mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Luis Henriques <luis.henriques@canonical.com>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org,
	kernel-team@lists.ubuntu.com
Cc: Daniel Borkmann <dborkman@redhat.com>,
	Vlad Yasevich <vyasevich@gmail.com>,
	"David S. Miller" <davem@davemloft.net>,
	Luis Henriques <luis.henriques@canonical.com>
Subject: [PATCH 3.16.y-ckt 086/170] net: sctp: fix skb_over_panic when receiving malformed ASCONF chunks
Date: Tue, 11 Nov 2014 11:07:25 +0000	[thread overview]
Message-ID: <1415704129-12709-87-git-send-email-luis.henriques@canonical.com> (raw)
In-Reply-To: <1415704129-12709-1-git-send-email-luis.henriques@canonical.com>

3.16.7-ckt1 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <dborkman@redhat.com>

commit 9de7922bc709eee2f609cd01d98aaedc4cf5ea74 upstream.

Commit 6f4c618ddb0 ("SCTP : Add paramters validity check for
ASCONF chunk") added basic verification of ASCONF chunks, however,
it is still possible to remotely crash a server by sending a
special crafted ASCONF chunk, even up to pre 2.6.12 kernels:

skb_over_panic: text:ffffffffa01ea1c3 len:31056 put:30768
 head:ffff88011bd81800 data:ffff88011bd81800 tail:0x7950
 end:0x440 dev:<NULL>
 ------------[ cut here ]------------
kernel BUG at net/core/skbuff.c:129!
[...]
Call Trace:
 <IRQ>
 [<ffffffff8144fb1c>] skb_put+0x5c/0x70
 [<ffffffffa01ea1c3>] sctp_addto_chunk+0x63/0xd0 [sctp]
 [<ffffffffa01eadaf>] sctp_process_asconf+0x1af/0x540 [sctp]
 [<ffffffff8152d025>] ? _read_unlock_bh+0x15/0x20
 [<ffffffffa01e0038>] sctp_sf_do_asconf+0x168/0x240 [sctp]
 [<ffffffffa01e3751>] sctp_do_sm+0x71/0x1210 [sctp]
 [<ffffffff8147645d>] ? fib_rules_lookup+0xad/0xf0
 [<ffffffffa01e6b22>] ? sctp_cmp_addr_exact+0x32/0x40 [sctp]
 [<ffffffffa01e8393>] sctp_assoc_bh_rcv+0xd3/0x180 [sctp]
 [<ffffffffa01ee986>] sctp_inq_push+0x56/0x80 [sctp]
 [<ffffffffa01fcc42>] sctp_rcv+0x982/0xa10 [sctp]
 [<ffffffffa01d5123>] ? ipt_local_in_hook+0x23/0x28 [iptable_filter]
 [<ffffffff8148bdc9>] ? nf_iterate+0x69/0xb0
 [<ffffffff81496d10>] ? ip_local_deliver_finish+0x0/0x2d0
 [<ffffffff8148bf86>] ? nf_hook_slow+0x76/0x120
 [<ffffffff81496d10>] ? ip_local_deliver_finish+0x0/0x2d0
 [<ffffffff81496ded>] ip_local_deliver_finish+0xdd/0x2d0
 [<ffffffff81497078>] ip_local_deliver+0x98/0xa0
 [<ffffffff8149653d>] ip_rcv_finish+0x12d/0x440
 [<ffffffff81496ac5>] ip_rcv+0x275/0x350
 [<ffffffff8145c88b>] __netif_receive_skb+0x4ab/0x750
 [<ffffffff81460588>] netif_receive_skb+0x58/0x60

This can be triggered e.g., through a simple scripted nmap
connection scan injecting the chunk after the handshake, for
example, ...

  -------------- INIT[ASCONF; ASCONF_ACK] ------------->
  <----------- INIT-ACK[ASCONF; ASCONF_ACK] ------------
  -------------------- COOKIE-ECHO -------------------->
  <-------------------- COOKIE-ACK ---------------------
  ------------------ ASCONF; UNKNOWN ------------------>

... where ASCONF chunk of length 280 contains 2 parameters ...

  1) Add IP address parameter (param length: 16)
  2) Add/del IP address parameter (param length: 255)

... followed by an UNKNOWN chunk of e.g. 4 bytes. Here, the
Address Parameter in the ASCONF chunk is even missing, too.
This is just an example and similarly-crafted ASCONF chunks
could be used just as well.

The ASCONF chunk passes through sctp_verify_asconf() as all
parameters passed sanity checks, and after walking, we ended
up successfully at the chunk end boundary, and thus may invoke
sctp_process_asconf(). Parameter walking is done with
WORD_ROUND() to take padding into account.

In sctp_process_asconf()'s TLV processing, we may fail in
sctp_process_asconf_param() e.g., due to removal of the IP
address that is also the source address of the packet containing
the ASCONF chunk, and thus we need to add all TLVs after the
failure to our ASCONF response to remote via helper function
sctp_add_asconf_response(), which basically invokes a
sctp_addto_chunk() adding the error parameters to the given
skb.

When walking to the next parameter this time, we proceed
with ...

  length = ntohs(asconf_param->param_hdr.length);
  asconf_param = (void *)asconf_param + length;

... instead of the WORD_ROUND()'ed length, thus resulting here
in an off-by-one that leads to reading the follow-up garbage
parameter length of 12336, and thus throwing an skb_over_panic
for the reply when trying to sctp_addto_chunk() next time,
which implicitly calls the skb_put() with that length.

Fix it by using sctp_walk_params() [ which is also used in
INIT parameter processing ] macro in the verification *and*
in ASCONF processing: it will make sure we don't spill over,
that we walk parameters WORD_ROUND()'ed. Moreover, we're being
more defensive and guard against unknown parameter types and
missized addresses.

Joint work with Vlad Yasevich.

Fixes: b896b82be4ae ("[SCTP] ADDIP: Support for processing incoming ASCONF_ACK chunks.")
Signed-off-by: Daniel Borkmann <dborkman@redhat.com>
Signed-off-by: Vlad Yasevich <vyasevich@gmail.com>
Acked-by: Neil Horman <nhorman@tuxdriver.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 include/net/sctp/sm.h    |  6 +--
 net/sctp/sm_make_chunk.c | 99 +++++++++++++++++++++++++++---------------------
 net/sctp/sm_statefuns.c  | 18 +--------
 3 files changed, 60 insertions(+), 63 deletions(-)

diff --git a/include/net/sctp/sm.h b/include/net/sctp/sm.h
index 7f4eeb340a54..72a31db47ded 100644
--- a/include/net/sctp/sm.h
+++ b/include/net/sctp/sm.h
@@ -248,9 +248,9 @@ struct sctp_chunk *sctp_make_asconf_update_ip(struct sctp_association *,
 					      int, __be16);
 struct sctp_chunk *sctp_make_asconf_set_prim(struct sctp_association *asoc,
 					     union sctp_addr *addr);
-int sctp_verify_asconf(const struct sctp_association *asoc,
-		       struct sctp_paramhdr *param_hdr, void *chunk_end,
-		       struct sctp_paramhdr **errp);
+bool sctp_verify_asconf(const struct sctp_association *asoc,
+			struct sctp_chunk *chunk, bool addr_param_needed,
+			struct sctp_paramhdr **errp);
 struct sctp_chunk *sctp_process_asconf(struct sctp_association *asoc,
 				       struct sctp_chunk *asconf);
 int sctp_process_asconf_ack(struct sctp_association *asoc,
diff --git a/net/sctp/sm_make_chunk.c b/net/sctp/sm_make_chunk.c
index ae0e616a7ca5..ab734be8cb20 100644
--- a/net/sctp/sm_make_chunk.c
+++ b/net/sctp/sm_make_chunk.c
@@ -3110,50 +3110,63 @@ static __be16 sctp_process_asconf_param(struct sctp_association *asoc,
 	return SCTP_ERROR_NO_ERROR;
 }
 
-/* Verify the ASCONF packet before we process it.  */
-int sctp_verify_asconf(const struct sctp_association *asoc,
-		       struct sctp_paramhdr *param_hdr, void *chunk_end,
-		       struct sctp_paramhdr **errp) {
-	sctp_addip_param_t *asconf_param;
+/* Verify the ASCONF packet before we process it. */
+bool sctp_verify_asconf(const struct sctp_association *asoc,
+			struct sctp_chunk *chunk, bool addr_param_needed,
+			struct sctp_paramhdr **errp)
+{
+	sctp_addip_chunk_t *addip = (sctp_addip_chunk_t *) chunk->chunk_hdr;
 	union sctp_params param;
-	int length, plen;
-
-	param.v = (sctp_paramhdr_t *) param_hdr;
-	while (param.v <= chunk_end - sizeof(sctp_paramhdr_t)) {
-		length = ntohs(param.p->length);
-		*errp = param.p;
+	bool addr_param_seen = false;
 
-		if (param.v > chunk_end - length ||
-		    length < sizeof(sctp_paramhdr_t))
-			return 0;
+	sctp_walk_params(param, addip, addip_hdr.params) {
+		size_t length = ntohs(param.p->length);
 
+		*errp = param.p;
 		switch (param.p->type) {
+		case SCTP_PARAM_ERR_CAUSE:
+			break;
+		case SCTP_PARAM_IPV4_ADDRESS:
+			if (length != sizeof(sctp_ipv4addr_param_t))
+				return false;
+			addr_param_seen = true;
+			break;
+		case SCTP_PARAM_IPV6_ADDRESS:
+			if (length != sizeof(sctp_ipv6addr_param_t))
+				return false;
+			addr_param_seen = true;
+			break;
 		case SCTP_PARAM_ADD_IP:
 		case SCTP_PARAM_DEL_IP:
 		case SCTP_PARAM_SET_PRIMARY:
-			asconf_param = (sctp_addip_param_t *)param.v;
-			plen = ntohs(asconf_param->param_hdr.length);
-			if (plen < sizeof(sctp_addip_param_t) +
-			    sizeof(sctp_paramhdr_t))
-				return 0;
+			/* In ASCONF chunks, these need to be first. */
+			if (addr_param_needed && !addr_param_seen)
+				return false;
+			length = ntohs(param.addip->param_hdr.length);
+			if (length < sizeof(sctp_addip_param_t) +
+				     sizeof(sctp_paramhdr_t))
+				return false;
 			break;
 		case SCTP_PARAM_SUCCESS_REPORT:
 		case SCTP_PARAM_ADAPTATION_LAYER_IND:
 			if (length != sizeof(sctp_addip_param_t))
-				return 0;
-
+				return false;
 			break;
 		default:
-			break;
+			/* This is unkown to us, reject! */
+			return false;
 		}
-
-		param.v += WORD_ROUND(length);
 	}
 
-	if (param.v != chunk_end)
-		return 0;
+	/* Remaining sanity checks. */
+	if (addr_param_needed && !addr_param_seen)
+		return false;
+	if (!addr_param_needed && addr_param_seen)
+		return false;
+	if (param.v != chunk->chunk_end)
+		return false;
 
-	return 1;
+	return true;
 }
 
 /* Process an incoming ASCONF chunk with the next expected serial no. and
@@ -3162,16 +3175,17 @@ int sctp_verify_asconf(const struct sctp_association *asoc,
 struct sctp_chunk *sctp_process_asconf(struct sctp_association *asoc,
 				       struct sctp_chunk *asconf)
 {
+	sctp_addip_chunk_t *addip = (sctp_addip_chunk_t *) asconf->chunk_hdr;
+	bool all_param_pass = true;
+	union sctp_params param;
 	sctp_addiphdr_t		*hdr;
 	union sctp_addr_param	*addr_param;
 	sctp_addip_param_t	*asconf_param;
 	struct sctp_chunk	*asconf_ack;
-
 	__be16	err_code;
 	int	length = 0;
 	int	chunk_len;
 	__u32	serial;
-	int	all_param_pass = 1;
 
 	chunk_len = ntohs(asconf->chunk_hdr->length) - sizeof(sctp_chunkhdr_t);
 	hdr = (sctp_addiphdr_t *)asconf->skb->data;
@@ -3199,9 +3213,14 @@ struct sctp_chunk *sctp_process_asconf(struct sctp_association *asoc,
 		goto done;
 
