mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-kernel@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	stable@vger.kernel.org, Daniel Borkmann <daniel@iogearbox.net>,
	Alexei Starovoitov <ast@kernel.org>,
	"David S. Miller" <davem@davemloft.net>
Subject: [PATCH 4.7 008/184] bpf: fix write helpers with regards to non-linear parts
Date: Thu, 22 Sep 2016 19:39:02 +0200	[thread overview]
Message-ID: <20160922174049.020608243@linuxfoundation.org> (raw)
In-Reply-To: <20160922174048.653794923@linuxfoundation.org>

4.7-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <daniel@iogearbox.net>


[ Upstream commit 0ed661d5a48fa6df0b50ae64d27fe759a3ce42cf ]

Fix the bpf_try_make_writable() helper and all call sites we have in BPF,
it's currently defect with regards to skbs when the write_len spans into
non-linear parts, no matter if cloned or not.

There are multiple issues at once. First, using skb_store_bits() is not
correct since even if we have a cloned skb, page frags can still be shared.
To really make them private, we need to pull them in via __pskb_pull_tail()
first, which also gets us a private head via pskb_expand_head() implicitly.

This is for helpers like bpf_skb_store_bytes(), bpf_l3_csum_replace(),
bpf_l4_csum_replace(). Really, the only thing reasonable and working here
is to call skb_ensure_writable() before any write operation. Meaning, via
pskb_may_pull() it makes sure that parts we want to access are pulled in and
if not does so plus unclones the skb implicitly. If our write_len still fits
the headlen and we're cloned and our header of the clone is not writable,
then we need to make a private copy via pskb_expand_head(). skb_store_bits()
is a bit misleading and only safe to store into non-linear data in different
contexts such as 357b40a18b04 ("[IPV6]: IPV6_CHECKSUM socket option can
corrupt kernel memory").

For above BPF helper functions, it means after fixed bpf_try_make_writable(),
we've pulled in enough, so that we operate always based on skb->data. Thus,
the call to skb_header_pointer() and skb_store_bits() becomes superfluous.
In bpf_skb_store_bytes(), the len check is unnecessary too since it can
only pass in maximum of BPF stack size, so adding offset is guaranteed to
never overflow. Also bpf_l3/4_csum_replace() helpers must test for proper
offset alignment since they use __sum16 pointer for writing resulting csum.

The remaining helpers that change skb data not discussed here yet are
bpf_skb_vlan_push(), bpf_skb_vlan_pop() and bpf_skb_change_proto(). The
vlan helpers internally call either skb_ensure_writable() (pop case) and
skb_cow_head() (push case, for head expansion), respectively. Similarly,
bpf_skb_proto_xlat() takes care to not mangle page frags.

Fixes: 608cd71a9c7c ("tc: bpf: generalize pedit action")
Fixes: 91bc4822c3d6 ("tc: bpf: add checksum helpers")
Fixes: 3697649ff29e ("bpf: try harder on clones when writing into skb")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/core/filter.c |   70 +++++++++++++-----------------------------------------
 1 file changed, 18 insertions(+), 52 deletions(-)

--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -1353,54 +1353,33 @@ static inline int bpf_try_make_writable(
 {
 	int err;
 
-	if (!skb_cloned(skb))
-		return 0;
-	if (skb_clone_writable(skb, write_len))
-		return 0;
-	err = pskb_expand_head(skb, 0, 0, GFP_ATOMIC);
-	if (!err)
-		bpf_compute_data_end(skb);
+	err = skb_ensure_writable(skb, write_len);
+	bpf_compute_data_end(skb);
+
 	return err;
 }
 
 static u64 bpf_skb_store_bytes(u64 r1, u64 r2, u64 r3, u64 r4, u64 flags)
 {
-	struct bpf_scratchpad *sp = this_cpu_ptr(&bpf_sp);
 	struct sk_buff *skb = (struct sk_buff *) (long) r1;
-	int offset = (int) r2;
+	unsigned int offset = (unsigned int) r2;
 	void *from = (void *) (long) r3;
 	unsigned int len = (unsigned int) r4;
 	void *ptr;
 
