* [PATCH AUTOSEL for 3.18 03/16] PCI: Apply _HPX settings only to relevant devices
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 02/16] RDS: RDMA: return appropriate error on rdma map failures alexander.levin
` (13 subsequent siblings)
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable; +Cc: Bjorn Helgaas, alexander.levin
From: Bjorn Helgaas <bhelgaas@google.com>
[ Upstream commit 977509f7c5c6fb992ffcdf4291051af343b91645 ]
Previously we didn't check the type of device before trying to apply Type 1
(PCI-X) or Type 2 (PCIe) Setting Records from _HPX.
We don't support PCI-X Setting Records, so this was harmless, but the
warning was useless.
We do support PCIe Setting Records, and we didn't check whether a device
was PCIe before applying settings. I don't think anything bad happened on
non-PCIe devices because pcie_capability_clear_and_set_word(),
pcie_cap_has_lnkctl(), etc., would fail before doing any harm. But it's
ugly to depend on those internals.
Check the device type before attempting to apply Type 1 and Type 2 Setting
Records (Type 0 records are applicable to PCI, PCI-X, and PCIe devices).
A side benefit is that this prevents useless "not supported" warnings when
a BIOS supplies a Type 1 (PCI-X) Setting Record and we try to apply it to
every single device:
pci 0000:00:00.0: PCI-X settings not supported
After this patch, we'll get the warning only when a BIOS supplies a Type 1
record and we have a PCI-X device to which it should be applied.
Link: https://bugzilla.kernel.org/show_bug.cgi?id=187731
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
drivers/pci/probe.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
diff --git a/drivers/pci/probe.c b/drivers/pci/probe.c
index 7de026897f1d..c43300ced57d 100644
--- a/drivers/pci/probe.c
+++ b/drivers/pci/probe.c
@@ -1329,8 +1329,16 @@ static void program_hpp_type0(struct pci_dev *dev, struct hpp_type0 *hpp)
static void program_hpp_type1(struct pci_dev *dev, struct hpp_type1 *hpp)
{
- if (hpp)
- dev_warn(&dev->dev, "PCI-X settings not supported\n");
+ int pos;
+
+ if (!hpp)
+ return;
+
+ pos = pci_find_capability(dev, PCI_CAP_ID_PCIX);
+ if (!pos)
+ return;
+
+ dev_warn(&dev->dev, "PCI-X settings not supported\n");
}
static void program_hpp_type2(struct pci_dev *dev, struct hpp_type2 *hpp)
@@ -1341,6 +1349,9 @@ static void program_hpp_type2(struct pci_dev *dev, struct hpp_type2 *hpp)
if (!hpp)
return;
+ if (!pci_is_pcie(dev))
+ return;
+
if (hpp->revision > 1) {
dev_warn(&dev->dev, "PCIe settings rev %d not supported\n",
hpp->revision);
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread* [PATCH AUTOSEL for 3.18 02/16] RDS: RDMA: return appropriate error on rdma map failures
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 03/16] PCI: Apply _HPX settings only to relevant devices alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 05/16] net: 3com: typhoon: typhoon_init_one: fix incorrect return values alexander.levin
` (12 subsequent siblings)
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable; +Cc: Santosh Shilimkar, alexander.levin
From: Santosh Shilimkar <santosh.shilimkar@oracle.com>
[ Upstream commit 584a8279a44a800dea5a5c1e9d53a002e03016b4 ]
The first message to a remote node should prompt a new
connection even if it is RDMA operation. For RDMA operation
the MR mapping can fail because connections is not yet up.
Since the connection establishment is asynchronous,
we make sure the map failure because of unavailable
connection reach to the user by appropriate error code.
Before returning to the user, lets trigger the connection
so that its ready for the next retry.
Signed-off-by: Santosh Shilimkar <santosh.shilimkar@oracle.com>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
net/rds/send.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/net/rds/send.c b/net/rds/send.c
index 45b800c3cc83..e827b41c9da2 100644
--- a/net/rds/send.c
+++ b/net/rds/send.c
@@ -903,6 +903,11 @@ static int rds_cmsg_send(struct rds_sock *rs, struct rds_message *rm,
ret = rds_cmsg_rdma_map(rs, rm, cmsg);
if (!ret)
*allocated_mr = 1;
+ else if (ret == -ENODEV)
+ /* Accommodate the get_mr() case which can fail
+ * if connection isn't established yet.
