mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Kamal Mostafa <kamal@canonical.com>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org,
	kernel-team@lists.ubuntu.com
Cc: Filipe Manana <fdmanana@suse.com>, Kamal Mostafa <kamal@canonical.com>
Subject: [PATCH 3.19.y-ckt 042/164] Btrfs: fix truncation of compressed and inlined extents
Date: Wed,  2 Dec 2015 08:58:13 -0800	[thread overview]
Message-ID: <1449075615-20754-43-git-send-email-kamal@canonical.com> (raw)
In-Reply-To: <1449075615-20754-1-git-send-email-kamal@canonical.com>

3.19.8-ckt11 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Filipe Manana <fdmanana@suse.com>

commit 0305cd5f7fca85dae392b9ba85b116896eb7c1c7 upstream.

When truncating a file to a smaller size which consists of an inline
extent that is compressed, we did not discard (or made unusable) the
data between the new file size and the old file size, wasting metadata
space and allowing for the truncated data to be leaked and the data
corruption/loss mentioned below.
We were also not correctly decrementing the number of bytes used by the
inode, we were setting it to zero, giving a wrong report for callers of
the stat(2) syscall. The fsck tool also reported an error about a mismatch
between the nbytes of the file versus the real space used by the file.

Now because we weren't discarding the truncated region of the file, it
was possible for a caller of the clone ioctl to actually read the data
that was truncated, allowing for a security breach without requiring root
access to the system, using only standard filesystem operations. The
scenario is the following:

   1) User A creates a file which consists of an inline and compressed
      extent with a size of 2000 bytes - the file is not accessible to
      any other users (no read, write or execution permission for anyone
      else);

   2) The user truncates the file to a size of 1000 bytes;

   3) User A makes the file world readable;

   4) User B creates a file consisting of an inline extent of 2000 bytes;

   5) User B issues a clone operation from user A's file into its own
      file (using a length argument of 0, clone the whole range);

   6) User B now gets to see the 1000 bytes that user A truncated from
      its file before it made its file world readbale. User B also lost
      the bytes in the range [1000, 2000[ bytes from its own file, but
      that might be ok if his/her intention was reading stale data from
      user A that was never supposed to be public.

Note that this contrasts with the case where we truncate a file from 2000
bytes to 1000 bytes and then truncate it back from 1000 to 2000 bytes. In
this case reading any byte from the range [1000, 2000[ will return a value
of 0x00, instead of the original data.

This problem exists since the clone ioctl was added and happens both with
and without my recent data loss and file corruption fixes for the clone
ioctl (patch "Btrfs: fix file corruption and data loss after cloning
inline extents").

So fix this by truncating the compressed inline extents as we do for the
non-compressed case, which involves decompressing, if the data isn't already
in the page cache, compressing the truncated version of the extent, writing
the compressed content into the inline extent and then truncate it.

The following test case for fstests reproduces the problem. In order for
the test to pass both this fix and my previous fix for the clone ioctl
that forbids cloning a smaller inline extent into a larger one,
which is titled "Btrfs: fix file corruption and data loss after cloning
inline extents", are needed. Without that other fix the test fails in a
different way that does not leak the truncated data, instead part of
destination file gets replaced with zeroes (because the destination file
has a larger inline extent than the source).

  seq=`basename $0`
  seqres=$RESULT_DIR/$seq
  echo "QA output created by $seq"
  tmp=/tmp/$$
  status=1	# failure is the default!
  trap "_cleanup; exit \$status" 0 1 2 3 15

  _cleanup()
  {
      rm -f $tmp.*
  }

  # get standard environment, filters and checks
  . ./common/rc
  . ./common/filter

  # real QA test starts here
  _need_to_be_root
  _supported_fs btrfs
  _supported_os Linux
  _require_scratch
  _require_cloner

  rm -f $seqres.full

  _scratch_mkfs >>$seqres.full 2>&1
  _scratch_mount "-o compress"

  # Create our test files. File foo is going to be the source of a clone operation
  # and consists of a single inline extent with an uncompressed size of 512 bytes,
  # while file bar consists of a single inline extent with an uncompressed size of
  # 256 bytes. For our test's purpose, it's important that file bar has an inline
  # extent with a size smaller than foo's inline extent.
  $XFS_IO_PROG -f -c "pwrite -S 0xa1 0 128"   \
          -c "pwrite -S 0x2a 128 384" \
          $SCRATCH_MNT/foo | _filter_xfs_io
  $XFS_IO_PROG -f -c "pwrite -S 0xbb 0 256" $SCRATCH_MNT/bar | _filter_xfs_io

  # Now durably persist all metadata and data. We do this to make sure that we get
  # on disk an inline extent with a size of 512 bytes for file foo.
  sync

  # Now truncate our file foo to a smaller size. Because it consists of a
  # compressed and inline extent, btrfs did not shrink the inline extent to the
  # new size (if the extent was not compressed, btrfs would shrink it to 128
  # bytes), it only updates the inode's i_size to 128 bytes.
  $XFS_IO_PROG -c "truncate 128" $SCRATCH_MNT/foo

  # Now clone foo's inline extent into bar.
  # This clone operation should fail with errno EOPNOTSUPP because the source
  # file consists only of an inline extent and the file's size is smaller than
  # the inline extent of the destination (128 bytes < 256 bytes). However the
  # clone ioctl was not prepared to deal with a file that has a size smaller
  # than the size of its inline extent (something that happens only for compressed
  # inline extents), resulting in copying the full inline extent from the source
  # file into the destination file.
  #
  # Note that btrfs' clone operation for inline extents consists of removing the
  # inline extent from the destination inode and copy the inline extent from the
  # source inode into the destination inode, meaning that if the destination
  # inode's inline extent is larger (N bytes) than the source inode's inline
  # extent (M bytes), some bytes (N - M bytes) will be lost from the destination
  # file. Btrfs could copy the source inline extent's data into the destination's
  # inline extent so that we would not lose any data, but that's currently not
  # done due to the complexity that would be needed to deal with such cases
  # (specially when one or both extents are compressed), returning EOPNOTSUPP, as
  # it's normally not a very common case to clone very small files (only case
  # where we get inline extents) and copying inline extents does not save any
  # space (unlike for normal, non-inlined extents).
  $CLONER_PROG -s 0 -d 0 -l 0 $SCRATCH_MNT/foo $SCRATCH_MNT/bar

  # Now because the above clone operation used to succeed, and due to foo's inline
  # extent not being shinked by the truncate operation, our file bar got the whole
  # inline extent copied from foo, making us lose the last 128 bytes from bar
  # which got replaced by the bytes in range [128, 256[ from foo before foo was
  # truncated - in other words, data loss from bar and being able to read old and
  # stale data from foo that should not be possible to read anymore through normal
  # filesystem operations. Contrast with the case where we truncate a file from a
  # size N to a smaller size M, truncate it back to size N and then read the range
  # [M, N[, we should always get the value 0x00 for all the bytes in that range.

  # We expected the clone operation to fail with errno EOPNOTSUPP and therefore
  # not modify our file's bar data/metadata. So its content should be 256 bytes
  # long with all bytes having the value 0xbb.
  #
  # Without the btrfs bug fix, the clone operation succeeded and resulted in
  # leaking truncated data from foo, the bytes that belonged to its range
  # [128, 256[, and losing data from bar in that same range. So reading the
  # file gave us the following content:
  #
  # 0000000 a1 a1 a1 a1 a1 a1 a1 a1 a1 a1 a1 a1 a1 a1 a1 a1
  # *
  # 0000200 2a 2a 2a 2a 2a 2a 2a 2a 2a 2a 2a 2a 2a 2a 2a 2a
  # *
  # 0000400
  echo "File bar's content after the clone operation:"
  od -t x1 $SCRATCH_MNT/bar

  # Also because the foo's inline extent was not shrunk by the truncate
  # operation, btrfs' fsck, which is run by the fstests framework everytime a
  # test completes, failed reporting the following error:
  #
  #  root 5 inode 257 errors 400, nbytes wrong

  status=0
  exit

Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/btrfs/inode.c | 82 ++++++++++++++++++++++++++++++++++++++++++++++----------
 1 file changed, 68 insertions(+), 14 deletions(-)

diff --git a/fs/btrfs/inode.c b/fs/btrfs/inode.c
index fbcd590..76a450c 100644
--- a/fs/btrfs/inode.c
+++ b/fs/btrfs/inode.c
@@ -4074,6 +4074,47 @@ out:
 	return err;
 }
 
+static int truncate_inline_extent(struct inode *inode,
+				  struct btrfs_path *path,
+				  struct btrfs_key *found_key,
+				  const u64 item_end,
+				  const u64 new_size)
+{
+	struct extent_buffer *leaf = path->nodes[0];
+	int slot = path->slots[0];
+	struct btrfs_file_extent_item *fi;
+	u32 size = (u32)(new_size - found_key->offset);
+	struct btrfs_root *root = BTRFS_I(inode)->root;
+
+	fi = btrfs_item_ptr(leaf, slot, struct btrfs_file_extent_item);
+
+	if (btrfs_file_extent_compression(leaf, fi) != BTRFS_COMPRESS_NONE) {
+		loff_t offset = new_size;
+		loff_t page_end = ALIGN(offset, PAGE_CACHE_SIZE);
+
+		/*
+		 * Zero out the remaining of the last page of our inline extent,
+		 * instead of directly truncating our inline extent here - that
+		 * would be much more complex (decompressing all the data, then
+		 * compressing the truncated data, which might be bigger than
+		 * the size of the inline extent, resize the extent, etc).
+		 * We release the path because to get the page we might need to
+		 * read the extent item from disk (data not in the page cache).
+		 */
+		btrfs_release_path(path);
+		return btrfs_truncate_page(inode, offset, page_end - offset, 0);
+	}
+
+	btrfs_set_file_extent_ram_bytes(leaf, fi, size);
+	size = btrfs_file_extent_calc_inline_size(size);
+	btrfs_truncate_item(root, path, size, 1);
+
+	if (test_bit(BTRFS_ROOT_REF_COWS, &root->state))
+		inode_sub_bytes(inode, item_end + 1 - new_size);
+
+	return 0;
+}
+
 /*
  * this can truncate away extent items, csum items and directory items.
  * It starts at a high offset and removes keys until it can't find
@@ -4243,27 +4284,40 @@ search_again:
 			 * special encodings
 			 */
 			if (!del_item &&
-			    btrfs_file_extent_compression(leaf, fi) == 0 &&
 			    btrfs_file_extent_encryption(leaf, fi) == 0 &&
 			    btrfs_file_extent_other_encoding(leaf, fi) == 0) {
-				u32 size = new_size - found_key.offset;
-
-				if (test_bit(BTRFS_ROOT_REF_COWS, &root->state))
-					inode_sub_bytes(inode, item_end + 1 -
-							new_size);
 
 				/*
-				 * update the ram bytes to properly reflect
-				 * the new size of our item
+				 * Need to release path in order to truncate a
+				 * compressed extent. So delete any accumulated
+				 * extent items so far.
 				 */
-				btrfs_set_file_extent_ram_bytes(leaf, fi, size);
-				size =
-				    btrfs_file_extent_calc_inline_size(size);
-				btrfs_truncate_item(root, path, size, 1);
+				if (btrfs_file_extent_compression(leaf, fi) !=
+				    BTRFS_COMPRESS_NONE && pending_del_nr) {
+					err = btrfs_del_items(trans, root, path,
+							      pending_del_slot,
+							      pending_del_nr);
+					if (err) {
+						btrfs_abort_transaction(trans,
+									root,
+									err);
+						goto error;
+					}
+					pending_del_nr = 0;
+				}
+
+				err = truncate_inline_extent(inode, path,
+							     &found_key,
+							     item_end,
+							     new_size);
+				if (err) {
+					btrfs_abort_transaction(trans,
+								root, err);
+					goto error;
+				}
 			} else if (test_bit(BTRFS_ROOT_REF_COWS,
 					    &root->state)) {
-				inode_sub_bytes(inode, item_end + 1 -
-						found_key.offset);
+				inode_sub_bytes(inode, item_end + 1 - new_size);
 			}
 		}
 delete:
-- 
1.9.1


  parent reply	other threads:[~2015-12-02 17:52 UTC|newest]