 	if (unlikely(flags & ~(BPF_F_RECOMPUTE_CSUM | BPF_F_INVALIDATE_HASH)))
 		return -EINVAL;
-
-	/* bpf verifier guarantees that:
-	 * 'from' pointer points to bpf program stack
-	 * 'len' bytes of it were initialized
-	 * 'len' > 0
-	 * 'skb' is a valid pointer to 'struct sk_buff'
-	 *
-	 * so check for invalid 'offset' and too large 'len'
-	 */
-	if (unlikely((u32) offset > 0xffff || len > sizeof(sp->buff)))
+	if (unlikely(offset > 0xffff))
 		return -EFAULT;
 	if (unlikely(bpf_try_make_writable(skb, offset + len)))
 		return -EFAULT;
 
-	ptr = skb_header_pointer(skb, offset, len, sp->buff);
-	if (unlikely(!ptr))
-		return -EFAULT;
-
+	ptr = skb->data + offset;
 	if (flags & BPF_F_RECOMPUTE_CSUM)
 		skb_postpull_rcsum(skb, ptr, len);
 
 	memcpy(ptr, from, len);
 
-	if (ptr == sp->buff)
-		/* skb_store_bits cannot return -EFAULT here */
-		skb_store_bits(skb, offset, ptr, len);
-
 	if (flags & BPF_F_RECOMPUTE_CSUM)
 		skb_postpush_rcsum(skb, ptr, len);
 	if (flags & BPF_F_INVALIDATE_HASH)
@@ -1423,12 +1402,12 @@ static const struct bpf_func_proto bpf_s
 static u64 bpf_skb_load_bytes(u64 r1, u64 r2, u64 r3, u64 r4, u64 r5)
 {
 	const struct sk_buff *skb = (const struct sk_buff *)(unsigned long) r1;
-	int offset = (int) r2;
+	unsigned int offset = (unsigned int) r2;
 	void *to = (void *)(unsigned long) r3;
 	unsigned int len = (unsigned int) r4;
 	void *ptr;
 
-	if (unlikely((u32) offset > 0xffff))
+	if (unlikely(offset > 0xffff))
 		goto err_clear;
 
 	ptr = skb_header_pointer(skb, offset, len, to);
@@ -1456,20 +1435,17 @@ static const struct bpf_func_proto bpf_s
 static u64 bpf_l3_csum_replace(u64 r1, u64 r2, u64 from, u64 to, u64 flags)
 {
 	struct sk_buff *skb = (struct sk_buff *) (long) r1;
-	int offset = (int) r2;
-	__sum16 sum, *ptr;
+	unsigned int offset = (unsigned int) r2;
+	__sum16 *ptr;
 
 	if (unlikely(flags & ~(BPF_F_HDR_FIELD_MASK)))
 		return -EINVAL;
-	if (unlikely((u32) offset > 0xffff))
+	if (unlikely(offset > 0xffff || offset & 1))
 		return -EFAULT;
-	if (unlikely(bpf_try_make_writable(skb, offset + sizeof(sum))))
-		return -EFAULT;
-
-	ptr = skb_header_pointer(skb, offset, sizeof(sum), &sum);
-	if (unlikely(!ptr))
+	if (unlikely(bpf_try_make_writable(skb, offset + sizeof(*ptr))))
 		return -EFAULT;
 
+	ptr = (__sum16 *)(skb->data + offset);
 	switch (flags & BPF_F_HDR_FIELD_MASK) {
 	case 0:
 		if (unlikely(from != 0))
@@ -1487,10 +1463,6 @@ static u64 bpf_l3_csum_replace(u64 r1, u
 		return -EINVAL;
 	}
 
-	if (ptr == &sum)
-		/* skb_store_bits guaranteed to not return -EFAULT here */
-		skb_store_bits(skb, offset, ptr, sizeof(sum));
-
 	return 0;
 }
 
