mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Sasha Levin <Alexander.Levin@microsoft.com>
To: "stable@vger.kernel.org" <stable@vger.kernel.org>,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>
Cc: Chao Yu <yuchao0@huawei.com>, Jaegeuk Kim <jaegeuk@kernel.org>,
	Sasha Levin <Alexander.Levin@microsoft.com>
Subject: [PATCH AUTOSEL 4.18 121/131] f2fs: fix to do sanity check with extra_attr feature
Date: Sun, 2 Sep 2018 13:05:36 +0000	[thread overview]
Message-ID: <20180902064601.183036-121-alexander.levin@microsoft.com> (raw)
In-Reply-To: <20180902064601.183036-1-alexander.levin@microsoft.com>

From: Chao Yu <yuchao0@huawei.com>

[ Upstream commit 76d56d4ab4f2a9e4f085c7d77172194ddaccf7d2 ]

If FI_EXTRA_ATTR is set in inode by fuzzing, inode.i_addr[0] will be
parsed as inode.i_extra_isize, then in __recover_inline_status, inline
data address will beyond boundary of page, result in accessing invalid
memory.

So in this condition, during reading inode page, let's do sanity check
with EXTRA_ATTR feature of fs and extra_attr bit of inode, if they're
inconsistent, deny to load this inode.

- Overview
Out-of-bound access in f2fs_iget() when mounting a corrupted f2fs image

- Reproduce

The following message will be got in KASAN build of 4.18 upstream kernel.
[  819.392227] ==================================================================
[  819.393901] BUG: KASAN: slab-out-of-bounds in f2fs_iget+0x736/0x1530
[  819.395329] Read of size 4 at addr ffff8801f099c968 by task mount/1292

[  819.397079] CPU: 1 PID: 1292 Comm: mount Not tainted 4.18.0-rc1+ #4
[  819.397082] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Ubuntu-1.8.2-1ubuntu1 04/01/2014
[  819.397088] Call Trace:
[  819.397124]  dump_stack+0x7b/0xb5
[  819.397154]  print_address_description+0x70/0x290
[  819.397159]  kasan_report+0x291/0x390
[  819.397163]  ? f2fs_iget+0x736/0x1530
[  819.397176]  check_memory_region+0x139/0x190
[  819.397182]  __asan_loadN+0xf/0x20
[  819.397185]  f2fs_iget+0x736/0x1530
[  819.397197]  f2fs_fill_super+0x1b4f/0x2b40
[  819.397202]  ? f2fs_fill_super+0x1b4f/0x2b40
[  819.397208]  ? f2fs_commit_super+0x1b0/0x1b0
[  819.397227]  ? set_blocksize+0x90/0x140
[  819.397241]  mount_bdev+0x1c5/0x210
[  819.397245]  ? f2fs_commit_super+0x1b0/0x1b0
[  819.397252]  f2fs_mount+0x15/0x20
[  819.397256]  mount_fs+0x60/0x1a0
[  819.397267]  ? alloc_vfsmnt+0x309/0x360
[  819.397272]  vfs_kern_mount+0x6b/0x1a0
[  819.397282]  do_mount+0x34a/0x18c0
[  819.397300]  ? lockref_put_or_lock+0xcf/0x160
[  819.397306]  ? copy_mount_string+0x20/0x20
[  819.397318]  ? memcg_kmem_put_cache+0x1b/0xa0
[  819.397324]  ? kasan_check_write+0x14/0x20
[  819.397334]  ? _copy_from_user+0x6a/0x90
[  819.397353]  ? memdup_user+0x42/0x60
[  819.397359]  ksys_mount+0x83/0xd0
[  819.397365]  __x64_sys_mount+0x67/0x80
[  819.397388]  do_syscall_64+0x78/0x170
[  819.397403]  entry_SYSCALL_64_after_hwframe+0x44/0xa9
[  819.397422] RIP: 0033:0x7f54c667cb9a
[  819.397424] Code: 48 8b 0d 01 c3 2b 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d ce c2 2b 00 f7 d8 64 89 01 48
[  819.397483] RSP: 002b:00007ffd8f46cd08 EFLAGS: 00000202 ORIG_RAX: 00000000000000a5
[  819.397496] RAX: ffffffffffffffda RBX: 0000000000dfa030 RCX: 00007f54c667cb9a
[  819.397498] RDX: 0000000000dfa210 RSI: 0000000000dfbf30 RDI: 0000000000e02ec0
[  819.397501] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000013
[  819.397503] R10: 00000000c0ed0000 R11: 0000000000000202 R12: 0000000000e02ec0
[  819.397505] R13: 0000000000dfa210 R14: 0000000000000000 R15: 0000000000000003

[  819.397866] Allocated by task 139:
[  819.398702]  save_stack+0x46/0xd0
[  819.398705]  kasan_kmalloc+0xad/0xe0
[  819.398709]  kasan_slab_alloc+0x11/0x20
[  819.398713]  kmem_cache_alloc+0xd1/0x1e0
[  819.398717]  dup_fd+0x50/0x4c0
[  819.398740]  copy_process.part.37+0xbed/0x32e0
[  819.398744]  _do_fork+0x16e/0x590
[  819.398748]  __x64_sys_clone+0x69/0x80
[  819.398752]  do_syscall_64+0x78/0x170
[  819.398756]  entry_SYSCALL_64_after_hwframe+0x44/0xa9

[  819.399097] Freed by task 159:
[  819.399743]  save_stack+0x46/0xd0
[  819.399747]  __kasan_slab_free+0x13c/0x1a0
[  819.399750]  kasan_slab_free+0xe/0x10
[  819.399754]  kmem_cache_free+0x89/0x1e0
[  819.399757]  put_files_struct+0x132/0x150
[  819.399761]  exit_files+0x62/0x70
[  819.399766]  do_exit+0x47b/0x1390
[  819.399770]  do_group_exit+0x86/0x130
[  819.399774]  __x64_sys_exit_group+0x2c/0x30
[  819.399778]  do_syscall_64+0x78/0x170
[  819.399782]  entry_SYSCALL_64_after_hwframe+0x44/0xa9

[  819.400115] The buggy address belongs to the object at ffff8801f099c680
                which belongs to the cache files_cache of size 704
[  819.403234] The buggy address is located 40 bytes to the right of
                704-byte region [ffff8801f099c680, ffff8801f099c940)
[  819.405689] The buggy address belongs to the page:
[  819.406709] page:ffffea0007c26700 count:1 mapcount:0 mapping:ffff8801f69a3340 index:0xffff8801f099d380 compound_mapcount: 0
[  819.408984] flags: 0x2ffff0000008100(slab|head)
[  819.409932] raw: 02ffff0000008100 ffffea00077fb600 0000000200000002 ffff8801f69a3340
[  819.411514] raw: ffff8801f099d380 0000000080130000 00000001ffffffff 0000000000000000
[  819.413073] page dumped because: kasan: bad access detected

[  819.414539] Memory state around the buggy address:
[  819.415521]  ffff8801f099c800: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[  819.416981]  ffff8801f099c880: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[  819.418454] >ffff8801f099c900: fb fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc
[  819.419921]                                                           ^
[  819.421265]  ffff8801f099c980: fc fc fc fc fc fc fc fc fb fb fb fb fb fb fb fb
[  819.422745]  ffff8801f099ca00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[  819.424206] ==================================================================
[  819.425668] Disabling lock debugging due to kernel taint
[  819.457463] F2FS-fs (loop0): Mounted with checkpoint version = 3

The kernel still mounts the image. If you run the following program on the mounted folder mnt,

(poc.c)

static void activity(char *mpoint) {

  char *foo_bar_baz;
  int err;

  static int buf[8192];
  memset(buf, 0, sizeof(buf));

  err = asprintf(&foo_bar_baz, "%s/foo/bar/baz", mpoint);
    int fd = open(foo_bar_baz, O_RDONLY, 0);
  if (fd >= 0) {
      read(fd, (char *)buf, 11);
      close(fd);
  }
}

int main(int argc, char *argv[]) {
  activity(argv[1]);
  return 0;
}

You can get kernel crash:
[  819.457463] F2FS-fs (loop0): Mounted with checkpoint version = 3
[  918.028501] BUG: unable to handle kernel paging request at ffffed0048000d82
[  918.044020] PGD 23ffee067 P4D 23ffee067 PUD 23fbef067 PMD 0
[  918.045207] Oops: 0000 [#1] SMP KASAN PTI
[  918.046048] CPU: 0 PID: 1309 Comm: poc Tainted: G    B             4.18.0-rc1+ #4
[  918.047573] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Ubuntu-1.8.2-1ubuntu1 04/01/2014
[  918.049552] RIP: 0010:check_memory_region+0x5e/0x190
[  918.050565] Code: f8 49 c1 e8 03 49 89 db 49 c1 eb 03 4d 01 cb 4d 01 c1 4d 8d 63 01 4c 89 c8 4d 89 e2 4d 29 ca 49 83 fa 10 7f 3d 4d 85 d2 74 32 <41> 80 39 00 75 23 48 b8 01 00 00 00 00 fc ff df 4d 01 d1 49 01 c0
[  918.054322] RSP: 0018:ffff8801e3a1f258 EFLAGS: 00010202
[  918.055400] RAX: ffffed0048000d82 RBX: ffff880240006c11 RCX: ffffffffb8867d14
[  918.056832] RDX: 0000000000000000 RSI: 0000000000000002 RDI: ffff880240006c10
[  918.058253] RBP: ffff8801e3a1f268 R08: 1ffff10048000d82 R09: ffffed0048000d82
[  918.059717] R10: 0000000000000001 R11: ffffed0048000d82 R12: ffffed0048000d83
[  918.061159] R13: ffff8801e3a1f390 R14: 0000000000000000 R15: ffff880240006c08
[  918.062614] FS:  00007fac9732c700(0000) GS:ffff8801f6e00000(0000) knlGS:0000000000000000
[  918.064246] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  918.065412] CR2: ffffed0048000d82 CR3: 00000001df77a000 CR4: 00000000000006f0
[  918.066882] Call Trace:
[  918.067410]  __asan_loadN+0xf/0x20
[  918.068149]  f2fs_find_target_dentry+0xf4/0x270
[  918.069083]  ? __get_node_page+0x331/0x5b0
[  918.069925]  f2fs_find_in_inline_dir+0x24b/0x310
[  918.070881]  ? f2fs_recover_inline_data+0x4c0/0x4c0
[  918.071905]  ? unwind_next_frame.part.5+0x34f/0x490
[  918.072901]  ? unwind_dump+0x290/0x290
[  918.073695]  ? is_bpf_text_address+0xe/0x20
[  918.074566]  __f2fs_find_entry+0x599/0x670
[  918.075408]  ? kasan_unpoison_shadow+0x36/0x50
[  918.076315]  ? kasan_kmalloc+0xad/0xe0
[  918.077100]  ? memcg_kmem_put_cache+0x55/0xa0
[  918.077998]  ? f2fs_find_target_dentry+0x270/0x270
[  918.079006]  ? d_set_d_op+0x30/0x100
[  918.079749]  ? __d_lookup_rcu+0x69/0x2e0
[  918.080556]  ? __d_alloc+0x275/0x450
[  918.081297]  ? kasan_check_write+0x14/0x20
[  918.082135]  ? memset+0x31/0x40
[  918.082820]  ? fscrypt_setup_filename+0x1ec/0x4c0
[  918.083782]  ? d_alloc_parallel+0x5bb/0x8c0
[  918.084640]  f2fs_find_entry+0xe9/0x110
[  918.085432]  ? __f2fs_find_entry+0x670/0x670
[  918.086308]  ? kasan_check_write+0x14/0x20
[  918.087163]  f2fs_lookup+0x297/0x590
[  918.087902]  ? f2fs_link+0x2b0/0x2b0
[  918.088646]  ? legitimize_path.isra.29+0x61/0xa0
[  918.089589]  __lookup_slow+0x12e/0x240
[  918.090371]  ? may_delete+0x2b0/0x2b0
[  918.091123]  ? __nd_alloc_stack+0xa0/0xa0
[  918.091944]  lookup_slow+0x44/0x60
[  918.092642]  walk_component+0x3ee/0xa40
[  918.093428]  ? is_bpf_text_address+0xe/0x20
[  918.094283]  ? pick_link+0x3e0/0x3e0
[  918.095047]  ? in_group_p+0xa5/0xe0
[  918.095771]  ? generic_permission+0x53/0x1e0
[  918.096666]  ? security_inode_permission+0x1d/0x70
[  918.097646]  ? inode_permission+0x7a/0x1f0
[  918.098497]  link_path_walk+0x2a2/0x7b0
[  918.099298]  ? apparmor_capget+0x3d0/0x3d0
[  918.100140]  ? walk_component+0xa40/0xa40
[  918.100958]  ? path_init+0x2e6/0x580
[  918.101695]  path_openat+0x1bb/0x2160
[  918.102471]  ? __save_stack_trace+0x92/0x100
[  918.103352]  ? save_stack+0xb5/0xd0
[  918.104070]  ? vfs_unlink+0x250/0x250
[  918.104822]  ? save_stack+0x46/0xd0
[  918.105538]  ? kasan_slab_alloc+0x11/0x20
[  918.106370]  ? kmem_cache_alloc+0xd1/0x1e0
[  918.107213]  ? getname_flags+0x76/0x2c0
[  918.107997]  ? getname+0x12/0x20
[  918.108677]  ? do_sys_open+0x14b/0x2c0
[  918.109450]  ? __x64_sys_open+0x4c/0x60
[  918.110255]  ? do_syscall_64+0x78/0x170
[  918.111083]  ? entry_SYSCALL_64_after_hwframe+0x44/0xa9
[  918.112148]  ? entry_SYSCALL_64_after_hwframe+0x44/0xa9
[  918.113204]  ? f2fs_empty_inline_dir+0x1e0/0x1e0
[  918.114150]  ? timespec64_trunc+0x5c/0x90
[  918.114993]  ? wb_io_lists_depopulated+0x1a/0xc0
[  918.115937]  ? inode_io_list_move_locked+0x102/0x110
[  918.116949]  do_filp_open+0x12b/0x1d0
[  918.117709]  ? may_open_dev+0x50/0x50
[  918.118475]  ? kasan_kmalloc+0xad/0xe0
[  918.119246]  do_sys_open+0x17c/0x2c0
[  918.119983]  ? do_sys_open+0x17c/0x2c0
[  918.120751]  ? filp_open+0x60/0x60
[  918.121463]  ? task_work_run+0x4d/0xf0
[  918.122237]  __x64_sys_open+0x4c/0x60
[  918.123001]  do_syscall_64+0x78/0x170
[  918.123759]  entry_SYSCALL_64_after_hwframe+0x44/0xa9
[  918.124802] RIP: 0033:0x7fac96e3e040
[  918.125537] Code: 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 83 3d 09 27 2d 00 00 75 10 b8 02 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 31 c3 48 83 ec 08 e8 7e e0 01 00 48 89 04 24
[  918.129341] RSP: 002b:00007fff1b37f848 EFLAGS: 00000246 ORIG_RAX: 0000000000000002
[  918.130870] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fac96e3e040
[  918.132295] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 000000000122d080
[  918.133748] RBP: 00007fff1b37f9b0 R08: 00007fac9710bbd8 R09: 0000000000000001
[  918.135209] R10: 000000000000069d R11: 0000000000000246 R12: 0000000000400c20
[  918.136650] R13: 00007fff1b37fab0 R14: 0000000000000000 R15: 0000000000000000
[  918.138093] Modules linked in: snd_hda_codec_generic snd_hda_intel snd_hda_codec snd_hwdep snd_hda_core snd_pcm snd_timer snd mac_hid i2c_piix4 soundcore ib_iser rdma_cm iw_cm ib_cm ib_core iscsi_tcp libiscsi_tcp libiscsi scsi_transport_iscsi raid10 raid456 async_raid6_recov async_memcpy async_pq async_xor async_tx raid1 raid0 multipath linear 8139too crct10dif_pclmul crc32_pclmul qxl drm_kms_helper syscopyarea aesni_intel sysfillrect sysimgblt fb_sys_fops ttm drm aes_x86_64 crypto_simd cryptd 8139cp glue_helper mii pata_acpi floppy
[  918.147924] CR2: ffffed0048000d82
[  918.148619] ---[ end trace 4ce02f25ff7d3df5 ]---
[  918.149563] RIP: 0010:check_memory_region+0x5e/0x190
[  918.150576] Code: f8 49 c1 e8 03 49 89 db 49 c1 eb 03 4d 01 cb 4d 01 c1 4d 8d 63 01 4c 89 c8 4d 89 e2 4d 29 ca 49 83 fa 10 7f 3d 4d 85 d2 74 32 <41> 80 39 00 75 23 48 b8 01 00 00 00 00 fc ff df 4d 01 d1 49 01 c0
[  918.154360] RSP: 0018:ffff8801e3a1f258 EFLAGS: 00010202
[  918.155411] RAX: ffffed0048000d82 RBX: ffff880240006c11 RCX: ffffffffb8867d14
[  918.156833] RDX: 0000000000000000 RSI: 0000000000000002 RDI: ffff880240006c10
[  918.158257] RBP: ffff8801e3a1f268 R08: 1ffff10048000d82 R09: ffffed0048000d82
[  918.159722] R10: 0000000000000001 R11: ffffed0048000d82 R12: ffffed0048000d83
[  918.161149] R13: ffff8801e3a1f390 R14: 0000000000000000 R15: ffff880240006c08
[  918.162587] FS:  00007fac9732c700(0000) GS:ffff8801f6e00000(0000) knlGS:0000000000000000
[  918.164203] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  918.165356] CR2: ffffed0048000d82 CR3: 00000001df77a000 CR4: 00000000000006f0

Reported-by: Wen Xu <wen.xu@gatech.edu>
Signed-off-by: Chao Yu <yuchao0@huawei.com>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Sasha Levin <alexander.levin@microsoft.com>
---
 fs/f2fs/inode.c | 19 +++++++++++++++----
 1 file changed, 15 insertions(+), 4 deletions(-)

diff --git a/fs/f2fs/inode.c b/fs/f2fs/inode.c
index f121c864f4c0..cf0f944fcaea 100644
--- a/fs/f2fs/inode.c
+++ b/fs/f2fs/inode.c
@@ -197,6 +197,16 @@ static bool sanity_check_inode(struct inode *inode)
 			__func__, inode->i_ino);
 		return false;
 	}
+
+	if (f2fs_has_extra_attr(inode) &&
+			!f2fs_sb_has_extra_attr(sbi->sb)) {
+		set_sbi_flag(sbi, SBI_NEED_FSCK);
+		f2fs_msg(sbi->sb, KERN_WARNING,
+			"%s: inode (ino=%lx) is with extra_attr, "
+			"but extra_attr feature is off",
+			__func__, inode->i_ino);
+		return false;
+	}
 	return true;
 }
 
@@ -249,6 +259,11 @@ static int do_read_inode(struct inode *inode)
 
 	get_inline_info(inode, ri);
 
+	if (!sanity_check_inode(inode)) {
+		f2fs_put_page(node_page, 1);
+		return -EINVAL;
+	}
+
 	fi->i_extra_isize = f2fs_has_extra_attr(inode) ?
 					le16_to_cpu(ri->i_extra_isize) : 0;
 
@@ -330,10 +345,6 @@ struct inode *f2fs_iget(struct super_block *sb, unsigned long ino)
 	ret = do_read_inode(inode);
 	if (ret)
 		goto bad_inode;
-	if (!sanity_check_inode(inode)) {
-		ret = -EINVAL;
-		goto bad_inode;
-	}
 make_now:
 	if (ino == F2FS_NODE_INO(sbi)) {
 		inode->i_mapping->a_ops = &f2fs_node_aops;
-- 
2.17.1

  parent reply	other threads:[~2018-09-02 13:28 UTC|newest]

Thread overview: 144+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-09-02 13:02 [PATCH AUTOSEL 4.18 001/131] tc-testing: flush gact actions on test teardown Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 002/131] tc-testing: remove duplicate spaces in connmark match patterns Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 003/131] misc: mic: SCIF Fix scif_get_new_port() error handling Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 004/131] ALSA: hda/realtek - Add mute LED quirk for HP Spectre x360 Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 005/131] ethtool: Remove trailing semicolon for static inline Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 006/131] i2c: aspeed: Add an explicit type casting for *get_clk_reg_val Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 007/131] Bluetooth: h5: Fix missing dependency on BT_HCIUART_SERDEV Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 008/131] pinctrl: berlin: fix 'pctrl->functions' allocation in berlin_pinctrl_build_state Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 009/131] gpio: tegra: Move driver registration to subsys_init level Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 010/131] powerpc/powernv: Fix concurrency issue with npu->mmio_atsd_usage Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 011/131] powerpc/4xx: Fix error return path in ppc4xx_msi_probe() Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 012/131] selftests/bpf: fix a typo in map in map test Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 013/131] media: davinci: vpif_display: Mix memory leak on probe error path Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 014/131] media: dw2102: Fix memleak on sequence of probes Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 015/131] net: phy: Fix the register offsets in Broadcom iProc mdio mux driver Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 016/131] scsi: qla2xxx: Fix unintended Logout Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 017/131] scsi: qla2xxx: Fix session state stuck in Get Port DB Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 018/131] scsi: qla2xxx: Silent erroneous message Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 019/131] clk: scmi: Fix the rounding of clock rate Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 020/131] blk-mq: fix updating tags depth Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 021/131] scsi: lpfc: Fix driver crash when re-registering NVME rports Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 022/131] scsi: target: fix __transport_register_session locking Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 023/131] media: usbtv: use irqsave() in USB's complete callback Sasha Levin
2018-09-03  7:16   ` Sebastian Andrzej Siewior
2018-09-07  0:22     ` Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 024/131] md/raid5: fix data corruption of replacements after originals dropped Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 025/131] timers: Clear timer_base::must_forward_clk with timer_base::lock held Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 026/131] media: camss: csid: Configure data type and decode format properly Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 027/131] gpu: ipu-v3: default to id 0 on missing OF alias Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 028/131] misc: ti-st: Fix memory leak in the error path of probe() Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 029/131] uio: potential double frees if __uio_register_device() fails Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 030/131] firmware: vpd: Fix section enabled flag on vpd_section_destroy Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 031/131] Drivers: hv: vmbus: Cleanup synic memory free path Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 032/131] tty: rocket: Fix possible buffer overwrite on register_PCI Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 033/131] uio: fix possible circular locking dependency Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 034/131] iwlwifi: pcie: don't access periphery registers when not available Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 035/131] IB/IPoIB: Set ah valid flag in multicast send flow Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 036/131] f2fs: fix to active page in lru list for read path Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 037/131] ftrace: Add missing check for existing hwlat thread Sasha Levin
2018-09-04 16:43   ` Steven Rostedt
2018-09-07  0:23     ` Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 038/131] f2fs: do not set free of current section Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 039/131] f2fs: Keep alloc_valid_block_count in sync Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 040/131] f2fs: issue discard align to section in LFS mode Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 041/131] f2fs: fix defined but not used build warnings Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 042/131] f2fs: fix to detect looped node chain correctly Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 043/131] ASoC: soc-pcm: Use delay set in component pointer function Sasha Levin
2018-09-03 11:16   ` Mark Brown
2018-09-07  0:23     ` Sasha Levin
2018-09-07  7:16       ` Agrawal, Akshu
2018-09-07 12:00         ` Mark Brown
2018-09-07 10:39       ` Mark Brown
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 044/131] perf tools: Allow overriding MAX_NR_CPUS at compile time Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 045/131] device-dax: avoid hang on error before devm_memremap_pages() Sasha Levin
2018-09-02 13:03 ` [PATCH AUTOSEL 4.18 046/131] NFSv4.0 fix client reference leak in callback Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 047/131] perf c2c report: Fix crash for empty browser Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 048/131] fbdev/core: Disable console-lock warnings when fb.lockless_register_fb is set Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 049/131] perf evlist: Fix error out while applying initial delay and LBR Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 050/131] powerpc/pseries: fix EEH recovery of some IOV devices Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 051/131] macintosh/via-pmu: Add missing mmio accessors Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 052/131] perf build: Fix installation directory for eBPF Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 053/131] ath9k: report tx status on EOSP Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 054/131] ath9k_hw: fix channel maximum power level test Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 055/131] ath10k: prevent active scans on potential unusable channels Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 056/131] wlcore: Set rx_status boottime_ns field on rx Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 057/131] rpmsg: core: add support to power domains for devices Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 058/131] mtd: rawnand: make subop helpers return unsigned values Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 059/131] scsi: tcmu: do not set max_blocks if data_bitmap has been setup Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 060/131] MIPS: Fix ISA virt/bus conversion for non-zero PHYS_OFFSET Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 061/131] ata: libahci: Allow reconfigure of DEVSLP register Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 062/131] ata: libahci: Correct setting " Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 063/131] nfs: Referrals not inheriting proto setting from parent Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 064/131] scsi: 3ware: fix return 0 on the error path of probe Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 065/131] tools/testing/nvdimm: kaddr and pfn can be NULL to ->direct_access() Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 066/131] ath10k: disable bundle mgmt tx completion event support Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 067/131] media: em28xx: explicitly disable TS packet filter Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 068/131] PCI: mobiveil: Add missing ../pci.h include Sasha Levin
2018-09-03  2:24   ` Subrahmanya Lingappa
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 069/131] PCI: mobiveil: Fix struct mobiveil_pcie.pcie_reg_base address type Sasha Levin
2018-09-03  2:24   ` Subrahmanya Lingappa
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 070/131] powerpc/mm: Don't report PUDs as memory leaks when using kmemleak Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 071/131] Bluetooth: hidp: Fix handling of strncpy for hid->name information Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 072/131] x86/mm: Remove in_nmi() warning from vmalloc_fault() Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 073/131] x86/kexec: Allocate 8k PGDs for PTI Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 074/131] ARM: 8783/1: NOMMU: Extend check for VBAR support Sasha Levin
2018-09-10  9:41   ` Vladimir Murzin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 075/131] regulator: tps65217: Fix NULL pointer dereference on probe Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 076/131] pinctrl: imx: off by one in imx_pinconf_group_dbg_show() Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 077/131] gpio: pxa: disable pinctrl calls for PXA3xx Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 078/131] gpio: ml-ioh: Fix buffer underwrite on probe error path Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 079/131] pinctrl/amd: only handle irq if it is pending and unmasked Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 080/131] net: mvneta: fix mtu change on port without link Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 081/131] f2fs: try grabbing node page lock aggressively in sync scenario Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 082/131] pktcdvd: Fix possible Spectre-v1 for pkt_devs Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 083/131] f2fs: fix to skip GC if type in SSA and SIT is inconsistent Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 084/131] tpm_tis_spi: Pass the SPI IRQ down to the driver Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 085/131] tpm/tpm_i2c_infineon: switch to i2c_lock_bus(..., I2C_LOCK_SEGMENT) Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 086/131] f2fs: fix to do sanity check with reserved blkaddr of inline inode Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 087/131] MIPS: Octeon: add missing of_node_put() Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 088/131] MIPS: generic: fix " Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 089/131] iio: ad9523: Fix return value for ad952x_store() Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 090/131] thermal: rcar_thermal: avoid NULL dereference in absence of IRQ resources Sasha Levin
2018-09-02 13:04 ` [PATCH AUTOSEL 4.18 091/131] thermal_hwmon: Sanitize attribute name passed to hwmon Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 092/131] net: dcb: For wild-card lookups, use priority -1, not 0 Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 093/131] dm cache: only allow a single io_mode cache feature to be requested Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 094/131] Input: atmel_mxt_ts - only use first T9 instance Sasha Levin
2018-09-05 17:14   ` Dmitry Torokhov
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 095/131] iommu/dma: Respect bus DMA limit for IOVAs Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 096/131] media: s5p-mfc: Fix buffer look up in s5p_mfc_handle_frame_{new, copy_time} functions Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 097/131] partitions/aix: append null character to print data from disk Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 098/131] partitions/aix: fix usage of uninitialized lv_info and lvname structures Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 099/131] media: rcar-csi2: update stream start for V3M Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 100/131] media: helene: fix xtal frequency setting at power on Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 101/131] drm/amd/display: Prevent PSR from being enabled if initialization fails Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 102/131] media: em28xx: Fix dual transport stream operation Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 103/131] iommu/arm-smmu-v3: Abort all transactions if SMMU is enabled in kdump kernel Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 104/131] f2fs: fix to wait on page writeback before updating page Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 105/131] f2fs: Fix uninitialized return in f2fs_ioc_shutdown() Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 106/131] media: em28xx: Fix DualHD disconnect oops Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 107/131] f2fs: avoid potential deadlock in f2fs_sbi_store Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 108/131] f2fs: fix to do sanity check with secs_per_zone Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 109/131] mfd: rave-sp: Initialize flow control and parity of the port Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 110/131] iommu/ipmmu-vmsa: Fix allocation in atomic context Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 111/131] mfd: ti_am335x_tscadc: Fix struct clk memory leak Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 112/131] f2fs: fix to do sanity check with {sit,nat}_ver_bitmap_bytesize Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 113/131] ALSA: riptide: Properly endian notations Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 114/131] ALSA: pcm: Fix sparse warning wrt PCM format type Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 115/131] ALSA: wss: " Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 116/131] ALSA: xen: Use standard pcm_format_to_bits() for ALSA format bits Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 117/131] ALSA: sb: Fix PCM format bit calculation Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 118/131] ALSA: asihpi: Fix PCM format notations Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 119/131] ALSA: ad1816a: Fix sparse warning wrt PCM format type Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 120/131] f2fs: fix to propagate return value of scan_nat_page() Sasha Levin
2018-09-02 13:05 ` Sasha Levin [this message]
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 122/131] RDMA/hns: Add illegal hop_num judgement Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 123/131] ALSA: hda: Fix implicit PCM format type conversion Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 124/131] ALSA: au88x0: Fix sparse warning wrt PCM format type Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 125/131] ALSA: sb: " Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 126/131] NFSv4.1: Fix a potential layoutget/layoutrecall deadlock Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 127/131] RDMA/hns: Update the data type of immediate data Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 128/131] MIPS: WARN_ON invalid DMA cache maintenance, not BUG_ON Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 129/131] MIPS: mscc: ocelot: fix length of memory address space for MIIM Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 130/131] RDMA/cma: Do not ignore net namespace for unbound cm_id Sasha Levin
2018-09-02 13:05 ` [PATCH AUTOSEL 4.18 131/131] fuse: Add missed unlock_page() to fuse_readpages_fill() Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20180902064601.183036-121-alexander.levin@microsoft.com \
    --to=alexander.levin@microsoft.com \
    --cc=jaegeuk@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=yuchao0@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome