mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Luis Henriques <luis.henriques@canonical.com>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org,
	kernel-team@lists.ubuntu.com
Cc: Daniel Borkmann <dborkman@redhat.com>,
	Vlad Yasevich <vyasevich@gmail.com>,
	"David S. Miller" <davem@davemloft.net>,
	Luis Henriques <luis.henriques@canonical.com>
Subject: [PATCH 3.16.y-ckt 088/170] net: sctp: fix remote memory pressure from excessive queueing
Date: Tue, 11 Nov 2014 11:07:27 +0000	[thread overview]
Message-ID: <1415704129-12709-89-git-send-email-luis.henriques@canonical.com> (raw)
In-Reply-To: <1415704129-12709-1-git-send-email-luis.henriques@canonical.com>

3.16.7-ckt1 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <dborkman@redhat.com>

commit 26b87c7881006311828bb0ab271a551a62dcceb4 upstream.

This scenario is not limited to ASCONF, just taken as one
example triggering the issue. When receiving ASCONF probes
in the form of ...

  -------------- INIT[ASCONF; ASCONF_ACK] ------------->
  <----------- INIT-ACK[ASCONF; ASCONF_ACK] ------------
  -------------------- COOKIE-ECHO -------------------->
  <-------------------- COOKIE-ACK ---------------------
  ---- ASCONF_a; [ASCONF_b; ...; ASCONF_n;] JUNK ------>
  [...]
  ---- ASCONF_m; [ASCONF_o; ...; ASCONF_z;] JUNK ------>

... where ASCONF_a, ASCONF_b, ..., ASCONF_z are good-formed
ASCONFs and have increasing serial numbers, we process such
ASCONF chunk(s) marked with !end_of_packet and !singleton,
since we have not yet reached the SCTP packet end. SCTP does
only do verification on a chunk by chunk basis, as an SCTP
packet is nothing more than just a container of a stream of
chunks which it eats up one by one.

We could run into the case that we receive a packet with a
malformed tail, above marked as trailing JUNK. All previous
chunks are here goodformed, so the stack will eat up all
previous chunks up to this point. In case JUNK does not fit
into a chunk header and there are no more other chunks in
the input queue, or in case JUNK contains a garbage chunk
header, but the encoded chunk length would exceed the skb
tail, or we came here from an entirely different scenario
and the chunk has pdiscard=1 mark (without having had a flush
point), it will happen, that we will excessively queue up
the association's output queue (a correct final chunk may
then turn it into a response flood when flushing the
queue ;)): I ran a simple script with incremental ASCONF
serial numbers and could see the server side consuming
excessive amount of RAM [before/after: up to 2GB and more].

The issue at heart is that the chunk train basically ends
with !end_of_packet and !singleton markers and since commit
2e3216cd54b1 ("sctp: Follow security requirement of responding
with 1 packet") therefore preventing an output queue flush
point in sctp_do_sm() -> sctp_cmd_interpreter() on the input
chunk (chunk = event_arg) even though local_cork is set,
but its precedence has changed since then. In the normal
case, the last chunk with end_of_packet=1 would trigger the
queue flush to accommodate possible outgoing bundling.

In the input queue, sctp_inq_pop() seems to do the right thing
in terms of discarding invalid chunks. So, above JUNK will
not enter the state machine and instead be released and exit
the sctp_assoc_bh_rcv() chunk processing loop. It's simply
the flush point being missing at loop exit. Adding a try-flush
approach on the output queue might not work as the underlying
infrastructure might be long gone at this point due to the
side-effect interpreter run.

One possibility, albeit a bit of a kludge, would be to defer
invalid chunk freeing into the state machine in order to
possibly trigger packet discards and thus indirectly a queue
flush on error. It would surely be better to discard chunks
as in the current, perhaps better controlled environment, but
going back and forth, it's simply architecturally not possible.
I tried various trailing JUNK attack cases and it seems to
look good now.

Joint work with Vlad Yasevich.

Fixes: 2e3216cd54b1 ("sctp: Follow security requirement of responding with 1 packet")
Signed-off-by: Daniel Borkmann <dborkman@redhat.com>
Signed-off-by: Vlad Yasevich <vyasevich@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
 net/sctp/inqueue.c      | 33 +++++++--------------------------
 net/sctp/sm_statefuns.c |  3 +++
 2 files changed, 10 insertions(+), 26 deletions(-)

diff --git a/net/sctp/inqueue.c b/net/sctp/inqueue.c
index 4de12afa13d4..7e8a16c77039 100644
--- a/net/sctp/inqueue.c
+++ b/net/sctp/inqueue.c
@@ -140,18 +140,9 @@ struct sctp_chunk *sctp_inq_pop(struct sctp_inq *queue)
 		} else {
 			/* Nothing to do. Next chunk in the packet, please. */
 			ch = (sctp_chunkhdr_t *) chunk->chunk_end;
-
 			/* Force chunk->skb->data to chunk->chunk_end.  */
-			skb_pull(chunk->skb,
-				 chunk->chunk_end - chunk->skb->data);
-
-			/* Verify that we have at least chunk headers
-			 * worth of buffer left.
-			 */
-			if (skb_headlen(chunk->skb) < sizeof(sctp_chunkhdr_t)) {
-				sctp_chunk_free(chunk);
-				chunk = queue->in_progress = NULL;
-			}
+			skb_pull(chunk->skb, chunk->chunk_end - chunk->skb->data);
+			/* We are guaranteed to pull a SCTP header. */
 		}
 	}
 
@@ -187,24 +178,14 @@ struct sctp_chunk *sctp_inq_pop(struct sctp_inq *queue)
 	skb_pull(chunk->skb, sizeof(sctp_chunkhdr_t));
 	chunk->subh.v = NULL; /* Subheader is no longer valid.  */
 
-	if (chunk->chunk_end < skb_tail_pointer(chunk->skb)) {
+	if (chunk->chunk_end + sizeof(sctp_chunkhdr_t) <
+	    skb_tail_pointer(chunk->skb)) {
 		/* This is not a singleton */
 		chunk->singleton = 0;
 	} else if (chunk->chunk_end > skb_tail_pointer(chunk->skb)) {
-		/* RFC 2960, Section 6.10  Bundling
-		 *
-		 * Partial chunks MUST NOT be placed in an SCTP packet.
-		 * If the receiver detects a partial chunk, it MUST drop
-		 * the chunk.
-		 *
-		 * Since the end of the chunk is past the end of our buffer
-		 * (which contains the whole packet, we can freely discard
-		 * the whole packet.
-		 */
-		sctp_chunk_free(chunk);
-		chunk = queue->in_progress = NULL;
-
-		return NULL;
+		/* Discard inside state machine. */
+		chunk->pdiscard = 1;
+		chunk->chunk_end = skb_tail_pointer(chunk->skb);
 	} else {
 		/* We are at the end of the packet, so mark the chunk
 		 * in case we need to send a SACK.
diff --git a/net/sctp/sm_statefuns.c b/net/sctp/sm_statefuns.c
index e6b6b830fdd4..3e287a3fa03b 100644
--- a/net/sctp/sm_statefuns.c
+++ b/net/sctp/sm_statefuns.c
@@ -170,6 +170,9 @@ sctp_chunk_length_valid(struct sctp_chunk *chunk,
 {
 	__u16 chunk_length = ntohs(chunk->chunk_hdr->length);
 
+	/* Previously already marked? */
+	if (unlikely(chunk->pdiscard))
+		return 0;
 	if (unlikely(chunk_length < required_length))
 		return 0;
 
-- 
2.1.0


  parent reply	other threads:[~2014-11-11 11:10 UTC|newest]

Thread overview: 173+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-11-11 11:05 [3.16.y-ckt stable] Linux 3.16.7-ckt1 stable review Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 001/170] drm/tilcdc: Fix the error path in tilcdc_load() Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 002/170] builddeb: put the dbg files into the correct directory Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 003/170] switch iov_iter_get_pages() to passing maximal number of pages Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 004/170] fuse: honour max_read and max_write in direct_io mode Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 005/170] usb: phy: return -ENODEV on failure of try_module_get Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 006/170] PM / clk: Fix crash in clocks management code if !CONFIG_PM_RUNTIME Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 007/170] rt2x00: support Ralink 5362 Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 008/170] wireless: rt2x00: add new rt2800usb devices Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 009/170] NFS: Fix /proc/fs/nfsfs/servers and /proc/fs/nfsfs/volumes Luis Henriques
2014-11-14  6:36   ` Ben Hutchings
2014-11-14 10:52     ` Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 010/170] nfs: fix duplicate proc entries Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 011/170] mm: page_alloc: fix zone allocation fairness on UP Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 012/170] ext4: check EA value offset when loading Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 013/170] jbd2: free bh when descriptor block checksum fails Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 014/170] ext4: don't check quota format when there are no quota files Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 015/170] target: Fix queue full status NULL pointer for SCF_TRANSPORT_TASK_SENSE Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 016/170] vfs: fix data corruption when blocksize < pagesize for mmaped data Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 017/170] ext4: fix mmap data corruption when blocksize < pagesize Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 018/170] ext4: grab missed write_count for EXT4_IOC_SWAP_BOOT Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 019/170] qla_target: don't delete changed nacls Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 020/170] target: Fix APTPL metadata handling for dynamic MappedLUNs Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 021/170] iser-target: Disable TX completion interrupt coalescing Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 022/170] ext4: don't orphan or truncate the boot loader inode Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 023/170] ext4: add ext4_iget_normal() which is to be used for dir tree lookups Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 024/170] ext4: fix reservation overflow in ext4_da_write_begin Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 025/170] ext4: Replace open coded mdata csum feature to helper function Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 026/170] ext4: move error report out of atomic context in ext4_init_block_bitmap() Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 027/170] ARC: [nsimosci] Allow "headless" models to boot Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 028/170] ARC: Update order of registers in KGDB to match GDB 7.5 Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 029/170] ARC: unbork FPU save/restore Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 030/170] ext4: check s_chksum_driver when looking for bg csum presence Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 031/170] drm/radeon: fix speaker allocation setup Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 032/170] drm/radeon: use gart memory for DMA ring tests Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 033/170] random: add and use memzero_explicit() for clearing data Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 034/170] MIPS: cp1emu: Fix ISA restrictions for cop1x_op instructions Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 035/170] freezer: Do not freeze tasks killed by OOM killer Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 036/170] OOM, PM: OOM killed task shouldn't escape PM suspend Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 037/170] qxl: don't create too large primary surface Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 038/170] MIPS: loongson2_cpufreq: Fix CPU clock rate setting mismerge Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 039/170] MIPS: tlbex: Properly fix HUGE TLB Refill exception handler Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 040/170] drm/cirrus: bind also to qemu-xen-traditional Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 041/170] cpufreq: intel_pstate: Fix setting max_perf_pct in performance policy Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 042/170] cpufreq: expose scaling_cur_freq sysfs file for set_policy() drivers Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 043/170] cpufreq: intel_pstate: Reflect current no_turbo state correctly Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 044/170] intel_pstate: Don't lose sysfs settings during cpu offline Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 045/170] intel_pstate: Fix BYT frequency reporting Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 046/170] intel_pstate: Correct BYT VID values Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 047/170] MIPS: ftrace: Fix a microMIPS build problem Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 048/170] KVM: x86: Check non-canonical addresses upon WRMSR Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 049/170] KVM: x86: Prevent host from panicking on shared MSR writes Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 050/170] KVM: x86: Improve thread safety in pit Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 051/170] KVM: x86: Fix wrong masking on relative jump/call Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 052/170] KVM: x86: Emulator fixes for eip canonical checks on near branches Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 053/170] KVM: x86: Handle errors when RIP is set during far jumps Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 054/170] kvm: vmx: handle invvpid vm exit gracefully Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 055/170] kvm: x86: don't kill guest on unknown exit reason Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 056/170] kvm: fix excessive pages un-pinning in kvm_iommu_map error path Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 057/170] KVM: x86: Fix far-jump to non-canonical check Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 058/170] init/Kconfig: Hide printk log config if CONFIG_PRINTK=n Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 059/170] be careful with nd->inode in path_init() and follow_dotdot_rcu() Luis Henriques
2014-11-11 11:06 ` [PATCH 3.16.y-ckt 060/170] can: flexcan: mark TX mailbox as TX_INACTIVE Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 061/170] can: flexcan: correctly initialize mailboxes Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 062/170] can: flexcan: implement workaround for errata ERR005829 Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 063/170] can: flexcan: put TX mailbox into TX_INACTIVE mode after tx-complete Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 064/170] can: at91_can: add missing prepare and unprepare of the clock Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 065/170] virtio-rng: fix stuck of hot-unplugging busy device Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 066/170] virtio-rng: skip reading when we start to remove the device Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 067/170] pstore: Fix duplicate {console,ftrace}-efi entries Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 068/170] x86: bpf_jit: fix two bugs in eBPF JIT compiler Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 069/170] ipv4: fix nexthop attlen check in fib_nh_match Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 070/170] vxlan: fix a use after free in vxlan_encap_bypass Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 071/170] vxlan: using pskb_may_pull as early as possible Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 072/170] vxlan: fix a free after use Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 073/170] ipv4: dst_entry leak in ip_send_unicast_reply() Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 074/170] ipv4: fix a potential use after free in ip_tunnel_core.c Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 075/170] ax88179_178a: fix bonding failure Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 076/170] net: tso: fix unaligned access to crafted TCP header in helper API Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 077/170] hyperv: Fix the total_data_buflen in send path Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 078/170] tcp: md5: do not use alloc_percpu() Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 079/170] macvlan: fix a race on port dismantle and possible skb leaks Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 080/170] ipv4: Do not cache routing failures due to disabled forwarding Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 081/170] net/mlx4_en: Don't attempt to TX offload the outer UDP checksum for VXLAN Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 082/170] gre: Use inner mac length when computing tunnel length Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 083/170] drivers/net: Disable UFO through virtio Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 084/170] drivers/net, ipv6: Select IPv6 fragment idents for virtio UFO packets Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 085/170] drivers/net: macvtap and tun depend on INET Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 086/170] net: sctp: fix skb_over_panic when receiving malformed ASCONF chunks Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 087/170] net: sctp: fix panic on duplicate " Luis Henriques
2014-11-11 11:07 ` Luis Henriques [this message]
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 089/170] staging:iio:ad5933: Fix NULL pointer deref when enabling buffer Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 090/170] staging:iio:ad5933: Drop "raw" from channel names Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 091/170] iio: st_sensors: Fix buffer copy Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 092/170] iio: adc: mxs-lradc: Disable the clock on probe failure Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 093/170] spi: pl022: Fix incorrect dma_unmap_sg Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 094/170] mac80211: fix typo in starting baserate for rts_cts_rate_idx Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 095/170] ASoC: Intel: HSW/BDW only support S16 and S24 formats Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 096/170] staging: comedi: (regression) channel list must be set for COMEDI_CMD ioctl Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 097/170] usb: dwc3: gadget: fix set_halt() bug with pending transfers Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 098/170] usb: gadget: function: acm: make f_acm pass USB20CV Chapter9 Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 099/170] nfsd4: fix response size estimation for OP_SEQUENCE Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 100/170] mtd: move support for struct flash_platform_data into m25p80 Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 101/170] mtd: m25p80: get rid of spi_get_device_id Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 102/170] mtd: spi-nor: make spi_nor_scan() take a chip type name, not spi_device_id Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 103/170] mtd: m25p80,spi-nor: Fix module aliases for m25p80 Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 104/170] ext3: Don't check quota format when there are no quota files Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 105/170] quota: Properly return errors from dquot_writeback_dquots() Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 106/170] USB: serial: cp210x: add Silicon Labs 358x VID and PID Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 107/170] usb: serial: ftdi_sio: add Awinda Station and Dongle products Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 108/170] usb: option: add support for Telit LE910 Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 109/170] USB: option: add Haier CE81B CDMA modem Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 110/170] ASoC: adau1761: Fix input PGA volume Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 111/170] x86, apic: Handle a bad TSC more gracefully Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 112/170] i3200_edac: Report CE events properly Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 113/170] i82860_edac: " Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 114/170] cpc925_edac: Report UE " Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 115/170] e7xxx_edac: Report CE " Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 116/170] scsi: Fix error handling in SCSI_IOCTL_SEND_COMMAND Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 117/170] usb: serial: ftdi_sio: add "bricked" FTDI device PID Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 118/170] usb: musb: cppi41: restart hrtimer only if not yet done Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 119/170] Revert "usb: dwc3: dwc3-omap: Disable/Enable only wrapper interrupts in prepare/complete" Luis Henriques
2014-11-11 11:07 ` [PATCH 3.16.y-ckt 120/170] usb: gadget: f_fs: remove redundant ffs_data_get() Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 121/170] usb: ffs: fix regression when quirk_ep_out_aligned_size flag is set Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 122/170] usb: musb: dsps: start OTG timer on resume again Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 123/170] usb: gadget: udc: core: fix kernel oops with soft-connect Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 124/170] nfsd4: fix crash on unknown operation number Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 125/170] iwlwifi: configure the LTR Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 126/170] iwlwifi: dvm: drop non VO frames when flushing Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 127/170] Revert "iwlwifi: mvm: treat EAPOLs like mgmt frames wrt rate" Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 128/170] usb: dwc3: gadget: Properly initialize LINK TRB Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 129/170] Input: i8042 - quirks for Fujitsu Lifebook A544 and Lifebook AH544 Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 130/170] posix-timers: Fix stack info leak in timer_create() Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 131/170] futex: Fix a race condition between REQUEUE_PI and task death Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 132/170] usb: chipidea: Fix oops when removing the ci_hdrc module Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 133/170] drm/i915: Do a dummy DPCD read before the actual read Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 134/170] ALSA: bebob: Uninitialized id returned by saffirepro_both_clk_src_get Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 135/170] PM / Sleep: fix async suspend_late/freeze_late error handling Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 136/170] PM / Sleep: fix recovery during resuming from hibernation Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 137/170] Revert "block: all blk-mq requests are tagged" Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 138/170] ALSA: pcm: Zero-clear reserved fields of PCM status ioctl in compat mode Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 139/170] ima: check xattr value length and type in the ima_inode_setxattr() Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 140/170] evm: check xattr value length and type in evm_inode_setxattr() Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 141/170] drm/radeon/dpm: disable ulv support on SI Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 142/170] drm/radeon: Use drm_malloc_ab instead of kmalloc_array Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 143/170] drm/radeon: add bapm module parameter Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 144/170] drm/radeon: dpm fixes for asrock systems Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 145/170] drm/radeon: remove invalid pci id Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 146/170] zap_pte_range: update addr when forcing flush after TLB batching faiure Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 147/170] staging: comedi: fix memory leak / bad pointer freeing for chanlist Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 148/170] drm/i915: Ignore VBT backlight check on Macbook 2, 1 Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 149/170] x86, pageattr: Prevent overflow in slow_virt_to_phys() for X86_PAE Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 150/170] ACPI / EC: Fix regression due to conflicting firmware behavior between Samsung and Acer Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 151/170] cgroup/kmemleak: add kmemleak_free() for cgroup deallocations Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 152/170] mm: free compound page with correct order Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 153/170] mm, thp: fix collapsing of hugepages on madvise Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 154/170] lib/bitmap.c: fix undefined shift in __bitmap_shift_{left|right}() Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 155/170] sh: fix sh770x SCIF memory regions Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 156/170] mtd: cfi_cmdset_0001.c: fix resume for LH28F640BF chips Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 157/170] ext4: fix overflow when updating superblock backups after resize Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 158/170] ext4: fix oops when loading block bitmap failed Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 159/170] ext4: enable journal checksum when metadata checksum feature enabled Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 160/170] ext4: prevent bugon on race between write/fcntl Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 161/170] ext4: convert do_split() to use the ERR_PTR convention Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 162/170] ext4: bail out from make_indexed_dir() on first error Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 163/170] PCI: Rename sysfs 'enabled' file back to 'enable' Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 164/170] wireless: rt2x00: add new rt2800usb device Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 165/170] fs: allow open(dir, O_TMPFILE|..., 0) with mode 0 Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 166/170] tracing/syscalls: Ignore numbers outside NR_syscalls' range Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 167/170] x86_64, entry: Filter RFLAGS.NT on entry from userspace Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 168/170] x86_64, entry: Fix out of bounds read on sysenter Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 169/170] mnt: Prevent pivot_root from creating a loop in the mount tree Luis Henriques
2014-11-11 11:08 ` [PATCH 3.16.y-ckt 170/170] mm: Remove false WARN_ON from pagecache_isize_extended() Luis Henriques

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1415704129-12709-89-git-send-email-luis.henriques@canonical.com \
    --to=luis.henriques@canonical.com \
    --cc=davem@davemloft.net \
    --cc=dborkman@redhat.com \
    --cc=kernel-team@lists.ubuntu.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=vyasevich@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®