 	/* Process the TLVs contained within the ASCONF chunk. */
-	while (chunk_len > 0) {
+	sctp_walk_params(param, addip, addip_hdr.params) {
+		/* Skip preceeding address parameters. */
+		if (param.p->type == SCTP_PARAM_IPV4_ADDRESS ||
+		    param.p->type == SCTP_PARAM_IPV6_ADDRESS)
+			continue;
+
 		err_code = sctp_process_asconf_param(asoc, asconf,
-						     asconf_param);
+						     param.addip);
 		/* ADDIP 4.1 A7)
 		 * If an error response is received for a TLV parameter,
 		 * all TLVs with no response before the failed TLV are
@@ -3209,28 +3228,20 @@ struct sctp_chunk *sctp_process_asconf(struct sctp_association *asoc,
 		 * the failed response are considered unsuccessful unless
 		 * a specific success indication is present for the parameter.
 		 */
-		if (SCTP_ERROR_NO_ERROR != err_code)
-			all_param_pass = 0;
-
+		if (err_code != SCTP_ERROR_NO_ERROR)
+			all_param_pass = false;
 		if (!all_param_pass)
-			sctp_add_asconf_response(asconf_ack,
-						 asconf_param->crr_id, err_code,
-						 asconf_param);
+			sctp_add_asconf_response(asconf_ack, param.addip->crr_id,
+						 err_code, param.addip);
 
 		/* ADDIP 4.3 D11) When an endpoint receiving an ASCONF to add
 		 * an IP address sends an 'Out of Resource' in its response, it
 		 * MUST also fail any subsequent add or delete requests bundled
 		 * in the ASCONF.
 		 */
-		if (SCTP_ERROR_RSRC_LOW == err_code)
+		if (err_code == SCTP_ERROR_RSRC_LOW)
 			goto done;
-
-		/* Move to the next ASCONF param. */
-		length = ntohs(asconf_param->param_hdr.length);
-		asconf_param = (void *)asconf_param + length;
-		chunk_len -= length;
 	}
-
 done:
 	asoc->peer.addip_serial++;
 
diff --git a/net/sctp/sm_statefuns.c b/net/sctp/sm_statefuns.c
index 7194fe8589b0..e6b6b830fdd4 100644
--- a/net/sctp/sm_statefuns.c
+++ b/net/sctp/sm_statefuns.c
@@ -3591,9 +3591,7 @@ sctp_disposition_t sctp_sf_do_asconf(struct net *net,
 	struct sctp_chunk	*asconf_ack = NULL;
 	struct sctp_paramhdr	*err_param = NULL;
 	sctp_addiphdr_t		*hdr;
-	union sctp_addr_param	*addr_param;
 	__u32			serial;
-	int			length;
 
 	if (!sctp_vtag_verify(chunk, asoc)) {
 		sctp_add_cmd_sf(commands, SCTP_CMD_REPORT_BAD_TAG,
@@ -3618,17 +3616,8 @@ sctp_disposition_t sctp_sf_do_asconf(struct net *net,
 	hdr = (sctp_addiphdr_t *)chunk->skb->data;
 	serial = ntohl(hdr->serial);
 
-	addr_param = (union sctp_addr_param *)hdr->params;
-	length = ntohs(addr_param->p.length);
-	if (length < sizeof(sctp_paramhdr_t))
-		return sctp_sf_violation_paramlen(net, ep, asoc, type, arg,
-			   (void *)addr_param, commands);
-
 	/* Verify the ASCONF chunk before processing it. */
-	if (!sctp_verify_asconf(asoc,
-			    (sctp_paramhdr_t *)((void *)addr_param + length),
-			    (void *)chunk->chunk_end,
-			    &err_param))
+	if (!sctp_verify_asconf(asoc, chunk, true, &err_param))
 		return sctp_sf_violation_paramlen(net, ep, asoc, type, arg,
 						  (void *)err_param, commands);
 
@@ -3745,10 +3734,7 @@ sctp_disposition_t sctp_sf_do_asconf_ack(struct net *net,
 	rcvd_serial = ntohl(addip_hdr->serial);
 
 	/* Verify the ASCONF-ACK chunk before processing it. */
-	if (!sctp_verify_asconf(asoc,
-	    (sctp_paramhdr_t *)addip_hdr->params,
-	    (void *)asconf_ack->chunk_end,
-	    &err_param))
+	if (!sctp_verify_asconf(asoc, asconf_ack, false, &err_param))
 		return sctp_sf_violation_paramlen(net, ep, asoc, type, arg,
 			   (void *)err_param, commands);
 
-- 
2.1.0


  parent reply	other threads:[~2014-11-11 11:10 UTC|newest]

Thread overview: 173+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-11-11 11:05 [3.16.y-ckt stable] Linux 3.16.7-ckt1 stable review Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 001/170] drm/tilcdc: Fix the error path in tilcdc_load() Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 002/170] builddeb: put the dbg files into the correct directory Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 003/170] switch iov_iter_get_pages() to passing maximal number of pages Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 004/170] fuse: honour max_read and max_write in direct_io mode Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 005/170] usb: phy: return -ENODEV on failure of try_module_get Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 006/170] PM / clk: Fix crash in clocks management code if !CONFIG_PM_RUNTIME Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 007/170] rt2x00: support Ralink 5362 Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 008/170] wireless: rt2x00: add new rt2800usb devices Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 009/170] NFS: Fix /proc/fs/nfsfs/servers and /proc/fs/nfsfs/volumes Luis Henriques
2014-11-14  6:36   ` Ben Hutchings
2014-11-14 10:52     ` Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 010/170] nfs: fix duplicate proc entries Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 011/170] mm: page_alloc: fix zone allocation fairness on UP Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 012/170] ext4: check EA value offset when loading Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 013/170] jbd2: free bh when descriptor block checksum fails Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 014/170] ext4: don't check quota format when there are no quota files Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 015/170] target: Fix queue full status NULL pointer for SCF_TRANSPORT_TASK_SENSE Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 016/170] vfs: fix data corruption when blocksize < pagesize for mmaped data Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 017/170] ext4: fix mmap data corruption when blocksize < pagesize Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 018/170] ext4: grab missed write_count for EXT4_IOC_SWAP_BOOT Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 019/170] qla_target: don't delete changed nacls Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 020/170] target: Fix APTPL metadata handling for dynamic MappedLUNs Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 021/170] iser-target: Disable TX completion interrupt coalescing Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 022/170] ext4: don't orphan or truncate the boot loader inode Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 023/170] ext4: add ext4_iget_normal() which is to be used for dir tree lookups Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 024/170] ext4: fix reservation overflow in ext4_da_write_begin Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 025/170] ext4: Replace open coded mdata csum feature to helper function Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 026/170] ext4: move error report out of atomic context in ext4_init_block_bitmap() Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 027/170] ARC: [nsimosci] Allow "headless" models to boot Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 028/170] ARC: Update order of registers in KGDB to match GDB 7.5 Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 029/170] ARC: unbork FPU save/restore Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 030/170] ext4: check s_chksum_driver when looking for bg csum presence Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 031/170] drm/radeon: fix speaker allocation setup Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 032/170] drm/radeon: use gart memory for DMA ring tests Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 033/170] random: add and use memzero_explicit() for clearing data Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 034/170] MIPS: cp1emu: Fix ISA restrictions for cop1x_op instructions Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 035/170] freezer: Do not freeze tasks killed by OOM killer Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 036/170] OOM, PM: OOM killed task shouldn't escape PM suspend Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 037/170] qxl: don't create too large primary surface Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 038/170] MIPS: loongson2_cpufreq: Fix CPU clock rate setting mismerge Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 039/170] MIPS: tlbex: Properly fix HUGE TLB Refill exception handler Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 040/170] drm/cirrus: bind also to qemu-xen-traditional Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 041/170] cpufreq: intel_pstate: Fix setting max_perf_pct in performance policy Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 042/170] cpufreq: expose scaling_cur_freq sysfs file for set_policy() drivers Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 043/170] cpufreq: intel_pstate: Reflect current no_turbo state correctly Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 044/170] intel_pstate: Don't lose sysfs settings during cpu offline Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 045/170] intel_pstate: Fix BYT frequency reporting Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 046/170] intel_pstate: Correct BYT VID values Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 047/170] MIPS: ftrace: Fix a microMIPS build problem Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 048/170] KVM: x86: Check non-canonical addresses upon WRMSR Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 049/170] KVM: x86: Prevent host from panicking on shared MSR writes Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 050/170] KVM: x86: Improve thread safety in pit Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 051/170] KVM: x86: Fix wrong masking on relative jump/call Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 052/170] KVM: x86: Emulator fixes for eip canonical checks on near branches Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 053/170] KVM: x86: Handle errors when RIP is set during far jumps Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 054/170] kvm: vmx: handle invvpid vm exit gracefully Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 055/170] kvm: x86: don't kill guest on unknown exit reason Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 056/170] kvm: fix excessive pages un-pinning in kvm_iommu_map error path Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 057/170] KVM: x86: Fix far-jump to non-canonical check Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 058/170] init/Kconfig: Hide printk log config if CONFIG_PRINTK=n Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 059/170] be careful with nd->inode in path_init() and follow_dotdot_rcu() Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 060/170] can: flexcan: mark TX mailbox as TX_INACTIVE Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 061/170] can: flexcan: correctly initialize mailboxes Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 062/170] can: flexcan: implement workaround for errata ERR005829 Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 063/170] can: flexcan: put TX mailbox into TX_INACTIVE mode after tx-complete Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 064/170] can: at91_can: add missing prepare and unprepare of the clock Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 065/170] virtio-rng: fix stuck of hot-unplugging busy device Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 066/170] virtio-rng: skip reading when we start to remove the device Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 067/170] pstore: Fix duplicate {console,ftrace}-efi entries Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 068/170] x86: bpf_jit: fix two bugs in eBPF JIT compiler Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 069/170] ipv4: fix nexthop attlen check in fib_nh_match Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 070/170] vxlan: fix a use after free in vxlan_encap_bypass Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 071/170] vxlan: using pskb_may_pull as early as possible Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 072/170] vxlan: fix a free after use Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 073/170] ipv4: dst_entry leak in ip_send_unicast_reply() Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 074/170] ipv4: fix a potential use after free in ip_tunnel_core.c Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 075/170] ax88179_178a: fix bonding failure Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 076/170] net: tso: fix unaligned access to crafted TCP header in helper API Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 077/170] hyperv: Fix the total_data_buflen in send path Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 078/170] tcp: md5: do not use alloc_percpu() Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 079/170] macvlan: fix a race on port dismantle and possible skb leaks Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 080/170] ipv4: Do not cache routing failures due to disabled forwarding Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 081/170] net/mlx4_en: Don't attempt to TX offload the outer UDP checksum for VXLAN Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 082/170] gre: Use inner mac length when computing tunnel length Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 083/170] drivers/net: Disable UFO through virtio Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 084/170] drivers/net, ipv6: Select IPv6 fragment idents for virtio UFO packets Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 085/170] drivers/net: macvtap and tun depend on INET Luis Henriques
2014-11-11 11:07 ` Luis Henriques [this message]
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 087/170] net: sctp: fix panic on duplicate ASCONF chunks Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 088/170] net: sctp: fix remote memory pressure from excessive queueing Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 089/170] staging:iio:ad5933: Fix NULL pointer deref when enabling buffer Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 090/170] staging:iio:ad5933: Drop "raw" from channel names Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 091/170] iio: st_sensors: Fix buffer copy Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 092/170] iio: adc: mxs-lradc: Disable the clock on probe failure Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 093/170] spi: pl022: Fix incorrect dma_unmap_sg Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 094/170] mac80211: fix typo in starting baserate for rts_cts_rate_idx Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 095/170] ASoC: Intel: HSW/BDW only support S16 and S24 formats Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 096/170] staging: comedi: (regression) channel list must be set for COMEDI_CMD ioctl Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 097/170] usb: dwc3: gadget: fix set_halt() bug with pending transfers Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 098/170] usb: gadget: function: acm: make f_acm pass USB20CV Chapter9 Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 099/170] nfsd4: fix response size estimation for OP_SEQUENCE Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 100/170] mtd: move support for struct flash_platform_data into m25p80 Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 101/170] mtd: m25p80: get rid of spi_get_device_id Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 102/170] mtd: spi-nor: make spi_nor_scan() take a chip type name, not spi_device_id Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 103/170] mtd: m25p80,spi-nor: Fix module aliases for m25p80 Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 104/170] ext3: Don't check quota format when there are no quota files Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 105/170] quota: Properly return errors from dquot_writeback_dquots() Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 106/170] USB: serial: cp210x: add Silicon Labs 358x VID and PID Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 107/170] usb: serial: ftdi_sio: add Awinda Station and Dongle products Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 108/170] usb: option: add support for Telit LE910 Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 109/170] USB: option: add Haier CE81B CDMA modem Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 110/170] ASoC: adau1761: Fix input PGA volume Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 111/170] x86, apic: Handle a bad TSC more gracefully Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 112/170] i3200_edac: Report CE events properly Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 113/170] i82860_edac: " Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 114/170] cpc925_edac: Report UE " Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 115/170] e7xxx_edac: Report CE " Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 116/170] scsi: Fix error handling in SCSI_IOCTL_SEND_COMMAND Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 117/170] usb: serial: ftdi_sio: add "bricked" FTDI device PID Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 118/170] usb: musb: cppi41: restart hrtimer only if not yet done Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 119/170] Revert "usb: dwc3: dwc3-omap: Disable/Enable only wrapper interrupts in prepare/complete" Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 120/170] usb: gadget: f_fs: remove redundant ffs_data_get() Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 121/170] usb: ffs: fix regression when quirk_ep_out_aligned_size flag is set Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 122/170] usb: musb: dsps: start OTG timer on resume again Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 123/170] usb: gadget: udc: core: fix kernel oops with soft-connect Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 124/170] nfsd4: fix crash on unknown operation number Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 125/170] iwlwifi: configure the LTR Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 126/170] iwlwifi: dvm: drop non VO frames when flushing Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 127/170] Revert "iwlwifi: mvm: treat EAPOLs like mgmt frames wrt rate" Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 128/170] usb: dwc3: gadget: Properly initialize LINK TRB Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 129/170] Input: i8042 - quirks for Fujitsu Lifebook A544 and Lifebook AH544 Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 130/170] posix-timers: Fix stack info leak in timer_create() Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 131/170] futex: Fix a race condition between REQUEUE_PI and task death Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 132/170] usb: chipidea: Fix oops when removing the ci_hdrc module Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 133/170] drm/i915: Do a dummy DPCD read before the actual read Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 134/170] ALSA: bebob: Uninitialized id returned by saffirepro_both_clk_src_get Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 135/170] PM / Sleep: fix async suspend_late/freeze_late error handling Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 136/170] PM / Sleep: fix recovery during resuming from hibernation Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 137/170] Revert "block: all blk-mq requests are tagged" Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 138/170] ALSA: pcm: Zero-clear reserved fields of PCM status ioctl in compat mode Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 139/170] ima: check xattr value length and type in the ima_inode_setxattr() Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 140/170] evm: check xattr value length and type in evm_inode_setxattr() Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 141/170] drm/radeon/dpm: disable ulv support on SI Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 142/170] drm/radeon: Use drm_malloc_ab instead of kmalloc_array Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 143/170] drm/radeon: add bapm module parameter Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 144/170] drm/radeon: dpm fixes for asrock systems Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 145/170] drm/radeon: remove invalid pci id Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 146/170] zap_pte_range: update addr when forcing flush after TLB batching faiure Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 147/170] staging: comedi: fix memory leak / bad pointer freeing for chanlist Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 148/170] drm/i915: Ignore VBT backlight check on Macbook 2, 1 Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 149/170] x86, pageattr: Prevent overflow in slow_virt_to_phys() for X86_PAE Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 150/170] ACPI / EC: Fix regression due to conflicting firmware behavior between Samsung and Acer Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 151/170] cgroup/kmemleak: add kmemleak_free() for cgroup deallocations Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 152/170] mm: free compound page with correct order Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 153/170] mm, thp: fix collapsing of hugepages on madvise Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 154/170] lib/bitmap.c: fix undefined shift in __bitmap_shift_{left|right}() Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 155/170] sh: fix sh770x SCIF memory regions Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 156/170] mtd: cfi_cmdset_0001.c: fix resume for LH28F640BF chips Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 157/170] ext4: fix overflow when updating superblock backups after resize Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 158/170] ext4: fix oops when loading block bitmap failed Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 159/170] ext4: enable journal checksum when metadata checksum feature enabled Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 160/170] ext4: prevent bugon on race between write/fcntl Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 161/170] ext4: convert do_split() to use the ERR_PTR convention Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 162/170] ext4: bail out from make_indexed_dir() on first error Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 163/170] PCI: Rename sysfs 'enabled' file back to 'enable' Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 164/170] wireless: rt2x00: add new rt2800usb device Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 165/170] fs: allow open(dir, O_TMPFILE|..., 0) with mode 0 Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 166/170] tracing/syscalls: Ignore numbers outside NR_syscalls' range Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 167/170] x86_64, entry: Filter RFLAGS.NT on entry from userspace Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 168/170] x86_64, entry: Fix out of bounds read on sysenter Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 169/170] mnt: Prevent pivot_root from creating a loop in the mount tree Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 170/170] mm: Remove false WARN_ON from pagecache_isize_extended() Luis Henriques

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1415704129-12709-87-git-send-email-luis.henriques@canonical.com \
    --to=luis.henriques@canonical.com \
    --cc=davem@davemloft.net \
    --cc=dborkman@redhat.com \
    --cc=kernel-team@lists.ubuntu.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=vyasevich@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®