* [3.8.y.z extended stable] Linux 3.8.13.14 stable review
@ 2013-12-06 23:08 Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 001/152] ipv6: ip6_dst_check needs to check for expired dst_entries Kamal Mostafa
` (151 more replies)
0 siblings, 152 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Kamal Mostafa
This is the start of the review cycle for the Linux 3.8.13.14 stable kernel.
This version contains 152 new patches, summarized below. The new patches are
posted as replies to this message and also available in this git branch:
http://kernel.ubuntu.com/git?p=ubuntu/linux.git;h=linux-3.8.y-review;a=shortlog
git://kernel.ubuntu.com/ubuntu/linux.git linux-3.8.y-review
The review period for version 3.8.13.14 will be open for the next three days.
To report a problem, please reply to the relevant follow-up patch message.
For more information about the Linux 3.8.y.z extended stable kernel version,
see https://wiki.ubuntu.com/Kernel/Dev/ExtendedStable .
-Kamal
--
Documentation/sysctl/kernel.txt | 25 ++--
arch/arm/kernel/entry-armv.S | 46 +------
arch/arm/kernel/entry-header.S | 38 +++++-
arch/arm/mach-integrator/integrator_cp.c | 3 +-
arch/arm/mach-omap2/irq.c | 2 +-
arch/arm/mach-omap2/omap_device.c | 19 ++-
arch/arm/mach-sa1100/assabet.c | 3 +
arch/arm/mm/extable.c | 7 +-
arch/avr32/boot/u-boot/head.S | 35 +++++-
arch/avr32/kernel/entry-avr32b.S | 3 +-
arch/avr32/kernel/head.S | 20 ---
arch/cris/include/asm/io.h | 1 +
arch/ia64/include/asm/processor.h | 2 +-
arch/powerpc/kernel/signal_32.c | 10 +-
arch/powerpc/kernel/time.c | 4 +-
arch/powerpc/kernel/vio.c | 4 +-
arch/powerpc/platforms/powernv/pci-ioda.c | 12 +-
arch/s390/kernel/smp.c | 4 +-
arch/s390/kernel/vtime.c | 2 +-
arch/x86/include/asm/apic.h | 2 +
arch/x86/kernel/apic/io_apic.c | 5 +
arch/x86/kernel/crash.c | 6 +-
arch/x86/kernel/ftrace.c | 14 ++-
arch/x86/kernel/microcode_amd.c | 2 +-
arch/x86/kernel/reboot.c | 8 +-
arch/x86/kvm/emulate.c | 5 +-
block/blk-core.c | 5 +-
block/blk-settings.c | 1 +
block/blk-timeout.c | 3 +-
crypto/asymmetric_keys/x509_public_key.c | 38 ------
drivers/acpi/ec.c | 3 +-
drivers/ata/ahci.c | 4 +
drivers/ata/libahci.c | 16 +++
drivers/ata/libata-core.c | 1 +
drivers/ata/libata-transport.c | 16 +--
drivers/block/brd.c | 2 +-
drivers/block/loop.c | 21 ++--
drivers/block/xen-blkback/blkback.c | 3 +-
drivers/edac/highbank_l2_edac.c | 18 +--
drivers/edac/highbank_mc_edac.c | 18 +--
drivers/gpu/drm/i915/intel_display.c | 4 +
drivers/gpu/drm/nouveau/nouveau_gem.c | 3 +-
drivers/gpu/drm/radeon/atombios_crtc.c | 2 +-
drivers/gpu/drm/radeon/atombios_i2c.c | 5 +-
drivers/gpu/drm/radeon/radeon_legacy_crtc.c | 28 +++++
drivers/gpu/drm/radeon/radeon_semaphore.c | 6 +-
drivers/gpu/drm/radeon/radeon_trace.h | 36 ++++++
drivers/gpu/drm/radeon/sid.h | 2 +-
drivers/gpu/drm/shmobile/Kconfig | 1 +
drivers/gpu/drm/ttm/ttm_bo.c | 32 +++--
drivers/gpu/drm/ttm/ttm_bo_util.c | 30 +++--
drivers/gpu/drm/vmwgfx/vmwgfx_resource.c | 41 +++++-
drivers/hwmon/lm90.c | 11 +-
drivers/i2c/muxes/i2c-mux-gpio.c | 8 +-
drivers/infiniband/hw/ipath/ipath_user_sdma.c | 7 +-
drivers/infiniband/hw/qib/qib_iba7322.c | 11 +-
drivers/infiniband/ulp/srp/ib_srp.c | 20 +--
drivers/md/dm-mpath.c | 18 ++-
drivers/md/dm-table.c | 18 ++-
drivers/md/md.c | 1 +
drivers/mtd/devices/m25p80.c | 20 ++-
drivers/mtd/nand/nand_base.c | 15 ++-
drivers/net/can/c_can/c_can.c | 6 +-
drivers/net/can/usb/kvaser_usb.c | 20 +--
drivers/net/ethernet/chelsio/cxgb3/sge.c | 3 +-
drivers/net/virtio_net.c | 13 +-
drivers/net/wireless/libertas/debugfs.c | 6 +-
drivers/net/wireless/mwifiex/sdio.c | 3 +
drivers/net/wireless/mwifiex/uap_txrx.c | 29 ++++-
drivers/net/wireless/prism54/islpci_dev.c | 7 +-
drivers/net/wireless/rt2x00/rt2400pci.c | 2 +-
drivers/net/wireless/rt2x00/rt2800usb.c | 12 +-
drivers/net/wireless/rt2x00/rt2x00dev.c | 3 +-
drivers/net/wireless/rt2x00/rt2x00lib.h | 2 +-
drivers/net/wireless/rt2x00/rt2x00mac.c | 7 +-
drivers/net/wireless/rt2x00/rt2x00queue.c | 4 +-
drivers/net/wireless/rtlwifi/base.c | 89 ++++++-------
drivers/net/wireless/rtlwifi/rtl8192cu/mac.c | 6 +-
drivers/net/wireless/rtlwifi/rtl8192cu/trx.c | 8 +-
drivers/net/wireless/rtlwifi/rtl8192de/trx.c | 2 +-
drivers/net/wireless/rtlwifi/rtl8192se/rf.c | 2 +-
drivers/net/wireless/rtlwifi/wifi.h | 6 +-
drivers/net/xen-netback/common.h | 1 +
drivers/net/xen-netback/interface.c | 3 +-
drivers/net/xen-netback/netback.c | 10 +-
drivers/pci/pcie/portdrv_pci.c | 1 -
drivers/pinctrl/mvebu/pinctrl-dove.c | 2 +-
drivers/s390/net/qeth_core_main.c | 6 +-
drivers/scsi/sd.c | 5 +-
drivers/target/iscsi/iscsi_target_auth.c | 5 +-
drivers/target/iscsi/iscsi_target_nego.c | 2 +-
drivers/target/target_core_transport.c | 2 +
drivers/usb/core/hub.c | 11 ++
drivers/usb/musb/musb_core.c | 1 +
drivers/usb/serial/mos7840.c | 4 +
drivers/usb/serial/option.c | 17 +++
drivers/usb/wusbcore/wa-rpipe.c | 5 +-
drivers/usb/wusbcore/wa-xfer.c | 5 +-
drivers/video/backlight/atmel-pwm-bl.c | 10 +-
drivers/video/console/sticore.c | 166 ++++++++++++++----------
drivers/video/sticore.h | 62 +++++++--
drivers/video/stifb.c | 10 +-
fs/cifs/cifssmb.c | 8 +-
fs/configfs/dir.c | 16 ++-
fs/coredump.c | 2 +-
fs/devpts/inode.c | 1 +
fs/exec.c | 16 ++-
fs/ext4/xattr.c | 1 +
fs/nfs/nfs4proc.c | 4 +-
fs/nfsd/nfs4xdr.c | 3 +-
fs/nfsd/vfs.c | 173 +++++++++++++++-----------
fs/proc/internal.h | 3 +-
include/linux/binfmts.h | 3 -
include/linux/msg.h | 6 +-
include/linux/mtd/map.h | 4 +-
include/linux/sched.h | 7 +-
include/linux/vm_event_item.h | 1 +
include/net/ip6_fib.h | 1 +
ipc/msgutil.c | 116 +++++++++--------
ipc/util.h | 4 +-
kernel/audit.c | 17 +--
kernel/power/snapshot.c | 6 +-
kernel/ptrace.c | 3 +-
kernel/sysctl.c | 2 +-
kernel/trace/trace_event_perf.c | 2 +-
lib/vsprintf.c | 33 ++++-
mm/huge_memory.c | 19 ++-
mm/mmap.c | 10 +-
mm/mprotect.c | 18 ++-
mm/vmstat.c | 1 +
net/core/flow_dissector.c | 2 +-
net/ipv6/route.c | 9 +-
net/sunrpc/clnt.c | 34 ++---
net/sunrpc/rpc_pipe.c | 2 +-
net/sunrpc/xprtsock.c | 28 +++--
net/wireless/scan.c | 4 +-
security/integrity/ima/ima_policy.c | 1 -
security/selinux/netlabel.c | 6 +-
sound/drivers/pcsp/pcsp.c | 2 +-
sound/isa/msnd/msnd_pinnacle.c | 4 +-
sound/pci/hda/hda_codec.c | 7 +-
sound/pci/hda/hda_intel.c | 10 +-
sound/pci/hda/patch_conexant.c | 3 +
sound/pci/hda/patch_realtek.c | 60 +++++++++
sound/soc/blackfin/bf5xx-i2s.c | 1 +
sound/soc/codecs/ak4642.c | 2 +-
sound/soc/codecs/cs42l52.h | 2 +-
sound/soc/codecs/wm5110.c | 43 ++++++-
sound/soc/codecs/wm8962.c | 2 +
sound/soc/fsl/imx-pcm-fiq.c | 29 +++--
sound/usb/6fire/chip.c | 2 +-
virt/kvm/iommu.c | 4 +
virt/kvm/kvm_main.c | 19 +--
153 files changed, 1343 insertions(+), 721 deletions(-)
Aaron Lu (1):
PM / hibernate: Avoid overflow in hibernate_preallocate_memory()
Akira Takeuchi (1):
mm: ensure get_unmapped_area() returns higher address than mmap_min_addr
Alex Deucher (2):
drm/radeon/si: fix define for MC_SEQ_TRAIN_WAKEUP_CNTL
drm/radeon: don't share PPLLs on DCE4.1
Alex Williamson (1):
KVM: Fix iommu map/unmap to handle memory slot moves
Andreas Bießmann (2):
avr32: setup crt for early panic()
avr32: fix out-of-range jump in large kernels
Anton Blanchard (1):
powerpc/pseries: Duplicate dtl entries sometimes sent to userspace
Avinash Patil (1):
mwifiex: correct packet length for packets from SDIO interface
Bart Van Assche (2):
IB/srp: Avoid offlining operational SCSI devices
IB/srp: Report receive errors correctly
Ben Hutchings (1):
cxgb3: Fix length calculation in write_ofld_wr() on 32-bit architectures
Ben Skeggs (1):
drm/nouveau: when bailing out of a pushbuf ioctl, do not remove previous fence
Bernd Schubert (1):
[SCSI] sd: Reduce buffer size for vpd request
Brian Austin (1):
ASoC: cs42l52: Correct MIC CTL mask
Brian Norris (2):
mtd: nand: hack ONFI for non-power-of-2 dimensions
mtd: m25p80: fix allocation size
Charles Keepax (1):
ASoC: wm5110: Add post SYSCLK register patch for rev D chip
Christian König (1):
drm/radeon: add semaphore trace point
Christoph Hellwig (2):
nfsd: split up nfsd_setattr
nfsd: make sure to balance get/put_write_access
Dan Carpenter (1):
libertas: potential oops in debugfs
Dan Williams (1):
prism54: set netdev type to "wlan"
Daniel Vetter (1):
drm/i915: flush cursors harder
David Howells (1):
X.509: Remove certificate date checks
Eric Seppanen (2):
iscsi-target: fix extract_param to handle buffer length corner case
iscsi-target: chap auth shouldn't match username with trailing garbage
Felipe Pena (1):
rtlwifi: rtl8192se: Fix wrong assignment
Felix Fietkau (1):
rt2x00: fix a crash bug in the HT descriptor handling fix
Fenghua Yu (1):
x86/apic: Disable I/O APIC before shutdown of the local APIC
Gavin Shan (1):
powerpc/powernv: Add PE to its own PELTV
Greg Edwards (1):
KVM: IOMMU: hva align mapping page size
Guenter Roeck (1):
hwmon: (lm90) Fix max6696 alarm handling
Gwendal Grignou (1):
libata: Fix display of sata speed
Hannes Frederic Sowa (2):
ipv6: ip6_dst_check needs to check for expired dst_entries
ipv6: reset dst.expires value when clearing expire flag
Helge Deller (1):
parisc: sticon - unbreak on 64bit kernel
Ilija Hadzic (1):
devpts: plug the memory leak in kill_sb
Ionut Nicu (2):
i2c: mux: gpio: use gpio_set_value_cansleep()
i2c: mux: gpio: use reg value for i2c_add_mux_adapter
J. Bruce Fields (1):
nfsd4: fix xdr decoding of large non-write compounds
Jakob Bornecrantz (1):
drm/ttm: Handle in-memory region copies
James Ralston (1):
ahci: Add Device IDs for Intel Wildcat Point-LP
Jan Kara (1):
IB/ipath: Convert ipath_user_sdma_pin_pages() to use get_user_pages_fast()
Jason Wang (2):
virtio-net: correctly handle cpu hotplug notifier during resuming
net: flow_dissector: fail on evil iph->ihl
Jeff Moyer (1):
block: fix race between request completion and timeout handling
Jerome Glisse (2):
radeon/i2c: do not count reg index in number of i2c byte we are writing.
radeon: workaround pinning failure on low ram gpu
Johan Hovold (3):
USB: mos7840: fix tiocmget error handling
backlight: atmel-pwm-bl: fix reported brightness
backlight: atmel-pwm-bl: fix gpio polarity in remove
Johannes Berg (1):
cfg80211: fix scheduled scan pointer access
Jonathan Austin (1):
ARM: integrator_cp: Set LCD{0,1} enable lines when turning on CLCD
Julius Werner (1):
usb: hub: Clear Port Reset Change during init/resume
Junxiao Bi (1):
configfs: fix race between dentry put and lookup
Kailang Yang (2):
ALSA: hda - Add support of new codec ALC233
ALSA: hda - Add support of ALC255 codecs
Kees Cook (2):
coredump: remove redundant defines for dumpable states
exec/ptrace: fix get_dumpable() incorrect tests
Kevin Hao (1):
ftrace/x86: skip over the breakpoint for ftrace caller
Larry Finger (3):
rtlwifi: rtl8192cu: Fix incorrect signal strength for unassociated AP
rtlwifi: rtl8192de: Fix incorrect signal strength for unassociated AP
rtlwifi: rtl8192cu: Fix more pointer arithmetic errors
Laurent Pinchart (1):
drm: shmobile: Add dependency on BACKLIGHT_CLASS_DEVICE
Marc Zyngier (1):
ARM: 7876/1: clear Thumb-2 IT state on exception handling
Mark Cave-Ayland (1):
rtlwifi: Fix endian error in extracting packet type
Markus Pargmann (2):
ARM: OMAP2+: irq, AM33XX add missing register check
can: c_can: Fix RX message handling, handle lost message before EOB
Martin Schwidefsky (1):
s390/vtime: correct idle time calculation
Mathias Krause (3):
audit: fix info leak in AUDIT_GET requests
audit: use nlmsg_len() to get message payload length
ipc, msg: fix message length check for negative values
Mauro Carvalho Chehab (1):
cris: media platform drivers: fix build
Mel Gorman (2):
mm: Only flush TLBs if a transhuge PMD is modified for NUMA pte scanning
mm: numa: return the number of base pages altered by protection changes
Michael Neuling (1):
powerpc/signals: Mark VSX not saved with small contexts
Mike Marciniszyn (1):
IB/qib: Fix txselect regression
Mike Snitzer (1):
block: properly stack underlying max_segment_size to DM device
Mikulas Patocka (5):
dm: allocate buffer for messages with small number of arguments using GFP_NOIO
blk-core: Fix memory corruption if blkcg_init_queue fails
loop: fix crash if blk_alloc_queue fails
block: fix a probe argument to blk_register_region
loop: fix crash when using unassigned loop device
Mimi Zohar (1):
Revert "ima: policy for RAMFS"
NeilBrown (1):
md: fix calculation of stacking limits on level change.
Nicholas Bellinger (1):
target: Fix delayed Task Aborted Status (TAS) handling bug
Nicolin Chen (1):
ASoC: wm8962: Turn on regcache_cache_only before disabling regulator
Nishanth Menon (1):
ARM: OMAP2+: omap_device: maintain sane runtime pm status around suspend/resume
Olivier Sobrie (1):
can: kvaser_usb: fix usb endpoints detection
Oskar Schirmer (1):
ASoC: fsl: imx-pcm-fiq: omit fiq counter to avoid harm in unbalanced situations
Paolo Bonzini (1):
KVM: x86: fix emulation of "movzbl %bpl, %eax"
Paul Moore (1):
selinux: correct locking in selinux_netlbl_socket_connect)
Peter Hurley (4):
ipc: clamp with min()
ipc: separate msg allocation from userspace copy
ipc: tighten msg copy loops
ipc: set EFAULT as default error in load_msg()
Phil Edworthy (1):
ASoC: ak4642: prevent un-necessary changes to SG_SL1
Prarit Bhargava (1):
powerpc/vio: use strcpy in modalias_show
Puneet Kumar (1):
ACPI / EC: Ensure lock is acquired before accessing ec struct members
Robert Richter (1):
edac, highbank: Fix interrupt setup of mem and l2 controller
Roel Kluin (1):
pinctrl: dove: unset twsi option3 for gconfig as well
Rui li (1):
USB:add new zte 3g-dongle's pid to option.c
Russell King (3):
ARM: sa11x0/assabet: ensure CS2 is configured appropriately
ARM: entry: move IRQ tracing exit into svc_exit
ARM: entry: move disable_irq_notrace into svc_exit
Ryan Mallon (1):
vsprintf: check real user/group id for %pK
Sarah Sharp (1):
usb: Disable USB 2.0 Link PM before device reset.
Sebastian Andrzej Siewior (1):
usb: musb: cancel work on removal
Shan Hai (1):
drivers/libata: Set max sector to 65535 for Slimtype DVD A DS8A9SH drive
Shiva Krishna Merla (1):
dm mpath: fix race condition between multipath_dtr and pg_init_done
Stanislav Kinsbursky (1):
SUNRPC: fix races on PipeFS UMOUNT notifications
Stanislaw Gruszka (4):
rt2400pci: fix RSSI read
rt2x00: check if device is still available on rt2x00mac_flush()
rt2800usb: slow down TX status polling
rt2x00: fix HT TX descriptor settings regression
Steve French (1):
setfacl removes part of ACL when setting POSIX ACLs to Samba
Steven Rostedt (1):
perf/ftrace: Fix paranoid level for enabling function tracer
Takashi Iwai (12):
ALSA: 6fire: Fix probe of multiple cards
ALSA: hda - Enable SPDIF for Acer TravelMate 6293
ALSA: hda - Force buffer alignment for Haswell HDMI controllers
ALSA: hda - Add support for CX20952
ALSA: hda - Add pincfg fixup for ASUS W5A
ALSA: msnd: Avoid duplicated driver name
ALSA: hda - Don't clear the power state at snd_hda_codec_reset()
ASoC: blackfin: Fix missing break
ALSA: pcsp: Fix the order of input device unregistration
ALSA: hda - Fix unbalanced runtime PM notification at resume
ALSA: hda - Fix the headphone jack detection on Sony VAIO TX
ALSA: hda - Provide missing pin configs for VAIO with ALC260
Theodore Ts'o (1):
ext4: avoid bh leak in retry path of ext4_expand_extra_isize_ea()
Thomas Hellstrom (3):
drm/ttm: Fix ttm_bo_move_memcpy
drm/ttm: Fix memory type compatibility check
drm/vmwgfx: Resource evict fixes
Thomas Pugliese (2):
usb: wusbcore: set the RPIPE wMaxPacketSize value correctly
usb: wusbcore: change WA_SEGS_MAX to a legal value
Thomas Renninger (1):
x86/microcode/amd: Tone down printk(), don't treat a missing firmware file as an error
Trond Myklebust (3):
NFSv4: Fix a use-after-free situation in _nfs4_proc_getlk()
SUNRPC: Fix a data corruption issue when retransmitting RPC calls
SUNRPC: Avoid deep recursion in rpc_release_client
Tyler Hicks (1):
audit: printk USER_AVC messages when audit isn't enabled
Ujjal Roy (1):
mwifiex: fix wrong eth_hdr usage for bridged packets in AP mode
Ursula Braun (1):
qeth: avoid buffer overflow in snmp ioctl
Vegard Nossum (1):
xen/blkback: fix reference counting
Vu Pham (1):
IB/srp: Remove target from list before freeing Scsi_Host structure
Wang Haitao (1):
mtd: map: fixed bug in 64-bit systems
Wang Xingchao (1):
ALSA - HDA: New PCI ID for Haswell ULT
Wei Liu (1):
xen-netback: use jiffies_64 value to calculate credit timeout
Weston Andros Adamson (1):
NFSv4: fix NULL dereference in open recover
Yinghai Lu (1):
PCI: Remove duplicate pci_disable_device() from pcie_portdrv_remove()
Yoshihiro YUNOMAE (1):
x86/ioapic/kcrash: Prevent crash_kexec() from deadlocking on ioapic_lock
xiangliang yu (1):
ahci: disabled FBS prior to issuing software reset
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 001/152] ipv6: ip6_dst_check needs to check for expired dst_entries
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 002/152] ipv6: reset dst.expires value when clearing expire flag Kamal Mostafa
` (150 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: YOSHIFUJI Hideaki, Hannes Frederic Sowa, David S. Miller, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Hannes Frederic Sowa <hannes@stressinduktion.org>
[ Upstream commit e3bc10bd95d7fcc3f2ac690c6ff22833ea6781d6 ]
On receiving a packet too big icmp error we check if our current cached
dst_entry in the socket is still valid. This validation check did not
care about the expiration of the (cached) route.
The error path I traced down:
The socket receives a packet too big mtu notification. It still has a
valid dst_entry and thus issues the ip6_rt_pmtu_update on this dst_entry,
setting RTF_EXPIRE and updates the dst.expiration value (which could
fail because of not up-to-date expiration values, see previous patch).
In some seldom cases we race with a) the ip6_fib gc or b) another routing
lookup which would result in a recreation of the cached rt6_info from its
parent non-cached rt6_info. While copying the rt6_info we reinitialize the
metrics store by copying it over from the parent thus invalidating the
just installed pmtu update (both dsts use the same key to the inetpeer
storage). The dst_entry with the just invalidated metrics data would
just get its RTF_EXPIRES flag cleared and would continue to stay valid
for the socket.
We should have not issued the pmtu update on the already expired dst_entry
in the first placed. By checking the expiration on the dst entry and
doing a relookup in case it is out of date we close the race because
we would install a new rt6_info into the fib before we issue the pmtu
update, thus closing this race.
Not reliably updating the dst.expire value was fixed by the patch "ipv6:
reset dst.expires value when clearing expire flag".
Reported-by: Steinar H. Gunderson <sgunderson@bigfoot.com>
Reported-by: Valentijn Sessink <valentyn@blub.net>
Cc: YOSHIFUJI Hideaki <yoshfuji@linux-ipv6.org>
Signed-off-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Tested-by: Valentijn Sessink <valentyn@blub.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
net/ipv6/route.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/net/ipv6/route.c b/net/ipv6/route.c
index 2f01ab3..c9eb8eb 100644
--- a/net/ipv6/route.c
+++ b/net/ipv6/route.c
@@ -1086,10 +1086,13 @@ static struct dst_entry *ip6_dst_check(struct dst_entry *dst, u32 cookie)
if (rt->rt6i_genid != rt_genid(dev_net(rt->dst.dev)))
return NULL;
- if (rt->rt6i_node && (rt->rt6i_node->fn_sernum == cookie))
- return dst;
+ if (!rt->rt6i_node || (rt->rt6i_node->fn_sernum != cookie))
+ return NULL;
- return NULL;
+ if (rt6_check_expired(rt))
+ return NULL;
+
+ return dst;
}
static struct dst_entry *ip6_negative_advice(struct dst_entry *dst)
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 002/152] ipv6: reset dst.expires value when clearing expire flag
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 001/152] ipv6: ip6_dst_check needs to check for expired dst_entries Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 003/152] cxgb3: Fix length calculation in write_ofld_wr() on 32-bit architectures Kamal Mostafa
` (149 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: YOSHIFUJI Hideaki, Hannes Frederic Sowa, David S. Miller, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Hannes Frederic Sowa <hannes@stressinduktion.org>
[ Upstream commit 01ba16d6ec85a1ec4669c75513a76b61ec53ee50 ]
On receiving a packet too big icmp error we update the expire value by
calling rt6_update_expires. This function uses dst_set_expires which is
implemented that it can only reduce the expiration value of the dst entry.
If we insert new routing non-expiry information into the ipv6 fib where
we already have a matching rt6_info we only clear the RTF_EXPIRES flag
in rt6i_flags and leave the dst.expires value as is.
When new mtu information arrives for that cached dst_entry we again
call dst_set_expires. This time it won't update the dst.expire value
because we left the dst.expire value intact from the last update. So
dst_set_expires won't touch dst.expires.
Fix this by resetting dst.expires when clearing the RTF_EXPIRE flag.
dst_set_expires checks for a zero expiration and updates the
dst.expires.
In the past this (not updating dst.expires) was necessary because
dst.expire was placed in a union with the dst_entry *from reference
and rt6_clean_expires did assign NULL to it. This split happend in
ecd9883724b78cc72ed92c98bcb1a46c764fff21 ("ipv6: fix race condition
regarding dst->expires and dst->from").
Reported-by: Steinar H. Gunderson <sgunderson@bigfoot.com>
Reported-by: Valentijn Sessink <valentyn@blub.net>
Cc: YOSHIFUJI Hideaki <yoshfuji@linux-ipv6.org>
Acked-by: Eric Dumazet <edumazet@google.com>
Tested-by: Valentijn Sessink <valentyn@blub.net>
Signed-off-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
include/net/ip6_fib.h | 1 +
1 file changed, 1 insertion(+)
diff --git a/include/net/ip6_fib.h b/include/net/ip6_fib.h
index 28d27a6..90d7b4c 100644
--- a/include/net/ip6_fib.h
+++ b/include/net/ip6_fib.h
@@ -167,6 +167,7 @@ static inline struct inet6_dev *ip6_dst_idev(struct dst_entry *dst)
static inline void rt6_clean_expires(struct rt6_info *rt)
{
rt->rt6i_flags &= ~RTF_EXPIRES;
+ rt->dst.expires = 0;
}
static inline void rt6_set_expires(struct rt6_info *rt, unsigned long expires)
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 003/152] cxgb3: Fix length calculation in write_ofld_wr() on 32-bit architectures
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 001/152] ipv6: ip6_dst_check needs to check for expired dst_entries Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 002/152] ipv6: reset dst.expires value when clearing expire flag Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-07 0:10 ` Ben Hutchings
2013-12-06 23:08 ` [PATCH 3.8 004/152] xen-netback: use jiffies_64 value to calculate credit timeout Kamal Mostafa
` (148 subsequent siblings)
151 siblings, 1 reply; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Ben Hutchings, David S. Miller, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ben Hutchings <ben@decadent.org.uk>
[ Upstream commit 262e827fe745642589450ae241b7afd3912c3f25 ]
The length calculation here is now invalid on 32-bit architectures,
since sk_buff::tail is a pointer and sk_buff::transport_header is
an integer offset:
drivers/net/ethernet/chelsio/cxgb3/sge.c: In function 'write_ofld_wr':
drivers/net/ethernet/chelsio/cxgb3/sge.c:1603:9: warning: passing argument 4 of 'make_sgl' makes integer from pointer without a cast [enabled by default]
adap->pdev);
^
drivers/net/ethernet/chelsio/cxgb3/sge.c:964:28: note: expected 'unsigned int' but argument is of type 'sk_buff_data_t'
static inline unsigned int make_sgl(const struct sk_buff *skb,
^
Use the appropriate skb accessor functions.
Compile-tested only.
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Fixes: 1a37e412a022 ('net: Use 16bits for *_headers fields of struct skbuff')
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/ethernet/chelsio/cxgb3/sge.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/chelsio/cxgb3/sge.c b/drivers/net/ethernet/chelsio/cxgb3/sge.c
index dd901c5..ecae9bc 100644
--- a/drivers/net/ethernet/chelsio/cxgb3/sge.c
+++ b/drivers/net/ethernet/chelsio/cxgb3/sge.c
@@ -1600,7 +1600,8 @@ static void write_ofld_wr(struct adapter *adap, struct sk_buff *skb,
flits = skb_transport_offset(skb) / 8;
sgp = ndesc == 1 ? (struct sg_ent *)&d->flit[flits] : sgl;
sgl_flits = make_sgl(skb, sgp, skb_transport_header(skb),
- skb->tail - skb->transport_header,
+ skb_tail_pointer(skb) -
+ skb_transport_header(skb),
adap->pdev);
if (need_skb_unmap()) {
setup_deferred_unmapping(skb, adap->pdev, sgp, sgl_flits);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 004/152] xen-netback: use jiffies_64 value to calculate credit timeout
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (2 preceding siblings ...)
2013-12-06 23:08 ` [PATCH 3.8 003/152] cxgb3: Fix length calculation in write_ofld_wr() on 32-bit architectures Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 005/152] virtio-net: correctly handle cpu hotplug notifier during resuming Kamal Mostafa
` (147 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Wei Liu, Ian Campbell, Jason Luan, David S. Miller, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Wei Liu <wei.liu2@citrix.com>
[ Upstream commit 059dfa6a93b779516321e5112db9d7621b1367ba ]
time_after_eq() only works if the delta is < MAX_ULONG/2.
For a 32bit Dom0, if netfront sends packets at a very low rate, the time
between subsequent calls to tx_credit_exceeded() may exceed MAX_ULONG/2
and the test for timer_after_eq() will be incorrect. Credit will not be
replenished and the guest may become unable to send packets (e.g., if
prior to the long gap, all credit was exhausted).
Use jiffies_64 variant to mitigate this problem for 32bit Dom0.
Suggested-by: Jan Beulich <jbeulich@suse.com>
Signed-off-by: Wei Liu <wei.liu2@citrix.com>
Reviewed-by: David Vrabel <david.vrabel@citrix.com>
Cc: Ian Campbell <ian.campbell@citrix.com>
Cc: Jason Luan <jianhai.luan@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/xen-netback/common.h | 1 +
drivers/net/xen-netback/interface.c | 3 +--
drivers/net/xen-netback/netback.c | 10 +++++-----
3 files changed, 7 insertions(+), 7 deletions(-)
diff --git a/drivers/net/xen-netback/common.h b/drivers/net/xen-netback/common.h
index 1a28508..f2faa77 100644
--- a/drivers/net/xen-netback/common.h
+++ b/drivers/net/xen-netback/common.h
@@ -88,6 +88,7 @@ struct xenvif {
unsigned long credit_usec;
unsigned long remaining_credit;
struct timer_list credit_timeout;
+ u64 credit_window_start;
/* Statistics */
unsigned long rx_gso_checksum_fixup;
diff --git a/drivers/net/xen-netback/interface.c b/drivers/net/xen-netback/interface.c
index 2ef5ec9..c63cbd0 100644
--- a/drivers/net/xen-netback/interface.c
+++ b/drivers/net/xen-netback/interface.c
@@ -273,8 +273,7 @@ struct xenvif *xenvif_alloc(struct device *parent, domid_t domid,
vif->credit_bytes = vif->remaining_credit = ~0UL;
vif->credit_usec = 0UL;
init_timer(&vif->credit_timeout);
- /* Initialize 'expires' now: it's used to track the credit window. */
- vif->credit_timeout.expires = jiffies;
+ vif->credit_window_start = get_jiffies_64();
dev->netdev_ops = &xenvif_netdev_ops;
dev->hw_features = NETIF_F_SG | NETIF_F_IP_CSUM | NETIF_F_TSO;
diff --git a/drivers/net/xen-netback/netback.c b/drivers/net/xen-netback/netback.c
index f427455..d56fe61 100644
--- a/drivers/net/xen-netback/netback.c
+++ b/drivers/net/xen-netback/netback.c
@@ -1427,9 +1427,8 @@ out:
static bool tx_credit_exceeded(struct xenvif *vif, unsigned size)
{
- unsigned long now = jiffies;
- unsigned long next_credit =
- vif->credit_timeout.expires +
+ u64 now = get_jiffies_64();
+ u64 next_credit = vif->credit_window_start +
msecs_to_jiffies(vif->credit_usec / 1000);
/* Timer could already be pending in rare cases. */
@@ -1437,8 +1436,8 @@ static bool tx_credit_exceeded(struct xenvif *vif, unsigned size)
return true;
/* Passed the point where we can replenish credit? */
- if (time_after_eq(now, next_credit)) {
- vif->credit_timeout.expires = now;
+ if (time_after_eq64(now, next_credit)) {
+ vif->credit_window_start = now;
tx_add_credit(vif);
}
@@ -1450,6 +1449,7 @@ static bool tx_credit_exceeded(struct xenvif *vif, unsigned size)
tx_credit_callback;
mod_timer(&vif->credit_timeout,
next_credit);
+ vif->credit_window_start = next_credit;
return true;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 005/152] virtio-net: correctly handle cpu hotplug notifier during resuming
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (3 preceding siblings ...)
2013-12-06 23:08 ` [PATCH 3.8 004/152] xen-netback: use jiffies_64 value to calculate credit timeout Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 006/152] net: flow_dissector: fail on evil iph->ihl Kamal Mostafa
` (146 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Wanlong Gao, Rusty Russell, Michael S. Tsirkin, Jason Wang,
David S. Miller, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jason Wang <jasowang@redhat.com>
[ Upstream commit ec9debbd9a88d8ea86c488d6ffcac419ee7d46d9 ]
commit 3ab098df35f8b98b6553edc2e40234af512ba877 (virtio-net: don't respond to
cpu hotplug notifier if we're not ready) tries to bypass the cpu hotplug
notifier by checking the config_enable and does nothing is it was false. So it
need to try to hold the config_lock mutex which may happen in atomic
environment which leads the following warnings:
[ 622.944441] CPU0 attaching NULL sched-domain.
[ 622.944446] CPU1 attaching NULL sched-domain.
[ 622.944485] CPU0 attaching NULL sched-domain.
[ 622.950795] BUG: sleeping function called from invalid context at kernel/mutex.c:616
[ 622.950796] in_atomic(): 1, irqs_disabled(): 1, pid: 10, name: migration/1
[ 622.950796] no locks held by migration/1/10.
[ 622.950798] CPU: 1 PID: 10 Comm: migration/1 Not tainted 3.12.0-rc5-wl-01249-gb91e82d #317
[ 622.950799] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 622.950802] 0000000000000000 ffff88001d42dba0 ffffffff81a32f22 ffff88001bfb9c70
[ 622.950803] ffff88001d42dbb0 ffffffff810edb02 ffff88001d42dc38 ffffffff81a396ed
[ 622.950805] 0000000000000046 ffff88001d42dbe8 ffffffff810e861d 0000000000000000
[ 622.950805] Call Trace:
[ 622.950810] [<ffffffff81a32f22>] dump_stack+0x54/0x74
[ 622.950815] [<ffffffff810edb02>] __might_sleep+0x112/0x114
[ 622.950817] [<ffffffff81a396ed>] mutex_lock_nested+0x3c/0x3c6
[ 622.950818] [<ffffffff810e861d>] ? up+0x39/0x3e
[ 622.950821] [<ffffffff8153ea7c>] ? acpi_os_signal_semaphore+0x21/0x2d
[ 622.950824] [<ffffffff81565ed1>] ? acpi_ut_release_mutex+0x5e/0x62
[ 622.950828] [<ffffffff816d04ec>] virtnet_cpu_callback+0x33/0x87
[ 622.950830] [<ffffffff81a42576>] notifier_call_chain+0x3c/0x5e
[ 622.950832] [<ffffffff810e86a8>] __raw_notifier_call_chain+0xe/0x10
[ 622.950835] [<ffffffff810c5556>] __cpu_notify+0x20/0x37
[ 622.950836] [<ffffffff810c5580>] cpu_notify+0x13/0x15
[ 622.950838] [<ffffffff81a237cd>] take_cpu_down+0x27/0x3a
[ 622.950841] [<ffffffff81136289>] stop_machine_cpu_stop+0x93/0xf1
[ 622.950842] [<ffffffff81136167>] cpu_stopper_thread+0xa0/0x12f
[ 622.950844] [<ffffffff811361f6>] ? cpu_stopper_thread+0x12f/0x12f
[ 622.950847] [<ffffffff81119710>] ? lock_release_holdtime.part.7+0xa3/0xa8
[ 622.950848] [<ffffffff81135e4b>] ? cpu_stop_should_run+0x3f/0x47
[ 622.950850] [<ffffffff810ea9b0>] smpboot_thread_fn+0x1c5/0x1e3
[ 622.950852] [<ffffffff810ea7eb>] ? lg_global_unlock+0x67/0x67
[ 622.950854] [<ffffffff810e36b7>] kthread+0xd8/0xe0
[ 622.950857] [<ffffffff81a3bfad>] ? wait_for_common+0x12f/0x164
[ 622.950859] [<ffffffff810e35df>] ? kthread_create_on_node+0x124/0x124
[ 622.950861] [<ffffffff81a45ffc>] ret_from_fork+0x7c/0xb0
[ 622.950862] [<ffffffff810e35df>] ? kthread_create_on_node+0x124/0x124
[ 622.950876] smpboot: CPU 1 is now offline
[ 623.194556] SMP alternatives: lockdep: fixing up alternatives
[ 623.194559] smpboot: Booting Node 0 Processor 1 APIC 0x1
...
A correct fix is to unregister the hotcpu notifier during restore and register a
new one in resume.
Reported-by: Fengguang Wu <fengguang.wu@intel.com>
Tested-by: Fengguang Wu <fengguang.wu@intel.com>
Cc: Wanlong Gao <gaowanlong@cn.fujitsu.com>
Cc: Rusty Russell <rusty@rustcorp.com.au>
Cc: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Jason Wang <jasowang@redhat.com>
Acked-by: Michael S. Tsirkin <mst@redhat.com>
Reviewed-by: Wanlong Gao <gaowanlong@cn.fujitsu.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/virtio_net.c | 13 ++++++-------
1 file changed, 6 insertions(+), 7 deletions(-)
diff --git a/drivers/net/virtio_net.c b/drivers/net/virtio_net.c
index 848d26c..c3bcb4a 100644
--- a/drivers/net/virtio_net.c
+++ b/drivers/net/virtio_net.c
@@ -1076,11 +1076,6 @@ static int virtnet_cpu_callback(struct notifier_block *nfb,
{
struct virtnet_info *vi = container_of(nfb, struct virtnet_info, nb);
- mutex_lock(&vi->config_lock);
-
- if (!vi->config_enable)
- goto done;
-
switch(action & ~CPU_TASKS_FROZEN) {
case CPU_ONLINE:
case CPU_DOWN_FAILED:
@@ -1094,8 +1089,6 @@ static int virtnet_cpu_callback(struct notifier_block *nfb,
break;
}
-done:
- mutex_unlock(&vi->config_lock);
return NOTIFY_OK;
}
@@ -1650,6 +1643,8 @@ static int virtnet_freeze(struct virtio_device *vdev)
struct virtnet_info *vi = vdev->priv;
int i;
+ unregister_hotcpu_notifier(&vi->nb);
+
/* Prevent config work handler from accessing the device */
mutex_lock(&vi->config_lock);
vi->config_enable = false;
@@ -1696,6 +1691,10 @@ static int virtnet_restore(struct virtio_device *vdev)
virtnet_set_queues(vi, vi->curr_queue_pairs);
+ err = register_hotcpu_notifier(&vi->nb);
+ if (err)
+ return err;
+
return 0;
}
#endif
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 006/152] net: flow_dissector: fail on evil iph->ihl
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (4 preceding siblings ...)
2013-12-06 23:08 ` [PATCH 3.8 005/152] virtio-net: correctly handle cpu hotplug notifier during resuming Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 007/152] X.509: Remove certificate date checks Kamal Mostafa
` (145 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Eric Dumazet, Petr Matousek, Michael S. Tsirkin, Daniel Borkmann,
Jason Wang, David S. Miller, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jason Wang <jasowang@redhat.com>
[ Upstream commit 6f092343855a71e03b8d209815d8c45bf3a27fcd ]
We don't validate iph->ihl which may lead a dead loop if we meet a IPIP
skb whose iph->ihl is zero. Fix this by failing immediately when iph->ihl
is evil (less than 5).
This issue were introduced by commit ec5efe7946280d1e84603389a1030ccec0a767ae
(rps: support IPIP encapsulation).
Cc: Eric Dumazet <edumazet@google.com>
Cc: Petr Matousek <pmatouse@redhat.com>
Cc: Michael S. Tsirkin <mst@redhat.com>
Cc: Daniel Borkmann <dborkman@redhat.com>
Signed-off-by: Jason Wang <jasowang@redhat.com>
Acked-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
net/core/flow_dissector.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/core/flow_dissector.c b/net/core/flow_dissector.c
index 744b3ad..e2df3a9 100644
--- a/net/core/flow_dissector.c
+++ b/net/core/flow_dissector.c
@@ -36,7 +36,7 @@ again:
struct iphdr _iph;
ip:
iph = skb_header_pointer(skb, nhoff, sizeof(_iph), &_iph);
- if (!iph)
+ if (!iph || iph->ihl < 5)
return false;
if (ip_is_fragment(iph))
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 007/152] X.509: Remove certificate date checks
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (5 preceding siblings ...)
2013-12-06 23:08 ` [PATCH 3.8 006/152] net: flow_dissector: fail on evil iph->ihl Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 008/152] selinux: correct locking in selinux_netlbl_socket_connect) Kamal Mostafa
` (144 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: David Howells, David Woodhouse, Rusty Russell, Josh Boyer,
Alexander Holler, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: David Howells <dhowells@redhat.com>
commit 124df926090b32a998483f6e43ebeccdbe5b5302 upstream.
Remove the certificate date checks that are performed when a certificate is
parsed. There are two checks: a valid from and a valid to. The first check is
causing a lot of problems with system clocks that don't keep good time and the
second places an implicit expiry date upon the kernel when used for module
signing, so do we really need them?
Signed-off-by: David Howells <dhowells@redhat.com>
cc: David Woodhouse <dwmw2@infradead.org>
cc: Rusty Russell <rusty@rustcorp.com.au>
cc: Josh Boyer <jwboyer@redhat.com>
cc: Alexander Holler <holler@ahsoftware.de>
[ kamal: backport to 3.8 (context) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
crypto/asymmetric_keys/x509_public_key.c | 38 --------------------------------
1 file changed, 38 deletions(-)
diff --git a/crypto/asymmetric_keys/x509_public_key.c b/crypto/asymmetric_keys/x509_public_key.c
index 06007f0..52222a2 100644
--- a/crypto/asymmetric_keys/x509_public_key.c
+++ b/crypto/asymmetric_keys/x509_public_key.c
@@ -106,7 +106,6 @@ error_no_sig:
static int x509_key_preparse(struct key_preparsed_payload *prep)
{
struct x509_certificate *cert;
- struct tm now;
size_t srlen, sulen;
char *desc = NULL;
int ret;
@@ -137,43 +136,6 @@ static int x509_key_preparse(struct key_preparsed_payload *prep)
goto error_free_cert;
}
- time_to_tm(CURRENT_TIME.tv_sec, 0, &now);
- pr_devel("Now: %04ld-%02d-%02d %02d:%02d:%02d\n",
- now.tm_year + 1900, now.tm_mon + 1, now.tm_mday,
- now.tm_hour, now.tm_min, now.tm_sec);
- if (now.tm_year < cert->valid_from.tm_year ||
- (now.tm_year == cert->valid_from.tm_year &&
- (now.tm_mon < cert->valid_from.tm_mon ||
- (now.tm_mon == cert->valid_from.tm_mon &&
- (now.tm_mday < cert->valid_from.tm_mday ||
- (now.tm_mday == cert->valid_from.tm_mday &&
- (now.tm_hour < cert->valid_from.tm_hour ||
- (now.tm_hour == cert->valid_from.tm_hour &&
- (now.tm_min < cert->valid_from.tm_min ||
- (now.tm_min == cert->valid_from.tm_min &&
- (now.tm_sec < cert->valid_from.tm_sec
- ))))))))))) {
- pr_warn("Cert %s is not yet valid\n", cert->fingerprint);
- ret = -EKEYREJECTED;
- goto error_free_cert;
- }
- if (now.tm_year > cert->valid_to.tm_year ||
- (now.tm_year == cert->valid_to.tm_year &&
- (now.tm_mon > cert->valid_to.tm_mon ||
- (now.tm_mon == cert->valid_to.tm_mon &&
- (now.tm_mday > cert->valid_to.tm_mday ||
- (now.tm_mday == cert->valid_to.tm_mday &&
- (now.tm_hour > cert->valid_to.tm_hour ||
- (now.tm_hour == cert->valid_to.tm_hour &&
- (now.tm_min > cert->valid_to.tm_min ||
- (now.tm_min == cert->valid_to.tm_min &&
- (now.tm_sec > cert->valid_to.tm_sec
- ))))))))))) {
- pr_warn("Cert %s has expired\n", cert->fingerprint);
- ret = -EKEYEXPIRED;
- goto error_free_cert;
- }
-
cert->pub->algo = x509_public_key_algorithms[cert->pkey_algo];
cert->pub->id_type = PKEY_ID_X509;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 008/152] selinux: correct locking in selinux_netlbl_socket_connect)
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (6 preceding siblings ...)
2013-12-06 23:08 ` [PATCH 3.8 007/152] X.509: Remove certificate date checks Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 009/152] NFSv4: Fix a use-after-free situation in _nfs4_proc_getlk() Kamal Mostafa
` (143 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Paul Moore, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Paul Moore <pmoore@redhat.com>
commit 42d64e1add3a1ce8a787116036163b8724362145 upstream.
The SELinux/NetLabel glue code has a locking bug that affects systems
with NetLabel enabled, see the kernel error message below. This patch
corrects this problem by converting the bottom half socket lock to a
more conventional, and correct for this call-path, lock_sock() call.
===============================
[ INFO: suspicious RCU usage. ]
3.11.0-rc3+ #19 Not tainted
-------------------------------
net/ipv4/cipso_ipv4.c:1928 suspicious rcu_dereference_protected() usage!
other info that might help us debug this:
rcu_scheduler_active = 1, debug_locks = 0
2 locks held by ping/731:
#0: (slock-AF_INET/1){+.-...}, at: [...] selinux_netlbl_socket_connect
#1: (rcu_read_lock){.+.+..}, at: [<...>] netlbl_conn_setattr
stack backtrace:
CPU: 1 PID: 731 Comm: ping Not tainted 3.11.0-rc3+ #19
Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
0000000000000001 ffff88006f659d28 ffffffff81726b6a ffff88003732c500
ffff88006f659d58 ffffffff810e4457 ffff88006b845a00 0000000000000000
000000000000000c ffff880075aa2f50 ffff88006f659d90 ffffffff8169bec7
Call Trace:
[<ffffffff81726b6a>] dump_stack+0x54/0x74
[<ffffffff810e4457>] lockdep_rcu_suspicious+0xe7/0x120
[<ffffffff8169bec7>] cipso_v4_sock_setattr+0x187/0x1a0
[<ffffffff8170f317>] netlbl_conn_setattr+0x187/0x190
[<ffffffff8170f195>] ? netlbl_conn_setattr+0x5/0x190
[<ffffffff8131ac9e>] selinux_netlbl_socket_connect+0xae/0xc0
[<ffffffff81303025>] selinux_socket_connect+0x135/0x170
[<ffffffff8119d127>] ? might_fault+0x57/0xb0
[<ffffffff812fb146>] security_socket_connect+0x16/0x20
[<ffffffff815d3ad3>] SYSC_connect+0x73/0x130
[<ffffffff81739a85>] ? sysret_check+0x22/0x5d
[<ffffffff810e5e2d>] ? trace_hardirqs_on_caller+0xfd/0x1c0
[<ffffffff81373d4e>] ? trace_hardirqs_on_thunk+0x3a/0x3f
[<ffffffff815d52be>] SyS_connect+0xe/0x10
[<ffffffff81739a59>] system_call_fastpath+0x16/0x1b
Signed-off-by: Paul Moore <pmoore@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
security/selinux/netlabel.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/security/selinux/netlabel.c b/security/selinux/netlabel.c
index da4b8b2..6235d05 100644
--- a/security/selinux/netlabel.c
+++ b/security/selinux/netlabel.c
@@ -442,8 +442,7 @@ int selinux_netlbl_socket_connect(struct sock *sk, struct sockaddr *addr)
sksec->nlbl_state != NLBL_CONNLABELED)
return 0;
- local_bh_disable();
- bh_lock_sock_nested(sk);
+ lock_sock(sk);
/* connected sockets are allowed to disconnect when the address family
* is set to AF_UNSPEC, if that is what is happening we want to reset
@@ -464,7 +463,6 @@ int selinux_netlbl_socket_connect(struct sock *sk, struct sockaddr *addr)
sksec->nlbl_state = NLBL_CONNLABELED;
socket_connect_return:
- bh_unlock_sock(sk);
- local_bh_enable();
+ release_sock(sk);
return rc;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 009/152] NFSv4: Fix a use-after-free situation in _nfs4_proc_getlk()
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (7 preceding siblings ...)
2013-12-06 23:08 ` [PATCH 3.8 008/152] selinux: correct locking in selinux_netlbl_socket_connect) Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 010/152] usb: musb: cancel work on removal Kamal Mostafa
` (142 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Trond Myklebust, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Trond Myklebust <Trond.Myklebust@netapp.com>
commit a6f951ddbdfb7bd87d31a44f61abe202ed6ce57f upstream.
In nfs4_proc_getlk(), when some error causes a retry of the call to
_nfs4_proc_getlk(), we can end up with Oopses of the form
BUG: unable to handle kernel NULL pointer dereference at 0000000000000134
IP: [<ffffffff8165270e>] _raw_spin_lock+0xe/0x30
<snip>
Call Trace:
[<ffffffff812f287d>] _atomic_dec_and_lock+0x4d/0x70
[<ffffffffa053c4f2>] nfs4_put_lock_state+0x32/0xb0 [nfsv4]
[<ffffffffa053c585>] nfs4_fl_release_lock+0x15/0x20 [nfsv4]
[<ffffffffa0522c06>] _nfs4_proc_getlk.isra.40+0x146/0x170 [nfsv4]
[<ffffffffa052ad99>] nfs4_proc_lock+0x399/0x5a0 [nfsv4]
The problem is that we don't clear the request->fl_ops after the first
try and so when we retry, nfs4_set_lock_state() exits early without
setting the lock stateid.
Regression introduced by commit 70cc6487a4e08b8698c0e2ec935fb48d10490162
(locks: make ->lock release private data before returning in GETLK case)
Reported-by: Weston Andros Adamson <dros@netapp.com>
Reported-by: Jorge Mora <mora@netapp.com>
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
fs/nfs/nfs4proc.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/fs/nfs/nfs4proc.c b/fs/nfs/nfs4proc.c
index ad967bf..ecc6f12 100644
--- a/fs/nfs/nfs4proc.c
+++ b/fs/nfs/nfs4proc.c
@@ -4326,6 +4326,7 @@ static int _nfs4_proc_getlk(struct nfs4_state *state, int cmd, struct file_lock
status = 0;
}
request->fl_ops->fl_release_private(request);
+ request->fl_ops = NULL;
out:
return status;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 010/152] usb: musb: cancel work on removal
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (8 preceding siblings ...)
2013-12-06 23:08 ` [PATCH 3.8 009/152] NFSv4: Fix a use-after-free situation in _nfs4_proc_getlk() Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 011/152] USB: mos7840: fix tiocmget error handling Kamal Mostafa
` (141 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Sebastian Andrzej Siewior, Felipe Balbi, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
commit c5340bd14336b902604ab95212a8877de109d9ae upstream.
So I captured this:
|WARNING: CPU: 0 PID: 2078 at /home/bigeasy/work/new/TI/linux/lib/debugobjects.c:260 debug_print_object+0x94/0xc4()
|ODEBUG: free active (active state 0) object type: work_struct hint: musb_irq_work+0x0/0x38 [musb_hdrc]
|CPU: 0 PID: 2078 Comm: rmmod Not tainted 3.12.0-rc4+ #338
|[<c0014d38>] (unwind_backtrace+0x0/0xf4) from [<c001249c>] (show_stack+0x14/0x1c)
|[<c001249c>] (show_stack+0x14/0x1c) from [<c0037720>] (warn_slowpath_common+0x64/0x84)
|[<c0037720>] (warn_slowpath_common+0x64/0x84) from [<c00377d4>] (warn_slowpath_fmt+0x30/0x40)
|[<c00377d4>] (warn_slowpath_fmt+0x30/0x40) from [<c022ae90>] (debug_print_object+0x94/0xc4)
|[<c022ae90>] (debug_print_object+0x94/0xc4) from [<c022b7e0>] (debug_check_no_obj_freed+0x1c0/0x228)
|[<c022b7e0>] (debug_check_no_obj_freed+0x1c0/0x228) from [<c00f1f38>] (kfree+0xf8/0x228)
|[<c00f1f38>] (kfree+0xf8/0x228) from [<c02921c4>] (release_nodes+0x1a8/0x248)
|[<c02921c4>] (release_nodes+0x1a8/0x248) from [<c028f70c>] (__device_release_driver+0x98/0xf0)
|[<c028f70c>] (__device_release_driver+0x98/0xf0) from [<c028f840>] (device_release_driver+0x24/0x34)
|[<c028f840>] (device_release_driver+0x24/0x34) from [<c028ebe8>] (bus_remove_device+0x148/0x15c)
|[<c028ebe8>] (bus_remove_device+0x148/0x15c) from [<c028d120>] (device_del+0x104/0x1c0)
|[<c028d120>] (device_del+0x104/0x1c0) from [<c02911e4>] (platform_device_del+0x18/0xac)
|[<c02911e4>] (platform_device_del+0x18/0xac) from [<c029179c>] (platform_device_unregister+0xc/0x18)
|[<c029179c>] (platform_device_unregister+0xc/0x18) from [<bf1902fc>] (dsps_remove+0x20/0x4c [musb_dsps])
|[<bf1902fc>] (dsps_remove+0x20/0x4c [musb_dsps]) from [<c0290d7c>] (platform_drv_remove+0x1c/0x24)
|[<c0290d7c>] (platform_drv_remove+0x1c/0x24) from [<c028f704>] (__device_release_driver+0x90/0xf0)
|[<c028f704>] (__device_release_driver+0x90/0xf0) from [<c028f818>] (driver_detach+0xb4/0xb8)
|[<c028f818>] (driver_detach+0xb4/0xb8) from [<c028e6e8>] (bus_remove_driver+0x98/0xec)
|[<c028e6e8>] (bus_remove_driver+0x98/0xec) from [<c008fc70>] (SyS_delete_module+0x1e0/0x24c)
|[<c008fc70>] (SyS_delete_module+0x1e0/0x24c) from [<c000e680>] (ret_fast_syscall+0x0/0x48)
|---[ end trace d79045419a3e51ec ]---
The workqueue is only scheduled from the ep0 and never canceled in case
the musb is removed before the work has a chance to run.
Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Felipe Balbi <balbi@ti.com>
[ kamal: backport to 3.8 (context) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/usb/musb/musb_core.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/usb/musb/musb_core.c b/drivers/usb/musb/musb_core.c
index 60b41cc..85b7a91 100644
--- a/drivers/usb/musb/musb_core.c
+++ b/drivers/usb/musb/musb_core.c
@@ -1816,6 +1816,7 @@ static void musb_free(struct musb *musb)
disable_irq_wake(musb->nIrq);
free_irq(musb->nIrq, musb);
}
+ cancel_work_sync(&musb->irq_work);
if (is_dma_capable() && musb->dma_controller) {
struct dma_controller *c = musb->dma_controller;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 011/152] USB: mos7840: fix tiocmget error handling
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (9 preceding siblings ...)
2013-12-06 23:08 ` [PATCH 3.8 010/152] usb: musb: cancel work on removal Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 012/152] pinctrl: dove: unset twsi option3 for gconfig as well Kamal Mostafa
` (140 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Johan Hovold, Greg Kroah-Hartman, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Johan Hovold <jhovold@gmail.com>
commit a91ccd26e75235d86248d018fe3779732bcafd8d upstream.
Make sure to return errors from tiocmget rather than rely on
uninitialised stack data.
Signed-off-by: Johan Hovold <jhovold@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/usb/serial/mos7840.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/usb/serial/mos7840.c b/drivers/usb/serial/mos7840.c
index 85f28bf..84502ea 100644
--- a/drivers/usb/serial/mos7840.c
+++ b/drivers/usb/serial/mos7840.c
@@ -1644,7 +1644,11 @@ static int mos7840_tiocmget(struct tty_struct *tty)
return -ENODEV;
status = mos7840_get_uart_reg(port, MODEM_STATUS_REGISTER, &msr);
+ if (status != 1)
+ return -EIO;
status = mos7840_get_uart_reg(port, MODEM_CONTROL_REGISTER, &mcr);
+ if (status != 1)
+ return -EIO;
result = ((mcr & MCR_DTR) ? TIOCM_DTR : 0)
| ((mcr & MCR_RTS) ? TIOCM_RTS : 0)
| ((mcr & MCR_LOOPBACK) ? TIOCM_LOOP : 0)
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 012/152] pinctrl: dove: unset twsi option3 for gconfig as well
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (10 preceding siblings ...)
2013-12-06 23:08 ` [PATCH 3.8 011/152] USB: mos7840: fix tiocmget error handling Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 013/152] usb: Disable USB 2.0 Link PM before device reset Kamal Mostafa
` (139 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Roel Kluin, Linus Walleij, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Roel Kluin <roel.kluin@gmail.com>
commit 6d0a4ed2b90a12e1403d3e7d9d8c2cc7fdc301b5 upstream.
This fixes a typo which left twsi config3 option enabled.
Signed-off-by: Roel Kluin <roel.kluin@gmail.com>
Acked-by: Sebastian Hesselbarth <sebastian.hesselbarth@gmail.com>
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/pinctrl/mvebu/pinctrl-dove.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/pinctrl/mvebu/pinctrl-dove.c b/drivers/pinctrl/mvebu/pinctrl-dove.c
index 428ea96..e29e6d8 100644
--- a/drivers/pinctrl/mvebu/pinctrl-dove.c
+++ b/drivers/pinctrl/mvebu/pinctrl-dove.c
@@ -323,7 +323,7 @@ static int dove_twsi_ctrl_set(struct mvebu_mpp_ctrl *ctrl,
unsigned long gcfg2 = readl(DOVE_GLOBAL_CONFIG_2);
gcfg1 &= ~DOVE_TWSI_ENABLE_OPTION1;
- gcfg2 &= ~(DOVE_TWSI_ENABLE_OPTION2 | DOVE_TWSI_ENABLE_OPTION2);
+ gcfg2 &= ~(DOVE_TWSI_ENABLE_OPTION2 | DOVE_TWSI_ENABLE_OPTION3);
switch (config) {
case 1:
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 013/152] usb: Disable USB 2.0 Link PM before device reset.
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (11 preceding siblings ...)
2013-12-06 23:08 ` [PATCH 3.8 012/152] pinctrl: dove: unset twsi option3 for gconfig as well Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 014/152] usb: hub: Clear Port Reset Change during init/resume Kamal Mostafa
` (138 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Sarah Sharp, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Sarah Sharp <sarah.a.sharp@linux.intel.com>
commit dcc01c0864823f91c3bf3ffca6613e2351702b87 upstream.
Before the USB core resets a device, we need to disable the L1 timeout
for the roothub, if USB 2.0 Link PM is enabled. Otherwise the port may
transition into L1 in between descriptor fetches, before we know if the
USB device descriptors changed. LPM will be re-enabled after the
full device descriptors are fetched, and we can confirm the device still
supports USB 2.0 LPM after the reset.
We don't need to wait for the USB device to exit L1 before resetting the
device, since the xHCI roothub port diagrams show a transition to the
Reset state from any of the Ux states (see Figure 34 in the 2012-08-14
xHCI specification update).
This patch should be backported to kernels as old as 3.2, that contain
the commit 65580b4321eb36f16ae8b5987bfa1bb948fc5112 "xHCI: set USB2
hardware LPM". That was the first commit to enable USB 2.0
hardware-driven Link Power Management.
Signed-off-by: Sarah Sharp <sarah.a.sharp@linux.intel.com>
[ kamal: backport to 3.8 (context) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/usb/core/hub.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/usb/core/hub.c b/drivers/usb/core/hub.c
index 0763d84..5edb3ad 100644
--- a/drivers/usb/core/hub.c
+++ b/drivers/usb/core/hub.c
@@ -5032,6 +5032,12 @@ static int usb_reset_and_verify_device(struct usb_device *udev)
}
parent_hub = hdev_to_hub(parent_hdev);
+ /* Disable USB2 hardware LPM.
+ * It will be re-enabled by the enumeration process.
+ */
+ if (udev->usb2_hw_lpm_enabled == 1)
+ usb_set_usb2_hardware_lpm(udev, 0);
+
/* Disable LPM and LTM while we reset the device and reinstall the alt
* settings. Device-initiated LPM settings, and system exit latency
* settings are cleared when the device is reset, so we have to set
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 014/152] usb: hub: Clear Port Reset Change during init/resume
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (12 preceding siblings ...)
2013-12-06 23:08 ` [PATCH 3.8 013/152] usb: Disable USB 2.0 Link PM before device reset Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 015/152] rt2400pci: fix RSSI read Kamal Mostafa
` (137 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Julius Werner, Greg Kroah-Hartman, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Julius Werner <jwerner@chromium.org>
commit e92aee330837e4911553761490a8fb843f2053a6 upstream.
This patch adds the Port Reset Change flag to the set of bits that are
preemptively cleared on init/resume of a hub. In theory this bit should
never be set unexpectedly... in practice it can still happen if BIOS,
SMM or ACPI code plays around with USB devices without cleaning up
correctly. This is especially dangerous for XHCI root hubs, which don't
generate any more Port Status Change Events until all change bits are
cleared, so this is a good precaution to have (similar to how it's
already done for the Warm Port Reset Change flag).
Signed-off-by: Julius Werner <jwerner@chromium.org>
Acked-by: Alan Stern <stern@rowland.harvard.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ kamal: backport to 3.8 (clear_port_feature rename) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/usb/core/hub.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/usb/core/hub.c b/drivers/usb/core/hub.c
index 5edb3ad..1ac190b 100644
--- a/drivers/usb/core/hub.c
+++ b/drivers/usb/core/hub.c
@@ -1153,6 +1153,11 @@ static void hub_activate(struct usb_hub *hub, enum hub_activation_type type)
clear_port_feature(hub->hdev, port1,
USB_PORT_FEAT_C_ENABLE);
}
+ if (portchange & USB_PORT_STAT_C_RESET) {
+ need_debounce_delay = true;
+ clear_port_feature(hub->hdev, port1,
+ USB_PORT_FEAT_C_RESET);
+ }
if ((portchange & USB_PORT_STAT_C_BH_RESET) &&
hub_is_superspeed(hub->hdev)) {
need_debounce_delay = true;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 015/152] rt2400pci: fix RSSI read
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (13 preceding siblings ...)
2013-12-06 23:08 ` [PATCH 3.8 014/152] usb: hub: Clear Port Reset Change during init/resume Kamal Mostafa
@ 2013-12-06 23:08 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 016/152] rt2x00: check if device is still available on rt2x00mac_flush() Kamal Mostafa
` (136 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:08 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Stanislaw Gruszka, John W. Linville, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislaw Gruszka <stf_xl@wp.pl>
commit 2bf127a5cc372b9319afcbae10b090663b621c8b upstream.
RSSI value is provided on word3 not on word2.
Signed-off-by: Stanislaw Gruszka <stf_xl@wp.pl>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/rt2x00/rt2400pci.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/rt2x00/rt2400pci.c b/drivers/net/wireless/rt2x00/rt2400pci.c
index a2d2bc2..f17a5c3 100644
--- a/drivers/net/wireless/rt2x00/rt2400pci.c
+++ b/drivers/net/wireless/rt2x00/rt2400pci.c
@@ -1253,7 +1253,7 @@ static void rt2400pci_fill_rxdone(struct queue_entry *entry,
*/
rxdesc->timestamp = ((u64)rx_high << 32) | rx_low;
rxdesc->signal = rt2x00_get_field32(word2, RXD_W2_SIGNAL) & ~0x08;
- rxdesc->rssi = rt2x00_get_field32(word2, RXD_W3_RSSI) -
+ rxdesc->rssi = rt2x00_get_field32(word3, RXD_W3_RSSI) -
entry->queue->rt2x00dev->rssi_offset;
rxdesc->size = rt2x00_get_field32(word0, RXD_W0_DATABYTE_COUNT);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 016/152] rt2x00: check if device is still available on rt2x00mac_flush()
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (14 preceding siblings ...)
2013-12-06 23:08 ` [PATCH 3.8 015/152] rt2400pci: fix RSSI read Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 017/152] rt2800usb: slow down TX status polling Kamal Mostafa
` (135 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Stanislaw Gruszka, John W. Linville, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislaw Gruszka <stf_xl@wp.pl>
commit 5671ab05cf2a579218985ef56595387932d78ee4 upstream.
Fix random kernel panic with below messages when remove dongle.
[ 2212.355447] BUG: unable to handle kernel NULL pointer dereference at 0000000000000250
[ 2212.355527] IP: [<ffffffffa02667f2>] rt2x00usb_kick_tx_entry+0x12/0x160 [rt2x00usb]
[ 2212.355599] PGD 0
[ 2212.355626] Oops: 0000 [#1] SMP
[ 2212.355664] Modules linked in: rt2800usb rt2x00usb rt2800lib crc_ccitt rt2x00lib mac80211 cfg80211 tun arc4 fuse rfcomm bnep snd_hda_codec_realtek snd_hda_intel snd_hda_codec btusb uvcvideo bluetooth snd_hwdep x86_pkg_temp_thermal snd_seq coretemp aesni_intel aes_x86_64 snd_seq_device glue_helper snd_pcm ablk_helper videobuf2_vmalloc sdhci_pci videobuf2_memops videobuf2_core sdhci videodev mmc_core serio_raw snd_page_alloc microcode i2c_i801 snd_timer hid_multitouch thinkpad_acpi lpc_ich mfd_core snd tpm_tis wmi tpm tpm_bios soundcore acpi_cpufreq i915 i2c_algo_bit drm_kms_helper drm i2c_core video [last unloaded: cfg80211]
[ 2212.356224] CPU: 0 PID: 34 Comm: khubd Not tainted 3.12.0-rc3-wl+ #3
[ 2212.356268] Hardware name: LENOVO 3444CUU/3444CUU, BIOS G6ET93WW (2.53 ) 02/04/2013
[ 2212.356319] task: ffff880212f687c0 ti: ffff880212f66000 task.ti: ffff880212f66000
[ 2212.356392] RIP: 0010:[<ffffffffa02667f2>] [<ffffffffa02667f2>] rt2x00usb_kick_tx_entry+0x12/0x160 [rt2x00usb]
[ 2212.356481] RSP: 0018:ffff880212f67750 EFLAGS: 00010202
[ 2212.356519] RAX: 000000000000000c RBX: 000000000000000c RCX: 0000000000000293
[ 2212.356568] RDX: ffff8801f4dc219a RSI: 0000000000000000 RDI: 0000000000000240
[ 2212.356617] RBP: ffff880212f67778 R08: ffffffffa02667e0 R09: 0000000000000002
[ 2212.356665] R10: 0001f95254ab4b40 R11: ffff880212f675be R12: ffff8801f4dc2150
[ 2212.356712] R13: 0000000000000000 R14: ffffffffa02667e0 R15: 000000000000000d
[ 2212.356761] FS: 0000000000000000(0000) GS:ffff88021e200000(0000) knlGS:0000000000000000
[ 2212.356813] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 2212.356852] CR2: 0000000000000250 CR3: 0000000001a0c000 CR4: 00000000001407f0
[ 2212.356899] Stack:
[ 2212.356917] 000000000000000c ffff8801f4dc2150 0000000000000000 ffffffffa02667e0
[ 2212.356980] 000000000000000d ffff880212f677b8 ffffffffa03a31ad ffff8801f4dc219a
[ 2212.357038] ffff8801f4dc2150 0000000000000000 ffff8800b93217a0 ffff8801f49bc800
[ 2212.357099] Call Trace:
[ 2212.357122] [<ffffffffa02667e0>] ? rt2x00usb_interrupt_txdone+0x90/0x90 [rt2x00usb]
[ 2212.357174] [<ffffffffa03a31ad>] rt2x00queue_for_each_entry+0xed/0x170 [rt2x00lib]
[ 2212.357244] [<ffffffffa026701c>] rt2x00usb_kick_queue+0x5c/0x60 [rt2x00usb]
[ 2212.357314] [<ffffffffa03a3682>] rt2x00queue_flush_queue+0x62/0xa0 [rt2x00lib]
[ 2212.357386] [<ffffffffa03a2930>] rt2x00mac_flush+0x30/0x70 [rt2x00lib]
[ 2212.357470] [<ffffffffa04edded>] ieee80211_flush_queues+0xbd/0x140 [mac80211]
[ 2212.357555] [<ffffffffa0502e52>] ieee80211_set_disassoc+0x2d2/0x3d0 [mac80211]
[ 2212.357645] [<ffffffffa0506da3>] ieee80211_mgd_deauth+0x1d3/0x240 [mac80211]
[ 2212.357718] [<ffffffff8108b17c>] ? try_to_wake_up+0xec/0x290
[ 2212.357788] [<ffffffffa04dbd18>] ieee80211_deauth+0x18/0x20 [mac80211]
[ 2212.357872] [<ffffffffa0418ddc>] cfg80211_mlme_deauth+0x9c/0x140 [cfg80211]
[ 2212.357913] [<ffffffffa041907c>] cfg80211_mlme_down+0x5c/0x60 [cfg80211]
[ 2212.357962] [<ffffffffa041cd18>] cfg80211_disconnect+0x188/0x1a0 [cfg80211]
[ 2212.358014] [<ffffffffa04013bc>] ? __cfg80211_stop_sched_scan+0x1c/0x130 [cfg80211]
[ 2212.358067] [<ffffffffa03f8954>] cfg80211_leave+0xc4/0xe0 [cfg80211]
[ 2212.358124] [<ffffffffa03f8d1b>] cfg80211_netdev_notifier_call+0x3ab/0x5e0 [cfg80211]
[ 2212.358177] [<ffffffff815140f8>] ? inetdev_event+0x38/0x510
[ 2212.358217] [<ffffffff81085a94>] ? __wake_up+0x44/0x50
[ 2212.358254] [<ffffffff8155995c>] notifier_call_chain+0x4c/0x70
[ 2212.358293] [<ffffffff81081156>] raw_notifier_call_chain+0x16/0x20
[ 2212.358361] [<ffffffff814b6dd5>] call_netdevice_notifiers_info+0x35/0x60
[ 2212.358429] [<ffffffff814b6ec9>] __dev_close_many+0x49/0xd0
[ 2212.358487] [<ffffffff814b7028>] dev_close_many+0x88/0x100
[ 2212.358546] [<ffffffff814b8150>] rollback_registered_many+0xb0/0x220
[ 2212.358612] [<ffffffff814b8319>] unregister_netdevice_many+0x19/0x60
[ 2212.358694] [<ffffffffa04d8eb2>] ieee80211_remove_interfaces+0x112/0x190 [mac80211]
[ 2212.358791] [<ffffffffa04c585f>] ieee80211_unregister_hw+0x4f/0x100 [mac80211]
[ 2212.361994] [<ffffffffa03a1221>] rt2x00lib_remove_dev+0x161/0x1a0 [rt2x00lib]
[ 2212.365240] [<ffffffffa0266e2e>] rt2x00usb_disconnect+0x2e/0x70 [rt2x00usb]
[ 2212.368470] [<ffffffff81419ce4>] usb_unbind_interface+0x64/0x1c0
[ 2212.371734] [<ffffffff813b446f>] __device_release_driver+0x7f/0xf0
[ 2212.374999] [<ffffffff813b4503>] device_release_driver+0x23/0x30
[ 2212.378131] [<ffffffff813b3c98>] bus_remove_device+0x108/0x180
[ 2212.381358] [<ffffffff813b0565>] device_del+0x135/0x1d0
[ 2212.384454] [<ffffffff81417760>] usb_disable_device+0xb0/0x270
[ 2212.387451] [<ffffffff8140d9cd>] usb_disconnect+0xad/0x1d0
[ 2212.390294] [<ffffffff8140f6cd>] hub_thread+0x63d/0x1660
[ 2212.393034] [<ffffffff8107c860>] ? wake_up_atomic_t+0x30/0x30
[ 2212.395728] [<ffffffff8140f090>] ? hub_port_debounce+0x130/0x130
[ 2212.398412] [<ffffffff8107baa0>] kthread+0xc0/0xd0
[ 2212.401058] [<ffffffff8107b9e0>] ? insert_kthread_work+0x40/0x40
[ 2212.403639] [<ffffffff8155de3c>] ret_from_fork+0x7c/0xb0
[ 2212.406193] [<ffffffff8107b9e0>] ? insert_kthread_work+0x40/0x40
[ 2212.408732] Code: 24 58 08 00 00 bf 80 00 00 00 e8 3a c3 e0 e0 5b 41 5c 5d c3 0f 1f 44 00 00 0f 1f 44 00 00 55 48 89 e5 41 57 41 56 41 55 41 54 53 <48> 8b 47 10 48 89 fb 4c 8b 6f 28 4c 8b 20 49 8b 04 24 4c 8b 30
[ 2212.414671] RIP [<ffffffffa02667f2>] rt2x00usb_kick_tx_entry+0x12/0x160 [rt2x00usb]
[ 2212.417646] RSP <ffff880212f67750>
[ 2212.420547] CR2: 0000000000000250
[ 2212.441024] ---[ end trace 5442918f33832bce ]---
Signed-off-by: Stanislaw Gruszka <stf_xl@wp.pl>
Acked-by: Helmut Schaa <helmut.schaa@googlemail.com>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/rt2x00/rt2x00mac.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/rt2x00/rt2x00mac.c b/drivers/net/wireless/rt2x00/rt2x00mac.c
index ed7a1bb..509c3f1 100644
--- a/drivers/net/wireless/rt2x00/rt2x00mac.c
+++ b/drivers/net/wireless/rt2x00/rt2x00mac.c
@@ -753,6 +753,9 @@ void rt2x00mac_flush(struct ieee80211_hw *hw, bool drop)
struct rt2x00_dev *rt2x00dev = hw->priv;
struct data_queue *queue;
+ if (!test_bit(DEVICE_STATE_PRESENT, &rt2x00dev->flags))
+ return;
+
tx_queue_for_each(rt2x00dev, queue)
rt2x00queue_flush_queue(queue, drop);
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 017/152] rt2800usb: slow down TX status polling
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (15 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 016/152] rt2x00: check if device is still available on rt2x00mac_flush() Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 018/152] cfg80211: fix scheduled scan pointer access Kamal Mostafa
` (134 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Stanislaw Gruszka, John W. Linville, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislaw Gruszka <sgruszka@redhat.com>
commit 36165fd5b00bf8163f89c21bb16a3e9834555b10 upstream.
Polling TX statuses too frequently has two negative effects. First is
randomly peek CPU usage, causing overall system functioning delays.
Second bad effect is that device is not able to fill TX statuses in
H/W register on some workloads and we get lot of timeouts like below:
ieee80211 phy4: rt2800usb_entry_txstatus_timeout: Warning - TX status timeout for entry 7 in queue 2
ieee80211 phy4: rt2800usb_entry_txstatus_timeout: Warning - TX status timeout for entry 7 in queue 2
ieee80211 phy4: rt2800usb_txdone: Warning - Got TX status for an empty queue 2, dropping
This not only cause flood of messages in dmesg, but also bad throughput,
since rate scaling algorithm can not work optimally.
In the future, we should probably make polling interval be adjusted
automatically, but for now just increase values, this make mentioned
problems gone.
Resolve:
https://bugzilla.kernel.org/show_bug.cgi?id=62781
Signed-off-by: Stanislaw Gruszka <sgruszka@redhat.com>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/rt2x00/rt2800usb.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/net/wireless/rt2x00/rt2800usb.c b/drivers/net/wireless/rt2x00/rt2800usb.c
index 5c149b5..926f1b0 100644
--- a/drivers/net/wireless/rt2x00/rt2800usb.c
+++ b/drivers/net/wireless/rt2x00/rt2800usb.c
@@ -148,6 +148,8 @@ static bool rt2800usb_txstatus_timeout(struct rt2x00_dev *rt2x00dev)
return false;
}
+#define TXSTATUS_READ_INTERVAL 1000000
+
static bool rt2800usb_tx_sta_fifo_read_completed(struct rt2x00_dev *rt2x00dev,
int urb_status, u32 tx_status)
{
@@ -175,8 +177,9 @@ static bool rt2800usb_tx_sta_fifo_read_completed(struct rt2x00_dev *rt2x00dev,
queue_work(rt2x00dev->workqueue, &rt2x00dev->txdone_work);
if (rt2800usb_txstatus_pending(rt2x00dev)) {
- /* Read register after 250 us */
- hrtimer_start(&rt2x00dev->txstatus_timer, ktime_set(0, 250000),
+ /* Read register after 1 ms */
+ hrtimer_start(&rt2x00dev->txstatus_timer,
+ ktime_set(0, TXSTATUS_READ_INTERVAL),
HRTIMER_MODE_REL);
return false;
}
@@ -201,8 +204,9 @@ static void rt2800usb_async_read_tx_status(struct rt2x00_dev *rt2x00dev)
if (test_and_set_bit(TX_STATUS_READING, &rt2x00dev->flags))
return;
- /* Read TX_STA_FIFO register after 500 us */
- hrtimer_start(&rt2x00dev->txstatus_timer, ktime_set(0, 500000),
+ /* Read TX_STA_FIFO register after 2 ms */
+ hrtimer_start(&rt2x00dev->txstatus_timer,
+ ktime_set(0, 2*TXSTATUS_READ_INTERVAL),
HRTIMER_MODE_REL);
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 018/152] cfg80211: fix scheduled scan pointer access
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (16 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 017/152] rt2800usb: slow down TX status polling Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 019/152] ARM: OMAP2+: irq, AM33XX add missing register check Kamal Mostafa
` (133 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Johannes Berg, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
commit 79845c662eeb95c9a180b9bd0d3ad848ee65b94c upstream.
Since rdev->sched_scan_req is dereferenced outside the
lock protecting it, this might be done at the wrong
time, causing crashes. Move the dereference to where
it should be - inside the RTNL locked section.
Reviewed-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
[ kamal: backport to 3.8 (context) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
net/wireless/scan.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/wireless/scan.c b/net/wireless/scan.c
index 45f1618..c6390e7 100644
--- a/net/wireless/scan.c
+++ b/net/wireless/scan.c
@@ -166,10 +166,10 @@ void __cfg80211_sched_scan_results(struct work_struct *wk)
rdev = container_of(wk, struct cfg80211_registered_device,
sched_scan_results_wk);
- request = rdev->sched_scan_req;
-
mutex_lock(&rdev->sched_scan_mtx);
+ request = rdev->sched_scan_req;
+
/* we don't have sched_scan_req anymore if the scan is stopping */
if (request) {
if (request->flags & NL80211_SCAN_FLAG_FLUSH) {
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 019/152] ARM: OMAP2+: irq, AM33XX add missing register check
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (17 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 018/152] cfg80211: fix scheduled scan pointer access Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 020/152] ALSA: hda - Add support of new codec ALC233 Kamal Mostafa
` (132 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Markus Pargmann, Tony Lindgren, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Markus Pargmann <mpa@pengutronix.de>
commit 0bebda684857f76548ea48c8886785198701d8d3 upstream.
am33xx has a INTC_PENDING_IRQ3 register that is not checked for pending
interrupts. This patch adds AM33XX to the ifdef of SOCs that have to
check this register.
Signed-off-by: Markus Pargmann <mpa@pengutronix.de>
Signed-off-by: Tony Lindgren <tony@atomide.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/arm/mach-omap2/irq.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm/mach-omap2/irq.c b/arch/arm/mach-omap2/irq.c
index 3926f37..e022a86 100644
--- a/arch/arm/mach-omap2/irq.c
+++ b/arch/arm/mach-omap2/irq.c
@@ -233,7 +233,7 @@ static inline void omap_intc_handle_irq(void __iomem *base_addr, struct pt_regs
goto out;
irqnr = readl_relaxed(base_addr + 0xd8);
-#ifdef CONFIG_SOC_TI81XX
+#if IS_ENABLED(CONFIG_SOC_TI81XX) || IS_ENABLED(CONFIG_SOC_AM33XX)
if (irqnr)
goto out;
irqnr = readl_relaxed(base_addr + 0xf8);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 020/152] ALSA: hda - Add support of new codec ALC233
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (18 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 019/152] ARM: OMAP2+: irq, AM33XX add missing register check Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 021/152] ALSA: hda - Add support of ALC255 codecs Kamal Mostafa
` (131 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Kailang Yang, Takashi Iwai, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Kailang Yang <kailang@realtek.com>
commit 84dfd0ac231f69d70e100e712ad5e5f0092ad46b upstream.
It's compatible with ALC282.
Signed-off-by: Kailang Yang <kailang@realtek.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/pci/hda/patch_realtek.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index d8c539b..5267e48 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -6454,6 +6454,7 @@ static int patch_alc269(struct hda_codec *codec)
case 0x10ec0290:
spec->codec_variant = ALC269_TYPE_ALC280;
break;
+ case 0x10ec0233:
case 0x10ec0282:
case 0x10ec0283:
spec->codec_variant = ALC269_TYPE_ALC282;
@@ -7162,6 +7163,7 @@ static int patch_alc680(struct hda_codec *codec)
*/
static const struct hda_codec_preset snd_hda_preset_realtek[] = {
{ .id = 0x10ec0221, .name = "ALC221", .patch = patch_alc269 },
+ { .id = 0x10ec0233, .name = "ALC233", .patch = patch_alc269 },
{ .id = 0x10ec0260, .name = "ALC260", .patch = patch_alc260 },
{ .id = 0x10ec0262, .name = "ALC262", .patch = patch_alc262 },
{ .id = 0x10ec0267, .name = "ALC267", .patch = patch_alc268 },
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 021/152] ALSA: hda - Add support of ALC255 codecs
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (19 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 020/152] ALSA: hda - Add support of new codec ALC233 Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 022/152] USB:add new zte 3g-dongle's pid to option.c Kamal Mostafa
` (130 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Kailang Yang, Takashi Iwai, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Kailang Yang <kailang@realtek.com>
commit 1d04c9de5c76df113e4af7120feb53c628b5efcc upstream.
It's just another variant of ALC269 & co.
Signed-off-by: Kailang Yang <kailang@realtek.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/pci/hda/patch_realtek.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index 5267e48..fe2138d 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -5824,6 +5824,7 @@ enum {
ALC269_TYPE_ALC282,
ALC269_TYPE_ALC284,
ALC269_TYPE_ALC286,
+ ALC269_TYPE_ALC255,
};
/*
@@ -5848,6 +5849,7 @@ static int alc269_parse_auto_config(struct hda_codec *codec)
case ALC269_TYPE_ALC269VD:
case ALC269_TYPE_ALC282:
case ALC269_TYPE_ALC286:
+ case ALC269_TYPE_ALC255:
ssids = alc269_ssids;
break;
default:
@@ -6466,6 +6468,9 @@ static int patch_alc269(struct hda_codec *codec)
case 0x10ec0286:
spec->codec_variant = ALC269_TYPE_ALC286;
break;
+ case 0x10ec0255:
+ spec->codec_variant = ALC269_TYPE_ALC255;
+ break;
}
/* automatic parse from the BIOS config */
@@ -7164,6 +7169,7 @@ static int patch_alc680(struct hda_codec *codec)
static const struct hda_codec_preset snd_hda_preset_realtek[] = {
{ .id = 0x10ec0221, .name = "ALC221", .patch = patch_alc269 },
{ .id = 0x10ec0233, .name = "ALC233", .patch = patch_alc269 },
+ { .id = 0x10ec0255, .name = "ALC255", .patch = patch_alc269 },
{ .id = 0x10ec0260, .name = "ALC260", .patch = patch_alc260 },
{ .id = 0x10ec0262, .name = "ALC262", .patch = patch_alc262 },
{ .id = 0x10ec0267, .name = "ALC267", .patch = patch_alc268 },
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 022/152] USB:add new zte 3g-dongle's pid to option.c
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (20 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 021/152] ALSA: hda - Add support of ALC255 codecs Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 023/152] [SCSI] sd: Reduce buffer size for vpd request Kamal Mostafa
` (129 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Rui li, Greg Kroah-Hartman, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Rui li <li.rui27@zte.com.cn>
commit 0636fc507a976cdc40f21bdbcce6f0b98ff1dfe9 upstream.
Signed-off-by: Rui li <li.rui27@zte.com.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/usb/serial/option.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/drivers/usb/serial/option.c b/drivers/usb/serial/option.c
index 48c4f3d..4da1743 100644
--- a/drivers/usb/serial/option.c
+++ b/drivers/usb/serial/option.c
@@ -1376,6 +1376,23 @@ static const struct usb_device_id option_ids[] = {
.driver_info = (kernel_ulong_t)&net_intf2_blacklist },
{ USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1426, 0xff, 0xff, 0xff), /* ZTE MF91 */
.driver_info = (kernel_ulong_t)&net_intf2_blacklist },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1533, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1534, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1535, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1545, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1546, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1547, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1565, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1566, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1567, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1589, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1590, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1591, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1592, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1594, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1596, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1598, 0xff, 0xff, 0xff) },
+ { USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x1600, 0xff, 0xff, 0xff) },
{ USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x2002, 0xff,
0xff, 0xff), .driver_info = (kernel_ulong_t)&zte_k3765_z_blacklist },
{ USB_DEVICE_AND_INTERFACE_INFO(ZTE_VENDOR_ID, 0x2003, 0xff, 0xff, 0xff) },
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 023/152] [SCSI] sd: Reduce buffer size for vpd request
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (21 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 022/152] USB:add new zte 3g-dongle's pid to option.c Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 024/152] Revert "ima: policy for RAMFS" Kamal Mostafa
` (128 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Bernd Schubert, James Bottomley, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Bernd Schubert <bernd.schubert@itwm.fraunhofer.de>
commit af73623f5f10eb3832c87a169b28f7df040a875b upstream.
Somehow older areca firmware versions have issues with
scsi_get_vpd_page() and a large buffer, the firmware
seems to crash and the scsi error-handler will start endless
recovery retries.
Limiting the buf-size to 64-bytes fixes this issue with older
firmware versions (<1.49 for my controller).
Fixes a regression with areca controllers and older firmware versions
introduced by commit: 66c28f97120e8a621afd5aa7a31c4b85c547d33d
Reported-by: Nix <nix@esperi.org.uk>
Tested-by: Nix <nix@esperi.org.uk>
Signed-off-by: Bernd Schubert <bernd.schubert@itwm.fraunhofer.de>
Acked-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: James Bottomley <JBottomley@Parallels.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/scsi/sd.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c
index bc108d2..a4dc067 100644
--- a/drivers/scsi/sd.c
+++ b/drivers/scsi/sd.c
@@ -2640,13 +2640,16 @@ static void sd_read_write_same(struct scsi_disk *sdkp, unsigned char *buffer)
struct scsi_device *sdev = sdkp->device;
if (scsi_report_opcode(sdev, buffer, SD_BUF_SIZE, INQUIRY) < 0) {
+ /* too large values might cause issues with arcmsr */
+ int vpd_buf_len = 64;
+
sdev->no_report_opcodes = 1;
/* Disable WRITE SAME if REPORT SUPPORTED OPERATION
* CODES is unsupported and the device has an ATA
* Information VPD page (SAT).
*/
- if (!scsi_get_vpd_page(sdev, 0x89, buffer, SD_BUF_SIZE))
+ if (!scsi_get_vpd_page(sdev, 0x89, buffer, vpd_buf_len))
sdev->no_write_same = 1;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 024/152] Revert "ima: policy for RAMFS"
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (22 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 023/152] [SCSI] sd: Reduce buffer size for vpd request Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 025/152] libata: Fix display of sata speed Kamal Mostafa
` (127 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Mimi Zohar, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mimi Zohar <zohar@linux.vnet.ibm.com>
commit 08de59eb144d7c41351a467442f898d720f0f15f upstream.
This reverts commit 4c2c392763a682354fac65b6a569adec4e4b5387.
Everything in the initramfs should be measured and appraised,
but until the initramfs has extended attribute support, at
least measured.
Signed-off-by: Mimi Zohar <zohar@us.ibm.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
security/integrity/ima/ima_policy.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/security/integrity/ima/ima_policy.c b/security/integrity/ima/ima_policy.c
index 479fca9..cb98e81 100644
--- a/security/integrity/ima/ima_policy.c
+++ b/security/integrity/ima/ima_policy.c
@@ -69,7 +69,6 @@ static struct ima_rule_entry default_rules[] = {
{.action = DONT_MEASURE,.fsmagic = SYSFS_MAGIC,.flags = IMA_FSMAGIC},
{.action = DONT_MEASURE,.fsmagic = DEBUGFS_MAGIC,.flags = IMA_FSMAGIC},
{.action = DONT_MEASURE,.fsmagic = TMPFS_MAGIC,.flags = IMA_FSMAGIC},
- {.action = DONT_MEASURE,.fsmagic = RAMFS_MAGIC,.flags = IMA_FSMAGIC},
{.action = DONT_MEASURE,.fsmagic = DEVPTS_SUPER_MAGIC,.flags = IMA_FSMAGIC},
{.action = DONT_MEASURE,.fsmagic = BINFMTFS_MAGIC,.flags = IMA_FSMAGIC},
{.action = DONT_MEASURE,.fsmagic = SECURITYFS_MAGIC,.flags = IMA_FSMAGIC},
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 025/152] libata: Fix display of sata speed
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (23 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 024/152] Revert "ima: policy for RAMFS" Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 026/152] ahci: disabled FBS prior to issuing software reset Kamal Mostafa
` (126 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Gwendal Grignou, Tejun Heo, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Gwendal Grignou <gwendal@google.com>
commit 3e85c3ecbc520751324a191d23bb94873ed01b10 upstream.
6.0 Gbps link speed was not decoded properly:
speed was reported at 3.0 Gbps only.
Tested: On a machine where libata reports 6.0 Gbps in
/var/log/messages:
ata1: SATA link up 6.0 Gbps (SStatus 133 SControl 300)
Before:
cat /sys/class/ata_link/link1/sata_spd
3.0 Gbps
After:
cat /sys/class/ata_link/link1/sata_spd
6.0 Gbps
Signed-off-by: Gwendal Grignou <gwendal@google.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/ata/libata-transport.c | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/drivers/ata/libata-transport.c b/drivers/ata/libata-transport.c
index c04d393..08e6728 100644
--- a/drivers/ata/libata-transport.c
+++ b/drivers/ata/libata-transport.c
@@ -319,25 +319,25 @@ int ata_tport_add(struct device *parent,
/*
* ATA link attributes
*/
+static int noop(int x) { return x; }
-
-#define ata_link_show_linkspeed(field) \
+#define ata_link_show_linkspeed(field, format) \
static ssize_t \
show_ata_link_##field(struct device *dev, \
struct device_attribute *attr, char *buf) \
{ \
struct ata_link *link = transport_class_to_link(dev); \
\
- return sprintf(buf,"%s\n", sata_spd_string(fls(link->field))); \
+ return sprintf(buf, "%s\n", sata_spd_string(format(link->field))); \
}
-#define ata_link_linkspeed_attr(field) \
- ata_link_show_linkspeed(field) \
+#define ata_link_linkspeed_attr(field, format) \
+ ata_link_show_linkspeed(field, format) \
static DEVICE_ATTR(field, S_IRUGO, show_ata_link_##field, NULL)
-ata_link_linkspeed_attr(hw_sata_spd_limit);
-ata_link_linkspeed_attr(sata_spd_limit);
-ata_link_linkspeed_attr(sata_spd);
+ata_link_linkspeed_attr(hw_sata_spd_limit, fls);
+ata_link_linkspeed_attr(sata_spd_limit, fls);
+ata_link_linkspeed_attr(sata_spd, noop);
static DECLARE_TRANSPORT_CLASS(ata_link_class,
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 026/152] ahci: disabled FBS prior to issuing software reset
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (24 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 025/152] libata: Fix display of sata speed Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 027/152] drivers/libata: Set max sector to 65535 for Slimtype DVD A DS8A9SH drive Kamal Mostafa
` (125 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Xiangliang Yu, Tejun Heo, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: xiangliang yu <yxlraid@gmail.com>
commit 89dafa20f3daab5b3e0c13d0068a28e8e64e2102 upstream.
Tested with Marvell 88se9125, attached with one port mulitplier(5 ports)
and one disk, we will get following boot log messages if using current
code:
ata8: SATA link up 6.0 Gbps (SStatus 133 SControl 330)
ata8.15: Port Multiplier 1.2, 0x1b4b:0x9715 r160, 5 ports, feat 0x1/0x1f
ahci 0000:03:00.0: FBS is enabled
ata8.00: hard resetting link
ata8.00: SATA link down (SStatus 0 SControl 330)
ata8.01: hard resetting link
ata8.01: SATA link down (SStatus 0 SControl 330)
ata8.02: hard resetting link
ata8.02: SATA link down (SStatus 0 SControl 330)
ata8.03: hard resetting link
ata8.03: SATA link up 6.0 Gbps (SStatus 133 SControl 133)
ata8.04: hard resetting link
ata8.04: failed to resume link (SControl 133)
ata8.04: failed to read SCR 0 (Emask=0x40)
ata8.04: failed to read SCR 0 (Emask=0x40)
ata8.04: failed to read SCR 1 (Emask=0x40)
ata8.04: failed to read SCR 0 (Emask=0x40)
ata8.03: native sectors (2) is smaller than sectors (976773168)
ata8.03: ATA-8: ST3500413AS, JC4B, max UDMA/133
ata8.03: 976773168 sectors, multi 0: LBA48 NCQ (depth 31/32)
ata8.03: configured for UDMA/133
ata8.04: failed to IDENTIFY (I/O error, err_mask=0x100)
ata8.15: hard resetting link
ata8.15: SATA link up 6.0 Gbps (SStatus 133 SControl 330)
ata8.15: Port Multiplier vendor mismatch '0x1b4b' != '0x133'
ata8.15: PMP revalidation failed (errno=-19)
ata8.15: hard resetting link
ata8.15: SATA link up 6.0 Gbps (SStatus 133 SControl 330)
ata8.15: Port Multiplier vendor mismatch '0x1b4b' != '0x133'
ata8.15: PMP revalidation failed (errno=-19)
ata8.15: limiting SATA link speed to 3.0 Gbps
ata8.15: hard resetting link
ata8.15: SATA link up 3.0 Gbps (SStatus 123 SControl 320)
ata8.15: Port Multiplier vendor mismatch '0x1b4b' != '0x133'
ata8.15: PMP revalidation failed (errno=-19)
ata8.15: failed to recover PMP after 5 tries, giving up
ata8.15: Port Multiplier detaching
ata8.03: disabled
ata8.00: disabled
ata8: EH complete
The reason is that current detection code doesn't follow AHCI spec:
First,the port multiplier detection process look like this:
ahci_hardreset(link, class, deadline)
if (class == ATA_DEV_PMP) {
sata_pmp_attach(dev) /* will enable FBS */
sata_pmp_init_links(ap, nr_ports);
ata_for_each_link(link, ap, EDGE) {
sata_std_hardreset(link, class, deadline);
if (link_is_online) /* do soft reset */
ahci_softreset(link, class, deadline);
}
}
But, according to chapter 9.3.9 in AHCI spec: Prior to issuing software
reset, software shall clear PxCMD.ST to '0' and then clear PxFBS.EN to
'0'.
The patch test ok with kernel 3.11.1.
tj: Patch white space contaminated, applied manually with trivial
updates.
Signed-off-by: Xiangliang Yu <yuxiangl@marvell.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/ata/libahci.c | 16 ++++++++++++++++
1 file changed, 16 insertions(+)
diff --git a/drivers/ata/libahci.c b/drivers/ata/libahci.c
index c86d560..a2fe286 100644
--- a/drivers/ata/libahci.c
+++ b/drivers/ata/libahci.c
@@ -1266,9 +1266,11 @@ int ahci_do_softreset(struct ata_link *link, unsigned int *class,
{
struct ata_port *ap = link->ap;
struct ahci_host_priv *hpriv = ap->host->private_data;
+ struct ahci_port_priv *pp = ap->private_data;
const char *reason = NULL;
unsigned long now, msecs;
struct ata_taskfile tf;
+ bool fbs_disabled = false;
int rc;
DPRINTK("ENTER\n");
@@ -1278,6 +1280,16 @@ int ahci_do_softreset(struct ata_link *link, unsigned int *class,
if (rc && rc != -EOPNOTSUPP)
ata_link_warn(link, "failed to reset engine (errno=%d)\n", rc);
+ /*
+ * According to AHCI-1.2 9.3.9: if FBS is enable, software shall
+ * clear PxFBS.EN to '0' prior to issuing software reset to devices
+ * that is attached to port multiplier.
+ */
+ if (!ata_is_host_link(link) && pp->fbs_enabled) {
+ ahci_disable_fbs(ap);
+ fbs_disabled = true;
+ }
+
ata_tf_init(link->device, &tf);
/* issue the first D2H Register FIS */
@@ -1318,6 +1330,10 @@ int ahci_do_softreset(struct ata_link *link, unsigned int *class,
} else
*class = ahci_dev_classify(ap);
+ /* re-enable FBS if disabled before */
+ if (fbs_disabled)
+ ahci_enable_fbs(ap);
+
DPRINTK("EXIT, class=%u\n", *class);
return 0;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 027/152] drivers/libata: Set max sector to 65535 for Slimtype DVD A DS8A9SH drive
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (25 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 026/152] ahci: disabled FBS prior to issuing software reset Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 028/152] NFSv4: fix NULL dereference in open recover Kamal Mostafa
` (124 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Shan Hai, Tejun Heo, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Shan Hai <shan.hai@windriver.com>
commit 0523f037f65dba10191b0fa9c51266f90ba64630 upstream.
The "Slimtype DVD A DS8A9SH" drive locks up with following backtrace when
the max sector is smaller than 65535 bytes, fix it by adding a quirk to set
the max sector to 65535 bytes.
INFO: task flush-11:0:663 blocked for more than 120 seconds.
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
flush-11:0 D 00000000ffff5ceb 0 663 2 0x00000000
ffff88026d3b1710 0000000000000046 0000000000000001 0000000000000000
ffff88026f2530c0 ffff88026d365860 ffff88026d3b16e0 ffffffff812ffd52
ffff88026d4fd3d0 0000000100000001 ffff88026d3b16f0 ffff88026d3b1fd8
Call Trace:
[<ffffffff812ffd52>] ? cfq_may_queue+0x52/0xf0
[<ffffffff81604338>] schedule+0x18/0x30
[<ffffffff81604392>] io_schedule+0x42/0x60
[<ffffffff812f22bb>] get_request_wait+0xeb/0x1f0
[<ffffffff81065660>] ? autoremove_wake_function+0x0/0x40
[<ffffffff812eb382>] ? elv_merge+0x42/0x210
[<ffffffff812f26ae>] __make_request+0x8e/0x4e0
[<ffffffff812f068e>] generic_make_request+0x21e/0x5e0
[<ffffffff812f0aad>] submit_bio+0x5d/0xd0
[<ffffffff81141422>] submit_bh+0xf2/0x130
[<ffffffff8114474c>] __block_write_full_page+0x1dc/0x3a0
[<ffffffff81143f60>] ? end_buffer_async_write+0x0/0x120
[<ffffffff811474e0>] ? blkdev_get_block+0x0/0x70
[<ffffffff811474e0>] ? blkdev_get_block+0x0/0x70
[<ffffffff81143f60>] ? end_buffer_async_write+0x0/0x120
[<ffffffff811449ee>] block_write_full_page_endio+0xde/0x100
[<ffffffff81144a20>] block_write_full_page+0x10/0x20
[<ffffffff81148703>] blkdev_writepage+0x13/0x20
[<ffffffff810d7525>] __writepage+0x15/0x40
[<ffffffff810d7c0f>] write_cache_pages+0x1cf/0x3e0
[<ffffffff810d7510>] ? __writepage+0x0/0x40
[<ffffffff810d7e42>] generic_writepages+0x22/0x30
[<ffffffff810d7e6f>] do_writepages+0x1f/0x40
[<ffffffff8113ae67>] writeback_single_inode+0xe7/0x3b0
[<ffffffff8113b574>] writeback_sb_inodes+0x184/0x280
[<ffffffff8113bedb>] writeback_inodes_wb+0x6b/0x1a0
[<ffffffff8113c24b>] wb_writeback+0x23b/0x2a0
[<ffffffff8113c42d>] wb_do_writeback+0x17d/0x190
[<ffffffff8113c48b>] bdi_writeback_task+0x4b/0xe0
[<ffffffff810e82a0>] ? bdi_start_fn+0x0/0x100
[<ffffffff810e8321>] bdi_start_fn+0x81/0x100
[<ffffffff810e82a0>] ? bdi_start_fn+0x0/0x100
[<ffffffff8106522e>] kthread+0x8e/0xa0
[<ffffffff81039274>] ? finish_task_switch+0x54/0xc0
[<ffffffff81003334>] kernel_thread_helper+0x4/0x10
[<ffffffff810651a0>] ? kthread+0x0/0xa0
[<ffffffff81003330>] ? kernel_thread_helper+0x0/0x10
The above trace was triggered by
"dd if=/dev/zero of=/dev/sr0 bs=2048 count=32768"
Signed-off-by: Shan Hai <shan.hai@windriver.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/ata/libata-core.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/ata/libata-core.c b/drivers/ata/libata-core.c
index 5866bf5..d32d6bb 100644
--- a/drivers/ata/libata-core.c
+++ b/drivers/ata/libata-core.c
@@ -4108,6 +4108,7 @@ static const struct ata_blacklist_entry ata_device_blacklist [] = {
{ "TORiSAN DVD-ROM DRD-N216", NULL, ATA_HORKAGE_MAX_SEC_128 },
{ "QUANTUM DAT DAT72-000", NULL, ATA_HORKAGE_ATAPI_MOD16_DMA },
{ "Slimtype DVD A DS8A8SH", NULL, ATA_HORKAGE_MAX_SEC_LBA48 },
+ { "Slimtype DVD A DS8A9SH", NULL, ATA_HORKAGE_MAX_SEC_LBA48 },
/* Devices we expect to fail diagnostics */
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 028/152] NFSv4: fix NULL dereference in open recover
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (26 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 027/152] drivers/libata: Set max sector to 65535 for Slimtype DVD A DS8A9SH drive Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 029/152] ALSA: 6fire: Fix probe of multiple cards Kamal Mostafa
` (123 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Weston Andros Adamson, Trond Myklebust, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Weston Andros Adamson <dros@netapp.com>
commit f494a6071d31e3294a3b51ad7a3684f983953f9f upstream.
_nfs4_opendata_reclaim_to_nfs4_state doesn't expect to see a cached
open CLAIM_PREVIOUS, but this can happen. An example is when there are
RDWR openers and RDONLY openers on a delegation stateid. The recovery
path will first try an open CLAIM_PREVIOUS for the RDWR openers, this
marks the delegation as not needing RECLAIM anymore, so the open
CLAIM_PREVIOUS for the RDONLY openers will not actually send an rpc.
The NULL dereference is due to _nfs4_opendata_reclaim_to_nfs4_state
returning PTR_ERR(rpc_status) when !rpc_done. When the open is
cached, rpc_done == 0 and rpc_status == 0, thus
_nfs4_opendata_reclaim_to_nfs4_state returns NULL - this is unexpected
by callers of nfs4_opendata_to_nfs4_state().
This can be reproduced easily by opening the same file two times on an
NFSv4.0 mount with delegations enabled, once as RDWR and once as RDONLY then
sleeping for a long time. While the files are held open, kick off state
recovery and this NULL dereference will be hit every time.
An example OOPS:
[ 65.003602] BUG: unable to handle kernel NULL pointer dereference at 00000000
00000030
[ 65.005312] IP: [<ffffffffa037d6ee>] __nfs4_close+0x1e/0x160 [nfsv4]
[ 65.006820] PGD 7b0ea067 PUD 791ff067 PMD 0
[ 65.008075] Oops: 0000 [#1] SMP
[ 65.008802] Modules linked in: rpcsec_gss_krb5 nfsv4 dns_resolver nfs fscache
snd_ens1371 gameport nfsd snd_rawmidi snd_ac97_codec ac97_bus btusb snd_seq snd
_seq_device snd_pcm ppdev bluetooth auth_rpcgss coretemp snd_page_alloc crc32_pc
lmul crc32c_intel ghash_clmulni_intel microcode rfkill nfs_acl vmw_balloon serio
_raw snd_timer lockd parport_pc e1000 snd soundcore parport i2c_piix4 shpchp vmw
_vmci sunrpc ata_generic mperf pata_acpi mptspi vmwgfx ttm scsi_transport_spi dr
m mptscsih mptbase i2c_core
[ 65.018684] CPU: 0 PID: 473 Comm: 192.168.10.85-m Not tainted 3.11.2-201.fc19
.x86_64 #1
[ 65.020113] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop
Reference Platform, BIOS 6.00 07/31/2013
[ 65.022012] task: ffff88003707e320 ti: ffff88007b906000 task.ti: ffff88007b906000
[ 65.023414] RIP: 0010:[<ffffffffa037d6ee>] [<ffffffffa037d6ee>] __nfs4_close+0x1e/0x160 [nfsv4]
[ 65.025079] RSP: 0018:ffff88007b907d10 EFLAGS: 00010246
[ 65.026042] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
[ 65.027321] RDX: 0000000000000050 RSI: 0000000000000001 RDI: 0000000000000000
[ 65.028691] RBP: ffff88007b907d38 R08: 0000000000016f60 R09: 0000000000000000
[ 65.029990] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000001
[ 65.031295] R13: 0000000000000050 R14: 0000000000000000 R15: 0000000000000001
[ 65.032527] FS: 0000000000000000(0000) GS:ffff88007f600000(0000) knlGS:0000000000000000
[ 65.033981] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 65.035177] CR2: 0000000000000030 CR3: 000000007b27f000 CR4: 00000000000407f0
[ 65.036568] Stack:
[ 65.037011] 0000000000000000 0000000000000001 ffff88007b907d90 ffff88007a880220
[ 65.038472] ffff88007b768de8 ffff88007b907d48 ffffffffa037e4a5 ffff88007b907d80
[ 65.039935] ffffffffa036a6c8 ffff880037020e40 ffff88007a880000 ffff880037020e40
[ 65.041468] Call Trace:
[ 65.042050] [<ffffffffa037e4a5>] nfs4_close_state+0x15/0x20 [nfsv4]
[ 65.043209] [<ffffffffa036a6c8>] nfs4_open_recover_helper+0x148/0x1f0 [nfsv4]
[ 65.044529] [<ffffffffa036a886>] nfs4_open_recover+0x116/0x150 [nfsv4]
[ 65.045730] [<ffffffffa036d98d>] nfs4_open_reclaim+0xad/0x150 [nfsv4]
[ 65.046905] [<ffffffffa037d979>] nfs4_do_reclaim+0x149/0x5f0 [nfsv4]
[ 65.048071] [<ffffffffa037e1dc>] nfs4_run_state_manager+0x3bc/0x670 [nfsv4]
[ 65.049436] [<ffffffffa037de20>] ? nfs4_do_reclaim+0x5f0/0x5f0 [nfsv4]
[ 65.050686] [<ffffffffa037de20>] ? nfs4_do_reclaim+0x5f0/0x5f0 [nfsv4]
[ 65.051943] [<ffffffff81088640>] kthread+0xc0/0xd0
[ 65.052831] [<ffffffff81088580>] ? insert_kthread_work+0x40/0x40
[ 65.054697] [<ffffffff8165686c>] ret_from_fork+0x7c/0xb0
[ 65.056396] [<ffffffff81088580>] ? insert_kthread_work+0x40/0x40
[ 65.058208] Code: 5c 41 5d 5d c3 0f 1f 84 00 00 00 00 00 66 66 66 66 90 55 48 89 e5 41 57 41 89 f7 41 56 41 89 ce 41 55 41 89 d5 41 54 53 48 89 fb <4c> 8b 67 30 f0 41 ff 44 24 44 49 8d 7c 24 40 e8 0e 0a 2d e1 44
[ 65.065225] RIP [<ffffffffa037d6ee>] __nfs4_close+0x1e/0x160 [nfsv4]
[ 65.067175] RSP <ffff88007b907d10>
[ 65.068570] CR2: 0000000000000030
[ 65.070098] ---[ end trace 0d1fe4f5c7dd6f8b ]---
Signed-off-by: Weston Andros Adamson <dros@netapp.com>
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
fs/nfs/nfs4proc.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/nfs/nfs4proc.c b/fs/nfs/nfs4proc.c
index ecc6f12..ef31b6b 100644
--- a/fs/nfs/nfs4proc.c
+++ b/fs/nfs/nfs4proc.c
@@ -1095,7 +1095,8 @@ _nfs4_opendata_reclaim_to_nfs4_state(struct nfs4_opendata *data)
struct nfs4_state *state = data->state;
int ret;
- if (!data->rpc_done) {
+ /* allow cached opens (!rpc_done && !rpc_status) */
+ if (!data->rpc_done && data->rpc_status) {
ret = data->rpc_status;
goto err;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 029/152] ALSA: 6fire: Fix probe of multiple cards
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (27 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 028/152] NFSv4: fix NULL dereference in open recover Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 030/152] ARM: sa11x0/assabet: ensure CS2 is configured appropriately Kamal Mostafa
` (122 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Takashi Iwai, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit 9b389a8a022110b4bc055a19b888283544d9eba6 upstream.
The probe code of snd-usb-6fire driver overrides the devices[] pointer
wrongly without checking whether it's already occupied or not. This
would screw up the device disconnection later.
Spotted by coverity CID 141423.
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/usb/6fire/chip.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/usb/6fire/chip.c b/sound/usb/6fire/chip.c
index 4394ae7..0716ba6 100644
--- a/sound/usb/6fire/chip.c
+++ b/sound/usb/6fire/chip.c
@@ -101,7 +101,7 @@ static int usb6fire_chip_probe(struct usb_interface *intf,
usb_set_intfdata(intf, chips[i]);
mutex_unlock(®ister_mutex);
return 0;
- } else if (regidx < 0)
+ } else if (!devices[i] && regidx < 0)
regidx = i;
}
if (regidx < 0) {
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 030/152] ARM: sa11x0/assabet: ensure CS2 is configured appropriately
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (28 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 029/152] ALSA: 6fire: Fix probe of multiple cards Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 031/152] usb: wusbcore: set the RPIPE wMaxPacketSize value correctly Kamal Mostafa
` (121 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Russell King, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Russell King <rmk+kernel@arm.linux.org.uk>
commit f3964fe1c9d9a887d65faf594669852e4dec46e0 upstream.
The CS2 region contains the Assabet board configuration and status
registers, which are 32-bit. Unfortunately, some boot loaders do not
configure this region correctly, leaving it setup as a 16-bit region.
Fix this.
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/arm/mach-sa1100/assabet.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/arch/arm/mach-sa1100/assabet.c b/arch/arm/mach-sa1100/assabet.c
index 9a23739..45628dd 100644
--- a/arch/arm/mach-sa1100/assabet.c
+++ b/arch/arm/mach-sa1100/assabet.c
@@ -511,6 +511,9 @@ static void __init assabet_map_io(void)
* Its called GPCLKR0 in my SA1110 manual.
*/
Ser1SDCR0 |= SDCR0_SUS;
+ MSC1 = (MSC1 & ~0xffff) |
+ MSC_NonBrst | MSC_32BitStMem |
+ MSC_RdAcc(2) | MSC_WrAcc(2) | MSC_Rec(0);
if (!machine_has_neponset())
sa1100_register_uart_fns(&assabet_port_fns);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 031/152] usb: wusbcore: set the RPIPE wMaxPacketSize value correctly
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (29 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 030/152] ARM: sa11x0/assabet: ensure CS2 is configured appropriately Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 032/152] usb: wusbcore: change WA_SEGS_MAX to a legal value Kamal Mostafa
` (120 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Thomas Pugliese, Greg Kroah-Hartman, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Pugliese <thomas.pugliese@gmail.com>
commit 7b6bc07ab554e929c85d51b3d5b26cf7f12c6a3b upstream.
For isochronous endpoints, set the RPIPE wMaxPacketSize value using
wOverTheAirPacketSize from the endpoint companion descriptor instead of
wMaxPacketSize from the normal endpoint descriptor.
Signed-off-by: Thomas Pugliese <thomas.pugliese@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ kamal: backport to 3.8 (context) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/usb/wusbcore/wa-rpipe.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/usb/wusbcore/wa-rpipe.c b/drivers/usb/wusbcore/wa-rpipe.c
index f0d546c..ca1031b 100644
--- a/drivers/usb/wusbcore/wa-rpipe.c
+++ b/drivers/usb/wusbcore/wa-rpipe.c
@@ -332,7 +332,10 @@ static int rpipe_aim(struct wa_rpipe *rpipe, struct wahc *wa,
/* FIXME: compute so seg_size > ep->maxpktsize */
rpipe->descr.wBlocks = cpu_to_le16(16); /* given */
/* ep0 maxpktsize is 0x200 (WUSB1.0[4.8.1]) */
- rpipe->descr.wMaxPacketSize = cpu_to_le16(ep->desc.wMaxPacketSize);
+ if (usb_endpoint_xfer_isoc(&ep->desc))
+ rpipe->descr.wMaxPacketSize = epcd->wOverTheAirPacketSize;
+ else
+ rpipe->descr.wMaxPacketSize = ep->desc.wMaxPacketSize;
rpipe->descr.bHSHubAddress = 0; /* reserved: zero */
rpipe->descr.bHSHubPort = wusb_port_no_to_idx(urb->dev->portnum);
/* FIXME: use maximum speed as supported or recommended by device */
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 032/152] usb: wusbcore: change WA_SEGS_MAX to a legal value
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (30 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 031/152] usb: wusbcore: set the RPIPE wMaxPacketSize value correctly Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 033/152] powerpc/vio: use strcpy in modalias_show Kamal Mostafa
` (119 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Thomas Pugliese, Greg Kroah-Hartman, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Pugliese <thomas.pugliese@gmail.com>
commit f74b75e7f920c700636cccca669c7d16d12e9202 upstream.
change WA_SEGS_MAX to a number that is legal according to the WUSB
spec.
Signed-off-by: Thomas Pugliese <thomas.pugliese@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ kamal: backport to 3.8 (context) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/usb/wusbcore/wa-xfer.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/usb/wusbcore/wa-xfer.c b/drivers/usb/wusbcore/wa-xfer.c
index 57c01ab..5f6df6e 100644
--- a/drivers/usb/wusbcore/wa-xfer.c
+++ b/drivers/usb/wusbcore/wa-xfer.c
@@ -90,7 +90,8 @@
#include "wusbhc.h"
enum {
- WA_SEGS_MAX = 255,
+ /* [WUSB] section 8.3.3 allocates 7 bits for the segment index. */
+ WA_SEGS_MAX = 128,
};
enum wa_seg_status {
@@ -444,7 +445,7 @@ static ssize_t __wa_xfer_setup_sizes(struct wa_xfer *xfer,
xfer->seg_size = (xfer->seg_size / maxpktsize) * maxpktsize;
xfer->segs = (urb->transfer_buffer_length + xfer->seg_size - 1)
/ xfer->seg_size;
- if (xfer->segs >= WA_SEGS_MAX) {
+ if (xfer->segs > WA_SEGS_MAX) {
dev_err(dev, "BUG? ops, number of segments %d bigger than %d\n",
(int)(urb->transfer_buffer_length / xfer->seg_size),
WA_SEGS_MAX);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 033/152] powerpc/vio: use strcpy in modalias_show
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (31 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 032/152] usb: wusbcore: change WA_SEGS_MAX to a legal value Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 034/152] i2c: mux: gpio: use gpio_set_value_cansleep() Kamal Mostafa
` (118 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: benh, ben, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Prarit Bhargava <prarit@redhat.com>
commit 411cabf79e684171669ad29a0628c400b4431e95 upstream.
Commit e82b89a6f19bae73fb064d1b3dd91fcefbb478f4 used strcat instead of
strcpy which can result in an overflow of newlines on the buffer.
Signed-off-by: Prarit Bhargava
Cc: benh@kernel.crashing.org
Cc: ben@decadent.org.uk
Signed-off-by: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/powerpc/kernel/vio.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/powerpc/kernel/vio.c b/arch/powerpc/kernel/vio.c
index 2d845d8..56d2e72 100644
--- a/arch/powerpc/kernel/vio.c
+++ b/arch/powerpc/kernel/vio.c
@@ -1530,12 +1530,12 @@ static ssize_t modalias_show(struct device *dev, struct device_attribute *attr,
dn = dev->of_node;
if (!dn) {
- strcat(buf, "\n");
+ strcpy(buf, "\n");
return strlen(buf);
}
cp = of_get_property(dn, "compatible", NULL);
if (!cp) {
- strcat(buf, "\n");
+ strcpy(buf, "\n");
return strlen(buf);
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 034/152] i2c: mux: gpio: use gpio_set_value_cansleep()
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (32 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 033/152] powerpc/vio: use strcpy in modalias_show Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 035/152] i2c: mux: gpio: use reg value for i2c_add_mux_adapter Kamal Mostafa
` (117 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Ionut Nicu, Wolfram Sang, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ionut Nicu <ioan.nicu.ext@nsn.com>
commit 250ad590d6f12d93f4d85be305b0a598d609232e upstream.
Some gpio chips may have get/set operations that
can sleep. gpio_set_value() only works for chips
which do not sleep, for the others we will get a
kernel warning. Using gpio_set_value_cansleep()
will work for both chips that do sleep and those
who don't.
Signed-off-by: Ionut Nicu <ioan.nicu.ext@nsn.com>
Acked-by: Peter Korsgaard <peter.korsgaard@barco.com>
Signed-off-by: Wolfram Sang <wsa@the-dreams.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/i2c/muxes/i2c-mux-gpio.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/i2c/muxes/i2c-mux-gpio.c b/drivers/i2c/muxes/i2c-mux-gpio.c
index 9f50ef0..61da6b4 100644
--- a/drivers/i2c/muxes/i2c-mux-gpio.c
+++ b/drivers/i2c/muxes/i2c-mux-gpio.c
@@ -31,8 +31,8 @@ static void i2c_mux_gpio_set(const struct gpiomux *mux, unsigned val)
int i;
for (i = 0; i < mux->data.n_gpios; i++)
- gpio_set_value(mux->gpio_base + mux->data.gpios[i],
- val & (1 << i));
+ gpio_set_value_cansleep(mux->gpio_base + mux->data.gpios[i],
+ val & (1 << i));
}
static int i2c_mux_gpio_select(struct i2c_adapter *adap, void *data, u32 chan)
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 035/152] i2c: mux: gpio: use reg value for i2c_add_mux_adapter
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (33 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 034/152] i2c: mux: gpio: use gpio_set_value_cansleep() Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 036/152] s390/vtime: correct idle time calculation Kamal Mostafa
` (116 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Ionut Nicu, Wolfram Sang, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ionut Nicu <ioan.nicu.ext@nsn.com>
commit 8c0ec2500eeb89749341884a972860d7f9e56f9c upstream.
The i2c-mux driver requires that the chan_id parameter
passed to the i2c_add_mux_adapter() function is equal
to the reg value for that adapter:
for_each_child_of_node(mux_dev->of_node, child) {
ret = of_property_read_u32(child, "reg", ®);
if (ret)
continue;
if (chan_id == reg) {
priv->adap.dev.of_node = child;
break;
}
}
The i2c-mux-gpio driver uses an internal logical index
for chan_id when calling i2c_add_mux_adapter() instead
of using the reg value.
Because of this, there will problems in selecting the
right adapter when the i2c-mux-gpio's index into
mux->data.values doesn't match the reg value.
An example of such a case:
mux->data.values = { 1, 0 }
For chan_id = 0, i2c-mux will bind the adapter to the
of_node with reg = <0>, but when it will call the
select() callback with chan_id set to 0, the i2c-mux-gpio
will use it as an index into mux->data.values and it will
actually select the bus with reg = <1>.
Signed-off-by: Ionut Nicu <ioan.nicu.ext@nsn.com>
Acked-by: Alexander Sverdlin <alexander.sverdlin@nsn.com>
Signed-off-by: Wolfram Sang <wsa@the-dreams.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/i2c/muxes/i2c-mux-gpio.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/i2c/muxes/i2c-mux-gpio.c b/drivers/i2c/muxes/i2c-mux-gpio.c
index 61da6b4..4c3db19 100644
--- a/drivers/i2c/muxes/i2c-mux-gpio.c
+++ b/drivers/i2c/muxes/i2c-mux-gpio.c
@@ -39,7 +39,7 @@ static int i2c_mux_gpio_select(struct i2c_adapter *adap, void *data, u32 chan)
{
struct gpiomux *mux = data;
- i2c_mux_gpio_set(mux, mux->data.values[chan]);
+ i2c_mux_gpio_set(mux, chan);
return 0;
}
@@ -212,7 +212,7 @@ static int i2c_mux_gpio_probe(struct platform_device *pdev)
unsigned int class = mux->data.classes ? mux->data.classes[i] : 0;
mux->adap[i] = i2c_add_mux_adapter(parent, &pdev->dev, mux, nr,
- i, class,
+ mux->data.values[i], class,
i2c_mux_gpio_select, deselect);
if (!mux->adap[i]) {
ret = -ENODEV;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 036/152] s390/vtime: correct idle time calculation
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (34 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 035/152] i2c: mux: gpio: use reg value for i2c_add_mux_adapter Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 037/152] dm: allocate buffer for messages with small number of arguments using GFP_NOIO Kamal Mostafa
` (115 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Martin Schwidefsky, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Martin Schwidefsky <schwidefsky@de.ibm.com>
commit 4560e7c3317c7a2b370e36dadd3a3bac2ed70818 upstream.
Use the ACCESS_ONCE macro for both accesses to idle->sequence in the
loops to calculate the idle time. If only one access uses the macro,
the compiler is free to cache the value for the second access which
can cause endless loops.
Signed-off-by: Martin Schwidefsky <schwidefsky@de.ibm.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/s390/kernel/smp.c | 4 ++--
arch/s390/kernel/vtime.c | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/arch/s390/kernel/smp.c b/arch/s390/kernel/smp.c
index 7433a2f..8341c28 100644
--- a/arch/s390/kernel/smp.c
+++ b/arch/s390/kernel/smp.c
@@ -934,7 +934,7 @@ static ssize_t show_idle_count(struct device *dev,
idle_count = ACCESS_ONCE(idle->idle_count);
if (ACCESS_ONCE(idle->clock_idle_enter))
idle_count++;
- } while ((sequence & 1) || (idle->sequence != sequence));
+ } while ((sequence & 1) || (ACCESS_ONCE(idle->sequence) != sequence));
return sprintf(buf, "%llu\n", idle_count);
}
static DEVICE_ATTR(idle_count, 0444, show_idle_count, NULL);
@@ -952,7 +952,7 @@ static ssize_t show_idle_time(struct device *dev,
idle_time = ACCESS_ONCE(idle->idle_time);
idle_enter = ACCESS_ONCE(idle->clock_idle_enter);
idle_exit = ACCESS_ONCE(idle->clock_idle_exit);
- } while ((sequence & 1) || (idle->sequence != sequence));
+ } while ((sequence & 1) || (ACCESS_ONCE(idle->sequence) != sequence));
idle_time += idle_enter ? ((idle_exit ? : now) - idle_enter) : 0;
return sprintf(buf, "%llu\n", idle_time >> 12);
}
diff --git a/arch/s390/kernel/vtime.c b/arch/s390/kernel/vtime.c
index e84b8b6..2fc9deb 100644
--- a/arch/s390/kernel/vtime.c
+++ b/arch/s390/kernel/vtime.c
@@ -195,7 +195,7 @@ cputime64_t s390_get_idle_time(int cpu)
sequence = ACCESS_ONCE(idle->sequence);
idle_enter = ACCESS_ONCE(idle->clock_idle_enter);
idle_exit = ACCESS_ONCE(idle->clock_idle_exit);
- } while ((sequence & 1) || (idle->sequence != sequence));
+ } while ((sequence & 1) || (ACCESS_ONCE(idle->sequence) != sequence));
return idle_enter ? ((idle_exit ?: now) - idle_enter) : 0;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 037/152] dm: allocate buffer for messages with small number of arguments using GFP_NOIO
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (35 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 036/152] s390/vtime: correct idle time calculation Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 038/152] can: c_can: Fix RX message handling, handle lost message before EOB Kamal Mostafa
` (114 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Mikulas Patocka, Mike Snitzer, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikulas Patocka <mpatocka@redhat.com>
commit f36afb3957353d2529cb2b00f78fdccd14fc5e9c upstream.
dm-mpath and dm-thin must process messages even if some device is
suspended, so we allocate argv buffer with GFP_NOIO. These messages have
a small fixed number of arguments.
