From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
Jonathan Nieder <jrnieder@gmail.com>,
Heiko Carstens <heiko.carstens@de.ibm.com>,
Martin Schwidefsky <schwidefsky@de.ibm.com>
Subject: [34/55] [S390] pfault: fix token handling
Date: Fri, 29 Apr 2011 11:55:57 -0700 [thread overview]
Message-ID: <20110429185655.869230858@clark.kroah.org> (raw)
In-Reply-To: <20110429185706.GA12824@kroah.com>
2.6.38-stable review patch. If anyone has any objections, please let us know.
------------------
From: Heiko Carstens <heiko.carstens@de.ibm.com>
commit e35c76cd47c244eaa7a74adaabde4d0a1cadb907 upstream.
f6649a7e "[S390] cleanup lowcore access from external interrupts" changed
handling of external interrupts. Instead of letting the external interrupt
handlers accessing the per cpu lowcore the entry code of the kernel reads
already all fields that are necessary and passes them to the handlers.
The pfault interrupt handler was incorrectly converted. It tries to
dereference a value which used to be a pointer to a lowcore field. After
the conversion however it is not anymore the pointer to the field but its
content. So instead of a dereference only a cast is needed to get the
task pointer that caused the pfault.
Fixes a NULL pointer dereference and a subsequent kernel crash:
Unable to handle kernel pointer dereference at virtual kernel address (null)
Oops: 0004 [#1] SMP
Modules linked in: nfsd exportfs nfs lockd fscache nfs_acl auth_rpcgss sunrpc
loop qeth_l3 qeth vmur ccwgroup ext3 jbd mbcache dm_mod
dasd_eckd_mod dasd_diag_mod dasd_mod
CPU: 0 Not tainted 2.6.38-2-s390x #1
Process cron (pid: 1106, task: 000000001f962f78, ksp: 000000001fa0f9d0)
Krnl PSW : 0404200180000000 000000000002c03e (pfault_interrupt+0xa2/0x138)
R:0 T:1 IO:0 EX:0 Key:0 M:1 W:0 P:0 AS:0 CC:2 PM:0 EA:3
Krnl GPRS: 0000000000000000 0000000000000001 0000000000000000 0000000000000001
000000001f962f78 0000000000518968 0000000090000002 000000001ff03280
0000000000000000 000000000064f000 000000001f962f78 0000000000002603
0000000006002603 0000000000000000 000000001ff7fe68 000000001ff7fe48
Krnl Code: 000000000002c036: 5820d010 l %r2,16(%r13)
000000000002c03a: 1832 lr %r3,%r2
000000000002c03c: 1a31 ar %r3,%r1
>000000000002c03e: ba23d010 cs %r2,%r3,16(%r13)
000000000002c042: a744fffc brc 4,2c03a
000000000002c046: a7290002 lghi %r2,2
000000000002c04a: e320d0000024 stg %r2,0(%r13)
000000000002c050: 07f0 bcr 15,%r0
Call Trace:
([<000000001f962f78>] 0x1f962f78)
[<000000000001acda>] do_extint+0xf6/0x138
[<000000000039b6ca>] ext_no_vtime+0x30/0x34
[<000000007d706e04>] 0x7d706e04
Last Breaking-Event-Address:
[<0000000000000000>] 0x0
For stable maintainers:
the first kernel which contains this bug is 2.6.37.
Reported-by: Stephen Powell <zlinuxman@wowway.com>
Cc: Jonathan Nieder <jrnieder@gmail.com>
Signed-off-by: Heiko Carstens <heiko.carstens@de.ibm.com>
Signed-off-by: Martin Schwidefsky <schwidefsky@de.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
---
arch/s390/mm/fault.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/arch/s390/mm/fault.c
+++ b/arch/s390/mm/fault.c
@@ -558,9 +558,9 @@ static void pfault_interrupt(unsigned in
* Get the token (= address of the task structure of the affected task).
*/
#ifdef CONFIG_64BIT
- tsk = *(struct task_struct **) param64;
+ tsk = (struct task_struct *) param64;
#else
- tsk = *(struct task_struct **) param32;
+ tsk = (struct task_struct *) param32;
#endif
if (subcode & 0x0080) {
next prev parent reply other threads:[~2011-04-29 19:03 UTC|newest]
Thread overview: 62+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-04-29 18:57 [00/55] 2.6.38.5-stable review Greg KH
2011-04-29 18:55 ` [01/55] ath9k_hw: fix stopping rx DMA during resets Greg KH
2011-04-29 18:55 ` [02/55] netxen: limit skb frags for non tso packet Greg KH
2011-04-29 18:55 ` [03/55] ath: add missing regdomain pair 0x5c mapping Greg KH
2011-04-29 18:55 ` [04/55] block, blk-sysfs: Fix an err return path in blk_register_queue() Greg KH
2011-04-29 18:55 ` [05/55] p54: Initialize extra_len in p54_tx_80211 Greg KH
2011-04-29 18:55 ` [06/55] qlcnic: limit skb frags for non tso packet Greg KH
2011-04-29 18:55 ` [07/55] nfsd4: fix struct file leak on delegation Greg KH
2011-04-29 18:55 ` [08/55] nfsd4: Fix filp leak Greg KH
2011-04-29 18:55 ` [09/55] virtio: Decrement avail idx on buffer detach Greg KH
2011-04-29 18:55 ` [10/55] x86, gart: Set DISTLBWALKPRB bit always Greg KH
2011-04-29 18:55 ` [11/55] x86, gart: Make sure GART does not map physmem above 1TB Greg KH
2011-04-29 18:55 ` [12/55] intel-iommu: Fix use after release during device attach Greg KH
2011-04-29 18:55 ` [13/55] intel-iommu: Unlink domain from iommu Greg KH
2011-04-29 18:55 ` [14/55] intel-iommu: Fix get_domain_for_dev() error path Greg KH
2011-04-29 18:55 ` [15/55] drm/radeon/kms: pll tweaks for r7xx Greg KH
2011-04-29 18:55 ` [16/55] drm/nouveau: fix notifier memory corruption bug Greg KH
2011-04-29 18:55 ` [17/55] drm/radeon/kms: fix bad shift in atom iio table parser Greg KH
2011-04-29 18:55 ` [18/55] drm/i915: Sanitize the output registers after resume Greg KH
2011-04-29 18:55 ` [19/55] drm/i915/tv: Remember the detected TV type Greg KH
2011-04-29 18:55 ` [20/55] tty/n_gsm: fix bug in CRC calculation for gsm1 mode Greg KH
2011-04-29 18:55 ` [21/55] serial/imx: read cts state only after acking cts change irq Greg KH
2011-04-29 18:55 ` [22/55] ASoC: Fix output PGA enabling in wm_hubs CODECs Greg KH
2011-04-29 18:55 ` [23/55] ASoC: codecs: JZ4740: Fix OOPS Greg KH
2011-04-29 18:55 ` [24/55] ALSA: hda - Add a fix-up for Acer dmic with ALC271x codec Greg KH
2011-04-29 18:55 ` [25/55] ahci: dont enable port irq before handler is registered Greg KH
2011-04-29 18:55 ` [26/55] libata: Implement ATA_FLAG_NO_DIPM and apply it to mcp65 Greg KH
2011-04-29 18:55 ` [27/55] kconfig: Avoid buffer underrun in choice input Greg KH
2011-04-29 18:55 ` [28/55] UBIFS: fix master node recovery Greg KH
2011-04-29 18:55 ` [29/55] ideapad: read brightness setting on brightness key notify Greg KH
2011-04-29 18:55 ` [30/55] ACPI battery: fribble sysfs files from a resume notifier Greg KH
2011-04-29 18:55 ` [31/55] ath9k_hw: partially revert "fix dma descriptor rx error bit parsing" Greg KH
2011-04-29 18:55 ` [32/55] UBIFS: fix false space checking failure Greg KH
2011-04-29 18:55 ` [33/55] [S390] kvm-390: Let kernel exit SIE instruction on work Greg KH
2011-04-29 18:55 ` Greg KH [this message]
2011-04-29 18:55 ` [35/55] ACPI / PM: Avoid infinite recurrence while registering power resources Greg KH
2011-04-29 18:55 ` [36/55] [PARISC] slub: fix panic with DISCONTIGMEM Greg KH
2011-05-02 20:04 ` [Stable-review] " Ben Hutchings
2011-05-02 21:44 ` Michael Schmitz
2011-05-03 22:46 ` David Rientjes
2011-05-03 23:17 ` Ben Hutchings
2011-05-03 23:20 ` James Bottomley
2011-05-03 23:57 ` David Rientjes
2011-04-29 18:56 ` [37/55] [PARISC] set memory ranges in N_NORMAL_MEMORY when onlined Greg KH
2011-04-29 18:56 ` [38/55] [media] FLEXCOP-PCI: fix __xlate_proc_name-warning for flexcop-pci Greg KH
2011-04-29 18:56 ` [39/55] virtio: console: Enable call to hvc_remove() on console port remove Greg KH
2011-04-29 18:56 ` [40/55] oom: use pte pages in OOM score Greg KH
2011-04-29 18:56 ` [41/55] mm: check if PTE is already allocated during page fault Greg KH
2011-04-29 18:56 ` [42/55] mm: thp: fix /dev/zero MAP_PRIVATE and vm_flags cleanups Greg KH
2011-04-29 18:56 ` [43/55] m68k/mm: Set all online nodes in N_NORMAL_MEMORY Greg KH
2011-04-29 18:56 ` [44/55] vfs: avoid large kmalloc()s for the fdtable Greg KH
2011-04-29 18:56 ` [45/55] nfs: dont lose MS_SYNCHRONOUS on remount of noac mount Greg KH
2011-04-29 18:56 ` [46/55] NFSv4.1: Ensure state manager thread dies on last umount Greg KH
2011-04-29 18:56 ` [47/55] um: mdd support for 64 bit atomic operations Greg KH
2011-04-29 18:56 ` [48/55] drm: select FRAMEBUFFER_CONSOLE_PRIMARY if we have FRAMEBUFFER_CONSOLE Greg KH
2011-04-29 18:56 ` [49/55] agp: fix arbitrary kernel memory writes Greg KH
2011-04-29 18:56 ` [50/55] agp: fix OOM and buffer overflow Greg KH
2011-04-29 18:56 ` [51/55] iwlwifi: do not set tx power when channel is changing Greg KH
2011-04-29 18:56 ` [52/55] iwl3945: do not deprecate software scan Greg KH
2011-04-29 18:56 ` [53/55] iwl3945: disable hw scan by default Greg KH
2011-04-29 18:56 ` [54/55] iwlegacy: fix tx_power initialization Greg KH
2011-04-29 18:56 ` [55/55] Input: xen-kbdfront - fix mouse getting stuck after save/restore Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20110429185655.869230858@clark.kroah.org \
--to=gregkh@suse.de \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=heiko.carstens@de.ibm.com \
--cc=jrnieder@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=schwidefsky@de.ibm.com \
--cc=stable-review@kernel.org \
--cc=stable@kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®