* [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review
@ 2015-03-06 9:54 Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 001/183] [media] em28xx: fix em28xx-input removal Luis Henriques
` (182 more replies)
0 siblings, 183 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:54 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Luis Henriques
This is the start of the review cycle for the Linux 3.16.7-ckt8 stable kernel.
This version contains 183 new patches, summarized below. The new patches are
posted as replies to this message and also available in this git branch:
http://kernel.ubuntu.com/git?p=ubuntu/linux.git;h=linux-3.16.y-review;a=shortlog
git://kernel.ubuntu.com/ubuntu/linux.git linux-3.16.y-review
The review period for version 3.16.7-ckt8 will be open for the next three days.
To report a problem, please reply to the relevant follow-up patch message.
For more information about the Linux 3.16.y-ckt extended stable kernel version,
see https://wiki.ubuntu.com/Kernel/Dev/ExtendedStable .
-Luis
--
arch/arc/include/asm/pgtable.h | 3 +-
arch/arm/boot/dts/am335x-bone-common.dtsi | 1 +
arch/arm/boot/dts/tegra20.dtsi | 8 +-
arch/arm/mach-omap2/omap_hwmod_7xx_data.c | 2 +-
arch/arm/mach-pxa/corgi.c | 3 +
arch/arm/mach-pxa/hx4700.c | 2 +
arch/arm/mach-pxa/poodle.c | 2 +
arch/arm/mach-pxa/spitz.c | 2 +
arch/arm/mach-sa1100/pm.c | 1 +
arch/mips/include/asm/asmmacro.h | 4 +-
arch/mips/kernel/cps-vec.S | 16 +--
arch/mips/kernel/mips_ksyms.c | 10 ++
arch/mips/kvm/kvm_locore.S | 2 +-
arch/mips/kvm/kvm_mips.c | 6 +-
arch/powerpc/kernel/paca.c | 8 ++
arch/powerpc/sysdev/axonram.c | 2 +-
arch/s390/kvm/interrupt.c | 8 +-
arch/s390/kvm/kvm-s390.c | 2 +-
arch/x86/mm/gup.c | 2 +-
arch/x86/mm/hugetlbpage.c | 8 +-
arch/x86/mm/mmap.c | 6 +-
block/blk-mq-tag.c | 1 +
block/blk-throttle.c | 3 +
block/cfq-iosched.c | 16 ++-
drivers/acpi/video.c | 45 +++++++
drivers/bluetooth/ath3k.c | 2 +
drivers/bluetooth/btusb.c | 16 ++-
drivers/char/tpm/tpm-interface.c | 2 +-
drivers/char/tpm/tpm_i2c_atmel.c | 4 +
drivers/char/tpm/tpm_i2c_nuvoton.c | 5 +
drivers/char/tpm/tpm_i2c_stm_st33.c | 9 +-
drivers/char/tpm/tpm_ibmvtpm.c | 28 +++--
drivers/char/tpm/tpm_tis.c | 76 ++++++++---
drivers/clk/clk-gate.c | 2 +-
drivers/clk/sunxi/clk-factors.c | 2 +-
drivers/clk/sunxi/clk-factors.h | 1 +
drivers/clk/sunxi/clk-sunxi.c | 1 +
drivers/clk/zynq/clkc.c | 1 +
drivers/cpufreq/cpufreq.c | 6 +-
drivers/cpufreq/s3c2416-cpufreq.c | 4 +-
drivers/cpufreq/s3c24xx-cpufreq.c | 2 +-
drivers/cpufreq/speedstep-lib.c | 3 +
drivers/cpufreq/speedstep-smi.c | 12 ++
drivers/edac/amd64_edac.c | 10 +-
drivers/firmware/efi/runtime-map.c | 2 +-
drivers/gpio/gpio-rcar.c | 6 +-
drivers/gpio/gpiolib.c | 62 +++++----
drivers/gpu/drm/i915/intel_sideband.c | 26 ++--
drivers/gpu/drm/radeon/atombios_dp.c | 4 +-
drivers/gpu/drm/radeon/cik.c | 37 +++---
drivers/gpu/drm/radeon/kv_dpm.c | 17 ++-
drivers/gpu/drm/radeon/radeon_atombios.c | 1 +
drivers/hid/hid-input.c | 17 +++
drivers/hid/i2c-hid/i2c-hid.c | 5 +-
drivers/infiniband/core/ucma.c | 3 +
drivers/infiniband/core/uverbs_cmd.c | 9 +-
drivers/infiniband/hw/mlx4/main.c | 10 +-
drivers/infiniband/hw/qib/qib.h | 9 +-
drivers/infiniband/hw/qib/qib_eeprom.c | 181 ---------------------------
drivers/infiniband/hw/qib/qib_iba6120.c | 2 -
drivers/infiniband/hw/qib/qib_iba7220.c | 2 -
drivers/infiniband/hw/qib/qib_iba7322.c | 2 -
drivers/infiniband/hw/qib/qib_init.c | 1 -
drivers/infiniband/hw/qib/qib_sysfs.c | 24 ----
drivers/infiniband/ulp/iser/iscsi_iser.h | 4 +-
drivers/infiniband/ulp/iser/iser_initiator.c | 12 +-
drivers/infiniband/ulp/iser/iser_memory.c | 9 +-
drivers/input/tablet/wacom_wac.c | 6 +
drivers/md/dm-io.c | 6 +
drivers/md/dm-raid1.c | 9 ++
drivers/md/dm-snap.c | 4 +-
drivers/md/dm.c | 27 ++--
drivers/md/raid5.c | 3 +-
drivers/media/dvb-frontends/si2168.c | 4 +-
drivers/media/usb/dvb-usb-v2/lmedm04.c | 7 ++
drivers/media/usb/em28xx/em28xx-audio.c | 8 +-
drivers/media/usb/em28xx/em28xx-core.c | 4 +-
drivers/media/usb/em28xx/em28xx-dvb.c | 14 +--
drivers/media/usb/em28xx/em28xx-input.c | 9 +-
drivers/media/usb/em28xx/em28xx-video.c | 6 +-
drivers/misc/mei/hw-me.c | 4 +-
drivers/mmc/host/sdhci-pxav3.c | 75 +++++++----
drivers/net/caif/caif_hsi.c | 1 -
drivers/net/wireless/iwlwifi/mvm/mac80211.c | 5 +-
drivers/net/wireless/iwlwifi/mvm/tx.c | 5 +
drivers/net/wireless/iwlwifi/pcie/tx.c | 7 +-
drivers/pci/pci-driver.c | 2 +-
drivers/pci/rom.c | 7 +-
drivers/pinctrl/pinctrl-imx.c | 2 +-
drivers/platform/x86/ideapad-laptop.c | 41 +++---
drivers/platform/x86/samsung-laptop.c | 20 ++-
drivers/power/88pm860x_charger.c | 1 +
drivers/power/bq24190_charger.c | 2 +-
drivers/power/gpio-charger.c | 4 +-
drivers/scsi/be2iscsi/be_main.c | 1 -
drivers/scsi/megaraid/megaraid_sas_fusion.c | 3 +-
drivers/scsi/sg.c | 6 +-
drivers/staging/comedi/comedi_compat32.c | 12 +-
drivers/staging/comedi/drivers/cb_pcidas64.c | 122 +++++++++++-------
drivers/target/iscsi/iscsi_target_tq.c | 28 +----
drivers/target/target_core_pr.c | 155 +++++++++++++++++------
drivers/target/target_core_sbc.c | 15 ++-
drivers/tty/pty.c | 3 +
drivers/tty/serial/atmel_serial.c | 16 ++-
drivers/tty/serial/fsl_lpuart.c | 16 +--
drivers/tty/vt/vt.c | 4 +-
drivers/usb/class/cdc-acm.c | 21 +++-
drivers/usb/core/buffer.c | 26 ++--
drivers/usb/core/driver.c | 12 ++
drivers/usb/core/hcd.c | 16 +--
drivers/usb/core/usb.c | 1 +
drivers/usb/host/isp1760-hcd.c | 3 +
drivers/usb/serial/cp210x.c | 1 +
drivers/vhost/scsi.c | 6 +-
drivers/xen/manage.c | 8 +-
fs/autofs4/dev-ioctl.c | 8 +-
fs/binfmt_elf.c | 5 +-
fs/btrfs/ctree.c | 17 +--
fs/btrfs/disk-io.c | 11 +-
fs/btrfs/tree-log.c | 93 ++++++++++++--
fs/debugfs/inode.c | 34 ++---
fs/gfs2/acl.c | 2 +-
fs/jffs2/scan.c | 5 +
fs/nfs/callback.c | 8 +-
fs/nfs/callback_xdr.c | 4 +-
fs/nfs/direct.c | 2 +-
fs/nfs/pnfs.c | 41 +++---
fs/ocfs2/quota_local.c | 4 +-
fs/proc/generic.c | 12 --
fs/proc/inode.c | 21 ++++
fs/proc/internal.h | 1 +
fs/proc/task_mmu.c | 67 ++++++----
fs/quota/dquot.c | 18 +--
fs/quota/quota_v1.c | 4 +-
fs/quota/quota_v2.c | 10 +-
fs/xfs/xfs_bmap.c | 6 +-
fs/xfs/xfs_buf_item.c | 4 +
fs/xfs/xfs_inode.c | 2 +
fs/xfs/xfs_symlink_remote.c | 2 +
fs/xfs/xfs_trans.c | 1 +
include/linux/fsnotify.h | 6 +-
include/linux/hugetlb.h | 8 +-
include/linux/nfs_xdr.h | 2 +-
include/linux/quota.h | 4 +-
include/linux/swapops.h | 4 +
include/linux/usb/hcd.h | 3 +
include/net/ip_fib.h | 4 +-
include/target/target_core_base.h | 2 +-
include/trace/events/kmem.h | 7 +-
kernel/debug/kdb/kdb_main.c | 2 +-
kernel/locking/rtmutex.c | 3 +-
kernel/sched/rt.c | 17 ++-
kernel/softirq.c | 6 +-
kernel/time/ntp.c | 11 ++
kernel/trace/ring_buffer.c | 40 +++++-
kernel/trace/trace.c | 2 +-
mm/compaction.c | 2 +-
mm/gup.c | 25 ++--
mm/hugetlb.c | 124 +++++++++++++-----
mm/memory-failure.c | 2 -
mm/memory.c | 2 +-
mm/migrate.c | 5 +-
mm/mmap.c | 4 +-
mm/nommu.c | 4 +-
mm/page_alloc.c | 12 +-
net/caif/chnl_net.c | 1 -
net/ceph/osd_client.c | 30 +++--
net/ipv4/igmp.c | 11 +-
net/ipv6/mcast.c | 9 +-
net/llc/sysctl_net_llc.c | 8 +-
net/rds/sysctl.c | 4 +-
net/sctp/socket.c | 7 ++
security/smack/smack.h | 10 ++
security/smack/smack_lsm.c | 20 +--
sound/pci/hda/patch_realtek.c | 1 +
sound/pci/hda/patch_sigmatel.c | 31 +++++
sound/pci/riptide/riptide.c | 27 ++--
sound/pci/rme9652/hdspm.c | 6 +
sound/soc/pxa/mioa701_wm9713.c | 2 +-
179 files changed, 1513 insertions(+), 889 deletions(-)
Aaron Lu (1):
ACPI / video: Add some Samsung models to disable_native_backlight list
Adrian Knoth (1):
ALSA: hdspm - Constrain periods to 2 on older cards
Al Viro (3):
debugfs: leave freeing a symlink body until inode eviction
procfs: fix race between symlink removals and traversals
autofs4 copy_dev_ioctl(): keep the value of ->size we'd used for allocation
Alan Stern (2):
USB: add flag for HCDs that can't receive wakeup requests (isp1760-hcd)
USB: fix use-after-free bug in usb_hcd_unlink_urb()
Alex Deucher (3):
drm/radeon: only enable kv/kb dpm interrupts once v3
drm/radeon/dp: Set EDP_CONFIGURATION_SET for bridge chips if necessary
drm/radeon: fix voltage setup on hawaii
Alexander Duyck (1):
fib_trie: Fix /proc/net/fib_trie when CONFIG_IP_MULTIPLE_TABLES is not defined
Alexander Usyskin (2):
mei: mask interrupt set bit on clean reset bit
mei: me: release hw from reset only during the reset flow
Alexey Brodkin (1):
ARC: fix page address calculation if PAGE_OFFSET != LINUX_LINK_BASE
Andrew Elble (1):
GFS2: Fix crash during ACL deletion in acl max entry check in gfs2_set_acl()
Andrey Ryabinin (1):
smack: fix possible use after frees in task_security() callers
Antti Palosaari (1):
[media] si2168: define symbol rate limits
Arnd Bergmann (1):
cpufreq: s3c: remove incorrect __init annotations
Calvin Owens (1):
ksoftirqd: Enable IRQs and call cond_resched() before poking RCU
Chen Jie (1):
jffs2: fix handling of corrupted summary length
Chen-Yu Tsai (1):
clk: sunxi: Support factor clocks with N factor starting not from 0
Christian König (1):
drm/radeon: workaround for CP HW bug on CIK
Christophe Ricard (2):
tpm/tpm_i2c_stm_st33: Fix potential bug in tpm_stm_i2c_send
tpm/tpm_i2c_stm_st33: Add status check when reading data on the FIFO
Cyrille Pitchen (2):
tty/serial: at91: enable peripheral clock before accessing I/O registers
tty/serial: at91: fix error handling in atmel_serial_probe()
Dan Carpenter (3):
efi: Small leak on error in runtime map code
ALSA: off by one bug in snd_riptide_joystick_probe()
vhost/scsi: potential memory corruption
Daniel Borkmann (2):
net: sctp: fix race for one-to-many sockets in sendmsg's auto associate
ipv6: mld: fix add_grhead skb_over_panic for devs with large MTUs
Daniel J Blueman (1):
EDAC, amd64_edac: Prevent OOPS with >16 memory controllers
Darrick J. Wong (1):
dm io: reject unsupported DISCARD requests with EOPNOTSUPP
Dave Chinner (4):
xfs: ensure buffer types are set correctly
xfs: inode unlink does not set AGI buffer type
xfs: set buf types when converting extent formats
xfs: set superblock buffer type correctly
David Herrmann (1):
HID: input: fix confusion on conflicting mappings
David Hildenbrand (3):
KVM: s390: base hrtimer on a monotonic clock
KVM: s390: avoid memory leaks if __inject_vm() fails
KVM: s390: floating irqs: fix user triggerable endless loop
David Howells (1):
TPM: Add new TPMs to the tail of the list to prevent inadvertent change of dev
David Sterba (2):
btrfs: fix leak of path in btrfs_find_item
btrfs: set proper message level for skinny metadata
Dmitry Eremin-Solenikov (5):
ARM: pxa: add regulator_has_full_constraints to corgi board file
ARM: pxa: add regulator_has_full_constraints to poodle board file
ARM: pxa: add regulator_has_full_constraints to spitz board file
power: gpio-charger: balance enable/disable_irq_wake calls
ARM: 8284/1: sa1100: clear RCSR_SMR on resume
Dmitry Osipenko (1):
ARM: dts: tegra20: fix GR3D, DSI unit and reg base addresses
Dmitry Tunin (1):
Bluetooth: ath3k: Add support of AR3012 bluetooth 13d3:3423 device
Emmanuel Grumbach (1):
iwlwifi: pcie: disable the SCD_BASE_ADDR when we resume from WoWLAN
Eyal Shapira (1):
iwlwifi: mvm: validate tid and sta_id in ba_notif
Fabio K (1):
Bluetooth: Add support for Broadcom BCM20702A1 variant
Filipe Manana (1):
Btrfs: fix fsync data loss after adding hard link to inode
Gavin Shan (1):
powerpc/kernel: Avoid memory corruption at early stage
Geert Uytterhoeven (1):
gpio: rcar: Fix error path for devm_kzalloc() failure
Grazvydas Ignotas (1):
mm/memory.c: actually remap enough memory
Gregory CLEMENT (1):
mmc: sdhci-pxav3: Fix SDR50 and DDR50 capabilities for the Armada 38x flavor
Hans de Goede (6):
samsung-laptop: Add use_native_backlight quirk, and enable it on some models
ACPI / video: Add disable_native_backlight quirk for Dell XPS15 L521X
ACPI / video: Add disable_native_backlight quirk for Samsung 730U3E/740U3E
ACPI / video: Add disable_native_backlight quirk for Samsung 510R
ideapad-laptop: Change Lenovo Yoga 2 series rfkill handling
sunxi: clk: Set sun6i-pll1 n_start = 1
Hector Marco-Gisbert (1):
x86, mm/ASLR: Fix stack randomization on 64-bit systems
Heinrich Siebmanns (1):
Bluetooth: Add support for Broadcom BCM20702A0 variants firmware download
Hon Ching (Vicky) Lo (1):
tpm: Fix NULL return in tpm_ibmvtpm_get_desired_dma
Hui Wang (1):
ALSA: hda - enable mute led quirk for one more hp machine.
Ian Abbott (2):
staging: comedi: comedi_compat32.c: fix COMEDI_CMD copy back
staging: comedi: cb_pcidas64: fix incorrect AI range code handling
Ilya Dryomov (3):
libceph: assert both regular and lingering lists in __remove_osd()
libceph: change from BUG to WARN for __remove_osd() asserts
libceph: fix double __remove_osd() problem
Ilya Nelkenbaum (1):
IB/core: When marshaling ucma path from user-space, clear unused fields
James Hogan (3):
KVM: MIPS: Don't leak FPU/DSP to guest
MIPS: Export FP functions used by lose_fpu(1) for KVM
MIPS: Export MSA functions used by lose_fpu(1) for KVM
Jan Kara (2):
fsnotify: fix handling of renames in audit
quota: Store maximum space limit in bytes
Jason Gerecke (1):
HID: wacom: Report ABS_MISC event for Cintiq Companion Hybrid
Jay Lan (1):
kdb: fix incorrect counts in KDB summary command output
Jeff Layton (1):
nfs: don't call blocking operations while !TASK_RUNNING
Jeff Moyer (1):
cfq-iosched: fix incorrect filing of rt async cfqq
Jiri Kosina (1):
HID: fixup the conflicting keyboard mappings quirk
Jisheng Zhang (3):
mmc: sdhci-pxav3: fix unbalanced clock issues during probe
mmc: sdhci-pxav3: fix race between runtime pm and irq
mmc: sdhci-pxav3: fix setting of pdata->clk_delay_cycles
Johan Hovold (1):
gpio: sysfs: fix gpio attribute-creation race
John Stultz (1):
ntp: Fixup adjtimex freq validation on 32-bit systems
Joonsoo Kim (1):
mm/compaction: fix wrong order check in compact_finished()
Jurgen Kramer (1):
[media] Si2168: increase timeout to fix firmware loading
Kiran Padwal (1):
char: tpm: Add missing error check for devm_kzalloc
Konstantin Khlebnikov (2):
cfq-iosched: handle failure of cfq group allocation
proc/pagemap: walk page tables under pte lock
Krzysztof Kozlowski (2):
power: bq24190: Fix ignored supplicants
power_supply: 88pm860x: Fix leaked power supply on probe fail
Lars-Peter Clausen (1):
ASoC: mioa701_wm9713: Fix speaker event
Lee Duncan (1):
target: Allow Write Exclusive non-reservation holders to READ
Lennart Sorensen (1):
USB: cp210x: add ID for RUGGEDCOM USB Serial Console
Lokesh Vutla (1):
ARM: DRA7: hwmod: Fix boot crash with DEBUG_LL enabled on UART3
Luciano Coelho (2):
iwlwifi: mvm: always use mac color zero
iwlwifi: mvm: fix failure path when power_update fails in add_interface
Malcolm Priestley (1):
[media] lmedm04: Fix usb_submit_urb BOGUS urb xfer, pipe 1 != type 3 in interrupt urb
Marcel Holtmann (1):
Bluetooth: btusb: Add support for Dynex/Insignia USB dongles
Marcin Wojtas (1):
mmc: sdhci-pxav3: Fix Armada 38x controller's caps according to erratum ERR-7878951
Markos Chandras (2):
MIPS: asm: asmmacro: Replace "add" instructions with "addu"
MIPS: kernel: cps-vec: Replace "addi" with "addiu"
Martin Vajnar (1):
hx4700: regulator: declare full constraints
Matej Dubovy (1):
Bluetooth: btusb: Add support for Lite-On (04ca) Broadcom based, BCM43142
Matthew Wilcox (1):
axonram: Fix bug in direct_access
Michel Dänzer (1):
PCI: Fix infinite loop with ROM image of size 0
Mikulas Patocka (4):
cpufreq: speedstep-smi: enable interrupts when waiting
dm mirror: do not degrade the mirror on discard error
dm: fix a race condition in dm_get_md
dm snapshot: fix a possible invalid memory access on unload
Minh Duc Tran (1):
fixed invalid assignment of 64bit mask to host dma_boundary for scatter gather segment boundary limit.
Mitko Haralanov (1):
IB/qib: Do not write EEPROM
Moshe Lazer (1):
IB/core: Fix deadlock on uverbs modify_qp error flow
Naoya Horiguchi (6):
mm/hugetlb: pmd_huge() returns true for non-present hugepage
mm/hugetlb: take page table lock in follow_huge_pmd()
mm/hugetlb: fix getting refcount 0 page in hugetlb_fault()
mm/hugetlb: add migration/hwpoisoned entry check in hugetlb_change_protection
mm/hugetlb: add migration entry check in __unmap_hugepage_range
mm: hwpoison: drop lru_add_drain_all() in __soft_offline_page()
NeilBrown (1):
md/raid5: Fix livelock when array is both resyncing and degraded.
Nicholas Bellinger (7):
iscsi-target: Drop problematic active_ts_list usage
target: Fix PR_APTPL_BUF_LEN buffer size limitation
target: Add missing WRITE_SAME end-of-device sanity check
target: Check for LBA + sectors wrap-around in sbc_parse_cdb
target: Fix R_HOLDER bit usage for AllRegistrants
target: Avoid dropping AllRegistrants reservation during unregister
target: Allow AllRegistrants to re-RESERVE existing reservation
Nicolas Dichtel (1):
caif: remove wrong dev_net_set() call
Nicolas Pitre (1):
vt: provide notifications on selection changes
Oliver Neukum (1):
cdc-acm: add sanity checks
Or Gerlitz (1):
IB/mlx4: Fix wrong usage of IPv4 protocol for multicast attach/detach
Peng Tao (1):
nfs41: .init_read and .init_write can be called with valid pg_lseg
Peter Feiner (1):
mm: softdirty: unmapped addresses between VMAs are clean
Peter Hurley (1):
tty: Prevent untrappable signals from malicious program
Ricardo Ribalda Delgado (1):
PCI: Generate uppercase hex for modalias var in uevent
Rick Dunn (1):
Bluetooth: btusb: Add Broadcom patchram support for ASUSTek devices
Robert Nelson (1):
ARM: dts: am335x-bone*: usb0 is hardwired for peripheral
Roi Dayan (1):
IB/iser: Use correct dma direction when unmapping SGs
Roman Gushchin (2):
mm/mmap.c: fix arithmetic overflow in __vm_enough_memory()
mm/nommu.c: fix arithmetic overflow in __vm_enough_memory()
Ross Lagerwall (1):
xen/manage: Fix USB interaction issues when resuming
Russell King (8):
[media] em28xx: fix em28xx-input removal
[media] em28xx: ensure "closing" messages terminate with a newline
[media] em28xx-input: fix missing newlines
[media] em28xx-core: fix missing newlines
[media] em28xx-audio: fix missing newlines
[media] em28xx-audio: fix missing newlines
[media] em28xx-dvb: fix missing newlines
[media] em28xx-video: fix missing newlines
Sasha Levin (3):
time: adjtimex: Validate the ADJ_FREQUENCY values
net: llc: use correct size for sysctl timeout entries
net: rds: use correct size for max unacked packets and bytes
Scot Doyle (1):
tpm_tis: verify interrupt during init
Sebastian Andrzej Siewior (2):
usb: core: buffer: smallest buffer should start at ARCH_DMA_MINALIGN
locking/rtmutex: Avoid a NULL pointer dereference on deadlock
Sebastian Hesselbarth (1):
mmc: sdhci-pxav3: Remove checks for mandatory host clock
Sergei Shtylyov (1):
clk-gate: fix bit # check in clk_register_gate()
Seth Forshee (1):
HID: i2c-hid: Limit reads to wMaxInputLength bytes for input events
Shobhit Kumar (1):
drm/i915: Correct the IOSF Dev_FN field for IOSF transfers
Soren Brinkmann (1):
clk: zynq: Force CPU_2X clock to be ungated
Stefan Agner (2):
serial: fsl_lpuart: delete timer on shutdown
serial: fsl_lpuart: avoid new transfer while DMA is running
Steven Rostedt (Red Hat) (1):
ring-buffer: Do not wake up a splice waiter when page is not full
Sumit.Saxena@avagotech.com (1):
megaraid_sas: disable interrupt_mask before enabling hardware interrupts
Takashi Iwai (2):
ALSA: hda - Add the pin fixup for HP Envy TS bass speaker
ALSA: hda - Set up GPIO for Toshiba Satellite S50D
Thadeu Lima de Souza Cascardo (1):
blk-throttle: check stats_cpu before reading it from sysfs
Tim Chen (1):
sched/rt: Reduce rq lock contention by eliminating locking of non-feasible target
Tony Battersby (2):
blk-mq: fix double-free in error path
sg: fix read() error reporting
Trond Myklebust (2):
NFSv4.1: Fix a kfree() of uninitialised pointers in decode_cb_sequence_args
NFS: struct nfs_commit_info.lock must always point to inode->i_lock
Uwe Kleine-König (1):
pinctrl: pinctrl-imx: don't use invalid value of conf_reg
Vikram Mulukutla (1):
tracing: Fix unmapping loop in tracing_mark_write
Viresh Kumar (1):
cpufreq: Set cpufreq_cpu_data to NULL before putting kobject
Vlastimil Babka (1):
mm: when stealing freepages, also take pages created by splitting buddy page
honclo (1):
Added Little Endian support to vtpm module
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 001/183] [media] em28xx: fix em28xx-input removal
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
@ 2015-03-06 9:54 ` Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 002/183] [media] em28xx: ensure "closing" messages terminate with a newline Luis Henriques
` (181 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:54 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Russell King, Mauro Carvalho Chehab, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Russell King <rmk+kernel@arm.linux.org.uk>
commit bbfebeea7640973613c484f0281bdd15d68fd873 upstream.
Removing the em28xx-rc module results in the following lockdep splat,
which is caused by trying to call cancel_delayed_work_sync() on an
uninitialised delayed work. Fix this by ensuring we always initialise
the work.
INFO: trying to register non-static key.
the code is fine but needs lockdep annotation.
turning off the locking correctness validator.
CPU: 0 PID: 2183 Comm: rmmod Not tainted 3.18.0+ #1464
Hardware name: Freescale i.MX6 Quad/DualLite (Device Tree)
Backtrace:
[<c0012228>] (dump_backtrace) from [<c00123c0>] (show_stack+0x18/0x1c)
r6:c1419d2c r5:00000000 r4:00000000 r3:00000000
[<c00123a8>] (show_stack) from [<c06e2550>] (dump_stack+0x7c/0x98)
[<c06e24d4>] (dump_stack) from [<c0061c94>] (__lock_acquire+0x16d4/0x1bb0)
r4:edf19f74 r3:df049380
[<c00605c0>] (__lock_acquire) from [<c00626d4>] (lock_acquire+0xb0/0x124)
r10:00000000 r9:c003ba90 r8:00000000 r7:00000000 r6:00000000 r5:edf19f74
r4:00000000
[<c0062624>] (lock_acquire) from [<c003bad4>] (flush_work+0x44/0x264)
r10:00000000 r9:eaa86000 r8:edf190b0 r7:edf19f74 r6:00000001 r5:edf19f64
r4:00000000
[<c003ba90>] (flush_work) from [<c003d8f0>] (__cancel_work_timer+0x8c/0x124)
r7:00000000 r6:00000001 r5:00000000 r4:edf19f64
[<c003d864>] (__cancel_work_timer) from [<c003d99c>] (cancel_delayed_work_sync+0x14/0x18)
r7:00000000 r6:eccc3600 r5:00000000 r4:edf19000
[<c003d988>] (cancel_delayed_work_sync) from [<bf0b5c10>] (em28xx_ir_fini+0x48/0xd8 [em28xx_rc])
[<bf0b5bc8>] (em28xx_ir_fini [em28xx_rc]) from [<bf08a0a8>] (em28xx_unregister_extension+0x40/0x94 [em28xx])
r8:c000edc4 r7:00000081 r6:bf092bf4 r5:bf0b6a2c r4:edf19000 r3:bf0b5bc8
[<bf08a068>] (em28xx_unregister_extension [em28xx]) from [<bf0b64dc>] (em28xx_rc_unregister+0x14/0x1c [em28xx_rc])
r6:00000800 r5:00000000 r4:bf0b6a50 r3:bf0b64c8
[<bf0b64c8>] (em28xx_rc_unregister [em28xx_rc]) from [<c0096710>] (SyS_delete_module+0x11c/0x180)
[<c00965f4>] (SyS_delete_module) from [<c000ec00>] (ret_fast_syscall+0x0/0x48)
r6:00000001 r5:beb0f813 r4:b8b17d00
Fixes: f52226099382 ("[media] em28xx: extend the support for device buttons")
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Reviewed-by: Frank Schäfer <fschaefer.oss@googlemail.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/media/usb/em28xx/em28xx-input.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/media/usb/em28xx/em28xx-input.c b/drivers/media/usb/em28xx/em28xx-input.c
index 56ef49df4f8d..381d60de5654 100644
--- a/drivers/media/usb/em28xx/em28xx-input.c
+++ b/drivers/media/usb/em28xx/em28xx-input.c
@@ -642,8 +642,6 @@ next_button:
if (dev->num_button_polling_addresses) {
memset(dev->button_polling_last_values, 0,
EM28XX_NUM_BUTTON_ADDRESSES_MAX);
- INIT_DELAYED_WORK(&dev->buttons_query_work,
- em28xx_query_buttons);
schedule_delayed_work(&dev->buttons_query_work,
msecs_to_jiffies(dev->button_polling_interval));
}
@@ -677,6 +675,7 @@ static int em28xx_ir_init(struct em28xx *dev)
}
kref_get(&dev->ref);
+ INIT_DELAYED_WORK(&dev->buttons_query_work, em28xx_query_buttons);
if (dev->board.buttons)
em28xx_init_buttons(dev);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 002/183] [media] em28xx: ensure "closing" messages terminate with a newline
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 001/183] [media] em28xx: fix em28xx-input removal Luis Henriques
@ 2015-03-06 9:54 ` Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 003/183] [media] em28xx-input: fix missing newlines Luis Henriques
` (180 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:54 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Russell King, Mauro Carvalho Chehab, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Russell King <rmk+kernel@arm.linux.org.uk>
commit 0418ca6073478f54f1da2e4013fa50d36838de75 upstream.
The lockdep splat addressed in a previous commit revealed that at
least one message in em28xx-input.c was missing a new line:
em28178 #0: Closing input extensionINFO: trying to register non-static key.
Further inspection shows several other messages also miss a new line.
These will be fixed in a subsequent patch.
Fixes: aa929ad783c0 ("[media] em28xx: print a message at disconnect")
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Reviewed-by: Frank Schäfer <fschaefer.oss@googlemail.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/media/usb/em28xx/em28xx-audio.c | 2 +-
drivers/media/usb/em28xx/em28xx-dvb.c | 2 +-
drivers/media/usb/em28xx/em28xx-input.c | 2 +-
drivers/media/usb/em28xx/em28xx-video.c | 2 +-
4 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/media/usb/em28xx/em28xx-audio.c b/drivers/media/usb/em28xx/em28xx-audio.c
index e881ef7b6445..5a090555c750 100644
--- a/drivers/media/usb/em28xx/em28xx-audio.c
+++ b/drivers/media/usb/em28xx/em28xx-audio.c
@@ -982,7 +982,7 @@ static int em28xx_audio_fini(struct em28xx *dev)
return 0;
}
- em28xx_info("Closing audio extension");
+ em28xx_info("Closing audio extension\n");
if (dev->adev.sndcard) {
snd_card_disconnect(dev->adev.sndcard);
diff --git a/drivers/media/usb/em28xx/em28xx-dvb.c b/drivers/media/usb/em28xx/em28xx-dvb.c
index a121ed9561fd..fc5ff59e819a 100644
--- a/drivers/media/usb/em28xx/em28xx-dvb.c
+++ b/drivers/media/usb/em28xx/em28xx-dvb.c
@@ -1635,7 +1635,7 @@ static int em28xx_dvb_fini(struct em28xx *dev)
if (!dev->dvb)
return 0;
- em28xx_info("Closing DVB extension");
+ em28xx_info("Closing DVB extension\n");
dvb = dev->dvb;
client = dvb->i2c_client_tuner;
diff --git a/drivers/media/usb/em28xx/em28xx-input.c b/drivers/media/usb/em28xx/em28xx-input.c
index 381d60de5654..d67bf4d46d53 100644
--- a/drivers/media/usb/em28xx/em28xx-input.c
+++ b/drivers/media/usb/em28xx/em28xx-input.c
@@ -811,7 +811,7 @@ static int em28xx_ir_fini(struct em28xx *dev)
return 0;
}
- em28xx_info("Closing input extension");
+ em28xx_info("Closing input extension\n");
em28xx_shutdown_buttons(dev);
diff --git a/drivers/media/usb/em28xx/em28xx-video.c b/drivers/media/usb/em28xx/em28xx-video.c
index f072d554b889..f4d5e577a49c 100644
--- a/drivers/media/usb/em28xx/em28xx-video.c
+++ b/drivers/media/usb/em28xx/em28xx-video.c
@@ -1978,7 +1978,7 @@ static int em28xx_v4l2_fini(struct em28xx *dev)
if (v4l2 == NULL)
return 0;
- em28xx_info("Closing video extension");
+ em28xx_info("Closing video extension\n");
mutex_lock(&dev->lock);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 003/183] [media] em28xx-input: fix missing newlines
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 001/183] [media] em28xx: fix em28xx-input removal Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 002/183] [media] em28xx: ensure "closing" messages terminate with a newline Luis Henriques
@ 2015-03-06 9:54 ` Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 004/183] [media] em28xx-core: " Luis Henriques
` (179 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:54 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Russell King, Mauro Carvalho Chehab, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Russell King <rmk+kernel@arm.linux.org.uk>
commit ebfd59cf549899a166d595bf1eab7eec3299ebe7 upstream.
Inspection shows that newlines are missing from several kernel messages
in em28xx-input. Fix these.
Fixes: 5025076aadfe ("[media] em28xx-input: implement em28xx_ops: suspend/resume hooks")
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Reviewed-by: Frank Schäfer <fschaefer.oss@googlemail.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/media/usb/em28xx/em28xx-input.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/media/usb/em28xx/em28xx-input.c b/drivers/media/usb/em28xx/em28xx-input.c
index d67bf4d46d53..2d73a171693e 100644
--- a/drivers/media/usb/em28xx/em28xx-input.c
+++ b/drivers/media/usb/em28xx/em28xx-input.c
@@ -839,7 +839,7 @@ static int em28xx_ir_suspend(struct em28xx *dev)
if (dev->is_audio_only)
return 0;
- em28xx_info("Suspending input extension");
+ em28xx_info("Suspending input extension\n");
if (ir)
cancel_delayed_work_sync(&ir->work);
cancel_delayed_work_sync(&dev->buttons_query_work);
@@ -856,7 +856,7 @@ static int em28xx_ir_resume(struct em28xx *dev)
if (dev->is_audio_only)
return 0;
- em28xx_info("Resuming input extension");
+ em28xx_info("Resuming input extension\n");
/* if suspend calls ir_raw_event_unregister(), the should call
ir_raw_event_register() */
if (ir)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 004/183] [media] em28xx-core: fix missing newlines
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (2 preceding siblings ...)
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 003/183] [media] em28xx-input: fix missing newlines Luis Henriques
@ 2015-03-06 9:54 ` Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 005/183] [media] em28xx-audio: " Luis Henriques
` (178 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:54 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Russell King, Mauro Carvalho Chehab, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Russell King <rmk+kernel@arm.linux.org.uk>
commit 522adc7c1f70d302155bb07f7fdf5a7fe4ff9094 upstream.
Inspection shows that newlines are missing from several kernel messages
in em28xx-core. Fix these.
Fixes: 9c669b731470 ("[media] em28xx: add suspend/resume to em28xx_ops")
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Reviewed-by: Frank Schäfer <fschaefer.oss@googlemail.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/media/usb/em28xx/em28xx-core.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/media/usb/em28xx/em28xx-core.c b/drivers/media/usb/em28xx/em28xx-core.c
index 523d7e92bf47..f0832cf8e0ab 100644
--- a/drivers/media/usb/em28xx/em28xx-core.c
+++ b/drivers/media/usb/em28xx/em28xx-core.c
@@ -1113,7 +1113,7 @@ int em28xx_suspend_extension(struct em28xx *dev)
{
const struct em28xx_ops *ops = NULL;
- em28xx_info("Suspending extensions");
+ em28xx_info("Suspending extensions\n");
mutex_lock(&em28xx_devlist_mutex);
list_for_each_entry(ops, &em28xx_extension_devlist, next) {
if (ops->suspend)
@@ -1127,7 +1127,7 @@ int em28xx_resume_extension(struct em28xx *dev)
{
const struct em28xx_ops *ops = NULL;
- em28xx_info("Resuming extensions");
+ em28xx_info("Resuming extensions\n");
mutex_lock(&em28xx_devlist_mutex);
list_for_each_entry(ops, &em28xx_extension_devlist, next) {
if (ops->resume)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 005/183] [media] em28xx-audio: fix missing newlines
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (3 preceding siblings ...)
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 004/183] [media] em28xx-core: " Luis Henriques
@ 2015-03-06 9:54 ` Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 006/183] " Luis Henriques
` (177 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:54 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Russell King, Mauro Carvalho Chehab, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Russell King <rmk+kernel@arm.linux.org.uk>
commit 7818b0aab87b680fb10f68eccebeeb6cd8283c73 upstream.
Inspection shows that newlines are missing from several kernel messages
in em28xx-audio. Fix these.
Fixes: 1b3fd2d34266 ("[media] em28xx-audio: don't hardcode audio URB calculus")
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Reviewed-by: Frank Schäfer <fschaefer.oss@googlemail.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/media/usb/em28xx/em28xx-audio.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/media/usb/em28xx/em28xx-audio.c b/drivers/media/usb/em28xx/em28xx-audio.c
index 5a090555c750..2b463f145962 100644
--- a/drivers/media/usb/em28xx/em28xx-audio.c
+++ b/drivers/media/usb/em28xx/em28xx-audio.c
@@ -821,7 +821,7 @@ static int em28xx_audio_urb_init(struct em28xx *dev)
if (urb_size > ep_size * npackets)
npackets = DIV_ROUND_UP(urb_size, ep_size);
- em28xx_info("Number of URBs: %d, with %d packets and %d size",
+ em28xx_info("Number of URBs: %d, with %d packets and %d size\n",
num_urb, npackets, urb_size);
/* Estimate the bytes per period */
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 006/183] [media] em28xx-audio: fix missing newlines
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (4 preceding siblings ...)
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 005/183] [media] em28xx-audio: " Luis Henriques
@ 2015-03-06 9:54 ` Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 007/183] [media] em28xx-dvb: " Luis Henriques
` (176 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:54 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Russell King, Mauro Carvalho Chehab, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Russell King <rmk+kernel@arm.linux.org.uk>
commit fbaa48d1853002c2e7bcf12c1fdc0f6fb16d1525 upstream.
Inspection shows that newlines are missing from several kernel messages
in em28xx-audio. Fix these.
Fixes: 6d746f91f230 ("[media] em28xx-audio: implement em28xx_ops: suspend/resume hooks")
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Reviewed-by: Frank Schäfer <fschaefer.oss@googlemail.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/media/usb/em28xx/em28xx-audio.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/media/usb/em28xx/em28xx-audio.c b/drivers/media/usb/em28xx/em28xx-audio.c
index 2b463f145962..d04d9be10019 100644
--- a/drivers/media/usb/em28xx/em28xx-audio.c
+++ b/drivers/media/usb/em28xx/em28xx-audio.c
@@ -1006,7 +1006,7 @@ static int em28xx_audio_suspend(struct em28xx *dev)
if (!dev->has_alsa_audio)
return 0;
- em28xx_info("Suspending audio extension");
+ em28xx_info("Suspending audio extension\n");
em28xx_deinit_isoc_audio(dev);
atomic_set(&dev->adev.stream_started, 0);
return 0;
@@ -1020,7 +1020,7 @@ static int em28xx_audio_resume(struct em28xx *dev)
if (!dev->has_alsa_audio)
return 0;
- em28xx_info("Resuming audio extension");
+ em28xx_info("Resuming audio extension\n");
/* Nothing to do other than schedule_work() ?? */
schedule_work(&dev->adev.wq_trigger);
return 0;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 007/183] [media] em28xx-dvb: fix missing newlines
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (5 preceding siblings ...)
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 006/183] " Luis Henriques
@ 2015-03-06 9:54 ` Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 008/183] [media] em28xx-video: " Luis Henriques
` (175 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:54 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Russell King, Mauro Carvalho Chehab, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Russell King <rmk+kernel@arm.linux.org.uk>
commit a084c57fc1ccd24ef8e6ca41e75afa745d5dbb98 upstream.
Inspection shows that newlines are missing from several kernel messages
in em28xx-dvb. Fix these.
Fixes: ca2b46dacbf5 ("[media] em28xx-dvb: implement em28xx_ops: suspend/resume hooks")
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Reviewed-by: Frank Schäfer <fschaefer.oss@googlemail.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/media/usb/em28xx/em28xx-dvb.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/drivers/media/usb/em28xx/em28xx-dvb.c b/drivers/media/usb/em28xx/em28xx-dvb.c
index fc5ff59e819a..26ada1ae166e 100644
--- a/drivers/media/usb/em28xx/em28xx-dvb.c
+++ b/drivers/media/usb/em28xx/em28xx-dvb.c
@@ -1682,17 +1682,17 @@ static int em28xx_dvb_suspend(struct em28xx *dev)
if (!dev->board.has_dvb)
return 0;
- em28xx_info("Suspending DVB extension");
+ em28xx_info("Suspending DVB extension\n");
if (dev->dvb) {
struct em28xx_dvb *dvb = dev->dvb;
if (dvb->fe[0]) {
ret = dvb_frontend_suspend(dvb->fe[0]);
- em28xx_info("fe0 suspend %d", ret);
+ em28xx_info("fe0 suspend %d\n", ret);
}
if (dvb->fe[1]) {
dvb_frontend_suspend(dvb->fe[1]);
- em28xx_info("fe1 suspend %d", ret);
+ em28xx_info("fe1 suspend %d\n", ret);
}
}
@@ -1709,19 +1709,19 @@ static int em28xx_dvb_resume(struct em28xx *dev)
if (!dev->board.has_dvb)
return 0;
- em28xx_info("Resuming DVB extension");
+ em28xx_info("Resuming DVB extension\n");
if (dev->dvb) {
struct em28xx_dvb *dvb = dev->dvb;
struct i2c_client *client = dvb->i2c_client_tuner;
if (dvb->fe[0]) {
ret = dvb_frontend_resume(dvb->fe[0]);
- em28xx_info("fe0 resume %d", ret);
+ em28xx_info("fe0 resume %d\n", ret);
}
if (dvb->fe[1]) {
ret = dvb_frontend_resume(dvb->fe[1]);
- em28xx_info("fe1 resume %d", ret);
+ em28xx_info("fe1 resume %d\n", ret);
}
/* remove I2C tuner */
if (client) {
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 008/183] [media] em28xx-video: fix missing newlines
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (6 preceding siblings ...)
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 007/183] [media] em28xx-dvb: " Luis Henriques
@ 2015-03-06 9:54 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 009/183] ARM: pxa: add regulator_has_full_constraints to corgi board file Luis Henriques
` (174 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:54 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Russell King, Mauro Carvalho Chehab, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Russell King <rmk+kernel@arm.linux.org.uk>
commit 32e63f0368ed16e5ac417dc0bc2a5f8acbfb1511 upstream.
Inspection shows that newlines are missing from several kernel messages
in em28xx-video. Fix these.
Fixes: a61f68119af3 ("[media] em28xx-video: implement em28xx_ops: suspend/resume hooks")
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Reviewed-by: Frank Schäfer <fschaefer.oss@googlemail.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/media/usb/em28xx/em28xx-video.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/media/usb/em28xx/em28xx-video.c b/drivers/media/usb/em28xx/em28xx-video.c
index f4d5e577a49c..69810fa0151a 100644
--- a/drivers/media/usb/em28xx/em28xx-video.c
+++ b/drivers/media/usb/em28xx/em28xx-video.c
@@ -2027,7 +2027,7 @@ static int em28xx_v4l2_suspend(struct em28xx *dev)
if (!dev->has_video)
return 0;
- em28xx_info("Suspending video extension");
+ em28xx_info("Suspending video extension\n");
em28xx_stop_urbs(dev);
return 0;
}
@@ -2040,7 +2040,7 @@ static int em28xx_v4l2_resume(struct em28xx *dev)
if (!dev->has_video)
return 0;
- em28xx_info("Resuming video extension");
+ em28xx_info("Resuming video extension\n");
/* what do we do here */
return 0;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 009/183] ARM: pxa: add regulator_has_full_constraints to corgi board file
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (7 preceding siblings ...)
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 008/183] [media] em28xx-video: " Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 010/183] ARM: pxa: add regulator_has_full_constraints to poodle " Luis Henriques
` (173 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dmitry Eremin-Solenikov, Robert Jarzmik, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Eremin-Solenikov <dbaryshkov@gmail.com>
commit 271e80176aae4e5b481f4bb92df9768c6075bbca upstream.
Add regulator_has_full_constraints() call to corgi board file to let
regulator core know that we do not have any additional regulators left.
This lets it substitute unprovided regulators with dummy ones.
This fixes the following warnings that can be seen on corgi if
regulators are enabled:
ads7846 spi1.0: unable to get regulator: -517
spi spi1.0: Driver ads7846 requests probe deferral
wm8731 0-001b: Failed to get supply 'AVDD': -517
wm8731 0-001b: Failed to request supplies: -517
wm8731 0-001b: ASoC: failed to probe component -517
corgi-audio corgi-audio: ASoC: failed to instantiate card -517
Signed-off-by: Dmitry Eremin-Solenikov <dbaryshkov@gmail.com>
Acked-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Robert Jarzmik <robert.jarzmik@free.fr>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/arm/mach-pxa/corgi.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/arch/arm/mach-pxa/corgi.c b/arch/arm/mach-pxa/corgi.c
index 91dd1c7cdbcd..b42615a60c25 100644
--- a/arch/arm/mach-pxa/corgi.c
+++ b/arch/arm/mach-pxa/corgi.c
@@ -26,6 +26,7 @@
#include <linux/i2c.h>
#include <linux/i2c/pxa-i2c.h>
#include <linux/io.h>
+#include <linux/regulator/machine.h>
#include <linux/spi/spi.h>
#include <linux/spi/ads7846.h>
#include <linux/spi/corgi_lcd.h>
@@ -752,6 +753,8 @@ static void __init corgi_init(void)
sharpsl_nand_partitions[1].size = 53 * 1024 * 1024;
platform_add_devices(devices, ARRAY_SIZE(devices));
+
+ regulator_has_full_constraints();
}
static void __init fixup_corgi(struct tag *tags, char **cmdline)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 010/183] ARM: pxa: add regulator_has_full_constraints to poodle board file
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (8 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 009/183] ARM: pxa: add regulator_has_full_constraints to corgi board file Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 011/183] ARM: pxa: add regulator_has_full_constraints to spitz " Luis Henriques
` (172 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dmitry Eremin-Solenikov, Robert Jarzmik, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Eremin-Solenikov <dbaryshkov@gmail.com>
commit 9bc78f32c2e430aebf6def965b316aa95e37a20c upstream.
Add regulator_has_full_constraints() call to poodle board file to let
regulator core know that we do not have any additional regulators left.
This lets it substitute unprovided regulators with dummy ones.
This fixes the following warnings that can be seen on poodle if
regulators are enabled:
ads7846 spi1.0: unable to get regulator: -517
spi spi1.0: Driver ads7846 requests probe deferral
wm8731 0-001b: Failed to get supply 'AVDD': -517
wm8731 0-001b: Failed to request supplies: -517
wm8731 0-001b: ASoC: failed to probe component -517
Signed-off-by: Dmitry Eremin-Solenikov <dbaryshkov@gmail.com>
Acked-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Robert Jarzmik <robert.jarzmik@free.fr>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/arm/mach-pxa/poodle.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/arm/mach-pxa/poodle.c b/arch/arm/mach-pxa/poodle.c
index 131991629116..e81d216b05e4 100644
--- a/arch/arm/mach-pxa/poodle.c
+++ b/arch/arm/mach-pxa/poodle.c
@@ -25,6 +25,7 @@
#include <linux/gpio.h>
#include <linux/i2c.h>
#include <linux/i2c/pxa-i2c.h>
+#include <linux/regulator/machine.h>
#include <linux/spi/spi.h>
#include <linux/spi/ads7846.h>
#include <linux/spi/pxa2xx_spi.h>
@@ -455,6 +456,7 @@ static void __init poodle_init(void)
pxa_set_i2c_info(NULL);
i2c_register_board_info(0, ARRAY_AND_SIZE(poodle_i2c_devices));
poodle_init_spi();
+ regulator_has_full_constraints();
}
static void __init fixup_poodle(struct tag *tags, char **cmdline)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 011/183] ARM: pxa: add regulator_has_full_constraints to spitz board file
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (9 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 010/183] ARM: pxa: add regulator_has_full_constraints to poodle " Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 012/183] hx4700: regulator: declare full constraints Luis Henriques
` (171 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dmitry Eremin-Solenikov, Robert Jarzmik, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Eremin-Solenikov <dbaryshkov@gmail.com>
commit baad2dc49c5d970ea881d92981a1b76c94a7b7a1 upstream.
Add regulator_has_full_constraints() call to spitz board file to let
regulator core know that we do not have any additional regulators left.
This lets it substitute unprovided regulators with dummy ones.
This fixes the following warnings that can be seen on spitz if
regulators are enabled:
ads7846 spi2.0: unable to get regulator: -517
spi spi2.0: Driver ads7846 requests probe deferral
Signed-off-by: Dmitry Eremin-Solenikov <dbaryshkov@gmail.com>
Acked-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Robert Jarzmik <robert.jarzmik@free.fr>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/arm/mach-pxa/spitz.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/arm/mach-pxa/spitz.c b/arch/arm/mach-pxa/spitz.c
index 840c3a48e720..f4f713b2fea2 100644
--- a/arch/arm/mach-pxa/spitz.c
+++ b/arch/arm/mach-pxa/spitz.c
@@ -970,6 +970,8 @@ static void __init spitz_init(void)
spitz_nor_init();
spitz_nand_init();
spitz_i2c_init();
+
+ regulator_has_full_constraints();
}
static void __init spitz_fixup(struct tag *tags, char **cmdline)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 012/183] hx4700: regulator: declare full constraints
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (10 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 011/183] ARM: pxa: add regulator_has_full_constraints to spitz " Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 013/183] HID: input: fix confusion on conflicting mappings Luis Henriques
` (170 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Martin Vajnar, Robert Jarzmik, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Martin Vajnar <martin.vajnar@gmail.com>
commit a52d209336f8fc7483a8c7f4a8a7d2a8e1692a6c upstream.
Since the removal of CONFIG_REGULATOR_DUMMY option, the touchscreen stopped
working. This patch enables the "replacement" for REGULATOR_DUMMY and
allows the touchscreen to work even though there is no regulator for "vcc".
Signed-off-by: Martin Vajnar <martin.vajnar@gmail.com>
Signed-off-by: Robert Jarzmik <robert.jarzmik@free.fr>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/arm/mach-pxa/hx4700.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/arm/mach-pxa/hx4700.c b/arch/arm/mach-pxa/hx4700.c
index c66ad4edc5e3..5fb41ad6e3bc 100644
--- a/arch/arm/mach-pxa/hx4700.c
+++ b/arch/arm/mach-pxa/hx4700.c
@@ -893,6 +893,8 @@ static void __init hx4700_init(void)
mdelay(10);
gpio_set_value(GPIO71_HX4700_ASIC3_nRESET, 1);
mdelay(10);
+
+ regulator_has_full_constraints();
}
MACHINE_START(H4700, "HP iPAQ HX4700")
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 013/183] HID: input: fix confusion on conflicting mappings
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (11 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 012/183] hx4700: regulator: declare full constraints Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 014/183] HID: fixup the conflicting keyboard mappings quirk Luis Henriques
` (169 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: David Herrmann, Jiri Kosina, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: David Herrmann <dh.herrmann@gmail.com>
commit 6ce901eb61aa30ba8565c62049ee80c90728ef14 upstream.
On an PC-101/103/104 keyboard (American layout) the 'Enter' key and its
neighbours look like this:
+---+ +---+ +-------+
| 1 | | 2 | | 5 |
+---+ +---+ +-------+
+---+ +-----------+
| 3 | | 4 |
+---+ +-----------+
On a PC-102/105 keyboard (European layout) it looks like this:
+---+ +---+ +-------+
| 1 | | 2 | | |
+---+ +---+ +-+ 4 |
+---+ +---+ | |
| 3 | | 5 | | |
+---+ +---+ +-----+
(Note that the number of keys is the same, but key '5' is moved down and
the shape of key '4' is changed. Keys '1' to '3' are exactly the same.)
The keys 1-4 report the same scan-code in HID in both layouts, even though
the keysym they produce is usually different depending on the XKB-keymap
used by user-space.
However, key '5' (US 'backslash'/'pipe') reports 0x31 for the upper layout
and 0x32 for the lower layout, as defined by the HID spec. This is highly
confusing as the linux-input API uses a single keycode for both.
So far, this was never a problem as there never has been a keyboard with
both of those keys present at the same time. It would have to look
something like this:
+---+ +---+ +-------+
| 1 | | 2 | | x31 |
+---+ +---+ +-------+
+---+ +---+ +-----+
| 3 | |x32| | 4 |
+---+ +---+ +-----+
HID can represent such a keyboard, but the linux-input API cannot.
Furthermore, any user-space mapping would be confused by this and,
luckily, no-one ever produced such hardware.
Now, the HID input layer fixed this mess by mapping both 0x31 and 0x32 to
the same keycode (KEY_BACKSLASH==0x2b). As only one of both physical keys
is present on a hardware, this works just fine.
Lets introduce hardware-vendors into this:
------------------------------------------
Unfortunately, it seems way to expensive to produce a different device for
American and European layouts. Therefore, hardware-vendors put both keys,
(0x31 and 0x32) on the same keyboard, but only one of them is hooked up
to the physical button, the other one is 'dead'.
This means, they can use the same hardware, with a different button-layout
and automatically produce the correct HID events for American *and*
European layouts. This is unproblematic for normal keyboards, as the
'dead' key will never report any KEY-DOWN events. But RollOver keyboards
send the whole matrix on each key-event, allowing n-key roll-over mode.
This means, we get a 0x31 and 0x32 event on each key-press. One of them
will always be 0, the other reports the real state. As we map both to the
same keycode, we will get spurious key-events, even though the real
key-state never changed.
The easiest way would be to blacklist 'dead' keys and never handle those.
We could simply read the 'country' tag of USB devices and blacklist either
key according to the layout. But... hardware vendors... want the same
device for all countries and thus many of them set 'country' to 0 for all
devices. Meh..
So we have to deal with this properly. As we cannot know which of the keys
is 'dead', we either need a heuristic and track those keys, or we simply
make use of our value-tracking for HID fields. We simply ignore HID events
for absolute data if the data didn't change. As HID tracks events on the
HID level, we haven't done the keycode translation, yet. Therefore, the
'dead' key is tracked independently of the real key, therefore, any events
on it will be ignored.
This patch simply discards any HID events for absolute data if it didn't
change compared to the last report. We need to ignore relative and
buffered-byte reports for obvious reasons. But those cannot be affected by
this bug, so we're fine.
Preferably, we'd do this filtering on the HID-core level. But this might
break a lot of custom drivers, if they do not follow the HID specs.
Therefore, we do this late in hid-input just before we inject it into the
input layer (which does the exact same filtering, but on the keycode
level).
If this turns out to break some devices, we might have to limit filtering
to EV_KEY events. But lets try to do the Right Thing first, and properly
filter any absolute data that didn't change.
This patch is tagged for 'stable' as it fixes a lot of n-key RollOver
hardware. We might wanna wait with backporting for a while, before we know
it doesn't break anything else, though.
Reported-by: Adam Goode <adam@spicenitz.org>
Reported-by: Fredrik Hallenberg <megahallon@gmail.com>
Tested-by: Fredrik Hallenberg <megahallon@gmail.com>
Signed-off-by: David Herrmann <dh.herrmann@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/hid/hid-input.c | 16 ++++++++++++++++
1 file changed, 16 insertions(+)
diff --git a/drivers/hid/hid-input.c b/drivers/hid/hid-input.c
index 89ce91883eba..323c3ba85a5d 100644
--- a/drivers/hid/hid-input.c
+++ b/drivers/hid/hid-input.c
@@ -1098,6 +1098,22 @@ void hidinput_hid_event(struct hid_device *hid, struct hid_field *field, struct
return;
}
+ /*
+ * Ignore reports for absolute data if the data didn't change. This is
+ * not only an optimization but also fixes 'dead' key reports. Some
+ * RollOver implementations for localized keys (like BACKSLASH/PIPE; HID
+ * 0x31 and 0x32) report multiple keys, even though a localized keyboard
+ * can only have one of them physically available. The 'dead' keys
+ * report constant 0. As all map to the same keycode, they'd confuse
+ * the input layer. If we filter the 'dead' keys on the HID level, we
+ * skip the keycode translation and only forward real events.
+ */
+ if (!(field->flags & (HID_MAIN_ITEM_RELATIVE |
+ HID_MAIN_ITEM_BUFFERED_BYTE)) &&
+ usage->usage_index < field->maxusage &&
+ value == field->value[usage->usage_index])
+ return;
+
/* report the usage code as scancode if the key status has changed */
if (usage->type == EV_KEY && !!test_bit(usage->code, input->key) != value)
input_event(input, EV_MSC, MSC_SCAN, usage->hid);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 014/183] HID: fixup the conflicting keyboard mappings quirk
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (12 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 013/183] HID: input: fix confusion on conflicting mappings Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 015/183] ARM: dts: tegra20: fix GR3D, DSI unit and reg base addresses Luis Henriques
` (168 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Jiri Kosina, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiri Kosina <jkosina@suse.cz>
commit 8e7b341037db1835ee6eea64663013cbfcf33575 upstream.
The ignore check that got added in 6ce901eb61 ("HID: input: fix confusion
on conflicting mappings") needs to properly check for VARIABLE reports
as well (ARRAY reports should be ignored), otherwise legitimate keyboards
might break.
Fixes: 6ce901eb61 ("HID: input: fix confusion on conflicting mappings")
Reported-by: Fredrik Hallenberg <megahallon@gmail.com>
Reported-by: David Herrmann <dh.herrmann@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/hid/hid-input.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/hid/hid-input.c b/drivers/hid/hid-input.c
index 323c3ba85a5d..79fa1cd9dfdd 100644
--- a/drivers/hid/hid-input.c
+++ b/drivers/hid/hid-input.c
@@ -1110,6 +1110,7 @@ void hidinput_hid_event(struct hid_device *hid, struct hid_field *field, struct
*/
if (!(field->flags & (HID_MAIN_ITEM_RELATIVE |
HID_MAIN_ITEM_BUFFERED_BYTE)) &&
+ (field->flags & HID_MAIN_ITEM_VARIABLE) &&
usage->usage_index < field->maxusage &&
value == field->value[usage->usage_index])
return;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 015/183] ARM: dts: tegra20: fix GR3D, DSI unit and reg base addresses
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (13 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 014/183] HID: fixup the conflicting keyboard mappings quirk Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 016/183] megaraid_sas: disable interrupt_mask before enabling hardware interrupts Luis Henriques
` (167 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dmitry Osipenko, Thierry Reding, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Osipenko <digetx@gmail.com>
commit de47699d005996b41cea590c6098078ac12058be upstream.
Commit 58ecb23f64ee ("ARM: tegra: add missing unit addresses to DT") added
unit address and changed reg base for GR3D and DSI host1x modules, but these
addresses belongs to GR2D and TVO modules respectively. Fix it by changing
modules unit and reg base addresses to proper ones.
Signed-off-by: Dmitry Osipenko <digetx@gmail.com>
Fixes: 58ecb23f64ee (ARM: tegra: add missing unit addresses to DT)
Reviewed-by: Alexandre Courbot <acourbot@nvidia.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/arm/boot/dts/tegra20.dtsi | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm/boot/dts/tegra20.dtsi b/arch/arm/boot/dts/tegra20.dtsi
index a7ddf70df50b..98eeb3d9105d 100644
--- a/arch/arm/boot/dts/tegra20.dtsi
+++ b/arch/arm/boot/dts/tegra20.dtsi
@@ -76,9 +76,9 @@
reset-names = "2d";
};
- gr3d@54140000 {
+ gr3d@54180000 {
compatible = "nvidia,tegra20-gr3d";
- reg = <0x54140000 0x00040000>;
+ reg = <0x54180000 0x00040000>;
clocks = <&tegra_car TEGRA20_CLK_GR3D>;
resets = <&tegra_car 24>;
reset-names = "3d";
@@ -138,9 +138,9 @@
status = "disabled";
};
- dsi@542c0000 {
+ dsi@54300000 {
compatible = "nvidia,tegra20-dsi";
- reg = <0x542c0000 0x00040000>;
+ reg = <0x54300000 0x00040000>;
clocks = <&tegra_car TEGRA20_CLK_DSI>;
resets = <&tegra_car 48>;
reset-names = "dsi";
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 016/183] megaraid_sas: disable interrupt_mask before enabling hardware interrupts
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (14 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 015/183] ARM: dts: tegra20: fix GR3D, DSI unit and reg base addresses Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 017/183] PCI: Generate uppercase hex for modalias var in uevent Luis Henriques
` (166 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Sumit Saxena, Chaitra Basappa, Christoph Hellwig, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: "Sumit.Saxena@avagotech.com" <Sumit.Saxena@avagotech.com>
commit c2ced1719a1b903350955a511e1666e6d05a7f5b upstream.
Update driver "mask_interrupts" before enable/disable hardware interrupt
in order to avoid missing interrupts because of "mask_interrupts" still
set to 1 and hardware interrupts are enabled.
Signed-off-by: Sumit Saxena <sumit.saxena@avagotech.com>
Signed-off-by: Chaitra Basappa <chaitra.basappa@avagotech.com>
Reviewed-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/scsi/megaraid/megaraid_sas_fusion.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/scsi/megaraid/megaraid_sas_fusion.c b/drivers/scsi/megaraid/megaraid_sas_fusion.c
index 22600419ae9f..9872ccb28f1f 100644
--- a/drivers/scsi/megaraid/megaraid_sas_fusion.c
+++ b/drivers/scsi/megaraid/megaraid_sas_fusion.c
@@ -100,6 +100,8 @@ megasas_enable_intr_fusion(struct megasas_instance *instance)
{
struct megasas_register_set __iomem *regs;
regs = instance->reg_set;
+
+ instance->mask_interrupts = 0;
/* For Thunderbolt/Invader also clear intr on enable */
writel(~0, ®s->outbound_intr_status);
readl(®s->outbound_intr_status);
@@ -108,7 +110,6 @@ megasas_enable_intr_fusion(struct megasas_instance *instance)
/* Dummy readl to force pci flush */
readl(®s->outbound_intr_mask);
- instance->mask_interrupts = 0;
}
/**
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 017/183] PCI: Generate uppercase hex for modalias var in uevent
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (15 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 016/183] megaraid_sas: disable interrupt_mask before enabling hardware interrupts Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 018/183] usb: core: buffer: smallest buffer should start at ARCH_DMA_MINALIGN Luis Henriques
` (165 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Ricardo Ribalda Delgado, Bjorn Helgaas, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ricardo Ribalda Delgado <ricardo.ribalda@gmail.com>
commit 145b3fe579db66fbe999a2bc3fd5b63dffe9636d upstream.
Some implementations of modprobe fail to load the driver for a PCI device
automatically because the "interface" part of the modalias from the kernel
is lowercase, and the modalias from file2alias is uppercase.
The "interface" is the low-order byte of the Class Code, defined in PCI
r3.0, Appendix D. Most interface types defined in the spec do not use
alpha characters, so they won't be affected. For example, 00h, 01h, 10h,
20h, etc. are unaffected.
Print the "interface" byte of the Class Code in uppercase hex, as we
already do for the Vendor ID, Device ID, Class, etc.
Commit 89ec3dcf17fd ("PCI: Generate uppercase hex for modalias interface
class") fixed only half of the problem. Some udev implementations rely on
the uevent file and not the modalias file.
Fixes: d1ded203adf1 ("PCI: add MODALIAS to hotplug event for pci devices")
Fixes: 89ec3dcf17fd ("PCI: Generate uppercase hex for modalias interface class")
Signed-off-by: Ricardo Ribalda Delgado <ricardo.ribalda@gmail.com>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Acked-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/pci/pci-driver.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/pci/pci-driver.c b/drivers/pci/pci-driver.c
index 3f8e3dbcaa7c..e2bab48f6446 100644
--- a/drivers/pci/pci-driver.c
+++ b/drivers/pci/pci-driver.c
@@ -1382,7 +1382,7 @@ static int pci_uevent(struct device *dev, struct kobj_uevent_env *env)
if (add_uevent_var(env, "PCI_SLOT_NAME=%s", pci_name(pdev)))
return -ENOMEM;
- if (add_uevent_var(env, "MODALIAS=pci:v%08Xd%08Xsv%08Xsd%08Xbc%02Xsc%02Xi%02x",
+ if (add_uevent_var(env, "MODALIAS=pci:v%08Xd%08Xsv%08Xsd%08Xbc%02Xsc%02Xi%02X",
pdev->vendor, pdev->device,
pdev->subsystem_vendor, pdev->subsystem_device,
(u8)(pdev->class >> 16), (u8)(pdev->class >> 8),
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 018/183] usb: core: buffer: smallest buffer should start at ARCH_DMA_MINALIGN
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (16 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 017/183] PCI: Generate uppercase hex for modalias var in uevent Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 019/183] tty/serial: at91: enable peripheral clock before accessing I/O registers Luis Henriques
` (164 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Sebastian Andrzej Siewior, Greg Kroah-Hartman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
commit 5efd2ea8c9f4f12916ffc8ba636792ce052f6911 upstream.
the following error pops up during "testusb -a -t 10"
| musb-hdrc musb-hdrc.1.auto: dma_pool_free buffer-128, f134e000/be842000 (bad dma)
hcd_buffer_create() creates a few buffers, the smallest has 32 bytes of
size. ARCH_KMALLOC_MINALIGN is set to 64 bytes. This combo results in
hcd_buffer_alloc() returning memory which is 32 bytes aligned and it
might by identified by buffer_offset() as another buffer. This means the
buffer which is on a 32 byte boundary will not get freed, instead it
tries to free another buffer with the error message.
This patch fixes the issue by creating the smallest DMA buffer with the
size of ARCH_KMALLOC_MINALIGN (or 32 in case ARCH_KMALLOC_MINALIGN is
smaller). This might be 32, 64 or even 128 bytes. The next three pools
will have the size 128, 512 and 2048.
In case the smallest pool is 128 bytes then we have only three pools
instead of four (and zero the first entry in the array).
The last pool size is always 2048 bytes which is the assumed PAGE_SIZE /
2 of 4096. I doubt it makes sense to continue using PAGE_SIZE / 2 where
we would end up with 8KiB buffer in case we have 16KiB pages.
Instead I think it makes sense to have a common size(s) and extend them
if there is need to.
There is a BUILD_BUG_ON() now in case someone has a minalign of more than
128 bytes.
Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Acked-by: Alan Stern <stern@rowland.harvard.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/usb/core/buffer.c | 26 +++++++++++++++++---------
drivers/usb/core/usb.c | 1 +
include/linux/usb/hcd.h | 1 +
3 files changed, 19 insertions(+), 9 deletions(-)
diff --git a/drivers/usb/core/buffer.c b/drivers/usb/core/buffer.c
index 684ef70dc09d..506b969ea7fd 100644
--- a/drivers/usb/core/buffer.c
+++ b/drivers/usb/core/buffer.c
@@ -22,17 +22,25 @@
*/
/* FIXME tune these based on pool statistics ... */
-static const size_t pool_max[HCD_BUFFER_POOLS] = {
- /* platforms without dma-friendly caches might need to
- * prevent cacheline sharing...
- */
- 32,
- 128,
- 512,
- PAGE_SIZE / 2
- /* bigger --> allocate pages */
+static size_t pool_max[HCD_BUFFER_POOLS] = {
+ 32, 128, 512, 2048,
};
+void __init usb_init_pool_max(void)
+{
+ /*
+ * The pool_max values must never be smaller than
+ * ARCH_KMALLOC_MINALIGN.
+ */
+ if (ARCH_KMALLOC_MINALIGN <= 32)
+ ; /* Original value is okay */
+ else if (ARCH_KMALLOC_MINALIGN <= 64)
+ pool_max[0] = 64;
+ else if (ARCH_KMALLOC_MINALIGN <= 128)
+ pool_max[0] = 0; /* Don't use this pool */
+ else
+ BUILD_BUG(); /* We don't allow this */
+}
/* SETUP primitives */
diff --git a/drivers/usb/core/usb.c b/drivers/usb/core/usb.c
index 4d1144990d4c..a92273026ecc 100644
--- a/drivers/usb/core/usb.c
+++ b/drivers/usb/core/usb.c
@@ -1050,6 +1050,7 @@ static int __init usb_init(void)
pr_info("%s: USB support disabled\n", usbcore_name);
return 0;
}
+ usb_init_pool_max();
retval = usb_debugfs_init();
if (retval)
diff --git a/include/linux/usb/hcd.h b/include/linux/usb/hcd.h
index 485cd5e2100c..52598bdce2ba 100644
--- a/include/linux/usb/hcd.h
+++ b/include/linux/usb/hcd.h
@@ -448,6 +448,7 @@ extern const struct dev_pm_ops usb_hcd_pci_pm_ops;
#endif /* CONFIG_PCI */
/* pci-ish (pdev null is ok) buffer alloc/mapping support */
+void usb_init_pool_max(void);
int hcd_buffer_create(struct usb_hcd *hcd);
void hcd_buffer_destroy(struct usb_hcd *hcd);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 019/183] tty/serial: at91: enable peripheral clock before accessing I/O registers
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (17 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 018/183] usb: core: buffer: smallest buffer should start at ARCH_DMA_MINALIGN Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 020/183] tty/serial: at91: fix error handling in atmel_serial_probe() Luis Henriques
` (163 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Cyrille Pitchen, Greg Kroah-Hartman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Cyrille Pitchen <cyrille.pitchen@atmel.com>
commit d4f641876a68d1961e30c202709cc2d484f69f6f upstream.
atmel_serial_probe() calls atmel_init_port(). In turn, atmel_init_port() calls
clk_disable_unprepare() to disable the peripheral clock before returning.
Later atmel_serial_probe() accesses some I/O registers such as the Mode and
Control registers for RS485 support then the Name and Version registers, through a call to
atmel_get_ip_name(), but at that moment the peripheral clock was still
disabled.
Signed-off-by: Cyrille Pitchen <cyrille.pitchen@atmel.com>
Acked-by: Nicolas Ferre <nicolas.ferre@atmel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/tty/serial/atmel_serial.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/drivers/tty/serial/atmel_serial.c b/drivers/tty/serial/atmel_serial.c
index ffefec83a02f..fcb08e87873e 100644
--- a/drivers/tty/serial/atmel_serial.c
+++ b/drivers/tty/serial/atmel_serial.c
@@ -2605,6 +2605,12 @@ static int atmel_serial_probe(struct platform_device *pdev)
device_init_wakeup(&pdev->dev, 1);
platform_set_drvdata(pdev, port);
+ /*
+ * The peripheral clock has been disabled by atmel_init_port():
+ * enable it before accessing I/O registers
+ */
+ clk_prepare_enable(port->clk);
+
if (port->rs485.flags & SER_RS485_ENABLED) {
UART_PUT_MR(&port->uart, ATMEL_US_USMODE_NORMAL);
UART_PUT_CR(&port->uart, ATMEL_US_RTSEN);
@@ -2615,6 +2621,12 @@ static int atmel_serial_probe(struct platform_device *pdev)
*/
atmel_get_ip_name(&port->uart);
+ /*
+ * The peripheral clock can now safely be disabled till the port
+ * is used
+ */
+ clk_disable_unprepare(port->clk);
+
return 0;
err_add_port:
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 020/183] tty/serial: at91: fix error handling in atmel_serial_probe()
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (18 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 019/183] tty/serial: at91: enable peripheral clock before accessing I/O registers Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 021/183] axonram: Fix bug in direct_access Luis Henriques
` (162 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Cyrille Pitchen, Greg Kroah-Hartman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Cyrille Pitchen <cyrille.pitchen@atmel.com>
commit 6fbb9bdf0f3fbe23aeff806489791aa876adaffb upstream.
-EDEFER error wasn't handle properly by atmel_serial_probe().
As an example, when atmel_serial_probe() is called for the first time, we pass
the test_and_set_bit() test to check whether the port has already been
initalized. Then we call atmel_init_port(), which may return -EDEFER, possibly
returned before by clk_get(). Consequently atmel_serial_probe() used to return
this error code WITHOUT clearing the port bit in the "atmel_ports_in_use" mask.
When atmel_serial_probe() was called for the second time, it used to fail on
the test_and_set_bit() function then returning -EBUSY.
When atmel_serial_probe() fails, this patch make it clear the port bit in the
"atmel_ports_in_use" mask, if needed, before returning the error code.
Signed-off-by: Cyrille Pitchen <cyrille.pitchen@atmel.com>
Acked-by: Nicolas Ferre <nicolas.ferre@atmel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/tty/serial/atmel_serial.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/tty/serial/atmel_serial.c b/drivers/tty/serial/atmel_serial.c
index fcb08e87873e..60d05fc2c1c4 100644
--- a/drivers/tty/serial/atmel_serial.c
+++ b/drivers/tty/serial/atmel_serial.c
@@ -2576,7 +2576,7 @@ static int atmel_serial_probe(struct platform_device *pdev)
ret = atmel_init_port(port, pdev);
if (ret)
- goto err;
+ goto err_clear_bit;
if (!atmel_use_pdc_rx(&port->uart)) {
ret = -ENOMEM;
@@ -2637,6 +2637,8 @@ err_alloc_ring:
clk_put(port->clk);
port->clk = NULL;
}
+err_clear_bit:
+ clear_bit(port->uart.line, atmel_ports_in_use);
err:
return ret;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 021/183] axonram: Fix bug in direct_access
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (19 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 020/183] tty/serial: at91: fix error handling in atmel_serial_probe() Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 022/183] btrfs: fix leak of path in btrfs_find_item Luis Henriques
` (161 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Matthew Wilcox, Jens Axboe, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthew Wilcox <matthew.r.wilcox@intel.com>
commit 91117a20245b59f70b563523edbf998a62fc6383 upstream.
The 'pfn' returned by axonram was completely bogus, and has been since
2008.
Signed-off-by: Matthew Wilcox <matthew.r.wilcox@intel.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Reviewed-by: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Signed-off-by: Jens Axboe <axboe@fb.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/powerpc/sysdev/axonram.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/powerpc/sysdev/axonram.c b/arch/powerpc/sysdev/axonram.c
index 47b6b9f81d43..830edc83c12a 100644
--- a/arch/powerpc/sysdev/axonram.c
+++ b/arch/powerpc/sysdev/axonram.c
@@ -156,7 +156,7 @@ axon_ram_direct_access(struct block_device *device, sector_t sector,
}
*kaddr = (void *)(bank->ph_addr + offset);
- *pfn = virt_to_phys(kaddr) >> PAGE_SHIFT;
+ *pfn = virt_to_phys(*kaddr) >> PAGE_SHIFT;
return 0;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 022/183] btrfs: fix leak of path in btrfs_find_item
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (20 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 021/183] axonram: Fix bug in direct_access Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 023/183] ksoftirqd: Enable IRQs and call cond_resched() before poking RCU Luis Henriques
` (160 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: David Sterba, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: David Sterba <dsterba@suse.cz>
commit 381cf6587f8a8a8e981bc0c1aaaa8859b51dc756 upstream.
If btrfs_find_item is called with NULL path it allocates one locally but
does not free it. Affected paths are inserting an orphan item for a file
and for a subvol root.
Move the path allocation to the callers.
Fixes: 3f870c289900 ("btrfs: expand btrfs_find_item() to include find_orphan_item functionality")
Signed-off-by: David Sterba <dsterba@suse.cz>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/btrfs/ctree.c | 17 ++++-------------
fs/btrfs/disk-io.c | 9 ++++++++-
fs/btrfs/tree-log.c | 11 ++++++++++-
3 files changed, 22 insertions(+), 15 deletions(-)
diff --git a/fs/btrfs/ctree.c b/fs/btrfs/ctree.c
index 0e4361805944..49f8392662b6 100644
--- a/fs/btrfs/ctree.c
+++ b/fs/btrfs/ctree.c
@@ -2617,32 +2617,23 @@ static int key_search(struct extent_buffer *b, struct btrfs_key *key,
return 0;
}
-int btrfs_find_item(struct btrfs_root *fs_root, struct btrfs_path *found_path,
+int btrfs_find_item(struct btrfs_root *fs_root, struct btrfs_path *path,
u64 iobjectid, u64 ioff, u8 key_type,
struct btrfs_key *found_key)
{
int ret;
struct btrfs_key key;
struct extent_buffer *eb;
- struct btrfs_path *path;
+
+ ASSERT(path);
key.type = key_type;
key.objectid = iobjectid;
key.offset = ioff;
- if (found_path == NULL) {
- path = btrfs_alloc_path();
- if (!path)
- return -ENOMEM;
- } else
- path = found_path;
-
ret = btrfs_search_slot(NULL, fs_root, &key, path, 0, 0);
- if ((ret < 0) || (found_key == NULL)) {
- if (path != found_path)
- btrfs_free_path(path);
+ if ((ret < 0) || (found_key == NULL))
return ret;
- }
eb = path->nodes[0];
if (ret && path->slots[0] >= btrfs_header_nritems(eb)) {
diff --git a/fs/btrfs/disk-io.c b/fs/btrfs/disk-io.c
index 1d5eff90d510..cac1e4284878 100644
--- a/fs/btrfs/disk-io.c
+++ b/fs/btrfs/disk-io.c
@@ -1627,6 +1627,7 @@ struct btrfs_root *btrfs_get_fs_root(struct btrfs_fs_info *fs_info,
bool check_ref)
{
struct btrfs_root *root;
+ struct btrfs_path *path;
int ret;
if (location->objectid == BTRFS_ROOT_TREE_OBJECTID)
@@ -1666,8 +1667,14 @@ again:
if (ret)
goto fail;
- ret = btrfs_find_item(fs_info->tree_root, NULL, BTRFS_ORPHAN_OBJECTID,
+ path = btrfs_alloc_path();
+ if (!path) {
+ ret = -ENOMEM;
+ goto fail;
+ }
+ ret = btrfs_find_item(fs_info->tree_root, path, BTRFS_ORPHAN_OBJECTID,
location->objectid, BTRFS_ORPHAN_ITEM_KEY, NULL);
+ btrfs_free_path(path);
if (ret < 0)
goto fail;
if (ret == 0)
diff --git a/fs/btrfs/tree-log.c b/fs/btrfs/tree-log.c
index 4347890fa71d..f3fbcc314c29 100644
--- a/fs/btrfs/tree-log.c
+++ b/fs/btrfs/tree-log.c
@@ -1254,10 +1254,19 @@ static int insert_orphan_item(struct btrfs_trans_handle *trans,
struct btrfs_root *root, u64 offset)
{
int ret;
- ret = btrfs_find_item(root, NULL, BTRFS_ORPHAN_OBJECTID,
+ struct btrfs_path *path;
+
+ path = btrfs_alloc_path();
+ if (!path)
+ return -ENOMEM;
+
+ ret = btrfs_find_item(root, path, BTRFS_ORPHAN_OBJECTID,
offset, BTRFS_ORPHAN_ITEM_KEY, NULL);
if (ret > 0)
ret = btrfs_insert_orphan_item(trans, root, offset);
+
+ btrfs_free_path(path);
+
return ret;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 023/183] ksoftirqd: Enable IRQs and call cond_resched() before poking RCU
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (21 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 022/183] btrfs: fix leak of path in btrfs_find_item Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 024/183] TPM: Add new TPMs to the tail of the list to prevent inadvertent change of dev Luis Henriques
` (159 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Calvin Owens, Paul E. McKenney, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Calvin Owens <calvinowens@fb.com>
commit 28423ad283d5348793b0c45cc9b1af058e776fd6 upstream.