On the other hand, dm-switch needs to process bulk data using messages
so excessive use of GFP_NOIO could cause trouble.
The patch also lowers the default number of arguments from 64 to 8, so
that there is smaller load on GFP_NOIO allocations.
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Acked-by: Alasdair G Kergon <agk@redhat.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/md/dm-table.c | 18 ++++++++++++++++--
1 file changed, 16 insertions(+), 2 deletions(-)
diff --git a/drivers/md/dm-table.c b/drivers/md/dm-table.c
index 62545f6..ee51e08 100644
--- a/drivers/md/dm-table.c
+++ b/drivers/md/dm-table.c
@@ -581,14 +581,28 @@ static int adjoin(struct dm_table *table, struct dm_target *ti)
/*
* Used to dynamically allocate the arg array.
+ *
+ * We do first allocation with GFP_NOIO because dm-mpath and dm-thin must
+ * process messages even if some device is suspended. These messages have a
+ * small fixed number of arguments.
+ *
+ * On the other hand, dm-switch needs to process bulk data using messages and
+ * excessive use of GFP_NOIO could cause trouble.
*/
static char **realloc_argv(unsigned *array_size, char **old_argv)
{
char **argv;
unsigned new_size;
+ gfp_t gfp;
- new_size = *array_size ? *array_size * 2 : 64;
- argv = kmalloc(new_size * sizeof(*argv), GFP_KERNEL);
+ if (*array_size) {
+ new_size = *array_size * 2;
+ gfp = GFP_KERNEL;
+ } else {
+ new_size = 8;
+ gfp = GFP_NOIO;
+ }
+ argv = kmalloc(new_size * sizeof(*argv), gfp);
if (argv) {
memcpy(argv, old_argv, *array_size * sizeof(*argv));
*array_size = new_size;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 038/152] can: c_can: Fix RX message handling, handle lost message before EOB
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (36 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 037/152] dm: allocate buffer for messages with small number of arguments using GFP_NOIO Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 039/152] can: kvaser_usb: fix usb endpoints detection Kamal Mostafa
` (113 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Markus Pargmann, Marc Kleine-Budde, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Markus Pargmann <mpa@pengutronix.de>
commit 5d0f801a2ccec3b1fdabc3392c8d99ed0413d216 upstream.
If we handle end of block messages with higher priority than a lost message,
we can run into an endless interrupt loop.
This is reproducable with a am335x processor and "cansequence -r" at 1Mbit.
As soon as we loose a packet we can't escape from an interrupt loop.
This patch fixes the problem by handling lost packets before EOB packets.
Signed-off-by: Markus Pargmann <mpa@pengutronix.de>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/can/c_can/c_can.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/net/can/c_can/c_can.c b/drivers/net/can/c_can/c_can.c
index 2282b1a..915847d 100644
--- a/drivers/net/can/c_can/c_can.c
+++ b/drivers/net/can/c_can/c_can.c
@@ -810,9 +810,6 @@ static int c_can_do_rx_poll(struct net_device *dev, int quota)
msg_ctrl_save = priv->read_reg(priv,
C_CAN_IFACE(MSGCTRL_REG, 0));
- if (msg_ctrl_save & IF_MCONT_EOB)
- return num_rx_pkts;
-
if (msg_ctrl_save & IF_MCONT_MSGLST) {
c_can_handle_lost_msg_obj(dev, 0, msg_obj);
num_rx_pkts++;
@@ -820,6 +817,9 @@ static int c_can_do_rx_poll(struct net_device *dev, int quota)
continue;
}
+ if (msg_ctrl_save & IF_MCONT_EOB)
+ return num_rx_pkts;
+
if (!(msg_ctrl_save & IF_MCONT_NEWDAT))
continue;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 039/152] can: kvaser_usb: fix usb endpoints detection
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (37 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 038/152] can: c_can: Fix RX message handling, handle lost message before EOB Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 040/152] dm mpath: fix race condition between multipath_dtr and pg_init_done Kamal Mostafa
` (112 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Olivier Sobrie, Marc Kleine-Budde, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Olivier Sobrie <olivier@sobrie.be>
commit 896e23bd04ea50a146dffd342e2f96180f0812a5 upstream.
Some devices, like the Kvaser Memorator Professional, have several bulk in
endpoints. Only the first one found must be used by the driver. The same holds
for the bulk out endpoint. The official Kvaser driver (leaf) was used as
reference for this patch.
Signed-off-by: Olivier Sobrie <olivier@sobrie.be>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/can/usb/kvaser_usb.c | 20 +++++++++++++-------
1 file changed, 13 insertions(+), 7 deletions(-)
diff --git a/drivers/net/can/usb/kvaser_usb.c b/drivers/net/can/usb/kvaser_usb.c
index 20b5a3a..431f07e 100644
--- a/drivers/net/can/usb/kvaser_usb.c
+++ b/drivers/net/can/usb/kvaser_usb.c
@@ -1546,9 +1546,9 @@ static int kvaser_usb_init_one(struct usb_interface *intf,
return 0;
}
-static void kvaser_usb_get_endpoints(const struct usb_interface *intf,
- struct usb_endpoint_descriptor **in,
- struct usb_endpoint_descriptor **out)
+static int kvaser_usb_get_endpoints(const struct usb_interface *intf,
+ struct usb_endpoint_descriptor **in,
+ struct usb_endpoint_descriptor **out)
{
const struct usb_host_interface *iface_desc;
struct usb_endpoint_descriptor *endpoint;
@@ -1559,12 +1559,18 @@ static void kvaser_usb_get_endpoints(const struct usb_interface *intf,
for (i = 0; i < iface_desc->desc.bNumEndpoints; ++i) {
endpoint = &iface_desc->endpoint[i].desc;
- if (usb_endpoint_is_bulk_in(endpoint))
+ if (!*in && usb_endpoint_is_bulk_in(endpoint))
*in = endpoint;
- if (usb_endpoint_is_bulk_out(endpoint))
+ if (!*out && usb_endpoint_is_bulk_out(endpoint))
*out = endpoint;
+
+ /* use first bulk endpoint for in and out */
+ if (*in && *out)
+ return 0;
}
+
+ return -ENODEV;
}
static int kvaser_usb_probe(struct usb_interface *intf,
@@ -1578,8 +1584,8 @@ static int kvaser_usb_probe(struct usb_interface *intf,
if (!dev)
return -ENOMEM;
- kvaser_usb_get_endpoints(intf, &dev->bulk_in, &dev->bulk_out);
- if (!dev->bulk_in || !dev->bulk_out) {
+ err = kvaser_usb_get_endpoints(intf, &dev->bulk_in, &dev->bulk_out);
+ if (err) {
dev_err(&intf->dev, "Cannot get usb endpoint(s)");
return err;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 040/152] dm mpath: fix race condition between multipath_dtr and pg_init_done
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (38 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 039/152] can: kvaser_usb: fix usb endpoints detection Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 041/152] ext4: avoid bh leak in retry path of ext4_expand_extra_isize_ea() Kamal Mostafa
` (111 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Shiva Krishna Merla, Mike Snitzer, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Shiva Krishna Merla <shivakrishna.merla@netapp.com>
commit 954a73d5d3073df2231820c718fdd2f18b0fe4c9 upstream.
Whenever multipath_dtr() is happening we must prevent queueing any
further path activation work. Implement this by adding a new
'pg_init_disabled' flag to the multipath structure that denotes future
path activation work should be skipped if it is set. By disabling
pg_init and then re-enabling in flush_multipath_work() we also avoid the
potential for pg_init to be initiated while suspending an mpath device.
Without this patch a race condition exists that may result in a kernel
panic:
1) If after pg_init_done() decrements pg_init_in_progress to 0, a call
to wait_for_pg_init_completion() assumes there are no more pending path
management commands.
2) If pg_init_required is set by pg_init_done(), due to retryable
mode_select errors, then process_queued_ios() will again queue the
path activation work.
3) If free_multipath() completes before activate_path() work is called a
NULL pointer dereference like the following can be seen when
accessing members of the recently destructed multipath:
BUG: unable to handle kernel NULL pointer dereference at 0000000000000090
RIP: 0010:[<ffffffffa003db1b>] [<ffffffffa003db1b>] activate_path+0x1b/0x30 [dm_multipath]
[<ffffffff81090ac0>] worker_thread+0x170/0x2a0
[<ffffffff81096c80>] ? autoremove_wake_function+0x0/0x40
[switch to disabling pg_init in flush_multipath_work & header edits by Mike Snitzer]
Signed-off-by: Shiva Krishna Merla <shivakrishna.merla@netapp.com>
Reviewed-by: Krishnasamy Somasundaram <somasundaram.krishnasamy@netapp.com>
Tested-by: Speagle Andy <Andy.Speagle@netapp.com>
Acked-by: Junichi Nomura <j-nomura@ce.jp.nec.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/md/dm-mpath.c | 18 +++++++++++++++---
1 file changed, 15 insertions(+), 3 deletions(-)
diff --git a/drivers/md/dm-mpath.c b/drivers/md/dm-mpath.c
index 9f330c1..9d11b4e 100644
--- a/drivers/md/dm-mpath.c
+++ b/drivers/md/dm-mpath.c
@@ -86,6 +86,7 @@ struct multipath {
unsigned queue_if_no_path:1; /* Queue I/O if last path fails? */
unsigned saved_queue_if_no_path:1; /* Saved state during suspension */
unsigned retain_attached_hw_handler:1; /* If there's already a hw_handler present, don't change it. */
+ unsigned pg_init_disabled:1; /* pg_init is not currently allowed */
unsigned pg_init_retries; /* Number of times to retry pg_init */
unsigned pg_init_count; /* Number of times pg_init called */
@@ -497,7 +498,8 @@ static void process_queued_ios(struct work_struct *work)
(!pgpath && !m->queue_if_no_path))
must_queue = 0;
- if (m->pg_init_required && !m->pg_init_in_progress && pgpath)
+ if (m->pg_init_required && !m->pg_init_in_progress && pgpath &&
+ !m->pg_init_disabled)
__pg_init_all_paths(m);
spin_unlock_irqrestore(&m->lock, flags);
@@ -941,10 +943,20 @@ static void multipath_wait_for_pg_init_completion(struct multipath *m)
static void flush_multipath_work(struct multipath *m)
{
+ unsigned long flags;
+
+ spin_lock_irqsave(&m->lock, flags);
+ m->pg_init_disabled = 1;
+ spin_unlock_irqrestore(&m->lock, flags);
+
flush_workqueue(kmpath_handlerd);
multipath_wait_for_pg_init_completion(m);
flush_workqueue(kmultipathd);
flush_work(&m->trigger_event);
+
+ spin_lock_irqsave(&m->lock, flags);
+ m->pg_init_disabled = 0;
+ spin_unlock_irqrestore(&m->lock, flags);
}
static void multipath_dtr(struct dm_target *ti)
@@ -1163,7 +1175,7 @@ static int pg_init_limit_reached(struct multipath *m, struct pgpath *pgpath)
spin_lock_irqsave(&m->lock, flags);
- if (m->pg_init_count <= m->pg_init_retries)
+ if (m->pg_init_count <= m->pg_init_retries && !m->pg_init_disabled)
m->pg_init_required = 1;
else
limit_reached = 1;
@@ -1689,7 +1701,7 @@ out:
*---------------------------------------------------------------*/
static struct target_type multipath_target = {
.name = "multipath",
- .version = {1, 5, 1},
+ .version = {1, 6, 0},
.module = THIS_MODULE,
.ctr = multipath_ctr,
.dtr = multipath_dtr,
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 041/152] ext4: avoid bh leak in retry path of ext4_expand_extra_isize_ea()
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (39 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 040/152] dm mpath: fix race condition between multipath_dtr and pg_init_done Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 042/152] ASoC: ak4642: prevent un-necessary changes to SG_SL1 Kamal Mostafa
` (110 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Theodore Ts'o, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Theodore Ts'o <tytso@mit.edu>
commit dcb9917ba041866686fe152850364826c4622a36 upstream.
Reported-by: Dave Jones <davej@redhat.com>
Signed-off-by: "Theodore Ts'o" <tytso@mit.edu>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
fs/ext4/xattr.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/fs/ext4/xattr.c b/fs/ext4/xattr.c
index f88c442..44f19f3 100644
--- a/fs/ext4/xattr.c
+++ b/fs/ext4/xattr.c
@@ -1358,6 +1358,7 @@ retry:
new_extra_isize = s_min_extra_isize;
kfree(is); is = NULL;
kfree(bs); bs = NULL;
+ brelse(bh);
goto retry;
}
error = -1;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 042/152] ASoC: ak4642: prevent un-necessary changes to SG_SL1
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (40 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 041/152] ext4: avoid bh leak in retry path of ext4_expand_extra_isize_ea() Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 043/152] drm/radeon/si: fix define for MC_SEQ_TRAIN_WAKEUP_CNTL Kamal Mostafa
` (109 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Phil Edworthy, Kuninori Morimoto, Mark Brown, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Phil Edworthy <phil.edworthy@renesas.com>
commit 7b5bfb82882b9b1c8423ce0ed6852ca3762d967a upstream.
If you record the sound during playback,
the playback sound becomes silent.
Modify so that the codec driver does not clear
SG_SL1::DACL bit which is controlled under widget
Signed-off-by: Phil Edworthy <phil.edworthy@renesas.com>
Signed-off-by: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
Signed-off-by: Mark Brown <broonie@linaro.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/soc/codecs/ak4642.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/soc/codecs/ak4642.c b/sound/soc/codecs/ak4642.c
index 1f0cdab..1e09512 100644
--- a/sound/soc/codecs/ak4642.c
+++ b/sound/soc/codecs/ak4642.c
@@ -256,7 +256,7 @@ static int ak4642_dai_startup(struct snd_pcm_substream *substream,
* This operation came from example code of
* "ASAHI KASEI AK4642" (japanese) manual p94.
*/
- snd_soc_write(codec, SG_SL1, PMMP | MGAIN0);
+ snd_soc_update_bits(codec, SG_SL1, PMMP | MGAIN0, PMMP | MGAIN0);
snd_soc_write(codec, TIMER, ZTM(0x3) | WTM(0x3));
snd_soc_write(codec, ALC_CTL1, ALC | LMTH0);
snd_soc_update_bits(codec, PW_MGMT1, PMADL, PMADL);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 043/152] drm/radeon/si: fix define for MC_SEQ_TRAIN_WAKEUP_CNTL
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (41 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 042/152] ASoC: ak4642: prevent un-necessary changes to SG_SL1 Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 044/152] drm/radeon: don't share PPLLs on DCE4.1 Kamal Mostafa
` (108 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Alex Deucher, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Deucher <alexander.deucher@amd.com>
commit d5693761b2b4ff530c8af8af9ec55b6eae76e617 upstream.
Typo in the register offset.
Noticed-by: Sylvain BERTRAND <sylware@legeek.net>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/gpu/drm/radeon/sid.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/radeon/sid.h b/drivers/gpu/drm/radeon/sid.h
index 4767968..c394695 100644
--- a/drivers/gpu/drm/radeon/sid.h
+++ b/drivers/gpu/drm/radeon/sid.h
@@ -200,7 +200,7 @@
#define NOOFGROUPS_SHIFT 12
#define NOOFGROUPS_MASK 0x00001000
-#define MC_SEQ_TRAIN_WAKEUP_CNTL 0x2808
+#define MC_SEQ_TRAIN_WAKEUP_CNTL 0x28e8
#define TRAIN_DONE_D0 (1 << 30)
#define TRAIN_DONE_D1 (1 << 31)
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 044/152] drm/radeon: don't share PPLLs on DCE4.1
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (42 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 043/152] drm/radeon/si: fix define for MC_SEQ_TRAIN_WAKEUP_CNTL Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 045/152] KVM: x86: fix emulation of "movzbl %bpl, %eax" Kamal Mostafa
` (107 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Alex Deucher, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Deucher <alexander.deucher@amd.com>
commit 70471860ff9f335c60c004d42ebd48945bfa5403 upstream.
Sharing PPLLs seems to cause problems on some boards.
Bug:
https://bugs.freedesktop.org/show_bug.cgi?id=45334
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/gpu/drm/radeon/atombios_crtc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/radeon/atombios_crtc.c b/drivers/gpu/drm/radeon/atombios_crtc.c
index 6d6fdb3..ef32bf6 100644
--- a/drivers/gpu/drm/radeon/atombios_crtc.c
+++ b/drivers/gpu/drm/radeon/atombios_crtc.c
@@ -1683,7 +1683,7 @@ static int radeon_atom_pick_pll(struct drm_crtc *crtc)
if (pll != ATOM_PPLL_INVALID)
return pll;
}
- } else {
+ } else if (!ASIC_IS_DCE41(rdev)) { /* Don't share PLLs on DCE4.1 chips */
/* use the same PPLL for all monitors with the same clock */
pll = radeon_get_shared_nondp_ppll(crtc);
if (pll != ATOM_PPLL_INVALID)
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 045/152] KVM: x86: fix emulation of "movzbl %bpl, %eax"
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (43 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 044/152] drm/radeon: don't share PPLLs on DCE4.1 Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 046/152] ALSA: hda - Enable SPDIF for Acer TravelMate 6293 Kamal Mostafa
` (106 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Gleb Natapov, Paolo Bonzini, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Paolo Bonzini <pbonzini@redhat.com>
commit daf727225b8abfdfe424716abac3d15a3ac5626a upstream.
When I was looking at RHEL5.9's failure to start with
unrestricted_guest=0/emulate_invalid_guest_state=1, I got it working with a
slightly older tree than kvm.git. I now debugged the remaining failure,
which was introduced by commit 660696d1 (KVM: X86 emulator: fix
source operand decoding for 8bit mov[zs]x instructions, 2013-04-24)
introduced a similar mis-emulation to the one in commit 8acb4207 (KVM:
fix sil/dil/bpl/spl in the mod/rm fields, 2013-05-30). The incorrect
decoding occurs in 8-bit movzx/movsx instructions whose 8-bit operand
is sil/dil/bpl/spl.
Needless to say, "movzbl %bpl, %eax" does occur in RHEL5.9's decompression
prolog, just a handful of instructions before finally giving control to
the decompressed vmlinux and getting out of the invalid guest state.
Because OpMem8 bypasses decode_modrm, the same handling of the REX prefix
must be applied to OpMem8.
Reported-by: Michele Baldessari <michele@redhat.com>
Cc: Gleb Natapov <gleb@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Gleb Natapov <gleb@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/x86/kvm/emulate.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/arch/x86/kvm/emulate.c b/arch/x86/kvm/emulate.c
index d330b3c..c047b35 100644
--- a/arch/x86/kvm/emulate.c
+++ b/arch/x86/kvm/emulate.c
@@ -4031,7 +4031,10 @@ static int decode_operand(struct x86_emulate_ctxt *ctxt, struct operand *op,
case OpMem8:
ctxt->memop.bytes = 1;
if (ctxt->memop.type == OP_REG) {
- ctxt->memop.addr.reg = decode_register(ctxt, ctxt->modrm_rm, 1);
+ int highbyte_regs = ctxt->rex_prefix == 0;
+
+ ctxt->memop.addr.reg = decode_register(ctxt, ctxt->modrm_rm,
+ highbyte_regs);
fetch_register_operand(&ctxt->memop);
}
goto mem_common;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 046/152] ALSA: hda - Enable SPDIF for Acer TravelMate 6293
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (44 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 045/152] KVM: x86: fix emulation of "movzbl %bpl, %eax" Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 047/152] ahci: Add Device IDs for Intel Wildcat Point-LP Kamal Mostafa
` (105 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Takashi Iwai, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit 24eff328f65c8ef352c90b6adb7c2f39eb94205d upstream.
BIOS on Acer TravelMate 6293 doesn't set up the SPDIF output pin
correctly as default, so enable it via a fixup entry.
Reported-and-tested-by: Hagen Heiduck <heiduck.suse@fmail.postpro.net>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/pci/hda/patch_realtek.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index fe2138d..500c00a 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -5687,6 +5687,7 @@ static const struct hda_verb alc268_beep_init_verbs[] = {
enum {
ALC268_FIXUP_INV_DMIC,
ALC268_FIXUP_HP_EAPD,
+ ALC268_FIXUP_SPDIF,
};
static const struct alc_fixup alc268_fixups[] = {
@@ -5701,6 +5702,13 @@ static const struct alc_fixup alc268_fixups[] = {
{}
}
},
+ [ALC268_FIXUP_SPDIF] = {
+ .type = HDA_FIXUP_PINS,
+ .v.pins = (const struct hda_pintbl[]) {
+ { 0x1e, 0x014b1180 }, /* enable SPDIF out */
+ {}
+ }
+ },
};
static const struct alc_model_fixup alc268_fixup_models[] = {
@@ -5710,6 +5718,7 @@ static const struct alc_model_fixup alc268_fixup_models[] = {
};
static const struct snd_pci_quirk alc268_fixup_tbl[] = {
+ SND_PCI_QUIRK(0x1025, 0x0139, "Acer TravelMate 6293", ALC268_FIXUP_SPDIF),
SND_PCI_QUIRK(0x1025, 0x015b, "Acer AOA 150 (ZG5)", ALC268_FIXUP_INV_DMIC),
/* below is codec SSID since multiple Toshiba laptops have the
* same PCI SSID 1179:ff00
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 047/152] ahci: Add Device IDs for Intel Wildcat Point-LP
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (45 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 046/152] ALSA: hda - Enable SPDIF for Acer TravelMate 6293 Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 048/152] edac, highbank: Fix interrupt setup of mem and l2 controller Kamal Mostafa
` (104 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: James Ralston, Tejun Heo, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: James Ralston <james.d.ralston@intel.com>
commit 9f961a5f6efc87a79571d7166257b36af28ffcfe upstream.
This patch adds the AHCI-mode SATA Device IDs for the Intel Wildcat Point-LP PCH.
Signed-off-by: James Ralston <james.d.ralston@intel.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/ata/ahci.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/ata/ahci.c b/drivers/ata/ahci.c
index d340976..2a870e3 100644
--- a/drivers/ata/ahci.c
+++ b/drivers/ata/ahci.c
@@ -290,6 +290,10 @@ static const struct pci_device_id ahci_pci_tbl[] = {
{ PCI_VDEVICE(INTEL, 0x8d66), board_ahci }, /* Wellsburg RAID */
{ PCI_VDEVICE(INTEL, 0x8d6e), board_ahci }, /* Wellsburg RAID */
{ PCI_VDEVICE(INTEL, 0x23a3), board_ahci }, /* Coleto Creek AHCI */
+ { PCI_VDEVICE(INTEL, 0x9c83), board_ahci }, /* Wildcat Point-LP AHCI */
+ { PCI_VDEVICE(INTEL, 0x9c85), board_ahci }, /* Wildcat Point-LP RAID */
+ { PCI_VDEVICE(INTEL, 0x9c87), board_ahci }, /* Wildcat Point-LP RAID */
+ { PCI_VDEVICE(INTEL, 0x9c8f), board_ahci }, /* Wildcat Point-LP RAID */
/* JMicron 360/1/3/5/6, match class to avoid IDE function */
{ PCI_VENDOR_ID_JMICRON, PCI_ANY_ID, PCI_ANY_ID, PCI_ANY_ID,
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 048/152] edac, highbank: Fix interrupt setup of mem and l2 controller
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (46 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 047/152] ahci: Add Device IDs for Intel Wildcat Point-LP Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 049/152] KVM: IOMMU: hva align mapping page size Kamal Mostafa
` (103 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Robert Richter, Robert Richter, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Robert Richter <robert.richter@linaro.org>
commit a72b8859fd3941cc1d2940d5c43026d2c6fb959e upstream.
Register and enable interrupts after the edac registration. Otherwise
incomming ecc error interrupts lead to crashes during device setup.
Fixing this in drivers for mc and l2.
Signed-off-by: Robert Richter <robert.richter@linaro.org>
Acked-by: Rob Herring <rob.herring@calxeda.com>
Signed-off-by: Robert Richter <rric@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/edac/highbank_l2_edac.c | 18 ++++++++++--------
drivers/edac/highbank_mc_edac.c | 18 ++++++++++--------
2 files changed, 20 insertions(+), 16 deletions(-)
diff --git a/drivers/edac/highbank_l2_edac.c b/drivers/edac/highbank_l2_edac.c
index c2bd8c6..10d3d29 100644
--- a/drivers/edac/highbank_l2_edac.c
+++ b/drivers/edac/highbank_l2_edac.c
@@ -90,28 +90,30 @@ static int highbank_l2_err_probe(struct platform_device *pdev)
goto err;
}
+ dci->mod_name = dev_name(&pdev->dev);
+ dci->dev_name = dev_name(&pdev->dev);
+
+ if (edac_device_add_device(dci))
+ goto err;
+
drvdata->db_irq = platform_get_irq(pdev, 0);
res = devm_request_irq(&pdev->dev, drvdata->db_irq,
highbank_l2_err_handler,
0, dev_name(&pdev->dev), dci);
if (res < 0)
- goto err;
+ goto err2;
drvdata->sb_irq = platform_get_irq(pdev, 1);
res = devm_request_irq(&pdev->dev, drvdata->sb_irq,
highbank_l2_err_handler,
0, dev_name(&pdev->dev), dci);
if (res < 0)
- goto err;
-
- dci->mod_name = dev_name(&pdev->dev);
- dci->dev_name = dev_name(&pdev->dev);
-
- if (edac_device_add_device(dci))
- goto err;
+ goto err2;
devres_close_group(&pdev->dev, NULL);
return 0;
+err2:
+ edac_device_del_device(&pdev->dev);
err:
devres_release_group(&pdev->dev, NULL);
edac_device_free_ctl_info(dci);
diff --git a/drivers/edac/highbank_mc_edac.c b/drivers/edac/highbank_mc_edac.c
index 4695dd2..7a78307 100644
--- a/drivers/edac/highbank_mc_edac.c
+++ b/drivers/edac/highbank_mc_edac.c
@@ -189,14 +189,6 @@ static int highbank_mc_probe(struct platform_device *pdev)
goto err;
}
- irq = platform_get_irq(pdev, 0);
- res = devm_request_irq(&pdev->dev, irq, highbank_mc_err_handler,
- 0, dev_name(&pdev->dev), mci);
- if (res < 0) {
- dev_err(&pdev->dev, "Unable to request irq %d\n", irq);
- goto err;
- }
-
mci->mtype_cap = MEM_FLAG_DDR3;
mci->edac_ctl_cap = EDAC_FLAG_NONE | EDAC_FLAG_SECDED;
mci->edac_cap = EDAC_FLAG_SECDED;
@@ -217,10 +209,20 @@ static int highbank_mc_probe(struct platform_device *pdev)
if (res < 0)
goto err;
+ irq = platform_get_irq(pdev, 0);
+ res = devm_request_irq(&pdev->dev, irq, highbank_mc_err_handler,
+ 0, dev_name(&pdev->dev), mci);
+ if (res < 0) {
+ dev_err(&pdev->dev, "Unable to request irq %d\n", irq);
+ goto err2;
+ }
+
highbank_mc_create_debugfs_nodes(mci);
devres_close_group(&pdev->dev, NULL);
return 0;
+err2:
+ edac_mc_del_mc(&pdev->dev);
err:
devres_release_group(&pdev->dev, NULL);
edac_mc_free(mci);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 049/152] KVM: IOMMU: hva align mapping page size
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (47 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 048/152] edac, highbank: Fix interrupt setup of mem and l2 controller Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 050/152] audit: printk USER_AVC messages when audit isn't enabled Kamal Mostafa
` (102 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Greg Edwards, Gleb Natapov, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Greg Edwards <gedwards@ddn.com>
commit 27ef63c7e97d1e5dddd85051c03f8d44cc887f34 upstream.
When determining the page size we could use to map with the IOMMU, the
page size should also be aligned with the hva, not just the gfn. The
gfn may not reflect the real alignment within the hugetlbfs file.
Most of the time, this works fine. However, if the hugetlbfs file is
backed by non-contiguous huge pages, a multi-huge page memslot starts at
an unaligned offset within the hugetlbfs file, and the gfn is aligned
with respect to the huge page size, kvm_host_page_size() will return the
huge page size and we will use that to map with the IOMMU.
When we later unpin that same memslot, the IOMMU returns the unmap size
as the huge page size, and we happily unpin that many pfns in
monotonically increasing order, not realizing we are spanning
non-contiguous huge pages and partially unpin the wrong huge page.
Ensure the IOMMU mapping page size is aligned with the hva corresponding
to the gfn, which does reflect the alignment within the hugetlbfs file.
Reviewed-by: Marcelo Tosatti <mtosatti@redhat.com>
Signed-off-by: Greg Edwards <gedwards@ddn.com>
Signed-off-by: Gleb Natapov <gleb@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
virt/kvm/iommu.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/virt/kvm/iommu.c b/virt/kvm/iommu.c
index 4a340cb..ba781f6 100644
--- a/virt/kvm/iommu.c
+++ b/virt/kvm/iommu.c
@@ -101,6 +101,10 @@ int kvm_iommu_map_pages(struct kvm *kvm, struct kvm_memory_slot *slot)
while ((gfn << PAGE_SHIFT) & (page_size - 1))
page_size >>= 1;
+ /* Make sure hva is aligned to the page size we want to map */
+ while (__gfn_to_hva_memslot(slot, gfn) & (page_size - 1))
+ page_size >>= 1;
+
/*
* Pin all pages we are about to map in memory. This is
* important because we unmap and unpin in 4kb steps later.
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 050/152] audit: printk USER_AVC messages when audit isn't enabled
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (48 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 049/152] KVM: IOMMU: hva align mapping page size Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 051/152] audit: fix info leak in AUDIT_GET requests Kamal Mostafa
` (101 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Tyler Hicks, Al Viro, Eric Paris, linux-audit,
Richard Guy Briggs, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Tyler Hicks <tyhicks@canonical.com>
commit 0868a5e150bc4c47e7a003367cd755811eb41e0b upstream.
When the audit=1 kernel parameter is absent and auditd is not running,
AUDIT_USER_AVC messages are being silently discarded.
AUDIT_USER_AVC messages should be sent to userspace using printk(), as
mentioned in the commit message of 4a4cd633 ("AUDIT: Optimise the
audit-disabled case for discarding user messages").
When audit_enabled is 0, audit_receive_msg() discards all user messages
except for AUDIT_USER_AVC messages. However, audit_log_common_recv_msg()
refuses to allocate an audit_buffer if audit_enabled is 0. The fix is to
special case AUDIT_USER_AVC messages in both functions.
It looks like commit 50397bd1 ("[AUDIT] clean up audit_receive_msg()")
introduced this bug.
Signed-off-by: Tyler Hicks <tyhicks@canonical.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Eric Paris <eparis@redhat.com>
Cc: linux-audit@redhat.com
Acked-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
Signed-off-by: Eric Paris <eparis@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
kernel/audit.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/audit.c b/kernel/audit.c
index 8a667f10..1da9782 100644
--- a/kernel/audit.c
+++ b/kernel/audit.c
@@ -615,7 +615,7 @@ static int audit_log_common_recv_msg(struct audit_buffer **ab, u16 msg_type,
char *ctx = NULL;
u32 len;
- if (!audit_enabled) {
+ if (!audit_enabled && msg_type != AUDIT_USER_AVC) {
*ab = NULL;
return rc;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 051/152] audit: fix info leak in AUDIT_GET requests
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (49 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 050/152] audit: printk USER_AVC messages when audit isn't enabled Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 052/152] audit: use nlmsg_len() to get message payload length Kamal Mostafa
` (100 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Al Viro, Eric Paris, Mathias Krause, Richard Guy Briggs, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mathias Krause <minipli@googlemail.com>
commit 64fbff9ae0a0a843365d922e0057fc785f23f0e3 upstream.
We leak 4 bytes of kernel stack in response to an AUDIT_GET request as
we miss to initialize the mask member of status_set. Fix that.
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Eric Paris <eparis@redhat.com>
Signed-off-by: Mathias Krause <minipli@googlemail.com>
Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
Signed-off-by: Eric Paris <eparis@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
kernel/audit.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/kernel/audit.c b/kernel/audit.c
index 1da9782..bccbce0 100644
--- a/kernel/audit.c
+++ b/kernel/audit.c
@@ -676,6 +676,7 @@ static int audit_receive_msg(struct sk_buff *skb, struct nlmsghdr *nlh)
switch (msg_type) {
case AUDIT_GET:
+ status_set.mask = 0;
status_set.enabled = audit_enabled;
status_set.failure = audit_failure;
status_set.pid = audit_pid;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 052/152] audit: use nlmsg_len() to get message payload length
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (50 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 051/152] audit: fix info leak in AUDIT_GET requests Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 053/152] ALSA - HDA: New PCI ID for Haswell ULT Kamal Mostafa
` (99 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Al Viro, Eric Paris, Mathias Krause, Richard Guy Briggs, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mathias Krause <minipli@googlemail.com>
commit 4d8fe7376a12bf4524783dd95cbc00f1fece6232 upstream.
Using the nlmsg_len member of the netlink header to test if the message
is valid is wrong as it includes the size of the netlink header itself.
Thereby allowing to send short netlink messages that pass those checks.
Use nlmsg_len() instead to test for the right message length. The result
of nlmsg_len() is guaranteed to be non-negative as the netlink message
already passed the checks of nlmsg_ok().
Also switch to min_t() to please checkpatch.pl.
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Eric Paris <eparis@redhat.com>
Signed-off-by: Mathias Krause <minipli@googlemail.com>
Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
Signed-off-by: Eric Paris <eparis@redhat.com>
[ kamal: backport to 3.8 (addtional bits from 46e959ea) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
kernel/audit.c | 14 +++++++-------
1 file changed, 7 insertions(+), 7 deletions(-)
diff --git a/kernel/audit.c b/kernel/audit.c
index bccbce0..5924919 100644
--- a/kernel/audit.c
+++ b/kernel/audit.c
@@ -688,7 +688,7 @@ static int audit_receive_msg(struct sk_buff *skb, struct nlmsghdr *nlh)
&status_set, sizeof(status_set));
break;
case AUDIT_SET:
- if (nlh->nlmsg_len < sizeof(struct audit_status))
+ if (nlmsg_len(nlh) < sizeof(struct audit_status))
return -EINVAL;
status_get = (struct audit_status *)data;
if (status_get->mask & AUDIT_STATUS_ENABLED) {
@@ -881,17 +881,17 @@ static int audit_receive_msg(struct sk_buff *skb, struct nlmsghdr *nlh)
break;
}
case AUDIT_TTY_SET: {
- struct audit_tty_status *s;
+ struct audit_tty_status s;
struct task_struct *tsk = current;
- if (nlh->nlmsg_len < sizeof(struct audit_tty_status))
- return -EINVAL;
- s = data;
- if (s->enabled != 0 && s->enabled != 1)
+ memset(&s, 0, sizeof(s));
+ /* guard against past and future API changes */
+ memcpy(&s, data, min_t(size_t, sizeof(s), nlmsg_len(nlh)));
+ if (s.enabled != 0 && s.enabled != 1)
return -EINVAL;
spin_lock_irq(&tsk->sighand->siglock);
- tsk->signal->audit_tty = s->enabled != 0;
+ tsk->signal->audit_tty = s.enabled != 0;
spin_unlock_irq(&tsk->sighand->siglock);
break;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 053/152] ALSA - HDA: New PCI ID for Haswell ULT
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (51 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 052/152] audit: use nlmsg_len() to get message payload length Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 054/152] ALSA: hda - Force buffer alignment for Haswell HDMI controllers Kamal Mostafa
` (98 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Wang Xingchao, Takashi Iwai, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Wang Xingchao <xingchao.wang@linux.intel.com>
commit 4a7c516bf0cd697dbbee11db6258e3b3146e41a6 upstream.
Add new PCI ID 0x0a0c for Haswell ULT platform.
Signed-off-by: Wang Xingchao <xingchao.wang@linux.intel.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/pci/hda/hda_intel.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/sound/pci/hda/hda_intel.c b/sound/pci/hda/hda_intel.c
index 714b801..efe16d2 100644
--- a/sound/pci/hda/hda_intel.c
+++ b/sound/pci/hda/hda_intel.c
@@ -3619,6 +3619,8 @@ static DEFINE_PCI_DEVICE_TABLE(azx_ids) = {
{ PCI_DEVICE(0x8086, 0x9c21),
.driver_data = AZX_DRIVER_PCH | AZX_DCAPS_INTEL_PCH },
/* Haswell */
+ { PCI_DEVICE(0x8086, 0x0a0c),
+ .driver_data = AZX_DRIVER_SCH | AZX_DCAPS_INTEL_PCH },
{ PCI_DEVICE(0x8086, 0x0c0c),
.driver_data = AZX_DRIVER_SCH | AZX_DCAPS_INTEL_PCH },
{ PCI_DEVICE(0x8086, 0x0d0c),
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 054/152] ALSA: hda - Force buffer alignment for Haswell HDMI controllers
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (52 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 053/152] ALSA - HDA: New PCI ID for Haswell ULT Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 055/152] ftrace/x86: skip over the breakpoint for ftrace caller Kamal Mostafa
` (97 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Takashi Iwai, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit 33499a15c2f7addc81695778753c2338b960eff7 upstream.
Haswell HDMI audio controllers seem to get stuck when unaligned buffer
size is used. Let's enable the buffer alignment for the corresponding
entries.
Since AZX_DCAPS_INTEL_PCH contains AZX_DCAPS_BUFSIZE that disables the
buffer alignment forcibly, define AZX_DCAPS_INTEL_HASWELL and put the
necessary AZX_DCAPS bits there.
Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=60769
Reported-by: Alexander E. Patrakov <patrakov@gmail.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
[ kamal: backport to 3.8 (no POWERWELL support) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/pci/hda/hda_intel.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/sound/pci/hda/hda_intel.c b/sound/pci/hda/hda_intel.c
index efe16d2..0614bf4 100644
--- a/sound/pci/hda/hda_intel.c
+++ b/sound/pci/hda/hda_intel.c
@@ -580,6 +580,10 @@ enum {
#define AZX_DCAPS_INTEL_PCH \
(AZX_DCAPS_INTEL_PCH_NOPM | AZX_DCAPS_PM_RUNTIME)
+#define AZX_DCAPS_INTEL_HASWELL \
+ (AZX_DCAPS_SCH_SNOOP | AZX_DCAPS_ALIGN_BUFSIZE | \
+ AZX_DCAPS_COUNT_LPIB_DELAY | AZX_DCAPS_PM_RUNTIME)
+
/* quirks for ATI SB / AMD Hudson */
#define AZX_DCAPS_PRESET_ATI_SB \
(AZX_DCAPS_ATI_SNOOP | AZX_DCAPS_NO_TCSEL | \
@@ -3620,11 +3624,11 @@ static DEFINE_PCI_DEVICE_TABLE(azx_ids) = {
.driver_data = AZX_DRIVER_PCH | AZX_DCAPS_INTEL_PCH },
/* Haswell */
{ PCI_DEVICE(0x8086, 0x0a0c),
- .driver_data = AZX_DRIVER_SCH | AZX_DCAPS_INTEL_PCH },
+ .driver_data = AZX_DRIVER_SCH | AZX_DCAPS_INTEL_HASWELL },
{ PCI_DEVICE(0x8086, 0x0c0c),
- .driver_data = AZX_DRIVER_SCH | AZX_DCAPS_INTEL_PCH },
+ .driver_data = AZX_DRIVER_SCH | AZX_DCAPS_INTEL_HASWELL },
{ PCI_DEVICE(0x8086, 0x0d0c),
- .driver_data = AZX_DRIVER_SCH | AZX_DCAPS_INTEL_PCH },
+ .driver_data = AZX_DRIVER_SCH | AZX_DCAPS_INTEL_HASWELL },
/* 5 Series/3400 */
{ PCI_DEVICE(0x8086, 0x3b56),
.driver_data = AZX_DRIVER_SCH | AZX_DCAPS_INTEL_PCH_NOPM },
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 055/152] ftrace/x86: skip over the breakpoint for ftrace caller
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (53 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 054/152] ALSA: hda - Force buffer alignment for Haswell HDMI controllers Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 056/152] drm: shmobile: Add dependency on BACKLIGHT_CLASS_DEVICE Kamal Mostafa
` (96 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Kevin Hao, Steven Rostedt, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Kevin Hao <haokexin@gmail.com>
commit ab4ead02ec235d706d0611d8741964628291237e upstream.
In commit 8a4d0a687a59 "ftrace: Use breakpoint method to update ftrace
caller", we choose to use breakpoint method to update the ftrace
caller. But we also need to skip over the breakpoint in function
ftrace_int3_handler() for them. Otherwise weird things would happen.
Signed-off-by: Kevin Hao <haokexin@gmail.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/x86/kernel/ftrace.c | 14 +++++++++++++-
1 file changed, 13 insertions(+), 1 deletion(-)
diff --git a/arch/x86/kernel/ftrace.c b/arch/x86/kernel/ftrace.c
index 1d41402..8d5d9e5 100644
--- a/arch/x86/kernel/ftrace.c
+++ b/arch/x86/kernel/ftrace.c
@@ -248,6 +248,15 @@ int ftrace_update_ftrace_func(ftrace_func_t func)
return ret;
}
+static int is_ftrace_caller(unsigned long ip)
+{
+ if (ip == (unsigned long)(&ftrace_call) ||
+ ip == (unsigned long)(&ftrace_regs_call))
+ return 1;
+
+ return 0;
+}
+
/*
* A breakpoint was added to the code address we are about to
* modify, and this is the handle that will just skip over it.
@@ -257,10 +266,13 @@ int ftrace_update_ftrace_func(ftrace_func_t func)
*/
int ftrace_int3_handler(struct pt_regs *regs)
{
+ unsigned long ip;
+
if (WARN_ON_ONCE(!regs))
return 0;
- if (!ftrace_location(regs->ip - 1))
+ ip = regs->ip - 1;
+ if (!ftrace_location(ip) && !is_ftrace_caller(ip))
return 0;
regs->ip += MCOUNT_INSN_SIZE - 1;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 056/152] drm: shmobile: Add dependency on BACKLIGHT_CLASS_DEVICE
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (54 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 055/152] ftrace/x86: skip over the breakpoint for ftrace caller Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 057/152] powerpc/powernv: Add PE to its own PELTV Kamal Mostafa
` (95 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Laurent Pinchart, Dave Airlie, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
commit 0a5a5499ad886dde4a032203d01e324cfe593f99 upstream.
The driver registers a backlight device and thus requires
BACKLIGHT_CLASS_DEVICE to be selected to avoid compilation breakages.
Reported-by: Russell King <linux@arm.linux.org.uk>
Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Dave Airlie <airlied@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/gpu/drm/shmobile/Kconfig | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/gpu/drm/shmobile/Kconfig b/drivers/gpu/drm/shmobile/Kconfig
index 7e7d52b..cb4beb5 100644
--- a/drivers/gpu/drm/shmobile/Kconfig
+++ b/drivers/gpu/drm/shmobile/Kconfig
@@ -1,6 +1,7 @@
config DRM_SHMOBILE
tristate "DRM Support for SH Mobile"
depends on DRM && (SUPERH || ARCH_SHMOBILE)
+ select BACKLIGHT_CLASS_DEVICE
select DRM_KMS_HELPER
select DRM_KMS_CMA_HELPER
select DRM_GEM_CMA_HELPER
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 057/152] powerpc/powernv: Add PE to its own PELTV
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (55 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 056/152] drm: shmobile: Add dependency on BACKLIGHT_CLASS_DEVICE Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 058/152] drm/ttm: Handle in-memory region copies Kamal Mostafa
` (94 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Gavin Shan, Benjamin Herrenschmidt, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Gavin Shan <shangw@linux.vnet.ibm.com>
commit 631ad691b5818291d89af9be607d2fe40be0886e upstream.
We need add PE to its own PELTV. Otherwise, the errors originated
from the PE might contribute to other PEs. In the result, we can't
clear up the error successfully even we're checking and clearing
errors during access to PCI config space.
Reported-by: kalshett@in.ibm.com
Signed-off-by: Gavin Shan <shangw@linux.vnet.ibm.com>
Signed-off-by: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/powerpc/platforms/powernv/pci-ioda.c | 12 +++++++++++-
1 file changed, 11 insertions(+), 1 deletion(-)
diff --git a/arch/powerpc/platforms/powernv/pci-ioda.c b/arch/powerpc/platforms/powernv/pci-ioda.c
index 8e90e89..7e18662 100644
--- a/arch/powerpc/platforms/powernv/pci-ioda.c
+++ b/arch/powerpc/platforms/powernv/pci-ioda.c
@@ -158,13 +158,23 @@ static int pnv_ioda_configure_pe(struct pnv_phb *phb, struct pnv_ioda_pe *pe)
rid_end = pe->rid + 1;
}
- /* Associate PE in PELT */
+ /*
+ * Associate PE in PELT. We need add the PE into the
+ * corresponding PELT-V as well. Otherwise, the error
+ * originated from the PE might contribute to other
+ * PEs.
+ */
rc = opal_pci_set_pe(phb->opal_id, pe->pe_number, pe->rid,
bcomp, dcomp, fcomp, OPAL_MAP_PE);
if (rc) {
pe_err(pe, "OPAL error %ld trying to setup PELT table\n", rc);
return -ENXIO;
}
+
+ rc = opal_pci_set_peltv(phb->opal_id, pe->pe_number,
+ pe->pe_number, OPAL_ADD_PE_TO_DOMAIN);
+ if (rc)
+ pe_warn(pe, "OPAL error %d adding self to PELTV\n", rc);
opal_pci_eeh_freeze_clear(phb->opal_id, pe->pe_number,
OPAL_EEH_ACTION_CLEAR_FREEZE_ALL);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 058/152] drm/ttm: Handle in-memory region copies
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (56 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 057/152] powerpc/powernv: Add PE to its own PELTV Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 059/152] drm/ttm: Fix ttm_bo_move_memcpy Kamal Mostafa
` (93 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Jakob Bornecrantz, Thomas Hellström, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jakob Bornecrantz <jakob@vmware.com>
commit 9a0599ddeae012a771bba5e23393fc52d8a59d89 upstream.
Fix the case where the ttm pointer may be NULL causing
a NULL pointer dereference.
Signed-off-by: Jakob Bornecrantz <jakob@vmware.com>
Signed-off-by: Thomas Hellström <thellstrom@vmware.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/gpu/drm/ttm/ttm_bo_util.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/ttm/ttm_bo_util.c b/drivers/gpu/drm/ttm/ttm_bo_util.c
index 8be35c8..037f101 100644
--- a/drivers/gpu/drm/ttm/ttm_bo_util.c
+++ b/drivers/gpu/drm/ttm/ttm_bo_util.c
@@ -342,7 +342,9 @@ int ttm_bo_move_memcpy(struct ttm_buffer_object *bo,
if (old_iomap == NULL && ttm == NULL)
goto out2;
- if (ttm->state == tt_unpopulated) {
+ /* TTM might be null for moves within the same region.
+ */
+ if (ttm && ttm->state == tt_unpopulated) {
ret = ttm->bdev->driver->ttm_tt_populate(ttm);
if (ret) {
/* if we fail here don't nuke the mm node
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 059/152] drm/ttm: Fix ttm_bo_move_memcpy
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (57 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 058/152] drm/ttm: Handle in-memory region copies Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 060/152] drm/ttm: Fix memory type compatibility check Kamal Mostafa
` (92 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Thomas Hellstrom, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Hellstrom <thellstrom@vmware.com>
commit da95c788ef0c645378ffccb7060a0df1a33aee38 upstream.
All error paths will want to keep the mm node, so handle this at the
function exit. This fixes an ioremap failure error path.
Also add some comments to make the function a bit easier to understand.
Signed-off-by: Thomas Hellstrom <thellstrom@vmware.com>
Reviewed-by: Jakob Bornecrantz <jakob@vmware.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/gpu/drm/ttm/ttm_bo_util.c | 28 +++++++++++++++++-----------
1 file changed, 17 insertions(+), 11 deletions(-)
diff --git a/drivers/gpu/drm/ttm/ttm_bo_util.c b/drivers/gpu/drm/ttm/ttm_bo_util.c
index 037f101..2a90955 100644
--- a/drivers/gpu/drm/ttm/ttm_bo_util.c
+++ b/drivers/gpu/drm/ttm/ttm_bo_util.c
@@ -337,21 +337,25 @@ int ttm_bo_move_memcpy(struct ttm_buffer_object *bo,
if (ret)
goto out;
+ /*
+ * Single TTM move. NOP.
+ */
if (old_iomap == NULL && new_iomap == NULL)
goto out2;
+
+ /*
+ * Move nonexistent data. NOP.
+ */
if (old_iomap == NULL && ttm == NULL)
goto out2;
- /* TTM might be null for moves within the same region.
+ /*
+ * TTM might be null for moves within the same region.
*/
if (ttm && ttm->state == tt_unpopulated) {
ret = ttm->bdev->driver->ttm_tt_populate(ttm);
- if (ret) {
- /* if we fail here don't nuke the mm node
- * as the bo still owns it */
- old_copy.mm_node = NULL;
+ if (ret)
goto out1;
- }
}
add = 0;
@@ -377,11 +381,8 @@ int ttm_bo_move_memcpy(struct ttm_buffer_object *bo,
prot);
} else
ret = ttm_copy_io_page(new_iomap, old_iomap, page);
- if (ret) {
- /* failing here, means keep old copy as-is */
- old_copy.mm_node = NULL;
+ if (ret)
goto out1;
- }
}
mb();
out2:
@@ -399,7 +400,12 @@ out1:
ttm_mem_reg_iounmap(bdev, old_mem, new_iomap);
out:
ttm_mem_reg_iounmap(bdev, &old_copy, old_iomap);
- ttm_bo_mem_put(bo, &old_copy);
+
+ /*
+ * On error, keep the mm node!
+ */
+ if (!ret)
+ ttm_bo_mem_put(bo, &old_copy);
return ret;
}
EXPORT_SYMBOL(ttm_bo_move_memcpy);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 060/152] drm/ttm: Fix memory type compatibility check
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (58 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 059/152] drm/ttm: Fix ttm_bo_move_memcpy Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 061/152] perf/ftrace: Fix paranoid level for enabling function tracer Kamal Mostafa
` (91 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Thomas Hellstrom, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Hellstrom <thellstrom@vmware.com>
commit 59c8e66378fb78adbcd05f0d09783dde6fef282b upstream.
Also check the busy placements before deciding to move a buffer object.
Failing to do this may result in a completely unneccessary move within a
single memory type.
Signed-off-by: Thomas Hellstrom <thellstrom@vmware.com>
Reviewed-by: Jakob Bornecrantz <jakob@vmware.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/gpu/drm/ttm/ttm_bo.c | 32 ++++++++++++++++++++------------
1 file changed, 20 insertions(+), 12 deletions(-)
diff --git a/drivers/gpu/drm/ttm/ttm_bo.c b/drivers/gpu/drm/ttm/ttm_bo.c
index 52b20b1..ba60a89 100644
--- a/drivers/gpu/drm/ttm/ttm_bo.c
+++ b/drivers/gpu/drm/ttm/ttm_bo.c
@@ -1090,24 +1090,32 @@ out_unlock:
return ret;
}
-static int ttm_bo_mem_compat(struct ttm_placement *placement,
- struct ttm_mem_reg *mem)
+static bool ttm_bo_mem_compat(struct ttm_placement *placement,
+ struct ttm_mem_reg *mem,
+ uint32_t *new_flags)
{
int i;
if (mem->mm_node && placement->lpfn != 0 &&
(mem->start < placement->fpfn ||
mem->start + mem->num_pages > placement->lpfn))
- return -1;
+ return false;
for (i = 0; i < placement->num_placement; i++) {
- if ((placement->placement[i] & mem->placement &
- TTM_PL_MASK_CACHING) &&
- (placement->placement[i] & mem->placement &
- TTM_PL_MASK_MEM))
- return i;
+ *new_flags = placement->placement[i];
+ if ((*new_flags & mem->placement & TTM_PL_MASK_CACHING) &&
+ (*new_flags & mem->placement & TTM_PL_MASK_MEM))
+ return true;
+ }
+
+ for (i = 0; i < placement->num_busy_placement; i++) {
+ *new_flags = placement->busy_placement[i];
+ if ((*new_flags & mem->placement & TTM_PL_MASK_CACHING) &&
+ (*new_flags & mem->placement & TTM_PL_MASK_MEM))
+ return true;
}
- return -1;
+
+ return false;
}
int ttm_bo_validate(struct ttm_buffer_object *bo,
@@ -1116,6 +1124,7 @@ int ttm_bo_validate(struct ttm_buffer_object *bo,
bool no_wait_gpu)
{
int ret;
+ uint32_t new_flags;
BUG_ON(!ttm_bo_is_reserved(bo));
/* Check that range is valid */
@@ -1126,8 +1135,7 @@ int ttm_bo_validate(struct ttm_buffer_object *bo,
/*
* Check whether we need to move buffer.
*/
- ret = ttm_bo_mem_compat(placement, &bo->mem);
- if (ret < 0) {
+ if (!ttm_bo_mem_compat(placement, &bo->mem, &new_flags)) {
ret = ttm_bo_move_buffer(bo, placement, interruptible,
no_wait_gpu);
if (ret)
@@ -1137,7 +1145,7 @@ int ttm_bo_validate(struct ttm_buffer_object *bo,
* Use the access and other non-mapping-related flag bits from
* the compatible memory placement flags to the active flags
*/
- ttm_flag_masked(&bo->mem.placement, placement->placement[ret],
+ ttm_flag_masked(&bo->mem.placement, new_flags,
~TTM_PL_MASK_MEMTYPE);
}
/*
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 061/152] perf/ftrace: Fix paranoid level for enabling function tracer
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (59 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 060/152] drm/ttm: Fix memory type compatibility check Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 062/152] ARM: entry: move IRQ tracing exit into svc_exit Kamal Mostafa
` (90 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Peter Zijlstra, Ingo Molnar, Jiri Olsa, Frederic Weisbecker,
Steven Rostedt, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Steven Rostedt <rostedt@goodmis.org>
commit 12ae030d54ef250706da5642fc7697cc60ad0df7 upstream.
The current default perf paranoid level is "1" which has
"perf_paranoid_kernel()" return false, and giving any operations that
use it, access to normal users. Unfortunately, this includes function
tracing and normal users should not be allowed to enable function
tracing by default.
The proper level is defined at "-1" (full perf access), which
"perf_paranoid_tracepoint_raw()" will only give access to. Use that
check instead for enabling function tracing.
Reported-by: Dave Jones <davej@redhat.com>
Reported-by: Vince Weaver <vincent.weaver@maine.edu>
Tested-by: Vince Weaver <vincent.weaver@maine.edu>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Ingo Molnar <mingo@kernel.org>
Cc: Jiri Olsa <jolsa@redhat.com>
Cc: Frederic Weisbecker <fweisbec@gmail.com>
CVE: CVE-2013-2930
Fixes: ced39002f5ea ("ftrace, perf: Add support to use function tracepoint in perf")
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
kernel/trace/trace_event_perf.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/trace/trace_event_perf.c b/kernel/trace/trace_event_perf.c
index 84b1e04..8354dc8 100644
--- a/kernel/trace/trace_event_perf.c
+++ b/kernel/trace/trace_event_perf.c
@@ -26,7 +26,7 @@ static int perf_trace_event_perm(struct ftrace_event_call *tp_event,
{
/* The ftrace function trace is allowed only for root. */
if (ftrace_event_is_function(tp_event) &&
- perf_paranoid_kernel() && !capable(CAP_SYS_ADMIN))
+ perf_paranoid_tracepoint_raw() && !capable(CAP_SYS_ADMIN))
return -EPERM;
/* No tracing, just counting, so no obvious leak */
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 062/152] ARM: entry: move IRQ tracing exit into svc_exit
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (60 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 061/152] perf/ftrace: Fix paranoid level for enabling function tracer Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 063/152] ARM: entry: move disable_irq_notrace " Kamal Mostafa
` (89 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Russell King, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Russell King <rmk+kernel@arm.linux.org.uk>
commit 9b56febea22003c424f11248908b534eba0f1eeb upstream.
The IRQ tracing exit path is much the same between all SVC mode
exits, so move this into the svc_exit macro. Use a macro parameter
to identify the IRQ case, which is the only different case there is.
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
[ kamal: 3.8 stable prereq for
e16b31b ARM: 7876/1: clear Thumb-2 IT state on exception handling ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/arm/kernel/entry-armv.S | 27 +--------------------------
| 32 ++++++++++++++++++++++++++++++--
2 files changed, 31 insertions(+), 28 deletions(-)
diff --git a/arch/arm/kernel/entry-armv.S b/arch/arm/kernel/entry-armv.S
index 5492d72..a716ea9 100644
--- a/arch/arm/kernel/entry-armv.S
+++ b/arch/arm/kernel/entry-armv.S
@@ -197,13 +197,6 @@ __dabt_svc:
@ IRQs off again before pulling preserved data off the stack
@
disable_irq_notrace
-
-#ifdef CONFIG_TRACE_IRQFLAGS
- tst r5, #PSR_I_BIT
- bleq trace_hardirqs_on
- tst r5, #PSR_I_BIT
- blne trace_hardirqs_off
-#endif
svc_exit r5 @ return from exception
UNWIND(.fnend )
ENDPROC(__dabt_svc)
@@ -223,12 +216,7 @@ __irq_svc:
blne svc_preempt
#endif
-#ifdef CONFIG_TRACE_IRQFLAGS
- @ The parent context IRQs must have been enabled to get here in
- @ the first place, so there's no point checking the PSR I bit.
- bl trace_hardirqs_on
-#endif
- svc_exit r5 @ return from exception
+ svc_exit r5, irq = 1 @ return from exception
UNWIND(.fnend )
ENDPROC(__irq_svc)
@@ -305,12 +293,6 @@ __und_svc_finish:
@ restore SPSR and restart the instruction
@
ldr r5, [sp, #S_PSR] @ Get SVC cpsr
-#ifdef CONFIG_TRACE_IRQFLAGS
- tst r5, #PSR_I_BIT
- bleq trace_hardirqs_on
- tst r5, #PSR_I_BIT
- blne trace_hardirqs_off
-#endif
svc_exit r5 @ return from exception
UNWIND(.fnend )
ENDPROC(__und_svc)
@@ -325,13 +307,6 @@ __pabt_svc:
@ IRQs off again before pulling preserved data off the stack
@
disable_irq_notrace
-
-#ifdef CONFIG_TRACE_IRQFLAGS
- tst r5, #PSR_I_BIT
- bleq trace_hardirqs_on
- tst r5, #PSR_I_BIT
- blne trace_hardirqs_off
-#endif
svc_exit r5 @ return from exception
UNWIND(.fnend )
ENDPROC(__pabt_svc)
--git a/arch/arm/kernel/entry-header.S b/arch/arm/kernel/entry-header.S
index 9a8531e..0bf15e5 100644
--- a/arch/arm/kernel/entry-header.S
+++ b/arch/arm/kernel/entry-header.S
@@ -74,7 +74,21 @@
.endm
#ifndef CONFIG_THUMB2_KERNEL
- .macro svc_exit, rpsr
+ .macro svc_exit, rpsr, irq = 0
+ .if \irq != 0
+#ifdef CONFIG_TRACE_IRQFLAGS
+ @ The parent context IRQs must have been enabled to get here in
+ @ the first place, so there's no point checking the PSR I bit.
+ bl trace_hardirqs_on
+#endif
+ .else
+#ifdef CONFIG_TRACE_IRQFLAGS
+ tst \rpsr, #PSR_I_BIT
+ bleq trace_hardirqs_on
+ tst \rpsr, #PSR_I_BIT
+ blne trace_hardirqs_off
+#endif
+ .endif
msr spsr_cxsf, \rpsr
#if defined(CONFIG_CPU_V6)
ldr r0, [sp]
@@ -120,7 +134,21 @@
mov pc, \reg
.endm
#else /* CONFIG_THUMB2_KERNEL */
- .macro svc_exit, rpsr
+ .macro svc_exit, rpsr, irq = 0
+ .if \irq != 0
+#ifdef CONFIG_TRACE_IRQFLAGS
+ @ The parent context IRQs must have been enabled to get here in
+ @ the first place, so there's no point checking the PSR I bit.
+ bl trace_hardirqs_on
+#endif
+ .else
+#ifdef CONFIG_TRACE_IRQFLAGS
+ tst \rpsr, #PSR_I_BIT
+ bleq trace_hardirqs_on
+ tst \rpsr, #PSR_I_BIT
+ blne trace_hardirqs_off
+#endif
+ .endif
ldr lr, [sp, #S_SP] @ top of the stack
ldrd r0, r1, [sp, #S_LR] @ calling lr and pc
clrex @ clear the exclusive monitor
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 063/152] ARM: entry: move disable_irq_notrace into svc_exit
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (61 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 062/152] ARM: entry: move IRQ tracing exit into svc_exit Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 064/152] ARM: 7876/1: clear Thumb-2 IT state on exception handling Kamal Mostafa
` (88 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Russell King, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Russell King <rmk+kernel@arm.linux.org.uk>
commit f8f02ec25ce3eafb049feeb3abf34fcd6e338241 upstream.
All svc exit paths need IRQs off. Rather than placing this before
every user of svc_exit, combine it into this macro.
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
[ kamal: 3.8 stable prereq for
e16b31b ARM: 7876/1: clear Thumb-2 IT state on exception handling ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/arm/kernel/entry-armv.S | 18 ------------------
| 6 ++++++
2 files changed, 6 insertions(+), 18 deletions(-)
diff --git a/arch/arm/kernel/entry-armv.S b/arch/arm/kernel/entry-armv.S
index a716ea9..a7de792 100644
--- a/arch/arm/kernel/entry-armv.S
+++ b/arch/arm/kernel/entry-armv.S
@@ -192,11 +192,6 @@ __dabt_svc:
svc_entry
mov r2, sp
dabt_helper
-
- @
- @ IRQs off again before pulling preserved data off the stack
- @
- disable_irq_notrace
svc_exit r5 @ return from exception
UNWIND(.fnend )
ENDPROC(__dabt_svc)
@@ -283,15 +278,7 @@ __und_svc_fault:
mov r0, sp @ struct pt_regs *regs
bl __und_fault
- @
- @ IRQs off again before pulling preserved data off the stack
- @
__und_svc_finish:
- disable_irq_notrace
-
- @
- @ restore SPSR and restart the instruction
- @
ldr r5, [sp, #S_PSR] @ Get SVC cpsr
svc_exit r5 @ return from exception
UNWIND(.fnend )
@@ -302,11 +289,6 @@ __pabt_svc:
svc_entry
mov r2, sp @ regs
pabt_helper
-
- @
- @ IRQs off again before pulling preserved data off the stack
- @
- disable_irq_notrace
svc_exit r5 @ return from exception
UNWIND(.fnend )
ENDPROC(__pabt_svc)
--git a/arch/arm/kernel/entry-header.S b/arch/arm/kernel/entry-header.S
index 0bf15e5..57a1631 100644
--- a/arch/arm/kernel/entry-header.S
+++ b/arch/arm/kernel/entry-header.S
@@ -76,12 +76,15 @@
#ifndef CONFIG_THUMB2_KERNEL
.macro svc_exit, rpsr, irq = 0
.if \irq != 0
+ @ IRQs already off
#ifdef CONFIG_TRACE_IRQFLAGS
@ The parent context IRQs must have been enabled to get here in
@ the first place, so there's no point checking the PSR I bit.
bl trace_hardirqs_on
#endif
.else
+ @ IRQs off again before pulling preserved data off the stack
+ disable_irq_notrace
#ifdef CONFIG_TRACE_IRQFLAGS
tst \rpsr, #PSR_I_BIT
bleq trace_hardirqs_on
@@ -136,12 +139,15 @@
#else /* CONFIG_THUMB2_KERNEL */
.macro svc_exit, rpsr, irq = 0
.if \irq != 0
+ @ IRQs already off
#ifdef CONFIG_TRACE_IRQFLAGS
@ The parent context IRQs must have been enabled to get here in
@ the first place, so there's no point checking the PSR I bit.
bl trace_hardirqs_on
#endif
.else
+ @ IRQs off again before pulling preserved data off the stack
+ disable_irq_notrace
#ifdef CONFIG_TRACE_IRQFLAGS
tst \rpsr, #PSR_I_BIT
bleq trace_hardirqs_on
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 064/152] ARM: 7876/1: clear Thumb-2 IT state on exception handling
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (62 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 063/152] ARM: entry: move disable_irq_notrace " Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 065/152] PM / hibernate: Avoid overflow in hibernate_preallocate_memory() Kamal Mostafa
` (87 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Will Deacon, Marc Zyngier, Russell King, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Marc Zyngier <Marc.Zyngier@arm.com>
commit e16b31bf47738f4498d7ce632e12d7d2a6a2492a upstream.
The exception handling code fails to clear the IT state, potentially
leading to incorrect execution of the fixup if the size of the IT
block is more than one.
Let fixup_exception do the IT sanitizing if a fixup has been found,
and restore CPSR from the stack when returning from a data abort.
Cc: Will Deacon <will.deacon@arm.com>
Reviewed-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Marc Zyngier <marc.zyngier@arm.com>
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/arm/kernel/entry-armv.S | 1 +
arch/arm/mm/extable.c | 7 ++++++-
2 files changed, 7 insertions(+), 1 deletion(-)
diff --git a/arch/arm/kernel/entry-armv.S b/arch/arm/kernel/entry-armv.S
index a7de792..130ed1f 100644
--- a/arch/arm/kernel/entry-armv.S
+++ b/arch/arm/kernel/entry-armv.S
@@ -192,6 +192,7 @@ __dabt_svc:
svc_entry
mov r2, sp
dabt_helper
+ THUMB( ldr r5, [sp, #S_PSR] ) @ potentially updated CPSR
svc_exit r5 @ return from exception
UNWIND(.fnend )
ENDPROC(__dabt_svc)
diff --git a/arch/arm/mm/extable.c b/arch/arm/mm/extable.c
index 9d28562..312e15e 100644
--- a/arch/arm/mm/extable.c
+++ b/arch/arm/mm/extable.c
@@ -9,8 +9,13 @@ int fixup_exception(struct pt_regs *regs)
const struct exception_table_entry *fixup;
fixup = search_exception_tables(instruction_pointer(regs));
- if (fixup)
+ if (fixup) {
regs->ARM_pc = fixup->fixup;
+#ifdef CONFIG_THUMB2_KERNEL
+ /* Clear the IT state to avoid nasty surprises in the fixup */
+ regs->ARM_cpsr &= ~PSR_IT_MASK;
+#endif
+ }
return fixup != NULL;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 065/152] PM / hibernate: Avoid overflow in hibernate_preallocate_memory()
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (63 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 064/152] ARM: 7876/1: clear Thumb-2 IT state on exception handling Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 066/152] ALSA: hda - Add support for CX20952 Kamal Mostafa
` (86 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Aaron Lu, Rafael J. Wysocki, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Aaron Lu <aaron.lu@intel.com>
commit fd432b9f8c7c88428a4635b9f5a9c6e174df6e36 upstream.
When system has a lot of highmem (e.g. 16GiB using a 32 bits kernel),
the code to calculate how much memory we need to preallocate in
normal zone may cause overflow. As Leon has analysed:
It looks that during computing 'alloc' variable there is overflow:
alloc = (3943404 - 1970542) - 1978280 = -5418 (signed)
And this function goes to err_out.
Fix this by avoiding that overflow.
References: https://bugzilla.kernel.org/show_bug.cgi?id=60817
Reported-and-tested-by: Leon Drugi <eyak@wp.pl>
Signed-off-by: Aaron Lu <aaron.lu@intel.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
kernel/power/snapshot.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/kernel/power/snapshot.c b/kernel/power/snapshot.c
index 0de2857..91c04f1 100644
--- a/kernel/power/snapshot.c
+++ b/kernel/power/snapshot.c
@@ -1398,7 +1398,11 @@ int hibernate_preallocate_memory(void)
* highmem and non-highmem zones separately.
*/
pages_highmem = preallocate_image_highmem(highmem / 2);
- alloc = (count - max_size) - pages_highmem;
+ alloc = count - max_size;
+ if (alloc > pages_highmem)
+ alloc -= pages_highmem;
+ else
+ alloc = 0;
pages = preallocate_image_memory(alloc, avail_normal);
if (pages < alloc) {
/* We have exhausted non-highmem pages, try highmem. */
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 066/152] ALSA: hda - Add support for CX20952
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (64 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 065/152] PM / hibernate: Avoid overflow in hibernate_preallocate_memory() Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 067/152] ALSA: hda - Add pincfg fixup for ASUS W5A Kamal Mostafa
` (85 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Takashi Iwai, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit 8f42d7698751a45cd9f7134a5da49bc5b6206179 upstream.
It's a superset of the existing CX2075x codecs, so we can reuse the
existing parser code.
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/pci/hda/patch_conexant.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/sound/pci/hda/patch_conexant.c b/sound/pci/hda/patch_conexant.c
index 09fae16..c631e08 100644
--- a/sound/pci/hda/patch_conexant.c
+++ b/sound/pci/hda/patch_conexant.c
@@ -4642,6 +4642,8 @@ static const struct hda_codec_preset snd_hda_preset_conexant[] = {
.patch = patch_conexant_auto },
{ .id = 0x14f15115, .name = "CX20757",
.patch = patch_conexant_auto },
+ { .id = 0x14f151d7, .name = "CX20952",
+ .patch = patch_conexant_auto },
{} /* terminator */
};
@@ -4668,6 +4670,7 @@ MODULE_ALIAS("snd-hda-codec-id:14f15111");
MODULE_ALIAS("snd-hda-codec-id:14f15113");
MODULE_ALIAS("snd-hda-codec-id:14f15114");
MODULE_ALIAS("snd-hda-codec-id:14f15115");
+MODULE_ALIAS("snd-hda-codec-id:14f151d7");
MODULE_LICENSE("GPL");
MODULE_DESCRIPTION("Conexant HD-audio codec");
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 067/152] ALSA: hda - Add pincfg fixup for ASUS W5A
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (65 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 066/152] ALSA: hda - Add support for CX20952 Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 068/152] mtd: nand: hack ONFI for non-power-of-2 dimensions Kamal Mostafa
` (84 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Takashi Iwai, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit 487a588d09db0d6508261867df208d8bdc718251 upstream.
BIOS on ASUS W5A laptop with ALC880 codec doesn't provide any pin
configurations, so we have to set up all pins manually.
Reported-and-tested-by: nb <nb@dagami.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/pci/hda/patch_realtek.c | 22 ++++++++++++++++++++++
1 file changed, 22 insertions(+)
diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index 500c00a..a9a177a 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -4411,6 +4411,7 @@ enum {
ALC880_FIXUP_UNIWILL,
ALC880_FIXUP_UNIWILL_DIG,
ALC880_FIXUP_Z71V,
+ ALC880_FIXUP_ASUS_W5A,
ALC880_FIXUP_3ST_BASE,
ALC880_FIXUP_3ST,
ALC880_FIXUP_3ST_DIG,
@@ -4572,6 +4573,26 @@ static const struct alc_fixup alc880_fixups[] = {
{ }
}
},
+ [ALC880_FIXUP_ASUS_W5A] = {
+ .type = HDA_FIXUP_PINS,
+ .v.pins = (const struct hda_pintbl[]) {
+ /* set up the whole pins as BIOS is utterly broken */
+ { 0x14, 0x0121411f }, /* HP */
+ { 0x15, 0x411111f0 }, /* N/A */
+ { 0x16, 0x411111f0 }, /* N/A */
+ { 0x17, 0x411111f0 }, /* N/A */
+ { 0x18, 0x90a60160 }, /* mic */
+ { 0x19, 0x411111f0 }, /* N/A */
+ { 0x1a, 0x411111f0 }, /* N/A */
+ { 0x1b, 0x411111f0 }, /* N/A */
+ { 0x1c, 0x411111f0 }, /* N/A */
+ { 0x1d, 0x411111f0 }, /* N/A */
+ { 0x1e, 0xb743111e }, /* SPDIF out */
+ { }
+ },
+ .chained = true,
+ .chain_id = ALC880_FIXUP_GPIO1,
+ },
[ALC880_FIXUP_3ST_BASE] = {
.type = ALC_FIXUP_PINS,
.v.pins = (const struct alc_pincfg[]) {
@@ -4684,6 +4705,7 @@ static const struct alc_fixup alc880_fixups[] = {
static const struct snd_pci_quirk alc880_fixup_tbl[] = {
SND_PCI_QUIRK(0x1019, 0x0f69, "Coeus G610P", ALC880_FIXUP_W810),
+ SND_PCI_QUIRK(0x1043, 0x10c3, "ASUS W5A", ALC880_FIXUP_ASUS_W5A),
SND_PCI_QUIRK(0x1043, 0x1964, "ASUS Z71V", ALC880_FIXUP_Z71V),
SND_PCI_QUIRK_VENDOR(0x1043, "ASUS", ALC880_FIXUP_GPIO1),
SND_PCI_QUIRK(0x1558, 0x5401, "Clevo GPIO2", ALC880_FIXUP_GPIO2),
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 068/152] mtd: nand: hack ONFI for non-power-of-2 dimensions
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (66 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 067/152] ALSA: hda - Add pincfg fixup for ASUS W5A Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 069/152] mtd: map: fixed bug in 64-bit systems Kamal Mostafa
` (83 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Brian Norris, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Brian Norris <computersforpeace@gmail.com>
commit 4355b70cf48363c50a9de450b01178c83aba8f6a upstream.
Some bright specification writers decided to write this in the ONFI spec
(from ONFI 3.0, Section 3.1):
"The number of blocks and number of pages per block is not required to
be a power of two. In the case where one of these values is not a
power of two, the corresponding address shall be rounded to an
integral number of bits such that it addresses a range up to the
subsequent power of two value. The host shall not access upper
addresses in a range that is shown as not supported."
This breaks every assumption MTD makes about NAND block/chip-size
dimensions -- they *must* be a power of two!
And of course, an enterprising manufacturer has made use of this lovely
freedom. Exhibit A: Micron MT29F32G08CBADAWP
"- Plane size: 2 planes x 1064 blocks per plane
- Device size: 32Gb: 2128 blockss [sic]"
This quickly hits a BUG() in nand_base.c, since the extra dimensions
overflow so we think it's a second chip (on my single-chip setup):
ONFI param page 0 valid
ONFI flash detected
NAND device: Manufacturer ID: 0x2c, Chip ID: 0x44 (Micron MT29F32G08CBADAWP), 4256MiB, page size: 8192, OOB size: 744
------------[ cut here ]------------
kernel BUG at drivers/mtd/nand/nand_base.c:203!
Internal error: Oops - BUG: 0 [#1] SMP ARM
[... trim ...]
[<c02cf3e4>] (nand_select_chip+0x18/0x2c) from [<c02d25c0>] (nand_do_read_ops+0x90/0x424)
[<c02d25c0>] (nand_do_read_ops+0x90/0x424) from [<c02d2dd8>] (nand_read+0x54/0x78)
[<c02d2dd8>] (nand_read+0x54/0x78) from [<c02ad2c8>] (mtd_read+0x84/0xbc)
[<c02ad2c8>] (mtd_read+0x84/0xbc) from [<c02d4b28>] (scan_read.clone.4+0x4c/0x64)
[<c02d4b28>] (scan_read.clone.4+0x4c/0x64) from [<c02d4c88>] (search_bbt+0x148/0x290)
[<c02d4c88>] (search_bbt+0x148/0x290) from [<c02d4ea4>] (nand_scan_bbt+0xd4/0x5c0)
[... trim ...]
---[ end trace 0c9363860d865ff2 ]---
So to fix this, just truncate these dimensions down to the greatest
power-of-2 dimension that is less than or equal to the specified
dimension.
Signed-off-by: Brian Norris <computersforpeace@gmail.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/mtd/nand/nand_base.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
diff --git a/drivers/mtd/nand/nand_base.c b/drivers/mtd/nand/nand_base.c
index d831091..016882d 100644
--- a/drivers/mtd/nand/nand_base.c
+++ b/drivers/mtd/nand/nand_base.c
@@ -2923,10 +2923,21 @@ static int nand_flash_detect_onfi(struct mtd_info *mtd, struct nand_chip *chip,
sanitize_string(p->model, sizeof(p->model));
if (!mtd->name)
mtd->name = p->model;
+
mtd->writesize = le32_to_cpu(p->byte_per_page);
- mtd->erasesize = le32_to_cpu(p->pages_per_block) * mtd->writesize;
+
+ /*
+ * pages_per_block and blocks_per_lun may not be a power-of-2 size
+ * (don't ask me who thought of this...). MTD assumes that these
+ * dimensions will be power-of-2, so just truncate the remaining area.
+ */
+ mtd->erasesize = 1 << (fls(le32_to_cpu(p->pages_per_block)) - 1);
+ mtd->erasesize *= mtd->writesize;
+
mtd->oobsize = le16_to_cpu(p->spare_bytes_per_page);
- chip->chipsize = le32_to_cpu(p->blocks_per_lun);
+
+ /* See erasesize comment */
+ chip->chipsize = 1 << (fls(le32_to_cpu(p->blocks_per_lun)) - 1);
chip->chipsize *= (uint64_t)mtd->erasesize * p->lun_count;
*busw = 0;
if (le16_to_cpu(p->features) & 1)
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 069/152] mtd: map: fixed bug in 64-bit systems
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (67 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 068/152] mtd: nand: hack ONFI for non-power-of-2 dimensions Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 070/152] mtd: m25p80: fix allocation size Kamal Mostafa
` (82 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Pang Xunlei, Zhang Yi, Lu Zhongjun, Brian Norris, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Wang Haitao <wang.haitao1@zte.com.cn>
commit a4d62babf988fe5dfde24437fa135ef147bc7aa0 upstream.
Hardware:
CPU: XLP832,the 64-bit OS
NOR Flash:S29GL128S 128M
Software:
Kernel:2.6.32.41
Filesystem:JFFS2
When writing files, errors appear:
Write len 182 but return retlen 180
Write of 182 bytes at 0x072c815c failed. returned -5, retlen 180
Write len 186 but return retlen 184
Write of 186 bytes at 0x072caff4 failed. returned -5, retlen 184
These errors exist only in 64-bit systems,not in 32-bit systems. After analysis, we
found that the left shift operation is wrong in map_word_load_partial. For instance:
unsigned char buf[3] ={0x9e,0x3a,0xea};
map_bankwidth(map) is 4;
for (i=0; i < 3; i++) {
int bitpos;
bitpos = (map_bankwidth(map)-1-i)*8;
orig.x[0] &= ~(0xff << bitpos);
orig.x[0] |= buf[i] << bitpos;
}
The value of orig.x[0] is expected to be 0x9e3aeaff, but in this situation(64-bit
System) we'll get the wrong value of 0xffffffff9e3aeaff due to the 64-bit sign
extension:
buf[i] is defined as "unsigned char" and the left-shift operation will convert it
to the type of "signed int", so when left-shift buf[i] by 24 bits, the final result
will get the wrong value: 0xffffffff9e3aeaff.
If the left-shift bits are less than 24, then sign extension will not occur. Whereas
the bankwidth of the nor flash we used is 4, therefore this BUG emerges.
Signed-off-by: Pang Xunlei <pang.xunlei@zte.com.cn>
Signed-off-by: Zhang Yi <zhang.yi20@zte.com.cn>
Signed-off-by: Lu Zhongjun <lu.zhongjun@zte.com.cn>
Signed-off-by: Brian Norris <computersforpeace@gmail.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
include/linux/mtd/map.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/include/linux/mtd/map.h b/include/linux/mtd/map.h
index f6eb433..d4f5f16 100644
--- a/include/linux/mtd/map.h
+++ b/include/linux/mtd/map.h
@@ -362,7 +362,7 @@ static inline map_word map_word_load_partial(struct map_info *map, map_word orig
bitpos = (map_bankwidth(map)-1-i)*8;
#endif
orig.x[0] &= ~(0xff << bitpos);
- orig.x[0] |= buf[i-start] << bitpos;
+ orig.x[0] |= (unsigned long)buf[i-start] << bitpos;
}
}
return orig;
@@ -381,7 +381,7 @@ static inline map_word map_word_ff(struct map_info *map)
if (map_bankwidth(map) < MAP_FF_LIMIT) {
int bw = 8 * map_bankwidth(map);
- r.x[0] = (1 << bw) - 1;
+ r.x[0] = (1UL << bw) - 1;
} else {
for (i=0; i<map_words(map); i++)
r.x[i] = ~0UL;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 070/152] mtd: m25p80: fix allocation size
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (68 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 069/152] mtd: map: fixed bug in 64-bit systems Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 071/152] qeth: avoid buffer overflow in snmp ioctl Kamal Mostafa
` (81 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Brian Norris, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Brian Norris <computersforpeace@gmail.com>
commit 778d226a1462572b51d6777cdb1d611543410cb4 upstream.
This patch fixes two memory errors:
1. During a probe failure (in mtd_device_parse_register?) the command
buffer would not be freed.
2. The command buffer's size is determined based on the 'fast_read'
boolean, but the assignment of fast_read is made after this
allocation. Thus, the buffer may be allocated "too small".
To fix the first, just switch to the devres version of kzalloc.
To fix the second, increase MAX_CMD_SIZE unconditionally. It's not worth
saving a byte to fiddle around with the conditions here.
This problem was reported by Yuhang Wang a while back.
Signed-off-by: Brian Norris <computersforpeace@gmail.com>
Reported-by: Yuhang Wang <wangyuhang2014@gmail.com>
Reviewed-by: Sourav Poddar <sourav.poddar@ti.com>
[ kamal: backport to 3.8 (context) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/mtd/devices/m25p80.c | 20 +++++++-------------
1 file changed, 7 insertions(+), 13 deletions(-)
diff --git a/drivers/mtd/devices/m25p80.c b/drivers/mtd/devices/m25p80.c
index 4eeeb2d..ae5ccf5 100644
--- a/drivers/mtd/devices/m25p80.c
+++ b/drivers/mtd/devices/m25p80.c
@@ -71,7 +71,7 @@
/* Define max times to check status register before we give up. */
#define MAX_READY_WAIT_JIFFIES (40 * HZ) /* M25P16 specs 40s max chip erase */
-#define MAX_CMD_SIZE 5
+#define MAX_CMD_SIZE 6
#define JEDEC_MFR(_jedec_id) ((_jedec_id) >> 16)
@@ -861,15 +861,13 @@ static int m25p_probe(struct spi_device *spi)
}
}
- flash = kzalloc(sizeof *flash, GFP_KERNEL);
+ flash = devm_kzalloc(&spi->dev, sizeof(*flash), GFP_KERNEL);
if (!flash)
return -ENOMEM;
- flash->command = kmalloc(MAX_CMD_SIZE + (flash->fast_read ? 1 : 0),
- GFP_KERNEL);
- if (!flash->command) {
- kfree(flash);
+
+ flash->command = devm_kzalloc(&spi->dev, MAX_CMD_SIZE, GFP_KERNEL);
+ if (!flash->command)
return -ENOMEM;
- }
flash->spi = spi;
mutex_init(&flash->lock);
@@ -976,14 +974,10 @@ static int m25p_probe(struct spi_device *spi)
static int m25p_remove(struct spi_device *spi)
{
struct m25p *flash = dev_get_drvdata(&spi->dev);
- int status;
/* Clean up MTD stuff. */
- status = mtd_device_unregister(&flash->mtd);
- if (status == 0) {
- kfree(flash->command);
- kfree(flash);
- }
+ mtd_device_unregister(&flash->mtd);
+
return 0;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 071/152] qeth: avoid buffer overflow in snmp ioctl
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (69 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 070/152] mtd: m25p80: fix allocation size Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 072/152] x86/ioapic/kcrash: Prevent crash_kexec() from deadlocking on ioapic_lock Kamal Mostafa
` (80 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Ursula Braun, Frank Blaschka, David S. Miller, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ursula Braun <ursula.braun@de.ibm.com>
commit 6fb392b1a63ae36c31f62bc3fc8630b49d602b62 upstream.
Check user-defined length in snmp ioctl request and allow request
only if it fits into a qeth command buffer.
Signed-off-by: Ursula Braun <ursula.braun@de.ibm.com>
Signed-off-by: Frank Blaschka <frank.blaschka@de.ibm.com>
Reviewed-by: Heiko Carstens <heicars2@linux.vnet.ibm.com>
Reported-by: Nico Golde <nico@ngolde.de>
Reported-by: Fabian Yamaguchi <fabs@goesec.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/s390/net/qeth_core_main.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/s390/net/qeth_core_main.c b/drivers/s390/net/qeth_core_main.c
index 638a57f..98b60fd 100644
--- a/drivers/s390/net/qeth_core_main.c
+++ b/drivers/s390/net/qeth_core_main.c
@@ -4368,7 +4368,7 @@ int qeth_snmp_command(struct qeth_card *card, char __user *udata)
struct qeth_cmd_buffer *iob;
struct qeth_ipa_cmd *cmd;
struct qeth_snmp_ureq *ureq;
- int req_len;
+ unsigned int req_len;
struct qeth_arp_query_info qinfo = {0, };
int rc = 0;
@@ -4384,6 +4384,10 @@ int qeth_snmp_command(struct qeth_card *card, char __user *udata)
/* skip 4 bytes (data_len struct member) to get req_len */
if (copy_from_user(&req_len, udata + sizeof(int), sizeof(int)))
return -EFAULT;
+ if (req_len > (QETH_BUFSIZE - IPA_PDU_HEADER_SIZE -
+ sizeof(struct qeth_ipacmd_hdr) -
+ sizeof(struct qeth_ipacmd_setadpparms_hdr)))
+ return -EINVAL;
ureq = memdup_user(udata, req_len + sizeof(struct qeth_snmp_ureq_hdr));
if (IS_ERR(ureq)) {
QETH_CARD_TEXT(card, 2, "snmpnome");
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 072/152] x86/ioapic/kcrash: Prevent crash_kexec() from deadlocking on ioapic_lock
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (70 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 071/152] qeth: avoid buffer overflow in snmp ioctl Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 073/152] x86/apic: Disable I/O APIC before shutdown of the local APIC Kamal Mostafa
` (79 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Yoshihiro YUNOMAE, Andi Kleen, Gleb Natapov,
Konrad Rzeszutek Wilk, Joerg Roedel, Marcelo Tosatti,
Hidehiro Kawai, Sebastian Andrzej Siewior, Zhang Yanfei,
Eric W. Biederman, yrl.pp-manager.tt, Masami Hiramatsu,
Seiji Aguchi, Ingo Molnar, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Yoshihiro YUNOMAE <yoshihiro.yunomae.ez@hitachi.com>
commit 17405453f4ad0220721a29978692081be6392b8f upstream.
Prevent crash_kexec() from deadlocking on ioapic_lock. When
crash_kexec() is executed on a CPU, the CPU will take ioapic_lock
in disable_IO_APIC(). So if the cpu gets an NMI while locking
ioapic_lock, a deadlock will happen.
In this patch, ioapic_lock is zapped/initialized before disable_IO_APIC().
You can reproduce this deadlock the following way:
1. Add mdelay(1000) after raw_spin_lock_irqsave() in
native_ioapic_set_affinity()@arch/x86/kernel/apic/io_apic.c
Although the deadlock can occur without this modification, it will increase
the potential of the deadlock problem.
2. Build and install the kernel
3. Set up the OS which will run panic() and kexec when NMI is injected
# echo "kernel.unknown_nmi_panic=1" >> /etc/sysctl.conf
# vim /etc/default/grub
add "nmi_watchdog=0 crashkernel=256M" in GRUB_CMDLINE_LINUX line
# grub2-mkconfig
4. Reboot the OS
5. Run following command for each vcpu on the guest
# while true; do echo <CPU num> > /proc/irq/<IO-APIC-edge or IO-APIC-fasteoi>/smp_affinitity; done;
By running this command, cpus will get ioapic_lock for setting affinity.
6. Inject NMI (push a dump button or execute 'virsh inject-nmi <domain>' if you
use VM). After injecting NMI, panic() is called in an nmi-handler context.
Then, kexec will normally run in panic(), but the operation will be stopped
by deadlock on ioapic_lock in crash_kexec()->machine_crash_shutdown()->
native_machine_crash_shutdown()->disable_IO_APIC()->clear_IO_APIC()->
clear_IO_APIC_pin()->ioapic_read_entry().
Signed-off-by: Yoshihiro YUNOMAE <yoshihiro.yunomae.ez@hitachi.com>
Cc: Andi Kleen <ak@linux.intel.com>
Cc: Gleb Natapov <gleb@redhat.com>
Cc: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Cc: Joerg Roedel <joro@8bytes.org>
Cc: Marcelo Tosatti <mtosatti@redhat.com>
Cc: Hidehiro Kawai <hidehiro.kawai.ez@hitachi.com>
Cc: Sebastian Andrzej Siewior <sebastian@breakpoint.cc>
Cc: Zhang Yanfei <zhangyanfei@cn.fujitsu.com>
Cc: Eric W. Biederman <ebiederm@xmission.com>
Cc: yrl.pp-manager.tt@hitachi.com
Cc: Masami Hiramatsu <masami.hiramatsu.pt@hitachi.com>
Cc: Seiji Aguchi <seiji.aguchi@hds.com>
Link: http://lkml.kernel.org/r/20130820070107.28245.83806.stgit@yunodevel
Signed-off-by: Ingo Molnar <mingo@kernel.org>
[ kamal: 3.8 stable prereq for
522e664 x86/apic: Disable I/O APIC before shutdown of the local APIC ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/x86/include/asm/apic.h | 2 ++
arch/x86/kernel/apic/io_apic.c | 5 +++++
arch/x86/kernel/crash.c | 4 +++-
3 files changed, 10 insertions(+), 1 deletion(-)
diff --git a/arch/x86/include/asm/apic.h b/arch/x86/include/asm/apic.h
index 3388034..cb8bc81 100644
--- a/arch/x86/include/asm/apic.h
+++ b/arch/x86/include/asm/apic.h
@@ -688,4 +688,6 @@ extern int default_check_phys_apicid_present(int phys_apicid);
#endif /* CONFIG_X86_LOCAL_APIC */
+extern void ioapic_zap_locks(void);
+
#endif /* _ASM_X86_APIC_H */
diff --git a/arch/x86/kernel/apic/io_apic.c b/arch/x86/kernel/apic/io_apic.c
index b739d39..c605173 100644
--- a/arch/x86/kernel/apic/io_apic.c
+++ b/arch/x86/kernel/apic/io_apic.c
@@ -1513,6 +1513,11 @@ static void __init setup_timer_IRQ0_pin(unsigned int ioapic_idx,
ioapic_write_entry(ioapic_idx, pin, entry);
}
+void ioapic_zap_locks(void)
+{
+ raw_spin_lock_init(&ioapic_lock);
+}
+
__apicdebuginit(void) print_IO_APIC(int ioapic_idx)
{
int i;
diff --git a/arch/x86/kernel/crash.c b/arch/x86/kernel/crash.c
index 74467fe..e0e0841 100644
--- a/arch/x86/kernel/crash.c
+++ b/arch/x86/kernel/crash.c
@@ -128,7 +128,9 @@ void native_machine_crash_shutdown(struct pt_regs *regs)
cpu_emergency_svm_disable();
lapic_shutdown();
-#if defined(CONFIG_X86_IO_APIC)
+#ifdef CONFIG_X86_IO_APIC
+ /* Prevent crash_kexec() from deadlocking on ioapic_lock. */
+ ioapic_zap_locks();
disable_IO_APIC();
#endif
#ifdef CONFIG_HPET_TIMER
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 073/152] x86/apic: Disable I/O APIC before shutdown of the local APIC
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (71 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 072/152] x86/ioapic/kcrash: Prevent crash_kexec() from deadlocking on ioapic_lock Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 074/152] parisc: sticon - unbreak on 64bit kernel Kamal Mostafa
` (78 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Fenghua Yu, Ingo Molnar, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Fenghua Yu <fenghua.yu@intel.com>
commit 522e66464467543c0d88d023336eec4df03ad40b upstream.
In reboot and crash path, when we shut down the local APIC, the I/O APIC is
still active. This may cause issues because external interrupts
can still come in and disturb the local APIC during shutdown process.
To quiet external interrupts, disable I/O APIC before shutdown local APIC.
Signed-off-by: Fenghua Yu <fenghua.yu@intel.com>
Link: http://lkml.kernel.org/r/1382578212-4677-1-git-send-email-fenghua.yu@intel.com
[ I suppose the 'issue' is a hang during shutdown. It's a fine change nevertheless. ]
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/x86/kernel/crash.c | 2 +-
arch/x86/kernel/reboot.c | 8 ++++----
2 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/arch/x86/kernel/crash.c b/arch/x86/kernel/crash.c
index e0e0841..18677a9 100644
--- a/arch/x86/kernel/crash.c
+++ b/arch/x86/kernel/crash.c
@@ -127,12 +127,12 @@ void native_machine_crash_shutdown(struct pt_regs *regs)
cpu_emergency_vmxoff();
cpu_emergency_svm_disable();
- lapic_shutdown();
#ifdef CONFIG_X86_IO_APIC
/* Prevent crash_kexec() from deadlocking on ioapic_lock. */
ioapic_zap_locks();
disable_IO_APIC();
#endif
+ lapic_shutdown();
#ifdef CONFIG_HPET_TIMER
hpet_disable();
#endif
diff --git a/arch/x86/kernel/reboot.c b/arch/x86/kernel/reboot.c
index 90fd119..44135ec 100644
--- a/arch/x86/kernel/reboot.c
+++ b/arch/x86/kernel/reboot.c
@@ -629,6 +629,10 @@ static void native_machine_emergency_restart(void)
void native_machine_shutdown(void)
{
/* Stop the cpus and apics */
+#ifdef CONFIG_X86_IO_APIC
+ disable_IO_APIC();
+#endif
+
#ifdef CONFIG_SMP
/* The boot cpu is always logical cpu 0 */
@@ -657,10 +661,6 @@ void native_machine_shutdown(void)
lapic_shutdown();
-#ifdef CONFIG_X86_IO_APIC
- disable_IO_APIC();
-#endif
-
#ifdef CONFIG_HPET_TIMER
hpet_disable();
#endif
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 074/152] parisc: sticon - unbreak on 64bit kernel
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (72 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 073/152] x86/apic: Disable I/O APIC before shutdown of the local APIC Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 075/152] block: fix race between request completion and timeout handling Kamal Mostafa
` (77 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Helge Deller, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Helge Deller <deller@gmx.de>
commit 0219132fe7c26574371232b50db085573f6fbd3f upstream.
STI text console (sticon) was broken on 64bit machines with more than
4GB RAM and this lead in some cases to a kernel crash.
Since sticon uses the 32bit STI API it needs to keep pointers to memory
below 4GB. But on a 64bit kernel some memory regions (e.g. the kernel
stack) might be above 4GB which then may crash the kernel in the STI
functions.
Additionally sticon didn't selected the built-in framebuffer fonts by
default. This is now fixed.
On a side-note: Theoretically we could enhance the sticon driver to
use the 64bit STI API. But - beside the fact that some machines don't
provide a 64bit STI ROM - this would just add complexity.
Signed-off-by: Helge Deller <deller@gmx.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/video/console/sticore.c | 166 +++++++++++++++++++++++++---------------
drivers/video/sticore.h | 62 ++++++++++++---
drivers/video/stifb.c | 10 +--
3 files changed, 158 insertions(+), 80 deletions(-)
diff --git a/drivers/video/console/sticore.c b/drivers/video/console/sticore.c
index 35687fd..4ad24f2 100644
--- a/drivers/video/console/sticore.c
+++ b/drivers/video/console/sticore.c
@@ -3,7 +3,7 @@
* core code for console driver using HP's STI firmware
*
* Copyright (C) 2000 Philipp Rumpf <prumpf@tux.org>
- * Copyright (C) 2001-2003 Helge Deller <deller@gmx.de>
+ * Copyright (C) 2001-2013 Helge Deller <deller@gmx.de>
* Copyright (C) 2001-2002 Thomas Bogendoerfer <tsbogend@alpha.franken.de>
*
* TODO:
@@ -30,7 +30,7 @@
#include "../sticore.h"
-#define STI_DRIVERVERSION "Version 0.9a"
+#define STI_DRIVERVERSION "Version 0.9b"
static struct sti_struct *default_sti __read_mostly;
@@ -73,28 +73,34 @@ static const struct sti_init_flags default_init_flags = {
static int sti_init_graph(struct sti_struct *sti)
{
- struct sti_init_inptr_ext inptr_ext = { 0, };
- struct sti_init_inptr inptr = {
- .text_planes = 3, /* # of text planes (max 3 for STI) */
- .ext_ptr = STI_PTR(&inptr_ext)
- };
- struct sti_init_outptr outptr = { 0, };
+ struct sti_init_inptr *inptr = &sti->sti_data->init_inptr;
+ struct sti_init_inptr_ext *inptr_ext = &sti->sti_data->init_inptr_ext;
+ struct sti_init_outptr *outptr = &sti->sti_data->init_outptr;
unsigned long flags;
- int ret;
+ int ret, err;
spin_lock_irqsave(&sti->lock, flags);
- ret = STI_CALL(sti->init_graph, &default_init_flags, &inptr,
- &outptr, sti->glob_cfg);
+ memset(inptr, 0, sizeof(*inptr));
+ inptr->text_planes = 3; /* # of text planes (max 3 for STI) */
+ memset(inptr_ext, 0, sizeof(*inptr_ext));
+ inptr->ext_ptr = STI_PTR(inptr_ext);
+ outptr->errno = 0;
+
+ ret = sti_call(sti, sti->init_graph, &default_init_flags, inptr,
+ outptr, sti->glob_cfg);
+
+ if (ret >= 0)
+ sti->text_planes = outptr->text_planes;
+ err = outptr->errno;
spin_unlock_irqrestore(&sti->lock, flags);
if (ret < 0) {
- printk(KERN_ERR "STI init_graph failed (ret %d, errno %d)\n",ret,outptr.errno);
+ pr_err("STI init_graph failed (ret %d, errno %d)\n", ret, err);
return -1;
}
- sti->text_planes = outptr.text_planes;
return 0;
}
@@ -104,16 +110,18 @@ static const struct sti_conf_flags default_conf_flags = {
static void sti_inq_conf(struct sti_struct *sti)
{
- struct sti_conf_inptr inptr = { 0, };
+ struct sti_conf_inptr *inptr = &sti->sti_data->inq_inptr;
+ struct sti_conf_outptr *outptr = &sti->sti_data->inq_outptr;
unsigned long flags;
s32 ret;
- sti->outptr.ext_ptr = STI_PTR(&sti->outptr_ext);
+ outptr->ext_ptr = STI_PTR(&sti->sti_data->inq_outptr_ext);
do {
spin_lock_irqsave(&sti->lock, flags);
- ret = STI_CALL(sti->inq_conf, &default_conf_flags,
- &inptr, &sti->outptr, sti->glob_cfg);
+ memset(inptr, 0, sizeof(*inptr));
+ ret = sti_call(sti, sti->inq_conf, &default_conf_flags,
+ inptr, outptr, sti->glob_cfg);
spin_unlock_irqrestore(&sti->lock, flags);
} while (ret == 1);
}
@@ -126,7 +134,8 @@ static const struct sti_font_flags default_font_flags = {
void
sti_putc(struct sti_struct *sti, int c, int y, int x)
{
- struct sti_font_inptr inptr = {
+ struct sti_font_inptr *inptr = &sti->sti_data->font_inptr;
+ struct sti_font_inptr inptr_default = {
.font_start_addr= STI_PTR(sti->font->raw),
.index = c_index(sti, c),
.fg_color = c_fg(sti, c),
@@ -134,14 +143,15 @@ sti_putc(struct sti_struct *sti, int c, int y, int x)
.dest_x = x * sti->font_width,
.dest_y = y * sti->font_height,
};
- struct sti_font_outptr outptr = { 0, };
+ struct sti_font_outptr *outptr = &sti->sti_data->font_outptr;
s32 ret;
unsigned long flags;
do {
spin_lock_irqsave(&sti->lock, flags);
- ret = STI_CALL(sti->font_unpmv, &default_font_flags,
- &inptr, &outptr, sti->glob_cfg);
+ *inptr = inptr_default;
+ ret = sti_call(sti, sti->font_unpmv, &default_font_flags,
+ inptr, outptr, sti->glob_cfg);
spin_unlock_irqrestore(&sti->lock, flags);
} while (ret == 1);
}
@@ -156,7 +166,8 @@ void
sti_set(struct sti_struct *sti, int src_y, int src_x,
int height, int width, u8 color)
{
- struct sti_blkmv_inptr inptr = {
+ struct sti_blkmv_inptr *inptr = &sti->sti_data->blkmv_inptr;
+ struct sti_blkmv_inptr inptr_default = {
.fg_color = color,
.bg_color = color,
.src_x = src_x,
@@ -166,14 +177,15 @@ sti_set(struct sti_struct *sti, int src_y, int src_x,
.width = width,
.height = height,
};
- struct sti_blkmv_outptr outptr = { 0, };
+ struct sti_blkmv_outptr *outptr = &sti->sti_data->blkmv_outptr;
s32 ret;
unsigned long flags;
do {
spin_lock_irqsave(&sti->lock, flags);
- ret = STI_CALL(sti->block_move, &clear_blkmv_flags,
- &inptr, &outptr, sti->glob_cfg);
+ *inptr = inptr_default;
+ ret = sti_call(sti, sti->block_move, &clear_blkmv_flags,
+ inptr, outptr, sti->glob_cfg);
spin_unlock_irqrestore(&sti->lock, flags);
} while (ret == 1);
}
@@ -182,7 +194,8 @@ void
sti_clear(struct sti_struct *sti, int src_y, int src_x,
int height, int width, int c)
{
- struct sti_blkmv_inptr inptr = {
+ struct sti_blkmv_inptr *inptr = &sti->sti_data->blkmv_inptr;
+ struct sti_blkmv_inptr inptr_default = {
.fg_color = c_fg(sti, c),
.bg_color = c_bg(sti, c),
.src_x = src_x * sti->font_width,
@@ -192,14 +205,15 @@ sti_clear(struct sti_struct *sti, int src_y, int src_x,
.width = width * sti->font_width,
.height = height* sti->font_height,
};
- struct sti_blkmv_outptr outptr = { 0, };
+ struct sti_blkmv_outptr *outptr = &sti->sti_data->blkmv_outptr;
s32 ret;
unsigned long flags;
do {
spin_lock_irqsave(&sti->lock, flags);
- ret = STI_CALL(sti->block_move, &clear_blkmv_flags,
- &inptr, &outptr, sti->glob_cfg);
+ *inptr = inptr_default;
+ ret = sti_call(sti, sti->block_move, &clear_blkmv_flags,
+ inptr, outptr, sti->glob_cfg);
spin_unlock_irqrestore(&sti->lock, flags);
} while (ret == 1);
}
@@ -212,7 +226,8 @@ void
sti_bmove(struct sti_struct *sti, int src_y, int src_x,
int dst_y, int dst_x, int height, int width)
{
- struct sti_blkmv_inptr inptr = {
+ struct sti_blkmv_inptr *inptr = &sti->sti_data->blkmv_inptr;
+ struct sti_blkmv_inptr inptr_default = {
.src_x = src_x * sti->font_width,
.src_y = src_y * sti->font_height,
.dest_x = dst_x * sti->font_width,
@@ -220,14 +235,15 @@ sti_bmove(struct sti_struct *sti, int src_y, int src_x,
.width = width * sti->font_width,
.height = height* sti->font_height,
};
- struct sti_blkmv_outptr outptr = { 0, };
+ struct sti_blkmv_outptr *outptr = &sti->sti_data->blkmv_outptr;
s32 ret;
unsigned long flags;
do {
spin_lock_irqsave(&sti->lock, flags);
- ret = STI_CALL(sti->block_move, &default_blkmv_flags,
- &inptr, &outptr, sti->glob_cfg);
+ *inptr = inptr_default;
+ ret = sti_call(sti, sti->block_move, &default_blkmv_flags,
+ inptr, outptr, sti->glob_cfg);
spin_unlock_irqrestore(&sti->lock, flags);
} while (ret == 1);
}
@@ -284,7 +300,7 @@ __setup("sti=", sti_setup);
-static char *font_name[MAX_STI_ROMS] = { "VGA8x16", };
+static char *font_name[MAX_STI_ROMS];
static int font_index[MAX_STI_ROMS],
font_height[MAX_STI_ROMS],
font_width[MAX_STI_ROMS];
@@ -389,10 +405,10 @@ static void sti_dump_outptr(struct sti_struct *sti)
"%d used bits\n"
"%d planes\n"
"attributes %08x\n",
- sti->outptr.bits_per_pixel,
- sti->outptr.bits_used,
- sti->outptr.planes,
- sti->outptr.attributes));
+ sti->sti_data->inq_outptr.bits_per_pixel,
+ sti->sti_data->inq_outptr.bits_used,
+ sti->sti_data->inq_outptr.planes,
+ sti->sti_data->inq_outptr.attributes));
}
static int sti_init_glob_cfg(struct sti_struct *sti, unsigned long rom_address,
@@ -402,24 +418,21 @@ static int sti_init_glob_cfg(struct sti_struct *sti, unsigned long rom_address,
struct sti_glob_cfg_ext *glob_cfg_ext;
void *save_addr;
void *sti_mem_addr;
- const int save_addr_size = 1024; /* XXX */
- int i;
+ int i, size;
- if (!sti->sti_mem_request)
+ if (sti->sti_mem_request < 256)
sti->sti_mem_request = 256; /* STI default */
- glob_cfg = kzalloc(sizeof(*sti->glob_cfg), GFP_KERNEL);
- glob_cfg_ext = kzalloc(sizeof(*glob_cfg_ext), GFP_KERNEL);
- save_addr = kzalloc(save_addr_size, GFP_KERNEL);
- sti_mem_addr = kzalloc(sti->sti_mem_request, GFP_KERNEL);
+ size = sizeof(struct sti_all_data) + sti->sti_mem_request - 256;
- if (!(glob_cfg && glob_cfg_ext && save_addr && sti_mem_addr)) {
- kfree(glob_cfg);
- kfree(glob_cfg_ext);
- kfree(save_addr);
- kfree(sti_mem_addr);
+ sti->sti_data = kzalloc(size, STI_LOWMEM);
+ if (!sti->sti_data)
return -ENOMEM;
- }
+
+ glob_cfg = &sti->sti_data->glob_cfg;
+ glob_cfg_ext = &sti->sti_data->glob_cfg_ext;
+ save_addr = &sti->sti_data->save_addr;
+ sti_mem_addr = &sti->sti_data->sti_mem_addr;
glob_cfg->ext_ptr = STI_PTR(glob_cfg_ext);
glob_cfg->save_addr = STI_PTR(save_addr);
@@ -475,32 +488,31 @@ static int sti_init_glob_cfg(struct sti_struct *sti, unsigned long rom_address,
return 0;
}
-#ifdef CONFIG_FB
+#ifdef CONFIG_FONTS
static struct sti_cooked_font *
sti_select_fbfont(struct sti_cooked_rom *cooked_rom, const char *fbfont_name)
{
- const struct font_desc *fbfont;
+ const struct font_desc *fbfont = NULL;
unsigned int size, bpc;
void *dest;
struct sti_rom_font *nf;
struct sti_cooked_font *cooked_font;
- if (!fbfont_name || !strlen(fbfont_name))
- return NULL;
- fbfont = find_font(fbfont_name);
+ if (fbfont_name && strlen(fbfont_name))
+ fbfont = find_font(fbfont_name);
if (!fbfont)
fbfont = get_default_font(1024,768, ~(u32)0, ~(u32)0);
if (!fbfont)
return NULL;
- DPRINTK((KERN_DEBUG "selected %dx%d fb-font %s\n",
- fbfont->width, fbfont->height, fbfont->name));
+ pr_info("STI selected %dx%d framebuffer font %s for sticon\n",
+ fbfont->width, fbfont->height, fbfont->name);
bpc = ((fbfont->width+7)/8) * fbfont->height;
size = bpc * 256;
size += sizeof(struct sti_rom_font);
- nf = kzalloc(size, GFP_KERNEL);
+ nf = kzalloc(size, STI_LOWMEM);
if (!nf)
return NULL;
@@ -637,7 +649,7 @@ static void *sti_bmode_font_raw(struct sti_cooked_font *f)
unsigned char *n, *p, *q;
int size = f->raw->bytes_per_char*256+sizeof(struct sti_rom_font);
- n = kzalloc (4*size, GFP_KERNEL);
+ n = kzalloc(4*size, STI_LOWMEM);
if (!n)
return NULL;
p = n + 3;
@@ -673,7 +685,7 @@ static struct sti_rom *sti_get_bmode_rom (unsigned long address)
sti_bmode_rom_copy(address + BMODE_LAST_ADDR_OFFS, sizeof(size), &size);
size = (size+3) / 4;
- raw = kmalloc(size, GFP_KERNEL);
+ raw = kmalloc(size, STI_LOWMEM);
if (raw) {
sti_bmode_rom_copy(address, size, raw);
memmove (&raw->res004, &raw->type[0], 0x3c);
@@ -707,7 +719,7 @@ static struct sti_rom *sti_get_wmode_rom(unsigned long address)
/* read the ROM size directly from the struct in ROM */
size = gsc_readl(address + offsetof(struct sti_rom,last_addr));
- raw = kmalloc(size, GFP_KERNEL);
+ raw = kmalloc(size, STI_LOWMEM);
if (raw)
sti_rom_copy(address, size, raw);
@@ -743,6 +755,10 @@ static int sti_read_rom(int wordmode, struct sti_struct *sti,
address = (unsigned long) STI_PTR(raw);
+ pr_info("STI ROM supports 32 %sbit firmware functions.\n",
+ raw->alt_code_type == ALT_CODE_TYPE_PA_RISC_64
+ ? "and 64 " : "");
+
sti->font_unpmv = address + (raw->font_unpmv & 0x03ffffff);
sti->block_move = address + (raw->block_move & 0x03ffffff);
sti->init_graph = address + (raw->init_graph & 0x03ffffff);
@@ -901,7 +917,8 @@ test_rom:
sti_dump_globcfg(sti->glob_cfg, sti->sti_mem_request);
sti_dump_outptr(sti);
- printk(KERN_INFO " graphics card name: %s\n", sti->outptr.dev_name );
+ pr_info(" graphics card name: %s\n",
+ sti->sti_data->inq_outptr.dev_name);
sti_roms[num_sti_roms] = sti;
num_sti_roms++;
@@ -1073,6 +1090,29 @@ struct sti_struct * sti_get_rom(unsigned int index)
}
EXPORT_SYMBOL(sti_get_rom);
+
+int sti_call(const struct sti_struct *sti, unsigned long func,
+ const void *flags, void *inptr, void *outptr,
+ struct sti_glob_cfg *glob_cfg)
+{
+ unsigned long _flags = STI_PTR(flags);
+ unsigned long _inptr = STI_PTR(inptr);
+ unsigned long _outptr = STI_PTR(outptr);
+ unsigned long _glob_cfg = STI_PTR(glob_cfg);
+ int ret;
+
+#ifdef CONFIG_64BIT
+ /* Check for overflow when using 32bit STI on 64bit kernel. */
+ if (WARN_ONCE(_flags>>32 || _inptr>>32 || _outptr>>32 || _glob_cfg>>32,
+ "Out of 32bit-range pointers!"))
+ return -1;
+#endif
+
+ ret = pdc_sti_call(func, _flags, _inptr, _outptr, _glob_cfg);
+
+ return ret;
+}
+
MODULE_AUTHOR("Philipp Rumpf, Helge Deller, Thomas Bogendoerfer");
MODULE_DESCRIPTION("Core STI driver for HP's NGLE series graphics cards in HP PARISC machines");
MODULE_LICENSE("GPL v2");
diff --git a/drivers/video/sticore.h b/drivers/video/sticore.h
index addf7b6..af16195 100644
--- a/drivers/video/sticore.h
+++ b/drivers/video/sticore.h
@@ -18,6 +18,9 @@
#define STI_FONT_HPROMAN8 1
#define STI_FONT_KANA8 2
+#define ALT_CODE_TYPE_UNKNOWN 0x00 /* alt code type values */
+#define ALT_CODE_TYPE_PA_RISC_64 0x01
+
/* The latency of the STI functions cannot really be reduced by setting
* this to 0; STI doesn't seem to be designed to allow calling a different
* function (or the same function with different arguments) after a
@@ -40,14 +43,6 @@
#define STI_PTR(p) ( virt_to_phys(p) )
#define PTR_STI(p) ( phys_to_virt((unsigned long)p) )
-#define STI_CALL(func, flags, inptr, outptr, glob_cfg) \
- ({ \
- pdc_sti_call( func, STI_PTR(flags), \
- STI_PTR(inptr), \
- STI_PTR(outptr), \
- STI_PTR(glob_cfg)); \
- })
-
#define sti_onscreen_x(sti) (sti->glob_cfg->onscreen_x)
#define sti_onscreen_y(sti) (sti->glob_cfg->onscreen_y)
@@ -56,6 +51,12 @@
#define sti_font_x(sti) (PTR_STI(sti->font)->width)
#define sti_font_y(sti) (PTR_STI(sti->font)->height)
+#ifdef CONFIG_64BIT
+#define STI_LOWMEM (GFP_KERNEL | GFP_DMA)
+#else
+#define STI_LOWMEM (GFP_KERNEL)
+#endif
+
/* STI function configuration structs */
@@ -306,6 +307,34 @@ struct sti_blkmv_outptr {
};
+/* sti_all_data is an internal struct which needs to be allocated in
+ * low memory (< 4GB) if STI is used with 32bit STI on a 64bit kernel */
+
+struct sti_all_data {
+ struct sti_glob_cfg glob_cfg;
+ struct sti_glob_cfg_ext glob_cfg_ext;
+
+ struct sti_conf_inptr inq_inptr;
+ struct sti_conf_outptr inq_outptr; /* configuration */
+ struct sti_conf_outptr_ext inq_outptr_ext;
+
+ struct sti_init_inptr_ext init_inptr_ext;
+ struct sti_init_inptr init_inptr;
+ struct sti_init_outptr init_outptr;
+
+ struct sti_blkmv_inptr blkmv_inptr;
+ struct sti_blkmv_outptr blkmv_outptr;
+
+ struct sti_font_inptr font_inptr;
+ struct sti_font_outptr font_outptr;
+
+ /* leave as last entries */
+ unsigned long save_addr[1024 / sizeof(unsigned long)];
+ /* min 256 bytes which is STI default, max sti->sti_mem_request */
+ unsigned long sti_mem_addr[256 / sizeof(unsigned long)];
+ /* do not add something below here ! */
+};
+
/* internal generic STI struct */
struct sti_struct {
@@ -330,11 +359,9 @@ struct sti_struct {
region_t regions[STI_REGION_MAX];
unsigned long regions_phys[STI_REGION_MAX];
- struct sti_glob_cfg *glob_cfg;
- struct sti_cooked_font *font; /* ptr to selected font (cooked) */
+ struct sti_glob_cfg *glob_cfg; /* points into sti_all_data */
- struct sti_conf_outptr outptr; /* configuration */
- struct sti_conf_outptr_ext outptr_ext;
+ struct sti_cooked_font *font; /* ptr to selected font (cooked) */
struct pci_dev *pd;
@@ -343,6 +370,9 @@ struct sti_struct {
/* pointer to the fb_info where this STI device is used */
struct fb_info *info;
+
+ /* pointer to all internal data */
+ struct sti_all_data *sti_data;
};
@@ -350,6 +380,14 @@ struct sti_struct {
struct sti_struct *sti_get_rom(unsigned int index); /* 0: default sti */
+
+/* sticore main function to call STI firmware */
+
+int sti_call(const struct sti_struct *sti, unsigned long func,
+ const void *flags, void *inptr, void *outptr,
+ struct sti_glob_cfg *glob_cfg);
+
+
/* functions to call the STI ROM directly */
void sti_putc(struct sti_struct *sti, int c, int y, int x);
diff --git a/drivers/video/stifb.c b/drivers/video/stifb.c
index 876648e..019a1fe 100644
--- a/drivers/video/stifb.c
+++ b/drivers/video/stifb.c
@@ -1101,6 +1101,7 @@ static int __init stifb_init_fb(struct sti_struct *sti, int bpp_pref)
var = &info->var;
fb->sti = sti;
+ dev_name = sti->sti_data->inq_outptr.dev_name;
/* store upper 32bits of the graphics id */
fb->id = fb->sti->graphics_id[0];
@@ -1114,11 +1115,11 @@ static int __init stifb_init_fb(struct sti_struct *sti, int bpp_pref)
Since this driver only supports standard mode, we check
if the device name contains the string "DX" and tell the
user how to reconfigure the card. */
- if (strstr(sti->outptr.dev_name, "DX")) {
+ if (strstr(dev_name, "DX")) {
printk(KERN_WARNING
"WARNING: stifb framebuffer driver does not support '%s' in double-buffer mode.\n"
"WARNING: Please disable the double-buffer mode in IPL menu (the PARISC-BIOS).\n",
- sti->outptr.dev_name);
+ dev_name);
goto out_err0;
}
/* fall though */
@@ -1130,7 +1131,7 @@ static int __init stifb_init_fb(struct sti_struct *sti, int bpp_pref)
break;
default:
printk(KERN_WARNING "stifb: '%s' (id: 0x%08x) not supported.\n",
- sti->outptr.dev_name, fb->id);
+ dev_name, fb->id);
goto out_err0;
}
@@ -1154,7 +1155,6 @@ static int __init stifb_init_fb(struct sti_struct *sti, int bpp_pref)
fb->id = S9000_ID_A1659A;
break;
case S9000_ID_TIMBER: /* HP9000/710 Any (may be a grayscale device) */
- dev_name = fb->sti->outptr.dev_name;
if (strstr(dev_name, "GRAYSCALE") ||
strstr(dev_name, "Grayscale") ||
strstr(dev_name, "grayscale"))
@@ -1290,7 +1290,7 @@ static int __init stifb_init_fb(struct sti_struct *sti, int bpp_pref)
var->xres,
var->yres,
var->bits_per_pixel,
- sti->outptr.dev_name,
+ dev_name,
fb->id,
fix->mmio_start);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 075/152] block: fix race between request completion and timeout handling
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (73 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 074/152] parisc: sticon - unbreak on 64bit kernel Kamal Mostafa
@ 2013-12-06 23:09 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 076/152] blk-core: Fix memory corruption if blkcg_init_queue fails Kamal Mostafa
` (76 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:09 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Jeff Moyer, Jens Axboe, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Moyer <jmoyer@redhat.com>
commit 4912aa6c11e6a5d910264deedbec2075c6f1bb73 upstream.
crocode i2c_i801 i2c_core iTCO_wdt iTCO_vendor_support shpchp ioatdma dca be2net sg ses enclosure ext4 mbcache jbd2 sd_mod crc_t10dif ahci megaraid_sas(U) dm_mirror dm_region_hash dm_log dm_mod [last unloaded: scsi_wait_scan]
Pid: 491, comm: scsi_eh_0 Tainted: G W ---------------- 2.6.32-220.13.1.el6.x86_64 #1 IBM -[8722PAX]-/00D1461
RIP: 0010:[<ffffffff8124e424>] [<ffffffff8124e424>] blk_requeue_request+0x94/0xa0
RSP: 0018:ffff881057eefd60 EFLAGS: 00010012
RAX: ffff881d99e3e8a8 RBX: ffff881d99e3e780 RCX: ffff881d99e3e8a8
RDX: ffff881d99e3e8a8 RSI: ffff881d99e3e780 RDI: ffff881d99e3e780
RBP: ffff881057eefd80 R08: ffff881057eefe90 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffff881057f92338
R13: 0000000000000000 R14: ffff881057f92338 R15: ffff883058188000
FS: 0000000000000000(0000) GS:ffff880040200000(0000) knlGS:0000000000000000
CS: 0010 DS: 0018 ES: 0018 CR0: 000000008005003b
CR2: 00000000006d3ec0 CR3: 000000302cd7d000 CR4: 00000000000406b0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Process scsi_eh_0 (pid: 491, threadinfo ffff881057eee000, task ffff881057e29540)
Stack:
0000000000001057 0000000000000286 ffff8810275efdc0 ffff881057f16000
<0> ffff881057eefdd0 ffffffff81362323 ffff881057eefe20 ffffffff8135f393
<0> ffff881057e29af8 ffff8810275efdc0 ffff881057eefe78 ffff881057eefe90
Call Trace:
[<ffffffff81362323>] __scsi_queue_insert+0xa3/0x150
[<ffffffff8135f393>] ? scsi_eh_ready_devs+0x5e3/0x850
[<ffffffff81362a23>] scsi_queue_insert+0x13/0x20
[<ffffffff8135e4d4>] scsi_eh_flush_done_q+0x104/0x160
[<ffffffff8135fb6b>] scsi_error_handler+0x35b/0x660
[<ffffffff8135f810>] ? scsi_error_handler+0x0/0x660
[<ffffffff810908c6>] kthread+0x96/0xa0
[<ffffffff8100c14a>] child_rip+0xa/0x20
[<ffffffff81090830>] ? kthread+0x0/0xa0
[<ffffffff8100c140>] ? child_rip+0x0/0x20
Code: 00 00 eb d1 4c 8b 2d 3c 8f 97 00 4d 85 ed 74 bf 49 8b 45 00 49 83 c5 08 48 89 de 4c 89 e7 ff d0 49 8b 45 00 48 85 c0 75 eb eb a4 <0f> 0b eb fe 0f 1f 84 00 00 00 00 00 55 48 89 e5 0f 1f 44 00 00
RIP [<ffffffff8124e424>] blk_requeue_request+0x94/0xa0
RSP <ffff881057eefd60>
The RIP is this line:
BUG_ON(blk_queued_rq(rq));
After digging through the code, I think there may be a race between the
request completion and the timer handler running.
A timer is started for each request put on the device's queue (see
blk_start_request->blk_add_timer). If the request does not complete
before the timer expires, the timer handler (blk_rq_timed_out_timer)
will mark the request complete atomically:
static inline int blk_mark_rq_complete(struct request *rq)
{
return test_and_set_bit(REQ_ATOM_COMPLETE, &rq->atomic_flags);
}
and then call blk_rq_timed_out. The latter function will call
scsi_times_out, which will return one of BLK_EH_HANDLED,
BLK_EH_RESET_TIMER or BLK_EH_NOT_HANDLED. If BLK_EH_RESET_TIMER is
returned, blk_clear_rq_complete is called, and blk_add_timer is again
called to simply wait longer for the request to complete.
Now, if the request happens to complete while this is going on, what
happens? Given that we know the completion handler will bail if it
finds the REQ_ATOM_COMPLETE bit set, we need to focus on the completion
handler running after that bit is cleared. So, from the above
paragraph, after the call to blk_clear_rq_complete. If the completion
sets REQ_ATOM_COMPLETE before the BUG_ON in blk_add_timer, we go boom
there (I haven't seen this in the cores). Next, if we get the
completion before the call to list_add_tail, then the timer will
eventually fire for an old req, which may either be freed or reallocated
(there is evidence that this might be the case). Finally, if the
completion comes in *after* the addition to the timeout list, I think
it's harmless. The request will be removed from the timeout list,
req_atom_complete will be set, and all will be well.
This will only actually explain the coredumps *IF* the request
structure was freed, reallocated *and* queued before the error handler
thread had a chance to process it. That is possible, but it may make
sense to keep digging for another race. I think that if this is what
was happening, we would see other instances of this problem showing up
as null pointer or garbage pointer dereferences, for example when the
request structure was not re-used. It looks like we actually do run
into that situation in other reports.
This patch moves the BUG_ON(test_bit(REQ_ATOM_COMPLETE,
&req->atomic_flags)); from blk_add_timer to the only caller that could
trip over it (blk_start_request). It then inverts the calls to
blk_clear_rq_complete and blk_add_timer in blk_rq_timed_out to address
the race. I've boot tested this patch, but nothing more.
Signed-off-by: Jeff Moyer <jmoyer@redhat.com>
Acked-by: Hannes Reinecke <hare@suse.de>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
block/blk-core.c | 1 +
block/blk-timeout.c | 3 +--
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/block/blk-core.c b/block/blk-core.c
index c973249..6ec83eb 100644
--- a/block/blk-core.c
+++ b/block/blk-core.c
@@ -2204,6 +2204,7 @@ void blk_start_request(struct request *req)
if (unlikely(blk_bidi_rq(req)))
req->next_rq->resid_len = blk_rq_bytes(req->next_rq);
+ BUG_ON(test_bit(REQ_ATOM_COMPLETE, &req->atomic_flags));
blk_add_timer(req);
}
EXPORT_SYMBOL(blk_start_request);
diff --git a/block/blk-timeout.c b/block/blk-timeout.c
index 6e4744c..5a6296e 100644
--- a/block/blk-timeout.c
+++ b/block/blk-timeout.c
@@ -90,8 +90,8 @@ static void blk_rq_timed_out(struct request *req)
__blk_complete_request(req);
break;
case BLK_EH_RESET_TIMER:
- blk_clear_rq_complete(req);
blk_add_timer(req);
+ blk_clear_rq_complete(req);
break;
case BLK_EH_NOT_HANDLED:
/*
@@ -173,7 +173,6 @@ void blk_add_timer(struct request *req)
return;
BUG_ON(!list_empty(&req->timeout_list));
- BUG_ON(test_bit(REQ_ATOM_COMPLETE, &req->atomic_flags));
/*
* Some LLDs, like scsi, peek at the timeout to prevent a
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 076/152] blk-core: Fix memory corruption if blkcg_init_queue fails
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (74 preceding siblings ...)
2013-12-06 23:09 ` [PATCH 3.8 075/152] block: fix race between request completion and timeout handling Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 077/152] loop: fix crash if blk_alloc_queue fails Kamal Mostafa
` (75 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Mikulas Patocka, Jens Axboe, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikulas Patocka <mpatocka@redhat.com>
commit fff4996b7db7955414ac74386efa5e07fd766b50 upstream.
If blkcg_init_queue fails, blk_alloc_queue_node doesn't call bdi_destroy
to clean up structures allocated by the backing dev.
------------[ cut here ]------------
WARNING: at lib/debugobjects.c:260 debug_print_object+0x85/0xa0()
ODEBUG: free active (active state 0) object type: percpu_counter hint: (null)
Modules linked in: dm_loop dm_mod ip6table_filter ip6_tables uvesafb cfbcopyarea cfbimgblt cfbfillrect fbcon font bitblit fbcon_rotate fbcon_cw fbcon_ud fbcon_ccw softcursor fb fbdev ipt_MASQUERADE iptable_nat nf_nat_ipv4 msr nf_conntrack_ipv4 nf_defrag_ipv4 xt_state ipt_REJECT xt_tcpudp iptable_filter ip_tables x_tables bridge stp llc tun ipv6 cpufreq_userspace cpufreq_stats cpufreq_powersave cpufreq_ondemand cpufreq_conservative spadfs fuse hid_generic usbhid hid raid0 md_mod dmi_sysfs nf_nat_ftp nf_nat nf_conntrack_ftp nf_conntrack lm85 hwmon_vid snd_usb_audio snd_pcm_oss snd_mixer_oss snd_pcm snd_timer snd_page_alloc snd_hwdep snd_usbmidi_lib snd_rawmidi snd soundcore acpi_cpufreq freq_table mperf sata_svw serverworks kvm_amd ide_core ehci_pci ohci_hcd libata ehci_hcd kvm usbcore tg3 usb_common libphy k10temp pcspkr ptp i2c_piix4 i2c_core evdev microcode hwmon rtc_cmos pps_core e100 skge floppy mii processor button unix
CPU: 0 PID: 2739 Comm: lvchange Tainted: G W
3.10.15-devel #14
Hardware name: empty empty/S3992-E, BIOS 'V1.06 ' 06/09/2009
0000000000000009 ffff88023c3c1ae8 ffffffff813c8fd4 ffff88023c3c1b20
ffffffff810399eb ffff88043d35cd58 ffffffff81651940 ffff88023c3c1bf8
ffffffff82479d90 0000000000000005 ffff88023c3c1b80 ffffffff81039a67
Call Trace:
[<ffffffff813c8fd4>] dump_stack+0x19/0x1b
[<ffffffff810399eb>] warn_slowpath_common+0x6b/0xa0
[<ffffffff81039a67>] warn_slowpath_fmt+0x47/0x50
[<ffffffff8122aaaf>] ? debug_check_no_obj_freed+0xcf/0x250
[<ffffffff81229a15>] debug_print_object+0x85/0xa0
[<ffffffff8122abe3>] debug_check_no_obj_freed+0x203/0x250
[<ffffffff8113c4ac>] kmem_cache_free+0x20c/0x3a0
[<ffffffff811f6709>] blk_alloc_queue_node+0x2a9/0x2c0
[<ffffffff811f672e>] blk_alloc_queue+0xe/0x10
[<ffffffffa04c0093>] dm_create+0x1a3/0x530 [dm_mod]
[<ffffffffa04c6bb0>] ? list_version_get_info+0xe0/0xe0 [dm_mod]
[<ffffffffa04c6c07>] dev_create+0x57/0x2b0 [dm_mod]
[<ffffffffa04c6bb0>] ? list_version_get_info+0xe0/0xe0 [dm_mod]
[<ffffffffa04c6bb0>] ? list_version_get_info+0xe0/0xe0 [dm_mod]
[<ffffffffa04c6528>] ctl_ioctl+0x268/0x500 [dm_mod]
[<ffffffff81097662>] ? get_lock_stats+0x22/0x70
[<ffffffffa04c67ce>] dm_ctl_ioctl+0xe/0x20 [dm_mod]
[<ffffffff81161aad>] do_vfs_ioctl+0x2ed/0x520
[<ffffffff8116cfc7>] ? fget_light+0x377/0x4e0
[<ffffffff81161d2b>] SyS_ioctl+0x4b/0x90
[<ffffffff813cff16>] system_call_fastpath+0x1a/0x1f
---[ end trace 4b5ff0d55673d986 ]---
------------[ cut here ]------------
This fix should be backported to stable kernels starting with 2.6.37. Note
that in the kernels prior to 3.5 the affected code is different, but the
bug is still there - bdi_init is called and bdi_destroy isn't.
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Acked-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
block/blk-core.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/block/blk-core.c b/block/blk-core.c
index 6ec83eb..5176e78 100644
--- a/block/blk-core.c
+++ b/block/blk-core.c
@@ -654,10 +654,12 @@ struct request_queue *blk_alloc_queue_node(gfp_t gfp_mask, int node_id)
__set_bit(QUEUE_FLAG_BYPASS, &q->queue_flags);
if (blkcg_init_queue(q))
- goto fail_id;
+ goto fail_bdi;
return q;
+fail_bdi:
+ bdi_destroy(&q->backing_dev_info);
fail_id:
ida_simple_remove(&blk_queue_ida, q->id);
fail_q:
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 077/152] loop: fix crash if blk_alloc_queue fails
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (75 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 076/152] blk-core: Fix memory corruption if blkcg_init_queue fails Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 078/152] block: fix a probe argument to blk_register_region Kamal Mostafa
` (74 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Mikulas Patocka, Jens Axboe, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikulas Patocka <mpatocka@redhat.com>
commit 3ec981e30fae1f3c8728a05c730acaa1f627bcfb upstream.
loop: fix crash if blk_alloc_queue fails
If blk_alloc_queue fails, loop_add cleans up, but it doesn't clean up the
identifier allocated with idr_alloc. That causes crash on module unload in
idr_for_each(&loop_index_idr, &loop_exit_cb, NULL); where we attempt to
remove non-existed device with that id.
BUG: unable to handle kernel NULL pointer dereference at 0000000000000380
IP: [<ffffffff812057c9>] del_gendisk+0x19/0x2d0
PGD 43d399067 PUD 43d0ad067 PMD 0
Oops: 0000 [#1] PREEMPT SMP
Modules linked in: loop(-) dm_snapshot dm_zero dm_mirror dm_region_hash dm_log dm_loop dm_mod ip6table_filter ip6_tables uvesafb cfbcopyarea cfbimgblt cfbfillrect fbcon font bitblit fbcon_rotate fbcon_cw fbcon_ud fbcon_ccw softcursor fb fbdev msr ipt_MASQUERADE iptable_nat nf_nat_ipv4 nf_conntrack_ipv4 nf_defrag_ipv4 xt_state ipt_REJECT xt_tcpudp iptable_filter ip_tables x_tables bridge stp llc tun ipv6 cpufreq_userspace cpufreq_stats cpufreq_ondemand cpufreq_conservative cpufreq_powersave spadfs fuse hid_generic usbhid hid raid0 md_mod dmi_sysfs nf_nat_ftp nf_nat nf_conntrack_ftp nf_conntrack snd_usb_audio snd_pcm_oss snd_mixer_oss snd_pcm snd_timer snd_page_alloc lm85 hwmon_vid snd_hwdep snd_usbmidi_lib snd_rawmidi snd soundcore acpi_cpufreq ohci_hcd freq_table tg3 ehci_pci mperf ehci_hcd kvm_amd kvm sata_svw serverworks libphy libata ide_core k10temp usbcore hwmon microcode ptp pcspkr pps_core e100 skge mii usb_common i2c_piix4 floppy evdev rtc_cmos i2c_core processor but!
ton unix
CPU: 7 PID: 2735 Comm: rmmod Tainted: G W 3.10.15-devel #15
Hardware name: empty empty/S3992-E, BIOS 'V1.06 ' 06/09/2009
task: ffff88043d38e780 ti: ffff88043d21e000 task.ti: ffff88043d21e000
RIP: 0010:[<ffffffff812057c9>] [<ffffffff812057c9>] del_gendisk+0x19/0x2d0
RSP: 0018:ffff88043d21fe10 EFLAGS: 00010282
RAX: ffffffffa05102e0 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffff88043ea82800 RDI: 0000000000000000
RBP: ffff88043d21fe48 R08: 0000000000000000 R09: 0000000000000001
R10: 0000000000000001 R11: 0000000000000000 R12: 00000000000000ff
R13: 0000000000000080 R14: 0000000000000000 R15: ffff88043ea82800
FS: 00007ff646534700(0000) GS:ffff880447000000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 000000008005003b
CR2: 0000000000000380 CR3: 000000043e9bf000 CR4: 00000000000007e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Stack:
ffffffff8100aba4 0000000000000092 ffff88043d21fe48 ffff88043ea82800
00000000000000ff ffff88043d21fe98 0000000000000000 ffff88043d21fe60
ffffffffa05102b4 0000000000000000 ffff88043d21fe70 ffffffffa05102ec
Call Trace:
[<ffffffff8100aba4>] ? native_sched_clock+0x24/0x80
[<ffffffffa05102b4>] loop_remove+0x14/0x40 [loop]
[<ffffffffa05102ec>] loop_exit_cb+0xc/0x10 [loop]
[<ffffffff81217b74>] idr_for_each+0x104/0x190
[<ffffffffa05102e0>] ? loop_remove+0x40/0x40 [loop]
[<ffffffff8109adc5>] ? trace_hardirqs_on_caller+0x105/0x1d0
[<ffffffffa05135dc>] loop_exit+0x34/0xa58 [loop]
[<ffffffff810a98ea>] SyS_delete_module+0x13a/0x260
[<ffffffff81221d5e>] ? trace_hardirqs_on_thunk+0x3a/0x3f
[<ffffffff813cff16>] system_call_fastpath+0x1a/0x1f
Code: f0 4c 8b 6d f8 c9 c3 66 66 2e 0f 1f 84 00 00 00 00 00 55 48 89 e5 41 56 41 55 4c 8d af 80 00 00 00 41 54 53 48 89 fb 48 83 ec 18 <48> 83 bf 80 03 00
00 00 74 4d e8 98 fe ff ff 31 f6 48 c7 c7 20
RIP [<ffffffff812057c9>] del_gendisk+0x19/0x2d0
RSP <ffff88043d21fe10>
CR2: 0000000000000380
---[ end trace 64ec069ec70f1309 ]---
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Acked-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/block/loop.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/block/loop.c b/drivers/block/loop.c
index f74f2c0..f18df48 100644
--- a/drivers/block/loop.c
+++ b/drivers/block/loop.c
@@ -1656,7 +1656,7 @@ static int loop_add(struct loop_device **l, int i)
lo->lo_queue = blk_alloc_queue(GFP_KERNEL);
if (!lo->lo_queue)
- goto out_free_dev;
+ goto out_free_idr;
disk = lo->lo_disk = alloc_disk(1 << part_shift);
if (!disk)
@@ -1701,6 +1701,8 @@ static int loop_add(struct loop_device **l, int i)
out_free_queue:
blk_cleanup_queue(lo->lo_queue);
+out_free_idr:
+ idr_remove(&loop_index_idr, i);
out_free_dev:
kfree(lo);
out:
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 078/152] block: fix a probe argument to blk_register_region
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (76 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 077/152] loop: fix crash if blk_alloc_queue fails Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 079/152] block: properly stack underlying max_segment_size to DM device Kamal Mostafa
` (73 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Mikulas Patocka, Jens Axboe, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikulas Patocka <mpatocka@redhat.com>
commit a207f5937630dd35bd2550620bef416937a1365e upstream.
The probe function is supposed to return NULL on failure (as we can see in
kobj_lookup: kobj = probe(dev, index, data); ... if (kobj) return kobj;
However, in loop and brd, it returns negative error from ERR_PTR.
This causes a crash if we simulate disk allocation failure and run
less -f /dev/loop0 because the negative number is interpreted as a pointer:
BUG: unable to handle kernel NULL pointer dereference at 00000000000002b4
IP: [<ffffffff8118b188>] __blkdev_get+0x28/0x450
PGD 23c677067 PUD 23d6d1067 PMD 0
Oops: 0000 [#1] PREEMPT SMP
Modules linked in: loop hpfs nvidia(PO) ip6table_filter ip6_tables uvesafb cfbcopyarea cfbimgblt cfbfillrect fbcon font bitblit fbcon_rotate fbcon_cw fbcon_ud fbcon_ccw softcursor fb fbdev msr ipt_MASQUERADE iptable_nat nf_nat_ipv4 nf_conntrack_ipv4 nf_defrag_ipv4 xt_state ipt_REJECT xt_tcpudp iptable_filter ip_tables x_tables bridge stp llc tun ipv6 cpufreq_stats cpufreq_ondemand cpufreq_userspace cpufreq_powersave cpufreq_conservative hid_generic spadfs usbhid hid fuse raid0 snd_usb_audio snd_pcm_oss snd_mixer_oss md_mod snd_pcm snd_timer snd_page_alloc snd_hwdep snd_usbmidi_lib dmi_sysfs snd_rawmidi nf_nat_ftp nf_nat nf_conntrack_ftp nf_conntrack snd soundcore lm85 hwmon_vid ohci_hcd ehci_pci ehci_hcd serverworks sata_svw libata acpi_cpufreq freq_table mperf ide_core usbcore kvm_amd kvm tg3 i2c_piix4 libphy microcode e100 usb_common ptp skge i2c_core pcspkr k10temp evdev floppy hwmon pps_core mii rtc_cmos button processor unix [last unloaded: nvidia]
CPU: 1 PID: 6831 Comm: less Tainted: P W O 3.10.15-devel #18
Hardware name: empty empty/S3992-E, BIOS 'V1.06 ' 06/09/2009
task: ffff880203cc6bc0 ti: ffff88023e47c000 task.ti: ffff88023e47c000
RIP: 0010:[<ffffffff8118b188>] [<ffffffff8118b188>] __blkdev_get+0x28/0x450
RSP: 0018:ffff88023e47dbd8 EFLAGS: 00010286
RAX: ffffffffffffff74 RBX: ffffffffffffff74 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000001
RBP: ffff88023e47dc18 R08: 0000000000000002 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffff88023f519658
R13: ffffffff8118c300 R14: 0000000000000000 R15: ffff88023f519640
FS: 00007f2070bf7700(0000) GS:ffff880247400000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000000002b4 CR3: 000000023da1d000 CR4: 00000000000007e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Stack:
0000000000000002 0000001d00000000 000000003e47dc50 ffff88023f519640
ffff88043d5bb668 ffffffff8118c300 ffff88023d683550 ffff88023e47de60
ffff88023e47dc98 ffffffff8118c10d 0000001d81605698 0000000000000292
Call Trace:
[<ffffffff8118c300>] ? blkdev_get_by_dev+0x60/0x60
[<ffffffff8118c10d>] blkdev_get+0x1dd/0x370
[<ffffffff8118c300>] ? blkdev_get_by_dev+0x60/0x60
[<ffffffff813cea6c>] ? _raw_spin_unlock+0x2c/0x50
[<ffffffff8118c300>] ? blkdev_get_by_dev+0x60/0x60
[<ffffffff8118c365>] blkdev_open+0x65/0x80
[<ffffffff8114d12e>] do_dentry_open.isra.18+0x23e/0x2f0
[<ffffffff8114d214>] finish_open+0x34/0x50
[<ffffffff8115e122>] do_last.isra.62+0x2d2/0xc50
[<ffffffff8115eb58>] path_openat.isra.63+0xb8/0x4d0
[<ffffffff81115a8e>] ? might_fault+0x4e/0xa0
[<ffffffff8115f4f0>] do_filp_open+0x40/0x90
[<ffffffff813cea6c>] ? _raw_spin_unlock+0x2c/0x50
[<ffffffff8116db85>] ? __alloc_fd+0xa5/0x1f0
[<ffffffff8114e45f>] do_sys_open+0xef/0x1d0
[<ffffffff8114e559>] SyS_open+0x19/0x20
[<ffffffff813cff16>] system_call_fastpath+0x1a/0x1f
Code: 44 00 00 55 48 89 e5 41 57 49 89 ff 41 56 41 89 d6 41 55 41 54 4c 8d 67 18 53 48 83 ec 18 89 75 cc e9 f2 00 00 00 0f 1f 44 00 00 <48> 8b 80 40 03 00 00 48 89 df 4c 8b 68 58 e8 d5
a4 07 00 44 89
RIP [<ffffffff8118b188>] __blkdev_get+0x28/0x450
RSP <ffff88023e47dbd8>
CR2: 00000000000002b4
---[ end trace bb7f32dbf02398dc ]---
The brd change should be backported to stable kernels starting with 2.6.25.
The loop change should be backported to stable kernels starting with 2.6.22.
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Acked-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/block/brd.c | 2 +-
drivers/block/loop.c | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/block/brd.c b/drivers/block/brd.c
index 4e8213a..a7d70e2 100644
--- a/drivers/block/brd.c
+++ b/drivers/block/brd.c
@@ -546,7 +546,7 @@ static struct kobject *brd_probe(dev_t dev, int *part, void *data)
mutex_lock(&brd_devices_mutex);
brd = brd_init_one(MINOR(dev) >> part_shift);
- kobj = brd ? get_disk(brd->brd_disk) : ERR_PTR(-ENOMEM);
+ kobj = brd ? get_disk(brd->brd_disk) : NULL;
mutex_unlock(&brd_devices_mutex);
*part = 0;
diff --git a/drivers/block/loop.c b/drivers/block/loop.c
index f18df48..735e77f 100644
--- a/drivers/block/loop.c
+++ b/drivers/block/loop.c
@@ -1766,7 +1766,7 @@ static struct kobject *loop_probe(dev_t dev, int *part, void *data)
if (err < 0)
err = loop_add(&lo, MINOR(dev) >> part_shift);
if (err < 0)
- kobj = ERR_PTR(err);
+ kobj = NULL;
else
kobj = get_disk(lo->lo_disk);
mutex_unlock(&loop_index_mutex);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 079/152] block: properly stack underlying max_segment_size to DM device
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (77 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 078/152] block: fix a probe argument to blk_register_region Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 080/152] xen/blkback: fix reference counting Kamal Mostafa
` (72 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Mike Snitzer, Jens Axboe, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mike Snitzer <snitzer@redhat.com>
commit d82ae52e68892338068e7559a0c0657193341ce4 upstream.
Without this patch all DM devices will default to BLK_MAX_SEGMENT_SIZE
(65536) even if the underlying device(s) have a larger value -- this is
due to blk_stack_limits() using min_not_zero() when stacking the
max_segment_size limit.
1073741824
before patch:
65536
after patch:
1073741824
Reported-by: Lukasz Flis <l.flis@cyfronet.pl>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
block/blk-settings.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/block/blk-settings.c b/block/blk-settings.c
index c50ecf0..5330933 100644
--- a/block/blk-settings.c
+++ b/block/blk-settings.c
@@ -144,6 +144,7 @@ void blk_set_stacking_limits(struct queue_limits *lim)
lim->discard_zeroes_data = 1;
lim->max_segments = USHRT_MAX;
lim->max_hw_sectors = UINT_MAX;
+ lim->max_segment_size = UINT_MAX;
lim->max_sectors = UINT_MAX;
lim->max_write_same_sectors = UINT_MAX;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 080/152] xen/blkback: fix reference counting
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (78 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 079/152] block: properly stack underlying max_segment_size to DM device Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 081/152] loop: fix crash when using unassigned loop device Kamal Mostafa
` (71 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Jan Beulich, Konrad Rzeszutek Wilk, Vegard Nossum, Jens Axboe,
Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Vegard Nossum <vegard.nossum@oracle.com>
commit ea5ec76d76da9279d12027c1828544c5ccbe7932 upstream.
If the permission check fails, we drop a reference to the blkif without
having taken it in the first place. The bug was introduced in commit
604c499cbbcc3d5fe5fb8d53306aa0fae1990109 (xen/blkback: Check device
permissions before allowing OP_DISCARD).
Cc: Jan Beulich <JBeulich@suse.com>
Cc: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Signed-off-by: Vegard Nossum <vegard.nossum@oracle.com>
Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/block/xen-blkback/blkback.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/block/xen-blkback/blkback.c b/drivers/block/xen-blkback/blkback.c
index bdee5f8..088f012 100644
--- a/drivers/block/xen-blkback/blkback.c
+++ b/drivers/block/xen-blkback/blkback.c
@@ -658,6 +658,8 @@ static int dispatch_discard_io(struct xen_blkif *blkif,
unsigned long secure;
struct phys_req preq;
+ xen_blkif_get(blkif);
+
preq.sector_number = req->u.discard.sector_number;
preq.nr_sects = req->u.discard.nr_sectors;
@@ -670,7 +672,6 @@ static int dispatch_discard_io(struct xen_blkif *blkif,
}
blkif->st_ds_req++;
- xen_blkif_get(blkif);
secure = (blkif->vbd.discard_secure &&
(req->u.discard.flag & BLKIF_DISCARD_SECURE)) ?
BLKDEV_DISCARD_SECURE : 0;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 081/152] loop: fix crash when using unassigned loop device
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (79 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 080/152] xen/blkback: fix reference counting Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 082/152] SUNRPC: Fix a data corruption issue when retransmitting RPC calls Kamal Mostafa
` (70 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Mikulas Patocka, Jens Axboe, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikulas Patocka <mpatocka@redhat.com>
commit ef7e7c82e02b602f29c2b87f42dcd6143a6777da upstream.
When the loop module is loaded, it creates 8 loop devices /dev/loop[0-7].
The devices have no request routine and thus, when they are used without
being assigned, a crash happens.
For example, these commands cause crash (assuming there are no used loop
devices):
Kernel Fault: Code=26 regs=000000007f420980 (Addr=0000000000000010)
CPU: 1 PID: 50 Comm: kworker/1:1 Not tainted 3.11.0 #1
Workqueue: ksnaphd do_metadata [dm_snapshot]
task: 000000007fcf4078 ti: 000000007f420000 task.ti: 000000007f420000
[ 116.319988]
YZrvWESTHLNXBCVMcbcbcbcbOGFRQPDI
PSW: 00001000000001001111111100001111 Not tainted
r00-03 000000ff0804ff0f 00000000408bf5d0 00000000402d8204 000000007b7ff6c0
r04-07 00000000408a95d0 000000007f420950 000000007b7ff6c0 000000007d06c930
r08-11 000000007f4205c0 0000000000000001 000000007f4205c0 000000007f4204b8
r12-15 0000000000000010 0000000000000000 0000000000000000 0000000000000000
r16-19 000000001108dd48 000000004061cd7c 000000007d859800 000000000800000f
r20-23 0000000000000000 0000000000000008 0000000000000000 0000000000000000
r24-27 00000000ffffffff 000000007b7ff6c0 000000007d859800 00000000408a95d0
r28-31 0000000000000000 000000007f420950 000000007f420980 000000007f4208e8
sr00-03 0000000000000000 0000000000000000 0000000000000000 0000000000303000
sr04-07 0000000000000000 0000000000000000 0000000000000000 0000000000000000
[ 117.549988]
IASQ: 0000000000000000 0000000000000000 IAOQ: 00000000402d82fc 00000000402d8300
IIR: 53820020 ISR: 0000000000000000 IOR: 0000000000000010
CPU: 1 CR30: 000000007f420000 CR31: ffffffffffffffff
ORIG_R28: 0000000000000001
IAOQ[0]: generic_make_request+0x11c/0x1a0
IAOQ[1]: generic_make_request+0x120/0x1a0
RP(r2): generic_make_request+0x24/0x1a0
Backtrace:
[<00000000402d83f0>] submit_bio+0x70/0x140
[<0000000011087c4c>] dispatch_io+0x234/0x478 [dm_mod]
[<0000000011087f44>] sync_io+0xb4/0x190 [dm_mod]
[<00000000110883bc>] dm_io+0x2c4/0x310 [dm_mod]
[<00000000110bfcd0>] do_metadata+0x28/0xb0 [dm_snapshot]
[<00000000401591d8>] process_one_work+0x160/0x460
[<0000000040159bc0>] worker_thread+0x300/0x478
[<0000000040161a70>] kthread+0x118/0x128
[<0000000040104020>] end_fault_vector+0x20/0x28
[<0000000040177220>] task_tick_fair+0x420/0x4d0
[<00000000401aa048>] invoke_rcu_core+0x50/0x60
[<00000000401ad5b8>] rcu_check_callbacks+0x210/0x8d8
[<000000004014aaa0>] update_process_times+0xa8/0xc0
[<00000000401ab86c>] rcu_process_callbacks+0x4b4/0x598
[<0000000040142408>] __do_softirq+0x250/0x2c0
[<00000000401789d0>] find_busiest_group+0x3c0/0xc70
[ 119.379988]
Kernel panic - not syncing: Kernel Fault
Rebooting in 1 seconds..
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
[ kamal: backport to 3.8 (context) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/block/loop.c | 15 ++++++++-------
1 file changed, 8 insertions(+), 7 deletions(-)
diff --git a/drivers/block/loop.c b/drivers/block/loop.c
index 735e77f..ca9d5bf 100644
--- a/drivers/block/loop.c
+++ b/drivers/block/loop.c
@@ -887,13 +887,6 @@ static int loop_set_fd(struct loop_device *lo, fmode_t mode,
bio_list_init(&lo->lo_bio_list);
- /*
- * set queue make_request_fn, and add limits based on lower level
- * device
- */
- blk_queue_make_request(lo->lo_queue, loop_make_request);
- lo->lo_queue->queuedata = lo;
-
if (!(lo_flags & LO_FLAGS_READ_ONLY) && file->f_op->fsync)
blk_queue_flush(lo->lo_queue, REQ_FLUSH);
@@ -1629,6 +1622,8 @@ static int loop_add(struct loop_device **l, int i)
if (!lo)
goto out;
+ lo->lo_state = Lo_unbound;
+
if (!idr_pre_get(&loop_index_idr, GFP_KERNEL))
goto out_free_dev;
@@ -1658,6 +1653,12 @@ static int loop_add(struct loop_device **l, int i)
if (!lo->lo_queue)
goto out_free_idr;
+ /*
+ * set queue make_request_fn
+ */
+ blk_queue_make_request(lo->lo_queue, loop_make_request);
+ lo->lo_queue->queuedata = lo;
+
disk = lo->lo_disk = alloc_disk(1 << part_shift);
if (!disk)
goto out_free_queue;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 082/152] SUNRPC: Fix a data corruption issue when retransmitting RPC calls
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (80 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 081/152] loop: fix crash when using unassigned loop device Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 083/152] IB/ipath: Convert ipath_user_sdma_pin_pages() to use get_user_pages_fast() Kamal Mostafa
` (69 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Trond Myklebust, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Trond Myklebust <Trond.Myklebust@netapp.com>
commit a6b31d18b02ff9d7915c5898c9b5ca41a798cd73 upstream.
The following scenario can cause silent data corruption when doing
NFS writes. It has mainly been observed when doing database writes
using O_DIRECT.
1) The RPC client uses sendpage() to do zero-copy of the page data.
2) Due to networking issues, the reply from the server is delayed,
and so the RPC client times out.
3) The client issues a second sendpage of the page data as part of
an RPC call retransmission.
4) The reply to the first transmission arrives from the server
_before_ the client hardware has emptied the TCP socket send
buffer.
5) After processing the reply, the RPC state machine rules that
the call to be done, and triggers the completion callbacks.
6) The application notices the RPC call is done, and reuses the
pages to store something else (e.g. a new write).
7) The client NIC drains the TCP socket send buffer. Since the
page data has now changed, it reads a corrupted version of the
initial RPC call, and puts it on the wire.
This patch fixes the problem in the following manner:
The ordering guarantees of TCP ensure that when the server sends a
reply, then we know that the _first_ transmission has completed. Using
zero-copy in that situation is therefore safe.
If a time out occurs, we then send the retransmission using sendmsg()
(i.e. no zero-copy), We then know that the socket contains a full copy of
the data, and so it will retransmit a faithful reproduction even if the
RPC call completes, and the application reuses the O_DIRECT buffer in
the meantime.
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
net/sunrpc/xprtsock.c | 28 +++++++++++++++++++++-------
1 file changed, 21 insertions(+), 7 deletions(-)
diff --git a/net/sunrpc/xprtsock.c b/net/sunrpc/xprtsock.c
index 68b0a81..c50ac35 100644
--- a/net/sunrpc/xprtsock.c
+++ b/net/sunrpc/xprtsock.c
@@ -390,8 +390,10 @@ static int xs_send_kvec(struct socket *sock, struct sockaddr *addr, int addrlen,
return kernel_sendmsg(sock, &msg, NULL, 0, 0);
}
-static int xs_send_pagedata(struct socket *sock, struct xdr_buf *xdr, unsigned int base, int more)
+static int xs_send_pagedata(struct socket *sock, struct xdr_buf *xdr, unsigned int base, int more, bool zerocopy)
{
+ ssize_t (*do_sendpage)(struct socket *sock, struct page *page,
+ int offset, size_t size, int flags);
struct page **ppage;
unsigned int remainder;
int err, sent = 0;
@@ -400,6 +402,9 @@ static int xs_send_pagedata(struct socket *sock, struct xdr_buf *xdr, unsigned i
base += xdr->page_base;
ppage = xdr->pages + (base >> PAGE_SHIFT);
base &= ~PAGE_MASK;
+ do_sendpage = sock->ops->sendpage;
+ if (!zerocopy)
+ do_sendpage = sock_no_sendpage;
for(;;) {
unsigned int len = min_t(unsigned int, PAGE_SIZE - base, remainder);
int flags = XS_SENDMSG_FLAGS;
@@ -407,7 +412,7 @@ static int xs_send_pagedata(struct socket *sock, struct xdr_buf *xdr, unsigned i
remainder -= len;
if (remainder != 0 || more)
flags |= MSG_MORE;
- err = sock->ops->sendpage(sock, *ppage, base, len, flags);
+ err = do_sendpage(sock, *ppage, base, len, flags);
if (remainder == 0 || err != len)
break;
sent += err;
@@ -428,9 +433,10 @@ static int xs_send_pagedata(struct socket *sock, struct xdr_buf *xdr, unsigned i
* @addrlen: UDP only -- length of destination address
* @xdr: buffer containing this request
* @base: starting position in the buffer
+ * @zerocopy: true if it is safe to use sendpage()
*
*/
-static int xs_sendpages(struct socket *sock, struct sockaddr *addr, int addrlen, struct xdr_buf *xdr, unsigned int base)
+static int xs_sendpages(struct socket *sock, struct sockaddr *addr, int addrlen, struct xdr_buf *xdr, unsigned int base, bool zerocopy)
{
unsigned int remainder = xdr->len - base;
int err, sent = 0;
@@ -458,7 +464,7 @@ static int xs_sendpages(struct socket *sock, struct sockaddr *addr, int addrlen,
if (base < xdr->page_len) {
unsigned int len = xdr->page_len - base;
remainder -= len;
- err = xs_send_pagedata(sock, xdr, base, remainder != 0);
+ err = xs_send_pagedata(sock, xdr, base, remainder != 0, zerocopy);
if (remainder == 0 || err != len)
goto out;
sent += err;
@@ -561,7 +567,7 @@ static int xs_local_send_request(struct rpc_task *task)
req->rq_svec->iov_base, req->rq_svec->iov_len);
status = xs_sendpages(transport->sock, NULL, 0,
- xdr, req->rq_bytes_sent);
+ xdr, req->rq_bytes_sent, true);
dprintk("RPC: %s(%u) = %d\n",
__func__, xdr->len - req->rq_bytes_sent, status);
if (likely(status >= 0)) {
@@ -617,7 +623,7 @@ static int xs_udp_send_request(struct rpc_task *task)
status = xs_sendpages(transport->sock,
xs_addr(xprt),
xprt->addrlen, xdr,
- req->rq_bytes_sent);
+ req->rq_bytes_sent, true);
dprintk("RPC: xs_udp_send_request(%u) = %d\n",
xdr->len - req->rq_bytes_sent, status);
@@ -688,6 +694,7 @@ static int xs_tcp_send_request(struct rpc_task *task)
struct rpc_xprt *xprt = req->rq_xprt;
struct sock_xprt *transport = container_of(xprt, struct sock_xprt, xprt);
struct xdr_buf *xdr = &req->rq_snd_buf;
+ bool zerocopy = true;
int status;
xs_encode_stream_record_marker(&req->rq_snd_buf);
@@ -695,13 +702,20 @@ static int xs_tcp_send_request(struct rpc_task *task)
xs_pktdump("packet data:",
req->rq_svec->iov_base,
req->rq_svec->iov_len);
+ /* Don't use zero copy if this is a resend. If the RPC call
+ * completes while the socket holds a reference to the pages,
+ * then we may end up resending corrupted data.
+ */
+ if (task->tk_flags & RPC_TASK_SENT)
+ zerocopy = false;
/* Continue transmitting the packet/record. We must be careful
* to cope with writespace callbacks arriving _after_ we have
* called sendmsg(). */
while (1) {
status = xs_sendpages(transport->sock,
- NULL, 0, xdr, req->rq_bytes_sent);
+ NULL, 0, xdr, req->rq_bytes_sent,
+ zerocopy);
dprintk("RPC: xs_tcp_send_request(%u) = %d\n",
xdr->len - req->rq_bytes_sent, status);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 083/152] IB/ipath: Convert ipath_user_sdma_pin_pages() to use get_user_pages_fast()
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (81 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 082/152] SUNRPC: Fix a data corruption issue when retransmitting RPC calls Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 084/152] IB/qib: Fix txselect regression Kamal Mostafa
` (68 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Jan Kara, Mike Marciniszyn, Roland Dreier, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jan Kara <jack@suse.cz>
commit 4adcf7fb6783e354aab38824d803fa8c4f8e8a27 upstream.
ipath_user_sdma_queue_pkts() gets called with mmap_sem held for
writing. Except for get_user_pages() deep down in
ipath_user_sdma_pin_pages() we don't seem to need mmap_sem at all.
Even more interestingly the function ipath_user_sdma_queue_pkts() (and
also ipath_user_sdma_coalesce() called somewhat later) call
copy_from_user() which can hit a page fault and we deadlock on trying
to get mmap_sem when handling that fault. So just make
ipath_user_sdma_pin_pages() use get_user_pages_fast() and leave
mmap_sem locking for mm.
This deadlock has actually been observed in the wild when the node
is under memory pressure.
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Mike Marciniszyn <mike.marciniszyn@intel.com>
[ Merged in fix for call to get_user_pages_fast from Tetsuo Handa
<penguin-kernel@I-love.SAKURA.ne.jp>. - Roland ]
Signed-off-by: Roland Dreier <roland@purestorage.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/infiniband/hw/ipath/ipath_user_sdma.c | 7 +------
1 file changed, 1 insertion(+), 6 deletions(-)
diff --git a/drivers/infiniband/hw/ipath/ipath_user_sdma.c b/drivers/infiniband/hw/ipath/ipath_user_sdma.c
index f5cb13b..cc04b7b 100644
--- a/drivers/infiniband/hw/ipath/ipath_user_sdma.c
+++ b/drivers/infiniband/hw/ipath/ipath_user_sdma.c
@@ -280,9 +280,7 @@ static int ipath_user_sdma_pin_pages(const struct ipath_devdata *dd,
int j;
int ret;
- ret = get_user_pages(current, current->mm, addr,
- npages, 0, 1, pages, NULL);
-
+ ret = get_user_pages_fast(addr, npages, 0, pages);
if (ret != npages) {
int i;
@@ -811,10 +809,7 @@ int ipath_user_sdma_writev(struct ipath_devdata *dd,
while (dim) {
const int mxp = 8;
- down_write(¤t->mm->mmap_sem);
ret = ipath_user_sdma_queue_pkts(dd, pq, &list, iov, dim, mxp);
- up_write(¤t->mm->mmap_sem);
-
if (ret <= 0)
goto done_unlock;
else {
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 084/152] IB/qib: Fix txselect regression
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (82 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 083/152] IB/ipath: Convert ipath_user_sdma_pin_pages() to use get_user_pages_fast() Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 085/152] IB/srp: Remove target from list before freeing Scsi_Host structure Kamal Mostafa
` (67 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Mike Marciniszyn, Roland Dreier, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mike Marciniszyn <mike.marciniszyn@intel.com>
commit 2fadd83184d58701f1116ca578465b5a75f9417c upstream.
Commit 7fac33014f54("IB/qib: checkpatch fixes") was overzealous in
removing a simple_strtoul for a parse routine, setup_txselect(). That
routine is required to handle a multi-value string.
Unwind that aspect of the fix.
Signed-off-by: Mike Marciniszyn <mike.marciniszyn@intel.com>
Signed-off-by: Roland Dreier <roland@purestorage.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/infiniband/hw/qib/qib_iba7322.c | 11 +++++------
1 file changed, 5 insertions(+), 6 deletions(-)
diff --git a/drivers/infiniband/hw/qib/qib_iba7322.c b/drivers/infiniband/hw/qib/qib_iba7322.c
index 3f6b21e..bd8cb0f 100644
--- a/drivers/infiniband/hw/qib/qib_iba7322.c
+++ b/drivers/infiniband/hw/qib/qib_iba7322.c
@@ -5853,21 +5853,20 @@ static int setup_txselect(const char *str, struct kernel_param *kp)
{
struct qib_devdata *dd;
unsigned long val;
- int ret;
-
+ char *n;
if (strlen(str) >= MAX_ATTEN_LEN) {
pr_info("txselect_values string too long\n");
return -ENOSPC;
}
- ret = kstrtoul(str, 0, &val);
- if (ret || val >= (TXDDS_TABLE_SZ + TXDDS_EXTRA_SZ +
+ val = simple_strtoul(str, &n, 0);
+ if (n == str || val >= (TXDDS_TABLE_SZ + TXDDS_EXTRA_SZ +
TXDDS_MFG_SZ)) {
pr_info("txselect_values must start with a number < %d\n",
TXDDS_TABLE_SZ + TXDDS_EXTRA_SZ + TXDDS_MFG_SZ);
- return ret ? ret : -EINVAL;
+ return -EINVAL;
}
-
strcpy(txselect_list, str);
+
list_for_each_entry(dd, &qib_dev_list, list)
if (dd->deviceid == PCI_DEVICE_ID_QLOGIC_IB_7322)
set_no_qsfp_atten(dd, 1);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 085/152] IB/srp: Remove target from list before freeing Scsi_Host structure
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (83 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 084/152] IB/qib: Fix txselect regression Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 086/152] IB/srp: Avoid offlining operational SCSI devices Kamal Mostafa
` (66 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Vu Pham, Bart Van Assche, Roland Dreier, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Vu Pham <vuhuong@mellanox.com>
commit 65d7dd2f3479ef5aec1d9ddd1481cb7851c11af6 upstream.
Remove an SRP target from the SRP target list before invoking the last
scsi_host_put() call. This change is necessary because that last put
frees the memory that holds the srp_target_port structure.
This patch prevents the following kernel oops:
RIP: 0010:[<ffffffff810b00d0>] __lock_acquire+0x500/0x1570
Call Trace:
[<ffffffff810b11e4>] lock_acquire+0xa4/0x120
[<ffffffff81531206>] _spin_lock+0x36/0x70
[<ffffffffa01b6d8f>] srp_remove_work+0xef/0x180 [ib_srp]
[<ffffffff8109125c>] worker_thread+0x21c/0x3d0
[<ffffffff81096e86>] kthread+0x96/0xa0
[<ffffffff8100c20a>] child_rip+0xa/0x20
Signed-off-by: Vu Pham <vuhuong@mellanox.com>
[ bvanassche - Modified path description and CC'ed stable. ]
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Signed-off-by: Roland Dreier <roland@purestorage.com>
[ kamal: backport to 3.8 (context) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/infiniband/ulp/srp/ib_srp.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/infiniband/ulp/srp/ib_srp.c b/drivers/infiniband/ulp/srp/ib_srp.c
index 7ccf328..2223eb6 100644
--- a/drivers/infiniband/ulp/srp/ib_srp.c
+++ b/drivers/infiniband/ulp/srp/ib_srp.c
@@ -532,6 +532,11 @@ static void srp_remove_target(struct srp_target_port *target)
ib_destroy_cm_id(target->cm_id);
srp_free_target_ib(target);
srp_free_req_data(target);
+
+ spin_lock(&target->srp_host->target_lock);
+ list_del(&target->list);
+ spin_unlock(&target->srp_host->target_lock);
+
scsi_host_put(target->scsi_host);
}
@@ -542,10 +547,6 @@ static void srp_remove_work(struct work_struct *work)
WARN_ON_ONCE(target->state != SRP_TARGET_REMOVED);
- spin_lock(&target->srp_host->target_lock);
- list_del(&target->list);
- spin_unlock(&target->srp_host->target_lock);
-
srp_remove_target(target);
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 086/152] IB/srp: Avoid offlining operational SCSI devices
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (84 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 085/152] IB/srp: Remove target from list before freeing Scsi_Host structure Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 087/152] IB/srp: Report receive errors correctly Kamal Mostafa
` (65 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Bart Van Assche, Roland Dreier, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Bart Van Assche <bvanassche@acm.org>
commit 99b6697a50c2acbe3ca2772d359fc9a28835dc84 upstream.
If SCSI commands are submitted with a SCSI request timeout that is
lower than the the IB RC timeout, it can happen that the SCSI error
handler has already started device recovery before transport layer
error handling starts. So it can happen that the SCSI error handler
tries to abort a SCSI command after it has been reset by
srp_rport_reconnect().
Tell the SCSI error handler that such commands have finished and that
it is not necessary to continue its recovery strategy for commands
that have been reset by srp_rport_reconnect().
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Signed-off-by: Roland Dreier <roland@purestorage.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/infiniband/ulp/srp/ib_srp.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/ulp/srp/ib_srp.c b/drivers/infiniband/ulp/srp/ib_srp.c
index 2223eb6..bff567b 100644
--- a/drivers/infiniband/ulp/srp/ib_srp.c
+++ b/drivers/infiniband/ulp/srp/ib_srp.c
@@ -1749,7 +1749,7 @@ static int srp_abort(struct scsi_cmnd *scmnd)
shost_printk(KERN_ERR, target->scsi_host, "SRP abort called\n");
if (!req || !srp_claim_req(target, req, scmnd))
- return FAILED;
+ return SUCCESS;
srp_send_tsk_mgmt(target, req->index, scmnd->device->lun,
SRP_TSK_ABORT_TASK);
srp_free_req(target, req, scmnd, 0);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 087/152] IB/srp: Report receive errors correctly
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (85 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 086/152] IB/srp: Avoid offlining operational SCSI devices Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 088/152] rtlwifi: rtl8192se: Fix wrong assignment Kamal Mostafa
` (64 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Bart Van Assche, Roland Dreier, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Bart Van Assche <bvanassche@acm.org>
commit cd4e38542a5c2cab94e5410fb17c1cc004a60792 upstream.
The IB spec does not guarantee that the opcode is available in error
completions. Hence do not rely on it. See also commit 948d1e889e5b
("IB/srp: Introduce srp_handle_qp_err()").
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Signed-off-by: Roland Dreier <roland@purestorage.com>
[ kamal: backport to 3.8 (context) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/infiniband/ulp/srp/ib_srp.c | 9 ++++-----
1 file changed, 4 insertions(+), 5 deletions(-)
diff --git a/drivers/infiniband/ulp/srp/ib_srp.c b/drivers/infiniband/ulp/srp/ib_srp.c
index bff567b..e070166 100644
--- a/drivers/infiniband/ulp/srp/ib_srp.c
+++ b/drivers/infiniband/ulp/srp/ib_srp.c
@@ -1301,14 +1301,13 @@ static void srp_handle_recv(struct srp_target_port *target, struct ib_wc *wc)
PFX "Recv failed with error code %d\n", res);
}
-static void srp_handle_qp_err(enum ib_wc_status wc_status,
- enum ib_wc_opcode wc_opcode,
+static void srp_handle_qp_err(enum ib_wc_status wc_status, bool send_err,
struct srp_target_port *target)
{
if (target->connected && !target->qp_in_error) {
shost_printk(KERN_ERR, target->scsi_host,
PFX "failed %s status %d\n",
- wc_opcode & IB_WC_RECV ? "receive" : "send",
+ send_err ? "send" : "receive",
wc_status);
}
target->qp_in_error = true;
@@ -1324,7 +1323,7 @@ static void srp_recv_completion(struct ib_cq *cq, void *target_ptr)
if (likely(wc.status == IB_WC_SUCCESS)) {
srp_handle_recv(target, &wc);
} else {
- srp_handle_qp_err(wc.status, wc.opcode, target);
+ srp_handle_qp_err(wc.status, false, target);
}
}
}
@@ -1340,7 +1339,7 @@ static void srp_send_completion(struct ib_cq *cq, void *target_ptr)
iu = (struct srp_iu *) (uintptr_t) wc.wr_id;
list_add(&iu->list, &target->free_tx);
} else {
- srp_handle_qp_err(wc.status, wc.opcode, target);
+ srp_handle_qp_err(wc.status, true, target);
}
}
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 088/152] rtlwifi: rtl8192se: Fix wrong assignment
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (86 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 087/152] IB/srp: Report receive errors correctly Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 089/152] rt2x00: fix HT TX descriptor settings regression Kamal Mostafa
` (63 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Felipe Pena, John W. Linville, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Felipe Pena <felipensp@gmail.com>
commit 3aef7dde8dcf09e0124f0a2665845a507331972b upstream.
There is a typo in the struct member name on assignment when checking
rtlphy->current_chan_bw == HT_CHANNEL_WIDTH_20_40, the check uses pwrgroup_ht40
for bound limit and uses pwrgroup_ht20 when assigning instead.
Signed-off-by: Felipe Pena <felipensp@gmail.com>
Acked-by: Larry Finger <Larry.Finger@lwfinger.net>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/rtlwifi/rtl8192se/rf.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/rtlwifi/rtl8192se/rf.c b/drivers/net/wireless/rtlwifi/rtl8192se/rf.c
index 5061f1d..92d38ab 100644
--- a/drivers/net/wireless/rtlwifi/rtl8192se/rf.c
+++ b/drivers/net/wireless/rtlwifi/rtl8192se/rf.c
@@ -265,7 +265,7 @@ static void _rtl92s_get_txpower_writeval_byregulatory(struct ieee80211_hw *hw,
rtlefuse->pwrgroup_ht40
[RF90_PATH_A][chnl - 1]) {
pwrdiff_limit[i] =
- rtlefuse->pwrgroup_ht20
+ rtlefuse->pwrgroup_ht40
[RF90_PATH_A][chnl - 1];
}
} else {
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 089/152] rt2x00: fix HT TX descriptor settings regression
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (87 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 088/152] rtlwifi: rtl8192se: Fix wrong assignment Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 090/152] rtlwifi: Fix endian error in extracting packet type Kamal Mostafa
` (62 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Stanislaw Gruszka, John W. Linville, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislaw Gruszka <sgruszka@redhat.com>
commit 3d8bfe141be8e5c21261fc63da8e7964d44f2645 upstream.
Since:
commit 36323f817af0376c78612cfdab714b0feb05fea5
Author: Thomas Huehn <thomas@net.t-labs.tu-berlin.de>
Date: Mon Jul 23 21:33:42 2012 +0200
mac80211: move TX station pointer and restructure TX
we do not pass sta pointer to rt2x00queue_create_tx_descriptor_ht(),
hence we do not correctly set station WCID and AMPDU density parameters.
Signed-off-by: Stanislaw Gruszka <sgruszka@redhat.com>
Acked-by: Gertjan van Wingerde <gwingerde@gmail.com>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/rt2x00/rt2x00lib.h | 2 +-
drivers/net/wireless/rt2x00/rt2x00mac.c | 4 ++--
drivers/net/wireless/rt2x00/rt2x00queue.c | 4 ++--
3 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/drivers/net/wireless/rt2x00/rt2x00lib.h b/drivers/net/wireless/rt2x00/rt2x00lib.h
index a093598..7f40ab8 100644
--- a/drivers/net/wireless/rt2x00/rt2x00lib.h
+++ b/drivers/net/wireless/rt2x00/rt2x00lib.h
@@ -146,7 +146,7 @@ void rt2x00queue_remove_l2pad(struct sk_buff *skb, unsigned int header_length);
* @local: frame is not from mac80211
*/
int rt2x00queue_write_tx_frame(struct data_queue *queue, struct sk_buff *skb,
- bool local);
+ struct ieee80211_sta *sta, bool local);
/**
* rt2x00queue_update_beacon - Send new beacon from mac80211
diff --git a/drivers/net/wireless/rt2x00/rt2x00mac.c b/drivers/net/wireless/rt2x00/rt2x00mac.c
index 509c3f1..9b00fcb 100644
--- a/drivers/net/wireless/rt2x00/rt2x00mac.c
+++ b/drivers/net/wireless/rt2x00/rt2x00mac.c
@@ -90,7 +90,7 @@ static int rt2x00mac_tx_rts_cts(struct rt2x00_dev *rt2x00dev,
frag_skb->data, data_length, tx_info,
(struct ieee80211_rts *)(skb->data));
- retval = rt2x00queue_write_tx_frame(queue, skb, true);
+ retval = rt2x00queue_write_tx_frame(queue, skb, NULL, true);
if (retval) {
dev_kfree_skb_any(skb);
WARNING(rt2x00dev, "Failed to send RTS/CTS frame.\n");
@@ -151,7 +151,7 @@ void rt2x00mac_tx(struct ieee80211_hw *hw,
goto exit_fail;
}
- if (unlikely(rt2x00queue_write_tx_frame(queue, skb, false)))
+ if (unlikely(rt2x00queue_write_tx_frame(queue, skb, control->sta, false)))
goto exit_fail;
/*
diff --git a/drivers/net/wireless/rt2x00/rt2x00queue.c b/drivers/net/wireless/rt2x00/rt2x00queue.c
index a57032e..bc1216f 100644
--- a/drivers/net/wireless/rt2x00/rt2x00queue.c
+++ b/drivers/net/wireless/rt2x00/rt2x00queue.c
@@ -583,7 +583,7 @@ static void rt2x00queue_kick_tx_queue(struct data_queue *queue,
}
int rt2x00queue_write_tx_frame(struct data_queue *queue, struct sk_buff *skb,
- bool local)
+ struct ieee80211_sta *sta, bool local)
{
struct ieee80211_tx_info *tx_info;
struct queue_entry *entry;
@@ -597,7 +597,7 @@ int rt2x00queue_write_tx_frame(struct data_queue *queue, struct sk_buff *skb,
* after that we are free to use the skb->cb array
* for our information.
*/
- rt2x00queue_create_tx_descriptor(queue->rt2x00dev, skb, &txdesc, NULL);
+ rt2x00queue_create_tx_descriptor(queue->rt2x00dev, skb, &txdesc, sta);
/*
* All information is retrieved from the skb->cb array,
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 090/152] rtlwifi: Fix endian error in extracting packet type
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (88 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 089/152] rt2x00: fix HT TX descriptor settings regression Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 091/152] rtlwifi: rtl8192cu: Fix incorrect signal strength for unassociated AP Kamal Mostafa
` (61 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Larry Finger, Mark Cave-Ayland, John W. Linville, Luis Henriques,
Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Cave-Ayland <mark.cave-ayland@ilande.co.uk>
commit 0c5d63f0ab6728f05ddefa25aff55e31297f95e6 upstream.
All of the rtlwifi drivers have an error in the routine that tests if
the data is "special". If it is, the subsequant transmission will be
at the lowest rate to enhance reliability. The 16-bit quantity is
big-endian, but was being extracted in native CPU mode. One of the
effects of this bug is to inhibit association under some conditions
as the TX rate is too high.
Based on suggestions by Joe Perches, the entire routine is rewritten.
One of the local headers contained duplicates of some of the ETH_P_XXX
definitions. These are deleted.
Signed-off-by: Larry Finger <Larry.Finger@lwfinger.net>
Cc: Mark Cave-Ayland <mark.cave-ayland@ilande.co.uk>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
[ luis: backported to 3.5: since commit a269913 has not been backported:
- dropped changes to rtl_priv->enter_ps field
- replaced lps_change_work by lps_leave_work ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/rtlwifi/base.c | 89 +++++++++++++++++--------------------
drivers/net/wireless/rtlwifi/wifi.h | 6 +--
2 files changed, 41 insertions(+), 54 deletions(-)
diff --git a/drivers/net/wireless/rtlwifi/base.c b/drivers/net/wireless/rtlwifi/base.c
index 0f8b051..acfaf40 100644
--- a/drivers/net/wireless/rtlwifi/base.c
+++ b/drivers/net/wireless/rtlwifi/base.c
@@ -37,6 +37,7 @@
#include <linux/ip.h>
#include <linux/module.h>
+#include <linux/udp.h>
/*
*NOTICE!!!: This file will be very big, we should
@@ -981,61 +982,51 @@ u8 rtl_is_special_data(struct ieee80211_hw *hw, struct sk_buff *skb, u8 is_tx)
if (!ieee80211_is_data(fc))
return false;
+ ip = (const struct iphdr *)(skb->data + mac_hdr_len +
+ SNAP_SIZE + PROTOC_TYPE_SIZE);
+ ether_type = be16_to_cpup((__be16 *)
+ (skb->data + mac_hdr_len + SNAP_SIZE));
- ip = (struct iphdr *)((u8 *) skb->data + mac_hdr_len +
- SNAP_SIZE + PROTOC_TYPE_SIZE);
- ether_type = *(u16 *) ((u8 *) skb->data + mac_hdr_len + SNAP_SIZE);
- /* ether_type = ntohs(ether_type); */
-
- if (ETH_P_IP == ether_type) {
- if (IPPROTO_UDP == ip->protocol) {
- struct udphdr *udp = (struct udphdr *)((u8 *) ip +
- (ip->ihl << 2));
- if (((((u8 *) udp)[1] == 68) &&
- (((u8 *) udp)[3] == 67)) ||
- ((((u8 *) udp)[1] == 67) &&
- (((u8 *) udp)[3] == 68))) {
- /*
- * 68 : UDP BOOTP client
- * 67 : UDP BOOTP server
- */
- RT_TRACE(rtlpriv, (COMP_SEND | COMP_RECV),
- DBG_DMESG, "dhcp %s !!\n",
- is_tx ? "Tx" : "Rx");
-
- if (is_tx) {
- schedule_work(&rtlpriv->
- works.lps_leave_work);
- ppsc->last_delaylps_stamp_jiffies =
- jiffies;
- }
+ switch (ether_type) {
+ case ETH_P_IP: {
+ struct udphdr *udp;
+ u16 src;
+ u16 dst;
- return true;
- }
- }
- } else if (ETH_P_ARP == ether_type) {
- if (is_tx) {
- schedule_work(&rtlpriv->works.lps_leave_work);
- ppsc->last_delaylps_stamp_jiffies = jiffies;
- }
+ if (ip->protocol != IPPROTO_UDP)
+ return false;
+ udp = (struct udphdr *)((u8 *)ip + (ip->ihl << 2));
+ src = be16_to_cpu(udp->source);
+ dst = be16_to_cpu(udp->dest);
- return true;
- } else if (ETH_P_PAE == ether_type) {
+ /* If this case involves port 68 (UDP BOOTP client) connecting
+ * with port 67 (UDP BOOTP server), then return true so that
+ * the lowest speed is used.
+ */
+ if (!((src == 68 && dst == 67) || (src == 67 && dst == 68)))
+ return false;
+
+ RT_TRACE(rtlpriv, (COMP_SEND | COMP_RECV), DBG_DMESG,
+ "dhcp %s !!\n", is_tx ? "Tx" : "Rx");
+ break;
+ }
+ case ETH_P_ARP:
+ break;
+ case ETH_P_PAE:
RT_TRACE(rtlpriv, (COMP_SEND | COMP_RECV), DBG_DMESG,
"802.1X %s EAPOL pkt!!\n", is_tx ? "Tx" : "Rx");
-
- if (is_tx) {
- schedule_work(&rtlpriv->works.lps_leave_work);
- ppsc->last_delaylps_stamp_jiffies = jiffies;
- }
-
- return true;
- } else if (ETH_P_IPV6 == ether_type) {
- /* IPv6 */
- return true;
+ break;
+ case ETH_P_IPV6:
+ /* TODO: Is this right? */
+ return false;
+ default:
+ return false;
}
-
- return false;
+ if (is_tx) {
+ schedule_work(&rtlpriv->works.lps_leave_work);
+ ppsc->last_delaylps_stamp_jiffies = jiffies;
+ }
+ return true;
}
/*********************************************************
diff --git a/drivers/net/wireless/rtlwifi/wifi.h b/drivers/net/wireless/rtlwifi/wifi.h
index a382f95..88732e7 100644
--- a/drivers/net/wireless/rtlwifi/wifi.h
+++ b/drivers/net/wireless/rtlwifi/wifi.h
@@ -77,11 +77,7 @@
#define RTL_SLOT_TIME_9 9
#define RTL_SLOT_TIME_20 20
-/*related with tcp/ip. */
-/*if_ehther.h*/
-#define ETH_P_PAE 0x888E /*Port Access Entity (IEEE 802.1X) */
-#define ETH_P_IP 0x0800 /*Internet Protocol packet */
-#define ETH_P_ARP 0x0806 /*Address Resolution packet */
+/*related to tcp/ip. */
#define SNAP_SIZE 6
#define PROTOC_TYPE_SIZE 2
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 091/152] rtlwifi: rtl8192cu: Fix incorrect signal strength for unassociated AP
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (89 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 090/152] rtlwifi: Fix endian error in extracting packet type Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 092/152] rtlwifi: rtl8192de: " Kamal Mostafa
` (60 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Larry Finger, John W. Linville, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Larry Finger <Larry.Finger@lwfinger.net>
commit 78dbfecb95be4635b995af3bd29fa10013409fcd upstream.
The routine that processes received frames was returning the RSSI value for the
signal strength; however, that value is available only for associated APs. As
a result, the strength was the absurd value of 10 dBm. As a result, scans
return incorrect values for the strength, which causes unwanted attempts to roam.
Signed-off-by: Larry Finger <Larry.Finger@lwfinger.net>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/rtlwifi/rtl8192cu/trx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/rtlwifi/rtl8192cu/trx.c b/drivers/net/wireless/rtlwifi/rtl8192cu/trx.c
index 03b6d81..6075b34 100644
--- a/drivers/net/wireless/rtlwifi/rtl8192cu/trx.c
+++ b/drivers/net/wireless/rtlwifi/rtl8192cu/trx.c
@@ -349,7 +349,7 @@ bool rtl92cu_rx_query_desc(struct ieee80211_hw *hw,
p_drvinfo);
}
/*rx_status->qual = stats->signal; */
- rx_status->signal = stats->rssi + 10;
+ rx_status->signal = stats->recvsignalpower + 10;
/*rx_status->noise = -stats->noise; */
return true;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 092/152] rtlwifi: rtl8192de: Fix incorrect signal strength for unassociated AP
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (90 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 091/152] rtlwifi: rtl8192cu: Fix incorrect signal strength for unassociated AP Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 093/152] mwifiex: correct packet length for packets from SDIO interface Kamal Mostafa
` (59 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Larry Finger, John W. Linville, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Larry Finger <Larry.Finger@lwfinger.net>
commit 3545f3d5f4af715c914394123ce7725a9cf0a1c4 upstream.
The routine that processes received frames was returning the RSSI value for the
signal strength; however, that value is available only for associated APs. As
a result, the strength was the absurd value of 10 dBm. As a result, scans
return incorrect values for the strength, which causes unwanted attempts to roam.
Signed-off-by: Larry Finger <Larry.Finger@lwfinger.net>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/rtlwifi/rtl8192de/trx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/rtlwifi/rtl8192de/trx.c b/drivers/net/wireless/rtlwifi/rtl8192de/trx.c
index a0fbf28..4494a44 100644
--- a/drivers/net/wireless/rtlwifi/rtl8192de/trx.c
+++ b/drivers/net/wireless/rtlwifi/rtl8192de/trx.c
@@ -525,7 +525,7 @@ bool rtl92de_rx_query_desc(struct ieee80211_hw *hw, struct rtl_stats *stats,
p_drvinfo);
}
/*rx_status->qual = stats->signal; */
- rx_status->signal = stats->rssi + 10;
+ rx_status->signal = stats->recvsignalpower + 10;
/*rx_status->noise = -stats->noise; */
return true;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 093/152] mwifiex: correct packet length for packets from SDIO interface
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (91 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 092/152] rtlwifi: rtl8192de: " Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 094/152] mwifiex: fix wrong eth_hdr usage for bridged packets in AP mode Kamal Mostafa
` (58 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Avinash Patil, Bing Zhao, John W. Linville, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Avinash Patil <patila@marvell.com>
commit d03b4aa77e1187b77dfe37d14a923547f00baa66 upstream.
While receiving a packet on SDIO interface, we allocate skb with
size multiple of SDIO block size. We need to resize this skb
after RX using packet length from RX header.
Signed-off-by: Avinash Patil <patila@marvell.com>
Signed-off-by: Bing Zhao <bzhao@marvell.com>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/mwifiex/sdio.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/mwifiex/sdio.c b/drivers/net/wireless/mwifiex/sdio.c
index 86c025d..2df55d8 100644
--- a/drivers/net/wireless/mwifiex/sdio.c
+++ b/drivers/net/wireless/mwifiex/sdio.c
@@ -944,7 +944,10 @@ static int mwifiex_decode_rx_packet(struct mwifiex_adapter *adapter,
struct sk_buff *skb, u32 upld_typ)
{
u8 *cmd_buf;
+ __le16 *curr_ptr = (__le16 *)skb->data;
+ u16 pkt_len = le16_to_cpu(*curr_ptr);
+ skb_trim(skb, pkt_len);
skb_pull(skb, INTF_HEADER_LEN);
switch (upld_typ) {
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 094/152] mwifiex: fix wrong eth_hdr usage for bridged packets in AP mode
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (92 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 093/152] mwifiex: correct packet length for packets from SDIO interface Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 095/152] prism54: set netdev type to "wlan" Kamal Mostafa
` (57 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Ujjal Roy, Amitkumar Karwar, Bing Zhao, John W. Linville, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ujjal Roy <royujjal@gmail.com>
commit 8d93f1f309d38b65fce0b9f0de91ba6c96990c07 upstream.
The eth_hdr is never defined in this driver but it gets compiled
without any warning/error because kernel has defined eth_hdr.
Fix it by defining our own p_ethhdr and use it instead of eth_hdr.
Signed-off-by: Ujjal Roy <royujjal@gmail.com>
Signed-off-by: Amitkumar Karwar <akarwar@marvell.com>
Signed-off-by: Bing Zhao <bzhao@marvell.com>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/mwifiex/uap_txrx.c | 29 ++++++++++++++++++++++++++---
1 file changed, 26 insertions(+), 3 deletions(-)
diff --git a/drivers/net/wireless/mwifiex/uap_txrx.c b/drivers/net/wireless/mwifiex/uap_txrx.c
index a018e42..48e6724 100644
--- a/drivers/net/wireless/mwifiex/uap_txrx.c
+++ b/drivers/net/wireless/mwifiex/uap_txrx.c
@@ -34,6 +34,7 @@ static void mwifiex_uap_queue_bridged_pkt(struct mwifiex_private *priv,
struct mwifiex_txinfo *tx_info;
int hdr_chop;
struct timeval tv;
+ struct ethhdr *p_ethhdr;
u8 rfc1042_eth_hdr[ETH_ALEN] = { 0xaa, 0xaa, 0x03, 0x00, 0x00, 0x00 };
uap_rx_pd = (struct uap_rxpd *)(skb->data);
@@ -48,14 +49,36 @@ static void mwifiex_uap_queue_bridged_pkt(struct mwifiex_private *priv,
}
if (!memcmp(&rx_pkt_hdr->rfc1042_hdr,
- rfc1042_eth_hdr, sizeof(rfc1042_eth_hdr)))
+ rfc1042_eth_hdr, sizeof(rfc1042_eth_hdr))) {
+ /* Replace the 803 header and rfc1042 header (llc/snap) with
+ * an Ethernet II header, keep the src/dst and snap_type
+ * (ethertype).
+ *
+ * The firmware only passes up SNAP frames converting all RX
+ * data from 802.11 to 802.2/LLC/SNAP frames.
+ *
+ * To create the Ethernet II, just move the src, dst address
+ * right before the snap_type.
+ */
+ p_ethhdr = (struct ethhdr *)
+ ((u8 *)(&rx_pkt_hdr->eth803_hdr)
+ + sizeof(rx_pkt_hdr->eth803_hdr)
+ + sizeof(rx_pkt_hdr->rfc1042_hdr)
+ - sizeof(rx_pkt_hdr->eth803_hdr.h_dest)
+ - sizeof(rx_pkt_hdr->eth803_hdr.h_source)
+ - sizeof(rx_pkt_hdr->rfc1042_hdr.snap_type));
+ memcpy(p_ethhdr->h_source, rx_pkt_hdr->eth803_hdr.h_source,
+ sizeof(p_ethhdr->h_source));
+ memcpy(p_ethhdr->h_dest, rx_pkt_hdr->eth803_hdr.h_dest,
+ sizeof(p_ethhdr->h_dest));
/* Chop off the rxpd + the excess memory from
* 802.2/llc/snap header that was removed.
*/
- hdr_chop = (u8 *)eth_hdr - (u8 *)uap_rx_pd;
- else
+ hdr_chop = (u8 *)p_ethhdr - (u8 *)uap_rx_pd;
+ } else {
/* Chop off the rxpd */
hdr_chop = (u8 *)&rx_pkt_hdr->eth803_hdr - (u8 *)uap_rx_pd;
+ }
/* Chop off the leading header bytes so the it points
* to the start of either the reconstructed EthII frame
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 095/152] prism54: set netdev type to "wlan"
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (93 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 094/152] mwifiex: fix wrong eth_hdr usage for bridged packets in AP mode Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 096/152] ALSA: msnd: Avoid duplicated driver name Kamal Mostafa
` (56 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dan Williams, John W. Linville, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dan Williams <dcbw@redhat.com>
commit 8e3ffa471091c560deb6738ed9ab7445b7a5fd04 upstream.
Userspace uses the netdev devtype for stuff like device naming and type
detection. Be nice and set it. Remove the pointless #if/#endif around
SET_NETDEV_DEV too.
Signed-off-by: Dan Williams <dcbw@redhat.com>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/prism54/islpci_dev.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/prism54/islpci_dev.c b/drivers/net/wireless/prism54/islpci_dev.c
index 5970ff6..d498b02 100644
--- a/drivers/net/wireless/prism54/islpci_dev.c
+++ b/drivers/net/wireless/prism54/islpci_dev.c
@@ -811,6 +811,10 @@ static const struct net_device_ops islpci_netdev_ops = {
.ndo_validate_addr = eth_validate_addr,
};
+static struct device_type wlan_type = {
+ .name = "wlan",
+};
+
struct net_device *
islpci_setup(struct pci_dev *pdev)
{
@@ -821,9 +825,8 @@ islpci_setup(struct pci_dev *pdev)
return ndev;
pci_set_drvdata(pdev, ndev);
-#if defined(SET_NETDEV_DEV)
SET_NETDEV_DEV(ndev, &pdev->dev);
-#endif
+ SET_NETDEV_DEVTYPE(ndev, &wlan_type);
/* setup the structure members */
ndev->base_addr = pci_resource_start(pdev, 0);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 096/152] ALSA: msnd: Avoid duplicated driver name
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (94 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 095/152] prism54: set netdev type to "wlan" Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 097/152] x86/microcode/amd: Tone down printk(), don't treat a missing firmware file as an error Kamal Mostafa
` (55 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Takashi Iwai, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit 092f9cd16aac7d054af1755c945f37c1b33399e6 upstream.
msnd_pinnacle.c is used for both snd-msnd-pinnacle and
snd-msnd-classic drivers, and both should have different driver
names. Using the same driver name results in the sysfs warning for
duplicated entries like
kobject: 'msnd-pinnacle.7' (cec33408): kobject_release, parent (null) (delayed)
kobject: 'msnd-pinnacle' (cecd4980): kobject_release, parent cf3ad9b0 (delayed)
------------[ cut here ]------------
WARNING: CPU: 0 PID: 1 at fs/sysfs/dir.c:486 sysfs_warn_dup+0x7d/0xa0()
sysfs: cannot create duplicate filename '/bus/isa/drivers/msnd-pinnacle'
......
Reported-by: Fengguang Wu <fengguang.wu@intel.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/isa/msnd/msnd_pinnacle.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/sound/isa/msnd/msnd_pinnacle.c b/sound/isa/msnd/msnd_pinnacle.c
index ddabb40..3a7946e 100644
--- a/sound/isa/msnd/msnd_pinnacle.c
+++ b/sound/isa/msnd/msnd_pinnacle.c
@@ -73,9 +73,11 @@
#ifdef MSND_CLASSIC
# include "msnd_classic.h"
# define LOGNAME "msnd_classic"
+# define DEV_NAME "msnd-classic"
#else
# include "msnd_pinnacle.h"
# define LOGNAME "snd_msnd_pinnacle"
+# define DEV_NAME "msnd-pinnacle"
#endif
static void set_default_audio_parameters(struct snd_msnd *chip)
@@ -1068,8 +1070,6 @@ static int snd_msnd_isa_remove(struct device *pdev, unsigned int dev)
return 0;
}
-#define DEV_NAME "msnd-pinnacle"
-
static struct isa_driver snd_msnd_driver = {
.match = snd_msnd_isa_match,
.probe = snd_msnd_isa_probe,
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 097/152] x86/microcode/amd: Tone down printk(), don't treat a missing firmware file as an error
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (95 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 096/152] ALSA: msnd: Avoid duplicated driver name Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 098/152] SUNRPC: fix races on PipeFS UMOUNT notifications Kamal Mostafa
` (54 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Thomas Renninger, Ingo Molnar, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Renninger <trenn@suse.de>
commit 11f918d3e2d3861b6931e97b3aa778e4984935aa upstream.
Do it the same way as done in microcode_intel.c: use pr_debug()
for missing firmware files.
There seem to be CPUs out there for which no microcode update
has been submitted to kernel-firmware repo yet resulting in
scary sounding error messages in dmesg:
microcode: failed to load file amd-ucode/microcode_amd_fam16h.bin
Signed-off-by: Thomas Renninger <trenn@suse.de>
Acked-by: Borislav Petkov <bp@suse.de>
Link: http://lkml.kernel.org/r/1384274383-43510-1-git-send-email-trenn@suse.de
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/x86/kernel/microcode_amd.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/x86/kernel/microcode_amd.c b/arch/x86/kernel/microcode_amd.c
index efdec7c..b516dfb 100644
--- a/arch/x86/kernel/microcode_amd.c
+++ b/arch/x86/kernel/microcode_amd.c
@@ -430,7 +430,7 @@ static enum ucode_state request_microcode_amd(int cpu, struct device *device,
snprintf(fw_name, sizeof(fw_name), "amd-ucode/microcode_amd_fam%.2xh.bin", c->x86);
if (request_firmware(&fw, (const char *)fw_name, device)) {
- pr_err("failed to load file %s\n", fw_name);
+ pr_debug("failed to load file %s\n", fw_name);
goto out;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 098/152] SUNRPC: fix races on PipeFS UMOUNT notifications
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (96 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 097/152] x86/microcode/amd: Tone down printk(), don't treat a missing firmware file as an error Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 099/152] SUNRPC: Avoid deep recursion in rpc_release_client Kamal Mostafa
` (53 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Stanislav Kinsbursky, Trond Myklebust, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislav Kinsbursky <skinsbursky@parallels.com>
commit adb6fa7ffe9031857ec14b8aab75c9ab65556cbc upstream.
CPU#0 CPU#1
----------------------------- -----------------------------
rpc_kill_sb
sn->pipefs_sb = NULL rpc_release_client
(UMOUNT_EVENT) rpc_free_auth
rpc_pipefs_event
rpc_get_client_for_event
!atomic_inc_not_zero(cl_count)
<skip the client>
atomic_inc(cl_count)
rpc_free_client
rpc_clnt_remove_pipedir
<skip client dir removing>
To fix this, this patch does the following:
1) Calls RPC_PIPEFS_UMOUNT notification with sn->pipefs_sb_lock being held.
2) Removes SUNRPC client from the list AFTER pipes destroying.
3) Doesn't hold RPC client on notification: if client in the list, then it
can't be destroyed while sn->pipefs_sb_lock in hold by notification caller.
Signed-off-by: Stanislav Kinsbursky <skinsbursky@parallels.com>
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
net/sunrpc/clnt.c | 5 +----
net/sunrpc/rpc_pipe.c | 2 +-
2 files changed, 2 insertions(+), 5 deletions(-)
diff --git a/net/sunrpc/clnt.c b/net/sunrpc/clnt.c
index 716aa41..1a3bd4d 100644
--- a/net/sunrpc/clnt.c
+++ b/net/sunrpc/clnt.c
@@ -240,8 +240,6 @@ static struct rpc_clnt *rpc_get_client_for_event(struct net *net, int event)
continue;
if (rpc_clnt_skip_event(clnt, event))
continue;
- if (atomic_inc_not_zero(&clnt->cl_count) == 0)
- continue;
spin_unlock(&sn->rpc_client_lock);
return clnt;
}
@@ -258,7 +256,6 @@ static int rpc_pipefs_event(struct notifier_block *nb, unsigned long event,
while ((clnt = rpc_get_client_for_event(sb->s_fs_info, event))) {
error = __rpc_pipefs_event(clnt, event, sb);
- rpc_release_client(clnt);
if (error)
break;
}
@@ -635,8 +632,8 @@ rpc_free_client(struct rpc_clnt *clnt)
rcu_dereference(clnt->cl_xprt)->servername);
if (clnt->cl_parent != clnt)
rpc_release_client(clnt->cl_parent);
- rpc_unregister_client(clnt);
rpc_clnt_remove_pipedir(clnt);
+ rpc_unregister_client(clnt);
rpc_free_iostats(clnt->cl_metrics);
kfree(clnt->cl_principal);
clnt->cl_metrics = NULL;
diff --git a/net/sunrpc/rpc_pipe.c b/net/sunrpc/rpc_pipe.c
index fd10981..05bd864 100644
--- a/net/sunrpc/rpc_pipe.c
+++ b/net/sunrpc/rpc_pipe.c
@@ -1157,12 +1157,12 @@ static void rpc_kill_sb(struct super_block *sb)
goto out;
}
sn->pipefs_sb = NULL;
- mutex_unlock(&sn->pipefs_sb_lock);
dprintk("RPC: sending pipefs UMOUNT notification for net %p%s\n",
net, NET_NAME(net));
blocking_notifier_call_chain(&rpc_pipefs_notifier_list,
RPC_PIPEFS_UMOUNT,
sb);
+ mutex_unlock(&sn->pipefs_sb_lock);
put_net(net);
out:
kill_litter_super(sb);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 099/152] SUNRPC: Avoid deep recursion in rpc_release_client
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (97 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 098/152] SUNRPC: fix races on PipeFS UMOUNT notifications Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 100/152] cris: media platform drivers: fix build Kamal Mostafa
` (52 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Trond Myklebust, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Trond Myklebust <Trond.Myklebust@netapp.com>
commit d07ba8422f1e58be94cc98a1f475946dc1b89f1b upstream.
In cases where an rpc client has a parent hierarchy, then
rpc_free_client may end up calling rpc_release_client() on the
parent, thus recursing back into rpc_free_client. If the hierarchy
is deep enough, then we can get into situations where the stack
simply overflows.
The fix is to have rpc_release_client() loop so that it can take
care of the parent rpc client hierarchy without needing to
recurse.
Reported-by: Jeff Layton <jlayton@redhat.com>
Reported-by: Weston Andros Adamson <dros@netapp.com>
Reported-by: Bruce Fields <bfields@fieldses.org>
Link: http://lkml.kernel.org/r/2C73011F-0939-434C-9E4D-13A1EB1403D7@netapp.com
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
net/sunrpc/clnt.c | 29 +++++++++++++++++------------
1 file changed, 17 insertions(+), 12 deletions(-)
diff --git a/net/sunrpc/clnt.c b/net/sunrpc/clnt.c
index 1a3bd4d..d8b6ad9 100644
--- a/net/sunrpc/clnt.c
+++ b/net/sunrpc/clnt.c
@@ -624,14 +624,16 @@ EXPORT_SYMBOL_GPL(rpc_shutdown_client);
/*
* Free an RPC client
*/
-static void
+static struct rpc_clnt *
rpc_free_client(struct rpc_clnt *clnt)
{
+ struct rpc_clnt *parent = NULL;
+
dprintk_rcu("RPC: destroying %s client for %s\n",
clnt->cl_protname,
rcu_dereference(clnt->cl_xprt)->servername);
if (clnt->cl_parent != clnt)
- rpc_release_client(clnt->cl_parent);
+ parent = clnt->cl_parent;
rpc_clnt_remove_pipedir(clnt);
rpc_unregister_client(clnt);
rpc_free_iostats(clnt->cl_metrics);
@@ -640,18 +642,17 @@ rpc_free_client(struct rpc_clnt *clnt)
xprt_put(rcu_dereference_raw(clnt->cl_xprt));
rpciod_down();
kfree(clnt);
+ return parent;
}
/*
* Free an RPC client
*/
-static void
+static struct rpc_clnt *
rpc_free_auth(struct rpc_clnt *clnt)
{
- if (clnt->cl_auth == NULL) {
- rpc_free_client(clnt);
- return;
- }
+ if (clnt->cl_auth == NULL)
+ return rpc_free_client(clnt);
/*
* Note: RPCSEC_GSS may need to send NULL RPC calls in order to
@@ -662,7 +663,8 @@ rpc_free_auth(struct rpc_clnt *clnt)
rpcauth_release(clnt->cl_auth);
clnt->cl_auth = NULL;
if (atomic_dec_and_test(&clnt->cl_count))
- rpc_free_client(clnt);
+ return rpc_free_client(clnt);
+ return NULL;
}
/*
@@ -673,10 +675,13 @@ rpc_release_client(struct rpc_clnt *clnt)
{
dprintk("RPC: rpc_release_client(%p)\n", clnt);
- if (list_empty(&clnt->cl_tasks))
- wake_up(&destroy_wait);
- if (atomic_dec_and_test(&clnt->cl_count))
- rpc_free_auth(clnt);
+ do {
+ if (list_empty(&clnt->cl_tasks))
+ wake_up(&destroy_wait);
+ if (!atomic_dec_and_test(&clnt->cl_count))
+ break;
+ clnt = rpc_free_auth(clnt);
+ } while (clnt != NULL);
}
/**
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 100/152] cris: media platform drivers: fix build
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (98 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 099/152] SUNRPC: Avoid deep recursion in rpc_release_client Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 101/152] mm: ensure get_unmapped_area() returns higher address than mmap_min_addr Kamal Mostafa
` (51 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Mauro Carvalho Chehab, Mikael Starvik, Jesper Nilsson,
Andrew Morton, Linus Torvalds, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mauro Carvalho Chehab <m.chehab@samsung.com>
commit 72a0c5571351f5184195754d23db3e14495b2080 upstream.
On cris arch, the functions below aren't defined:
drivers/media/platform/sh_veu.c: In function 'sh_veu_reg_read':
drivers/media/platform/sh_veu.c:228:2: error: implicit declaration of function 'ioread32' [-Werror=implicit-function-declaration]
drivers/media/platform/sh_veu.c: In function 'sh_veu_reg_write':
drivers/media/platform/sh_veu.c:234:2: error: implicit declaration of function 'iowrite32' [-Werror=implicit-function-declaration]
drivers/media/platform/vsp1/vsp1.h: In function 'vsp1_read':
drivers/media/platform/vsp1/vsp1.h:66:2: error: implicit declaration of function 'ioread32' [-Werror=implicit-function-declaration]
drivers/media/platform/vsp1/vsp1.h: In function 'vsp1_write':
drivers/media/platform/vsp1/vsp1.h:71:2: error: implicit declaration of function 'iowrite32' [-Werror=implicit-function-declaration]
drivers/media/platform/vsp1/vsp1.h: In function 'vsp1_read':
drivers/media/platform/vsp1/vsp1.h:66:2: error: implicit declaration of function 'ioread32' [-Werror=implicit-function-declaration]
drivers/media/platform/vsp1/vsp1.h: In function 'vsp1_write':
drivers/media/platform/vsp1/vsp1.h:71:2: error: implicit declaration of function 'iowrite32' [-Werror=implicit-function-declaration]
drivers/media/platform/soc_camera/rcar_vin.c: In function 'rcar_vin_setup':
drivers/media/platform/soc_camera/rcar_vin.c:284:3: error: implicit declaration of function 'iowrite32' [-Werror=implicit-function-declaration]
drivers/media/platform/soc_camera/rcar_vin.c: In function 'rcar_vin_request_capture_stop':
drivers/media/platform/soc_camera/rcar_vin.c:353:2: error: implicit declaration of function 'ioread32' [-Werror=implicit-function-declaration]
Yet, they're available, as CONFIG_GENERIC_IOMAP is defined. What happens
is that asm/io.h was not including asm-generic/iomap.h.
Suggested-by: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: Mauro Carvalho Chehab <m.chehab@samsung.com>
Cc: Mikael Starvik <starvik@axis.com>
Cc: Jesper Nilsson <jesper.nilsson@axis.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/cris/include/asm/io.h | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/cris/include/asm/io.h b/arch/cris/include/asm/io.h
index ac12ae2..db9a16c 100644
--- a/arch/cris/include/asm/io.h
+++ b/arch/cris/include/asm/io.h
@@ -3,6 +3,7 @@
#include <asm/page.h> /* for __va, __pa */
#include <arch/io.h>
+#include <asm-generic/iomap.h>
#include <linux/kernel.h>
struct cris_io_operations
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 101/152] mm: ensure get_unmapped_area() returns higher address than mmap_min_addr
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (99 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 100/152] cris: media platform drivers: fix build Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 102/152] mm: Only flush TLBs if a transhuge PMD is modified for NUMA pte scanning Kamal Mostafa
` (50 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Akira Takeuchi, Kiyoshi Owada, Andrew Morton, Linus Torvalds,
Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Akira Takeuchi <takeuchi.akr@jp.panasonic.com>
commit 2afc745f3e3079ab16c826be4860da2529054dd2 upstream.
This patch fixes the problem that get_unmapped_area() can return illegal
address and result in failing mmap(2) etc.
In case that the address higher than PAGE_SIZE is set to
/proc/sys/vm/mmap_min_addr, the address lower than mmap_min_addr can be
returned by get_unmapped_area(), even if you do not pass any virtual
address hint (i.e. the second argument).
This is because the current get_unmapped_area() code does not take into
account mmap_min_addr.
This leads to two actual problems as follows:
1. mmap(2) can fail with EPERM on the process without CAP_SYS_RAWIO,
although any illegal parameter is not passed.
2. The bottom-up search path after the top-down search might not work in
arch_get_unmapped_area_topdown().
Note: The first and third chunk of my patch, which changes "len" check,
are for more precise check using mmap_min_addr, and not for solving the
above problem.
[How to reproduce]
--- test.c -------------------------------------------------
#include <stdio.h>
#include <unistd.h>
#include <sys/mman.h>
#include <sys/errno.h>
int main(int argc, char *argv[])
{
void *ret = NULL, *last_map;
size_t pagesize = sysconf(_SC_PAGESIZE);
do {
last_map = ret;
ret = mmap(0, pagesize, PROT_NONE,
MAP_PRIVATE|MAP_ANONYMOUS, -1, 0);
// printf("ret=%p\n", ret);
} while (ret != MAP_FAILED);
if (errno != ENOMEM) {
printf("ERR: unexpected errno: %d (last map=%p)\n",
errno, last_map);
}
return 0;
}
---------------------------------------------------------------
$ gcc -m32 -o test test.c
$ sudo sysctl -w vm.mmap_min_addr=65536
vm.mmap_min_addr = 65536
$ ./test (run as non-priviledge user)
ERR: unexpected errno: 1 (last map=0x10000)
Signed-off-by: Akira Takeuchi <takeuchi.akr@jp.panasonic.com>
Signed-off-by: Kiyoshi Owada <owada.kiyoshi@jp.panasonic.com>
Reviewed-by: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
mm/mmap.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/mm/mmap.c b/mm/mmap.c
index 82fbbab..44ec3e6 100644
--- a/mm/mmap.c
+++ b/mm/mmap.c
@@ -1786,7 +1786,7 @@ arch_get_unmapped_area(struct file *filp, unsigned long addr,
struct vm_area_struct *vma;
struct vm_unmapped_area_info info;
- if (len > TASK_SIZE)
+ if (len > TASK_SIZE - mmap_min_addr)
return -ENOMEM;
if (flags & MAP_FIXED)
@@ -1795,7 +1795,7 @@ arch_get_unmapped_area(struct file *filp, unsigned long addr,
if (addr) {
addr = PAGE_ALIGN(addr);
vma = find_vma(mm, addr);
- if (TASK_SIZE - len >= addr &&
+ if (TASK_SIZE - len >= addr && addr >= mmap_min_addr &&
(!vma || addr + len <= vma->vm_start))
return addr;
}
@@ -1834,7 +1834,7 @@ arch_get_unmapped_area_topdown(struct file *filp, const unsigned long addr0,
struct vm_unmapped_area_info info;
/* requested length too big for entire address space */
- if (len > TASK_SIZE)
+ if (len > TASK_SIZE - mmap_min_addr)
return -ENOMEM;
if (flags & MAP_FIXED)
@@ -1844,14 +1844,14 @@ arch_get_unmapped_area_topdown(struct file *filp, const unsigned long addr0,
if (addr) {
addr = PAGE_ALIGN(addr);
vma = find_vma(mm, addr);
- if (TASK_SIZE - len >= addr &&
+ if (TASK_SIZE - len >= addr && addr >= mmap_min_addr &&
(!vma || addr + len <= vma->vm_start))
return addr;
}
info.flags = VM_UNMAPPED_AREA_TOPDOWN;
info.length = len;
- info.low_limit = PAGE_SIZE;
+ info.low_limit = max(PAGE_SIZE, mmap_min_addr);
info.high_limit = mm->mmap_base;
info.align_mask = 0;
addr = vm_unmapped_area(&info);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 102/152] mm: Only flush TLBs if a transhuge PMD is modified for NUMA pte scanning
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (100 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 101/152] mm: ensure get_unmapped_area() returns higher address than mmap_min_addr Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 103/152] mm: numa: return the number of base pages altered by protection changes Kamal Mostafa
` (49 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Andrea Arcangeli, Johannes Weiner, Srikar Dronamraju, Mel Gorman,
Peter Zijlstra, Ingo Molnar, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mel Gorman <mgorman@suse.de>
commit f123d74abf91574837d14e5ea58f6a779a387bf5 upstream.
NUMA PTE scanning is expensive both in terms of the scanning itself and
the TLB flush if there are any updates. The TLB flush is avoided if no
PTEs are updated but there is a bug where transhuge PMDs are considered
to be updated even if they were already pmd_numa. This patch addresses
the problem and TLB flushes should be reduced.
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Srikar Dronamraju <srikar@linux.vnet.ibm.com>
Reviewed-by: Rik van Riel <riel@redhat.com>
Signed-off-by: Mel Gorman <mgorman@suse.de>
Signed-off-by: Peter Zijlstra <peterz@infradead.org>
Link: http://lkml.kernel.org/r/1381141781-10992-12-git-send-email-mgorman@suse.de
Signed-off-by: Ingo Molnar <mingo@kernel.org>
[ kamal: 3.8 stable prereq for
72403b4 mm: numa: return the number of base pages altered by protection changes ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
mm/huge_memory.c | 19 ++++++++++++++++---
mm/mprotect.c | 14 ++++++++++----
2 files changed, 26 insertions(+), 7 deletions(-)
diff --git a/mm/huge_memory.c b/mm/huge_memory.c
index 9c37776..9d0b5f5 100644
--- a/mm/huge_memory.c
+++ b/mm/huge_memory.c
@@ -1472,6 +1472,12 @@ out:
return ret;
}
+/*
+ * Returns
+ * - 0 if PMD could not be locked
+ * - 1 if PMD was locked but protections unchange and TLB flush unnecessary
+ * - HPAGE_PMD_NR is protections changed and TLB flush necessary
+ */
int change_huge_pmd(struct vm_area_struct *vma, pmd_t *pmd,
unsigned long addr, pgprot_t newprot, int prot_numa)
{
@@ -1480,9 +1486,11 @@ int change_huge_pmd(struct vm_area_struct *vma, pmd_t *pmd,
if (__pmd_trans_huge_lock(pmd, vma) == 1) {
pmd_t entry;
- entry = pmdp_get_and_clear(mm, addr, pmd);
+ ret = 1;
if (!prot_numa) {
+ entry = pmdp_get_and_clear(mm, addr, pmd);
entry = pmd_modify(entry, newprot);
+ ret = HPAGE_PMD_NR;
BUG_ON(pmd_write(entry));
} else {
struct page *page = pmd_page(*pmd);
@@ -1490,12 +1498,17 @@ int change_huge_pmd(struct vm_area_struct *vma, pmd_t *pmd,
/* only check non-shared pages */
if (page_mapcount(page) == 1 &&
!pmd_numa(*pmd)) {
+ entry = pmdp_get_and_clear(mm, addr, pmd);
entry = pmd_mknuma(entry);
+ ret = HPAGE_PMD_NR;
}
}
- set_pmd_at(mm, addr, pmd, entry);
+
+ /* Set PMD if cleared earlier */
+ if (ret == HPAGE_PMD_NR)
+ set_pmd_at(mm, addr, pmd, entry);
+
spin_unlock(&vma->vm_mm->page_table_lock);
- ret = 1;
}
return ret;
diff --git a/mm/mprotect.c b/mm/mprotect.c
index 2bbb648..16a42b2 100644
--- a/mm/mprotect.c
+++ b/mm/mprotect.c
@@ -143,10 +143,16 @@ static inline unsigned long change_pmd_range(struct vm_area_struct *vma,
if (pmd_trans_huge(*pmd)) {
if (next - addr != HPAGE_PMD_SIZE)
split_huge_page_pmd(vma, addr, pmd);
- else if (change_huge_pmd(vma, pmd, addr, newprot,
- prot_numa)) {
- pages++;
- continue;
+ else {
+ int nr_ptes = change_huge_pmd(vma, pmd, addr,
+ newprot, prot_numa);
+
+ if (nr_ptes) {
+ if (nr_ptes == HPAGE_PMD_NR)
+ pages++;
+
+ continue;
+ }
}
/* fall through */
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 103/152] mm: numa: return the number of base pages altered by protection changes
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (101 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 102/152] mm: Only flush TLBs if a transhuge PMD is modified for NUMA pte scanning Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 104/152] vsprintf: check real user/group id for %pK Kamal Mostafa
` (48 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Mel Gorman, Andrew Morton, Linus Torvalds, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mel Gorman <mgorman@suse.de>
commit 72403b4a0fbdf433c1fe0127e49864658f6f6468 upstream.
Commit 0255d4918480 ("mm: Account for a THP NUMA hinting update as one
PTE update") was added to account for the number of PTE updates when
marking pages prot_numa. task_numa_work was using the old return value
to track how much address space had been updated. Altering the return
value causes the scanner to do more work than it is configured or
documented to in a single unit of work.
This patch reverts that commit and accounts for the number of THP
updates separately in vmstat. It is up to the administrator to
interpret the pair of values correctly. This is a straight-forward
operation and likely to only be of interest when actively debugging NUMA
balancing problems.
The impact of this patch is that the NUMA PTE scanner will scan slower
when THP is enabled and workloads may converge slower as a result. On
the flip size system CPU usage should be lower than recent tests
reported. This is an illustrative example of a short single JVM specjbb
test
specjbb
3.12.0 3.12.0
vanilla acctupdates
TPut 1 26143.00 ( 0.00%) 25747.00 ( -1.51%)
TPut 7 185257.00 ( 0.00%) 183202.00 ( -1.11%)
TPut 13 329760.00 ( 0.00%) 346577.00 ( 5.10%)
TPut 19 442502.00 ( 0.00%) 460146.00 ( 3.99%)
TPut 25 540634.00 ( 0.00%) 549053.00 ( 1.56%)
TPut 31 512098.00 ( 0.00%) 519611.00 ( 1.47%)
TPut 37 461276.00 ( 0.00%) 474973.00 ( 2.97%)
TPut 43 403089.00 ( 0.00%) 414172.00 ( 2.75%)
3.12.0 3.12.0
vanillaacctupdates
User 5169.64 5184.14
System 100.45 80.02
Elapsed 252.75 251.85
Performance is similar but note the reduction in system CPU time. While
this showed a performance gain, it will not be universal but at least
it'll be behaving as documented. The vmstats are obviously different but
here is an obvious interpretation of them from mmtests.
3.12.0 3.12.0
vanillaacctupdates
NUMA page range updates 1408326 11043064
NUMA huge PMD updates 0 21040
NUMA PTE updates 1408326 291624
"NUMA page range updates" == nr_pte_updates and is the value returned to
the NUMA pte scanner. NUMA huge PMD updates were the number of THP
updates which in combination can be used to calculate how many ptes were
updated from userspace.
Signed-off-by: Mel Gorman <mgorman@suse.de>
Reported-by: Alex Thorlton <athorlton@sgi.com>
Reviewed-by: Rik van Riel <riel@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
include/linux/vm_event_item.h | 1 +
mm/mprotect.c | 10 +++++++---
mm/vmstat.c | 1 +
3 files changed, 9 insertions(+), 3 deletions(-)
diff --git a/include/linux/vm_event_item.h b/include/linux/vm_event_item.h
index fce0a27..84f4d96 100644
--- a/include/linux/vm_event_item.h
+++ b/include/linux/vm_event_item.h
@@ -40,6 +40,7 @@ enum vm_event_item { PGPGIN, PGPGOUT, PSWPIN, PSWPOUT,
PAGEOUTRUN, ALLOCSTALL, PGROTATED,
#ifdef CONFIG_NUMA_BALANCING
NUMA_PTE_UPDATES,
+ NUMA_HUGE_PTE_UPDATES,
NUMA_HINT_FAULTS,
NUMA_HINT_FAULTS_LOCAL,
NUMA_PAGE_MIGRATE,
diff --git a/mm/mprotect.c b/mm/mprotect.c
index 16a42b2..4c35eb8 100644
--- a/mm/mprotect.c
+++ b/mm/mprotect.c
@@ -136,6 +136,7 @@ static inline unsigned long change_pmd_range(struct vm_area_struct *vma,
unsigned long next;
unsigned long pages = 0;
bool all_same_node;
+ unsigned long nr_huge_updates = 0;
pmd = pmd_offset(pud, addr);
do {
@@ -148,9 +149,10 @@ static inline unsigned long change_pmd_range(struct vm_area_struct *vma,
newprot, prot_numa);
if (nr_ptes) {
- if (nr_ptes == HPAGE_PMD_NR)
- pages++;
-
+ if (nr_ptes == HPAGE_PMD_NR) {
+ pages += HPAGE_PMD_NR;
+ nr_huge_updates++;
+ }
continue;
}
}
@@ -171,6 +173,8 @@ static inline unsigned long change_pmd_range(struct vm_area_struct *vma,
change_pmd_protnuma(vma->vm_mm, addr, pmd);
} while (pmd++, addr = next, addr != end);
+ if (nr_huge_updates)
+ count_vm_numa_events(NUMA_HUGE_PTE_UPDATES, nr_huge_updates);
return pages;
}
diff --git a/mm/vmstat.c b/mm/vmstat.c
index 9800306..1071ca6 100644
--- a/mm/vmstat.c
+++ b/mm/vmstat.c
@@ -776,6 +776,7 @@ const char * const vmstat_text[] = {
#ifdef CONFIG_NUMA_BALANCING
"numa_pte_updates",
+ "numa_huge_pte_updates",
"numa_hint_faults",
"numa_hint_faults_local",
"numa_pages_migrated",
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 104/152] vsprintf: check real user/group id for %pK
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (102 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 103/152] mm: numa: return the number of base pages altered by protection changes Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 105/152] backlight: atmel-pwm-bl: fix reported brightness Kamal Mostafa
` (47 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Ryan Mallon, Kees Cook, Alexander Viro, Joe Perches,
Eric W. Biederman, Andrew Morton, Linus Torvalds, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ryan Mallon <rmallon@gmail.com>
commit 312b4e226951f707e120b95b118cbc14f3d162b2 upstream.
Some setuid binaries will allow reading of files which have read
permission by the real user id. This is problematic with files which
use %pK because the file access permission is checked at open() time,
but the kptr_restrict setting is checked at read() time. If a setuid
binary opens a %pK file as an unprivileged user, and then elevates
permissions before reading the file, then kernel pointer values may be
leaked.
This happens for example with the setuid pppd application on Ubuntu 12.04:
$ head -1 /proc/kallsyms
00000000 T startup_32
$ pppd file /proc/kallsyms
pppd: In file /proc/kallsyms: unrecognized option 'c1000000'
This will only leak the pointer value from the first line, but other
setuid binaries may leak more information.
Fix this by adding a check that in addition to the current process having
CAP_SYSLOG, that effective user and group ids are equal to the real ids.
If a setuid binary reads the contents of a file which uses %pK then the
pointer values will be printed as NULL if the real user is unprivileged.
Update the sysctl documentation to reflect the changes, and also correct
the documentation to state the kptr_restrict=0 is the default.
This is a only temporary solution to the issue. The correct solution is
to do the permission check at open() time on files, and to replace %pK
with a function which checks the open() time permission. %pK uses in
printk should be removed since no sane permission check can be done, and
instead protected by using dmesg_restrict.
Signed-off-by: Ryan Mallon <rmallon@gmail.com>
Cc: Kees Cook <keescook@chromium.org>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Joe Perches <joe@perches.com>
Cc: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
Documentation/sysctl/kernel.txt | 25 ++++++++++++++++++-------
lib/vsprintf.c | 33 ++++++++++++++++++++++++++++++---
2 files changed, 48 insertions(+), 10 deletions(-)
diff --git a/Documentation/sysctl/kernel.txt b/Documentation/sysctl/kernel.txt
index ccd4258..9b34b16 100644
--- a/Documentation/sysctl/kernel.txt
+++ b/Documentation/sysctl/kernel.txt
@@ -289,13 +289,24 @@ Default value is "/sbin/hotplug".
kptr_restrict:
This toggle indicates whether restrictions are placed on
-exposing kernel addresses via /proc and other interfaces. When
-kptr_restrict is set to (0), there are no restrictions. When
-kptr_restrict is set to (1), the default, kernel pointers
-printed using the %pK format specifier will be replaced with 0's
-unless the user has CAP_SYSLOG. When kptr_restrict is set to
-(2), kernel pointers printed using %pK will be replaced with 0's
-regardless of privileges.
+exposing kernel addresses via /proc and other interfaces.
+
+When kptr_restrict is set to (0), the default, there are no restrictions.
+
+When kptr_restrict is set to (1), kernel pointers printed using the %pK
+format specifier will be replaced with 0's unless the user has CAP_SYSLOG
+and effective user and group ids are equal to the real ids. This is
+because %pK checks are done at read() time rather than open() time, so
+if permissions are elevated between the open() and the read() (e.g via
+a setuid binary) then %pK will not leak kernel pointers to unprivileged
+users. Note, this is a temporary solution only. The correct long-term
+solution is to do the permission checks at open() time. Consider removing
+world read permissions from files that use %pK, and using dmesg_restrict
+to protect against uses of %pK in dmesg(8) if leaking kernel pointer
+values to unprivileged users is a concern.
+
+When kptr_restrict is set to (2), kernel pointers printed using
+%pK will be replaced with 0's regardless of privileges.
==============================================================
diff --git a/lib/vsprintf.c b/lib/vsprintf.c
index fab33a9..91cee87 100644
--- a/lib/vsprintf.c
+++ b/lib/vsprintf.c
@@ -26,6 +26,7 @@
#include <linux/math64.h>
#include <linux/uaccess.h>
#include <linux/ioport.h>
+#include <linux/cred.h>
#include <net/addrconf.h>
#include <asm/page.h> /* for PAGE_SIZE */
@@ -1109,11 +1110,37 @@ char *pointer(const char *fmt, char *buf, char *end, void *ptr,
spec.field_width = default_width;
return string(buf, end, "pK-error", spec);
}
- if (!((kptr_restrict == 0) ||
- (kptr_restrict == 1 &&
- has_capability_noaudit(current, CAP_SYSLOG))))
+
+ switch (kptr_restrict) {
+ case 0:
+ /* Always print %pK values */
+ break;
+ case 1: {
+ /*
+ * Only print the real pointer value if the current
+ * process has CAP_SYSLOG and is running with the
+ * same credentials it started with. This is because
+ * access to files is checked at open() time, but %pK
+ * checks permission at read() time. We don't want to
+ * leak pointer values if a binary opens a file using
+ * %pK and then elevates privileges before reading it.
+ */
+ const struct cred *cred = current_cred();
+
+ if (!has_capability_noaudit(current, CAP_SYSLOG) ||
+ !uid_eq(cred->euid, cred->uid) ||
+ !gid_eq(cred->egid, cred->gid))
+ ptr = NULL;
+ break;
+ }
+ case 2:
+ default:
+ /* Always print 0's for %pK */
ptr = NULL;
+ break;
+ }
break;
+
case 'N':
switch (fmt[1]) {
case 'F':
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 105/152] backlight: atmel-pwm-bl: fix reported brightness
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (103 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 104/152] vsprintf: check real user/group id for %pK Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 106/152] backlight: atmel-pwm-bl: fix gpio polarity in remove Kamal Mostafa
` (46 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Johan Hovold, Jingoo Han, Andrew Morton, Linus Torvalds, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Johan Hovold <jhovold@gmail.com>
commit 185d91442550110db67a7dc794a32efcea455a36 upstream.
The driver supports 16-bit brightness values, but the value returned
from get_brightness was truncated to eight bits.
Signed-off-by: Johan Hovold <jhovold@gmail.com>
Cc: Jingoo Han <jg1.han@samsung.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/video/backlight/atmel-pwm-bl.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/video/backlight/atmel-pwm-bl.c b/drivers/video/backlight/atmel-pwm-bl.c
index de5e5e7..f1b85ac 100644
--- a/drivers/video/backlight/atmel-pwm-bl.c
+++ b/drivers/video/backlight/atmel-pwm-bl.c
@@ -70,7 +70,7 @@ static int atmel_pwm_bl_set_intensity(struct backlight_device *bd)
static int atmel_pwm_bl_get_intensity(struct backlight_device *bd)
{
struct atmel_pwm_bl *pwmbl = bl_get_data(bd);
- u8 intensity;
+ u32 intensity;
if (pwmbl->pdata->pwm_active_low) {
intensity = pwm_channel_readl(&pwmbl->pwmc, PWM_CDTY) -
@@ -80,7 +80,7 @@ static int atmel_pwm_bl_get_intensity(struct backlight_device *bd)
pwm_channel_readl(&pwmbl->pwmc, PWM_CDTY);
}
- return intensity;
+ return intensity & 0xffff;
}
static int atmel_pwm_bl_init_pwm(struct atmel_pwm_bl *pwmbl)
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 106/152] backlight: atmel-pwm-bl: fix gpio polarity in remove
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (104 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 105/152] backlight: atmel-pwm-bl: fix reported brightness Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 107/152] coredump: remove redundant defines for dumpable states Kamal Mostafa
` (45 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Johan Hovold, Andrew Morton, Linus Torvalds, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Johan Hovold <jhovold@gmail.com>
commit ad5066d4c2b1d696749f8d7816357c23b648c4d3 upstream.
Make sure to honour gpio polarity also at remove so that the backlight is
actually disabled on boards with active-low enable pin.
Signed-off-by: Johan Hovold <jhovold@gmail.com>
Acked-by: Jingoo Han <jg1.han@samsung.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/video/backlight/atmel-pwm-bl.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/video/backlight/atmel-pwm-bl.c b/drivers/video/backlight/atmel-pwm-bl.c
index f1b85ac..96d07a1 100644
--- a/drivers/video/backlight/atmel-pwm-bl.c
+++ b/drivers/video/backlight/atmel-pwm-bl.c
@@ -207,8 +207,10 @@ static int __exit atmel_pwm_bl_remove(struct platform_device *pdev)
{
struct atmel_pwm_bl *pwmbl = platform_get_drvdata(pdev);
- if (pwmbl->gpio_on != -1)
- gpio_set_value(pwmbl->gpio_on, 0);
+ if (pwmbl->gpio_on != -1) {
+ gpio_set_value(pwmbl->gpio_on,
+ 0 ^ pwmbl->pdata->on_active_low);
+ }
pwm_channel_disable(&pwmbl->pwmc);
pwm_channel_free(&pwmbl->pwmc);
backlight_device_unregister(pwmbl->bldev);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 107/152] coredump: remove redundant defines for dumpable states
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (105 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 106/152] backlight: atmel-pwm-bl: fix gpio polarity in remove Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 108/152] exec/ptrace: fix get_dumpable() incorrect tests Kamal Mostafa
` (44 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Kees Cook, Alexander Viro, Alan Cox, Eric W. Biederman,
Doug Ledford, Serge Hallyn, James Morris, Andrew Morton,
Linus Torvalds, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Kees Cook <keescook@chromium.org>
commit e579d2c259be42b6f29458327e5153b22414b031 upstream.
The existing SUID_DUMP_* defines duplicate the newer SUID_DUMPABLE_*
defines introduced in 54b501992dd2 ("coredump: warn about unsafe
suid_dumpable / core_pattern combo"). Remove the new ones, and use the
prior values instead.
Signed-off-by: Kees Cook <keescook@chromium.org>
Reported-by: Chen Gang <gang.chen@asianux.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Alan Cox <alan@linux.intel.com>
Cc: "Eric W. Biederman" <ebiederm@xmission.com>
Cc: Doug Ledford <dledford@redhat.com>
Cc: Serge Hallyn <serge.hallyn@canonical.com>
Cc: James Morris <james.l.morris@oracle.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[ kamal: 3.8 stable prereq for
d049f74 exec/ptrace: fix get_dumpable() incorrect tests ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
fs/coredump.c | 2 +-
fs/exec.c | 10 +++++-----
fs/proc/internal.h | 3 ++-
include/linux/sched.h | 5 -----
kernel/sysctl.c | 2 +-
5 files changed, 9 insertions(+), 13 deletions(-)
diff --git a/fs/coredump.c b/fs/coredump.c
index 1774932..57b9bd6 100644
--- a/fs/coredump.c
+++ b/fs/coredump.c
@@ -501,7 +501,7 @@ void do_coredump(siginfo_t *siginfo)
* so we dump it as root in mode 2, and only into a controlled
* environment (pipe handler or fully qualified path).
*/
- if (__get_dumpable(cprm.mm_flags) == SUID_DUMPABLE_SAFE) {
+ if (__get_dumpable(cprm.mm_flags) == SUID_DUMP_ROOT) {
/* Setuid core dump mode */
flag = O_EXCL; /* Stop rewrite attacks */
cred->fsuid = GLOBAL_ROOT_UID; /* Dump root private */
diff --git a/fs/exec.c b/fs/exec.c
index 0b5038a..40418c9 100644
--- a/fs/exec.c
+++ b/fs/exec.c
@@ -1114,7 +1114,7 @@ void setup_new_exec(struct linux_binprm * bprm)
current->sas_ss_sp = current->sas_ss_size = 0;
if (uid_eq(current_euid(), current_uid()) && gid_eq(current_egid(), current_gid()))
- set_dumpable(current->mm, SUID_DUMPABLE_ENABLED);
+ set_dumpable(current->mm, SUID_DUMP_USER);
else
set_dumpable(current->mm, suid_dumpable);
@@ -1644,17 +1644,17 @@ EXPORT_SYMBOL(set_binfmt);
void set_dumpable(struct mm_struct *mm, int value)
{
switch (value) {
- case SUID_DUMPABLE_DISABLED:
+ case SUID_DUMP_DISABLE:
clear_bit(MMF_DUMPABLE, &mm->flags);
smp_wmb();
clear_bit(MMF_DUMP_SECURELY, &mm->flags);
break;
- case SUID_DUMPABLE_ENABLED:
+ case SUID_DUMP_USER:
set_bit(MMF_DUMPABLE, &mm->flags);
smp_wmb();
clear_bit(MMF_DUMP_SECURELY, &mm->flags);
break;
- case SUID_DUMPABLE_SAFE:
+ case SUID_DUMP_ROOT:
set_bit(MMF_DUMP_SECURELY, &mm->flags);
smp_wmb();
set_bit(MMF_DUMPABLE, &mm->flags);
@@ -1667,7 +1667,7 @@ int __get_dumpable(unsigned long mm_flags)
int ret;
ret = mm_flags & MMF_DUMPABLE_MASK;
- return (ret > SUID_DUMPABLE_ENABLED) ? SUID_DUMPABLE_SAFE : ret;
+ return (ret > SUID_DUMP_USER) ? SUID_DUMP_ROOT : ret;
}
int get_dumpable(struct mm_struct *mm)
diff --git a/fs/proc/internal.h b/fs/proc/internal.h
index 252544c..85ff3a4 100644
--- a/fs/proc/internal.h
+++ b/fs/proc/internal.h
@@ -11,6 +11,7 @@
#include <linux/sched.h>
#include <linux/proc_fs.h>
+#include <linux/binfmts.h>
struct ctl_table_header;
struct mempolicy;
@@ -108,7 +109,7 @@ static inline int task_dumpable(struct task_struct *task)
if (mm)
dumpable = get_dumpable(mm);
task_unlock(task);
- if (dumpable == SUID_DUMPABLE_ENABLED)
+ if (dumpable == SUID_DUMP_USER)
return 1;
return 0;
}
diff --git a/include/linux/sched.h b/include/linux/sched.h
index caa76ae..6019ecc 100644
--- a/include/linux/sched.h
+++ b/include/linux/sched.h
@@ -378,11 +378,6 @@ static inline void arch_pick_mmap_layout(struct mm_struct *mm) {}
extern void set_dumpable(struct mm_struct *mm, int value);
extern int get_dumpable(struct mm_struct *mm);
-/* get/set_dumpable() values */
-#define SUID_DUMPABLE_DISABLED 0
-#define SUID_DUMPABLE_ENABLED 1
-#define SUID_DUMPABLE_SAFE 2
-
/* mm flags */
/* dumpable bits */
#define MMF_DUMPABLE 0 /* core dump is permitted */
diff --git a/kernel/sysctl.c b/kernel/sysctl.c
index c88878d..585015f 100644
--- a/kernel/sysctl.c
+++ b/kernel/sysctl.c
@@ -2083,7 +2083,7 @@ int proc_dointvec_minmax(struct ctl_table *table, int write,
static void validate_coredump_safety(void)
{
#ifdef CONFIG_COREDUMP
- if (suid_dumpable == SUID_DUMPABLE_SAFE &&
+ if (suid_dumpable == SUID_DUMP_ROOT &&
core_pattern[0] != '/' && core_pattern[0] != '|') {
printk(KERN_WARNING "Unsafe core_pattern used with "\
"suid_dumpable=2. Pipe handler or fully qualified "\
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 108/152] exec/ptrace: fix get_dumpable() incorrect tests
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (106 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 107/152] coredump: remove redundant defines for dumpable states Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 109/152] devpts: plug the memory leak in kill_sb Kamal Mostafa
` (43 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Kees Cook, Luck, Tony, Oleg Nesterov, Eric W. Biederman,
Andrew Morton, Linus Torvalds, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Kees Cook <keescook@chromium.org>
commit d049f74f2dbe71354d43d393ac3a188947811348 upstream.
The get_dumpable() return value is not boolean. Most users of the
function actually want to be testing for non-SUID_DUMP_USER(1) rather than
SUID_DUMP_DISABLE(0). The SUID_DUMP_ROOT(2) is also considered a
protected state. Almost all places did this correctly, excepting the two
places fixed in this patch.
Wrong logic:
if (dumpable == SUID_DUMP_DISABLE) { /* be protective */ }
or
if (dumpable == 0) { /* be protective */ }
or
if (!dumpable) { /* be protective */ }
Correct logic:
if (dumpable != SUID_DUMP_USER) { /* be protective */ }
or
if (dumpable != 1) { /* be protective */ }
Without this patch, if the system had set the sysctl fs/suid_dumpable=2, a
user was able to ptrace attach to processes that had dropped privileges to
that user. (This may have been partially mitigated if Yama was enabled.)
The macros have been moved into the file that declares get/set_dumpable(),
which means things like the ia64 code can see them too.
CVE-2013-2929
Reported-by: Vasily Kulikov <segoon@openwall.com>
Signed-off-by: Kees Cook <keescook@chromium.org>
Cc: "Luck, Tony" <tony.luck@intel.com>
Cc: Oleg Nesterov <oleg@redhat.com>
Cc: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/ia64/include/asm/processor.h | 2 +-
fs/exec.c | 6 ++++++
include/linux/binfmts.h | 3 ---
include/linux/sched.h | 4 ++++
kernel/ptrace.c | 3 ++-
5 files changed, 13 insertions(+), 5 deletions(-)
diff --git a/arch/ia64/include/asm/processor.h b/arch/ia64/include/asm/processor.h
index e0a899a..5a84b3a 100644
--- a/arch/ia64/include/asm/processor.h
+++ b/arch/ia64/include/asm/processor.h
@@ -319,7 +319,7 @@ struct thread_struct {
regs->loadrs = 0; \
regs->r8 = get_dumpable(current->mm); /* set "don't zap registers" flag */ \
regs->r12 = new_sp - 16; /* allocate 16 byte scratch area */ \
- if (unlikely(!get_dumpable(current->mm))) { \
+ if (unlikely(get_dumpable(current->mm) != SUID_DUMP_USER)) { \
/* \
* Zap scratch regs to avoid leaking bits between processes with different \
* uid/privileges. \
diff --git a/fs/exec.c b/fs/exec.c
index 40418c9..2902493 100644
--- a/fs/exec.c
+++ b/fs/exec.c
@@ -1670,6 +1670,12 @@ int __get_dumpable(unsigned long mm_flags)
return (ret > SUID_DUMP_USER) ? SUID_DUMP_ROOT : ret;
}
+/*
+ * This returns the actual value of the suid_dumpable flag. For things
+ * that are using this for checking for privilege transitions, it must
+ * test against SUID_DUMP_USER rather than treating it as a boolean
+ * value.
+ */
int get_dumpable(struct mm_struct *mm)
{
return __get_dumpable(mm->flags);
diff --git a/include/linux/binfmts.h b/include/linux/binfmts.h
index 0530b98..c3a6276 100644
--- a/include/linux/binfmts.h
+++ b/include/linux/binfmts.h
@@ -99,9 +99,6 @@ extern void setup_new_exec(struct linux_binprm * bprm);
extern void would_dump(struct linux_binprm *, struct file *);
extern int suid_dumpable;
-#define SUID_DUMP_DISABLE 0 /* No setuid dumping */
-#define SUID_DUMP_USER 1 /* Dump as user of process */
-#define SUID_DUMP_ROOT 2 /* Dump as root */
/* Stack area protections */
#define EXSTACK_DEFAULT 0 /* Whatever the arch defaults to */
diff --git a/include/linux/sched.h b/include/linux/sched.h
index 6019ecc..87f0503 100644
--- a/include/linux/sched.h
+++ b/include/linux/sched.h
@@ -378,6 +378,10 @@ static inline void arch_pick_mmap_layout(struct mm_struct *mm) {}
extern void set_dumpable(struct mm_struct *mm, int value);
extern int get_dumpable(struct mm_struct *mm);
+#define SUID_DUMP_DISABLE 0 /* No setuid dumping */
+#define SUID_DUMP_USER 1 /* Dump as user of process */
+#define SUID_DUMP_ROOT 2 /* Dump as root */
+
/* mm flags */
/* dumpable bits */
#define MMF_DUMPABLE 0 /* core dump is permitted */
diff --git a/kernel/ptrace.c b/kernel/ptrace.c
index 6cbeaae..278e437 100644
--- a/kernel/ptrace.c
+++ b/kernel/ptrace.c
@@ -255,7 +255,8 @@ ok:
if (task->mm)
dumpable = get_dumpable(task->mm);
rcu_read_lock();
- if (!dumpable && !ptrace_has_cap(__task_cred(task)->user_ns, mode)) {
+ if (dumpable != SUID_DUMP_USER &&
+ !ptrace_has_cap(__task_cred(task)->user_ns, mode)) {
rcu_read_unlock();
return -EPERM;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 109/152] devpts: plug the memory leak in kill_sb
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (107 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 108/152] exec/ptrace: fix get_dumpable() incorrect tests Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 110/152] ipc: clamp with min() Kamal Mostafa
` (42 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Ilija Hadzic, Sukadev Bhattiprolu, Andrew Morton, Linus Torvalds,
Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilija Hadzic <ihadzic@research.bell-labs.com>
commit 66da0e1f9034140ae2f571ef96e254a25083906c upstream.
When devpts is unmounted, there may be a no-longer-used IDR tree hanging
off the superblock we are about to kill. This needs to be cleaned up
before destroying the SB.
The leak is usually not a big deal because unmounting devpts is typically
done when shutting down the whole machine. However, shutting down an LXC
container instead of a physical machine exposes the problem (the garbage
is detectable with kmemleak).
Signed-off-by: Ilija Hadzic <ihadzic@research.bell-labs.com>
Cc: Sukadev Bhattiprolu <sukadev@linux.vnet.ibm.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
fs/devpts/inode.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/fs/devpts/inode.c b/fs/devpts/inode.c
index 472e6be..1d24d57 100644
--- a/fs/devpts/inode.c
+++ b/fs/devpts/inode.c
@@ -483,6 +483,7 @@ static void devpts_kill_sb(struct super_block *sb)
{
struct pts_fs_info *fsi = DEVPTS_SB(sb);
+ ida_destroy(&fsi->allocated_ptys);
kfree(fsi);
kill_litter_super(sb);
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 110/152] ipc: clamp with min()
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (108 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 109/152] devpts: plug the memory leak in kill_sb Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 111/152] ipc: separate msg allocation from userspace copy Kamal Mostafa
` (41 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Peter Hurley, Andrew Morton, Linus Torvalds, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Hurley <peter@hurleysoftware.com>
commit 3d8fa456d5ed22ce8db085a89a037b87568b2b64 upstream.
Signed-off-by: Peter Hurley <peter@hurleysoftware.com>
Acked-by: Stanislav Kinsbursky <skinsbursky@parallels.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[ kamal: 3.8 stable prereq for
4e9b45a ipc, msg: fix message length check for negative values ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
ipc/msgutil.c | 30 ++++++++----------------------
1 file changed, 8 insertions(+), 22 deletions(-)
diff --git a/ipc/msgutil.c b/ipc/msgutil.c
index 5df8e4b..98b1c2b 100644
--- a/ipc/msgutil.c
+++ b/ipc/msgutil.c
@@ -41,8 +41,8 @@ struct msg_msgseg {
/* the next part of the message follows immediately */
};
-#define DATALEN_MSG (PAGE_SIZE-sizeof(struct msg_msg))
-#define DATALEN_SEG (PAGE_SIZE-sizeof(struct msg_msgseg))
+#define DATALEN_MSG (int)(PAGE_SIZE-sizeof(struct msg_msg))
+#define DATALEN_SEG (int)(PAGE_SIZE-sizeof(struct msg_msgseg))
struct msg_msg *load_msg(const void __user *src, int len)
{
@@ -51,10 +51,7 @@ struct msg_msg *load_msg(const void __user *src, int len)
int err;
int alen;
- alen = len;
- if (alen > DATALEN_MSG)
- alen = DATALEN_MSG;
-
+ alen = min(len, DATALEN_MSG);
msg = kmalloc(sizeof(*msg) + alen, GFP_KERNEL);
if (msg == NULL)
return ERR_PTR(-ENOMEM);
@@ -72,9 +69,7 @@ struct msg_msg *load_msg(const void __user *src, int len)
pseg = &msg->next;
while (len > 0) {
struct msg_msgseg *seg;
- alen = len;
- if (alen > DATALEN_SEG)
- alen = DATALEN_SEG;
+ alen = min(len, DATALEN_SEG);
seg = kmalloc(sizeof(*seg) + alen,
GFP_KERNEL);
if (seg == NULL) {
@@ -113,19 +108,14 @@ struct msg_msg *copy_msg(struct msg_msg *src, struct msg_msg *dst)
if (src->m_ts > dst->m_ts)
return ERR_PTR(-EINVAL);
- alen = len;
- if (alen > DATALEN_MSG)
- alen = DATALEN_MSG;
-
+ alen = min(len, DATALEN_MSG);
memcpy(dst + 1, src + 1, alen);
len -= alen;
dst_pseg = dst->next;
src_pseg = src->next;
while (len > 0) {
- alen = len;
- if (alen > DATALEN_SEG)
- alen = DATALEN_SEG;
+ alen = min(len, DATALEN_SEG);
memcpy(dst_pseg + 1, src_pseg + 1, alen);
dst_pseg = dst_pseg->next;
len -= alen;
@@ -148,9 +138,7 @@ int store_msg(void __user *dest, struct msg_msg *msg, int len)
int alen;
struct msg_msgseg *seg;
- alen = len;
- if (alen > DATALEN_MSG)
- alen = DATALEN_MSG;
+ alen = min(len, DATALEN_MSG);
if (copy_to_user(dest, msg + 1, alen))
return -1;
@@ -158,9 +146,7 @@ int store_msg(void __user *dest, struct msg_msg *msg, int len)
dest = ((char __user *)dest) + alen;
seg = msg->next;
while (len > 0) {
- alen = len;
- if (alen > DATALEN_SEG)
- alen = DATALEN_SEG;
+ alen = min(len, DATALEN_SEG);
if (copy_to_user(dest, seg + 1, alen))
return -1;
len -= alen;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 111/152] ipc: separate msg allocation from userspace copy
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (109 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 110/152] ipc: clamp with min() Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 112/152] ipc: tighten msg copy loops Kamal Mostafa
` (40 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Peter Hurley, Andrew Morton, Linus Torvalds, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Hurley <peter@hurleysoftware.com>
commit be5f4b335f6e05df1b5c24b7e7d79ff52d7b8dbc upstream.
Separating msg allocation enables single-block vmalloc
allocation instead.
