mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Willy Tarreau <w@1wt.eu>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Guillaume Nault <g.nault@alphalink.fr>,
	"David S . Miller" <davem@davemloft.net>,
	Willy Tarreau <w@1wt.eu>
Subject: [PATCH 3.10 070/143] ppp: take reference on channels netns
Date: Sun,  5 Jun 2016 12:19:33 +0200	[thread overview]
Message-ID: <1465122046-9645-71-git-send-email-w@1wt.eu> (raw)
In-Reply-To: <1465122046-9645-1-git-send-email-w@1wt.eu>

From: Guillaume Nault <g.nault@alphalink.fr>

commit 1f461dcdd296eecedaffffc6bae2bfa90bd7eb89 upstream.

Let channels hold a reference on their network namespace.
Some channel types, like ppp_async and ppp_synctty, can have their
userspace controller running in a different namespace. Therefore they
can't rely on them to preclude their netns from being removed from
under them.

==================================================================
BUG: KASAN: use-after-free in ppp_unregister_channel+0x372/0x3a0 at
addr ffff880064e217e0
Read of size 8 by task syz-executor/11581
=============================================================================
BUG net_namespace (Not tainted): kasan: bad access detected
-----------------------------------------------------------------------------

Disabling lock debugging due to kernel taint
INFO: Allocated in copy_net_ns+0x6b/0x1a0 age=92569 cpu=3 pid=6906
[<      none      >] ___slab_alloc+0x4c7/0x500 kernel/mm/slub.c:2440
[<      none      >] __slab_alloc+0x4c/0x90 kernel/mm/slub.c:2469
[<     inline     >] slab_alloc_node kernel/mm/slub.c:2532
[<     inline     >] slab_alloc kernel/mm/slub.c:2574
[<      none      >] kmem_cache_alloc+0x23a/0x2b0 kernel/mm/slub.c:2579
[<     inline     >] kmem_cache_zalloc kernel/include/linux/slab.h:597
[<     inline     >] net_alloc kernel/net/core/net_namespace.c:325
[<      none      >] copy_net_ns+0x6b/0x1a0 kernel/net/core/net_namespace.c:360
[<      none      >] create_new_namespaces+0x2f6/0x610 kernel/kernel/nsproxy.c:95
[<      none      >] copy_namespaces+0x297/0x320 kernel/kernel/nsproxy.c:150
[<      none      >] copy_process.part.35+0x1bf4/0x5760 kernel/kernel/fork.c:1451
[<     inline     >] copy_process kernel/kernel/fork.c:1274
[<      none      >] _do_fork+0x1bc/0xcb0 kernel/kernel/fork.c:1723
[<     inline     >] SYSC_clone kernel/kernel/fork.c:1832
[<      none      >] SyS_clone+0x37/0x50 kernel/kernel/fork.c:1826
[<      none      >] entry_SYSCALL_64_fastpath+0x16/0x7a kernel/arch/x86/entry/entry_64.S:185

INFO: Freed in net_drop_ns+0x67/0x80 age=575 cpu=2 pid=2631
[<      none      >] __slab_free+0x1fc/0x320 kernel/mm/slub.c:2650
[<     inline     >] slab_free kernel/mm/slub.c:2805
[<      none      >] kmem_cache_free+0x2a0/0x330 kernel/mm/slub.c:2814
[<     inline     >] net_free kernel/net/core/net_namespace.c:341
[<      none      >] net_drop_ns+0x67/0x80 kernel/net/core/net_namespace.c:348
[<      none      >] cleanup_net+0x4e5/0x600 kernel/net/core/net_namespace.c:448
[<      none      >] process_one_work+0x794/0x1440 kernel/kernel/workqueue.c:2036
[<      none      >] worker_thread+0xdb/0xfc0 kernel/kernel/workqueue.c:2170
[<      none      >] kthread+0x23f/0x2d0 kernel/drivers/block/aoe/aoecmd.c:1303
[<      none      >] ret_from_fork+0x3f/0x70 kernel/arch/x86/entry/entry_64.S:468
INFO: Slab 0xffffea0001938800 objects=3 used=0 fp=0xffff880064e20000
flags=0x5fffc0000004080
INFO: Object 0xffff880064e20000 @offset=0 fp=0xffff880064e24200

