Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1738558 > unrolled thread

[PATCH 4.4 00/66] 4.4.89-stable review

Started byGreg Kroah-Hartman <gregkh@linuxfoundation.org>
First post2017-09-24 23:30 +0200
Last post2017-09-26 01:20 +0200
Articles 9 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 4.4 00/66] 4.4.89-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-09-24 23:30 +0200
    [PATCH 4.4 19/66] tty: fix __tty_insert_flip_char regression Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-09-24 23:40 +0200
    [PATCH 4.4 20/66] Input: i8042 - add Gigabyte P57 to the keyboard reset table Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-09-24 23:40 +0200
    [PATCH 4.4 16/66] mm: prevent double decrease of nr_reserved_highatomic Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-09-24 23:40 +0200
    [PATCH 4.4 17/66] tty: improve tty_insert_flip_char() fast path Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-09-24 23:40 +0200
    [PATCH 4.4 02/66] ipv6: add rcu grace period before freeing fib6_node Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-09-24 23:40 +0200
    [PATCH 4.4 14/66] md/raid5: release/flush io in raid5_do_work() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-09-24 23:40 +0200
    Re: [PATCH 4.4 00/66] 4.4.89-stable review Guenter Roeck <linux@roeck-us.net> - 2017-09-25 03:10 +0200
    Re: [PATCH 4.4 00/66] 4.4.89-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2017-09-26 01:20 +0200

#1738558 — [PATCH 4.4 00/66] 4.4.89-stable review

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-09-24 23:30 +0200
Subject[PATCH 4.4 00/66] 4.4.89-stable review
Message-ID<utlQZ-4Ti-3@gated-at.bofh.it>
This is the start of the stable review cycle for the 4.4.89 release.
There are 66 patches in this series, all will be posted as a response
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Tue Sep 26 20:29:06 UTC 2017.
Anything received after that time might be too late.

The whole patch series can be found in one patch at:
	kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.4.89-rc1.gz
or in the git tree and branch at:
  git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.4.y
and the diffstat can be found below.

thanks,

greg k-h

-------------
Pseudo-Shortlog of commits:

Greg Kroah-Hartman <gregkh@linuxfoundation.org>
    Linux 4.4.89-rc1

Avraham Stern <avraham.stern@intel.com>
    mac80211: flush hw_roc_start work before cancelling the ROC

Steven Rostedt (VMware) <rostedt@goodmis.org>
    ftrace: Fix memleak when unregistering dynamic ops when tracing disabled

Michael Lyle <mlyle@lyle.org>
    bcache: fix bch_hprint crash and improve output

Tang Junhui <tang.junhui@zte.com.cn>
    bcache: fix for gc and write-back race

Tony Asleson <tasleson@redhat.com>
    bcache: Correct return value for sysfs attach errors

Tang Junhui <tang.junhui@zte.com.cn>
    bcache: correct cache_dirty_target in __update_writeback_rate()

Tang Junhui <tang.junhui@zte.com.cn>
    bcache: do not subtract sectors_to_gc for bypassed IO

Jan Kara <jack@suse.cz>
    bcache: Fix leak of bdev reference

Tang Junhui <tang.junhui@zte.com.cn>
    bcache: initialize dirty stripes in flash_dev_run()

Guenter Roeck <linux@roeck-us.net>
    media: uvcvideo: Prevent heap overflow when accessing mapped controls

Daniel Mentz <danielmentz@google.com>
    media: v4l2-compat-ioctl32: Fix timespec conversion

Aleksandr Bezzubikov <zuban32s@gmail.com>
    PCI: shpchp: Enable bridge bus mastering if MSI is enabled

Jose Abreu <Jose.Abreu@synopsys.com>
    ARC: Re-enable MMU upon Machine Check exception

Baohong Liu <baohong.liu@intel.com>
    tracing: Apply trace_clock changes to instance max buffer

Steven Rostedt (VMware) <rostedt@goodmis.org>
    ftrace: Fix selftest goto location on error

Dan Carpenter <dan.carpenter@oracle.com>
    scsi: qla2xxx: Fix an integer overflow in sysfs code

Hannes Reinecke <hare@suse.de>
    scsi: sg: fixup infoleak when using SG_GET_REQUEST_TABLE

Hannes Reinecke <hare@suse.de>
    scsi: sg: factor out sg_fill_request_table()

