mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Ben Hutchings <ben@decadent.org.uk>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: akpm@linux-foundation.org,
	"David S. Miller" <davem@davemloft.net>,
	"Guillaume Nault" <g.nault@alphalink.fr>
Subject: [PATCH 3.16 035/136] l2tp: protect sock pointer of struct pppol2tp_session with RCU
Date: Sun, 11 Feb 2018 04:31:11 +0000	[thread overview]
Message-ID: <lsq.1518323471.785641503@decadent.org.uk> (raw)
In-Reply-To: <lsq.1518323469.348919605@decadent.org.uk>

3.16.54-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Guillaume Nault <g.nault@alphalink.fr>

commit ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 upstream.

pppol2tp_session_create() registers sessions that can't have their
corresponding socket initialised. This socket has to be created by
userspace, then connected to the session by pppol2tp_connect().
Therefore, we need to protect the pppol2tp socket pointer of L2TP
sessions, so that it can safely be updated when userspace is connecting
or closing the socket. This will eventually allow pppol2tp_connect()
to avoid generating transient states while initialising its parts of the
session.

To this end, this patch protects the pppol2tp socket pointer using RCU.

The pppol2tp socket pointer is still set in pppol2tp_connect(), but
only once we know the function isn't going to fail. It's eventually
reset by pppol2tp_release(), which now has to wait for a grace period
to elapse before it can drop the last reference on the socket. This
ensures that pppol2tp_session_get_sock() can safely grab a reference
on the socket, even after ps->sk is reset to NULL but before this
operation actually gets visible from pppol2tp_session_get_sock().

The rest is standard RCU conversion: pppol2tp_recv(), which already
runs in atomic context, is simply enclosed by rcu_read_lock() and
rcu_read_unlock(), while other functions are converted to use
pppol2tp_session_get_sock() followed by sock_put().
pppol2tp_session_setsockopt() is a special case. It used to retrieve
the pppol2tp socket from the L2TP session, which itself was retrieved
from the pppol2tp socket. Therefore we can just avoid dereferencing
ps->sk and directly use the original socket pointer instead.

With all users of ps->sk now handling NULL and concurrent updates, the
L2TP ->ref() and ->deref() callbacks aren't needed anymore. Therefore,
rather than converting pppol2tp_session_sock_hold() and
pppol2tp_session_sock_put(), we can just drop them.

Signed-off-by: Guillaume Nault <g.nault@alphalink.fr>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 net/l2tp/l2tp_ppp.c | 154 ++++++++++++++++++++++++++++++++++------------------
 1 file changed, 101 insertions(+), 53 deletions(-)

--- a/net/l2tp/l2tp_ppp.c
+++ b/net/l2tp/l2tp_ppp.c
@@ -122,8 +122,11 @@
 struct pppol2tp_session {
 	int			owner;		/* pid that opened the socket */
 
-	struct sock		*sock;		/* Pointer to the session
+	struct mutex		sk_lock;	/* Protects .sk */
+	struct sock __rcu	*sk;		/* Pointer to the session
 						 * PPPoX socket */
+	struct sock		*__sk;		/* Copy of .sk, for cleanup */
+	struct rcu_head		rcu;		/* For asynchronous release */
 	struct sock		*tunnel_sock;	/* Pointer to the tunnel UDP
 						 * socket */
 	int			flags;		/* accessed by PPPIOCGFLAGS.
@@ -138,6 +141,24 @@ static const struct ppp_channel_ops pppo
 
 static const struct proto_ops pppol2tp_ops;
 
+/* Retrieves the pppol2tp socket associated to a session.
+ * A reference is held on the returned socket, so this function must be paired
+ * with sock_put().
+ */
+static struct sock *pppol2tp_session_get_sock(struct l2tp_session *session)
+{
+	struct pppol2tp_session *ps = l2tp_session_priv(session);
+	struct sock *sk;
+
+	rcu_read_lock();
+	sk = rcu_dereference(ps->sk);
+	if (sk)
+		sock_hold(sk);
+	rcu_read_unlock();
+
+	return sk;
+}
+
 /* Helpers to obtain tunnel/session contexts from sockets.
  */
 static inline struct l2tp_session *pppol2tp_sock_to_session(struct sock *sk)
@@ -225,7 +246,8 @@ static void pppol2tp_recv(struct l2tp_se
 	/* If the socket is bound, send it in to PPP's input queue. Otherwise
 	 * queue it on the session socket.
 	 */
-	sk = ps->sock;
+	rcu_read_lock();
+	sk = rcu_dereference(ps->sk);
 	if (sk == NULL)
 		goto no_sock;
 
@@ -263,30 +285,16 @@ static void pppol2tp_recv(struct l2tp_se
 			kfree_skb(skb);
 		}
 	}
+	rcu_read_unlock();
 
 	return;
 
 no_sock:
+	rcu_read_unlock();
 	l2tp_info(session, PPPOL2TP_MSG_DATA, "%s: no socket\n", session->name);
 	kfree_skb(skb);
 }
 
-static void pppol2tp_session_sock_hold(struct l2tp_session *session)
-{
-	struct pppol2tp_session *ps = l2tp_session_priv(session);
-
-	if (ps->sock)
-		sock_hold(ps->sock);
-}
-
-static void pppol2tp_session_sock_put(struct l2tp_session *session)
-{
-	struct pppol2tp_session *ps = l2tp_session_priv(session);
-
-	if (ps->sock)
-		sock_put(ps->sock);
-}
-
 /************************************************************************
  * Transmit handling
  ***********************************************************************/
@@ -450,14 +458,16 @@ abort:
  */
 static void pppol2tp_session_close(struct l2tp_session *session)
 {
-	struct pppol2tp_session *ps = l2tp_session_priv(session);
-	struct sock *sk = ps->sock;
-	struct socket *sock = sk->sk_socket;
+	struct sock *sk;
 
 	BUG_ON(session->magic != L2TP_SESSION_MAGIC);
 
-	if (sock)
-		inet_shutdown(sock, 2);
+	sk = pppol2tp_session_get_sock(session);
+	if (sk) {
+		if (sk->sk_socket)
+			inet_shutdown(sk->sk_socket, SEND_SHUTDOWN);
+		sock_put(sk);
+	}
 
 	/* Don't let the session go away before our socket does */
 	l2tp_session_inc_refcount(session);
@@ -480,6 +490,14 @@ static void pppol2tp_session_destruct(st
 	}
 }
 
+static void pppol2tp_put_sk(struct rcu_head *head)
+{
+	struct pppol2tp_session *ps;
+
+	ps = container_of(head, typeof(*ps), rcu);
+	sock_put(ps->__sk);
+}
+
 /* Called when the PPPoX socket (session) is closed.
  */
 static int pppol2tp_release(struct socket *sock)
@@ -505,11 +523,24 @@ static int pppol2tp_release(struct socke
 
 	session = pppol2tp_sock_to_session(sk);
 
-	/* Purge any queued data */
 	if (session != NULL) {
+		struct pppol2tp_session *ps;
+
 		__l2tp_session_unhash(session);
 		l2tp_session_queue_purge(session);
-		sock_put(sk);
+
+		ps = l2tp_session_priv(session);
+		mutex_lock(&ps->sk_lock);
+		ps->__sk = rcu_dereference_protected(ps->sk,
+						     lockdep_is_held(&ps->sk_lock));
+		RCU_INIT_POINTER(ps->sk, NULL);
+		mutex_unlock(&ps->sk_lock);
+		call_rcu(&ps->rcu, pppol2tp_put_sk);
+
+		/* Rely on the sock_put() call at the end of the function for
+		 * dropping the reference held by pppol2tp_sock_to_session().
+		 * The last reference will be dropped by pppol2tp_put_sk().
+		 */
 	}
 	release_sock(sk);
 
@@ -576,12 +607,14 @@ out:
 static void pppol2tp_show(struct seq_file *m, void *arg)
 {
 	struct l2tp_session *session = arg;
-	struct pppol2tp_session *ps = l2tp_session_priv(session);
+	struct sock *sk;
+
+	sk = pppol2tp_session_get_sock(session);
+	if (sk) {
+		struct pppox_sock *po = pppox_sk(sk);
 
-	if (ps) {
-		struct pppox_sock *po = pppox_sk(ps->sock);
-		if (po)
-			seq_printf(m, "   interface %s\n", ppp_dev_name(&po->chan));
+		seq_printf(m, "   interface %s\n", ppp_dev_name(&po->chan));
+		sock_put(sk);
 	}
 }
 #endif
@@ -715,13 +748,17 @@ static int pppol2tp_connect(struct socke
 		/* Using a pre-existing session is fine as long as it hasn't
 		 * been connected yet.
 		 */
-		if (ps->sock) {
+		mutex_lock(&ps->sk_lock);
+		if (rcu_dereference_protected(ps->sk,
+					      lockdep_is_held(&ps->sk_lock))) {
+			mutex_unlock(&ps->sk_lock);
 			error = -EEXIST;
 			goto end;
 		}
 
 		/* consistency checks */
 		if (ps->tunnel_sock != tunnel->sock) {
+			mutex_unlock(&ps->sk_lock);
 			error = -EEXIST;
 			goto end;
 		}
@@ -738,19 +775,21 @@ static int pppol2tp_connect(struct socke
 			goto end;
 		}
 
+		ps = l2tp_session_priv(session);
+		mutex_init(&ps->sk_lock);
 		l2tp_session_inc_refcount(session);
+
+		mutex_lock(&ps->sk_lock);
 		error = l2tp_session_register(session, tunnel);
 		if (error < 0) {
+			mutex_unlock(&ps->sk_lock);
 			kfree(session);
 			goto end;
 		}
 		drop_refcnt = true;
 	}
 
-	/* Associate session with its PPPoL2TP socket */
-	ps = l2tp_session_priv(session);
 	ps->owner	     = current->pid;
-	ps->sock	     = sk;
 	ps->tunnel_sock = tunnel->sock;
 
 	session->recv_skb	= pppol2tp_recv;
@@ -759,12 +798,6 @@ static int pppol2tp_connect(struct socke
 	session->show		= pppol2tp_show;
 #endif
 
-	/* We need to know each time a skb is dropped from the reorder
-	 * queue.
-	 */
-	session->ref = pppol2tp_session_sock_hold;
-	session->deref = pppol2tp_session_sock_put;
-
 	/* If PMTU discovery was enabled, use the MTU that was discovered */
 	dst = sk_dst_get(tunnel->sock);
 	if (dst != NULL) {
@@ -798,12 +831,17 @@ static int pppol2tp_connect(struct socke
 	po->chan.mtu	 = session->mtu;
 
 	error = ppp_register_net_channel(sock_net(sk), &po->chan);
-	if (error)
+	if (error) {
+		mutex_unlock(&ps->sk_lock);
 		goto end;
+	}
 
 out_no_ppp:
 	/* This is how we get the session context from the socket. */
 	sk->sk_user_data = session;
+	rcu_assign_pointer(ps->sk, sk);
+	mutex_unlock(&ps->sk_lock);
+
 	sk->sk_state = PPPOX_CONNECTED;
 	l2tp_info(session, PPPOL2TP_MSG_CONTROL, "%s: created\n",
 		  session->name);
@@ -851,6 +889,7 @@ static int pppol2tp_session_create(struc
 	}
 
 	ps = l2tp_session_priv(session);
+	mutex_init(&ps->sk_lock);
 	ps->tunnel_sock = tunnel->sock;
 
 	error = l2tp_session_register(session, tunnel);
@@ -1022,12 +1061,10 @@ static int pppol2tp_session_ioctl(struct
 		 "%s: pppol2tp_session_ioctl(cmd=%#x, arg=%#lx)\n",
 		 session->name, cmd, arg);
 
-	sk = ps->sock;
+	sk = pppol2tp_session_get_sock(session);
 	if (!sk)
 		return -EBADR;
 
-	sock_hold(sk);
-
 	switch (cmd) {
 	case SIOCGIFMTU:
 		err = -ENXIO;
@@ -1303,7 +1340,6 @@ static int pppol2tp_session_setsockopt(s
 				       int optname, int val)
 {
 	int err = 0;
-	struct pppol2tp_session *ps = l2tp_session_priv(session);
 
 	switch (optname) {
 	case PPPOL2TP_SO_RECVSEQ:
@@ -1324,8 +1360,8 @@ static int pppol2tp_session_setsockopt(s
 		}
 		session->send_seq = val ? -1 : 0;
 		{
-			struct sock *ssk      = ps->sock;
-			struct pppox_sock *po = pppox_sk(ssk);
+			struct pppox_sock *po = pppox_sk(sk);
+
 			po->chan.hdrlen = val ? PPPOL2TP_L2TP_HDR_SIZE_SEQ :
 				PPPOL2TP_L2TP_HDR_SIZE_NOSEQ;
 		}
@@ -1664,8 +1700,9 @@ static void pppol2tp_seq_session_show(st
 {
 	struct l2tp_session *session = v;
 	struct l2tp_tunnel *tunnel = session->tunnel;
-	struct pppol2tp_session *ps = l2tp_session_priv(session);
-	struct pppox_sock *po = pppox_sk(ps->sock);
+	unsigned char state;
+	char user_data_ok;
+	struct sock *sk;
 	u32 ip = 0;
 	u16 port = 0;
 