@@ -1510,20 +1482,18 @@ static u64 bpf_l4_csum_replace(u64 r1, u
 	struct sk_buff *skb = (struct sk_buff *) (long) r1;
 	bool is_pseudo = flags & BPF_F_PSEUDO_HDR;
 	bool is_mmzero = flags & BPF_F_MARK_MANGLED_0;
-	int offset = (int) r2;
-	__sum16 sum, *ptr;
+	unsigned int offset = (unsigned int) r2;
+	__sum16 *ptr;
 
 	if (unlikely(flags & ~(BPF_F_MARK_MANGLED_0 | BPF_F_PSEUDO_HDR |
 			       BPF_F_HDR_FIELD_MASK)))
 		return -EINVAL;
-	if (unlikely((u32) offset > 0xffff))
+	if (unlikely(offset > 0xffff || offset & 1))
 		return -EFAULT;
-	if (unlikely(bpf_try_make_writable(skb, offset + sizeof(sum))))
+	if (unlikely(bpf_try_make_writable(skb, offset + sizeof(*ptr))))
 		return -EFAULT;
 
-	ptr = skb_header_pointer(skb, offset, sizeof(sum), &sum);
-	if (unlikely(!ptr))
-		return -EFAULT;
+	ptr = (__sum16 *)(skb->data + offset);
 	if (is_mmzero && !*ptr)
 		return 0;
 
@@ -1546,10 +1516,6 @@ static u64 bpf_l4_csum_replace(u64 r1, u
 
 	if (is_mmzero && !*ptr)
 		*ptr = CSUM_MANGLED_0;
-	if (ptr == &sum)
-		/* skb_store_bits guaranteed to not return -EFAULT here */
-		skb_store_bits(skb, offset, ptr, sizeof(sum));
-
 	return 0;
 }
 

  parent reply	other threads:[~2016-09-22 18:43 UTC|newest]

Thread overview: 182+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <CGME20160922174349uscas1p2c2b016dc9c367dda310785cb703014d2@uscas1p2.samsung.com>
2016-09-22 17:38 ` [PATCH 4.7 000/184] 4.7.5-stable review Greg Kroah-Hartman
2016-09-22 17:38   ` [PATCH 4.7 001/184] clocksource/drivers/sun4i: Clear interrupts after stopping timer in probe function Greg Kroah-Hartman
2016-09-22 17:38   ` [PATCH 4.7 003/184] fscrypto: require write access to mount to set encryption policy Greg Kroah-Hartman
2016-09-22 17:38   ` [PATCH 4.7 004/184] drm/msm: protect against faults from copy_from_user() in submit ioctl Greg Kroah-Hartman
2016-10-03  9:38     ` Vegard Nossum
2016-09-22 17:38   ` [PATCH 4.7 005/184] bpf: fix method of PTR_TO_PACKET reg id generation Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 006/184] ipv4: panic in leaf_walk_rcu due to stale node pointer Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 007/184] vti: flush x-netns xfrm cache when vti interface is removed Greg Kroah-Hartman
2016-09-22 17:39   ` Greg Kroah-Hartman [this message]
2016-09-22 17:39   ` [PATCH 4.7 009/184] net/irda: handle iriap_register_lsap() allocation failure Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 010/184] net/sctp: always initialise sctp_ht_iter::start_fail Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 011/184] net: ipv6: Do not keep IPv6 addresses when IPv6 is disabled Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 012/184] tipc: fix NULL pointer dereference in shutdown() Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 014/184] net/mlx5: Fix pci error recovery flow Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 015/184] net/mlx5: Added missing check of msg length in verifying its signature Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 016/184] net/mlx5e: Use correct flow dissector key on flower offloading Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 017/184] net sched: fix encoding to use real length Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 018/184] udp: fix poll() issue with zero sized packets Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 019/184] tcp: properly scale window in tcp_v[46]_reqsk_send_ack() Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 020/184] sctp: fix overrun in sctp_diag_dump_one() Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 021/184] tun: fix transmit timestamp support Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 022/184] net: dsa: bcm_sf2: Fix race condition while unmasking interrupts Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 023/184] Revert "phy: IRQ cannot be shared" Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 024/184] net: smc91x: fix SMC accesses Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 025/184] bridge: re-introduce fix parsing of MLDv2 reports Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 026/184] kcm: fix a socket double free Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 027/184] bonding: Fix bonding crash Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 028/184] Revert "af_unix: Fix splice-bind deadlock" Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 029/184] af_unix: split u->readlock into two: iolock and bindlock Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 030/184] ipv6: release dst in ping_v6_sendmsg Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 031/184] bnxt_en: Fix TX push operation on ARM64 Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 032/184] ipv6: addrconf: fix dev refcont leak when DAD failed Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 033/184] tcp: fastopen: avoid negative sk_forward_alloc Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 034/184] net/mlx5e: Fix parsing of vlan packets when updating lro header Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 035/184] tcp: cwnd does not increase in TCP YeAH Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 036/184] powerpc/tm: do not use r13 for tabort_syscall Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 037/184] powerpc/powernv : Drop reference added by kset_find_obj() Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 038/184] powerpc: sysdev: cpm: fix gpio save_regs functions Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 039/184] powerpc/mm: Dont alias user region to other regions below PAGE_OFFSET Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 040/184] powerpc/powernv: Fix corrupted PE allocation bitmap on releasing PE Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 041/184] kernfs: dont depend on d_find_any_alias() when generating notifications Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 042/184] pNFS/flexfiles: Fix an Oopsable condition when connection to the DS fails Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 043/184] pNFS: The client must not do I/O to the DS if its lease has expired Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 044/184] NFSv4.1: Fix Oopsable condition in server callback races Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 045/184] NFSv4.x: Fix a refcount leak in nfs_callback_up_net Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 046/184] nfsd: Close race between nfsd4_release_lockowner and nfsd4_lock Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 047/184] pNFS: Ensure LAYOUTGET and LAYOUTRETURN are properly serialised Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 048/184] NFSv4.1: Fix the CREATE_SESSION slot number accounting Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 049/184] kexec: fix double-free when failing to relocate the purgatory Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 050/184] mm, oom: prevent premature OOM killer invocation for high order request Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 051/184] mm, mempolicy: task->mempolicy must be NULL before dropping final reference Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 052/184] ahci: disable correct irq for dummy ports Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 053/184] rapidio/tsi721: fix incorrect detection of address translation condition Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 054/184] mm: introduce get_task_exe_file Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 055/184] audit: fix exe_file access in audit_exe_compare Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 056/184] dm flakey: fix reads to be issued if drop_writes configured Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 057/184] IB/hfi1,IB/qib: Fix qp_stats sleep with rcu read lock held Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 058/184] IB/uverbs: Fix race between uverbs_close and remove_one Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 059/184] IB/hfi1: Reset QSFP on every run through channel tuning Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 060/184] mm: fix cache mode of dax pmd mappings Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 062/184] x86/AMD: Apply erratum 665 on machines without a BIOS fix Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 063/184] KVM: s390: dont use current->thread.fpu.* when accessing registers Greg Kroah-Hartman
2016-09-22 17:39   ` [PATCH 4.7 064/184] kvm-arm: Unmap shadow pagetables properly Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 066/184] iio: accel: kxsd9: Fix raw read return Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 067/184] iio: sw-trigger: Fix config group initialization Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 068/184] iio: proximity: as3935: set up buffer timestamps for non-zero values Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 069/184] iio: adc: rockchip_saradc: reset saradc controller before programming it Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 070/184] iio: adc: ti_am335x_adc: Protect FIFO1 from concurrent access Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 071/184] iio: adc: ti_am335x_adc: Increase timeout value waiting for ADC sample Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 072/184] iio:ti-ads1015: fix a wrong pointer definition Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 073/184] iio: ad799x: Fix buffered capture for ad7991/ad7995/ad7999 Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 074/184] iio: humidity: am2315: set up buffer timestamps for non-zero values Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 075/184] iio: adc: at91: unbreak channel adc channel 3 Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 076/184] iio: humidity: hdc100x: fix sensor data reads of temp and humidity Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 077/184] iio: accel: bmc150: reset chip at init time Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 078/184] iio: fix pressure data output unit in hid-sensor-attributes Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 079/184] iio: accel: kxsd9: Fix scaling bug Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 080/184] iio:core: fix IIO_VAL_FRACTIONAL sign handling Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 081/184] iio: ensure ret is initialized to zero before entering do loop Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 082/184] serial: 8250_mid: fix divide error bug if baud rate is 0 Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 083/184] serial: 8250: added acces i/o products quad and octal serial cards Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 084/184] USB: serial: simple: add support for another Infineon flashloader Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 085/184] usb: gadget: udc: renesas-usb3: clear VBOUT bit in DRD_CON Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 086/184] usb: renesas_usbhs: fix clearing the {BRDY,BEMP}STS condition Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 087/184] usb: chipidea: udc: fix NULL ptr dereference in isr_setup_status_phase Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 088/184] ARM: dts: STiH410: Handle interconnect clock required by EHCI/OHCI (USB) Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 089/184] USB: change bInterval default to 10 ms Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 090/184] devpts: return NULL pts priv entry for non-devpts nodes Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 091/184] cxl: use pcibios_free_controller_deferred() when removing vPHBs Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 092/184] net: thunderx: Fix OOPs with ethtool --register-dump Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 093/184] net: macb: Correct CAPS mask Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 094/184] cpuset: make sure new tasks conform to the current config of the cpuset Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 095/184] arm: dts: rockchip: add reset node for the exist saradc SoCs Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 096/184] ARM: AM43XX: hwmod: Fix RSTST register offset for pruss Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 097/184] ARM: imx6: add missing BM_CLPCR_BYP_MMDC_CH0_LPM_HS setting for imx6ul Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 098/184] ARM: imx6: add missing BM_CLPCR_BYPASS_PMIC_READY setting for imx6sx Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 099/184] ARM: kirkwood: ib62x0: fix size of u-boot environment partition Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 100/184] ARM: OMAP3: hwmod data: Add sysc information for DSI Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 101/184] ARM: dts: kirkwood: Fix PCIe label on OpenRD Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 102/184] ARM: dts: imx6qdl: Fix SPDIF regression Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 103/184] ARM: dts: armada-388-clearfog: number LAN ports properly Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 104/184] ARM: dts: overo: fix gpmc nand cs0 range Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 105/184] ARM: dts: overo: fix gpmc nand on boards with ethernet Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 106/184] ARM: dts: STiH407-family: Provide interconnect clock for consumption in ST SDHCI Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 107/184] bus: arm-ccn: Fix PMU handling of MN Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 108/184] bus: arm-ccn: Do not attempt to configure XPs for cycle counter Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 109/184] bus: arm-ccn: Fix XP watchpoint settings bitmask Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 110/184] dm log writes: fix check of kthread_run() return value Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 111/184] dm crypt: fix free of bad values after tfm allocation failure Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 112/184] dm log writes: move IO accounting earlier to fix error path Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 113/184] dm crypt: fix error with too large bios Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 114/184] pinctrl: pistachio: fix mfio pll_lock pinmux Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 115/184] pinctrl: sunxi: fix uart1 CTS/RTS pins at PG on A23/A33 Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 116/184] memory: omap-gpmc: allow probe of child nodes to fail Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 117/184] arm64: spinlocks: implement smp_mb__before_spinlock() as smp_mb() Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 118/184] crypto: cryptd - initialize child shash_desc on import Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 119/184] Btrfs: remove root_log_ctx from ctx list before btrfs_sync_log returns Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 120/184] fuse: direct-io: dont dirty ITER_BVEC pages Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 121/184] xhci: fix null pointer dereference in stop command timeout function Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 122/184] brcmfmac: avoid potential stack overflow in brcmf_cfg80211_start_ap() Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 123/184] md-cluster: make md-cluster also can work when compiled into kernel Greg Kroah-Hartman
