH-45@gated-at.bofh.it>
In reply to#1620052
From: Johan Hovold <johan@kernel.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit de46e56653de7b3b54baa625bd582635008b8d05 upstream.

Make sure to verify that we have the required interrupt-out endpoint for
IOWarrior56 devices to avoid dereferencing a NULL-pointer in write
should a malicious device lack such an endpoint.

Fixes: 946b960d13c1 ("USB: add driver for iowarrior devices.")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/usb/misc/iowarrior.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/drivers/usb/misc/iowarrior.c b/drivers/usb/misc/iowarrior.c
index 6dda72ef6ccf..05aa716cf6b5 100644
--- a/drivers/usb/misc/iowarrior.c
+++ b/drivers/usb/misc/iowarrior.c
@@ -809,6 +809,14 @@ static int iowarrior_probe(struct usb_interface *interface,
 		goto error;
 	}
 
+	if (dev->product_id == USB_DEVICE_ID_CODEMERCS_IOW56) {
+		if (!dev->int_out_endpoint) {
+			dev_err(&interface->dev, "no interrupt-out endpoint found\n");
+			retval = -ENODEV;
+			goto error;
+		}
+	}
+
 	/* we have to check the report_size often, so remember it in the endianness suitable for our machine */
 	dev->report_size = usb_endpoint_maxp(dev->int_in_endpoint);
 	if ((dev->interface->cur_altsetting->desc.bInterfaceNumber == 0) &&
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620206 — [PATCH 3.12 008/142] MIPS: ip27: Disable qlge driver in defconfig

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:20 +0200
Subject[PATCH 3.12 008/142] MIPS: ip27: Disable qlge driver in defconfig
Message-ID<tuKcP-2ZH-57@gated-at.bofh.it>
In reply to#1620052
From: Arnd Bergmann <arnd@arndb.de>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit b617649468390713db1515ea79fc772d2eb897a8 upstream.

One of the last remaining failures in kernelci.org is for a gcc bug:

drivers/net/ethernet/qlogic/qlge/qlge_main.c:4819:1: error: insn does not satisfy its constraints:
drivers/net/ethernet/qlogic/qlge/qlge_main.c:4819:1: internal compiler error: in extract_constrain_insn, at recog.c:2190

This is apparently broken in gcc-6 but fixed in gcc-7, and I cannot
reproduce the problem here. However, it is clear that ip27_defconfig
does not actually need this driver as the platform has only PCI-X but
not PCIe, and the qlge adapter in turn is PCIe-only.

The driver was originally enabled in 2010 along with lots of other
drivers.

Fixes: 59d302b342e5 ("MIPS: IP27: Make defconfig useful again.")
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Cc: Ralf Baechle <ralf@linux-mips.org>
Cc: linux-mips@linux-mips.org
Cc: linux-kernel@vger.kernel.org
Patchwork: https://patchwork.linux-mips.org/patch/15197/
Signed-off-by: James Hogan <james.hogan@imgtec.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 arch/mips/configs/ip27_defconfig | 1 -
 1 file changed, 1 deletion(-)

diff --git a/arch/mips/configs/ip27_defconfig b/arch/mips/configs/ip27_defconfig
index 0e36abcd39cc..7446284dd7b3 100644
--- a/arch/mips/configs/ip27_defconfig
+++ b/arch/mips/configs/ip27_defconfig
@@ -206,7 +206,6 @@ CONFIG_MLX4_EN=m
 # CONFIG_MLX4_DEBUG is not set
 CONFIG_TEHUTI=m
 CONFIG_BNX2X=m
-CONFIG_QLGE=m
 CONFIG_SFC=m
 CONFIG_BE2NET=m
 CONFIG_LIBERTAS_THINFIRM=m
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620210 — [PATCH 3.12 021/142] USB: serial: io_ti: fix NULL-deref in interrupt callback

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:20 +0200
Subject[PATCH 3.12 021/142] USB: serial: io_ti: fix NULL-deref in interrupt callback
Message-ID<tuKcP-2ZH-59@gated-at.bofh.it>
In reply to#1620052
From: Johan Hovold <johan@kernel.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 0b1d250afb8eb9d65afb568bac9b9f9253a82b49 upstream.