@@ -1675,6 +1712,15 @@ static void pppol2tp_seq_session_show(st
 		port = ntohs(inet->inet_sport);
 	}
 
+	sk = pppol2tp_session_get_sock(session);
+	if (sk) {
+		state = sk->sk_state;
+		user_data_ok = (session == sk->sk_user_data) ? 'Y' : 'N';
+	} else {
+		state = 0;
+		user_data_ok = 'N';
+	}
+
 	seq_printf(m, "  SESSION '%s' %08X/%d %04X/%04X -> "
 		   "%04X/%04X %d %c\n",
 		   session->name, ip, port,
@@ -1682,9 +1728,7 @@ static void pppol2tp_seq_session_show(st
 		   session->session_id,
 		   tunnel->peer_tunnel_id,
 		   session->peer_session_id,
-		   ps->sock->sk_state,
-		   (session == ps->sock->sk_user_data) ?
-		   'Y' : 'N');
+		   state, user_data_ok);
 	seq_printf(m, "   %d/%d/%c/%c/%s %08x %u\n",
 		   session->mtu, session->mru,
 		   session->recv_seq ? 'R' : '-',
@@ -1701,8 +1745,12 @@ static void pppol2tp_seq_session_show(st
 		   atomic_long_read(&session->stats.rx_bytes),
 		   atomic_long_read(&session->stats.rx_errors));
 
-	if (po)
+	if (sk) {
+		struct pppox_sock *po = pppox_sk(sk);
+
 		seq_printf(m, "   interface %s\n", ppp_dev_name(&po->chan));
+		sock_put(sk);
+	}
 }
 
 static int pppol2tp_seq_show(struct seq_file *m, void *v)

  parent reply	other threads:[~2018-02-11  4:40 UTC|newest]

Thread overview: 140+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-02-11  4:31 [PATCH 3.16 000/136] 3.16.54-rc1 review Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 026/136] tpm-dev-common: Reject too short writes Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 068/136] ASoC: cs42l56: Fix reset GPIO name in example DT binding Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 082/136] s390/disassembler: increase show_code buffer size Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 029/136] net: bcmgenet: enable loopback during UniMAC sw_reset Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 015/136] p54: don't unregister leds when they are not initialized Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 017/136] USB: serial: garmin_gps: fix memory leak on probe errors Ben Hutchings
2018-02-11  4:31 ` Ben Hutchings [this message]
2018-02-11  4:31 ` [PATCH 3.16 084/136] sctp: fully initialize the IPv6 address in sctp_v6_to_addr() Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 065/136] iscsi-target: Make TASK_REASSIGN use proper se_cmd->cmd_kref Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 019/136] KVM: nVMX: set IDTR and GDTR limits when loading L1 host state Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 104/136] ALSA: usb-audio: Add sanity checks to FE parser Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 072/136] rt2x00usb: mark device removed when get ENOENT usb error Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 048/136] staging: rtl8188eu: avoid a null dereference on pmlmepriv Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 045/136] drm/ttm: once more fix ttm_buffer_object_transfer Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 110/136] ixgbevf: Use smp_rmb rather than read_barrier_depends Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 030/136] f2fs: expose some sectors to user in inline data or dentry case Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 080/136] clk: ti: dra7-atl-clock: fix child-node lookups Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 075/136] blktrace: Fix potential deadlock between delete & sysfs ops Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 012/136] ext4: fix interaction between i_size, fallocate, and delalloc after a crash Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 036/136] l2tp: initialise PPP sessions before registering them Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 121/136] ALSA: seq: Make ioctls race-free Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 008/136] usbip: tools: Install all headers needed for libusbip development Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 038/136] bcache: only permit to recovery read error when cache device is clean Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 131/136] x86/vdso: Get pvclock data from the vvar VMA instead of the fixmap Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 126/136] usbip: fix stub_send_ret_submit() vulnerability to null transfer_buffer Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 074/136] dm: fix race between dm_get_from_kobject() and __dm_destroy() Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 095/136] autofs: don't fail mount for transient error Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 114/136] ALSA: hda: Add Raven PCI ID Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 130/136] x86, vdso, pvclock: Simplify and speed up the vdso pvclock reader Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 076/136] blktrace: fix unlocked access to init/start-stop/teardown Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 003/136] Input: adxl34x - do not treat FIFO_MODE() as boolean Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 057/136] powerpc/opal: Fix EBUSY bug in acquiring tokens Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 051/136] platform/x86: sony-laptop: Fix error handling in sony_nc_setup_rfkill() Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 113/136] i40evf: Use smp_rmb rather than read_barrier_depends Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 134/136] x86/vdso: Remove pvclock fixmap machinery Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 087/136] dm bufio: fix integer overflow when limiting maximum cache size Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 125/136] usbip: prevent vhci_hcd driver from leaking a socket pointer address Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 115/136] x86/decoder: Add new TEST instruction pattern Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 103/136] ALSA: timer: Remove kernel warning at compat ioctl error paths Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 040/136] arm64: vdso: minor ABI fix for clock_getres Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 122/136] usbip: fix NULL pointer dereference on errors Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 078/136] IB/mlx4: Increase maximal message size under UD QP Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 056/136] powerpc/pseries/vio: Dispose of virq mapping on vdevice unregister Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 096/136] autofs: fix careless error in recent commit Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 033/136] l2tp: don't register sessions in l2tp_session_create() Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 066/136] iscsi-target: Fix non-immediate TMR reference leak Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 067/136] ima: fix hash algorithm initialization Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 090/136] parisc: Fix validity check of pointer size argument in new CAS implementation Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 044/136] isofs: fix timestamps beyond 2027 Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 013/136] drm/i915: Read timings from the correct transcoder in intel_crtc_mode_get() Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 097/136] nilfs2: fix race condition that causes file system corruption Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 054/136] f2fs: remove redundant lines in allocate_data_block Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 089/136] KVM: SVM: obey guest PAT Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 119/136] RDS: Heap OOB write in rds_message_alloc_sgs() Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 105/136] ALSA: usb-audio: Fix potential out-of-bound access at parsing SU Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 106/136] ALSA: usb-audio: Fix potential zero-division at parsing FU Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 060/136] ACPI / APEI: Replace ioremap_page_range() with fixmap Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 034/136] l2tp: initialise l2tp_eth sessions before registering them Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 025/136] IB/srp: Avoid that a cable pull can trigger a kernel crash Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 083/136] sctp: Fixup v4mapped behaviour to comply with Sock API Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 102/136] ARM: 8721/1: mm: dump: check hardware RO bit for LPAE Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 098/136] route: update fnhe_expires for redirect when the fnhe exists Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 041/136] arm64: vdso: fix clock_getres for 4GiB-aligned res Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 053/136] NFC: fix device-allocation error return Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 069/136] USB: usbfs: compute urb->actual_length for isochronous Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 063/136] target: Avoid early CMD_T_PRE_EXECUTE failures during ABORT_TASK Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 006/136] rtc: interface: ignore expired timers when enqueuing new timers Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 101/136] apparmor: ensure that undecidable profile attachments fail Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 020/136] elf_fdpic: fix unused variable warning Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 129/136] x86: pvclock: Really remove the sched notifier for cross-cpu migrations Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 049/136] crypto: caam - fix incorrect define Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 133/136] x86/platform/uv: Include clocksource.h for clocksource_touch_watchdog() Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 042/136] media: omap_vout: Fix a possible null pointer dereference in omap_vout_open() Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 092/136] nfs: Fix ugly referral attributes Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 073/136] s390: fix transactional execution control register handling Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 081/136] ocfs2: should wait dio before inode lock in ocfs2_setattr() Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 043/136] mtd: nand: Fix writing mtdoops to nand flash Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 071/136] video: udlfb: Fix read EDID timeout Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 070/136] MIPS: Fix an n32 core file generation regset support regression Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 014/136] drm/i915/bios: parse DDI ports also for CHV for HDMI DDC pin and DP AUX channel Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 009/136] drm/i915/edp: Get the Panel Power Off timestamp after panel is off Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 027/136] fs/9p: Compare qid.path in v9fs_test_inode Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 086/136] dm: discard support requires all targets in a table support discards Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 100/136] nl80211: don't expose wdev->ssid for most interfaces Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 010/136] PCI/AER: Report non-fatal errors only to the affected endpoint Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 028/136] net/9p: Switch to wait_event_killable() Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 093/136] NFS: Fix typo in nomigration mount option Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 117/136] netfilter: xt_TCPMSS: add more sanity tests on tcph->doff Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 023/136] scsi: bfa: integer overflow in debugfs Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 116/136] staging: android: ashmem: fix a race condition in ASHMEM_SET_SIZE ioctl Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 132/136] Revert "x86: kvmclock: Disable use from vDSO if KPTI is enabled" Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 064/136] target/iscsi: Fix iSCSI task reassignment handling Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 032/136] l2tp: ensure sessions are freed after their PPPOL2TP socket Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 099/136] route: also update fnhe_genid when updating a route cache Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 124/136] usbip: fix stub_rx: harden CMD_SUBMIT path to handle malicious input Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 046/136] drm/radeon: fix atombios on big endian Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 058/136] eCryptfs: use after free in ecryptfs_release_messaging() Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 088/136] KVM: vmx: Inject #GP on invalid PAT CR Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 108/136] ixgbe: Fix skb list corruption on Power systems Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 001/136] drm: gma500: fix logic error Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 062/136] kprobes, x86/alternatives: Use text_mutex to protect smp_alt_modules Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 037/136] btrfs: avoid null pointer dereference on fs_info when calling btrfs_crit Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 047/136] clk: tegra: Fix cclk_lp divisor register Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 022/136] bcache: check ca->alloc_thread initialized before wake up it Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 059/136] powerpc/powernv/cpufreq: Fix the frequency read by /proc/cpuinfo Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 039/136] USB: serial: qcserial: add pid/vid for Sierra Wireless EM7355 fw update Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 118/136] Bluetooth: Prevent stack info leak from the EFS element Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 018/136] media: rc: check for integer overflow Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 107/136] ALSA: usb-audio: Add sanity checks in v2 clock parsers Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 004/136] ipmi: fix unsigned long underflow Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 016/136] USB: serial: garmin_gps: fix I/O after failed probe and remove Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 005/136] s390/runtime instrumention: fix possible memory corruption Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 011/136] iommu/vt-d: Don't register bus-notifier under dmar_global_lock Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 055/136] Revert "f2fs: handle dirty segments inside refresh_sit_entry" Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 077/136] IB/mlx5: Assign send CQ and recv CQ of UMR QP Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 031/136] mtd: nand: omap2: Fix subpage write Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 024/136] IB/srpt: Do not accept invalid initiator port names Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 050/136] USB: Add delay-init quirk for Corsair K70 LUX keyboards Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 061/136] ACPI / APEI: Remove ghes_ioremap_area Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 007/136] rtc: set the alarm to the next expiring timer Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 021/136] USB: serial: metro-usb: stop I/O after failed open Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 136/136] kaiser: Set _PAGE_NX only if supported Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 120/136] RDS: null pointer dereference in rds_atomic_free_op Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 091/136] NFS: Avoid RCU usage in tracepoints Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 094/136] lib/int_sqrt: optimize small argument Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 079/136] clk: ti: dra7-atl-clock: Fix of_node reference counting Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 123/136] usbip: fix stub_rx: get_pipe() to validate endpoint number Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 135/136] kaiser: Set _PAGE_NX only if supported Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 127/136] [media] cx231xx: Fix the max number of interfaces Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 052/136] coda: fix 'kernel memory exposure attempt' in fsync Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 112/136] igb: Use smp_rmb rather than read_barrier_depends Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 085/136] net/sctp: Always set scope_id in sctp_inet6_skb_msgname Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 111/136] igbvf: Use smp_rmb rather than read_barrier_depends Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 128/136] x86, vdso: Move the vvar area before the vdso text Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 109/136] i40e: Use smp_rmb rather than read_barrier_depends Ben Hutchings
2018-02-11  4:31 ` [PATCH 3.16 002/136] staging: lustre: ptlrpc: kfree used instead of kvfree Ben Hutchings
2018-02-11 21:35   ` James Simmons
2018-02-11 11:19 ` [PATCH 3.16 000/136] 3.16.54-rc1 review Guenter Roeck
2018-02-11 17:57   ` Ben Hutchings

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=lsq.1518323471.785641503@decadent.org.uk \
    --to=ben@decadent.org.uk \
    --cc=akpm@linux-foundation.org \
    --cc=davem@davemloft.net \
    --cc=g.nault@alphalink.fr \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®