2016-09-22 17:40   ` [PATCH 4.7 124/184] ath9k: fix using sta->drv_priv before initializing it Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 126/184] perf/x86/intel: Fix PEBSv3 record drain Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 127/184] perf/x86/intel/cqm: Check cqm/mbm enabled state in event init Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 128/184] perf/x86/amd: Make HW_CACHE_REFERENCES and HW_CACHE_MISSES measure L2 Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 129/184] perf/x86/intel/pt: Fix an off-by-one in address filter configuration Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 130/184] perf/x86/intel/pt: Fix kernel address filters offset validation Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 131/184] perf/x86/intel/pt: Do validate the size of a kernel address filter Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 132/184] Revert "wext: Fix 32 bit iwpriv compatibility issue with 64 bit Kernel" Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 133/184] sched/core: Fix a race between try_to_wake_up() and a woken up task Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 134/184] ipv6: Dont unset flowi6_proto in ipxip6_tnl_xmit() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 135/184] efi: Make for_each_efi_memory_desc_in_map() cope with running on Xen Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 136/184] efi/libstub: Allocate headspace in efi_get_memory_map() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 137/184] efi/libstub: Introduce ExitBootServices helper Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 138/184] efi/libstub: Use efi_exit_boot_services() in FDT Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 139/184] x86/efi: Use efi_exit_boot_services() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 140/184] powerpc/32: Fix csum_partial_copy_generic() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 141/184] powerpc/32: Fix again csum_partial_copy_generic() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 143/184] kconfig: tinyconfig: provide whole choice blocks to avoid warnings Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 144/184] drm: atmel-hlcdc: Fix vertical scaling Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 146/184] drm: Only use compat ioctl for addfb2 on X86/IA64 Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 147/184] svcauth_gss: Revert 64c59a3726f2 ("Remove unnecessary allocation") Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 148/184] mmc: sdhci-st: Handle interconnect clock Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 149/184] genirq: Provide irq_gc_{lock_irqsave,unlock_irqrestore}() helpers Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 150/184] irqchip/atmel-aic: Fix potential deadlock in ->xlate() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 151/184] fix iov_iter_fault_in_readable() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 152/184] microblaze: fix __get_user() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 153/184] avr32: fix copy_from_user() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 154/184] microblaze: " Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 155/184] fix minor infoleak in get_user_ex() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 156/184] mn10300: failing __get_user() and get_user() should zero Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 157/184] m32r: fix __get_user() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 158/184] sh64: failing __get_user() should zero Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 159/184] nios2: fix __get_user() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 160/184] score: fix __get_user/get_user Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 161/184] s390: get_user() should zero on failure Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 162/184] ARC: uaccess: get_user to zero out dest in cause of fault Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 163/184] asm-generic: make get_user() clear the destination on errors Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 164/184] frv: fix clear_user() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 165/184] cris: buggered copy_from_user/copy_to_user/clear_user Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 166/184] blackfin: fix copy_from_user() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 167/184] score: fix copy_from_user() and friends Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 168/184] sh: fix copy_from_user() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 169/184] sh: cmpxchg: fix a bit shift bug in big_endian os Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 170/184] hexagon: fix strncpy_from_user() error return Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 171/184] mips: copy_from_user() must zero the destination on access_ok() failure Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 172/184] asm-generic: make copy_from_user() zero the destination properly Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 173/184] alpha: fix copy_from_user() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 174/184] metag: copy_from_user() should zero the destination on access_ok() failure Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 175/184] parisc: fix copy_from_user() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 176/184] openrisc: " Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 177/184] nios2: copy_from_user() should zero the tail of destination Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 178/184] mn10300: copy_from_user() should zero on access_ok() failure Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 179/184] sparc32: fix copy_from_user() Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 180/184] ppc32: " Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 181/184] ia64: copy_from_user() should zero the destination on access_ok() failure Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 182/184] iwlegacy: avoid warning about missing braces Greg Kroah-Hartman
2016-09-22 17:41   ` [PATCH 4.7 183/184] genirq/msi: Fix broken debug output Greg Kroah-Hartman
2016-09-22 23:44   ` [PATCH 4.7 000/184] 4.7.5-stable review Guenter Roeck
2016-09-23  8:15     ` Greg Kroah-Hartman
2016-09-23 16:03   ` Shuah Khan
2016-09-23 16:15     ` Greg Kroah-Hartman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20160922174049.020608243@linuxfoundation.org \
    --to=gregkh@linuxfoundation.org \
    --cc=ast@kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=davem@davemloft.net \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome