[PATCH v3 2/2] Protected O_CREAT open in sticky directories

2017-11-22 Thread Salvatore Mesoraca
Disallows O_CREAT open missing the O_EXCL flag, in world or group writable directories, even if the file doesn't exist yet. With few exceptions (e.g. shared lock files based on flock()) if a program tries to open a file, in a sticky directory, with the O_CREAT flag and without the O_EXCL, it probab

[PATCH v3 0/2] Restrict dangerous open in sticky directories

2017-11-22 Thread Salvatore Mesoraca
This patch-set introduces two separate features aimed at restricting dangerous open in world or group writable sticky directories. The purpose is to prevent exploitable bugs in user-space programs that don't access sticky directories in the proper way. The first patch prevents the O_CREAT open of F

[PATCH v3 1/2] Protected FIFOs and regular files

2017-11-22 Thread Salvatore Mesoraca
Disallows open of FIFOs or regular files not owned by the user in world writable sticky directories, unless the owner is the same as that of the directory or the file is opened without the O_CREAT flag. The purpose is to make data spoofing attacks harder. This protection can be turned on and off se

[PATCH] crypto: arm64/aes - do not call crypto_unregister_skcipher twice on error

2017-11-22 Thread Corentin Labbe
When a cipher fail to register in aes_init(), the error path go thought aes_exit() then crypto_unregister_skciphers(). Since aes_exit calls also crypto_unregister_skcipher, this trigger a refcount_t: underflow; use-after-free. Signed-off-by: Corentin Labbe --- arch/arm64/crypto/aes-glue.c | 5 ++

Re: [GIT PULL 1/2] bcm2835-dt-fixes-2017-10-06

2017-11-22 Thread Loic Poulain
Hi Peter, > So it seems it's actually working fine albeit the strange mac addr, no > idea what I was trying before, although there's an error about loading > firmware: > > [ 31.035291] Bluetooth: hci0: BCM: chip id 94 > [ 31.035801] Bluetooth: hci0: BCM: features 0x2e > [ 31.037483] Bluetoot

[f2fs-dev] [PATCH RESEND v3] f2fs: fix concurrent problem for updating free bitmap

2017-11-22 Thread LiFan
alloc_nid_failed and scan_nat_page can be called at the same time, and we haven't protected add_free_nid and update_free_nid_bitmap with the same nid_list_lock. That could lead to Thread AThread B - __build_free_nids - scan_nat_page

Re: [PATCHv2 0/4] x86: 5-level related changes into decompression code

2017-11-22 Thread Kirill A. Shutemov
On Sat, Nov 11, 2017 at 01:06:41AM +0300, Kirill A. Shutemov wrote: > Hi Ingo, > > Here's updated changes that prepare the code to boot-time switching between > paging modes and handle booting in 5-level mode when bootloader put kernel > image above 4G, but haven't enabled 5-level paging for us. >

Re: [PATCHv3 2/2] x86/selftests: Add test for mapping placement for 5-level paging

2017-11-22 Thread Kirill A. Shutemov
On Wed, Nov 22, 2017 at 11:11:36AM +0530, Aneesh Kumar K.V wrote: > "Kirill A. Shutemov" writes: > > > With 5-level paging, we have 56-bit virtual address space available for > > userspace. But we don't want to expose userspace to addresses above > > 47-bits, unless it asked specifically for it.

Re: [PATCH v1 3/9] perf util: Reconstruct rblist for supporting per-thread shadow stats

2017-11-22 Thread Jiri Olsa
On Wed, Nov 22, 2017 at 09:29:26AM +0800, Jin, Yao wrote: > > > On 11/21/2017 11:17 PM, Jiri Olsa wrote: > > On Mon, Nov 20, 2017 at 10:43:38PM +0800, Jin Yao wrote: > > > > SNIP > > > > > +static void init_saved_rblist(struct rblist *rblist) > > > +{ > > > + rblist__init(rblist); > > > + rblis

Re: [PATCH v1 3/9] perf util: Reconstruct rblist for supporting per-thread shadow stats

2017-11-22 Thread Jiri Olsa
On Wed, Nov 22, 2017 at 02:57:12PM +0800, Jin, Yao wrote: > > > On 11/22/2017 2:31 PM, Ravi Bangoria wrote: > > > > On 11/20/2017 08:13 PM, Jin Yao wrote: > > > @@ -76,6 +97,17 @@ static struct rb_node *saved_value_new(struct > > > rblist *rblist __maybe_unused, > > >   return &nd->rb_node;

Re: [PATCH v1 8/9] perf stat: Remove --per-thread pid/tid limitation

2017-11-22 Thread Jiri Olsa
On Wed, Nov 22, 2017 at 11:42:05AM +0800, Jin, Yao wrote: > > > On 11/21/2017 11:18 PM, Jiri Olsa wrote: > > On Mon, Nov 20, 2017 at 10:43:43PM +0800, Jin Yao wrote: > > > > SNIP > > > > > - if ((stat_config.aggr_mode == AGGR_THREAD) && > > > !target__has_task(&target)) { > > > - fprin

[rcu:rcu/dev 62/62] kernel/rcu/rcuperf.c:649:32: sparse: too many arguments for function torture_init_begin

2017-11-22 Thread kbuild test robot
tree: https://git.kernel.org/pub/scm/linux/kernel/git/paulmck/linux-rcu.git rcu/dev head: b151f93a71fc9fecb560e823a92402d882516483 commit: b151f93a71fc9fecb560e823a92402d882516483 [62/62] torture: Eliminate torture_runnable reproduce: # apt-get install sparse git checkout b151

Re: [PATCH v1 4/9] perf util: Update and print per-thread shadow stats

2017-11-22 Thread Jiri Olsa
On Wed, Nov 22, 2017 at 11:10:37AM +0800, Jin, Yao wrote: > > > On 11/21/2017 11:18 PM, Jiri Olsa wrote: > > On Mon, Nov 20, 2017 at 10:43:39PM +0800, Jin Yao wrote: > > > > SNIP > > > > > if (num == 0) > > > diff --git a/tools/perf/util/stat.c b/tools/perf/util/stat.c > > > index 151

Re: [PATCH] KVM: VMX: Fix vmx->nested freeing when no SMI handler

2017-11-22 Thread Liran Alon
On 22/11/17 09:56, Wanpeng Li wrote: From: Wanpeng Li Reported by syzkaller: [ cut here ] WARNING: CPU: 5 PID: 2939 at arch/x86/kvm/vmx.c:3844 free_loaded_vmcs+0x77/0x80 [kvm_intel] CPU: 5 PID: 2939 Comm: repro Not tainted 4.14.0+ #26

Re: [PATCH] KVM: VMX: Fix vmx->nested freeing when no SMI handler

2017-11-22 Thread Wanpeng Li
2017-11-22 16:45 GMT+08:00 Liran Alon : > > > On 22/11/17 09:56, Wanpeng Li wrote: >> >> From: Wanpeng Li >> >> Reported by syzkaller: >> >> [ cut here ] >> WARNING: CPU: 5 PID: 2939 at arch/x86/kvm/vmx.c:3844 >> free_loaded_vmcs+0x77/0x80 [kvm_intel] >>

Re: Linux & FAT32 label

2017-11-22 Thread Pali Rohár
On Monday 20 November 2017 12:12:56 Karel Zak wrote: > On Sun, Nov 19, 2017 at 01:44:40PM +0100, Pali Rohár wrote: > > On Thursday 09 November 2017 22:21:31 Pali Rohár wrote: > > > So from all tests and discussion I would propose new unification: > > > > > > 1. Read label only from the root direct

Re: [PATCH] mm: migrate: fix an incorrect call of prep_transhuge_page()

2017-11-22 Thread Michal Hocko
On Mon 20-11-17 21:18:55, Zi Yan wrote: > From: Zi Yan > > In [1], Andrea reported that during memory hotplug/hot remove > prep_transhuge_page() is called incorrectly on non-THP pages for > migration, when THP is on but THP migration is not enabled. > This leads to a bad state of target pages for

Re: [PATCH] crypto: arm64/aes - do not call crypto_unregister_skcipher twice on error

2017-11-22 Thread Ard Biesheuvel
Hello Corentin, On 22 November 2017 at 08:08, Corentin Labbe wrote: > When a cipher fail fails > to register in aes_init(), the error path go thought goes through > aes_exit() then crypto_unregister_skciphers(). > Since aes_exit calls also crypto_unregister_skcipher, this trigger a triggers

[PATCH] PCI: endpoint: Use EPC's device in dma_alloc_coherent/dma_free_coherent

2017-11-22 Thread Kishon Vijay Abraham I
After commit 723288836628bc1c08 ("of: restrict DMA configuration"), of_dma_configure doesn't configure the coherent_dma_mask/dma_mask of endpoint function device (since it doesn't have a dt node associated with and hence no dma-ranges property), resulting in dma_alloc_coherent (used in pci_epf_allo

Re: [PATCH v2 06/18] x86/kasan/64: Teach KASAN about the cpu_entry_area

2017-11-22 Thread Andrey Ryabinin
On 11/22/2017 07:44 AM, Andy Lutomirski wrote: > The cpu_entry_area will contain stacks. Make sure that KASAN has > appropriate shadow mappings for them. > > Cc: Andrey Ryabinin > Cc: Alexander Potapenko > Cc: Dmitry Vyukov > Cc: kasan-...@googlegroups.com > Signed-off-by: Andy Lutomirski >

[PATCH] PCI: designware-ep: Fix ->get_msi() to check MSI_EN bit

2017-11-22 Thread Kishon Vijay Abraham I
->get_msi() now checks MSI_EN bit in the MSI CAPABILITY register to find whether the host supports MSI instead of using the MSI ADDRESS in the MSI CAPABILITY register. This fixes the issue with the following sequence 'modprobe pci_endpoint_test' enables MSI 'rmmod pci_endpoint_test' disables M

Re: [PATCH] KVM: VMX: Fix vmx->nested freeing when no SMI handler

2017-11-22 Thread Liran Alon
On 22/11/17 10:45, Liran Alon wrote: On 22/11/17 09:56, Wanpeng Li wrote: From: Wanpeng Li Reported by syzkaller: [ cut here ] WARNING: CPU: 5 PID: 2939 at arch/x86/kvm/vmx.c:3844 free_loaded_vmcs+0x77/0x80 [kvm_intel] CPU: 5 PID: 2939 Comm: repro Not t

Re: [PATCH v2] mm: show total hugetlb memory consumption in /proc/meminfo

2017-11-22 Thread Michal Hocko
On Tue 21-11-17 16:27:38, Mike Kravetz wrote: > On 11/21/2017 11:59 AM, Roman Gushchin wrote: [...] > > What we can do, is to rename "count" into "nr_huge_pages", like: > > > > for_each_hstate(h) { > > unsigned long nr_huge_pages = h->nr_huge_pages; > > > > total += (P

Re: [tegra186]: emmc resume failing after booting from snapshot image

2017-11-22 Thread Mikko Perttunen
The upstream kernel currently has no core rail suspend support (LP0/SC7) on Tegras - in general the downstream kernel (used e.g. in L4T) is the reference that has the most functionality on Tegra. IIRC the MMC subsystem and Tegra MMC driver between upstream and downstream are currently quite di

Re: [PATCH 2/4] ARM: dts: imx6qdl: Add Variscite DART-MX6 SoM support

2017-11-22 Thread Neil Armstrong
Hi Fabio, On 21/11/2017 17:54, Fabio Estevam wrote: > On Tue, Nov 21, 2017 at 2:28 PM, Neil Armstrong > wrote: > >> + reg_wl18xx_vmmc: regulator-wl18xx { >> + compatible = "regulator-fixed"; >> + regulator-name = "vwl1807"; >> + regulator-min-micr

Re: [PATCH] mm: migrate: fix an incorrect call of prep_transhuge_page()

2017-11-22 Thread Zi Yan
On 22 Nov 2017, at 3:54, Michal Hocko wrote: > On Mon 20-11-17 21:18:55, Zi Yan wrote: >> From: Zi Yan >> >> In [1], Andrea reported that during memory hotplug/hot remove >> prep_transhuge_page() is called incorrectly on non-THP pages for >> migration, when THP is on but THP migration is not enab

Re: [RFC PATCH] tpm: don't return -EINVAL if TPM command validation fails

2017-11-22 Thread Javier Martinez Canillas
On 11/21/2017 09:29 PM, Roberts, William C wrote: [snip] >>> >>> Do you agree with Jason's suggestion to send a synthesized TPM command >>> in the that the command isn't supported? >> >> Nope. > > We should update the elf loader to make sure that ELF files don't contain > Incorrect instructions.

Re: Does CONFIG_HARDENED_USERCOPY break /dev/mem?

2017-11-22 Thread Michael Holzheu
Am Mon, 13 Nov 2017 11:19:38 +0100 schrieb Michael Holzheu : > Am Fri, 10 Nov 2017 10:46:49 -0800 > schrieb Kees Cook : > > > On Fri, Nov 10, 2017 at 7:45 AM, Michael Holzheu > > wrote: > > > Hello Kees, > > > > > > When I try to run the crash tool on my s390 live system I get a kernel > > > pa

[V9fs-developer] [bug report] fs/9p: inode blocks show error in fscache mode

2017-11-22 Thread jiangyiwen
Hi all, I test a scenario that will cause the difference of inode blocks between client and host, the scenario as follows: Precondition: 1) use VirtFS(virtio-9p) to connect guest and host. 2) 9p dir in guest is /mnt/9p, host is /9p-host. 3) server fs is ext4 and block size is 4096. Test steps: 1

Re: [PATCH] KVM: VMX: Fix vmx->nested freeing when no SMI handler

2017-11-22 Thread Wanpeng Li
2017-11-22 17:07 GMT+08:00 Liran Alon : > > > On 22/11/17 10:45, Liran Alon wrote: >> >> >> >> On 22/11/17 09:56, Wanpeng Li wrote: >>> >>> From: Wanpeng Li >>> >>> Reported by syzkaller: >>> >>> [ cut here ] >>> WARNING: CPU: 5 PID: 2939 at arch/x86/kvm/vmx.c:3844

Re: 答复: [PATCH v5,1/2] misc: rtsx: Move Realtek Card Reader Driver to misc

2017-11-22 Thread Arnd Bergmann
On Wed, Nov 22, 2017 at 4:24 AM, 冯锐 wrote: > Dear all: > > I checked the file ".config", I found " CONFIG_MMC_REALTEK_USB=y " but its > dependence MISC_RTSX_USB is not selected, so compile errors occurred. > What should I do to fix it? The problem is this bit in the Makefile: --- a/drivers/misc

Re: [PATCH] mm: migrate: fix an incorrect call of prep_transhuge_page()

2017-11-22 Thread Michal Hocko
On Wed 22-11-17 04:18:35, Zi Yan wrote: > On 22 Nov 2017, at 3:54, Michal Hocko wrote: [...] > > I would keep the two checks consistent. But that leads to a more > > interesting question. new_page_nodemask does > > > > if (thp_migration_supported() && PageTransHuge(page)) { > > orde

Re: VMs freezing when host is running 4.14

2017-11-22 Thread Marc Haber
On Tue, Nov 21, 2017 at 05:18:21PM +0100, Marc Haber wrote: > On the affected host, VMs freeze at a rate about two or three per day. > They just stop dead in their tracks, console and serial console become > unresponsive, ping stops, they don't react to virsh shutdown, only to > virsh destroy. I w

Re: [PATCH] KVM: VMX: Fix vmx->nested freeing when no SMI handler

2017-11-22 Thread Liran Alon
On 22/11/17 11:31, Wanpeng Li wrote: 2017-11-22 17:07 GMT+08:00 Liran Alon : On 22/11/17 10:45, Liran Alon wrote: On 22/11/17 09:56, Wanpeng Li wrote: From: Wanpeng Li Reported by syzkaller: [ cut here ] WARNING: CPU: 5 PID: 2939 at arch/x86/kvm/vmx

Re: [PATCH] mm: migrate: fix an incorrect call of prep_transhuge_page()

2017-11-22 Thread Andrea Reale
On Tue 21 Nov 2017, 17:35, Zi Yan wrote: > On 21 Nov 2017, at 17:12, Andrew Morton wrote: > > > On Mon, 20 Nov 2017 21:18:55 -0500 Zi Yan wrote: > > > >> This patch fixes it by only calling prep_transhuge_page() when we are > >> certain that the target page is THP. > > > > What are the user-visib

Re: [PATCH v2 1/3] media: V3s: Add support for Allwinner CSI.

2017-11-22 Thread Maxime Ripard
Hi, On Wed, Nov 22, 2017 at 09:33:06AM +0800, Yong wrote: > > On Thu, Jul 27, 2017 at 01:01:35PM +0800, Yong Deng wrote: > > > Allwinner V3s SoC have two CSI module. CSI0 is used for MIPI interface > > > and CSI1 is used for parallel interface. This is not documented in > > > datasheet but by test

Re: [RFC] doc: add maintainer book

2017-11-22 Thread Greg Kroah-Hartman
On Wed, Nov 22, 2017 at 09:39:39AM +1100, Tobin C. Harding wrote: > There is currently very little documentation in the kernel on maintainer > level tasks. In particular there are no documents on creating pull > requests to submit to Linus. > > Quoting Greg Kroah-Hartman on LKML: > > Anyway,

Re: [PATCH v6 26/37] tracing: Add 'onmatch' hist trigger action support

2017-11-22 Thread Namhyung Kim
On Fri, Nov 17, 2017 at 02:33:05PM -0600, Tom Zanussi wrote: > Add an 'onmatch(matching.event).(param list)' > hist trigger action which is invoked with the set of variables or > event fields named in the 'param list'. The result is the generation > of a synthetic event that consists of the values

[PATCH 1/2] serial: 8250_early: Only set divisor if valid clk & baud

2017-11-22 Thread Matt Redfearn
If either uartclk or baud are 0, avoid calculating and setting a divisor based on them since the output will almost certainly be garbage. This also allows platforms such as the MIPS generic kernel, which has no way to know a valid BASE_BASE for the board it is actually booted on at compile time, t

[PATCH 2/2] MIPS: Add custom serial.h with BASE_BAUD override for generic kernel

2017-11-22 Thread Matt Redfearn
Add a custom serial.h header for MIPS, allowing platforms to override the asm-generic version if required. The generic platform uses this header to set BASE_BAUD to 0. The generic platform supports multiple boards, which may have different UART clocks. Also one of the boards supported is the Bosto

[PATCH] f2fs: obsolete free nid list approach

2017-11-22 Thread Chao Yu
Previously, we use free nid list to manage free nid entry, so during nid allocation, we can just pick up one entry from list header, which has quite low overhead. But sadly, during initialization of free nid list, we should do lookup combining with lots of different inner caches, including NAT pag

Re: [PATCH 12/31] nds32: Device specific operations

2017-11-22 Thread Greentime Hu
2017-11-11 0:14 GMT+08:00 Arnd Bergmann : > Could you move ioremap_nocache/ioremap_uc/ioremap_wc/ioremap_wt > out of that #ifdef, or would that break other architectures? > It seems ok. I just tried arm64, x86 and nds32. #endif /* CONFIG_MMU */ #ifndef ioremap_nocache void __iomem *ioremap(phys_a

Re: [PATCH] KVM: VMX: Fix vmx->nested freeing when no SMI handler

2017-11-22 Thread Dmitry Vyukov
On Wed, Nov 22, 2017 at 10:43 AM, Liran Alon wrote: > > > On 22/11/17 11:31, Wanpeng Li wrote: >> >> 2017-11-22 17:07 GMT+08:00 Liran Alon : >>> >>> >>> >>> On 22/11/17 10:45, Liran Alon wrote: On 22/11/17 09:56, Wanpeng Li wrote: > > > From: Wanpeng Li >

[PATCH] lib/rbtree,drm/mm: Add rbtree_replace_node_cached()

2017-11-22 Thread Chris Wilson
Add a variant of rbtree_replace_node() that maintains the leftmost cache of struct rbtree_root_cached when replacing nodes within the rbtree. As drm_mm is the only rb_replace_node() being used on an interval tree, the mistake looks fairly self-contained. Furthermore the only user of drm_mm_replace

Re: [PATCH v9 4/5] x86/PCI: Enable a 64bit BAR on AMD Family 15h (Models 30h-3fh) Processors v5

2017-11-22 Thread Christian König
Am 21.11.2017 um 23:26 schrieb Boris Ostrovsky: On 11/21/2017 08:34 AM, Christian König wrote: Hi Boris, attached are two patches. The first one is a trivial fix for the infinite loop issue, it now correctly aborts the fixup when it can't find address space for the root window. The second is

[PATCH 3.18 10/12] ocfs2: should wait dio before inode lock in ocfs2_setattr()

2017-11-22 Thread Greg Kroah-Hartman
3.18-stable review patch. If anyone has any objections, please let me know. -- From: alex chen commit 28f5a8a7c033cbf3e32277f4cc9c6afd74f05300 upstream. we should wait dio requests to finish before inode lock in ocfs2_setattr(), otherwise the following deadlock will happen: p

[PATCH 3.18 00/12] 3.18.84-stable review

2017-11-22 Thread Greg Kroah-Hartman
This is the start of the stable review cycle for the 3.18.84 release. There are 12 patches in this series, all will be posted as a response to this one. If anyone has any issues with these being applied, please let me know. Responses should be made by Fri Nov 24 10:10:45 UTC 2017. Anything receiv

[PATCH 3.18 01/12] ipv6/dccp: do not inherit ipv6_mc_list from parent

2017-11-22 Thread Greg Kroah-Hartman
3.18-stable review patch. If anyone has any objections, please let me know. -- From: WANG Cong commit 83eaddab4378db256d00d295bda6ca997cd13a52 upstream. Like commit 657831ffc38e ("dccp/tcp: do not inherit mc_list from parent") we should clear ipv6_mc_list etc. for IPv6 sockets

[PATCH 3.18 11/12] ipmi: fix unsigned long underflow

2017-11-22 Thread Greg Kroah-Hartman
3.18-stable review patch. If anyone has any objections, please let me know. -- From: Corey Minyard commit 392a17b10ec4320d3c0e96e2a23ebaad1123b989 upstream. When I set the timeout to a specific value such as 500ms, the timeout event will not happen in time due to the overflow

[PATCH 3.18 05/12] sctp: do not peel off an assoc from one netns to another one

2017-11-22 Thread Greg Kroah-Hartman
3.18-stable review patch. If anyone has any objections, please let me know. -- From: Xin Long [ Upstream commit df80cd9b28b9ebaa284a41df611dbf3a2d05ca74 ] Now when peeling off an association to the sock in another netns, all transports in this assoc are not to be rehashed and

[PATCH 4.4 13/16] ocfs2: should wait dio before inode lock in ocfs2_setattr()

2017-11-22 Thread Greg Kroah-Hartman
4.4-stable review patch. If anyone has any objections, please let me know. -- From: alex chen commit 28f5a8a7c033cbf3e32277f4cc9c6afd74f05300 upstream. we should wait dio requests to finish before inode lock in ocfs2_setattr(), otherwise the following deadlock will happen: pr

[PATCH 3.18 07/12] af_netlink: ensure that NLMSG_DONE never fails in dumps

2017-11-22 Thread Greg Kroah-Hartman
3.18-stable review patch. If anyone has any objections, please let me know. -- From: "Jason A. Donenfeld" [ Upstream commit 0642840b8bb008528dbdf929cec9f65ac4231ad0 ] The way people generally use netlink_dump is that they fill in the skb as much as possible, breaking when nla

[PATCH 3.18 12/12] coda: fix kernel memory exposure attempt in fsync

2017-11-22 Thread Greg Kroah-Hartman
3.18-stable review patch. If anyone has any objections, please let me know. -- From: Jan Harkes commit d337b66a4c52c7b04eec661d86c2ef6e168965a2 upstream. When an application called fsync on a file in Coda a small request with just the file identifier was allocated, but the dec

[PATCH 4.4 12/16] [PATCH-stable] nvme: Fix memory order on async queue deletion

2017-11-22 Thread Greg Kroah-Hartman
4.4-stable review patch. If anyone has any objections, please let me know. -- From: Keith Busch This patch is a fix specific to the 3.19 - 4.4 kernels. The 4.5 kernel inadvertently fixed this bug differently (db3cbfff5bcc0), but is not a stable candidate due it being a complica

[PATCH 4.4 11/16] arm64: fix dump_instr when PAN and UAO are in use

2017-11-22 Thread Greg Kroah-Hartman
4.4-stable review patch. If anyone has any objections, please let me know. -- From: Mark Rutland commit c5cea06be060f38e5400d796e61cfc8c36e52924 upstream. If the kernel is set to show unhandled signals, and a user task does not handle a SIGILL as a result of an instruction abo

[PATCH 3.18 04/12] netfilter/ipvs: clear ipvs_property flag when SKB net namespace changed

2017-11-22 Thread Greg Kroah-Hartman
3.18-stable review patch. If anyone has any objections, please let me know. -- From: Ye Yin [ Upstream commit 2b5ec1a5f9738ee7bf8f5ec0526e75e00362c48f ] When run ipvs in two different network namespace at the same host, and one ipvs transport network traffic to the other netw

[PATCH 3.18 08/12] vlan: fix a use-after-free in vlan_device_event()

2017-11-22 Thread Greg Kroah-Hartman
3.18-stable review patch. If anyone has any objections, please let me know. -- From: Cong Wang [ Upstream commit 052d41c01b3a2e3371d66de569717353af489d63 ] After refcnt reaches zero, vlan_vid_del() could free dev->vlan_info via RCU: RCU_INIT_POINTER(dev->vlan_info, N

[PATCH 3.18 09/12] ima: do not update security.ima if appraisal status is not INTEGRITY_PASS

2017-11-22 Thread Greg Kroah-Hartman
3.18-stable review patch. If anyone has any objections, please let me know. -- From: Roberto Sassu commit 020aae3ee58c1af0e7ffc4e2cc9fe4dc630338cb upstream. Commit b65a9cfc2c38 ("Untangling ima mess, part 2: deal with counters") moved the call of ima_file_check() from may_open

[PATCH 4.4 10/16] serial: omap: Fix EFR write on RTS deassertion

2017-11-22 Thread Greg Kroah-Hartman
4.4-stable review patch. If anyone has any objections, please let me know. -- From: Lukas Wunner commit 2a71de2f7366fb1aec632116d0549ec56d6a3940 upstream. Commit 348f9bb31c56 ("serial: omap: Fix RTS handling") sought to enable auto RTS upon manual RTS assertion and disable it

[PATCH 3.18 03/12] tcp: do not mangle skb->cb[] in tcp_make_synack()

2017-11-22 Thread Greg Kroah-Hartman
3.18-stable review patch. If anyone has any objections, please let me know. -- From: Eric Dumazet [ Upstream commit 3b11775033dc87c3d161996c54507b15ba26414a ] Christoph Paasch sent a patch to address the following issue : tcp_make_synack() is leaving some TCP private info in

[PATCH 4.9 13/25] fealnx: Fix building error on MIPS

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Huacai Chen [ Upstream commit cc54c1d32e6a4bb3f116721abf900513173e4d02 ] This patch try to fix the building error on MIPS. The reason is MIPS has already defined the LONG macro, which conflict

[PATCH 4.9 10/25] vlan: fix a use-after-free in vlan_device_event()

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Cong Wang [ Upstream commit 052d41c01b3a2e3371d66de569717353af489d63 ] After refcnt reaches zero, vlan_vid_del() could free dev->vlan_info via RCU: RCU_INIT_POINTER(dev->vlan_info, NU

[PATCH 4.9 01/25] tcp_nv: fix division by zero in tcpnv_acked()

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Konstantin Khlebnikov [ Upstream commit 4eebff27ca4182bbf5f039dd60d79e2d7c0a707e ] Average RTT could become zero. This happened in real life at least twice. This patch treats zero as 1us. Sig

[PATCH 4.4 09/16] ima: do not update security.ima if appraisal status is not INTEGRITY_PASS

2017-11-22 Thread Greg Kroah-Hartman
4.4-stable review patch. If anyone has any objections, please let me know. -- From: Roberto Sassu commit 020aae3ee58c1af0e7ffc4e2cc9fe4dc630338cb upstream. Commit b65a9cfc2c38 ("Untangling ima mess, part 2: deal with counters") moved the call of ima_file_check() from may_open(

[PATCH 4.4 02/16] netfilter/ipvs: clear ipvs_property flag when SKB net namespace changed

2017-11-22 Thread Greg Kroah-Hartman
4.4-stable review patch. If anyone has any objections, please let me know. -- From: Ye Yin [ Upstream commit 2b5ec1a5f9738ee7bf8f5ec0526e75e00362c48f ] When run ipvs in two different network namespace at the same host, and one ipvs transport network traffic to the other netwo

[PATCH 4.4 00/16] 4.4.101-stable review

2017-11-22 Thread Greg Kroah-Hartman
This is the start of the stable review cycle for the 4.4.101 release. There are 16 patches in this series, all will be posted as a response to this one. If anyone has any issues with these being applied, please let me know. Responses should be made by Fri Nov 24 10:11:01 UTC 2017. Anything receiv

[PATCH 4.4 07/16] fealnx: Fix building error on MIPS

2017-11-22 Thread Greg Kroah-Hartman
4.4-stable review patch. If anyone has any objections, please let me know. -- From: Huacai Chen [ Upstream commit cc54c1d32e6a4bb3f116721abf900513173e4d02 ] This patch try to fix the building error on MIPS. The reason is MIPS has already defined the LONG macro, which conflict

[PATCH 4.4 03/16] bonding: discard lowest hash bit for 802.3ad layer3+4

2017-11-22 Thread Greg Kroah-Hartman
4.4-stable review patch. If anyone has any objections, please let me know. -- From: Hangbin Liu [ Upstream commit b5f862180d7011d9575d0499fa37f0f25b423b12 ] After commit 07f4c90062f8 ("tcp/dccp: try to not exhaust ip_local_port_range in connect()"), we will try to use even po

[PATCH 4.4 16/16] coda: fix kernel memory exposure attempt in fsync

2017-11-22 Thread Greg Kroah-Hartman
4.4-stable review patch. If anyone has any objections, please let me know. -- From: Jan Harkes commit d337b66a4c52c7b04eec661d86c2ef6e168965a2 upstream. When an application called fsync on a file in Coda a small request with just the file identifier was allocated, but the decl

[PATCH 4.4 08/16] net/sctp: Always set scope_id in sctp_inet6_skb_msgname

2017-11-22 Thread Greg Kroah-Hartman
4.4-stable review patch. If anyone has any objections, please let me know. -- From: "Eric W. Biederman" [ Upstream commit 7c8a61d9ee1df0fb4747879fa67a99614eb62fec ] Alexandar Potapenko while testing the kernel with KMSAN and syzkaller discovered that in some configurations sc

[PATCH 4.9 16/25] crypto: dh - Fix double free of ctx->p

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Eric Biggers commit 12d41a023efb01b846457ccdbbcbe2b65a87d530 upstream. When setting the secret with the software Diffie-Hellman implementation, if allocating 'g' failed (e.g. if it was longer t

[PATCH 4.9 14/25] net/sctp: Always set scope_id in sctp_inet6_skb_msgname

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: "Eric W. Biederman" [ Upstream commit 7c8a61d9ee1df0fb4747879fa67a99614eb62fec ] Alexandar Potapenko while testing the kernel with KMSAN and syzkaller discovered that in some configurations sc

[PATCH 4.9 15/25] crypto: dh - fix memleak in setkey

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Tudor-Dan Ambarus commit ee34e2644a78e2561742bea8c4bdcf83cabf90a7 upstream. setkey can be called multiple times during the existence of the transformation object. In case of multiple setkey cal

[PATCH 4.9 19/25] serial: 8250_fintek: Fix finding base_port with activated SuperIO

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Ji-Ze Hong (Peter Hong) commit fd97e66c5529046e989a0879c3bb58fddb592c71 upstream. The SuperIO will be configured at boot time by BIOS, but some BIOS will not deactivate the SuperIO when the end

[PATCH 4.9 02/25] net: vrf: correct FRA_L3MDEV encode type

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Jeff Barnhill <0xeff...@gmail.com> [ Upstream commit 18129a24983906eaf2a2d448ce4b83e27091ebe2 ] FRA_L3MDEV is defined as U8, but is being added as a U32 attribute. On big endian architecture, t

[PATCH 4.9 20/25] dmaengine: dmatest: warn user when dma test times out

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Adam Wallis commit a9df21e34b422f79d9a9fa5c3eff8c2a53491be6 upstream. Commit adfa543e7314 ("dmatest: don't use set_freezable_with_signal()") introduced a bug (that is in fact documented by the

[PATCH 4.9 25/25] coda: fix kernel memory exposure attempt in fsync

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Jan Harkes commit d337b66a4c52c7b04eec661d86c2ef6e168965a2 upstream. When an application called fsync on a file in Coda a small request with just the file identifier was allocated, but the decl

[PATCH 4.9 05/25] bonding: discard lowest hash bit for 802.3ad layer3+4

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Hangbin Liu [ Upstream commit b5f862180d7011d9575d0499fa37f0f25b423b12 ] After commit 07f4c90062f8 ("tcp/dccp: try to not exhaust ip_local_port_range in connect()"), we will try to use even po

[PATCH 4.13 14/35] vlan: fix a use-after-free in vlan_device_event()

2017-11-22 Thread Greg Kroah-Hartman
4.13-stable review patch. If anyone has any objections, please let me know. -- From: Cong Wang [ Upstream commit 052d41c01b3a2e3371d66de569717353af489d63 ] After refcnt reaches zero, vlan_vid_del() could free dev->vlan_info via RCU: RCU_INIT_POINTER(dev->vlan_info, N

[PATCH 4.9 03/25] tcp: do not mangle skb->cb[] in tcp_make_synack()

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Eric Dumazet [ Upstream commit 3b11775033dc87c3d161996c54507b15ba26414a ] Christoph Paasch sent a patch to address the following issue : tcp_make_synack() is leaving some TCP private info in

[PATCH 4.13 01/35] tcp_nv: fix division by zero in tcpnv_acked()

2017-11-22 Thread Greg Kroah-Hartman
4.13-stable review patch. If anyone has any objections, please let me know. -- From: Konstantin Khlebnikov [ Upstream commit 4eebff27ca4182bbf5f039dd60d79e2d7c0a707e ] Average RTT could become zero. This happened in real life at least twice. This patch treats zero as 1us. Si

[PATCH 4.9 04/25] netfilter/ipvs: clear ipvs_property flag when SKB net namespace changed

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Ye Yin [ Upstream commit 2b5ec1a5f9738ee7bf8f5ec0526e75e00362c48f ] When run ipvs in two different network namespace at the same host, and one ipvs transport network traffic to the other netwo

[PATCH 4.13 12/35] tcp: gso: avoid refcount_t warning from tcp_gso_segment()

2017-11-22 Thread Greg Kroah-Hartman
4.13-stable review patch. If anyone has any objections, please let me know. -- From: Eric Dumazet [ Upstream commit 7ec318feeed10a64c0359ec4d10889cb4defa39a ] When a GSO skb of truesize O is segmented into 2 new skbs of truesize N1 and N2, we want to transfer socket ownership

[PATCH 4.9 00/25] 4.9.65-stable review

2017-11-22 Thread Greg Kroah-Hartman
This is the start of the stable review cycle for the 4.9.65 release. There are 25 patches in this series, all will be posted as a response to this one. If anyone has any issues with these being applied, please let me know. Responses should be made by Fri Nov 24 10:11:07 UTC 2017. Anything receive

[PATCH 4.9 23/25] ipmi: fix unsigned long underflow

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Corey Minyard commit 392a17b10ec4320d3c0e96e2a23ebaad1123b989 upstream. When I set the timeout to a specific value such as 500ms, the timeout event will not happen in time due to the overflow i

[PATCH 4.13 15/35] net/mlx5: Cancel health poll before sending panic teardown command

2017-11-22 Thread Greg Kroah-Hartman
4.13-stable review patch. If anyone has any objections, please let me know. -- From: Huy Nguyen [ Upstream commit d2aa060d40fa060e963f9a356d43481e43ba3dac ] After the panic teardown firmware command, health_care detects the error in PCI bus and calls the mlx5_pci_err_detected

[PATCH 4.9 21/25] ocfs2: fix cluster hang after a node dies

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Changwei Ge commit 1c01967116a678fed8e2c68a6ab82abc8effeddc upstream. When a node dies, other live nodes have to choose a new master for an existed lock resource mastered by the dead node. As

[PATCH 4.9 22/25] ocfs2: should wait dio before inode lock in ocfs2_setattr()

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: alex chen commit 28f5a8a7c033cbf3e32277f4cc9c6afd74f05300 upstream. we should wait dio requests to finish before inode lock in ocfs2_setattr(), otherwise the following deadlock will happen: pr

[PATCH 4.13 11/35] net: usb: asix: fill null-ptr-deref in asix_suspend

2017-11-22 Thread Greg Kroah-Hartman
4.13-stable review patch. If anyone has any objections, please let me know. -- From: Andrey Konovalov [ Upstream commit 8f5624629105589bcc23d0e51cc01bd8103d09a5 ] When asix_suspend() is called dev->driver_priv might not have been assigned a value, so we need to check that it'

[PATCH 4.9 09/25] net: usb: asix: fill null-ptr-deref in asix_suspend

2017-11-22 Thread Greg Kroah-Hartman
4.9-stable review patch. If anyone has any objections, please let me know. -- From: Andrey Konovalov [ Upstream commit 8f5624629105589bcc23d0e51cc01bd8103d09a5 ] When asix_suspend() is called dev->driver_priv might not have been assigned a value, so we need to check that it's

[PATCH 4.13 28/35] mm/pagewalk.c: report holes in hugetlb ranges

2017-11-22 Thread Greg Kroah-Hartman
4.13-stable review patch. If anyone has any objections, please let me know. -- From: Jann Horn commit 373c4557d2aa362702c4c2d41288fb1e54990b7c upstream. This matters at least for the mincore syscall, which will otherwise copy uninitialized memory from the page allocator to use

[PATCH 4.13 25/35] serial: 8250_fintek: Fix finding base_port with activated SuperIO

2017-11-22 Thread Greg Kroah-Hartman
4.13-stable review patch. If anyone has any objections, please let me know. -- From: Ji-Ze Hong (Peter Hong) commit fd97e66c5529046e989a0879c3bb58fddb592c71 upstream. The SuperIO will be configured at boot time by BIOS, but some BIOS will not deactivate the SuperIO when the en

[PATCH 4.13 27/35] rcu: Fix up pending cbs check in rcu_prepare_for_idle

2017-11-22 Thread Greg Kroah-Hartman
4.13-stable review patch. If anyone has any objections, please let me know. -- From: Neeraj Upadhyay commit 135bd1a230bb69a68c9808a7d25467318900b80a upstream. The pending-callbacks check in rcu_prepare_for_idle() is backwards. It should accelerate if there are pending callback

[PATCH 4.13 18/35] vxlan: fix the issue that neigh proxy blocks all icmpv6 packets

2017-11-22 Thread Greg Kroah-Hartman
4.13-stable review patch. If anyone has any objections, please let me know. -- From: Xin Long [ Upstream commit 8bff3685a4bbf175a96bc6a528f13455d8d38244 ] Commit f1fb08f6337c ("vxlan: fix ND proxy when skb doesn't have transport header offset") removed icmp6_code and icmp6_ty

[PATCH 4.13 23/35] ima: do not update security.ima if appraisal status is not INTEGRITY_PASS

2017-11-22 Thread Greg Kroah-Hartman
4.13-stable review patch. If anyone has any objections, please let me know. -- From: Roberto Sassu commit 020aae3ee58c1af0e7ffc4e2cc9fe4dc630338cb upstream. Commit b65a9cfc2c38 ("Untangling ima mess, part 2: deal with counters") moved the call of ima_file_check() from may_open

[PATCH 4.13 26/35] tpm-dev-common: Reject too short writes

2017-11-22 Thread Greg Kroah-Hartman
4.13-stable review patch. If anyone has any objections, please let me know. -- From: Alexander Steffen commit ee70bc1e7b63ac8023c9ff9475d8741e397316e7 upstream. tpm_transmit() does not offer an explicit interface to indicate the number of valid bytes in the communication buffe

[PATCH 4.13 02/35] net: vrf: correct FRA_L3MDEV encode type

2017-11-22 Thread Greg Kroah-Hartman
4.13-stable review patch. If anyone has any objections, please let me know. -- From: Jeff Barnhill <0xeff...@gmail.com> [ Upstream commit 18129a24983906eaf2a2d448ce4b83e27091ebe2 ] FRA_L3MDEV is defined as U8, but is being added as a U32 attribute. On big endian architecture,

[PATCH 4.13 07/35] bonding: discard lowest hash bit for 802.3ad layer3+4

2017-11-22 Thread Greg Kroah-Hartman
4.13-stable review patch. If anyone has any objections, please let me know. -- From: Hangbin Liu [ Upstream commit b5f862180d7011d9575d0499fa37f0f25b423b12 ] After commit 07f4c90062f8 ("tcp/dccp: try to not exhaust ip_local_port_range in connect()"), we will try to use even p

[PATCH 4.13 32/35] mm/page_alloc.c: broken deferred calculation

2017-11-22 Thread Greg Kroah-Hartman
4.13-stable review patch. If anyone has any objections, please let me know. -- From: Pavel Tatashin commit d135e5750205a21a212a19dbb05aeb339e2cbea7 upstream. In reset_deferred_meminit() we determine number of pages that must not be deferred. We initialize pages for at least 2

[PATCH 4.13 00/35] 4.13.16-stable review

2017-11-22 Thread Greg Kroah-Hartman
This is the start of the stable review cycle for the 4.13.16 release. There are 35 patches in this series, all will be posted as a response to this one. If anyone has any issues with these being applied, please let me know. Responses should be made by Fri Nov 24 10:11:25 UTC 2017. Anything receiv

  1   2   3   4   5   6   7   8   9   10   >