mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Luis Henriques <luis.henriques@canonical.com>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org,
	kernel-team@lists.ubuntu.com
Cc: Tejun Heo <tj@kernel.org>, Jens Axboe <axboe@fb.com>,
	Luis Henriques <luis.henriques@canonical.com>
Subject: [PATCH 3.11 024/128] blkcg: fix use-after-free in __blkg_release_rcu() by making blkcg_gq refcnt an atomic_t
Date: Thu, 24 Jul 2014 10:44:33 +0100	[thread overview]
Message-ID: <1406195177-8656-25-git-send-email-luis.henriques@canonical.com> (raw)
In-Reply-To: <1406195177-8656-1-git-send-email-luis.henriques@canonical.com>

3.11.10.14 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tejun Heo <tj@kernel.org>

commit a5049a8ae34950249a7ae94c385d7c5c98914412 upstream.

Hello,

So, this patch should do.  Joe, Vivek, can one of you guys please
verify that the oops goes away with this patch?

Jens, the original thread can be read at

  http://thread.gmane.org/gmane.linux.kernel/1720729

The fix converts blkg->refcnt from int to atomic_t.  It does some
overhead but it should be minute compared to everything else which is
going on and the involved cacheline bouncing, so I think it's highly
unlikely to cause any noticeable difference.  Also, the refcnt in
question should be converted to a perpcu_ref for blk-mq anyway, so the
atomic_t is likely to go away pretty soon anyway.

Thanks.

------- 8< -------
__blkg_release_rcu() may be invoked after the associated request_queue
is released with a RCU grace period inbetween.  As such, the function
and callbacks invoked from it must not dereference the associated
request_queue.  This is clearly indicated in the comment above the
function.

Unfortunately, while trying to fix a different issue, 2a4fd070ee85
("blkcg: move bulk of blkcg_gq release operations to the RCU
callback") ignored this and added [un]locking of @blkg->q->queue_lock
to __blkg_release_rcu().  This of course can cause oops as the
request_queue may be long gone by the time this code gets executed.

  general protection fault: 0000 [#1] SMP
  CPU: 21 PID: 30 Comm: rcuos/21 Not tainted 3.15.0 #1
  Hardware name: Stratus ftServer 6400/G7LAZ, BIOS BIOS Version 6.3:57 12/25/2013
  task: ffff880854021de0 ti: ffff88085403c000 task.ti: ffff88085403c000
  RIP: 0010:[<ffffffff8162e9e5>]  [<ffffffff8162e9e5>] _raw_spin_lock_irq+0x15/0x60
  RSP: 0018:ffff88085403fdf0  EFLAGS: 00010086
  RAX: 0000000000020000 RBX: 0000000000000010 RCX: 0000000000000000
  RDX: 000060ef80008248 RSI: 0000000000000286 RDI: 6b6b6b6b6b6b6b6b
  RBP: ffff88085403fdf0 R08: 0000000000000286 R09: 0000000000009f39
  R10: 0000000000020001 R11: 0000000000020001 R12: ffff88103c17a130
  R13: ffff88103c17a080 R14: 0000000000000000 R15: 0000000000000000
  FS:  0000000000000000(0000) GS:ffff88107fca0000(0000) knlGS:0000000000000000
  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
  CR2: 00000000006e5ab8 CR3: 000000000193d000 CR4: 00000000000407e0
  Stack:
   ffff88085403fe18 ffffffff812cbfc2 ffff88103c17a130 0000000000000000
   ffff88103c17a130 ffff88085403fec0 ffffffff810d1d28 ffff880854021de0
   ffff880854021de0 ffff88107fcaec58 ffff88085403fe80 ffff88107fcaec30
  Call Trace:
   [<ffffffff812cbfc2>] __blkg_release_rcu+0x72/0x150
   [<ffffffff810d1d28>] rcu_nocb_kthread+0x1e8/0x300
   [<ffffffff81091d81>] kthread+0xe1/0x100
   [<ffffffff8163813c>] ret_from_fork+0x7c/0xb0
  Code: ff 47 04 48 8b 7d 08 be 00 02 00 00 e8 55 48 a4 ff 5d c3 0f 1f 00 66 66 66 66 90 55 48 89 e5
  +fa 66 66 90 66 66 90 b8 00 00 02 00 <f0> 0f c1 07 89 c2 c1 ea 10 66 39 c2 75 02 5d c3 83 e2 fe 0f
  +b7
  RIP  [<ffffffff8162e9e5>] _raw_spin_lock_irq+0x15/0x60
   RSP <ffff88085403fdf0>