Signed-off-by: Peter Hurley <peter@hurleysoftware.com>
Acked-by: Stanislav Kinsbursky <skinsbursky@parallels.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[ kamal: 3.8 stable prereq for
4e9b45a ipc, msg: fix message length check for negative values ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
ipc/msgutil.c | 52 ++++++++++++++++++++++++++++++++++++++--------------
1 file changed, 38 insertions(+), 14 deletions(-)
diff --git a/ipc/msgutil.c b/ipc/msgutil.c
index 98b1c2b..0a5c8a9 100644
--- a/ipc/msgutil.c
+++ b/ipc/msgutil.c
@@ -44,21 +44,54 @@ struct msg_msgseg {
#define DATALEN_MSG (int)(PAGE_SIZE-sizeof(struct msg_msg))
#define DATALEN_SEG (int)(PAGE_SIZE-sizeof(struct msg_msgseg))
-struct msg_msg *load_msg(const void __user *src, int len)
+
+static struct msg_msg *alloc_msg(int len)
{
struct msg_msg *msg;
struct msg_msgseg **pseg;
- int err;
int alen;
alen = min(len, DATALEN_MSG);
msg = kmalloc(sizeof(*msg) + alen, GFP_KERNEL);
if (msg == NULL)
- return ERR_PTR(-ENOMEM);
+ return NULL;
msg->next = NULL;
msg->security = NULL;
+ len -= alen;
+ pseg = &msg->next;
+ while (len > 0) {
+ struct msg_msgseg *seg;
+ alen = min(len, DATALEN_SEG);
+ seg = kmalloc(sizeof(*seg) + alen, GFP_KERNEL);
+ if (seg == NULL)
+ goto out_err;
+ *pseg = seg;
+ seg->next = NULL;
+ pseg = &seg->next;
+ len -= alen;
+ }
+
+ return msg;
+
+out_err:
+ free_msg(msg);
+ return NULL;
+}
+
+struct msg_msg *load_msg(const void __user *src, int len)
+{
+ struct msg_msg *msg;
+ struct msg_msgseg *seg;
+ int err;
+ int alen;
+
+ msg = alloc_msg(len);
+ if (msg == NULL)
+ return ERR_PTR(-ENOMEM);
+
+ alen = min(len, DATALEN_MSG);
if (copy_from_user(msg + 1, src, alen)) {
err = -EFAULT;
goto out_err;
@@ -66,23 +99,14 @@ struct msg_msg *load_msg(const void __user *src, int len)
len -= alen;
src = ((char __user *)src) + alen;
- pseg = &msg->next;
+ seg = msg->next;
while (len > 0) {
- struct msg_msgseg *seg;
alen = min(len, DATALEN_SEG);
- seg = kmalloc(sizeof(*seg) + alen,
- GFP_KERNEL);
- if (seg == NULL) {
- err = -ENOMEM;
- goto out_err;
- }
- *pseg = seg;
- seg->next = NULL;
if (copy_from_user(seg + 1, src, alen)) {
err = -EFAULT;
goto out_err;
}
- pseg = &seg->next;
+ seg = seg->next;
len -= alen;
src = ((char __user *)src) + alen;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 112/152] ipc: tighten msg copy loops
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (110 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 111/152] ipc: separate msg allocation from userspace copy Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 113/152] ipc: set EFAULT as default error in load_msg() Kamal Mostafa
` (39 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Peter Hurley, Andrew Morton, Linus Torvalds, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Hurley <peter@hurleysoftware.com>
commit da085d4591a6fe11eac2e1f659f25b655e9f2e53 upstream.
Signed-off-by: Peter Hurley <peter@hurleysoftware.com>
Acked-by: Stanislav Kinsbursky <skinsbursky@parallels.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[ kamal: 3.8 stable prereq for
4e9b45a ipc, msg: fix message length check for negative values ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
ipc/msgutil.c | 32 +++++++++++---------------------
1 file changed, 11 insertions(+), 21 deletions(-)
diff --git a/ipc/msgutil.c b/ipc/msgutil.c
index 0a5c8a9..b79582d 100644
--- a/ipc/msgutil.c
+++ b/ipc/msgutil.c
@@ -97,18 +97,14 @@ struct msg_msg *load_msg(const void __user *src, int len)
goto out_err;
}
- len -= alen;
- src = ((char __user *)src) + alen;
- seg = msg->next;
- while (len > 0) {
+ for (seg = msg->next; seg != NULL; seg = seg->next) {
+ len -= alen;
+ src = (char __user *)src + alen;
alen = min(len, DATALEN_SEG);
if (copy_from_user(seg + 1, src, alen)) {
err = -EFAULT;
goto out_err;
}
- seg = seg->next;
- len -= alen;
- src = ((char __user *)src) + alen;
}
err = security_msg_msg_alloc(msg);
@@ -135,15 +131,13 @@ struct msg_msg *copy_msg(struct msg_msg *src, struct msg_msg *dst)
alen = min(len, DATALEN_MSG);
memcpy(dst + 1, src + 1, alen);
- len -= alen;
- dst_pseg = dst->next;
- src_pseg = src->next;
- while (len > 0) {
+ for (dst_pseg = dst->next, src_pseg = src->next;
+ src_pseg != NULL;
+ dst_pseg = dst_pseg->next, src_pseg = src_pseg->next) {
+
+ len -= alen;
alen = min(len, DATALEN_SEG);
memcpy(dst_pseg + 1, src_pseg + 1, alen);
- dst_pseg = dst_pseg->next;
- len -= alen;
- src_pseg = src_pseg->next;
}
dst->m_type = src->m_type;
@@ -166,16 +160,12 @@ int store_msg(void __user *dest, struct msg_msg *msg, int len)
if (copy_to_user(dest, msg + 1, alen))
return -1;
- len -= alen;
- dest = ((char __user *)dest) + alen;
- seg = msg->next;
- while (len > 0) {
+ for (seg = msg->next; seg != NULL; seg = seg->next) {
+ len -= alen;
+ dest = (char __user *)dest + alen;
alen = min(len, DATALEN_SEG);
if (copy_to_user(dest, seg + 1, alen))
return -1;
- len -= alen;
- dest = ((char __user *)dest) + alen;
- seg = seg->next;
}
return 0;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 113/152] ipc: set EFAULT as default error in load_msg()
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (111 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 112/152] ipc: tighten msg copy loops Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 114/152] ipc, msg: fix message length check for negative values Kamal Mostafa
` (38 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Peter Hurley, Andrew Morton, Linus Torvalds, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Hurley <peter@hurleysoftware.com>
commit 2b3097a294b6daaf390010de14ca50bfccbc6fb6 upstream.
Signed-off-by: Peter Hurley <peter@hurleysoftware.com>
Acked-by: Stanislav Kinsbursky <skinsbursky@parallels.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[ kamal: 3.8 stable prereq for
4e9b45a ipc, msg: fix message length check for negative values ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
ipc/msgutil.c | 10 +++-------
1 file changed, 3 insertions(+), 7 deletions(-)
diff --git a/ipc/msgutil.c b/ipc/msgutil.c
index b79582d..d33fbb2 100644
--- a/ipc/msgutil.c
+++ b/ipc/msgutil.c
@@ -84,7 +84,7 @@ struct msg_msg *load_msg(const void __user *src, int len)
{
struct msg_msg *msg;
struct msg_msgseg *seg;
- int err;
+ int err = -EFAULT;
int alen;
msg = alloc_msg(len);
@@ -92,19 +92,15 @@ struct msg_msg *load_msg(const void __user *src, int len)
return ERR_PTR(-ENOMEM);
alen = min(len, DATALEN_MSG);
- if (copy_from_user(msg + 1, src, alen)) {
- err = -EFAULT;
+ if (copy_from_user(msg + 1, src, alen))
goto out_err;
- }
for (seg = msg->next; seg != NULL; seg = seg->next) {
len -= alen;
src = (char __user *)src + alen;
alen = min(len, DATALEN_SEG);
- if (copy_from_user(seg + 1, src, alen)) {
- err = -EFAULT;
+ if (copy_from_user(seg + 1, src, alen))
goto out_err;
- }
}
err = security_msg_msg_alloc(msg);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 114/152] ipc, msg: fix message length check for negative values
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (112 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 113/152] ipc: set EFAULT as default error in load_msg() Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 115/152] drm/vmwgfx: Resource evict fixes Kamal Mostafa
` (37 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Mathias Krause, Pax Team, Davidlohr Bueso, Brad Spengler,
Manfred Spraul, Andrew Morton, Linus Torvalds, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Mathias Krause <minipli@googlemail.com>
commit 4e9b45a19241354daec281d7a785739829b52359 upstream.
On 64 bit systems the test for negative message sizes is bogus as the
size, which may be positive when evaluated as a long, will get truncated
to an int when passed to load_msg(). So a long might very well contain a
positive value but when truncated to an int it would become negative.
That in combination with a small negative value of msg_ctlmax (which will
be promoted to an unsigned type for the comparison against msgsz, making
it a big positive value and therefore make it pass the check) will lead to
two problems: 1/ The kmalloc() call in alloc_msg() will allocate a too
small buffer as the addition of alen is effectively a subtraction. 2/ The
copy_from_user() call in load_msg() will first overflow the buffer with
userland data and then, when the userland access generates an access
violation, the fixup handler copy_user_handle_tail() will try to fill the
remainder with zeros -- roughly 4GB. That almost instantly results in a
system crash or reset.
,-[ Reproducer (needs to be run as root) ]--
| #include <sys/stat.h>
| #include <sys/msg.h>
| #include <unistd.h>
| #include <fcntl.h>
|
| int main(void) {
| long msg = 1;
| int fd;
|
| fd = open("/proc/sys/kernel/msgmax", O_WRONLY);
| write(fd, "-1", 2);
| close(fd);
|
| msgsnd(0, &msg, 0xfffffff0, IPC_NOWAIT);
|
| return 0;
| }
'---
Fix the issue by preventing msgsz from getting truncated by consistently
using size_t for the message length. This way the size checks in
do_msgsnd() could still be passed with a negative value for msg_ctlmax but
we would fail on the buffer allocation in that case and error out.
Also change the type of m_ts from int to size_t to avoid similar nastiness
in other code paths -- it is used in similar constructs, i.e. signed vs.
unsigned checks. It should never become negative under normal
circumstances, though.
Setting msg_ctlmax to a negative value is an odd configuration and should
be prevented. As that might break existing userland, it will be handled
in a separate commit so it could easily be reverted and reworked without
reintroducing the above described bug.
Hardening mechanisms for user copy operations would have catched that bug
early -- e.g. checking slab object sizes on user copy operations as the
usercopy feature of the PaX patch does. Or, for that matter, detect the
long vs. int sign change due to truncation, as the size overflow plugin
of the very same patch does.
[akpm@linux-foundation.org: fix i386 min() warnings]
Signed-off-by: Mathias Krause <minipli@googlemail.com>
Cc: Pax Team <pageexec@freemail.hu>
Cc: Davidlohr Bueso <davidlohr@hp.com>
Cc: Brad Spengler <spender@grsecurity.net>
Cc: Manfred Spraul <manfred@colorfullife.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
include/linux/msg.h | 6 +++---
ipc/msgutil.c | 20 ++++++++++----------
ipc/util.h | 4 ++--
3 files changed, 15 insertions(+), 15 deletions(-)
diff --git a/include/linux/msg.h b/include/linux/msg.h
index 391af8d..e21f9d4 100644
--- a/include/linux/msg.h
+++ b/include/linux/msg.h
@@ -6,9 +6,9 @@
/* one msg_msg structure for each message */
struct msg_msg {
- struct list_head m_list;
- long m_type;
- int m_ts; /* message text size */
+ struct list_head m_list;
+ long m_type;
+ size_t m_ts; /* message text size */
struct msg_msgseg* next;
void *security;
/* the actual message follows immediately */
diff --git a/ipc/msgutil.c b/ipc/msgutil.c
index d33fbb2..3c75850 100644
--- a/ipc/msgutil.c
+++ b/ipc/msgutil.c
@@ -41,15 +41,15 @@ struct msg_msgseg {
/* the next part of the message follows immediately */
};
-#define DATALEN_MSG (int)(PAGE_SIZE-sizeof(struct msg_msg))
-#define DATALEN_SEG (int)(PAGE_SIZE-sizeof(struct msg_msgseg))
+#define DATALEN_MSG ((size_t)PAGE_SIZE-sizeof(struct msg_msg))
+#define DATALEN_SEG ((size_t)PAGE_SIZE-sizeof(struct msg_msgseg))
-static struct msg_msg *alloc_msg(int len)
+static struct msg_msg *alloc_msg(size_t len)
{
struct msg_msg *msg;
struct msg_msgseg **pseg;
- int alen;
+ size_t alen;
alen = min(len, DATALEN_MSG);
msg = kmalloc(sizeof(*msg) + alen, GFP_KERNEL);
@@ -80,12 +80,12 @@ out_err:
return NULL;
}
-struct msg_msg *load_msg(const void __user *src, int len)
+struct msg_msg *load_msg(const void __user *src, size_t len)
{
struct msg_msg *msg;
struct msg_msgseg *seg;
int err = -EFAULT;
- int alen;
+ size_t alen;
msg = alloc_msg(len);
if (msg == NULL)
@@ -117,8 +117,8 @@ out_err:
struct msg_msg *copy_msg(struct msg_msg *src, struct msg_msg *dst)
{
struct msg_msgseg *dst_pseg, *src_pseg;
- int len = src->m_ts;
- int alen;
+ size_t len = src->m_ts;
+ size_t alen;
BUG_ON(dst == NULL);
if (src->m_ts > dst->m_ts)
@@ -147,9 +147,9 @@ struct msg_msg *copy_msg(struct msg_msg *src, struct msg_msg *dst)
return ERR_PTR(-ENOSYS);
}
#endif
-int store_msg(void __user *dest, struct msg_msg *msg, int len)
+int store_msg(void __user *dest, struct msg_msg *msg, size_t len)
{
- int alen;
+ size_t alen;
struct msg_msgseg *seg;
alen = min(len, DATALEN_MSG);
diff --git a/ipc/util.h b/ipc/util.h
index eeb79a1..099f28a 100644
--- a/ipc/util.h
+++ b/ipc/util.h
@@ -139,9 +139,9 @@ int ipc_parse_version (int *cmd);
#endif
extern void free_msg(struct msg_msg *msg);
-extern struct msg_msg *load_msg(const void __user *src, int len);
+extern struct msg_msg *load_msg(const void __user *src, size_t len);
extern struct msg_msg *copy_msg(struct msg_msg *src, struct msg_msg *dst);
-extern int store_msg(void __user *dest, struct msg_msg *msg, int len);
+extern int store_msg(void __user *dest, struct msg_msg *msg, size_t len);
extern void recompute_msgmni(struct ipc_namespace *);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 115/152] drm/vmwgfx: Resource evict fixes
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (113 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 114/152] ipc, msg: fix message length check for negative values Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 116/152] ALSA: hda - Don't clear the power state at snd_hda_codec_reset() Kamal Mostafa
` (36 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Thomas Hellstrom, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Hellstrom <thellstrom@vmware.com>
commit ea029c28deadc33d2af4baf26810dd5fc44d4926 upstream.
Fix an error message that was incorrectly blaming device resource id
shortage.
Also make sure we correctly catch resource eviction errors, that
could otherwise lead to evictable resources temporarily not being on the
LRU list.
Signed-off-by: Thomas Hellstrom <thellstrom@vmware.com>
Reviewed-by: Jakob Bornecrantz <jakob@vmware.com>
[ kamal: backport to 3.8 (context; no ticket param) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/gpu/drm/vmwgfx/vmwgfx_resource.c | 41 +++++++++++++++++++++++++++-----
1 file changed, 35 insertions(+), 6 deletions(-)
diff --git a/drivers/gpu/drm/vmwgfx/vmwgfx_resource.c b/drivers/gpu/drm/vmwgfx/vmwgfx_resource.c
index 6453029..44f0fd6 100644
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_resource.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_resource.c
@@ -32,6 +32,8 @@
#include <drm/drmP.h>
#include "vmwgfx_resource_priv.h"
+#define VMW_RES_EVICT_ERR_COUNT 10
+
struct vmw_user_dma_buffer {
struct ttm_base_object base;
struct vmw_dma_buffer dma;
@@ -1088,8 +1090,9 @@ void vmw_resource_backoff_reservation(struct ttm_validate_buffer *val_buf)
* to a backup buffer.
*
* @res: The resource to evict.
+ * @interruptible: Whether to wait interruptible.
*/
-int vmw_resource_do_evict(struct vmw_resource *res)
+int vmw_resource_do_evict(struct vmw_resource *res, bool interruptible)
{
struct ttm_validate_buffer val_buf;
const struct vmw_res_func *func = res->func;
@@ -1098,7 +1101,7 @@ int vmw_resource_do_evict(struct vmw_resource *res)
BUG_ON(!func->may_evict);
val_buf.bo = NULL;
- ret = vmw_resource_check_buffer(res, true, &val_buf);
+ ret = vmw_resource_check_buffer(res, interruptible, &val_buf);
if (unlikely(ret != 0))
return ret;
@@ -1137,6 +1140,7 @@ int vmw_resource_validate(struct vmw_resource *res)
struct vmw_private *dev_priv = res->dev_priv;
struct list_head *lru_list = &dev_priv->res_lru[res->func->res_type];
struct ttm_validate_buffer val_buf;
+ unsigned err_count = 0;
if (likely(!res->func->may_evict))
return 0;
@@ -1151,7 +1155,7 @@ int vmw_resource_validate(struct vmw_resource *res)
write_lock(&dev_priv->resource_lock);
if (list_empty(lru_list) || !res->func->may_evict) {
- DRM_ERROR("Out of device device id entries "
+ DRM_ERROR("Out of device device resources "
"for %s.\n", res->func->type_name);
ret = -EBUSY;
write_unlock(&dev_priv->resource_lock);
@@ -1164,7 +1168,19 @@ int vmw_resource_validate(struct vmw_resource *res)
list_del_init(&evict_res->lru_head);
write_unlock(&dev_priv->resource_lock);
- vmw_resource_do_evict(evict_res);
+
+ ret = vmw_resource_do_evict(evict_res, true);
+ if (unlikely(ret != 0)) {
+ write_lock(&dev_priv->resource_lock);
+ list_add_tail(&evict_res->lru_head, lru_list);
+ write_unlock(&dev_priv->resource_lock);
+ if (ret == -ERESTARTSYS ||
+ ++err_count > VMW_RES_EVICT_ERR_COUNT) {
+ vmw_resource_unreference(&evict_res);
+ goto out_no_validate;
+ }
+ }
+
vmw_resource_unreference(&evict_res);
} while (1);
@@ -1249,13 +1265,15 @@ bool vmw_resource_needs_backup(const struct vmw_resource *res)
* @type: The resource type to evict
*
* To avoid thrashing starvation or as part of the hibernation sequence,
- * evict all evictable resources of a specific type.
+ * try to evict all evictable resources of a specific type.
*/
static void vmw_resource_evict_type(struct vmw_private *dev_priv,
enum vmw_res_type type)
{
struct list_head *lru_list = &dev_priv->res_lru[type];
struct vmw_resource *evict_res;
+ unsigned err_count = 0;
+ int ret;
do {
write_lock(&dev_priv->resource_lock);
@@ -1268,7 +1286,18 @@ static void vmw_resource_evict_type(struct vmw_private *dev_priv,
lru_head));
list_del_init(&evict_res->lru_head);
write_unlock(&dev_priv->resource_lock);
- vmw_resource_do_evict(evict_res);
+
+ ret = vmw_resource_do_evict(evict_res, false);
+ if (unlikely(ret != 0)) {
+ write_lock(&dev_priv->resource_lock);
+ list_add_tail(&evict_res->lru_head, lru_list);
+ write_unlock(&dev_priv->resource_lock);
+ if (++err_count > VMW_RES_EVICT_ERR_COUNT) {
+ vmw_resource_unreference(&evict_res);
+ return;
+ }
+ }
+
vmw_resource_unreference(&evict_res);
} while (1);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 116/152] ALSA: hda - Don't clear the power state at snd_hda_codec_reset()
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (114 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 115/152] drm/vmwgfx: Resource evict fixes Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 117/152] ASoC: blackfin: Fix missing break Kamal Mostafa
` (35 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Takashi Iwai, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit d183b4fc463489b6bbe05c99afa0257a6fe578eb upstream.
snd_hda_codec_reset() is called either in resetting the whole setup at
error paths or hwdep clear/reconfig sysfs triggers. But all of these
don't assume that the power has to be off, rather they want to keep
the power state unchanged (e.g. reconfig_codec() calls the power
up/down by itself). Thus, unconditionally clearing the power state in
snd_hda_codec_reset() leads to the inconsistency, confuses the further
operation. This patch gets rid of the lines doing that bad thing.
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/pci/hda/hda_codec.c | 3 ---
1 file changed, 3 deletions(-)
diff --git a/sound/pci/hda/hda_codec.c b/sound/pci/hda/hda_codec.c
index d048204..3f242b5 100644
--- a/sound/pci/hda/hda_codec.c
+++ b/sound/pci/hda/hda_codec.c
@@ -2338,9 +2338,6 @@ int snd_hda_codec_reset(struct hda_codec *codec)
cancel_delayed_work_sync(&codec->jackpoll_work);
#ifdef CONFIG_PM
cancel_delayed_work_sync(&codec->power_work);
- codec->power_on = 0;
- codec->power_transition = 0;
- codec->power_jiffies = jiffies;
flush_workqueue(bus->workq);
#endif
snd_hda_ctls_clear(codec);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 117/152] ASoC: blackfin: Fix missing break
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (115 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 116/152] ALSA: hda - Don't clear the power state at snd_hda_codec_reset() Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 118/152] target: Fix delayed Task Aborted Status (TAS) handling bug Kamal Mostafa
` (34 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Takashi Iwai, Mark Brown, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit afed4dbe3a043dbd833a53b6b4951e155708afd2 upstream.
Fixes: 4b2ffc205cb9 ('ASoC: Blackfin I2S: add 8-bit sample support')
Reported-by: David Binderman
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Mark Brown <broonie@linaro.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/soc/blackfin/bf5xx-i2s.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sound/soc/blackfin/bf5xx-i2s.c b/sound/soc/blackfin/bf5xx-i2s.c
index 168d88b..822bb97 100644
--- a/sound/soc/blackfin/bf5xx-i2s.c
+++ b/sound/soc/blackfin/bf5xx-i2s.c
@@ -111,6 +111,7 @@ static int bf5xx_i2s_hw_params(struct snd_pcm_substream *substream,
bf5xx_i2s->tcr2 |= 7;
bf5xx_i2s->rcr2 |= 7;
sport_handle->wdsize = 1;
+ break;
case SNDRV_PCM_FORMAT_S16_LE:
bf5xx_i2s->tcr2 |= 15;
bf5xx_i2s->rcr2 |= 15;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 118/152] target: Fix delayed Task Aborted Status (TAS) handling bug
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (116 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 117/152] ASoC: blackfin: Fix missing break Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 119/152] md: fix calculation of stacking limits on level change Kamal Mostafa
` (33 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Nicholas Bellinger, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicholas Bellinger <nab@linux-iscsi.org>
commit 29f4c090079f442ea2723d292e4e64f0b6ac1f27 upstream.
This patch fixes a bug in delayed Task Aborted Status (TAS) handling,
where transport_send_task_abort() was not returning for the case
when the se_tfo->write_pending() callback indicated that last fabric
specific WRITE PDU had not yet been received.
It also adds an explicit cmd->scsi_status = SAM_STAT_TASK_ABORTED
assignment within transport_check_aborted_status() to avoid the case
where se_tfo->queue_status() is called when the SAM_STAT_TASK_ABORTED
assignment + ->queue_status() in transport_send_task_abort() does not
occur once SCF_SENT_DELAYED_TAS has been set.
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/target/target_core_transport.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/target/target_core_transport.c b/drivers/target/target_core_transport.c
index e26f673..6a626ec 100644
--- a/drivers/target/target_core_transport.c
+++ b/drivers/target/target_core_transport.c
@@ -2784,6 +2784,7 @@ int transport_check_aborted_status(struct se_cmd *cmd, int send_status)
cmd->t_task_cdb[0], cmd->se_tfo->get_task_tag(cmd));
cmd->se_cmd_flags |= SCF_SENT_DELAYED_TAS;
+ cmd->scsi_status = SAM_STAT_TASK_ABORTED;
cmd->se_tfo->queue_status(cmd);
return 1;
@@ -2811,6 +2812,7 @@ void transport_send_task_abort(struct se_cmd *cmd)
if (cmd->se_tfo->write_pending_status(cmd) != 0) {
cmd->transport_state |= CMD_T_ABORTED;
smp_mb__after_atomic_inc();
+ return;
}
}
cmd->scsi_status = SAM_STAT_TASK_ABORTED;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 119/152] md: fix calculation of stacking limits on level change.
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (117 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 118/152] target: Fix delayed Task Aborted Status (TAS) handling bug Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 120/152] drm/nouveau: when bailing out of a pushbuf ioctl, do not remove previous fence Kamal Mostafa
` (32 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: NeilBrown, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: NeilBrown <neilb@suse.de>
commit 02e5f5c0a0f726e66e3d8506ea1691e344277969 upstream.
The various ->run routines of md personalities assume that the 'queue'
has been initialised by the blk_set_stacking_limits() call in
md_alloc().
However when the level is changed (by level_store()) the ->run routine
for the new level is called for an array which has already had the
stacking limits modified. This can result in incorrect final
settings.
So call blk_set_stacking_limits() before ->run in level_store().
A specific consequence of this bug is that it causes
discard_granularity to be set incorrectly when reshaping a RAID4 to a
RAID0.
This is suitable for any -stable kernel since 3.3 in which
blk_set_stacking_limits() was introduced.
Reported-and-tested-by: "Baldysiak, Pawel" <pawel.baldysiak@intel.com>
Signed-off-by: NeilBrown <neilb@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/md/md.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/md/md.c b/drivers/md/md.c
index a240f16..8e27791 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -3622,6 +3622,7 @@ level_store(struct mddev *mddev, const char *buf, size_t len)
mddev->in_sync = 1;
del_timer_sync(&mddev->safemode_timer);
}
+ blk_set_stacking_limits(&mddev->queue->limits);
pers->run(mddev);
set_bit(MD_CHANGE_DEVS, &mddev->flags);
mddev_resume(mddev);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 120/152] drm/nouveau: when bailing out of a pushbuf ioctl, do not remove previous fence
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (118 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 119/152] md: fix calculation of stacking limits on level change Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 121/152] ASoC: fsl: imx-pcm-fiq: omit fiq counter to avoid harm in unbalanced situations Kamal Mostafa
` (31 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Ben Skeggs, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Ben Skeggs <bskeggs@redhat.com>
commit 9360bd1112d8874d21942e2ae74f5416b00a8db6 upstream.
Signed-off-by: Ben Skeggs <bskeggs@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/gpu/drm/nouveau/nouveau_gem.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/nouveau/nouveau_gem.c b/drivers/gpu/drm/nouveau/nouveau_gem.c
index 8bf695c..3aa8e2f 100644
--- a/drivers/gpu/drm/nouveau/nouveau_gem.c
+++ b/drivers/gpu/drm/nouveau/nouveau_gem.c
@@ -288,7 +288,8 @@ validate_fini_list(struct list_head *list, struct nouveau_fence *fence)
list_for_each_safe(entry, tmp, list) {
nvbo = list_entry(entry, struct nouveau_bo, entry);
- nouveau_bo_fence(nvbo, fence);
+ if (likely(fence))
+ nouveau_bo_fence(nvbo, fence);
if (unlikely(nvbo->validate_mapped)) {
ttm_bo_kunmap(&nvbo->kmap);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 121/152] ASoC: fsl: imx-pcm-fiq: omit fiq counter to avoid harm in unbalanced situations
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (119 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 120/152] drm/nouveau: when bailing out of a pushbuf ioctl, do not remove previous fence Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 122/152] ALSA: pcsp: Fix the order of input device unregistration Kamal Mostafa
` (30 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Oskar Schirmer, Mark Brown, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Oskar Schirmer <oskar@scara.com>
commit fc7dc61d9a87011aaf8a6eb3144ebf9552adf5d2 upstream.
Unbalanced calls to snd_imx_pcm_trigger() may result in endless
FIQ activity and thus provoke eternal sound. While on the first glance,
the switch statement looks pretty symmetric, the SUSPEND/RESUME
pair is not: the suspend case comes along snd_pcm_suspend_all(),
which for fsl/imx-pcm-fiq is called only at snd_soc_suspend(),
but the resume case originates straight from the SNDRV_PCM_IOCTL_RESUME.
This way userland may provoke an unbalanced resume, which might cause
the fiq_enable counter to increase and never return to zero again,
so eventually imx_pcm_fiq is never disabled.
Simply removing the fiq_enable will solve the problem, as long as
one never goes play and capture game simultaneously, but beware
trying both at once, the early TRIGGER_STOP will cut off the other
activity prematurely. So now playing and capturing is scrutinized
separately, instead of by counting.
Signed-off-by: Oskar Schirmer <oskar@scara.com>
Signed-off-by: Mark Brown <broonie@linaro.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/soc/fsl/imx-pcm-fiq.c | 29 +++++++++++++++++------------
1 file changed, 17 insertions(+), 12 deletions(-)
diff --git a/sound/soc/fsl/imx-pcm-fiq.c b/sound/soc/fsl/imx-pcm-fiq.c
index 920f945..6948a6a 100644
--- a/sound/soc/fsl/imx-pcm-fiq.c
+++ b/sound/soc/fsl/imx-pcm-fiq.c
@@ -42,7 +42,8 @@ struct imx_pcm_runtime_data {
struct hrtimer hrt;
int poll_time_ns;
struct snd_pcm_substream *substream;
- atomic_t running;
+ atomic_t playing;
+ atomic_t capturing;
};
static enum hrtimer_restart snd_hrtimer_callback(struct hrtimer *hrt)
@@ -54,7 +55,7 @@ static enum hrtimer_restart snd_hrtimer_callback(struct hrtimer *hrt)
struct pt_regs regs;
unsigned long delta;
- if (!atomic_read(&iprtd->running))
+ if (!atomic_read(&iprtd->playing) && !atomic_read(&iprtd->capturing))
return HRTIMER_NORESTART;
get_fiq_regs(®s);
@@ -122,7 +123,6 @@ static int snd_imx_pcm_prepare(struct snd_pcm_substream *substream)
return 0;
}
-static int fiq_enable;
static int imx_pcm_fiq;
static int snd_imx_pcm_trigger(struct snd_pcm_substream *substream, int cmd)
@@ -134,23 +134,27 @@ static int snd_imx_pcm_trigger(struct snd_pcm_substream *substream, int cmd)
case SNDRV_PCM_TRIGGER_START:
case SNDRV_PCM_TRIGGER_RESUME:
case SNDRV_PCM_TRIGGER_PAUSE_RELEASE:
- atomic_set(&iprtd->running, 1);
+ if (substream->stream == SNDRV_PCM_STREAM_PLAYBACK)
+ atomic_set(&iprtd->playing, 1);
+ else
+ atomic_set(&iprtd->capturing, 1);
hrtimer_start(&iprtd->hrt, ns_to_ktime(iprtd->poll_time_ns),
HRTIMER_MODE_REL);
- if (++fiq_enable == 1)
- enable_fiq(imx_pcm_fiq);
-
+ enable_fiq(imx_pcm_fiq);
break;
case SNDRV_PCM_TRIGGER_STOP:
case SNDRV_PCM_TRIGGER_SUSPEND:
case SNDRV_PCM_TRIGGER_PAUSE_PUSH:
- atomic_set(&iprtd->running, 0);
-
- if (--fiq_enable == 0)
+ if (substream->stream == SNDRV_PCM_STREAM_PLAYBACK)
+ atomic_set(&iprtd->playing, 0);
+ else
+ atomic_set(&iprtd->capturing, 0);
+ if (!atomic_read(&iprtd->playing) &&
+ !atomic_read(&iprtd->capturing))
disable_fiq(imx_pcm_fiq);
-
break;
+
default:
return -EINVAL;
}
@@ -198,7 +202,8 @@ static int snd_imx_open(struct snd_pcm_substream *substream)
iprtd->substream = substream;
- atomic_set(&iprtd->running, 0);
+ atomic_set(&iprtd->playing, 0);
+ atomic_set(&iprtd->capturing, 0);
hrtimer_init(&iprtd->hrt, CLOCK_MONOTONIC, HRTIMER_MODE_REL);
iprtd->hrt.function = snd_hrtimer_callback;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 122/152] ALSA: pcsp: Fix the order of input device unregistration
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (120 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 121/152] ASoC: fsl: imx-pcm-fiq: omit fiq counter to avoid harm in unbalanced situations Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 123/152] ASoC: wm8962: Turn on regcache_cache_only before disabling regulator Kamal Mostafa
` (29 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Takashi Iwai, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit 6408eac2665955343cd0e4bcd7d6237ce39611ed upstream.
The current code may access to the already freed object. The input
device must be accessed and unregistered before freeing the top level
sound object.
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/drivers/pcsp/pcsp.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/drivers/pcsp/pcsp.c b/sound/drivers/pcsp/pcsp.c
index 7a5fdb9..cc7cd2d 100644
--- a/sound/drivers/pcsp/pcsp.c
+++ b/sound/drivers/pcsp/pcsp.c
@@ -187,8 +187,8 @@ static int pcsp_probe(struct platform_device *dev)
static int pcsp_remove(struct platform_device *dev)
{
struct snd_pcsp *chip = platform_get_drvdata(dev);
- alsa_card_pcsp_exit(chip);
pcspkr_input_remove(chip->input_dev);
+ alsa_card_pcsp_exit(chip);
platform_set_drvdata(dev, NULL);
return 0;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 123/152] ASoC: wm8962: Turn on regcache_cache_only before disabling regulator
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (121 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 122/152] ALSA: pcsp: Fix the order of input device unregistration Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 124/152] ARM: integrator_cp: Set LCD{0,1} enable lines when turning on CLCD Kamal Mostafa
` (28 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Nicolin Chen, Mark Brown, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolin Chen <b42378@freescale.com>
commit 50bfcf2df2fadf77e143d6099150e6fa7ef4d78c upstream.
It's safer to turn on regcache_cache_only before disabling regulator since
the driver will turn off the regcache_cache_only after enabling regulator.
If we remain cache_only false, some command like 'amixer cset' would get
failure if being run before wm8962_resume().
Signed-off-by: Nicolin Chen <b42378@freescale.com>
Signed-off-by: Mark Brown <broonie@linaro.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/soc/codecs/wm8962.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/sound/soc/codecs/wm8962.c b/sound/soc/codecs/wm8962.c
index 1b5bda8..df54650 100644
--- a/sound/soc/codecs/wm8962.c
+++ b/sound/soc/codecs/wm8962.c
@@ -3690,6 +3690,8 @@ static int wm8962_i2c_probe(struct i2c_client *i2c,
if (ret < 0)
goto err_enable;
+ regcache_cache_only(wm8962->regmap, true);
+
/* The drivers should power up as needed */
regulator_bulk_disable(ARRAY_SIZE(wm8962->supplies), wm8962->supplies);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 124/152] ARM: integrator_cp: Set LCD{0,1} enable lines when turning on CLCD
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (122 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 123/152] ASoC: wm8962: Turn on regcache_cache_only before disabling regulator Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 125/152] hwmon: (lm90) Fix max6696 alarm handling Kamal Mostafa
` (27 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Jonathan Austin, Olof Johansson, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jonathan Austin <jonathan.austin@arm.com>
commit 30aeadd44deea3f3b0df45b9a70ee0fd5f8d6dc2 upstream.
This turns on the internal integrator LCD display(s). It seems that the code
to do this got lost in refactoring of the CLCD driver.
Signed-off-by: Jonathan Austin <jonathan.austin@arm.com>
Acked-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Olof Johansson <olof@lixom.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/arm/mach-integrator/integrator_cp.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/arm/mach-integrator/integrator_cp.c b/arch/arm/mach-integrator/integrator_cp.c
index 7322838..2314469 100644
--- a/arch/arm/mach-integrator/integrator_cp.c
+++ b/arch/arm/mach-integrator/integrator_cp.c
@@ -199,7 +199,8 @@ static struct mmci_platform_data mmc_data = {
static void cp_clcd_enable(struct clcd_fb *fb)
{
struct fb_var_screeninfo *var = &fb->fb.var;
- u32 val = CM_CTRL_STATIC1 | CM_CTRL_STATIC2;
+ u32 val = CM_CTRL_STATIC1 | CM_CTRL_STATIC2
+ | CM_CTRL_LCDEN0 | CM_CTRL_LCDEN1;
if (var->bits_per_pixel <= 8 ||
(var->bits_per_pixel == 16 && var->green.length == 5))
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 125/152] hwmon: (lm90) Fix max6696 alarm handling
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (123 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 124/152] ARM: integrator_cp: Set LCD{0,1} enable lines when turning on CLCD Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 126/152] ASoC: cs42l52: Correct MIC CTL mask Kamal Mostafa
` (26 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Guenter Roeck, Jean Delvare, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Guenter Roeck <linux@roeck-us.net>
commit e41fae2b1ed8c78283d73651cd65be0228c0dd1c upstream.
Bit 2 of status register 2 on MAX6696 (external diode 2 open)
sets ALERT; the bit thus has to be listed in alert_alarms.
Also display a message in the alert handler if the condition
is encountered.
Even though not all overtemperature conditions cause ALERT
to be set, we should not ignore them in the alert handler.
Display messages for all out-of-range conditions.
Reported-by: Jean Delvare <khali@linux-fr.org>
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Jean Delvare <khali@linux-fr.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/hwmon/lm90.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
diff --git a/drivers/hwmon/lm90.c b/drivers/hwmon/lm90.c
index 863412a..5181a76 100644
--- a/drivers/hwmon/lm90.c
+++ b/drivers/hwmon/lm90.c
@@ -278,7 +278,7 @@ static const struct lm90_params lm90_params[] = {
[max6696] = {
.flags = LM90_HAVE_EMERGENCY
| LM90_HAVE_EMERGENCY_ALARM | LM90_HAVE_TEMP3,
- .alert_alarms = 0x187c,
+ .alert_alarms = 0x1c7c,
.max_convrate = 6,
.reg_local_ext = MAX6657_REG_R_LOCAL_TEMPL,
},
@@ -1500,19 +1500,22 @@ static void lm90_alert(struct i2c_client *client, unsigned int flag)
if ((alarms & 0x7f) == 0 && (alarms2 & 0xfe) == 0) {
dev_info(&client->dev, "Everything OK\n");
} else {
- if (alarms & 0x61)
+ if ((alarms & 0x61) || (alarms2 & 0x80))
dev_warn(&client->dev,
"temp%d out of range, please check!\n", 1);
- if (alarms & 0x1a)
+ if ((alarms & 0x1a) || (alarms2 & 0x20))
dev_warn(&client->dev,
"temp%d out of range, please check!\n", 2);
if (alarms & 0x04)
dev_warn(&client->dev,
"temp%d diode open, please check!\n", 2);
- if (alarms2 & 0x18)
+ if (alarms2 & 0x5a)
dev_warn(&client->dev,
"temp%d out of range, please check!\n", 3);
+ if (alarms2 & 0x04)
+ dev_warn(&client->dev,
+ "temp%d diode open, please check!\n", 3);
/*
* Disable ALERT# output, because these chips don't implement
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 126/152] ASoC: cs42l52: Correct MIC CTL mask
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (124 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 125/152] hwmon: (lm90) Fix max6696 alarm handling Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 127/152] ARM: OMAP2+: omap_device: maintain sane runtime pm status around suspend/resume Kamal Mostafa
` (25 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Brian Austin, Mark Brown, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Brian Austin <brian.austin@cirrus.com>
commit 3d800c6d75b8c92fa928a0bcaf95cd7ac5fd1ce5 upstream.
The mask for CS42L52_MIC_CTL_TYPE_MASK was wrong keeping the mic config
from being set correctly.
Signed-off-by: Brian Austin <brian.austin@cirrus.com>
Signed-off-by: Mark Brown <broonie@linaro.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/soc/codecs/cs42l52.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/soc/codecs/cs42l52.h b/sound/soc/codecs/cs42l52.h
index 60985c0..647a693 100644
--- a/sound/soc/codecs/cs42l52.h
+++ b/sound/soc/codecs/cs42l52.h
@@ -179,7 +179,7 @@
#define CS42L52_MICB_CTL 0x11
#define CS42L52_MIC_CTL_MIC_SEL_MASK 0xBF
#define CS42L52_MIC_CTL_MIC_SEL_SHIFT 6
-#define CS42L52_MIC_CTL_TYPE_MASK 0xDF
+#define CS42L52_MIC_CTL_TYPE_MASK 0x20
#define CS42L52_MIC_CTL_TYPE_SHIFT 5
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 127/152] ARM: OMAP2+: omap_device: maintain sane runtime pm status around suspend/resume
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (125 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 126/152] ASoC: cs42l52: Correct MIC CTL mask Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 128/152] drm/i915: flush cursors harder Kamal Mostafa
` (24 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Nishanth Menon, Tony Lindgren, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Nishanth Menon <nm@ti.com>
commit 3522bf7bfa248b99eafa2f4872190699a808c7d9 upstream.
OMAP device hooks around suspend|resume_noirq ensures that hwmod
devices are forced to idle using omap_device_idle/enable as part of
the last stage of suspend activity.
For a device such as i2c who uses autosuspend, it is possible to enter
the suspend path with dev->power.runtime_status = RPM_ACTIVE.
As part of the suspend flow, the generic runtime logic would increment
it's dev->power.disable_depth to 1. This should prevent further
pm_runtime_get_sync from succeeding once the runtime_status has been
set to RPM_SUSPENDED.
Now, as part of the suspend_noirq handler in omap_device, we force the
following: if the device status is !suspended, we force the device
to idle using omap_device_idle (clocks are cut etc..). This ensures
that from a hardware perspective, the device is "suspended". However,
runtime_status is left to be active.
*if* an operation is attempted after this point to
pm_runtime_get_sync, runtime framework depends on runtime_status to
indicate accurately the device status, and since it sees it to be
ACTIVE, it assumes the module is functional and returns a non-error
value. As a result the user will see pm_runtime_get succeed, however a
register access will crash due to the lack of clocks.
To prevent this from happening, we should ensure that runtime_status
exactly indicates the device status. As a result of this change
any further calls to pm_runtime_get* would return -EACCES (since
disable_depth is 1). On resume, we restore the clocks and runtime
status exactly as we suspended with. These operations are not expected
to fail as we update the states after the core runtime framework has
suspended itself and restore before the core runtime framework has
resumed.
Reported-by: J Keerthy <j-keerthy@ti.com>
Signed-off-by: Nishanth Menon <nm@ti.com>
Acked-by: Rajendra Nayak <rnayak@ti.com>
Acked-by: Kevin Hilman <khilman@linaro.org>
Reviewed-by: Felipe Balbi <balbi@ti.com>
Signed-off-by: Tony Lindgren <tony@atomide.com>
[ kamal: backport to 3.8 (keep OMAP_DEVICE_NO_IDLE_ON_SUSPEND handling) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/arm/mach-omap2/omap_device.c | 19 +++++++++++++++----
1 file changed, 15 insertions(+), 4 deletions(-)
diff --git a/arch/arm/mach-omap2/omap_device.c b/arch/arm/mach-omap2/omap_device.c
index e065daa..3550708 100644
--- a/arch/arm/mach-omap2/omap_device.c
+++ b/arch/arm/mach-omap2/omap_device.c
@@ -836,8 +836,10 @@ static int _od_suspend_noirq(struct device *dev)
if (!ret && !pm_runtime_status_suspended(dev)) {
if (pm_generic_runtime_suspend(dev) == 0) {
- if (!(od->flags & OMAP_DEVICE_NO_IDLE_ON_SUSPEND))
+ if (!(od->flags & OMAP_DEVICE_NO_IDLE_ON_SUSPEND)) {
+ pm_runtime_set_suspended(dev);
omap_device_idle(pdev);
+ }
od->flags |= OMAP_DEVICE_SUSPENDED;
}
}
@@ -850,11 +852,20 @@ static int _od_resume_noirq(struct device *dev)
struct platform_device *pdev = to_platform_device(dev);
struct omap_device *od = to_omap_device(pdev);
- if ((od->flags & OMAP_DEVICE_SUSPENDED) &&
- !pm_runtime_status_suspended(dev)) {
+ if (od->flags & OMAP_DEVICE_SUSPENDED) {
od->flags &= ~OMAP_DEVICE_SUSPENDED;
- if (!(od->flags & OMAP_DEVICE_NO_IDLE_ON_SUSPEND))
+ if (!(od->flags & OMAP_DEVICE_NO_IDLE_ON_SUSPEND)) {
omap_device_enable(pdev);
+ /*
+ * XXX: we run before core runtime pm has resumed itself. At
+ * this point in time, we just restore the runtime pm state and
+ * considering symmetric operations in resume, we donot expect
+ * to fail. If we failed, something changed in core runtime_pm
+ * framework OR some device driver messed things up, hence, WARN
+ */
+ WARN(pm_runtime_set_active(dev),
+ "Could not set %s runtime state active\n", dev_name(dev));
+ }
pm_generic_runtime_resume(dev);
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 128/152] drm/i915: flush cursors harder
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (126 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 127/152] ARM: OMAP2+: omap_device: maintain sane runtime pm status around suspend/resume Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 129/152] rt2x00: fix a crash bug in the HT descriptor handling fix Kamal Mostafa
` (23 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Thomas Richter, Ville Syrjälä, Daniel Vetter, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Vetter <daniel.vetter@ffwll.ch>
commit b2ea8ef559b4d94190009f3651b5b3ab7c05afd3 upstream.
Apparently they need the same treatment as primary planes. This fixes
modesetting failures because of stuck cursors (!) on Thomas' i830M
machine.
I've figured while at it I'll also roll it out for the ivb 3 pipe
version of this function. I didn't do this for i845/i865 since Bspec
says the update mechanism works differently, and there's some
additional rules about what can be updated in which order.
Tested-by: Thomas Richter <thor@math.tu-berlin.de>
Cc: Thomas Richter <thor@math.tu-berlin.de>
Cc: Ville Syrjälä <ville.syrjala@linux.intel.com>
Signed-off-by: Daniel Vetter <daniel.vetter@ffwll.ch>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/gpu/drm/i915/intel_display.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/gpu/drm/i915/intel_display.c b/drivers/gpu/drm/i915/intel_display.c
index 4ab9685..82fcb37 100644
--- a/drivers/gpu/drm/i915/intel_display.c
+++ b/drivers/gpu/drm/i915/intel_display.c
@@ -6337,7 +6337,9 @@ static void i9xx_update_cursor(struct drm_crtc *crtc, u32 base)
intel_crtc->cursor_visible = visible;
}
/* and commit changes on next vblank */
+ POSTING_READ(CURCNTR(pipe));
I915_WRITE(CURBASE(pipe), base);
+ POSTING_READ(CURBASE(pipe));
}
static void ivb_update_cursor(struct drm_crtc *crtc, u32 base)
@@ -6362,7 +6364,9 @@ static void ivb_update_cursor(struct drm_crtc *crtc, u32 base)
intel_crtc->cursor_visible = visible;
}
/* and commit changes on next vblank */
+ POSTING_READ(CURCNTR_IVB(pipe));
I915_WRITE(CURBASE_IVB(pipe), base);
+ POSTING_READ(CURBASE_IVB(pipe));
}
/* If no-part of the cursor is visible on the framebuffer, then the GPU may hang... */
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 129/152] rt2x00: fix a crash bug in the HT descriptor handling fix
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (127 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 128/152] drm/i915: flush cursors harder Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 130/152] rtlwifi: rtl8192cu: Fix more pointer arithmetic errors Kamal Mostafa
` (22 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Felix Fietkau, John W. Linville, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@openwrt.org>
commit b4089d6d8e71a7293e2192025dfa507a04f661c4 upstream.
Commit "rt2x00: fix HT TX descriptor settings regression"
assumes that the control parameter to rt2x00mac_tx is always non-NULL.
There is an internal call in rt2x00lib_bc_buffer_iter where NULL is
passed. Fix the resulting crash by adding an initialized dummy on-stack
ieee80211_tx_control struct.
Signed-off-by: Felix Fietkau <nbd@openwrt.org>
Acked-by: Gertjan van Wingerde <gwingerde@gmail.com>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/rt2x00/rt2x00dev.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/rt2x00/rt2x00dev.c b/drivers/net/wireless/rt2x00/rt2x00dev.c
index cdbfc30..a1789f5 100644
--- a/drivers/net/wireless/rt2x00/rt2x00dev.c
+++ b/drivers/net/wireless/rt2x00/rt2x00dev.c
@@ -181,6 +181,7 @@ static void rt2x00lib_autowakeup(struct work_struct *work)
static void rt2x00lib_bc_buffer_iter(void *data, u8 *mac,
struct ieee80211_vif *vif)
{
+ struct ieee80211_tx_control control = {};
struct rt2x00_dev *rt2x00dev = data;
struct sk_buff *skb;
@@ -195,7 +196,7 @@ static void rt2x00lib_bc_buffer_iter(void *data, u8 *mac,
*/
skb = ieee80211_get_buffered_bc(rt2x00dev->hw, vif);
while (skb) {
- rt2x00mac_tx(rt2x00dev->hw, NULL, skb);
+ rt2x00mac_tx(rt2x00dev->hw, &control, skb);
skb = ieee80211_get_buffered_bc(rt2x00dev->hw, vif);
}
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 130/152] rtlwifi: rtl8192cu: Fix more pointer arithmetic errors
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (128 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 129/152] rt2x00: fix a crash bug in the HT descriptor handling fix Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 131/152] radeon/i2c: do not count reg index in number of i2c byte we are writing Kamal Mostafa
` (21 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Larry Finger, John W. Linville, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Larry Finger <Larry.Finger@lwfinger.net>
commit eafbdde9c5629bea58df07275c5917eb42afbbe7 upstream.
This driver uses a number of macros to get and set various fields in the
RX and TX descriptors. To work correctly, a u8 pointer to the descriptor
must be used; however, in some cases a descriptor structure pointer is used
instead. In addition, a duplicated statement is removed.
Signed-off-by: Larry Finger <Larry.Finger@lwfinger.net>
Reported-by: Mark Cave-Ayland <mark.cave-ayland@ilande.co.uk>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/rtlwifi/rtl8192cu/mac.c | 6 +++---
drivers/net/wireless/rtlwifi/rtl8192cu/trx.c | 6 +++---
2 files changed, 6 insertions(+), 6 deletions(-)
diff --git a/drivers/net/wireless/rtlwifi/rtl8192cu/mac.c b/drivers/net/wireless/rtlwifi/rtl8192cu/mac.c
index 32ff959..aa5528c 100644
--- a/drivers/net/wireless/rtlwifi/rtl8192cu/mac.c
+++ b/drivers/net/wireless/rtlwifi/rtl8192cu/mac.c
@@ -762,7 +762,7 @@ static long _rtl92c_signal_scale_mapping(struct ieee80211_hw *hw,
static void _rtl92c_query_rxphystatus(struct ieee80211_hw *hw,
struct rtl_stats *pstats,
- struct rx_desc_92c *pdesc,
+ struct rx_desc_92c *p_desc,
struct rx_fwinfo_92c *p_drvinfo,
bool packet_match_bssid,
bool packet_toself,
@@ -777,11 +777,11 @@ static void _rtl92c_query_rxphystatus(struct ieee80211_hw *hw,
u32 rssi, total_rssi = 0;
bool in_powersavemode = false;
bool is_cck_rate;
+ u8 *pdesc = (u8 *)p_desc;
- is_cck_rate = RX_HAL_IS_CCK_RATE(pdesc);
+ is_cck_rate = RX_HAL_IS_CCK_RATE(p_desc);
pstats->packet_matchbssid = packet_match_bssid;
pstats->packet_toself = packet_toself;
- pstats->is_cck = is_cck_rate;
pstats->packet_beacon = packet_beacon;
pstats->is_cck = is_cck_rate;
pstats->RX_SIGQ[0] = -1;
diff --git a/drivers/net/wireless/rtlwifi/rtl8192cu/trx.c b/drivers/net/wireless/rtlwifi/rtl8192cu/trx.c
index 6075b34..265862d 100644
--- a/drivers/net/wireless/rtlwifi/rtl8192cu/trx.c
+++ b/drivers/net/wireless/rtlwifi/rtl8192cu/trx.c
@@ -303,10 +303,10 @@ out:
bool rtl92cu_rx_query_desc(struct ieee80211_hw *hw,
struct rtl_stats *stats,
struct ieee80211_rx_status *rx_status,
- u8 *p_desc, struct sk_buff *skb)
+ u8 *pdesc, struct sk_buff *skb)
{
struct rx_fwinfo_92c *p_drvinfo;
- struct rx_desc_92c *pdesc = (struct rx_desc_92c *)p_desc;
+ struct rx_desc_92c *p_desc = (struct rx_desc_92c *)pdesc;
u32 phystatus = GET_RX_DESC_PHY_STATUS(pdesc);
stats->length = (u16) GET_RX_DESC_PKT_LEN(pdesc);
@@ -345,7 +345,7 @@ bool rtl92cu_rx_query_desc(struct ieee80211_hw *hw,
if (phystatus) {
p_drvinfo = (struct rx_fwinfo_92c *)(skb->data +
stats->rx_bufshift);
- rtl92c_translate_rx_signal_stuff(hw, skb, stats, pdesc,
+ rtl92c_translate_rx_signal_stuff(hw, skb, stats, p_desc,
p_drvinfo);
}
/*rx_status->qual = stats->signal; */
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 131/152] radeon/i2c: do not count reg index in number of i2c byte we are writing.
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (129 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 130/152] rtlwifi: rtl8192cu: Fix more pointer arithmetic errors Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 132/152] radeon: workaround pinning failure on low ram gpu Kamal Mostafa
` (20 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Jerome Glisse, Alex Deucher, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jerome Glisse <jglisse@redhat.com>
commit fae009d15a44e5f1d938340facf4b8bc7dc69a09 upstream.
Useless to count the register index in number of bytes we are writing.
Fixes a regression with hw i2c enabled.
Signed-off-by: Jerome Glisse <jglisse@redhat.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
[ kamal: backport to 3.8 (context) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/gpu/drm/radeon/atombios_i2c.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/radeon/atombios_i2c.c b/drivers/gpu/drm/radeon/atombios_i2c.c
index 2ca389d..4bb4b7a 100644
--- a/drivers/gpu/drm/radeon/atombios_i2c.c
+++ b/drivers/gpu/drm/radeon/atombios_i2c.c
@@ -55,7 +55,10 @@ static int radeon_process_i2c_ch(struct radeon_i2c_chan *chan,
DRM_ERROR("hw i2c: tried to write too many bytes (%d vs 2)\n", num);
return -EINVAL;
}
- memcpy(&out, buf, num);
+ if (num > 1) {
+ num--;
+ memcpy(&out, &buf[1], num);
+ }
args.lpI2CDataOut = cpu_to_le16(out);
} else {
if (num > ATOM_MAX_HW_I2C_READ) {
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 132/152] radeon: workaround pinning failure on low ram gpu
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (130 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 131/152] radeon/i2c: do not count reg index in number of i2c byte we are writing Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 133/152] drm/radeon: add semaphore trace point Kamal Mostafa
` (19 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Jerome Glisse, Alex Deucher, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Jerome Glisse <jglisse@redhat.com>
commit 97b6ff6be9da7675aab339334fda996d6c5077d9 upstream.
GPU with low amount of ram can fails at pinning new framebuffer before
unpinning old one. On such failure, retry with unpinning old one before
pinning new one allowing to work around the issue. This is somewhat
ugly but only affect those old GPU we care about.
Signed-off-by: Jerome Glisse <jglisse@redhat.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/gpu/drm/radeon/radeon_legacy_crtc.c | 28 ++++++++++++++++++++++++++++
1 file changed, 28 insertions(+)
diff --git a/drivers/gpu/drm/radeon/radeon_legacy_crtc.c b/drivers/gpu/drm/radeon/radeon_legacy_crtc.c
index 6857cb4..ebd36ac 100644
--- a/drivers/gpu/drm/radeon/radeon_legacy_crtc.c
+++ b/drivers/gpu/drm/radeon/radeon_legacy_crtc.c
@@ -422,6 +422,7 @@ int radeon_crtc_do_set_base(struct drm_crtc *crtc,
/* Pin framebuffer & get tilling informations */
obj = radeon_fb->obj;
rbo = gem_to_radeon_bo(obj);
+retry:
r = radeon_bo_reserve(rbo, false);
if (unlikely(r != 0))
return r;
@@ -430,6 +431,33 @@ int radeon_crtc_do_set_base(struct drm_crtc *crtc,
&base);
if (unlikely(r != 0)) {
radeon_bo_unreserve(rbo);
+
+ /* On old GPU like RN50 with little vram pining can fails because
+ * current fb is taking all space needed. So instead of unpining
+ * the old buffer after pining the new one, first unpin old one
+ * and then retry pining new one.
+ *
+ * As only master can set mode only master can pin and it is
+ * unlikely the master client will race with itself especialy
+ * on those old gpu with single crtc.
+ *
+ * We don't shutdown the display controller because new buffer
+ * will end up in same spot.
+ */
+ if (!atomic && fb && fb != crtc->fb) {
+ struct radeon_bo *old_rbo;
+ unsigned long nsize, osize;
+
+ old_rbo = gem_to_radeon_bo(to_radeon_framebuffer(fb)->obj);
+ osize = radeon_bo_size(old_rbo);
+ nsize = radeon_bo_size(rbo);
+ if (nsize <= osize && !radeon_bo_reserve(old_rbo, false)) {
+ radeon_bo_unpin(old_rbo);
+ radeon_bo_unreserve(old_rbo);
+ fb = NULL;
+ goto retry;
+ }
+ }
return -EINVAL;
}
radeon_bo_get_tiling_flags(rbo, &tiling_flags, NULL);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 133/152] drm/radeon: add semaphore trace point
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (131 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 132/152] radeon: workaround pinning failure on low ram gpu Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 134/152] ACPI / EC: Ensure lock is acquired before accessing ec struct members Kamal Mostafa
` (18 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Christian König, Alex Deucher, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: =?UTF-8?q?Christian=20K=C3=B6nig?= <christian.koenig@amd.com>
commit bd80c8ba995c1dbdddee14acc55c541c499e0442 upstream.
Signed-off-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/gpu/drm/radeon/radeon_semaphore.c | 6 +++++-
drivers/gpu/drm/radeon/radeon_trace.h | 36 +++++++++++++++++++++++++++++++
2 files changed, 41 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/radeon/radeon_semaphore.c b/drivers/gpu/drm/radeon/radeon_semaphore.c
index 8dcc20f..97d73bf 100644
--- a/drivers/gpu/drm/radeon/radeon_semaphore.c
+++ b/drivers/gpu/drm/radeon/radeon_semaphore.c
@@ -29,7 +29,7 @@
*/
#include <drm/drmP.h>
#include "radeon.h"
-
+#include "radeon_trace.h"
int radeon_semaphore_create(struct radeon_device *rdev,
struct radeon_semaphore **semaphore)
@@ -56,6 +56,8 @@ int radeon_semaphore_create(struct radeon_device *rdev,
void radeon_semaphore_emit_signal(struct radeon_device *rdev, int ring,
struct radeon_semaphore *semaphore)
{
+ trace_radeon_semaphore_signale(ring, semaphore);
+
--semaphore->waiters;
radeon_semaphore_ring_emit(rdev, ring, &rdev->ring[ring], semaphore, false);
}
@@ -63,6 +65,8 @@ void radeon_semaphore_emit_signal(struct radeon_device *rdev, int ring,
void radeon_semaphore_emit_wait(struct radeon_device *rdev, int ring,
struct radeon_semaphore *semaphore)
{
+ trace_radeon_semaphore_wait(ring, semaphore);
+
++semaphore->waiters;
radeon_semaphore_ring_emit(rdev, ring, &rdev->ring[ring], semaphore, true);
}
diff --git a/drivers/gpu/drm/radeon/radeon_trace.h b/drivers/gpu/drm/radeon/radeon_trace.h
index eafd816..a20bc7e 100644
--- a/drivers/gpu/drm/radeon/radeon_trace.h
+++ b/drivers/gpu/drm/radeon/radeon_trace.h
@@ -74,6 +74,42 @@ DEFINE_EVENT(radeon_fence_request, radeon_fence_wait_end,
TP_ARGS(dev, seqno)
);
+DECLARE_EVENT_CLASS(radeon_semaphore_request,
+
+ TP_PROTO(int ring, struct radeon_semaphore *sem),
+
+ TP_ARGS(ring, sem),
+
+ TP_STRUCT__entry(
+ __field(int, ring)
+ __field(signed, waiters)
+ __field(uint64_t, gpu_addr)
+ ),
+
+ TP_fast_assign(
+ __entry->ring = ring;
+ __entry->waiters = sem->waiters;
+ __entry->gpu_addr = sem->gpu_addr;
+ ),
+
+ TP_printk("ring=%u, waiters=%d, addr=%010Lx", __entry->ring,
+ __entry->waiters, __entry->gpu_addr)
+);
+
+DEFINE_EVENT(radeon_semaphore_request, radeon_semaphore_signale,
+
+ TP_PROTO(int ring, struct radeon_semaphore *sem),
+
+ TP_ARGS(ring, sem)
+);
+
+DEFINE_EVENT(radeon_semaphore_request, radeon_semaphore_wait,
+
+ TP_PROTO(int ring, struct radeon_semaphore *sem),
+
+ TP_ARGS(ring, sem)
+);
+
#endif
/* This part must be outside protection */
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 134/152] ACPI / EC: Ensure lock is acquired before accessing ec struct members
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (132 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 133/152] drm/radeon: add semaphore trace point Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 135/152] setfacl removes part of ACL when setting POSIX ACLs to Samba Kamal Mostafa
` (17 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Puneet Kumar, Olof Johansson, Rafael J. Wysocki, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Puneet Kumar <puneetster@chromium.org>
commit 36b15875a7819a2ec4cb5748ff7096ad7bd86cbb upstream.
A bug was introduced by commit b76b51ba0cef ('ACPI / EC: Add more debug
info and trivial code cleanup') that erroneously caused the struct member
to be accessed before acquiring the required lock. This change fixes
it by ensuring the lock acquisition is done first.
Found by Aaron Durbin <adurbin@chromium.org>
Fixes: b76b51ba0cef ('ACPI / EC: Add more debug info and trivial code cleanup')
References: http://crbug.com/319019
Signed-off-by: Puneet Kumar <puneetster@chromium.org>
Reviewed-by: Aaron Durbin <adurbin@chromium.org>
[olof: Commit message reworded a bit]
Signed-off-by: Olof Johansson <olof@lixom.net>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/acpi/ec.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/acpi/ec.c b/drivers/acpi/ec.c
index 0b58c9d..97fcfb0 100644
--- a/drivers/acpi/ec.c
+++ b/drivers/acpi/ec.c
@@ -175,9 +175,10 @@ static void start_transaction(struct acpi_ec *ec)
static void advance_transaction(struct acpi_ec *ec, u8 status)
{
unsigned long flags;
- struct transaction *t = ec->curr;
+ struct transaction *t;
spin_lock_irqsave(&ec->lock, flags);
+ t = ec->curr;
if (!t)
goto unlock;
if (t->wlen > t->wi) {
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 135/152] setfacl removes part of ACL when setting POSIX ACLs to Samba
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (133 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 134/152] ACPI / EC: Ensure lock is acquired before accessing ec struct members Kamal Mostafa
@ 2013-12-06 23:10 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 136/152] nfsd: split up nfsd_setattr Kamal Mostafa
` (16 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:10 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Steve French, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Steve French <smfrench@gmail.com>
commit b1d93356427be6f050dc55c86eb019d173700af6 upstream.
setfacl over cifs mounts can remove the default ACL when setting the
(non-default part of) the ACL and vice versa (we were leaving at 0
rather than setting to -1 the count field for the unaffected
half of the ACL. For example notice the setfacl removed
the default ACL in this sequence:
steven@steven-GA-970A-DS3:~/cifs-2.6$ getfacl /mnt/test-dir ; setfacl
-m default:user:test:rwx,user:test:rwx /mnt/test-dir
getfacl: Removing leading '/' from absolute path names
user::rwx
group::r-x
other::r-x
default:user::rwx
default:user:test:rwx
default:group::r-x
default:mask::rwx
default:other::r-x
steven@steven-GA-970A-DS3:~/cifs-2.6$ getfacl /mnt/test-dir
getfacl: Removing leading '/' from absolute path names
user::rwx
user:test:rwx
group::r-x
mask::rwx
other::r-x
Signed-off-by: Steve French <smfrench@gmail.com>
Acked-by: Jeremy Allison <jra@samba.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
fs/cifs/cifssmb.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/fs/cifs/cifssmb.c b/fs/cifs/cifssmb.c
index 76d0d29..2b280d9 100644
--- a/fs/cifs/cifssmb.c
+++ b/fs/cifs/cifssmb.c
@@ -3296,11 +3296,13 @@ static __u16 ACL_to_cifs_posix(char *parm_data, const char *pACL,
return 0;
}
cifs_acl->version = cpu_to_le16(1);
- if (acl_type == ACL_TYPE_ACCESS)
+ if (acl_type == ACL_TYPE_ACCESS) {
cifs_acl->access_entry_count = cpu_to_le16(count);
- else if (acl_type == ACL_TYPE_DEFAULT)
+ cifs_acl->default_entry_count = __constant_cpu_to_le16(0xFFFF);
+ } else if (acl_type == ACL_TYPE_DEFAULT) {
cifs_acl->default_entry_count = cpu_to_le16(count);
- else {
+ cifs_acl->access_entry_count = __constant_cpu_to_le16(0xFFFF);
+ } else {
cFYI(1, "unknown ACL type %d", acl_type);
return 0;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 136/152] nfsd: split up nfsd_setattr
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (134 preceding siblings ...)
2013-12-06 23:10 ` [PATCH 3.8 135/152] setfacl removes part of ACL when setting POSIX ACLs to Samba Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 137/152] nfsd: make sure to balance get/put_write_access Kamal Mostafa
` (15 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Christoph Hellwig, J. Bruce Fields, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@infradead.org>
commit 818e5a22e907fbae75e9c1fd78233baec9fa64b6 upstream.
Split out two helpers to make the code more readable and easier to verify
for correctness.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
fs/nfsd/vfs.c | 144 ++++++++++++++++++++++++++++++++++------------------------
1 file changed, 84 insertions(+), 60 deletions(-)
diff --git a/fs/nfsd/vfs.c b/fs/nfsd/vfs.c
index 10f950f..4fc2843 100644
--- a/fs/nfsd/vfs.c
+++ b/fs/nfsd/vfs.c
@@ -297,41 +297,12 @@ commit_metadata(struct svc_fh *fhp)
}
/*
- * Set various file attributes.
- * N.B. After this call fhp needs an fh_put
+ * Go over the attributes and take care of the small differences between
+ * NFS semantics and what Linux expects.
*/
-__be32
-nfsd_setattr(struct svc_rqst *rqstp, struct svc_fh *fhp, struct iattr *iap,
- int check_guard, time_t guardtime)
+static void
+nfsd_sanitize_attrs(struct inode *inode, struct iattr *iap)
{
- struct dentry *dentry;
- struct inode *inode;
- int accmode = NFSD_MAY_SATTR;
- umode_t ftype = 0;
- __be32 err;
- int host_err;
- int size_change = 0;
-
- if (iap->ia_valid & (ATTR_ATIME | ATTR_MTIME | ATTR_SIZE))
- accmode |= NFSD_MAY_WRITE|NFSD_MAY_OWNER_OVERRIDE;
- if (iap->ia_valid & ATTR_SIZE)
- ftype = S_IFREG;
-
- /* Get inode */
- err = fh_verify(rqstp, fhp, ftype, accmode);
- if (err)
- goto out;
-
- dentry = fhp->fh_dentry;
- inode = dentry->d_inode;
-
- /* Ignore any mode updates on symlinks */
- if (S_ISLNK(inode->i_mode))
- iap->ia_valid &= ~ATTR_MODE;
-
- if (!iap->ia_valid)
- goto out;
-
/*
* NFSv2 does not differentiate between "set-[ac]time-to-now"
* which only requires access, and "set-[ac]time-to-X" which
@@ -341,8 +312,7 @@ nfsd_setattr(struct svc_rqst *rqstp, struct svc_fh *fhp, struct iattr *iap,
* convert to "set to now" instead of "set to explicit time"
*
* We only call inode_change_ok as the last test as technically
- * it is not an interface that we should be using. It is only
- * valid if the filesystem does not define it's own i_op->setattr.
+ * it is not an interface that we should be using.
*/
#define BOTH_TIME_SET (ATTR_ATIME_SET | ATTR_MTIME_SET)
#define MAX_TOUCH_TIME_ERROR (30*60)
@@ -368,30 +338,6 @@ nfsd_setattr(struct svc_rqst *rqstp, struct svc_fh *fhp, struct iattr *iap,
iap->ia_valid &= ~BOTH_TIME_SET;
}
}
-
- /*
- * The size case is special.
- * It changes the file as well as the attributes.
- */
- if (iap->ia_valid & ATTR_SIZE) {
- if (iap->ia_size < inode->i_size) {
- err = nfsd_permission(rqstp, fhp->fh_export, dentry,
- NFSD_MAY_TRUNC|NFSD_MAY_OWNER_OVERRIDE);
- if (err)
- goto out;
- }
-
- host_err = get_write_access(inode);
- if (host_err)
- goto out_nfserr;
-
- size_change = 1;
- host_err = locks_verify_truncate(inode, NULL, iap->ia_size);
- if (host_err) {
- put_write_access(inode);
- goto out_nfserr;
- }
- }
/* sanitize the mode change */
if (iap->ia_valid & ATTR_MODE) {
@@ -414,8 +360,86 @@ nfsd_setattr(struct svc_rqst *rqstp, struct svc_fh *fhp, struct iattr *iap,
iap->ia_valid |= (ATTR_KILL_SUID | ATTR_KILL_SGID);
}
}
+}
- /* Change the attributes. */
+static __be32
+nfsd_get_write_access(struct svc_rqst *rqstp, struct svc_fh *fhp,
+ struct iattr *iap)
+{
+ struct inode *inode = fhp->fh_dentry->d_inode;
+ int host_err;
+
+ if (iap->ia_size < inode->i_size) {
+ __be32 err;
+
+ err = nfsd_permission(rqstp, fhp->fh_export, fhp->fh_dentry,
+ NFSD_MAY_TRUNC | NFSD_MAY_OWNER_OVERRIDE);
+ if (err)
+ return err;
+ }
+
+ host_err = get_write_access(inode);
+ if (host_err)
+ goto out_nfserrno;
+
+ host_err = locks_verify_truncate(inode, NULL, iap->ia_size);
+ if (host_err)
+ goto out_put_write_access;
+ return 0;
+
+out_put_write_access:
+ put_write_access(inode);
+out_nfserrno:
+ return nfserrno(host_err);
+}
+
+/*
+ * Set various file attributes. After this call fhp needs an fh_put.
+ */
+__be32
+nfsd_setattr(struct svc_rqst *rqstp, struct svc_fh *fhp, struct iattr *iap,
+ int check_guard, time_t guardtime)
+{
+ struct dentry *dentry;
+ struct inode *inode;
+ int accmode = NFSD_MAY_SATTR;
+ umode_t ftype = 0;
+ __be32 err;
+ int host_err;
+ int size_change = 0;
+
+ if (iap->ia_valid & (ATTR_ATIME | ATTR_MTIME | ATTR_SIZE))
+ accmode |= NFSD_MAY_WRITE|NFSD_MAY_OWNER_OVERRIDE;
+ if (iap->ia_valid & ATTR_SIZE)
+ ftype = S_IFREG;
+
+ /* Get inode */
+ err = fh_verify(rqstp, fhp, ftype, accmode);
+ if (err)
+ goto out;
+
+ dentry = fhp->fh_dentry;
+ inode = dentry->d_inode;
+
+ /* Ignore any mode updates on symlinks */
+ if (S_ISLNK(inode->i_mode))
+ iap->ia_valid &= ~ATTR_MODE;
+
+ if (!iap->ia_valid)
+ goto out;
+
+ nfsd_sanitize_attrs(inode, iap);
+
+ /*
+ * The size case is special, it changes the file in addition to the
+ * attributes.
+ */
+ if (iap->ia_valid & ATTR_SIZE) {
+ err = nfsd_get_write_access(rqstp, fhp, iap);
+ if (err)
+ goto out;
+ size_change = 1;
+ }
iap->ia_valid |= ATTR_CTIME;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 137/152] nfsd: make sure to balance get/put_write_access
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (135 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 136/152] nfsd: split up nfsd_setattr Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 138/152] ASoC: wm5110: Add post SYSCLK register patch for rev D chip Kamal Mostafa
` (14 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Christoph Hellwig, J. Bruce Fields, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@infradead.org>
commit 987da4791052fa298b7cfcde4dea9f6f2bbc786b upstream.
Use a straight goto error label style in nfsd_setattr to make sure
we always do the put_write_access call after we got it earlier.
Note that the we have been failing to do that in the case
nfsd_break_lease() returns an error, a bug introduced into 2.6.38 with
6a76bebefe15d9a08864f824d7f8d5beaf37c997 "nfsd4: break lease on nfsd
setattr".
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
[ kamal: backport to 3.8 (notify_change args) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
fs/nfsd/vfs.c | 29 +++++++++++++++--------------
1 file changed, 15 insertions(+), 14 deletions(-)
diff --git a/fs/nfsd/vfs.c b/fs/nfsd/vfs.c
index 4fc2843..59f1e77 100644
--- a/fs/nfsd/vfs.c
+++ b/fs/nfsd/vfs.c
@@ -443,27 +443,28 @@ nfsd_setattr(struct svc_rqst *rqstp, struct svc_fh *fhp, struct iattr *iap,
iap->ia_valid |= ATTR_CTIME;
- err = nfserr_notsync;
- if (!check_guard || guardtime == inode->i_ctime.tv_sec) {
- host_err = nfsd_break_lease(inode);
- if (host_err)
- goto out_nfserr;
- fh_lock(fhp);
-
- host_err = notify_change(dentry, iap);
- err = nfserrno(host_err);
- fh_unlock(fhp);
+ if (check_guard && guardtime != inode->i_ctime.tv_sec) {
+ err = nfserr_notsync;
+ goto out_put_write_access;
}
+
+ host_err = nfsd_break_lease(inode);
+ if (host_err)
+ goto out_put_write_access_nfserror;
+
+ fh_lock(fhp);
+ host_err = notify_change(dentry, iap);
+ fh_unlock(fhp);
+
+out_put_write_access_nfserror:
+ err = nfserrno(host_err);
+out_put_write_access:
if (size_change)
put_write_access(inode);
if (!err)
commit_metadata(fhp);
out:
return err;
-
-out_nfserr:
- err = nfserrno(host_err);
- goto out;
}
#if defined(CONFIG_NFSD_V2_ACL) || \
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 138/152] ASoC: wm5110: Add post SYSCLK register patch for rev D chip
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (136 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 137/152] nfsd: make sure to balance get/put_write_access Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 139/152] nfsd4: fix xdr decoding of large non-write compounds Kamal Mostafa
` (13 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Charles Keepax, Mark Brown, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Charles Keepax <ckeepax@opensource.wolfsonmicro.com>
commit f69f86b1ba6493126a7f093a65a8952bcb183de2 upstream.
Certain registers require patching after the SYSCLK has been brought up
add support for this into the CODEC driver.
Signed-off-by: Charles Keepax <ckeepax@opensource.wolfsonmicro.com>
Signed-off-by: Mark Brown <broonie@linaro.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/soc/codecs/wm5110.c | 43 ++++++++++++++++++++++++++++++++++++++++++-
1 file changed, 42 insertions(+), 1 deletion(-)
diff --git a/sound/soc/codecs/wm5110.c b/sound/soc/codecs/wm5110.c
index ccbdc46..e0bb6dc 100644
--- a/sound/soc/codecs/wm5110.c
+++ b/sound/soc/codecs/wm5110.c
@@ -37,6 +37,47 @@ struct wm5110_priv {
struct arizona_fll fll[2];
};
+static const struct reg_default wm5110_sysclk_revd_patch[] = {
+ { 0x3093, 0x1001 },
+ { 0x30E3, 0x1301 },
+ { 0x3133, 0x1201 },
+ { 0x3183, 0x1501 },
+ { 0x31D3, 0x1401 },
+};
+
+static int wm5110_sysclk_ev(struct snd_soc_dapm_widget *w,
+ struct snd_kcontrol *kcontrol, int event)
+{
+ struct snd_soc_codec *codec = w->codec;
+ struct arizona *arizona = dev_get_drvdata(codec->dev->parent);
+ struct regmap *regmap = codec->control_data;
+ const struct reg_default *patch = NULL;
+ int i, patch_size;
+
+ switch (arizona->rev) {
+ case 3:
+ patch = wm5110_sysclk_revd_patch;
+ patch_size = ARRAY_SIZE(wm5110_sysclk_revd_patch);
+ break;
+ default:
+ return 0;
+ }
+
+ switch (event) {
+ case SND_SOC_DAPM_POST_PMU:
+ if (patch)
+ for (i = 0; i < patch_size; i++)
+ regmap_write(regmap, patch[i].reg,
+ patch[i].def);
+ break;
+
+ default:
+ break;
+ }
+
+ return 0;
+}
+
static DECLARE_TLV_DB_SCALE(ana_tlv, 0, 100, 0);
static DECLARE_TLV_DB_SCALE(eq_tlv, -1200, 100, 0);
static DECLARE_TLV_DB_SCALE(digital_tlv, -6400, 50, 0);
@@ -354,7 +395,7 @@ static const struct snd_kcontrol_new wm5110_aec_loopback_mux =
static const struct snd_soc_dapm_widget wm5110_dapm_widgets[] = {
SND_SOC_DAPM_SUPPLY("SYSCLK", ARIZONA_SYSTEM_CLOCK_1, ARIZONA_SYSCLK_ENA_SHIFT,
- 0, NULL, 0),
+ 0, wm5110_sysclk_ev, SND_SOC_DAPM_POST_PMU),
SND_SOC_DAPM_SUPPLY("ASYNCCLK", ARIZONA_ASYNC_CLOCK_1,
ARIZONA_ASYNC_CLK_ENA_SHIFT, 0, NULL, 0),
SND_SOC_DAPM_SUPPLY("OPCLK", ARIZONA_OUTPUT_SYSTEM_CLOCK,
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 139/152] nfsd4: fix xdr decoding of large non-write compounds
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (137 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 138/152] ASoC: wm5110: Add post SYSCLK register patch for rev D chip Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 140/152] avr32: setup crt for early panic() Kamal Mostafa
` (12 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: J. Bruce Fields, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: "J. Bruce Fields" <bfields@redhat.com>
commit 365da4adebb1c012febf81019ad3dc5bb52e2a13 upstream.
This fixes a regression from 247500820ebd02ad87525db5d9b199e5b66f6636
"nfsd4: fix decoding of compounds across page boundaries". The previous
code was correct: argp->pagelist is initialized in
nfs4svc_deocde_compoundargs to rqstp->rq_arg.pages, and is therefore a
pointer to the page *after* the page we are currently decoding.
The reason that patch nevertheless fixed a problem with decoding
compounds containing write was a bug in the write decoding introduced by
5a80a54d21c96590d013378d8c5f65f879451ab4 "nfsd4: reorganize write
decoding", after which write decoding no longer adhered to the rule that
argp->pagelist point to the next page.
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
[ kamal: backport to 3.8 (next_decode_page change is in read_buf) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
fs/nfsd/nfs4xdr.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/nfsd/nfs4xdr.c b/fs/nfsd/nfs4xdr.c
index 859d145..3ed8550 100644
--- a/fs/nfsd/nfs4xdr.c
+++ b/fs/nfsd/nfs4xdr.c
@@ -162,8 +162,8 @@ static __be32 *read_buf(struct nfsd4_compoundargs *argp, u32 nbytes)
*/
memcpy(p, argp->p, avail);
/* step to next page */
- argp->pagelist++;
argp->p = page_address(argp->pagelist[0]);
+ argp->pagelist++;
if (argp->pagelen < PAGE_SIZE) {
argp->end = argp->p + (argp->pagelen>>2);
argp->pagelen = 0;
@@ -1160,6 +1160,7 @@ nfsd4_decode_write(struct nfsd4_compoundargs *argp, struct nfsd4_write *write)
len -= pages * PAGE_SIZE;
argp->p = (__be32 *)page_address(argp->pagelist[0]);
+ argp->pagelist++;
argp->end = argp->p + XDR_QUADLEN(PAGE_SIZE);
}
argp->p += XDR_QUADLEN(len);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 140/152] avr32: setup crt for early panic()
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (138 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 139/152] nfsd4: fix xdr decoding of large non-write compounds Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 141/152] avr32: fix out-of-range jump in large kernels Kamal Mostafa
` (11 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Andreas Bießmann, Haavard Skinnemoen, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: =?UTF-8?q?Andreas=20Bie=C3=9Fmann?= <andreas@biessmann.de>
commit 7a2a74f4b856993218aa7cdeeb6c3103101340db upstream.
Before the CRT was (fully) set up in kernel_entry (bss cleared before in
_start, but also not before jump to panic() in no_tag_table case).
This patch fixes this up to have a fully working CRT when branching to panic()
in no_tag_table.
Signed-off-by: Andreas Bießmann <andreas@biessmann.de>
Acked-by: Hans-Christian Egtvedt <egtvedt@samfundet.no>
Cc: Haavard Skinnemoen <hskinnemoen@gmail.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/avr32/boot/u-boot/head.S | 30 +++++++++++++++++++++++++-----
arch/avr32/kernel/head.S | 20 --------------------
2 files changed, 25 insertions(+), 25 deletions(-)
diff --git a/arch/avr32/boot/u-boot/head.S b/arch/avr32/boot/u-boot/head.S
index 4488fa2..d36d865 100644
--- a/arch/avr32/boot/u-boot/head.S
+++ b/arch/avr32/boot/u-boot/head.S
@@ -8,6 +8,8 @@
* published by the Free Software Foundation.
*/
#include <asm/setup.h>
+#include <asm/thread_info.h>
+#include <asm/sysreg.h>
/*
* The kernel is loaded where we want it to be and all caches
@@ -20,11 +22,6 @@
.section .init.text,"ax"
.global _start
_start:
- /* Check if the boot loader actually provided a tag table */
- lddpc r0, magic_number
- cp.w r12, r0
- brne no_tag_table
-
/* Initialize .bss */
lddpc r2, bss_start_addr
lddpc r3, end_addr
@@ -34,6 +31,25 @@ _start:
cp r2, r3
brlo 1b
+ /* Initialize status register */
+ lddpc r0, init_sr
+ mtsr SYSREG_SR, r0
+
+ /* Set initial stack pointer */
+ lddpc sp, stack_addr
+ sub sp, -THREAD_SIZE
+
+#ifdef CONFIG_FRAME_POINTER
+ /* Mark last stack frame */
+ mov lr, 0
+ mov r7, 0
+#endif
+
+ /* Check if the boot loader actually provided a tag table */
+ lddpc r0, magic_number
+ cp.w r12, r0
+ brne no_tag_table
+
/*
* Save the tag table address for later use. This must be done
* _after_ .bss has been initialized...
@@ -53,6 +69,10 @@ bss_start_addr:
.long __bss_start
end_addr:
.long _end
+init_sr:
+ .long 0x007f0000 /* Supervisor mode, everything masked */
+stack_addr:
+ .long init_thread_union
no_tag_table:
sub r12, pc, (. - 2f)
diff --git a/arch/avr32/kernel/head.S b/arch/avr32/kernel/head.S
index 6163bd0..59eae6d 100644
--- a/arch/avr32/kernel/head.S
+++ b/arch/avr32/kernel/head.S
@@ -10,33 +10,13 @@
#include <linux/linkage.h>
#include <asm/page.h>
-#include <asm/thread_info.h>
-#include <asm/sysreg.h>
.section .init.text,"ax"
.global kernel_entry
kernel_entry:
- /* Initialize status register */
- lddpc r0, init_sr
- mtsr SYSREG_SR, r0
-
- /* Set initial stack pointer */
- lddpc sp, stack_addr
- sub sp, -THREAD_SIZE
-
-#ifdef CONFIG_FRAME_POINTER
- /* Mark last stack frame */
- mov lr, 0
- mov r7, 0
-#endif
-
/* Start the show */
lddpc pc, kernel_start_addr
.align 2
-init_sr:
- .long 0x007f0000 /* Supervisor mode, everything masked */
-stack_addr:
- .long init_thread_union
kernel_start_addr:
.long start_kernel
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 141/152] avr32: fix out-of-range jump in large kernels
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (139 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 140/152] avr32: setup crt for early panic() Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 142/152] ALSA: hda - Fix unbalanced runtime PM notification at resume Kamal Mostafa
` (10 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Andreas Bießmann, Haavard Skinnemoen, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: =?UTF-8?q?Andreas=20Bie=C3=9Fmann?= <andreas@biessmann.de>
commit d617b338bbfdd77e9cbd8e7dc949cee3dd73d575 upstream.
This patch fixes following error (for big kernels):
---8<---
arch/avr32/boot/u-boot/head.o: In function `no_tag_table':
(.init.text+0x44): relocation truncated to fit: R_AVR32_22H_PCREL against symbol `panic' defined in .text.unlikely section in kernel/built-in.o
arch/avr32/kernel/built-in.o: In function `bad_return':
(.ex.text+0x236): relocation truncated to fit: R_AVR32_22H_PCREL against symbol `panic' defined in .text.unlikely section in kernel/built-in.o
--->8---
It comes up when the kernel increases and 'panic()' is too far away to fit in
the +/- 2MiB range. Which in turn issues from the 21-bit displacement in
'br{cond4}' mnemonic which is one of the two ways to do jumps (rjmp has just
10-bit displacement and therefore a way smaller range). This fact was stated
before in 8d29b7b9f81d6b83d869ff054e6c189d6da73f1f.
One solution to solve this is to add a local storage for the symbol address
and just load the $pc with that value.
Signed-off-by: Andreas Bießmann <andreas@biessmann.de>
Acked-by: Hans-Christian Egtvedt <egtvedt@samfundet.no>
Cc: Haavard Skinnemoen <hskinnemoen@gmail.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/avr32/boot/u-boot/head.S | 5 ++++-
arch/avr32/kernel/entry-avr32b.S | 3 ++-
2 files changed, 6 insertions(+), 2 deletions(-)
diff --git a/arch/avr32/boot/u-boot/head.S b/arch/avr32/boot/u-boot/head.S
index d36d865..2ffc298 100644
--- a/arch/avr32/boot/u-boot/head.S
+++ b/arch/avr32/boot/u-boot/head.S
@@ -73,8 +73,11 @@ init_sr:
.long 0x007f0000 /* Supervisor mode, everything masked */
stack_addr:
.long init_thread_union
+panic_addr:
+ .long panic
no_tag_table:
sub r12, pc, (. - 2f)
- bral panic
+ /* branch to panic() which can be far away with that construct */
+ lddpc pc, panic_addr
2: .asciz "Boot loader didn't provide correct magic number\n"
diff --git a/arch/avr32/kernel/entry-avr32b.S b/arch/avr32/kernel/entry-avr32b.S
index 9899d3c..7301f48 100644
--- a/arch/avr32/kernel/entry-avr32b.S
+++ b/arch/avr32/kernel/entry-avr32b.S
@@ -401,9 +401,10 @@ handle_critical:
/* We should never get here... */
bad_return:
sub r12, pc, (. - 1f)
- bral panic
+ lddpc pc, 2f
.align 2
1: .asciz "Return from critical exception!"
+2: .long panic
.align 1
do_bus_error_write:
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 142/152] ALSA: hda - Fix unbalanced runtime PM notification at resume
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (140 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 141/152] avr32: fix out-of-range jump in large kernels Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 143/152] PCI: Remove duplicate pci_disable_device() from pcie_portdrv_remove() Kamal Mostafa
` (9 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Takashi Iwai, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit 0fc28fc030a85aa3d6d14e9e9fca0c8237c9ffb5 upstream.
When a codec is resumed, it keeps the power on while the resuming
phase via hda_keep_power_on(), then turns down via
snd_hda_power_down(). At that point, snd_hda_power_down() notifies
the power down to the controller, and this may confuse the refcount if
the codec was already powered up before the resume.
In the end result, the controller goes to runtime suspend even before
the codec is kicked off to the power save, and the communication
stalls happens.
The fix is to add the power-up notification together with
hda_keep_power_on(), and clears the flag appropriately.
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/pci/hda/hda_codec.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/sound/pci/hda/hda_codec.c b/sound/pci/hda/hda_codec.c
index 3f242b5..b542636 100644
--- a/sound/pci/hda/hda_codec.c
+++ b/sound/pci/hda/hda_codec.c
@@ -3650,6 +3650,10 @@ static void hda_call_codec_resume(struct hda_codec *codec)
* in the resume / power-save sequence
*/
hda_keep_power_on(codec);
+ if (codec->pm_down_notified) {
+ codec->pm_down_notified = 0;
+ hda_call_pm_notify(codec->bus, true);
+ }
hda_set_power_state(codec, AC_PWRST_D0);
restore_shutup_pins(codec);
hda_exec_init_verbs(codec);
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 143/152] PCI: Remove duplicate pci_disable_device() from pcie_portdrv_remove()
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (141 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 142/152] ALSA: hda - Fix unbalanced runtime PM notification at resume Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 144/152] powerpc/pseries: Duplicate dtl entries sometimes sent to userspace Kamal Mostafa
` (8 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Yinghai Lu, Bjorn Helgaas, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Yinghai Lu <yinghai@kernel.org>
commit e7cc5cf74544d97d7b69e2701595037474db1f96 upstream.
The pcie_portdrv .probe() method calls pci_enable_device() once, in
pcie_port_device_register(), but the .remove() method calls
pci_disable_device() twice, in pcie_port_device_remove() and in
pcie_portdrv_remove().
That causes a "disabling already-disabled device" warning when removing a
PCIe port device. This happens all the time when removing Thunderbolt
devices, but is also easy to reproduce with, e.g.,
"echo 0000:00:1c.3 > /sys/bus/pci/drivers/pcieport/unbind"
This patch removes the disable from pcie_portdrv_remove().
[bhelgaas: changelog, tag for stable]
Reported-by: David Bulkow <David.Bulkow@stratus.com>
Reported-by: Mika Westerberg <mika.westerberg@linux.intel.com>
Signed-off-by: Yinghai Lu <yinghai@kernel.org>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/pci/pcie/portdrv_pci.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/pci/pcie/portdrv_pci.c b/drivers/pci/pcie/portdrv_pci.c
index ed4d094..2ca1a0b 100644
--- a/drivers/pci/pcie/portdrv_pci.c
+++ b/drivers/pci/pcie/portdrv_pci.c
@@ -223,7 +223,6 @@ static int pcie_portdrv_probe(struct pci_dev *dev,
static void pcie_portdrv_remove(struct pci_dev *dev)
{
pcie_port_device_remove(dev);
- pci_disable_device(dev);
}
static int error_detected_iter(struct device *device, void *data)
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 144/152] powerpc/pseries: Duplicate dtl entries sometimes sent to userspace
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (142 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 143/152] PCI: Remove duplicate pci_disable_device() from pcie_portdrv_remove() Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 145/152] powerpc/signals: Mark VSX not saved with small contexts Kamal Mostafa
` (7 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Anton Blanchard, Benjamin Herrenschmidt, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Anton Blanchard <anton@samba.org>
commit 84b073868b9d9e754ae48b828337633d1b386482 upstream.
When reading from the dispatch trace log (dtl) userspace interface, I
sometimes see duplicate entries. One example:
00000000 07 04 00 0c 00 00 48 44 00 00 00 00 00 00 00 00
00000010 00 0c a0 b4 16 83 6d 68 00 00 00 00 00 00 00 00
00000020 00 00 00 00 10 00 13 50 80 00 00 00 00 00 d0 32
00000030 07 04 00 0c 00 00 48 44 00 00 00 00 00 00 00 00
00000040 00 0c a0 b4 16 83 6d 68 00 00 00 00 00 00 00 00
00000050 00 00 00 00 10 00 13 50 80 00 00 00 00 00 d0 32
The problem is in scan_dispatch_log() where we call dtl_consumer()
but bail out before incrementing the index.
To fix this I moved dtl_consumer() after the timebase comparison.
Signed-off-by: Anton Blanchard <anton@samba.org>
Signed-off-by: Benjamin Herrenschmidt <benh@kernel.crashing.org>
[ kamal: backport to 3.8 (context) ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/powerpc/kernel/time.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/powerpc/kernel/time.c b/arch/powerpc/kernel/time.c
index 127361e..b89c2ee 100644
--- a/arch/powerpc/kernel/time.c
+++ b/arch/powerpc/kernel/time.c
@@ -213,8 +213,6 @@ static u64 scan_dispatch_log(u64 stop_tb)
if (i == vpa->dtl_idx)
return 0;
while (i < vpa->dtl_idx) {
- if (dtl_consumer)
- dtl_consumer(dtl, i);
dtb = dtl->timebase;
tb_delta = dtl->enqueue_to_dispatch_time +
dtl->ready_to_enqueue_time;
@@ -227,6 +225,8 @@ static u64 scan_dispatch_log(u64 stop_tb)
}
if (dtb > stop_tb)
break;
+ if (dtl_consumer)
+ dtl_consumer(dtl, i);
stolen += tb_delta;
++i;
++dtl;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 145/152] powerpc/signals: Mark VSX not saved with small contexts
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (143 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 144/152] powerpc/pseries: Duplicate dtl entries sometimes sent to userspace Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 146/152] iscsi-target: fix extract_param to handle buffer length corner case Kamal Mostafa
` (6 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Michael Neuling, Benjamin Herrenschmidt, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Neuling <mikey@neuling.org>
commit c13f20ac48328b05cd3b8c19e31ed6c132b44b42 upstream.
The VSX MSR bit in the user context indicates if the context contains VSX
state. Currently we set this when the process has touched VSX at any stage.
Unfortunately, if the user has not provided enough space to save the VSX state,
we can't save it but we currently still set the MSR VSX bit.
This patch changes this to clear the MSR VSX bit when the user doesn't provide
enough space. This indicates that there is no valid VSX state in the user
context.
This is needed to support get/set/make/swapcontext for applications that use
VSX but only provide a small context. For example, getcontext in glibc
provides a smaller context since the VSX registers don't need to be saved over
the glibc function call. But since the program calling getcontext may have
used VSX, the kernel currently says the VSX state is valid when it's not. If
the returned context is then used in setcontext (ie. a small context without
VSX but with MSR VSX set), the kernel will refuse the context. This situation
has been reported by the glibc community.
Based on patch from Carlos O'Donell.
Tested-by: Haren Myneni <haren@linux.vnet.ibm.com>
Signed-off-by: Michael Neuling <mikey@neuling.org>
Signed-off-by: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
arch/powerpc/kernel/signal_32.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
diff --git a/arch/powerpc/kernel/signal_32.c b/arch/powerpc/kernel/signal_32.c
index 804e323..d344c036 100644
--- a/arch/powerpc/kernel/signal_32.c
+++ b/arch/powerpc/kernel/signal_32.c
@@ -449,7 +449,15 @@ static int save_user_regs(struct pt_regs *regs, struct mcontext __user *frame,
if (copy_vsx_to_user(&frame->mc_vsregs, current))
return 1;
msr |= MSR_VSX;
- }
+ } else if (!ctx_has_vsx_region)
+ /*
+ * With a small context structure we can't hold the VSX
+ * registers, hence clear the MSR value to indicate the state
+ * was not saved.
+ */
+ msr &= ~MSR_VSX;
+
+
#endif /* CONFIG_VSX */
#ifdef CONFIG_SPE
/* save spe registers */
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 146/152] iscsi-target: fix extract_param to handle buffer length corner case
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (144 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 145/152] powerpc/signals: Mark VSX not saved with small contexts Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 147/152] iscsi-target: chap auth shouldn't match username with trailing garbage Kamal Mostafa
` (5 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Eric Seppanen, Nicholas Bellinger, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Seppanen <eric@purestorage.com>
commit 369653e4fb511928511b0ce81f41c812ff1f28b6 upstream.
extract_param() is called with max_length set to the total size of the
output buffer. It's not safe to allow a parameter length equal to the
buffer size as the terminating null would be written one byte past the
end of the output buffer.
Signed-off-by: Eric Seppanen <eric@purestorage.com>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/target/iscsi/iscsi_target_nego.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/target/iscsi/iscsi_target_nego.c b/drivers/target/iscsi/iscsi_target_nego.c
index 9d902ae..c7f68b3 100644
--- a/drivers/target/iscsi/iscsi_target_nego.c
+++ b/drivers/target/iscsi/iscsi_target_nego.c
@@ -89,7 +89,7 @@ int extract_param(
if (len < 0)
return -1;
- if (len > max_length) {
+ if (len >= max_length) {
pr_err("Length of input: %d exceeds max_length:"
" %d\n", len, max_length);
return -1;
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 147/152] iscsi-target: chap auth shouldn't match username with trailing garbage
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (145 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 146/152] iscsi-target: fix extract_param to handle buffer length corner case Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 148/152] ALSA: hda - Fix the headphone jack detection on Sony VAIO TX Kamal Mostafa
` (4 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Eric Seppanen, Nicholas Bellinger, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Seppanen <eric@purestorage.com>
commit 86784c6bdeeef78eed94d298be7a8879f6a97ee2 upstream.
In iSCSI negotiations with initiator CHAP enabled, usernames with
trailing garbage are permitted, because the string comparison only
checks the strlen of the configured username.
e.g. "usernameXXXXX" will be permitted to match "username".
Just check one more byte so the trailing null char is also matched.
Signed-off-by: Eric Seppanen <eric@purestorage.com>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/target/iscsi/iscsi_target_auth.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/target/iscsi/iscsi_target_auth.c b/drivers/target/iscsi/iscsi_target_auth.c
index a0fc7b9..b54f6ec 100644
--- a/drivers/target/iscsi/iscsi_target_auth.c
+++ b/drivers/target/iscsi/iscsi_target_auth.c
@@ -174,6 +174,7 @@ static int chap_server_compute_md5(
unsigned char client_digest[MD5_SIGNATURE_SIZE];
unsigned char server_digest[MD5_SIGNATURE_SIZE];
unsigned char chap_n[MAX_CHAP_N_SIZE], chap_r[MAX_RESPONSE_LENGTH];
+ size_t compare_len;
struct iscsi_chap *chap = conn->auth_protocol;
struct crypto_hash *tfm;
struct hash_desc desc;
@@ -212,7 +213,9 @@ static int chap_server_compute_md5(
goto out;
}
- if (memcmp(chap_n, auth->userid, strlen(auth->userid)) != 0) {
+ /* Include the terminating NULL in the compare */
+ compare_len = strlen(auth->userid) + 1;
+ if (strncmp(chap_n, auth->userid, compare_len) != 0) {
pr_err("CHAP_N values do not match!\n");
goto out;
}
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 148/152] ALSA: hda - Fix the headphone jack detection on Sony VAIO TX
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (146 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 147/152] iscsi-target: chap auth shouldn't match username with trailing garbage Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 149/152] configfs: fix race between dentry put and lookup Kamal Mostafa
` (3 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Takashi Iwai, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit 0f5a5b8515472a0219768423226b58228001e3d5 upstream.
BIOS sets MISC_NO_PRESENCE bit wrongly to the pin config on NID 0x0f.
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/pci/hda/patch_realtek.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index a9a177a..c6c9e58 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -4970,6 +4970,7 @@ static const struct snd_pci_quirk alc260_fixup_tbl[] = {
SND_PCI_QUIRK(0x1025, 0x008f, "Acer", ALC260_FIXUP_GPIO1),
SND_PCI_QUIRK(0x103c, 0x280a, "HP dc5750", ALC260_FIXUP_HP_DC5750),
SND_PCI_QUIRK(0x103c, 0x30ba, "HP Presario B1900", ALC260_FIXUP_HP_B1900),
+ SND_PCI_QUIRK(0x104d, 0x81e2, "Sony VAIO TX", ALC260_FIXUP_HP_PIN_0F),
SND_PCI_QUIRK(0x1509, 0x4540, "Favorit 100XS", ALC260_FIXUP_GPIO1),
SND_PCI_QUIRK(0x152d, 0x0729, "Quanta KN1", ALC260_FIXUP_KN1),
SND_PCI_QUIRK(0x161f, 0x2057, "Replacer 672V", ALC260_FIXUP_REPLACER),
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 149/152] configfs: fix race between dentry put and lookup
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (147 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 148/152] ALSA: hda - Fix the headphone jack detection on Sony VAIO TX Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 150/152] ALSA: hda - Provide missing pin configs for VAIO with ALC260 Kamal Mostafa
` (2 subsequent siblings)
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Junxiao Bi, Joel Becker, Al Viro, Andrew Morton, Linus Torvalds,
Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Junxiao Bi <junxiao.bi@oracle.com>
commit 76ae281f6307331aa063288edb6422ae99f435f0 upstream.
A race window in configfs, it starts from one dentry is UNHASHED and end
before configfs_d_iput is called. In this window, if a lookup happen,
since the original dentry was UNHASHED, so a new dentry will be
allocated, and then in configfs_attach_attr(), sd->s_dentry will be
updated to the new dentry. Then in configfs_d_iput(),
BUG_ON(sd->s_dentry != dentry) will be triggered and system panic.
sys_open: sys_close:
... fput
dput
dentry_kill
__d_drop <--- dentry unhashed here,
but sd->dentry still point
to this dentry.
lookup_real
configfs_lookup
configfs_attach_attr---> update sd->s_dentry
to new allocated dentry here.
d_kill
configfs_d_iput <--- BUG_ON(sd->s_dentry != dentry)
triggered here.
To fix it, change configfs_d_iput to not update sd->s_dentry if
sd->s_count > 2, that means there are another dentry is using the sd
beside the one that is going to be put. Use configfs_dirent_lock in
configfs_attach_attr to sync with configfs_d_iput.
With the following steps, you can reproduce the bug.
1. enable ocfs2, this will mount configfs at /sys/kernel/config and
fill configure in it.
2. run the following script.
while [ 1 ]; do cat /sys/kernel/config/cluster/$your_cluster_name/idle_timeout_ms > /dev/null; done &
while [ 1 ]; do cat /sys/kernel/config/cluster/$your_cluster_name/idle_timeout_ms > /dev/null; done &
Signed-off-by: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
fs/configfs/dir.c | 16 ++++++++++++++--
1 file changed, 14 insertions(+), 2 deletions(-)
diff --git a/fs/configfs/dir.c b/fs/configfs/dir.c
index 712b10f..76bb46a 100644
--- a/fs/configfs/dir.c
+++ b/fs/configfs/dir.c
@@ -56,10 +56,19 @@ static void configfs_d_iput(struct dentry * dentry,
struct configfs_dirent *sd = dentry->d_fsdata;
if (sd) {
- BUG_ON(sd->s_dentry != dentry);
/* Coordinate with configfs_readdir */
spin_lock(&configfs_dirent_lock);
- sd->s_dentry = NULL;
+ /* Coordinate with configfs_attach_attr where will increase
+ * sd->s_count and update sd->s_dentry to new allocated one.
+ * Only set sd->dentry to null when this dentry is the only
+ * sd owner.
+ * If not do so, configfs_d_iput may run just after
+ * configfs_attach_attr and set sd->s_dentry to null
+ * even it's still in use.
+ */
+ if (atomic_read(&sd->s_count) <= 2)
+ sd->s_dentry = NULL;
+
spin_unlock(&configfs_dirent_lock);
configfs_put(sd);
}
@@ -426,8 +435,11 @@ static int configfs_attach_attr(struct configfs_dirent * sd, struct dentry * den
struct configfs_attribute * attr = sd->s_element;
int error;
+ spin_lock(&configfs_dirent_lock);
dentry->d_fsdata = configfs_get(sd);
sd->s_dentry = dentry;
+ spin_unlock(&configfs_dirent_lock);
+
error = configfs_create(dentry, (attr->ca_mode & S_IALLUGO) | S_IFREG,
configfs_init_file);
if (error) {
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 150/152] ALSA: hda - Provide missing pin configs for VAIO with ALC260
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (148 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 149/152] configfs: fix race between dentry put and lookup Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 151/152] KVM: Fix iommu map/unmap to handle memory slot moves Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 152/152] libertas: potential oops in debugfs Kamal Mostafa
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team; +Cc: Takashi Iwai, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit d08c5ef2a039393eaf2ab2152db5f07790fa0f40 upstream.
Some models (or maybe depending on BIOS version) of Sony VAIO with
ALC260 give no proper pin configurations as default, resulting in the
non-working speaker, etc. Just provide the whole pin configurations
via a fixup.
Reported-by: Matthew Markus <mmarkus@hearit.co>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
sound/pci/hda/patch_realtek.c | 20 ++++++++++++++++++++
1 file changed, 20 insertions(+)
diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index c6c9e58..876948f 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -4850,6 +4850,7 @@ enum {
ALC260_FIXUP_REPLACER,
ALC260_FIXUP_HP_B1900,
ALC260_FIXUP_KN1,
+ ALC260_FIXUP_VAIO_PINS,
};
static void alc260_gpio1_automute(struct hda_codec *codec)
@@ -4962,6 +4963,24 @@ static const struct alc_fixup alc260_fixups[] = {
.type = ALC_FIXUP_FUNC,
.v.func = alc260_fixup_kn1,
},
+ [ALC260_FIXUP_VAIO_PINS] = {
+ .type = HDA_FIXUP_PINS,
+ .v.pins = (const struct hda_pintbl[]) {
+ /* Pin configs are missing completely on some VAIOs */
+ { 0x0f, 0x01211020 },
+ { 0x10, 0x0001003f },
+ { 0x11, 0x411111f0 },
+ { 0x12, 0x01a15930 },
+ { 0x13, 0x411111f0 },
+ { 0x14, 0x411111f0 },
+ { 0x15, 0x411111f0 },
+ { 0x16, 0x411111f0 },
+ { 0x17, 0x411111f0 },
+ { 0x18, 0x411111f0 },
+ { 0x19, 0x411111f0 },
+ { }
+ }
+ },
};
static const struct snd_pci_quirk alc260_fixup_tbl[] = {
@@ -4970,6 +4989,7 @@ static const struct snd_pci_quirk alc260_fixup_tbl[] = {
SND_PCI_QUIRK(0x1025, 0x008f, "Acer", ALC260_FIXUP_GPIO1),
SND_PCI_QUIRK(0x103c, 0x280a, "HP dc5750", ALC260_FIXUP_HP_DC5750),
SND_PCI_QUIRK(0x103c, 0x30ba, "HP Presario B1900", ALC260_FIXUP_HP_B1900),
+ SND_PCI_QUIRK(0x104d, 0x81bb, "Sony VAIO", ALC260_FIXUP_VAIO_PINS),
SND_PCI_QUIRK(0x104d, 0x81e2, "Sony VAIO TX", ALC260_FIXUP_HP_PIN_0F),
SND_PCI_QUIRK(0x1509, 0x4540, "Favorit 100XS", ALC260_FIXUP_GPIO1),
SND_PCI_QUIRK(0x152d, 0x0729, "Quanta KN1", ALC260_FIXUP_KN1),
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 151/152] KVM: Fix iommu map/unmap to handle memory slot moves
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (149 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 150/152] ALSA: hda - Provide missing pin configs for VAIO with ALC260 Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 152/152] libertas: potential oops in debugfs Kamal Mostafa
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Alex Williamson, Marcelo Tosatti, Luis Henriques, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Williamson <alex.williamson@redhat.com>
commit e40f193f5bb022e927a57a4f5d5194e4f12ddb74 upstream.
The iommu integration into memory slots expects memory slots to be
added or removed and doesn't handle the move case. We can unmap
slots from the iommu after we mark them invalid and map them before
installing the final memslot array. Also re-order the kmemdup vs
map so we don't leave iommu mappings if we get ENOMEM.
Reviewed-by: Gleb Natapov <gleb@redhat.com>
Signed-off-by: Alex Williamson <alex.williamson@redhat.com>
Signed-off-by: Marcelo Tosatti <mtosatti@redhat.com>
[ kamal: 3.8 stable for CVE-2013-4592 ]
Cc: Luis Henriques <luis.henriques@canonical.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
virt/kvm/kvm_main.c | 19 +++++++++++--------
1 file changed, 11 insertions(+), 8 deletions(-)
diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c
index 10afa34..4dc41654 100644
--- a/virt/kvm/kvm_main.c
+++ b/virt/kvm/kvm_main.c
@@ -811,6 +811,8 @@ int __kvm_set_memory_region(struct kvm *kvm,
old_memslots = kvm->memslots;
rcu_assign_pointer(kvm->memslots, slots);
synchronize_srcu_expedited(&kvm->srcu);
+ /* slot was deleted or moved, clear iommu mapping */
+ kvm_iommu_unmap_pages(kvm, &old);
/* From this point no new shadow pages pointing to a deleted,
* or moved, memslot will be created.
*
@@ -826,20 +828,19 @@ int __kvm_set_memory_region(struct kvm *kvm,
if (r)
goto out_free;
- /* map/unmap the pages in iommu page table */
- if (npages) {
- r = kvm_iommu_map_pages(kvm, &new);
- if (r)
- goto out_free;
- } else
- kvm_iommu_unmap_pages(kvm, &old);
-
r = -ENOMEM;
slots = kmemdup(kvm->memslots, sizeof(struct kvm_memslots),
GFP_KERNEL);
if (!slots)
goto out_free;
+ /* map new memory slot into the iommu */
+ if (npages) {
+ r = kvm_iommu_map_pages(kvm, &new);
+ if (r)
+ goto out_slots;
+ }
+
/* actual memory is freed via old in kvm_free_physmem_slot below */
if (!npages) {
new.dirty_bitmap = NULL;
@@ -858,6 +859,8 @@ int __kvm_set_memory_region(struct kvm *kvm,
return 0;
+out_slots:
+ kfree(slots);
out_free:
kvm_free_physmem_slot(&new, &old);
out:
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* [PATCH 3.8 152/152] libertas: potential oops in debugfs
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
` (150 preceding siblings ...)
2013-12-06 23:11 ` [PATCH 3.8 151/152] KVM: Fix iommu map/unmap to handle memory slot moves Kamal Mostafa
@ 2013-12-06 23:11 ` Kamal Mostafa
151 siblings, 0 replies; 154+ messages in thread
From: Kamal Mostafa @ 2013-12-06 23:11 UTC (permalink / raw)
To: linux-kernel, stable, kernel-team
Cc: Dan Carpenter, John W. Linville, Luis Henriques, Kamal Mostafa
3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
------------------
From: Dan Carpenter <dan.carpenter@oracle.com>
commit a497e47d4aec37aaf8f13509f3ef3d1f6a717d88 upstream.
If we do a zero size allocation then it will oops. Also we can't be
sure the user passes us a NUL terminated string so I've added a
terminator.
This code can only be triggered by root.
Reported-by: Nico Golde <nico@ngolde.de>
Reported-by: Fabian Yamaguchi <fabs@goesec.de>
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Acked-by: Dan Williams <dcbw@redhat.com>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
[ kamal: 3.8 stable for CVE-2013-6378 ]
Cc: Luis Henriques <luis.henriques@canonical.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
drivers/net/wireless/libertas/debugfs.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/libertas/debugfs.c b/drivers/net/wireless/libertas/debugfs.c
index 668dd27..cc6a0a5 100644
--- a/drivers/net/wireless/libertas/debugfs.c
+++ b/drivers/net/wireless/libertas/debugfs.c
@@ -913,7 +913,10 @@ static ssize_t lbs_debugfs_write(struct file *f, const char __user *buf,
char *p2;
struct debug_data *d = f->private_data;
- pdata = kmalloc(cnt, GFP_KERNEL);
+ if (cnt == 0)
+ return 0;
+
+ pdata = kmalloc(cnt + 1, GFP_KERNEL);
if (pdata == NULL)
return 0;
@@ -922,6 +925,7 @@ static ssize_t lbs_debugfs_write(struct file *f, const char __user *buf,
kfree(pdata);
return 0;
}
+ pdata[cnt] = '\0';
p0 = pdata;
for (i = 0; i < num_of_items; i++) {
--
1.8.3.2
^ permalink raw reply [flat|nested] 154+ messages in thread
* Re: [PATCH 3.8 003/152] cxgb3: Fix length calculation in write_ofld_wr() on 32-bit architectures
2013-12-06 23:08 ` [PATCH 3.8 003/152] cxgb3: Fix length calculation in write_ofld_wr() on 32-bit architectures Kamal Mostafa
@ 2013-12-07 0:10 ` Ben Hutchings
0 siblings, 0 replies; 154+ messages in thread
From: Ben Hutchings @ 2013-12-07 0:10 UTC (permalink / raw)
To: Kamal Mostafa; +Cc: linux-kernel, stable, kernel-team, David S. Miller
On Fri, Dec 06, 2013 at 03:08:47PM -0800, Kamal Mostafa wrote:
> 3.8.13.14 -stable review patch. If anyone has any objections, please let me know.
>
> ------------------
>
> From: Ben Hutchings <ben@decadent.org.uk>
>
> [ Upstream commit 262e827fe745642589450ae241b7afd3912c3f25 ]
>
> The length calculation here is now invalid on 32-bit architectures,
> since sk_buff::tail is a pointer and sk_buff::transport_header is
> an integer offset:
>
> drivers/net/ethernet/chelsio/cxgb3/sge.c: In function 'write_ofld_wr':
> drivers/net/ethernet/chelsio/cxgb3/sge.c:1603:9: warning: passing argument 4 of 'make_sgl' makes integer from pointer without a cast [enabled by default]
> adap->pdev);
> ^
> drivers/net/ethernet/chelsio/cxgb3/sge.c:964:28: note: expected 'unsigned int' but argument is of type 'sk_buff_data_t'
> static inline unsigned int make_sgl(const struct sk_buff *skb,
> ^
>
> Use the appropriate skb accessor functions.
>
> Compile-tested only.
>
> Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
> Fixes: 1a37e412a022 ('net: Use 16bits for *_headers fields of struct skbuff')
[...]
This is only needed for 3.11+, though it should be harmless for
older versions.
Ben.
--
Ben Hutchings
Design a system any fool can use, and only a fool will want to use it.
^ permalink raw reply [flat|nested] 154+ messages in thread
end of thread, other threads:[~2013-12-07 0:10 UTC | newest]
Thread overview: 154+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2013-12-06 23:08 [3.8.y.z extended stable] Linux 3.8.13.14 stable review Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 001/152] ipv6: ip6_dst_check needs to check for expired dst_entries Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 002/152] ipv6: reset dst.expires value when clearing expire flag Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 003/152] cxgb3: Fix length calculation in write_ofld_wr() on 32-bit architectures Kamal Mostafa
2013-12-07 0:10 ` Ben Hutchings
2013-12-06 23:08 ` [PATCH 3.8 004/152] xen-netback: use jiffies_64 value to calculate credit timeout Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 005/152] virtio-net: correctly handle cpu hotplug notifier during resuming Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 006/152] net: flow_dissector: fail on evil iph->ihl Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 007/152] X.509: Remove certificate date checks Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 008/152] selinux: correct locking in selinux_netlbl_socket_connect) Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 009/152] NFSv4: Fix a use-after-free situation in _nfs4_proc_getlk() Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 010/152] usb: musb: cancel work on removal Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 011/152] USB: mos7840: fix tiocmget error handling Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 012/152] pinctrl: dove: unset twsi option3 for gconfig as well Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 013/152] usb: Disable USB 2.0 Link PM before device reset Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 014/152] usb: hub: Clear Port Reset Change during init/resume Kamal Mostafa
2013-12-06 23:08 ` [PATCH 3.8 015/152] rt2400pci: fix RSSI read Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 016/152] rt2x00: check if device is still available on rt2x00mac_flush() Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 017/152] rt2800usb: slow down TX status polling Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 018/152] cfg80211: fix scheduled scan pointer access Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 019/152] ARM: OMAP2+: irq, AM33XX add missing register check Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 020/152] ALSA: hda - Add support of new codec ALC233 Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 021/152] ALSA: hda - Add support of ALC255 codecs Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 022/152] USB:add new zte 3g-dongle's pid to option.c Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 023/152] [SCSI] sd: Reduce buffer size for vpd request Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 024/152] Revert "ima: policy for RAMFS" Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 025/152] libata: Fix display of sata speed Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 026/152] ahci: disabled FBS prior to issuing software reset Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 027/152] drivers/libata: Set max sector to 65535 for Slimtype DVD A DS8A9SH drive Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 028/152] NFSv4: fix NULL dereference in open recover Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 029/152] ALSA: 6fire: Fix probe of multiple cards Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 030/152] ARM: sa11x0/assabet: ensure CS2 is configured appropriately Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 031/152] usb: wusbcore: set the RPIPE wMaxPacketSize value correctly Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 032/152] usb: wusbcore: change WA_SEGS_MAX to a legal value Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 033/152] powerpc/vio: use strcpy in modalias_show Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 034/152] i2c: mux: gpio: use gpio_set_value_cansleep() Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 035/152] i2c: mux: gpio: use reg value for i2c_add_mux_adapter Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 036/152] s390/vtime: correct idle time calculation Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 037/152] dm: allocate buffer for messages with small number of arguments using GFP_NOIO Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 038/152] can: c_can: Fix RX message handling, handle lost message before EOB Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 039/152] can: kvaser_usb: fix usb endpoints detection Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 040/152] dm mpath: fix race condition between multipath_dtr and pg_init_done Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 041/152] ext4: avoid bh leak in retry path of ext4_expand_extra_isize_ea() Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 042/152] ASoC: ak4642: prevent un-necessary changes to SG_SL1 Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 043/152] drm/radeon/si: fix define for MC_SEQ_TRAIN_WAKEUP_CNTL Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 044/152] drm/radeon: don't share PPLLs on DCE4.1 Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 045/152] KVM: x86: fix emulation of "movzbl %bpl, %eax" Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 046/152] ALSA: hda - Enable SPDIF for Acer TravelMate 6293 Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 047/152] ahci: Add Device IDs for Intel Wildcat Point-LP Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 048/152] edac, highbank: Fix interrupt setup of mem and l2 controller Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 049/152] KVM: IOMMU: hva align mapping page size Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 050/152] audit: printk USER_AVC messages when audit isn't enabled Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 051/152] audit: fix info leak in AUDIT_GET requests Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 052/152] audit: use nlmsg_len() to get message payload length Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 053/152] ALSA - HDA: New PCI ID for Haswell ULT Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 054/152] ALSA: hda - Force buffer alignment for Haswell HDMI controllers Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 055/152] ftrace/x86: skip over the breakpoint for ftrace caller Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 056/152] drm: shmobile: Add dependency on BACKLIGHT_CLASS_DEVICE Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 057/152] powerpc/powernv: Add PE to its own PELTV Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 058/152] drm/ttm: Handle in-memory region copies Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 059/152] drm/ttm: Fix ttm_bo_move_memcpy Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 060/152] drm/ttm: Fix memory type compatibility check Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 061/152] perf/ftrace: Fix paranoid level for enabling function tracer Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 062/152] ARM: entry: move IRQ tracing exit into svc_exit Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 063/152] ARM: entry: move disable_irq_notrace " Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 064/152] ARM: 7876/1: clear Thumb-2 IT state on exception handling Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 065/152] PM / hibernate: Avoid overflow in hibernate_preallocate_memory() Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 066/152] ALSA: hda - Add support for CX20952 Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 067/152] ALSA: hda - Add pincfg fixup for ASUS W5A Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 068/152] mtd: nand: hack ONFI for non-power-of-2 dimensions Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 069/152] mtd: map: fixed bug in 64-bit systems Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 070/152] mtd: m25p80: fix allocation size Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 071/152] qeth: avoid buffer overflow in snmp ioctl Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 072/152] x86/ioapic/kcrash: Prevent crash_kexec() from deadlocking on ioapic_lock Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 073/152] x86/apic: Disable I/O APIC before shutdown of the local APIC Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 074/152] parisc: sticon - unbreak on 64bit kernel Kamal Mostafa
2013-12-06 23:09 ` [PATCH 3.8 075/152] block: fix race between request completion and timeout handling Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 076/152] blk-core: Fix memory corruption if blkcg_init_queue fails Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 077/152] loop: fix crash if blk_alloc_queue fails Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 078/152] block: fix a probe argument to blk_register_region Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 079/152] block: properly stack underlying max_segment_size to DM device Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 080/152] xen/blkback: fix reference counting Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 081/152] loop: fix crash when using unassigned loop device Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 082/152] SUNRPC: Fix a data corruption issue when retransmitting RPC calls Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 083/152] IB/ipath: Convert ipath_user_sdma_pin_pages() to use get_user_pages_fast() Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 084/152] IB/qib: Fix txselect regression Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 085/152] IB/srp: Remove target from list before freeing Scsi_Host structure Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 086/152] IB/srp: Avoid offlining operational SCSI devices Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 087/152] IB/srp: Report receive errors correctly Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 088/152] rtlwifi: rtl8192se: Fix wrong assignment Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 089/152] rt2x00: fix HT TX descriptor settings regression Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 090/152] rtlwifi: Fix endian error in extracting packet type Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 091/152] rtlwifi: rtl8192cu: Fix incorrect signal strength for unassociated AP Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 092/152] rtlwifi: rtl8192de: " Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 093/152] mwifiex: correct packet length for packets from SDIO interface Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 094/152] mwifiex: fix wrong eth_hdr usage for bridged packets in AP mode Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 095/152] prism54: set netdev type to "wlan" Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 096/152] ALSA: msnd: Avoid duplicated driver name Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 097/152] x86/microcode/amd: Tone down printk(), don't treat a missing firmware file as an error Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 098/152] SUNRPC: fix races on PipeFS UMOUNT notifications Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 099/152] SUNRPC: Avoid deep recursion in rpc_release_client Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 100/152] cris: media platform drivers: fix build Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 101/152] mm: ensure get_unmapped_area() returns higher address than mmap_min_addr Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 102/152] mm: Only flush TLBs if a transhuge PMD is modified for NUMA pte scanning Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 103/152] mm: numa: return the number of base pages altered by protection changes Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 104/152] vsprintf: check real user/group id for %pK Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 105/152] backlight: atmel-pwm-bl: fix reported brightness Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 106/152] backlight: atmel-pwm-bl: fix gpio polarity in remove Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 107/152] coredump: remove redundant defines for dumpable states Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 108/152] exec/ptrace: fix get_dumpable() incorrect tests Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 109/152] devpts: plug the memory leak in kill_sb Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 110/152] ipc: clamp with min() Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 111/152] ipc: separate msg allocation from userspace copy Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 112/152] ipc: tighten msg copy loops Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 113/152] ipc: set EFAULT as default error in load_msg() Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 114/152] ipc, msg: fix message length check for negative values Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 115/152] drm/vmwgfx: Resource evict fixes Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 116/152] ALSA: hda - Don't clear the power state at snd_hda_codec_reset() Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 117/152] ASoC: blackfin: Fix missing break Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 118/152] target: Fix delayed Task Aborted Status (TAS) handling bug Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 119/152] md: fix calculation of stacking limits on level change Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 120/152] drm/nouveau: when bailing out of a pushbuf ioctl, do not remove previous fence Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 121/152] ASoC: fsl: imx-pcm-fiq: omit fiq counter to avoid harm in unbalanced situations Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 122/152] ALSA: pcsp: Fix the order of input device unregistration Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 123/152] ASoC: wm8962: Turn on regcache_cache_only before disabling regulator Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 124/152] ARM: integrator_cp: Set LCD{0,1} enable lines when turning on CLCD Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 125/152] hwmon: (lm90) Fix max6696 alarm handling Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 126/152] ASoC: cs42l52: Correct MIC CTL mask Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 127/152] ARM: OMAP2+: omap_device: maintain sane runtime pm status around suspend/resume Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 128/152] drm/i915: flush cursors harder Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 129/152] rt2x00: fix a crash bug in the HT descriptor handling fix Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 130/152] rtlwifi: rtl8192cu: Fix more pointer arithmetic errors Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 131/152] radeon/i2c: do not count reg index in number of i2c byte we are writing Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 132/152] radeon: workaround pinning failure on low ram gpu Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 133/152] drm/radeon: add semaphore trace point Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 134/152] ACPI / EC: Ensure lock is acquired before accessing ec struct members Kamal Mostafa
2013-12-06 23:10 ` [PATCH 3.8 135/152] setfacl removes part of ACL when setting POSIX ACLs to Samba Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 136/152] nfsd: split up nfsd_setattr Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 137/152] nfsd: make sure to balance get/put_write_access Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 138/152] ASoC: wm5110: Add post SYSCLK register patch for rev D chip Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 139/152] nfsd4: fix xdr decoding of large non-write compounds Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 140/152] avr32: setup crt for early panic() Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 141/152] avr32: fix out-of-range jump in large kernels Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 142/152] ALSA: hda - Fix unbalanced runtime PM notification at resume Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 143/152] PCI: Remove duplicate pci_disable_device() from pcie_portdrv_remove() Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 144/152] powerpc/pseries: Duplicate dtl entries sometimes sent to userspace Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 145/152] powerpc/signals: Mark VSX not saved with small contexts Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 146/152] iscsi-target: fix extract_param to handle buffer length corner case Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 147/152] iscsi-target: chap auth shouldn't match username with trailing garbage Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 148/152] ALSA: hda - Fix the headphone jack detection on Sony VAIO TX Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 149/152] configfs: fix race between dentry put and lookup Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 150/152] ALSA: hda - Provide missing pin configs for VAIO with ALC260 Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 151/152] KVM: Fix iommu map/unmap to handle memory slot moves Kamal Mostafa
2013-12-06 23:11 ` [PATCH 3.8 152/152] libertas: potential oops in debugfs Kamal Mostafa
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®