CPU: 1 PID: 11581 Comm: syz-executor Tainted: G    B           4.4.0+
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
rel-1.8.2-0-g33fbe13 by qemu-project.org 04/01/2014
 00000000ffffffff ffff8800662c7790 ffffffff8292049d ffff88003e36a300
 ffff880064e20000 ffff880064e20000 ffff8800662c77c0 ffffffff816f2054
 ffff88003e36a300 ffffea0001938800 ffff880064e20000 0000000000000000
Call Trace:
 [<     inline     >] __dump_stack kernel/lib/dump_stack.c:15
 [<ffffffff8292049d>] dump_stack+0x6f/0xa2 kernel/lib/dump_stack.c:50
 [<ffffffff816f2054>] print_trailer+0xf4/0x150 kernel/mm/slub.c:654
 [<ffffffff816f875f>] object_err+0x2f/0x40 kernel/mm/slub.c:661
 [<     inline     >] print_address_description kernel/mm/kasan/report.c:138
 [<ffffffff816fb0c5>] kasan_report_error+0x215/0x530 kernel/mm/kasan/report.c:236
 [<     inline     >] kasan_report kernel/mm/kasan/report.c:259
 [<ffffffff816fb4de>] __asan_report_load8_noabort+0x3e/0x40 kernel/mm/kasan/report.c:280
 [<     inline     >] ? ppp_pernet kernel/include/linux/compiler.h:218
 [<ffffffff83ad71b2>] ? ppp_unregister_channel+0x372/0x3a0 kernel/drivers/net/ppp/ppp_generic.c:2392
 [<     inline     >] ppp_pernet kernel/include/linux/compiler.h:218
 [<ffffffff83ad71b2>] ppp_unregister_channel+0x372/0x3a0 kernel/drivers/net/ppp/ppp_generic.c:2392
 [<     inline     >] ? ppp_pernet kernel/drivers/net/ppp/ppp_generic.c:293
 [<ffffffff83ad6f26>] ? ppp_unregister_channel+0xe6/0x3a0 kernel/drivers/net/ppp/ppp_generic.c:2392
 [<ffffffff83ae18f3>] ppp_asynctty_close+0xa3/0x130 kernel/drivers/net/ppp/ppp_async.c:241
 [<ffffffff83ae1850>] ? async_lcp_peek+0x5b0/0x5b0 kernel/drivers/net/ppp/ppp_async.c:1000
 [<ffffffff82c33239>] tty_ldisc_close.isra.1+0x99/0xe0 kernel/drivers/tty/tty_ldisc.c:478
 [<ffffffff82c332c0>] tty_ldisc_kill+0x40/0x170 kernel/drivers/tty/tty_ldisc.c:744
 [<ffffffff82c34943>] tty_ldisc_release+0x1b3/0x260 kernel/drivers/tty/tty_ldisc.c:772
 [<ffffffff82c1ef21>] tty_release+0xac1/0x13e0 kernel/drivers/tty/tty_io.c:1901
 [<ffffffff82c1e460>] ? release_tty+0x320/0x320 kernel/drivers/tty/tty_io.c:1688
 [<ffffffff8174de36>] __fput+0x236/0x780 kernel/fs/file_table.c:208
 [<ffffffff8174e405>] ____fput+0x15/0x20 kernel/fs/file_table.c:244
 [<ffffffff813595ab>] task_work_run+0x16b/0x200 kernel/kernel/task_work.c:115
 [<     inline     >] exit_task_work kernel/include/linux/task_work.h:21
 [<ffffffff81307105>] do_exit+0x8b5/0x2c60 kernel/kernel/exit.c:750
 [<ffffffff813fdd20>] ? debug_check_no_locks_freed+0x290/0x290 kernel/kernel/locking/lockdep.c:4123
 [<ffffffff81306850>] ? mm_update_next_owner+0x6f0/0x6f0 kernel/kernel/exit.c:357
 [<ffffffff813215e6>] ? __dequeue_signal+0x136/0x470 kernel/kernel/signal.c:550
 [<ffffffff8132067b>] ? recalc_sigpending_tsk+0x13b/0x180 kernel/kernel/signal.c:145
 [<ffffffff81309628>] do_group_exit+0x108/0x330 kernel/kernel/exit.c:880
 [<ffffffff8132b9d4>] get_signal+0x5e4/0x14f0 kernel/kernel/signal.c:2307
 [<     inline     >] ? kretprobe_table_lock kernel/kernel/kprobes.c:1113
 [<ffffffff8151d355>] ? kprobe_flush_task+0xb5/0x450 kernel/kernel/kprobes.c:1158
 [<ffffffff8115f7d3>] do_signal+0x83/0x1c90 kernel/arch/x86/kernel/signal.c:712
 [<ffffffff8151d2a0>] ? recycle_rp_inst+0x310/0x310 kernel/include/linux/list.h:655
 [<ffffffff8115f750>] ? setup_sigcontext+0x780/0x780 kernel/arch/x86/kernel/signal.c:165
 [<ffffffff81380864>] ? finish_task_switch+0x424/0x5f0 kernel/kernel/sched/core.c:2692
 [<     inline     >] ? finish_lock_switch kernel/kernel/sched/sched.h:1099
 [<ffffffff81380560>] ? finish_task_switch+0x120/0x5f0 kernel/kernel/sched/core.c:2678
 [<     inline     >] ? context_switch kernel/kernel/sched/core.c:2807
 [<ffffffff85d794e9>] ? __schedule+0x919/0x1bd0 kernel/kernel/sched/core.c:3283
 [<ffffffff81003901>] exit_to_usermode_loop+0xf1/0x1a0 kernel/arch/x86/entry/common.c:247
 [<     inline     >] prepare_exit_to_usermode kernel/arch/x86/entry/common.c:282
 [<ffffffff810062ef>] syscall_return_slowpath+0x19f/0x210 kernel/arch/x86/entry/common.c:344
 [<ffffffff85d88022>] int_ret_from_sys_call+0x25/0x9f kernel/arch/x86/entry/entry_64.S:281
Memory state around the buggy address:
 ffff880064e21680: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
 ffff880064e21700: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
>ffff880064e21780: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
                                                       ^
 ffff880064e21800: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
 ffff880064e21880: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
==================================================================