The request_queue locking was added because blkcg_gq->refcnt is an int
protected with the queue lock and __blkg_release_rcu() needs to put
the parent.  Let's fix it by making blkcg_gq->refcnt an atomic_t and
dropping queue locking in the function.

Given the general heavy weight of the current request_queue and blkcg
operations, this is unlikely to cause any noticeable overhead.
Moreover, blkcg_gq->refcnt is likely to be converted to percpu_ref in
the near future, so whatever (most likely negligible) overhead it may
add is temporary.

Signed-off-by: Tejun Heo <tj@kernel.org>
Reported-by: Joe Lawrence <joe.lawrence@stratus.com>
Acked-by: Vivek Goyal <vgoyal@redhat.com>
Link: http://lkml.kernel.org/g/alpine.DEB.2.02.1406081816540.17948@jlaw-desktop.mno.stratus.com
Signed-off-by: Jens Axboe <axboe@fb.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 block/blk-cgroup.c |  7 ++-----
 block/blk-cgroup.h | 17 +++++++----------
 2 files changed, 9 insertions(+), 15 deletions(-)

diff --git a/block/blk-cgroup.c b/block/blk-cgroup.c
index 290792a13e3c..354efcdad847 100644
--- a/block/blk-cgroup.c
+++ b/block/blk-cgroup.c
@@ -80,7 +80,7 @@ static struct blkcg_gq *blkg_alloc(struct blkcg *blkcg, struct request_queue *q,
 	blkg->q = q;
 	INIT_LIST_HEAD(&blkg->q_node);
 	blkg->blkcg = blkcg;
-	blkg->refcnt = 1;
+	atomic_set(&blkg->refcnt, 1);
 
 	/* root blkg uses @q->root_rl, init rl only for !root blkgs */
 	if (blkcg != &blkcg_root) {
@@ -392,11 +392,8 @@ void __blkg_release_rcu(struct rcu_head *rcu_head)
 
 	/* release the blkcg and parent blkg refs this blkg has been holding */
 	css_put(&blkg->blkcg->css);
-	if (blkg->parent) {
-		spin_lock_irq(blkg->q->queue_lock);
+	if (blkg->parent)
 		blkg_put(blkg->parent);
-		spin_unlock_irq(blkg->q->queue_lock);
-	}
 
 	blkg_free(blkg);
 }
diff --git a/block/blk-cgroup.h b/block/blk-cgroup.h
index f50082d1e155..c20deb138239 100644
--- a/block/blk-cgroup.h
+++ b/block/blk-cgroup.h
@@ -18,6 +18,7 @@
 #include <linux/seq_file.h>
 #include <linux/radix-tree.h>
 #include <linux/blkdev.h>
+#include <linux/atomic.h>
 
 /* Max limits for throttle policy */
 #define THROTL_IOPS_MAX		UINT_MAX
@@ -104,7 +105,7 @@ struct blkcg_gq {
 	struct request_list		rl;
 
 	/* reference count */
-	int				refcnt;
+	atomic_t			refcnt;
 
 	/* is this blkg online? protected by both blkcg and q locks */
 	bool				online;
@@ -257,13 +258,12 @@ static inline int blkg_path(struct blkcg_gq *blkg, char *buf, int buflen)
  * blkg_get - get a blkg reference
  * @blkg: blkg to get
  *
- * The caller should be holding queue_lock and an existing reference.
+ * The caller should be holding an existing reference.
  */
 static inline void blkg_get(struct blkcg_gq *blkg)
 {
-	lockdep_assert_held(blkg->q->queue_lock);
-	WARN_ON_ONCE(!blkg->refcnt);
-	blkg->refcnt++;
+	WARN_ON_ONCE(atomic_read(&blkg->refcnt) <= 0);
+	atomic_inc(&blkg->refcnt);
 }
 
 void __blkg_release_rcu(struct rcu_head *rcu);
@@ -271,14 +271,11 @@ void __blkg_release_rcu(struct rcu_head *rcu);
 /**
  * blkg_put - put a blkg reference
  * @blkg: blkg to put
- *
- * The caller should be holding queue_lock.
  */
 static inline void blkg_put(struct blkcg_gq *blkg)
 {
-	lockdep_assert_held(blkg->q->queue_lock);
-	WARN_ON_ONCE(blkg->refcnt <= 0);
-	if (!--blkg->refcnt)
+	WARN_ON_ONCE(atomic_read(&blkg->refcnt) <= 0);
+	if (atomic_dec_and_test(&blkg->refcnt))
 		call_rcu(&blkg->rcu_head, __blkg_release_rcu);
 }
 
-- 
1.9.1


  parent reply	other threads:[~2014-07-24 10:23 UTC|newest]

Thread overview: 132+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-07-24  9:44 [3.11.y.z extended stable] Linux 3.11.10.14 stable review Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 001/128] sym53c8xx_2: Set DID_REQUEUE return code when aborting squeue Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 002/128] MIPS: KVM: Remove redundant NULL checks before kfree() Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 003/128] MIPS: KVM: Fix memory leak on VCPU Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 004/128] btrfs: Add ctime/mtime update for btrfs device add/remove Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 005/128] Btrfs: output warning instead of error when loading free space cache failed Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 006/128] Btrfs: make sure there are not any read requests before stopping workers Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 007/128] Btrfs: fix NULL pointer crash of deleting a seed device Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 008/128] Btrfs: mark mapping with error flag to report errors to userspace Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 009/128] Btrfs: set right total device count for seeding support Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 010/128] Btrfs: send, don't error in the presence of subvols/snapshots Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 011/128] fs: btrfs: volumes.c: Fix for possible null pointer dereference Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 012/128] Btrfs: use right type to get real comparison Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 013/128] Btrfs: fix scrub_print_warning to handle skinny metadata extents Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 014/128] btrfs: fix use of uninit "ret" in end_extent_writepage() Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 015/128] Bluetooth: Fix check for connection encryption Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 016/128] Bluetooth: Fix SSP acceptor just-works confirmation without MITM Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 017/128] Bluetooth: Fix indicating discovery state when canceling inquiry Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 018/128] Bluetooth: Fix locking of hdev when calling into SMP code Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 019/128] Bluetooth: Allow change security level on ATT_CID in slave role Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 020/128] rt2x00: disable TKIP on USB Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 021/128] b43: fix frequency reported on G-PHY with /new/ firmware Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 022/128] rt2x00: fix rfkill regression on rt2500pci Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 023/128] tracing: Fix syscall_*regfunc() vs copy_process() race Luis Henriques
2014-07-24  9:44 ` Luis Henriques [this message]
2014-07-24  9:44 ` [PATCH 3.11 025/128] rbd: handle parent_overlap on writes correctly Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 026/128] lz4: ensure length does not wrap Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 027/128] mm, pcp: allow restoring percpu_pagelist_fraction default Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 028/128] mm: fix crashes from mbind() merging vmas Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 029/128] [CIFS] fix mount failure with broken pathnames when smb3 mount with mapchars option Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 030/128] drm: fix NULL pointer access by wrong ioctl Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 031/128] net: allwinner: emac: Add missing free_irq Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 032/128] ALSA: usb-audio: Fix races at disconnection and PCM closing Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 033/128] recordmcount/MIPS: Fix possible incorrect mcount_loc table entries in modules Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 034/128] MIPS: MSC: Prevent out-of-bounds writes to MIPS SC ioremap'd region Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 035/128] target: Fix left-over se_lun->lun_sep pointer OOPs Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 036/128] iscsi-target: Explicily clear login response PDU in exception path Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 037/128] efi-pstore: Fix an overflow on 32-bit builds Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 038/128] lz4: fix another possible overrun Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 039/128] iscsi-target: Avoid rejecting incorrect ITT for Data-Out Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 040/128] powerpc: fix typo 'CONFIG_PPC_CPU' Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 041/128] powerpc: fix typo 'CONFIG_PMAC' Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 042/128] PCI: Fix incorrect vgaarb conditional in WARN_ON() Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 043/128] ptrace,x86: force IRET path after a ptrace_stop() Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 044/128] mei: me: fix hw ready reset flow Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 045/128] tracing: Try again for saved cmdline if failed due to locking Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 046/128] ring-buffer: Check if buffer exists before polling Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 047/128] Score: Implement the function csum_ipv6_magic Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 048/128] Score: The commit is for compiling successfully Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 049/128] Score: Modify the Makefile of Score, remove -mlong-calls for compiling Luis Henriques
2014-07-24  9:44 ` [PATCH 3.11 050/128] ext4: Fix buffer double free in ext4_alloc_branch() Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 051/128] ARM: OMAP2+: Fix parser-bug in platform muxing code Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 052/128] KVM: x86: Increase the number of fixed MTRR regs to 10 Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 053/128] KVM: x86: preserve the high 32-bits of the PAT register Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 054/128] usb: musb: ux500: don't propagate the OF node Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 055/128] usb: gadget: f_fs: fix NULL pointer dereference when there are no strings Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 056/128] iio: of_iio_channel_get_by_name() returns non-null pointers for error legs Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 057/128] irqchip: spear_shirq: Fix interrupt offset Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 058/128] USB: option: add device ID for SpeedUp SU9800 usb 3g modem Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 059/128] USB: ftdi_sio: fix null deref at port probe Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 060/128] usb: option: add/modify Olivetti Olicard modems Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 061/128] xhci: correct burst count field for isoc transfers on 1.0 xhci hosts Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 062/128] xhci: clear root port wake on bits if controller isn't wake-up capable Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 063/128] xhci: Fix runtime suspended xhci from blocking system suspend Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 064/128] ibmvscsi: Abort init sequence during error recovery Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 065/128] ibmvscsi: Add memory barriers for send / receive Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 