Fix a NULL-pointer dereference in the interrupt callback should a
malicious device send data containing a bad port number by adding the
missing sanity check.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/usb/serial/io_ti.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/usb/serial/io_ti.c b/drivers/usb/serial/io_ti.c
index d569d773e1ce..2e4589a7b982 100644
--- a/drivers/usb/serial/io_ti.c
+++ b/drivers/usb/serial/io_ti.c
@@ -1572,6 +1572,12 @@ static void edge_interrupt_callback(struct urb *urb)
 	function    = TIUMP_GET_FUNC_FROM_CODE(data[0]);
 	dev_dbg(dev, "%s - port_number %d, function %d, info 0x%x\n", __func__,
 		port_number, function, data[1]);
+
+	if (port_number >= edge_serial->serial->num_ports) {
+		dev_err(dev, "bad port number %d\n", port_number);
+		goto exit;
+	}
+
 	port = edge_serial->serial->port[port_number];
 	edge_port = usb_get_serial_port_data(port);
 	if (!edge_port) {
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620211 — [PATCH 3.12 031/142] tcp: fix various issues for sockets morphing to listen state

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:20 +0200
Subject[PATCH 3.12 031/142] tcp: fix various issues for sockets morphing to listen state
Message-ID<tuKcQ-2ZH-65@gated-at.bofh.it>
In reply to#1620052
From: Eric Dumazet <edumazet@google.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 02b2faaf0af1d85585f6d6980e286d53612acfc2 ]

Dmitry Vyukov reported a divide by 0 triggered by syzkaller, exploiting
tcp_disconnect() path that was never really considered and/or used
before syzkaller ;)

I was not able to reproduce the bug, but it seems issues here are the
three possible actions that assumed they would never trigger on a
listener.

1) tcp_write_timer_handler
2) tcp_delack_timer_handler
3) MTU reduction

Only IPv6 MTU reduction was properly testing TCP_CLOSE and TCP_LISTEN
 states from tcp_v6_mtu_reduced()

Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 net/ipv4/tcp_ipv4.c  | 7 +++++--
 net/ipv4/tcp_timer.c | 6 ++++--
 2 files changed, 9 insertions(+), 4 deletions(-)

diff --git a/net/ipv4/tcp_ipv4.c b/net/ipv4/tcp_ipv4.c
index 12504f57fd7b..c67d89ccadf7 100644
--- a/net/ipv4/tcp_ipv4.c
+++ b/net/ipv4/tcp_ipv4.c
@@ -271,10 +271,13 @@ EXPORT_SYMBOL(tcp_v4_connect);
  */
 void tcp_v4_mtu_reduced(struct sock *sk)
 {
-	struct dst_entry *dst;
 	struct inet_sock *inet = inet_sk(sk);
-	u32 mtu = tcp_sk(sk)->mtu_info;
+	struct dst_entry *dst;
+	u32 mtu;
 
+	if ((1 << sk->sk_state) & (TCPF_LISTEN | TCPF_CLOSE))
+		return;
+	mtu = tcp_sk(sk)->mtu_info;
 	dst = inet_csk_update_pmtu(sk, mtu);
 	if (!dst)
 		return;
diff --git a/net/ipv4/tcp_timer.c b/net/ipv4/tcp_timer.c
index 4b85e6f636c9..722367a6d817 100644
--- a/net/ipv4/tcp_timer.c
+++ b/net/ipv4/tcp_timer.c
@@ -201,7 +201,8 @@ void tcp_delack_timer_handler(struct sock *sk)
 
 	sk_mem_reclaim_partial(sk);
 
-	if (sk->sk_state == TCP_CLOSE || !(icsk->icsk_ack.pending & ICSK_ACK_TIMER))
+	if (((1 << sk->sk_state) & (TCPF_CLOSE | TCPF_LISTEN)) ||
+	    !(icsk->icsk_ack.pending & ICSK_ACK_TIMER))
 		goto out;
 
 	if (time_after(icsk->icsk_ack.timeout, jiffies)) {
@@ -480,7 +481,8 @@ void tcp_write_timer_handler(struct sock *sk)
 	struct inet_connection_sock *icsk = inet_csk(sk);
 	int event;
 
-	if (sk->sk_state == TCP_CLOSE || !icsk->icsk_pending)
+	if (((1 << sk->sk_state) & (TCPF_CLOSE | TCPF_LISTEN)) ||
+	    !icsk->icsk_pending)
 		goto out;
 
 	if (time_after(icsk->icsk_timeout, jiffies)) {
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620212 — [PATCH 3.12 006/142] USB: serial: digi_acceleport: fix OOB-event processing

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:20 +0200
Subject[PATCH 3.12 006/142] USB: serial: digi_acceleport: fix OOB-event processing
Message-ID<tuKcQ-2ZH-69@gated-at.bofh.it>
In reply to#1620052
From: Johan Hovold <johan@kernel.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 2e46565cf622dd0534a9d8bffe152a577b48d7aa upstream.