Thread overview: 170+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-12-02 16:57 [3.19.y-ckt stable] Linux 3.19.8-ckt11 stable review Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 001/164] x86/setup: Extend low identity map to cover whole kernel range Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 002/164] x86/setup: Fix low identity map for >= 2GB " Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 003/164] drm/radeon: add quirk for MSI R7 370 Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 004/164] drm/radeon: add quirk for ASUS " Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 005/164] drm/radeon: fix quirk for MSI R7 370 Armor 2X Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 006/164] irda: precedence bug in irlmp_seq_hb_idx() Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 007/164] tipc: allow non-linear first fragment buffer Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 008/164] qmi_wwan: add Sierra Wireless MC74xx/EM74xx Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 009/164] macvtap: unbreak receiving of gro skb with frag list Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 010/164] RDS-TCP: Recover correctly from pskb_pull()/pksb_trim() failure in rds_tcp_data_recv Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 011/164] stmmac: Correctly report PTP capabilities Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 012/164] ipmr: fix possible race resulting from improper usage of IP_INC_STATS_BH() in preemptible context Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 013/164] qmi_wwan: fix entry for HP lt4112 LTE/HSPA+ Gobi 4G Module Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 014/164] sit: fix sit0 percpu double allocations Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 015/164] sfc: push partner queue for skb->xmit_more Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 016/164] net: avoid NULL deref in inet_ctl_sock_destroy() Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 017/164] ipv6: clean up dev_snmp6 proc entry when we fail to initialize inet6_dev Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 018/164] ipv4: disable BH when changing ip local port range Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 019/164] packet: race condition in packet_bind Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 020/164] net: fix a race in dst_release() Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 021/164] HID: core: Avoid uninitialized buffer access Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 022/164] [media] v4l2-compat-ioctl32: fix alignment for ARM64 Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 023/164] net: mvneta: Fix CPU_MAP registers initialisation Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 024/164] mtd: mtdpart: fix add_mtd_partitions error path Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 025/164] fs/proc, core/debug: Don't expose absolute kernel addresses via wchan Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 026/164] [media] v4l2-ctrls: arrays are also considered compound controls Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 027/164] [media] media: v4l2-ctrls: Fix 64bit support in get_ctrl() Kamal Mostafa
2015-12-02 16:57 ` [PATCH 3.19.y-ckt 028/164] ARM: tegra: paz00: use con_id's to refer GPIO's in gpiod_lookup table Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 029/164] ARM: 8426/1: dma-mapping: add missing range check in dma_mmap() Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 030/164] ARM: 8427/1: dma-mapping: add support for offset parameter " Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 031/164] integrity: prevent loading untrusted certificates on the IMA trusted keyring Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 032/164] usb: dwc3: pci: Add the Synopsys HAPS AXI Product ID Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 033/164] usb: dwc3: pci: Add the PCI Product ID for Synopsys USB 3.1 Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 034/164] usb: dwc3: Support Synopsys USB 3.1 IP Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 035/164] usb: dwc3: Add dis_enblslpm_quirk Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 036/164] spi: ti-qspi: Fix data corruption seen on r/w stress test Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 037/164] nfsd: serialize state seqid morphing operations Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 038/164] lockd: create NSM handles per net namespace Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 039/164] Btrfs: fix file corruption and data loss after cloning inline extents Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 040/164] ARM: common: edma: Fix channel parameter for irq callbacks Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 041/164] iommu/vt-d: Fix ATSR handling for Root-Complex integrated endpoints Kamal Mostafa
2015-12-02 16:58 ` Kamal Mostafa [this message]
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 043/164] jbd2: fix checkpoint list cleanup Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 044/164] ext4: fix potential use after free in __ext4_journal_stop Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 045/164] [PATCH] fix calculation of meta_bg descriptor backups Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 046/164] ext4, jbd2: ensure entering into panic after recording an error in superblock Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 047/164] vTPM: fix memory allocation flag for rtce buffer at kernel boot Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 048/164] spi: dw: explicitly free IRQ handler in dw_spi_remove_host() Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 049/164] [media] media: vb2 dma-contig: Fully cache synchronise buffers in prepare and finish Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 050/164] [media] media: vb2 dma-sg: " Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 051/164] [media] media/v4l2-ctrls: fix setting autocluster to manual with VIDIOC_S_CTRL Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 052/164] Bluetooth: hidp: fix device disconnect on idle timeout Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 053/164] Bluetooth: ath3k: Add new AR3012 0930:021c id Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 054/164] Bluetooth: ath3k: Add support of AR3012 0cf3:817b device Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 055/164] Bluetooth: Fix removing connection