From: Ben Hutchings <ben@decadent.org.uk>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: akpm@linux-foundation.org, "Aristeu Rozanski" <aris@redhat.com>,
"Herton R. Krzesinski" <herton@redhat.com>,
"Manfred Spraul" <manfred@colorfullife.com>,
"David Jeffery" <djeffery@redhat.com>,
"Davidlohr Bueso" <dave@stgolabs.net>,
"Rafael Aquini" <aquini@redhat.com>,
"Linus Torvalds" <torvalds@linux-foundation.org>
Subject: [PATCH 3.2 025/107] ipc,sem: fix use after free on IPC_RMID after a task using same semaphore set exits
Date: Fri, 09 Oct 2015 01:12:27 +0100 [thread overview]
Message-ID: <lsq.1444349547.675753374@decadent.org.uk> (raw)
In-Reply-To: <lsq.1444349547.316291576@decadent.org.uk>
3.2.72-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: "Herton R. Krzesinski" <herton@redhat.com>
commit 602b8593d2b4138c10e922eeaafe306f6b51817b upstream.
The current semaphore code allows a potential use after free: in
exit_sem we may free the task's sem_undo_list while there is still
another task looping through the same semaphore set and cleaning the
sem_undo list at freeary function (the task called IPC_RMID for the same
semaphore set).
For example, with a test program [1] running which keeps forking a lot
of processes (which then do a semop call with SEM_UNDO flag), and with
the parent right after removing the semaphore set with IPC_RMID, and a
kernel built with CONFIG_SLAB, CONFIG_SLAB_DEBUG and
CONFIG_DEBUG_SPINLOCK, you can easily see something like the following
in the kernel log:
Slab corruption (Not tainted): kmalloc-64 start=ffff88003b45c1c0, len=64
000: 6b 6b 6b 6b 6b 6b 6b 6b 00 6b 6b 6b 6b 6b 6b 6b kkkkkkkk.kkkkkkk
010: ff ff ff ff 6b 6b 6b 6b ff ff ff ff ff ff ff ff ....kkkk........
Prev obj: start=ffff88003b45c180, len=64
000: 00 00 00 00 ad 4e ad de ff ff ff ff 5a 5a 5a 5a .....N......ZZZZ
010: ff ff ff ff ff ff ff ff c0 fb 01 37 00 88 ff ff ...........7....
Next obj: start=ffff88003b45c200, len=64
000: 00 00 00 00 ad 4e ad de ff ff ff ff 5a 5a 5a 5a .....N......ZZZZ
010: ff ff ff ff ff ff ff ff 68 29 a7 3c 00 88 ff ff ........h).<....
BUG: spinlock wrong CPU on CPU#2, test/18028
general protection fault: 0000 [#1] SMP
Modules linked in: 8021q mrp garp stp llc nf_conntrack_ipv4 nf_defrag_ipv4 ip6t_REJECT nf_reject_ipv6 nf_conntrack_ipv6 nf_defrag_ipv6 xt_state nf_conntrack ip6table_filter ip6_tables binfmt_misc ppdev input_leds joydev parport_pc parport floppy serio_raw virtio_balloon virtio_rng virtio_console virtio_net iosf_mbi crct10dif_pclmul crc32_pclmul ghash_clmulni_intel pcspkr qxl ttm drm_kms_helper drm snd_hda_codec_generic i2c_piix4 snd_hda_intel snd_hda_codec snd_hda_core snd_hwdep snd_seq snd_seq_device snd_pcm snd_timer snd soundcore crc32c_intel virtio_pci virtio_ring virtio pata_acpi ata_generic [last unloaded: speedstep_lib]
CPU: 2 PID: 18028 Comm: test Not tainted 4.2.0-rc5+ #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.8.1-20150318_183358- 04/01/2014
RIP: spin_dump+0x53/0xc0
Call Trace:
spin_bug+0x30/0x40
do_raw_spin_unlock+0x71/0xa0
_raw_spin_unlock+0xe/0x10
freeary+0x82/0x2a0
? _raw_spin_lock+0xe/0x10
semctl_down.clone.0+0xce/0x160
? __do_page_fault+0x19a/0x430
? __audit_syscall_entry+0xa8/0x100
SyS_semctl+0x236/0x2c0
? syscall_trace_leave+0xde/0x130
entry_SYSCALL_64_fastpath+0x12/0x71
Code: 8b 80 88 03 00 00 48 8d 88 60 05 00 00 48 c7 c7 a0 2c a4 81 31 c0 65 8b 15 eb 40 f3 7e e8 08 31 68 00 4d 85 e4 44 8b 4b 08 74 5e <45> 8b 84 24 88 03 00 00 49 8d 8c 24 60 05 00 00 8b 53 04 48 89
RIP [<ffffffff810d6053>] spin_dump+0x53/0xc0
RSP <ffff88003750fd68>
---[ end trace 783ebb76612867a0 ]---
NMI watchdog: BUG: soft lockup - CPU#3 stuck for 22s! [test:18053]
Modules linked in: 8021q mrp garp stp llc nf_conntrack_ipv4 nf_defrag_ipv4 ip6t_REJECT nf_reject_ipv6 nf_conntrack_ipv6 nf_defrag_ipv6 xt_state nf_conntrack ip6table_filter ip6_tables binfmt_misc ppdev input_leds joydev parport_pc parport floppy serio_raw virtio_balloon virtio_rng virtio_console virtio_net iosf_mbi crct10dif_pclmul crc32_pclmul ghash_clmulni_intel pcspkr qxl ttm drm_kms_helper drm snd_hda_codec_generic i2c_piix4 snd_hda_intel snd_hda_codec snd_hda_core snd_hwdep snd_seq snd_seq_device snd_pcm snd_timer snd soundcore crc32c_intel virtio_pci virtio_ring virtio pata_acpi ata_generic [last unloaded: speedstep_lib]
CPU: 3 PID: 18053 Comm: test Tainted: G D 4.2.0-rc5+ #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.8.1-20150318_183358- 04/01/2014
RIP: native_read_tsc+0x0/0x20
Call Trace:
? delay_tsc+0x40/0x70
__delay+0xf/0x20
do_raw_spin_lock+0x96/0x140
_raw_spin_lock+0xe/0x10
sem_lock_and_putref+0x11/0x70
SYSC_semtimedop+0x7bf/0x960
? handle_mm_fault+0xbf6/0x1880
? dequeue_task_fair+0x79/0x4a0
? __do_page_fault+0x19a/0x430
? kfree_debugcheck+0x16/0x40
? __do_page_fault+0x19a/0x430
? __audit_syscall_entry+0xa8/0x100
? do_audit_syscall_entry+0x66/0x70
? syscall_trace_enter_phase1+0x139/0x160
SyS_semtimedop+0xe/0x10
SyS_semop+0x10/0x20
entry_SYSCALL_64_fastpath+0x12/0x71
Code: 47 10 83 e8 01 85 c0 89 47 10 75 08 65 48 89 3d 1f 74 ff 7e c9 c3 0f 1f 44 00 00 55 48 89 e5 e8 87 17 04 00 66 90 c9 c3 0f 1f 00 <55> 48 89 e5 0f 31 89 c1 48 89 d0 48 c1 e0 20 89 c9 48 09 c8 c9
Kernel panic - not syncing: softlockup: hung tasks
I wasn't able to trigger any badness on a recent kernel without the
proper config debugs enabled, however I have softlockup reports on some
kernel versions, in the semaphore code, which are similar as above (the
scenario is seen on some servers running IBM DB2 which uses semaphore
syscalls).
The patch here fixes the race against freeary, by acquiring or waiting
on the sem_undo_list lock as necessary (exit_sem can race with freeary,
while freeary sets un->semid to -1 and removes the same sem_undo from
list_proc or when it removes the last sem_undo).
After the patch I'm unable to reproduce the problem using the test case
[1].
[1] Test case used below:
#include <stdio.h>
#include <sys/types.h>
#include <sys/ipc.h>
#include <sys/sem.h>
#include <sys/wait.h>
#include <stdlib.h>
#include <time.h>
#include <unistd.h>
#include <errno.h>
#define NSEM 1
#define NSET 5
int sid[NSET];
void thread()
{
struct sembuf op;
int s;
uid_t pid = getuid();
s = rand() % NSET;
op.sem_num = pid % NSEM;
op.sem_op = 1;
op.sem_flg = SEM_UNDO;
semop(sid[s], &op, 1);
exit(EXIT_SUCCESS);
}
void create_set()
{
int i, j;
pid_t p;
union {
int val;
struct semid_ds *buf;
unsigned short int *array;
struct seminfo *__buf;
} un;
/* Create and initialize semaphore set */
for (i = 0; i < NSET; i++) {
sid[i] = semget(IPC_PRIVATE , NSEM, 0644 | IPC_CREAT);
if (sid[i] < 0) {
perror("semget");
exit(EXIT_FAILURE);
}
}
un.val = 0;
for (i = 0; i < NSET; i++) {
for (j = 0; j < NSEM; j++) {
if (semctl(sid[i], j, SETVAL, un) < 0)
perror("semctl");
}
}
/* Launch threads that operate on semaphore set */
for (i = 0; i < NSEM * NSET * NSET; i++) {
p = fork();
if (p < 0)
perror("fork");
if (p == 0)
thread();
}
/* Free semaphore set */
for (i = 0; i < NSET; i++) {
if (semctl(sid[i], NSEM, IPC_RMID))
perror("IPC_RMID");
}
/* Wait for forked processes to exit */
while (wait(NULL)) {
if (errno == ECHILD)
break;
};
}
int main(int argc, char **argv)
{
pid_t p;
srand(time(NULL));
while (1) {
p = fork();
if (p < 0) {
perror("fork");
exit(EXIT_FAILURE);
}
if (p == 0) {
create_set();
goto end;
}
/* Wait for forked processes to exit */
while (wait(NULL)) {
if (errno == ECHILD)
break;
};
}
end:
return 0;
}
[akpm@linux-foundation.org: use normal comment layout]
Signed-off-by: Herton R. Krzesinski <herton@redhat.com>
Acked-by: Manfred Spraul <manfred@colorfullife.com>
Cc: Davidlohr Bueso <dave@stgolabs.net>
Cc: Rafael Aquini <aquini@redhat.com>
CC: Aristeu Rozanski <aris@redhat.com>
Cc: David Jeffery <djeffery@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/ipc/sem.c
+++ b/ipc/sem.c
@@ -1606,16 +1606,27 @@ void exit_sem(struct task_struct *tsk)
rcu_read_lock();
un = list_entry_rcu(ulp->list_proc.next,
struct sem_undo, list_proc);
- if (&un->list_proc == &ulp->list_proc)
- semid = -1;
- else
- semid = un->semid;
+ if (&un->list_proc == &ulp->list_proc) {
+ /*
+ * We must wait for freeary() before freeing this ulp,
+ * in case we raced with last sem_undo. There is a small
+ * possibility where we exit while freeary() didn't
+ * finish unlocking sem_undo_list.
+ */
+ spin_unlock_wait(&ulp->lock);
+ rcu_read_unlock();
+ break;
+ }
+ spin_lock(&ulp->lock);
+ semid = un->semid;
+ spin_unlock(&ulp->lock);
rcu_read_unlock();
+ /* exit_sem raced with IPC_RMID, nothing to do */
if (semid == -1)
- break;
+ continue;
- sma = sem_lock_check(tsk->nsproxy->ipc_ns, un->semid);
+ sma = sem_lock_check(tsk->nsproxy->ipc_ns, semid);
/* exit_sem raced with IPC_RMID, nothing to do */
if (IS_ERR(sma))
next prev parent reply other threads:[~2015-10-09 0:20 UTC|newest]
Thread overview: 114+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-10-09 0:12 [PATCH 3.2 000/107] 3.2.72-rc1 review Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 031/107] vfs: Test for and handle paths that are unreachable from their mnt_root Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 013/107] perf: Fix fasync handling on inherited events Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 030/107] dcache: Handle escaped paths in prepend_path Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 007/107] target/iscsi: Fix double free of a TUR followed by a solicited NOPOUT Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 014/107] MIPS: Make set_pte() SMP safe Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 028/107] sctp: donot reset the overall_error_count in SHUTDOWN_RECEIVE state Ben Hutchings
2015-10-09 0:12 ` Ben Hutchings [this message]
2015-10-09 0:12 ` [PATCH 3.2 026/107] x86/ldt: Further fix FPU emulation Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 001/107] ipv6: Fix build failure when CONFIG_INET disabled Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 027/107] net: Fix RCU splat in af_key Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 034/107] mac80211: enable assoc check for mesh interfaces Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 036/107] PCI: Add VPD function 0 quirk for Intel Ethernet devices Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 009/107] target: REPORT LUNS should return LUN 0 even for dynamic ACLs Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 010/107] MIPS: Fix sched_getaffinity with MT FPAFF enabled Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 003/107] jbd2: protect all log tail updates with j_checkpoint_mutex Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 019/107] x86/ldt: Correct LDT access in single stepping logic Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 016/107] net: Clone skb before setting peeked flag Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 004/107] xen/gntdevt: Fix race condition in gntdev_release() Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 012/107] rds: fix an integer overflow test in rds_info_getsockopt() Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 038/107] KVM: MMU: fix validation of mmio page fault Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 035/107] PCI: Add dev_flags bit to access VPD through function 0 Ben Hutchings
2015-10-09 0:26 ` Rustad, Mark D
2015-10-09 1:22 ` Ben Hutchings
2015-10-09 17:02 ` Rustad, Mark D
2015-10-09 0:12 ` [PATCH 3.2 006/107] USB: sierra: add 1199:68AB device ID Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 008/107] md/raid1: extend spinlock to protect raid1_end_read_request against inconsistencies Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 039/107] auxdisplay: ks0108: fix refcount Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 029/107] sparc64: Fix userspace FPU register corruptions Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 022/107] dm btree: add ref counting ops for the leaves of top level btrees Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 011/107] xhci: fix off by one error in TRB DMA address boundary check Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 023/107] libiscsi: Fix host busy blocking during connection teardown Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 037/107] usb: gadget: m66592-udc: forever loop in set_feature() Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 033/107] PCI: Fix TI816X class code quirk Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 020/107] x86/ldt: Correct FPU emulation access to LDT Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 032/107] [media] rc-core: fix remove uevent generation Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 002/107] pktgen: Require CONFIG_INET due to use of IPv4 checksum function Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 017/107] net: Fix skb_set_peeked use-after-free bug Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 015/107] ocfs2: fix BUG in ocfs2_downconvert_thread_do_work() Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 005/107] crypto: ixp4xx - Remove bogus BUG_ON on scattered dst buffer Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 024/107] libfc: Fix fc_fcp_cleanup_each_cmd() Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 018/107] x86/ldt: Make modify_ldt synchronous Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 021/107] localmodconfig: Use Kbuild files too Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 057/107] IB/mlx4: Use correct SL on AH query under RoCE Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 091/107] virtio-net: drop NETIF_F_FRAGLIST Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 049/107] DRM - radeon: Don't link train DisplayPort on HPD until we get the dpcd Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 076/107] ARM: fix Thumb2 signal handling when ARMv6 is enabled Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 066/107] ARM: 8429/1: disable GCC SRA optimization Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 051/107] rtlwifi: rtl8192cu: Add new device ID Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 068/107] powerpc/MSI: Fix race condition in tearing down MSI interrupts Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 075/107] ARM: 7880/1: Clear the IT state independent of the Thumb-2 mode Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 104/107] ipv6: update ip6_rt_last_gc every time GC is run Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 095/107] net/tipc: initialize security state for new connection socket Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 047/107] eCryptfs: Invalidate dcache entries when lower i_nlink is zero Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 072/107] USB: option: add ZTE PIDs Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 092/107] RDS: verify the underlying transport exists before creating a connection Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 045/107] usb: host: ehci-sys: delete useless bus_to_hcd conversion Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 078/107] ASoC: fix broken pxa SoC support Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 061/107] Add radeon suspend/resume quirk for HP Compaq dc5750 Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 044/107] serial: 8250: bind to ALi Fast Infrared Controller (ALI5123) Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 073/107] Btrfs: fix read corruption of compressed and shared extents Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 103/107] ipv6: prevent fib6_run_gc() contention Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 050/107] rtlwifi: rtl8192cu: Add new device ID Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 069/107] hfs,hfsplus: cache pages correctly between bnode_create and bnode_free Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 089/107] md: use kzalloc() when bitmap is disabled Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 086/107] x86/paravirt: Replace the paravirt nop with a bona fide empty function Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 100/107] net/ipv6: Correct PIM6 mrt_lock handling Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 074/107] btrfs: skip waiting on ordered range for special files Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 059/107] spi: spi-pxa2xx: Check status register to determine if SSSR_TINT is disabled Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 087/107] ocfs2/dlm: fix deadlock when dispatch assert master Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 058/107] IB/uverbs: Fix race between ib_uverbs_open and remove_one Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 099/107] bonding: correct the MAC address for "follow" fail_over_mac policy Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 046/107] USB: ftdi_sio: Added custom PID for CustomWare products Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 048/107] xfs: Fix xfs_attr_leafblock definition Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 043/107] drivers: usb: fsl: Workaround for USB erratum-A005275 Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 081/107] usb: Use the USB_SS_MULT() macro to get the burst multiplier Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 064/107] crypto: ghash-clmulni: specify context size for ghash async algorithm Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 067/107] pagemap: hide physical addresses from non-privileged users Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 052/107] of/address: Don't loop forever in of_find_matching_node_by_address() Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 054/107] xfs: return errors from partial I/O failures to files Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 040/107] devres: fix devres_get() Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 053/107] drivercore: Fix unregistration path of platform devices Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 084/107] xhci: change xhci 1.0 only restrictions to support xhci 1.1 Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 107/107] Revert "sctp: Fix race between OOTB responce and route removal" Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 063/107] Input: evdev - do not report errors form flush() Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 085/107] cifs: use server timestamp for ntlmv2 authentication Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 093/107] ipc/sem.c: fully initialize sem_array before making it visible Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 041/107] windfarm: decrement client count when unregistering Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 070/107] hfs: fix B-tree corruption after insertion at position 0 Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 080/107] KVM: x86: trap AMD MSRs for the TSeg base and mask Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 071/107] perf header: Fixup reading of HEADER_NRCPUS feature Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 079/107] s390/compat: correct uc_sigmask of the compat signal frame Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 083/107] usb: xhci: Clear XHCI_STATE_DYING on start Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 042/107] NFSv4: don't set SETATTR for O_RDONLY|O_EXCL Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 105/107] parisc: Filter out spurious interrupts in PA-RISC irq handler Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 102/107] perf tools: Fix build with perl 5.18 Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 060/107] drm/i915: Always mark the object as dirty when used by the GPU Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 065/107] fs: create and use seq_show_option for escaping Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 097/107] net: Fix skb csum races when peeking Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 098/107] ipv6: lock socket in ip6_datagram_connect() Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 055/107] IB/qib: Change lkey table allocation to support more MRs Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 082/107] xhci: give command abortion one more chance before killing xhci Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 094/107] Initialize msg/shm IPC objects before doing ipc_addid() Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 096/107] net: pktgen: fix race between pktgen_thread_worker() and kthread_stop() Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 056/107] SUNRPC: xs_reset_transport must mark the connection as disconnected Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 106/107] jbd2: avoid infinite loop when destroying aborted journal Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 088/107] USB: whiteheat: fix potential null-deref at probe Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 101/107] fib_rules: fix fib rule dumps across multiple skbs Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 090/107] ipv6: addrconf: validate new MTU before applying it Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 062/107] IB/uverbs: reject invalid or unknown opcodes Ben Hutchings
2015-10-09 0:12 ` [PATCH 3.2 077/107] x86/platform: Fix Geode LX timekeeping in the generic x86 build Ben Hutchings
2015-10-09 0:56 ` [PATCH 3.2 000/107] 3.2.72-rc1 review Guenter Roeck
2015-10-09 1:17 ` Ben Hutchings
2015-10-09 1:17 ` Ben Hutchings
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=lsq.1444349547.675753374@decadent.org.uk \
--to=ben@decadent.org.uk \
--cc=akpm@linux-foundation.org \
--cc=aquini@redhat.com \
--cc=aris@redhat.com \
--cc=dave@stgolabs.net \
--cc=djeffery@redhat.com \
--cc=herton@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=manfred@colorfullife.com \
--cc=stable@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®