A recent change claimed to fix an off-by-one error in the OOB-port
completion handler, but instead introduced such an error. This could
specifically led to modem-status changes going unnoticed, effectively
breaking TIOCMGET.

Note that the offending commit fixes a loop-condition underflow and is
marked for stable, but should not be backported without this fix.

Reported-by: Ben Hutchings <ben@decadent.org.uk>
Fixes: 2d380889215f ("USB: serial: digi_acceleport: fix OOB data sanity
check")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/usb/serial/digi_acceleport.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/usb/serial/digi_acceleport.c b/drivers/usb/serial/digi_acceleport.c
index b5dcbf563cd4..9c07bbc4f8a7 100644
--- a/drivers/usb/serial/digi_acceleport.c
+++ b/drivers/usb/serial/digi_acceleport.c
@@ -1494,7 +1494,7 @@ static int digi_read_oob_callback(struct urb *urb)
 		return -1;
 
 	/* handle each oob command */
-	for (i = 0; i < urb->actual_length - 4; i += 4) {
+	for (i = 0; i < urb->actual_length - 3; i += 4) {
 		opcode = buf[i];
 		line = buf[i + 1];
 		status = buf[i + 2];
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620213 — [PATCH 3.12 027/142] l2tp: avoid use-after-free caused by l2tp_ip_backlog_recv

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:20 +0200
Subject[PATCH 3.12 027/142] l2tp: avoid use-after-free caused by l2tp_ip_backlog_recv
Message-ID<tuKcQ-2ZH-67@gated-at.bofh.it>
In reply to#1620052
From: Paul Hüber <phueber@kernsp.in>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 51fb60eb162ab84c5edf2ae9c63cf0b878e5547e ]

l2tp_ip_backlog_recv may not return -1 if the packet gets dropped.
The return value is passed up to ip_local_deliver_finish, which treats
negative values as an IP protocol number for resubmission.

Signed-off-by: Paul Hüber <phueber@kernsp.in>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 net/l2tp/l2tp_ip.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/l2tp/l2tp_ip.c b/net/l2tp/l2tp_ip.c
index b69b762159ad..c44b3742ae36 100644
--- a/net/l2tp/l2tp_ip.c
+++ b/net/l2tp/l2tp_ip.c
@@ -383,7 +383,7 @@ static int l2tp_ip_backlog_recv(struct sock *sk, struct sk_buff *skb)
 drop:
 	IP_INC_STATS(sock_net(sk), IPSTATS_MIB_INDISCARDS);
 	kfree_skb(skb);
-	return -1;
+	return 0;
 }
 
 /* Userspace will call sendmsg() on the tunnel socket to send L2TP
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620214 — [PATCH 3.12 003/142] mm/huge_memory.c: respect FOLL_FORCE/FOLL_COW for thp

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:20 +0200
Subject[PATCH 3.12 003/142] mm/huge_memory.c: respect FOLL_FORCE/FOLL_COW for thp
Message-ID<tuKcQ-2ZH-61@gated-at.bofh.it>
In reply to#1620052
From: Keno Fischer <keno@juliacomputing.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 8310d48b125d19fcd9521d83b8293e63eb1646aa upstream.

In commit 19be0eaffa3a ("mm: remove gup_flags FOLL_WRITE games from
__get_user_pages()"), the mm code was changed from unsetting FOLL_WRITE
after a COW was resolved to setting the (newly introduced) FOLL_COW
instead.  Simultaneously, the check in gup.c was updated to still allow
writes with FOLL_FORCE set if FOLL_COW had also been set.

However, a similar check in huge_memory.c was forgotten.  As a result,
remote memory writes to ro regions of memory backed by transparent huge
pages cause an infinite loop in the kernel (handle_mm_fault sets
FOLL_COW and returns 0 causing a retry, but follow_trans_huge_pmd bails
out immidiately because `(flags & FOLL_WRITE) && !pmd_write(*pmd)` is
true.

While in this state the process is stil SIGKILLable, but little else
works (e.g.  no ptrace attach, no other signals).  This is easily
reproduced with the following code (assuming thp are set to always):

    #include <assert.h>
    #include <fcntl.h>
    #include <stdint.h>
    #include <stdio.h>
    #include <string.h>
    #include <sys/mman.h>
    #include <sys/stat.h>
    #include <sys/types.h>
    #include <sys/wait.h>
    #include <unistd.h>

    #define TEST_SIZE 5 * 1024 * 1024

    int main(void) {
      int status;
      pid_t child;
      int fd = open("/proc/self/mem", O_RDWR);
      void *addr = mmap(NULL, TEST_SIZE, PROT_READ,
                        MAP_ANONYMOUS | MAP_PRIVATE, 0, 0);
      assert(addr != MAP_FAILED);
      pid_t parent_pid = getpid();
      if ((child = fork()) == 0) {
        void *addr2 = mmap(NULL, TEST_SIZE, PROT_READ | PROT_WRITE,
                           MAP_ANONYMOUS | MAP_PRIVATE, 0, 0);
        assert(addr2 != MAP_FAILED);
        memset(addr2, 'a', TEST_SIZE);
        pwrite(fd, addr2, TEST_SIZE, (uintptr_t)addr);
        return 0;
      }
      assert(child == waitpid(child, &status, 0));
      assert(WIFEXITED(status) && WEXITSTATUS(status) == 0);
      return 0;
    }

Fix this by updating follow_trans_huge_pmd in huge_memory.c analogously
to the update in gup.c in the original commit.  The same pattern exists
in follow_devmap_pmd.  However, we should not be able to reach that
check with FOLL_COW set, so add WARN_ONCE to make sure we notice if we
ever do.

[akpm@linux-foundation.org: coding-style fixes]
Link: http://lkml.kernel.org/r/20170106015025.GA38411@juliacomputing.com
Signed-off-by: Keno Fischer <keno@juliacomputing.com>
Acked-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Cc: Greg Thelen <gthelen@google.com>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Willy Tarreau <w@1wt.eu>
Cc: Oleg Nesterov <oleg@redhat.com>
Cc: Kees Cook <keescook@chromium.org>
Cc: Andy Lutomirski <luto@kernel.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Hugh Dickins <hughd@google.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[bwh: Backported to 3.2:
 - Drop change to follow_devmap_pmd()
 - pmd_dirty() is not available; check the page flags as in
   can_follow_write_pte()
 - Adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
[mhocko:
  This has been forward ported from the 3.2 stable tree.
  And fixed to return NULL.]
Reviewed-by: Michal Hocko <mhocko@suse.cz>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 mm/huge_memory.c | 19 ++++++++++++++++---
 1 file changed, 16 insertions(+), 3 deletions(-)

diff --git a/mm/huge_memory.c b/mm/huge_memory.c
index 04535b64119c..59ab994d1bc4 100644
--- a/mm/huge_memory.c
+++ b/mm/huge_memory.c
@@ -1222,6 +1222,18 @@ out_unlock:
 	return ret;
 }
 
+/*
+ * foll_force can write to even unwritable pmd's, but only
+ * after we've gone through a cow cycle and they are dirty.
+ */
+static inline bool can_follow_write_pmd(pmd_t pmd, struct page *page,
+					unsigned int flags)
+{
+	return pmd_write(pmd) ||
+		((flags & FOLL_FORCE) && (flags & FOLL_COW) &&
+		 page && PageAnon(page));
+}
+
 struct page *follow_trans_huge_pmd(struct vm_area_struct *vma,
 				   unsigned long addr,
 				   pmd_t *pmd,
@@ -1232,9 +1244,6 @@ struct page *follow_trans_huge_pmd(struct vm_area_struct *vma,
 
 	assert_spin_locked(&mm->page_table_lock);
 
-	if (flags & FOLL_WRITE && !pmd_write(*pmd))
-		goto out;
-
 	/* Avoid dumping huge zero page */
 	if ((flags & FOLL_DUMP) && is_huge_zero_pmd(*pmd))
 		return ERR_PTR(-EFAULT);
@@ -1245,6 +1254,10 @@ struct page *follow_trans_huge_pmd(struct vm_area_struct *vma,
 
 	page = pmd_page(*pmd);
 	VM_BUG_ON(!PageHead(page));
+
+	if (flags & FOLL_WRITE && !can_follow_write_pmd(*pmd, page, flags))
+		return NULL;
+
 	if (flags & FOLL_TOUCH) {
 		pmd_t _pmd;
 		/*
-- 
2.12.2

[toc] | [prev] | [standalone]


Page 7 of 7 — ← Prev page 1 2 3 4 5 6 [7]

Back to top | Article view | linux.kernel


csiph-web