Fixes: 273ec51dd7ce ("net: ppp_generic - introduce net-namespace functionality v2")
Reported-by: Baozeng Ding <sploving1@gmail.com>
Signed-off-by: Guillaume Nault <g.nault@alphalink.fr>
Reviewed-by: Cyrill Gorcunov <gorcunov@openvz.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/net/ppp/ppp_generic.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ppp/ppp_generic.c b/drivers/net/ppp/ppp_generic.c
index a2d7d5f..14a8d29 100644
--- a/drivers/net/ppp/ppp_generic.c
+++ b/drivers/net/ppp/ppp_generic.c
@@ -2220,7 +2220,7 @@ int ppp_register_net_channel(struct net *net, struct ppp_channel *chan)
 
 	pch->ppp = NULL;
 	pch->chan = chan;
-	pch->chan_net = net;
+	pch->chan_net = get_net(net);
 	chan->ppp = pch;
 	init_ppp_file(&pch->file, CHANNEL);
 	pch->file.hdrlen = chan->hdrlen;
@@ -2317,6 +2317,8 @@ ppp_unregister_channel(struct ppp_channel *chan)
 	spin_lock_bh(&pn->all_channels_lock);
 	list_del(&pch->list);
 	spin_unlock_bh(&pn->all_channels_lock);
+	put_net(pch->chan_net);
+	pch->chan_net = NULL;
 
 	pch->file.dead = 1;
 	wake_up_interruptible(&pch->file.rwait);
-- 
2.8.0.rc2.1.gbe9624a

  parent reply	other threads:[~2016-06-05 10:22 UTC|newest]