+ */
+ ret = -EAGAIN;
break;
case RDS_CMSG_ATOMIC_CSWP:
case RDS_CMSG_ATOMIC_FADD:
@@ -1011,8 +1016,12 @@ int rds_sendmsg(struct kiocb *iocb, struct socket *sock, struct msghdr *msg,
/* Parse any control messages the user may have included. */
ret = rds_cmsg_send(rs, rm, msg, &allocated_mr);
- if (ret)
+ if (ret) {
+ /* Trigger connection so that its ready for the next retry */
+ if (ret == -EAGAIN)
+ rds_conn_connect_if_down(conn);
goto out;
+ }
if (rm->rdma.op_active && !conn->c_trans->xmit_rdma) {
printk_ratelimited(KERN_NOTICE "rdma_op %p conn xmit_rdma %p\n",
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread* [PATCH AUTOSEL for 3.18 05/16] net: 3com: typhoon: typhoon_init_one: fix incorrect return values
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 03/16] PCI: Apply _HPX settings only to relevant devices alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 02/16] RDS: RDMA: return appropriate error on rdma map failures alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 04/16] net: 3com: typhoon: typhoon_init_one: make return values more specific alexander.levin
` (11 subsequent siblings)
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable
Cc: Thomas Preisner, Milan Stephan, David S . Miller, alexander.levin
From: Thomas Preisner <thomas.preisner+linux@fau.de>
[ Upstream commit 107fded7bf616ad6f46823d98b8ed6405d7adf2d ]
In a few cases the err-variable is not set to a negative error code if a
function call in typhoon_init_one() fails and thus 0 is returned
instead.
It may be better to set err to the appropriate negative error
code before returning.
Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=188841
Reported-by: Pan Bian <bianpan2016@163.com>
Signed-off-by: Thomas Preisner <thomas.preisner+linux@fau.de>
Signed-off-by: Milan Stephan <milan.stephan+linux@fau.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
drivers/net/ethernet/3com/typhoon.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/3com/typhoon.c b/drivers/net/ethernet/3com/typhoon.c
index 0f55088d18c4..247879a68f29 100644
--- a/drivers/net/ethernet/3com/typhoon.c
+++ b/drivers/net/ethernet/3com/typhoon.c
@@ -2398,8 +2398,9 @@ typhoon_init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
*(__be16 *)&dev->dev_addr[0] = htons(le16_to_cpu(xp_resp[0].parm1));
*(__be32 *)&dev->dev_addr[2] = htonl(le32_to_cpu(xp_resp[0].parm2));
- if(!is_valid_ether_addr(dev->dev_addr)) {
+ if (!is_valid_ether_addr(dev->dev_addr)) {
err_msg = "Could not obtain valid ethernet address, aborting";
+ err = -EIO;
goto error_out_reset;
}
@@ -2407,7 +2408,8 @@ typhoon_init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
* later when we print out the version reported.
*/
INIT_COMMAND_WITH_RESPONSE(&xp_cmd, TYPHOON_CMD_READ_VERSIONS);
- if(typhoon_issue_command(tp, 1, &xp_cmd, 3, xp_resp) < 0) {
+ err = typhoon_issue_command(tp, 1, &xp_cmd, 3, xp_resp);
+ if (err < 0) {
err_msg = "Could not get Sleep Image version";
goto error_out_reset;
}
@@ -2449,7 +2451,8 @@ typhoon_init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
dev->features = dev->hw_features |
NETIF_F_HW_VLAN_CTAG_RX | NETIF_F_RXCSUM;
- if(register_netdev(dev) < 0) {
+ err = register_netdev(dev);
+ if (err < 0) {
err_msg = "unable to register netdev";
goto error_out_reset;
}
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread* [PATCH AUTOSEL for 3.18 04/16] net: 3com: typhoon: typhoon_init_one: make return values more specific
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
` (2 preceding siblings ...)
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 05/16] net: 3com: typhoon: typhoon_init_one: fix incorrect return values alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 06/16] drm/armada: Fix compile fail alexander.levin
` (10 subsequent siblings)
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable
Cc: Thomas Preisner, Milan Stephan, David S . Miller, alexander.levin
From: Thomas Preisner <thomas.preisner+linux@fau.de>
[ Upstream commit 6b6bbb5922a4b1d4b58125a572da91010295fba3 ]
In some cases the return value of a failing function is not being used
and the function typhoon_init_one() returns another negative error code
instead.
Signed-off-by: Thomas Preisner <thomas.preisner+linux@fau.de>
Signed-off-by: Milan Stephan <milan.stephan+linux@fau.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
drivers/net/ethernet/3com/typhoon.c | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/drivers/net/ethernet/3com/typhoon.c b/drivers/net/ethernet/3com/typhoon.c
index 48775b88bac7..0f55088d18c4 100644
--- a/drivers/net/ethernet/3com/typhoon.c
+++ b/drivers/net/ethernet/3com/typhoon.c
@@ -2366,9 +2366,9 @@ typhoon_init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
* 4) Get the hardware address.