Dan Carpenter <dan.carpenter@oracle.com>
    scsi: sg: off by one in sg_ioctl()

Hannes Reinecke <hare@suse.de>
    scsi: sg: use standard lists for sg_requests

Hannes Reinecke <hare@suse.de>
    scsi: sg: remove 'save_scat_len'

Long Li <longli@microsoft.com>
    scsi: storvsc: fix memory leak on ring buffer busy

Shivasharan S <shivasharan.srikanteshwara@broadcom.com>
    scsi: megaraid_sas: Return pended IOCTLs with cmd_status MFI_STAT_WRONG_STATE in case adapter is dead

Shivasharan S <shivasharan.srikanteshwara@broadcom.com>
    scsi: megaraid_sas: Check valid aen class range to avoid kernel panic

Steffen Maier <maier@linux.vnet.ibm.com>
    scsi: zfcp: trace high part of "new" 64 bit SCSI LUN

Steffen Maier <maier@linux.vnet.ibm.com>
    scsi: zfcp: trace HBA FSF response by default on dismiss or timedout late response

Steffen Maier <maier@linux.vnet.ibm.com>
    scsi: zfcp: fix payload with full FCP_RSP IU in SCSI trace records

Steffen Maier <maier@linux.vnet.ibm.com>
    scsi: zfcp: fix missing trace records for early returns in TMF eh handlers

Steffen Maier <maier@linux.vnet.ibm.com>
    scsi: zfcp: fix passing fsf_req to SCSI trace on TMF to correlate with HBA

Steffen Maier <maier@linux.vnet.ibm.com>
    scsi: zfcp: fix capping of unsuccessful GPN_FT SAN response trace records

Benjamin Block <bblock@linux.vnet.ibm.com>
    scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path

Steffen Maier <maier@linux.vnet.ibm.com>
    scsi: zfcp: fix queuecommand for scsi_eh commands when DIX enabled

Bart Van Assche <bart.vanassche@wdc.com>
    skd: Submit requests to firmware before triggering the doorbell

Bart Van Assche <bart.vanassche@wdc.com>
    skd: Avoid that module unloading triggers a use-after-free

NeilBrown <neilb@suse.com>
    md/bitmap: disable bitmap_resize for file-backed bitmaps.

Bart Van Assche <bart.vanassche@wdc.com>
    block: Relax a check in blk_start_queue()

Michael Ellerman <mpe@ellerman.id.au>
    powerpc: Fix DAR reporting when alignment handler faults

zhangyi (F) <yi.zhang@huawei.com>
    ext4: fix quota inconsistency during orphan cleanup for read-only mounts

zhangyi (F) <yi.zhang@huawei.com>
    ext4: fix incorrect quotaoff if the quota feature is enabled

Stephan Mueller <smueller@chronox.de>
    crypto: AF_ALG - remove SGL terminator indicator when chaining

Aleksandar Markovic <aleksandar.markovic@imgtec.com>
    MIPS: math-emu: MINA.<D|S>: Fix some cases of infinity and zero inputs

Aleksandar Markovic <aleksandar.markovic@imgtec.com>
    MIPS: math-emu: <MAXA|MINA>.<D|S>: Fix cases of both infinite inputs

Aleksandar Markovic <aleksandar.markovic@imgtec.com>
    MIPS: math-emu: <MAXA|MINA>.<D|S>: Fix cases of input values with opposite signs

Aleksandar Markovic <aleksandar.markovic@imgtec.com>
    MIPS: math-emu: <MAX|MIN>.<D|S>: Fix cases of both inputs negative

Aleksandar Markovic <aleksandar.markovic@imgtec.com>
    MIPS: math-emu: <MAX|MAXA|MIN|MINA>.<D|S>: Fix cases of both inputs zero

Aleksandar Markovic <aleksandar.markovic@imgtec.com>
    MIPS: math-emu: <MAX|MAXA|MIN|MINA>.<D|S>: Fix quiet NaN propagation

Kai-Heng Feng <kai.heng.feng@canonical.com>
    Input: i8042 - add Gigabyte P57 to the keyboard reset table

Arnd Bergmann <arnd@arndb.de>
    tty: fix __tty_insert_flip_char regression

Arnd Bergmann <arnd@arndb.de>
    tty: improve tty_insert_flip_char() slow path

Arnd Bergmann <arnd@arndb.de>
    tty: improve tty_insert_flip_char() fast path

Minchan Kim <minchan@kernel.org>
    mm: prevent double decrease of nr_reserved_highatomic

Chuck Lever <chuck.lever@oracle.com>
    nfsd: Fix general protection fault in release_lock_stateid()

Song Liu <songliubraving@fb.com>
    md/raid5: release/flush io in raid5_do_work()

Andy Lutomirski <luto@kernel.org>
    x86/fsgsbase/64: Report FSBASE and GSBASE correctly in core dumps

Jaegeuk Kim <jaegeuk@kernel.org>
    f2fs: check hot_data for roll-forward recovery

Eric Dumazet <edumazet@google.com>
    ipv6: fix typo in fib6_net_exit()

Sabrina Dubroca <sd@queasysnail.net>
    ipv6: fix memory leak with multiple tables during netns destruction

Claudiu Manoil <claudiu.manoil@nxp.com>
    gianfar: Fix Tx flow control deactivation

Jesper Dangaard Brouer <brouer@redhat.com>
    Revert "net: fix percpu memory leaks"

Jesper Dangaard Brouer <brouer@redhat.com>
    Revert "net: use lib/percpu_counter API for fragmentation mem accounting"

Wei Wang <weiwan@google.com>
    tcp: initialize rcv_mss to TCP_MIN_MSS instead of 0

Florian Fainelli <f.fainelli@gmail.com>
    Revert "net: phy: Correctly process PHY_HALTED in phy_stop_machine()"

Arnd Bergmann <arnd@arndb.de>
    qlge: avoid memcpy buffer overflow

Wei Wang <weiwan@google.com>
    ipv6: fix sparse warning on rt6i_node

Wei Wang <weiwan@google.com>
    ipv6: add rcu grace period before freeing fib6_node

Stefano Brivio <sbrivio@redhat.com>
    ipv6: accept 64k - 1 packet length in ip6_find_1stfragopt()


-------------

Diffstat:

 Makefile                                      |   4 +-
 arch/arc/kernel/entry.S                       |   6 +
 arch/arc/mm/tlb.c                             |   3 -
 arch/mips/math-emu/dp_fmax.c                  |  84 +++++++++----
 arch/mips/math-emu/dp_fmin.c                  |  86 +++++++++----
 arch/mips/math-emu/sp_fmax.c                  |  84 +++++++++----
 arch/mips/math-emu/sp_fmin.c                  |  86 +++++++++----
 arch/powerpc/kernel/align.c                   | 119 +++++++++++-------
 arch/x86/include/asm/elf.h                    |   5 +-
 block/blk-core.c                              |   2 +-
 crypto/algif_skcipher.c                       |   4 +-
 drivers/block/skd_main.c                      |  21 ++--
 drivers/input/serio/i8042-x86ia64io.h         |   7 ++
 drivers/md/bcache/bcache.h                    |   1 +
 drivers/md/bcache/request.c                   |   6 +-
 drivers/md/bcache/super.c                     |   7 +-
 drivers/md/bcache/sysfs.c                     |   4 +-
 drivers/md/bcache/util.c                      |  50 +++++---
 drivers/md/bcache/writeback.c                 |  20 +--
 drivers/md/bcache/writeback.h                 |  21 +++-
 drivers/md/bitmap.c                           |   5 +
 drivers/md/raid5.c                            |   2 +
 drivers/media/usb/uvc/uvc_ctrl.c              |   7 ++
 drivers/media/v4l2-core/v4l2-compat-ioctl32.c |   3 +-
 drivers/net/ethernet/freescale/gianfar.c      |   2 +-
 drivers/net/ethernet/qlogic/qlge/qlge_dbg.c   |   2 +-
 drivers/net/phy/phy.c                         |   3 -
 drivers/pci/hotplug/shpchp_hpc.c              |   2 +
 drivers/s390/scsi/zfcp_dbf.c                  |  33 ++++-
 drivers/s390/scsi/zfcp_dbf.h                  |  17 ++-
 drivers/s390/scsi/zfcp_fc.h                   |   6 +-
 drivers/s390/scsi/zfcp_fsf.c                  |   7 +-
 drivers/s390/scsi/zfcp_scsi.c                 |  16 ++-
 drivers/scsi/megaraid/megaraid_sas_base.c     |  13 +-
 drivers/scsi/qla2xxx/qla_attr.c               |   8 +-
 drivers/scsi/sg.c                             | 169 ++++++++++++--------------
 drivers/scsi/storvsc_drv.c                    |   2 +
 drivers/tty/tty_buffer.c                      |  26 ++++
 fs/ext4/super.c                               |  38 ++++--
 fs/f2fs/recovery.c                            |   2 +-
 fs/nfsd/nfs4state.c                           |  10 +-
 include/linux/tty_flip.h                      |   3 +-
 include/net/inet_frag.h                       |  41 ++-----
 include/net/ip6_fib.h                         |  32 ++++-
 kernel/trace/ftrace.c                         |  10 +-
 kernel/trace/trace.c                          |   2 +-
 kernel/trace/trace_selftest.c                 |   2 +-
 mm/page_alloc.c                               |  24 +++-
 net/ieee802154/6lowpan/reassembly.c           |  11 +-
 net/ipv4/inet_fragment.c                      |   4 +-
 net/ipv4/ip_fragment.c                        |  12 +-
 net/ipv4/tcp.c                                |   4 +
 net/ipv6/addrconf.c                           |   2 +-
 net/ipv6/ip6_fib.c                            |  56 ++++++---
 net/ipv6/netfilter/nf_conntrack_reasm.c       |  12 +-
 net/ipv6/output_core.c                        |   6 +-
 net/ipv6/reassembly.c                         |  12 +-
 net/ipv6/route.c                              |  17 ++-
 net/mac80211/offchannel.c                     |   2 +
 59 files changed, 821 insertions(+), 424 deletions(-)