While debugging an issue with excessive softirq usage, I encountered the
following note in commit 3e339b5dae24a706 ("softirq: Use hotplug thread
infrastructure"):
[ paulmck: Call rcu_note_context_switch() with interrupts enabled. ]
...but despite this note, the patch still calls RCU with IRQs disabled.
This seemingly innocuous change caused a significant regression in softirq
CPU usage on the sending side of a large TCP transfer (~1 GB/s): when
introducing 0.01% packet loss, the softirq usage would jump to around 25%,
spiking as high as 50%. Before the change, the usage would never exceed 5%.
Moving the call to rcu_note_context_switch() after the cond_sched() call,
as it was originally before the hotplug patch, completely eliminated this
problem.
Signed-off-by: Calvin Owens <calvinowens@fb.com>
Signed-off-by: Paul E. McKenney <paulmck@linux.vnet.ibm.com>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
kernel/softirq.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/kernel/softirq.c b/kernel/softirq.c
index 5918d227730f..f74268fa965e 100644
--- a/kernel/softirq.c
+++ b/kernel/softirq.c
@@ -656,9 +656,13 @@ static void run_ksoftirqd(unsigned int cpu)
* in the task stack here.
*/
__do_softirq();
- rcu_note_context_switch(cpu);
local_irq_enable();
cond_resched();
+
+ preempt_disable();
+ rcu_note_context_switch(cpu);
+ preempt_enable();
+
return;
}
local_irq_enable();
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 024/183] TPM: Add new TPMs to the tail of the list to prevent inadvertent change of dev
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (22 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 023/183] ksoftirqd: Enable IRQs and call cond_resched() before poking RCU Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 025/183] char: tpm: Add missing error check for devm_kzalloc Luis Henriques
` (158 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: David Howells, Peter Huewe, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: David Howells <dhowells@redhat.com>
commit 398a1e71dc827b994b7f2f56c7c2186fea7f8d75 upstream.
Add newly registered TPMs to the tail of the list, not the beginning, so that
things that are specifying TPM_ANY_NUM don't find that the device they're
using has inadvertently changed. Adding a second device would break IMA, for
instance.
Signed-off-by: David Howells <dhowells@redhat.com>
Reviewed-by: Jason Gunthorpe <jgunthorpe@obsidianresearch.com>
Signed-off-by: Peter Huewe <peterhuewe@gmx.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/char/tpm/tpm-interface.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/char/tpm/tpm-interface.c b/drivers/char/tpm/tpm-interface.c
index 6af17002a115..cfb9089887bd 100644
--- a/drivers/char/tpm/tpm-interface.c
+++ b/drivers/char/tpm/tpm-interface.c
@@ -1122,7 +1122,7 @@ struct tpm_chip *tpm_register_hardware(struct device *dev,
/* Make chip available */
spin_lock(&driver_lock);
- list_add_rcu(&chip->list, &tpm_chip_list);
+ list_add_tail_rcu(&chip->list, &tpm_chip_list);
spin_unlock(&driver_lock);
return chip;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 025/183] char: tpm: Add missing error check for devm_kzalloc
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (23 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 024/183] TPM: Add new TPMs to the tail of the list to prevent inadvertent change of dev Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 026/183] tpm_tis: verify interrupt during init Luis Henriques
` (157 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Kiran Padwal, Peter Huewe, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Kiran Padwal <kiran.padwal@smartplayin.com>
commit bb95cd34ba4c9467114acc78eeddd53ab1c10085 upstream.
Currently these driver are missing a check on the return value of devm_kzalloc,
which would cause a NULL pointer dereference in a OOM situation.
This patch adds a missing check for tpm_i2c_atmel.c and tpm_i2c_nuvoton.c
Signed-off-by: Kiran Padwal <kiran.padwal@smartplayin.com>
Reviewed-By: Jason Gunthorpe <jgunthorpe@obsidianresearch.com>
Signed-off-by: Peter Huewe <peterhuewe@gmx.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/char/tpm/tpm_i2c_atmel.c | 4 ++++
drivers/char/tpm/tpm_i2c_nuvoton.c | 5 +++++
2 files changed, 9 insertions(+)
diff --git a/drivers/char/tpm/tpm_i2c_atmel.c b/drivers/char/tpm/tpm_i2c_atmel.c
index 77272925dee6..503a85ae176c 100644
--- a/drivers/char/tpm/tpm_i2c_atmel.c
+++ b/drivers/char/tpm/tpm_i2c_atmel.c
@@ -168,6 +168,10 @@ static int i2c_atmel_probe(struct i2c_client *client,
chip->vendor.priv = devm_kzalloc(dev, sizeof(struct priv_data),
GFP_KERNEL);
+ if (!chip->vendor.priv) {
+ rc = -ENOMEM;
+ goto out_err;
+ }
/* Default timeouts */
chip->vendor.timeout_a = msecs_to_jiffies(TPM_I2C_SHORT_TIMEOUT);
diff --git a/drivers/char/tpm/tpm_i2c_nuvoton.c b/drivers/char/tpm/tpm_i2c_nuvoton.c
index 7b158efd49f7..23c7b137a7fd 100644
--- a/drivers/char/tpm/tpm_i2c_nuvoton.c
+++ b/drivers/char/tpm/tpm_i2c_nuvoton.c
@@ -538,6 +538,11 @@ static int i2c_nuvoton_probe(struct i2c_client *client,
chip->vendor.priv = devm_kzalloc(dev, sizeof(struct priv_data),
GFP_KERNEL);
+ if (!chip->vendor.priv) {
+ rc = -ENOMEM;
+ goto out_err;
+ }
+
init_waitqueue_head(&chip->vendor.read_queue);
init_waitqueue_head(&chip->vendor.int_queue);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 026/183] tpm_tis: verify interrupt during init
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (24 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 025/183] char: tpm: Add missing error check for devm_kzalloc Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 027/183] tpm: Fix NULL return in tpm_ibmvtpm_get_desired_dma Luis Henriques
` (156 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Scot Doyle, Peter Huewe, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Scot Doyle <lkml14@scotdoyle.com>
commit 448e9c55c12d6bd4fa90a7e31d802e045666d7c8 upstream.
Some machines, such as the Acer C720 and Toshiba CB35, have TPMs that do
not send IRQs while also having an ACPI TPM entry indicating that they
will be sent. These machines freeze on resume while the tpm_tis module
waits for an IRQ, eventually timing out.
When in interrupt mode, the tpm_tis module should receive an IRQ during
module init. Fall back to polling mode if none is received when expected.
Signed-off-by: Scot Doyle <lkml14@scotdoyle.com>
Tested-by: Michael Mullin <masmullin@gmail.com>
Reviewed-by: Jason Gunthorpe <jgunthorpe@obsidianresearch.com>
[phuewe: minor checkpatch fixed]
Signed-off-by: Peter Huewe <peterhuewe@gmx.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/char/tpm/tpm_tis.c | 76 +++++++++++++++++++++++++++++++++++++---------
1 file changed, 62 insertions(+), 14 deletions(-)
diff --git a/drivers/char/tpm/tpm_tis.c b/drivers/char/tpm/tpm_tis.c
index 2c46734b266d..51350cd0847e 100644
--- a/drivers/char/tpm/tpm_tis.c
+++ b/drivers/char/tpm/tpm_tis.c
@@ -75,6 +75,10 @@ enum tis_defaults {
#define TPM_DID_VID(l) (0x0F00 | ((l) << 12))
#define TPM_RID(l) (0x0F04 | ((l) << 12))
+struct priv_data {
+ bool irq_tested;
+};
+
static LIST_HEAD(tis_chips);
static DEFINE_MUTEX(tis_lock);
@@ -338,12 +342,27 @@ out_err:
return rc;
}
+static void disable_interrupts(struct tpm_chip *chip)
+{
+ u32 intmask;
+
+ intmask =
+ ioread32(chip->vendor.iobase +
+ TPM_INT_ENABLE(chip->vendor.locality));
+ intmask &= ~TPM_GLOBAL_INT_ENABLE;
+ iowrite32(intmask,
+ chip->vendor.iobase +
+ TPM_INT_ENABLE(chip->vendor.locality));
+ free_irq(chip->vendor.irq, chip);
+ chip->vendor.irq = 0;
+}
+
/*
* If interrupts are used (signaled by an irq set in the vendor structure)
* tpm.c can skip polling for the data to be available as the interrupt is
* waited for here
*/
-static int tpm_tis_send(struct tpm_chip *chip, u8 *buf, size_t len)
+static int tpm_tis_send_main(struct tpm_chip *chip, u8 *buf, size_t len)
{
int rc;
u32 ordinal;
@@ -373,6 +392,30 @@ out_err:
return rc;
}
+static int tpm_tis_send(struct tpm_chip *chip, u8 *buf, size_t len)
+{
+ int rc, irq;
+ struct priv_data *priv = chip->vendor.priv;
+
+ if (!chip->vendor.irq || priv->irq_tested)
+ return tpm_tis_send_main(chip, buf, len);
+
+ /* Verify receipt of the expected IRQ */
+ irq = chip->vendor.irq;
+ chip->vendor.irq = 0;
+ rc = tpm_tis_send_main(chip, buf, len);
+ chip->vendor.irq = irq;
+ if (!priv->irq_tested)
+ msleep(1);
+ if (!priv->irq_tested) {
+ disable_interrupts(chip);
+ dev_err(chip->dev,
+ FW_BUG "TPM interrupt not working, polling instead\n");
+ }
+ priv->irq_tested = true;
+ return rc;
+}
+
struct tis_vendor_timeout_override {
u32 did_vid;
unsigned long timeout_us[4];
@@ -505,6 +548,7 @@ static irqreturn_t tis_int_handler(int dummy, void *dev_id)
if (interrupt == 0)
return IRQ_NONE;
+ ((struct priv_data *)chip->vendor.priv)->irq_tested = true;
if (interrupt & TPM_INTF_DATA_AVAIL_INT)
wake_up_interruptible(&chip->vendor.read_queue);
if (interrupt & TPM_INTF_LOCALITY_CHANGE_INT)
@@ -534,9 +578,14 @@ static int tpm_tis_init(struct device *dev, resource_size_t start,
u32 vendor, intfcaps, intmask;
int rc, i, irq_s, irq_e, probe;
struct tpm_chip *chip;
+ struct priv_data *priv;
+ priv = devm_kzalloc(dev, sizeof(struct priv_data), GFP_KERNEL);
+ if (priv == NULL)
+ return -ENOMEM;
if (!(chip = tpm_register_hardware(dev, &tpm_tis)))
return -ENODEV;
+ chip->vendor.priv = priv;
chip->vendor.iobase = ioremap(start, len);
if (!chip->vendor.iobase) {
@@ -605,19 +654,6 @@ static int tpm_tis_init(struct device *dev, resource_size_t start,
if (intfcaps & TPM_INTF_DATA_AVAIL_INT)
dev_dbg(dev, "\tData Avail Int Support\n");
- /* get the timeouts before testing for irqs */
- if (tpm_get_timeouts(chip)) {
- dev_err(dev, "Could not get TPM timeouts and durations\n");
- rc = -ENODEV;
- goto out_err;
- }
-
- if (tpm_do_selftest(chip)) {
- dev_err(dev, "TPM self test failed\n");
- rc = -ENODEV;
- goto out_err;
- }
-
/* INTERRUPT Setup */
init_waitqueue_head(&chip->vendor.read_queue);
init_waitqueue_head(&chip->vendor.int_queue);
@@ -719,6 +755,18 @@ static int tpm_tis_init(struct device *dev, resource_size_t start,
}
}
+ if (tpm_get_timeouts(chip)) {
+ dev_err(dev, "Could not get TPM timeouts and durations\n");
+ rc = -ENODEV;
+ goto out_err;
+ }
+
+ if (tpm_do_selftest(chip)) {
+ dev_err(dev, "TPM self test failed\n");
+ rc = -ENODEV;
+ goto out_err;
+ }
+
INIT_LIST_HEAD(&chip->vendor.list);
mutex_lock(&tis_lock);
list_add(&chip->vendor.list, &tis_chips);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 027/183] tpm: Fix NULL return in tpm_ibmvtpm_get_desired_dma
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (25 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 026/183] tpm_tis: verify interrupt during init Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 028/183] tpm/tpm_i2c_stm_st33: Fix potential bug in tpm_stm_i2c_send Luis Henriques
` (155 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Hon Ching (Vicky) Lo, Peter Huewe, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: "Hon Ching (Vicky) Lo" <honclo@linux.vnet.ibm.com>
commit 84eb186bc37c0900b53077ca21cf6dd15823a232 upstream.
There was an oops in tpm_ibmvtpm_get_desired_dma, which caused
kernel panic during boot when vTPM is enabled in Power partition
configured in AMS mode.
vio_bus_probe calls vio_cmo_bus_probe which calls
tpm_ibmvtpm_get_desired_dma to get the size needed for DMA allocation.
The problem is, vio_cmo_bus_probe is called before calling probe, which
for vtpm is tpm_ibmvtpm_probe and it's this function that initializes
and sets up vtpm's CRQ and gets required data values. Therefore,
since this has not yet been done, NULL is returned in attempt to get
the size for DMA allocation.
We added a NULL check. In addition, a default buffer size will
be set when NULL is returned.
Signed-off-by: Hon Ching (Vicky) Lo <honclo@linux.vnet.ibm.com>
Signed-off-by: Peter Huewe <peterhuewe@gmx.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/char/tpm/tpm_ibmvtpm.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/char/tpm/tpm_ibmvtpm.c b/drivers/char/tpm/tpm_ibmvtpm.c
index af74c57e5090..4109222f2878 100644
--- a/drivers/char/tpm/tpm_ibmvtpm.c
+++ b/drivers/char/tpm/tpm_ibmvtpm.c
@@ -307,6 +307,14 @@ static int tpm_ibmvtpm_remove(struct vio_dev *vdev)
static unsigned long tpm_ibmvtpm_get_desired_dma(struct vio_dev *vdev)
{
struct ibmvtpm_dev *ibmvtpm = ibmvtpm_get_data(&vdev->dev);
+
+ /* ibmvtpm initializes at probe time, so the data we are
+ * asking for may not be set yet. Estimate that 4K required
+ * for TCE-mapped buffer in addition to CRQ.
+ */
+ if (!ibmvtpm)
+ return CRQ_RES_BUF_SIZE + PAGE_SIZE;
+
return CRQ_RES_BUF_SIZE + ibmvtpm->rtce_size;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 028/183] tpm/tpm_i2c_stm_st33: Fix potential bug in tpm_stm_i2c_send
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (26 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 027/183] tpm: Fix NULL return in tpm_ibmvtpm_get_desired_dma Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 029/183] tpm/tpm_i2c_stm_st33: Add status check when reading data on the FIFO Luis Henriques
` (154 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Christophe Ricard, Peter Huewe, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Christophe Ricard <christophe.ricard@gmail.com>
commit 1ba3b0b6f218072afe8372d12f1b6bf26a26008e upstream.
When sending data in tpm_stm_i2c_send, each loop iteration send buf.
Send buf + i instead as the goal of this for loop is to send a number
of byte from buf that fit in burstcnt. Once those byte are sent, we are
supposed to send the next ones.
The driver was working because the burstcount value returns always the maximum size for a TPM
command or response. (0x800 for a command and 0x400 for a response).
Reviewed-by: Jason Gunthorpe <jgunthorpe@obsidianresearch.com>
Signed-off-by: Christophe Ricard <christophe-h.ricard@st.com>
Signed-off-by: Peter Huewe <peterhuewe@gmx.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/char/tpm/tpm_i2c_stm_st33.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/char/tpm/tpm_i2c_stm_st33.c b/drivers/char/tpm/tpm_i2c_stm_st33.c
index 4669e3713428..7d1c540fa26a 100644
--- a/drivers/char/tpm/tpm_i2c_stm_st33.c
+++ b/drivers/char/tpm/tpm_i2c_stm_st33.c
@@ -487,7 +487,7 @@ static int tpm_stm_i2c_send(struct tpm_chip *chip, unsigned char *buf,
if (burstcnt < 0)
return burstcnt;
size = min_t(int, len - i - 1, burstcnt);
- ret = I2C_WRITE_DATA(client, TPM_DATA_FIFO, buf, size);
+ ret = I2C_WRITE_DATA(client, TPM_DATA_FIFO, buf + i, size);
if (ret < 0)
goto out_err;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 029/183] tpm/tpm_i2c_stm_st33: Add status check when reading data on the FIFO
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (27 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 028/183] tpm/tpm_i2c_stm_st33: Fix potential bug in tpm_stm_i2c_send Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 030/183] mmc: sdhci-pxav3: fix unbalanced clock issues during probe Luis Henriques
` (153 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Christophe Ricard, Peter Huewe, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Christophe Ricard <christophe.ricard@gmail.com>
commit c4eadfafb91d5501095c55ffadaa1168743f39d3 upstream.
Add a return value check when reading data from the FIFO register.
Reviewed-by: Jason Gunthorpe <jason.gunthorpe@obsidianresearch.com>
Signed-off-by: Christophe Ricard <christophe-h.ricard@st.com>
Reviewed-by: Peter Huewe <peterhuewe@gmx.de>
Signed-off-by: Peter Huewe <peterhuewe@gmx.de>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/char/tpm/tpm_i2c_stm_st33.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/char/tpm/tpm_i2c_stm_st33.c b/drivers/char/tpm/tpm_i2c_stm_st33.c
index 7d1c540fa26a..7d2081a049dc 100644
--- a/drivers/char/tpm/tpm_i2c_stm_st33.c
+++ b/drivers/char/tpm/tpm_i2c_stm_st33.c
@@ -397,7 +397,7 @@ static int wait_for_stat(struct tpm_chip *chip, u8 mask, unsigned long timeout,
*/
static int recv_data(struct tpm_chip *chip, u8 *buf, size_t count)
{
- int size = 0, burstcnt, len;
+ int size = 0, burstcnt, len, ret;
struct i2c_client *client;
client = (struct i2c_client *)TPM_VPRIV(chip);
@@ -412,7 +412,10 @@ static int recv_data(struct tpm_chip *chip, u8 *buf, size_t count)
if (burstcnt < 0)
return burstcnt;
len = min_t(int, burstcnt, count - size);
- I2C_READ_DATA(client, TPM_DATA_FIFO, buf + size, len);
+ ret = I2C_READ_DATA(client, TPM_DATA_FIFO, buf + size, len);
+ if (ret < 0)
+ return ret;
+
size += len;
}
return size;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 030/183] mmc: sdhci-pxav3: fix unbalanced clock issues during probe
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (28 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 029/183] tpm/tpm_i2c_stm_st33: Add status check when reading data on the FIFO Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 031/183] iwlwifi: mvm: validate tid and sta_id in ba_notif Luis Henriques
` (152 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Jisheng Zhang, Ulf Hansson, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jisheng Zhang <jszhang@marvell.com>
commit 62cf983ad84275f8580c807e5e596216c46773cf upstream.
Commit 0dcaa2499b7d ("sdhci-pxav3: Fix runtime PM initialization") tries
to fix one hang issue caused by calling sdhci_add_host() on a suspended
device. The fix enables the clock twice, once by clk_prepare_enable() and
another by pm_runtime_get_sync(), meaning that the clock will never be
gated at runtime PM suspend. I observed the power consumption regression on
Marvell BG2Q SoCs.
In fact, the fix is not correct. There still be a very small window
during which a runtime suspend might somehow occur after pm_runtime_enable()
but before pm_runtime_get_sync().
This patch fixes all of the two problems by just incrementing the usage
counter before pm_runtime_enable(). It also adjust the order of disabling
runtime pm and storing the usage count in the error path to handle clock
gating properly.
Signed-off-by: Jisheng Zhang <jszhang@marvell.com>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/mmc/host/sdhci-pxav3.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/mmc/host/sdhci-pxav3.c b/drivers/mmc/host/sdhci-pxav3.c
index bdfdf5273252..81143e57b2ff 100644
--- a/drivers/mmc/host/sdhci-pxav3.c
+++ b/drivers/mmc/host/sdhci-pxav3.c
@@ -356,10 +356,11 @@ static int sdhci_pxav3_probe(struct platform_device *pdev)
}
}
- pm_runtime_enable(&pdev->dev);
- pm_runtime_get_sync(&pdev->dev);
+ pm_runtime_get_noresume(&pdev->dev);
+ pm_runtime_set_active(&pdev->dev);
pm_runtime_set_autosuspend_delay(&pdev->dev, PXAV3_RPM_DELAY_MS);
pm_runtime_use_autosuspend(&pdev->dev);
+ pm_runtime_enable(&pdev->dev);
pm_suspend_ignore_children(&pdev->dev, 1);
ret = sdhci_add_host(host);
@@ -382,8 +383,8 @@ static int sdhci_pxav3_probe(struct platform_device *pdev)
return 0;
err_add_host:
- pm_runtime_put_sync(&pdev->dev);
pm_runtime_disable(&pdev->dev);
+ pm_runtime_put_noidle(&pdev->dev);
err_of_parse:
err_cd_req:
err_mbus_win:
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 031/183] iwlwifi: mvm: validate tid and sta_id in ba_notif
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (29 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 030/183] mmc: sdhci-pxav3: fix unbalanced clock issues during probe Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 032/183] power: gpio-charger: balance enable/disable_irq_wake calls Luis Henriques
` (151 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Eyal Shapira, Emmanuel Grumbach, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Eyal Shapira <eyal@wizery.com>
commit 2cee4762c528a9bd2cdff793197bf591a2196c11 upstream.
These are coming from the FW and are used to access arrays.
Bad values can cause an out of bounds access so discard
such ba_notifs and warn.
Signed-off-by: Eyal Shapira <eyalx.shapira@intel.com>
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/net/wireless/iwlwifi/mvm/tx.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/net/wireless/iwlwifi/mvm/tx.c b/drivers/net/wireless/iwlwifi/mvm/tx.c
index 3846a6c41eb1..ccc5eaf2e77c 100644
--- a/drivers/net/wireless/iwlwifi/mvm/tx.c
+++ b/drivers/net/wireless/iwlwifi/mvm/tx.c
@@ -859,6 +859,11 @@ int iwl_mvm_rx_ba_notif(struct iwl_mvm *mvm, struct iwl_rx_cmd_buffer *rxb,
sta_id = ba_notif->sta_id;
tid = ba_notif->tid;
+ if (WARN_ONCE(sta_id >= IWL_MVM_STATION_COUNT ||
+ tid >= IWL_MAX_TID_COUNT,
+ "sta_id %d tid %d", sta_id, tid))
+ return 0;
+
rcu_read_lock();
sta = rcu_dereference(mvm->fw_id_to_mac_id[sta_id]);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 032/183] power: gpio-charger: balance enable/disable_irq_wake calls
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (30 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 031/183] iwlwifi: mvm: validate tid and sta_id in ba_notif Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 033/183] power: bq24190: Fix ignored supplicants Luis Henriques
` (150 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dmitry Eremin-Solenikov, Sebastian Reichel, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Eremin-Solenikov <dbaryshkov@gmail.com>
commit faeed51bb65ce0241052d8dc24ac331ade12e976 upstream.
enable_irq_wakeup returns 0 in case it correctly enabled the IRQ to
generate the wakeup event (and thus resume should call disable_irq_wake).
Currently gpio-charger driver has this logic inverted. Correct that thus
correcting enable/disable_irq_wake() calls balance.
Signed-off-by: Dmitry Eremin-Solenikov <dbaryshkov@gmail.com>
Signed-off-by: Sebastian Reichel <sre@kernel.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/power/gpio-charger.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/power/gpio-charger.c b/drivers/power/gpio-charger.c
index a0024b252197..86e03c6d28f3 100644
--- a/drivers/power/gpio-charger.c
+++ b/drivers/power/gpio-charger.c
@@ -168,7 +168,7 @@ static int gpio_charger_suspend(struct device *dev)
if (device_may_wakeup(dev))
gpio_charger->wakeup_enabled =
- enable_irq_wake(gpio_charger->irq);
+ !enable_irq_wake(gpio_charger->irq);
return 0;
}
@@ -178,7 +178,7 @@ static int gpio_charger_resume(struct device *dev)
struct platform_device *pdev = to_platform_device(dev);
struct gpio_charger *gpio_charger = platform_get_drvdata(pdev);
- if (gpio_charger->wakeup_enabled)
+ if (device_may_wakeup(dev) && gpio_charger->wakeup_enabled)
disable_irq_wake(gpio_charger->irq);
power_supply_changed(&gpio_charger->charger);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 033/183] power: bq24190: Fix ignored supplicants
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (31 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 032/183] power: gpio-charger: balance enable/disable_irq_wake calls Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 034/183] ARM: DRA7: hwmod: Fix boot crash with DEBUG_LL enabled on UART3 Luis Henriques
` (149 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Krzysztof Kozlowski, Sebastian Reichel, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Krzysztof Kozlowski <k.kozlowski@samsung.com>
commit 478913fdbdfd4a781d91c993eb86838620fe7421 upstream.
The driver mismatched 'num_supplicants' with 'num_supplies' of
power_supply structure.
It provided list of supplicants (power_supply.supplied_to) but did
not set the number of supplicants. Instead it set the num_supplies which
is used when iterating over number of supplies (power_supply.supplied_from).
As a result the list of supplicants was ignored by core because its size
was 0.
Signed-off-by: Krzysztof Kozlowski <k.kozlowski@samsung.com>
Fixes: d7bf353fd0aa ("bq24190_charger: Add support for TI BQ24190 Battery Charger")
Signed-off-by: Sebastian Reichel <sre@kernel.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/power/bq24190_charger.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/power/bq24190_charger.c b/drivers/power/bq24190_charger.c
index ad3ff8fbfbbb..e4c95e1a6733 100644
--- a/drivers/power/bq24190_charger.c
+++ b/drivers/power/bq24190_charger.c
@@ -929,7 +929,7 @@ static void bq24190_charger_init(struct power_supply *charger)
charger->properties = bq24190_charger_properties;
charger->num_properties = ARRAY_SIZE(bq24190_charger_properties);
charger->supplied_to = bq24190_charger_supplied_to;
- charger->num_supplies = ARRAY_SIZE(bq24190_charger_supplied_to);
+ charger->num_supplicants = ARRAY_SIZE(bq24190_charger_supplied_to);
charger->get_property = bq24190_charger_get_property;
charger->set_property = bq24190_charger_set_property;
charger->property_is_writeable = bq24190_charger_property_is_writeable;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 034/183] ARM: DRA7: hwmod: Fix boot crash with DEBUG_LL enabled on UART3
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (32 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 033/183] power: bq24190: Fix ignored supplicants Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 035/183] Bluetooth: ath3k: Add support of AR3012 bluetooth 13d3:3423 device Luis Henriques
` (148 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Lokesh Vutla, Paul Walmsley, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Lokesh Vutla <lokeshvutla@ti.com>
commit 1c7e36bfc3e2fb2df5e2d1989a4b6fb9055a0f9b upstream.
With commit '7dedd34: ARM: OMAP2+: hwmod: Fix a crash in _setup_reset()
with DEBUG_LL' we moved from parsing cmdline to identify uart used
for earlycon to using the requsite hwmod CONFIG_DEBUG_OMAPxUARTy FLAGS.
On DRA7 UART3 hwmod doesn't have this flag enabled, and atleast on
BeagleBoard-X15, where we use UART3 for console, boot fails with
DEBUG_LL enabled. Enable DEBUG_OMAP4UART3_FLAGS for UART3 hwmod.
For using DEBUG_LL, enable CONFIG_DEBUG_OMAP4UART3 in menuconfig.
Fixes: 90020c7b2c5e ("ARM: OMAP: DRA7: hwmod: Create initial DRA7XX SoC data")
Reviewed-by: Felipe Balbi <balbi@ti.com>
Acked-by: Felipe Balbi <balbi@ti.com>
Signed-off-by: Lokesh Vutla <lokeshvutla@ti.com>
Signed-off-by: Paul Walmsley <paul@pwsan.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/arm/mach-omap2/omap_hwmod_7xx_data.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm/mach-omap2/omap_hwmod_7xx_data.c b/arch/arm/mach-omap2/omap_hwmod_7xx_data.c
index c95033c1029b..6b6ac11bcafa 100644
--- a/arch/arm/mach-omap2/omap_hwmod_7xx_data.c
+++ b/arch/arm/mach-omap2/omap_hwmod_7xx_data.c
@@ -1665,7 +1665,7 @@ static struct omap_hwmod dra7xx_uart3_hwmod = {
.class = &dra7xx_uart_hwmod_class,
.clkdm_name = "l4per_clkdm",
.main_clk = "uart3_gfclk_mux",
- .flags = HWMOD_SWSUP_SIDLE_ACT,
+ .flags = HWMOD_SWSUP_SIDLE_ACT | DEBUG_OMAP4UART3_FLAGS,
.prcm = {
.omap4 = {
.clkctrl_offs = DRA7XX_CM_L4PER_UART3_CLKCTRL_OFFSET,
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 035/183] Bluetooth: ath3k: Add support of AR3012 bluetooth 13d3:3423 device
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (33 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 034/183] ARM: DRA7: hwmod: Fix boot crash with DEBUG_LL enabled on UART3 Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 036/183] Bluetooth: btusb: Add Broadcom patchram support for ASUSTek devices Luis Henriques
` (147 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dmitry Tunin, Marcel Holtmann, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Tunin <hanipouspilot@gmail.com>
commit 033efa920a7f22a8caf7a38d851a2f451781bbf7 upstream.
Add support of 13d3:3423 device.
BugLink: https://bugs.launchpad.net/bugs/1411193
T: Bus=01 Lev=02 Prnt=03 Port=00 Cnt=01 Dev#= 5 Spd=12 MxCh= 0
D: Ver= 1.10 Cls=e0(wlcon) Sub=01 Prot=01 MxPS=64 #Cfgs= 1
P: Vendor=13d3 ProdID=3423 Rev= 0.01
C:* #Ifs= 2 Cfg#= 1 Atr=e0 MxPwr=100mA
A: FirstIf#= 0 IfCount= 2 Cls=e0(wlcon) Sub=01 Prot=01
I:* If#= 0 Alt= 0 #EPs= 3 Cls=e0(wlcon) Sub=01 Prot=01 Driver=btusb
E: Ad=81(I) Atr=03(Int.) MxPS= 16 Ivl=1ms
E: Ad=82(I) Atr=02(Bulk) MxPS= 64 Ivl=0ms
E: Ad=02(O) Atr=02(Bulk) MxPS= 64 Ivl=0ms
I:* If#= 1 Alt= 0 #EPs= 2 Cls=e0(wlcon) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 0 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 0 Ivl=1ms
I: If#= 1 Alt= 1 #EPs= 2 Cls=e0(wlcon) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 9 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 9 Ivl=1ms
I: If#= 1 Alt= 2 #EPs= 2 Cls=e0(wlcon) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 17 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 17 Ivl=1ms
I: If#= 1 Alt= 3 #EPs= 2 Cls=e0(wlcon) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 25 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 25 Ivl=1ms
I: If#= 1 Alt= 4 #EPs= 2 Cls=e0(wlcon) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 33 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 33 Ivl=1ms
I: If#= 1 Alt= 5 #EPs= 2 Cls=e0(wlcon) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 49 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 49 Ivl=1ms
Signed-off-by: Dmitry Tunin <hanipouspilot@gmail.com>
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/bluetooth/ath3k.c | 2 ++
drivers/bluetooth/btusb.c | 1 +
2 files changed, 3 insertions(+)
diff --git a/drivers/bluetooth/ath3k.c b/drivers/bluetooth/ath3k.c
index c8398678ead4..6f08271c1d99 100644
--- a/drivers/bluetooth/ath3k.c
+++ b/drivers/bluetooth/ath3k.c
@@ -108,6 +108,7 @@ static const struct usb_device_id ath3k_table[] = {
{ USB_DEVICE(0x13d3, 0x3393) },
{ USB_DEVICE(0x13d3, 0x3402) },
{ USB_DEVICE(0x13d3, 0x3408) },
+ { USB_DEVICE(0x13d3, 0x3423) },
{ USB_DEVICE(0x13d3, 0x3432) },
/* Atheros AR5BBU12 with sflash firmware */
@@ -162,6 +163,7 @@ static const struct usb_device_id ath3k_blist_tbl[] = {
{ USB_DEVICE(0x13d3, 0x3393), .driver_info = BTUSB_ATH3012 },
{ USB_DEVICE(0x13d3, 0x3402), .driver_info = BTUSB_ATH3012 },
{ USB_DEVICE(0x13d3, 0x3408), .driver_info = BTUSB_ATH3012 },
+ { USB_DEVICE(0x13d3, 0x3423), .driver_info = BTUSB_ATH3012 },
{ USB_DEVICE(0x13d3, 0x3432), .driver_info = BTUSB_ATH3012 },
/* Atheros AR5BBU22 with sflash firmware */
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index b7fa7ac76fdb..08a063b17546 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -187,6 +187,7 @@ static const struct usb_device_id blacklist_table[] = {
{ USB_DEVICE(0x13d3, 0x3393), .driver_info = BTUSB_ATH3012 },
{ USB_DEVICE(0x13d3, 0x3402), .driver_info = BTUSB_ATH3012 },
{ USB_DEVICE(0x13d3, 0x3408), .driver_info = BTUSB_ATH3012 },
+ { USB_DEVICE(0x13d3, 0x3423), .driver_info = BTUSB_ATH3012 },
{ USB_DEVICE(0x13d3, 0x3432), .driver_info = BTUSB_ATH3012 },
/* Atheros AR5BBU12 with sflash firmware */
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 036/183] Bluetooth: btusb: Add Broadcom patchram support for ASUSTek devices
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (34 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 035/183] Bluetooth: ath3k: Add support of AR3012 bluetooth 13d3:3423 device Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 037/183] cfq-iosched: fix incorrect filing of rt async cfqq Luis Henriques
` (146 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Rick Dunn, Marcel Holtmann, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Rick Dunn <rick@rickdunn.com>
commit 9a5abdaaf9d2e80e157c7a756f9d9fd933dee48e upstream.
T: Bus=03 Lev=01 Prnt=01 Port=06 Cnt=02 Dev#= 3 Spd=12 MxCh= 0
D: Ver= 2.00 Cls=ff(vend.) Sub=01 Prot=01 MxPS=64 #Cfgs= 1
P: Vendor=0b05 ProdID=17cf Rev= 1.12
S: Manufacturer=Broadcom Corp
S: Product=BCM20702A0
S: SerialNumber=54271E3298CD
C:* #Ifs= 4 Cfg#= 1 Atr=e0 MxPwr= 0mA
I:* If#= 0 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=81(I) Atr=03(Int.) MxPS= 16 Ivl=1ms
E: Ad=82(I) Atr=02(Bulk) MxPS= 64 Ivl=0ms
E: Ad=02(O) Atr=02(Bulk) MxPS= 64 Ivl=0ms
I:* If#= 1 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 0 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 0 Ivl=1ms
I: If#= 1 Alt= 1 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 9 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 9 Ivl=1ms
I: If#= 1 Alt= 2 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 17 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 17 Ivl=1ms
I: If#= 1 Alt= 3 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 25 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 25 Ivl=1ms
I: If#= 1 Alt= 4 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 33 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 33 Ivl=1ms
I: If#= 1 Alt= 5 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 49 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 49 Ivl=1ms
I:* If#= 2 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=ff Driver=(none)
E: Ad=84(I) Atr=02(Bulk) MxPS= 32 Ivl=0ms
E: Ad=04(O) Atr=02(Bulk) MxPS= 32 Ivl=0ms
I:* If#= 3 Alt= 0 #EPs= 0 Cls=fe(app. ) Sub=01 Prot=01 Driver=(none)
Firmware is extracted from the latest Broadcom BCM4352 Windows driver
by extracting the zip and searching the .hex file names for '17cf'.
The hex file must then be converted to hcd format using the hex2hcd
utility and then moved to /lib/firmware/brcm/.
Signed-off-by: Rick Dunn <rick@rickdunn.com>
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/bluetooth/btusb.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index 08a063b17546..1c617983315d 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -117,7 +117,8 @@ static const struct usb_device_id btusb_table[] = {
.driver_info = BTUSB_BCM_PATCHRAM },
/* ASUSTek Computer - Broadcom based */
- { USB_VENDOR_AND_INTERFACE_INFO(0x0b05, 0xff, 0x01, 0x01) },
+ { USB_VENDOR_AND_INTERFACE_INFO(0x0b05, 0xff, 0x01, 0x01),
+ .driver_info = BTUSB_BCM_PATCHRAM },
/* Belkin F8065bf - Broadcom based */
{ USB_VENDOR_AND_INTERFACE_INFO(0x050d, 0xff, 0x01, 0x01) },
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 037/183] cfq-iosched: fix incorrect filing of rt async cfqq
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (35 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 036/183] Bluetooth: btusb: Add Broadcom patchram support for ASUSTek devices Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 038/183] smack: fix possible use after frees in task_security() callers Luis Henriques
` (145 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Jeff Moyer, Jens Axboe, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Moyer <jmoyer@redhat.com>
commit c6ce194325cef342313e3d27620411ce90a89c50 upstream.
Hi,
If you can manage to submit an async write as the first async I/O from
the context of a process with realtime scheduling priority, then a
cfq_queue is allocated, but filed into the wrong async_cfqq bucket. It
ends up in the best effort array, but actually has realtime I/O
scheduling priority set in cfqq->ioprio.
The reason is that cfq_get_queue assumes the default scheduling class and
priority when there is no information present (i.e. when the async cfqq
is created):
static struct cfq_queue *
cfq_get_queue(struct cfq_data *cfqd, bool is_sync, struct cfq_io_cq *cic,
struct bio *bio, gfp_t gfp_mask)
{
const int ioprio_class = IOPRIO_PRIO_CLASS(cic->ioprio);
const int ioprio = IOPRIO_PRIO_DATA(cic->ioprio);
cic->ioprio starts out as 0, which is "invalid". So, class of 0
(IOPRIO_CLASS_NONE) is passed to cfq_async_queue_prio like so:
async_cfqq = cfq_async_queue_prio(cfqd, ioprio_class, ioprio);
static struct cfq_queue **
cfq_async_queue_prio(struct cfq_data *cfqd, int ioprio_class, int ioprio)
{
switch (ioprio_class) {
case IOPRIO_CLASS_RT:
return &cfqd->async_cfqq[0][ioprio];
case IOPRIO_CLASS_NONE:
ioprio = IOPRIO_NORM;
/* fall through */
case IOPRIO_CLASS_BE:
return &cfqd->async_cfqq[1][ioprio];
case IOPRIO_CLASS_IDLE:
return &cfqd->async_idle_cfqq;
default:
BUG();
}
}
Here, instead of returning a class mapped from the process' scheduling
priority, we get back the bucket associated with IOPRIO_CLASS_BE.
Now, there is no queue allocated there yet, so we create it:
cfqq = cfq_find_alloc_queue(cfqd, is_sync, cic, bio, gfp_mask);
That function ends up doing this:
cfq_init_cfqq(cfqd, cfqq, current->pid, is_sync);
cfq_init_prio_data(cfqq, cic);
cfq_init_cfqq marks the priority as having changed. Then, cfq_init_prio
data does this:
ioprio_class = IOPRIO_PRIO_CLASS(cic->ioprio);
switch (ioprio_class) {
default:
printk(KERN_ERR "cfq: bad prio %x\n", ioprio_class);
case IOPRIO_CLASS_NONE:
/*
* no prio set, inherit CPU scheduling settings
*/
cfqq->ioprio = task_nice_ioprio(tsk);
cfqq->ioprio_class = task_nice_ioclass(tsk);
break;
So we basically have two code paths that treat IOPRIO_CLASS_NONE
differently, which results in an RT async cfqq filed into a best effort
bucket.
Attached is a patch which fixes the problem. I'm not sure how to make
it cleaner. Suggestions would be welcome.
Signed-off-by: Jeff Moyer <jmoyer@redhat.com>
Tested-by: Hidehiro Kawai <hidehiro.kawai.ez@hitachi.com>
Signed-off-by: Jens Axboe <axboe@fb.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
block/cfq-iosched.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/block/cfq-iosched.c b/block/cfq-iosched.c
index d7494637c5db..f3627ca9303b 100644
--- a/block/cfq-iosched.c
+++ b/block/cfq-iosched.c
@@ -3648,12 +3648,17 @@ static struct cfq_queue *
cfq_get_queue(struct cfq_data *cfqd, bool is_sync, struct cfq_io_cq *cic,
struct bio *bio, gfp_t gfp_mask)
{
- const int ioprio_class = IOPRIO_PRIO_CLASS(cic->ioprio);
- const int ioprio = IOPRIO_PRIO_DATA(cic->ioprio);
+ int ioprio_class = IOPRIO_PRIO_CLASS(cic->ioprio);
+ int ioprio = IOPRIO_PRIO_DATA(cic->ioprio);
struct cfq_queue **async_cfqq = NULL;
struct cfq_queue *cfqq = NULL;
if (!is_sync) {
+ if (!ioprio_valid(cic->ioprio)) {
+ struct task_struct *tsk = current;
+ ioprio = task_nice_ioprio(tsk);
+ ioprio_class = task_nice_ioclass(tsk);
+ }
async_cfqq = cfq_async_queue_prio(cfqd, ioprio_class, ioprio);
cfqq = *async_cfqq;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 038/183] smack: fix possible use after frees in task_security() callers
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (36 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 037/183] cfq-iosched: fix incorrect filing of rt async cfqq Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 039/183] xfs: ensure buffer types are set correctly Luis Henriques
` (144 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Andrey Ryabinin, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrey Ryabinin <a.ryabinin@samsung.com>
commit 6d1cff2a885850b78b40c34777b46cf5da5d1050 upstream.
We hit use after free on dereferncing pointer to task_smack struct in
smk_of_task() called from smack_task_to_inode().
task_security() macro uses task_cred_xxx() to get pointer to the task_smack.
task_cred_xxx() could be used only for non-pointer members of task's
credentials. It cannot be used for pointer members since what they point
to may disapper after dropping RCU read lock.
Mainly task_security() used this way:
smk_of_task(task_security(p))
Intead of this introduce function smk_of_task_struct() which
takes task_struct as argument and returns pointer to smk_known struct
and do this under RCU read lock.
Bogus task_security() macro is not used anymore, so remove it.
KASan's report for this:
AddressSanitizer: use after free in smack_task_to_inode+0x50/0x70 at addr c4635600
=============================================================================
BUG kmalloc-64 (Tainted: PO): kasan error
-----------------------------------------------------------------------------
Disabling lock debugging due to kernel taint
INFO: Allocated in new_task_smack+0x44/0xd8 age=39 cpu=0 pid=1866
kmem_cache_alloc_trace+0x88/0x1bc
new_task_smack+0x44/0xd8
smack_cred_prepare+0x48/0x21c
security_prepare_creds+0x44/0x4c
prepare_creds+0xdc/0x110
smack_setprocattr+0x104/0x150
security_setprocattr+0x4c/0x54
proc_pid_attr_write+0x12c/0x194
vfs_write+0x1b0/0x370
SyS_write+0x5c/0x94
ret_fast_syscall+0x0/0x48
INFO: Freed in smack_cred_free+0xc4/0xd0 age=27 cpu=0 pid=1564
kfree+0x270/0x290
smack_cred_free+0xc4/0xd0
security_cred_free+0x34/0x3c
put_cred_rcu+0x58/0xcc
rcu_process_callbacks+0x738/0x998
__do_softirq+0x264/0x4cc
do_softirq+0x94/0xf4
irq_exit+0xbc/0x120
handle_IRQ+0x104/0x134
gic_handle_irq+0x70/0xac
__irq_svc+0x44/0x78
_raw_spin_unlock+0x18/0x48
sync_inodes_sb+0x17c/0x1d8
sync_filesystem+0xac/0xfc
vdfs_file_fsync+0x90/0xc0
vfs_fsync_range+0x74/0x7c
INFO: Slab 0xd3b23f50 objects=32 used=31 fp=0xc4635600 flags=0x4080
INFO: Object 0xc4635600 @offset=5632 fp=0x (null)
Bytes b4 c46355f0: 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a ZZZZZZZZZZZZZZZZ
Object c4635600: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk
Object c4635610: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk
Object c4635620: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk
Object c4635630: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b a5 kkkkkkkkkkkkkkk.
Redzone c4635640: bb bb bb bb ....
Padding c46356e8: 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a ZZZZZZZZZZZZZZZZ
Padding c46356f8: 5a 5a 5a 5a 5a 5a 5a 5a ZZZZZZZZ
CPU: 5 PID: 834 Comm: launchpad_prelo Tainted: PBO 3.10.30 #1
Backtrace:
[<c00233a4>] (dump_backtrace+0x0/0x158) from [<c0023dec>] (show_stack+0x20/0x24)
r7:c4634010 r6:d3b23f50 r5:c4635600 r4:d1002140
[<c0023dcc>] (show_stack+0x0/0x24) from [<c06d6d7c>] (dump_stack+0x20/0x28)
[<c06d6d5c>] (dump_stack+0x0/0x28) from [<c01c1d50>] (print_trailer+0x124/0x144)
[<c01c1c2c>] (print_trailer+0x0/0x144) from [<c01c1e88>] (object_err+0x3c/0x44)
r7:c4635600 r6:d1002140 r5:d3b23f50 r4:c4635600
[<c01c1e4c>] (object_err+0x0/0x44) from [<c01cac18>] (kasan_report_error+0x2b8/0x538)
r6:d1002140 r5:d3b23f50 r4:c6429cf8 r3:c09e1aa7
[<c01ca960>] (kasan_report_error+0x0/0x538) from [<c01c9430>] (__asan_load4+0xd4/0xf8)
[<c01c935c>] (__asan_load4+0x0/0xf8) from [<c031e168>] (smack_task_to_inode+0x50/0x70)
r5:c4635600 r4:ca9da000
[<c031e118>] (smack_task_to_inode+0x0/0x70) from [<c031af64>] (security_task_to_inode+0x3c/0x44)
r5:cca25e80 r4:c0ba9780
[<c031af28>] (security_task_to_inode+0x0/0x44) from [<c023d614>] (pid_revalidate+0x124/0x178)
r6:00000000 r5:cca25e80 r4:cbabe3c0 r3:00008124
[<c023d4f0>] (pid_revalidate+0x0/0x178) from [<c01db98c>] (lookup_fast+0x35c/0x43y4)
r9:c6429efc r8:00000101 r7:c079d940 r6:c6429e90 r5:c6429ed8 r4:c83c4148
[<c01db630>] (lookup_fast+0x0/0x434) from [<c01deec8>] (do_last.isra.24+0x1c0/0x1108)
[<c01ded08>] (do_last.isra.24+0x0/0x1108) from [<c01dff04>] (path_openat.isra.25+0xf4/0x648)
[<c01dfe10>] (path_openat.isra.25+0x0/0x648) from [<c01e1458>] (do_filp_open+0x3c/0x88)
[<c01e141c>] (do_filp_open+0x0/0x88) from [<c01ccb28>] (do_sys_open+0xf0/0x198)
r7:00000001 r6:c0ea2180 r5:0000000b r4:00000000
[<c01cca38>] (do_sys_open+0x0/0x198) from [<c01ccc00>] (SyS_open+0x30/0x34)
[<c01ccbd0>] (SyS_open+0x0/0x34) from [<c001db80>] (ret_fast_syscall+0x0/0x48)
Read of size 4 by thread T834:
Memory state around the buggy address:
c4635380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
c4635400: 00 00 00 00 00 00 00 00 fc fc fc fc fc fc fc fc
c4635480: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
c4635500: 00 00 00 00 00 fc fc fc fc fc fc fc fc fc fc fc
c4635580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
>c4635600: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
^
c4635680: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
c4635700: 00 00 00 00 04 fc fc fc fc fc fc fc fc fc fc fc
c4635780: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
c4635800: 00 00 00 00 00 00 04 fc fc fc fc fc fc fc fc fc
c4635880: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
==================================================================
Signed-off-by: Andrey Ryabinin <a.ryabinin@samsung.com>
[ luis: backported to 3.16:
- dropped changes to smk_bu_task()
- adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
security/smack/smack.h | 10 ++++++++++
security/smack/smack_lsm.c | 20 +++++++++++---------
2 files changed, 21 insertions(+), 9 deletions(-)
diff --git a/security/smack/smack.h b/security/smack/smack.h
index 020307ef0972..3bb1618f14b4 100644
--- a/security/smack/smack.h
+++ b/security/smack/smack.h
@@ -297,6 +297,16 @@ static inline struct smack_known *smk_of_task(const struct task_smack *tsp)
return tsp->smk_task;
}
+static inline struct smack_known *smk_of_task_struct(const struct task_struct *t)
+{
+ struct smack_known *skp;
+
+ rcu_read_lock();
+ skp = smk_of_task(__task_cred(t)->security);
+ rcu_read_unlock();
+ return skp;
+}
+
/*
* Present a pointer to the forked smack label entry in an task blob.
*/
diff --git a/security/smack/smack_lsm.c b/security/smack/smack_lsm.c
index f2c30801ce41..40cdee62097e 100644
--- a/security/smack/smack_lsm.c
+++ b/security/smack/smack_lsm.c
@@ -43,8 +43,6 @@
#include <linux/binfmts.h>
#include "smack.h"
-#define task_security(task) (task_cred_xxx((task), security))
-
#define TRANS_TRUE "TRUE"
#define TRANS_TRUE_SIZE 4
@@ -199,7 +197,8 @@ static int smk_ptrace_rule_check(struct task_struct *tracer, char *tracee_label,
saip = &ad;
}
- tsp = task_security(tracer);
+ rcu_read_lock();
+ tsp = __task_cred(tracer)->security;
skp = smk_of_task(tsp);
if ((mode & PTRACE_MODE_ATTACH) &&
@@ -217,11 +216,14 @@ static int smk_ptrace_rule_check(struct task_struct *tracer, char *tracee_label,
if (saip)
smack_log(skp->smk_known, tracee_label, 0, rc, saip);
+ rcu_read_unlock();
return rc;
}
/* In case of rule==SMACK_PTRACE_DEFAULT or mode==PTRACE_MODE_READ */
rc = smk_tskacc(tsp, tracee_label, smk_ptrace_mode(mode), saip);
+
+ rcu_read_unlock();
return rc;
}
@@ -248,7 +250,7 @@ static int smack_ptrace_access_check(struct task_struct *ctp, unsigned int mode)
if (rc != 0)
return rc;
- skp = smk_of_task(task_security(ctp));
+ skp = smk_of_task_struct(ctp);
rc = smk_ptrace_rule_check(current, skp->smk_known, mode, __func__);
return rc;
@@ -1639,7 +1641,7 @@ static int smk_curacc_on_task(struct task_struct *p, int access,
const char *caller)
{
struct smk_audit_info ad;
- struct smack_known *skp = smk_of_task(task_security(p));
+ struct smack_known *skp = smk_of_task_struct(p);
smk_ad_init(&ad, caller, LSM_AUDIT_DATA_TASK);
smk_ad_setfield_u_tsk(&ad, p);
@@ -1689,7 +1691,7 @@ static int smack_task_getsid(struct task_struct *p)
*/
static void smack_task_getsecid(struct task_struct *p, u32 *secid)
{
- struct smack_known *skp = smk_of_task(task_security(p));
+ struct smack_known *skp = smk_of_task_struct(p);
*secid = skp->smk_secid;
}
@@ -1796,7 +1798,7 @@ static int smack_task_kill(struct task_struct *p, struct siginfo *info,
{
struct smk_audit_info ad;
struct smack_known *skp;
- struct smack_known *tkp = smk_of_task(task_security(p));
+ struct smack_known *tkp = smk_of_task_struct(p);
smk_ad_init(&ad, __func__, LSM_AUDIT_DATA_TASK);
smk_ad_setfield_u_tsk(&ad, p);
@@ -1844,7 +1846,7 @@ static int smack_task_wait(struct task_struct *p)
static void smack_task_to_inode(struct task_struct *p, struct inode *inode)
{
struct inode_smack *isp = inode->i_security;
- struct smack_known *skp = smk_of_task(task_security(p));
+ struct smack_known *skp = smk_of_task_struct(p);
isp->smk_inode = skp->smk_known;
}
@@ -2988,7 +2990,7 @@ unlockandout:
*/
static int smack_getprocattr(struct task_struct *p, char *name, char **value)
{
- struct smack_known *skp = smk_of_task(task_security(p));
+ struct smack_known *skp = smk_of_task_struct(p);
char *cp;
int slen;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 039/183] xfs: ensure buffer types are set correctly
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (37 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 038/183] smack: fix possible use after frees in task_security() callers Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 040/183] xfs: inode unlink does not set AGI buffer type Luis Henriques
` (143 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dave Chinner, Dave Chinner, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dave Chinner <dchinner@redhat.com>
commit 0d612fb570b71ea2e49554a770cff4c489018b2c upstream.
Jan Kara reported that log recovery was finding buffers with invalid
types in them. This should not happen, and indicates a bug in the
logging of buffers. To catch this, add asserts to the buffer
formatting code to ensure that the buffer type is in range when the
transaction is committed.
We don't set a type on buffers being marked stale - they are not
going to get replayed, the format item exists only for recovery to
be able to prevent replay of the buffer, so the type does not
matter. Hence that needs special casing here.
Reported-by: Jan Kara <jack@suse.cz>
Tested-by: Jan Kara <jack@suse.cz>
Signed-off-by: Dave Chinner <dchinner@redhat.com>
Reviewed-by: Brian Foster <bfoster@redhat.com>
Signed-off-by: Dave Chinner <david@fromorbit.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/xfs/xfs_buf_item.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/fs/xfs/xfs_buf_item.c b/fs/xfs/xfs_buf_item.c
index 4654338b03fc..ee668787b71e 100644
--- a/fs/xfs/xfs_buf_item.c
+++ b/fs/xfs/xfs_buf_item.c
@@ -319,6 +319,10 @@ xfs_buf_item_format(
ASSERT(atomic_read(&bip->bli_refcount) > 0);
ASSERT((bip->bli_flags & XFS_BLI_LOGGED) ||
(bip->bli_flags & XFS_BLI_STALE));
+ ASSERT((bip->bli_flags & XFS_BLI_STALE) ||
+ (xfs_blft_from_flags(&bip->__bli_format) > XFS_BLFT_UNKNOWN_BUF
+ && xfs_blft_from_flags(&bip->__bli_format) < XFS_BLFT_MAX_BUF));
+
/*
* If it is an inode buffer, transfer the in-memory state to the
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 040/183] xfs: inode unlink does not set AGI buffer type
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (38 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 039/183] xfs: ensure buffer types are set correctly Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 041/183] xfs: set buf types when converting extent formats Luis Henriques
` (142 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dave Chinner, Dave Chinner, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dave Chinner <dchinner@redhat.com>
commit f19b872b086711bb4b22c3a0f52f16aa920bcc61 upstream.
This leads to log recovery throwing errors like:
XFS (md0): Mounting V5 Filesystem
XFS (md0): Starting recovery (logdev: internal)
XFS (md0): Unknown buffer type 0!
XFS (md0): _xfs_buf_ioapply: no ops on block 0xaea8802/0x1
ffff8800ffc53800: 58 41 47 49 .....
Which is the AGI buffer magic number.
Ensure that we set the type appropriately in both unlink list
addition and removal.
Tested-by: Jan Kara <jack@suse.cz>
Signed-off-by: Dave Chinner <dchinner@redhat.com>
Reviewed-by: Brian Foster <bfoster@redhat.com>
Signed-off-by: Dave Chinner <david@fromorbit.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/xfs/xfs_inode.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/fs/xfs/xfs_inode.c b/fs/xfs/xfs_inode.c
index a6115fe1ac94..162a4b688a0c 100644
--- a/fs/xfs/xfs_inode.c
+++ b/fs/xfs/xfs_inode.c
@@ -1996,6 +1996,7 @@ xfs_iunlink(
agi->agi_unlinked[bucket_index] = cpu_to_be32(agino);
offset = offsetof(xfs_agi_t, agi_unlinked) +
(sizeof(xfs_agino_t) * bucket_index);
+ xfs_trans_buf_set_type(tp, agibp, XFS_BLFT_AGI_BUF);
xfs_trans_log_buf(tp, agibp, offset,
(offset + sizeof(xfs_agino_t) - 1));
return 0;
@@ -2087,6 +2088,7 @@ xfs_iunlink_remove(
agi->agi_unlinked[bucket_index] = cpu_to_be32(next_agino);
offset = offsetof(xfs_agi_t, agi_unlinked) +
(sizeof(xfs_agino_t) * bucket_index);
+ xfs_trans_buf_set_type(tp, agibp, XFS_BLFT_AGI_BUF);
xfs_trans_log_buf(tp, agibp, offset,
(offset + sizeof(xfs_agino_t) - 1));
} else {
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 041/183] xfs: set buf types when converting extent formats
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (39 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 040/183] xfs: inode unlink does not set AGI buffer type Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 042/183] xfs: set superblock buffer type correctly Luis Henriques
` (141 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dave Chinner, Dave Chinner, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dave Chinner <dchinner@redhat.com>
commit fe22d552b82d7cc7de1851233ae8bef579198637 upstream.
Conversion from local to extent format does not set the buffer type
correctly on the new extent buffer when a symlink data is moved out
of line.
Fix the symlink code and leave a comment in the generic bmap code
reminding us that the format-specific data copy needs to set the
destination buffer type appropriately.
Tested-by: Jan Kara <jack@suse.cz>
Signed-off-by: Dave Chinner <dchinner@redhat.com>
Reviewed-by: Brian Foster <bfoster@redhat.com>
Signed-off-by: Dave Chinner <david@fromorbit.com>
[ luis: backported to 3.16: libxfs infrastructure not available in 3.16 kernel ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/xfs/xfs_bmap.c | 6 +++++-
fs/xfs/xfs_symlink_remote.c | 2 ++
2 files changed, 7 insertions(+), 1 deletion(-)
diff --git a/fs/xfs/xfs_bmap.c b/fs/xfs/xfs_bmap.c
index 75c3fe5f3d9d..94a5c1914fb3 100644
--- a/fs/xfs/xfs_bmap.c
+++ b/fs/xfs/xfs_bmap.c
@@ -976,7 +976,11 @@ xfs_bmap_local_to_extents(
*firstblock = args.fsbno;
bp = xfs_btree_get_bufl(args.mp, tp, args.fsbno, 0);
- /* initialise the block and copy the data */
+ /*
+ * Initialise the block and copy the data
+ *
+ * Note: init_fn must set the buffer log item type correctly!
+ */
init_fn(tp, bp, ip, ifp);
/* account for the change in fork size and log everything */
diff --git a/fs/xfs/xfs_symlink_remote.c b/fs/xfs/xfs_symlink_remote.c
index 23c2f2577c8d..4c92ef63b11b 100644
--- a/fs/xfs/xfs_symlink_remote.c
+++ b/fs/xfs/xfs_symlink_remote.c
@@ -180,6 +180,8 @@ xfs_symlink_local_to_remote(
struct xfs_mount *mp = ip->i_mount;
char *buf;
+ xfs_trans_buf_set_type(tp, bp, XFS_BLFT_SYMLINK_BUF);
+
if (!xfs_sb_version_hascrc(&mp->m_sb)) {
bp->b_ops = NULL;
memcpy(bp->b_addr, ifp->if_u1.if_data, ifp->if_bytes);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 042/183] xfs: set superblock buffer type correctly
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (40 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 041/183] xfs: set buf types when converting extent formats Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 043/183] btrfs: set proper message level for skinny metadata Luis Henriques
` (140 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dave Chinner, Dave Chinner, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dave Chinner <dchinner@redhat.com>
commit 3443a3bca54588f43286b725d8648d33a38c86f1 upstream.
When the superblock is modified in a transaction, the commonly
modified fields are not actually copied to the superblock buffer to
avoid the buffer lock becoming a serialisation point. However, there
are some other operations that modify the superblock fields within
the transaction that don't directly log to the superblock but rely
on the changes to be applied during the transaction commit (to
minimise the buffer lock hold time).
When we do this, we fail to mark the buffer log item as being a
superblock buffer and that can lead to the buffer not being marked
with the corect type in the log and hence causing recovery issues.
Fix it by setting the type correctly, similar to xfs_mod_sb()...
Tested-by: Jan Kara <jack@suse.cz>
Signed-off-by: Dave Chinner <dchinner@redhat.com>
Reviewed-by: Brian Foster <bfoster@redhat.com>
Signed-off-by: Dave Chinner <david@fromorbit.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/xfs/xfs_trans.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/fs/xfs/xfs_trans.c b/fs/xfs/xfs_trans.c
index d03932564ccb..c81f51c290c1 100644
--- a/fs/xfs/xfs_trans.c
+++ b/fs/xfs/xfs_trans.c
@@ -474,6 +474,7 @@ xfs_trans_apply_sb_deltas(
whole = 1;
}
+ xfs_trans_buf_set_type(tp, bp, XFS_BLFT_SB_BUF);
if (whole)
/*
* Log the whole thing, the fields are noncontiguous.
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 043/183] btrfs: set proper message level for skinny metadata
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (41 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 042/183] xfs: set superblock buffer type correctly Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 044/183] KVM: s390: base hrtimer on a monotonic clock Luis Henriques
` (139 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: David Sterba, Chris Mason, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: David Sterba <dsterba@suse.cz>
commit 5efa0490cc94aee06cd8d282683e22a8ce0a0026 upstream.
This has been confusing people for too long, the message is really just
informative.
Signed-off-by: David Sterba <dsterba@suse.cz>
Signed-off-by: Chris Mason <clm@fb.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/btrfs/disk-io.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/btrfs/disk-io.c b/fs/btrfs/disk-io.c
index cac1e4284878..83ca0469b178 100644
--- a/fs/btrfs/disk-io.c
+++ b/fs/btrfs/disk-io.c
@@ -2499,7 +2499,7 @@ int open_ctree(struct super_block *sb,
features |= BTRFS_FEATURE_INCOMPAT_COMPRESS_LZO;
if (features & BTRFS_FEATURE_INCOMPAT_SKINNY_METADATA)
- printk(KERN_ERR "BTRFS: has skinny extents\n");
+ printk(KERN_INFO "BTRFS: has skinny extents\n");
/*
* flag our filesystem as having big metadata blocks if
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 044/183] KVM: s390: base hrtimer on a monotonic clock
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (42 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 043/183] btrfs: set proper message level for skinny metadata Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 045/183] KVM: s390: avoid memory leaks if __inject_vm() fails Luis Henriques
` (138 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: David Hildenbrand, Christian Borntraeger, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: David Hildenbrand <dahi@linux.vnet.ibm.com>
commit 0ac96caf0f9381088c673a16d910b1d329670edf upstream.
The hrtimer that handles the wait with enabled timer interrupts
should not be disturbed by changes of the host time.
This patch changes our hrtimer to be based on a monotonic clock.
Signed-off-by: David Hildenbrand <dahi@linux.vnet.ibm.com>
Acked-by: Cornelia Huck <cornelia.huck@de.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@de.ibm.com>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/s390/kvm/kvm-s390.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/s390/kvm/kvm-s390.c b/arch/s390/kvm/kvm-s390.c
index 0eaf87281f45..5e9217d96cfe 100644
--- a/arch/s390/kvm/kvm-s390.c
+++ b/arch/s390/kvm/kvm-s390.c
@@ -646,7 +646,7 @@ int kvm_arch_vcpu_setup(struct kvm_vcpu *vcpu)
if (rc)
return rc;
}
- hrtimer_init(&vcpu->arch.ckc_timer, CLOCK_REALTIME, HRTIMER_MODE_ABS);
+ hrtimer_init(&vcpu->arch.ckc_timer, CLOCK_MONOTONIC, HRTIMER_MODE_REL);
tasklet_init(&vcpu->arch.tasklet, kvm_s390_tasklet,
(unsigned long) vcpu);
vcpu->arch.ckc_timer.function = kvm_s390_idle_wakeup;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 045/183] KVM: s390: avoid memory leaks if __inject_vm() fails
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (43 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 044/183] KVM: s390: base hrtimer on a monotonic clock Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 046/183] samsung-laptop: Add use_native_backlight quirk, and enable it on some models Luis Henriques
` (137 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: David Hildenbrand, Christian Borntraeger, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: David Hildenbrand <dahi@linux.vnet.ibm.com>
commit 428d53be5e7468769d4e7899cca06ed5f783a6e1 upstream.
We have to delete the allocated interrupt info if __inject_vm() fails.
Otherwise user space can keep flooding kvm with floating interrupts and
provoke more and more memory leaks.
Reported-by: Dominik Dingel <dingel@linux.vnet.ibm.com>
Reviewed-by: Dominik Dingel <dingel@linux.vnet.ibm.com>
Signed-off-by: David Hildenbrand <dahi@linux.vnet.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@de.ibm.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/s390/kvm/interrupt.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/arch/s390/kvm/interrupt.c b/arch/s390/kvm/interrupt.c
index db3625ae7a47..e2354f97264e 100644
--- a/arch/s390/kvm/interrupt.c
+++ b/arch/s390/kvm/interrupt.c
@@ -951,6 +951,7 @@ int kvm_s390_inject_vm(struct kvm *kvm,
struct kvm_s390_interrupt *s390int)
{
struct kvm_s390_interrupt_info *inti;
+ int rc;
inti = kzalloc(sizeof(*inti), GFP_KERNEL);
if (!inti)
@@ -998,7 +999,10 @@ int kvm_s390_inject_vm(struct kvm *kvm,
trace_kvm_s390_inject_vm(s390int->type, s390int->parm, s390int->parm64,
2);
- return __inject_vm(kvm, inti);
+ rc = __inject_vm(kvm, inti);
+ if (rc)
+ kfree(inti);
+ return rc;
}
void kvm_s390_reinject_io_int(struct kvm *kvm,
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 046/183] samsung-laptop: Add use_native_backlight quirk, and enable it on some models
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (44 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 045/183] KVM: s390: avoid memory leaks if __inject_vm() fails Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 047/183] PCI: Fix infinite loop with ROM image of size 0 Luis Henriques
` (136 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Hans de Goede, Darren Hart, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <hdegoede@redhat.com>
commit 4690555e13c48fef07f2762f6b0cd6b181e326d0 upstream.
Since kernel 3.14 the backlight control has been broken on various Samsung
Atom based netbooks. This has been bisected and this problem happens since
commit b35684b8fa94 ("drm/i915: do full backlight setup at enable time")
This has been reported and discussed in detail here:
http://lists.freedesktop.org/archives/intel-gfx/2014-July/049395.html
Unfortunately no-one has been able to fix this. This only affects Samsung
Atom netbooks, and the Linux kernel and the BIOS of those laptops have never
worked well together. All affected laptops already have a quirk to avoid using
the standard acpi-video interface and instead use the samsung specific SABI
interface which samsung-laptop uses. It seems that recent fixes to the i915
driver have also broken backlight control through the SABI interface.
The intel_backlight driver OTOH works fine, and also allows for finer grained
backlight control. So add a new use_native_backlight quirk, and replace the
broken_acpi_video quirk with this quirk for affected models. This new quirk
disables acpi-video as before and also stops samsung-laptop from registering
the SABI based samsung_laptop backlight interface, leaving only the working
intel_backlight interface.
This commit enables this new quirk for 3 models which are known to be affected,
chances are that it needs to be used on other models too.
BugLink: https://bugzilla.redhat.com/show_bug.cgi?id=1094948 # N145P
BugLink: https://bugzilla.redhat.com/show_bug.cgi?id=1115713 # N250P
Reported-by: Bertrik Sikken <bertrik@sikken.nl> # N150P
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Darren Hart <dvhart@linux.intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/platform/x86/samsung-laptop.c | 20 +++++++++++++++++---
1 file changed, 17 insertions(+), 3 deletions(-)
diff --git a/drivers/platform/x86/samsung-laptop.c b/drivers/platform/x86/samsung-laptop.c
index ff765d8e1a09..ce364a41842a 100644
--- a/drivers/platform/x86/samsung-laptop.c
+++ b/drivers/platform/x86/samsung-laptop.c
@@ -353,6 +353,7 @@ struct samsung_quirks {
bool broken_acpi_video;
bool four_kbd_backlight_levels;
bool enable_kbd_backlight;
+ bool use_native_backlight;
};
static struct samsung_quirks samsung_unknown = {};
@@ -361,6 +362,10 @@ static struct samsung_quirks samsung_broken_acpi_video = {
.broken_acpi_video = true,
};
+static struct samsung_quirks samsung_use_native_backlight = {
+ .use_native_backlight = true,
+};
+
static struct samsung_quirks samsung_np740u3e = {
.four_kbd_backlight_levels = true,
.enable_kbd_backlight = true,
@@ -1507,7 +1512,7 @@ static struct dmi_system_id __initdata samsung_dmi_table[] = {
DMI_MATCH(DMI_PRODUCT_NAME, "N150P"),
DMI_MATCH(DMI_BOARD_NAME, "N150P"),
},
- .driver_data = &samsung_broken_acpi_video,
+ .driver_data = &samsung_use_native_backlight,
},
{
.callback = samsung_dmi_matched,
@@ -1517,7 +1522,7 @@ static struct dmi_system_id __initdata samsung_dmi_table[] = {
DMI_MATCH(DMI_PRODUCT_NAME, "N145P/N250P/N260P"),
DMI_MATCH(DMI_BOARD_NAME, "N145P/N250P/N260P"),
},
- .driver_data = &samsung_broken_acpi_video,
+ .driver_data = &samsung_use_native_backlight,
},
{
.callback = samsung_dmi_matched,
@@ -1557,7 +1562,7 @@ static struct dmi_system_id __initdata samsung_dmi_table[] = {
DMI_MATCH(DMI_PRODUCT_NAME, "N250P"),
DMI_MATCH(DMI_BOARD_NAME, "N250P"),
},
- .driver_data = &samsung_broken_acpi_video,
+ .driver_data = &samsung_use_native_backlight,
},
{
.callback = samsung_dmi_matched,
@@ -1616,6 +1621,15 @@ static int __init samsung_init(void)
pr_info("Disabling ACPI video driver\n");
acpi_video_unregister();
}
+
+ if (samsung->quirks->use_native_backlight) {
+ pr_info("Using native backlight driver\n");
+ /* Tell acpi-video to not handle the backlight */
+ acpi_video_dmi_promote_vendor();
+ acpi_video_unregister();
+ /* And also do not handle it ourselves */
+ samsung->handle_backlight = false;
+ }
#endif
ret = samsung_platform_init(samsung);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 047/183] PCI: Fix infinite loop with ROM image of size 0
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (45 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 046/183] samsung-laptop: Add use_native_backlight quirk, and enable it on some models Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 048/183] USB: cp210x: add ID for RUGGEDCOM USB Serial Console Luis Henriques
` (135 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Michel Dänzer, Bjorn Helgaas, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: =?UTF-8?q?Michel=20D=C3=A4nzer?= <michel.daenzer@amd.com>
commit 16b036af31e1456cb69243a5a0c9ef801ecd1f17 upstream.
If the image size would ever read as 0, pci_get_rom_size() could keep
processing the same image over and over again. Exit the loop if we ever
read a length of zero.
This fixes a soft lockup on boot when the radeon driver calls
pci_get_rom_size() on an AMD Radeon R7 250X PCIe discrete graphics card.
[bhelgaas: changelog, reference]
Link: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1386973
Reported-by: Federico <federicotg@gmail.com>
Signed-off-by: Michel Dänzer <michel.daenzer@amd.com>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Reviewed-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/pci/rom.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/pci/rom.c b/drivers/pci/rom.c
index f955edb9bea7..eb0ad530dc43 100644
--- a/drivers/pci/rom.c
+++ b/drivers/pci/rom.c
@@ -71,6 +71,7 @@ size_t pci_get_rom_size(struct pci_dev *pdev, void __iomem *rom, size_t size)
{
void __iomem *image;
int last_image;
+ unsigned length;
image = rom;
do {
@@ -93,9 +94,9 @@ size_t pci_get_rom_size(struct pci_dev *pdev, void __iomem *rom, size_t size)
if (readb(pds + 3) != 'R')
break;
last_image = readb(pds + 21) & 0x80;
- /* this length is reliable */
- image += readw(pds + 16) * 512;
- } while (!last_image);
+ length = readw(pds + 16);
+ image += length * 512;
+ } while (length && !last_image);
/* never return a size larger than the PCI resource window */
/* there are known ROMs that get the size wrong */
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 048/183] USB: cp210x: add ID for RUGGEDCOM USB Serial Console
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (46 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 047/183] PCI: Fix infinite loop with ROM image of size 0 Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 049/183] Bluetooth: Add support for Broadcom BCM20702A1 variant Luis Henriques
` (134 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Len Sorensen, Johan Hovold, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Lennart Sorensen <lsorense@csclub.uwaterloo.ca>
commit a6f0331236fa75afba14bbcf6668d42cebb55c43 upstream.
Added the USB serial console device ID for Siemens Ruggedcom devices
which have a USB port for their serial console.
Signed-off-by: Len Sorensen <lsorense@csclub.uwaterloo.ca>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/usb/serial/cp210x.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/usb/serial/cp210x.c b/drivers/usb/serial/cp210x.c
index 9e8708c5cbfa..a2d040971afe 100644
--- a/drivers/usb/serial/cp210x.c
+++ b/drivers/usb/serial/cp210x.c
@@ -56,6 +56,7 @@ static const struct usb_device_id id_table[] = {
{ USB_DEVICE(0x0846, 0x1100) }, /* NetGear Managed Switch M4100 series, M5300 series, M7100 series */
{ USB_DEVICE(0x08e6, 0x5501) }, /* Gemalto Prox-PU/CU contactless smartcard reader */
{ USB_DEVICE(0x08FD, 0x000A) }, /* Digianswer A/S , ZigBee/802.15.4 MAC Device */
+ { USB_DEVICE(0x0908, 0x01FF) }, /* Siemens RUGGEDCOM USB Serial Console */
{ USB_DEVICE(0x0BED, 0x1100) }, /* MEI (TM) Cashflow-SC Bill/Voucher Acceptor */
{ USB_DEVICE(0x0BED, 0x1101) }, /* MEI series 2000 Combo Acceptor */
{ USB_DEVICE(0x0FCF, 0x1003) }, /* Dynastream ANT development board */
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 049/183] Bluetooth: Add support for Broadcom BCM20702A1 variant
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (47 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 048/183] USB: cp210x: add ID for RUGGEDCOM USB Serial Console Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 050/183] Bluetooth: Add support for Broadcom BCM20702A0 variants firmware download Luis Henriques
` (133 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Fabio K, Marcel Holtmann, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Fabio K <healthkit@gmail.com>
commit a86c02ea38c53b695209b1181f9e2e18d73eb4e8 upstream.
This variant requires the flag BTUSB_BCM_PATCHRAM to work.
Relevant details from /sys/kernel/debug/usb/devices:
T: Bus=01 Lev=02 Prnt=02 Port=04 Cnt=01 Dev#= 3 Spd=12 MxCh= 0
D: Ver= 2.00 Cls=ff(vend.) Sub=01 Prot=01 MxPS=64 #Cfgs= 1
P: Vendor=13d3 ProdID=3404 Rev= 1.12
S: Manufacturer=Broadcom Corp
S: Product=BCM20702A0
S: SerialNumber=240A646F1XXX
C:* #Ifs= 4 Cfg#= 1 Atr=e0 MxPwr= 0mA
I:* If#= 0 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=81(I) Atr=03(Int.) MxPS= 16 Ivl=1ms
E: Ad=82(I) Atr=02(Bulk) MxPS= 64 Ivl=0ms
E: Ad=02(O) Atr=02(Bulk) MxPS= 64 Ivl=0ms
I:* If#= 1 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 0 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 0 Ivl=1ms
I: If#= 1 Alt= 1 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 9 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 9 Ivl=1ms
I: If#= 1 Alt= 2 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 17 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 17 Ivl=1ms
I: If#= 1 Alt= 3 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 25 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 25 Ivl=1ms
I: If#= 1 Alt= 4 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 33 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 33 Ivl=1ms
I: If#= 1 Alt= 5 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 49 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 49 Ivl=1ms
I:* If#= 2 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=ff Driver=(none)
E: Ad=84(I) Atr=02(Bulk) MxPS= 32 Ivl=0ms
E: Ad=04(O) Atr=02(Bulk) MxPS= 32 Ivl=0ms
I:* If#= 3 Alt= 0 #EPs= 0 Cls=fe(app. ) Sub=01 Prot=01 Driver=(none)
The firmware was extracted from a Windows 8.1 64-bit installation
and converted from 'hex' to 'hcd' for use in Linux.
Under Windows it also identifies itself as BCM20702A0,
but the firmware is named "BCM20702A1_001.002.014.1315.1356.hex"
and is located in "%SYSTEMROOT%\system32\drivers\"
(md5 67cf6bfdae61c4bb819a66da984f7913)
(sha1 5f74cc6a9a3bf19ee0f8c3d01e4be34c609b188f)
The same firmware file is also available as a download at
http://www.asrock.com/mb/Intel/Z87E-ITX/?cat=Download&os=All
marked as "Bluetooth driver ver:12.0.0.7820"
'hcd' file should be placed at "brcm/BCM20702A0-13d3-3404.hcd"
inside the firmware directory (e.g. "/lib/firmware")
Signed-off-by: Fabio K <healthkit@gmail.com>
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/bluetooth/btusb.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index 1c617983315d..391f1b975f57 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -108,6 +108,8 @@ static const struct usb_device_id btusb_table[] = {
{ USB_DEVICE(0x0b05, 0x17b5) },
{ USB_DEVICE(0x0b05, 0x17cb) },
{ USB_DEVICE(0x413c, 0x8197) },
+ { USB_DEVICE(0x13d3, 0x3404),
+ .driver_info = BTUSB_BCM_PATCHRAM },
/* Foxconn - Hon Hai */
{ USB_VENDOR_AND_INTERFACE_INFO(0x0489, 0xff, 0x01, 0x01) },
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 050/183] Bluetooth: Add support for Broadcom BCM20702A0 variants firmware download
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (48 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 049/183] Bluetooth: Add support for Broadcom BCM20702A1 variant Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 051/183] Bluetooth: btusb: Add support for Dynex/Insignia USB dongles Luis Henriques
` (132 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Heinrich Siebmanns, Marcel Holtmann, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Heinrich Siebmanns <harv@gmx.de>
commit 6029ddc2333ae37f637d44beef3a1480cbbb33b9 upstream.
This requires the flag BTUSB_BCM_PATCHRAM to work.
Relevant details from /sys/kernel/debug/usb/devices for my device:
T: Bus=03 Lev=02 Prnt=02 Port=03 Cnt=02 Dev#= 4 Spd=12 MxCh= 0
D: Ver= 2.00 Cls=ff(vend.) Sub=01 Prot=01 MxPS=64 #Cfgs= 1
P: Vendor=0489 ProdID=e031 Rev= 1.12
S: Manufacturer=Broadcom Corp
S: Product=BCM20702A0
S: SerialNumber=3859F9CD2AEE
C:* #Ifs= 4 Cfg#= 1 Atr=e0 MxPwr= 0mA
I:* If#= 0 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=81(I) Atr=03(Int.) MxPS= 16 Ivl=1ms
E: Ad=82(I) Atr=02(Bulk) MxPS= 64 Ivl=0ms
E: Ad=02(O) Atr=02(Bulk) MxPS= 64 Ivl=0ms
I:* If#= 1 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 0 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 0 Ivl=1ms
I: If#= 1 Alt= 1 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 9 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 9 Ivl=1ms
I: If#= 1 Alt= 2 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 17 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 17 Ivl=1ms
I: If#= 1 Alt= 3 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 25 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 25 Ivl=1ms
I: If#= 1 Alt= 4 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 33 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 33 Ivl=1ms
I: If#= 1 Alt= 5 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 49 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 49 Ivl=1ms
I:* If#= 2 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=ff Driver=(none)
E: Ad=84(I) Atr=02(Bulk) MxPS= 32 Ivl=0ms
E: Ad=04(O) Atr=02(Bulk) MxPS= 32 Ivl=0ms
I:* If#= 3 Alt= 0 #EPs= 0 Cls=fe(app. ) Sub=01 Prot=01 Driver=(none)
The firmware was extracted from a Windows 7 32-bit installation
and converted from 'hex' to 'hcd' for use in Linux.
The firmware is named "BCM20702A0_001.001.024.0156.0204.hex"
and is located in "%SYSTEMROOT%\system32\drivers\"
(md5 d126e6c4e0e669d76c38cf9377f76b7f)
(sha1 145d1850b2785a953233b409e7ff77786927c7d2)
The firmware file is also available as a download at
http://support.ts.fujitsu.com/Download/
contained in "FTS_WIDCOMMBluetoothSoftware_6309000_1072149.zip"
Search for the file Win32/bcbtums-win7x86-brcm.inf in the archive,
look for the vendor and product ID of your adapter, see the section
'devices' in that file to find out what device name it uses. See
the device entry in the inf file (in my case it was 'RAMUSBE031')
to find out which hex file you need to convert to hcd for upload
'hcd' file should be placed at "brcm/BCM20702A0-0489-e031.hcd"
inside the firmware directory (e.g. "/lib/firmware")
Signed-off-by: Heinrich Siebmanns <harv@gmx.de>
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/bluetooth/btusb.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index 391f1b975f57..ce08dcf22e3b 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -112,7 +112,8 @@ static const struct usb_device_id btusb_table[] = {
.driver_info = BTUSB_BCM_PATCHRAM },
/* Foxconn - Hon Hai */
- { USB_VENDOR_AND_INTERFACE_INFO(0x0489, 0xff, 0x01, 0x01) },
+ { USB_VENDOR_AND_INTERFACE_INFO(0x0489, 0xff, 0x01, 0x01),
+ .driver_info = BTUSB_BCM_PATCHRAM },
/* Broadcom devices with vendor specific id */
{ USB_VENDOR_AND_INTERFACE_INFO(0x0a5c, 0xff, 0x01, 0x01),
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 051/183] Bluetooth: btusb: Add support for Dynex/Insignia USB dongles
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (49 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 050/183] Bluetooth: Add support for Broadcom BCM20702A0 variants firmware download Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 052/183] clk: zynq: Force CPU_2X clock to be ungated Luis Henriques
` (131 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Marcel Holtmann, Johan Hedberg, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Marcel Holtmann <marcel@holtmann.org>
commit d049f4e513e861167361b06c7ca85f9e872c8cde upstream.
The Dynex/Insignia USB dongles are Broadcom BCM20702B0 based and require
firmware update before operation.
T: Bus=01 Lev=01 Prnt=01 Port=00 Cnt=01 Dev#= 2 Spd=12 MxCh= 0
D: Ver= 2.00 Cls=ff(vend.) Sub=01 Prot=01 MxPS=64 #Cfgs= 1
P: Vendor=19ff ProdID=0239 Rev= 1.12
S: Manufacturer=Broadcom Corp
S: Product=BCM20702A0
C:* #Ifs= 4 Cfg#= 1 Atr=e0 MxPwr= 0mA
I:* If#= 0 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=81(I) Atr=03(Int.) MxPS= 16 Ivl=1ms
E: Ad=82(I) Atr=02(Bulk) MxPS= 64 Ivl=0ms
E: Ad=02(O) Atr=02(Bulk) MxPS= 64 Ivl=0ms
I:* If#= 1 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 0 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 0 Ivl=1ms
I: If#= 1 Alt= 1 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 9 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 9 Ivl=1ms
I: If#= 1 Alt= 2 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 17 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 17 Ivl=1ms
I: If#= 1 Alt= 3 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 25 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 25 Ivl=1ms
I: If#= 1 Alt= 4 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 33 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 33 Ivl=1ms
I: If#= 1 Alt= 5 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=btusb
E: Ad=83(I) Atr=01(Isoc) MxPS= 49 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 49 Ivl=1ms
I:* If#= 2 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=ff Driver=(none)
E: Ad=84(I) Atr=02(Bulk) MxPS= 32 Ivl=0ms
E: Ad=04(O) Atr=02(Bulk) MxPS= 32 Ivl=0ms
I:* If#= 3 Alt= 0 #EPs= 0 Cls=fe(app. ) Sub=01 Prot=01 Driver=(none)
Since this is an unsual USB vendor ID (0x19ff), these dongles are added
via USB_DEVICE macro and not USB_VENDOR_AND_INTERFACE_INFO as done for
mainstream Broadcom based dongles.
The latest known working firmware is BCM20702B0_002.001.014.0527.0557.hex
which needs to be converted using hex2hcd utility and then installed
as /lib/firmware/brcm/BCM20702A0-19ff-0239.hcd to make this device fully
operational.
Bluetooth: hci0: BCM: patching hci_ver=06 hci_rev=2000 lmp_ver=06 lmp_subver=410e
Bluetooth: hci0: BCM: firmware hci_ver=06 hci_rev=222d lmp_ver=06 lmp_subver=410e
With this firmware the device reports support for connectionless slave
broadcast (master and slave) feature used by 3D Glasses and TVs.
< HCI Command: Read Local Extended Features (0x04|0x0004) plen 1
Page: 2
> HCI Event: Command Complete (0x0e) plen 14
Read Local Extended Features (0x04|0x0004) ncmd 1
Status: Success (0x00)
Page: 2/2
Features: 0x0f 0x00 0x00 0x00 0x00 0x00 0x00 0x00
Connectionless Slave Broadcast - Master
Connectionless Slave Broadcast - Slave
Synchronization Train
Synchronization Scan
However there are some flaws with this feature. The Set Event Mask Page 2
command is actually not supported and with that all connectionless slave
broadcast events are always enabled.
< HCI Command: Set Event Mask Page 2 (0x03|0x0063) plen 8
Mask: 0x00000000000f0000
Synchronization Train Received
Connectionless Slave Broadcast Receive
Connectionless Slave Broadcast Timeout
Truncated Page Complete
> HCI Event: Command Complete (0x0e) plen 4
Set Event Mask Page 2 (0x03|0x0063) ncmd 1
Status: Unknown HCI Command (0x01)
In addition the Synchronization Train Received event is actually broken
on this controller. It mixes up the order of parameters. According to the
Bluetooth Core specification the fields are like this:
struct hci_ev_sync_train_received {
__u8 status;
bdaddr_t bdaddr;
__le32 offset;
__u8 map[10];
__u8 lt_addr;
__le32 instant;
__le16 interval;
__u8 service_data;
} __packed;
This controller however sends the service_data as 5th parameter instead
of having it as last parameter.
struct hci_ev_sync_train_received {
__u8 status;
bdaddr_t bdaddr;
__le32 offset;
__u8 map[10];
__u8 service_data;
__u8 lt_addr;
__le32 instant;
__le16 interval;
} __packed;
So anybody trying to use this hardware for utilizing connectionless slave
broadcast receivers (aka 3D Glasses), be warned about this shortcoming.
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
Signed-off-by: Johan Hedberg <johan.hedberg@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/bluetooth/btusb.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index ce08dcf22e3b..143c4b6622ca 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -111,6 +111,9 @@ static const struct usb_device_id btusb_table[] = {
{ USB_DEVICE(0x13d3, 0x3404),
.driver_info = BTUSB_BCM_PATCHRAM },
+ /* Broadcom BCM20702B0 (Dynex/Insignia) */
+ { USB_DEVICE(0x19ff, 0x0239), .driver_info = BTUSB_BCM_PATCHRAM },
+
/* Foxconn - Hon Hai */
{ USB_VENDOR_AND_INTERFACE_INFO(0x0489, 0xff, 0x01, 0x01),
.driver_info = BTUSB_BCM_PATCHRAM },
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 052/183] clk: zynq: Force CPU_2X clock to be ungated
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (50 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 051/183] Bluetooth: btusb: Add support for Dynex/Insignia USB dongles Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 053/183] mmc: sdhci-pxav3: Remove checks for mandatory host clock Luis Henriques
` (130 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Soren Brinkmann, Michael Turquette, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Soren Brinkmann <soren.brinkmann@xilinx.com>
commit 3dccfecdb867fe35b305a4e493ef5652b7d9d4cb upstream.
The CPU_2X clock does not have a classical in-kernel user, but is,
amongst other things, required for OCM and debug access. Make sure this
clock is not mistakenly disabled during boot up by enabling it in the
platform's clock driver.
Fixes: 0ee52b157b8e 'clk: zynq: Add clock controller driver'
Signed-off-by: Soren Brinkmann <soren.brinkmann@xilinx.com>
Signed-off-by: Michael Turquette <mturquette@linaro.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/clk/zynq/clkc.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/clk/zynq/clkc.c b/drivers/clk/zynq/clkc.c
index 246cf1226eaa..5b66a8e0cc82 100644
--- a/drivers/clk/zynq/clkc.c
+++ b/drivers/clk/zynq/clkc.c
@@ -304,6 +304,7 @@ static void __init zynq_clk_setup(struct device_node *np)
clks[cpu_2x] = clk_register_gate(NULL, clk_output_name[cpu_2x],
"cpu_2x_div", CLK_IGNORE_UNUSED, SLCR_ARM_CLK_CTRL,
26, 0, &armclk_lock);
+ clk_prepare_enable(clks[cpu_2x]);
clk = clk_register_fixed_factor(NULL, "cpu_1x_div", "cpu_div", 0, 1,
4 + 2 * tmp);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 053/183] mmc: sdhci-pxav3: Remove checks for mandatory host clock
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (51 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 052/183] clk: zynq: Force CPU_2X clock to be ungated Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 054/183] mmc: sdhci-pxav3: fix race between runtime pm and irq Luis Henriques
` (129 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Sebastian Hesselbarth, Ulf Hansson, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Sebastian Hesselbarth <sebastian.hesselbarth@gmail.com>
commit 20d5a70344e526f51efe50861be10f6d743b7706 upstream.
NULL-checking a struct clk it not only wrong but also not required as
for PXAv3 driver the corresponding clock is mandatory. Remove the
checks from sdhci_pxav3_runtime_{suspend,resume}.
Signed-off-by: Sebastian Hesselbarth <sebastian.hesselbarth@gmail.com>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/mmc/host/sdhci-pxav3.c | 20 ++++++++------------
1 file changed, 8 insertions(+), 12 deletions(-)
diff --git a/drivers/mmc/host/sdhci-pxav3.c b/drivers/mmc/host/sdhci-pxav3.c
index 81143e57b2ff..f62655bc1604 100644
--- a/drivers/mmc/host/sdhci-pxav3.c
+++ b/drivers/mmc/host/sdhci-pxav3.c
@@ -450,13 +450,11 @@ static int sdhci_pxav3_runtime_suspend(struct device *dev)
struct sdhci_pltfm_host *pltfm_host = sdhci_priv(host);
unsigned long flags;
- if (pltfm_host->clk) {
- spin_lock_irqsave(&host->lock, flags);
- host->runtime_suspended = true;
- spin_unlock_irqrestore(&host->lock, flags);
+ spin_lock_irqsave(&host->lock, flags);
+ host->runtime_suspended = true;
+ spin_unlock_irqrestore(&host->lock, flags);
- clk_disable_unprepare(pltfm_host->clk);
- }
+ clk_disable_unprepare(pltfm_host->clk);
return 0;
}
@@ -467,13 +465,11 @@ static int sdhci_pxav3_runtime_resume(struct device *dev)
struct sdhci_pltfm_host *pltfm_host = sdhci_priv(host);
unsigned long flags;
- if (pltfm_host->clk) {
- clk_prepare_enable(pltfm_host->clk);
+ clk_prepare_enable(pltfm_host->clk);
- spin_lock_irqsave(&host->lock, flags);
- host->runtime_suspended = false;
- spin_unlock_irqrestore(&host->lock, flags);
- }
+ spin_lock_irqsave(&host->lock, flags);
+ host->runtime_suspended = false;
+ spin_unlock_irqrestore(&host->lock, flags);
return 0;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 054/183] mmc: sdhci-pxav3: fix race between runtime pm and irq
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (52 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 053/183] mmc: sdhci-pxav3: Remove checks for mandatory host clock Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 055/183] power_supply: 88pm860x: Fix leaked power supply on probe fail Luis Henriques
` (128 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Jisheng Zhang, Ulf Hansson, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jisheng Zhang <jszhang@marvell.com>
commit 3bb10f60933e84abfe2be69f60b3486f9b96348b upstream.
This patch is to fix a race condition that may cause an unhandled irq,
which results in big sdhci interrupt numbers and endless "mmc1: got irq
while runtime suspended" msgs before v3.15.
Consider following scenario:
CPU0 CPU1
sdhci_pxav3_runtime_suspend()
spin_lock_irqsave(&host->lock, flags);
sdhci_irq()
spining on the &host->lock
host->runtime_suspended = true;
spin_unlock_irqrestore(&host->lock, flags);
get the &host->lock
runtime_suspended is true now
return IRQ_NONE;
Fix this race by using the core sdhci.c supplied sdhci_runtime_suspend_host()
in runtime suspend hook which will disable card interrupts. We also use the
sdhci_runtime_resume_host() in the runtime resume hook accordingly.
Signed-off-by: Jisheng Zhang <jszhang@marvell.com>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/mmc/host/sdhci-pxav3.c | 15 +++++----------
1 file changed, 5 insertions(+), 10 deletions(-)
diff --git a/drivers/mmc/host/sdhci-pxav3.c b/drivers/mmc/host/sdhci-pxav3.c
index f62655bc1604..a30f42003fb8 100644
--- a/drivers/mmc/host/sdhci-pxav3.c
+++ b/drivers/mmc/host/sdhci-pxav3.c
@@ -448,11 +448,11 @@ static int sdhci_pxav3_runtime_suspend(struct device *dev)
{
struct sdhci_host *host = dev_get_drvdata(dev);
struct sdhci_pltfm_host *pltfm_host = sdhci_priv(host);
- unsigned long flags;
+ int ret;
- spin_lock_irqsave(&host->lock, flags);
- host->runtime_suspended = true;
- spin_unlock_irqrestore(&host->lock, flags);
+ ret = sdhci_runtime_suspend_host(host);
+ if (ret)
+ return ret;
clk_disable_unprepare(pltfm_host->clk);
@@ -463,15 +463,10 @@ static int sdhci_pxav3_runtime_resume(struct device *dev)
{
struct sdhci_host *host = dev_get_drvdata(dev);
struct sdhci_pltfm_host *pltfm_host = sdhci_priv(host);
- unsigned long flags;
clk_prepare_enable(pltfm_host->clk);
- spin_lock_irqsave(&host->lock, flags);
- host->runtime_suspended = false;
- spin_unlock_irqrestore(&host->lock, flags);
-
- return 0;
+ return sdhci_runtime_resume_host(host);
}
#endif
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 055/183] power_supply: 88pm860x: Fix leaked power supply on probe fail
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (53 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 054/183] mmc: sdhci-pxav3: fix race between runtime pm and irq Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 056/183] staging: comedi: comedi_compat32.c: fix COMEDI_CMD copy back Luis Henriques
` (127 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Krzysztof Kozlowski, Sebastian Reichel, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Krzysztof Kozlowski <k.kozlowski@samsung.com>
commit 24727b45b484e8937dcde53fa8d1aa70ac30ec0c upstream.
Driver forgot to unregister power supply if request_threaded_irq()
failed in probe(). In such case the memory associated with power supply
leaked.
Signed-off-by: Krzysztof Kozlowski <k.kozlowski@samsung.com>
Fixes: a830d28b48bf ("power_supply: Enable battery-charger for 88pm860x")
Signed-off-by: Sebastian Reichel <sre@kernel.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/power/88pm860x_charger.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/power/88pm860x_charger.c b/drivers/power/88pm860x_charger.c
index de029bbc1cc1..5ccca8743ce6 100644
--- a/drivers/power/88pm860x_charger.c
+++ b/drivers/power/88pm860x_charger.c
@@ -711,6 +711,7 @@ static int pm860x_charger_probe(struct platform_device *pdev)
return 0;
out_irq:
+ power_supply_unregister(&info->usb);
while (--i >= 0)
free_irq(info->irq[i], info);
out:
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 056/183] staging: comedi: comedi_compat32.c: fix COMEDI_CMD copy back
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (54 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 055/183] power_supply: 88pm860x: Fix leaked power supply on probe fail Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 057/183] mmc: sdhci-pxav3: fix setting of pdata->clk_delay_cycles Luis Henriques
` (126 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Ian Abbott, Greg Kroah-Hartman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Abbott <abbotti@mev.co.uk>
commit 42b8ce6f55facfa101462e694d33fc6bca471138 upstream.
`do_cmd_ioctl()` in "comedi_fops.c" handles the `COMEDI_CMD` ioctl.
This returns `-EAGAIN` if it has copied a modified `struct comedi_cmd`
back to user-space. (This occurs when the low-level Comedi driver's
`do_cmdtest()` handler returns non-zero to indicate a problem with the
contents of the `struct comedi_cmd`, or when the `struct comedi_cmd` has
the `CMDF_BOGUS` flag set.)
`compat_cmd()` in "comedi_compat32.c" handles the 32-bit compatible
version of the `COMEDI_CMD` ioctl. Currently, it never copies a 32-bit
compatible version of `struct comedi_cmd` back to user-space, which is
at odds with the way the regular `COMEDI_CMD` ioctl is handled. To fix
it, change `compat_cmd()` to copy a 32-bit compatible version of the
`struct comedi_cmd` back to user-space when the main ioctl handler
returns `-EAGAIN`.
Signed-off-by: Ian Abbott <abbotti@mev.co.uk>
Reviewed-by: H Hartley Sweeten <hsweeten@visionengravers.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/staging/comedi/comedi_compat32.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/drivers/staging/comedi/comedi_compat32.c b/drivers/staging/comedi/comedi_compat32.c
index 1e9da405d833..528781049ad5 100644
--- a/drivers/staging/comedi/comedi_compat32.c
+++ b/drivers/staging/comedi/comedi_compat32.c
@@ -262,7 +262,7 @@ static int compat_cmd(struct file *file, unsigned long arg)
{
struct comedi_cmd __user *cmd;
struct comedi32_cmd_struct __user *cmd32;
- int rc;
+ int rc, err;
cmd32 = compat_ptr(arg);
cmd = compat_alloc_user_space(sizeof(*cmd));
@@ -271,7 +271,15 @@ static int compat_cmd(struct file *file, unsigned long arg)
if (rc)
return rc;
- return translated_ioctl(file, COMEDI_CMD, (unsigned long)cmd);
+ rc = translated_ioctl(file, COMEDI_CMD, (unsigned long)cmd);
+ if (rc == -EAGAIN) {
+ /* Special case: copy cmd back to user. */
+ err = put_compat_cmd(cmd32, cmd);
+ if (err)
+ rc = err;
+ }
+
+ return rc;
}
/* Handle 32-bit COMEDI_CMDTEST ioctl. */
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 057/183] mmc: sdhci-pxav3: fix setting of pdata->clk_delay_cycles
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (55 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 056/183] staging: comedi: comedi_compat32.c: fix COMEDI_CMD copy back Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 058/183] mmc: sdhci-pxav3: Fix SDR50 and DDR50 capabilities for the Armada 38x flavor Luis Henriques
` (125 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Jisheng Zhang, Ulf Hansson, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jisheng Zhang <jszhang@marvell.com>
commit 14460dbaf7a5a0488963fdb8232ad5c8a8cca7b7 upstream.
Current code checks "clk_delay_cycles > 0" to know whether the optional
"mrvl,clk_delay_cycles" is set or not. But of_property_read_u32() doesn't
touch clk_delay_cycles if the property is not set. And type of
clk_delay_cycles is u32, so we may always set pdata->clk_delay_cycles as a
random value.
This patch fix this problem by check the return value of of_property_read_u32()
to know whether the optional clk-delay-cycles is set or not.
Signed-off-by: Jisheng Zhang <jszhang@marvell.com>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/mmc/host/sdhci-pxav3.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/mmc/host/sdhci-pxav3.c b/drivers/mmc/host/sdhci-pxav3.c
index a30f42003fb8..0c2c12b7149a 100644
--- a/drivers/mmc/host/sdhci-pxav3.c
+++ b/drivers/mmc/host/sdhci-pxav3.c
@@ -261,8 +261,8 @@ static struct sdhci_pxa_platdata *pxav3_get_mmc_pdata(struct device *dev)
if (!pdata)
return NULL;
- of_property_read_u32(np, "mrvl,clk-delay-cycles", &clk_delay_cycles);
- if (clk_delay_cycles > 0)
+ if (!of_property_read_u32(np, "mrvl,clk-delay-cycles",
+ &clk_delay_cycles))
pdata->clk_delay_cycles = clk_delay_cycles;
return pdata;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 058/183] mmc: sdhci-pxav3: Fix SDR50 and DDR50 capabilities for the Armada 38x flavor
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (56 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 057/183] mmc: sdhci-pxav3: fix setting of pdata->clk_delay_cycles Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 059/183] mmc: sdhci-pxav3: Fix Armada 38x controller's caps according to erratum ERR-7878951 Luis Henriques
` (124 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Gregory CLEMENT, Marcin Wojtas, Ulf Hansson, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Gregory CLEMENT <gregory.clement@free-electrons.com>
commit d4b803c559843e3774736e5108cf6331cf75f64c upstream.
According to erratum 'FE-2946959' both SDR50 and DDR50 modes require
specific clock adjustments in SDIO3 Configuration register. However,
this register was not part of the device tree binding. Even if the
binding can (and will) be extended we still need handling the case
where this register was not available. In this case we use the
SDHCI_QUIRK_MISSING_CAPS quirk remove them from the capabilities.
This commit is based on the work done by Marcin Wojtas<mw@semihalf.com>
Fixes: 5491ce3f79ee ("mmc: sdhci-pxav3: add support for the Armada 38x SDHCI controller")
Signed-off-by: Gregory CLEMENT <gregory.clement@free-electrons.com>
Signed-off-by: Marcin Wojtas <mw@semihalf.com>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/mmc/host/sdhci-pxav3.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/drivers/mmc/host/sdhci-pxav3.c b/drivers/mmc/host/sdhci-pxav3.c
index 0c2c12b7149a..f6a5aaf7c918 100644
--- a/drivers/mmc/host/sdhci-pxav3.c
+++ b/drivers/mmc/host/sdhci-pxav3.c
@@ -112,6 +112,20 @@ static int mv_conf_mbus_windows(struct platform_device *pdev,
return 0;
}
+static int armada_38x_quirks(struct sdhci_host *host)
+{
+ host->quirks |= SDHCI_QUIRK_MISSING_CAPS;
+ /*
+ * According to erratum 'FE-2946959' both SDR50 and DDR50
+ * modes require specific clock adjustments in SDIO3
+ * Configuration register, if the adjustment is not done,
+ * remove them from the capabilities.
+ */
+ host->caps1 = sdhci_readl(host, SDHCI_CAPABILITIES_1);
+ host->caps1 &= ~(SDHCI_SUPPORT_SDR50 | SDHCI_SUPPORT_DDR50);
+ return 0;
+}
+
static void pxav3_reset(struct sdhci_host *host, u8 mask)
{
struct platform_device *pdev = to_platform_device(mmc_dev(host->mmc));
@@ -310,6 +324,9 @@ static int sdhci_pxav3_probe(struct platform_device *pdev)
clk_prepare_enable(clk);
if (of_device_is_compatible(np, "marvell,armada-380-sdhci")) {
+ ret = armada_38x_quirks(host);
+ if (ret < 0)
+ goto err_clk_get;
ret = mv_conf_mbus_windows(pdev, mv_mbus_dram_info());
if (ret < 0)
goto err_mbus_win;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 059/183] mmc: sdhci-pxav3: Fix Armada 38x controller's caps according to erratum ERR-7878951
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (57 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 058/183] mmc: sdhci-pxav3: Fix SDR50 and DDR50 capabilities for the Armada 38x flavor Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 060/183] ARM: 8284/1: sa1100: clear RCSR_SMR on resume Luis Henriques
` (123 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Gregory CLEMENT, Ulf Hansson, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Marcin Wojtas <mw@semihalf.com>
commit a39128bcd6f1e56c6514abf489b40b67d226093b upstream.
According to erratum 'ERR-7878951' Armada 38x SDHCI controller has
different capabilities than the ones shown in its registers:
- it doesn't support the voltage switching: it can work either with
3.3V or 1.8V supply
- it doesn't support the SDR104 mode
- SDR50 mode doesn't need tuning
The SDHCI_QUIRK_MISSING_CAPS quirk is used for updating the
capabilities accordingly.
[gregory.clement@free-electrons.com: port from 3.10]
Fixes: 5491ce3f79ee ("mmc: sdhci-pxav3: add support for the Armada 38x SDHCI controller")
Signed-off-by: Gregory CLEMENT <gregory.clement@free-electrons.com>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/mmc/host/sdhci-pxav3.c | 28 +++++++++++++++++++++++-----
1 file changed, 23 insertions(+), 5 deletions(-)
diff --git a/drivers/mmc/host/sdhci-pxav3.c b/drivers/mmc/host/sdhci-pxav3.c
index f6a5aaf7c918..3ceadd11f641 100644
--- a/drivers/mmc/host/sdhci-pxav3.c
+++ b/drivers/mmc/host/sdhci-pxav3.c
@@ -112,8 +112,11 @@ static int mv_conf_mbus_windows(struct platform_device *pdev,
return 0;
}
-static int armada_38x_quirks(struct sdhci_host *host)
+static int armada_38x_quirks(struct platform_device *pdev,
+ struct sdhci_host *host)
{
+ struct device_node *np = pdev->dev.of_node;
+
host->quirks |= SDHCI_QUIRK_MISSING_CAPS;
/*
* According to erratum 'FE-2946959' both SDR50 and DDR50
@@ -123,6 +126,21 @@ static int armada_38x_quirks(struct sdhci_host *host)
*/
host->caps1 = sdhci_readl(host, SDHCI_CAPABILITIES_1);
host->caps1 &= ~(SDHCI_SUPPORT_SDR50 | SDHCI_SUPPORT_DDR50);
+
+ /*
+ * According to erratum 'ERR-7878951' Armada 38x SDHCI
+ * controller has different capabilities than the ones shown
+ * in its registers
+ */
+ host->caps = sdhci_readl(host, SDHCI_CAPABILITIES);
+ if (of_property_read_bool(np, "no-1-8-v")) {
+ host->caps &= ~SDHCI_CAN_VDD_180;
+ host->mmc->caps &= ~MMC_CAP_1_8V_DDR;
+ } else {
+ host->caps &= ~SDHCI_CAN_VDD_330;
+ }
+ host->caps1 &= ~(SDHCI_SUPPORT_SDR104 | SDHCI_USE_SDR50_TUNING);
+
return 0;
}
@@ -323,8 +341,11 @@ static int sdhci_pxav3_probe(struct platform_device *pdev)
pltfm_host->clk = clk;
clk_prepare_enable(clk);
+ /* enable 1/8V DDR capable */
+ host->mmc->caps |= MMC_CAP_1_8V_DDR;
+
if (of_device_is_compatible(np, "marvell,armada-380-sdhci")) {
- ret = armada_38x_quirks(host);
+ ret = armada_38x_quirks(pdev, host);
if (ret < 0)
goto err_clk_get;
ret = mv_conf_mbus_windows(pdev, mv_mbus_dram_info());
@@ -332,9 +353,6 @@ static int sdhci_pxav3_probe(struct platform_device *pdev)
goto err_mbus_win;
}
- /* enable 1/8V DDR capable */
- host->mmc->caps |= MMC_CAP_1_8V_DDR;
-
match = of_match_device(of_match_ptr(sdhci_pxav3_of_match), &pdev->dev);
if (match) {
ret = mmc_of_parse(host->mmc);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 060/183] ARM: 8284/1: sa1100: clear RCSR_SMR on resume
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (58 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 059/183] mmc: sdhci-pxav3: Fix Armada 38x controller's caps according to erratum ERR-7878951 Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 061/183] [media] si2168: define symbol rate limits Luis Henriques
` (122 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dmitry Eremin-Solenikov, Russell King, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Eremin-Solenikov <dbaryshkov@gmail.com>
commit e461894dc2ce7778ccde1c3483c9b15a85a7fc5f upstream.
StrongARM core uses RCSR SMR bit to tell to bootloader that it was reset
by entering the sleep mode. After we have resumed, there is little point
in having that bit enabled. Moreover, if this bit is set before reboot,
the bootloader can become confused. Thus clear the SMR bit on resume
just before clearing the scratchpad (resume address) register.
Signed-off-by: Dmitry Eremin-Solenikov <dbaryshkov@gmail.com>
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/arm/mach-sa1100/pm.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/arm/mach-sa1100/pm.c b/arch/arm/mach-sa1100/pm.c
index 6645d1e31f14..34853d5dfda2 100644
--- a/arch/arm/mach-sa1100/pm.c
+++ b/arch/arm/mach-sa1100/pm.c
@@ -81,6 +81,7 @@ static int sa11x0_pm_enter(suspend_state_t state)
/*
* Ensure not to come back here if it wasn't intended
*/
+ RCSR = RCSR_SMR;
PSPR = 0;
/*
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 061/183] [media] si2168: define symbol rate limits
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (59 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 060/183] ARM: 8284/1: sa1100: clear RCSR_SMR on resume Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 062/183] nfs: don't call blocking operations while !TASK_RUNNING Luis Henriques
` (121 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Antti Palosaari, Mauro Carvalho Chehab, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Antti Palosaari <crope@iki.fi>
commit f1ecc5d119530fce01094307e029ed7f2c9067d8 upstream.
w_scan complains about missing symbol rate limits:
This dvb driver is *buggy*: the symbol rate limits are undefined - please report to linuxtv.org
Chip supports 1 to 7.2 MSymbol/s on DVB-C.
Signed-off-by: Antti Palosaari <crope@iki.fi>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/media/dvb-frontends/si2168.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/media/dvb-frontends/si2168.c b/drivers/media/dvb-frontends/si2168.c
index 2e3cdcfa0a67..23cc7f089974 100644
--- a/drivers/media/dvb-frontends/si2168.c
+++ b/drivers/media/dvb-frontends/si2168.c
@@ -624,6 +624,8 @@ static const struct dvb_frontend_ops si2168_ops = {
.delsys = {SYS_DVBT, SYS_DVBT2, SYS_DVBC_ANNEX_A},
.info = {
.name = "Silicon Labs Si2168",
+ .symbol_rate_min = 1000000,
+ .symbol_rate_max = 7200000,
.caps = FE_CAN_FEC_1_2 |
FE_CAN_FEC_2_3 |
FE_CAN_FEC_3_4 |
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 062/183] nfs: don't call blocking operations while !TASK_RUNNING
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (60 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 061/183] [media] si2168: define symbol rate limits Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 063/183] cdc-acm: add sanity checks Luis Henriques
` (120 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Jeff Layton, Trond Myklebust, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Layton <jlayton@primarydata.com>
commit 6ffa30d3f734d4f6b478081dfc09592021028f90 upstream.
Bruce reported seeing this warning pop when mounting using v4.1:
------------[ cut here ]------------
WARNING: CPU: 1 PID: 1121 at kernel/sched/core.c:7300 __might_sleep+0xbd/0xd0()
do not call blocking ops when !TASK_RUNNING; state=1 set at [<ffffffff810ff58f>] prepare_to_wait+0x2f/0x90
Modules linked in: rpcsec_gss_krb5 auth_rpcgss nfsv4 dns_resolver nfs lockd grace sunrpc fscache ip6t_rpfilter ip6t_REJECT nf_reject_ipv6 xt_conntrack ebtable_nat ebtable_broute bridge stp llc ebtable_filter ebtables ip6table_nat nf_conntrack_ipv6 nf_defrag_ipv6 nf_nat_ipv6 ip6table_mangle ip6table_security ip6table_raw ip6table_filter ip6_tables iptable_nat nf_conntrack_ipv4 nf_defrag_ipv4 nf_nat_ipv4 nf_nat nf_conntrack iptable_mangle iptable_security iptable_raw snd_hda_codec_generic snd_hda_intel snd_hda_controller snd_hda_codec snd_hwdep snd_pcm snd_timer ppdev joydev snd virtio_console virtio_balloon pcspkr serio_raw parport_pc parport pvpanic floppy soundcore i2c_piix4 virtio_blk virtio_net qxl drm_kms_helper ttm drm virtio_pci virtio_ring ata_generic virtio pata_acpi
CPU: 1 PID: 1121 Comm: nfsv4.1-svc Not tainted 3.19.0-rc4+ #25
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.7.5-20140709_153950- 04/01/2014
0000000000000000 000000004e5e3f73 ffff8800b998fb48 ffffffff8186ac78
0000000000000000 ffff8800b998fba0 ffff8800b998fb88 ffffffff810ac9da
ffff8800b998fb68 ffffffff81c923e7 00000000000004d9 0000000000000000
Call Trace:
[<ffffffff8186ac78>] dump_stack+0x4c/0x65
[<ffffffff810ac9da>] warn_slowpath_common+0x8a/0xc0
[<ffffffff810aca65>] warn_slowpath_fmt+0x55/0x70
[<ffffffff810ff58f>] ? prepare_to_wait+0x2f/0x90
[<ffffffff810ff58f>] ? prepare_to_wait+0x2f/0x90
[<ffffffff810dd2ad>] __might_sleep+0xbd/0xd0
[<ffffffff8124c973>] kmem_cache_alloc_trace+0x243/0x430
[<ffffffff810d941e>] ? groups_alloc+0x3e/0x130
[<ffffffff810d941e>] groups_alloc+0x3e/0x130
[<ffffffffa0301b1e>] svcauth_unix_accept+0x16e/0x290 [sunrpc]
[<ffffffffa0300571>] svc_authenticate+0xe1/0xf0 [sunrpc]
[<ffffffffa02fc564>] svc_process_common+0x244/0x6a0 [sunrpc]
[<ffffffffa02fd044>] bc_svc_process+0x1c4/0x260 [sunrpc]
[<ffffffffa03d5478>] nfs41_callback_svc+0x128/0x1f0 [nfsv4]
[<ffffffff810ff970>] ? wait_woken+0xc0/0xc0
[<ffffffffa03d5350>] ? nfs4_callback_svc+0x60/0x60 [nfsv4]
[<ffffffff810d45bf>] kthread+0x11f/0x140
[<ffffffff810ea815>] ? local_clock+0x15/0x30
[<ffffffff810d44a0>] ? kthread_create_on_node+0x250/0x250
[<ffffffff81874bfc>] ret_from_fork+0x7c/0xb0
[<ffffffff810d44a0>] ? kthread_create_on_node+0x250/0x250
---[ end trace 675220a11e30f4f2 ]---
nfs41_callback_svc does most of its work while in TASK_INTERRUPTIBLE,
which is just wrong. Fix that by finishing the wait immediately if we've
found that the list has something on it.
Also, we don't expect this kthread to accept signals, so we should be
using a TASK_UNINTERRUPTIBLE sleep instead. That however, opens us up
hung task warnings from the watchdog, so have the schedule_timeout
wake up every 60s if there's no callback activity.
Reported-by: "J. Bruce Fields" <bfields@fieldses.org>
Signed-off-by: Jeff Layton <jlayton@primarydata.com>
Signed-off-by: Trond Myklebust <trond.myklebust@primarydata.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/nfs/callback.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/fs/nfs/callback.c b/fs/nfs/callback.c
index 073b4cf67ed9..0a2016bd6e58 100644
--- a/fs/nfs/callback.c
+++ b/fs/nfs/callback.c
@@ -128,22 +128,24 @@ nfs41_callback_svc(void *vrqstp)
if (try_to_freeze())
continue;
- prepare_to_wait(&serv->sv_cb_waitq, &wq, TASK_INTERRUPTIBLE);
+ prepare_to_wait(&serv->sv_cb_waitq, &wq, TASK_UNINTERRUPTIBLE);
spin_lock_bh(&serv->sv_cb_lock);
if (!list_empty(&serv->sv_cb_list)) {
req = list_first_entry(&serv->sv_cb_list,
struct rpc_rqst, rq_bc_list);
list_del(&req->rq_bc_list);
spin_unlock_bh(&serv->sv_cb_lock);
+ finish_wait(&serv->sv_cb_waitq, &wq);
dprintk("Invoking bc_svc_process()\n");
error = bc_svc_process(serv, req, rqstp);
dprintk("bc_svc_process() returned w/ error code= %d\n",
error);
} else {
spin_unlock_bh(&serv->sv_cb_lock);
- schedule();
+ /* schedule_timeout to game the hung task watchdog */
+ schedule_timeout(60 * HZ);
+ finish_wait(&serv->sv_cb_waitq, &wq);
}
- finish_wait(&serv->sv_cb_waitq, &wq);
}
return 0;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 063/183] cdc-acm: add sanity checks
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (61 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 062/183] nfs: don't call blocking operations while !TASK_RUNNING Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 064/183] USB: add flag for HCDs that can't receive wakeup requests (isp1760-hcd) Luis Henriques
` (119 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Oliver Neukum, Greg Kroah-Hartman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Oliver Neukum <oneukum@suse.de>
commit 7e860a6e7aa62b337a61110430cd633db5b0d2dd upstream.
Check the special CDC headers for a plausible minimum length.
Another big operating systems ignores such garbage.
Signed-off-by: Oliver Neukum <oneukum@suse.de>
Reviewed-by: Adam Lee <adam8157@gmail.com>
Tested-by: Adam Lee <adam8157@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/usb/class/cdc-acm.c | 21 ++++++++++++++++-----
1 file changed, 16 insertions(+), 5 deletions(-)
diff --git a/drivers/usb/class/cdc-acm.c b/drivers/usb/class/cdc-acm.c
index 4d4f6db94c72..bffb50450132 100644
--- a/drivers/usb/class/cdc-acm.c
+++ b/drivers/usb/class/cdc-acm.c
@@ -1086,6 +1086,7 @@ static int acm_probe(struct usb_interface *intf,
unsigned long quirks;
int num_rx_buf;
int i;
+ unsigned int elength = 0;
int combined_interfaces = 0;
struct device *tty_dev;
int rv = -ENOMEM;
@@ -1131,9 +1132,12 @@ static int acm_probe(struct usb_interface *intf,
dev_err(&intf->dev, "skipping garbage\n");
goto next_desc;
}
+ elength = buffer[0];
switch (buffer[2]) {
case USB_CDC_UNION_TYPE: /* we've found it */
+ if (elength < sizeof(struct usb_cdc_union_desc))
+ goto next_desc;
if (union_header) {
dev_err(&intf->dev, "More than one "
"union descriptor, skipping ...\n");
@@ -1142,31 +1146,38 @@ static int acm_probe(struct usb_interface *intf,
union_header = (struct usb_cdc_union_desc *)buffer;
break;
case USB_CDC_COUNTRY_TYPE: /* export through sysfs*/
+ if (elength < sizeof(struct usb_cdc_country_functional_desc))
+ goto next_desc;
cfd = (struct usb_cdc_country_functional_desc *)buffer;
break;
case USB_CDC_HEADER_TYPE: /* maybe check version */
break; /* for now we ignore it */
case USB_CDC_ACM_TYPE:
+ if (elength < 4)
+ goto next_desc;
ac_management_function = buffer[3];
break;
case USB_CDC_CALL_MANAGEMENT_TYPE:
+ if (elength < 5)
+ goto next_desc;
call_management_function = buffer[3];
call_interface_num = buffer[4];
if ((quirks & NOT_A_MODEM) == 0 && (call_management_function & 3) != 3)
dev_err(&intf->dev, "This device cannot do calls on its own. It is not a modem.\n");
break;
default:
- /* there are LOTS more CDC descriptors that
+ /*
+ * there are LOTS more CDC descriptors that
* could legitimately be found here.
*/
dev_dbg(&intf->dev, "Ignoring descriptor: "
- "type %02x, length %d\n",
- buffer[2], buffer[0]);
+ "type %02x, length %ud\n",
+ buffer[2], elength);
break;
}
next_desc:
- buflen -= buffer[0];
- buffer += buffer[0];
+ buflen -= elength;
+ buffer += elength;
}
if (!union_header) {
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 064/183] USB: add flag for HCDs that can't receive wakeup requests (isp1760-hcd)
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (62 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 063/183] cdc-acm: add sanity checks Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 065/183] USB: fix use-after-free bug in usb_hcd_unlink_urb() Luis Henriques
` (118 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Alan Stern, Greg Kroah-Hartman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Alan Stern <stern@rowland.harvard.edu>
commit 074f9dd55f9cab1b82690ed7e44bcf38b9616ce0 upstream.
Currently the USB stack assumes that all host controller drivers are
capable of receiving wakeup requests from downstream devices.
However, this isn't true for the isp1760-hcd driver, which means that
it isn't safe to do a runtime suspend of any device attached to a
root-hub port if the device requires wakeup.
This patch adds a "cant_recv_wakeups" flag to the usb_hcd structure
and sets the flag in isp1760-hcd. The core is modified to prevent a
direct child of the root hub from being put into runtime suspend with
wakeup enabled if the flag is set.
Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Tested-by: Nicolas Pitre <nico@linaro.org>
Signed-off-by: Greg Kroah-Hartman <greg@kroah.com>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/usb/core/driver.c | 12 ++++++++++++
drivers/usb/host/isp1760-hcd.c | 3 +++
include/linux/usb/hcd.h | 2 ++
3 files changed, 17 insertions(+)
diff --git a/drivers/usb/core/driver.c b/drivers/usb/core/driver.c
index 4aeb10034de7..37c7ce9af220 100644
--- a/drivers/usb/core/driver.c
+++ b/drivers/usb/core/driver.c
@@ -1800,6 +1800,18 @@ static int autosuspend_check(struct usb_device *udev)
dev_dbg(&udev->dev, "remote wakeup needed for autosuspend\n");
return -EOPNOTSUPP;
}
+
+ /*
+ * If the device is a direct child of the root hub and the HCD
+ * doesn't handle wakeup requests, don't allow autosuspend when
+ * wakeup is needed.
+ */
+ if (w && udev->parent == udev->bus->root_hub &&
+ bus_to_hcd(udev->bus)->cant_recv_wakeups) {
+ dev_dbg(&udev->dev, "HCD doesn't handle wakeup requests\n");
+ return -EOPNOTSUPP;
+ }
+
udev->do_remote_wakeup = w;
return 0;
}
diff --git a/drivers/usb/host/isp1760-hcd.c b/drivers/usb/host/isp1760-hcd.c
index 51a0ae9cdd1d..5ea7c6bdfd28 100644
--- a/drivers/usb/host/isp1760-hcd.c
+++ b/drivers/usb/host/isp1760-hcd.c
@@ -2247,6 +2247,9 @@ struct usb_hcd *isp1760_register(phys_addr_t res_start, resource_size_t res_len,
hcd->rsrc_start = res_start;
hcd->rsrc_len = res_len;
+ /* This driver doesn't support wakeup requests */
+ hcd->cant_recv_wakeups = 1;
+
ret = usb_add_hcd(hcd, irq, irqflags);
if (ret)
goto err_unmap;
diff --git a/include/linux/usb/hcd.h b/include/linux/usb/hcd.h
index 52598bdce2ba..6e98f62ea70d 100644
--- a/include/linux/usb/hcd.h
+++ b/include/linux/usb/hcd.h
@@ -144,6 +144,8 @@ struct usb_hcd {
unsigned has_tt:1; /* Integrated TT in root hub */
unsigned amd_resume_bug:1; /* AMD remote wakeup quirk */
unsigned can_do_streams:1; /* HC supports streams */
+ unsigned cant_recv_wakeups:1;
+ /* wakeup requests from downstream aren't received */
unsigned int irq; /* irq allocated */
void __iomem *regs; /* device memory/io */
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 065/183] USB: fix use-after-free bug in usb_hcd_unlink_urb()
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (63 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 064/183] USB: add flag for HCDs that can't receive wakeup requests (isp1760-hcd) Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 066/183] iwlwifi: mvm: always use mac color zero Luis Henriques
` (117 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Alan Stern, Greg Kroah-Hartman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Alan Stern <stern@rowland.harvard.edu>
commit c99197902da284b4b723451c1471c45b18537cde upstream.
The usb_hcd_unlink_urb() routine in hcd.c contains two possible
use-after-free errors. The dev_dbg() statement at the end of the
routine dereferences urb and urb->dev even though both structures may
have been deallocated.
This patch fixes the problem by storing urb->dev in a local variable
(avoiding the dereference of urb) and moving the dev_dbg() up before
the usb_put_dev() call.
Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Reported-by: Joe Lawrence <joe.lawrence@stratus.com>
Tested-by: Joe Lawrence <joe.lawrence@stratus.com>
Signed-off-by: Greg Kroah-Hartman <greg@kroah.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/usb/core/hcd.c | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/drivers/usb/core/hcd.c b/drivers/usb/core/hcd.c
index 23d44ac95cd6..4195906f94d6 100644
--- a/drivers/usb/core/hcd.c
+++ b/drivers/usb/core/hcd.c
@@ -1621,6 +1621,7 @@ static int unlink1(struct usb_hcd *hcd, struct urb *urb, int status)
int usb_hcd_unlink_urb (struct urb *urb, int status)
{
struct usb_hcd *hcd;
+ struct usb_device *udev = urb->dev;
int retval = -EIDRM;
unsigned long flags;
@@ -1632,20 +1633,19 @@ int usb_hcd_unlink_urb (struct urb *urb, int status)
spin_lock_irqsave(&hcd_urb_unlink_lock, flags);
if (atomic_read(&urb->use_count) > 0) {
retval = 0;
- usb_get_dev(urb->dev);
+ usb_get_dev(udev);
}
spin_unlock_irqrestore(&hcd_urb_unlink_lock, flags);
if (retval == 0) {
hcd = bus_to_hcd(urb->dev->bus);
retval = unlink1(hcd, urb, status);
- usb_put_dev(urb->dev);
+ if (retval == 0)
+ retval = -EINPROGRESS;
+ else if (retval != -EIDRM && retval != -EBUSY)
+ dev_dbg(&udev->dev, "hcd_unlink_urb %p fail %d\n",
+ urb, retval);
+ usb_put_dev(udev);
}
-
- if (retval == 0)
- retval = -EINPROGRESS;
- else if (retval != -EIDRM && retval != -EBUSY)
- dev_dbg(&urb->dev->dev, "hcd_unlink_urb %p fail %d\n",
- urb, retval);
return retval;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 066/183] iwlwifi: mvm: always use mac color zero
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (64 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 065/183] USB: fix use-after-free bug in usb_hcd_unlink_urb() Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 067/183] iwlwifi: pcie: disable the SCD_BASE_ADDR when we resume from WoWLAN Luis Henriques
` (116 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Luciano Coelho, Emmanuel Grumbach, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Luciano Coelho <luciano.coelho@intel.com>
commit 5523d11cc46393a1e61b7ef4a0b2d4e7ed9521e4 upstream.
We don't really need to use different mac colors when adding mac
contexts, because they're not used anywhere. In fact, the firmware
doesn't accept 255 as a valid color, so we get into a SYSASSERT 0x3401
when we reach that.
Remove the color increment to use always zero and avoid reaching 255.
Signed-off-by: Luciano Coelho <luciano.coelho@intel.com>
Reviewed-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/net/wireless/iwlwifi/mvm/mac80211.c | 3 ---
1 file changed, 3 deletions(-)
diff --git a/drivers/net/wireless/iwlwifi/mvm/mac80211.c b/drivers/net/wireless/iwlwifi/mvm/mac80211.c
index ec70feccf77c..1a5351553078 100644
--- a/drivers/net/wireless/iwlwifi/mvm/mac80211.c
+++ b/drivers/net/wireless/iwlwifi/mvm/mac80211.c
@@ -627,9 +627,6 @@ static void iwl_mvm_cleanup_iterator(void *data, u8 *mac,
mvmvif->uploaded = false;
mvmvif->ap_sta_id = IWL_MVM_STATION_COUNT;
- /* does this make sense at all? */
- mvmvif->color++;
-
spin_lock_bh(&mvm->time_event_lock);
iwl_mvm_te_clear_data(mvm, &mvmvif->time_event_data);
spin_unlock_bh(&mvm->time_event_lock);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 067/183] iwlwifi: pcie: disable the SCD_BASE_ADDR when we resume from WoWLAN
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (65 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 066/183] iwlwifi: mvm: always use mac color zero Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 068/183] iwlwifi: mvm: fix failure path when power_update fails in add_interface Luis Henriques
` (115 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Emmanuel Grumbach, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
commit cd8f438405032ac8ff88bd8f2eca5e0c0063b14b upstream.
The base address of the scheduler in the device's memory
(SRAM) comes from two different sources. The periphery
register and the alive notification from the firmware.
We have a check in iwl_pcie_tx_start that ensures that
they are the same.
When we resume from WoWLAN, the firmware may have crashed
for whatever reason. In that case, the whole device may be
reset which means that the periphery register will hold a
meaningless value. When we come to compare
trans_pcie->scd_base_addr (which really holds the value we
had when we loaded the WoWLAN firmware upon suspend) and
the current value of the register, we don't see a match
unsurprisingly.
Trick the check to avoid a loud yet harmless WARN.
Note that when the WoWLAN has crashed, we will see that
in iwl_trans_pcie_d3_resume which will let the op_mode
know. Once the op_mode is informed that the WowLAN firmware
has crashed, it can't do much besides resetting the whole
device.
Reviewed-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/net/wireless/iwlwifi/pcie/tx.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/iwlwifi/pcie/tx.c b/drivers/net/wireless/iwlwifi/pcie/tx.c
index 038940afbdc5..452bb1b0c791 100644
--- a/drivers/net/wireless/iwlwifi/pcie/tx.c
+++ b/drivers/net/wireless/iwlwifi/pcie/tx.c
@@ -731,7 +731,12 @@ void iwl_trans_pcie_tx_reset(struct iwl_trans *trans)
iwl_write_direct32(trans, FH_KW_MEM_ADDR_REG,
trans_pcie->kw.dma >> 4);
- iwl_pcie_tx_start(trans, trans_pcie->scd_base_addr);
+ /*
+ * Send 0 as the scd_base_addr since the device may have be reset
+ * while we were in WoWLAN in which case SCD_SRAM_BASE_ADDR will
+ * contain garbage.
+ */
+ iwl_pcie_tx_start(trans, 0);
}
/*
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 068/183] iwlwifi: mvm: fix failure path when power_update fails in add_interface
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (66 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 067/183] iwlwifi: pcie: disable the SCD_BASE_ADDR when we resume from WoWLAN Luis Henriques
@ 2015-03-06 9:55 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 069/183] vt: provide notifications on selection changes Luis Henriques
` (114 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:55 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Luciano Coelho, Emmanuel Grumbach, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Luciano Coelho <luciano.coelho@intel.com>
commit fd66fc1cafd72ddf27dbec3a5e29e99839d1bc84 upstream.
When iwl_mvm_power_update_mac() is called, we have already added the
mac context, so if this call fails we should remove the mac.
Fixes: commit e5e7aa8e2561 ('iwlwifi: mvm: refactor power code')
Signed-off-by: Luciano Coelho <luciano.coelho@intel.com>
Reviewed-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/net/wireless/iwlwifi/mvm/mac80211.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/iwlwifi/mvm/mac80211.c b/drivers/net/wireless/iwlwifi/mvm/mac80211.c
index 1a5351553078..b690f7a4ae2f 100644
--- a/drivers/net/wireless/iwlwifi/mvm/mac80211.c
+++ b/drivers/net/wireless/iwlwifi/mvm/mac80211.c
@@ -832,7 +832,7 @@ static int iwl_mvm_mac_add_interface(struct ieee80211_hw *hw,
ret = iwl_mvm_power_update_mac(mvm);
if (ret)
- goto out_release;
+ goto out_remove_mac;
/* beacon filtering */
ret = iwl_mvm_disable_beacon_filter(mvm, vif, 0);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 069/183] vt: provide notifications on selection changes
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (67 preceding siblings ...)
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 068/183] iwlwifi: mvm: fix failure path when power_update fails in add_interface Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 070/183] tty: Prevent untrappable signals from malicious program Luis Henriques
` (113 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Nicolas Pitre, Dave Mielke, Greg Kroah-Hartman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Pitre <nicolas.pitre@linaro.org>
commit 19e3ae6b4f07a87822c1c9e7ed99d31860e701af upstream.
The vcs device's poll/fasync support relies on the vt notifier to signal
changes to the screen content. Notifier invocations were missing for
changes that comes through the selection interface though. Fix that.
Tested with BRLTTY 5.2.
Signed-off-by: Nicolas Pitre <nico@linaro.org>
Cc: Dave Mielke <dave@mielke.cc>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/tty/vt/vt.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/tty/vt/vt.c b/drivers/tty/vt/vt.c
index b33b00b386de..53c25bca7d05 100644
--- a/drivers/tty/vt/vt.c
+++ b/drivers/tty/vt/vt.c
@@ -498,6 +498,7 @@ void invert_screen(struct vc_data *vc, int offset, int count, int viewed)
#endif
if (DO_UPDATE(vc))
do_update_region(vc, (unsigned long) p, count);
+ notify_update(vc);
}
/* used by selection: complement pointer position */
@@ -514,6 +515,7 @@ void complement_pos(struct vc_data *vc, int offset)
scr_writew(old, screenpos(vc, old_offset, 1));
if (DO_UPDATE(vc))
vc->vc_sw->con_putc(vc, old, oldy, oldx);
+ notify_update(vc);
}
old_offset = offset;
@@ -531,8 +533,8 @@ void complement_pos(struct vc_data *vc, int offset)
oldy = (offset >> 1) / vc->vc_cols;
vc->vc_sw->con_putc(vc, new, oldy, oldx);
}
+ notify_update(vc);
}
-
}
static void insert_char(struct vc_data *vc, unsigned int nr)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 070/183] tty: Prevent untrappable signals from malicious program
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (68 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 069/183] vt: provide notifications on selection changes Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 071/183] serial: fsl_lpuart: delete timer on shutdown Luis Henriques
` (112 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Theodore Ts'o, Howard Chu, One Thousand Gnomes, Jiri Slaby,
Peter Hurley, Greg Kroah-Hartman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Hurley <peter@hurleysoftware.com>
commit 37480a05685ed5b8e1b9bf5e5c53b5810258b149 upstream.
Commit 26df6d13406d1a5 ("tty: Add EXTPROC support for LINEMODE")
allows a process which has opened a pty master to send _any_ signal
to the process group of the pty slave. Although potentially
exploitable by a malicious program running a setuid program on
a pty slave, it's unknown if this exploit currently exists.
Limit to signals actually used.
Cc: Theodore Ts'o <tytso@mit.edu>
Cc: Howard Chu <hyc@symas.com>
Cc: One Thousand Gnomes <gnomes@lxorguk.ukuu.org.uk>
Cc: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Peter Hurley <peter@hurleysoftware.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/tty/pty.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/tty/pty.c b/drivers/tty/pty.c
index 25c9bc783722..e49616eeb1cc 100644
--- a/drivers/tty/pty.c
+++ b/drivers/tty/pty.c
@@ -209,6 +209,9 @@ static int pty_signal(struct tty_struct *tty, int sig)
unsigned long flags;
struct pid *pgrp;
+ if (sig != SIGINT && sig != SIGQUIT && sig != SIGTSTP)
+ return -EINVAL;
+
if (tty->link) {
spin_lock_irqsave(&tty->link->ctrl_lock, flags);
pgrp = get_pid(tty->link->pgrp);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 071/183] serial: fsl_lpuart: delete timer on shutdown
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (69 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 070/183] tty: Prevent untrappable signals from malicious program Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 072/183] serial: fsl_lpuart: avoid new transfer while DMA is running Luis Henriques
` (111 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Stefan Agner, Greg Kroah-Hartman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Stefan Agner <stefan@agner.ch>
commit 4a8588a1cf867333187d9ff071e6fbdab587d194 upstream.
If the serial port gets closed while a RX transfer is in progress,
the timer might fire after the serial port shutdown finished. This
leads in a NULL pointer dereference:
[ 7.508324] Unable to handle kernel NULL pointer dereference at virtual address 00000000
[ 7.516590] pgd = 86348000
[ 7.519445] [00000000] *pgd=86179831, *pte=00000000, *ppte=00000000
[ 7.526145] Internal error: Oops: 17 [#1] ARM
[ 7.530611] Modules linked in:
[ 7.533876] CPU: 0 PID: 123 Comm: systemd Not tainted 3.19.0-rc3-00004-g5b11ea7 #1778
[ 7.541827] Hardware name: Freescale Vybrid VF610 (Device Tree)
[ 7.547862] task: 861c3400 ti: 86ac8000 task.ti: 86ac8000
[ 7.553392] PC is at lpuart_timer_func+0x24/0xf8
[ 7.558127] LR is at lpuart_timer_func+0x20/0xf8
[ 7.562857] pc : [<802df99c>] lr : [<802df998>] psr: 600b0113
[ 7.562857] sp : 86ac9b90 ip : 86ac9b90 fp : 86ac9bbc
[ 7.574467] r10: 80817180 r9 : 80817b98 r8 : 80817998
[ 7.579803] r7 : 807acee0 r6 : 86989000 r5 : 00000100 r4 : 86997210
[ 7.586444] r3 : 86ac8000 r2 : 86ac9bc0 r1 : 86997210 r0 : 00000000
[ 7.593085] Flags: nZCv IRQs on FIQs on Mode SVC_32 ISA ARM Segment user
[ 7.600341] Control: 10c5387d Table: 86348059 DAC: 00000015
[ 7.606203] Process systemd (pid: 123, stack limit = 0x86ac8230)
Setup the timer on UART startup which allows to delete the timer
unconditionally on shutdown. This also saves the initialization
on each transfer.
Signed-off-by: Stefan Agner <stefan@agner.ch>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/tty/serial/fsl_lpuart.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/tty/serial/fsl_lpuart.c b/drivers/tty/serial/fsl_lpuart.c
index 49385c86cfba..c930dafce173 100644
--- a/drivers/tty/serial/fsl_lpuart.c
+++ b/drivers/tty/serial/fsl_lpuart.c
@@ -374,9 +374,6 @@ static inline void lpuart_prepare_rx(struct lpuart_port *sport)
spin_lock_irqsave(&sport->port.lock, flags);
- init_timer(&sport->lpuart_timer);
- sport->lpuart_timer.function = lpuart_timer_func;
- sport->lpuart_timer.data = (unsigned long)sport;
sport->lpuart_timer.expires = jiffies + sport->dma_rx_timeout;
add_timer(&sport->lpuart_timer);
@@ -777,6 +774,8 @@ static int lpuart_startup(struct uart_port *port)
sport->lpuart_dma_use = false;
} else {
sport->lpuart_dma_use = true;
+ setup_timer(&sport->lpuart_timer, lpuart_timer_func,
+ (unsigned long)sport);
temp = readb(port->membase + UARTCR5);
writeb(temp | UARTCR5_TDMAS, port->membase + UARTCR5);
}
@@ -817,6 +816,8 @@ static void lpuart_shutdown(struct uart_port *port)
devm_free_irq(port->dev, port->irq, sport);
if (sport->lpuart_dma_use) {
+ del_timer_sync(&sport->lpuart_timer);
+
lpuart_dma_tx_free(port);
lpuart_dma_rx_free(port);
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 072/183] serial: fsl_lpuart: avoid new transfer while DMA is running
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (70 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 071/183] serial: fsl_lpuart: delete timer on shutdown Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 073/183] cpufreq: Set cpufreq_cpu_data to NULL before putting kobject Luis Henriques
` (110 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Stefan Agner, Greg Kroah-Hartman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Stefan Agner <stefan@agner.ch>
commit 5f1437f61a0b351d25b528c159360da3d5e8c77b upstream.
When the UART is in DMA receive mode (RDMAS set) and one character
just arrived while another interrupt is handled (e.g. TX), the RDRF
(receiver data register full flag) is set due to the water level of
1. But since the DMA will take care of this character, there is no
need to handle it by calling lpuart_prepare_rx. Handling it leads to
adding the RX timeout timer twice:
[ 74.336698] Kernel BUG at 80053070 [verbose debug info unavailable]
[ 74.342999] Internal error: Oops - BUG: 0 [#1] ARM0:00.00 khungtaskd
[ 74.347817] Modules linked in: 0 S 0.0 0.0 0:00.00 writeback
[ 74.350926] CPU: 0 PID: 0 Comm: swapper Not tainted 3.19.0-rc3-00001-g39d78e2 #1788
[ 74.358617] Hardware name: Freescale Vybrid VF610 (Device Tree)t
[ 74.364563] task: 807a7678 ti: 8079c000 task.ti: 8079c000 kblockd
[ 74.370002] PC is at add_timer+0x24/0x28.0 0.0 0:00.09 kworker/u2:1
[ 74.373960] LR is at lpuart_int+0x15c/0x3d8
[ 74.378171] pc : [<80053070>] lr : [<802e0d88>] psr: a0010193
[ 74.378171] sp : 8079de10 ip : 8079de20 fp : 8079de1c
[ 74.389694] r10: 807d44c0 r9 : 8688c300 r8 : 00000013
[ 74.394943] r7 : 20010193 r6 : 00000000 r5 : 000000a0 r4 : 86997210
[ 74.401498] r3 : ffffa7da r2 : 80817868 r1 : 86997210 r0 : 86997344
[ 74.408052] Flags: NzCv IRQs off FIQs on Mode SVC_32 ISA ARM Segment kernel
[ 74.415489] Control: 10c5387d Table: 8611c059 DAC: 00000015
[ 74.421265] Process swapper (pid: 0, stack limit = 0x8079c230)
...
Solve this by only execute the receiver path (lpuart_prepare_rx) if
the DMA receive mode (RDMAS) is not set. Also, make sure the flag is
cleared on initialization, in case it has been left set.
This can be best reproduced using UART as a serial console, then
running top while dd'ing data into the terminal.
Signed-off-by: Stefan Agner <stefan@agner.ch>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/tty/serial/fsl_lpuart.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/tty/serial/fsl_lpuart.c b/drivers/tty/serial/fsl_lpuart.c
index c930dafce173..05a033e7446c 100644
--- a/drivers/tty/serial/fsl_lpuart.c
+++ b/drivers/tty/serial/fsl_lpuart.c
@@ -514,18 +514,18 @@ out:
static irqreturn_t lpuart_int(int irq, void *dev_id)
{
struct lpuart_port *sport = dev_id;
- unsigned char sts;
+ unsigned char sts, crdma;
sts = readb(sport->port.membase + UARTSR1);
+ crdma = readb(sport->port.membase + UARTCR5);
- if (sts & UARTSR1_RDRF) {
+ if (sts & UARTSR1_RDRF && !(crdma & UARTCR5_RDMAS)) {
if (sport->lpuart_dma_use)
lpuart_prepare_rx(sport);
else
lpuart_rxint(irq, dev_id);
}
- if (sts & UARTSR1_TDRE &&
- !(readb(sport->port.membase + UARTCR5) & UARTCR5_TDMAS)) {
+ if (sts & UARTSR1_TDRE && !(crdma & UARTCR5_TDMAS)) {
if (sport->lpuart_dma_use)
lpuart_pio_tx(sport);
else
@@ -777,6 +777,7 @@ static int lpuart_startup(struct uart_port *port)
setup_timer(&sport->lpuart_timer, lpuart_timer_func,
(unsigned long)sport);
temp = readb(port->membase + UARTCR5);
+ temp &= ~UARTCR5_RDMAS;
writeb(temp | UARTCR5_TDMAS, port->membase + UARTCR5);
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 073/183] cpufreq: Set cpufreq_cpu_data to NULL before putting kobject
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (71 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 072/183] serial: fsl_lpuart: avoid new transfer while DMA is running Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 074/183] Bluetooth: btusb: Add support for Lite-On (04ca) Broadcom based, BCM43142 Luis Henriques
` (109 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Viresh Kumar, Rafael J. Wysocki, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Viresh Kumar <viresh.kumar@linaro.org>
commit 6ffae8c06fab058d6c3f8ecb7f921327721034e7 upstream.
In __cpufreq_remove_dev_finish(), per-cpu 'cpufreq_cpu_data' needs
to be cleared before calling kobject_put(&policy->kobj) and under
cpufreq_driver_lock. Otherwise, if someone else calls cpufreq_cpu_get()
in parallel with it, they can obtain a non-NULL policy from that after
kobject_put(&policy->kobj) was executed.
Consider this case:
Thread A Thread B
cpufreq_cpu_get()
acquire cpufreq_driver_lock
read-per-cpu cpufreq_cpu_data
kobject_put(&policy->kobj);
kobject_get(&policy->kobj);
...
per_cpu(&cpufreq_cpu_data, cpu) = NULL
And this will result in a warning like this one:
------------[ cut here ]------------
WARNING: CPU: 0 PID: 4 at include/linux/kref.h:47
kobject_get+0x41/0x50()
Modules linked in: acpi_cpufreq(+) nfsd auth_rpcgss nfs_acl
lockd grace sunrpc xfs libcrc32c sd_mod ixgbe igb mdio ahci hwmon
...
Call Trace:
[<ffffffff81661b14>] dump_stack+0x46/0x58
[<ffffffff81072b61>] warn_slowpath_common+0x81/0xa0
[<ffffffff81072c7a>] warn_slowpath_null+0x1a/0x20
[<ffffffff812e16d1>] kobject_get+0x41/0x50
[<ffffffff815262a5>] cpufreq_cpu_get+0x75/0xc0
[<ffffffff81527c3e>] cpufreq_update_policy+0x2e/0x1f0
[<ffffffff810b8cb2>] ? up+0x32/0x50
[<ffffffff81381aa9>] ? acpi_ns_get_node+0xcb/0xf2
[<ffffffff81381efd>] ? acpi_evaluate_object+0x22c/0x252
[<ffffffff813824f6>] ? acpi_get_handle+0x95/0xc0
[<ffffffff81360967>] ? acpi_has_method+0x25/0x40
[<ffffffff81391e08>] acpi_processor_ppc_has_changed+0x77/0x82
[<ffffffff81089566>] ? move_linked_works+0x66/0x90
[<ffffffff8138e8ed>] acpi_processor_notify+0x58/0xe7
[<ffffffff8137410c>] acpi_ev_notify_dispatch+0x44/0x5c
[<ffffffff8135f293>] acpi_os_execute_deferred+0x15/0x22
[<ffffffff8108c910>] process_one_work+0x160/0x410
[<ffffffff8108d05b>] worker_thread+0x11b/0x520
[<ffffffff8108cf40>] ? rescuer_thread+0x380/0x380
[<ffffffff81092421>] kthread+0xe1/0x100
[<ffffffff81092340>] ? kthread_create_on_node+0x1b0/0x1b0
[<ffffffff81669ebc>] ret_from_fork+0x7c/0xb0
[<ffffffff81092340>] ? kthread_create_on_node+0x1b0/0x1b0
---[ end trace 89e66eb9795efdf7 ]---
The actual code flow is as follows:
Thread A: Workqueue: kacpi_notify
acpi_processor_notify()
acpi_processor_ppc_has_changed()
cpufreq_update_policy()
cpufreq_cpu_get()
kobject_get()
Thread B: xenbus_thread()
xenbus_thread()
msg->u.watch.handle->callback()
handle_vcpu_hotplug_event()
vcpu_hotplug()
cpu_down()
__cpu_notify(CPU_POST_DEAD..)
cpufreq_cpu_callback()
__cpufreq_remove_dev_finish()
cpufreq_policy_put_kobj()
kobject_put()
cpufreq_cpu_get() gets the policy from per-cpu variable cpufreq_cpu_data
under cpufreq_driver_lock, and once it gets a valid policy it expects it
to not be freed until cpufreq_cpu_put() is called.
But the race happens when another thread puts the kobject first and updates
cpufreq_cpu_data before or later. And so the first thread gets a valid policy
structure and before it does kobject_get() on it, the second one has already
done kobject_put().
Fix this by setting cpufreq_cpu_data to NULL before putting the kobject and that
too under locks.
Reported-by: Ethan Zhao <ethan.zhao@oracle.com>
Reported-by: Santosh Shilimkar <santosh.shilimkar@oracle.com>
Signed-off-by: Viresh Kumar <viresh.kumar@linaro.org>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/cpufreq/cpufreq.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/cpufreq/cpufreq.c b/drivers/cpufreq/cpufreq.c
index 8daa0c95aa21..f1c5e49ece97 100644
--- a/drivers/cpufreq/cpufreq.c
+++ b/drivers/cpufreq/cpufreq.c
@@ -1417,9 +1417,10 @@ static int __cpufreq_remove_dev_finish(struct device *dev,
unsigned long flags;
struct cpufreq_policy *policy;
- read_lock_irqsave(&cpufreq_driver_lock, flags);
+ write_lock_irqsave(&cpufreq_driver_lock, flags);
policy = per_cpu(cpufreq_cpu_data, cpu);
- read_unlock_irqrestore(&cpufreq_driver_lock, flags);
+ per_cpu(cpufreq_cpu_data, cpu) = NULL;
+ write_unlock_irqrestore(&cpufreq_driver_lock, flags);
if (!policy) {
pr_debug("%s: No cpu_data found\n", __func__);
@@ -1474,7 +1475,6 @@ static int __cpufreq_remove_dev_finish(struct device *dev,
}
}
- per_cpu(cpufreq_cpu_data, cpu) = NULL;
return 0;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 074/183] Bluetooth: btusb: Add support for Lite-On (04ca) Broadcom based, BCM43142
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (72 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 073/183] cpufreq: Set cpufreq_cpu_data to NULL before putting kobject Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 075/183] nfs41: .init_read and .init_write can be called with valid pg_lseg Luis Henriques
` (108 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Matej Dubovy, Marcel Holtmann, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Matej Dubovy <matej.dubovy@gmail.com>
commit 8f0c304c693c5a9759ed6ae50d07d4590dad5ae7 upstream.
Please add support for sub BT chip on the combo card
Broadcom 43142A0 (in Lenovo E145), 04ca:2007
/sys/kernel/debug/usb/devices
T: Bus=05 Lev=01 Prnt=01 Port=01 Cnt=02 Dev#= 3 Spd=12 MxCh= 0
D: Ver= 2.00 Cls=ff(vend.) Sub=01 Prot=01 MxPS=64 #Cfgs= 1
P: Vendor=04ca ProdID=2007 Rev= 1.12
S: Manufacturer=Broadcom Corp
S: Product=BCM43142A0
S: SerialNumber=28E347EC73BD
C:* #Ifs= 4 Cfg#= 1 Atr=e0 MxPwr= 0mA
I:* If#= 0 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=01 Prot=01 Driver=(none)
E: Ad=81(I) Atr=03(Int.) MxPS= 16 Ivl=1ms
E: Ad=82(I) Atr=02(Bulk) MxPS= 64 Ivl=0ms
E: Ad=02(O) Atr=02(Bulk) MxPS= 64 Ivl=0ms
I:* If#= 1 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=(none)
E: Ad=83(I) Atr=01(Isoc) MxPS= 0 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 0 Ivl=1ms
I: If#= 1 Alt= 1 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=(none)
E: Ad=83(I) Atr=01(Isoc) MxPS= 9 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 9 Ivl=1ms
I: If#= 1 Alt= 2 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=(none)
E: Ad=83(I) Atr=01(Isoc) MxPS= 17 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 17 Ivl=1ms
I: If#= 1 Alt= 3 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=(none)
E: Ad=83(I) Atr=01(Isoc) MxPS= 25 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 25 Ivl=1ms
I: If#= 1 Alt= 4 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=(none)
E: Ad=83(I) Atr=01(Isoc) MxPS= 33 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 33 Ivl=1ms
I: If#= 1 Alt= 5 #EPs= 2 Cls=ff(vend.) Sub=01 Prot=01 Driver=(none)
E: Ad=83(I) Atr=01(Isoc) MxPS= 49 Ivl=1ms
E: Ad=03(O) Atr=01(Isoc) MxPS= 49 Ivl=1ms
I:* If#= 2 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=ff Driver=(none)
E: Ad=84(I) Atr=02(Bulk) MxPS= 32 Ivl=0ms
E: Ad=04(O) Atr=02(Bulk) MxPS= 32 Ivl=0ms
I:* If#= 3 Alt= 0 #EPs= 0 Cls=fe(app. ) Sub=01 Prot=01 Driver=(none)
Firmware for 04ca:2007 can be extracted from the latest Lenovo E145
Bluetooth driver for Windows (driver is however described as BCM20702
but contains also firwmare for BCM43142).
Search for BCM43142A0_001.001.011.0122.0153.hex within hex files, then
it must be converted using hex2hcd utility. Rename file to
BCM43142A0-04ca-2007.hcd, then move to /lib/firmware/brcm/.
Signed-off-by: Matej Dubovy <matej.dubovy@gmail.com>
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/bluetooth/btusb.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index 143c4b6622ca..35b8e75eb6fb 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -118,6 +118,10 @@ static const struct usb_device_id btusb_table[] = {
{ USB_VENDOR_AND_INTERFACE_INFO(0x0489, 0xff, 0x01, 0x01),
.driver_info = BTUSB_BCM_PATCHRAM },
+ /* Lite-On Technology - Broadcom based */
+ { USB_VENDOR_AND_INTERFACE_INFO(0x04ca, 0xff, 0x01, 0x01),
+ .driver_info = BTUSB_BCM_PATCHRAM },
+
/* Broadcom devices with vendor specific id */
{ USB_VENDOR_AND_INTERFACE_INFO(0x0a5c, 0xff, 0x01, 0x01),
.driver_info = BTUSB_BCM_PATCHRAM },
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 075/183] nfs41: .init_read and .init_write can be called with valid pg_lseg
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (73 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 074/183] Bluetooth: btusb: Add support for Lite-On (04ca) Broadcom based, BCM43142 Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 076/183] [media] lmedm04: Fix usb_submit_urb BOGUS urb xfer, pipe 1 != type 3 in interrupt urb Luis Henriques
` (107 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Peng Tao, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Peng Tao <tao.peng@primarydata.com>
commit cb5d04bc39e914124e811ea55f3034d2379a5f6c upstream.
With pgio refactoring in v3.15, .init_read and .init_write can be
called with valid pgio->pg_lseg. file layout was fixed at that time
by commit c6194271f (pnfs: filelayout: support non page aligned
layouts). But the generic helper still needs to be fixed.
Signed-off-by: Peng Tao <tao.peng@primarydata.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/nfs/pnfs.c | 41 ++++++++++++++++++++---------------------
1 file changed, 20 insertions(+), 21 deletions(-)
diff --git a/fs/nfs/pnfs.c b/fs/nfs/pnfs.c
index 5f3eb3df7c59..dea11c2c8c1e 100644
--- a/fs/nfs/pnfs.c
+++ b/fs/nfs/pnfs.c
@@ -1403,19 +1403,19 @@ pnfs_generic_pg_init_read(struct nfs_pageio_descriptor *pgio, struct nfs_page *r
{
u64 rd_size = req->wb_bytes;
- WARN_ON_ONCE(pgio->pg_lseg != NULL);
-
- if (pgio->pg_dreq == NULL)
- rd_size = i_size_read(pgio->pg_inode) - req_offset(req);
- else
- rd_size = nfs_dreq_bytes_left(pgio->pg_dreq);
-
- pgio->pg_lseg = pnfs_update_layout(pgio->pg_inode,
- req->wb_context,
- req_offset(req),
- rd_size,
- IOMODE_READ,
- GFP_KERNEL);
+ if (pgio->pg_lseg == NULL) {
+ if (pgio->pg_dreq == NULL)
+ rd_size = i_size_read(pgio->pg_inode) - req_offset(req);
+ else
+ rd_size = nfs_dreq_bytes_left(pgio->pg_dreq);
+
+ pgio->pg_lseg = pnfs_update_layout(pgio->pg_inode,
+ req->wb_context,
+ req_offset(req),
+ rd_size,
+ IOMODE_READ,
+ GFP_KERNEL);
+ }
/* If no lseg, fall back to read through mds */
if (pgio->pg_lseg == NULL)
nfs_pageio_reset_read_mds(pgio);
@@ -1427,14 +1427,13 @@ void
pnfs_generic_pg_init_write(struct nfs_pageio_descriptor *pgio,
struct nfs_page *req, u64 wb_size)
{
- WARN_ON_ONCE(pgio->pg_lseg != NULL);
-
- pgio->pg_lseg = pnfs_update_layout(pgio->pg_inode,
- req->wb_context,
- req_offset(req),
- wb_size,
- IOMODE_RW,
- GFP_NOFS);
+ if (pgio->pg_lseg == NULL)
+ pgio->pg_lseg = pnfs_update_layout(pgio->pg_inode,
+ req->wb_context,
+ req_offset(req),
+ wb_size,
+ IOMODE_RW,
+ GFP_NOFS);
/* If no lseg, fall back to write through mds */
if (pgio->pg_lseg == NULL)
nfs_pageio_reset_write_mds(pgio);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 076/183] [media] lmedm04: Fix usb_submit_urb BOGUS urb xfer, pipe 1 != type 3 in interrupt urb
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (74 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 075/183] nfs41: .init_read and .init_write can be called with valid pg_lseg Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 077/183] mei: mask interrupt set bit on clean reset bit Luis Henriques
` (106 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Malcolm Priestley, Mauro Carvalho Chehab, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Malcolm Priestley <tvboxspy@gmail.com>
commit 15e1ce33182d1d5dbd8efe8d382b9352dc857527 upstream.
A quirk of some older firmwares that report endpoint pipe type as PIPE_BULK
but the endpoint otheriwse functions as interrupt.
Check if usb_endpoint_type is USB_ENDPOINT_XFER_BULK and set as usb_rcvbulkpipe.
Signed-off-by: Malcolm Priestley <tvboxspy@gmail.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/media/usb/dvb-usb-v2/lmedm04.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/media/usb/dvb-usb-v2/lmedm04.c b/drivers/media/usb/dvb-usb-v2/lmedm04.c
index f674dc024d06..d2a4e6d40bf0 100644
--- a/drivers/media/usb/dvb-usb-v2/lmedm04.c
+++ b/drivers/media/usb/dvb-usb-v2/lmedm04.c
@@ -350,6 +350,7 @@ static int lme2510_int_read(struct dvb_usb_adapter *adap)
{
struct dvb_usb_device *d = adap_to_d(adap);
struct lme2510_state *lme_int = adap_to_priv(adap);
+ struct usb_host_endpoint *ep;
lme_int->lme_urb = usb_alloc_urb(0, GFP_ATOMIC);
@@ -371,6 +372,12 @@ static int lme2510_int_read(struct dvb_usb_adapter *adap)
adap,
8);
+ /* Quirk of pipe reporting PIPE_BULK but behaves as interrupt */
+ ep = usb_pipe_endpoint(d->udev, lme_int->lme_urb->pipe);
+
+ if (usb_endpoint_type(&ep->desc) == USB_ENDPOINT_XFER_BULK)
+ lme_int->lme_urb->pipe = usb_rcvbulkpipe(d->udev, 0xa),
+
lme_int->lme_urb->transfer_flags |= URB_NO_TRANSFER_DMA_MAP;
usb_submit_urb(lme_int->lme_urb, GFP_ATOMIC);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 077/183] mei: mask interrupt set bit on clean reset bit
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (75 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 076/183] [media] lmedm04: Fix usb_submit_urb BOGUS urb xfer, pipe 1 != type 3 in interrupt urb Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 078/183] mei: me: release hw from reset only during the reset flow Luis Henriques
` (105 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Alexander Usyskin, Tomas Winkler, Greg Kroah-Hartman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Usyskin <alexander.usyskin@intel.com>
commit 1ab1e79b9fd4b01331490bbe2e630a0fc0b25449 upstream.
We should mask interrupt set bit when writing back
hcsr value in reset bit clean-up.
This is refinement for
mei: clean reset bit before reset
commit b13a65ef190e488e2761d65bdd2e1fe8a3a125f5
Signed-off-by: Alexander Usyskin <alexander.usyskin@intel.com>
Signed-off-by: Tomas Winkler <tomas.winkler@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/misc/mei/hw-me.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/misc/mei/hw-me.c b/drivers/misc/mei/hw-me.c
index 9d0cd32d885a..98bc7e05b97b 100644
--- a/drivers/misc/mei/hw-me.c
+++ b/drivers/misc/mei/hw-me.c
@@ -204,7 +204,7 @@ static int mei_me_hw_reset(struct mei_device *dev, bool intr_enable)
if ((hcsr & H_RST) == H_RST) {
dev_warn(&dev->pdev->dev, "H_RST is set = 0x%08X", hcsr);
hcsr &= ~H_RST;
- mei_me_reg_write(hw, H_CSR, hcsr);
+ mei_hcsr_set(hw, hcsr);
hcsr = mei_hcsr_read(hw);
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 078/183] mei: me: release hw from reset only during the reset flow
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (76 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 077/183] mei: mask interrupt set bit on clean reset bit Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 079/183] KVM: MIPS: Don't leak FPU/DSP to guest Luis Henriques
` (104 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Alexander Usyskin, Tomas Winkler, Greg Kroah-Hartman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Usyskin <alexander.usyskin@intel.com>
commit 663b7ee9517eec6deea9a48c7a1392a9a34f7809 upstream.
We might enter the interrupt handler with hw_ready already set,
but prior we actually started the reset flow.
To soleve this we move the reset release from the interrupt handler
to the HW start wait function which is part of the reset sequence.
Signed-off-by: Alexander Usyskin <alexander.usyskin@intel.com>
Signed-off-by: Tomas Winkler <tomas.winkler@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/misc/mei/hw-me.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/misc/mei/hw-me.c b/drivers/misc/mei/hw-me.c
index 98bc7e05b97b..5fcd1d69debc 100644
--- a/drivers/misc/mei/hw-me.c
+++ b/drivers/misc/mei/hw-me.c
@@ -293,6 +293,7 @@ static int mei_me_hw_ready_wait(struct mei_device *dev)
return err;
}
+ mei_me_hw_reset_release(dev);
dev->recvd_hw_ready = false;
return 0;
}
@@ -672,7 +673,6 @@ irqreturn_t mei_me_irq_thread_handler(int irq, void *dev_id)
/* check if we need to start the dev */
if (!mei_host_is_ready(dev)) {
if (mei_hw_is_ready(dev)) {
- mei_me_hw_reset_release(dev);
dev_dbg(&dev->pdev->dev, "we need to start the dev.\n");
dev->recvd_hw_ready = true;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 079/183] KVM: MIPS: Don't leak FPU/DSP to guest
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (77 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 078/183] mei: me: release hw from reset only during the reset flow Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 080/183] ALSA: hda - Add the pin fixup for HP Envy TS bass speaker Luis Henriques
` (103 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: James Hogan, Paolo Bonzini, Ralf Baechle, Sanjay Lal,
Gleb Natapov, kvm, linux-mips, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: James Hogan <james.hogan@imgtec.com>
commit f798217dfd038af981a18bbe4bc57027a08bb182 upstream.
The FPU and DSP are enabled via the CP0 Status CU1 and MX bits by
kvm_mips_set_c0_status() on a guest exit, presumably in case there is
active state that needs saving if pre-emption occurs. However neither of
these bits are cleared again when returning to the guest.
This effectively gives the guest access to the FPU/DSP hardware after
the first guest exit even though it is not aware of its presence,
allowing FP instructions in guest user code to intermittently actually
execute instead of trapping into the guest OS for emulation. It will
then read & manipulate the hardware FP registers which technically
belong to the user process (e.g. QEMU), or are stale from another user
process. It can also crash the guest OS by causing an FP exception, for
which a guest exception handler won't have been registered.
First lets save and disable the FPU (and MSA) state with lose_fpu(1)
before entering the guest. This simplifies the problem, especially for
when guest FPU/MSA support is added in the future, and prevents FR=1 FPU
state being live when the FR bit gets cleared for the guest, which
according to the architecture causes the contents of the FPU and vector
registers to become UNPREDICTABLE.
We can then safely remove the enabling of the FPU in
kvm_mips_set_c0_status(), since there should never be any active FPU or
MSA state to save at pre-emption, which should plug the FPU leak.
DSP state is always live rather than being lazily restored, so for that
it is simpler to just clear the MX bit again when re-entering the guest.
Signed-off-by: James Hogan <james.hogan@imgtec.com>
Cc: Paolo Bonzini <pbonzini@redhat.com>
Cc: Ralf Baechle <ralf@linux-mips.org>
Cc: Sanjay Lal <sanjayl@kymasys.com>
Cc: Gleb Natapov <gleb@kernel.org>
Cc: kvm@vger.kernel.org
Cc: linux-mips@linux-mips.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
[ luis: backported to 3.16: files rename:
- locore.S -> kvm_locore.S
- mips.c -> kvm_mips.c ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/mips/kvm/kvm_locore.S | 2 +-
arch/mips/kvm/kvm_mips.c | 6 +++---
2 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/mips/kvm/kvm_locore.S b/arch/mips/kvm/kvm_locore.S
index 033ac343e72c..17376cd838e6 100644
--- a/arch/mips/kvm/kvm_locore.S
+++ b/arch/mips/kvm/kvm_locore.S
@@ -428,7 +428,7 @@ __kvm_mips_return_to_guest:
/* Setup status register for running guest in UM */
.set at
or v1, v1, (ST0_EXL | KSU_USER | ST0_IE)
- and v1, v1, ~ST0_CU0
+ and v1, v1, ~(ST0_CU0 | ST0_MX)
.set noat
mtc0 v1, CP0_STATUS
ehb
diff --git a/arch/mips/kvm/kvm_mips.c b/arch/mips/kvm/kvm_mips.c
index f3c56a182fd8..d84f96e51349 100644
--- a/arch/mips/kvm/kvm_mips.c
+++ b/arch/mips/kvm/kvm_mips.c
@@ -15,6 +15,7 @@
#include <linux/vmalloc.h>
#include <linux/fs.h>
#include <linux/bootmem.h>
+#include <asm/fpu.h>
#include <asm/page.h>
#include <asm/cacheflush.h>
#include <asm/mmu_context.h>
@@ -413,6 +414,8 @@ int kvm_arch_vcpu_ioctl_run(struct kvm_vcpu *vcpu, struct kvm_run *run)
vcpu->mmio_needed = 0;
}
+ lose_fpu(1);
+
local_irq_disable();
/* Check if we have any exceptions/interrupts pending */
kvm_mips_deliver_interrupts(vcpu,
@@ -1028,9 +1031,6 @@ void kvm_mips_set_c0_status(void)
{
uint32_t status = read_c0_status();
- if (cpu_has_fpu)
- status |= (ST0_CU1);
-
if (cpu_has_dsp)
status |= (ST0_MX);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 080/183] ALSA: hda - Add the pin fixup for HP Envy TS bass speaker
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (78 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 079/183] KVM: MIPS: Don't leak FPU/DSP to guest Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 081/183] ALSA: hda - Set up GPIO for Toshiba Satellite S50D Luis Henriques
` (102 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Takashi Iwai, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit 8695a003a5f4f5bc88b915e1c4a56d954f810f6e upstream.
NID 0x10 seems corresponding to the bass speaker.
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
sound/pci/hda/patch_sigmatel.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/sound/pci/hda/patch_sigmatel.c b/sound/pci/hda/patch_sigmatel.c
index 3075c765d19c..1824bd51d9a4 100644
--- a/sound/pci/hda/patch_sigmatel.c
+++ b/sound/pci/hda/patch_sigmatel.c
@@ -104,6 +104,7 @@ enum {
STAC_92HD83XXX_HP,
STAC_HP_ENVY_BASS,
STAC_HP_BNB13_EQ,
+ STAC_HP_ENVY_TS_BASS,
STAC_92HD83XXX_MODELS
};
@@ -2680,6 +2681,13 @@ static const struct hda_fixup stac92hd83xxx_fixups[] = {
.chained = true,
.chain_id = STAC_92HD83XXX_HP_MIC_LED,
},
+ [STAC_HP_ENVY_TS_BASS] = {
+ .type = HDA_FIXUP_PINS,
+ .v.pins = (const struct hda_pintbl[]) {
+ { 0x10, 0x92170111 },
+ {}
+ },
+ },
};
static const struct hda_model_fixup stac92hd83xxx_models[] = {
@@ -2696,6 +2704,7 @@ static const struct hda_model_fixup stac92hd83xxx_models[] = {
{ .id = STAC_92HD83XXX_HEADSET_JACK, .name = "headset-jack" },
{ .id = STAC_HP_ENVY_BASS, .name = "hp-envy-bass" },
{ .id = STAC_HP_BNB13_EQ, .name = "hp-bnb13-eq" },
+ { .id = STAC_HP_ENVY_TS_BASS, .name = "hp-envy-ts-bass" },
{}
};
@@ -2751,6 +2760,8 @@ static const struct snd_pci_quirk stac92hd83xxx_fixup_tbl[] = {
"HP bNB13", STAC_HP_BNB13_EQ),
SND_PCI_QUIRK(PCI_VENDOR_ID_HP, 0x190A,
"HP bNB13", STAC_HP_BNB13_EQ),
+ SND_PCI_QUIRK(PCI_VENDOR_ID_HP, 0x190e,
+ "HP ENVY TS", STAC_HP_ENVY_TS_BASS),
SND_PCI_QUIRK(PCI_VENDOR_ID_HP, 0x1940,
"HP bNB13", STAC_HP_BNB13_EQ),
SND_PCI_QUIRK(PCI_VENDOR_ID_HP, 0x1941,
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 081/183] ALSA: hda - Set up GPIO for Toshiba Satellite S50D
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (79 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 080/183] ALSA: hda - Add the pin fixup for HP Envy TS bass speaker Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 082/183] xen/manage: Fix USB interaction issues when resuming Luis Henriques
` (101 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Takashi Iwai, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit 4227de2a7e5f0ff6a58e919a9c4f2bb06e882f48 upstream.
Toshiba Satellite S50D laptop with an IDT codec uses the GPIO4 (0x10)
as the master EAPD.
Bugzilla: https://bugzilla.novell.com/show_bug.cgi?id=915858
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
sound/pci/hda/patch_sigmatel.c | 20 ++++++++++++++++++++
1 file changed, 20 insertions(+)
diff --git a/sound/pci/hda/patch_sigmatel.c b/sound/pci/hda/patch_sigmatel.c
index 1824bd51d9a4..fbb51d9331b0 100644
--- a/sound/pci/hda/patch_sigmatel.c
+++ b/sound/pci/hda/patch_sigmatel.c
@@ -105,6 +105,7 @@ enum {
STAC_HP_ENVY_BASS,
STAC_HP_BNB13_EQ,
STAC_HP_ENVY_TS_BASS,
+ STAC_92HD83XXX_GPIO10_EAPD,
STAC_92HD83XXX_MODELS
};
@@ -2173,6 +2174,19 @@ static void stac92hd83xxx_fixup_headset_jack(struct hda_codec *codec,
spec->headset_jack = 1;
}
+static void stac92hd83xxx_fixup_gpio10_eapd(struct hda_codec *codec,
+ const struct hda_fixup *fix,
+ int action)
+{
+ struct sigmatel_spec *spec = codec->spec;
+
+ if (action != HDA_FIXUP_ACT_PRE_PROBE)
+ return;
+ spec->eapd_mask = spec->gpio_mask = spec->gpio_dir =
+ spec->gpio_data = 0x10;
+ spec->eapd_switch = 0;
+}
+
static const struct hda_verb hp_bnb13_eq_verbs[] = {
/* 44.1KHz base */
{ 0x22, 0x7A6, 0x3E },
@@ -2688,6 +2702,10 @@ static const struct hda_fixup stac92hd83xxx_fixups[] = {
{}
},
},
+ [STAC_92HD83XXX_GPIO10_EAPD] = {
+ .type = HDA_FIXUP_FUNC,
+ .v.func = stac92hd83xxx_fixup_gpio10_eapd,
+ },
};
static const struct hda_model_fixup stac92hd83xxx_models[] = {
@@ -2893,6 +2911,8 @@ static const struct snd_pci_quirk stac92hd83xxx_fixup_tbl[] = {
SND_PCI_QUIRK(PCI_VENDOR_ID_HP, 0x148a,
"HP Mini", STAC_92HD83XXX_HP_LED),
SND_PCI_QUIRK_VENDOR(PCI_VENDOR_ID_HP, "HP", STAC_92HD83XXX_HP),
+ SND_PCI_QUIRK(PCI_VENDOR_ID_TOSHIBA, 0xfa91,
+ "Toshiba Satellite S50D", STAC_92HD83XXX_GPIO10_EAPD),
{} /* terminator */
};
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 082/183] xen/manage: Fix USB interaction issues when resuming
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (80 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 081/183] ALSA: hda - Set up GPIO for Toshiba Satellite S50D Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 083/183] ACPI / video: Add some Samsung models to disable_native_backlight list Luis Henriques
` (100 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Ross Lagerwall, David Vrabel, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ross Lagerwall <ross.lagerwall@citrix.com>
commit 72978b2fe2f2cdf9f319c6c6dcdbe92b38de2be2 upstream.
Commit 61a734d305e1 ("xen/manage: Always freeze/thaw processes when
suspend/resuming") ensured that userspace processes were always frozen
before suspending to reduce interaction issues when resuming devices.
However, freeze_processes() does not freeze kernel threads. Freeze
kernel threads as well to prevent deadlocks with the khubd thread when
resuming devices.
This is what native suspend and resume does.
Example deadlock:
[ 7279.648010] [<ffffffff81446bde>] ? xen_poll_irq_timeout+0x3e/0x50
[ 7279.648010] [<ffffffff81448d60>] xen_poll_irq+0x10/0x20
[ 7279.648010] [<ffffffff81011723>] xen_lock_spinning+0xb3/0x120
[ 7279.648010] [<ffffffff810115d1>] __raw_callee_save_xen_lock_spinning+0x11/0x20
[ 7279.648010] [<ffffffff815620b6>] ? usb_control_msg+0xe6/0x120
[ 7279.648010] [<ffffffff81747e50>] ? _raw_spin_lock_irq+0x50/0x60
[ 7279.648010] [<ffffffff8174522c>] wait_for_completion+0xac/0x160
[ 7279.648010] [<ffffffff8109c520>] ? try_to_wake_up+0x2c0/0x2c0
[ 7279.648010] [<ffffffff814b60f2>] dpm_wait+0x32/0x40
[ 7279.648010] [<ffffffff814b6eb0>] device_resume+0x90/0x210
[ 7279.648010] [<ffffffff814b7d71>] dpm_resume+0x121/0x250
[ 7279.648010] [<ffffffff8144c570>] ? xenbus_dev_request_and_reply+0xc0/0xc0
[ 7279.648010] [<ffffffff814b80d5>] dpm_resume_end+0x15/0x30
[ 7279.648010] [<ffffffff81449fba>] do_suspend+0x10a/0x200
[ 7279.648010] [<ffffffff8144a2f0>] ? xen_pre_suspend+0x20/0x20
[ 7279.648010] [<ffffffff8144a1d0>] shutdown_handler+0x120/0x150
[ 7279.648010] [<ffffffff8144c60f>] xenwatch_thread+0x9f/0x160
[ 7279.648010] [<ffffffff810ac510>] ? finish_wait+0x80/0x80
[ 7279.648010] [<ffffffff8108d189>] kthread+0xc9/0xe0
[ 7279.648010] [<ffffffff8108d0c0>] ? flush_kthread_worker+0x80/0x80
[ 7279.648010] [<ffffffff8175087c>] ret_from_fork+0x7c/0xb0
[ 7279.648010] [<ffffffff8108d0c0>] ? flush_kthread_worker+0x80/0x80
[ 7441.216287] INFO: task khubd:89 blocked for more than 120 seconds.
[ 7441.219457] Tainted: G X 3.13.11-ckt12.kz #1
[ 7441.222176] "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
[ 7441.225827] khubd D ffff88003f433440 0 89 2 0x00000000
[ 7441.229258] ffff88003ceb9b98 0000000000000046 ffff88003ce83000 0000000000013440
[ 7441.232959] ffff88003ceb9fd8 0000000000013440 ffff88003cd13000 ffff88003ce83000
[ 7441.236658] 0000000000000286 ffff88003d3e0000 ffff88003ceb9bd0 00000001001aa01e
[ 7441.240415] Call Trace:
[ 7441.241614] [<ffffffff817442f9>] schedule+0x29/0x70
[ 7441.243930] [<ffffffff81743406>] schedule_timeout+0x166/0x2c0
[ 7441.246681] [<ffffffff81075b80>] ? call_timer_fn+0x110/0x110
[ 7441.249339] [<ffffffff8174357e>] schedule_timeout_uninterruptible+0x1e/0x20
[ 7441.252644] [<ffffffff81077710>] msleep+0x20/0x30
[ 7441.254812] [<ffffffff81555f00>] hub_port_reset+0xf0/0x580
[ 7441.257400] [<ffffffff81558465>] hub_port_init+0x75/0xb40
[ 7441.259981] [<ffffffff814bb3c9>] ? update_autosuspend+0x39/0x60
[ 7441.262817] [<ffffffff814bb4f0>] ? pm_runtime_set_autosuspend_delay+0x50/0xa0
[ 7441.266212] [<ffffffff8155a64a>] hub_thread+0x71a/0x1750
[ 7441.268728] [<ffffffff810ac510>] ? finish_wait+0x80/0x80
[ 7441.271272] [<ffffffff81559f30>] ? usb_port_resume+0x670/0x670
[ 7441.274067] [<ffffffff8108d189>] kthread+0xc9/0xe0
[ 7441.276305] [<ffffffff8108d0c0>] ? flush_kthread_worker+0x80/0x80
[ 7441.279131] [<ffffffff8175087c>] ret_from_fork+0x7c/0xb0
[ 7441.281659] [<ffffffff8108d0c0>] ? flush_kthread_worker+0x80/0x80
Signed-off-by: Ross Lagerwall <ross.lagerwall@citrix.com>
Signed-off-by: David Vrabel <david.vrabel@citrix.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/xen/manage.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/xen/manage.c b/drivers/xen/manage.c
index f8bb36f9d9ce..bf1940706422 100644
--- a/drivers/xen/manage.c
+++ b/drivers/xen/manage.c
@@ -105,10 +105,16 @@ static void do_suspend(void)
err = freeze_processes();
if (err) {
- pr_err("%s: freeze failed %d\n", __func__, err);
+ pr_err("%s: freeze processes failed %d\n", __func__, err);
goto out;
}
+ err = freeze_kernel_threads();
+ if (err) {
+ pr_err("%s: freeze kernel threads failed %d\n", __func__, err);
+ goto out_thaw;
+ }
+
err = dpm_suspend_start(PMSG_FREEZE);
if (err) {
pr_err("%s: dpm_suspend_start %d\n", __func__, err);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 083/183] ACPI / video: Add some Samsung models to disable_native_backlight list
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (81 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 082/183] xen/manage: Fix USB interaction issues when resuming Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 084/183] ACPI / video: Add disable_native_backlight quirk for Dell XPS15 L521X Luis Henriques
` (99 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Aaron Lu, Rafael J. Wysocki, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Aaron Lu <aaron.lu@intel.com>
commit 7d0b93499f4879ddbc75d594f4ea216ba964f78e upstream.
Several Samsung laptop models (SAMSUNG 870Z5E/880Z5E/680Z5E and
SAMSUNG 370R4E/370R4V/370R5E/3570RE/370R5V) do not have a working
native backlight control interface so restore their acpi_videoX
interface.
Link: https://bugzilla.kernel.org/show_bug.cgi?id=84221
Link: https://bugzilla.kernel.org/show_bug.cgi?id=84651
For SAMSUNG 870Z5E/880Z5E/680Z5E:
Reported-and-tested-by: Brent Saner <brent.saner@gmail.com>
Reported-by: Vitaliy Filippov <vitalif@yourcmc.ru>
Reported-by: Laszlo KREKACS <laszlo.krekacs.list@gmail.com>
For SAMSUNG 370R4E/370R4V/370R5E/3570RE/370R5V:
Reported-by: Vladimir Perepechin <vovochka13@gmail.com>
Signed-off-by: Aaron Lu <aaron.lu@intel.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/acpi/video.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/drivers/acpi/video.c b/drivers/acpi/video.c
index f1e3496c00c7..28fa58c11e56 100644
--- a/drivers/acpi/video.c
+++ b/drivers/acpi/video.c
@@ -694,6 +694,23 @@ static struct dmi_system_id video_dmi_table[] __initdata = {
DMI_MATCH(DMI_PRODUCT_NAME, "HP ENVY 15 Notebook PC"),
},
},
+
+ {
+ .callback = video_disable_native_backlight,
+ .ident = "SAMSUNG 870Z5E/880Z5E/680Z5E",
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "SAMSUNG ELECTRONICS CO., LTD."),
+ DMI_MATCH(DMI_PRODUCT_NAME, "870Z5E/880Z5E/680Z5E"),
+ },
+ },
+ {
+ .callback = video_disable_native_backlight,
+ .ident = "SAMSUNG 370R4E/370R4V/370R5E/3570RE/370R5V",
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "SAMSUNG ELECTRONICS CO., LTD."),
+ DMI_MATCH(DMI_PRODUCT_NAME, "370R4E/370R4V/370R5E/3570RE/370R5V"),
+ },
+ },
{}
};
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 084/183] ACPI / video: Add disable_native_backlight quirk for Dell XPS15 L521X
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (82 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 083/183] ACPI / video: Add some Samsung models to disable_native_backlight list Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 085/183] ACPI / video: Add disable_native_backlight quirk for Samsung 730U3E/740U3E Luis Henriques
` (98 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Hans de Goede, Rafael J. Wysocki, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <hdegoede@redhat.com>
commit 6a3ef10bacb08860805e9053f919786dc34760ba upstream.
The L521X variant of the Dell XPS15 has integrated nvidia graphics, and
backlight control does not work properly when using the native interfaces.
Link: https://bugzilla.redhat.com/show_bug.cgi?id=1163574
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/acpi/video.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/drivers/acpi/video.c b/drivers/acpi/video.c
index 28fa58c11e56..b7bed5fdc433 100644
--- a/drivers/acpi/video.c
+++ b/drivers/acpi/video.c
@@ -711,6 +711,16 @@ static struct dmi_system_id video_dmi_table[] __initdata = {
DMI_MATCH(DMI_PRODUCT_NAME, "370R4E/370R4V/370R5E/3570RE/370R5V"),
},
},
+
+ {
+ /* https://bugzilla.redhat.com/show_bug.cgi?id=1163574 */
+ .callback = video_disable_native_backlight,
+ .ident = "Dell XPS15 L521X",
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "Dell Inc."),
+ DMI_MATCH(DMI_PRODUCT_NAME, "XPS L521X"),
+ },
+ },
{}
};
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 085/183] ACPI / video: Add disable_native_backlight quirk for Samsung 730U3E/740U3E
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (83 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 084/183] ACPI / video: Add disable_native_backlight quirk for Dell XPS15 L521X Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 086/183] ACPI / video: Add disable_native_backlight quirk for Samsung 510R Luis Henriques
` (97 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Hans de Goede, Rafael J. Wysocki, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <hdegoede@redhat.com>
commit 3295d73002f4be341069a000aec4b8d7e5ea8d2c upstream.
The Samsung 730U3E/740U3E has integrated ATI Radeon graphics, and backlight
control does not work properly when using the native interfaces.
Link: https://bugzilla.redhat.com/show_bug.cgi?id=1094948
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/acpi/video.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/drivers/acpi/video.c b/drivers/acpi/video.c
index b7bed5fdc433..d4b6a214892b 100644
--- a/drivers/acpi/video.c
+++ b/drivers/acpi/video.c
@@ -711,6 +711,15 @@ static struct dmi_system_id video_dmi_table[] __initdata = {
DMI_MATCH(DMI_PRODUCT_NAME, "370R4E/370R4V/370R5E/3570RE/370R5V"),
},
},
+ {
+ /* https://bugzilla.redhat.com/show_bug.cgi?id=1094948 */
+ .callback = video_disable_native_backlight,
+ .ident = "SAMSUNG 730U3E/740U3E",
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "SAMSUNG ELECTRONICS CO., LTD."),
+ DMI_MATCH(DMI_PRODUCT_NAME, "730U3E/740U3E"),
+ },
+ },
{
/* https://bugzilla.redhat.com/show_bug.cgi?id=1163574 */
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 086/183] ACPI / video: Add disable_native_backlight quirk for Samsung 510R
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (84 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 085/183] ACPI / video: Add disable_native_backlight quirk for Samsung 730U3E/740U3E Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 087/183] KVM: s390: floating irqs: fix user triggerable endless loop Luis Henriques
` (96 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Hans de Goede, Rafael J. Wysocki, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <hdegoede@redhat.com>
commit e77a16355a29230b99bafe55834a8252e55308ec upstream.
Backlight control through the native intel interface does not work properly
on the Samsung 510R, where as using the acpi_video interface does work, add
a quirk for this.
Link: https://bugzilla.redhat.com/show_bug.cgi?id=1186097
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/acpi/video.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/drivers/acpi/video.c b/drivers/acpi/video.c
index d4b6a214892b..0f9bf52792b5 100644
--- a/drivers/acpi/video.c
+++ b/drivers/acpi/video.c
@@ -712,6 +712,15 @@ static struct dmi_system_id video_dmi_table[] __initdata = {
},
},
{
+ /* https://bugzilla.redhat.com/show_bug.cgi?id=1186097 */
+ .callback = video_disable_native_backlight,
+ .ident = "SAMSUNG 3570R/370R/470R/450R/510R/4450RV",
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "SAMSUNG ELECTRONICS CO., LTD."),
+ DMI_MATCH(DMI_PRODUCT_NAME, "3570R/370R/470R/450R/510R/4450RV"),
+ },
+ },
+ {
/* https://bugzilla.redhat.com/show_bug.cgi?id=1094948 */
.callback = video_disable_native_backlight,
.ident = "SAMSUNG 730U3E/740U3E",
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 087/183] KVM: s390: floating irqs: fix user triggerable endless loop
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (85 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 086/183] ACPI / video: Add disable_native_backlight quirk for Samsung 510R Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 088/183] drm/i915: Correct the IOSF Dev_FN field for IOSF transfers Luis Henriques
` (95 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: David Hildenbrand, Christian Borntraeger, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: David Hildenbrand <dahi@linux.vnet.ibm.com>
commit 8e2207cdd087ebb031e9118d1fd0902c6533a5e5 upstream.
If a vm with no VCPUs is created, the injection of a floating irq
leads to an endless loop in the kernel.
Let's skip the search for a destination VCPU for a floating irq if no
VCPUs were created.
Reviewed-by: Dominik Dingel <dingel@linux.vnet.ibm.com>
Reviewed-by: Cornelia Huck <cornelia.huck@de.ibm.com>
Signed-off-by: David Hildenbrand <dahi@linux.vnet.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@de.ibm.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/s390/kvm/interrupt.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/s390/kvm/interrupt.c b/arch/s390/kvm/interrupt.c
index e2354f97264e..f19702fc89ec 100644
--- a/arch/s390/kvm/interrupt.c
+++ b/arch/s390/kvm/interrupt.c
@@ -925,6 +925,8 @@ static int __inject_vm(struct kvm *kvm, struct kvm_s390_interrupt_info *inti)
list_add_tail(&inti->list, &iter->list);
}
atomic_set(&fi->active, 1);
+ if (atomic_read(&kvm->online_vcpus) == 0)
+ goto unlock_fi;
sigcpu = find_first_bit(fi->idle_mask, KVM_MAX_VCPUS);
if (sigcpu == KVM_MAX_VCPUS) {
do {
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 088/183] drm/i915: Correct the IOSF Dev_FN field for IOSF transfers
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (86 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 087/183] KVM: s390: floating irqs: fix user triggerable endless loop Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 089/183] cfq-iosched: handle failure of cfq group allocation Luis Henriques
` (94 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Shobhit Kumar, Jani Nikula, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Shobhit Kumar <shobhit.kumar@intel.com>
commit d180d2bbb66579e3bf449642b8ec2a76f4014fcd upstream.
As per the specififcation, the SB_DevFn is the PCI_DEVFN of the target
device and not the source. So PCI_DEVFN(2,0) is not correct. Further the
port ID should be enough to identify devices unless they are MFD. The
SB_DevFn was intended to remove ambiguity in case of these MFD devices.
For non MFD devices the recommendation for the target device IP was to
ignore these fields, but not all of them followed the recommendation.
Some like CCK ignore these fields and hence PCI_DEVFN(2, 0) works and so
does PCI_DEVFN(0, 0) as it works for DPIO. The issue came to light because
of GPIONC which was not getting programmed correctly with PCI_DEVFN(2, 0).
It turned out that this did not follow the recommendation and expected 0
in this field.
In general the recommendation is to use SB_DevFn as PCI_DEVFN(0, 0) for
all devices except target PCI devices.
Signed-off-by: Shobhit Kumar <shobhit.kumar@intel.com>
Reviewed-by: Ville Syrjälä <ville.syrjala@linux.intel.com>
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/gpu/drm/i915/intel_sideband.c | 26 +++++++++++++-------------
1 file changed, 13 insertions(+), 13 deletions(-)
diff --git a/drivers/gpu/drm/i915/intel_sideband.c b/drivers/gpu/drm/i915/intel_sideband.c
index 01d841ea3140..731b10a09aa0 100644
--- a/drivers/gpu/drm/i915/intel_sideband.c
+++ b/drivers/gpu/drm/i915/intel_sideband.c
@@ -82,7 +82,7 @@ u32 vlv_punit_read(struct drm_i915_private *dev_priv, u8 addr)
WARN_ON(!mutex_is_locked(&dev_priv->rps.hw_lock));
mutex_lock(&dev_priv->dpio_lock);
- vlv_sideband_rw(dev_priv, PCI_DEVFN(2, 0), IOSF_PORT_PUNIT,
+ vlv_sideband_rw(dev_priv, PCI_DEVFN(0, 0), IOSF_PORT_PUNIT,
SB_CRRDDA_NP, addr, &val);
mutex_unlock(&dev_priv->dpio_lock);
@@ -94,7 +94,7 @@ void vlv_punit_write(struct drm_i915_private *dev_priv, u8 addr, u32 val)
WARN_ON(!mutex_is_locked(&dev_priv->rps.hw_lock));
mutex_lock(&dev_priv->dpio_lock);
- vlv_sideband_rw(dev_priv, PCI_DEVFN(2, 0), IOSF_PORT_PUNIT,
+ vlv_sideband_rw(dev_priv, PCI_DEVFN(0, 0), IOSF_PORT_PUNIT,
SB_CRWRDA_NP, addr, &val);
mutex_unlock(&dev_priv->dpio_lock);
}
@@ -103,7 +103,7 @@ u32 vlv_bunit_read(struct drm_i915_private *dev_priv, u32 reg)
{
u32 val = 0;
- vlv_sideband_rw(dev_priv, PCI_DEVFN(2, 0), IOSF_PORT_BUNIT,
+ vlv_sideband_rw(dev_priv, PCI_DEVFN(0, 0), IOSF_PORT_BUNIT,
SB_CRRDDA_NP, reg, &val);
return val;
@@ -111,7 +111,7 @@ u32 vlv_bunit_read(struct drm_i915_private *dev_priv, u32 reg)
void vlv_bunit_write(struct drm_i915_private *dev_priv, u32 reg, u32 val)
{
- vlv_sideband_rw(dev_priv, PCI_DEVFN(2, 0), IOSF_PORT_BUNIT,
+ vlv_sideband_rw(dev_priv, PCI_DEVFN(0, 0), IOSF_PORT_BUNIT,
SB_CRWRDA_NP, reg, &val);
}
@@ -122,7 +122,7 @@ u32 vlv_nc_read(struct drm_i915_private *dev_priv, u8 addr)
WARN_ON(!mutex_is_locked(&dev_priv->rps.hw_lock));
mutex_lock(&dev_priv->dpio_lock);
- vlv_sideband_rw(dev_priv, PCI_DEVFN(2, 0), IOSF_PORT_NC,
+ vlv_sideband_rw(dev_priv, PCI_DEVFN(0, 0), IOSF_PORT_NC,
SB_CRRDDA_NP, addr, &val);
mutex_unlock(&dev_priv->dpio_lock);
@@ -132,56 +132,56 @@ u32 vlv_nc_read(struct drm_i915_private *dev_priv, u8 addr)
u32 vlv_gpio_nc_read(struct drm_i915_private *dev_priv, u32 reg)
{
u32 val = 0;
- vlv_sideband_rw(dev_priv, PCI_DEVFN(2, 0), IOSF_PORT_GPIO_NC,
+ vlv_sideband_rw(dev_priv, PCI_DEVFN(0, 0), IOSF_PORT_GPIO_NC,
SB_CRRDDA_NP, reg, &val);
return val;
}
void vlv_gpio_nc_write(struct drm_i915_private *dev_priv, u32 reg, u32 val)
{
- vlv_sideband_rw(dev_priv, PCI_DEVFN(2, 0), IOSF_PORT_GPIO_NC,
+ vlv_sideband_rw(dev_priv, PCI_DEVFN(0, 0), IOSF_PORT_GPIO_NC,
SB_CRWRDA_NP, reg, &val);
}
u32 vlv_cck_read(struct drm_i915_private *dev_priv, u32 reg)
{
u32 val = 0;
- vlv_sideband_rw(dev_priv, PCI_DEVFN(2, 0), IOSF_PORT_CCK,
+ vlv_sideband_rw(dev_priv, PCI_DEVFN(0, 0), IOSF_PORT_CCK,
SB_CRRDDA_NP, reg, &val);
return val;
}
void vlv_cck_write(struct drm_i915_private *dev_priv, u32 reg, u32 val)
{
- vlv_sideband_rw(dev_priv, PCI_DEVFN(2, 0), IOSF_PORT_CCK,
+ vlv_sideband_rw(dev_priv, PCI_DEVFN(0, 0), IOSF_PORT_CCK,
SB_CRWRDA_NP, reg, &val);
}
u32 vlv_ccu_read(struct drm_i915_private *dev_priv, u32 reg)
{
u32 val = 0;
- vlv_sideband_rw(dev_priv, PCI_DEVFN(2, 0), IOSF_PORT_CCU,
+ vlv_sideband_rw(dev_priv, PCI_DEVFN(0, 0), IOSF_PORT_CCU,
SB_CRRDDA_NP, reg, &val);
return val;
}
void vlv_ccu_write(struct drm_i915_private *dev_priv, u32 reg, u32 val)
{
- vlv_sideband_rw(dev_priv, PCI_DEVFN(2, 0), IOSF_PORT_CCU,
+ vlv_sideband_rw(dev_priv, PCI_DEVFN(0, 0), IOSF_PORT_CCU,
SB_CRWRDA_NP, reg, &val);
}
u32 vlv_gps_core_read(struct drm_i915_private *dev_priv, u32 reg)
{
u32 val = 0;
- vlv_sideband_rw(dev_priv, PCI_DEVFN(2, 0), IOSF_PORT_GPS_CORE,
+ vlv_sideband_rw(dev_priv, PCI_DEVFN(0, 0), IOSF_PORT_GPS_CORE,
SB_CRRDDA_NP, reg, &val);
return val;
}
void vlv_gps_core_write(struct drm_i915_private *dev_priv, u32 reg, u32 val)
{
- vlv_sideband_rw(dev_priv, PCI_DEVFN(2, 0), IOSF_PORT_GPS_CORE,
+ vlv_sideband_rw(dev_priv, PCI_DEVFN(0, 0), IOSF_PORT_GPS_CORE,
SB_CRWRDA_NP, reg, &val);
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 089/183] cfq-iosched: handle failure of cfq group allocation
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (87 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 088/183] drm/i915: Correct the IOSF Dev_FN field for IOSF transfers Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 090/183] tracing: Fix unmapping loop in tracing_mark_write Luis Henriques
` (93 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Konstantin Khlebnikov, Jens Axboe, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Konstantin Khlebnikov <khlebnikov@yandex-team.ru>
commit 69abaffec7d47a083739b79e3066cb3730eba72e upstream.
Cfq_lookup_create_cfqg() allocates struct blkcg_gq using GFP_ATOMIC.
In cfq_find_alloc_queue() possible allocation failure is not handled.
As a result kernel oopses on NULL pointer dereference when
cfq_link_cfqq_cfqg() calls cfqg_get() for NULL pointer.
Bug was introduced in v3.5 in commit cd1604fab4f9 ("blkcg: factor
out blkio_group creation"). Prior to that commit cfq group lookup
had returned pointer to root group as fallback.
This patch handles this error using existing fallback oom_cfqq.
Signed-off-by: Konstantin Khlebnikov <khlebnikov@yandex-team.ru>
Acked-by: Tejun Heo <tj@kernel.org>
Acked-by: Vivek Goyal <vgoyal@redhat.com>
Fixes: cd1604fab4f9 ("blkcg: factor out blkio_group creation")
Signed-off-by: Jens Axboe <axboe@fb.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
block/cfq-iosched.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/block/cfq-iosched.c b/block/cfq-iosched.c
index f3627ca9303b..2c0585adfaea 100644
--- a/block/cfq-iosched.c
+++ b/block/cfq-iosched.c
@@ -3582,6 +3582,11 @@ retry:
blkcg = bio_blkcg(bio);
cfqg = cfq_lookup_create_cfqg(cfqd, blkcg);
+ if (!cfqg) {
+ cfqq = &cfqd->oom_cfqq;
+ goto out;
+ }
+
cfqq = cic_to_cfqq(cic, is_sync);
/*
@@ -3618,7 +3623,7 @@ retry:
} else
cfqq = &cfqd->oom_cfqq;
}
-
+out:
if (new_cfqq)
kmem_cache_free(cfq_pool, new_cfqq);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 090/183] tracing: Fix unmapping loop in tracing_mark_write
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (88 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 089/183] cfq-iosched: handle failure of cfq group allocation Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 091/183] fsnotify: fix handling of renames in audit Luis Henriques
` (92 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Vikram Mulukutla, Steven Rostedt, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Vikram Mulukutla <markivx@codeaurora.org>
commit 7215853e985a4bef1a6c14e00e89dfec84f1e457 upstream.
Commit 6edb2a8a385f0cdef51dae37ff23e74d76d8a6ce introduced
an array map_pages that contains the addresses returned by
kmap_atomic. However, when unmapping those pages, map_pages[0]
is unmapped before map_pages[1], breaking the nesting requirement
as specified in the documentation for kmap_atomic/kunmap_atomic.
This was caught by the highmem debug code present in kunmap_atomic.
Fix the loop to do the unmapping properly.
Link: http://lkml.kernel.org/r/1418871056-6614-1-git-send-email-markivx@codeaurora.org
Reviewed-by: Stephen Boyd <sboyd@codeaurora.org>
Reported-by: Lime Yang <limey@codeaurora.org>
Signed-off-by: Vikram Mulukutla <markivx@codeaurora.org>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
kernel/trace/trace.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/trace/trace.c b/kernel/trace/trace.c
index 01603e48742e..8b924fb7f915 100644
--- a/kernel/trace/trace.c
+++ b/kernel/trace/trace.c
@@ -4894,7 +4894,7 @@ tracing_mark_write(struct file *filp, const char __user *ubuf,
*fpos += written;
out_unlock:
- for (i = 0; i < nr_pages; i++){
+ for (i = nr_pages - 1; i >= 0; i--) {
kunmap_atomic(map_page[i]);
put_page(pages[i]);
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 091/183] fsnotify: fix handling of renames in audit
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (89 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 090/183] tracing: Fix unmapping loop in tracing_mark_write Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 092/183] ring-buffer: Do not wake up a splice waiter when page is not full Luis Henriques
` (91 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Jan Kara, Paul Moore, Eric Paris, Andrew Morton, Linus Torvalds,
Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jan Kara <jack@suse.cz>
commit 6ee8e25fc3e916193bce4ebb43d5439e1e2144ab upstream.
Commit e9fd702a58c4 ("audit: convert audit watches to use fsnotify
instead of inotify") broke handling of renames in audit. Audit code
wants to update inode number of an inode corresponding to watched name
in a directory. When something gets renamed into a directory to a
watched name, inotify previously passed moved inode to audit code
however new fsnotify code passes directory inode where the change
happened. That confuses audit and it starts watching parent directory
instead of a file in a directory.
This can be observed for example by doing:
cd /tmp
touch foo bar
auditctl -w /tmp/foo
touch foo
mv bar foo
touch foo
In audit log we see events like:
type=CONFIG_CHANGE msg=audit(1423563584.155:90): auid=1000 ses=2 op="updated rules" path="/tmp/foo" key=(null) list=4 res=1
...
type=PATH msg=audit(1423563584.155:91): item=2 name="bar" inode=1046884 dev=08:0 2 mode=0100644 ouid=0 ogid=0 rdev=00:00 nametype=DELETE
type=PATH msg=audit(1423563584.155:91): item=3 name="foo" inode=1046842 dev=08:0 2 mode=0100644 ouid=0 ogid=0 rdev=00:00 nametype=DELETE
type=PATH msg=audit(1423563584.155:91): item=4 name="foo" inode=1046884 dev=08:0 2 mode=0100644 ouid=0 ogid=0 rdev=00:00 nametype=CREATE
...
and that's it - we see event for the first touch after creating the
audit rule, we see events for rename but we don't see any event for the
last touch. However we start seeing events for unrelated stuff
happening in /tmp.
Fix the problem by passing moved inode as data in the FS_MOVED_FROM and
FS_MOVED_TO events instead of the directory where the change happens.
This doesn't introduce any new problems because noone besides
audit_watch.c cares about the passed value:
fs/notify/fanotify/fanotify.c cares only about FSNOTIFY_EVENT_PATH events.
fs/notify/dnotify/dnotify.c doesn't care about passed 'data' value at all.
fs/notify/inotify/inotify_fsnotify.c uses 'data' only for FSNOTIFY_EVENT_PATH.
kernel/audit_tree.c doesn't care about passed 'data' at all.
kernel/audit_watch.c expects moved inode as 'data'.
Fixes: e9fd702a58c49db ("audit: convert audit watches to use fsnotify instead of inotify")
Signed-off-by: Jan Kara <jack@suse.cz>
Cc: Paul Moore <paul@paul-moore.com>
Cc: Eric Paris <eparis@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
include/linux/fsnotify.h | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/include/linux/fsnotify.h b/include/linux/fsnotify.h
index 1c804b057fb1..7ee1774edee5 100644
--- a/include/linux/fsnotify.h
+++ b/include/linux/fsnotify.h
@@ -101,8 +101,10 @@ static inline void fsnotify_move(struct inode *old_dir, struct inode *new_dir,
new_dir_mask |= FS_ISDIR;
}
- fsnotify(old_dir, old_dir_mask, old_dir, FSNOTIFY_EVENT_INODE, old_name, fs_cookie);
- fsnotify(new_dir, new_dir_mask, new_dir, FSNOTIFY_EVENT_INODE, new_name, fs_cookie);
+ fsnotify(old_dir, old_dir_mask, source, FSNOTIFY_EVENT_INODE, old_name,
+ fs_cookie);
+ fsnotify(new_dir, new_dir_mask, source, FSNOTIFY_EVENT_INODE, new_name,
+ fs_cookie);
if (target)
fsnotify_link_count(target);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 092/183] ring-buffer: Do not wake up a splice waiter when page is not full
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (90 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 091/183] fsnotify: fix handling of renames in audit Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 093/183] blk-mq: fix double-free in error path Luis Henriques
` (90 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Rabin Vincent, Steven Rostedt, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: "Steven Rostedt (Red Hat)" <rostedt@goodmis.org>
commit 1e0d6714aceb770b04161fbedd7765d0e1fc27bd upstream.
When an application connects to the ring buffer via splice, it can only
read full pages. Splice does not work with partial pages. If there is
not enough data to fill a page, the splice command will either block
or return -EAGAIN (if set to nonblock).
Code was added where if the page is not full, to just sleep again.
The problem is, it will get woken up again on the next event. That
is, when something is written into the ring buffer, if there is a waiter
it will wake it up. The waiter would then check the buffer, see that
it still does not have enough data to fill a page and go back to sleep.
To make matters worse, when the waiter goes back to sleep, it could
cause another event, which would wake it back up again to see it
doesn't have enough data and sleep again. This produces a tremendous
overhead and fills the ring buffer with noise.
For example, recording sched_switch on an idle system for 10 seconds
produces 25,350,475 events!!!
Create another wait queue for those waiters wanting full pages.
When an event is written, it only wakes up waiters if there's a full
page of data. It does not wake up the waiter if the page is not yet
full.
After this change, recording sched_switch on an idle system for 10
seconds produces only 800 events. Getting rid of 25,349,675 useless
events (99.9969% of events!!), is something to take seriously.
Cc: Rabin Vincent <rabin@rab.in>
Fixes: e30f53aad220 "tracing: Do not busy wait in buffer splice"
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
kernel/trace/ring_buffer.c | 40 +++++++++++++++++++++++++++++++++++-----
1 file changed, 35 insertions(+), 5 deletions(-)
diff --git a/kernel/trace/ring_buffer.c b/kernel/trace/ring_buffer.c
index 80516c7cee86..a16472e40117 100644
--- a/kernel/trace/ring_buffer.c
+++ b/kernel/trace/ring_buffer.c
@@ -450,7 +450,10 @@ int ring_buffer_print_page_header(struct trace_seq *s)
struct rb_irq_work {
struct irq_work work;
wait_queue_head_t waiters;
+ wait_queue_head_t full_waiters;
bool waiters_pending;
+ bool full_waiters_pending;
+ bool wakeup_full;
};
/*
@@ -532,6 +535,10 @@ static void rb_wake_up_waiters(struct irq_work *work)
struct rb_irq_work *rbwork = container_of(work, struct rb_irq_work, work);
wake_up_all(&rbwork->waiters);
+ if (rbwork->wakeup_full) {
+ rbwork->wakeup_full = false;
+ wake_up_all(&rbwork->full_waiters);
+ }
}
/**
@@ -556,9 +563,11 @@ int ring_buffer_wait(struct ring_buffer *buffer, int cpu, bool full)
* data in any cpu buffer, or a specific buffer, put the
* caller on the appropriate wait queue.
*/
- if (cpu == RING_BUFFER_ALL_CPUS)
+ if (cpu == RING_BUFFER_ALL_CPUS) {
work = &buffer->irq_work;
- else {
+ /* Full only makes sense on per cpu reads */
+ full = false;
+ } else {
if (!cpumask_test_cpu(cpu, buffer->cpumask))
return -ENODEV;
cpu_buffer = buffer->buffers[cpu];
@@ -567,7 +576,10 @@ int ring_buffer_wait(struct ring_buffer *buffer, int cpu, bool full)
while (true) {
- prepare_to_wait(&work->waiters, &wait, TASK_INTERRUPTIBLE);
+ if (full)
+ prepare_to_wait(&work->full_waiters, &wait, TASK_INTERRUPTIBLE);
+ else
+ prepare_to_wait(&work->waiters, &wait, TASK_INTERRUPTIBLE);
/*
* The events can happen in critical sections where
@@ -589,7 +601,10 @@ int ring_buffer_wait(struct ring_buffer *buffer, int cpu, bool full)
* that is necessary is that the wake up happens after
* a task has been queued. It's OK for spurious wake ups.
*/
- work->waiters_pending = true;
+ if (full)
+ work->full_waiters_pending = true;
+ else
+ work->waiters_pending = true;
if (signal_pending(current)) {
ret = -EINTR;
@@ -618,7 +633,10 @@ int ring_buffer_wait(struct ring_buffer *buffer, int cpu, bool full)
schedule();
}
- finish_wait(&work->waiters, &wait);
+ if (full)
+ finish_wait(&work->full_waiters, &wait);
+ else
+ finish_wait(&work->waiters, &wait);
return ret;
}
@@ -1233,6 +1251,7 @@ rb_allocate_cpu_buffer(struct ring_buffer *buffer, int nr_pages, int cpu)
init_completion(&cpu_buffer->update_done);
init_irq_work(&cpu_buffer->irq_work.work, rb_wake_up_waiters);
init_waitqueue_head(&cpu_buffer->irq_work.waiters);
+ init_waitqueue_head(&cpu_buffer->irq_work.full_waiters);
bpage = kzalloc_node(ALIGN(sizeof(*bpage), cache_line_size()),
GFP_KERNEL, cpu_to_node(cpu));
@@ -2820,6 +2839,8 @@ static void rb_commit(struct ring_buffer_per_cpu *cpu_buffer,
static __always_inline void
rb_wakeups(struct ring_buffer *buffer, struct ring_buffer_per_cpu *cpu_buffer)
{
+ bool pagebusy;
+
if (buffer->irq_work.waiters_pending) {
buffer->irq_work.waiters_pending = false;
/* irq_work_queue() supplies it's own memory barriers */
@@ -2831,6 +2852,15 @@ rb_wakeups(struct ring_buffer *buffer, struct ring_buffer_per_cpu *cpu_buffer)
/* irq_work_queue() supplies it's own memory barriers */
irq_work_queue(&cpu_buffer->irq_work.work);
}
+
+ pagebusy = cpu_buffer->reader_page == cpu_buffer->commit_page;
+
+ if (!pagebusy && cpu_buffer->irq_work.full_waiters_pending) {
+ cpu_buffer->irq_work.wakeup_full = true;
+ cpu_buffer->irq_work.full_waiters_pending = false;
+ /* irq_work_queue() supplies it's own memory barriers */
+ irq_work_queue(&cpu_buffer->irq_work.work);
+ }
}
/**
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 093/183] blk-mq: fix double-free in error path
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (91 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 092/183] ring-buffer: Do not wake up a splice waiter when page is not full Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 094/183] drm/radeon: workaround for CP HW bug on CIK Luis Henriques
` (89 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Tony Battersby, Jens Axboe, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Tony Battersby <tonyb@cybernetics.com>
commit 564e559f2baf6a868768d0cac286980b3cfd6e30 upstream.
If the allocation of bt->bs fails, then bt->map can be freed twice, once
in blk_mq_init_bitmap_tags() -> bt_alloc(), and once in
blk_mq_init_bitmap_tags() -> bt_free(). Fix by setting the pointer to
NULL after the first free.
Signed-off-by: Tony Battersby <tonyb@cybernetics.com>
Signed-off-by: Jens Axboe <axboe@fb.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
block/blk-mq-tag.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/block/blk-mq-tag.c b/block/blk-mq-tag.c
index 1caaa7c4605d..b88f4b375c27 100644
--- a/block/blk-mq-tag.c
+++ b/block/blk-mq-tag.c
@@ -511,6 +511,7 @@ static int bt_alloc(struct blk_mq_bitmap_tags *bt, unsigned int depth,
bt->bs = kzalloc(BT_WAIT_QUEUES * sizeof(*bt->bs), GFP_KERNEL);
if (!bt->bs) {
kfree(bt->map);
+ bt->map = NULL;
return -ENOMEM;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 094/183] drm/radeon: workaround for CP HW bug on CIK
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (92 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 093/183] blk-mq: fix double-free in error path Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 095/183] drm/radeon: only enable kv/kb dpm interrupts once v3 Luis Henriques
` (88 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Christian König, Alex Deucher, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: =?UTF-8?q?Christian=20K=C3=B6nig?= <christian.koenig@amd.com>
commit a9c73a0e022c33954835e66fec3cd744af90ec98 upstream.
Emit the EOP twice to avoid cache flushing problems.
Signed-off-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/gpu/drm/radeon/cik.c | 16 +++++++++++++++-
1 file changed, 15 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/radeon/cik.c b/drivers/gpu/drm/radeon/cik.c
index 096a36c186a0..60b589e07ee2 100644
--- a/drivers/gpu/drm/radeon/cik.c
+++ b/drivers/gpu/drm/radeon/cik.c
@@ -3656,7 +3656,21 @@ void cik_fence_gfx_ring_emit(struct radeon_device *rdev,
struct radeon_ring *ring = &rdev->ring[fence->ring];
u64 addr = rdev->fence_drv[fence->ring].gpu_addr;
- /* EVENT_WRITE_EOP - flush caches, send int */
+ /* Workaround for cache flush problems. First send a dummy EOP
+ * event down the pipe with seq one below.
+ */
+ radeon_ring_write(ring, PACKET3(PACKET3_EVENT_WRITE_EOP, 4));
+ radeon_ring_write(ring, (EOP_TCL1_ACTION_EN |
+ EOP_TC_ACTION_EN |
+ EVENT_TYPE(CACHE_FLUSH_AND_INV_TS_EVENT) |
+ EVENT_INDEX(5)));
+ radeon_ring_write(ring, addr & 0xfffffffc);
+ radeon_ring_write(ring, (upper_32_bits(addr) & 0xffff) |
+ DATA_SEL(1) | INT_SEL(0));
+ radeon_ring_write(ring, fence->seq - 1);
+ radeon_ring_write(ring, 0);
+
+ /* Then send the real EOP event down the pipe. */
radeon_ring_write(ring, PACKET3(PACKET3_EVENT_WRITE_EOP, 4));
radeon_ring_write(ring, (EOP_TCL1_ACTION_EN |
EOP_TC_ACTION_EN |
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 095/183] drm/radeon: only enable kv/kb dpm interrupts once v3
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (93 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 094/183] drm/radeon: workaround for CP HW bug on CIK Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 096/183] NFSv4.1: Fix a kfree() of uninitialised pointers in decode_cb_sequence_args Luis Henriques
` (87 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Alex Deucher, Christian König, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Deucher <alexander.deucher@amd.com>
commit 410af8d7285a0b96314845c75c39fd612b755688 upstream.
Enable at init and disable on fini. Workaround for hardware problems.
v2 (chk): extend commit message
v3: add new function
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Christian König <christian.koenig@amd.com> (v2)
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/gpu/drm/radeon/cik.c | 21 ---------------------
drivers/gpu/drm/radeon/kv_dpm.c | 17 +++++++++++++++--
2 files changed, 15 insertions(+), 23 deletions(-)
diff --git a/drivers/gpu/drm/radeon/cik.c b/drivers/gpu/drm/radeon/cik.c
index 60b589e07ee2..f898ed31cffb 100644
--- a/drivers/gpu/drm/radeon/cik.c
+++ b/drivers/gpu/drm/radeon/cik.c
@@ -6939,7 +6939,6 @@ int cik_irq_set(struct radeon_device *rdev)
u32 hpd1, hpd2, hpd3, hpd4, hpd5, hpd6;
u32 grbm_int_cntl = 0;
u32 dma_cntl, dma_cntl1;
- u32 thermal_int;
if (!rdev->irq.installed) {
WARN(1, "Can't enable IRQ/MSI because no handler is installed\n");
@@ -6976,13 +6975,6 @@ int cik_irq_set(struct radeon_device *rdev)
cp_m2p2 = RREG32(CP_ME2_PIPE2_INT_CNTL) & ~TIME_STAMP_INT_ENABLE;
cp_m2p3 = RREG32(CP_ME2_PIPE3_INT_CNTL) & ~TIME_STAMP_INT_ENABLE;
- if (rdev->flags & RADEON_IS_IGP)
- thermal_int = RREG32_SMC(CG_THERMAL_INT_CTRL) &
- ~(THERM_INTH_MASK | THERM_INTL_MASK);
- else
- thermal_int = RREG32_SMC(CG_THERMAL_INT) &
- ~(THERM_INT_MASK_HIGH | THERM_INT_MASK_LOW);
-
/* enable CP interrupts on all rings */
if (atomic_read(&rdev->irq.ring_int[RADEON_RING_TYPE_GFX_INDEX])) {
DRM_DEBUG("cik_irq_set: sw int gfx\n");
@@ -7140,14 +7132,6 @@ int cik_irq_set(struct radeon_device *rdev)
hpd6 |= DC_HPDx_INT_EN;
}
- if (rdev->irq.dpm_thermal) {
- DRM_DEBUG("dpm thermal\n");
- if (rdev->flags & RADEON_IS_IGP)
- thermal_int |= THERM_INTH_MASK | THERM_INTL_MASK;
- else
- thermal_int |= THERM_INT_MASK_HIGH | THERM_INT_MASK_LOW;
- }
-
WREG32(CP_INT_CNTL_RING0, cp_int_cntl);
WREG32(SDMA0_CNTL + SDMA0_REGISTER_OFFSET, dma_cntl);
@@ -7201,11 +7185,6 @@ int cik_irq_set(struct radeon_device *rdev)
WREG32(DC_HPD5_INT_CONTROL, hpd5);
WREG32(DC_HPD6_INT_CONTROL, hpd6);
- if (rdev->flags & RADEON_IS_IGP)
- WREG32_SMC(CG_THERMAL_INT_CTRL, thermal_int);
- else
- WREG32_SMC(CG_THERMAL_INT, thermal_int);
-
return 0;
}
diff --git a/drivers/gpu/drm/radeon/kv_dpm.c b/drivers/gpu/drm/radeon/kv_dpm.c
index d873f86a3045..2be79cf71591 100644
--- a/drivers/gpu/drm/radeon/kv_dpm.c
+++ b/drivers/gpu/drm/radeon/kv_dpm.c
@@ -1169,6 +1169,19 @@ void kv_dpm_enable_bapm(struct radeon_device *rdev, bool enable)
}
}
+static void kv_enable_thermal_int(struct radeon_device *rdev, bool enable)
+{
+ u32 thermal_int;
+
+ thermal_int = RREG32_SMC(CG_THERMAL_INT_CTRL);
+ if (enable)
+ thermal_int |= THERM_INTH_MASK | THERM_INTL_MASK;
+ else
+ thermal_int &= ~(THERM_INTH_MASK | THERM_INTL_MASK);
+ WREG32_SMC(CG_THERMAL_INT_CTRL, thermal_int);
+
+}
+
int kv_dpm_enable(struct radeon_device *rdev)
{
struct kv_power_info *pi = kv_get_pi(rdev);
@@ -1280,8 +1293,7 @@ int kv_dpm_late_enable(struct radeon_device *rdev)
DRM_ERROR("kv_set_thermal_temperature_range failed\n");
return ret;
}
- rdev->irq.dpm_thermal = true;
- radeon_irq_set(rdev);
+ kv_enable_thermal_int(rdev, true);
}
/* powerdown unused blocks for now */
@@ -1312,6 +1324,7 @@ void kv_dpm_disable(struct radeon_device *rdev)
kv_stop_dpm(rdev);
kv_enable_ulv(rdev, false);
kv_reset_am(rdev);
+ kv_enable_thermal_int(rdev, false);
kv_update_current_ps(rdev, rdev->pm.dpm.boot_ps);
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 096/183] NFSv4.1: Fix a kfree() of uninitialised pointers in decode_cb_sequence_args
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (94 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 095/183] drm/radeon: only enable kv/kb dpm interrupts once v3 Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 097/183] cpufreq: speedstep-smi: enable interrupts when waiting Luis Henriques
` (86 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Trond Myklebust, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Trond Myklebust <trond.myklebust@primarydata.com>
commit d8ba1f971497c19cf80da1ea5391a46a5f9fbd41 upstream.
If the call to decode_rc_list() fails due to a memory allocation error,
then we need to truncate the array size to ensure that we only call
kfree() on those pointer that were allocated.
Reported-by: David Ramos <daramos@stanford.edu>
Fixes: 4aece6a19cf7f ("nfs41: cb_sequence xdr implementation")
Signed-off-by: Trond Myklebust <trond.myklebust@primarydata.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/nfs/callback_xdr.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/fs/nfs/callback_xdr.c b/fs/nfs/callback_xdr.c
index f4ccfe6521ec..02f8d09e119f 100644
--- a/fs/nfs/callback_xdr.c
+++ b/fs/nfs/callback_xdr.c
@@ -464,8 +464,10 @@ static __be32 decode_cb_sequence_args(struct svc_rqst *rqstp,
for (i = 0; i < args->csa_nrclists; i++) {
status = decode_rc_list(xdr, &args->csa_rclists[i]);
- if (status)
+ if (status) {
+ args->csa_nrclists = i;
goto out_free;
+ }
}
}
status = 0;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 097/183] cpufreq: speedstep-smi: enable interrupts when waiting
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (95 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 096/183] NFSv4.1: Fix a kfree() of uninitialised pointers in decode_cb_sequence_args Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 098/183] mm/hugetlb: pmd_huge() returns true for non-present hugepage Luis Henriques
` (85 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Mikulas Patocka, Rafael J. Wysocki, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikulas Patocka <mpatocka@redhat.com>
commit d4d4eda23794c701442e55129dd4f8f2fefd5e4d upstream.
On Dell Latitude C600 laptop with Pentium 3 850MHz processor, the
speedstep-smi driver sometimes loads and sometimes doesn't load with
"change to state X failed" message.
The hardware sometimes refuses to change frequency and in this case, we
need to retry later. I found out that we need to enable interrupts while
waiting. When we enable interrupts, the hardware blockage that prevents
frequency transition resolves and the transition is possible. With
disabled interrupts, the blockage doesn't resolve (no matter how long do
we wait). The exact reasons for this hardware behavior are unknown.
This patch enables interrupts in the function speedstep_set_state that can
be called with disabled interrupts. However, this function is called with
disabled interrupts only from speedstep_get_freqs, so it shouldn't cause
any problem.
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com
Acked-by: Viresh Kumar <viresh.kumar@linaro.org>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/cpufreq/speedstep-lib.c | 3 +++
drivers/cpufreq/speedstep-smi.c | 12 ++++++++++++
2 files changed, 15 insertions(+)
diff --git a/drivers/cpufreq/speedstep-lib.c b/drivers/cpufreq/speedstep-lib.c
index 7047821a7f8a..4ab7a2156672 100644
--- a/drivers/cpufreq/speedstep-lib.c
+++ b/drivers/cpufreq/speedstep-lib.c
@@ -400,6 +400,7 @@ unsigned int speedstep_get_freqs(enum speedstep_processor processor,
pr_debug("previous speed is %u\n", prev_speed);
+ preempt_disable();
local_irq_save(flags);
/* switch to low state */
@@ -464,6 +465,8 @@ unsigned int speedstep_get_freqs(enum speedstep_processor processor,
out:
local_irq_restore(flags);
+ preempt_enable();
+
return ret;
}
EXPORT_SYMBOL_GPL(speedstep_get_freqs);
diff --git a/drivers/cpufreq/speedstep-smi.c b/drivers/cpufreq/speedstep-smi.c
index 8635eec96da5..a19e7ee25813 100644
--- a/drivers/cpufreq/speedstep-smi.c
+++ b/drivers/cpufreq/speedstep-smi.c
@@ -156,6 +156,7 @@ static void speedstep_set_state(unsigned int state)
return;
/* Disable IRQs */
+ preempt_disable();
local_irq_save(flags);
command = (smi_sig & 0xffffff00) | (smi_cmd & 0xff);
@@ -166,9 +167,19 @@ static void speedstep_set_state(unsigned int state)
do {
if (retry) {
+ /*
+ * We need to enable interrupts, otherwise the blockage
+ * won't resolve.
+ *
+ * We disable preemption so that other processes don't
+ * run. If other processes were running, they could
+ * submit more DMA requests, making the blockage worse.
+ */
pr_debug("retry %u, previous result %u, waiting...\n",
retry, result);
+ local_irq_enable();
mdelay(retry * 50);
+ local_irq_disable();
}
retry++;
__asm__ __volatile__(
@@ -185,6 +196,7 @@ static void speedstep_set_state(unsigned int state)
/* enable IRQs */
local_irq_restore(flags);
+ preempt_enable();
if (new_state == state)
pr_debug("change to %u MHz succeeded after %u tries "
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 098/183] mm/hugetlb: pmd_huge() returns true for non-present hugepage
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (96 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 097/183] cpufreq: speedstep-smi: enable interrupts when waiting Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 099/183] mm/hugetlb: take page table lock in follow_huge_pmd() Luis Henriques
` (84 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Naoya Horiguchi, Hugh Dickins, James Hogan, David Rientjes,
Mel Gorman, Johannes Weiner, Michal Hocko, Rik van Riel,
Andrea Arcangeli, Luiz Capitulino, Nishanth Aravamudan,
Lee Schermerhorn, Steve Capper, Andrew Morton, Linus Torvalds,
Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
commit cbef8478bee55775ac312a574aad48af7bb9cf9f upstream.
Migrating hugepages and hwpoisoned hugepages are considered as non-present
hugepages, and they are referenced via migration entries and hwpoison
entries in their page table slots.
This behavior causes race condition because pmd_huge() doesn't tell
non-huge pages from migrating/hwpoisoned hugepages. follow_page_mask() is
one example where the kernel would call follow_page_pte() for such
hugepage while this function is supposed to handle only normal pages.
To avoid this, this patch makes pmd_huge() return true when pmd_none() is
true *and* pmd_present() is false. We don't have to worry about mixing up
non-present pmd entry with normal pmd (pointing to leaf level pte entry)
because pmd_present() is true in normal pmd.
The same race condition could happen in (x86-specific) gup_pmd_range(),
where this patch simply adds pmd_present() check instead of pmd_huge().
This is because gup_pmd_range() is fast path. If we have non-present
hugepage in this function, we will go into gup_huge_pmd(), then return 0
at flag mask check, and finally fall back to the slow path.
Fixes: 290408d4a2 ("hugetlb: hugepage migration core")
Signed-off-by: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: James Hogan <james.hogan@imgtec.com>
Cc: David Rientjes <rientjes@google.com>
Cc: Mel Gorman <mel@csn.ul.ie>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Michal Hocko <mhocko@suse.cz>
Cc: Rik van Riel <riel@redhat.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Luiz Capitulino <lcapitulino@redhat.com>
Cc: Nishanth Aravamudan <nacc@linux.vnet.ibm.com>
Cc: Lee Schermerhorn <lee.schermerhorn@hp.com>
Cc: Steve Capper <steve.capper@linaro.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/x86/mm/gup.c | 2 +-
arch/x86/mm/hugetlbpage.c | 8 +++++++-
mm/hugetlb.c | 2 ++
3 files changed, 10 insertions(+), 2 deletions(-)
diff --git a/arch/x86/mm/gup.c b/arch/x86/mm/gup.c
index 207d9aef662d..448ee8912d9b 100644
--- a/arch/x86/mm/gup.c
+++ b/arch/x86/mm/gup.c
@@ -172,7 +172,7 @@ static int gup_pmd_range(pud_t pud, unsigned long addr, unsigned long end,
*/
if (pmd_none(pmd) || pmd_trans_splitting(pmd))
return 0;
- if (unlikely(pmd_large(pmd))) {
+ if (unlikely(pmd_large(pmd) || !pmd_present(pmd))) {
/*
* NUMA hinting faults need to be handled in the GUP
* slowpath for accounting purposes and so that they
diff --git a/arch/x86/mm/hugetlbpage.c b/arch/x86/mm/hugetlbpage.c
index 8b977ebf9388..006cc914994b 100644
--- a/arch/x86/mm/hugetlbpage.c
+++ b/arch/x86/mm/hugetlbpage.c
@@ -66,9 +66,15 @@ follow_huge_addr(struct mm_struct *mm, unsigned long address, int write)
return ERR_PTR(-EINVAL);
}
+/*
+ * pmd_huge() returns 1 if @pmd is hugetlb related entry, that is normal
+ * hugetlb entry or non-present (migration or hwpoisoned) hugetlb entry.
+ * Otherwise, returns 0.
+ */
int pmd_huge(pmd_t pmd)
{
- return !!(pmd_val(pmd) & _PAGE_PSE);
+ return !pmd_none(pmd) &&
+ (pmd_val(pmd) & (_PAGE_PRESENT|_PAGE_PSE)) != _PAGE_PRESENT;
}
int pud_huge(pud_t pud)
diff --git a/mm/hugetlb.c b/mm/hugetlb.c
index 7ae54449f252..4a1af45eefcd 100644
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -3673,6 +3673,8 @@ follow_huge_pmd(struct mm_struct *mm, unsigned long address,
{
struct page *page;
+ if (!pmd_present(*pmd))
+ return NULL;
page = pte_page(*(pte_t *)pmd);
if (page)
page += ((address & ~PMD_MASK) >> PAGE_SHIFT);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 099/183] mm/hugetlb: take page table lock in follow_huge_pmd()
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (97 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 098/183] mm/hugetlb: pmd_huge() returns true for non-present hugepage Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 100/183] mm/hugetlb: fix getting refcount 0 page in hugetlb_fault() Luis Henriques
` (83 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Naoya Horiguchi, James Hogan, David Rientjes, Mel Gorman,
Johannes Weiner, Michal Hocko, Rik van Riel, Andrea Arcangeli,
Luiz Capitulino, Nishanth Aravamudan, Lee Schermerhorn,
Steve Capper, Andrew Morton, Linus Torvalds, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
commit e66f17ff71772b209eed39de35aaa99ba819c93d upstream.
We have a race condition between move_pages() and freeing hugepages, where
move_pages() calls follow_page(FOLL_GET) for hugepages internally and
tries to get its refcount without preventing concurrent freeing. This
race crashes the kernel, so this patch fixes it by moving FOLL_GET code
for hugepages into follow_huge_pmd() with taking the page table lock.
This patch intentionally removes page==NULL check after pte_page.
This is justified because pte_page() never returns NULL for any
architectures or configurations.
This patch changes the behavior of follow_huge_pmd() for tail pages and
then tail pages can be pinned/returned. So the caller must be changed to
properly handle the returned tail pages.
We could have a choice to add the similar locking to
follow_huge_(addr|pud) for consistency, but it's not necessary because
currently these functions don't support FOLL_GET flag, so let's leave it
for future development.
Here is the reproducer:
$ cat movepages.c
#include <stdio.h>
#include <stdlib.h>
#include <numaif.h>
#define ADDR_INPUT 0x700000000000UL
#define HPS 0x200000
#define PS 0x1000
int main(int argc, char *argv[]) {
int i;
int nr_hp = strtol(argv[1], NULL, 0);
int nr_p = nr_hp * HPS / PS;
int ret;
void **addrs;
int *status;
int *nodes;
pid_t pid;
pid = strtol(argv[2], NULL, 0);
addrs = malloc(sizeof(char *) * nr_p + 1);
status = malloc(sizeof(char *) * nr_p + 1);
nodes = malloc(sizeof(char *) * nr_p + 1);
while (1) {
for (i = 0; i < nr_p; i++) {
addrs[i] = (void *)ADDR_INPUT + i * PS;
nodes[i] = 1;
status[i] = 0;
}
ret = numa_move_pages(pid, nr_p, addrs, nodes, status,
MPOL_MF_MOVE_ALL);
if (ret == -1)
err("move_pages");
for (i = 0; i < nr_p; i++) {
addrs[i] = (void *)ADDR_INPUT + i * PS;
nodes[i] = 0;
status[i] = 0;
}
ret = numa_move_pages(pid, nr_p, addrs, nodes, status,
MPOL_MF_MOVE_ALL);
if (ret == -1)
err("move_pages");
}
return 0;
}
$ cat hugepage.c
#include <stdio.h>
#include <sys/mman.h>
#include <string.h>
#define ADDR_INPUT 0x700000000000UL
#define HPS 0x200000
int main(int argc, char *argv[]) {
int nr_hp = strtol(argv[1], NULL, 0);
char *p;
while (1) {
p = mmap((void *)ADDR_INPUT, nr_hp * HPS, PROT_READ | PROT_WRITE,
MAP_PRIVATE | MAP_ANONYMOUS | MAP_HUGETLB, -1, 0);
if (p != (void *)ADDR_INPUT) {
perror("mmap");
break;
}
memset(p, 0, nr_hp * HPS);
munmap(p, nr_hp * HPS);
}
}
$ sysctl vm.nr_hugepages=40
$ ./hugepage 10 &
$ ./movepages 10 $(pgrep -f hugepage)
Fixes: e632a938d914 ("mm: migrate: add hugepage migration code to move_pages()")
Signed-off-by: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
Reported-by: Hugh Dickins <hughd@google.com>
Cc: James Hogan <james.hogan@imgtec.com>
Cc: David Rientjes <rientjes@google.com>
Cc: Mel Gorman <mel@csn.ul.ie>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Michal Hocko <mhocko@suse.cz>
Cc: Rik van Riel <riel@redhat.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Luiz Capitulino <lcapitulino@redhat.com>
Cc: Nishanth Aravamudan <nacc@linux.vnet.ibm.com>
Cc: Lee Schermerhorn <lee.schermerhorn@hp.com>
Cc: Steve Capper <steve.capper@linaro.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
include/linux/hugetlb.h | 8 ++++----
include/linux/swapops.h | 4 ++++
mm/gup.c | 25 ++++++++-----------------
mm/hugetlb.c | 48 ++++++++++++++++++++++++++++++++++--------------
mm/migrate.c | 5 +++--
5 files changed, 53 insertions(+), 37 deletions(-)
diff --git a/include/linux/hugetlb.h b/include/linux/hugetlb.h
index a23c096b3080..26534ba1aef3 100644
--- a/include/linux/hugetlb.h
+++ b/include/linux/hugetlb.h
@@ -100,9 +100,9 @@ int huge_pmd_unshare(struct mm_struct *mm, unsigned long *addr, pte_t *ptep);
struct page *follow_huge_addr(struct mm_struct *mm, unsigned long address,
int write);
struct page *follow_huge_pmd(struct mm_struct *mm, unsigned long address,
- pmd_t *pmd, int write);
+ pmd_t *pmd, int flags);
struct page *follow_huge_pud(struct mm_struct *mm, unsigned long address,
- pud_t *pud, int write);
+ pud_t *pud, int flags);
int pmd_huge(pmd_t pmd);
int pud_huge(pud_t pmd);
unsigned long hugetlb_change_protection(struct vm_area_struct *vma,
@@ -134,8 +134,8 @@ static inline void hugetlb_report_meminfo(struct seq_file *m)
static inline void hugetlb_show_meminfo(void)
{
}
-#define follow_huge_pmd(mm, addr, pmd, write) NULL
-#define follow_huge_pud(mm, addr, pud, write) NULL
+#define follow_huge_pmd(mm, addr, pmd, flags) NULL
+#define follow_huge_pud(mm, addr, pud, flags) NULL
#define prepare_hugepage_range(file, addr, len) (-EINVAL)
#define pmd_huge(x) 0
#define pud_huge(x) 0
diff --git a/include/linux/swapops.h b/include/linux/swapops.h
index 6adfb7bfbf44..e288d5c016a7 100644
--- a/include/linux/swapops.h
+++ b/include/linux/swapops.h
@@ -137,6 +137,8 @@ static inline void make_migration_entry_read(swp_entry_t *entry)
*entry = swp_entry(SWP_MIGRATION_READ, swp_offset(*entry));
}
+extern void __migration_entry_wait(struct mm_struct *mm, pte_t *ptep,
+ spinlock_t *ptl);
extern void migration_entry_wait(struct mm_struct *mm, pmd_t *pmd,
unsigned long address);
extern void migration_entry_wait_huge(struct vm_area_struct *vma,
@@ -150,6 +152,8 @@ static inline int is_migration_entry(swp_entry_t swp)
}
#define migration_entry_to_page(swp) NULL
static inline void make_migration_entry_read(swp_entry_t *entryp) { }
+static inline void __migration_entry_wait(struct mm_struct *mm, pte_t *ptep,
+ spinlock_t *ptl) { }
static inline void migration_entry_wait(struct mm_struct *mm, pmd_t *pmd,
unsigned long address) { }
static inline void migration_entry_wait_huge(struct vm_area_struct *vma,
diff --git a/mm/gup.c b/mm/gup.c
index 3840fdbad19e..9cb1cfbe4677 100644
--- a/mm/gup.c
+++ b/mm/gup.c
@@ -163,10 +163,10 @@ struct page *follow_page_mask(struct vm_area_struct *vma,
if (pud_none(*pud))
return no_page_table(vma, flags);
if (pud_huge(*pud) && vma->vm_flags & VM_HUGETLB) {
- if (flags & FOLL_GET)
- return NULL;
- page = follow_huge_pud(mm, address, pud, flags & FOLL_WRITE);
- return page;
+ page = follow_huge_pud(mm, address, pud, flags);
+ if (page)
+ return page;
+ return no_page_table(vma, flags);
}
if (unlikely(pud_bad(*pud)))
return no_page_table(vma, flags);
@@ -175,19 +175,10 @@ struct page *follow_page_mask(struct vm_area_struct *vma,
if (pmd_none(*pmd))
return no_page_table(vma, flags);
if (pmd_huge(*pmd) && vma->vm_flags & VM_HUGETLB) {
- page = follow_huge_pmd(mm, address, pmd, flags & FOLL_WRITE);
- if (flags & FOLL_GET) {
- /*
- * Refcount on tail pages are not well-defined and
- * shouldn't be taken. The caller should handle a NULL
- * return when trying to follow tail pages.
- */
- if (PageHead(page))
- get_page(page);
- else
- page = NULL;
- }
- return page;
+ page = follow_huge_pmd(mm, address, pmd, flags);
+ if (page)
+ return page;
+ return no_page_table(vma, flags);
}
if ((flags & FOLL_NUMA) && pmd_numa(*pmd))
return no_page_table(vma, flags);
diff --git a/mm/hugetlb.c b/mm/hugetlb.c
index 4a1af45eefcd..0f03a4a79942 100644
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -3669,28 +3669,48 @@ pte_t *huge_pte_offset(struct mm_struct *mm, unsigned long addr)
struct page *
follow_huge_pmd(struct mm_struct *mm, unsigned long address,
- pmd_t *pmd, int write)
+ pmd_t *pmd, int flags)
{
- struct page *page;
-
- if (!pmd_present(*pmd))
- return NULL;
- page = pte_page(*(pte_t *)pmd);
- if (page)
- page += ((address & ~PMD_MASK) >> PAGE_SHIFT);
+ struct page *page = NULL;
+ spinlock_t *ptl;
+retry:
+ ptl = pmd_lockptr(mm, pmd);
+ spin_lock(ptl);
+ /*
+ * make sure that the address range covered by this pmd is not
+ * unmapped from other threads.
+ */
+ if (!pmd_huge(*pmd))
+ goto out;
+ if (pmd_present(*pmd)) {
+ page = pte_page(*(pte_t *)pmd) +
+ ((address & ~PMD_MASK) >> PAGE_SHIFT);
+ if (flags & FOLL_GET)
+ get_page(page);
+ } else {
+ if (is_hugetlb_entry_migration(huge_ptep_get((pte_t *)pmd))) {
+ spin_unlock(ptl);
+ __migration_entry_wait(mm, (pte_t *)pmd, ptl);
+ goto retry;
+ }
+ /*
+ * hwpoisoned entry is treated as no_page_table in
+ * follow_page_mask().
+ */
+ }
+out:
+ spin_unlock(ptl);
return page;
}
struct page *
follow_huge_pud(struct mm_struct *mm, unsigned long address,
- pud_t *pud, int write)
+ pud_t *pud, int flags)
{
- struct page *page;
+ if (flags & FOLL_GET)
+ return NULL;
- page = pte_page(*(pte_t *)pud);
- if (page)
- page += ((address & ~PUD_MASK) >> PAGE_SHIFT);
- return page;
+ return pte_page(*(pte_t *)pud) + ((address & ~PUD_MASK) >> PAGE_SHIFT);
}
#else /* !CONFIG_ARCH_WANT_GENERAL_HUGETLB */
diff --git a/mm/migrate.c b/mm/migrate.c
index 0bba97914af0..f6296904a324 100644
--- a/mm/migrate.c
+++ b/mm/migrate.c
@@ -229,7 +229,7 @@ static void remove_migration_ptes(struct page *old, struct page *new)
* get to the page and wait until migration is finished.
* When we return from this function the fault will be retried.
*/
-static void __migration_entry_wait(struct mm_struct *mm, pte_t *ptep,
+void __migration_entry_wait(struct mm_struct *mm, pte_t *ptep,
spinlock_t *ptl)
{
pte_t pte;
@@ -1274,7 +1274,8 @@ static int do_move_page_to_node_array(struct mm_struct *mm,
goto put_and_set;
if (PageHuge(page)) {
- isolate_huge_page(page, &pagelist);
+ if (PageHead(page))
+ isolate_huge_page(page, &pagelist);
goto put_and_set;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 100/183] mm/hugetlb: fix getting refcount 0 page in hugetlb_fault()
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (98 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 099/183] mm/hugetlb: take page table lock in follow_huge_pmd() Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 101/183] mm/hugetlb: add migration/hwpoisoned entry check in hugetlb_change_protection Luis Henriques
` (82 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Naoya Horiguchi, Hugh Dickins, James Hogan, David Rientjes,
Mel Gorman, Johannes Weiner, Michal Hocko, Rik van Riel,
Andrea Arcangeli, Luiz Capitulino, Nishanth Aravamudan,
Lee Schermerhorn, Steve Capper, Andrew Morton, Linus Torvalds,
Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
commit 0f792cf949a0be506c2aa8bfac0605746b146dda upstream.
When running the test which causes the race as shown in the previous patch,
we can hit the BUG "get_page() on refcount 0 page" in hugetlb_fault().
This race happens when pte turns into migration entry just after the first
check of is_hugetlb_entry_migration() in hugetlb_fault() passed with false.
To fix this, we need to check pte_present() again after huge_ptep_get().
This patch also reorders taking ptl and doing pte_page(), because
pte_page() should be done in ptl. Due to this reordering, we need use
trylock_page() in page != pagecache_page case to respect locking order.
Fixes: 66aebce747ea ("hugetlb: fix race condition in hugetlb_fault()")
Signed-off-by: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: James Hogan <james.hogan@imgtec.com>
Cc: David Rientjes <rientjes@google.com>
Cc: Mel Gorman <mel@csn.ul.ie>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Michal Hocko <mhocko@suse.cz>
Cc: Rik van Riel <riel@redhat.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Luiz Capitulino <lcapitulino@redhat.com>
Cc: Nishanth Aravamudan <nacc@linux.vnet.ibm.com>
Cc: Lee Schermerhorn <lee.schermerhorn@hp.com>
Cc: Steve Capper <steve.capper@linaro.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
mm/hugetlb.c | 52 ++++++++++++++++++++++++++++++++++++----------------
1 file changed, 36 insertions(+), 16 deletions(-)
diff --git a/mm/hugetlb.c b/mm/hugetlb.c
index 0f03a4a79942..9508a818f496 100644
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -3142,6 +3142,7 @@ int hugetlb_fault(struct mm_struct *mm, struct vm_area_struct *vma,
struct page *pagecache_page = NULL;
struct hstate *h = hstate_vma(vma);
struct address_space *mapping;
+ int need_wait_lock = 0;
address &= huge_page_mask(h);
@@ -3180,6 +3181,16 @@ int hugetlb_fault(struct mm_struct *mm, struct vm_area_struct *vma,
ret = 0;
/*
+ * entry could be a migration/hwpoison entry at this point, so this
+ * check prevents the kernel from going below assuming that we have
+ * a active hugepage in pagecache. This goto expects the 2nd page fault,
+ * and is_hugetlb_entry_(migration|hwpoisoned) check will properly
+ * handle it.
+ */
+ if (!pte_present(entry))
+ goto out_mutex;
+
+ /*
* If we are going to COW the mapping later, we examine the pending
* reservations for this page now. This will ensure that any
* allocations necessary to record that reservation occur outside the
@@ -3198,30 +3209,31 @@ int hugetlb_fault(struct mm_struct *mm, struct vm_area_struct *vma,
vma, address);
}
+ ptl = huge_pte_lock(h, mm, ptep);
+
+ /* Check for a racing update before calling hugetlb_cow */
+ if (unlikely(!pte_same(entry, huge_ptep_get(ptep))))
+ goto out_ptl;
+
/*
* hugetlb_cow() requires page locks of pte_page(entry) and
* pagecache_page, so here we need take the former one
* when page != pagecache_page or !pagecache_page.
- * Note that locking order is always pagecache_page -> page,
- * so no worry about deadlock.
*/
page = pte_page(entry);
- get_page(page);
if (page != pagecache_page)
- lock_page(page);
-
- ptl = huge_pte_lockptr(h, mm, ptep);
- spin_lock(ptl);
- /* Check for a racing update before calling hugetlb_cow */
- if (unlikely(!pte_same(entry, huge_ptep_get(ptep))))
- goto out_ptl;
+ if (!trylock_page(page)) {
+ need_wait_lock = 1;
+ goto out_ptl;
+ }
+ get_page(page);
if (flags & FAULT_FLAG_WRITE) {
if (!huge_pte_write(entry)) {
ret = hugetlb_cow(mm, vma, address, ptep, entry,
pagecache_page, ptl);
- goto out_ptl;
+ goto out_put_page;
}
entry = huge_pte_mkdirty(entry);
}
@@ -3229,7 +3241,10 @@ int hugetlb_fault(struct mm_struct *mm, struct vm_area_struct *vma,
if (huge_ptep_set_access_flags(vma, address, ptep, entry,
flags & FAULT_FLAG_WRITE))
update_mmu_cache(vma, address, ptep);
-
+out_put_page:
+ if (page != pagecache_page)
+ unlock_page(page);
+ put_page(page);
out_ptl:
spin_unlock(ptl);
@@ -3237,12 +3252,17 @@ out_ptl:
unlock_page(pagecache_page);
put_page(pagecache_page);
}
- if (page != pagecache_page)
- unlock_page(page);
- put_page(page);
-
out_mutex:
mutex_unlock(&htlb_fault_mutex_table[hash]);
+ /*
+ * Generally it's safe to hold refcount during waiting page lock. But
+ * here we just wait to defer the next page fault to avoid busy loop and
+ * the page is not used after unlocked before returning from the current
+ * page fault. So we are safe from accessing freed page, even if we wait
+ * here without taking refcount.
+ */
+ if (need_wait_lock)
+ wait_on_page_locked(page);
return ret;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 101/183] mm/hugetlb: add migration/hwpoisoned entry check in hugetlb_change_protection
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (99 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 100/183] mm/hugetlb: fix getting refcount 0 page in hugetlb_fault() Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 102/183] mm/hugetlb: add migration entry check in __unmap_hugepage_range Luis Henriques
` (81 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Naoya Horiguchi, Hugh Dickins, James Hogan, David Rientjes,
Mel Gorman, Johannes Weiner, Michal Hocko, Rik van Riel,
Andrea Arcangeli, Luiz Capitulino, Nishanth Aravamudan,
Lee Schermerhorn, Steve Capper, Andrew Morton, Linus Torvalds,
Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
commit a8bda28d87c38c6aa93de28ba5d30cc18e865a11 upstream.
There is a race condition between hugepage migration and
change_protection(), where hugetlb_change_protection() doesn't care about
migration entries and wrongly overwrites them. That causes unexpected
results like kernel crash. HWPoison entries also can cause the same
problem.
This patch adds is_hugetlb_entry_(migration|hwpoisoned) check in this
function to do proper actions.
Fixes: 290408d4a2 ("hugetlb: hugepage migration core")
Signed-off-by: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: James Hogan <james.hogan@imgtec.com>
Cc: David Rientjes <rientjes@google.com>
Cc: Mel Gorman <mel@csn.ul.ie>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Michal Hocko <mhocko@suse.cz>
Cc: Rik van Riel <riel@redhat.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Luiz Capitulino <lcapitulino@redhat.com>
Cc: Nishanth Aravamudan <nacc@linux.vnet.ibm.com>
Cc: Lee Schermerhorn <lee.schermerhorn@hp.com>
Cc: Steve Capper <steve.capper@linaro.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
mm/hugetlb.c | 21 ++++++++++++++++++++-
1 file changed, 20 insertions(+), 1 deletion(-)
diff --git a/mm/hugetlb.c b/mm/hugetlb.c
index 9508a818f496..5aab37914cbd 100644
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -3392,7 +3392,26 @@ unsigned long hugetlb_change_protection(struct vm_area_struct *vma,
spin_unlock(ptl);
continue;
}
- if (!huge_pte_none(huge_ptep_get(ptep))) {
+ pte = huge_ptep_get(ptep);
+ if (unlikely(is_hugetlb_entry_hwpoisoned(pte))) {
+ spin_unlock(ptl);
+ continue;
+ }
+ if (unlikely(is_hugetlb_entry_migration(pte))) {
+ swp_entry_t entry = pte_to_swp_entry(pte);
+
+ if (is_write_migration_entry(entry)) {
+ pte_t newpte;
+
+ make_migration_entry_read(&entry);
+ newpte = swp_entry_to_pte(entry);
+ set_huge_pte_at(mm, address, ptep, newpte);
+ pages++;
+ }
+ spin_unlock(ptl);
+ continue;
+ }
+ if (!huge_pte_none(pte)) {
pte = huge_ptep_get_and_clear(mm, address, ptep);
pte = pte_mkhuge(huge_pte_modify(pte, newprot));
pte = arch_make_huge_pte(pte, vma, NULL, 0);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 102/183] mm/hugetlb: add migration entry check in __unmap_hugepage_range
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (100 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 101/183] mm/hugetlb: add migration/hwpoisoned entry check in hugetlb_change_protection Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 103/183] mm: when stealing freepages, also take pages created by splitting buddy page Luis Henriques
` (80 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Naoya Horiguchi, Hugh Dickins, James Hogan, David Rientjes,
Mel Gorman, Johannes Weiner, Michal Hocko, Rik van Riel,
Andrea Arcangeli, Luiz Capitulino, Nishanth Aravamudan,
Lee Schermerhorn, Steve Capper, Andrew Morton, Linus Torvalds,
Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
commit 9fbc1f635fd0bd28cb32550211bf095753ac637a upstream.
If __unmap_hugepage_range() tries to unmap the address range over which
hugepage migration is on the way, we get the wrong page because pte_page()
doesn't work for migration entries. This patch simply clears the pte for
migration entries as we do for hwpoison entries.
Fixes: 290408d4a2 ("hugetlb: hugepage migration core")
Signed-off-by: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: James Hogan <james.hogan@imgtec.com>
Cc: David Rientjes <rientjes@google.com>
Cc: Mel Gorman <mel@csn.ul.ie>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Michal Hocko <mhocko@suse.cz>
Cc: Rik van Riel <riel@redhat.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Luiz Capitulino <lcapitulino@redhat.com>
Cc: Nishanth Aravamudan <nacc@linux.vnet.ibm.com>
Cc: Lee Schermerhorn <lee.schermerhorn@hp.com>
Cc: Steve Capper <steve.capper@linaro.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
mm/hugetlb.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/mm/hugetlb.c b/mm/hugetlb.c
index 5aab37914cbd..5f217e906ff9 100644
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -2660,9 +2660,10 @@ again:
goto unlock;
/*
- * HWPoisoned hugepage is already unmapped and dropped reference
+ * Migrating hugepage or HWPoisoned hugepage is already
+ * unmapped and its refcount is dropped, so just clear pte here.
*/
- if (unlikely(is_hugetlb_entry_hwpoisoned(pte))) {
+ if (unlikely(!pte_present(pte))) {
huge_pte_clear(mm, address, ptep);
goto unlock;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 103/183] mm: when stealing freepages, also take pages created by splitting buddy page
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (101 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 102/183] mm/hugetlb: add migration entry check in __unmap_hugepage_range Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 104/183] mm/mmap.c: fix arithmetic overflow in __vm_enough_memory() Luis Henriques
` (79 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Vlastimil Babka, Zhang Yanfei, David Rientjes, Rik van Riel,
Aneesh Kumar K.V, Kirill A. Shutemov, Johannes Weiner,
Joonsoo Kim, Michal Hocko, KOSAKI Motohiro, Andrew Morton,
Linus Torvalds, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Vlastimil Babka <vbabka@suse.cz>
commit 99592d598eca62bdbbf62b59941c189176dfc614 upstream.
When studying page stealing, I noticed some weird looking decisions in
try_to_steal_freepages(). The first I assume is a bug (Patch 1), the
following two patches were driven by evaluation.
Testing was done with stress-highalloc of mmtests, using the
mm_page_alloc_extfrag tracepoint and postprocessing to get counts of how
often page stealing occurs for individual migratetypes, and what
migratetypes are used for fallbacks. Arguably, the worst case of page
stealing is when UNMOVABLE allocation steals from MOVABLE pageblock.
RECLAIMABLE allocation stealing from MOVABLE allocation is also not ideal,
so the goal is to minimize these two cases.
The evaluation of v2 wasn't always clear win and Joonsoo questioned the
results. Here I used different baseline which includes RFC compaction
improvements from [1]. I found that the compaction improvements reduce
variability of stress-highalloc, so there's less noise in the data.
First, let's look at stress-highalloc configured to do sync compaction,
and how these patches reduce page stealing events during the test. First
column is after fresh reboot, other two are reiterations of test without
reboot. That was all accumulater over 5 re-iterations (so the benchmark
was run 5x3 times with 5 fresh restarts).
Baseline:
3.19-rc4 3.19-rc4 3.19-rc4
5-nothp-1 5-nothp-2 5-nothp-3
Page alloc extfrag event 10264225 8702233 10244125
Extfrag fragmenting 10263271 8701552 10243473
Extfrag fragmenting for unmovable 13595 17616 15960
Extfrag fragmenting unmovable placed with movable 7989 12193 8447
Extfrag fragmenting for reclaimable 658 1840 1817
Extfrag fragmenting reclaimable placed with movable 558 1677 1679
Extfrag fragmenting for movable 10249018 8682096 10225696
With Patch 1:
3.19-rc4 3.19-rc4 3.19-rc4
6-nothp-1 6-nothp-2 6-nothp-3
Page alloc extfrag event 11834954 9877523 9774860
Extfrag fragmenting 11833993 9876880 9774245
Extfrag fragmenting for unmovable 7342 16129 11712
Extfrag fragmenting unmovable placed with movable 4191 10547 6270
Extfrag fragmenting for reclaimable 373 1130 923
Extfrag fragmenting reclaimable placed with movable 302 906 738
Extfrag fragmenting for movable 11826278 9859621 9761610
With Patch 2:
3.19-rc4 3.19-rc4 3.19-rc4
7-nothp-1 7-nothp-2 7-nothp-3
Page alloc extfrag event 4725990 3668793 3807436
Extfrag fragmenting 4725104 3668252 3806898
Extfrag fragmenting for unmovable 6678 7974 7281
Extfrag fragmenting unmovable placed with movable 2051 3829 4017
Extfrag fragmenting for reclaimable 429 1208 1278
Extfrag fragmenting reclaimable placed with movable 369 976 1034
Extfrag fragmenting for movable 4717997 3659070 3798339
With Patch 3:
3.19-rc4 3.19-rc4 3.19-rc4
8-nothp-1 8-nothp-2 8-nothp-3
Page alloc extfrag event 5016183 4700142 3850633
Extfrag fragmenting 5015325 4699613 3850072
Extfrag fragmenting for unmovable 1312 3154 3088
Extfrag fragmenting unmovable placed with movable 1115 2777 2714
Extfrag fragmenting for reclaimable 437 1193 1097
Extfrag fragmenting reclaimable placed with movable 330 969 879
Extfrag fragmenting for movable 5013576 4695266 3845887
In v2 we've seen apparent regression with Patch 1 for unmovable events,
this is now gone, suggesting it was indeed noise. Here, each patch
improves the situation for unmovable events. Reclaimable is improved by
patch 1 and then either the same modulo noise, or perhaps sligtly worse -
a small price for unmovable improvements, IMHO. The number of movable
allocations falling back to other migratetypes is most noisy, but it's
reduced to half at Patch 2 nevertheless. These are least critical as
compaction can move them around.
If we look at success rates, the patches don't affect them, that didn't change.
Baseline:
3.19-rc4 3.19-rc4 3.19-rc4
5-nothp-1 5-nothp-2 5-nothp-3
Success 1 Min 49.00 ( 0.00%) 42.00 ( 14.29%) 41.00 ( 16.33%)
Success 1 Mean 51.00 ( 0.00%) 45.00 ( 11.76%) 42.60 ( 16.47%)
Success 1 Max 55.00 ( 0.00%) 51.00 ( 7.27%) 46.00 ( 16.36%)
Success 2 Min 53.00 ( 0.00%) 47.00 ( 11.32%) 44.00 ( 16.98%)
Success 2 Mean 59.60 ( 0.00%) 50.80 ( 14.77%) 48.20 ( 19.13%)
Success 2 Max 64.00 ( 0.00%) 56.00 ( 12.50%) 52.00 ( 18.75%)
Success 3 Min 84.00 ( 0.00%) 82.00 ( 2.38%) 78.00 ( 7.14%)
Success 3 Mean 85.60 ( 0.00%) 82.80 ( 3.27%) 79.40 ( 7.24%)
Success 3 Max 86.00 ( 0.00%) 83.00 ( 3.49%) 80.00 ( 6.98%)
Patch 1:
3.19-rc4 3.19-rc4 3.19-rc4
6-nothp-1 6-nothp-2 6-nothp-3
Success 1 Min 49.00 ( 0.00%) 44.00 ( 10.20%) 44.00 ( 10.20%)
Success 1 Mean 51.80 ( 0.00%) 46.00 ( 11.20%) 45.80 ( 11.58%)
Success 1 Max 54.00 ( 0.00%) 49.00 ( 9.26%) 49.00 ( 9.26%)
Success 2 Min 58.00 ( 0.00%) 49.00 ( 15.52%) 48.00 ( 17.24%)
Success 2 Mean 60.40 ( 0.00%) 51.80 ( 14.24%) 50.80 ( 15.89%)
Success 2 Max 63.00 ( 0.00%) 54.00 ( 14.29%) 55.00 ( 12.70%)
Success 3 Min 84.00 ( 0.00%) 81.00 ( 3.57%) 79.00 ( 5.95%)
Success 3 Mean 85.00 ( 0.00%) 81.60 ( 4.00%) 79.80 ( 6.12%)
Success 3 Max 86.00 ( 0.00%) 82.00 ( 4.65%) 82.00 ( 4.65%)
Patch 2:
3.19-rc4 3.19-rc4 3.19-rc4
7-nothp-1 7-nothp-2 7-nothp-3
Success 1 Min 50.00 ( 0.00%) 44.00 ( 12.00%) 39.00 ( 22.00%)
Success 1 Mean 52.80 ( 0.00%) 45.60 ( 13.64%) 42.40 ( 19.70%)
Success 1 Max 55.00 ( 0.00%) 46.00 ( 16.36%) 47.00 ( 14.55%)
Success 2 Min 52.00 ( 0.00%) 48.00 ( 7.69%) 45.00 ( 13.46%)
Success 2 Mean 53.40 ( 0.00%) 49.80 ( 6.74%) 48.80 ( 8.61%)
Success 2 Max 57.00 ( 0.00%) 52.00 ( 8.77%) 52.00 ( 8.77%)
Success 3 Min 84.00 ( 0.00%) 81.00 ( 3.57%) 79.00 ( 5.95%)
Success 3 Mean 85.00 ( 0.00%) 82.40 ( 3.06%) 79.60 ( 6.35%)
Success 3 Max 86.00 ( 0.00%) 83.00 ( 3.49%) 80.00 ( 6.98%)
Patch 3:
3.19-rc4 3.19-rc4 3.19-rc4
8-nothp-1 8-nothp-2 8-nothp-3
Success 1 Min 46.00 ( 0.00%) 44.00 ( 4.35%) 42.00 ( 8.70%)
Success 1 Mean 50.20 ( 0.00%) 45.60 ( 9.16%) 44.00 ( 12.35%)
Success 1 Max 52.00 ( 0.00%) 47.00 ( 9.62%) 47.00 ( 9.62%)
Success 2 Min 53.00 ( 0.00%) 49.00 ( 7.55%) 48.00 ( 9.43%)
Success 2 Mean 55.80 ( 0.00%) 50.60 ( 9.32%) 49.00 ( 12.19%)
Success 2 Max 59.00 ( 0.00%) 52.00 ( 11.86%) 51.00 ( 13.56%)
Success 3 Min 84.00 ( 0.00%) 80.00 ( 4.76%) 79.00 ( 5.95%)
Success 3 Mean 85.40 ( 0.00%) 81.60 ( 4.45%) 80.40 ( 5.85%)
Success 3 Max 87.00 ( 0.00%) 83.00 ( 4.60%) 82.00 ( 5.75%)
While there's no improvement here, I consider reduced fragmentation events
to be worth on its own. Patch 2 also seems to reduce scanning for free
pages, and migrations in compaction, suggesting it has somewhat less work
to do:
Patch 1:
Compaction stalls 4153 3959 3978
Compaction success 1523 1441 1446
Compaction failures 2630 2517 2531
Page migrate success 4600827 4943120 5104348
Page migrate failure 19763 16656 17806
Compaction pages isolated 9597640 10305617 10653541
Compaction migrate scanned 77828948 86533283 87137064
Compaction free scanned 517758295 521312840 521462251
Compaction cost 5503 5932 6110
Patch 2:
Compaction stalls 3800 3450 3518
Compaction success 1421 1316 1317
Compaction failures 2379 2134 2201
Page migrate success 4160421 4502708 4752148
Page migrate failure 19705 14340 14911
Compaction pages isolated 8731983 9382374 9910043
Compaction migrate scanned 98362797 96349194 98609686
Compaction free scanned 496512560 469502017 480442545
Compaction cost 5173 5526 5811
As with v2, /proc/pagetypeinfo appears unaffected with respect to numbers
of unmovable and reclaimable pageblocks.
Configuring the benchmark to allocate like THP page fault (i.e. no sync
compaction) gives much noisier results for iterations 2 and 3 after
reboot. This is not so surprising given how [1] offers lower improvements
in this scenario due to less restarts after deferred compaction which
would change compaction pivot.
Baseline:
3.19-rc4 3.19-rc4 3.19-rc4
5-thp-1 5-thp-2 5-thp-3
Page alloc extfrag event 8148965 6227815 6646741
Extfrag fragmenting 8147872 6227130 6646117
Extfrag fragmenting for unmovable 10324 12942 15975
Extfrag fragmenting unmovable placed with movable 5972 8495 10907
Extfrag fragmenting for reclaimable 601 1707 2210
Extfrag fragmenting reclaimable placed with movable 520 1570 2000
Extfrag fragmenting for movable 8136947 6212481 6627932
Patch 1:
3.19-rc4 3.19-rc4 3.19-rc4
6-thp-1 6-thp-2 6-thp-3
Page alloc extfrag event 8345457 7574471 7020419
Extfrag fragmenting 8343546 7573777 7019718
Extfrag fragmenting for unmovable 10256 18535 30716
Extfrag fragmenting unmovable placed with movable 6893 11726 22181
Extfrag fragmenting for reclaimable 465 1208 1023
Extfrag fragmenting reclaimable placed with movable 353 996 843
Extfrag fragmenting for movable 8332825 7554034 6987979
Patch 2:
3.19-rc4 3.19-rc4 3.19-rc4
7-thp-1 7-thp-2 7-thp-3
Page alloc extfrag event 3512847 3020756 2891625
Extfrag fragmenting 3511940 3020185 2891059
Extfrag fragmenting for unmovable 9017 6892 6191
Extfrag fragmenting unmovable placed with movable 1524 3053 2435
Extfrag fragmenting for reclaimable 445 1081 1160
Extfrag fragmenting reclaimable placed with movable 375 918 986
Extfrag fragmenting for movable 3502478 3012212 2883708
Patch 3:
3.19-rc4 3.19-rc4 3.19-rc4
8-thp-1 8-thp-2 8-thp-3
Page alloc extfrag event 3181699 3082881 2674164
Extfrag fragmenting 3180812 3082303 2673611
Extfrag fragmenting for unmovable 1201 4031 4040
Extfrag fragmenting unmovable placed with movable 974 3611 3645
Extfrag fragmenting for reclaimable 478 1165 1294
Extfrag fragmenting reclaimable placed with movable 387 985 1030
Extfrag fragmenting for movable 3179133 3077107 2668277
The improvements for first iteration are clear, the rest is much noisier
and can appear like regression for Patch 1. Anyway, patch 2 rectifies it.
Allocation success rates are again unaffected so there's no point in
making this e-mail any longer.
[1] http://marc.info/?l=linux-mm&m=142166196321125&w=2
This patch (of 3):
When __rmqueue_fallback() is called to allocate a page of order X, it will
find a page of order Y >= X of a fallback migratetype, which is different
from the desired migratetype. With the help of try_to_steal_freepages(),
it may change the migratetype (to the desired one) also of:
1) all currently free pages in the pageblock containing the fallback page
2) the fallback pageblock itself
3) buddy pages created by splitting the fallback page (when Y > X)
These decisions take the order Y into account, as well as the desired
migratetype, with the goal of preventing multiple fallback allocations
that could e.g. distribute UNMOVABLE allocations among multiple
pageblocks.
Originally, decision for 1) has implied the decision for 3). Commit
47118af076f6 ("mm: mmzone: MIGRATE_CMA migration type added") changed that
(probably unintentionally) so that the buddy pages in case 3) are always
changed to the desired migratetype, except for CMA pageblocks.
Commit fef903efcf0c ("mm/page_allo.c: restructure free-page stealing code
and fix a bug") did some refactoring and added a comment that the case of
3) is intended. Commit 0cbef29a7821 ("mm: __rmqueue_fallback() should
respect pageblock type") removed the comment and tried to restore the
original behavior where 1) implies 3), but due to the previous
refactoring, the result is instead that only 2) implies 3) - and the
conditions for 2) are less frequently met than conditions for 1). This
may increase fragmentation in situations where the code decides to steal
all free pages from the pageblock (case 1)), but then gives back the buddy
pages produced by splitting.
This patch restores the original intended logic where 1) implies 3).
During testing with stress-highalloc from mmtests, this has shown to
decrease the number of events where UNMOVABLE and RECLAIMABLE allocations
steal from MOVABLE pageblocks, which can lead to permanent fragmentation.
In some cases it has increased the number of events when MOVABLE
allocations steal from UNMOVABLE or RECLAIMABLE pageblocks, but these are
fixable by sync compaction and thus less harmful.
Note that evaluation has shown that the behavior introduced by
47118af076f6 for buddy pages in case 3) is actually even better than the
original logic, so the following patch will introduce it properly once
again. For stable backports of this patch it makes thus sense to only fix
versions containing 0cbef29a7821.
[iamjoonsoo.kim@lge.com: tracepoint fix]
Signed-off-by: Vlastimil Babka <vbabka@suse.cz>
Acked-by: Mel Gorman <mgorman@suse.de>
Cc: Zhang Yanfei <zhangyanfei@cn.fujitsu.com>
Acked-by: Minchan Kim <minchan@kernel.org>
Cc: David Rientjes <rientjes@google.com>
Cc: Rik van Riel <riel@redhat.com>
Cc: "Aneesh Kumar K.V" <aneesh.kumar@linux.vnet.ibm.com>
Cc: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Joonsoo Kim <iamjoonsoo.kim@lge.com>
Cc: Michal Hocko <mhocko@suse.cz>
Cc: KOSAKI Motohiro <kosaki.motohiro@jp.fujitsu.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
include/trace/events/kmem.h | 7 ++++---
mm/page_alloc.c | 12 +++++-------
2 files changed, 9 insertions(+), 10 deletions(-)
diff --git a/include/trace/events/kmem.h b/include/trace/events/kmem.h
index aece1346ceb7..4ad10baecd4d 100644
--- a/include/trace/events/kmem.h
+++ b/include/trace/events/kmem.h
@@ -268,11 +268,11 @@ TRACE_EVENT(mm_page_alloc_extfrag,
TP_PROTO(struct page *page,
int alloc_order, int fallback_order,
- int alloc_migratetype, int fallback_migratetype, int new_migratetype),
+ int alloc_migratetype, int fallback_migratetype),
TP_ARGS(page,
alloc_order, fallback_order,
- alloc_migratetype, fallback_migratetype, new_migratetype),
+ alloc_migratetype, fallback_migratetype),
TP_STRUCT__entry(
__field( struct page *, page )
@@ -289,7 +289,8 @@ TRACE_EVENT(mm_page_alloc_extfrag,
__entry->fallback_order = fallback_order;
__entry->alloc_migratetype = alloc_migratetype;
__entry->fallback_migratetype = fallback_migratetype;
- __entry->change_ownership = (new_migratetype == alloc_migratetype);
+ __entry->change_ownership = (alloc_migratetype ==
+ get_pageblock_migratetype(page));
),
TP_printk("page=%p pfn=%lu alloc_order=%d fallback_order=%d pageblock_order=%d alloc_migratetype=%d fallback_migratetype=%d fragmenting=%d change_ownership=%d",
diff --git a/mm/page_alloc.c b/mm/page_alloc.c
index 8f4ba9ae030f..9ddea0200c94 100644
--- a/mm/page_alloc.c
+++ b/mm/page_alloc.c
@@ -1077,8 +1077,8 @@ static void change_pageblock_range(struct page *pageblock_page,
* nor move CMA pages to different free lists. We don't want unmovable pages
* to be allocated from MIGRATE_CMA areas.
*
- * Returns the new migratetype of the pageblock (or the same old migratetype
- * if it was unchanged).
+ * Returns the allocation migratetype if free pages were stolen, or the
+ * fallback migratetype if it was decided not to steal.
*/
static int try_to_steal_freepages(struct zone *zone, struct page *page,
int start_type, int fallback_type)
@@ -1109,12 +1109,10 @@ static int try_to_steal_freepages(struct zone *zone, struct page *page,
/* Claim the whole block if over half of it is free */
if (pages >= (1 << (pageblock_order-1)) ||
- page_group_by_mobility_disabled) {
-
+ page_group_by_mobility_disabled)
set_pageblock_migratetype(page, start_type);
- return start_type;
- }
+ return start_type;
}
return fallback_type;
@@ -1166,7 +1164,7 @@ __rmqueue_fallback(struct zone *zone, unsigned int order, int start_migratetype)
set_freepage_migratetype(page, new_type);
trace_mm_page_alloc_extfrag(page, order, current_order,
- start_migratetype, migratetype, new_type);
+ start_migratetype, migratetype);
return page;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 104/183] mm/mmap.c: fix arithmetic overflow in __vm_enough_memory()
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (102 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 103/183] mm: when stealing freepages, also take pages created by splitting buddy page Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 105/183] mm/nommu.c: " Luis Henriques
` (78 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Roman Gushchin, Andrew Shewmaker, Rik van Riel,
Konstantin Khlebnikov, Andrew Morton, Linus Torvalds,
Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Roman Gushchin <klamm@yandex-team.ru>
commit 5703b087dc8eaf47bfb399d6cf512d471beff405 upstream.
I noticed, that "allowed" can easily overflow by falling below 0,
because (total_vm / 32) can be larger than "allowed". The problem
occurs in OVERCOMMIT_NONE mode.
In this case, a huge allocation can success and overcommit the system
(despite OVERCOMMIT_NONE mode). All subsequent allocations will fall
(system-wide), so system become unusable.
The problem was masked out by commit c9b1d0981fcc
("mm: limit growth of 3% hardcoded other user reserve"),
but it's easy to reproduce it on older kernels:
1) set overcommit_memory sysctl to 2
2) mmap() large file multiple times (with VM_SHARED flag)
3) try to malloc() large amount of memory
It also can be reproduced on newer kernels, but miss-configured
sysctl_user_reserve_kbytes is required.
Fix this issue by switching to signed arithmetic here.
[akpm@linux-foundation.org: use min_t]
Signed-off-by: Roman Gushchin <klamm@yandex-team.ru>
Cc: Andrew Shewmaker <agshew@gmail.com>
Cc: Rik van Riel <riel@redhat.com>
Cc: Konstantin Khlebnikov <khlebnikov@yandex-team.ru>
Reviewed-by: Michal Hocko <mhocko@suse.cz>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
mm/mmap.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/mm/mmap.c b/mm/mmap.c
index 5f0712551402..38dec592f496 100644
--- a/mm/mmap.c
+++ b/mm/mmap.c
@@ -132,7 +132,7 @@ EXPORT_SYMBOL_GPL(vm_memory_committed);
*/
int __vm_enough_memory(struct mm_struct *mm, long pages, int cap_sys_admin)
{
- unsigned long free, allowed, reserve;
+ long free, allowed, reserve;
vm_acct_memory(pages);
@@ -196,7 +196,7 @@ int __vm_enough_memory(struct mm_struct *mm, long pages, int cap_sys_admin)
*/
if (mm) {
reserve = sysctl_user_reserve_kbytes >> (PAGE_SHIFT - 10);
- allowed -= min(mm->total_vm / 32, reserve);
+ allowed -= min_t(long, mm->total_vm / 32, reserve);
}
if (percpu_counter_read_positive(&vm_committed_as) < allowed)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 105/183] mm/nommu.c: fix arithmetic overflow in __vm_enough_memory()
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (103 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 104/183] mm/mmap.c: fix arithmetic overflow in __vm_enough_memory() Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 106/183] iscsi-target: Drop problematic active_ts_list usage Luis Henriques
` (77 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Roman Gushchin, Andrew Shewmaker, Rik van Riel,
Konstantin Khlebnikov, Andrew Morton, Linus Torvalds,
Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Roman Gushchin <klamm@yandex-team.ru>
commit 8138a67a5557ffea3a21dfd6f037842d4e748513 upstream.
I noticed that "allowed" can easily overflow by falling below 0, because
(total_vm / 32) can be larger than "allowed". The problem occurs in
OVERCOMMIT_NONE mode.
In this case, a huge allocation can success and overcommit the system
(despite OVERCOMMIT_NONE mode). All subsequent allocations will fall
(system-wide), so system become unusable.
The problem was masked out by commit c9b1d0981fcc
("mm: limit growth of 3% hardcoded other user reserve"),
but it's easy to reproduce it on older kernels:
1) set overcommit_memory sysctl to 2
2) mmap() large file multiple times (with VM_SHARED flag)
3) try to malloc() large amount of memory
It also can be reproduced on newer kernels, but miss-configured
sysctl_user_reserve_kbytes is required.
Fix this issue by switching to signed arithmetic here.
Signed-off-by: Roman Gushchin <klamm@yandex-team.ru>
Cc: Andrew Shewmaker <agshew@gmail.com>
Cc: Rik van Riel <riel@redhat.com>
Cc: Konstantin Khlebnikov <khlebnikov@yandex-team.ru>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
mm/nommu.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/mm/nommu.c b/mm/nommu.c
index 4a852f6c5709..2991b074aeae 100644
--- a/mm/nommu.c
+++ b/mm/nommu.c
@@ -1905,7 +1905,7 @@ EXPORT_SYMBOL(unmap_mapping_range);
*/
int __vm_enough_memory(struct mm_struct *mm, long pages, int cap_sys_admin)
{
- unsigned long free, allowed, reserve;
+ long free, allowed, reserve;
vm_acct_memory(pages);
@@ -1969,7 +1969,7 @@ int __vm_enough_memory(struct mm_struct *mm, long pages, int cap_sys_admin)
*/
if (mm) {
reserve = sysctl_user_reserve_kbytes >> (PAGE_SHIFT - 10);
- allowed -= min(mm->total_vm / 32, reserve);
+ allowed -= min_t(long, mm->total_vm / 32, reserve);
}
if (percpu_counter_read_positive(&vm_committed_as) < allowed)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 106/183] iscsi-target: Drop problematic active_ts_list usage
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (104 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 105/183] mm/nommu.c: " Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 107/183] target: Fix PR_APTPL_BUF_LEN buffer size limitation Luis Henriques
` (76 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Nicholas Bellinger, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicholas Bellinger <nab@linux-iscsi.org>
commit 3fd7b60f2c7418239d586e359e0c6d8503e10646 upstream.
This patch drops legacy active_ts_list usage within iscsi_target_tq.c
code. It was originally used to track the active thread sets during
iscsi-target shutdown, and is no longer used by modern upstream code.
Two people have reported list corruption using traditional iscsi-target
and iser-target with the following backtrace, that appears to be related
to iscsi_thread_set->ts_list being used across both active_ts_list and
inactive_ts_list.
[ 60.782534] ------------[ cut here ]------------
[ 60.782543] WARNING: CPU: 0 PID: 9430 at lib/list_debug.c:53 __list_del_entry+0x63/0xd0()
[ 60.782545] list_del corruption, ffff88045b00d180->next is LIST_POISON1 (dead000000100100)
[ 60.782546] Modules linked in: ib_srpt tcm_qla2xxx qla2xxx tcm_loop tcm_fc libfc scsi_transport_fc scsi_tgt ib_isert rdma_cm iw_cm ib_addr iscsi_target_mod target_core_pscsi target_core_file target_core_iblock target_core_mod configfs ebtable_nat ebtables ipt_MASQUERADE iptable_nat nf_nat_ipv4 nf_nat nf_conntrack_ipv4 nf_defrag_ipv4 ipt_REJECT xt_CHECKSUM iptable_mangle iptable_filter ip_tables bridge stp llc autofs4 sunrpc ip6t_REJECT nf_conntrack_ipv6 nf_defrag_ipv6 xt_state nf_conntrack ip6table_filter ip6_tables ipv6 ib_ipoib ib_cm ib_uverbs ib_umad mlx4_en mlx4_ib ib_sa ib_mad ib_core mlx4_core dm_mirror dm_region_hash dm_log dm_mod vhost_net macvtap macvlan vhost tun kvm_intel kvm uinput iTCO_wdt iTCO_vendor_support microcode serio_raw pcspkr sb_edac edac_core sg i2c_i801 lpc_ich mfd_core mtip32xx igb i2c_algo_bit i2c_core ptp pps_core ioatdma dca wmi ext3(F) jbd(F) mbcache(F) sd_mod(F) crc_t10dif(F) crct10dif_common(F) ahci(F) libahci(F) isci(F) libsas(F) scsi_transport_sas(F) [last unloaded: speedstep_lib]
[ 60.782597] CPU: 0 PID: 9430 Comm: iscsi_ttx Tainted: GF 3.12.19+ #2
[ 60.782598] Hardware name: Supermicro X9DRX+-F/X9DRX+-F, BIOS 3.00 07/09/2013
[ 60.782599] 0000000000000035 ffff88044de31d08 ffffffff81553ae7 0000000000000035
[ 60.782602] ffff88044de31d58 ffff88044de31d48 ffffffff8104d1cc 0000000000000002
[ 60.782605] ffff88045b00d180 ffff88045b00d0c0 ffff88045b00d0c0 ffff88044de31e58
[ 60.782607] Call Trace:
[ 60.782611] [<ffffffff81553ae7>] dump_stack+0x49/0x62
[ 60.782615] [<ffffffff8104d1cc>] warn_slowpath_common+0x8c/0xc0
[ 60.782618] [<ffffffff8104d2b6>] warn_slowpath_fmt+0x46/0x50
[ 60.782620] [<ffffffff81280933>] __list_del_entry+0x63/0xd0
[ 60.782622] [<ffffffff812809b1>] list_del+0x11/0x40
[ 60.782630] [<ffffffffa06e7cf9>] iscsi_del_ts_from_active_list+0x29/0x50 [iscsi_target_mod]
[ 60.782635] [<ffffffffa06e87b1>] iscsi_tx_thread_pre_handler+0xa1/0x180 [iscsi_target_mod]
[ 60.782642] [<ffffffffa06fb9ae>] iscsi_target_tx_thread+0x4e/0x220 [iscsi_target_mod]
[ 60.782647] [<ffffffffa06fb960>] ? iscsit_handle_snack+0x190/0x190 [iscsi_target_mod]
[ 60.782652] [<ffffffffa06fb960>] ? iscsit_handle_snack+0x190/0x190 [iscsi_target_mod]
[ 60.782655] [<ffffffff8106f99e>] kthread+0xce/0xe0
[ 60.782657] [<ffffffff8106f8d0>] ? kthread_freezable_should_stop+0x70/0x70
[ 60.782660] [<ffffffff8156026c>] ret_from_fork+0x7c/0xb0
[ 60.782662] [<ffffffff8106f8d0>] ? kthread_freezable_should_stop+0x70/0x70
[ 60.782663] ---[ end trace 9662f4a661d33965 ]---
Since this code is no longer used, go ahead and drop the problematic usage
all-together.
Reported-by: Gavin Guo <gavin.guo@canonical.com>
Reported-by: Moussa Ba <moussaba@micron.com>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/target/iscsi/iscsi_target_tq.c | 28 +++++-----------------------
1 file changed, 5 insertions(+), 23 deletions(-)
diff --git a/drivers/target/iscsi/iscsi_target_tq.c b/drivers/target/iscsi/iscsi_target_tq.c
index 601e9cc61e98..bb2890e79ca0 100644
--- a/drivers/target/iscsi/iscsi_target_tq.c
+++ b/drivers/target/iscsi/iscsi_target_tq.c
@@ -24,36 +24,22 @@
#include "iscsi_target_tq.h"
#include "iscsi_target.h"
-static LIST_HEAD(active_ts_list);
static LIST_HEAD(inactive_ts_list);
-static DEFINE_SPINLOCK(active_ts_lock);
static DEFINE_SPINLOCK(inactive_ts_lock);
static DEFINE_SPINLOCK(ts_bitmap_lock);
-static void iscsi_add_ts_to_active_list(struct iscsi_thread_set *ts)
-{
- spin_lock(&active_ts_lock);
- list_add_tail(&ts->ts_list, &active_ts_list);
- iscsit_global->active_ts++;
- spin_unlock(&active_ts_lock);
-}
-
static void iscsi_add_ts_to_inactive_list(struct iscsi_thread_set *ts)
{
+ if (!list_empty(&ts->ts_list)) {
+ WARN_ON(1);
+ return;
+ }
spin_lock(&inactive_ts_lock);
list_add_tail(&ts->ts_list, &inactive_ts_list);
iscsit_global->inactive_ts++;
spin_unlock(&inactive_ts_lock);
}
-static void iscsi_del_ts_from_active_list(struct iscsi_thread_set *ts)
-{
- spin_lock(&active_ts_lock);
- list_del(&ts->ts_list);
- iscsit_global->active_ts--;
- spin_unlock(&active_ts_lock);
-}
-
static struct iscsi_thread_set *iscsi_get_ts_from_inactive_list(void)
{
struct iscsi_thread_set *ts;
@@ -66,7 +52,7 @@ static struct iscsi_thread_set *iscsi_get_ts_from_inactive_list(void)
ts = list_first_entry(&inactive_ts_list, struct iscsi_thread_set, ts_list);
- list_del(&ts->ts_list);
+ list_del_init(&ts->ts_list);
iscsit_global->inactive_ts--;
spin_unlock(&inactive_ts_lock);
@@ -204,8 +190,6 @@ static void iscsi_deallocate_extra_thread_sets(void)
void iscsi_activate_thread_set(struct iscsi_conn *conn, struct iscsi_thread_set *ts)
{
- iscsi_add_ts_to_active_list(ts);
-
spin_lock_bh(&ts->ts_state_lock);
conn->thread_set = ts;
ts->conn = conn;
@@ -397,7 +381,6 @@ struct iscsi_conn *iscsi_rx_thread_pre_handler(struct iscsi_thread_set *ts)
if (ts->delay_inactive && (--ts->thread_count == 0)) {
spin_unlock_bh(&ts->ts_state_lock);
- iscsi_del_ts_from_active_list(ts);
if (!iscsit_global->in_shutdown)
iscsi_deallocate_extra_thread_sets();
@@ -452,7 +435,6 @@ struct iscsi_conn *iscsi_tx_thread_pre_handler(struct iscsi_thread_set *ts)
if (ts->delay_inactive && (--ts->thread_count == 0)) {
spin_unlock_bh(&ts->ts_state_lock);
- iscsi_del_ts_from_active_list(ts);
if (!iscsit_global->in_shutdown)
iscsi_deallocate_extra_thread_sets();
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 107/183] target: Fix PR_APTPL_BUF_LEN buffer size limitation
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (105 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 106/183] iscsi-target: Drop problematic active_ts_list usage Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 108/183] mm/compaction: fix wrong order check in compact_finished() Luis Henriques
` (75 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Nicholas Bellinger, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicholas Bellinger <nab@linux-iscsi.org>
commit f161d4b44d7cc1dc66b53365215227db356378b1 upstream.
This patch addresses the original PR_APTPL_BUF_LEN = 8k limitiation
for write-out of PR APTPL metadata that Martin has recently been
running into.
It changes core_scsi3_update_and_write_aptpl() to use vzalloc'ed
memory instead of kzalloc, and increases the default hardcoded
length to 256k.
It also adds logic in core_scsi3_update_and_write_aptpl() to double
the original length upon core_scsi3_update_aptpl_buf() failure, and
retries until the vzalloc'ed buffer is large enough to accommodate
the outgoing APTPL metadata.
Reported-by: Martin Svec <martin.svec@zoner.cz>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/target/target_core_pr.c | 25 +++++++++++++------------
include/target/target_core_base.h | 2 +-
2 files changed, 14 insertions(+), 13 deletions(-)
diff --git a/drivers/target/target_core_pr.c b/drivers/target/target_core_pr.c
index 1aadcfc9a8c1..d6d4d8b6c2a1 100644
--- a/drivers/target/target_core_pr.c
+++ b/drivers/target/target_core_pr.c
@@ -1877,8 +1877,8 @@ static int core_scsi3_update_aptpl_buf(
}
if ((len + strlen(tmp) >= pr_aptpl_buf_len)) {
- pr_err("Unable to update renaming"
- " APTPL metadata\n");
+ pr_err("Unable to update renaming APTPL metadata,"
+ " reallocating larger buffer\n");
ret = -EMSGSIZE;
goto out;
}
@@ -1895,8 +1895,8 @@ static int core_scsi3_update_aptpl_buf(
lun->lun_sep->sep_rtpi, lun->unpacked_lun, reg_count);
if ((len + strlen(tmp) >= pr_aptpl_buf_len)) {
- pr_err("Unable to update renaming"
- " APTPL metadata\n");
+ pr_err("Unable to update renaming APTPL metadata,"
+ " reallocating larger buffer\n");
ret = -EMSGSIZE;
goto out;
}
@@ -1959,7 +1959,7 @@ static int __core_scsi3_write_aptpl_to_file(
static sense_reason_t core_scsi3_update_and_write_aptpl(struct se_device *dev, bool aptpl)
{
unsigned char *buf;
- int rc;
+ int rc, len = PR_APTPL_BUF_LEN;
if (!aptpl) {
char *null_buf = "No Registrations or Reservations\n";
@@ -1973,25 +1973,26 @@ static sense_reason_t core_scsi3_update_and_write_aptpl(struct se_device *dev, b
return 0;
}
-
- buf = kzalloc(PR_APTPL_BUF_LEN, GFP_KERNEL);
+retry:
+ buf = vzalloc(len);
if (!buf)
return TCM_OUT_OF_RESOURCES;
- rc = core_scsi3_update_aptpl_buf(dev, buf, PR_APTPL_BUF_LEN);
+ rc = core_scsi3_update_aptpl_buf(dev, buf, len);
if (rc < 0) {
- kfree(buf);
- return TCM_OUT_OF_RESOURCES;
+ vfree(buf);
+ len *= 2;
+ goto retry;
}
rc = __core_scsi3_write_aptpl_to_file(dev, buf);
if (rc != 0) {
pr_err("SPC-3 PR: Could not update APTPL\n");
- kfree(buf);
+ vfree(buf);
return TCM_LOGICAL_UNIT_COMMUNICATION_FAILURE;
}
dev->t10_pr.pr_aptpl_active = 1;
- kfree(buf);
+ vfree(buf);
pr_debug("SPC-3 PR: Set APTPL Bit Activated\n");
return 0;
}
diff --git a/include/target/target_core_base.h b/include/target/target_core_base.h
index 9ec9864ecf38..9cbe50191dd6 100644
--- a/include/target/target_core_base.h
+++ b/include/target/target_core_base.h
@@ -407,7 +407,7 @@ struct t10_reservation {
/* Activate Persistence across Target Power Loss enabled
* for SCSI device */
int pr_aptpl_active;
-#define PR_APTPL_BUF_LEN 8192
+#define PR_APTPL_BUF_LEN 262144
u32 pr_generation;
spinlock_t registration_lock;
spinlock_t aptpl_reg_lock;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 108/183] mm/compaction: fix wrong order check in compact_finished()
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (106 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 107/183] target: Fix PR_APTPL_BUF_LEN buffer size limitation Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 109/183] mm/memory.c: actually remap enough memory Luis Henriques
` (74 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Joonsoo Kim, Mel Gorman, David Rientjes, Rik van Riel,
Andrew Morton, Linus Torvalds, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Joonsoo Kim <iamjoonsoo.kim@lge.com>
commit 372549c2a3778fd3df445819811c944ad54609ca upstream.
What we want to check here is whether there is highorder freepage in buddy
list of other migratetype in order to steal it without fragmentation.
But, current code just checks cc->order which means allocation request
order. So, this is wrong.
Without this fix, non-movable synchronous compaction below pageblock order
would not stopped until compaction is complete, because migratetype of
most pageblocks are movable and high order freepage made by compaction is
usually on movable type buddy list.
There is some report related to this bug. See below link.
http://www.spinics.net/lists/linux-mm/msg81666.html
Although the issued system still has load spike comes from compaction,
this makes that system completely stable and responsive according to his
report.
stress-highalloc test in mmtests with non movable order 7 allocation
doesn't show any notable difference in allocation success rate, but, it
shows more compaction success rate.
Compaction success rate (Compaction success * 100 / Compaction stalls, %)
18.47 : 28.94
Fixes: 1fb3f8ca0e92 ("mm: compaction: capture a suitable high-order page immediately when it is made available")
Signed-off-by: Joonsoo Kim <iamjoonsoo.kim@lge.com>
Acked-by: Vlastimil Babka <vbabka@suse.cz>
Reviewed-by: Zhang Yanfei <zhangyanfei@cn.fujitsu.com>
Cc: Mel Gorman <mgorman@suse.de>
Cc: David Rientjes <rientjes@google.com>
Cc: Rik van Riel <riel@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
mm/compaction.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/mm/compaction.c b/mm/compaction.c
index 21bf292b642a..c7c6ae59f787 100644
--- a/mm/compaction.c
+++ b/mm/compaction.c
@@ -937,7 +937,7 @@ static int compact_finished(struct zone *zone,
return COMPACT_PARTIAL;
/* Job done if allocation would set block type */
- if (cc->order >= pageblock_order && area->nr_free)
+ if (order >= pageblock_order && area->nr_free)
return COMPACT_PARTIAL;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 109/183] mm/memory.c: actually remap enough memory
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (107 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 108/183] mm/compaction: fix wrong order check in compact_finished() Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 110/183] mm: hwpoison: drop lru_add_drain_all() in __soft_offline_page() Luis Henriques
` (73 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Grazvydas Ignotas, Rik van Riel, Andrew Morton, Linus Torvalds,
Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Grazvydas Ignotas <notasas@gmail.com>
commit 9cb12d7b4ccaa976f97ce0c5fd0f1b6a83bc2a75 upstream.
For whatever reason, generic_access_phys() only remaps one page, but
actually allows to access arbitrary size. It's quite easy to trigger
large reads, like printing out large structure with gdb, which leads to a
crash. Fix it by remapping correct size.
Fixes: 28b2ee20c7cb ("access_process_vm device memory infrastructure")
Signed-off-by: Grazvydas Ignotas <notasas@gmail.com>
Cc: Rik van Riel <riel@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
mm/memory.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/mm/memory.c b/mm/memory.c
index 769bc8906b2d..e7ae35a5ffeb 100644
--- a/mm/memory.c
+++ b/mm/memory.c
@@ -3566,7 +3566,7 @@ int generic_access_phys(struct vm_area_struct *vma, unsigned long addr,
if (follow_phys(vma, addr, write, &prot, &phys_addr))
return -EINVAL;
- maddr = ioremap_prot(phys_addr, PAGE_SIZE, prot);
+ maddr = ioremap_prot(phys_addr, PAGE_ALIGN(len + offset), prot);
if (write)
memcpy_toio(maddr + offset, buf, len);
else
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 110/183] mm: hwpoison: drop lru_add_drain_all() in __soft_offline_page()
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (108 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 109/183] mm/memory.c: actually remap enough memory Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 111/183] ALSA: hda - enable mute led quirk for one more hp machine Luis Henriques
` (72 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Naoya Horiguchi, Andi Kleen, Tony Luck, Chen Gong, Andrew Morton,
Linus Torvalds, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
commit 9ab3b598d2dfbdb0153ffa7e4b1456bbff59a25d upstream.
A race condition starts to be visible in recent mmotm, where a PG_hwpoison
flag is set on a migration source page *before* it's back in buddy page
poo= l.
This is problematic because no page flag is supposed to be set when
freeing (see __free_one_page().) So the user-visible effect of this race
is that it could trigger the BUG_ON() when soft-offlining is called.
The root cause is that we call lru_add_drain_all() to make sure that the
page is in buddy, but that doesn't work because this function just
schedule= s a work item and doesn't wait its completion.
drain_all_pages() does drainin= g directly, so simply dropping
lru_add_drain_all() solves this problem.
Fixes: f15bdfa802bf ("mm/memory-failure.c: fix memory leak in successful soft offlining")
Signed-off-by: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
Cc: Andi Kleen <andi@firstfloor.org>
Cc: Tony Luck <tony.luck@intel.com>
Cc: Chen Gong <gong.chen@linux.intel.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
mm/memory-failure.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/mm/memory-failure.c b/mm/memory-failure.c
index a013bc94ebbe..607a6d62bcab 100644
--- a/mm/memory-failure.c
+++ b/mm/memory-failure.c
@@ -1649,8 +1649,6 @@ static int __soft_offline_page(struct page *page, int flags)
* setting PG_hwpoison.
*/
if (!is_free_buddy_page(page))
- lru_add_drain_all();
- if (!is_free_buddy_page(page))
drain_all_pages();
SetPageHWPoison(page);
if (!is_free_buddy_page(page))
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 111/183] ALSA: hda - enable mute led quirk for one more hp machine.
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (109 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 110/183] mm: hwpoison: drop lru_add_drain_all() in __soft_offline_page() Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 112/183] ARC: fix page address calculation if PAGE_OFFSET != LINUX_LINK_BASE Luis Henriques
` (71 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Hui Wang, Takashi Iwai, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Wang <hui.wang@canonical.com>
commit 7976eb49cbd138d8014fa02682d8f969ad1e9ff2 upstream.
Otherwise, the mute led can't work at all.
Tested-by: Taihsiang Ho <taihsiang.ho@canonical.com>
BugLink: https://bugs.launchpad.net/bugs/1410704
Signed-off-by: Hui Wang <hui.wang@canonical.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
sound/pci/hda/patch_realtek.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index ded8b2fa136f..f7c6e6e3ce66 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -4801,6 +4801,7 @@ static const struct snd_pci_quirk alc269_fixup_tbl[] = {
SND_PCI_QUIRK(0x103c, 0x18e6, "HP", ALC269_FIXUP_HP_GPIO_LED),
SND_PCI_QUIRK(0x103c, 0x218b, "HP", ALC269_FIXUP_LIMIT_INT_MIC_BOOST_MUTE_LED),
/* ALC282 */
+ SND_PCI_QUIRK(0x103c, 0x21f9, "HP", ALC269_FIXUP_HP_MUTE_LED_MIC1),
SND_PCI_QUIRK(0x103c, 0x2191, "HP Touchsmart 14", ALC269_FIXUP_HP_MUTE_LED_MIC1),
SND_PCI_QUIRK(0x103c, 0x2192, "HP Touchsmart 15", ALC269_FIXUP_HP_MUTE_LED_MIC1),
SND_PCI_QUIRK(0x103c, 0x2210, "HP", ALC269_FIXUP_HP_MUTE_LED_MIC1),
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 112/183] ARC: fix page address calculation if PAGE_OFFSET != LINUX_LINK_BASE
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (110 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 111/183] ALSA: hda - enable mute led quirk for one more hp machine Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 113/183] drm/radeon/dp: Set EDP_CONFIGURATION_SET for bridge chips if necessary Luis Henriques
` (70 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Alexey Brodkin, Vineet Gupta, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexey Brodkin <abrodkin@synopsys.com>
commit 06f34e1c28f3608b0ce5b310e41102d3fe7b65a1 upstream.
We used to calculate page address differently in 2 cases:
1. In virt_to_page(x) we do
--->8---
mem_map + (x - CONFIG_LINUX_LINK_BASE) >> PAGE_SHIFT
--->8---
2. In in pte_page(x) we do
--->8---
mem_map + (pte_val(x) - PAGE_OFFSET) >> PAGE_SHIFT
--->8---
That leads to problems in case PAGE_OFFSET != CONFIG_LINUX_LINK_BASE -
different pages will be selected depending on where and how we calculate
page address.
In particular in the STAR 9000853582 when gdb attempted to read memory
of another process it got improper page in get_user_pages() because this
is exactly one of the places where we search for a page by pte_page().
The fix is trivial - we need to calculate page address similarly in both
cases.
Signed-off-by: Alexey Brodkin <abrodkin@synopsys.com>
Signed-off-by: Vineet Gupta <vgupta@synopsys.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/arc/include/asm/pgtable.h | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/arc/include/asm/pgtable.h b/arch/arc/include/asm/pgtable.h
index 6b0b7f7ef783..7670f33b9ce2 100644
--- a/arch/arc/include/asm/pgtable.h
+++ b/arch/arc/include/asm/pgtable.h
@@ -259,7 +259,8 @@ static inline void pmd_set(pmd_t *pmdp, pte_t *ptep)
#define pmd_clear(xp) do { pmd_val(*(xp)) = 0; } while (0)
#define pte_page(x) (mem_map + \
- (unsigned long)(((pte_val(x) - PAGE_OFFSET) >> PAGE_SHIFT)))
+ (unsigned long)(((pte_val(x) - CONFIG_LINUX_LINK_BASE) >> \
+ PAGE_SHIFT)))
#define mk_pte(page, pgprot) \
({ \
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 113/183] drm/radeon/dp: Set EDP_CONFIGURATION_SET for bridge chips if necessary
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (111 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 112/183] ARC: fix page address calculation if PAGE_OFFSET != LINUX_LINK_BASE Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 114/183] drm/radeon: fix voltage setup on hawaii Luis Henriques
` (69 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Alex Deucher, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Deucher <alexander.deucher@amd.com>
commit 66c2b84ba6256bc5399eed45582af9ebb3ba2c15 upstream.
Don't restrict it to just eDP panels. Some LVDS bridge chips require
this. Fixes blank panels on resume on certain laptops. Noticed
by mrnuke on IRC.
bug:
https://bugs.freedesktop.org/show_bug.cgi?id=42960
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/gpu/drm/radeon/atombios_dp.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/radeon/atombios_dp.c b/drivers/gpu/drm/radeon/atombios_dp.c
index d011729f20b0..41c2cd8954e7 100644
--- a/drivers/gpu/drm/radeon/atombios_dp.c
+++ b/drivers/gpu/drm/radeon/atombios_dp.c
@@ -626,10 +626,8 @@ static int radeon_dp_link_train_init(struct radeon_dp_link_train_info *dp_info)
drm_dp_dpcd_writeb(dp_info->aux,
DP_DOWNSPREAD_CTRL, 0);
- if ((dp_info->connector->connector_type == DRM_MODE_CONNECTOR_eDP) &&
- (dig->panel_mode == DP_PANEL_MODE_INTERNAL_DP2_MODE)) {
+ if (dig->panel_mode == DP_PANEL_MODE_INTERNAL_DP2_MODE)
drm_dp_dpcd_writeb(dp_info->aux, DP_EDP_CONFIGURATION_SET, 1);
- }
/* set the lane count on the sink */
tmp = dp_info->dp_lane_count;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 114/183] drm/radeon: fix voltage setup on hawaii
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (112 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 113/183] drm/radeon/dp: Set EDP_CONFIGURATION_SET for bridge chips if necessary Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 115/183] ALSA: hdspm - Constrain periods to 2 on older cards Luis Henriques
` (68 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Alex Deucher, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Deucher <alexander.deucher@amd.com>
commit 09b6e85fc868568e1b2820235a2a851aecbccfcc upstream.
Missing parameter when fetching the real voltage values
from atom. Fixes problems with dynamic clocking on
certain boards.
bug:
https://bugs.freedesktop.org/show_bug.cgi?id=87457
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/gpu/drm/radeon/radeon_atombios.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/gpu/drm/radeon/radeon_atombios.c b/drivers/gpu/drm/radeon/radeon_atombios.c
index be6705eeb649..1db2be827ea2 100644
--- a/drivers/gpu/drm/radeon/radeon_atombios.c
+++ b/drivers/gpu/drm/radeon/radeon_atombios.c
@@ -3280,6 +3280,7 @@ int radeon_atom_get_voltage_evv(struct radeon_device *rdev,
args.in.ucVoltageType = VOLTAGE_TYPE_VDDC;
args.in.ucVoltageMode = ATOM_GET_VOLTAGE_EVV_VOLTAGE;
+ args.in.usVoltageLevel = cpu_to_le16(virtual_voltage_id);
args.in.ulSCLKFreq =
cpu_to_le32(rdev->pm.dpm.dyn_state.vddc_dependency_on_sclk.entries[entry_id].clk);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 115/183] ALSA: hdspm - Constrain periods to 2 on older cards
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (113 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 114/183] drm/radeon: fix voltage setup on hawaii Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 116/183] jffs2: fix handling of corrupted summary length Luis Henriques
` (67 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Adrian Knoth, Takashi Iwai, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Adrian Knoth <adi@drcomp.erfurt.thur.de>
commit f0153c3d948c1764f6c920a0675d86fc1d75813e upstream.
RME RayDAT and AIO use a fixed buffer size of 16384 samples. With period
sizes of 32-4096, this translates to 4-512 periods.
The older RME cards have a variable buffer size but require exactly two
periods.
This patch enforces nperiods=2 on those cards.
Signed-off-by: Adrian Knoth <adi@drcomp.erfurt.thur.de>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
sound/pci/rme9652/hdspm.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/sound/pci/rme9652/hdspm.c b/sound/pci/rme9652/hdspm.c
index cb82b593473a..f292bed4424d 100644
--- a/sound/pci/rme9652/hdspm.c
+++ b/sound/pci/rme9652/hdspm.c
@@ -6114,6 +6114,9 @@ static int snd_hdspm_playback_open(struct snd_pcm_substream *substream)
snd_pcm_hw_constraint_minmax(runtime,
SNDRV_PCM_HW_PARAM_PERIOD_SIZE,
64, 8192);
+ snd_pcm_hw_constraint_minmax(runtime,
+ SNDRV_PCM_HW_PARAM_PERIODS,
+ 2, 2);
break;
}
@@ -6188,6 +6191,9 @@ static int snd_hdspm_capture_open(struct snd_pcm_substream *substream)
snd_pcm_hw_constraint_minmax(runtime,
SNDRV_PCM_HW_PARAM_PERIOD_SIZE,
64, 8192);
+ snd_pcm_hw_constraint_minmax(runtime,
+ SNDRV_PCM_HW_PARAM_PERIODS,
+ 2, 2);
break;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 116/183] jffs2: fix handling of corrupted summary length
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (114 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 115/183] ALSA: hdspm - Constrain periods to 2 on older cards Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 117/183] dm mirror: do not degrade the mirror on discard error Luis Henriques
` (66 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Chen Jie, Andrew Morton, David Woodhouse, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Jie <chenjie6@huawei.com>
commit 164c24063a3eadee11b46575c5482b2f1417be49 upstream.
sm->offset maybe wrong but magic maybe right, the offset do not have CRC.
Badness at c00c7580 [verbose debug info unavailable]
NIP: c00c7580 LR: c00c718c CTR: 00000014
REGS: df07bb40 TRAP: 0700 Not tainted (2.6.34.13-WR4.3.0.0_standard)
MSR: 00029000 <EE,ME,CE> CR: 22084f84 XER: 00000000
TASK = df84d6e0[908] 'mount' THREAD: df07a000
GPR00: 00000001 df07bbf0 df84d6e0 00000000 00000001 00000000 df07bb58 00000041
GPR08: 00000041 c0638860 00000000 00000010 22084f88 100636c8 df814ff8 00000000
GPR16: df84d6e0 dfa558cc c05adb90 00000048 c0452d30 00000000 000240d0 000040d0
GPR24: 00000014 c05ae734 c05be2e0 00000000 00000001 00000000 00000000 c05ae730
NIP [c00c7580] __alloc_pages_nodemask+0x4d0/0x638
LR [c00c718c] __alloc_pages_nodemask+0xdc/0x638
Call Trace:
[df07bbf0] [c00c718c] __alloc_pages_nodemask+0xdc/0x638 (unreliable)
[df07bc90] [c00c7708] __get_free_pages+0x20/0x48
[df07bca0] [c00f4a40] __kmalloc+0x15c/0x1ec
[df07bcd0] [c01fc880] jffs2_scan_medium+0xa58/0x14d0
[df07bd70] [c01ff38c] jffs2_do_mount_fs+0x1f4/0x6b4
[df07bdb0] [c020144c] jffs2_do_fill_super+0xa8/0x260
[df07bdd0] [c020230c] jffs2_fill_super+0x104/0x184
[df07be00] [c0335814] get_sb_mtd_aux+0x9c/0xec
[df07be20] [c033596c] get_sb_mtd+0x84/0x1e8
[df07be60] [c0201ed0] jffs2_get_sb+0x1c/0x2c
[df07be70] [c0103898] vfs_kern_mount+0x78/0x1e8
[df07bea0] [c0103a58] do_kern_mount+0x40/0x100
[df07bec0] [c011fe90] do_mount+0x240/0x890
[df07bf10] [c0120570] sys_mount+0x90/0xd8
[df07bf40] [c00110d8] ret_from_syscall+0x0/0x4
=== Exception: c01 at 0xff61a34
LR = 0x100135f0
Instruction dump:
38800005 38600000 48010f41 4bfffe1c 4bfc2d15 4bfffe8c 72e90200 4082fc28
3d20c064 39298860 8809000d 68000001 <0f000000> 2f800000 419efc0c 38000001
mount: mounting /dev/mtdblock3 on /common failed: Input/output error
Signed-off-by: Chen Jie <chenjie6@huawei.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/jffs2/scan.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/fs/jffs2/scan.c b/fs/jffs2/scan.c
index 7654e87b0428..9ad5ba4b299b 100644
--- a/fs/jffs2/scan.c
+++ b/fs/jffs2/scan.c
@@ -510,6 +510,10 @@ static int jffs2_scan_eraseblock (struct jffs2_sb_info *c, struct jffs2_eraseblo
sumlen = c->sector_size - je32_to_cpu(sm->offset);
sumptr = buf + buf_size - sumlen;
+ /* sm->offset maybe wrong but MAGIC maybe right */
+ if (sumlen > c->sector_size)
+ goto full_scan;
+
/* Now, make sure the summary itself is available */
if (sumlen > buf_size) {
/* Need to kmalloc for this. */
@@ -544,6 +548,7 @@ static int jffs2_scan_eraseblock (struct jffs2_sb_info *c, struct jffs2_eraseblo
}
}
+full_scan:
buf_ofs = jeb->offset;
if (!buf_size) {
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 117/183] dm mirror: do not degrade the mirror on discard error
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (115 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 116/183] jffs2: fix handling of corrupted summary length Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 118/183] dm io: reject unsupported DISCARD requests with EOPNOTSUPP Luis Henriques
` (65 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Mikulas Patocka, Mike Snitzer, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikulas Patocka <mpatocka@redhat.com>
commit f2ed51ac64611d717d1917820a01930174c2f236 upstream.
It may be possible that a device claims discard support but it rejects
discards with -EOPNOTSUPP. It happens when using loopback on ext2/ext3
filesystem driven by the ext4 driver. It may also happen if the
underlying devices are moved from one disk on another.
If discard error happens, we reject the bio with -EOPNOTSUPP, but we do
not degrade the array.
This patch fixes failed test shell/lvconvert-repair-transient.sh in the
lvm2 testsuite if the testsuite is extracted on an ext2 or ext3
filesystem and it is being driven by the ext4 driver.
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/md/dm-raid1.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/drivers/md/dm-raid1.c b/drivers/md/dm-raid1.c
index 7dfdb5c746d6..089d62751f7f 100644
--- a/drivers/md/dm-raid1.c
+++ b/drivers/md/dm-raid1.c
@@ -604,6 +604,15 @@ static void write_callback(unsigned long error, void *context)
return;
}
+ /*
+ * If the bio is discard, return an error, but do not
+ * degrade the array.
+ */
+ if (bio->bi_rw & REQ_DISCARD) {
+ bio_endio(bio, -EOPNOTSUPP);
+ return;
+ }
+
for (i = 0; i < ms->nr_mirrors; i++)
if (test_bit(i, &error))
fail_mirror(ms->mirror + i, DM_RAID1_WRITE_ERROR);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 118/183] dm io: reject unsupported DISCARD requests with EOPNOTSUPP
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (116 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 117/183] dm mirror: do not degrade the mirror on discard error Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 119/183] NFS: struct nfs_commit_info.lock must always point to inode->i_lock Luis Henriques
` (64 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Darrick J. Wong, Mike Snitzer, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: "Darrick J. Wong" <darrick.wong@oracle.com>
commit 37527b869207ad4c208b1e13967d69b8bba1fbf9 upstream.
I created a dm-raid1 device backed by a device that supports DISCARD
and another device that does NOT support DISCARD with the following
dm configuration:
# echo '0 2048 mirror core 1 512 2 /dev/sda 0 /dev/sdb 0' | dmsetup create moo
# lsblk -D
NAME DISC-ALN DISC-GRAN DISC-MAX DISC-ZERO
sda 0 4K 1G 0
`-moo (dm-0) 0 4K 1G 0
sdb 0 0B 0B 0
`-moo (dm-0) 0 4K 1G 0
Notice that the mirror device /dev/mapper/moo advertises DISCARD
support even though one of the mirror halves doesn't.
If I issue a DISCARD request (via fstrim, mount -o discard, or ioctl
BLKDISCARD) through the mirror, kmirrord gets stuck in an infinite
loop in do_region() when it tries to issue a DISCARD request to sdb.
The problem is that when we call do_region() against sdb, num_sectors
is set to zero because q->limits.max_discard_sectors is zero.
Therefore, "remaining" never decreases and the loop never terminates.
To fix this: before entering the loop, check for the combination of
REQ_DISCARD and no discard and return -EOPNOTSUPP to avoid hanging up
the mirror device.
This bug was found by the unfortunate coincidence of pvmove and a
discard operation in the RHEL 6.5 kernel; upstream is also affected.
Signed-off-by: Darrick J. Wong <darrick.wong@oracle.com>
Acked-by: "Martin K. Petersen" <martin.petersen@oracle.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/md/dm-io.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/md/dm-io.c b/drivers/md/dm-io.c
index db404a0f7e2c..d2a8d64f8526 100644
--- a/drivers/md/dm-io.c
+++ b/drivers/md/dm-io.c
@@ -292,6 +292,12 @@ static void do_region(int rw, unsigned region, struct dm_io_region *where,
unsigned short logical_block_size = queue_logical_block_size(q);
sector_t num_sectors;
+ /* Reject unsupported discard requests */
+ if ((rw & REQ_DISCARD) && !blk_queue_discard(q)) {
+ dec_count(io, region, -EOPNOTSUPP);
+ return;
+ }
+
/*
* where->count may be zero if rw holds a flush and we need to
* send a zero-sized flush.
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 119/183] NFS: struct nfs_commit_info.lock must always point to inode->i_lock
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (117 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 118/183] dm io: reject unsupported DISCARD requests with EOPNOTSUPP Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 120/183] target: Add missing WRITE_SAME end-of-device sanity check Luis Henriques
` (63 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Weston Andros Adamson, Trond Myklebust, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Trond Myklebust <trond.myklebust@primarydata.com>
commit f4086a3d789dbe18949862276d83b8f49fce6d2f upstream.
Commit 411a99adffb4f (nfs: clear_request_commit while holding i_lock)
assumes that the nfs_commit_info always points to the inode->i_lock.
For historical reasons, that is not the case for O_DIRECT writes.
Cc: Weston Andros Adamson <dros@primarydata.com>
Fixes: 411a99adffb4f ("nfs: clear_request_commit while holding i_lock")
Signed-off-by: Trond Myklebust <trond.myklebust@primarydata.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/nfs/direct.c | 2 +-
include/linux/nfs_xdr.h | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/fs/nfs/direct.c b/fs/nfs/direct.c
index ac8e19995f56..1d36353ce13c 100644
--- a/fs/nfs/direct.c
+++ b/fs/nfs/direct.c
@@ -246,7 +246,7 @@ static void nfs_direct_release_pages(struct page **pages, unsigned int npages)
void nfs_init_cinfo_from_dreq(struct nfs_commit_info *cinfo,
struct nfs_direct_req *dreq)
{
- cinfo->lock = &dreq->lock;
+ cinfo->lock = &dreq->inode->i_lock;
cinfo->mds = &dreq->mds_cinfo;
cinfo->ds = &dreq->ds_cinfo;
cinfo->dreq = dreq;
diff --git a/include/linux/nfs_xdr.h b/include/linux/nfs_xdr.h
index a8f111be79a0..6f2ca8976069 100644
--- a/include/linux/nfs_xdr.h
+++ b/include/linux/nfs_xdr.h
@@ -1319,7 +1319,7 @@ struct nfs_commit_completion_ops {
};
struct nfs_commit_info {
- spinlock_t *lock;
+ spinlock_t *lock; /* inode->i_lock */
struct nfs_mds_commit_info *mds;
struct pnfs_ds_commit_info *ds;
struct nfs_direct_req *dreq; /* O_DIRECT request */
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 120/183] target: Add missing WRITE_SAME end-of-device sanity check
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (118 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 119/183] NFS: struct nfs_commit_info.lock must always point to inode->i_lock Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 121/183] target: Check for LBA + sectors wrap-around in sbc_parse_cdb Luis Henriques
` (62 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Martin Petersen, Christoph Hellwig, Nicholas Bellinger, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicholas Bellinger <nab@linux-iscsi.org>
commit 8e575c50a171f2579e367a7f778f86477dfdaf49 upstream.
This patch adds a check to sbc_setup_write_same() to verify
the incoming WRITE_SAME LBA + number of blocks does not exceed
past the end-of-device.
Also check for potential LBA wrap-around as well.
Reported-by: Bart Van Assche <bart.vanassche@sandisk.com>
Cc: Martin Petersen <martin.petersen@oracle.com>
Cc: Christoph Hellwig <hch@lst.de>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/target/target_core_sbc.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/drivers/target/target_core_sbc.c b/drivers/target/target_core_sbc.c
index 8368870dc01f..efd0a98313fb 100644
--- a/drivers/target/target_core_sbc.c
+++ b/drivers/target/target_core_sbc.c
@@ -251,6 +251,8 @@ static inline unsigned long long transport_lba_64_ext(unsigned char *cdb)
static sense_reason_t
sbc_setup_write_same(struct se_cmd *cmd, unsigned char *flags, struct sbc_ops *ops)
{
+ struct se_device *dev = cmd->se_dev;
+ sector_t end_lba = dev->transport->get_blocks(dev) + 1;
unsigned int sectors = sbc_get_write_same_sectors(cmd);
if ((flags[0] & 0x04) || (flags[0] & 0x02)) {
@@ -264,6 +266,16 @@ sbc_setup_write_same(struct se_cmd *cmd, unsigned char *flags, struct sbc_ops *o
sectors, cmd->se_dev->dev_attrib.max_write_same_len);
return TCM_INVALID_CDB_FIELD;
}
+ /*
+ * Sanity check for LBA wrap and request past end of device.
+ */
+ if (((cmd->t_task_lba + sectors) < cmd->t_task_lba) ||
+ ((cmd->t_task_lba + sectors) > end_lba)) {
+ pr_err("WRITE_SAME exceeds last lba %llu (lba %llu, sectors %u)\n",
+ (unsigned long long)end_lba, cmd->t_task_lba, sectors);
+ return TCM_ADDRESS_OUT_OF_RANGE;
+ }
+
/* We always have ANC_SUP == 0 so setting ANCHOR is always an error */
if (flags[0] & 0x10) {
pr_warn("WRITE SAME with ANCHOR not supported\n");
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 121/183] target: Check for LBA + sectors wrap-around in sbc_parse_cdb
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (119 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 120/183] target: Add missing WRITE_SAME end-of-device sanity check Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 122/183] Btrfs: fix fsync data loss after adding hard link to inode Luis Henriques
` (61 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Martin Petersen, Christoph Hellwig, Nicholas Bellinger, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicholas Bellinger <nab@linux-iscsi.org>
commit aa179935edea9a64dec4b757090c8106a3907ffa upstream.
This patch adds a check to sbc_parse_cdb() in order to detect when
an LBA + sector vs. end-of-device calculation wraps when the LBA is
sufficently large enough (eg: 0xFFFFFFFFFFFFFFFF).
Cc: Martin Petersen <martin.petersen@oracle.com>
Cc: Christoph Hellwig <hch@lst.de>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/target/target_core_sbc.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/target/target_core_sbc.c b/drivers/target/target_core_sbc.c
index efd0a98313fb..ccddbd1d97ed 100644
--- a/drivers/target/target_core_sbc.c
+++ b/drivers/target/target_core_sbc.c
@@ -967,7 +967,8 @@ sbc_parse_cdb(struct se_cmd *cmd, struct sbc_ops *ops)
unsigned long long end_lba;
check_lba:
end_lba = dev->transport->get_blocks(dev) + 1;
- if (cmd->t_task_lba + sectors > end_lba) {
+ if (((cmd->t_task_lba + sectors) < cmd->t_task_lba) ||
+ ((cmd->t_task_lba + sectors) > end_lba)) {
pr_err("cmd exceeds last lba %llu "
"(lba %llu, sectors %u)\n",
end_lba, cmd->t_task_lba, sectors);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 122/183] Btrfs: fix fsync data loss after adding hard link to inode
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (120 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 121/183] target: Check for LBA + sectors wrap-around in sbc_parse_cdb Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 123/183] Added Little Endian support to vtpm module Luis Henriques
` (60 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Filipe Manana, Chris Mason, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
commit 1a4bcf470c886b955adf36486f4c86f2441d85cb upstream.
We have a scenario where after the fsync log replay we can lose file data
that had been previously fsync'ed if we added an hard link for our inode
and after that we sync'ed the fsync log (for example by fsync'ing some
other file or directory).
This is because when adding an hard link we updated the inode item in the
log tree with an i_size value of 0. At that point the new inode item was
in memory only and a subsequent fsync log replay would not make us lose
the file data. However if after adding the hard link we sync the log tree
to disk, by fsync'ing some other file or directory for example, we ended
up losing the file data after log replay, because the inode item in the
persisted log tree had an an i_size of zero.
This is easy to reproduce, and the following excerpt from my test for
xfstests shows this:
_scratch_mkfs >> $seqres.full 2>&1
_init_flakey
_mount_flakey
# Create one file with data and fsync it.
# This made the btrfs fsync log persist the data and the inode metadata with
# a correct inode->i_size (4096 bytes).
$XFS_IO_PROG -f -c "pwrite -S 0xaa -b 4K 0 4K" -c "fsync" \
$SCRATCH_MNT/foo | _filter_xfs_io
# Now add one hard link to our file. This made the btrfs code update the fsync
# log, in memory only, with an inode metadata having a size of 0.
ln $SCRATCH_MNT/foo $SCRATCH_MNT/foo_link
# Now force persistence of the fsync log to disk, for example, by fsyncing some
# other file.
touch $SCRATCH_MNT/bar
$XFS_IO_PROG -c "fsync" $SCRATCH_MNT/bar
# Before a power loss or crash, we could read the 4Kb of data from our file as
# expected.
echo "File content before:"
od -t x1 $SCRATCH_MNT/foo
# Simulate a crash/power loss.
_load_flakey_table $FLAKEY_DROP_WRITES
_unmount_flakey
_load_flakey_table $FLAKEY_ALLOW_WRITES
_mount_flakey
# After the fsync log replay, because the fsync log had a value of 0 for our
# inode's i_size, we couldn't read anymore the 4Kb of data that we previously
# wrote and fsync'ed. The size of the file became 0 after the fsync log replay.
echo "File content after:"
od -t x1 $SCRATCH_MNT/foo
Another alternative test, that doesn't need to fsync an inode in the same
transaction it was created, is:
_scratch_mkfs >> $seqres.full 2>&1
_init_flakey
_mount_flakey
# Create our test file with some data.
$XFS_IO_PROG -f -c "pwrite -S 0xaa -b 8K 0 8K" \
$SCRATCH_MNT/foo | _filter_xfs_io
# Make sure the file is durably persisted.
sync
# Append some data to our file, to increase its size.
$XFS_IO_PROG -f -c "pwrite -S 0xcc -b 4K 8K 4K" \
$SCRATCH_MNT/foo | _filter_xfs_io
# Fsync the file, so from this point on if a crash/power failure happens, our
# new data is guaranteed to be there next time the fs is mounted.
$XFS_IO_PROG -c "fsync" $SCRATCH_MNT/foo
# Add one hard link to our file. This made btrfs write into the in memory fsync
# log a special inode with generation 0 and an i_size of 0 too. Note that this
# didn't update the inode in the fsync log on disk.
ln $SCRATCH_MNT/foo $SCRATCH_MNT/foo_link
# Now make sure the in memory fsync log is durably persisted.
# Creating and fsync'ing another file will do it.
touch $SCRATCH_MNT/bar
$XFS_IO_PROG -c "fsync" $SCRATCH_MNT/bar
# As expected, before the crash/power failure, we should be able to read the
# 12Kb of file data.
echo "File content before:"
od -t x1 $SCRATCH_MNT/foo
# Simulate a crash/power loss.
_load_flakey_table $FLAKEY_DROP_WRITES
_unmount_flakey
_load_flakey_table $FLAKEY_ALLOW_WRITES
_mount_flakey
# After mounting the fs again, the fsync log was replayed.
# The btrfs fsync log replay code didn't update the i_size of the persisted
# inode because the inode item in the log had a special generation with a
# value of 0 (and it couldn't know the correct i_size, since that inode item
# had a 0 i_size too). This made the last 4Kb of file data inaccessible and
# effectively lost.
echo "File content after:"
od -t x1 $SCRATCH_MNT/foo
This isn't a new issue/regression. This problem has been around since the
log tree code was added in 2008:
Btrfs: Add a write ahead tree log to optimize synchronous operations
(commit e02119d5a7b4396c5a872582fddc8bd6d305a70a)
Test cases for xfstests follow soon.
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: Chris Mason <clm@fb.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/btrfs/tree-log.c | 82 +++++++++++++++++++++++++++++++++++++++++++++++------
1 file changed, 73 insertions(+), 9 deletions(-)
diff --git a/fs/btrfs/tree-log.c b/fs/btrfs/tree-log.c
index f3fbcc314c29..76bbe6557eb6 100644
--- a/fs/btrfs/tree-log.c
+++ b/fs/btrfs/tree-log.c
@@ -485,8 +485,20 @@ insert:
src_item = (struct btrfs_inode_item *)src_ptr;
dst_item = (struct btrfs_inode_item *)dst_ptr;
- if (btrfs_inode_generation(eb, src_item) == 0)
+ if (btrfs_inode_generation(eb, src_item) == 0) {
+ struct extent_buffer *dst_eb = path->nodes[0];
+
+ if (S_ISREG(btrfs_inode_mode(eb, src_item)) &&
+ S_ISREG(btrfs_inode_mode(dst_eb, dst_item))) {
+ struct btrfs_map_token token;
+ u64 ino_size = btrfs_inode_size(eb, src_item);
+
+ btrfs_init_map_token(&token);
+ btrfs_set_token_inode_size(dst_eb, dst_item,
+ ino_size, &token);
+ }
goto no_copy;
+ }
if (overwrite_root &&
S_ISDIR(btrfs_inode_mode(eb, src_item)) &&
@@ -3216,7 +3228,8 @@ static int drop_objectid_items(struct btrfs_trans_handle *trans,
static void fill_inode_item(struct btrfs_trans_handle *trans,
struct extent_buffer *leaf,
struct btrfs_inode_item *item,
- struct inode *inode, int log_inode_only)
+ struct inode *inode, int log_inode_only,
+ u64 logged_isize)
{
struct btrfs_map_token token;
@@ -3229,7 +3242,7 @@ static void fill_inode_item(struct btrfs_trans_handle *trans,
* to say 'update this inode with these values'
*/
btrfs_set_token_inode_generation(leaf, item, 0, &token);
- btrfs_set_token_inode_size(leaf, item, 0, &token);
+ btrfs_set_token_inode_size(leaf, item, logged_isize, &token);
} else {
btrfs_set_token_inode_generation(leaf, item,
BTRFS_I(inode)->generation,
@@ -3281,7 +3294,7 @@ static int log_inode_item(struct btrfs_trans_handle *trans,
return ret;
inode_item = btrfs_item_ptr(path->nodes[0], path->slots[0],
struct btrfs_inode_item);
- fill_inode_item(trans, path->nodes[0], inode_item, inode, 0);
+ fill_inode_item(trans, path->nodes[0], inode_item, inode, 0, 0);
btrfs_release_path(path);
return 0;
}
@@ -3290,7 +3303,8 @@ static noinline int copy_items(struct btrfs_trans_handle *trans,
struct inode *inode,
struct btrfs_path *dst_path,
struct btrfs_path *src_path, u64 *last_extent,
- int start_slot, int nr, int inode_only)
+ int start_slot, int nr, int inode_only,
+ u64 logged_isize)
{
unsigned long src_offset;
unsigned long dst_offset;
@@ -3347,7 +3361,8 @@ static noinline int copy_items(struct btrfs_trans_handle *trans,
dst_path->slots[0],
struct btrfs_inode_item);
fill_inode_item(trans, dst_path->nodes[0], inode_item,
- inode, inode_only == LOG_INODE_EXISTS);
+ inode, inode_only == LOG_INODE_EXISTS,
+ logged_isize);
} else {
copy_extent_buffer(dst_path->nodes[0], src, dst_offset,
src_offset, ins_sizes[i]);
@@ -3843,6 +3858,33 @@ process:
return ret;
}
+static int logged_inode_size(struct btrfs_root *log, struct inode *inode,
+ struct btrfs_path *path, u64 *size_ret)
+{
+ struct btrfs_key key;
+ int ret;
+
+ key.objectid = btrfs_ino(inode);
+ key.type = BTRFS_INODE_ITEM_KEY;
+ key.offset = 0;
+
+ ret = btrfs_search_slot(NULL, log, &key, path, 0, 0);
+ if (ret < 0) {
+ return ret;
+ } else if (ret > 0) {
+ *size_ret = i_size_read(inode);
+ } else {
+ struct btrfs_inode_item *item;
+
+ item = btrfs_item_ptr(path->nodes[0], path->slots[0],
+ struct btrfs_inode_item);
+ *size_ret = btrfs_inode_size(path->nodes[0], item);
+ }
+
+ btrfs_release_path(path);
+ return 0;
+}
+
/* log a single inode in the tree log.
* At least one parent directory for this inode must exist in the tree
* or be logged already.
@@ -3876,6 +3918,7 @@ static int btrfs_log_inode(struct btrfs_trans_handle *trans,
int ins_nr;
bool fast_search = false;
u64 ino = btrfs_ino(inode);
+ u64 logged_isize = 0;
path = btrfs_alloc_path();
if (!path)
@@ -3929,6 +3972,25 @@ static int btrfs_log_inode(struct btrfs_trans_handle *trans,
max_key_type = BTRFS_XATTR_ITEM_KEY;
ret = drop_objectid_items(trans, log, path, ino, max_key_type);
} else {
+ if (inode_only == LOG_INODE_EXISTS) {
+ /*
+ * Make sure the new inode item we write to the log has
+ * the same isize as the current one (if it exists).
+ * This is necessary to prevent data loss after log
+ * replay, and also to prevent doing a wrong expanding
+ * truncate - for e.g. create file, write 4K into offset
+ * 0, fsync, write 4K into offset 4096, add hard link,
+ * fsync some other file (to sync log), power fail - if
+ * we use the inode's current i_size, after log replay
+ * we get a 8Kb file, with the last 4Kb extent as a hole
+ * (zeroes), as if an expanding truncate happened,
+ * instead of getting a file of 4Kb only.
+ */
+ err = logged_inode_size(log, inode, path,
+ &logged_isize);
+ if (err)
+ goto out_unlock;
+ }
if (test_and_clear_bit(BTRFS_INODE_NEEDS_FULL_SYNC,
&BTRFS_I(inode)->runtime_flags)) {
clear_bit(BTRFS_INODE_COPY_EVERYTHING,
@@ -3985,7 +4047,8 @@ again:
}
ret = copy_items(trans, inode, dst_path, path, &last_extent,
- ins_start_slot, ins_nr, inode_only);
+ ins_start_slot, ins_nr, inode_only,
+ logged_isize);
if (ret < 0) {
err = ret;
goto out_unlock;
@@ -4008,7 +4071,7 @@ next_slot:
if (ins_nr) {
ret = copy_items(trans, inode, dst_path, path,
&last_extent, ins_start_slot,
- ins_nr, inode_only);
+ ins_nr, inode_only, logged_isize);
if (ret < 0) {
err = ret;
goto out_unlock;
@@ -4029,7 +4092,8 @@ next_slot:
}
if (ins_nr) {
ret = copy_items(trans, inode, dst_path, path, &last_extent,
- ins_start_slot, ins_nr, inode_only);
+ ins_start_slot, ins_nr, inode_only,
+ logged_isize);
if (ret < 0) {
err = ret;
goto out_unlock;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 123/183] Added Little Endian support to vtpm module
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (121 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 122/183] Btrfs: fix fsync data loss after adding hard link to inode Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 124/183] fixed invalid assignment of 64bit mask to host dma_boundary for scatter gather segment boundary limit Luis Henriques
` (59 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Hon Ching(Vicky) Lo, Joy Latten, Peter Huewe, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: honclo <honclo@imap.linux.ibm.com>
commit eb71f8a5e33fa1066fb92f0111ab366a341e1f6c upstream.
The tpm_ibmvtpm module is affected by an unaligned access problem.
ibmvtpm_crq_get_version failed with rc=-4 during boot when vTPM is
enabled in Power partition, which supports both little endian and
big endian modes.
We added little endian support to fix this problem:
1) added cpu_to_be64 calls to ensure BE data is sent from an LE OS.
2) added be16_to_cpu and be32_to_cpu calls to make sure data received
is in LE format on a LE OS.
Signed-off-by: Hon Ching(Vicky) Lo <honclo@linux.vnet.ibm.com>
Signed-off-by: Joy Latten <jmlatten@linux.vnet.ibm.com>
[phuewe: manually applied the patch :( ]
Reviewed-by: Ashley Lai <ashley@ahsleylai.com>
Signed-off-by: Peter Huewe <peterhuewe@gmx.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/char/tpm/tpm_ibmvtpm.c | 20 ++++++++++++--------
1 file changed, 12 insertions(+), 8 deletions(-)
diff --git a/drivers/char/tpm/tpm_ibmvtpm.c b/drivers/char/tpm/tpm_ibmvtpm.c
index 4109222f2878..eff9d5870034 100644
--- a/drivers/char/tpm/tpm_ibmvtpm.c
+++ b/drivers/char/tpm/tpm_ibmvtpm.c
@@ -148,7 +148,8 @@ static int tpm_ibmvtpm_send(struct tpm_chip *chip, u8 *buf, size_t count)
crq.len = (u16)count;
crq.data = ibmvtpm->rtce_dma_handle;
- rc = ibmvtpm_send_crq(ibmvtpm->vdev, word[0], word[1]);
+ rc = ibmvtpm_send_crq(ibmvtpm->vdev, cpu_to_be64(word[0]),
+ cpu_to_be64(word[1]));
if (rc != H_SUCCESS) {
dev_err(ibmvtpm->dev, "tpm_ibmvtpm_send failed rc=%d\n", rc);
rc = 0;
@@ -186,7 +187,8 @@ static int ibmvtpm_crq_get_rtce_size(struct ibmvtpm_dev *ibmvtpm)
crq.valid = (u8)IBMVTPM_VALID_CMD;
crq.msg = (u8)VTPM_GET_RTCE_BUFFER_SIZE;
- rc = ibmvtpm_send_crq(ibmvtpm->vdev, buf[0], buf[1]);
+ rc = ibmvtpm_send_crq(ibmvtpm->vdev, cpu_to_be64(buf[0]),
+ cpu_to_be64(buf[1]));
if (rc != H_SUCCESS)
dev_err(ibmvtpm->dev,
"ibmvtpm_crq_get_rtce_size failed rc=%d\n", rc);
@@ -212,7 +214,8 @@ static int ibmvtpm_crq_get_version(struct ibmvtpm_dev *ibmvtpm)
crq.valid = (u8)IBMVTPM_VALID_CMD;
crq.msg = (u8)VTPM_GET_VERSION;
- rc = ibmvtpm_send_crq(ibmvtpm->vdev, buf[0], buf[1]);
+ rc = ibmvtpm_send_crq(ibmvtpm->vdev, cpu_to_be64(buf[0]),
+ cpu_to_be64(buf[1]));
if (rc != H_SUCCESS)
dev_err(ibmvtpm->dev,
"ibmvtpm_crq_get_version failed rc=%d\n", rc);
@@ -335,7 +338,8 @@ static int tpm_ibmvtpm_suspend(struct device *dev)
crq.valid = (u8)IBMVTPM_VALID_CMD;
crq.msg = (u8)VTPM_PREPARE_TO_SUSPEND;
- rc = ibmvtpm_send_crq(ibmvtpm->vdev, buf[0], buf[1]);
+ rc = ibmvtpm_send_crq(ibmvtpm->vdev, cpu_to_be64(buf[0]),
+ cpu_to_be64(buf[1]));
if (rc != H_SUCCESS)
dev_err(ibmvtpm->dev,
"tpm_ibmvtpm_suspend failed rc=%d\n", rc);
@@ -480,11 +484,11 @@ static void ibmvtpm_crq_process(struct ibmvtpm_crq *crq,
case IBMVTPM_VALID_CMD:
switch (crq->msg) {
case VTPM_GET_RTCE_BUFFER_SIZE_RES:
- if (crq->len <= 0) {
+ if (be16_to_cpu(crq->len) <= 0) {
dev_err(ibmvtpm->dev, "Invalid rtce size\n");
return;
}
- ibmvtpm->rtce_size = crq->len;
+ ibmvtpm->rtce_size = be16_to_cpu(crq->len);
ibmvtpm->rtce_buf = kmalloc(ibmvtpm->rtce_size,
GFP_KERNEL);
if (!ibmvtpm->rtce_buf) {
@@ -505,11 +509,11 @@ static void ibmvtpm_crq_process(struct ibmvtpm_crq *crq,
return;
case VTPM_GET_VERSION_RES:
- ibmvtpm->vtpm_version = crq->data;
+ ibmvtpm->vtpm_version = be32_to_cpu(crq->data);
return;
case VTPM_TPM_COMMAND_RES:
/* len of the data in rtce buffer */
- ibmvtpm->res_len = crq->len;
+ ibmvtpm->res_len = be16_to_cpu(crq->len);
wake_up_interruptible(&ibmvtpm->wq);
return;
default:
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 124/183] fixed invalid assignment of 64bit mask to host dma_boundary for scatter gather segment boundary limit.
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (122 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 123/183] Added Little Endian support to vtpm module Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 125/183] sg: fix read() error reporting Luis Henriques
` (58 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Minh Tran, James Bottomley, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Minh Duc Tran <MinhDuc.Tran@Emulex.Com>
commit f76a610a8b4b6280eaedf48f3af9d5d74e418b66 upstream.
In reference to bug https://bugzilla.redhat.com/show_bug.cgi?id=1097141
Assert is seen with AMD cpu whenever calling pci_alloc_consistent.
[ 29.406183] ------------[ cut here ]------------
[ 29.410505] kernel BUG at lib/iommu-helper.c:13!
Signed-off-by: Minh Tran <minh.tran@emulex.com>
Fixes: 6733b39a1301b0b020bbcbf3295852e93e624cb1
Signed-off-by: James Bottomley <JBottomley@Parallels.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/scsi/be2iscsi/be_main.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/scsi/be2iscsi/be_main.c b/drivers/scsi/be2iscsi/be_main.c
index 56467df3d6de..f7e9c531cc26 100644
--- a/drivers/scsi/be2iscsi/be_main.c
+++ b/drivers/scsi/be2iscsi/be_main.c
@@ -586,7 +586,6 @@ static struct beiscsi_hba *beiscsi_hba_alloc(struct pci_dev *pcidev)
"beiscsi_hba_alloc - iscsi_host_alloc failed\n");
return NULL;
}
- shost->dma_boundary = pcidev->dma_mask;
shost->max_id = BE2_MAX_SESSIONS;
shost->max_channel = 0;
shost->max_cmd_len = BEISCSI_MAX_CMD_LEN;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 125/183] sg: fix read() error reporting
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (123 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 124/183] fixed invalid assignment of 64bit mask to host dma_boundary for scatter gather segment boundary limit Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 126/183] IB/qib: Do not write EEPROM Luis Henriques
` (57 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Tony Battersby, James Bottomley, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Tony Battersby <tonyb@cybernetics.com>
commit 3b524a683af8991b4eab4182b947c65f0ce1421b upstream.
Fix SCSI generic read() incorrectly returning success after detecting an
error.
Signed-off-by: Tony Battersby <tonyb@cybernetics.com>
Acked-by: Douglas Gilbert <dgilbert@interlog.com>
Signed-off-by: James Bottomley <JBottomley@Parallels.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/scsi/sg.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/scsi/sg.c b/drivers/scsi/sg.c
index 53268aaba559..791460b798f4 100644
--- a/drivers/scsi/sg.c
+++ b/drivers/scsi/sg.c
@@ -522,7 +522,7 @@ static ssize_t
sg_new_read(Sg_fd * sfp, char __user *buf, size_t count, Sg_request * srp)
{
sg_io_hdr_t *hp = &srp->header;
- int err = 0;
+ int err = 0, err2;
int len;
if (count < SZ_SG_IO_HDR) {
@@ -551,8 +551,8 @@ sg_new_read(Sg_fd * sfp, char __user *buf, size_t count, Sg_request * srp)
goto err_out;
}
err_out:
- err = sg_finish_rem_req(srp);
- return (0 == err) ? count : err;
+ err2 = sg_finish_rem_req(srp);
+ return err ? : err2 ? : count;
}
static ssize_t
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 126/183] IB/qib: Do not write EEPROM
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (124 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 125/183] sg: fix read() error reporting Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 127/183] EDAC, amd64_edac: Prevent OOPS with >16 memory controllers Luis Henriques
` (56 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Mitko Haralanov, Mike Marciniszyn, Roland Dreier, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mitko Haralanov <mitko.haralanov@intel.com>
commit 18c0b82a3e4501511b08d0e8676fb08ac08734a3 upstream.
This changeset removes all the code that allows the driver to write to
the EEPROM and update the recorded error counters and power on hours.
These two stats are unused and writing them exposes a timing risk
which could leave the EEPROM in a bad state preventing further normal
operation of the HCA.
Reviewed-by: Mike Marciniszyn <mike.marciniszyn@intel.com>
Signed-off-by: Mitko Haralanov <mitko.haralanov@intel.com>
Signed-off-by: Mike Marciniszyn <mike.marciniszyn@intel.com>
Signed-off-by: Roland Dreier <roland@purestorage.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/infiniband/hw/qib/qib.h | 9 +-
drivers/infiniband/hw/qib/qib_eeprom.c | 181 --------------------------------
drivers/infiniband/hw/qib/qib_iba6120.c | 2 -
drivers/infiniband/hw/qib/qib_iba7220.c | 2 -
drivers/infiniband/hw/qib/qib_iba7322.c | 2 -
drivers/infiniband/hw/qib/qib_init.c | 1 -
drivers/infiniband/hw/qib/qib_sysfs.c | 24 -----
7 files changed, 1 insertion(+), 220 deletions(-)
diff --git a/drivers/infiniband/hw/qib/qib.h b/drivers/infiniband/hw/qib/qib.h
index c00ae093b6f8..b218254ee41b 100644
--- a/drivers/infiniband/hw/qib/qib.h
+++ b/drivers/infiniband/hw/qib/qib.h
@@ -1082,12 +1082,6 @@ struct qib_devdata {
/* control high-level access to EEPROM */
struct mutex eep_lock;
uint64_t traffic_wds;
- /* active time is kept in seconds, but logged in hours */
- atomic_t active_time;
- /* Below are nominal shadow of EEPROM, new since last EEPROM update */
- uint8_t eep_st_errs[QIB_EEP_LOG_CNT];
- uint8_t eep_st_new_errs[QIB_EEP_LOG_CNT];
- uint16_t eep_hrs;
/*
* masks for which bits of errs, hwerrs that cause
* each of the counters to increment.
@@ -1309,8 +1303,7 @@ int qib_twsi_blk_rd(struct qib_devdata *dd, int dev, int addr, void *buffer,
int qib_twsi_blk_wr(struct qib_devdata *dd, int dev, int addr,
const void *buffer, int len);
void qib_get_eeprom_info(struct qib_devdata *);
-int qib_update_eeprom_log(struct qib_devdata *dd);
-void qib_inc_eeprom_err(struct qib_devdata *dd, u32 eidx, u32 incr);
+#define qib_inc_eeprom_err(dd, eidx, incr)
void qib_dump_lookup_output_queue(struct qib_devdata *);
void qib_force_pio_avail_update(struct qib_devdata *);
void qib_clear_symerror_on_linkup(unsigned long opaque);
diff --git a/drivers/infiniband/hw/qib/qib_eeprom.c b/drivers/infiniband/hw/qib/qib_eeprom.c
index 4d5d71aaa2b4..e2280b07df02 100644
--- a/drivers/infiniband/hw/qib/qib_eeprom.c
+++ b/drivers/infiniband/hw/qib/qib_eeprom.c
@@ -267,190 +267,9 @@ void qib_get_eeprom_info(struct qib_devdata *dd)
"Board SN %s did not pass functional test: %s\n",
dd->serial, ifp->if_comment);
- memcpy(&dd->eep_st_errs, &ifp->if_errcntp, QIB_EEP_LOG_CNT);
- /*
- * Power-on (actually "active") hours are kept as little-endian value
- * in EEPROM, but as seconds in a (possibly as small as 24-bit)
- * atomic_t while running.
- */
- atomic_set(&dd->active_time, 0);
- dd->eep_hrs = ifp->if_powerhour[0] | (ifp->if_powerhour[1] << 8);
-
done:
vfree(buf);
bail:;
}
-/**
- * qib_update_eeprom_log - copy active-time and error counters to eeprom
- * @dd: the qlogic_ib device
- *
- * Although the time is kept as seconds in the qib_devdata struct, it is
- * rounded to hours for re-write, as we have only 16 bits in EEPROM.
- * First-cut code reads whole (expected) struct qib_flash, modifies,
- * re-writes. Future direction: read/write only what we need, assuming
- * that the EEPROM had to have been "good enough" for driver init, and
- * if not, we aren't making it worse.
- *
- */
-int qib_update_eeprom_log(struct qib_devdata *dd)
-{
- void *buf;
- struct qib_flash *ifp;
- int len, hi_water;
- uint32_t new_time, new_hrs;
- u8 csum;
- int ret, idx;
- unsigned long flags;
-
- /* first, check if we actually need to do anything. */
- ret = 0;
- for (idx = 0; idx < QIB_EEP_LOG_CNT; ++idx) {
- if (dd->eep_st_new_errs[idx]) {
- ret = 1;
- break;
- }
- }
- new_time = atomic_read(&dd->active_time);
-
- if (ret == 0 && new_time < 3600)
- goto bail;
-
- /*
- * The quick-check above determined that there is something worthy
- * of logging, so get current contents and do a more detailed idea.
- * read full flash, not just currently used part, since it may have
- * been written with a newer definition
- */
- len = sizeof(struct qib_flash);
- buf = vmalloc(len);
- ret = 1;
- if (!buf) {
- qib_dev_err(dd,
- "Couldn't allocate memory to read %u bytes from eeprom for logging\n",
- len);
- goto bail;
- }
-
- /* Grab semaphore and read current EEPROM. If we get an
- * error, let go, but if not, keep it until we finish write.
- */
- ret = mutex_lock_interruptible(&dd->eep_lock);
- if (ret) {
- qib_dev_err(dd, "Unable to acquire EEPROM for logging\n");
- goto free_bail;
- }
- ret = qib_twsi_blk_rd(dd, dd->twsi_eeprom_dev, 0, buf, len);
- if (ret) {
- mutex_unlock(&dd->eep_lock);
- qib_dev_err(dd, "Unable read EEPROM for logging\n");
- goto free_bail;
- }
- ifp = (struct qib_flash *)buf;
-
- csum = flash_csum(ifp, 0);
- if (csum != ifp->if_csum) {
- mutex_unlock(&dd->eep_lock);
- qib_dev_err(dd, "EEPROM cks err (0x%02X, S/B 0x%02X)\n",
- csum, ifp->if_csum);
- ret = 1;
- goto free_bail;
- }
- hi_water = 0;
- spin_lock_irqsave(&dd->eep_st_lock, flags);
- for (idx = 0; idx < QIB_EEP_LOG_CNT; ++idx) {
- int new_val = dd->eep_st_new_errs[idx];
- if (new_val) {
- /*
- * If we have seen any errors, add to EEPROM values
- * We need to saturate at 0xFF (255) and we also
- * would need to adjust the checksum if we were
- * trying to minimize EEPROM traffic
- * Note that we add to actual current count in EEPROM,
- * in case it was altered while we were running.
- */
- new_val += ifp->if_errcntp[idx];
- if (new_val > 0xFF)
- new_val = 0xFF;
- if (ifp->if_errcntp[idx] != new_val) {
- ifp->if_errcntp[idx] = new_val;
- hi_water = offsetof(struct qib_flash,
- if_errcntp) + idx;
- }
- /*
- * update our shadow (used to minimize EEPROM
- * traffic), to match what we are about to write.
- */
- dd->eep_st_errs[idx] = new_val;
- dd->eep_st_new_errs[idx] = 0;
- }
- }
- /*
- * Now update active-time. We would like to round to the nearest hour
- * but unless atomic_t are sure to be proper signed ints we cannot,
- * because we need to account for what we "transfer" to EEPROM and
- * if we log an hour at 31 minutes, then we would need to set
- * active_time to -29 to accurately count the _next_ hour.
- */
- if (new_time >= 3600) {
- new_hrs = new_time / 3600;
- atomic_sub((new_hrs * 3600), &dd->active_time);
- new_hrs += dd->eep_hrs;
- if (new_hrs > 0xFFFF)
- new_hrs = 0xFFFF;
- dd->eep_hrs = new_hrs;
- if ((new_hrs & 0xFF) != ifp->if_powerhour[0]) {
- ifp->if_powerhour[0] = new_hrs & 0xFF;
- hi_water = offsetof(struct qib_flash, if_powerhour);
- }
- if ((new_hrs >> 8) != ifp->if_powerhour[1]) {
- ifp->if_powerhour[1] = new_hrs >> 8;
- hi_water = offsetof(struct qib_flash, if_powerhour) + 1;
- }
- }
- /*
- * There is a tiny possibility that we could somehow fail to write
- * the EEPROM after updating our shadows, but problems from holding
- * the spinlock too long are a much bigger issue.
- */
- spin_unlock_irqrestore(&dd->eep_st_lock, flags);
- if (hi_water) {
- /* we made some change to the data, uopdate cksum and write */
- csum = flash_csum(ifp, 1);
- ret = eeprom_write_with_enable(dd, 0, buf, hi_water + 1);
- }
- mutex_unlock(&dd->eep_lock);
- if (ret)
- qib_dev_err(dd, "Failed updating EEPROM\n");
-
-free_bail:
- vfree(buf);
-bail:
- return ret;
-}
-
-/**
- * qib_inc_eeprom_err - increment one of the four error counters
- * that are logged to EEPROM.
- * @dd: the qlogic_ib device
- * @eidx: 0..3, the counter to increment
- * @incr: how much to add
- *
- * Each counter is 8-bits, and saturates at 255 (0xFF). They
- * are copied to the EEPROM (aka flash) whenever qib_update_eeprom_log()
- * is called, but it can only be called in a context that allows sleep.
- * This function can be called even at interrupt level.
- */
-void qib_inc_eeprom_err(struct qib_devdata *dd, u32 eidx, u32 incr)
-{
- uint new_val;
- unsigned long flags;
-
- spin_lock_irqsave(&dd->eep_st_lock, flags);
- new_val = dd->eep_st_new_errs[eidx] + incr;
- if (new_val > 255)
- new_val = 255;
- dd->eep_st_new_errs[eidx] = new_val;
- spin_unlock_irqrestore(&dd->eep_st_lock, flags);
-}
diff --git a/drivers/infiniband/hw/qib/qib_iba6120.c b/drivers/infiniband/hw/qib/qib_iba6120.c
index d68266ac7619..f7f49a6c34b0 100644
--- a/drivers/infiniband/hw/qib/qib_iba6120.c
+++ b/drivers/infiniband/hw/qib/qib_iba6120.c
@@ -2681,8 +2681,6 @@ static void qib_get_6120_faststats(unsigned long opaque)
spin_lock_irqsave(&dd->eep_st_lock, flags);
traffic_wds -= dd->traffic_wds;
dd->traffic_wds += traffic_wds;
- if (traffic_wds >= QIB_TRAFFIC_ACTIVE_THRESHOLD)
- atomic_add(5, &dd->active_time); /* S/B #define */
spin_unlock_irqrestore(&dd->eep_st_lock, flags);
qib_chk_6120_errormask(dd);
diff --git a/drivers/infiniband/hw/qib/qib_iba7220.c b/drivers/infiniband/hw/qib/qib_iba7220.c
index 7dec89fdc124..f5fa106e1992 100644
--- a/drivers/infiniband/hw/qib/qib_iba7220.c
+++ b/drivers/infiniband/hw/qib/qib_iba7220.c
@@ -3297,8 +3297,6 @@ static void qib_get_7220_faststats(unsigned long opaque)
spin_lock_irqsave(&dd->eep_st_lock, flags);
traffic_wds -= dd->traffic_wds;
dd->traffic_wds += traffic_wds;
- if (traffic_wds >= QIB_TRAFFIC_ACTIVE_THRESHOLD)
- atomic_add(5, &dd->active_time); /* S/B #define */
spin_unlock_irqrestore(&dd->eep_st_lock, flags);
done:
mod_timer(&dd->stats_timer, jiffies + HZ * ACTIVITY_TIMER);
diff --git a/drivers/infiniband/hw/qib/qib_iba7322.c b/drivers/infiniband/hw/qib/qib_iba7322.c
index a7eb32517a04..23ca2aca1ad6 100644
--- a/drivers/infiniband/hw/qib/qib_iba7322.c
+++ b/drivers/infiniband/hw/qib/qib_iba7322.c
@@ -5178,8 +5178,6 @@ static void qib_get_7322_faststats(unsigned long opaque)
spin_lock_irqsave(&ppd->dd->eep_st_lock, flags);
traffic_wds -= ppd->dd->traffic_wds;
ppd->dd->traffic_wds += traffic_wds;
- if (traffic_wds >= QIB_TRAFFIC_ACTIVE_THRESHOLD)
- atomic_add(ACTIVITY_TIMER, &ppd->dd->active_time);
spin_unlock_irqrestore(&ppd->dd->eep_st_lock, flags);
if (ppd->cpspec->qdr_dfe_on && (ppd->link_speed_active &
QIB_IB_QDR) &&
diff --git a/drivers/infiniband/hw/qib/qib_init.c b/drivers/infiniband/hw/qib/qib_init.c
index 8d3c78ddc906..38c5c95f9f95 100644
--- a/drivers/infiniband/hw/qib/qib_init.c
+++ b/drivers/infiniband/hw/qib/qib_init.c
@@ -931,7 +931,6 @@ static void qib_shutdown_device(struct qib_devdata *dd)
qib_free_pportdata(ppd);
}
- qib_update_eeprom_log(dd);
}
/**
diff --git a/drivers/infiniband/hw/qib/qib_sysfs.c b/drivers/infiniband/hw/qib/qib_sysfs.c
index 3c8e4e3caca6..b9ccbda7817d 100644
--- a/drivers/infiniband/hw/qib/qib_sysfs.c
+++ b/drivers/infiniband/hw/qib/qib_sysfs.c
@@ -611,28 +611,6 @@ bail:
return ret < 0 ? ret : count;
}
-static ssize_t show_logged_errs(struct device *device,
- struct device_attribute *attr, char *buf)
-{
- struct qib_ibdev *dev =
- container_of(device, struct qib_ibdev, ibdev.dev);
- struct qib_devdata *dd = dd_from_dev(dev);
- int idx, count;
-
- /* force consistency with actual EEPROM */
- if (qib_update_eeprom_log(dd) != 0)
- return -ENXIO;
-
- count = 0;
- for (idx = 0; idx < QIB_EEP_LOG_CNT; ++idx) {
- count += scnprintf(buf + count, PAGE_SIZE - count, "%d%c",
- dd->eep_st_errs[idx],
- idx == (QIB_EEP_LOG_CNT - 1) ? '\n' : ' ');
- }
-
- return count;
-}
-
/*
* Dump tempsense regs. in decimal, to ease shell-scripts.
*/
@@ -679,7 +657,6 @@ static DEVICE_ATTR(nctxts, S_IRUGO, show_nctxts, NULL);
static DEVICE_ATTR(nfreectxts, S_IRUGO, show_nfreectxts, NULL);
static DEVICE_ATTR(serial, S_IRUGO, show_serial, NULL);
static DEVICE_ATTR(boardversion, S_IRUGO, show_boardversion, NULL);
-static DEVICE_ATTR(logged_errors, S_IRUGO, show_logged_errs, NULL);
static DEVICE_ATTR(tempsense, S_IRUGO, show_tempsense, NULL);
static DEVICE_ATTR(localbus_info, S_IRUGO, show_localbus_info, NULL);
static DEVICE_ATTR(chip_reset, S_IWUSR, NULL, store_chip_reset);
@@ -693,7 +670,6 @@ static struct device_attribute *qib_attributes[] = {
&dev_attr_nfreectxts,
&dev_attr_serial,
&dev_attr_boardversion,
- &dev_attr_logged_errors,
&dev_attr_tempsense,
&dev_attr_localbus_info,
&dev_attr_chip_reset,
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 127/183] EDAC, amd64_edac: Prevent OOPS with >16 memory controllers
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (125 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 126/183] IB/qib: Do not write EEPROM Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 128/183] MIPS: asm: asmmacro: Replace "add" instructions with "addu" Luis Henriques
` (55 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Daniel J Blueman, Borislav Petkov, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel J Blueman <daniel@numascale.com>
commit 0c510cc83bdbaac8406f4f7caef34f4da0ba35ea upstream.
When DRAM errors occur on memory controllers after EDAC_MAX_MCS (16),
the kernel fatally dereferences unallocated structures, see splat below;
this occurs on at least NumaConnect systems.
Fix by checking if a memory controller info structure was found.
BUG: unable to handle kernel NULL pointer dereference at 0000000000000320
IP: [<ffffffff819f714f>] decode_bus_error+0x2f/0x2b0
PGD 2f8b5a3067 PUD 2f8b5a2067 PMD 0
Oops: 0000 [#2] SMP
Modules linked in:
CPU: 224 PID: 11930 Comm: stream_c.exe.gn Tainted: G D 3.19.0 #1
Hardware name: Supermicro H8QGL/H8QGL, BIOS 3.5b 01/28/2015
task: ffff8807dbfb8c00 ti: ffff8807dd16c000 task.ti: ffff8807dd16c000
RIP: 0010:[<ffffffff819f714f>] [<ffffffff819f714f>] decode_bus_error+0x2f/0x2b0
RSP: 0000:ffff8907dfc03c48 EFLAGS: 00010297
RAX: 0000000000000001 RBX: 9c67400010080a13 RCX: 0000000000001dc6
RDX: 000000001dc61dc6 RSI: ffff8907dfc03df0 RDI: 000000000000001c
RBP: ffff8907dfc03ce8 R08: 0000000000000000 R09: 0000000000000022
R10: ffff891fffa30380 R11: 00000000001cfc90 R12: 0000000000000008
R13: 0000000000000000 R14: 000000000000001c R15: 00009c6740001000
FS: 00007fa97ee18700(0000) GS:ffff8907dfc00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000320 CR3: 0000003f889b8000 CR4: 00000000000407e0
Stack:
0000000000000000 ffff8907dfc03df0 0000000000000008 9c67400010080a13
000000000000001c 00009c6740001000 ffff8907dfc03c88 ffffffff810e4f9a
ffff8907dfc03ce8 ffffffff81b375b9 0000000000000000 0000000000000010
Call Trace:
<IRQ>
? vprintk_default
? printk
amd_decode_mce
notifier_call_chain
atomic_notifier_call_chain
mce_log
machine_check_poll
mce_timer_fn
? mce_cpu_restart
call_timer_fn.isra.29
run_timer_softirq
__do_softirq
irq_exit
smp_apic_timer_interrupt
apic_timer_interrupt
<EOI>
? down_read_trylock
__do_page_fault
? __schedule
do_page_fault
page_fault
Signed-off-by: Daniel J Blueman <daniel@numascale.com>
Link: http://lkml.kernel.org/r/1424144078-24589-1-git-send-email-daniel@numascale.com
[ Boris: massage commit message ]
Signed-off-by: Borislav Petkov <bp@suse.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/edac/amd64_edac.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/edac/amd64_edac.c b/drivers/edac/amd64_edac.c
index f8bf00010d45..4af3ae4fcd96 100644
--- a/drivers/edac/amd64_edac.c
+++ b/drivers/edac/amd64_edac.c
@@ -2025,14 +2025,20 @@ static void __log_bus_error(struct mem_ctl_info *mci, struct err_info *err,
static inline void decode_bus_error(int node_id, struct mce *m)
{
- struct mem_ctl_info *mci = mcis[node_id];
- struct amd64_pvt *pvt = mci->pvt_info;
+ struct mem_ctl_info *mci;
+ struct amd64_pvt *pvt;
u8 ecc_type = (m->status >> 45) & 0x3;
u8 xec = XEC(m->status, 0x1f);
u16 ec = EC(m->status);
u64 sys_addr;
struct err_info err;
+ mci = edac_mc_find(node_id);
+ if (!mci)
+ return;
+
+ pvt = mci->pvt_info;
+
/* Bail out early if this was an 'observed' error */
if (PP(ec) == NBSL_PP_OBS)
return;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 128/183] MIPS: asm: asmmacro: Replace "add" instructions with "addu"
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (126 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 127/183] EDAC, amd64_edac: Prevent OOPS with >16 memory controllers Luis Henriques
@ 2015-03-06 9:56 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 129/183] MIPS: kernel: cps-vec: Replace "addi" with "addiu" Luis Henriques
` (54 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:56 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Paul Burton, Maciej W. Rozycki, Markos Chandras, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Markos Chandras <markos.chandras@imgtec.com>
commit 98a833c1fa4de0695830f77b2d13fd86693da298 upstream.
The "add" instruction is actually a macro in binutils and depending on
the size of the immediate it can expand to an "addi" instruction.
However, the "addi" instruction traps on overflows which is not
something we want on address calculation.
Link: http://www.linux-mips.org/archives/linux-mips/2015-01/msg00121.html
Cc: Paul Burton <paul.burton@imgtec.com>
Cc: Maciej W. Rozycki <macro@linux-mips.org>
Signed-off-by: Markos Chandras <markos.chandras@imgtec.com>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/mips/include/asm/asmmacro.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/mips/include/asm/asmmacro.h b/arch/mips/include/asm/asmmacro.h
index 935543f14538..9dbc454ad14e 100644
--- a/arch/mips/include/asm/asmmacro.h
+++ b/arch/mips/include/asm/asmmacro.h
@@ -293,7 +293,7 @@
.macro ld_d wd, off, base
.set push
.set noat
- add $1, \base, \off
+ addu $1, \base, \off
.word LDD_MSA_INSN | (\wd << 6)
.set pop
.endm
@@ -301,7 +301,7 @@
.macro st_d wd, off, base
.set push
.set noat
- add $1, \base, \off
+ addu $1, \base, \off
.word STD_MSA_INSN | (\wd << 6)
.set pop
.endm
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 129/183] MIPS: kernel: cps-vec: Replace "addi" with "addiu"
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (127 preceding siblings ...)
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 128/183] MIPS: asm: asmmacro: Replace "add" instructions with "addu" Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 130/183] md/raid5: Fix livelock when array is both resyncing and degraded Luis Henriques
` (53 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Maciej W. Rozycki, Paul Burton, Markos Chandras, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Markos Chandras <markos.chandras@imgtec.com>
commit acac4108df6029c03195513ead7073bbb0cb9718 upstream.
The "addi" instruction will trap on overflows which is not something
we need in this code, so we replace that with "addiu".
Link: http://www.linux-mips.org/archives/linux-mips/2015-01/msg00430.html
Cc: Maciej W. Rozycki <macro@linux-mips.org>
Cc: Paul Burton <paul.burton@imgtec.com>
Signed-off-by: Markos Chandras <markos.chandras@imgtec.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/mips/kernel/cps-vec.S | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/arch/mips/kernel/cps-vec.S b/arch/mips/kernel/cps-vec.S
index e6e97d2a5c9e..3b3fb8924628 100644
--- a/arch/mips/kernel/cps-vec.S
+++ b/arch/mips/kernel/cps-vec.S
@@ -99,11 +99,11 @@ not_nmi:
xori t2, t1, 0x7
beqz t2, 1f
li t3, 32
- addi t1, t1, 1
+ addiu t1, t1, 1
sllv t1, t3, t1
1: /* At this point t1 == I-cache sets per way */
_EXT t2, v0, MIPS_CONF1_IA_SHF, MIPS_CONF1_IA_SZ
- addi t2, t2, 1
+ addiu t2, t2, 1
mul t1, t1, t0
mul t1, t1, t2
@@ -126,11 +126,11 @@ icache_done:
xori t2, t1, 0x7
beqz t2, 1f
li t3, 32
- addi t1, t1, 1
+ addiu t1, t1, 1
sllv t1, t3, t1
1: /* At this point t1 == D-cache sets per way */
_EXT t2, v0, MIPS_CONF1_DA_SHF, MIPS_CONF1_DA_SZ
- addi t2, t2, 1
+ addiu t2, t2, 1
mul t1, t1, t0
mul t1, t1, t2
@@ -249,7 +249,7 @@ LEAF(mips_cps_core_init)
mfc0 t0, CP0_MVPCONF0
srl t0, t0, MVPCONF0_PVPE_SHIFT
andi t0, t0, (MVPCONF0_PVPE >> MVPCONF0_PVPE_SHIFT)
- addi t7, t0, 1
+ addiu t7, t0, 1
/* If there's only 1, we're done */
beqz t0, 2f
@@ -279,7 +279,7 @@ LEAF(mips_cps_core_init)
mttc0 t0, CP0_TCHALT
/* Next VPE */
- addi t5, t5, 1
+ addiu t5, t5, 1
slt t0, t5, t7
bnez t0, 1b
nop
@@ -316,7 +316,7 @@ LEAF(mips_cps_boot_vpes)
mfc0 t1, CP0_MVPCONF0
srl t1, t1, MVPCONF0_PVPE_SHIFT
andi t1, t1, MVPCONF0_PVPE >> MVPCONF0_PVPE_SHIFT
- addi t1, t1, 1
+ addiu t1, t1, 1
/* Calculate a mask for the VPE ID from EBase.CPUNum */
clz t1, t1
@@ -422,7 +422,7 @@ LEAF(mips_cps_boot_vpes)
/* Next VPE */
2: srl t6, t6, 1
- addi t5, t5, 1
+ addiu t5, t5, 1
bnez t6, 1b
nop
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 130/183] md/raid5: Fix livelock when array is both resyncing and degraded.
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (128 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 129/183] MIPS: kernel: cps-vec: Replace "addi" with "addiu" Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 131/183] locking/rtmutex: Avoid a NULL pointer dereference on deadlock Luis Henriques
` (52 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: NeilBrown, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: NeilBrown <neilb@suse.de>
commit 26ac107378c4742978216be1005b7291b799c7b2 upstream.
Commit a7854487cd7128a30a7f4f5259de9f67d5efb95f:
md: When RAID5 is dirty, force reconstruct-write instead of read-modify-write.
Causes an RCW cycle to be forced even when the array is degraded.
A degraded array cannot support RCW as that requires reading all data
blocks, and one may be missing.
Forcing an RCW when it is not possible causes a live-lock and the code
spins, repeatedly deciding to do something that cannot succeed.
So change the condition to only force RCW on non-degraded arrays.
Reported-by: Manibalan P <pmanibalan@amiindia.co.in>
Bisected-by: Jes Sorensen <Jes.Sorensen@redhat.com>
Tested-by: Jes Sorensen <Jes.Sorensen@redhat.com>
Signed-off-by: NeilBrown <neilb@suse.de>
Fixes: a7854487cd7128a30a7f4f5259de9f67d5efb95f
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/md/raid5.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/md/raid5.c b/drivers/md/raid5.c
index 68a03d7f25ee..b1b9efb5359f 100644
--- a/drivers/md/raid5.c
+++ b/drivers/md/raid5.c
@@ -3111,7 +3111,8 @@ static void handle_stripe_dirtying(struct r5conf *conf,
* generate correct data from the parity.
*/
if (conf->max_degraded == 2 ||
- (recovery_cp < MaxSector && sh->sector >= recovery_cp)) {
+ (recovery_cp < MaxSector && sh->sector >= recovery_cp &&
+ s->failed == 0)) {
/* Calculate the real rcw later - for now make it
* look like rcw is cheaper
*/
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 131/183] locking/rtmutex: Avoid a NULL pointer dereference on deadlock
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (129 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 130/183] md/raid5: Fix livelock when array is both resyncing and degraded Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 132/183] time: adjtimex: Validate the ADJ_FREQUENCY values Luis Henriques
` (51 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Sebastian Andrzej Siewior, Thomas Gleixner, Ingo Molnar, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
commit 8d1e5a1a1ccf5ae9d8a5a0ee7960202ccb0c5429 upstream.
With task_blocks_on_rt_mutex() returning early -EDEADLK we never
add the waiter to the waitqueue. Later, we try to remove it via
remove_waiter() and go boom in rt_mutex_top_waiter() because
rb_entry() gives a NULL pointer.
( Tested on v3.18-RT where rtmutex is used for regular mutex and I
tried to get one twice in a row. )
Not sure when this started but I guess 397335f004f4 ("rtmutex: Fix
deadlock detector for real") or commit 3d5c9340d194 ("rtmutex:
Handle deadlock detection smarter").
Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Acked-by: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Link: http://lkml.kernel.org/r/1424187823-19600-1-git-send-email-bigeasy@linutronix.de
Signed-off-by: Ingo Molnar <mingo@kernel.org>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
kernel/locking/rtmutex.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/kernel/locking/rtmutex.c b/kernel/locking/rtmutex.c
index fc605941b9b8..f9878d16b80b 100644
--- a/kernel/locking/rtmutex.c
+++ b/kernel/locking/rtmutex.c
@@ -936,7 +936,8 @@ rt_mutex_slowlock(struct rt_mutex *lock, int state,
set_current_state(TASK_RUNNING);
if (unlikely(ret)) {
- remove_waiter(lock, &waiter);
+ if (rt_mutex_has_waiters(lock))
+ remove_waiter(lock, &waiter);
rt_mutex_handle_deadlock(ret, detect_deadlock, &waiter);
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 132/183] time: adjtimex: Validate the ADJ_FREQUENCY values
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (130 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 131/183] locking/rtmutex: Avoid a NULL pointer dereference on deadlock Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 133/183] ntp: Fixup adjtimex freq validation on 32-bit systems Luis Henriques
` (50 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Thomas Gleixner, Ingo Molnar, Sasha Levin, John Stultz, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Sasha Levin <sasha.levin@oracle.com>
commit 5e5aeb4367b450a28f447f6d5ab57d8f2ab16a5f upstream.
Verify that the frequency value from userspace is valid and makes sense.
Unverified values can cause overflows later on.
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
[jstultz: Fix up bug for negative values and drop redunent cap check]
Signed-off-by: John Stultz <john.stultz@linaro.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
kernel/time/ntp.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/kernel/time/ntp.c b/kernel/time/ntp.c
index 33db43a39515..3fca3fdd7c82 100644
--- a/kernel/time/ntp.c
+++ b/kernel/time/ntp.c
@@ -632,6 +632,13 @@ int ntp_validate_timex(struct timex *txc)
if ((txc->modes & ADJ_SETOFFSET) && (!capable(CAP_SYS_TIME)))
return -EPERM;
+ if (txc->modes & ADJ_FREQUENCY) {
+ if (LONG_MIN / PPM_SCALE > txc->freq)
+ return -EINVAL;
+ if (LONG_MAX / PPM_SCALE < txc->freq)
+ return -EINVAL;
+ }
+
return 0;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 133/183] ntp: Fixup adjtimex freq validation on 32-bit systems
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (131 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 132/183] time: adjtimex: Validate the ADJ_FREQUENCY values Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 134/183] dm: fix a race condition in dm_get_md Luis Henriques
` (49 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: John Stultz, Peter Zijlstra (Intel),
Linus Torvalds, Sasha Levin, Ingo Molnar, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: John Stultz <john.stultz@linaro.org>
commit 29183a70b0b828500816bd794b3fe192fce89f73 upstream.
Additional validation of adjtimex freq values to avoid
potential multiplication overflows were added in commit
5e5aeb4367b (time: adjtimex: Validate the ADJ_FREQUENCY values)
Unfortunately the patch used LONG_MAX/MIN instead of
LLONG_MAX/MIN, which was fine on 64-bit systems, but being
much smaller on 32-bit systems caused false positives
resulting in most direct frequency adjustments to fail w/
EINVAL.
ntpd only does direct frequency adjustments at startup, so
the issue was not as easily observed there, but other time
sync applications like ptpd and chrony were more effected by
the bug.
See bugs:
https://bugzilla.kernel.org/show_bug.cgi?id=92481
https://bugzilla.redhat.com/show_bug.cgi?id=1188074
This patch changes the checks to use LLONG_MAX for
clarity, and additionally the checks are disabled
on 32-bit systems since LLONG_MAX/PPM_SCALE is always
larger then the 32-bit long freq value, so multiplication
overflows aren't possible there.
Reported-by: Josh Boyer <jwboyer@fedoraproject.org>
Reported-by: George Joseph <george.joseph@fairview5.com>
Tested-by: George Joseph <george.joseph@fairview5.com>
Signed-off-by: John Stultz <john.stultz@linaro.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Sasha Levin <sasha.levin@oracle.com>
Link: http://lkml.kernel.org/r/1423553436-29747-1-git-send-email-john.stultz@linaro.org
[ Prettified the changelog and the comments a bit. ]
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
kernel/time/ntp.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/kernel/time/ntp.c b/kernel/time/ntp.c
index 3fca3fdd7c82..b1d6d26dbdc3 100644
--- a/kernel/time/ntp.c
+++ b/kernel/time/ntp.c
@@ -632,10 +632,14 @@ int ntp_validate_timex(struct timex *txc)
if ((txc->modes & ADJ_SETOFFSET) && (!capable(CAP_SYS_TIME)))
return -EPERM;
- if (txc->modes & ADJ_FREQUENCY) {
- if (LONG_MIN / PPM_SCALE > txc->freq)
+ /*
+ * Check for potential multiplication overflows that can
+ * only happen on 64-bit systems:
+ */
+ if ((txc->modes & ADJ_FREQUENCY) && (BITS_PER_LONG == 64)) {
+ if (LLONG_MIN / PPM_SCALE > txc->freq)
return -EINVAL;
- if (LONG_MAX / PPM_SCALE < txc->freq)
+ if (LLONG_MAX / PPM_SCALE < txc->freq)
return -EINVAL;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 134/183] dm: fix a race condition in dm_get_md
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (132 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 133/183] ntp: Fixup adjtimex freq validation on 32-bit systems Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 135/183] dm snapshot: fix a possible invalid memory access on unload Luis Henriques
` (48 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Mikulas Patocka, Mike Snitzer, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikulas Patocka <mpatocka@redhat.com>
commit 2bec1f4a8832e74ebbe859f176d8a9cb20dd97f4 upstream.
The function dm_get_md finds a device mapper device with a given dev_t,
increases the reference count and returns the pointer.
dm_get_md calls dm_find_md, dm_find_md takes _minor_lock, finds the
device, tests that the device doesn't have DMF_DELETING or DMF_FREEING
flag, drops _minor_lock and returns pointer to the device. dm_get_md then
calls dm_get. dm_get calls BUG if the device has the DMF_FREEING flag,
otherwise it increments the reference count.
There is a possible race condition - after dm_find_md exits and before
dm_get is called, there are no locks held, so the device may disappear or
DMF_FREEING flag may be set, which results in BUG.
To fix this bug, we need to call dm_get while we hold _minor_lock. This
patch renames dm_find_md to dm_get_md and changes it so that it calls
dm_get while holding the lock.
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/md/dm.c | 27 ++++++++++-----------------
1 file changed, 10 insertions(+), 17 deletions(-)
diff --git a/drivers/md/dm.c b/drivers/md/dm.c
index 00a6cff2fffd..e705042a997c 100644
--- a/drivers/md/dm.c
+++ b/drivers/md/dm.c
@@ -2341,7 +2341,7 @@ int dm_setup_md_queue(struct mapped_device *md)
return 0;
}
-static struct mapped_device *dm_find_md(dev_t dev)
+struct mapped_device *dm_get_md(dev_t dev)
{
struct mapped_device *md;
unsigned minor = MINOR(dev);
@@ -2352,12 +2352,15 @@ static struct mapped_device *dm_find_md(dev_t dev)
spin_lock(&_minor_lock);
md = idr_find(&_minor_idr, minor);
- if (md && (md == MINOR_ALLOCED ||
- (MINOR(disk_devt(dm_disk(md))) != minor) ||
- dm_deleting_md(md) ||
- test_bit(DMF_FREEING, &md->flags))) {
- md = NULL;
- goto out;
+ if (md) {
+ if ((md == MINOR_ALLOCED ||
+ (MINOR(disk_devt(dm_disk(md))) != minor) ||
+ dm_deleting_md(md) ||
+ test_bit(DMF_FREEING, &md->flags))) {
+ md = NULL;
+ goto out;
+ }
+ dm_get(md);
}
out:
@@ -2365,16 +2368,6 @@ out:
return md;
}
-
-struct mapped_device *dm_get_md(dev_t dev)
-{
- struct mapped_device *md = dm_find_md(dev);
-
- if (md)
- dm_get(md);
-
- return md;
-}
EXPORT_SYMBOL_GPL(dm_get_md);
void *dm_get_mdptr(struct mapped_device *md)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 135/183] dm snapshot: fix a possible invalid memory access on unload
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (133 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 134/183] dm: fix a race condition in dm_get_md Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 136/183] cpufreq: s3c: remove incorrect __init annotations Luis Henriques
` (47 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Mikulas Patocka, Mike Snitzer, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikulas Patocka <mpatocka@redhat.com>
commit 22aa66a3ee5b61e0f4a0bfeabcaa567861109ec3 upstream.
When the snapshot target is unloaded, snapshot_dtr() waits until
pending_exceptions_count drops to zero. Then, it destroys the snapshot.
Therefore, the function that decrements pending_exceptions_count
should not touch the snapshot structure after the decrement.
pending_complete() calls free_pending_exception(), which decrements
pending_exceptions_count, and then it performs up_write(&s->lock) and it
calls retry_origin_bios() which dereferences s->origin. These two
memory accesses to the fields of the snapshot may touch the dm_snapshot
struture after it is freed.
This patch moves the call to free_pending_exception() to the end of
pending_complete(), so that the snapshot will not be destroyed while
pending_complete() is in progress.
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/md/dm-snap.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/md/dm-snap.c b/drivers/md/dm-snap.c
index 5bd2290cfb1e..8380d036eec3 100644
--- a/drivers/md/dm-snap.c
+++ b/drivers/md/dm-snap.c
@@ -1440,8 +1440,6 @@ out:
full_bio->bi_private = pe->full_bio_private;
atomic_inc(&full_bio->bi_remaining);
}
- free_pending_exception(pe);
-
increment_pending_exceptions_done_count();
up_write(&s->lock);
@@ -1458,6 +1456,8 @@ out:
}
retry_origin_bios(s, origin_bios);
+
+ free_pending_exception(pe);
}
static void commit_callback(void *context, int success)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 136/183] cpufreq: s3c: remove incorrect __init annotations
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (134 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 135/183] dm snapshot: fix a possible invalid memory access on unload Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 137/183] x86, mm/ASLR: Fix stack randomization on 64-bit systems Luis Henriques
` (46 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Arnd Bergmann, Rafael J. Wysocki, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnd Bergmann <arnd@arndb.de>
commit 61882b63171736571e1139ab5aa929e3bb336016 upstream.
The two functions s3c2416_cpufreq_driver_init and s3c_cpufreq_register
are marked init but are called from a context that might be run after
the __init sections are discarded, as the compiler points out:
WARNING: vmlinux.o(.data+0x1ad9dc): Section mismatch in reference from the variable s3c2416_cpufreq_driver to the function .init.text:s3c2416_cpufreq_driver_init()
WARNING: drivers/built-in.o(.text+0x35b5dc): Section mismatch in reference from the function s3c2410a_cpufreq_add() to the function .init.text:s3c_cpufreq_register()
This removes the __init markings.
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Acked-by: Viresh Kumar <viresh.kumar@linaro.org>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/cpufreq/s3c2416-cpufreq.c | 4 ++--
drivers/cpufreq/s3c24xx-cpufreq.c | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/cpufreq/s3c2416-cpufreq.c b/drivers/cpufreq/s3c2416-cpufreq.c
index 2fd53eaaec20..d6d425773fa4 100644
--- a/drivers/cpufreq/s3c2416-cpufreq.c
+++ b/drivers/cpufreq/s3c2416-cpufreq.c
@@ -263,7 +263,7 @@ out:
}
#ifdef CONFIG_ARM_S3C2416_CPUFREQ_VCORESCALE
-static void __init s3c2416_cpufreq_cfg_regulator(struct s3c2416_data *s3c_freq)
+static void s3c2416_cpufreq_cfg_regulator(struct s3c2416_data *s3c_freq)
{
int count, v, i, found;
struct cpufreq_frequency_table *pos;
@@ -333,7 +333,7 @@ static struct notifier_block s3c2416_cpufreq_reboot_notifier = {
.notifier_call = s3c2416_cpufreq_reboot_notifier_evt,
};
-static int __init s3c2416_cpufreq_driver_init(struct cpufreq_policy *policy)
+static int s3c2416_cpufreq_driver_init(struct cpufreq_policy *policy)
{
struct s3c2416_data *s3c_freq = &s3c2416_cpufreq;
struct cpufreq_frequency_table *pos;
diff --git a/drivers/cpufreq/s3c24xx-cpufreq.c b/drivers/cpufreq/s3c24xx-cpufreq.c
index 227ebf7c1eea..176e5da16829 100644
--- a/drivers/cpufreq/s3c24xx-cpufreq.c
+++ b/drivers/cpufreq/s3c24xx-cpufreq.c
@@ -455,7 +455,7 @@ static struct cpufreq_driver s3c24xx_driver = {
};
-int __init s3c_cpufreq_register(struct s3c_cpufreq_info *info)
+int s3c_cpufreq_register(struct s3c_cpufreq_info *info)
{
if (!info || !info->name) {
printk(KERN_ERR "%s: failed to pass valid information\n",
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 137/183] x86, mm/ASLR: Fix stack randomization on 64-bit systems
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (135 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 136/183] cpufreq: s3c: remove incorrect __init annotations Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 138/183] libceph: assert both regular and lingering lists in __remove_osd() Luis Henriques
` (45 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Hector Marco-Gisbert, Ismael Ripoll, Kees Cook, Linus Torvalds,
Andrew Morton, Al Viro, Borislav Petkov, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Hector Marco-Gisbert <hecmargi@upv.es>
commit 4e7c22d447bb6d7e37bfe39ff658486ae78e8d77 upstream.
The issue is that the stack for processes is not properly randomized on
64 bit architectures due to an integer overflow.
The affected function is randomize_stack_top() in file
"fs/binfmt_elf.c":
static unsigned long randomize_stack_top(unsigned long stack_top)
{
unsigned int random_variable = 0;
if ((current->flags & PF_RANDOMIZE) &&
!(current->personality & ADDR_NO_RANDOMIZE)) {
random_variable = get_random_int() & STACK_RND_MASK;
random_variable <<= PAGE_SHIFT;
}
return PAGE_ALIGN(stack_top) + random_variable;
return PAGE_ALIGN(stack_top) - random_variable;
}
Note that, it declares the "random_variable" variable as "unsigned int".
Since the result of the shifting operation between STACK_RND_MASK (which
is 0x3fffff on x86_64, 22 bits) and PAGE_SHIFT (which is 12 on x86_64):
random_variable <<= PAGE_SHIFT;
then the two leftmost bits are dropped when storing the result in the
"random_variable". This variable shall be at least 34 bits long to hold
the (22+12) result.
These two dropped bits have an impact on the entropy of process stack.
Concretely, the total stack entropy is reduced by four: from 2^28 to
2^30 (One fourth of expected entropy).
This patch restores back the entropy by correcting the types involved
in the operations in the functions randomize_stack_top() and
stack_maxrandom_size().
The successful fix can be tested with:
$ for i in `seq 1 10`; do cat /proc/self/maps | grep stack; done
7ffeda566000-7ffeda587000 rw-p 00000000 00:00 0 [stack]
7fff5a332000-7fff5a353000 rw-p 00000000 00:00 0 [stack]
7ffcdb7a1000-7ffcdb7c2000 rw-p 00000000 00:00 0 [stack]
7ffd5e2c4000-7ffd5e2e5000 rw-p 00000000 00:00 0 [stack]
...
Once corrected, the leading bytes should be between 7ffc and 7fff,
rather than always being 7fff.
Signed-off-by: Hector Marco-Gisbert <hecmargi@upv.es>
Signed-off-by: Ismael Ripoll <iripoll@upv.es>
[ Rebased, fixed 80 char bugs, cleaned up commit message, added test example and CVE ]
Signed-off-by: Kees Cook <keescook@chromium.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Fixes: CVE-2015-1593
Link: http://lkml.kernel.org/r/20150214173350.GA18393@www.outflux.net
Signed-off-by: Borislav Petkov <bp@suse.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/x86/mm/mmap.c | 6 +++---
fs/binfmt_elf.c | 5 +++--
2 files changed, 6 insertions(+), 5 deletions(-)
diff --git a/arch/x86/mm/mmap.c b/arch/x86/mm/mmap.c
index 25e7e1372bb2..3601ff284b92 100644
--- a/arch/x86/mm/mmap.c
+++ b/arch/x86/mm/mmap.c
@@ -35,12 +35,12 @@ struct __read_mostly va_alignment va_align = {
.flags = -1,
};
-static unsigned int stack_maxrandom_size(void)
+static unsigned long stack_maxrandom_size(void)
{
- unsigned int max = 0;
+ unsigned long max = 0;
if ((current->flags & PF_RANDOMIZE) &&
!(current->personality & ADDR_NO_RANDOMIZE)) {
- max = ((-1U) & STACK_RND_MASK) << PAGE_SHIFT;
+ max = ((-1UL) & STACK_RND_MASK) << PAGE_SHIFT;
}
return max;
diff --git a/fs/binfmt_elf.c b/fs/binfmt_elf.c
index 3892c1a23241..c10fc70e4912 100644
--- a/fs/binfmt_elf.c
+++ b/fs/binfmt_elf.c
@@ -554,11 +554,12 @@ out:
static unsigned long randomize_stack_top(unsigned long stack_top)
{
- unsigned int random_variable = 0;
+ unsigned long random_variable = 0;
if ((current->flags & PF_RANDOMIZE) &&
!(current->personality & ADDR_NO_RANDOMIZE)) {
- random_variable = get_random_int() & STACK_RND_MASK;
+ random_variable = (unsigned long) get_random_int();
+ random_variable &= STACK_RND_MASK;
random_variable <<= PAGE_SHIFT;
}
#ifdef CONFIG_STACK_GROWSUP
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 138/183] libceph: assert both regular and lingering lists in __remove_osd()
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (136 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 137/183] x86, mm/ASLR: Fix stack randomization on 64-bit systems Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 139/183] libceph: change from BUG to WARN for __remove_osd() asserts Luis Henriques
` (44 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Ilya Dryomov, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Dryomov <ilya.dryomov@inktank.com>
commit 7c6e6fc53e7335570ed82f77656cedce1502744e upstream.
It is important that both regular and lingering requests lists are
empty when the OSD is removed.
Signed-off-by: Ilya Dryomov <ilya.dryomov@inktank.com>
Reviewed-by: Alex Elder <elder@linaro.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
net/ceph/osd_client.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/net/ceph/osd_client.c b/net/ceph/osd_client.c
index 05be0c181695..14e0387e3595 100644
--- a/net/ceph/osd_client.c
+++ b/net/ceph/osd_client.c
@@ -1008,6 +1008,8 @@ static void __remove_osd(struct ceph_osd_client *osdc, struct ceph_osd *osd)
{
dout("__remove_osd %p\n", osd);
BUG_ON(!list_empty(&osd->o_requests));
+ BUG_ON(!list_empty(&osd->o_linger_requests));
+
rb_erase(&osd->o_node, &osdc->osds);
list_del_init(&osd->o_osd_lru);
ceph_con_close(&osd->o_con);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 139/183] libceph: change from BUG to WARN for __remove_osd() asserts
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (137 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 138/183] libceph: assert both regular and lingering lists in __remove_osd() Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 140/183] libceph: fix double __remove_osd() problem Luis Henriques
` (43 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Ilya Dryomov, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Dryomov <idryomov@redhat.com>
commit cc9f1f518cec079289d11d732efa490306b1ddad upstream.
No reason to use BUG_ON for osd request list assertions.
Signed-off-by: Ilya Dryomov <idryomov@redhat.com>
Reviewed-by: Alex Elder <elder@linaro.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
net/ceph/osd_client.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/ceph/osd_client.c b/net/ceph/osd_client.c
index 14e0387e3595..18a59c60a2b7 100644
--- a/net/ceph/osd_client.c
+++ b/net/ceph/osd_client.c
@@ -1007,8 +1007,8 @@ static void put_osd(struct ceph_osd *osd)
static void __remove_osd(struct ceph_osd_client *osdc, struct ceph_osd *osd)
{
dout("__remove_osd %p\n", osd);
- BUG_ON(!list_empty(&osd->o_requests));
- BUG_ON(!list_empty(&osd->o_linger_requests));
+ WARN_ON(!list_empty(&osd->o_requests));
+ WARN_ON(!list_empty(&osd->o_linger_requests));
rb_erase(&osd->o_node, &osdc->osds);
list_del_init(&osd->o_osd_lru);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 140/183] libceph: fix double __remove_osd() problem
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (138 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 139/183] libceph: change from BUG to WARN for __remove_osd() asserts Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 141/183] MIPS: Export FP functions used by lose_fpu(1) for KVM Luis Henriques
` (42 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Sage Weil, Ilya Dryomov, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Dryomov <idryomov@gmail.com>
commit 7eb71e0351fbb1b242ae70abb7bb17107fe2f792 upstream.
It turns out it's possible to get __remove_osd() called twice on the
same OSD. That doesn't sit well with rb_erase() - depending on the
shape of the tree we can get a NULL dereference, a soft lockup or
a random crash at some point in the future as we end up touching freed
memory. One scenario that I was able to reproduce is as follows:
<osd3 is idle, on the osd lru list>
<con reset - osd3>
con_fault_finish()
osd_reset()
<osdmap - osd3 down>
ceph_osdc_handle_map()
<takes map_sem>
kick_requests()
<takes request_mutex>
reset_changed_osds()
__reset_osd()
__remove_osd()
<releases request_mutex>
<releases map_sem>
<takes map_sem>
<takes request_mutex>
__kick_osd_requests()
__reset_osd()
__remove_osd() <-- !!!
A case can be made that osd refcounting is imperfect and reworking it
would be a proper resolution, but for now Sage and I decided to fix
this by adding a safe guard around __remove_osd().
Fixes: http://tracker.ceph.com/issues/8087
Cc: Sage Weil <sage@redhat.com>
Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
Reviewed-by: Sage Weil <sage@redhat.com>
Reviewed-by: Alex Elder <elder@linaro.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
net/ceph/osd_client.c | 26 ++++++++++++++++++--------
1 file changed, 18 insertions(+), 8 deletions(-)
diff --git a/net/ceph/osd_client.c b/net/ceph/osd_client.c
index 18a59c60a2b7..8cbd41f5c424 100644
--- a/net/ceph/osd_client.c
+++ b/net/ceph/osd_client.c
@@ -1006,14 +1006,24 @@ static void put_osd(struct ceph_osd *osd)
*/
static void __remove_osd(struct ceph_osd_client *osdc, struct ceph_osd *osd)
{
- dout("__remove_osd %p\n", osd);
+ dout("%s %p osd%d\n", __func__, osd, osd->o_osd);
WARN_ON(!list_empty(&osd->o_requests));
WARN_ON(!list_empty(&osd->o_linger_requests));
- rb_erase(&osd->o_node, &osdc->osds);
list_del_init(&osd->o_osd_lru);
- ceph_con_close(&osd->o_con);
- put_osd(osd);
+ rb_erase(&osd->o_node, &osdc->osds);
+ RB_CLEAR_NODE(&osd->o_node);
+}
+
+static void remove_osd(struct ceph_osd_client *osdc, struct ceph_osd *osd)
+{
+ dout("%s %p osd%d\n", __func__, osd, osd->o_osd);
+
+ if (!RB_EMPTY_NODE(&osd->o_node)) {
+ ceph_con_close(&osd->o_con);
+ __remove_osd(osdc, osd);
+ put_osd(osd);
+ }
}
static void remove_all_osds(struct ceph_osd_client *osdc)
@@ -1023,7 +1033,7 @@ static void remove_all_osds(struct ceph_osd_client *osdc)
while (!RB_EMPTY_ROOT(&osdc->osds)) {
struct ceph_osd *osd = rb_entry(rb_first(&osdc->osds),
struct ceph_osd, o_node);
- __remove_osd(osdc, osd);
+ remove_osd(osdc, osd);
}
mutex_unlock(&osdc->request_mutex);
}
@@ -1053,7 +1063,7 @@ static void remove_old_osds(struct ceph_osd_client *osdc)
list_for_each_entry_safe(osd, nosd, &osdc->osd_lru, o_osd_lru) {
if (time_before(jiffies, osd->lru_ttl))
break;
- __remove_osd(osdc, osd);
+ remove_osd(osdc, osd);
}
mutex_unlock(&osdc->request_mutex);
}
@@ -1068,8 +1078,7 @@ static int __reset_osd(struct ceph_osd_client *osdc, struct ceph_osd *osd)
dout("__reset_osd %p osd%d\n", osd, osd->o_osd);
if (list_empty(&osd->o_requests) &&
list_empty(&osd->o_linger_requests)) {
- __remove_osd(osdc, osd);
-
+ remove_osd(osdc, osd);
return -ENODEV;
}
@@ -1869,6 +1878,7 @@ static void reset_changed_osds(struct ceph_osd_client *osdc)
{
struct rb_node *p, *n;
+ dout("%s %p\n", __func__, osdc);
for (p = rb_first(&osdc->osds); p; p = n) {
struct ceph_osd *osd = rb_entry(p, struct ceph_osd, o_node);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 141/183] MIPS: Export FP functions used by lose_fpu(1) for KVM
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (139 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 140/183] libceph: fix double __remove_osd() problem Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 142/183] MIPS: Export MSA " Luis Henriques
` (41 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: James Hogan, Paolo Bonzini, Ralf Baechle, Paul Burton,
Gleb Natapov, kvm, linux-mips, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: James Hogan <james.hogan@imgtec.com>
commit 3ce465e04bfd8de9956d515d6e9587faac3375dc upstream.
Export the _save_fp asm function used by the lose_fpu(1) macro to GPL
modules so that KVM can make use of it when it is built as a module.
This fixes the following build error when CONFIG_KVM=m due to commit
f798217dfd03 ("KVM: MIPS: Don't leak FPU/DSP to guest"):
ERROR: "_save_fp" [arch/mips/kvm/kvm.ko] undefined!
Signed-off-by: James Hogan <james.hogan@imgtec.com>
Fixes: f798217dfd03 (KVM: MIPS: Don't leak FPU/DSP to guest)
Cc: Paolo Bonzini <pbonzini@redhat.com>
Cc: Ralf Baechle <ralf@linux-mips.org>
Cc: Paul Burton <paul.burton@imgtec.com>
Cc: Gleb Natapov <gleb@kernel.org>
Cc: kvm@vger.kernel.org
Cc: linux-mips@linux-mips.org
Patchwork: https://patchwork.linux-mips.org/patch/9260/
Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/mips/kernel/mips_ksyms.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/arch/mips/kernel/mips_ksyms.c b/arch/mips/kernel/mips_ksyms.c
index 2607c3a4ff7e..e69bdd3b4b74 100644
--- a/arch/mips/kernel/mips_ksyms.c
+++ b/arch/mips/kernel/mips_ksyms.c
@@ -14,6 +14,7 @@
#include <linux/mm.h>
#include <asm/uaccess.h>
#include <asm/ftrace.h>
+#include <asm/fpu.h>
extern void *__bzero(void *__s, size_t __count);
extern long __strncpy_from_kernel_nocheck_asm(char *__to,
@@ -34,6 +35,11 @@ extern long __strnlen_user_nocheck_asm(const char *s);
extern long __strnlen_user_asm(const char *s);
/*
+ * Core architecture code
+ */
+EXPORT_SYMBOL_GPL(_save_fp);
+
+/*
* String functions
*/
EXPORT_SYMBOL(memset);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 142/183] MIPS: Export MSA functions used by lose_fpu(1) for KVM
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (140 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 141/183] MIPS: Export FP functions used by lose_fpu(1) for KVM Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 143/183] kdb: fix incorrect counts in KDB summary command output Luis Henriques
` (40 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: James Hogan, Paolo Bonzini, Ralf Baechle, Paul Burton,
Gleb Natapov, kvm, linux-mips, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: James Hogan <james.hogan@imgtec.com>
commit ca5d25642e212f73492d332d95dc90ef46a0e8dc upstream.
Export the _save_msa asm function used by the lose_fpu(1) macro to GPL
modules so that KVM can make use of it when it is built as a module.
This fixes the following build error when CONFIG_KVM=m and
CONFIG_CPU_HAS_MSA=y due to commit f798217dfd03 ("KVM: MIPS: Don't leak
FPU/DSP to guest"):
ERROR: "_save_msa" [arch/mips/kvm/kvm.ko] undefined!
Fixes: f798217dfd03 (KVM: MIPS: Don't leak FPU/DSP to guest)
Signed-off-by: James Hogan <james.hogan@imgtec.com>
Cc: Paolo Bonzini <pbonzini@redhat.com>
Cc: Ralf Baechle <ralf@linux-mips.org>
Cc: Paul Burton <paul.burton@imgtec.com>
Cc: Gleb Natapov <gleb@kernel.org>
Cc: kvm@vger.kernel.org
Cc: linux-mips@linux-mips.org
Patchwork: https://patchwork.linux-mips.org/patch/9261/
Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/mips/kernel/mips_ksyms.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/arch/mips/kernel/mips_ksyms.c b/arch/mips/kernel/mips_ksyms.c
index e69bdd3b4b74..1b2452e2be67 100644
--- a/arch/mips/kernel/mips_ksyms.c
+++ b/arch/mips/kernel/mips_ksyms.c
@@ -15,6 +15,7 @@
#include <asm/uaccess.h>
#include <asm/ftrace.h>
#include <asm/fpu.h>
+#include <asm/msa.h>
extern void *__bzero(void *__s, size_t __count);
extern long __strncpy_from_kernel_nocheck_asm(char *__to,
@@ -38,6 +39,9 @@ extern long __strnlen_user_asm(const char *s);
* Core architecture code
*/
EXPORT_SYMBOL_GPL(_save_fp);
+#ifdef CONFIG_CPU_HAS_MSA
+EXPORT_SYMBOL_GPL(_save_msa);
+#endif
/*
* String functions
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 143/183] kdb: fix incorrect counts in KDB summary command output
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (141 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 142/183] MIPS: Export MSA " Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 144/183] blk-throttle: check stats_cpu before reading it from sysfs Luis Henriques
` (39 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Jay Lan, Jason Wessel, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jay Lan <jlan@sgi.com>
commit 146755923262037fc4c54abc28c04b1103f3cc51 upstream.
The output of KDB 'summary' command should report MemTotal, MemFree
and Buffers output in kB. Current codes report in unit of pages.
A define of K(x) as
is defined in the code, but not used.
This patch would apply the define to convert the values to kB.
Please include me on Cc on replies. I do not subscribe to linux-kernel.
Signed-off-by: Jay Lan <jlan@sgi.com>
Signed-off-by: Jason Wessel <jason.wessel@windriver.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
kernel/debug/kdb/kdb_main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/debug/kdb/kdb_main.c b/kernel/debug/kdb/kdb_main.c
index 2f7c760305ca..98d2f17479d7 100644
--- a/kernel/debug/kdb/kdb_main.c
+++ b/kernel/debug/kdb/kdb_main.c
@@ -2535,7 +2535,7 @@ static int kdb_summary(int argc, const char **argv)
#define K(x) ((x) << (PAGE_SHIFT - 10))
kdb_printf("\nMemTotal: %8lu kB\nMemFree: %8lu kB\n"
"Buffers: %8lu kB\n",
- val.totalram, val.freeram, val.bufferram);
+ K(val.totalram), K(val.freeram), K(val.bufferram));
return 0;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 144/183] blk-throttle: check stats_cpu before reading it from sysfs
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (142 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 143/183] kdb: fix incorrect counts in KDB summary command output Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 145/183] debugfs: leave freeing a symlink body until inode eviction Luis Henriques
` (38 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Thadeu Lima de Souza Cascardo, Jens Axboe, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Thadeu Lima de Souza Cascardo <cascardo@linux.vnet.ibm.com>
commit 045c47ca306acf30c740c285a77a4b4bda6be7c5 upstream.
When reading blkio.throttle.io_serviced in a recently created blkio
cgroup, it's possible to race against the creation of a throttle policy,
which delays the allocation of stats_cpu.
Like other functions in the throttle code, just checking for a NULL
stats_cpu prevents the following oops caused by that race.
[ 1117.285199] Unable to handle kernel paging request for data at address 0x7fb4d0020
[ 1117.285252] Faulting instruction address: 0xc0000000003efa2c
[ 1137.733921] Oops: Kernel access of bad area, sig: 11 [#1]
[ 1137.733945] SMP NR_CPUS=2048 NUMA PowerNV
[ 1137.734025] Modules linked in: bridge stp llc kvm_hv kvm binfmt_misc autofs4
[ 1137.734102] CPU: 3 PID: 5302 Comm: blkcgroup Not tainted 3.19.0 #5
[ 1137.734132] task: c000000f1d188b00 ti: c000000f1d210000 task.ti: c000000f1d210000
[ 1137.734167] NIP: c0000000003efa2c LR: c0000000003ef9f0 CTR: c0000000003ef980
[ 1137.734202] REGS: c000000f1d213500 TRAP: 0300 Not tainted (3.19.0)
[ 1137.734230] MSR: 9000000000009032 <SF,HV,EE,ME,IR,DR,RI> CR: 42008884 XER: 20000000
[ 1137.734325] CFAR: 0000000000008458 DAR: 00000007fb4d0020 DSISR: 40000000 SOFTE: 0
GPR00: c0000000003ed3a0 c000000f1d213780 c000000000c59538 0000000000000000
GPR04: 0000000000000800 0000000000000000 0000000000000000 0000000000000000
GPR08: ffffffffffffffff 00000007fb4d0020 00000007fb4d0000 c000000000780808
GPR12: 0000000022000888 c00000000fdc0d80 0000000000000000 0000000000000000
GPR16: 0000000000000000 0000000000000000 0000000000000000 0000000000000000
GPR20: 000001003e120200 c000000f1d5b0cc0 0000000000000200 0000000000000000
GPR24: 0000000000000001 c000000000c269e0 0000000000000020 c000000f1d5b0c80
GPR28: c000000000ca3a08 c000000000ca3dec c000000f1c667e00 c000000f1d213850
[ 1137.734886] NIP [c0000000003efa2c] .tg_prfill_cpu_rwstat+0xac/0x180
[ 1137.734915] LR [c0000000003ef9f0] .tg_prfill_cpu_rwstat+0x70/0x180
[ 1137.734943] Call Trace:
[ 1137.734952] [c000000f1d213780] [d000000005560520] 0xd000000005560520 (unreliable)
[ 1137.734996] [c000000f1d2138a0] [c0000000003ed3a0] .blkcg_print_blkgs+0xe0/0x1a0
[ 1137.735039] [c000000f1d213960] [c0000000003efb50] .tg_print_cpu_rwstat+0x50/0x70
[ 1137.735082] [c000000f1d2139e0] [c000000000104b48] .cgroup_seqfile_show+0x58/0x150
[ 1137.735125] [c000000f1d213a70] [c0000000002749dc] .kernfs_seq_show+0x3c/0x50
[ 1137.735161] [c000000f1d213ae0] [c000000000218630] .seq_read+0xe0/0x510
[ 1137.735197] [c000000f1d213bd0] [c000000000275b04] .kernfs_fop_read+0x164/0x200
[ 1137.735240] [c000000f1d213c80] [c0000000001eb8e0] .__vfs_read+0x30/0x80
[ 1137.735276] [c000000f1d213cf0] [c0000000001eb9c4] .vfs_read+0x94/0x1b0
[ 1137.735312] [c000000f1d213d90] [c0000000001ebb38] .SyS_read+0x58/0x100
[ 1137.735349] [c000000f1d213e30] [c000000000009218] syscall_exit+0x0/0x98
[ 1137.735383] Instruction dump:
[ 1137.735405] 7c6307b4 7f891800 409d00b8 60000000 60420000 3d420004 392a63b0 786a1f24
[ 1137.735471] 7d49502a e93e01c8 7d495214 7d2ad214 <7cead02a> e9090008 e9490010 e9290018
And here is one code that allows to easily reproduce this, although this
has first been found by running docker.
void run(pid_t pid)
{
int n;
int status;
int fd;
char *buffer;
buffer = memalign(BUFFER_ALIGN, BUFFER_SIZE);
n = snprintf(buffer, BUFFER_SIZE, "%d\n", pid);
fd = open(CGPATH "/test/tasks", O_WRONLY);
write(fd, buffer, n);
close(fd);
if (fork() > 0) {
fd = open("/dev/sda", O_RDONLY | O_DIRECT);
read(fd, buffer, 512);
close(fd);
wait(&status);
} else {
fd = open(CGPATH "/test/blkio.throttle.io_serviced", O_RDONLY);
n = read(fd, buffer, BUFFER_SIZE);
close(fd);
}
free(buffer);
exit(0);
}
void test(void)
{
int status;
mkdir(CGPATH "/test", 0666);
if (fork() > 0)
wait(&status);
else
run(getpid());
rmdir(CGPATH "/test");
}
int main(int argc, char **argv)
{
int i;
for (i = 0; i < NR_TESTS; i++)
test();
return 0;
}
Reported-by: Ricardo Marin Matinata <rmm@br.ibm.com>
Signed-off-by: Thadeu Lima de Souza Cascardo <cascardo@linux.vnet.ibm.com>
Signed-off-by: Jens Axboe <axboe@fb.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
block/blk-throttle.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/block/blk-throttle.c b/block/blk-throttle.c
index 3fdb21a390c1..6b011cebe655 100644
--- a/block/blk-throttle.c
+++ b/block/blk-throttle.c
@@ -1292,6 +1292,9 @@ static u64 tg_prfill_cpu_rwstat(struct seq_file *sf,
struct blkg_rwstat rwstat = { }, tmp;
int i, cpu;
+ if (tg->stats_cpu == NULL)
+ return 0;
+
for_each_possible_cpu(cpu) {
struct tg_stats_cpu *sc = per_cpu_ptr(tg->stats_cpu, cpu);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 145/183] debugfs: leave freeing a symlink body until inode eviction
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (143 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 144/183] blk-throttle: check stats_cpu before reading it from sysfs Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 146/183] procfs: fix race between symlink removals and traversals Luis Henriques
` (37 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Al Viro, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Al Viro <viro@zeniv.linux.org.uk>
commit 0db59e59299f0b67450c5db21f7f316c8fb04e84 upstream.
As it is, we have debugfs_remove() racing with symlink traversals.
Supply ->evict_inode() and do freeing there - inode will remain
pinned until we are done with the symlink body.
And rip the idiocy with checking if dentry is positive right after
we'd verified debugfs_positive(), which is a stronger check...
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/debugfs/inode.c | 34 +++++++++++++++++-----------------
1 file changed, 17 insertions(+), 17 deletions(-)
diff --git a/fs/debugfs/inode.c b/fs/debugfs/inode.c
index dc240009e8ec..0c6ba4ef00a0 100644
--- a/fs/debugfs/inode.c
+++ b/fs/debugfs/inode.c
@@ -246,10 +246,19 @@ static int debugfs_show_options(struct seq_file *m, struct dentry *root)
return 0;
}
+static void debugfs_evict_inode(struct inode *inode)
+{
+ truncate_inode_pages_final(&inode->i_data);
+ clear_inode(inode);
+ if (S_ISLNK(inode->i_mode))
+ kfree(inode->i_private);
+}
+
static const struct super_operations debugfs_super_operations = {
.statfs = simple_statfs,
.remount_fs = debugfs_remount,
.show_options = debugfs_show_options,
+ .evict_inode = debugfs_evict_inode,
};
static int debug_fill_super(struct super_block *sb, void *data, int silent)
@@ -466,23 +475,14 @@ static int __debugfs_remove(struct dentry *dentry, struct dentry *parent)
int ret = 0;
if (debugfs_positive(dentry)) {
- if (dentry->d_inode) {
- dget(dentry);
- switch (dentry->d_inode->i_mode & S_IFMT) {
- case S_IFDIR:
- ret = simple_rmdir(parent->d_inode, dentry);
- break;
- case S_IFLNK:
- kfree(dentry->d_inode->i_private);
- /* fall through */
- default:
- simple_unlink(parent->d_inode, dentry);
- break;
- }
- if (!ret)
- d_delete(dentry);
- dput(dentry);
- }
+ dget(dentry);
+ if (S_ISDIR(dentry->d_inode->i_mode))
+ ret = simple_rmdir(parent->d_inode, dentry);
+ else
+ simple_unlink(parent->d_inode, dentry);
+ if (!ret)
+ d_delete(dentry);
+ dput(dentry);
}
return ret;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 146/183] procfs: fix race between symlink removals and traversals
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (144 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 145/183] debugfs: leave freeing a symlink body until inode eviction Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 147/183] autofs4 copy_dev_ioctl(): keep the value of ->size we'd used for allocation Luis Henriques
` (36 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Al Viro, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Al Viro <viro@zeniv.linux.org.uk>
commit 7e0e953bb0cf649f93277ac8fb67ecbb7f7b04a9 upstream.
use_pde()/unuse_pde() in ->follow_link()/->put_link() resp.
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/proc/generic.c | 12 ------------
fs/proc/inode.c | 21 +++++++++++++++++++++
fs/proc/internal.h | 1 +
3 files changed, 22 insertions(+), 12 deletions(-)
diff --git a/fs/proc/generic.c b/fs/proc/generic.c
index b7f268eb5f45..2e2d9d5d78d9 100644
--- a/fs/proc/generic.c
+++ b/fs/proc/generic.c
@@ -19,7 +19,6 @@
#include <linux/mount.h>
#include <linux/init.h>
#include <linux/idr.h>
-#include <linux/namei.h>
#include <linux/bitops.h>
#include <linux/spinlock.h>
#include <linux/completion.h>
@@ -162,17 +161,6 @@ void proc_free_inum(unsigned int inum)
spin_unlock_irqrestore(&proc_inum_lock, flags);
}
-static void *proc_follow_link(struct dentry *dentry, struct nameidata *nd)
-{
- nd_set_link(nd, __PDE_DATA(dentry->d_inode));
- return NULL;
-}
-
-static const struct inode_operations proc_link_inode_operations = {
- .readlink = generic_readlink,
- .follow_link = proc_follow_link,
-};
-
/*
* Don't create negative dentries here, return -ENOENT by hand
* instead.
diff --git a/fs/proc/inode.c b/fs/proc/inode.c
index 0adbc02d60e3..965b82e61570 100644
--- a/fs/proc/inode.c
+++ b/fs/proc/inode.c
@@ -23,6 +23,7 @@
#include <linux/slab.h>
#include <linux/mount.h>
#include <linux/magic.h>
+#include <linux/namei.h>
#include <asm/uaccess.h>
@@ -401,6 +402,26 @@ static const struct file_operations proc_reg_file_ops_no_compat = {
};
#endif
+static void *proc_follow_link(struct dentry *dentry, struct nameidata *nd)
+{
+ struct proc_dir_entry *pde = PDE(dentry->d_inode);
+ if (unlikely(!use_pde(pde)))
+ return ERR_PTR(-EINVAL);
+ nd_set_link(nd, pde->data);
+ return pde;
+}
+
+static void proc_put_link(struct dentry *dentry, struct nameidata *nd, void *p)
+{
+ unuse_pde(p);
+}
+
+const struct inode_operations proc_link_inode_operations = {
+ .readlink = generic_readlink,
+ .follow_link = proc_follow_link,
+ .put_link = proc_put_link,
+};
+
struct inode *proc_get_inode(struct super_block *sb, struct proc_dir_entry *de)
{
struct inode *inode = new_inode_pseudo(sb);
diff --git a/fs/proc/internal.h b/fs/proc/internal.h
index 3ab6d14e71c5..8b24f3640cd9 100644
--- a/fs/proc/internal.h
+++ b/fs/proc/internal.h
@@ -202,6 +202,7 @@ struct pde_opener {
int closing;
struct completion *c;
};
+extern const struct inode_operations proc_link_inode_operations;
extern const struct inode_operations proc_pid_link_inode_operations;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 147/183] autofs4 copy_dev_ioctl(): keep the value of ->size we'd used for allocation
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (145 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 146/183] procfs: fix race between symlink removals and traversals Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 148/183] ASoC: mioa701_wm9713: Fix speaker event Luis Henriques
` (35 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Al Viro, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Al Viro <viro@zeniv.linux.org.uk>
commit 0a280962dc6e117e0e4baa668453f753579265d9 upstream.
X-Coverup: just ask spender
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/autofs4/dev-ioctl.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/fs/autofs4/dev-ioctl.c b/fs/autofs4/dev-ioctl.c
index 5b570b6efa28..9fae6e8a4c7e 100644
--- a/fs/autofs4/dev-ioctl.c
+++ b/fs/autofs4/dev-ioctl.c
@@ -95,7 +95,7 @@ static int check_dev_ioctl_version(int cmd, struct autofs_dev_ioctl *param)
*/
static struct autofs_dev_ioctl *copy_dev_ioctl(struct autofs_dev_ioctl __user *in)
{
- struct autofs_dev_ioctl tmp;
+ struct autofs_dev_ioctl tmp, *res;
if (copy_from_user(&tmp, in, sizeof(tmp)))
return ERR_PTR(-EFAULT);
@@ -106,7 +106,11 @@ static struct autofs_dev_ioctl *copy_dev_ioctl(struct autofs_dev_ioctl __user *i
if (tmp.size > (PATH_MAX + sizeof(tmp)))
return ERR_PTR(-ENAMETOOLONG);
- return memdup_user(in, tmp.size);
+ res = memdup_user(in, tmp.size);
+ if (!IS_ERR(res))
+ res->size = tmp.size;
+
+ return res;
}
static inline void free_dev_ioctl(struct autofs_dev_ioctl *param)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 148/183] ASoC: mioa701_wm9713: Fix speaker event
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (146 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 147/183] autofs4 copy_dev_ioctl(): keep the value of ->size we'd used for allocation Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 149/183] gpio: rcar: Fix error path for devm_kzalloc() failure Luis Henriques
` (34 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Lars-Peter Clausen, Mark Brown, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Lars-Peter Clausen <lars@metafoo.de>
commit 7331ea474e9e7a348541c207bdb6aa518c6403f4 upstream.
Commit f6b2a04590bb ("ASoC: pxa: mioa701_wm9713: Convert to table based DAPM
setup") converted the driver to register the board level DAPM elements with
the card's DAPM context rather than the CODEC's DAPM context. The change
overlooked that the speaker widget event callback accesses the widget's
codec field which is only valid if the widget has been registered in a CODEC
DAPM context. This patch modifies the callback to take an alternative route
to get the CODEC.
Fixes: f6b2a04590bb ("ASoC: pxa: mioa701_wm9713: Convert to table based DAPM
setup")
Signed-off-by: Lars-Peter Clausen <lars@metafoo.de>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
sound/soc/pxa/mioa701_wm9713.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/soc/pxa/mioa701_wm9713.c b/sound/soc/pxa/mioa701_wm9713.c
index 595eee341e90..a08a877fc10c 100644
--- a/sound/soc/pxa/mioa701_wm9713.c
+++ b/sound/soc/pxa/mioa701_wm9713.c
@@ -81,7 +81,7 @@ static int rear_amp_power(struct snd_soc_codec *codec, int power)
static int rear_amp_event(struct snd_soc_dapm_widget *widget,
struct snd_kcontrol *kctl, int event)
{
- struct snd_soc_codec *codec = widget->codec;
+ struct snd_soc_codec *codec = widget->dapm->card->rtd[0].codec;
return rear_amp_power(codec, SND_SOC_DAPM_EVENT_ON(event));
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 149/183] gpio: rcar: Fix error path for devm_kzalloc() failure
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (147 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 148/183] ASoC: mioa701_wm9713: Fix speaker event Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 150/183] efi: Small leak on error in runtime map code Luis Henriques
` (33 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Geert Uytterhoeven, Linus Walleij, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Geert Uytterhoeven <geert+renesas@glider.be>
commit 7d82bf3419c103dbb730e7834186fc5d577b9da1 upstream.
If the call to devm_kzalloc() fails, nothing must be cleant up.
This was missed before because gpio_rcar_probe() had a "return"
statement after the first "goto err0".
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Fixes: df0c6c80232f2ad4 ("gpio: rcar: Add minimal runtime PM support")
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/gpio/gpio-rcar.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/drivers/gpio/gpio-rcar.c b/drivers/gpio/gpio-rcar.c
index b6ae89ea8811..c3ea3e9e3d14 100644
--- a/drivers/gpio/gpio-rcar.c
+++ b/drivers/gpio/gpio-rcar.c
@@ -363,10 +363,8 @@ static int gpio_rcar_probe(struct platform_device *pdev)
int ret;
p = devm_kzalloc(dev, sizeof(*p), GFP_KERNEL);
- if (!p) {
- ret = -ENOMEM;
- goto err0;
- }
+ if (!p)
+ return -ENOMEM;
p->pdev = pdev;
spin_lock_init(&p->lock);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 150/183] efi: Small leak on error in runtime map code
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (148 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 149/183] gpio: rcar: Fix error path for devm_kzalloc() failure Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 151/183] clk-gate: fix bit # check in clk_register_gate() Luis Henriques
` (32 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dan Carpenter, Matt Fleming, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dan Carpenter <dan.carpenter@oracle.com>
commit 86d68a58d00db3770735b5919ef2c6b12d7f06f3 upstream.
The "> 0" here should ">= 0" so we free map_entries[0].
Fixes: 926172d46038 ('efi: Export EFI runtime memory mapping to sysfs')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Acked-by: Dave Young <dyoung@redhat.com>
Signed-off-by: Matt Fleming <matt.fleming@intel.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/firmware/efi/runtime-map.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/firmware/efi/runtime-map.c b/drivers/firmware/efi/runtime-map.c
index 97cdd16a2169..c98b101a73ae 100644
--- a/drivers/firmware/efi/runtime-map.c
+++ b/drivers/firmware/efi/runtime-map.c
@@ -170,7 +170,7 @@ int __init efi_runtime_map_init(struct kobject *efi_kobj)
return 0;
out_add_entry:
- for (j = i - 1; j > 0; j--) {
+ for (j = i - 1; j >= 0; j--) {
entry = *(map_entries + j);
kobject_put(&entry->kobj);
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 151/183] clk-gate: fix bit # check in clk_register_gate()
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (149 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 150/183] efi: Small leak on error in runtime map code Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 152/183] powerpc/kernel: Avoid memory corruption at early stage Luis Henriques
` (31 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Sergei Shtylyov, Michael Turquette, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Sergei Shtylyov <sergei.shtylyov@cogentembedded.com>
commit 2e9dcdae4068460c45a308dd891be5248260251c upstream.
In case CLK_GATE_HIWORD_MASK flag is passed to clk_register_gate(), the bit #
should be no higher than 15, however the corresponding check is obviously off-
by-one.
Fixes: 045779942c04 ("clk: gate: add CLK_GATE_HIWORD_MASK")
Signed-off-by: Sergei Shtylyov <sergei.shtylyov@cogentembedded.com>
Signed-off-by: Michael Turquette <mturquette@linaro.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/clk/clk-gate.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/clk/clk-gate.c b/drivers/clk/clk-gate.c
index 4a58c55255bd..797bab97cea6 100644
--- a/drivers/clk/clk-gate.c
+++ b/drivers/clk/clk-gate.c
@@ -128,7 +128,7 @@ struct clk *clk_register_gate(struct device *dev, const char *name,
struct clk_init_data init;
if (clk_gate_flags & CLK_GATE_HIWORD_MASK) {
- if (bit_idx > 16) {
+ if (bit_idx > 15) {
pr_err("gate bit exceeds LOWORD field\n");
return ERR_PTR(-EINVAL);
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 152/183] powerpc/kernel: Avoid memory corruption at early stage
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (150 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 151/183] clk-gate: fix bit # check in clk_register_gate() Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 153/183] pinctrl: pinctrl-imx: don't use invalid value of conf_reg Luis Henriques
` (30 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Gavin Shan, Michael Ellerman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Gavin Shan <gwshan@linux.vnet.ibm.com>
commit 6f20e7f2e930211613a66d0603fa4abaaf3ce662 upstream.
When calling to early_setup(), we pick "boot_paca" up for the master CPU
and initialize that with initialise_paca(). At that point, the SLB
shadow buffer isn't populated yet. Updating the SLB shadow buffer should
corrupt what we had in physical address 0 where the trap instruction is
usually stored.
This hasn't been observed to cause any trouble in practice, but is
obviously fishy.
Fixes: 6f4441ef7009 ("powerpc: Dynamically allocate slb_shadow from memblock")
Signed-off-by: Gavin Shan <gwshan@linux.vnet.ibm.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/powerpc/kernel/paca.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/arch/powerpc/kernel/paca.c b/arch/powerpc/kernel/paca.c
index d6e195e8cd4c..5a23b69f8129 100644
--- a/arch/powerpc/kernel/paca.c
+++ b/arch/powerpc/kernel/paca.c
@@ -115,6 +115,14 @@ static struct slb_shadow * __init init_slb_shadow(int cpu)
{
struct slb_shadow *s = &slb_shadow[cpu];
+ /*
+ * When we come through here to initialise boot_paca, the slb_shadow
+ * buffers are not allocated yet. That's OK, we'll get one later in
+ * boot, but make sure we don't corrupt memory at 0.
+ */
+ if (!slb_shadow)
+ return NULL;
+
s->persistent = cpu_to_be32(SLB_NUM_BOLTED);
s->buffer_length = cpu_to_be32(sizeof(*s));
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 153/183] pinctrl: pinctrl-imx: don't use invalid value of conf_reg
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (151 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 152/183] powerpc/kernel: Avoid memory corruption at early stage Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 154/183] ALSA: off by one bug in snd_riptide_joystick_probe() Luis Henriques
` (29 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Uwe Kleine-König, Linus Walleij, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: =?UTF-8?q?Uwe=20Kleine-K=C3=B6nig?= <u.kleine-koenig@pengutronix.de>
commit 4ff0f034e95d65f8f063a362dfcf86e986377a82 upstream.
The right check for conf_reg to be invalid it testing against -1 not 0
as is done in the rest of the driver.
This fixes an oops that can be triggered by:
cat /sys/kernel/debug/pinctrl/43fac000.iomuxc/*
Fixes: ae75ff814538 ("pinctrl: pinctrl-imx: add imx pinctrl core driver")
Signed-off-by: Uwe Kleine-König <u.kleine-koenig@pengutronix.de>
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
[ luis: backported to 3.16:
- file rename: drivers/pinctrl/freescale/pinctrl-imx.c ->
drivers/pinctrl/pinctrl-imx.c ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/pinctrl/pinctrl-imx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/pinctrl/pinctrl-imx.c b/drivers/pinctrl/pinctrl-imx.c
index a24448e5d399..6cd65e6987e4 100644
--- a/drivers/pinctrl/pinctrl-imx.c
+++ b/drivers/pinctrl/pinctrl-imx.c
@@ -365,7 +365,7 @@ static void imx_pinconf_dbg_show(struct pinctrl_dev *pctldev,
const struct imx_pin_reg *pin_reg = &info->pin_regs[pin_id];
unsigned long config;
- if (!pin_reg || !pin_reg->conf_reg) {
+ if (!pin_reg || pin_reg->conf_reg == -1) {
seq_printf(s, "N/A");
return;
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 154/183] ALSA: off by one bug in snd_riptide_joystick_probe()
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (152 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 153/183] pinctrl: pinctrl-imx: don't use invalid value of conf_reg Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 155/183] GFS2: Fix crash during ACL deletion in acl max entry check in gfs2_set_acl() Luis Henriques
` (28 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dan Carpenter, Takashi Iwai, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dan Carpenter <dan.carpenter@oracle.com>
commit e4940626defdf6c92da1052ad3f12741c1a28c90 upstream.
The problem here is that we check:
if (dev >= SNDRV_CARDS)
Then we increment "dev".
if (!joystick_port[dev++])
Then we use it as an offset into a array with SNDRV_CARDS elements.
if (!request_region(joystick_port[dev], 8, "Riptide gameport")) {
This has 3 effects:
1) If you use the module option to specify the joystick port then it has
to be shifted one space over.
2) The wrong error message will be printed on failure if you have over
32 cards.
3) Static checkers will correctly complain that are off by one.
Fixes: db1005ec6ff8 ('ALSA: riptide - Fix joystick resource handling')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
sound/pci/riptide/riptide.c | 27 +++++++++++++++++++--------
1 file changed, 19 insertions(+), 8 deletions(-)
diff --git a/sound/pci/riptide/riptide.c b/sound/pci/riptide/riptide.c
index b4a8278241b1..4c3a5e479d79 100644
--- a/sound/pci/riptide/riptide.c
+++ b/sound/pci/riptide/riptide.c
@@ -2030,32 +2030,43 @@ snd_riptide_joystick_probe(struct pci_dev *pci, const struct pci_device_id *id)
{
static int dev;
struct gameport *gameport;
+ int ret;
if (dev >= SNDRV_CARDS)
return -ENODEV;
+
if (!enable[dev]) {
- dev++;
- return -ENOENT;
+ ret = -ENOENT;
+ goto inc_dev;
}
- if (!joystick_port[dev++])
- return 0;
+ if (!joystick_port[dev]) {
+ ret = 0;
+ goto inc_dev;
+ }
gameport = gameport_allocate_port();
- if (!gameport)
- return -ENOMEM;
+ if (!gameport) {
+ ret = -ENOMEM;
+ goto inc_dev;
+ }
if (!request_region(joystick_port[dev], 8, "Riptide gameport")) {
snd_printk(KERN_WARNING
"Riptide: cannot grab gameport 0x%x\n",
joystick_port[dev]);
gameport_free_port(gameport);
- return -EBUSY;
+ ret = -EBUSY;
+ goto inc_dev;
}
gameport->io = joystick_port[dev];
gameport_register_port(gameport);
pci_set_drvdata(pci, gameport);
- return 0;
+
+ ret = 0;
+inc_dev:
+ dev++;
+ return ret;
}
static void snd_riptide_joystick_remove(struct pci_dev *pci)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 155/183] GFS2: Fix crash during ACL deletion in acl max entry check in gfs2_set_acl()
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (153 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 154/183] ALSA: off by one bug in snd_riptide_joystick_probe() Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 156/183] net: llc: use correct size for sysctl timeout entries Luis Henriques
` (27 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Andrew Elble, Steven Whitehouse, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrew Elble <aweits@rit.edu>
commit 278702074ff77b1a3fa2061267997095959f5e2c upstream.
Fixes: e01580bf9e ("gfs2: use generic posix ACL infrastructure")
Reported-by: Eric Meddaugh <etmsys@rit.edu>
Tested-by: Eric Meddaugh <etmsys@rit.edu>
Signed-off-by: Andrew Elble <aweits@rit.edu>
Signed-off-by: Steven Whitehouse <swhiteho@redhat.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/gfs2/acl.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/gfs2/acl.c b/fs/gfs2/acl.c
index 3088e2a38e30..7b3143064af1 100644
--- a/fs/gfs2/acl.c
+++ b/fs/gfs2/acl.c
@@ -73,7 +73,7 @@ int gfs2_set_acl(struct inode *inode, struct posix_acl *acl, int type)
BUG_ON(name == NULL);
- if (acl->a_count > GFS2_ACL_MAX_ENTRIES(GFS2_SB(inode)))
+ if (acl && acl->a_count > GFS2_ACL_MAX_ENTRIES(GFS2_SB(inode)))
return -E2BIG;
if (type == ACL_TYPE_ACCESS) {
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 156/183] net: llc: use correct size for sysctl timeout entries
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (154 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 155/183] GFS2: Fix crash during ACL deletion in acl max entry check in gfs2_set_acl() Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 157/183] net: rds: use correct size for max unacked packets and bytes Luis Henriques
` (26 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Sasha Levin, David S. Miller, Moritz Muehlenhoff, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Sasha Levin <sasha.levin@oracle.com>
commit 6b8d9117ccb4f81b1244aafa7bc70ef8fa45fc49 upstream.
The timeout entries are sizeof(int) rather than sizeof(long), which
means that when they were getting read we'd also leak kernel memory
to userspace along with the timeout values.
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Cc: Moritz Muehlenhoff <jmm@inutil.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
net/llc/sysctl_net_llc.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/net/llc/sysctl_net_llc.c b/net/llc/sysctl_net_llc.c
index 612a5ddaf93b..799bafc2af39 100644
--- a/net/llc/sysctl_net_llc.c
+++ b/net/llc/sysctl_net_llc.c
@@ -18,28 +18,28 @@ static struct ctl_table llc2_timeout_table[] = {
{
.procname = "ack",
.data = &sysctl_llc2_ack_timeout,
- .maxlen = sizeof(long),
+ .maxlen = sizeof(sysctl_llc2_ack_timeout),
.mode = 0644,
.proc_handler = proc_dointvec_jiffies,
},
{
.procname = "busy",
.data = &sysctl_llc2_busy_timeout,
- .maxlen = sizeof(long),
+ .maxlen = sizeof(sysctl_llc2_busy_timeout),
.mode = 0644,
.proc_handler = proc_dointvec_jiffies,
},
{
.procname = "p",
.data = &sysctl_llc2_p_timeout,
- .maxlen = sizeof(long),
+ .maxlen = sizeof(sysctl_llc2_p_timeout),
.mode = 0644,
.proc_handler = proc_dointvec_jiffies,
},
{
.procname = "rej",
.data = &sysctl_llc2_rej_timeout,
- .maxlen = sizeof(long),
+ .maxlen = sizeof(sysctl_llc2_rej_timeout),
.mode = 0644,
.proc_handler = proc_dointvec_jiffies,
},
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 157/183] net: rds: use correct size for max unacked packets and bytes
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (155 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 156/183] net: llc: use correct size for sysctl timeout entries Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 158/183] HID: i2c-hid: Limit reads to wMaxInputLength bytes for input events Luis Henriques
` (25 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Sasha Levin, David S. Miller, Moritz Muehlenhoff, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Sasha Levin <sasha.levin@oracle.com>
commit db27ebb111e9f69efece08e4cb6a34ff980f8896 upstream.
Max unacked packets/bytes is an int while sizeof(long) was used in the
sysctl table.
This means that when they were getting read we'd also leak kernel memory
to userspace along with the timeout values.
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Cc: Moritz Muehlenhoff <jmm@inutil.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
net/rds/sysctl.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/rds/sysctl.c b/net/rds/sysctl.c
index c3b0cd43eb56..c173f69e1479 100644
--- a/net/rds/sysctl.c
+++ b/net/rds/sysctl.c
@@ -71,14 +71,14 @@ static struct ctl_table rds_sysctl_rds_table[] = {
{
.procname = "max_unacked_packets",
.data = &rds_sysctl_max_unacked_packets,
- .maxlen = sizeof(unsigned long),
+ .maxlen = sizeof(int),
.mode = 0644,
.proc_handler = proc_dointvec,
},
{
.procname = "max_unacked_bytes",
.data = &rds_sysctl_max_unacked_bytes,
- .maxlen = sizeof(unsigned long),
+ .maxlen = sizeof(int),
.mode = 0644,
.proc_handler = proc_dointvec,
},
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 158/183] HID: i2c-hid: Limit reads to wMaxInputLength bytes for input events
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (156 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 157/183] net: rds: use correct size for max unacked packets and bytes Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 159/183] fib_trie: Fix /proc/net/fib_trie when CONFIG_IP_MULTIPLE_TABLES is not defined Luis Henriques
` (24 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Seth Forshee, Jiri Kosina, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Seth Forshee <seth.forshee@canonical.com>
commit 6d00f37e49d95e640a3937a4a1ae07dbe92a10cb upstream.
d1c7e29e8d27 (HID: i2c-hid: prevent buffer overflow in early IRQ)
changed hid_get_input() to read ihid->bufsize bytes, which can be
more than wMaxInputLength. This is the case with the Dell XPS 13
9343, and it is causing events to be missed. In some cases the
missed events are releases, which can cause the cursor to jump or
freeze, among other problems. Limit the number of bytes read to
min(wMaxInputLength, ihid->bufsize) to prevent such problems.
Fixes: d1c7e29e8d27 "HID: i2c-hid: prevent buffer overflow in early IRQ"
Signed-off-by: Seth Forshee <seth.forshee@canonical.com>
Reviewed-by: Benjamin Tissoires <benjamin.tissoires@redhat.com>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/hid/i2c-hid/i2c-hid.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/hid/i2c-hid/i2c-hid.c b/drivers/hid/i2c-hid/i2c-hid.c
index c56c7388d2d6..1c313e3aa0fd 100644
--- a/drivers/hid/i2c-hid/i2c-hid.c
+++ b/drivers/hid/i2c-hid/i2c-hid.c
@@ -370,7 +370,10 @@ static int i2c_hid_hwreset(struct i2c_client *client)
static void i2c_hid_get_input(struct i2c_hid *ihid)
{
int ret, ret_size;
- int size = ihid->bufsize;
+ int size = le16_to_cpu(ihid->hdesc.wMaxInputLength);
+
+ if (size > ihid->bufsize)
+ size = ihid->bufsize;
ret = i2c_master_recv(ihid->client, ihid->inbuf, size);
if (ret != size) {
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 159/183] fib_trie: Fix /proc/net/fib_trie when CONFIG_IP_MULTIPLE_TABLES is not defined
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (157 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 158/183] HID: i2c-hid: Limit reads to wMaxInputLength bytes for input events Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 160/183] net: sctp: fix race for one-to-many sockets in sendmsg's auto associate Luis Henriques
` (23 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Alexander Duyck, David S. Miller, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Duyck <alexander.h.duyck@redhat.com>
commit a5a519b2710be43fce3cf9ce7bd8de8db3f2a9de upstream.
In recent testing I had disabled CONFIG_IP_MULTIPLE_TABLES and as a result
when I ran "cat /proc/net/fib_trie" the main trie was displayed multiple
times. I found that the problem line of code was in the function
fib_trie_seq_next. Specifically the line below caused the indexes to go in
the opposite direction of our traversal:
h = tb->tb_id & (FIB_TABLE_HASHSZ - 1);
This issue was that the RT tables are defined such that RT_TABLE_LOCAL is ID
255, while it is located at TABLE_LOCAL_INDEX of 0, and RT_TABLE_MAIN is 254
with a TABLE_MAIN_INDEX of 1. This means that the above line will return 1
for the local table and 0 for main. The result is that fib_trie_seq_next
will return NULL at the end of the local table, fib_trie_seq_start will
return the start of the main table, and then fib_trie_seq_next will loop on
main forever as h will always return 0.
The fix for this is to reverse the ordering of the two tables. It has the
advantage of making it so that the tables now print in the same order
regardless of if multiple tables are enabled or not. In order to make the
definition consistent with the multiple tables case I simply masked the to
RT_TABLE_XXX values by (FIB_TABLE_HASHSZ - 1). This way the two table
layouts should always stay consistent.
Fixes: 93456b6 ("[IPV4]: Unify access to the routing tables")
Signed-off-by: Alexander Duyck <alexander.h.duyck@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
include/net/ip_fib.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/include/net/ip_fib.h b/include/net/ip_fib.h
index 9922093f575e..699c4046a8cb 100644
--- a/include/net/ip_fib.h
+++ b/include/net/ip_fib.h
@@ -200,8 +200,8 @@ void fib_free_table(struct fib_table *tb);
#ifndef CONFIG_IP_MULTIPLE_TABLES
-#define TABLE_LOCAL_INDEX 0
-#define TABLE_MAIN_INDEX 1
+#define TABLE_LOCAL_INDEX (RT_TABLE_LOCAL & (FIB_TABLE_HASHSZ - 1))
+#define TABLE_MAIN_INDEX (RT_TABLE_MAIN & (FIB_TABLE_HASHSZ - 1))
static inline struct fib_table *fib_get_table(struct net *net, u32 id)
{
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 160/183] net: sctp: fix race for one-to-many sockets in sendmsg's auto associate
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (158 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 159/183] fib_trie: Fix /proc/net/fib_trie when CONFIG_IP_MULTIPLE_TABLES is not defined Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 161/183] gpio: sysfs: fix gpio attribute-creation race Luis Henriques
` (22 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Daniel Borkmann, David S. Miller, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Borkmann <dborkman@redhat.com>
commit 2061dcd6bff8b774b4fac8b0739b6be3f87bc9f2 upstream.
I.e. one-to-many sockets in SCTP are not required to explicitly
call into connect(2) or sctp_connectx(2) prior to data exchange.
Instead, they can directly invoke sendmsg(2) and the SCTP stack
will automatically trigger connection establishment through 4WHS
via sctp_primitive_ASSOCIATE(). However, this in its current
implementation is racy: INIT is being sent out immediately (as
it cannot be bundled anyway) and the rest of the DATA chunks are
queued up for later xmit when connection is established, meaning
sendmsg(2) will return successfully. This behaviour can result
in an undesired side-effect that the kernel made the application
think the data has already been transmitted, although none of it
has actually left the machine, worst case even after close(2)'ing
the socket.
Instead, when the association from client side has been shut down
e.g. first gracefully through SCTP_EOF and then close(2), the
client could afterwards still receive the server's INIT_ACK due
to a connection with higher latency. This INIT_ACK is then considered
out of the blue and hence responded with ABORT as there was no
alive assoc found anymore. This can be easily reproduced f.e.
with sctp_test application from lksctp. One way to fix this race
is to wait for the handshake to actually complete.
The fix defers waiting after sctp_primitive_ASSOCIATE() and
sctp_primitive_SEND() succeeded, so that DATA chunks cooked up
from sctp_sendmsg() have already been placed into the output
queue through the side-effect interpreter, and therefore can then
be bundeled together with COOKIE_ECHO control chunks.
strace from example application (shortened):
socket(PF_INET, SOCK_SEQPACKET, IPPROTO_SCTP) = 3
sendmsg(3, {msg_name(28)={sa_family=AF_INET, sin_port=htons(8888), sin_addr=inet_addr("192.168.1.115")},
msg_iov(1)=[{"hello", 5}], msg_controllen=0, msg_flags=0}, 0) = 5
sendmsg(3, {msg_name(28)={sa_family=AF_INET, sin_port=htons(8888), sin_addr=inet_addr("192.168.1.115")},
msg_iov(1)=[{"hello", 5}], msg_controllen=0, msg_flags=0}, 0) = 5
sendmsg(3, {msg_name(28)={sa_family=AF_INET, sin_port=htons(8888), sin_addr=inet_addr("192.168.1.115")},
msg_iov(1)=[{"hello", 5}], msg_controllen=0, msg_flags=0}, 0) = 5
sendmsg(3, {msg_name(28)={sa_family=AF_INET, sin_port=htons(8888), sin_addr=inet_addr("192.168.1.115")},
msg_iov(1)=[{"hello", 5}], msg_controllen=0, msg_flags=0}, 0) = 5
sendmsg(3, {msg_name(28)={sa_family=AF_INET, sin_port=htons(8888), sin_addr=inet_addr("192.168.1.115")},
msg_iov(0)=[], msg_controllen=48, {cmsg_len=48, cmsg_level=0x84 /* SOL_??? */, cmsg_type=, ...},
msg_flags=0}, 0) = 0 // graceful shutdown for SOCK_SEQPACKET via SCTP_EOF
close(3) = 0
tcpdump before patch (fooling the application):
22:33:36.306142 IP 192.168.1.114.41462 > 192.168.1.115.8888: sctp (1) [INIT] [init tag: 3879023686] [rwnd: 106496] [OS: 10] [MIS: 65535] [init TSN: 3139201684]
22:33:36.316619 IP 192.168.1.115.8888 > 192.168.1.114.41462: sctp (1) [INIT ACK] [init tag: 3345394793] [rwnd: 106496] [OS: 10] [MIS: 10] [init TSN: 3380109591]
22:33:36.317600 IP 192.168.1.114.41462 > 192.168.1.115.8888: sctp (1) [ABORT]
tcpdump after patch:
14:28:58.884116 IP 192.168.1.114.35846 > 192.168.1.115.8888: sctp (1) [INIT] [init tag: 438593213] [rwnd: 106496] [OS: 10] [MIS: 65535] [init TSN: 3092969729]
14:28:58.888414 IP 192.168.1.115.8888 > 192.168.1.114.35846: sctp (1) [INIT ACK] [init tag: 381429855] [rwnd: 106496] [OS: 10] [MIS: 10] [init TSN: 2141904492]
14:28:58.888638 IP 192.168.1.114.35846 > 192.168.1.115.8888: sctp (1) [COOKIE ECHO] , (2) [DATA] (B)(E) [TSN: 3092969729] [...]
14:28:58.893278 IP 192.168.1.115.8888 > 192.168.1.114.35846: sctp (1) [COOKIE ACK] , (2) [SACK] [cum ack 3092969729] [a_rwnd 106491] [#gap acks 0] [#dup tsns 0]
14:28:58.893591 IP 192.168.1.114.35846 > 192.168.1.115.8888: sctp (1) [DATA] (B)(E) [TSN: 3092969730] [...]
14:28:59.096963 IP 192.168.1.115.8888 > 192.168.1.114.35846: sctp (1) [SACK] [cum ack 3092969730] [a_rwnd 106496] [#gap acks 0] [#dup tsns 0]
14:28:59.097086 IP 192.168.1.114.35846 > 192.168.1.115.8888: sctp (1) [DATA] (B)(E) [TSN: 3092969731] [...] , (2) [DATA] (B)(E) [TSN: 3092969732] [...]
14:28:59.103218 IP 192.168.1.115.8888 > 192.168.1.114.35846: sctp (1) [SACK] [cum ack 3092969732] [a_rwnd 106486] [#gap acks 0] [#dup tsns 0]
14:28:59.103330 IP 192.168.1.114.35846 > 192.168.1.115.8888: sctp (1) [SHUTDOWN]
14:28:59.107793 IP 192.168.1.115.8888 > 192.168.1.114.35846: sctp (1) [SHUTDOWN ACK]
14:28:59.107890 IP 192.168.1.114.35846 > 192.168.1.115.8888: sctp (1) [SHUTDOWN COMPLETE]
Looks like this bug is from the pre-git history museum. ;)
Fixes: 08707d5482df ("lksctp-2_5_31-0_5_1.patch")
Signed-off-by: Daniel Borkmann <dborkman@redhat.com>
Acked-by: Vlad Yasevich <vyasevich@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
net/sctp/socket.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/net/sctp/socket.c b/net/sctp/socket.c
index 429899689408..e3528c40a6ea 100644
--- a/net/sctp/socket.c
+++ b/net/sctp/socket.c
@@ -1606,6 +1606,7 @@ static int sctp_sendmsg(struct kiocb *iocb, struct sock *sk,
sctp_scope_t scope;
long timeo;
__u16 sinfo_flags = 0;
+ bool wait_connect = false;
struct sctp_datamsg *datamsg;
int msg_flags = msg->msg_flags;
@@ -1925,6 +1926,7 @@ static int sctp_sendmsg(struct kiocb *iocb, struct sock *sk,
if (err < 0)
goto out_free;
+ wait_connect = true;
pr_debug("%s: we associated primitively\n", __func__);
}
@@ -1962,6 +1964,11 @@ static int sctp_sendmsg(struct kiocb *iocb, struct sock *sk,
sctp_datamsg_put(datamsg);
err = msg_len;
+ if (unlikely(wait_connect)) {
+ timeo = sock_sndtimeo(sk, msg_flags & MSG_DONTWAIT);
+ sctp_wait_for_connect(asoc, &timeo);
+ }
+
/* If we are already past ASSOCIATE, the lower
* layers are responsible for association cleanup.
*/
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 161/183] gpio: sysfs: fix gpio attribute-creation race
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (159 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 160/183] net: sctp: fix race for one-to-many sockets in sendmsg's auto associate Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 162/183] ipv6: mld: fix add_grhead skb_over_panic for devs with large MTUs Luis Henriques
` (21 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Johan Hovold, Linus Walleij, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Johan Hovold <johan@kernel.org>
commit ebbeba120ab2ec6ac5f3afc1425ec6ff0b77ad6f upstream.
Fix attribute-creation race with userspace by using the default group
to create also the contingent gpio device attributes.
Fixes: d8f388d8dc8d ("gpio: sysfs interface")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
[ luis: backported to 3.16:
- all changes in drivers/gpio/gpiolib.c
- adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/gpio/gpiolib.c | 62 ++++++++++++++++++++++++++++++++------------------
1 file changed, 40 insertions(+), 22 deletions(-)
diff --git a/drivers/gpio/gpiolib.c b/drivers/gpio/gpiolib.c
index afdca5a6b2a6..d9b8844e2715 100644
--- a/drivers/gpio/gpiolib.c
+++ b/drivers/gpio/gpiolib.c
@@ -60,6 +60,7 @@ struct gpio_desc {
#define FLAG_OPEN_DRAIN 7 /* Gpio is open drain type */
#define FLAG_OPEN_SOURCE 8 /* Gpio is open source type */
#define FLAG_USED_AS_IRQ 9 /* GPIO is connected to an IRQ */
+#define FLAG_SYSFS_DIR 10 /* show sysfs direction attribute */
#define ID_SHIFT 16 /* add new flags before this one */
@@ -637,12 +638,44 @@ static ssize_t gpio_active_low_store(struct device *dev,
static DEVICE_ATTR(active_low, 0644,
gpio_active_low_show, gpio_active_low_store);
+static umode_t gpio_is_visible(struct kobject *kobj, struct attribute *attr,
+ int n)
+{
+ struct device *dev = container_of(kobj, struct device, kobj);
+ struct gpio_desc *desc = dev_get_drvdata(dev);
+ umode_t mode = attr->mode;
+ bool show_direction = test_bit(FLAG_SYSFS_DIR, &desc->flags);
+
+ if (attr == &dev_attr_direction.attr) {
+ if (!show_direction)
+ mode = 0;
+ } else if (attr == &dev_attr_edge.attr) {
+ if (gpiod_to_irq(desc) < 0)
+ mode = 0;
+ if (!show_direction && test_bit(FLAG_IS_OUT, &desc->flags))
+ mode = 0;
+ }
+
+ return mode;
+}
+
static struct attribute *gpio_attrs[] = {
+ &dev_attr_direction.attr,
+ &dev_attr_edge.attr,
&dev_attr_value.attr,
&dev_attr_active_low.attr,
NULL,
};
-ATTRIBUTE_GROUPS(gpio);
+
+static const struct attribute_group gpio_group = {
+ .attrs = gpio_attrs,
+ .is_visible = gpio_is_visible,
+};
+
+static const struct attribute_group *gpio_groups[] = {
+ &gpio_group,
+ NULL
+};
/*
* /sys/class/gpio/gpiochipN/
@@ -831,8 +864,11 @@ int gpiod_export(struct gpio_desc *desc, bool direction_may_change)
goto fail_unlock;
}
- if (!desc->chip->direction_input || !desc->chip->direction_output)
- direction_may_change = false;
+ if (desc->chip->direction_input && desc->chip->direction_output &&
+ direction_may_change) {
+ set_bit(FLAG_SYSFS_DIR, &desc->flags);
+ }
+
spin_unlock_irqrestore(&gpio_lock, flags);
offset = gpio_chip_hwgpio(desc);
@@ -848,27 +884,10 @@ int gpiod_export(struct gpio_desc *desc, bool direction_may_change)
goto fail_unlock;
}
- if (direction_may_change) {
- status = device_create_file(dev, &dev_attr_direction);
- if (status)
- goto fail_unregister_device;
- }
-
- if (gpiod_to_irq(desc) >= 0 && (direction_may_change ||
- !test_bit(FLAG_IS_OUT, &desc->flags))) {
- status = device_create_file(dev, &dev_attr_edge);
- if (status)
- goto fail_remove_attr_direction;
- }
-
set_bit(FLAG_EXPORT, &desc->flags);
mutex_unlock(&sysfs_lock);
return 0;
-fail_remove_attr_direction:
- device_remove_file(dev, &dev_attr_direction);
-fail_unregister_device:
- device_unregister(dev);
fail_unlock:
mutex_unlock(&sysfs_lock);
gpiod_dbg(desc, "%s: status %d\n", __func__, status);
@@ -994,6 +1013,7 @@ void gpiod_unexport(struct gpio_desc *desc)
dev = class_find_device(&gpio_class, NULL, desc, match_export);
if (dev) {
gpio_setup_irq(desc, dev, 0);
+ clear_bit(FLAG_SYSFS_DIR, &desc->flags);
clear_bit(FLAG_EXPORT, &desc->flags);
} else
status = -ENODEV;
@@ -1002,8 +1022,6 @@ void gpiod_unexport(struct gpio_desc *desc)
mutex_unlock(&sysfs_lock);
if (dev) {
- device_remove_file(dev, &dev_attr_edge);
- device_remove_file(dev, &dev_attr_direction);
device_unregister(dev);
put_device(dev);
}
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 162/183] ipv6: mld: fix add_grhead skb_over_panic for devs with large MTUs
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (160 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 161/183] gpio: sysfs: fix gpio attribute-creation race Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 163/183] ideapad-laptop: Change Lenovo Yoga 2 series rfkill handling Luis Henriques
` (20 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Daniel Borkmann, Eric Dumazet, Hannes Frederic Sowa,
David L Stevens, David S. Miller, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Borkmann <dborkman@redhat.com>
commit 4c672e4b42bc8046d63a6eb0a2c6a450a501af32 upstream.
It has been reported that generating an MLD listener report on
devices with large MTUs (e.g. 9000) and a high number of IPv6
addresses can trigger a skb_over_panic():
skbuff: skb_over_panic: text:ffffffff80612a5d len:3776 put:20
head:ffff88046d751000 data:ffff88046d751010 tail:0xed0 end:0xec0
dev:port1
------------[ cut here ]------------
kernel BUG at net/core/skbuff.c:100!
invalid opcode: 0000 [#1] SMP
Modules linked in: ixgbe(O)
CPU: 3 PID: 0 Comm: swapper/3 Tainted: G O 3.14.23+ #4
[...]
Call Trace:
<IRQ>
[<ffffffff80578226>] ? skb_put+0x3a/0x3b
[<ffffffff80612a5d>] ? add_grhead+0x45/0x8e
[<ffffffff80612e3a>] ? add_grec+0x394/0x3d4
[<ffffffff80613222>] ? mld_ifc_timer_expire+0x195/0x20d
[<ffffffff8061308d>] ? mld_dad_timer_expire+0x45/0x45
[<ffffffff80255b5d>] ? call_timer_fn.isra.29+0x12/0x68
[<ffffffff80255d16>] ? run_timer_softirq+0x163/0x182
[<ffffffff80250e6f>] ? __do_softirq+0xe0/0x21d
[<ffffffff8025112b>] ? irq_exit+0x4e/0xd3
[<ffffffff802214bb>] ? smp_apic_timer_interrupt+0x3b/0x46
[<ffffffff8063f10a>] ? apic_timer_interrupt+0x6a/0x70
mld_newpack() skb allocations are usually requested with dev->mtu
in size, since commit 72e09ad107e7 ("ipv6: avoid high order allocations")
we have changed the limit in order to be less likely to fail.
However, in MLD/IGMP code, we have some rather ugly AVAILABLE(skb)
macros, which determine if we may end up doing an skb_put() for
adding another record. To avoid possible fragmentation, we check
the skb's tailroom as skb->dev->mtu - skb->len, which is a wrong
assumption as the actual max allocation size can be much smaller.
The IGMP case doesn't have this issue as commit 57e1ab6eaddc
("igmp: refine skb allocations") stores the allocation size in
the cb[].
Set a reserved_tailroom to make it fit into the MTU and use
skb_availroom() helper instead. This also allows to get rid of
igmp_skb_size().
Reported-by: Wei Liu <lw1a2.jing@gmail.com>
Fixes: 72e09ad107e7 ("ipv6: avoid high order allocations")
Signed-off-by: Daniel Borkmann <dborkman@redhat.com>
Cc: Eric Dumazet <edumazet@google.com>
Cc: Hannes Frederic Sowa <hannes@stressinduktion.org>
Cc: David L Stevens <david.stevens@oracle.com>
Acked-by: Eric Dumazet <edumazet@google.com>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
net/ipv4/igmp.c | 11 +++++------
net/ipv6/mcast.c | 9 +++++----
2 files changed, 10 insertions(+), 10 deletions(-)
diff --git a/net/ipv4/igmp.c b/net/ipv4/igmp.c
index db710b059bab..fbb230ea039a 100644
--- a/net/ipv4/igmp.c
+++ b/net/ipv4/igmp.c
@@ -318,9 +318,7 @@ igmp_scount(struct ip_mc_list *pmc, int type, int gdeleted, int sdeleted)
return scount;
}
-#define igmp_skb_size(skb) (*(unsigned int *)((skb)->cb))
-
-static struct sk_buff *igmpv3_newpack(struct net_device *dev, int size)
+static struct sk_buff *igmpv3_newpack(struct net_device *dev, unsigned int mtu)
{
struct sk_buff *skb;
struct rtable *rt;
@@ -330,6 +328,7 @@ static struct sk_buff *igmpv3_newpack(struct net_device *dev, int size)
struct flowi4 fl4;
int hlen = LL_RESERVED_SPACE(dev);
int tlen = dev->needed_tailroom;
+ unsigned int size = mtu;
while (1) {
skb = alloc_skb(size + hlen + tlen,
@@ -341,7 +340,6 @@ static struct sk_buff *igmpv3_newpack(struct net_device *dev, int size)
return NULL;
}
skb->priority = TC_PRIO_CONTROL;
- igmp_skb_size(skb) = size;
rt = ip_route_output_ports(net, &fl4, NULL, IGMPV3_ALL_MCR, 0,
0, 0,
@@ -354,6 +352,8 @@ static struct sk_buff *igmpv3_newpack(struct net_device *dev, int size)
skb_dst_set(skb, &rt->dst);
skb->dev = dev;
+ skb->reserved_tailroom = skb_end_offset(skb) -
+ min(mtu, skb_end_offset(skb));
skb_reserve(skb, hlen);
skb_reset_network_header(skb);
@@ -423,8 +423,7 @@ static struct sk_buff *add_grhead(struct sk_buff *skb, struct ip_mc_list *pmc,
return skb;
}
-#define AVAILABLE(skb) ((skb) ? ((skb)->dev ? igmp_skb_size(skb) - (skb)->len : \
- skb_tailroom(skb)) : 0)
+#define AVAILABLE(skb) ((skb) ? skb_availroom(skb) : 0)
static struct sk_buff *add_grec(struct sk_buff *skb, struct ip_mc_list *pmc,
int type, int gdeleted, int sdeleted)
diff --git a/net/ipv6/mcast.c b/net/ipv6/mcast.c
index a23b655a7627..2a6da3e5483f 100644
--- a/net/ipv6/mcast.c
+++ b/net/ipv6/mcast.c
@@ -1545,7 +1545,7 @@ static void ip6_mc_hdr(struct sock *sk, struct sk_buff *skb,
hdr->daddr = *daddr;
}
-static struct sk_buff *mld_newpack(struct inet6_dev *idev, int size)
+static struct sk_buff *mld_newpack(struct inet6_dev *idev, unsigned int mtu)
{
struct net_device *dev = idev->dev;
struct net *net = dev_net(dev);
@@ -1556,13 +1556,13 @@ static struct sk_buff *mld_newpack(struct inet6_dev *idev, int size)
const struct in6_addr *saddr;
int hlen = LL_RESERVED_SPACE(dev);
int tlen = dev->needed_tailroom;
+ unsigned int size = mtu + hlen + tlen;
int err;
u8 ra[8] = { IPPROTO_ICMPV6, 0,
IPV6_TLV_ROUTERALERT, 2, 0, 0,
IPV6_TLV_PADN, 0 };
/* we assume size > sizeof(ra) here */
- size += hlen + tlen;
/* limit our allocations to order-0 page */
size = min_t(int, size, SKB_MAX_ORDER(0, 0));
skb = sock_alloc_send_skb(sk, size, 1, &err);
@@ -1571,6 +1571,8 @@ static struct sk_buff *mld_newpack(struct inet6_dev *idev, int size)
return NULL;
skb->priority = TC_PRIO_CONTROL;
+ skb->reserved_tailroom = skb_end_offset(skb) -
+ min(mtu, skb_end_offset(skb));
skb_reserve(skb, hlen);
if (__ipv6_get_lladdr(idev, &addr_buf, IFA_F_TENTATIVE)) {
@@ -1685,8 +1687,7 @@ static struct sk_buff *add_grhead(struct sk_buff *skb, struct ifmcaddr6 *pmc,
return skb;
}
-#define AVAILABLE(skb) ((skb) ? ((skb)->dev ? (skb)->dev->mtu - (skb)->len : \
- skb_tailroom(skb)) : 0)
+#define AVAILABLE(skb) ((skb) ? skb_availroom(skb) : 0)
static struct sk_buff *add_grec(struct sk_buff *skb, struct ifmcaddr6 *pmc,
int type, int gdeleted, int sdeleted, int crsend)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 163/183] ideapad-laptop: Change Lenovo Yoga 2 series rfkill handling
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (161 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 162/183] ipv6: mld: fix add_grhead skb_over_panic for devs with large MTUs Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 164/183] IB/core: When marshaling ucma path from user-space, clear unused fields Luis Henriques
` (19 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Hans de Goede, Matthew Garrett, Gaudenz Steinlin, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <hdegoede@redhat.com>
commit ce363c2bcb2303e7fad3a79398db739c6995141b upstream.
It seems that the same problems which lead to adding an rfkill blacklist and
putting the Lenovo Yoga 2 11 on it are also present on the Lenovo Yoga 2 13
and Lenovo Yoga 2 Pro too:
https://bugzilla.redhat.com/show_bug.cgi?id=1021036
https://forums.lenovo.com/t5/Linux-Discussion/Yoga-2-13-not-Pro-Linux-Warning/m-p/1517612
Testing has shown that the firmware rfkill settings are persistent over
reboots. So blacklisting the driver is not good enough, if the wifi is blocked
at the firmware level the wifi needs to be explictly unblocked through the
ideapad-laptop interface.
And at least on the Lenovo Yoga 2 13 the VPCCMD_RF register which on devices
with hardware kill switch reports the hardware switch state, needs to be
explictly set to 1 (radio enabled / not blocked).
So this patch does 3 things to get proper rfkill handling on these models:
1) Instead of blacklisting the rfkill functionality, which means that people
with a firmware blocked wifi get stuck in that situation, ignore the value
reported by the not present hardware rfkill switch, as this is what is causing
ideapad-laptop to wrongly report all radios as hardware blocks. But do register
the rfkill interfaces so that the user can soft [un]block them.
2) On models without a hardware rfkill switch, explictly set VPCCMD_RF to 1
3) Drop the " 11" postfix from the dmi match string, as the entire Yoga 2
series is affected.
Yoga 2 11:
Reported-and-tested-by: Vincent Gerris <vgerris@gmail.com>
Yoga 2 13:
Tested-by: madls05 <http://ubuntuforums.org/showthread.php?t=2215044>
Yoga 2 Pro:
Reported-and-tested-by: Peter F. Patel-Schneider <pfpschneider@gmail.com>
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Matthew Garrett <matthew.garrett@nebula.com>
Cc: Gaudenz Steinlin <gaudenz@debian.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/platform/x86/ideapad-laptop.c | 41 +++++++++++++++++++++++------------
1 file changed, 27 insertions(+), 14 deletions(-)
diff --git a/drivers/platform/x86/ideapad-laptop.c b/drivers/platform/x86/ideapad-laptop.c
index 96056e29b673..7fe7ed830d8d 100644
--- a/drivers/platform/x86/ideapad-laptop.c
+++ b/drivers/platform/x86/ideapad-laptop.c
@@ -87,6 +87,7 @@ struct ideapad_private {
struct backlight_device *blightdev;
struct dentry *debug;
unsigned long cfg;
+ bool has_hw_rfkill_switch;
};
static bool no_bt_rfkill;
@@ -473,12 +474,14 @@ static struct rfkill_ops ideapad_rfk_ops = {
static void ideapad_sync_rfk_state(struct ideapad_private *priv)
{
- unsigned long hw_blocked;
+ unsigned long hw_blocked = 0;
int i;
- if (read_ec_data(priv->adev->handle, VPCCMD_R_RF, &hw_blocked))
- return;
- hw_blocked = !hw_blocked;
+ if (priv->has_hw_rfkill_switch) {
+ if (read_ec_data(priv->adev->handle, VPCCMD_R_RF, &hw_blocked))
+ return;
+ hw_blocked = !hw_blocked;
+ }
for (i = 0; i < IDEAPAD_RFKILL_DEV_NUM; i++)
if (priv->rfk[i])
@@ -821,14 +824,17 @@ static void ideapad_acpi_notify(acpi_handle handle, u32 event, void *data)
}
}
-/* Blacklist for devices where the ideapad rfkill interface does not work */
-static struct dmi_system_id rfkill_blacklist[] = {
- /* The Lenovo Yoga 2 11 always reports everything as blocked */
+/*
+ * Some ideapads don't have a hardware rfkill switch, reading VPCCMD_R_RF
+ * always results in 0 on these models, causing ideapad_laptop to wrongly
+ * report all radios as hardware-blocked.
+ */
+static struct dmi_system_id no_hw_rfkill_list[] = {
{
- .ident = "Lenovo Yoga 2 11",
+ .ident = "Lenovo Yoga 2 11 / 13 / Pro",
.matches = {
DMI_MATCH(DMI_SYS_VENDOR, "LENOVO"),
- DMI_MATCH(DMI_PRODUCT_VERSION, "Lenovo Yoga 2 11"),
+ DMI_MATCH(DMI_PRODUCT_VERSION, "Lenovo Yoga 2"),
},
},
{
@@ -863,6 +869,7 @@ static int ideapad_acpi_add(struct platform_device *pdev)
priv->cfg = cfg;
priv->adev = adev;
priv->platform_device = pdev;
+ priv->has_hw_rfkill_switch = !dmi_check_system(no_hw_rfkill_list);
ret = ideapad_sysfs_init(priv);
if (ret)
@@ -876,11 +883,17 @@ static int ideapad_acpi_add(struct platform_device *pdev)
if (ret)
goto input_failed;
- if (!dmi_check_system(rfkill_blacklist)) {
- for (i = 0; i < IDEAPAD_RFKILL_DEV_NUM; i++)
- if (test_bit(ideapad_rfk_data[i].cfgbit, &priv->cfg))
- ideapad_register_rfkill(priv, i);
- }
+ /*
+ * On some models without a hw-switch (the yoga 2 13 at least)
+ * VPCCMD_W_RF must be explicitly set to 1 for the wifi to work.
+ */
+ if (!priv->has_hw_rfkill_switch)
+ write_ec_cmd(priv->adev->handle, VPCCMD_W_RF, 1);
+
+ for (i = 0; i < IDEAPAD_RFKILL_DEV_NUM; i++)
+ if (test_bit(ideapad_rfk_data[i].cfgbit, &priv->cfg))
+ ideapad_register_rfkill(priv, i);
+
ideapad_sync_rfk_state(priv);
ideapad_sync_touchpad_state(priv);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 164/183] IB/core: When marshaling ucma path from user-space, clear unused fields
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (162 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 163/183] ideapad-laptop: Change Lenovo Yoga 2 series rfkill handling Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 165/183] IB/core: Fix deadlock on uverbs modify_qp error flow Luis Henriques
` (18 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Ilya Nelkenbaum, Or Gerlitz, Roland Dreier, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Nelkenbaum <ilyan@mellanox.com>
commit c2be9dc0e0fa59cc43c2c7084fc42b430809a0fe upstream.
When marshaling a user path to the kernel struct ib_sa_path, we need
to zero smac and dmac and set the vlan id to the "no vlan" value.
This is to ensure that Ethernet attributes are not used with
InfiniBand QPs.
Fixes: dd5f03beb4f7 ("IB/core: Ethernet L2 attributes in verbs/cm structures")
Signed-off-by: Ilya Nelkenbaum <ilyan@mellanox.com>
Signed-off-by: Or Gerlitz <ogerlitz@mellanox.com>
Signed-off-by: Roland Dreier <roland@purestorage.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/infiniband/core/ucma.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/infiniband/core/ucma.c b/drivers/infiniband/core/ucma.c
index 56a4b7ca7ee3..45d67e9228d7 100644
--- a/drivers/infiniband/core/ucma.c
+++ b/drivers/infiniband/core/ucma.c
@@ -1124,6 +1124,9 @@ static int ucma_set_ib_path(struct ucma_context *ctx,
if (!optlen)
return -EINVAL;
+ memset(&sa_path, 0, sizeof(sa_path));
+ sa_path.vlan_id = 0xffff;
+
ib_sa_unpack_path(path_data->path_rec, &sa_path);
ret = rdma_set_ib_paths(ctx->cm_id, &sa_path, 1);
if (ret)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 165/183] IB/core: Fix deadlock on uverbs modify_qp error flow
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (163 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 164/183] IB/core: When marshaling ucma path from user-space, clear unused fields Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 166/183] IB/mlx4: Fix wrong usage of IPv4 protocol for multicast attach/detach Luis Henriques
` (17 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Moshe Lazer, Or Gerlitz, Roland Dreier, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Moshe Lazer <moshel@mellanox.com>
commit 0fb8bcf022f19a375d7c4bd79ac513da8ae6d78b upstream.
The deadlock occurs in __uverbs_modify_qp: we take a lock (idr_read_qp)
and in case of failure in ib_resolve_eth_l2_attrs we don't release
it (put_qp_read). Fix that.
Fixes: ed4c54e5b4ba ("IB/core: Resolve Ethernet L2 addresses when modifying QP")
Signed-off-by: Moshe Lazer <moshel@mellanox.com>
Signed-off-by: Or Gerlitz <ogerlitz@mellanox.com>
Signed-off-by: Roland Dreier <roland@purestorage.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/infiniband/core/uverbs_cmd.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/infiniband/core/uverbs_cmd.c b/drivers/infiniband/core/uverbs_cmd.c
index 23467a2abd62..2adc14372b94 100644
--- a/drivers/infiniband/core/uverbs_cmd.c
+++ b/drivers/infiniband/core/uverbs_cmd.c
@@ -1964,20 +1964,21 @@ ssize_t ib_uverbs_modify_qp(struct ib_uverbs_file *file,
if (qp->real_qp == qp) {
ret = ib_resolve_eth_l2_attrs(qp, attr, &cmd.attr_mask);
if (ret)
- goto out;
+ goto release_qp;
ret = qp->device->modify_qp(qp, attr,
modify_qp_mask(qp->qp_type, cmd.attr_mask), &udata);
} else {
ret = ib_modify_qp(qp, attr, modify_qp_mask(qp->qp_type, cmd.attr_mask));
}
- put_qp_read(qp);
-
if (ret)
- goto out;
+ goto release_qp;
ret = in_len;
+release_qp:
+ put_qp_read(qp);
+
out:
kfree(attr);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 166/183] IB/mlx4: Fix wrong usage of IPv4 protocol for multicast attach/detach
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (164 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 165/183] IB/core: Fix deadlock on uverbs modify_qp error flow Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 167/183] IB/iser: Use correct dma direction when unmapping SGs Luis Henriques
` (16 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Or Gerlitz, Roland Dreier, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Or Gerlitz <ogerlitz@mellanox.com>
commit e9a7faf11af94957e5107b40af46c2e329541510 upstream.
The MLX4_PROT_IB_IPV4 protocol should only be used with RoCEv2 and such.
Removing this wrong usage allows to run multicast applications over RoCE.
Fixes: d487ee77740c ("IB/mlx4: Use IBoE (RoCE) IP based GIDs in the port GID table")
Reported-by: Carol Soto <clsoto@linux.vnet.ibm.com>
Signed-off-by: Or Gerlitz <ogerlitz@mellanox.com>
Signed-off-by: Roland Dreier <roland@purestorage.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/infiniband/hw/mlx4/main.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/drivers/infiniband/hw/mlx4/main.c b/drivers/infiniband/hw/mlx4/main.c
index 91eeb5edff80..e48e96528657 100644
--- a/drivers/infiniband/hw/mlx4/main.c
+++ b/drivers/infiniband/hw/mlx4/main.c
@@ -1170,8 +1170,7 @@ static int mlx4_ib_mcg_attach(struct ib_qp *ibqp, union ib_gid *gid, u16 lid)
struct mlx4_ib_qp *mqp = to_mqp(ibqp);
u64 reg_id;
struct mlx4_ib_steering *ib_steering = NULL;
- enum mlx4_protocol prot = (gid->raw[1] == 0x0e) ?
- MLX4_PROT_IB_IPV4 : MLX4_PROT_IB_IPV6;
+ enum mlx4_protocol prot = MLX4_PROT_IB_IPV6;
if (mdev->dev->caps.steering_mode ==
MLX4_STEERING_MODE_DEVICE_MANAGED) {
@@ -1184,8 +1183,10 @@ static int mlx4_ib_mcg_attach(struct ib_qp *ibqp, union ib_gid *gid, u16 lid)
!!(mqp->flags &
MLX4_IB_QP_BLOCK_MULTICAST_LOOPBACK),
prot, ®_id);
- if (err)
+ if (err) {
+ pr_err("multicast attach op failed, err %d\n", err);
goto err_malloc;
+ }
err = add_gid_entry(ibqp, gid);
if (err)
@@ -1233,8 +1234,7 @@ static int mlx4_ib_mcg_detach(struct ib_qp *ibqp, union ib_gid *gid, u16 lid)
struct net_device *ndev;
struct mlx4_ib_gid_entry *ge;
u64 reg_id = 0;
- enum mlx4_protocol prot = (gid->raw[1] == 0x0e) ?
- MLX4_PROT_IB_IPV4 : MLX4_PROT_IB_IPV6;
+ enum mlx4_protocol prot = MLX4_PROT_IB_IPV6;
if (mdev->dev->caps.steering_mode ==
MLX4_STEERING_MODE_DEVICE_MANAGED) {
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 167/183] IB/iser: Use correct dma direction when unmapping SGs
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (165 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 166/183] IB/mlx4: Fix wrong usage of IPv4 protocol for multicast attach/detach Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 168/183] [media] Si2168: increase timeout to fix firmware loading Luis Henriques
` (15 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Roi Dayan, Or Gerlitz, Roland Dreier, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Roi Dayan <roid@mellanox.com>
commit c6c95ef4cec680f7a10aa425a9970744b35b6489 upstream.
We always unmap SGs with the same direction instead of unmapping
with the direction the mapping was done, fix that.
Fixes: 9a8b08fad2ef ("IB/iser: Generalize iser_unmap_task_data and [...]")
Signed-off-by: Roi Dayan <roid@mellanox.com>
Signed-off-by: Or Gerlitz <ogerlitz@mellanox.com>
Signed-off-by: Roland Dreier <roland@purestorage.com>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/infiniband/ulp/iser/iscsi_iser.h | 4 +++-
drivers/infiniband/ulp/iser/iser_initiator.c | 12 ++++++++----
drivers/infiniband/ulp/iser/iser_memory.c | 9 ++++++---
3 files changed, 17 insertions(+), 8 deletions(-)
diff --git a/drivers/infiniband/ulp/iser/iscsi_iser.h b/drivers/infiniband/ulp/iser/iscsi_iser.h
index 97cd385bf7f7..7bd85f694999 100644
--- a/drivers/infiniband/ulp/iser/iscsi_iser.h
+++ b/drivers/infiniband/ulp/iser/iscsi_iser.h
@@ -471,7 +471,9 @@ int iser_dma_map_task_data(struct iscsi_iser_task *iser_task,
enum dma_data_direction dma_dir);
void iser_dma_unmap_task_data(struct iscsi_iser_task *iser_task,
- struct iser_data_buf *data);
+ struct iser_data_buf *data,
+ enum dma_data_direction dir);
+
int iser_initialize_task_headers(struct iscsi_task *task,
struct iser_tx_desc *tx_desc);
int iser_alloc_rx_descriptors(struct iser_conn *ib_conn, struct iscsi_session *session);
diff --git a/drivers/infiniband/ulp/iser/iser_initiator.c b/drivers/infiniband/ulp/iser/iser_initiator.c
index 8d44a4060634..73c4ca8d2458 100644
--- a/drivers/infiniband/ulp/iser/iser_initiator.c
+++ b/drivers/infiniband/ulp/iser/iser_initiator.c
@@ -702,19 +702,23 @@ void iser_task_rdma_finalize(struct iscsi_iser_task *iser_task)
device->iser_unreg_rdma_mem(iser_task, ISER_DIR_IN);
if (is_rdma_data_aligned)
iser_dma_unmap_task_data(iser_task,
- &iser_task->data[ISER_DIR_IN]);
+ &iser_task->data[ISER_DIR_IN],
+ DMA_FROM_DEVICE);
if (prot_count && is_rdma_prot_aligned)
iser_dma_unmap_task_data(iser_task,
- &iser_task->prot[ISER_DIR_IN]);
+ &iser_task->prot[ISER_DIR_IN],
+ DMA_FROM_DEVICE);
}
if (iser_task->dir[ISER_DIR_OUT]) {
device->iser_unreg_rdma_mem(iser_task, ISER_DIR_OUT);
if (is_rdma_data_aligned)
iser_dma_unmap_task_data(iser_task,
- &iser_task->data[ISER_DIR_OUT]);
+ &iser_task->data[ISER_DIR_OUT],
+ DMA_TO_DEVICE);
if (prot_count && is_rdma_prot_aligned)
iser_dma_unmap_task_data(iser_task,
- &iser_task->prot[ISER_DIR_OUT]);
+ &iser_task->prot[ISER_DIR_OUT],
+ DMA_TO_DEVICE);
}
}
diff --git a/drivers/infiniband/ulp/iser/iser_memory.c b/drivers/infiniband/ulp/iser/iser_memory.c
index 47acd3ad3a17..e5e16cdc0618 100644
--- a/drivers/infiniband/ulp/iser/iser_memory.c
+++ b/drivers/infiniband/ulp/iser/iser_memory.c
@@ -333,12 +333,13 @@ int iser_dma_map_task_data(struct iscsi_iser_task *iser_task,
}
void iser_dma_unmap_task_data(struct iscsi_iser_task *iser_task,
- struct iser_data_buf *data)
+ struct iser_data_buf *data,
+ enum dma_data_direction dir)
{
struct ib_device *dev;
dev = iser_task->ib_conn->device->ib_device;
- ib_dma_unmap_sg(dev, data->buf, data->size, DMA_FROM_DEVICE);
+ ib_dma_unmap_sg(dev, data->buf, data->size, dir);
}
static int fall_to_bounce_buf(struct iscsi_iser_task *iser_task,
@@ -358,7 +359,9 @@ static int fall_to_bounce_buf(struct iscsi_iser_task *iser_task,
iser_data_buf_dump(mem, ibdev);
/* unmap the command data before accessing it */
- iser_dma_unmap_task_data(iser_task, mem);
+ iser_dma_unmap_task_data(iser_task, mem,
+ (cmd_dir == ISER_DIR_OUT) ?
+ DMA_TO_DEVICE : DMA_FROM_DEVICE);
/* allocate copy buf, if we are writing, copy the */
/* unaligned scatterlist, dma map the copy */
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 168/183] [media] Si2168: increase timeout to fix firmware loading
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (166 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 167/183] IB/iser: Use correct dma direction when unmapping SGs Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 169/183] staging: comedi: cb_pcidas64: fix incorrect AI range code handling Luis Henriques
` (14 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Jurgen Kramer, Mauro Carvalho Chehab, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jurgen Kramer <gtmkramer@xs4all.nl>
commit 551c33e729f654ecfaed00ad399f5d2a631b72cb upstream.
Increase si2168 cmd execute timeout to prevent firmware load failures. Tests
shows it takes up to 52ms to load the 'dvb-demod-si2168-a30-01.fw' firmware.
Increase timeout to a safe value of 70ms.
Signed-off-by: Jurgen Kramer <gtmkramer@xs4all.nl>
Reviewed-by: Antti Palosaari <crope@iki.fi>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/media/dvb-frontends/si2168.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/media/dvb-frontends/si2168.c b/drivers/media/dvb-frontends/si2168.c
index 23cc7f089974..f6846954b9a6 100644
--- a/drivers/media/dvb-frontends/si2168.c
+++ b/drivers/media/dvb-frontends/si2168.c
@@ -39,7 +39,7 @@ static int si2168_cmd_execute(struct si2168 *s, struct si2168_cmd *cmd)
if (cmd->rlen) {
/* wait cmd execution terminate */
- #define TIMEOUT 50
+ #define TIMEOUT 70
timeout = jiffies + msecs_to_jiffies(TIMEOUT);
while (!time_after(jiffies, timeout)) {
ret = i2c_master_recv(s->client, cmd->args, cmd->rlen);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 169/183] staging: comedi: cb_pcidas64: fix incorrect AI range code handling
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (167 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 168/183] [media] Si2168: increase timeout to fix firmware loading Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 170/183] target: Fix R_HOLDER bit usage for AllRegistrants Luis Henriques
` (13 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Ian Abbott, Greg Kroah-Hartman, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Abbott <abbotti@mev.co.uk>
commit be8e89087ec2d2c8a1ad1e3db64bf4efdfc3c298 upstream.
The hardware range code values and list of valid ranges for the AI
subdevice is incorrect for several supported boards. The hardware range
code values for all boards except PCI-DAS4020/12 is determined by
calling `ai_range_bits_6xxx()` based on the maximum voltage of the range
and whether it is bipolar or unipolar, however it only returns the
correct hardware range code for the PCI-DAS60xx boards. For
PCI-DAS6402/16 (and /12) it returns the wrong code for the unipolar
ranges. For PCI-DAS64/Mx/16 it returns the wrong code for all the
ranges and the comedi range table is incorrect.
Change `ai_range_bits_6xxx()` to use a look-up table pointed to by new
member `ai_range_codes` of `struct pcidas64_board` to map the comedi
range table indices to the hardware range codes. Use a new comedi range
table for the PCI-DAS64/Mx/16 boards (and the commented out variants).
Signed-off-by: Ian Abbott <abbotti@mev.co.uk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/staging/comedi/drivers/cb_pcidas64.c | 122 ++++++++++++++++-----------
1 file changed, 75 insertions(+), 47 deletions(-)
diff --git a/drivers/staging/comedi/drivers/cb_pcidas64.c b/drivers/staging/comedi/drivers/cb_pcidas64.c
index 035c3a176005..18097b18fe5e 100644
--- a/drivers/staging/comedi/drivers/cb_pcidas64.c
+++ b/drivers/staging/comedi/drivers/cb_pcidas64.c
@@ -441,6 +441,29 @@ static const struct comedi_lrange ai_ranges_64xx = {
}
};
+static const uint8_t ai_range_code_64xx[8] = {
+ 0x0, 0x1, 0x2, 0x3, /* bipolar 10, 5, 2,5, 1.25 */
+ 0x8, 0x9, 0xa, 0xb /* unipolar 10, 5, 2.5, 1.25 */
+};
+
+/* analog input ranges for 64-Mx boards */
+static const struct comedi_lrange ai_ranges_64_mx = {
+ 7, {
+ BIP_RANGE(5),
+ BIP_RANGE(2.5),
+ BIP_RANGE(1.25),
+ BIP_RANGE(0.625),
+ UNI_RANGE(5),
+ UNI_RANGE(2.5),
+ UNI_RANGE(1.25)
+ }
+};
+
+static const uint8_t ai_range_code_64_mx[7] = {
+ 0x0, 0x1, 0x2, 0x3, /* bipolar 5, 2.5, 1.25, 0.625 */
+ 0x9, 0xa, 0xb /* unipolar 5, 2.5, 1.25 */
+};
+
/* analog input ranges for 60xx boards */
static const struct comedi_lrange ai_ranges_60xx = {
4, {
@@ -451,6 +474,10 @@ static const struct comedi_lrange ai_ranges_60xx = {
}
};
+static const uint8_t ai_range_code_60xx[4] = {
+ 0x0, 0x1, 0x4, 0x7 /* bipolar 10, 5, 0.5, 0.05 */
+};
+
/* analog input ranges for 6030, etc boards */
static const struct comedi_lrange ai_ranges_6030 = {
14, {
@@ -471,6 +498,11 @@ static const struct comedi_lrange ai_ranges_6030 = {
}
};
+static const uint8_t ai_range_code_6030[14] = {
+ 0x0, 0x1, 0x2, 0x3, 0x4, 0x5, 0x6, /* bip 10, 5, 2, 1, 0.5, 0.2, 0.1 */
+ 0x9, 0xa, 0xb, 0xc, 0xd, 0xe, 0xf /* uni 10, 5, 2, 1, 0.5, 0.2, 0.1 */
+};
+
/* analog input ranges for 6052, etc boards */
static const struct comedi_lrange ai_ranges_6052 = {
15, {
@@ -492,6 +524,11 @@ static const struct comedi_lrange ai_ranges_6052 = {
}
};
+static const uint8_t ai_range_code_6052[15] = {
+ 0x0, 0x1, 0x2, 0x3, 0x4, 0x5, 0x6, 0x7, /* bipolar 10 ... 0.05 */
+ 0x9, 0xa, 0xb, 0xc, 0xd, 0xe, 0xf /* unipolar 10 ... 0.1 */
+};
+
/* analog input ranges for 4020 board */
static const struct comedi_lrange ai_ranges_4020 = {
2, {
@@ -595,6 +632,7 @@ struct pcidas64_board {
int ai_bits; /* analog input resolution */
int ai_speed; /* fastest conversion period in ns */
const struct comedi_lrange *ai_range_table;
+ const uint8_t *ai_range_code;
int ao_nchan; /* number of analog out channels */
int ao_bits; /* analog output resolution */
int ao_scan_speed; /* analog output scan speed */
@@ -653,6 +691,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 10000,
.layout = LAYOUT_64XX,
.ai_range_table = &ai_ranges_64xx,
+ .ai_range_code = ai_range_code_64xx,
.ao_range_table = &ao_ranges_64xx,
.ao_range_code = ao_range_code_64xx,
.ai_fifo = &ai_fifo_64xx,
@@ -668,6 +707,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 10000,
.layout = LAYOUT_64XX,
.ai_range_table = &ai_ranges_64xx,
+ .ai_range_code = ai_range_code_64xx,
.ao_range_table = &ao_ranges_64xx,
.ao_range_code = ao_range_code_64xx,
.ai_fifo = &ai_fifo_64xx,
@@ -682,7 +722,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_bits = 16,
.ao_scan_speed = 10000,
.layout = LAYOUT_64XX,
- .ai_range_table = &ai_ranges_64xx,
+ .ai_range_table = &ai_ranges_64_mx,
+ .ai_range_code = ai_range_code_64_mx,
.ao_range_table = &ao_ranges_64xx,
.ao_range_code = ao_range_code_64xx,
.ai_fifo = &ai_fifo_64xx,
@@ -697,7 +738,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_bits = 16,
.ao_scan_speed = 10000,
.layout = LAYOUT_64XX,
- .ai_range_table = &ai_ranges_64xx,
+ .ai_range_table = &ai_ranges_64_mx,
+ .ai_range_code = ai_range_code_64_mx,
.ao_range_table = &ao_ranges_64xx,
.ao_range_code = ao_range_code_64xx,
.ai_fifo = &ai_fifo_64xx,
@@ -712,7 +754,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_bits = 16,
.ao_scan_speed = 10000,
.layout = LAYOUT_64XX,
- .ai_range_table = &ai_ranges_64xx,
+ .ai_range_table = &ai_ranges_64_mx,
+ .ai_range_code = ai_range_code_64_mx,
.ao_range_table = &ao_ranges_64xx,
.ao_range_code = ao_range_code_64xx,
.ai_fifo = &ai_fifo_64xx,
@@ -727,6 +770,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_bits = 16,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_60xx,
+ .ai_range_code = ai_range_code_60xx,
.ao_range_table = &range_bipolar10,
.ao_range_code = ao_range_code_60xx,
.ai_fifo = &ai_fifo_60xx,
@@ -742,6 +786,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 100000,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_60xx,
+ .ai_range_code = ai_range_code_60xx,
.ao_range_table = &range_bipolar10,
.ao_range_code = ao_range_code_60xx,
.ai_fifo = &ai_fifo_60xx,
@@ -756,6 +801,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 100000,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_60xx,
+ .ai_range_code = ai_range_code_60xx,
.ao_range_table = &range_bipolar10,
.ao_range_code = ao_range_code_60xx,
.ai_fifo = &ai_fifo_60xx,
@@ -771,6 +817,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 100000,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_60xx,
+ .ai_range_code = ai_range_code_60xx,
.ao_range_table = &range_bipolar10,
.ao_range_code = ao_range_code_60xx,
.ai_fifo = &ai_fifo_60xx,
@@ -786,6 +833,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 10000,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_6030,
+ .ai_range_code = ai_range_code_6030,
.ao_range_table = &ao_ranges_6030,
.ao_range_code = ao_range_code_6030,
.ai_fifo = &ai_fifo_60xx,
@@ -801,6 +849,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 10000,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_6030,
+ .ai_range_code = ai_range_code_6030,
.ao_range_table = &ao_ranges_6030,
.ao_range_code = ao_range_code_6030,
.ai_fifo = &ai_fifo_60xx,
@@ -814,6 +863,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_nchan = 0,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_6030,
+ .ai_range_code = ai_range_code_6030,
.ai_fifo = &ai_fifo_60xx,
.has_8255 = 0,
},
@@ -825,6 +875,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_nchan = 0,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_6030,
+ .ai_range_code = ai_range_code_6030,
.ai_fifo = &ai_fifo_60xx,
.has_8255 = 0,
},
@@ -837,6 +888,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 0,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_60xx,
+ .ai_range_code = ai_range_code_60xx,
.ai_fifo = &ai_fifo_60xx,
.has_8255 = 0,
},
@@ -850,6 +902,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 100000,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_60xx,
+ .ai_range_code = ai_range_code_60xx,
.ao_range_table = &range_bipolar10,
.ao_range_code = ao_range_code_60xx,
.ai_fifo = &ai_fifo_60xx,
@@ -865,6 +918,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 100000,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_60xx,
+ .ai_range_code = ai_range_code_60xx,
.ao_range_table = &range_bipolar10,
.ao_range_code = ao_range_code_60xx,
.ai_fifo = &ai_fifo_60xx,
@@ -880,6 +934,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 1000,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_6052,
+ .ai_range_code = ai_range_code_6052,
.ao_range_table = &ao_ranges_6030,
.ao_range_code = ao_range_code_6030,
.ai_fifo = &ai_fifo_60xx,
@@ -895,6 +950,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 3333,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_6052,
+ .ai_range_code = ai_range_code_6052,
.ao_range_table = &ao_ranges_6030,
.ao_range_code = ao_range_code_6030,
.ai_fifo = &ai_fifo_60xx,
@@ -910,6 +966,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 1000,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_6052,
+ .ai_range_code = ai_range_code_6052,
.ao_range_table = &ao_ranges_6030,
.ao_range_code = ao_range_code_6030,
.ai_fifo = &ai_fifo_60xx,
@@ -925,6 +982,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 1000,
.layout = LAYOUT_60XX,
.ai_range_table = &ai_ranges_6052,
+ .ai_range_code = ai_range_code_6052,
.ao_range_table = &ao_ranges_6030,
.ao_range_code = ao_range_code_6030,
.ai_fifo = &ai_fifo_60xx,
@@ -959,6 +1017,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_scan_speed = 10000,
.layout = LAYOUT_64XX,
.ai_range_table = &ai_ranges_64xx,
+ .ai_range_code = ai_range_code_64xx,
.ai_fifo = ai_fifo_64xx,
.has_8255 = 1,
},
@@ -970,7 +1029,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_nchan = 0,
.ao_scan_speed = 10000,
.layout = LAYOUT_64XX,
- .ai_range_table = &ai_ranges_64xx,
+ .ai_range_table = &ai_ranges_64_mx,
+ .ai_range_code = ai_range_code_64_mx,
.ai_fifo = ai_fifo_64xx,
.has_8255 = 1,
},
@@ -982,7 +1042,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_nchan = 0,
.ao_scan_speed = 10000,
.layout = LAYOUT_64XX,
- .ai_range_table = &ai_ranges_64xx,
+ .ai_range_table = &ai_ranges_64_mx,
+ .ai_range_code = ai_range_code_64_mx,
.ai_fifo = ai_fifo_64xx,
.has_8255 = 1,
},
@@ -994,7 +1055,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_nchan = 0,
.ao_scan_speed = 10000,
.layout = LAYOUT_64XX,
- .ai_range_table = &ai_ranges_64xx,
+ .ai_range_table = &ai_ranges_64_mx,
+ .ai_range_code = ai_range_code_64_mx,
.ai_fifo = ai_fifo_64xx,
.has_8255 = 1,
},
@@ -1006,7 +1068,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_nchan = 2,
.ao_scan_speed = 10000,
.layout = LAYOUT_64XX,
- .ai_range_table = &ai_ranges_64xx,
+ .ai_range_table = &ai_ranges_64_mx,
+ .ai_range_code = ai_range_code_64_mx,
.ai_fifo = ai_fifo_64xx,
.has_8255 = 1,
},
@@ -1018,7 +1081,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_nchan = 2,
.ao_scan_speed = 10000,
.layout = LAYOUT_64XX,
- .ai_range_table = &ai_ranges_64xx,
+ .ai_range_table = &ai_ranges_64_mx,
+ .ai_range_code = ai_range_code_64_mx,
.ai_fifo = ai_fifo_64xx,
.has_8255 = 1,
},
@@ -1030,7 +1094,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
.ao_nchan = 2,
.ao_scan_speed = 10000,
.layout = LAYOUT_64XX,
- .ai_range_table = &ai_ranges_64xx,
+ .ai_range_table = &ai_ranges_64_mx,
+ .ai_range_code = ai_range_code_64_mx,
.ai_fifo = ai_fifo_64xx,
.has_8255 = 1,
},
@@ -1127,45 +1192,8 @@ static unsigned int ai_range_bits_6xxx(const struct comedi_device *dev,
unsigned int range_index)
{
const struct pcidas64_board *thisboard = comedi_board(dev);
- const struct comedi_krange *range =
- &thisboard->ai_range_table->range[range_index];
- unsigned int bits = 0;
- switch (range->max) {
- case 10000000:
- bits = 0x000;
- break;
- case 5000000:
- bits = 0x100;
- break;
- case 2000000:
- case 2500000:
- bits = 0x200;
- break;
- case 1000000:
- case 1250000:
- bits = 0x300;
- break;
- case 500000:
- bits = 0x400;
- break;
- case 200000:
- case 250000:
- bits = 0x500;
- break;
- case 100000:
- bits = 0x600;
- break;
- case 50000:
- bits = 0x700;
- break;
- default:
- comedi_error(dev, "bug! in ai_range_bits_6xxx");
- break;
- }
- if (range->min == 0)
- bits += 0x900;
- return bits;
+ return thisboard->ai_range_code[range_index] << 8;
}
static unsigned int hw_revision(const struct comedi_device *dev,
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 170/183] target: Fix R_HOLDER bit usage for AllRegistrants
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (168 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 169/183] staging: comedi: cb_pcidas64: fix incorrect AI range code handling Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 171/183] target: Avoid dropping AllRegistrants reservation during unregister Luis Henriques
` (12 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: James Bottomley, Nicholas Bellinger, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicholas Bellinger <nab@linux-iscsi.org>
commit d16ca7c5198fd668db10d2c7b048ed3359c12c54 upstream.
This patch fixes the usage of R_HOLDER bit for an All Registrants
reservation in READ_FULL_STATUS, where only the registration who
issued RESERVE was being reported as having an active reservation.
It changes core_scsi3_pri_read_full_status() to check ahead of the
list walk of active registrations to see if All Registrants is active,
and if so set R_HOLDER bit and scope/type fields for all active
registrations.
Reported-by: Ilias Tsitsimpis <i.tsitsimpis@gmail.com>
Cc: James Bottomley <James.Bottomley@HansenPartnership.com>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/target/target_core_pr.c | 26 +++++++++++++++++++++++---
1 file changed, 23 insertions(+), 3 deletions(-)
diff --git a/drivers/target/target_core_pr.c b/drivers/target/target_core_pr.c
index d6d4d8b6c2a1..1c153ed5c415 100644
--- a/drivers/target/target_core_pr.c
+++ b/drivers/target/target_core_pr.c
@@ -3855,7 +3855,8 @@ core_scsi3_pri_read_full_status(struct se_cmd *cmd)
unsigned char *buf;
u32 add_desc_len = 0, add_len = 0, desc_len, exp_desc_len;
u32 off = 8; /* off into first Full Status descriptor */
- int format_code = 0;
+ int format_code = 0, pr_res_type = 0, pr_res_scope = 0;
+ bool all_reg = false;
if (cmd->data_length < 8) {
pr_err("PRIN SA READ_FULL_STATUS SCSI Data Length: %u"
@@ -3872,6 +3873,19 @@ core_scsi3_pri_read_full_status(struct se_cmd *cmd)
buf[2] = ((dev->t10_pr.pr_generation >> 8) & 0xff);
buf[3] = (dev->t10_pr.pr_generation & 0xff);
+ spin_lock(&dev->dev_reservation_lock);
+ if (dev->dev_pr_res_holder) {
+ struct t10_pr_registration *pr_holder = dev->dev_pr_res_holder;
+
+ if (pr_holder->pr_res_type == PR_TYPE_WRITE_EXCLUSIVE_ALLREG ||
+ pr_holder->pr_res_type == PR_TYPE_EXCLUSIVE_ACCESS_ALLREG) {
+ all_reg = true;
+ pr_res_type = pr_holder->pr_res_type;
+ pr_res_scope = pr_holder->pr_res_scope;
+ }
+ }
+ spin_unlock(&dev->dev_reservation_lock);
+
spin_lock(&pr_tmpl->registration_lock);
list_for_each_entry_safe(pr_reg, pr_reg_tmp,
&pr_tmpl->registration_list, pr_reg_list) {
@@ -3921,14 +3935,20 @@ core_scsi3_pri_read_full_status(struct se_cmd *cmd)
* reservation holder for PR_HOLDER bit.
*
* Also, if this registration is the reservation
- * holder, fill in SCOPE and TYPE in the next byte.
+ * holder or there is an All Registrants reservation
+ * active, fill in SCOPE and TYPE in the next byte.
*/
if (pr_reg->pr_res_holder) {
buf[off++] |= 0x01;
buf[off++] = (pr_reg->pr_res_scope & 0xf0) |
(pr_reg->pr_res_type & 0x0f);
- } else
+ } else if (all_reg) {
+ buf[off++] |= 0x01;
+ buf[off++] = (pr_res_scope & 0xf0) |
+ (pr_res_type & 0x0f);
+ } else {
off += 2;
+ }
off += 4; /* Skip over reserved area */
/*
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 171/183] target: Avoid dropping AllRegistrants reservation during unregister
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (169 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 170/183] target: Fix R_HOLDER bit usage for AllRegistrants Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 172/183] target: Allow AllRegistrants to re-RESERVE existing reservation Luis Henriques
` (11 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: James Bottomley, Nicholas Bellinger, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicholas Bellinger <nab@linux-iscsi.org>
commit 6c3c9baa0debeb4bcc52a78c4463a0a97518de10 upstream.
This patch fixes an issue with AllRegistrants reservations where
an unregister operation by the I_T nexus reservation holder would
incorrectly drop the reservation, instead of waiting until the
last active I_T nexus is unregistered as per SPC-4.
This includes updating __core_scsi3_complete_pro_release() to reset
dev->dev_pr_res_holder with another pr_reg for this special case,
as well as a new 'unreg' parameter to determine when the release
is occuring from an implicit unregister, vs. explicit RELEASE.
It also adds special handling in core_scsi3_free_pr_reg_from_nacl()
to release the left-over pr_res_holder, now that pr_reg is deleted
from pr_reg_list within __core_scsi3_complete_pro_release().
Reported-by: Ilias Tsitsimpis <i.tsitsimpis@gmail.com>
Cc: James Bottomley <James.Bottomley@HansenPartnership.com>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/target/target_core_pr.c | 87 ++++++++++++++++++++++++++++++-----------
1 file changed, 65 insertions(+), 22 deletions(-)
diff --git a/drivers/target/target_core_pr.c b/drivers/target/target_core_pr.c
index 1c153ed5c415..6ea72db87460 100644
--- a/drivers/target/target_core_pr.c
+++ b/drivers/target/target_core_pr.c
@@ -76,7 +76,7 @@ enum preempt_type {
};
static void __core_scsi3_complete_pro_release(struct se_device *, struct se_node_acl *,
- struct t10_pr_registration *, int);
+ struct t10_pr_registration *, int, int);
static sense_reason_t
target_scsi2_reservation_check(struct se_cmd *cmd)
@@ -1186,7 +1186,7 @@ static int core_scsi3_check_implicit_release(
* service action with the SERVICE ACTION RESERVATION KEY
* field set to zero (see 5.7.11.3).
*/
- __core_scsi3_complete_pro_release(dev, nacl, pr_reg, 0);
+ __core_scsi3_complete_pro_release(dev, nacl, pr_reg, 0, 1);
ret = 1;
/*
* For 'All Registrants' reservation types, all existing
@@ -1228,7 +1228,8 @@ static void __core_scsi3_free_registration(
pr_reg->pr_reg_deve->def_pr_registered = 0;
pr_reg->pr_reg_deve->pr_res_key = 0;
- list_del(&pr_reg->pr_reg_list);
+ if (!list_empty(&pr_reg->pr_reg_list))
+ list_del(&pr_reg->pr_reg_list);
/*
* Caller accessing *pr_reg using core_scsi3_locate_pr_reg(),
* so call core_scsi3_put_pr_reg() to decrement our reference.
@@ -1280,6 +1281,7 @@ void core_scsi3_free_pr_reg_from_nacl(
{
struct t10_reservation *pr_tmpl = &dev->t10_pr;
struct t10_pr_registration *pr_reg, *pr_reg_tmp, *pr_res_holder;
+ bool free_reg = false;
/*
* If the passed se_node_acl matches the reservation holder,
* release the reservation.
@@ -1287,13 +1289,18 @@ void core_scsi3_free_pr_reg_from_nacl(
spin_lock(&dev->dev_reservation_lock);
pr_res_holder = dev->dev_pr_res_holder;
if ((pr_res_holder != NULL) &&
- (pr_res_holder->pr_reg_nacl == nacl))
- __core_scsi3_complete_pro_release(dev, nacl, pr_res_holder, 0);
+ (pr_res_holder->pr_reg_nacl == nacl)) {
+ __core_scsi3_complete_pro_release(dev, nacl, pr_res_holder, 0, 1);
+ free_reg = true;
+ }
spin_unlock(&dev->dev_reservation_lock);
/*
* Release any registration associated with the struct se_node_acl.
*/
spin_lock(&pr_tmpl->registration_lock);
+ if (pr_res_holder && free_reg)
+ __core_scsi3_free_registration(dev, pr_res_holder, NULL, 0);
+
list_for_each_entry_safe(pr_reg, pr_reg_tmp,
&pr_tmpl->registration_list, pr_reg_list) {
@@ -1316,7 +1323,7 @@ void core_scsi3_free_all_registrations(
if (pr_res_holder != NULL) {
struct se_node_acl *pr_res_nacl = pr_res_holder->pr_reg_nacl;
__core_scsi3_complete_pro_release(dev, pr_res_nacl,
- pr_res_holder, 0);
+ pr_res_holder, 0, 0);
}
spin_unlock(&dev->dev_reservation_lock);
@@ -2126,13 +2133,13 @@ core_scsi3_emulate_pro_register(struct se_cmd *cmd, u64 res_key, u64 sa_res_key,
/*
* sa_res_key=0 Unregister Reservation Key for registered I_T Nexus.
*/
- pr_holder = core_scsi3_check_implicit_release(
- cmd->se_dev, pr_reg);
+ type = pr_reg->pr_res_type;
+ pr_holder = core_scsi3_check_implicit_release(cmd->se_dev,
+ pr_reg);
if (pr_holder < 0) {
ret = TCM_RESERVATION_CONFLICT;
goto out;
}
- type = pr_reg->pr_res_type;
spin_lock(&pr_tmpl->registration_lock);
/*
@@ -2406,23 +2413,59 @@ static void __core_scsi3_complete_pro_release(
struct se_device *dev,
struct se_node_acl *se_nacl,
struct t10_pr_registration *pr_reg,
- int explicit)
+ int explicit,
+ int unreg)
{
struct target_core_fabric_ops *tfo = se_nacl->se_tpg->se_tpg_tfo;
char i_buf[PR_REG_ISID_ID_LEN];
+ int pr_res_type = 0, pr_res_scope = 0;
memset(i_buf, 0, PR_REG_ISID_ID_LEN);
core_pr_dump_initiator_port(pr_reg, i_buf, PR_REG_ISID_ID_LEN);
/*
* Go ahead and release the current PR reservation holder.
+ * If an All Registrants reservation is currently active and
+ * a unregister operation is requested, replace the current
+ * dev_pr_res_holder with another active registration.
*/
- dev->dev_pr_res_holder = NULL;
+ if (dev->dev_pr_res_holder) {
+ pr_res_type = dev->dev_pr_res_holder->pr_res_type;
+ pr_res_scope = dev->dev_pr_res_holder->pr_res_scope;
+ dev->dev_pr_res_holder->pr_res_type = 0;
+ dev->dev_pr_res_holder->pr_res_scope = 0;
+ dev->dev_pr_res_holder->pr_res_holder = 0;
+ dev->dev_pr_res_holder = NULL;
+ }
+ if (!unreg)
+ goto out;
- pr_debug("SPC-3 PR [%s] Service Action: %s RELEASE cleared"
- " reservation holder TYPE: %s ALL_TG_PT: %d\n",
- tfo->get_fabric_name(), (explicit) ? "explicit" : "implicit",
- core_scsi3_pr_dump_type(pr_reg->pr_res_type),
- (pr_reg->pr_reg_all_tg_pt) ? 1 : 0);
+ spin_lock(&dev->t10_pr.registration_lock);
+ list_del_init(&pr_reg->pr_reg_list);
+ /*
+ * If the I_T nexus is a reservation holder, the persistent reservation
+ * is of an all registrants type, and the I_T nexus is the last remaining
+ * registered I_T nexus, then the device server shall also release the
+ * persistent reservation.
+ */
+ if (!list_empty(&dev->t10_pr.registration_list) &&
+ ((pr_res_type == PR_TYPE_WRITE_EXCLUSIVE_ALLREG) ||
+ (pr_res_type == PR_TYPE_EXCLUSIVE_ACCESS_ALLREG))) {
+ dev->dev_pr_res_holder =
+ list_entry(dev->t10_pr.registration_list.next,
+ struct t10_pr_registration, pr_reg_list);
+ dev->dev_pr_res_holder->pr_res_type = pr_res_type;
+ dev->dev_pr_res_holder->pr_res_scope = pr_res_scope;
+ dev->dev_pr_res_holder->pr_res_holder = 1;
+ }
+ spin_unlock(&dev->t10_pr.registration_lock);
+out:
+ if (!dev->dev_pr_res_holder) {
+ pr_debug("SPC-3 PR [%s] Service Action: %s RELEASE cleared"
+ " reservation holder TYPE: %s ALL_TG_PT: %d\n",
+ tfo->get_fabric_name(), (explicit) ? "explicit" :
+ "implicit", core_scsi3_pr_dump_type(pr_res_type),
+ (pr_reg->pr_reg_all_tg_pt) ? 1 : 0);
+ }
pr_debug("SPC-3 PR [%s] RELEASE Node: %s%s\n",
tfo->get_fabric_name(), se_nacl->initiatorname,
i_buf);
@@ -2553,7 +2596,7 @@ core_scsi3_emulate_pro_release(struct se_cmd *cmd, int type, int scope,
* server shall not establish a unit attention condition.
*/
__core_scsi3_complete_pro_release(dev, se_sess->se_node_acl,
- pr_reg, 1);
+ pr_reg, 1, 0);
spin_unlock(&dev->dev_reservation_lock);
@@ -2641,7 +2684,7 @@ core_scsi3_emulate_pro_clear(struct se_cmd *cmd, u64 res_key)
if (pr_res_holder) {
struct se_node_acl *pr_res_nacl = pr_res_holder->pr_reg_nacl;
__core_scsi3_complete_pro_release(dev, pr_res_nacl,
- pr_res_holder, 0);
+ pr_res_holder, 0, 0);
}
spin_unlock(&dev->dev_reservation_lock);
/*
@@ -2700,7 +2743,7 @@ static void __core_scsi3_complete_pro_preempt(
*/
if (dev->dev_pr_res_holder)
__core_scsi3_complete_pro_release(dev, nacl,
- dev->dev_pr_res_holder, 0);
+ dev->dev_pr_res_holder, 0, 0);
dev->dev_pr_res_holder = pr_reg;
pr_reg->pr_res_holder = 1;
@@ -2944,8 +2987,8 @@ core_scsi3_pro_preempt(struct se_cmd *cmd, int type, int scope, u64 res_key,
*/
if (pr_reg_n != pr_res_holder)
__core_scsi3_complete_pro_release(dev,
- pr_res_holder->pr_reg_nacl,
- dev->dev_pr_res_holder, 0);
+ pr_res_holder->pr_reg_nacl,
+ dev->dev_pr_res_holder, 0, 0);
/*
* b) Remove the registrations for all I_T nexuses identified
* by the SERVICE ACTION RESERVATION KEY field, except the
@@ -3415,7 +3458,7 @@ after_iport_check:
* holder (i.e., the I_T nexus on which the
*/
__core_scsi3_complete_pro_release(dev, pr_res_nacl,
- dev->dev_pr_res_holder, 0);
+ dev->dev_pr_res_holder, 0, 0);
/*
* g) Move the persistent reservation to the specified I_T nexus using
* the same scope and type as the persistent reservation released in
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 172/183] target: Allow AllRegistrants to re-RESERVE existing reservation
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (170 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 171/183] target: Avoid dropping AllRegistrants reservation during unregister Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 173/183] target: Allow Write Exclusive non-reservation holders to READ Luis Henriques
` (10 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Ilias Tsitsimpis, Lee Duncan, James Bottomley,
Nicholas Bellinger, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicholas Bellinger <nab@linux-iscsi.org>
commit ae450e246e8540300699480a3780a420a028b73f upstream.
This patch changes core_scsi3_pro_release() logic to allow an
existing AllRegistrants type reservation to be re-reserved by
any registered I_T nexus.
This addresses a issue where AllRegistrants type RESERVE was
receiving RESERVATION_CONFLICT status if dev_pr_res_holder did
not match the same I_T nexus, instead of just returning GOOD
status following spc4r34 Section 5.9.9:
"If the device server receives a PERSISTENT RESERVE OUT command
with RESERVE service action where the TYPE field and the SCOPE
field contain the same values as the existing type and scope
from a persistent reservation holder, it shall not make any
change to the existing persistent reservation and shall complete
the command with GOOD status."
Reported-by: Ilias Tsitsimpis <i.tsitsimpis@gmail.com>
Cc: Ilias Tsitsimpis <i.tsitsimpis@gmail.com>
Cc: Lee Duncan <lduncan@suse.com>
Cc: James Bottomley <James.Bottomley@HansenPartnership.com>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/target/target_core_pr.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/target/target_core_pr.c b/drivers/target/target_core_pr.c
index 6ea72db87460..fde735eeea57 100644
--- a/drivers/target/target_core_pr.c
+++ b/drivers/target/target_core_pr.c
@@ -2297,6 +2297,7 @@ core_scsi3_pro_reserve(struct se_cmd *cmd, int type, int scope, u64 res_key)
spin_lock(&dev->dev_reservation_lock);
pr_res_holder = dev->dev_pr_res_holder;
if (pr_res_holder) {
+ int pr_res_type = pr_res_holder->pr_res_type;
/*
* From spc4r17 Section 5.7.9: Reserving:
*
@@ -2307,7 +2308,9 @@ core_scsi3_pro_reserve(struct se_cmd *cmd, int type, int scope, u64 res_key)
* the logical unit, then the command shall be completed with
* RESERVATION CONFLICT status.
*/
- if (pr_res_holder != pr_reg) {
+ if ((pr_res_holder != pr_reg) &&
+ (pr_res_type != PR_TYPE_WRITE_EXCLUSIVE_ALLREG) &&
+ (pr_res_type != PR_TYPE_EXCLUSIVE_ACCESS_ALLREG)) {
struct se_node_acl *pr_res_nacl = pr_res_holder->pr_reg_nacl;
pr_err("SPC-3 PR: Attempted RESERVE from"
" [%s]: %s while reservation already held by"
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 173/183] target: Allow Write Exclusive non-reservation holders to READ
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (171 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 172/183] target: Allow AllRegistrants to re-RESERVE existing reservation Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 174/183] vhost/scsi: potential memory corruption Luis Henriques
` (9 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Lee Duncan, Nicholas Bellinger, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Lee Duncan <lduncan@suse.com>
commit 1ecc7586922662e3ca2f3f0c3f17fec8749fc621 upstream.
For PGR reservation of type Write Exclusive Access, allow all non
reservation holding I_T nexuses with active registrations to READ
from the device.
This addresses a bug where active registrations that attempted
to READ would result in an reservation conflict.
Signed-off-by: Lee Duncan <lduncan@suse.com>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/target/target_core_pr.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/drivers/target/target_core_pr.c b/drivers/target/target_core_pr.c
index fde735eeea57..ec155de017f4 100644
--- a/drivers/target/target_core_pr.c
+++ b/drivers/target/target_core_pr.c
@@ -528,6 +528,18 @@ static int core_scsi3_pr_seq_non_holder(
return 0;
}
+ } else if (we && registered_nexus) {
+ /*
+ * Reads are allowed for Write Exclusive locks
+ * from all registrants.
+ */
+ if (cmd->data_direction == DMA_FROM_DEVICE) {
+ pr_debug("Allowing READ CDB: 0x%02x for %s"
+ " reservation\n", cdb[0],
+ core_scsi3_pr_dump_type(pr_reg_type));
+
+ return 0;
+ }
}
pr_debug("%s Conflict for %sregistered nexus %s CDB: 0x%2x"
" for %s reservation\n", transport_dump_cmd_direction(cmd),
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 174/183] vhost/scsi: potential memory corruption
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (172 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 173/183] target: Allow Write Exclusive non-reservation holders to READ Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 175/183] clk: sunxi: Support factor clocks with N factor starting not from 0 Luis Henriques
` (8 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dan Carpenter, Nicholas Bellinger, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dan Carpenter <dan.carpenter@oracle.com>
commit 59c816c1f24df0204e01851431d3bab3eb76719c upstream.
This code in vhost_scsi_make_tpg() is confusing because we limit "tpgt"
to UINT_MAX but the data type of "tpg->tport_tpgt" and that is a u16.
I looked at the context and it turns out that in
vhost_scsi_set_endpoint(), "tpg->tport_tpgt" is used as an offset into
the vs_tpg[] array which has VHOST_SCSI_MAX_TARGET (256) elements so
anything higher than 255 then it is invalid. I have made that the limit
now.
In vhost_scsi_send_evt() we mask away values higher than 255, but now
that the limit has changed, we don't need the mask.
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
[ luis: backported to 3.16: functions rename:
- tcm_vhost_send_evt -> vhost_scsi_send_evt
- tcm_vhost_make_tpg -> vhost_scsi_make_tpg ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/vhost/scsi.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/vhost/scsi.c b/drivers/vhost/scsi.c
index befe07b1e71d..0dfb3fd6e836 100644
--- a/drivers/vhost/scsi.c
+++ b/drivers/vhost/scsi.c
@@ -1251,7 +1251,7 @@ tcm_vhost_send_evt(struct vhost_scsi *vs,
* lun[4-7] need to be zero according to virtio-scsi spec.
*/
evt->event.lun[0] = 0x01;
- evt->event.lun[1] = tpg->tport_tpgt & 0xFF;
+ evt->event.lun[1] = tpg->tport_tpgt;
if (lun->unpacked_lun >= 256)
evt->event.lun[2] = lun->unpacked_lun >> 8 | 0x40 ;
evt->event.lun[3] = lun->unpacked_lun & 0xFF;
@@ -2122,12 +2122,12 @@ tcm_vhost_make_tpg(struct se_wwn *wwn,
struct tcm_vhost_tport, tport_wwn);
struct tcm_vhost_tpg *tpg;
- unsigned long tpgt;
+ u16 tpgt;
int ret;
if (strstr(name, "tpgt_") != name)
return ERR_PTR(-EINVAL);
- if (kstrtoul(name + 5, 10, &tpgt) || tpgt > UINT_MAX)
+ if (kstrtou16(name + 5, 10, &tpgt) || tpgt >= VHOST_SCSI_MAX_TARGET)
return ERR_PTR(-EINVAL);
tpg = kzalloc(sizeof(struct tcm_vhost_tpg), GFP_KERNEL);
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 175/183] clk: sunxi: Support factor clocks with N factor starting not from 0
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (173 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 174/183] vhost/scsi: potential memory corruption Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 176/183] sunxi: clk: Set sun6i-pll1 n_start = 1 Luis Henriques
` (7 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Chen-Yu Tsai, Maxime Ripard, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen-Yu Tsai <wens@csie.org>
commit 9a5e6c7eb5ccbb5f0d3a1dffce135f0a727f40e1 upstream.
The PLLs on newer Allwinner SoC's, such as the A31 and A23, have a
N multiplier factor that starts from 1, not 0.
This patch adds an option to the factor clk driver's config data
structures to specify the base value of N.
Signed-off-by: Chen-Yu Tsai <wens@csie.org>
Acked-by: Maxime Ripard <maxime.ripard@free-electrons.com>
Signed-off-by: Maxime Ripard <maxime.ripard@free-electrons.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/clk/sunxi/clk-factors.c | 2 +-
drivers/clk/sunxi/clk-factors.h | 1 +
2 files changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/clk/sunxi/clk-factors.c b/drivers/clk/sunxi/clk-factors.c
index 3806d97e529b..2057c8ac648f 100644
--- a/drivers/clk/sunxi/clk-factors.c
+++ b/drivers/clk/sunxi/clk-factors.c
@@ -62,7 +62,7 @@ static unsigned long clk_factors_recalc_rate(struct clk_hw *hw,
p = FACTOR_GET(config->pshift, config->pwidth, reg);
/* Calculate the rate */
- rate = (parent_rate * n * (k + 1) >> p) / (m + 1);
+ rate = (parent_rate * (n + config->n_start) * (k + 1) >> p) / (m + 1);
return rate;
}
diff --git a/drivers/clk/sunxi/clk-factors.h b/drivers/clk/sunxi/clk-factors.h
index 02e1a43ebac7..d2d0efa39379 100644
--- a/drivers/clk/sunxi/clk-factors.h
+++ b/drivers/clk/sunxi/clk-factors.h
@@ -15,6 +15,7 @@ struct clk_factors_config {
u8 mwidth;
u8 pshift;
u8 pwidth;
+ u8 n_start;
};
struct clk_factors {
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 176/183] sunxi: clk: Set sun6i-pll1 n_start = 1
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (174 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 175/183] clk: sunxi: Support factor clocks with N factor starting not from 0 Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 177/183] HID: wacom: Report ABS_MISC event for Cintiq Companion Hybrid Luis Henriques
` (6 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Chen-Yu Tsai, Hans de Goede, Maxime Ripard, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <hdegoede@redhat.com>
commit 76820fcf7aa5a418b69cb7bed31b62d1feb1d6ad upstream.
For all pll-s on sun6i n == 0 means use a multiplier of 1, rather then 0 as
it means on sun4i / sun5i / sun7i. n_start = 1 is already correctly set
for sun6i pll6, but was missing for pll1, this commit fixes this.
Cc: Chen-Yu Tsai <wens@csie.org>
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Maxime Ripard <maxime.ripard@free-electrons.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/clk/sunxi/clk-sunxi.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/clk/sunxi/clk-sunxi.c b/drivers/clk/sunxi/clk-sunxi.c
index fb2ce8440f0e..067333c9b789 100644
--- a/drivers/clk/sunxi/clk-sunxi.c
+++ b/drivers/clk/sunxi/clk-sunxi.c
@@ -420,6 +420,7 @@ static struct clk_factors_config sun6i_a31_pll1_config = {
.kwidth = 2,
.mshift = 0,
.mwidth = 2,
+ .n_start = 1,
};
static struct clk_factors_config sun4i_pll5_config = {
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 177/183] HID: wacom: Report ABS_MISC event for Cintiq Companion Hybrid
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (175 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 176/183] sunxi: clk: Set sun6i-pll1 n_start = 1 Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 178/183] mm: softdirty: unmapped addresses between VMAs are clean Luis Henriques
` (5 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Jason Gerecke, Jiri Kosina, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jason Gerecke <killertofu@gmail.com>
commit 33e5df0e0e32027866e9fb00451952998fc957f2 upstream.
It appears that the Cintiq Companion Hybrid does not send an ABS_MISC event to
userspace when any of its ExpressKeys are pressed. This is not strictly
necessary now that the pad exists on its own device, but should be fixed for
consistency's sake.
Traditionally both the stylus and pad shared the same device node, and
xf86-input-wacom would use ABS_MISC for disambiguation. Not sending this causes
the Hybrid to behave incorrectly with xf86-input-wacom beginning with its
8f44f3 commit.
Signed-off-by: Jason Gerecke <killertofu@gmail.com>
Reviewed-by: Benjamin Tissoires <benjamin.tissoires@redhat.com>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
[killertofu@gmail.com: ported to drivers/input/tablet/wacom_wac.c]
Signed-off-by: Jason Gerecke <killertofu@gmail.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/input/tablet/wacom_wac.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/input/tablet/wacom_wac.c b/drivers/input/tablet/wacom_wac.c
index e73cf2c71f35..234ac2e14fda 100644
--- a/drivers/input/tablet/wacom_wac.c
+++ b/drivers/input/tablet/wacom_wac.c
@@ -698,6 +698,12 @@ static int wacom_intuos_irq(struct wacom_wac *wacom)
input_report_key(input, BTN_7, (data[4] & 0x40)); /* Left */
input_report_key(input, BTN_8, (data[4] & 0x80)); /* Down */
input_report_key(input, BTN_0, (data[3] & 0x01)); /* Center */
+
+ if (data[4] | (data[3] & 0x01)) {
+ input_report_abs(input, ABS_MISC, PAD_DEVICE_ID);
+ } else {
+ input_report_abs(input, ABS_MISC, 0);
+ }
} else if (features->type >= INTUOS5S && features->type <= INTUOSPL) {
int i;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 178/183] mm: softdirty: unmapped addresses between VMAs are clean
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (176 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 177/183] HID: wacom: Report ABS_MISC event for Cintiq Companion Hybrid Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 179/183] proc/pagemap: walk page tables under pte lock Luis Henriques
` (4 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Peter Feiner, Kirill A. Shutemov, Cyrill Gorcunov,
Pavel Emelyanov, Jamie Liu, Hugh Dickins, Naoya Horiguchi,
Andrew Morton, Linus Torvalds, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Feiner <pfeiner@google.com>
commit 81d0fa623c5b8dbd5279d9713094b0f9b0a00fb4 upstream.
If a /proc/pid/pagemap read spans a [VMA, an unmapped region, then a
VM_SOFTDIRTY VMA], the virtual pages in the unmapped region are reported
as softdirty. Here's a program to demonstrate the bug:
int main() {
const uint64_t PAGEMAP_SOFTDIRTY = 1ul << 55;
uint64_t pme[3];
int fd = open("/proc/self/pagemap", O_RDONLY);;
char *m = mmap(NULL, 3 * getpagesize(), PROT_READ,
MAP_ANONYMOUS | MAP_SHARED, -1, 0);
munmap(m + getpagesize(), getpagesize());
pread(fd, pme, 24, (unsigned long) m / getpagesize() * 8);
assert(pme[0] & PAGEMAP_SOFTDIRTY); /* passes */
assert(!(pme[1] & PAGEMAP_SOFTDIRTY)); /* fails */
assert(pme[2] & PAGEMAP_SOFTDIRTY); /* passes */
return 0;
}
(Note that all pages in new VMAs are softdirty until cleared).
Tested:
Used the program given above. I'm going to include this code in
a selftest in the future.
[n-horiguchi@ah.jp.nec.com: prevent pagemap_pte_range() from overrunning]
Signed-off-by: Peter Feiner <pfeiner@google.com>
Cc: "Kirill A. Shutemov" <kirill@shutemov.name>
Cc: Cyrill Gorcunov <gorcunov@openvz.org>
Cc: Pavel Emelyanov <xemul@parallels.com>
Cc: Jamie Liu <jamieliu@google.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
Signed-off-by: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[ luis: 3.16-stable prereq for:
05fbf357d941 "proc/pagemap: walk page tables under pte lock" ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/proc/task_mmu.c | 61 +++++++++++++++++++++++++++++++++++-------------------
1 file changed, 40 insertions(+), 21 deletions(-)
diff --git a/fs/proc/task_mmu.c b/fs/proc/task_mmu.c
index cfa63ee92c96..143674aef97c 100644
--- a/fs/proc/task_mmu.c
+++ b/fs/proc/task_mmu.c
@@ -1005,7 +1005,6 @@ static int pagemap_pte_range(pmd_t *pmd, unsigned long addr, unsigned long end,
spinlock_t *ptl;
pte_t *pte;
int err = 0;
- pagemap_entry_t pme = make_pme(PM_NOT_PRESENT(pm->v2));
/* find the first VMA at or above 'addr' */
vma = find_vma(walk->mm, addr);
@@ -1019,6 +1018,7 @@ static int pagemap_pte_range(pmd_t *pmd, unsigned long addr, unsigned long end,
for (; addr != end; addr += PAGE_SIZE) {
unsigned long offset;
+ pagemap_entry_t pme;
offset = (addr & ~PAGEMAP_WALK_MASK) >>
PAGE_SHIFT;
@@ -1033,32 +1033,51 @@ static int pagemap_pte_range(pmd_t *pmd, unsigned long addr, unsigned long end,
if (pmd_trans_unstable(pmd))
return 0;
- for (; addr != end; addr += PAGE_SIZE) {
- int flags2;
-
- /* check to see if we've left 'vma' behind
- * and need a new, higher one */
- if (vma && (addr >= vma->vm_end)) {
- vma = find_vma(walk->mm, addr);
- if (vma && (vma->vm_flags & VM_SOFTDIRTY))
- flags2 = __PM_SOFT_DIRTY;
- else
- flags2 = 0;
- pme = make_pme(PM_NOT_PRESENT(pm->v2) | PM_STATUS2(pm->v2, flags2));
+
+ while (1) {
+ /* End of address space hole, which we mark as non-present. */
+ unsigned long hole_end;
+
+ if (vma)
+ hole_end = min(end, vma->vm_start);
+ else
+ hole_end = end;
+
+ for (; addr < hole_end; addr += PAGE_SIZE) {
+ pagemap_entry_t pme = make_pme(PM_NOT_PRESENT(pm->v2));
+
+ err = add_to_pagemap(addr, &pme, pm);
+ if (err)
+ return err;
}
- /* check that 'vma' actually covers this address,
- * and that it isn't a huge page vma */
- if (vma && (vma->vm_start <= addr) &&
- !is_vm_hugetlb_page(vma)) {
+ if (!vma || vma->vm_start >= end)
+ break;
+ /*
+ * We can't possibly be in a hugetlb VMA. In general,
+ * for a mm_walk with a pmd_entry and a hugetlb_entry,
+ * the pmd_entry can only be called on addresses in a
+ * hugetlb if the walk starts in a non-hugetlb VMA and
+ * spans a hugepage VMA. Since pagemap_read walks are
+ * PMD-sized and PMD-aligned, this will never be true.
+ */
+ BUG_ON(is_vm_hugetlb_page(vma));
+
+ /* Addresses in the VMA. */
+ for (; addr < min(end, vma->vm_end); addr += PAGE_SIZE) {
+ pagemap_entry_t pme;
pte = pte_offset_map(pmd, addr);
pte_to_pagemap_entry(&pme, pm, vma, addr, *pte);
- /* unmap before userspace copy */
pte_unmap(pte);
+ err = add_to_pagemap(addr, &pme, pm);
+ if (err)
+ return err;
}
- err = add_to_pagemap(addr, &pme, pm);
- if (err)
- return err;
+
+ if (addr == end)
+ break;
+
+ vma = find_vma(walk->mm, addr);
}
cond_resched();
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 179/183] proc/pagemap: walk page tables under pte lock
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (177 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 178/183] mm: softdirty: unmapped addresses between VMAs are clean Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 180/183] ARM: dts: am335x-bone*: usb0 is hardwired for peripheral Luis Henriques
` (3 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Konstantin Khlebnikov, Andrew Morton, Linus Torvalds, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Konstantin Khlebnikov <khlebnikov@yandex-team.ru>
commit 05fbf357d94152171bc50f8a369390f1f16efd89 upstream.
Lockless access to pte in pagemap_pte_range() might race with page
migration and trigger BUG_ON(!PageLocked()) in migration_entry_to_page():
CPU A (pagemap) CPU B (migration)
lock_page()
try_to_unmap(page, TTU_MIGRATION...)
make_migration_entry()
set_pte_at()
<read *pte>
pte_to_pagemap_entry()
remove_migration_ptes()
unlock_page()
if(is_migration_entry())
migration_entry_to_page()
BUG_ON(!PageLocked(page))
Also lockless read might be non-atomic if pte is larger than wordsize.
Other pte walkers (smaps, numa_maps, clear_refs) already lock ptes.
Fixes: 052fb0d635df ("proc: report file/anon bit in /proc/pid/pagemap")
Signed-off-by: Konstantin Khlebnikov <khlebnikov@yandex-team.ru>
Reported-by: Andrey Ryabinin <a.ryabinin@samsung.com>
Reviewed-by: Cyrill Gorcunov <gorcunov@openvz.org>
Acked-by: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
Acked-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/proc/task_mmu.c | 14 +++++++++-----
1 file changed, 9 insertions(+), 5 deletions(-)
diff --git a/fs/proc/task_mmu.c b/fs/proc/task_mmu.c
index 143674aef97c..a6b314919d9d 100644
--- a/fs/proc/task_mmu.c
+++ b/fs/proc/task_mmu.c
@@ -1003,7 +1003,7 @@ static int pagemap_pte_range(pmd_t *pmd, unsigned long addr, unsigned long end,
struct vm_area_struct *vma;
struct pagemapread *pm = walk->private;
spinlock_t *ptl;
- pte_t *pte;
+ pte_t *pte, *orig_pte;
int err = 0;
/* find the first VMA at or above 'addr' */
@@ -1064,15 +1064,19 @@ static int pagemap_pte_range(pmd_t *pmd, unsigned long addr, unsigned long end,
BUG_ON(is_vm_hugetlb_page(vma));
/* Addresses in the VMA. */
- for (; addr < min(end, vma->vm_end); addr += PAGE_SIZE) {
+ orig_pte = pte = pte_offset_map_lock(walk->mm, pmd, addr, &ptl);
+ for (; addr < min(end, vma->vm_end); pte++, addr += PAGE_SIZE) {
pagemap_entry_t pme;
- pte = pte_offset_map(pmd, addr);
+
pte_to_pagemap_entry(&pme, pm, vma, addr, *pte);
- pte_unmap(pte);
err = add_to_pagemap(addr, &pme, pm);
if (err)
- return err;
+ break;
}
+ pte_unmap_unlock(orig_pte, ptl);
+
+ if (err)
+ return err;
if (addr == end)
break;
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 180/183] ARM: dts: am335x-bone*: usb0 is hardwired for peripheral
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (178 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 179/183] proc/pagemap: walk page tables under pte lock Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 181/183] sched/rt: Reduce rq lock contention by eliminating locking of non-feasible target Luis Henriques
` (2 subsequent siblings)
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Robert Nelson, Tony Lindgren, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Robert Nelson <robertcnelson@gmail.com>
commit 67fd14b3eca63b14429350e9eadc5fab709a8821 upstream.
Fixes: http://bugs.elinux.org/issues/127
the bb.org community was seeing random reboots before this change.
Signed-off-by: Robert Nelson <robertcnelson@gmail.com>
Reviewed-by: Felipe Balbi <balbi@ti.com>
Acked-by: Felipe Balbi <balbi@ti.com>
Signed-off-by: Tony Lindgren <tony@atomide.com>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
arch/arm/boot/dts/am335x-bone-common.dtsi | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/arm/boot/dts/am335x-bone-common.dtsi b/arch/arm/boot/dts/am335x-bone-common.dtsi
index bde1777b62be..d268ddaece9e 100644
--- a/arch/arm/boot/dts/am335x-bone-common.dtsi
+++ b/arch/arm/boot/dts/am335x-bone-common.dtsi
@@ -198,6 +198,7 @@
&usb0 {
status = "okay";
+ dr_mode = "peripheral";
};
&usb1 {
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 181/183] sched/rt: Reduce rq lock contention by eliminating locking of non-feasible target
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (179 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 180/183] ARM: dts: am335x-bone*: usb0 is hardwired for peripheral Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 182/183] caif: remove wrong dev_net_set() call Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 183/183] quota: Store maximum space limit in bytes Luis Henriques
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Tim Chen, Peter Zijlstra (Intel),
Shawn Bohrer, Suruchi Kadu, Doug Nelson, Steven Rostedt,
Linus Torvalds, Ingo Molnar, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Tim Chen <tim.c.chen@linux.intel.com>
commit 80e3d87b2c5582db0ab5e39610ce3707d97ba409 upstream.
This patch adds checks that prevens futile attempts to move rt tasks
to a CPU with active tasks of equal or higher priority.
This reduces run queue lock contention and improves the performance of
a well known OLTP benchmark by 0.7%.
Signed-off-by: Tim Chen <tim.c.chen@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Shawn Bohrer <sbohrer@rgmadvisors.com>
Cc: Suruchi Kadu <suruchi.a.kadu@intel.com>
Cc: Doug Nelson<doug.nelson@intel.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Link: http://lkml.kernel.org/r/1421430374.2399.27.camel@schen9-desk2.jf.intel.com
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
kernel/sched/rt.c | 17 ++++++++++++++++-
1 file changed, 16 insertions(+), 1 deletion(-)
diff --git a/kernel/sched/rt.c b/kernel/sched/rt.c
index a49083192c64..5d720ac96246 100644
--- a/kernel/sched/rt.c
+++ b/kernel/sched/rt.c
@@ -1336,7 +1336,12 @@ select_task_rq_rt(struct task_struct *p, int cpu, int sd_flag, int flags)
curr->prio <= p->prio)) {
int target = find_lowest_rq(p);
- if (target != -1)
+ /*
+ * Don't bother moving it if the destination CPU is
+ * not running a lower priority task.
+ */
+ if (target != -1 &&
+ p->prio < cpu_rq(target)->rt.highest_prio.curr)
cpu = target;
}
rcu_read_unlock();
@@ -1608,6 +1613,16 @@ static struct rq *find_lock_lowest_rq(struct task_struct *task, struct rq *rq)
lowest_rq = cpu_rq(cpu);
+ if (lowest_rq->rt.highest_prio.curr <= task->prio) {
+ /*
+ * Target rq has tasks of equal or higher priority,
+ * retrying does not release any lock and is unlikely
+ * to yield a different result.
+ */
+ lowest_rq = NULL;
+ break;
+ }
+
/* if the prio of this runqueue changed, try again */
if (double_lock_balance(rq, lowest_rq)) {
/*
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 182/183] caif: remove wrong dev_net_set() call
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (180 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 181/183] sched/rt: Reduce rq lock contention by eliminating locking of non-feasible target Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 183/183] quota: Store maximum space limit in bytes Luis Henriques
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Sjur Brændeland, Dmitry Tarnyagin, Nicolas Dichtel,
David S. Miller, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Dichtel <nicolas.dichtel@6wind.com>
commit 8997c27ec41127bf57421cc0205413d525421ddc upstream.
src_net points to the netns where the netlink message has been received. This
netns may be different from the netns where the interface is created (because
the user may add IFLA_NET_NS_[PID|FD]). In this case, src_net is the link netns.
It seems wrong to override the netns in the newlink() handler because if it
was not already src_net, it means that the user explicitly asks to create the
netdevice in another netns.
CC: Sjur Brændeland <sjur.brandeland@stericsson.com>
CC: Dmitry Tarnyagin <dmitry.tarnyagin@lockless.no>
Fixes: 8391c4aab1aa ("caif: Bugfixes in CAIF netdevice for close and flow control")
Fixes: c41254006377 ("caif-hsi: Add rtnl support")
Signed-off-by: Nicolas Dichtel <nicolas.dichtel@6wind.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
drivers/net/caif/caif_hsi.c | 1 -
net/caif/chnl_net.c | 1 -
2 files changed, 2 deletions(-)
diff --git a/drivers/net/caif/caif_hsi.c b/drivers/net/caif/caif_hsi.c
index 5e40a8b68cbe..b3b922adc0e4 100644
--- a/drivers/net/caif/caif_hsi.c
+++ b/drivers/net/caif/caif_hsi.c
@@ -1415,7 +1415,6 @@ static int caif_hsi_newlink(struct net *src_net, struct net_device *dev,
cfhsi = netdev_priv(dev);
cfhsi_netlink_parms(data, cfhsi);
- dev_net_set(cfhsi->ndev, src_net);
get_ops = symbol_get(cfhsi_get_ops);
if (!get_ops) {
diff --git a/net/caif/chnl_net.c b/net/caif/chnl_net.c
index 4589ff67bfa9..67a4a36febd1 100644
--- a/net/caif/chnl_net.c
+++ b/net/caif/chnl_net.c
@@ -470,7 +470,6 @@ static int ipcaif_newlink(struct net *src_net, struct net_device *dev,
ASSERT_RTNL();
caifdev = netdev_priv(dev);
caif_netlink_parms(data, &caifdev->conn_req);
- dev_net_set(caifdev->netdev, src_net);
ret = register_netdevice(dev);
if (ret)
^ permalink raw reply [flat|nested] 184+ messages in thread
* [PATCH 3.16.y-ckt 183/183] quota: Store maximum space limit in bytes
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
` (181 preceding siblings ...)
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 182/183] caif: remove wrong dev_net_set() call Luis Henriques
@ 2015-03-06 9:57 ` Luis Henriques
182 siblings, 0 replies; 184+ messages in thread
From: Luis Henriques @ 2015-03-06 9:57 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Jan Kara, Luis Henriques
3.16.7-ckt8 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jan Kara <jack@suse.cz>
commit b10a08194c2b615955dfab2300331a90ae9344c7 upstream.
Currently maximum space limit quota format supports is in blocks however
since we store space limits in bytes, this is somewhat confusing. So
store the maximum limit in bytes as well. Also rename the field to match
the new unit and related inode field to match the new naming scheme.
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Jan Kara <jack@suse.cz>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
---
fs/ocfs2/quota_local.c | 4 ++--
fs/quota/dquot.c | 18 ++++--------------
fs/quota/quota_v1.c | 4 ++--
fs/quota/quota_v2.c | 10 +++++-----
include/linux/quota.h | 4 ++--
5 files changed, 15 insertions(+), 25 deletions(-)
diff --git a/fs/ocfs2/quota_local.c b/fs/ocfs2/quota_local.c
index 2001862bf2b1..068b525b6c22 100644
--- a/fs/ocfs2/quota_local.c
+++ b/fs/ocfs2/quota_local.c
@@ -700,8 +700,8 @@ static int ocfs2_local_read_info(struct super_block *sb, int type)
/* We don't need the lock and we have to acquire quota file locks
* which will later depend on this lock */
mutex_unlock(&sb_dqopt(sb)->dqio_mutex);
- info->dqi_maxblimit = 0x7fffffffffffffffLL;
- info->dqi_maxilimit = 0x7fffffffffffffffLL;
+ info->dqi_max_spc_limit = 0x7fffffffffffffffLL;
+ info->dqi_max_ino_limit = 0x7fffffffffffffffLL;
oinfo = kmalloc(sizeof(struct ocfs2_mem_dqinfo), GFP_NOFS);
if (!oinfo) {
mlog(ML_ERROR, "failed to allocate memory for ocfs2 quota"
diff --git a/fs/quota/dquot.c b/fs/quota/dquot.c
index 6a350356c058..29552a0a2cf2 100644
--- a/fs/quota/dquot.c
+++ b/fs/quota/dquot.c
@@ -2396,16 +2396,6 @@ out:
}
EXPORT_SYMBOL(dquot_quota_on_mount);
-static inline qsize_t qbtos(qsize_t blocks)
-{
- return blocks << QIF_DQBLKSIZE_BITS;
-}
-
-static inline qsize_t stoqb(qsize_t space)
-{
- return (space + QIF_DQBLKSIZE - 1) >> QIF_DQBLKSIZE_BITS;
-}
-
/* Generic routine for getting common part of quota structure */
static void do_get_dqblk(struct dquot *dquot, struct qc_dqblk *di)
{
@@ -2455,13 +2445,13 @@ static int do_set_dqblk(struct dquot *dquot, struct qc_dqblk *di)
return -EINVAL;
if (((di->d_fieldmask & QC_SPC_SOFT) &&
- stoqb(di->d_spc_softlimit) > dqi->dqi_maxblimit) ||
+ di->d_spc_softlimit > dqi->dqi_max_spc_limit) ||
((di->d_fieldmask & QC_SPC_HARD) &&
- stoqb(di->d_spc_hardlimit) > dqi->dqi_maxblimit) ||
+ di->d_spc_hardlimit > dqi->dqi_max_spc_limit) ||
((di->d_fieldmask & QC_INO_SOFT) &&
- (di->d_ino_softlimit > dqi->dqi_maxilimit)) ||
+ (di->d_ino_softlimit > dqi->dqi_max_ino_limit)) ||
((di->d_fieldmask & QC_INO_HARD) &&
- (di->d_ino_hardlimit > dqi->dqi_maxilimit)))
+ (di->d_ino_hardlimit > dqi->dqi_max_ino_limit)))
return -ERANGE;
spin_lock(&dq_data_lock);
diff --git a/fs/quota/quota_v1.c b/fs/quota/quota_v1.c
index 469c6848b322..8fe79beced5c 100644
--- a/fs/quota/quota_v1.c
+++ b/fs/quota/quota_v1.c
@@ -169,8 +169,8 @@ static int v1_read_file_info(struct super_block *sb, int type)
}
ret = 0;
/* limits are stored as unsigned 32-bit data */
- dqopt->info[type].dqi_maxblimit = 0xffffffff;
- dqopt->info[type].dqi_maxilimit = 0xffffffff;
+ dqopt->info[type].dqi_max_spc_limit = 0xffffffffULL << QUOTABLOCK_BITS;
+ dqopt->info[type].dqi_max_ino_limit = 0xffffffff;
dqopt->info[type].dqi_igrace =
dqblk.dqb_itime ? dqblk.dqb_itime : MAX_IQ_TIME;
dqopt->info[type].dqi_bgrace =
diff --git a/fs/quota/quota_v2.c b/fs/quota/quota_v2.c
index 02751ec695c5..d1a8054bba9a 100644
--- a/fs/quota/quota_v2.c
+++ b/fs/quota/quota_v2.c
@@ -117,12 +117,12 @@ static int v2_read_file_info(struct super_block *sb, int type)
qinfo = info->dqi_priv;
if (version == 0) {
/* limits are stored as unsigned 32-bit data */
- info->dqi_maxblimit = 0xffffffff;
- info->dqi_maxilimit = 0xffffffff;
+ info->dqi_max_spc_limit = 0xffffffffULL << QUOTABLOCK_BITS;
+ info->dqi_max_ino_limit = 0xffffffff;
} else {
- /* used space is stored as unsigned 64-bit value */
- info->dqi_maxblimit = 0xffffffffffffffffULL; /* 2^64-1 */
- info->dqi_maxilimit = 0xffffffffffffffffULL;
+ /* used space is stored as unsigned 64-bit value in bytes */
+ info->dqi_max_spc_limit = 0xffffffffffffffffULL; /* 2^64-1 */
+ info->dqi_max_ino_limit = 0xffffffffffffffffULL;
}
info->dqi_bgrace = le32_to_cpu(dinfo.dqi_bgrace);
info->dqi_igrace = le32_to_cpu(dinfo.dqi_igrace);
diff --git a/include/linux/quota.h b/include/linux/quota.h
index 6724c121b916..b8fc216f5d2e 100644
--- a/include/linux/quota.h
+++ b/include/linux/quota.h
@@ -211,8 +211,8 @@ struct mem_dqinfo {
unsigned long dqi_flags;
unsigned int dqi_bgrace;
unsigned int dqi_igrace;
- qsize_t dqi_maxblimit;
- qsize_t dqi_maxilimit;
+ qsize_t dqi_max_spc_limit;
+ qsize_t dqi_max_ino_limit;
void *dqi_priv;
};
^ permalink raw reply [flat|nested] 184+ messages in thread
end of thread, other threads:[~2015-03-06 11:27 UTC | newest]
Thread overview: 184+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2015-03-06 9:54 [3.16.y-ckt stable] Linux 3.16.7-ckt8 stable review Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 001/183] [media] em28xx: fix em28xx-input removal Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 002/183] [media] em28xx: ensure "closing" messages terminate with a newline Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 003/183] [media] em28xx-input: fix missing newlines Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 004/183] [media] em28xx-core: " Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 005/183] [media] em28xx-audio: " Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 006/183] " Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 007/183] [media] em28xx-dvb: " Luis Henriques
2015-03-06 9:54 ` [PATCH 3.16.y-ckt 008/183] [media] em28xx-video: " Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 009/183] ARM: pxa: add regulator_has_full_constraints to corgi board file Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 010/183] ARM: pxa: add regulator_has_full_constraints to poodle " Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 011/183] ARM: pxa: add regulator_has_full_constraints to spitz " Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 012/183] hx4700: regulator: declare full constraints Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 013/183] HID: input: fix confusion on conflicting mappings Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 014/183] HID: fixup the conflicting keyboard mappings quirk Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 015/183] ARM: dts: tegra20: fix GR3D, DSI unit and reg base addresses Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 016/183] megaraid_sas: disable interrupt_mask before enabling hardware interrupts Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 017/183] PCI: Generate uppercase hex for modalias var in uevent Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 018/183] usb: core: buffer: smallest buffer should start at ARCH_DMA_MINALIGN Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 019/183] tty/serial: at91: enable peripheral clock before accessing I/O registers Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 020/183] tty/serial: at91: fix error handling in atmel_serial_probe() Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 021/183] axonram: Fix bug in direct_access Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 022/183] btrfs: fix leak of path in btrfs_find_item Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 023/183] ksoftirqd: Enable IRQs and call cond_resched() before poking RCU Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 024/183] TPM: Add new TPMs to the tail of the list to prevent inadvertent change of dev Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 025/183] char: tpm: Add missing error check for devm_kzalloc Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 026/183] tpm_tis: verify interrupt during init Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 027/183] tpm: Fix NULL return in tpm_ibmvtpm_get_desired_dma Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 028/183] tpm/tpm_i2c_stm_st33: Fix potential bug in tpm_stm_i2c_send Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 029/183] tpm/tpm_i2c_stm_st33: Add status check when reading data on the FIFO Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 030/183] mmc: sdhci-pxav3: fix unbalanced clock issues during probe Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 031/183] iwlwifi: mvm: validate tid and sta_id in ba_notif Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 032/183] power: gpio-charger: balance enable/disable_irq_wake calls Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 033/183] power: bq24190: Fix ignored supplicants Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 034/183] ARM: DRA7: hwmod: Fix boot crash with DEBUG_LL enabled on UART3 Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 035/183] Bluetooth: ath3k: Add support of AR3012 bluetooth 13d3:3423 device Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 036/183] Bluetooth: btusb: Add Broadcom patchram support for ASUSTek devices Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 037/183] cfq-iosched: fix incorrect filing of rt async cfqq Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 038/183] smack: fix possible use after frees in task_security() callers Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 039/183] xfs: ensure buffer types are set correctly Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 040/183] xfs: inode unlink does not set AGI buffer type Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 041/183] xfs: set buf types when converting extent formats Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 042/183] xfs: set superblock buffer type correctly Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 043/183] btrfs: set proper message level for skinny metadata Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 044/183] KVM: s390: base hrtimer on a monotonic clock Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 045/183] KVM: s390: avoid memory leaks if __inject_vm() fails Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 046/183] samsung-laptop: Add use_native_backlight quirk, and enable it on some models Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 047/183] PCI: Fix infinite loop with ROM image of size 0 Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 048/183] USB: cp210x: add ID for RUGGEDCOM USB Serial Console Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 049/183] Bluetooth: Add support for Broadcom BCM20702A1 variant Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 050/183] Bluetooth: Add support for Broadcom BCM20702A0 variants firmware download Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 051/183] Bluetooth: btusb: Add support for Dynex/Insignia USB dongles Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 052/183] clk: zynq: Force CPU_2X clock to be ungated Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 053/183] mmc: sdhci-pxav3: Remove checks for mandatory host clock Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 054/183] mmc: sdhci-pxav3: fix race between runtime pm and irq Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 055/183] power_supply: 88pm860x: Fix leaked power supply on probe fail Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 056/183] staging: comedi: comedi_compat32.c: fix COMEDI_CMD copy back Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 057/183] mmc: sdhci-pxav3: fix setting of pdata->clk_delay_cycles Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 058/183] mmc: sdhci-pxav3: Fix SDR50 and DDR50 capabilities for the Armada 38x flavor Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 059/183] mmc: sdhci-pxav3: Fix Armada 38x controller's caps according to erratum ERR-7878951 Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 060/183] ARM: 8284/1: sa1100: clear RCSR_SMR on resume Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 061/183] [media] si2168: define symbol rate limits Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 062/183] nfs: don't call blocking operations while !TASK_RUNNING Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 063/183] cdc-acm: add sanity checks Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 064/183] USB: add flag for HCDs that can't receive wakeup requests (isp1760-hcd) Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 065/183] USB: fix use-after-free bug in usb_hcd_unlink_urb() Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 066/183] iwlwifi: mvm: always use mac color zero Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 067/183] iwlwifi: pcie: disable the SCD_BASE_ADDR when we resume from WoWLAN Luis Henriques
2015-03-06 9:55 ` [PATCH 3.16.y-ckt 068/183] iwlwifi: mvm: fix failure path when power_update fails in add_interface Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 069/183] vt: provide notifications on selection changes Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 070/183] tty: Prevent untrappable signals from malicious program Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 071/183] serial: fsl_lpuart: delete timer on shutdown Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 072/183] serial: fsl_lpuart: avoid new transfer while DMA is running Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 073/183] cpufreq: Set cpufreq_cpu_data to NULL before putting kobject Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 074/183] Bluetooth: btusb: Add support for Lite-On (04ca) Broadcom based, BCM43142 Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 075/183] nfs41: .init_read and .init_write can be called with valid pg_lseg Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 076/183] [media] lmedm04: Fix usb_submit_urb BOGUS urb xfer, pipe 1 != type 3 in interrupt urb Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 077/183] mei: mask interrupt set bit on clean reset bit Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 078/183] mei: me: release hw from reset only during the reset flow Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 079/183] KVM: MIPS: Don't leak FPU/DSP to guest Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 080/183] ALSA: hda - Add the pin fixup for HP Envy TS bass speaker Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 081/183] ALSA: hda - Set up GPIO for Toshiba Satellite S50D Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 082/183] xen/manage: Fix USB interaction issues when resuming Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 083/183] ACPI / video: Add some Samsung models to disable_native_backlight list Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 084/183] ACPI / video: Add disable_native_backlight quirk for Dell XPS15 L521X Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 085/183] ACPI / video: Add disable_native_backlight quirk for Samsung 730U3E/740U3E Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 086/183] ACPI / video: Add disable_native_backlight quirk for Samsung 510R Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 087/183] KVM: s390: floating irqs: fix user triggerable endless loop Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 088/183] drm/i915: Correct the IOSF Dev_FN field for IOSF transfers Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 089/183] cfq-iosched: handle failure of cfq group allocation Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 090/183] tracing: Fix unmapping loop in tracing_mark_write Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 091/183] fsnotify: fix handling of renames in audit Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 092/183] ring-buffer: Do not wake up a splice waiter when page is not full Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 093/183] blk-mq: fix double-free in error path Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 094/183] drm/radeon: workaround for CP HW bug on CIK Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 095/183] drm/radeon: only enable kv/kb dpm interrupts once v3 Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 096/183] NFSv4.1: Fix a kfree() of uninitialised pointers in decode_cb_sequence_args Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 097/183] cpufreq: speedstep-smi: enable interrupts when waiting Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 098/183] mm/hugetlb: pmd_huge() returns true for non-present hugepage Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 099/183] mm/hugetlb: take page table lock in follow_huge_pmd() Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 100/183] mm/hugetlb: fix getting refcount 0 page in hugetlb_fault() Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 101/183] mm/hugetlb: add migration/hwpoisoned entry check in hugetlb_change_protection Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 102/183] mm/hugetlb: add migration entry check in __unmap_hugepage_range Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 103/183] mm: when stealing freepages, also take pages created by splitting buddy page Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 104/183] mm/mmap.c: fix arithmetic overflow in __vm_enough_memory() Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 105/183] mm/nommu.c: " Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 106/183] iscsi-target: Drop problematic active_ts_list usage Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 107/183] target: Fix PR_APTPL_BUF_LEN buffer size limitation Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 108/183] mm/compaction: fix wrong order check in compact_finished() Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 109/183] mm/memory.c: actually remap enough memory Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 110/183] mm: hwpoison: drop lru_add_drain_all() in __soft_offline_page() Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 111/183] ALSA: hda - enable mute led quirk for one more hp machine Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 112/183] ARC: fix page address calculation if PAGE_OFFSET != LINUX_LINK_BASE Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 113/183] drm/radeon/dp: Set EDP_CONFIGURATION_SET for bridge chips if necessary Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 114/183] drm/radeon: fix voltage setup on hawaii Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 115/183] ALSA: hdspm - Constrain periods to 2 on older cards Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 116/183] jffs2: fix handling of corrupted summary length Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 117/183] dm mirror: do not degrade the mirror on discard error Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 118/183] dm io: reject unsupported DISCARD requests with EOPNOTSUPP Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 119/183] NFS: struct nfs_commit_info.lock must always point to inode->i_lock Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 120/183] target: Add missing WRITE_SAME end-of-device sanity check Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 121/183] target: Check for LBA + sectors wrap-around in sbc_parse_cdb Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 122/183] Btrfs: fix fsync data loss after adding hard link to inode Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 123/183] Added Little Endian support to vtpm module Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 124/183] fixed invalid assignment of 64bit mask to host dma_boundary for scatter gather segment boundary limit Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 125/183] sg: fix read() error reporting Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 126/183] IB/qib: Do not write EEPROM Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 127/183] EDAC, amd64_edac: Prevent OOPS with >16 memory controllers Luis Henriques
2015-03-06 9:56 ` [PATCH 3.16.y-ckt 128/183] MIPS: asm: asmmacro: Replace "add" instructions with "addu" Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 129/183] MIPS: kernel: cps-vec: Replace "addi" with "addiu" Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 130/183] md/raid5: Fix livelock when array is both resyncing and degraded Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 131/183] locking/rtmutex: Avoid a NULL pointer dereference on deadlock Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 132/183] time: adjtimex: Validate the ADJ_FREQUENCY values Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 133/183] ntp: Fixup adjtimex freq validation on 32-bit systems Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 134/183] dm: fix a race condition in dm_get_md Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 135/183] dm snapshot: fix a possible invalid memory access on unload Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 136/183] cpufreq: s3c: remove incorrect __init annotations Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 137/183] x86, mm/ASLR: Fix stack randomization on 64-bit systems Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 138/183] libceph: assert both regular and lingering lists in __remove_osd() Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 139/183] libceph: change from BUG to WARN for __remove_osd() asserts Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 140/183] libceph: fix double __remove_osd() problem Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 141/183] MIPS: Export FP functions used by lose_fpu(1) for KVM Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 142/183] MIPS: Export MSA " Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 143/183] kdb: fix incorrect counts in KDB summary command output Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 144/183] blk-throttle: check stats_cpu before reading it from sysfs Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 145/183] debugfs: leave freeing a symlink body until inode eviction Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 146/183] procfs: fix race between symlink removals and traversals Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 147/183] autofs4 copy_dev_ioctl(): keep the value of ->size we'd used for allocation Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 148/183] ASoC: mioa701_wm9713: Fix speaker event Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 149/183] gpio: rcar: Fix error path for devm_kzalloc() failure Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 150/183] efi: Small leak on error in runtime map code Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 151/183] clk-gate: fix bit # check in clk_register_gate() Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 152/183] powerpc/kernel: Avoid memory corruption at early stage Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 153/183] pinctrl: pinctrl-imx: don't use invalid value of conf_reg Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 154/183] ALSA: off by one bug in snd_riptide_joystick_probe() Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 155/183] GFS2: Fix crash during ACL deletion in acl max entry check in gfs2_set_acl() Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 156/183] net: llc: use correct size for sysctl timeout entries Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 157/183] net: rds: use correct size for max unacked packets and bytes Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 158/183] HID: i2c-hid: Limit reads to wMaxInputLength bytes for input events Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 159/183] fib_trie: Fix /proc/net/fib_trie when CONFIG_IP_MULTIPLE_TABLES is not defined Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 160/183] net: sctp: fix race for one-to-many sockets in sendmsg's auto associate Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 161/183] gpio: sysfs: fix gpio attribute-creation race Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 162/183] ipv6: mld: fix add_grhead skb_over_panic for devs with large MTUs Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 163/183] ideapad-laptop: Change Lenovo Yoga 2 series rfkill handling Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 164/183] IB/core: When marshaling ucma path from user-space, clear unused fields Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 165/183] IB/core: Fix deadlock on uverbs modify_qp error flow Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 166/183] IB/mlx4: Fix wrong usage of IPv4 protocol for multicast attach/detach Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 167/183] IB/iser: Use correct dma direction when unmapping SGs Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 168/183] [media] Si2168: increase timeout to fix firmware loading Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 169/183] staging: comedi: cb_pcidas64: fix incorrect AI range code handling Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 170/183] target: Fix R_HOLDER bit usage for AllRegistrants Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 171/183] target: Avoid dropping AllRegistrants reservation during unregister Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 172/183] target: Allow AllRegistrants to re-RESERVE existing reservation Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 173/183] target: Allow Write Exclusive non-reservation holders to READ Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 174/183] vhost/scsi: potential memory corruption Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 175/183] clk: sunxi: Support factor clocks with N factor starting not from 0 Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 176/183] sunxi: clk: Set sun6i-pll1 n_start = 1 Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 177/183] HID: wacom: Report ABS_MISC event for Cintiq Companion Hybrid Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 178/183] mm: softdirty: unmapped addresses between VMAs are clean Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 179/183] proc/pagemap: walk page tables under pte lock Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 180/183] ARM: dts: am335x-bone*: usb0 is hardwired for peripheral Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 181/183] sched/rt: Reduce rq lock contention by eliminating locking of non-feasible target Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 182/183] caif: remove wrong dev_net_set() call Luis Henriques
2015-03-06 9:57 ` [PATCH 3.16.y-ckt 183/183] quota: Store maximum space limit in bytes Luis Henriques
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®