066/128] virtio-scsi: avoid cancelling uninitialized work items Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 067/128] virtio-scsi: fix various bad behavior on aborted requests Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 068/128] ext4: Fix hole punching for files with indirect blocks Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 069/128] nfsd: fix rare symlink decoding bug Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 070/128] tools: ffs-test: fix header values endianess Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 071/128] drm/radeon/dpm: fix typo in vddci setup for eg/btc Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 072/128] drm/radeon/dpm: fix vddci setup typo on cayman Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 073/128] tracing: Remove ftrace_stop/start() from reading the trace file Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 074/128] usb: chipidea: udc: delete td from req's td list at ep_dequeue Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 075/128] drm/radeon/cik: fix typo in EOP packet Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 076/128] md: flush writes before starting a recovery Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 077/128] drm/vmwgfx: Fix incorrect write to read-only register v2: Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 078/128] mm: page_alloc: fix CMA area initialisation when pageblock > MAX_ORDER Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 079/128] /proc/stat: convert to single_open_size() Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 080/128] lz4: add overrun checks to lz4_uncompress_unknownoutputsize() Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 081/128] arm64: mm: Make icache synchronisation logic huge page aware Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 082/128] rtmutex: Detect changes in the pi lock chain Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 083/128] rtmutex: Plug slow unlock race Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 084/128] ARC: Implement ptrace(PTRACE_GET_THREAD_AREA) Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 085/128] mac80211: fix IBSS join by initializing last_scan_completed Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 086/128] [SCSI] Fix spurious request sense in error handling Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 087/128] ipvs: stop tot_stats estimator only under CONFIG_SYSCTL Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 088/128] netfilter: nf_nat: fix oops on netns removal Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 089/128] workqueue: fix dev_set_uevent_suppress() imbalance Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 090/128] cpuset,mempolicy: fix sleeping function called from invalid context Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 091/128] crypto: sha512_ssse3 - fix byte count to bit count conversion Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 092/128] thermal: hwmon: Make the check for critical temp valid consistent Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 093/128] hwmon: (amc6821) Fix permissions for temp2_input Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 094/128] hwmon: (adm1029) Ensure the fan_div cache is updated in set_fan_div Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 095/128] hwmon: (adm1021) Fix cache problem when writing temperature limits Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 096/128] ext4: fix unjournalled bg descriptor while initializing inode bitmap Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 097/128] ext4: clarify error count warning messages Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 098/128] ext4: disable synchronous transaction batching if max_batch_time==0 Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 099/128] intel_pstate: Set CPU number before accessing MSRs Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 100/128] USB: cp210x: add support for Corsair usb dongle Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 101/128] usb: option: Add ID for Telewell TW-LTE 4G v2 Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 102/128] ACPI / EC: Avoid race condition related to advance_transaction() Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 103/128] ACPI / EC: Add asynchronous command byte write support Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 104/128] ACPI / EC: Remove duplicated ec_wait_ibf0() waiter Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 105/128] ACPI / EC: Fix race condition in ec_transaction_completed() Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 106/128] ACPI / battery: Retry to get battery information if failed during probing Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 107/128] hwmon: (adm1031) Fix writes to limit registers Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 108/128] workqueue: zero cpumask of wq_numa_possible_cpumask on init Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 109/128] hwmon: (emc2103) Fix return value Luis Henriques
2014-07-24  9:45 ` [PATCH 3.11 110/128] hwmon: (emc2103) Clamp limits instead of bailing out Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 111/128] arm64: implement TASK_SIZE_OF Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 112/128] iio: ti_am335x_adc: Fix: Use same step id at FIFOs both ends Luis Henriques
2014-07-25 11:13   ` [PATCH] iio: ti_am335x_adc: Fix prerequisite for stepid patch Jan Kardell
2014-07-28 10:05     ` Luis Henriques
2014-08-08  8:24       ` Jonathan Cameron
2014-07-24  9:46 ` [PATCH 3.11 113/128] cpufreq: Makefile: fix compilation for davinci platform Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 114/128] Drivers: hv: vmbus: Fix a bug in the channel callback dispatch code Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 115/128] USB: ftdi_sio: Add extra PID Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 116/128] dm io: fix a race condition in the wake up code for sync_io Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 117/128] drm/radeon: fix typo in golden register setup on evergreen Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 118/128] drm/radeon/dpm: Reenabling SS on Cayman Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 119/128] powerpc/perf: Add PPMU_ARCH_207S define Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 120/128] powerpc/perf: Clear MMCR2 when enabling PMU Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 121/128] powerpc/perf: Never program book3s PMCs with values >= 0x80000000 Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 122/128] USB: serial: ftdi_sio: Add Infineon Triboard Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 123/128] clk: spear3xx: Use proper control register offset Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 124/128] x86, ioremap: Speed up check for RAM pages Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 125/128] rbd: use reference counts for image requests Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 126/128] Don't trigger congestion wait on dirty-but-not-writeout pages Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 127/128] hugetlb: fix copy_hugetlb_page_range() to handle migration/hwpoisoned entry Luis Henriques
2014-07-24  9:46 ` [PATCH 3.11 128/128] mm: hugetlb: fix copy_hugetlb_page_range() Luis Henriques

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1406195177-8656-25-git-send-email-luis.henriques@canonical.com \
    --to=luis.henriques@canonical.com \
    --cc=axboe@fb.com \
    --cc=kernel-team@lists.ubuntu.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=tj@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®