[toc] | [next] | [standalone]


#1738559 — [PATCH 4.4 19/66] tty: fix __tty_insert_flip_char regression

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-09-24 23:40 +0200
Subject[PATCH 4.4 19/66] tty: fix __tty_insert_flip_char regression
Message-ID<utmN3-5vy-1@gated-at.bofh.it>
In reply to#1738558
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnd Bergmann <arnd@arndb.de>

commit 8a5a90a2a477b86a3dc2eaa5a706db9bfdd647ca upstream.

Sergey noticed a small but fatal mistake in __tty_insert_flip_char,
leading to an oops in an interrupt handler when using any serial
port.

The problem is that I accidentally took the tty_buffer pointer
before calling __tty_buffer_request_room(), which replaces the
buffer. This moves the pointer lookup to the right place after
allocating the new buffer space.

Fixes: 979990c62848 ("tty: improve tty_insert_flip_char() fast path")
Reported-by: Sergey Senozhatsky <sergey.senozhatsky@gmail.com>
Tested-by: Sergey Senozhatsky <sergey.senozhatsky@gmail.com>
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/tty/tty_buffer.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/tty/tty_buffer.c
+++ b/drivers/tty/tty_buffer.c
@@ -372,12 +372,13 @@ EXPORT_SYMBOL(tty_insert_flip_string_fla
  */
 int __tty_insert_flip_char(struct tty_port *port, unsigned char ch, char flag)
 {
-	struct tty_buffer *tb = port->buf.tail;
+	struct tty_buffer *tb;
 	int flags = (flag == TTY_NORMAL) ? TTYB_NORMAL : 0;
 
 	if (!__tty_buffer_request_room(port, 1, flags))
 		return 0;
 
+	tb = port->buf.tail;
 	if (~tb->flags & TTYB_NORMAL)
 		*flag_buf_ptr(tb, tb->used) = flag;
 	*char_buf_ptr(tb, tb->used++) = ch;

[toc] | [prev] | [next] | [standalone]


#1738564 — [PATCH 4.4 20/66] Input: i8042 - add Gigabyte P57 to the keyboard reset table

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-09-24 23:40 +0200
Subject[PATCH 4.4 20/66] Input: i8042 - add Gigabyte P57 to the keyboard reset table
Message-ID<utmN4-5vy-15@gated-at.bofh.it>
In reply to#1738558
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kai-Heng Feng <kai.heng.feng@canonical.com>

commit 697c5d8a36768b36729533fb44622b35d56d6ad0 upstream.

Similar to other Gigabyte laptops, the touchpad on P57 requires a
keyboard reset to detect Elantech touchpad correctly.

BugLink: https://bugs.launchpad.net/bugs/1594214
Signed-off-by: Kai-Heng Feng <kai.heng.feng@canonical.com>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/input/serio/i8042-x86ia64io.h |    7 +++++++
 1 file changed, 7 insertions(+)

--- a/drivers/input/serio/i8042-x86ia64io.h
+++ b/drivers/input/serio/i8042-x86ia64io.h
@@ -905,6 +905,13 @@ static const struct dmi_system_id __init
 		},
 	},
 	{
+		/* Gigabyte P57 - Elantech touchpad */
+		.matches = {
+			DMI_MATCH(DMI_SYS_VENDOR, "GIGABYTE"),
+			DMI_MATCH(DMI_PRODUCT_NAME, "P57"),
+		},
+	},
+	{
 		/* Schenker XMG C504 - Elantech touchpad */
 		.matches = {
 			DMI_MATCH(DMI_SYS_VENDOR, "XMG"),

[toc] | [prev] | [next] | [standalone]


#1738565 — [PATCH 4.4 16/66] mm: prevent double decrease of nr_reserved_highatomic

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-09-24 23:40 +0200
Subject[PATCH 4.4 16/66] mm: prevent double decrease of nr_reserved_highatomic
Message-ID<utmN4-5vy-17@gated-at.bofh.it>
In reply to#1738558
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Minchan Kim <minchan@kernel.org>

commit 4855e4a7f29d6d10b0b9c84e189c770c9a94e91e upstream.

There is race between page freeing and unreserved highatomic.

 CPU 0				    CPU 1

    free_hot_cold_page
      mt = get_pfnblock_migratetype
      set_pcppage_migratetype(page, mt)
    				    unreserve_highatomic_pageblock
    				    spin_lock_irqsave(&zone->lock)
    				    move_freepages_block
    				    set_pageblock_migratetype(page)
    				    spin_unlock_irqrestore(&zone->lock)
      free_pcppages_bulk
        __free_one_page(mt) <- mt is stale

By above race, a page on CPU 0 could go non-highorderatomic free list
since the pageblock's type is changed.  By that, unreserve logic of
highorderatomic can decrease reserved count on a same pageblock severak
times and then it will make mismatch between nr_reserved_highatomic and
the number of reserved pageblock.

So, this patch verifies whether the pageblock is highatomic or not and
decrease the count only if the pageblock is highatomic.

Link: http://lkml.kernel.org/r/1476259429-18279-3-git-send-email-minchan@kernel.org
Signed-off-by: Minchan Kim <minchan@kernel.org>
Acked-by: Vlastimil Babka <vbabka@suse.cz>
Acked-by: Mel Gorman <mgorman@techsingularity.net>
Cc: Joonsoo Kim <iamjoonsoo.kim@lge.com>
Cc: Sangseok Lee <sangseok.lee@lge.com>
Cc: Michal Hocko <mhocko@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Miles Chen <miles.chen@mediatek.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 mm/page_alloc.c |   24 ++++++++++++++++++------
 1 file changed, 18 insertions(+), 6 deletions(-)

--- a/mm/page_alloc.c
+++ b/mm/page_alloc.c
@@ -1748,13 +1748,25 @@ static void unreserve_highatomic_pageblo
 						struct page, lru);
 
 			/*
-			 * It should never happen but changes to locking could
-			 * inadvertently allow a per-cpu drain to add pages
-			 * to MIGRATE_HIGHATOMIC while unreserving so be safe
-			 * and watch for underflows.
+			 * In page freeing path, migratetype change is racy so
+			 * we can counter several free pages in a pageblock
+			 * in this loop althoug we changed the pageblock type
+			 * from highatomic to ac->migratetype. So we should
+			 * adjust the count once.
 			 */
-			zone->nr_reserved_highatomic -= min(pageblock_nr_pages,
-				zone->nr_reserved_highatomic);
+			if (get_pageblock_migratetype(page) ==
+							MIGRATE_HIGHATOMIC) {
+				/*
+				 * It should never happen but changes to
+				 * locking could inadvertently allow a per-cpu
+				 * drain to add pages to MIGRATE_HIGHATOMIC
+				 * while unreserving so be safe and watch for
+				 * underflows.
+				 */
+				zone->nr_reserved_highatomic -= min(
+						pageblock_nr_pages,
+						zone->nr_reserved_highatomic);
+			}
 
 			/*
 			 * Convert to ac->migratetype and avoid the normal

[toc] | [prev] | [next] | [standalone]


#1738566 — [PATCH 4.4 17/66] tty: improve tty_insert_flip_char() fast path

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-09-24 23:40 +0200
Subject[PATCH 4.4 17/66] tty: improve tty_insert_flip_char() fast path
Message-ID<utmN4-5vy-21@gated-at.bofh.it>
In reply to#1738558
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnd Bergmann <arnd@arndb.de>

commit 979990c6284814617d8f2179d197f72ff62b5d85 upstream.

kernelci.org reports a crazy stack usage for the VT code when CONFIG_KASAN
is enabled:

drivers/tty/vt/keyboard.c: In function 'kbd_keycode':
drivers/tty/vt/keyboard.c:1452:1: error: the frame size of 2240 bytes is larger than 2048 bytes [-Werror=frame-larger-than=]

The problem is that tty_insert_flip_char() gets inlined many times into
kbd_keycode(), and also into other functions, and each copy requires 128
bytes for stack redzone to check for a possible out-of-bounds access on
the 'ch' and 'flags' arguments that are passed into
tty_insert_flip_string_flags as a variable-length string.

This introduces a new __tty_insert_flip_char() function for the slow
path, which receives the two arguments by value. This completely avoids
the problem and the stack usage goes back down to around 100 bytes.

Without KASAN, this is also slightly better, as we don't have to
spill the arguments to the stack but can simply pass 'ch' and 'flag'
in registers, saving a few bytes in .text for each call site.

This should be backported to linux-4.0 or later, which first introduced
the stack sanitizer in the kernel.

Fixes: c420f167db8c ("kasan: enable stack instrumentation")
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/tty/tty_buffer.c |   24 ++++++++++++++++++++++++
 include/linux/tty_flip.h |    3 ++-
 2 files changed, 26 insertions(+), 1 deletion(-)

--- a/drivers/tty/tty_buffer.c
+++ b/drivers/tty/tty_buffer.c
@@ -362,6 +362,30 @@ int tty_insert_flip_string_flags(struct
 EXPORT_SYMBOL(tty_insert_flip_string_flags);
 
 /**
+ *	__tty_insert_flip_char   -	Add one character to the tty buffer
+ *	@port: tty port
+ *	@ch: character
+ *	@flag: flag byte
+ *
+ *	Queue a single byte to the tty buffering, with an optional flag.
+ *	This is the slow path of tty_insert_flip_char.
+ */
+int __tty_insert_flip_char(struct tty_port *port, unsigned char ch, char flag)
+{
+	struct tty_buffer *tb = port->buf.tail;
+	int flags = (flag == TTY_NORMAL) ? TTYB_NORMAL : 0;
+
+	if (!tty_buffer_request_room(port, 1))
+		return 0;
+
+	*flag_buf_ptr(tb, tb->used) = flag;
+	*char_buf_ptr(tb, tb->used++) = ch;
+
+	return 1;
+}
+EXPORT_SYMBOL(__tty_insert_flip_char);
+
+/**
  *	tty_schedule_flip	-	push characters to ldisc
  *	@port: tty port to push from
  *
--- a/include/linux/tty_flip.h
+++ b/include/linux/tty_flip.h
@@ -12,6 +12,7 @@ extern int tty_prepare_flip_string(struc
 		unsigned char **chars, size_t size);
 extern void tty_flip_buffer_push(struct tty_port *port);
 void tty_schedule_flip(struct tty_port *port);
+int __tty_insert_flip_char(struct tty_port *port, unsigned char ch, char flag);
 
 static inline int tty_insert_flip_char(struct tty_port *port,
 					unsigned char ch, char flag)
@@ -26,7 +27,7 @@ static inline int tty_insert_flip_char(s
 		*char_buf_ptr(tb, tb->used++) = ch;
 		return 1;
 	}
-	return tty_insert_flip_string_flags(port, &ch, &flag, 1);
+	return __tty_insert_flip_char(port, ch, flag);
 }
 
 static inline int tty_insert_flip_string(struct tty_port *port,

[toc] | [prev] | [next] | [standalone]


#1738571 — [PATCH 4.4 02/66] ipv6: add rcu grace period before freeing fib6_node

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-09-24 23:40 +0200
Subject[PATCH 4.4 02/66] ipv6: add rcu grace period before freeing fib6_node
Message-ID<utmN5-5vy-27@gated-at.bofh.it>
In reply to#1738558
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wei Wang <weiwan@google.com>


[ Upstream commit c5cff8561d2d0006e972bd114afd51f082fee77c ]

We currently keep rt->rt6i_node pointing to the fib6_node for the route.
And some functions make use of this pointer to dereference the fib6_node
from rt structure, e.g. rt6_check(). However, as there is neither
refcount nor rcu taken when dereferencing rt->rt6i_node, it could
potentially cause crashes as rt->rt6i_node could be set to NULL by other
CPUs when doing a route deletion.
This patch introduces an rcu grace period before freeing fib6_node and
makes sure the functions that dereference it takes rcu_read_lock().

Note: there is no "Fixes" tag because this bug was there in a very
early stage.

Signed-off-by: Wei Wang <weiwan@google.com>
Acked-by: Eric Dumazet <edumazet@google.com>
Acked-by: Martin KaFai Lau <kafai@fb.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 include/net/ip6_fib.h |   30 +++++++++++++++++++++++++++++-
 net/ipv6/ip6_fib.c    |   20 ++++++++++++++++----
 net/ipv6/route.c      |   14 +++++++++++---
 3 files changed, 56 insertions(+), 8 deletions(-)

--- a/include/net/ip6_fib.h
+++ b/include/net/ip6_fib.h
@@ -68,6 +68,7 @@ struct fib6_node {
 	__u16			fn_flags;
 	int			fn_sernum;
 	struct rt6_info		*rr_ptr;
+	struct rcu_head		rcu;
 };
 
 #ifndef CONFIG_IPV6_SUBTREES
@@ -165,13 +166,40 @@ static inline void rt6_update_expires(st
 	rt0->rt6i_flags |= RTF_EXPIRES;
 }
 
+/* Function to safely get fn->sernum for passed in rt
+ * and store result in passed in cookie.
+ * Return true if we can get cookie safely
+ * Return false if not
+ */
+static inline bool rt6_get_cookie_safe(const struct rt6_info *rt,
+				       u32 *cookie)
+{
+	struct fib6_node *fn;
+	bool status = false;
+
+	rcu_read_lock();
+	fn = rcu_dereference(rt->rt6i_node);
+
+	if (fn) {
+		*cookie = fn->fn_sernum;
+		status = true;
+	}
+
+	rcu_read_unlock();
+	return status;
+}
+
 static inline u32 rt6_get_cookie(const struct rt6_info *rt)
 {
+	u32 cookie = 0;
+
 	if (rt->rt6i_flags & RTF_PCPU ||
 	    (unlikely(rt->dst.flags & DST_NOCACHE) && rt->dst.from))
 		rt = (struct rt6_info *)(rt->dst.from);
 
-	return rt->rt6i_node ? rt->rt6i_node->fn_sernum : 0;
+	rt6_get_cookie_safe(rt, &cookie);
+
+	return cookie;
 }
 
 static inline void ip6_rt_put(struct rt6_info *rt)
--- a/net/ipv6/ip6_fib.c
+++ b/net/ipv6/ip6_fib.c
@@ -150,11 +150,23 @@ static struct fib6_node *node_alloc(void
 	return fn;
 }
 
-static void node_free(struct fib6_node *fn)
+static void node_free_immediate(struct fib6_node *fn)
+{
+	kmem_cache_free(fib6_node_kmem, fn);
+}
+
+static void node_free_rcu(struct rcu_head *head)
 {
+	struct fib6_node *fn = container_of(head, struct fib6_node, rcu);
+
 	kmem_cache_free(fib6_node_kmem, fn);
 }
 
+static void node_free(struct fib6_node *fn)
+{
+	call_rcu(&fn->rcu, node_free_rcu);
+}
+
 static void rt6_rcu_free(struct rt6_info *rt)
 {
 	call_rcu(&rt->dst.rcu_head, dst_rcu_free);
@@ -588,9 +600,9 @@ insert_above:
 
 		if (!in || !ln) {
 			if (in)
-				node_free(in);
+				node_free_immediate(in);
 			if (ln)
-				node_free(ln);
+				node_free_immediate(ln);
 			return ERR_PTR(-ENOMEM);
 		}
 
@@ -1015,7 +1027,7 @@ int fib6_add(struct fib6_node *root, str
 				   root, and then (in failure) stale node
 				   in main tree.
 				 */
-				node_free(sfn);
+				node_free_immediate(sfn);
 				err = PTR_ERR(sn);
 				goto failure;
 			}
--- a/net/ipv6/route.c
+++ b/net/ipv6/route.c
@@ -1248,7 +1248,9 @@ static void rt6_dst_from_metrics_check(s
 
 static struct dst_entry *rt6_check(struct rt6_info *rt, u32 cookie)
 {
-	if (!rt->rt6i_node || (rt->rt6i_node->fn_sernum != cookie))
+	u32 rt_cookie;
+
+	if (!rt6_get_cookie_safe(rt, &rt_cookie) || rt_cookie != cookie)
 		return NULL;
 
 	if (rt6_check_expired(rt))
@@ -1316,8 +1318,14 @@ static void ip6_link_failure(struct sk_b
 		if (rt->rt6i_flags & RTF_CACHE) {
 			dst_hold(&rt->dst);
 			ip6_del_rt(rt);
-		} else if (rt->rt6i_node && (rt->rt6i_flags & RTF_DEFAULT)) {
-			rt->rt6i_node->fn_sernum = -1;
+		} else {
+			struct fib6_node *fn;
+
+			rcu_read_lock();
+			fn = rcu_dereference(rt->rt6i_node);
+			if (fn && (rt->rt6i_flags & RTF_DEFAULT))
+				fn->fn_sernum = -1;
+			rcu_read_unlock();
 		}
 	}
 }

[toc] | [prev] | [next] | [standalone]


#1738572 — [PATCH 4.4 14/66] md/raid5: release/flush io in raid5_do_work()

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-09-24 23:40 +0200
Subject[PATCH 4.4 14/66] md/raid5: release/flush io in raid5_do_work()
Message-ID<utmN5-5vy-35@gated-at.bofh.it>
In reply to#1738558
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Song Liu <songliubraving@fb.com>

commit 9c72a18e46ebe0f09484cce8ebf847abdab58498 upstream.

In raid5, there are scenarios where some ios are deferred to a later
time, and some IO need a flush to complete. To make sure we make
progress with these IOs, we need to call the following functions:

    flush_deferred_bios(conf);
    r5l_flush_stripe_to_raid(conf->log);

Both of these functions are called in raid5d(), but missing in
raid5_do_work(). As a result, these functions are not called
when multi-threading (group_thread_cnt > 0) is enabled. This patch
adds calls to these function to raid5_do_work().

Note for stable branches:

  r5l_flush_stripe_to_raid(conf->log) is need for 4.4+
  flush_deferred_bios(conf) is only needed for 4.11+

Signed-off-by: Song Liu <songliubraving@fb.com>
Signed-off-by: Shaohua Li <shli@fb.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/md/raid5.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/md/raid5.c
+++ b/drivers/md/raid5.c
@@ -5822,6 +5822,8 @@ static void raid5_do_work(struct work_st
 
 	spin_unlock_irq(&conf->device_lock);
 
+	r5l_flush_stripe_to_raid(conf->log);
+
 	async_tx_issue_pending_all();
 	blk_finish_plug(&plug);
 

[toc] | [prev] | [next] | [standalone]


#1738615

FromGuenter Roeck <linux@roeck-us.net>
Date2017-09-25 03:10 +0200
Message-ID<utq4h-7BV-5@gated-at.bofh.it>
In reply to#1738558
On 09/24/2017 01:30 PM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 4.4.89 release.
> There are 66 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Tue Sep 26 20:29:06 UTC 2017.
> Anything received after that time might be too late.
> 

Build results:
	total: 145 pass: 145 fail: 0
Qemu test results:
	total: 116 pass: 116 fail: 0

Details are available at http://kerneltests.org/builders.

Guenter

[toc] | [prev] | [next] | [standalone]


#1739336

FromShuah Khan <shuahkh@osg.samsung.com>
Date2017-09-26 01:20 +0200
Message-ID<utKPp-4Lc-17@gated-at.bofh.it>
In reply to#1738558
On 09/24/2017 02:30 PM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 4.4.89 release.
> There are 66 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Tue Sep 26 20:29:06 UTC 2017.
> Anything received after that time might be too late.
> 
> The whole patch series can be found in one patch at:
> 	kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.4.89-rc1.gz
> or in the git tree and branch at:
>   git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-4.4.y
> and the diffstat can be found below.
> 
> thanks,
> 
> greg k-h
> 

Compiled and booted on my test system. No dmesg regressions.

thanks,
-- Shuah

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web