* 5) Put the card to sleep.
*/
- if (typhoon_reset(ioaddr, WaitSleep) < 0) {
+ err = typhoon_reset(ioaddr, WaitSleep);
+ if (err < 0) {
err_msg = "could not reset 3XP";
- err = -EIO;
goto error_out_dma;
}
@@ -2382,16 +2382,16 @@ typhoon_init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
typhoon_init_interface(tp);
typhoon_init_rings(tp);
- if(typhoon_boot_3XP(tp, TYPHOON_STATUS_WAITING_FOR_HOST) < 0) {
+ err = typhoon_boot_3XP(tp, TYPHOON_STATUS_WAITING_FOR_HOST);
+ if (err < 0) {
err_msg = "cannot boot 3XP sleep image";
- err = -EIO;
goto error_out_reset;
}
INIT_COMMAND_WITH_RESPONSE(&xp_cmd, TYPHOON_CMD_READ_MAC_ADDRESS);
- if(typhoon_issue_command(tp, 1, &xp_cmd, 1, xp_resp) < 0) {
+ err = typhoon_issue_command(tp, 1, &xp_cmd, 1, xp_resp);
+ if (err < 0) {
err_msg = "cannot read MAC address";
- err = -EIO;
goto error_out_reset;
}
@@ -2424,9 +2424,9 @@ typhoon_init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
if(xp_resp[0].numDesc != 0)
tp->capabilities |= TYPHOON_WAKEUP_NEEDS_RESET;
- if(typhoon_sleep(tp, PCI_D3hot, 0) < 0) {
+ err = typhoon_sleep(tp, PCI_D3hot, 0);
+ if (err < 0) {
err_msg = "cannot put adapter to sleep";
- err = -EIO;
goto error_out_reset;
}
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread* [PATCH AUTOSEL for 3.18 06/16] drm/armada: Fix compile fail
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
` (3 preceding siblings ...)
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 04/16] net: 3com: typhoon: typhoon_init_one: make return values more specific alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 07/16] ALSA: hda - Apply ALC269_FIXUP_NO_SHUTUP on HDA_FIXUP_ACT_PROBE alexander.levin
` (9 subsequent siblings)
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable
Cc: Daniel Vetter, Russell King, Chris Wilson, Daniel Vetter,
alexander.levin
From: Daniel Vetter <daniel.vetter@ffwll.ch>
[ Upstream commit 7357f89954b6d005df6ab8929759e78d7d9a80f9 ]
I reported the include issue for tracepoints a while ago, but nothing
seems to have happened. Now it bit us, since the drm_mm_print
conversion was broken for armada. Fix it, so I can re-enable armada
in the drm-misc build configs.
v2: Rebase just the compile fix on top of Chris' build fix.
Cc: Russell King <rmk+kernel@armlinux.org.uk>
Cc: Chris Wilson <chris@chris-wilson.co.uk>
Acked: Chris Wilson <chris@chris-wilson.co.uk>
Signed-off-by: Daniel Vetter <daniel.vetter@intel.com>
Link: http://patchwork.freedesktop.org/patch/msgid/1483115932-19584-1-git-send-email-daniel.vetter@ffwll.ch
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
drivers/gpu/drm/armada/Makefile | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/gpu/drm/armada/Makefile b/drivers/gpu/drm/armada/Makefile
index d6f43e06150a..c9c619727806 100644
--- a/drivers/gpu/drm/armada/Makefile
+++ b/drivers/gpu/drm/armada/Makefile
@@ -5,3 +5,5 @@ armada-y += armada_510.o
armada-$(CONFIG_DEBUG_FS) += armada_debugfs.o
obj-$(CONFIG_DRM_ARMADA) := armada.o
+
+CFLAGS_armada_trace.o := -I$(src)
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread* [PATCH AUTOSEL for 3.18 07/16] ALSA: hda - Apply ALC269_FIXUP_NO_SHUTUP on HDA_FIXUP_ACT_PROBE
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
` (4 preceding siblings ...)
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 06/16] drm/armada: Fix compile fail alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 10/16] staging: iio: cdc: fix improper return value alexander.levin
` (8 subsequent siblings)
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable; +Cc: Gabriele Mazzotta, Takashi Iwai, alexander.levin
From: Gabriele Mazzotta <gabriele.mzt@gmail.com>
[ Upstream commit 972aa2c708703c21f14eb958b37e82aae2530e44 ]
Setting shutup when the action is HDA_FIXUP_ACT_PRE_PROBE might
not have the desired effect since it could be overridden by
another more generic shutup function. Prevent this by setting
the more specific shutup function on HDA_FIXUP_ACT_PROBE.
Signed-off-by: Gabriele Mazzotta <gabriele.mzt@gmail.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
sound/pci/hda/patch_realtek.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index 09686203052c..fefc502f5bf5 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -4289,7 +4289,7 @@ static void alc_no_shutup(struct hda_codec *codec)
static void alc_fixup_no_shutup(struct hda_codec *codec,
const struct hda_fixup *fix, int action)
{
- if (action == HDA_FIXUP_ACT_PRE_PROBE) {
+ if (action == HDA_FIXUP_ACT_PROBE) {
struct alc_spec *spec = codec->spec;
spec->shutup = alc_no_shutup;
}
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread* [PATCH AUTOSEL for 3.18 10/16] staging: iio: cdc: fix improper return value
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
` (5 preceding siblings ...)
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 07/16] ALSA: hda - Apply ALC269_FIXUP_NO_SHUTUP on HDA_FIXUP_ACT_PROBE alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 11/16] netfilter: nft_queue: use raw_smp_processor_id() alexander.levin
` (7 subsequent siblings)
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable; +Cc: Pan Bian, Jonathan Cameron, alexander.levin
From: Pan Bian <bianpan2016@163.com>
[ Upstream commit 91ca1a8c584f55857b1f6ab20a1d3a1ce7a559bb ]
At the end of function ad7150_write_event_config(), directly returns 0.
As a result, the errors will be ignored by the callers. It may be better
to return variable "ret".
Signed-off-by: Pan Bian <bianpan2016@163.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
drivers/staging/iio/cdc/ad7150.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/staging/iio/cdc/ad7150.c b/drivers/staging/iio/cdc/ad7150.c
index a2b7ae3329c0..9fe1d5793cee 100644
--- a/drivers/staging/iio/cdc/ad7150.c
+++ b/drivers/staging/iio/cdc/ad7150.c
@@ -275,7 +275,7 @@ static int ad7150_write_event_config(struct iio_dev *indio_dev,
error_ret:
mutex_unlock(&chip->state_lock);
- return 0;
+ return ret;
}
static int ad7150_read_event_value(struct iio_dev *indio_dev,
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread* [PATCH AUTOSEL for 3.18 11/16] netfilter: nft_queue: use raw_smp_processor_id()
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
` (6 preceding siblings ...)
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 10/16] staging: iio: cdc: fix improper return value alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 09/16] mac80211: Suppress NEW_PEER_CANDIDATE event if no room alexander.levin
` (6 subsequent siblings)
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable; +Cc: Pablo Neira Ayuso, alexander.levin
From: Pablo Neira Ayuso <pablo@netfilter.org>
[ Upstream commit c2e756ff9e699865d294cdc112acfc36419cf5cc ]
Using smp_processor_id() causes splats with PREEMPT_RCU:
[19379.552780] BUG: using smp_processor_id() in preemptible [00000000] code: ping/32389
[19379.552793] caller is debug_smp_processor_id+0x17/0x19
[...]
[19379.552823] Call Trace:
[19379.552832] [<ffffffff81274e9e>] dump_stack+0x67/0x90
[19379.552837] [<ffffffff8129a4d4>] check_preemption_disabled+0xe5/0xf5
[19379.552842] [<ffffffff8129a4fb>] debug_smp_processor_id+0x17/0x19
[19379.552849] [<ffffffffa07c42dd>] nft_queue_eval+0x35/0x20c [nft_queue]
No need to disable preemption since we only fetch the numeric value, so
let's use raw_smp_processor_id() instead.
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
net/netfilter/nft_queue.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/netfilter/nft_queue.c b/net/netfilter/nft_queue.c
index e8ae2f6bf232..88cd49d3548e 100644
--- a/net/netfilter/nft_queue.c
+++ b/net/netfilter/nft_queue.c
@@ -37,7 +37,7 @@ static void nft_queue_eval(const struct nft_expr *expr,
if (priv->queues_total > 1) {
if (priv->flags & NFT_QUEUE_FLAG_CPU_FANOUT) {
- int cpu = smp_processor_id();
+ int cpu = raw_smp_processor_id();
queue = priv->queuenum + cpu % priv->queues_total;
} else {
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread* [PATCH AUTOSEL for 3.18 09/16] mac80211: Suppress NEW_PEER_CANDIDATE event if no room
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
` (7 preceding siblings ...)
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 11/16] netfilter: nft_queue: use raw_smp_processor_id() alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 12/16] netfilter: nf_tables: fix oob access alexander.levin
` (5 subsequent siblings)
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable; +Cc: Masashi Honma, Johannes Berg, alexander.levin
From: Masashi Honma <masashi.honma@gmail.com>
[ Upstream commit 11197d006bcfabf0173a7820a163fcaac420d10e ]
Previously, kernel sends NEW_PEER_CANDIDATE event to user land even if
the found peer does not have any room to accept other peer. This causes
continuous connection trials.
Signed-off-by: Masashi Honma <masashi.honma@gmail.com>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
net/mac80211/mesh_plink.c | 14 ++++++++------
1 file changed, 8 insertions(+), 6 deletions(-)
diff --git a/net/mac80211/mesh_plink.c b/net/mac80211/mesh_plink.c
index b488e1859b18..7d3e925430ae 100644
--- a/net/mac80211/mesh_plink.c
+++ b/net/mac80211/mesh_plink.c
@@ -448,12 +448,14 @@ mesh_sta_info_alloc(struct ieee80211_sub_if_data *sdata, u8 *addr,
/* Userspace handles station allocation */
if (sdata->u.mesh.user_mpm ||
- sdata->u.mesh.security & IEEE80211_MESH_SEC_AUTHED)
- cfg80211_notify_new_peer_candidate(sdata->dev, addr,
- elems->ie_start,
- elems->total_len,
- GFP_KERNEL);
- else
+ sdata->u.mesh.security & IEEE80211_MESH_SEC_AUTHED) {
+ if (mesh_peer_accepts_plinks(elems) &&
+ mesh_plink_availables(sdata))
+ cfg80211_notify_new_peer_candidate(sdata->dev, addr,
+ elems->ie_start,
+ elems->total_len,
+ GFP_KERNEL);
+ } else
sta = __mesh_sta_info_alloc(sdata, addr);
return sta;
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread* [PATCH AUTOSEL for 3.18 12/16] netfilter: nf_tables: fix oob access
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
` (8 preceding siblings ...)
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 09/16] mac80211: Suppress NEW_PEER_CANDIDATE event if no room alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 08/16] mac80211: Remove invalid flag operations in mesh TSF synchronization alexander.levin
` (4 subsequent siblings)
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable; +Cc: Florian Westphal, Pablo Neira Ayuso, alexander.levin
From: Florian Westphal <fw@strlen.de>
[ Upstream commit 3e38df136e453aa69eb4472108ebce2fb00b1ba6 ]
BUG: KASAN: slab-out-of-bounds in nf_tables_rule_destroy+0xf1/0x130 at addr ffff88006a4c35c8
Read of size 8 by task nft/1607
When we've destroyed last valid expr, nft_expr_next() returns an invalid expr.
We must not dereference it unless it passes != nft_expr_last() check.
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
net/netfilter/nf_tables_api.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c
index 9fe2baa01fbe..74724560bc48 100644
--- a/net/netfilter/nf_tables_api.c
+++ b/net/netfilter/nf_tables_api.c
@@ -1869,7 +1869,7 @@ static void nf_tables_rule_destroy(const struct nft_ctx *ctx,
* is called on error from nf_tables_newrule().
*/
expr = nft_expr_first(rule);
- while (expr->ops && expr != nft_expr_last(rule)) {
+ while (expr != nft_expr_last(rule) && expr->ops) {
nf_tables_expr_destroy(ctx, expr);
expr = nft_expr_next(expr);
}
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread* [PATCH AUTOSEL for 3.18 08/16] mac80211: Remove invalid flag operations in mesh TSF synchronization
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
` (9 preceding siblings ...)
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 12/16] netfilter: nf_tables: fix oob access alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 15/16] s390/kbuild: enable modversions for symbols exported from asm alexander.levin
` (3 subsequent siblings)
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable; +Cc: Masashi Honma, Johannes Berg, alexander.levin
From: Masashi Honma <masashi.honma@gmail.com>
[ Upstream commit 76f43b4c0a9337af22827d78de4f2b8fd5328489 ]
mesh_sync_offset_adjust_tbtt() implements Extensible synchronization
framework ([1] 13.13.2 Extensible synchronization framework). It shall
not operate the flag "TBTT Adjusting subfield" ([1] 8.4.2.100.8 Mesh
Capability), since it is used only for MBCA ([1] 13.13.4 Mesh beacon
collision avoidance, see 13.13.4.4.3 TBTT scanning and adjustment
procedures for detail). So this patch remove the flag operations.
[1] IEEE Std 802.11 2012
Signed-off-by: Masashi Honma <masashi.honma@gmail.com>
[remove adjusting_tbtt entirely, since it's now unused]
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
net/mac80211/ieee80211_i.h | 1 -
net/mac80211/mesh.c | 3 ---
net/mac80211/mesh_sync.c | 11 -----------
3 files changed, 15 deletions(-)
diff --git a/net/mac80211/ieee80211_i.h b/net/mac80211/ieee80211_i.h
index aed656d18b23..9460d4e3248e 100644
--- a/net/mac80211/ieee80211_i.h
+++ b/net/mac80211/ieee80211_i.h
@@ -640,7 +640,6 @@ struct ieee80211_if_mesh {
const struct ieee80211_mesh_sync_ops *sync_ops;
s64 sync_offset_clockdrift_max;
spinlock_t sync_offset_lock;
- bool adjusting_tbtt;
/* mesh power save */
enum nl80211_mesh_power_mode nonpeer_pm;
int ps_peers_light_sleep;
diff --git a/net/mac80211/mesh.c b/net/mac80211/mesh.c
index ac04e3874af1..30bea9dcafed 100644
--- a/net/mac80211/mesh.c
+++ b/net/mac80211/mesh.c
@@ -289,8 +289,6 @@ int mesh_add_meshconf_ie(struct ieee80211_sub_if_data *sdata,
/* Mesh PS mode. See IEEE802.11-2012 8.4.2.100.8 */
*pos |= ifmsh->ps_peers_deep_sleep ?
IEEE80211_MESHCONF_CAPAB_POWER_SAVE_LEVEL : 0x00;
- *pos++ |= ifmsh->adjusting_tbtt ?
- IEEE80211_MESHCONF_CAPAB_TBTT_ADJUSTING : 0x00;
*pos++ = 0x00;
return 0;
@@ -790,7 +788,6 @@ int ieee80211_start_mesh(struct ieee80211_sub_if_data *sdata)
ifmsh->mesh_cc_id = 0; /* Disabled */
/* register sync ops from extensible synchronization framework */
ifmsh->sync_ops = ieee80211_mesh_sync_ops_get(ifmsh->mesh_sp_id);
- ifmsh->adjusting_tbtt = false;
ifmsh->sync_offset_clockdrift_max = 0;
set_bit(MESH_WORK_HOUSEKEEPING, &ifmsh->wrkq_flags);
ieee80211_mesh_root_setup(ifmsh);
diff --git a/net/mac80211/mesh_sync.c b/net/mac80211/mesh_sync.c
index 09625d6205c3..6e8ece73bfa6 100644
--- a/net/mac80211/mesh_sync.c
+++ b/net/mac80211/mesh_sync.c
@@ -119,7 +119,6 @@ static void mesh_sync_offset_rx_bcn_presp(struct ieee80211_sub_if_data *sdata,
*/
if (elems->mesh_config && mesh_peer_tbtt_adjusting(elems)) {
- clear_sta_flag(sta, WLAN_STA_TOFFSET_KNOWN);
msync_dbg(sdata, "STA %pM : is adjusting TBTT\n",
sta->sta.addr);
goto no_sync;
@@ -168,11 +167,9 @@ static void mesh_sync_offset_adjust_tbtt(struct ieee80211_sub_if_data *sdata,
struct beacon_data *beacon)
{
struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
- u8 cap;
WARN_ON(ifmsh->mesh_sp_id != IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET);
WARN_ON(!rcu_read_lock_held());
- cap = beacon->meshconf->meshconf_cap;
spin_lock_bh(&ifmsh->sync_offset_lock);
@@ -186,21 +183,13 @@ static void mesh_sync_offset_adjust_tbtt(struct ieee80211_sub_if_data *sdata,
"TBTT : kicking off TBTT adjustment with clockdrift_max=%lld\n",
ifmsh->sync_offset_clockdrift_max);
set_bit(MESH_WORK_DRIFT_ADJUST, &ifmsh->wrkq_flags);
-
- ifmsh->adjusting_tbtt = true;
} else {
msync_dbg(sdata,
"TBTT : max clockdrift=%lld; too small to adjust\n",
(long long)ifmsh->sync_offset_clockdrift_max);
ifmsh->sync_offset_clockdrift_max = 0;
-
- ifmsh->adjusting_tbtt = false;
}
spin_unlock_bh(&ifmsh->sync_offset_lock);
-
- beacon->meshconf->meshconf_cap = ifmsh->adjusting_tbtt ?
- IEEE80211_MESHCONF_CAPAB_TBTT_ADJUSTING | cap :
- ~IEEE80211_MESHCONF_CAPAB_TBTT_ADJUSTING & cap;
}
static const struct sync_method sync_methods[] = {
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread* [PATCH AUTOSEL for 3.18 15/16] s390/kbuild: enable modversions for symbols exported from asm
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
` (10 preceding siblings ...)
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 08/16] mac80211: Remove invalid flag operations in mesh TSF synchronization alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 14/16] ASoC: wm_adsp: Don't overrun firmware file buffer when reading region data alexander.levin
` (2 subsequent siblings)
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable; +Cc: Heiko Carstens, Martin Schwidefsky, alexander.levin
From: Heiko Carstens <heiko.carstens@de.ibm.com>
[ Upstream commit cabab3f9f5ca077535080b3252e6168935b914af ]
s390 version of commit 334bb7738764 ("x86/kbuild: enable modversions
for symbols exported from asm") so we get also rid of all these
warnings:
WARNING: EXPORT symbol "_mcount" [vmlinux] version generation failed, symbol will not be versioned.
WARNING: EXPORT symbol "memcpy" [vmlinux] version generation failed, symbol will not be versioned.
WARNING: EXPORT symbol "memmove" [vmlinux] version generation failed, symbol will not be versioned.
WARNING: EXPORT symbol "memset" [vmlinux] version generation failed, symbol will not be versioned.
WARNING: EXPORT symbol "save_fpu_regs" [vmlinux] version generation failed, symbol will not be versioned.
WARNING: EXPORT symbol "sie64a" [vmlinux] version generation failed, symbol will not be versioned.
WARNING: EXPORT symbol "sie_exit" [vmlinux] version generation failed, symbol will not be versioned.
Signed-off-by: Heiko Carstens <heiko.carstens@de.ibm.com>
Signed-off-by: Martin Schwidefsky <schwidefsky@de.ibm.com>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
arch/s390/include/asm/asm-prototypes.h | 8 ++++++++
1 file changed, 8 insertions(+)
create mode 100644 arch/s390/include/asm/asm-prototypes.h
diff --git a/arch/s390/include/asm/asm-prototypes.h b/arch/s390/include/asm/asm-prototypes.h
new file mode 100644
index 000000000000..2c3413b0ca52
--- /dev/null
+++ b/arch/s390/include/asm/asm-prototypes.h
@@ -0,0 +1,8 @@
+#ifndef _ASM_S390_PROTOTYPES_H
+
+#include <linux/kvm_host.h>
+#include <linux/ftrace.h>
+#include <asm/fpu/api.h>
+#include <asm-generic/asm-prototypes.h>
+
+#endif /* _ASM_S390_PROTOTYPES_H */
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread* [PATCH AUTOSEL for 3.18 14/16] ASoC: wm_adsp: Don't overrun firmware file buffer when reading region data
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
` (11 preceding siblings ...)
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 15/16] s390/kbuild: enable modversions for symbols exported from asm alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 13/16] btrfs: return the actual error value from from btrfs_uuid_tree_iterate alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 16/16] xen: xenbus driver must not accept invalid transaction ids alexander.levin
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable; +Cc: Richard Fitzgerald, Mark Brown, alexander.levin
From: Richard Fitzgerald <rf@opensource.wolfsonmicro.com>
[ Upstream commit 1cab2a84f470e15ecc8e5143bfe9398c6e888032 ]
Protect against corrupt firmware files by ensuring that the length we
get for the data in a region actually lies within the available firmware
file data buffer.
Signed-off-by: Richard Fitzgerald <rf@opensource.wolfsonmicro.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
sound/soc/codecs/wm_adsp.c | 25 ++++++++++++++++++++++++-
1 file changed, 24 insertions(+), 1 deletion(-)
diff --git a/sound/soc/codecs/wm_adsp.c b/sound/soc/codecs/wm_adsp.c
index 7f2f661c6453..d53bfd4d0ada 100644
--- a/sound/soc/codecs/wm_adsp.c
+++ b/sound/soc/codecs/wm_adsp.c
@@ -532,7 +532,7 @@ static int wm_adsp_load(struct wm_adsp *dsp)
const struct wmfw_region *region;
const struct wm_adsp_region *mem;
const char *region_name;
- char *file, *text;
+ char *file, *text = NULL;
struct wm_adsp_buf *buf;
unsigned int reg;
int regions = 0;
@@ -677,10 +677,21 @@ static int wm_adsp_load(struct wm_adsp *dsp)
regions, le32_to_cpu(region->len), offset,
region_name);
+ if ((pos + le32_to_cpu(region->len) + sizeof(*region)) >
+ firmware->size) {
+ adsp_err(dsp,
+ "%s.%d: %s region len %d bytes exceeds file length %zu\n",
+ file, regions, region_name,
+ le32_to_cpu(region->len), firmware->size);
+ ret = -EINVAL;
+ goto out_fw;
+ }
+
if (text) {
memcpy(text, region->data, le32_to_cpu(region->len));
adsp_info(dsp, "%s: %s\n", file, text);
kfree(text);
+ text = NULL;
}
if (reg) {
@@ -737,6 +748,7 @@ static int wm_adsp_load(struct wm_adsp *dsp)
regmap_async_complete(regmap);
wm_adsp_buf_free(&buf_list);
release_firmware(firmware);
+ kfree(text);
out:
kfree(file);
@@ -1316,6 +1328,17 @@ static int wm_adsp_load_coeff(struct wm_adsp *dsp)
}
if (reg) {
+ if ((pos + le32_to_cpu(blk->len) + sizeof(*blk)) >
+ firmware->size) {
+ adsp_err(dsp,
+ "%s.%d: %s region len %d bytes exceeds file length %zu\n",
+ file, blocks, region_name,
+ le32_to_cpu(blk->len),
+ firmware->size);
+ ret = -EINVAL;
+ goto out_fw;
+ }
+
buf = wm_adsp_buf_alloc(blk->data,
le32_to_cpu(blk->len),
&buf_list);
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread* [PATCH AUTOSEL for 3.18 13/16] btrfs: return the actual error value from from btrfs_uuid_tree_iterate
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
` (12 preceding siblings ...)
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 14/16] ASoC: wm_adsp: Don't overrun firmware file buffer when reading region data alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 16/16] xen: xenbus driver must not accept invalid transaction ids alexander.levin
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable; +Cc: Pan Bian, David Sterba, alexander.levin
From: Pan Bian <bianpan2016@163.com>
[ Upstream commit 73ba39ab9307340dc98ec3622891314bbc09cc2e ]
In function btrfs_uuid_tree_iterate(), errno is assigned to variable ret
on errors. However, it directly returns 0. It may be better to return
ret. This patch also removes the warning, because the caller already
prints a warning.
Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=188731
Signed-off-by: Pan Bian <bianpan2016@163.com>
Reviewed-by: Omar Sandoval <osandov@fb.com>
[ edited subject ]
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
fs/btrfs/uuid-tree.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/fs/btrfs/uuid-tree.c b/fs/btrfs/uuid-tree.c
index 778282944530..837a9a8d579e 100644
--- a/fs/btrfs/uuid-tree.c
+++ b/fs/btrfs/uuid-tree.c
@@ -348,7 +348,5 @@ int btrfs_uuid_tree_iterate(struct btrfs_fs_info *fs_info,
out:
btrfs_free_path(path);
- if (ret)
- btrfs_warn(fs_info, "btrfs_uuid_tree_iterate failed %d", ret);
- return 0;
+ return ret;
}
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread* [PATCH AUTOSEL for 3.18 16/16] xen: xenbus driver must not accept invalid transaction ids
2017-11-15 2:46 [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long alexander.levin
` (13 preceding siblings ...)
2017-11-15 2:46 ` [PATCH AUTOSEL for 3.18 13/16] btrfs: return the actual error value from from btrfs_uuid_tree_iterate alexander.levin
@ 2017-11-15 2:46 ` alexander.levin
14 siblings, 0 replies; 16+ messages in thread
From: alexander.levin @ 2017-11-15 2:46 UTC (permalink / raw)
To: linux-kernel, stable; +Cc: Juergen Gross, alexander.levin
From: Juergen Gross <jgross@suse.com>
[ Upstream commit 639b08810d6ad74ded2c5f6e233c4fcb9d147168 ]
When accessing Xenstore in a transaction the user is specifying a
transaction id which he normally obtained from Xenstore when starting
the transaction. Xenstore is validating a transaction id against all
known transaction ids of the connection the request came in. As all
requests of a domain not being the one where Xenstore lives share
one connection, validation of transaction ids of different users of
Xenstore in that domain should be done by the kernel of that domain
being the multiplexer between the Xenstore users in that domain and
Xenstore.
In order to prohibit one Xenstore user "hijacking" a transaction from
another user the xenbus driver has to verify a given transaction id
against all known transaction ids of the user before forwarding it to
Xenstore.
Signed-off-by: Juergen Gross <jgross@suse.com>
Reviewed-by: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Signed-off-by: Juergen Gross <jgross@suse.com>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
drivers/xen/xenbus/xenbus_dev_frontend.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/xen/xenbus/xenbus_dev_frontend.c b/drivers/xen/xenbus/xenbus_dev_frontend.c
index 0e0eb10f82a0..816a0e08ef10 100644
--- a/drivers/xen/xenbus/xenbus_dev_frontend.c
+++ b/drivers/xen/xenbus/xenbus_dev_frontend.c
@@ -316,7 +316,7 @@ static int xenbus_write_transaction(unsigned msg_type,
rc = -ENOMEM;
goto out;
}
- } else if (msg_type == XS_TRANSACTION_END) {
+ } else if (u->u.msg.tx_id != 0) {
list_for_each_entry(trans, &u->transactions, list)
if (trans->handle.id == u->u.msg.tx_id)
break;
--
2.11.0
^ permalink raw reply [flat|nested] 16+ messages in thread