parameters when unpairing Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 056/164] spi: atmel: Fix DMA-setup for transfers with more than 8 bits per word Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 057/164] USB: qcserial: add Sierra Wireless MC74xx/EM74xx Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 058/164] staging: rtl8712: Add device ID for Sitecom WLA2100 Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 059/164] ACPI: Use correct IRQ when uninstalling ACPI interrupt handler Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 060/164] ACPI: Using correct irq when waiting for events Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 061/164] ACPI / PM: Fix incorrect wakeup IRQ setting during suspend-to-idle Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 062/164] ALSA: hda/realtek - Dell XPS one ALC3260 speaker no sound after resume back Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 063/164] ALSA: hda - Disable 64bit address for Creative HDA controllers Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 064/164] MAINTAINERS: Add public mailing list for ARC Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 065/164] megaraid_sas: Expose TAPE drives unconditionally Kamal Mostafa
2015-12-02 17:09   ` Sumit Saxena
2015-12-02 17:39     ` Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 066/164] megaraid_sas: Do not use PAGE_SIZE for max_sectors Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 067/164] KVM: s390: SCA must not cross page boundaries Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 068/164] arm64: Fix compat register mappings Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 069/164] can: Use correct type in sizeof() in nla_put() Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 070/164] mtd: blkdevs: fix potential deadlock + lockdep warnings Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 071/164] Revert "dm mpath: fix stalls when handling invalid ioctls" Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 072/164] drm/i915: add quirk to enable backlight on Dell Chromebook 11 (2015) Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 073/164] crypto: algif_hash - Only export and import on sockets with data Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 074/164] xtensa: fixes for configs without loop option Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 075/164] PCI: spear: Fix dw_pcie_cfg_read/write() usage Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 076/164] megaraid_sas : SMAP restriction--do not access user memory from IOCTL code Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 077/164] mac80211: fix divide by zero when NOA update Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 078/164] nl80211: Fix potential memory leak from parse_acl_data Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 079/164] mac80211: allow null chandef in tracing Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 080/164] xtensa: fix secondary core boot in SMP Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 081/164] recordmcount: Fix endianness handling bug for nop_mcount Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 082/164] recordmcount: arm64: Replace the ignored mcount call into nop Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 083/164] KVM: VMX: fix SMEP and SMAP without EPT Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 084/164] thermal: exynos: Fix unbalanced regulator disable on probe failure Kamal Mostafa
2015-12-09 13:24   ` Krzysztof Kozlowski
2015-12-10  0:49     ` Krzysztof Kozlowski
2015-12-10 16:26       ` Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 085/164] ALSA: hda - Apply pin fixup for HP ProBook 6550b Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 086/164] ALSA: hda - Add Intel Lewisburg device IDs Audio Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 087/164] firewire: ohci: fix JMicron JMB38x IT context discovery Kamal Mostafa
2015-12-02 16:58 ` [PATCH 3.19.y-ckt 088/164] scsi: restart list search after unlock in scsi_remove_target Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 089/164] mm: slab: only move management objects off-slab for sizes larger than KMALLOC_MIN_SIZE Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 090/164] memcg: fix thresholds for 32b architectures Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 091/164] arm64: bpf: fix div-by-zero case Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 092/164] arm64: bpf: fix mod-by-zero case Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 093/164] Input: elantech - add Fujitsu Lifebook U745 to force crc_enabled Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 094/164] proc: actually make proc_fd_permission() thread-friendly Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 095/164] printk: prevent userland from spoofing kernel messages Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 096/164] fs, seqfile: always allow oom killer Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 097/164] x86/cpu: Call verify_cpu() after having entered long mode too Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 098/164] parisc: Fixes and cleanups in kernel uapi header files Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 099/164] Btrfs: fix race leading to incorrect item deletion when dropping extents Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 100/164] Btrfs: fix race leading to BUG_ON when running delalloc for nodatacow Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 101/164] ALSA: usb: Add native DSD support for Aune X1S Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 102/164] perf: Fix inherited events vs. tracepoint filters Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 103/164] scsi_sysfs: Fix queue_ramp_up_period return code Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 104/164] Btrfs: fix race when listing an inode's xattrs Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 105/164] ideapad-laptop: Add Lenovo Yoga 900 to no_hw_rfkill dmi list Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 106/164] storvsc: Don't set the SRB_FLAGS_QUEUE_ACTION_ENABLE flag Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 107/164] KVM: x86: work around infinite loop in microcode when #AC is delivered Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 108/164] KVM: svm: unconditionally intercept #DB Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 109/164] drivers: of: of_reserved_mem: fixup the alignment with CMA setup Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 110/164] drm/ast: Initialized data needed to map fbdev memory Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 111/164] FS-Cache: Increase reference of parent after registering, netfs success Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 112/164] FS-Cache: Don't override netfs's primary_index if registering failed Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 113/164] FS-Cache: Handle a write to the page immediately beyond the EOF marker Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 114/164] binfmt_elf: Don't clobber passed executable's file header Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 115/164] fs/pipe.c: return error code rather than 0 in pipe_write() Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 116/164] ALSA: hda/hdmi - apply Skylake fix-ups to Broxton display codec Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 117/164] crypto: crc32c-pclmul - use .rodata instead of .rotata Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 118/164] wm831x_power: Use IRQF_ONESHOT to request threaded IRQs Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 119/164] mwifiex: fix mwifiex_rdeeprom_read() Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 120/164] dmaengine: dw: convert to __ffs() Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 121/164] tcp: call sk_mark_napi_id() on the child, not the listener Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 122/164] vivid: Fix iteration in driver removal path Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 123/164] usb: ehci-orion: fix probe for !GENERIC_PHY Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 124/164] devres: fix a for loop bounds check Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 125/164] netfilter: remove dead code Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 126/164] ipv4: Fix ip_queue_xmit to pass sk into ip_local_out_sk Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 127/164] i2c: img-scb: enable fencing for all versions of the ip Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 128/164] i2c: img-scb: do dummy writes before fifo access Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 129/164] i2c: img-scb: use DIV_ROUND_UP to round divisor values Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 130/164] i2c: img-scb: fix LOW and HIGH period values for the SCL clock Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 131/164] i2c: img-scb: Clear line and interrupt status before starting a transfer Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 132/164] i2c: img-scb: verify support for requested bit rate Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 133/164] hsi: fix double kfree Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 134/164] hsi: omap_ssi_port: Prevent warning if cawake_gpio is not defined Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 135/164] regulator: arizona-ldo1: Fix handling of GPIO 0 Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 136/164] ARM: pxa: remove incorrect __init annotation on pxa27x_set_pwrmode Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 137/164] ALSA: fireworks/bebob/oxfw/dice: enable to make as built-in Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 138/164] drm: Fix return value of drm_framebuffer_init() Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 139/164] ALSA: dice: correct variable types for __be32 data Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 140/164] ALSA: dice: assign converted data to the same type of variable Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 141/164] ALSA: fireworks: use u32 type for be32_to_cpup() macro Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 142/164] ALSA: bebob: use correct type for __be32 data Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 143/164] sunrpc: avoid warning in gss_key_timeout Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 144/164] clk: versatile-icst: fix memory leak Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 145/164] MIPS: atomic: Fix comment describing atomic64_add_unless's return value Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 146/164] mfd: twl6040: Fix deferred probe handling for clk32k Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 147/164] DT: mmc: sh_mmcif: fix "compatible" property text Kamal Mostafa
2015-12-02 16:59 ` [PATCH 3.19.y-ckt 148/164] netfilter: nf_nat_redirect: add missing NULL pointer check Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 149/164] of/fdt: fix error checking for earlycon address Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 150/164] netfilter: nfnetlink: don't probe module if it exists Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 151/164] sparc/PCI: Add mem64 resource parsing for root bus Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 152/164] xprtrdma: Re-arm after missed events Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 153/164] ceph: fix message length computation Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 154/164] tracepoints: Fix documentation of RCU lockdep checks Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 155/164] ipv6: fix tunnel error handling Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 156/164] perf trace: Fix documentation for -i Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 157/164] bonding: fix panic on non-ARPHRD_ETHER enslave failure Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 158/164] rtc: ds1307: Fix alarm programming for mcp794xx Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 159/164] mac80211: fix driver RSSI event calculations Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 160/164] packet: fix match_fanout_group() Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 161/164] tcp: apply Kern's check on RTTs used for congestion control Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 162/164] net: fix percpu memory leaks Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 163/164] TPM: Avoid reference to potentially freed memory Kamal Mostafa
2015-12-02 17:00 ` [PATCH 3.19.y-ckt 164/164] [3.19-stable only] fib_rules: Fix dump_rules() not to exit early Kamal Mostafa

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1449075615-20754-43-git-send-email-kamal@canonical.com \
    --to=kamal@canonical.com \
    --cc=fdmanana@suse.com \
    --cc=kernel-team@lists.ubuntu.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®