Thread overview: 154+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-06-05 10:18 [PATCH 3.10 000/143] 3.10.102-stable review Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 001/143] pipe: Fix buffer offset after partially failed read Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 002/143] x86/iopl/64: Properly context-switch IOPL on Xen PV Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 003/143] ext4: fix NULL pointer dereference in ext4_mark_inode_dirty() Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 004/143] compiler-gcc: integrate the various compiler-gcc[345].h files Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 005/143] x86: LLVMLinux: Fix "incomplete type const struct x86cpu_device_id" Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 006/143] KVM: i8254: change PIT discard tick policy Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 007/143] KVM: fix spin_lock_init order on x86 Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 008/143] EDAC, amd64_edac: Shift wrapping issue in f1x_get_norm_dct_addr() Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 009/143] PCI: Disable IO/MEM decoding for devices with non-compliant BARs Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 010/143] linux/const.h: Add _BITUL() and _BITULL() Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 011/143] x86: Rename X86_CR4_RDWRGSFS to X86_CR4_FSGSBASE Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 012/143] x86, processor-flags: Fix the datatypes and add bit number defines Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 013/143] x86/iopl: Fix iopl capability check on Xen PV Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 014/143] sg: fix dxferp in from_to case Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 015/143] aacraid: Fix memory leak in aac_fib_map_free Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 016/143] be2iscsi: set the boot_kset pointer to NULL in case of failure Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 017/143] usb: retry reset if a device times out Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 018/143] USB: cdc-acm: more sanity checking Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 019/143] USB: iowarrior: fix oops with malicious USB descriptors Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 020/143] USB: usb_driver_claim_interface: add sanity checking Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 021/143] USB: mct_u232: add sanity checking in probe Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 022/143] USB: digi_acceleport: do sanity checking for the number of ports Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 023/143] USB: cypress_m8: add endpoint sanity check Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 024/143] USB: serial: cp210x: Adding GE Healthcare Device ID Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 025/143] USB: option: add "D-Link DWM-221 B1" device id Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 026/143] pwc: Add USB id for Philips Spc880nc webcam Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 027/143] Input: powermate - fix oops with malicious USB descriptors Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 028/143] net: irda: Fix use-after-free in irtty_open() Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 029/143] 8250: use callbacks to access UART_DLL/UART_DLM Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 030/143] bttv: Width must be a multiple of 16 when capturing planar formats Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 031/143] media: v4l2-compat-ioctl32: fix missing length copy in put_v4l2_buffer32 Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 032/143] ALSA: intel8x0: Add clock quirk entry for AD1981B on IBM ThinkPad X41 Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 033/143] jbd2: fix FS corruption possibility in jbd2_journal_destroy() on umount path Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 034/143] bcache: fix cache_set_flush() NULL pointer dereference on OOM Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 035/143] watchdog: rc32434_wdt: fix ioctl error handling Willy Tarreau
2016-06-05 10:18 ` [PATCH 3.10 036/143] splice: handle zero nr_pages in splice_to_pipe() Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 037/143] xtensa: ISS: don't hang if stdin EOF is reached Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 038/143] xtensa: clear all DBREAKC registers on start Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 039/143] md/raid5: Compare apples to apples (or sectors to sectors) Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 040/143] rapidio/rionet: fix deadlock on SMP Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 041/143] ipr: Fix out-of-bounds null overwrite Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 042/143] ipr: Fix regression when loading firmware Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 043/143] drm/radeon: Don't drop DP 2.7 Ghz link setup on some cards Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 044/143] tracing: Have preempt(irqs)off trace preempt disabled functions Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 045/143] tracing: Fix crash from reading trace_pipe with sendfile Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 046/143] tracing: Fix trace_printk() to print when not using bprintk() Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 047/143] scripts/coccinelle: modernize & Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 048/143] Input: ims-pcu - sanity check against missing interfaces Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 049/143] Input: ati_remote2 - fix crashes on detecting device with invalid descriptor Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 050/143] ocfs2/dlm: fix race between convert and recovery Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 051/143] ocfs2/dlm: fix BUG in dlm_move_lockres_to_recovery_list Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 052/143] mtd: onenand: fix deadlock in onenand_block_markbad Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 053/143] sched/cputime: Fix steal time accounting vs. CPU hotplug Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 054/143] perf/x86/intel: Fix PEBS data source interpretation on Nehalem/Westmere Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 055/143] hwmon: (max1111) Return -ENODEV from max1111_read_channel if not instantiated Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 056/143] parisc: Avoid function pointers for kernel exception routines Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 057/143] parisc: Fix kernel crash with reversed copy_from_user() Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 058/143] ALSA: timer: Use mod_timer() for rearming the system timer Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 059/143] net: jme: fix suspend/resume on JMC260 Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 060/143] sctp: lack the check for ports in sctp_v6_cmp_addr Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 061/143] ipv6: re-enable fragment header matching in ipv6_find_hdr Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 062/143] cdc_ncm: toggle altsetting to force reset before setup Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 063/143] usbnet: cleanup after bind() in probe() Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 064/143] udp6: fix UDP/IPv6 encap resubmit path Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 065/143] sh_eth: fix NULL pointer dereference in sh_eth_ring_format() Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 066/143] net: Fix use after free in the recvmmsg exit path Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 067/143] farsync: fix off-by-one bug in fst_add_one Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 068/143] ath9k: fix buffer overrun for ar9287 Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 069/143] qlge: Fix receive packets drop Willy Tarreau
2016-06-05 10:19 ` Willy Tarreau [this message]
2016-06-05 10:19 ` [PATCH 3.10 071/143] qmi_wwan: add "D-Link DWM-221 B1" device id Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 072/143] ipv4: l2tp: fix a potential issue in l2tp_ip_recv Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 073/143] ipv6: l2tp: fix a potential issue in l2tp_ip6_recv Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 074/143] ip6_tunnel: set rtnl_link_ops before calling register_netdevice Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 075/143] usb: renesas_usbhs: avoid NULL pointer derefernce in usbhsf_pkt_handler() Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 076/143] usb: renesas_usbhs: disable TX IRQ before starting TX DMAC transfer Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 077/143] ext4: add lockdep annotations for i_data_sem Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 078/143] HID: usbhid: fix inconsistent reset/resume/reset-resume behavior Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 079/143] drm/radeon: hold reference to fences in radeon_sa_bo_new (3.17 and older) Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 080/143] [media] usbvision-video: fix memory leak of alt_max_pkt_size Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 081/143] usbvision: fix leak of usb_dev on failure paths in usbvision_probe() Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 082/143] usbvision: fix crash on detecting device with invalid configuration Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 083/143] usb: xhci: fix wild pointers in xhci_mem_cleanup Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 084/143] usb: hcd: out of bounds access in for_each_companion Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 085/143] crypto: gcm - Fix rfc4543 decryption crash Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 086/143] nl80211: check netlink protocol in socket release notification Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 087/143] Input: gtco - fix crash on detecting device without endpoints Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 088/143] i2c: cpm: Fix build break due to incompatible pointer types Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 089/143] EDAC: i7core, sb_edac: Don't return NOTIFY_BAD from mce_decoder callback Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 090/143] ASoC: s3c24xx: use const snd_soc_component_driver pointer Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 091/143] efi: Fix out-of-bounds read in variable_matches() Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 092/143] workqueue: fix ghost PENDING flag while doing MQ IO Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 093/143] USB: usbip: fix potential out-of-bounds write Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 094/143] paride: make 'verbose' parameter an 'int' again Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 095/143] fbdev: da8xx-fb: fix videomodes of lcd panels Willy Tarreau
2016-06-05 10:19 ` [PATCH 3.10 096/143] misc/bmp085: Enable building as a module Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 097/143] rtc: vr41xx: Wire up alarm_irq_enable Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 098/143] drivers/misc/ad525x_dpot: AD5274 fix RDAC read back errors Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 099/143] include/linux/poison.h: fix LIST_POISON{1,2} offset Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 100/143] Drivers: hv: vmbus: prevent cpu offlining on newer hypervisors Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 101/143] perf stat: Document --detailed option Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 102/143] ARM: OMAP3: Add cpuidle parameters table for omap3430 Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 103/143] compiler-gcc: disable -ftracer for __noclone functions Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 104/143] ipvs: correct initial offset of Call-ID header search in SIP persistence engine Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 105/143] nbd: ratelimit error msgs after socket close Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 106/143] clk: versatile: sp810: support reentrance Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 107/143] lpfc: fix misleading indentation Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 108/143] ARM: SoCFPGA: Fix secondary CPU startup in thumb2 kernel Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 109/143] proc: prevent accessing /proc/<PID>/environ until it's ready Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 110/143] batman-adv: Fix broadcast/ogm queue limit on a removed interface Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 111/143] MAINTAINERS: Remove asterisk from EFI directory names Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 112/143] ACPICA: Dispatcher: Update thread ID for recursive method calls Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 113/143] USB: serial: cp210x: add ID for Link ECU Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 114/143] USB: serial: cp210x: add Straizona Focusers device ids Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 115/143] Input: ads7846 - correct the value got from SPI Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 116/143] powerpc: scan_features() updates incorrect bits for REAL_LE Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 117/143] crypto: hash - Fix page length clamping in hash walk Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 118/143] get_rock_ridge_filename(): handle malformed NM entries Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 119/143] Input: max8997-haptic - fix NULL pointer dereference Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 120/143] asmlinkage, pnp: Make variables used from assembler code visible Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 121/143] ARM: OMAP3: Fix booting with thumb2 kernel Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 122/143] decnet: Do not build routes to devices without decnet private data Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 123/143] route: do not cache fib route info on local routes with oif Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 124/143] packet: fix heap info leak in PACKET_DIAG_MCLIST sock_diag interface Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 125/143] atl2: Disable unimplemented scatter/gather feature Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 126/143] net: fix infoleak in llc Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 127/143] net: fix infoleak in rtnetlink Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 128/143] VSOCK: do not disconnect socket when peer has shutdown SEND only Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 129/143] net: bridge: fix old ioctl unlocked net device walk Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 130/143] net: fix a kernel infoleak in x25 module Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 131/143] fs/cifs: correctly to anonymous authentication via NTLMSSP Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 132/143] ring-buffer: Use long for nr_pages to avoid overflow failures Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 133/143] ring-buffer: Prevent overflow of size in ring_buffer_resize() Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 134/143] mfd: omap-usb-tll: Fix scheduling while atomic BUG Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 135/143] mmc: mmc: Fix partition switch timeout for some eMMCs Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 136/143] mmc: longer timeout for long read time quirk Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 137/143] Bluetooth: vhci: purge unhandled skbs Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 138/143] USB: serial: keyspan: fix use-after-free in probe error path Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 139/143] USB: serial: quatech2: " Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 140/143] USB: serial: io_edgeport: fix memory leaks " Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 141/143] USB: serial: option: add support for Cinterion PH8 and AHxx Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 142/143] tty: vt, return error when con_startup fails Willy Tarreau
2016-06-05 10:20 ` [PATCH 3.10 143/143] serial: samsung: Reorder the sequence of clock control when call s3c24xx_serial_set_termios() Willy Tarreau
2016-06-07  3:46 ` [PATCH 3.10 000/143] 3.10.102-stable review Guenter Roeck
2016-06-07  4:09   ` Willy Tarreau
2016-06-07  4:30     ` Guenter Roeck
2016-06-07  5:17       ` Willy Tarreau
2016-06-07  5:59         ` Guenter Roeck
2016-06-07  6:54           ` Willy Tarreau
2016-06-07 17:49             ` Willy Tarreau
2016-06-07 18:21               ` Guenter Roeck
2016-06-08  0:52               ` Guenter Roeck
2016-06-08  5:19                 ` Willy Tarreau

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1465122046-9645-71-git-send-email-w@1wt.eu \
    --to=w@1wt.eu \
    --cc=davem@davemloft.net \
    --cc=g.nault@alphalink.fr \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®